Maulik Patel
Summary
Network Security Consultant with 7+ years of IT experience with a focus on designing and developing security solutions.
Strong knowledge based in the planning, design, and implementation of Information Systems and Network Technologies.
Skilled & technically proficient with multiple firewall solutions, network security, and information security practices.
Firewall technologies including general configuration, risk analysis, security policy, rules creation and modification of Check Point/Nokia Firewall VPN-1 FW-1 NGX R65, R70 & R75 Provider-1/Site Manager-1 R65, R70.30 & R75.40 Smart Domain Manager command line & GUI.
Configure all Palo Alto Networks Firewall models (PA-2k, PA-3k, PA-5k etc.) as well as a centralized management system (Panorama) to manage large scale firewall deployments.
Experienced in design, installation, configuration, administration and troubleshooting of LAN/WAN infrastructure and security using Cisco routers/Switches/firewalls.
Advanced Knowledge in IPSEC VPN design connection and protocols, IPSEC tunnel configuration, encryption and integrity protocols
Administering Firewalls access control requests to ensure security standards and policies, application security reviews using vulnerability assessment tool i.e. ISS Internet Security Systems (IBM's) for application level vulnerability assessment & Solar Winds for performance monitoring.
Knowledge of Intrusion Detection, DMZ, encryption, IPsec, proxy services, Site to Site VPN tunnels, MPLS/VPN, SSL/VPN.
Knowledge in preparing Technical Documentation and presentations using Microsoft VISIO/Office.
Strong written and verbal communication skills, self-motivated, self-managed, result oriented, practical, always looking to learn and contribute.
TECHNICAL SKILLS
CERTIFICATION
CCNP (Cisco Certified Network Professional) Routing&Switching&T-shoot certified
CCNA (Cisco Certified Network Associate) Certified
JNCIA-JUNOS (Juniper Certified Network Associate ) certified
BCNE (Brocade Certified Network Engineer)
Cloud Computing Network Certified
Python Developer Certified
Protocols
NAT, VTP, VLAN, L2TP, PPTP, RDP, TCP/IP, IPX/SPX, NetBEUI, UDP, ARP, NTP, EIGRP, OSPF, RIP, HTTP, HTTPS, FTP, POP3, SMTP, DNS, ICMP
Programming Languages
C,C++
Firewalls
Palo Alto PA-500, PA-2k, PA-3k & PA-5k series, Checkpoint Provider-1 R65/R70/R75/R77 & Cisco ASA,
Routers
Cisco 7609, 2600, 2800, 3800, 3640, Cisco 3745, 7200 Series
Switches
Cisco 3500, 5000, 6500 Catalyst Series Cisco 7000, 2000 Nexus Series
Network Equipment
CISCO 2950,3500,4500,6500 series Switches, CISCO 800, 1600, 2500, 2600,3700,3800,7200 series Routers
Operating System
Routing
Switching
Networking
Hardware
Windows XP/7/8, UNIX, Linux
OSPF, EIGRP, BGP, RIP-2, PBR, Route Filtering, Redistribution, Summarization, Static Routing
VLAN, VTP, STP, PVST+, RPVST+, Inter VLAN routing & Multi-Layer Switching, Multicast operations, Layer 3 Switches, Ether channels, Transparent Bridging
Conversant in LAN, WAN, Wi-Fi, DNS, WINS, DHCP, TCP/IP, ISCSI, Fiber, Firewalls/IPS/IDS,
Dell, HP, CISCO, IBM, SUN, Checkpoint, SonicWall, Barracuda Appliances, SOPHOS email appliances
PROFESSIONAL EXPEREINCE
HP, Houston, TX Sep 2014 -Present
Network Security /Firewall Engineer
Responsible for setting up the infrastructure environment with majority of Cisco & Palo Alto appliances apart from various other equipment.
Researched, designed, and replaced aging Checkpoint firewall architecture with new next generation Palo Alto appliances serving as firewalls and URL and application inspection.
Configuring and troubleshooting perimeter security devices such as Checkpoint NGX R77 Gaia, Provider-1/MDM, Secure Platform, Palo Alto and ASA Firewalls.
Palo Alto design and installation (Application and URL filtering, Threat Prevention, Data Filtering)
Configuring rules and Maintaining Palo Alto Firewalls & Analysis of firewall logs using various tools.
Successfully installed Palo Alto PA 3060 firewalls to protects Data Center and provided L3 support for routers/switches/firewalls
Implemented Positive Enforcement Model with the help of Palo Alto Networks.
Configured and maintained IPSEC and SSL VPN's on Palo Alto Firewalls.
Implemented Zone Based Firewalling and Security Rules on the Palo Alto Firewall
Exposure to wild fire feature of Palo Alto.
