Network
Administration
SKILL
AREAS
AT
A
G LANCE
01
Networking
Fundamentals
02
Routing
&
Switching
03
Network
Security
04
Wireless
Networking
05
Monitoring
&
Diagnostics
06
Servers
&
Directory
Services
07
Virtualization
&
Cloud
08
Automation
&
Scripting
09
Cabling
&
Infrastructure
10
Operations
&
Recovery
01
Networking
Fundamentals
7
skills
02
Routing
&
Switching
6
skills
OSI
&
TCP
/
IP
models
—
Layer
-
by
-
layer
fault
isolation
and
protocol
mapping
IPv
4 &
IPv
6
addressing
—
Address
planning
,
dual
-
stack
deployment
,
SLAAC
,
and
prefix
delegation
Subnetting
&
CIDR
notation
—
Variable
-
length
masks
,
route
summarization
,
and
address
conservation
VLANs
&
trunking
—
802.1
Q
tagging
,
native
VLAN
design
,
and
inter
-
VLAN
routing
Ethernet
switching
&
spanning
tree
—
MAC
address
tables
,
STP
/
RSTP
/
MSTP
,
loop
prevention
Core
network
services
—
DNS
zone
design
,
DHCP
scope
configuration
,
NTP
synchronization
NAT
&
PAT
—
Static
and
dynamic
translation
,
overload
pools
,
port
forwarding
Dynamic
routing
protocols
—
OSPF
,
EIGRP
,
and
BGP
configuration
,
tuning
,
and
redistribution
Static
routing
&
route
tables
—
Default
routes
,
floating
statics
,
administrative
distance
,
policy
routing
Layer
2 /
Layer
3
switching
—
Port
channels
(
LACP
),
switch
stacks
,
QoS
marking
and
queuing
WAN
edge
technologies
—
MPLS
,
SD
-
WAN
overlays
,
tunnel
interfaces
,
and
path
selection
policy
First
-
hop
redundancy
—
HSRP
,
VRRP
,
and
GLBP
gateway
failover
design
and
testing
Device
OS
&
CLI
administration
—
Cisco
IOS
/
NX
-
OS
,
Junos
,
and
Aruba
CLI
configuration
and
image
management
1 / 3
03
Network
Security
7
skills
04
Wireless
Networking
5
skills
05
Monitoring
&
Diagnostics
6
skills
06
Servers
&
Directory
Services
5
skills
Firewall
administration
—
Rule
-
set
design
and
rule
hygiene
on
Palo
Alto
,
Fortinet
,
and
Cisco
ASA
IDS
/
IPS
operations
—
Signature
tuning
,
alert
triage
,
and
inline
blocking
decisions
VPN
technologies
—
Site
-
to
-
site
IPsec
,
GRE
,
DMVPN
,
and
SSL
/
TLS
remote
-
access
concentrators
802.1
X
&
network
access
control
—
RADIUS
and
TACACS
+
authentication
,
port
security
,
guest
onboarding
Access
control
lists
—
Standard
and
extended
ACLs
,
object
groups
,
time
-
based
rules
Zero
trust
&
microsegmentation
—
Identity
-
aware
policy
and
least
-
privilege
east
-
west
segmentation
PKI
&
certificate
management
—
CA
hierarchy
,
certificate
enrollment
,
and
TLS
inspection
WLAN
design
&
site
surveys
—
Predictive
and
on
-
site
surveys
,
heat
maps
,
AP
placement
,
channel
planning
802.11
standards
—
a
/
b
/
g
/
n
/
ac
/
ax
(
Wi
-
Fi
6
and
6
E
)
capabilities
,
coexistence
,
and
tuning
Controller
&
cloud
-
managed
WLAN
—
Cisco
WLC
,
Aruba
Central
,
and
Meraki
dashboard
administration
RF
troubleshooting
—
Interference
analysis
,
SNR
,
channel
utilization
,
and
roaming
behavior
Wireless
security
—
WPA
2/
WPA
3-
Enterprise
,
PSK
rotation
,
and
rogue
AP
detection
SNMP
&
syslog
—
Polling
design
,
trap
handling
,
and
centralized
log
