Sr. Network Engineer Resume
Pittsburgh, PA
SUMMARY
- CCNP Certified Professional with 8+ years of experience in routing, switching, firewall technologies, NOC, system design, implementation and troubleshooting of complex network systems.
- Experience in site - to-site and remote access VPN solutions.
- Experience working with Nexus 7010, 5020, 2148, 2248 devices.
- Experience with F5 load balancers - LTM, GTM series like 6400, 6800, 8800 for the corporate applications and their availability.
- Worked extensively on Cisco Firewalls, Cisco PIX (506E/515E/525) and ASA 5500 (5510/5540) series.
- Experience working with OTV & FCOE on the nexus between the datacenters.
- Experience working with Cisco Nexus 2148 Fabric Extender and Nexus 5000 series to provide a Flexible Access Solution for Datacenter access architecture.
- Implemented Cisco Application Centric Infrastructure (ACI) as a solution for data centers using a Spine and Leaf architecture.
- Good knowledge in configuring and troubleshooting Exterior Gateway protocols such as BGPv4 including internal BGP (iBGP) and external BGP (eBGP)
- Understanding of JUNOS platform and worked with IOS upgrade of Juniper devices.
- Good knowledge in configuration of Voice VLAN’s (VOIP), prioritizing the voice traffic over the data traffic.
- In depth understanding of IPV4 and IPV6 and implementation of Subnetting.
- Configured security policies including NAT, PAT, and VPN, Route-maps, Prefix lists and Access Control Lists.
- Extensive experience in WAN Technologies, Switching Technologies along with Failover Mechanisms and Inter VlAN Routing types.
- Switching tasks include VTP, ISL/802.1q, IPSec and GRE Tunneling, VLANs, Ether Channel, Trunking, Port Security, STP and RSTP.
- Experience in adding rules and monitoring checkpoint Firewall Traffic through Smart view tracker Application.
- Experience in configuring and working on Juniper (SSG&, ISG), SRX, Checkpoint, Palo Alto Firewalls (NAT policies, VPN Configuration) in Standalone and High Availability mode.
- Successfully completed various projects in upgrading Checkpoint firewalls from R65 to 75.40, R75.47, R77 and implemented IPS policies.
- Configuring NAT policies on ASA and Palo Alto.
- Troubleshoot and Worked with Security issues related to Cisco ASA/PIX, Checkpoint, IDS/IPS, Palo Alto and Juniper Netscreen firewalls.
- Worked with Bluecoat proxy Servers, ZSCALER Web Security and Authentication controls(RADIUS,TACAACS+)
- Good knowledge with the technologies VPN, WLAN and Multicast.
- Involved in designing and deploying various network security and High availability products like Cisco ASA and other security products.
- Strong hands on experience in installing, configuring and troubleshooting of Cisco 7600, 7200, 3900, 3600, 2900, 2600, 2500 and 1800 series routers, Cisco Catalyst 6500, 4500, 3750, 2950 and 3500XL series switches.
- Configured WIFI AP’s connected in LAN to reduce cable costing by creating Access Points.
- Extensive experience in configuring and troubleshooting of protocols RIP v1/v2, EIGRP, OSPF, BGP and MPLS.
- Worked on network topologies and configurations, TCP/IP, UDP, Frame Relay, Token Ring, ATM, bridges, routers, hubs and switches.
- Well experienced in configuring HSRP, GLBP, ICMP, PPP, PAP, CHAP and SNMP.
- Experience in installing and configuring DNS, DHCP server.
- Excellent communication skills, enthusiastic, motivated and a team player.
- A highly organized individual who adopts a systematic approach to problem solving, effectively analyzes results and implements solutions.
- Highly motivated with the ability to work independently or as an integral part of a team and committed to highest levels of professional.
- Experience working on network monitoring tools like, SOLAR WINDS, CISCO works, Wireshark and splunk.
- Experience with Change management process and Project documentation tools like Excel and VISIO.
TECHNICAL SKILLS
Security/Firewalls: Cisco ASA, Checkpoint, Palo Alto, Juniper SSG and SRX, IPSEC and SSL VPNs, IPS/IDS, DMZ Setup, CBAC, Cisco NAC, ACL, NAT, PAT, RSA Secure IDIOS Firewall features, IOS Setup and Security features.
