Design and Infrastructure
How many users, how many devices, which traffic. The IP plan, VLAN scheme, cabling and access point layout are drawn and handed to you as documents before anything is installed.
From network design to router and switch configuration, from firewall and VPN deployment to 24/7 monitoring — the whole corporate network from one team.
Done Dynamics delivers network infrastructure, network security, network management and monitoring as one service. Three requests come in more often than any other: firewall rule writing and the review of an existing rule set, site-to-site VPN between branches, and ongoing network management as a monthly service. Alongside those we combine firewall deployment, content filtering, VLAN segmentation and access control. Router and switch configuration lives in version control; every change is documented and stays revertible.
Each can be bought separately, but they work when built together; piecemeal networks lose the line of responsibility.
How many users, how many devices, which traffic. The IP plan, VLAN scheme, cabling and access point layout are drawn and handed to you as documents before anything is installed.
Firewall deployment, rule sets, content filtering, intrusion detection and segmentation. Guest, staff and server traffic never mix.
Router and switch configuration lives in version control; every change is recorded with who, when and why. Firmware and patches run on a schedule.
Link state, bandwidth, error counters and device temperature are watched continuously, with thresholds set to fire before a user complains.
Four questions. If your answers point to a single device swap, we say that too.
From firewall and VPN deployment to VLAN segmentation, from device configuration to wireless coverage surveys.
Enterprise-grade firewall hardware and software setup, NAT and port forwarding, application awareness and logging. Log retention and configuration backup are arranged while the device goes live.
Every rule carries its reason, its requester and its date in writing, and an impact analysis is run before any change. Conflicting and shadowed rules are identified, and unused ones are closed at the periodic review. We also take over an existing set of hundreds of rules, document it and reduce it.
Two or more locations behave as a single network, with IP range overlaps prevented from the start and routing managed centrally. WireGuard or IPsec is chosen to match existing hardware; critical sites get a backup line, and configuration stays central as the branch count grows.
Client VPN for remote workers: access to internal resources through an encrypted tunnel, with multi-factor authentication and device-level authorisation. Services such as remote desktop are reached without leaving a port open to the internet.
Routing tables, VLANs, trunking and link aggregation, spanning tree, QoS and port security. Configurations are backed up and always revertible.
Accounting, production, guest and camera traffic in separate segments. A compromised device in one cannot move laterally into another.
Category-based access policy, malicious domain blocking and working-hours rules, designed together with any logging obligation that applies.
Coverage survey, access point placement, channel planning, roaming and capacity planning — measured on site in demanding environments like hotels and plants.
What the monthly service covers: periodic rule review, a firmware and patch schedule, configuration backups and a capacity report. Incident response, keeping the device inventory current and a written change log are included.
Most networks we find on site grew by accretion over years, with no diagram anyone can produce. Documents first, cabling second.
Measure first, buy hardware second
No device is recommended before a site survey and traffic measurement. Most network problems are answered by configuration rather than by new equipment.
Configuration under version control
Router and switch configs live in a repository. The before and after of every change is visible, and a bad rule is reverted in minutes.
Segmentation by default
A flat network is a door to the whole organisation the moment one device is compromised. Guest, staff, server and camera traffic are separated from day one.
Logging and compliance
Where public access is offered, the legal logging obligation is part of the deployment — signed retention and defined access rights included.
Someone is on call
Monitoring alerts reach us directly. Incident records, response times and resolution steps are reported in writing.
Handover built in
The diagram, IP plan, configuration files and credentials belong to you. Changing provider does not mean rebuilding from scratch.
Five stages, with any step requiring downtime written up front and moved outside working hours.
Device inventory, cabling condition, coverage measurement and traffic profile. The output is a report: what stays and what needs to change.
IP plan, VLAN scheme, routing and security policy are documented. No cable is touched before you approve them.
Device configuration, firewall rules, VPN and wireless infrastructure go live. The cutover plan is written first to keep downtime minimal.
Inter-segment access tests, VPN connection tests, coverage measurement and load testing, with results reported.
Continuous monitoring, firmware updates, rule review and periodic configuration backups.
The installation project is fixed-price, with its scope written into the site survey report so it does not grow mid-build. Ongoing management and monitoring runs monthly, priced by device count, including incident response and periodic rule review. The survey and design report is a separate first step — take the report and continue with another team if you prefer; the documents are yours either way.
