Post Job Free
Sign in

Sr. Network Engineer

Location:
Santa Clara, CA
Salary:
125000
Posted:
March 05, 2019

Contact this candidate

Resume:

Prashanth B

Sr. Network Security Engineer

Ph No: 908-***-****

Email id: ******************@*****.***

Professional Summary:

Around 7+ years of professional experience in Network Planning, Implementing, Configuring, Troubleshooting and Testing of networking system on both Cisco and Juniper Networks.

Expertise with Installation, configuration and troubleshooting of Cisco Routers (ASR 9K, NSX 5K, Meraki MX84, CISCO ISR 1K, 7600, 3800, 2800, 2600, 1800 series). and Juniper Routers (MX, PTX, T4000-series)

Expertise with Installation, configuration and maintenance of Cisco Switches (6500,3560, 2960, 1900 series); Nexus 2000, 9000 series switches while implementing advanced features like VDC, VPC, OTV and Fabric Path and Juniper EX Switches (4300, 4550, 9200), QFX Switches (5100,5200,10000), OCX1100 series.

Lead the IWAN (Intelligent WAN - Cisco SD-WAN) and VPN (Secure Transport) for enterprise networks working with Cisco ISR 4k,1k routers

Expertise with Installation of Arista 7250QX series switches on Spine Platform, Deploying and decommission of VLANs on Nexus 9K, 7K, 5K and its downstream devices and update DNS records, and release IP addresses when the VMs are taken down by using Infoblox

Experience in configuration and troubleshooting of Layer 3 protocols (ISIS, OSPF, EIGRP, BGP and RIP) and Layer 2 features (VLAN, PORT SECURITY [802.1X], STP, RSTP, MST, VTP, ARP, Port Security, HSRP, VRRP. In-depth knowledge and experience on IP Addressing, Subnetting, VLSM, and ARP, Ping concept. Working knowledge on OSI model, TCP/IP, 802.1q.

Experience in monitoring, debugging, and resolving Cisco infrastructure issues like routing, Network Hardware/Software failure, configuration, WAN outages, and performance issues.

Working experience on WAN technologies like MPLS, Frame Relay, PPP, HDLC, T1, DS3, ADCCP.

Working experience on Cisco Virtual Office solution. Sound knowledge of Multicasting (IGMP, PIM), QOS (Queuing, Marking) and MPLS (LDP, L3VPN) and virtual port channel configuration.

Experience in implementing site-to-site and remote access VPN Technologies using GRE, IPSEC & MPLS. Establishing VPN Tunnels using IPSec encryption standards and also configuring and implementing site-to-site VPN. Analyzing traffic behaviors using Wireshark and Solar winds.

Strong troubleshooting skills using Packet capture in Cisco devices and FW monitor and TCP dump in Checkpoint devices and analyzing them in Wire shark. Created detailed network documentation for LAN, WAN and Wireless environments. Troubleshot various tickets associated to tier 3 LAN, WAN and Wireless issues with Meraki MR42E

Responsible for wireless configuration, implementation of wireless solutions, and remote troubleshooting. Hands on Experience with Cisco Wireless Controllers 5500's and 2500's and coming to access points, worked on 3700's, 3500's and 1142 access points.

Configured High availability, User ID on Palo Alto firewall. Configuring rules and Maintaining Palo Alto Firewalls & Analysis of firewall logs using various tools. Demonstrated experience in developing, implementing, auditing Checkpoint firewall (R77.30) configurations and analyzing, optimizing rule sets.

Experience with convert Checkpoint VPN rules over to the Cisco ASA solution. Migration with both Checkpoint and Palo Alto rules. Extensive experience with Check Point and CISCO Security Firewall Configurations and network configurations, Strong TCP/IP understanding. Knowledge of debugging Check Point Firewall.

Installed, Configured and currently maintaining Check Point Firewalls (R76 Gaia, R75.40, R75 and R70) in a Distributed Deployment and High Availability Redundancy Scenario. Implementation and administration of Check Point Firewalls & network Management.

