Infrastructure · Beginner
Networking Foundations
Build switches, VLANs, routers, DHCP, DNS, NAT, a firewall and a VPN yourself on one Ubuntu lab machine, then troubleshoot seeded faults and hand over a small business network.
About this course
"The network is down" is the least useful sentence in IT, and the one you will hear most. This course teaches you to turn it into something specific: which layer, which device, which setting, and the evidence that proves it. It does that by having you build every piece of a network yourself instead of memorising diagrams. You work on **net01**, your own Ubuntu Server 24.04 LTS lab machine. Inside it you create Linux network namespaces - complete, separate network stacks that behave like real computers, switches and routers - and wire them together with virtual cables. Over ten lessons you build and capture: - the layered model and encapsulation, seen in a real packet capture, plus a shell survival kit; - IPv4 addressing and subnetting by hand and with `ipcalc`, and IPv6 basics; - an Ethernet switch, MAC learning and ARP; - 802.1Q VLANs, a trunk and a router on a stick, with isolation you prove; - static routing, longest-prefix match, TTL and traceroute; - OSPF dynamic routing with FRR, including a link failure and reconvergence; - DHCP and DNS with dnsmasq, and NAT with nftables and connection tracking; - a stateful default-deny firewall, applied through a change record with a tested rollback; - a troubleshooting method, practised on a branch office with three seeded faults and written up as a ticket; - WAN, VPN, TLS, cloud and wireless vocabulary, and an encrypted WireGuard tunnel between two offices. The final project is an engagement for Brackenfold Tax Advisers, an invented firm: you design and build its staff and guest networks, a second router, DHCP, DNS and NAT, a default-deny firewall and a VPN to its remote office, make the build survive a restart, fix three seeded faults, and deliver a design note and a troubleshooting report. Lab checks read the state of the network you built, not your memory of it. This is a learning pathway toward IT support, systems administration and SOC analyst roles. It awards an Ultiblob Certificate of Completion; it is not a vendor certification and makes no promise about employment.
- Content time
- 12 h 40 min
- Lessons
- 10
- Lab
- Yes
- provisioned for you
- Certificate
- Yes
- on completion
Lesson 1 is free. Enroll in a career path to access its full courses.
Lesson 1 is a free preview — read it without an account.

Outline
Lessons
Lesson 1: Layers, packets and your lab machineFree preview
How a message crosses a network in layers, how to place a reported symptom at the right layer, and a shell survival kit for asking your lab machine about its own network.
1 hLesson 2: Addressing and subnetting
IPv4 addresses, prefixes and masks worked out by hand and checked with ipcalc, the special ranges you must recognise, IPv6 basics, and your first two namespaces joined by a virtual cable.
1 h 15 minLesson 3: Switching, MAC and ARP
What an Ethernet frame carries, how a switch learns where every MAC address lives, how ARP turns an IP address into a MAC address, and how to prove all three with a packet capture on a switch you build yourself.
1 hLesson 4: VLANs and trunks
Split one switch into separate networks with 802.1Q VLANs, carry several VLANs over one trunk to a router on a stick, capture the tags, and prove that a guest cannot reach a staff PC at layer 2.
1 h 15 minLesson 5: Static routing
Build two LANs joined by two routers, fix the path one fault at a time (forwarding, a missing route, a missing return route), and read routing tables, longest-prefix match, TTL and traceroute from real output.
1 h 10 minLesson 6: Dynamic routing with FRR
Run OSPF between two router namespaces with one FRR instance each, read neighbours, costs and learned routes, then fail a link and watch the network reconverge, including the slow case where the link stays up but stops working.
1 h 20 minLesson 7: DHCP, DNS and NAT
Turn a router namespace into an office gateway that hands out addresses with DHCP, answers names with DNS and shares one public address with NAT, then watch each step in captures, logs and the connection-tracking table.
1 h 20 minLesson 8: Firewalls with nftables
Write a stateful default-deny policy for an office router, explain every rule, and apply it the way production changes are applied - through a change record, with a saved rollback, an automatic rollback timer, an atomic load and a verification matrix - then read the dropped packets live.
1 h 30 minLesson 9: Troubleshooting method
A repeatable method - observe, hypothesise, test one thing, fix, verify, record - with the right tool for each layer and the fingerprints of the classic faults, practised on a worked example and then on a branch office with three seeded faults of your own, finished with a ticket-quality report.
1 h 30 minLesson 10: Beyond the LAN
WAN links, VPNs, TLS, cloud networking and wireless explained through what you have already built, then an encrypted WireGuard tunnel between two offices that carries routed traffic, with captures on both sides of the encryption.
1 h 20 min
Hands-on
Your lab
Real virtual machines on the Ultiblob cluster, reached from your browser. You administer them; we provision and destroy them.
- vm-01net01linux
Provisioned for you when you launch the lab from the course. The machines are yours for the access window; release them and launch again whenever you like.
Where it leads