Skip to content

Internet and Networking

A computer network is a set of interconnected devices that exchange data and share resources through agreed communication protocols. The Internet is the global packet-switched network of interconnected networks that uses the TCP/IP protocol suite. The Internet is infrastructure; the World Wide Web, email, file transfer and DNS are services that operate over it.

Network communication requires a source and destination, a transmission medium, addressing, rules for formatting and exchanging data, and intermediate devices that forward traffic. Scope, topology, protocol layer and service role answer different questions and must not be used interchangeably.

Networks are classified partly by geographical reach and partly by administrative ownership. The boundaries are descriptive rather than exact distance limits.

TypeTypical coverageOwnership and technologyExample and operating implication
PANA person’s immediate areaOne user; Bluetooth, USB or short-range wirelessPhone linked to a headset; very short reach and low infrastructure overhead
LANRoom, building or campusUsually one home or organization; Ethernet and Wi-FiPCs and printers in an office; high local capacity and direct local administration
MANTown or metropolitan regionMunicipality, operator or consortium; Metro Ethernet and fiber ringsFiber linking exchanges across Kathmandu; routing and resilient metropolitan paths are needed
WANRegional, national or globalMultiple organizations, telecom operators and ISPs; MPLS/IP, leased lines, microwave, submarine fiber and satelliteOperator backbone connecting provinces or the Internet; more hops, carrier agreements and greater delay/error exposure

PAN, LAN, MAN and WAN compared.

In the usual comparison, LAN delay and error exposure are lowest, MAN is intermediate, and WAN is highest because distance and the number of intermediate systems increase. This is a tendency, not a guarantee: a congested wireless LAN can perform worse than a well-engineered WAN.

LANs commonly permit direct local administration and high capacity. MAN and WAN designs additionally need routing, service-level agreements, path redundancy and strong protection when traffic crosses shared or untrusted facilities.

A network topology is either the physical arrangement of nodes, ports and links or the logical path followed by frames or signals. These views can differ: switched Ethernet is normally a physical star whose links are logically independent point-to-point connections.

Physical link arrangements and traffic direction for terminated bus, switched star, directional ring, partial mesh, full mesh and hierarchical tree topologies.

Physical link arrangements and traffic direction for terminated bus, switched star, directional ring, partial mesh, full mesh and hierarchical tree topologies.

TopologyArrangementAdvantagesFailure domain and limitations
BusEvery station taps one backbone terminated at both endsLow cable cost and simple small installationA backbone break or bad terminator can stop all nodes; the shared medium has collisions and poor fault isolation
StarEvery station has a separate link to a central hub or switchEasy addition, management and spoke-fault isolationOne spoke failure affects one node, but central-device or power failure affects the whole star
RingEach node has two neighbors in a closed loop; traffic follows the ring protocolOrderly, predictable access without a central hubOne link or node can break a single ring; dual counter-rotating rings improve recovery at extra cost
MeshNodes have several links; a full mesh joins every pairMultiple paths, high availability and load sharingPort/cable cost and routing complexity; full-mesh growth is quadratic
TreeAccess nodes feed distribution nodes under a core/rootScalable hierarchy and policy aggregationAn upper-level failure can disconnect an entire branch unless the hierarchy is redundantly connected

Characteristics of common network topologies.

For nn nodes in a full mesh, each node could connect to n−1n-1 others, but counting both ends would count every link twice. Therefore

An IP address is a logical network-layer identifier assigned to an interface. Routers compare its network prefix with routing-table entries to choose a next hop. It is not the same as a data-link MAC address, a DNS name, or the physical location of a device.

An IPv4 address contains 32 bits and is normally written as four decimal octets, for example 192.168.10.25. Early IPv4 allocation used the following classful interpretation.

ClassFirst octetDefault prefixHistorical purpose
A–126/8Very large unicast networks
B–191/16Medium unicast networks
C–223/24Small unicast networks
D–239Not host addressingMulticast
E–255Not ordinary host addressingReserved or experimental

Historical classful IPv4 ranges.

