0% found this document useful (0 votes)
2 views29 pages

Roadmap Networking

The document outlines a comprehensive curriculum for networking education, structured in eight stages ranging from beginner to expert levels. It covers essential topics such as the OSI and TCP/IP models, routing protocols, traffic engineering, network security, and cloud networking. Each stage builds on the previous one, introducing more advanced concepts and practical troubleshooting scenarios.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
2 views29 pages

Roadmap Networking

The document outlines a comprehensive curriculum for networking education, structured in eight stages ranging from beginner to expert levels. It covers essential topics such as the OSI and TCP/IP models, routing protocols, traffic engineering, network security, and cloud networking. Each stage builds on the previous one, introducing more advanced concepts and practical troubleshooting scenarios.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

August 17, 2025 1

Created by Sherif (shareefmvl007@[Link])


Networking Fundamentals
Stage 1 – Networking Fundamentals (Beginner)
1. OSI Model layers 1-7 overview
2. TCP/IP model layers mapping
3. Ethernet framing and types (II, SNAP)
4. MAC addresses structure and usage
5. Unicast vs broadcast vs multicast basics
6. IPv4 addressing and classes
7. Subnetting, CIDR, VLSM
8. IP header structure and fields
9. IPv4 fragmentation and reassembly
10. IPv6 addressing formats (global, link-local, unique local)
11. IPv6 header and extension headers
12. Stateless vs Stateful IPv6 address autoconfiguration
13. IPv6 no-addressing mechanisms (SLAAC, DHCPv6)
14. Dual-stack deployment basics
15. IPv4 vs IPv6 coexistence strategies (tunneling, translation)
16. IPv4/IPv6 address summarization
17. ARP vs ND (Neighbor Discovery protocol)
18. ICMPv4 message types and uses
19. ICMPv6 message types and uses (MLD)
20. TCP functionality: 3-way handshake, flags
21. UDP characteristics and use-cases
22. IP fragmentation in IPv6 (no fragmentation by routers)
23. TTL vs Hop Limit differences
24. DNS fundamentals and record types (A, AAAA, PTR, MX)
25. DNS caching and recursive vs iterative queries
26. DHCP (IPv4) operations and message types (DISCOVER, OFFER, REQUEST, ACK)
27. DHCP lease lifecycle
28. DHCP options (subnet mask, DNS, router)
29. DHCPv6 message types and operation
30. DHCP Relay Agent operation and configuration
31. NAT fundamentals (NAT overload, static NAT)
32. PAT (Port Address Translation)
33. NAT64 and NAT46 translation basics
34. Loopback interfaces purpose
35. Default gateways and router discovery
36. Network segmentation and ARP behavior
37. Collision vs broadcast domains
38. Introduction to wireless networking concepts (SSID, channels)
39. Basic WLAN architecture (AP, bridge, mesh)
40. Wireless standards overview (802.11a/b/g/n/ac/ax)
41. Wireless security basics (WEP, WPA, WPA2, WPA3)
42. Wireless channel bonding and width
43. Wireless interference and mitigation

August 17, 2025 2


Created by Sherif (shareefmvl007@[Link])
Stage 2 – Basic Routing Protocols & IPv6 (Intermediate)
44. RIP v2 features and limitations
45. RIPv2 convergence and timers
46. RIPv2 split-horizon and poison reverse
47. RIPng basics for IPv6
48. EIGRP fundamentals (DUAL, metric calculation)
49. EIGRP metrics tuning (bandwidth, delay, variance)
50. EIGRP stub and summarization features
51. EIGRP for IPv6 (EIGRPv6)
52. IS-IS basics: L1 vs L2 IS-IS in IPv4/IPv6 (overview)
53. IS-IS network entities (L1, L2, router roles)
54. Redistribution between RIP, EIGRP, IS-IS
55. Static routing for IPv4
56. Static routing for IPv6
57. Floating static routes and administrative distance
58. Default routing configuration IPv4/IPv6
59. Route summarization and aggregation strategies
60. Route redistribution pitfalls and loop prevention

Stage 3 – Forwarding, Traffic Engineering & QoS (Advanced)


61. IP packet forwarding process
62. CEF (Cisco Express Forwarding) internals
63. FIB and adjacency tables
64. Policy-Based Routing (PBR) basics
65. Traffic Classification and marking (DSCP, CoS)
66. QoS queuing strategies (CBWFQ, LLQ)
67. Shaping vs Policing principles
68. MQC (Modular QoS CLI) configuration workflow
69. QoS over links (MPLS, WAN, Metro)
70. Traffic selection and trust boundaries
71. CoS vs DSCP marking for converged networks
72. Re-marking strategies for interoperability
73. Packet Loss, Jitter, Latency definitions and handling
74. TCP congestion control fundamentals (slow start, AIMD)
75. Traffic shaping for TCP flows
76. Queueing delay and buffer impacts
77. QoS measurement and verification (show commands)
78. DiffServ classes (EF, AF, Best Effort)
79. Expedited Forwarding vs Assured Forwarding models
80. Traffic Engineering with RSVP (for TE path setup)
81. MPLS TE vs IP-TE fundamentals
82. Resource Reservation basics for QoS/TE
83. Bandwidth estimation and reservation models
84. OSPF-TE basics (traffic engineering extensions)
85. Segment Routing Traffic Engineering (brief overview)

August 17, 2025 3


Created by Sherif (shareefmvl007@[Link])
Stage 4 – High-Availability, Security & Data Center (Expert)
86. VRRP/HSRP/GLBP redundancy protocols (IPv4/IPv6)
87. VRRP for IPv6 differences vs IPv4
88. Load balancing at the router edge
89. Control-plane vs data-plane redundancy
90. DHCP failover mechanism
91. DNS redundancy and zones (primary/secondary)
92. IP SLA for monitoring and failover
93. Network automation introduction (templates, scripting)
94. RESTCONF/YANG for network programmability
95. SDN basics in enterprise (controller, southbound protocols)
96. VXLAN within switching (overview, already covered)
97. EVPN use-cases for routing decisions (overview)
98. Data Center fabric elements (leaf/spine architectures)
99. FabricPath and TRILL basics
100. Underlay (BGP or OSPF) for fabric routing
101. Overlay for East-West routing (EVPN/VXLAN)
102. Server virtualization and NIC teaming
103. vPC (Virtual Port Channel) principles (brief)
104. Micro-segmentation fundamentals
105. Network Function Virtualization (NFV) overview

Stage 5 – Wireless, Network Services & Inspection (Specialist)


106. Wireless controller architectures (centralized, distributed)
107. Wireless roaming fundamentals
108. RF fundamentals (dBm, channels, throughput)
109. Wireless QoS (WMM)
110. Wireless intrusion protection systems (WIPS) basics
111. Guest vs enterprise authentication (WPA-EAP, 802.1X)
112. RADIUS vs TACACS+ differences
113. RADIUS attributes and packet flow
114. VLAN assignment via RADIUS (dynamic assignment)
115. NTP synchronization for network devices
116. SNMP (v2, v3) fundamentals and MIBs
117. Syslog, logging levels, and centralized collection
118. IPFIX / NetFlow basics for traffic analysis
119. Network monitoring tools overview (e.g., NMS)
120. Basic packet capture and Wireshark usage

