NetworkDesign,VPN&Wi-FiOptimization
MPLS / QoS / VLAN | VPN-First Access | Wi-Fi Coverage Assessment
The foundation that makes backup, DR, VoIP, CCTV, and secure ERP access reliable. We design segmented networks that protect ERP and SQL from public exposure, route VoIP traffic with proper QoS, isolate CCTV/NVR feeds onto their own VLAN, and authenticate every remote user via VPN with AD and 2FA before they touch a production system.
Request Consultation
Technologies in use
When this service becomes urgent
912 designs networks for the traffic that actually matters: SAP, VoIP, CCTV, Wi-Fi, VPN, backups, and cloud access. The output is VLAN, routing, firewall, redundancy, and documentation discipline.
Discovery call agenda
Network audit, traffic segmentation, Wi-Fi survey, routing/firewall design, redundancy planning, implementation, and documentation.
- 1Map locations, users, critical apps, and links.
- 2Review segmentation, VPN, and Wi-Fi pain.
- 3Prioritize fixes by business impact.
What the numbers say about leaving this alone
Backups, VoIP, CCTV and ERP access all inherit whatever the network gives them. Segmentation is not a networking preference — it is the thing that decides whether the other four are reliable.
Kenya had 28,130.3 Gbps of lit international bandwidth and used 17,758.824 Gbps between January and March 2026.
Communications Authority of Kenya(opens in a new tab) — Kenya's international capacity, January–March 2026
Across Africa, the ITU recorded 52 mobile-broadband subscriptions per 100 inhabitants and fewer than one fixed-broadband subscription per 100 inhabitants.
International Telecommunication Union(opens in a new tab) — across Africa — which is why access design cannot assume a fixed line
Network Architecture Capabilities
MPLS, QoS & Backup Internet
- MPLS sizing and QoS design with Safaricom or other carriers
- Backup internet paths for DR and continuity
- MPLS latency benchmarking for DR replication thresholds
- Documented runbooks per link
VLAN Segmentation & DHCP
- VLAN/IP readdressing
- DHCP reservations for production systems
- DNS updates and authority handover
- Network monitoring alerts on each segment
VPN-First Secure Access
- VPN-first access with Active Directory authentication
- 2FA on every privileged session
- Time-based access restrictions
- Jump-host architecture for ERP and SQL
What Poor Network Design Causes
Unsegmented networks where guest Wi-Fi, CCTV, VoIP, and production ERP all share the same broadcast domain.
Duplicated NVR feeds caused by subnet contention — load on the recorder doubles, evidence quality drops.
Insecure ERP exposure: SQL or SAP application servers reachable directly from the internet because nobody mapped the firewall rules.
Poor VoIP quality because bulk file transfers and video streams have no QoS priority over voice traffic.
Honest Risk Framing
What this protects against — and what it doesn't.
MPLS reliability sits with the carrier
We design the QoS, size the bandwidth, and benchmark latency — but MPLS uptime is the carrier's SLA, not ours. Backup internet paths via a secondary ISP are quoted for sites where the primary MPLS reliability is mission-critical.
Wi-Fi coverage gaps surface during deployment, not at quoting
Site walks identify obvious coverage issues, but signal-strength reality only emerges with actual AP placement and testing. Coverage gaps found during installation may require additional APs or extenders — quoted as a coverage-expansion line item.
Re-IP and VLAN migrations require planned downtime windows
Network segmentation changes affect every device on the network. We schedule migrations during agreed change windows; users will see brief interruptions. There's no truly zero-downtime path through a full VLAN re-architecture.
Network Design Process
Topology to runbook, in the right order.
Part of the 912 six-phase engagement model — this is how it runs for this service.
Topology Assessment
Map current routers, switches, firewalls, ISPs, IP ranges, VLAN capability, DHCP/DNS authority, and Wi-Fi coverage.
Segmentation Design
Define VLANs per workload (production, CCTV, VoIP, IoT, guest). Plan IP ranges and inter-VLAN access policies.
Implementation
Procure required extenders/access points. Reassign IP addresses with minimal disruption. Verify each system maps to intended network resources.
Documentation & Handover
Documented settings, runbooks for adds/moves/changes, and monitoring alert thresholds. Your network is now operable by your team or ours.
Why Network Comes First
Foundation for Everything Else
Backup, DR replication, VoIP call quality, CCTV NVR reliability, and secure ERP access all depend on correctly-segmented networks. Get the network wrong and every other service runs unreliably.
Honest Wi-Fi Assessments
Wireless IP phones fail silently if Wi-Fi coverage is weak — we verify signal strength at every extension location before deploying. We refuse to ship installations that will fail.
Cisco
Technology in scope
Fortinet
Technology in scope
Safaricom MPLS
Technology in scope
Common Questions
Everything you need to know about Network Design, VPN & Wi-Fi Optimization.
What does a 912 network design engagement cover?
Network architecture for production systems, DR links, VoIP, CCTV/NVR segmentation, VPN-controlled ERP access, Wi-Fi readiness, DNS, and branch connectivity. Topics include MPLS/QoS design, backup internet paths, VLAN/IP readdressing, DHCP reservations, VPN-first access with Active Directory authentication and 2FA, time-based access restrictions, and network monitoring alerts.
Why is network design the foundation for everything else?
Backup, DR replication, VoIP call quality, CCTV NVR reliability, and secure ERP access all depend on correctly-segmented networks. We have seen NVRs duplicate feeds because of subnet contention, ERP slowdowns from undifferentiated traffic, and VPNs that leak across VLAN boundaries. Get network design right and every other service runs reliably.
Do you handle MPLS sizing and SLA negotiation with Safaricom?
Yes — including the MPLS latency figures needed to configure DR replication health monitoring thresholds, QoS rules to protect VoIP traffic from bulk data, and backup internet paths via secondary ISPs. We have worked with Safaricom Business, Liquid Intelligent, and SimbaNET on production deployments.
How is remote access secured?
VPN-first design with Active Directory authentication, 2FA, time-based access restrictions, and role-based VLAN isolation. ERP and SQL systems are never exposed directly to the public internet — administrators connect via VPN, are authenticated, and routed to a jump host with audit logging.
What about Wi-Fi coverage and IP phone readiness?
Wi-Fi assessments include coverage maps, AP placement, channel planning, and PoE budget. For wireless IP phone deployments we verify Wi-Fi signal strength at every extension location before shipping handsets — VoIP fails silently if Wi-Fi is weak, and we refuse to ship installations that will fail.
Related Technical Protocol

Try Bitdefender GravityZone Free for 30 Days: What Your Business Should Test.
A free product trial should answer whether GravityZone fits your devices, applications, policies, reporting needs, and operating team. Here is what organisations with at least 15 endpoints should test during the 30-day evaluation.

What Happens When Ransomware Starts Encrypting Files? GravityZone Prevention and Recovery Explained.
When ransomware begins abnormal encryption, GravityZone can detect the behaviour, block the responsible process, and preserve temporary recovery data where the required protection and prerequisites are active. Here is what that does—and does not—mean for recovery.

SAP ECC to S/4HANA: The 2027 Deadline Explained for Kenyan Businesses
SAP ends mainstream support for ECC at the end of 2027. Here is what the deadline actually means for Kenyan businesses, the migration paths to S/4HANA, and why planning now is cheaper than reacting later.