Venkat - Network Engineer
Venkat - Network Engineer
PROFESSIONAL SUMMARY:
9+ years of experience as Network Engineer with extensive experience in various technologies such as Palo Alto, Cisco,
switching (STP, Ether Channel, VDC, VPC, FHRP, LLDP, CDP, SPAN, LACP), routing (EIGRP, BGP, OSPF, VRF, PBR, IS - IS,
redistribution, route-maps, etc.), deployment, IOS upgrading, etc. on both Catalyst and Nexus platforms.
Professionally trained in CCNP-level routing and switching curriculum.
Excellent Hands-on experience with Cisco ISE and the Migration of Wireless and TACACs to ISE.
Experience in working with Cisco Nexus Switches and Virtual Port Channel configuration.
Expertise in installing, configuring, and troubleshooting of Cisco Routers (3800, 3600, 2800, 2600, 1800, 1700, 800).
Successfully designed and delivered secure cloud solutions for some Major organizations on AWS Cloud.
In-depth knowledge on various AWS Services including EC2, VPC (NAT, Peering, VPN), IAM, EC2 Container Service,
Elastic Beanstalk, Lambda, S3, Cloud Front, Glacier, RDS, DynamoDB, ElasticCache, Redshift, Direct Connect, Route 53,
cloud watch, Cloud Formation, Cloud Trial, Opsworks, Amazon Elastic Map Reduce (EMR), AWS IoT, SNS, SQS, Lambda,
API Gateway, AWS Alexa etc.
Experience working on administering various AWS Services using AWS Console, AWS CLI.
Experience in designing and configuring of OSPF, BGP on Juniper Routers (MX960, MX480) and SRX Firewalls (SRX240,
SRX550).
Extensive experience in configuring and testing Verizon ARC BA850 Cradle Point as the turnkey networking solution
for 4G/LTE failover. Experience on MWG, Bluecoat and Zscaler proxies.
Experience working on Load BalancerF5 LTM, GTM series like 6400, 6800, and 8800.
Strong knowledge of TACACS+, RADIUS implementation in Access Control Network.
Good experience on Firewall technologies including general configuration, risk analysis, security policy, rules creation
and modification of Checkpoint R65, R70, R77, Palo Alto and Cisco ASA.
Experience in configuring all Palo Alto Networks Firewall models (PA-2k, PA-3k, PA-5k etc.) as well as a centralized
management system (Panorama) to manage large scale Firewall deployments.
Experience on dealing with VoIP information deployment including troubleshooting protocols like Session Initiation
Protocol (SIP), Real-Time Transport Protocol (RTP), Media Gateway Routing Protocol (MGRP) and Session Description
Protocol (SDP).
Advanced knowledge in Cisco ASA 5500 series and PIX installation, configuration and maintenance, configuration and
installation of IOS security features and IPS, security risk analysis, attack mitigation & penetration tests based on LPT
methodology.
Experienced in handling and installing Palo Alto Firewalls
Knowledge of implementing and troubleshooting complex layer 2 technologies such as VLAN Trunks, VTP, Ether
channel, STP, RSTP and MST. Implementation of HSRP, VRRP for Default Gateway Redundancy.
Experience working with Nexus 7K, 5K and 2K and experience using Qualcomm tools like QXDM, QPST, QMICM, QCAT
Experience working on Juniper Net Screen Firewalls like, NS50, SSG 550M, SSG520M, ISG 1000, and ISG 200.
Experience on implementation of Juniper Firewall, SSG Series, Net Screen Series ISG 1000, and SRX Series.
Extensive experience in managing and maintaining 200+ Palo Alto, Cisco ASA, Juniper firewalls and IPS/IDS deployed
across the site.
Extensively used Splunk for Log review, event correlation and threat analysis and successfully mitigated threats by
applying best practices.
Successfully updated operating system for Next generation firewalls (Palo Alto, Checkpoint and Cisco).
Successfully completed App-ID project -Converted all the rules App Id based which resulted in granular traffic control.
Assisted customers with troubleshooting their networks, security devices, operating systems, e-mail system.
Strong knowledge of firewalls, DLP, IDS/IPS, Web application firewalls (WAF), anti-virus, URL filtering.
Strong understanding of information system security vulnerability assessment/testing on a wide variety of
technologies and implementations utilizing both automated tools and manual techniques such as: XSS/CSRF, SQL
Injection, Buffer Overflow, and DoS attacks.
