Back to portfolio
RS
Security

VPN & Firewall Design

Site-to-site and remote-access VPN on Sophos and Fortigate with segmented VLANs, IPS and strict egress control.

Network Security Engineer 5 weeks
0
Shared VPN accounts
100%
MFA coverage
1000+
Malicious egress blocked/day
0
Security incidents
Challenges
  • Flat network with production and guest traffic mixed together.
  • Remote users on shared VPN accounts with no MFA.
  • No IPS or egress filtering.
Solutions
  • Segmented network into VLANs by role with inter-VLAN policies.
  • Rolled out per-user SSL VPN with MFA and endpoint compliance checks.
  • Enabled IPS, geo-blocking and egress filtering on all zones.
Business Impact

Secure remote work for a distributed workforce with zero credential-based breaches.

Technology Stack
Sophos XGFortigateSSL VPNIPsecVLANIPS