Network engineering case study

A safer path for production traffic.

A manufacturing network design that separates production, office, and CCTV traffic while preserving visibility and priority for business-critical systems.

By Nadeeja NirmalaIT Manager and network engineerUpdated 14 August 2026

Why segment a manufacturing network?

Network segmentation limits how far a fault, compromise, or unnecessary broadcast can travel. In a manufacturing environment, it also separates systems with different risk and availability needs, so office activity, surveillance traffic, and production services do not all share one unrestricted trust boundary.

The design treats production, office, and CCTV as distinct zones. That creates clearer access rules, makes traffic easier to understand, and allows production applications such as ERP to receive deliberate priority.

Security zones3 segments
Business priorityERP QoS
VisibilityFirewall + IDS

How the network is separated

Production zone

Production traffic receives the strictest operational attention and priority. Access is based on what the service needs rather than broad reachability.

Office zone

Business users and normal workplace services operate in their own segment, reducing direct exposure to production equipment.

CCTV zone

Surveillance devices are isolated from general business systems. This limits unnecessary paths from embedded devices into higher-trust services.

Security and traffic controls

  • Firewall policy: inspects and enforces traffic between zones.
  • Intrusion detection: adds visibility into traffic patterns and suspicious activity.
  • Encrypted DNS: uses DoH or DoT where appropriate to protect resolver traffic.
  • Quality of service: gives ERP and production-relevant flows deliberate priority.

The goal is not to add controls for appearance. Each control should have a clear operational reason, an owner, and a way to confirm it is still working.

How I approach network changes

I begin with the actual traffic and dependencies, not an idealized diagram. I identify what must communicate, separate what should not, stage the smallest safe change, and verify both intended connectivity and blocked paths. The final topology should be easier to operate than the one it replaces.

Documented scopeProduction, office, and CCTV zones with explicit traffic boundaries
Verification focusRequired paths, blocked paths, monitoring visibility, and ERP priority

Need someone who can own the network and the wider system?

I work across routing, segmentation, DNS security, servers, recovery, and the user-facing services that depend on them.

Start a conversation
Nadeeja NirmalaIT Manager and hands-on engineer. View background and credentials.
Next case studyHybrid systems engineeringRelated capabilityDisaster recovery design