Study guides
Study guides
Two ways to study here, and they answer different questions. Curated reading paths follow a technology rather than an exam: read the Learn library in teaching order, with the tools to practise on as you go. Certification study guides live on their own page and do the opposite - they start from a vendor's published exam blueprint and map it objective by objective.
Curated reading paths
A path is a syllabus with no exam behind it. Nothing here is organised around a certification blueprint or scored against one: the order is the order the subject makes sense in, chosen so each article earns the next. Read straight through, or stop when you have what you came for. Everything computes locally and nothing is paywalled.
Vendor-agnostic
HTTP, told forward 14 articles
HTTP (the Hypertext Transfer Protocol) across its five versions - from the one-line GET of 1991 to HTTP/3 on QUIC - then the operational layer: forward and reverse proxies, HSTS (HTTP Strict Transport Security), and curl beyond the browser.
Reading order:
- HTTP/0.9 vs 1.0 vs 1.1 vs 2 vs 3: Five Versions of the Web's Protocol
- HTTP Methods: The Verbs of the Web
- HTTP QUERY: the read that finally carries a body
- HTTP Status Codes: The Five Families
- HTTP Headers: The Anatomy of the Metadata
- HTTP Cookies: State Over a Stateless Protocol
- HTML Forms and Request Encoding: How the Web Ships Your Input
- AJAX, XHR, and fetch: When Pages Learned to Talk Back
- CORS Explained: The Border Control of the Browser
- URI, URL, URN: What's Actually the Difference?
- HTML, CSS, and the DOM: The Page as a Living Tree
- HTTP Proxies: Forward vs Reverse, Explicit vs Transparent
- HSTS and HTTPS Enforcement
- The 27 Protocols curl Speaks
Practice with: HTTP request translator · HTTP methods comparison · HTTP status code explainer · URL Inspector · curl command builder
Modern identity, from the token up 8 articles
The open standards behind single sign-on, in dependency order: the JWT (JSON Web Token) itself, the signatures and JWKS (JSON Web Key Set) that make it verifiable, the OAuth 2.0 and PKCE (Proof Key for Code Exchange) flows that mint it, OIDC (OpenID Connect) on top, and TOTP/HOTP (time-based and HMAC-based one-time passwords) as the second factor.
Reading order:
- Anatomien til en JSON Web Token
- JWT-signeringsalgoritmer: HMAC, RSA og ECDSA
- Verifying a JWT with a JWKS: From kid to Signature
- OAuth 2.0-autorisasjonskodeflyten
- PKCE: å sikre OAuth-autorisasjonskodeflyten
- OpenID Connect: An Identity Layer on OAuth 2.0
- OIDC vs OAuth 2.0: Authentication vs Authorization
- How TOTP and HOTP one-time passwords work
Practice with: JWT-dekoder og -verifikator · JWKS explainer + key matcher · OAuth-PKCE-verifikator og -challenge · OIDC-dekoder · TOTP / HOTP Generator & Validator
Regular expressions, properly 5 articles
The craft skill under log analysis and every parser: quantifiers and classes, groups and backreferences, anchors and boundaries, flags and modes - ending on catastrophic backtracking, the failure mode every production regex must avoid.
TLS from zero 6 articles
TLS (Transport Layer Security) from the cipher suite string upward: what each part of a suite name means, what TLS 1.3 removed and why, how hybrid post-quantum key exchange works, and how TLS 1.2, TLS 1.3, DTLS (Datagram TLS), and QUIC relate as one family.
Reading order:
- Anatomien til en TLS-chiffersuite
- Å lese chiffersuitenavn: IANA, OpenSSL og GnuTLS
- Which TLS Cipher Keywords Are Safe, and Which Are Not
- TLS 1.3-chiffersuiter: hva som endret seg
- Hybrid Key Exchange in TLS 1.3: What X25519MLKEM768 Does on the Wire
- TLS 1.2 vs TLS 1.3 vs DTLS vs QUIC: One Handshake Family, Four Shapes
Practice with: Dekoder for chiffersuiter
F5
F5 BIG-IP end to end 63 articles
Everything the retired 101, 201, 301A, and 301B blueprints listed, as this site's articles in teaching order: the networking fundamentals the modern track assumes (OSI (Open Systems Interconnection) to VPN (virtual private network)), the full administration arc from interfaces to high availability to the support workflows the new exams dropped, and the LTM (Local Traffic Manager) specialist craft - iRules, analytics, captures, SSL (Secure Sockets Layer) - closing with the two articles that compare the retired blueprints against the current ones.
