Service detail

Network Infrastructure, Security and Management

From network design to router and switch configuration, from firewall and VPN deployment to 24/7 monitoring — the whole corporate network from one team.

Done Dynamics delivers network infrastructure, network security, network management and monitoring as one service. Three requests come in more often than any other: firewall rule writing and the review of an existing rule set, site-to-site VPN between branches, and ongoing network management as a monthly service. Alongside those we combine firewall deployment, content filtering, VLAN segmentation and access control. Router and switch configuration lives in version control; every change is documented and stays revertible.

Four pillars

Design, security, management, monitoring

Each can be bought separately, but they work when built together; piecemeal networks lose the line of responsibility.

Design and Infrastructure

How many users, how many devices, which traffic. The IP plan, VLAN scheme, cabling and access point layout are drawn and handed to you as documents before anything is installed.

Network Security

Firewall deployment, rule sets, content filtering, intrusion detection and segmentation. Guest, staff and server traffic never mix.

Network Management

Router and switch configuration lives in version control; every change is recorded with who, when and why. Firmware and patches run on a schedule.

Monitoring

Link state, bandwidth, error counters and device temperature are watched continuously, with thresholds set to fire before a user complains.

2 minutes · 4 questions

Does your network cause trouble as it grows?

Four questions. If your answers point to a single device swap, we say that too.

Do you have a current network diagram and IP plan?

Question 1 / 4

Do you have a current network diagram and IP plan?

Scope

What we build

From firewall and VPN deployment to VLAN segmentation, from device configuration to wireless coverage surveys.

Firewall Deployment

Enterprise-grade firewall hardware and software setup, NAT and port forwarding, application awareness and logging. Log retention and configuration backup are arranged while the device goes live.

Firewall Rule Writing and Review

Every rule carries its reason, its requester and its date in writing, and an impact analysis is run before any change. Conflicting and shadowed rules are identified, and unused ones are closed at the periodic review. We also take over an existing set of hundreds of rules, document it and reduce it.

Site-to-Site VPN (Between Branches)

Two or more locations behave as a single network, with IP range overlaps prevented from the start and routing managed centrally. WireGuard or IPsec is chosen to match existing hardware; critical sites get a backup line, and configuration stays central as the branch count grows.

VPN Setup

Client VPN for remote workers: access to internal resources through an encrypted tunnel, with multi-factor authentication and device-level authorisation. Services such as remote desktop are reached without leaving a port open to the internet.

Router and Switch Configuration

Routing tables, VLANs, trunking and link aggregation, spanning tree, QoS and port security. Configurations are backed up and always revertible.

VLAN Segmentation

Accounting, production, guest and camera traffic in separate segments. A compromised device in one cannot move laterally into another.

Content Filtering

Category-based access policy, malicious domain blocking and working-hours rules, designed together with any logging obligation that applies.

Wireless Infrastructure

Coverage survey, access point placement, channel planning, roaming and capacity planning — measured on site in demanding environments like hotels and plants.

Ongoing Network Management

What the monthly service covers: periodic rule review, a firmware and patch schedule, configuration backups and a capacity report. Incident response, keeping the device inventory current and a written change log are included.

How we work

A network is drawn before it is built

Most networks we find on site grew by accretion over years, with no diagram anyone can produce. Documents first, cabling second.

  • Measure first, buy hardware second

    No device is recommended before a site survey and traffic measurement. Most network problems are answered by configuration rather than by new equipment.

  • Configuration under version control

    Router and switch configs live in a repository. The before and after of every change is visible, and a bad rule is reverted in minutes.

  • Segmentation by default

    A flat network is a door to the whole organisation the moment one device is compromised. Guest, staff, server and camera traffic are separated from day one.

  • Logging and compliance

    Where public access is offered, the legal logging obligation is part of the deployment — signed retention and defined access rights included.

  • Someone is on call

    Monitoring alerts reach us directly. Incident records, response times and resolution steps are reported in writing.

  • Handover built in

    The diagram, IP plan, configuration files and credentials belong to you. Changing provider does not mean rebuilding from scratch.

Process

From survey to continuous monitoring

Five stages, with any step requiring downtime written up front and moved outside working hours.

  1. 01

    Site Survey

    Device inventory, cabling condition, coverage measurement and traffic profile. The output is a report: what stays and what needs to change.

  2. 02

    Design

    IP plan, VLAN scheme, routing and security policy are documented. No cable is touched before you approve them.

  3. 03

    Deployment

    Device configuration, firewall rules, VPN and wireless infrastructure go live. The cutover plan is written first to keep downtime minimal.

  4. 04

    Verification

    Inter-segment access tests, VPN connection tests, coverage measurement and load testing, with results reported.

  5. 05

    Monitoring and Maintenance

    Continuous monitoring, firmware updates, rule review and periodic configuration backups.

Commercial model

Fixed project, monthly management

The installation project is fixed-price, with its scope written into the site survey report so it does not grow mid-build. Ongoing management and monitoring runs monthly, priced by device count, including incident response and periodic rule review. The survey and design report is a separate first step — take the report and continue with another team if you prefer; the documents are yours either way.

Detail pages

Every topic has its own page

The eight things we are asked about most, each covered end to end.