Stage 6 – Automation, Cloud & Future Networking (CCIE-Level)


121. Infrastructure as Code (Ansible, Terraform for network)
122. GitOps principles in networking
123. CI/CD pipelines for network changes

August 17, 2025 4


Created by Sherif (shareefmvl007@[Link])
124. Telemetry streaming (gNMI, gRPC)
125. Model-driven telemetry (YANG-based)
126. Network assurance & validation tools
127. Cloud networking fundamentals (VPC, subnets, routing)
128. Cloud-native network service insertion
129. Hybrid cloud connectivity (VPN, Direct Connect, ExpressRoute)
130. Cloud load balancing and gateway concepts
131. Cloud DNS and DHCP services (Route 53, Azure DNS)
132. Secure cloud edge (NGFW, ZTNA)
133. Micro-segmentation in cloud
134. Network slicing concept (5G context)
135. IoT network design patterns
136. SD-Branch deployment modes
137. Intent-based networking fundamentals
138. AI/ML for network anomaly detection
139. Self-healing network concepts
140. Brownfield to SDN migration strategies
141. Distributed denial-of-service (DDoS) mitigation basics
142. Network segmentation and zero trust models
143. Time-sensitive networking (TSN) basics
144. Edge computing network design
145. 5G network architecture basics (standalone vs non-standalone)
146. Carrier Ethernet SD-WAN integration (overview)
147. Green networking: power and capacity planning
148. Network business continuity planning
149. Compliance (PCI, GDPR) considerations in networking
150. Operational runbooks and playbooks

Stage 7 – Troubleshooting & Real-World Case Studies (Expert)


151. Layer-2 vs Layer-3 isolation testing
152. ARP and ND cache issues
153. Dual-stack connectivity problems
154. TCP handshake failure troubleshooting
155. Fragmentation path-MTU issues
156. DNS resolution failure debugging
157. DHCP lease acquisition problems
158. DHCP Relay misconfiguration cases
159. NAT/PAT translation failures
160. IPv6 unreachable host scenarios
161. QoS misplacement and policy order errors
162. SLA violation troubleshooting (jitter/loss)
163. VRRP/HSRP failover anomalies
164. Wireless coverage and interference issues
165. Wireless authentication failures
166. RADIUS accounting mismatches
167. ACL order mistakes and unintended blocks
168. Path-MTU black holes
169. Cloud connectivity latency/bandwidth issues

August 17, 2025 5


Created by Sherif (shareefmvl007@[Link])
170. SDN controller discovery issues
171. API failure diagnosis (timeouts, auth issues)
172. Automation script error tracing
173. Infrastructure drift detection and remediation
174. Configuration rollback best practices
175. Network outage post-mortem case study
176. Multi-vendor interoperability snags
177. Stateful vs stateless firewalling errors
178. DNS failover misconfiguration diagnosis
179. Cyber-attack impact on network operations
180. Real-world: Cloud bursting network design failures

Stage 8 – Strategy, Design & Leadership (Expert+)


181. Enterprise network design frameworks (Cisco, MEF)
182. Network as a Service (NaaS) trends
183. Multi-cloud network architecture planning
184. Intent to operation mapping in networks
185. Network operations centers (NOC) vs SecOps integration
186. Vendor evaluation criteria for enterprise networks
187. Technology adoption roadmap design
188. Greenfield vs brownfield deployment planning
189. Disaster recovery network strategies
190. Business intent translation into network SLAs
191. Steering policy around business workflows
192. Executive-level network health dashboards
193. Network cost optimization strategies
194. Operational maturity models (ITIL, COBIT) in networking
195. Security posture measurement (risk scoring)
196. Policy governance frameworks
197. RFP and bid evaluation for network solutions
198. Proof-of-Concept validation metrics
199. Continuous improvement through NPS/feedback loops
200. Post-incident learning and continuous operational improvement

Switching
Stage 1 – Beginner (Fundamental Concepts & Basics)
1. Layer 2 vs Layer 3 switching
2. How switches learn MAC addresses
3. MAC address table (CAM) entries & aging
4. Static MAC address entries
5. Switch forwarding modes (cut-through, store-and-forward, fragment-free)
6. Switch architecture: backplane, switch fabric, ASICs

August 17, 2025 6


Created by Sherif (shareefmvl007@[Link])
7. Multilayer switching basics
8. Switch port types: access vs trunk
9. VLAN concept and broadcast domains
10. VLAN configuration
11. 802.1Q trunking
12. Native VLAN
13. Voice VLAN implementation
14. VLAN hopping vulnerabilities
15. Private VLANs (PVLAN)
16. Inter-VLAN routing fundamentals
17. Basic switch troubleshooting (interface up/down)
18. CEF (Cisco Express Forwarding) basics
19. SDM (Switching Database Manager)
20. Troubleshooting high CPU/memory on switch

Stage 2 – Intermediate (VLANs, Trunking & Spanning Tree)


21. VLAN Trunking Protocol (VTP) versions 1/2/3
22. VTP pruning
23. VTP transparent mode
24. Spanning Tree Protocol (STP) fundamentals
25. STP port states
26. STP cost calculation
27. PVST+ (Per-VLAN STP)
28. RPVST+ (Rapid PVST+)
29. RSTP (IEEE 802.1w)
30. MSTP (Multiple Spanning Tree)
31. Spanning Tree: TCN (Topology Change Notification)
32. PortFast
33. UplinkFast
34. BackboneFast
35. BPDU Guard
36. BPDU Filter
37. Root Guard
38. Loop Guard
39. UDLD (Unidirectional Link Detection)
40. Flex Links
41. Spanning Tree troubleshooting scenarios
42. EtherChannel concepts
43. LACP vs PAgP vs static port-channel
44. Layer-2 EtherChannel
45. Layer-3 EtherChannel
46. EtherChannel load balancing methods
47. EtherChannel misconfiguration issues
48. Virtualization: StackWise (Cisco switch stacking)
49. Switch virtualization basics
50. Stack troubleshooting

August 17, 2025 7


Created by Sherif (shareefmvl007@[Link])
Stage 3 – Advanced (Security, QoS & Design Considerations)
51. Port security (MAC lock, violation actions)
52. DHCP Snooping
53. Dynamic ARP Inspection (DAI)
54. IP Source Guard
55. Storm control (broadcast, multicast)
56. VLAN Access Control Lists (VACLs)
57. QoS basics on LAN switches
58. QoS trust boundaries
59. Classification and marking (CoS, DSCP)
60. Queuing mechanisms (e.g., CBWFQ)
61. Storm control algorithm tuning
62. ARP inspection combined with port security
63. Loop prevention design (UDLD, BPDU Guard combined)
64. Asymmetric routing and unicast flooding issues
65. VXLAN basics for overlays
66. RSPAN (Remote SPAN)
67. NetFlow on switches
68. IGMP Snooping and Querier functionality
69. Multi-Chassis LAG (vPC/Stackwise Virtual)
70. MAC address changing on switchport (MAC aliasing)
71. QoS policing configuration
72. QoS pre-classify
73. SNMPv3 switch management
74. NTP on switches
75. Device IOS upgrade via StackWise

