1---2name: network3description: Understand and troubleshoot computer networks with TCP/IP, DNS, routing, and diagnostic tools.4---56# Network Fundamentals78## TCP/IP Basics9- TCP guarantees delivery with retransmission — use for reliability (HTTP, SSH, databases)10- UDP is fire-and-forget — use for speed when loss is acceptable (video, gaming, DNS queries)11- Port numbers: 0-1023 privileged (need root), 1024-65535 available — common services have well-known ports12- Ephemeral ports for client connections — OS assigns randomly from high range1314## DNS15- DNS resolution is cached at multiple levels — browser, OS, router, ISP — flush all when debugging16- TTL determines cache duration — lower before migrations, raise after for performance17- A record for IPv4, AAAA for IPv6, CNAME for aliases, MX for mail18- CNAME cannot exist at zone apex (root domain) — use A record or provider-specific alias19- `dig` and `nslookup` query DNS directly — bypass local cache for accurate results2021## IP Addressing22- Private ranges: 10.x.x.x, 172.16-31.x.x, 192.168.x.x — not routable on internet23- CIDR notation: /24 = 256 IPs, /16 = 65536 IPs — each bit halves or doubles the range24- 127.0.0.1 is localhost — 0.0.0.0 means all interfaces, not a valid destination25- NAT translates private to public IPs — most home/office networks use this26- IPv6 eliminates NAT need — but dual-stack with IPv4 still common2728## Common Ports29- 22: SSH — 80: HTTP — 443: HTTPS — 53: DNS30- 25/465/587: SMTP (mail sending) — 143/993: IMAP — 110/995: POP331- 3306: MySQL — 5432: PostgreSQL — 6379: Redis — 27017: MongoDB32- 3000/8080/8000: Common development servers3334## Troubleshooting Tools35- `ping` tests reachability — but ICMP may be blocked, no response doesn't mean down36- `traceroute`/`tracert` shows path — identifies where packets stop or slow down37- `netstat -tulpn` or `ss -tulpn` shows listening ports — find what's using a port38- `curl -v` shows full HTTP transaction — headers, timing, TLS negotiation39- `tcpdump` and Wireshark capture packets — last resort for deep debugging4041## Firewalls and NAT42- Stateful firewalls track connections — allow response to outbound requests automatically43- Port forwarding maps external port to internal IP:port — required to expose services behind NAT44- Hairpin NAT for internal access to external IP — not all routers support it45- UPnP auto-configures port forwarding — convenient but security risk, disable on servers4647## Load Balancing48- Round-robin distributes sequentially — simple but ignores server capacity49- Least connections sends to least busy — better for varying request durations50- Health checks remove dead servers — configure appropriate intervals and thresholds51- Sticky sessions (affinity) keep user on same server — needed for stateful apps, breaks scaling5253## VPNs and Tunnels54- VPN encrypts traffic to exit point — all traffic appears from VPN server IP55- Split tunneling sends only some traffic through VPN — reduces latency for local resources56- WireGuard is modern and fast — simpler than OpenVPN, better performance57- SSH tunnels for ad-hoc port forwarding — `ssh -L local:remote:port` creates secure tunnel5859## SSL/TLS60- TLS 1.2 minimum, prefer 1.3 — older versions have known vulnerabilities61- Certificate chain: leaf → intermediate → root — missing intermediate causes validation failures62- SNI allows multiple certs on one IP — older clients without SNI get default cert63- Let's Encrypt certs expire in 90 days — automate renewal or face outages6465## Common Mistakes66- Assuming DNS changes are instant — TTL means old records persist in caches67- Blocking ICMP entirely — breaks path MTU discovery, causes mysterious failures68- Forgetting IPv6 — services may be accessible on IPv6 even with IPv4 firewall69- Hardcoding IPs instead of hostnames — breaks when IPs change70- Not checking both TCP and UDP — some services need UDP (DNS, VPN, game servers)71- Confusing latency and bandwidth — high bandwidth doesn't mean low latency