Skip to content

Lab-aligned learning path

Use this page as the bridge between theory and hands-on work. The practical material is divided by platform so Packet Tracer exercises are not mixed with Terraform/GCP deployments.

  • Packet Tracer labs isolate Cisco, protocol, and packet-flow fundamentals.
  • Terraform & GCP labs apply those fundamentals to declarative cloud infrastructure.

Read the listed theory first, predict the flow, complete the lab, and then prove the result using device state, packet inspection, or cloud runtime evidence.

Packet Tracer lab sequence

Stage Packet Tracer lab Read first What the lab proves
1 Single-subnet FTP/HTTP Models, MAC and ARP, Switches and routers, HTTP/HTTPS Hosts in one subnet communicate through Layer 2 switching without a gateway.
2 Router and subnets IP addressing, Subnetting, Switches and routers Traffic between broadcast domains needs a router and correct default gateways.
3 Multi-router NAT and DHCP Private IP and NAT, Subnetting and DHCP, Routing DHCP, default routing, and PAT combine at an enterprise edge.
4 DHCP and relay Subnetting and DHCP, Switches and routers Broadcast-based DORA works locally; a relay carries requests across a router.
5 DNS and name resolution DNS and ports, TCP and UDP, HTTP/HTTPS DNS resolution precedes application traffic and depends on routing and DHCP options.
6 NAT, PAT, and forwarding Private IP and NAT, TCP and UDP, Firewalls Translation state changes packet endpoints while ports identify simultaneous flows.
7 OSPF and BGP Routing protocols, Packets and IP An IGP distributes internal reachability while BGP exchanges routes between autonomous systems.
8 VLANs and ACLs VLANs, ACLs and segmentation, TCP and UDP VLANs create boundaries; inter-VLAN routing reconnects them; ACLs enforce policy.
9 GCP architecture equivalent Cloud and hybrid networking, VLANs, Firewalls Packet Tracer components model the physical concepts behind a two-tier cloud architecture.

Lab 9 remains in this sequence because it is built and tested in Packet Tracer; it uses GCP terminology only as a conceptual mapping.

Terraform & GCP lab sequence

All Terraform exercises are located under docs/terraform/ and build from a first provider configuration toward multi-network and hybrid designs.

Stage Terraform/GCP lab Read first What the lab proves
1 Setup and first apply Cloud and hybrid networking Provider authentication, state, planning, application, and destruction form the Terraform workflow.
2 VPC and subnets Packets and IP, Subnetting A custom VPC and regional subnet express a software-defined routing domain and address plan.
3 Routing, NAT, and firewall NAT and PAT, Routing, Firewalls Routes, Cloud NAT, and firewall rules solve different forwarding, translation, and policy problems.
4 VMs and private DNS DNS and ports, Cloud networking Private workloads receive addresses and resolve internal names without requiring public exposure.
5 Two-tier networking scenario Stages 1–4 VPC, subnets, private DNS, firewall policy, NAT, and VMs work together in one architecture.
6 VPC peering and Shared VPC Routing, Cloud networking Private connectivity and centralized network administration are separate design choices.
7 L4 and L7 load balancing TCP and UDP, HTTP/HTTPS, Load balancers L4 distributes connections while L7 can route using HTTP information.
8 IPsec VPN and BGP Routing, VPNs, Cloud networking IPsec secures the tunnel while BGP exchanges the private prefixes that use it.

A repeatable study loop

  1. Predict: identify source, destination, subnet boundary, gateway, and expected protocol.
  2. Build: follow the selected platform's lab exactly; treat its addressing plan as authoritative.
  3. Observe: inspect ARP, DHCP, DNS, routing, NAT, ACL, session state, Terraform output, or cloud runtime state as applicable.
  4. Explain: describe every hop using an OSI layer and the forwarding or policy decision being made.
  5. Break and repair: change one item, predict the symptom, restore it, and verify again.

Questions to answer for every lab

  • Is the destination local or remote, and how does the sender decide?
  • Which addresses remain end-to-end, and which are rewritten?
  • Which control-plane process created the forwarding information?
  • Where is policy enforced, and is the device stateful or stateless?
  • Which command, packet capture, Terraform output, or cloud log proves the explanation?