Book 11 · Cheat sheet
Networking
How data travels between machines: addresses, ports, protocols and the things that make connections fast, slow or safe.
Software Dictionary · softwaredictionary.org/categories/networking/cheat-sheet
- 01ARPAddress Resolution Protocol
- ARP is a network protocol that finds the MAC address belonging to an IPv4 address on the local network, so a device knows where to deliver each Ethernet frame.
- ARP maps an IPv4 address to a MAC address on the local network.
- A device broadcasts an ARP request, and the owner of the address replies with its MAC address.
- Answers are kept in an ARP cache for a short time.
- 02Bandwidth
- Bandwidth is the maximum amount of data a network connection can carry per second, usually measured in megabits or gigabits per second (Mbps or Gbps).
- Bandwidth is the maximum data transfer capacity of a connection.
- It is measured in bits per second, such as Mbps or Gbps.
- Throughput is the amount actually achieved, and it is often lower than bandwidth.
- 03BGPBorder Gateway Protocol
- BGP (Border Gateway Protocol) is the routing protocol that links the internet's autonomous systems by letting them announce which IP ranges they can reach.
- BGP routes traffic between the internet's autonomous systems.
- Networks announce the IP prefixes they can reach to their neighbors.
- Routes carry the path of AS numbers and follow each network's policies.
- 04CIDRClassless Inter-Domain Routing
- CIDR (Classless Inter-Domain Routing) writes an IP range as an address and prefix length, like 10.0.0.0/16; the prefix counts the leading network bits.
- CIDR writes a range as an address plus a prefix length, such as /24.
- The prefix is the number of leading bits that identify the network.
- A /24 has 256 addresses, a /16 has 65,536 and a /32 is one address.
- 05Default Gateway
- A default gateway is the router a device sends traffic to whenever the destination lies outside its own subnet, acting as the network's exit to other networks.
- The default gateway is the router a device uses for every destination outside its own subnet.
- Local destinations are reached directly; everything else goes through the gateway.
- It usually comes from DHCP and appears in the routing table as the default route, 0.0.0.0/0.
- 06DHCPDynamic Host Configuration Protocol
- DHCP is a network protocol that automatically gives devices an IP address and other settings, such as the router and DNS server, when they join a network.
- DHCP automatically assigns IP addresses and network settings to devices.
- The four-step exchange is Discover, Offer, Request, Acknowledge (DORA).
- Addresses are leased for a limited time and renewed before they expire.
- 07DNS Record
- A DNS record is an entry in a domain's DNS zone that maps a name to information, such as an IP address (A, AAAA), another name (CNAME) or mail servers (MX).
- A DNS record maps a name to data, with a type, value and TTL.
- A and AAAA point to IPv4 and IPv6 addresses; CNAME points to another name.
- MX handles email; TXT holds verification and email security data.
- 08Firewall
- A firewall is a security system that checks network traffic and allows or blocks it based on rules, acting as a barrier between trusted and untrusted networks.
- A firewall allows or blocks network traffic according to rules.
- Rules typically match on IP address, port, protocol, and traffic direction.
- Stateful firewalls track connections and automatically allow replies to outgoing requests.
- 09HTTP/2
- HTTP/2 is the second major version of HTTP, sending many requests and responses at once over one connection in a compact binary format so pages load faster.
- HTTP/2 was standardized in 2015, based on Google's SPDY.
- Multiplexing sends many requests at once over one connection.
- It uses binary frames and HPACK header compression.
- 10IP AddressInternet Protocol Address
- An IP address is a numeric label assigned to each device on a network so that data can be routed to it, much like a postal address for a house.
- An IP address identifies a device on a network so data can be routed to it.
- IPv4 uses 32-bit addresses like 192.168.1.10; IPv6 uses 128-bit addresses like 2001:db8::1.
- Private addresses work only inside a local network; public addresses are reachable from the internet.
- 11IPv4Internet Protocol version 4
- IPv4 is the internet's original addressing system, using 32-bit addresses written as four numbers such as 192.168.1.10, allowing about 4.3 billion addresses.
- IPv4 uses 32-bit addresses written as four numbers, such as 192.168.1.10.
- It allows about 4.3 billion addresses and dates from 1981.
- 10/8, 172.16/12 and 192.168/16 are private ranges; 127.0.0.1 is loopback.
- 12IPv6Internet Protocol version 6
- IPv6 is the newest version of the Internet Protocol, using 128-bit addresses that give every device a unique address and replace the exhausted IPv4 pool.
