Stage 10: DNS & Ports¶
Key takeaways
- DNS turns domain names into IP addresses via a hierarchical lookup
- Ports let one IP address serve many simultaneous applications/connections
- IP = building address, Port = apartment number
DNS (Domain Name System)¶
Humans use google.com; the network needs 142.250.72.14. DNS is the
distributed lookup system that bridges the two.
The hierarchy, top to bottom¶
- Root servers — know where to find servers for each top-level domain (
.com,.org, etc.) - TLD servers — know where to find the authoritative servers for domains under that TLD
- Authoritative DNS servers — hold the actual record for
google.comand return its IP
A typical lookup (simplified)¶
Your device → DNS resolver (often your ISP or 8.8.8.8)
→ Resolver asks a root server: "who handles .com?"
→ Root server: "ask this TLD server"
→ TLD server: "ask google.com's authoritative server"
→ Authoritative server: "142.250.72.14"
→ Resolver caches this and returns it to you
In practice, most lookups never touch the root/TLD servers directly because of aggressive caching at every layer — your OS, your browser, and your resolver all cache DNS answers for a TTL (a different TTL concept from the packet one — this is "how long is this DNS answer valid before I should ask again").
Common record types (worth knowing cold)¶
| Record | Purpose |
|---|---|
| A | Domain → IPv4 address |
| AAAA | Domain → IPv6 address |
| CNAME | Domain → another domain (alias) |
| MX | Mail server for the domain |
| TXT | Arbitrary text (often used for domain verification, SPF/DKIM) |
| NS | Which servers are authoritative for this domain |
Ports¶
A single device might be running a web server, an SSH daemon, and a mail client all at once — all sharing one IP address. Ports disambiguate which application on that device a given piece of traffic is meant for.
- Range: 0–65535
- IP address ≈ building address, port number ≈ apartment number
- A connection is really identified by a 4-tuple:
(source IP, sourceport, destination IP, destination port)— this is what makes thousands of simultaneous connections between the same two IPs possible (your browser has many tabs open to the same site, each using a different source port)
Well-known ports (memorize these — they come up constantly)¶
| Port | Protocol |
|---|---|
| 20/21 | FTP (data / control) |
| 22 | SSH |
| 23 | Telnet |
| 25 | SMTP (email sending) |
| 53 | DNS |
| 80 | HTTP |
| 443 | HTTPS |
| 3306 | MySQL |
| 5432 | PostgreSQL |
Ports 0–1023 are "well-known/system" ports (traditionally require admin privileges to bind to on Unix systems); 1024–49151 are "registered"; above that are "dynamic/ephemeral" — the range your OS picks from when your machine initiates an outbound connection.
Cloud connection
Public DNS can point a hostname to a cloud load balancer, while Kubernetes cluster DNS resolves internal Service names. DNS returns an address or alias; routing, policy, and a listening application must still make that destination usable.
Practice in Packet Tracer¶
- Lab 05 — DNS & Name Resolution: configure A/CNAME records and observe DNS before HTTP.