Project Citrus Refresh
Orange Pod Networking Training Lab
A five-week, hands-on path from Layer 2 switch standards through routing, firewall policy, and site-to-site VPNs.
Project Citrus Refresh
A five-week, hands-on path from Layer 2 switch standards through routing, firewall policy, and site-to-site VPNs.
Orange and Peel began in 2008 when longtime friends Nora Orange and Peter Peel rented a small warehouse outside Grove. Their original business supplied fresh citrus and specialty ingredients to independent restaurants, bakeries, and neighborhood markets. Nora managed relationships with growers while Peter built a reputation for getting difficult orders delivered on time.
The company grew through personal service rather than sophisticated technology. Orders initially arrived by phone, inventory lived in spreadsheets, and the warehouse team could identify most customers by name. That approach worked well while everyone operated from one building.
By 2015, Orange and Peel had expanded beyond wholesale produce. The company began making bottled juices, dried fruit, preserves, and citrus-based flavoring products. Production remained at Grove, but new distribution sites were opened to shorten delivery times and support regional customers.
Today, Orange and Peel employs approximately 180 people across four locations. The company is still privately owned and takes pride in being friendly, practical, and quick to adapt. Unfortunately, its network has adapted a little too quickly.
Grove is the original location and remains the center of the company. It contains:
Most company-wide technology is operated from Grove. If Grove becomes unavailable, the branches can continue some local work, but many business services are affected.
Zest was the first branch office. It supports regional sales, product demonstrations, and customer training. Its employees rely heavily on voice, video meetings, and access to corporate applications hosted at Grove.
Zest frequently hosts customers and therefore needs dependable guest access that remains separated from corporate systems.
Juice is a busy distribution site with warehouse workstations, shipping stations, phones, handheld devices, and network-connected operational equipment. The site operates early and late shifts, so outages outside normal office hours can still interrupt the business.
The site is especially sensitive to poor documentation because visiting technicians may be asked to troubleshoot equipment without help from the person who installed it.
Pulp is the newest site. It contains offices, test kitchens, small production equipment, security devices, and temporary workspaces for visiting employees. The site changes frequently as equipment and projects move in and out.
Pulp needs a network that can accommodate change without sacrificing segmentation or supportability.
Each location was originally opened under time pressure. Switches were purchased when needed, local vendors made one-off changes, and documentation varied from site to site. Some settings are sensible, some are outdated, and some exist because “that was the only way it worked at the time.”
As the company grew, several recurring problems appeared:
No major incident triggered the current project. Leadership instead recognized that the company had reached the point where informal practices created unacceptable operational and security risk.
Orange and Peel has launched an internal modernization effort called Project Citrus Refresh. The project will standardize the network at all four sites while allowing the business to remain operational.
The project goals are to:
You are the Tier 1 technical team assigned to Project Citrus Refresh. Each technician owns one site throughout the project
Your responsibility is broader than making the equipment work. Every configuration must follow the standard, every change must be verifiable, and every site must be left in a state that another technician can support.
Over the coming weeks, you will:
Project Citrus Refresh is successful when the network works as designed, prohibited traffic fails for the intended reason, and the team can explain the complete traffic path from an endpoint at a branch to a service at headquarters.
Orange and Peel is beginning Project Citrus Refresh. The company has one headquarters at Grove and branch offices at Zest, Juice, and Pulp. Each location has received a spare switch that will eventually support employees, phones, guests, network management, and—in some locations—security equipment.
The switches were pulled from storage. Nobody is willing to guarantee what configuration is currently on them. Some may have old names, old VLANs, outdated management settings, or configuration left behind by a previous project.
Orange and Peel wants all four sites to follow the same switch standard. A technician visiting an unfamiliar site should be able to identify the switch, understand its port usage, manage it securely, and locate a usable backup without relying on the original installer.
At this stage, no firewall or router has been installed. The immediate goal is to create a safe, consistent Layer 2 foundation.
As a group, sketch one site and identify:
Do not write device commands yet. The purpose is to agree on what the network must accomplish and why.
Before implementation, list the details you would need from the network standard or project owner. Consider naming, VLANs, management addressing, authentication, monitoring, time, logging, trunking, STP, unused ports, backups, and approved software.
Orange and Peel is preparing four sites for deployment. Each technician has received a spare switch with an unknown or incomplete configuration. The switch must be brought into compliance with company standards before it can be installed.
By the end of the session, participants should be able to:
120 minutes
| Site | Switch FQDN | Netman network | Switch IP | Future gateway |
|---|---|---|---|---|
| Grove | sw1.grove.orangeandpeel.private | 10.11.220.0/24 | 10.11.220.5 | 10.11.220.1 |
| Zest | sw1.zest.orangeandpeel.private | 10.12.220.0/24 | 10.12.220.5 | 10.12.220.1 |
| Juice | sw1.juice.orangeandpeel.private | 10.13.220.0/24 | 10.13.220.5 | 10.13.220.1 |
| Pulp | sw1.pulp.orangeandpeel.private | 10.14.220.0/24 | 10.14.220.5 | 10.14.220.1 |
Use short scenarios instead of trivia questions. Mark each topic as comfortable, partial, or unfamiliar.
For each applicable company standard, cover the required setting, its purpose, and the verification method.
Do not place real production secrets in the lab configuration.
Participants should:
.5/24 in VLAN 220..1 in the Netman network.Each participant demonstrates:
Finish the standards-compliant Layer 2 configuration for your assigned site. The result must be understandable and supportable by another technician.
| VLAN | Name | Requirement |
|---|---|---|
| 10 | Corp | Create and assign at least two test access ports |
| 100 | Voice | Create and configure at least one Corp/Voice edge port |
| 220 | Netman | Create and use for switch management |
| 250 | Guest | Create and assign at least one test access port |
| 210 | Security | Configure only if assigned by the instructor |
.5/24 in the site's Netman network..1 as the future Netman gateway.Capture the platform-equivalent output showing:
Submit:
Do not include reusable credentials, private keys, or production secrets.
Another technician should be able to audit the switch, identify every connected device, and restore the switch from the submitted documentation.