Basic Networking Concepts¶
On this page
The mental model for how packets move: layered models, addressing and subnetting, DNS, routing, ports, NAT, and the troubleshooting workflow that finds 90% of problems.
Basics¶
Two layered models¶
The OSI model (7 layers) is the teaching model; the TCP/IP model (4 layers) is what the internet actually runs on.
| OSI Layer | TCP/IP | Examples | Unit |
|---|---|---|---|
| 7 Application | Application | HTTP, DNS, SSH, TLS | Data |
| 6 Presentation | Application | TLS, encoding | Data |
| 5 Session | Application | sockets | Data |
| 4 Transport | Transport | TCP, UDP | Segment |
| 3 Network | Internet | IP, ICMP, routing | Packet |
| 2 Data Link | Link | Ethernet, ARP, MAC | Frame |
| 1 Physical | Link | cables, Wi-Fi radio | Bits |
TCP vs UDP¶
- TCP — connection-oriented, reliable, ordered, flow/congestion control (3-way handshake SYN → SYN/ACK → ACK). Web, SSH, databases.
- UDP — connectionless, no delivery guarantee, low overhead. DNS, DHCP, VoIP, gaming, QUIC.
IP addressing¶
- IPv4 — 32-bit, dotted quad
192.168.1.10. ~4.3B addresses; exhausted, hence NAT. - IPv6 — 128-bit, hex
2001:db8::1. Vast space, no NAT needed.
Private ranges (RFC 1918) — not routable on the public internet:
10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16. Loopback is 127.0.0.0/8.
Subnetting (CIDR)¶
A /n prefix means the first n bits are the network portion.
| CIDR | Mask | Usable hosts | Note |
|---|---|---|---|
| /24 | 255.255.255.0 | 254 | classic LAN |
| /25 | 255.255.255.128 | 126 | split a /24 in two |
| /30 | 255.255.255.252 | 2 | point-to-point links |
| /16 | 255.255.0.0 | 65,534 | large network |
Usable hosts = 2^(32−prefix) − 2 (subtract network + broadcast). The first address is the network ID, the last is broadcast.
DNS¶
The Domain Name System maps names to addresses. Resolution walks
root → TLD (.com) → authoritative server. Common record types:
| Record | Purpose |
|---|---|
| A / AAAA | name → IPv4 / IPv6 |
| CNAME | alias to another name |
| MX | mail servers |
| TXT | arbitrary text (SPF, DKIM, verification) |
| NS | delegating name servers |
| PTR | reverse (IP → name) |
| SOA | zone authority/metadata |
TTL controls how long a record is cached.
Ports¶
16-bit (0–65535). Well-known examples: 22 SSH, 25 SMTP, 53 DNS, 80 HTTP, 123 NTP, 443 HTTPS, 3306 MySQL, 5432 PostgreSQL, 6379 Redis, 8080 alt-HTTP.
NAT, gateways, DHCP¶
- Default gateway — the router that forwards traffic off your subnet.
- NAT — rewrites private source IPs to a public IP so many hosts share one address.
- DHCP — auto-assigns IP, mask, gateway, DNS to clients (DORA: Discover, Offer, Request, Ack).
