Sr. Network Engineer Resume
Farmington, CT
SUMMARY
- Senior Network/Network Security/Application Delivery Engineer/Wireless Engineer with overall experience of almost 8 years.
- Experience with various Network Topologies, LAN, MAN, WAN, Campus, Data Center, ISP Connectivity, WLAN, VOIP environments.
- Worked on Next generation Network Engineering trends and have hands on experience in migration projects from legacy to latest technologies and equipment.
- Team player and has experience working with various teams like server, Project Management, Virtualization, Storage, Cabling (SM/MM), Application etc.
- Thorough with Documentation Skills from end to end Project implementation.
- Switching experience which includes campus and Data Center Switching, Worked on Cisco, Juniper, Arista, Aruba and Dell Switching gear.
- Experience with IDF/MDF Architecture, remote sites switching with access and Distribution layers, Data Center Top of the Rack switching, Distribution and core in DC.
- Campus Switching and Routing Hardware includes - Cisco 3750, 3850, Cat 9K, 4500, cisco ISR routers, 2300, 7200 series routers Juniper EX 4300, 3400 in access and EX 4600 in Distribution. Aruba 2530, 2540, 3810 and 5400R switches. Cisco Layer 2/3 networking knowledge.
- Data Center Switching and Routing Hardware Includes Cisco Nexus 2K, 5K, 3K and 7K modules.
- ASR 1K, 9K, Cisco Juniper QFX Series, MX series routers, Arista 7000 series.
- High Level understanding and implementation experience in VLAN, STP, RSTP, MST, 802.1X, DHCP, DNS, HSRP, VRRP, GLBP, IPv4, IPv6, OSPF, EIGRP, IS-IS, BGP, RIP, Static Routing, VSS, MLAG- VPC, MEC, VDC, VXLAN, EVPN Protocols.
- Extensive experience working with Network Firewalls. Worked on Cisco ASA, Cisco Firepower, Palo Alto Next Gen Firewalls, Checkpoint, Fortigate and Sonic Firewalls.
- Experience with Perimeter Firewalls, VPN firewalls, Server Farm Firewalls using Standard and Extended ACL, All types of NAT, URL Filtering, SSL Forward Proxy, SSL Decryption, Threat ID, User ID and APP ID based Security policies.
- Worked on Internet Web Security Proxies which includes Cisco Iron Ports, Bluecoat Proxies, Zscaler Cloud Proxies. Worked on PAC files, Whitelist and Blacklist policies, AD group-based policies, User based, location-based Policies on proxies.
- Experience with Application delivery controllers which include Cisco ACE, F5 LTM, GTM, APM, ASM modules, Citrix Netscalers. Worked on Virtual servers, Pools, SNAT, persistence, Profiles, iRule Scripting, DNS, Topology based load balancing on F5. Migration experience from ACE to F5.
- Worked on all major vendor-based application load balancing which includes Microsoft Office 365, Secure email Gateways, Citrix VDI, ICA proxy, tenant restrictions etc.
- Experience with Overlay and Underlay networks which includes VXLAN tunneling, OTV. Software defined networks using Cisco ACI and Arista Cloud Vision. Experience configuring Bridge Domains, Application templates, VNI, VTEPS, Symmetric and Asymmetric IRB in Spine and Leaf Architecture.
- Experience with remote site connectivity to Data centers using SD-WAN in MPLS WAN. Worked on Versa, Viptella and Meraki SD WAN solutions. Experience with vSmart, vBond, vEdge and vManage components in SD-WAN.
- Worked on Cisco, Meraki and Aruba Wireless solutions. Worked on configuration of WLAN controllers, AP groups, SSID, RF parameters, Anchor controllers, BYOD policies, Integration with RADIUS servers for Authentication. Experience with Cisco Prime, Aruba Airwave.
- Worked on Cisco ISE, Aruba ClearPass for RADIUS and TACACS Authentication. Integration with WLAN controllers. Wired and Wireless Authentication using Cert based and MAB.
- Enhanced level of knowledge with, PPP, PAP, CHAP, ATM, T1 /T3 Frame-Relay, MPLS.
- Experience with DNS and DHCP servers which Include Infoblox, Windows DNS and DHCP, BlueCat DNS. DHCP scopes, IPAM, DNS Zones, Forwarders, Delegations to F5 GTM for WideIP, sub Domains, External, Internal and Cache grids for DNS.
- Worked on SNMP for network monitoring which includes SolarWinds, Netbrain, Whatsup Gold.
- Experience with Cisco and Avaya VOIP environment. Worked on Configuration of Call Managers, H.323, SIP trunks, QOS policies, VOICE VLANS, CUCM, VOIP gateways etc. Very good understanding in 802.1X.
