Managed switch estate
Configuration, VLAN assignment, trunking, spanning-tree sanity, PoE budgeting and port documentation across every closet.
Network Administration
Most small business networks were configured once, by someone who has since left, and never touched again. We take ongoing responsibility for switching, routing, segmentation and firewall policy, with documentation you can actually read and a change process that stops surprises.
The Problem
Networks rarely fail loudly. They degrade: a spanning-tree loop that slows a floor, a DHCP scope quietly filling, a firewall rule added for a temporary project four years ago that still allows RDP from anywhere.
Network administration is the discipline of continuous ownership. We hold current configuration backups for every switch, router and firewall, so a device that dies can be replaced from a known-good config in minutes rather than rebuilt from memory. We track firmware against vendor advisories and schedule updates in maintenance windows instead of reacting after an exploit is published. We keep a live diagram and a port map, because a network that only exists in one person's head is a single point of failure with a pulse.
VLANs are not decoration. Your point-of-sale terminals, security cameras, guest Wi-Fi, VoIP phones and staff workstations have different trust levels and different traffic patterns, and flattening them onto one broadcast domain is how one compromised camera becomes a company-wide incident. We design segmentation around what each group of devices genuinely needs to reach, then write inter-VLAN rules that are explicit rather than permissive.
IoT is the common gap in Arizona offices, smart thermostats, badge readers, sensors and irrigation controllers that ship with default credentials and no update path. They belong on their own segment with outbound-only access, and we will show you exactly how many of them are currently sitting on your primary network.
Enterprise change management is too heavy for a twenty-person company, but no process at all is worse. Ours is deliberately light: every change is logged with what changed, why, who approved it, and how to roll it back. Risky work happens in scheduled windows. Configurations are backed up before and after.
The payoff shows up on the bad day. When something breaks at 9am Monday, the first question is always what changed, and we can answer it in under a minute instead of guessing.
Capacity planning is the other half of the job. We track port utilisation, uplink saturation, PoE budget headroom and wireless client counts over time. That turns hardware replacement into a planned line in next year's budget rather than an emergency purchase at retail pricing. It also catches the slow problems: the uplink that saturates every afternoon when backups overlap with the workday, or the 24-port switch that has been at 24 ports for eight months.
This service pairs naturally with business networking and cabling for physical work and Wi-Fi design for wireless coverage. If you want a point-in-time picture before committing to anything ongoing, start with a network security audit. There is more depth on our networking microsite.
A network you cannot diagram is a network you cannot troubleshoot.Orca IT, Gilbert AZ
Scope
Six areas we take ownership of, monitored continuously and reviewed on a schedule.
Configuration, VLAN assignment, trunking, spanning-tree sanity, PoE budgeting and port documentation across every closet.
Static and dynamic routing, multi-site connectivity, failover circuits and sensible QoS for voice and video traffic.
Rule base review, removal of stale permits, geo and threat feeds, IPS tuning, and documented justification for every inbound rule.
Site-to-site tunnels between offices and client VPN for staff, with MFA on the front door rather than a shared password.
Live topology diagrams, port maps, IP schemes, credential vaulting and configuration backups, all handed to you, not held hostage.
Utilisation trending, firmware currency, end-of-support tracking and a replacement calendar so nothing dies unannounced.
How It Works
We walk the closets, pull configurations, scan the address space and build an accurate picture of what is actually connected.
Topology, VLANs, IP scheme, firewall rules and physical port map, written up in a form your team can use without us.
Stale rules removed, firmware brought current, segmentation implemented, monitoring deployed, configs backed up.
Ongoing monitoring, scheduled maintenance windows, logged changes and a quarterly review of capacity and risk.
Even if you never hire us to run it, an accurate diagram of your own network is worth having.
Why Orca
Six reasons clients stop managing switches themselves.
Every device config is versioned and stored. A dead switch is replaced and restored in minutes, not rebuilt by trial and error.
We watch vendor advisories for the gear you actually own and schedule updates before a published exploit forces the issue.
Cameras, IoT, guest and payment traffic get their own VLANs by default. It is not an upsell, it is the correct design.
Diagrams, credentials and configs belong to you. If you leave, the next provider inherits a clean handover, not a mystery.
We deploy UniFi, Ubiquiti and other business-grade gear based on fit and budget, not on which brand pays us. You buy it in your name.
When a link goes down in Chandler or Mesa, someone from our Gilbert office can be standing in front of the rack, not scheduling a dispatch.
IT support is largely user facing: the laptop, the mailbox, the printer. Network administration is infrastructure facing: switches, routers, firewalls, VLANs and the policy that governs traffic. Managed IT clients usually get both, but businesses with internal IT staff often hire us for the network layer alone.
If you need VLANs, PoE control, port-level visibility or any kind of traffic prioritisation, you need managed switches. Unmanaged switches are acceptable at the very edge of a small deployment, but they give you no diagnostics, which turns every intermittent fault into guesswork.
In most cases, yes. We support UniFi and Ubiquiti, plus common business-class firewalls and switching platforms. If a device is genuinely past end of support and no longer receiving security firmware, we will tell you and give you a replacement cost rather than pretending it is fine.
Carefully, and in stages. We map traffic flows before touching anything, build the new VLANs alongside the existing structure, migrate device groups one at a time in maintenance windows, and keep a rollback for each step. Big-bang segmentation on a Friday is how weekends get ruined.
Yes. Device availability, interface errors, uplink saturation, PoE budget, configuration changes and firewall events are monitored continuously, with alerts routed to your pod. A surprising number of issues are resolved before staff arrive in the morning.
Yes. Multi-site clients typically get site-to-site VPN or SD-WAN style connectivity, consistent VLAN numbering across locations, centralised firewall policy and a single monitoring view. Consistency across sites is what makes troubleshooting fast.
Deliberately lightweight. Each change gets a short record: what, why, who approved, when it happened, and how to reverse it. Configuration snapshots are taken before and after. It adds a few minutes to each job and saves hours the first time something goes wrong.
Configuration, monitoring, firewall policy and troubleshooting are all delivered remotely, so we administer networks for clients in all 50 states. Physical work such as cabling, rack installs and hardware swaps is limited to the Phoenix metro and East Valley.
Discovery, diagram and a prioritised list of what needs attention first.
Talk to Your Pod
We will map what exists, compare it to what should exist, and give you a prioritised list. Most reviews turn up at least one firewall rule nobody can explain and one switch running firmware from a previous decade.
(602) 677-0779Family owned in Gilbert, AZ since 2015 · onsite across the Phoenix metro · remote support nationwide · never outsourced
A few details and your pod gets right back to you, usually the same business day.