Cisco Catalyst SD-WAN Security & Configuration Audit — Certified Engineer Needed
Worldwide
Scope of Work 1. Controller and management plane vManage hardening review: RBAC and user roles, local vs TACACS+/RADIUS/SAML authentication, session and password policy, API/REST access, audit logging and log export, backup posture, cluster configuration vBond/vSmart hardening and reachability exposure Version and patch review against published Cisco security advisories/PSIRT for the running releases Certificate posture: CA method in use (Cisco-hosted, enterprise root CA, manual), certificate lifecycle, expiry risk, root CA distribution, device allow-list/serial file integrity 2. Control plane OMP configuration review: route advertisement, path selection, filtering, graceful restart, TLOC handling DTLS/TLS control connection posture, control policy review at vSmart Site/system ID structure, organization name and controller trust model 3. Data plane and transport IPsec/DTLS data plane settings: rekey timers, anti-replay, integrity/encryption suites, pairwise keys TLOC and color configuration: restrict/public-private exposure, tunnel interface allowed services (SSH, NETCONF, HTTPS, ICMP, SNMP, etc.) — flagging anything unnecessarily exposed on public transports TLOC extension review where used 4. Policy and segmentation Centralized and localized policy review (control, data, app-aware routing, cflowd) VPN/segment isolation validation — confirming that intended segmentation is actually enforced by policy, not just documented Service insertion and traffic hairpinning review 5. Edge/service-side security Zone-Based Firewall policy review on cEdge UTD/security virtual image features in use: Snort IPS/IDS, URL filtering, AMP, TLS/SSL decryption — signature currency, fail-open vs fail-closed behavior, logging DIA (Direct Internet Access) and NAT policy review, split-tunnel exposure Local device hardening: management access, SNMP, NetFlow, syslog, NTP, console/AUX, banner, unused services 6. Configuration consistency and drift Template vs configuration-group usage, device templates vs CLI add-ons, out-of-band/manual changes and drift from the intended baseline Duplicate, orphaned, or unused policies and objects Change management and configuration backup practices
- Less than 30 hrs/weekHourly
- 1-3 monthsDuration
- ExpertExperience Level
- Remote Job
- Ongoing projectProject Type
Skills and Expertise
Activity on this job
- Proposals:5 to 10
- Last viewed by client:yesterday
- Interviewing:3
- Invites sent:0
- Unanswered invites:0
About the client
- United Arab EmiratesDubai10:29 PM
- $199K total spent64 hires, 15 active
- 5,690 hours
- Individual client
Explore similar jobs on Upwork
How it works
Create your free profileHighlight your skills and experience, show your portfolio, and set your ideal pay rate.
Work the way you wantApply for jobs, create easy-to-by projects, or access exclusive opportunities that come to you.
Get paid securelyFrom contract to payment, we help you work safely and get paid securely.
About Upwork
- 4.9/5(Average rating of clients by professionals)
- G2 2021#1 freelance platform
- 49,000+Signed contract every week
- $2.3BFreelancers earned on Upwork in 2020
Find the best freelance jobs
Growing your career is as easy as creating a free profile and finding work like this that fits your skills.
Trusted by