0%

Explore Courses Defend What Matters

Your Bag

Network Security & Firewalls

04 Networking

Network Security & Firewalls

Design and operate the controls that sit between an attacker and your infrastructure: firewalls, segmentation, VPNs, and detection.

Levels
04
Skill Range
Beginner Expert
Track
Networking
Lifetime Access
Network Security & Firewalls
From 243CREDS

A firewall rule set tells you what an organisation actually believes about its own network. This course teaches you to write a good one. You will work through stateful inspection, next-generation firewall features, and rule design that stays reviewable as it grows past a few hundred entries. Segmentation is covered as a strategy rather than a product, including the zone models and micro-segmentation approaches that contain an intrusion instead of merely detecting it. You will configure site-to-site and remote access VPNs with IPsec and WireGuard, deploy intrusion detection and prevention with Snort or Suricata, and tune rules against real traffic so alerts stay meaningful. Zero trust architecture closes the course.

Curriculum

Learning Path

Each level is enrolled separately. Work through them in order, or start at the level that matches your experience.

  1. Level 01

    Beginner

    243 CREDS

    Purpose

    Write a firewall rule set that stays reviewable as it grows.

    Outcome

    You can write and review a firewall rule set.

    What You'll Learn
    • Configure stateful inspection and understand what state adds.
    • Design rules that remain readable past a few hundred entries.
    • Review an existing rule set and find the dead and dangerous rules.
  2. Level 02

    Intermediate

    486 CREDS

    Purpose

    Segment a network as a strategy that contains an intrusion rather than merely detecting it.

    Outcome

    You can design segmentation that contains an intrusion.

    What You'll Learn
    • Design zone models that separate trust levels.
    • Apply micro-segmentation to limit lateral movement.
    • Show how segmentation turns one compromised host into a contained one.
  3. Level 03

    Advanced

    699 CREDS

    Purpose

    Configure VPNs and detection and tune them against real traffic.

    Outcome

    You can deploy VPNs and intrusion detection that produce useful alerts.

    What You'll Learn
    • Configure site-to-site and remote access VPNs with IPsec and WireGuard.
    • Deploy intrusion detection with Snort or Suricata.
    • Tune rules against real traffic so alerts stay meaningful.
  4. Level 04

    Expert

    1,072 CREDS

    Purpose

    Design toward zero trust, where the network is no longer a trust boundary.

    Outcome

    You can plan a move toward a zero trust architecture.

    What You'll Learn
    • Compare perimeter and zero trust models honestly, including what zero trust does not solve.
    • Design identity-aware access to internal services.
    • Plan a realistic migration path rather than a rip and replace.