Karoly B.

Senior Network Engineer, Freelancer with 20+ Years Experience

Neu-Ulm, Germany

Experience

Jan 2024 - Present
1 year 8 months
Garching, Germany

Network Specialist

Zeppelin GmbH

  • Administration of Cisco network infrastructure (LAN, WAN, and WLAN) including Cisco ISE, Cisco Prime, and Palo Alto Panorama applications; support for maintenance and troubleshooting at 3rd level; technical consulting for business units
  • Administration of Palo Alto firewalls, firewall rule configurations; troubleshooting using firewall logs; participation in documentation maintenance; adding missing processes and methods
  • Remote access and site-to-site VPN configurations with Cisco ASA for various external service providers and partner companies; improved network infrastructure and further development of the existing lifecycle; monitoring of responsible systems (PRTG)
  • Configuration templates and other software distribution and new configuration rollout with Cisco Catalyst Center; enabled "Plug and Play" feature for switch configuration automation
  • Management of external service providers; maintenance of IT documentation (operation manuals, etc.)
  • Used HW/SW: Cisco 2900/9300/Nexus 5xxx switch series; Cisco ASA5500-X / Firepower 21xx; Cisco ISE v3.2; Palo Alto Panorama 10.x; Palo Alto Firewall 220/30xx series; Cisco Catalyst Center; Cisco Prime 3.10; Cisco Umbrella; Splunk; RSA Appliance (Secure Logon); Meraki MS210 switches; MR44 APs
Aug 2023 - Dec 2023
5 months
Munich, Germany

Cisco Network Specialist

Münchener Hypothekenbank

  • Administration of Cisco network infrastructure (LAN, WAN, and WLAN) including Cisco ACI, DNA Center, ISE, and Email Security Appliance; support for maintenance and troubleshooting at 3rd level; technical consulting for business units
  • Administration of Check Point firewalls; firewall rule configurations; troubleshooting using firewall logs; use of SmartConsole and GAIA OS
  • Implementation of measures to ensure and improve network infrastructure and further development of the existing lifecycle; monitoring of responsible systems (LibreNMS)
  • Management of external service providers; maintenance of IT documentation (operation manuals, etc.)
  • Used HW/SW: Cisco 9300 switch series; Cisco ISE v3.2; Cisco DNA Center v2.3; Cisco ACI v5.x; Cisco ESA C300V; Check Point 6000/7000 series firewalls
Nov 2022 - Oct 2023
1 year

Senior Network Engineer

AundE Group / Fehrer

  • Operation, maintenance, and administration of the global network and security system landscape; support for maintenance and troubleshooting at 3rd level; technical consulting for business units
  • Independent planning, execution, and monitoring of system updates (updates, upgrades, minor/major changes, software/hardware swaps/upgrades, etc.); responsible for end-to-end creation, continuation, and updating of documentation, guides, and operations manuals across locations
  • Management of external service providers as part of service and escalation management
  • Writing or modifying Ansible scripts based on task requirements
  • Used HW/SW: VMware Velocloud SD-WAN; ExtremeCloud IQ; Extreme Networks X440/X460/X680 series switches; Extreme Networks NAC; PRTG; FortiGate FW 80E-600F v7.0; FortiAuthenticator v7.x; FortiSandbox v7.x; FortiAnalyzer v7.x; FortiManager v7.x; FortiMail 7.x
Feb 2022 - Nov 2022
10 months
Essen, Germany

Security Consultant + Subproject Lead

RWE AG

  • Technical network project management; subproject leadership in migration and consolidation topics (several Cisco ASA to FortiGate 1101 models (multi-VDOM configuration), layer 2/3 switch consolidation at multiple sites, lifecycle replacement, migration of multiple sites to redundant IPSec VPN connections from single VPN-tunnel sites); participation in project and new design discussions; defining and implementing project milestones; collaboration with internal and external colleagues
  • Operational support in firewall rule implementation and troubleshooting in routing, security, VPN, and site-to-site VPN areas (Palo Alto, FortiGate, Cisco ASA + Firepower devices); AWS cloud administration and troubleshooting
  • Used HW/SW: Palo Alto Panorama v10; Palo Alto firewall 200/3000/5000 series; AWS Cloud Web Services; Splunk; FortiManager; FortiAnalyzer; FortiGate 30/80/200/1100 series firewalls; Cisco ASA5545-X; Cisco ASDM; Cisco Catalyst 2960-X/3800 switches; Cisco Nexus 2000/5000 series switches; HP Aruba switches and access points
Jan 2022 - Jun 2023
1 year 6 months
Germany

