Multi-Layer Firewall Architecture & Perimeter Defense
To satisfy the stringent security, isolation, and compliance demands of government, banking, healthcare, and enterprise workloads, Okustera implements a Defense-in-Depth, Multi-Layer Firewall Architecture.
Rather than relying on a single perimeter barrier, security controls are distributed across five specialized architectural tiers spanning physical border hardware, software-defined SDN networks, application-layer ingress gateways, in-kernel container runtime sensors, and tenant-dedicated virtual firewall appliances.
🛡️ Multi-Tier Architecture Diagram
Defense-in-Depth Summary
| Tier | Architectural Layer | Technology Stack | Core Capabilities |
|---|---|---|---|
| Tier 1 | Physical Border Edge | Active-Passive Fortinet FortiGate (100F/200F/1000F) | Hardware DDoS scrubbing, line-rate DPI/IPS, BGP ASN /22 transit, dynamic /32 floating IP injection, and hardware IPsec VPN. |
| Tier 2 | Software-Defined Cloud Firewall | OpenStack Neutron (OVN FWaaS v2) | Stateful per-vNIC distributed security groups, control plane port isolation, and automated perimeter ingress lockdown. |
| Tier 3 | Ingress Application Gateway | Apache APISIX + Coraza WAF | OWASP Core Rule Set 4.0, real-time SQLi, XSS, and RCE blocking (HTTP 403), rate-limiting, and TLS 1.3 termination. |
| Tier 4 | In-Kernel Container Runtime | Cilium eBPF CNI & Cilium Tetragon | eBPF in-kernel binary execution termination (SIGKILL), namespace breakout interception (setns/unshare), and DNS-aware zero-trust egress. |
| Tier 5 | Virtual Firewall Appliances | pfSense-CE, OPNsense, FortiGate-VM | 1-Click Glance marketplace catalog, vfw.small flavor, and Transit Inspection VPC pattern with default route interception (0.0.0.0/0). |
Tier 1: Physical Border Hardware Perimeter
In multi-rack colocation and enterprise data center environments, Okustera deploys redundant active-passive Fortinet FortiGate physical appliances positioned directly between upstream ISP transit feeds and the data center Leaf-Spine switching fabric:
- Volumetric DDoS Mitigation & Scrubbing:
- Fortinet NP7 and CP9 hardware network processors drop multi-gigabit SYN floods, UDP amplification reflection attacks, and fragmented packets before traffic reaches the hypervisor network interfaces.
- BGP Border Peering:
- Upstream: Peers via eBGP with border transit providers, advertising the cloud's public sovereign
/22IP prefix. - Downstream: Peers via iBGP with spine switches, dynamically injecting tenant
/32floating IP host routes.
- Upstream: Peers via eBGP with border transit providers, advertising the cloud's public sovereign
- Hardware-Accelerated IPsec Gateway:
- Wire-speed AES-256-GCM hardware encryption connecting customer on-premises data centers to Okustera private VPCs via Direct Connect or IPsec tunnels.
Tier 2: Software-Defined Cloud Firewall (SDN Layer)
The SDN firewall layer enforces stateful packet filtering at the hypervisor virtual NIC boundary via OpenStack Neutron and OVN distributed connection tracking (conntrack):
- Zero Management Port Exposure: Internal management ports (Kubernetes API
6443, Kubelet10250, etcd2379, MariaDB3306, PostgreSQL5432) are strictly forbidden from binding to public0.0.0.0/0. - Automated Perimeter Hardening: Declarative security group
secgroup-perimeter-hardened(infrastructure/scripts/openstack_perimeter_firewall.sh) standardizes perimeter access:- Ingress TCP 443 (HTTPS Ingress)
- Ingress TCP 80 (HTTP & ACME TLS Challenge)
- Ingress TCP 2026 (Hardened SSH management)
- Ingress ICMP Echo-Request (Ping diagnostics)
- Default-Deny on all unapproved ingress ports.