collection
Monitoring
platforms
—
PRTG
,
SolarWinds
NPM
,
Zabbix
,
Nagios
,
and
LibreNMS
deployment
Packet
analysis
—
Wireshark
and
tcpdump
capture
,
SPAN
ports
,
and
protocol
decode
Flow
analysis
—
NetFlow
,
sFlow
,
and
IPFIX
collection
for
traffic
and
capacity
reporting
Performance
baselining
—
Latency
,
jitter
,
throughput
,
and
packet
-
loss
thresholds
per
link
Fault
isolation
—
Ping
,
traceroute
,
path
MTU
discovery
,
and
layered
troubleshooting
method
Windows
Server
administration
—
Server
roles
,
Group
Policy
,
DNS
and
DHCP
integration
,
patching
Active
Directory
—
Forest
and
domain
design
,
OU
structure
,
replication
,
trust
relationships
Linux
administration
—
systemd
services
,
network
stack
configuration
,
iptables
and
nftables
File
&
print
services
—
SMB
and
NFS
share
design
,
permission
models
,
and
quotas
Identity
&
access
management
—
Entra
ID
,
LDAP
,
and
SSO
federation
with
network
authentication
2 / 3
07
Virtualization
&
Cloud
Networking
5
skills
08
Automation
&
Scripting
5
skills
09
Cabling
&
Physical
Infrastructure
5
skills
10
Operations
,
Documentation
&
Recovery
5
skills
Hypervisor
networking
—
VMware
vSphere
and
Hyper
-
V
virtual
switches
,
VLAN
trunks
to
hosts
Cloud
network
design
—
AWS
VPC
,
Azure
VNet
,
and
GCP
VPC
subnets
,
route
tables
,
security
groups
Hybrid
connectivity
—
ExpressRoute
,
Direct
Connect
,
and
cloud
site
-
to
-
site
VPN
tunnels
Container
&
overlay
networking
—
Docker
bridge
networks
,
Kubernetes
CNI
plugins
,
service
mesh
basics
Software
-
defined
networking
—
Cisco
ACI
and
VMware
NSX
fabric
configuration
and
policy
Python
for
networking
—
Netmiko
,
NAPALM
,
Paramiko
,
and
REST
API
integration
workflows
Ansible
&
Terraform
—
Playbook
-
driven
device
configuration
and
infrastructure
as
code
Configuration
management
—
Golden
config
templates
,
compliance
checks
,
and
drift
detection
Model
-
driven
interfaces
—
RESTCONF
,
NETCONF
,
YANG
models
,
and
streaming
telemetry
Git
&
version
control
—
Network
configuration
repository
workflow
,
peer
review
,
and
rollback
Structured
cabling
—
TIA
/
EIA
-568
standards
,
patch
-
panel
termination
,
and
labeling
schemes
Copper
&
fiber
media
—
Cat
5
e
/6/6
A
,
single
-
mode
and
multi
-
mode
fiber
,
LC
/
SC
connectors
,
transceivers
Rack
&
power
management
—
UPS
sizing
,
PDU
layout
,
airflow
,
and
thermal
planning
Data
center
topology
—
Top
-
of
-
rack
and
end
-
of
-
row
design
,
cross
-
connects
,
redundant
paths
Cable
testing
&
certification
—
Certification
testers
,
OTDR
traces
,
and
optical
loss
budgets
Network
documentation
—
Topology
diagrams
,
IPAM
records
,
rack
elevations
,
circuit
inventory
Change
management
—
CAB
review
,
rollback
planning
,
and
scheduled
maintenance
windows
Configuration
backup
—
RANCID
or
Oxidized
deployment
and
versioned
device
backup
retention
Disaster
recovery
—
Failover
testing
,
RTO
/
RPO
targets
,
and
spare
hardware
pools
Capacity
planning
—
Port
utilization
trending
,
bandwidth
forecasting
,
and
refresh
cycles
3 / 3