Canonical terms for the networking-backend course. In this workspace, a request always has four stages — DNS, TCP, TLS, HTTP — and incidents are named by the stage (and later, the failure signature) they belong to.
The four stages
- DNS resolution
- Turning a hostname into an IP address via a resolver. Stage ① — nothing else can start until it succeeds. Avoid: "lookup issues", "name stuff".
- TCP connect
- Opening a connection to an IP and port; healthy sign is curl's "Connected to … port …". Stage ②. Avoid: "socket stuff".
- TLS handshake
- Negotiating encryption and verifying the server's certificate before any HTTP flows. Stage ③. Avoid: "SSL" (legacy protocol name; the handshake is TLS).
- HTTP exchange
- The request/response conversation itself — any status code means the exchange happened. Stage ④.
Triage
- Triage ladder
- The fixed question order for "A can't reach B": name resolves? → port reachable? → TLS completes? → app answers? → path sane? Climb in order; a passing rung rules out everything below it.
- TTFB (time to first byte)
- The gap between TLS completing and the first response byte — approximately
starttransfer − appconnectincurl -w; mostly server think-time.
Connections
- 4-tuple
- The four values that uniquely identify a TCP connection:
(local IP, local port, peer IP, peer port). One server port serves many clients because each has a distinct 4-tuple. - Listening socket
- A process parked on a port waiting for connections; shows as
LISTENinss. Avoid: "open port" (ambiguous — open in a firewall, or actually accepting?). - Ephemeral port
- The client's temporary source port, taken from a high range for one connection's lifetime.
- Handshake
SYN → SYN-ACK → ACK, the three packets that open a TCP connection; both sides then readESTAB.- FIN
- The polite, negotiated connection close.
- RST
- The abrupt close/refusal — a live host saying "no" or "over, now". Avoid: calling every failure a "reset"; only an
RSTis. - TIME_WAIT
- Brief wait by the side that closed first; normal. Forensics: Unit 9.
- CLOSE_WAIT
- Peer closed, local app hasn't; piles of these signal an app bug. Forensics: Unit 9.
Failure signatures
The course spine — the five things "A can't reach B" reduces to (full sheet: Failure Alphabet).
- refused
RSTfrom a closed port (curl exit7). Host up, packet arrived, nothing listening. Rules out path/firewall. →ss -tlnp.- timeout
- Silent drop, no reply (curl exit
28). Firewall, routing, or dead host. → host-up and path checks. - reset
RSTmid-stream (curl exit56). A live connection torn down. → logs/capture (Unit 9).- hang
- Connected, but no reply byte returns. App stuck or reply lost. →
curl -wTTFB. - resolves-wrong
- Name maps to the wrong IP or none (curl exit
6). A DNS problem. →dig(Unit 3).
DNS
The full cheat sheet is DNS in Anger.
- Resolver
- The server that answers your DNS queries. Named on the
SERVER:line ofdigoutput — "DNS is fine" is meaningless until you say which resolver. Avoid: "the DNS", singular, as if there were one. - Stub resolver
- The local client (libc or
systemd-resolved) that reads/etc/resolv.confand forwards queries; often127.0.0.53. - Recursive resolver
- The server that walks root → TLD → authoritative and caches the result (your
8.8.8.8/ VPC resolver). - Authoritative server
- The server that owns the zone and holds the original answer; every cache is quoting it. Listed by the
NSrecord. - A / AAAA record
- Name → IPv4 (
A) / IPv6 (AAAA) address. The end of resolution. - CNAME
- An alias — "this name is that one; look it up instead". Follow the chain to an
A/AAAA. - NS record
- The authoritative servers for a zone.
- TTL (DNS)
- Seconds an answer may be cached — at the resolver, the stub, and inside the app process. Avoid: confusing with
curl -wtiming. - NXDOMAIN
- Authoritative "no such name" — an answer; rules out resolver/network. DNS's
refused. - SERVFAIL
- Resolver reached but couldn't complete the lookup (broken upstream, DNSSEC). Rules out "name is simply absent".
- NODATA
status: NOERRORwithANSWER: 0— the name exists but has no record of the requested type. Not "resolved".- Search domain
- A suffix from
resolv.confsilently appended to short names; the reason a bare name works in one environment andNXDOMAINs in another. - Split-horizon
- The same name deliberately resolving to different IPs inside vs outside a network.