NET-220 · Kernel Networking
Traffic Control & QoS
Shaping, scheduling and prioritising traffic with tc, including the modern queue disciplines.
Who this course is for
Engineers who must shape, schedule and prioritise traffic on Linux routers or hosts — and need to prove the QoS policy works under overload, not just that it parses.
Prerequisites
Course outline
Day 1 — the tc architecture
- The qdisc model: where queueing actually happens
- Classful vs classless qdiscs
- Ingress and egress hooks; the ifb device
- Filters, classifiers and the handle scheme
- Reading tc -s output without squinting
Day 2 — the queue disciplines
- HTB: classes, rates, ceilings and borrowing
- FQ and FQ-CoDel: flow isolation and AQM
- CAKE: what it automates and what it assumes
- Policing vs shaping; TBF and burst mathematics
- Choosing a discipline for a stated requirement
Day 3 — classification, offload and validation
- u32 and flower classifiers
- Hardware offload of tc and what your NIC can do
- Bufferbloat: measuring latency under load
- Validating a QoS policy with iperf3 and Flent-style tests
- Documenting a policy so the next engineer trusts it
Hands-on labs
Labs follow the academy model — 35% principles, 20% guided investigation, 45% engineering studio. Every claim you make in a lab is backed by a trace, a counter or a measurement you captured yourself. How we teach
- Lab: build an HTB hierarchy with guarantees and ceilings; verify each class with parallel iperf3 flows
- Lab: compare FQ-CoDel and CAKE on a bottleneck link and chart latency under load
- Lab: classify flows with flower filters and prove placement with tc -s counters
- Lab: police vs shape the same flow and document the different drop and delay signatures
- Lab: overload a link, then fix it with an AQM and show the before/after bufferbloat evidence
Capstone project
Design, implement and validate a QoS policy for a shared link with stated per-class guarantees and a latency bound: the written design, the tc implementation, and measurement evidence — per-class throughput under overload and latency-under-load distributions — proving each guarantee holds.
What you leave with
- A working command of tc: HTB, FQ-CoDel, CAKE and flower
- The ability to measure bufferbloat and latency under load honestly
- Classifier skills from u32 to flower with offload awareness
- A validation workflow that turns QoS from folklore into evidence
How it runs
Every course follows the same model: 35% principles, 20% guided investigation, 45% engineering studio. You leave with working code, raw measurements and an evidence-based report — not a certificate of attendance. Read the methodology or see a full sample lesson.
Material is adapted to your kernel version, hardware and workload before a private delivery. For public cohorts, the environment is provided and configured.
Questions
Who is this course for?
Engineers who must shape, schedule and prioritise traffic on Linux routers or hosts — and need to prove the QoS policy works under overload, not just that it parses. It sits at advanced level within the Kernel Networking track.
What do I need to know already?
Specific prerequisites for this course: NET-101-level stack knowledge; Solid TCP/IP (flows, RTT, queueing basics); Linux command line. We confirm levels before the cohort starts and adapt if a group is stronger or weaker than expected.
Can this run privately for my team?
Yes. Any course runs on-site at your offices anywhere, or live online for a distributed team, with labs adapted to your hardware and codebase.
What is the difference between in-person and online?
In person is 3 full days with hardware on your desk, capped at 14. Online is 6 half-day sessions across about two weeks so you can keep working, capped at 20, with remote lab access.
Do you invoice companies?
Yes. Purchase orders are accepted and invoicing is available in USD, EUR, GBP, SAR and CAD.
Upcoming dates
| Dates | Where | Seats | Early bird | Regular | |
|---|---|---|---|---|---|
| 11 Oct – 13 Oct 20263 full days | RiyadhIn person · KAFD Conference Centre | 11 of 14 | — | SAR 9,000 | |
| 11 Oct – 13 Oct 20263 full days | Kuwait CityIn person · Al Hamra Tower | 6 of 14 | — | KWD 740 | |
| 18 Oct – 20 Oct 20263 full days | MuscatIn person · Knowledge Oasis Muscat | 11 of 14 | — | OMR 920 | |
| 25 Oct – 1 Nov 20266 half-days | Gulf bandLive online · 09:00–13:00 GMT+3 | 3 of 20 | — | US$1,750 | |
| 26 Oct – 28 Oct 20263 full days | OttawaIn person · Kanata North Tech Park | 6 of 14 | — | CAD 3,260 | |
| 26 Oct – 28 Oct 20263 full days | TorontoIn person · MaRS Discovery District | 11 of 14 | — | CAD 3,260 | |
| 26 Oct – 2 Nov 20266 half-days | Europe bandLive online · 09:00–13:00 CET | 8 of 20 | — | US$1,750 | |
| 2 Nov – 4 Nov 20263 full days | LondonIn person · Shoreditch Works | 6 of 14 | — | GBP 1,870 | |
| 2 Nov – 9 Nov 20266 half-days | Americas bandLive online · 13:00–17:00 ET | 13 of 20 | — | US$1,750 | |
| 9 Nov – 11 Nov 20263 full days | BerlinIn person · Factory Görlitzer Park | 11 of 14 | EUR 1,990until 10 Oct |
Dates shown for the next few months. If nothing fits, tell us where and when — cohorts are added on demand, and private delivery can be scheduled any week.
More in Kernel Networking
NET-1013 days
Network Stack Architecture
The path a packet takes through the kernel, which is the map you need before tuning or debugging anything.
Practitioner-taught
SAR 7,880Next 18 Oct
NET-1103 days
Socket Layer & Protocol Handling
TCP and UDP implementation details that explain the behaviour you see on the wire.
Practitioner-taught
SAR 9,000Next 22 Nov
NET-1203 days
netfilter & nftables
Packet filtering and NAT as implemented, not as configured by copying rules from the internet.
Practitioner-taught
SAR 7,880Next 1 Nov
NET-2014 days
XDP & eBPF Networking
Processing packets at the driver level for filtering, load balancing and DDoS mitigation at line rate.
Practitioner-taught
SAR 12,000Next 8 Nov
NET-2103 days
DPDK & Kernel Bypass
When to leave the kernel network stack entirely, and what you give up when you do.
Practitioner-taught
SAR 9,000Next 25 Oct