How the Internet Works
A structured guide to how the Internet connects independent networks, identifies destinations, moves packets, and remains resilient when conditions change.
The as a Network of Networks
The is best understood as a network of networks rather than as one centrally owned system. Independent organizations operate local networks, access networks, ISP networks, backbone links, data centers, and interconnection facilities. Shared protocols allow these networks to communicate even when they use different equipment, physical media, and internal designs.
A useful progression is:
End devices such as phones, computers, servers, and sensors create or receive data.
Local networks connect nearby devices.
Access networks connect a home, organization, or subscriber to an ISP.
ISP and backbone networks carry traffic over regional, national, and long-distance paths.
Interconnection points allow independent networks to exchange traffic directly or through transit providers.
The provides the common -layer system for addressing and forwarding packets. No single organization needs to operate every link or know every detail of every network. Coordination comes from shared protocols, exchanged reachability information, and agreements among network operators.
Takeaway: The combines independent ownership with common technical rules.
Local Networks and the First Hop
A connects devices in a limited physical or organizational area, such as a home, classroom, office, or data center. Ethernet and Wi-Fi are common LAN technologies.
A home LAN may include:
End devices such as laptops and phones.
A wireless access point that provides Wi-Fi connectivity.
An Ethernet switch that forwards frames among wired devices.
A router that connects the LAN to other networks.
A combined modem/router supplied by an ISP.
Devices use link-layer identifiers such as MAC addresses to deliver frames across a local link. IP addresses identify interfaces at the layer. If a destination is outside the local subnet, the sending device usually sends the frame to its , normally the local router.
Private IPv4 address ranges, including 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16, are intended for private networks and are not globally routable on the public IPv4 . Before an IP packet can be placed in an Ethernet or Wi-Fi frame, the sender must determine the next device's link-layer address. IPv4 commonly uses ARP for this purpose, while IPv6 uses Neighbor Discovery mechanisms.
Takeaway: Local delivery uses link-layer addresses, while communication beyond the local network depends on IP addressing and a gateway.
Access Networks, ISPs, and Autonomous Systems
An access network provides the path from a user's local network or device to an ISP. The access connection may use fiber-to-the-home, cable broadband, DSL, fixed wireless, cellular service, satellite links, or an enterprise or campus connection.
The ISP generally provides connectivity, a route toward the wider , and one or more IP addresses. It may also provide recursive DNS resolution. An ISP is not merely a single connection: it is a network of routers and links that carries customer traffic and exchanges traffic with other networks.
Two important forms of interconnection are:
Peering: Two networks exchange traffic directly.
Transit: One network pays another to carry traffic to destinations beyond its own customers and peers.
Large ISPs, cloud providers, content networks, and other organizations operate routing domains known as . Within an AS, an interior gateway protocol commonly calculates routes. Between ASes, the exchanges reachability information and applies routing policies. A BGP announcement can tell other networks that a particular AS can deliver traffic toward a set of IP prefixes.
Takeaway: Access networks connect users to ISPs, while peering, transit, and inter-AS routing connect independently operated networks to one another.
Addressing, Prefixes, and Ports
An identifies an interface or endpoint at the layer. IPv4 uses 32-bit addresses, and IPv6 uses 128-bit addresses. IPv6 provides a much larger address space and supports address hierarchy and autoconfiguration.
Addresses are grouped into prefixes. For example, 203.0.113.0/24 represents a block whose first 24 bits identify the network prefix. Prefixes allow a router to represent many destinations with one routing entry. Classless Inter-Domain Routing supports route aggregation, which reduces the amount of routing information that must be advertised.
When multiple routes could apply, a router uses to select the most specific matching route. A public is intended to be reachable across the public , whereas a private address is used within a local or organizational network.
In IPv4, commonly allows several private devices to share one public address. NAT changes address information and often port information as traffic crosses the gateway, but it is not a replacement for the underlying routing system.
An identifies a host interface, not a particular application. A transport-layer port number identifies an application endpoint on that host. A flow can therefore be distinguished by its source address, source port, destination address, destination port, and transport protocol.
Takeaway: IP addresses guide packets to hosts or interfaces, while prefixes guide routing and ports guide data to applications.
Naming with DNS
People generally use names such as www.example.com instead of memorizing numerical IP addresses. The maps domain names to resource records, including IP addresses.
DNS uses a hierarchy:
Root name servers direct queries toward top-level domains.
Top-level-domain servers handle domains such as
.comand.org.Authoritative name servers hold records for particular domains.
Resolvers obtain answers for applications and may cache them.
A resolver can follow referrals through the hierarchy or answer from cached information. Caching improves speed and reduces the load on name servers, but a cached record is usable only for the period specified by its time-to-live, or TTL.
