SlideShare a Scribd company logo
1 of 5
IGOR LAKHMAN
iLakhman@lanwanprofessional.com | (732) 290-5234
SUMMARY
IT Professional with over 15 years of experience in planning, engineering, administration, maintenance, optimization , analysis
and troubleshooting for various network technologies including VoIP, wireless and data center for medium to global
enterprise environments which includes proficiency in routing, routing protocols, switching, WLAN, VPN, WiFi, security,
firewalls, network performance and security assessment as well as post-assessment reports and recommendations.
TECHNICAL CERTIFICATIONS &SKILLS
 Cisco Certified Network Professional – Routing & Switching CCNP–R & S
 Cisco Certified Network Professional / Cisco Certified Network Associate CCDP/CCDA
 Certified WAN Professional / Certified WAN Enterprise Administrator CWP/CWEA
 Cisco Security Administrator / Data Center Administrator CSA/CDCA
 Cisco Voice Administrator / Wireless Technician CVA/CWT
 Cisco Certified Network Associate – Routing & Switching CCNA–R & S
TECHNICAL SKILLS DETAIL
Routing/Switching Technologies - Cisco Routers (3900, 2900, 1900, 800 Series), Cisco Catalyst Switch (6500, 5500, 4900,
4500, 3750, 3560-X, 3100), Cisco Nexus 1kv, 2k, 5k Series, Juniper and HP Routers & Switches - WAN, LAN, TCP/IP,
Cisco IOS, Spanning Tree Protocol, BPDU, CDP, ACL, NAT, PAT, RIP, RIPv2, OSPF, OSPFv3, EIGRP, BGP, MPLS,
VTP, SNMP, SMTP, ARP, TCP, UDP, Static Routing, Stub Routing, VLAN, VLAN Trunking, VXLANs, Multicast routing,
HSRP, SVI, CEF, Etherchannel, Portfast, VSS, VPC.
Security/Firewalls Technologies - Cisco Security Manager Suite, Cisco ASA 5500 series firewalls, Cisco FWSM, Cisco
IPS/IDS, Cisco ACS, Advanced Firewall Manager (AFM), Cisco ASA 1000V cloud firewall, Checkpoint Firewall, Juniper SRX
series, Palo Alto, Protocols & Standards - AAA, TACACS+, RADIUS, SSH, VPN, IPSec, SSL/IPSec, Data Loss
Prevention, Data Management Zone, Pretty Good Protection (PGP), Public Key Infrastructure (PKI), Internet Key Exchange
Policy, Port Security, MAC Address Filtering
Wireless/Voice Technologies - Cisco WLC, IEEE 802.1x & 802.11, WLAN, WAP, AP, SSID, LWAPP, Aironet,
Bluetooth, Avaya, AURA - Voice Over Internet Protocol (VoIP), VoIP/SIP, CUCM, UCCM, UCCX, MGCP, RSTP, SCCP,
STP, Quality of Service (QoS), PoE, MMDS, LMDS, CCK, DSSS
Monitoring/Data Center Technologies/APPS - Wireshark, Remedy, Cacti, Nagios, VMware, Solarwinds, Cisco Security
Manager Suite, Server, Sniffer, Ethereal, Orion - VMware, F5 Big-IP load balancing (GTM/LTM), Cisco AnyConnect VPN
mtg, Cisco Prime, Cisco ISE, Cisco IPS/IDS, Meraki cloud.based - Splunk Enterprise, SNMPv2c, SNMPv3, DNS, DHCP,
FTP, Telnet, HTTP(S), SMTP, tunneling protocols, PTP, SFTP, RDP.
Other Technologies – Hardware: IBM 30XX; 43XX; Operating Systems: OS/MVS/XA; Languages: Cobol/370, Cobol II,
ADS/O; Database: IDMS 14.0, DB2/SQL; Networks: ADS/A IDMS/DC, CICS; Other Packages: JCL, Utilitiies DME,
DBOL, DMLO, OLQ, IDD/M, IDD, MAPSC, ADS/G, ADS/M, CULPRIT, DEBUGGER, SPUFL, QMF, INTERTEST,
EZTest2000, IDMS Data Ager, DB Image, QA Hyper Station; Other: Quick Books, Microsoft Office.
SUMMARY OF PROFESSIONAL EXPERIENCE
LAN/WAN Professional Senior Network Engineer/Contractor 2014 – Present
Nexus Asset Mgmt LLC & Zimmer Lucas Partners Lead Network Engineer/Project Mgr.2003 – 2014
AG Edwards- New York Stock Exchange Onsite Relations 2002 – 2003
McGraw-Hill Company Senior Programmer/Analyst 2001 – 2002
Top-Tier Brokerage Firms Project Leader /Sen. Prog. / Analyst 1980 – 2001
EDUCATION
Certified WAN Professional Program LANWAN Professional
Associate of Science in Computer Science Odessa University
PROFESSIONAL EXPERIENCE DETAIL
LAN/WAN Professional Senior Network Engineer/Contractor 2014 – Present
Company Overview – LAN/WAN Professional is a nationwide membership organization of LAN/WAN professionals
including administrators, engineers, consultants, analysts, architects located throughout the continental United States.
Responsibilities handled:
 Member of a team responsible for onsite LAN/WAN support deployment and configurations of routers, switches,
wireless, voice, firewalls and related LAN/WAN technologies.
 Secondary responsibilities including general escalation troubleshooting support and general administration to included
LAN/WAN configurations, logical/physical diagrams based on company standards and policies.
 Additional responsibilities included provided timely and accurate updates/reports to technical leads/managers relates to
tasks and responsibilities that are assigned and act as subject matter expert on routing, switch related activities.
Nexus Asset Mgmt LLC & Zimmer Lucas Partners Lead Network Engineer/Project Mgr. 2003 - 2014
Company Overview – Zimmer Lucas Partners is a private company whose line of business includes providing investment
information and advice to companies and individuals. Responsibilities handled:
 Researched various network products and interacted with vendors and contractors to evaluate network and
telecommunications products and services in preparation of the new installation development effort.
 Supervised network assessment and capacity planning project for new network infrastructure.
 Lead design, configuration and implementation effort of the trading and back office networks.
 Conducted daily monitoring, troubleshooting and maintenance of network equipment and software, and other security
components, and peripheral devices.
 Managed network equipment and security solutions such as firewalls, anti-virus and intrusion detection systems.
 Ensured network connectivity and administered necessary hardware and software upgrades and repairs.
AG Edwards- New York Stock Exchange Onsite Relations 2002 – 2003
Company Overview – AG Edwards – New YorkStock Exchange is the world’s largest stock exchange and leading financial
market. Responsibilities handled:
 Responsible for timely and proficient completion of day-to-day administration, as needed support and troubleshoot of
mission critical and time sensitive activities while meeting mandated policies, procedures and compliance.
 Professional responsibilities included collections, verification and following corporate policies and procedures.
McGraw-Hill Company Senior Programmer/Analyst 2001 – 2002
Company Overview – McGraw-Hill is a worldwide company which is the leading provider of ratings, benchmarks and
analytics in the global capital and commodity markets. Responsibilities handled:
 Member to a team of professionals responsible for daily production support, maintenance, enhancements,
implementation, administration, configuration and troubleshoot activities.
 Technologies include but not limited to server, enterprise applications and local area network (LAN) technologies, wide
area network (WAN) technologies.
 Professional responsibilities included documentation, administration, project management, following corporate policies
and procedures, documentation, and scheduling as needed reports to management.
Top-Tier Brokerage Firms Project Leader / Sen. Prog. / Analyst 1980 – 2001
Company Overview – Worked as a contractor for a number of Investment Banks and Service companies that provided
transaction services to the financial industry. Some of the companies were ADP Brokerage Services, Goldman Sachs & Co. ,
American Express Bank/EDS, Solomon Smith Barney, Inc. , Citibank and Brown Brothers Harriman to name a few.
Responsibilities handled:
 Support, maintenance, enhancements to software, testing, administration, analysis, project management and
troubleshooting in main frame environments.
 Responsibilities included administration, documentation, following corporate policies and procedures and scheduling as
needed reports to management.
SUMMARY OF TECHNICAL ACCOMPLISHMENTS
Routing & Nexus & Catalyst Switching
 Implement trunk ports and implement granular control of VLANs and VXLANs using NX-OS to ensure
virtual and flexible subnets that can extend further across the network infrastructure than previous generation of
switches.
 Implement port-profiles as part of the NX-OS command structure that allows for configuration of multiple
ports and port-types via inherited configurations applied via a single command that reduces administrative error
and allows for better configuration readability.
 Implement a virtual version of Nexus: Nexus1000v into VMWare to extend Nexus capabilities directly adjacent
to virtual machines so that they benefit from Cisco switching capabilitiesand network topology consistency
ensuring VMs maintain their subnet/VLAN relationships during failover.
 Implement secure privileged administrative access to the Cisco IOS system. Enable the encryption of system
passwords to prevent unauthorized users access to passwords in the system configuration.
 Implement secure access to the console and vty ports, and set the interval that the EXEC command interpreter
