NET-120 · Kernel Networking
netfilter & nftables
Packet filtering and NAT as implemented, not as configured by copying rules from the internet.
Who this course is for
System and network administrators who write firewall and NAT rules and want to understand the machinery well enough to stop copying rules from the internet.
Prerequisites
Course outline
Day 1 — netfilter hooks and the nftables model
- The five netfilter hooks and traversal order
- Tables, chains, priorities and base vs regular chains
- The ruleset as one object: atomic replacement
- Packet vs connection: what conntrack adds
Day 2 — writing rules that scale
- nft syntax: matches, statements and verdicts
- Sets, maps and vmaps for large policies
- The iptables compatibility layer and what it hides
- Conntrack states, helpers and their security implications
- Scripting ruleset changes safely
Day 3 — NAT and debugging
- SNAT, DNAT and masquerade as implemented
- Conntrack interaction: one translation, one entry
- Port exhaustion and conntrack table limits
- Debugging with nft monitor trace and rule counters
- Auditing an inherited ruleset without taking the site down
Hands-on labs
Labs follow the academy model — 35% principles, 20% guided investigation, 45% engineering studio. Every claim you make in a lab is backed by a trace, a counter or a measurement you captured yourself. How we teach
- Lab: build a firewall ruleset from scratch with sets and maps, then swap it in atomically
- Lab: trace a packet through every hook with nft monitor trace and explain each verdict
- Lab: configure masquerade and watch conntrack entries appear, age and exhaust
- Lab: debug an intentionally broken ruleset using counters and trace — no guessing allowed
Capstone project
Design and enforce a firewall-plus-NAT policy for a multi-namespace topology simulating a small site: a documented policy, an atomic deploy script, and a test matrix of allowed and denied flows proving the implementation does exactly what the policy says and nothing more.
What you leave with
- A correct mental model of hook order and conntrack
- Fluent nftables: sets, maps and atomic updates
- Debugging skill with nftrace and counters instead of tcpdump folklore
- A policy-to-ruleset workflow you can apply to your own infrastructure
How it runs
Every course follows the same model: 35% principles, 20% guided investigation, 45% engineering studio. You leave with working code, raw measurements and an evidence-based report — not a certificate of attendance. Read the methodology or see a full sample lesson.
Material is adapted to your kernel version, hardware and workload before a private delivery. For public cohorts, the environment is provided and configured.
Questions
Who is this course for?
System and network administrators who write firewall and NAT rules and want to understand the machinery well enough to stop copying rules from the internet. It sits at practitioner level within the Kernel Networking track.
What do I need to know already?
Specific prerequisites for this course: TCP/IP fundamentals (ports, flags, NAT concepts); Linux command line and shell scripting; No kernel programming required. We confirm levels before the cohort starts and adapt if a group is stronger or weaker than expected.
Can this run privately for my team?
Yes. Any course runs on-site at your offices anywhere, or live online for a distributed team, with labs adapted to your hardware and codebase.
What is the difference between in-person and online?
In person is 3 full days with hardware on your desk, capped at 14. Online is 6 half-day sessions across about two weeks so you can keep working, capped at 20, with remote lab access.
Do you invoice companies?
Yes. Purchase orders are accepted and invoicing is available in USD, EUR, GBP, SAR and CAD.
Upcoming dates
| Dates | Where | Seats | Early bird | Regular | |
|---|---|---|---|---|---|
| 1 Nov – 3 Nov 20263 full days | RiyadhIn person · KAFD Conference Centre | 10 of 14 | — | SAR 7,880 | |
| 8 Nov – 10 Nov 20263 full days | Kuwait CityIn person · Al Hamra Tower | 5 of 14 | KWD 580until 9 Oct | ||
| 15 Nov – 17 Nov 20263 full days | MuscatIn person · Knowledge Oasis Muscat | 10 of 14 | OMR 730until 16 Oct | ||
| 15 Nov – 22 Nov 20266 half-days | Gulf bandLive online · 09:00–13:00 GMT+3 | 18 of 20 | US$1,350until 16 Oct | ||
| 16 Nov – 18 Nov 20263 full days | OttawaIn person · Kanata North Tech Park | 5 of 14 | CAD 2,570until 17 Oct | ||
| 23 Nov – 25 Nov 20263 full days | TorontoIn person · MaRS Discovery District | 10 of 14 | CAD 2,570until 24 Oct | ||
| 23 Nov – 30 Nov 20266 half-days | Europe bandLive online · 09:00–13:00 CET | 7 of 20 | US$1,350until 24 Oct | ||
| 30 Nov – 2 Dec 20263 full days | LondonIn person · Shoreditch Works | 5 of 14 | GBP 1,480until 31 Oct | ||
| 30 Nov – 7 Dec 20266 half-days | Americas bandLive online · 13:00–17:00 ET | 12 of 20 | US$1,350until 31 Oct | ||
| 7 Dec – 9 Dec 20263 full days | BerlinIn person · Factory Görlitzer Park | 10 of 14 | EUR 1,740until 7 Nov |
Dates shown for the next few months. If nothing fits, tell us where and when — cohorts are added on demand, and private delivery can be scheduled any week.
More in Kernel Networking
NET-1013 days
Network Stack Architecture
The path a packet takes through the kernel, which is the map you need before tuning or debugging anything.
Practitioner-taught
SAR 7,880Next 18 Oct
NET-1103 days
Socket Layer & Protocol Handling
TCP and UDP implementation details that explain the behaviour you see on the wire.
Practitioner-taught
SAR 9,000Next 22 Nov
NET-2014 days
XDP & eBPF Networking
Processing packets at the driver level for filtering, load balancing and DDoS mitigation at line rate.
Practitioner-taught
SAR 12,000Next 8 Nov
NET-2103 days
DPDK & Kernel Bypass
When to leave the kernel network stack entirely, and what you give up when you do.
Practitioner-taught
SAR 9,000Next 25 Oct
NET-2203 days
Traffic Control & QoS
Shaping, scheduling and prioritising traffic with tc, including the modern queue disciplines.
Practitioner-taught
SAR 9,000Next 11 Oct