1---2name: network3description: Understand and troubleshoot computer networks with TCP/IP, DNS, routing, and diagnostic tools.4---5
6# Network Fundamentals
7
8## TCP/IP Basics
9- TCP guarantees delivery with retransmission — use for reliability (HTTP, SSH, databases)
10- UDP is fire-and-forget — use for speed when loss is acceptable (video, gaming, DNS queries)
11- Port numbers: 0-1023 privileged (need root), 1024-65535 available — common services have well-known ports
12- Ephemeral ports for client connections — OS assigns randomly from high range
13
14## DNS
15- DNS resolution is cached at multiple levels — browser, OS, router, ISP — flush all when debugging
16- TTL determines cache duration — lower before migrations, raise after for performance
17- A record for IPv4, AAAA for IPv6, CNAME for aliases, MX for mail
18- CNAME cannot exist at zone apex (root domain) — use A record or provider-specific alias
19- `dig` and `nslookup` query DNS directly — bypass local cache for accurate results
20
21## IP Addressing
22- Private ranges: 10.x.x.x, 172.16-31.x.x, 192.168.x.x — not routable on internet
23- CIDR notation: /24 = 256 IPs, /16 = 65536 IPs — each bit halves or doubles the range
24- 127.0.0.1 is localhost — 0.0.0.0 means all interfaces, not a valid destination
25- NAT translates private to public IPs — most home/office networks use this
26- IPv6 eliminates NAT need — but dual-stack with IPv4 still common
27
28## Common Ports
29- 22: SSH — 80: HTTP — 443: HTTPS — 53: DNS
30- 25/465/587: SMTP (mail sending) — 143/993: IMAP — 110/995: POP3
31- 3306: MySQL — 5432: PostgreSQL — 6379: Redis — 27017: MongoDB
32- 3000/8080/8000: Common development servers
33
34## Troubleshooting Tools
35- `ping` tests reachability — but ICMP may be blocked, no response doesn't mean down
36- `traceroute`/`tracert` shows path — identifies where packets stop or slow down
37- `netstat -tulpn` or `ss -tulpn` shows listening ports — find what's using a port
38- `curl -v` shows full HTTP transaction — headers, timing, TLS negotiation
39- `tcpdump` and Wireshark capture packets — last resort for deep debugging
40
41## Firewalls and NAT
42- Stateful firewalls track connections — allow response to outbound requests automatically
43- Port forwarding maps external port to internal IP:port — required to expose services behind NAT
44- Hairpin NAT for internal access to external IP — not all routers support it
45- UPnP auto-configures port forwarding — convenient but security risk, disable on servers
46
47## Load Balancing
48- Round-robin distributes sequentially — simple but ignores server capacity
49- Least connections sends to least busy — better for varying request durations
50- Health checks remove dead servers — configure appropriate intervals and thresholds
51- Sticky sessions (affinity) keep user on same server — needed for stateful apps, breaks scaling
52
53## VPNs and Tunnels
54- VPN encrypts traffic to exit point — all traffic appears from VPN server IP
55- Split tunneling sends only some traffic through VPN — reduces latency for local resources
56- WireGuard is modern and fast — simpler than OpenVPN, better performance
57- SSH tunnels for ad-hoc port forwarding — `ssh -L local:remote:port` creates secure tunnel
58
59## SSL/TLS
60- TLS 1.2 minimum, prefer 1.3 — older versions have known vulnerabilities
61- Certificate chain: leaf → intermediate → root — missing intermediate causes validation failures
62- SNI allows multiple certs on one IP — older clients without SNI get default cert
63- Let's Encrypt certs expire in 90 days — automate renewal or face outages
64
65## Common Mistakes
66- Assuming DNS changes are instant — TTL means old records persist in caches
67- Blocking ICMP entirely — breaks path MTU discovery, causes mysterious failures
68- Forgetting IPv6 — services may be accessible on IPv6 even with IPv4 firewall
69- Hardcoding IPs instead of hostnames — breaks when IPs change
70- Not checking both TCP and UDP — some services need UDP (DNS, VPN, game servers)
71- Confusing latency and bandwidth — high bandwidth doesn't mean low latency