The rest of the blog is how — command by command. This is why and when: the design decisions you make before you configure anything. Which topology, how to segment, where the firewall goes, how to survive failure, and the reference blueprints that turn all of it into a real build. Each guide links down into the config posts that implement it.
Good networks aren't configured into existence — they're designed, then configured. These ten guides are the design layer that sits above the Cisco and MikroTik how-to series: vendor-neutral decisions about shape, trust, resilience, and scale, each cross-linked down into the posts that build it on real gear.
Read top to bottom as a course in network design, or jump to the decision you're facing. Every guide opens with the trade-off, gives you a decision table, and is honest about when the fancy option is over-engineering — because knowing when not to reach for spine-leaf or SD-WAN is as much the job as knowing how.
Part 1
The two decisions everything else follows from — the topology, and how you carve it up.
01Collapsed-Core vs Three-Tier vs Spine-LeafThe topology decision — device count, failure domain, and bandwidth traded across three shapes, with a one-table guide.5 min→ 02Designing SegmentationEnumerate trust zones by blast-radius, build a default-deny matrix, and pick the right enforcement per boundary.5 min→Part 2
How sites connect, and how your network meets the internet.
03Hub-Spoke vs Mesh vs SD-WANThe multi-site WAN shape — and why dynamic-shortcut overlays give much of SD-WAN's benefit without the subscription.5 min→ 04The Multihomed EdgePA dual-WAN vs PI+BGP, active/backup vs active/active, and where NAT/CGNAT belongs (double-NAT and Starlink traps).5 min→ 05Spine-Leaf & VXLAN/EVPNThe modern fabric — a routed ECMP underlay, a VXLAN overlay, and EVPN as the BGP control plane that scales it.5 min→Part 3
Where the walls go, and how you keep trust from leaking across them.
06Perimeter & DMZ DesignFirewall placement, the load-bearing DMZ-to-LAN deny rule, and safe patterns for publishing services.5 min→ 07Zero-Trust SegmentationZero trust minus the marketing — identity-driven microsegmentation, and the 80/20 on gear you already own.5 min→ 08Out-of-Band ManagementWhy you can't fix a down network over the down network — isolated management, console access, independent recovery.5 min→Part 4
Designing to survive failure, and the blueprints that put it all together.
09Designing for FailureA systematic SPOF audit across every layer — matching redundancy to the cost of downtime, and testing it by causing failure.5 min→ 10SMB Reference DesignsThe common skeleton plus the trade-specific twist for a hotel, a clinic, and a professional office — from real builds.4 min→NOCTIS designs right-sized network architectures across Crete — topology, segmentation, edge, and resilience — matched to your scale and trade, then built and documented on Cisco or MikroTik.
Book a Discovery Call →