skip to content

Provider Network Model

Your own private address range on a shared platform: per-zone subnets, route tables, private paths to managed services and boundary filtering. Probed because the network plan is what nobody revisits.

on this pageshow

questions

page 1 of 2

A stateless subnet filter fronts a workload whose own rule set is stateful — what does each need written for return traffic?

level: juniorimportance: must knowfreq 74%

answer

  1. two filters, two different machines
  2. who remembers the request
  3. the reply is a separate packet
  4. ephemeral port on the client side
  5. stateless needs the return direction too

basics

~20 s

The stateful rule set needs only the request direction written; it matches the reply to the flow it already accepted. The stateless subnet filter judges each packet alone, so the reply needs its own rule allowing the client's ephemeral port range.

solid answer

~40 s

Two boundaries, two different machines. A rule set attached to the workload is normally **stateful**: it decides on the first packet of a flow, records that flow, and matches every later packet — including the reply — against that record. You write the inbound allow and nothing else. A filter attached to the subnet is normally **stateless**: it has no record, so the reply is just another packet travelling outbound, from the service port to whatever high `ephemeral port` the client picked. If the outbound direction of that filter does not allow the ephemeral range back to the caller, the reply is dropped. The symptom is a hang rather than a refusal, because nothing rejects anything — the request is served and the answer vanishes at the subnet boundary.

go deeper

for a junior

Remember the one-line difference: a stateful boundary needs the request direction written, a stateless one needs both directions. Recall that the reply goes to a high ephemeral port the client chose, not back to the service port.

for a middle

Explain the mechanism, not the label: the first packet is decided against the rules and recorded, later packets of that flow are matched against the record. Then explain why a stateless layer cannot do that and what it forces you to write.

for a senior

Show the diagnosis. Say why the symptom is a hang, why a test from inside the same subnet passes, and why the workload's own logs look healthy. Name the direction and destination port you would check at each boundary.

for a principal

Frame it as a policy-placement standard: precise per-tier policy on the stateful workload layer, coarse whole-subnet statements on the stateless layer, so that return-traffic rules never have to be fine-grained and no team writes a broad ephemeral allow to make their tier work.

## Two filters that look alike and are not Inside a private address range you allocate on a provider's platform there are usually two places to filter traffic: a filter attached to a **subnet**, which every packet entering or leaving that subnet crosses, and a rule set attached to the **workload**, which only that workload's traffic crosses. On the platforms that offer both, the subnet-level filter is typically **stateless** and the workload-attached rule set is typically **stateful**. That property, not the scope, is what decides how much you have to write. ## What stateful means A stateful filter makes its decision on the **first packet of a flow** and records that flow — the two addresses, the two ports and the protocol — in a connection table. Every later packet belonging to that flow, in either direction, is matched against the table rather than decided again against the rules. So when you allow inbound traffic to the service port, the reply is allowed as a consequence: it belongs to a flow the filter already accepted. These rule sets are normally **allow-only with an implicit deny** — anything you have not allowed is refused, and there is nothing at all to write for return traffic. ## What stateless means A stateless filter keeps no connection table. Each packet is judged on its own, against an ordered list, in whichever direction it happens to be travelling. The reply to a request is a *separate packet in the opposite direction*: it leaves from the service port and is addressed to whatever **ephemeral port** the client's operating system picked for that connection, typically somewhere in the high range above 1024. The filter has no idea it is a reply. If the outbound direction does not allow that traffic, the reply is dropped. ## The reply, written out | Boundary | Inbound rule you write | Outbound rule you write | |---|---|---| | Stateful rule set on the workload | allow the service port from the caller | none — the tracked flow covers it | | Stateless filter on the subnet | allow the service port from the caller | allow the high ephemeral range back to the caller | The ephemeral range is chosen by the client, not by you, so a stateless return rule has to be broad enough to cover it. That is one reason the stateless layer is a coarse instrument and the workload-attached one carries the precise policy. ## Why this failure is mis-diagnosed - The symptom is a **hang, not a refusal**. The request arrives, the workload answers, and the answer disappears; the client sits until its own timeout fires. Nothing sends an error, so there is no error to read. - Testing **from inside the same subnet** succeeds, because that traffic never crosses the subnet boundary and so never meets the stateless filter at all. - The workload's own logs show the request **served successfully**, which sends people to the application, the route table or name resolution instead of to the return direction. - The mirror image fails identically: a call *initiated outbound* from the subnet needs the **inbound** direction of the stateless filter to allow the ephemeral range, and forgetting that looks like the dependency being down. The habit worth building is to ask, for every boundary a packet crosses, **in which direction** it is crossing and **which port is the destination** — and to check the return direction explicitly wherever the layer is stateless. ## Where each one belongs 1. Put the **workload-attached stateful rule set** at the centre of the design. It is where precise per-tier policy lives, it is safe by construction because it is allow-only, and it needs no return rules. 2. Use the **stateless subnet filter** as a coarse backstop for the whole subnet — a broad statement such as "nothing in this subnet reaches that range at all" — which survives a mistake in any single workload's rules. 3. Do not try to express fine-grained policy on the stateless layer. Every precise rule there doubles, because the return direction must be written too, and that return rule is necessarily broad. ## The trade underneath State costs memory and bookkeeping. A stateful filter holds an entry per flow, which is why very high connection counts and long-idle connections behave differently there. A stateless filter holds nothing, which makes it cheap, predictable and immediate — it applies to the very next packet, with no already-accepted flow to survive a change. Neither is safer in general. They fail in different directions, and knowing which of the two dropped a packet is most of the work of debugging a boundary.