Experience in Network Management Tools and sniffers like SNMP, HP-Open view, Wireshark and Cisco works to support 24 x 7 Network Operation Center.

Configure all Palo Alto Networks Firewall models (PA-2k, PA-3k, PA-5k etc.) as well as a centralized management system (Panorama) to manage large scale firewall deployments. Network monitoring and debugging tools: SevOne, Netscout, Wireshark. Hands-on experience in using network monitoring tool Solar winds Orion.

Experience in physical cabling, IP addressing and subnetting with VLSM, configuring and supporting TCP/IP, DNS, installing and configuring proxies. Access control server configuration for RADIUS & TACAS+. Hands-on experience using Cisco Virtual Switching System (VSS).

Good knowledge on Bluecoat proxy server SG. Worked on riverbed steel head CX/GX models. Worked on Deep Packet Inspection (DPI) with riverbed Steelhead platform. Experience in configuring and Troubleshooting BIG-IP F5 load balancer LTM & GTM.

Basic and advance F5 load balancer configurations, including migrating configurations from Cisco ACE to F5 and general troubleshooting of the F5 load balancers

Complete basic configurations on the F5 Big-IP LTMs and GTM load balancer on existing network to split traffic on web-servers. Ability to Install, Manage & Troubleshoot Large Networks & Systems Administration on Windows & Linux platforms in Development, Lab & Production Environments.

Education Details:

Bachelor’s in Electrical & Electronics Engineering from St. Martins Engineering College, India.

Master’s in Information Technology from Valparaiso University, Indiana, USA.

Technical Skills:

Cisco Platforms

Cisco routers (ASR 9K,1K 7600,7200, 3900, 3600, 2800, 2600, 2500, 1800 series) & Cisco Nexus 9k,7k,5k,2k, Catalyst switches (6500, 4900, 3750, 3500, 4500, 2900, 6807,9000 series)

Juniper Platforms

SRX, MX, EX Series Routers and Switches

Networking Concepts

Access-lists, Routing, Switching, Subnetting, Designing, CSU/DSU, IPSec, VLAN, VPN, WEP, WAP, MPLS, VoIP, Bluetooth, Wi-Fi

Firewall

Checkpoint, Cisco ASA, Palo Alto.

Network Tools

Solar Winds, SNMP, Cisco Works, Wireshark

Load Balancers

Cisco CSM, ACE, F5 Networks (Big-IP)

WAN technologies

Frame Relay, ISDN, ATM, MPLS, leased lines & exposure to PPP, DS1, DS3, OC3, T1 /T3 & SONET

LAN technologies

Ethernet, Fast Ethernet, Gigabit Ethernet, & 10 Gigabit Ethernet, Port- channel, VLANS, VTP, STP, RSTP, 802.1Q

Security Protocols

IKE, IPSEC, SSL-VPN

Networking Protocols

RIP, OSPF, EIGRP, BGP, STP, RSTP, VLANs, VTP, PAGP, LACP, MPLS, HSRP, VRRP, GLBP, TACACS+, Radius, AAA, IPv4 and IPv6

Operating System

Windows 7/XP, MAC OS X, Windows Server 2008/2003, Linux, Unix

Professional Experience:

Sutter Health, Sacramento, CA Aug 2018 - Present

Sr. Network Engineer

Responsibilities:

Experience in Cisco Physical cabling, IP addressing, Wide Area Network configurations (Frame-relay & MPLS), Routing protocol configurations (RIP, EIGRP, OSPF, and BGP). Proficiency in configuration of VLAN setup on various CISCO Routers and Switches.

Hands-on configuration and experience in setting up Cisco routers to perform functions at the Access, Distribution, and Core layers. Knowledge of implementing and troubleshooting complex layer 2 technologies such as VLAN Trunks, VTP Ether channel, STP, RSTP and MST.

Hardware upgrades includes Cisco switches from individual switches to Stacks of 3950 series, from 4500 series switches to 9400 series switches and more. Software upgrades includes upgrading a variety series of switches to latest updated software for ISE deployments.