Reading order:
- The OSI Model in Practice: Mapping Real Traffic to Seven Layers
- Switch, Router, Firewall: Who Does What on the Path
- Hvordan IPv4-adresser fungerer
- Grunnleggende om subnettinndeling
- CIDR-notasjon forklart
- Privat IPv4-adresserom og RFC 1918
- NAT Explained: Source, Destination, and Why the Internet Still Works
- DHCP: the Lease Lifecycle Behind Automatic Addressing
- Å forstå IPv6-adressering
- ARP and MAC Addresses: How IP Finds Ethernet
- Routing Tables and the Default Gateway: How a Packet Picks Its Next Hop
- ICMP, ping, and traceroute: the Control Messages That Explain Your Network
- The TCP Connection Lifecycle: Handshake, Teardown, and Why Connections Fail
- HTTP/0.9 vs 1.0 vs 1.1 vs 2 vs 3: Five Versions of the Web's Protocol
- Hvordan sertifikatvalidering faktisk fungerer
- Public vs private PKI: which certificates SC-081v3 governs
- VPN Fundamentals: What Tunnels Protect, and What They Don't
- From Interface to Self-IP: BIG-IP Layer 2 and 3 Dependencies
- Route Domains: Layer 3 Segmentation Inside One BIG-IP
- Management Access on BIG-IP: the Management IP, Port Lockdown, and Access Lists
- The System Services Behind a Healthy BIG-IP: DNS, NTP, SNMP, Syslog
- Reading BIG-IP Status: Dashboard, Network Map, TMSH, and netstat
- The BIG-IP Log Files: a Map of /var/log
- How a BIG-IP Virtual Server Works
- BIG-IP Virtual Server Types, and What Each One Actually Does
- Profiles on a Virtual Server
- BIG-IP Pools and Load-Balancing Methods
- BIG-IP Load-Balancing Methods, and What Each One Weighs
- How LTM Health Monitors Decide Up or Down
- BIG-IP Persistence Methods, and What Each Keys On
- SNAT and the Return-Traffic Problem
- Where Do the Requests Go? Simulating BIG-IP LTM Distribution
- BIG-IP High Availability: Device Trust, Device Groups, and Traffic Groups
- Failover on BIG-IP: States, Forcing, and Network Failover
- Config Sync on BIG-IP: When to Sync, and Why It Fails
- UCS Archives: the BIG-IP Backup That Contains Everything
- Anatomy of a BIG-IP License File
- The BIG-IP Service Check Date, and Why an Upgrade Can Refuse to Load
- BIG-IP Upgrade vs Update: Why the Distinction Decides Whether the License Date Is Checked
- The BIG-IP 21.x Ops Story: In-Place Upgrades, a 64-Bit Control Plane, and BigD at Scale
- qkview and iHealth: the Support Snapshot Workflow
- TAC Cases That Get Triaged Fast
- EUD: BIG-IP Hardware Diagnostics Before You RMA
- Protocol Profiles: Living TCP, Frozen TCP, and the Two Fast Paths
- OneConnect: Reuse Is a Grouping Problem, and SNAT Rewrites the Groups
- CMP: The Cores You Paid For, and the iRule Lines That Give Them Back
- What Makes an Event Fire: Provisioning and Profiles
- iRule Event Order: The Connection Lifecycle
- Client Side vs Server Side in iRules
- iRules performance: cycles, timing, and the runtime calculator
- AVR: Application Visibility and Reporting on BIG-IP
- Deploying Applications with Templates: iApps and FAST
- vCMP: Hosts, Guests, and How Resources Are Carved
- Custom Alerting on BIG-IP: SNMP Traps, Email, and Remote Syslog
- Capturing Safely on a Production BIG-IP
- BIG-IP tcpdump: How It Differs from Standard tcpdump
- Capturing on VLANs, Self-IPs, and Trunks
- Reading a BIG-IP Capture: The F5 Trailer in Wireshark
- Client SSL vs Server SSL Profiles on BIG-IP
- Cipher Ordering and Negotiation on BIG-IP
- Certificates, Keys, and Chain Building in an SSL Profile
- From 101 and 201 to F5-CA: What the Retired Exams Taught That the New Track Dropped
- From 301A and 301B to the New LTM Specialist: a Faithful Restructure, and the Few Things It Dropped
Practice with: CIDR-/subnettkalkulator · IPv6-verktøykasse · dig output explainer · HTTP methods comparison · X.509-sertifikatdekoder · BIG-IP LTM load balancing simulator · Persistence-method explainer · tmsh config explainer · F5 service check date · BIG-IP tcpdump builder · iRules runtime calculator · iRules performance linter · Dekoder for chiffersuiter · BigD thread calculator
Extreme Networks
Extreme fabric and the two operating systems 7 articles
ExtremeXOS for the configuration model, then why VOSS feels so different (it came from another company entirely), then Fabric Connect built up from IS-IS through I-SIDs to the resilience features.
