On the wire

Networking

Every website and app depends on machines finding each other and passing data along. Networking covers how that works: the IP addresses and ports that identify a machine and the program on it, and the two transport protocols, TCP and UDP, that carry the data between them.

The rest is about getting around safely and quickly. Proxies relay traffic, VPNs tunnel it with encryption, firewalls decide who can reach what, and SSH is how people log in to servers. Latency, bandwidth and jitter explain why one connection feels instant and another lags.

11 terms · 2 comparisons · prices checked September 2026

11 terms, click any to open

Network basics

OSI model

Concept
A way of describing networking as seven stacked layers, from the cable up to the app, so people can say exactly where a problem or a product sits.

From the bottom up, the seven layers are physical (cables and radio), data link (Ethernet and Wi-Fi between neighbouring devices), network (IP addresses and routing), transport (TCP and UDP), session, presentation and application (HTTP, DNS, SSH). Each layer relies only on the one below it, which is why a website works the same over Wi-Fi, fibre or a mobile network.

The internet actually runs on the simpler four-layer TCP/IP model, which merges the top three OSI layers into one application layer and the bottom two into a link layer. The OSI numbers survive as shorthand: a 'layer 2' switch moves Ethernet frames, a 'layer 4' load balancer routes by address and port, and a 'layer 7' firewall reads the requests themselves.

Also called: OSI reference model, seven-layer model, TCP/IP model, network layers

Open OSI model as a page

IP address

Concept
The number that identifies a device on a network so data knows where to go, much like a postal address for computers.

IPv4 addresses look like 203.0.113.7: four numbers from 0 to 255, about 4.3 billion addresses in total, which the world ran short of years ago. IPv6 addresses look like 2001:db8::1 and are 128 bits long, enough to give every device its own address many times over. Many networks now run both side by side.

A public address can be reached across the internet. Private ranges such as 192.168.x.x and 10.x.x.x are reused inside homes and offices, and the router shares one public address between them through NAT (network address translation). NAT is why a home server cannot be reached from outside without port forwarding, and why video calls need helpers such as STUN and TURN servers to connect.

Devices usually get their address automatically from the router through DHCP, and DNS turns names such as example.com into addresses. An address shows roughly where a device connects from, which is how websites guess a visitor's country, but it does not pinpoint a person.

Also called: IPv4, IPv6, public IP, private IP, NAT, DHCP

Open IP address as a pageOfficial site (opens in a new tab)

TCP

Protocol
The internet's reliable delivery protocol: it makes sure every piece of data arrives, in the right order, and resends anything that gets lost.

Before any data moves, TCP opens a connection with a three-way handshake (SYN, SYN-ACK, ACK). It then numbers every byte, waits for acknowledgements, resends whatever goes missing and slows down when the network is congested. The app on each end simply sees a clean, ordered stream of data.

Web pages over HTTP/1.1 and HTTP/2, email, SSH and database connections all run on TCP. The price of reliability is delay: a single lost packet holds up everything behind it until it is resent (head-of-line blocking). That is why video calls and online games use UDP instead, and why HTTP/3 moved to QUIC, which rebuilds reliability on top of UDP.

Also called: Transmission Control Protocol, TCP/IP, three-way handshake

Open TCP as a pageOfficial site (opens in a new tab)

UDP

Protocol
A lightweight way to send data with no connection and no delivery guarantee, which makes it fast enough for video calls, live streams and online games.

UDP sends each packet (a datagram) on its own: no handshake, no acknowledgements, no resending and no ordering. A lost packet is simply gone, and the app decides whether that matters. Its header is only 8 bytes, against at least 20 for TCP, and there is no connection to keep track of.

That suits real-time traffic, where a late packet is as useless as a lost one. Video calls, online games and live streams run over UDP, and so do most DNS lookups. QUIC, the base of HTTP/3, builds its own reliability on top of it. Some office networks block UDP, which is one reason WebRTC can fall back to TURN relays over TCP or TLS.

Also called: User Datagram Protocol, datagram

Open UDP as a pageOfficial site (opens in a new tab)

Ports

Concept
Numbers that pick out which program on a machine should receive incoming data: the IP address finds the building, the port finds the flat.

A port is a number from 0 to 65535 attached to every TCP or UDP connection. Common services have agreed defaults: 80 for HTTP, 443 for HTTPS, 22 for SSH, 53 for DNS, 587 for sending email and 5432 for PostgreSQL. A server listens on its port, and a firewall decides which ports can be reached from outside.

Numbers below 1024 are the well-known range, and on Linux opening one needs admin rights. Port forwarding on a router sends traffic that arrives on a public port to a device inside the network. Leaving admin ports such as 22 (SSH) or 3389 (Windows Remote Desktop) open to the whole internet invites a constant stream of automated login attempts.

Also called: port number, port forwarding, well-known ports

Open Ports as a pageOfficial site (opens in a new tab)

LAN, WAN and subnets

Concept
A LAN is the local network inside one home or office, a WAN links networks over long distances, and subnets split a network into smaller, separate blocks of addresses.

