Made by Austin BC
IRONVEIL is an enterprise network security architecture project that models a resilient, segmented, multi-floor company network for a workforce of approximately 600 users. The design combines Cisco ASA perimeter security, dual-ISP connectivity, redundant multilayer switching, VLAN segmentation, OSPF routing, HSRP gateway redundancy, DMZ services, centralized DHCP/DNS/RADIUS infrastructure, wireless LAN services, and VoIP.
Disclaimer: This repository documents is a LAB enterprise network design. Configurations are intended for portfolio, design, simulation, and architecture review purposes. Lab passwords and sample addressing must be replaced before any production use.
- Executive Summary
- Architecture Overview
- Repository Navigation
- Key Objectives
- Technologies Used
- Network Topology Summary
- VLAN and Subnet Design
- Security Architecture
- Firewall and DMZ Design
- Routing and Redundancy Design
- Wireless Architecture
- VoIP Architecture
- Server Infrastructure
- Configuration Highlights
- Testing and Validation
- Lessons Learned
- Future Improvements
- Repository Tree
IRONVEIL transforms a campus-style enterprise network into a security-focused reference architecture. The network is divided into operational zones and VLANs, protected by redundant Cisco ASA firewalls, and routed through a resilient core. Department access switches provide wired user access, voice endpoints, wireless access-point connectivity, and blackhole handling for unused ports.
The design emphasizes controlled traffic flow, survivable connectivity, and clear operational ownership. Cisco ASA security levels and ACLs separate inside, DMZ, and outside zones. NAT enables internal and DMZ networks to reach external services. OSPF provides dynamic routing across the simulated enterprise and ISP/cloud edge. HSRP provides first-hop gateway availability for major VLANs. EtherChannel with LACP strengthens the core interconnect, while PortFast and BPDU Guard harden access-layer edge ports.
Figure 1: Full enterprise topology showing internet/cloud simulation, dual ISP routers, redundant ASA firewalls, core switching, departmental access layers, DMZ/server networks, wireless, and voice services.
The architecture is organized into six major layers:
| Layer | Role | Primary Components |
|---|---|---|
| Internet and cloud simulation | Represents external clients and upstream networks | Cloud router, cloud switch, foreign/client PCs |
| ISP edge | Provides dual upstream paths | CONVERSE-ISP router, PLDT-ISP router |
| Security perimeter | Enforces zone separation and NAT | Cisco ASA 5500-X firewalls |
| Core/distribution | Provides routed campus backbone and gateway redundancy | Catalyst 3850 multilayer switches |
| Access layer | Connects departments, APs, phones, and user endpoints | Catalyst 2960 access switches |
| Services | Hosts DMZ, inside servers, wireless control, voice, DHCP/DNS/RADIUS | DMZ switch, inside server switch, WLC, voice gateway |
The design uses a defense-in-depth model: upstream resilience at the WAN edge, firewall segmentation at the perimeter, Layer 3 segmentation in the core, VLAN isolation at access, and controlled remote administration through a management-only ACL model.
| Path | Purpose |
|---|---|
| docs/architecture-overview.md | Expanded architecture narrative and topology breakdown |
| docs/addressing-and-vlans.md | VLANs, subnets, gateway model, and addressing notes |
| docs/security-architecture.md | ASA zones, ACLs, NAT, DMZ, and management-plane security |
| docs/routing-redundancy.md | OSPF, HSRP, EtherChannel, dual ISP, and failover considerations |
| docs/wireless-voice-services.md | WLC, lightweight AP, SSID, and Cisco voice gateway design |
| docs/implementation-flow.md | Practical build order for deploying the lab |
| docs/testing-validation.md | Validation checklist and non-fabricated test guidance |
| docs/lessons-learned.md | Engineering takeaways from the project |
| docs/future-enhancements.md | Professional next-step improvements |
| configs/ | Device configurations split by role |
| diagrams/ | Extracted PDF diagrams and screenshots with descriptive filenames |
| screenshots/ | Reserved for future validation evidence captures |
| assets/image-inventory.md | Inventory of every extracted visual asset |
| references/source-scope.md | Sanitized source scope and assumptions |
- Build a secure enterprise network for a three-floor company building.
- Segment departments and services using VLANs and routed interfaces.
- Protect the perimeter with Cisco ASA inside, outside, and DMZ zones.
