£600 - £651 per day
15 days ago
Network Palo Alto Engineer
INSIDE & REMOTE
My client, a Pharma Organisation, are looking for a Network Engineer with strong Palo Alto Firewall experience. The role is INSIDE or IR35 and Remote apart from the Cabling element of the role.
All expenses will be covered.
Below is some detail on the role.
- Review IT and OT networks/VLANs in customer environment
- Identify in coordination with customer the IT and OT networks to be segmented
- Design and plan the implementation of the Palo Alto PA 450 firewalls in the network
- Create the Low-Level Design (LLD) as needed
- Create the High-Level Design (HLD) as needed
- Onsite Technician will need to have console cable, hotspot & ability to connect to WebEx/Zoom/Teams without going through customer network if possible.
- Ensure sufficient power and rack outlet capacity for HA firewalls
- Review of available rack unit (RU) in existing racks to install new Palo 450 firewalls edge devices.
- Review of infrastructure cabling, patch panel port availability and appropriate cable lengths.
- Rack HA Pair of PA 450 firewalls
- Cable PA 450 firewall interfaces for HA and to the assigned switchports for management, IT and OT networks.
- Verify management interfaces have connectivity to Panorama and internet.
- Verify SSH and HTTPS access to PA 450 firewalls
- Import PA 450 HA firewalls into Panorama
- Configure Panorama network templates and template Stacks with the relevant information from HLD
- Configure 2 security zones, one for IT and OT
- Configure virtual router and relevant routing protocol determined in design session and HLD
- Configure Panorama device groups with the relevant information from HLD
- Configure Security Policy rules with an allow all rule set
- Monitor traffic traversing the IT and OT security zones for two weeks and come up with locked down rule set of protocol, ports and services
- Coordinate with customer to schedule an approved maintenance window to implement new locked down security policy rule set and remove allow all rule
- Conduct full connectivity testing
- Perform knowledge transfer to customer network engineering team
Oscar Technology is acting as an Employment Business in relation to this vacancy.