Pumpkin
    Network Architecture

    The Point of Secure Network Design Is Containment

    One infected laptop shouldn't be able to reach the tax server. Segmented zones, managed firewalls, and remote access that checks the device before it lets anything through.

    Damage Control You Build in Advance

    Most firms run one flat network where every device can see every other device. That works fine until the day it doesn't, and then it works against you.

    Segmentation

    Client data lives on its own segment, away from the guest Wi-Fi, the conference room TV, and whatever the printer thinks it's doing.

    Remote Access With Checks

    VPN and zero-trust access that verify the machine before it reaches anything, so a home laptop with three years of missed patches doesn't get a seat at the table.

    Managed Firewalls

    Rules written for your firm, firmware kept current, threat feeds applied. Somebody owns the box, which is more than most firms can say.

    Network Topology

    See Your Entire Network at a Glance

    Every segment, every connection, every device, with health and policy state alongside it. The inventory alone usually earns the exercise. Almost every firm we map turns up something on the network that nobody present can account for.

    • Visual topology mapping
    • Device health monitoring
    • Policy compliance verification
    network.pumpkin.cloud/topology

    Segments

    5

    Devices

    72

    Status

    Healthy

    Client Data Zone

    12 devices

    Secured

    Staff Operations

    28 devices

    Secured

    VoIP Network

    18 devices

    Secured

    Guest Wi-Fi

    8 devices

    Isolated

    Remote VPN

    6 connections

    Active

    The Pieces We Design and Run

    Firewalls, zones, remote access, wireless, and the cloud side of it, all under one set of rules rather than five.

    Zone Design

    Client data, staff operations, guest access, and VoIP traffic on separate zones, with deliberate rules about what crosses between them.

    VPN and Zero Trust

    Encrypted access with device health checks, so getting on the network means proving the machine is in reasonable shape first.

    Firewall Management

    Rule changes, firmware updates, and log review handled, with a change history you can hand to an auditor.

    Cloud Connectivity

    Virtual firewalls and encrypted tunnels for cloud workloads, which now hold as much client data as the server closet ever did.

    Multi-Site Architecture

    Site-to-site VPN and SD-WAN with the same policy at every office, including the one with two people in it.

    Wireless Done Properly

    WPA3, client isolation, and a guest network that reaches the internet and nothing else on your network.

    Who It's For

    Firms whose network grew one device at a time and has never been drawn on paper.

    Multi-Office CPA Firms

    Branch offices connected under one policy instead of three different setups from three different installers.

    Remote & Hybrid Teams

    Access from home and from client sites that's fast enough to use and checked enough to trust.

    Growing Practices

    Architecture that survives the next ten hires and the next office without a rebuild.

    network.pumpkin.cloud/firewall
    Firewall Rules, Active

    Block all inbound RDP

    AnyAll Segments

    Deny

    Allow VPN tunnel (Branch Office)

    192.168.2.0/24Client Data Zone

    Allow

    Restrict guest to internet only

    Guest VLANInternet

    Allow

    Allow VoIP SIP traffic

    VoIP ZoneSIP Provider

    Allow

    Block known malicious IPs

    Threat FeedAll

    Deny
    Firewall Management

    Somebody Owns the Firewall

    We manage the rules, read the logs, and keep firmware current. In plenty of small firms the firewall was configured once by whoever installed the internet and hasn't been touched since. That's a fine arrangement right up until a vulnerability gets published for that exact model.

    • Custom rules for your practice
    • Threat intelligence integration
    • Multi-site policy management

    Frequently Asked Questions

    What is network segmentation, and why does it matter here?

    Segmentation splits the network into zones that can't freely reach each other, so the machine holding client tax data isn't sitting on the same flat network as the guest Wi-Fi and the conference room TV. When something does get in, segmentation decides whether you're cleaning one laptop or the entire firm.

    How do you handle staff working from home?

    VPN with device health checks and MFA, or zero-trust access that verifies each request no matter where it comes from. The check on the device is the important half. A personal laptop the whole family uses shouldn't get the same access as a firm-managed machine.

    Can you manage firewalls across several offices?

    Yes. One console, the same rules everywhere, site-to-site VPN between locations, and unified logging. Policy changes go out to every office at once, which beats the alternative of discovering in year three that the branch firewall was never configured past the default.

    How does network design help with compliance?

    IRS Publication 4557 and SOC 2 both expect network controls: segmentation, encrypted communication, restricted access, managed firewalls. We design with the documentation in mind, so what you built and what you can prove you built are the same thing.

    What if we're moving everything to the cloud?

    Then the network gets smaller and identity gets more important, but it doesn't disappear. We build hybrid designs connecting on-premises systems to Microsoft 365, hosted practice management, and virtual desktops, with virtual firewalls and encrypted tunnels around the cloud side.

    Draw the Network Before You Need To

    We'll map what you have, show you how far one bad click could travel today, and lay out what segmentation would take. The diagram is useful even if you stop there.