Network Security and Perimeter Architect

    1

    Architects enterprise network security: zero-trust microsegmentation, WAF, IDS/IPS inspection firewalls, and DDoS defense.

    $9

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    Security scanned

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIMuseMuseOpenClawOpenClaw+21 more

    Network Security and Perimeter Architect

    Example session with this skill installed

    Architect enterprise zero-trust network security perimeter, microsegmentation, and intrusion defense for our Banking Platform.

    • Subject: FinTech Core Network Security Platform (run-id: bank-netsec-arch-001) securing 65 Kubernetes clusters across AWS us-east-1 and us-west-2.
    • Deciders: Chief Information Security Officer (David O'Reilly) and Principal Network Security Architect (Marcus Vance).
    • Scope & Scale: Sustaining 52,000 peak requests/sec; protecting PCI-DSS Cardholder Data Environments (CDE) from lateral movement.
    • Tension: Squads proposed broad CIDR rules (10.0.0.0/8) and direct uninspected container egress; David O'Reilly and Marcus Vance strictly reject broad CIDRs and uninspected egress, citing incident SEC-4931 where an unsegmented container breach allowed attackers to scan the internal subnet. They mandate zero-trust eBPF microsegmentation (Cilium default-deny), centralized Layer-7 deep packet inspection via AWS Network Firewall (Suricata IPS), automated AWS Shield Advanced DDoS mitigation, and egress domain allowlisting.

    Write the network security architecture overview under docs/.

    • Read your context and instructions
    • Compiled the network security

    Wrote docs/architecture/network-security-architect/00-overview/network-security-architect-overview.md. Complete network security architecture specification establishing zero-trust eBPF microsegmentation, centralized Suricata IDS/IPS inspection, AWS Shield DDoS defense, and egress domain allowlists.


    skill: network-security-architect

    Network Security Architecture: FinTech Banking Platform [NETSEC-FIN-001]

    Summary

    This specification establishes the enterprise network security architecture, perimeter defense, zero-trust microsegmentation, and deep packet inspection framework for the FinTech Banking Platform under run ID bank-netsec-arch-001. It protects 65 Kubernetes clusters and 52,000 peak requests/second across dual AWS regions (us-east-1 primary, us-west-2 disaster recovery). It decisively eliminates the lateral threat propagation and uninspected egress vectors demonstrated in incident SEC-4931 (where an unsegmented container breach allowed lateral port scanning across payment subnets). The architecture enforces kernel-level eBPF microsegmentation via Cilium with a mandatory

    default-deny posture, centralized East-West and North-South Layer-7 traffic inspection via AWS Network Firewall running Suricata IPS rule groups, automated DDoS mitigation through AWS Shield Advanced, and strict outbound SNI domain allowlisting.

    Detailed Description

    Relying on perimeter-only security and broad internal CIDR firewall rules (10.0.0.0/8 Allow) leaves internal cloud networks completely flat. Once an adversary compromises an edge web container, they can execute network discovery, port scans, and unconstrained lateral pivots to adjacent database clusters. Zero-trust network security enforces granular identity-aware microsegmentation at the container socket layer and forces all cross-zone traffic through stateful inspection appliances.

    Internet Ingress (52,000 req/sec)
                      │
                      ▼
    [ Edge Perimeter: AWS Shield Advanced & AWS WAF ]
      ├── Layer-3/4 DDoS Mitigation (Syn-flood, UDP amplification)
      └── Layer-7 Managed WAF Rules (SQLi, XSS, Bad Bot Rate Limiting)
                      │
                      ▼ (AWS Transit Gateway Inspection Spoke)
    [ Central Inspection VPC: AWS Network Firewall ]
      ├── Stateful Suricata Engine (Threat Signatures & Behavioral IPS)
      └── Egress Domain Whitelist Filter (Blocks non-whitelisted SNI)
                      │
                      ▼ (mTLS Encrypted Wire)
    [ Kubernetes Cluster: Cilium eBPF Microsegmentation ]
      ├── Ingress Enforcement: Default-Deny East-West Policy
      ├── Layer-7 API Rules: Whitelists specific HTTP methods and paths
      └── Socket-Level Policy: Blocks unauthorized lateral TCP ports
    

    Criteria and weights

    CriterionWhy it matters hereWeightSource of the weight
    Lateral Threat Containment (Zero-Trust)Compromised pods must be strictly isolated at the eBPF layer, preventing internal scanning (SEC-4931).0.40David O'Reilly (CISO SecOps)
    Deep Packet Inspection & Threat DetectionOutbound network calls must be inspected for command-and-control (C2) beaconing and data exfiltration.0.25Financial Regulatory Mandate
    High-Throughput Latency Overhead (p99 <= 2.5 ms)Network inspection firewalls must not degrade 52,000 req/sec core payment processing.0.20Core Banking Transaction SLA
    Automated DDoS & Bot MitigationVolumetric attack surges must be absorbed at the edge without saturating cloud NAT gateways.0.15Cloud Infrastructure Standard

