Technical notes, project documentation, and article drafts.

This hub collects the thinking behind the portfolio: industrial networking, OT cybersecurity, packet analysis, engineering governance, and the transition from manufacturing engineering into Network Security Engineering.

Documentation purpose

This page is the knowledge hub for the portfolio: a place for technical notes, project documentation, OT cybersecurity articles, and professional writing connected to industrial networking.

The aim is to show not only the projects, but the thinking behind them: secure change, packet evidence, configuration control, operational risk, and reliable industrial networks.


Project documentation

Engineering Change Request Platform

Governance workflow, roles, evidence, audit trail, reports, and secure demo strategy.

Open case study

Packet Insight

Scientific PCAP analytics, case-based packet investigation, statistics, and professional reporting.

Open case study

NetSafe Auditor

Future device inspection, configuration auditing, baseline comparison, and structured audit reports.

Open case study

OT Network Lab

Architecture, Proxmox, PNETLab, automation, segmentation, routing, switching, and OT security controls.

Open case study

Building the Proxmox OT Security Lab

A practical progress report covering the move from a Proxmox host to a working PNETLab environment with IT, industrial DMZ, and OT paths connected through a Palo Alto firewall.

The article records host and VM resources, topology milestones, router and switch checks, firewall interfaces and zones, and the unresolved NTP result. It demonstrates why a saved configuration must be followed by operational validation.

Implementation evidence and lessons learned

View the annotated screenshot gallery, completed milestones, open fault, and next build steps.

Read lab update

Designing OT Segmentation: Two Preliminary Architecture Concepts

A focused engineering comparison of two approaches to OT VLAN segmentation before implementation in the Proxmox and Palo Alto lab.

The study compares Layer 3 core routing with ACL enforcement against firewall-hosted tagged subinterfaces with centralised security policy. It records the assumptions, Packet Tracer proof, scalability questions, and measurements planned for the next lab phase.

From concept to measurable decision

Review both architecture diagrams, their control points, and the criteria that will guide the final design.

Read architecture study

Implementing the OT Layer 3 Core in PNETLab

A practical checkpoint showing how the five-VLAN OT segmentation plan moved from architecture study to a working Layer 3 core and routed firewall transit.

The article includes the implemented VLAN and addressing strategy, the newest topology, routing and backup evidence, a duplicate-IP troubleshooting lesson, and the initial inter-VLAN ACL policy and rollout plan.

From unrestricted routing to controlled conduits

Review the validated pre-ACL baseline and the staged controls planned for management, cell, service, and test VLANs.

Read implementation article

Technical notes

This section will collect short, readable notes that explain specific networking and OT security concepts in a practical engineering context.

VLAN segmentation802.1Q trunksSTP / RSTPHSRPACLsFirewall rulesPacket capturesDNS / ARP / TCPOT zoningConfiguration backupBaseline auditingSecure remote access

Practical networking concepts applied to OT environments

These notes adapt core networking topics into an industrial context. The focus is not only on how the technology works, but why it matters when networks support manufacturing operations, engineering access, asset visibility, and operational resilience.

VLANs for OT Network Segmentation

VLANs are one of the first practical controls used to separate network traffic. In an office network, VLANs may separate departments or device types. In an OT environment, the purpose becomes more operationally important: separating production assets, engineering workstations, HMIs, PLCs, cameras, vendor access, and business IT systems.

Good segmentation helps reduce unnecessary broadcast traffic, limits the spread of faults, and supports clearer security boundaries. For example, a production cell should not automatically share the same flat network as office laptops or guest devices. Even when firewall rules are not yet mature, VLANs provide a structured foundation for zoning and future control.

From a manufacturing perspective, VLANs are useful because they make the network easier to understand, document, troubleshoot, and protect. They turn a flat environment into defined areas of responsibility.

DHCP Snooping: Protecting Industrial Networks from Rogue DHCP

DHCP makes IP addressing easier, but in industrial networks an unexpected DHCP server can create serious disruption. A misconfigured router, test device, or laptop can hand out incorrect network settings and cause machines, HMIs, or engineering stations to lose communication.

DHCP Snooping helps by allowing switches to distinguish trusted DHCP sources from untrusted ports. Only approved ports should provide DHCP responses. This reduces the risk of accidental or malicious address assignment and helps preserve predictable network behaviour.

In OT environments, the value is not only cybersecurity. It is also reliability. Preventing rogue DHCP behaviour can protect production continuity and reduce difficult troubleshooting during outages.

Dynamic ARP Inspection: Reducing ARP Spoofing Risk

ARP is a normal part of Ethernet networking, but it can also be abused. ARP spoofing or poisoning can misdirect traffic, interrupt communication, or support man-in-the-middle attacks. In industrial networks, this could affect visibility between engineering workstations, HMIs, servers, and control devices.

Dynamic ARP Inspection checks ARP messages against trusted information, often learned through DHCP Snooping. This helps prevent devices from falsely claiming another device’s IP address.

For OT cybersecurity, this is a useful example of Layer 2 protection. Many industrial networks rely heavily on stable local Ethernet communication, so protecting address resolution supports both security and operational reliability.

STP/RSTP: Redundancy and Loop Prevention in Plant Networks

Redundancy is common in industrial environments because downtime matters. However, connecting switches with multiple paths can create loops if the design is not controlled. A switching loop can flood a network and quickly become an operational incident.