Stage 4 – Expert (Automation, SDN, Advanced Design & Emerging


Tech)
76. Layer-4 switching (e.g., traffic policing by port numbers)
77. Overlay Transport Virtualization (OTV)
78. VXLAN deeply (multicast/no multicast, EVPN)
79. SDN concepts in switching (separation of control/data planes)
80. OpenFlow-enabled switching
81. SD-LAN architecture
82. Network Function Virtualization (NFV) in switching contexts
83. Active networking concepts
84. Software-Defined Networking controller integrations (e.g., Cisco ACI)
85. Switch orchestration with automation (Ansible, Python)
86. Telemetry on switches
87. Overlay vs Underlay network design
88. Zero-trust segmentation using switches
89. MPLS integration points with switching (e.g., CE switching)
90. Orchestration for VXLAN EVPN deployment
91. Anycast gateway design
92. High-performance spine-leaf topologies

August 17, 2025 8


Created by Sherif (shareefmvl007@[Link])
93. Switching at data center scale (leaf/spine, low latency)
94. Broadcast domain scaling strategies
95. Switch fabric scaling in chassis systems
96. Automation of VLAN provisioning across environments
97. Telemetry (gNMI, Streaming Telemetry)
98. Threat detection via switch logs/telemetry
99. Automation for port security deployment
100. SD-Access integrated switches (Cisco DNA)
101. Switch interoperability issues across vendors
102. ACL automation and compliance verification
103. Failover and redundancy design (HSRP/VRRP integration awareness)
104. Edge switching for IoT segmentation
105. Virtual switch integration (open vSwitch)
106. Automation for stack firmware upgrades
107. Event-driven automation for switch anomalies
108. Multi-tenancy VLAN automated segmentation
109. Campus fabric designs (Cisco FabricPath)
110. Design guidelines to prevent unicast flooding
111. Evolution: Switch chip (ASIC) trends and capacities
112. Advanced switch memory/FIB scaling issues
113. Design for multicast optimized switching
114. Inter-switch control plane isolation strategies
115. Advanced debugging (SPAN, interface err-disabled recovery)
116. ERR-disable recovery automation
117. Future developments: AI/ML in switch anomaly detection
118. Switch role in micro-segmentation architectures
119. Whitebox switching and SONiC OS
120. Emerging switch APIs (e.g., OpenConfig, gRPC)
121. Case studies of switching failures and recovery

OSPF
OSPF Beginner (Foundations)
1. OSPF overview and characteristics
2. Link-state vs distance-vector vs path-vector
3. OSPF terminology (LSA, LSDB, SPF, neighbors, adjacency)
4. OSPF router ID
5. OSPF process ID vs area ID
6. OSPF interface types (broadcast, NBMA, point-to-point, point-to-multipoint, virtual links)
7. OSPF Hello protocol
8. OSPF neighbor states (Down, Init, 2-Way, ExStart, Exchange, Loading, Full)
9. OSPF Hello and Dead timers
10. OSPF DR/BDR election
11. OSPF cost metric calculation
12. OSPF administrative distance
13. OSPF areas and backbone area (area 0)

August 17, 2025 9


Created by Sherif (shareefmvl007@[Link])
14. Stub area concept
15. Totally stubby area
16. Not-so-stubby area (NSSA)
17. Totally NSSA
18. OSPF area types comparison table
19. OSPF LSAs overview
20. OSPF packet types (Hello, DBD, LSR, LSU, LSAck)

OSPF Intermediate (Configuration & Operations)


21. OSPF network types and behavior (broadcast, non-broadcast, p2p, p2mp)
22. OSPF NBMA modes (P2MP NBMA, P2MP Non-broadcast)
23. OSPF neighbor configuration (manual neighbors for NBMA)
24. OSPF priority and DR/BDR control
25. OSPF passive-interface command
26. OSPF loopback treatment
27. OSPF virtual-links configuration
28. OSPF authentication (plain text, MD5, SHA)
29. OSPF multi-area configuration
30. OSPF summarization (inter-area)
31. OSPF summarization (external routes)
32. OSPF route filtering with distribute-lists
33. OSPF route filtering with prefix-lists
34. OSPF route filtering with area filter-lists
35. OSPF cost manipulation (bandwidth command, ip ospf cost, auto-cost reference-bandwidth)
36. OSPF path selection rules
37. OSPF default-information originate
38. OSPF default route in stub areas
39. OSPF LSA types in detail (1-11)
40. Type 1 Router LSA
41. Type 2 Network LSA
42. Type 3 Summary LSA
43. Type 4 ASBR-Summary LSA
44. Type 5 External LSA
45. Type 7 NSSA LSA
46. Type 8 External attributes (for BGP, rarely used)
47. Type 9 Opaque LSA (link-local scope)
48. Type 10 Opaque LSA (area scope)
49. Type 11 Opaque LSA (AS scope)
50. OSPF LSDB database examination

OSPF Advanced (Design & Optimization)


51. OSPF SPF algorithm (Dijkstra’s algorithm)
52. OSPF incremental SPF
53. OSPF LSA flooding and aging
54. OSPF throttling timers (spf timers, lsa timers)

August 17, 2025 10


Created by Sherif (shareefmvl007@[Link])
55. OSPF demand circuits
56. OSPF fast hellos
57. OSPF graceful restart (non-stop forwarding, NSF)
58. OSPF BFD (Bidirectional Forwarding Detection) integration
59. OSPF sham-link (MPLS VPN design)
60. OSPF external route types (E1 vs E2)
61. OSPF redistribution (with metrics and tags)
62. OSPF route-maps in redistribution
63. OSPF sub-second convergence tuning
64. OSPF TE (Traffic Engineering extensions, opaque LSAs)
65. OSPF multi-topology extensions
66. OSPF over Frame Relay (legacy)
67. OSPF over DMVPN
68. OSPF over MPLS
69. OSPF over GRE
70. OSPF over IPsec
71. OSPF auto-cost reference bandwidth scaling (for 10G/40G/100G)
72. OSPF database overflows and scaling techniques
73. OSPF prefix suppression
74. OSPF hierarchical design best practices
75. OSPF area design (hub-and-spoke, mesh, transit areas)
76. OSPF inter-area route preference vs intra-area
77. OSPF LSA pacing and optimization
78. OSPF neighbor flapping troubleshooting
79. OSPF stuck in EXSTART/Exchange states troubleshooting
80. OSPF LSA flooding storm troubleshooting

OSPF Expert (Enterprise & Service Provider Focus)


