Enterprise Network Implementation & Live Troubleshooting

Enterprise-network-troubleshooting
  • Lectures: 51
  • Students: 1

Enterprise Network Implementation & Live Troubleshooting

Build an Enterprise Lab, Understand the Concepts and Solve Real Troubleshooting Tickets

Course overview:

Enterprise Network Implementation & Live Troubleshooting is a practical, lab-driven course designed to help you understand how enterprise networks are built, how the underlying technologies work, and how to systematically troubleshoot real production issues.

The course is divided into three phases:

Phase 1 – Building the Enterprise Lab

Building a complete enterprise network from scratch, including enterprise routing, switching, internal and perimeter security, VPN connectivity, servers, and supporting infrastructure. This lab serves as the foundation for the entire course.

Phase 2 – Core Foundations (Conceptual Refresh)

A quick, practical refresh of the networking and security concepts that are essential for troubleshooting. The focus is on understanding the “why” behind each technology rather than just the configuration.

Phase 3 – Production Outage Scenarios & Live Ticket-Based Troubleshooting

Apply everything you’ve learned by investigating and resolving realistic production-style incidents on the same enterprise lab built in Phase 1. Each troubleshooting ticket is demonstrated live using a structured investigation and root cause analysis approach.

PHASE 1 : Building the Enterprise Lab

We start by building a real enterprise topology together.

  1. Core Network
  • Multiple VLANs (Users / PROD / UAT / DMZ / Management)
  • Inter-VLAN routing (SVIs)
  • Network segmentation design
  • Basic Layer-2 protections (loops, VLAN boundaries)
  1. Internal Firewall (East–West Security)
  • Deploy internal firewall
  • Control traffic between:
  • Users ↔ PROD servers
  • Users ↔ UAT servers
  • UAT ↔ PROD servers
  • Security policies
  • Internal segmentation concepts
  • Why internal firewalls are critical in enterprises

3.External Firewall (North–South Security)

  • Basic firewall configuration
  • Internet access for users & servers
  • NAT policies
  • Security policies
  • DMZ design
  1. DMZ + WAF
  • Deploy DMZ web servers
  • Configure WAF
  • Publish applications securely
  • Understand reverse proxy flow
  1. VPN & Hybrid Connectivity
  • IPsec Site-to-Site VPN (HQ ↔ Branch)
  • Remote Access VPN
  • Understand VPN routing, selectors and encryption domains

By the end of this phase, we will have a fully working enterprise network:

  • Users → Internal Firewall → PROD/UAT
  • DMZ behind WAF
  • External Firewall → Internet
  • Branch connected via VPN
  • Cloud connected via VPN

PHASE 2:  Core Foundations (Quick Refresh, Practical based)

Focused on concepts that directly help troubleshooting.

  1. TCP/IP & Practical OSI
  • Where enterprise networks actually break
  • Control plane vs data plane
  • Packet life cycle across switches, routers and firewalls

2.IP Header Deep Dive

  • TTL (loop detection, routing issues)
  • DF bit (PMTUD failures)
  • Fragmentation
  • DSCP / QoS markings
  • IP options (rare but important)
  1. TCP Header & Behavior
  • TCP flags
  • Connection setup & teardown
  • Sequence / ACK numbers
  • Windowing & window scaling
  • SACK
  • Retransmissions
  • Duplicate ACKs
  • Spurious retransmissions
  1. MSS / MTU / Blackhole
  • MSS vs MTU
  • Path MTU Discovery
  • MTU blackhole scenarios
  • Fragmentation impact on applications
  1. Layer 2 & Segmentation (Only What Breaks Networks)
  • VLAN design from security perspective
  • SVIs and routing boundaries
  • Private VLAN concepts
  • Broadcast storms
  • Switching loops
  • MAC flapping
  • Real outage caused by unmanaged switches
  1. Routing & Packet Path Analysis
  • Default routes
  • Forward vs return path
  • Asymmetric routing
  • Policy routing concepts

7.Firewall & VPN Troubleshooting

  • Firewall packet flow (NAT vs security policy)
  • Session tables
  • App-based policies
  • NAT order of operation
  • SSL inspection impact
  • VPN Deep Dive
  • Phase 1 / Phase 2
  • Proxy IDs / traffic selectors
  • MSS on VPN
  • Tunnel flapping
  • DPD failures

8.Application Slowness & WAN Issues

  • Latency vs bandwidth
  • TCP delays
  • Server response vs network delay
  • WAN packet loss
  • Jitter
  • False DDoS scenarios
  • Using Linux WAN impairment + Wireshark + monitoring.
  1. SSL / TLS & Certificates
  • TLS handshake
  • Certificate chains
  • Cipher negotiation
  • SSL inspection failures
  1. Monitoring + Root Cause Correlation
  • Using enterprise monitoring tools:
  • Interface utilization
  • Link flaps
  • Bandwidth spikes
  • Flow visibility
  • Correlating monitoring with packet captures

PHASE 3 : Production Outage Scenarios & Real Enterprise Tickets

Ticket 1 #  Users Can Reach Internal Resources but Cannot Access Internet

Ticket 2 # Users Unable to Access Application Through Firewall

Ticket 3 # Branch Users Unable to Access HQ Resources Over VPN

Ticket 4 # Branch to HQ Communication Failure Despite Active VPN Tunnel

Ticket 5 # Production Server at HQ Site Inaccessible from Branch Office

Ticket 6 # VPN Peer Reachable but Tunnel Never Establishes

Ticket 7 # Remote VPN Users Lose Internet Connectivity After Connecting to Corporate Network

