VyOS · Curriculum
Curriculum
342 lessons across 63 parts. Lessons build on each other; later parts assume familiarity with earlier material.
Part I
Networking Foundations for Routing Engineers
Ethernet, MAC, ARP, IPv4/IPv6, CIDR, subnets, gateways, MTU, TCP/UDP, ICMP — the prerequisites every routing engineer must already understand.
- 01Ethernet, MAC and ARP — the Layer 2 the routing engineer must readLayer 2 and Layer 3 foundations · foundation · ~18 min
- 02IPv4, IPv6, CIDR and subnetting — the arithmetic the routing engineer must do in their headLayer 2 and Layer 3 foundations · foundation · ~22 min
- 03TCP, UDP and ICMP — the transport protocols the routing decisions affectLayer 2 and Layer 3 foundations · foundation · ~20 min
- 04MTU and fragmentation — the constraint every tunnel violatesLayer 2 and Layer 3 foundations · foundation · ~18 min
- 05DNS and DHCP — the services every routing change depends onLayer 2 and Layer 3 foundations · foundation · ~18 min
- 06ARP vs NDP — neighbour discovery at Layer 2 / Layer 3, IPv4 and IPv6 side by sideLayer 2 and Layer 3 foundations · foundation · ~14 min
Part II
Routing Fundamentals
Routing tables, longest-prefix match, connected routes, static routes, default routes, next hops, recursive lookup, administrative distance, metric, ECMP.
- 01Routing tables — what an entry actually isRouting primitives · foundation · ~18 min
- 02Longest-prefix match — the algorithm that decides every packetRouting primitives · foundation · ~16 min
- 03Connected routes — the free routes the interface gives youRouting primitives · foundation · ~12 min
- 04Static and default routes — explicit pathsRouting primitives · foundation · ~16 min
- 05Administrative distance — how a router prefers one source over anotherRouting primitives · foundation · ~16 min
- 06ECMP — equal-cost paths and the per-flow decisionRouting primitives · intermediate · ~14 min
Part III
VyOS Architecture
Linux base, FRRouting, configuration tree, commit engine, generated runtime configuration, services, web UI, API.
- 01Linux base — what VyOS is at the bottomArchitecture · foundation · ~18 min
- 02FRRouting and the routing daemons — the dynamic brainArchitecture · intermediate · ~18 min
- 03The configuration tree — where every set command livesArchitecture · intermediate · ~14 min
- 04The commit engine — from candidate to runningArchitecture · intermediate · ~14 min
- 05Generated runtime configuration — what VyOS hands to FRR and the kernelArchitecture · intermediate · ~14 min
- 06Services, web UI, HTTP API — what is reachable and howArchitecture · intermediate · ~14 min
Part IV
Installation and Initial Deployment
ISO install, VM deployment, cloud image concepts, console, initial configuration, management connectivity.
- 01ISO install — booting VyOS from a long-support imageInstallation · foundation · ~24 min
- 02VM deployment — running VyOS as a guest on Proxmox, VMware, KVMInstallation · foundation · ~22 min
- 03Cloud image — running VyOS on AWS, GCP, Azure, and OpenStackInstallation · intermediate · ~20 min
- 04Console access and initial management — first contact with the boxInstallation · foundation · ~18 min
- 05Post-install hardening — what to change before the box touches the public InternetInstallation · intermediate · ~22 min
- 06Image management — upgrades, downgrades, dual-image rollbackInstallation · intermediate · ~18 min
Part V
Configuration Model
configure / set / delete / show / compare / commit / save / discard / exit; candidate vs active vs saved configuration.
- 01configure / set / delete / show / compare — the operational vocabularyConfigure mode · foundation · ~18 min
- 02Candidate, active, saved — the three configurations every VyOS box hasConfigure mode · foundation · ~16 min
- 03Hierarchical tree — the schema the operator navigatesConfigure mode · foundation · ~14 min
- 04show configuration and compare — inspecting the candidate without leaving itConfigure mode · foundation · ~12 min
- 05save / discard / exit — exiting configure mode with intentConfigure mode · foundation · ~10 min
- 06Common configuration traps — patterns that bite every operator at least onceConfigure mode · intermediate · ~16 min
Part VI
Commit and Rollback Safety
commit, commit-confirm, rollback, configuration history, save — production-critical safe-change mechanics.
- 01commit semantics — what the commit engine actually doesSafe changes · intermediate · ~18 min
- 02commit-confirm — the rollback safety net for remote changesSafe changes · intermediate · ~16 min
- 03Configuration history — the archive of every successful commitSafe changes · intermediate · ~14 min
- 04rollback — the in-place revert to a known-good stateSafe changes · intermediate · ~14 min
- 05save — making the configuration persistSafe changes · intermediate · ~10 min
- 06Remote change discipline — the operational standard for changes the operator cannot seeSafe changes · intermediate · ~18 min
Part VII
Interface Fundamentals
Ethernet interfaces, addressing, descriptions, MTU, administrative and operational state.
- 01Ethernet interfaces — naming, MAC, driver mappingInterfaces · foundation · ~18 min
- 02IP addressing on interfaces — static, DHCP, and address-lessInterfaces · foundation · ~16 min
- 03MTU on the interface — the most misunderstood setting on a routerInterfaces · intermediate · ~14 min
- 04Administrative and operational state — the four states of an interfaceInterfaces · foundation · ~12 min
- 05Interface diagnostics — what to run when an interface is brokenInterfaces · intermediate · ~18 min
- 06Interface anti-patterns — the configurations that always cause troubleInterfaces · intermediate · ~16 min
Part VIII
VLANs
IEEE 802.1Q, tagged traffic, trunks, sub-interfaces, parent interfaces, VLAN addressing, switch interaction.
- 01IEEE 802.1Q — the tagging modelVLAN · foundation · ~16 min
- 02VLAN sub-interfaces — eth0.10, eth0.20, ...VLAN · foundation · ~14 min
- 03Trunks and access — what the operator controls at each end of the cableVLAN · foundation · ~12 min
- 04VLAN routing — moving packets between VLANs on the same routerVLAN · intermediate · ~18 min
- 05VLAN troubleshooting — finding the broken VLAN in five minutesVLAN · intermediate · ~16 min
- 06VLAN security — VLAN hopping, native VLAN attacks, and the mitigationsVLAN · intermediate · ~16 min
Part IX
Bridges
Layer-2 bridging, bridge interfaces, when bridging is appropriate versus routing.