81. OSPFv2 vs OSPFv3
82. OSPFv3 address-family support (IPv4, IPv6 unicast, multicast)
83. OSPFv3 authentication (IPsec)
84. OSPFv3 LSA changes vs OSPFv2
85. OSPFv3 neighbor formation
86. OSPFv3 multi-topology
87. OSPFv3 route filtering
88. OSPFv3 virtual-links
89. OSPFv3 multi-area adjacency on a single link
90. OSPFv3 in MPLS VPNs
91. OSPF multi-instance support
92. OSPF multi-area adjacencies
93. OSPF on point-to-point links vs broadcast difference in scaling
94. OSPF inter-AS (though rarely used, type 5 LSAs)
95. OSPF vs IS-IS comparison
96. OSPF vs EIGRP comparison
97. OSPF vs BGP design use cases
98. OSPF in large-scale ISP backbones
99. OSPF hierarchical area scaling in ISPs
100. OSPF convergence benchmarks in large networks

August 17, 2025 11


Created by Sherif (shareefmvl007@[Link])
101. OSPF Graceful Shutdown (RFC 8379)
102. OSPF Link Overload (RFC 8335)
103. OSPF LFA (Loop-Free Alternates) interaction
104. OSPF TI-LFA for SR networks
105. OSPF Segment Routing extensions
106. OSPF in SDN environments
107. OSPF troubleshooting with Wireshark
108. OSPF adjacency flaps in unstable WANs
109. OSPF vs IS-IS for traffic engineering
110. OSPF security vulnerabilities and mitigations
111. OSPF authentication key rollover design
112. OSPF interoperability issues across vendors
113. OSPF route-tagging strategies in redistribution
114. OSPF blackhole scenarios and prevention
115. OSPF split-area design issues
116. OSPF false LSA injection attacks
117. OSPF TE with RSVP-TE/MPLS
118. OSPF Graceful Restart interoperability issues
119. OSPF multi-area sham links in MPLS VPNs
120. OSPF advanced debugs (adjacency, database, spf, flooding)

BGP
Stage 1 – Beginner (Foundations & Basics)
1. What is BGP
2. BGP features and characteristics
3. BGP use cases (ISP, Enterprise, Datacenter, Cloud)
4. Autonomous Systems (AS) concept
5. Private vs Public AS numbers
6. BGP message types (Open, Update, Notification, Keepalive)
7. BGP neighbor states (Idle → Established)
8. eBGP vs iBGP
9. BGP session establishment (TCP port 179)
10. eBGP multihop
11. BGP authentication (MD5, TCP-AO)
12. BGP timers (Keepalive, Hold)
13. BGP path vector concept
14. BGP table vs RIB vs FIB
15. Advertising networks (network command)
16. Redistribution into BGP
17. Next-hop behavior (eBGP vs iBGP)
18. Next-hop-self
19. Synchronization rule (legacy concept)
20. BGP administrative distance (eBGP 20, iBGP 200)

August 17, 2025 12


Created by Sherif (shareefmvl007@[Link])
Stage 2 – Intermediate (Attributes, Path Selection & Policies)
21. Route aggregation (manual / auto-summary)
22. Aggregate-address command
23. AS-Path attribute
24. AS-Path prepending
25. Local Preference attribute
26. Weight attribute (Cisco-specific)
27. MED (Multi Exit Discriminator)
28. Origin attribute (IGP, EGP, Incomplete)
29. Community attribute (well-known)
30. Extended communities
31. Large communities (RFC 8092)
32. Route Maps for BGP policy
33. Prefix lists for BGP filtering
34. Distribute lists with BGP
35. Filter lists (AS-Path filter)
36. Route filtering inbound vs outbound
37. BGP soft reconfiguration (inbound)
38. BGP route refresh capability
39. BGP Best Path Selection order
40. Tie-breakers in path selection
41. BGP multipath (ECMP)
42. iBGP split-horizon rule
43. Full-mesh iBGP requirement

Stage 3 – Advanced (Scaling, Optimization & Stability)


44. Route Reflectors
45. Route Reflector cluster-ID
46. Route Reflector redundancy
47. Confederations
48. Confederation AS numbering
49. Confederation vs Route Reflector differences
50. Route dampening
51. Flap damping parameters
52. BGP convergence challenges
53. Graceful restart
54. Route refresh mechanism
55. BGP fast external fallover
56. BGP session culling
57. BGP TCP path MTU discovery
58. TTL security (GTSM)
59. Max-prefix feature
60. BGP neighbor password security
61. Inbound vs Outbound route filtering
62. BGP maximum-paths (load sharing)
63. Multi-homing design with BGP
64. Dual-homing to single ISP

August 17, 2025 13


Created by Sherif (shareefmvl007@[Link])
65. Dual-homing to multiple ISPs
66. Default route origination in BGP
67. BGP conditional advertisement
68. BGP policy-based routing integration

Stage 4 – Expert (MPLS, VPNs, Cloud, Security)


69. BGP and MPLS VPN (MP-BGP)
70. BGP VPNv4 address family
71. BGP VPNv6 address family
72. BGP Route Targets (extended community)
73. BGP Route Distinguishers
74. BGP in MPLS L3VPN
75. BGP in MPLS L2VPN
76. BGP in EVPN (Ethernet VPN)
77. BGP in VXLAN EVPN
78. BGP labeled unicast (BGP-LU)
79. BGP with SR (Segment Routing)
80. BGP in IPv6 (MP-BGP for IPv6)
81. IPv4-mapped IPv6 sessions
82. BGP ORF (Outbound Route Filtering)
83. BGP add-path capability
84. BGP PIC (Prefix Independent Convergence)
85. BGP GR (Graceful Restart) vs NSF (Non Stop Forwarding)
86. BGP RIB failure (reason codes)
87. BGP route recursion and next-hop resolution
88. BGP monitoring commands (show ip bgp, debug ip bgp)
89. Route selection with Local Preference vs MED
90. Influence inbound traffic with AS-Path prepend
91. Influence outbound traffic with Local Pref
92. Influence outbound traffic with Weight
93. Hot-potato vs Cold-potato routing
94. BGP traffic engineering with communities
95. Blackhole routing with BGP communities
96. Internet routing table size & scaling challenges
97. BGP convergence issues at Internet scale
98. BGP hijacking (security threat)
99. RPKI (Resource Public Key Infrastructure)
100. BGP origin validation
101. BGP monitoring tools (BMP, SNMP, NetFlow, telemetry)
102. BGP large-scale troubleshooting (route leaks, hijacks)
103. BGP session debugging (TCP 3-way handshake issues)
104. Route oscillation problem
105. BGP route server (IXPs)
106. BGP Graceful Shutdown (RFC 8326)
107. BGP SR-TE policies
108. BGP Flowspec (RFC 5575, DDoS mitigation)
109. BGP Anycast deployments
110. BGP with Cloud providers (AWS, Azure, GCP Direct Connect)

August 17, 2025 14


Created by Sherif (shareefmvl007@[Link])
111. BGP default route only peering
112. Partial vs full routing table from ISP
113. Internet peering vs transit BGP design
114. Blackholing with RTBH (Remote Triggered Black Hole)
115. BGP bug/quirks in Cisco vs Juniper vs Arista implementations
116. BGP GRACEFUL_SHUTDOWN community
117. BGP session protection with IPsec
118. BGP confederation deployment in real-world ISPs
119. BGP timers tuning (fast vs slow failover)
120. Troubleshooting case studies (neighbor stuck in Active, routes not advertised, next-hop
unreachable, flap damping misconfig, etc.)