TECHNICAL SKILLS
Networking Technologies: LAN/WAN Architecture, TCP/IP, Frame Relay, VPN, VLAN, VTP, NAT, PAT, STP, RSTP, PVST, MSTP
Networking Hardware: Cisco Switches, Cisco Routers, ASA/Pix/Palo Alto/Fortinet/Juniper firewalls.
Routing Protocols: OSPF, ISIS, EIGRP, RIP, MPLS, IS-IS, BGP, Multicasting
Security Technologies: PAP, CHAP, Cisco PIX, Blue Coat, Palo Alto, ASA, Fortinet, Checkpoint
Network Monitoring: Solarwinds, Wireshark, HRping, Whatsupgold, Infoblox
Operating Systems: Windows 7, Vista, XP, 2000, LINUX, Cisco IOS, IOS XR, IOS-XE, NX-OS
Routers: CISCO 4300, 4400, 4500,2600, 2800,3800,7200, Juniper M & T Series, ASR 1000
Load Balancers: F5 Networks (BIG-IP), Netscaler (Citrix)
Switches: CISCO 2960,3750,3850, CAT 9300, CAT9400, CAT 9500,4500,6500,6800 Nexus 7k,5k,2k
Firewalls: Juniper Net Screen (500/5200), Juniper SRX (650/3600), Pix (525/535), ASA (5520/5550/5580 ), McAfee Web Gateway, Checkpoint, Palo Alto firewalls.
AAA Architecture: TACACS+, RADIUS, Cisco ACS
Features & Services: IOS and Features, HSRP, GLBP, VRRP, IPAM IRDP, NAT, SNMP, SYSLOG, NTP, DHCP, CDP, DNS, TFTP and FTP Management, Open Stack, IVR’s, HLD and LLD documents.
PROFESSIONAL EXPERIENCE
Confidential, Farmington CT
Sr. Network Engineer
Responsibilities:
- Implemented Zone Based Firewalls and Security Rules on the Palo Alto Firewall. Palo Alto design and installation (Application and URL filtering, Threat Prevention, Data Filtering). Configured and maintained IPSEC and SSL VPN's on Palo Alto Firewalls.
- Experience working with Nexus 7010, 5548, 5596, 2148, 2248 devices.
- Deploying and decommission of VLANs on core ASR 9K, Nexus 9K, 7K, 5K and its downstream devices also configure 2k, 3k, 7k series Routers
- Experience configuring VPC (Virtual Port Channel), VDC (Virtual Device Context) in Nexus 7010/7018
- Installation and Configuration of Cisco Catalyst switches 6500, 3850 & 2960, 9300 series and configured routing protocol OSPF, EIGRP, BGP with Access Control lists implemented as per Network Design Document and followed the change process as per IT policy it also includes the configuration of port channel between core switches and server distribution switches
- Experience with setting up MPLS Layer 3 VPN cloud in data center and working with BGP WAN towards customer.
- Migrated to Juniper EX series switches from Cisco 3500 series and 6500 series switches.
- Well Experienced in configuring protocols HSRP, GLBP, PPP, PAP, CHAP, and SNMP.
- Work with Load Balancing team to build connectivity to production and disaster recovery servers through F5 Big IP LTM load balancers
- Install, manage and monitored Large scale Palo Alto Firewalls through Panorama.
- Experience in installing and configuring DNS and DHCP servers.
- Worked with Palo Alto firewalls PA250, PA4050, PA3020 using Panorama servers, performing changes to monitor/block/allow the traffic on the firewall. Technical assistance for LAN/WAN management and complex customer issues.
- Remediation of firewall rules from checkpoint firewalls to Cisco ASA firewalls and their implementation.
- Implemented Security Policies using ACL, Firewall, IPSEC, SSL VPN, IPS/IDS, AAA (TACACS+ & RADIUS).
- Dealt with Aruba wireless access points 200,300 series supporting 802.11 ac.
Confidential, Dayton, OH
Sr. Network Engineer
Responsibilities:
- Installed and configured LAN/WAN Networks, Hardware, Software, and Telecommunication services- Cisco Routers and Switches.
- Worked on Cisco wireless LAN technologies, Integration with Cisco ISE. Worked on WLAN AP profiles, Authentication roles, RF properties, AP configuration, WLAN upgrades, Anchor controllers, Cisco prime.
- Worked on SD-WAN implementation for remote site connectivity using Viptella. Configuration of Application policies, vEdge, vManage, vSmart and vBond in Viptella.
- Routing protocol configuration such as OSPF, IS-IS, EIGRP and BGP, Router redundancy configuration (HSRP, VRRP and GLBP) and Wireless LAN (Access point, LWAPP).
