Advanced Network Training
OpenShift · Kubernetes · OVN
Develop operational expertise in cloud-native networking
From the Kubernetes network model to expert troubleshooting.
A training course designed for teams that operate OpenShift and Kubernetes in production. Over three days, you’ll gain an in-depth understanding of OVN-Kubernetes, masterIngress/Egress, network security, enterprise integration, and networking with KubeVirt, and learn how to diagnose any network incident.
Each module alternates between concepts and reproducible labs, so you'll walk away with skills you can apply immediately on your platform.
Program
10 modules
A step-by-step course, covering everything from Kubernetes networking fundamentals to KubeVirt networking. Each module combines advanced concepts with hands-on labs in preconfigured environments.
Target audience: OpenShift/Kubernetes platform engineers, cloud and infrastructure architects, DevSecOps engineers, and traditional networking teams transitioning to cloud-native environments.
Prerequisites: Linux · TCP/IP · Kubernetes Fundamentals
1 · Linux Networking Fundamentals
- IP Fundamentals
- Netmask and CIDR
- Routing
- ARP / NDP
- ICMP
- MTU
- Networking under Linux
- Network Namespace
- veth Interface
- Interface, Port, and Master
- Bridge Linux
- VLAN
- Neighbor Cache
- Netfilter / Conntrack
- Lab 1 – Understanding IP Addressing
- Subnet Calculation
- Understanding CIDR
- Sizing a Kubernetes Cluster
- Lab 2 – Understanding the Linux Network
- Exploring Network Interfaces
- Understanding Routing
- An Introduction to the ARP Resolution
- Analysis of Network Tables
2 · Kubernetes Network Fundamentals
- Fundamental Principles
- The 4 Rules of the Kubernetes Network
- Why Kubernetes Doesn't Use NAT for Pods
- The Addressing Plan
- Cluster Network
- Network Services
- Node Network
- HostPrefix
- IP Address Allocation
- Network Communications
- Pod → Pod (same Node)
- Pod → Pod (Different node)
- Pod → Service
- Pod → Internet
- Kubernetes Network Objects
- Pod
- Service
- Endpoints
- EndpointSlice
- DNS
- Network Components
- CNI
- CoreDNS
- kube-proxy
- Why OVN Replaces kube-proxy
- Connect a Pod to the network
- Why a CNI?
- CNI Architecture
- Life Cycle (ADD / DEL / CHECK)
- Creating the Network Namespace
- Creation of the veth
- Connecting the Interface to the Node Network
- IP Address Assignment
- Route Configuration
- Introduction to OVN-Kubernetes
- Lab 3 – Exploring the Network of Two Pods
- Two Pods on Two Nodes
- Network Interface Analysis
- Analysis of Routing Tables
- Neighbor Cache Analysis
- Validation of the Four Kubernetes Network Rules
- Lab 4 – Understanding the Kubernetes Network Model
- Analysis of the Cluster Addressing Plan
- Identifying Network Objects
- Monitoring Network Components
- Lab 5 – Understanding How a CNI Works
- Creating a Pod
- Monitoring the Network Connection
- Analysis of the Network Configuration Applied to the Pod
3 · From the Kubernetes Network Model to Its Implementation
- Why Kubernetes Delegates Networking to the CNI
- Kubernetes describes a desired state.
- He never configures the network directly.
- The CNI translates this model into a network configuration.
- The Major Families of National Identity Cards
- CNIs based on an overlay network.
- CNIs based on a routed network (underlay).
- CNIs that use eBPF.
- CNIs based on an SDN architecture.
- Overview of the Major National Identity Cards
- Flannel
- Calico
- Cilium
- OVN-Kubernetes
- Why OpenShift Uses OVN-Kubernetes
- A comprehensive SDN architecture.
- Excellent scalability.
- Distributed routing.
- Native integration with OpenShift.
- Advanced networking features (ACL, Load Balancer, MultiNetwork, Interconnect, etc.).
- Transition to OVN Deep Dive
- Understanding the OVN-Kubernetes Architecture.