MPLS
MPLS Beginner (Fundamentals & Basics)
1. What is MPLS
2. MPLS purpose and benefits
3. MPLS data plane (Layer 2.5)
4. Forwarding Equivalence Classes (FECs)
5. Label operations: PUSH, SWAP, POP
6. Label stack structure
7. MPLS header and EtherType (0x8847/0x8848)
8. MPLS devices: LER vs LSR
9. Label Switched Path (LSP) concept
10. Penultimate Hop Popping (PHP)
11. Implicit-null vs explicit-null labels
12. TTL propagation in MPLS
13. Label Distribution Protocol (LDP)
14. LDP label distribution
15. LDP sessions and neighbors
16. Static label distribution
17. Resource Reservation Protocol – Traffic Engineering (RSVP-TE)
18. RSVP-TE setup of LSPs
19. MPLS and IP routing interaction (IGP requirements)
20. MPLS VPN basics (Layer 3 VPN)
21. VRFs (Virtual Routing and Forwarding)
22. Route Distinguisher (RD)
23. Route Target (RT)
24. VPNv4 vs IPv4 address families
25. PE vs P vs CE routers in VPNs
26. MPLS over GRE/IP tunnels basic
27. MPLS IGP dependencies – OSPF/EIGRP/BGP prerequisites

August 17, 2025 15


Created by Sherif (shareefmvl007@[Link])
MPLS Intermediate (Configuration, TE & VPN Enhancements)
28. MPLS VPN configuration basics
29. L3VPN PE-CE using IGP
30. L3VPN PE-CE using BGP (MP-BGP)
31. MPLS VPN BGP “allow-as-in”
32. VPN BGP AS-override
33. VPN default-route injection
34. Sham-link in MPLS VPN
35. VRF Lite and route leaking
36. Extranet route leaking
37. VRF import/export route-maps
38. AToM (Any Transport over MPLS, L2 VPN)
39. IPv6 over MPLS (6PE/6VPE)
40. Traffic Engineering (TE) fundamentals
41. MPLS TE with IS-IS
42. MPLS TE with OSPF
43. RSVP-TE tunnel configurations
44. TE explicit path options
45. Policy-Based Routing for TE
46. Autoroute announce/destination
47. Unequal-cost load balancing with TE
48. TE forwarding adjacency
49. Class-Based Tunnel Selection (CBTS)
50. TE metrics and path selection
51. TE setup and hold priorities
52. TE affinity and attribute flag use
53. TE re-optimization
54. TE Fast Reroute (FRR)
55. FRR path link protection
56. FRR path node protection
57. LDP label filtering techniques
58. MPLS tuning: label range, scaling
59. MPLS label space and range (default 16–100000)
60. Full mesh vs route-reflector in MPLS VPN BGP

MPLS Advanced (Resiliency, Segment Routing & Troubleshooting)


61. Label-Switched Path loop prevention
62. MPLS loop detection mechanisms
63. Traffic Engineering scaling challenges
64. Path Computation Element (PCE) architecture
65. Hierarchical or Stateful PCE
66. MPLS local protection (Fast Reroute)
67. One-to-one vs many-to-one local protection
68. Link protection vs node protection
69. Element-level protection
70. MPLS LSP design for resilience
71. Segment Routing (SR) fundamentals

August 17, 2025 16


Created by Sherif (shareefmvl007@[Link])
72. SR architecture over MPLS
73. Node and adjacency segments in SR
74. Source-routed SR paths
75. SR advantages over RSVP-TE
76. SR scaling and state-efficiency
77. SRv6 (Segment Routing over IPv6) extension
78. SR standardization and implementations
79. SDN-MPLS hybrid traffic engineering
80. Bandwidth Allocation Models (BAMs) in MPLS DS-TE
81. Autonomic BAM switching
82. Advanced troubleshooting: label-stack decoding
83. Troubleshooting LDP sessions
84. LDP neighbor issues diagnosis
85. Troubleshooting RSVP-TE tunnels
86. Troubleshooting FRR behavior
87. MPLS traffic-eng troubleshooting commands
88. Label stack analysis (depth, order)
89. LFIB vs RIB vs FIB discrepancies
90. Scaling: LFIB memory and CPU challenges
91. Monitoring tools: mpls-trace, show commands

MPLS Expert (Security, Loops, Cloud & Emerging)


92. MPLS security vulnerabilities (label spoofing, DoS)
93. Security mitigation strategies in MPLS networks
94. MPLS in cloud connectivity and provider backbones
95. MPLS in SDN-controlled environments
96. OAM integration with MPLS
97. MPLS enhancement with GMPLS
98. Interoperability across vendors (Cisco/Juniper/Arista)
99. MPLS route-reflector design patterns
100. Inter-AS MPLS VPN mechanisms (Option A/B/C)
101. L2 VPN (VPLS) integration with MPLS
102. MPLS Graceful Shutdown (RFC 8274)
103. Segment Routing TE with LFA / TI-LFA
104. MPLS Anycast use cases
105. RTBH (Remote Triggered Black Hole) with MPLS
106. MPLS for CDN and streaming
107. MPLS label stack fragmentation issues
108. Dynamic virtual circuit provisioning over MPLS
109. MPLS orchestration with automation tools
110. Telemetry in MPLS networks
111. MPLS route leak detection and prevention
112. Case studies: MPLS failures and recovery designs
113. MPLS large-scale convergence benchmarking
114. Interactions: MPLS TE with BGP, OSPF, IS-IS
115. MPLS in IoT and edge network designs
116. Evolution: GMPLS over optical networks
117. MPLS evolution toward SR and IETF RFC developments

August 17, 2025 17


Created by Sherif (shareefmvl007@[Link])
118. MPLS modeling and simulation platforms
119. MPLS during network segmentation / zero trust
120. Future research in MPLS (e.g., PCE, SR, automation)

VXLAN
Stage 1 – Beginner (Fundamentals)
1. VXLAN overview and purpose
2. Overlay vs Underlay networks
3. VXLAN Network Identifier (VNI) significance
4. VXLAN Tunnel End Point (VTEP) concept
5. VXLAN frame encapsulation (MAC-in-UDP)
6. VXLAN UDP ports (IANA 4789, legacy 8472)
7. Scalability advantages over VLANs (16M segments)
8. Basic VXLAN packet walkthrough
9. Underlay routing protocols (OSPF, IS-IS) for VXLAN
10. Static ingress replication approach
11. Multicast flood-and-learn BUM handling
12. VXLAN in traditional data center architecture

