Companion to the network visualizer. Five sections: a step-by-step walk of one request from phone to database (start here if any of this is new), the non-networking exam domains as decision-oriented cards with a diagram each, an animated disaster-recovery failover simulator, a door into the three-cloud atlas of service names, and the deep conceptual differences between the three clouds that actually change your architecture. Every diagram has a plain-English caption, no cloud background assumed.
Two memory aids. Top-down, 7→1: All People Seem To Need Data Processing. Bottom-up, 1→7: Please Do Not Throw Sausage Pizza Away.
The honest caveat. Real networks run TCP/IP, not OSI. Layers 5, 6 and 7 do not exist as separate things in practice, HTTPS smears encryption, session and application into a single stack. OSI survives anyway, because it gives engineers a shared vocabulary: saying “that’s a layer 3 problem” instantly means routing, rather than the app being broken.
| What you observe | Where the problem is | Because |
|---|---|---|
| Cannot ping the IP at all | Layer 3 | Nothing is reaching the machine. Routing, the address, or a network-level block, and no point looking at the app |
| Ping works, but the port is refused | Layer 4 | The machine is reachable, so routing is fine. Either a firewall is blocking that port or nothing is listening on it |
| Port is open, but you get a 500 | Layer 7 | The whole network path works. The request arrived and the application itself failed, stop looking at infrastructure |
| Works by IP, fails by name | Layer 7 (DNS) | Everything below is proven by the IP working. Only the name lookup is broken |
| Works from one machine, not another | Layer 3 or 4 | The service is fine, so it is about the path or the permission, a source range, a security group, a route |
Why five are missing: AWS reserves the first four addresses and the last one in every subnet, network, VPC router, DNS, one held for future use, and broadcast. GCP reserves four. That is why a /28 gives you 11 usable addresses, not 16.
One process does four jobs that used to need four products: web server (hands out files), reverse proxy (forwards requests to your app), load balancer (spreads them across several copies), and edge (TLS, caching, compression, rate limiting). In Kubernetes it is usually running as the ingress controller, so if you use Kubernetes you almost certainly run NGINX already, whether you chose it or not.
| Area | When you see this | The answer is usually | Because |
|---|
Missed cards come back. The deck is not finished until you have seen every one of them twice in a row without a miss, which is a better use of ten minutes than re-reading the table.