← All services

Networking

DNS, private connectivity and traffic filtering. Nobody notices any of it until it breaks, and then nobody talks about anything else.

We work on networks that connect cloud environments, offices and people, entirely remotely. If you need someone physically standing next to a switch, we are the wrong call and will say so.

What the work covers

  • DNS design and migration, including moves nobody notices
  • VPN and tunnels with Cloudflare Tunnel or WireGuard, connecting environments without opening them to the internet
  • Firewall and WAF rules, rate limiting, bot filtering
  • Private networking between cloud resources, so your database is not on a public address
  • Access control for internal tools, using identity rather than IP allowlists

What we build it with

  • Cloudflare: DNS, Tunnel, Access, WAF
  • WireGuard
  • AWS VPC, security groups, PrivateLink

How an engagement runs

  1. 01

    Map what is actually there

    Networks are rarely documented accurately. We find out what is really connected to what before changing anything.

  2. 02

    Plan the cutover

    Written, with the rollback in it. DNS changes are slow to undo, so the plan matters more than the change.

  3. 03

    Change it out of hours

    Where a change carries visible risk, we do it when nobody is using the system.

  4. 04

    Verify from outside

    We test from networks that are not yours, because a firewall rule that looks right from the inside proves nothing.

What we don't do

  • On-site work: cabling, switches, anything physical
  • Office wifi and end-user support
  • Telephony and VoIP
Get in touch