Fachlicher Schwerpunkt dieses Freiberuflers

Unix/Linux and Network Administration, Security, especially wrt. to Internet

Available from
May 1, 2020
Availability
30 %
on customer site
100 %
Areas

D8

D9

Cities
München
50 km
Contact Settings

I prefer getting offers for these sites. However, you may also contact me for interesting projects in other places.

Comment

Deutschland: bevorzugt Raum München und evtl. Nordbayern; Kürzere Einsätze außerhalb der angegebenen Bereiche nach Absprache möglich

Position

Comment

Erfahrung bei Definition und Verhandlung von SLAs und anderen
Betriebsdokumenten, ITIL-Schemata, BSI-Grundschutz

Projects

05/2010 - Today

9 years 10 months

Migration of existing Debian clusters to new hardware, hardening of OS and application (DNS, Apache, squid, postfix, LDAP)

Tasks

Migration of existing Debian clusters to new hardware, hardening of OS and application (DNS, Apache, squid, postfix, LDAP), reconfiguration of DNS servers (split resolver and authoritative, adapt to new Windows domain controllers)
Evaluation of cluster SW (heartbeat/pacemaker), Rolling upgrade of cluster members to new HW Migration from Sun iPlanet directory server to OpenLDAP, evaluation of
alternatives and user interfaces, adapt replication mechanisms and administration tools, test connectivity and function with RADIUS servers (Radiator), run performance tests for parameter fine-tuning Planning of migration steps, writing migration concepts and operational documentation for all services, presentations for operational staff and end customer, documentation according to IT-Grundschutz (BSI)

02/2004 - Today

16 years 1 month

Administration and consulting (focus: advanced Linux issues, firewalls and security)

Customer
large public authority in Munich
Tasks

Development and Setup of a highly available web server setup based on low cost equipment for a small hosting company and other smaller projects (DNS Server migration, temperature control system for data centres with short message alarming, setup of a mail server with database authentication, web mail front end, spam and virus scanning entirely based on open source)

04/2010 - 05/2010

2 months

Consulting and prototype setup for a media company/broadcast station

Tasks

implement high availability on a broadcast media storage system (Omneon MediaGrid), tune performance of cluster members to 10GB/s of total traffic, instruct administrators

04/2009 - 04/2010

1 year 1 month

Planning and automated kickstart setup of several large web setups with Red Hat Enterprise Linux using Red Hat Satellite Server (Apache/Tomcat, Weblogic, Oracle RAC 11g, DNS, Mail)

Tasks

Planning and automated kickstart setup of several large web setups with Red Hat Enterprise Linux using Red Hat Satellite Server (Apache/Tomcat, Weblogic, Oracle RAC 11g, DNS, Mail), Consulting for System Security and Operational Procedures in these setups, Setup of a VPN tunnel infrastructure for a small consulting company

10/2008 - 03/2009

6 months

Planning and administration of routers and firewalls (Juniper Netscreen/SSG), concepts and implementation, Evaluation of Juniper STRM for a large

10/2005 - 10/2008

3 years 1 month

Administration of Servers

Tasks

Administration of Servers, Storage and Backup (Sun, Veritas, NetBackup, HP-UX) for (another) Telco, administration of mail servers, planning and consulting on security and capacity, planning, setup and verification of a centralised, OpenLDAP-based authentication system for all Unix systems, trainings for
admin team (apache, postfix) Setup of several heartbeat clusters, Setup of Nagios monitoring (clustered)

03/2007 - 03/2008

1 year 1 month

Planning and setup of IT infrastructure for a small-sized SW company including servers, switches, UPS; Setup und Operating documentation

10/2007 - 12/2007

3 months

OS Upgrades on Solaris and Linux servers for an intl. Telco

03/2006 - 03/2007

1 year 1 month

Planning, sizing and installation of a medium-sized web server setup (20 servers) with firewalls, load balancers, FC storage and focus on high availability and low administration costs

Tasks

Planning, sizing and installation of a medium-sized web server setup (20 servers) with firewalls, load balancers, FC storage and focus on high availability and low administration costs (Debian Linux OS, Apache web server, tomcat and JBoss application servers, Foundry Server Iron Load Balancer, Juniper Netscreen Firewalls, all in HA cluster configuration). Load simulation, security assessment, availability checks, creation of basic operation documents (according to ITIL processes)

02/2004 - 07/2006

2 years 6 months

Installation, upgrade and administration of Solaris, Linux, FreeBSD machines and clusters during a large internal IT restructuring project

Tasks

Installation, upgrade and administration of Solaris, Linux, FreeBSD machines and clusters during a large internal IT restructuring project for a Telco company, migration of network management applications (HP OpenView, NetCool, InfoVista) to new systems, setup of a customised JumpStart server and development of a automated Linux install server (FAI)

