Learning networking is not about memorizing ports, acronyms, or commands. A system administrator needs to understand what happens to a packet from the moment an application sends it until it reaches its destination, where that path can fail, and how to prove what is happening.
This guide is a networking-from-scratch roadmap for future sysadmins. You can read it as an introduction, but it is designed primarily as a study plan: every stage builds on the previous one and ends with concrete skills you should be able to demonstrate before moving on.
You do not need enterprise hardware to begin. A computer, Linux, a few virtual machines, and tools such as Wireshark, VirtualBox, KVM, or Proxmox VE are enough to build an excellent lab.
| Stage | Goal |
|---|---|
| 0. Build a lab | Linux, terminal, virtual machines, and basic binary concepts. |
| 1. Physical and Ethernet | NICs, copper/fiber, MAC, switching, Wi‑Fi, speed, duplex, MTU. |
| 2. IP addressing | IPv4, IPv6, CIDR, subnetting, gateways, ARP, and NDP. |
| 3. Transport | TCP, UDP, ICMP, ports, sockets, state, and TLS. |
| 4. Services | DNS, DHCP, NTP, HTTP(S), SSH, mail, SMB/NFS, and directory services. |
| 5. Switching | VLANs, access/trunk ports, STP/RSTP, LACP, Layer 2 security. |
| 6. Routing | Routing tables, static routes, OSPF, BGP concepts, NAT/PAT. |
| 7. Security | Stateful firewalls, ACLs, segmentation, VPNs, secure administration. |
| 8. Linux sysadmin | iproute2, NetworkManager, resolvectl, ss, nftables, tcpdump. |
| 9. Virtualization and cloud | Bridges, vNICs, TAP/TUN, namespaces, containers, VXLAN. |
| 10. Observability | Logs, SNMP, metrics, flows, packet capture, capacity. |
| 11. Troubleshooting | A reproducible method from physical layer to application. |
| 12. Automation | Git, Ansible, APIs, Python, and network as code. |
Networking becomes much easier when you can observe packets and intentionally break things. Start with a small lab.
tcpdump inside the VMs.You do not need to master Linux first, but you should be comfortable with the shell, files, permissions, processes, services, and a text editor.
Move on when: you can create two VMs on the same network, identify their interfaces, and verify connectivity between them.
Before IP, understand what actually carries the bits: copper, fiber, and radio.
A NIC connects a host to the network medium. Modern Ethernet normally auto-negotiates speed and duplex, but negotiation problems can still produce loss and poor throughput.
The MTU is the largest unit that can cross a link without fragmentation. Ethernet commonly uses 1500 bytes, while tunnels and VPNs reduce the space available for the original packet. MTU problems can create confusing symptoms where ping works but some sites or transfers stall.
Ethernet moves frames inside a Layer 2 domain. Switches learn which MAC addresses appear behind which ports and use that table to forward traffic efficiently.
Understand unicast, broadcast, and multicast, and remember that basic switching decisions are based on MAC addresses, not IP routing.
Move on when: you can explain what a switch learns, what a MAC address is, what MTU means, and why two hosts on the same LAN do not need a router to communicate.
IP addressing and routing are core sysadmin skills because almost every service depends on them.
For example, 192.168.10.34/24 belongs to 192.168.10.0/24. A /24 reserves 24 bits for the network and leaves 8 bits for addresses within that network.
Starting from 192.168.10.0/24, four equal-size subnets can be created using /26:
Each block contains 64 addresses. Traditional IPv4 subnets reserve network and broadcast addresses, with special cases for certain point-to-point designs.
fe80::/10.::1.IPv4 uses ARP to discover the MAC address associated with a local IPv4 address. IPv6 uses Neighbor Discovery Protocol, based on ICMPv6, for neighbor and router discovery.
Move on when: you can determine whether two hosts are in the same subnet, calculate several IPv4 subnet sizes, explain the role of the default gateway, and recognize IPv6 link-local and global addresses.