waits until user input is detected on the Console and vty ports. Also, configure the console and vty ports log
messaging to not interfere with active device configuration.
 Implement VLAN Trunking Protocol to reduce administrative overhead. Enable secure sharing of VLAN
information to prevent the introduction of rogue devices from affecting the VLAN database. Shutdown unused
switchports following Layer 2 security best practices.
 Create and manage Local VLANs based on department function, and configure ports with static VLAN
assignment, static 802.1Q trunks, and dynamic ISL trunking using PAgP for layer 2 forwarding. Utilize VLAN
Spanning-Tree in conjunction with PVST+ for compatibility between Cisco and Juniper switches. Configure
edge ports for fast-transitioning into the forwarding state to fix workstation startup connectivity delays. Modify
spanning-tree parameters for manual root bridge assignment. Implement ether-channels between each switch
using PAgP for negotiation. Modify ether-channel load balancing method.
 Implement WAN links between sites using frame-relay point-to-point and multipoint connections to establish
connectivity between each of the four sites as required. Establish frame-relay point-to-point connections three
of the sites creating a full mesh. Implement hub and spoke network between three of the sites with the main
office as the hub for redundant connections.
 Implement EIGRP routing for point-to-point and Non Broadcast Multi-Access networks. Ensure that the
spoke routers are receiving routing information about each other from the hub. Configure EIGRP unequal-
cost load balancing to also use the lower capacity multipoint links when routing packets.
 Prevent neighbor adjacencies from being formed as well as the sending and receiving of routing updates on
unnecessary interfaces. Implement EIGRP MD5 Message Authentication between sites to prevent
unauthorized insertion of routes into the domain. Implement manual EIGRP route summarization to reduce
routing protocol demand on CPU resources, memory, and bandwidth used to maintain the routing table.
 Implement OSPF routing with multiple areas for networks between sites. Implement totally stubby areas to
lower the system resource utilization of routing devices for the network. Implement NSSA area to allow
injection of external routes into the area and propagation into the OSPF domain.
 Implement backup and recovery of Cisco IOS Images. Perform password recovery on Cisco IOS
routers/switches and a Juniper EX2200 Series switch to restore administrative access. Backup and Restore
startup-comfit file for disaster recovery.
 Configured and verified internal BGP peering using directly connected networks.
 Configured and verified internal BGP peering using loopbacks by using an interior gateway protocol (OSPF) to
provide routing information.
 Configured and verified external BGP peering using directly connected networks.
 Configured and verified external BGP peering using loopbacks and ebgp-multihop.
 Configured and verified internal BGP peering using a Route Reflector.
 Used debugging diagnostic commands to monitor BGP events.
 Configured and verified MPLS manually and using automatic configuration via OSPF.
 Configured and verified virtual routing and forwarding (VRF) instances with route-targets and route descriptors.
 Configured and verified MP-BGP to send VRF traffic in an MPLS VPN.
 Redistributed provider edge networks into MP-BGP.
 Verified end-to-end connectivity over the MPLS VPN.
Security
Implement an IPSec Site-to-Site VPN between the Cisco ASA5505 at small office location and Cisco 1841 ISR
with a security IOS image at the main office. Implementation of the VPN includes the following configurations:
Internet Key Exchange Policy using DES and SHA for encryption and authentication, access-lists to define VPN
traffic, transform set using esp-des esp-sha-hmac to define how the traffic is protected, crypto-map to associate
the previously configured elements to a peer, and application of the crypto map to appropriate interface or VPN
endpoint.
Implementation of Zone-Based Policy Firewall on the Cisco 1841 ISR with the following components: three
zones, class-maps specifying traffic that must have policy applied as it crosses a zone-pair, policy maps to apply
action to the class-maps’ traffic, zone-pairs, and application of policy to zone pairs.
Implement a Clientless SSL VPN (WebVPN) to allow users to establish a secure, remote-access VPN tunnel to
the Cisco ASA 5505 using a web browser. Prepare the Cisco ASA with necessary configurations to self-signed
certificate generation. Generate a general purpose RSA key-pair for certificate authority identification, configure
certificate authority trustpoint for the WebVPN using self enrollment, and configure CA trustpoint interface
association.
Configure Syslog on the Cisco ASA5505 with logging to a host and internal buffer. Forward all logging to an
internal Syslog server for monitoring and management. Configure and manage Syslog output generation using
custom message lists. Implement FTP backup of internal buffer when it is exceeded.
Implement Basic Threat-Detection, Advanced TCP Intercept, and Scanning Threat-Detection. Simulate attacks
on network to manage threat-detection rates and verify Syslog generation.
Utilize Cisco ASA5505 Modular Policy Frame-Work to configure and manage layer 3/4 interface service policies,
apply inspection and connection limits to services, apply inspection and QoS policing to HTTP traffic. Configure
HTTP inspection policy to block restricted sites and file downloads.
Voice
Implement a local voice network with the following network elements: Cisco 2811 ISR (VoIP) with a Cisco Unity
Express Network Module (NM-CUE) installed, Cisco Communications Manager Express, a standard Cisco 3550
Switch, and a Cisco 3550 switch with Power-over-Ethernet. Create and manage Data and Voice VLANs, and
configure ports with static VLAN assignment and 802.1Q trunks for layer 2 forwarding. Configure edge ports for
fast-transitioning into the forwarding state to fix workstation startup connectivitydelays.
Configure Fast Ethernet main and sub-interface assignments as required for intervlan routing. Implement static
routes for local connectivity. Implement NTP server, DHCP server, and TFTP server for support of the VoIP
network. Modification of system level parameters including max phones, max directory numbers, display format
for date and time, and setting the Time-Zone.
Implement Unity Voicemail on the Cisco Unity Express Network Module. Configure a dial-peer on the Cisco
2811 ISR to define the attributes of the packet voice network connection to the Cisco Unity Express Network
Module. Enable call forwarding on busy or no answer. Implement Message Waiting Indicators and Voicemail
access via SMTP. Daisy-chain PCs to VoIP phones to reduce network cabling costs. Utilize PoE ports for VoIP
phones to reduce power infrastructure costs.
Wireless
Implement a wireless network infrastructure providing access to wired LANs to increase mobility and
productivity utilizing the following network elements: Cisco Wireless LAN Controller (WLC) 2106, a Cisco 3550
switch, a Cisco 1130AG series Access Point, and a Cisco 1121G series Access Point. Create wireless LANs and
configure interface association, security parameters, and radios used. Utilize the Wireless LAN Controllers web
GUI to configure and manage the wireless network. Configure internal DHCP scopes for WLANs.
Prepare infrastructure for AP registration on same subnet as management VLAN and for AP registration on
different subnet. Configure AAA AP policies to allow Self Signed Certifications for APs shipped without a
Manufacturer Installed Certificate. Implement AP Grouping to ensure WLAN SSIDs are only broadcast by the
APs desired.
Data Center
 Configured VLANs and access ports connecting virtual machines using the NX-OS CLI on a Cisco Nexus
1000v virtual machine and VMWare vSphere Client networking.
 Configured routing policies and service profiles for separate levels in an organizational hierarchy using a Cisco
Prime Network Services Controller virtual machine. These policies and profiles were applied to Cisco Cloud
Service Router 1000v (CSR 1000v) virtualrouters.
 Configured a CSR 1000v router using the Cisco IOS 15.4 CLI.
Monitoring
 Used the Cisco Configuration Professional GUI to configure interfaces, passwords, hostnames, DHCP,
EIGRP, and SNMP on a Cisco router. Used the CCP monitoring tool to monitor traffic from that router.
 Configured the Nagios XI monitoring tool to monitor routers and switches and customized its dashboard.
 Configured SolarWinds Orion NPM and used it to monitor traffic on a network.
 Configured the CACTI tool to graph traffic from a router and to generate alerts based on a threshold traffic
level.
 Used the Wireshark tool to study HTTP, telnet, and SSL traffic.

