Supplement · Network

20 câu hỏi Linux Networking và Nginx

Nêu packet/queue/resource evidence và phân biệt từng layer.

20 câu hỏi

Linux Networking

1. Route lookup chọn gì?
Policy rules/table, longest prefix, metric/nexthop và source address; dùng ip route get cho exact flow.
2. ARP/neighbor dùng khi nào?
Resolve L3 next-hop địa chỉ sang L2 trên link; stale/incomplete/duplicate IP gây local reachability failures.
3. SNAT vs DNAT?
SNAT đổi source cho egress, DNAT đổi destination cho ingress/service; conntrack reverse translation. Không thay firewall policy.
4. TIME_WAIT có xấu?
Bảo vệ delayed segments và connection tuple reuse sau active close; quá nhiều có thể phản ánh churn/ephemeral pressure, ưu tiên pooling/keepalive/capacity.
5. Ephemeral port exhaustion?
Không còn source tuple cho outbound destination/NAT; thấy connect failures, TIME_WAIT/conntrack pressure. Giảm churn/pool, scale source IP/NAT và tune có evidence.
6. SYN queue vs accept queue?
Half-open handshake vs established chưa accept; app/proxy có queues tiếp theo. Đo kernel counters cùng listener capacity.
7. TCP keepalive vs HTTP keep-alive?
TCP probes dead idle peer; HTTP reuse connection cho requests. Timeouts/lifecycle khác nhau.
8. Connect được nhưng request lớn treo?
PMTU/MSS black hole, proxy/body buffering/limits, congestion hoặc app read; capture segment sizes/retransmissions/ICMP và layer timings.
9. RST nghĩa gì?
Abort/no listener/invalid state; cần direction/sequence/context. Không tự đồng nghĩa firewall hay server crash.
10. Packet capture an toàn?
Filter tối thiểu, đúng interface/namespace/timestamp, encrypt/restrict/expire vì payload có credentials/PII; correlate both ends.

Nginx

11. Nginx event-driven nhưng vẫn hết capacity?
FD/worker_connections, CPU/TLS, buffers/temp disk, accept queues và upstream sockets/latency vẫn bounded.
12. least_conn khi nào hơn round-robin?
Request durations khác nhau và active count phản ánh load; không biết CPU/internal queue và keepalive/HTTP2 semantics có caveat.
13. Nginx retry POST?
Có duplicate risk nếu upstream đã nhận effect; chỉ retry theo idempotency/conditions và application key, giới hạn tries/deadline.
14. 499/502/504?
499 client đóng; 502 connect/bad upstream response; 504 upstream timeout. Correlate request/upstream timings và app logs.
15. Proxy buffering trade-off?
Protect upstream khỏi slow clients và allow retry/cache, nhưng memory/disk/latency và streaming behavior thay đổi.
16. Cache key thiếu gì nguy hiểm?
Host/query/language/encoding/auth/user dimension có thể serve sai hoặc leak personalized data; define representation identity.
17. Cache stampede?
Nhiều misses cùng fetch key; cache lock, stale-while-updating/jitter/prewarm và upstream capacity.
18. limit_req burst/nodelay?
Burst cho queue/excess; delay smooths, nodelay cho burst ngay nhưng account slots. Chọn theo UX/backpressure và key trust.
19. real client IP an toàn?
Chỉ trust known proxies và recursive chain policy sau strip/overwrite; client header trực tiếp spoof được.
20. Nginx reload?
Master validate/load config, start new workers, graceful old drain. Long-lived connections hoặc leaks giữ old generation; monitor and rollback config.
← NginxThực hành →