Skip to content

Basic Networking Concepts

On this page

The mental model for how packets move: layered models, addressing and subnetting, DNS, routing, ports, NAT, and the troubleshooting workflow that finds 90% of problems.

Basics

Two layered models

The OSI model (7 layers) is the teaching model; the TCP/IP model (4 layers) is what the internet actually runs on.

OSI Layer TCP/IP Examples Unit
7 Application Application HTTP, DNS, SSH, TLS Data
6 Presentation Application TLS, encoding Data
5 Session Application sockets Data
4 Transport Transport TCP, UDP Segment
3 Network Internet IP, ICMP, routing Packet
2 Data Link Link Ethernet, ARP, MAC Frame
1 Physical Link cables, Wi-Fi radio Bits

TCP vs UDP

  • TCP — connection-oriented, reliable, ordered, flow/congestion control (3-way handshake SYN → SYN/ACK → ACK). Web, SSH, databases.
  • UDP — connectionless, no delivery guarantee, low overhead. DNS, DHCP, VoIP, gaming, QUIC.

IP addressing

  • IPv4 — 32-bit, dotted quad 192.168.1.10. ~4.3B addresses; exhausted, hence NAT.
  • IPv6 — 128-bit, hex 2001:db8::1. Vast space, no NAT needed.

Private ranges (RFC 1918) — not routable on the public internet: 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16. Loopback is 127.0.0.0/8.

Subnetting (CIDR)

A /n prefix means the first n bits are the network portion.

CIDR Mask Usable hosts Note
/24 255.255.255.0 254 classic LAN
/25 255.255.255.128 126 split a /24 in two
/30 255.255.255.252 2 point-to-point links
/16 255.255.0.0 65,534 large network

Usable hosts = 2^(32−prefix) − 2 (subtract network + broadcast). The first address is the network ID, the last is broadcast.

DNS

The Domain Name System maps names to addresses. Resolution walks root → TLD (.com) → authoritative server. Common record types:

Record Purpose
A / AAAA name → IPv4 / IPv6
CNAME alias to another name
MX mail servers
TXT arbitrary text (SPF, DKIM, verification)
NS delegating name servers
PTR reverse (IP → name)
SOA zone authority/metadata

TTL controls how long a record is cached.

Ports

16-bit (0–65535). Well-known examples: 22 SSH, 25 SMTP, 53 DNS, 80 HTTP, 123 NTP, 443 HTTPS, 3306 MySQL, 5432 PostgreSQL, 6379 Redis, 8080 alt-HTTP.

NAT, gateways, DHCP

  • Default gateway — the router that forwards traffic off your subnet.
  • NAT — rewrites private source IPs to a public IP so many hosts share one address.
  • DHCP — auto-assigns IP, mask, gateway, DNS to clients (DORA: Discover, Offer, Request, Ack).

Cheatsheet

# Interfaces & addresses
ip a                       # show addresses (replaces ifconfig)
ip link set eth0 up
ip route                   # routing table; 'default via' = gateway
ip neigh                   # ARP/neighbor cache

# Connectivity & path
ping -c4 1.1.1.1           # reachability + RTT
traceroute example.com     # hop-by-hop path (mtr for live)
mtr example.com            # traceroute + ping combined

# DNS
dig example.com +short
dig @8.8.8.8 example.com MX
dig -x 1.1.1.1             # reverse lookup
nslookup example.com
host example.com
resolvectl status          # systemd-resolved config

# Sockets & ports
ss -tulpn                  # listening TCP/UDP + process
ss -tan state established
lsof -i :443

# HTTP / TLS checks
curl -v https://example.com
curl -I https://example.com           # headers only
openssl s_client -connect host:443 -servername host   # inspect cert

# Captures
sudo tcpdump -ni eth0 port 80
sudo tcpdump -ni any host 10.0.0.5 and tcp

# Firewall (pick your stack)
sudo ufw status ; sudo ufw allow 443/tcp
sudo firewall-cmd --list-all
sudo nft list ruleset

Subnet quick math

/24 = 256 addrs (254 hosts)   /26 = 64 (62)    /28 = 16 (14)
/25 = 128 (126)               /27 = 32 (30)    /30 = 4 (2)
Hosts = 2^(32-prefix) - 2

Thumb Rules

Rules of thumb

  • Work the layers bottom-up. Link (cable/IP) → Network (route/gateway) → Transport (port/firewall) → Application (DNS/TLS/HTTP).
  • “It’s always DNS.” When something resolves slowly or intermittently, suspect DNS first.
  • Ping tests reachability, not service health. A host can ping but the app port be closed.
  • Private IPs never appear on the public internet — if you see one as a source from outside, something's wrong.
  • Smaller prefix = bigger network (/16 > /24). The number is how many bits are fixed.
  • Default-deny inbound, allow only what you need. Egress filtering catches exfiltration.
  • MTU mismatches cause “works for small, hangs for large” transfers — suspect path MTU / VPN overhead.

Use Cases

  • Designing IP plans for offices, data centers, cloud VPCs (subnet per tier/zone).
  • Connecting environments via VPN, peering, or transit gateways.
  • Exposing services with load balancers, reverse proxies, and DNS.
  • Securing traffic with firewalls, security groups, and network policies.
  • Diagnosing outages — latency, packet loss, routing loops, DNS failures.

Common Issues

Can ping IP but not the hostname

DNS resolution is broken. Check /etc/resolv.conf / resolvectl status, try dig @1.1.1.1 name. If IP works and name doesn't, it's name resolution, not connectivity.

Connection refused vs timeout

Refused = reached the host but nothing is listening / port closed (fast). Timeout = no response at all — firewall dropping, wrong route, or host down (slow). Use ss -tulpn on the server and nc -vz host port from the client.

Works locally, not remotely

Service bound to 127.0.0.1 instead of 0.0.0.0, or a firewall/security group blocks the port. Check the bind address and inbound rules.

Intermittent connectivity / asymmetric routing

Duplicate IPs, overlapping subnets (common with VPNs), or two default gateways. Check ip route, ARP table, and for IP conflicts (arping).

TLS errors

Expired/mismatched cert, wrong SNI, or missing intermediate chain. Inspect with openssl s_client -connect host:443 -servername host. Clock skew also breaks TLS.

Best Practices

  • Plan address space deliberately — leave room to grow; document subnets/VLANs.
  • Segment networks (VLANs, VPC subnets, security groups) and apply least-privilege rules.
  • Prefer names over hardcoded IPs; manage DNS as code.
  • Use private subnets for internal tiers, public only for load balancers/bastions.
  • Encrypt in transit (TLS, WireGuard/IPsec for site-to-site).
  • Monitor latency, loss, and DNS health, not just up/down.
  • Keep firewall rules in version control; default-deny inbound, restrict egress.
  • Enable IPv6 thoughtfully rather than ignoring it.

Official Sources