nodeworks
AboutApproachContact
Get in touch
About

One engineer for the
network your business runs on

Nodeworks is an independent network, infrastructure and security practice. I design, build, monitor and defend the systems organisations cannot afford to lose, working remotely or on site, and you deal with me from the first call to the handover.

Who I am

Not a reseller with a service desk attached

Most providers in this market are structured around hardware margin and ticket throughput. That structure rewards volume, and it quietly punishes the two things that actually keep an estate healthy: careful design and honest measurement.

I work the other way around. Engagements start with measurement, designs are written so your own team can operate them, changes are staged and reversible, and everything I claim is backed by something you can verify independently.

Being one person is the point, not a limitation. Nothing is lost in a handover between tiers, you never explain your topology twice, and the person who designed your network is the person who fixes it when it breaks. It also means I am honest about capacity: if a piece of work needs a larger team or a specialist, I will say so rather than stretch.

I am vendor neutral because I carry no quota and resell no hardware. If the right answer is that you already own the capability and simply need it configured properly, that is the answer you will get. If the right answer is that the problem is not the network at all, I will tell you that too, with the evidence.

How I operate

Six principles that decide every engagement

Measure first

No recommendation leaves my desk without telemetry behind it. Two weeks of real baseline data beats any assessment questionnaire ever written.

Reversible change

Every change carries a rollback gate. If a step genuinely cannot be reversed, it gets its own window, its own approval and its own rehearsal.

Documentation is delivery

An undocumented change is an incomplete change. Diagrams, runbooks and configuration baselines are updated inside the change window.

Noise is a defect

If an alert does not require action, it is retuned or removed. Alert fatigue is the mechanism by which real outages get missed at 3am.

Direct accountability

You know exactly who owns your estate. There is no tier rotation, no account manager relaying messages, and no ambiguity about who to call.

Evidence over assertion

Restore tests with timings. Availability measured against target. Root cause with the packet capture that proves it, not a plausible story.

Everything I do

Every service, in full

Ten services across five disciplines. Each one is delivered to the same standard, with the same documentation, and can be bought as a fixed scope project, ongoing support, or block hours.

Network

2 services

Network Design & Deployment

Network

Routed, switched and segmented networks built to survive growth.

Greenfield builds and brownfield rebuilds: campus LAN, data centre fabric, WAN and SD-WAN edge, delivered with documentation you can actually operate from.

What you receive
  • High and low level design documents
  • IP addressing and VLAN/VRF plan
  • Routing and failover policy
  • Staged cutover runbook with rollback gates
  • As built topology and port maps
  • Configuration baseline in version control
Outcomes
  • Deterministic failover behaviour under link and device loss
  • Segmentation that holds up to an audit
  • Change windows measured in minutes, not nights
Cisco IOS-XE / NX-OSFortiGateMikroTik RouterOSAruba / HPEBGP / OSPFVXLAN / EVPN
Engagement
Project, fixed scope
Typical timeline
3 to 10 weeks
Full detail

Wireless Engineering & Surveys

Network

Coverage designed with a spectrum analyser, not with optimism.

Predictive and on site wireless surveys, high density design, roaming optimisation and RF troubleshooting for campus, warehouse and industrial sites.

What you receive
  • Predictive RF design against floor plans
  • On site passive and active validation survey
  • Channel, power and band steering plan
  • Roaming and voice optimisation
  • Spectrum interference report
  • Coverage heat maps, pre and post
Outcomes
  • Reliable roaming for voice and scanning workloads
  • Interference sources identified and removed
  • Density handled without co-channel collapse
EkahauArubaUniFiCisco WLCSpectrum analysis802.11ax / 6E
Engagement
Project, fixed scope
Typical timeline
1 to 4 weeks
Full detail

Monitoring

2 services

NMS Deployment

Monitoring

A monitoring system your engineers trust at 3am.

Design and rollout of a full network management system: discovery, polling, flow, syslog, traps, dashboards and alert routing, tuned so that every page means something.

What you receive
  • Sized and hardened NMS platform (HA optional)
  • Device discovery and templated polling
  • Flow collection and top talker analytics
  • Syslog and SNMP trap normalisation
  • Service mapped dashboards per audience
  • Alert routing, escalation and on call matrix
  • Runbook per alert class
Outcomes
  • Actionable alert volume, typically 80 to 95 percent below the untuned baseline
  • Mean time to detect under 60 seconds for link and node loss
  • Capacity trending your finance team can read
ZabbixLibreNMSPrometheusGrafanaElasticNetFlow / sFlowSNMPv3
Engagement
Project, optional managed handover
Typical timeline
2 to 6 weeks
Full detail

24/7 Network Monitoring

Monitoring

Continuous eyes on the estate, with a person behind the alerts.

Managed monitoring of your network, servers and connectivity with defined response targets, incident handling, and monthly capacity and availability reporting.

