NET-101 · Kernel Networking
Network Stack Architecture
The path a packet takes through the kernel, which is the map you need before tuning or debugging anything.
Who this course is for
Systems and network engineers who tune or debug Linux networking and need an accurate model of the packet path before changing a single sysctl.
Prerequisites
Course outline
Day 1 — sk_buff and the receive path
- sk_buff structure, allocation, cloning and refcounting
- Driver receive rings, descriptors and DMA
- NAPI polling: budget, weights and interrupt mitigation
- From netif_receive_skb up through the protocol handlers
- GRO aggregation and what it does to the packets you capture
Day 2 — transmit path and the netdevice layer
- qdiscs, device queues and the dequeue path
- ndo_start_xmit, completion and freeing skbs
- net_device features and offloads: GSO, TSO, checksum
- Why tcpdump lies when offloads are on
- Reading ethtool -S counters to see what the driver is doing
Day 3 — namespaces and virtual topologies
- Network namespaces and what they isolate
- veth pairs, bridges, taps and macvlan
- How a container packet actually reaches the wire
- Routing and netfilter traversal across namespace boundaries
- Building reproducible lab topologies with ip netns
Hands-on labs
Labs follow the academy model — 35% principles, 20% guided investigation, 45% engineering studio. Every claim you make in a lab is backed by a trace, a counter or a measurement you captured yourself. How we teach
- Lab: trace one packet from NIC interrupt to socket wakeup with perf/ftrace probes on the receive path
- Lab: watch NAPI under load — poll budgets, coalescing and per-queue counters via ethtool and /proc/interrupts
- Lab: toggle GRO/GSO/TSO and document how tcpdump output and throughput change
- Lab: build a two-namespace veth topology and verify each hop with ping and tcpdump
Capstone project
Produce an end-to-end packet-path map of a supplied VM pair: where a packet is handled, which kernel functions it traverses, which offloads reshape what you observe, and the counters that prove it — written so a colleague can use it as a debugging checklist on a real incident.
What you leave with
- A packet-path map you can redraw for any Linux host
- Working fluency with ethtool, ip, ss, tcpdump and network tracepoints
- The ability to read driver and NAPI counters instead of guessing
- Enough sk_buff literacy to follow net/ source when behaviour surprises you
How it runs
Every course follows the same model: 35% principles, 20% guided investigation, 45% engineering studio. You leave with working code, raw measurements and an evidence-based report — not a certificate of attendance. Read the methodology or see a full sample lesson.
Material is adapted to your kernel version, hardware and workload before a private delivery. For public cohorts, the environment is provided and configured.
Questions
Who is this course for?
Systems and network engineers who tune or debug Linux networking and need an accurate model of the packet path before changing a single sysctl. It sits at practitioner level within the Kernel Networking track.
What do I need to know already?
Specific prerequisites for this course: Working TCP/IP knowledge (headers, sockets, ports); Linux command line and basic scripting; Ability to read C with guidance for the source-level segments. We confirm levels before the cohort starts and adapt if a group is stronger or weaker than expected.
Can this run privately for my team?
Yes. Any course runs on-site at your offices anywhere, or live online for a distributed team, with labs adapted to your hardware and codebase.
What is the difference between in-person and online?
In person is 3 full days with hardware on your desk, capped at 14. Online is 6 half-day sessions across about two weeks so you can keep working, capped at 20, with remote lab access.
Do you invoice companies?
Yes. Purchase orders are accepted and invoicing is available in USD, EUR, GBP, SAR and CAD.
Upcoming dates
| Dates | Where | Seats | Early bird | Regular | |
|---|---|---|---|---|---|
| 18 Oct – 20 Oct 20263 full days | RiyadhIn person · KAFD Conference Centre | 9 of 14 | — | SAR 7,880 | |
| 25 Oct – 27 Oct 20263 full days | Kuwait CityIn person · Al Hamra Tower | 4 of 14 | — | KWD 650 | |
| 1 Nov – 3 Nov 20263 full days | MuscatIn person · Knowledge Oasis Muscat | 9 of 14 | — | OMR 810 | |
| 1 Nov – 8 Nov 20266 half-days | Gulf bandLive online · 09:00–13:00 GMT+3 | 5 of 20 | — | US$1,500 | |
| 2 Nov – 4 Nov 20263 full days | OttawaIn person · Kanata North Tech Park | 4 of 14 | — | CAD 2,860 | |
| 9 Nov – 11 Nov 20263 full days | TorontoIn person · MaRS Discovery District | 9 of 14 | CAD 2,570until 10 Oct | ||
| 9 Nov – 16 Nov 20266 half-days | Europe bandLive online · 09:00–13:00 CET | 10 of 20 | US$1,350until 10 Oct | ||
| 16 Nov – 18 Nov 20263 full days | LondonIn person · Shoreditch Works | 4 of 14 | GBP 1,480until 17 Oct | ||
| 16 Nov – 23 Nov 20266 half-days | Americas bandLive online · 13:00–17:00 ET | 15 of 20 | US$1,350until 17 Oct | ||
| 23 Nov – 25 Nov 20263 full days | BerlinIn person · Factory Görlitzer Park | 9 of 14 | EUR 1,740until 24 Oct |
Dates shown for the next few months. If nothing fits, tell us where and when — cohorts are added on demand, and private delivery can be scheduled any week.
More in Kernel Networking
NET-1103 days
Socket Layer & Protocol Handling
TCP and UDP implementation details that explain the behaviour you see on the wire.
Practitioner-taught
SAR 9,000Next 22 Nov
NET-1203 days
netfilter & nftables
Packet filtering and NAT as implemented, not as configured by copying rules from the internet.
Practitioner-taught
SAR 7,880Next 1 Nov
NET-2014 days
XDP & eBPF Networking
Processing packets at the driver level for filtering, load balancing and DDoS mitigation at line rate.
Practitioner-taught
SAR 12,000Next 8 Nov
NET-2103 days
DPDK & Kernel Bypass
When to leave the kernel network stack entirely, and what you give up when you do.
Practitioner-taught
SAR 9,000Next 25 Oct
NET-2203 days
Traffic Control & QoS
Shaping, scheduling and prioritising traffic with tc, including the modern queue disciplines.
Practitioner-taught
SAR 9,000Next 11 Oct