The Foundation Every Security Professional Needs
Here is a simple truth that experienced security professionals repeat: you cannot defend a network you do not understand.
A student can memorise a hundred attack names and still be lost the first time a SOC alert says, “Unusual outbound traffic from 10.20.5.14 to port 4444.” Someone with solid networking knowledge reads the same alert and immediately asks the right questions. Which VLAN is that host in? Is port 4444 normal? Is the DNS behaviour strange? What does the packet capture show?
If you are a student in Greater Noida, a fresher in Noida’s IT corridor or a professional in Delhi NCR planning a move into security, networking is the layer under everything else. Attacks travel over networks. Defences live on networks. Evidence is found in network traffic.
This guide covers the 12 topics of the Networking for Cyber Security module:
- OSI and TCP/IP models
- IPv4, IPv6 and addressing
- Subnetting and network segmentation
- TCP, UDP and common ports
- DNS, DHCP and ARP
- HTTP, HTTPS and web traffic
- ICMP and network diagnostics
- Routing, switching and VLAN concepts
- Firewalls, proxies and VPNs
- Network monitoring and traffic analysis
- Wireshark and packet analysis fundamentals
- Nmap and network security assessment
Part of a series. This module connects with our other guides: Cyber Threats & World Readiness (the attacks and frameworks), Protocols & Cryptography (how data is secured) and Python for Cyber Security (automation and tool-building). Networking is the common ground between all three.
Why Networking Is the Backbone of Cyber Security
Think about the major incident types in our Cyber Threats guide: ransomware spreading across a flat network, DDoS floods, man-in-the-middle interception, APTs moving laterally. Every one of them is a networking story.
Networking knowledge helps you to:
- Detect abnormal traffic, scans, beaconing and data exfiltration
- Design networks that limit damage when something goes wrong
- Investigate incidents by reading packets and logs
- Configure firewalls, VPNs and segmentation correctly
- Communicate with network and infrastructure teams in their own language
In job descriptions for SOC analysts, network security engineers, penetration testers and cloud security roles, networking fundamentals are almost always listed as a core requirement. Certifications such as CompTIA Network+, CCNA and Security+ all build on this base.
Topic 1: OSI and TCP/IP Models
Why models matter
A network model is a way to break the complex job of communication into layers. Each layer has one responsibility and talks to the layers above and below it. For security, layers give you a map for troubleshooting and for thinking about attacks.
The OSI model (7 layers)
| Layer | Name | What it does | Example protocols / devices | Example attacks |
|---|---|---|---|---|
| 7 | Application | User-facing services | HTTP, DNS, SMTP, FTP | SQL injection, phishing, XSS |
| 6 | Presentation | Formatting, encryption, encoding | TLS, JPEG, ASCII | SSL stripping, weak ciphers |
| 5 | Session | Starts, maintains, ends sessions | NetBIOS, RPC | Session hijacking |
| 4 | Transport | End-to-end delivery, ports | TCP, UDP | SYN flood, port scanning |
| 3 | Network | Addressing and routing | IP, ICMP, routers | IP spoofing, ICMP abuse |
| 2 | Data Link | Local delivery using MAC addresses | Ethernet, Wi-Fi, switches | ARP spoofing, MAC flooding |
| 1 | Physical | Signals, cables, radio | Cables, hubs, Wi-Fi radio | Cable tapping, jamming |
A memory trick: “Please Do Not Throw Sausage Pizza Away” (Physical, Data Link, Network, Transport, Session, Presentation, Application).
The TCP/IP model (4 layers)
The real internet runs on TCP/IP, which is simpler:
| TCP/IP layer | Matches OSI layers |
|---|---|
| Application | 5, 6, 7 |
| Transport | 4 |
| Internet | 3 |
| Network Access | 1, 2 |
Encapsulation: how data is wrapped
When you send data, each layer adds its own header, like putting a letter in an envelope, then into a bigger envelope:
Data → Segment (TCP/UDP) → Packet (IP) → Frame (Ethernet) → Bits
At the receiving end, the process runs in reverse. Understanding this is what makes packet analysis in Wireshark make sense later.
Using layers in real security work
- A device that cannot reach a website? Troubleshoot bottom-up: cable/Wi-Fi, then IP, then DNS, then the application.
- A firewall that filters by IP and port works at Layers 3 and 4. A web application firewall works at Layer 7.
- ARP spoofing is a Layer 2 problem, so a Layer 7 control will not solve it.
Layered thinking prevents the common mistake of applying the right fix at the wrong layer.
Topic 2: IPv4, IPv6 and Addressing
IPv4
IPv4 addresses are 32 bits, written as four decimal numbers (octets), such as 192.168.1.10. That gives roughly 4.3 billion possible addresses, which is no longer enough for the world’s devices.
