208 208.fi

VPN Gateway as Your Internet Facade

Our HTTPS proxy server that has been integrated with DNS and a VPN will protect your Internet facade by blocking direct connections to your existing servers.


On one hand, it is unsafe to operate a system without applying security updates. On the other hand, an update could break some customizations or tailored systems, such as a deployment of the WordPress content management system. The safety of web browsers is being constantly improved, and old services may cease to work or make various metrics scream red.

A Solid Internet Facade

Our HTTPS proxy server that has been integrated with domain name servers (DNS) and a VPN gateway will protect your Internet facade by blocking direct connections to your existing server and restricting remote maintenance access. The CSP rules that we define will do their share in countering some attacks (DDoS, XSS).

We will take care of renewing TLS certificates and operating system updates in our infrastructure. Potential attackers will only see our up-to-date proxy server and won’t be able to determine implementation details of your system, such as the address of your server or which security updates or software package versions have been installed. There will be no direct connection from the Internet to your server.

Our usage statistics and reports will help you to monitor the usage of your Internet services. They will also help you demonstrate to the authorities and stakeholders that security is being taken care of.

An IPsec based VPN Gateway

Nowadays, VPN technology is being used for circumventing geographical traffic restrictions, for example those of commercial video streaming services. We are not offering that; all outgoing traffic from the connected sites to the public Internet will be routed directly.

Conventionally, the focus is in connecting the members of the virtual private network (VPN) of an organization. In our VPN solution, the fixed sites as well any external users will connect to an IPsec gateway and identified by certificates. Our solution allows public addresses to be assigned to some of the private network hosts.

For example, the server that handles a public web site address www.example.com may be located on company premises, which means that physical access control and safety are in the own hands of the company and not at the mercy of an external supplier.

No company site will need a precious static public IP address; a cheaper Internet connection will do. Inside the VPN, company private addresses will be used. In the Internet, the company will be only visible via some IPv4 or IPv6 addresses that are associated with our proxy service. The Internet Service Provider (ISP) will observe the inter-office traffic as traffic that flows between offices and our IPsec gateway.

Inside the VPN, the name www.example.com may point directly to the actual server, with full functionality exposed. In the public Internet, the same name www.example.com may point to a HTTPS reverse proxy gateway, which will allow filtered traffic to flow to the target server. For improved security, we may prevent access to some parts of the web site, such as a WordPress or employee authentication. Thus, only a restricted subset of the services may be accessed from the public Internet.

The employees or contractors of the company will gain full access by coming over to a company office or by connecting to your private network by using their personal credentials to connect to our IPsec gateway.

Your virtual private network may also include servers that are colocated at a supplier, such as cloud servers. The only requirement is that the operating system supports our IPsec solution. Each host is analogous to a remote worker, whose home happens to be a remote server room and the connection always open.

Protecting an Individual Host Without VPN

If it is not possible to deploy our IPsec solution on a host, it is possible to route traffic from our reverse proxy server via the public Internet.

As such, this is comparable to building a new fancy house and a corridor leading to the door of an old shed. The shed may still be accessed by anyone who knows the location. Because security by obscurity is not real security, the old route must be blocked.

Block unnecessary traffic

We must block any other traffic than with the desired proxy servers. As an exception, some outgoing traffic may be enabled as necessary to facilitate operating system updates and remote backup.

The block can be implemented by modifying the network settings of the service provider or by reconfiguring the built-in firewall of the operating system. For instance, the Linux kernel supports a firewall since decades (first ipchains, then iptables and nowadays nft).

We implemented such a solution on an old Linux server where it was not possible to install a compatible version of VPN software. We allow traffic to the TCP ports 443 (HTTPS) and 22 (SSH) from the public IP addresses of our proxy servers. This will protect the service until it can be reimplemented in and transferred into a more up-to-date environment.

Ask about a VPN gateway deployment