- 01Bridges — Layer 2 forwarding in softwareBridges · foundation · ~14 min
- 02Bridge configuration — members, addressing, STPBridges · intermediate · ~16 min
- 03Bridge vs routing — when to bridge, when to routeBridges · intermediate · ~12 min
- 04Bridge troubleshooting — finding the broken bridge fastBridges · intermediate · ~14 min
- 05Bridge + VRF — combining Layer 2 and Layer 3 segmentationBridges · advanced · ~14 min
- 06Bridge anti-patterns — what not to do with bridgesBridges · intermediate · ~12 min
Part X
Bonding and Link Aggregation
LACP, active-backup, balance modes, switch dependencies, failure behaviour.
- 01LACP — the protocol that aggregates linksBonding · intermediate · ~18 min
- 02Bond modes — balance-rr, active-backup, balance-xor, 802.3ad, balance-tlb, balance-albBonding · intermediate · ~18 min
- 03Switch dependencies — LAG, port-channel, MLAG, and switch model specificsBonding · intermediate · ~18 min
- 04Bond failure modes — slave down, LACP flap, hash mismatch, MTU mismatchBonding · intermediate · ~18 min
- 05Bond + VLAN — trunk on a bond, sub-interfaces on bond members, native VLAN ruleBonding · advanced · ~18 min
- 06Bond validation — /proc/net/bonding, show bonding, throughput testingBonding · advanced · ~18 min
Part XI
IPv6
Addresses, prefixes, neighbour discovery, router advertisements, static and dynamic routing, firewall.
- 01IPv6 fundamentals — 128-bit addressing, headers, ICMPv6, NDPIPv6 · foundation · ~18 min
- 02IPv6 addressing — global unicast, ULA, link-local, multicast, anycast, prefix delegationIPv6 · foundation · ~18 min
- 03IPv6 router advertisements — SLAAC, prefix options, M/O flags, RDNSSIPv6 · intermediate · ~18 min
- 04DHCPv6 — stateful vs stateless, IA_NA, IA_PD, RDNSSIPv6 · intermediate · ~18 min
- 05IPv6 routing — static routes, OSPFv3, BGP, MP-BGP, IPv6 in VRFIPv6 · advanced · ~20 min
- 06IPv6 troubleshooting — ping6, traceroute6, neighbour cache, MTU 1280, fragmentationIPv6 · advanced · ~18 min
Part XII
Static Routing
Static routes, default routes, recursive next hops, floating static routes, blackhole routes.
- 01Static routes — the foundation of a routed estateStatic routing · foundation · ~16 min
- 02Default route — 0.0.0.0/0, dual default, floating default, ICMP unreachableStatic routing · foundation · ~16 min
- 03Static route options — tag, description, on-link, VRF, disableStatic routing · intermediate · ~18 min
- 04Blackhole routes — silent drops for martians, aggregation, and DDoS mitigationStatic routing · intermediate · ~18 min
- 05Recursive routing — indirect next-hops, MTU, and RFC 8308 path MTUStatic routing · advanced · ~18 min
- 06Static route troubleshooting — show ip route, traceroute, looking-glass, asymmetric routingStatic routing · advanced · ~20 min
Part XIII
Policy-Based Routing
When destination routing is insufficient; source-based routing, application routing, management routing.
- 01Policy-based routing — concept, FIB vs RIB, table selection, why PBR existsPolicy-based routing · advanced · ~22 min
- 02Route-maps — match clauses and set clauses for PBRPolicy-based routing · advanced · ~22 min
- 03PBR rules — the policy route tree, its interface, ip rule, and the table it points atPolicy-based routing · advanced · ~20 min
- 04PBR for IPv6 — IPv6 source/destination matches, IPv6 next-hop, IPv6 interfacePolicy-based routing · advanced · ~18 min
- 05PBR troubleshoot — show ip route, show ip rule, traceflow, asymmetry, countersPolicy-based routing · advanced · ~20 min
- 06PBR anti-patterns — PBR everywhere, conflicting route-maps, missing table, asymmetric PBRPolicy-based routing · advanced · ~18 min
Part XIV
Multiple Routing Tables
Linux/VyOS policy-routing, tables, rules, priorities, lookup sequence.
- 01The routing-table concept — RIB, FIB, FRR, and the Linux kernel datapathRouting tables · intermediate · ~16 min
- 02Multiple routing tables and the ip rule policy databaseRouting tables · intermediate · ~18 min
- 03Table ID namespace — reserved IDs, custom IDs, and VRF conflictRouting tables · intermediate · ~14 min
- 04Source-based routing — binding traffic to a table by sourceRouting tables · intermediate · ~16 min
- 05Routing table troubleshooting — ip route show table all, ip rule show, asymmetryRouting tables · intermediate · ~18 min
- 06Routing table anti-patterns — too many tables, conflicting priorities, FRR not pushingRouting tables · intermediate · ~16 min
Part XV
VRFs
Route isolation, VRF interfaces, route-leaking considerations, operational troubleshooting.
- 01VRF concept — L3VPN, the kernel vrf driver, and how VyOS implements routing tables per VRFVRF · advanced · ~20 min
- 02VRF configuration — set vrf name, table ids, attaching interfaces, addressesVRF · advanced · ~22 min
- 03VRF routing protocols — OSPF, BGP, and crossing the VRF boundary on purposeVRF · advanced · ~24 min
- 04IPv6 inside a VRF — link-local next-hops, OSPFv3 and BGP per VRF, leaking route6VRF · advanced · ~22 min
- 05VRF troubleshooting — RIB versus FIB, `ip vrf exec`, and the leak that installs nothingVRF · advanced · ~22 min
- 06VRF anti-patterns — VRFs for non-routing problems, overlapping space, leaks that install nothing, MTUVRF · advanced · ~22 min
Part XVI
Route Leaking Between VRFs
Controlled connectivity between VRFs, security implications, accidental leaks.
