We build the network.
Then we hand over the access.
Some projects need more than a machine with a cable in it. We design the network, buy the equipment, rack it in our own data centres, configure it — and then hand over the access.
- where
- 4 data centres — Amsterdam, Meppel, US East and US West
- scope
- design, procurement, racking, cabling, configuration, handover
- equipment
- Cisco, Juniper, MikroTik and other enterprise vendors
- hardware
- switches, routers, hardware firewalls, optics and modules
- segmentation
- VLAN and VXLAN, L2/L3 access control, DMZ, microsegmentation
- routing
- static, OSPF and BGP, including between our sites
- uplinks
- several independent upstream providers per site
- resilience
- LACP link aggregation, redundant equipment, provider-level failover
- distributed
- one L2 domain across sites over VXLAN
- afterwards
- monitoring, incident response and configuration changes by ticket
- price
- quoted per project
This is the one place on the site where we do the work rather than hand you the tools. It does not move the boundary: the operating systems on your machines stay yours, exactly as /about says.
From a topology drawing to a configured rack.
Network architecture
We work out the topology for the job in front of us — a handful of servers in one rack, or a distributed system across two continents.
- architecture for server clusters
- isolated private segments
- distributed networks between our data centres
- highly available configurations with redundant equipment
- multi-level segmentation by traffic type
- room to grow without a rebuild
Procurement and installation
You do not have to source anything. We buy what the design calls for, within the budget it has to fit, and put it in the rack ourselves.
- buying switches, routers and firewalls to the specification
- physical mounting in the data centre rack
- power and network connection
- structured cabling
- configuration and handover with access
Private segments
Isolated environments, so that the data stays inside a boundary you control and only the people who need access have it.
- private VLANs per segment of your infrastructure
- traffic separation at L2 and L3
- DMZ zones for public services
- microsegmentation with per-service policy
- east-west filtering inside the network
Multiple uplinks and BGP
Several independent upstream providers in each site, with routing that moves traffic off a carrier that stops behaving.
- connections to several upstream providers
- BGP routing with automatic failover
- balancing between carriers
- route optimisation for shorter paths
- separate channels for different traffic types
- redundancy at the provider level, not just the switch
Distributed networks and VXLAN
Servers standing in different data centres, behaving as one network — L2 carried over L3 between our sites.
- VXLAN between our sites in the US and the Netherlands
- one addressing domain across locations
- geo-distributed clusters
- disaster-recovery configurations
- hybrid setups split across sites
Throughput and latency
Tuning for the traffic the project actually carries, rather than for a generic profile.
- high-throughput configurations
- tuning per traffic type — storage, database, web
- jumbo frames
- RDMA for latency-sensitive workloads
- dedicated bandwidth channels
- LACP aggregation for speed and redundancy
- QoS priorities for the traffic that must not wait
Network security
Control over what reaches what, enforced in the network rather than left to each host.
- firewall rules and ACLs
- NAT and address translation
- isolation between customer segments
- protected management networks
- intrusion detection at the network layer
- monitoring for anomalous traffic
- periodic review of the configuration
Monitoring and support
After handover the infrastructure stays watched, and changes go through a ticket with an agreed window.
- availability of every network component
- bandwidth use and emerging bottlenecks
- latency and packet loss
- BGP session and routing state
- load on the network equipment
- incident response and scheduled maintenance
- configuration changes at an agreed time
Whatever the project actually needs
Requirements that do not fit a standard shape are the normal case here, not the exception.
- non-standard VLAN schemes
- complex routing policies
- custom firewall rules
- specific QoS configurations
- integration with your existing network over VPN or IPsec
- BGP peering with your own infrastructure
- hybrid cloud connectivity
Priced per project, because none of them repeat.
Cost follows the architecture: how many segments, whether VXLAN spans sites, how many uplinks and carriers, what has to be redundant, and how much of it we watch afterwards.
You describe the requirement
Technical requirements, or the problem you are trying to solve if the requirements are not settled yet.
Our engineers design it
We work out the architecture and the equipment list against your constraints, budget included.
We quote the whole thing
A commercial proposal with the solution described in detail — equipment, work, and what it costs to keep running.
We agree terms and timing
An accurate timeline is possible once the design exists. Before that, any date would be a guess.
We build it and keep it running
Procurement, racking, configuration, handover — then monitoring and changes by ticket.
Our own infrastructure
We control the network in our data centres, so a change does not wait on a third party to schedule it.
Four sites, two continents
Data centres in the United States and the Netherlands, which is what makes geo-distributed designs possible at all.
Nothing is a template
No two of these projects have been the same. The network is designed for the job rather than picked off a list.
Experience in complex builds
Our team has delivered dozens of projects of varying complexity — from basic VLANs to VXLAN networks spanning continents.
Several carriers per site
Independent upstream providers mean a single carrier failing is a routing event rather than an outage.
Problems found before you find them
Monitoring exists so that we see the bottleneck or the flapping session first, not after it has cost you something.
- We do not sell DDoS mitigation, here or anywhere else on this site. Filtering at the network edge and monitoring that wakes a human is the whole of it.
- No uptime percentage. Redundant equipment and several carriers are real; a number we have not signed is not, so we do not print one.
- No timeline before the design exists. Anything quoted earlier would be a guess with a date attached.
- Monitoring data is shared on request, but in a limited form — it is our infrastructure being measured.
- The operating systems on your servers stay yours. Unmanaged means the same thing here as everywhere else on this site.
Can you build a network between servers in different data centres of yours?
Yes — that is what VXLAN is for. Servers in the US and the Netherlands can sit in one L2 segment.
Which providers are available for uplinks?
Each site is connected to several Tier-1 providers. We can set up BGP routing with balancing between them.
Can you create a fully isolated network for my servers?
Yes. Private VLAN segments with full isolation from other customers and traffic control at every level.
How long does a complex build take?
It depends on the design. An accurate timeline is only possible after we have analysed the requirement — we would rather say that than invent a date.
Do you give access to network metrics?
Yes, though in a limited form. It is our infrastructure being measured, so what we can expose has a boundary.
What if I need the configuration changed later?
Open a ticket describing the change. Our engineers make it at an agreed time rather than mid-traffic.
Can you integrate with my existing infrastructure?
Usually yes — BGP peering or another form of integration. What is possible depends on what the end result has to look like, so describe that first.
Do you support IPv6?
Yes, fully, in every location.
Ready to talk about your network?
Describe the requirement and we will come back with an architecture — from a handful of VLANs to a VXLAN cluster across two continents.