- Support redundant internet access through two ISP paths.
- Provide high availability through HSRP and redundant core switching.
- Use OSPF to exchange routes between the enterprise, firewall, ISP, and cloud simulation.
- Centralize DHCP for enterprise networks through Active Directory DHCP.
- Support wireless access through a Cisco WLC and lightweight access points.
- Support IP telephony with a Cisco voice gateway and a dedicated voice VLAN.
- Harden access ports with PortFast, BPDU Guard, and blackhole VLAN assignment.
| Technology | Project Role | Why It Matters |
|---|---|---|
| Cisco ASA 5500-X | Security perimeter | Enforces zone-based control between inside, DMZ, and outside networks. |
| Cisco Catalyst 3850 | Core multilayer switching | Provides routed SVIs, HSRP gateways, and resilient campus switching. |
| Cisco Catalyst 2960 | Access and service switching | Provides departmental endpoint connectivity and server/access VLAN presentation. |
| VLANs | Segmentation | Separates management, LAN, WLAN, voice, inside servers, and unused ports. |
| OSPF | Dynamic routing | Allows routing changes to propagate across core, firewalls, ISPs, and cloud simulation. |
| HSRP | Gateway redundancy | Provides virtual default gateways for VLANs if a core switch fails. |
| EtherChannel/LACP | Link aggregation | Bundles core switch interconnects for bandwidth and link resilience. |
| STP PortFast and BPDU Guard | Layer 2 protection | Accelerates safe endpoint port startup and protects against rogue switch attachment. |
| NAT | Address translation | Allows internal and DMZ networks to communicate externally through firewall interfaces. |
| ACLs | Traffic control | Restricts management access and controls permitted ICMP, HTTP, and DNS flows. |
| Active Directory DHCP | Address assignment | Centralizes IP leasing for data, wireless, and management/client VLANs. |
| DNS | Name resolution | Supports enterprise and service reachability. |
| RADIUS | Authentication services | Represents centralized identity support for controlled access services. |
| Cisco WLC and LAPs | Wireless | Centralizes SSID and lightweight AP management. |
| Cisco Voice Gateway | VoIP | Provides telephony services and DHCP option 150 for IP phones. |
The topology begins with simulated global clients connected through an internet/cloud segment. Two ISP routers provide upstream paths into the enterprise edge. The perimeter contains two Cisco ASA firewalls with outside, inside, and DMZ-facing interfaces. Behind the firewalls, two multilayer core switches provide campus routing, VLAN gateways, HSRP redundancy, OSPF participation, and LACP-based inter-switch connectivity. Department access switches connect wired clients, IP phones, wireless AP segments, and unused blackhole ports.
Figure 3: Core switch redundancy model showing HSRP gateway roles and LACP/EtherChannel between the multilayer switches.
Figure 4: Department access-layer layout showing repeated access-switch patterns for user, wireless, voice, and unused-port segmentation.
| VLAN | Name | Subnet | Function |
|---|---|---|---|
| 10 | MGT | 192.168.10.0/24 |
Management network and authorized remote administration source. |
| 20 | LAN | 172.16.0.0/16 |
Primary wired enterprise user network. |
| 50 | WLAN | 10.20.0.0/16 |
Wireless client and WLC/LAP-connected network. |
| 70 | VoIP | 172.30.0.0/16 |
IP phone and voice gateway services. |
| 90 | InsideServers | 10.11.11.32/27 |
Internal server infrastructure, including DHCP and DNS. |
| 199 | BlackHole | Not routed | Shutdown VLAN for unused access-layer ports. |
HSRP uses .1 as the virtual gateway pattern for major VLANs. Core switch addressing follows the design note where Core SW2 uses .2 and Core SW1 uses .3 on VLAN SVIs. VLAN 90 uses 10.11.11.33 as the virtual gateway, with individual core switch SVIs assigned from the same inside-server range.
IRONVEIL uses segmentation and perimeter control as its primary security model:
- Inside zones connect protected enterprise VLANs and core routing domains.
- DMZ zone hosts public-facing or semi-public services such as web, email, FTP, app, and NAS-style services.
- Outside zones connect to ISP and internet/cloud simulation paths.
- Management access is limited to the management subnet through standard ACL logic on access switch VTY lines.
