Tom Heinrich

Infrastructure Design and Implementation

Avatar placeholder
Möhnesee, Germany

Experience

Jan 2025 - Present
1 year

Network Architect / System Engineer

Teleperformance

Key focus: Fortinet rollout / site homogenization / cloud / ISP migration

  • Network analysis, design and optimization, change
  • ISP changes
  • Commissioning of service providers, decentralized IT support
  • Setting up central management platform
  • Routing optimization to dynamic routing
  • Optimizing and creating firewall rules
  • AWS integration / design
  • MS Azure integration / design

Technologies / Tools: Fortigate, Palo Alto, WAN, SDN WAN, VPN, BGP, OSFP, Fortimanager, Panorama, Meraki, Alcatel, AWS, MS Azure, Network Architecture

Apr 2024 - Dec 2024
9 months
Düsseldorf, Germany

Network Engineer / Network Architect

Douglas IT

Key focus: Fortinet rollout / site homogenization

  • As-is assessment
  • Documentation
  • Setting up central management platform
  • SD-WAN connections
  • Replacement of Bintec
  • Commissioning, mostly in the evening / night / weekends
  • Follow-up of the local network, Cisco Meraki switches and access points
  • Datacenter migration Hagen -> Düsseldorf
  • Replacing Juniper DC solution with Cisco Nexus VPC
  • Datacenter documentation current / target

Technologies / Tools: Fortigate, WAN, SD-WAN, Bintec, VPN, BGP, OSFP, Fortimanager, Cisco Meraki switches and APs, VMware, NX-OS, Netbox, Visio, Fortiswitch, FortiAP, Network Architecture, Juniper

Jan 2024 - Present
2 years

Lead Network Architect

Francotyp Postalia

Key focus: Fortinet rollout / site homogenization / DC hardware migration

  • Technical procurement consulting
  • Network analysis, design and optimization, change
  • Planning / documentation
  • Commissioning of service providers, decentralized IT support
  • Setting up central management platform
  • Routing optimization to dynamic routing
  • Darktrace analysis
  • MS Azure integration / design

Technologies / Tools: Fortigate, WAN, SD-WAN, VPN, BGP, OSFP, Fortimanager, Fortiswitch, FortiAP, Juniper SRX, Darktrace, MS Azure, AWS, Network Architecture, HP Aruba

Jan 2024 - Apr 2024
4 months

Network Architect, Network Engineer

Metabowerke GmbH

Key focus: Fortinet rollout / site homogenization

  • Staging
  • Firewall migration (device + policy)
  • Commissioning of service providers, decentralized IT support
  • Setting up central management platform
  • SD-WAN connections
  • Reverse engineering, hardening of firewall rule set, applying security profiles
  • Adoption into central management, hypercare phase, if needed adjustments and
  • AWS integration / design
  • Troubleshooting
  • Commissioning, also in the evening, weekends and holidays (per customer request)
  • Follow-up of the local network, mostly Cisco Systems and HP Aruba

Technologies / Tools: Fortigate, WAN, SD-WAN, VPN, BGP, OSFP, Fortimanager, Fortiswitch, Checkpoint, Sonicwall, AWS, Cisco switches, HP Aruba, Network Architecture

Jun 2023 - Sep 2023
4 months

System Engineer

Infodas

Key focus: LAN/WAN assessment, WAN/network redesign

  • Network analysis, design and optimization
  • Planning / documentation

Technologies / Tools: Fortigate, Cisco, VMware, MS Azure, AWS, Fortiswitch, FortiAP, Network Architecture

Jun 2023 - Sep 2023
4 months

Network Specialist

Signal Iduna

Main focus: network separation / segmentation / zoning

  • Network analysis, design and optimization
  • Planning / documentation
  • Creating firewall rules
  • Commissioning service providers

Technologies / tools: Fortigate, HP Aruba, servers, network architecture

May 2023 - Apr 2024
1 year
Germany

Lead Engineer for SD WAN rollout in Germany

Telefonica Deutschland

Main focus: SD WAN

  • Customer consulting
  • Network analysis, design and optimization
  • Planning / documentation

Technologies / tools: Fortigate, WAN, SDN WAN, VPN, BGP, OSPF, Cisco / HP Aruba / Netgear / TP-Link switches, network architecture

Mar 2023 - May 2023
3 months

Network / Firewall Specialist

Aunde

Project on behalf of CirC IT.

