Module 1 · How It Actually Works
You cannot debug what you cannot picture. This module builds an accurate mental model of what a computer does when it runs your code and what the network does when you load a page — then verifies every claim with a packet capture you take yourself. Nothing here is taken on faith.
This is the most theory-heavy module in the curriculum, deliberately placed before you build anything. When your Module 2 server won’t boot, your Module 3 VLAN won’t route, or your Module 5 WireGuard tunnel won’t handshake, the diagnosis will come from the mental models you build here. Everyone who skips this module pays for it later with hours of confused config-shuffling.
The lessons
Section titled “The lessons”| Lesson | Topic | Time |
|---|---|---|
| 1.1 · The Machine | Boot process, the OS, kernel vs. user space, resource triage | 4–5 hrs |
| 1.2 · TCP/IP, Layer by Layer | Ethernet, ARP, IP, subnets, routing, TCP/UDP, NAT | 6–8 hrs |
| 1.3 · DNS | Recursion vs. authority, record types, caching, dig |
3–4 hrs |
| 1.4 · HTTP & TLS | Requests by hand, status codes, the TLS handshake, certificates | 4–5 hrs |
| 1.5 · Packet Capture | tcpdump and Wireshark — seeing everything above, live | 4–6 hrs |
| Labs | The five graded exercises | 6–10 hrs |
Total: roughly 30–40 hours, or 3–4 weeks part-time.
What you need
Section titled “What you need”- Your machine from Module 0 with a working shell — plus Wireshark installed
(free, all platforms) and
tcpdump,dig,curl,nc,traceroute/mtravailable. The labs page has install commands. - No lab hardware needed yet — everything here runs against your existing home network and the public internet. (Your micro PC should be arriving around now for Module 2.)
How the lessons fit together
Section titled “How the lessons fit together”The module tells one story: what happens when you load a webpage. Lesson 1.1 explains the machine that runs the browser. Lesson 1.2 explains how packets find the server. Lesson 1.3 explains how the name became an address. Lesson 1.4 explains the conversation itself and its encryption. Lesson 1.5 hands you the instrument — packet capture — that lets you watch all of it happen, and the capstone lab has you annotate a real capture of a real page load, protocol by protocol.
Checkpoint
Section titled “Checkpoint”- I can explain the boot process from power button to login prompt
- I can name the layer at which a given networking problem lives
- I can subnet in my head for common prefixes (/24, /25, /26, /16)
- I can resolve a domain manually with
digand explain each step - I can capture and read a TCP handshake and a DNS query in Wireshark
- I can explain what a TLS certificate does and doesn’t prove
Deliverable
Section titled “Deliverable”An annotated packet-capture walkthrough — a blog post in your repo that walks a reader through your capture of a single page load, screenshot by screenshot, explaining every protocol involved. Full spec in Lab 4.
Resources
Section titled “Resources”- Computer Networking: A Top-Down Approach (Kurose & Ross) — the standard text, skim-friendly
- How DNS Works — comic-format, genuinely good
- Julia Evans: Networking! ACK! zine
- Beej’s Guide to Network Programming — when you want to go one level deeper