NET-120 · Kernel Networking · Practitioner
netfilter & nftables — full syllabus
Packet filtering and NAT as implemented, not as configured by copying rules from the internet.
Who this course is for
System and network administrators who write firewall and NAT rules and want to understand the machinery well enough to stop copying rules from the internet.
Prerequisites
- TCP/IP fundamentals (ports, flags, NAT concepts)
- Linux command line and shell scripting
- No kernel programming required
Course outline
Day 1 — netfilter hooks and the nftables model
- The five netfilter hooks and traversal order
- Tables, chains, priorities and base vs regular chains
- The ruleset as one object: atomic replacement
- Packet vs connection: what conntrack adds
Day 2 — writing rules that scale
- nft syntax: matches, statements and verdicts
- Sets, maps and vmaps for large policies
- The iptables compatibility layer and what it hides
- Conntrack states, helpers and their security implications
- Scripting ruleset changes safely
Day 3 — NAT and debugging
- SNAT, DNAT and masquerade as implemented
- Conntrack interaction: one translation, one entry
- Port exhaustion and conntrack table limits
- Debugging with nft monitor trace and rule counters
- Auditing an inherited ruleset without taking the site down
Hands-on labs
- Lab: build a firewall ruleset from scratch with sets and maps, then swap it in atomically
- Lab: trace a packet through every hook with nft monitor trace and explain each verdict
- Lab: configure masquerade and watch conntrack entries appear, age and exhaust
- Lab: debug an intentionally broken ruleset using counters and trace — no guessing allowed
Capstone project
Design and enforce a firewall-plus-NAT policy for a multi-namespace topology simulating a small site: a documented policy, an atomic deploy script, and a test matrix of allowed and denied flows proving the implementation does exactly what the policy says and nothing more.
What you leave with
- A correct mental model of hook order and conntrack
- Fluent nftables: sets, maps and atomic updates
- Debugging skill with nftrace and counters instead of tcpdump folklore
- A policy-to-ruleset workflow you can apply to your own infrastructure
Upcoming dates
| Dates | Where | Seats | Early bird | Regular | |
|---|---|---|---|---|---|
| 1 Nov – 3 Nov 20263 full days | RiyadhIn person · KAFD Conference Centre | 10 of 14 | — | SAR 7,880 | |
| 8 Nov – 10 Nov 20263 full days | Kuwait CityIn person · Al Hamra Tower | 5 of 14 | KWD 580until 9 Oct | ||
| 15 Nov – 17 Nov 20263 full days | MuscatIn person · Knowledge Oasis Muscat | 10 of 14 | OMR 730until 16 Oct | ||
| 15 Nov – 22 Nov 20266 half-days | Gulf bandLive online · 09:00–13:00 GMT+3 | 18 of 20 | US$1,350until 16 Oct | ||
| 16 Nov – 18 Nov 20263 full days | OttawaIn person · Kanata North Tech Park | 5 of 14 | CAD 2,570until 17 Oct | ||
| 23 Nov – 25 Nov 20263 full days | TorontoIn person · MaRS Discovery District | 10 of 14 | CAD 2,570until 24 Oct | ||
| 23 Nov – 30 Nov 20266 half-days | Europe bandLive online · 09:00–13:00 CET | 7 of 20 | US$1,350until 24 Oct | ||
| 30 Nov – 2 Dec 20263 full days | LondonIn person · Shoreditch Works | 5 of 14 | GBP 1,480until 31 Oct | ||
| 30 Nov – 7 Dec 20266 half-days | Americas bandLive online · 13:00–17:00 ET | 12 of 20 | US$1,350until 31 Oct | ||
| 7 Dec – 9 Dec 20263 full days | BerlinIn person · Factory Görlitzer Park | 10 of 14 | EUR 1,740until 7 Nov |
Book a seat, or bring this course to your team
Seats can be reserved online; private delivery runs on-site or live online, adapted to your stack.
Questions about fit or prerequisites? Email hello@kernelsystems.academy. To save this syllabus, print this page to PDF from your browser.