chore: sync content to repo (#9906)

Co-authored-by: nilbuild <4921183+nilbuild@users.noreply.github.com>
This commit is contained in:
github-actions[bot]
2026-05-05 11:08:00 +02:00
committed by GitHub
co-authored by nilbuild
parent e887915712
commit 63eef79202
117 changed files with 351 additions and 0 deletions
@@ -0,0 +1,3 @@
# Access Points & Controllers
Wireless access points (APs) are devices that broadcast Wi-Fi signals and connect wireless clients to a wired network. In larger deployments, multiple access points are managed by a wireless controller, which centralizes configuration, monitoring, and roaming policies across all APs. This controller-based architecture simplifies management and ensures consistent performance and security across the entire wireless network.
@@ -0,0 +1,3 @@
# Access Points
A wireless access point (AP) is a device that creates a wireless local area network, typically in an office or large building, by connecting to a wired router or switch and broadcasting a Wi-Fi signal. Multiple access points can be deployed across a large area to extend wireless coverage and allow devices to roam seamlessly. Access points are distinct from routers —they extend the network wirelessly but do not typically perform routing functions on their own.
@@ -0,0 +1,3 @@
# Application
The Application layer is the seventh and topmost layer of the OSI model, where end-user software interacts with the network. It provides network services directly to applications, enabling functions like web browsing, email, file transfer, and domain name resolution. Protocols such as HTTP, FTP, SMTP, and DNS all operate at this layer.
@@ -0,0 +1,3 @@
# Application
The Application layer of the TCP/IP model is the topmost layer and encompasses all the protocols that applications use to communicate over the network. It combines the functions of the OSI Session, Presentation, and Application layers into one. Protocols like HTTP, DNS, SMTP, FTP, and SSH all operate here, directly serving user-facing applications.
@@ -0,0 +1,3 @@
# ARP
ARP, or Address Resolution Protocol, is used to map an IP address to a physical MAC address on a local network. When a device wants to communicate with another device on the same network, it uses ARP to discover which MAC address corresponds to a known IP address. The result is stored temporarily in an ARP cache to speed up future lookups.
@@ -0,0 +1,3 @@
# Bandwidth
Bandwidth refers to the maximum amount of data that can be transmitted over a network connection in a given amount of time, typically measured in bits per second (bps). Higher bandwidth means more data can flow simultaneously, which generally results in faster network performance. It is often compared to the width of a pipe: the wider the pipe, the more water (data) can flow through it at once.
@@ -0,0 +1,3 @@
# BGP
BGP, or Border Gateway Protocol, is the routing protocol that powers the Internet by exchanging routing information between autonomous systems, i.e., the large networks operated by ISPs, corporations, and other organizations. It is a path-vector protocol that makes routing decisions based on network policies, path attributes, and rules rather than simply the shortest path. BGP is responsible for ensuring that traffic can reach any two points on the global Internet.
@@ -0,0 +1,3 @@
# Bluetooth Basics
Bluetooth is a short-range wireless communication standard used to connect devices over distances typically up to 10 meters. It operates in the 2.4 GHz frequency band and is designed for low-power, point-to-point or small-group connections between devices like phones, headsets, keyboards, and IoT sensors. Bluetooth is not a replacement for Wi-Fi, but complements it for personal area networking and device pairing scenarios.
@@ -0,0 +1,3 @@
# CIDR
CIDR, or Classless Inter-Domain Routing, is a method of allocating IP addresses and routing that replaced the older class-based system. Instead of fixed classes (A, B, C), CIDR uses a slash notation (e.g., 192.168.1.0/24) to indicate how many bits are used for the network portion of the address. This allows for more flexible and efficient use of IP address space and is the standard method used in modern networking.
@@ -0,0 +1,3 @@
# Circuit Level Gateway
A circuit-level gateway is a type of firewall that operates at the session layer and monitors TCP handshakes to verify that a connection is legitimate before allowing data to flow. Unlike application-layer proxies, it does not inspect the content of the data itself — only the connection establishment. Once a session is deemed valid, traffic passes through without further inspection, making it faster but less thorough than application-layer firewalls.
@@ -0,0 +1,3 @@
# Client-Server Network
A client-server network is a model where one or more central servers provide resources or services, and multiple client devices request and consume those resources. The server manages shared resources such as files, databases, or applications, while clients interact with them through the network. This model is widely used in enterprise environments because it centralizes management, improves security, and makes it easier to scale.
@@ -0,0 +1,3 @@
# Client
A client is any device or software application that sends requests to a server to access resources or services. In everyday terms, your web browser acts as a client when it asks a web server to load a page. Clients initiate communication in the client-server model and rely on servers to respond with the requested data or functionality.
