A complete engineering resource for enterprise network design professionals. Covers campus and data-center network architecture, structured cabling per TIA-568, wireless network design (802.11), PoE budget planning, VLAN/IP addressing schemes, and low-voltage systems integration including access control and CCTV.
Built for network engineers, low-voltage designers, IT infrastructure managers, and networking certification candidates. Covers the structured cabling and network segmentation practices used in commercial and campus deployments.
VLAN design, IP addressing, WAN sizing, QoS (DSCP), security architecture, cable schedule (TIA-568), rack diagram, equipment BOM, and design package.
Enterprise campus and data-center topology, SD-WAN, firewall zoning, IPAM, capacity modeling, redundancy planning, and full design package.
Campus access-layer wizard that generates real per-vendor CLI configuration (Cisco Catalyst, Aruba CX, Juniper EX) for VLANs, PoE, and trunking, plus a device recommendation and equipment BOM.
Full topology builder: drag-and-drop routers and switches; run OSPF SPF (multi-area, O IA), IS-IS (L1/L2/L1L2 multi-area), BGP (eBGP/iBGP, Route Reflectors, best-path), MPLS LDP, SR-MPLS (Node-SID/Adj-SID/LFIB), SRv6, SR-TE explicit paths (segment lists → label stacks), MPLS L3VPN with VRF and Route Targets, and EVPN/VXLAN (Type-2 MAC/IP + Type-5 prefix, VTEP discovery). Realistic CLI for all protocols. Supports Cisco, Juniper, Arista, Nokia.
Toggle link and device failures across a three-tier core/distribution/access topology with optional dual paths. Computes end-to-end availability, downtime/yr, and whether connectivity survives using series/parallel reliability math.
Set link capacity and per-class offered traffic (voice/video/data) with DSCP priorities. Strict-priority scheduling shows per-class throughput, drops, and latency as the link saturates and oversubscribes.
Define VLAN segments with host counts and watch VLSM allocate non-overlapping subnets from a /16 block. Visualizes address blocks, usable hosts, and address waste with a live allocation table.
Step through an ARP broadcast request, unicast reply, and cache update across a 4-host LAN segment. Shows the switch flooding the broadcast, a bystander host discarding it, and the ARP cache filling in.
Animate flood-then-learn switch behavior frame by frame across a 4-port switch. Watch the MAC address table fill in and unknown-unicast flooding disappear as traffic converges to clean single-port forwarding.
Animate a full recursive DNS lookup — client, resolver, root, TLD, and authoritative server — with each hop's role labeled. Includes a DHCP DORA (Discover/Offer/Request/Ack) lease-assignment mode.
Step through the TLS handshake message by message, comparing the streamlined 1-RTT TLS 1.3 flow against the older 2-RTT TLS 1.2 flow with a plain-language explanation of each message.
Watch Spanning Tree Protocol elect a root bridge by lowest Bridge ID and block redundant links across 4 switches with 2 loops. Click any link to fail/restore it and see RSTP reconverge in real time.
Send the same request stream through round-robin, weighted round-robin, least-connections, and IP hash and compare how each distributes load across a 4-server pool with a live distribution chart.
Animate an ICMP Echo Request/Reply round trip hop by hop, then switch to a traceroute mode showing TTL expiring at each router to build the hop list — illustrating why switches never appear as a hop.
IPv4 CIDR subnet math: network address, broadcast, subnet mask, wildcard, first/last host, and usable host count. Quick presets for /24–/30.
WAN circuit sizing from user count and application profile. Concurrency and overhead factors. Recommends standard carrier circuit tier.
PoE power budget for 4 device groups. Calculates max draw, required PSU, and recommended standard switch PSU size with efficiency factor.
Server rack kW to kVA, BTU/hr, tons, and CFM. UPS battery runtime, Ah sizing, and PDU amperage at 208V single or 3-phase.
Log-distance path loss model for 6 environment types. Coverage radius from EIRP, frequency, and receiver sensitivity. AP count from floor area.
Define VLAN segments with host counts and get the minimum /prefix that fits. Shows usable IPs, address waste, and design guidelines.
System availability from series component reliabilities. Dual ISP parallel redundancy option. Annual downtime, SLA tier, and MTBF.
RAID usable capacity, deduplication, and compression ratios. Multi-year growth projection for SAN/NAS sizing. Disk count estimate.
DSCP mapping and bandwidth allocation per traffic class. Visual bandwidth bar, allocation balance check, and queuing mechanism notes.
TIA-568 channel compliance check for Cat 5e–8 and fiber. Horizontal run + patch cord total, connector loss, and attenuation budget.
Enterprise networking and IT are certification-driven. This overview maps the main vendor-neutral (CompTIA) and vendor (Cisco, Juniper) networking tracks, structured-cabling design (BICSI RCDD), and security (CISSP) — what each covers and how they ladder.
CompTIA A+ prep: both Core 1 and Core 2 domains — hardware, networking, virtualization, OS, security and troubleshooting.
