DC ENGINEERING · BY ANGEL INGLESE
Zero Trust doesn't replace your fabric.
Labs and builds bridging Cloudflare ZTNA/Tunnels with datacenter infrastructure — VXLAN/EVPN, ACI, Nexus, firewalls, VPNs — from someone who's run it all in production, not a homelab.
Most "Zero Trust" content is a homelab hobbyist wiring a Raspberry Pi to the internet. It skips the part that actually matters: what happens when you bridge this into a live VXLAN/EVPN fabric, an ACI tenant, or a firewall policy that's been in production for five years. That's the gap this fills — no 101 tutorials, no reposted docs. Every piece starts from an edge case.
What to expect
Bridge labs
Cloudflare Tunnel/WARP connecting into a lab VXLAN/EVPN fabric or ACI tenant — topology, config, gotchas.
Migration teardowns
Legacy patterns — site-to-site VPN, IPsec — rebuilt as ZTNA, side by side, tradeoffs and all.
Failure & troubleshooting
Deliberately broken builds — asymmetric routing, VRF leaks, tunnel flapping — walked through end to end.
Quick config drops
Short, single-topic notes — Terraform for a tunnel, a moquery one-liner, a WARP split-tunnel gotcha.
Latest
First lab dropping soon. Full writeups land here, videos on @a2ivdev.
Hi, I'm Angel
CCNP DC / JNCIA network engineer running day-2 operations across 3,000+ Nexus and ACI devices in multi-site environments. Currently working across SRX, MX, QFX, and Arista. I'm building a2iv to translate production DC experience into the Zero Trust world — configs included.
Available for short freelance engagements — Cloudflare Zero Trust/Tunnel rollouts, ZTNA migrations off legacy VPN, DC fabric design reviews (VXLAN/EVPN, ACI). If that's relevant to what you're building, reach out: angel@a2iv.dev.
Get updates
No newsletter form yet — for now, follow on YouTube.