VPN, firewalls, zero trust, secure remote access
Site-to-site VPN builds, secure remote access rollouts, firewall rebuilds, and zero-trust network access. Led by a US Air Force veteran with a Cyber Transport Systems and cybersecurity background — the military discipline for building and defending mission-critical network infrastructure. Enterprise-grade design at project prices.
Who this is for
Signals it's time to bring in an outside engineer for this work.
Your VPN is legacy hardware from 2015
Slow, unreliable, unsupported. Time to move to Cisco AnyConnect, WireGuard, or SASE. We design, migrate, and cut over.
Remote work made your perimeter meaningless
Users are everywhere, apps are everywhere, the "office network" no longer defines the security boundary. We design zero-trust and roll it out phased.
Your firewall rule set is 10 years of accumulated cruft
Nobody knows why half the rules exist. We audit, document, rebuild with named objects and change control.
You need site-to-site connectivity between offices, DC, or cloud
IPsec, dynamic routing, redundancy, failover. Buffalo to remote branches, on-prem to Azure/AWS, all normal work.
What we deliver
The specific capabilities we scope, build, and hand off.
VPN builds & migrations
Cisco AnyConnect, SonicWall, Fortinet, WireGuard. Site-to-site or remote-access. Full cutover with parallel run and rollback.
Firewall rebuilds & audit
Cleanup of stale rules, named object model, change control process, weekly rule review discipline. Vendor-agnostic (Cisco, Fortinet, SonicWall, Palo Alto).
Zero-trust network access
Cloudflare Zero Trust, Zscaler, Tailscale. Identity-based access to internal apps without exposing the network.
Network segmentation
VLAN design, micro-segmentation, PCI zone separation, guest Wi-Fi isolation. Design + implementation + documentation.
Wi-Fi design & deploy
Enterprise Wi-Fi (Ubiquiti, Meraki, Ruckus). Site survey, AP placement, controller setup, captive portal, guest network.
Site-to-site + cloud connectivity
IPsec tunnels between offices, on-prem to Azure/AWS, ExpressRoute or Direct Connect setup, BGP dynamic routing.
A typical engagement
Sample scope: VPN modernization for 50-user org
- Current-state audit of existing VPN hardware, licensing, and remote-access patterns
- Design doc: Cisco AnyConnect (or alternative) with MFA via Duo or Azure MFA
- Firewall reconfiguration: named object model, cleaned rule set, split-tunnel policy
- Client rollout to all 50 users with automated deploy (Intune / Jamf / GPO)
- Parallel run for 2 weeks, cutover of legacy VPN with rollback ready
- Documentation: architecture diagram, admin runbook, user onboarding guide
Timeline
3 to 6 weeks
Fixed fee from
$8,500
Confirmed in SOW
Platforms we deploy for networking & security
Common questions
We're a Buffalo-area business. Do you come on site or do everything remotely?
Both. Cabling, hardware install, and hands-on troubleshooting are on-site (Buffalo, Hamburg, Orchard Park, East Aurora included). Design, configuration, and monitoring are remote by default. We're usually on-site for the initial cutover of anything critical.
Do you sell the hardware or do we source it?
You source. Hardware is billed at cost with the vendor invoice provided. No markup. We can spec exactly what to order and from where.
Are you a Cisco/Fortinet/SonicWall partner?
Registered partners with Cisco and Ubiquiti; long-time deployers of Fortinet, SonicWall, and Palo Alto. We are genuinely vendor-agnostic and recommend based on your environment, not commission.
Can you do zero-trust without ripping out our current firewall?
Usually yes. Cloudflare Zero Trust and Tailscale sit alongside your existing perimeter and cover specific app-level access. We phase them in without disruption to the current setup.
What about security assessments / penetration testing?
We do infrastructure security posture reviews (config audits, patching status, network exposure). We do not perform penetration testing; we refer that work to specialized firms and integrate the findings.
Ready to scope a project?
Book a 15-minute discovery call. We'll listen, ask questions, and tell you plainly whether the engagement is a fit.