  • Ticket handling, mainly in the firewall area
  • Troubleshooting
  • Local network analysis, mostly Fortinet
  • Network analysis, design and optimization
  • Planning / documentation

Technologies / tools: Fortigate, WAN, SDN WAN, VPN, Cisco switching, FortiSwitch, FortiAP

Nov 2022 - Mar 2023
5 months

Network Engineer

Würth Group

Project on behalf of Computacenter AG.

  • Rollout and implementation of about 200 Fortinet firewalls (model F601E/FG-101F) in over 80 subsidiaries worldwide
  • Initial documentation of the IT infrastructure, coordination with local IT, alignment with central IT
  • Aligning customer requirements, reviewing existing documentation
  • Preparing the local network, mostly Cisco Systems
  • Migrating existing rule sets using FortiConverter
  • Adjusting system, interface, and VPN settings / rule sets according to central IT requirements
  • Deployment, including evenings, weekends, and holidays (depending on customer needs)
  • Segmentation into VLANs and subinterfaces, separation of services
  • Firewall rule set optimization, adjustments in coordination with global and local IT
  • Reverse engineering, hardening firewall rule sets, applying security profiles
  • Migration to central management, hypercare phase, adjustments and
  • Troubleshooting
  • Post-configuration of the local network, mostly Cisco Systems
  • Integration into PRTG, centralized global monitoring
  • Documentation
  • Handover to central IT, operational phase

Technologies / tools: Fortigate, FortiManager, FortiConverter, FortiAnalyzer, WAN, SDN WAN, VPN, Cisco routing / switching, Dell servers, HP servers & HP switches, VMware, MS Windows Server, Linux Server

Oct 2018 - Oct 2022
4 years 1 month

Network Architect / Consultant

NTT DATA Business Solutions

  • Concept creation, WAN design, vendor and product selection
  • Design and implementation of central firewall management, FortiManager
  • Design and implementation of central firewall management, FortiAnalyzer
  • Design and classification of a global IPv4 IP concept, level A – enterprise
  • Header policy design
  • Rollout and implementation of about 80 Fortinet firewalls (models 60/100/200/600) in over 50 countries worldwide
  • Expansion / redesign of LAN standards (including replacements), Cisco switches models 9500/3650/Nexus
  • Coordination with site managers, usually IT staff
  • Implementation of centralized DHCP services, certificate services, 802.1X
  • Introduction of two-factor FortiToken, FortiAuthenticator
  • Expansion of global remote dial-in
  • Global monitoring with Cisco Prime and distributed PRTG systems
  • Global second level support, vendor escalation
  • Redesign of WAN connections using own firewall systems, VPN, BGP, OSPF
  • Data center redesign, three-firewall concept (two vendors), logical separation of data center / office
  • Replacement of leased MPLS, migration to VPN, SD-WAN
  • Firewall rule set optimization
  • Supporting UHD with tickets
  • Training new employees and apprentices
  • Remote and on-site assignments worldwide

Technologies / tools: Fortigate, FortiManager, FortiConverter, FortiAnalyzer, WAN, SDN WAN, VPN, Cisco routing / switching, Dell servers, HP servers & HP switches, VMware, MS Windows Server, PRTG, ServiceNow, network architecture

Apr 2018 - Oct 2018
7 months
Frankfurt am Main, Germany

Datacenter Migration Consultant

Telefónica / O2

Project on behalf of Cancom GmbH.

  • Move datacenter from Munich to Frankfurt
  • Create quotes
  • Divide devices to be replaced into installation or staging blocks
  • Identify affected switches and import new switches into Command
  • Review environment design and redesign
  • Manage, plan, and document changes in ARS
  • Assess risk and complexity
  • Update network documentation (network diagrams, etc.)
  • Coordinate with responsible departments and external service providers
  • Create migration/move runbook and manage teams
  • Site inspection

Technologies / Tools: Cisco Routing / Switching, Check Point Firewalls

Jan 2017 - Dec 2017
1 year
Munich, Germany

Freelancer

Baumann TGA

  • Plan and set up a new office in Munich (cabling, servers, clients)
  • Antivirus concept with Worry-Free Business
  • Expand and connect storage
  • Wi-Fi with UniFi
  • Installation, support and operation, training and handover

Technologies / Tools: Fortigate, Switching, HP Servers, VMware, MS Windows Server, Veeam, Trend Micro AV

Jan 2017 - Dec 2017
1 year
Schalksmühle, Germany

Freelancer

Spelsberg

Combined projects for 2017.

