Case Study: The "Connectivity Gap" – 200Mbps via Mast-Head LTE

Kent ITS engineered and deployed a high-throughput, mast-head LTE cellular broadband architecture to bridge a critical connectivity gap for a remote commercial facility. The location was stranded in a digital dead zone due to prohibitive five-figure Openreach civil engineering quotes for traditional fiber installation. To overcome the extreme signal attenuation associated with long coaxial cable runs, the solution deployed an integrated high-gain radio and modem directly at the mast-head, utilizing carrier aggregation to deliver commercial-grade broadband over external-grade digital copper cabling. This deployment provided reliable high-speed member wireless access, a static public IP for secure VPN monitoring, and lightning surge protection for a fraction of the cost of physical infrastructure excavation.
Section

This network engineering project demonstrates the use of advanced RF (Radio Frequency) engineering to defeat severe geographical infrastructure limitations. Faced with a £10k+ fiber installation barrier, Kent ITS bypassed traditional landlines entirely by building an on-site wireless local loop. By utilizing an integrated mast-head processing architecture, the design eliminates high-frequency coaxial signal degradation by converting cellular signals to digital data directly at the antenna focus. Featuring Category 18 carrier aggregation, specialized atmospheric surge protection, and a managed wireless mesh integration, this project successfully delivered 200Mbps speeds to a remote facility, proving that precision radio engineering can substitute for costly civil infrastructure.

A newly constructed remote facility was left completely isolated from traditional telecommunications networks. Openreach quoted civil engineering and trenching costs exceeding £10,000 to bring a dedicated fiber or copper line to the site, creating an immediate project standstill. The facility strictly required high-speed, low-latency internet to support open guest WiFi networks for its members alongside a static public IP address to allow for secure, encrypted inbound VPN remote monitoring.

Typical consumer-grade deployments fail in these environments because providers install an internal cellular router coupled to an external antenna via long coaxial cables. At high 4G/5G radio frequencies, the signal loss ($dB$ attenuation) across coaxial cabling is incredibly severe, often reducing the captured signal to an unusable state before it ever reaches the router's modem. The core challenge required capturing weak, distant cellular signals at peak strength and delivering it into the local network without cable-borne signal degradation or exposing the internal network to atmospheric electrical hazards.

1. Mast-Head Processing & Advanced RF Engineering

To completely eliminate coaxial signal loss, Kent ITS deployed a specialized MikroTik LHGG integrated dish architecture mounted to a 6-foot external mast. This system places the cellular modem and high-gain directional antenna inside a single weatherized enclosure at the focal point of the dish. By processing the raw radio frequency waves at the mast-head, the cellular signal is immediately converted into standard digital data packets directly at the source, ensuring maximum signal capture and link quality.

2. Digital Transport & Industrial Cabling

Once converted at the mast-head, the data is transmitted down into the facility using heavy-duty, external-grade Category 6 SFTP (Shielded and Foiled Twisted Pair) copper network cabling. Because digital Ethernet signals suffer zero degradation over these distances compared to raw RF cables, the internal router receives an uncompromised, full-strength data stream regardless of mast height or cable length.

3. Carrier Aggregation Hardware Optimization

Rather than utilizing basic Category 4 cellular equipment which binds to a single wireless frequency band, Kent ITS sourced an advanced Category 18 radio subsystem. This hardware level unlocks multi-band "Carrier Aggregation," allowing the modem to establish simultaneous, concurrent connections across multiple cellular frequency bands at once. This significantly multiplies the aggregate network throughput and stabilizes low-latency data streams even during peak cell-tower congestion windows.

4. Electrical Integrity & Surge Hardening

To safeguard the internal network assets from lightning strikes and atmospheric static build-up inherent to high external masts, a rigorous electrical grounding framework was integrated. A dedicated, heavy-duty inline network surge protector was installed at the building's entry point, bonded directly via a low-resistance functional earth drain lead back to the facility's MET (Main Earthing Terminal).