- 01Route leaking between VRFs — concept, RFC 4364, shared servicesLeaking · advanced · ~22 min
- 02Route leaking configuration — static next-hop-vrf, BGP import vrf, filteringLeaking · advanced · ~26 min
- 03Leaking and firewall — dispatch by interface, state, asymmetric pathsLeaking · advanced · ~26 min
- 04IPv6 leaking — dual-stack leaks, RDNSS sharing, prefix delegationLeaking · advanced · ~22 min
- 05Troubleshooting leaking — routes missing, route-map blocking, asymmetric pathLeaking · advanced · ~22 min
- 06Anti-patterns — leaking everything, leaking without firewall, MTU-naive leakingLeaking · advanced · ~20 min
Part XVII
Routing Protocol Fundamentals
Adjacency, convergence, control plane vs data plane, IGP vs EGP, route preference.
- 01Adjacency — the neighbour relationship that has to exist before any routing can happenControl plane · intermediate · ~20 min
- 02Convergence — when the network agrees it has the same topology as beforeControl plane · intermediate · ~20 min
- 03Control plane versus data plane — what FRR decides and what the Linux kernel forwardsControl plane · intermediate · ~20 min
- 04IGP versus EGP — the inside and outside of an Autonomous SystemControl plane · intermediate · ~18 min
- 05Route preference — administrative distance, longest-prefix-match, and which route winsControl plane · intermediate · ~18 min
- 06Protocol metrics — cost, MED, IS-IS wide metrics, and how operators shift trafficControl plane · intermediate · ~18 min
Part XVIII
OSPF Fundamentals
Link-state routing, neighbours, LSAs, areas, DR/BDR, SPF, cost.
- 01Link-state routing — Dijkstra, the LSDB, and SPF calculationOSPF · intermediate · ~22 min
- 02OSPF neighbours and adjacency — the hello protocol and the eight-state machineOSPF · intermediate · ~22 min
- 03OSPF LSA types — Type 1 through Type 11 and what each one carriesOSPF · advanced · ~24 min
- 04OSPF areas — backbone, stub, NSSA, ABR, and area range aggregationOSPF · advanced · ~24 min
- 05DR/BDR election — designated router, broadcast vs point-to-point, and why the DR existsOSPF · advanced · ~20 min
- 06OSPF SPF and cost — Dijkstra's metric, reference bandwidth, and tuning pathsOSPF · advanced · ~22 min
Part XIX
OSPF Configuration
VyOS/FRR OSPF configuration: router ID, networks, passive interfaces, areas, summarisation.
- 01OSPF basics — enabling OSPF, router-id, default route, and area assignmentOSPF · intermediate · ~22 min
- 02OSPF interface configuration — network type, timers, MTU, passiveOSPF · intermediate · ~24 min
- 03OSPF area configuration — area types, area range, and per-area authenticationOSPF · advanced · ~26 min
- 04OSPF redistribution — static, connected, BGP, and route-map filteringOSPF · advanced · ~24 min
- 05OSPF authentication — plaintext, MD5, SHA-256, key chain, virtual linksOSPF · advanced · ~26 min
- 06OSPF cost tuning — auto-cost reference-bandwidth, manual cost, ECMPOSPF · advanced · ~24 min
Part XX
OSPF Areas and Design
Area 0, non-backbone areas, ABRs, area design, summarisation, stub area concepts.
- 01OSPF area types — backbone, standard, stub, totally stubby, NSSA, totally NSSADesign · advanced · ~22 min
- 02Stub and NSSA mechanics — Type 5 blocking, ABR default, Type 7 propagationStub and NSSA · advanced · ~22 min
- 03Inter-area summarisation — area range, ABR aggregation, prefix-list filteringSummarisation · advanced · ~22 min
- 04Virtual links — patching the backbone across a transit areaVirtual links · advanced · ~22 min
- 05Multi-area design — two-tier hierarchy, hub-and-spoke, scalability limitsDesign · advanced · ~22 min
- 06OSPF area troubleshooting — LSDB inconsistencies, area mismatch, stuck states, NSSA issuesTroubleshooting · advanced · ~22 min
Part XXI
OSPFv3 / IPv6 Routing
OSPFv3 for IPv6, differences from OSPFv2, current VyOS support.
- 01OSPFv3 concept — IPv6 link-state, link-local source, per-link semanticsIPv6 routing · advanced · ~22 min
- 02OSPFv3 configuration — router-id, area assignment, interface parameters, IPv6-onlyIPv6 routing · advanced · ~24 min
- 03OSPFv3 vs OSPFv2 — protocol differences, address family separation, new LSA types, R-bitIPv6 routing · advanced · ~24 min
- 04OSPFv3 troubleshooting — neighbour stuck, link-local issues, LSDB inconsistencies, IPv6 ACLsIPv6 routing · advanced · ~22 min
- 05Dual-stack OSPF — running OSPFv2 and OSPFv3 on the same networkIPv6 routing · advanced · ~24 min
- 06OSPFv3 with BGP — BGP carrying OSPFv3 routes, IPv6 NLRI, route-map filteringIPv6 routing · advanced · ~24 min
Part XXII
OSPF Troubleshooting
Neighbour states, MTU mismatch, area mismatch, authentication, timers, network type, duplicate router ID, missing routes.
- 01Neighbour stuck in EXSTART / EXCHANGE / Loading — MTU, DD exchange, LSR retransmissionDiagnostics · advanced · ~24 min
- 02MTU mismatch — DF bit, fragmentation, `ip ospf mtu-ignore`, vendor behaviourDiagnostics · advanced · ~22 min
- 03Area mismatch — hello area field, type 1 mismatch, summary vs external in stubDiagnostics · advanced · ~22 min
- 04OSPF authentication — simple-text, MD5, SHA, key-id mismatch, key chain timingDiagnostics · advanced · ~22 min
- 05Duplicate router-id — Type 1 LSA conflict, why uniqueness matters, recoveryDiagnostics · advanced · ~22 min
- 06Missing route — SPF not running, summarisation hiding route, LSA not flooded, area filterDiagnostics · advanced · ~24 min
Part XXIII
BGP Fundamentals
AS numbers, eBGP, iBGP, sessions, route advertisement, best path, path-vector model.
