Service detail

Network Design and Corporate Deployment

Drawn first, built second. The IP plan, VLAN scheme and physical layout reach you before anything is installed.

Most of the networks we meet in the field were never designed; they grew as needs appeared. A modem arrived first, then a switch when headcount rose, then an access point when wireless was requested, then a second one when guests complained. Each step is reasonable on its own. What exists five years later is a structure nobody can draw, where nobody knows which cable goes where, and where every intervention is a gamble.

Network design replaces that accumulation with a planned structure. Our first rule in corporate network deployment is straightforward: a network is not built before it is drawn. Before any device is ordered, the IP plan, the VLAN scheme and the physical layout are put on the table as documents. No hardware is purchased until they are approved — because buying the right device for a badly designed network is the most expensive way to spend the budget.

Design deliverables

Three documents, before deployment

A network design has deliverables you can hold. "We have a plan in mind" is not a design.

IP plan

Which range serves which purpose, where static addresses begin and where the assignment pool ends. In networks that grew without a plan, overlapping ranges and untouchable static addresses pile up.

VLAN scheme

Staff, guests, servers, cameras and production devices in separate segments. Which segment may reach which is written into a table before deployment, and every later exception is recorded there.

Physical layout

Cabinet locations, cable routes, access point positions and the labelling convention. The goal is simple: not a single unlabelled cable left in the rack.

Of the three, the IP plan is the one most often skipped and the one that costs the most. In networks that grew without a plan, addresses were handed out from whichever range came to mind that day. A few years later, when two branches need to be joined, it turns out the same range is in use at both sites and the link between them fails for reasons of design rather than equipment. In the same way, static addresses accumulate with no record of who assigned them or why; nobody dares touch them because nobody knows which device would stop.

The VLAN scheme, meanwhile, is the physical counterpart of security policy. On a network where a guest device can see the finance server, what is written in the firewall matters rather less. Keeping cameras, payment terminals and production equipment in their own segments is decided at design time for the same reason — adding segmentation later means splitting a live network, and that always costs downtime.

Site survey

Design does not start before the building is seen

The output of a survey is a report rather than a quotation: what stays, what changes, and the reason for both. That report remains yours even if you do not continue with us.

  • Existing device inventory: make, model, firmware version, warranty status and whether it is manageable at all.
  • Cabling condition: how many runs exist, in which category, how they are terminated at the patch panel, and whether they carry labels.
  • Coverage survey: where the wireless signal actually reaches inside the building — measured against the floor plan, not estimated.
  • Traffic profile: how much load at which hour, which application fills the circuit, where the peaks sit.
  • Power and cabinet conditions: is there a UPS, is cabinet ventilation adequate, are there enough outlets.
  • Constraints: hours when downtime is impossible, devices that cannot be touched, and buildings where pulling cable is difficult.
Capacity and headroom

Thirty users today, fifty in three years

The most common mistake in network design is sizing for today. A forty-eight port switch is more than enough for thirty users now; three years later, with fifty users, two printers, eight cameras, a few meeting room displays and the handheld terminals in the warehouse, the same switch is full. What happens when it fills is predictable: an unmanaged desktop switch appears under a desk somewhere, and the day it does the network stops being observable.

Port count, cabling, cabinet space and power capacity are therefore planned against a three-year projection. Headroom matters most in cabling, because pulling cable afterwards is the most expensive and most disruptive part of the job: ceilings come down, trunking is opened, the office fills with dust. A few spare runs pulled during the original deployment cost almost nothing next to the same runs pulled three years later.

The same arithmetic applies to power. Where access points and cameras are fed over the data cable, the switch power budget has to be calculated up front; a device chosen at the margin will quietly stop delivering power once a few more cameras arrive. UPS capacity is likewise sized against how long it must keep the whole network up — a network that dies in a power cut also renders the protected server useless.

Structured cabling

The layer that outlives everything else

Devices are replaced; cable stays. The layer that receives the least attention is the one that deserves the most.

The longest-lived layer

A switch is replaced in five years, a firewall in three; cable stays for ten. That is why cabling decisions follow the next decade rather than the present headcount.

Labelling

Both ends of every run are labelled with the same convention and recorded on the rack diagram. In an unlabelled cabinet a simple port move takes half an hour; in a labelled one, two minutes.

Link testing

Every run is tested and the result goes into the handover file. A marginal cable does not fail outright — it produces a connection that drops occasionally and whose cause is never found.

Rack discipline

Cable management, unit placement, ventilation and earthing. A messy cabinet is not merely ugly; it produces thermal problems and cables pulled loose by accident.

Wireless design

Coverage is one thing, capacity another

Signal reaching everywhere and everyone working comfortably are not the same outcome. The real question in wireless design is not where the signal lands but how many devices are doing what at once.

  1. 1 A pre-deployment coverage survey: current signal levels and interference from neighbouring networks measured against the floor plan.
  2. 2 Channel plan: neighbouring access points sharing a channel slow each other down. Channel allocation is worked out floor by floor, neighbouring buildings included.
  3. 3 Capacity calculation: thirty people reading email is not the same demand as thirty people watching video in a lobby. Access point count follows capacity, not coverage.
  4. 4 Roaming: handing a client over between access points without dropping the session. Left unconfigured, a phone clings to the old access point and the call breaks.
  5. 5 A second survey after deployment: the same measurement is repeated and the two reports are compared. Whether the promise was kept is visible in those two documents.
Migration plan

Changing a live network is harder than building one

Cabling an empty building is easy. The difficult work is renewing the network of an organisation that operates every day without moving it off its feet. That is why the migration plan is inseparable from the design.

