Cisco Catalyst SD-WAN Security & Configuration Audit — Certified Engineer Needed

Posted 5 days ago

Worldwide

Summary

Scope of Work 1. Controller and management plane vManage hardening review: RBAC and user roles, local vs TACACS+/RADIUS/SAML authentication, session and password policy, API/REST access, audit logging and log export, backup posture, cluster configuration vBond/vSmart hardening and reachability exposure Version and patch review against published Cisco security advisories/PSIRT for the running releases Certificate posture: CA method in use (Cisco-hosted, enterprise root CA, manual), certificate lifecycle, expiry risk, root CA distribution, device allow-list/serial file integrity 2. Control plane OMP configuration review: route advertisement, path selection, filtering, graceful restart, TLOC handling DTLS/TLS control connection posture, control policy review at vSmart Site/system ID structure, organization name and controller trust model 3. Data plane and transport IPsec/DTLS data plane settings: rekey timers, anti-replay, integrity/encryption suites, pairwise keys TLOC and color configuration: restrict/public-private exposure, tunnel interface allowed services (SSH, NETCONF, HTTPS, ICMP, SNMP, etc.) — flagging anything unnecessarily exposed on public transports TLOC extension review where used 4. Policy and segmentation Centralized and localized policy review (control, data, app-aware routing, cflowd) VPN/segment isolation validation — confirming that intended segmentation is actually enforced by policy, not just documented Service insertion and traffic hairpinning review 5. Edge/service-side security Zone-Based Firewall policy review on cEdge UTD/security virtual image features in use: Snort IPS/IDS, URL filtering, AMP, TLS/SSL decryption — signature currency, fail-open vs fail-closed behavior, logging DIA (Direct Internet Access) and NAT policy review, split-tunnel exposure Local device hardening: management access, SNMP, NetFlow, syslog, NTP, console/AUX, banner, unused services 6. Configuration consistency and drift Template vs configuration-group usage, device templates vs CLI add-ons, out-of-band/manual changes and drift from the intended baseline Duplicate, orphaned, or unused policies and objects Change management and configuration backup practices

  • Less than 30 hrs/week
    Hourly
  • 1-3 months
    Duration
  • Expert
    Experience Level
  • Remote Job
  • Ongoing project
    Project Type
Skills and Expertise
Mandatory skills
Cisco Certified Network Professional
Activity on this job
  • Proposals:5 to 10
  • Last viewed by client:yesterday
  • Interviewing:
    3
  • Invites sent:
    0
  • Unanswered invites:
    0
About the client
Member since Mar 26, 2020
  • United Arab Emirates
    Dubai10:29 PM
  • $199K total spent
    64 hires, 15 active
  • 5,690 hours
  • Individual client

Explore similar jobs on Upwork

Network Security
Zero Trust Architecture
Microsoft Intune
Cybersecurity Management
Vulnerability Assessment
Penetration Testing
Information Security

How it works

  • Post a job icon
    Create your free profile
    Highlight your skills and experience, show your portfolio, and set your ideal pay rate.
  • Talent comes to you icon
    Work the way you want
    Apply for jobs, create easy-to-by projects, or access exclusive opportunities that come to you.
  • Payment simplified icon
    Get paid securely
    From contract to payment, we help you work safely and get paid securely.
Want to get started? Create a profile

About Upwork

  • Rating is 4.9 out of 5.
    4.9/5
    (Average rating of clients by professionals)
  • G2 2021
    #1 freelance platform
  • 49,000+
    Signed contract every week
  • $2.3B
    Freelancers earned on Upwork in 2020

Find the best freelance jobs

Growing your career is as easy as creating a free profile and finding work like this that fits your skills.

Trusted by

  • Microsoft Logo
  • Airbnb Logo
  • Bissell Logo
  • GoDaddy Logo