Open to conversations

luis@cvmendes — whoami

Luis Mendes

network engineer | network security

I design secure, resilient infrastructure for global environments — strong security controls, operational visibility, and pragmatic engineering.

// 01 — impact

Impact, in numbers

28
global sites
12
countries
56
firewalls managed centrally
15+
years hands-on in IT — technician to network engineer
24/7
critical infrastructure

// 02 — about

About

I'm a Network Engineer at a global life-sciences company, designing and deploying secure campus and data-center networks across sites worldwide.

My day-to-day is segmenting laboratory and OT systems, rolling out next-generation firewall policies, and keeping critical manufacturing networks resilient. I'm hands-on — change windows, configs, troubleshooting — while thinking at the architecture level about scalability, resiliency and security.

I came up through IT operations, so I know the systems the network carries: Active Directory, Group Policy, Entra ID and Microsoft 365 / Exchange Online. A full-stack software background shows up in my automation, tooling and documentation.

company
global life-sciences company
scope
campus · DC · lab · OT
approach
hands-on + architecture
also
AD · Entra ID · M365
location
Boston, MA

// 03 — skills

Skills

network-engineering

  • LAN/WLAN design
  • Routing & switching L2/L3
  • SD-WAN & site-to-site VPN
  • QoS
  • HA clustering
  • Data-center switching
  • MDF/IDF design

security-&-segmentation

  • Firewall admin & hardening
  • VLAN design & ACLs
  • OT/lab segmentation
  • Zero Trust
  • IPS/WAF tuning
  • Incident response support

platforms

  • FortiGate
  • FortiManager
  • FortiAnalyzer
  • FortiSwitch
  • Security Fabric
  • AWS & Azure VPN
  • Cisco switching & wireless
  • Armis
  • SNMP monitoring

identity-&-microsoft-365

  • Active Directory
  • Group Policy
  • Windows Server DNS/DHCP
  • Entra ID
  • Entra Connect (hybrid sync)
  • Conditional Access & MFA
  • Exchange Online
  • Mailbox migration
  • Microsoft 365 admin
  • Teams & SharePoint

automation

  • Git
  • Scripting
  • Network automation
  • Linux
  • Docker
  • Python
  • JavaScript
  • Docs, diagrams & SOPs

// 04 — case-studies

Case studies

Real problems from production — the approach and the outcome.

campus lan · fortiswitch · mclag

Campus LAN Redesign — FortiSwitch MCLAG

problem
Two campus sites ran on ageing access switches, with building uplinks passing through MDF access switches and STP leaving backup links idle — a single switch or fiber failure could take buildings offline.
approach
Designed FortiLink-managed topologies sized to each site: a 3-tier core / distribution / access design for the larger campus and a collapsed MCLAG core for the smaller one. Every tier is an MCLAG pair with dual-homed LACP uplinks, and existing access hardware is reused.
result
Active/active uplinks (2×10G per building instead of one blocked link), no spanning-tree reconvergence on failover, and any single core, distribution or IDF switch can fail without an access outage.
fortigate-aactivefortigate-bstandbyha2×25gcore-1core-2icl4×10gdist-1dist-2iclidf-1pairidf-2pairidf-3pairidf-4pairidf-5pairidf-6pair3-tier · every tier is an mclag pair
large campus — 3-tier, 25G firewall uplinks, 6 IDFs
fortigate ha pairactive-passive20g lag20g lagcore-1core-2iclmdfaccess ringringidf-1mclag pairringidf-2mclag pairringidf-3mclag pairringidf-4mclag pairring10g dual-homed uplinks · solid → core-1 · dashed → core-2collapsed core · icl 2×100g · no single point of failure
mid-size campus — collapsed core, IDFs home straight to core

sd-wan · fortigate · global

Global SD-WAN & Firewall Modernization

problem
Inconsistent configurations and single points of failure across global sites.
approach
Standardized FortiGate configs, dual-ISP SD-WAN with SLA-based steering, site-to-site VPN and failover paths.
result
One consistent config baseline across 28 sites, automatic failover between ISPs, and single points of failure eliminated.
isp-a isp-b fgt-a fgt-b ha hq sd-wan