Tier 3: Ingress Application Gateway (APISIX + Coraza WAF)
For HTTP/HTTPS web applications and API endpoints, incoming requests pass through Apache APISIX equipped with the Coraza WAF engine and the OWASP Core Rule Set (CRS 4.0):
- Real-Time Attack Mitigation: Deep inspection of request URIs, HTTP headers, query strings, and JSON/form payloads against:
- SQL Injection (SQLi)
- Cross-Site Scripting (XSS)
- Remote Code Execution (RCE)
- Local/Remote File Inclusion (LFI/RFI)
- Shellshock and command injection attempts
- Enforcement Behavior:
- Offending payloads trigger an immediate HTTP 403 Forbidden response:
{"error": "Forbidden by Okustera WAF: Request matches injection attack signature."}
- Offending payloads trigger an immediate HTTP 403 Forbidden response:
- Declarative APISIX GlobalRule:
apiVersion: apisix.apache.org/v2kind: ApisixGlobalRulemetadata:name: okustera-waf-security-shieldnamespace: apisixspec:plugins:- name: serverless-pre-functionenable: trueconfig:phase: rewritefunctions:- "return function(conf, ctx) ... end"
Tier 4: Container Zero-Trust & In-Kernel eBPF Runtime Security
Within the Kubernetes compute plane, security is enforced directly inside the Linux kernel using eBPF (Extended Berkeley Packet Filter) via Cilium CNI and Cilium Tetragon:
1. Cilium Tetragon In-Kernel Runtime Enforcement
Tetragon monitors low-level kernel system calls (sys_execve, sys_setns, sys_openat) and executes instant kernel actions:
- Unauthorized Binary Blocking (
SIGKILL): Instantly terminates any container process attempting to execute offensive security utilities or cryptominers:apiVersion: cilium.io/v1alpha1kind: TracingPolicymetadata:name: block-malicious-binariesspec:kprobes:- call: "sys_execve"syscall: trueselectors:- matchArgs:- index: 0operator: "Equal"values:- "/bin/nc"- "/usr/bin/nc"- "/bin/netcat"- "/bin/nmap"- "/bin/socat"- "/bin/xmrig"matchActions:- action: Sigkill - Privilege Escalation & Container Escape Interception:
Detects and audits namespace manipulation syscalls (
sys_setns,sys_unshare) attempting to cross container boundaries. - Sensitive File & Credential Protection:
Intercepts unauthorized read/write attempts to
/etc/shadow,/etc/kubernetes/admin.conf, and/var/run/docker.sock.
2. DNS-Aware Zero-Trust Egress Policies
Kubernetes NetworkPolicies enforce outbound traffic restrictions:
- Pods can only query local CoreDNS (
kube-dns:53). - Outbound connections to external endpoints are restricted to standard HTTP/HTTPS (
80/443). - Direct outbound egress to known cryptomining pool ports (
3333,4444,5555,6666,8333,14433,14444) is strictly dropped at the eBPF layer.
Tier 5: Virtual Next-Gen Firewall (vNGFW) Marketplace Catalog & Inspection VPC
Regulated enterprise tenants (Tier 3/4) requiring dedicated deep-packet antivirus inspection, corporate DLP, or custom VPN tunnels can deploy dedicated virtual firewalls inside their private VPCs.
Marketplace Golden Image Catalog
Okustera maintains certified, pre-configured vNGFW golden images in OpenStack Glance:
| Image Name | OS Distro | Specs | Capabilities |
|---|---|---|---|
pfSense-CE-KVM | FreeBSD | 2 vCPU, 4GB RAM, 20GB Disk | Netgate pfSense Community Edition with Suricata IDS/IPS, OpenVPN, and multi-WAN routing. |
OPNsense-KVM | HardenedBSD | 2 vCPU, 4GB RAM, 20GB Disk | OPNsense firewall with Zenarmor Layer 7 application control and WireGuard integration. |
FortiGate-VM64-KVM | FortiOS | 2 vCPU, 4GB RAM, 20GB Disk | Fortinet Next-Gen Virtual Firewall with hardware-assisted FortiOS inspection engines. |
Marketplace instances use the dedicated compute flavor vfw.small (2 vCPU, 4096 MB RAM, 20 GB Disk, hardware RNG device enabled).
🌐 Live Reference Implementation: See Quickstart: Sovereign AI Security Gateway & Zero-Trust Perimeter for a production deployment combining FortiGate-VM (
vfw.small) with OpenStack Octavia LBaaS, Microsoft Presidio in-line PII masking, and Model Context Protocol (MCP) at https://shield.okustera.com.
