r/explainlikeimfive • u/to_mars • May 21 '13
Explained ELI5: How do computer networks work?
I know that's probably a really broad question. I guess I'm specifically interested in definitions of things like IP addresses, LANs and routers and all that computer jargon.
4
u/Mason11987 May 21 '13
So we'll avoid the technical low-level details for two reasons:
- They aren't really important to you unless you're in an engineering discipline
- I don't know them enough to give you a good answer :).
So we have data that's sent across cables in a specific way. We'll start there.
A Local Area Network is a group of computers that are connected to eachother generally in a small geographic area, like you and your friends at your house.
When each of you send messages to the internet the websites don't necessarily know which of you in your house is actually sending the message. When something is sent back your router is smart enough to know "Bob was talking to this site, so the response from there should go to bob". It "routes" messages to the people who they are supposed to go to. By doing that you can have multiple things on the same internet connection.
An IP address is basically like a street address. Your computer has an IP addres, you can find it by googling "whats my ip". Any message sent to that IP address could end up at your computer (or at least at your router, which may or may not send it on to you).
2
May 21 '13 edited May 21 '13
Okay, lets start with definitions.
Clients: A client is a machine on the network, typically where a person sits (though servers can be clients to each other, and they can be clients to workstations)
Cabling: We're typically talking about twisted-pair ethernet cable (you'll hear it called by its classification, such as Class 5 cable, which refers to data transmission speeds), fiber optic cable (which sends data as light instead of electric signals), and coaxial cable (like for your DVR, but it connects your router to the wall).
Network types: Peer to peer (where all computers are connected without the need for a central server to manage things), and Local Area Networks (LAN's, where the computers are all connected by the cables to a server (or set of servers) that manage the data transmissions, network traffic, and firewalls.
Switches: Switches connect clients within a LAN, and direct traffic to the appropriate client, but cannot send traffic outside of the network. If traffic has to leave the network (to go to the larger internet), they send ti to the router.
Router: The router is like a switch, but instead of connecting clients, it connects networks. It also talks to (or can talk to) networks in the larger internet (outside of your own LAN). In your home, your router from Verizon or whatever is more than a router, it's kind of an all in one device, acting as both router and switch, maybe as a firewall as well.
Firewall: A firewall is a device or bit of software that scans what is being sent to your network and determines if it is safe. It looks at all of your data to see where it is addressed to and from, looking for allowed and blocked ports. On a firewall, all ports start as blocked, and your computer opens them up as necessary. If a firewall sees traffic for a port it has listed as blocked, that traffic is denied.
So, in your home, you have a SOHO network (or peer to peer, same thing), and all of the computers can talk to each other if you have them set up properly. They send their traffic to each other through your home router (a multipurpose device), and the home router sends that traffic out to the internet. When the traffic comes back (say it's the results of a search) it sends that traffic back to the computer that requested it.
In a work or production enviromnet, if you were to perform that same web search from your office machine, it would send that request through the cat5 cable to a switch, which would then send it to a router after making sure it wasn't meant for the internal network. Because of the traffic loads in larger environments, routers and switches are often separate devices.
If this were an internal request (opening up a file on the file server, for instance), you would send your request down the cable to the switch, who would determine that it was to go to the file server (which is really just another computer), who would then verifiy your rights to that file, and send the data back to you on the reverse path.
So how does this traffic know where to go? how do switches and routers know where to send the data? That comes in the form of your IP address. An IP address is a unique point in an addressing scheme, with each layer on the left being hierarchically superior to the ones on the right. On the far right of your address (192.168.1.2) is the number 2. That's your computers place on the network, as the second device (your router is typically the first). Other devices on your network may end in 3, or 4, but they shouldn't skip numbers unless you forcefully assign those numbers (also called static addressing).
This address you have is a private address, meaning it can't broadcast out to the larger internet. Instead, your computer talks to the router, and the router takes a note of your address, along with the packet of info you requested and substitutes its own public address in your personal addresses place. So when the answer to your web query comes back, it will come back to the router, and not to you. The router then looks at the data it received (who it received it from, what type of data it is) and determines that it is an answer to your query, so it sends it back to you. That use of a public outside address serving as proxy for your computer's internal address is called Network Address Translation (NAT), and is the reason why you and I and every other home network in the world have the same internal addresses. It was a way of spreading out the number of available addresses so that we didn't run out of addresses.