Extensive hand on experience with complex routed LAN networks, CISCO Routers and Switches. Worked on ISE 802.1X, ISE wired/wireless guest and ISE trust sec implementations.

Exposure to multiple technologies and builds/troubleshooting: VSAN/NSX/SDA/VXLAN, etc. Upgrade Cisco 6500-E, 3560, and 2960 switches to IOS software that is on the ISE compatibility matrix.

Worked extensively with Nexus 9K, Catalyst 3K, 6K and ASR 1K.

Create and test Cisco router and switching operations using OSPF routing protocol, ASA Firewalls, and MPLS switching for stable VPNs.

Deployment, configuration, and management of 802.1x solutions to include Cisco Identity Services Engine (ISE), ACS (Radius and TACACS+), and Cisco Prime Infrastructure. Address, ISE Endpoint Information, which is used to estimate the failure, risks before change windows.

Installing, configuring, and maintaining Cisco Switches (2900, 3500,7600, 3700 series, 6500, 9400 series), Cisco Routers (4800, 3800, 3600). Configure Palo Alto Panorama Console to maintain and control all Infrastructure firewall templates.

Managed all network and devices to include Cisco routers, switches, VPNs, SSL, Cisco PIX, Cisco ASA, as well as content delivery networks (CSS, Citrix Net Scaler and F5 Big IP LTM and GTM 1600 and 3400 load balancers) enterprise environment.

Manage project task to migrate from Cisco ASA firewalls to Check Point firewalls. Deploying of Cisco ISE on Nexus 5000/7000 routers, Cisco switches, and Cisco ASA and Firepower firewalls. Executing RADIUS pre-deployment tasks like ISE setup, loading templates into Cisco Prime.

Implemented Zone Based Firewalls and Security Rules on the Palo Alto Firewall. Exposure to wildfire feature of Palo Alto. Supported Blue Coat Proxy in explicit mode for users trying to access Internet from Corp Network. Editing and Changing Palo Alto Polices and Monitoring threats on firewalls.

Analyzed traffic pattern and implemented URL filtering using the Palo Alto Firewall. Good understanding of Wildfire and creating various policies on Palo Alto (PA 5050, PA 500).

Maintaining and Configuring Palo Alto Firewall Platform Panorama with Dual Authentication and User Authentication and User. Configuring network interfaces, static routes, NAT rules in panorama and thereafter pushing to individual Palo alto devices.

Performing the software upgrade from version 7 to 8.0.2 on panorama and VM-300 series Palo alto firewalls. Performed centralized control of next-generation firewalls at internet edge, in the data center, and in the private and public cloud deployments using Panorama 8.1

Experience with deployment of Palo Alto firewalls for different NAT, video conferencing traffic

secured all traffic flow between riverbed Steelheads over private MPLS and performed optimization for demanding security protocols such as SSL/TLS and HTTPS

Performed data streamlining, transport stream lining, application stream lining on riverbed steel head

Experience in configuring and Troubleshooting BIG-IP F5 load balancer LTM & GTM.

Basic and advance F5 load balancer configurations, including migrating configurations from Cisco ACE to F5 and general troubleshooting of the F5 load balancers

Complete basic configurations on the F5 Big-IP LTMs and GTM load balancer on existing network to split traffic on web-servers.

Design and implement fiber and copper cable requests for connectivity within the data center.

Environment: Cisco 2948/3560/4500/3560/3750/3550/3500/2960 6500 switches and Cisco3640 /12000 /7200/ 3845/3600/2800 routers, Cisco Nexus 7K/5K, Cisco ASA 500, F5 BIGIP LTM, RIP, OSPF, BGP, EIGRP, Cisco ASA, Palo alto Panorama & wildfire.

Imprivata, Lexington, MA Jul 17 – Jul 18

Sr. Firewall Security Engineer

Responsibilities:

Installing and configuration and troubleshooting of various Cisco switches like 2960 X series, 2960 L series, 3850 series, Nexus 2000, 5000 & 9000 series.

Worked as a team with other engineers to design, install, implement, and configure ASR 9K Network for interconnectivity, and egress redundancy. Worked on the Cisco ASR 9006 and Cisco ASR 9001 Routers at CORE level.

