HomeTopologiesProjectsAbout

Network Topologies

Reference architectures and design patterns from enterprise campus to cloud-native security. Each topology includes a full diagram, component breakdown, and design rationale.

🏒
Enterprise

Campus LAN β€” Hierarchical 3-Tier

Classic core-distribution-access design for large campus environments. Covers redundancy, spanning tree, and inter-VLAN routing strategies.

Aruba CXSwitchingRoutingVSX
View topology β†’
πŸ”’
Security Soon

Zero Trust Network Access

Identity-centric access model eliminating implicit trust. Covers micro-segmentation, policy enforcement points, and continuous verification.

Palo AltoZTNAPrismaIAM
🌐
WAN Soon

SD-WAN with Dual-Cloud On-Ramp

Software-defined WAN connecting branches to AWS and Azure via dedicated cloud gateways. Covers QoS, path selection, and failover.

EdgeConnectAWSAzureBGP
☁️
Security

SASE β€” Converged Security & Networking

Secure Access Service Edge architecture combining SD-WAN, CASB, SWG, and ZTNA into a unified cloud-delivered service.

FortinetSASECASBSWG
View topology β†’
πŸ–₯️
Data Center

Data Center Spine-Leaf

Modern CLOS fabric topology for high-performance data center environments. VXLAN overlay with BGP EVPN for multi-tenancy.

JuniperVXLANBGP EVPNLeaf-SpineApstra
View topology β†’
πŸ›‘οΈ
Security

Perimeter NGFW

NGFW-based perimeter with DMZ, IPS, URL filtering, and SSL inspection. Active/passive HA with asymmetric routing handling.

FortinetIPSSSL InspectionHA
View topology β†’
πŸ•ΈοΈ
Enterprise

Campus Fabrics

Software-defined campus using an overlay/underlay fabric architecture. Policy-based segmentation with automated provisioning and group-based access control.

EVPN-VXLANSPBMIS-IS
View topology β†’
πŸ“Ά
Wireless

WLAN β€” Guest Portal

Guest wireless architecture with captive portal authentication, hotspot onboarding, and policy-based network segmentation to isolate guest traffic.

ArubaCaptive PortalClearPass
View topology β†’
πŸ“‘
Wireless Soon

Wireless LAN β€” High-Density Deployment

High-density Wi-Fi 7 deployment for stadiums, conference centers, and open-plan offices. Tunneled SSID, band steering, and client load balancing.

ArubaWi-Fi 7Tunneled SSID802.11ax
πŸ”—
Cloud Soon

Hybrid Cloud Connectivity

Site-to-cloud connectivity patterns using Direct Connect, ExpressRoute, and partner interconnects alongside IPsec VPN fallback.

AWSAzureDirect ConnectExpressRoute