- Learn about the components that implement the Kubernetes network model.
- Track the transformation of a Kubernetes object into a network configuration.
4 · OVN-Kubernetes Deep Dive
- Architecture
- Why OVN?
- Components
- Databases
- The control plane
- The data plane
- Logical Objects
- Logical Switch
- Logical Router
- Logical Switch Port
- Logical Router Port
- ACL
- Address Set
- Port Group
- Load Balancer
- How OVN Builds the Network
- Creating a Pod
- Creating Logical Objects
- Open vSwitch Programming
- OpenFlow
- Datapath
- Network Flows
- Pod → Pod (same node)
- Pod → Pod (remote node)
- Pod → Service
- Pod → Internet
- The Overlay Network
- Geneva
- Encapsulation
- Transit
- MTU
- Packet Walk
- Large-Scale OVN-Kubernetes
- Areas
- Interconnect
- Chassis
- Encapsulation
- High Availability
- Debug
- Lab 6 – Exploring the Architecture and Logical Objects of OVN
- Identification of Components and Northbound and Southbound Interfaces
- Exploring Logical Switches, Logical Routers, and Ports
- Creating a Pod and Viewing Associated Objects
- Mapping Between Kubernetes Objects, OVN Objects, and Open vSwitch Ports
- Lab 7 – Monitoring Network Traffic and Geneva Encapsulation
- Analysis of communications between pods on the same node and on different nodes
- Monitoring Traffic to a Service and to the Internet
- Traffic Capture in Geneva and Tunnel Identification
- Lab 8 – Troubleshooting the OVN-Kubernetes Network
- Exploring Zones, Chassis, and Interconnections
- Analysis of Logical Flows Using ovn-trace
- Inspection of OpenFlow Rules and the Open vSwitch Datapath
- Diagnosis of a Communication Failure and Verification of Restoration
5 · OpenShift Networking
- Network Operators
- Cluster Network Operator
- DNS Operator
- Ingress Operator
- Components
- Router
- Road
- IngressController
- CA Department
- The Roads
- Edge
- Passthrough
- Reencrypt
- Wildcard
- TLS
- DNS
- CoreDNS
- DNS Wildcard
- DNS API
- Operation
- oc
- Debug
- tcpdump
- ovn-nbctl
- ovn-sbctl
- Lab 9 – Comparison of Service Types
- Lab 10 – Configuring Ingress Controllers
- Lab 11 – DNS Resolution and Certificates
6 · Network Security
Network Security — Securing Kubernetes/OpenShift Communications
- Network Security Principles
- Zero Trust and the Principle of Least Privilege
- Application Microsegmentation
- Namespaces and Network Isolation
- Multi-tenant isolation
- Network Policies
- Selecting Pods and Namespaces
- Ingress and Egress Policies
- Default isolation: Default Deny
- Explicit Authorization for Communications
- DNS Access Management
- Communications Monitoring
- Control of East-West Traffic Between Applications
- Network Egress Control: Egress Control
- Authorization of Destinations and Required Ports
- Security with a Service Mesh
- Principles of Service Mesh Networking
- Encryption of Communications Using mTLS
- Service Identification and Trade Authorization
- Compatibility with NetworkPolicies
- Network Policy Assessment
- Verification of labels and selectors
- Analysis of Cumulative Rules and Policies
- Monitoring Authorized and Blocked Traffic
- Troubleshooting DNS and Connection Issues
- Impact of Existing Connections and Conntrack
- Lab 12 – Application and Tenant Isolation
- Setting Up Multiple Namespaces
- Enforcing "Default Deny" Policies
- Authorization for Necessary Communications
- Validation of Isolation Between Applications and Tenants
