
Practical Network Security, Firewalls, IPSec, SSH, TLS, Scanning, and Wi-Fi Security
2-Day Instructor-Led Hands-On Lab Class
Available in either Web-Based Delivery or On-Site Delivery
Minimum 10 students – Maximum 16 students
Course Description
Network security is an essential skill for anyone responsible for designing, operating, supporting, testing, or troubleshooting IP networks.
CSI-HO-029 – Hands-On Security in IP Networks/Protocols is a practical two-day course that helps technicians and engineers understand common network vulnerabilities, security technologies, attack methods, and mitigation techniques.
The course combines technical explanation with hands-on exercises and demonstrations using Linux-based systems and network-analysis tools.
Students examine security from several perspectives, including:
- Common security terminology and threats
- Attack types and vectors
- Personal security and social engineering
- Firewalls and intrusion detection
- Network scanning
- Layer 2 and Layer 3 security
- IPSec and VPN security
- Encryption and key exchange
- SSH
- HTTPS and TLS
- Packet-generation and testing tools
- ARP spoofing
- Wireless security
The emphasis is on understanding what the threat is, how it affects the network, what evidence may reveal it, and what can be done to reduce the risk.
Why Network Security Skills Matter
Security is not separate from networking.
Every security control operates within a network architecture, protocol stack, application, device, or communications path.
Network professionals therefore need to understand questions such as:
- What is being protected?
- Where is the vulnerability?
- What does the attack attempt to exploit?
- What information can an attacker observe or manipulate?
- Which security mechanism can reduce the risk?
- How does encryption change what can be observed on the network?
A strong networking foundation combined with practical security knowledge helps technicians and engineers recognize risks and make better operational decisions.
Course Objectives
Upon completion of this course, students will be able to:
- Explain fundamental network-security terminology.
- Identify common security vulnerabilities and attack vectors.
- Understand the concepts of confidentiality, integrity, and availability.
- Recognize common malware and social-engineering risks.
- Explain the role of firewalls and intrusion-detection technologies.
- Understand network scanning and reconnaissance concepts.
- Explain common Layer 2 and Layer 3 security risks.
- Describe the purpose and operation of IPSec.
- Explain the roles of AH and ESP.
- Understand IPSec tunnel and transport modes.
- Explain the purpose of Internet Key Exchange.
- Understand fundamental encryption concepts.
- Differentiate symmetric and asymmetric encryption.
- Explain hashing and its security applications.
- Describe how SSH provides secure remote communications.
- Explain the role of HTTPS and TLS.
- Understand the purpose of digital certificates.
- Use packet analysis to examine secure communications.
- Understand how network-security testing tools can help reveal protocol behavior and vulnerabilities.
- Recognize common ARP-related and wireless-security risks.
- Identify practical techniques for mitigating network-security vulnerabilities.
The emphasis throughout the course is on connecting security concepts with real network behavior.
Security Through a Network Engineer’s Eyes
Security becomes easier to understand when it is examined through the protocols and technologies already operating on the network.
For example:
- A firewall controls which communications are permitted.
- IPSec protects IP communications.
- SSH protects remote administrative sessions.
- TLS protects application communications.
- Encryption protects information from unauthorized observation.
- Network scanning reveals systems and services that may be reachable.
- ARP attacks demonstrate how weaknesses at one layer can affect communications at another.
Understanding these relationships helps students view security as part of the overall network architecture rather than as a separate technology.
Audience
This course is designed for technical professionals who need practical network-security knowledge.
Ideal participants include:
- Network Engineers
- Broadband and Service Provider Technicians
- Network Operations Center personnel
- Network Administrators
- Network Support personnel
- Network Design Engineers
- Systems Engineers
- Development and Test Engineers
- Network Management personnel
- IT Professionals
- Security personnel who need stronger networking knowledge
- Technical Sales Engineers
- Technical Marketing personnel
- Individuals preparing for networking or security certifications
The course is particularly useful for professionals responsible for operating, supporting, testing, troubleshooting, or securing IP networks.
Course Prerequisites
Students should have a basic understanding of TCP/IP networking, Ethernet, IPv4 addressing, and general network operation.
Previous network-security experience is not required.
Students should be comfortable working with computers and basic networking concepts so the class can concentrate on security technologies and techniques.
Students will use the CellStream Security Lab throughout the course.
