System Owner
CurrentSpecializing in:•Design, configure, and deployment of Cisco Prime Infrastructure & Cisco Identity Services Engine (ISE) within a Windows 20xx AD – TACACS+ & RADIUS. 802.1x & MAB Authentication & Authorization for Wired & Wireless (Router, Switch, FW and WLC) - network and appliance.•Configuration/Establishment & integration of Certification Stores, Authentication & Authorization w/ Cisco ISE and MS Active Directory & Certificate Authority. Anyconnect: EAP-FAST w/ MSCHAPv2 & EAP chaining (user and machine) - Windows Supplicant: TEAP w/ EAP-TLS & EAP chaining•Establish TACACS (AA profile & policies, command sets, shell profiles, conditions) services for device administration w/ internal and MS AD groups within Cisco ISE.•Implemented and documented custom fully redundant and HA WLAN environment utilizing 550x Wireless LAN Controllers, 33xx ISE Appliances, and Wireless Access Points of 11xx, 350x and 360x series.• Design, migrate, deploy, configuration and administration of virtualization of Cisco ISE Servers with VMWARE ESXi and/or VM Server/workstation (platform and networking).• Create the repository for the backup and performing upgrades.• Installing or Upgrading Cisco IOS Software for router, switch, ISE, FW / ASA, IDS/IPS, WLC, WAP systems•Desktop Virtualization, Application Virtualization, Server Virtualization, Storage Virtualization, and Network Virtualization• AWS Direct Connect (DX) & Microsoft Azure ExpressRoute - Connection establishment• AWS network services: Route 53, S3, EC2, CloudFront, CloudFormation, VPCs and subnets, Direct Connect, Transit Gateway, NACLS & Security Groups, WAF• AWS Route 53 - Registration, Hosted Zones, Records (naming, types, policy etc), DNS FW, DNSSEC, Traffic Polices, Test Records• AWS S3 - Naming, regions, access control, properties, metrics, Access points• AWS EC2 - Amazon AMI, Instance types, storage, tagging, security groups, EBS volumes, Snapshots, Key pairing, Network interfaces, Elastic IPs.