What you receive
  • Around the clock alert monitoring and triage
  • Defined response and escalation SLAs
  • Incident creation, comms and post incident review
  • Availability and capacity reporting
  • Quarterly threshold and coverage review
Outcomes
  • Outages detected before your users report them
  • Documented availability evidence for customers and auditors
  • Capacity problems caught a quarter early
ZabbixGrafanaEscalation routingStatus pagesSyslog pipeline
Engagement
Recurring, monthly
Typical timeline
Onboarding in 5 to 10 days
Full detail

Security

2 services

Network Security & Segmentation

Security

Firewalls, zones and policy that reflect how the business actually works.

Perimeter and internal security: next generation firewall design, zero trust segmentation, remote access, IPS tuning and policy lifecycle management.

What you receive
  • Zone and segmentation model
  • Firewall build or migration with rule rationalisation
  • IPS/IDS profile tuning
  • Secure remote access (SSL-VPN / IPsec / ZTNA)
  • Policy lifecycle and change-control process
  • Audit-ready configuration evidence
Outcomes
  • Lateral movement contained to a single zone
  • Rule base reduced and fully attributed to an owner
  • Remote access with enforced MFA and device posture
FortiGatePalo AltopfSense / OPNsenseCisco FTD802.1XZTNA
Engagement
Project or recurring
Typical timeline
3 to 8 weeks
Full detail

Security Operations & Hardening

Security

Detection, response and the unglamorous hygiene that prevents both.

Log collection and correlation, vulnerability management, patch orchestration, endpoint hardening, and incident response retainers.

What you receive
  • Log source onboarding and normalisation
  • Detection content and correlation rules
  • Authenticated vulnerability scanning cycle
  • Risk-weighted remediation plan and patch orchestration
  • Hardening baselines (CIS aligned)
  • Incident response retainer and playbooks
Outcomes
  • Critical vulnerability closure inside agreed windows
  • Detection coverage mapped to MITRE ATT&CK
  • Contained incidents with defensible evidence chains
WazuhElastic SIEMOpenVAS / NessusCIS BenchmarksMITRE ATT&CKEDR integrations
Engagement
Recurring, monthly
Typical timeline
Onboarding in 2 to 4 weeks
Full detail

Infrastructure

2 services

Infrastructure & Virtualization

Infrastructure

Compute, storage and platform services that stay boring.

Server and hypervisor builds, storage design, identity services, hybrid cloud connectivity and platform lifecycle management.

What you receive
  • Hypervisor cluster design and build
  • Storage sizing, tiering and replication
  • Identity, DNS, DHCP and IPAM services
  • Hybrid cloud connectivity
  • Patch and firmware lifecycle programme
  • Capacity and end-of-support register
Outcomes
  • Predictable maintenance with no user-visible impact
  • Documented recovery paths for every platform service
  • No surprise end-of-support exposure
VMware vSphereProxmox VEHyper-VTrueNAS / CephActive DirectoryAzure / AWS hybrid
Engagement
Project or recurring
Typical timeline
4 to 12 weeks
Full detail

Backup & Disaster Recovery

Infrastructure

Recovery you have actually tested, with numbers to prove it.

Backup architecture, immutable and offsite copies, documented recovery objectives, and scheduled restore testing with evidence.

What you receive
  • Per-workload RPO/RTO register
  • Backup architecture with immutable and offsite copies
  • Credential and access separation model
  • Documented recovery runbooks
  • Quarterly restore testing with evidence pack
  • DR failover plan and annual exercise
Outcomes
  • Ransomware-resilient backup estate
  • Recovery objectives proven, not assumed
  • Audit evidence produced automatically
VeeamProxmox Backup ServerResticObject storage with lockOffline vault
Engagement
Project + recurring assurance
Typical timeline
2 to 6 weeks
Full detail

Support

2 services

Network Troubleshooting

Support

For the problem nobody has been able to close.

Deep dive diagnostics on intermittent, performance and application layer network faults: packet capture, flow analysis and structured root cause.

What you receive
  • Structured diagnostic plan
  • Distributed packet capture and analysis
  • Flow and counter correlation timeline
  • Root cause statement with evidence
  • Remediation plan and implementation
  • Detection rules to catch recurrence
Outcomes
  • Faults closed with evidence, not with a reboot
  • Vendor escalations backed by capture data
  • Recurrence detected automatically
Wiresharktcpdumpiperf3NetFlow analyticsSynthetic probesSNMP counters
Engagement
Time boxed or block hours
Typical timeline
48 hours to 3 weeks
Full detail

Managed IT & Co Managed Support

Support

A full operations function, or extra capacity for the team you have.

Service desk, endpoint management, vendor coordination, documentation and technical account management under a defined SLA.