Stage 2 – Intermediate (Control Plane & Multicast)


13. VXLAN Flood-and-Learn with multicast configuration
14. VXLAN Multicast Anycast RP design and configuration
15. VXLAN static ingress replication limitations
16. Head-end replication alternatives
17. Multicast underlay for BUM traffic
18. Use of PIM in VXLAN environments
19. Rendezvous Point (RP) redundancy strategies
20. VXLAN underlay eBGP two-AS model
21. VXLAN underlay eBGP multi-AS model
22. VXLAN underlay using OSPF
23. VXLAN underlay using IS-IS
24. Role of ECMP in VXLAN underlay fabrics
25. Overlay configuration without multicast

Stage 3 – Advanced (EVPN, MAC/IP Learning & Optimization)


26. MP-BGP EVPN for VXLAN (L2 VNI)
27. MP-BGP EVPN for VXLAN (L3 VNI)
28. EVPN control-plane vs data-plane modes

August 17, 2025 18


Created by Sherif (shareefmvl007@[Link])
29. EVPN route types (Type 2 MAC/IP, Type 5 IP Prefix)
30. EVPN Route Distinguisher (RD) and Route Target (RT) usage
31. VXLAN EVPN MAC/IP advertisement
32. Scaling benefits of EVPN over multicast
33. Address resolution via EVPN
34. EVPN with ARP suppression and cache behavior
35. Conflict and aging complexities in ARP suppression
36. EVPN-based BUM handling strategies
37. VXLAN ARP suppression configuration techniques
38. VXLAN EVPN ARP cache maintenance
39. Integration of EVPN with underlay protocols
40. VXLAN device types: software vs hardware VTEPs

Stage 4 – Expert (Design, Scaling & Automation)


41. VXLAN VTEP high availability and redundancy
42. Overlay scalability and control-plane efficiency
43. Design patterns for EVPN-VXLAN fabrics
44. EVPN-active multi-homing (Ingress replication vs EVPN)
45. VXLAN underlay automation best practices
46. VXLAN in multi-tenant cloud environments
47. VXLAN integration with SDN frameworks
48. VXLAN troubleshooting commands and debugging
49. Packet capture and analysis for VXLAN/NVE traffic
50. VXLAN interoperability across vendors
51. VXLAN deployments in public cloud (e.g., AWS, Azure)
52. VXLAN in Kubernetes/containerized environments
53. VXLAN telemetry and analytics
54. VXLAN performance tuning (MTU, pacing)
55. VXLAN flow optimization and ECGP considerations
56. VXLAN secure overlay deployments (ACLs/QoS)
57. VXLAN in convergence scenarios with other overlays (e.g., GENEVE)
58. VXLAN deployment case studies and lessons learned
59. VXLAN scalability challenges and solutions
60. VXLAN future directions (e.g., GENEVE comparison)
61. VXLAN in hybrid data center designs
62. Integration with orchestration tools (Ansible, Terraform)
63. VXLAN switch/ASIC capabilities comparison
64. VXLAN logging and anomaly detection strategies
65. VXLAN cross-pod/data-center bridging
66. Secure multi-tenancy isolation in VXLAN overlays
67. VXLAN failover and convergence mechanisms
68. Testing VXLAN fabrics at scale
69. VXLAN load balancing strategies
70. Future overlay evolution (e.g., towards Segment Routing overlays)

August 17, 2025 19


Created by Sherif (shareefmvl007@[Link])
SDWAN
Stage 1 – Beginner (Foundations & Architecture)
1. What is SD-WAN
2. SD-WAN vs Traditional WAN
3. SD-WAN business drivers and benefits
4. Overlay vs Underlay concepts
5. Control plane vs Data plane separation
6. Cisco SD-WAN (Viptela) architecture overview
7. vManage role and functions
8. vSmart role and functions
9. vBond role and functions
10. WAN Edge (vEdge/cEdge) roles
11. vAnalytics overview
12. OMP (Overlay Management Protocol) basics
13. TLOC concept
14. TLOC color types
15. System IP, Site ID, Organization name
16. VPN and VRF basics in SD-WAN
17. Transport options (MPLS, Internet, LTE, 5G)
18. DIA (Direct Internet Access) concept
19. Segmentation and multi-tenancy fundamentals
20. SD-WAN and SASE relationship
21. App-aware routing high level
22. Underlay IGP/BGP vs Overlay control basics
23. Cloud connectivity basics
24. SD-WAN device onboarding flow
25. ZTP (Zero-Touch Provisioning) concept

Stage 2 – Intermediate (Components, Onboarding & Operations)


26. Device certificates and PKI options
27. Controller deployment models (on-prem, cloud-hosted)
28. vManage templates (feature/device)
29. Variables and device-specific parameters
30. CLI add-on templates
31. Controller redundancy and clustering
32. Control connections establishment
33. Data plane IPsec tunnels
34. DTLS/TLS control connections
35. NAT traversal mechanisms
36. Management VPN (VPN 512)
37. Transport VPN (VPN 0)
38. Service VPNs (user/data)
39. vBond orchestration flow
40. OMP route types (OMP/TLOC/Service)

August 17, 2025 20


Created by Sherif (shareefmvl007@[Link])
41. OMP path selection behavior
42. OMP timers and graceful restart
43. OMP route advertisement and withdrawal
44. TLOC extension
45. Service chaining basics
46. Integrated ZBFW (zone-based firewall) overview
47. URL filtering overview
48. IPS/IDS overview
49. Local policies vs centralized policies
50. Policy attachments and sequencing
51. Role-Based Access Control (RBAC) in vManage
52. Audit logs and configuration history
53. Software image repository and management
54. Device upgrades and maintenance windows
55. vManage backups and restore
56. High availability for branches
57. Dual-WAN edge designs
58. Hub-and-spoke topologies
59. Full-mesh topologies
60. Regional hub designs

Stage 3 – Advanced (Policies, Performance & QoS)


61. Centralized data policy
62. Centralized control policy
63. App-route policy
64. Localized policy
65. SLA class definitions (loss, latency, jitter)
66. Dynamic Path Selection (DPS)
67. Application lists and NBAR2 identification
68. Per-application traffic steering
69. Packet duplication
70. Forward Error Correction (FEC)
71. Jitter buffering and brownout handling
72. Path preference and color affinity
73. ECMP and load balancing
74. Per-VPN QoS models
75. Queuing, shaping, policing on WAN edge
76. QoS trust boundaries
77. DSCP/CoS remarking strategies
78. MTU/MSS and fragmentation handling
79. TCP optimization and app acceleration
80. Cloud QoE optimization for SaaS
81. On-Ramp to SaaS (probing and path selection)
82. On-Ramp to IaaS (AWS/Azure/GCP)
83. Cloud hubs and colocation hubs
84. Service insertion to NGFW/LB
85. BGP on service VPNs (PE-CE)
86. OSPF on service VPNs

