120 lines
4.9 KiB
Markdown
120 lines
4.9 KiB
Markdown
# Network – Basics
|
||
|
||
Core networking concepts: IP addressing, subnets, ports, routing, and protocols.
|
||
|
||
Related pages:
|
||
|
||
- [Network / DNS](./DNS.md)
|
||
- [Network / Reverse Proxy](./ReverseProxy.md)
|
||
- [Network / SSH](./SSH.md)
|
||
- [Network / VPN Basics](./VPN/Basics.md)
|
||
- [Network / Firewall](./Firewall.md)
|
||
|
||
---
|
||
|
||
## 1. IP Addresses
|
||
|
||
Every device on a network is identified by an **IP address**. The most common version is IPv4, written as four numbers separated by dots: `192.168.1.18`. Each number is between 0 and 255, giving 4 bytes (32 bits) per address.
|
||
|
||
### 1.1 Private vs Public Addresses
|
||
|
||
Some ranges are reserved for private use — they are only valid inside a local network and are never routed on the public internet:
|
||
|
||
| Range | Example | Common use |
|
||
|-------------------|-----------------|------------------------------|
|
||
| `10.0.0.0/8` | `10.10.10.1` | VPNs, corporate networks |
|
||
| `172.16.0.0/12` | `172.16.0.1` | Docker default bridge |
|
||
| `192.168.0.0/16` | `192.168.1.18` | Home/office LANs |
|
||
|
||
Everything else is a **public** address, routable on the internet. Your internet box has one public IP assigned by your ISP.
|
||
|
||
### 1.2 Subnets and CIDR Notation
|
||
|
||
A subnet groups a range of IP addresses together. The size is expressed with **CIDR notation**: a `/` followed by the number of fixed bits.
|
||
|
||
- `/24` → first 24 bits are fixed → 256 addresses (`192.168.1.0` to `192.168.1.255`).
|
||
- `/32` → all 32 bits are fixed → exactly one address.
|
||
- `/16` → first 16 bits are fixed → 65 536 addresses.
|
||
|
||
The most common home network is a `/24`, for example `192.168.1.0/24`.
|
||
|
||
A **subnet mask** expresses the same thing differently: `/24` ↔ `255.255.255.0`.
|
||
|
||
---
|
||
|
||
## 2. Ports
|
||
|
||
An IP address identifies a machine. A **port** identifies a specific service or application running on that machine. Ports are numbers from 0 to 65 535.
|
||
|
||
When two machines communicate they use an IP + port pair: `192.168.1.18:80`.
|
||
|
||
### 2.1 Why Ports Exist
|
||
|
||
A server typically runs several services at once — a web server, an SSH daemon, a database, etc. Ports allow the OS to route each incoming packet to the correct service.
|
||
|
||
- A packet arrives at `192.168.1.18:443` → the OS delivers it to the HTTPS server.
|
||
- A packet arrives at `192.168.1.18:22` → the OS delivers it to the SSH daemon.
|
||
|
||
When you "open a port", you are telling a firewall or router to allow traffic destined for that port number to pass through.
|
||
|
||
### 2.2 TCP vs UDP
|
||
|
||
| Protocol | Characteristics | Common uses |
|
||
|----------|--------------------------------------------------------------|-------------------------------------------|
|
||
| **TCP** | Connection-oriented, reliable, ordered delivery | HTTP/HTTPS, SSH, databases, email |
|
||
| **UDP** | Connectionless, no delivery guarantee, lower overhead | DNS, WireGuard, video streaming, QUIC |
|
||
|
||
TCP establishes a connection before transferring data and retransmits lost packets. UDP fires packets without verifying receipt — faster but not guaranteed.
|
||
|
||
### 2.3 Well-Known Ports
|
||
|
||
Ports 0–1023 are "well-known" — standardised assignments used by common services:
|
||
|
||
| Port | Protocol | Service |
|
||
|-------|----------|--------------------------|
|
||
| 22 | TCP | SSH |
|
||
| 53 | TCP/UDP | DNS |
|
||
| 80 | TCP | HTTP |
|
||
| 443 | TCP | HTTPS |
|
||
| 51820 | UDP | WireGuard (conventional) |
|
||
|
||
Ports 1024–49 151 are "registered". Ports 49 152–65 535 are "dynamic" (used temporarily for outbound connections).
|
||
|
||
For filtering and controlling port access, see [Network / Firewall](./Firewall.md).
|
||
|
||
---
|
||
|
||
## 3. Routing
|
||
|
||
Routing is the process of forwarding packets from one network to another. At home this is mostly transparent:
|
||
|
||
1. Your device sends a packet.
|
||
2. If the destination is on the same subnet, it is delivered directly.
|
||
3. Otherwise it is sent to the **default gateway** (your router), which forwards it towards the internet.
|
||
|
||
The default gateway is normally the IP of your router on the local network (for example `192.168.1.1`).
|
||
|
||
---
|
||
|
||
## 4. HTTP and HTTPS
|
||
|
||
**HTTP** (HyperText Transfer Protocol) is the protocol used by web browsers and APIs. It is a request-response protocol over TCP:
|
||
|
||
- A client sends a request: `GET /page HTTP/1.1`
|
||
- A server responds with a status code and a body: `200 OK`
|
||
|
||
**HTTPS** is HTTP over a **TLS** (Transport Layer Security) encrypted connection. TLS:
|
||
|
||
- Encrypts traffic so it cannot be read in transit.
|
||
- Authenticates the server via a certificate.
|
||
|
||
Modern browsers require HTTPS. Self-signed certificates work for internal networks but require the client to explicitly trust the issuing CA.
|
||
|
||
For TLS and certificates in depth, see:
|
||
|
||
- [Security / Certificates](../Security/Certificates.md)
|
||
|
||
For HTTP routing via a reverse proxy, see:
|
||
|
||
- [Network / Reverse Proxy](./ReverseProxy.md)
|