- 01Autonomous system numbersBGP · intermediate · ~24 min
- 02eBGP and iBGPBGP · intermediate · ~23 min
- 03Path-vector routing and AS_PATHBGP · intermediate · ~24 min
- 04BGP RIB and FRR table architectureBGP · advanced · ~25 min
- 05BGP best-path decisionBGP · advanced · ~27 min
- 06BGP session lifecycleBGP · advanced · ~26 min
Part XXIV
BGP Session Establishment
Idle / Connect / Active / OpenSent / OpenConfirm / Established, TCP 179, source addresses, multihop, TTL, authentication.
- 01BGP configuration foundationsSessions · advanced · ~25 min
- 02BGP neighbour identity and source addressSessions · advanced · ~24 min
- 03BGP timers and advertisement intervalsSessions · advanced · ~26 min
- 04BGP authentication and GTSMSessions · advanced · ~28 min
- 05eBGP multihop and peer groupsSessions · advanced · ~27 min
- 06BGP session troubleshootingSessions · advanced · ~30 min
Part XXV
BGP Route Advertisement
Network origination, redistribution, aggregates, default route advertisement, risks of advertising more than intended.
- 01The BGP network statement — origin and exact-match semanticsAdvertisement · advanced · ~22 min
- 02BGP aggregation — aggregate-address, summary-only, and as-setAdvertisement · advanced · ~24 min
- 03Redistributing static routes into BGP — metric, route-map, and route leakAdvertisement · advanced · ~22 min
- 04Redistributing OSPF into BGP — E1/E2 metric types, route-maps, and feedbackAdvertisement · advanced · ~24 min
- 05BGP conditional advertisement — advertise-map and non-exist-mapAdvertisement · advanced · ~24 min
- 06BGP advertisement troubleshooting — prefix not advertised, route-map blocking, next-hop unreachableAdvertisement · advanced · ~26 min
Part XXVI
BGP Attributes
Local preference, AS path, origin, MED, next hop, weight, communities.
- 01Local preference — the iBGP outbound path selectorAttributes · advanced · ~24 min
- 02AS path — prepend, aggregation loss, and the loop preventionAttributes · advanced · ~24 min
- 03BGP origin — IGP, EGP, and incomplete in FRRAttributes · advanced · ~20 min
- 04BGP MED — multi-exit discriminator, eBGP-only, and always-compare-medAttributes · advanced · ~22 min
- 05BGP communities — well-known, extended, and largeAttributes · advanced · ~26 min
- 06BGP attribute anti-patterns — missing local-preference, MED oscillation, attribute loss on aggregationAttributes · advanced · ~24 min
Part XXVII
BGP Best Path
Best-path decision process, visual exercises, validation against FRR behaviour.
- 01The 11-step BGP best-path algorithm — how FRR decides which route winsBest path · advanced · ~24 min
- 02The Weight attribute — a local-only tie-breaker, per-neighbour and per-prefixBest path · advanced · ~18 min
- 03AS Path prepending — making your own AS path look longer to influence inbound trafficBest path · advanced · ~20 min
- 04Origin and MED — the IGP/EGP/incomplete origin and the MED tie-break between same-AS pathsBest path · advanced · ~22 min
- 05IGP cost tiebreak — when AS Path and other attributes tie, lowest IGP cost to next-hop winsBest path · advanced · ~18 min
- 06BGP best-path troubleshooting — missing routes, suboptimal path, why MED is ignoredBest path · advanced · ~24 min
Part XXVIII
BGP Prefix Filtering
Prefix lists, route maps, inbound filters, outbound filters, default deny, route leaks.
- 01Prefix-list semantics — ordered, sequential, ge/le/exact-match, implicit denyPrefix filters · intermediate · ~18 min
- 02Prefix-list configuration — sequence numbers, ge/le operators, descriptions, hit countersPrefix filters · intermediate · ~20 min
- 03Distribute-list — applying an ACL or prefix-list to a BGP neighbour in/outPrefix filters · intermediate · ~16 min
- 04AS-path filter-list — regex matching on AS_PATH for BGP neighbour filteringPrefix filters · advanced · ~18 min
- 05Maximum-prefix — bounding the number of prefixes a BGP peer can sendPrefix filters · intermediate · ~16 min
- 06Filter troubleshooting — prefix not received, prefix not advertised, regex errors, AS-path-list syntaxPrefix filters · advanced · ~22 min
Part XXIX
BGP Communities
Standard communities, operational tagging, upstream policy, blackholing concepts.
- 01BGP communities — the optional transitive attribute, the AA:NN format, and well-known communitiesCommunities · advanced · ~22 min
- 02Configuring community-lists and route-maps — set community add, replace, and the choice VyOS makes you stateCommunities · advanced · ~24 min
- 03Large communities — RFC 8092, the 12-byte format, and the 4-byte ASN problemCommunities · advanced · ~22 min
- 04Extended communities — the 8-byte format, MPLS VPN RT/RD, and link-bandwidthCommunities · advanced · ~24 min
- 05Community-driven policy — matching communities to set local-pref, AS-path prepend, MED, and geographic taggingCommunities · advanced · ~26 min
- 06Community troubleshooting — community not propagated, transitive vs non-transitive, regex matchingCommunities · advanced · ~24 min
Part XXX
BGP Route Reflectors
iBGP scaling, full mesh, route reflectors, clients, cluster concepts.
- 01iBGP full-mesh problem — why IBGP requires a full mesh, what the route reflector solves, and the loop-prevention trio (originator-id, cluster-list, cluster-id)Route reflectors · advanced · ~26 min
- 02Route reflector configuration — `route-reflector-client`, the two-RR cluster, and the canonical client/server meshRoute reflectors · advanced · ~24 min
- 03Cluster-id — the deduplication key, and why it decides how your clients must peerRoute reflectors · advanced · ~22 min
- 04Confederations — sub-AS, AS_CONFED segments, eBGP-within-confederation, and when to use RR vs confederationConfederations · advanced · ~24 min
- 05Multipath-relax — `bestpath as-path multipath-relax`, the identical-AS_PATH default, and eBGP/iBGP multipathMultipath · advanced · ~22 min
- 06Route reflector troubleshooting — missing client flag, loop-guard rejections, and the attributes an RR must not touchRoute reflectors · advanced · ~26 min
Part XXXI
BGP Troubleshooting
Session down, route not received, route received but not selected, route selected but not installed, prefix filtered, next hop unreachable, AS path issue, route leak.
