¶ Network — Domain Overview
Domain Owner: Network Engineering
Standards Body: Cisco / Meraki / Palo Alto
¶ What This Domain Covers
The Network domain spans all connectivity infrastructure: campus LAN, data centre switching and routing, wide-area network (WAN / SD-WAN), wireless, DNS, DHCP, and network security perimeter. The network is the connective tissue that links compute, desktop, cloud, and external partners.
| Page |
Description |
| Network Architecture |
Core topology, addressing, routing design |
| SD-WAN |
Cisco Catalyst SD-WAN deployment, policy, and operations |
| Wireless |
Wi-Fi standards, SSID design, Meraki management |
| DNS & DHCP |
Enterprise DNS/DHCP standards, split-DNS, IPAM |
Internet
│
├── [2x Palo Alto PA-5450 — Active/Passive]
│ Internet Edge Firewall
│
├── [DMZ] — reverse proxies, external-facing services
│
├── [Core Routing Layer] — Cisco Catalyst 9500 (VSS pair)
│ BGP: AS 65001 (internal)
│ OSPF Area 0 (backbone)
│
├── [Data Centre Fabric] — Cisco Nexus 9300 (vPC)
│ DC1-CORE-01 / DC1-CORE-02
│
├── [Campus Distribution] — Cisco Catalyst 9300 (StackWise)
│ Per-building distribution switch pairs
│
├── [Access Layer] — Cisco Catalyst 9200 / Meraki MS Series
│ Per-floor access switches
│
└── [WAN / SD-WAN] — Cisco Catalyst SD-WAN (vEdge)
All branch sites via MPLS + broadband overlay
| Protocol |
Scope |
Notes |
| BGP (eBGP) |
Internet edge, cloud peering |
AS 65001; prefix filtering enforced |
| BGP (iBGP) |
DC core, cloud Direct Connect |
Route reflectors in DC1 and DC2 |
| OSPF Area 0 |
Campus and DC core |
Redistribute from BGP with metric |
| OSPF Area N |
Per-building stub areas |
LSA type 3 summarised at distribution |
| Static |
Last-resort defaults, OOB |
Documented in IPAM |
All IP address allocation is managed in NetBox (IPAM). No subnets or IPs are to be manually assigned without a NetBox entry. Request new allocations via the #network-ipam Slack channel or raise a ServiceNow request.
| Block |
Purpose |
| 10.0.0.0/8 |
Corporate internal (all sites) |
| 10.0.0.0/16 |
DC1 — servers, virtualisation |
| 10.1.0.0/16 |
DC2 — DR, replication |
| 10.10.0.0/16 |
Campus HQ |
| 10.20.0.0/16 – 10.50.0.0/16 |
Branch sites (per site /24) |
| 172.16.0.0/12 |
AWS VPC allocations |
| 172.32.0.0/12 |
Azure VNet allocations |
| Role |
Team |
Slack |
| Domain Architect |
Network Architecture |
#arch-network |
| Network Operations |
NOC |
#noc-alerts |
| IPAM Owner |
Network Engineering |
#network-ipam |
| Wireless Lead |
Network Engineering |
#team-wireless |
¶ Related Domains
- Compute — network connectivity for DC and cloud
- Cyber Security — firewall policy, network segmentation
- Desktop — endpoint connectivity and SSID access