In today’s interconnected world, secure network design is essential to organizational resilience. As networks expand across offices, plants, and data centers, cyber threats increasingly exploit vulnerabilities such as misconfigurations, weak segmentation, and unmonitored systems. This course equips learners with the skills to design, implement, and manage secure network infrastructures at every stage of their lifecycle.
Through a balance of theory and hands-on labs, students will learn to apply principles like defense in depth, least privilege, segmentation, and zero trust. They will gain practical experience configuring VLANs, implementing firewalls and IDS/IPS, and deploying VPN technologies such as IPSec, SSL/TLS, and L2TP. Learners will also practice real-time traffic monitoring, log analysis, and SIEM integration to detect and respond to intrusions.
Designed for aspiring network security professionals, system administrators, and IT managers, this course emphasizes scalable architectures, policy-driven operations, and continuous monitoring—preparing learners to protect modern enterprise networks against evolving threats.
In this course, you’ll learn how to design, implement, and manage secure network infrastructures that can withstand evolving cyber threats. You’ll focus on real-world applications such as network segmentation with VLANs, secure remote connectivity through VPNs, and proactive defense using firewalls, IDS/IPS, and SIEM systems. Through guided labs and hands-on configuration, you’ll gain the skills to build scalable, resilient networks, monitor traffic in real time, and apply layered security principles like zero trust and defense in depth—ensuring data integrity, confidentiality, and continuous protection across complex digital environments.
What's included
1 video1 reading
Show info about module content
1 video•Total 4 minutes
Intro Video to Course •4 minutes
1 reading•Total 5 minutes
Welcome to the Course: Course Overview•5 minutes
Network Security Fundamentals & Architecture
Module 2•2 hours to complete
Module details
In this module, you’ll learn how to build secure network architectures from the ground up—starting with the foundational principles of network security and progressing to practical configuration of VLANs for segmentation and protection. You’ll explore key concepts such as the CIA triad, common cyberattack methods, and architectural design principles like defense in depth and least privilege. Through interactive lessons, hands-on VLAN labs, and demonstrations, you’ll gain the skills to design, implement, and secure segmented network environments that minimize attack surfaces and enhance organizational resilience.
Hands-On-Learning: Creating VLANs and Implementing Inter-VLAN Routing •10 minutes
1 discussion prompt•Total 10 minutes
Designing for Security: What Matters Most?•10 minutes
Access Control, VPNs, and Device Security
Module 3•2 hours to complete
Module details
In this module, you’ll learn how to control who and what can access your network, secure data as it travels across untrusted environments, and harden network devices against unauthorized use. You’ll explore access control mechanisms like ACLs for filtering traffic, VPNs for encrypting communication, and secure authentication methods for device protection. Through real-world demonstrations, guided configurations, and hands-on labs, you’ll gain the skills to build, deploy, and manage secure access solutions that safeguard both internal and external network communications.
Access Control, VPNs, and Device Security•20 minutes
1 peer review•Total 10 minutes
Hands-On-Learning: Configuring and Applying Access Control Lists (ACLs) •10 minutes
1 discussion prompt•Total 10 minutes
Overcoming Access Control Misconfiguration •10 minutes
Centralized Authentication and Network Monitoring
Module 4•2 hours to complete
Module details
In this module, you’ll learn how to centralize network authentication and gain full visibility into network activity through monitoring and analysis tools. You’ll configure AAA services using TACACS+ for secure and auditable user management, compare it with RADIUS, and implement centralized authorization policies. The module then guides you through traffic analysis and performance monitoring using Wireshark, NetFlow, and SNMP to detect anomalies and performance bottlenecks. Finally, you’ll integrate these insights into a layered defense strategy combining firewalls, IDS/IPS, and incident response to create a robust, proactive security posture.
