Network and service-provider engineering
BGP, routing policy, peering, transit, RPKI, IPv4/IPv6, IS-IS, OSPF, MPLS, EVPN/VXLAN, incident analysis and the operational design around them.
NETWORK / INFRASTRUCTURE / ROLLOUTS / TEACHING
From BGP policy to the switch port that is actually flapping.
At 21:00, it was clear that another remote call would not rescue a factory network rollout in northern Czechia.
At 02:00, I was on a bus to the airport. By early afternoon, after Helsinki, Paris, Prague and a train north, I was on site.
Roughly 3,000 kilometres after making the decision, we solved the problem.
01 / WHAT I DO
I am usually brought in when the problem spans more than one supplier, one technical layer or one team. Sometimes the right answer is architecture. Sometimes it is a console cable and another look at the link state.
BGP, routing policy, peering, transit, RPKI, IPv4/IPv6, IS-IS, OSPF, MPLS, EVPN/VXLAN, incident analysis and the operational design around them.
Bitstream access, FTTH, DSL, carrier Ethernet, leased lines, CPE, address resources, last-mile migrations and the service models around access products.
Planning, staging, supplier coordination, travel, on-site delivery, acceptance testing and handover for offices, factories, datacenters and multi-site environments.
Switching, VLANs, PoE, wireless, structured cabling, installation and troubleshooting from the physical link upward. I am not afraid of the part that needs hands.
Linux and BSD, virtualisation, storage, monitoring, identity, datacenter platforms, migrations and technical recovery when “it must be the network” has stopped helping.
Product and service workflows, data models, APIs, inventory, provisioning states and operational tooling built around how a provider actually works.
02 / FIELD NOTES
FIELD NOTE 01 / INDUSTRIAL ROLLOUT
A new industrial site was being brought online. The local team was struggling with the network fabric, and remote assistance was no longer moving the rollout forward.
I decided at 21:00 that the next useful step was to be there. A bus at 02:00, two flights and a train later, I reached the site the following afternoon and worked directly with the team. By the time my colleagues in Turku expected me at the office, I was calling them from Paris.
Result: the issue was resolved, the rollout moved again, and the factory could continue towards production.
FIELD NOTE 02 / OFFICE NETWORK
A customer called on Friday. Around 100 SAP consultants were due to move into a new office on Monday. The Wi-Fi was unstable, and there was no useful wired fallback.
The access points worked during testing, then failed after installation. Replacement hardware behaved the same way. Vendor support focused on firewall rules. The useful clue was lower down the stack: PoE remained available while the Ethernet link cycled between down and a negotiated 2.5 Gbit connection.
I changed the Dell PoE switch so that the affected ports advertised only 10, 100 and 1,000 Mbit during link negotiation.
Result: the site became stable.
03 / WAYS TO WORK WITH ME
I work alongside existing technical teams, suppliers and local hands. Each engagement has a scope, a commercial agreement, an outcome and a handover.
01
02
03
04
When an agreed engagement genuinely needs somebody on site, I can often move quickly within Europe.
I do not operate a general end-user support desk or sell unrestricted 24/7 availability.
New work normally begins with paid discovery or a prepaid engineering block. Travel and non-refundable external costs are agreed before booking.
I am not positioned as low-cost field labour. Clients bring me in when delay, another failed attempt or the wrong technical decision costs more than senior expertise.
04 / PROVISIONING PLATFORM
I originally studied application development before changing direction and qualifying in systems engineering. Today I use coding assistants to accelerate implementation, while keeping the architecture, framework choices, data model, integrations and operational workflows under my own direction.
One result is a working provisioning platform designed as a foundation for an OSS/BSS environment. It applies service-provider knowledge built over more than two decades to the software that has to represent products, resources, orders, services and actual network state.
The assistant accelerates code. It does not decide what an access product, address resource, provisioning state or operational handover means.
Framework-aware development around real provider processes, not a generic CRUD demo with telecom labels.
05 / SELECTED WORK
Seventeen years across backbone routing, peering, transit, access products, addressing, datacenters, monitoring, migrations, provisioning, suppliers and customer escalations.
Hands-on and advisory work in offices, factories, datacenters and multi-site environments, from southern France to northern Norway and from Central Europe to Sicily, plus intercontinental assignments.
A non-commercial routing project giving students, enthusiasts and emerging networks practical access to BGP and real Internet resources.
Project siteWorked with the exercise and industry-partner teams on infrastructure, local model-serving systems and operations in 2025.
Operated local inference and model-serving infrastructure for challenge environments and contributed extensively to adversarial testing.
SwiNOG materialProvided a small amount of production-routing and infrastructure support to research acknowledged in an ACM IMC 2025 paper.
Paper
LOCKED SHIELDS 2025 / TALLINN / EXERCISE AND INDUSTRY-PARTNER WORK
06 / SECURITY IN PRACTICE
My security work grows out of infrastructure: understand how the system actually runs, how people depend on it, and where the assumptions stop holding.
That includes routing security, incident analysis, secure infrastructure, cyber-defence exercise work, local AI systems and adversarial testing.
07 / ABOUT
For 17 years I built and operated an ISP and related infrastructure businesses. That meant owning the outcome across routing, access networks, systems, datacenters, suppliers, customer platforms, field work, incidents and the software around them.
I now apply that experience through a smaller independent practice, taking on selected consulting, rollout, teaching and development assignments. Commercial engagements are handled through Openfactory Nordic Oy under the Institute for Pyrotechnical Cleaning name.
