PL Contact us
Back to news

Networks

Seven Signs It Is Time for a LAN Network Modernisation

A network rarely fails overnight. First it gives signs that are easy to mistake for everyday nuisance. Here are the seven most common ones.

Seven Signs It Is Time for a LAN Network Modernisation

Signal 1. Switches the manufacturer no longer supports

Network hardware can keep working for a very long time, and that is exactly the problem. A switch bought eight years ago still moves traffic, nobody touches it, so it never appears on any replacement list.

Manufacturers move devices through the stages of a product lifecycle. After the last day of support for a given model there are no more software updates, no security fixes and no right to technical assistance. Cisco states this plainly in its end of life policy. The device still works, it is just that nobody in the world is obliged to repair anything in it any more.

In practice that threatens two things. A failure means hunting for parts on the second hand market, and a vulnerability found in the software stays in the network for good, because no fix is coming.

The first step is cheap. All it takes is an inventory of devices with models, software versions and support dates. Only then does the replacement order get decided, starting with the network core that all traffic passes through. We work mainly on Cisco Catalyst and Nexus switches, so we read an inventory like that together with the lifecycle history of the specific model.

Signal 2. One device that stops the whole company

There is a simple test. Walk into the server room and point at the device whose failure would stop everyone from working. If such a device exists, you have your answer.

It is usually one switch where all the cables meet, one router on the way out to the world, or one cabinet on a single power feed. A network built this way works very well until the day it does not.

The repair time for that kind of failure is not the time an administrator needs. It is the delivery time for a part, and with older hardware nobody knows it in advance. The company is down for as long as the delivery takes.

The fix does not require rebuilding everything. It starts with duplicating the one place all traffic goes through, and with splitting the power feeds. A network core can also be spread across two locations so that losing one of them does not stop work. We have built a core like that on Cisco Catalyst and Nexus, joined by a fibre link between two data centres.

Signal 3. A single internet link

Over the past few years more and more of the working day has moved outside the building. Mail, drives, sales systems, payment terminals and remote work all pass through the internet link today. Very often through one link.

It is the only part of the infrastructure the company has no control over at all. A digger during road works or a fault at the operator is enough, and there is nothing to repair on your own side. All that is left is waiting.

A backup link only helps when it is genuinely a backup. Two links from the same operator, in the same bundle and through the same manhole, are still one link. What makes sense is a second operator and a different physical route, and with several sites also a sensible way of spreading traffic across the links.

The technical side of this is well understood. Traffic can be switched automatically with BGP routing, sites can be joined with MPLS links, or the whole thing can run over SD-WAN, which picks the better link itself and moves traffic onto it when the first one stops responding. The choice depends on the number of locations and on what has to keep running without a break.

Signal 4. Wi-Fi with gaps in coverage

The symptoms are always similar. Calls break up in one meeting room, there is a spot in the warehouse where the scanner loses its connection, and people carry laptops to wherever it works better.

The cause usually lies not in the access points but in the fact that there was never a design. Points were placed by feel, more were added as complaints came in, channels started to overlap, and the guest network went the same way as the company one.

As long as it is only about comfort, it can be lived with. It becomes a problem when warehouse scanners, terminals or telephony run over that Wi-Fi. A gap in coverage then stops being an inconvenience and becomes an interruption to work that nobody can prove, because nothing was ever measured.

Decent Wi-Fi starts with a survey on site and a plan for where the access points go, not with buying hardware. A separate network for guests is the first thing to set up. We work on Cisco and Ubiquiti equipment. Cisco or Ubiquiti? The building and the budget decide.

Signal 5. "It works, you just have to restart it sometimes"

The sentence sounds harmless and it is said in a lot of companies. There is a device in the network that has to be switched off and on every few weeks, everybody has got used to it, and somebody even knows the best hour to do it.

A restart is not a repair. It is a symptom that something in the device is missing or running out. It can be memory, a full address table, an overheating power supply, a loop in the network, or a link that is simply saturated at peak hours.

The worst part of this symptom is that nobody can predict the next time. The device will restart itself at the least convenient moment, because the cause was never named.

Monitoring explains it, but not the kind that only shows whether a device answers. What is needed is history, meaning load, memory, temperature, link saturation and the logs from the minutes before the restart. We run network and server monitoring in Elastic Stack, and it covers several thousand devices today, so cases like this can usually be closed on a specific cause.

Signal 6. Nobody knows how this network is built

There is no diagram. There is no device inventory. The addressing is not written down and there is no description of what sits in which VLAN. The configuration stayed in the head of somebody who left two years ago, and one person in the company holds the passwords.

This is the cheapest of the seven to fix and at the same time the one that costs the most during the first serious failure. The first hours then go not into repairing anything, but into working out what is plugged in where.

Missing documentation also makes every change harder. A new switch, a new site or a new system goes in by trial and error, because nobody can say in advance what it will break. Changing the company that looks after the network turns into a punishment in a setup like this.

The cure is dull and effective. An inventory of devices, a physical and a logical diagram, a description of addressing and segments, configuration copies kept off the devices themselves, and access to all of it for more than one person. None of that requires replacing any hardware.

Signal 7. Everything in one network, with no separation

Laptops, servers, printers, cameras, tills, production equipment and guest Wi-Fi all sit in one network. Every one of those devices can reach every other one, because nobody ever restricted it.

The consequence only shows during an incident. One infected laptop then has an open road to the database server. CISA and the NSA write plainly that where security rests on protecting the perimeter, almost nothing restricts traffic once someone has authenticated. They recommend dividing the network precisely to limit how far an intruder can get.

Splitting the network into segments does not solve this on its own. A common mistake is having the VLANs in place with no rules between them, so traffic still goes everywhere. A segment only means something together with a firewall rule that says what is allowed and drops the rest.

It starts with the simplest and most worthwhile parts. Guests on their own, servers apart from workstations, production equipment and cameras apart from everything. A finer division is worth discussing only after that.

How many signs are too many

One sign is a task to get done. Three or more is a network that will stop the company at the least convenient moment, and nobody will be able to say when.

The good news is that modernisation is not done in one cut. The order usually looks like this: first the inventory and the diagram, because without them every later step is guesswork, then removing the single point that stops everything, then replacing hardware with no support, and finally splitting the network into segments.

Each of those stages is a separate short maintenance window, usually in the evening or at the weekend. The company keeps working the whole time, and after every stage something genuinely improves, so there is no need to wait for the end of the whole project.

After the modernisation comes maintenance, because a network left alone drifts back to the same state within a few years. The scope of support, including round the clock cover, is agreed in the contract. If you want to start by going through these seven points at your place, call +48 662 036 615 or write to [email protected].

See the service

We start with a talk, not an invoice

15 minutes is enough to tell you where we can help.