Skip to main content

Multi-Layer Firewall Architecture & Perimeter Defense

To satisfy the stringent security, isolation, and compliance demands of government, banking, healthcare, and enterprise workloads, Okustera implements a Defense-in-Depth, Multi-Layer Firewall Architecture.

Rather than relying on a single perimeter barrier, security controls are distributed across five specialized architectural tiers spanning physical border hardware, software-defined SDN networks, application-layer ingress gateways, in-kernel container runtime sensors, and tenant-dedicated virtual firewall appliances.


🛡️ Multi-Tier Architecture Diagram​


Defense-in-Depth Summary​

TierArchitectural LayerTechnology StackCore Capabilities
Tier 1Physical Border EdgeActive-Passive Fortinet FortiGate (100F/200F/1000F)Hardware DDoS scrubbing, line-rate DPI/IPS, BGP ASN /22 transit, dynamic /32 floating IP injection, and hardware IPsec VPN.
Tier 2Software-Defined Cloud FirewallOpenStack Neutron (OVN FWaaS v2)Stateful per-vNIC distributed security groups, control plane port isolation, and automated perimeter ingress lockdown.
Tier 3Ingress Application GatewayApache APISIX + Coraza WAFOWASP Core Rule Set 4.0, real-time SQLi, XSS, and RCE blocking (HTTP 403), rate-limiting, and TLS 1.3 termination.
Tier 4In-Kernel Container RuntimeCilium eBPF CNI & Cilium TetragoneBPF in-kernel binary execution termination (SIGKILL), namespace breakout interception (setns/unshare), and DNS-aware zero-trust egress.
Tier 5Virtual Firewall AppliancespfSense-CE, OPNsense, FortiGate-VM1-Click Glance marketplace catalog, vfw.small flavor, and Transit Inspection VPC pattern with default route interception (0.0.0.0/0).

Tier 1: Physical Border Hardware Perimeter​

In multi-rack colocation and enterprise data center environments, Okustera deploys redundant active-passive Fortinet FortiGate physical appliances positioned directly between upstream ISP transit feeds and the data center Leaf-Spine switching fabric:

  1. Volumetric DDoS Mitigation & Scrubbing:
    • Fortinet NP7 and CP9 hardware network processors drop multi-gigabit SYN floods, UDP amplification reflection attacks, and fragmented packets before traffic reaches the hypervisor network interfaces.
  2. BGP Border Peering:
    • Upstream: Peers via eBGP with border transit providers, advertising the cloud's public sovereign /22 IP prefix.
    • Downstream: Peers via iBGP with spine switches, dynamically injecting tenant /32 floating IP host routes.
  3. Hardware-Accelerated IPsec Gateway:
    • Wire-speed AES-256-GCM hardware encryption connecting customer on-premises data centers to Okustera private VPCs via Direct Connect or IPsec tunnels.

Tier 2: Software-Defined Cloud Firewall (SDN Layer)​

The SDN firewall layer enforces stateful packet filtering at the hypervisor virtual NIC boundary via OpenStack Neutron and OVN distributed connection tracking (conntrack):

  • Zero Management Port Exposure: Internal management ports (Kubernetes API 6443, Kubelet 10250, etcd 2379, MariaDB 3306, PostgreSQL 5432) are strictly forbidden from binding to public 0.0.0.0/0.
  • Automated Perimeter Hardening: Declarative security group secgroup-perimeter-hardened (infrastructure/scripts/openstack_perimeter_firewall.sh) standardizes perimeter access:
    • Ingress TCP 443 (HTTPS Ingress)
    • Ingress TCP 80 (HTTP & ACME TLS Challenge)
    • Ingress TCP 2026 (Hardened SSH management)
    • Ingress ICMP Echo-Request (Ping diagnostics)
    • Default-Deny on all unapproved ingress ports.

