PROJECT EXPERIENCE

Representative project types and delivery patterns.

Examples are anonymized to protect customer confidentiality. Specific client names, addresses, and configurations are not published.

Financial Services

Subnet and application-edge migration between sites

Challenge: Move a production subnet and internet-facing application services from a hub location to another site while preserving BGP reachability, NAT behavior, and vendor connectivity.

Approach: Redesigned routing advertisements, rebuilt VIPs and policies, validated asymmetric-path risks, and staged application cutover and rollback.

Capabilities: FortiGate, BGP, NAT/VIP, SIP/TLS, application validation.

Cloud Networking

Azure FortiGate HA routing hub

Challenge: Replace fragmented cloud routing and firewall controls with a centralized, highly available architecture supporting branches and multiple VNets.

Approach: Designed hub-and-spoke peering, FortiGate HA, VPN/BGP migration sequencing, UDR changes, validation, and customer knowledge transfer.

Capabilities: Azure, FortiGate VM, HA, BGP, Route Server, hub-and-spoke.

Managed Services

Multi-site SD-WAN and VPN architecture

Challenge: Improve failover behavior and route symmetry across dual tunnels while maintaining direct spoke connectivity and predictable primary paths.

Approach: Reviewed BGP attributes, ADVPN behavior, tunnel preference, policy symmetry, and failure-state routing.

Capabilities: Fortinet SD-WAN, ADVPN, BGP, route preference, troubleshooting.

Data Center

Core network replacement and migration planning

Challenge: Replace legacy core switching with redundant data-center switching while maintaining VLAN gateway, HSRP, vPC, and BGP functions.

Approach: Developed target configuration, validation checkpoints, rollback conditions, and troubleshooting procedures for physical and logical dependencies.

Capabilities: Cisco Nexus, vPC, HSRP, BGP, migration and rollback planning.

Security Access

Remote-access VPN modernization

Challenge: Move remote access to SAML-based authentication while preserving user experience and controlling access to internal resources.

Approach: Designed identity integration, address pools, portal/policy behavior, DNS, certificate requirements, and staged validation.

Capabilities: FortiGate, Entra ID / SAML, IPsec or SSL VPN, policy design.

Firewall Migration

Platform refresh with minimal disruption

Challenge: Replace an aging firewall platform without carrying forward unnecessary rules, legacy objects, or undocumented routing assumptions.

Approach: Performed discovery, translated policy intent, mapped NAT and VPN dependencies, defined cutover tests, and produced rollback documentation.

Capabilities: Multi-vendor firewall migration, policy review, NAT, VPN, documentation.