Infrastructure Monitoring & Observability Stack
Building a centralized monitoring and logging platform using Prometheus, Grafana, LibreNMS, and SNMP for real-time visibility.
- Prometheus
- Grafana
- LibreNMS
- SNMP
- Docker
- +2
A comprehensive network architecture engineering project focused on establishing resilient connectivity across multi-building campuses, integrating core routing, switch stack redundancy, structured VLAN segmentation, and secure site-to-site tunnels.
This project established a high-performance network foundation for a distributed enterprise campus requiring 99.99% uptime, strict VLAN isolation between operational departments, and automated failover across primary ISP and backup secondary links.
The legacy network suffered from broadcast storms due to a flat Layer 2 topology, lack of traffic prioritization for VoIP systems, single points of failure across core switches, and minimal visibility into bandwidth utilization per department.
Architected a hierarchical 3-tier network model (Core, Distribution, Access) using OSPF dynamic routing between distribution switches, LACP link aggregation for high-bandwidth switch trunks, isolated IEEE 802.1Q VLANs with strict firewall inter-VLAN policies, and IPsec site-to-site tunnels.
The network architecture leverages redundant Core Routers running OSPF for internal subnet routing and VRRP for gateway resiliency. VLANs separate Admin, IoT, Guest, and Server subnets at the Access layer.
Dual MikroTik CCR routers operating active-passive VRRP with OSPF routing and multi-WAN BGP/ECMP failover.
Managed L3 switch stack with 10GbE fiber interconnects providing inter-VLAN routing and ACL enforcement.
PoE+ Managed Access switches configured with Port Security, DHCP Snooping, and 802.1X authentication.
Dedicated IPsec / WireGuard VPN gateways for secure remote access and branch office inter-site mesh connectivity.
Conducted physical and logical network audit to identify topology bottlenecks and cable run limitations.
Designed standard IP subnetting schema using CIDR allocation and VLAN mapping per building/department.
Deployed core MikroTik and Cisco switches with redundant power supplies and LACP trunking.
Configured OSPF dynamic routing, BGP multi-WAN failover scripts, and QoS queues for VoIP latency protection.
Implemented switch hardening: disabled unused ports, enabled BPDU Guard, Loop Protect, and DHCP Snooping.
Integrated SNMP polling with centralized network management tools for realtime link alerts.
Broadcast storms and STP topology changes causing intermittent connectivity loss.
Configured Rapid Spanning Tree Protocol (RSTP) with explicit Root Bridge priority assignment and BPDU Guard on all edge ports.
Unrestricted inter-department traffic access exposing sensitive database servers.
Implemented stateful firewall rules restricting inter-VLAN traffic, allowing only explicitly required port communications.
Building a centralized monitoring and logging platform using Prometheus, Grafana, LibreNMS, and SNMP for real-time visibility.
Architecting a hardened Proxmox VE hypervisor cluster with Linux containerization, Nginx reverse proxy, and zero-trust VPN.
If you need assistance designing or auditing your network, hypervisor, or monitoring platform, let's talk.
Get In Touch