Skip to content

Networking Fundamentals

Almost every attack travels over the network, so understanding how machines communicate isn’t optional: it’s the substrate of recon, scanning, pivoting, and exfiltration. You don’t need to be a network engineer, but you do need to master the layered model, how packets are addressed and routed, and which protocols you’ll meet on each port.

Two models, same idea (encapsulation: each layer wraps the one above):

  • OSI (7 layers) — theoretical: Physical, Data Link, Network, Transport, Session, Presentation, Application.
  • TCP/IP (4 layers) — practical: Link, Internet (IP), Transport (TCP/UDP), Application (HTTP, DNS…).

For a pentester, the ones that matter daily: Network (IP) = addressing and routing; Transport (TCP/UDP) = ports and reliability; Application = the service’s protocol.

IPv4: 192.168.1.10 /24 -> network 192.168.1.0, hosts .1-.254, broadcast .255
CIDR: /24 = 256 IPs, /16 = 65536, /30 = 4 (point-to-point links)
Private (RFC1918): 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16

Subnetting tells you what range to scan: a /24 is 254 hosts; a /16, 65k. IPv6 (fe80::/10 link-local) increasingly present and often unwatched (see mitm6 in AD).

  • TCP — connection-oriented, reliable. Handshake: SYN → SYN-ACK → ACK. The basis of port scanning (a SYN-ACK = open port).
  • UDP — connectionless, no guarantees; faster and harder to scan (no response ≠ closed). DNS, SNMP, DHCP, VPN.
Useful TCP states: LISTEN (service waiting), ESTABLISHED (live connection)
Key flags: SYN, ACK, FIN, RST (reset = closed), PSH, URG
21 FTP 22 SSH 23 Telnet 25 SMTP 53 DNS 80 HTTP
110 POP3 111 RPC 135 MSRPC 139/445 SMB 143 IMAP 161 SNMP
389 LDAP 443 HTTPS 636 LDAPS 1433 MSSQL 3306 MySQL 3389 RDP
5432 PostgreSQL 5985/5986 WinRM 5900 VNC 8080 HTTP-alt

Recognizing a port is recognizing a surface: 445 = SMB (Windows/AD), 389 = LDAP (AD), 3389 = RDP, 5985 = WinRM.

  • Gateway/routing: how packets leave your subnet toward others (ip route, route print).
  • NAT: translates private IPs to public; that’s why your internal /24 isn’t visible from outside (relevant for pivoting).
  • DNS: translates names to IPs; a key recon piece (see DNS Fundamentals). ARP: resolves IP↔MAC on the LAN (basis of MITM).
ip a / ifconfig # interfaces and addresses
ip route / route print # routing table
ping / traceroute # connectivity and hops
nslookup / dig # DNS queries
netstat -ano / ss -tulpn # local ports and connections
nmap # port/service scanning (see recon)
tcpdump / wireshark # capture and analyze traffic

Without this model you don’t understand what nmap does (SYN scan), why a firewall blocks, how you pivot from one subnet to another, or why you capture hashes at layer 2 (ARP/LLMNR). The network is the terrain; this is the map.

  • I understand encapsulation and the layers that matter (IP, TCP/UDP, Application)
  • I can read CIDR notation and compute how many hosts a range has
  • I can explain the TCP handshake and what each flag/state means
  • I distinguish TCP from UDP and why UDP is harder to scan
  • I recognize common ports/services from memory
  • I understand routing, NAT, and ARP, and their relevance to pivoting/MITM
  • I can use ip/ss/dig/tcpdump to inspect the network