Designing Networks. Securing Infrastructure.
Solving Real Problems.

Packet Craft

From Packets to Protection — Real-World Network Engineering

Network Engineer Security-Focused MSP Experience Based in NZ

Where Real Network Problems Get Solved

Inside PacketCraft

PacketCraft is a hands-on network engineering lab focused on real-world problem solving across security, routing, and infrastructure — the kind engineers face daily in production environments.

Built from MSP experience in New Zealand, every scenario here is designed, tested, and troubleshot on real enterprise hardware. Not theory. This is how networks actually behave.

Lab Projects & Builds

What's Running in the Lab

🔥

FortiGate Homelab

Enterprise-grade perimeter firewall with policy segmentation, IPS, and SSL inspection across VLAN-tagged infrastructure.

FortinetVLANIPS
📡

Juniper SRX Routing

BGP/OSPF configuration, route policies, and zone-based security on Junos — hands-on toward JNCIA/JNCIS.

JuniperBGPJunos
🛡️

Wazuh SIEM + Grafana

Centralised log ingestion, threat detection dashboards, and alerting across all homelab nodes via Wazuh and Grafana.

WazuhGrafanaSIEM
🖥️

Proxmox Virtualisation

Multi-VM environment running TrueNAS, security tools, and test workloads. Isolated networks per service tier.

ProxmoxTrueNASKVM
🏠

Home Assistant Automation

Locally-hosted smart home integration with network isolation — no cloud dependency, full control.

Home AssistantIoT
⚔️

Pentesting Environment

Dedicated offensive security subnet with Kali Linux for OSCP prep — isolated from production segments.

KaliOSCPRed Team
🗄️

Dell R720 — Running in Lab

Bare-metal Dell PowerEdge R720 running ESXi, hosting isolated VM clusters for routing labs, security tools, and network simulation workloads.

Dell R720ESXiVMware
🌐

PNetLab — Network Simulations

PNetLab running on ESXi for multi-vendor network topology simulation. Used for CCNP/JNCIA lab scenarios with real IOS and Junos images.

PNetLabCisco IOSJunos
🔬

EVE-NG Lab Environment

EVE-NG Community Edition for building complex multi-vendor network topologies — BGP, MPLS, and SD-WAN scenarios across Cisco, Juniper, and FortiGate nodes.

EVE-NGMPLSSD-WAN

Proof of Work

Real-World Lab Scenarios

Scenario 01 · Firewall

FortiGate VPN Split Tunnel Misconfiguration

Diagnosed an SSL-VPN split tunnel issue where remote users were unable to reach internal subnets post-failover. Traced the fault to overlapping phase-2 selectors and corrected routing table priority.

✓ Phase-2 selector scope corrected, failover tested under load

Scenario 02 · Routing

BGP Route Leak Causing Asymmetric Path

Identified a BGP route leak between two VRFs on the Juniper SRX causing asymmetric routing and intermittent TCP resets. Applied route-policy filters and prefix-lists to enforce correct path selection.

✓ Symmetric path confirmed via traceroute across all VRFs

Scenario 03 · Security

Wazuh Alert Storm — False Positive Tuning

Wazuh generating 2,000+ alerts/hr from a misconfigured agent on a Proxmox node. Created custom decoders and tuned thresholds to reduce noise by 94% while retaining real detections.

✓ Custom ruleset deployed, alert fidelity fully restored

Scenario 04 · Switching

VLAN Trunk Mismatch Causing Intermittent Outage

Traced intermittent connectivity loss on a production VLAN to a native VLAN mismatch across trunk links between a Cisco switch and FortiGate. Identified via CDP and packet capture, corrected across all trunk ports.

✓ Trunk ports aligned, outage eliminated, documented for change control

Scenario 05 · Infrastructure

ESXi VM Network Isolation Breakdown

Discovered unintended cross-VLAN communication between ESXi VMs due to incorrect port group configuration on a virtual switch. Rebuilt vSwitch segmentation with dedicated port groups per security zone.

✓ Full VM network isolation restored, verified via inter-VLAN ping tests

Scenario 06 · Monitoring

Grafana Dashboard — Blind Spot in Metric Collection

Grafana dashboards showed gaps in node metrics during peak hours. Root cause traced to Prometheus scrape timeout on high-load Proxmox nodes. Tuned scrape intervals and added alerting for collection failures.

✓ 100% metric coverage restored, alerting on scrape failure added

Tools & Technologies

Tech Stack

Networking

FortiGate / Fortinet
Juniper SRX / Junos
Cisco IOS / IOS-XE
BGP / OSPF / EIGRP
VLANs / STP / Trunking
VPN / IPsec / SSL-VPN
MPLS / SD-WAN

Security

Wazuh SIEM
Kali Linux
Wireshark / tcpdump
IDS / IPS
Firewall Policy Design
Zero Trust Architecture
Nmap / Metasploit

Infrastructure

Proxmox VE
VMware ESXi
Dell PowerEdge R720
TrueNAS
Grafana / Prometheus
Home Assistant
Cloudflare

Lab & Simulation

PNetLab
EVE-NG
GNS3
Cisco IOS Images
Junos vSRX
FortiGate VM

Certifications

CCNA Certified
CCNP Certified
Fortinet NSE4 Certified
JNCIA Certified
CISSP In Progress
OSCP In Progress

Get In Touch

Let's Talk Networks

Open to MSP roles, network engineering opportunities, and collaboration in New Zealand and beyond.