A complete 1,000-bed hospital network designed, built, and documented from scratch as the flagship engagement for Ali-AS Network LLC. Dual-ISP BGP edge, two redundant pfSense CARP firewall pairs, hardware-isolated OT/SCADA stack, per-floor VLAN segmentation, and a HIPAA-defensible architecture where every rule has a documented rationale. Every secondary node config was generated programmatically. Zero single points of failure.
A hospital network isn't just a large office network. It's a life-critical system that has to satisfy simultaneously conflicting requirements — and getting the architecture wrong has consequences that go beyond downtime.
This project is the answer to all four of those problems at once. Every design decision was made against this backdrop.
Built top to bottom, verified at each layer before proceeding. Here's exactly what runs at every tier and why.
Every IP address in this network tells you what it is before you look it up. The scheme was designed so that reading a log entry or a packet capture immediately reveals the zone, the VLAN, and the role of the device.
The consistent .1/.2/.3 pattern across every VLAN — CARP VIP, fw2, fw3 — means troubleshooting is mechanical. If something on VLAN 14 (radiology) can't reach its gateway, you know the gateway is 10.21.14.1 without looking it up. You know fw2 is 10.21.14.2 and fw3 is 10.21.14.3. You know the OT equivalent is 10.22.14.x if it existed. The scheme scales to new VLANs and new sites without breaking the mental model.
PHI-bearing VLANs are isolated from each other and from everything else. OT runs on a completely separate addressing zone. Guest is deliberately off the 10.x.x.x range to make accidental routing impossible.
The OT network is not a separate VLAN. It's a separate physical stack with its own firewall pair, its own distribution switches, its own access switches, and its own addressing zone. The only connection between IT and OT is a single controlled path through the jump host.
Every config in this writeup is real. These are live screenshots from the running topology — pfSense WebGUI, firewall rules, and CARP status as the network operates.
Every design decision has a documented reason. These aren't preferences — they're choices that can be defended to a HIPAA auditor, a hospital CIO, a senior network engineer, and a skeptical client asking why the bill is what it is.
Every network control in this design maps to a specific HIPAA Security Rule requirement. The architecture isn't HIPAA-compliant by accident — it was built against these requirements from the ground up.
The full topology was built in EVE-NG with 30+ nodes. Each layer was validated independently before proceeding to the next. Failures were documented and resolved. One limitation was found and documented honestly rather than worked around.
vtp primary vlan command. All 16 VLANs propagated to Core-21 via EtherChannel trunk automatically. Confirmed VTP client mode on Core-21 with matching domain and password.This project wasn't built from a template. It was built, broken, redesigned, and rebuilt. Here are the things that changed between the first design and the final one.
I'm a network engineer based in Lancaster, PA. My day-to-day involves BGP, OSPF, VRRP, MLAG, pfSense HA firewall clusters, and MikroTik hardware — the same stack that runs Valleybrook. I didn't design this network in a vacuum. I designed it against the same problems I solve at work, with the same tools I use every day.
I founded Ali-AS Network LLC as a solo network consulting venture targeting municipalities, medical offices, and SMBs. The positioning is audit-first, I go into a network, document what exists, identify what's broken or risky, and build a remediation plan. Valleybrook is what that engagement looks like when the client needs the full buildout, not just the audit.
The things in this project that I'm most proud of aren't the technologies, it's understanding and the decisions. Deciding that two internal firewalls was overcomplicated and the right answer was one well-configured pair. Deciding that the OT handoff needed its own dedicated L2 switch rather than going through the core stack. These are the decisions that come from understanding what you're building and why, not from following a template.
BGP/OSPF on enterprise fiber infrastructure · pfSense HA firewall clusters · MikroTik RouterOS · VRRP · iPerf3 throughput testing · production fiber infrastructure engineering
Solo network consulting · audit first positioning · Lancaster County PA · municipalities · medical offices · SMBs · PA LLC filed · aliasnetwork.net
If you want a network engineer who thinks about the why, not just the how: [email protected]