New: Roadmaps ordered paths through our cheat sheets and flashcards, so you always know what to study next.
Explore themSee what's new on GitHubFrom subnetting a network by hand to designing one that keeps running.
A 15-step learning path. Follow it in order, or jump to what you need.
For IT support staff, sysadmins, or complete beginners who want to own the wires, routers, and Wi-Fi that keep an organization connected, this path builds a working network engineer's toolkit from the ground up. Plan on about 8 weeks at a few hours a week, moving from IP addressing and subnetting through DNS, DHCP, routing, and switching to wireless, monitoring, and network design. This path stays on infrastructure: deep incident response, SIEM, and threat-hunting work belong to the Cybersecurity Analyst path, not here. By the end you can subnet a network by hand, troubleshoot a routing or DNS failure end to end, and design a topology that keeps running when a link or router fails.
No prior experience needed. Start from zero.
Hands you a working map of OSI layers, protocols, and devices you can use today, the same map the routing, wireless, and design steps ahead all assume you already have.
Puts real numbers on the OSI layers from step one, and this is where subnet math finally clicks instead of feeling like memorized formulas; expect to keep coming back to CIDR and VLSM as networks grow.
You can read an IP address, place it on the OSI layers, and slice a network into subnets without panicking. Next up: turning that into real, running services.
Finish this section to unlock.
+100 XP
Turns the raw IP addresses from step two into the names people actually type, and every service you configure from here on leans on it resolving correctly.
Automates the address assignment you just did by hand in step two, so a DORA handshake, not a spreadsheet, keeps a growing network's IPs straight.
Splits one physical switch into isolated broadcast domains, the segmentation habit that step nine's firewall zones and step fifteen's design patterns both build on.
Explains how the private addresses you carved out in step two actually reach the internet through a single public IP, and why the VPNs in step nine sometimes fight it.
Moves you from the static routing step one sketched into a live conversation between routers, where OSPF and BGP path selection trip up most learners on the first pass, so plan on circling back.
You can resolve a name to an address, hand that address out automatically, wall off traffic with a VLAN, and read a routing table well enough to argue with it. Next up: getting that network onto radio waves and behind a firewall.
Finish this section to unlock.
+100 XP
Extends everything you configured on the wire, VLANs, DHCP, security, onto radio, where signal, channel, and roaming problems replace cable problems.
Puts the NAT boundary from step six behind a rule set you control, plus the encrypted tunnels a distributed team needs to reach the network at all.
Gives you eyes on everything steps three through nine built, so a failing link or a saturated VLAN shows up as an alert instead of an angry phone call.
Hands you the systematic ping-to-application diagnostic path that turns the DNS, routing, and NAT concepts from earlier steps into an actual fix during an outage.
You can secure a wireless and wired network at once and pull the right diagnostic for a failure, and a few minutes of due flashcards keeps the routing and VLAN work from section two fresh while you build on it. Next up: making the network faster, more automated, and cloud-ready.
Finish this section to unlock.
+100 XP
Take this if you're heading toward application delivery or data-center roles: it distributes traffic across the servers your routing and NAT already deliver packets to.
Reach for this if a NetDevOps or automation-heavy role is the goal: it scripts the VLAN, routing, and DHCP work from earlier steps across hundreds of devices instead of one at a time.
Grab this if your networks live partly in the cloud: it carries the addressing from step two and the segmentation from step five onto Azure's virtual network constructs.
Pulls routing, switching, wireless, and redundancy from every step before into one skill: designing a topology, three-tier, spine-leaf, or otherwise, that keeps running when a link or router fails.
You can troubleshoot an outage end to end, defend the perimeter with a firewall and VPN, and design a topology that keeps running when a link or router dies. This badge marks you ready to own real network infrastructure, campus, wireless, or hybrid cloud, and keep growing from here.
Finish this section to unlock.
+100 XP
Finish every required step, at least 70% of them genuinely done (not skipped), to earn this badge and 500 XP.