More Related Content

What's hot

Farooq Razzaque - Network Specialist
Farooq Razzaque - Network SpecialistFarooq Razzaque - Network Specialist
Farooq Razzaque - Network SpecialistFarooq Razzaque
 
Haseeb Resume LATEST
Haseeb Resume LATESTHaseeb Resume LATEST
Haseeb Resume LATESTAbdul Haseeb
 
Juther Jones CCNP 12
Juther Jones CCNP 12Juther Jones CCNP 12
Juther Jones CCNP 12Juther Jones
 
Hasan Ghannag CV System and Network 2016
Hasan Ghannag CV System and Network 2016Hasan Ghannag CV System and Network 2016
Hasan Ghannag CV System and Network 2016Hasan Ghannag
 
Windows Server Active Directory Systems Administrator
Windows Server Active Directory Systems AdministratorWindows Server Active Directory Systems Administrator
Windows Server Active Directory Systems AdministratorPatrick Ross
 
Resume_ejaz dt. 2.2.15
Resume_ejaz dt. 2.2.15Resume_ejaz dt. 2.2.15
Resume_ejaz dt. 2.2.15Ejaz Ahmad
 
Network Engineer - Resume
Network Engineer - ResumeNetwork Engineer - Resume
Network Engineer - ResumeAssan Samba
 
Network and Telecom Engineer
Network and Telecom EngineerNetwork and Telecom Engineer
Network and Telecom EngineerSrinivaas V.S
 
RESUME-GANESH D
RESUME-GANESH DRESUME-GANESH D
RESUME-GANESH DGanesh D
 
PhuongDang Resume D5
PhuongDang Resume D5PhuongDang Resume D5
PhuongDang Resume D5Phuong Dang
 
Elsayed, Mustafa-NW Engineer-CVs1
Elsayed, Mustafa-NW Engineer-CVs1Elsayed, Mustafa-NW Engineer-CVs1
Elsayed, Mustafa-NW Engineer-CVs1Mustafa Elsayed
 

What's hot (20)

Farooq Razzaque - Network Specialist
Farooq Razzaque - Network SpecialistFarooq Razzaque - Network Specialist
Farooq Razzaque - Network Specialist
 
Haseeb Resume LATEST
Haseeb Resume LATESTHaseeb Resume LATEST
Haseeb Resume LATEST
 
Giri - Resume 6+exp
Giri - Resume 6+expGiri - Resume 6+exp
Giri - Resume 6+exp
 
SHRUTHI SHARMA MS
SHRUTHI SHARMA MSSHRUTHI SHARMA MS
SHRUTHI SHARMA MS
 
Juther Jones CCNP 12
Juther Jones CCNP 12Juther Jones CCNP 12
Juther Jones CCNP 12
 
Hasan Ghannag CV System and Network 2016
Hasan Ghannag CV System and Network 2016Hasan Ghannag CV System and Network 2016
Hasan Ghannag CV System and Network 2016
 
Windows Server Active Directory Systems Administrator
Windows Server Active Directory Systems AdministratorWindows Server Active Directory Systems Administrator
Windows Server Active Directory Systems Administrator
 
Resume
ResumeResume
Resume
 
Resume_ejaz dt. 2.2.15
Resume_ejaz dt. 2.2.15Resume_ejaz dt. 2.2.15
Resume_ejaz dt. 2.2.15
 
Latest_Resume
Latest_ResumeLatest_Resume
Latest_Resume
 
Network Engineer - Resume
Network Engineer - ResumeNetwork Engineer - Resume
Network Engineer - Resume
 
White Paper on SNMPv3
White Paper on SNMPv3White Paper on SNMPv3
White Paper on SNMPv3
 
Network and Telecom Engineer
Network and Telecom EngineerNetwork and Telecom Engineer
Network and Telecom Engineer
 