Devices on a LAN (local area network) reach each other directly through switches and Wi-Fi access points, and a router joins the LAN to other networks. The internet is a WAN (wide area network) on a global scale, and companies also build private WANs between offices with leased lines, SD-WAN services or site-to-site VPNs.

A subnet is a block of addresses written in CIDR notation: 192.168.1.0/24 fixes the first 24 bits, which leaves 256 addresses, 254 of them usable by devices. Subnets and VLANs (virtual LANs that share the same switches) keep groups of devices apart. Offices often give guests, printers and cameras their own VLANs, so a problem on one cannot spread to the rest of the network.

Also called: LAN, WAN, subnet, CIDR, VLAN, SD-WAN

Open LAN, WAN and subnets as a page

Latency, bandwidth and jitter

Concept
Three measures of how a connection feels: latency is the delay, bandwidth is how much data fits through at once, and jitter is how unevenly that delay varies.

Latency is usually measured as round-trip time in milliseconds, the 'ping'. Bandwidth is capacity, in megabits per second: a wider pipe speeds up downloads but does nothing for delay. Jitter is the variation in delay from one packet to the next, and packet loss is the share of packets that never arrive at all.

Web pages feel slow mostly because of latency rather than bandwidth. A new connection spends round trips on the TCP and TLS handshakes before any data moves, and a page may fetch dozens of files. That is why CDNs serve content from servers near the visitor, and why HTTP/2 and HTTP/3 reuse connections and cut handshake round trips. Video calls and online games feel jitter and packet loss most, so apps keep a small buffer that trades a little extra delay for smooth playback.

Also called: ping, round-trip time, packet loss, throughput, lag

Open Latency, bandwidth and jitter as a page

Getting around

Proxy and reverse proxy

Concept
A server that sits in the middle of a connection and passes traffic along: a forward proxy acts for the people browsing, a reverse proxy acts for the servers being visited.

A forward proxy sits in front of clients. Companies and schools use one to filter, log or cache web traffic, and websites see the proxy's address instead of each user's. Unlike a VPN, a proxy usually handles only web traffic or chosen apps, and it does not have to encrypt anything. Squid is a long-standing open-source example.

A reverse proxy sits in front of servers. Visitors connect to it, and it forwards each request to one of the app servers behind it, handling HTTPS certificates, caching, compression and load balancing on the way. Nginx, HAProxy, Caddy and Traefik are common self-hosted choices, while Cloudflare and other CDNs act as a reverse proxy for a whole site and filter attacks before they reach it.

Also called: forward proxy, reverse proxy, load balancer, Squid, HAProxy

Open Proxy and reverse proxy as a page

VPN

ServiceFree tier
An encrypted tunnel between a device and another network, so traffic crosses the public internet privately, as if the device were plugged in at the other end.

A VPN client wraps each packet in an encrypted envelope and sends it to a VPN server, which unwraps it and passes it on. Others on the same café Wi-Fi, and the internet provider, see only scrambled traffic heading to that server. Common protocols are WireGuard (small, fast and built into Linux), IPsec (built into most business routers and firewalls) and OpenVPN (older and flexible, over TCP or UDP).

VPNs come in a few shapes. Site-to-site VPNs join office networks over the internet. Remote-access VPNs let staff reach internal systems from home. Consumer VPN services route browsing through their own servers to hide it from the local network or to appear in another country. Mesh VPNs such as Tailscale (built on WireGuard) connect devices directly to each other where they can, so there is no central VPN server to run.

A VPN moves trust rather than removing it: the VPN provider can now see what the local network used to see. It does not make anyone anonymous to websites, which still recognise logins and cookies, and it adds delay, most of all when traffic detours through a distant server. Zero trust access tools, which check each app login separately, are a common alternative to one office-wide VPN.

Pros

  • Encrypts traffic on untrusted networks such as public Wi-Fi
  • Gives remote staff safe access to internal systems
  • Joins offices and cloud networks as if they were one network
  • WireGuard and OpenVPN are free and open source

Cons

  • Adds delay, and speed depends on the VPN server's load and distance
  • The VPN provider sees the traffic instead, so it has to be trusted
  • No anonymity from websites, which still see logins and cookies
  • One stolen VPN login can open up a whole internal network

Pick it when

  • Staff need to reach internal servers or tools from outside the office
  • Linking two offices, or an office and a cloud network
  • Working on public Wi-Fi you do not trust
  • Reaching home or lab machines from anywhere (a mesh VPN fits well)

Skip it when

  • The goal is anonymity, which a VPN does not provide
  • Everything already runs over HTTPS and nothing internal needs reaching
  • Low delay matters, as in games or video calls, and the nearest VPN server is far away

What it costs · Free tier

WireGuard and OpenVPN are free to run yourself. Tailscale is free for personal use (up to 6 users) and about $8 per user a month for businesses. Proton VPN has a free plan; Mullvad costs a flat €5 a month.

VPN pricing (opens in a new tab)Approximate, checked September 2026.

