NET-201 · Kernel Networking
XDP & eBPF Networking
Processing packets at the driver level for filtering, load balancing and DDoS mitigation at line rate.
Who this course is for
Engineers who need packet filtering, load balancing or DDoS mitigation at line rate and want to do it inside the kernel rather than beside it.
Prerequisites
Course outline
Day 1 — the XDP hook
- The eBPF execution model and the verifier, briefly and precisely
- Where XDP runs: before the skb is allocated
- Actions: PASS, DROP, TX, REDIRECT, ABORTED
- Driver support levels: native, generic, offload
- Loading programs with libbpf and ip link
Day 2 — state, statistics and control
- Map types and when each is correct
- Per-CPU maps for statistics that scale
- Map pinning and sharing between programs and userspace
- Tail calls and structuring larger programs
- Control-plane interaction: reading counters, updating policy
Day 3 — building real XDP programs
- Packet parsing: the bounds checks the verifier demands
- A rate limiter with token-bucket state in a map
- An L4 load balancer with XDP_TX and XDP_REDIRECT
- DDoS mitigation patterns and their limits
- Verifier errors: reading them and fixing what they mean
Day 4 — AF_XDP and tc-bpf
- AF_XDP sockets: UMEM, fill/completion rings, rx/tx rings
- Zero-copy delivery to userspace and its requirements
- tc-bpf hooks on ingress and egress
- Traffic classification with tc-bpf
- Choosing between XDP, AF_XDP, tc-bpf and plain sockets
Hands-on labs
Labs follow the academy model — 35% principles, 20% guided investigation, 45% engineering studio. Every claim you make in a lab is backed by a trace, a counter or a measurement you captured yourself. How we teach
- Lab: write, load and iterate an XDP drop program with libbpf and measure the drop rate at line rate
- Lab: add per-CPU map statistics and export them to a userspace control program
- Lab: build a rate limiter that survives the verifier, then tune it under an iperf3 flood
- Lab: steer packets to userspace with AF_XDP and benchmark against the socket path
- Lab: classify egress traffic with a tc-bpf program and verify placement with tc -s counters
Capstone project
Build a working line-rate service: an XDP program (filter or L4 load balancer) with map-backed policy, per-CPU statistics and a control-plane loader — then benchmark it against the nftables equivalent and deliver the evidence: throughput, CPU cost, drop counts and a short write-up of where each approach wins.
What you leave with
- Working XDP development skills with libbpf and the verifier
- Map and per-CPU statistics patterns you can reuse
- Hands-on AF_XDP and tc-bpf experience
- A measured sense of when in-kernel eBPF beats both nftables and bypass
How it runs
Every course follows the same model: 35% principles, 20% guided investigation, 45% engineering studio. You leave with working code, raw measurements and an evidence-based report — not a certificate of attendance. Read the methodology or see a full sample lesson.
Material is adapted to your kernel version, hardware and workload before a private delivery. For public cohorts, the environment is provided and configured.
Questions
Who is this course for?
Engineers who need packet filtering, load balancing or DDoS mitigation at line rate and want to do it inside the kernel rather than beside it. It sits at advanced level within the Kernel Networking track.
What do I need to know already?
Specific prerequisites for this course: C programming; NET-101-level packet-path knowledge; Basic eBPF awareness is helpful but not required. We confirm levels before the cohort starts and adapt if a group is stronger or weaker than expected.
Can this run privately for my team?
Yes. Any course runs on-site at your offices anywhere, or live online for a distributed team, with labs adapted to your hardware and codebase.
What is the difference between in-person and online?
In person is 4 full days with hardware on your desk, capped at 14. Online is 8 half-day sessions across about two weeks so you can keep working, capped at 20, with remote lab access.
Do you invoice companies?
Yes. Purchase orders are accepted and invoicing is available in USD, EUR, GBP, SAR and CAD.
Upcoming dates
| Dates | Where | Seats | Early bird | Regular | |
|---|---|---|---|---|---|
| 8 Nov – 11 Nov 20264 full days | RiyadhIn person · KAFD Conference Centre | 10 of 14 | SAR 10,800until 9 Oct | ||
| 15 Nov – 18 Nov 20264 full days | Kuwait CityIn person · Al Hamra Tower | 5 of 14 | KWD 890until 16 Oct | ||
| 22 Nov – 25 Nov 20264 full days | MuscatIn person · Knowledge Oasis Muscat | 10 of 14 | OMR 1,110until 23 Oct | ||
| 22 Nov – 1 Dec 20268 half-days | Gulf bandLive online · 09:00–13:00 GMT+3 | 6 of 20 | US$2,070until 23 Oct | ||
| 23 Nov – 26 Nov 20264 full days | OttawaIn person · Kanata North Tech Park | 5 of 14 | CAD 3,920until 24 Oct | ||
| 30 Nov – 3 Dec 20264 full days | TorontoIn person · MaRS Discovery District | 10 of 14 | CAD 3,920until 31 Oct | ||
| 30 Nov – 9 Dec 20268 half-days | Europe bandLive online · 09:00–13:00 CET | 11 of 20 | US$2,070until 31 Oct | ||
| 7 Dec – 10 Dec 20264 full days | LondonIn person · Shoreditch Works | 5 of 14 | GBP 2,250until 7 Nov | ||
| 7 Dec – 16 Dec 20268 half-days | Americas bandLive online · 13:00–17:00 ET | 16 of 20 | US$2,070until 7 Nov | ||
| 14 Dec – 17 Dec 20264 full days | BerlinIn person · Factory Görlitzer Park | 10 of 14 | EUR 2,650until 14 Nov |
Dates shown for the next few months. If nothing fits, tell us where and when — cohorts are added on demand, and private delivery can be scheduled any week.
More in Kernel Networking
NET-1013 days
Network Stack Architecture
The path a packet takes through the kernel, which is the map you need before tuning or debugging anything.
Practitioner-taught
SAR 7,880Next 18 Oct
NET-1103 days
Socket Layer & Protocol Handling
TCP and UDP implementation details that explain the behaviour you see on the wire.
Practitioner-taught
SAR 9,000Next 22 Nov
NET-1203 days
netfilter & nftables
Packet filtering and NAT as implemented, not as configured by copying rules from the internet.
Practitioner-taught
SAR 7,880Next 1 Nov
NET-2103 days
DPDK & Kernel Bypass
When to leave the kernel network stack entirely, and what you give up when you do.
Practitioner-taught
SAR 9,000Next 25 Oct
NET-2203 days
Traffic Control & QoS
Shaping, scheduling and prioritising traffic with tc, including the modern queue disciplines.
Practitioner-taught
SAR 9,000Next 11 Oct