Skip to content
View otengg's full-sized avatar

Block or report otengg

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
otengg/README.md

Gideon Oteng

Network engineer building toward security engineering.
Homelab run like production: BGP mesh, zero-trust access, observability, automation with preflight gates.

Portfolio Lab Status Field Notes Location

Cisco Palo Alto Fortinet AWS Azure Cloudflare Proxmox Tailscale Splunk Python Ansible Linux


Recently shipped

Project What it proves
Netgate DNS Cutover Toolkit Preflight gate caught a real outage before any write; fixed a Tailscale routing trap and an API client bug; ran DHCP cutover live
Tailscale on pfSense Subnet router and DNS authority moved to the firewall; accept-routes trap documented and fixed
AWS Private Cloud Lab VPC, VPN, CloudTrail, and detection engineering on real AWS telemetry
Cisco FTD + FMC Lab Access policy, IPS, URL filtering, NAT, and event analysis on virtual FTD

Building now

Network automation toolkit — Ansible roles for LXC bootstrap, nginx vhosts, and Netgate Unbound DNS sync (read → merge → apply via pfSense REST API).

AWS detection engineering — Sigma rules for IAM privilege escalation, validated against CloudGoat with Stratus Red Team and CloudTrail.

SecureBytes platform — two-node Proxmox cluster, wildcard TLS, Cloudflare Tunnel exposure, dual-repo sanitization workflow. Public reference: securebytes-platform.


Homelab stack

Layer What's running
Edge Netgate 2100 · pfSense Plus · FRRouting eBGP · Snort · pfBlockerNG
Access Tailscale WireGuard overlay · deny-by-default ACLs · pfSense subnet router
DNS Unbound on pfSense · DHCP hands out firewall only · host overrides via REST API
Compute Proxmox VE 9 · two Lenovo nodes · LXC/VM services behind nginx
Exposure Cloudflare Tunnel + Access · Let's Encrypt wildcard via DNS-01
Observability Grafana · Prometheus · Uptime Kuma · Security Onion · ntfy

Full inventory: securebytes.net/stack


Expertise

Domain Strongest in
Networking BGP · OSPF · MPLS · LAN/WAN · VLANs · TCP/IP · DNS · DHCP · segmentation
Security Cisco ASA/FTD · Palo Alto · Fortinet · pfSense · Zero Trust · IDS/IPS · SIEM · IR
Cloud AWS · Azure · Cloudflare (Tunnel, Access, DNS-01) · VPC · private endpoints
Platforms Proxmox · Linux · Windows Server · VMware · Cisco CML · EVE-NG
Automation Python · Bash · Ansible · API-driven network ops · detection-as-code (Sigma)
Ops Splunk · Grafana · Prometheus · Wireshark · ServiceNow · postmortems · RCA

CCNP Security · AZ-104 · five years across Cogent backbone and CDW enterprise managed services.


Links

Portfolio securebytes.net
Writing Field notes
Status status.securebytes.net/status/lab
Platform repo github.com/otengg/securebytes-platform
FTD lab repo github.com/otengg/cisco-ftd-fmc-lab

Open to senior network and security engineering roles · DC metro · remote-friendly
Email · LinkedIn · securebytes.net

Popular repositories Loading

  1. securebytes-platform securebytes-platform Public

  2. otengg otengg Public

  3. cisco-ftd-fmc-lab cisco-ftd-fmc-lab Public

    Cisco FTD + FMC enterprise security lab — access control policy, IPS, URL filtering, NAT, and event analysis