ICMP is more than ping. It carries network control information such as unreachable destinations, time exceeded, and MTU-related conditions. ICMPv6 is fundamental to normal IPv6 operation.
UDP sends datagrams without a TCP-style connection and does not guarantee delivery, ordering, or retransmission. Reliability can be implemented by the application when needed. DNS, voice, video, and QUIC are common examples where UDP may be part of the solution.
ss -tulpn
ss -tan
ss -uan Move on when: you can explain why one server IP can simultaneously provide SSH, HTTPS, and DNS, and identify an established TCP connection in ss.
DNS is a distributed database. Learn recursive versus authoritative resolution and records such as A, AAAA, CNAME, MX, NS, PTR, TXT, and SRV.
dig universodigital.org
dig A universodigital.org
dig AAAA universodigital.org
dig MX example.com
dig +trace example.com DHCPv4 can provide addressing, gateway, DNS, and other parameters. Learn the DORA flow—Discover, Offer, Request, Acknowledge—and understand leases, reservations, scopes, and DHCP relay.
Correct time is infrastructure. TLS, Kerberos, logs, clusters, and event correlation all become harder or unreliable when clocks drift.
Move on when: when a service “does not open,” you can separate DNS, IP reachability, routing, firewalling, listening port, and application behavior.
A VLAN creates an independent Layer 2 broadcast domain on shared infrastructure. An access port normally carries one VLAN for an endpoint, while a trunk can carry multiple VLANs using IEEE 802.1Q tags.
Hosts in different VLANs require routing to communicate. VLANs segment Layer 2; they do not replace a firewall.
Layer 2 loops can create broadcast storms and unstable MAC tables. Spanning Tree Protocol and its variants block redundant paths to keep Ethernet topologies loop-free.
LACP can bundle physical links into one logical interface when both ends support it. This can add redundancy and spread flows, but a single TCP flow does not automatically gain the sum of all member-link speeds.
Managed networks may use DHCP snooping, Dynamic ARP Inspection, RA Guard, port security, and storm control. Current CCNA objectives include these topics because Layer 2 mistakes and attacks can affect both security and availability.
Move on when: you can design user, server, and management VLANs and explain where inter-VLAN traffic is routed and filtered.
ip route
ip -6 route
ip route get 1.1.1.1 Learn connected routes, static routes, default routes, dynamically learned routes, metrics, and longest-prefix matching.
Start with static routing. Then learn OSPF to understand an interior routing protocol. Study BGP later as the protocol used to exchange reachability between autonomous systems and as a core part of Internet routing.
NAT rewrites addresses. PAT lets many private IPv4 hosts share one public IPv4 address by differentiating flows with ports. NAT is not a firewall, even when both functions run on the same device.
Move on when: you can read a routing table and predict which gateway or interface will be used for several destinations.
A modern firewall normally tracks connection state. Think in terms of source, destination, protocol, port, direction, and state—not simply “open port 443.”
Apply least privilege: expose only what is required and separate trust zones when risks differ.
WireGuard, IPsec, and OpenVPN can create protected tunnels for remote access or site-to-site connectivity. Learn routing, DNS, and MTU behavior inside tunnels as well as encryption.
For practice, see our pfSense introduction.
ip -br link
ip -br addr
ip addr show ip route
ip route get 1.1.1.1
ip -6 route ip neigh ss -tulpn
ss -tanp resolvectl status
resolvectl query universodigital.org
dig universodigital.org Many Linux distributions use NetworkManager. Red Hat documents nmcli and nmtui for administration, including headless systems.
nmcli device status
nmcli connection show
nmcli -f GENERAL,IP4,IP6 device show ethtool eth0 sudo tcpdump -ni any
sudo tcpdump -ni eth0 port 53
sudo tcpdump -ni eth0 host 192.168.1.50 Wireshark can open pcap and pcapng captures and dissect protocols visually. Being able to read a simple packet capture is one of the most useful sysadmin troubleshooting skills.
iperf3 -s
iperf3 -c SERVER_IP Modern Linux administrators should understand nftables and Netfilter connection tracking. Distribution tools such as firewalld or UFW can simplify policy management, but knowing the underlying model remains valuable.
