Don Yap
Network Engineer at CMB International- Claim this Profile
Click to upgrade to our gold package
for the full feature experience.
-
Cantonese -
-
Mandarin -
-
English -
Topline Score
Bio
Credentials
-
CCIE (Router & Switch)
CiscoMar, 2014- Nov, 2024
Experience
-
CMB International
-
Hong Kong
-
Financial Services
-
200 - 300 Employee
-
Network Engineer
-
Aug 2019 - Present
Redesign and rebuild WAN connection between all Datacenters and Offices Upgrade WAN connection between all Datacenters and Offices from Layer 2 structure to Layer 3 structure to enhance WAN network stability Design load balancing solution on 2 lease line which optimize BW utilization between 2 sites. Design solution to allow auto-failover between 2 lease lines to protect connection between sites Design solution to achieve auto-failover between 2 VPN while the opposite site has no auto-failover mechanism. Design workaround to allow new Vlan user to emergently access remote site via IPSec VPN without modifying VPN interested subnets. Setup connection between On-Premises and Ali Cloud & MBCloud Implement QoS on Cisco routers and Forti Firewall to control/optimize traffic Setup IPSec VPN connection between sites Firewall policy management to control access between On-Premises and 3rd party network Cables laying in DC Show less
-
-
-
-
Network Consultant
-
Apr 2014 - May 2019
Technical Support to DataCenter in HK & US Network Monitor: Webmetric, Whatsup Gold (SNMP, Netflow), SolarWind, RSA, WireShark Support Worldwide Remote Sites (around 50 Sites, 1000 users) Buildup VPN between DC & Cloud (ASA, Azure) Network support in Azure platform Manage vender for Network Project Network Security Enhancement Budget Management ASA Project Involved - Create 20 X IPSec VPNs between on-premises ASA & Remote Sites VPN Gateway (ASA, Solarwind, Cyberoam, Fortigate) - Create SSL VPN (Anyconnect) - Create IPSec VPN between on-premises ASA & Azure cloud - Migrate VPN authentication from local authentication to ACS authentication - Reconfigure ASA ACL to make permitted traffic accurate - Enhance VPN security by utilizing encryption as AES-256 & 30 characters PSK - NAT configuration General Project Involved: - Router & Switch configuration - Datacenter relocation - Setup MPLS connections with new Service Provider - Create Vlan and set Vlan ACL - Configure Links & Server load-balancing - IOS upgrade due to EOL or vulnerability Touched Devices: - ASA5550: IPSec, SSL, ACL, NAT, - ASR1000: NAT, BGP, OSPF, MPLS, Route-map, Prefix-list, HSRP, NTP - Nexus7000: VDC, VPC, Vlan, - Link Loadbalancer (LinkProof), - App Loadbalancer (AppDirector, Netscaler) - Email Gateway (Ironport C380) - ACS - DigiPass Show less
-
-
-
-
System Analyst
-
Aug 2013 - Nov 2013
Evaluate proposed configuration. Liaise with Vender for the network enhancement project. Router/Switch/Firewall configuration Evaluate proposed configuration. Liaise with Vender for the network enhancement project. Router/Switch/Firewall configuration
-
-
-
Citi
-
United States
-
Financial Services
-
700 & Above Employee
-
Network Engineer
-
Oct 2011 - May 2013
Work in ibank for the End of Life Devices Replacement Project. Decommission devices which are end of CISCO support. Preparing new configuration for replacement CISCO devices. Network enhancement Preparing Migration Plan In charge of migration Supervise and cooperate with regional colleagues/vendor to complete migration in time. Network Trouble-shooting. Preparing Circuit Diagram with Visio. Touched CISCO Device: 2911, 3745, 2960, 6509, 1941 Work in ibank for the End of Life Devices Replacement Project. Decommission devices which are end of CISCO support. Preparing new configuration for replacement CISCO devices. Network enhancement Preparing Migration Plan In charge of migration Supervise and cooperate with regional colleagues/vendor to complete migration in time. Network Trouble-shooting. Preparing Circuit Diagram with Visio. Touched CISCO Device: 2911, 3745, 2960, 6509, 1941
-
-
-
China Unicom
-
Telecommunications
-
700 & Above Employee
-
Network Engineer
-
Apr 2008 - Oct 2011
Router/Switch (Cisco) configuration Data Centre Management Network failure trouble-shooting. Data Center Customer Support Touched Devices: Router & Switch (CISCO); DWDM(HUAWEI); SDH (Nortel) Router/Switch (Cisco) configuration Data Centre Management Network failure trouble-shooting. Data Center Customer Support Touched Devices: Router & Switch (CISCO); DWDM(HUAWEI); SDH (Nortel)
-
-
-
-
Network Engineer
-
May 2007 - Apr 2008
Router/Switch (Cisco) configuration. Network failure trouble-shooting. Call Center Customer Support VoIP system development Router/Switch (Cisco) configuration. Network failure trouble-shooting. Call Center Customer Support VoIP system development
-
-
Education
-
The Hong Kong Polytechnic University
Bachelor of Engineering (B.Eng.), Electronic & Information Engineering