40m motor yacht — network & compute refit.
A vessel whose connectivity and onboard servers had grown by accretion, being rebuilt into a redundant, segmented, documented system — scheduled around the charter season.
The brief
The vessel arrived with the classic accumulation problem: connectivity and IT that had been extended by different hands over the years, a single firewall carrying everything, and onboard servers running on an ageing VMware host. Everything mostly worked — and nobody aboard could say exactly how, or what would happen if any one piece failed during a charter.
The requirement was straightforward to state and demanding to deliver: no single point of failure at the network edge, a supported virtualisation platform for the onboard servers, clean separation between bridge, crew, guest and technical traffic, and documentation good enough that the crew could operate the system without phoning ashore.
The engineering
At the edge, the design puts a pair of FortiGate 121G firewalls in active-passive high availability. Either unit can carry the vessel alone; if the active unit fails, the standby takes over in seconds with sessions preserved. The vessel’s three uplinks — VSAT, Starlink and cellular — terminate into the pair with policy-based routing, so traffic classes fail over between links automatically according to priority and cost rather than waiting for someone to notice.
The onboard servers are moving from VMware ESXi to Microsoft Hyper-V — planned around licensing direction as much as technology — with each workload moved, verified and load-tested in sequence. Backup and recovery are rebuilt alongside, and the recovery procedure gets tested rather than assumed: a timed restore drill, with the results going into the handover pack.
The flat network gives way to five segments — bridge, crew, guest, AV and CCTV — each on its own VLAN with explicit firewall policy between them. Charter guests get fast, isolated internet; navigation and vessel systems are unreachable from anything guest-facing; cameras record on their own segment.
The outcome, by design
Commissioned, the vessel loses a firewall — or an uplink — and carries on, every failure path exercised deliberately rather than just diagrammed. The crew take handover with as-built topology drawings, labelled patching and failover runbooks written for the people who actually stand watch; support then continues remotely, scheduled around the charter calendar.
Systems installed
Vessel and owner identities are withheld. A reference can be arranged privately on request.
Similar vessel, similar symptoms?
Start with an audit — a written report on what’s solid, what’s a risk, and what fixing it costs.