@@ -0,0 +1,3 @@
# Cloud
In networking, the cloud refers to a model of delivering computing resources, such as servers, storage, databases, and networking, over the Internet on a pay-as-you-go basis. Rather than owning and maintaining physical infrastructure, organizations can provision and scale resources through cloud providers like AWS, Azure, or Google Cloud. This shifts network design considerations to include connectivity to cloud environments, hybrid architectures, and cloud-native security.
@@ -0,0 +1,3 @@
# Cloudflare
Cloudflare's DNS resolver, known by its address 1.1.1.1, is a public DNS service focused on speed and privacy. It is consistently ranked among the fastest DNS resolvers in the world and does not log user queries for advertising purposes. Cloudflare also supports DNS over HTTPS (DoH) and DNS over TLS (DoT) to encrypt DNS queries and prevent snooping.
@@ -0,0 +1,3 @@
# Data Link
The Data Link layer is the second layer of the OSI model, responsible for node-to-node data transfer and error detection within a single network segment. It organizes raw bits from the Physical layer into frames and uses MAC addresses to identify devices on the local network. This layer is divided into two sublayers: the Logical Link Control (LLC) and the Media Access Control (MAC).
@@ -0,0 +1,3 @@
# Default Gateway
A default gateway is the IP address of the router that a device uses to send traffic destined for networks outside its own local subnet. When a device does not have a specific route for a destination, it forwards the packet to the default gateway, which then handles the routing decision. In most home and office networks, the default gateway is the IP address of the local router.
@@ -0,0 +1,3 @@
# DHCP
DHCP, or Dynamic Host Configuration Protocol, is a network management protocol that automatically assigns IP addresses and other network configuration parameters to devices when they join a network. Without DHCP, administrators would need to manually configure the IP address, subnet mask, gateway, and DNS settings on every device. DHCP simplifies network management by handling these assignments dynamically from a central server or router.
@@ -0,0 +1,3 @@
# DNS
DNS, or Domain Name System, is the system that translates human-readable domain names like www.example.com into IP addresses that computers use to identify each other on the network. Without DNS, users would need to memorize IP addresses to visit websites or access online services. DNS operates as a distributed, hierarchical database spread across many servers around the world.
@@ -0,0 +1,3 @@
# DoS & DDoS
A DoS (Denial of Service) attack is an attempt to make a network resource or service unavailable by overwhelming it with a flood of illegitimate traffic or requests. A DDoS (Distributed Denial of Service) attack is the same concept but launched from many different sources simultaneously — often thousands of compromised machines in a botnet — making it much harder to block. These attacks do not typically steal data but can cause significant downtime and financial damage to the targeted organization.
@@ -0,0 +1,3 @@
# EIGRP
EIGRP, or Enhanced Interior Gateway Routing Protocol, is an advanced distance-vector routing protocol developed by Cisco that combines features of both distance-vector and link-state protocols. It uses a composite metric based on bandwidth, delay, load, and reliability to calculate the best route and converges faster than traditional distance-vector protocols. EIGRP is efficient in terms of bandwidth usage and CPU load, making it popular in Cisco-based enterprise networks.
@@ -0,0 +1,3 @@
# Encryption Basics
Encryption is the process of converting readable data (plaintext) into an unreadable format (ciphertext) using an algorithm and a key, so that only authorized parties with the correct key can decrypt and read it. It is the foundation of data security in networking, protecting information in transit and at rest from unauthorized access. The two main types are symmetric encryption, where the same key is used to encrypt and decrypt, and asymmetric encryption, which uses a pair of public and private keys.
@@ -0,0 +1,3 @@
# Failover
Failover is the process by which a system automatically switches to a backup server, network path, or resource when the primary one becomes unavailable due to failure or maintenance. The goal is to minimize downtime and ensure continuity of service without requiring manual intervention. Failover configurations can be active-passive, where the backup sits idle until needed, or active-active, where multiple systems share the load and take over seamlessly if one fails.
@@ -0,0 +1,3 @@
# Firewalls
A firewall is a network security device or software that monitors and controls incoming and outgoing network traffic based on predefined security rules. It acts as a barrier between a trusted internal network and untrusted external networks, blocking traffic that does not meet the specified criteria. Firewalls are a foundational component of network security and can be implemented in hardware, software, or as a cloud-based service.
@@ -0,0 +1,3 @@
# Frame
A frame is a unit of data transmission at the Data Link layer of the OSI model. It wraps raw bits into a structured format that includes source and destination MAC addresses, the data payload, and error-checking information. Frames are used to move data between devices on the same local network segment.
