Network engineering · Security · Testing · Since 2004

Networks built to hold up — and proof that they do.

ZAR Tech is an Ontario consulting practice with two halves that feed each other: Cisco, Palo Alto and Arista design and deployment on one side, security testing on the other — segmentation validation, firewall rulebase review, and network penetration testing. Twenty years of building enterprise networks is what makes us good at finding the gaps in them.

INTERNET BGP EDGE HA PAIR NGFW-01 NGFW-02 SPINE SPINE LEAF LEAF VLAN 20 · USERS VLAN 90 · CARD ZONE TEST PATH · SEGMENTATION UNDER TEST

Reference build · edge → NGFW HA pair → EVPN/VXLAN fabric → segmented zones, then tested

2004Incorporated in Ontario
20+ yrsEnterprise network delivery
Build & proveDesign, then test the controls
Cisco · PAN · AristaCore vendor depth

Services

Three practices, one engineer accountable for all of them.

No account layer, no handoff to an offshore NOC. You deal with the person writing the config, running the test, and standing in the comms room at 2 a.m. during cutover.

Security testing

Segmentation & penetration testing

Scoped, authorised testing of the controls that are supposed to be holding. Detail below.

  • Segmentation validation — card, OT and management zones
  • Firewall rulebase review against intended policy
  • External and internal network penetration testing
  • Wireless assessment and guest isolation testing
  • Design validation on networks we built
  • Retest and remediation verification included

Findings ranked by exploitability, not CVSS alone
Written authorisation and rules of engagement, always

Network

Design, configure, install

Greenfield builds, refreshes and migrations — from the rack and the cabling to the routing table.

  • Campus and datacentre LAN, spine-and-leaf fabrics
  • WAN and SD-WAN, MPLS and broadband failover
  • BGP, OSPF, VRFs, EVPN/VXLAN
  • Wireless survey, design and deployment
  • Structured cabling — CAT6 and fibre, rack and stack
  • Cutover plans, rollback runbooks, night-of execution

IOS-XE · NX-OS · EOS · PAN-OS
Catalyst · Nexus · 7050X · 720XP

Security

Firewalls & segmentation

Perimeter and internal controls that are documented, reviewable, and survive an audit.

  • Palo Alto and Cisco firewall design and migration
  • Rulebase cleanup — shadowed, permissive, orphaned rules
  • Zero-trust segmentation and east-west policy
  • Remote access VPN and site-to-site rebuilds
  • NAC and 802.1X rollout
  • Logging, alerting and SIEM feed design

PA-Series · Panorama · Firepower · ASA
ISE · GlobalProtect · IPSec / SSL VPN

Security testing

Testing run by people who build the same networks for a living.

Most test reports land as a scanner dump with a CVSS column. Ours come from an engineer who has configured the firewall you are asking about, so the findings name the rule, the interface and the fix — and we stay on to verify the remediation.

Engagement What we test What you get
Segmentation validation Card, OT and management zones against the policy that is supposed to separate them. Rule by rule, both directions, from inside each zone. Pass/fail matrix
Rulebase remediation list
Firewall rulebase review Every rule against intended policy: shadowed and orphaned entries, any/any permits, unused objects, drift between the config and the design. Rule-level findings
Cleanup change plan
External penetration test Internet-facing perimeter, VPN gateways, published services, exposed management planes. Ranked findings
Exec summary
Free retest
Internal penetration test Assumed-breach from a user VLAN: lateral movement, credential capture, reachability of infrastructure that should be out of reach. Attack path walkthrough
Choke-point fixes
Wireless assessment PSK and 802.1X attacks, rogue and evil-twin AP, guest isolation, BYOD boundaries, coverage bleed outside the building. Findings plus RF map
Design validation For networks we built: failover drills, policy conformance, as-built against the agreed design. Not a substitute for an independent test. Conformance report
Signed-off as-builts
Independence

We do not audit our own work.

Where ZAR Tech designed or installed the network, we run design validation — testing the build against the agreed design and policy: failover drills, policy conformance, as-built verification — and we will point you to an independent firm for the penetration test. Adversarial testing is for networks we did not build. It keeps the result credible for your auditors, and for you.

Every engagement runs under written authorisation and agreed rules of engagement, with a named contact on your side for the duration.

How an engagement runs

Understand, design, build, prove.

Same sequence whether it is a two-week firewall migration or a full site build. Each stage has a deliverable you keep.

STAGE 01

Discover

Site walk, config pull, traffic and dependency mapping. You get a current-state diagram that matches reality.

STAGE 02

Design

Low-level design, IP and VLAN plan, policy model, bill of materials. Reviewed with your team before anything is ordered.

STAGE 03

Implement

Staged build, lab validation, scheduled cutover with a written rollback. Change records and as-builts on completion.

STAGE 04

Prove

Design validation on our own builds — failover drills and policy conformance. Full penetration testing where someone else built it.

Experience

Two decades inside regulated, high-availability environments.

Work delivered directly and through prime contractors for Canadian Schedule I banks, a global insurer, provincial government, national telecom carriers and one of the country's largest grocery retailers. Client names are held in confidence and shared on request under NDA.

Schedule I banks Global insurance Provincial government National telecom carriers National retail & distribution Global systems integrators
Financial servicesSegmented card environments, change-controlled networks, audit-ready documentation.
Public sectorProcurement-friendly delivery, security standards, formal acceptance testing.
Telecom & carrierWAN handoffs, BGP peering, circuit migrations in tight maintenance windows.
Retail & distributionMulti-site rollouts, store and warehouse wireless, repeatable build templates.

Get in touch

Tell us what the network has to do, or what you need proven.

Scoping calls are free. Send the site count, the vendors in play, and your deadline — or, for testing, the scope and whether you own the environment. You will get a straight answer on feasibility and rough effort, not a brochure.