Address classes and special ranges you must know:
| Range | Purpose |
|---|---|
10.0.0.0/8 | Private (RFC 1918) |
172.16.0.0/12 | Private (RFC 1918) |
192.168.0.0/16 | Private (RFC 1918) |
127.0.0.0/8 | Loopback (127.0.0.1 is “this machine”) |
169.254.0.0/16 | Link-local (APIPA), seen when DHCP fails |
224.0.0.0/4 | Multicast |
Private addresses are not routed on the public internet. Home and office networks use NAT (Network Address Translation) to share one public IP among many private devices.
IPv6
IPv6 uses 128-bit addresses, written in hexadecimal, for example 2001:db8::1. It offers an effectively unlimited address space and has features such as built-in autoconfiguration (SLAAC). India has seen large IPv6 deployment by major mobile operators, so you will meet it in real networks.
Security points for IPv6:
- Many organisations enable IPv6 on devices without securing it, leaving a blind spot where firewalls and monitoring only cover IPv4.
- Neighbor Discovery Protocol (NDP) replaces ARP and has its own spoofing risks (for example, rogue router advertisements).
- Scanning IPv6 ranges is very different, because address spaces are enormous, so attackers rely on DNS and other discovery methods.
- Rule: if you run IPv6, secure and monitor it as seriously as IPv4. If you do not need it, disable it deliberately and document the decision.
Other addressing concepts
- MAC addresses: 48-bit hardware addresses used at Layer 2 on the local network
- Public vs private IP: your device’s private IP differs from your router’s public IP
- Static vs dynamic addressing: servers usually have static IPs, while user devices get dynamic ones from DHCP
- NAT and PAT: address translation, which hides internal addressing but is not a security control by itself
Why this matters for security
When you read a log containing 203.0.113.5 and 10.0.0.8, you should instantly know which is external and which is internal. Spotting an internal host talking to an unusual external address is the core of threat detection.
Topic 3: Subnetting and Network Segmentation
What is subnetting?
Subnetting divides a larger network into smaller networks (subnets). A subnet mask or CIDR prefix shows which part of an address is the network and which part is the host.
| CIDR | Subnet mask | Total addresses | Usable hosts |
|---|---|---|---|
/24 | 255.255.255.0 | 256 | 254 |
/25 | 255.255.255.128 | 128 | 126 |
/26 | 255.255.255.192 | 64 | 62 |
/27 | 255.255.255.224 | 32 | 30 |
/28 | 255.255.255.240 | 16 | 14 |
/30 | 255.255.255.252 | 4 | 2 |
Usable hosts = 2^(host bits) − 2. (One address is the network ID and one is the broadcast.)
A worked example
Network 192.168.10.0/26:
- Block size: 64 addresses
- Network ID:
192.168.10.0 - Usable range:
192.168.10.1to192.168.10.62 - Broadcast:
192.168.10.63 - Next subnet starts at:
192.168.10.64
You can check your answers with Python’s ipaddress module, a nice link to our Python for Cyber Security guide:
import ipaddress
net = ipaddress.ip_network("192.168.10.0/26")
print(net.network_address, net.broadcast_address, net.num_addresses)Network segmentation: the security payoff
Segmentation splits a network into zones with controlled paths between them. It is one of the most effective defences against ransomware and lateral movement.
A sensible enterprise layout:
| Zone | Contents | Security idea |
|---|---|---|
| User LAN | Employee devices | No direct access to servers’ admin ports |
| Server zone | Internal applications | Only required ports reachable |
| DMZ | Public web, mail, VPN gateways | Isolated, heavily monitored |
| Management network | Admin interfaces, jump hosts | Strictly limited access |
| Guest / IoT | Visitors, cameras, smart devices | No path to internal systems |
| Database / critical zone | Crown-jewel data | Tightest rules, extra logging |
Why it works: if one laptop is compromised, a flat network lets the attacker reach everything. A segmented network forces them to cross firewalls where traffic is filtered and logged.
Related concepts
- Zero trust: do not trust a device just because it is “inside”
- Microsegmentation: very fine-grained rules, often in cloud and virtualised environments
- Least privilege: allow only the traffic that is required, and deny everything else
Topic 4: TCP, UDP and Common Ports
TCP vs UDP
| Feature | TCP | UDP |
|---|---|---|
| Connection | Connection-oriented | Connectionless |
| Reliability | Acknowledgements, retransmission | None |
| Speed | Slower | Faster |
| Uses | Web, email, file transfer, SSH | DNS, streaming, VoIP, DHCP, gaming |
The TCP three-way handshake
- SYN: client says “I want to connect”
- SYN-ACK: server says “OK, I’m ready”
- ACK: client confirms, and the connection is established
Closing uses FIN (graceful) or RST (abrupt reset). Other flags you will meet: PSH, URG.
Security relevance:
- A SYN flood sends many SYNs and never completes the handshake, exhausting server resources.
