TCP
Connection-oriented. A handshake sets up the session, and lost segments are retransmitted. Use it when the bytes must arrive intact, as with web pages, SSH, and file copies.
Study guide · Core notes
Reference notes for how hosts are addressed, how names resolve, which device forwards traffic, and where the customer's job starts in IaaS, PaaS, and SaaS.
How to read these notes: Items tagged Extra sit outside the everyday set, such as Wi-Fi 7 and legacy ports. Learn the unmarked items first. New to the topic? Start with the overview for domains and a study plan. Port and cloud facts match the CompTIA A+ notes.
Use the layer to decide which address or device is involved.
| OSI | Name | What you see there | TCP/IP grouping |
|---|---|---|---|
| 7 | Application | HTTP, DNS, SMTP, and the programs users touch | Application |
| 6 | Presentation | Formatting and encryption such as TLS | Application |
| 5 | Session | Starting and ending a conversation between programs | Application |
| 4 | Transport | TCP and UDP, and port numbers | Transport |
| 3 | Network | IP addresses and routers | Internet |
| 2 | Data Link | MAC addresses, switches, and Wi-Fi frames | Link |
| 1 | Physical | Cables, radio, bits, and hubs | Link |
Connection-oriented. A handshake sets up the session, and lost segments are retransmitted. Use it when the bytes must arrive intact, as with web pages, SSH, and file copies.
Connectionless. There is no handshake and no guarantee of delivery. DHCP, most DNS lookups, and voice or video often use it because a late retry is worse than a dropped packet.
Address versus port: An IP address identifies a host on a network. A port identifies a program on that host. HTTPS on a server is IP plus TCP port 443, not the IP alone.
Know which ranges are private, which mean "no DHCP," and how many hosts a prefix allows.
| Type | Range |
|---|---|
| Private (RFC 1918) | 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16 |
| APIPA | 169.254.0.0/16 |
| IPv4 loopback | 127.0.0.1 |
| IPv6 loopback | ::1 |
| IPv6 link-local | fe80::/10 |
| IPv6 global unicast | 2000::/3 |
| Prefix | Mask | Usable hosts |
|---|---|---|
| /8 | 255.0.0.0 | 16,777,214 |
| /16 | 255.255.0.0 | 65,534 |
| /24 | 255.255.255.0 | 254 |
| /25 | 255.255.255.128 | 126 |
| /26 | 255.255.255.192 | 62 |
| /27 | 255.255.255.224 | 30 |
| /28 | 255.255.255.240 | 14 |
IPv4 addresses are 32 bits, written as four decimal octets. IPv6 addresses are 128 bits, written as eight hexadecimal groups. You may replace one run of zero groups with ::, and only once. 172.16.0.0/12 covers 172.16.0.0 through 172.31.255.255, so 172.32.0.1 is not private. NAT lets many private hosts share a public address; the private ranges themselves are not routed on the public internet.
Default gateway: The router on the host's own subnet. Traffic for other networks is sent there. A wrong mask can make a host treat a remote address as local and skip the gateway.
Learn the number, the transport, the job, and whether the protocol encrypts by default.
| Port | Protocol | Transport | Purpose |
|---|---|---|---|
| 20, 21 | FTP | TCP | File transfer. 21 is control and 20 is data. Not encrypted. SFTP is SSH on 22, not FTP. |
| 22 | SSH, SFTP | TCP | Encrypted remote shell and file transfer over SSH. |
| 23 | Telnet | TCP | Legacy remote shell in clear text. Replace it with SSH. |
| 25 | SMTP | TCP | Sending and relaying email. |
| 53 | DNS | UDP and TCP | Names to addresses. TCP is used for large responses and zone transfers. |
| 67, 68 | DHCP | UDP | 67 is the server and 68 is the client. |
| 69 | TFTP Extra | UDP | Simple unauthenticated file transfer, often for network boot. |
| 80 | HTTP | TCP | Web traffic without TLS. |
| 110 | POP3 | TCP | Downloads mail to one client and usually removes it from the server. |
| 143 | IMAP | TCP | Reads mail that stays on the server and syncs across devices. |
| 389 | LDAP | TCP | Directory queries. LDAPS on 636 is Extra. |
| 443 | HTTPS | TCP | Web traffic protected by TLS. |
| 445 | SMB | TCP | Windows file and printer sharing. |
| 3389 | RDP | TCP | Graphical remote desktop. |
Pick the device by the problem. A Wi-Fi name is not a routing problem, and a full disk is not a switch problem.
