> Infrastructure & Networking | automateglobal.ca
NewOur PIPEDA + Quebec Law 25 compliance accelerator is liveRead the brief →
07 / 10 · Infrastructure & Networking

Networks that behave under pressure.

SD-WAN design and deployment, firewall and edge security, switching and routing architecture, load balancing, site-to-site VPN. Topology diagrams you can read, runbooks you can follow, failover that actually fails over when the primary link drops.

SD-WAN Multi-vendor Zero-trust Design-in Documented Topology Tested Failover
Network Infrastructure · Live
OPERATIONAL
YYZ-01 · Primary
7sites Topology
99.98% Uplink SLA
<30ms Inter-site RTT
0flap Last 30 days
5sub-services
SD-WAN, firewall, switching/routing, load balancing, VPN. Design through runbook.
Service breadth
99.98%
Target uplink availability with dual-carrier SD-WAN. Measured, not promised.
Uplink SLA
0flat
No flat Layer 2 networks. VLAN segmentation, zero-trust by default on every design.
Architecture
1diagram
Every deployment ships with a current topology diagram. Updated when it changes.
Documentation
Scope · 5 sub-services

SD-WAN, firewall, switching, load balancing, VPN. Designed, documented, operated.

Networking is where "it works most of the time" is the enemy. Our designs prioritize predictability over cleverness: segment properly, document religiously, test failover quarterly, replace equipment before it dies in a thunderstorm.

01 / 05

SD-WAN design & deployment

Multi-site SD-WAN with dual-carrier failover, application-aware routing, and QoS tuned per site. Design starts with your traffic profile and bandwidth per site, not vendor datasheet promises.

Fortinet SD-WAN Meraki Versa
02 / 05

Firewall & edge security

Next-gen firewall deployment, rule base design and quarterly review, IDS/IPS tuning, SSL inspection where appropriate. Rules written as code where supported, so changes are tracked and reversible.

Fortinet FortiGate Palo Alto pfSense
03 / 05

Switching, routing, VLAN

LAN design with proper segmentation: VLANs per role, inter-VLAN routing policies, STP tuning that prevents loops instead of hoping for the best. Documented IP schema so the next person can read it.

Cisco Catalyst Aruba Juniper
04 / 05

Load balancing & CDN

L4/L7 load balancer deployment with health checks that actually detect application failure (not just port-up). CDN integration for static assets. Session persistence configured for stateful apps that need it.

HAProxy NGINX Cloudflare
05 / 05

Site-to-site VPN & zero-trust access

IPsec site-to-site tunnels for interconnect, WireGuard where latency matters, zero-trust remote access replacing legacy VPN. Modern remote access without the "all or nothing" posture of yesterday's VPN.

WireGuard Tailscale Cloudflare Access
What we actually do

Three categories, one operating discipline.

SD-WAN overlay, perimeter security, traffic distribution. Not sold as separate line items by separate teams. One architecture, one documentation set, one on-call rotation when something flaps at 3am.

Overlay
01 · SD-WAN & Site Interconnect

Multi-site overlay with dual-carrier failover

SD-WAN replaces fragile MPLS as default, but we deploy MPLS or dedicated circuits where latency or compliance requires. Application-aware routing, QoS tuned to your traffic profile, and dual-carrier last-mile so a single provider outage does not take down a site.

Platforms we deploy
Fortinet SD-WAN Cisco Meraki Versa Palo Alto Prisma pfSense
Edge
02 · Firewall & Edge Security

Next-gen firewall, rule hygiene, SSL inspection

Rules written as code where the vendor supports it, so changes are tracked, reviewed, and reversible. Quarterly rule-base audit removes orphaned ACLs that accumulate over time. IDS/IPS tuned to your traffic (not vendor defaults) and SSL inspection scoped to what the policy actually requires.

Platforms we deploy
Fortinet FortiGate Palo Alto Check Point pfSense OPNsense
Distribution
03 · Load Balancing, CDN & Remote Access

L4/L7 LB, edge CDN, zero-trust remote access

Load balancer health checks that detect application failure, not just port-up. Session persistence configured correctly for stateful apps. CDN at the edge for static assets. Zero-trust remote access (Cloudflare Access, Tailscale) replacing legacy all-or-nothing VPN wherever the posture allows.

Platforms we deploy
HAProxy NGINX Cloudflare Tailscale WireGuard
Other platforms used on request: Cisco Catalyst, Aruba, Juniper, Arista, Ubiquiti UniFi, F5 BIG-IP, Citrix NetScaler, Zscaler, Netskope, and client-specific tooling. We adapt to your existing stack rather than forcing a rip-and-replace.
Why practitioner, not integrator

Three things that separate reliable networks from the ones you learn about on Monday morning.