August 17, 2025 21


Created by Sherif (shareefmvl007@[Link])
87. Static routing design patterns
88. Route leaking between service VPNs
89. Inter-VRF communication policies
90. Multicast over SD-WAN basics
91. Multicast control-plane options
92. IPv6 support in SD-WAN
93. Dual-stack design considerations
94. MPLS coexistence and hybrid WAN
95. DIA with local breakout security stack
96. DNS policies and resolution strategies
97. NAT policies (static, dynamic, PAT)
98. Firewall zones and policy order of operations
99. URL category updates and handling
100. IPS signature lifecycle and updates

Stage 4 – Expert (Security, Automation, Analytics & Scale)


101. End-to-end encryption key management
102. Certificate revocation and renewal workflows
103. Controller plane security hardening
104. WAN edge hardening best practices
105. Integration with Umbrella DNS security
106. SIG/secure web gateway integration
107. ZTNA integration models
108. CASB/SWG service chaining options
109. SD-WAN as part of SASE fabric
110. API fundamentals in vManage
111. Automation with Ansible
112. Automation with Python/SDK
113. CI/CD for SD-WAN policy deployments
114. Infrastructure as Code patterns
115. Webhooks and event-driven automation
116. Telemetry streaming (model-driven)
117. IPFIX/Cflowd/app telemetry
118. vAnalytics dashboards and KPIs
119. SLA reporting and historical trends
120. Anomaly detection and alert tuning
121. Capacity planning using analytics
122. SIEM integration and SOC workflows
123. Compliance and audit reporting
124. Multi-tenant MSP designs
125. Large-scale template strategy
126. Controller scale limits and planning
127. Control-plane scaling and sizing
128. Data-plane throughput considerations
129. Device platform selection and sizing
130. Brownfield migration strategies (IWAN to SD-WAN)
131. Coexistence with legacy WAN during migration
132. Rollback and golden-config strategies

August 17, 2025 22


Created by Sherif (shareefmvl007@[Link])
133. Change windows and blast radius control
134. Blue/green policy deployments
135. Staged rollout with canary sites
136. Disaster recovery for controllers
137. Regionally distributed controllers
138. Cloud-only branch designs
139. 5G/LTE primary WAN designs
140. SD-WAN for mobile/temporary sites
141. IoT edge segmentation with SD-WAN
142. Industrial SD-WAN considerations
143. Retail and POS segmentation patterns
144. Healthcare and compliance-driven designs
145. Financial low-latency considerations
146. App segmentation by business unit
147. Multi-domain policy governance
148. Interop with SD-Access campus fabrics
149. Data center integration with ACI
150. Internet offload vs backhaul design tradeoffs

Stage 5 – Troubleshooting & Case Studies (Deep-Dive)


151. Control connection down scenarios
152. OMP adjacency issues
153. BFD session flaps
154. Data-plane tunnel instability
155. SLA violation triage
156. App recognition misclassification
157. Policy hit/miss verification
158. Asymmetric routing detection
159. MTU/MSS black-hole issues
160. NAT traversal failures
161. Certificate enrollment failures
162. Controller CPU/memory saturation
163. Template attachment failures
164. Device upgrade failures and rollbacks
165. Cloud On-Ramp provisioning failures
166. Multicast overlay troubleshooting
167. QoS queue starvation analysis
168. Packet duplication overhead analysis
169. FEC effectiveness analysis
170. IPS/URL feature performance impacts
171. DIA breakout misroutes
172. DNS resolution troubleshooting
173. ZTP onboarding failures
174. Serial-file/whitelist mismatches
175. Policy order and precedence issues
176. RBAC privilege anomalies
177. Config drift detection and remediation
178. Log correlation across controllers and edges

August 17, 2025 23


Created by Sherif (shareefmvl007@[Link])
179. Time sync/NTP issues impact
180. Case studies: regional outage response

Stage 6 – Strategy & Future Direction


181. Intent-based SD-WAN policy design
182. Business intent translation to policy objects
183. AI/ML-assisted path selection
184. Proactive remediation and auto-tuning
185. Sustainability and power/space planning
186. Cost optimization across transports
187. Contract and SLA negotiation inputs from analytics
188. SD-WAN lifecycle governance
189. Vendor interoperability strategy
190. Roadmap to SASE convergence
191. Zero-touch branch of the future
192. Edge compute integration with SD-WAN
193. API-first operations culture
194. Continuous validation and testing
195. Security posture scoring and reporting
196. Executive dashboards and outcomes mapping
197. RFP checklists for SD-WAN solutions
198. Proof-of-Concept validation plans
199. Runbooks and operational playbooks
200. Post-incident reviews and improvements

Linux, Python & Network


Automation
Stage 1 – Linux Fundamentals (Beginner)
1. What is Linux? Kernel vs Distribution
2. Linux directory structure (/etc, /var, /usr, /home, /opt)
3. Linux shell basics (bash, zsh, sh)
4. File system navigation (ls, pwd, cd)
5. File operations (cp, mv, rm, touch, cat, less, head, tail)
6. Directory operations (mkdir, rmdir, tree)
7. File permissions (rwx, chmod, chown, chgrp)
8. File ownership and groups
9. File attributes (ls -l, hidden files)
10. Links in Linux (hard link, soft link)
11. Process basics (ps, top, htop)
12. Background/foreground jobs (fg, bg, jobs, kill)

August 17, 2025 24


Created by Sherif (shareefmvl007@[Link])
13. System monitoring (uptime, free, df, du)
14. User management (useradd, usermod, passwd, who, id)
15. Group management (groupadd, groups)
16. Switching users (su, sudo)
17. Environment variables (echo $PATH, export)
18. Editors (nano, vim, vi)
19. Package management (apt, yum, dnf, zypper)
20. Services (systemctl, service)

Stage 2 – Linux Networking Basics


21. IP configuration (ifconfig, ip addr)
22. Routing table (route, ip route)
23. Hostname and DNS resolution (/etc/hosts, /etc/[Link])
24. Checking connectivity (ping, traceroute, mtr)
25. Port checks (netstat, ss, lsof -i)
26. TCP vs UDP basics
27. Firewall basics (iptables, ufw, firewalld)
28. SSH basics (ssh, scp, sftp)
29. SSH key-based authentication (ssh-keygen, authorized_keys)
30. Secure file transfer between devices
31. Understanding MTU, ARP, MAC addresses
32. TCP 3-way handshake recap
33. Packet capture (tcpdump, wireshark)
34. Network performance testing (iperf3)
35. Proxy configuration and curl/wget usage

Stage 3 – Linux Scripting & Automation


36. Introduction to shell scripting (#!/bin/bash)
37. Variables in shell scripts
38. Conditional statements (if, else, elif)
39. Loops (for, while, until)
40. Functions in bash
41. Reading input (read)
42. Command substitution ($())
43. String manipulation in bash
44. Arrays in bash
45. Exit codes ($?)
46. Cron jobs and scheduling
47. System logs (/var/log)
48. Using awk, sed, grep for text parsing
49. Creating simple automation scripts (backup, monitoring, alerts)
50. Secure shell automation (sshpass, expect)

