Network Security Essentials for IT Professionals

Network security is often treated as a firewall problem. In practice, most breaches involve misconfigurations, unpatched services, or traffic that was never monitored. This course focuses on what actually happens on networks and what you can do about it.
Who this is for
System administrators, help desk staff moving into infrastructure roles, and developers who need to understand the network layer. You should be comfortable with basic TCP/IP concepts — this course builds on that foundation rather than starting from scratch.
Packet-level thinking
You will work through how common protocols behave, where they are vulnerable, and how tools like Wireshark reveal what is happening on a network. The goal is to read traffic, not just configure devices.
Segmentation and perimeter design
The course covers VLAN design, DMZ architecture, and firewall rule logic. You will look at real rule sets and identify problems — overly permissive rules, missing logging, and gaps in egress filtering.
Hands-on labs run in a virtual environment. You do not need physical hardware. Each lab has a specific objective and a debrief explaining what a real attacker would do in the same scenario.
A firewall rule that allows everything outbound on port 443 is not a security control. It is a gap with a label on it.Labs require a computer capable of running VirtualBox or VMware. Setup instructions are provided at enrollment.
-
TCP/IP Review and Attack Surface Mapping
Protocol behavior, common services, and how to identify what is exposed.
-
Traffic Analysis with Wireshark
Capturing packets, reading headers, identifying anomalies.
-
Firewall Architecture and Rule Design
Stateful inspection, rule ordering, logging, and common misconfigurations.
-
Network Segmentation
VLANs, DMZ design, and access control between segments.
-
Wireless Security
WPA2/3, rogue access points, and enterprise wireless authentication.
-
Intrusion Detection Systems
Signature vs. anomaly detection, Snort basics, and alert triage.
-
VPNs and Encrypted Tunnels
IPSec, SSL VPN, and split tunneling risks.
-
Lab: Network Audit Exercise
Scan a simulated network, document findings, and write a remediation plan.
