Skip to main content
← All Practices
Practice: Networking & Security

VPN, firewalls, zero trust, secure remote access

Site-to-site VPN builds, secure remote access rollouts, firewall rebuilds, and zero-trust network access. Led by a US Air Force veteran with a Cyber Transport Systems and cybersecurity background — the military discipline for building and defending mission-critical network infrastructure. Enterprise-grade design at project prices.

Who this is for

Signals it's time to bring in an outside engineer for this work.

Your VPN is legacy hardware from 2015

Slow, unreliable, unsupported. Time to move to Cisco AnyConnect, WireGuard, or SASE. We design, migrate, and cut over.

Remote work made your perimeter meaningless

Users are everywhere, apps are everywhere, the "office network" no longer defines the security boundary. We design zero-trust and roll it out phased.

Your firewall rule set is 10 years of accumulated cruft

Nobody knows why half the rules exist. We audit, document, rebuild with named objects and change control.

You need site-to-site connectivity between offices, DC, or cloud

IPsec, dynamic routing, redundancy, failover. Buffalo to remote branches, on-prem to Azure/AWS, all normal work.

What we deliver

The specific capabilities we scope, build, and hand off.

VPN builds & migrations

Cisco AnyConnect, SonicWall, Fortinet, WireGuard. Site-to-site or remote-access. Full cutover with parallel run and rollback.

Firewall rebuilds & audit

Cleanup of stale rules, named object model, change control process, weekly rule review discipline. Vendor-agnostic (Cisco, Fortinet, SonicWall, Palo Alto).

Zero-trust network access

Cloudflare Zero Trust, Zscaler, Tailscale. Identity-based access to internal apps without exposing the network.

Network segmentation

VLAN design, micro-segmentation, PCI zone separation, guest Wi-Fi isolation. Design + implementation + documentation.

Wi-Fi design & deploy

Enterprise Wi-Fi (Ubiquiti, Meraki, Ruckus). Site survey, AP placement, controller setup, captive portal, guest network.

Site-to-site + cloud connectivity

IPsec tunnels between offices, on-prem to Azure/AWS, ExpressRoute or Direct Connect setup, BGP dynamic routing.

A typical engagement

Sample scope: VPN modernization for 50-user org

  • Current-state audit of existing VPN hardware, licensing, and remote-access patterns
  • Design doc: Cisco AnyConnect (or alternative) with MFA via Duo or Azure MFA
  • Firewall reconfiguration: named object model, cleaned rule set, split-tunnel policy
  • Client rollout to all 50 users with automated deploy (Intune / Jamf / GPO)
  • Parallel run for 2 weeks, cutover of legacy VPN with rollback ready
  • Documentation: architecture diagram, admin runbook, user onboarding guide

Timeline

3 to 6 weeks

Fixed fee from

$8,500

Confirmed in SOW

Platforms we deploy for networking & security

Cisco AnyConnectCisco ASACisco MerakiFortinet FortiGateSonicWallPalo AltoUbiquiti UniFiWireGuardCloudflare Zero TrustTailscaleAzure VPN GatewayAWS Site-to-Site VPNExpressRouteBGP

Common questions

We're a Buffalo-area business. Do you come on site or do everything remotely?

Both. Cabling, hardware install, and hands-on troubleshooting are on-site (Buffalo, Hamburg, Orchard Park, East Aurora included). Design, configuration, and monitoring are remote by default. We're usually on-site for the initial cutover of anything critical.

Do you sell the hardware or do we source it?

You source. Hardware is billed at cost with the vendor invoice provided. No markup. We can spec exactly what to order and from where.

Are you a Cisco/Fortinet/SonicWall partner?

Registered partners with Cisco and Ubiquiti; long-time deployers of Fortinet, SonicWall, and Palo Alto. We are genuinely vendor-agnostic and recommend based on your environment, not commission.

Can you do zero-trust without ripping out our current firewall?

Usually yes. Cloudflare Zero Trust and Tailscale sit alongside your existing perimeter and cover specific app-level access. We phase them in without disruption to the current setup.

What about security assessments / penetration testing?

We do infrastructure security posture reviews (config audits, patching status, network exposure). We do not perform penetration testing; we refer that work to specialized firms and integrate the findings.

Ready to scope a project?

Book a 15-minute discovery call. We'll listen, ask questions, and tell you plainly whether the engagement is a fit.