pfSense Consultant · Ireland · Senior network engineering
pfSense / Netgate consultant for Irish hotels, SMEs, food producers and equestrian operators. Firewall design, VLAN segmentation, captive portal, multi-WAN failover, VPN, IDS/IPS. Senior-led delivery. Tipperary, Cashel, Galway, Portlaoise and the Midlands.
pfSense / Netgate VLAN segmentation Multi-WAN failover IPsec / WireGuard VPN
There's a Netgate appliance in the comms cupboard. The MSP that installed it is hard to reach. The rule set has grown organically over three years. Nobody can confidently say what's actually allowed. We come in, document the existing state, simplify the ruleset, and hand you back something legible.
We routinely walk into hospitality sites where the guest WiFi, the POS terminals, the property-management system, and the IoT devices are all on one flat /24. From a security and PCI-DSS perspective, that's a problem. We re-architect the network into clean VLANs and write the firewall rules between them.
Two ISPs, two cables into the building, an expensive monthly bill — but when the primary drops, traffic doesn't move to the secondary. Or it does, but the VPN re-establishes badly and the PMS loses its database connection. We tune the failover so it actually works on a Tuesday at 6pm.
Old IPsec configs with weak ciphers, OpenVPN setups that drop daily, road-warrior VPN that needs a fresh certificate generated by hand every onboarding. We modernise the VPN to WireGuard where it makes sense, IPsec where it must, and write the runbook so onboarding new users is a 5-minute job.
Site survey, traffic mapping, segmentation plan. We design the VLAN layout against your actual business — PMS / POS / payments / staff / guest / IoT / management — with documented inter-VLAN rules. PCI-DSS-friendly by default for hospitality clients.
Branded captive portal with T&Cs, optional email capture, optional voucher / paid access for events. SSO with the PMS for room-keyed access on hotel sites. Bandwidth shaping so one guest can't drown a wedding floor.
Two-WAN (or three-WAN) failover that actually works. Health-check tuning, packet-loss thresholds, latency budgets. Policy routing for VoIP / payments. QoS so a backup upload doesn't crater a Friday booking spike.
Modern VPN setups. Site-to-site IPsec to head office / cloud. WireGuard for road-warrior users and developers. Documented onboarding runbook so adding a new user is a 5-minute job, not a half-day for the network engineer.
Suricata IDS/IPS deployed with curated rule sets — emerging-threats, GeoIP, abuse.ch, our own tuned policies. Logs shipped to a SIEM (Wazuh / Graylog / Elastic) so you have searchable visibility, not a black-box appliance.
Every engagement ends with a written network diagram, VLAN inventory, firewall ruleset map, VPN onboarding runbook and a backup of the pfSense config. Optional monthly retainer for ongoing changes, monitoring and quarterly tune-ups.
pfSense engagements delivered with on-site work across Ireland (typically from our Thurles office) and remote-first delivery elsewhere.
pfSense consultant Ireland — Tipperary, Cashel, Thurles, Galway, Limerick, Portlaoise and the Midlands. Hospitality, food, equestrian and SME networks.
Email [email protected] with a paragraph describing the site, the current setup (or the chaos), and the goal — or use the form on the live page. We come back within two working days with whether we're a fit and a fixed-price scoping proposal.
← Back to Intellix snapshot · Cybersecurity audit · Hospitality & hotel IT · sitemap
Generated 2026-05-16 13:18 UTC