IT‑IS Networking
Technology › Security Architecture

Multi-Tenant Isolation

Six independently governed agencies on shared infrastructure, none able to reach, disrupt or inherit the regulatory exposure of any other.

Also known as Multi-VSYS, Virtual Systems, Tenant Isolation

Architected the enterprise Palo Alto Networks firewall platform as a hard multi-tenant boundary between the city, the Clerk of Courts, the Public Defender, the public library system, the Sheriff’s Office and the municipal utility — each carrying its own virtual system, routing domain, DMZ and security policy on shared physical infrastructure and shared, diversely routed internet egress. One tenant extended across multiple counties.

The design goal was that no agency could reach, disrupt or inherit the regulatory exposure of any other, while each kept the autonomy its independently elected leadership required. Twenty-six revisions of the design document over its life.

Palo Alto Networks asked more than once to publish it as a vendor white paper. The answer was no every time. The architecture is public-safety facing, and a published diagram of how a sheriff’s office and a court system are isolated from one another is a gift to somebody.