- Lab 13 – Controlling East-West Flows and Outflows
- Segmenting an application into several parts
- Controlling Communication Between Components
- Restrictions on Network Outbound Traffic
- Lab 14 – Securing Communication with a Service Mesh
- Enabling mTLS Between Services
- Application of Authorization Rules
- Checking Authorized and Denied Communications
- Integration with NetworkPolicies
7 · Integration with the corporate network
- Data Center Architecture
◦ LAN
◦ DMZ
◦ Firewall
◦ VLAN
◦ VRF - Load Balancers
◦ F5
◦ NetScaler
◦ HAProxy
Publication ◦ NodePort
◦ LoadBalancer
◦ Ingress
◦ Reverse Proxy- Security
◦ Firewall
◦ WAF
◦ IPS
◦ IDS
◦ TLS - Internet Outbound
◦ NAT
◦ EgressIP
◦ Proxy
◦ SSL Inspection - High Availability
◦ BGP
◦ ECMP
◦ Anycast
◦ GSLB - Lab 15 – Publishing with MetalLB
8 · API Gateway
- Why Gateway API
- Architecture
◦ GatewayClass
◦ Gateway
◦ Listener
Routes ◦ HTTPRoute
◦ TCPRoute
◦ TLSRoute
◦ UDPRoute
◦ GRPCRoute- Traffic Management
◦ Load Balancing
◦ Header Rewrite
◦ URL Rewrite
◦ Redirect - Security
◦ TLS
◦ mTLS
◦ Authentication
◦ Rate Limiting - Use Cases
- Lab 16 – Deploying a Gateway
- Lab 17 – Publishing with HTTPRoute
- Lab 18 – Securing Connections with TLS and mTLS
- Lab 19 – Publishing a TCP Service
9 · Multi Network - UDN
- Why Multiple Networks?
- Multus
◦ NAD
◦ Secondary interfaces - UDN
◦ Primary UDN
◦ Secondary UDN
◦ CUDN - Types of Networks
◦ Layer 2
◦ Layer 3
◦ Localnet - Communication
◦ UDN → UDN
◦ UDN → Cluster
◦ UDN → Physical - Security
◦ MultiNetworkPolicy
◦ Isolation
◦ ACL - Lab 20 – Setting Up a Secondary Network with Multus
- Lab 21 – Deploying a User-Defined Network
- Lab 22 – Connecting to a Physical Network (Localnet)
- Lab 23 – Isolation Between Multiple Networks
- Lab 24 – Configuring an EgressIP on a UDN
10 · KubeVirt Networking
Architecture ◦ VM
◦ VMI
◦ virt-launcher- Network Interfaces
◦ Masquerade
◦ Bridge
◦ SR-IOV
◦ Passt - VM Network
◦ VM ↔ VM
◦ VM ↔ Pod
◦ VM ↔ Physical - VLAN
◦ Trunk
◦ Access
◦ Linux Bridge
Services ◦ Live Migration
◦ DHCP
◦ DNS
◦ Kubernetes Services
Business Case ◦ VMware Migration
◦ Legacy Networks
◦ Bare Metal
◦ High Availability- Lab 25 – Exploring the Virtual Machine Network
- Lab 26 – Comparison of Network Modes (Masquerade / Bridge / Passt)
- Lab 27 – Connecting a VM to a Physical VLAN
- Lab 28 – Communication Between VMs and Pods
- Lab 29 – Publishing a Virtual Machine
- Lab 30 – Live Migration and Network Traffic Analysis
Course Overview
Get an overview of the networking training provided by our technical experts.
Format, Deliverables, and Process
A 3-day in-person training course that can be spread out over time to accommodate your teams’ schedules. You’ll leave with comprehensive training materials, reproducible lab environments, and ready-to-use cheat sheets.
Do you have a question about the content or organization? Contact us—we’ll tailor the course to your tech stack.
Format & Duration
In-person, 3 days, with the option to spread out the training over time based on your teams' availability. Advanced/Expert level.
Included
Deliverables
Leave with everything you need to repeat the labs and reinforce what you've learned: comprehensive materials, reproducible environments, and practical cheat sheets.
You will receive
Who is this for?
A training program tailored for technical professionals who operate or design OpenShift/Kubernetes platforms in production.