Features and Services: IOS and Features, NAT, SNMP, NTP, DHCP, CDP, DNS, TFTP and FTP Management, AD.
Protocols: OSPF, BGP, EIGRP, RIP-2, HSRP, VRRP, GLBP, LACP, PAGP, DNS, SMTP, SNMP, FTP, TFTP, LPD/TDP, WLAN, SIP, 802.11/802.11 e. Route Filtering, Redistribution, Summarization, Static Routing.
Switching: VLANs, VTP, STP, RSTP Inter VLAN routing and Multi-Layer Switching, Layer3 Switches, and Ether channels, Dot1Q, HSRP, GLBP, CEF, DCEF and Port Security.
Network Security: Check Point Nokia Firewalls IP350, IP550 & IP750, Juniper Netscreen, Fortinet, Firewalls ISG 1000/2000, Cisco PIX 505/515E/525 & ASA 5500 Series, ZSCALER
Network Products: CISCO ISR Routers 1900, 2900. CISCO High End Router 3600, 3800, 7200, 12010. CISCO Switches 1900, 2950, 2960. CISCO Campus Switches 3550XL, 4984 Core Catalyst 4503, 4507 RE, Catalyst 6500/6503/6507.
LAN: Ethernet, Fast Ethernet, Gigabit Ethernet, Ten Gigabit Ethernet, LAN emulation.
WAN: Leased lines (PPP/HDLC), channelized links (E1/T1/E3/T3/DS1/DS3), Fiber Optic circuits (OS3), Frame relay, ISDN.
AAA Architecture: TACACS+, RADIUS, Cisco ACS.
Monitoring: Wire shark, Solar Winds, TCP Dump, HP NNMI, Clearpass, Netscout, Gigamon, Open Manage
Programming Language: Python, Java, MATLAB, C/C++,Shell Scripting, Spirent(Landslide)
PROFESSIONAL EXPERIENCE
Confidential, Pittsburgh, PA
Sr. Network Engineer
Responsibilities:
- Design, deployment and maintenance of enterprise networks and datacenters.
- Configured, maintained, and troubleshoot routers and switches ranging from the 2960 series through Nexus 9k 6500, 7k series switches in a highly redundant Cisco ACI environment.
- Configuration of EIGRP, BGP, and OSPF based network by resolving level 2 &3 problems of internal teams & external customers of all locations.
- IOS upgradations on Switches and Routers, ACI leaves and Spines.
- Migration of the Core network from Legacy Cisco 6k core network to ACI based network.
- Configuration of Access List ACL (Std, Ext, Named) to allow users all over the company to access different applications and blocking others.
- Experience working with OTV & FCOE on the nexus between the datacenters.
- Troubleshoot issues on OTV layer 2 Vlan Extension between Datacenters.
- Responsible for Palo Alto and ASA Firewall administration on some of the nodes across our global networks.
- Built and Troubleshoot Site-Site IPsec VPN tunnels to remote sites.
- Migrating/configuring Site-site tunnels from ASA to Palo alto.
- Perform Rule audits based on hit count and modified/removed policies as needed.
- Implementing URL filtering, User - IP mapping via User ID authentication, SSL Interception thereby using Palo Alto for layer 7 filtering bypassing current Websense proxy servers.
- Configured and troubleshoot VIP’s on Citrix NetScaler Load balancer, Installation/renewal of Certificates, and Configuration of content switching VIP’s /policies.
- Performed network scans for security vulnerabilities and provide solutions and taking necessary actions for risk mitigation.
- Working experience on Aruba Wireless controller and configuration of enforcement policies on Clearpass authentication for wireless users.
Confidential
Sr. Network Engineer
Responsibilities:
- Design, deployment and maintenance of enterprise networks, NOC and datacenters.
- Configured, maintained, and troubleshot routers and switches ranging from the 2960 series through the 7200 series routers and the 2900 series through the 6500 series switches and ASR 1000 series routers in a redundant environment.
- Improve scalability and ease of deployments of the Open stack underlay network by migrating from Standalone Nexus to Cisco ACI platform.
- Used Cisco ACI Fabric which is based on Cisco Nexus 9k series switches and Cisco Application Virtual Switch (AVS).
- Focused on working with Cisco Channel partners to build practices around Cisco ACI.