I began in application development, changed direction into systems engineering, completed the Swiss federal qualification in computer science, and later taught in Swiss professional and higher technical IT education. I have also worked around startups, Internet exchanges, network-operator communities, international public-sector infrastructure and large multinational enterprises.
Community work includes FREETRANSIT, Internet-exchange involvement, years in the RIPE and hacker communities, and service as a board member of TurkuSec ry.
08 / PUBLIC RECORD
Operator, security and hacker communities have been part of my working life for a long time. The chronology below links the talks, workshops, writing, projects and events that left a public trace.
SELECTED PUBLIC WORK
My public work ranges from BGP workshops and Internet exchanges to production routing incidents, routing security, homelabs and local AI. The chronology also includes the communities around that work.
Routing-security practice from the operator side: what is deployable now, what is changing, and where the gaps still are.
Programme ↗An operator reading of an ambitious protocol proposal, with rather more questions about deployment and operations than about the slideware.
Read at RIPE Labs ↗Followed the measurement and routing sessions and asked a few practical operator questions around RPKI data and ASPA. A couple of people joining remotely recognised the voice afterwards.
EVENTS FOSDEM · Brussels · Disobey · Helsinki · Netnod Meeting · Stockholm · Easterhegg · Koblenz · RIPE 92 · Edinburgh · nog.fi · Tampere
Worked with the exercise and industry-partner teams on infrastructure, local model-serving systems and operations.
Provided a small amount of production-routing and infrastructure support to an Internet-measurement project, acknowledged in the resulting ACM IMC 2025 paper.
Paper ↗A practical local GenAI stack: model serving, self-hosting, hardware constraints and an adversarial challenge environment.
Operated the self-hosted model-serving platform used for the challenge environment and contributed extensively to adversarial testing.
Easterhegg 2025 ↗Two pieces on adversarial testing and on keeping some deliberate distance from constant AI use.
Hands-on adversarial testing around the local challenge platform.
EVENTS Disobey · Helsinki · Easterhegg · Hamburg · WHY2025 · Netherlands · DENOG17 · Essen · BalCCon · Novi Sad · 39C3 · Hamburg
Operator-community discussions, hallway conversations and the usual working-group sessions.
Meeting ↗A practical talk about building a home lab, using it to experiment with real systems, and why more people should learn by running and breaking their own infrastructure.
Event recap ↗EVENTS Disobey · Helsinki · Disarray · Baltic Sea · DENOG16 · Berlin · BalCCon · Novi Sad · 38C3 · Hamburg
Using exchange-point software in a service-provider network, with the compromises and operational lessons that come with doing that for real.
Programme ↗A real route leak, how we got there, what it did, and what changed afterwards.
A production routing incident, an AS-SET that did not behave as expected, and the post-mortem.
EVENTS RIPE 86 · Rotterdam · RIPE 87 · Rome · Disobey · Helsinki · Easterhegg · Hamburg · DENOG15 · Berlin · Chaos Communication Camp · Mildenberg · 37C3 · Hamburg
Ran the camp IXP at MCH2022 using IXP Manager. The exchange brought together several community networks, including AS41666 and FREETRANSIT / AS41051.
MCH2022 IXP wiki ↗Operational networking stories from the provider side.
nog.fi meeting ↗A hands-on evening around the information an operator can pull together from an IP address or network: RIR data, BGP, traceroutes, reverse DNS, WHOIS and the surrounding infrastructure.
Hosted a small practical workshop with TurkuSec, building WireGuard setups on MikroTik hardware instead of stopping at a slide deck.
EVENTS MCH2022 · Netherlands · TurkuSec · Turku · BalCCon · Novi Sad
Stood for the RIPE NCC Executive Board with a focus on operator experience, education and bringing more people into the networking community.
EVENTS FOSDEM · Brussels · Disobey · Helsinki
Helped run a hands-on Tranalyzer traffic-mining workshop at the TurkuSec lab, working directly with captured traffic and analysis tooling.
Tranalyzer workshop archive ↗EVENTS Disobey · Helsinki · TurkuSec · Turku · Easterhegg · Vienna · GPN19 · Karlsruhe · BalCCon · Novi Sad · DENOG11 · Hamburg · Chaos Communication Camp · Mildenberg · 36C3 · Leipzig
EVENTS FOSDEM · Brussels · Disobey · Helsinki · Easterhegg · Würzburg · BalCCon · Novi Sad · 35C3 · Leipzig
/31 point-to-point networks, sixteen years after the RFC already said we could stop wasting two addresses per link.
Slides ↗EVENTS BalCCon · Novi Sad · 33C3 · Hamburg
EVENTS RIPE SEE 4 · Belgrade · Chaos Communication Camp · Mildenberg · BalCCon · Novi Sad · 32C3 · Hamburg
EVENTS BalCCon · Novi Sad · 31C3 · Hamburg
Worked as an Archangel during the event, helping keep the day-to-day operation of the Easter weekend moving.
Event ↗EVENTS Easterhegg · Basel · 29C3 · Hamburg
EVENTS RIPE 63 · Vienna · Chaos Communication Camp · Finowfurt · 28C3 · Berlin
Became active in the Swiss network-operator community while still early in my systems-engineering career.
09 / CONTACT
Tell me what is happening, what has already been tried, where the work is, who is already involved and what a useful outcome would look like.
I will tell you directly whether I am likely to be useful.
Discuss the workSend the event or organisation, date, audience, topic and CFP link where applicable.
I am quite capable of noticing a CFP shortly after it closes, so a direct nudge is welcome.
Send an invitationEngagements are contracted through Openfactory Nordic Oy, operating under the Institute for Pyrotechnical Cleaning name.