Cloud Networking Fundamentals for Infrastructure Teams Training Course

5 days Cloud Computing Certificate on completion
Course codeSD-CC-011
Duration5 days
LevelIntermediate
CategoryCloud Computing
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Infrastructure teams increasingly support applications spread across cloud accounts, regions, managed services and on-premises environments. A poorly planned subnet, route table or security rule can block a deployment, expose a workload, create expensive traffic paths or make an incident difficult to diagnose. This course gives infrastructure professionals a practical foundation for designing and operating cloud networks without treating cloud networking as a simple extension of the data centre.

Participants work through the building blocks of cloud networking: CIDR planning, IP address allocation, virtual networks, subnets, route tables, internet access, NAT, security groups, network ACLs, private endpoints, DNS and load balancing. They compare common AWS and Azure patterns, assess hub-and-spoke and segmented network designs, and trace traffic through hybrid connectivity paths. The course also covers network observability, flow logs, firewall rule review and Infrastructure as Code practices for repeatable network changes.

Teaching combines instructor-led explanations with guided configuration labs, architecture reviews and incident-based troubleshooting exercises. Participants use cloud consoles, command-line tools and Terraform examples to build and test network components rather than only review diagrams. By the end of the week, each participant produces a cloud network design pack containing an IP plan, logical architecture diagram, routing and security decisions, connectivity assumptions, and an operational validation checklist that can be adapted for a live environment.

The course is particularly suited to infrastructure, systems, platform and security professionals who need enough cloud networking depth to make sound implementation and design decisions, collaborate effectively with cloud specialists, and recognise when a proposed network design introduces operational or security risk.

Course objectives

By the end of this course, participants will be able to:

  • Design a CIDR-based IP addressing plan for multi-subnet cloud workloads
  • Configure virtual networks, subnets, route tables and internet egress paths
  • Apply security groups, network ACLs and least-privilege traffic rules
  • Trace packet paths across subnets, gateways, load balancers and private endpoints
  • Compare hub-and-spoke, shared-services and segmented cloud network architectures
  • Troubleshoot connectivity failures using flow logs, DNS checks and route analysis
  • Create repeatable cloud network resources using Terraform modules and variables
  • Produce a cloud network design pack with diagrams, controls and validation tests

Benefits of attending

For you

  • Gain the practical vocabulary to participate confidently in cloud architecture and migration discussions
  • Diagnose common cloud connectivity faults without relying solely on specialist network teams
  • Build credible AWS and Azure network diagrams that explain routing, segmentation and exposure decisions
  • Add Terraform-based network provisioning evidence to a cloud infrastructure portfolio
  • Prepare for infrastructure and cloud engineering roles that require responsibility for network foundations

For your organisation

  • Reduce avoidable deployment delays caused by incorrect subnet, route or security-rule configuration
  • Improve consistency of IP planning and network segmentation across cloud projects
  • Strengthen review of internet exposure, private access and east-west traffic controls
  • Enable faster first-line investigation of cloud DNS and connectivity incidents
  • Create reusable network design and validation artefacts for project governance and handover

Target competencies

CIDR address planningCloud route designNetwork segmentationTraffic path analysisCloud network monitoringTerraform network automation

Who should attend

  • Infrastructure Engineers — who must deploy and support cloud-hosted platforms and services
  • Systems Administrators — who are moving server and application workloads into AWS or Azure
  • Network Engineers — who need to translate routing, segmentation and connectivity expertise into cloud environments
  • Cloud Support Engineers — who investigate access, DNS, routing and service connectivity incidents
  • Platform Engineers — who build secure network foundations for application delivery teams
  • Cyber Security Analysts — who review cloud traffic controls, exposure paths and network telemetry

Requirements and prerequisites

Participants should understand basic TCP/IP concepts, including IP addresses, subnet masks, default gateways, DNS, ports and common protocols such as HTTP and HTTPS. Familiarity with traditional firewall rules, VLANs or routing is useful, as is experience administering Windows or Linux systems. Participants should be comfortable using a web browser, command line and text editor. Prior AWS, Azure, Terraform or cloud certification knowledge is not required; cloud accounts and guided lab environments are provided where needed. This is a fundamentals course, but it is not designed for people with no prior IT infrastructure experience.

Training methodology

The week alternates short instructor-led technical briefings with guided labs in AWS and Azure-style environments. Participants calculate address ranges, configure virtual networks and route tables, test traffic flows, inspect DNS responses and analyse flow-log evidence. Small groups review realistic designs for a multi-tier application and a hybrid branch connection, identifying exposure, routing and cost issues. Daily exercises build towards an individual cloud network design pack. The final session includes a structured peer review and an application plan for adapting the design to participants’ own environments.

