SUSHMITHA
Network Engineer
C: +1-203-***-**** • E-mail: *********@*****.***
Professional Summary:
An enthusiastic and hardworking network professional with an experience of 8+ years and proficient hands-on experience in the areas of Routing, Troubleshooting and Switching.
Knowledge on configuring Cisco Catalyst 2950, 3750, 4500, 6500 and Nexus 3000, 5000, 6000, 7000 series switches and Cisco 2500, 2800, 3600, 3800, 7200 series routers, Load Balancers & Cisco Firewalls.
Experience working on Cisco ASR 9001 & ASR 1006.
Experience in configuring and troubleshooting Static and Dynamic protocols like OSPF, RIP, BGP, IS-IS, SNMP, EIGRP and Switching protocols like STP, RSTP, VSTP, MSTP, VTP.
Implementation, working analysis, troubleshooting and documentation of LAN, WLAN & WAN architecture with excellent work experience on IP series.
Expertise in L2VPN, L3VPN, DMVPN, VPLS, Multicast VPNs, SSL VPNs.
Comprehensive understanding of OSI Model, TCP/IP protocol suite (IP, ARP, ICMP, TCP, UDP, SNMP, FTP, TFTP).
Having vast experience in designing and configuring of Switches for VLANS and inter-switch communications.
Familiarity with Cat 5/6 and fiber optic cabling for network communication capabilities.
Proficient expertise in deploying, designing, troubleshooting and administering data networks for organizations in Cisco Wireless Networks: LWAPP, WLC, WCS, Standalone APs, Client Roaming, Wireless Security Basics, Dual band WAPs, RF spectrum characteristics, AP groups, WLANS, Cisco Prime Site Maps.
Experience in Network Security that includes perimeter security for Internet, Extranet, DMZ, Internal Server farms, Web-traffic security with Proxies, Web Application firewalls. Worked and migrated multi-vendor equipment and Next generation firewall technologies. Worked on ASA, Checkpoint and Palo Alto firewalls. Experience on MWG, Bluecoat proxies.
Implementation of HSRP, VRRP for Default Gateway Redundancy.
Good knowledge on IEEE 802.12.1, IEEE 802.11a, b, g, n, WIFI, Ethernet and mesh networks.
Experience in Designing and assisting in deploying enterprise wide Network Security and High Availability Solutions for ASA.
Hands on experience on dealing with Microsoft Azure cloud computing including implementing access lists in the Network Security Group.
Excellent knowledge on configuring of SSH, TFTP, FTP, DNS, DHCP and Syslog and Experience with DNS/DFS/DHCP/WINS Standardizations and Implementations.
Hands-on experience in Tier II ISP Routing Policies, Network Architecture, IP Subnetting, VLSM, TCP/IP, NAT, DHCP, DNS, GigE circuits, Firewalls.
Experience on frame-relay, GRE tunnels, Remote Access VPN and Site-to-Site VPN.
Knowledge on Ethernet, ISDN, ADSL and wireless technologies.
Expertise in creating groups and pruning traffic flow using VLAN, VTP, ISL, 802.1Q.
Worked extensively in Configuring, Monitoring and Troubleshooting Cisco's ASA 5500/PIX security appliance, Failover DMZ zoning & configuring VLANs/routing/NAT with the firewalls as per the design.
Excellent in documentation and updating client’s network documentation using VISIO.
Deployed Cisco UCS compute cluster with ESX 4.1 and ESX 5.0.
Experience in configuration of AAA with RADIUS and TACACS+.
Certifications:
Cisco Certified Network Associate (CCNA)
Technical Skills:
Routers
Cisco 6500, 4500, 3800, 3600, 2800, 2500, Nexus 7000, Nexus 6000, and Nexus 5000, and Juniper EX, QFX and Alcatel 7705 SAR series.
Switches
Cisco switches (2900, 3500, 3750, 4500, 4900 & 6500), Nexus (2248, 5548 &7010), Arista 7500, 7050,7300 series
Routing Protocols
RIP, EIGRP, OSPF & BGP, Route Filtering, Redistribution, Summarization, Static routing.
Switching Protocols
VTP, STP, RSTP, MSTP, VLANs, PAgP, and LACP.
LAN Technologies
Ethernet, Fast Ethernet, Gigabit Ethernet, NAT/PAT, FDDI.
WAN Technologies
FRAME RELAY, ISDN T1/E1, PPP, ATM, MPLS, leased lines, DSL modems.
Firewalls & Load Balancers
Cisco ASA 5585, 5550, 5540, Juniper SRX 5400, 5600, 5800, Juniper Netscreen 6500, 6000, 5400. Juniper SSG Firewalls, Check point, Palo Alto PA-3060/3000, F-5 BIG-IP LTM (3900 and 8900), A10 Load Balancers.