- Port scans use SYN, FIN and other flag combinations to learn which ports are open.
- Too many RST packets can mean blocked or failing connections.
Ports
A port (0 to 65535) identifies a specific service on a host. They fall into three ranges: well-known (0 to 1023), registered (1024 to 49151) and dynamic/ephemeral (49152 to 65535).
Common ports every analyst should know
| Port | Protocol | Notes for security |
|---|---|---|
| 20/21 | FTP | Cleartext, avoid; use SFTP or FTPS |
| 22 | SSH | Secure remote access; common brute-force target |
| 23 | Telnet | Cleartext, should be disabled |
| 25 | SMTP | Email sending; watch for spam relay |
| 53 | DNS | TCP and UDP; watch for tunnelling |
| 67/68 | DHCP | Address assignment |
| 80 | HTTP | Cleartext web |
| 110 / 143 | POP3 / IMAP | Email retrieval (prefer encrypted versions) |
| 123 | NTP | Time sync; can be abused for amplification |
| 161 | SNMP | Device management; weak community strings are risky |
| 389 / 636 | LDAP / LDAPS | Directory services |
| 443 | HTTPS | Encrypted web |
| 445 | SMB | File sharing; heavily targeted by worms and ransomware |
| 1433 / 3306 / 5432 | MSSQL / MySQL / PostgreSQL | Databases; should never be exposed to the internet |
| 3389 | RDP | Remote desktop; a very common ransomware entry point |
Key insight: ports tell you what a service is probably doing, but not for certain. Malware can use port 443 or 53 to blend in, so a port number alone proves nothing. Context and traffic content matter.
Useful commands
netstat -ano # Windows: connections and process IDs
ss -tulpn # Linux: listening ports and processesChecking what is listening on your own machine is one of the first steps of system hardening.
Topic 5: DNS, DHCP and ARP
These three small protocols run constantly in the background, and each has a well-known abuse.
DNS (Domain Name System)
DNS translates names such as example.com into IP addresses. It uses UDP port 53 for most queries (TCP for large responses and zone transfers).
Common record types:
| Record | Purpose |
|---|---|
| A / AAAA | Name to IPv4 / IPv6 address |
| CNAME | Alias to another name |
| MX | Mail servers |
| TXT | Free text; used for SPF, DKIM, DMARC and verification |
| NS | Authoritative name servers |
| PTR | Reverse lookup (IP to name) |
DNS attacks and abuse:
- DNS spoofing / cache poisoning: forging responses so users reach fake sites
- DNS tunnelling: hiding data inside DNS queries to sneak data out or run command-and-control
- DGA (Domain Generation Algorithms): malware generating random domains to contact its operators
- Typosquatting and lookalike domains for phishing
- DDoS amplification using open resolvers
- Zone transfer leaks from misconfigured servers
Defences: DNSSEC (signing records), DNS filtering and sinkholing, monitoring query volume and unusual domains, restricting zone transfers, and using DoT/DoH (DNS over TLS/HTTPS) to encrypt queries. Remember that DoH can also hide traffic from security tools, so organisations must plan for it.
Useful tools: nslookup, dig, host.
DHCP (Dynamic Host Configuration Protocol)
DHCP automatically gives devices an IP address, subnet mask, gateway and DNS server. The process is called DORA:
- Discover (client broadcasts)
- Offer (server proposes an address)
- Request (client accepts)
- Acknowledge (server confirms)
DHCP risks:
- Rogue DHCP server: an attacker hands out a malicious gateway or DNS server, redirecting traffic
- DHCP starvation: exhausting the address pool so legitimate devices cannot connect
Defence: DHCP snooping on switches, which only trusts DHCP replies from authorised ports.
ARP (Address Resolution Protocol)
ARP maps an IP address to a MAC address on the local network. A device broadcasts “Who has 192.168.1.1?” and the owner replies with its MAC address. ARP has no authentication.
ARP spoofing (poisoning): an attacker sends fake ARP replies so victims send traffic to the attacker’s machine, enabling man-in-the-middle attacks (see our Cyber Threats guide).
Defences: Dynamic ARP Inspection (DAI) with DHCP snooping, port security, static ARP entries for critical devices, segmentation and encrypted protocols (TLS and SSH) so intercepted traffic is useless.
Useful command: arp -a shows your ARP table. Duplicate MAC addresses for different IPs can be a warning sign.
Topic 6: HTTP, HTTPS and Web Traffic
The web is where most users and most attacks meet. (For the TLS and encryption details, see our Protocols & Cryptography guide.)
Anatomy of an HTTP request
GET /login HTTP/1.1
Host: example.com
User-Agent: Mozilla/5.0
Cookie: session=abc123Request methods: GET, POST, PUT, DELETE, HEAD, OPTIONS.