05/2002 - 02/2004

1 year 10 months

Administration of a large client/server setup running Digital Unix/Tru64

Tasks

Administration of a large client/server setup running Digital Unix/Tru64, OS upgrade, upgrade of TruCluster setups, migration of Digital Unix servers to Linux server clusters, adminstration of the core network components (FDDI and Ethernet), mail, web, proxy, dns servers, implementation of a
open source network management and monitoring system with nagios and cricket, development of a security concept for data center and clients together with the customer, training for the operating team by regular seminars, assistant manager of operations, Consulting on web servers, security, and internet server setups in general for the end customer during this time also Setup and securing a DNS resolver, DHCP Server and
Implementation of a internal firewall with traffic shaping abilities
(assigning bandwidth to subnets and services individually)
for an international media company

01/2002 - 04/2002

4 months

Documentation work for a ISP, Managing IP ranges with RIPE and local registries, managing the renumbering project

Tasks

Installation of several Sun/Solaris servers incl. securing OS and
applications for internet use Setup of a Linux/IPsec based VPN between DSL dialins for testing and evaluating a VoIP solution entirely based on open source products

07/2000 - 12/2001

1 year 6 months

Administration of various Unix machines and services for a intl. Telco

Tasks
  • Administration of a large web server setup including Load Balancers, NetApp Filer, Cisco Routers for an international customer. Also responsible for all technical communication, ressource planning and troubleshooting. SW and security consulting for customers of C&W ECRC regarding their server
    setups and networks (supporting the presales teams)
  • Creation and testing of standard configurations for several unix software packages (sendmail, apache, ftp daemons, inn etc., see openpkg.org)
  • Migration of the Usenet architecture to inn, including ressource planning, setup and securing the servers, migrating peers and customers
  • Definition of SLAs for "Web Server Hosting" as a standard product

01/2000 - 06/2000

6 months

Adminstration of world-wide router network using HP NNM, Concord Network

Tasks

Health and self-written tools, performance monitoring and capacity planning, administration of the central firewall and its platform (CheckPoint FW-1 on Solaris), authoring of several documents on security, operating and management of the network, security consulting for the customer (DeTeSystem/German Telekom, now T-Systems)

04/1999 - 12/1999

9 months

Process design, process documentation and operational concept according to ITIL Best Practices for a nationwide network solution

Tasks

This network was based on ATM and FR and operated by DeTeSystem for a customer (Finance).

during this time also

Adminstration of a "Internet Service Area" for a worldwide IP
network (CheckPoint FW-1, mail, proxy, name server, RealSecure IDS) for a German Telekom customer and
Evaluation of a IP accounting and billing SW (X-acct)

Several smaller projects for different german ISPs

03/1996 - 03/1999

3 years 1 month

CTO of a regional ISP Startup

Tasks

planning and setup of all needed equipment (servers, routers),
administrating and securing network infrastructure, selection of upstream, contracts with upstreams and carriers, financial planning and controlling, operation, team building and training
Main customer projects include DSL services and a pan-european VPN based on Ascend (now Lucent) routers

Industries

Internet Service Provider
Telekommunication
Finance
Network (LAN/WAN)
Security (Network/Firewall, OS, Applications)
Professional Audio and Video, Broadcast

Skills

Programming Languages
Fortran
Perl
Shell
Tcl/Tk
TeX, LaTeX

Operating Systems
HPUX
IRIX
Mac OS
MS-DOS
Novell
OSF/Motif
SUN OS, Solaris
Unix
VMS
Windows

Databases
MySQL
Oracle
Postgres

Language Skills
English
German
Greek
Latin
Spanish

Hardware
Alpha
CD-Writer / Burner
Control and Regulation Systems
Digital
Embedded Systems
Framegrabber
Hardware developed
HP
Industrial Robot
Iomega
Macintosh
Measuring Devices
Microcontroller
Atmel AVR
Modem
PC
Plotter
Printer
Real-Time systems
Silicon-Graphics
Streamer
SUN
Sparc and x86
VAX
NetApp Filer
HP Storageworks (MSA, EVA)
EMC Storage
Foundry Load Balancer
F5 BigIp
Netzwerk-HW from Cisco, Nortel, Bay, Digital
Omneon MediaGrid

Data Communication
ATM
Ethernet
Fax
FDDI
HDLC
HDSL
Internet, Intranet
IPNG
ISDN
ISO/OSI
LAN, LAN Manager
NetBeui
Novell
OSF/DCE
Parallel Interfaces
Public Networks
Router
RPC
RS232
SMTP
SNMP
TCP/IP
Token Ring
Voice

Comments

Focus of interest:

Internet and internet services, Security, professional audio and video/broadcast


Training History

1986

School and Abitur in Bayreuth

1994

Study of Physics Physik at University Bayreuth
Diploma in Physics 

Start of a Ph. D. work in science/engineering