Tier 3: Ingress Application Gateway (APISIX + Coraza WAF)​

For HTTP/HTTPS web applications and API endpoints, incoming requests pass through Apache APISIX equipped with the Coraza WAF engine and the OWASP Core Rule Set (CRS 4.0):

  • Real-Time Attack Mitigation: Deep inspection of request URIs, HTTP headers, query strings, and JSON/form payloads against:
    • SQL Injection (SQLi)
    • Cross-Site Scripting (XSS)
    • Remote Code Execution (RCE)
    • Local/Remote File Inclusion (LFI/RFI)
    • Shellshock and command injection attempts
  • Enforcement Behavior:
    • Offending payloads trigger an immediate HTTP 403 Forbidden response:
      {
      "error": "Forbidden by Okustera WAF: Request matches injection attack signature."
      }
  • Declarative APISIX GlobalRule:
    apiVersion: apisix.apache.org/v2
    kind: ApisixGlobalRule
    metadata:
    name: okustera-waf-security-shield
    namespace: apisix
    spec:
    plugins:
    - name: serverless-pre-function
    enable: true
    config:
    phase: rewrite
    functions:
    - "return function(conf, ctx) ... end"

Tier 4: Container Zero-Trust & In-Kernel eBPF Runtime Security​

Within the Kubernetes compute plane, security is enforced directly inside the Linux kernel using eBPF (Extended Berkeley Packet Filter) via Cilium CNI and Cilium Tetragon:

1. Cilium Tetragon In-Kernel Runtime Enforcement​

Tetragon monitors low-level kernel system calls (sys_execve, sys_setns, sys_openat) and executes instant kernel actions:

  • Unauthorized Binary Blocking (SIGKILL): Instantly terminates any container process attempting to execute offensive security utilities or cryptominers:
    apiVersion: cilium.io/v1alpha1
    kind: TracingPolicy
    metadata:
    name: block-malicious-binaries
    spec:
    kprobes:
    - call: "sys_execve"
    syscall: true
    selectors:
    - matchArgs:
    - index: 0
    operator: "Equal"
    values:
    - "/bin/nc"
    - "/usr/bin/nc"
    - "/bin/netcat"
    - "/bin/nmap"
    - "/bin/socat"
    - "/bin/xmrig"
    matchActions:
    - action: Sigkill
  • Privilege Escalation & Container Escape Interception: Detects and audits namespace manipulation syscalls (sys_setns, sys_unshare) attempting to cross container boundaries.
  • Sensitive File & Credential Protection: Intercepts unauthorized read/write attempts to /etc/shadow, /etc/kubernetes/admin.conf, and /var/run/docker.sock.

2. DNS-Aware Zero-Trust Egress Policies​

Kubernetes NetworkPolicies enforce outbound traffic restrictions:

  • Pods can only query local CoreDNS (kube-dns:53).
  • Outbound connections to external endpoints are restricted to standard HTTP/HTTPS (80/443).
  • Direct outbound egress to known cryptomining pool ports (3333, 4444, 5555, 6666, 8333, 14433, 14444) is strictly dropped at the eBPF layer.

Tier 5: Virtual Next-Gen Firewall (vNGFW) Marketplace Catalog & Inspection VPC​

Regulated enterprise tenants (Tier 3/4) requiring dedicated deep-packet antivirus inspection, corporate DLP, or custom VPN tunnels can deploy dedicated virtual firewalls inside their private VPCs.

Marketplace Golden Image Catalog​

Okustera maintains certified, pre-configured vNGFW golden images in OpenStack Glance:

Image NameOS DistroSpecsCapabilities
pfSense-CE-KVMFreeBSD2 vCPU, 4GB RAM, 20GB DiskNetgate pfSense Community Edition with Suricata IDS/IPS, OpenVPN, and multi-WAN routing.
OPNsense-KVMHardenedBSD2 vCPU, 4GB RAM, 20GB DiskOPNsense firewall with Zenarmor Layer 7 application control and WireGuard integration.
FortiGate-VM64-KVMFortiOS2 vCPU, 4GB RAM, 20GB DiskFortinet Next-Gen Virtual Firewall with hardware-assisted FortiOS inspection engines.

Marketplace instances use the dedicated compute flavor vfw.small (2 vCPU, 4096 MB RAM, 20 GB Disk, hardware RNG device enabled).