@@ -0,0 +1,3 @@
# FTP / SFTP
FTP (File Transfer Protocol) is a standard protocol used to transfer files between a client and a server over a network. It operates over two channels (one for commands and one for data), but transmits information in plain text, making it insecure. SFTP (SSH File Transfer Protocol) is a secure alternative that encrypts both commands and data using SSH, making it the preferred choice for transferring sensitive files.
@@ -0,0 +1,3 @@
# Google
Google's public DNS service, accessible at 8.8.8.8 and 8.8.4.4, is one of the most widely used DNS resolvers in the world. It provides fast and reliable DNS resolution and supports modern security extensions like DNSSEC to protect against DNS spoofing. Google Public DNS is free to use and is often chosen as an alternative to ISP-provided DNS for its speed and reliability.
@@ -0,0 +1,3 @@
# Host
A host is any device connected to a network that has an IP address and can send or receive data. This includes computers, servers, printers, smartphones, and any other networked device. The term is used broadly to refer to any endpoint that participates in network communication.
@@ -0,0 +1,3 @@
# Hotspot and Tethering
A hotspot is a physical location or device that provides wireless Internet access to other devices, typically by sharing a cellular data connection. Tethering is the act of connecting a device, such as a laptop, to a smartphone's mobile data connection via Wi-Fi, USB, or Bluetooth to access the Internet. Both concepts are relevant for network engineers when designing mobile connectivity solutions or troubleshooting remote access scenarios.
@@ -0,0 +1,3 @@
# How does the Internet Work?
The Internet is a massive global network of interconnected computers and devices that communicate by sending data to each other using a shared set of rules. When you visit a website, your device sends a request that travels through multiple routers and networks until it reaches the server hosting that site, which then sends the data back to your screen. This exchange happens through a system of protocols —most notably TCP/IP— that break data into small packets, route them across the network, and reassemble them at the destination.
@@ -0,0 +1,3 @@
# HTTP / HTTPS
HTTP (HyperText Transfer Protocol) is the foundation of data communication on the web, defining how messages are formatted and transmitted between browsers and servers. HTTPS is the secure version of HTTP, adding an SSL/TLS encryption layer to protect data from being intercepted during transmission. Most modern websites use HTTPS to ensure privacy and data integrity for their users.
@@ -0,0 +1,3 @@
# Hub
A hub is a basic network device that connects multiple devices in a LAN and broadcasts incoming data to all connected ports, regardless of the intended recipient. This makes hubs simple but inefficient, as all devices receive all traffic, even if it is not meant for them. Hubs have largely been replaced by switches, which are smarter and handle traffic more efficiently.
@@ -0,0 +1,3 @@
# IDS / IPS
An IDS (Intrusion Detection System) monitors network traffic for suspicious patterns and known attack signatures, alerting administrators when potential threats are detected without taking direct action. An IPS (Intrusion Prevention System) goes a step further by automatically blocking or dropping malicious traffic in real time based on the same detection mechanisms. Together, they provide visibility into network threats and an active layer of defense against intrusions.
@@ -0,0 +1,3 @@
# Internet
The Internet layer of the TCP/IP model corresponds to the Network layer of the OSI model and is responsible for logical addressing and routing packets across networks. The primary protocol at this layer is IP (Internet Protocol), which assigns addresses to packets and determines how they are routed toward their destination. ICMP and ARP also operate at this layer.
@@ -0,0 +1,3 @@
# Introduction
A network engineer is a technology professional responsible for designing, building, and maintaining the communication infrastructure that allows computers and devices to exchange data. This includes planning how networks are structured, selecting and configuring hardware like routers and switches, troubleshooting connectivity issues, and ensuring the network remains secure and reliable. Network engineers work across a wide range of environments and must understand both the theoretical principles behind how data travels and the practical skills needed to implement and manage real-world systems.
@@ -0,0 +1,3 @@
# IP Address
An IP address is a numerical label assigned to each device on a network that uses the Internet Protocol for communication. It serves two main purposes: identifying the host and providing its location in the network for routing purposes. IP addresses come in two versions: IPv4, which uses a 32-bit format, and IPv6, which uses a 128-bit format to accommodate a much larger number of devices.
@@ -0,0 +1,3 @@
# IP Addressing
IP addressing is the system used to assign unique numerical identifiers to devices on a network so they can communicate with each other. Every device connected to a network needs an IP address, which tells other devices where to send data. IP addresses come in two versions — IPv4 and IPv6 — and can be assigned statically by an administrator or dynamically by a DHCP server.
@@ -0,0 +1,3 @@
# IP vs MAC vs ARP
An IP address is a logical address used to identify a device across networks and is assigned by software, while a MAC address is a physical address burned into the network interface hardware, used for communication within a local network segment. ARP (Address Resolution Protocol) bridges the two by resolving a known IP address to its corresponding MAC address so that data can be delivered on the local network. Together, these three concepts work in layers: IP handles routing across networks, MAC handles delivery within a network, and ARP connects them.