- Scripted, Configured and Monitored the HP NNMI NMS system for different Network Alerts.
- Hands on experience with F5 LTM installation/support and used HA proxy for Layer4 load balancing.
- Configuring and managing F5Web Accelerator module and Application Security Module (ASM) technology.
- Supporting EIGRP based network by resolving level 2 &3 problems of internal teams & external customers of all locations.
- IOS upgradations on Switches and Routers, Migrated to SSH from telnet for more secure remote connections.
- Configuring BGP, MPLS in Cisco IOS XR. Configuring Virtual Device Context in Nexus 7010.
- Implemented VDC, VPC, VRF and OTV on the Nexus 5505 and 7009 switches.
- Troubleshooting of complex LAN/WAN infrastructure that include routing protocols EIGRP, BGP, MPLS.
- Worked on MPLS while ensuring secure networking, improving the network performance by prioritizing network traffic and allocating bandwidth according to usage and service requirements.
- Responsible for Checkpoint and Palo Alto Firewall administration across our global networks.
- Worked in migration of Cisco ASA & Checkpoint firewalls to Palo Alto firewalls using a migration tool.
- Understanding different types of NAT on Cisco ASA & Checkpoint firewalls and applied them.
- Configured routing protocols in relation to Checkpoint firewalls (61000 and 21400).
- Configure the access policies and VPN policies in checkpoint firewall.
- Worked on configuration and upgradation of Checkpoint Firewalls within regular maintenance windows..
- Upgrading Checkpoint firewalls from R65 to 75.40, R75.47, R77 and performed rule audits and modified/removed rules as needed.
- Upgrading Panorama to latest version for optimizing performance.
- Performed network scans for security vulnerabilities and provide solutions and taking necessary actions for risk mitigation.
- Cisco ASA/Checkpoint Firewall troubleshooting and policy change requests for new IP segments that either come on line or that may have been altered during various planned network changes on the network
- Implemented an IP telephone network with 200+ IP phones. Configured data network to support voice including VoIP VLAN, interVLAN routing and QoS tagging. Included 4 PCX system, voice mail server, my teamwork server and a management server. This project included 7 wireless AP and LAN bridging through a wireless link.
- Configured all aspects of CUCM and Unity Connection including: SRST, MoH, TAPS, Extension Mobility, IPMA, etc.
- Implementing SIP Trunking using CUBE router (CGI Group).
- Configuration of Access List ACL (Std, Ext, Named) to allow users all over the company to access different applications and blocking others.
- Configured Cisco 2702/3702I/E Access points, Bridges and 2504/5520 WLC’s and designed wireless networks accordingly in a harsh plant environment. (choosing suitable antennas for Moving equipment in the plant)
- Worked on the security levels with RADIUS, TACACS+ and could establish secure identity management using Net IQ identity manager.
- Involved in L2/L3 Switching Technology Administration including creating and managing VLANs, Port security, Trunking, STP, Inter-Vlan routing, LAN security.
- Wireless Technology implementation, maintenance, and security (WEP 40bit, WPA2, AES). Management and configuration of wireless Cisco Wi-Fi hardware
- Optimized wireless networks for Crane PLC’s in harsh/High noise environments by analyzing RF parameters (SNR, RSSI).
- Hands on experience with Cisco Prime for configuration and real-time tracking of alarms in support of LAN and wireless networks
- Create vPC domain, design double-sided vPC, design vPC peer-keep alive, vPC peer- link, and vPC member port, and configure single and dual home FEX.
- Troubleshooting of DNS, DHCP and other IP conflict problems. Implementation of name resolution using WINS & DNS in TCP/IP environment
- Maintained and Updated the HP open view map to reflect and changes made to any existing node/object
- Used python scripts for generating network alerts and automation.
- Python Automation scripting for Cisco IOS/IOSXR platforms.
- Resolving and Closing tickets using IBM Service Now.
- Handled SRST and implemented and configured the Gateways, Voice Gateways.
- Manage Cisco Routers and troubleshoot layer1, layer2 and layer3 technologies for customer escalations
- Worked on a broad range of topics such as routing and switching, dedicated voice access, planning and implementation, large-scale high-visibility outages, change management coordination, proactive monitoring and maintenance, disaster recovery exercises, and core network repairs.
- Worked on Linux, Unix and windows platforms.
