← Projects
CASE STUDY / 01

Multi-siteInfrastructure.

Segmentation, secure connectivity, routing and a unified operational model for distributed production infrastructure.

50+ VLANssegmented infrastructure
Multipleproduction sites
Multi-WANresilient external connectivity
01 / CONTEXT

Unified infrastructure should not become a flat network.

Multiple sites need to share infrastructure services and provide the required connectivity between users, servers and systems, while still preserving separate security zones.

The network is therefore designed not as a single trust domain, but as a set of segmented sites with explicit routes, VPN connections and access directions. Connectivity is allowed where services and operational processes actually require it.

02 / RESPONSIBILITY

Responsibility from local segment to inter-site route.

01Multi-site network architecture
02VLAN segmentation and access policies
03Routing and inter-site connectivity
04IPsec, WireGuard and OpenVPN
05Multi-WAN and uplink redundancy
06Firewall, NAT and policy routing
07Controlled inter-segment access
08Diagnostics, monitoring and documentation
03 / ARCHITECTURE

Sites are connected, but remain separated.

The diagram is intentionally abstracted. It shows functional network layers without exposing customer addressing, site names, providers, tunnel endpoints or internal security rules.

SITES & SEGMENTSIsolated local zonesUsers · servers · voice · management
ROUTINGControlled routingVLAN · routes · policy routing
VPNSecure connectivityIPsec · WireGuard · OpenVPN
WANUplink redundancyPrimary · backup · failover
ACCESSControlled directionsFirewall · least privilege · no-NAT
SERVICESShared infrastructure servicesDNS · identity · monitoring
OPERATIONSUnified operating modelMonitoring · diagnostics · runbooks
04 / SEGMENTATION
01

Users

Workstations and user devices are separated from server and administrative networks and receive only the access required for their services.

02

Servers

Server networks are isolated into dedicated zones with controlled routes to users, services and other sites.

03

Voice and specialized networks

Telephony, video surveillance, printing and other specialized systems are kept separate from ordinary user traffic.

04

Management

Network and server management is separated from user segments and exposed only to administrative zones.

05 / CONNECTIVITY & RESILIENCE

Routing should remain predictable when an uplink fails.

Inter-site connectivity is built around protected VPN tunnels and explicit routes. IPsec, WireGuard and OpenVPN are used depending on site, client and service requirements.

Sites with multiple Internet connections use failover and policy routing. Specific destinations and services can use a defined uplink, while failure of the primary link should not require manual switching of the entire network.

06 / OPERATIONS

A complex network must remain diagnosable.

Changes are validated across routes, tunnel state, routing tables, NAT and firewall policy. Troubleshooting follows the actual traffic flow rather than assuming the problem is located on one side of a VPN.

Repeatable inter-site rules are documented, network devices and tunnels are monitored, and changes are made in a way that preserves a clear operational model as the infrastructure grows.

07 / RESULT

Multiple sites, one manageable infrastructure.

Segmentation, routing, VPN, external-link redundancy and access policy operate as one model. Sites can share the services they require without turning the environment into one flat and fully trusted network domain.

← Back to projects