- Unused access ports are placed into the blackhole VLAN and administratively shut down.
- ACLs permit only documented inspection/test services such as ICMP, HTTP, and DNS where configured.
- NAT translates inside and DMZ networks to firewall outside interfaces.
Figure 5: ASA firewall zoning model showing inside NAT domains and outside static/default route paths.
The firewall layer uses Cisco ASA interfaces with clear security levels:
| Zone | Security Level | Purpose |
|---|---|---|
| Inside | 100 | Trusted enterprise-facing connectivity from core switches. |
| DMZ | 70 | Controlled server segment for exposed or shared services. |
| Outside | 0 | Untrusted ISP-facing connectivity. |
The DMZ contains web, email, FTP, application, and NAS/storage services connected through a dedicated DMZ switch. The DMZ subnet in the source design is 10.11.11.0/27, separate from the inside-server subnet used behind the campus core.
Figure 6: DMZ/server farm segment with dedicated service hosts connected to the DMZ switch.
NAT rules are defined per source subnet and firewall interface pair. This makes the translation intent explicit: DMZ traffic can translate through outside interfaces, wired LAN traffic can translate through inside-to-outside mappings, and WLAN traffic has separate object definitions for both firewall paths.
OSPF process 35 is used across the design for dynamic route advertisement. The core switches advertise management, LAN, WLAN, inside-server, and transit networks. Firewall and ISP routers advertise the relevant outside and point-to-point networks. Cloud simulation networks are advertised from the internet cloud router.
HSRP is configured between Core SW1 and Core SW2. Core SW1 is active for VLANs 10 and 20, while Core SW2 is active for VLANs 50 and 90. That split distributes gateway responsibility while preserving a virtual default gateway for clients.
Dual ISP routing is represented by two upstream routers:
CONVERSE-ISPconnects the105.100.50.0/30and105.100.50.4/30firewall edge networks.PLDT-ISPconnects the197.200.100.0/30and197.200.100.4/30firewall edge networks.
Figure 7: Dual ISP edge segment with separate upstream routers and point-to-point transit networks.
Figure 8: Cloud/internet router segment representing external reachability through the simulated internet.
The wireless design uses a Cisco Wireless LAN Controller with lightweight APs. Wireless users are separated from the wired LAN through VLAN 50, and the controller must be connected to the VLANs required for LAP management and wireless client traffic. The source design identifies multiple SSID groups: Employees, Guest, Auditors, and Corporates.
The WLC configuration in the lab uses placeholder administrative credentials and shared wireless passwords. Those values are intentionally treated as lab-only and should be replaced with enterprise identity integration, per-SSID policy, and centralized authentication in any real deployment.
Figure 9: Wireless LAN controller and voice gateway services segment.
Voice endpoints are isolated into VLAN 70. The Cisco voice gateway uses a router subinterface with dot1Q 70, provides DHCP for phones, and supplies option 150 pointing phones to the call-control source address. The lab configuration supports up to 30 phones and 30 directory numbers.
Access switches use switchport voice vlan 70 for IP phone ports rather than treating phones as ordinary data access ports. This preserves the separation between data and voice traffic while keeping endpoint deployment practical at the access layer.
The inside server segment supports DHCP, DNS, RADIUS, and WLC-related services. Active Directory DHCP is responsible for leasing addresses to enterprise departments and non-voice network segments, while the voice gateway handles DHCP for IP phones.
Figure 10: Inside server network containing DHCP, DNS, RADIUS, and associated service nodes.
The server switch is unique because it trunks selected ports and presents access ports for inside-server and WLAN-related infrastructure.
Important configuration areas are split into files under configs/:
- Core VLANs, routed interfaces, SVIs, HSRP, OSPF, and EtherChannel.
- ASA interfaces, security levels, static/default routing, OSPF, NAT objects, and ACL bindings.
- Department access switch baseline with SSH, management ACL, VLANs, data ports, voice ports, AP ports, and blackhole shutdown ports.
- DMZ switch hardening with PortFast and BPDU Guard.
- Inside server switch trunk/access layout.
- ISP and cloud router OSPF configurations.
- Voice gateway subinterface, DHCP pool, and telephony-service configuration.