🌐 Live Reference Implementation: See Quickstart: Sovereign AI Security Gateway & Zero-Trust Perimeter for a production deployment combining FortiGate-VM (vfw.small) with OpenStack Octavia LBaaS, Microsoft Presidio in-line PII masking, and Model Context Protocol (MCP) at https://shield.okustera.com.


Transit Inspection VPC Architecture Pattern​

In the Inspection VPC pattern, all outbound tenant traffic is intercepted and filtered through the virtual firewall before reaching the Internet:

[ External Public WAN / Internet ]
|
[ Inspection VPC Router ]
| (198.51.100.1)
+----------------------------------+
| DMZ Subnet (198.51.100.0/24) |
+----------------------------------+
| (198.51.100.254)
[ eth0: Public / WAN ]
+------------------------+
| vNGFW Virtual Firewall |
| (pfSense / FortiGate) |
+------------------------+
[ eth1: Transit / LAN ]
| (198.51.101.254)
+----------------------------------+
| Tenant Transit (198.51.101.0/24) |
+----------------------------------+
|
Static Route: 0.0.0.0/0 -> Next-Hop 198.51.101.254
|
[ Tenant Workload Instances ]

Declarative Terraform Recipe​

Tenants can provision this entire architecture using standard Terraform:

# 1. Inspection VPC Router
resource "openstack_networking_router_v2" "inspection_router" {
name = "inspection-vpc-router"
admin_state_up = true
external_network_id = data.openstack_networking_network_v2.external.id
}

# 2. DMZ & Transit Subnets
resource "openstack_networking_subnet_v2" "dmz_subnet" {
name = "inspection-dmz-subnet"
network_id = openstack_networking_network_v2.dmz_net.id
cidr = "198.51.100.0/24"
}

resource "openstack_networking_subnet_v2" "transit_subnet" {
name = "tenant-transit-subnet"
network_id = openstack_networking_network_v2.transit_net.id
cidr = "198.51.101.0/24"
}

# 3. Intercept 0.0.0.0/0 egress via vFW LAN IP
resource "openstack_networking_subnet_route_v2" "transit_default_route" {
subnet_id = openstack_networking_subnet_v2.transit_subnet.id
destination_cidr = "0.0.0.0/0"
next_hop = "198.51.101.254"
}

# 4. Dual-NIC Ports with Forwarding Allowed
resource "openstack_networking_port_v2" "vfw_transit_port" {
name = "vfw-transit-port"
network_id = openstack_networking_network_v2.transit_net.id
fixed_ip {
subnet_id = openstack_networking_subnet_v2.transit_subnet.id
ip_address = "198.51.101.254"
}
allowed_address_pairs {
ip_address = "0.0.0.0/0"
}
}

# 5. vFW Compute Appliance
resource "openstack_compute_instance_v2" "vfw_appliance" {
name = "omc-vfw-appliance-01"
image_id = data.openstack_images_image_v2.vfw_image.id
flavor_id = data.openstack_compute_flavor_v2.vfw_flavor.id

network { port = openstack_networking_port_v2.vfw_dmz_port.id }
network { port = openstack_networking_port_v2.vfw_transit_port.id }
}

Operational Verification Runbook​

1. Verify WAF SQL Injection Blocking (Tier 3)​

# Test benign request (should return HTTP 200)
curl -k -s -o /dev/null -w "HTTP %{http_code}\n" https://demo.okustera.com/

# Test SQLi payload (must return HTTP 403 Forbidden)
curl -k -s -o /dev/null -w "HTTP %{http_code}\n" "https://demo.okustera.com/?q=%27%20OR%201=1--"

2. Verify Tetragon Kernel SIGKILL Enforcement (Tier 4)​

# Attempt to execute netcat inside a test container
kubectl run sec-test --rm -i --restart=Never --image=busybox -- nc -h

# Expected output:
# pod default/sec-test terminated (Error)
# Kernel eBPF sensor intercepts sys_execve and dispatches SIGKILL

3. Verify OpenStack Perimeter Firewall & Ports (Tier 2)​

# Run automated security group audit and reconciliation
bash infrastructure/scripts/openstack_perimeter_firewall.sh