August 17, 2025 25


Created by Sherif (shareefmvl007@[Link])
Stage 4 – Python Fundamentals (Beginner)
51. Python installation & virtual environments
52. Python REPL and script execution
53. Data types: int, float, str, bool
54. Variables and constants
55. Strings and string methods
56. Lists and list methods
57. Tuples
58. Dictionaries
59. Sets
60. Type conversion and casting
61. Operators (+, -, *, /, //, %)
62. Conditional statements (if, elif, else)
63. Loops (for, while)
64. Functions (def, return values, parameters)
65. Scope (local, global variables)
66. Exception handling (try/except/finally)
67. File I/O (open, read, write, close)
68. Modules and imports
69. Python standard libraries overview (os, sys, json, re, datetime)
70. Virtual environments (venv, pipenv)

Stage 5 – Python Advanced Concepts


71. Object-Oriented Programming (OOP)
72. Classes and Objects
73. Inheritance
74. Polymorphism
75. Encapsulation
76. Decorators
77. Generators
78. Iterators
79. Lambda functions
80. List comprehensions
81. Dictionary comprehensions
82. Context managers (with)
83. Logging in Python
84. Unit testing (unittest, pytest)
85. Type hinting and annotations
86. Multi-threading
87. Multi-processing
88. Asyncio basics (async/await)
89. REST API consumption (requests)
90. Data parsing (JSON, XML, YAML)

August 17, 2025 26


Created by Sherif (shareefmvl007@[Link])
Stage 6 – Python for Networking
91. Netmiko basics (SSH automation)
92. Paramiko basics (SSH library)
93. NAPALM for device interaction
94. pyATS and Genie for testing & parsing
95. RESTCONF basics in Python
96. NETCONF with ncclient
97. gNMI with Python clients
98. YAML + Python (for configs)
99. Jinja2 templating (config generation)
100. CSV/Excel parsing with Python (csv, openpyxl)
101. Database interaction (sqlite3, PostgreSQL)
102. SNMP automation (pysnmp)
103. Socket programming basics
104. Telnetlib for legacy devices
105. Multi-vendor automation examples (Cisco, Juniper, Arista)

Stage 7 – Ansible for Network Engineers


106. Ansible basics (YAML, inventory)
107. Static vs dynamic inventory
108. Ad-hoc commands
109. Ansible Playbooks
110. Variables in playbooks
111. Conditionals and loops
112. Ansible roles and tasks
113. Templates (Jinja2)
114. Ansible facts collection
115. Ansible Vault (secrets management)
116. Error handling in Ansible
117. Ansible Galaxy collections
118. Network modules (ios_config, nxos_config, junos_config)
119. Ansible with REST API calls
120. Playbook execution strategies (serial, free, batch)

Stage 8 – Network Automation Use Cases


121. Configuration backup scripts
122. Configuration push scripts
123. Network device onboarding automation
124. Bulk VLAN provisioning
125. Interface shutdown/no-shutdown automation
126. IP address management automation
127. ACL/Firewall rule deployment
128. Routing configuration automation

August 17, 2025 27


Created by Sherif (shareefmvl007@[Link])
129. SNMP config automation
130. NTP config automation
131. Syslog config automation
132. Automating software upgrades on devices
133. Golden config compliance checks
134. Config audit and drift detection
135. Parsing “show” commands into structured data
136. Automated topology discovery
137. Network performance monitoring with scripts
138. Auto-remediation workflows (restart BGP if down)
139. API-based automation for SD-WAN controllers
140. ChatOps integration (Slack/Teams alerts)

Stage 9 – Advanced Tools & Ecosystem


141. Git for version control
142. GitHub/GitLab workflows
143. CI/CD basics (Jenkins, GitHub Actions)
144. Docker basics (containers for lab environments)
145. Kubernetes basics (for scaling automation)
146. Infrastructure as Code (IaC) concept
147. Terraform basics for networking
148. SaltStack for config management
149. Nornir (Python automation framework)
150. Batfish for network validation
151. PyEZ for Juniper automation
152. ACI toolkit for Cisco ACI
153. Automation for NSO (Cisco NSO)
154. SDN controllers automation (OpenDaylight, ONOS)
155. Cloud automation basics (AWS/GCP/Azure networking)
156. Using APIs for public cloud networking
157. Grafana/Prometheus for network metrics
158. ELK stack for log analysis
159. Security automation (block malicious IPs via script)
160. Network simulation (EVE-NG, GNS3 with automation)

Stage 10 – Expert Level Automation Concepts


161. Zero-touch provisioning (ZTP)
162. Event-driven automation (triggers from syslog/SNMP)
163. Closed-loop automation (self-healing networks)
164. Intent-based networking (IBN)
165. Digital twin modeling of networks
166. Network analytics with ML/AI
167. Using Python for anomaly detection
168. Streaming telemetry (gRPC, gNMI, Kafka)
169. Automating QoS policies

August 17, 2025 28


Created by Sherif (shareefmvl007@[Link])
170. Automating traffic engineering (MPLS TE, SR-TE)
171. Policy-based automation
172. Multi-domain automation (DC + WAN + Cloud)
173. Workflow orchestration (StackStorm, Ansible Tower, AWX)
174. DevNet certifications track for automation
175. Automated compliance with security standards (PCI, HIPAA)
176. Automated inventory discovery & update in CMDB
177. Using Python/Ansible for disaster recovery testing
178. Auto-ticketing integrations (ServiceNow, Jira)
179. Automated rollback after failed config push
180. Closed-loop SD-WAN monitoring & healing

Stage 11 – Linux Advanced for Automation


181. Advanced permissions (ACLs, sticky bits, SUID, SGID)
182. SELinux/AppArmor basics
183. System monitoring with sar, dstat, iotop
184. Process management (nice, renice)
185. Kernel tuning (sysctl)
186. Log rotation (logrotate)
187. Networking performance tuning (TCP windows, buffers)
188. Sockets and IPC in Linux
189. System security hardening basics
190. Linux containers (LXC vs Docker)
191. Using Python + Linux CLI together
192. Shell & Python hybrid scripts
193. Linux networking namespaces
194. VRFs in Linux for lab testing
195. Building a Linux-based router/firewall lab

Stage 12 – Final Expert Use Cases for Network Engineers


196. Automated failover between ISPs
197. Building a custom network monitoring dashboard
198. Automating NetFlow/sFlow data collection
199. Automating BGP peering config updates
200. Automated prefix-list updates from RPKI feeds
201. Automating DDOS mitigation (blackhole routing)
202. Multi-cloud networking automation with APIs
203. Automating VXLAN EVPN fabric configs
204. End-to-end service provisioning automation
205. API-driven provisioning of VPN tunnels
206. AI-assisted troubleshooting bots for networks
207. Infrastructure drift detection & reconciliation
208. Automated golden baseline validation before/after change
209. Integration with CI/CD pipelines for config testing
210. Building custom Ansible modules in Python

August 17, 2025 29


Created by Sherif (shareefmvl007@[Link])

You might also like