Network Security & SD-WAN

Network security and SD-WAN that stay online when your internet provider does not.

A single internet circuit, a flat network, and logs scattered across devices are how small outages become lost days and how intrusions go unnoticed. We design and build segmented, monitored networks on FortiGate SD-WAN with multiple independent internet paths, centralized authentication, and network events streamed into Microsoft Sentinel.

View related work

A free 30-minute working session. We review your environment and send a prioritized action plan you keep, whether or not we work together.

Consultants sketching a network topology and VLAN plan on paper
Topology and VLAN plans agreed before a single port changes.

When to bring in a network security consultant

These are the sparks that usually bring us into the room.

  • One internet provider goes down and the whole office goes with it.
  • Every device shares one flat network, so nothing limits lateral movement.
  • Firewall, switch, and access-point logs live on each device and nobody reviews them.
  • Remote users connect to the VPN but still cannot reach network drives or internal apps.
  • Nobody can say which devices on the network are known and which are not.

Need identity, devices, and data secured alongside the network? See our cybersecurity and Zero Trust program.

What our network security and SD-WAN work delivers

Every engagement ships measurable impact, documentation, and enablement.

  • A FortiGate next-generation firewall configured as the central security and routing platform, with organized, reviewed policies.
  • FortiGate SD-WAN across independent circuits — fiber, Starlink, cellular — with health checks and automatic failover.
  • VLAN segmentation with a dedicated management network and firewall-controlled inter-VLAN traffic.
  • Core and access switching with LACP uplinks, 802.1Q trunks, and PoE for wireless access points.
  • Centralized RADIUS authentication and a known-device MAC inventory.
  • Network logs centralized and forwarded into Microsoft Sentinel, tuned so alerts are worth reading.
  • Secure VPN access for administrators and MSPs, without exposing management interfaces to the internet.

Delivery method

How we work with your team

Every week includes demos, telemetry, and regulator-ready documentation.

  1. 01

    Assessment & topology review

    Map circuits, closets, switches, access points, and traffic flows; inventory every known device.

  2. 02

    Architecture & segmentation design

    VLAN plan, firewall policy model, SD-WAN rules, and authentication design, agreed before anything changes.

  3. 03

    Build, cutover & failover testing

    Configure firewall, switching, wireless, and WAN; prove failover, throughput, and remote access end to end.

  4. 04

    Monitoring, tuning & documentation

    Logs into Sentinel with noise filtered out, plus VLAN, port-role, WAN, and policy documentation your team keeps.

Where it shines

High-value use cases

Nonprofit & human services

Volunteers of America National

Rebuilt the national office network on a FortiGate 121G and redundant NETGEAR MS324TXUP core switches: VLAN segmentation, SD-WAN across fiber, Starlink, and cellular, RADIUS on Synology, and a locked-down MSP VPN.

Traffic fails over automatically and network events land in Microsoft Sentinel.

3 independent internet paths

Remote access

VPN connected, drives unreachable

Users could connect to the VPN but could not reach internal network drives. We traced VPN routing, internal routes, firewall policy, DNS resolution, and client routing until shares resolved over every path.

Remote users reach internal shares reliably.

Routing, policy, and DNS fixed end to end

Security operations

Network logs into Microsoft Sentinel

Network and infrastructure events are collected on Synology and forwarded into Microsoft Sentinel, then tuned to drop repetitive, low-value events while keeping what matters for investigation.

One place to investigate instead of logging into each device.

Network → Synology → Sentinel

FortiGate SD-WAN with fiber, Starlink, and cellular

Most offices still run on one internet circuit, and when it fails, so does everything that lives in the cloud — Microsoft 365, line-of-business apps, phones. FortiGate SD-WAN removes that single point of failure by treating several independent connections as one managed pool. A typical design pairs primary fiber with Starlink and a cellular circuit: three providers, three physical paths, very little shared risk.

The SD-WAN rules decide where traffic goes. Health checks continuously probe DNS, general internet reachability, and Microsoft 365 endpoints on every circuit; when a link goes down or drops below its performance thresholds, traffic steers to a healthy path automatically and moves back when the primary recovers. Failover is tested during the build, not discovered during the first outage.

This is how we rebuilt connectivity for the Volunteers of America National office: a FortiGate 121G managing fiber, Starlink, and cellular in SD-WAN zones, with health checks feeding route selection and failover verified before handoff.

VLAN segmentation, RADIUS, and knowing what is on your network

A flat network lets any compromised laptop talk to every server, printer, and camera. Segmentation splits the network into VLANs by device type and purpose — a dedicated management network, staff, wireless, infrastructure — and the FortiGate decides which segments may talk to each other. Access is granted on operational need, and anything unnecessary is removed during the policy review.

Segmentation works best alongside identity and inventory. Centralized RADIUS authentication replaces independently managed credentials on network gear, and a known-device MAC inventory makes unexpected devices stand out the moment they appear. Neither replaces the firewall policy; together they give administrators visibility and control that a single control cannot.

Network logs in Microsoft Sentinel, without the noise

Firewalls and switches generate enormous volumes of events, and forwarding all of them to a SIEM buys you a large bill and alert fatigue. We centralize network and infrastructure logs first — on Synology in the VOA National build — and forward them into Microsoft Sentinel, then review what actually arrives.

Repetitive and low-value events are filtered at the source, logging levels are adjusted, and the events that matter for detection and incident investigation are kept. The result is a Sentinel workspace administrators actually use, covering the network as well as Microsoft 365 and endpoints, which is where our cybersecurity program picks up.

Platforms & accelerators

Tech we bring to the table

FortiGateFortiOSSD-WANNETGEAR managed switchesVLAN / 802.1QLACPRADIUSSynologyMicrosoft SentinelStarlink

FAQs

Questions we get a lot

Do you configure Fortinet FortiGate firewalls and SD-WAN?

Yes. FortiGate is the platform behind our most recent network build: firewall policy, NAT, routing, inter-VLAN security, VPN, and SD-WAN with health checks and automatic failover across multiple internet circuits.

Can Starlink or cellular be used as backup internet for an office?

Yes. With SD-WAN, Starlink and cellular circuits sit alongside primary fiber as independent paths. Health checks watch each one, and traffic moves automatically when a circuit fails or degrades, then returns when it recovers.

Can network and firewall logs go into Microsoft Sentinel?

Yes. We centralize network and infrastructure logs and forward them into Microsoft Sentinel, then tune what gets ingested so the workspace holds security-relevant events rather than repetitive noise.

Our VPN connects, but users cannot reach network drives. Can you fix that?

That is a routing, firewall-policy, or DNS problem far more often than a VPN problem. We trace VPN and internal routes, firewall policies, DNS resolution, and client routing until internal shares are reachable over every connection type.

How do you give an MSP remote access without exposing the network?

Through a dedicated VPN with its own policies, routing, and authentication, restricted to the systems the MSP actually administers. Management interfaces stay off the public internet.

Ready for a segmented, resilient network?

Tell us about your priorities and we will share a playbook within one business day.

Contact sales