VOIP Devices & Wireless Technologies
Cisco IP phones, QOS, Avaya, CUCM, UCCX, CIPC and UCS.
Wireless: LWAPP, WLC, WCS, Standalone APs, Client Roaming, Wireless Security Basics, AP groups, WLANS, Cisco Prime Site Maps.
Secure Access Control Server
TACACS+/Radius.
Network management
SNMP, Cisco Works LMS, HP Open View, Solar winds, ACI, Ethereal.
Carrier Technologies
MPLS, MPLS-VPN, SONET.
Security Protocols
IKE, IPsec, SSL, AAA, Access-lists, prefix-lists.
Firewall Security Protocols
NAT, PAT, ACL.
Redundancy protocols
HSRP, VRRP, GLBP.
Monitoring Tools
Opnet, Solar winds and Infoblox.
Operating Systems
Microsoft XP/Vista/7,10, UNIX, LINUX.
Professional Experience:
Catholic Health Initiatives, NE Aug 2017 – Current
Network & System Engineer
Responsibilities:
Managing and administering Juniper SRX and Checkpoint Firewalls at various zones including DMZ, Extranet (Various Business Partners) and ASZ and internal.
Worked with site-to-site large scale network deployment and troubleshooting issues with all the site involved.
Mentoring the partner technical engineer on executing the Voucher Guidelines for ISE Trustsec activation, ISE Wireless guest management activation.
Implemented Cisco ISE for wired and wireless user authentication utilizing certificates and MAB for all known company assets.
Implementing Security Solutions in Juniper SRX and NetScreen SSG firewalls by using NSM.
Juniper Firewall Policy management using NSM and Screen OS CLI.
Daily technical hands-on experience in the configuration, troubleshooting of Juniper SRX firewalls as well as experience working directly with the customer in a service/support environment.
Troubleshooting Firewall Connectivity related issues using Smart view tracker on Checkpoint, NSM Log viewer for Juniper Firewalls.
Designed and configured Server Load Balancing on Extreme Summit switches for corporate web servers, greatly increasing availability and speed of connectivity for customers.
Creating and provisioning Juniper SRX firewall policies.
Worked with JUNOS OS on Juniper Routers and Switches.
Experience on ASA firewall upgrades to 9.x.
Websense Web Security Gateway Installation, Upgrade & Configuration 8.4.
Maintenance and implementation of enterprise security and firewalls (Cisco ASA, Palo Alto, Websense DLP, CyberArk).
Configuration for cisco ACI, EPG's, contracts and commissioning and de-commissioning of leafs and spines. Used 9348GC-FXP for leafs and 9364C and 9508 for spines.
CyberArk upgradation from 8.X to 9.X version Deploying and decommission of VLANs on core ASR 9K, Nexus 7K, 5K, 2k and its downstream devices.
Responsible for building Global Remote VPN, Site-to-Site, Any connect and clientless SSL VPN- ASA5540.
Configured Panorama web-based management for multiple firewalls.
Worked on configuration, maintenance and administration of Palo Alto PA3000 Firewalls and migrating customers from Cisco ASA to Palo Alto in HA network.
Configuring rules and Maintaining Palo Alto Firewalls & analysis of firewall logs using various tools.
Configuring, Troubleshooting, Designation and Implementation of Aruba Wireless solution including Aruba S3500 mobility switch, Aruba 105,175,225 Campus AP, Aruba 7210,7220 Controllers.
Operational support for all Sprint retail stores. Devices consist of Aruba equipment such as Aruba7010, Aruba S1500-48p, Aruba APs (105, 205 and 225s), Aruba RAP-5s.
Installed and deployed the Controller based Aruba Wireless Access Point.
Understand the flow of traffic through the Check Point Security gateway cluster and troubleshoot connectivity issues using advanced troubleshooting from Command Line Utilities.
Install and configure Bluecoat Proxy SG in the network for web traffic management and policy configuration.
Successfully installed Palo Alto PA-3060 firewalls to protect Data Center and provided L3 support for routers/switches/firewalls.
Configuring and deploying Cisco ASA 5505; Cisco 594/294; I500 web sense manager at customer locations with minimum downtime possible.
Installed, configured and managed 2800, 3800, 3600, 7200 series Cisco routers and 2900, 3750, 6500 Cisco switches.
Active/Standby and Active/Active HA configuration on Cisco ASA Firewalls.
Configuring rules and maintaining Palo Alto firewalls and analysis of firewall logs using various tools.
Work with Software Distribution teams to develop and execute Custom Prop for Endpoint systems.
Manage and monitor security rules and policies for Endpoint Protection.
Understand different types of NAT on Cisco ASA firewalls and apply them.
Support Blue Coat Proxy in explicit mode for users trying to access Internet from Corp Network.
Support the One to One proxy migration project from legacy, end of life and proxies to Blue Coat Proxy SG units.