Network / Security Consultant + Project Lead

ECKART GmbH

  • Creating project schedules for LAN and WLAN component replacements with Cisco DNA Center (20 sites, 300 devices); executing the project plan; preparing hardware order lists by site and getting approval from management and site contacts
  • Performing network segmentation and lifecycle replacement projects with local IT technicians at all sites worldwide
  • Evaluating existing security concepts from external integrators on endpoint security and firewall improvements; coordinating with team leads and affected departments
  • Planning new sites; developing network designs (HLD and LLD) according to company standards
  • Supporting the operation of firewalls and LAN/WLAN infrastructure; firewall rule maintenance; creation and maintenance of relevant documents; troubleshooting and analysis; log file analysis
  • Managing an external service provider and internal staff; updating project plans; tracking deliverables
  • Used HW/SW: Cisco WLC9800; Cisco AP 2700/2800/3600/9100 series; Open Systems SD-WAN; Cisco 9200-9300 series switches; Cisco DNA Center; NeDI; PRTG; FortiGate FW 200E-600E v6.2; FortiAuthenticator v6.x; FortiSandbox v6.x; FortiAnalyzer v6.x; FortiNAC v9.x; Palo Alto Panorama v10; Palo Alto 400 series and 3200 series firewalls; Palo Alto Cortex XDR Endpoint Security
May 2021 - Dec 2021
8 months
Holzwickede, Germany

Firewall Specialist

Rhenus Logistics

  • Supported firewall replacement project at all locations in Europe (around 500 sites), migrating from Juniper to newer Palo Alto models in a project team (6 colleagues)
  • Supported firewall rule configurations and troubleshooting for outages and other incidents
  • Assisted in configuring Cisco SD-WAN appliances between headquarters and remote offices for various transport protocols (MPLS, P2P, DSL connections), using vManage and vSmart for VPN policy configurations during new office setups, applying routing configuration via SD-WAN vManage
  • Used HW/SW: Juniper SRX100/240/300/1500/4000 series firewalls, Palo Alto 220/3200/5200 firewalls, JunOS Space, Palo Alto Panorama v10, ITS4 ticket system, Tufin SecureTrack, Infoblox, Spektrum CA monitoring, Icinga2 monitoring, Cisco SD-WAN v18.1, HP Procurve and Aruba switches
Nov 2020 - Sep 2021
11 months
Mainz, Germany

Project Engineer

Aareon Deutschland / Aareal Bank AG

  • Supported network segmentation project at Aareon Deutschland GmbH after Aareal Bank AG acquisition, consolidating firewall policies and redesigning IP addressing, preparing IPv6 addressing technology, reconfiguring Checkpoint firewalls to IPS, threat emulation, zero-day attack and SandBlast applications
  • Created new unified company rules across all access and server network areas at German and European branches (VLANs, IP address ranges, firewall objects, firewall rules, switch configs, naming conventions, WLC configs), testing and troubleshooting after migrations
  • Implemented 802.1x authentication (MAC-address or machine certificate) for PCs, printers, and other endpoints using Cisco ISE, TACACS and RADIUS servers, FlexConnect and other AP/WLC configs
  • Assisted in MFA (multi-factor authentication) project with RSA Authentication Manager 8.x, held customer meetings and did requirements analysis with the project team and external experts. Connected RSA Authentication Manager to AD, configured policies, users, RADIUS profiles/clients, identity sources, backup tests, replica setup, created failover scenarios, project documentation and reports based on customer needs
  • Assisted in configuring Cisco SD-WAN appliances between headquarters and remote offices, using new configuration templates (vManage, vSmart) for VPN policies during new office rollouts, applying routing (OSPF, BGP), QoS, traffic engineering and app-policy configurations
  • Automated daily routine tasks, collected necessary data or changed global configs on network devices using Ansible scripts
  • Used HW/SW: Cisco Catalyst 2960/3560/6500/9300 series switches, Cisco Nexus 5500 switches + 2248 FEX modules, Checkpoint 1400/5000/15000 series firewalls, Fortigate firewalls v6.2 with FortiAnalyzer, Cisco ASA-X firewalls, Cisco ISE v3.0, Cisco WLC 5500 series, RSA Authentication Manager v8.x, Cisco SD-WAN v17.2, HP Procurve switches
Feb 2019 - Oct 2020
1 year 9 months
Nuremberg, Germany

