Astaro Experts in Germany
in minutes from over 15,000 CVs with vetted, available specialistsHire experts who handle Astaro Security Gateway setup, VPN access, web filtering, mail protection, and firewall policy tuning. Get fast, precise matching with vetted, available freelancers.
Meet FRATCH Experts in Germany, who have recently used Astaro
Christian Enderle
Last position:
IT Consulting / IT Rebuild at IT-Neuaufbau (PF)
- Analysis of requirements and the current situation
- Migration of an old domain structure and Tobit to Exchange 2019 with integration to MS365
- Evaluation of implementation paths and planning for securing sensitive data
- Planning regarding BSI basic protection, the German Federal Data Protection Act (BDSG), and GDPR
- IT governance and IT security backtests
- Support with ERP setup and securing mail transfer
- Hyper-V 2016/2022, Microsoft Terminal Services Cluster, Microsoft Exchange 2019
- Office 365, Microsoft 365, Azure AD, Teams, Salesforce
- Cisco, Zyxel, and HP switches, Sophos firewalls/UTMs, SecurePoint
- Microsoft IIS 2022, IPv4/IPv6, Veeam, Wortmann online backup, NextCloud
- Services: DNS, DHCP, TCP/IP, subnetting, firewalling, routing, VoIP, Group Policy (GPO), SIEM, remote work, home office, high availability, failover, VLAN, PRTG
Florian Krebs
Last position:
LAN Planner at Global Network AG
- As-is assessment of the current network infrastructure and its documentation, including on-site inspections
- Independent planning of new distribution and main distribution rooms in the individual district offices (components used, rack layout, connectivity), considering the BSI IT-Grundschutz and InfoSic requirements
- Planning of new copper and fiber optic cabling, including patch panels
- Coordination with building services engineering (TGA) to ensure compliance with relevant on-site requirements
- Development of detailed execution plans and high-level concepts for the rollout of the new infrastructure
- Additional support after the components go live (hypercare phase)
- Regular communication with project management and client stakeholders
Andreas Fischer
Last position:
Project Manager & Portfolio Owner for Infrastructure (Automotive) at MHP Management- und IT-Beratung GmbH
- Overall coordination of service providers for all infrastructure topics at a production site being set up in Baden-Württemberg
- Design and finding solutions for internet connectivity, building office communication networks, setting up WLAN in production and administration buildings, IP address management, password policies, time tracking, access control systems, backup strategies, emergency power planning, operating concepts, cost planning, event management, workplace setup including laptop/mobile phones/telephony, remote support, print servers
- Selecting suitable external service providers and planning to meet needs for spare parts, repairs, on-site service, network and workplace support including on-site system replacement by providers
- Choosing suitable external service providers for facility management and building technology (fiber optic connections, data center infrastructure, cable ducts etc.)
- Coordination with clients and service providers
- Escalation management, schedule control
- On-site presence for service meetings and managing service providers
David Bleyer
Last position:
Acting Partner at Bliestal Consulting UG
- Redesigning cablewise infrastructure with CAT 8.1 keystones, measuring the speed and quality of the new installation with Pockethernet, documentation at a local saddlery
- CAT 8.1 installation and building a data center, site linking, VPN and VLAN configuration for a local car dealership, implementation of IT-Security standards like virus protection (G Data) and firewalling (OPNSense)
- Relocation of a tax office with redesign of the IT infrastructure, virus protection (G Data) and backup solutions (QNAP)
- Planning, conception and implementation of an inhouse data center, BSI-compliant for commercial laundry (including Proxmox-based virtualization of existing infrastructures, QNAP, G Data, OPNSense, APC)
- Implementation and conception of security solutions in the SME sector
- Collaboration on the IT-security concept for the Bremen network of authorities (in the dLAN network)
- Creation of IT-security concept VOIS (modules MESO, KFZ/iKFZ) including audit preparation for KBA
- Expansion of the IT-security concept for the online service for electronic residence registration (eWA) to include use as an eFA (one-for-all) service (nationwide)
- Expansion of the IT-security concept to include modules wos & wvp
- Concept development for the implementation of DIN SPEC 27076 at MSEs and SMEs
- Creation and evaluation of emergency concepts
- Creation and evaluation of response actions and BCM plans
- Assessment of existing business continuity management (ISO 22301)
- Development of BCM strategy options
- Conducting awareness training
Andreas Zimmermann
Last position:
ITSM Consultant at Industrial company / Global IT division
- Designed and implemented a new user support tower organization as part of the global IT transformation initiative.
