A conceptual design proposal based on real-world observations. The institution and any identified shortcomings remain fully anonymized; the upgrade is a proposed architecture developed as a design case study — not a deployed system.
This project is a conceptual network security upgrade designed for a university environment, based on operational needs I observed firsthand and framed as a formal recommendation to a CIO. It's a design case study built on a realistic scenario — the proposal assumes approval to proceed, allowing a complete architecture to be designed end to end on Ubiquiti's UniFi enterprise platform.
Status: Planned — design work begins later this week.
The scenario: From a campus safety operations vantage point, I identified recurring gaps in how a campus network could be segmented, monitored, and protected — particularly where physical-security systems intersect with the broader network. This proposal turns those observations into a prioritized, defensible upgrade plan suitable for executive review.
Proposed scope:
- Network segmentation (VLANs) — would isolate administrative, academic, student/residential, guest, IoT, and physical-security systems (surveillance, access control) so a breach in one domain can't move laterally into another.
- Inter-VLAN firewall policy — least-privilege rules governing traffic between segments.
- Threat management (IDS/IPS) — network-wide intrusion detection and prevention with anomaly monitoring.
- Centralized visibility — a UniFi Network controller for logging, monitoring, and alerting across the deployment.
- Converged security — treating the physical-security network as a hardened, monitored segment, bridging physical-security experience with network defense.
- Scalability & resilience — a design intended to scale across buildings, with redundancy considerations.
- Secure WiFi at scale — WPA3/enterprise authentication, role-based SSIDs, and guest isolation.
Proposed platform (Ubiquiti UniFi enterprise): UniFi security gateway (routing, firewall, IDS/IPS); UniFi aggregation and access switches (VLAN-aware, PoE); UniFi enterprise access points (multi-SSID); UniFi Network controller (centralized management and logging).
What this demonstrates: enterprise network segmentation and VLAN design, security architecture, IDS/IPS, requirements analysis and risk-based prioritization, executive-level communication, and converged physical/cyber security.
