Kunal Tyagi
E-Mail: *************@*****.*** Mobile No: +919*********
Career Objective
Professional with 18+ years of experience in Solution Design and infrastructure Architect. Worked on cutting edge technologies, in high-pressure situations collaborating with global teams for global customers. I have been consistent performer exceeding expectation and meeting deadlines in my commitments. I would prefer having a long tenure with an organization, which provides excellent technical growth, challenging work opportunities, appropriate compensation and work benefits on per with the industry standards.
Summary
18+Years Experience in Data Center designing, Cisco ACI, Spine and Leaf Network, VXLAN, MPBGP EVPN, Private Cloud and campus designing (LAN, WAN, security, f5 LTM, GTM, 3DNS, Cisco ACE, brocade Load balance), Cisco Nexus Cisco ASA, IDS/IPS, Cisco fire Power, VMware, and Holding CCIE SP LAB CCIE SP#40852, vcp6-641, CSR router.
Practical experience on Design, deploy on Cisco ACI (Single Fabric, Multi Pod Fabric )
Practical understanding of VxLAN implementation and concepts
Proven experience of working on F5 (LTM) and DNS (GTM)
Working on SDN and NFV,
Good Knowledge of High Level and Low-level Network Design Creation.
Experience in designing UCS and VMware NSX-V and Understanding on V-Center and EXI Host, VFS Cloud
Experience in Cisco SD-WAN (Viptela )
Network Device configuration validation.
Juniper MX-9600/QFX10k
AWS: VPC, Direct Connect, Transit Gateway and Dot1q BGP peering with on Prem over DC.
Multicast – IGMP, PIM
In-depth experience with TCP/IP and L3/L2 protocol (BGP, OSPF, IGMP, PIM, Multicast, VRRP, LACP, LLDP and STP) and Cisco and Arista datacentre product (Spine, Leaf) deployment in datacentre
Palo Alto firewall
Python and Ansible – Not a full-fledged coder but I consider myself as a hybrid network engineer who can work his way around python and ansible to automate housekeeping tasks which improve efficiency, like changes on ASA devices with REST API OR POSTMAN,
Designed, implemented, and supported OT network infrastructure across manufacturing plants, substations, and industrial environments.
Deployed and managed industrial firewalls (e.g., Cisco Secure Firewall, Palo Alto, Fortinet, Check Point) between IT, DMZ, and OT zones.
Designed secure remote access solutions for engineers and third-party vendors using VPN, MFA, PAM, and jump servers
Certifications
CCIE – SP #40852
CCIE - Data Center Written – 350-080
VMware NSX 4 . Professional
Training on Cisco Application Centric Infrastructure (ACI).
VSphere foundation.
Palo Alto Firewall Training
Viptela SDWAN
CCNA DevNet
Academic Qualification
B.E in Electronic and Communication from Hubli Karnataka year2001
Work Experience
Organization: KFORCE INC AT Cisco (Payroll - iPlace) – 06th Jan 2025 to till dtae
Cisco Project: Designed end-to-end network architecture, including solution finalization and design freeze, for enterprise data center environments.
Led migration of Legacy Data Centers to Cisco ACI, covering planning, execution, and validation.
Hands-on experience configuring and managing Palo Alto firewall policies, including application-based, URL filtering, and security policy implementations as per business and compliance requirements.
Prepared Bill of Materials (BOM) for new deployments, refresh projects, and data center expansions.
Worked on Data Center Refresh and DC Consolidation projects, ensuring minimal downtime and risk mitigation.
Designed and implemented Service Graphs in Cisco ACI integrating firewalls and load balancers.
Designed and implemented BGP routing for both Internet edge and internal Data Center connectivity, ensuring scalable and resilient routing architecture.
Agile tools (Jira, GIT ) and worked on sonic images
Organization: ANZ Bank – Oct 2022 to Dec 6th 2024
Designation: ENGINEER - Architect,
Design, deploy and Contribute to the development and performance of a migration plan from traditional data center network designs to VCF VMWARE NSX-T, Enabling micro segmentation at Distributed Firewall
(DFW), Creating Overlay Segment and VLAN backed segment, Built VXLAN Infrastructure on Cisco Nexus 9k, Upgrade NSX-T environment, Cisco SD-WAN Knowledge and experience, hands on experience of on Viptela vEdges Cisco WAN Edge Routers,
vManage, vSmart and vBond. Creation of templates and policy as per the design requirement and guidelines. Working on Palo Alto firewall, Cisco SDA, working on ACLMANAGER to push policy in FTD (Cisco asa firewall,), GITHUB.
Hands-on experience configuring and managing Palo Alto firewall policies, including application-based, URL filtering, and security policy implementations as per business and compliance requirements.
Worked on VMware Micro-Segmentation for enhanced workload-level security.
Designed and managed F5 LTM and GTM for local and global load balancing solutions and Content Switching in F5 LTM
Organization: Commonwealth Bank – May 2021 to OCT 2022
Designation: Systems Technical Specialist
Working on Material (BOM) and Refresh Project, DC Consolidation,
Spine and Leaf Network, VXLAN, MPBGP EVPN
Ansible automation for Network Compliance and remediation for CSR 1000
Working on Palo Alto firewall. Zero-Trust security using Micro segmentation
Organization: Barclays – April 2019 to May 2021
Designation: Network Solution Engineer.
