Skip to content

Enterprise

A multi-site network that keeps working

Site interconnect, segmentation, identity, endpoints and business continuity — under one engineering owner.

The problem

IT grew with the branches; ownership scattered

Every site has its own router, each chosen by a different contractor. The VPN was built the week it became urgent. Everyone knows the Wi-Fi password, and the backup sits in the same building. When something breaks, three suppliers point at each other and nobody owns the answer.

  • There is no single diagram or documentation
  • The branches are each built differently
  • The backup sits next to production
  • Nobody clearly owns an incident

What we deliver

A multi-site network that keeps working

Site interconnect

One design for every site: circuits, a backup path and the rule for switching over.

Segmentation and access

User, server, guest and device zones — and what is allowed to pass between them.

Wireless

A coverage survey, a controller, separate SSIDs and guest isolation.

Backup and recovery

A second copy off site, retention periods and a restore rehearsal.

Monitoring and support

Detection and escalation on one process, across every site.

Documentation and a single owner

Diagrams, addressing, access — and who owns which part of it.

Architecture

Architecture

  1. 01BranchThe standard site design
    • MikroTik
    • 802.11ax
    • VLAN
  2. 02InterconnectA primary and a backup path
    • IPsec
    • WireGuard
    • SD-WAN
  3. 03PerimeterZones and the inter-zone policy
    • FortiGate
    • HA cluster
    • 802.1X
  4. 04CoreServers and applications
    • Proxmox VE
    • VMware vSphere
    • VRRP
  5. 05BackupA second copy off site
    • Veeam
    • Proxmox Backup Server
    • Off-site
  6. 06MonitoringOne process across every site
    • Zabbix
    • LibreNMS
    • Graylog
From branch to core — one design, repeated at every site

Operator consoles

Operator consoles

These exact systems run on the group's own infrastructure — the screenshots are processed before publication.

A Zabbix graph for a single circuit — inbound and outbound traffic over time.

One circuit, one graph — QoS in real time

This is what one business circuit looks like in Zabbix: inbound and outbound traffic, peaks, the real use of the committed rate, and history. It is the graph that answers "is the link actually enough" — and the customer can see that answer too, not only us.

ZabbixQoSSNMPper-circuit
Blurred vSphere Client — the virtual machine inventory and one machine's resource usage.

vSphere — the cluster, its hosts and the workloads on it

A vCenter with several ESXi hosts and the services placed on them: web, billing, a domain controller, backup agents. This is the environment where VMware and Proxmox coexist — part of it still on vSphere, part already migrated. One team operates both, under one backup policy.

vSphereESXivCentermigration
Blurred FortiGate dashboard: session, memory and throughput graphs with security-fabric status.

The firewall — policy, sessions and load

A FortiGate in production: thousands of concurrent sessions, SPU load, security-fabric state and per-interface throughput on one screen. A firewall is not a separate box to us — it is designed and operated together with routing, segmentation and logging, by certified engineers.

FortiGateHAsegmentationIPsec
The WireGuard Portal interface administration screen — peer counts and interface parameters; keys and addresses are redacted.

WireGuard Portal — peers managed in one place

WireGuard is fast, but by default it is administered through config files — and by the twentieth peer that is a problem. The portal centralises key and peer management, adds self-service provisioning and shows who is connected right now. Interface state, MTU, DNS and keepalive on one screen.

WireGuardpeer managementself-serviceMikroTik
screenshot not supplied yetpublic/media/proof/paloalto-firewall.webpnpm run proof:blur
Palo Alto · PAN-OSblurred

Palo Alto — policy at the application layer

The PAN-OS platform: App-ID and User-ID level policy, logging and threat prevention. We have engineers certified on it; a deployment screen goes up here once a specific production environment is cleared for publication.

PAN-OSApp-IDUser-IDthreat prevention
The phpIPAM dashboard — aggregate statistics for subnets, VLANs and addresses, with usage charts.

IPAM — the address space in one system

A live phpIPAM deployment: subnet hierarchy, VLAN domains, VRFs, devices and locations in one searchable database. Only the aggregate statistics are public — customer names, individual subnets and locations are not on the frame, and should not be.

phpIPAMIPv4 / IPv6VLANVRF

Capabilities

Capabilities

Every item is marked: verified production experience, or engineering capability.

SD-WAN and VPN

Capability
  • IPsec
  • SD-WAN
  • WireGuard

Segmentation and access control

Proven
  • VLAN
  • 802.1X
  • Zones

Firewall architecture

Proven

A FortiGate in production — policy, an HA pair and IPsec, designed together with routing and logging.

  • FortiGate
  • HA
  • IPsec

Wireless networks

Proven
  • 802.11ax
  • Controller
  • Site survey

Backup and DR

Capability
  • Veeam
  • Off-site

Monitoring and helpdesk

Proven

Technology stack

Technology stack

Network
FortiGateMikroTikCiscoVLANVRRP
Remote access
IPsecWireGuard802.1XMFA
Wireless
802.11axControllerSite survey
Virtualization
Proxmox VEVMware vSphereZFS
Backup
VeeamProxmox Backup ServerOff-site copy
Monitoring
ZabbixGrafanaLibreNMSGraylog

Engagement model

Engagement model

Project

A one-off scope: audit, migration or implementation with a fixed outcome.

Retainer

Monthly engineering hours — specialist access on demand.

Fully managed

We own the agreed operational scope end to end.

Use cases

Use cases

A new office opens

The opening date is fixed and the circuit is not in yet. We prepare a standard site design — network, Wi-Fi, segmentation and VPN — that repeats at every next location.

The board asks about backups

"How long until we are back?" — that answer exists only after a rehearsal. We put the copies in order, test the restore and write down which system returns in which order.

In-house IT is one person

One administrator carries everything. We take monitoring and out-of-hours escalation in a co-managed model, so they can stay on the business work.

FAQ

FAQ

We have in-house IT — do we still need you?

A co-managed model usually fits best: your team stays on day-to-day work while we take architecture, out-of-hours escalation and projects. Replacing them is not the goal.

Who buys the hardware?

You do — and we recommend the vendor after the audit. Hardware and licences stay in your name, so changing supplier is a technical question rather than a legal one.

Do you come on site?

Most of the work is done remotely; installation, surveys and migration windows happen on site, on a schedule agreed in advance.

Tell us about your infrastructure