- Created an operating and control model for the central service desk, including downstream support units (field service, VIP support, service points).
- Performed a comprehensive as-is analysis of existing service desk and field service structures and developed a target architecture based on ITIL 4 and SIAM.
- Defined roles, responsibilities, and governance mechanisms for internal IT and external providers.
- Prepared the blueprint document Service Management & Governance Handbook (User Support) to standardize global service processes (incident, request, problem, change, knowledge, ITSCM, CSI).
- Developed a KPI and SLA framework to measure service quality and performance in global user support.
- Defined the reporting and review structure (operations meeting, service review meeting, management steering board).
- Prepared RFP documents for the external tendering of L1/L2 support services, including definition of scope, governance model, process requirements, tool integration (ServiceNow), and KPI/SLA sets.
- Supported procurement and legal departments in evaluating and negotiating vendor proposals and assisted in vendor selection and contract finalization.
- Oversaw the handover to operational support, including knowledge transfer, training of provider teams, and establishment of a continuous improvement process (CSI).
- Methods / framework / tools: ITIL 4 / ITSM, SIAM, IT4IT, ServiceNow, Jira, BPMN, operating model canvas, KPI & SLA design, governance & performance management
Christian Decker
Last position:
Managing Director and Senior Consultant at business-security (b-sec®) GmbH
- Conceptual consulting for securing business processes
- Consulting on planning and implementation of IT and IT security projects
- Security and policy checks, process optimizations, emergency planning
- Project management and interim management in IT infrastructure and information security
Overview of relevant projects:
- 2025: Consulting on a DLP concept for Digid GmbH.
- 2025: Consulting a client after a cybersecurity attack that compromised the IT infrastructure and where the attacker obtained M365 tenant admin rights. Investigated the IT infrastructure and restored it. Developed recommendations to improve IT security.
- 2025: Continued the projects listed below for Thyssenkrupp Marine Systems and Norddeutsche Landesbank.
- 2024: Created a DNS concept including advice on DNS strategy and technology, DNS design, DNS security, load balancing, reverse lookup zones, and automation. Created a DHCP concept including advice on DHCP design, a central DHCP management system and automation. Advised on operating the mentioned products, the operational processes, and updated IT documentation and IT service descriptions for Thyssenkrupp Marine Systems.
- 2024: As-is analysis and assessment of the network and security infrastructure established by providers in terms of overall architecture including design and components. Designed solution proposals to improve current operations for performance and security maximization as well as complexity reduction. Presented the results to C-level, their causes and possible solutions including required decision templates. Developed a SASE concept based on a zero-trust architecture for Norddeutsche Landesbank.
- 2024: Continued the projects listed below for Atlas GmbH and Deutsche Vermögensberatung AG.
- 2023: Consulting on resolving findings from an IT security assessment of the IT infrastructure, conducting proofs of concept for DDoS protection and digital experience monitoring (DEM) with Zscaler (ZIA, ZPA & ZDX), creating a new security architecture based on zero trust, redesigning a Cisco ISE implementation, and designing a DNS security solution to protect guests and financial advisors for Atlas GmbH / Deutsche Vermögensberatung AG.
- 2023: Continued the projects listed below for Digid GmbH, Vaillant Group GmbH (until 09/2023), Federal Institute for Geosciences and Natural Resources (until 05/2023), and Union Investment IT-Services GmbH (until 07/2023).
- 2022: Created and reviewed whitepapers for infrastructure and security architectures, and planned new network infrastructures for the German Aerospace Center.
- 2022: Developed a concept for the technical and procedural modernization of a disaster recovery plan for United Nations Volunteers.
- 2022: Developed a concept for migrating measurement data to a cloud environment, introduced network access control, and conducted an awareness training for Digid GmbH.