Ticket 8 # Remote VPN Users Can Access some corporate Resources but not others

Ticket 9 # Remote VPN Connected but Corporate Web Apps can not be accessed

Ticket 10 # Internet Browsing is Extremely Slow for HQ user

Ticket 11 #  Website Loads Partially and then freezes

Ticket 12 # Split Tunnel Enabled, Yet Internet Stops Working

Ticket 13 # Some websites are working normally while others are not opening at all

Ticket 14 # Social Media Applications are Blocked, Yet Some Users Can Still Access Them

Ticket 15 # Users in VLAN 20 Cannot Access the Internet, While Other Departments Are Working Normally

  • 1. Course Introduction (Free Preview) 0/1

  • 2. Secure network design 0/1

  • 3. Understanding Network Building 0/1

  • 4. Building LAB inside eve-ng 0/1

  • 5. Core switching and VLAN Foundation 0/1

  • 6. Monitoring and Visibility Layer 0/1

  • 7. Installing LibreNMS 0/1

  • 8. Installing NTOPNG 0/1

  • 9. Adding switch into LibreNMS and configuing SPAN 0/1

  • 10. Understanding Routing and Configuring Internet Router 0/1

  • 11. Understanding and configuring Palo Alto firewall 0/1

  • 12. Verification and Troubleshooting 0/1

  • 13. Configuring Internal Firewall (FortiGate) 0/1

  • 14. Verification and Troubleshooting 0/1

  • 15. Understanding Load Balancer (ADC) 0/1

  • 16. Building the Application Delivery Path 0/1

  • 17. Verification and Troubleshooting 0/1

  • 18. WAF (FortiWEB) Protection Policy 0/1

  • 19. Adding Devices into LibreNMS 0/1

  • 20. Branch Firewall Configuration 0/1

  • 21. VPN Concepts 0/1

  • 22. Understanding IPsec S2S and Remote Access VPN 0/1

  • 23. IPSec site to site VPN Configuration 0/1

  • 24. Remote Access VPN configuration 0/1

  • 25. End of PHASE 1 (Building Enterprise Network) 0/1

  • 26. Introduction to Wireshark 0/1

  • 27. OSI and Pcaket Life Cycles 0/1

  • 28. IP Header Deep Dive 0/1

  • 29. TCP Header and Behavior 0/1

  • 30. Switching and Layer 2 Segmentation 0/1

  • 31. Routing and Packet Path Analysis 0/1

  • 32. Firewalls Packet Flow 0/1

  • 34. Application Slowness And WAN Issues 0/1

  • 35. Understanding Digital certificate and TLS Handshake 0/1

  • 36. Monitoring and Root cause Correlation 0/1

  • TICKET 1 # Users Can Reach Internal Resources but Cannot Access Internet 0/1

  • TICKET 2 # Users Unable to Access Application Through Firewall 0/1

  • TICKET 3 # Branch Users Unable to Access HQ Resources Over VPN 0/1

  • TICKET 4 # Branch to HQ Communication Failure Despite Active VPN Tunnel 0/1

  • TICKET 5 # Production Server at HQ Site Inaccessible from Branch Office 0/1

  • TICKET 6 # VPN Peer Reachable but Tunnel Never Establishes 0/1

  • TICKET 7 # Remote VPN Users Lose Internet Connectivity After Connecting to Corporate Network 0/1

  • TICKET 8 # Remote VPN Users Can Access some corporate Resources but not others 0/1

  • TICKET 9 # Remote VPN Connected but Corporate Web Apps can not be accessed 0/1

  • TICKET 10 # Internet Browsing is Extremely Slow for HQ user 0/1

  • TICKET 11 # Website Loads Partially and then freezes 0/1

  • TICKET 12 # Split Tunnel Enabled, Yet Internet Stops Working 0/1

  • TICKET 13 # Some websites are working normally while others are not opening at all 0/1

  • TICKET 14 # Social Media Applications are Blocked, Yet Some Users Can Still Access Them 0/1

  • TICKET 15 # Users in VLAN 20 Cannot Access the Internet, While Other Departments Are Working Normally 0/1

Admin bar avatar
Manoj Verma - CCIE # 43923 is a highly experienced senior technical instructor and Network/ security consultant. He has been in the networking industry for more than 19 years, with a focus on networking and security for the past 15 years. He has assisted thousands of engineers in obtaining their various certifications starting from CCNA to CCIE, CCSA, CCSE, PCNSE, F5, etc. and learning the latest and cutting-edge technologies.  He started his career as a system administrator and then switched to the networking and security domain. During the job, he realized that he is gifted with a passion for teaching and sharing his knowledge, as he used to teach his colleagues and friends. In his classroom training, he always starts with explaining the theory on a certain topic and then gives away a short note of key points and finally end with lab implementation. Now a day, driving down to the training institute to attend classroom training sessions is not feasible for everyone owing to the workflow, odd working hours and rotational shifts, especially for working professionals and those who are living in different cities and countries. He started getting multiple requests from lots of students to launch an online training module in the same way as he teaches in his classrooms. Keeping all this in mind, he designed this self-paced training module which replicates classroom training. He has brought his years of classroom teaching experience, and years of real-world enterprise and service provider experience in designing training modules. For a better understanding of technologies and in-depth knowledge, reading books or short notes is necessary and to witness the theoretical information in live, practical knowledge is required so he has included both which is very unique in the IT training sector.

There is no review for this course

Price

₹20,000.00

Rating

Not enough ratings to display

Leave a Reply

Select your currency
INR Indian rupee
X