Biswajeeban
BiswajeebanBiswajeeban
Biswajeeban
 
Muhammad Waqas Khalil
Muhammad Waqas KhalilMuhammad Waqas Khalil
Muhammad Waqas Khalil
 
ChadKillinger2016
ChadKillinger2016ChadKillinger2016
ChadKillinger2016
 
Mohamed_Omar_Cv
Mohamed_Omar_CvMohamed_Omar_Cv
Mohamed_Omar_Cv
 
RESUME-GANESH D
RESUME-GANESH DRESUME-GANESH D
RESUME-GANESH D
 
PhuongDang Resume D5
PhuongDang Resume D5PhuongDang Resume D5
PhuongDang Resume D5
 
Elsayed, Mustafa-NW Engineer-CVs1
Elsayed, Mustafa-NW Engineer-CVs1Elsayed, Mustafa-NW Engineer-CVs1
Elsayed, Mustafa-NW Engineer-CVs1
 

Viewers also liked

3rd Year IGEN Project - Final Report
3rd Year IGEN Project - Final Report3rd Year IGEN Project - Final Report
3rd Year IGEN Project - Final ReportMichael Harvey
 
Competencia Y Resultados De Aprendisaje
Competencia Y Resultados De AprendisajeCompetencia Y Resultados De Aprendisaje
Competencia Y Resultados De AprendisajeNestor Arsuza
 
Power point visual fundamentals project
Power point visual fundamentals projectPower point visual fundamentals project
Power point visual fundamentals projectkatiedawn1003
 
Mateusz_Miłek_Portfolio
Mateusz_Miłek_PortfolioMateusz_Miłek_Portfolio
Mateusz_Miłek_PortfolioMateusz Miłek
 
2nd Year IGEN Project - Final Report
2nd Year IGEN Project - Final Report2nd Year IGEN Project - Final Report
2nd Year IGEN Project - Final ReportMichael Harvey
 
Curriculum development
Curriculum developmentCurriculum development
Curriculum developmentArish Hares
 
Continuous Delivery at Gogo with Spinnaker and Foremast
Continuous Delivery at Gogo with Spinnaker and ForemastContinuous Delivery at Gogo with Spinnaker and Foremast
Continuous Delivery at Gogo with Spinnaker and ForemastN. Douglas Campbell
 

Viewers also liked (12)

3rd Year IGEN Project - Final Report
3rd Year IGEN Project - Final Report3rd Year IGEN Project - Final Report
3rd Year IGEN Project - Final Report
 
Resume
ResumeResume
Resume
 
Competencia Y Resultados De Aprendisaje
Competencia Y Resultados De AprendisajeCompetencia Y Resultados De Aprendisaje
Competencia Y Resultados De Aprendisaje
 
RUSSELL W Givens
RUSSELL W GivensRUSSELL W Givens
RUSSELL W Givens
 
Avalance Company Presentation 2016
Avalance  Company Presentation 2016Avalance  Company Presentation 2016
Avalance Company Presentation 2016
 
Power point visual fundamentals project
Power point visual fundamentals projectPower point visual fundamentals project
Power point visual fundamentals project
 
GTBV Presentation
GTBV PresentationGTBV Presentation
GTBV Presentation
 
Consumer Happiness & Well-Being
Consumer Happiness & Well-BeingConsumer Happiness & Well-Being
Consumer Happiness & Well-Being
 
Mateusz_Miłek_Portfolio
Mateusz_Miłek_PortfolioMateusz_Miłek_Portfolio
Mateusz_Miłek_Portfolio
 
2nd Year IGEN Project - Final Report
2nd Year IGEN Project - Final Report2nd Year IGEN Project - Final Report
2nd Year IGEN Project - Final Report
 
Curriculum development
Curriculum developmentCurriculum development
Curriculum development
 
Continuous Delivery at Gogo with Spinnaker and Foremast
Continuous Delivery at Gogo with Spinnaker and ForemastContinuous Delivery at Gogo with Spinnaker and Foremast
Continuous Delivery at Gogo with Spinnaker and Foremast
 

Similar to Igor lakhman net_res_v1 (20)

eurv3
eurv3eurv3
eurv3
 
Manjesh cv
Manjesh cvManjesh cv
Manjesh cv
 
Resume mohammed ahmed awad (1)
Resume mohammed ahmed awad (1)Resume mohammed ahmed awad (1)
Resume mohammed ahmed awad (1)
 
Samer_Sammour_CV_NEW_OCT_15
Samer_Sammour_CV_NEW_OCT_15Samer_Sammour_CV_NEW_OCT_15
Samer_Sammour_CV_NEW_OCT_15
 
Syed yasir ali_cv
Syed yasir ali_cvSyed yasir ali_cv
Syed yasir ali_cv
 
Nagabhushana Rao P
Nagabhushana Rao PNagabhushana Rao P
Nagabhushana Rao P
 
Syed Siraj - Telecom_Infrastructure Manager
Syed Siraj - Telecom_Infrastructure ManagerSyed Siraj - Telecom_Infrastructure Manager
Syed Siraj - Telecom_Infrastructure Manager
 
Network Engineer - Resume
Network Engineer - ResumeNetwork Engineer - Resume
Network Engineer - Resume
 
KRISHNAMOORTHI_NW
KRISHNAMOORTHI_NW KRISHNAMOORTHI_NW
KRISHNAMOORTHI_NW
 
Resume_Susheel Jain
Resume_Susheel JainResume_Susheel Jain
Resume_Susheel Jain
 
Rahul Sharma
Rahul SharmaRahul Sharma
Rahul Sharma
 
Yawer Hussain Hameedi-V4.00
Yawer Hussain Hameedi-V4.00Yawer Hussain Hameedi-V4.00
Yawer Hussain Hameedi-V4.00
 
Updated CV
Updated CVUpdated CV
Updated CV
 
cv
cvcv
cv
 
Resume_2015a
Resume_2015aResume_2015a
Resume_2015a
 
Resume_Q2-2016.2
Resume_Q2-2016.2Resume_Q2-2016.2
Resume_Q2-2016.2
 
Lon cv network_10072013
Lon cv network_10072013Lon cv network_10072013
Lon cv network_10072013
 
Muhammad Musavir
Muhammad MusavirMuhammad Musavir
Muhammad Musavir
 
Muhammad Musavir
Muhammad MusavirMuhammad Musavir
Muhammad Musavir
 
KIRAN UPDATED CV
KIRAN UPDATED CVKIRAN UPDATED CV
KIRAN UPDATED CV
 

Recently uploaded

Concrete Mix Design - IS 10262-2019 - .pptx
Concrete Mix Design - IS 10262-2019 - .pptxConcrete Mix Design - IS 10262-2019 - .pptx
Concrete Mix Design - IS 10262-2019 - .pptxKartikeyaDwivedi3
 
Call Us ≽ 8377877756 ≼ Call Girls In Shastri Nagar (Delhi)
Call Us ≽ 8377877756 ≼ Call Girls In Shastri Nagar (Delhi)Call Us ≽ 8377877756 ≼ Call Girls In Shastri Nagar (Delhi)
Call Us ≽ 8377877756 ≼ Call Girls In Shastri Nagar (Delhi)dollysharma2066
 
