Networking
Networking
6 interactive questions
TCP vs UDP?
TCP = reliable, ordered, connection-oriented (3-way handshake), flow & congestion control. UDP = unreliable, unordered, connectionless, no handshake, lower overhead. Use TCP for correctness (HTTP, SSH); UDP for speed/latency (DNS, streaming, gaming).
What happens when you type `curl google.com`?
- DNS lookup (A/AAAA record) → IP. 2. TCP 3-way handshake (SYN, SYN-ACK, ACK). 3. TLS handshake (if HTTPS). 4. HTTP request sent. 5. Server responds. 6. Connection close (FIN/FIN-ACK). 🎯 Interviewers check if you mention DNS → TCP → TLS → HTTP.
What is the difference between `netstat` and `ss`?
netstat is legacy (from net-tools), reads /proc. ss is modern (iproute2), uses netlink sockets — much faster, shows more socket states, supports filters. ss -tulpn replaces netstat -tulpn.
How do you check if a port is listening?
ss -tulpn | grep :<port> or lsof -i :<port>. For remote: nc -zv host port or timeout 2 bash -c "cat < /dev/null > /dev/tcp/host/port".
What is `iptables` vs `nftables`?
iptables is the classic kernel packet filter (chains: INPUT, FORWARD, OUTPUT). nftables is the modern successor — single tool for IPv4/IPv6, faster, better syntax, atomic ruleset updates. Most distros now default to nftables with iptables compat layer.
How does DNS resolution work in Linux?
- Check
/etc/hosts. 2. Query resolver in/etc/resolv.conf(nameservers). 3. Recursive resolver walks root → TLD → authoritative. 4. Cache TTL. Tools:dig,nslookup,resolvectl. ⚠️ Systemd-resolved handles caching/DNS-over-TLS on modern distros.