Case studyPublic sector · Digital identity — Romania

Digital Identity Platform

The infrastructure behind a national digital-identity platform — designed rack to cluster and delivered with firewalling, traffic visibility and network threat detection built in from the first cable.

ClientAuthority for the Digitalization of Romania
RoleInfrastructure low-level design & delivery
Footprint6 racks · segregated clusters
SecurityFortiGate · GigaVUE · Vectra NDR
StatusDelivered
Digital Identity Platform — the infrastructure behind a national digital-identity platform, delivered with firewalling, traffic visibility and network threat detection built in from the first cable. A glowing holographic identity card with photo and fingerprint in front of a data-centre server row.

01The challenge

Infrastructure worthy of
a national identity.

A digital-identity platform is only as trustworthy as the ground it runs on. It needs perimeter and segmentation to keep environments apart, storage and compute sized for a high-availability service, and — above all — the ability to see and reason about every packet on the network.

We produced the low-level design and delivered the estate end to end: racks, cabling, LAN and SAN, security, virtualisation and storage — with visibility and threat detection engineered in, not bolted on.

P1 Segmented by purpose Separate Security, Production and Test clusters, so environments never bleed into one another.
P2 Guarded at the edge High-throughput next-generation firewalls and application delivery in front of every service.
P3 Fully observable A packet broker mirrors traffic to a network detection-and-response engine that watches every flow.
P4 Tiered & protected High-end SAN, scale-out NAS, deduplicating backup and tape — data placed by value, protected at each tier.

02At a glance

Built for trust,
watched end to end.

6
APC racks, designed & cabled
3
segregated VMware clusters
4
storage tiers, SAN to tape
100%
traffic mirrored for detection

03The architecture

Edge, compute and storage, kept apart on purpose

The model below is the reference architecture, not the actual implementation. Traffic is firewalled and delivered at the edge, served by segregated virtualisation clusters, and held on a tiered SAN-and-NAS storage estate.

TIER 01
Edge & security perimeter & delivery
FortiGate

High-throughput next-generation firewall cluster.

F5 BIG-IP

Application delivery & load balancing.

TIER 02
Compute segregated virtualisation
VMware vSphere

Three isolated clusters across the estate.

Security cluster

Security and visibility workloads, kept apart.

Production · Test

Separate PROD and TEST clusters, no crossover.

TIER 03
SAN & storage tiered by value
Cisco Nexus

Data-centre switching backbone.

Cisco MDS

Fibre Channel SAN fabric.

DellEMC PowerMax

Tier-1 mission-critical SAN.

Isilon · Data Domain · tape

Scale-out NAS, deduplicating backup and a tape library.

04Visibility & threat detection

Every packet mirrored, every flow watched

Packet brokeringA GigaVUE visibility node aggregates and mirrors network traffic from across the fabric, so security tools see everything without sitting inline.
Network detection & responseA Vectra NDR platform consumes that mirrored traffic and applies AI-driven detection to surface threats and lateral movement in real time.
Isolation by designSecurity and visibility run in their own cluster, so detection keeps working even under pressure on the production estate.

05Confidentiality note

This is a security-sensitive engagement. We do not disclose specific addressing, locations, rack layouts, or the actual internal configuration of the platform.

The figures and the architecture on this page describe the reference model and the publicly communicable scope of the work.

06Next step

Securing critical national infrastructure?

We designed and delivered secured, observable infrastructure for a national digital-identity platform — firewalls, segmented clusters, tiered storage and full network detection. If you are building something that has to be trusted, we can help.

Connect with us →