Configuration, operation and troubleshooting of BGP, OSPF, EIGRP, RIP, VPN routing protocol in Cisco Routers & L3 Switches.
Knowledge on SDN Networks and implementing the SD-Wan.
Configured MPLS L3 and L2 VPNs for customers.
FWSM configurations in single/multiple context with routed and transparent modes.
Environment: Juniper routers and switches, Cisco routers 7200; Cisco Catalyst switches 6500, 4500, 2950; Big-IP F5 Load Balancer, Cisco Works; MS Visio, Checkpoint, Cisco ASA and Palo Alto firewalls, Blue Coat Proxy, Cisco PIX Firewalls 535, 525 Routing Protocols OSPF, BGP, STP, VTP, VLAN, VPN, MPLS, HSRP, GLBP
Logicalis, OH Aug 2015 – July 2017
Network & System Engineer
Responsibilities:
Installation, Configuration and troubleshooting Cisco switches and Firewall on multi-mode context-based environments.
Managing a TACACS server for VPN user authentication and network devices authentication
Handled Corporate and Review Audits from the perspective of IT Security for Network Devices and Servers under our control.
Installation and Configuration of Cisco Catalyst switches 6500, 3750 & 3550 series and configured routing protocol OSPF, EIGRP, BGP with Access Control lists implemented as per Network Design Document and followed the change process as per IT policy It also includes the configuration of port channel between core switches and server distribution switches.
Involved in design and implementation of Data Center Migration, worked on implementation strategies for the expansion of the MPLS VPN networks.
Router/ Microsoft VPN Server in order to access certain limited network resources from customer locations.
This includes Artifacts for regular Health Checks, IP and System Integrity, Change management, Problem management, Logical Access Controls, Network Connectivity, Service Registration and Performance Management.
Installed and configured the Cisco routers 2800 in two different customer locations. It includes coordinating with Verizon and AT&T in order to bring the serial interface up for T3 link. Also, configuration includes frame relay, BGP and VPN tunnel on GRE.
Installation, Configuration and Administration of ADS, DNS, DHCP and Web proxy (ISA) server.
Upgrade Cisco Routers, Switches and Firewall (PIX) IOS using TFTP.
Manage Cisco Routers and troubleshoot layer1, layer2 and layer3 technologies for customer escalations
Taking Regular backups & testing the backups by restoring in test lab frequently.
Involved in designing L2VPN services and VPN-IPSEC authentication & encryption system.
Experience in HSRP standby troubleshooting & Experience in configuring & upgrading of Cisco IOS.
Installed and configured fornix 525 and two ASA 5505 in customer locations. In addition to that, two PIX firewall configured for the Guest access.
Experience in migration of Frame-relay based branches to MPLS based technology using multilayer stackable switch like 6500 series and 2800 series router.
Created engineering configuration, Security Standards, documenting processes and Network documentation using Microsoft VISIO.
Managing health check of Network devices this is involves upgrading IOS on every quarter after checking the vulnerability of IOS and reviewing the configuration.
VLAN Configurations, troubleshooting and Firewall ACLs and Object-Groups configuration and support.
Configured IPSec site-to-site VPN connection between Cisco VPN 3000 Concentrator and Cisco 3800.
Environment: Router series (2800, 3800, 7200) and switch series (3750, 3550, 4509E,6509E), Cisco PIX(525, 535), ASA(5505, 5510) firewall, Routing Protocols (EIGRP, OSPF, BGP), Switching protocols (VTP, STP), Site to Site VPN, Remote Access VPN, Cisco VPN 3000 Concentrator, Cisco ACS 4.x, TACACS.
Ventus, CT Jan 2014 – July 2015
System Engineer
Responsibilities:
Replaced old 6500 and WAN routers from DR testing site and installed Nexus 7K and ASR 1006 routers.
Involved in the configuration of the Nexus 2248 Fabric Extender (FEX) module on the Nexus 5000 to connect servers and storage devices.
Replaced 6500 from core layer and installed 3750s Switches.
Involved in Racking and Stacking of Cisco 3750 Switches and configured VLANs.
Hands on experience with F5 GTM3600 and LTM1600 configuring device pools, nodes, virtual IP’s
Implementation, configuration and support of Checkpoint and ASA firewalls for clients.
Actively use, smart view tracker, and Checkpoint CLI (to security gateways) for troubleshooting.
Work on Policy administration of Cisco and Checkpoint Firewalls
Troubleshooting end user connectivity issues through the firewalls and network
Experience with configuring FCOE using Cisco nexus 5548, VPC (Virtual Port Channel), VDC (Virtual Device Context) in Nexus 7010/7018.
Work on different networking concepts and routing protocols like BGP, EIGRP, OSPF and other LAN/WAN technologies.
Implemented standard configuration template scripts in various network devices for SNMP v2, logging, and NTP.
