Sr. Network Engineer
Current• Worked on data center segmentation project to create segmentation between the user and server traffic by deploying Palo Alto firewalls (5250s) in the datacenter including cabling to the Nexus 7K and HA.• Validated routing throughout the environment and created test plans for failover including using link monitoring and path monitoring.• Worked on providing management connectivity, HA configuration, setting up RSA for MFA, license and updates management,L3,aggregate Ethernet and sub interfaces configuration, configuration of BGP on both Nexus and Palo Alto, moved SVI (server VLAN) interfaces from ASA core to Palo Alto.• Collected data to determine which permit rules to create between the user and server VLANs based on the logs.• Experience using Source fire IPS and Fire sight management console • Review and analyze events from logs and Source Fire IDS/IPS• Determined the VPN connectivity requirement for users, VPN pool and gateway information, integration of RSA for VPN authentication, defined rules for non-console administrative access, implemented and tested non-console admin rules for firewalls.• Worked on creating SNMP, Syslog, Email profiles, log forwarding, data filtering profiles according to the client’s requirement. • Responsible in troubleshooting on Cisco ISE added new devices on network based on policies on ISE.• Upgraded the existing Panorama to V8. Integrating the new firewalls to Panorama and responsible for working on change tickets for existing 3250 Palo Firewalls in the environment.• Worked with the Info security team to closely monitor threats, incident handling, working with the network administration team to provide them with the remediation steps.• Responsible in troubleshooting on Cisco ISE added new devices on network based on policies on ISE.