- 01BGP session states — Idle, Connect, Active, OpenSent, OpenConfirm, Established, and the Notification codes that knock a peer out of eachTroubleshooting · advanced · ~24 min
- 02BGP routes missing — not received, not advertised, not installedTroubleshooting · advanced · ~24 min
- 03BGP session flapping — interface, route-flap damping, BFD, peer resetTroubleshooting · advanced · ~24 min
- 04BGP route oscillation — next-hop resolution, MED, and reflectorsTroubleshooting · advanced · ~24 min
- 05BGP blackhole — route leak, prefix hijack, RPKI invalid, BGP dampeningTroubleshooting · advanced · ~24 min
- 06BGP performance — MRAI, route-refresh, soft-reconfiguration, ORF, large BGP tablesTroubleshooting · advanced · ~24 min
Part XXXII
BFD
Bidirectional Forwarding Detection, integration with BGP and OSPF, static-route tracking.
- 01BFD concept — Bidirectional Forwarding Detection, sub-second failure detection, control-plane independentBFD · advanced · ~24 min
- 02BFD configuration — protocols bfd, peer configuration, transmit/receive interval, multiplierBFD · advanced · ~24 min
- 03BFD with BGP — neighbor bfd, sub-second failure detection, and the profile that owns the timersBFD · advanced · ~24 min
- 04BFD with OSPF — ip ospf bfd, sub-second OSPF failure detection, faster SPFBFD · advanced · ~24 min
- 05BFD with static routes — tracking a static next-hop, and the distance that makes it a fallbackBFD · advanced · ~24 min
- 06BFD troubleshooting — session down, misconfigured timers, asymmetric intervalsBFD · advanced · ~24 min
Part XXXIII
Route Policy
Prefix lists, route maps, community lists, policy evaluation order, named policies.
- 01Policy concept — the vocabulary, the building blocks, the evaluation orderPolicy primitives · advanced · ~22 min
- 02Prefix-list — sequence, ge, le, exact-match, deny vs permitPrefix-list · advanced · ~24 min
- 03Community-list — standard, expanded, and regular-expression matchingCommunity-list · advanced · ~22 min
- 04AS-path-list — regular-expression matching over the BGP AS_PATH attributeAS-path-list · advanced · ~24 min
- 05Route-map composition — match and set clauses, sequence ordering, implicit denyRoute-map composition · advanced · ~28 min
- 06Policy validation — testing with vtysh, clearing route-maps, sequence numbering gotchasPolicy validation · advanced · ~20 min
Part XXXIV
Route Redistribution
Redistributing static, OSPF, BGP, connected; loops, feedback, tagging, filtering, administrative distance.
- 01Redistribution concept — why redistribute, route-map filtering, metric preservation, seed metricRedistribution primitives · advanced · ~24 min
- 02Redistributing static into BGP — route-map filtering, seed metric, community tagsStatic redistribution · advanced · ~22 min
- 03Redistributing OSPF into BGP — what survives the boundary, the MED, and feedback preventionOSPF redistribution · advanced · ~26 min
- 04Redistributing connected routes — physical interface routes, when to include, when to excludeConnected redistribution · advanced · ~20 min
- 05Redistributing kernel routes — what `redistribute kernel` really carries, and why it is rarely the right answerKernel redistribution · advanced · ~18 min
- 06Redistribution anti-patterns — bidirectional loops, missing tags, suboptimal pathsRedistribution anti-patterns · advanced · ~26 min
Part XXXV
Route Summarisation
Aggregation, summary routes, blackhole/discard supporting routes, failure implications.
- 01Route summarisation concept — aggregation, prefix length, route-map filteringSummarisation · advanced · ~22 min
- 02BGP aggregation — aggregate-address, summary-only, as-set, attribute inheritanceSummarisation · advanced · ~26 min
- 03OSPF summarisation — area range, ABR summarisation, totally-stubby areaSummarisation · advanced · ~24 min
- 04RIPv2 summarisation — default-metric, automatic classful-boundary summarySummarisation · intermediate · ~18 min
- 05Blackhole routes for summary prefixes — null0, discard, loop preventionSummarisation · intermediate · ~18 min
- 06Summarisation troubleshooting — missing summaries, more-specific leaks, attribute lossSummarisation · advanced · ~22 min
Part XXXVI
ECMP
Equal-cost paths, hashing, per-flow behaviour, failure handling, troubleshooting implications.
- 01ECMP concept — Equal-Cost Multi-Path, kernel flow-based or route-based hashing, throughput scalingECMP · advanced · ~20 min
- 02ECMP configuration — multiple next-hops, max-paths, load-balancing algorithmECMP · advanced · ~22 min
- 03BGP ECMP — maximum-paths, eBGP/iBGP, multipath-relax, AS_PATH length requirementECMP · advanced · ~24 min
- 04OSPF ECMP — equal-cost behaviour, default configuration, when ECMP appliesECMP · advanced · ~18 min
- 05Per-class ECMP — policy routes, alternate tables, and the fwmark VyOS ownsECMP · advanced · ~20 min
- 06ECMP troubleshooting — only one path used, asymmetric traffic, next-hop unreachableECMP · advanced · ~24 min
Part XXXVII
Firewall Fundamentals
VyOS stateful firewall, zones, input, forward, output, state tracking, conntrack.
- 01Stateful vs stateless filtering — conntrack, NEW/ESTABLISHED/RELATED, the performance argumentStateful vs stateless · advanced · ~22 min
- 02Zones and chains — base chains, named rule-sets, `firewall zone`, and jump targetsZones and chains · advanced · ~22 min
- 03Rule ordering — sequence numbers, first-match, action accept/drop/rejectRule ordering · intermediate · ~20 min
- 04State tracking — connection marks, recent, and the limits of the conntrack matchesState tracking · advanced · ~24 min
- 05Default deny — WAN-IN posture, established accept, INVALID log, the production reference architectureDefault deny · advanced · ~24 min
- 06Firewall troubleshooting — log, conntrack, packet capture, the diagnostic methodFirewall troubleshoot · advanced · ~26 min
Part XXXVIII
NAT Fundamentals
SNAT, DNAT, masquerade, port forwarding, 1:1 mappings.