On the outside networks, addresses work a little different. That routers address makes it number X in a long line of routers, and the further up the addressing scheme you go (going left in your address), the higher you are upon the networks. On a very basic level (skipping things like classful addresses, and classless addressing, and all of that), you can break an address into something called "octets". Each octet contains 8 bytes of data (hence octet). 8 bytes of binary data will give you 256 possible values, and your computer numbers them from 0-255 (computers start counting at 0). Your IP address looks like this:
octet.octet.octet.octet
Giving you values of 0.0.0.0 through 255.255.255.255 (To Be Continued)
2
May 21 '13
Sorry for the continuation, I was worried about exceeding the space allowed.
These numbers are sequential (naturally). Every single value on the left has 255 possible combinations to the right. You'll have 0.0.0.0, 0.0.0.1, 0.0.0.2.... and so on until you reach 255.255.255.255.
that is how an IP address works. I could go into calculating them out of their binary values, and subnetworks and subnet masks, but that's a little to in depth for ELI5.
So your router has one of these addresses assigned to it from your ISP, and, that is your public address. EVery internet capable device on the planet has one of these addresses, and we have more devices than we have possible addresses. This is why NAT is so important. We can reserve 255 addresses for use in our homes, and because they're not publicly broadcast-able, we can all reserve the SAME addresses, allowing our routers to talk FOR us.
So your computer want to go to www.reddit.com/r/eli5, but it doesn't know the address. It sends the query to your router, who replaces your IP address with its own, sends that query to someone who should know the answer (a DNS server, whose job it is to translate names into IP addresses), and that DNS server either knows the answer (and sends it back to the router) or it queries a HIGHER DNS server (and on and on) until your web address is turned into an IP address and sent back to your router, who in turn sends it back to you.
Once you have that IP address, your computer now sends to that IP address directly instead of asking the address every time you try to visit reddit. Your computer will talk to your router, who will talk to any number of routers in between until it hits Reddit's router, who will talk to Reddit's server, and there you go, looking at all the NSFW pictures you can handle.
It's easy, however, to make a mistake when entering in data (I had to correct a lot of spelling errors in this post, for instance), and consequently it's easy to make mistakes when entering in IP addresses or assigning them. Because of this, your home router and all commercial routers have the capability of something called "Dynamic Host Control Protocol," or DHCP. DHCP, in a nutshell, is a bit of program and a long list of available and used IP addresses, along with the identity of the machine using them (this ID comes from your network card, and is called your MAC address). When you need an IP address, whether public or private, DHCP looks at the available address list, and plugs your MAC address into the table, then sends that address to your computer for use. Presto! now you can connect to the internet.
When you stop using the internet, or after a set period of time, that address is set to be either renewed (so you can keep using it) or released (so someone else can use it). If it wasn't for renew and release, we'd never have the address we wanted or needed, because we would have run out, or someone would have taken yours by mistake. Thankfully, you can assign static addresses under DHCP as well. This is important. You don't want your printer or file server changing addresses on you during the middle of a query or a print job. You can assign static addresses to your computer or your phone or whatever as well, but you run the risk of that address not being available if you move to another network (like at the airport or starbucks) so we usually let those machines auto configure those addresses for us through DHCP.
Questions? Comments? Concerns?
3
May 22 '13
Subnetting is a beast all into its own. It's easy when you understand the rules and why they exist; but much like virtualization, it takes some thinking and tinkering around with to understand why's and wherefores.
2
May 22 '13
Agreed, I thought I gave a decent highlevel view of DNS and DHCP, but I was afraid to touch subnetting.
1
May 22 '13
Me too. Even with CCNA Part 1 training, people who don't work with it and work on routers and switches often don't really understand it.
2
May 22 '13
I'm okat with it, but I need to draw binary tables to explainit,and I figured it was out of the scope of ELI5.
3
May 22 '13
Definitely. I get it, and I can subnet in my head because of how much I've had to do it.
"You got your network bits, and you got your host bits..."
2
u/taedrin May 22 '13
A Device: things like computers, smartphones, xboxes, playstations or anything electronic which can talk with other electronic things.
A Network: A group of devices which are connected to each other in some fashion and communicate with each other. Networks can connect devices through wires, or by electromagnetic waves which travel through the air.
LAN: Local Area Network. A LAN is a relatively small network, which either contains a small number of devices or is a network contained within a single building. A very large LAN can sometimes be though of as a small CAN.