Deploying and decommission of VLANs on Nexus 9K, 7K, 5K and its downstream devices and also configure 2k, 3k,7k series Routers. Design and implementation engineer for data center with 425 customers and performing tech refresh on all End of Cycle and End of Support devices

Migrated 7613 chassis with ASR 9001 chassis at core level and catalyst 6503 with Nexus 7k,5k and 2k as fix extender in distribution level in data center

Configured and monitored network and enforce business policies through Cisco Intelligent WAN (IWAN). Using GUI. Worked on the Cisco I wan routers like Meraki MX 400. Configuration of cisco meraki wireless security MX (64H,84). Multivendor Hybrid clouds management Using Infoblox management tools.

Improved the Datacenter efficiency by Infoblox ip address management in seconds. Routing related tasks included providing Cisco router configuration and change management, providing technical support for Cisco Router configurations and installation for Customer.

Configuring IP RIP, EIGRP, OSPF and BGP. Configuring routing policy for BGP. Switching related tasks included implementing VLANS and configuring ISL trunk on Fast-Ethernet channel between switches. Working with BGP, OSPF protocols in DMVPN, MPLS Cloud.

Providing daily network support for national wide area network consisting of DMVPN, MPLS, VPN and point-to-point site. Establishing VPN Tunnels using IPSec encryption standards and also configuring and implementing site-to-site VPN. VPN Configuration for Remote client login with IPSec Implementation. Configuring access servers to perform reverse telnet and configuring AAA.

Configuring static NAT, dynamic NAT, inside Global Address Overloading, TCP overload distribution, Overlapping Address Translation. Experience in troubleshooting VLAN, STP (Spanning tree protocol), & Switch Trunk and IP subnet issues. Designed VLAN’s and VTP topology, troubleshooting IP addressing issues and Updating IOS images.

Configuring GLBP, VLAN TRUNKING 802.1Q, STP, Port security on Catalyst 6500 switches. Responsible for wireless configuration, implementation of wireless solutions, and remote troubleshooting. Experience with Cisco Wireless Controllers 5500's and 2500's and coming to access points, worked on 3700's, 3500's and 1142 access points.

Performed DHCP configuration using Infoblox and deployed TACACS for accounting and authorization implementations. Managed IP addressing and Sub Netting using Infoblox. Managed successful delivery of massive security response portfolio including Splunk, Cisco ISE, and Infoblox.

Datacenter experience create new cable run list (L1), document runbook and Solution planning and upgrading, architect VXLAN, ACI and ASA cluster firewall with NAC, ISE. Deployed Cisco ISE integration with LDAP for domain user authentication

Design, setup and configure Cisco wireless networking that supports open or secured access. Troubleshooting failed radius authentication on wired, wireless and guest Wi-Fi in Cisco ISE.

Worked with implementation of Cisco Meraki wireless environments. Configuring High availability on Cisco WLC's, adding Access points on Cisco wireless controller.

Configuration, Troubleshooting and Maintenance of Palo Alto Firewalls (160+ firewalls) - PA200, PA2000 series, PA3000 series, PA4000 series and PA5000 series

Worked on User-ID to collect user-mapping information. Used App-ID to determine that encryption (SSL or SSH) is in use. Worked on App-ID to match Traffic against policy to check whether it is allowed on the network.

Configuring rules and Maintaining Palo Alto Firewalls & Analysis of firewall logs using various tools. Configured the Firepower chassis in clustered and then after HA mode to meet the clients ever changing design requirements.

Experience with Cisco Firepower 9300 and 4120 Fire Sight. Complete implementation of Firepower Firewall protects threat from External attack. Unified Threat Management, Configuration of Remote VPN connectivity.

Configure the Firepower chassis in clustered and then after HA mode to meet the clients ever changing design requirements. Configured Cisco AMP for endpoint security systems.

