Gavilan Consulting Call (559) 507-2076

Networks, Servers & Cloud

The wiring, the Wi-Fi, the firewall, the server and the Microsoft 365 accounts are one system, not five separate ones. We design it, install it, and keep watch over it — on site across California's Central Valley, and remotely across the entire United States.

The Foundation

Almost Every “Computer Problem” Is A Network Problem

The complaints that reach us rarely sound like network complaints. The accounting software is slow. The label printer keeps going offline. Outlook asks for the password again. Someone in the back office says the internet “drops”, but only in the afternoon, and only for them. Four different symptoms, four different people blaming four different things — and one cause underneath, usually a network that was assembled a piece at a time and never designed.

That is what this page is about. Not products, but the connective tissue: the cable in the wall, the box that decides what is allowed in from the internet, the place your files live, the accounts your staff sign in with, and the mail that has to arrive. Get that layer right and most of the day-to-day noise simply stops. Get it wrong and you pay for it steadily, in small interruptions that nobody ever adds up.

We work in plain language. If something we recommend cannot be explained in a sentence that makes sense to the person signing the check, it is either the wrong recommendation or we have not thought about it hard enough yet.

Coverage

Wired And Wireless Networks That Reach The Whole Building

A network is not one box. It is a chain, and the whole chain performs like its weakest link — which is very often the free box the internet company left behind.

Why The Router Your ISP Supplied Usually Is Not Enough

The unit the internet provider installs is four devices squeezed into one small plastic case: the modem that terminates their line, a router, a wireless radio, and a small four-port switch. It was chosen because it is cheap to give away, and it was designed for a house — a couple of laptops, a television, a phone or two.

Put it in a business and the seams show quickly. There are ports for four wired devices, and the office has more machines than that before anyone counts the printer. The wireless was built to cover a living room, not an office with a break room, a warehouse and a metal roof. It cannot separate one kind of traffic from another, so the guest streaming video and the workstation running your practice software are treated as equals. Its firmware is updated when the provider gets round to it, which is not a schedule you control. And when it does misbehave, the support path is the same phone queue you already dread.

The fix is not dramatic. Keep the provider's box doing the one job it is good at — delivering the internet connection — and put a proper firewall and router behind it, a switch with enough ports for the building you actually have, cabling run to where people actually sit, and wireless access points positioned by walking the site rather than by guessing from the closet.

Switches, Cabling And The Faults Nobody Can Find

Cable is the least glamorous part of this work and the most common source of the faults that survive three visits from someone else. A run that is too long, kinked behind a filing cabinet, terminated in a hurry, or sharing a conduit with fluorescent lighting does not fail cleanly. It works, mostly. It slows down under load. It drops one machine, at odd times, in a way that always looks like the machine's fault. Intermittent is far harder to chase than broken, which is why we test and label runs rather than assume them.

The switch matters too, and not for the reason people expect. Ports are the obvious part; the useful part is that a managed switch can be asked questions — which port is saturated, which one is flapping, which device just appeared on your network that nobody recognizes. A network you cannot ask questions of is a network you can only guess about.

Wi-Fi That Hands Off Instead Of Dropping

When wireless does not reach the far end of a building, the instinct is to turn the power up on the one access point. It does not work, and the reason is worth knowing: a laptop at the far corner can then hear the access point, so it stays connected and refuses to look for anything better — but the little radio in the laptop is not strong enough to be heard talking back. You get full bars and nothing loading, which is the most infuriating failure mode there is.

Real coverage comes from several access points, each turned down rather than up, placed so their areas overlap slightly, and set to channels that are not fighting each other or the office next door. Configured that way, a phone carried from the front desk to the stockroom moves from one access point to the next without the call or the scanner session noticing.

Separation

Guest Wi-Fi That Is Actually Separate

In most small offices we walk into, there is one wireless password. Staff use it. Visitors are given it. The delivery driver has it. The contractor who came in eighteen months ago still has it, and so does the person who left last spring, because their phone rejoins automatically every time they walk past. It is written on a whiteboard in the break room and it has not changed since it was set up.