- 01SNAT vs DNAT concept — source vs destination NAT, the kernel nftables primitivesSNAT vs DNAT concept · advanced · ~22 min
- 02Masquerade — dynamic source NAT for the WAN interfaceMasquerade · intermediate · ~20 min
- 03Port forwarding — DNAT, translation table, hairpin NAT, firewall rulesPort forwarding · advanced · ~24 min
- 04One-to-one NAT — 1:1 static NAT, both directions, no conntrack asymmetryOne-to-one NAT · advanced · ~22 min
- 05NAT with firewall — rule placement, established match, conntrack interactionNAT with firewall · advanced · ~22 min
- 06NAT troubleshooting — hairpin failure, port exhaustion, asymmetric routing, conntrack flushNAT troubleshoot · advanced · ~24 min
Part XXXIX
Multi-WAN
Multiple defaults, failover, load distribution, policy routing, health checking.
- 01Multi-WAN concept — the three mechanisms VyOS actually offers, and the asymmetry each one createsMulti-WAN concept · advanced · ~22 min
- 02WAN failover — the floating static design, the load-balancer design, and why they are verified differentlyWAN failover · advanced · ~24 min
- 03WAN load sharing — ECMP across two circuits, and what the hash seesWAN load sharing · advanced · ~22 min
- 04WAN policy routing — policy route rule-sets, alternate tables, and the mark that gets overwrittenWAN policy routing · advanced · ~24 min
- 05WAN health check — the three test types VyOS ships, the counters that replace a threshold, and the targets worth probingWAN health check · advanced · ~22 min
- 06Multi-WAN troubleshoot — which mechanism is in play, marks, conntrack, asymmetry, hairpinMulti-WAN troubleshoot · advanced · ~28 min
Part XL
VRRP High Availability
Virtual router, virtual IP, MASTER/BACKUP, priority, advertisements, preemption, tracking.
- 01VRRP concept — Virtual Router Redundancy Protocol, master/backup, virtual MACVRRP · advanced · ~22 min
- 02VRRP priority and skew — how election really works, the master-down-interval calculationVRRP · advanced · ~18 min
- 03VRRP preemption — higher priority takes over, and when to disable itVRRP · advanced · ~16 min
- 04VRRP advertisements — packet format, IP protocol 112, multicast 224.0.0.18VRRP · advanced · ~16 min
- 05VRRP tracking — decrement priority on link failure, react to upstream stateVRRP · advanced · ~20 min
- 06VRRP troubleshooting — split-brain, both-master, asymmetric traffic, missed electionsVRRP · advanced · ~24 min
Part XLI
WireGuard
Keys, peers, allowed IPs, routing, firewall, site-to-site, remote access.
- 01WireGuard concept — kernel WireGuard, Noise protocol, UDP-based VPNWireGuard · advanced · ~18 min
- 02WireGuard keys — Curve25519 key pairs, preshared key, key managementWireGuard · advanced · ~18 min
- 03WireGuard peers — named peers, allowed-ips, peer address and port, persistent keepaliveWireGuard · advanced · ~20 min
- 04WireGuard routing — routing over WireGuard, MTU 1420, MSS clampingWireGuard · advanced · ~22 min
- 05WireGuard firewall and outer-packet routing — UDP port, input chain, multi-WANWireGuard · advanced · ~18 min
- 06WireGuard troubleshooting — handshake never happens, allowed-ips mismatch, MTU issuesWireGuard · advanced · ~22 min
Part XLII
IPsec
IKE, ESP, peers, tunnels, route-based VTI, NAT-T, modern proposals.
- 01IPsec concept — IKE, ESP, transport vs tunnel mode, the IPsec suiteIPsec · advanced · ~22 min
- 02IKEv2 — Internet Key Exchange v2, RFC 7296, MOBIKE, EAP authenticationIPsec · advanced · ~20 min
- 03ESP proposals — ciphers, integrity, DH/PFS groups, configurationIPsec · advanced · ~18 min
- 04Route-based VTI — Virtual Tunnel Interface, route-based IPsec, ip xfrmIPsec · advanced · ~22 min
- 05NAT-T — NAT traversal for IPsec, UDP 4500 encapsulationIPsec · advanced · ~16 min
- 06IPsec troubleshooting — IKE debug, ESP debug, MTU, PFS mismatchIPsec · advanced · ~24 min
Part XLIII
VPN Routing
Static routes over tunnels, BGP/OSPF over tunnels, route propagation, failover.
- 01VPN routing basics — routing over tunnels, recursive routing, BGP/OSPF over VPNVPN Routing · advanced · ~22 min
- 02BGP over VPN — iBGP over WireGuard or IPsec, peer addresses, route reflectionVPN Routing · advanced · ~22 min
- 03OSPF over VPN — the multicast problem, NBMA with static neighbours, and area designVPN Routing · advanced · ~22 min
- 04VPN failover — why a tunnel route never withdraws itself, BFD on the next-hop, and ECMPVPN Routing · advanced · ~22 min
- 05VPN MTU — tunnel MTU, MSS clamping, fragmentationVPN Routing · advanced · ~22 min
- 06VPN routing validation — end-to-end, asymmetric, BGP convergenceVPN Routing · advanced · ~22 min
Part XLIV
VXLAN
VNI, encapsulation, underlay, overlay, when VXLAN belongs in network design.
- 01VXLAN concept — RFC 7348, VNI 24-bit, UDP 4789, overlay networkingVXLAN · advanced · ~22 min
- 02VXLAN VNI — 24-bit namespace, tenant segmentation, VNI assignmentVXLAN · advanced · ~18 min
- 03VXLAN underlay — underlay routing, MTU 1550, jumbo framesVXLAN · advanced · ~18 min
- 04VXLAN with BGP EVPN — EVPN Type-2/3/5 routes, BGP as control planeVXLAN · advanced · ~24 min
- 05VXLAN without EVPN — flood-and-learn, multicast underlayVXLAN · advanced · ~16 min
- 06VXLAN troubleshooting — VNI mismatch, underlay MTU, EVPN routes that never arriveVXLAN · advanced · ~22 min
Part XLV
QoS Fundamentals
Classification, marking, queuing, shaping, policing, DSCP, trust boundaries.