The entire 127.0.0.0/8 block is reserved for loopback: traffic sent there remains within the host. Zero-valued addresses also have special meanings; for example, 0.0.0.0 can denote an unspecified local address and 0.0.0.0/0 is the default route, so neither should be treated as an ordinary assigned host address without context.

PrefixMeaning
10.0.0.0/8Large private range
172.16.0.0/12Private range from 172.16.0.0 through 172.31.255.255
192.168.0.0/16Common home and organizational private range

Private IPv4 address space.

Private addresses can be routed internally but are not globally routed on the public Internet. An edge router often translates them with NAT, although NAT is not encryption and does not replace a firewall.

A subnet mask separates the network and host portions of an IPv4 address. It has nn leading one bits followed by 32−n32-n zero bits for prefix /n; bitwise AND of the address and mask gives the subnet address.

The subtraction reserves the all-zero host part as the network address and the all-one host part as the directed broadcast address. It is the traditional exam rule, not a universal law: /31 point-to-point links can use both addresses and /32 identifies one host route.

IPv6 expands the address to 128 bits and writes eight hexadecimal groups separated by colons, for example 2001:0db8:0000:0000:0000:ff00:0042:8329. Leading zeros in a group may be omitted and one consecutive run of zero groups may be compressed as ::.

FeatureIPv4IPv6
Address lengthbitsbits
NotationDotted decimalHexadecimal colon notation
Address space232≈4.3×1092^{32}\approx4.3\times10^92128≈3.4×10382^{128}\approx3.4\times10^{38}
Base headerVariable length, normally 20–60 bytesSimplified fixed 40-byte base header; optional information uses extension headers
BroadcastSupportedNo broadcast; multicast and anycast serve the relevant delivery cases
NATCommon because public addresses are scarceUsually less necessary for address conservation, though translation may still be deployed

IPv4 and IPv6 compared.

Layering divides communication into manageable services. At the sender, application data is carried by TCP, UDP or a transport built over UDP such as QUIC; IP supplies logical addressing and routing; Ethernet, Wi-Fi or another link technology creates a local frame; and the physical layer sends bits as electrical, optical or radio signals.

OSI and TCP/IP layer mapping with functions, protocol examples, PDUs and the encapsulation sequence from application data to transmitted bits.

OSI and TCP/IP layer mapping with functions, protocol examples, PDUs and the encapsulation sequence from application data to transmitted bits.

The seven-layer OSI model is a conceptual ISO reference framework, whereas the four-layer TCP/IP model describes the practical Internet architecture. Their functional mapping is:

  • OSI Application ++ Presentation ++ Session →\rightarrow TCP/IP Application;

  • OSI Transport →\rightarrow TCP/IP Transport;

  • OSI Network →\rightarrow TCP/IP Internet; and

  • OSI Data Link ++ Physical →\rightarrow TCP/IP Network Access.

The protocol data units (PDUs) are data at the upper layers, a TCP segment or UDP datagram at transport, an IP packet at network, a frame at data link and bits at physical. During encapsulation, each lower layer adds control information around the complete higher-layer PDU; the data-link layer commonly adds both a header and an error-detecting trailer/FCS. The receiver decapsulates in reverse and delivers the payload upward.

The Domain Name System (DNS) is a distributed hierarchical database that maps domain names to typed resource records, including IPv4/IPv6 addresses, mail exchangers and authoritative name servers. DNS resolution does not itself carry the later web or email content.

The host’s stub resolver first checks an unexpired browser or OS cache and then sends one recursive query to its configured recursive resolver. If that resolver has no valid cached answer, it performs iterative queries: a root server refers it to the relevant top-level domain (TLD) server, the TLD server refers it to the domain’s authoritative server, and the authoritative server returns the requested record.

DNS resolution as one recursive client query followed, on a cache miss, by iterative root, TLD and authoritative queries and TTL-controlled caching.

DNS resolution as one recursive client query followed, on a cache miss, by iterative root, TLD and authoritative queries and TTL-controlled caching.