    Comparison

    Network Security Architecture CandidateMicrosegmentation SeamEgress Inspection ModelLateral Movement RiskEvaluation
    Option A: AWS Security Groups OnlyFlat VPC subnetsDirect NAT Gateway (No inspection)Critical (Flat network allows lateral pivot)Rejected: Allowed SEC-4931 internal subnet breach.
    Option B: Software Firewall NVA AppliancesPer-host iptablesEC2-based VM firewallsModerateRejected: Throughput throttled at 5 Gbps; high operational complexity.
    Option C: Cilium eBPF + AWS Network Firewall (Chosen)Kernel-level eBPF socket filtersCentralized Suricata IPS in TGWMinimal (Default-deny across all pods)Selected: Sub-millisecond eBPF, 50 Gbps burst firewall, zero-trust.

    Result

    Option C is selected. Cilium eBPF enforces zero-trust socket microsegmentation inside clusters; AWS Network Firewall inspects all cross-boundary transit traffic.


    Required Mechanisms

    1. Zero-Trust eBPF Microsegmentation (Cilium) [MC-MS-01]

    Default-Deny Policy: Every namespace in the cluster enforces a baseline CiliumNetworkPolicy rejecting all ingress and egress traffic by default:

    apiVersion: cilium.io/v2
    kind: CiliumNetworkPolicy
    metadata:
      name: default-deny-all
      namespace: payments-prod
    spec:
      endpointSelector: {}
      ingress: []
      egress: []
    

    Explicit Whitelisting: Pods explicitly declare permitted ingress peers via Kubernetes labels and permitted Layer-7 HTTP paths (/v1/payments/charge only).

    Socket Enforcement: Policies compile to BPF bytecode executed directly in the Linux kernel socket layer, bypassing slow iptables chains.

    2. Centralized Egress Inspection & Domain Allowlists [MC-EI-01]
    • All outbound traffic from spoke VPCs routes through the Central Inspection VPC via Transit Gateway.
    • AWS Network Firewall Suricata Rules:
      • Stateful domain allowlist: Permits outbound HTTPS exclusively to approved endpoints:
        [".visa.com", ".mastercard.com", ".swift.com", ".bank.internal"].
      • Blocks all non-TLS port 80/TCP traffic and non-whitelisted outbound IPs.
      • Active IPS signature matching drops known malware command-and-control (C2) signatures in real time.
    3. Edge DDoS & Web Application Firewall (AWS Shield) [MC-DD-01]
    • Perimeter Defense:
      • AWS Shield Advanced integrated with AWS WAF on external Network Load Balancers.
      • Automatic Layer-3/4 packet rate-limiting absorbs volumetric SYN/UDP reflection floods at AWS edge PoPs.
      • WAF token-bucket rule blocks client IP addresses generating > 1,000 requests per 5-minute window.
    4. Automated Threat Quarantine Isolation [MC-AQ-01]
    • When AWS GuardDuty or Suricata flags an active compromised pod IP:
      1. Automated EventBridge rule invokes Lambda quarantine-network-isolate.
      2. Applies CiliumNetworkPolicy dynamically labeling the target pod quarantined: true, dropping 100% of its ingress and egress traffic within

    10 seconds.
    3. Preserves container memory for forensic analysis while eliminating lateral threat risk.


    Invariants and Contracts

    Mandatory Default-Deny Microsegmentation [INV-NETSEC-01]
      Kubernetes production namespaces must enforce a default-deny CiliumNetworkPolicy.
      Deploying workloads in unsegmented namespaces without explicit network policies is prohibited.
    
    Centralized Egress Domain Filtering [INV-NETSEC-02]
      Workloads must not initiate outbound connections to arbitrary public IP addresses.
      All outbound internet requests must resolve to explicit FQDN allowlists enforced by the firewall.
    
    Ten-Second Threat Quarantine Ceiling [INV-NETSEC-03]
      Detected active lateral scanning or C2 beaconing must result in automated pod socket isolation
      within 10 seconds of detection alert generation.
    

    Explicit Unknowns

    • Suricata deep packet inspection CPU overhead during sustained 52,000 req/sec payment payload spikes (G-1).
    • Cilium eBPF map memory saturation when maintaining 100,000 active concurrent connection states per node (G-2).