Most networking engagements end with a diagram you cannot read, a config nobody has, and a vendor contact who left the firm. Here is how we work differently.

01

Topology you can read on day one.

Every deployment ships with a current, versioned topology diagram, VLAN plan, IP schema, and change log. Not Visio screenshots from six months ago, not whiteboard photos. Readable artifacts that match the running config.

When the config drifts from the diagram, we update the diagram, not the other way around.

02

Failover tested on a schedule.

Dual-carrier SD-WAN failover, HA firewall pairs, redundant uplinks: all of them are only real if they have been tested within the last 90 days. We schedule and run quarterly failover tests with scripted procedures and documented outcomes.

The first time you discover failover is broken should not be during a real outage.

03

No vendor religion.

We are not a Fortinet reseller, not a Cisco Partner tier, not a Palo Alto NextWave. No commission shapes what we recommend. If your existing Meraki stack is fine, we leave it alone and operate it. If pfSense fits better than $40k of commercial firewalls, we say so.

The recommendation is driven by your constraints and your team's skills, not our quarterly channel targets.

Buyer questions

The things architects and procurement teams actually ask us.

Is SD-WAN really cheaper than MPLS now?

For most Canadian multi-site deployments, yes, by a wide margin. SD-WAN over two commodity internet links (fibre + cable, or fibre + LTE) typically runs 40-70% below equivalent MPLS pricing with better burst bandwidth. The gap closes if your sites genuinely need carrier-managed QoS for real-time workloads at low latency.

Where MPLS still wins: locations where carriers have monopoly pricing on internet circuits, latency-sensitive workloads with strict jitter budgets, or regulatory requirements that specifically demand private circuits. We assess per site rather than applying one model to everything.

How often do you touch firewall rules?

Change windows depend on scope: routine access requests (new SaaS, new user group) get processed weekly in a batched change window with documented justification. Policy-level changes go through a design review before any config touches production.

Separately, we run a quarterly rule-base audit: unused rules get flagged for removal, shadowed rules get consolidated, overly permissive rules get tightened. The rule base shrinks over time with proper hygiene, not grows forever.

What happens when a core link goes down at 3am?

Autonomous failover first. Dual-carrier SD-WAN flips to the secondary link within 1-3 seconds depending on vendor. HA firewall pair fails over sub-second. If the architecture is designed properly, nothing wakes anyone up for a single-link failure.

If something does need human attention, the on-call engineer gets paged within 2 minutes of the primary alert, acknowledges within 15 minutes, and the designated incident contact at your organization is notified within 30 minutes with status and ETA. Post-incident report lands within 48 hours.

How do you keep us from being locked into a vendor?

Separation of layers. Overlay (SD-WAN) is picked for fit per deployment, but the underlying principles (dual-carrier, QoS buckets, routing policy) are vendor-neutral. If we had to migrate off Fortinet to Palo Alto, the architecture translates cleanly because the design is not Fortinet-specific.

Configurations are stored as code in your git repo where the vendor supports it (Fortinet via FortiManager APIs, Palo Alto via Panorama, Cisco via NSO/Ansible). Even non-code configs get exported, versioned, and reviewed quarterly. The config is yours, not held in our tenancy.

Are you IPv6-ready, and do we need to care?

Yes, and yes, you probably should start caring. Canadian ISPs are increasingly deploying IPv6 by default, cloud providers charge extra for IPv4, and modern mobile networks (Rogers, Bell, Telus) are IPv6-first with 4-to-6 translation.

Our default new designs are dual-stack IPv4+IPv6 where equipment supports it. For existing IPv4-only networks, we scope IPv6 enablement as a project: typically a few weeks of design + rollout for a mid-sized multi-site org, run alongside existing IPv4 with no cut-over risk.

Should we move off traditional VPN to zero-trust access?

In most cases, yes, incrementally. Zero-trust remote access (Cloudflare Access, Tailscale, Twingate) is strictly better than legacy VPN for the common case: granular per-app access, device posture checks, no "trusted network" fiction, and users do not have to connect to anything.

We typically run the two side by side during migration: zero-trust for new apps and new users, legacy VPN for the small set of workloads that genuinely require it (noisy UDP protocols, legacy admin tools). Over 6-12 months the legacy VPN footprint shrinks to zero.

Thirty minutes with the practitioner

Tell us what keeps dropping. We will say why, and what to fix.

Not a sales call. A practitioner conversation about which links keep flapping, which sites are isolated when the primary carrier burps, and what a sensible next 90 days of network work would look like for your current size and setup.

What you get on the call
Honest read on your current topology and the 2 or 3 biggest risks in it
Where SD-WAN would actually help, and where MPLS or private circuits still win
Zero-trust vs legacy VPN tradeoffs for your specific access patterns
If we are not the right fit, we say so and point you to who is