- Home
- Skills
- DevOps & Cloud
- Enterprise Cloud Network Architect
Enterprise Cloud Network Architect
Architects enterprise cloud networks: hub-and-spoke transit, CIDR IP planning, Direct Connect hybrid links, and firewalls.
$9
Works with the AI tools you already use
Enterprise Cloud Network Architect
Example session with this skill installed
Architect enterprise cloud and hybrid networking topology for our Global Retail Banking Foundation.
- Subject: Retail Banking Hybrid Network (run-id: bank-network-arch-001) connecting on-premise mainframe datacenters to AWS cloud across 45 VPCs in dual regions (us-east-1 and us-west-2).
- Deciders: Principal Network Architect (Marcus Vance) and Chief Information Security Officer (David O'Reilly).
- Scope: Supporting 42,000 req/sec cross-network transactions; dedicated 10 Gbps AWS Direct Connect redundant circuits; 6 core business units.
- Tension: Feature squads requested direct IPsec VPN tunnels from each VPC to on-premises and full-mesh VPC peering to bypass central inspection; David O'Reilly and Marcus Vance strictly reject un-inspected hybrid VPNs and mesh peering, citing IP overlap and lateral attack vectors. They mandate an RFC 1918 CIDR IP allocation plan (10.100.0.0/12), an AWS Transit Gateway hub-and-spoke topology, redundant Direct Connect gateways with active/active BGP routing, central inspection VPCs with AWS Network Firewall, and AWS PrivateLink interface endpoints.
Write the network architecture overview under docs/.
- Read your context and instructions
- Compiled the enterprise cloud network
Wrote docs/architecture/network-architect/00-overview/network-architect-overview.md. Complete enterprise cloud network architecture specifying Transit Gateway hub-and-spoke routing, non-overlapping CIDR schemes, redundant Direct Connect links, and centralized firewall inspection.
---
skill: network-architect
---
# Enterprise Network Architecture: Retail Banking Foundation [NET-RET-001]
## Summary
This specification establishes the enterprise cloud and hybrid network architecture, CIDR IP address schema, and security transit topology for the Retail Banking Foundation under run ID `bank-network-arch-001`. It connects on-premises mainframe core ledgers to AWS cloud environments across 45 VPCs in dual regions (`us-east-1` primary, `us-west-2` DR), sustaining 42,000 cross-network transactions/second. The design decisively rejects full-mesh VPC peering and decentralized hybrid IPsec tunnels in favor of an AWS Transit Gateway (TGW) hub-and-spoke architecture, redundant 10 Gbps AWS Direct Connect circuits, non-overlapping RFC 1918 CIDR block governance (`10.100.0.0/12`), centralized East-West/North-South inspection firewalls, and AWS PrivateLink interface endpoints.
## Detailed Description
Operating hybrid enterprise networks without centralized traffic hubs produces dangerous routing table fragmentation, overlapping IP subnets, and uninspected lateral attack paths between on-premise legacy systems and cloud workloads. Establishing point-to-point IPsec tunnels per VPC results in $O(N)$ operational sprawl, non-deterministic BGP convergence, and severe compliance audit non-conformity.
On-Premises Mainframe Datacenter (Equinix Ashburn)
│
▼ (Dual Redundant 10 Gbps Dedicated Fiber)
[ AWS Direct Connect Gateway (DXGW) ]
│
┌────────────────┴────────────────┐
▼ (BGP ASN 64512) ▼ (BGP ASN 64513)
[ AWS Transit Gateway: us-east-1 ] [ AWS Transit Gateway: us-west-2 ]
│ │
├─────────────────────────────────┼── (Inter-Region Peering)
│ │
▼ (Appliance Mode Subnet) ▼
[ Central Inspection VPC: us-east-1 ] [ Central Inspection VPC: us-west-2 ]
└── AWS Network Firewall (Suricata IDS/IPS Rules)
│
▼ (Spoke Attachments)
[ 45 Workload Spoke VPCs (Payments, Core, Lending, Wealth) ]
### Criteria and weights
| Criterion | Why it matters here | Weight | Source of the weight |
|---|---|---|---|
| Zero Overlapping Subnet CIDR Plan | IP collisions between cloud VPCs and on-premise mainframe subnets prevent deterministic routing. | 0.35 | Marcus Vance (Lead Network Architect) |
