Ayyappa Sunnam
Senior Network Engineer
Ph.no: 475-***-****
Email id: ************@*****.***
LinkedIn : https://www.linkedin.com/in/sunnam-ayyappa-882a10226/
Professional Summary:
* ***** ** ****rience in Networking, including hands - on experience in providing network installation, network integration, network support, and analysis for a broad range of LAN/WAN/MAN communication systems.
Hands-on experience with Cisco, Juniper, Arista, Palo Alto, Fortinet, F5, and Cisco ISE across enterprise and data center networking environments and Strong experience with routing and switching technologies including BGP, OSPF, EIGRP, VLANs, STP/RSTP/MSTP, HSRP, VRRP, LACP, QoS, MPLS, TCP/IP, IPv4/IPv6, and VPNs.
Experienced in SD-WAN, Zero Trust Network Access (ZTNA), Network Access Control (NAC), 802.1X, network segmentation, firewall security, IPS/IDS, and secure remote access, Hands-on experience with AWS networking, including VPC, subnets, NAT Gateway, Internet Gateway, Transit Gateway, Direct Connect, VPN, Route 53, Security Groups, and Network ACLs.
Experience with modern data center technologies including Cisco ACI, Nexus, spine-leaf architecture, Arista CloudVision, VMware NSX, VMware vSphere, and Cisco UCS, Experienced in network automation using Python, Ansible, Bash, REST APIs, JSON/YAML, Git, and CI/CD tools to improve network configuration and operational efficiency.
Experienced in enterprise network architecture, LAN/WAN design, network capacity planning, high availability, redundancy, incident management, change management, and root cause analysis (RCA) across complex production environments.
Strong knowledge of core network services and protocols including DHCP, DNS, IPAM, NTP, SNMP, Syslog, RADIUS, TACACS+, VRF, PBR, route redistribution, route filtering, and network performance optimization.
Skilled in network monitoring and troubleshooting using SolarWinds, Splunk, Wireshark, ELK/Elastic Stack, ExtraHop, Catchpoint, Cisco Prime, and other network monitoring platforms, Hands-on experience supporting Wi-Fi 6/6E enterprise wireless environments, Cisco wireless infrastructure, RF troubleshooting, and site-survey tools including Ekahau and AirMagnet.
Experienced in F5 application delivery technologies including BIG-IP LTM, GTM, and APM, supporting application load balancing, traffic management, and high availability, Adept in implementing Zero Trust Network Access (ZTNA) and managing Next-Gen Firewalls, NAC solutions (Cisco ISE/Aruba ClearPass), and SIEM tools (Splunk, QRadar) for proactive threat mitigation.
Working experience on the Juniper EX 2200 series, EX 2300 series, EX 3400 series, QFX 5120 series; MX5, MX40, PTX series, and T4000 Core Routers, Established continuous deployment (CD) pipelines with Docker, Kubernetes, Chef, and Puppet, alongside Jenkins and Ansible, to automate application deployment and improve time to production.
Thorough knowledge and hands on experience with the application of LAN Security practices such as DHCP snooping, Port Security, Dynamic ARP Inspection (DAI), IEEE 802.1X, and IP Source Guard (IPSG)
Technical Skills:
Networking: TCP/IP, IPv4/IPv6, BGP, OSPF, IS-IS, EIGRP, MPLS, VXLAN, EVPN, VRF, PBR, Route Redistribution, Route Filtering, Route Summarization, ECMP, VLAN, STP/RSTP/MSTP, HSRP, VRRP, GLBP, LACP, QoS, Multicast, IGMP
Core Network Services: DHCP, DNS, IPAM, NTP, SNMP, Syslog, RADIUS, TACACS+, AAA, ARP, ICMP, CDP, LLDP
Cisco: Catalyst, Nexus, ASR, ACI, Cisco ISE, Cisco DNA Center, SD-Access, SD-WAN
Juniper: MX, EX, QFX, SRX, Junos
SD-WAN/SASE: Cisco SD-WAN, VMware/VeloCloud, Silver Peak, SD-WAN Traffic Engineering, SASE, ZTNA
Cloud Networking: AWS VPC, Transit Gateway, Direct Connect, Route 53, VPN, Azure VNet, ExpressRoute, Azure VPN Gateway, Hybrid Cloud Networking
Network Security: Palo Alto, FortiGate, Check Point, Cisco Firepower, Cisco ISE, Aruba ClearPass, NAC, ZTNA, SASE, IPS/IDS, IPsec/SSL VPN, 802.1X, Network Segmentation
Data Center: Spine-Leaf, Cisco ACI, VXLAN/EVPN, Arista EOS, CloudVision, VMware NSX-T, Cisco UCS
Automation & IaC: Python, Ansible, Terraform, Netmiko, NAPALM, REST APIs, JSON, YAML, Git, Jenkins
