Computer Networks Roadmap

Learn how networks move data, from Ethernet and IP addressing to TCP, DNS, HTTPS, routing, security, and practical troubleshooting in production.

published: reading time: 10 min read author: Geek Workbench
Quick Summary

Learn how networks move data, from Ethernet and IP addressing to TCP, DNS, HTTPS, routing, security, and practical troubleshooting in production.

Computer Networks Roadmap

Computer networks connect applications, operating systems, data centers, and the public internet. Understanding the path a request takes helps you build reliable services and diagnose failures that otherwise look like application bugs. This roadmap moves from layered network models and local links through IP routing, transport protocols, application protocols, and operational security.

It is designed for learners who can use a command line and have basic programming experience. You do not need prior networking coursework. By the end, you should be able to reason about packet delivery, read common network symptoms, and explain how a client reaches a service over a real network.

Before You Start

  • Be comfortable using a terminal and reading basic command output.
  • Know what a process, operating system, and client/server application are.
  • Basic binary arithmetic helps with subnetting, but the roadmap introduces the concepts before using them.

The Roadmap

1

📚 Models and Packet Delivery

OSI and TCP/IP Models Map application behavior to link, internet, transport, and application layers.
Encapsulation and the Journey of a Packet Follow application data as each layer adds headers and a host sends it across a network.
Network Performance Basics Distinguish bandwidth, throughput, latency, jitter, and packet loss.
↓
2

🌐 Local Networks and IP

IPv4, IPv6, CIDR, and Subnetting Read addresses and prefixes, calculate network ranges, and understand private and public addressing.
Ethernet, MAC Addresses, ARP, and Neighbor Discovery Learn how hosts find a next-hop link-layer address on a local network.
IP Routing and NAT Use routing tables and default gateways to understand how packets cross network boundaries.
Docker Networking Connect bridge networks, published ports, and container name resolution to the same fundamentals.
↓
3

🔗 Transport and Network APIs

IP, TCP, and UDP Compare best-effort packet delivery with reliable byte streams and datagrams.
TCP Connection Management and Congestion Control Study handshakes, acknowledgments, retransmission, flow control, and congestion response.
Sockets and Network IPC See how programs bind, listen, connect, and exchange data through socket APIs.
Ports and Firewalls Trace a connection from a listening process through host and network filtering rules.
↓
4

🔎 Application Protocols

DNS and Domain Names Resolve names through recursive resolvers, authoritative servers, records, and caches.
HTTP and HTTPS Understand request and response semantics, connection reuse, HTTP/2, and HTTP/3.
TLS Handshakes and Certificates Follow server authentication, key negotiation, encryption, and certificate validation.
Load Balancing Compare Layer 4 and Layer 7 traffic distribution, health checks, and failover.
Forward Proxies and Reverse Proxies Distinguish client-side egress proxies from server-side request routing and gateways.
↓
5

📊 Reliability and Troubleshooting

Latency, Timeouts, and Network Failure Set bounded deadlines and retries while accounting for packet loss, tail latency, and partial failure.
Packet Capture and Network Troubleshooting Use ping, traceroute, dig, curl, and packet captures to narrow down where a request fails.
Network Observability Choose useful flow, interface, DNS, connection, and latency signals for operations.
↓
6

🔒 Security and Cloud Networking

Network Security and Segmentation Apply least privilege across cloud networks, workloads, policies, and service identities.
Kubernetes Services and Networking Connect cluster IPs, Services, ingress paths, and pod-to-pod traffic.
Kubernetes Network Policies Limit pod ingress and egress using workload-level network policy.
Mutual TLS and Service Identity Authenticate both ends of a service connection and rotate workload credentials.
Capstone: Trace and Secure a Web Request Document the request path, capture a failing case, identify its network boundary, and apply a least-privilege fix.

Timeline & Milestones

This plan assumes about 5–7 hours of study each week. Spend the first eight weeks on the six core sections, then reserve two weeks for the capstone and review. Learners with prior systems or networking experience can move faster; repeat the packet exercises if the concepts still feel abstract.

📅

📅 Estimated Timeline

Weeks 1–2: Models and Packet DeliveryMap layers, headers, and packet flow; explain bandwidth, latency, jitter, and loss.
Weeks 3–4: Local Networks and IPPractice CIDR and subnet calculations, then trace local delivery, routing, and NAT.
Week 5: Transport and Network APIsCompare TCP and UDP, inspect socket behavior, and follow firewall decisions.
Week 6: Application ProtocolsTrace DNS resolution, an HTTPS request, TLS negotiation, and proxy routing.
Week 7: Reliability and TroubleshootingDiagnose latency and packet loss with command-line tools and packet captures.
Week 8: Security and Cloud NetworkingReview segmentation, Kubernetes traffic paths, network policy, and workload identity.
🎓

🎓 Capstone Track

Week 9: Trace a Web RequestDocument DNS resolution, the TCP or QUIC connection, TLS, HTTP, and each network boundary.
Week 10: Diagnose and Secure a FailureCapture a reproducible failure, locate the failing hop, apply a least-privilege fix, and record evidence that it works.