Ready for your next software project?

Book a free 30-minute discovery call with our team.

Certifications

Our network and cyber security work is carried out by a team holding internationally recognised Cisco certification.

Cisco CyberOps Associate badge

Cisco CyberOps Associate

Issued by Cisco · Holder: Devrim Tunçer

A certification covering security operations centre (SOC) competency: security monitoring, incident response and analysis of network attacks. It is the foundation we rely on for intrusion detection, log correlation and post-incident response work.

Cisco CCNA Training

expired

Cisco training certificate · completed January 2023

Covers networking fundamentals: routing, switching, IP addressing and network security. The knowledge base we draw on for enterprise network setup and segmentation.

Network infrastructure: the network nobody can draw

It grew, it was not designed

The first question we ask on site is whether a network diagram exists. The answer is usually no. Networks grow by accretion rather than design — a new office, another switch; a printer for accounting, another cable; a camera system installed by whoever had a free port. Five years later the network infrastructure carrying every process in the building is one nobody fully understands.

The gap becomes visible on a bad day: the connection slows and nobody can say why, a device is compromised and nobody can map how far it reached, a branch needs access and nobody knows how it should be granted. We start by measuring and drawing what exists, then build the security and management layers on top.

Design before cabling

Network design does not begin with picking devices. How many users, how many devices, which traffic goes where — those come first. In a hotel where guest traffic and the reservation system share one link, reception freezing on a full night is not a surprise. In a plant where line controllers and office machines share a broadcast domain, one misconfigured device can stop production.

The design produces three documents: an IP plan, a VLAN scheme and a physical layout. Without them, growing networks accumulate overlapping ranges and static addresses nobody dares touch. On the wireless side design is done by measurement, because concrete, metal racks and a neighbour's network affect coverage in ways a floor plan cannot predict.

Security: firewall and segmentation

Network security answers two questions: what gets in from outside, and who can reach whom inside. The first is solved with a firewall and its rule set, the second with segmentation. Most organisations have the first and lack the second — and the real damage in an incident comes from that gap.

Malware on one employee's machine reaches everything that machine can reach. On a flat network that means the accounting server, the backup disk, the camera recorder and the production controller. VLAN segmentation cuts that lateral path. What matters in a firewall is not the number of rules but whether they can still be understood: every rule we write carries its reason and its requester, and unused rules are closed at periodic review.

VPN, router and switch configuration

The most common mistake we find is a remote desktop port opened to the internet so someone can reach an internal machine. Automated scanners find that port within minutes. A VPN is the alternative: the user joins an encrypted tunnel first, then reaches internal resources, and multi-factor authentication makes a stolen password insufficient on its own. We deploy WireGuard, IPsec and OpenVPN, and site-to-site links between branches.

Device configuration is code. Router and switch configs live in a version-controlled repository, so the before and after of every change is visible and a bad rule is reverted in minutes. Firmware updates run on a written schedule, with a configuration backup taken before each one and devices past vendor support tracked on a separate list.

Monitoring, and leaving a network someone else can take over

The shortest test of network maturity is who notices an outage first. If the answer is "when a user complains", there is no monitoring, and most of the downtime is spent discovering that a problem exists. We measure link state, bandwidth saturation, interface error counters, device temperature and the reachability of critical services, with thresholds set to fire before users notice.

What we hand over matters as much as what we build: the diagram, the IP plan, the VLAN table, the reasoning behind firewall rules, the device inventory and the configuration files all sit with the organisation. Credentials live in your own vault; our access runs through separate, logged accounts. Continuing with us should be a choice rather than a dependency.

Frequently asked questions

Can our existing devices be used, or does everything need replacing?
Most of it usually stays. The site survey records each device's model, firmware and vendor support status, and reports what is sufficient and what needs replacing with the reasoning written down — capacity, missing security updates or end of vendor support.
Which VPN technology do you use?
WireGuard, IPsec or OpenVPN depending on need. WireGuard leads on speed and simplicity in modern deployments; where existing hardware only supports IPsec we work with that. Site-to-site between branches, client VPN for remote workers, multi-factor authentication recommended on both.
Where are router and switch configuration backups kept?
In a version-controlled repository, with a copy held by the organisation. The before and after of every change is visible and a bad rule is reverted in minutes. At the end of a contract all configurations, the diagram and access details are handed over.
What does monitoring cover and who receives the alerts?
Link outages, bandwidth saturation, interface error counters, device temperature and the reachability of critical services. Alerts reach us directly; critical ones also reach your named contact. The monthly report covers downtime, capacity trend and recurring incidents.
Why must the guest network be separated?
A guest device on the same network can reach internal servers, printers and camera systems. VLAN segmentation closes that path, and where public access is offered a separate guest network also addresses the legal logging obligation at the same time.
Will our work stop during the installation?
The cutover plan is written in advance and steps requiring downtime move outside working hours. For critical infrastructure a temporary parallel setup is arranged and a rollback step stays ready. Expected downtime is stated in the proposal.
How is the service priced?
The installation project is fixed-price; ongoing management and monitoring is a monthly service priced by device count. The site survey and design report is a separate first step, and the documents are yours even if you continue the build with another team.