- 2022: Developed a network segmentation concept for DZ Hyp AG.
- 2022: Developed a network segmentation concept for the Federal Employment Agency.
- 2021: Developed a new load balancer architecture concept for Bundeswehr Fuhrparkservices GmbH.
- 2021: Conducted a vulnerability scan and penetration test of a web frontend including analysis and recommendations for remediation considering risk and likelihood for the client ifi GmbH.
- 2021: Consulting, design, and subproject management for implementing a network access control solution (certificate authentication and MAC address bypass) and macro segmentation (area and zone concept based on dynamic device assignment) in office and production IT for Vaillant Group GmbH.
- 2021: Upgraded and optimized LAN and WLAN infrastructure for United Nations Volunteers.
- 2021: Developed a target concept for modernizing the IT security infrastructure including the DMZ (Cisco switches, firewalls, WSA, ESA, SMA), internet connections, admin and management networks, and the wireless LAN, including overseeing implementation for the Federal Institute for Geosciences and Natural Resources.
- 2021: Created a micro-segmentation concept based on Cisco DNA, SGT, and zero trust for Union Investment IT-Services GmbH.
- 2021: Reviewed and updated ISMS level 3 policies and created procedure instructions for Software AG.
- 2021: Project lead for the global tech refresh project Meraki WLAN 2.0, coordinated the outsourcing of LAN/WLAN infrastructure to a managed service provider, and created a WLAN concept for automated guided vehicles for Heraeus Infosystems GmbH.
- 2021: Project management and technical support for the 'Transition of SIEM/SOC Services' project migrating a client to a shared environment, and took on the interim role of Head of Security Operations at Datagroup SE.
- 2021: Conducted a workshop for the future implementation of mobile device management for Allgeier Experts Go GmbH.
- 2021: Subproject management for implementing a firewall rule management tool and recertifying NAC endpoints based on 802.1x and MAB for Union Investment IT-Services GmbH.
- 2020: Developed a network segmentation concept for two data centers based on Cisco and VMware for Aareon AG.
- Recorded and analyzed the current network architecture including project initiation.
- Designed a micro-segmentation concept in the data center and access network.
- 2020: Infrastructure and security architecture audit for Stuttgarter Versicherung AG.
- Analyzed the IT infrastructure and security architecture regarding network and security component configurations. Also reviewed contracts, process documents, and manuals for completeness. Developed recommendations to improve the stability and operation of the infrastructure. Created a network segmentation concept and led the project to implement the measures from the audit.
- 2020: Consulting on setting up an ISMS-light for Josera foodforplanet GmbH & Co. KG.
- 2020: Security architecture consulting for Datagroup SE.
- Developed a future IT infrastructure and IT security architecture.
- Documented the current IT architecture of all 23 entities.
- Made recommendations to optimize the IT infrastructure and drafted a comparison of a traditional perimeter security concept versus a zero trust model.
- Created a security zone concept.
- Designed an IT infrastructure architecture in coordination with all entities.
- 2018 - 2019: Stream lead in the cybersecurity program at Deutsche Lufthansa AG.
- Responsible for designing and implementing 9 projects in IT security infrastructure and user access management, as well as managing project managers and experts.
- Project area: Network segmentation and access control.
- Project area: Security architecture.
- Project area: Privileged, identity & access management.
- Project area: Simplify user authentication (MFA).
- Project area: Mobile & endpoint security.
- Project area: OT security.
- Project area: E-enabled aircraft.
- 2018: Security architecture consulting for Deutsche Lufthansa AG.
- Project management for the development, evaluation, and management of the company-wide information security architecture.
- Developed a security strategy and a roadmap to align the security architecture with the zero trust model.
- Evaluated market security solutions, services, and tools.
- Defined requirements for RFPs and assessed proposals.
- Developed, maintained, and monitored security architecture artifacts.
- Conducted security assessments of existing and new IT systems and security services.
- 2018: ISMS consulting for GLS IT Services GmbH.
- Advised on implementing and initially operating an ISMS based on ISO27001.
