Since 2020 we have delivered cybersecurity and IT infrastructure services for companies and institutions — Fortinet perimeter security, detection and monitoring (SIEM, IDS/IPS, 24/7 SOC), virtualization, backup and disaster recovery, with continuous SLA-backed maintenance.
FortiGate portfolio in production
We manage 10 FortiGate devices in production (the key specialist manages 15 in total):
| FortiGate model | Type | Units |
|---|---|---|
| FortiGate-VM02 | Virtual | 2 |
| FortiGate-VM04 | Virtual | 5 |
| FortiGate-81F | Physical | 3 |
| FortiAnalyzer | Log management + reporting | 1 |
| TOTAL | 7 VM + 3 physical | 10 |
- Policies and routing — zone/interface firewall, NAT/VIP, static and BGP routing, VDOMs, VLAN inter-VLAN segmentation, GeoIP + IP reputation
- SD-WAN — multi-WAN with SLA-based selection (latency/jitter/loss), automatic failover, traffic shaping/QoS
- HA — active-passive FortiGate clusters, config+session sync, FortiOS upgrades with no downtime
- VPN — redundant site-to-site IPsec + FortiClient remote access (IPsec/SSL-VPN), LDAP/AD/RADIUS, FortiToken 2FA
- NGFW/UTM — FortiGuard IDS/IPS, antivirus, web filtering, application control, DNS filter, SSL/TLS inspection
- Logs + visibility — FortiAnalyzer + FortiManager, syslog export to Wazuh SIEM, Suricata/CrowdSec correlation
Firewall and security on Linux
- iptables / nftables — advanced rulesets, ipset, GeoIP, IP reputation (CrowdSec, AbuseIPDB, Spamhaus), Fail2ban, port knocking
- VPN — OpenVPN, IPsec (strongSwan), WireGuard — site-to-site and remote access, with LDAP
- Hardening — CIS Benchmarks verified with Lynis; Windows Server hardening; pfSense, OPNsense, Mikrotik as perimeter platforms
Detection, prevention and monitoring
- Suricata / Snort — inline and monitoring IDS/IPS, Emerging Threats + Talos rules
- CrowdSec — behavioral detection + community-reputation blocking, daily-updated lists
- Wazuh SIEM / XDR — deployed at clients: log collection from firewall/servers/endpoints, correlation, anomaly detection, long retention
- Monitoring — Checkmk platform we operate, plus Nagios/Zabbix at clients; Grafana/Prometheus/Loki; alerting + 24/7 SOC with escalation matrix
- Vulnerability assessment — Nessus, OpenVAS, Rapid7 + penetration tests, with report and remediation plan
Virtualization
- VMware — vCenter, ESXi, vSAN, NSX-T (microsegmentation + distributed firewall), HA/DRS/vMotion
- Hyper-V — Failover Cluster, Storage Spaces Direct, Hyper-V Replica, P2V migrations
- Proxmox VE — hyperconverged clusters with Ceph, Proxmox Backup Server, VMware -> Proxmox migrations
- KVM — consolidating apps on Debian, isolated and secured
Backup and continuity
- Veeam B&R — for VMware and Hyper-V, with an immutable hardened repository, ransomware-resistant
- 3-2-1-1-0 strategy — three copies, two media, one offsite, one immutable, zero restore-test errors (periodically automated)
- Disaster recovery — cross-site replication over IPsec/WireGuard, documented RTO/RPO, runbooks
- Database backup — PostgreSQL, MySQL, MSSQL, MongoDB
Representative projects
- Hardened Linux server — Debian hardened CIS, nftables with GeoIP, inline Suricata IPS, CrowdSec, Wazuh monitoring, KVM virtualization
- Redundant two-site network — dual-ISP with failover, Suricata + CrowdSec + ipset + GeoIP, backup server taking over services in 15 minutes
- Ransomware-proof backup — Veeam B&R with immutable repository + cross-site replication, automated monthly restore test
- NIS2 / ISO 27001 controls — CIS hardening, Wazuh SIEM + Suricata IDS/IPS, 2-year log retention, incident response procedures, audit documentation
24/7 SOC and contact
24/7 SOC monitoring with under-15-minute incident response, a call center (phone + e-mail + ticketing) and an SLA maintenance contract. office@cymmunity.ro · +40 742 170 290.