Course outline

Day 1: Cloud network foundations and addressing

  • Cloud networking responsibility boundaries and shared-responsibility considerations
  • IPv4 addressing, CIDR notation and subnet capacity calculations
  • Private address ranges and RFC 1918 allocation strategy
  • Virtual networks, virtual private clouds and regional boundaries
  • Subnet roles for application, data, management and public-facing tiers
  • DNS resolution paths and cloud-provided DNS services
  • TCP, UDP, ports and stateful versus stateless traffic filtering

Workshop: Participants create an IP addressing plan and subnet map for a three-tier application deployed across two availability zones.

Day 2: Routing, internet access and application traffic

  • Route table evaluation and longest-prefix route matching
  • Internet gateways, public IP addressing and outbound internet design
  • NAT gateways, NAT instances and private subnet egress patterns
  • Network load balancers, application load balancers and traffic distribution
  • Private endpoints and service endpoint access patterns
  • Hub-and-spoke topology and shared-services network design
  • Cross-region and cross-network connectivity options

Workshop: Participants configure and test routing for public and private application tiers, documenting each traffic path and its gateway dependency.

Day 3: Segmentation and cloud network security

  • Security groups and workload-level stateful access control
  • Network ACLs and subnet-level stateless filtering
  • Least-privilege rule design using source, destination, protocol and port
  • Public exposure assessment for cloud workloads and management interfaces
  • Micro-segmentation patterns for application and data tiers
  • Private connectivity to managed databases and platform services
  • Firewall rule review and change-control evidence

Workshop: Participants remediate an intentionally over-permissive application environment and produce a reviewed rule matrix for approved traffic flows.

Day 4: Hybrid connectivity, visibility and troubleshooting

  • Site-to-site VPN architecture and IPsec tunnel components
  • Dedicated cloud connectivity concepts and routing considerations
  • Transit gateways, virtual WANs and central connectivity services
  • Cloud DNS forwarding and split-horizon name resolution
  • Flow logs, connection logs and network telemetry interpretation
  • Route analysis, reachability testing and packet-capture techniques
  • Structured troubleshooting for DNS, routing, firewall and NAT failures

Workshop: Participants investigate a hybrid connectivity incident using route tables, DNS queries, flow-log records and a documented fault-isolation workflow.

Day 5: Automation, governance and operational design

  • Terraform providers, resources, variables and state for network deployment
  • Reusable Terraform modules for virtual networks and subnet patterns
  • Naming, tagging and account or subscription boundary conventions
  • Network change validation and rollback planning
  • Cloud network cost drivers including NAT, data transfer and cross-zone traffic
  • Architecture review criteria for resilience, security and operability
  • Network documentation, runbooks and service handover requirements

Workshop: Participants complete and present a cloud network design pack with Terraform structure, architecture diagram, rule matrix, test plan and operational handover checklist.

Tools & standards covered

AWS Management Console, Azure Portal, Terraform, Wireshark

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

You should understand basic IP addressing, subnets, DNS, ports and firewall concepts, and have some experience supporting IT infrastructure. You do not need prior AWS, Azure or Terraform experience, but the course moves quickly beyond introductory cloud terminology.

Bring a laptop capable of using a modern browser and a command-line terminal. Guided lab access is provided, and the instructor will supply Terraform examples and configuration files; local installation requirements are communicated before the course.

It is designed for both. Network engineers learn how familiar routing and segmentation concepts are implemented through cloud-native controls, while infrastructure and cloud engineers gain the network reasoning needed to design and troubleshoot environments safely.

General cloud courses survey compute, storage, identity and pricing alongside networking. This course concentrates on the decisions that determine how workloads communicate: address plans, routes, gateways, security controls, DNS, hybrid links and operational evidence.

Yes. The course identifies the common design principles behind AWS VPCs and Azure Virtual Networks, then highlights where service behaviour and terminology differ. The design pack uses provider-neutral decisions that can be mapped to either platform.

You leave with a completed cloud network design pack containing an IP plan, topology diagram, routing and security rationale, validation checklist and runbook prompts. You also receive Terraform examples that demonstrate how to structure repeatable network resources.

Upcoming sessions

New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.

Ask about dates

Group of 5+?

Request in-house delivery or group rates →

Related courses in Cloud Computing

5 Days Certificate

NIST Cybersecurity Framework for Cloud Security Training Course

Cloud programmes often accumulate controls without a clear way to demonstrate that identity, data protection, monitoring, recovery, and supp…

10 Days Certificate

Cloud Data Platform Engineering for Data Engineers Training Course

Data engineers are increasingly expected to build more than individual pipelines: they must create reliable cloud data platforms that ingest…

5 Days Certificate

AWS Well-Architected Framework Implementation Training Course

AWS workloads often grow faster than their governance, documentation and operational controls. Teams inherit accounts with inconsistent tagg…

5 Days Certificate

Pulumi Cloud Infrastructure Automation Training Course

Cloud teams often inherit manually created environments, inconsistent naming, undocumented access settings and deployment scripts that canno…