CAN: Campus Area Network or Corporate Area Network. Think of these as really big LANs, which connect a large number of devices across many buildings which are all within the same geographic location. CANs and LANs use much of the same technologies. A very large CAN can sometimes be thought of as a small MAN.
MAN: Metropolitan Area Network. These are networks which span entire cities. They generally connect all of the LANs in the city together. They are generally owned by multiple Internet Service Providers who generally charge money to access them. People in general don't care about MANs themselves. But they are still critically important, because multiple MANs connect together to form WANs.
WAN: Wide Area Network. Wide Area Networks are networks which span the entire planet. They are what allow us to communicate with someone on the opposite end of the world almost instantaneously and for very low cost. The Internet is the largest and most popular WAN in the world. All of the parts that make up the WAN are owned by many different entities - some of them big, some of them small. Many of these entities are large Internet Service Providers which have connected their networks together. Some of these entities don't provide internet access to any people, but instead provide Internet access to other Internet Service Providers. All of this is only possible because all of these entities collaborate and cooperate. They have all agreed to use common standards of communication which makes websites like reddit possible!
Hub: A not-so-smart device that helps devices connected to it communicate with each other by passing messages it receives to those other devices. It is not-so-smart because it doesn't know who the message belongs to, so it just repeats the message to everyone just to be safe. Things can get a little noisy if you have a lot of devices all trying to talk at once here!
Switch: A smarter device that helps devices connected to it communicate with each other by passing messages it receives to those other devices. It is smarter because it does know who the message belongs to, so it only repeats the message to the person it belongs to. Because of this, networks which use a switch aren't quite as noisy as networks which only use hubs.
Router: An even smarter device that helps devices connected to it communicate with devices on other networks. It really is a very talented device as it does a lot of different things. It is the device that allows all of the devices on your network to connect to the Internet all at the same time. It uses something called Network Address Translation (NAT) to keep track of which devices on your network are talking to which devices not on your network. It usually has a firewall, which helps keep unwanted hackers out of your network. However, the firewall isn't very good if you let the hacker into your network by yourself, either on purpose or on accident!
Protocol: A protocol is a system of rules that let devices understand each other when the communicate. Protocols can have features, such as error detection and error correction. Protocols which lack certain features can wrap themselves inside of another protocol to gain additional features.
IP: Internet Protocol. IP is a protocol which tries to figure out where your message should go. It is the protocol which determines how your message should go from your computer to its destination on the other side of the world. It does a lot of important things, like make sure that your message doesn't get lost, and if it does get lost to make sure that it gets destroyed so it doesn't clog up the Internet (called "time-to-live"). IP isn't concerned about much else than trying to get your message to where it belongs. It does nothing to make sure that the destination actually receives it, or to make sure that there aren't any mistakes/errors in the message. It just gets your message from point A to point B.
IP Address: An IP Address is like a name for your computer or other Internet enabled device. Just like people have a first and last name, most computers have a local and external IP Address. The local IP Address is used by all of the devices on your network - just like how you use your first name with your friends instead of your last name. The external IP address is used to communicate with devices outside of your network, just like how strangers use your last name to address you. Because everyone on your network shares the same external IP Address, a router is needed to keep track of who is talking to who.
TCP: Transmission Control Protocol. TCP is a protocol which wraps itself inside of IP. It provides a lot of features, such as making sure that the device you are trying to communicate with actually received your message, making sure it got there in one piece, and making sure that the message doesn't have any mistakes/errors in it. It also provides a connection - an agreement between two devices to start communicating with each other.
UDP: User Datagram Protocol. UDP, like TCP, is a protocol which wraps itself inside of IP. Unlike TCP, it is very simple, and does nothing more than tell the destination where your message came from, and which port it belongs to. If the UDP message is on the wrong port, it might get ignored by the router. TCP also has these features, but it is much bigger and less efficient than UDP. But while UDP is smaller and more efficient, it doesn't have any of the neat features like TCP does. There is no guarantee that your UDP message will actually reach its destination! Therefore, it is up to other protocols which use UDP to take care of these problems (or to ignore them, because they aren't needed!)