Third Party VPN migration from old data center to new data center.
Maintained and managed networks running EIGRP and BGP routing protocols.
Regularly performed firewall audits around CheckPoint Firewall-1 solutions for customers.
Provided tier 3 support for CheckPoint Firewall-1 software to support customers.
Work on Checkpoint Platform including Provider Smart Domain Manager. Worked on configuring, managing and supporting Checkpoint Gateways.
Configuration of routing protocols EIGRP and BGP for small to medium sized branches based on company branch standards, including redistribution and route maps.
Access Point refresh and implementation at various sized branches and locations.
Used network monitoring tools such as Spectrum to ensure network connectivity and protocol analysis tools to assess and pinpoint networking issues causing service disruption.
Worked with management and various departments to develop procedures and troubleshoot problems as they arose.
Build IT security infrastructure including Checkpoint, Juniper and Palo Alto firewalls
Experience in handling and installing FortiGate and TippingPoint next generation firewall
Administer, Maintain, and deploy Juniper IPS & VPN systems, and McAfee network based Data Loss Prevention (DLP) devices.
Proficient in design, implementation, management and troubleshooting of Check Point firewalls, Cisco PIX, NetScreen Firewalls, Check Point Provider-1 / VSX, Nokia VPN, Palo Alto IDS, Foundry / F5 Load Balancers, and Blue Coat Packet Shaper systems.
Configuring F5 Load Balancers: Adding virtual IPs, nodes, pools and health monitoring.
Configuring Juniper Netscreen Firewall Policies between secure zones using NSM (Network Security Manager)
Backup and restore of checkpoint and Cisco ASA Firewall policies
Handling Break/Fix situations, monitor, configure, policy creation on Checkpoint's Smart Center Server running on Secure Platform
Monitoring Traffic and Connections in Checkpoint and ASA Firewall
Manage project task to migrate from Cisco ASA firewalls to Check Point firewalls
Worked extensively in Configuring, Monitoring and Troubleshooting Cisco's ASA 5500/PIX security appliance, Failover DMZ zoning & configuring VLANs/routing/NAT with the firewalls as per the design
Work closely with network personnel to ensure dependencies are maintained.
Replaced end-of-life routers and switches within the environment.
Forsythe, Chicago, IL Nov 2011 – Aug 2014
Network Security Engineer
Implementing the necessary changes such as adding, moving and changing as per the requirements of business lines in a data center environment.
Adding and removing checkpoint firewall policies in SPLAT/IPSO R75, VSX firewalls based on the requirements of various projects.
Participated on the migration project of PIX to ASA firewalls.
Load balancing technology including algorithms and health check options.
Configuration and troubleshooting F5 LTM, GTM series like 6600, 6800 for different applications and monitoring the availability.
F5 BigIP GTM Wide IP configuration.
F5 BigIP LTM VIP configuration with health check.
F5 BigIP iRule programming and troubleshooting.
Cisco ASA Firewall troubleshooting and policy change requests for new IP segments that either come on line or that may have been altered during various planned network changes on the network.
Building site-site VPN connections for third party connectivity using ASA Firewalls.
Auditing user accounts in Checkpoint Provider-1/MDM on a monthly basis to remove unnecessary and ex-employee user accounts.
Security infrastructure engineering experience as well as a Microsoft Windows, UNIX, Checkpoint Firewalls, Juniper firewalls, PIX firewalls, Bluecoat Proxies, Juniper Intrusion Prevention devices, and wireless switch Security Management.
Experience with Juniper environment including SRX/Junos Space.
Configuring VLAN, Spanning tree, VSTP, SNMP on Juniper EX series switches
Configuring Juniper Netscreen Firewall Policies between secure zones using NSM (Network Security Manager)
Refining IPS Policy and Creating Rules according to the Security Standard.
Managed successful delivery of massive security response portfolio including Splunk, Cisco ISE.
Deploying Security Solutions in Juniper SRX and Netscreen SSG firewalls by using NSM.
Implement URL filtering requests in Bluecoat Proxy SG for website blocklist and whitelist purpose.
Conducted periodic reviews of Checkpoint firewall policies rule base for rules consolidation and cleanup in coordination with stakeholders using Firemon tool.
Worked primarily as a part of the security team and daily tasks included firewall rule analysis, rule modification and administration.
Managing and implementation of firewalls requests based on the requirements of various departments and business lines.
Monitoring the network traffic with the help of Qradar and Cisco IPS event viewer.
Co-ordinate with data center team for any kind new installations, remote support and device RMA's.
Implementing and troubleshooting network issues for various business lines and making sure everything is in place.
