Firewalls you can trust and change safely.

I'm a network security engineer with 10+ years on Palo Alto, FortiGate and Kemp. I design, migrate and clean up firewall estates for companies of any size, remotely from Croatia.

NameSourceDestinationAction
block-maliciousanyedl-bad-ipsdeny
vpn-to-appsvpn-mfadmz-appsallow
web-out-dnssectrustuntrustallow
default-denyanyanydeny + log
Short, named, documented. The kind of rulebase I leave behind.

What I do

Hands-on engineering on the platforms below, as a one-off project or as ongoing maintenance.

Firewall design and deployment

Palo Alto and FortiGate: policies, NAT, HA, site-to-site and remote-access VPN with two-factor authentication.

Migrations off legacy platforms

Moving you from unsupported or end-of-life firewalls to a current platform, without losing what the old config was quietly doing.

Audits and remediation

Getting drifted estates back in line: Panorama sync, rulebase clean-up, shared block lists, DNS Security, consistent standards across sites.

Load balancing and cloud

Kemp load balancers on-prem and in Azure, and Palo Alto firewalls in Azure in active/passive HA.

Selected projects

Client names are left out where I can't share them.

200+ Palo Alto firewalls back under control

Global organisation, Palo Alto and Panorama

Problem
Firewalls configured inconsistently, many out of sync with Panorama, no shared blocking of known-malicious IPs and no DNS Security in policy.
Change
Planned the standard, got security sign-off where needed, raised change requests and rolled it out device by device through ITIL change management.
Result
One consistent, centrally managed estate with shared threat blocking and DNS Security applied. Every change traceable.

Microsoft TMG replaced with FortiGate and Kemp

Public institution, FortiGate and Kemp

Problem
The perimeter ran on Microsoft TMG: obsolete and with no vendor support left.
Change
Designed and deployed FortiGate firewalls and Kemp load balancers, rebuilding the client's network along the way.
Result
A supported, current platform. The cut-over went through without issues.

Highly available Palo Alto in Azure

Food manufacturer, Palo Alto in Azure with Kemp

Problem
Workloads in Azure needed next-generation firewalling without a single point of failure.
Change
Deployed Palo Alto firewalls in an active/passive HA pair in Azure, with Kemp load balancers in front of the services.
Result
Redundant firewalling in the cloud: if the active firewall fails, the passive one takes over.

Why work with me

Four things you can check, rather than adjectives.

  • Certified on what I configure

    PCNSE for Palo Alto, NSE4 for FortiGate, Kemp, plus CCNA Routing & Switching and CCNA Security.

  • Lots of different networks behind me

    CARNET (Croatia's research and education network), SPAN and ATOS. Clients in government, municipalities, airports and food production, and numerous FortiGate and Palo Alto deployments.

  • I work inside your change process

    Plan first, security approval where it's needed, change request, deploy, document. I fit into ITIL instead of working around it.

  • You talk to the engineer

    No account managers and no hand-offs. The person who scopes the work is the person who does it.

How I work

Simple terms, agreed in writing before any work starts.

Contract
B2B, invoiced through my registered Croatian business. No employment, no agency in the middle.
Pricing
Hourly or fixed price, depending on the project.
Engagements
Projects (design, deployment, migration, remediation) or ongoing maintenance with agreed support hours.
Location
Remote, based in Croatia. Central European Time (UTC+1, UTC+2 in summer).
Languages
English and Croatian. Basic German.
First step
A short call about your environment, then a written scope and quote.

Got a firewall project, a migration or a messy rulebase?

Email me with a few lines about your setup and what needs to change.

info@teepnet.com