Skip to content

Lesson 2: Networking 101 & Subnet Math

🧠 The Concept (Explain Like I'm 5)

Imagine the internet is a global postal network: * IP Address (IPv4): The unique street address of your building (e.g., 192.168.1.50 or 54.239.28.85). * Packets: Envelopes containing data slices with a source address, destination address, and payload. * Port Number: The apartment or room number in the building (e.g., Port 80 = Lobby Web Server, Port 22 = Management Backdoor). * Router: The neighborhood post office directing packets down the right street. * DNS (Domain Name System): The phonebook that translates human names (google.com) into IP addresses (142.250.190.46).


🏢 The Enterprise Context (Why Platform Architects Care)

In Cloud and Kubernetes environments: 1. IP Exhaustion: If you pick a CIDR block that is too small for an EKS cluster (like /24), each Pod consumes an AWS VPC IP address and your cluster runs out of IPs, crashing all deployments. 2. Overlapping CIDRs: If two business units both pick 10.0.0.0/16, you cannot peer their VPCs or connect them over a Transit Gateway without complex NAT workarounds. 3. Security Boundaries: Public subnets talk to the internet; private subnets do not. Routing misconfigurations can expose your production databases to the public web.


🗺️ Visual Architecture: The OSI Model vs TCP/IP

In modern cloud platforms, networking is split across layers. Platform engineers primarily operate between Layer 3 (IP), Layer 4 (TCP/UDP), and Layer 7 (HTTP/Application):

flowchart LR
    subgraph OSI ["OSI 7-Layer Reference"]
        L7["L7: Application (HTTP, DNS)"]
        L4["L4: Transport (TCP, UDP)"]
        L3["L3: Network (IP, Routing)"]
        L2["L2: Data Link (MAC, ARP)"]
    end

    subgraph PlatformRole ["Platform Architect Tools"]
        T7["Ingress Controller, Istio, API Gateway"]
        T4["Network Load Balancers, Security Groups"]
        T3["VPCs, Subnets, Route Tables, Transit Gateway"]
        T2["VPC CNI, AWS Hyperplane Fabric"]
    end

    L7 --- T7
    L4 --- T4
    L3 --- T3
    L2 --- T2

📦 Packet Travel: The 3-Way Handshake

When your browser or a microservice initiates a secure connection to another service:

sequenceDiagram
    autonumber
    actor Client as 💻 Client (Pod / Laptop)
    participant DNS as 🌐 DNS Server (CoreDNS / Route53)
    participant Server as 🖥️ Target Server (Microservice)

    Client->>DNS: "What is api.company.internal IP?"
    DNS-->>Client: "10.0.4.25"
    Note over Client,Server: TCP 3-Way Handshake (L4)
    Client->>Server: SYN (Synchronize)
    Server-->>Client: SYN-ACK (Acknowledge)
    Client->>Server: ACK (Connected!)
    Note over Client,Server: Application Payload (L7)
    Client->>Server: HTTP GET /v1/orders
    Server-->>Client: 200 OK + JSON Payload

🧮 Subnetting & CIDR Math Demystified

An IPv4 address consists of 32 binary bits divided into 4 octets: 192 . 168 . 1 . 0 = [8 bits] . [8 bits] . [8 bits] . [8 bits]

The / number (prefix) tells you how many bits are locked for the network. The remaining bits belong to your hosts (machines/pods).

$$ ext{Total IPs} = 2^{(32 - ext{Prefix})}$$

Prefix   Total IPs   Usable AWS IPs*   Common Enterprise Usage
------------------------------------------------------------------------
/16      65,536      65,531            Standard Enterprise VPC (e.g. 10.0.0.0/16)
/20      4,096       4,091             Large EKS/Kubernetes Workload Subnet
/24      256         251               Standard Microservice Subnet (e.g. 10.0.1.0/24)
/28      16          11                Transit Gateway attachment subnet, Bastion host
/32      1           1                 Single host / Specific IP whitelist rule

AWS Reserves 5 IP Addresses per Subnet

In every AWS subnet, AWS reserves the first 4 IPs and the last IP: * 10.0.0.0: Network address * 10.0.0.1: AWS VPC Router * 10.0.0.2: AWS DNS Resolver (AmazonProvidedDNS) * 10.0.0.3: AWS Reserved for future use * 10.0.0.255: Network broadcast address (AWS does not support broadcast, but reserves it)


🛠️ Network Engineering Cheatsheet

# 1. Test basic connectivity (ICMP ping - L3)
ping -c 3 8.8.8.8

# 2. Check DNS resolution (L7)
nslookup internal.api.local
dig +short google.com

# 3. Test TCP port accessibility without sending a full payload (L4)
nc -zvw3 10.0.1.15 443

# 4. Inspect full HTTP request/response headers with timings (L7)
curl -Iv https://example.com

# 5. Trace packet hops across network routers (L3)
traceroute -n 10.0.2.50

📝 Knowledge Check

Question 1

Your team wants to deploy an AWS EKS cluster that will eventually scale to 500 pods. If you place the pods in a single /24 subnet using AWS VPC CNI, what happens and why?

Question 2

A developer complains that their service in a private subnet cannot reach api.stripe.com. You can ping internal IPs, but curl to Stripe hangs. What is missing in the VPC routing table?