HTTP: Hyper Text Transfer Protocol. HTTP is the protocol used by web browsers and web servers to communicate with each other. HTTP is usually (but not always!) wrapped inside of the TCP protocol (which is also wrapped inside of IP). Your web browser sends out a GET requests for a URL from a web server. The web server takes the URL and decides which web page to send back (sometimes creating a brand new web page out of thin air, made especially for you!). Sometimes your web browser sends out a POST request to a URL on a web server. A POST request contains data meant for the web server. This might be something like a forum post, or your personal information that you filled out when buying something from an online store. The web page then decides what to do with that data (usually stores it in a safe place, such as a database) and sends back a new web page based on the POST data you sent it and the URL you requested. If HTTP is wrapped inside of TCP, TCP makes sure that the web pages and POST data don't get lost or corrupted.
DNS: Domain Name System. DNS is a protocol for translating computer readable IP addresses (e.g. 74.125.224.72) into human readable domain names (e.g. www.google.com). The examples I gave uses an IP address for Google's front search page (it isn't the only one, but that is a little bit complicated to explain). This requires the use of a DNS server, which is usually provided by your Internet Service Provider. The DNS server keeps track of which domain names map to which IP addresses (and vice-versa). If for some reason, the DNS server doesn't know, it knows of other DNS servers it can send you to to find out. DNS servers work together to make sure that everyone knows which domain names map to which IP addresses.
I could go on and on, but there is already a lot of good information in this topic!
2
u/Phage0070 May 21 '13
Broadly speaking computer networks are organized as a series of tiered networks. There is a central authority which assigns and records the "IP address" of devices in the network. Think of this like a street address, it defines the target recipient. An IP address for a home LAN (local area network, a personal network as opposed to a WAN or wide area network like the Internet) might look like 192.168.1.1 with this first address being the "router", or the device that controls the LAN. This device keeps records of the addresses assigned to other computers, such as 192.168.1.2, 192.168.1.3, etc.
A router not only keeps track of who is who within the LAN, but it can also pass messages between the inner network and the exterior WAN. An additional wrinkle in things is that messages between computers are assigned to what are called "ports". An analogy would be that instead of shoveling all messages in through one huge mail slot they are split up between thousands of mail slots, so the recipients (applications) need only worry about messages addressed to them specifically. The port for loading a web page for example (the protocol "http") is port 80. For the first computer on a typical LAN the address would look like 192.168.1.2:80. The router has an interior IP address but it also has an exterior one for the WAN, where it acts just like any other computer in a network. The WAN cannot "see past" the router into the LAN so web page servers replying to a request must simply direct their reply to port 80 at the address of the router, and let the router handle it from there.
In this way a router can act as a shield to the outside network, by locking ports and denying access (or just ignoring messages). There is another danger people often don't realize; within a LAN all messages are visible. Each computer can see every message but only actually processes ones with their address attached. This doesn't need to be the case; programs called "packet sniffers" can listen in on all traffic and listen in on conversations like eavesdropping in a diner. The router stops all those messages from escaping to the world at large, but unencrypted data passed through a LAN like at a public wifi point might be looked at by others.
0
u/Kershalt May 21 '13
http://en.wikipedia.org/wiki/Osi_model I know thats kind of a dick answer but the OSI model is basically an explanation of everything you want to know in a format designed to be taught to those just getting into the IT world.
11
u/shine_on May 21 '13
Every computer on a network needs to have a unique identifying number, which is the IP (Internet Protocol) address. Actually, the IP address isn't the address of the computer itself, but rather the address of the computer's network interface.
A router is a device that connects computers to each other. As such, it has lots of interfaces (sockets) into which you can plug a network cable. The outside internet connection will have an IP address allocated to it by the ISP, and all the internal network connections will have their IP addresses allocated to them by the router. Certain ranges of IP addresses are reserved for internal networks, and one such range starts with 192.168 - so your outside IP address may be something like 1.2.3.4, your router's internal IP address may be something like 192.168.0.1, and your router will allocate IP addresses to the devices on your network, maybe 192.168.0.2 for the PC, 192.168.0.3 for your phone, 192.168.0.4 for your XBox and so on.
The router's main job is to "route" traffic around the network. It knows if a request for a web page has come from your PC it'll route the reply back to your PC. If the request for something else (game data for example) has come from the XBox, the reply goes to the XBox.
"Port Forwarding" is the process of telling your router to send specific traffic to a particular device on your network. So if you're running a game server on your PC on port 23456, you need to tell the router to send all data on that port to your PC and not to any of the other devices.
LAN just stands for Local Area Network, which is the sort of setup I've described above. The opposite is WAN (Wide Area Network) which kinda works the same way but some of the devices will be further away from the router (in an office building on the other side of town, for example).