- Audited the IT environments of GLS country subsidiaries.
- Analyzed and assessed IT security risks and derived necessary measures.
- Developed solution proposals in coordination with relevant stakeholders.
- Managed the project and handed over the ISMS to operations.
- 2016 - 2018: Security pre-sales consultant for Cisco Systems GmbH.
- Provided nationwide strategic and conceptual consulting to major enterprise and financial and insurance clients on Cisco and Meraki security products and services such as Firepower, WSA, ESA, Stealthwatch, and ISE.
- 2017 - 2018: Designed and implemented an ISMS for Verivox GmbH.
- Conducted various BIAs and gap analyses.
- Developed security policies based on ISO 2700x.
- Served as interim information security officer.
- 2017: Developed an emergency concept for VPV Lebensversicherungs-AG.
- Reviewed and updated the IT emergency manual.
- 2016: Consulting and project management for designing cloud & hosting services for Vodafone Group Services GmbH.
- Analyzed and optimized the sell-build-run process.
- Created detailed level designs for cloud products.
Markus Kraft
Last position:
Administration / Support at Hessische Zentrale für Datenverarbeitung
- Operation and development support (Linux, Tomcat)
- Web release builds with Jenkins and deployment
- Monitoring and operation planning
- Support for Online Access Act (OZG)
- Data queries and corrections in Oracle SQL via CloudBeaver and Rundeck
- Keycloak administration
- Regression testing and documentation in Jira
- Development of complex address database with MS Access/VBA
- Creation of documentation and guides in XWiki
Marco Köhl
Last position:
Freelancer at IBM Deutschland GmbH NGNCC
- Design and setup of infrastructure concepts for virtualized servers with VMware vSphere and VMware vCenter
- Migration from vCenter 7 environments to vCenter 8
- Automated deployment of virtual machines using Microsoft PowerShell and VMware PowerCLI as well as Ansible Tower
- Prototype setup and test migration of applications in various container environments
- Administration of firewalls and network components (routing and switching)
- Migration of VPN connection for all employees from Sophos UTM to Fortigate IPSec VPN with FortiToken
- Automation of OS installations on Linux with Ansible and GitLab
- VMware vSphere 8 with VMware vCenter 8
- VMware API
- VMware NSX-T
- VMware vSAN
- VMware Tanzu
- Red Hat OpenShift
- Docker
- SLES 15, Red Hat 9 and Microsoft Windows Server
- Microsoft Windows PowerShell
- GitLab
- Ansible Tower (AWX)
- SUSE Manager 4 and 5
- Fortigate Firewalls
- Fortinet Analyzer and Manager
- Juniper and Cisco switches and routers
Heiko Schönenberg
Last position:
Consultant Managed Print Service at ALDI Einkauf SE & Co. oHG
- Incident management of the existing printer fleet (multivendor)
- Technical consulting and support for the transition to a managed print service based on HP hardware and LRS software (VPSX / mfpsecure / VSPA) as the backend for a secure print / Follow Me solution
- Design and implementation of a hybrid operation for direct printing in branches
Szabolcs Kardos
Last position:
Senior Network Security Consultant at Mann+Hummel
- Network segmentation in a production IT environment
- Firewall migrations
- Integration of remote access sites
- Implementation of POCs (Backup, SCADA)
- Working in a multicultural environment
- Applied technologies: Panorama & Palo Alto Firewalls, Checkpoint, ServiceNOW, MS Azure Cloud
Andreas Müller
Last position:
Managing Director at ESIS-ERP GmbH
- took over as managing director
H̊akan Källberg
Last position:
Consultant at Simulina GmbH
- Project planning of photovoltaic systems for a citizens' initiative
- Design of billing systems
Discover over 15,000 top freelancers
Statistics of experts using Astaro
Aggregated from the professional profiles of matched freelancers.
