Networking
Enterprise networking, SD-WAN, zero-trust access, and cloud connectivity engineered by senior network architects. Designed for offices, data centres, and multi-cloud platforms that have to stay up.
01 — Approach
How we engage.
- Greenfield network architecture — campus, branch, data centre, and cloud-native designs documented end-to-end: IP plan, VLAN map, routing topology, redundancy strategy, and a written rollout plan.
- SD-WAN deployments — multi-site SD-WAN on Cisco, Fortinet, Palo Alto, VeloCloud, and Cloudflare Magic WAN, with QoS, application steering, and zero-touch provisioning.
- Zero-trust network access (ZTNA) — identity-aware access replacing legacy VPN, built on Cloudflare Access, Tailscale, Twingate, Zscaler, or open-source WireGuard fabrics.
- Multi-cloud & hybrid connectivity — AWS Transit Gateway, GCP Network Connectivity Center, Azure Virtual WAN, Direct Connect / Interconnect / ExpressRoute, mesh peering, and the policy work to keep it operable.
- Data centre networking — leaf-spine fabrics, EVPN-VXLAN, BGP / OSPF design, and the slow careful work of migrating from legacy three-tier to modern overlays without downtime.
- Network security & segmentation — micro-segmentation with NSX, Cisco ACI, or cloud-native security groups, plus next-gen firewall design on Palo Alto, Fortinet, and Check Point.
- Wi-Fi 6/6E/7 design — site surveys, AP placement, controller design, and roaming optimisation for offices, warehouses, and hospitality environments.
- Network observability & telemetry — streaming telemetry, flow analytics, packet-broker design, and the dashboards your NOC will actually open during an incident.
- Network automation — Terraform, Ansible, NetBox-as-source-of-truth, and CI-driven config rollouts that replace clicking through GUIs.
- Senior-only delivery. A staff-level network architect owns the engagement — not a delivery manager with a reference architecture and a vendor-supplied bill of materials.
- Vendor-agnostic. Cisco, Juniper, Arista, Palo Alto, Fortinet, Cloudflare, open-source — we recommend by fit, not channel margin. We have no reseller relationships shaping the answer.
- Boring networks are good networks. We pick the smallest set of moving parts that solves the problem. EVPN-VXLAN only when you need it. SD-WAN only when the SLAs justify it.
- Documented as built, not as imagined. Every engagement closes with current-state diagrams, a written runbook, and a NetBox or Nautobot source of truth your team can actually keep up to date.
- Migration over big-bang. Cut-overs happen in reversible steps. Production stays usable through the entire engagement — and we plan rollback for every change before it ships.
- Security and compliance baked in. Segmentation, identity, logging, and change control designed for SOC 2, ISO 27001, PCI-DSS, and HIPAA scope from day one, not retrofitted before the audit.
- Stay-on retainers. Most clients keep us on a monthly retainer for ongoing change review, capacity planning, vendor escalation help, and on-call augmentation when something breaks at 3 AM.
- Routing & switching: Cisco IOS-XE / NX-OS, Juniper Junos, Arista EOS, FRRouting on Linux.
- SD-WAN & WAN: Cisco Catalyst SD-WAN, Fortinet Secure SD-WAN, Palo Alto Prisma SD-WAN, Cloudflare Magic WAN.
- Zero-trust & remote access: Cloudflare Access, Tailscale, Twingate, Zscaler Private Access, WireGuard.
- Firewalls & security: Palo Alto NGFW, Fortinet FortiGate, Check Point, Cisco Firepower, pfSense / OPNsense at the edges.
- Cloud networking: AWS VPC + Transit Gateway, GCP VPC + NCC, Azure VNet + Virtual WAN, Direct Connect / Interconnect / ExpressRoute.
- Wireless: Cisco Meraki, Aruba CX / Instant, Juniper Mist, Ruckus, Ubiquiti UniFi for smaller footprints.
- Automation & SoT: Terraform, Ansible, NetBox, Nautobot, GitHub Actions for config CI/CD.
- Observability: Grafana, Prometheus SNMP exporter, Telegraf, Kentik, NetFlow / sFlow / IPFIX collectors, ELK for syslog.