Response status codes:
| Range | Meaning | Examples |
|---|---|---|
| 2xx | Success | 200 OK |
| 3xx | Redirect | 301, 302 |
| 4xx | Client error | 401, 403, 404, 429 |
| 5xx | Server error | 500, 502, 503 |
What security teams look at in web traffic
- User-Agent strings: unusual or scripted ones may indicate bots or scanners
- URLs and parameters: patterns like
' OR 1=1or../../suggest injection or traversal attempts - Status code patterns: hundreds of 401s suggest brute force, many 404s suggest directory scanning
- Cookies and sessions: theft or reuse indicates hijacking
- Referer and Origin headers: useful in investigating CSRF and phishing
- Request volume and rate: spikes can mean scraping, credential stuffing or an application-layer DDoS
HTTPS and visibility
HTTPS encrypts content, which protects users but also means a network monitor cannot read the payload. What you can still see:
- Source and destination IPs and ports
- The SNI (server name) in many cases
- Certificate details
- Timing, sizes and patterns of traffic
Some enterprises use TLS inspection at proxies or firewalls to see inside encrypted traffic. This must be done carefully, with clear policy, because it introduces its own privacy and security considerations.
Common web-related controls
- WAF (Web Application Firewall) in front of public applications
- Security headers: HSTS, Content-Security-Policy, X-Content-Type-Options
- Rate limiting and bot management
- Secure cookies:
Secure,HttpOnlyandSameSiteflags
Topic 7: ICMP and Network Diagnostics
What is ICMP?
ICMP (Internet Control Message Protocol) works at Layer 3 and carries control and error messages, not user data. It is how networks say “that host is unreachable” or “your packet took too long.”
| Type | Meaning |
|---|---|
| 0 | Echo Reply (ping response) |
| 3 | Destination Unreachable |
| 8 | Echo Request (ping) |
| 11 | Time Exceeded (used by traceroute) |
Essential diagnostic tools
| Tool | Purpose |
|---|---|
ping | Is the host reachable, and how fast? |
traceroute / tracert | Path and delays across routers |
nslookup / dig | DNS troubleshooting |
ipconfig / ifconfig / ip a | Local IP configuration |
netstat / ss | Connections and listening ports |
arp -a | ARP table |
curl | Test web requests from the command line |
mtr | Combined ping and traceroute |
A simple troubleshooting flow
ping 127.0.0.1tests the local TCP/IP stack.pingyour default gateway tests the local network.pingan external IP (such as8.8.8.8) tests internet routing.pingornslookupa domain name tests DNS.
Where it fails tells you which layer to investigate.
ICMP and security
- Reconnaissance: attackers use ping sweeps to discover live hosts.
- Ping flood / Smurf attacks: ICMP used for denial of service.
- ICMP tunnelling: hiding data in echo packets to bypass controls.
- Redirect abuse: malicious ICMP redirects can alter routing on poorly configured systems.
A common mistake is blocking ICMP completely. Doing so can break Path MTU Discovery and make troubleshooting painful. A better approach is to allow the necessary types and rate-limit the rest.
Topic 8: Routing, Switching and VLAN Concepts
Switching (Layer 2)
A switch forwards frames based on MAC addresses, learning which device is on which port in its MAC address table (CAM table). Unlike old hubs, switches send traffic only to the intended port, which already reduces eavesdropping.
Switch-level attacks:
- MAC flooding: overflowing the table so the switch behaves like a hub
- VLAN hopping: jumping between VLANs using double tagging or switch spoofing
- STP manipulation: a rogue switch becoming the root bridge to redirect traffic
Switch security features:
- Port security: limit MAC addresses per port
- DHCP snooping and Dynamic ARP Inspection
- BPDU Guard / Root Guard to protect Spanning Tree
- Shutting down unused ports and moving them to an unused VLAN
- 802.1X port-based authentication
Routing (Layer 3)
A router connects different networks and forwards packets based on IP addresses using a routing table.
- Static routes: manually configured
- Dynamic routing protocols: RIP, OSPF (inside an organisation) and BGP (between organisations on the internet)
- Default gateway: where a device sends traffic for unknown networks
Routing risks: route hijacking and leaks (BGP incidents have disrupted traffic globally), rogue routers and unauthenticated routing updates. Defences include routing authentication, route filtering and monitoring.
VLANs (Virtual LANs)
A VLAN logically separates devices on the same physical switch into different broadcast domains, so, for instance, HR, Finance, Guests and Servers can share hardware but not a network.
- Access ports carry one VLAN (for end devices)
- Trunk ports carry multiple VLANs using 802.1Q tagging
- Native VLAN: untagged traffic on a trunk, which should be set to an unused VLAN
- Inter-VLAN routing: traffic between VLANs passes through a router or Layer 3 switch, where access control lists (ACLs) or firewalls can filter it
Security practices:
- Use VLANs together with firewall rules or ACLs, because VLANs alone are separation, not complete security
- Change the native VLAN and disable unused trunking (DTP)
- Use private VLANs where hosts in the same segment should not talk to each other
This is the technical foundation for the segmentation design in Topic 3.
