Cisco-first · Automation-first
Network Engineering. Automated.
We design, build and operate business-critical Cisco networks — from consulting and design through implementation and migration to security and day-to-day operations. One team, senior expertise, documented handover.
- Senior network engineering
- Configuration as code
- Documented handover
Platforms & tooling
- Cisco
- Cisco Meraki
- Cisco Catalyst
- Cisco ISE
- Cisco pyATS
- Ansible
- Python
- NetBox
- Jinja
- Git
- pfSense
- Check Point
- Cisco
- Cisco Meraki
- Cisco Catalyst
- Cisco ISE
- Cisco pyATS
- Ansible
- Python
- NetBox
- Jinja
- Git
- pfSense
- Check Point
The whole network, across its whole lifecycle
Consulting, design, delivery and operations interlock. Engage any service on its own — or hand over the complete project.
What we usually find
Business-critical networks grow for years. At some point nobody knows for certain what is configured — and every change becomes a risk.
- F01
No reliable inventory
Spreadsheets, legacy documentation and tribal knowledge contradict each other. A trustworthy source of truth does not exist.
- F02
Manual CLI without approvals
Changes are made one by one on the command line, without versioning, review or a traceable history.
- F03
Hardware generations expiring
End-of-life deadlines force large migration waves that internal teams have no capacity for.
- F04
No pre- and post-checks
The effect of a change only shows in production. A defined rollback rarely exists.
- F05
Inconsistent standards
VLANs, routing, VPN, firewall rules and wireless differ from site to site.
- F06
Too little senior capacity
Internal teams and IT providers have the projects, but not enough experienced network engineers.
How we work
Every change travels the same lane
Six stages with defined entry and exit criteria. The separation of build, test and deploy matters most: a successfully generated configuration artifact is not yet an approval for production. You can watch stages 03–05 run live right below.
- 01
Discover
We capture the current state from devices, controllers and APIs and hold it against the existing documentation.
Inventory diff
- 02
Design
Target architecture, data model and migration path are designed and agreed with your team.
HLD / LLD
- 03
Automate
The target configuration is generated from structured data and versioned templates, not copy-and-paste.
Jinja template
- 04
Test
Cisco pyATS and Genie verify routing, adjacencies, VPN, redundancy and reachability — before and after the change.
pyATS report
- 05
Change
Execution in the approved window, with dry run, peer review, full logging and a defined rollback.
Change log
- 06
Document
The source of truth is updated, acceptance is recorded and operations are handed over.
Acceptance record
- 01Source of TruthNetBox: VLAN 240 created for site BRN-02
- 02RenderJinja2 template generates configuration for 4 access switches
- 03Diff12 lines added, 0 removed — target against actual
- 04Pre-checkpyATS: uplinks, OSPF neighbors and redundancy confirmed
- 05Dry runAnsible check mode with zero deviation
- 06ApprovalPeer review by a second engineer, change window open
- 07DeployRolled out to 4 devices, fully logged
- 08Post-checkVLAN active, adjacencies stable, no drift
Sample run with invented data. No customer systems are touched.
Automation in operations
Where repetition pays off, we automate
Automation is never an end in itself for us — it is the tool that makes recurring rollouts, checks and standard changes dependable. The example shows a standard change from data record to passed post-check.
Repeatable rollouts
Templates and structured data instead of one-off configuration.
Fewer manual errors
Validation, peer review and controlled execution.
Traceable changes
Git history, logs and acceptance reports for every change.
Less key-person risk
Standardised roles, tests and operating procedures.
Engineering you can trust with production
Senior expertise
Experienced network engineers with enterprise and service-provider backgrounds — no junior rotation.
Documented handover
HLD, LLD, operations manual and acceptance record are part of the service, not a special request.
Security & governance
Least privilege, peer review, separated environments and a defined rollback — in every project, not on request.
Vendor-open by design
Cisco-first in the network, open in the architecture: the automation stays vendor-neutral and belongs to you.
For IT providers
White-label senior engineering
You have the project and the client, but right now not the senior capacity for Cisco, security or automation. We deliver under your brand — with clear roles, client protection and NDA.
Request capacityNext step
An assessment, not a transformation promise
We start with an inventory: how reliable are your records, standards and change processes — and where does automation pay off first?
Request an assessment