Project: Designing of complete network architecture includes freezing of solution, Migration Legacy Data Center to Cisco ACI environment, Leaf and Spine DC (VXLAN, EVPN and MPBGP), Bill of Material (BOM) and Working on Refresh Project, DC Consolidation, working HLD and LLD, Service Graph in ACI, working on AWS project and Fortinet firewall,
Project:
1.Design, deploy and Contribute to the development and performance of a migration plan from traditional data center network designs to Cisco ACI (Which include create Cisco ACI. -Tenant. -Context (vrf). -BD: Bridge Domain (L2 or L3 or VLAN), L3 Out, IPG, EPG and Contract, Commissioning of 9K Switch’s and FEX, VPC .
2.Integrate services appliances to Cisco ACI deployments to FortiGATE Firewalls in One Arm Mode for AD project
3.Built Hong Kong DC - On ACI Fabric (Nearly 450 server migrated, F5, GTM, firewall devices)
4.Built Hadoop infrastructure on ACI Fabric.
5.Built O365 Stack – express routes
6.WebEx Project - Cisco Cloud
7.Built AWS Stack (Nearly 800 + server migrated from local DC to AWS)
8.Spin Virtual Device on Cloud Services Platform (CSR Router, F5, AVI, Fortgate, FortiManager) to built Stack for AWS, O365 and Webex Cloud service,
9.Worked on Multicast based Project
10.Juniper (MX960/480, EX/QFX),
Organization: Fidelity Information Services India Pvt Ltd. – Aug 2018 to Aril 2019
Designation: System Architect,
Project: Designing of complete network architecture includes freezing of solution, Bill of
Material (BOM) and Working on Refresh Project, DC Consolidation,
Spine and Leaf Network, VXLAN, MPBGP EVPN,
Low Latency network design by using Cisco Nexus 3500 series.
Multicast
Organization: Vodafone India services Pvt Ltd. – APRIL 2016 to July 2018
Designation: Manager (Architect,)
Project: Designing of complete network architecture includes freezing of solution, Bill of
Material (BOM) and Network and security Design for various customers, which
Includes solution like Data center solution (LAN, WAN, Security, server load balancer
Virtualization etc.
Designed, implemented, and supported OT network infrastructure across manufacturing plants, substations, and industrial environments.
Configured and managed industrial Ethernet networks using Cisco Industrial Ethernet (IE), Hirschmann, or other industrial switches and routers.
Implemented network segmentation based on the Purdue Enterprise Reference Architecture (Levels 0–5).Responsible for Designing Private Cloud environment for IOT customers by using the VMware NSX, Cisco UCS,
Integrated SCADA, DCS, PLC, RTU, and HMI systems while ensuring secure and resilient network connectivity.
Supported industrial communication protocols such as Modbus TCP, PROFINET, EtherNet/IP, OPC UA, DNP3, and IEC 61850.
Designed secure remote access solutions for engineers and third-party vendors using VPN, MFA, PAM, and jump servers.
Worked with OT cybersecurity teams to implement Zero Trust principles, network access control, and micro-segmentation.
Responsible for designing Cisco UCS Compute Infrastructure/VMware suites
Design End-To-End solution for new customers as per customer requirement with Network feasibility.
Responsible for Designing the GSLB solution (GTM) for different client.
Working in MPLS environment
Organization: BT e-Serv (NOV 2015 to April 2016)
Designation: Lead Consultant/Manager
Project: Designing of complete network architecture includes freezing of solution, Bill of
Material (BOM) and Network Design for various customers, which includes solution
Campus designing (WAN/ LAN, Network Security, etc.).
To prepare & deliver presentations, HLD, MLD, LLD on the designed solution specifically focusing on design aspects,
Bill of Material (BoM)
LAN and WAN Hardware refreshment project for legacy network
Rack Layout diagrams
Designing IP and VLAN schema etc.
Develop network standards, policies, and procedures based on industry best practices
Provide DMVPN solution,
Organization: FISERV India Pvt Ltd.–June 2010 to Nov 2015
Designation: Architect
Project: Responsible for 8 datacenter LAN/WAN US Based EFT Data Centers
Responsibilities as Network Consultant (Network Engineering group)
Participating in network designs as identified and plan implementations with other team members. Develop block diagrams, logic flowcharts, and detailed schematics and associated documentation
Preparing Design document HLD, LLD, BOM, Rack Layout diagram, Visio diagram,
Organization: WIPRO InfoTech
Duration: May 9th, 2006 to March 2010
Designation: Senior Engineer in Network Management for different customer
Project: Bits Pilani goa campus, Goa
Responsibilities as Senior Engineer in Network Management
Planning, Implementation, maintenance, & operation of Core, Distribution as Well as Access layer devices at Data Center & all Locations.
Designing & Troubleshooting of LAN, MAN, WAN, Datacenters (Data Networks
Infrastructure) etc.
Implementation of the firewall policy as per the customer requirement.
Designing & Troubleshooting of Voice.
Organization: Wipro Infotech Ltd (As a Retainer)
Duration: July 20th 2004 to 8th may 2006
Designation: Network Engineer
Project: ICICI bank Ltd
Responsibilities as Engineer in Network Management
Provisioned, commissioned, installed and monitored new branch network
Equipment’s such as routers, switches and modems for WAN and LAN
Connectivity
Designed and implemented several WAN designs – non-redundant remote sites
Redundant single carrier with ISDN dials back-up remote sites
Personal Profile
Name: Kunal Tyagi
Sex: Male
(Kunal Tyagi)