Role-based roadmaps, know what to learn and in what order
Understand how computers communicate, models, addresses, and protocols
IPv4 and IPv6 basics, subnet masks, CIDR, and MAC addressing at the edge
Name resolution, addressing helpers, transport, and the web stack
Perimeter controls, remote access, NAT, and how packets are switched and routed
You can explain how data gets from A to B
CCNA-level design, operations, and troubleshooting on Cisco-style campus and WAN networks.
Revisit models, IP, DNS/DHCP, TCP/UDP, switching, routing, and VLAN fundamentals
Link-state vs distance vector, path selection, BGP peering, and redistribution concepts
STP behavior, VTP-style management ideas, inter-VLAN routing, and 802.1Q trunks
Stateful firewalls, ACL mental models, IPS/IDS roles, VPNs, and port-based access
DHCP/DNS design, monitoring with SNMP-style thinking, time sync, and centralized logging
Structured methodology, CLI tools, and packet captures for proof
You can configure, verify, and troubleshoot a small multi-VLAN enterprise network
BGP at scale, OSPF multi-area, QoS policies, and automation-backed operations
Design and defend larger topologies with advanced routing and policy
VPCs, regional subnets, firewall rules, and route tables that steer traffic
Egress without public IPs, managed DNS, VPN tunnels, and dedicated or partner interconnect
Global and regional L7/L4 front ends, edge caching, and edge security policies
Peering limits, shared host projects, PSC endpoints, and Private Google Access
HA VPN, dedicated throughput, Cloud Router, and BGP-learned routes
You can diagram, implement, and justify a secure VPC and hybrid attachment
Verbs, status codes, certificate chains, handshake steps, and mutual TLS patterns
Record types, LB algorithms, reverse proxies, and CDN behavior at the edge
Bridge vs host, overlay meshes, published ports, and compose-style service graphs
Cluster IPs, Ingress controllers, policy objects, CNI overlays, and kube-dns patterns
Data-plane proxies, observability hooks, Terraform modules for VPC/LB, and GitOps workflows
You can trace a user request from DNS through TLS to pods and back
Ground truth in TCP/IP, then specialize in enterprise, cloud, or platform networking as needed
Multi-region layouts, high availability, failover, and active-active traffic steering
On-prem plus cloud attachments, migration cutovers, and consistent policy
BeyondCorp-style access, identity-aware proxies, private service consumption, no default public IPs
Pick the right network tier, model egress, and maximize CDN hit ratio
You can whiteboard end-to-end flows and defend trade-offs with customers
Follow GCP release notes for networking, Armor, PSC, and new connectivity options