NET-101 · Kernel Networking · Practitioner

Network Stack Architecture — full syllabus

The path a packet takes through the kernel, which is the map you need before tuning or debugging anything.

Duration3 full days in person · 6 half-days online
Cohortmax 14 in person · 20 online
Pricefrom SAR 7,880 in person · local pricing per city
Delivery35% principles · 20% guided investigation · 45% engineering studio

Who this course is for

Systems and network engineers who tune or debug Linux networking and need an accurate model of the packet path before changing a single sysctl.

Prerequisites

Course outline

Day 1 — sk_buff and the receive path

  • sk_buff structure, allocation, cloning and refcounting
  • Driver receive rings, descriptors and DMA
  • NAPI polling: budget, weights and interrupt mitigation
  • From netif_receive_skb up through the protocol handlers
  • GRO aggregation and what it does to the packets you capture

Day 2 — transmit path and the netdevice layer

  • qdiscs, device queues and the dequeue path
  • ndo_start_xmit, completion and freeing skbs
  • net_device features and offloads: GSO, TSO, checksum
  • Why tcpdump lies when offloads are on
  • Reading ethtool -S counters to see what the driver is doing

Day 3 — namespaces and virtual topologies

  • Network namespaces and what they isolate
  • veth pairs, bridges, taps and macvlan
  • How a container packet actually reaches the wire
  • Routing and netfilter traversal across namespace boundaries
  • Building reproducible lab topologies with ip netns

Hands-on labs

  1. Lab: trace one packet from NIC interrupt to socket wakeup with perf/ftrace probes on the receive path
  2. Lab: watch NAPI under load — poll budgets, coalescing and per-queue counters via ethtool and /proc/interrupts
  3. Lab: toggle GRO/GSO/TSO and document how tcpdump output and throughput change
  4. Lab: build a two-namespace veth topology and verify each hop with ping and tcpdump

Capstone project

Produce an end-to-end packet-path map of a supplied VM pair: where a packet is handled, which kernel functions it traverses, which offloads reshape what you observe, and the counters that prove it — written so a colleague can use it as a debugging checklist on a real incident.

What you leave with

Upcoming dates

DatesWhereSeatsEarly birdRegular
18 Oct – 20 Oct 20263 full days RiyadhIn person · KAFD Conference Centre 9 of 14 —SAR 7,880
25 Oct – 27 Oct 20263 full days Kuwait CityIn person · Al Hamra Tower 4 of 14 —KWD 650
1 Nov – 3 Nov 20263 full days MuscatIn person · Knowledge Oasis Muscat 9 of 14 —OMR 810
1 Nov – 8 Nov 20266 half-days Gulf bandLive online · 09:00–13:00 GMT+3 5 of 20 —US$1,500
2 Nov – 4 Nov 20263 full days OttawaIn person · Kanata North Tech Park 4 of 14 —CAD 2,860
9 Nov – 11 Nov 20263 full days TorontoIn person · MaRS Discovery District 9 of 14 CAD 2,570until 10 OctCAD 2,860
9 Nov – 16 Nov 20266 half-days Europe bandLive online · 09:00–13:00 CET 10 of 20 US$1,350until 10 OctUS$1,500
16 Nov – 18 Nov 20263 full days LondonIn person · Shoreditch Works 4 of 14 GBP 1,480until 17 OctGBP 1,640
16 Nov – 23 Nov 20266 half-days Americas bandLive online · 13:00–17:00 ET 15 of 20 US$1,350until 17 OctUS$1,500
23 Nov – 25 Nov 20263 full days BerlinIn person · Factory Görlitzer Park 9 of 14 EUR 1,740until 24 OctEUR 1,930

Book a seat, or bring this course to your team

Seats can be reserved online; private delivery runs on-site or live online, adapted to your stack.

Course page & booking

Questions about fit or prerequisites? Email hello@kernelsystems.academy. To save this syllabus, print this page to PDF from your browser.