
Advanced OSPF, IPv4 Quality of Service, Network Security, IPSec, Encryption, and TCP Analysis
2.5-Day Instructor Led Hands-On Lab Class
Available in either Web-Based Delivery or On-Site Delivery
Minimum 10 students – Maximum 16 students
Course Description
Understanding the fundamentals of Ethernet, IPv4, TCP/IP, addressing, subnetting, and routing is essential—but network engineers and technicians responsible for operating and troubleshooting production IP networks need to go deeper.
CSI-HO-006 is designed as the next step after CellStream’s Hands-On TCP/IP and Ethernet Fundamentals training. Students are expected to arrive with a working knowledge of IPv4 networking and router configuration so that the course can move quickly into more advanced network behavior, configuration, analysis, and troubleshooting.
The course concentrates on four major areas of advanced IP networking:
- OSPF routing and control-plane operation
- IPv4 Quality of Service
- IP network security and encryption
- Advanced Transmission Control Protocol behavior
Students go beyond basic definitions and configurations to examine how these technologies actually behave inside operational networks.
Through instructor-led discussion, Cisco router configuration, command-line analysis, packet examination, demonstrations, and hands-on lab exercises, students investigate routing adjacencies, OSPF areas and LSAs, traffic classification and scheduling, policy-based routing, security vulnerabilities, IPSec, SSH, HTTPS/TLS, encryption, and detailed TCP operation.
The goal is to turn a fundamental understanding of TCP/IP into a deeper engineering and troubleshooting skill set.
Students learn not simply how to configure network functions, but how to observe them, verify their operation, analyze their behavior, and determine what the network evidence actually proves.
Building on the Fundamentals
This course is intentionally designed for students who already understand fundamental Ethernet and TCP/IPv4 networking.
CellStream’s 5-day Hands-On TCP/IP and Ethernet Fundamentals course establishes the broad foundation:
Ethernet → ARP → TCP/UDP → IPv4 addressing → subnetting → network services → routing → troubleshooting → security → QoS → advanced networking concepts
CSI-HO-006 then takes selected subjects from that foundation and explores them in substantially greater depth.
Students move from:
- Understanding OSPF → examining OSPF operation, adjacencies, LSAs, and areas
- Understanding QoS → configuring classification, MQC, policing, shaping, scheduling, and policy-based routing
- Understanding network security → examining vulnerabilities, attacks, firewalls, IPSec, encryption, SSH, HTTPS, and security tools
- Understanding TCP → analyzing TCP states, handshakes, segmentation, windows, retransmissions, loss recovery, slow start, and application behavior
This progression allows the advanced course to spend less time reviewing basic networking concepts and more time developing the skills required to analyze and troubleshoot network behavior.
Course Objectives
Upon completion of this course, students will be able to:
- Apply an advanced, hands-on approach to IPv4 network operation and troubleshooting.
- Configure and analyze OSPF routing.
- Explain the OSPF protocol process and control-plane operation.
- Analyze OSPF neighbor and adjacency formation.
- Understand the purpose and application of OSPF Link State Advertisements.
- Explain the purpose and operation of OSPF areas.
- Configure and investigate multi-area OSPF networks.
- Explain the role of Quality of Service in IP networks.
- Identify and select appropriate IP QoS mechanisms.
- Explain traffic classification and packet marking.
- Understand Integrated Services and Differentiated Services concepts.
- Configure and analyze Cisco Modular Quality of Service Command-Line Interface policies.
- Explain the differences between traffic policing and traffic shaping.
- Understand and configure Policy-Based Routing.
- Explain Random Early Detection and Weighted Random Early Detection.
- Compare fundamental packet scheduling techniques including FIFO, WFQ, and CBWFQ.
- Identify common security vulnerabilities within IPv4 networks.
- Explain common attack types and attack vectors.
- Apply confidentiality, integrity, and availability concepts to network security.
- Explain the role of firewalls and network security controls.
- Understand network reconnaissance and scanning techniques.
- Explain the operation and purpose of IPSec.
- Differentiate IPSec Authentication Header and Encapsulating Security Payload.
- Explain IPSec tunnel and transport modes.
- Understand the role of Internet Key Exchange.
- Explain fundamental cryptographic concepts.
- Differentiate symmetric and asymmetric encryption.
- Explain hashing and its role in network security.
- Describe how SSH establishes secure remote communications.
- Explain the fundamental operation of HTTPS and TLS.
- Examine encrypted network sessions using packet-analysis techniques.
- Understand how security and packet-generation tools can be used to investigate network behavior.
- Explain TCP connection establishment and connection states.
- Analyze the TCP three-way handshake.
- Explain TCP sockets and segmentation.
- Understand TCP flow control and sliding-window operation.
