Network engineering · Security · Testing · Since 2004
Networks built to hold up — and proof that they do.
ZAR Tech is an Ontario consulting practice with two halves that feed each other: Cisco, Palo Alto and Arista design and deployment on one side, security testing on the other — segmentation validation, firewall rulebase review, and network penetration testing. Twenty years of building enterprise networks is what makes us good at finding the gaps in them.
Reference build · edge → NGFW HA pair → EVPN/VXLAN fabric → segmented zones, then tested
Services
Three practices, one engineer accountable for all of them.
No account layer, no handoff to an offshore NOC. You deal with the person writing the config, running the test, and standing in the comms room at 2 a.m. during cutover.
Security testing
Segmentation & penetration testing
Scoped, authorised testing of the controls that are supposed to be holding. Detail below.
- Segmentation validation — card, OT and management zones
- Firewall rulebase review against intended policy
- External and internal network penetration testing
- Wireless assessment and guest isolation testing
- Design validation on networks we built
- Retest and remediation verification included
Findings ranked by exploitability, not CVSS alone
Written authorisation and rules of engagement, always
Network
Design, configure, install
Greenfield builds, refreshes and migrations — from the rack and the cabling to the routing table.
- Campus and datacentre LAN, spine-and-leaf fabrics
- WAN and SD-WAN, MPLS and broadband failover
- BGP, OSPF, VRFs, EVPN/VXLAN
- Wireless survey, design and deployment
- Structured cabling — CAT6 and fibre, rack and stack
- Cutover plans, rollback runbooks, night-of execution
IOS-XE · NX-OS · EOS · PAN-OS
Catalyst · Nexus · 7050X · 720XP
Security
Firewalls & segmentation
Perimeter and internal controls that are documented, reviewable, and survive an audit.
- Palo Alto and Cisco firewall design and migration
- Rulebase cleanup — shadowed, permissive, orphaned rules
- Zero-trust segmentation and east-west policy
- Remote access VPN and site-to-site rebuilds
- NAC and 802.1X rollout
- Logging, alerting and SIEM feed design
PA-Series · Panorama · Firepower · ASA
ISE · GlobalProtect · IPSec / SSL VPN
Security testing
Testing run by people who build the same networks for a living.
Most test reports land as a scanner dump with a CVSS column. Ours come from an engineer who has configured the firewall you are asking about, so the findings name the rule, the interface and the fix — and we stay on to verify the remediation.
| Engagement | What we test | What you get |
|---|---|---|
| Segmentation validation | Card, OT and management zones against the policy that is supposed to separate them. Rule by rule, both directions, from inside each zone. | Pass/fail matrix Rulebase remediation list |
| Firewall rulebase review | Every rule against intended policy: shadowed and orphaned entries, any/any permits, unused objects, drift between the config and the design. | Rule-level findings Cleanup change plan |
| External penetration test | Internet-facing perimeter, VPN gateways, published services, exposed management planes. | Ranked findings Exec summary Free retest |
| Internal penetration test | Assumed-breach from a user VLAN: lateral movement, credential capture, reachability of infrastructure that should be out of reach. | Attack path walkthrough Choke-point fixes |
| Wireless assessment | PSK and 802.1X attacks, rogue and evil-twin AP, guest isolation, BYOD boundaries, coverage bleed outside the building. | Findings plus RF map |
| Design validation | For networks we built: failover drills, policy conformance, as-built against the agreed design. Not a substitute for an independent test. | Conformance report Signed-off as-builts |
We do not audit our own work.
Where ZAR Tech designed or installed the network, we run design validation — testing the build against the agreed design and policy: failover drills, policy conformance, as-built verification — and we will point you to an independent firm for the penetration test. Adversarial testing is for networks we did not build. It keeps the result credible for your auditors, and for you.
Every engagement runs under written authorisation and agreed rules of engagement, with a named contact on your side for the duration.
How an engagement runs
Understand, design, build, prove.
Same sequence whether it is a two-week firewall migration or a full site build. Each stage has a deliverable you keep.
Discover
Site walk, config pull, traffic and dependency mapping. You get a current-state diagram that matches reality.
Design
Low-level design, IP and VLAN plan, policy model, bill of materials. Reviewed with your team before anything is ordered.
Implement
Staged build, lab validation, scheduled cutover with a written rollback. Change records and as-builts on completion.
Prove
Design validation on our own builds — failover drills and policy conformance. Full penetration testing where someone else built it.
Experience
Two decades inside regulated, high-availability environments.
Work delivered directly and through prime contractors for Canadian Schedule I banks, a global insurer, provincial government, national telecom carriers and one of the country's largest grocery retailers. Client names are held in confidence and shared on request under NDA.
Get in touch
Tell us what the network has to do, or what you need proven.
Scoping calls are free. Send the site count, the vendors in play, and your deadline — or, for testing, the scope and whether you own the environment. You will get a straight answer on feasibility and rough effort, not a brochure.
Milton, Ontario L9T 5Y5