| Device | Decision it makes |
|---|---|
| Hub Extra | Repeats an electrical signal out every port. It has no MAC table. Modern networks use switches. |
| Switch | Forwards a frame to the port where that destination MAC was learned. Unknown unicasts are flooded. |
| Router | Forwards packets between IP networks using a routing table. The default gateway is a router interface. |
| Access point | Bridges wireless clients onto the wired LAN. It does not, by itself, route between IP networks. |
| Firewall | Allows or blocks traffic by rules such as address, port, and state. It is not a substitute for patching. |
| Modem | Converts between the local network and the provider's link, such as cable or DSL. |
| Load balancer | Spreads client requests across several servers so one host is not the only path. |
A MAC address is a layer 2 identifier on the local link, usually 48 bits. A switch uses it. An IP address is a layer 3 identifier that routers use between networks. ARP (or Neighbor Discovery on IPv6) connects an IP address to a MAC address on the local subnet.
Speeds are theoretical maximums. Real throughput is lower. These match the CompTIA A+ wireless table.
| Standard | Band | Max rate | What to remember |
|---|---|---|---|
| 802.11a | 5 GHz | 54 Mbps | Legacy. Less interference than 2.4 GHz, shorter range. |
| 802.11b | 2.4 GHz | 11 Mbps | Legacy. Microwaves, cordless phones, and Bluetooth overlap this band. |
| 802.11g | 2.4 GHz | 54 Mbps | Backward-compatible with 802.11b. |
| 802.11n (Wi-Fi 4) | 2.4 and 5 GHz | 600 Mbps | MIMO and channel bonding. |
| 802.11ac (Wi-Fi 5) | 5 GHz | about 6.9 Gbps | Downlink MU-MIMO and beamforming. |
| 802.11ax (Wi-Fi 6 / 6E) | 2.4, 5, and 6 GHz | about 9.6 Gbps | 6 GHz is Wi-Fi 6E. OFDMA helps dense networks. 6 GHz requires WPA3. |
| 802.11be (Wi-Fi 7) Extra | 2.4, 5, and 6 GHz | about 46 Gbps | 320 MHz channels and multi-link operation. |
2.4 GHz channels: In North America, channels 1, 6, and 11 do not overlap. Putting two access points on channel 1 and channel 2 makes them interfere. The SSID is the network name clients look for; hiding it is not encryption.
A host needs an address before it can use a name, and a name before people can remember the address.
| Name | Role |
|---|---|
| A | A hostname to an IPv4 address. |
| AAAA | A hostname to an IPv6 address. |
| CNAME | An alias that points at another hostname, not directly at an IP address. |
| MX | The mail servers that accept email for a domain. |
| NS | The authoritative name servers for a zone. |
| TXT | Text, often used for SPF and other mail checks. |
| PTR Extra | An IP address back to a name (reverse DNS). |
| DHCP Discover | The client broadcasts to find a server (UDP 68 to 67). |
| DHCP Offer | A server offers an address and options such as mask, gateway, and DNS. |
| DHCP Request | The client asks to take that offer. |
| DHCP Ack | The server confirms the lease. The four steps are DORA: Discover, Offer, Request, Ack. |
Commands: On Windows, ipconfig /all shows the lease, ipconfig /release and ipconfig /renew redo DHCP, and ipconfig /flushdns clears the local resolver cache. nslookup queries DNS. On Linux, ip addr and resolvectl or dig are the usual tools. See the Linux CLI networking notes for ip and ss.
Change one thing at a time, and test from the host outward.
| What you observe | Likely place to look |
|---|---|
| Address is 169.254.x.x | DHCP failed. Check the cable or Wi-Fi association, the VLAN, the DHCP server, and the scope, then renew. |
| Cannot ping the default gateway | Local link, wrong address or mask, wireless not associated, or the gateway is down. |
| Gateway answers, a public IP does not | The path past the gateway: routing, NAT, or the provider link. |
| Public IP answers, the hostname does not | DNS. Check the configured DNS servers, then the record. Flush the local cache after a record change. |
| Name resolves, the page still fails | The application or its port: firewall, TLS certificate, or the service is not listening. |
ping sends ICMP echo requests and shows whether a host answers. It does not prove that TCP port 443 is open. tracert on Windows and traceroute on Linux list routers along the path. A timeout at one hop can be a filter, not always a broken link.