CCS355 Neural Networks & Deep Learning Unit 1 PDF notes with Question bank .pdf
CCS355 Neural Networks & Deep Learning Unit 1 PDF notes with Question bank .pdfCCS355 Neural Networks & Deep Learning Unit 1 PDF notes with Question bank .pdf
CCS355 Neural Networks & Deep Learning Unit 1 PDF notes with Question bank .pdfAsst.prof M.Gokilavani
 
VICTOR MAESTRE RAMIREZ - Planetary Defender on NASA's Double Asteroid Redirec...
VICTOR MAESTRE RAMIREZ - Planetary Defender on NASA's Double Asteroid Redirec...VICTOR MAESTRE RAMIREZ - Planetary Defender on NASA's Double Asteroid Redirec...
VICTOR MAESTRE RAMIREZ - Planetary Defender on NASA's Double Asteroid Redirec...VICTOR MAESTRE RAMIREZ
 
main PPT.pptx of girls hostel security using rfid
main PPT.pptx of girls hostel security using rfidmain PPT.pptx of girls hostel security using rfid
main PPT.pptx of girls hostel security using rfidNikhilNagaraju
 
Architect Hassan Khalil Portfolio for 2024
Architect Hassan Khalil Portfolio for 2024Architect Hassan Khalil Portfolio for 2024
Architect Hassan Khalil Portfolio for 2024hassan khalil
 
Heart Disease Prediction using machine learning.pptx
Heart Disease Prediction using machine learning.pptxHeart Disease Prediction using machine learning.pptx
Heart Disease Prediction using machine learning.pptxPoojaBan
 
Application of Residue Theorem to evaluate real integrations.pptx
Application of Residue Theorem to evaluate real integrations.pptxApplication of Residue Theorem to evaluate real integrations.pptx
Application of Residue Theorem to evaluate real integrations.pptx959SahilShah
 
Past, Present and Future of Generative AI
Past, Present and Future of Generative AIPast, Present and Future of Generative AI
Past, Present and Future of Generative AIabhishek36461
 
INFLUENCE OF NANOSILICA ON THE PROPERTIES OF CONCRETE
INFLUENCE OF NANOSILICA ON THE PROPERTIES OF CONCRETEINFLUENCE OF NANOSILICA ON THE PROPERTIES OF CONCRETE
INFLUENCE OF NANOSILICA ON THE PROPERTIES OF CONCRETEroselinkalist12
 
HARMONY IN THE NATURE AND EXISTENCE - Unit-IV
HARMONY IN THE NATURE AND EXISTENCE - Unit-IVHARMONY IN THE NATURE AND EXISTENCE - Unit-IV
HARMONY IN THE NATURE AND EXISTENCE - Unit-IVRajaP95
 
Sachpazis Costas: Geotechnical Engineering: A student's Perspective Introduction
Sachpazis Costas: Geotechnical Engineering: A student's Perspective IntroductionSachpazis Costas: Geotechnical Engineering: A student's Perspective Introduction
Sachpazis Costas: Geotechnical Engineering: A student's Perspective IntroductionDr.Costas Sachpazis
 
Gfe Mayur Vihar Call Girls Service WhatsApp -> 9999965857 Available 24x7 ^ De...
Gfe Mayur Vihar Call Girls Service WhatsApp -> 9999965857 Available 24x7 ^ De...Gfe Mayur Vihar Call Girls Service WhatsApp -> 9999965857 Available 24x7 ^ De...
Gfe Mayur Vihar Call Girls Service WhatsApp -> 9999965857 Available 24x7 ^ De...srsj9000
 
Biology for Computer Engineers Course Handout.pptx
Biology for Computer Engineers Course Handout.pptxBiology for Computer Engineers Course Handout.pptx
Biology for Computer Engineers Course Handout.pptxDeepakSakkari2
 
Churning of Butter, Factors affecting .
Churning of Butter, Factors affecting  .Churning of Butter, Factors affecting  .
Churning of Butter, Factors affecting .Satyam Kumar
 
CCS355 Neural Network & Deep Learning UNIT III notes and Question bank .pdf
CCS355 Neural Network & Deep Learning UNIT III notes and Question bank .pdfCCS355 Neural Network & Deep Learning UNIT III notes and Question bank .pdf
CCS355 Neural Network & Deep Learning UNIT III notes and Question bank .pdfAsst.prof M.Gokilavani
 
Call Girls Narol 7397865700 Independent Call Girls
Call Girls Narol 7397865700 Independent Call GirlsCall Girls Narol 7397865700 Independent Call Girls
Call Girls Narol 7397865700 Independent Call Girlsssuser7cb4ff
 
pipeline in computer architecture design
pipeline in computer architecture  designpipeline in computer architecture  design
pipeline in computer architecture designssuser87fa0c1
 
Study on Air-Water & Water-Water Heat Exchange in a Finned Tube Exchanger
Study on Air-Water & Water-Water Heat Exchange in a Finned Tube ExchangerStudy on Air-Water & Water-Water Heat Exchange in a Finned Tube Exchanger
Study on Air-Water & Water-Water Heat Exchange in a Finned Tube ExchangerAnamika Sarkar
 

Recently uploaded (20)

Concrete Mix Design - IS 10262-2019 - .pptx
Concrete Mix Design - IS 10262-2019 - .pptxConcrete Mix Design - IS 10262-2019 - .pptx
Concrete Mix Design - IS 10262-2019 - .pptx
 
Call Us ≽ 8377877756 ≼ Call Girls In Shastri Nagar (Delhi)
Call Us ≽ 8377877756 ≼ Call Girls In Shastri Nagar (Delhi)Call Us ≽ 8377877756 ≼ Call Girls In Shastri Nagar (Delhi)
Call Us ≽ 8377877756 ≼ Call Girls In Shastri Nagar (Delhi)
 
CCS355 Neural Networks & Deep Learning Unit 1 PDF notes with Question bank .pdf
CCS355 Neural Networks & Deep Learning Unit 1 PDF notes with Question bank .pdfCCS355 Neural Networks & Deep Learning Unit 1 PDF notes with Question bank .pdf
CCS355 Neural Networks & Deep Learning Unit 1 PDF notes with Question bank .pdf
 
VICTOR MAESTRE RAMIREZ - Planetary Defender on NASA's Double Asteroid Redirec...
VICTOR MAESTRE RAMIREZ - Planetary Defender on NASA's Double Asteroid Redirec...VICTOR MAESTRE RAMIREZ - Planetary Defender on NASA's Double Asteroid Redirec...
VICTOR MAESTRE RAMIREZ - Planetary Defender on NASA's Double Asteroid Redirec...
 
main PPT.pptx of girls hostel security using rfid
main PPT.pptx of girls hostel security using rfidmain PPT.pptx of girls hostel security using rfid
main PPT.pptx of girls hostel security using rfid
 