- IPv6 uses 128-bit addresses, compared with 32 bits in IPv4.
- Addresses are written in hexadecimal groups, and :: shortens one run of zero groups, as in 2001:db8::1.
- Devices can configure their own addresses with SLAAC or get them from DHCPv6.
- 13LANLocal Area Network
- A LAN is a network that connects devices within a small area such as a home, office or school, letting them reach each other directly and share resources fast.
- A LAN connects devices within a small area, such as a home, office, or building.
- It is built from Ethernet switches, Wi-Fi access points, or both; a wireless LAN is called a WLAN.
- LANs offer high bandwidth and low latency because distances are short.
- 14Latency
- Latency is the delay between sending a request and the start of a response, usually measured in milliseconds, and it shapes how responsive an app feels.
- Latency is delay, usually measured in milliseconds.
- Round-trip time (RTT) measures how long a message takes to go and come back.
- Physical distance, network hops, queuing, and server processing all add to latency.
- 15Localhost
- Localhost is the hostname for the computer you are using; it resolves to the loopback address 127.0.0.1 (::1 in IPv6), so its traffic stays on the machine.
- Localhost is the name for your own machine, the loopback address.
- It resolves to 127.0.0.1 in IPv4 and ::1 in IPv6.
- Loopback traffic never leaves the computer.
- 16MAC AddressMedia Access Control Address
- A MAC address is a 48-bit hardware identifier assigned to a network interface and used to deliver data between devices on the same local network.
- A MAC address identifies a network interface, such as a Wi-Fi card or an Ethernet port.
- It is 48 bits long and written as six hexadecimal pairs, like 3c:22:fb:9a:41:0e.
- MAC addresses are used only within the local network, at the data link layer (layer 2).
- 17NATNetwork Address Translation
- NAT is a technique in which a router rewrites the IP addresses in passing packets, letting many devices on a private network share one public IP address.
- NAT rewrites IP addresses, and usually ports, as packets cross a router.
- It lets many devices with private addresses share one public IPv4 address.
- The router keeps a translation table so replies reach the right internal device.
- 18Network Switch
- A network switch is a device that connects devices on the same local network and forwards each frame only to the port where its destination MAC address lives.
- A network switch connects devices within a single local network.
- It forwards frames by destination MAC address, at layer 2 of the OSI model.
- It learns which device is on which port by recording source MAC addresses in a MAC address table.
- 19OSI ModelOpen Systems Interconnection Model
- The OSI model is a conceptual framework that splits network communication into seven layers, from physical cables up to the applications people use.
- The OSI model divides networking into seven layers, from Physical (1) to Application (7).
- Each layer adds its own header as data moves down the stack, a process called encapsulation.
- Layer 3 handles IP addresses and routing; layer 4 handles ports and protocols such as TCP and UDP.
- 20Packet
- A packet is a small, formatted unit of data sent across a network, made of a header with addressing information and a payload that carries the actual data.
- A packet is a small unit of data sent across a network.
- It has a header with addressing and control information and a payload with the data.
- Large messages are split into packets and reassembled by the receiver.
- 21Ping
- Ping is a network utility that checks whether a host is reachable by sending it small ICMP echo requests and measuring how long each reply takes to return.
- Ping checks whether a host is reachable and measures the round-trip time to it.
- It sends ICMP echo requests and waits for echo replies.
- Its summary reports the minimum, average, and maximum latency plus packet loss.
- 22Port
- A port is a number from 0 to 65535 that identifies a specific program or service on a device, so traffic reaching an IP address gets to the right application.
- A port number identifies a specific program or service on a device.
- Port numbers range from 0 to 65535, and TCP and UDP each have their own set.
- Well-known ports include 22 (SSH), 53 (DNS), 80 (HTTP), and 443 (HTTPS).
- 23Proxy Server
- A proxy server is an intermediary that receives network requests on behalf of clients or servers and passes them on, adding control, caching, or privacy.
- A proxy server relays requests and responses between clients and servers.
- A forward proxy acts for clients and hides their IP addresses from the sites they visit.
- A reverse proxy acts for servers and hides the backend servers from clients.
- 24QUIC
- QUIC is a modern transport protocol built on UDP that provides encrypted, reliable, multiplexed connections with fast setup, and it is the foundation of HTTP/3.
- QUIC is a reliable, encrypted transport protocol that runs over UDP.
- TLS 1.3 encryption is built in, and new connections usually need only one round trip.
- Independent streams avoid TCP's head-of-line blocking.
