What usually brings people to this.
- A network that grew by accretion rather than design
- No documented addressing, segmentation or routing standard
- Security controls bolted on after the topology was fixed
From business requirement to logical design to physical build
Network design and architecture is the strategic process of planning and creating a network infrastructure that meets specific business, operational and technical needs. We work through requirements, network type, logical architecture, physical components and security architecture as one sequence — so segmentation and security are decided with the topology, not after it.
-
01
Requirements and scope
Scope, user counts, performance expectations and compliance obligations captured before any design work begins.
-
02
Logical architecture
IP addressing, subnetting, VLAN design, routing and switching.
-
03
Physical component selection
Routers, switches, wireless LAN controllers and access points selected against the logical design.
-
04
Security architecture
Firewall, NAC, VPN and IDS/IPS placement designed into the topology.
How the engagement runs.
A defined sequence, so you know what is happening at any point and what comes out of each stage.
-
01
Understand business requirements
Establish what the network has to do before deciding what it is made of.
- Scope
- Users
- Performance expectations
- Compliance obligations
-
02
Determine the type of network
Select the network types in scope and how they relate.
- LAN
- WAN
- WLAN
- Data centre
-
03
Design the logical architecture
Define the addressing and forwarding model.
- IP addressing
- Subnetting
- VLANs
- Routing and switching
-
04
Select physical components
Choose hardware that implements the logical design.
- Routers
- Switches
- WLC and access points
-
05
Design the security architecture
Place controls within the topology rather than around it.
- Firewall
- NAC solution
- VPN
- IDS/IPS
-
06
Performance monitoring and testing
Validate the build and establish operational visibility.
- Network monitoring
- Logging and alerting
- Centralised management
Technologies and frameworks in scope
- Routing & switching
- VLAN / subnetting
- NAC
- VPN
- IDS/IPS
What you receive.
- 01Requirements and scope document
- 02Logical architecture covering IP addressing, subnetting, VLANs and routing
- 03Physical component selection against the logical design
- 04Security architecture covering firewall, NAC, VPN and IDS/IPS placement
- 05Monitoring, logging and centralised management design
What changes afterwards.
- A network that is designed rather than grown by accretion
- A documented addressing, segmentation and routing standard
- Security decided with the topology rather than bolted on after it
- Operational visibility established at build time
Also in Consulting & Infrastructure
All consulting servicesBefore you get in touch.
Do you decide the hardware before or after the logical design?
After — physical component selection (routers, switches, wireless controllers and access points) is chosen to implement the logical architecture, not the other way around.
Is security part of the network design, or a separate project?
Part of it — firewall, NAC, VPN and IDS/IPS placement are designed into the topology in the same sequence as the addressing and forwarding model, not bolted on afterwards.
Which network types does this cover?
LAN, WAN, WLAN and data centre — the type in scope is determined as part of the second stage of the methodology.
What comes after the network is designed?
Enterprise IT Infrastructure Deployment — installation, configuration and cutover — builds what this stage designs.