The resolver returns the answer to the stub and caches the result for its time-to-live (TTL). Referrals, address records and negative answers may all be cached. A recursive resolver performs work on the client’s behalf; an iterative server normally returns the best answer or referral it has. The client stub does not normally walk the root/TLD hierarchy itself.

RecordPurpose
AMaps a name to an IPv4 address
AAAAMaps a name to an IPv6 address
CNAMEMakes one domain name an alias of another canonical name
MXIdentifies the mail exchanger for a domain
NSIdentifies an authoritative name server for a DNS zone
TXTCarries text information, including data used for SPF and DKIM verification

Common DNS resource records.

A Uniform Resource Locator (URL) identifies how and where a client can access a resource. Its complete general anatomy is

scheme://host:port/path?query#fragment

https://www.example.com:443/docs/page?unit=ict#dns

ComponentExampleFunction
SchemehttpsSelects the access protocol and its default port
Hostwww.example.comNames the destination host; DNS normally resolves it to one or more IP addresses
Port443Optionally selects the destination server process; the scheme supplies a default when omitted
Path/docs/pageIdentifies a resource within the server’s namespace
Queryunit=ictSupplies parameters to the server-side resource
FragmentdnsIdentifies a client-side section of the returned representation and is normally not sent in the HTTP request

Meaning of each URL component.

HTTP is a stateless application-layer request/response protocol. A client sends a method, target, headers and possibly a body; a server returns a status code, headers and possibly a representation. Stateless means each HTTP request is independently interpretable, not that a web application cannot maintain state through cookies, tokens or server-side sessions.

HTTP request and response between a browser and a web server, with the transport protection added by HTTPS/TLS.

HTTP request and response between a browser and a web server, with the transport protection added by HTTPS/TLS.

HTTPS carries HTTP through TLS. Certificate-based server authentication helps the client verify the named peer, encryption provides confidentiality in transit, and integrity protection detects modification. HTTPS does not prove that the site’s content is honest, remove endpoint malware or replace application authorization.

MethodIntended use
GETRetrieve a resource representation
POSTSubmit data for processing or create a subordinate resource
PUTReplace, or create at, the addressed resource
PATCHPartially update a resource
DELETERequest deletion of the addressed resource

Common HTTP methods.

CodeMeaningInterpretation
200OKRequest succeeded
301 / 302RedirectResource is permanently/temporarily available at another location
400Bad RequestServer cannot process malformed or invalid request syntax
401UnauthorizedAuthentication is required or failed; despite the name, this is primarily an authentication response
403ForbiddenServer understood the request but refuses authorization
404Not FoundRequested resource was not found
500Internal Server ErrorServer encountered an unexpected failure

Frequently tested HTTP status codes.

ProtocolFoundationConnections and common portSecurity meaning
FTPFile Transfer ProtocolTCP control connection on port 21 plus a separate active or passive data connectionBasic FTP does not encrypt credentials or payload
FTPSFTP with TLSFTP control/data model with explicit or implicit TLSAdds TLS protection while remaining FTP
SFTPSSH File Transfer ProtocolOne SSH connection, commonly TCP port 22A different protocol carried by SSH; it is not an FTP “secure mode”

File-transfer protocol distinction.

A hub is a physical-layer multiport repeater. A switch is a data-link bridge that learns source MAC addresses and forwards frames toward a learned destination port. A router is a network-layer device that matches destination IP addresses against a routing table and forwards packets between IP networks.

Hub, one-VLAN switch and router behavior, showing collision domains and the Layer-2 broadcast boundaries separated by routing.

Hub, one-VLAN switch and router behavior, showing collision domains and the Layer-2 broadcast boundaries separated by routing.

FeatureHubLayer-2 switchRouter
OSI layer / unitLayer 1 / bitsLayer 2 / framesLayer 3 / packets
Forwarding basisNone; repeats incoming bitsLearned MAC address tableLongest matching IP prefix and next hop
Collision domainsOne shared domainOne per switched portOne per interface or point-to-point link
Broadcast domainsOneOne per VLANEach routed interface is a separate IP broadcast domain
Typical useObsolete small or shared test segmentConnect hosts inside a LAN/VLANConnect LANs/VLANs to other networks or a WAN

Hub, Layer-2 switch and router compared.