- Network audit & architecture — $20k–$80k, two to six weeks. Current-state report, target architecture, risk register, vendor selection, and a phased migration plan.
- Build & migration — $80k–$400k+, three to nine months. Fixed scope, milestone-billed, with a documented cut-over and rollback plan for every phase.
- SD-WAN or ZTNA rollout — $60k–$200k, six to sixteen weeks. Vendor selection, design, zero-touch provisioning, identity integration, and post-launch tuning.
- Embedded network engineer — monthly retainer. Senior coverage for teams scaling without a full-time network architect on staff.
- On-call augmentation — monthly retainer. Pre-negotiated SLA-backed coverage for organisations that cannot yet sustain a 24/7 NOC.
02 — What's included
Every engagement ships with.
Senior lead
A 10+-year practitioner who stays on the work, end-to-end.
Design system
A scalable foundation, not screen-by-screen one-offs.
Production deploys
Fortnightly increments to a staging URL.
Documentation
Runbooks, ADRs, and onboarding materials.
03 — Process
Four phases. Always.
Discovery
1–2 weeks. Audit, listen, scope.
Design
2–4 weeks. Prototypes you can click.
Build
6–16 weeks. Two-week cadences.
Stewardship
Ongoing. Continuity beats handoff.
04 — Common questions
Frequently Asked Questions
How much do enterprise networking services cost?
A focused network audit and architecture engagement starts at $20,000 (two to six weeks). Larger build-and-migration projects typically land between $80,000 and $400,000 depending on site count, compliance scope, and vendor mix. SD-WAN or zero-trust rollouts run $60,000–$200,000. Monthly retainers for ongoing change review and on-call support start at $10,000.
How long does a network migration take?
A single-site office network refresh ships in six to ten weeks. A multi-site SD-WAN or zero-trust rollout runs three to six months. A full data-centre to multi-cloud network re-architecture runs six to twelve months. We migrate in reversible cuts — production stays usable through the entire engagement, and we plan rollback for every change before it ships.
SD-WAN, zero-trust, or traditional VPN — which should we pick?
We are vendor-agnostic and will tell you honestly. Traditional VPN is right for small site counts and budget-sensitive teams. SD-WAN is right when you operate ten or more branches, run real-time traffic, or need application-aware steering. Zero-trust network access is right for identity-aware remote access and retiring legacy VPN. Most teams over fifty engineers end up with a small SD-WAN footprint for branches plus ZTNA for users.
Do you work with our existing network vendor, or do we have to switch?
We work with what you have. We have shipped Cisco, Juniper, Arista, Palo Alto, Fortinet, Cloudflare, and open-source designs in production — and we have no reseller relationships shaping the recommendation. If a rip-and-replace is the right call we will say so; if your current stack is fine, we will tell you that too.
Can you connect our on-prem network to AWS, GCP, or Azure?
Yes. Multi-cloud and hybrid connectivity is a core practice — Direct Connect, Interconnect, ExpressRoute, Transit Gateway, NCC, Virtual WAN, mesh peering, and the policy work to keep it operable. We handle the routing, the security boundary, and the cost optimisation that usually gets missed.
Do you do network automation and infrastructure-as-code?
Yes. Terraform, Ansible, and NetBox (or Nautobot) as the source of truth, plus CI-driven config rollouts replacing GUI clicks. We do not leave teams with networks that only one engineer understands — automation and documentation are part of every engagement.
Can you help with network security and compliance?
Yes — segmentation, identity, logging, and change control are designed for SOC 2, ISO 27001, PCI-DSS, and HIPAA scope from day one. Deeper security work pairs with our cybersecurity practice for penetration testing, threat modelling, and audit-readiness engagements. Findings are mapped to OWASP, NIST, and the relevant compliance control.
Do you offer 24/7 on-call support?
Yes. On-call augmentation is available on a monthly retainer — pre-negotiated SLA-backed coverage, named senior on-call engineers, and a documented runbook for the systems we built. We do not replace your NOC permanently, but we help teams that cannot yet sustain a 24/7 rotation bridge the gap.
05 — Selected work
Related projects.
— From the journal