Home/Cloud Computing/Network administration

01 · Cloud Computing

Network administration

We design, build and run networks for demanding clients — from company-wide LAN and Wi-Fi, through multi-site SD-WAN and edge routers into data centers, to network clustering for servers and GPU fabrics. Built on Fortinet, MikroTik, Cisco, Dell, NVIDIA and Supermicro, documented in full and maintained 24/7/365.

Who it's for

Who uses this service

  • Companies with multiple sites, warehouses or production plants
  • Organizations recovering from an incident in which the attack spread across a flat network
  • Regulated entities that require network segmentation and access control
  • Companies building a data center presence, edge routing or server clusters

When it makes sense

Signs that the time is right

  • Nobody has an up-to-date network diagram
  • Office, production and guest networks share a single VLAN
  • The firewall was configured years ago and nobody knows which rules are still needed

What we build

From a single office to a data center fabric

We design and build networks for demanding clients — and then run them. The same team plans the architecture, racks and configures the hardware, documents it and answers the phone at 3 a.m.

Company-wide networks

LAN and Wi-Fi for offices, warehouses and production plants, with segmentation, access control and redundant links between sites.

Multi-site and SD-WAN

Branch offices connected into one network: SD-WAN, site-to-site VPN, traffic prioritization and automatic failover between links.

Edge routers into data centers

Border routers with BGP, multiple ISPs, your own address space and AS, DDoS filtering and transit to our data centers.

Data center fabric

Leaf-spine switching, MLAG, redundant uplinks and VLAN/VXLAN design for hosting, virtualization and private clouds.

Server network clustering

Bonded and MLAG links for hypervisors, separate storage networks for Ceph and Proxmox, and high-throughput fabrics for GPU clusters.

Segmentation and OT

Zero Trust segmentation, guest and IoT networks, IT/OT separation with zones and conduits for industrial environments.

Hardware

Vendors we build on

We are vendor-neutral by design, but we go deep rather than wide: these are the platforms our engineers work with every day and hold certifications for.

Fortinet

FortiGate firewalls and SD-WAN, FortiSwitch and FortiAP under one Security Fabric, FortiManager and FortiAnalyzer for central policy and logs — from a branch office to an HA cluster at the edge.

MikroTik

RouterOS routers and switches where you need BGP, VPN concentrators, bandwidth management and a very good price-to-performance ratio — including CCR edge routers for ISPs and data centers.

Cisco

Catalyst and Nexus switching, ISR/ASR routing, VPN and enterprise Wi-Fi — the platform most corporate networks and regulated environments are standardized on.

Dell

PowerSwitch data center switching and PowerEdge servers — a proven combination for virtualization clusters and storage networks.

NVIDIA

Spectrum switches and ConnectX adapters, including RDMA and InfiniBand fabrics for GPU clusters and AI workloads — see GPU servers.

Supermicro

Servers and switching for dense compute and storage clusters, built to the specification the project actually needs.

Certified engineers

Our network team is certified by the vendors we deploy — Cisco, Fortinet and MikroTik, plus data center and OT tracks. See the full list of certifications.

Certifications

Engineers certified by the vendors we deploy

The person designing your network has passed the same exams as the vendor's own engineers — and support cases are escalated by someone who speaks the manufacturer's language.

CI
CiscoRouting, switching, security, data center
  • CCNAAssociate
  • CCNP EnterpriseProfessional
  • CCNP SecurityProfessional
  • CCNP Data CenterProfessional
  • CCIE Enterprise InfrastructureExpert
FT
FortinetFortiGate, SD-WAN, Security Fabric
  • FCA – Fortinet Certified AssociateAssociate
  • FCP – Network SecurityProfessional
  • FCP – Security OperationsProfessional
  • FCSS – Network SecuritySolution Specialist
  • NSE 4 / NSE 5 / NSE 7Legacy track
MT
MikroTikRouterOS, routing, wireless
  • MTCNANetwork Associate
  • MTCRERouting
  • MTCSESecurity
  • MTCWEWireless
  • MTCINEInter-networking (BGP/MPLS)
DC
Data center and OTServers, fabrics, industrial networks
  • Dell Technologies — NetworkingVendor training
  • NVIDIA Networking — Ethernet & InfiniBandVendor training
  • Proxmox VE / VMwareVirtualization
  • IEC 62443OT security
  • ITIL FoundationService management

Certifications are held by members of our network team; the exact set of certificates for a given project is listed in the offer.

Cooperation

Example scope of cooperation

A typical maintenance contract for a company with several sites. We tailor the scope, the response times and the rhythm to your environment.

AreaWhat we doRhythm
MonitoringAvailability, throughput, errors, link and device health; alerts routed to our on-call engineers24/7/365
IncidentsDiagnosis and repair of failures: links, routing, firewall, Wi-Fi; escalation to the vendor when neededSLA response
ChangesNew VLANs, rules, ports, VPN tunnels and users, carried out in agreed maintenance windowsOn request
Firmware and patchesTracking vendor advisories, planning and executing upgrades with a rollback planQuarterly / on advisory
Configuration backupAutomatic backup of device configurations with version history and quick restoreDaily
DocumentationDiagrams, IP and VLAN plans and the rule catalogue kept up to date after every changeAfter each change
Firewall reviewReview of rules, unused objects, VPN accounts and access from the outsideQuarterly
Capacity and performanceUtilization reports, bottleneck analysis and recommendations for the next budgetQuarterly
Hardware and RMAKeeping vendor support contracts alive, handling RMA and replacements, spare device policyContinuous
ArchitectureReview meetings: growth plans, new sites, segmentation and compliance requirementsQuarterly review
On-site workInstallation, rack and cabling work, migrations and audits at your locationsAs scheduled

Need something narrower — for example only 24/7 monitoring and incident response, or a one-off project to build a new site? We scope that too.

