Council secure remote access / Solution design

Secure access for a distributed public-service team

Connect office staff, remote workers and public counters without making internal services reachable from visitor networks.

Government environment for this solution design
Built around the way you workArchitecture · Equipment · Delivery
01

Protect internal services from public access

02

Make remote access attributable

03

Keep essential services usable on backup

Architecture / 01

How the solution connects

Independent uplinks meet a controlled network boundary. Local access is separated by purpose.

Secure access for a distributed public-service team: proposed architectureOffice internet connects to MX75 + remote access (Primary path). RUTM11 LTE · backup connects to MX75 + remote access (Alternate WAN). MX75 + remote access connects to Catalyst access switch (Policy boundary). Catalyst access switch connects to Staff applications (Separate zone). Catalyst access switch connects to Public counters + Wi-Fi (Separate zone). Catalyst access switch connects to Restricted management (Separate zone). Logical overview; final cabling and firewall rules are specified during design.01 / TRANSPORT02 / CONTROL03 / DISTRIBUTE04 / ACCESS ZONESWANBACKUPOffice internetRUTM11 LTE · backupMX75 + remote accessCatalyst access switchStaff applicationsPublic counters + Wi-FiRestricted management
Logical data pathBackup / optional transportConceptual design · final ports, policies and quantities are specified for the site
Read the connection map
  • Office internetMX75 + remote access · Primary path
  • RUTM11 LTE · backupMX75 + remote access · Alternate WAN
  • MX75 + remote accessCatalyst access switch · Policy boundary
  • Catalyst access switchStaff applications · Separate zone
  • Catalyst access switchPublic counters + Wi-Fi · Separate zone
  • Catalyst access switchRestricted management · Separate zone

The challenge on the ground

Public counters, meeting rooms and remote staff have different access needs. Shared accounts and broad VPN permissions make those differences difficult to enforce.

The network should expose only the applications a role needs and leave an audit trail that identifies the person and device involved.

Inside the design

Use an MX75 at the office edge, managed Catalyst access switching and indoor CW9172I APs. Create separate staff, public, building-device and management zones.

Connect RUTM11 LTE as a secondary WAN for essential applications. Remote access terminates at an approved gateway integrated with the organisation’s identity and MFA service; its licence and device-posture capabilities are scoped explicitly.

Operating it day to day

Assign application access by role and require a separate administrative account for infrastructure changes. Set an expiry for contractors and test offboarding, including active sessions.

Record which services are permitted over the cellular link and cap public Wi-Fi during an outage. Provide a recovery process for a lost authenticator that does not become an informal MFA bypass.

What to test before handover

  1. Test staff, contractor and disabled-account access separately.
  2. Verify public clients cannot reach staff or management networks.
  3. Check a critical public-service workflow over LTE.
  4. Review connection and administrative logs with the service owner.

Technical references

Equipment / 02

The bill of materials

4 scoped items

One municipal office with staff devices, public access and an existing identity provider. Quantities below describe the example; your proposal confirms the final equipment and services.

01In this design
CISCO

Cisco Meraki MX75 Security Appliance

MX75

Office security boundary

View product
02In this design
Cisco

Cisco Catalyst C9300-48P-E switch

C9300-48P-E

Managed office access

View product
03In this design
Cisco

Cisco CW9172I indoor access point

CW9172I-CFG

Staff and public wireless

View product
04In this design
Teltonika

Teltonika RUTM11 LTE router

RUTM11000000

Essential-service LTE backup

View product

Complete the installation

The equipment above is one part of the project. Include these items in the final scope.

  • Remote-access and network licences
  • Identity/MFA service
  • Cabinet, UPS and cabling
  • Mobile plan and application acceptance testing
Details worth knowing

Questions before you specify

Does a VPN give remote staff access to everything?

It should not. Assign named application or subnet permissions to roles, then test both allowed and denied access.

From reference to reality / 03

Let’s design it for your site.

Send us the details below. We can turn the reference architecture into a scoped design, equipment schedule and quotation.

Start your project

Bring these to the first conversation

  • 01Identity provider and remote-access client
  • 02Applications by staff role
  • 03Public Wi-Fi scope
  • 04Logging and offboarding policy
← Explore all solution designs