Network audit & architecture
- Topology mapping
- SPOF analysis
- Roadmap
ISP & telecom
From RIPE resources, BGP edge and MPLS core through to network digital twins, observability, security, backup and disaster recovery.
The problem
The typical Tier-2/Tier-3 operator: a single edge router, BGP policy grown over years, no flow data collected, manual backups, and a migration that hinges on one night window.
Architecture
Operator consoles
These exact systems run on the group's own infrastructure — the screenshots are processed before publication.
Every upstream and every peering session is measured separately, with global and local traffic split apart. Capacity and peering decisions come from this view — not from a hunch.
Flow records grouped into ASN categories: CDN/OTT, Georgian ISPs, the group's own networks and international transit. This is the picture that decides which cache to bring inside the network, where peering pays for itself and what stays on paid transit. It is the one screen published legible — everything in it is an aggregate share, with no customer and no address anywhere.
The same flow data, this time with names on it: which CDN and which platform sends the most, where it lands and which router carries it. This list is what turns a peering or cache-placement conversation into an argument with evidence — Akamai, Fastly, Meta, Google. The volumes are blurred; the names and the proportions are not.
Each prefix and how visible it is through each transit — which upstream propagates which prefix, and in what share. This is how a route leak, a missing announcement or a mis-built policy becomes visible before it becomes an incident. The tool is public on noc.com.ge.
From four international vantage points — Sofia, the USA, Amsterdam, India — every one of our prefixes is measured for reachability, loss and latency. No human assembles this: the system compares a 3-hour window against a 24-hour baseline, picks out the direction that is degrading and assigns the priority itself — in this frame P1 is India, where RTT passes 190 ms.
A small or mid-sized operator's network is rarely single-vendor: MikroTik in the core, Ubiquiti on the wireless links, Cambium at the access layer. This map carries, per link, what operations actually runs on — wireless clients on the sector, CCQ, noise floor, airMAX quality and capacity, distance, frequency, Rx/Tx and uptime. The tower power nodes sit on the same map: battery voltage is a metric like any other here, and it explains half of the night-time outages.
Over 130 devices and thousands of ports in one system: an availability map, alert history and the top errored interfaces — including the GPON/EPON access layer, where a fault shows up on the port before the subscriber notices it.
This is what one business circuit looks like in Zabbix: inbound and outbound traffic, peaks, the real use of the committed rate, and history. It is the graph that answers "is the link actually enough" — and the customer can see that answer too, not only us.
Live path monitoring on a 15-second refresh: latency and packet loss to each service, including cache servers hosted inside individual operators. A path change is recorded as its own incident, with filters by ASN, ISP and customer. We wrote this tool ourselves because no off-the-shelf product answered the question.
A FortiGate in production: thousands of concurrent sessions, SPU load, security-fabric state and per-interface throughput on one screen. A firewall is not a separate box to us — it is designed and operated together with routing, segmentation and logging, by certified engineers.
A device's configuration is the one file whose loss is measured in hours of downtime. ros-backup collects it every day over SSH — MikroTik RouterOS, Juniper JunOS, Cisco IOS and Arista EOS — and keeps it in a git repository, versioned, with a line-by-line diff between any two. No engineer signs in to each device to copy a config by hand: any router's configuration from any day is two clicks away — including when the device itself will no longer power on. We wrote this one ourselves too.
The whole subscriber lifecycle in one system: tariffs, balances, services (internet, Wi-Fi, IPTV), statuses, SMS notifications, logs and financial reports — wired into provisioning. We built it, and it runs a real ISP.
A live phpIPAM deployment: subnet hierarchy, VLAN domains, VRFs, devices and locations in one searchable database. Only the aggregate statistics are public — customer names, individual subnets and locations are not on the frame, and should not be.
A topology built from real network operating systems: border routers, IXP and CDN peerings, the aggregation layer, VLANs and the management network — production, replicated in the lab. Migration, failure and rollback run here first; only then does anyone touch the live network.
Portfolio
verified infrastructure
ASN
AS203136
OrduNet LLC
Prefix
185.143.176.0/22
announced
RPKI
valid
maxLength /22
Upstream operators
3
Caucasus Online · System Net Ltd · Silknet
Source: RIPE NCC — the group's own resources
Capabilities
Every item is marked: verified production experience, or engineering capability.
The group's own AS203136 runs on three upstreams — built on the same design principles.
ROAs published and valid — verifiable in the RIPE registry. Max-prefix limits and route-leak filtering are part of the design on every edge we build.
Technology stack
Engagement model
A one-off scope: audit, migration or implementation with a fixed outcome.
Monthly engineering hours — specialist access on demand.
NetWizard and your in-house team together, with split responsibility.
24/7 monitoring, response and severity-based escalation.
Use cases
Removing the SPOF: a second upstream, rewritten policy, validated in the lab first.
Reducing transit spend on the basis of actual flow data.
Addressing plan, ROAs, dual-stack termination and monitoring.
FAQ
Yes. The group holds AS203136, announces 185.143.176.0/22 with a valid RPKI ROA and connects to three upstream operators. All of it is verifiable in the RIPE registry.
No. The migration is first built in EVE-NG: same configuration, same network OS, with failure and rollback tested. Only an approved plan reaches production.
No — they work together. Streaming telemetry where sampling rate matters; SNMP polling where the device or metric requires it. Flow then provides a third, independent view.