Reading order:
- How an ExtremeXOS Config Is Structured
- VOSS vs EXOS: Two Extreme Operating Systems
- IS-IS, Nicknames, and B-MACs: The VOSS Control Plane
- Fabric Connect and SPBM: Why VOSS Retires Spanning Tree
- The I-SID: How VOSS Replaces VLAN Stretching
- Fabric Attach: Auto-Provisioning the Edge (Where VOSS Meets EXOS)
- SMLT and vIST: Dual-Homing a Fabric Edge
Practice with: ExtremeXOS config explainer
Fortinet
Fortinet beyond the single firewall 5 articles
What shows up once a FortiGate is not alone: inspection choices, the branch overlay, cloud integration, the SOC, and the operational technology edge.
Reading order:
- FortiGate SSL Inspection: Certificate vs Deep Inspection
- SD-Branch and Overlay Networks: VXLAN, LAN Extension, and Orchestrating Many Sites
- Fortinet in Public Cloud: Container Protection, Native Integration, and Infrastructure as Code
- SOC Architecture and Adversary Behaviour: Attack Vectors and What the Products Are For
- Operational Technology Security: Why the IT Playbook Does Not Transfer
Practice with: FortiGate policy lookup explainer · FortiGate route selection explainer · FortiGate security profile coverage checker · FortiOS config diff explainer
Netskope
Netskope SASE, End to End 11 articles
The whole platform in reading order: architecture and NewEdge, every steering method, the client, TLS decryption, the two protection paths, CCI-driven policy, Private Access, Cloud Firewall, and the analytics layer - with the PAC and SAML tools to practice on. Built to walk the accreditation and certification domains from this site.
Reading order:
- Netskope Platform Architecture: One Platform, Two Data Paths, One Private Cloud
- Choosing how traffic reaches the service edge
- How a PAC File Chooses a Proxy
- Netskope Client Deployment: Enrollment, Identity, and the Tunnel
- Netskope: Cloud Forward Proxy and Inline TLS Decryption
- Real-time vs API Protection: The Two Vantage Points of a Security Cloud
- The Cloud Confidence Index: Scoring the Apps Your Users Already Found
- Data Loss Prevention: How Machines Recognize Secrets
- Netskope Private Access: ZTNA Instead of the VPN
- Netskope Cloud Firewall: Egress Control for Everything That Isn't Web
- Netskope Events and Advanced Analytics: From Traffic to Evidence
Practice with: PAC file explainer and validator · Netskope steering decision explainer · SAML Decoder
Ping Identity and ForgeRock
PingFederate administration, end to end 16 articles
The blueprint's assumed fundamentals first - the directory model and the Kerberos ticket machinery - then the ten product articles in teaching order, SCIM beside the provisioning stop, and the SSO flows to close. The reading spine behind the PFP-001 certification guide.
