Sean Troxel
Chief Technology Officer
An instinct for how systems work, hard-won and applied to infrastructure that holds up under pressure.
See what one missing piece costs a network
Three types of networks, each with more redundancy than the last: a single path from the internet to the desks, then a firewall pair with a backup ready to take over, then a two-site design with clustered firewalls and multiple uplinks. Reachability is computed live for each one, so a failure shows you exactly which parts of the business it takes with it.
Click any node to take it offline and watch the status change.
Simulated failures knock nodes offline at random; turn them off to inspect the diagrams undisturbed.
Packets are the moving dots - the teal lines mark the live paths either way, so hiding the dots costs no information. They start hidden if your system asks for reduced motion.
An interactive network diagram belongs here: three networks doing the same job with different amounts of redundancy, with reachability recomputed live as nodes are taken offline. It needs JavaScript to run. What it demonstrates:
- Small - one uplink, one firewall, one switch
- This is the one that fails first, and it fails completely. Take out the uplink, the firewall or the switch and everything behind it goes dark in the same instant, servers and workstations together, and the status reads Business down. Nothing reroutes, because there is nowhere else for traffic to go.
- Medium - paired uplinks and firewalls, two switches, a server pair
- The same failure becomes a failover. The primary firewall dies and its VRRP backup carries the traffic; the primary uplink dies and the second one takes over; a switch dies and the servers answer on their secondary. What still hurts is the workstation groups, single-homed to one switch each on purpose, so losing a switch takes its group with it and the status drops to Services affected while the rest of the business keeps working. Only losing both halves of a pair puts it back where the small tier started.
- Large - two sites, four uplinks and two firewall clusters each, meshed core, dedicated site-to-site links
- No single failure reaches the business function. Uplinks, firewalls and core switches resolve as one fabric, so every surviving path carries and damage is absorbed rather than routed around. Lose all four uplinks at one site and it rides the point-to-point site links to the other site's internet, which reads as degraded rather than down, because it is. The single-homed workstation groups remain the weakest thing on the diagram at every tier: redundancy stops where the last cable stops.
Watch a botnet search for weaknesses in your network
A botnet does not know where you are. It wanders until something answers, then it piles on, and the machines it finds first go down hardest. Three networks face the identical swarm here: one with no defense at all, one that pushes attackers back, and one that holds them inert until they give up. Nothing about the attack changes between them. The only variable is what the network does when the swarm arrives.
The swarm runs continuously and never resolves, because the attack never stops. It starts paused if your system asks for reduced motion.
A swarm simulation belongs here: a botnet wandering a field of servers, piling onto whatever answers, against three networks that differ only in what they do when it arrives. It needs JavaScript to run. What each defense does to the identical swarm:
- No defense
- Attackers hold connection slots until the server has none left, and it goes offline. Losing the server is what clears the attack, since the swarm on it dies with it - so the node comes back, and so does the swarm. Its outage count climbs faster than either of the others by a wide margin, and nothing else on this tier ever stops an attacker.
- Rate limiting
- Past a threshold the server pushes attackers off and scatters them, then waits out a cooldown before it can do that again. That buys real time and the outages drop sharply, but it removes nobody: the same attackers are still on the field, still looking, and a wave that lands inside the cooldown takes the server down anyway. It ends up carrying the largest live swarm of the three, precisely because it is the tier that stops detonating without ever clearing anyone.
- Rate limiting and tarpitting
- The same pushback, unchanged, plus a tarpit: a connection identified as hostile is captured rather than pushed, held open and inert until it times out. This is the only tier where the stopped count moves at all - on the other two the only thing that ever clears a connection is the server going down. Outages become rare instead of routine, with capacity still getting close during a heavy pile-on. The claim stops there: a captured connection is not a captured machine, and none of the three swarms gets smaller.
15
person team led
100+
business clients
~2,000
endpoints under active management
up to 10,000 touched annually
SOC 2 Type I
completed 2022
Career progression
-
Support Specialist I-III
2017-2019
-
Systems & Network Engineer
2019-2020
-
Chief Technology Officer
Sep 2020-Present