- Lectures: 51
- Students: 1
Enterprise Network Implementation & Live Troubleshooting
Build an Enterprise Lab, Understand the Concepts and Solve Real Troubleshooting Tickets
Course overview:
Enterprise Network Implementation & Live Troubleshooting is a practical, lab-driven course designed to help you understand how enterprise networks are built, how the underlying technologies work, and how to systematically troubleshoot real production issues.
The course is divided into three phases:
Phase 1 – Building the Enterprise Lab
Building a complete enterprise network from scratch, including enterprise routing, switching, internal and perimeter security, VPN connectivity, servers, and supporting infrastructure. This lab serves as the foundation for the entire course.
Phase 2 – Core Foundations (Conceptual Refresh)
A quick, practical refresh of the networking and security concepts that are essential for troubleshooting. The focus is on understanding the “why” behind each technology rather than just the configuration.
Phase 3 – Production Outage Scenarios & Live Ticket-Based Troubleshooting
Apply everything you’ve learned by investigating and resolving realistic production-style incidents on the same enterprise lab built in Phase 1. Each troubleshooting ticket is demonstrated live using a structured investigation and root cause analysis approach.
PHASE 1 : Building the Enterprise Lab
We start by building a real enterprise topology together.
- Core Network
- Multiple VLANs (Users / PROD / UAT / DMZ / Management)
- Inter-VLAN routing (SVIs)
- Network segmentation design
- Basic Layer-2 protections (loops, VLAN boundaries)
- Internal Firewall (East–West Security)
- Deploy internal firewall
- Control traffic between:
- Users ↔ PROD servers
- Users ↔ UAT servers
- UAT ↔ PROD servers
- Security policies
- Internal segmentation concepts
- Why internal firewalls are critical in enterprises
3.External Firewall (North–South Security)
- Basic firewall configuration
- Internet access for users & servers
- NAT policies
- Security policies
- DMZ design
- DMZ + WAF
- Deploy DMZ web servers
- Configure WAF
- Publish applications securely
- Understand reverse proxy flow
- VPN & Hybrid Connectivity
- IPsec Site-to-Site VPN (HQ ↔ Branch)
- Remote Access VPN
- Understand VPN routing, selectors and encryption domains
By the end of this phase, we will have a fully working enterprise network:
- Users → Internal Firewall → PROD/UAT
- DMZ behind WAF
- External Firewall → Internet
- Branch connected via VPN
- Cloud connected via VPN
PHASE 2: Core Foundations (Quick Refresh, Practical based)
Focused on concepts that directly help troubleshooting.
- TCP/IP & Practical OSI
- Where enterprise networks actually break
- Control plane vs data plane
- Packet life cycle across switches, routers and firewalls
2.IP Header Deep Dive
- TTL (loop detection, routing issues)
- DF bit (PMTUD failures)
- Fragmentation
- DSCP / QoS markings
- IP options (rare but important)
- TCP Header & Behavior
- TCP flags
- Connection setup & teardown
- Sequence / ACK numbers
- Windowing & window scaling
- SACK
- Retransmissions
- Duplicate ACKs
- Spurious retransmissions
- MSS / MTU / Blackhole
- MSS vs MTU
- Path MTU Discovery
- MTU blackhole scenarios
- Fragmentation impact on applications
- Layer 2 & Segmentation (Only What Breaks Networks)
- VLAN design from security perspective
- SVIs and routing boundaries
- Private VLAN concepts
- Broadcast storms
- Switching loops
- MAC flapping
- Real outage caused by unmanaged switches
- Routing & Packet Path Analysis
- Default routes
- Forward vs return path
- Asymmetric routing
- Policy routing concepts
7.Firewall & VPN Troubleshooting
- Firewall packet flow (NAT vs security policy)
- Session tables
- App-based policies
- NAT order of operation
- SSL inspection impact
- VPN Deep Dive
- Phase 1 / Phase 2
- Proxy IDs / traffic selectors
- MSS on VPN
- Tunnel flapping
- DPD failures
8.Application Slowness & WAN Issues
- Latency vs bandwidth
- TCP delays
- Server response vs network delay
- WAN packet loss
- Jitter
- False DDoS scenarios
- Using Linux WAN impairment + Wireshark + monitoring.