Hands on experience on Cisco PIXASA Firewalls, Juniper SRX series, Palo Alto, VPN, Troubleshooting Skills, Log Analysis
and Review, Compliance Audit.
TECHNICAL SKILLS:
Network Protocols RIP, RIP V2, EIGRP, OSPF, IS-IS, IGRP, HSRP, VRRP, GLBP, LACP, PAGP, DNS, SMTP, SNMP,
FTP, TFTP, LPD/TDP, WLAN, WEP, POP3 LADP
Routing Protocols QoS, IPsec/SSL, HSRP, EIGRP, OSPF, RIP, BGP, TCP/IP, Multicast, VOIP, Riverbed,
Wireshark, tcpdump, TACACS, Wireless
Switching Protocols VTP, STP, RSTP, MST, VLANs, 802.1q trunking and tunnelling
CISCO Routers 1700, 1800, 2500, 2600, 2800. CISCO High End Router 3600, 3800, 7200, 12010
CISCO Switches 1900, 2950, 2960. CISCO Campus switches 3550XL, 3548, 4984 Core Catalyst 4503, 4507
RE, Catalyst F5 load balancer, Juniper ISG/SRX
Firewall Platforms Checkpoint (NGX R65, 3100, 5100, 5900), Cisco Firewalls (ASA 5505, 5506-X, 5585), Palo
Alto Networks (PA series 2K, 3K and 5K) with panorama 8.0, WAF
Security Protocols Standard and Extended ACLs, IPsec, VPN, Port-security, SSH, SSL, IKE, AAA, Prefix-lists,
Zone-Based Firewalls, NAT/PAT, HIPAA standards, Ingress & Egress Firewall Design,
Content Filtering, Load Balancing, IDS/IPS, URL Filtering, L2F, IDS, TCP Intercept, Router
Security, SNMP trap
Network Management and Wireshark, Infoblox, HP OpenView, Cisco Prime, Splunk, Security Device Manager
Monitoring (SDM), Cisco Works; TCP Dump and Sniffer, SolarWinds Net Flow Traffic Analyzer,
NetScout, Network Performance Monitor (NPM), Network Configuration Manager
(NCM), SAM, IP Address Manager, Additional Polling Engine
Load Balancers and Proxies F5 (BIG-IP) LTM 2000, 3900, 6400, 6800, AV 510, Citrix NetScaler, MWG, Zscaler Proxies,
Bluecoat Proxies
Servers Domain servers, DNS servers, WINS servers, Mail servers, Proxy Servers, Print Servers,
Application servers, FTP servers, NTP
Operating Systems Windows NT 4.0 (Desktop/Server), Windows server, Windows XP/7, LINUX, Solaris, Red
Hat, Active Directory, UNIX
Security/Firewalls Cisco ASA Firewalls, IPSEC & SSL VPNs, IPS/IDS, DMZ Setup, Cisco NAC, ACL, IOS Firewall
features, checkpoint
PROFESSIONAL EXPERIENCE:
Fannie Mae, Boston, MA April 2022 to Present
Role: Sr. Network Engineer
Responsibilities:
Designed and performed configuration of Cisco Identity Services Engine (ISE) Server to migrate of services from Cisco
Secure Access Control System (ACS) version 4.2(used for Wireless Client Access), Cisco Secure ACS Agent, Cisco
Network Admission Control (NAC) Guest server version 2.0.3 and Cisco Secure ACS version 5.5.0.46 (Used for Terminal
Access Controller Access Control System (TACACS+) to Network Devices) to the new Cisco ISE server.
Performed support, configuration, testing and documentation for ISE rollout for CenterPoint Energy which includes
making configuration changes in access and distribution layer switches, wireless controllers and ISE nodes.
Used AWS Cloud platform with features EC2, VPC, ELB, Auto-Scaling, Load Balancing, Security Groups, IAM, EBS, AMI,
RDS, S3, SNS, SQS, Cloud Watch, and Cloud Formation.
Experience building VPC's for specific environments, and subnetting for private or public needs.
Developed an AWS security roadmap which included the AWS Services and 3rd party tools to be utilized in the AWS
Cloud for Security monitoring.
Implemented continuous integration automated build pipelines using Jenkins.