5. Local Mesh Distribution & Remote Access Routing

The incoming high-speed digital link was fed into a managed network switch and distributed across the facility using a Ubiquiti UniFi Access Point wireless mesh array, ensuring seamless coverage for on-site members. Simultaneously, the WAN interface was configured with a static public IP address, facilitating secure inbound VPN tunnels for encrypted, real-time remote monitoring and administrative site management.

  • Enterprise-Grade Throughput: Achieved a highly stable, symmetric 200Mbps downstream connection in a geographic dead zone previously deemed completely offline.
  • Massive Capital Savings: Eliminated over £10,000 in upfront Openreach civil trenching costs, delivering a fully operational network topology for a small fraction of traditional leased-line capital expense.
  • Secure Remote Infrastructure Monitoring: Enabled continuous, encrypted remote facility management and closed-circuit security auditing via a dedicated static public IP and hardware-level VPN termination.
  • Atmospheric Surge Protection: Guaranteed long-term system survivability against static and transient over-voltage surges through structured, shielded cabling and direct building earthing integration.
  • Seamless Local Wireless Capacity: Provided high-density, multi-user guest wireless connectivity across the property via an integrated Ubiquiti UniFi local distribution mesh.
Meta Tag Description

Learn how Kent ITS defeated a digital dead zone with a high-gain MikroTik mast-head LTE system, delivering 200Mbps speeds and saving over £10k in fiber install costs.

Title Card Summary

See how Kent ITS bypassed a £10k fiber trenching quote by engineering an on-site wireless local loop. Uses a mast-head MikroTik Cat18 LTE system to deliver a stable 200Mbps connection with full surge grounding and a UniFi mesh network.

Case Study : Self‑Hosted Zimbra Email Platform for UK Distillery – Private Cloud Case Study

Kent ITS engineered and deployed a high-performance, private cloud email and directory services platform for a UK distillery, replacing an unstable and non-scalable third-party hosted architecture. Designed to overcome severe local infrastructure limitations—including early dependencies on highly latent connectivity—the system was built on dedicated, refurbished enterprise hardware using open-source workloads and robust application-aware backup utilities. Over more than a decade of active production, the platform underwent continuous live evolution, migrating hypervisors, hardening security boundaries, and integrating independent mail gateways to provide near-instant performance, absolute data sovereignty, and an 86% reduction in long-term licensing costs compared to public cloud alternatives.
Section

This long-term private cloud initiative demonstrates the immense economic and operational value of engineered system longevity over short-term public cloud dependency. Tasked with modernizing a failing, high-latency hosted mail setup for a UK distillery, Kent ITS built an independent, on-premise application environment. By decoupling core workloads into specialized virtual machines and transitioning from commercial VMware to open-source XCP-ng, the architecture eliminated vendor lock-in while vastly increasing compute efficiency. Featuring multi-layered threat mitigation, an application-aware backup matrix, and resilient LTE failover boundaries, this deployment has sustained business-critical communications for over ten years—proving that strict root-cause systems design can deliver unparalleled speed, absolute control, and massive capital savings.

The distillery's legacy email infrastructure, hosted externally via TSOhost, had devolved into a severe operational bottleneck and an escalating risk to business continuity. Because the site originally lacked a fixed broadband connection and relied on unstable early mobile links, external IMAP latency caused routine email actions to take minutes instead of seconds. This performance degradation was compounded by unstructured shared mailbox habits and exponential growth in message volumes, which the hosted platform could not scale to support even after basic ADSL lines were introduced.

Administratively, the organization possessed zero control over system configurations, lacked any native performance-tuning mechanisms, and had no reliable, independent backup or recovery pipeline. The enterprise was entirely dependent on a black-box third-party provider, creating an unacceptable operational environment where business data lacked sovereignty, visibility, and basic disaster resilience.