Modified internal infrastructure by adding switches to support server farms and added servers to existing DMZ environments to support new and existing application platforms.
Created standard access lists to allow SNMP, NTP and logging servers.
Worked on F5 LTM configuring different Load balancing methods like Round Robin, Ratio based Etc.
Experience working on F5 LTM NATs /SNATs and I Rules.
Experience with Firewall Administration, Rule Analysis and Rule Modification on cisco ASA 5540, 5585.
Responsible for Cisco ASA firewall administration across our networks.
Co-ordinate with the Data Network and Security team and come up with possible solutions.
Provide solutions to Tier 1/2 escalated issues and tickets.
Work on Physical site Inventory verification gather information of various Cisco Network devices and Security Devices to develop Run book and Spec Book.
Upgraded IOS on various Cisco Routers and Switches.
Identify additional Network operations requirement and improvement opportunity.
Environment: Nexus 5k, 7k series, Cisco Switches 3750, routing protocols BGP, OSPF, EIGRP, SNMP, NTP, Cisco ASA & Checkpoint firewall, SNMP, NTP, load balancers, firewall security protocols NAT, SNAT.
Conexon, AR Nov 2011 – Dec 2013
Network Engineer
Responsibilities:
Performed IOS upgrades/Password recovery on Catalyst 1900, 2900 series switches and 2500, 2600 series routers.
Did racking, stacking, and cabling network-based, IT systems.
Configured Access List ACL (Std., Ext, and Named) to allow users all over the company to access different applications and blocking others.
Configuring of IP Allocation and sub netting for all applications and servers and other needs throughout company using FLSM, VLSM addressing.
Troubleshot the issues related to L1 and L2 levels.
Network maintenance checks, configure and manage printers, copiers, and another miscellaneous network equipment.
Involved in trouble shooting of DNS, DHCP and other IP conflict problems.
Configuration, LAN/WAN, Switch/Routing protocols.
Troubleshooting complex LAN /WAN infrastructure that include routing protocols EIGRP, OSPF.
Configured Access-lists, Distribution-lists, Offset-lists and Route Redistribution.
Configured Ether channels, Trunks, VLans, HSRP in a LAN environment. Configured STP for loop prevention and VTP for Inter-VLAN Routing.
Configured PVSTP+ for loop prevention and VTP for Inter-VLAN Routing.
Implemented port aggregation & link negotiation using LACP and PAgP.
Responsible for Data Backup, System Update, Recovery and Restore, and Spyware removal.
Assisting Junior and Senior Engineers, on-site management of cable-wiring technicians.
Troubleshoot problems on a day to day basis and documented every issue to share it with design teams.
Providing documentation by creating MOPs and VISIO diagrams for the network designing team.
Environment: Cisco Routers 2500, 3600; Cisco Switches3500, 2900 and 1900 series; Catalyst 1900,2900 series switches; Routing protocols RIPv2, EIGRP, OSPF; Firewall Security Protocols: ACL, NAT, PAT.
Servomax India Ltd - Hyderabad Aug 2010 - Sep 2011
Jr. Network Engineer
Responsibilities:
Responsible for reporting day to day operations of all associated hubs, routers, bridges, gateways and related equipment.
Monitoring the network, troubleshooting network problems, implementing changes, communicating and working closely with vendors, customers, system administrators.
Responsible for LAN and internet connection file and print server.
Handled Tech Support as it relates to LAN & WAN systems.
Used various scanning and sniffing tools like Wire-shark.
Configured BGP for CE to PE route advertisement inside the lab environment.
Providing Tier II support in the provisioning, end-to-end test and turn-ups and maintenance of the major accounts. Optimizing Network by continuously working with customer to upgrade and optimize network and Circuit Move Add Changes including detailed design documentation.
Configured Cisco Routers for BGP, OSPF, RIP, RIPv2, EIGRP, Static and default route in a VPN environment using MPLS.
Provided Network Support in the designing and implementation of Point to Point over T1s Frame Relay, DSL over ATM and IP over Frame Relay and Gigabit Ethernet.
Network consists of Heavy Cisco equipment such as: Cisco 356*-****-**** switches, Cisco 650*-****-**** series Layer 3 switches, Cisco 3825 3640 series routers.
Worked on F5 and CSM load balancers deploying many load balancing techniques with multiple components for efficient performance.
Worked on Firewall Administration, Rule Analysis, and Rule Modification.
Environment: Cisco 3560/2950/2924/6509/6513/5500 switches, Cisco 3825/3640/7200 routers, LAN, WAN, BGP, DHCP. VPN, OSPF, RIP, EIGRP, F5 BIG-IP, LTM, GTM, Nexus Switches 5K/7K, VLAN, VTP, Checkpoint, Frame-Relay, Wireshark.
Education:
Bachelor of Technology in Electronics and Communications Engineering, India