Architect Hassan Khalil Portfolio for 2024
Architect Hassan Khalil Portfolio for 2024Architect Hassan Khalil Portfolio for 2024
Architect Hassan Khalil Portfolio for 2024
 
Heart Disease Prediction using machine learning.pptx
Heart Disease Prediction using machine learning.pptxHeart Disease Prediction using machine learning.pptx
Heart Disease Prediction using machine learning.pptx
 
Application of Residue Theorem to evaluate real integrations.pptx
Application of Residue Theorem to evaluate real integrations.pptxApplication of Residue Theorem to evaluate real integrations.pptx
Application of Residue Theorem to evaluate real integrations.pptx
 
Past, Present and Future of Generative AI
Past, Present and Future of Generative AIPast, Present and Future of Generative AI
Past, Present and Future of Generative AI
 
INFLUENCE OF NANOSILICA ON THE PROPERTIES OF CONCRETE
INFLUENCE OF NANOSILICA ON THE PROPERTIES OF CONCRETEINFLUENCE OF NANOSILICA ON THE PROPERTIES OF CONCRETE
INFLUENCE OF NANOSILICA ON THE PROPERTIES OF CONCRETE
 
HARMONY IN THE NATURE AND EXISTENCE - Unit-IV
HARMONY IN THE NATURE AND EXISTENCE - Unit-IVHARMONY IN THE NATURE AND EXISTENCE - Unit-IV
HARMONY IN THE NATURE AND EXISTENCE - Unit-IV
 
🔝9953056974🔝!!-YOUNG call girls in Rajendra Nagar Escort rvice Shot 2000 nigh...
🔝9953056974🔝!!-YOUNG call girls in Rajendra Nagar Escort rvice Shot 2000 nigh...🔝9953056974🔝!!-YOUNG call girls in Rajendra Nagar Escort rvice Shot 2000 nigh...
🔝9953056974🔝!!-YOUNG call girls in Rajendra Nagar Escort rvice Shot 2000 nigh...
 
Sachpazis Costas: Geotechnical Engineering: A student's Perspective Introduction
Sachpazis Costas: Geotechnical Engineering: A student's Perspective IntroductionSachpazis Costas: Geotechnical Engineering: A student's Perspective Introduction
Sachpazis Costas: Geotechnical Engineering: A student's Perspective Introduction
 
Gfe Mayur Vihar Call Girls Service WhatsApp -> 9999965857 Available 24x7 ^ De...
Gfe Mayur Vihar Call Girls Service WhatsApp -> 9999965857 Available 24x7 ^ De...Gfe Mayur Vihar Call Girls Service WhatsApp -> 9999965857 Available 24x7 ^ De...
Gfe Mayur Vihar Call Girls Service WhatsApp -> 9999965857 Available 24x7 ^ De...
 
Biology for Computer Engineers Course Handout.pptx
Biology for Computer Engineers Course Handout.pptxBiology for Computer Engineers Course Handout.pptx
Biology for Computer Engineers Course Handout.pptx
 
Churning of Butter, Factors affecting .
Churning of Butter, Factors affecting  .Churning of Butter, Factors affecting  .
Churning of Butter, Factors affecting .
 
CCS355 Neural Network & Deep Learning UNIT III notes and Question bank .pdf
CCS355 Neural Network & Deep Learning UNIT III notes and Question bank .pdfCCS355 Neural Network & Deep Learning UNIT III notes and Question bank .pdf
CCS355 Neural Network & Deep Learning UNIT III notes and Question bank .pdf
 
Call Girls Narol 7397865700 Independent Call Girls
Call Girls Narol 7397865700 Independent Call GirlsCall Girls Narol 7397865700 Independent Call Girls
Call Girls Narol 7397865700 Independent Call Girls
 
pipeline in computer architecture design
pipeline in computer architecture  designpipeline in computer architecture  design
pipeline in computer architecture design
 
Study on Air-Water & Water-Water Heat Exchange in a Finned Tube Exchanger
Study on Air-Water & Water-Water Heat Exchange in a Finned Tube ExchangerStudy on Air-Water & Water-Water Heat Exchange in a Finned Tube Exchanger
Study on Air-Water & Water-Water Heat Exchange in a Finned Tube Exchanger
 