The password is not the real problem. The real problem is what being on that network lets a device do. Once connected, a visitor's laptop is inside your building's network exactly like your own machines — it can see the file server, the printers, the cameras, the point-of-sale terminal, the network drive with the payroll folder on it. Nobody has to be malicious for that to hurt. A phone or laptop that picked up something nasty somewhere else does the damage on its owner's behalf, quietly, without them ever knowing they brought it in.

A guest network fixes it, and it is one of the cheapest improvements available because it costs nothing but the time to configure it properly. Guests get their own wireless name and their own password, on a segment that can reach the internet and nothing else. They can look things up, send mail and get on with their visit. They cannot see a single one of your business devices, because as far as your network is concerned they are not on it.

The Same Logic Applies Inside

Guests are the obvious case, but the principle is broader. Security cameras, door controllers, smart televisions, thermostats and the machinery on a shop floor all benefit from sitting on their own segment rather than alongside the accounts department. These devices are notoriously slow to receive security updates and they rarely need to talk to anything except their own controller. Separating them is configuration work, not new hardware.

The Front Door

Firewalls And Remote Access Done Safely

A firewall's job, in one sentence: decide what is allowed in from the internet, what is allowed out, and refuse everything else. What matters is not the brand on the box. It is whether anyone has looked at the rules since the day it was installed.

The Shortcut That Lets Ransomware In

Somebody needs to work from home. The quick way to arrange that is to “open a port” on the firewall and forward Remote Desktop straight through to a machine in the office. It is a couple of clicks, it works immediately, and that is exactly why it is everywhere.

Here is what it actually does. That computer's login screen is now published on the public internet. Automated scanners sweep the entire internet address space continuously, looking for precisely that, and they will find it — not because anyone targeted your business, but because they are looking at everybody. From the moment it is found, an unattended password-guessing contest runs against your office around the clock, at machine speed, for as long as the port stays open. One staff member who reused a password from a site that was breached years ago ends the contest. This is one of the most common ways ransomware gets into a small business, and it is almost always a convenience someone set up in good faith.

What To Do Instead: A VPN

A VPN — a virtual private network — is an encrypted tunnel between the person outside and the office. The important part is the order of operations. You prove who you are to the tunnel first; only then does anything inside the office become reachable at all. Nothing on your network is published to the internet, so those automated scanners find nothing to hammer at. There is no login screen sitting outside for them to guess against.

Add a second factor — a code from a phone, or a prompt to approve — and a stolen password on its own stops being enough to get in. That single change closes off the majority of the break-in attempts a small business will ever face.

None of this makes remote work harder for the person doing it. Once it is set up, they click connect and everything is where it was.

On Premises

Servers — What They Are Still For, And When You Do Not Need One

We will tell you when a server is the right answer. We will also tell you when the one humming in your closet is no longer earning its keep, which is not a sentence that costs us nothing to say.

When A Server Still Makes Sense

Your industry software requires one. Dental, medical, legal, veterinary, manufacturing, property management and accounting packages frequently run on a server in the building, and the vendor supports it that way and no other. That decision is often made for you.

You move genuinely large files — design work, video, engineering drawings, high-resolution imaging. Opening a two-gigabyte file across the room is a different experience from opening it across an internet connection, and no amount of enthusiasm about the cloud changes the physics.

You have an obligation about where data physically sits, or you need the business to keep working through an internet outage rather than stopping with it.

When You Honestly Do Not Need One

If the server in your closet holds shared folders, handles logins and drives the printers — and your staff are already working in Microsoft 365 — there is a fair chance you are paying to power, cool, patch, back up, license and eventually replace a machine whose whole remaining job is a shared folder.

Retiring it is not the right answer for everyone and it is never a decision to make on a slogan. But it deserves an honest look, and the right time to have that conversation is before the hardware forces one by failing.

Where the answer is to keep the server, the details do the work: enough memory, drives arranged so a single failure does not stop the day, an uninterruptible power supply so a Central Valley summer brownout does not take it down mid-write, and a backup that somebody has actually tested by restoring from it.

