NET-120 · Kernel Networking

netfilter & nftables

Packet filtering and NAT as implemented, not as configured by copying rules from the internet.

Practitioner 3 days in person6 half-days online Max 14 in person

Who this course is for

System and network administrators who write firewall and NAT rules and want to understand the machinery well enough to stop copying rules from the internet.

Prerequisites

TCP/IP fundamentals (ports, flags, NAT concepts)Linux command line and shell scriptingNo kernel programming required

Course outline

Day 1 — netfilter hooks and the nftables model

  • The five netfilter hooks and traversal order
  • Tables, chains, priorities and base vs regular chains
  • The ruleset as one object: atomic replacement
  • Packet vs connection: what conntrack adds

Day 2 — writing rules that scale

  • nft syntax: matches, statements and verdicts
  • Sets, maps and vmaps for large policies
  • The iptables compatibility layer and what it hides
  • Conntrack states, helpers and their security implications
  • Scripting ruleset changes safely

Day 3 — NAT and debugging

  • SNAT, DNAT and masquerade as implemented
  • Conntrack interaction: one translation, one entry
  • Port exhaustion and conntrack table limits
  • Debugging with nft monitor trace and rule counters
  • Auditing an inherited ruleset without taking the site down

Hands-on labs

Labs follow the academy model — 35% principles, 20% guided investigation, 45% engineering studio. Every claim you make in a lab is backed by a trace, a counter or a measurement you captured yourself. How we teach

  1. Lab: build a firewall ruleset from scratch with sets and maps, then swap it in atomically
  2. Lab: trace a packet through every hook with nft monitor trace and explain each verdict
  3. Lab: configure masquerade and watch conntrack entries appear, age and exhaust
  4. Lab: debug an intentionally broken ruleset using counters and trace — no guessing allowed

Capstone project

Design and enforce a firewall-plus-NAT policy for a multi-namespace topology simulating a small site: a documented policy, an atomic deploy script, and a test matrix of allowed and denied flows proving the implementation does exactly what the policy says and nothing more.

What you leave with

  • A correct mental model of hook order and conntrack
  • Fluent nftables: sets, maps and atomic updates
  • Debugging skill with nftrace and counters instead of tcpdump folklore
  • A policy-to-ruleset workflow you can apply to your own infrastructure

How it runs

Every course follows the same model: 35% principles, 20% guided investigation, 45% engineering studio. You leave with working code, raw measurements and an evidence-based report — not a certificate of attendance. Read the methodology or see a full sample lesson.

Material is adapted to your kernel version, hardware and workload before a private delivery. For public cohorts, the environment is provided and configured.

Questions

Who is this course for?

System and network administrators who write firewall and NAT rules and want to understand the machinery well enough to stop copying rules from the internet. It sits at practitioner level within the Kernel Networking track.

What do I need to know already?

Specific prerequisites for this course: TCP/IP fundamentals (ports, flags, NAT concepts); Linux command line and shell scripting; No kernel programming required. We confirm levels before the cohort starts and adapt if a group is stronger or weaker than expected.

Can this run privately for my team?

Yes. Any course runs on-site at your offices anywhere, or live online for a distributed team, with labs adapted to your hardware and codebase.

What is the difference between in-person and online?

In person is 3 full days with hardware on your desk, capped at 14. Online is 6 half-day sessions across about two weeks so you can keep working, capped at 20, with remote lab access.

Do you invoice companies?

Yes. Purchase orders are accepted and invoicing is available in USD, EUR, GBP, SAR and CAD.

Upcoming dates

DatesWhereSeatsEarly birdRegular
1 Nov – 3 Nov 20263 full days RiyadhIn person · KAFD Conference Centre 10 of 14 —SAR 7,880
8 Nov – 10 Nov 20263 full days Kuwait CityIn person · Al Hamra Tower 5 of 14 KWD 580until 9 OctKWD 650
15 Nov – 17 Nov 20263 full days MuscatIn person · Knowledge Oasis Muscat 10 of 14 OMR 730until 16 OctOMR 810
15 Nov – 22 Nov 20266 half-days Gulf bandLive online · 09:00–13:00 GMT+3 18 of 20 US$1,350until 16 OctUS$1,500
16 Nov – 18 Nov 20263 full days OttawaIn person · Kanata North Tech Park 5 of 14 CAD 2,570until 17 OctCAD 2,860
23 Nov – 25 Nov 20263 full days TorontoIn person · MaRS Discovery District 10 of 14 CAD 2,570until 24 OctCAD 2,860
23 Nov – 30 Nov 20266 half-days Europe bandLive online · 09:00–13:00 CET 7 of 20 US$1,350until 24 OctUS$1,500
30 Nov – 2 Dec 20263 full days LondonIn person · Shoreditch Works 5 of 14 GBP 1,480until 31 OctGBP 1,640
30 Nov – 7 Dec 20266 half-days Americas bandLive online · 13:00–17:00 ET 12 of 20 US$1,350until 31 OctUS$1,500
7 Dec – 9 Dec 20263 full days BerlinIn person · Factory Görlitzer Park 10 of 14 EUR 1,740until 7 NovEUR 1,930

Dates shown for the next few months. If nothing fits, tell us where and when — cohorts are added on demand, and private delivery can be scheduled any week.

More in Kernel Networking