@@ -0,0 +1,3 @@
# IPSec vs SSL VPN
IPSec (Internet Protocol Security) VPNs operate at the network layer, encrypting all IP traffic between two endpoints and are commonly used for site-to-site connections between networks. SSL/TLS VPNs operate at the application layer, typically accessible through a web browser or lightweight client, and are better suited for remote individual user access. The choice between the two depends on the use case: IPSec is generally preferred for permanent network-to-network tunnels, while SSL VPNs offer more flexibility for end-user remote access.
@@ -0,0 +1,3 @@
# IPv4 vs IPv6
IPv4 is the original version of the Internet Protocol, using 32-bit addresses written in dotted decimal notation (e.g., 192.168.1.1), allowing for about 4.3 billion unique addresses. IPv6 was introduced to solve the problem of IPv4 address exhaustion, using 128-bit addresses written in hexadecimal (e.g., 2001:0db8::1), providing an astronomically larger address space. Beyond address size, IPv6 also introduces improvements in routing efficiency, auto-configuration, and built-in security features.
@@ -0,0 +1,3 @@
# LAN
A LAN, or Local Area Network, is a network that connects devices within a limited geographic area, such as a home, office, or building. LANs typically use Ethernet cables or Wi-Fi to link computers, printers, and other devices, allowing them to share files and resources at high speeds. Because all devices are physically close, LANs offer low latency and high bandwidth compared to larger network types.
@@ -0,0 +1,3 @@
# Latency
Latency is the time it takes for a data packet to travel from its source to its destination, usually measured in milliseconds. Low latency means data arrives quickly, which is critical for real-time applications like video calls and online gaming. Latency is influenced by factors such as physical distance, network congestion, and the number of hops between devices.
@@ -0,0 +1,3 @@
# Least Connections
The Least Connections algorithm is a load-balancing method that routes each new request to the server with the fewest active connections at that moment. This approach is more adaptive than Round Robin because it accounts for varying request durations and server load. It is particularly useful when requests have significantly different processing times, ensuring that no single server gets backed up while others are idle.
@@ -0,0 +1,3 @@
# Link Aggregation
Link aggregation is a technique that combines multiple physical network connections between two devices into a single logical link, increasing bandwidth and providing redundancy. If one physical link fails, the others continue to carry traffic without interruption. It is standardized under IEEE 802.3ad (LACP) and is commonly used between switches, servers, and storage devices to improve both performance and reliability.
@@ -0,0 +1,3 @@
# Load Balancer
A load balancer is a device or software that distributes incoming network traffic across multiple servers to prevent any single server from becoming overwhelmed. By spreading the workload, load balancers improve application availability, responsiveness, and fault tolerance. They can operate at Layer 4 (based on IP and TCP/UDP) or Layer 7 (based on application-level data like HTTP headers and URLs).
@@ -0,0 +1,3 @@
# MAC Address Tables
A MAC address table, also called a CAM (Content Addressable Memory) table, is a database maintained by a network switch that maps MAC addresses to the specific ports those devices are connected to. When a frame arrives, the switch looks up the destination MAC address in this table to determine which port to forward the frame to. If the address is not found, the switch floods the frame to all ports until it learns the correct mapping.
@@ -0,0 +1,3 @@
# Mac Address
A MAC address, or Media Access Control address, is a unique hardware identifier assigned to a network interface card (NIC) by its manufacturer. It operates at the Data Link layer and is used to identify devices within the same local network segment. Unlike IP addresses, MAC addresses are typically fixed and do not change as a device moves between networks.
@@ -0,0 +1,3 @@
# MAN
A MAN, or Metropolitan Area Network, is a network that covers a geographic area roughly the size of a city or a large campus. It is larger than a LAN but smaller than a WAN, often used by organizations or service providers to connect multiple buildings or locations within the same metropolitan region. MANs typically use fiber optic cables or wireless links to achieve high-speed connectivity across the area.
@@ -0,0 +1,3 @@
# Mobile Networks
Mobile networks are wireless communication systems that provide connectivity to devices over large geographic areas through a network of cell towers and base stations. They have evolved through generations, from 2G and 3G through 4G to 5G, each offering faster speeds, lower latency, and greater capacity. Understanding mobile network architecture is increasingly important as more devices rely on cellular connectivity and as 5G enables new enterprise and IoT use cases.