Reading order:
- SAML 2.0: How Browser SSO Works
- LDAP Fundamentals: The Directory Model Behind Identity Systems
- Kerberos and SPNEGO: How Silent Desktop SSO Actually Works
- Installing PingFederate: Requirements, First Run, and the Setup Wizard
- The PingFederate Startup Files: Who Controls What
- Upgrading PingFederate: The Utility, the Merge, and the Cluster Order
- Who Administers PingFederate: Native Accounts, Roles, and Console Login via LDAP
- PingFederate Operational Hygiene: License, Notifications, and the Configuration Archive
- The PingFederate Endpoints Map: Admin Port, Runtime Port, and What Lives Where
- PingFederate Data Stores: LDAP and JDBC, Defined Once, Used Everywhere
- SCIM: The Standard That Provisions the Accounts SSO Signs In
- How Users Prove Who They Are: PCVs and the Five Adapters
- PingFederate Authentication Policies: Trees, Selectors, and the Contract at the End
- The PingFederate Log Files: Which One Answers Which Question
- SAML Bindings and SP vs IdP Initiation
- The OIDC Authorization Code Flow
Practice with: SAML Decoder · X.509-sertifikatdekoder · CSR-dekoder · Planlegger for fornyelse av sertifikater · OIDC-dekoder · JWT-dekoder og -verifikator · OAuth-PKCE-verifikator og -challenge · JWKS explainer + key matcher
The Ping Identity Platform 15 articles
The whole Ping estate in reading order: the PingOne platform map and the ForgeRock lineage first, so every product name resolves; then PingAccess policy, the PingDirectory data platform, and DaVinci orchestration; closing with the PingFederate shelf - the self-managed federation core - in its established teaching order. The companion walk to the Certified Professional guides on the certifications hub.
Reading order:
- PingOne: The Platform Behind the Product Names
- From Sun to Ping: The ForgeRock Lineage Decoded
- The PingAccess Policy Model: Gateway, Agent, and the Rule Stack
- The PingDirectory Platform: Store, Aggregate, Sync, Delegate
- PingOne DaVinci: Identity Orchestration as a Canvas
- Installing PingFederate: Requirements, First Run, and the Setup Wizard
- The PingFederate Startup Files: Who Controls What
- Upgrading PingFederate: The Utility, the Merge, and the Cluster Order
- Who Administers PingFederate: Native Accounts, Roles, and Console Login via LDAP
- PingFederate Operational Hygiene: License, Notifications, and the Configuration Archive
- The PingFederate Endpoints Map: Admin Port, Runtime Port, and What Lives Where
- PingFederate Data Stores: LDAP and JDBC, Defined Once, Used Everywhere
- How Users Prove Who They Are: PCVs and the Five Adapters
- PingFederate Authentication Policies: Trees, Selectors, and the Contract at the End
- The PingFederate Log Files: Which One Answers Which Question
Practice with: OIDC-dekoder · JWT-dekoder og -verifikator · OAuth-PKCE-verifikator og -challenge · SAML Decoder · TOTP / HOTP Generator & Validator
Zscaler
Zscaler Zero Trust Exchange 31 articles
From tunnels and fundamentals to the full policy brain: forwarding, firewall order, TLS inspection, web and file controls, DLP, CASB, and ZPA's segments, policy, and posture — with the three native tools to practice on.