  1. 1 Steps that require downtime move outside business hours. How much downtime each step produces is written into the plan in minutes.
  2. 2 For critical infrastructure the old and new setups run in parallel for a period; the cutover is never attempted wholesale in one night.
  3. 3 Every step keeps a rollback path ready. If the new configuration does not behave as expected, returning to the previous one takes minutes.
  4. 4 Changes that affect users are announced beforehand; what changes on which day is shared in writing.
  5. 5 On the first business day after cutover, support is on site or immediately reachable so the small issues of day one close on day one.
Process

Five stages from survey to handover

Every stage has a deliverable; a stage without one is not finished.

  1. 01

    Site Survey

    Inventory, cabling, coverage and traffic profile are captured. The output is a report: what stays, what changes, and why.

  2. 02

    Design

    IP plan, VLAN scheme and physical layout are drawn. They reach you as documents before deployment, and no hardware is ordered until they are approved.

  3. 03

    Materials and Cabling

    Device selection follows the design. Cabling, labelling and rack build are completed at this stage and every run is tested.

  4. 04

    Configuration and Cutover

    Devices are staged first, then brought into service to plan. Steps requiring downtime move out of hours and the rollback path stays open.

  5. 05

    Handover and Documentation

    Diagram, IP plan, configuration files, link test results and passwords are handed to the organisation, along with the post-deployment coverage survey.

Handover

Someone else must be able to run what we built

The most practical way to judge a network deployment is this: if the team that built it disappeared tomorrow, how many days would it take a newcomer to become effective? In an undocumented installation the answer is measured in weeks, most of them spent tracing cables and hunting for device passwords.

The handover file is therefore part of the job rather than an extra to be requested later. It contains the network diagram, IP plan, VLAN table, device inventory, configuration files, link test results, coverage survey reports and passwords. Passwords are handed to a nominated officer of the organisation and can be changed by them — we never keep access to ourselves after a deployment.

There is a commercial consequence to this: we do not lock clients in through missing documentation. Taking ongoing network management from us should be a choice, not a necessity. Where it does continue, the documents produced during design become the foundation for monitoring, rule writing and capacity planning.

FAQ

Frequently asked

How long does a network design and deployment take?

Survey and design take a few days in a small office and one to two weeks in a multi-storey hotel or factory. The item that really drives the deployment schedule is cabling: if existing cabling can be reused, a week may be enough, while pulling cable from scratch in a difficult building can stretch the work to three to six weeks. The schedule is given step by step alongside the survey report.

Can our existing devices be reused, or does everything have to be replaced?

Usually a good part of it stays. The survey report assigns each device one of three outcomes: stays as is, stays with a different configuration, or has to be replaced. Where replacement is required the reason is written down as well — not manageable, not enough ports, end of vendor support, or no longer receiving security updates. We do not replace a working device merely because it is old.

Will work stop during deployment?

The aim is that it does not. Devices are staged during business hours and only the cutover steps produce downtime, which is scheduled out of hours. For critical infrastructure the old and new setups run in parallel for a period. How much downtime each step produces is written into the migration plan in minutes, and each step keeps a rollback path ready.

Is cabling included, or do you only install devices?

Structured cabling is part of the design. Route planning, cable category selection, rack layout, labelling convention and termination are ours. The physical pulling of cable is carried out together with regional crews, while responsibility and testing remain with us. Every run is tested and the result goes into the handover file.

What does the coverage survey report contain?

A signal level map against the floor plan, interference from neighbouring networks, channel usage, and an estimate of clients per access point. The survey is run twice: once before deployment to record the starting point and once after to record what was achieved. Both reports are handed over together, so what the deployment changed is not open to debate.

Can we continue with another team after deployment?

Yes, and we work in a way that makes it possible from the start. The network diagram, IP plan, VLAN table, configuration files, link test results and all passwords are handed to the organisation. We do not tie anyone in through missing documentation; whether an incoming team can do the job on day one is the measure of the handover file.

How do you calculate headroom for growth?

The design follows the three-year projection rather than today's headcount. If there are thirty users today and fifty are expected in three years, port count, cabling, cabinet space and power are planned accordingly. Pulling cable later is the most expensive part of the job, so a spare run left in place during deployment costs almost nothing next to the same run pulled three years from now.

How does pricing work?

We split the work in two. Survey and design are a separate fixed-fee item whose output — a report and a set of diagrams — stays with you even if you do not continue with us. Deployment is quoted once the design is approved, with hardware and cabling itemised openly. Equipment cost and labour appear on separate lines, and the reason each device was chosen is written down.

Ready for your next software project?

Book a free 30-minute discovery call with our team.

Certifications

Our network and cyber security work is carried out by a team holding internationally recognised Cisco certification.

Cisco CyberOps Associate badge

Cisco CyberOps Associate

Issued by Cisco · Holder: Devrim Tunçer

A certification covering security operations centre (SOC) competency: security monitoring, incident response and analysis of network attacks. It is the foundation we rely on for intrusion detection, log correlation and post-incident response work.

Cisco CCNA Training

expired

Cisco training certificate · completed January 2023

Covers networking fundamentals: routing, switching, IP addressing and network security. The knowledge base we draw on for enterprise network setup and segmentation.