Move on when: you can repair VM networking, identify which process listens on a port, test DNS, inspect the routing decision, and capture packets for a failing connection.
Modern sysadmins work with virtual interfaces as often as physical ones.
A Linux bridge behaves conceptually like a software switch. Hypervisors such as KVM and Proxmox VE attach VM interfaces to bridges, VLANs, and physical networks.
Docker, Podman, and Kubernetes build virtual networks, bridges, NAT, and policy on top of these fundamentals. Learn routing, NAT, DNS, and namespaces before diving deeply into Kubernetes networking.
VXLAN and other overlays can carry Layer 2-like segments across Layer 3 networks. Study them after you are comfortable with VLANs and routing.
Our Proxmox VE articles provide practical scenarios for bridges, VLANs, and VM networking.
SNMP, syslog, Prometheus/Grafana, Zabbix, LibreNMS, and similar platforms can provide visibility. The specific product matters less than learning to establish a baseline and detect deviations.
A 1 Gbit/s link can feel worse than a 100 Mbit/s link for interactive traffic when latency, jitter, or loss are high.
ip link.ip addr.ip neigh.ip route get DESTINATION.dig.ss.Ping is useful, but do not turn it into the only test. A host may block ICMP Echo and still serve HTTPS, while a successful ping proves nothing about DNS, TCP 443, TLS, or the application.
| Tool | Purpose |
|---|---|
| ip | Interfaces, addresses, neighbors, and routes. |
| ping | Basic ICMP reachability and latency. |
| tracepath / traceroute | Path and hops to a destination. |
| mtr | Observed latency and loss along a path. |
| dig | DNS queries and troubleshooting. |
| ss | Sockets and listening ports. |
| tcpdump | Command-line packet capture. |
| Wireshark | Detailed packet analysis. |
| ethtool | Ethernet link state and features. |
| iperf3 | Point-to-point performance testing. |
| nft | nftables/Netfilter rules. |
| curl | HTTP/HTTPS and application-layer tests. |
| openssl s_client | Basic TLS and certificate troubleshooting. |
Learn to automate only after you understand the manual operation. Automating something you do not understand simply lets you make mistakes faster.
Modern professional networking objectives increasingly include controller-based management, APIs, automation, and infrastructure as code. CLI skills remain important, but network operations are progressively becoming software-driven.
Certifications such as CCNA or CompTIA Network+ can help organize your learning, but they are not a replacement for a lab. Use their objectives as checklists rather than as the boundary of what you should understand.
You do not need every RFC memorized. You have a solid base when someone says “the server cannot be reached from another VLAN” and you can form a logical sequence of questions: does it have the right address and prefix, is there a gateway, does the route exist, does ARP/NDP work, does the firewall allow the flow, is the service listening, does DNS point to the right place, and what does the packet capture show?
That transition—from trying random fixes to reasoning about the traffic path—is the real objective of learning networking for systems administration.
History and architecture of Evelyn Berezin’s United Airlines reservation system, distinguishing it from the earlier…
Biography of Evelyn Berezin: systems designer behind an early United Airlines reservation system and founder…
Step-by-step guide to installing Nextcloud 35 on Ubuntu Server 24.04 LTS with Apache, MariaDB, PHP…
Step-by-step guide to installing WordPress on Ubuntu Server 24.04 LTS with Apache, MySQL 8.0, PHP…
What Delphi is in 2026: Object Pascal, VCL and FireMonkey, supported platforms, Community Edition, commercial…
What a web browser is, how it works, its history, Blink, Gecko and WebKit engines,…