Deployed Chef Dashboard for configuration management to existing infrastructure.
Developed an AWS Security Group strategy. Determined naming conventions, owners, and approval process for
Security Group change requests in a promote-to-production environment.
Configured Terraform to architect and deploy scalable and secure network infrastructure components, including
Virtual Private Clouds (VPCs), subnets, route tables, security groups, Palo Alto Networks (PAN) firewalls, and load
balancers.
Deployed Palo Alto Virtual Appliances in Azure cloud for Edge security and DMZ deployments.
Enabled and configured CloudTrail logs for 26 AWS accounts. Created and managed an encrypted S3 Bucket for all
CloudTrail logs and adjusted bucket policy for each account CloudTrail to access.
Installed and configured Amazon's Inspector. Created Targets and Templates and scheduled Assessment runs on all
EC2 instances in the AWS account.
Provided ISE deployment services for migration of users from Cisco NAC to Cisco ISE platform for the following
locations.
Configured and deployed Next Generation Firewalls including Palo Alto, Cisco ASA and Checkpoint Firewalls.
Profound working knowledge of administration and management of Palo Alto firewalls using centralized Panorama M-
100 and M-500 devices.
Configured VLANs, Trunk groups, ether channels, and Spanning tree for creating Access/distribution and core layer
switching architecture.
Configured ACLs in Juniper SRX 3400 and Palo Alto PA-5050 firewalls for Internet Access requests for servers, Protocol
Handling, Object Grouping, and NAT.
Upgraded Cisco 7200, 3600 Router IOS Software, backup Routers, and Catalyst 3560, 4500 switch configurations.
Used the ISE Endpoint Analysis Tool (ISEEAT) to analyze data and design new ISE Profiling Policies.
Performed operational Moves/Adds/Changes in Integrated Services Engine (ISE) 2.3 including but not limited to
network devices, Identity Groups, Local Hosts, Local Users, Administrator Policies, etc.
Performed evaluation and analysis of the environment for NSX deployment, including NSX manager, Distributed
Firewall, Distributed Logical Router.
Addressed technical issues and questions regarding Cisco ISE including troubleshooting and feature changes and
modifications.
Implementation of Cradle point with 3G/4G LTE as Backup Solution for Clients WAN. Connections and using Enterprise
Cloud Manager for Monitoring.
Tested 7750 for bandwidth, packet loss, Jitter, latency using network diagnostic tools, QSCOPE before the site is being
integrated to LTE. Configured Cisco ISE for Wireless and Wired 802.1x Authentication on Cisco Wireless LAN.
Consisted of ISE Deployment, Authentication with Active Directory and Microsoft Certificate Authority.
Responsible for F5 design for few clients, also did migrations as per MOP by our design lead.
Designed, managed and troubleshoot EIGRP and OSPF routing environment comprised of multiple areas.
Provided network administration services such as authentication, web filtering and deployment secure gateway using
Bluecoat proxy and Zscaler Cloud solution Proxies.
Designed and Configured Cisco Identity Services Engine (ISE v2.3) to support corporate connectivity to a new wireless
environment utilizing Active Directory Authentication.
Worked on IP networking and network security as well as good knowledge in Peripheral Component Interconnect PCI.
Established and implemented network policies, procedures and standards and ensures their conformance with
information systems and company's objectives, trains users on network operation.
Environment: Checkpoint, Nexus, Cisco 3500, 1400, 1500, 5400, ASA firewall -- ASA5545, ASA5585-SSP-20, firewall PIX-
525, VPN concentrator -- Cisco 3060, check point firewall -- r77, F5 Local Traffic Managers (LTM) 5000, 7000 series, (ISE)
2.3, VLANs, STP, DNS/DHCP issues, Bluecoat proxy, Zscaler, Palo Alto firewalls, Cradle Point, FortiGate TACACs, BGP, AWS,
MPLS, Firewall analyzer, Wireless LAN, service desk, Cisco ISE, Cisco Prime, JUNOS
EDUCATION:
Bachelor in Electronics and Communication Engineering (ECE), Vidya Jyothi Institute of Technology, Hyderabad,
Telangana, India.
CERTIFICATION:
CCNA Routing and Switching (200-125)
CCNP Routing & Switching (300-101, 300-115)
Palo Alto Networks Certified Network Security Engineer (PCNSE)