Cheatsheet¶
# Interfaces & addresses
ip a # show addresses (replaces ifconfig)
ip link set eth0 up
ip route # routing table; 'default via' = gateway
ip neigh # ARP/neighbor cache
# Connectivity & path
ping -c4 1.1.1.1 # reachability + RTT
traceroute example.com # hop-by-hop path (mtr for live)
mtr example.com # traceroute + ping combined
# DNS
dig example.com +short
dig @8.8.8.8 example.com MX
dig -x 1.1.1.1 # reverse lookup
nslookup example.com
host example.com
resolvectl status # systemd-resolved config
# Sockets & ports
ss -tulpn # listening TCP/UDP + process
ss -tan state established
lsof -i :443
# HTTP / TLS checks
curl -v https://example.com
curl -I https://example.com # headers only
openssl s_client -connect host:443 -servername host # inspect cert
# Captures
sudo tcpdump -ni eth0 port 80
sudo tcpdump -ni any host 10.0.0.5 and tcp
# Firewall (pick your stack)
sudo ufw status ; sudo ufw allow 443/tcp
sudo firewall-cmd --list-all
sudo nft list ruleset
Subnet quick math¶
/24 = 256 addrs (254 hosts) /26 = 64 (62) /28 = 16 (14)
/25 = 128 (126) /27 = 32 (30) /30 = 4 (2)
Hosts = 2^(32-prefix) - 2
Thumb Rules¶
Rules of thumb
- Work the layers bottom-up. Link (cable/IP) → Network (route/gateway) → Transport (port/firewall) → Application (DNS/TLS/HTTP).
- “It’s always DNS.” When something resolves slowly or intermittently, suspect DNS first.
- Ping tests reachability, not service health. A host can ping but the app port be closed.
- Private IPs never appear on the public internet — if you see one as a source from outside, something's wrong.
- Smaller prefix = bigger network (/16 > /24). The number is how many bits are fixed.
- Default-deny inbound, allow only what you need. Egress filtering catches exfiltration.
- MTU mismatches cause “works for small, hangs for large” transfers — suspect path MTU / VPN overhead.
Use Cases¶
- Designing IP plans for offices, data centers, cloud VPCs (subnet per tier/zone).
- Connecting environments via VPN, peering, or transit gateways.
- Exposing services with load balancers, reverse proxies, and DNS.
- Securing traffic with firewalls, security groups, and network policies.
- Diagnosing outages — latency, packet loss, routing loops, DNS failures.
Common Issues¶
Can ping IP but not the hostname
DNS resolution is broken. Check /etc/resolv.conf / resolvectl status, try
dig @1.1.1.1 name. If IP works and name doesn't, it's name resolution, not connectivity.
Connection refused vs timeout
Refused = reached the host but nothing is listening / port closed (fast).
Timeout = no response at all — firewall dropping, wrong route, or host down (slow).
Use ss -tulpn on the server and nc -vz host port from the client.
Works locally, not remotely
Service bound to 127.0.0.1 instead of 0.0.0.0, or a firewall/security group blocks
the port. Check the bind address and inbound rules.
Intermittent connectivity / asymmetric routing
Duplicate IPs, overlapping subnets (common with VPNs), or two default gateways. Check
ip route, ARP table, and for IP conflicts (arping).
TLS errors
Expired/mismatched cert, wrong SNI, or missing intermediate chain. Inspect with
openssl s_client -connect host:443 -servername host. Clock skew also breaks TLS.
Best Practices¶
- Plan address space deliberately — leave room to grow; document subnets/VLANs.
- Segment networks (VLANs, VPC subnets, security groups) and apply least-privilege rules.
- Prefer names over hardcoded IPs; manage DNS as code.
- Use private subnets for internal tiers, public only for load balancers/bastions.
- Encrypt in transit (TLS, WireGuard/IPsec for site-to-site).
- Monitor latency, loss, and DNS health, not just up/down.
- Keep firewall rules in version control; default-deny inbound, restrict egress.
- Enable IPv6 thoughtfully rather than ignoring it.
Official Sources¶
- IETF RFCs (authoritative protocol specs) — https://www.rfc-editor.org/ (e.g. RFC 1918 private addresses, RFC 791 IPv4, RFC 8200 IPv6)
- ICANN / IANA registries — https://www.iana.org/
- Cloudflare Learning Center (clear explainers) — https://www.cloudflare.com/learning/
- Linux
ip/ss(iproute2) — https://www.kernel.org/doc/html/latest/networking/ - nftables wiki — https://wiki.nftables.org/
- Wireshark docs — https://www.wireshark.org/docs/