Enterprise
A multi-site network that keeps working
Site interconnect, segmentation, identity, endpoints and business continuity — under one engineering owner.
The problem
IT grew with the branches; ownership scattered
Every site has its own router, each chosen by a different contractor. The VPN was built the week it became urgent. Everyone knows the Wi-Fi password, and the backup sits in the same building. When something breaks, three suppliers point at each other and nobody owns the answer.
- There is no single diagram or documentation
- The branches are each built differently
- The backup sits next to production
- Nobody clearly owns an incident
What we deliver
A multi-site network that keeps working
Site interconnect
One design for every site: circuits, a backup path and the rule for switching over.
Segmentation and access
User, server, guest and device zones — and what is allowed to pass between them.
Wireless
A coverage survey, a controller, separate SSIDs and guest isolation.
Backup and recovery
A second copy off site, retention periods and a restore rehearsal.
Monitoring and support
Detection and escalation on one process, across every site.
Documentation and a single owner
Diagrams, addressing, access — and who owns which part of it.
Architecture
Architecture
- 01BranchThe standard site design
- MikroTik
- 802.11ax
- VLAN
- 02InterconnectA primary and a backup path
- IPsec
- WireGuard
- SD-WAN
- 03PerimeterZones and the inter-zone policy
- FortiGate
- HA cluster
- 802.1X
- 04CoreServers and applications
- Proxmox VE
- VMware vSphere
- VRRP
- 05BackupA second copy off site
- Veeam
- Proxmox Backup Server
- Off-site
- 06MonitoringOne process across every site
- Zabbix
- LibreNMS
- Graylog
Operator consoles
Operator consoles
These exact systems run on the group's own infrastructure — the screenshots are processed before publication.
One circuit, one graph — QoS in real time
This is what one business circuit looks like in Zabbix: inbound and outbound traffic, peaks, the real use of the committed rate, and history. It is the graph that answers "is the link actually enough" — and the customer can see that answer too, not only us.
vSphere — the cluster, its hosts and the workloads on it
A vCenter with several ESXi hosts and the services placed on them: web, billing, a domain controller, backup agents. This is the environment where VMware and Proxmox coexist — part of it still on vSphere, part already migrated. One team operates both, under one backup policy.
The firewall — policy, sessions and load
A FortiGate in production: thousands of concurrent sessions, SPU load, security-fabric state and per-interface throughput on one screen. A firewall is not a separate box to us — it is designed and operated together with routing, segmentation and logging, by certified engineers.
WireGuard Portal — peers managed in one place
WireGuard is fast, but by default it is administered through config files — and by the twentieth peer that is a problem. The portal centralises key and peer management, adds self-service provisioning and shows who is connected right now. Interface state, MTU, DNS and keepalive on one screen.
public/media/proof/paloalto-firewall.webpnpm run proof:blurPalo Alto — policy at the application layer
The PAN-OS platform: App-ID and User-ID level policy, logging and threat prevention. We have engineers certified on it; a deployment screen goes up here once a specific production environment is cleared for publication.
IPAM — the address space in one system
A live phpIPAM deployment: subnet hierarchy, VLAN domains, VRFs, devices and locations in one searchable database. Only the aggregate statistics are public — customer names, individual subnets and locations are not on the frame, and should not be.
Capabilities
Capabilities
Every item is marked: verified production experience, or engineering capability.
SD-WAN and VPN
Capability- IPsec
- SD-WAN
- WireGuard
Segmentation and access control
Proven- VLAN
- 802.1X
- Zones
Firewall architecture
ProvenA FortiGate in production — policy, an HA pair and IPsec, designed together with routing and logging.
- FortiGate
- HA
- IPsec
Wireless networks
Proven- 802.11ax
- Controller
- Site survey
Backup and DR
Capability- Veeam
- Off-site
Monitoring and helpdesk
ProvenTechnology stack
Technology stack
- Network
- FortiGateMikroTikCiscoVLANVRRP
- Remote access
- IPsecWireGuard802.1XMFA
- Wireless
- 802.11axControllerSite survey
- Virtualization
- Proxmox VEVMware vSphereZFS
- Backup
- VeeamProxmox Backup ServerOff-site copy
- Monitoring
- ZabbixGrafanaLibreNMSGraylog
Engagement model
Engagement model
Project
A one-off scope: audit, migration or implementation with a fixed outcome.
Retainer
Monthly engineering hours — specialist access on demand.
Fully managed
We own the agreed operational scope end to end.
Use cases
Use cases
A new office opens
The opening date is fixed and the circuit is not in yet. We prepare a standard site design — network, Wi-Fi, segmentation and VPN — that repeats at every next location.
The board asks about backups
"How long until we are back?" — that answer exists only after a rehearsal. We put the copies in order, test the restore and write down which system returns in which order.
In-house IT is one person
One administrator carries everything. We take monitoring and out-of-hours escalation in a co-managed model, so they can stay on the business work.
FAQ
FAQ
We have in-house IT — do we still need you?
A co-managed model usually fits best: your team stays on day-to-day work while we take architecture, out-of-hours escalation and projects. Replacing them is not the goal.
Who buys the hardware?
You do — and we recommend the vendor after the audit. Hardware and licences stay in your name, so changing supplier is a technical question rather than a legal one.
Do you come on site?
Most of the work is done remotely; installation, surveys and migration windows happen on site, on a schedule agreed in advance.