Topic 9: Firewalls, Proxies and VPNs
Firewalls
A firewall enforces which traffic may pass between networks.
| Type | How it works |
|---|---|
| Packet filter | Checks IP, port, protocol |
| Stateful firewall | Tracks connections, allows valid replies |
| Proxy / application firewall | Understands application data |
| NGFW | Adds application awareness, user identity, IPS, TLS inspection |
| WAF | Protects web applications specifically |
Example rule logic:
| Source | Destination | Port | Action |
|---|---|---|---|
| User LAN | Web server | 443 | Allow |
| Internet | DMZ web server | 443 | Allow |
| Internet | Database zone | Any | Deny |
| Any | Any | Any | Deny (default) |
Best practices: default-deny, least privilege, rule documentation, regular rule cleanup, logging of denied traffic and testing changes before production. Rule sets that grow messy over years are a real source of breaches.
Proxies
A proxy sits between users and the internet.
- Forward proxy: filters and logs outbound web access for users (URL filtering, malware scanning, data-loss prevention)
- Reverse proxy: sits in front of servers, handling TLS, load balancing, caching and protection (for example, Nginx or cloud CDNs)
- Transparent vs explicit proxies: users may or may not need to configure them
Proxies give defenders visibility and control, and give attackers a reason to abuse them (open proxies, proxy chaining to hide origin).
VPNs
A VPN creates an encrypted tunnel across an untrusted network. Variants include remote-access VPNs, site-to-site VPNs, IPsec, SSL/TLS VPNs, OpenVPN and WireGuard (details in our Protocols & Cryptography guide).
Network design points:
- Split tunnelling sends only corporate traffic through the VPN (efficient, but less visible)
- Full tunnelling sends everything through the VPN (more control, more load)
- Protect VPN gateways with MFA, patching and monitoring, because they are frequent attack targets
- Many organisations are moving towards zero-trust network access (ZTNA)
How they fit together
A typical layout: Internet → edge firewall → DMZ (reverse proxy, VPN gateway) → internal firewall → server and user segments, with a forward proxy controlling outbound traffic. Each layer filters, logs and limits damage.
Topic 10: Network Monitoring and Traffic Analysis
Why monitor?
Prevention fails sometimes. Monitoring is how you notice. Industry reports consistently show that the time between compromise and detection is a major factor in how costly a breach becomes.
Data sources
| Source | What it gives you |
|---|---|
| Firewall logs | Allowed and denied connections |
| NetFlow / IPFIX / sFlow | Summaries of who talked to whom, how much, and when |
| Full packet capture (PCAP) | Complete detail, but heavy on storage |
| DNS logs | Every domain lookup, a goldmine for threat hunting |
| Proxy logs | Web activity per user |
| IDS/IPS alerts | Signature and anomaly detections |
| Switch/router logs and SNMP data | Device health and changes |
| Authentication logs | Who logged in from where |
Tools in the monitoring toolkit
- SIEM (Security Information and Event Management): collects and correlates logs and raises alerts
- IDS/IPS: Snort, Suricata
- Network analysis framework: Zeek, producing rich logs of connections, DNS, HTTP and TLS
- NDR (Network Detection and Response) platforms
- Monitoring platforms such as Nagios, Zabbix and Grafana for availability and performance
- SPAN/mirror ports and network TAPs to feed traffic to sensors
Establishing a baseline
You cannot spot “abnormal” unless you know “normal.” A baseline covers typical traffic volumes by time of day, common destinations, usual protocols and normal DNS behaviour.
What suspicious traffic looks like
| Pattern | Possible meaning |
|---|---|
| Regular outbound connections at fixed intervals | Beaconing to a command-and-control server |
| Very large outbound transfer at odd hours | Data exfiltration |
| One host contacting many internal hosts on port 445 or 3389 | Lateral movement |
| One source trying many ports or many hosts | Scanning |
| Huge DNS queries with long random names | DNS tunnelling or DGA |
| Sudden flood from many sources | DDoS |
| Traffic on unusual ports from servers | Possible backdoor or tunnel |
| Cleartext credentials crossing the network | Legacy protocol risk |
The monitoring workflow
- Collect logs and traffic
- Normalise and correlate in a SIEM
- Alert on rules and anomalies
- Triage: is it real? How severe?
- Investigate with packets and logs
- Respond and document
- Tune rules to reduce false positives and alert fatigue
If you want to automate steps 2 and 3 on your own data, our Python for Cyber Security guide shows how to parse logs and build detection logic.
Topic 11: Wireshark and Packet Analysis Fundamentals
Wireshark is the world’s most widely used packet analyser. It lets you see exactly what is on the wire, which is where networking theory becomes real.