Network/Firewall Specialist

BNP Paribas/Consorsbank

  • Handled tickets and provided last-level support for firewall authorizations in Munich and Nuremberg, created load balancer VIPs, iRules, load balancing, and changed settings based on customer requests
  • Managed security certificates for endpoints and public servers (rolled out 802.1x authentication with Cisco ISE) and renewed them every two years using Microsoft PKI
  • Performed software and hardware updates, migrated to a compact (consolidated) firewall and LAN network
  • Proactively monitored performance/load and latency using NetFlow and OpenNMS
  • Consolidated firewall rules using Tufin software and built a new rule structure (consolidating 3,500 rules to 200), developed user-based firewall authorizations based on AD groups
  • Automated daily routine tasks, collected necessary data or changed global configs on network devices using Ansible scripts
  • Used HW/SW: Cisco Catalyst/Nexus switches (Catalyst 2960, 3650, 4500, 6500 series, Nexus 5000/7000/9000 series), Checkpoint 12000/4000 firewall appliances (SW ver. R80.10), Smart-1, VSX, SmartConsole R80.20, Checkpoint CloudGuard, Cisco FWSM, Cisco ASA-X 5515/5525 ver. 8.6.1, Palo Alto firewall PA200, PA220, PA3060, PA5050 (VPN), PA5250, PAN-OS 7.1-8.0, Forcepoint/StoneGate SG-3201 firewall, Fortinet FortiGate 800C (SW 5.2.2), FortiManager (SW 5.4), load balancers F5 BIG-IP 10200, 5050, 4200, i4600, F5 ASM (WAF), Palo Alto Panorama ver. 8.0 for monitoring, Infoblox, NeDi, Tufin, OpenNMS, syslog, Splunk, ServiceNow ticket system, Nagios, Cisco ISE
Jun 2018 - Jan 2019
8 months
Munich, Germany

Network Consultant

Unisys Deutschland GmbH/Bayerisches Justizministerium

  • Took over the network from a colleague who left (group transfer due to mass layoffs)
  • Handled tickets and provided last-level support at sites in Bavaria with IET ticket system (around 150 sites)
  • Daily operation of LAN and WLAN environments and supported 2nd-level and server teams on network issues, provided training and workshops, explained the use of new technologies (Cisco VRF-Lite, MACsec, ISE, ACI)
  • Further developed/optimized the overall solution in close coordination with the customer, advised on implementing new/changed business requirements
  • LAN refresh, network developments (device and IP address expansions at various sites), site builds and decommissions, coordination of field engineers, single to redundant site migrations, routing adjustments
  • Used HW/SW: Cisco ASDM, ACI, Prime, ACS server, ISE, KIWI CatTools, Microsoft NPS, Windows Server 2012, Cisco ASA 5515-X, Cisco switches (2960, 3560, 3650, 3750, 3800, 4500, 4900 series), Nexus switch (3100 series), Icinga/MRTG monitoring, Cisco WLC 5508/8500 series
Jan 2018 - May 2018
5 months
Karlsfeld, Germany

Security Engineer

Dimension Data AG

  • Performed operational tasks: defined and implemented security-related and/or organizational measures
  • Designed security infrastructure, did preventive maintenance, analyzed and resolved issues, implemented non-standard changes, evaluated change requests for their impact and risks
  • Created documentation and reports using FNT-Command and Microsoft Visio
  • Used hardware/software: Cisco IronPort, Cisco ASDM, Splunk Log Management, HP/VW Service Center 2.0, Checkpoint SmartDashboard/SmartView, Genua Genugate 800 / Genubox 400, Checkpoint 4800 firewall (SW ver. R77.30), Checkpoint CloudGuard, Cisco ASA 5555-X / 5585-X, Cisco Firepower 4110, Juniper SRX 1400, Cisco WSA S680 / SMA M680
Mar 2017 - Jan 2018
11 months
Munich, Germany

