Practical Network Security
Your On-Premises IT — Securely Consolidated in a Data Center
Over 30 years of experience with secure IT infrastructure. No third-party cloud services, no compromises — your hardware, your data, your control.
Move servers, applications, and core data out of your business premises into a professionally operated data center environment. There, your IT runs on hardware you own or control — protected by redundant power, reliable cooling, and controlled physical access.
Employees and company locations access applications, files, and work environments over encrypted VPN connections — from the office, from home, or on the road. The external attack surface is kept to a minimum. Access is controlled by clearly defined firewall rules and granted only to authorized users and systems.
Suitable for companies that …
- want to consolidate local servers and standalone systems centrally
- want to move their IT out of their own business premises
- want to securely connect multiple locations
- want to give employees protected access from home
- want to remain independent of major cloud platforms
- want to keep running existing hardware and software under their own control
An XCP-ng-based hypervisor divides the physical server into several isolated virtual systems. This makes it possible to run Windows and Linux servers, file storage, communication services, and other business applications on a shared hardware platform.
A virtual pfSense firewall controls all inbound and outbound traffic. Management access and internal services are never made unnecessarily reachable from the public internet. Only explicitly authorized users and systems can communicate.
Access to the virtual company network is provided over encrypted VPN connections. Almost any standard desktop, laptop, tablet, or smartphone can be used for this.
The internal network is divided into separate security zones as needed:
- Demilitarized zone (DMZ)
For systems that need to accept controlled connections from outside, such as mail servers, internet telephony, or chat services. - Internal company network (LAN)
For Windows and Linux servers, file storage, business applications, and virtual workstations. Access can be provided via Remote Desktop, among other methods — for employees, it feels much like working on a computer in the office.
Additional separate network zones can be set up for backup, administration, telephony, or individual company locations, for example.
With classic colocation, your own hardware is securely housed in the data center. You retain technical responsibility and decide for yourself who manages the system.
On request, you can get a fully managed solution through our Managed Colocation service. Depending on your needs, this can include the following services:
- Consulting and selection of suitable hardware
- Consolidation of existing servers
- Planning and execution of the migration
- Setup of virtualization, firewall, and VPN
- Connectivity for locations and remote workstations
- Documentation and onboarding
- Installation of updates and security patches
- Monitoring and ongoing technical support
- Development of a suitable backup and recovery strategy
Existing hardware or cost-effective refurbished enterprise equipment can often still be put to good use. The solution is tailored to actual needs and available budget — without unnecessary licensing costs or dependence on a particular cloud provider.
You decide which systems are run, where your data is stored, and who can access it. The platform used is based largely on established open-source software and can be transparently documented, extended, and, if needed, migrated to a different provider.
This gives you the reliability of a professional data center environment without giving up control over your systems and data.
Let's discuss, with no obligation, which systems you'd like to consolidate or outsource.
Your Infrastructure. Your Data. Your Rules.
Every project begins and ends on hardware that you own or control — no vendor lock-in, and no data leaves your custody unless you decide otherwise.
Built on open-source, auditable software — free of licensing fees and secured through disciplined configuration, patching, and monitoring, not blind trust in the code.
No-Obligation Inquiryor write directly
[email protected] ↑ Back to top