A Server Without A Tested Backup Is A Single Point Of Failure

The most expensive assumption in small business IT is that a backup which appears to be running is a backup you can restore from. Encrypted on-site and off-site backup, disaster recovery planning and the restore testing that proves any of it works are covered under data recovery, backup and forensics — and if you take one thing from this page, take that one.

Cloud

Microsoft 365 — Mail, Files, Accounts And Calendars

In plain terms: your company's email, the documents everybody shares, the calendars, and the list of who works here — held in Microsoft's data centers so they are reachable from a desk, a laptop at home or a phone in a truck, and so that losing the laptop does not mean losing the work.

Migrating From An Old Mail Host

The fear with any mail migration is the same everywhere: we will lose mail, or we will be down for a day. Neither has to happen, and the reason is that the copying and the switching are separate steps.

Mailboxes are copied across first, in the background, while the old system carries on receiving mail exactly as it did yesterday. Folder structure, calendars and contacts come with them — people find their own filing where they left it, which matters more to daily comfort than anyone admits. Only once the copy is complete does the domain's mail record change to point at the new home. A second pass then sweeps up anything that arrived at the old host after the first copy began, so the gap closes rather than leaves a hole. The visible part for staff is signing in again on their computers and phones.

Migrations from a website host's bundled mail, from an old on-site mail server, or from a mailbox that has been forwarded through three generations of provider all follow the same shape. The messy ones are messy because of what is already there, not because of the destination — which is why we look before quoting.

The Account And License Housekeeping Nobody Enjoys

This is the tedious half of Microsoft 365 administration, and it is where most of the value hides. A tenant that has never been audited almost always turns up some version of the following.

  • Licenses being paid for every month against people who left the business, sometimes years ago.
  • Departed staff whose accounts still work — still able to sign in, still receiving mail, still holding access to shared files. A licensed mailbox for a leaver can usually become a shared mailbox instead, keeping the history available without keeping the login alive.
  • People on the wrong plan in both directions: someone paying for a plan they never use a feature of, and someone else missing the one thing their job actually needs.
  • An administrator account nobody can sign into, because the person who set it up is gone and the password went with them.
  • Multi-factor sign-in never switched on, which is the single largest gap on this list.
  • No record anywhere of who has access to what.

None of that is interesting work. All of it either saves money every month or closes a door that is standing open, and it is the kind of thing that only ever gets done when somebody makes it their job. Under a managed IT agreement it becomes routine rather than a project.

Deliverability

Business Email That Reaches The Inbox Instead Of The Junk Folder

You send a quote. The customer never sees it. A week later you find out you lost the job to somebody slower. Email that fails this way does not bounce and does not warn you — it is filed as junk, or accepted and quietly discarded, and the sender is told nothing at all.

Three small records published in your domain's DNS decide most of it. They are the most commonly missing piece we find, they cost nothing but the care to set them up correctly, and the large mail providers treat a domain that has none of them with more suspicion every year. Here is what each one is, without the acronym soup.

SPF — Who Is Allowed To Send As You

SPF is a short public list, published under your domain name, naming the mail systems that are permitted to send email claiming to be from you. When a receiving server takes delivery of a message that says it is from your business, it looks up that list and checks whether the server the message actually arrived from is on it. If it is not, the message looks forged — because usually it is.

The place this goes wrong in real businesses is that mail leaves from more places than anyone remembers. Microsoft 365 sends your day-to-day mail; the accounting package emails invoices; a newsletter tool sends the monthly update; the website's contact form sends notifications; the copier in the corner emails scans. If the list names only one of those, the rest look like impostors. Getting SPF right is mostly an inventory exercise: find everything that sends as you, then list it.

DKIM — A Seal That Proves It Was Not Altered

DKIM adds an invisible cryptographic signature to every message your mail system sends. The matching public key is published in your DNS, where any receiving server can fetch it. On arrival, that server recalculates the signature and compares. If it matches, two things are proven at once: the message genuinely came from a system holding your private signing key, and the contents were not tampered with along the way.

