
Claude Skills by gesh75
github.com/gesh75Design and triage Clos fabrics with eBGP underlay and EVPN-VXLAN overlay on Juniper, Arista, Cisco, and Nokia. Use when a VTEP is missing, MAC is silent, or a leaf is joining the fabric.
Design and triage campus 802.1X and MAB with ISE or ClearPass. Use when a port will not authorize, a phone+PC daisy-chain fails, or failed-open policy is being reviewed.
Design hybrid cloud interconnects (AWS Direct Connect, Azure ExpressRoute, Google Interconnect) with TGW/VPN backup. Use when attaching a new VPC/VNet or reviewing BGP to a cloud on-ramp.
Preflight a candidate network config for secrets, blast radius, and silent defaults. Use when a human or an LLM produced a snippet and it must be reviewed before a dry-run.
Plan data-center fabric upgrades (ISSU, SMU, or cold) with traffic shift and abort criteria. Use when a spine, leaf, or border-leaf train is moving and you need a sequenced window.
Operate DNS, DHCP, and IPAM as one system. Use when a scope is exhausted, a resolver is poisoned, or a split-horizon zone is drifting from NetBox.
Review firewall security policy on PAN-OS, FortiOS, and ASA for shadow rules, any-any, and missing log-end. Use when a rule is changing or a quarterly hygiene pass is due.
Build idempotent network intent with Nornir and NAPALM, inventory from NetBox. Use when replacing a hop-by-hop CLI change with a rendered, diffed, dry-run pipeline.
Plan and review IPv6 dual-stack on campus, DC, and WAN. Use when numbering a VRF, enabling RA, or deciding NAT64 versus native.
Design and triage Kubernetes networking with Cilium or Calico, NetworkPolicy, and egress control. Use when pods cannot reach a service, a NetworkPolicy is too open, or a node drops overlay traffic.
Design fail-closed MCP tool access to network devices for Claude Code and other agents. Use when adding a NAPALM/Netmiko tool, reviewing allow-lists, or connecting an LLM to a lab or production fabric.
Design and triage MPLS L3VPN on PE-CE edges. Use when adding a VRF, dual-homing a CE, or a prefix is missing in a customer VPN.
Translate a network task across Cisco IOS-XE/XR, Junos, Arista EOS, Nokia SR Linux, and PAN-OS. Use when you know the intent and need vendor-correct show or config syntax.
Treat NetBox as the source of truth for devices, prefixes, VLANs, and cables. Use when planning IP space, racking a leaf, or reconciling a drift between intent and running-config.
Guard network writes behind dry-run, RFC 6241 confirmed-commit, and explicit rollback. Use when applying config to Cisco, Juniper, Arista, or Nokia and a human must own the blast radius.
Run a network manager's weekly and monthly cadence covering CAB, capacity, vendor risk, and staffing. Use when preparing leadership updates, change calendars, or budget narratives.
Gate network alerts on two agreeing signals from independent collectors. Use when a page is noisy, a new check is being added, or an on-call wants to drop a single-counter alarm.
Design SASE and ZTNA access for private apps, SWG, and CASB. Use when replacing VPN, onboarding a connector, or reviewing Prisma / Zscaler / Netskope policy.
Design and review SD-WAN overlays across Cisco Catalyst SD-WAN, Palo Alto Prisma, Fortinet, and Versa. Use when adding a site, changing transport colors, or migrating MPLS to DIA.
Run senior-network-engineer incident response from first page to RCA. Use when a SEV-1/2 hits BGP, WAN, DC fabric, or firewall and you need a timed, fail-closed playbook.
Triage WAN circuit faults from optics to BGP. Use when a DIA, MPLS, or P2P circuit is down, errored, or saturating and you need an ISP-ready package.
Design and triage campus Wi-Fi 6E/7 (MLO, 6 GHz, roaming). Use when an SSID is sticky, a floor has retries, or a controller upgrade is planned.
Extracts text and tables from PDFs, fills forms, and merges documents. Use when the user mentions PDFs, form filling, or document extraction. Do not use for scanned image-only PDFs without OCR.