@@ -0,0 +1,3 @@
# Modems
A modem (modulator-demodulator) is a device that converts digital data from a computer into a format suitable for transmission over a communication medium such as telephone lines or cable, and vice versa. It serves as the bridge between your local network and your Internet Service Provider's infrastructure. Modern modems often include router functionality built in, combining both devices into a single unit.
@@ -0,0 +1,3 @@
# MPLS
MPLS, or Multiprotocol Label Switching, is a technique for speeding up network traffic by using short labels to direct packets along predetermined paths rather than making complex routing decisions at each hop. When a packet enters an MPLS network, it is assigned a label, and subsequent routers forward it based on that label without needing to inspect the IP header. MPLS is widely used by service providers to manage traffic efficiently and deliver services like VPNs and quality of service guarantees.
@@ -0,0 +1,3 @@
# NetFlow / sFlow
NetFlow is a Cisco-developed protocol that collects and exports metadata about IP traffic flows passing through a network device, providing visibility into who is communicating with whom, how much data is being exchanged, and what protocols are in use. sFlow is a similar, vendor-neutral sampling-based protocol that works across a broader range of hardware. Both are used for traffic analysis, capacity planning, anomaly detection, and security monitoring without requiring full packet capture.
@@ -0,0 +1,3 @@
# Network Access
The Network Access layer is the lowest layer of the TCP/IP model, combining the functions of the OSI Physical and Data Link layers. It handles how data is physically transmitted over the network medium, including framing, MAC addressing, and hardware-level error detection. Ethernet and Wi-Fi protocols operate at this layer.
@@ -0,0 +1,3 @@
# Network Attacks
Network attacks are deliberate actions taken by malicious actors to disrupt, intercept, or gain unauthorized access to network resources and data. They can target vulnerabilities in protocols, devices, software, or human behavior to compromise the confidentiality, integrity, or availability of a network. Understanding the types of attacks that exist is the first step in designing defenses and responding effectively when incidents occur.
@@ -0,0 +1,3 @@
# Network Devices
Network devices are the physical hardware components that make up a network and enable communication between connected devices. Each type of device serves a specific function, such as directing traffic, amplifying signals, or connecting different network segments. Understanding what each device does and how they interact is fundamental to designing and troubleshooting any network.
@@ -0,0 +1,3 @@
# Network
The Network layer is the third layer of the OSI model, responsible for logical addressing and routing data packets between devices across different networks. It uses IP addresses to determine the best path for data to travel from source to destination. Routers operate at this layer, making forwarding decisions based on routing tables and protocols.
@@ -0,0 +1,3 @@
# Next-Generation
A Next-Generation Firewall (NGFW) is an advanced firewall that goes beyond traditional packet filtering and stateful inspection to include deep packet inspection, application awareness, intrusion prevention, and user identity tracking. NGFWs can identify and control traffic based on the specific application being used, regardless of port or protocol, and can detect and block sophisticated threats in real time. They represent the current standard for enterprise perimeter security.
@@ -0,0 +1,3 @@
# Nmap
Nmap (Network Mapper) is a free, open-source tool used to discover hosts and services on a network by sending packets and analyzing the responses. It can identify active devices, open ports, running services, operating systems, and potential vulnerabilities across a network. Nmap is widely used by network engineers and security professionals for network inventory, auditing, and reconnaissance.
@@ -0,0 +1,3 @@
# NTP
NTP, or Network Time Protocol, is used to synchronize the clocks of computers and network devices over a network. Accurate timekeeping is essential for logging events, coordinating distributed systems, and ensuring security certificates work correctly. NTP works by having devices query time servers and adjust their local clocks to match, accounting for network delay in the process.
@@ -0,0 +1,3 @@
# Observability
Network observability refers to the ability to understand the internal state and behavior of a network by collecting and analyzing data from its components, including logs, metrics, traces, and flow records. It goes beyond basic monitoring by providing deep insight into why things are happening, not just what is happening. Good observability enables network engineers to detect issues early, troubleshoot faster, and optimize performance across complex, distributed environments.
@@ -0,0 +1,3 @@
# OpenDNS
OpenDNS is a cloud-based DNS service operated by Cisco that provides fast DNS resolution along with additional security and filtering features. It can block access to malicious websites, phishing domains, and unwanted content categories before a connection is ever established. OpenDNS is commonly used by organizations and families to add a layer of protection at the DNS level without requiring software on individual devices.
@@ -0,0 +1,3 @@
# OSI Model
The OSI (Open Systems Interconnection) model is a conceptual framework that standardizes the functions of a network into seven distinct layers, from physical transmission up to application-level communication. It was developed to help different systems and vendors communicate using common standards, making troubleshooting and network design more systematic. Each layer has a specific role and interacts only with the layers directly above and below it.