- Analyze packet loss and TCP retransmission behavior.
- Explain TCP slow start and its effect on data transfer.
- Describe the purpose and effects of the Nagle algorithm.
- Use configuration information, operational commands, and packet evidence to verify network behavior.
The emphasis throughout the course is on analysis rather than memorization.
Students are continually challenged to determine:
What is the network doing?
Why is it doing it?
How can I verify that?
Audience
CSI-HO-006 is intended for networking professionals who already understand TCP/IP fundamentals and need a deeper operational and troubleshooting skill set.
Ideal participants include:
- Network Engineers
- Broadband Network Engineers and Technicians
- Service Provider Engineers and Technicians
- Network Operations Center personnel
- Network Administrators
- Network Design Engineers
- Network Support Engineers
- Escalation and Tier 2/Tier 3 Support personnel
- Systems Engineers
- Development and Test Engineers
- Network Management personnel
- Security professionals who require a stronger networking foundation
- Technical Sales Engineers
- Technical Marketing personnel
- Individuals pursuing advanced networking certifications
This course is particularly valuable for people responsible for configuring, operating, analyzing, troubleshooting, testing, or supporting production IP networks.
Course Prerequisites
This is not an introductory TCP/IP course.
Students should already have a solid understanding of:
- Ethernet networking
- IPv4 addressing
- IPv4 subnetting
- TCP and UDP fundamentals
- IP routing
- Routing tables
- Basic routing protocol concepts
- Cisco router configuration and command-line operation
Students should have completed CellStream’s CSI-HO-001-C – Hands-On TCP/IP and Ethernet Fundamentals – 5 Day course, an equivalent CellStream TCP/IPv4 fundamentals course, or possess equivalent knowledge and hands-on experience.
The prerequisite is important because CSI-HO-006 assumes students already understand fundamental IP networking and moves directly into advanced configuration, protocol behavior, and analysis.
Students will use a hands-on router lab throughout the course.
Students participating remotely should have a computer capable of connecting to the provided lab environment.
For on-site classes, students should bring a laptop computer unless suitable classroom computers are being provided.
Course Materials
Students receive:
- Course Student Guide
- Hands-On Lab Guide
- Access to the CellStream router lab environment
- OSPF configuration and analysis exercises
- IPv4 Quality of Service exercises
- Network security exercises and demonstrations
- IPSec and encryption exercises
- TCP analysis exercises
- Packet-analysis activities associated with advanced protocol behavior
The combination of instructor explanation, hands-on configuration, demonstrations, operational commands, and packet analysis allows students to examine the same networking concepts from multiple perspectives.
The Advanced Hands-On Approach
At the fundamentals level, students learn what protocols do.
At the advanced level, the more important questions become:
- How does the protocol actually work?
- What happens when something goes wrong?
- What evidence proves the cause of the problem?
CSI-HO-006 emphasizes this deeper level of investigation.
Students configure technologies, generate network behavior, examine router output, analyze protocol exchanges, and use packet-level evidence to connect configuration with actual network operation.
For example, students do not simply learn that OSPF routers form adjacencies. They investigate the OSPF process, adjacency behavior, Link State Advertisements, and areas.
They do not simply learn that QoS prioritizes traffic. They examine classification, marking, policing, shaping, scheduling, MQC, and policy-based routing.
They do not simply learn that encryption protects communications. They examine IPSec, SSH, HTTPS, TLS, cryptographic concepts, authentication, and the effect encryption has on packets traversing the network.
And they do not simply learn that TCP provides reliable transport. They examine handshakes, connection states, segmentation, sliding windows, packet loss, retransmissions, and TCP congestion behavior.
This is the transition from knowing networking concepts to analyzing network behavior.
Course Outline
The course outline is as follows:
- Part 1: The Groundwork
- Overview and Introductions
- Introduction/Logistics/Time Frames/Course Plan
- Accessing the Online School content
- LAB: Setting up for Internetworking with the CellStream Router Lab Network
- Part 2: OSPF in Detail
- OSPF Defined
- Basic OSPF configuration
- LAB: OSPF Configuration Lab
- OSPF Protocol Format and Process
- OSPF Fundamentals Lab
- OSPF Adjancencies
- OSPF Link State Advertisement Types
- OSPF Areas
- LAB: OSPF Areas Experiment
- Part 3: Delivering Quality of Service with IP Networks
- Review of IP QoS Fundamentals
- Define the QoS Tools
- Marking Packets – Classification
- Integrated Services
- Differentiated Services
- LAB Exercise/Demonstration: IP Network QoS Baseline
- Cisco MQC Process
- LAB Exercise/Demonstration: Cisco MQC Configuration
- Policing and Shaping
- Policy Based Routing
- LAB Exercise/Demonstration: PBR in an IP Network
- Commited Access Rate
- LAB Exercise/Demonstration: CAR in an IP Network
- Random Early Detection (RED)
- Weighted Random Early Detection (WRED)
- Scheduling
- FIFO
- WFQ
- CBWFQ
- Part 4: Security in IPv4 Networks
- Security Terminology
- Types of Hackers
- Group Exercise: Where are vulnerabilities in an IP Network?
