HomeAboutContactPartners & Clientele Managed WiFi Security & CCTV Smart Home Automation NAS Solutions PBX Solutions Audio Visual Network Design Heat Mapping Custom PC Case Studies Wi-Fi 5 vs 6 vs 7 Managed WiFi vs ISP NAS vs Cloud Storage KNX vs WiFi Automation
Home  /  Case Studies  /  Commercial  /  REFERENCE SITE-1

Reference Site-1
Commercial Network

QUICK SURF NETWORK

Unleashing Digital Excellence

CASE STUDY · 2026
SITE: REFERENCE SITE-1 · COMMERCIAL
STACK: TP-LINK OMADA · CLOUD-MANAGED
UPTIME: 4+ YEARS · CONTINUOUS SINCE 2021
WAN: TRI-WAN · LOAD-BALANCED
STATUS: ● LIVE · HEALTH 98/100
Reference Site-1 · Multi-Floor Commercial
Enterprise Multi-Floor
Network Topology

A fully managed TP-Link Omada deployment under continuous QSN operations since August 2021 — 55 access points distributed across 5 floors on a structured copper backbone, tri-WAN edge with intelligent load balancing, 6-VLAN per-floor segmentation policy, hardware-controller managed for cloud-grade reliability, and defended by 12-of-12 IDS/IPS threat categories with full packet-anomaly and flood-defense hardening. 512 sustained clients · 826 GB daily throughput · zero unplanned downtime — engineered, deployed, and monitored end-to-end by QSN.

1
Gateway + Controller
ER7206 + OC300
7
Switches
1 × 10G CORE + 6 × ACCESS
55
Access Points
5 FLOORS · STRUCTURED LAN
6
VLANs · 9 SSIDs
PER-FLOOR SEGMENTED
512
Clients · Sustained
5 WIRED · 507 WIRELESS
4+yr
Cloud Operations
CONTINUOUS SINCE 2021
Layer 0 — Tri-WAN Edge · Load Balancing · Cloud Management

Internet (3) · Tri-WAN

SFP WAN
Fibre · Primary uplink
•••.•••.•••.•••
Copper WAN
Primary ISP · Secondary uplink
•••.•••.•••.•••
WAN/LAN1
Test Port · Tertiary uplink
•••.•••.•••.•••
REFERENCE SITE-1
ER7206 GATEWAY · OC300 CONTROLLER
Cloud-Managed Edge · Load-Balanced · GEO-Enforced

Cloud Operations

Omada Cloud Access
Connected · UTC+04:00
LIVE
Controller Uptime
OC300 hardware controller
37 d + 23 h
24h Site Health
Device · Client · Wi-Fi · WAN
98 / 100
Layer 1 — Traffic Policy · QoS Profiles · Rate Limiting
Corporate
Download6 000 Kbps
Upload2 500 Kbps
Admin
Download10 000 Kbps
Upload5 000 Kbps
Workstations
Download5 000 Kbps
Upload2 000 Kbps
Limitless
Download20 000 Kbps
Upload10 000 Kbps
Layer 2 — VLAN Architecture · Per-Floor Isolation

6 VLAN Segments

Subnet · DHCP · Access-Control Enforced
Management
VLAN 1 · DEFAULT
/24 · MGMT only
Ground Floor
VLAN 10 · GF
/24 · 254 IPs
1st Floor
VLAN 20 · 1F
/24 · 254 IPs
2nd Floor
VLAN 30 · 2F
/24 · 254 IPs
3rd Floor
VLAN 40 · 3F
/24 · 254 IPs
4th Floor
VLAN 50 · 4F
/24 · 254 IPs
Layer 3 — Wireless Network Architecture · 8 WLAN Groups · 9 SSID Broadcasts
RS1-CORP
2.4 GHz · WPA-Personal
Default Group · VLAN 1
Site-wide management
RS1-CORP
2.4 GHz · Guest Mode ✓
GF Group · VLAN 10
Ground Floor access
RS1-ADMIN
2.4 + 5 GHz · WPA-Personal
Admin + GF Group · VLAN 10
Privileged staff · dual-band
RS1-SURVEILLANCE
2.4 GHz · Guest Mode ✓
Security GF Group · VLAN 10
CCTV uplink · isolated
RS1-CORP
2.4 GHz · WPA-Personal
1F Group · VLAN 20
1st Floor access
RS1-CORP
2.4 GHz · WPA-Personal
2F Group · VLAN 30
2nd Floor access
RS1-CORP
2.4 GHz · WPA-Personal
3F Group · VLAN 40
3rd Floor access
RS1-CORP
2.4 GHz · WPA-Personal
4F Group · VLAN 50
4th Floor access
Layer 4 — Core Aggregation · Access Distribution · AP Estate

