Firewall Service

CDSEC Green Wall


Our firewall services are based on CDSEC's own security appliance, the Green Wall. The Green Wall runs OPNSense Business Edition and is offered as either managed service or software as a service (SaaS). It is combined with a centralized log management solution based on GrayLogs log management solution and is hosted either in CDSEC's Azure Cloud or the Customers' own Azure environment. The appliance is part of the SaaS or MSP offering and can be connected to an internal WiFi Router or the customer's local network. The Firewall software is pre-configured and will be customized to customer needs and their environment.

The following features are implemented and configured:

  • OPNSense state-of-the-art firewall software
  • IDS/IPS based on Suricata
  • Web and Application Control using Zenarmor Application layer firewall
  • Available as Small Business Edition or Business Edition
  • VPN Configuration options using integrated IPSEC (Gateway-Gateway) or Open VPN (Client based)
  • Client-based VPN with 2-factor authentication pre-configured to provide remote configuration support
  • Dynamic DNS using one of the integrated DynDNS providers (e.g. DuckDNS)

The firewall hardware comes with the following specifications:

  • Model: GreenWall Model S
  • Material: High-quality all aluminum, Surface anodic oxidation
  • Processor: Onboard Intel Core i5 8250U (quad core 8 threads, 1.6GHz, Max. Turbo 3.4GHz, 6MB Cache)
  • RAM: 8GB
  • Display Port: HDMI
  • Front: 4x USB3.0 ports, Power Switch, RJ45 COM(Support Console), HDMI port
  • Back: 6x Gibabit LAN ports
  • Storage: 128GB MSATA SSD
  • Input Voltage: 12V
  • Dimensions: 186mm x 126.5mm x 66mm
  • Weight: 1.3kg
  • Other Functions: Auto power on when there is electricity, Timing boot, Wake on LAN, PXE boot, Watchdog(0~255 level)

SOC / Log Analytics and Reporting


Our CDSEC Green Wall will send their log data and alerts to our centralized SIEM environment. For this, we host a Graylog server and send all the logs, secured with TLS encryption.

siem-services