Decorative animation: a three-tier campus network diagram in which packets travel between core, distribution, and access switches, links occasionally fail, and traffic reroutes along redundant paths.
Worcester, MA · 9+ years in production
Michael Kiernan
Senior Network Engineer
I design, migrate, and hold together multi-campus enterprise networks: switching, Wi-Fi, routing, identity, and firewalls. I'm also the escalation point when they break. Currently extending that into AWS and hybrid-cloud networking.
Cisco → Aruba
reorganized
outage duration
under support
01 Selected work
Migrations that had to happen
without anyone noticing.
Four projects that define how I work. Every one ran on a live network with users on it.
-
Problem
An aging multi-campus Cisco estate needed to move to Aruba, but the network serves classrooms, clinics, residence halls, and offices across Worcester, Boston, and Manchester. There was no window big enough to do it at once, and no appetite for a rip-and-replace.
Approach
Ran it as a phased migration instead of a cutover, moving more than 170 switches to Aruba while keeping 80+ Cisco Catalyst switches in production alongside them. That meant holding spanning-tree, LACP, and VLAN behaviour consistent across two vendors for the duration, standardising configuration baselines before each wave, and scheduling monthly firmware work under controlled maintenance rather than as emergency changes.
Outcome
A stable multi-vendor environment throughout the transition with minimal disruption to users, plus documented lifecycle and firmware plans that made every subsequent wave more routine than the last.
- Aruba CX
- Cisco Catalyst
- Spanning Tree
- LACP
- VLAN design
- Firmware lifecycle
- Change control
-
Problem
The Palo Alto policy base had accreted past a thousand rules over years of one-off additions. Nobody could answer "what does this rule do and who still needs it?" quickly, which made every change slower and riskier than it should have been.
Approach
Worked through the full ruleset and reorganized it into a structure that reflects how traffic actually flows: consistent naming, grouped intent, dead rules identified rather than left in place. Carried the same segmentation thinking across the Fortinet platforms and NAC so policy enforcement was coherent between them instead of platform-specific folklore.
Outcome
A policy base that can be read and audited by someone who didn't write it. Changes became faster to make and easier to justify, and ongoing operational support stopped depending on tribal knowledge.
- Palo Alto
- Fortinet
- NAC
- Segmentation
- Policy audit
- Rule hygiene
-
Problem
Thousands of students, staff, and visiting academics expect to open a laptop and be on the network: on personal devices, on eduroam from other institutions, in high-density lecture spaces. Authentication failures at that scale are invisible until they're everywhere at once.
Approach
Led design and troubleshooting for 802.1X and RADIUS-based access: eduroam federation, EAP-PEAP, certificate trust and the PKI planning behind it, and BYOD onboarding that people can complete without a help desk ticket. Currently driving ClearPass migration planning to move the estate onto proper identity-based access control, having completed HPE Aruba's ClearPass Configuration training.
Outcome
Reliable authenticated access across classrooms, offices, residence spaces, and high-density environments, with a documented path from the current RADIUS setup to policy-driven, identity-aware enforcement.
- 802.1X
- RADIUS
- eduroam
- EAP-PEAP
- PKI / cert trust
- ClearPass
- BYOD
-
Problem
Two campuses running on aging Brocade switching, joined by a 100 Mb link that had quietly become the ceiling on everything. Wireless onboarding was a recurring source of complaints.
Approach
Led design and implementation of the full migration to Aruba across both sites, and replaced the inter-campus link with 10 Gb fiber. Redesigned the Aruba wireless environment, earning the Aruba OS 8 certificate along the way, and built custom captive portal pages so BYOD onboarding stopped being a support burden. Rebuilt the data closets and server rooms to a consistent standard while I was in them.
Outcome
Network performance up 20%, user satisfaction with onboarding up 40%, security incidents down 25%, and a physical plant that the next engineer could actually work in.
- Aruba OS 8
- Brocade
- OSPF
- MPLS
- 10 Gb fiber
- Captive portal
- Structured cabling
02 Capability
What I actually run.
Routing & Switching
- Aruba CX
- Aruba AOS
- Cisco Catalyst
- OSPF
- BGP
- VRRP
- MPLS
- ECMP
- IPv4 routing
- LAN / WAN
Layer 2 & Resiliency
- VLANs
- Spanning Tree
- LACP
- Redundant core / dist
- High availability
- Segmentation
- Firmware lifecycle
Wireless
- Aruba controllers
- High-density design
- Coverage & capacity
- Roaming
- Aruba Central
- AirWave
- Captive portal
Access & Security
- 802.1X
- RADIUS
- EAP-PEAP
- eduroam
- ClearPass
- PKI / cert trust
- Palo Alto
- Fortinet
- NAC
- BYOD / guest
Cloud & Automation
- AWS networking
- Hybrid cloud
- Azure
- Active Directory
- Python
- PowerShell
- Node.js
- TypeScript
- C#
Operations
- Root-cause analysis
- Major incident escalation
- Packet capture
- Monitoring
- Change control
- Runbooks
- Network diagrams
- Vendor coordination
03 Credentials
Certifications & education.
- CompTIA Network+ Certified
- Aruba OS 8 Certificate Certified
- HPE Aruba ClearPass Configuration Training complete · Rev. 25.21
- AWS Advanced Networking - Specialty ANS-C01 · In progress
- CISSP In progress
- B.S. Interactive Media, Programming Concentration Becker College · 2016
Employment
- Network Engineer
- MCPHS University · Worcester, MA
- Jun 2021 to Present
- Senior Network Engineer
- Ellucian · Worcester, MA
- Sep 2016 to May 2021
04 Contact
Hiring for a network role?
Let's talk.
Open to senior network engineering and network architecture roles, whether on-site in Central MA, hybrid, or remote.