Transit Inspection VPC Architecture Pattern
In the Inspection VPC pattern, all outbound tenant traffic is intercepted and filtered through the virtual firewall before reaching the Internet:
[ External Public WAN / Internet ]
|
[ Inspection VPC Router ]
| (198.51.100.1)
+----------------------------------+
| DMZ Subnet (198.51.100.0/24) |
+----------------------------------+
| (198.51.100.254)
[ eth0: Public / WAN ]
+------------------------+
| vNGFW Virtual Firewall |
| (pfSense / FortiGate) |
+------------------------+
[ eth1: Transit / LAN ]
| (198.51.101.254)
+----------------------------------+
| Tenant Transit (198.51.101.0/24) |
+----------------------------------+
|
Static Route: 0.0.0.0/0 -> Next-Hop 198.51.101.254
|
[ Tenant Workload Instances ]
Declarative Terraform Recipe
Tenants can provision this entire architecture using standard Terraform:
# 1. Inspection VPC Router
resource "openstack_networking_router_v2" "inspection_router" {
name = "inspection-vpc-router"
admin_state_up = true
external_network_id = data.openstack_networking_network_v2.external.id
}
# 2. DMZ & Transit Subnets
resource "openstack_networking_subnet_v2" "dmz_subnet" {
name = "inspection-dmz-subnet"
network_id = openstack_networking_network_v2.dmz_net.id
cidr = "198.51.100.0/24"
}
resource "openstack_networking_subnet_v2" "transit_subnet" {
name = "tenant-transit-subnet"
network_id = openstack_networking_network_v2.transit_net.id
cidr = "198.51.101.0/24"
}
# 3. Intercept 0.0.0.0/0 egress via vFW LAN IP
resource "openstack_networking_subnet_route_v2" "transit_default_route" {
subnet_id = openstack_networking_subnet_v2.transit_subnet.id
destination_cidr = "0.0.0.0/0"
next_hop = "198.51.101.254"
}
# 4. Dual-NIC Ports with Forwarding Allowed
resource "openstack_networking_port_v2" "vfw_transit_port" {
name = "vfw-transit-port"
network_id = openstack_networking_network_v2.transit_net.id
fixed_ip {
subnet_id = openstack_networking_subnet_v2.transit_subnet.id
ip_address = "198.51.101.254"
}
allowed_address_pairs {
ip_address = "0.0.0.0/0"
}
}
# 5. vFW Compute Appliance
resource "openstack_compute_instance_v2" "vfw_appliance" {
name = "omc-vfw-appliance-01"
image_id = data.openstack_images_image_v2.vfw_image.id
flavor_id = data.openstack_compute_flavor_v2.vfw_flavor.id
network { port = openstack_networking_port_v2.vfw_dmz_port.id }
network { port = openstack_networking_port_v2.vfw_transit_port.id }
}
Operational Verification Runbook
1. Verify WAF SQL Injection Blocking (Tier 3)
# Test benign request (should return HTTP 200)
curl -k -s -o /dev/null -w "HTTP %{http_code}\n" https://demo.okustera.com/
# Test SQLi payload (must return HTTP 403 Forbidden)
curl -k -s -o /dev/null -w "HTTP %{http_code}\n" "https://demo.okustera.com/?q=%27%20OR%201=1--"
2. Verify Tetragon Kernel SIGKILL Enforcement (Tier 4)
# Attempt to execute netcat inside a test container
kubectl run sec-test --rm -i --restart=Never --image=busybox -- nc -h
# Expected output:
# pod default/sec-test terminated (Error)
# Kernel eBPF sensor intercepts sys_execve and dispatches SIGKILL
3. Verify OpenStack Perimeter Firewall & Ports (Tier 2)
# Run automated security group audit and reconciliation
bash infrastructure/scripts/openstack_perimeter_firewall.sh
Related Security Documentation
- Infrastructure Credentials & Password Hardening: Runbooks for credential rotation and eliminating default passwords.
- Identity & Access Management (Keystone): Multi-tenant RBAC and Kubernetes Pod Workload Identity.
- Sovereign Compliance & Data Governance: Mapping to ISO 27001, NIS2, and GDPR sovereign data residency.