Getting started safely
- Install Wireshark and choose the correct network interface
- Start a capture, perform an action (such as opening a web page), then stop
- Save the capture as a
.pcap/.pcapngfile for later analysis - Only capture traffic on networks you own or are authorised to monitor. Unauthorised sniffing is illegal under India’s IT Act, 2000.
Reading the interface
Wireshark shows three panes: the packet list, the packet details (layer by layer, mirroring the OSI/TCP/IP models from Topic 1) and the packet bytes.
Capture filters vs display filters
- Capture filters limit what is recorded (BPF syntax), for example
host 192.168.1.10 - Display filters limit what is shown after capture
Display filters worth memorising:
| Filter | Purpose |
|---|---|
ip.addr == 192.168.1.10 | Traffic to or from a host |
tcp.port == 443 | HTTPS traffic |
dns | DNS queries and responses |
http.request | HTTP requests |
tcp.flags.syn == 1 && tcp.flags.ack == 0 | Connection attempts (scan detection) |
arp | ARP traffic |
icmp | Ping and ICMP messages |
tls.handshake | TLS handshakes |
!(arp or dns) | Hide noise |
Core techniques
- Follow TCP Stream: reconstruct an entire conversation
- Statistics → Conversations / Endpoints: find top talkers
- Statistics → Protocol Hierarchy: see what protocols dominate
- Expert Information: retransmissions, resets and anomalies
- Colouring rules: quickly spot problems
- Export objects: extract files transferred over HTTP in lab captures
Practical exercises to try in a lab
- Watch a three-way handshake by filtering for one connection.
- Compare HTTP and HTTPS: see readable content vs encrypted data.
- Observe DNS: capture a lookup and read the query and response.
- Watch ARP: see “who has” requests and replies.
- Trace a ping: see ICMP echo request and reply.
- Spot a scan: run a scan against your own lab VM and see the SYN pattern.
- Inspect a TLS handshake: find Client Hello and certificate.
What analysts hunt for
- Cleartext passwords in legacy protocols
- Retransmissions and resets that signal network trouble or blocking
- Strange DNS queries
- Repeated beacon-like connections
- Unexpected protocols on a segment
- Certificate anomalies
Command-line companion: tcpdump
On servers without a GUI, tcpdump captures packets for later analysis in Wireshark. Python’s Scapy can also read and craft packets in authorised labs.
Topic 12: Nmap and Network Security Assessment
Nmap (Network Mapper) is the standard tool for discovering hosts, open ports and services. Security teams use it for asset inventory, attack-surface checks and vulnerability assessment preparation.
Legal and ethical rule: Scan only systems you own or have explicit written authorisation to test. Unauthorised scanning can violate the IT Act, 2000 and your organisation’s policies. Practise on your own lab VMs or deliberately vulnerable training environments.
What Nmap can tell you
- Which hosts are alive on a network
- Which ports are open, closed or filtered
- Which services and versions are running
- A best guess at the operating system
- Results from scripts (the Nmap Scripting Engine, NSE)
Basic examples (on your own lab network)
nmap -sn 192.168.56.0/24 # host discovery only (no port scan)
nmap 192.168.56.101 # scan common ports
nmap -p 1-1000 192.168.56.101 # scan a port range
nmap -sV 192.168.56.101 # detect service versions
nmap -O 192.168.56.101 # OS detection (needs privileges)
nmap -sC -sV 192.168.56.101 # default scripts + versions
nmap -oA scan_results 192.168.56.101 # save results in all formatsUnderstanding port states
| State | Meaning |
|---|---|
| Open | A service is accepting connections |
| Closed | Reachable, but nothing is listening |
| Filtered | A firewall or filter is blocking probes |
| **Open | filtered** |
Common scan types (concepts)
- TCP connect scan (
-sT): completes the full handshake, noisier but needs no special privileges - SYN scan (
-sS): sends SYN and does not complete the handshake, so it is faster and quieter (needs privileges) - UDP scan (
-sU): slower and less reliable, but important because DNS, SNMP and others use UDP
From scan to security assessment
Scanning is just the first step. A professional workflow looks like this:
- Get written authorisation and define the scope
- Discover assets and build an inventory
- Enumerate services and versions
- Compare with policy: are any unexpected ports open (RDP, SMB, databases, Telnet)?
- Identify vulnerabilities by matching versions to known CVEs and using vulnerability scanners
- Prioritise by risk, linking back to the risk process in our Cyber Threats guide
- Report clearly with evidence and remediation steps
- Fix and re-scan to confirm the issue is resolved
Defender’s view of scanning
Nmap is not only an offensive tool. Defenders run it to:
- Find forgotten servers and shadow IT
- Verify that firewall rules actually work
- Confirm only intended ports are exposed to the internet
- Detect unauthorised devices
And if your IDS or logs show one source probing many ports, you now know exactly what you are seeing. You can pair this with Python to automate scheduled scans and compare results over time, as shown in our Python for Cyber Security guide.