Also called: virtual private network, WireGuard, IPsec, OpenVPN, Tailscale, mesh VPN

Open VPN as a pageOfficial site (opens in a new tab)

Firewall

ToolFree
A gatekeeper that checks network traffic against a set of rules and blocks anything not allowed, such as strangers trying to reach a database or an admin login.

Rules are written in terms of addresses, ports and protocols: allow 443 from anywhere, allow 22 only from the office, block everything else. Most modern firewalls are stateful, which means they remember outgoing connections and let the replies back in automatically. Home routers do this by default, which is one reason devices at home cannot be reached directly from the internet.

Firewalls come in several forms: software on each machine (Windows Defender Firewall, the macOS firewall, ufw and nftables on Linux), cloud firewall rules and security groups on AWS, Google Cloud and Azure, and hardware appliances at the edge of an office network. Next-generation firewalls also recognise the apps inside the traffic, and a web application firewall (WAF) specialises in attacks on websites.

A sound starting point is to deny everything inbound and open only what each service needs: 80 and 443 for a website, and SSH only from known addresses or through a VPN. Databases should never be open to the whole internet; managed database services usually offer an IP allow list as an extra layer on top of passwords.

What it costs · Free

Firewalls built into Windows, macOS and Linux are free. Hardware and managed firewalls are paid, often as a device plus a yearly security subscription.

Approximate, checked September 2026.

Also called: packet filter, ufw, iptables, nftables, security group, NGFW

Open Firewall as a page

SSH

ProtocolOpen source
A secure way to log in to another computer over the network, usually a server, and type commands as if you were sitting in front of it.

SSH encrypts everything between your terminal and the remote machine, which listens on port 22 by default. Passwords work, but key pairs are the norm: the private key stays on your computer and the public key sits on the server, so no secret crosses the network. The first connection records the server's fingerprint, so a machine that later pretends to be that server triggers a warning.

Beyond a remote shell, SSH copies files (scp and SFTP), carries Git pushes to services such as GitHub, and forwards ports, so a database that only listens locally on a server can be reached through the encrypted tunnel. OpenSSH is the standard implementation and comes with Linux, macOS and Windows. Servers open to the internet should switch off password logins and accept keys only.

What it costs · Open source

Free. OpenSSH is open source and comes with Linux, macOS and Windows.

Approximate, checked September 2026.

Also called: Secure Shell, OpenSSH, SSH keys, SFTP, scp

Open SSH as a pageOfficial site (opens in a new tab)

Side by side

Differences

How the options in this area compare on the questions that usually decide the choice.

The internet's two transport protocols. TCP guarantees that data arrives complete and in order; UDP just sends packets and moves on, which is faster and better for anything live.

CompareTCPUDP
What it isA reliable, ordered stream of dataSeparate packets, each sent on its own
ConnectionHandshake first, then a connectionNone; packets simply go
Lost dataDetected and resent automaticallyGone, unless the app deals with it
OrderAlways delivered in orderCan arrive out of order
DelayExtra delay from handshakes and resendsMinimal
Header sizeAt least 20 bytes8 bytes
Used byWeb pages, email, SSH, file transfersVideo calls, live streams, games, DNS
Watch out forOne lost packet stalls everything behind itNo congestion control; some firewalls block it

How to choose

  • Pick TCP when every byte must arrive, as with web pages, files, payments and database connections.
  • Pick UDP for live calls, video and games, where a late packet is worthless and low delay matters most.
  • Newer protocols such as QUIC (behind HTTP/3) build their own reliability on top of UDP to get low delay and dependable delivery together.

Three tools that sit between a device and the network and are often confused. A proxy relays traffic, a VPN tunnels it with encryption, and a firewall decides what may pass at all.

CompareProxyVPNFirewall
What it isA go-between that forwards requestsAn encrypted tunnel to another networkA rule-based gatekeeper
Main jobFilter, cache or balance trafficPrivate access and privacyBlock unwanted connections
EncryptionNot required; HTTPS stays as it wasAlways, for everything in the tunnelNone; it only allows or blocks
What it coversUsually web traffic or chosen appsAll traffic from a device or siteEverything crossing a machine or network edge
Hides addressesForward proxies hide clients, reverse proxies hide serversHides your address from the sites you visitNo
Where it runsA server between clients and serversA client app or router, plus a VPN serverOn the machine, the router or the cloud edge
ExamplesSquid, Nginx, CloudflareWireGuard, IPsec, Tailscaleufw, Windows Defender Firewall, security groups
Watch out forThe operator sees any unencrypted trafficThe provider sees what the local network used toOne wrong rule can open or cut off everything

How to choose

  • Pick a reverse proxy to put HTTPS, caching and load balancing in front of servers, and a forward proxy to filter a network's browsing.
  • Pick a VPN to reach private systems from outside or to protect traffic on networks you do not trust.
  • Every server and network needs a firewall; proxies and VPNs are added on top when their jobs are needed.

Crafted in the dark. Shipped to the world.

Tell us what you are building. You get a private project space with a proposal and a line-by-line quote within a day.