Use configuration text files and screen shots with eventual access into the Palo Alto firewall to map objects, firewall rules, and NAT configuration to the Cisco world

Migrate 40 NAT statements from Palo Alto NAT logic to Cisco NAT logic and documentation in spreadsheet including Static and Dynamic NAT with customer MAC addresses on some interfaces

Understand OSPF configuration and authentication settings to migrate routing over to the Firepower platform

Environment: Router series (2800, 3800, 7200) and switch series (3750, 3550, 4509E, 6509E), SRX 550firewall, Palo Alto (PA-4000/PA-2000/PA-3020), Juniper EX, Routing Protocols (EIGRP, OSPF, BGP), Switching protocols (VTP, STP), Site to Site VPN, Remote Access VPN

Atos, Irving, TX. Mar 16 – Jun 17

Sr. Network Engineer

Responsibilities:

Design, configure, and administer Juniper MX routers, SRX Firewalls, Cisco routers & switches.

Design and configuring of OSPF, BGP on Juniper Router and SRX Firewalls

Configuration and management of network routers (Cisco 6500, 7K; Juniper MX) and switches (Cisco 3850, 3750X, 3750, 3550; Juniper EX).

Installation & Maintenance of Juniper switches routers &firewalls. Implementing and maintaining WAN/LAN and WLAN networks in different diagrams. Implemented various EX, SRX & J series Juniper devices.

Troubleshooting for Layer 2 LAN technologies including but not limited to Ethernet (Switched, Fast E, GigE), Spanning-Tree, VLANs, VTP, and Trunking (802.1q).

Experience in Network Management Tools and sniffers like SNMP, HP-Open view, Wireshark and Cisco works to support 24 x 7 Network Operation Center.

Configuration and Maintenance of DNS/DHCP server with Infoblox appliance.

Experience in installing, configuring and managing AAA Authentication servers RADIUS & TACAS+, DNS and DHCP servers and management by means of Infoblox and Active Directory Database.

Daily tasks consist of design, engineer, implement, support and document for LAN/WAN, routing, switching, VPN configuration, firewalls, including Production and Non-Production Data-Centers.

Worked on FTP, HTTP, DNS, DHCP servers in windows server-client environment with resource allocation to desired Virtual LANs of network.

Hands on experience in implementation and management of Wireless networks, which includes Cisco Light Weight Access Points (LWAP) and Cisco Wireless Controllers

Experience in installing, configuring and managing AAA Authentication servers RADIUS & TACAS+, DNS and DHCP servers and management by means of Infoblox and Active Directory Database

Strong hands on and exposure to Checkpoint on a regular basis.

Firewall worked upon includes Checkpoint (R77 GAiA GUI) Focused on building new content, Created and resolved Checkpoint Firewalls Rules, Routing, Pushed Policy.

Created and resolved Checkpoint Customer Orders, and Request Orders

Researched, designed, and replaced aging Checkpoint firewall architecture with new SRX appliances serving as firewalls

Install and support various MPLS/BGP, Metro Ethernet deployments and configure routing and switching platforms and Aruba Wireless Solutions to support Academy's store expansions across 17 states.

Configured ACL's for Internet requests to Server Farm in LAN and DMZ.

Installed new networks, VoIP systems, managed Active Directory and Exchange systems. Provided prompt escalation of issues to both management and clients.

Configured VPN, clustering and ISP redundancy in Checkpoint firewall. Configured, maintained and troubleshooting IPS and IPS-1 in Checkpoint

Environment: Cisco 2948 / 3560 / 4500 / 3550 / 3500 / 2960/ 6500 switches and Cisco 7200 / 3845 / 3600, Juniper MX routers, Juniper EX Switches, SRX Firewall, Checkpoint, Infoblox, windows server 2003/2008.

State of NY- DOHMH, New York Mar 14 – Feb 16

Sr. Network Engineer

Responsibilities:

Managing the service request tickets within the phases of troubleshooting, maintenance, upgrades, fixes, patches and providing all-round technical support.

Commissioning and Decommissioning of the MPLS circuits for various field offices.

Preparing feasibility report for various upgrades and installations.