Capital One,Richmond,VA Nov 2010 –Oct 2011
Network Security Admin
Configuration and troubleshooting L3 switches with VLAN, STP, SPAN, ETHERCHANNEL, HSRP, VRRP and GLBP
Assisted in troubleshooting complex layer 1, 2 and 3 connectivity using WireShark protocol analyzer and recommended solution for better performance
Working with Cisco ISE / FWSM
Monitor devices in Netcool and Event Manager
Implemented Windows NT domain, domain name services, e-mail, Web, and FTP services
Perform risk assessments and execute tests of data processing system to ensure functioning of data processing activities and security measures
Perform Firewall OS upgrades using CLI, Splat and Voyager GUI
Built and support VRRP / Cluster based HA of Checkpoint firewalls
Perform Checkpoint and PIX firewall/IDS design, integration and implementation for Cyber Trap client networks
Working experience with A10 and F5 Load Balancer.
Experience with convert Checkpoint VPN rules over to the Cisco ASA solution. Migration with both Checkpoint and Cisco ASA VPN experience.
Configuring, Administering and troubleshooting the Checkpoint and ASA firewall
Configure and troubleshoot Remote access and site to site-in Checkpoint & ASA firewalls
Hands on experience and good working knowledge with Checkpoint Firewall policy provisioning
Worked with Remote Assistance through Windows Remote desktop and NetMeeting Remote Assistance using Wi-Fi Security, Windows XP, MS Office 2007, Windows 2003 Active Directory, Windows SharePoint Services, Exchange 2003, Congo’s BI-8 and LAN/WAN
Configured remote access support using PPP, VPN over dial-up, LAN and WAN
Configured Cisco ASA and Checkpoint firewall layers to secure the infrastructure for the Data Center.
Migrated firewalls from ASA to Checkpoint.
Drafted, installed, and provisioned ASA and Checkpoint firewall rules and policies.
Maintained, configured, and installed Cisco and Juniper routers and switches: 7500/catalyst 6500/RV320/2960/catalyst 3550/12410, 12816, 1204 series, Nexus 7k and 5k, WLC, and ASA 5540
Involved in Data Center migrations. Handled proper management, maintenance, configuration, and altered management of firewall structure.
Configured Cisco ASA and Checkpoint firewall layers securing existing Data Center infrastructure. Migrated information security from Cisco PIX to ASA5500 with LAN-failover platform.
Used Unified Threat Firewall Management Software with a Cisco infrastructure in and between multiple sites
Responsible for the Windows environment, including backup, disaster recovery and network security
Worked on Mcafee Data loss prevention endpoint (DLP)
Installed and Configured Checkpoint Firewall in Internet Edge
Configured and Deployed Checkpoint VSX on Smart dashboard R71, R75,R77.20, R77.30 GAIA
Experience with IP Address management tools and their allocations
Experience with convert Checkpoint VPN rules over to the Cisco ASA solution. Migration with Cisco ASA VPN experience
Experience in building IPsec VPN tunnels.
Experienced in GNS 3 for creating networks and packets.
Mangaro Systems, India Nov 2008 –Sep 2010
Network Support Executive
Help negotiate hardware, software, and circuit contracts for customers
Configuring Port Mirroring, VLAN, STP, RSTP, SNMP, and Routing Policies on switches
Maintaining all the network devices routers, firewall, switches
Configuring NAT and Route-map on Cisco routers Implemented and managed Norton’s corporate anti-virus solution.
Implemented the company dial up networking solution utilizing a Cisco 3600 with 24 digital modems and a PRI.
Migrated the company from bay networks 100mbit hubs to HP managed switches.
Incorporated VLANS to segment traffic on managed switches.
Manage Checkpoint 2000 v.4.1 firewall to include:
Usage of firewall log for investigative and troubleshooting purposes.
Use of TCP Dump to troubleshoot access issues.
Upgrading IPSO on Nokia IP440 security platform.
Installing service pack upgrades.
Configure Cisco VPN 3000 Concentrator to allow VPN clients
Redistribution of routing protocols and Frame-Relay configuration
Network Migration from L2PT to OSPF
Implemented SecuRemote VPN for high speed remote access.
Configuring VRRP, Static route, BGP, Routing policies, ACL
Preparing reports of the daily activities within the datacenter
Coordinating with Service providers & Clients on various implementations
Managing various activities in setting up Data Centers & Disaster recovery centers
Knowledge in OSPF, EIGRP and RIP
Knowledge in Dynamic routing protocols
Preparation of all Branches Link up time/down time report to maintain SLA with Customer
Build and maintain Visio documentations for Clients
Troubleshoot Windows 2000 Servers and streamlining the user policy.
Managing User accounts using Active Directory
Implementation of TCP/IP & related Services-DHCP/DNS/WINS