NET-210 · Kernel Networking
DPDK & Kernel Bypass
When to leave the kernel network stack entirely, and what you give up when you do.
Who this course is for
Engineers evaluating or operating kernel-bypass data planes who need an honest account of what DPDK buys, what it costs, and when XDP or the tuned kernel stack is the better answer.
Prerequisites
Course outline
Day 1 — the bypass architecture
- What the kernel path costs: context switches, copies, per-packet work
- Poll-mode drivers and the run-to-completion model
- UIO and VFIO: taking a NIC away from the kernel
- Hugepages, memory pools and mbufs
- lcore assignment and NUMA placement rules
Day 2 — programming the data plane
- EAL initialisation and device probing
- rx/tx rings, descriptors and burst processing
- A minimal forwarder, line by line
- Multi-queue, RSS and scaling across lcores
- What happens to tcpdump, ethtool and ss when the kernel no longer sees the NIC
Day 3 — evaluation and operations
- Benchmarking honestly: DPDK vs XDP vs the tuned kernel stack
- NUMA and hugepage misconfiguration penalties
- Operational cost: debugging, monitoring, upgrades, onboarding
- Failure modes: what a poll-mode loop hides until it melts
- Decision framework: bypass, XDP, or fix the kernel path
Hands-on labs
Labs follow the academy model — 35% principles, 20% guided investigation, 45% engineering studio. Every claim you make in a lab is backed by a trace, a counter or a measurement you captured yourself. How we teach
- Lab: bind a NIC to VFIO, allocate hugepages and reach line rate with testpmd
- Lab: write a minimal DPDK forwarder and measure throughput and latency against the kernel path
- Lab: move the same workload across NUMA nodes and quantify the placement penalty
- Lab: run one filtering task on the kernel stack, XDP and DPDK; chart throughput, CPU and debuggability
Capstone project
Run a controlled bake-off and write the recommendation: one packet-processing workload implemented on the tuned kernel path, XDP and DPDK, with a shared measurement harness — then deliver a decision memo covering throughput, tail latency, CPU cost and operational burden, defended in a review session.
What you leave with
- Hands-on DPDK setup: VFIO, hugepages, testpmd and a minimal forwarder
- A measurement methodology that compares data planes fairly
- Quantified knowledge of NUMA and placement effects
- A defensible decision framework for bypass vs XDP vs the kernel stack
How it runs
Every course follows the same model: 35% principles, 20% guided investigation, 45% engineering studio. You leave with working code, raw measurements and an evidence-based report — not a certificate of attendance. Read the methodology or see a full sample lesson.
Material is adapted to your kernel version, hardware and workload before a private delivery. For public cohorts, the environment is provided and configured.
Questions
Who is this course for?
Engineers evaluating or operating kernel-bypass data planes who need an honest account of what DPDK buys, what it costs, and when XDP or the tuned kernel stack is the better answer. It sits at advanced level within the Kernel Networking track.
What do I need to know already?
Specific prerequisites for this course: NET-101 or strong kernel-networking knowledge; C programming; NUMA and hugepage basics. We confirm levels before the cohort starts and adapt if a group is stronger or weaker than expected.
Can this run privately for my team?
Yes. Any course runs on-site at your offices anywhere, or live online for a distributed team, with labs adapted to your hardware and codebase.
What is the difference between in-person and online?
In person is 3 full days with hardware on your desk, capped at 14. Online is 6 half-day sessions across about two weeks so you can keep working, capped at 20, with remote lab access.
Do you invoice companies?
Yes. Purchase orders are accepted and invoicing is available in USD, EUR, GBP, SAR and CAD.
Upcoming dates
| Dates | Where | Seats | Early bird | Regular | |
|---|---|---|---|---|---|
| 25 Oct – 27 Oct 20263 full days | RiyadhIn person · KAFD Conference Centre | 10 of 14 | — | SAR 9,000 | |
| 1 Nov – 3 Nov 20263 full days | Kuwait CityIn person · Al Hamra Tower | 5 of 14 | — | KWD 740 | |
| 1 Nov – 3 Nov 20263 full days | MuscatIn person · Knowledge Oasis Muscat | 10 of 14 | — | OMR 920 | |
| 8 Nov – 15 Nov 20266 half-days | Gulf bandLive online · 09:00–13:00 GMT+3 | 4 of 20 | US$1,580until 9 Oct | ||
| 9 Nov – 11 Nov 20263 full days | OttawaIn person · Kanata North Tech Park | 5 of 14 | CAD 2,930until 10 Oct | ||
| 16 Nov – 18 Nov 20263 full days | TorontoIn person · MaRS Discovery District | 10 of 14 | CAD 2,930until 17 Oct | ||
| 16 Nov – 18 Nov 20263 full days | LondonIn person · Shoreditch Works | 5 of 14 | GBP 1,680until 17 Oct | ||
| 16 Nov – 23 Nov 20266 half-days | Europe bandLive online · 09:00–13:00 CET | 9 of 20 | US$1,580until 17 Oct | ||
| 16 Nov – 23 Nov 20266 half-days | Americas bandLive online · 13:00–17:00 ET | 14 of 20 | US$1,580until 17 Oct | ||
| 23 Nov – 25 Nov 20263 full days | BerlinIn person · Factory Görlitzer Park | 10 of 14 | EUR 1,990until 24 Oct |
Dates shown for the next few months. If nothing fits, tell us where and when — cohorts are added on demand, and private delivery can be scheduled any week.
More in Kernel Networking
NET-1013 days
Network Stack Architecture
The path a packet takes through the kernel, which is the map you need before tuning or debugging anything.
Practitioner-taught
SAR 7,880Next 18 Oct
NET-1103 days
Socket Layer & Protocol Handling
TCP and UDP implementation details that explain the behaviour you see on the wire.
Practitioner-taught
SAR 9,000Next 22 Nov
NET-1203 days
netfilter & nftables
Packet filtering and NAT as implemented, not as configured by copying rules from the internet.
Practitioner-taught
SAR 7,880Next 1 Nov
NET-2014 days
XDP & eBPF Networking
Processing packets at the driver level for filtering, load balancing and DDoS mitigation at line rate.
Practitioner-taught
SAR 12,000Next 8 Nov
NET-2203 days
Traffic Control & QoS
Shaping, scheduling and prioritising traffic with tc, including the modern queue disciplines.
Practitioner-taught
SAR 9,000Next 11 Oct