Igor lakhman net_res_v1

  • 1. IGOR LAKHMAN iLakhman@lanwanprofessional.com | (732) 290-5234 SUMMARY IT Professional with over 15 years of experience in planning, engineering, administration, maintenance, optimization , analysis and troubleshooting for various network technologies including VoIP, wireless and data center for medium to global enterprise environments which includes proficiency in routing, routing protocols, switching, WLAN, VPN, WiFi, security, firewalls, network performance and security assessment as well as post-assessment reports and recommendations. TECHNICAL CERTIFICATIONS &SKILLS  Cisco Certified Network Professional – Routing & Switching CCNP–R & S  Cisco Certified Network Professional / Cisco Certified Network Associate CCDP/CCDA  Certified WAN Professional / Certified WAN Enterprise Administrator CWP/CWEA  Cisco Security Administrator / Data Center Administrator CSA/CDCA  Cisco Voice Administrator / Wireless Technician CVA/CWT  Cisco Certified Network Associate – Routing & Switching CCNA–R & S TECHNICAL SKILLS DETAIL Routing/Switching Technologies - Cisco Routers (3900, 2900, 1900, 800 Series), Cisco Catalyst Switch (6500, 5500, 4900, 4500, 3750, 3560-X, 3100), Cisco Nexus 1kv, 2k, 5k Series, Juniper and HP Routers & Switches - WAN, LAN, TCP/IP, Cisco IOS, Spanning Tree Protocol, BPDU, CDP, ACL, NAT, PAT, RIP, RIPv2, OSPF, OSPFv3, EIGRP, BGP, MPLS, VTP, SNMP, SMTP, ARP, TCP, UDP, Static Routing, Stub Routing, VLAN, VLAN Trunking, VXLANs, Multicast routing, HSRP, SVI, CEF, Etherchannel, Portfast, VSS, VPC. Security/Firewalls Technologies - Cisco Security Manager Suite, Cisco ASA 5500 series firewalls, Cisco FWSM, Cisco IPS/IDS, Cisco ACS, Advanced Firewall Manager (AFM), Cisco ASA 1000V cloud firewall, Checkpoint Firewall, Juniper SRX series, Palo Alto, Protocols & Standards - AAA, TACACS+, RADIUS, SSH, VPN, IPSec, SSL/IPSec, Data Loss Prevention, Data Management Zone, Pretty Good Protection (PGP), Public Key Infrastructure (PKI), Internet Key Exchange Policy, Port Security, MAC Address Filtering Wireless/Voice Technologies - Cisco WLC, IEEE 802.1x & 802.11, WLAN, WAP, AP, SSID, LWAPP, Aironet, Bluetooth, Avaya, AURA - Voice Over Internet Protocol (VoIP), VoIP/SIP, CUCM, UCCM, UCCX, MGCP, RSTP, SCCP, STP, Quality of Service (QoS), PoE, MMDS, LMDS, CCK, DSSS Monitoring/Data Center Technologies/APPS - Wireshark, Remedy, Cacti, Nagios, VMware, Solarwinds, Cisco Security Manager Suite, Server, Sniffer, Ethereal, Orion - VMware, F5 Big-IP load balancing (GTM/LTM), Cisco AnyConnect VPN mtg, Cisco Prime, Cisco ISE, Cisco IPS/IDS, Meraki cloud.based - Splunk Enterprise, SNMPv2c, SNMPv3, DNS, DHCP, FTP, Telnet, HTTP(S), SMTP, tunneling protocols, PTP, SFTP, RDP. Other Technologies – Hardware: IBM 30XX; 43XX; Operating Systems: OS/MVS/XA; Languages: Cobol/370, Cobol II, ADS/O; Database: IDMS 14.0, DB2/SQL; Networks: ADS/A IDMS/DC, CICS; Other Packages: JCL, Utilitiies DME, DBOL, DMLO, OLQ, IDD/M, IDD, MAPSC, ADS/G, ADS/M, CULPRIT, DEBUGGER, SPUFL, QMF, INTERTEST, EZTest2000, IDMS Data Ager, DB Image, QA Hyper Station; Other: Quick Books, Microsoft Office. SUMMARY OF PROFESSIONAL EXPERIENCE LAN/WAN Professional Senior Network Engineer/Contractor 2014 – Present Nexus Asset Mgmt LLC & Zimmer Lucas Partners Lead Network Engineer/Project Mgr.2003 – 2014 AG Edwards- New York Stock Exchange Onsite Relations 2002 – 2003 McGraw-Hill Company Senior Programmer/Analyst 2001 – 2002 Top-Tier Brokerage Firms Project Leader /Sen. Prog. / Analyst 1980 – 2001 EDUCATION Certified WAN Professional Program LANWAN Professional Associate of Science in Computer Science Odessa University
  • 2. PROFESSIONAL EXPERIENCE DETAIL LAN/WAN Professional Senior Network Engineer/Contractor 2014 – Present Company Overview – LAN/WAN Professional is a nationwide membership organization of LAN/WAN professionals including administrators, engineers, consultants, analysts, architects located throughout the continental United States. Responsibilities handled:  Member of a team responsible for onsite LAN/WAN support deployment and configurations of routers, switches, wireless, voice, firewalls and related LAN/WAN technologies.  Secondary responsibilities including general escalation troubleshooting support and general administration to included LAN/WAN configurations, logical/physical diagrams based on company standards and policies.  Additional responsibilities included provided timely and accurate updates/reports to technical leads/managers relates to tasks and responsibilities that are assigned and act as subject matter expert on routing, switch related activities. Nexus Asset Mgmt LLC & Zimmer Lucas Partners Lead Network Engineer/Project Mgr. 2003 - 2014 Company Overview – Zimmer Lucas Partners is a private company whose line of business includes providing investment information and advice to companies and individuals. Responsibilities handled:  Researched various network products and interacted with vendors and contractors to evaluate network and telecommunications products and services in preparation of the new installation development effort.  Supervised network assessment and capacity planning project for new network infrastructure.  Lead design, configuration and implementation effort of the trading and back office networks.  Conducted daily monitoring, troubleshooting and maintenance of network equipment and software, and other security components, and peripheral devices.  Managed network equipment and security solutions such as firewalls, anti-virus and intrusion detection systems.  Ensured network connectivity and administered necessary hardware and software upgrades and repairs. AG Edwards- New York Stock Exchange Onsite Relations 2002 – 2003 Company Overview – AG Edwards – New YorkStock Exchange is the world’s largest stock exchange and leading financial market. Responsibilities handled:  Responsible for timely and proficient completion of day-to-day administration, as needed support and troubleshoot of mission critical and time sensitive activities while meeting mandated policies, procedures and compliance.  Professional responsibilities included collections, verification and following corporate policies and procedures. McGraw-Hill Company Senior Programmer/Analyst 2001 – 2002 Company Overview – McGraw-Hill is a worldwide company which is the leading provider of ratings, benchmarks and analytics in the global capital and commodity markets. Responsibilities handled:  Member to a team of professionals responsible for daily production support, maintenance, enhancements, implementation, administration, configuration and troubleshoot activities.  Technologies include but not limited to server, enterprise applications and local area network (LAN) technologies, wide area network (WAN) technologies.  Professional responsibilities included documentation, administration, project management, following corporate policies and procedures, documentation, and scheduling as needed reports to management. Top-Tier Brokerage Firms Project Leader / Sen. Prog. / Analyst 1980 – 2001 Company Overview – Worked as a contractor for a number of Investment Banks and Service companies that provided transaction services to the financial industry. Some of the companies were ADP Brokerage Services, Goldman Sachs & Co. , American Express Bank/EDS, Solomon Smith Barney, Inc. , Citibank and Brown Brothers Harriman to name a few. Responsibilities handled:  Support, maintenance, enhancements to software, testing, administration, analysis, project management and troubleshooting in main frame environments.  Responsibilities included administration, documentation, following corporate policies and procedures and scheduling as needed reports to management.
