24 Aug
|
NTT Data
|
Pimpri-Chinchwad
24 Aug
NTT Data
Pimpri-Chinchwad
CCNP-Certified L3 Network & Security Engineer with 18 years of IT infrastructure expertise spanning global market leaders like NTT, Infosys, and HCL. Proven track record in the end-to-end lifecycle—planning, implementation, and large-scale migrations—for enterprise routing/switching, Nexus data centres, wireless, and
SD-WAN architectures . Hands-on specialist in high-availability Palo Alto and Fortigate security deployments, progressing from L1/L2 operations into a trusted L3 escalation authority and technical leader.
v Technical Skill Profile
· Core Domains : Routing & Switching, Data Centre (Nexus, ACI), Wireless, SD-WAN (Viptela), Network Security (Palo Alto, Fortigate).
· Operational Frameworks : Change Management (ITIL v4).
v Hardware Expertise
· Cisco Routers : Branch and enterprise models including ISR 1700 through 3900 series, 4431, and ASR 1002.
· Cisco Switches : Campus and core switches (2950 to 9500 Catalyst series) and Virtual Switching System (VSS).
· Nexus Data Centre : Nexus 2K (FEX), 5K, 7K, and 9K switches, including Supervisor Engines (1, 2, 2E).
· Cisco Wireless : Wireless LAN Controllers (2504, 3504, 4404, 5508, 5520) and Access Points (2702, 3802
· Hardware expertise for Cisco viptela SDWAN Palo alto Firewall and Fortigate firewall
· Cisco SDWAN- Catalyst 8200/8300/8500 Series
· Palo alto -(phone hidden)/700 series
· Fortigate - 60F / 60G, 70G, 80F, 90G 100F / 101F, 120G, 200F / 200G, 400F
·
v Core Routing & Switching and SDWAN
· Layer 2 Protocols : STP, PVSTP, RSTP, DTP, VTP, and switch port security.
· High Availability : Switch stacking, EtherChannel, Virtual Port Channel (vpc), and Cisco Fabric Path.
· Layer 3 Protocols : Static, Default, RIP, EIGRP, OSPF, and BGP.
· Gateway Redundancy : HSRP, VRRP, and GLBP.
· Advanced Features : VRF, Private VLANs, IPv4, and IPv6.
· Next-Gen Networking (SDN & Cloud)
· Cisco ACI : Application Centric Infrastructure architecture and deployment.
· Cisco SD-WAN (Viptela) : Full fabric management and troubleshooting.
· SD-WAN Architecture : Vmanage, Vsmart, and vBond controller operations.
· SD-WAN Data Plane : Control plane bring-up, TLOCs, TLOC extensions, colours, and VPN segmentation.
· SD-WAN Automation : Zero Touch Provisioning (ZTP) and Plug-and-Play (PnP).
· SD-WAN Policies : Central/Local control and data policies, and App-Aware routing.
· Cloud & Internet : Direct Internet Access (DIA) and Cloud On Ramp for SaaS
- Protocols & Overlays: VXLAN, EVPN (Ethernet VPN), MP-BGP, OSPF, IS-IS, BGP EVPN Control Plane.
- Architecture: Spine-Leaf Topology, Multi-Chassis Link Aggregation (MC-LAG / vpc), Anycast Gateway, Underlay/Overlay Networking.
- Data Centre Concepts: Data Centre Interconnect (DCI), Multi-Tenancy, Network Virtualization, Layer 2/3 Extension.
· v Network Security & Services
· Firewalls : Hands-on knowledge of Palo Alto Networks and Fortinet firewalls.
· VPN Technologies : SSL VPN, IPsec remote-access, site-to-site, and multi-site VPNs.
· Access Control : Standard/Extended ACLs, NAT configurations, and DMZ design.
· Authentication : Dot1x and AAA services supporting RADIUS.
v Operations & Service Management
· ITIL v4 Change Management : Planning, assessing,
and authorizing network changes to minimize risk.
· Risk Mitigation : Evaluating potential impacts on live environments before scheduling maintenance windows.
· Standard Changes : Managing pre-approved, low-risk network modifications smoothly.
· Emergency Changes : Implementing urgent security patches and fixes following emergency protocols.
v Core Technical Expertise
· SD-WAN Technology: Cisco Viptela SD-WAN (Vmanage, Vsmart, vBond, VEdge/cEdge), Traffic Engineering, Policies.
· Network Security: Palo Alto Networks (PAN-OS), Fortinet FortiGate, Security Policies, NAT, VPN (IPsec/SSL), URL Filtering.
· Network Operations (L3): Incident/Change Management, BAU Support, SolarWinds, Topology Design (HLD/LLD
·
v Skilled Experience v Network Security & Cisco Viptela SD-WAN Operations
· Deliver 4 years of dedicated operations experience managing enterprise security perimeters and software-defined wide-area networks.