@@ -0,0 +1,3 @@
# OSPF
OSPF, or Open Shortest Path First, is a link-state interior gateway routing protocol used within a single autonomous system or organization. It works by having each router build a complete map of the network topology and then calculate the shortest path to every destination using Dijkstra's algorithm. OSPF converges quickly after network changes and is widely used in medium to large enterprise networks.
@@ -0,0 +1,3 @@
# Package
In networking, a package (or packet) is a small chunk of data broken off from a larger message for transmission across a network. Each packet travels independently through the network and is reassembled at the destination. Packets contain both the payload data and header information, such as source and destination addresses, needed to route them correctly.
@@ -0,0 +1,3 @@
# Packet Filtering
Packet filtering is the most basic type of firewall technique, where each packet is inspected individually against a set of rules based on attributes like source IP, destination IP, port numbers, and protocol. If a packet matches an allow rule, it passes through; if it matches a deny rule or no rule at all, it is dropped. Packet filtering is fast and lightweight, but provides limited protection since it does not consider the state of the connection or the content of the data.
@@ -0,0 +1,3 @@
# Packet prioritization
Packet prioritization is the process of classifying network traffic and assigning different levels of importance to different types of packets so that critical traffic is processed and delivered first. Real-time traffic, like VoIP and video conferencing, is given higher priority than background activities like file downloads or software updates. This ensures that time-sensitive applications remain functional even when the network is under heavy load.
@@ -0,0 +1,3 @@
# PAN
A PAN, or Personal Area Network, is a small network designed for communication between devices in proximity to a single person, typically within a range of a few meters. Examples include connecting a smartphone to wireless earbuds via Bluetooth or linking a laptop to a smartwatch. PANs can be wired (such as USB) or wireless (such as Bluetooth or infrared).
@@ -0,0 +1,3 @@
# Peer-to-Peer Network
A peer-to-peer (P2P) network is one where each device, or peer, can act as both a client and a server, sharing resources directly with other devices without a central server. This model is simpler and cheaper to set up than a client-server network, making it common in small home networks or applications like file sharing. However, P2P networks can be harder to manage and secure as they grow in size.
@@ -0,0 +1,3 @@
# Physical
The Physical layer is the first and lowest layer of the OSI model, responsible for the actual transmission of raw bits over a physical medium such as copper cables, fiber optics, or radio waves. It defines the electrical, mechanical, and timing specifications for hardware components like network cables, connectors, and network interface cards. Everything at this layer deals with the physical delivery of signals, not their meaning.
@@ -0,0 +1,3 @@
# Port
A port is a numerical identifier used to direct network traffic to a specific application or service running on a device. While an IP address identifies the device, the port number identifies which program on that device should handle the incoming data. For example, web traffic typically uses port 80 for HTTP and port 443 for HTTPS.
@@ -0,0 +1,3 @@
# Presentation
The Presentation layer is the sixth layer of the OSI model, responsible for translating data between the format used by the application and the format used for network transmission. It handles tasks such as data encryption and decryption, compression, and character encoding. This layer ensures that data sent from one system can be read by another, regardless of differences in internal data representation.
@@ -0,0 +1,3 @@
# Protocol
A protocol is a set of rules that defines how data is formatted, transmitted, and received between devices on a network. Protocols ensure that different systems, regardless of manufacturer or operating system, can predictably communicate with each other. Examples include TCP, IP, HTTP, and DNS, each governing a specific aspect of how network communication works.
@@ -0,0 +1,3 @@
# Proxy
A proxy firewall operates at the application layer and acts as an intermediary between internal clients and external servers, inspecting the full content of network requests and responses. Instead of allowing direct connections, all traffic is routed through the proxy, which can apply content filtering, authentication, and logging. Because it terminates and re-establishes each connection, a proxy firewall provides deep inspection but can introduce latency.
@@ -0,0 +1,3 @@
# Public vs Private Addresses
Public IP addresses are globally unique addresses assigned by Internet Service Providers and are reachable over the Internet. Private IP addresses are reserved for use within local networks and are not routable on the public Internet (ranges like 192.168.x.x, 10.x.x.x, and 172.16.x.x are commonly used internally). Devices with private addresses access the Internet through a process called NAT (Network Address Translation), which maps multiple private addresses to a single public one.
@@ -0,0 +1,3 @@
# QoS (Quality of Service)
QoS, or Quality of Service, refers to a set of techniques used to manage network traffic and ensure that critical applications receive the bandwidth, low latency, and reliability they need. Without QoS, all traffic is treated equally, which can cause voice calls to break up or video to buffer when the network is congested. QoS works by classifying, prioritizing, and managing packets so that high-priority traffic is delivered first.