Students participating remotely should have a computer capable of connecting to the provided lab environment.
Course Materials
Students receive:
- Course Student Guide
- Hands-On Lab Guide
- Access to the CellStream Security Lab
- Network-security exercises
- Packet-analysis exercises
- Security-tool demonstrations
- IPSec and encryption exercises
- SSH and TLS exercises
- Additional security reference material
Course Outline:
The course outline is as follows:
- Part 1: The Groundwork
- Overview and Introductions
- Introduction/Logistics/Time Frames/Course Plan
- Accessing the Online School content
- LAB: Setting up for the CellStream Security Lab
- Part 2: Introduction to Security
- Security Terminology
- Types of Hackers
- Group Exercise: Where are vulnerabilities in an IP Network?
- Phases in Hacking
- Attack Types and Vectors
- Confidentiality, Integrity, Availability
- Malware, Malware Mitigation, Examples
- Part 3: Personal Security
- Personal Awareness
- Default Username/Passwords
- Personal Security – Social Engineering
- Part 4: Security Appliances
- Firewalls, Types, Functionality, Rules Examples
- Intrusion Detection Systems
- Penetration Detection Systems
- Part 5: Scanning, Attacks and Tools
- Scanning Using ARP – demo
- Scanning with nmap – demo
- Local Network Scan mitigation
- MAC Filtering – bypass demo
- Part 6: Layer 2 and Layer 3 Mitigation
- Layer 2 Mitigation: Overview of PPPoE, why Layer 2
- Layer 3 Mitigation: IPSec for VPN Security
- Overview of IPSec
- AH and ESP Protocols and Message Exchange
- Cryptographic Algorithms
- Tunnel and Transport Modes
- IKE – Internet Key Exchange
- LAB Exercise/Demonstration: IPsec Network View and Packet examination
- Encryption Defined
- Diffie-Helman Encryption example
- Part 7: Layer 5 Mitigation with SSH and HTTPS
- How Does SSH Work?
- Symmetrical and Asymmetrical Encryption
- Hashing
- SSH Process, Authentication
- LAB Exercise/Demonstration: SSH Session Walkthrough and Packet Analysis
- HTTPS Defined
- TLS Version Comparison
- SSL Certificates
- LAB Exercise/Demonstration: HTTPS Process and Decryption Process
- Part 8: Other Security Tools
- Scapy packet manipulator – LAB Exercise/Demonstration
- Hping 3 – LAB Exercise/Demonstration
- ARP Spoofing – LAB Exercise/Demonstration
- Wireless Security – LAB Exercise/Demonstration
- Group Exercise: How can we mitigate security vulnerabilities in an IP Network?
Defense Requires Understanding the Attack
Effective network security requires understanding both sides of the problem.
A technician or engineer needs to understand how legitimate protocols operate—but also how those same protocols may be misused.
- Scanning can reveal exposed systems and services.
- Weak credentials can expose devices.
- Social engineering can bypass technical protections.
- ARP manipulation can affect local communications.
- Unencrypted protocols can expose sensitive information.
- Poorly configured security controls can create a false sense of protection.
This course helps students develop the ability to ask:
- What is the weakness?
- How could it be exploited?
- What evidence would I expect to see?
- What practical mitigation can reduce the risk?
That mindset is an important part of securing and troubleshooting modern IP networks.
Why Take This Course?
Network security can quickly become an overwhelming subject because it includes protocols, applications, devices, operating systems, users, encryption, authentication, and attack techniques.
CSI-HO-029 organizes those subjects around the network.
Students learn how common security mechanisms work, examine potential vulnerabilities, observe security technologies in operation, and connect those concepts to practical mitigation techniques.
The goal is to give networking professionals a stronger understanding of how security affects the networks they already design, operate, and troubleshoot.
Related Training
Students who want to continue developing their network-security and analysis skills may progress into CellStream training covering:
- Advanced IPv4 networking
- IPv6 security
- Wireshark and packet analysis
- Advanced network troubleshooting
- Ethernet
- Wi-Fi networking and troubleshooting
- Routing
- MPLS
Course Availability:
Contact us for schedule dates and times via our contact form or through the details provided on the page.
View the course calendar and browse for our schedule. It will show scheduled courses and available dates for scheduling.
Course Description, Content, Outline, and Instructional Design are Copyright ©CellStream, Inc.