- Experience with network management protocols/tools (TACACS, NTP, SNMP, SYSLOG, etc.). Working experience on complex Checkpoint, Cisco ASA & Palo Alto Firewalls Environment.
- Resolved Customers request to create firewall policies for Cisco ASA, Juniper SRX, Fortinet and NX-OS.
- Infrastructure configuration and troubleshooting for Windows Azure environments.
- Involved in the Team of Data Center Operations to perform duties like administration and monitoring of Cisco Routers and Switches according to the organization requirements.
- Configuring and implementing Remote Access Solution: IPsec VPN, AnyConnect, SSL VPN.
- Provided technical support services for DNS and IPAM services.
- Involved in Network Designing, Routing, DNS, IP Subnetting, TCP/IP protocol.
- Installed and maintained routers and switches in various network configurations supported VLANs, QoS, VoIP, Call Manager and advanced access-lists.
- Experienced in Configuring/Troubleshooting Routing Protocols EIGRP/OSPF/BGP/RIP.
- Troubleshoot layer1, layer2 and layer3 technologies for customer escalations.
- Experience with converting Cisco 6500 IOS to Cisco Nexus NX-OS in the data center environment.
- Install and maintain the wireless infrastructure (Aruba, HP controllers) Configuration of SSID, VLAN binding, security management
- Assigning RADIUS and TACACS for new deployments in production environment. AAA for users to implement changes on production devices.
Confidential, Englewood, CO
Network Security Engineer
Responsibilities:
- Worked primarily as a part of the security team and daily tasks included firewall rule analysis, rule modification and administration
- Worked on configuring and troubleshooting of routing protocols such as OSPF, EIGRP and BGP for effective communication. Maintain LAN communication between Servers/Workstations.
- Remediation of firewall rules from checkpoint firewalls to Cisco ASA firewalls, installing and configuring new juniper EX, MX, SRX series firewalls to meet day to day work.
- Support Network Technicians as they require training & support for problem resolution including performing diagnostics, & configuring network devices
- Recommended Security considerations for the Intranet data center, integrating security, providing solution design details and configuration details
- Designed WAN structure to prevent single point of failure in case of link failure.
- Maintenance and Troubleshooting of connectivity problems using Ping, Trace route.
- Planning and Implementation of Subnetting, VLSM to conserve IP addresses.
- Configured STP for loop prevention and VTP for Inter-VLAN Routing.
- Troubleshooting issues and outages on Trunks and Router interfaces extensively.
- Technical assistance for LAN/WAN management and complex customer issues.
- Provided support for troubleshooting and resolving Customer reported issues.
- Performed route redistribution & manipulated route updates using distribute lists, route-maps & AD
- Installed and configured SSH (Secure Shell) encryption to access securely on Ubuntu and Red hat Linux.
- Deployment of Palo Alto firewall into the network. Configured and wrote Access-list policies on protocol-based services.
- Configured network access servers and routers for AAA security (RADIUS/ TACACS+)
Confidential, Nashville, TN
Network Engineer
Responsibilities:
- Installing and configuring Juniper M series router along with Juniper switches QFX series
- Working Knowledge of frame relay, MPLS services, IPSec VPN's, OSPF, BGP and EIGRP routing protocols, NATing, sub-netting, also including DNS, WINS, LDAP, DHCP, TCP/IP, UDP, SNMP, OSPF, IPSEC, PPP, VLAN, VTP, STP (Spanning tree Protocol), RSTP & Multicasting protocols.
- Experience with Firewall administration, Rule analysis, Rule modification.
- Troubleshoot traffic passing managed via logs and packet captures
- Responsible for reviewing current and planned network designs, particularly F5 load balancer implementations. Identified opportunities for implementation of network best practices.
- Worked and engaged with Service Providers like AT&T, Verizon to test and turn up the CER routers throughout different sites in California.
- Implemented Quality of Service (QOS), Policy Maps, Class-maps, Policy Routing in the network infrastructure throughout all the different sites.
- Played responsible role for implementing, engineering, & level 2 support of existing network technologies/services & integration of new network technologies/services
- Worked with Cisco Layer 3 switches 3560, 3750, 4500, 6500; Cisco Nexus 5000 and 7000 in multi VLAN environment with the use of inter-VLAN routing, 802.1Q trunk, ether channel.
- Key contributions include troubleshooting of complex LAN /WAN infrastructure that include routing protocols EIGRP, OSPF & BGP.
- Installed redundant BigIP F5 LTM and GTM load balancers to provide uninterrupted service to customers.
- Configured and deployed BIG-IP LTM 8900 for providing application redundancy and load balancing.
- Generating RCA (Root Cause Analysis) for critical issues of layer1/layer2/layer3 problems
