A fully managed UniFi deployment serving as QSN’s own working head office — 10 GbE end-to-end fibre backbone, UDM SE gateway, 4-floor switching aggregation, Wi-Fi 7 access points across 4 zones, 8 segmented VLANs, zone-based firewall with 129 enforced policies, CyberSecure IDS/IPS with 72,102 active signatures, geo-blocking, region-routed VPN egress, encrypted DNS, and 24/7 honeypot deception across every subnet. Designed, deployed, and operated end-to-end by QSN as both reference architecture and daily-driver business network.
10 GbE fibre core fanning out to USW 1 Pro XG (SFP+ uplink), USW Lite 8 PoE, and downstream access switches. Spanning Tree root anchor, IGMP querier, and inter-VLAN L3 routing handoff to UDM SE.
• STP Root
8 × SFP+ 10G
IGMP Querier
RSTP
UDM SE Gateway
10 GbE
UniFi Dream Machine Special Edition · UniFi OS 5.0.16
All-in-one routing, firewall, IDS/IPS, threat intelligence, VPN termination (Teleport/WireGuard, OpenVPN client), and 7-zone policy engine. SFP+ to aggregation core.
Edge · Routing · Security
USW Aggregation
10 GbE
8-port 10G SFP+ aggregation switch
L3 fibre core handing off to USW 1 Pro XG and direct-attached 10G hosts. STP root anchor for the entire LAN. IGMP querier for multicast services.
Core Aggregation
USW 1 Pro XG
10 GbE
10-port managed multigig L2/L3 switch
Primary access switch — aggregates two Wi-Fi 7 APs, IT cabinet camera, NAS (10G), aggregation uplink, plus distribution to room-level switches. Multigig 2.5/10G ports.
Distribution + Access
USW Flex 2.5G 8 PoE
10 GbE
8-port 2.5G PoE access switch · 10G uplink
Workstation and smart-device PoE distribution. 2.5G to desktops, PoE+ for cameras and IoT bridges, 10G fibre uplink to USW 1 Pro XG.
Workstation Access
USW Flex XG
10 GbE
5-port 10G all-fibre access switch
High-throughput room/workstation switch serving the development zone. All 10G ports support full-line-rate sustained transfer to local NAS and across zones.
High-Throughput Zone
USW Lite 8 PoE
GbE
8-port managed PoE access switch
Auxiliary PoE distribution for media room: smart TV, PlayStation, room AP. GbE uplink to USW 1 Pro XG, PoE+ budget for additional APs/cameras.
Second flagship Wi-Fi 7 AP covering meeting/work area with overlapping seamless-roaming cell to AP Zone A. 10 GbE uplink, MLO-capable.
Secondary Coverage
AP Zone C
2.5 GbE
UniFi U7 Long-Range · Wi-Fi 7 dual-band
Long-range Wi-Fi 7 AP serving the far-end of the office footprint. 2.5 GbE multigig uplink, optimized for distance coverage rather than peak throughput.
Extended Coverage
AP Zone D
10 GbE
USW Flex XG attached AP · Wi-Fi 6
Dedicated AP block serving the dev zone. Mounted on USW Flex XG for full 10G-class capacity to LAN. Roaming-paired with Zone A/B for client handoff.
Development Zone
IT Cabinet Camera
FE
UniFi G5 Flex PTZ
Physical security camera attached to the rack itself — rack-cabinet surveillance, motion-triggered recording on UniFi Protect (VLAN 70), included as part of zero-trust physical posture.
Physical Security
DS-Class NAS
10 GbE
5-bay Synology NAS · 10G NIC
Centralized storage and Plex media server for the office. Connected at full 10 GbE to USW 1 Pro XG. Port-forwarded for remote-only Plex access (no SMB exposure to WAN).
Inbound Remote Access · Outbound Region Routing · Alt Egress
Primary Outbound VPN
↑ Egress · OpenVPN
Selected source devices on VLAN 40 are policy-routed outbound through a commercial OpenVPN endpoint in the US region. Used for region-locked services and privacy isolation while the rest of LAN egresses normally over WAN1.
Tunnel /32 · PBR: 6 source rules · Port 1195
Inbound Remote Access
↓ Ingress · WireGuard (Teleport)
UniFi Teleport / WireGuard hosted on the UDM SE for secure remote staff access. Invite-only via short-lived URL tokens with full invitation audit history. No always-open inbound ports.
VPN Server: WG-BlackPearl · Invite-based
Alt Egress Channel
↑ Egress · Reserved VPN
Secondary outbound VPN egress on VLAN 50 as policy-based-routing fallback or for clients needing a distinct egress identity from the primary VPN. All-traffic policy when in use.
The Black Pearl Head Office is one of QSN’s SMB managed deployments — designed as the reference architecture that QSN brings to every commercial client engagement. The full UniFi stack runs on a 10 GbE end-to-end fibre backbone with Wi-Fi 7 wireless edge, eight segmented VLANs governed by a 7-zone firewall enforcing 129 active policies, IDS/IPS with 72,102 signatures across all 7 threat categories, region blocking, encrypted DNS, layered VPN (inbound Teleport + outbound region-routed egress), and honeypot deception on every subnet. Over the last 24 hours alone the network blocked 23,807 threat events with zero successful breaches and zero unplanned downtime — the same operational posture QSN delivers to every managed SMB and commercial site.
Network as Mythology · The Black Pearl
AI · Generated Visualization
⊕
Edge Gateway · Steampunk Visualization
The Black Pearl, Reimagined as Legend.
An AI-generated artistic interpretation of the Black Pearl Head Office network stack — the 10 GbE backbone, UDM SE gateway, 7-zone firewall and segmented VLANs reimagined as a steampunk data-coffer aboard a pirate vessel. Each element of the visualization maps to a real component of the live infrastructure: the brass gear assembly stands in for the UDM SE core, the rope-tied patch cabling traces the 10 GbE backbone, the jellyfish-lit glass tubes represent illuminated VLAN segmentation, and the locked treasure chest at the centre is the encrypted-DNS · honeypot-defended subnet vault.
This visualization is not a literal rack diagram — it’s a brand-aligned reimagining that captures the spirit of the deployment: layered defense, structured aggregation, and the kind of operational reliability that makes a network worth naming after a flagship.
Brass Gear Assembly
→ UDM SE Core
Rope-Tied Patching
→ 10 GbE Backbone
Lit Glass Tubes
→ VLAN Segments
Locked Treasure Vault
→ Honeypot + DNS
AI-Generated Artistic Interpretation · Not a Literal Diagram · The Real Topology is Documented in Layers 0–7 Above
The Black Pearl · Reimagined as Legend · AI-Generated