Skip to content
NETFORGE // LABS • HIGH-PRECISION NETWORK ENGINEERING

NETFORGE LABS

Learn networking by building it. Stand up real fabrics on Arista cEOS, break them on purpose, and understand why every line of config is there — not just what to paste.

Choose your milestone-driven learning path in AI & Hyperscale Architecture, Network SRE & Observability, Cybersecurity & DevSecOps, NetDevOps, Low-Latency Finance, or TPM System Design.

ARISTA cEOS • CONTAINERLAB • ORBSTACK ON MACOS & LINUX


🎯 6 Milestone-Driven Learning Paths

  • 🌐 Network for AI & Hyperscale Architect   40–50 hrs


    Non-blocking AI training fabrics (RoCEv2, PFC, ECN), 5-Stage BGP Clos (RFC 7938), MPLS/SR-MPLS Ti-LFA, and EVPN-VXLAN ESI multihomed clusters.

    Explore AI Architect Path →

  • 🤖 Network SRE & Observability   30–35 hrs


    Production incident mitigation, BFD sub-second failover, gNMI real-time streaming telemetry, Prometheus alerts, and PyATS automated assertions.

    Explore SRE Path →

  • 🔒 Cybersecurity & DevSecOps   30–35 hrs


    Control Plane Policing (CoPP), VRF segmentation, Zero-Trust IAM/OAuth2/mTLS, Falco eBPF container security, Suricata IDS/IPS, and SIEM playbooks.

    Explore Security Path →

  • 🤖 NetDevOps & Infrastructure Automation   35–40 hrs


    Treat network infrastructure as code: Jinja2/YAML data models, PyATS assertions, Batfish AST static pre-flight analysis, and GitHub Actions CI/CD.

    Explore NetDevOps Path →

  • Low-Latency Financial Network Engineer   25–30 hrs


    High-Frequency Trading (HFT) infrastructure: PIM-SM multicast market feeds, IGMP fast-leave, sub-second BFD failover, and MACsec line-rate encryption.

    Explore Financial Path →

  • 📋 TPM & Hyperscale System Design   20–25 hrs


    System design & program leadership: 5-Stage Clos scaling math, eBGP vs. iBGP trade-offs, blast radius containment, and SLA budget calculations.

    Explore TPM Path →


🚀 All Validated Courses & Lab Matrix

  • Phase 4 · VXLAN-EVPN Datacenter Fabrics   5 labs live


    CLOS fabrics: Pure L2VNI, Symmetric IRB, Anycast Virtual Gateway, ESI All-Active Multihoming, EVPN-VPWS/ELAN, and DCI Multi-Site.

    Start Phase 4 →

  • Phase 5 · Network Automation & CI/CD   5 labs live


    Infrastructure as Code: Jinja2/YAML Data Models, PyATS/Genie, Batfish pre-flight static analysis, gNMI, and GitHub Actions CI/CD.

    Start Phase 5 →

  • Phase 7 · Streaming Telemetry & Observability   5 labs live


    gNMI gRPC protobuf streams, OpenConfig YANG models, Prometheus metrics, and real-time Grafana visual dashboards.

    Start Phase 7 →

  • Phase 8 · Network Security & Microsegmentation   4 labs live


    Control Plane Policing (CoPP) CPU protection, VRF microsegmentation with ACL filters, Infrastructure ACLs (iACLs), and MACsec.

    Start Phase 8 →

  • Phase 9 · IPv6 Transition & Dual-Stack   4 labs live


    IPv6 ND/SLAAC, BGP Unnumbered over IPv6 Link-Local (RFC 5549 / RFC 8950), 6PE/6VPE over MPLS, and NAT64/DNS64 translation.

    Start Phase 9 →

  • Phase 3.5 · Segment Routing (SR-MPLS)   3 labs live


    SRGB range (16000–23999), Node/Prefix SIDs, Ti-LFA Sub-50ms Fast Reroute, and SR-PCE BGP Color steering.

    Start Phase 3.5 →


💡 How Every Lab Works

Each topic follows the same structured engineering rhythm:

Mental model → why before how → protocol mechanics → build it → verify → break it → interview drill.

All labs feature single-source-of-truth configuration snippets, automated step runners (run.sh), and live containerlab gate checks.