Reading order:
- GRE Tunnels: The Simplest Envelope in Networking
- IPsec and IKE: How Encrypted Tunnels Negotiate Themselves
- Tunnel Overhead, MTU, and MSS: The Byte Math Every Tunnel Owes
- How a Proxy Knows Who You Are: User Authentication Methods Inline
- Data Loss Prevention: How Machines Recognize Secrets
- Sandbox Detonation: Judging a File by What It Does
- Browser Isolation: When You Cannot Trust the Page, Move the Browser
- The Zscaler Zero Trust Exchange: A Proxy Where the Perimeter Used to Be
- Getting Traffic to ZIA: The Forwarding Decision
- Zscaler Tunnel Types: Z-Tunnel, GRE, and IPsec, With the Numbers
- Client Connector Profiles: Where the Endpoint Decides How to Forward
- ZIA Cloud Firewall: Rule Order Is the Whole Ballgame
- TLS Inspection in ZIA: The Policy, the Bypasses, and the Bill
- URL Filtering and Cloud App Control: Two Policies, One Precedence Rule
- File Type Control and Cloud Sandbox: The Download's Two Judges
- ZIA Data Loss Prevention: Dictionaries, Engines, and the Fingerprint Tiers
- CASB in the Exchange: Inline, Out-of-Band, and the Posture of SaaS Itself
- ZPA Architecture: Two Outbound Calls and a Broker in the Middle
- ZPA App Segments and Access Policy: Naming Applications, Then Earning Them
- Posture and Device Trust: Letting the Device's State Vote
- The ZDX Score: What the Probes Measure and How the Number Is Made
- The Administrator Audit Log: Who Changed What, From Where, With What Outcome
- ZIA Log Fields: The Vocabulary Investigations Are Written In
- Nanolog, NSS, Cloud NSS, and LSS: Getting the Logs Out
- Reports and Executive Summaries: Turning the Nanolog Into Sentences Leadership Reads
- Locations and Sublocations: Teaching the Cloud Where Your Sites Are
- Troubleshooting Client Connector: The Diagnostics Menu and the First Four Checks
- ZPA Access Troubleshooting: Policy, Health, or DNS - Pick the Right Suspect
- The Exfiltration Alert: A Walkthrough From Signal to Posture Answer
- Mergers and Acquisitions on the Exchange: Day-One Access Without Merging Networks
- Updates and Change Management: Running Change on a Platform That Also Changes Itself
Practice with: Zscaler Tunnel Chooser · ZCC forwarding decision explainer · ZIA firewall rule-order simulator · ZIA SSL Bypass Planner · JA4 / JA3 TLS fingerprint decoder · ZDX score factor explainer
Check Point
Check Point security administration 14 articles
The platform in the order the CCSA teaches it: the three-tier split first, because nothing else makes sense until you know the management server and the gateway are different machines with different jobs, then the rule base, then the layer semantics that catch everyone.
Reading order:
- Check Point's Three-Tier Architecture: Management, Gateway, and SmartConsole
- Check Point Administrators, Sessions, and Objects: Publish Is Not Install
- The Check Point Rule Base: Order, Implied Rules, and the Rules Everyone Forgets
- Check Point Policy Layers: Ordered, Inline, and Shared
- Check Point Logging and Monitoring: Where Logs Go and How to Ask Them Questions
- Check Point Identity Awareness: Writing Rules About People Instead of Addresses
- Check Point HTTPS Inspection, Application Control, and URL Filtering
- Check Point Threat Prevention: The Blades, Profiles, and Prevent Versus Detect
- Check Point NAT: Automatic Versus Manual, Hide Versus Static, and Proxy ARP
- Check Point Site-to-Site VPN: Communities, Encryption Domains, and Why the Tunnel Is Empty
- Check Point Management High Availability: Active, Standby, and Why Failover Is Manual
- Check Point SmartEvent and the Compliance Blade: Turning Logs into Events Worth Reading
- Check Point Upgrades and Migrations: Order, Compatibility, and Getting the Database Out
- Check Point ElasticXL: One Cluster Object, Many Members
Practice with: Check Point policy layer evaluator
NGINX
NGINX, from configuration to cache 6 articles
In the order the confusions actually arrive: the configuration tree, then which location block wins, then what path the backend receives, then what gets cached and served to whom.
Reading order:
- The NGINX configuration tree: what includes, in what order, and who owns the worker
- NGINX location matching: why the block you expected is not the one that ran
- The NGINX proxy_pass trailing slash: one character that decides what your backend receives
- NGINX caching: what gets stored, what gets served, and the gap where user data leaks
- Limiting requests, connections and bandwidth in NGINX: leaky buckets and the burst that surprises people
- Reloading NGINX without dropping traffic, and the first four things to check when it breaks
Practice with: NGINX location matcher · NGINX proxy_pass rewriter · NGINX cache decision explainer
Certification study guides
These are the exam-shaped ones, and they live on the certifications page. Each follows a vendor's own published blueprint objective by objective, tying every objective to the articles that teach it, the tools that exercise it, and the manual pages that remain the source of truth.