Skip to content

Your production network, reviewed by people who run them.

For ISPs, data centers, and cloud providers. Senior engineers read every layer of your network and return one severity-rated report with a remediation sequence.

  • ISO 27001:2022 certified
  • 50+ production networks operated
  • Vendor-agnostic by design
Your networkread-only
  • Routing & BGP design
  • BGP policy
  • Control plane security
  • Data plane security
  • Fabric & topology
  • Operational health
  • Monitoring coverage
  • Management network
Your reportseverity-rated

The bar we hold your network to.

These are the practices that keep operator networks up. We compare your configuration, topology, and tooling against them. Where they differ, you get a finding: what is wrong, what it costs you, and what to change.

What we review

  • Routing & BGP designRoute reflection sized to each device's role. No full tables where a default will do.
  • BGP policyEvery community, filter, and blackhole path explicitly scoped. Peers cannot steer your routing.
  • Control plane securityPolicing and ACLs on every routing engine. Only known sources reach management protocols.
  • Data plane securitySpoofing protection and role-based ACLs enforced at the edge, IPv4 and IPv6 alike.
  • Fabric & topologySymmetric fabric, one gateway model, a border layer that scales independently.
  • Operational healthSynchronized time, centralized logs, redundant prefix origination, DDoS detection.
  • Monitoring coverageSessions, optics, and packet rates monitored from one source of truth.
  • Management networkEncrypted management transport and centralized AAA. No local users, no plaintext.

Example findings.

Typical issues we find on operator networks. The full write-ups are in the sample report.

Critical
Outage or compromise is one event away. Fix first.
High
Serious exposure or blind spot. First remediation wave.
Medium
Design debt that limits scale or slows recovery.
Low
Hygiene and consistency. Cheap to fix, easy to schedule.
Informational
Worth knowing. No action required today.

Routing & BGP design Medium

BGP redistribute static without route-policy

Description. The BGP configuration redistributes static routes without a route-policy or route-map. Every static route in the table is eligible for injection into BGP.

Impact. Null-route blackholes, test routes, temporary diagnostics, and internal-only destinations are all advertised into BGP the moment someone adds them.

Recommendation. Attach a route-policy that matches only the prefixes intended for advertisement, and tag or community-mark them so the intent is auditable.

  router bgp 64500   address-family ipv4 unicast-   redistribute static+   redistribute static route-policy STATIC-TO-BGP  !+ route-policy STATIC-TO-BGP+   if destination in ANNOUNCED-STATICS then+     set community (64500:100)+     pass+   endif+ end-policy

Illustrative syntax. The report names the exact device and policy.

How an assessment runs.

Read-only access, a defined scope, and a report you own. Duration and commercial terms are agreed in the first call.

  1. Scope

    Agree what we look at

    A representative point of presence or your full production edge. We name the devices, the domains, and the access we need. Read-only.

    Step 1 of 5
  2. Collect

    Configurations, topology, monitoring

    Device configs, routing tables, monitoring exports, and the diagrams you actually have. Handled under our ISO 27001:2022 controls and your NDA.

    Step 2 of 5
  3. Review

    Your network, read line by line

    Configurations and topology are reviewed by the engineers who design and operate ITcare-run networks. No scanners, no templates.

    Step 3 of 5
  4. Report

    Findings you can hand to your team

    Each one has a description, its impact, and a recommendation, rated Critical to Informational. The report closes with the order to fix them in.

    Step 4 of 5
  5. Remediate

    Fix it with us, or without us

    The report stands on its own. If you want the same engineers to execute, ITcare offers architecture, implementation, and 24/7 NOC.

    Step 5 of 5

Book an assessment.

A call with an engineer, not a sales rep. We scope what to look at and what access we need. You leave with a plan either way.

We confirm the exact time by email.

Your details are stored by ITcare for this request only and never shared.

ITcareConfidential

Network Assessment Report

ISP edge assessment · sample

Customer
Sample
Prepared by
ITcare Network Engineering
Classification
Customer Confidential
Scope
ISP edge assessment
13 pages

Read a real one first.

Two sample reports. Pick the one closer to your network and judge the depth before you talk to us.

Which sample?

Routing & BGP design, BGP policy, operational health, monitoring coverage, management network, firewall.

One PDF per request. No newsletter.