The same definitions are in the CompTIA A+ cloud notes.
| Service model | Provider operates | Customer operates | Example |
|---|---|---|---|
| IaaS | Hardware, networking, storage, and virtualization | Guest OS, middleware, runtime, applications, and data | A virtual machine such as Amazon EC2 or an Azure VM |
| PaaS | Everything in IaaS plus the OS and runtime | Applications and data | A platform you deploy code to, such as Google App Engine |
| SaaS | The application stack | Settings, accounts, and data | Microsoft 365, Google Workspace, Salesforce |
Vendor menus differ. The ideas below are the ones that transfer.
A region is a geographic area where a provider runs data centers. An availability zone is an isolated site inside that region, with separate power and networking. Putting instances in more than one zone reduces the chance that one site failure takes the service down. A content delivery network caches copies closer to users so they do not all fetch the original object across the world.
A Type 1 hypervisor (VMware ESXi, Microsoft Hyper-V, Proxmox VE) runs on the hardware. A Type 2 hypervisor (VirtualBox, VMware Workstation, Parallels) runs on a host operating system. A container shares the host kernel instead of booting a full guest OS, so it starts faster and uses less overhead. A virtual private cloud is an isolated virtual network where you choose subnets, route tables, and gateways.
The provider secures the cloud platform. You secure what you put in it. The line moves with the service model: on IaaS you patch the guest OS, on SaaS the provider patches the application, and in every model you decide who can see the data.
| Idea | What it means in practice |
|---|---|
| HTTP versus HTTPS | HTTP on TCP 80 is readable on the path. HTTPS is HTTP inside TLS, usually on TCP 443. |
| In transit versus at rest | TLS protects data while it moves. Encryption at rest protects stored disks and objects if the media is copied. |
| WPA2 and WPA3 | Both encrypt Wi-Fi. WEP is obsolete. An open network does not encrypt. Wi-Fi 6E on 6 GHz requires WPA3. |
| MFA | More than one factor: something you know, something you have, or something you are. A second password is not a second factor. |
| Least privilege | Grant only the access a person or service needs. Prefer a role the service assumes over a long-lived access key stored on disk. |
| Security group | A virtual firewall on a cloud resource. It filters traffic to that resource. It does not patch the operating system or classify the data. |
| Public object store | An object container left open to the internet exposes the files. Lock it down and do not store secrets in a public bucket. |
A switch forwards frames on a local network using MAC addresses. A router forwards packets between IP networks using IP addresses and a routing table. An access point attaches wireless clients; it is not a router by itself.
169.254.0.0/16 is the APIPA range. A host picks it when it cannot lease an address from DHCP. Check the link, the DHCP server or scope, then release and renew the lease.
The customer. In IaaS the provider operates the hardware, network, storage, and virtualization. The customer manages the guest operating system, applications, and data.
Cloud product names and Wi-Fi certifications change. Use these notes for the model, then confirm the current console and standard with the provider.
Drill the facts, then test them under a timer.
Scope, domains, address and port map, cloud models, and a study plan.
Reference notes for layers, addresses, ports, devices, Wi-Fi, DNS, DHCP, and cloud models.
40 recall cards in four decks, plus memory notes for ports, ranges, and service models.
200 original questions with custom exams, explanations, and a score report by domain.
Useful companions while you study.
Generate strong random passwords with custom length, characters, symbols, and security options.
Encode text and files to Base64 or decode Base64 data with UTF-8 support.
Convert structured data between JSON and YAML with formatting and validation.
Compare two text blocks and highlight added, removed, and changed content.
NodnWebTools provides general informational, educational, and convenience resources. Calculations, conversions, estimates, and learning materials may contain errors or become outdated. Financial, tax, medical, legal, and travel information is not professional advice. Verify important results and current requirements with qualified professionals or authoritative sources. Protect sensitive files and personal information, review each tool’s privacy limitations, and use only content you are authorized to process. You are responsible for how you use and share results. Study resources are independent and do not guarantee exam success or imply certification-provider endorsement. Amazon Web Services, Microsoft Azure, Google Cloud, and CompTIA are trademarks of their respective owners. NodnWebTools is not affiliated with, endorsed by, or sponsored by Amazon, Microsoft, Google, or CompTIA.