Example HSRP pattern:
interface Vlan20
ip address 172.16.0.3 255.255.0.0
ip helper-address 10.11.11.36
standby 20 ip 172.16.0.1
Example firewall NAT pattern:
object network INSIDE1-OUTSIDE1
subnet 172.16.0.0 255.255.0.0
nat (INSIDE1,OUTSIDE1) dynamic interface
Core and firewall configuration entry points
The source document states that reliability, performance, and security were tested, but it does not provide detailed test logs or packet captures. This repository therefore documents a validation plan rather than inventing results.
Recommended validation areas:
| Area | Validation Method |
|---|---|
| VLAN segmentation | Confirm endpoints receive expected subnet addressing and cannot access unauthorized VLANs. |
| HSRP | Shut down an active SVI/core path and verify default gateway continuity. |
| OSPF | Confirm neighbor formation and route propagation across core, firewall, ISP, and cloud routers. |
| NAT | Verify inside and DMZ networks translate through expected ASA outside interfaces. |
| ACLs | Confirm management access is accepted only from VLAN 10 and denied elsewhere. |
| DMZ | Verify only intended services are reachable through firewall policy. |
| Wireless | Confirm WLC-managed AP association and SSID-to-VLAN behavior. |
| VoIP | Confirm phone DHCP, option 150 delivery, and directory number assignment. |
- Redundant connectivity is most useful when routing, gateway design, and interface addressing are documented together.
- Security zones should be named consistently because NAT and ACL logic depend on exact interface mappings.
- Voice networks need their own access-layer treatment;
switchport voice vlanis cleaner than mixing phone traffic into ordinary access VLAN logic. - DHCP relay should be planned early so every routed VLAN has a clear path to the correct DHCP authority.
- Blackhole VLANs and shutdown ports are simple but important controls for unused edge interfaces.
- A professional network design is easier to operate when diagrams, configs, and implementation flow remain synchronized.
Potential enhancements are documented as future work, not as implemented features:
- Zero Trust policy model for identity-aware segmentation.
- SIEM integration for firewall, switch, wireless, and server telemetry.
- IDS/IPS sensors at the internet edge and DMZ boundary.
- Centralized syslog, NetFlow, and configuration archive services.
- Network Access Control for wired and wireless admission control.
- Backup internet failover testing with measured convergence times.
- Infrastructure as Code documentation using templates or network automation tooling.
- Monitoring dashboards for availability, interface health, wireless clients, and voice status.
- Disaster recovery runbooks for firewall, core switch, DHCP/DNS, and WLC restoration.
- Cloud security extension for hybrid connectivity and cloud workload segmentation.
.
|-- README.md
|-- CHANGELOG.md
|-- assets/
| |-- image-inventory.md
| `-- pdf-image-manifest.tsv
|-- configs/
| |-- README.md
| |-- access-switches/
| | `-- department-access-switch-template.cfg
| |-- core-switches/
| | |-- common-vlan-trunks.cfg
| | |-- core-sw1.cfg
| | `-- core-sw2.cfg
| |-- dmz/
| | `-- dmz-switch.cfg
| |-- firewalls/
| | |-- fw1.cfg
| | `-- fw2.cfg
| |-- routers/
| | |-- cloud-router.cfg
| | |-- cloud-switch.cfg
| | |-- isp-router-1-converse.cfg
| | `-- isp-router-2-pldt.cfg
| |-- server-switches/
| | `-- inside-server-switch.cfg
| `-- voice/
| `-- voice-gateway.cfg
|-- diagrams/
| |-- README.md
| |-- cloud-router-segment.png
| |-- core-switch-hsrp-etherchannel.png
| |-- department-access-layer-layout.png
| |-- dmz-server-farm.png
| |-- dual-isp-edge-routing.png
| |-- enterprise-topology-overview-page-01.png
| |-- enterprise-topology-overview-page-02.png
| |-- firewall-zone-design.png
| |-- inside-server-farm-layout.png
| `-- wlc-voice-services-segment.png
|-- docs/
| |-- addressing-and-vlans.md
| |-- architecture-overview.md
| |-- future-enhancements.md
| |-- implementation-flow.md
| |-- lessons-learned.md
| |-- routing-redundancy.md
| |-- security-architecture.md
| |-- testing-validation.md
| `-- wireless-voice-services.md
|-- references/
| `-- source-scope.md
`-- screenshots/
|-- README.md
`-- .gitkeep








