Firewall & VPN Consolidation for a Diocese in North Rhine-Westphalia

Consolidated site-to-site VPN and firewall policy for 250 locations onto Palo Alto Networks/Panorama, cutting the ruleset from ~5,000 to 850 rules with full App-ID enforcement.

✓ Ruleset cut from ~5,000 to 850 rules, fully App-ID enforced across 250 sites

References available upon request →

Approach

Brought order to a firewall estate that had grown organically over years — 250 locations, ~5,000 rules, and a legacy IP-and-port ruleset with no application awareness. The mandate: consolidate site connectivity onto a single VPN design and rebuild the policy base around App-ID rather than raw ports.

Implementation

  • Designed and rolled out a hub-and-spoke site-to-site VPN architecture connecting all 250 locations, replacing MPLS entirely
  • Rebuilt the firewall ruleset from the ground up around App-ID, retiring legacy port-based rules as applications were identified and validated
  • Tuned IPS profiles across the estate to balance detection coverage against false positives at this scale
  • Wrote custom application signatures for internal traffic that didn't match Palo Alto's App-ID library
  • Delivered the full engagement solo, as sole engineer for architecture, rollout, and rule migration

Outcome

Reduced the ruleset from ~5,000 to 850 rules — fully App-ID enforced, auditable, and materially faster to evaluate per session. The redesigned architecture passed security audit and delivered a measurable performance improvement across the estate.

Interested in working together?

Reach out and let's discuss your project.

Get in Touch