- SSL / TLS & Certificates
- TLS handshake
- Certificate chains
- Cipher negotiation
- SSL inspection failures
- Monitoring + Root Cause Correlation
- Using enterprise monitoring tools:
- Interface utilization
- Link flaps
- Bandwidth spikes
- Flow visibility
- Correlating monitoring with packet captures
PHASE 3 : Production Outage Scenarios & Real Enterprise Tickets
Ticket 1 # Users Can Reach Internal Resources but Cannot Access Internet
Ticket 2 # Users Unable to Access Application Through Firewall
Ticket 3 # Branch Users Unable to Access HQ Resources Over VPN
Ticket 4 # Branch to HQ Communication Failure Despite Active VPN Tunnel
Ticket 5 # Production Server at HQ Site Inaccessible from Branch Office
Ticket 6 # VPN Peer Reachable but Tunnel Never Establishes
Ticket 7 # Remote VPN Users Lose Internet Connectivity After Connecting to Corporate Network
Ticket 8 # Remote VPN Users Can Access some corporate Resources but not others
Ticket 9 # Remote VPN Connected but Corporate Web Apps can not be accessed
Ticket 10 # Internet Browsing is Extremely Slow for HQ user
Ticket 11 # Website Loads Partially and then freezes
Ticket 12 # Split Tunnel Enabled, Yet Internet Stops Working
Ticket 13 # Some websites are working normally while others are not opening at all
Ticket 14 # Social Media Applications are Blocked, Yet Some Users Can Still Access Them
Ticket 15 # Users in VLAN 20 Cannot Access the Internet, While Other Departments Are Working Normally
-
1. Course Introduction (Free Preview)
-
2. Secure network design
-
Lecture 2.1Secure network design
-
-
3. Understanding Network Building
-
Lecture 3.1Understanding Network Building
-
-
4. Building LAB inside eve-ng
-
Lecture 4.1Building LAB inside eve-ng
-
-
5. Core switching and VLAN Foundation
-
Lecture 5.1Core switching and VLAN Foundation
-
-
6. Monitoring and Visibility Layer
-
Lecture 6.1Monitoring and Visibility Layer
-
-
7. Installing LibreNMS
-
Lecture 7.1Installing LibreNMS
-
-
8. Installing NTOPNG
-
Lecture 8.1Installing NTOPNG
-
-
9. Adding switch into LibreNMS and configuing SPAN
-
Lecture 9.1Adding switch into LibreNMS and configuing SPAN
-
-
10. Understanding Routing and Configuring Internet Router
-
Lecture 10.1Understanding Routing and Configuring Internet Router
-
-
11. Understanding and configuring Palo Alto firewall
-
Lecture 11.1Understanding and configuring Palo Alto firewall
-
-
12. Verification and Troubleshooting
-
Lecture 12.1Verification and Troubleshooting
-
-
13. Configuring Internal Firewall (FortiGate)
-
Lecture 13.1Configuring Internal Firewall (FortiGate)
-
-
14. Verification and Troubleshooting
-
Lecture 14.1Verification and Troubleshooting
-
-
15. Understanding Load Balancer (ADC)
-
Lecture 15.1Understanding Load Balancer (ADC)
-
-
16. Building the Application Delivery Path
-
Lecture 16.1Building the Application Delivery Path
-
-
17. Verification and Troubleshooting
-
Lecture 17.1Verification and Troubleshooting
-
-
18. WAF (FortiWEB) Protection Policy
-
Lecture 18.1WAF (FortiWEB) Protection Policy
-
-
19. Adding Devices into LibreNMS
-
Lecture 19.1Adding Devices into LibreNMS
-
-
20. Branch Firewall Configuration
-
Lecture 20.1Branch Firewall Configuration
-
-
21. VPN Concepts
-
Lecture 21.1VPN Concepts
-
-
22. Understanding IPsec S2S and Remote Access VPN
-
Lecture 22.1Understanding IPsec S2S and Remote Access VPN
-
-
23. IPSec site to site VPN Configuration