Ensure Network, system and data availability and integrity through preventive maintenance and upgrade

Troubleshooting complex networks layer 1, 2 to layer 3 (routing with MPLS, BGP, EIGRP, OSPF) technical issues.

Providing support to networks containing more than 2000 Cisco devices.

Performing troubleshooting for IOS related bugs by analyzing history and related notes.

Carrying out documentation for tracking network issue symptoms and large-scale technical escalations.

Involved in L2/L3 Switching Technology Administration including creating and managing VLANs, Port security, Trucking, STP, Inter-VLan routing, LAN security.

Worked on the security levels with RADIUS, TACACS+.

Modified internal infrastructure by adding switches to support server farms and added servers to existing DMZ environments to support new and existing application platforms.

Configured switches with port security and 802.1 x for enhancing customer’s security.

Monitored network for optimum traffic distribution and load balancing using Solar winds.

Validate existing infrastructure and recommend new network designs.

Created scripts to monitor CPU/Memory on various low-end routers in the network.

Configuring and troubleshooting multi-customer network environment.

Involved in network monitoring, alarm notification and acknowledgement.

Implementing new/changing existing data networks for various projects as per the requirement.

Installed and maintained local printer as well as network printers.

Completed service requests (i.e. – IP readdressing, bandwidth upgrades, IOS/platform upgrades, etc.)

Identify, design and implement flexible, responsive, and secure technology services

Handled installation of Windows NT Server and Windows NT Workstations.

Handled Tech Support as it relates to LAN & WAN systems

Environment: Cisco Routers (2500, 2600, 7200) & Switches (1900, 2900, 6500), BGP, OSPF, RIP, VLAN, Trunking, MPLS VPN, IPSEC, Ether channel, LACP, PAGP, NAT, Access-lists and Windows XP Professional

Birla Soft, India Aug 11 – Dec 13

Network Engineer

Responsibilities:

Configuring/Troubleshoot issues with the following types of routers Cisco (7200, 1700, 2800 series), to include: bridging, switching, routing, Ethernet, NAT, and DHCP, as well as assisting with customer LAN /MAN, router/firewalls.

Wrote IOS and CAT OS upgrade procedures and Pre/Post checks for customer production upgrades.

Excellent Troubleshooting Skills and Customer Centric approach.

Switches Replace branch hardware with new 2851 routers and 2960 switches.

Implemented Cisco Wireless Access Points and WLC’s at various corporate sites fort 11n Infrastructure and its legacy technologies.

Provided estimated bandwidth requirements for data replication, to best determine adequate timing for migration service levels

Configuring HSRP between VLANs, Configuring Ether-Channels, Port Channel on 6500 catalysts

Configuring, managing and troubleshooting networks using routing protocols like RIP, EIGRP and OSPF (Single Area and Multi Area).

Configured OSPF on CISCO devices with multiple routing processes and redistributed them. Tested and hands on experience in multi area OSPF topologies.

Configured VLANs with 802.1q tagging. Configured Trunk groups, ether channels, and Spanning tree for creating Access/distribution and core layer switching architecture.

Assisted in network engineering efforts consistent with the infrastructure of an Internet Service Provider and support of such network services. Helped in designing and implementation of VLAN for the new users.

Installation and Configuration of various types of Personal Computers and Printers. Installation of different operating systems on Intel based PC's.

Installed Hard disks, Floppy drives, CD Drives, Sound Blaster cards, CPU, Memory, Power supply unit, Network card, Video graphics card, Hard disk controller card on PC systems.

Troubleshooting of personal computers. On line Support to customers concerning their computer problems.

Assisted with troubleshooting all network issues with routers and switches when necessary and consulted with on call tech as needed for client.

Monitor, troubleshoot, test and resolve Frame Relay, ATM, MLPPP, PPP, and Dial-up.

Configuring Vlan’s, VTP’s, enabling trunks between switches.

Environment: OSPF, RIPv2, BGP, IGRP, LAN, WAN, RADIUS, TACACS, VLAN, Cisco Works, HSRP, CISCO 2600, 2800, 3600, NAT, Static route, Switching.



Contact this candidate