I design scalable infrastructures, automate complex networks and craft comprehensive documentation for reliable systems at scale. Open to junior network engineering, NOC and network automation roles.
I'm a junior network engineer building solid fundamentals — routing, switching and security — and pairing them with modern practices from day one: infrastructure as code, automation and clean documentation.
I learn by building: I design realistic enterprise and datacenter labs from scratch (GNS3, FreeRADIUS, pfSense, NetBox, Ansible/AWX, Zabbix) to practise how a real network is deployed, secured and operated end to end. I care about the small things — consistent naming, predictable failure modes, and runbooks a colleague can actually follow. Currently preparing the Cisco CCNA 200-301 (v2.0 blueprint, including automation, programmability and controller-based networking).
A self-built lab reproducing, end to end, how a modern enterprise keeps its network both secure and consistent. 802.1X EAP-TLS authentication (FreeRADIUS + internal PKI) removes shared passwords and blocks credential-based attacks at the switch port; guests are contained behind a pfSense firewall and captive portal, fully isolated from corporate VLANs. Every switch configuration is generated from a single source of truth (NetBox), version-controlled in GitLab and deployed through AWX/Ansible. A compliance job audits 15 security rules per switch (SSH-only management ACLs, SNMPv3, DHCP snooping, dynamic ARP inspection, disabled insecure services…) and remediation playbooks automatically correct any drift — a true desired-state network. Code on GitLab.
A from-scratch GNS3 lab simulating a real company network: a three-tier enterprise estate (per-department subnets with inter-VLAN routing, OSPF internally, OSPF↔BGP at the edge, STP/RSTP, EtherChannel, HSRP) plus a spine-leaf datacenter fabric, protected by a FortiGate 7.6 NGFW at the edge. Services include PacketFence (open-source NAC), Zabbix monitoring, DHCP with relay, internal DNS and NGINX — everything deployed and audited as code through Ansible/AWX and GitLab. Actively evolving (PKI, Active Directory, SIEM, backup and more coming online).
OSPF single-area lab — adjacencies, DR/BDR election and cost-based path selection across three routers; HSRP lab — an active/standby pair sharing a virtual gateway IP with transparent failover. Each built and verified from scratch in GNS3.
EtherChannel lab — parallel inter-switch links bundled into one logical Port-Channel with LACP; VLAN lab — segmentation plus inter-VLAN routing over an 802.1Q trunk (router-on-a-stick). Layer-2 building blocks of any campus network.
Email: johannespambi@gmail.com — GitHub — LinkedIn