Colour coded patch cabling in a rack
Network Setup & Infrastructure

Switching and routing built around the site.

Cameras, door controllers, phones, computers, wireless access points, guest devices and building systems all need connectivity, but they should not all have unrestricted access to one another. We separate systems where it matters and control how they communicate.

Segmentation is the whole point

Most buildings end up with one physical network carrying everything, and that is normal. What matters is that the traffic on it is separated: cameras apart from door control, apart from voice, apart from staff devices, apart from anything a guest can reach.

Done properly, a compromised device stays a problem in one place instead of becoming a problem everywhere. That is the practical argument for segmentation, and it is worth more than any single security product.

Wireless access point and switching serving a building

What the work covers

  • Managed switching, layer 2 and layer 3, sized to the site
  • VLANs per system: users, guests, cameras, access control, voice, building systems
  • Routing, inter VLAN policy, addressing, DHCP and DNS
  • Firewall policy, network address translation, VPN and remote access
  • Secure wireless for staff, guests and devices, separated by VLAN
  • Power over Ethernet budget planned across switches and ports
  • Quality of service so voice and video stay usable under load
  • Monitoring and documentation handed over at commissioning

Power budget is the thing most often got wrong

Cameras, access points, phones and door devices are usually all powered over the same cabling. We add up what the site will actually draw, including phase two, and size switch capacity and port budget to carry it with headroom rather than at the limit.

Voice and video get priority, or they get unusable

A call and a large file transfer competing for the same link has one obvious loser. Quality of service policy puts real time traffic first, which is what keeps calls clean and meetings watchable when the network is busy.

Security systems are network systems now

Cameras, recorders, access control, door controllers and intercoms all live on the network, and each has its own bandwidth, power and isolation requirement. Designing for them up front avoids retrofitting a network that was only ever planned for computers.

More than one site, connected properly

Site to site VPN or secure WAN links buildings together with one set of policies applied centrally, so a second location is an extension of the network rather than a second network to administer.

You own the configuration

Addressing plan, VLAN scheme, firewall policy, credentials and documentation are handed to you at commissioning. Nothing about the network depends on us still being in the picture.

Switching installed with dressed cabling

Visibility before somebody reports a fault

Monitoring reports device failures, port errors, congestion and anything that has gone offline. Knowing a camera stopped talking three weeks ago is worth considerably more than finding out when you need the footage.

Network equipment rack with switching and power distribution

It has to come back up on its own

Power cuts, and what matters is what happens at three in the morning with nobody on site. Boot order, addressing and failover are set so the site recovers by itself rather than waiting for somebody to drive in.

Security is architecture, not an add on

A flat network where every device can reach every other device is one compromised printer away from a building wide incident. We segment by function with VLANs and inter zone firewall policy, so cameras, door controllers, voice, staff and guests each live in their own controlled space.

Management interfaces get their own protected segment, remote access arrives through VPN rather than exposed ports, and the configuration is documented and handed over. Your network should be auditable by any competent third party without us in the room.

Common questions

What is network segmentation and why does my business need it?

Splitting one physical network into separated zones so cameras, door controllers, phones, staff and guests cannot all reach each other. It keeps one compromised device from becoming a building wide problem.

Should guest WiFi be separate from the business network?

Yes, always. Guests get internet and nothing else: no cameras, no servers, no staff devices, no management interfaces. That separation is configuration, and it either exists or it does not.

What network does a VOIP phone system need?

Quality of service so calls beat file transfers, a voice VLAN, and power over Ethernet sized for the handsets. We configure all three because voice quality is decided by the network before the phones.

How is power over Ethernet capacity planned?

By adding up what cameras, access points, phones and door devices will actually draw, including the second phase, then sizing switch budgets with headroom rather than at the limit.

Can you monitor the network for problems?

Yes. Monitoring reports device failures, port errors, congestion and anything offline, so a camera that stopped talking is noticed long before its footage is needed.

How We Deliver

One team from design through commissioning

We cover the full project rather than turning up to install somebody else's design. That is what makes the result somebody's responsibility.

1

Design

We walk the building, work out what it needs to do and produce a design you can actually price against.

2

Procurement

We source the equipment and stand behind what we specify, so there is one party accountable for it.

3

Installation

Our own crews on site for cabling, mounting, terminations and containment.

4

Commissioning

Everything configured, tested and handed over with the records, credentials and documentation.

Tell us about the building

Send us the site and what you are trying to solve. We will tell you what it realistically takes.

Our Partners

Cisco
Cisco Meraki
Fortinet
HPE Aruba Networking
Ubiquiti UniFi
TP-Link
D-Link
Ruckus Networks