- Phases in Hacking
- Attack Types and Vectors
- Confidentiality, Integrity, Availability
- Malware, Malware Mitigation, Examples
- Personal Awareness
- Default Username/Passwords
- Personal Security – Social Engineering
- Firewalls, Types, Functionality, Rules Examples
- Instrucion Detection Systems
- Penetration Detection Systems
- Scanning, Attacks and Tools
- Scanning Using ARP – demo
- Scanning with nmap – demo
- Local Network Scan mitigation
- MAC Filtering – bypass demo
- Layer 2 Mitigation: PPPoE
- Overview of PPPoE, why Layer 2
- Layer 3 Mitigation: IPSec for VPN Security
- Overview of IPSec
- AH and ESP Protocols and Message Exchange
- Cryptographic Algorithms
- Tunnel and Transport Modes
- IKE – Internet Key Exchange
- LAB Exercise/Demonstration: IPsec Network View and Packet examination
- Encryption Defined
- Diffie-Helman Encryption example
- Layer 5 Mitigation with SSH and HTTPS
- How Does SSH Work?
- Symmetrical and Asymmetrical Encryption
- Hashing
- SSH Process, Authentication
- LAB Exercise/Demonstration: SSH Session Walkthrough and Packet Analysis
- HTTPS Defined
- TLS Version Comparison
- SSL Certificates
- LAB Exercise/Demonstration: HTTPS Process and Decryption Process
- Other Tools
- Scapy packet manipulator – LAB Exercise/Demonstration
- Hping 3 – LAB Exercise/Demonstration
- ARP Spoofing – LAB Exercise/Demonstration
- Wireless Security – LAB Exercise/Demonstration
- Group Exercise: How can we mitigate security vulnerabilities in an IP Network?
- Part 5: Understanding Transmission Control Protocol
- TCP Protocol Characteristics, Format
- TCP Connection States
- Three-Way-Handshake
- TCP Sockets
- TCP Segmentation
- LAB: TCP Three-Way Handshake
- Flow Control, Sliding Windows
- Packet Loss, Re-transmission & TCP Slow Start
- Nagle Algorithm
- LAB: TCP Sliding Windows Lab
Why Take This Course?
Network problems become more difficult as engineers move beyond basic connectivity.
A router can have IP connectivity while OSPF adjacency formation is failing.
Traffic can successfully reach a destination while application performance remains poor because of congestion, loss, or TCP behavior.
A QoS policy can exist in the configuration while failing to classify or treat the intended traffic correctly.
Encrypted traffic can provide confidentiality while significantly changing what network engineers can observe and troubleshoot.
A security mechanism can protect one portion of a communications path while leaving another portion exposed.
Advanced troubleshooting therefore requires something more than knowing configuration commands.
It requires understanding protocol behavior, network state, packet evidence, and the interaction between technologies.
CSI-HO-006 develops those skills through advanced study combined with hands-on configuration and analysis.
From Fundamentals to Advanced Network Engineering
The relationship between the two courses can be summarized simply: CSI-HO-001-C – Hands-On TCP/IP and Ethernet Fundamentals
Build the foundation. Learn how Ethernet, TCP/IP, IPv4 addressing, subnetting, network services, routing, security, QoS, and related networking technologies fit together.
This course: CSI-HO-006 – Hands-On Advanced IP Networks/Protocols Go deeper.
Analyze OSPF, advanced IPv4 QoS, network security, encryption, IPSec, SSH, HTTPS/TLS, and TCP behavior through configuration, experimentation, and packet-level analysis.
Together, the courses provide a progression from networking fundamentals to advanced IP network analysis and troubleshooting.
Related Training
Students completing CSI-HO-006 may continue into more specialized CellStream training in areas such as:
- Advanced IPv6
- Wireshark and advanced packet analysis
- Advanced network troubleshooting
- Routing technologies
- MPLS
- Ethernet networking
- Network security
- Voice over IP
- Wi-Fi networking and troubleshooting
The advanced protocol analysis and troubleshooting skills developed in this course also provide a strong foundation for more specialized network engineering responsibilities and industry certification study.
Course Availability:
Contact us for schedule dates and times via our contact form or through the details provided on the page.
View the course calendar and browse for our schedule. It will show scheduled courses and available dates for scheduling.
Course Description, Content, Outline, and Instructional Design are Copyright ©CellStream, Inc.