Demo: TACACS+ vs. RADIUS: What’s the Difference? •5 minutes
Configuring TACACS+ on Network Devices •3 minutes
Tools for Monitoring: Wireshark, NetFlow, and SNMP•6 minutes
Packet Analysis and Intrusion Detection Basics•6 minutes
Using Logs and Alerts to Detect Threats •6 minutes
Defense in Depth: Combining Controls•6 minutes
Firewalls, IDS/IPS, and Honeypots•6 minutes
Threat Response and Containment Techniques •6 minutes
1 reading•Total 5 minutes
AAA, TACACS+, and SSH: Secure Access Control Explained•5 minutes
1 assignment•Total 20 minutes
Centralized Authentication and Network Monitoring •20 minutes
1 peer review•Total 10 minutes
Hands-On-Learning: Configuring TACACS+ for Centralized Authentication •10 minutes
1 discussion prompt•Total 10 minutes
Seeing the Network Clearly •10 minutes
Wireless Security, Operations & Final Project
Module 5•2 hours to complete
Module details
In this module, you’ll learn how to secure wireless networks and bring together all your skills in a comprehensive network security project. You’ll explore wireless-specific vulnerabilities and defenses, including rogue access point detection, WPA2/WPA3 encryption, and secure segmentation using VLANs and ACLs. The module also introduces wireless intrusion prevention and enterprise-level monitoring practices. It concludes with a capstone project where you’ll design, configure, and audit a fully secured network—integrating wired, wireless, and remote access components into one cohesive, defense-in-depth architecture.
WPA2 vs. WPA3 and Secure Authentication•4 minutes
Segmenting Wireless Traffic with VLANs and ACLs •7 minutes
Detecting Rogue Access Points•5 minutes
Demo: Wireless IDS/IPS and Monitoring Tools •6 minutes
Best Practices for Enterprise Wi-Fi Security •5 minutes
Demo: Planning a Secure Network from the Ground Up •5 minutes
Demo: Implementing VLANs, VPNs, and Access Controls •7 minutes
Final Review: Auditing and Defending the Full Environment •6 minutes
1 reading•Total 5 minutes
Top Wireless Network Security Best Practices•5 minutes
1 assignment•Total 20 minutes
Wireless Security, Operations & Final Project •20 minutes
1 peer review•Total 10 minutes
Hands-On-Learning: Segmenting Wireless Traffic with VLANs and ACLs •10 minutes
1 discussion prompt•Total 10 minutes
Designing a Secure Wireless Environment •10 minutes
Course Conclusion
Module 6•1 hour to complete
Module details
In this final section, you’ll synthesize your learning across access control, VPNs, centralized authentication, and wireless defense to build a complete enterprise security framework. You’ll complete a capstone project that challenges you to design, configure, and defend a fully secured network integrating VLANs, ACLs, VPNs, TACACS+, and monitoring tools. By applying your knowledge in a practical environment, you’ll demonstrate your ability to implement layered security, mitigate threats, and maintain resilient network operations across wired and wireless infrastructures.
What's included
1 video1 peer review
Show info about module content
1 video•Total 3 minutes
Course Wrap-up Video •3 minutes
1 peer review•Total 60 minutes
Project: Designing and Defending a Complete Enterprise Network •60 minutes
Our purpose at Starweaver is to empower individuals and organizations with practical knowledge and skills for a rapidly transforming world. By collaborating with an extensive, global network of proven expert educators, we deliver engaging, information-rich learning experiences that work to revolutionize lives and careers. Committed to our belief that people are the most valuable asset, we focus on building capabilities to navigate ever evolving challenges in technology, business, and design.
OK
Why people choose Coursera for their career
Felipe M.
Learner since 2018
"To be able to take courses at my own pace and rhythm has been an amazing experience. I can learn whenever it fits my schedule and mood."
Jennifer J.
Learner since 2020
"I directly applied the concepts and skills I learned from my courses to an exciting new project at work."
Larry W.
Learner since 2021
"When I need courses on topics that my university doesn't offer, Coursera is one of the best places to go."
Chaitanya A.
"Learning isn't just about being better at your job: it's so much more than that. Coursera allows me to learn without limits."
When will I have access to the lectures and assignments?
To access the course materials, assignments and to earn a Certificate, you will need to purchase the Certificate experience when you enroll in a course. You can try a Free Trial instead, or apply for Financial Aid. The course may offer 'Full Course, No Certificate' instead. This option lets you see all course materials, submit required assessments, and get a final grade. This also means that you will not be able to purchase a Certificate experience.
What will I get if I purchase the Certificate?
When you purchase a Certificate you get access to all course materials, including graded assignments. Upon completing the course, your electronic Certificate will be added to your Accomplishments page - from there, you can print your Certificate or add it to your LinkedIn profile.
Is financial aid available?
Yes. In select learning programs, you can apply for financial aid or a scholarship if you can’t afford the enrollment fee. If fin aid or scholarship is available for your learning program selection, you’ll find a link to apply on the description page.