Network & Infrastructure Engineering
For small ISPs, WISPs, and regional operators — and any business whose network has outgrown the person who set it up — from an engineer who's a peer, not a vendor.
Thirteen years building and securing ISP infrastructure — and the software engineering to automate it. Most infrastructure consultants come from one side: they have run BGP in production, or they can ship the pipeline that manages it. The rare thing is both, and it is the difference between a design that looks right on a diagram and one that survives contact with real traffic, real change windows, and the person who has to operate it after you leave.
What you get
Routing & network design
BGP, OSPF, IS-IS, and MPLS designed, documented, and implemented — core routing operated across multiple markets on Cisco and Nokia platforms, plus DOCSIS/CMTS and PON access networks. The as-built documentation is part of the deliverable, not an extra.
Firewall migrations & segmentation
Fortigate-to-Palo Alto migrations done in production: security policy translated, traffic flows validated before cutover, rollback planned. VLAN/VRF segmentation designed and verified — default-deny where it belongs, and an access model someone else can maintain.
Defensive infrastructure security
Perimeter, segmentation, access control, secrets management, and hardening — the security that comes from how the infrastructure is built. Explicitly not pentesting, appsec, or SOC 2 certification; if you need those, I will say so and point you at the right kind of firm.
Price
Infrastructure Assessment
Network topology, addressing, segmentation and security posture, written up.
scope cap · 1 site or 1 logical estate
Network design & documentation
Topology, addressing plan, segmentation design and as-built docs.
scope cap · 1 site
Firewall migration
Policy translation and traffic validation.
scope cap · 1 pair / 1 policy set
Segmentation build
VLAN/VRF design implemented and verified.
scope cap · ≤6 segments
Access & hardening pass
SSH, least privilege, default-deny, encryption at rest.
scope cap · ≤20 hosts
Work beyond a scope cap is a separate line item at its published price, agreed before it starts — that is what keeps a fixed price fixed. No hourly billing. See every line item →
How I work
The operating history is the approach: thirteen years running ISP infrastructure serving roughly half a million subscribers across fifteen markets, including a full network and billing migration for a market acquisition. The habit that work builds — document what is actually there, validate before cutover, assume the failure you have not seen yet — is what you are hiring. And the current practice is written down honestly, gaps included, because an engineer who documents what is not protected is the one you want looking at what you have.
FAQ
Is this security consulting?
It is defensive infrastructure security — perimeter design, segmentation, access control, secrets, hardening. It is not penetration testing, application security, red-teaming, or SOC 2 / compliance certification. That distinction is stated up front so the word 'security' never oversells.
Can you work on our live network?
Yes — that is where this experience comes from. Production changes get a written plan, a validation step before cutover, and a rollback path. The migrations I have run were staged so the business kept operating through them.
What platforms do you know?
Cisco and Nokia routing, DOCSIS/CMTS and PON (Calix, Nokia) access, Palo Alto and Fortigate firewalls, and the Linux, Proxmox, Terraform, and Kubernetes layer underneath. The design principles transfer; the platform list is where they have already been applied in production.