  • Project Spelsberg II**

  • Expand data center (DC III) at 2 locations

  • Extend and configure LAN at 2 locations

  • In-house redesign (switches and cabling)

  • Create heatmap (signal coverage) – capture and optimize Wi-Fi (manufacturers: UniFi / Ubiquiti, Cisco Systems)

  • Installation, support and operation, training and handover

  • Project Spelsberg I**

  • Rebuild data center and infrastructure in Schalksmühle and Butttstätt

  • Design and set up firewall cluster for redundant VPN connections between Spielberg and Schalksmühle

  • In-house redesign (switches and cabling)

  • Create heatmap (signal coverage) – capture and optimize Wi-Fi (manufacturers: UniFi / Ubiquiti)

  • Installation, support and operation, training and handover

Technologies / Tools: Cisco Routing / Switching, Network Architecture, UniFi

Jan 2016 - Dec 2016
1 year

Freelancer

Project JONA (dental practice with 14,000 patients and a day clinic).

  • Set up network and firewall from scratch
  • SSL VPN for remote work
  • Server environment virtualization
  • Site-to-site VPN
  • Integrate backup solution with Veeam
  • Support and operation, training and handover

Technologies / Tools: Fortigate, Switching, HP Servers, VMware, MS Windows Server, Veeam, Trend Micro AV, Network Architecture

Jan 2015 - Dec 2015
1 year

Freelancer

  • Set up network and firewall ruleset from scratch
  • Server environment virtualization
  • Site-to-site VPN
  • Integrate backup solution with Veeam
  • Support and operation, training and handover

Technologies / Tools: Fortigate, Cisco Switching, HP Servers, VMware, MS Windows Server, Veeam, Trend Micro AV, Network Architecture

Jan 2015 - Dec 2015
1 year
Switzerland

Freelancer

Weka Media

  • New build of the Weka Media WAN, site-to-site VPN, hub-and-spoke
  • Main responsibility for the Weka Media WAN
  • Management of 8 firewall clusters
  • Redesign of the Kissing data center
  • Operation and maintenance of the Kissing data center
  • Redesign, planning and setup of 8 branches/locations: Germany, Austria, Switzerland

Technologies / Tools: Fortigate, Fortimanager, Fortianalyzer, Cisco routing/switching, PRTG, network architecture

Jan 2014 - Dec 2014
1 year
Russian Federation

Main responsibility for the Hoffmann WAN

Hoffman GmbH Munich

  • Management of 35 firewall clusters
  • Operation and maintenance of the Munich and Nuremberg data centers
  • Setup of the central data center as a mirror data center
  • Planning and setup of 3 branches/locations: India, Russia, North America

Technologies / Tools: Fortigate, Fortimanager, Forticonverter, Fortianalyzer, WAN, VPN, Cisco routing/switching, network architecture

Jan 2007 - Dec 2013
7 years

Main responsibility for the Synlab network

Synlab Services GmbH

  • Among other things, main responsibility for the Synlab network (data center, branches (domestic and abroad (EMEA)), MPLS and Internet)
  • Main responsibility for ISO 9001/27001 (re-)certification through Q4 each year since 2010
  • Project consulting / planning / implementation
  • Staff planning for projects
  • Planning and expansion of the Synlab network infrastructure (international)
  • 3rd level support (partial coordination of staff and on-site support at branches when needed)

Technologies / Tools: Fortigate, Fortimanager, Forticonverter, Fortianalyzer, WAN, VPN, Cisco routing/switching, network architecture

Jan 2003 - Dec 2007
5 years
Munich, Germany

Planning the replacement of the existing FDDI backbone

State Lottery Administration Munich

  • Project consulting / planning / implementation
  • 3rd level support
  • Communication interface with external companies
  • T-Systems, SGI, Deutscher Lotto-Block, external planning offices
  • Communication interface with specialist departments

