Design, deployment and monitoring of business networks — firewalls, switching, Wi-Fi, VLAN segmentation and VPN — as one managed system.
Why networks get neglected
A network is invisible while it works, which means it usually gets attention only twice: when it is installed, and when it breaks badly enough to stop the business. In between, access points get added ad hoc, firewall rules accumulate without review, firmware goes stale, and the documentation — if it ever existed — stops matching reality.
The result is the environment we most often inherit: a flat network with no segmentation, a firewall three years behind on firmware with a management interface exposed to the internet, Wi-Fi that works everywhere except the two rooms people complain about, and nobody who can say with confidence what is plugged into which switch port.
What managed network support covers
Firewall. Firmware maintained, rule set reviewed rather than accumulated, remote management access closed, VPN configured properly. This is the device most directly exposed to the internet and the one most worth keeping current.
Switching. Port state and uplink health monitored, VLANs configured and documented, PoE budget managed so adding access points and cameras does not silently overload a switch.
Wi-Fi. Access point placement based on a survey of the actual building. Channel planning to avoid interfering with yourself and with neighbouring tenancies. Separate guest network isolated from everything internal.
Segmentation. Staff devices, servers, guests, phones, cameras and payment systems in separate segments. This is the single most effective structural limit on how far an incident spreads, and it costs nothing but design time on a network you are building anyway.
Remote access. VPN for staff working off-site, configured with modern authentication rather than a shared password from 2019.
The intermittent fault problem
The network faults that cost the most are not the ones that take a site down — those get fixed within the hour. They are the ones where “the internet is slow sometimes”, or one user drops off calls twice a week, or a warehouse scanner disconnects in a particular aisle.
Those are unfixable by description. What resolves them is monitoring that was already running when it happened: port error counters, uplink saturation, access point client counts and roaming behaviour, recorded continuously so the pattern is visible after the fact rather than reproduced on demand.
Design before purchase
Network hardware is easy to buy and expensive to buy twice. We design the segmentation plan, addressing, access point placement and failover approach before anything is ordered, and cut over inside an agreed window with the old equipment retained until the new build is proven.
For office moves and fitouts this needs to start early — cabling and comms cabinet decisions are dramatically cheaper before the walls close. See onsite IT support for how we run fitout work.