🏙️ MAN (Metropolitan Area Network)

Connect Campuses, Data Centers & Cloud — Fast, Resilient, and Proven

A Metropolitan Area Network (MAN) is the high-speed fabric that stitches together headquarters, campuses, data centers, cloud on-ramps, and edge sites across a city/region.
SolveForce engineers MANs as a system: optical and packet rails (DWDM, wavelengths, Ethernet, IP/MPLS), EVPN/VXLAN campus cores, SD-WAN policy, Zero-Trust edges, and evidence pipelines so every span, class, and change is measurable and auditable.

Related deep dives
• Campus/DC fabric → /networks-and-data-centers • Access/Fiber → /fiber-internet • Optical/DCI → /wavelength • Dark/ Lit → /dark-fiber/lit-fiber
• WAN overlays → /sd-wan • Cloud on-ramps → /direct-connect • Campus LAN → /lan • Wide area → /wan
• Security → /ztna/sase/nac • Edge sites → /edge-data-centers
• Evidence/Ops → /siem-soar/circuit-monitoring • Colo/VDC → /colocation/virtual-data-centers


🎯 Outcomes We Optimize

  • Deterministic latency & throughput— low-microsecond switching, sub-millisecond metro spans for storage, AI fabrics, and real-time apps.
  • Resilience by design— protected rings/meshes, fast reroute, dual laterals/POPs, and SD-WAN brownout steering.
  • Cloud adjacency— private on-ramps (DX/ER/Interconnect) with policy-driven routing and Anycast edges.
  • Security by default— MACsec/L1 crypto where required, segmentation (EVPN/VXLAN), ZTNA for admin access.
  • Evidence on demand— OTDR, light levels, RFC 2544/Y.1564, BGP traces and change diffs to SIEM/SOAR.

🧭 Reference Architecture (metro fabric)

Optical layer (L0/L1)

  • DWDM/ROADM ring or mesh; protected spans with < 50 ms switching; coherent optics for 100/200/400G; optional L1 encryption.
    /wavelength/dark-fiber

Packet transport (L2/L3)

  • Carrier EthernetEPL/EVPL/E-LAN/E-Tree for L2 private connectivity.
  • IP/MPLS / Segment Routing (SR-MPLS/SRv6)for L3 VPNs with TE/FRR.
  • EVPN/VXLANstretching campus fabrics where justified (with failure-domain boundaries).
    /fiber-internet/networks-and-data-centers

Edge & policy

  • SD-WAN across dual underlays (DIA + Metro Ethernet/WL) for application SLOs, packet duplication/FEC for voice/video, Anycast ingress.
    /sd-wan

Cloud & colo interconnect

  • Dual Direct Connect / ExpressRoute / Interconnect POPs; BGP policy/communities; private endpoints in cloud landing zones.
    /direct-connect/colocation

Security & identity

  • MACsec on metro uplinks; ZTNA for admin/console access; NAC 802.1X at campus edges; SASE for web/SaaS.
    /ztna/nac/sase

Evidence & operations


🧰 Service Catalog (what we design & run)

1) Wavelength Services (10/25/40/50/100/200/400G) — protected ROADM rings/mesh, jumbo MTU, fixed FEC, optional L1 crypto.
2) Dark Fiber (IRU/lease) — strand pairs you light; full control over optics, spectrum, and encryption.
3) Carrier EthernetEPL, EVPL, E-LAN, E-Tree; MEF-aligned CoS and OAM.
4) Metro IP/MPLS / SR — L3 VPNs with FRR/TE; Anycast services; DDoS options on Internet edges.
5) Cloud Interconnect — metro cross-connects and NNI to cloud on-ramps with BGP design and route policy.
6) EVPN/VXLAN Campus Extension — any-to-any L2 overlay when needed (with failure domain guardrails).
7) SD-WAN Overlay — per-app SLOs, packet duplication/FEC, breakout strategy, and Anycast ingress for UC/CCaaS.
8) Security — MACsec keys, ZTNA for admin, ACL/SGTs, microseg for crown-jewel VRFs; WAF/Bot at public edges.
9) Ops & Evidence — acceptance suites, monitoring, QBR packs, RCAs, and savings (TEM) where transport is optimized.


📊 Transport & Use-Case Matrix

TechnologySpeedsTypical Latency (metro one-way)Best ForNotes
Wavelength (DWDM)10/25/40/50/100/200/400G≤ 1–2 msDCI, storage (NVMe-oF), AI fabrics, mediaJumbo MTU; coherent optics; L1 crypto optional
Dark FiberYou choose≤ 1–2 msFull control, hyperscale AI, bespoke TERequires optics/ROADM; diversity critical
EPL (L2 P2P)1–100G≤ 1–3 msL2 private line, storage, voice backhaulVLAN-transparent; dedicated path
EVPL (L2 Hub/Spoke)1–10G (typ.)≤ 1–3 msMulti-site spokes, service multiplexingMultiple EVCs per UNI
E-LAN (L2 Any-to-Any)1–100G≤ 1–3 msMulti-campus L2 domainsControl failure domains carefully
IP/MPLS / SR1G–400G≤ 1–5 msL3 VPNs, Anycast servicesFRR/TE; Internet/DDoS edge ready
SD-WAN OverlayPer underlayAdds ≤ 5–10 msApp-aware SLOs, brownout steerPacket dup/FEC for real-time apps

🛡️ Security & Trust (baked in)

  • MACsec/L1 cryptoon private transport; TLS/IPsec for targeted flows; DDoS posture on Internet edges.
  • Segmentationwith EVPN/VXLAN, VRFs, ACL/SGT; crown-jewel isolation.
  • Admin accessvia ZTNA, not flat VPNs; device posture checks; PAM JIT for privileged sessions.
  • Policy-as-codeand config drift watch to keep the binder == build.
    /ztna/pam/siem-soar

