Experience
Dec 2022 - Present
2 years 11 months
- Network automation
- CI/CD and Docker environment
- Python Nornir for network automation
- pyATS as monitoring and test case automation
- Network Access Control (RADIUS) and device admin access control (TACACS) with AAA using Cisco ISE on Cisco, HP, and Aruba devices
- Configuration of Cisco ISE clusters (2, 4, and 8 nodes)
- Cisco ISE authentication and authorization configuration
- Configuration of TACACS, dot1x, and RADIUS on Cisco, HP, and Aruba switches and wireless LAN controllers
- Automation of Cisco ISE with RESTCONF and Python
Jan 2021 - Dec 2022
2 years
- Configuration and maintenance of Brocade, Cisco, and Debian switches, routers, iptables, and VPN infrastructure
- Monitoring development (InfluxDB/Telegraf/Grafana, ELK, Elastiflow)
- Configuration of OpenVPN site-to-site and remote access between Debian and pfSense
- Network infrastructure services on Debian (BIND, DHCP, iptables/NAT)
- Automation with Bash, Ansible, and Puppet (security configuration, DNS, DHCP, iptables, …)
- BGP HA automation (using AS path, community, local preference, and metric)
- RIPE ROA/RPKI configuration
- AWS infrastructure configuration (VPN gateway, Bring Your Own IP in AWS or BYOIP, …)
Feb 2020 - Dec 2020
11 months
- Juniper switches and routers
- Firewalls (Juniper SRX, Cisco ASA, Check Point)
- Cisco IOS, Juniper MX
- IPsec VPN (point-to-point and multipoint)
- Automation with Ansible, RESTCONF, and NETCONF
- Automation with Puppet modules
Oct 2011 - Dec 2019
8 years 3 monthsTehran, Iran, Islamic Republic of
- Network infrastructure and data center consultant at National Post Company of Iran (POST) from April 2017 to December 2019
- Network infrastructure and data center consultant at Secure Transaction Infrastructure (SITS) from February 2017 to December 2019
- IPv6 consultant at Iran Telecommunication Research Center (ITRC) from December 2017 to November 2018
- Project to implement LAN security at Sarmayeh Bank, including 802.1X with Cisco ISE and SSL VPN for remote access with Cisco ASA
- Project to implement DMVPN for 120 branches, DMVPN Phase 3 with Cisco ISR routers
- Configuration of FEX, VPC with HSRP, FCoE, and OTV on Nexus 7010, 5600, and 2300 switches at Mellat Bank
- Trainer at RAYKA for routing & switching, network security, service provider, data center, and cloud courses up to CCIE level
- Created video trainings: CCNA-CCIE R&S, CCNA-CCIE SP, CCNA-CCIE Security, CCNA-CCIE Data Center, CCNA-Cloud, Ansible, VXLAN EVPN, Cisco SD-WAN, Bash scripting, F5 LTM, F5 DNS, and Juniper SRX security
May 2005 - Sep 2011
6 years 5 monthsTehran, Iran, Islamic Republic of
- Served as lead for network security and QoS
- Security equipment in the data center: Huawei firewalls and Juniper intrusion detection system
- QoS focus on IP telephony service to minimize delay, jitter, and packet loss
- Trainer for clients in Cisco routing & switching and security courses
May 2000 - May 2005
5 years 1 monthTehran, Iran, Islamic Republic of
- All technology needs: maintaining computers, setting up and maintaining Microsoft servers, Cisco routers and switches, and WAN connections