Skip to content
BigTree108

Network engineering services

Network engineering services for offices, data centres, clouds and provider networks: routing and switching on Cisco, Juniper and Arista, firewalls from Fortinet, Palo Alto Networks and Check Point, network design, cloud networking, SD-WAN and zero-trust access, Wi-Fi and network automation, with dedicated network engineers for your team or network projects delivered end to end.

Network engineering we take on

  • Routing and switching

    Campus, branch and core networks on Cisco, Juniper, Arista, HPE Aruba Networking or MikroTik, with OSPF and BGP routing, redundant uplinks, and configurations backed up and compared after every change.

  • Firewall administration

    FortiGate, Palo Alto Networks, Check Point and Cisco firewalls with rule sets reviewed and cleaned up, segments between users, servers, guests and devices, site-to-site VPNs, and firmware kept on releases the vendor still supports.

  • Network design and documentation

    Topology, addressing, VLANs and routing designed for your sites and traffic, with NetBox as the record of every device, prefix and cable, and diagrams that match what is installed.

  • Cloud networking

    VPCs and VNets with address ranges that do not clash, hub-and-spoke networks through AWS Transit Gateway, Azure Virtual WAN or Google Cloud Network Connectivity Center, private endpoints, and Direct Connect, ExpressRoute or Cloud Interconnect links to your data centres.

  • SD-WAN and zero-trust access

    Branches moved from MPLS to SD-WAN on Fortinet, Cisco Catalyst SD-WAN or Palo Alto Networks, and remote access moved from VPNs to zero-trust access through Zscaler, Cloudflare One, Netskope or Prisma Access.

  • Wireless networks

    Wi-Fi designed from a site survey for coverage and capacity, WPA3 and 802.1X sign-in against your identity provider, and separate networks for staff, guests and devices.

  • Data centre and provider networks

    Leaf-spine fabrics with EVPN-VXLAN on Arista, Cisco Nexus or Juniper, F5 BIG-IP and HAProxy load balancers, and BGP peering, MPLS and IPv6 for hosting companies, internet providers and telecom operators.

  • Network automation

    Configurations generated and pushed by Ansible, Python or Terraform providers from NetBox as the source of truth, changes tried first on a Containerlab copy of the network, and compliance reports produced from the devices rather than written by hand.

  • Access control and traffic analysis

    802.1X network access control with Cisco ISE or ClearPass, NetFlow and SNMP monitoring in LibreNMS, Zabbix or PRTG, and packet captures that settle whether the network or the application is at fault.

Hire network engineers

  • Dedicated network engineers

    Network engineers who join your team full time, work in your tools and process, and report to your lead. You interview them; we carry the Ukrainian contract, payroll, invoicing and leave.

  • Network engineering projects

    A defined piece of network engineering with a scope, a fixed plan and a named lead on our side who owns the result and reports progress in your channels.

  • Ongoing network engineering

    Network engineering as a continuing service: the same people every month, a backlog you prioritise, and hours you can see in our portal and on the invoice.

The dedicated team page explains how specialists join your team, and the outsourcing page covers project delivery, take-overs and how we charge.

Who works on your network engineering

  • Network engineers

    Routing, switching and network design

  • Network security engineers

    Firewalls, VPNs and zero-trust access

  • Cloud network engineers

    VPCs, VNets and hybrid links

  • Network automation engineers

    Ansible, Python and NetBox

  • Wireless engineers

    Site surveys, design and tuning

How we run networks

The network is recorded before it is changed: NetBox or your own records as the source of truth, configurations backed up and versioned, and every change planned with a rollback, approved and made in an agreed window. Where the equipment allows it, changes are pushed by automation from Git rather than typed into a console.

Access is denied by default, with segments between users, servers, guests and devices, and administrators sign in through named accounts with multi-factor authentication. On a network another team built, we start with a read-only review of configurations, firmware, rules and diagrams, and a written list of risks in order of impact. Our own cloud estate runs behind deny-by-default firewalls under the same rule.

Other cloud, DevOps and security services

Cloud, DevOps and security overview

Questions about network engineering

Which industries do your network engineers work in?

Mostly cloud, hosting and telecom companies running provider networks, data centres and customer connectivity; fintech and banking, with segmented and audited networks; industrial, manufacturing and energy companies keeping plant networks apart from office IT; security companies; retail and e-commerce businesses with many stores and warehouses; healthcare clinics; and public-sector offices.

Which vendors do you work with?

Cisco, Juniper, Arista, HPE Aruba Networking, MikroTik and Ubiquiti for routing, switching and Wi-Fi; Fortinet, Palo Alto Networks, Check Point and Cisco for firewalls; Zscaler, Cloudflare and Netskope for zero-trust access; and the networking services of AWS, Azure and Google Cloud. We work with the equipment you already have.

Can you move our sites from MPLS to SD-WAN?

Yes, one site at a time. The design and policies are proved at a pilot site, MPLS and SD-WAN run side by side while traffic moves across, and each site keeps a way back until its old circuit is cancelled.

How quickly can network engineers start?

When the right network engineer is available, the start is gated only by your interview and the NDA and IP assignment. Otherwise we run a search, which typically produces candidate profiles within two to three weeks, and nobody starts until you have said yes.

How do we hire network engineers through BigTree108?

Tell us the work, the seniority and the hours you need. We propose one or two people with their profiles, you interview them the way you would interview your own hire, and you sign one agreement with BIG TREE 108 LLC and receive one invoice a month.

Who owns the work they produce?

You do. Every specialist has a signed contract with BigTree108 that assigns all work product to the company, and our agreement with you assigns it onward. Code, designs and documents are delivered into your own repositories and tools, not kept where only we can change them.

Need network engineers?

Tell us how many sites you have, what equipment runs them and what needs to change. You get an answer within one business day: a plan for the work, a scope for a review, or candidate profiles.