- 01QoS concept — traffic classes, scheduling, the QoS pipelineQoS · advanced · ~22 min
- 02DSCP marking — RFC 2474, the DiffServ field, PHB classificationsQoS · advanced · ~18 min
- 03Classification and matching — filters, match rules, fwmark, QoS classesQoS · advanced · ~20 min
- 04Queuing and shaping — HTB tree, fq_codel leaves, bandwidth shapingQoS · advanced · ~20 min
- 05Trust boundaries — trust at access, untrusted at WAN, the operator's disciplineQoS · advanced · ~18 min
- 06QoS troubleshooting — latency, jitter, packet loss, the diagnostic flowQoS · advanced · ~22 min
Part XLVI
DHCP Services
DHCP server scopes, static mappings, options, relay, IPv6 DHCPv6.
- 01DHCPv4 server — shared-network, subnet, range, optionsDHCP · intermediate · ~22 min
- 02DHCPv4 static-mapping — fixed address by MAC, hostname, reservationsDHCP · intermediate · ~18 min
- 03DHCPv4 relay — forwarding across segments, giaddr, the relay loop failure modeDHCP · advanced · ~20 min
- 04DHCPv6 server — stateful IA_NA, prefix delegation IA_PD, the broadband CPE patternDHCP · advanced · ~24 min
- 05DHCP troubleshooting — lease exhaustion, conflict detection, relay loops, silent failuresDHCP · advanced · ~24 min
- 06DHCP monitoring — lease statistics, syslog export, Prometheus exporterDHCP · intermediate · ~20 min
Part XLVII
Management Plane Hardening
SSH, console, API, source restrictions, management VRF, out-of-band access.
- 01SSH hardening — key-only auth, port, listen-address, mgmt VRFMgmtPlane · intermediate · ~22 min
- 02HTTP API authentication — keys, localhost binding, TLS, the gRPC alternativeMgmtPlane · intermediate · ~20 min
- 03Source restrictions — listen-address, allow-client, and the firewall input chainMgmtPlane · intermediate · ~18 min
- 04Out-of-band access — OOB management VRF, console server, IPMI, the lockout safety netMgmtPlane · intermediate · ~20 min
- 05User roles — RBAC, privilege levels, the role-per-concern patternMgmtPlane · intermediate · ~18 min
- 06PKI and certificate rotation — x509, ACME, Let's Encrypt, the rotation scheduleMgmtPlane · advanced · ~24 min
Part XLVIII
Logging and Remote Syslog
Local logs, routing daemon logs, firewall logs, VPN logs, remote syslog forwarding.
- 01Local logging — rsyslog, journald, logrotate, retentionLogging · intermediate · ~18 min
- 02Routing daemon logs — zebra, bgpd, ospfd, the log-level configurationLogging · intermediate · ~18 min
- 03Firewall logs — default-log, the prefix VyOS generates, and reading the entriesLogging · intermediate · ~18 min
- 04VPN logs — IKE logs, charon, WireGuard, the diagnostic captureLogging · intermediate · ~22 min
- 05Remote syslog — RFC 5425 TLS syslog, the central server, the failoverLogging · advanced · ~22 min
- 06Log validation — log integrity, SIEM ingestion, retention policyLogging · advanced · ~22 min
Part XLIX
Monitoring and Observability Integration
Interface metrics, BGP/OSPF telemetry, route counts, CPU, memory, SNMP, exporters.
- 01Interface metrics — SNMP, NETCONF, gNMI, and the Prometheus exporterMonitoring · advanced · ~28 min
- 02BGP telemetry — BMP, RIB monitoring, and FRR streaming stateMonitoring · advanced · ~28 min
- 03OSPF telemetry — LSDB export, SPF runtimes, and FRR per-LSA monitoringMonitoring · advanced · ~26 min
- 04VRRP telemetry — master/backup state, gratuitous ARP, and failover event auditingMonitoring · advanced · ~24 min
- 05System metrics — CPU, memory, disk, temperature, and the prometheus-vyos-exporterMonitoring · advanced · ~26 min
- 06Prometheus exporters — textfile collector, custom scripts, and the SNMP exporterMonitoring · advanced · ~26 min
Part L
Performance Troubleshooting
CPU saturation, interrupts, packet drops, NIC limits, crypto performance, route churn.
- 01CPU saturation — top, mpstat, softirq vs hardirq vs userspace, Linux schedulerPerformance · advanced · ~26 min
- 02Interrupt affinity — /proc/irq, RSS, NUMA, IRQBALANCE_BANNED_CPUSPerformance · advanced · ~24 min
- 03Packet drops — softnet_stat, per-NIC counters, drop reasonsPerformance · advanced · ~22 min
- 04Crypto performance — AES-NI offload, IPsec throughput, kTLS, single-core bottleneckPerformance · advanced · ~26 min
- 05Route churn — FRR zebra CPU, route-flap, iBGP convergence, OSPF SPFPerformance · advanced · ~24 min
- 06Performance baselines — pbench, record baselines, alert on deviation, golden imagePerformance · advanced · ~24 min
Part LI
MTU and Fragmentation
Ethernet MTU, tunnels, IPsec overhead, WireGuard overhead, PMTUD, MSS clamping.
- 01MTU basics — 1500 default, jumbo 9000, 802.1Q tag 4 bytes, IPv6 minimum 1280MTU · advanced · ~24 min
- 02Tunnel overhead — WireGuard 32-80, IPsec 50-66, GRE 24, VXLAN 50MTU · advanced · ~26 min
- 03PMTUD — RFC 1191, RFC 8201, ICMP Frag Needed, black hole detection, MTU 1280 floorMTU · advanced · ~24 min
- 04MSS clamping — ip adjust-mss, MSS = MTU - 40, clamp-mss-to-pmtu, and which interface to clamp onMTU · advanced · ~22 min
- 05MTU and fragmentation troubleshoot — ping -M do -s, tracepath, ICMP filteringMTU · advanced · ~24 min
- 06MTU validation — end-to-end verification, jumbo on all path, sub-interface alignmentMTU · advanced · ~22 min
Part LII
Troubleshooting Methodology
Define source/destination, expected path, interface state, addressing, route, policy, firewall, NAT, capture, return path.