Technical Project Lead

Landeshauptstadt München / it@M

  • Technical project management for migration, coordinating remodeling work, network expansions for various departments (Social Affairs, Construction, Planning, District Administration, AWM, Directorate), supporting about 500 devices.
  • Operation, maintenance and further development of the infrastructure, implementation based on regulations on a virtualized platform.
  • Troubleshooting (receiving, analysis, resolution) using Assyst ticket system.
  • Inventory and needs analysis => documentation, network planning, component selection, client advising.
  • Carrying out remodeling and migrations with third-party companies (subproject lead), site migrations onto the new MPLS VPN design (new IP addresses, new device installations, new configurations (PE-CE sites)), followed by functionality and redundancy tests.
  • Advising city departments and municipal enterprises on communication technology questions, such as network solutions for various situations (connections, routing+switching, redundancy, datacenter, security, wireless rollout, guest Wi-Fi options).
  • Operation, maintenance (Command), optimization and administration of active network components deployed (Cisco routers and switches, Cisco ASA/ASA-X or Check Point 2000-4000 firewalls (SW ver. R77.30), Cisco WLC 4400/5500 series, Fortinet FortiGate 200/300 series firewalls), the entire MPLS network (P, PE, CE devices, MPLS VPN and BGP routing).
  • Creating concepts for various future and existing scenarios (larger/smaller sites with or without redundancy, hardware recommendations), WLAN installation concept (WLAN controller, APs, corresponding network hardware), concepts for different redundancy options (VSS, L3 redundancy, L2 redundancy, spanning-tree load balancing). Updating old concepts to current standards and Cisco recommendations.
Jun 2016 - Mar 2017
10 months
Haar, Germany
Lorem ipsum dolor sit amet

Finanz Informatik Technologie Service

  • Monitoring WAN/LAN (monitoring and checking status, utilization and performance, carrying out regular standard tests).
  • Ensuring that assigned trouble tickets, operational tasks, other orders and changes are processed correctly.
  • Troubleshooting (receiving, analysis, resolution).
  • Building and expanding WAN/LANs including active and passive network components (Cisco 2960/3560/4500 switches, Juniper EX series, Juniper SSG 5/10, SSG140, SSG350 cluster, F5 load balancer).
  • Migrating existing Juniper firewalls (SSG and SRX series) to Fortinet 80, 90, 100 series using Fortinet FortiConverter software and/or manual review of firewall rules.
  • Working with external service providers and coordinating them during incidents and installations.
  • Configuration and preparation for an ISP change or site teardown/setup based on customer requirements, voice readiness configurations at Bayerische Sparkasse and LB branches main office distribution layer, firewalls and various security configurations (e.g. IPSec VPN, load balancing, voice over IP, QoS).
  • Migration from Juniper to HP devices (Layer 2/Layer 3). Application use (Juniper NSM, Spectrum, Command, PSM (Auconet), Solarwinds Orion, eHealth).
  • Setting up and analyzing network traces, contributing to projects and conceptual tasks, optimizing networks and workflows.
Jul 2014 - May 2016
1 year 11 months
Stuttgart, Germany
Lorem ipsum dolor sit amet

Porsche AG

  • Rollout of standard network components in production environment (switches, routers, access points, firewalls). Data center operations (Cisco Nexus 2000/5000/7000 series, Cisco 6500-6800 series with VSS technology, Cisco ASA/ASA-X and Check Point 2200-4400 firewalls (SW R77.10), IPv6 addresses, Cisco WLC).
  • Technical project management for migration, teardown and setup, network expansions.
  • Advising on new technology introductions, project planning/pilot tests, software (IOS) certification.
  • Migration from 2.4 GHz to 5 GHz wireless LAN at all sites, project planning and implementation.
  • Assistance and test plan execution during prime installation (component testing), prime fine-tuning after implementation. Monitoring of the entire network using Cisco Prime application.
  • Development of WAN, LAN and WLAN standard concepts, configuration templates on various network platforms and sites, especially in production environment.
Aug 2011 - Jun 2014
2 years 11 months
Munich, Germany

System Engineer

Dimension Data

International integration company, Cisco Voice and other network installations and planning. Working in subprojects. Vendor-neutral consulting and implementation.