  • 3. SUMMARY OF TECHNICAL ACCOMPLISHMENTS Routing & Nexus & Catalyst Switching  Implement trunk ports and implement granular control of VLANs and VXLANs using NX-OS to ensure virtual and flexible subnets that can extend further across the network infrastructure than previous generation of switches.  Implement port-profiles as part of the NX-OS command structure that allows for configuration of multiple ports and port-types via inherited configurations applied via a single command that reduces administrative error and allows for better configuration readability.  Implement a virtual version of Nexus: Nexus1000v into VMWare to extend Nexus capabilities directly adjacent to virtual machines so that they benefit from Cisco switching capabilitiesand network topology consistency ensuring VMs maintain their subnet/VLAN relationships during failover.  Implement secure privileged administrative access to the Cisco IOS system. Enable the encryption of system passwords to prevent unauthorized users access to passwords in the system configuration.  Implement secure access to the console and vty ports, and set the interval that the EXEC command interpreter waits until user input is detected on the Console and vty ports. Also, configure the console and vty ports log messaging to not interfere with active device configuration.  Implement VLAN Trunking Protocol to reduce administrative overhead. Enable secure sharing of VLAN information to prevent the introduction of rogue devices from affecting the VLAN database. Shutdown unused switchports following Layer 2 security best practices.  Create and manage Local VLANs based on department function, and configure ports with static VLAN assignment, static 802.1Q trunks, and dynamic ISL trunking using PAgP for layer 2 forwarding. Utilize VLAN Spanning-Tree in conjunction with PVST+ for compatibility between Cisco and Juniper switches. Configure edge ports for fast-transitioning into the forwarding state to fix workstation startup connectivity delays. Modify spanning-tree parameters for manual root bridge assignment. Implement ether-channels between each switch using PAgP for negotiation. Modify ether-channel load balancing method.  Implement WAN links between sites using frame-relay point-to-point and multipoint connections to establish connectivity between each of the four sites as required. Establish frame-relay point-to-point connections three of the sites creating a full mesh. Implement hub and spoke network between three of the sites with the main office as the hub for redundant connections.  Implement EIGRP routing for point-to-point and Non Broadcast Multi-Access networks. Ensure that the spoke routers are receiving routing information about each other from the hub. Configure EIGRP unequal- cost load balancing to also use the lower capacity multipoint links when routing packets.  Prevent neighbor adjacencies from being formed as well as the sending and receiving of routing updates on unnecessary interfaces. Implement EIGRP MD5 Message Authentication between sites to prevent unauthorized insertion of routes into the domain. Implement manual EIGRP route summarization to reduce routing protocol demand on CPU resources, memory, and bandwidth used to maintain the routing table.  Implement OSPF routing with multiple areas for networks between sites. Implement totally stubby areas to lower the system resource utilization of routing devices for the network. Implement NSSA area to allow injection of external routes into the area and propagation into the OSPF domain.  Implement backup and recovery of Cisco IOS Images. Perform password recovery on Cisco IOS routers/switches and a Juniper EX2200 Series switch to restore administrative access. Backup and Restore startup-comfit file for disaster recovery.  Configured and verified internal BGP peering using directly connected networks.  Configured and verified internal BGP peering using loopbacks by using an interior gateway protocol (OSPF) to provide routing information.  Configured and verified external BGP peering using directly connected networks.  Configured and verified external BGP peering using loopbacks and ebgp-multihop.  Configured and verified internal BGP peering using a Route Reflector.  Used debugging diagnostic commands to monitor BGP events.  Configured and verified MPLS manually and using automatic configuration via OSPF.
  • 4.  Configured and verified virtual routing and forwarding (VRF) instances with route-targets and route descriptors.  Configured and verified MP-BGP to send VRF traffic in an MPLS VPN.  Redistributed provider edge networks into MP-BGP.  Verified end-to-end connectivity over the MPLS VPN. Security Implement an IPSec Site-to-Site VPN between the Cisco ASA5505 at small office location and Cisco 1841 ISR with a security IOS image at the main office. Implementation of the VPN includes the following configurations: Internet Key Exchange Policy using DES and SHA for encryption and authentication, access-lists to define VPN traffic, transform set using esp-des esp-sha-hmac to define how the traffic is protected, crypto-map to associate the previously configured elements to a peer, and application of the crypto map to appropriate interface or VPN endpoint. Implementation of Zone-Based Policy Firewall on the Cisco 1841 ISR with the following components: three zones, class-maps specifying traffic that must have policy applied as it crosses a zone-pair, policy maps to apply action to the class-maps’ traffic, zone-pairs, and application of policy to zone pairs. Implement a Clientless SSL VPN (WebVPN) to allow users to establish a secure, remote-access VPN tunnel to the Cisco ASA 5505 using a web browser. Prepare the Cisco ASA with necessary configurations to self-signed certificate generation. Generate a general purpose RSA key-pair for certificate authority identification, configure certificate authority trustpoint for the WebVPN using self enrollment, and configure CA trustpoint interface association. Configure Syslog on the Cisco ASA5505 with logging to a host and internal buffer. Forward all logging to an internal Syslog server for monitoring and management. Configure and manage Syslog output generation using custom message lists. Implement FTP backup of internal buffer when it is exceeded. Implement Basic Threat-Detection, Advanced TCP Intercept, and Scanning Threat-Detection. Simulate attacks on network to manage threat-detection rates and verify Syslog generation. Utilize Cisco ASA5505 Modular Policy Frame-Work to configure and manage layer 3/4 interface service policies, apply inspection and connection limits to services, apply inspection and QoS policing to HTTP traffic. Configure HTTP inspection policy to block restricted sites and file downloads. Voice Implement a local voice network with the following network elements: Cisco 2811 ISR (VoIP) with a Cisco Unity Express Network Module (NM-CUE) installed, Cisco Communications Manager Express, a standard Cisco 3550 Switch, and a Cisco 3550 switch with Power-over-Ethernet. Create and manage Data and Voice VLANs, and configure ports with static VLAN assignment and 802.1Q trunks for layer 2 forwarding. Configure edge ports for fast-transitioning into the forwarding state to fix workstation startup connectivitydelays. Configure Fast Ethernet main and sub-interface assignments as required for intervlan routing. Implement static routes for local connectivity. Implement NTP server, DHCP server, and TFTP server for support of the VoIP network. Modification of system level parameters including max phones, max directory numbers, display format for date and time, and setting the Time-Zone. Implement Unity Voicemail on the Cisco Unity Express Network Module. Configure a dial-peer on the Cisco 2811 ISR to define the attributes of the packet voice network connection to the Cisco Unity Express Network Module. Enable call forwarding on busy or no answer. Implement Message Waiting Indicators and Voicemail access via SMTP. Daisy-chain PCs to VoIP phones to reduce network cabling costs. Utilize PoE ports for VoIP phones to reduce power infrastructure costs. Wireless Implement a wireless network infrastructure providing access to wired LANs to increase mobility and productivity utilizing the following network elements: Cisco Wireless LAN Controller (WLC) 2106, a Cisco 3550 switch, a Cisco 1130AG series Access Point, and a Cisco 1121G series Access Point. Create wireless LANs and configure interface association, security parameters, and radios used. Utilize the Wireless LAN Controllers web GUI to configure and manage the wireless network. Configure internal DHCP scopes for WLANs.
  • 5. Prepare infrastructure for AP registration on same subnet as management VLAN and for AP registration on different subnet. Configure AAA AP policies to allow Self Signed Certifications for APs shipped without a Manufacturer Installed Certificate. Implement AP Grouping to ensure WLAN SSIDs are only broadcast by the APs desired. Data Center  Configured VLANs and access ports connecting virtual machines using the NX-OS CLI on a Cisco Nexus 1000v virtual machine and VMWare vSphere Client networking.  Configured routing policies and service profiles for separate levels in an organizational hierarchy using a Cisco Prime Network Services Controller virtual machine. These policies and profiles were applied to Cisco Cloud Service Router 1000v (CSR 1000v) virtualrouters.  Configured a CSR 1000v router using the Cisco IOS 15.4 CLI. Monitoring  Used the Cisco Configuration Professional GUI to configure interfaces, passwords, hostnames, DHCP, EIGRP, and SNMP on a Cisco router. Used the CCP monitoring tool to monitor traffic from that router.  Configured the Nagios XI monitoring tool to monitor routers and switches and customized its dashboard.  Configured SolarWinds Orion NPM and used it to monitor traffic on a network.  Configured the CACTI tool to graph traffic from a router and to generate alerts based on a threshold traffic level.  Used the Wireshark tool to study HTTP, telnet, and SSL traffic.