DNS supplies names and address information; it does not carry the web page, video, or message requested by an application. After a name is resolved, the application uses the resulting and an appropriate port to establish communication with the destination.
Takeaway: DNS separates human-readable naming from packet delivery and distributes the naming system across many servers and resolvers.
Layers and
communication is organized into layers. Each layer provides services to the layer above it and adds information required by its own protocol. This layered design allows an application to use networking services without managing every physical transmission detail.
The main responsibilities are:
Application layer: Provides services to programs, such as HTTP, DNS, and SMTP messages.
Transport layer: Provides process-to-process delivery using segments or datagrams, such as or .
layer: Provides addressing and forwarding between networks using IP packets.
Link layer: Moves data across one local link using frames, such as Ethernet or Wi-Fi frames.
Physical layer: Transmits bits as signals through copper, fiber, or radio.
occurs as data moves downward through the stack. An application creates a message. The transport layer may place it in a segment or datagram. IP places that transport data inside a packet. The local network then places the packet inside a frame for the next hop.
At each router, the incoming link-layer frame is removed and a new frame is created for the next link. The IP packet is generally forwarded onward, although a router may update fields such as an IPv4 time-to-live or an IPv6 hop limit. The router examines the IP header and chooses a next hop using its forwarding table.
Takeaway: The packet can persist across many hops, but its local link-layer frame is recreated for every link.
Transport Services and the End-to-End Model
and provide different transport services for applications.
provides a reliable, ordered byte stream. It uses sequence numbers, acknowledgments, retransmissions, flow control, and congestion-control mechanisms. If data is lost or arrives out of order, can retransmit it and present the application with an ordered stream.
provides a lighter datagram service. It uses ports and checksums but does not guarantee delivery, ordering, or duplicate protection. An application using must tolerate loss or implement any required recovery itself. can be useful when low overhead, quick delivery, or application-controlled recovery is important.
The follows an end-to-end model. Routers primarily forward packets, while communicating hosts implement much of the reliability, ordering, and application meaning. This keeps routers relatively general and lets different applications choose transport behavior appropriate to their needs.
Takeaway: supplies built-in reliability and ordering; supplies a simpler service in which the application controls more of the behavior.
Following a Web Request
Consider a laptop visiting https://www.example.com from a home network. The request follows a sequence of local, regional, and inter-network operations:
Local configuration: The laptop receives an , subnet information, a , and DNS resolver addresses, often through DHCP or IPv6 autoconfiguration.
Name resolution: The browser or operating system asks a resolver for the address of
www.example.com. The resolver uses cached information or queries DNS name servers.Transport and application setup: The browser prepares an HTTPS request. Depending on the implementation, the secure connection may use or a newer transport built over .
Local delivery: Because the destination is outside the local subnet, the laptop sends the first frame to the home router's link-layer address.
Access connection: The router forwards the packet through the broadband, cellular, or other access network to the ISP.
ISP routing: ISP routers consult forwarding tables and pass the packet along a route learned internally or through BGP from another AS.
Backbone and interconnection: The packet may cross several routers, backbone links, transit providers, peering connections, or an exchange point.
Destination network: Routers in the server's network deliver the packet to the appropriate data center, host, or load-balancing system.
Application delivery: The destination operating system uses the IP protocol, transport protocol, port number, and connection state to deliver the data to the web server.
Return traffic: The response travels back, potentially along a different path.
The page is divided into packets rather than sent as one uninterrupted signal. Packets can experience different delays or take different routes, and the outgoing and return paths can be asymmetric.
Takeaway: Loading a web page combines naming, local delivery, transport behavior, inter-network routing, and application processing.
Routing, Redundancy, and Resilience
Routing and forwarding are related but distinct activities. Routing calculates or learns possible paths through a network. Forwarding uses the current forwarding table to send each packet to its next hop.
A router may have multiple possible paths to a destination. If a link, interface, or router fails, routing protocols can withdraw the failed route and select an alternate path. Operators also build redundancy with multiple physical links, multiple routers, geographically separated facilities, and more than one upstream provider.
This design provides , but it does not guarantee perfect service. A failure can still cause packet loss, delay, congestion, or temporary unreachability while routing information converges. End systems and transport protocols add further recovery: can retransmit lost segments, and applications can retry requests or contact another server address.
The 's distributed design balances independence with coordination. No single router knows the entire future path of every packet, and no single organization controls the whole . Networks exchange reachability information and forward packets according to common protocols and local policies.
Takeaway: Redundancy and distributed recovery improve resilience, while routing convergence explains why failures can still cause temporary disruption.