NET-120 · Kernel Networking · Practitioner

netfilter & nftables — full syllabus

Packet filtering and NAT as implemented, not as configured by copying rules from the internet.

Duration3 full days in person · 6 half-days online
Cohortmax 14 in person · 20 online
Pricefrom SAR 7,880 in person · local pricing per city
Delivery35% principles · 20% guided investigation · 45% engineering studio

Who this course is for

System and network administrators who write firewall and NAT rules and want to understand the machinery well enough to stop copying rules from the internet.

Prerequisites

Course outline

Day 1 — netfilter hooks and the nftables model

  • The five netfilter hooks and traversal order
  • Tables, chains, priorities and base vs regular chains
  • The ruleset as one object: atomic replacement
  • Packet vs connection: what conntrack adds

Day 2 — writing rules that scale

  • nft syntax: matches, statements and verdicts
  • Sets, maps and vmaps for large policies
  • The iptables compatibility layer and what it hides
  • Conntrack states, helpers and their security implications
  • Scripting ruleset changes safely

Day 3 — NAT and debugging

  • SNAT, DNAT and masquerade as implemented
  • Conntrack interaction: one translation, one entry
  • Port exhaustion and conntrack table limits
  • Debugging with nft monitor trace and rule counters
  • Auditing an inherited ruleset without taking the site down

Hands-on labs

  1. Lab: build a firewall ruleset from scratch with sets and maps, then swap it in atomically
  2. Lab: trace a packet through every hook with nft monitor trace and explain each verdict
  3. Lab: configure masquerade and watch conntrack entries appear, age and exhaust
  4. Lab: debug an intentionally broken ruleset using counters and trace — no guessing allowed

Capstone project

Design and enforce a firewall-plus-NAT policy for a multi-namespace topology simulating a small site: a documented policy, an atomic deploy script, and a test matrix of allowed and denied flows proving the implementation does exactly what the policy says and nothing more.

What you leave with

Upcoming dates

DatesWhereSeatsEarly birdRegular
1 Nov – 3 Nov 20263 full days RiyadhIn person · KAFD Conference Centre 10 of 14 —SAR 7,880
8 Nov – 10 Nov 20263 full days Kuwait CityIn person · Al Hamra Tower 5 of 14 KWD 580until 9 OctKWD 650
15 Nov – 17 Nov 20263 full days MuscatIn person · Knowledge Oasis Muscat 10 of 14 OMR 730until 16 OctOMR 810
15 Nov – 22 Nov 20266 half-days Gulf bandLive online · 09:00–13:00 GMT+3 18 of 20 US$1,350until 16 OctUS$1,500
16 Nov – 18 Nov 20263 full days OttawaIn person · Kanata North Tech Park 5 of 14 CAD 2,570until 17 OctCAD 2,860
23 Nov – 25 Nov 20263 full days TorontoIn person · MaRS Discovery District 10 of 14 CAD 2,570until 24 OctCAD 2,860
23 Nov – 30 Nov 20266 half-days Europe bandLive online · 09:00–13:00 CET 7 of 20 US$1,350until 24 OctUS$1,500
30 Nov – 2 Dec 20263 full days LondonIn person · Shoreditch Works 5 of 14 GBP 1,480until 31 OctGBP 1,640
30 Nov – 7 Dec 20266 half-days Americas bandLive online · 13:00–17:00 ET 12 of 20 US$1,350until 31 OctUS$1,500
7 Dec – 9 Dec 20263 full days BerlinIn person · Factory Görlitzer Park 10 of 14 EUR 1,740until 7 NovEUR 1,930

Book a seat, or bring this course to your team

Seats can be reserved online; private delivery runs on-site or live online, adapted to your stack.

Course page & booking

Questions about fit or prerequisites? Email hello@kernelsystems.academy. To save this syllabus, print this page to PDF from your browser.