The ETHHACK course will contain components of a default course as deployed by RangeControl, The Gateway Configuration will change depending on your resources. The architecture shown below assumes a monolithic deployment on one highly provisioned hypervisor. If you need to support a huge number of clients, you would likely introduce a new virtual router gateway that supports targets running on another server. You would connect these two gateways via IPSEC or another site-to-site VPN like wireguard so that attack traffic does not appear in the "clear" over your production network.
The following diagram illustrates a simple 1 host configuration.