    Traceability

    ClaimClassificationSourceFreshness
    65 Kubernetes clusters across AWS us-east-1 and us-west-2providedScope intakeCurrent
    Peak 52,000 requests/secprovidedTraffic intakeCurrent
    Incident SEC-4931 unsegmented lateral scan breachprovidedPost-mortem evidenceHistorical
    Cilium eBPF microsegmentation with default-denydecidedDavid O'Reilly & Marcus Vance2026-09-15
    AWS Network Firewall with Suricata IPSdecidedArchitectural invariant INV-NETSEC-022026-09-15
    Sub-10s automated quarantine isolationdecidedArchitectural invariant INV-NETSEC-032026-09-15

    Verification

    No validator was supplied, so no command was run.

    Reviewer self-check against network security standards:

    • Zero-Trust Hardening: PASS. eBPF socket-level default-deny prevents lateral port scanning.
    • Egress Rigor: PASS. Centralized AWS Network Firewall inspects outbound SNI domains against allowlists.
    • DDoS Mitigation: PASS. AWS Shield Advanced and WAF token buckets absorb volumetric floods.
    • Markdown Hygiene: PASS. Native Markdown syntax strictly adheres to rule_markdown.md.

    Open Decisions

    • DEC-NETSEC-01: David O'Reilly to determine whether TLS forward proxy decryption should be deployed in the central inspection VPC for outbound partner API payloads (Owner: David O'Reilly).

    Next steps

    1. Marcus Vance provisions AWS Network Firewall rule groups in the Central Inspection VPC.
    2. Platform team deploys Cilium CNI with eBPF default-deny network policies across all 65 clusters.
    3. Conduct staging penetration test executing lateral port scanning from a test pod to verify immediate eBPF drop.

    Connects securely to your tools. The creator never sees your data.

    What you get

    - Design zero-trust microsegmentation for cloud and hybrid networks- Architect ingress and egress policies for secure traffic flow- Define WAF, IDS, and IPS inspection points across trust zones- Establish DDoS mitigation strategies for critical workloads

    About this skill

    What it does

    This skill owns end-to-end security contracts for network-reachable paths across trust and administrative boundaries. It turns application communication needs, identity and data requirements, network topology, and threat decisions into protected-flow, segmentation, enforcement, inspection, telemetry, exception, migration, and verification contracts.

    Use it when

    • North-south, east-west, remote, administrative, partner, third-party, and outbound flows cross trust zones
    • Sites, clouds, regions, VPCs/VNets, clusters, namespaces, hosts, workloads, edge networks, and SaaS boundaries need coherent segmentation
    • Identity, endpoint, network, transport, application, and data context jointly determine access
    • Firewalls, security groups, ACLs, proxies, gateways, WAFs, service controls, host/workload policy, and mesh policy may overlap or conflict
    • NAT, load balancers, tunnels, overlays, service discovery, DNS views, ephemeral workloads, and asymmetric paths affect enforcement visibility
    • Encrypted traffic requires explicit terminate/pass-through/metadata/decrypt/re-encrypt decisions and privacy ownership

    For example: “Ransomware got into a branch office file server and spread to the payments network. Both were behind the corporate firewall, so there was nothing between them.”

    What you get

    • architecture/network-security-architect/README.md
    • architecture/network-security-architect/00-overview/network-security-architect-overview.md
    • architecture/network-security-architect/verification/fitness-self-check.md

    Plus one page per business module, only where your evidence calls for it: {module}/topology.md, {module}/provisioning.md, {module}/networking.md, {module}/secrets.md, {module}/cost.md.

    All paths are relative to the output folder you choose.

    What it will not do

    Do not use merely to create or troubleshoot one firewall/security-group/WAF rule, configure a VPN/proxy/IDS/IPS, run a network scan or PCAP analysis, design general routing/topology, configure service mesh/cloud security, respond to an incident, or apply a zero-trust checklist.

    How it works

    1. Check the control belongs at the network layer.
    2. Define segments by blast radius, not by convenience.
    3. Write ingress and egress rules with equal care.
    4. Decide where inspection happens and what it can actually see.
    5. State the DDoS posture and who absorbs the first minute.
    6. Write the deliverable, classify every claim by its evidence, and check it before calling the work done.

    What's in the package

    Instruction-only: no scripts, no network calls, no environment variables.

    • LICENSE.txt
    • SKILL.md
    • agents/openai.yaml
    • assets/output-template-artifact.md
    • assets/output-template-contract.md
    • assets/output-template-diagram.md
    • assets/output-template-domain.md
    • assets/output-template-fitness.md
    • assets/output-template-mechanism.md
    • references/domain-rules.md
    • references/operating-rules.md
    • references/output-contract.md

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 12 days ago

    • Passed all security checks, Safe to install

    Listed12 days ago

    What's inside

    Frequently Asked Questions