About This Architecture
Red Retail's enterprise network spans headquarters, branch locations, and warehouse operations with segmented VLANs for production, testing, development, and management. Internet traffic flows through ISP Router, Firewall Externo, WAF, and Load Balancer before reaching the DMZ and internal Core Switch (L3), which distributes to environment-specific distribution switches. Production tier includes App Server, Web Server, API Server, and replicated databases; testing and development tiers mirror this structure at reduced scale. Remote sucursales and deposito connect via VPN Gateway through dedicated Firewall/Router appliances, with POS terminals and IoT scanners integrated at branch and warehouse levels. This architecture enforces security boundaries, enables traffic isolation by function, and supports scalable operations across geographically distributed retail locations. Fork this diagram on Diagrams.so to customize IP ranges, add additional branches, or integrate your own monitoring and authentication infrastructure. The design demonstrates defense-in-depth with external and internal firewalls, WAF protection, and VLAN-based segmentation—critical for retail environments handling payment data and customer transactions.