A hub repeats unicast and broadcast traffic to every port and permits collisions on a shared half-duplex segment. A switch gives each port a separate full-duplex collision domain, but floods broadcasts and unknown unicasts within the VLAN. A router does not normally forward Layer-2 broadcasts, so its interfaces bound separate IP broadcast domains.

A server is a software process that listens for requests and provides controlled resources to client programs. A client initiates a request. One physical or virtual computer may run several server processes, distinguished by transport addresses and ports.

Client-server operation: the client initiates a request, the listening server processes it and returns a controlled response.

Client-server operation: the client initiates a request, the listening server processes it and returns a controlled response.

The destination IP address selects the server host and the TCP or UDP port selects the listening process. The server authenticates or validates the request as required, accesses a resource, returns a response and should log security-relevant activity.

ServerMain functionProtocols and common portsExample
WebStores or generates pages, files and API responsesHTTP/TCP 80; HTTPS with TLS commonly TCP 443Browser requests a self-care page from Nginx, Apache or an application server
EmailAccepts, relays, filters, stores and retrieves messagesSMTP relay TCP 25; submission 587; IMAP 143/993; POP3 110/995Sender server looks up the recipient MX record and transfers mail by SMTP
PrintShares printers, accepts jobs, queues/spools them and reports statusIPP commonly TCP 631, plus vendor and legacy print protocolsSeveral clients submit jobs that are serialized for one office printer

Web, email and print server roles and common ports.

Port numbers identify conventional service endpoints, but configuration can change them. A listed port therefore aids connection and filtering; it does not by itself authenticate the service.

Transmission media are guided when a physical conductor or waveguide confines the signal and unguided when electromagnetic waves propagate through free space.

MediumMain characteristicsTypical use
Twisted pairCheap and easy to install; copper attenuation and interference limit reach and rateEthernet LAN and telephone line
Coaxial cableBetter shielding than twisted pair; robust shared radio-frequency pathCable television and older Ethernet
Optical fiberVery high bandwidth, low loss, electrical isolation and immunity to EMIBackbone, FTTH and long-distance links

Guided transmission media.

MediumMain characteristicsTypical use
Radio waveOften omnidirectional and able to penetrate buildings; shared spectrum suffers interferenceWi-Fi and mobile communication
MicrowaveDirectional and normally line-of-sight; high antenna gain and frequency reuseTerrestrial point-to-point link and satellite uplink
InfraredShort range and usually line-of-sight; does not readily penetrate wallsRemote controls and short-range device links

Unguided transmission media.

Media selection balances required rate and reach against attenuation, noise, EMI, terrain, spectrum/licensing, security exposure, installation effort, availability and total cost.

TCP and UDP both use port numbers for process-to-process delivery, but provide different service contracts over IP.

FeatureTCPUDP
ConnectionConnection-oriented byte streamConnectionless datagrams
ReliabilitySequence numbers, acknowledgements and retransmissionBest effort; an application must add recovery if needed
OrderingDelivers bytes in order and suppresses duplicatesNo delivery, ordering or duplicate-suppression guarantee
Flow/congestion controlBuilt inNot supplied by UDP itself
Overhead and latencyMore setup/state/header overheadSmall header and no connection setup; low protocol overhead
Typical useWeb over HTTP/1.1 or HTTP/2, email, FTP and SSHMany DNS queries, streaming, VoIP, gaming and QUIC/HTTP/3

TCP and UDP compared.

“UDP is faster” is only a shorthand for lower built-in overhead. Application design, loss recovery, congestion and network conditions determine observed performance. DNS normally uses UDP for compact queries but can use TCP for large responses, retries and zone transfer; modern HTTP/3 uses QUIC over UDP while implementing reliability and security above UDP.

Email separates message transfer from mailbox access. SMTP pushes a message from a client to a submission server and between mail servers. The recipient then uses IMAP to synchronize a server-resident mailbox or POP3 primarily to download messages.