@@ -0,0 +1,3 @@
# Quad9
Quad9 is a free, public DNS resolver that focuses on security by blocking access to known malicious domains at the DNS level. It uses threat intelligence from multiple cybersecurity partners to identify and block harmful websites before a connection is made, without logging personally identifiable information. Quad9 is operated by a non-profit organization and is accessible at the address 9.9.9.9.
@@ -0,0 +1,3 @@
# RIP
RIP, or Routing Information Protocol, is one of the oldest dynamic routing protocols, using a distance-vector algorithm to determine the best path based on hop count —the number of routers a packet must pass through to reach its destination. It has a maximum hop count of 15, making it unsuitable for large networks. RIP is simple to configure but has largely been replaced by more efficient protocols like OSPF and EIGRP in modern networks.
@@ -0,0 +1,3 @@
# Round Robin
Round Robin is one of the simplest load balancing algorithms, where incoming requests are distributed sequentially to each server in the pool, one after another, cycling back to the first when the end is reached. It assumes all servers have roughly equal capacity and is easy to implement. Round Robin works well when the servers are similar in performance and the requests are similar in complexity.
@@ -0,0 +1,3 @@
# Routers
A router is a network device that forwards data packets between different networks, directing traffic based on IP addresses. It determines the best path for data to travel from source to destination, making routing decisions using routing tables and protocols. Routers are what connect your home or office network to the Internet and are essential for communication between separate networks.
@@ -0,0 +1,3 @@
# Routing
Routing is the process of selecting a path for traffic to travel across one or more networks from source to destination. Routers perform this function by examining the destination IP address of each packet and consulting a routing table to determine where to forward it next. Routing can be done statically, where paths are manually configured, or dynamically, where routers automatically discover and update paths using routing protocols.
@@ -0,0 +1,3 @@
# SAN
A SAN, or Storage Area Network, is a specialized high-speed network that provides block-level access to shared storage devices such as disk arrays and tape libraries. Unlike a regular network where files are shared, a SAN makes storage appear as locally attached to the servers that use it, enabling fast and reliable data access. SANs are commonly used in enterprise environments to support databases, virtualization, and backup systems.
@@ -0,0 +1,3 @@
# Server
A server is a computer or software system that listens for requests from clients and responds by providing resources, data, or services. Servers can host websites, store files, manage emails, or run applications that many users access simultaneously. They are typically designed to be always available, handling multiple client connections at the same time.
@@ -0,0 +1,3 @@
# Session
The Session layer is the fifth layer of the OSI model, responsible for establishing, managing, and terminating communication sessions between applications. It handles synchronization and dialog control, ensuring that data exchanges are organized and that sessions can be paused and resumed if needed. Examples of protocols operating at this layer include NetBIOS and RPC.
@@ -0,0 +1,3 @@
# Site-to-Site vs Remote Access
Site-to-site VPNs connect two entire networks together — such as a branch office to a headquarters — over an encrypted tunnel, allowing devices on both networks to communicate as if they were on the same LAN. Remote access VPNs allow individual users to securely connect to a corporate network from any location, typically using a VPN client on their device. Both serve different purposes and are often deployed together in enterprise environments to address different connectivity needs.
@@ -0,0 +1,3 @@
# SMTP / IMAP
SMTP (Simple Mail Transfer Protocol) is the protocol used to send emails from a client to a server or between mail servers. IMAP (Internet Message Access Protocol) is used by email clients to retrieve and manage messages stored on a mail server, allowing access from multiple devices while keeping messages synchronized. Together, these protocols handle the sending and receiving sides of email communication.
@@ -0,0 +1,3 @@
# SNMP
SNMP, or Simple Network Management Protocol, is a widely used protocol for monitoring and managing network devices such as routers, switches, servers, and printers. It allows a central management system to query devices for performance data — like CPU usage, interface statistics, and error counts — and can also receive unsolicited alerts called traps when certain conditions occur. SNMP is a foundational tool in network operations centers (NOCs) for maintaining visibility across large infrastructure.
@@ -0,0 +1,3 @@
# SNTP
SNTP, or Simple Network Time Protocol, is a simplified version of NTP used to synchronize device clocks over a network. It is less precise than full NTP but requires fewer resources, making it suitable for devices that do not need highly accurate timekeeping. SNTP is commonly used in embedded systems, IoT devices, and environments where simplicity is prioritized over precision.
@@ -0,0 +1,3 @@
# Socket
A socket is the combination of an IP address and a port number, forming a unique endpoint for network communication. When two devices establish a connection, each end uses a socket to send and receive data, creating a two-way communication channel. Sockets are the fundamental abstraction used by applications to interact with the network.
