LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 05-29-2008, 02:53 PM   #1
abefroman
Senior Member
 
Registered: Feb 2004
Location: lost+found
Distribution: CentOS
Posts: 1,430

Rep: Reputation: 55
How do I know if I have a technical understanding of TCP/IP networking and network ar


How do I know if I have a technical understanding of TCP/IP networking and network architecture?

I am considering taking a snort class, but they require I have technical understanding of TCP/IP networking and network architecture.

I have some experience with IPtables, not much, some experience with tcpdump, some experience with cisco switches, and some experience with configuring 3rd party firewall software (like the APF) for ingress/egress traffic by port and/or ip. I would say I'm at the beginner level of those, execpt for tcpdump and configuring 3rd party firewall which I am intermeidate.

Does that qualify as a "technical understanding".
 
Old 05-29-2008, 03:12 PM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
if you do honestly understand tcpdump output then that's probably a good yardstick. with more information it might be clearer but i'd say you should...

- know the osi model
- know the tcp/ip model
- be able to compare the above matching up each layer
- compare tcp and udp
- understand arp
- appreciate relationships between each model layer and the realities of encapsulation

but if you're the sort of person who can appreciate things without necessarily already knowing them, then you can probably fill in the gaps yourself as you go along.

Obviously prereqs vary hugely, but i would think that for snort you could well go into quite a bit of theory in order to make the practical make sense, and lots of snort checks are analysing the health of the network packets themselves, not just the data contents.
 
Old 05-29-2008, 03:18 PM   #3
farslayer
LQ Guru
 
Registered: Oct 2005
Location: Northeast Ohio
Distribution: linuxdebian
Posts: 7,249
Blog Entries: 5

Rep: Reputation: 191Reputation: 191
I'd say if you comfortably understand the information required to pass the Cisco ICND course (Minus the Cisco specific commands) you should have a decent understanding of TCP/IP and networking. (addressing, Routing, Subnetting, NAT, etc.. )

Do you understand the OSI network Model ?
Do you understand the TCP/IP Network Model ?
I would imagine there would be quite a few concepts from those models referenced in an IDS course.
 
Old 05-29-2008, 03:19 PM   #4
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
you didn't know what pcap was though ;-)
 
Old 06-01-2008, 05:32 AM   #5
hasanatizaz
Member
 
Registered: Nov 2007
Location: Pakistan
Distribution: Redhat and Debian
Posts: 317
Blog Entries: 1

Rep: Reputation: 35
since i am learning about tcp/ip and i find this website to be the best..

http://www.linuxhomenetworking.com/w..._to_Networking
 
Old 06-01-2008, 10:49 AM   #6
abefroman
Senior Member
 
Registered: Feb 2004
Location: lost+found
Distribution: CentOS
Posts: 1,430

Original Poster
Rep: Reputation: 55
Quote:
Originally Posted by geniushasan View Post
since i am learning about tcp/ip and i find this website to be the best..

http://www.linuxhomenetworking.com/w..._to_Networking
Gratsi!
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: Networking 101: Understanding iBGP LXer Syndicated Linux News 0 07-06-2006 06:03 AM
Understanding Basic Networking carlosinfl Linux - Networking 3 05-05-2006 04:52 PM
LXer: 2006 USENIX Annual Technical Conference Features Networking on a Planetary Scale and Network Security Breakthroughs LXer Syndicated Linux News 0 05-01-2006 05:54 PM
Which non-technical and technical book had changed or influenced you alred General 18 08-25-2005 08:44 PM
Help with understanding networking... caffeinelegacy Linux - Networking 9 09-09-2003 03:29 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 07:16 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration