Enterprise network & security infrastructure at scale

Five years of enterprise IT infrastructure consulting: Cisco-based network design, Fortinet firewalling, multi-cloud connectivity — from ad-hoc subnets to designed, documented, operated infrastructure.
5+
years of enterprise infrastructure consulting
3
cloud providers connected with Aviatrix fabrics
Context
Enterprise IT groups in Morocco grew networks the way most do — one project at a time, no single architectural owner. The result is familiar: ad-hoc subnets, undefined boundaries, firewalls layered instead of designed, and a security posture that lives in whoever has the credentials. Across a five-year consulting practice I was brought in where the plumbing had to scale — where the network had to carry business growth, cloud migration, and security requirements simultaneously without collapsing under its own complexity.
The problem it fixes
Most enterprise networks in the region were built incrementally: a switch here for a new office, a firewall there after a scare, VPN tunnels opened ad hoc for vendors, and cloud connectivity bolted on as an afterthought. The result was a flat, undocumented topology where nobody could answer basic questions — which VLAN connects to which firewall zone? What traffic crosses the internet link? Who has access to what? When something broke, the troubleshooting started with a phone call to whoever built it, and that person had usually moved on.
The idea: architecture before equipment
Instead of buying gear and figuring out the design later, every engagement started with topology: VLAN schemas that mapped to business functions, not physical office layout; firewall zones that enforced policy, not just perimeter defense; IP addressing that could be extended without renumbering; and documentation that lived in a repository, not in someone's head. The shift was from reactive vendor calls to a designed infrastructure that could be operated, extended, and defended by the team that inherited it.
Network design that operates
Cisco-based LAN and WAN designs with proper segmentation: access layers sized for actual device density, distribution layers that aggregated cleanly, and core routing that didn't rely on flat switching. Wireless designed for industrial and office environments differently — separate SSIDs, separate VLANs, separate policies. IP addressing schemas documented and maintained. DNS and DHCP architected for resilience, not just defaults. Every design came with configuration templates, change procedures, and a handover document that a new engineer could read without calling the consultant.
Security that enforces, not just blocks
Fortinet firewalls deployed with explicit rule structure: application-level policies, not just port-based permits. VPN tunnels governed with authentication, logging, and least-privilege access — vendor X can reach appliance Y on port Z during maintenance window W, nothing else. Network monitoring that made faults visible: SNMP-based device health, flow analysis for traffic patterns, and alerting that reached the right person at the right time. The security layer was designed to be operated by the internal team, not to require a specialist on call.
Multi-cloud without the sprawl
AWS, Azure and Alibaba estates needed connected, and connectivity done wrong creates an attack site out of thin air. I designed multi-cloud network fabrics — Aviatrix-based control of routing and segmentation across providers — so that hybrid environments stayed as defensible as the on-prem ones. Transit gateways, peering relationships, and VPN interconnects all followed the same segmentation logic: production traffic isolated from development, management access separated from user access, and every cross-cloud path documented and monitored.
Results
Networks that ran without fire drills. Defined boundaries, an operated security layer, documents a new engineer can read, and internal teams that could run and extend the infrastructure themselves. Clients stopped buying infrastructure projects and started buying outcomes — a network that scaled with the business, a security posture that could be demonstrated to auditors, and cloud connectivity that didn't create new attack surfaces. The shift from ad-hoc to architectural was visible in the reduced number of emergency calls and the increased number of planned changes.
Next steps
Most plant IT/OT environments inherit the same ad-hoc history — check whether yours does before a breach discovers the topology for you. The same architectural discipline that transforms enterprise networks transforms industrial ones: design first, document always, operate deliberately.
Similar case studies
IT/OT foundations across 100+ food plants worldwide