Technologies / Tools: Cisco routing/switching

Summary

For the past 20 years, I have been involved in infrastructure design and implementation of firewall systems and switching/router infrastructures to a standard. Site networking (WAN/SDWAN/BGP/OSPF/VPN) is part of my responsibilities. The manufacturers used here are Fortinet, Cisco Systems, VMware, Microsoft, and Linux systems. The Fortigates are usually managed via a central management system (Fortimanager). The individual sites are connected via SD-WAN and VPN aggregates (BGP). My strengths lie in the data center area. This includes segmentation and implementation of security policies, as well as hybrid clouds with MS Azure/AWS. My perspective on system availability requires my willingness and understanding to work on weekends and evenings. The design and conception of the infrastructure, from initial review to the IPv4 concept, LAN/WAN design, documentation, and handover to the customer, is my area of responsibility. My hourly rate is €100 + VAT (remote) – the all-inclusive daily rate is €1,000 + VAT (onsite).

Languages

German
Advanced
English
Advanced
Need a freelancer? Find your match in seconds.
Try FRATCH GPT
More actions

Similar Freelancers

Discover other experts with similar qualifications and experience

Mustafa Kederoglu
Mustafa Kederoglu

Senior Network Design and Engineer

View Profile
Sami Bejaoui
Sami Bejaoui

Director IT Architecture & Infrastructure Management

View Profile
Frank Joraschkewitz
Frank Joraschkewitz

Lead Project Manager

View Profile
Alagi Mansaray
Alagi Mansaray

Senior Project Manager S4HANA in the energy sector

View Profile
Christian Decker
Christian Decker

Managing Director and Senior Consultant

View Profile
Andreas Antoni
Andreas Antoni

Project Manager for Network and Infrastructure Project Migration EU/US/MEX

View Profile
Valentin Oprea
Valentin Oprea

Network Architect

View Profile
Karoly Balint
Karoly Balint

Fortinet FortiGate 7.4 Administrator

View Profile
Rudolf Eggelbusch
Rudolf Eggelbusch

Datacenter Engineer, Network & Security Administrator

View Profile
Eddy Abanum
Eddy Abanum

Network Administrator

View Profile
Andreas Fischer
Andreas Fischer

Project Manager & Portfolio Owner for Infrastructure (Automotive)

View Profile
Christian Fritsch
Christian Fritsch

Architecture management

View Profile
Khyser Mohd. syed
Khyser Mohd. syed

Life Cycle Infrastructure Network Analyst

View Profile
Jens Rehsack
Jens Rehsack

Technical Product Owner

View Profile
Bernhard Bowitz
Bernhard Bowitz

Senior Security Architect

View Profile
Pierre Gronau
Pierre Gronau

Ansible Automation, Windows Third Level Support

View Profile
David Bleyer
David Bleyer

Acting Partner

View Profile
Stephan Le anh
Stephan Le anh

IT all-rounder

View Profile
Thomas Hartung
Thomas Hartung

Project Manager & Tender Manager

View Profile
Yoav Netzer
Yoav Netzer

Freelance Software Architect

View Profile
Miguel Skirl
Miguel Skirl

Senior System and Cloud Engineer

View Profile
Lothar Hinsche
Lothar Hinsche

Solution Manager for PoC investigation and replacement and refinement of an existing cloud and IoT power plant control system

View Profile
Samir Soliman
Samir Soliman

Project Manager in the Cybersecurity Department

View Profile
Jin-ho Yun
Jin-ho Yun

Server Migration Consultant

View Profile
Christian Wolpert
Christian Wolpert

Cisco Catalyst Center - SDA Wireless Consultant

View Profile
Oliver Frömel
Oliver Frömel

Senior IT Enterprise Security Architect | Project Bank Migration

View Profile
Ulf Haase
Ulf Haase

Configuration Manager (Interim)

View Profile
Mohamed Hawas
Mohamed Hawas

Sr. Network Consultant

View Profile
Mahesh Simha
Mahesh Simha

Azure Solution Architect

View Profile
Majk Kupferberg
Majk Kupferberg

Program Manager Core, Aggregation, Edge Network 4.0

View Profile