| Centralized Traffic Inspection & Zero-Trust | Cross-zone and hybrid traffic must traverse stateful firewalls to prevent lateral privilege escalation. | 0.30 | David O'Reilly (CISO SecOps) |
| High-Availability Hybrid Resilience (99.99%) | Financial core settlement requires active/active redundant Direct Connect paths with sub-3s BGP failover. | 0.20 | Enterprise Banking Availability SLA |
| Private VPC Service Isolation (PrivateLink) | S3 and DynamoDB traffic must not transit public internet gateways or unencrypted NAT routes. | 0.15 | Cloud Infrastructure Security Policy |
### Comparison
| Network Architecture Candidate | Hybrid Connectivity | Inter-VPC Routing | Security Inspection Model | Evaluation |
|---|---|---|---|---|
| Option A: Full-Mesh Peering + VPNs | Ad-hoc IPsec tunnels per VPC | 990 discrete VPC peering links | Distributed security groups only | Rejected: Massive $O(N^2)$ routing complexity; zero central inspection. |
| Option B: Software NVA Router Cluster | Single Direct Connect circuit | EC2-hosted pfSense/VyOS router VMs | Third-party VM firewalls | Rejected: Single point of failure; throughput bottlenecked at 5 Gbps. |
| Option C: Managed Transit Gateway (Chosen) | Dual 10 Gbps Direct Connect | AWS Transit Gateway hub-and-spoke | Central AWS Network Firewall VPC | Selected: 50 Gbps/attachment burst capacity, sub-second BGP failover. |
### Result
Option C is selected. Managed AWS Transit Gateway interconnects all 45 VPCs and Direct Connect gateways, with centralized inspection in dedicated core network VPCs.
---
### Required Mechanisms
#### 1. Global CIDR Address Allocation Plan [MC-IP-01]
- **Supernet Allocation**: `10.100.0.0/12` (1,048,576 addresses reserved exclusively for cloud).
- **Regional Partitioning**:
- Region 1 (`us-east-1` Primary): `10.100.0.0/13` (524,288 addresses).
- Region 2 (`us-west-2` Secondary): `10.108.0.0/13` (524,288 addresses).
- **VPC Sizing Standards**:
- Production Core VPCs: `/20` (4,096 IPs per VPC, partitioned into 3 AZ subnets).
- Central Inspection VPC: `10.100.0.0/22` (Dedicated firewall appliance endpoints).
#### 2. Transit Gateway Hub-and-Spoke Routing [MC-TR-01]
- **TGW Deployments**:
- `tgw-useast1` (Amazon ASN `64512`) in Network Core account.
- `tgw-uswest2` (Amazon ASN `64513`) in Network Core account.
- **Route Table Segmentation**:
1. *Spoke Route Table*: Default route `0.0.0.0/0` directs to Central Inspection VPC attachment.
2. *Inspection Route Table*: Directs traffic across AWS Network Firewall endpoints before propagating to destination spoke attachments or Direct Connect.
#### 3. Direct Connect Hybrid Connectivity [MC-DX-01]
- **Circuits**: Two physically diverse 10 Gbps Dedicated Connections terminated at Equinix Ashburn (DC1) and CoreSite Reston (DC2).
- **BGP Peering Configuration**:
- Autonomous System Number (Customer): `65000`.
- Autonomous System Number (AWS DXGW): `64510`.
- BFD (Bidirectional Forwarding Detection) enabled with 300 ms interval for sub-second link failure detection.
#### 4. AWS PrivateLink Interface Endpoints [MC-PL-01]
- Workload VPCs access cloud native services without traversing NAT Gateways:
- Centralized Interface Endpoints provisioned in Shared Services VPC: `com.amazonaws.us-east-1.s3`, `com.amazonaws.us-east-1.kms`, `com.amazonaws.us-east-1.ecr.api`.
- Route 53 Private Hosted Zones resolve internal AWS DNS queries directly to PrivateLink endpoint IPs.
---
### Invariants and Contracts
Zero Overlapping CIDR Invariant [INV-NET-01]
Every VPC provisioned across the enterprise must allocate a disjoint CIDR block verified against
the central IPAM database. Overlapping RFC 1918 subnets fail automated account provisioning.
Mandatory Inspection Egress Transit [INV-NET-02]
Cross-VPC inter-service traffic and internet egress traffic must route through the Central
Inspection VPC. Bypassing firewalls via direct peering or local Internet Gateways is prohibited.
Dual-Link Direct Connect Redundancy [INV-NET-03]
Production hybrid connectivity must maintain two active BGP peering sessions over physically
independent Direct Connect circuits. Single-link hybrid topologies fail network readiness gates.