segmentation · vdoms · ot/lab · zero trust

Lab & OT Network Segmentation

problem
Flat networks mixing office, lab, OT and guest traffic — plant-floor controllers were one hop from user laptops and the internet.
approach
Split the site FortiGate into Enterprise and OT VDOMs, each with its own routing, policy and admins. OT follows a Purdue-style zone model behind an IT/OT DMZ, and the only path between the two is an inter-VDOM link with explicit allow rules. VLAN standards, ACLs and re-mapped switch ports, with critical devices documented alongside lab stakeholders.
result
Office, lab, OT and guest fully separated. OT has no direct internet path, IT-to-OT access goes through the DMZ jump host, and every flow between VDOMs is inspected and logged — least-privilege access for critical manufacturing and lab systems, and cleaner security reviews.
internetdual isp · sd-wanfortigate ha pair · multi-vdoment-vdomsd-wan · utmoffice · guest · labot-vdomips · ot signaturesno internet routevdom-linkexplicit allow · all loggedofficecorp usersguestinternet onlylabinstrumentsenterprise zones · vlan per zone · 802.1xot · purdue modell3.5 · it/ot dmzjump host · patchingl3 · site operationshistorian · mesl2 · supervisoryscada · hmil1 · controlplc · rtul0 · processsensors · drivesfortianalyzerlogs · all vdomsot reached only via dmz jump hostsolid: routed vlan interface · dashed amber: inter-vdom link · dashed cyan: logging
one fortigate, two security domains — enterprise and ot never share a routing table

fortimanager · fortianalyzer · visibility

FortiManager & FortiAnalyzer Rollout

problem
Firewalls managed one by one, with fragmented logs and no single source of truth.
approach
Centralized policy management with global logging and reporting across the fleet.
result
Better change control, policy consistency and faster incident investigation across 56 firewalls.
fortimanager fortianalyzer site-01 site-02 site-n central policy + global logs

aws · azure · ipsec · hybrid

Hybrid Cloud Connectivity

problem
Workloads moving into AWS and Azure needed secure, reliable reachability to on-prem systems without bypassing existing security controls.
approach
Built IPsec connectivity from the on-prem FortiGates to cloud VPN gateways — route-based tunnels where dynamic routing and failover mattered, policy-based where the peer required it — and brought cloud subnets under the same firewall policy.
result
Cloud networks treated like any other site: one policy model, one place for logging, and documented runbooks for operations.
on-prem fortigate ha aws vpc vpn gateway azure vnet vpn gateway ipsec · route-based ipsec · policy-based same policy + logging

// 05 — homelab

Homelab — where I test ideas

Self-hosted infrastructure on an Unraid server running Docker services — my sandbox for breaking and fixing things before they ever touch production.

Remote access is zero-trust end to end: Cloudflare Zero Trust (Tunnel + Access with MFA) for anything public — no open ports — and a Tailscale mesh VPN for admin devices. A Caddy reverse proxy handles automatic TLS, and Prometheus + Grafana keep everything observable. Lately it's also home to self-hosted AI agents and automation experiments.

  • Unraid
  • Docker
  • Tailscale
  • Cloudflare Zero Trust
  • Caddy
  • Prometheus
  • Grafana
  • AI agents

architecture

internetcloudflare accesssso · mfaadmin deviceslaptop · phoneunraid host · docker · 30+ containerscloudflaredoutbound tunneltunneltailscalewireguard meshno open portscaddyauto tls · dns-01ai agentsclaude code · paperclipmediajellyfin · gpu nvencobservabilityprometheus · grafanadashboardshomarr · requestsexportersnode · smart · fortigatescraped by prometheusgluetun vpn namespacedownload clients share its network · kill switch
two ways in, zero open ports — everything routes through one reverse proxy

$ docker ps — what's running

edge & access

Nothing is port-forwarded. Public apps sit behind Cloudflare Access; everything else is tailnet-only.

  • cloudflared
  • caddy (custom build)
  • tailscale
  • gluetun

observability

Host, container, disk and firewall metrics in one Prometheus, with Grafana dashboards and alert rules.

