Gideon Oteng
Network engineer. Platform builder. Things I run don't fall over.
Five years across Tier-1 ISP backbone at Cogent and enterprise managed services at CDW. CCNP Security. Running a two-node Proxmox cluster as production infrastructure — BGP mesh, zero-trust access, full observability, wildcard TLS. The same standards I'd hold at work, operated solo.
// Selected work
Things I've built
securebytes.net
Personal engineering platform built with Astro and deployed globally through Cloudflare Pages - enterprise-grade security, zero infrastructure, $0/month.
SecureBytes Platform
Self-managed Proxmox cluster running production-style network and security infrastructure. Wildcard TLS, public status page, and selective Cloudflare Tunnel exposure.
Network Design Lab
Multi-vendor lab on Cisco Modeling Labs and EVE-NG. Routing, switching, wireless, security, SD-WAN, identity, and observability platforms for design validation, failure testing, and certification work.
// Field notes
Recent writing
Making pfSense the front door to my LAN over Tailscale
I moved remote network access off a DNS box and onto the firewall where it belongs, hit a pfSense package bug that silently failed to apply a setting, and tightened access down to exactly who needs what.
SecureCRT Button Command Suite - Full NOC Automation Pack
200+ commands across 13 sections, platform-tagged for IOS/IOS-XE, IOS-XR, NX-OS, ASA, and FTD/FMC — wired into SecureCRT's button bar to cut the time spent typing the same commands during every troubleshooting call.
Why TLS made my homelab actually usable
Running eight internal services without HTTPS is a friction tax you pay every day. Here's how I fixed it with nginx, acme.sh, and a single wildcard cert — no manual renewals, no browser warnings.
// /now
What I'm working on
Day job
Operations Analyst at CDW — supporting hundreds of enterprise networks across SD-WAN, firewall, and cloud-connected environments.
Just shipped
AWS Private Cloud Lab
Building next
Network automation toolkit — Ansible playbooks for LXC bootstrap, nginx vhosts, Pi-hole DNS sync, and TLS cert distribution.