WESTERN GOVERNORS UNIVERSITY
E031 - BSCNE Azure Capstone
Task 3: Post-Implementation Final Project Report
PROJECT TITLE Secure Hybrid Network Modernization Using VyOS and Microsoft Azure
STUDENT [Student Name]
STUDENT ID [Student ID]
PROGRAM Bachelor of Science, Cloud and Network Engineering (BSCNE)
SUBMISSION DATE August 7, 2026
Submission integrity note. This report used a coherent simulated client and lab design. Before submission, the student needed to
replace bracketed identity fields and reconcile every verification value and figure reference with the student’s own Task 1 proposal and
Task 2 evidence. No pass outcome could be guaranteed.
E031 (ITCL 4203) | Post-Implementation Final Project Report Page 1
, Document Control and Executive Abstract
Document control
Item Final record
Report status Post-implementation / completed-state narrative
Architecture baseline VyOS multi-zone edge integrated with an Azure virtual network
Evidence basis Task 2 configuration captures, tunnel status, routing outputs, firewall counters, and connectivity
tests
Required student action Replace bracketed fields and verify metrics against original screenshots before submission
Executive abstract
The organization had completed a secure hybrid-cloud modernization that connected its simulated on-premises
environment to Microsoft Azure. The completed design had replaced a flat, difficult-to-recover network with segmented
user, server, guest, and management zones. A VyOS edge router had provided 802.1Q subinterfaces, stateful zone-based
filtering, network address translation, routing, and the on-premises endpoint for an IPsec/IKEv2 site-to-site connection.
Azure resources had been deployed inside a dedicated virtual network with separate application, data, and gateway
subnets.
The implemented controls had reduced the blast radius of endpoint compromise, restricted administrative access,
protected cross-premises traffic, and created an off-site location for resilient workloads. Verification had included interface
inspection, effective route validation, firewall rule and counter review, tunnel-state inspection, allowed-path tests,
denied-path tests, and repeated reachability measurements. The resulting evidence had shown that authorized business
flows succeeded while prohibited inter-zone traffic was dropped.
The project had met its primary technical and operational objectives within the realized six-week schedule. The final
environment had remained a lab-scale implementation, so production adoption had still required formal key custody,
availability engineering, capacity sizing, change control, and monitoring ownership. Those day-two controls had been
documented as operational recommendations rather than treated as unfinished deployment work.
E031 (ITCL 4203) | Post-Implementation Final Project Report Page 2
E031 - BSCNE Azure Capstone
Task 3: Post-Implementation Final Project Report
PROJECT TITLE Secure Hybrid Network Modernization Using VyOS and Microsoft Azure
STUDENT [Student Name]
STUDENT ID [Student ID]
PROGRAM Bachelor of Science, Cloud and Network Engineering (BSCNE)
SUBMISSION DATE August 7, 2026
Submission integrity note. This report used a coherent simulated client and lab design. Before submission, the student needed to
replace bracketed identity fields and reconcile every verification value and figure reference with the student’s own Task 1 proposal and
Task 2 evidence. No pass outcome could be guaranteed.
E031 (ITCL 4203) | Post-Implementation Final Project Report Page 1
, Document Control and Executive Abstract
Document control
Item Final record
Report status Post-implementation / completed-state narrative
Architecture baseline VyOS multi-zone edge integrated with an Azure virtual network
Evidence basis Task 2 configuration captures, tunnel status, routing outputs, firewall counters, and connectivity
tests
Required student action Replace bracketed fields and verify metrics against original screenshots before submission
Executive abstract
The organization had completed a secure hybrid-cloud modernization that connected its simulated on-premises
environment to Microsoft Azure. The completed design had replaced a flat, difficult-to-recover network with segmented
user, server, guest, and management zones. A VyOS edge router had provided 802.1Q subinterfaces, stateful zone-based
filtering, network address translation, routing, and the on-premises endpoint for an IPsec/IKEv2 site-to-site connection.
Azure resources had been deployed inside a dedicated virtual network with separate application, data, and gateway
subnets.
The implemented controls had reduced the blast radius of endpoint compromise, restricted administrative access,
protected cross-premises traffic, and created an off-site location for resilient workloads. Verification had included interface
inspection, effective route validation, firewall rule and counter review, tunnel-state inspection, allowed-path tests,
denied-path tests, and repeated reachability measurements. The resulting evidence had shown that authorized business
flows succeeded while prohibited inter-zone traffic was dropped.
The project had met its primary technical and operational objectives within the realized six-week schedule. The final
environment had remained a lab-scale implementation, so production adoption had still required formal key custody,
availability engineering, capacity sizing, change control, and monitoring ownership. Those day-two controls had been
documented as operational recommendations rather than treated as unfinished deployment work.
E031 (ITCL 4203) | Post-Implementation Final Project Report Page 2