Decorative animation: a three-tier campus network diagram in which packets travel between core, distribution, and access switches, links occasionally fail, and traffic reroutes along redundant paths.

Worcester, MA  ·  9+ years in production

Michael Kiernan

Senior Network Engineer

I design, migrate, and hold together multi-campus enterprise networks: switching, Wi-Fi, routing, identity, and firewalls. I'm also the escalation point when they break. Currently extending that into AWS and hybrid-cloud networking.

  • Aruba CX / AOS
  • Cisco Catalyst
  • OSPF · BGP
  • Palo Alto · Fortinet
  • 802.1X / RADIUS
0 switches migrated
Cisco → Aruba
0 Palo Alto rules
reorganized
0 reduction in
outage duration
0 campuses
under support

01 Selected work

Migrations that had to happen
without anyone noticing.

Four projects that define how I work. Every one ran on a live network with users on it.

  1. Problem

    An aging multi-campus Cisco estate needed to move to Aruba, but the network serves classrooms, clinics, residence halls, and offices across Worcester, Boston, and Manchester. There was no window big enough to do it at once, and no appetite for a rip-and-replace.

    Approach

    Ran it as a phased migration instead of a cutover, moving more than 170 switches to Aruba while keeping 80+ Cisco Catalyst switches in production alongside them. That meant holding spanning-tree, LACP, and VLAN behaviour consistent across two vendors for the duration, standardising configuration baselines before each wave, and scheduling monthly firmware work under controlled maintenance rather than as emergency changes.

    Outcome

    A stable multi-vendor environment throughout the transition with minimal disruption to users, plus documented lifecycle and firmware plans that made every subsequent wave more routine than the last.

    • Aruba CX
    • Cisco Catalyst
    • Spanning Tree
    • LACP
    • VLAN design
    • Firmware lifecycle
    • Change control
  2. Problem

    The Palo Alto policy base had accreted past a thousand rules over years of one-off additions. Nobody could answer "what does this rule do and who still needs it?" quickly, which made every change slower and riskier than it should have been.

    Approach

    Worked through the full ruleset and reorganized it into a structure that reflects how traffic actually flows: consistent naming, grouped intent, dead rules identified rather than left in place. Carried the same segmentation thinking across the Fortinet platforms and NAC so policy enforcement was coherent between them instead of platform-specific folklore.

    Outcome

    A policy base that can be read and audited by someone who didn't write it. Changes became faster to make and easier to justify, and ongoing operational support stopped depending on tribal knowledge.

    • Palo Alto
    • Fortinet
    • NAC
    • Segmentation
    • Policy audit
    • Rule hygiene
  3. Problem

    Thousands of students, staff, and visiting academics expect to open a laptop and be on the network: on personal devices, on eduroam from other institutions, in high-density lecture spaces. Authentication failures at that scale are invisible until they're everywhere at once.

    Approach

    Led design and troubleshooting for 802.1X and RADIUS-based access: eduroam federation, EAP-PEAP, certificate trust and the PKI planning behind it, and BYOD onboarding that people can complete without a help desk ticket. Currently driving ClearPass migration planning to move the estate onto proper identity-based access control, having completed HPE Aruba's ClearPass Configuration training.

    Outcome

    Reliable authenticated access across classrooms, offices, residence spaces, and high-density environments, with a documented path from the current RADIUS setup to policy-driven, identity-aware enforcement.

    • 802.1X
    • RADIUS
    • eduroam
    • EAP-PEAP
    • PKI / cert trust
    • ClearPass
    • BYOD
  4. Problem

    Two campuses running on aging Brocade switching, joined by a 100 Mb link that had quietly become the ceiling on everything. Wireless onboarding was a recurring source of complaints.

    Approach

    Led design and implementation of the full migration to Aruba across both sites, and replaced the inter-campus link with 10 Gb fiber. Redesigned the Aruba wireless environment, earning the Aruba OS 8 certificate along the way, and built custom captive portal pages so BYOD onboarding stopped being a support burden. Rebuilt the data closets and server rooms to a consistent standard while I was in them.

    Outcome

    Network performance up 20%, user satisfaction with onboarding up 40%, security incidents down 25%, and a physical plant that the next engineer could actually work in.

    • Aruba OS 8
    • Brocade
    • OSPF
    • MPLS
    • 10 Gb fiber
    • Captive portal
    • Structured cabling

02 Capability

What I actually run.

Routing & Switching

  • Aruba CX
  • Aruba AOS
  • Cisco Catalyst
  • OSPF
  • BGP
  • VRRP
  • MPLS
  • ECMP
  • IPv4 routing
  • LAN / WAN

Layer 2 & Resiliency

  • VLANs
  • Spanning Tree
  • LACP
  • Redundant core / dist
  • High availability
  • Segmentation
  • Firmware lifecycle

Wireless

  • Aruba controllers
  • High-density design
  • Coverage & capacity
  • Roaming
  • Aruba Central
  • AirWave
  • Captive portal

Access & Security

  • 802.1X
  • RADIUS
  • EAP-PEAP
  • eduroam
  • ClearPass
  • PKI / cert trust
  • Palo Alto
  • Fortinet
  • NAC
  • BYOD / guest

Cloud & Automation

  • AWS networking
  • Hybrid cloud
  • Azure
  • Active Directory
  • Python
  • PowerShell
  • Node.js
  • TypeScript
  • C#

Operations

  • Root-cause analysis
  • Major incident escalation
  • Packet capture
  • Monitoring
  • Change control
  • Runbooks
  • Network diagrams
  • Vendor coordination

03 Credentials

Certifications & education.

  • CompTIA Network+ Certified
  • Aruba OS 8 Certificate Certified
  • HPE Aruba ClearPass Configuration Training complete · Rev. 25.21
  • AWS Advanced Networking - Specialty ANS-C01 · In progress
  • CISSP In progress
  • B.S. Interactive Media, Programming Concentration Becker College · 2016

Employment

Network Engineer
MCPHS University  ·  Worcester, MA
Jun 2021 to Present
Senior Network Engineer
Ellucian  ·  Worcester, MA
Sep 2016 to May 2021
MK Michael Kiernan

04 Contact

Hiring for a network role?
Let's talk.

Open to senior network engineering and network architecture roles, whether on-site in Central MA, hybrid, or remote.