· Administer Cisco Viptela SD-WAN environments , utilizing Vmanage for monitoring, Vsmart for policy control, and managing vEdge/cEdge routers across multiple sites
· Configure and troubleshoot Next-Generation Firewalls , including Palo Alto and Fortinet FortiGate, focusing on security policies, NAT rules, and threat prevention.
· Optimize WAN traffic steering using Viptela centralized policies, application-aware routing (AAR), and monitoring path quality to ensure business-critical application performance.
· Manage secure remote connectivity , configuring site-to-site IPsec VPNs, client-to-site SSL VPNs, and Palo Alto/FortiGate URL filtering profiles
- Device Onboarding : Provision VEdge/cEdge routers using Zero Touch Provisioning (ZTP) or Plug-and-Play (PnP).
- Policy Application : Deploy pre-built localized or centralized control and data policies via Vmanage.
- Circuit Monitoring : Track jitter, packet loss, and latency across MPLS, Broadband, and 4G/5G transports.
- Firmware Upgrades : Execute scheduled software upgrades on Edge devices and monitor reboot status.
- Troubleshooting : Resolve basic BGP/OSPF routing issues over OMP (Overlay Management Protocol).
- Backup Management : Perform routine configuration backups of Vmanage, Vsmart, and vBond controllers.
- Policy Engineering : Author complex centralized control policies for traffic engineering and service chaining.
- Migration Strategy : Plan legacy WAN to SD-WAN migrations, ensuring seamless OMP-to-BGP/OSPF redistribution.
- Panorama Operations : Push device groups and template stacks from Panorama to managed firewalls.
- Certificate Renewal : Update SSL/TLS certificates used for Global Protect VPN and decryption.
- Log Analysis : Monitor Traffic, Threat, and URL filtering logs to identify blocked legitimate traffic.
v Network Engineering & L3 Operations · Provide L3 network operations and Business-As-Usual (BAU) support,
managing a large-scale infrastructure of over 500 network devices.
· Proactively monitor network health and performance using enterprise tools like SolarWinds to ensure maximum uptime.
· Lead fault management by identifying, isolating, and resolving complex LAN, WAN, and wireless connectivity issues.
· Execute day-to-day troubleshooting under pressure, strictly following site-specific escalation matrices for timely resolution.
· Drive ITIL best practices across Incident Management, Problem Management, and Change Management frameworks.
- VLAN & Trunking : Configure and troubleshoot 802.1Q trunks, Native VLANs, and Voice VLANs.
- Spanning Tree (STP): Manage PVST+ and Rapid-PVST+ root bridges, port costs, and basic loop prevention.
- EtherChannel: Configure and troubleshoot LACP and PAGP link aggregation bundles.
- Routing Protocols: Troubleshoot basic neighbor adjacencies for OSPF and EIGRP in single-area environments.
- First Hop Redundancy: Configure and maintain HSRP, VRRP, or GLBP for default gateway redundancy.
- Switch Port Security: Implement MAC address limiting, sticky MACs, and err-disable recovery mechanisms.
v Network Design, Implementation & Migration · Author high-level technical documentation , including High-Level Designs (HLD), Low-Level Designs (LLD), migration strategies, test plans, and Standard Operating Procedures (SOPs).
· Execute hands-on network migrations , successfully transitioning legacy routing layouts to modern Cisco Viptela SD-WAN and NGFW deployments.
· Perform critical hardware upgrades , including core router replacements, Cisco IOS updates, and device license installations
· Deploy and provision network devices , configuring L2/L3 VLANs, IP phones, access points, and network printers based on business demands
· Designed and deployed scalable Data Centre Spine-Leaf architectures utilizing VXLAN overlay and MP-BGP EVPN control plane to support multi-tenancy.
· Architected EVPN-VXLAN fabrics to eliminate traditional Spanning Tree Protocol (STP) dependencies, achieving active-active forwarding and optimal bandwidth utilization.
· Engineered Data Centre Interconnect (DCI) solutions using EVPN over VXLAN to seamlessly extend Layer 2 and Layer 3 domains across geographically dispersed data centres.
v Wireless & Infrastructure Management
· Administer wireless LAN (WLAN) environments , utilizing Ruckus Wireless Controllers and Cisco WLC (including Cisco AIR-CT2504-K9) for secure user access.
· Configure and test wireless infrastructures , managing Cisco 3850 built-in WLCs and Cisco AIR-AP1602 access points across multiple sites.
· Manage robust Cisco hardware environments , including Core (C9200, 3650), Distribution (3850), and Access (2960) switches, alongside WAN routers (2911, ASR 4300).
·
Cross-Functional Collaboration & Leadership
· Lead high-priority bridge calls during major incidents, representing the network and security team to restore services rapidly.
· Collaborate seamlessly with cross-functional teams , including Security, Database (DBA), Storage, OS Operations, and Application teams.
· Manage vendor relationships , coordinating directly with external service providers to resolve complex hardware and circuit issues
📌 TCS., Wipro, Infosys, Accenture,TechM (Pimpri-Chinchwad)
🏢 NTT Data
📍 Pimpri-Chinchwad