Secure networks and verified access for your business

Perimetra is an independent networking and cybersecurity service in Barcelona, for small businesses and IT teams that need a specialist without hiring full time.

  • 15+ years in networking and security
  • Multi-vendor networking, security and cloud
  • CCNP, CCNA, CCDA, Extreme, Fortinet NSE certifications

Cloud RADIUS with MFA

A single authentication point for your VPN, corporate Wi-Fi and access to your network devices, with a second factor and no server to build or maintain in your office.

In many small businesses the VPN asks only for a username and password, the firewall is managed with a shared account, and the Wi-Fi has had the same key for years. With a central RADIUS, each person signs in with their own identity, and what they do is logged.

What it covers

  • Remote-access VPN with a second factor, on any device that has a RADIUS client.
  • Corporate Wi-Fi with 802.1X: each user signs in with their own credentials or a certificate, not a shared key.
  • Administrative access to firewalls, switches and access points with a named user.
  • Integration with your directory: Microsoft Entra ID, Active Directory or Google Workspace.

How it gets started

  1. Inventory of devices, users and directory.
  2. Cloud service setup and an encrypted connection to your devices (RadSec or IPsec tunnel).
  3. Pilot with a small group of users.
  4. Full rollout and handover of documentation.

The service includes authentication logging and a fallback mode agreed before it goes live, for example an emergency local account on each device.

User or administrator VPN, 802.1X Wi-Fi or device access Your company's network device Firewall, switch or access point RadSec or IPsec Cloud RADIUS Policies and authentication logs Second factor TOTP app or push Directory Entra ID, AD or Google

Services

Projects with a start and an end, or ongoing support. Every job ends with documentation your team can use without depending on anyone.

Firewall audits

Review of rules, objects, VPNs, security profiles, versions and logs on Fortinet, Palo Alto, Cisco and Check Point. It looks for rules nobody uses any more, access that is too broad, and settings that were left at their defaults.

Deliverable: a report with findings ranked by risk and a remediation plan.

Network design and migration

VLAN segmentation, routing, Wi-Fi, and changes of vendor or carrier. Every change is prepared with an agreed window and a rollback plan.

Deliverable: design, change plan and go-live.

SD-WAN and SASE

Site-to-site and remote connectivity with SD-WAN, and secure access to applications and the internet from anywhere with SASE. It starts from what you already have before any new product is proposed.

Deliverable: proposed architecture, pilot and phased rollout.

Azure security

Azure Firewall in production: hub-and-spoke topology, user-defined routes (UDR), DNAT rules, and access control with Entra ID and RBAC.

Deliverable: design, configuration and documentation of the environment.

Network documentation

Diagrams, device inventory, rule matrix and procedures. Useful for an audit, for handing over to a new provider, or so the network does not depend on one person's memory.

Deliverable: documentation in editable formats.

Support and incidents

Diagnosis of outages, slowness and VPN drops, and extra hands for IT teams that are stretched thin. One-off or recurring.

Deliverable: root cause identified, fix applied and a note of what was changed.

Experience

More than 15 years with multi-vendor networking and security, at carriers, software companies and managed service providers, with projects in several countries.

In practice, that means you will usually find a device you already know, or one very much like it. Typical work includes:

  • Redesign of a carrier's BGP edge and a data centre migration.
  • Full Fortinet deployments, and high-availability Wi-Fi with Extreme XIQ.
  • Monitoring platforms, PowerShell automation, and access with RADIUS and MFA.
Security and firewalls
Fortinet (FortiGate, FortiManager, FortiAnalyzer, FortiNAC, FortiSASE, FortiWeb), Palo Alto and Panorama, Check Point, Cisco ASA and Firepower, SonicWall, Sophos, WatchGuard, Netskope
Networking and Wi-Fi
Cisco, Juniper, Extreme (XIQ), Aruba, HPE, Meraki, Huawei, Alcatel-Lucent and Arista
Routing and switching
OSPF, BGP, MPLS, VPLS, VXLAN, SD-WAN, QoS, IPv6, VRRP, MCLAG and Wi-Fi 6/7
Identity and cloud
RADIUS, MFA, 802.1X, Entra ID (SAML), RBAC, Azure, AWS, Microsoft 365 and Teams
Monitoring and automation
PRTG, Dynatrace, PowerShell, Python, Bash and REST APIs
Certifications
Cisco CCNP, CCNA and CCDA. Extreme Switching Expert and XIQ. Fortinet NSE 4 and NSE 7. PRTG Monitoring Expert.
Where I work
Barcelona, remote or on site

How we work

  1. Initial conversation

    We go over what you have, what is failing and what you want to achieve.

  2. Written proposal

    Scope, timeline and a fixed price agreed before starting.

  3. Execution

    Changes with an agreed window and a rollback plan. Named, temporary access.

  4. Documentation and handover

    Diagrams, configurations and procedures delivered at the end.

Frequently asked questions

Which vendors do you work with?

Cisco, Fortinet, Palo Alto, Check Point, Juniper, Extreme, Aruba, Meraki, Huawei, SonicWall, WatchGuard and others, plus Azure Firewall. If you use another brand, it gets assessed before anything is committed.

How much does it cost?

It depends on the scope. The proposal includes a fixed price before work begins, so there are no surprises along the way.

Is the work remote or on site?

Almost everything is done remotely. If an intervention needs someone in Barcelona, it is agreed in the proposal.

What happens to my access and credentials?

Access is agreed in writing, named accounts are used, and everything is revoked when the work ends.

What happens to RADIUS if the internet connection fails?

Before the service goes live, a fallback mode is defined with each client, usually an emergency local account on critical devices.

What do I need to get started with RADIUS?

Know which devices you want to protect, which directory you use and who connects. With that, a small pilot can be prepared.

Tell me about your case

A few lines are enough: what equipment you use, what problem you have and when you need it.

You can also write directly to contacto.perimetra@protonmail.com.

The button opens your email app with the message ready to send. This website stores nothing, uses no cookies and loads no third-party resources.