Network Security Hardening Checklist
A quick summary you can apply to any environment:
- Segment the network into zones (users, servers, DMZ, management, guest/IoT)
- Use default-deny firewall rules and review them regularly
- Disable Telnet, FTP, SMBv1 and other legacy protocols
- Never expose RDP, SMB or databases directly to the internet
- Enable DHCP snooping, DAI and port security on switches
- Shut down unused switch ports; change the native VLAN
- Enforce TLS for web, email and management interfaces
- Secure and monitor IPv6 (or disable it deliberately)
- Protect VPN and remote access with MFA and patching
- Centralise logs in a SIEM and monitor DNS and NetFlow
- Keep an up-to-date asset inventory and scan regularly
- Patch network devices and change default credentials
- Back up configurations and test your incident response plan
Industry View: Where Networking and Security Skills Are Used
| Industry | How networking skills are applied | Typical roles |
|---|---|---|
| Banking, Fintech & Insurance | Segmentation for payment systems, traffic monitoring, secure connectivity | Network Security Engineer, SOC Analyst |
| Healthcare & Pharma | Securing medical devices, protecting patient data networks | Security Analyst, Network Administrator |
| E-commerce & Retail | DDoS protection, WAF, load balancing, secure payment flows | Cloud Network Engineer, Security Engineer |
| IT Services & BPO | Client VPNs, secure offshore delivery centres, VAPT | Network Security Specialist, VAPT Analyst |
| Telecom & ISPs | Core routing, BGP security, traffic monitoring | Network Engineer, Security Specialist |
| Cloud & SaaS | Virtual networks, security groups, zero-trust design | Cloud Security Engineer |
| Manufacturing & Energy | OT/ICS network segmentation | OT Security Engineer |
| Government & Defence | Secure communications, threat hunting | Network Defence Analyst, Forensic Analyst |
Trending skills for 2026 and beyond:
- Cloud networking security (VPCs, security groups, cloud firewalls)
- Zero-trust architecture and ZTNA
- Network detection and response (NDR)
- IPv6 security
- Automation of network security tasks with Python
- AI-assisted traffic analysis and anomaly detection
- Securing IoT and OT networks
To see how AI is used for traffic anomaly detection and threat hunting, explore our Artificial Intelligence Training Course in Greater Noida.
Hands-On Practice Projects for Beginners
Build these in a safe, legal home lab (VirtualBox or VMware, with your own virtual machines) and document them:
- Draw a segmented network for a small company, with IP ranges for each zone
- Subnetting practice sheet: solve 20 problems and verify with Python
- Capture and annotate a TCP handshake, a DNS query and an ARP exchange in Wireshark
- Demonstrate HTTP vs HTTPS in a capture, and note what an eavesdropper can see
- Build a VLAN lab in Cisco Packet Tracer, GNS3 or EVE-NG, with inter-VLAN routing and ACLs
- Set up a pfSense or OPNsense firewall with default-deny rules
- Install Suricata or Zeek and generate a test alert
- Run Nmap on your own lab and write a short assessment report
- Write a Python script that parses Nmap or log output and flags unexpected open ports
- Create a one-page network hardening policy based on the checklist above
A GitHub repository with diagrams, screenshots, configs and write-ups is more convincing to recruiters than a list of course names.
Career Roadmap: Networking to Security Professional
- Learn networking fundamentals: OSI/TCP-IP, addressing, subnetting, ports (this module).
- Understand threats and frameworks: Cyber Threats & World Readiness.
- Learn how data is protected: Protocols & Cryptography.
- Add automation skills: Python for Cyber Security.
- Practise in labs: Wireshark, Nmap, firewalls, IDS and SIEM.
- Choose a path: SOC and blue team, network security, penetration testing, cloud security or GRC.
- Get certified: options include CompTIA Network+ and Security+, CCNA, CEH, and later CISSP and cloud security certifications.
- Build a portfolio: lab write-ups, diagrams and scripts on GitHub.
Pro tip: If you can clearly explain what happens when you type a website address and press Enter (DNS, ARP, TCP handshake, TLS, HTTP, routing and switching), you can handle a large share of entry-level networking and security interview questions.
Why Learn Networking and Cyber Security in Greater Noida?
Greater Noida and the wider Delhi NCR region are a major technology and education hub. Learners from Knowledge Park I, II and III, Alpha, Beta and Gamma sectors, Pari Chowk, Gaur City and Greater Noida West are well connected to Noida’s Sector 62, Sector 125 and Sector 135 IT clusters, and to opportunities in Gurugram, Ghaziabad and Delhi.