- 25Router
- A router is a networking device that forwards packets between different networks, choosing the next hop for each one based on its destination IP address.
- A router forwards packets between different networks based on their destination IP address.
- It works at the network layer, layer 3 of the OSI model.
- A routing table maps network prefixes to next hops, and the most specific match wins.
- 26SMTPSimple Mail Transfer Protocol
- SMTP is the internet's standard protocol for sending email, used by apps to submit messages and by mail servers to relay them to the recipient's mail server.
- SMTP is the standard protocol for sending and relaying email.
- Mail servers exchange messages on port 25; apps submit mail on port 587 or 465 with TLS.
- Senders find the recipient's mail server through DNS MX records.
- 27Socket
- A socket is a software endpoint that a program opens to send and receive data over a network, identified by an IP address, a port number, and a protocol.
- A socket is a program's endpoint for sending and receiving network data.
- Servers call bind(), listen(), and accept(); clients call connect(); both then send() and recv().
- A TCP connection is identified by source IP, source port, destination IP, and destination port.
- 28SSHSecure Shell
- SSH is a cryptographic network protocol for securely logging in to and running commands on remote computers, encrypting all traffic between the two machines.
- SSH provides encrypted remote login, command execution, and file transfer.
- SSH servers listen on TCP port 22 by default.
- Key-based authentication with a private and a public key is safer than passwords.
- 29Subnet
- A subnet is a smaller network carved out of a larger one by splitting its range of IP addresses, which keeps traffic organized, contained, and easier to secure.
- A subnet is a range of IP addresses that forms a smaller network within a larger one.
- CIDR notation such as 10.0.1.0/24 gives the network address and how many bits form the prefix.
- A /24 IPv4 subnet has 256 addresses, of which 254 can be assigned to devices.
- 30TCPTransmission Control Protocol
- TCP is a core internet protocol that delivers data between two programs reliably and in order, by opening a connection and resending anything that gets lost.
- TCP is connection-oriented: it opens a connection with a three-way handshake before sending data.
- It guarantees delivery, correct order, and error checking using sequence numbers and acknowledgments.
- Lost data is detected and retransmitted automatically.
- 31TCP Handshake
- The TCP handshake is the SYN, SYN-ACK, ACK exchange a client and server use to open a connection and agree on starting sequence numbers before sending data.
- The handshake is SYN, SYN-ACK, ACK.
- Both sides exchange random initial sequence numbers.
- It costs one round trip before any data flows.
- 32Throughput
- Throughput is the amount of data or work a system actually handles per unit of time, like megabits per second on a network or requests per second on a server.
- Throughput is the work or data actually handled per unit of time.
- Networks measure it in bits per second; servers in requests per second.
- It is usually lower than bandwidth because of overhead and congestion.
- 33Traceroute
- Traceroute is a network diagnostic tool that lists every router a packet passes through on its way to a destination, along with the delay to reach each one.
- Traceroute lists each router hop between you and a destination, with the delay to each.
- It sends packets with increasing TTL values and reads the ICMP time exceeded replies.
- On Windows the command is tracert; Linux also offers tracepath and mtr.
- 34TTLTime to Live
- TTL (time to live) is a limit on how long data stays valid: router hops left for an IP packet, or seconds a DNS or cached answer may be reused.
- TTL limits how long data stays valid before it is dropped or refreshed.
- In IP packets it counts router hops; each router subtracts one.
- IPv6 calls the field the hop limit; traceroute relies on it.
- 35UDPUser Datagram Protocol
- UDP is a lightweight internet protocol that sends small, independent messages called datagrams without a connection, favoring speed over guaranteed delivery.
- UDP is connectionless: there is no handshake before data is sent.
- It does not guarantee delivery or order, and it does not prevent duplicates.
- Low overhead makes it fast and well suited to real-time applications.
- 36VPNVirtual Private Network
- A VPN is a technology that creates an encrypted tunnel between a device and another network, so traffic can travel privately across the public internet.
- A VPN creates an encrypted tunnel between a device and a remote network.
- Traffic appears to come from the VPN server's IP address instead of your own.
- Companies use VPNs for remote access and to connect networks site-to-site.
- 37WANWide Area Network
- A WAN is a network that connects devices and local networks across large distances, such as cities or countries, often over links rented from telecom providers.
- A WAN connects networks across long distances, such as offices in different cities or countries.
- The internet is the largest WAN.
- WAN links are usually leased from telecom providers or built as VPN tunnels over the internet.