- Network Cabling, dressing, labeling and troubleshooting various network drops onsite.
Environment: STP, VLAN, MPLS, SRST, EIGRP, MPLS, VPN,HSRP,RADIUS, TACACS+, Port Security, Firewall(ASA, Palo Alto),Trunking, Juniper, Cisco 2960 through 6500 Switches,F5BigIP Load Balancer Traffic Managers (LTM), EX series switches, Cisco Nexus 2148 Fabric Extender &,9k.,HP NNMI, Cisco Prime, VMware,ACI
Confidential, Chicago, IL
Sr. Data Center Engineer
Responsibilities:
- Design, deployment and maintenance of enterprise networks and datacenters.
- Worked extensively in configuring, Monitoring and Troubleshooting Cisco's ASA 5500/PIX security appliance, Failover DMZ zoning & configuring VLANs/routing/NATing with the firewalls as per the design.
- Configured, maintained, and troubleshot routers and switches ranging from the 1720 series through the 7200 series routers,ASR 1000 series and the 2900 series through the 6500 series Catalyst switches in a highly redundant dual-homed environment.
- Monitoring the NMS system for different Network Alerts.
- Worked on multiple projects related to Branch networks, Campus networks, extranet clients and Data Center Environments involving in data center migrations from one data center to another.
- Provisioning ports in Cisco ACI to support SAN, VoIP, and hypervisors.
- Worked with other network engineers to deploy the Cisco ACI fabric.
- Configuration of Cisco 6500 (sup 720), 4500 (SUP 6) & 3750 Catalyst Switches for network access. Worked extensively on Cisco Firewalls, Cisco PIX (506E/515E/525/) & ASA 5500(5510/5540) Series, experience with convert PIX rules over to the Cisco ASA solution.
- Configuring RIP, OSPF and Static routing.
- Configuration of F5 LTM 8950, 6900, VIPRION 2400 models.
- Member of project involving transitioning all load balancing off Cisco Content Switches onto new F5 LTM hardware
- Provide Tier III Level Load Balancer expertise onF5 Big IPLocal Traffic Managers (LTM). Designing F5 solutions/support for migration work of applications and websites from Cisco CSS Load Balancers to the F5 Big IPLoad Balancers.
- Provided load balancing towards access layer towards core layer using F5 load balancers and used SPOC for troubleshooting.
- Hands on experience with F5 GTM/LTM installation/support and used HA proxy for Layer4 load balancing.
- Performed Wireless RF Surveys for determining AP positions and Antenna directions/placements and setting RF parameters.
- Configured Cisco Wireless Hardware (WEP, WPA2) and designed WLAN for business networks.
- Configuring VLAN, Spanning tree, VSTP, SNMP on EX series switches.
- Once trouble ticket has been created keep customer informed of status of ticket and estimated time to repair.
- Coordinating with service providers for WAN link outages.
- Checking and configuring Cisco 7600 and 7200 routers at data center for remote sites’ issues.
- Configuring RIP, OSPF and Static routing on Juniper M JunOS x 480 and MX series Routers
- Juniper Net Screen Firewalls like NS50, SSG 550M, SSG520M, ISG 1000, ISG 2000, JCL with Site-Site VPN for client companies.
- Working on Cisco 6509 and 4507 series switches for LAN requirements that include managing VLANs, Port Security and troubleshooting LAN issues.
- Experience working with OTV & FCOE on the nexus between the datacenters.
- Experience working with Cisco Nexus 2148 Fabric Extender and Nexus 5000 series to provide a Flexible Access Solution for Datacenter access architecture.
- Supporting EIGRP and BGP based network by resolving level 2 &3 problems of internal teams & external customers of all locations.
- Upgrading WAN link using PPP Multilink and by implementing Cisco WAAS.
- Performed switching technology administration including VLANs, inter-VLAN routing, Trunking, STP, RSTP, port aggregation & link negotiation.
- Experience with converting campus WAN links from point to point to MPLS and to convert encryption from IPsec/GRE Tunneling to another data center
- Configuration of Access List ACL (Std, Ext, Named) to allow users all over the company to access different applications and blocking others.
- Worked on Bluecoat proxy server, Tipping Point Intrusion Protection System management, and reporting tool Algosec
- Responsible for Cisco ASA and Checkpoint firewall administration across our global networks.
