Skip to main content

05 · Production topology

Every tier drawn as a redundant pair

Cleaned up from the whiteboard sketch: the WAF, edge A10, site-to-site firewalls and the remote IDC core were drawn single there — all of them are HA pairs, so they are shown as pairs here.

North–SouthEast–WestAir-gap / at-riskPeer / HA linkFabric mesh CHT · TFN · TFNCHT · TFN · TFNBorder Switch ABorder Switch BINTERNET BORDER · MULTI-CARRIER, PER-SWITCH DIVERSITYINSPECTION & EDGE LB · CROSS-LINKED TO BOTH BORDERSWAF · Netscaler A + BEdge A10 · A + BPARTNER CIRCUITS · DEDICATED ROUTINGNCCCFubon Bank···GATEWAY FIREWALLS · BOTH HA, CROSS-CONNECTEDFortiGate AFortiGate BPalo Alto APalo Alto BEgress to internetCORE HA PAIR · BOTH CARRY N–S AND E–WCore Switch AactiveCore Switch BactiveOther IDC · core pairSite-to-site · HA both endsPAYMENT VLAN · SAME RACK GROUPTOR ATOR BSERVER VLANS · TOR PAIR PER RACK, DUAL-HOMEDTOR A / BTOR A / BTOR A / BWORKLOAD TIERPayment serversA10 · A + BAPISixServers · Kubernetes

Tier walk-through

Internet border

Multi-carrier circuits (CHT / TFN), per-switch diversity.

Inspection & edge LB

WAF (Netscaler pair) and edge A10 pair, both cross-linked to both border switches.

Partner circuits

NCCC and partners terminate on dedicated FortiGates with dedicated routing.

Gateway firewalls

FortiGate pair and Palo Alto pair, both HA and cross-connected; egress to internet.

Core

One HA pair; both switches carry north–south and east–west (see 06 · Corrected switch design for the fix).

Site-to-site

Tunnel to the other IDC, HA at both ends.

Server zone

Every rack has a TOR pair, dual-homed to both cores; server VLANs and the payment VLAN share the same rack group.

Workload tier

A10 load balances to APISix / A10; those load balance to servers or Kubernetes.

:::note Payment VLAN Payment servers share the same rack group on a separate VLAN — server ↔ payment traffic is routed Server → TOR → Core → FortiGate → Payment VLAN, never switched directly. :::