Project Background

Hospital Core Network Transformation

The hospital’s legacy network infrastructure could no longer meet the demands of modern medical information systems. The goal of this project was to design and implement a future-ready data centre network that would support critical hospital applications such as Electronic Medical Records (EMR), mobile ward rounds, surgical video recording, and large-scale medical imaging systems (PACS/RIS).

Before
After

Core Network Architecture

The internal network was built using a three-tier hierarchical design—core, aggregation, and access layers—to isolate fault domains and streamline management.

Core Layer – FabricPath Technology

To overcome the limitations of traditional Spanning Tree Protocol (STP), the core network deployed Cisco FabricPath (or equivalent).

Benefits:

  • Eliminates STP blocking, enabling full link utilization (ECMP).
  • Achieves low-latency Layer 2 switching through shortest-path bridging.
  • Enhances bandwidth efficiency and network convergence speed.

Aggregation Layer – vPC+ Virtualization

At the aggregation layer, vPC+ (Virtual Port Channel) technology was used to virtualize two physical switches into one logical unit.

Advantages:

  • Active/Active dual-homing for efficient load balancing.
  • Device and link redundancy to prevent single-point failures.

Internet Gateway & Security Architecture

VSS-based Core Virtualization

The Internet core adopted VSS (Virtual Switching System) to merge two switches into a single logical system, simplifying routing, increasing capacity, and ensuring redundancy for external connectivity.

Multi-ISP Design

Three firewalls connected to different ISPs ensure reliable Internet access. Policy-based routing (PBR) dynamically distributes traffic based on link performance and business priorities.

Comprehensive Security Framework

The hospital’s network security was built around six dimensions:

  • Device Security
  • Identity Authentication & Authorization
  • Boundary Protection (Firewalls with Active/Active HA)
  • Data Confidentiality & Integrity
  • Security Monitoring
  • Centralized Policy Management

Additional measures such as Control Plane Policing (CoPP) and Port Security were deployed to defend against DDoS and unauthorized device access.

Quality of Service (QoS) & Fiber Infrastructure

QoS Design

To ensure optimal performance for mission-critical applications:

  • Highest Priority: Voice and real-time video (LLQ – Low Latency Queuing).
  • High Priority: EMR, PACS, and other clinical systems.
  • Medium/Low Priority: General data and non-urgent traffic.

    All other traffic is managed using CBWFQ (Class-Based Weighted Fair Queuing) for fair bandwidth allocation.

Fiber Backbone

A multi-tier fiber deployment supports high-speed, resilient connectivity:

  • 32-core single-mode fiber: Between main data centres.
  • 24-core single-mode fiber: Between building aggregation and core rooms.
  • 24-core multi-mode fiber: Vertical links within buildings.

This layered optical backbone ensures 10G+ readiness for future expansion.

Outcome

The upgraded network now serves as a high-performance, secure, and scalable platform that fully supports the hospital’s digital transformation, enabling intelligent healthcare services for years to come.