The eight things we are asked about most, each covered end to end.
Rules written with a reason attached, shadowed rules found and closed, an existing tangle taken over.
Remote access, site-to-site tunnels, IP range collisions and failover links.
Configuration under version control, VLANs, QoS and a firmware update schedule.
Segmentation, cutting lateral movement, isolating devices that can no longer be patched.
Seeing an outage before your users do, capacity trends, what monthly maintenance covers.
IP plan, VLAN scheme, structured cabling and wireless coverage surveys.
802.1X authentication, device profiling, dynamic VLAN assignment and phased rollout.
Multi-site networks from one dashboard, template-driven rollout, Auto VPN and SD-WAN.
Related services
Compliant logging, user verification and a branded captive portal for hotels, hospitals and offices.
The user side of the network: workstations, office applications, installation and software support.
Testing the network and the applications on it from an attacker perspective, with a severity-rated report.
The servers at the end of the network: private hosting, web hosting and getting your project live.
Book a free 30-minute discovery call with our team.
Our network and cyber security work is carried out by a team holding internationally recognised Cisco certification.
Issued by Cisco · Holder: Devrim Tunçer
A certification covering security operations centre (SOC) competency: security monitoring, incident response and analysis of network attacks. It is the foundation we rely on for intrusion detection, log correlation and post-incident response work.
Cisco training certificate · completed January 2023
Covers networking fundamentals: routing, switching, IP addressing and network security. The knowledge base we draw on for enterprise network setup and segmentation.
The first question we ask on site is whether a network diagram exists. The answer is usually no. Networks grow by accretion rather than design — a new office, another switch; a printer for accounting, another cable; a camera system installed by whoever had a free port. Five years later the network infrastructure carrying every process in the building is one nobody fully understands.
The gap becomes visible on a bad day: the connection slows and nobody can say why, a device is compromised and nobody can map how far it reached, a branch needs access and nobody knows how it should be granted. We start by measuring and drawing what exists, then build the security and management layers on top.
Network design does not begin with picking devices. How many users, how many devices, which traffic goes where — those come first. In a hotel where guest traffic and the reservation system share one link, reception freezing on a full night is not a surprise. In a plant where line controllers and office machines share a broadcast domain, one misconfigured device can stop production.
The design produces three documents: an IP plan, a VLAN scheme and a physical layout. Without them, growing networks accumulate overlapping ranges and static addresses nobody dares touch. On the wireless side design is done by measurement, because concrete, metal racks and a neighbour's network affect coverage in ways a floor plan cannot predict.
Network security answers two questions: what gets in from outside, and who can reach whom inside. The first is solved with a firewall and its rule set, the second with segmentation. Most organisations have the first and lack the second — and the real damage in an incident comes from that gap.
Malware on one employee's machine reaches everything that machine can reach. On a flat network that means the accounting server, the backup disk, the camera recorder and the production controller. VLAN segmentation cuts that lateral path. What matters in a firewall is not the number of rules but whether they can still be understood: every rule we write carries its reason and its requester, and unused rules are closed at periodic review.
The most common mistake we find is a remote desktop port opened to the internet so someone can reach an internal machine. Automated scanners find that port within minutes. A VPN is the alternative: the user joins an encrypted tunnel first, then reaches internal resources, and multi-factor authentication makes a stolen password insufficient on its own. We deploy WireGuard, IPsec and OpenVPN, and site-to-site links between branches.
Device configuration is code. Router and switch configs live in a version-controlled repository, so the before and after of every change is visible and a bad rule is reverted in minutes. Firmware updates run on a written schedule, with a configuration backup taken before each one and devices past vendor support tracked on a separate list.
The shortest test of network maturity is who notices an outage first. If the answer is "when a user complains", there is no monitoring, and most of the downtime is spent discovering that a problem exists. We measure link state, bandwidth saturation, interface error counters, device temperature and the reachability of critical services, with thresholds set to fire before users notice.
What we hand over matters as much as what we build: the diagram, the IP plan, the VLAN table, the reasoning behind firewall rules, the device inventory and the configuration files all sit with the organisation. Credentials live in your own vault; our access runs through separate, logged accounts. Continuing with us should be a choice rather than a dependency.