Experience
28 years
Position duration
2.7 years
Positions per freelancer
19
Top business areas
Information Technology, Operations, Customer Service
Top industries
Information Technology, Telecommunication, Banking and Finance
Certification focus areas
Information Technology, Project Management, Audit
Bachelor's degree or higher
14%
Certifications per freelancer
6
Most common languages
German, English, French
Speak two or more languages
92%
Based on our profile pool as of 30 Aug 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Germany are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Germany using Astaro
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 30 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
About the technology
Astaro in practice
Astaro is a network security gateway used to control traffic, protect users, and connect sites. It is best known as Astaro Security Gateway and later as Sophos UTM. Companies use it for firewall rules, VPN access, web protection, and email security.
Typical work
- Firewall policy design and cleanup
- Site-to-site and remote VPN setup
- Web filtering, proxy rules, and access control
- Mail security and spam filtering
- Intrusion prevention and logging reviews
What strong specialists know
Strong Astaro specialists understand packet flow, NAT, routing, certificates, and rule order. They know how to read logs, spot conflicts, and keep security settings strict without breaking business traffic.
Ecosystem and integrations
Astaro often sits next to Active Directory, mail servers, branch networks, and authentication systems. In Germany, it is common in firms that still run stable gateway setups and need careful support for mixed office and remote access use.
When freelance help matters
Freelance expertise helps during audits, upgrades, migrations, and incident response. It is also useful when an internal team needs a clean policy review or help moving from Astaro to Sophos UTM or a newer Sophos Firewall setup.
What companies should expect
A good expert documents changes clearly, tests each rule, and works methodically. They should be able to explain security tradeoffs in plain language and support both short fixes and longer stabilization work.
Frequently asked questions
Key details about Astaro, drawn from the questions we get asked most.
Astaro is used to protect network traffic and control access between users, sites, and the internet. It commonly covers firewalling, VPN connections, web filtering, mail protection, and intrusion prevention. Many companies still rely on it for stable perimeter security and remote access.
Astaro was the original product name, and it later became known as Sophos UTM. People may still use either name when searching for help, especially if they work with older systems. A specialist should understand both the legacy setup and the later branding.
A strong Astaro specialist should know firewall policy design, NAT, VPNs, certificates, logs, and traffic troubleshooting. Experience with directory services and mail or proxy filtering is also useful. The best professionals can diagnose issues without changing more than needed.
Astaro projects often need outside help during upgrades, migration work, security audits, or after a rule set has grown messy. Companies also bring in specialists when remote access stops working or a gateway needs faster recovery. Freelance support is useful when the internal team lacks time or product depth.
Astaro is a mature gateway product, so it is often compared with newer UTM and firewall platforms from vendors like Sophos and others. The main difference is usually not the basic security model, but the workflow, licensing model, and migration path. A specialist helps reduce risk when moving away from an older installation.
Yes, Astaro support is often done remotely because most tasks can be handled through secure admin access, logs, and test calls. On-site work is only needed when hardware, cabling, or local network changes are involved. For Germany-based teams, clear communication and written change notes are especially helpful.
If rule changes are hard to track, VPN users report unstable access, or logs are too noisy to use, the Astaro setup likely needs review. Repeated certificate problems or unclear web filtering behavior are also common warning signs. A good specialist will simplify the policy and confirm what each rule is doing.
Look for an Astaro professional who asks about traffic flow, business needs, and the current change history before touching the system. Clear documentation, careful testing, and calm troubleshooting matter more than broad claims. Good work should leave the gateway easier to manage than before.
The average hourly rate of freelancers in Germany who have used Astaro in their recent projects is 109 €, which corresponds to a daily rate of about 871 € based on an 8-hour working day.
Of the freelancers in Germany who have used Astaro in their recent projects, 14% hold at least a Bachelor's degree.
On average, freelancers in Germany who have used Astaro in their recent projects have 28 years of professional experience, with a single engagement typically lasting around 2.7 years.
The most common languages among freelancers in Germany who have used Astaro in their recent projects are German (100%), English (92%), and French (58%).
The most common industries among freelancers in Germany who have used Astaro in their recent projects are Information Technology (100%), Telecommunication (75%), and Banking and Finance (67%).
The most common business areas among freelancers in Germany who have used Astaro in their recent projects are Information Technology (100%), Operations (100%), and Customer Service (83%).
Main locations of FRATCH Experts, who have recently used Astaro
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!