- 01Define and scope — ticket triage, scope boundaries, who is affectedTroubleshooting · advanced · ~22 min
- 02Evidence first — collect before changing, write down symptoms, no action without dataTroubleshooting · advanced · ~20 min
- 03Hypothesis-driven — generate hypotheses, test each, bisection, post-mortemTroubleshooting · advanced · ~24 min
- 04Subsystem by subsystem — kernel, FRR, firewall, interface, application, isolate layerTroubleshooting · advanced · ~24 min
- 05Return-path — forward and reverse, asymmetric routing, return-path sanityTroubleshooting · advanced · ~22 min
- 06Troubleshooting anti-patterns — reboot before evidence, blame the firewall, cargo-cult configsTroubleshooting · advanced · ~24 min
Part LIII
Security Hardening
Routing protocol authentication, max-prefix, prefix filtering, RPKI concepts, control-plane protection, management hardening.
- 01Routing protocol authentication — what VyOS actually exposes, and what it does notSecurity · advanced · ~28 min
- 02max-prefix as a security control — bounding a peer, and the outage it trades forSecurity · advanced · ~22 min
- 03Prefix filtering — prefix-list, AS-path, RPKI invalid, and the leak firewallSecurity · advanced · ~26 min
- 04RPKI — Route Origin Authorisation, validation cache, and route validationSecurity · advanced · ~28 min
- 05Control-plane protection — the input chain, BGP TTL security (GTSM), and authentication on every peerSecurity · advanced · ~24 min
- 06Router hardening checklist — configuration review, OOB management, audit logSecurity · advanced · ~22 min
Part LIV
API and Automation
VyOS HTTP API, Ansible integration, configuration-as-code, automated validation, change management.
- 01VyOS HTTP API — the /configure endpoint, key authentication, and one commit per requestAutomation · advanced · ~26 min
- 02VyOS Ansible integration — vyos.vyos collection over network_cli, modules, idempotent playbooksAutomation · advanced · ~28 min
- 03Configuration as code — Git repository, Jinja2 templates, render and applyAutomation · advanced · ~28 min
- 04Automated validation — pre-commit hooks, smoke tests, rollback on failureAutomation · advanced · ~24 min
- 05Change management — ticket, peer review, audit log, post-deploy verificationAutomation · advanced · ~22 min
- 06Automation anti-patterns — skip review, run-and-pray, no rollback pathAutomation · advanced · ~22 min
Part LV
Backup, Restore, Disaster Recovery
Saved configuration, remote backups, replacement appliance recovery, lost router recovery.
- 01Saved configuration — /config/config.boot, scp, off-box copy, versioningBackup · foundation · ~18 min
- 02Remote backup — cron + rsync, version control commit, S3 bucketBackup · intermediate · ~22 min
- 03Restore onto the same appliance — load saved, verify, commit, saveBackup · intermediate · ~18 min
- 04Restore onto a different appliance — hardware replacement, configuration migration, IP changesBackup · advanced · ~24 min
- 05Full router loss — RMA, replacement, restore, verify adjacencyBackup · advanced · ~22 min
- 06DR validation — quarterly DR drill, full restore, scenario testBackup · advanced · ~20 min
Part LVI
Software Images and Production Upgrades
Image management, rolling upgrade sequencing, FRRouting compatibility, rollback.
- 01Image management — dual-image model, add system image, alt slotUpgrades · intermediate · ~22 min
- 02Rolling upgrade — dual-router topology, upgrade one at a time, verify trafficUpgrades · advanced · ~24 min
- 03FRR compatibility — what an FRR version bump changes on VyOS, and what it does notUpgrades · advanced · ~24 min
- 04Upgrade validation — lab test, staged rollout, monitoringUpgrades · advanced · ~22 min
- 05Upgrade rollback — dual-image, automatic, manual, verify alt bootUpgrades · advanced · ~22 min
- 06Upgrade anti-patterns — skip lab test, no rollback, double-firmware upgradeUpgrades · advanced · ~20 min
Part LVII
Production Reference Architecture
A realistic dual-ISP BGP VRF-segmented VyOS estate with VPN, monitoring, backup, and DR.
- 01Reference topology — a complete dual-DC, dual-router VyOS production estateReference Architecture · advanced · ~32 min
- 02Reference rationale — design decisions, trade-offs, and why the topology is shaped this wayReference Architecture · advanced · ~28 min
- 03Reference failure domains — blast radius, isolation, and failover for every layerReference Architecture · advanced · ~30 min
- 04Reference monitoring — Prometheus, Grafana, Loki, and Tempo for the production estateReference Architecture · advanced · ~28 min
- 05Reference DR — backup strategy, RTO, RPO, and quarterly drillsReference Architecture · advanced · ~26 min
- 06Reference validation — end-to-end smoke tests, change windows, and the rollout disciplineReference Architecture · advanced · ~26 min
Part Labs
Hands-On Labs
Disposable-virtualisation labs covering install, routing, BGP, OSPF, VRFs, firewall, NAT, VPN, VRRP, automation, backup, recovery.
No lessons published in this part yet. The full curriculum is planned in docs/courses/vyos/curriculum.md on GitHub.
Part Runbooks
Operational Runbooks
Operational procedures: deploy, troubleshoot, change, fail over, restore, recover.
Part Checklists
Production Checklists
Printable readiness, change, and review checklists.
Part Break/Fix
Break/Fix Scenarios
Deliberate operational incidents with evidence-first diagnosis.
Part Capstone
Capstone: Production VyOS Estate
A complete dual-ISP BGP VRF-segmented VyOS estate with VPN, VRRP, monitoring, backup, and validated DR.
No lessons published in this part yet. The full curriculum is planned in docs/courses/vyos/curriculum.md on GitHub.
Part Final
Final Assessment
Theory and practical assessment of every production competency.
No lessons published in this part yet. The full curriculum is planned in docs/courses/vyos/curriculum.md on GitHub.