$ BLR//CODE

Home / Business IT / Networks & Wi-Fi

IT/NET — Networks & Wi-Fi

Wi-Fi that works everywhere, and a network that isn't one flat pool.

Two problems, one engagement. The Wi-Fi complaint is what gets us called; the flat network is usually the more serious thing we find while looking. Both are diagnosed and fixed remotely.

WIFI/ — Wireless

Why the Wi-Fi drops at the back.

It is almost always one of four things, and buying another router fixes none of them: everyone in the building is on overlapping channels, the access points are in cupboards and corners instead of ceilings, roaming was never configured, or the problem was never Wi-Fi at all and the uplink is saturated.

Three of those four are visible in the controller data and fixable remotely. The fourth — an access point in the wrong place — needs someone to move it, which is ten minutes of somebody's time once we have said where it should go.

The long version →

What we work from

  • Controller telemetry — per-client signal, retries, channel utilisation, and the neighbouring networks your APs can already see
  • Your floor plan, for placement and AP count
  • Readings from your end where a location has no coverage yet — a free analyser app and five minutes of someone's time
  • A written channel and placement plan your contractor or office manager can act on

SEG/ — Segmentation

Keeping the camera away from the accounts machine.

In most small offices, the receptionist's PC, the accounts machine, the CCTV recorder, the smart TV and the guest Wi-Fi all sit on one network and trust each other completely. That means the weakest device sets your security level — and the weakest device is never the one you worry about.

Internet ISP · MULTI-WAN Firewall / UTM POLICY · NAT · IDS Core switch (L3) 802.1Q TRUNK Remote access WIREGUARD MESH Staff Workstations, printers VLAN 10 · 10.0.10.0/24 Guest Visitor Wi-Fi only VLAN 20 · 10.0.20.0/24 IoT / CCTV Cameras, NVR, sensors VLAN 30 · 10.0.30.0/24 Servers NAS, line-of-business apps VLAN 40 · 10.0.40.0/24 DEFAULT DENY BETWEEN SEGMENTS — EAST-WEST TRAFFIC PASSES ONLY WHERE POLICY ALLOWS IT Monitoring & alerting UPTIME CHECKS · HOST METRICS · FIRMWARE + PATCH STATE · ALERTS THAT REACH A HUMAN
Fig. 1 — What we configure instead: four segments, default deny between them

Why this matters, in plain language →

SVC/ — The work

What we actually do.

Network review
What is on your network, what is reachable from outside, what is unpatched, and a prioritised list of what to change first. Done remotely from device access and configuration exports.
Wi-Fi design & tuning
Channel plan, access point count and positions marked on your floor plan, and ongoing tuning from controller data once it is live and carrying real clients.
Segmentation
Separate networks for staff, guests, cameras and servers, with a default-deny policy between them. Typically an evening cutover, executed remotely with someone at your end on the phone.
Firewall configuration
A rule set written from intent rather than accreted over years, with the reasoning documented so the next person can tell what each rule is for.
Guest & CCTV isolation
The cheapest meaningful win available, usually a configuration change on equipment you already own — which makes it ideal remote work. If you do one thing, do this.
Remote access
Mesh VPN tied to your existing Google or Microsoft accounts. No appliance, no open inbound port, and access revoked everywhere when someone leaves.
Multi-site links
Second office, warehouse or a director's home connected back securely, with the same policy model rather than a flat bridge between two networks.
Monitoring
Link and device monitoring so an outage is noticed by us rather than reported by your staff. Included in support plans.

FAQ/ — Common questions

Questions we get asked.

The Wi-Fi is weak at the back. Can we just add another router?

Usually that makes it worse. Two routers with the same network name do not hand devices over — your phone clings to the first one until the signal nearly dies, which is exactly when you are mid-call. And unless the channels are planned, the two units interfere with each other. The fix is planned access point placement with proper roaming, which is often the same money spent better.

You work remotely — how can you diagnose Wi-Fi you cannot walk around in?

From the controller, mostly. Modern access points report signal strength per client, retry and error rates, channel utilisation, and the neighbouring networks they can see — which is the same data a walk-around survey collects, gathered continuously from every AP instead of once from one person with a laptop. What we genuinely cannot do is measure a location where you have no AP yet. For that we work from your floor plan and, where it matters, ask someone at your end to run a free analyser app and send us the readings.

Will segmenting the network break our printers?

Printer discovery and casting rely on broadcast traffic that does not cross subnets, so those need handling deliberately — static printer addresses, and mDNS reflection where it is genuinely needed. This is the most common post-change complaint, which is precisely why it belongs in the plan rather than in Monday morning.

Do we need to replace our switches?

Sometimes. Segmentation needs switches that support VLANs, and cheap unmanaged switches do not. Where that is the case we will say so up front. We do not sell hardware, so there is nothing in it for us either way.

What if the work needs someone physically present?

Then you or a local contractor does that part, and we tell you exactly what is needed. Mounting an access point, pulling a cable or swapping a switch are trades, and a local crew does them better than a visiting consultant would. We handle everything from the configuration layer up, and we will brief your contractor directly.

Can staff work from home securely?

Yes, and this is entirely remote work to set up. For most small offices the modern answer is a WireGuard-based mesh tied to your existing Google or Microsoft accounts — no VPN appliance, no open inbound port on your firewall, and access removed everywhere the moment someone leaves.

CTA/ — Network work

Start with a review.

Tell us roughly how many devices, what equipment you have, and what prompted you to look. You'll get a scope for the assessment — or an honest note that what you have sounds fine as it is.

Ask about a network review →