📐 SLO Guardrails (targets you can tune)

DomainKPI / SLO (p95 unless noted)Target (Metro)
Optical spanProtection switch time< 50 ms
Wavelength/EPL one-way latencyMetro≤ 1–2 ms
EVPL/E-LAN L2 lossSustained< 0.05%
IP/MPLS jitterOne-way≤ 1–3 ms
SD-WAN brownout steerPath change≤ 1–3 s
MACsec coverageProtected uplinks= 100% (as scoped)
Cloud on-ramp attachMetro→region edge≤ 2–5 ms
AvailabilityMonthly≥ 99.99% protected core
Evidence pipelineTest/artifact → SIEM≤ 60–120 s
Unapproved changesPolicy gate= 0

Breaches open a case and trigger SOAR (reroute, enable packet-dup, adjust TE, rotate keys, roll back config) with artifacts. → /siem-soar


🔁 Topology Patterns (pick your fit)

PatternProsConsiderationsTypical Use
Ring (ROADM)Fast <50 ms protection, efficient fiberShared risk on adjacent spans3–8 site metro loops
MeshMultiple disjoint paths, high resilienceCost/complexityCore DCI across city
Hub-and-SpokeSimple ops, clear controlHub dependencyBranches ↔ DC/Cloud
Dual-Hub AnycastResilient ingress, easy SD-WANRequires Anycast designUC/CCaaS, Internet edges

📦 QoS Classes (metro quick table)

ClassTrafficMetro Target
EFRTP/voice, critical controlJitter ≤ 1 ms, loss < 0.05%
AF31/41Signaling, prioritized appsJitter ≤ 2–3 ms
BEBulk/backupBest effort; schedule windows

Mark at source, trust at edge, verify end-to-end over MAN and SD-WAN.


🧪 Acceptance Tests & Artifacts (we keep the receipts)

  • Optical— OTDR traces (distance, splice/connector loss), Rx/Tx light levels, BER/FEC counters, ROADM maps.
  • Service activationRFC 2544/Y.1564 throughput, latency, jitter, frame loss; CoS verification.
  • Security— MACsec enablement logs, ZTNA admin admits, ACL/SGT policy tests, WAF/Bot events at Internet edges.
  • Routing— BGP/OSPF/SR policies, Anycast failover tests, FRR timing; cloud on-ramp reachability proofs.
  • SD-WAN— brownout steer and packet-dup/FEC effectiveness; policy diffs.
    All artifacts stream to /siem-soar and bundle into QBR/audit packs.

🧱 Design Notes & Best Practices

  • Diversity matters— separate laterals, providers, bridges/tunnels; request diversity letters and validate with as-builts.
  • Bound your L2 domains— prefer routed access and EVPN/VXLAN boundaries; avoid spanning tree across the metro.
  • Jumbo MTU— align end-to-end for storage/AI movers; test fragmentation behavior.
  • MACsec at edges— especially for PHI/CUI/PCI or multi-tenant routes.
  • Anycast edges— improve ingress for UC/CCaaS and APIs; health-gated withdraw.
  • Policy-as-code— configs in Git with lint/tests; drift watchers; golden builds per device role.

📝 MAN Intake (copy-paste & fill)

  • Sites & addresses(HQ/campuses/DCs/colos/on-ramps) + target RFS
  • Transport preferences(Wavelength speeds, Dark vs Lit, EPL/EVPL/E-LAN, IP/MPLS)
  • Topology goal(ring/mesh/hub-spoke) + diversity requirements (laterals/POPs/providers)
  • Cloud(DX/ER/Interconnect POPs, regions, Private Endpoints only?)
  • QoS & MTU(EF/AF classes, jumbo needs, packet-dup/FEC)
  • Security(MACsec scope, ZTNA admin, ACL/SGT, WAF/DDoS posture)
  • Operations(managed vs co-managed, SIEM destination, change windows)
  • Compliance overlays(HIPAA/PCI/NIST/CJIS/etc.) & artifact retention
  • Budget & timeline(ROM vs build-ready), success metrics (latency, availability, cost)

We’ll return a design-to-quote with carrier options, optical/packet designs, SLO-mapped pricing, acceptance plan, and an evidence pipeline you can reuse in audits and QBRs.
Or jump to /customized-quotes.


📞 Build a MAN That’s Fast, Resilient, and Auditable

From campuses and colos to cloud on-ramps and edge sites, we’ll deliver the metro fabric your business can measure, trust, and prove.

Key terms in plain language

Open a term for a concise explanation of language used on this page.

Fiber Internet

Internet delivered through strands of glass using light. Fiber commonly supports high capacity, low latency, and strong upload performance, but availability must be confirmed for the exact address.

Latency

The time it takes data to travel between two points. Lower latency improves voice, video meetings, cloud applications, gaming, and other real-time services.

Dedicated Internet Access (DIA)

A business-grade Internet connection with capacity dedicated to the customer rather than shared in the same way as typical consumer broadband. It often includes symmetrical speeds and an SLA.

SD-WAN

Software-defined wide area networking. It manages multiple connections and chooses paths based on application needs, performance, and policy to improve resilience and control.

MPLS

Multiprotocol Label Switching, a private-network technology that directs traffic along managed paths. Organizations use it for predictable connectivity between locations.

VPN

A virtual private network creates an encrypted connection across another network, commonly allowing remote users or offices to access private resources securely.

Software as a Service (SaaS)

Software accessed as an online service instead of being installed and maintained entirely on the customer’s own computers or servers.

Zero Trust

A security model that does not automatically trust a user or device because of its location. Access is continuously verified and limited to what is necessary.