ANIMATED TRAFFIC FLOW ยท DARK MODE ยท LIVE TOPOLOGY
Fibre WAN
1G Ethernet
10G MMF Fibre
2.5G Ethernet
IPsec Tunnel
Cloud / VPS
// Topology
FIREWALLFortiGate 40F
CORE SWITCHArista 7010T
ACCESS SWITCHESMikroTik + Ubiquiti
WANFibre (primary only)
WIFIWiFi 7 ยท U7 Lite
// VPN / Cloud
TUNNEL 1Centurion ยท FGโFG
TUNNEL 2RandPark ยท FGโRB750
TUNNEL 3Sandton ยท FGโRBD52G
LINODE VPSUptime Kuma ยท n8n
TUNNEL TYPEIPsec Site-to-Site
// Device Roles
FORTIGATE 40FEdge FW
ARISTA 7010TL3 Core
MIKROTIK CRS326Access SW
UBI PRO MAX 16Access SW
TP-LINK / U7Access Points
โ Lab Upgrade Requirements
โก FortiGate โ Single Point of Failure
The FortiGate 40F is the sole edge firewall. Any failure means complete loss of internet connectivity and all 3 IPsec site-to-site tunnels simultaneously.
Add a second FortiGate 40F in Active-Passive HA mode. Config sync ensures seamless failover with no manual intervention required.
๐ก No Redundant WAN โ Fibre Only
Running on a single Fibre ISP link. If the link drops, all connectivity is lost โ internet, remote management, and all 3 site-to-site tunnels go down with it.
Add a MikroTik LTE router connected to both FortiGates. FortiGate SD-WAN monitors link health and auto-fails to LTE within seconds of detecting failure.
โก Arista 7010T โ Single Point of Failure
The Arista is the sole L3 core switch. A failure here simultaneously isolates both access switches, all servers, all APs โ total network outage for every downstream device.
Add a second Arista 7010T and configure MLAG between the pair. Connect Proxmox and Linux servers via dual uplinks across both Aristas for active-active redundancy.
๐ Server NICs Bottlenecked at 1G
Both Proxmox hypervisor and Linux Ubuntu server connect at 1G only. With 10G MMF fibre available at the Arista, this creates a significant bottleneck for VM migrations, storage and backup traffic.
Upgrade both servers to dual 10G NICs (Intel X550-T2 or Mellanox ConnectX-3). Bond as LACP into the dual Arista MLAG pair for speed and redundancy.