What you receive
  • Service desk with SLA-tracked queues
  • Endpoint management and patching
  • Asset and licence register
  • Vendor and carrier coordination
  • Living documentation set
  • Regular service review, run by me
Outcomes
  • One accountable owner for the whole stack
  • Predictable monthly cost with no surprise call-outs
  • Documentation that survives staff turnover
Ticketing + SLA engineRMMPatch orchestrationDocumentation platformAsset register
Engagement
Recurring, monthly
Typical timeline
Onboarding in 2 to 4 weeks
Full detail
Technical capability

The technologies I work in, every day

Routing and switching

  • Cisco IOS-XE and NX-OS
  • Aruba CX and AOS
  • MikroTik RouterOS
  • BGP, OSPF, EIGRP
  • VXLAN and EVPN fabrics
  • Spanning tree and loop free design
  • QoS and traffic engineering
  • IPv6 addressing and dual stack

Security

  • FortiGate and FortiOS
  • Palo Alto PAN-OS
  • pfSense and OPNsense
  • Zero trust segmentation
  • 802.1X and network access control
  • SSL VPN, IPsec and ZTNA
  • IPS and IDS tuning
  • CIS hardening baselines
  • Wazuh and Elastic SIEM
  • Vulnerability management

Wireless

  • Predictive RF design
  • On site passive and active survey
  • 802.11ax and Wi-Fi 6E
  • High density and warehouse RF
  • Roaming and voice optimisation
  • Spectrum interference analysis

Infrastructure

  • VMware vSphere
  • Proxmox VE and Ceph
  • Hyper-V
  • TrueNAS and shared storage
  • Active Directory, DNS, DHCP, IPAM
  • Certificate services
  • Azure and AWS hybrid connectivity

Monitoring

  • Zabbix
  • LibreNMS
  • Prometheus and Grafana
  • NetFlow and sFlow analytics
  • Syslog and SNMP trap pipelines
  • Synthetic transaction probes
  • Alert routing and escalation design

Resilience

  • Veeam
  • Proxmox Backup Server
  • Immutable and object lock repositories
  • Documented recovery objectives
  • Scheduled restore testing
  • Disaster recovery exercises
Working with me

How engagements run

Most engineering is delivered remotely and scheduled around your change windows. I attend in person when the work genuinely needs it.

Remote engineering
The majority of work, scheduled inside your maintenance window
On site attendance
Arranged when the work is physical or the fault needs eyes on the cabling
Response
Same or next business day for enquiries, agreed targets for ongoing support
Engagement types
Fixed scope projects, ongoing support, or block hours
Languages
English and Urdu
Compliance alignment
ISO 27001, PCI DSS evidence, IEC 62443 for operational technology
Questions

The things people ask me first

Do you work with our existing hardware?+

Yes, and most engagements are brownfield. I assess what stays, what moves and what retires, and I say so plainly in the design review rather than recommending a rip and replace by default.

Can you work alongside our internal IT team?+

That is the co managed model and it is the majority of my recurring work. Your team keeps ownership, and I take the load they cannot carry: after hours, escalation, projects, or a specific technology domain.

You are one person. What if you are unavailable?+

A fair question, and I answer it honestly. Documentation is written so your team or another engineer can operate the estate without me, credentials are held by you, and for anything where a single point of contact is unacceptable I will say so up front rather than take the work.

What size of organisation do you work with?+

From single site businesses with thirty users to multi site estates with several thousand. What matters more than headcount is whether downtime has a real cost attached.

How quickly can you start?+

Discovery engagements typically start within two weeks. Urgent troubleshooting is often same or next day, depending on what else is in flight.

Are you tied to particular vendors?+

No. I hold no sales quota with any manufacturer and resell no hardware. I work across Cisco, Fortinet, Palo Alto, Aruba, MikroTik, VMware, Proxmox and the open source monitoring stack, and I recommend what fits your estate and your team.

What does an engagement cost?+

It depends entirely on scope, and I will not pretend otherwise. Tell me the problem and I will come back with a written proposal that states its assumptions, so you can see exactly what you are paying for.

Do you sign NDAs and security agreements?+

Yes, as standard. I also work under client change control processes, approval requirements and regulated environment constraints where those apply.

What happens if we want to stop?+

You get a full documentation handover, credentials, configuration baselines and diagrams. No hostage taking, because that is not how I want to keep clients.

Let us talk about what you are running

One conversation is usually enough to tell whether I am the right person for the problem in front of you.

Get in touch
nodeworksnetwork · security

Network, infrastructure and security services for organisations that cannot afford an unplanned outage. Vendor neutral, evidence based, delivered remotely or on site.

contact@aleeraza.pro+92 331 5474870
Get in touch
Network
  • Network Design & Deployment
  • Wireless Engineering & Surveys
Monitoring
  • NMS Deployment
  • 24/7 Network Monitoring
Security
  • Network Security & Segmentation
  • Security Operations & Hardening
Infrastructure
  • Infrastructure & Virtualization
  • Backup & Disaster Recovery
Support
  • Network Troubleshooting
  • Managed IT & Co Managed Support
Company
  • About
  • Approach
  • All services
  • Contact

© 2026 Nodeworks

Remote and on site · Vendor neutral · Evidence based