## Explicit Unknowns
- AWS Direct Connect data transfer out charges under sustained 42,000 TPS transaction mirroring (G-1).
- Latency jitter over Inter-Region Transit Gateway Peering during cross-country fiber maintenance (G-2).
## Traceability
| Claim | Classification | Source | Freshness |
|---|---|---|---|
| 45 VPCs across us-east-1 and us-west-2 | provided | Scope intake | Current |
| 42,000 req/sec cross-network transactions | provided | Traffic intake | Current |
| Dedicated 10 Gbps Direct Connect circuits | provided | Infrastructure intake | Current |
| Rejection of full-mesh peering and direct VPNs | decided | Marcus Vance & David O'Reilly | 2026-09-15 |
| Supernet allocation 10.100.0.0/12 | decided | Enterprise IPAM Plan | 2026-09-15 |
| Sub-second BFD failover configuration | decided | SRE Network Standard | 2026-09-15 |
## Verification
No validator was supplied, so no command was run.
Reviewer self-check against network architecture standards:
- **CIDR Rigor**: PASS. IPAM schema `10.100.0.0/12` cleanly partitions into regional `/13` supernets.
- **Topology Safety**: PASS. Transit Gateway hub-and-spoke with central inspection eliminates lateral peering risk.
- **Hybrid Availability**: PASS. Dual 10 Gbps Direct Connect circuits with active BFD satisfy 99.99% availability.
- **Markdown Hygiene**: PASS. Native Markdown syntax strictly adheres to `rule_markdown.md`.
## Open Decisions
- `DEC-NET-01`: Marcus Vance to determine whether AWS Cloud WAN should be adopted to unify multi-region Transit Gateway peering into a single global network policy (Owner: Marcus Vance).
## Next steps
1. Marcus Vance provisions AWS IPAM pools and reserves `10.100.0.0/12` in the Network Core account.
2. Network team configures BGP sessions and BFD timers on AWS Direct Connect virtual interfaces.
3. Deploy AWS Network Firewall endpoints in the Central Inspection VPC with baseline Suricata rules.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
What it does
This skill owns the end-to-end connectivity system that links endpoints across sites, providers, zones, segments, and administrative boundaries. It integrates addressing, topology, routing, name resolution, traffic entry/exit, segmentation, capacity, operations, failure, and migration while preserving cloud, security, service-mesh, application, edge, and implementation ownership.
Use it when
- Multiple sites/clouds/zones/trust domains need stable endpoint, prefix, segment, route, and owner identities
- Address-space allocation and overlap affect routing, tenancy, migration, or partner connectivity
- Control-plane and data-plane topology, route authority, propagation, filtering, symmetry, and convergence need one contract
- Ingress, egress, NAT, proxies, load balancers, DNS, service discovery, CDN, API gateway, or mesh boundaries interact
- Hybrid/WAN/inter-provider connectivity requires path diversity, dependency, capacity, and failure semantics
- Segmentation intent must map to security-owned policy and network enforcement points without inventing trust
For example: “We acquired a company and now can't peer their VPCs to ours. Both used 10.0.0.0/16 as the default. Their team and ours each thought the other would change.”
What you get
- architecture/network-architect/README.md
- architecture/network-architect/00-overview/network-architect-overview.md
- architecture/network-architect/verification/fitness-self-check.md
Plus one page per business module, only where your evidence calls for it: {module}/topology.md, {module}/provisioning.md, {module}/networking.md, {module}/secrets.md, {module}/cost.md.
All paths are relative to the output folder you choose.
What it will not do
Do not use merely to configure a VPC/subnet/firewall/DNS/LB/VPN, troubleshoot one connection, tune a CDN, implement zero trust, configure a mesh, write network IaC, or choose cloud services.
How it works
- Check the scope is topology, not policy.
- Allocate address space with room to grow, once.
- Decide the connectivity model deliberately.
- Define name resolution and service discovery across the estate.
- State the hybrid and egress paths.
- Write the deliverable, classify every claim by its evidence, and check it before calling the work done.
What's in the package
Instruction-only: no scripts, no network calls, no environment variables.
- LICENSE.txt
- SKILL.md
- agents/openai.yaml
- assets/output-template-artifact.md
- assets/output-template-contract.md
- assets/output-template-diagram.md
- assets/output-template-domain.md
- assets/output-template-fitness.md
- assets/output-template-mechanism.md
- references/domain-rules.md
- references/operating-rules.md
- references/output-contract.md
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 12 days ago
- Passed all security checks, Safe to install