In this morning's presentation there were some filter rules we can implement on our firewall:
http://noc.ws.nsrc.org/pacnog14-sns/raw-attachment/wiki/Agenda/Firewalls.pdf
We also want to be able to connect to these ports on srv1-N and srv2-N from outside:
ssh - port 22
See:
https://doc.pfsense.org/index.php/Restrict_access_to_management_interface https://doc.pfsense.org/index.php/Remote_firewall_Administration