@@ -0,0 +1,3 @@
# SSH
SSH, or Secure Shell, is a network protocol that provides a secure, encrypted channel for remotely accessing and managing devices over an unsecured network. It replaces older, insecure protocols like Telnet by encrypting all communication between the client and the server. Network engineers use SSH extensively to configure routers, switches, and servers from a remote location.
@@ -0,0 +1,3 @@
# SSL / TLS
SSL (Secure Sockets Layer) and its successor TLS (Transport Layer Security) are cryptographic protocols designed to provide secure communication over a network. They work by encrypting the data exchanged between a client and a server, verifying the identity of the parties involved through digital certificates. TLS is the modern standard and is used to secure HTTPS connections, email, and many other internet services.
@@ -0,0 +1,3 @@
# Stateful Inspection
Stateful inspection, also known as dynamic packet filtering, is a firewall technique that tracks the state of active network connections and makes filtering decisions based on context, not just individual packets. By maintaining a state table of established connections, a stateful firewall can allow response packets that belong to a legitimate session while blocking unsolicited incoming traffic. This provides significantly better security than simple packet filtering without sacrificing too much performance.
@@ -0,0 +1,3 @@
# Static vs Dynamic Routing
Static routing involves manually configuring fixed routes in a router's routing table, which do not change unless an administrator updates them. It is simple and predictable, but does not adapt automatically to network changes or failures. Dynamic routing uses routing protocols that allow routers to automatically discover routes, share information with neighboring routers, and adapt to topology changes in real time.
@@ -0,0 +1,3 @@
# STP
STP, or Spanning Tree Protocol, is a network protocol that prevents loops in Ethernet networks by creating a logical tree topology from a physically redundant network. Without STP, multiple paths between switches could cause broadcast storms that would bring a network down. STP works by electing a root bridge and blocking redundant paths, re-enabling them only if the primary path fails.
@@ -0,0 +1,3 @@
# Subnet Masks
A subnet mask is a 32-bit number used alongside an IP address to determine which portion of the address identifies the network and which portion identifies the individual host. It works by applying a bitwise AND operation with the IP address to extract the network address. For example, a subnet mask of 255.255.255.0 means the first three octets represent the network and the last octet identifies hosts within that network.
@@ -0,0 +1,3 @@
# Subnetting
Subnetting is the process of dividing a large network into smaller, more manageable sub-networks called subnets. It helps improve network performance by reducing broadcast traffic and allows organizations to organize their network logically, such as separating departments or locations. Subnetting works by borrowing bits from the host portion of an IP address to create a subnet identifier, controlled by the subnet mask.
@@ -0,0 +1,3 @@
# Supernetting
Supernetting, also known as route aggregation or summarization, is the process of combining multiple smaller network routes into a single, larger route advertisement. This reduces the size of routing tables and simplifies routing by representing several contiguous subnets as one summary route. It is commonly used in large-scale networks and by ISPs to keep routing tables manageable.
@@ -0,0 +1,3 @@
# Switches
A switch is a network device that connects multiple devices within the same local network and forwards data based on MAC addresses. Unlike a hub, a switch sends data only to the specific device it is intended for, making communication more efficient and reducing unnecessary network traffic. Managed switches offer additional features like VLANs, port security, and traffic monitoring.
@@ -0,0 +1,3 @@
# Switching
Switching is the process of forwarding data frames within a local network based on MAC addresses. A network switch receives incoming frames and sends them only to the port connected to the intended destination device, unlike a hub which broadcasts to all ports. Switching forms the foundation of modern LAN design and can be enhanced with features like VLANs, STP, and link aggregation.
@@ -0,0 +1,3 @@
# TCP/IP Model
The TCP/IP model is a practical, four-layer framework that describes how data is transmitted over the Internet and most modern networks. It was developed by the U.S. Department of Defense and serves as the foundation for Internet communication. Unlike the OSI model's seven layers, the TCP/IP model consolidates functions into four layers: Network Access, Internet, Transport, and Application.
@@ -0,0 +1,3 @@
# Throughput
Throughput is the actual amount of data successfully transferred over a network in a given period of time, as opposed to the theoretical maximum that bandwidth represents. While bandwidth is the capacity of a network link, throughput reflects real-world performance after accounting for packet loss, latency, and protocol overhead. It is also measured in bits per second.
@@ -0,0 +1,3 @@
# Traffic shaping
Traffic shaping is a QoS technique used to control the rate at which data is transmitted on a network, smoothing out bursts and enforcing bandwidth limits for specific types of traffic. By delaying or queuing packets that exceed a defined rate, traffic shaping ensures that no single application or user monopolizes network resources. It is commonly used by ISPs and enterprises to manage congestion and maintain consistent performance across the network.

Some files were not shown because too many files have changed in this diff Show More