Skip to content

Networking

Engineering write-ups on networking from deployments KYCONNECTS has run, with the reasoning behind each approach.

Networking7 min read

pfSense in a business network

pfSense gives a growing business a firewall, a VPN concentrator and traffic visibility on hardware that costs a fraction of the commercial appliances. What it does not give you is a vendor to call, and that difference should decide whether it belongs in your network.

pfSenseFreeBSDCARPWireGuardOpenVPN
Read the write-up
Networking7 min read

WireGuard vs OpenVPN

These two make opposite design choices about the same problem. OpenVPN negotiates almost everything and is correspondingly flexible; WireGuard fixes almost everything and is correspondingly small. Which is right depends on what your network has to tolerate.

WireGuardOpenVPNpfSenseCurve25519ChaCha20
Read the write-up
Networking8 min read

Network design for a growing business

Enterprise network design usually arrives as a three-tier diagram from a vendor guide, which is the wrong shape for almost every growing business. The decisions that matter are the addressing plan, where the failure domains sit, and how much uplink you actually have.

VLANSpanning TreeLACPDHCPCisco
Read the write-up
Networking8 min read

Hardening Cisco network devices

Switches and routers are the most privileged and least maintained devices in most estates. Cisco's own hardening guidance divides a device into three planes, and that division turns an unbounded task into three short, checkable lists.

Cisco IOSIOS XENX-OSAAATACACS+
Read the write-up
Networking14 min read

VPN deployment: a practical guide

Choosing a topology is the architecture decision. Getting the deployment right is a different set of problems: protocol choice, addressing, certificate lifecycle, split routing and the rollback path you will want on the day it goes wrong.

WireGuardIPsecpfSensePKI
Read the write-up
Networking25 min read

Secure remote access architecture

A VPN answers whether someone can reach your network. The question that decides whether you are secure is what they should reach once they are on it, and most remote access designs never ask it.

pfSenseWireGuardIPsecFortinet
Read the write-up

Have a Problem That Looks Like One of These?

We typically respond within 4–8 business hours.