About This Architecture
Enterprise three-tier network topology with Palo Alto perimeter firewall, H3C core switches in HA, and distributed access layer serving office LAN and DMZ zones. ISP broadband connects through PA-VM-300 FW01 to a redundant core layer (CORE01/CORE02 stacked 10GE), which distributes traffic via L3 switches (DIST01/DIST02) to four access switches serving PCs, wireless APs, and servers. This architecture demonstrates defense-in-depth with trust/untrust zone separation, VLAN segmentation (DMZ on VLAN 10, office on VLANs 20/30/40), and high-availability core switching. Network architects can fork this diagram on Diagrams.so to customize switch models, add redundant firewall pairs, or adjust VLAN schemes for their environment. The design supports scalable office expansion and secure server isolation while maintaining sub-millisecond core convergence.