🌐 Infrastructure & Systems Networking: Complete Curriculum Index
Welcome to the Infrastructure and Systems Networking documentation series. This collection is organized as an end-to-end curriculum spanning physical and virtual network layers, transport protocols, global DNS architecture, cryptographic TLS handshakes, high-availability load balancing, cloud VPC design, edge CDNs, and VPN tunneling.
Every guide in this series strictly follows a two-part learning format:
- ⚡ Quick Dive: Executive comparison tables, CLI cheat sheets, and quick configuration one-liners for instant lookup.
- 📖 Extended Guide: Deep architectural blueprints, production configuration manifests (Nginx, HAProxy, WireGuard), protocol handshakes, and systems engineering best practices.
📚 Complete Curriculum Roadmap
Part 1: Core Networking & Transport Protocols
| # | Guide | Primary Topics Covered |
|---|---|---|
| 01 | OSI Model & TCP/IP Networking | The 7-layer OSI vs. 4-layer TCP/IP models, packet encapsulation/decapsulation, ARP, MTU/MSS fragmentation, and bottom-up troubleshooting. |
| 02 | DNS Architecture & Resolution | Hierarchical resolution tree (Root, TLD, Authoritative, Recursive), record types (A, AAAA, CNAME, MX, TXT, SRV), DNSSEC, and Anycast routing. |
| 03 | Transport Protocols: TCP, UDP & QUIC | TCP 3-way handshake and 4-way teardown, TIME_WAIT socket exhaustion, congestion control (Google BBR vs. Cubic), UDP, and QUIC. |
| 04 | HTTP Protocol Evolution (HTTP/1 to HTTP/3) | HTTP/1.1 head-of-line blocking, HTTP/2 binary framing and stream multiplexing (HPACK), and HTTP/3 over QUIC with 0-RTT connection resumption. |
| 05 | TLS, Public Key Infrastructure & mTLS | TLS 1.3 1-RTT handshake, X.509 certificate chain of trust, OCSP stapling, automated ACME / Let's Encrypt, and Mutual TLS (mTLS) for zero trust. |
Part 2: Reverse Proxies, Load Balancing & Cloud Networks
| # | Guide | Primary Topics Covered |
|---|---|---|
| 06 | NGINX Reverse Proxy & Load Balancing | Event-driven non-blocking architecture, upstream balancing algorithms, header forwarding, rate limiting (leaky bucket), and FastCGI/proxy caching. |
| 07 | HAProxy High Availability & Health Checking | Layer 4 TCP vs. Layer 7 HTTP load balancing, active health checks, sticky sessions, and high-availability failover using Keepalived & VRRP. |
| 08 | Cloud Networking: VPCs, Subnets & Gateways | CIDR subnet math, 3-tier multi-AZ VPC architecture, Internet Gateways (IGW), NAT Gateways, Stateful Security Groups vs. Stateless NACLs, and Transit Gateways. |
| 09 | CDNs, Edge Caching & Cache-Control | Global PoP and Origin Shield topology, Cache-Control directives, conditional validation (ETag/304), surrogate keys, and edge compute. |
| 10 | VPNs, Encrypted Tunnels & WireGuard | VPN protocols (IPsec, OpenVPN, WireGuard), Noise protocol cryptography, Cryptokey Routing, split vs. full tunneling, and peer-to-peer mesh overlays. |