Monitoring & Observability: SolarWinds, Splunk, Elastic Stack, Grafana, Prometheus, ThousandEyes, Wireshark, SNMP, NetFlow
Network Operations : Network Design & Architecture, Network Performance Optimization, Network Capacity Planning, High Availability, Network Redundancy, Root Cause Analysis (RCA), Incident Management, Problem Management, Change Management, Production Support, Network Documentation, Disaster Recovery
ITSM & Service Management: ServiceNow, ITIL, Incident Management, Problem Management, Change Management, Change Requests, Service Requests, SLA Management
Wireless: Wi-Fi 6/6E/7, Cisco Wireless, Aruba Wireless, Ekahau, AirMagnet, RF Site Surveys, WPA3, 802.1X
Load Balancing: F5 BIG-IP, LTM, GTM, APM, ADC, GSLB
Virtualization: VMware vSphere, ESXi, NSX-T, Kubernetes Networking, Docker
Automation & IaC : Jinja2, CI/CD, Network Automation, Configuration Management, Automated Network Provisioning, GitHub/GitLab
Certifications:
Cisco Certified Network Associate (CCNA)
Cisco Certified Network Professional (CCNP)
Professional Experience:
Client: Mastercard, St. Louis MO. Oct 2025-Till Date
Role: Network Engineer
Responsibilities
Responsibilities included installation, configuration, maintenance and troubleshooting of the corporate network, monitoring network performance using various network tools to ensure the availability, integrity and confidentiality of application and equipment and to provide support for Cisco network.
Performed advanced network troubleshooting, incident management, and root cause analysis (RCA) for Layer 2/Layer 3 connectivity, routing, switching, DNS, DHCP, VPN, and firewall-related production incidents.
Supported enterprise LAN/WAN network design, high availability, network redundancy, capacity planning, and performance optimization across Cisco, Juniper, Arista, and security infrastructure.
Configured and troubleshot core network services including DHCP, DNS, IPAM, SNMP, Syslog, RADIUS, TACACS+, and AAA to maintain reliable and secure network operations.
Implemented network access controls and security hardening using Cisco ISE, 802.1X, NAC, RADIUS/TACACS+, firewall policies, IPS/IDS, and network segmentation.
Automated network configuration, validation, and operational tasks using Python, Ansible, Terraform, Netmiko, REST APIs, Git, and Jenkins CI/CD pipelines.
Managed enterprise network infrastructure using Cisco, Juniper, Fortinet, and Palo Alto networking and security platforms.
Configured and troubleshot BGP, OSPF, VLANs, VPNs, NAT, PAT, DMZs, and Layer 2/Layer 3 connectivity.
Administered Palo Alto firewalls including security policies, NAT policies, URL filtering, threat prevention, and GlobalProtect VPN.
Configured and supported IPsec and SSL VPN connectivity for secure remote and site-to-site communications.
Implemented firewall security policies and DMZ zoning based on network and application requirements.
Configured OSPF and BGP across Juniper MX and SRX platforms supporting enterprise and data center connectivity.
Participated in IPv4-to-IPv6 migration, including IPv6 addressing, access-control policies, and dual-stack network configuration.
Supported data center connectivity using OSPF, OTV, HSRP, and Layer 2 extension technologies, and Supported F5 BIG-IP infrastructure and centralized management of LTM/GTM environments.
Participated in routing-protocol migration from EIGRP to OSPF to support Juniper-based network modernization.
Worked on Routing protocols Eigrp and BGP. Working on Infoblox for IPAM, DHCP and DNS. Working on Linksys, SG500, Cisco, Arista switches and Cisco routers, Implemented continuous integration automated build pipelines using Jenkins.
Environment: Checkpoint, Nexus, Cisco, ASA firewall -- ASA5545, ASA5585-SSP-20, firewall PIX-525, VPN concentrator -- Cisco 3060, check point firewall -- r77, F5 Local Traffic Managers (LTM) 5000, 7000 series, (ISE) 2.3, VLANs, STP, DNS/DHCP issues, Palo Alto firewalls, Cradle Point, FortiGate TACACs, BGP, AWS, MPLS, Firewall analyser, Wireless LAN, service desk, Cisco ISE, Cisco Prime, Jenkins.
