Skip to main content
OMNINET VISION OmniNet Vision LLC — home
Consulting and architecture

Enterprise network engineering

We work on networks that cannot be taken down to be fixed. Most of what we do is unglamorous: understanding an estate properly before changing it, then changing it in an order that stays recoverable.

Selected engagements

Anonymized
Financial services

Perimeter refresh on a live estate

The situation
An ageing Cisco ASA pair was carrying the perimeter for a regulated environment, with policy that had accreted across years of one-off changes and no reliable record of what any given rule was for.
What we did
Audited the existing rule base against actual observed traffic before touching anything, rebuilt policy on a Palo Alto HA pair under Panorama, and cut over in stages with a tested rollback at each one. Rules nobody could justify were retired rather than carried forward.
Where it landed
The estate came out with a perimeter the security team can actually reason about, and change control that no longer depends on institutional memory.
Logistics

Multi-site consolidation ahead of a cloud migration

The situation
Sites had been brought online one at a time over several years. Each had its own addressing decisions and its own interpretation of the routing standard, and the overlaps only surfaced when the cloud migration started failing in ways nobody could explain.
What we did
Mapped what was genuinely running rather than what the documentation claimed, resolved the address conflicts, and rebuilt route distribution so convergence behaved the same way at every site.
Where it landed
The migration got a stable base to work from, and the recurring cross-site incidents that had been written off as unavoidable stopped.
Live broadcast

Circuit design and pre-event validation

The situation
A live event schedule with no tolerance for a dropped feed, running on circuits whose redundancy had never been tested under real load.
What we did
Designed multi-homed circuits with genuinely independent physical paths — not two services from the same upstream — tuned multicast to hold up under production traffic, and load-tested the whole path at show levels in advance.
Where it landed
Failover was proven before it was needed rather than discovered during a broadcast.

Client names and identifying details are withheld under confidentiality terms. We will go through the specifics, including what did not go to plan, on a call.

What we work on

Datacenter migrations

Brownfield hardware refreshes on live estates. Most often that means moving a legacy Cisco ASA perimeter onto a high-availability Palo Alto NGFW pair, with policy managed centrally through Panorama rather than device by device.

#HA-Pair #Panorama #Datacenter-Refresh

Identity and access control

Zero trust enforced at the port, not just at the perimeter. We assess, deploy, and upgrade network access control on Cisco ISE and Juniper Access Assurance — 802.1X where the estate supports it, MAB where it does not, and a realistic plan for the gap between them.

#802.1X #MAB #Cisco-ISE #Juniper-Assurance

Routing and route distribution

Convergence that behaves predictably across sites. We work in large EIGRP and OSPF domains and in multi-homed BGP, tightening route distribution so a failure in one region stops being everyone's problem.

#BGP #OSPF #EIGRP #AS-Peering

Path visibility and observability

Closing the blind spot between your edge and the services your users actually depend on. ThousandEyes active agents on the paths that matter, Catalyst Center reaching into the switches and routers, so a degradation is something you spot rather than something a user reports.

#ThousandEyes #Catalyst-Center #Telemetry

Out-of-band management

A way into the estate when the estate is the thing that is broken. Air-gapped OOB console architecture on OpenGear appliances, kept off the production path so a bad change is recoverable without a site visit.

#OpenGear #OOB-Isolation #Console-Server

Multi-tenant segmentation

Clean boundaries between business units and subsidiaries, isolated at layer 2 and layer 3, so data governance and compliance scoping have something real to point at.

#Multi-Tenancy #VLAN-Isolation #Compliance

Not sure which of these you need?

That is usually the right starting point. A discovery call is a conversation about what your estate actually looks like, not a pitch.

Book a discovery call