It complements SPF rather than duplicating it. SPF asks where a message came from, which is a question that stops making sense the moment mail is forwarded — a customer who forwards your quote to their partner sends it on from a server that was never on your list. The DKIM signature travels with the message and survives the trip.

DMARC — What Should Happen When The First Two Fail

DMARC is the instruction you publish telling receiving servers what to do with a message that claims to be from your domain but fails those checks: let it through anyway, put it in junk, or reject it outright. Without a DMARC record every receiving server decides for itself, and they do not agree with each other — which is why the same message lands in one customer's inbox and another's junk folder.

DMARC also asks those servers to send back reports, and that is the part worth having even before the enforcement. Those reports are the only way to see the full picture of who is sending mail using your business name, including the systems you had forgotten and the people pretending to be you. The sensible sequence is to start in reporting-only mode, read what comes back, fix the legitimate senders that are failing, and only then tighten to reject. Rushing straight to reject is how a business accidentally blocks its own invoices.

Reaching enforcement is what stops somebody spoofing your domain to send a convincing invoice to your own customers with their bank details on it. That scam is common, it is cheap to run, and the damage is done to your reputation rather than the criminal's.

Ownership

Domains And DNS

Your domain is your name on the internet. DNS is the public directory that turns that name into the addresses where your website and your mail actually live. It is small, boring and completely load-bearing: every record described above lives there, and so does the one that keeps your website reachable.

The problems we find are almost never technical. A domain registered years ago in a former employee's personal account. Renewal notices going to a mailbox nobody has opened since that person left. A business that does not know which registrar holds its own name until the day the website goes dark and everyone starts guessing. The website company that built the site also “handles the domain”, and the relationship has since gone cold.

The domain should be registered in the business's name, billed to the business, with someone in the business able to sign in. We move domains into an account you control, set the records correctly, document what each one is for, and leave you holding the keys. That last part is not optional — it is your name.

Voice

VoIP Phones

VoIP means your phone calls travel over the same internet connection as everything else instead of over separate telephone lines. The practical consequences are the interesting part: an extension works anywhere there is internet, so someone at home or at a second site is simply on the phone system; moving a desk means moving the handset; adding a person means adding a handset rather than ordering a line; and how calls flow — who rings, in what order, what happens after hours — becomes configuration instead of an engineer visit.

The catch nobody mentions at the point of sale is that VoIP is only ever as good as the network beneath it. Voice is unforgiving in a way that file transfers are not: a small hesitation that a download would absorb without anyone noticing turns a phone call choppy and clipped. So the network has to know to give voice priority over everything else, and the internet connection has to be one you can lean on.

That is exactly why phones and networks belong in the same conversation. We would far rather fix the network first than sell you a phone system that stutters and then argue about whose fault it is.

Watching

Monitoring, So You Hear It From Us First

Equipment almost never fails without warning. It complains first, in a log file nobody reads, on a device nobody looks at, in a closet nobody opens. Continuous monitoring of servers and network equipment is simply the practice of reading those complaints while they are still complaints.

What that looks like in practice: a drive in a server reporting read errors weeks before it gives up. A backup job that quietly stopped running after an update and has been reporting nothing ever since, which reads exactly like success. A switch running hot because something is blocking its vents. Free disk space sliding toward zero. A firewall whose security subscription lapsed at renewal. An access point that has been quietly restarting itself all night.

Every one of those is a small, cheap, scheduled job today. Left alone, several of them are a closed office next month. Monitoring is included in a managed IT agreement, along with maintenance, helpdesk and on-site visits for a flat monthly fee — and around-the-clock telephone support is an entitlement of those managed-services clients.

The Process

How A Network Project Runs

No surprises, no jargon, and nothing installed that you have not had explained to you in language you can repeat to your business partner.

  1. A Free First Conversation

    Call us, or send us the details in writing if that is easier. Tell us what is not working, or what you are trying to build. The initial consultation is free, and it is a conversation with a technician rather than a sales script.