Architecture and documentation

We are responsible for the design — and for writing it down

Most network problems start with a network nobody can describe. In our projects the documentation is a deliverable, not an afterthought, and it stays current for as long as we run the network.

High- and low-level design

Target architecture with the reasoning behind it (HLD) and the configuration-level detail needed to build it (LLD).

Diagrams that match reality

Physical, logical and routing diagrams — including racks, ports, links and addressing, verified against the live network.

IP and VLAN plan

Address space, VLANs, naming conventions and DNS/DHCP design, planned with room for growth.

Firewall rule catalogue

Every rule with its owner, purpose and review date — so nobody has to guess whether a rule is still needed.

Runbooks and change log

Procedures for typical operations and failures, plus a history of changes: what was changed, when, by whom and why.

Handover package

Credentials in a vault, configuration backups, licences and support contracts — you own the network, not your supplier.

Maintenance

Running the network 24/7/365

Building a network is a project; keeping it healthy is a service. Both are done by the same engineers, which is why nothing gets lost in handover.

Round-the-clock monitoring

Devices, links, throughput and anomalies watched all year, with alerts going to on-call engineers — not to an empty inbox.

Guaranteed response

Response times defined in the SLA, with priorities agreed for critical links, sites and systems.

Planned changes

Work executed in maintenance windows, with a test plan and a rollback path prepared before we touch anything.

Security together with the network

Firewall policy, segmentation and VPN maintained together with our SOC and DDoS protection.

One team for servers and network

The same partner runs your servers, so nobody argues whether the problem is "the network" or "the application".

Ready for audits

Documentation, logs and reviews prepared with NIS2 and DORA requirements in mind.

Scope

What the service includes

Audit and documentation

Device inventory, logical and physical diagrams, firewall rule review.

Design

Segmentation (VLAN), Zero Trust, link redundancy, enterprise Wi-Fi, IoT/OT.

Firewall and VPN

Fortinet, Cisco, MikroTik and pfSense/OPNsense — deployment, rule sets, remote-access and site-to-site VPN, HA clusters at the edge.

Implementation

Configuration of switches, access points and routing — during maintenance windows.

Monitoring

Availability, throughput, anomalies — alerts routed to our 24/7 on-call team.

Maintenance

Firmware updates, changes, up-to-date documentation, SLA-backed support.

Process

How we work — four steps

STEP 1

Audit (1–2 weeks)

Inventory, diagrams, risks, regulatory requirements.

STEP 2

Design

Target architecture, hardware, schedule, cost estimate.

STEP 3

Implementation

In stages, with no downtime during business hours; testing after each stage.

STEP 4

Maintenance

24/7 monitoring, changes, quarterly reviews under the SLA.

Outcome

What you get

  1. Up-to-date network documentation (diagrams, addressing, rules)
  2. A segmented network with access control
  3. Firewall and VPN configured to best practices
  4. Monitoring with alerting
  5. SLA-backed maintenance with guaranteed response times, 24/7/365
24/7/365monitoring and on-call under SLA
Fortinet · MikroTik · CiscoDell, NVIDIA and Supermicro in the data center
CertifiedCisco and Fortinet engineers
See how it worked for a client

Anonymized Cloud Computing projects — scope, process, outcome.

Case studies

Questions

Frequently asked questions

Which vendors do you work with?

Mainly Fortinet, MikroTik and Cisco for routing, switching, firewalls and Wi-Fi, and Dell, NVIDIA and Supermicro in the data center — including NVIDIA fabrics for GPU clusters. If your environment is standardized on something else, we say so honestly before the project starts.

Do we need to replace our hardware?

Not always — the audit shows what can stay. We only replace equipment that is no longer vendor-supported or cannot deliver the required segmentation, performance or redundancy.

Can you build a large, multi-site network?

Yes. We design and build networks for entire companies: many locations, redundant links, SD-WAN, edge routers with BGP into data centers and data center fabrics for server and storage clusters.

Do you connect servers and clusters too?

Yes. We build the network layer for virtualization and storage clusters — bonded and MLAG uplinks, separate storage networks for Ceph and Proxmox, and high-throughput fabrics for GPU and AI workloads.

What certifications does your team hold?

Our engineers hold certifications across the Cisco and Fortinet tracks, from associate to expert level, as well as MikroTik certifications and vendor training for the data center platforms we deploy.

What does 24/7/365 maintenance actually cover?

Monitoring and on-call all year, incident diagnosis and repair under an SLA, changes in maintenance windows, firmware and security advisories, configuration backups, documentation updates and quarterly reviews. The full picture is in the example scope above.

Who owns the documentation and access?

You do. Diagrams, IP plans, rule catalogues, configuration backups, licences and credentials are yours and are handed over in a form you can pass to another supplier if you ever want to.

Do you support industrial (OT) networks?

Yes — we design IT/OT separation, zones and conduits in line with IEC 62443, working together with the client's automation engineers.

What about Wi-Fi for guests and employees?

Separate networks, 802.1X authentication for employees, a captive portal for guests and isolation from the corporate network — standard in every project.

Will the work disrupt our business?

We implement in stages, during agreed maintenance windows, with tests after each stage and a rollback plan. Work that cannot be done without an interruption is scheduled with you in advance.

How do we start?

With an audit: inventory, diagrams, risks and requirements — typically one to two weeks. You then get a target design, a schedule and a cost estimate before anything is bought or changed.

First step

Let's talk about network administration.

30 minutes, no slide deck. We'll tell you straight whether this service solves your problem, what scope makes sense and how much it costs.

Book a consultation

A proposal with scope and pricing within 48 hours of the call.

Go to contact