  • prometheus
  • grafana
  • node-exporter
  • cadvisor
  • smartctl-exporter
  • fortigate-exporter
  • exportarr ×5

media & home

GPU-accelerated streaming with automated library management and a request portal.

  • jellyfin
  • jellyseerr
  • sonarr
  • radarr
  • prowlarr
  • audiobookshelf
  • homarr

ai & automation

Always-on AI agents with their own scoped credentials — including the builder of this site.

  • claude-code (custom image)
  • paperclip
  • deepsite
  • hermes agent (vps)

implementation highlights

Firewall telemetry at home

A Prometheus exporter polls the FortiGate REST API — interface throughput, sessions, VPN and HA state — into the same Grafana dashboards as the server.

VPN-isolated egress

Download containers join Gluetun's network namespace instead of the bridge, so if the VPN drops they have no route out: a kill switch enforced by the network, not an app setting.

GPU transcoding

An RTX 3070 is handed to Jellyfin through the NVIDIA container runtime for full hardware decode, NVENC encode and HDR tone-mapping.

Least-privilege agents

AI agents get dedicated SSH keys pinned with from= source restrictions and never touch personal keys — revoking one is a one-line change.

Split public / private

Two tiers: Cloudflare Tunnel + Access (MFA) for the few public apps, and a Caddy + Tailscale tier with DNS-01 certificates for private admin UIs.

Custom images & runbooks

Hand-built images for the reverse proxy and agent containers, documented as reusable runbooks so any rebuild is repeatable.

// 06 — experience

Experience

  1. Jul 2023 — Present

    Network Engineer · Global Life-Sciences Company

    global infrastructure · network security

    • Designed and deployed enterprise-wide VLAN segmentation standards, shrinking broadcast domains and improving security posture across global sites.
    • Built OT segmentation for labs, manufacturing instruments and controlled environments using the Fortinet Security Fabric.
    • Delivered FortiGate upgrades, HA clustering, SD-WAN failover design and IPS/WAF tuning, plus automation scripts for proactive monitoring.
    • Brought new global sites online over SD-WAN with dual-ISP high availability; integrated AWS and Azure networks via route- and policy-based VPNs.
    • Deployed FortiSwitch stacks, migrated core switching and redesigned MDF/IDF topologies for reliability and compliance.
    • Authored the documentation, diagrams and SOPs for global routing, switching and firewall operations.
  2. Oct 2021 — Jul 2023

    IT Specialist · Global Life-Sciences Company

    infrastructure · identity · microsoft 365

    • Administered Active Directory — users, groups, OUs and Group Policy — alongside Windows Server DNS and DHCP.
    • Managed hybrid identity with Entra ID and Entra Connect, including Conditional Access and MFA rollout.
    • Ran Microsoft 365 and Exchange Online: mailboxes and migrations, licensing, Teams and SharePoint administration.
    • Supported network changes, hardware upgrades and high-impact troubleshooting — the path into network engineering.
  3. 2010 — 2023

    Earlier path

    before and alongside

    • IT Specialist at an analytics laboratory (2020 – 2023).
    • Full-stack software engineering program, Lambda School (2019 – 2020).
    • Founded and ran a small trucking business, growing it to two trucks (2014 – 2019).
    • Computer technician — hardware troubleshooting and support (2010 – 2014).

// 07 — certifications

Certifications

  • Cisco Certified Network Associate

    cisco · routing, switching & network fundamentals

  • Fortinet NSE 6

    fortinet · network security specialist

  • Fortinet NSE 4

    fortinet · network security professional

  • Fortinet NSE 3

    fortinet · network security associate

  • Fortinet NSE 2

    fortinet · network security associate

  • Fortinet NSE 1

    fortinet · network security associate

  • currently studying

    CISSP

    isc2 · certified information systems security professional · target: 2027

also: google it support fundamentals · ongoing: cybersecurity frameworks · cloud networking · secure architecture

// 08 — contact

Let's connect

Network engineering, security initiatives, or future opportunities — my inbox is open.