CompTIA Network+ prep: OSI/TCP-IP, subnetting, routing/switching basics, media, wireless and troubleshooting.
CompTIA Security+ prep: threats, cryptography, identity & access, network security, and risk/governance.
Cisco CCNA prep: routing, switching, IP services, security fundamentals, and automation/programmability.
Cisco DevNet Associate (200-901 DEVASC) prep: software design, APIs, Cisco platform development, and infrastructure automation.
Cisco CCNP Enterprise prep: advanced routing, VPN/overlays, assurance, security and automation (core + concentration).
Cisco CCNP Security (SCOR 350-701) prep: network/cloud/content security, endpoint protection, secure access and enforcement.
Cisco CCIE prep: the expert-level 8-hour hands-on lab plus qualifying exam — design, deploy and troubleshoot at scale.
Cisco CCIE Security prep: the expert-level 8-hour hands-on security lab — perimeter, VPNs, ISE, threat defense and automation.
BICSI RCDD prep: structured-cabling and telecom infrastructure design — pathways/spaces, bonding, and TIA/ISO standards.
CISSP prep: the eight (ISC)² domains — risk management, architecture, network security, IAM and security operations.
Interactive 13-section enterprise networking reference covering OSI model, Ethernet/VLANs/STP, OSPF/BGP routing, network security, Wi-Fi 6 design, SD-WAN, spine-leaf data center topology, VXLAN/EVPN, and cloud networking.
Interactive 27-section illustrated guide from OSI/TCP-IP fundamentals and IP subnetting through VLANs/STP, campus and spine-leaf data-center architecture, OSPF/BGP routing and ACLs, IT/OT security segmentation, and IP video surveillance design.
Interactive 14-section illustrated guide to MPLS, MPLS-TP, and SR-MPLS transport technologies — dynamic vs. static label-switched paths, label imposition/disposition, label stack types, real SR-MPLS/MPLS-TP/IS-IS configuration examples, and migration to hybrid SR-MPLS networks.
Why a CDN edge cache, an in-memory cache, and a browser cache all face the same tradeoff — TTLs, invalidation, and revalidation checks are the three ways of deciding how stale a cached copy is allowed to get before it has to catch up with the source.
One recipient, every device on the segment, or just the subscribed group — why multicast isn't "broadcast with fewer people," illustrated with a 1,000-viewer live stream sent three different ways.
TCP guarantees reliable, ordered delivery via a handshake and retransmission — but that guarantee can stall. UDP guarantees nothing, which is exactly why live video, VoIP, gaming, and DNS choose it on purpose.
A switch forwards frames by MAC address, entirely within one broadcast domain. A router forwards packets by IP address, between subnets — and re-writes the frame's MAC header at every hop. Neither one can do the other's job.
A switch gives every device its own private, collision-free wire — but it still has to flood a broadcast frame out every other port in the same VLAN. Eliminating collisions and shrinking broadcast domains are two different jobs, and only VLANs do the second one.
Latency is a physics-imposed time delay set by distance. Bandwidth is a theoretical capacity ceiling. Throughput is what you actually get — and the bandwidth-delay product shows why high latency caps it even on a fast, wide-open pipe.
Basic one-to-one NAT still needs roughly one public IP per device. PAT (NAT overload) adds port numbers as a second dimension, letting an entire office share just one public IP — which is what most routers are actually running.
An access port hands a device plain, untagged frames and quietly does the VLAN bookkeeping itself. A trunk port carries several VLANs over one wire at once, using 802.1Q tags to keep them straight — plug the wrong device into the wrong one and connectivity breaks immediately.
A static route keeps pointing at a dead link forever, blind to the failure, until an engineer fixes it by hand. A dynamic protocol like OSPF or BGP detects the same failure and converges on a new path automatically — at the cost of overhead, complexity, and its own failure modes that a static route never has to pay.
A pure Layer 2 switch can't move traffic between VLANs at all without an external router. A Layer 3 switch routes between VLANs itself, in its own ASIC, at wire speed — no extra hop, no round trip up a trunk link and back.
A VLAN is a Layer 2 broadcast-domain boundary enforced by switch ports and 802.1Q tags. A subnet is a Layer 3 IP addressing boundary enforced by network address and mask. The 1:1 mapping between them is a design convention, not a protocol requirement.
A single-mode core is narrow enough for only one light path — long reach on a precise laser. A multi-mode core is wide enough for several paths at once, capping distance via modal dispersion but enabling cheap LED/VCSEL transceivers built for exactly the distances a data center actually needs.
Learn how to design, implement, secure, troubleshoot, and maintain enterprise computer networks using real-world architectures and industry best practices. 19 modules from fundamentals through certification, 5 complete real-project design packages (corporate headquarters, hospital, manufacturing plant, data center, university campus), a 12-template documentation kit, and a certificate of completion. One-time $4.99 purchase, no account required.
Explore the Full Curriculum →