Cisco Premier Partner in Egypt: Routing, Switching & Enterprise Wireless

Cisco Premier Partner · Egypt

The layer nobody notices until it fails.

Routing, switching and enterprise wireless, designed as one hierarchy across every building, floor and desk, then operated by the engineers who built it.

Where we have deployed it

Cisco carries the access and distribution layers across our campus and data centre programmes. The security boundary above it is usually Fortinet. That split is deliberate, each vendor doing what it is strongest at, with one team accountable for both.

ProgrammeWhat was built
Contact-Centre Campus Network
Global hotel group · Egypt site
Stacked Catalyst 9300 distribution pairs forwarding active-active, with 4×10G and 2×10G fibre port-channels (LACP) between every layer. Designed so no single link or switch can take the floor offline.
Campus Core & Edge Design
Multi-building site · Egypt
Every core room, server room, floor edge room and workspace zone surveyed and documented, then core, distribution and access designed as a single hierarchy with resilient uplinks, not a room at a time.
National Data Centre
Government & defence · Egypt
Core routing, subnetting and switching inside a complete data centre build delivered under strict security requirements.
Structured Cabling Remediation
Multiple sites · Egypt
The physical layer underneath: re-termination, patching, labelling, containment, and as-built topology documentation handed over. Every port traceable.

These are real Stark programmes. Client identifiers are withheld under confidentiality.

What we actually design and configure on Cisco

A network that works on day one and a network that survives three years of growth are two different designs. Most of the estates we are asked to take over were built one room at a time, a switch added when a department expanded, a VLAN added when someone asked, and the result is a topology nobody can draw. This is the work that prevents that.

The design layer, decided before anything is racked

Three-tier hierarchyCore, distribution and access designed as one structure with a deliberate oversubscription ratio at each step, rather than switches daisy-chained until a floor runs out of ports. This is what makes the tenth building as predictable as the first.
VLAN and IP address planA documented subnet scheme with room to grow, separation for voice, wireless, guest, management, surveillance and building systems, and a summarisation-friendly layout so the routing table stays small.
Redundant uplinks and port-channelsLACP port-channels between every layer, with links deliberately split across different member switches and different line cards so no single failure isolates a floor. Verified by pulling a fibre during commissioning, not by reading the design document.
Switch stacking and chassis pairsStackWise stacks and stacked distribution pairs forwarding on both members, so a failed unit costs capacity rather than availability, and a software upgrade is a scheduled event rather than an outage.
Spanning-tree done on purposeRoot bridge placed deliberately, RSTP or MST chosen for the topology, and PortFast, BPDU Guard and Root Guard applied at the edge. An unplanned root bridge election is one of the most common causes of a campus-wide slowdown nobody can explain.
First-hop redundancy and routingHSRP or VRRP on the gateways, OSPF or EIGRP inside, BGP where there are two providers, with timers and route policy set so a failover is measured in seconds and does not flap.

Wireless, designed against a survey, not a floor plan

Predictive and on-site surveyAccess point placement decided against real materials and real obstructions. Concrete, lift shafts, plasterboard and glass behave very differently, and a coverage map drawn in an office is not evidence.
Controller architectureCatalyst 9800 in the appliance, embedded or cloud form that fits the site, with AP groups, RF profiles and a controller position that does not become a single point of failure.
Roaming and RF tuningFast roaming, band steering and minimum data rates configured so a call survives a walk down a corridor. Low legacy data rates left enabled are the usual cause of “the Wi-Fi is slow” in a busy building.
Guest and corporate separationGuest traffic terminated away from the corporate network, with its own address space, its own egress and no route to anything internal.

Controlling what gets onto the network

802.1X and MABCertificate or credential authentication on the wired port, with MAC authentication bypass and a profiling policy for the printers, cameras and controllers that will never run a supplicant.
Identity Services EngineWhere the estate justifies it, ISE for central policy, posture and dynamic VLAN assignment, so where a device lands is decided by what it is, not by which socket someone plugged it into.
Layer-2 hardeningDHCP snooping, dynamic ARP inspection, IP source guard, storm control and port security applied as standard build. These stop a rogue DHCP server or a spoofing attempt at the access port instead of at the firewall.
Management-plane securityOut-of-band management VLAN, AAA with TACACS+ or RADIUS, no shared local accounts, SSH only, and configuration change logging that names a person.

Data centre and WAN

Nexus and vPCTop-of-rack and spine switching with virtual port-channels so a server keeps both uplinks active across two physical switches, the difference between a maintenance window and a migration project.
Dual-provider edgeBGP with two circuits, path preference set deliberately, and failover proven while somebody is on a call, because that is the test that matters.
QoS for voice and payment trafficClassification and queuing end to end, so the traffic that cannot tolerate jitter is not competing with a backup job.
The physical layer underneathRe-termination, patching, labelling, containment and an as-built topology. Half the faults blamed on switching are a bad patch lead and an unlabelled port.

What you get handed over, and what happens afterwards

DeliverableWhy it matters later
As-built topology and port mapEvery port traceable to a room and a device. Without it, every future change starts with a day of tracing cables.
VLAN, subnet and addressing registerThe document that stops the next expansion from colliding with an address range somebody forgot about.
Configuration backups and version controlA configuration that only exists on the running device is a configuration you lose with the device.
Licence and support registerSmart Licensing entitlements and support contracts tracked ahead of expiry, so a renewal is planned rather than discovered during an outage.
Software currency planAn agreed IOS-XE train and an upgrade rhythm. Estates left on whatever shipped in the box are where the security advisories accumulate.

Where we draw the line. Cisco is not always the right answer at the boundary. We normally put Fortinet there, and we will say so. And no amount of hardware fixes a bad physical layer or an undocumented address plan. If your estate has grown organically, the honest first step is usually a survey and a documentation exercise, not a purchase order.

What Premier Partner status actually buys you

Vendor-level escalation when the fault is genuinely Cisco’s. Licensing sized to the requirement rather than the largest SKU. And engineers certified on the platform we are asking you to standardise on. We pay for the training and the lab time, because the badge is worth nothing without it.

Free network assessment, no obligation

Tell us how many buildings, floors and users. We will tell you what the design should look like and where your current one will hurt you.

Book the free assessment02 35375791