Local advantages include:
- Proximity to IT parks, data-driven companies, MNCs and startups across Noida and NCR
- A large student and fresher community from nearby universities and engineering colleges
- Metro, Aqua Line and road connectivity that makes regular classroom learning practical
- Strong demand for network and security professionals across the NCR
Whether you live in Greater Noida West, Alpha 1, Beta 2, Omicron, Delta, Noida Sector 62, Indirapuram or Ghaziabad, learning in a lab-based, mentor-guided environment can speed up your journey into the industry.
Learn It All at TUX Academy, Greater Noida
If this guide made you think, “I want to learn networking and security properly, with real labs,” TUX Academy offers industry-aligned programmes built around practical skills:
Cyber Security Training in Greater Noida
Learn networking, threats, protocols, cryptography, Python-based automation and network defence in one structured path.
Python Programming Training in Greater Noida
Build the scripting foundation to automate scans, parse logs and create your own security tools.
Artificial Intelligence Training in Greater Noida
Understand how AI is changing attack and defence, and prepare for the next decade of technology.
Continue reading the series:
- Cyber Threats & World Readiness: The Complete Guide
- Protocols & Cryptography: How the Internet Keeps Your Data Safe
- Python for Cyber Security: Automation, Scripting & Labs
What to expect from a good learning environment:
- Structured, module-wise curriculum
- Lab-based, practical sessions
- Resume, interview and certification guidance
- Support in building a real project portfolio
Explore courses: tuxacademy.org
Book a free demo class or counselling session today and take the first step toward a high-demand security career.
Frequently Asked Questions (FAQs)
1. Why is networking important for cyber security?
Almost every attack and every defence involves a network. Understanding addressing, protocols, ports and traffic lets you detect threats, design safer networks and investigate incidents effectively.
2. What topics are covered in the Networking for Cyber Security module?
OSI and TCP/IP models, IPv4/IPv6, subnetting and segmentation, TCP/UDP and ports, DNS/DHCP/ARP, HTTP/HTTPS, ICMP and diagnostics, routing/switching/VLANs, firewalls/proxies/VPNs, network monitoring, Wireshark, and Nmap.
3. Do I need to learn networking before cyber security?
You can learn them together, but strong networking fundamentals make every security topic easier. Most professionals recommend starting with the basics of TCP/IP, DNS and subnetting.
4. What is the difference between the OSI model and the TCP/IP model?
OSI has seven layers and is mainly a teaching and troubleshooting reference. TCP/IP has four layers and describes how the real internet works. Security professionals use both.
5. What is the difference between a switch, a router and a firewall?
A switch forwards frames within a local network using MAC addresses. A router forwards packets between networks using IP addresses. A firewall decides which traffic is allowed or denied based on rules.
6. What is a VLAN and is it secure?
A VLAN logically separates devices into different broadcast domains. It supports segmentation, but it is not complete security on its own, so it should be combined with ACLs or firewalls and proper switch hardening.
7. Is it legal to use Nmap and Wireshark?
The tools are legal. Using them on networks or systems you do not own or have written permission to test is not. Always practise in your own lab or an authorised environment.
8. Which ports should I memorise first?
Start with 22 (SSH), 53 (DNS), 80 (HTTP), 443 (HTTPS), 445 (SMB), 3389 (RDP), 25 (SMTP) and 3306 (MySQL), then expand your list.
9. How is subnetting used in security?
Subnetting enables segmentation, which limits how far an attacker or ransomware can spread. It also helps you write precise firewall rules and understand IP ranges in logs.
10. Can I get a job with networking and Python skills?
Yes. Networking plus scripting is a strong combination for SOC analyst, network security and junior penetration testing roles, especially when backed by a portfolio of lab projects.
11. Where can I learn networking and cyber security in Greater Noida?
You can explore the cyber security course at TUX Academy in Greater Noida and book a demo class to see whether it fits your goals.
Conclusion: Network Knowledge Turns Alerts into Answers
Security tools come and go, but the network underneath stays the same. The OSI and TCP/IP models give you a map. Addressing and subnetting give you structure. TCP, UDP and ports show you what services are doing. DNS, DHCP and ARP reveal the quiet protocols attackers love to abuse. Routing, switching and VLANs shape how traffic flows. Firewalls, proxies and VPNs control it, monitoring watches it, and Wireshark and Nmap let you see the truth.
Combine this with the attack knowledge in Cyber Threats & World Readiness, the encryption foundations in Protocols & Cryptography and the automation skills in Python for Cyber Security, and you have the full foundation employers across Greater Noida, Noida and Delhi NCR are searching for.
Ready to start? Explore Cyber Security Training, build your scripting base with Python Programming, and future-proof your career with Artificial Intelligence.
Disclaimer: This article is for educational purposes only. Perform scanning, packet capture and security testing only on networks and systems you own or are explicitly authorised to test.