SX3008F · 10 GbE Core Aggregation

8-port managed L3 fibre core switch
Single aggregation node fanning out to all 6 access switches over 1000FDX uplinks. Inter-VLAN routing, DHCP relay, multicast snooping, and STP enforced at this layer.
• HEALTH 10/10
8 GbE / SFP+ ports
L3 ROUTING
Access Switch GF
5 APs
GbE PoE managed switch · 1000FDX uplink to core
Common-area coverage across GF Common Hall · GF Service Area · GF Recreation Lounge · GF Admin & Security Office · GF Safety & Welfare Office. Hosts the dedicated RS1-SURVEILLANCE camera SSID and outdoor-rated admin uplink.
VLAN 10 · GF · 254 IPs
Access Switch 1F
13 APs
GbE PoE managed switch · 1000FDX uplink to core
Full-floor saturation: 13 access points deployed across rooms and corridors with overlapping coverage cells for seamless roaming. Per-room density tuned for sustained client load.
VLAN 20 · 1F · 254 IPs
Access Switch 2F
13 APs
GbE PoE managed switch · 1000FDX uplink to core
Mirror coverage profile to 1F — 13 access points across the floor footprint, channel-planned to minimize co-channel interference between vertically stacked APs.
VLAN 30 · 2F · 254 IPs
Access Switch 3F
13 APs
GbE PoE managed switch · 1000FDX uplink to core
13 access points distributed for full-floor coverage. Standard WLAN group binding with isolated subnet — no inter-floor broadcast traffic.
VLAN 40 · 3F · 254 IPs
Access Switch 4F
11 APs
GbE PoE managed switch · 1000FDX uplink to core
Top-floor coverage with 11 access points. Reduced count reflects floor-plan footprint; coverage equivalence maintained via cell tuning.
VLAN 50 · 4F · 254 IPs
Annex Distribution SW
Outbuilding
Auxiliary switch · 1000FDX uplink to core
Separate-block distribution serving outbuilding network drops. Connected at the core layer for failure-domain isolation from main-building access switches.
Routed at L3 · Core-attached

Defense in Depth · 30+ Active Hardening Controls

IDS/IPS · Firewall · Anomaly · Flood
Layer 7 · Intrusion Detection & Prevention
IDS/IPS · Detect & Prevent (IPS)
ACTIVE
Threat Categories · 12 of 12 Enabled
SECURITY: HIGH
GEO Enforcer · Region-Based Filtering
ENABLED
Signature Suppression · Block / Allow Lists
CURATED
Layer 3/4 · Packet Anomaly Defense
Block TCP Stealth Scan · FIN/Xmas/Null
ENFORCED
Block Ping of Death
ENFORCED
Block Large Ping
ENFORCED
Block Ping from WAN
ENFORCED
Block WinNuke Attack
ENFORCED
Block TCP SYN+FIN Set
ENFORCED
Block TCP FIN without ACK
ENFORCED
Block Specified IP Options · 5 sub-flags
ENFORCED
Layer 2/3 · Flood Defense · Stateful Firewall
Multi-Connections TCP SYN Flood Guard
10 000 Pkt/s
Multi-Connections UDP Flood Guard
20 000 Pkt/s
Multi-Connections ICMP Flood Guard
1 500 Pkt/s
Stationary-Source TCP SYN Flood Guard
4 000 Pkt/s
Stationary-Source UDP Flood Guard
6 000 Pkt/s
Stationary-Source ICMP Flood Guard
600 Pkt/s
SYN Cookies · Half-Open Connection Shield
ACTIVE
Broadcast Ping Blocked · ICMP Reflection Shield
BLOCKED
Receive Redirects Blocked · MITM Shield
BLOCKED
IntelliRecover · Auto PoE Reboot on Offline
3× / 15-min

Operational Excellence · 4-Year Cloud Track Record

98 / 100
Site Health Score
Device · Client · Wi-Fi · WAN
826 GB
Daily Throughput
SUSTAINED · 24H AVG
512
Total Clients
5 WIRED · 507 WIRELESS
37 d+
Camera Uptime
4 × IP CAM · ZERO DROPS

Reference Site-1 has been under continuous QSN cloud management since August 2021 — over four years of unbroken operations. The site sustains 512 concurrent clients across a 55-AP estate with a maintained health score of 98/100, processing 826 GB of daily throughput across a tri-WAN edge with intelligent load balancing. Four critical IP cameras have maintained 37+ day continuous uptime at last sample — a direct outcome of IntelliRecover PoE-cycling and continuous device-health monitoring. This deployment is one of several sister sites QSN operates for this client across the region under identical architectural blueprints.

TP-Link Omada Switch
EAP Access Point
SX3008F 10G Core
VLAN Boundary
OC300 Controller
IP Camera
Active Threat Alert
IDS/IPS Layer
Designed · Deployed · Monitored by QSN
quicksurfnetwork.com · +971 4 288 2335 · Port Saeed, Deira, Dubai · info@quicksurfnetwork.com