Ilyass MotyaIlyass Motya
Back to case studies

Enterprise network & security infrastructure at scale

Enterprise network & security infrastructure at scale

Five years of enterprise IT infrastructure consulting: Cisco-based network design, Fortinet firewalling, multi-cloud connectivity — from ad-hoc subnets to designed, documented, operated infrastructure.

5+

years of enterprise infrastructure consulting

3

cloud providers connected with Aviatrix fabrics

Context

Enterprise IT groups in Morocco grew networks the way most do — one project at a time, no single architectural owner. The result is familiar: ad-hoc subnets, undefined boundaries, firewalls layered instead of designed, and a security posture that lives in whoever has the credentials. Across a five-year consulting practice I was brought in where the plumbing had to scale — where the network had to carry business growth, cloud migration, and security requirements simultaneously without collapsing under its own complexity.

The problem it fixes

Most enterprise networks in the region were built incrementally: a switch here for a new office, a firewall there after a scare, VPN tunnels opened ad hoc for vendors, and cloud connectivity bolted on as an afterthought. The result was a flat, undocumented topology where nobody could answer basic questions — which VLAN connects to which firewall zone? What traffic crosses the internet link? Who has access to what? When something broke, the troubleshooting started with a phone call to whoever built it, and that person had usually moved on.

The idea: architecture before equipment

Instead of buying gear and figuring out the design later, every engagement started with topology: VLAN schemas that mapped to business functions, not physical office layout; firewall zones that enforced policy, not just perimeter defense; IP addressing that could be extended without renumbering; and documentation that lived in a repository, not in someone's head. The shift was from reactive vendor calls to a designed infrastructure that could be operated, extended, and defended by the team that inherited it.

Network design that operates

Cisco-based LAN and WAN designs with proper segmentation: access layers sized for actual device density, distribution layers that aggregated cleanly, and core routing that didn't rely on flat switching. Wireless designed for industrial and office environments differently — separate SSIDs, separate VLANs, separate policies. IP addressing schemas documented and maintained. DNS and DHCP architected for resilience, not just defaults. Every design came with configuration templates, change procedures, and a handover document that a new engineer could read without calling the consultant.

Security that enforces, not just blocks

Fortinet firewalls deployed with explicit rule structure: application-level policies, not just port-based permits. VPN tunnels governed with authentication, logging, and least-privilege access — vendor X can reach appliance Y on port Z during maintenance window W, nothing else. Network monitoring that made faults visible: SNMP-based device health, flow analysis for traffic patterns, and alerting that reached the right person at the right time. The security layer was designed to be operated by the internal team, not to require a specialist on call.

Multi-cloud without the sprawl

AWS, Azure and Alibaba estates needed connected, and connectivity done wrong creates an attack site out of thin air. I designed multi-cloud network fabrics — Aviatrix-based control of routing and segmentation across providers — so that hybrid environments stayed as defensible as the on-prem ones. Transit gateways, peering relationships, and VPN interconnects all followed the same segmentation logic: production traffic isolated from development, management access separated from user access, and every cross-cloud path documented and monitored.

Results

Networks that ran without fire drills. Defined boundaries, an operated security layer, documents a new engineer can read, and internal teams that could run and extend the infrastructure themselves. Clients stopped buying infrastructure projects and started buying outcomes — a network that scaled with the business, a security posture that could be demonstrated to auditors, and cloud connectivity that didn't create new attack surfaces. The shift from ad-hoc to architectural was visible in the reduced number of emergency calls and the increased number of planned changes.

Next steps

Most plant IT/OT environments inherit the same ad-hoc history — check whether yours does before a breach discovers the topology for you. The same architectural discipline that transforms enterprise networks transforms industrial ones: design first, document always, operate deliberately.

Similar case studies

FMCG

IT/OT foundations across 100+ food plants worldwide

Full story
IT/OT foundations across 100+ food plants worldwide
100+production sites on one IT/OT foundation standard
Zeroproduction downtime as the operating standard
2025project