Spanning Tree Protocol and Rapid Spanning Tree Protocol help prevent loops by controlling which paths are active and which paths remain available as backups. In plant networks, this supports resilience while reducing the risk of uncontrolled Layer 2 behaviour.

The key lesson is that redundancy must be designed, documented, and tested. More cables do not automatically mean more resilience. A resilient OT network needs predictable failover and clear understanding of how switches will behave during a fault.

Syslog: Turning Network Events into OT Visibility

Syslog allows switches, routers, firewalls, and other devices to send event messages to a central logging system. In a small lab, logs help with troubleshooting. In an OT environment, logs become part of operational visibility and incident response.

Without central logging, important events may remain hidden on individual devices. Link changes, failed logins, configuration changes, interface errors, and security alerts can be missed until a problem becomes visible in production.

For OT cybersecurity, Syslog supports evidence. It helps answer practical questions: what changed, when did it happen, which device reported it, and what else occurred at the same time?

NTP: Why Time Synchronisation Matters in OT

Network Time Protocol keeps systems aligned to a common time source. This may sound like a small detail, but in troubleshooting and cybersecurity it is critical. If switches, firewalls, servers, and monitoring tools all use different clocks, event correlation becomes unreliable.

In OT environments, time matters for alarms, production events, access logs, packet captures, and incident timelines. When investigating a fault or security concern, accurate timestamps help build a clear sequence of events.

NTP is therefore not just a convenience feature. It is part of engineering evidence quality. Reliable time supports reliable investigation.

ACLs: Basic Traffic Control Between OT Zones

Access Control Lists are a simple but important way to control which traffic is allowed or denied. In OT networks, they can help limit communication between zones, reduce unnecessary access, and support the principle of least privilege.

For example, an engineering workstation may need access to specific industrial devices, but office systems may not need direct access to the same area. ACLs can help define these boundaries, especially in smaller environments or lab designs where full firewall architecture is not yet in place.

ACLs should be planned carefully because blocking the wrong traffic can disrupt operations. The OT mindset is to understand the process, document the requirement, test the change, and keep evidence of what was implemented.


Procedures and practical guides

Procedure-style notes will focus on repeatable engineering methods that support secure and reliable industrial networks.

  • Reviewing an OT firewall-rule change before implementation.
  • Documenting an Engineering Change Request with evidence.
  • Capturing packets safely for troubleshooting and analysis.
  • Baselining a switch configuration for audit review.
  • Preparing a simple network audit report.

Article themes

Articles will connect manufacturing engineering credibility with practical network security learning. Each theme is designed to support the wider portfolio story.

Manufacturing and OT risk

How safety-critical engineering experience helps shape better thinking about industrial cybersecurity and operational reliability.

Packet evidence

How packet captures can become structured engineering evidence rather than disconnected troubleshooting files.

Secure change

How change control, approval, evidence, and verification support cybersecurity in industrial environments.

Network security development

How practical projects, labs, documentation, and writing support a long-term Network Security Engineer direction.


From Safety-Critical Manufacturing to OT Network Security

Modern manufacturing depends on connected systems, reliable networks, controlled change, and trustworthy data. For me, OT cybersecurity is not a completely separate career direction from manufacturing engineering. It is a natural extension of the same engineering discipline I have worked with for more than 20 years.

My background is rooted in safety-critical manufacturing, product engineering, process control, root-cause analysis, quality improvement, and structured change management. In these environments, reliability matters. Evidence matters. Traceability matters. A small uncontrolled change can create technical risk, production disruption, or safety concerns.

That same thinking applies directly to industrial networks.

An OT network is not only a collection of switches, routers, firewalls, PLCs, HMIs, and servers. It is part of the production system. If communication fails, visibility is lost, access is uncontrolled, or changes are not properly reviewed, the impact can move quickly from a technical issue to an operational risk.

This is why I am building my portfolio around industrial networking and OT cybersecurity. My goal is to connect manufacturing engineering experience with practical network security capability.

The Engineering Change Request Platform demonstrates controlled technical change, approvals, evidence, workflow status, and audit trail thinking.

Packet Insight focuses on packet captures as engineering evidence, helping transform network traffic into structured analysis and readable findings.

NetSafe Auditor is planned as a future network device inspection and configuration auditing tool, supporting repeatable review and reporting.

The OT Network Lab will demonstrate architecture, automation, segmentation, routing, switching, resilience, and secure design principles in a practical environment.

Together, these projects support one direction: developing as a Network Security Engineer with strong OT and industrial systems understanding.

For me, the key lesson is simple: cybersecurity in industrial environments is not only about tools. It is about engineering judgement, controlled change, visibility, evidence, and reliability.

That is the bridge I am building through this portfolio.


LinkedIn articles

This section will connect future LinkedIn articles with the portfolio projects they relate to. The aim is to make each article part of a wider technical story: engineering experience, OT networking, packet analysis, secure change, and practical Network Security Engineer development.

From Safety-Critical Manufacturing to OT Network Security

The first article draft on this page introduces the overall portfolio story and career direction.

Packet Captures as Engineering Evidence

A future article connected to Packet Insight and structured PCAP analysis.

Change Control as a Cybersecurity Control

A future article connected to the Engineering Change Request Platform and secure OT governance.

Building the Proxmox OT Security Lab

A published progress article connecting virtual infrastructure, network segmentation, firewall zones, validation evidence, and troubleshooting.

Read article

Designing OT Segmentation

A preliminary architecture study comparing distributed ACL enforcement with centralised firewall policy.

Read architecture study