ProtocolDirection and functionImportant distinction
SMTPSends/submits and relays mail toward the recipient serverTransfer protocol; MX DNS records identify destination mail exchangers
POP3Downloads mail from server to clientSimple retrieval, often oriented toward local storage
IMAPSynchronizes mailbox state between server and one or more clientsFolders, flags and messages normally remain coordinated on the server

Core email protocols.

Email delivery from the sender client through SMTP submission and server-to-server relay to recipient mailbox access by IMAP or POP3.

Email delivery from the sender client through SMTP submission and server-to-server relay to recipient mailbox access by IMAP or POP3.

TLS-protected variants or STARTTLS protect links in transit, but mail can cross several administrative systems; endpoint access control, anti-spam checks and appropriate end-to-end content protection remain separate concerns.

A gateway connects dissimilar systems or performs protocol/format translation. In ordinary IP host configuration, the default gateway is more specifically the router to which a host sends packets for destinations outside its local subnet.

TermMeaning
InternetPublic global interconnection of IP networks
IntranetPrivate organizational network that uses Internet technologies such as IP, DNS, web applications and browsers
ExtranetControlled extension of private-network services to selected external partners, suppliers or customers

Internet, intranet and extranet.

An extranet is not simply a public website: identities, authorization and network/application controls restrict which external parties reach which private resources.

Security is layered because no single control supplies identity, confidentiality, authorization, availability and detection simultaneously.

ControlPurpose and qualification
FirewallPermits or denies traffic according to address, port, protocol, state or application policy; rules must be least-privilege and reviewed
AuthenticationVerifies a user, service or device identity; strong methods include MFA and certificate/key-based credentials
EncryptionProtects confidentiality and usually integrity in transit; it does not decide whether an authenticated party is authorized
VPNCreates an authenticated encrypted tunnel across an untrusted network; the protected endpoints and access policy still require security
Access controlLimits resources and operations to authorized identities, roles, devices or network segments
SegmentationUses VLANs, subnets, routing/firewall policy or separate zones to limit reachability and fault/attack propagation
Logging and monitoringRecords activity and detects suspicious behavior; logs need time synchronization, protection, review and response procedures
Patching and secure configurationRemoves known weaknesses, disables unused services and changes insecure defaults
Backup and recoveryRestores essential configurations and data after failure or attack; backups must be protected and restoration tested

Basic network controls and their purposes.

  • Scope: PAN is personal, LAN covers a site, MAN spans a city and WAN spans regions to the globe.

  • Topology: modern LANs commonly use switched star; WANs often use partial mesh, while full mesh needs n(n−1)/2n(n-1)/2 links.

  • Addressing: IPv4 is 32-bit and IPv6 is 128-bit; CIDR prefixes, not obsolete address classes, define modern networks.

  • Layering: OSI has seven layers and TCP/IP is commonly shown with four; each lower layer encapsulates the higher-layer PDU with its own control information.

  • Transport: TCP is reliable, ordered and connection-oriented; UDP is connectionless with low built-in overhead.

  • DNS: the stub makes a recursive request to a resolver; on a cache miss the resolver makes iterative root, TLD and authoritative queries.

  • URL: remember the exact order scheme://host:port/path?query#fragment.

  • Web: HTTP is stateless request/response; HTTPS adds TLS peer authentication, confidentiality and integrity in transit.

  • File transfer: FTP uses separate control and data connections, FTPS adds TLS to FTP, and SFTP is a distinct SSH protocol.

  • Devices: a hub repeats bits, a switch forwards frames by MAC address and a router forwards packets by IP prefix.

  • Domains: a hub shares one collision and broadcast domain; a switch separates collision domains per port and VLANs separate broadcast domains; router interfaces bound IP broadcast domains.

  • Media and services: guided media use copper/fiber, unguided media use free-space radio; server ports identify web, mail and print processes.

  • Email: SMTP transfers mail, POP3 downloads it and IMAP synchronizes a server-resident mailbox.

  • Private access: an intranet is internal; an extranet grants controlled access to selected external parties; the default gateway routes off-subnet traffic.