Milestone Markers

Milestone When What you can do
Foundation End of Week 2 Explain packet encapsulation and distinguish latency, throughput, jitter, and loss.
Local Delivery End of Week 4 Calculate a subnet and follow a packet from a host to its default gateway.
Transport and Applications End of Week 6 Explain how DNS, TCP or UDP, TLS, and HTTP fit into one request.
Production Ready End of Week 8 Read a network symptom, identify relevant security boundaries, and choose useful telemetry.
Capstone Complete End of Week 10 Produce a request-path diagram, a packet-level diagnosis, and a verified least-privilege change.

Core Topics: When to Use / When Not to Use

TCP and UDP — When to Use vs When Not to Use
When to Use When NOT to Use
Use TCP when the application needs an ordered byte stream and connection-level retransmission. Do not choose TCP just because it is familiar when the application needs message boundaries or custom loss handling.
Use UDP when the application can handle loss itself or needs datagrams with low setup overhead. Do not use UDP to avoid thinking about reliability; congestion control and loss behavior still matter.
Choose QUIC-based protocols when you need encrypted, multiplexed streams over UDP and can use a supported implementation. Do not implement a transport protocol from scratch for an ordinary application.

Trade-off Summary: TCP provides a mature reliable stream with transport-level ordering. UDP exposes datagrams and leaves more behavior to the application. QUIC adds transport features over UDP, but requires protocol support and different operational debugging tools.

NAT and Private Addressing — When to Use vs When Not to Use
When to Use When NOT to Use
Use address translation when private hosts need controlled outbound access through a smaller set of public addresses. Do not treat NAT as a firewall or as a substitute for explicit access policy.
Use private address ranges to isolate internal networks and conserve public IPv4 addresses. Avoid overlapping address ranges when networks may later connect through VPNs or peering.
Plan IPv6 addressing where end-to-end addressing and provider support make it practical. Do not assume IPv6 is protected simply because a service has no IPv4 address.

Trade-off Summary: NAT helps with address conservation and boundary management, but hides endpoint identity and complicates inbound connectivity and troubleshooting. Clear routing and firewall policy still matter.

Load Balancers and Proxies — When to Use vs When Not to Use
When to Use When NOT to Use
Use a load balancer to distribute traffic, check backend health, or provide a stable service endpoint. Avoid adding one when a single local process is sufficient and the extra hop adds no useful control.
Use a reverse proxy for TLS termination, routing by host or path, or consistent edge policy. Do not assume a proxy can safely retry a request whose operation is not idempotent.
Use a forward proxy when clients need controlled egress, filtering, or an explicit outbound boundary. Do not route sensitive traffic through a proxy without understanding its trust and logging model.

Trade-off Summary: Proxies and load balancers centralize traffic handling and can improve resilience, but they add a hop, configuration, and another failure domain. Make health checks and retry behavior match the application.

Network Policies and Mutual TLS — When to Use vs When Not to Use
When to Use When NOT to Use
Use network policy to restrict workload communication where the cluster networking implementation enforces it. Do not rely on a policy object until you verify that the cluster CNI supports and applies it.
Use mutual TLS when both client and service need cryptographic identity over a connection. Do not add a service mesh solely to obtain mTLS if a simpler supported identity mechanism meets the requirement.
Combine identity-based controls with network boundaries for defense in depth. Do not mistake encrypted traffic for authorization; an authenticated peer can still lack permission for an operation.

Trade-off Summary: Workload policies and mTLS reduce implicit trust between services, but add configuration and certificate lifecycle concerns. Test enforcement and renewal paths as part of operations.

Resources

Next Steps

After this roadmap, continue with a deeper path through Distributed Systems or System Design to study how network behavior shapes multi-service applications.

Category

Related Posts

Event-Driven Architecture Roadmap: From Events to Production

Follow a practical path through event-driven design, brokers, contracts, reliable delivery, workflows, stream processing, and production operations.

#event-driven-architecture #events #distributed-systems

Backend Engineering Roadmap

Build the skills to design, secure, test, deploy, and operate backend services, from programming fundamentals through databases and distributed systems.

#backend-engineering #backend-roadmap #learning-path

API Design & Integration Roadmap

Design secure APIs and integrate them reliably, learning HTTP, API contracts, authentication, testing, and production operations along the way.

#api-design #api-integration #learning-path