Client: Verizon, Richardson, TX. Sept 2024-Oct 2025
Role: Network Engineer
Responsibilities
Proven track record of managing complex networks using Cisco, Juniper, Fortinet, and Palo Alto devices with deep proficiency in routing protocols (BGP, OSPF), VLANs, VPNs, and SD-WAN solutions.
Worked extensively in Configuring, Monitoring and Troubleshooting Cisco's ASA 5585 Security appliance.
Assist customers with correcting configurations of firewalls for various issues to include basic configuration, Global Protect VPNs, IPSEC VPNs, security policies, NAT policies.
Performed end-to-end troubleshooting and root cause analysis for enterprise LAN/WAN, routing, switching, firewall, VPN, DNS, DHCP, and application connectivity issues.
Implemented network changes through established change-management processes, including configuration validation, maintenance activities, implementation planning, and post-change verification.
Monitored network infrastructure using SNMP, Syslog, SolarWinds, Splunk, Wireshark, and network performance monitoring tools to proactively identify and resolve connectivity issues.
Improve perimeter security by configuring Palo Alto firewall devices application level security.
Failover DMZ zoning & configuring VLANs/routing/NATing with the firewalls as per the design.
Experience with Palo Alto Network firewalls such as security NAT, Threat prevention & URL filtering.
Configuration and troubleshooting of Firewalls ASA 5520, ASA 5510.
Configure, manage, and maintain security tools for DHHS including Palo Alto firewalls, FirePOWER (Sourcefire), Bluecoat, FireEye.
Design and Configuring of OSPF, BGP on Juniper Routers (MX960, MX480) and SRX series firewalls (SRX240, SRX550).
Configured OSPF as the IGP for both intra and inter datacenter connectivity with OTV running over the WAN for extended layer 2 network and used Localized HSRP for gateway redundancy and to aid workload mobility.
Experience with Cisco UCS, Virtual Infra on VMware, Installation, Upgrades and Patching.
Deployed BIG IP Enterprise manager to cluster all the F5 LTM, GTM, ASA, Netscreen devices for easier management and common configurations.
Involved in the migration of EIGRP to OSPF in the environment as to support the new implementation of Juniper Devices in the network.
Environment: Cisco, Juniper, Fortinet, and Palo Alto Cisco's ASA 5585, Global Protect VPNs, IPSEC VPNs, security policies, NAT & PAT policies, DMZ zoning, FirePOWER (Sourcefire), Bluecoat, FireEye, OSPF, BGP, BIG-IP,, vPE/VLAN and security cases with IXIA tool, VMware ESX, ESXi Servers, Juniper Layer 3 EX4200 & EX3200 switches, Big IP F5 LTM .
Client: Syneos Health, India Aug 2020-Jul 2023
Role: Network Engineer
Responsibilities
Implemented network solutions for EDS customers. Deliverables include a formal written proposal, detailed price quote, and network diagrams of the proposed solutions.
Design and coordinate implementation for customer access to a large-scale predominately Cisco-based router network.
Designed enterprise LAN/WAN network architectures, IP addressing schemes, routing strategies, and high-availability solutions based on customer requirements and network capacity.
Performed network capacity planning and traffic engineering across WAN and MPLS environments, optimizing BGP routing using Local Preference, MED, AS-Path Prepending, and Route Maps.
Developed network diagrams, implementation documentation, configuration standards, and technical design documents for large-scale enterprise network deployments.
Functions include determining hardware requirements, completing design and equipment documentation, developing IP addressing schemes, implementing router configurations and coordinating installations.
Part of team that designed network infrastructure in over 50 metro-areas utilizing WAN connectivity, wireless technologies, and dark fibre to provide Internet connectivity to partner ISP's and customers.
Re-engineered BGP routing (Route Maps, AS-Path prepend, MED, Local Preference) to load balance traffic across multiple ISP's links.
Configuration of AWS cloud services and deployment of AWS instance (VPC, subnets, NAT gateway, Internet gateway, Direct connect gateway, VPN, Route 53, AWS Transit Gateway, Group Security, Network ACL and AWS S3). Use of Route 53 to implement Geolocation based Routing policy.
Environment: WAN,, MPLS, TCP/IP, IPSec PIX, ACL, QoS, SNMP, VPC, subnets, NAT, EIGRP, OSPF, BGP, CISCO FIREWAL
Education Details:
Master of Science, Information Technology Management St. Francis College
Bachelor of Technology, Electrical and Electronics Engineering, TKR College of Engineering and Technology