  • Creating concepts for the implementation and operation of equipment in an existing customer environment or expansion of a new environment.
  • Installation, configuration and support of communication hardware and software.
  • On-site support and customer assistance with the introduction of new technologies.
  • Work in 2nd/3rd level support at MAN Truck & Bus (LAN, WAN, WLAN support), troubleshooting on-site and at various locations such as Neufahrn, Munich/Karlsfeld, Augsburg and remote at all German MN, MDT, MCC, MTB sites.
  • Supporting subprojects, building/upgrading new sites, supporting and leading projects in the areas of wireless, routing & switching and VoIP at the customer.
  • Voice network migrations for different customers (Leoni AG, REHAU..) for various branches, conducting workshops and training on VoIP technology for customers.
Sep 2009 - Jul 2011
1 year 11 months
Bratislava, Slovakia

Voice Engineer

AT&T GNS

Multinational telecommunications company with over 300,000 employees worldwide, mainly monitoring and support, troubleshooting for Cisco IP telephony and network systems with remote access. The Bratislava branch is the EMEA headquarters with about 1500 employees.

  • Configuration of Cisco VG224/248 devices, CallManager 3.x - 7.x, Unity 4.x – 7.x, CUE, CME, CER, IPCC devices for customers, configuring new customer sites based on approved plans, identifying VoIP issues for customers. Performing necessary maintenance on servers, routers and gateway devices. Working with AT&T ticket system and change management processes.
  • Installing and/or upgrading existing Unity or CallManager versions according to customer contracts or requirements at end customers such as Lexmark, General Motors, Flowserve, Ford Motor Co., Eli Lilly, Cognizant.
Aug 2008 - Dec 2009
1 year 5 months
Budapest, Hungary

Network Engineer

Interware ISP

Internet provider and server hosting environment. VSS technology was implemented to increase availability to 100% SLA. Implementation of new technologies (IPv6, QoS) to stay competitive. Connected to major Hungarian Internet providers, Budapest Internet Exchange and also to international providers.

  • Maintenance and monitoring of the entire network (60 devices + customer devices) and services (xDSL, hosting, leased line, VoIP, managed services). Configuration and installation of Cisco routers and switches within Interware datacenter and offices (routers series 800-7600, switches series 1900-6500). Use of OSPF, BGP, MPLS and MPLS-VPN protocols.
  • Implementation and installation of Juniper SSG5, Cisco ASA, PIX and Checkpoint firewalls, Draytek Vigor, Linksys and 3COM devices for customers. Implementation of QoS and IPv6 technologies in the network.
  • Configuration of Cisco VoIPGW (Cisco AS series) devices, SIP or H323 trunks, troubleshooting VoIP issues for customers. Making changes based on customer requirements. Using SolarWinds Orion, MRTG, Cacti and Nagios applications for network monitoring.
  • Pre-sales and post-sales activities with sales staff based on customer demands.
  • Maintaining network documentation and the RIPE database regarding new AS numbers or new public IP address ranges for customers.
Feb 2007 - Aug 2008
1 year 7 months
Tatabánya, Hungary

IT Engineer

Bridgestone GmbH

Manufacturing company with a redundant network and car tire production in 3 shifts. Wired and wireless network for offices and production area with about 3000 endpoints and 100 servers. Strict network security due to confidentiality of the fully automated production technology.