- Deployed both Zscaler and Cisco web security for multiple remote sites.
- Troubleshooting network traffic and its diagnosis using tools like ping, trace route, Gigamon, Wireshark, TCP dump and Linux operating system servers.
- Providing daily network support for national wide area network consisting of MPLS, VPN and point-to point site.
- Worked extensively in configuring, Monitoring and Troubleshooting Cisco's ASA 5500/PIX security appliance, Failover DMZ zoning & configuring VLANs/routing/NATing with the firewalls as per the design.
- Experience configuring Virtual Device Context in Nexus 7010.
- Install and configure various VoIP systems at customer sites to include Cisco Callmanger, Unity Connections, CER and voice gateways.
- Responding to alerts from various information security monitoring tools, including SIEM, IDS/IPS, WAF, DAM, log aggregators.
- Reviewed possible replacements to corporate SIEM and IPS/IDS solutions and provided feedback and opinions
- Designed QoS policies for critical applications based on business requirements and traffic patterns.
- Responsibilities also include technical documentation of all upgrades done. Attending meetings and technical discussions related to current project.
- Created VDC’s and vPC’S and ensure that those vPC’s are formed between those VPC’s.
- Upgrading WAN link using PPP Multilink and by implementing Cisco WAAS.
- Configuring HSRP between the 3845 router pairs for Gateway redundancy for the client desktops.
- Configure VRRP & GLBP and VLAN Trunking 802.1Q, STP, Port Security on Catalyst 6500 switches.
- Negotiate VPN tunnels using IPsec encryption standards and also configured and implemented site-to-site VPN, Remote VPN.
- Change Requests, Resolving and Closing tickets using Altria Service Now
- Troubleshooting of DNS, DHCP and other IP conflict problems. Implementation of name resolution using WINS & DNS in TCP/IP environment.
- Network Cabling, dressing, labeling and troubleshooting various network drops onsite.
Environment: Cisco Routers series 1720, 2900, 3750, 3845, 4500, 4507, 6500, 6509, 7200, 7600, F5 BigIP Load Balancer Traffic Managers (LTM), EX series switches, Cisco Nexus 2148 Fabric Extender Nexus 5000 series, VLAN, PPP Multilink, Cisco WAAS, Catalyst 6500 Switches, VRRP & GLBP, STPRSTP, ACL. Cisco ASA Firewall, 5500/PIX, Juniper M and MX.
Confidential, Reston, VA
Sr. Firewall Engineer
Responsibilities:
- Designated, validated and implemented LAN, WLAN&WAN solution to suite client's needs.
- Negotiate VPN tunnels using IPSec encryption standards and also configured and implemented site-to-site VPN, Remote VPN.
- Configuring STP for switching loop prevention and VLANs for data and voice along with configuring port security for users connecting to the switches.
- Working on Network design and support, implementation related internal projects for establishing connectivity between the various field offices and data centers.
- Ensure Network, system and data availability and integrity through preventive maintenance and upgrade.
- Experience working with design and deployment of MPLS Layer 3 VPN cloud, involving VRF, Route Distinguisher(RD), Route Target(RT), Label Distribution Protocol (LDP) & MP-BGP
- Configured Client-to-Site VPN using SSL Client on Cisco ASA 5520 ver8.2
- Configuring virtual servers, configure nodes and configuring the load balancing pools and also worked with configuring load balancing algorithms.
- Worked on configuration and upgradation of Checkpoint Firewalls on regular basis.
- Successfully completed various projects in upgrading Checkpoint firewalls from R65 to 75.40, R75.47, R77 and implemented IPS policies.
- Configured Checkpoint Firewall as Standard and Distribution deployment to have the network secure and also maintaining Site to Site VPN Connection through the Firewalls. Handling 8 to 10 gateways using a Smart Center Server as a management Station.
- Research, create, monitor and maintain all aspect of Fortinet DLP, IPS, A/V, Web filtering and SSL inspection by using my proficiency with Fortimanager, Fortianalyzer and Fortiauthenticator.
- Responsible for service request tickets generated by the helpdesk in all phases such as troubleshooting, maintenance, upgrades, patches and fixes with all around technical support
- Experience with converting WAN routing from EIGRP/OSPF to BGP (OSPF is used for local routing only) which also involved converting from Point to point circuits to MPLS circuits.
