WEEK 03

Networking II — Segmentation & Traffic

Operational scenario

Guest Wi-Fi and the finance servers share one flat network. Segment it before the auditor arrives Friday.

Week completion
0%
~10 hours this week
Assessment: Knowledge check 3; lab rubric
Deliverable: Segment config + annotated PCAP
Learning objectives
  • Configure VLANs, NAT and basic ACLs
  • Capture and read traffic
  • Identify exposed services
Classroom topics
  • Routing / switching
  • VLANs & segmentation
  • NAT
  • VPNs, proxies, load balancers
  • IDS / IPS
Standards · vocabulary
CIS Controls 4 & 12NIST SP 800-53 (SC)
VLANNATACLVPNIDSIPS
Open glossary
Competency demonstrated: Configures segmentation; analyzes traffic.

Four-mode learning matrix

~1.5 h
Physical hands-on lab

Configure two VLANs; capture with a tap or SPAN port.

~2 h
Docker container lab

Labs 3–4 — Read container logs; identify exposed services.

~0.5 h
AR/VR immersive scenario

Build segmentation with virtual equipment; inspect a firewall. Role: Network engineer.

No headset? Desktop segmentation simulator. Printed and mobile versions are also available.

Individual technical assignment

Analyze a provided PCAP and flag anomalies.

Team exercise

Segment the team lab into user and server zones.

Required hardware
  • Managed switch
  • Network tap or SPAN-capable switch
  • Wireshark host
Required software
  • Docker
  • Wireshark
  • tcpdump
Workplace application

Segmentation is one of the highest-value controls a network team can deploy and is required by PCI DSS and 62443.

Docker progression step
L3 Reading container logs

Tail proxy and webapp logs during a login attempt; capture the request line.

L4 Identifying exposed services

From student-ws, scan server-net and record the open ports; repeat from external.

Open the Docker range
Lab evidence to collect
Safety controls — confirm before starting
Controls practiced this week
Network security & segmentation
See the full crosswalk