  • Maintenance and installation of HP Blade and DL servers (DC, WSUS, application servers, file and print servers), support of other IT devices and users. Monitoring the infrastructure with HP OpenView, HP Insight Manager, Nagios, MRTG and Cacti applications.
  • Maintenance and configuration of Cisco devices (2960-6500 series switches, 2800/1800 series routers). Configuration and installation of the IP telephony system (CallManager 4.2 + Unity 4.0), the two wireless controllers and setup of 45 APs. Setup of the Tandberg MX series conference system.
  • Administration and monitoring of two Cisco ASA5540s with IPS modules, Cisco MARS, NAC, Security Agent and Management Center.
Feb 2005 - Feb 2007
2 years 1 month
Székesfehérvár, Hungary

IT Supervisor

IBM GS GmbH

Multinational telecommunications company with more than 200,000 employees worldwide, responsible for monitoring and supporting customer servers and other devices. The branch in Székesfehérvár is the second largest office in Hungary with about 800 employees working as experts and levels 1-3 engineers.

  • Server monitoring and troubleshooting customer servers (Windows 2000/2003, AIX). We used Tivoli Desktop, Tivoli Enterprise Console, NetView and TSM applications.
  • From February 2006, I was part of the level 3 team, where I was responsible for monitoring and troubleshooting Windows servers and Cisco devices/network (with about 500-800 endpoints). We used Patchlink, TSM and VMware ESX server applications with clients such as Alcatel, Bayer, Cedo, DAK, Deutsche Boerse, Hapag-Lloyd, Lufthansa, Muenchen.de, Roche and Stepstone Solutions.

Languages

Hungarian
Native
German
Advanced
English
Advanced

Education

Oct 2002 - Jun 2004

Péch Antal Technische Fachmittelschule und Technikum

Computer Science Technician · Computer Science · Tatabánya, Hungary

Oct 2000 - Jun 2002

Kodolányi János Fachmittelschule

Computer Programmer · Computer Science · Tatabánya, Hungary

Certifications & licenses

Fortinet FortiGate 7.4 Administrator

Fortinet

Palo Alto Networks Certified Network Security Administrator

Palo Alto Networks

Cisco Certified Specialist - Service Provider Core

Cisco

Fortinet FortiGate 7.0 Administrator

Fortinet

Palo Alto Networks Certified Network Security Administrator

Palo Alto Networks

Check Point Certified Security Administrator CCSA R80

Check Point Software Technologies

Understanding Cisco Network Security

Cisco

Understanding Cisco Wireless Network Fundamentals

Cisco

Understanding Design for Cisco Internetworking Solutions

Cisco

Understanding of Cisco Data Center Technologies and Networking

Cisco

Understanding of Cisco Network Devices

Cisco

Cisco Certified Network Professional Security (CCNP Security)

Cisco

Cisco Certified Specialist - Network Security Firepower

Cisco

Cisco Certified Specialist - Security Core

Cisco

Cisco Certified Specialist - Security Identity Management Implementation

Cisco

Cisco Certified Specialist - Web Content Security

Cisco

Cisco Certified Specialist - Network Security VPN Implementation

Cisco

Juniper Networks Certified Associate, Junos (JNCIA-Junos)

Juniper Networks

Cisco Certified Network Professional Data Center (CCNP Data Center)

Cisco

Cisco Certified Specialist - Data Center Core

Cisco

Cisco Certified Specialist - Data Center Design

Cisco

Cisco Certified Network Associate Data Center (CCNA Data Center)

Cisco

Cisco Certified Network Professional Wireless (CCNP Wireless)

Cisco

Cisco Certified Specialist - Enterprise Wireless Design

Cisco

Cisco Certified Specialist - Enterprise Wireless Implementation

Cisco

Cisco Certified Network Associate Wireless (CCNA Wireless)

Cisco

Cisco Certified Network Associate Security (CCNA Security)

Cisco

Cisco Certified Design Professional (CCDP)

Cisco

Cisco Certified Specialist - Enterprise Design

Cisco

Cisco Certified Network Professional Enterprise (CCNP Enterprise)

Cisco

Cisco Certified Network Professional Routing and Switching (CCNP Routing and Switching)

Cisco

Cisco Certified Specialist - Enterprise Advanced Infrastructure Implementation

Cisco

Cisco Certified Specialist - Enterprise Core

Cisco

Cisco Certified Design Associate (CCDA)

Cisco

CCNA

Cisco

Cisco Certified Network Associate Routing and Switching (CCNA Routing and Switching)

Cisco

Need a freelancer? Find your match in seconds.
Try FRATCH GPT
More actions