Live webinars on information security
Karnesav
Karnesav
Network Security Intermediate

Network Security Essentials for IT Professionals

8 weeks, 4 hours per week
Network Security Essentials for IT Professionals

Network security is often treated as a firewall problem. In practice, most breaches involve misconfigurations, unpatched services, or traffic that was never monitored. This course focuses on what actually happens on networks and what you can do about it.

Who this is for

System administrators, help desk staff moving into infrastructure roles, and developers who need to understand the network layer. You should be comfortable with basic TCP/IP concepts — this course builds on that foundation rather than starting from scratch.

Packet-level thinking

You will work through how common protocols behave, where they are vulnerable, and how tools like Wireshark reveal what is happening on a network. The goal is to read traffic, not just configure devices.

Segmentation and perimeter design

The course covers VLAN design, DMZ architecture, and firewall rule logic. You will look at real rule sets and identify problems — overly permissive rules, missing logging, and gaps in egress filtering.

Hands-on labs run in a virtual environment. You do not need physical hardware. Each lab has a specific objective and a debrief explaining what a real attacker would do in the same scenario.

A firewall rule that allows everything outbound on port 443 is not a security control. It is a gap with a label on it.
Labs require a computer capable of running VirtualBox or VMware. Setup instructions are provided at enrollment.
Program
  1. TCP/IP Review and Attack Surface Mapping

    Protocol behavior, common services, and how to identify what is exposed.

  2. Traffic Analysis with Wireshark

    Capturing packets, reading headers, identifying anomalies.

  3. Firewall Architecture and Rule Design

    Stateful inspection, rule ordering, logging, and common misconfigurations.

  4. Network Segmentation

    VLANs, DMZ design, and access control between segments.

  5. Wireless Security

    WPA2/3, rogue access points, and enterprise wireless authentication.

  6. Intrusion Detection Systems

    Signature vs. anomaly detection, Snort basics, and alert triage.

  7. VPNs and Encrypted Tunnels

    IPSec, SSL VPN, and split tunneling risks.

  8. Lab: Network Audit Exercise

    Scan a simulated network, document findings, and write a remediation plan.