Traffic Analysis
Measure current east-west traffic volumes
Use network monitoring tools to measure actual east-west traffic volumes between server groups. This determines spine-leaf oversubscription ratios.
Identify AI cluster bandwidth requirements
Document the bandwidth requirements for planned AI training clusters, per-node bandwidth and total cluster bandwidth.
Identify latency-sensitive traffic flows
Document the latency requirements for latency-sensitive applications: financial trading, real-time analytics, storage networks.
Document north-south traffic volumes
Measure traffic between the data center and external networks: internet, WAN, cloud. This determines border router and firewall sizing.
Topology Design
Define spine-leaf topology dimensions
Number of spine switches, number of leaf switches, uplink bandwidth per leaf, and oversubscription ratio.
Define out-of-band management network
Separate management network for all infrastructure components. Management network must be isolated from production traffic.
Define border routing architecture
BGP peering with upstream providers, redundant border routers, and failover routing.
Define AI cluster interconnect topology
For AI deployments: InfiniBand or RoCEv2 topology, switch count, and cabling plan.
Security Requirements
Define network segmentation requirements
Identify all compliance frameworks that require network segmentation (PCI DSS, HIPAA, FedRAMP) and the specific segmentation requirements of each.
Define firewall policy requirements
Document the firewall policies required for each network segment, including the business justification for each rule.
Define microsegmentation requirements
Identify workloads that require workload-level isolation beyond VLAN segmentation.
Define encryption requirements
Identify traffic flows that require encryption in transit (MACsec, IPsec) per compliance framework requirements.
IP and VLAN Design
Design IP addressing scheme
IP address ranges for all network segments, including management, production, storage, and AI cluster networks.
Design VLAN scheme
VLAN IDs for all network segments. Document the purpose and security zone for each VLAN.
Design BGP AS numbers and route policy
BGP autonomous system numbers, route policies, and prefix filters for all BGP peering sessions.
Design VXLAN VNI scheme
VXLAN Network Identifiers for all tenant networks. Document the mapping between VLANs and VNIs.
Migration Planning
Document current network topology
Complete documentation of the existing network: topology, configuration, IP addressing, and VLAN assignments.
Define cutover sequence
The order in which network segments will be migrated to the new infrastructure. Migrate lower-criticality segments first.
Define rollback procedures
How will the organization revert to the legacy network if a migration step fails? Rollback procedures must be documented and tested.
Plan maintenance windows
Maintenance windows for each migration event. Network migrations typically require brief outages, plan and communicate them in advance.
Configuration validation before cutover