1. Bare-Metal Infrastructure & Hypervisor Lifecycle Evolution

To achieve absolute performance control, Kent ITS established an on-site, rack-mounted private cloud environment utilizing structured cabling. The initial compute foundation relied on a refurbished HP ProLiant DL380 G5 server subjected to complete firmware lifecycle updates prior to production. The environment was initially virtualized using VMware ESXi, but as the platform evolved, it was seamlessly migrated in-place to an open-source XCP-ng ecosystem running on newer G6 hosts, achieving total hypervisor independence with zero operational downtime.

5. Decoupled Workload Architecture

To ensure systemic stability and simple administrative scaling, workloads were strictly isolated into dedicated Ubuntu Server virtual machines:

  • Directory Services: Centralized identity and user access control.

  • File Services: Secure local storage repositories.

  • Email Core: A dedicated Zimbra Collaboration deployment.

3. High-Performance Mail Engineering & Migration

Kent ITS executed an IMAP-based migration from the legacy TSOhost server, transferring historical mail volumes with zero data loss. By hosting the Zimbra instance locally within the private cloud network, external IMAP latency was completely eliminated, collapsing multi-minute mail delays down to near-instantaneous client responsiveness.

4. Storage Optimization & Application-Aware Backups

While shared storage originally allowed for virtual machine mobility, it introduced dangerous file locks and snapshot-related system instability. An engineering decision was made to prioritize absolute data integrity over live-migration capabilities by migrating the VM disks onto high-speed, local RAID-backed storage arrays—completely eliminating read-only disk state risks. For data protection, the architecture integrated Zextras, an application-aware backup suite that handles continuous incremental protection and allows granular object-level restores (from a single message up to a full disaster recovery).

5. Multi-Layered Security Hardening & Threat Reduction

Following a credential reuse event, a rigorous hardening framework was applied across the perimeter:

  • Brute-Force Mitigation: fail2ban was deployed across both the primary mail core and edge gateways.

  • Access Control: System-wide credential resets paired with strict, complex password policies.

  • Proxmox Mail Gateway (PMG) Integration: A dedicated, isolated edge mail gateway layer was built in front of the mail server (Internet → Mail Gateway → Mail Server), shielding it from direct exposure. This gateway enforced strict security filters: greylisting ($450$ temporary rejections), Reverse DNS validation, DNSBL blocklists (including Spamhaus), explicit recipient verification, and firewall-level blacklists.

6. Resilient Business Continuity Engineering

During a severe, week-long broadband outage caused by a physical ISP infrastructure failure, Kent ITS activated an automated failover path. Utilizing a specialized MikroTik LTE gateway, inbound and outbound mail traffic was instantly rerouted over cellular networks, maintaining continuous, uninterrupted business operations with zero mail drops or data loss.

  • Near-Instant Performance: Transformed the user experience by lowering email processing latencies from multi-minute delays to instant, real-time access.

  • 86% Licensing Capital Reduction: Saved the business over £18,000 across a 10-year horizon by opting for a self-hosted Zimbra/Zextras environment (~£3,000 total) over an equivalent 25-seat Microsoft 365 licensing model (~£21,000 total).

  • Definitive Threat Reduction: Drastically shrunk the mail network's visible attack surface and slashed inbound spam volumes via a multi-layered Proxmox Mail Gateway topology.

  • Proven Operational Resilience: Verified absolute site survivability during a catastrophic 7-day ISP broadband failure through rapid MikroTik LTE failover orchestration.

  • Engineered System Longevity: Validated a long-term architecture that seamlessly survived complete hypervisor changes (VMware to XCP-ng), underlying hardware generation upgrades (G5 to G6), and multiple major operating system updates over more than a decade without requiring a platform replacement.

Meta Tag Description

Discover how Kent ITS built a self-hosted Zimbra email platform on XCP-ng for a UK distillery, cutting licensing costs by 86% while ensuring near-instant performance.

Title Card Summary

A look into a ten-year private cloud email platform built on refurbished hardware for a UK distillery. Details the migration from VMware to XCP-ng, a Proxmox Mail Gateway threat defense layout, and an 86% cost reduction over public cloud alternatives.