-
Lecture 23.1IPSec site to site VPN Configuration
-
-
24. Remote Access VPN configuration
-
Lecture 24.1Remote Access VPN configuration
-
-
25. End of PHASE 1 (Building Enterprise Network)
-
Lecture 25.1End of Phase 1 (Building Enterprise Network)
-
-
26. Introduction to Wireshark
-
Lecture 26.1Introduction to Wireshark
-
-
27. OSI and Pcaket Life Cycles
-
Lecture 27.1OSI and Pcaket Life Cycles
-
-
28. IP Header Deep Dive
-
Lecture 28.1IP Header Deep Dive
-
-
29. TCP Header and Behavior
-
Lecture 29.1TCP Header and Behavior
-
-
30. Switching and Layer 2 Segmentation
-
Lecture 30.1Switching and Layer 2 Segmentation
-
-
31. Routing and Packet Path Analysis
-
Lecture 31.1Routing and Packet Path Analysis
-
-
32. Firewalls Packet Flow
-
Lecture 32.1Firewalls Packet Flow
-
-
34. Application Slowness And WAN Issues
-
Lecture 34.1Application Slowness And WAN Issues
-
-
35. Understanding Digital certificate and TLS Handshake
-
Lecture 35.1Understanding Digital certificate and TLS Handshake
-
-
36. Monitoring and Root cause Correlation
-
Lecture 36.1Monitoring and Root cause Correlation
-
-
TICKET 1 # Users Can Reach Internal Resources but Cannot Access Internet
-
Lecture 37.1Users Can Reach Internal Resources but Cannot Access Internet
-
-
TICKET 2 # Users Unable to Access Application Through Firewall
-
Lecture 38.1Users Unable to Access Application Through Firewall
-
-
TICKET 3 # Branch Users Unable to Access HQ Resources Over VPN
-
Lecture 39.1Branch Users Unable to Access HQ Resources Over VPN
-
-
TICKET 4 # Branch to HQ Communication Failure Despite Active VPN Tunnel
-
Lecture 40.1Branch to HQ Communication Failure Despite Active VPN Tunnel
-
-
TICKET 5 # Production Server at HQ Site Inaccessible from Branch Office
-
Lecture 41.1Production Server at HQ Site Inaccessible from Branch Office
-
-
TICKET 6 # VPN Peer Reachable but Tunnel Never Establishes
-
Lecture 42.1VPN Peer Reachable but Tunnel Never Establishes
-
-
TICKET 7 # Remote VPN Users Lose Internet Connectivity After Connecting to Corporate Network
-
Lecture 43.1Remote VPN Users Lose Internet Connectivity After Connecting to Corporate Network
-
-
TICKET 8 # Remote VPN Users Can Access some corporate Resources but not others
-
Lecture 44.1Remote VPN Users Can Access some corporate Resources but not others
-
-
TICKET 9 # Remote VPN Connected but Corporate Web Apps can not be accessed
-
Lecture 45.1Remote VPN Connected but Corporate Web Apps can not be accessed
-
-
TICKET 10 # Internet Browsing is Extremely Slow for HQ user
-
Lecture 46.1Internet Browsing is Extremely Slow for HQ user
-
-
TICKET 11 # Website Loads Partially and then freezes
-
Lecture 47.1Website Loads Partially and then freezes
-
-
TICKET 12 # Split Tunnel Enabled, Yet Internet Stops Working
-
Lecture 48.1Split Tunnel Enabled, Yet Internet Stops Working
-
-
TICKET 13 # Some websites are working normally while others are not opening at all
-
Lecture 49.1Some websites are working normally while others are not opening at all
-
-
TICKET 14 # Social Media Applications are Blocked, Yet Some Users Can Still Access Them
-
Lecture 50.1Social Media Applications are Blocked, Yet Some Users Can Still Access Them
-
-
TICKET 15 # Users in VLAN 20 Cannot Access the Internet, While Other Departments Are Working Normally
-
Lecture 51.1Users in VLAN 20 Cannot Access the Internet, While Other Departments Are Working Normally
-

