NetDevSecurity shield logoNetDevSecurity

Firewall, NSX, network, and DNS configuration automation.

Palo Alto, FortiGate, Check Point, and Zscaler policy. VMware NSX-T. Cisco and Arista fabrics. DNS. Designed by hand, then automated so changes are reviewed, repeatable, and fast. Twenty-plus years of enterprise network security, available to your team.

Start a conversation See services

Services

Engagements range from a focused design review to a multi-month build. Every one ends with documentation your team can operate from.

Firewall engineering

Design, deployment, upgrades, and policy cleanup for Palo Alto (Panorama, GlobalProtect, User-ID, HSM), FortiGate/FortiManager, Check Point, Zscaler, and Cisco ASA.

Palo AltoFortiGateCheck PointZscaler

Firewall automation and self-service

Request and approval portals that turn firewall changes into reviewed, repeatable pushes. React and Python/FastAPI front to back, PostgreSQL, pan-os-python, CI/CD, Kubernetes.

ReactFastAPIAnsibleGitHub Actions

NSX-T automation

VMware NSX-T distributed firewall and segmentation delivered through code: policy as data, API-driven changes, Layer 3 route advertisement with BGP, and migration from perimeter-only designs.

NSX-TPythonTerraform

Network configuration automation

Cisco and Arista configuration generated, validated, and pushed with Ansible, Netmiko, and Paramiko: port security, ACLs, routing changes, and refreshes at hundreds of sites.

CiscoAristaAnsible

DNS configuration automation

Self-service DNS record requests with approval, backed by Infoblox or Bluecat APIs, so record changes stop being tickets and start being audited pushes.

InfobloxBluecatFastAPI

Policy analysis and compliance

AlgoSec Firewall Analyzer and FireFlow deployment and tuning at enterprise scale, Firemon, rule risk review, and change workflow design.

AlgoSecFiremon

Routing and data center design

BGP and OSPF design, MPLS and VPN failover, DMZ and segmentation, Cisco Nexus and Arista fabrics, disaster recovery sites, and firewall test labs that mirror production.

BGPOSPFNexusArista

Cloud and hybrid connectivity

AWS and Azure network design, VPN and routing between cloud and corporate, firewall placement, and OpenStack or VMware private infrastructure.

AWSAzureOpenStack

Identity and access integration

Migrating legacy LDAP and token schemes to OAuth2/OIDC, PingFederate, Duo multi-factor, and captive portal and User-ID integration with firewalls.

OAuth2/OIDCPingFederateDuo

How an engagement runs

No black boxes. The goal is that your team owns the result.

  1. Discovery. Read the routing tables, firewall policies, and change history before recommending anything.
  2. Design and lab. Build and test the change in a lab that matches production, including routing failover.
  3. Implement. Scheduled windows, scripted where it reduces risk, with rollback prepared in advance.
  4. Hand off. Documentation, runbooks, and automation code delivered into your repositories.
20+years in network security
2,000+firewalls managed at one enterprise
150+firewalls under policy analysis at another
3self-service firewall portals built and shipped

About

NetDevSecurity LLC (doing business as NDS Solutions) is a Texas network security consultancy founded by Michael J. Ferguson, a firewall and network automation engineer with experience at banks, airlines, financial services, retail, healthcare, and research firms, currently leading NSX-T automation and Palo Alto policy for a major bank. Certifications include Cisco CCNP, Palo Alto ACE, and AlgoSec Firewall Analyzer and FireFlow Expert.

Read the full CV at mikeferguson.us

Contact

Email is the fastest way to reach us. Expect a reply within one business day.

Email: mike@netdevsecurity.com

Location: Denton, Texas. Remote and on-site engagements across the US.