Network engineering consultancy

Brought in when the cutover can't go wrong.

AdvancedEC is a project-based network engineering practice. Campus wireless and wired design, NAC rollouts, platform migrations, and the server and cloud infrastructure underneath — Aruba and Cisco, hands on the equipment, with documentation your team keeps when the engagement ends.

The practice
Model
Project-based
Scoped work, defined end
Core stacks
Aruba & Cisco
Wired, wireless, and NAC on both
Breadth
20+ platforms
Network, server, virtual, cloud
Environments
Enterprise scale
Multi-facility campus estates
01 — Engagements The work

Specific, scoped projects — the ones with a maintenance window, a rollback plan, and consequences if they go sideways. Not a support contract, and not a body in a seat.

Design

Campus network design

Wired and wireless design for new buildings, refreshes, and expansions — addressing, segmentation, and naming conventions written down so the tenth site matches the first.

  • Wireless surveys and AP placement
  • Switching, uplinks, and campus fabric
  • Addressing, VLAN, and segmentation models
Migration

Platform migration & refresh

Aruba to Cisco, Cisco to Aruba, or a generational refresh in place. Planned cutovers with a tested fallback, staged by site rather than attempted in one night.

  • Controller and management-plane transitions
  • Switch refresh and configuration conversion
  • Phased cutover and rollback planning
Access

NAC rollout

ClearPass and ISE from policy model through enforcement. The phase most rollouts stall on is going from monitor mode to enforcement without locking out the building — that phase is the work.

  • Role, policy, and profiling design
  • Guest and contractor access
  • Staged enforcement with exception handling
Assessment

Assessment & standards

What is actually deployed versus what the documentation claims, where the two drifted, and what it will cost to close the gap. Delivered as a written report you keep either way.

  • Configuration and standards audit
  • Documentation and diagram rebuild
  • Ranked remediation plan with costs
Infrastructure

Server & virtualization

VMware and Hyper-V estates, Windows Server and Active Directory, DNS and DHCP — designed and consolidated alongside the network rather than as someone else's separate project.

  • vSphere and Hyper-V design and consolidation
  • Active Directory and DNS/DHCP structure
  • Microsoft 365 and hybrid identity
Automation

Automation & tooling

Configuration generation, source-of-truth reconciliation, and reporting built against your systems — so the repetitive part of the last project doesn't have to be repeated by hand on the next one.

  • Config generation from your standards
  • IPAM, CMDB, and monitoring reconciliation
  • Custom integration against vendor APIs

02 — Experience Platform depth

Two network stacks carried end to end, and the server, virtualization, and cloud infrastructure underneath them. Not certification-deep — deployment-deep. The distinction matters when the window is four hours and the fallback has to actually work.

Full product line

Aruba / HPE Networking

The complete stack, from access layer to policy enforcement.

Wireless
Campus and Instant AP deploymentsCentral and CNX Cloud management
Wired
AOS-CX switching, campus fabricConfiguration generation and standards enforcement
NAC
ClearPass — policy, roles, guestDynamic segmentation and enforcement
Assurance
UXI sensors and user-experience monitoring
Wired · wireless · NAC

Cisco

The parallel stack, for organizations standardized on Cisco.

Wireless
Catalyst wireless, controller and access design
Wired
Catalyst switching and IOS-XECatalyst Center for site and config workflows
NAC
ISE — policy, profiling, segmentationPosture and guest services
Voice
Unified Communications Manager integration

Infrastructure — designed, built, operated

DomainPlatforms
WirelessAruba Central & Instant, Cisco Catalyst wireless, Ubiquiti UniFi
Wired & switchingAruba AOS-CX, Cisco Catalyst / IOS-XE, Ubiquiti
Network access controlAruba ClearPass, Cisco ISE
IPAM, DNS & DHCPBlueCat, Infoblox, Windows DNS / DHCP
VirtualizationVMware vSphere / ESXi, Microsoft Hyper-V
Server infrastructureWindows Server, Active Directory, file & print services
Cloud & identityMicrosoft 365, Entra ID, Exchange Online

Integrated in automation work

DomainPlatform
OT & device visibilityClaroty
Certificate lifecycleAppViewX
ITSM & CMDBServiceNow
MonitoringSolarWinds
Endpoint managementWorkspace ONE
Power & environmentalEcoStruxure
Physical securityAvigilon
Enterprise printLRS

03 — Selected work Engagements

Client names, locations, and identifying details are withheld under confidentiality. The projects below are described by their shape rather than their logos.

Enterprise

Large multi-facility campus estate

Network automation console

Designed and built an internal platform that generates switch and access-point configuration from documented standards, then reconciles it against the systems that are supposed to agree — IPAM, NAC, monitoring, and the CMDB. Replaced a build process that ran on spreadsheets and institutional memory.

Aruba CentralClearPassBlueCatClarotyServiceNow
Portability

Second estate, different vendor stack

Multi-vendor portability

Reworked that platform so it is not welded to one organization's vendor choices. Each capability — network management, access control, IPAM — sits behind a driver interface, so a site on one vendor stack runs the same product as a site on another, with the inapplicable pieces switched off rather than half-built.

Catalyst CenterCisco ISEInfobloxCapability model
IPAM migration

Enterprise DDI transition

Address-space reconciliation

Built the tooling to migrate between IPAM platforms without trusting either one blindly — reconciling fixed leases against reservations by IP address, enriching each record with its device profile, and producing the exception list of what genuinely had to be resolved by hand.

InfobloxBlueCatReconciliation
Restricted environment

Network with no outbound connectivity

Air-gapped deployment

Packaged the platform to install into an environment with no outbound connectivity at all — delivered by copied bundle rather than by URL, with signed updates, automatic snapshots, and rollback. No agent phoning home and no standing inbound access into the protected network.

Air-gappedSingle-tenantSigned updates

04 — Approach How it runs

Three stages, whether the engagement ends in a design document or a completed cutover.

STAGE 01

Assess

What is actually deployed, what the standards say, and where the two have drifted apart. You get written findings — ranked, costed, and yours regardless of whether the project continues.

STAGE 02

Execute

Design and implementation against a fixed scope. Migration path, rollback, and maintenance windows agreed before anything is touched — not improvised at 2 a.m.

STAGE 03

Hand over

Documentation, diagrams, and any automation built along the way, transferred to your team. The measure of success is that you don't need to call me about it again.

05 — Contact Start here

Tell me what the project is.

A migration you would rather not run alone, a NAC rollout that stalled in monitor mode, or a network nobody has documented in six years. First conversation costs nothing.

Discuss a project
Phone To be confirmed
Based in To be confirmed
LinkedIn To be confirmed