DC ENGINEERING · BY ANGEL INGLESE

Zero Trust doesn't replace your fabric.

Labs and builds bridging Cloudflare ZTNA/Tunnels with datacenter infrastructure — VXLAN/EVPN, ACI, Nexus, firewalls, VPNs — from someone who's run it all in production, not a homelab.

3,000+ Devices in production
2 Vendor certifications
4 Lab pillars
Angel Inglese

Most "Zero Trust" content is a homelab hobbyist wiring a Raspberry Pi to the internet. It skips the part that actually matters: what happens when you bridge this into a live VXLAN/EVPN fabric, an ACI tenant, or a firewall policy that's been in production for five years. That's the gap this fills — no 101 tutorials, no reposted docs. Every piece starts from an edge case.

What to expect

01

Bridge labs

Cloudflare Tunnel/WARP connecting into a lab VXLAN/EVPN fabric or ACI tenant — topology, config, gotchas.

02

Migration teardowns

Legacy patterns — site-to-site VPN, IPsec — rebuilt as ZTNA, side by side, tradeoffs and all.

03

Failure & troubleshooting

Deliberately broken builds — asymmetric routing, VRF leaks, tunnel flapping — walked through end to end.

04

Quick config drops

Short, single-topic notes — Terraform for a tunnel, a moquery one-liner, a WARP split-tunnel gotcha.

Latest

First lab dropping soon. Full writeups land here, videos on @a2ivdev.

Angel Inglese

Hi, I'm Angel

CCNP DC / JNCIA network engineer running day-2 operations across 3,000+ Nexus and ACI devices in multi-site environments. Currently working across SRX, MX, QFX, and Arista. I'm building a2iv to translate production DC experience into the Zero Trust world — configs included.

Available for short freelance engagements — Cloudflare Zero Trust/Tunnel rollouts, ZTNA migrations off legacy VPN, DC fabric design reviews (VXLAN/EVPN, ACI). If that's relevant to what you're building, reach out: angel@a2iv.dev.

Get updates

No newsletter form yet — for now, follow on YouTube.