  2. We Look At What Is Actually There

    Somebody opens the closet, traces the cabling, checks what the wireless really does at the far corner of the building, and finds out what is on the network that nobody recognizes. Recommendations made without this step are guesses.

  3. A Written Plan And A Quote

    What changes, why it changes, what it costs and what happens on the day. Every agreement is quoted per client after we have seen the environment, because no two buildings are the same.

  4. Installed With The Least Disruption We Can Manage

    Where the work allows it, the disruptive part happens outside your business hours. Where it does not, you know in advance which part of the day is affected and who it affects.

  5. Documented And Handed Over

    You receive the diagram, the labeled runs, the account details and the records of what was changed. It is your network. You should never need our permission to understand it.

  6. Looked After Afterwards

    Either under a managed IT agreement with monitoring and maintenance included, or on call when you need us. Both are real options and we will tell you which one fits.

Questions

Questions We Get Asked

Do we have to replace everything at once?

Almost never. Most of the work we do is sequenced, and the order matters more than the speed. The firewall and remote access usually come first because that is where the actual risk sits. Cabling and switches come next because everything else stands on them. Wireless follows, because placing access points is easier once the cabling can reach where they need to go. A plan that spreads over a few visits is normal and is often the better answer.

Is the router from my internet provider really a problem?

For a small office with a handful of devices and no server, it can be adequate. It stops being adequate when you need more wired ports than it has, when the building is bigger than its wireless can cover, when you want guests separated from the business, or when anyone needs to work from outside. In most cases we keep it for the job it does well — terminating the internet line — and put the equipment that does the real work behind it.

If we move to Microsoft 365, do we still need a server?

It depends entirely on what the server does today. If it exists to run industry software that requires it, yes. If it exists to hold shared folders and manage logins, quite possibly not. The honest answer needs somebody to look at what is running on it and who depends on it, which is part of the assessment rather than something anyone can answer from a website. What we will not do is recommend keeping a box alive because keeping boxes alive is billable.

Our email keeps landing in customers' junk folders. Can that be fixed?

Usually, yes, and usually it is the three records described in the email section above — SPF, DKIM and DMARC — being missing, incomplete or contradicting each other. The work is to inventory everything that sends mail as your business, publish the records to match, then watch the DMARC reports for a while to confirm it took effect before tightening anything.

Can you work with the equipment we already have?

Wherever it is sound, yes. Plenty of switches, firewalls and access points in service today are perfectly capable and simply misconfigured, and reconfiguring is cheaper than replacing. When something genuinely needs replacing we will explain what it cannot do and let you decide.

Do you only work in the Central Valley?

On-site work — cabling, access points, switches, servers, firewall installs — is across California's Central Valley. Everything that can be done down a wire, which is a great deal of this page, we do remotely across the entire United States. Microsoft 365 migrations, email authentication, DNS and firewall configuration do not require anyone in the room. See the service areas page, or the general questions and answers.

Coverage

Where We Do This Work

On-site network, server and phone work runs the length of California's Central Valley — from Sacramento and Stockton in the north, through Modesto, Merced and Madera, across Fresno and Clovis in the middle of the valley, and down through Hanford, Visalia and Tulare to Bakersfield. Cabling a suite of offices, replacing a server that is on its way out, or chasing down wireless that will not reach the back of a warehouse are all ordinary on-site jobs, and they are the reason we come to you — none of that work fits in a car.

Everything that does not need hands on the equipment — the Microsoft 365 migration, the email records, the firewall rules, the DNS, the monitoring — is done remotely across the entire United States. A business with an office here and staff in three other states is a normal arrangement, not a complication.

On-Site Service California's Central Valley Scheduled visits — see service areas
Remote Support Nationwide Across the entire United States
Talk To Us (559) 507-2076 Monday – Friday, 9:00 AM – 5:00 PM Pacific
First Conversation Free Initial Consultation Or send us the details

Let Us Look At What You Actually Have

Tell us what keeps dropping, or what you are trying to build. The first conversation is free, and you will speak to a technician rather than a call queue.