- Designed and implemented Cisco VoIP infrastructure for a large enterprise and multi-unit office environment. Met aggressive schedule to ensure a Multi-office reconfiguration project which was successfully delivered
- Worked on Data, VoIP, security as well as wireless installations and technologies
- Installing and configuring F5 load balancers and firewall using F5 load balancers with LAN/WAN/WLAN configuration.
- Managed the F5 BIG-IP LTM/GTM appliances to include writing iRules, SSL Offload and everyday tasks of creating WIP and VIPs.
- Installed ESXi 6.5 (bare-metal vSphere hypervisor) on Cisco UCS-C220-M4S server and installed the following Vms: Cisco ISE 2.4 and Windows Server.
- Created/modified necessary profiles that allowed authorized devices on to the network.
- Installed, configured new ISE nodes and connected them to external Active Directory services.
- Configured StealthWatch as a remote logging target on ISE to send pertinent data about people and devices that are connected to the network.
- Globally rolled out Zscaler to replace Websense as the web filtering solution
- Troubleshoot and Worked with Security issues related to Cisco ASA/PIX, Fortinet, Checkpoint, IDS/IPS, and Palo Alto 3020 firewalls to mitigate DDOS attacks.
- Providing support Palo Alto 3000/5000 and 7000 series firewall through Panorama Management Console
- Involved in L2/L3 Switching Technology Administration including creating and managing VLANs, Port security, Trunking, STP, Inter-Vlan routing, LAN security.
- Worked on the security levels with RADIUS, TACACS+ and could establish secure identity management using Net IQ identity manager.
- Performed Firewall audits, evaluation of RC’s for possible cyber-security threats.
- Implemented CUCM features including: Extension Mobility, IPMA
- Worked on commissioning and decommissioning of MPLS circuits for various field offices.
- Completed service requests (i.e. - IP readdressing, bandwidth upgrades, IOS/platform upgrades, etc)
- Supporting EIGRP and BGP based PwC network by resolving level 2 &3 problems of internal teams & external customers of all locations.
- Configured Cisco Meraki WIFI AP’s connected in LAN to reduce cable costing by creating AP.
- Worked on Cisco SP Wifi, troubleshoot in Cisco Aironet3700, 1700 and 600 series.
- Providing daily network support for national wide area network consisting of MPLS, VPN and point-to point site.
- Configuring HSRP between the 3845 router pairs for Gateway redundancy for the client desktops.
- Configure VRRP & GLBP and VLAN Trunking 802.1Q & ISL, STP, Port Security on Catalyst 6500 and 6800 switches.
- Implemented an IP telephone network with 100+ IP phones and 4 Alcatel 7000 L3 switch. Configured data network to support voice including VoIP VLAN, interVLAN routing and QoS tagging. Included 4 PCX system, voice mail server, my teamwork server and a management server. This project involved LAN bridging through a wireless link.
- Create vPC domain, design double-sided vPC, design vPC peer-keep alive, vPC peer- link, and vPC member port, and configure single and dual home FEX.
- Connected modern VoIP equipment to legacy telephone systems
- Troubleshooting of DNS, DHCP and other IP conflict problems. Implementation of name resolution using WINS & DNS in TCP/IP environment.
- Updated the HP open view map to reflect and changes made to any existing node/object used Netscout platform to gather Netflow information and packet captures.
- Use of Microsoft Excel Spread Sheets for analyzing the Netflow and its type especially to monitor according to the requirements.
- Handled SRST and implemented and configured the Gateways, Voice Gateways.
- Resolving and Closing tickets using IBM Service Now.
- Manage Cisco Routers and troubleshoot layer1, layer2 and layer3 technologies for customer escalations
- Worked on a broad range of topics such as routing and switching, dedicated voice access, planning and implementation, large-scale high-visibility outages, change management coordination, proactive monitoring and maintenance, disaster recovery exercises, and core network repairs.
- Network Cabling, dressing, labeling and troubleshooting various network drops onsite.
Environment: STP, VLAN, MPLS, SRST, EIGRP,OSPF,BGP,MPLS,VPN,HSRP,RADIUS, TACACS+, Port Security, Firewall(Checkpoint,PIX,Fortinet),Trunking, Cisco 6500 Switches, EIGRP, OSPF, F5 BigIPv9 .