  • Why does the missing return rule show up as a hang instead of a connection refused?
    A refusal requires something to send a rejection back. A stateless filter that does not match an allow simply discards the packet, so the client never hears anything and waits out its own timeout. The workload, meanwhile, believes it answered successfully — which is why its logs look healthy while the caller reports an outage.
  • The same missing rule breaks outbound calls too — which direction is wrong then?
    The inbound one. When the workload initiates the call, the reply arrives from outside addressed to the ephemeral port the workload chose, so the stateless filter's inbound direction must allow that high range. Teams usually write the outbound allow, see the request leave, and never check the return direction.
  • If the stateful layer needs fewer rules, why keep a stateless subnet filter at all?
    Because it applies to everything in the subnet regardless of what any individual workload's rules say, so it survives a mistake made one tier down. It is also immediate — with no tracked flows, a change takes effect on the next packet. Keep it coarse: a whole-subnet statement, not per-tier policy.

A stateful filter is a doorman who remembers letting you in and waves you back out without asking. A stateless one checks a card at every doorway and needs the way out written down separately.

saying these in an interview costs you the question

  • Says a stateful rule set still needs an explicit outbound allow for the reply
  • Assumes both boundaries behave the same because both filter traffic
  • Thinks allowing an inbound port implies the reply is allowed everywhere
  • Writes the stateless return rule to the service port, not the ephemeral range
  • Blames the application or the route when only the return direction is filtered
open as a page

A managed entry point keeps its public address when the machines behind it are replaced, so what makes that address a separate rented resource?

level: juniorimportance: must knowfreq 70%

basics

~20 s

The address is allocated from the platform's pool and held by the entry point resource, not by any machine. It outlives instance replacement, is usually charged while you hold it, and goes back to the pool only when you release it.

open as a page

What actually makes one subnet in your private cloud network public and another one private?

level: juniorimportance: must knowfreq 74%

basics

~20 s

Routing, not the name. A subnet is public when the route table it uses sends traffic for destinations outside the network to a target that reaches the internet. Private means no such route exists. The label itself configures nothing.

open as a page

Why would a team reach a managed store through an endpoint inside its own address range instead of the store's public address?

level: juniorimportance: must knowfreq 58%

basics

~20 s

An endpoint inside your own range keeps the call on the provider's internal network: the workload connects to an address in one of your subnets, so the request does not take the public path and the subnet needs no route to the internet.

open as a page

A batch job in a subnet with no internet route must call partner APIs without ever being reachable — what do you add?

level: juniorimportance: must knowfreq 72%

basics

~20 s

Two things: a default route on that subnet naming an address-translating gateway, and the gateway itself on the routed side. Outbound flows leave translated; unsolicited inbound packets match no translation entry, so nothing outside can open a connection.

open as a page

A search tier scales out and the new instances are refused by an address-based allowlist — what should that rule reference instead?

level: middleimportance: must knowfreq 60%

basics

~20 s

The caller's group rather than its addresses. A group-referencing rule on the workload-attached rule set resolves membership when the packet arrives, so instances that appear or disappear are covered with no rule edit and no address list to maintain.

open as a page

An encrypted tunnel over the internet or a dedicated private circuit into the provider: what does each buy, and why does only one start today?

level: middleimportance: must knowfreq 66%

basics

~20 s

An encrypted tunnel rides the public internet: usable within hours, but with variable latency and a throughput ceiling per tunnel. A dedicated circuit gives reserved capacity and latency inside a narrow band, after a lead time measured in weeks.

open as a page

Your managed entry point serves TLS with a certificate the platform issued, so who keeps it valid, and what changes if you upload your own?

level: middleimportance: must knowfreq 62%

basics

~20 s

A platform-issued certificate is requested against a name you prove you control, and the platform renews it on its own schedule while that proof still holds. An uploaded certificate stays your property: nobody renews it for you, and the door serves it until it expires.

open as a page

Why can two private networks that each peer with a shared middle network not reach each other?

level: middleimportance: must knowfreq 62%

basics

~20 s

Peering is non-transitive: a point-to-point link carries traffic only between the two ranges that are party to it, and the middle network will not relay for a third. Reaching the far network needs its own link, or a hub all three attach to.

open as a page

Your platform puts each subnet in one availability zone - what does a three-zone service need in its address plan?

level: middleimportance: must knowfreq 62%

basics

~20 s

At least one subnet per zone per tier, each with its own non-overlapping prefix. A zonal subnet cannot span zones, so the platform can only place instances in the zones you gave it subnets in, and each prefix needs its own growth headroom.

open as a page

After a private endpoint is added, what makes unchanged clients using the service's published hostname take the private path?

level: middleimportance: must knowfreq 62%

basics

~20 s

Name resolution is the switch. Inside the network holding the endpoint, the service's published hostname answers with the endpoint's address in your own range; everywhere else the same hostname still answers with the provider's public address. Clients change nothing.

open as a page

A workload holds a public address and the filter permits the traffic, yet outside connections just hang — which route is missing?

level: middleimportance: must knowfreq 58%

basics

~20 s

The subnet's route table has no default route toward the network's internet-facing attachment, so the workload's reply has no path back out. A public address is an attribute; only a route makes it reachable, and the caller sees a hang.

open as a page

In a stateless subnet filter evaluated in numbered order, what happens when an explicit deny sits ahead of a broader allow?

level: middleimportance: should knowfreq 56%

basics

~20 s

Evaluation stops at the first rule that matches, so the deny wins and the broader allow is never reached for that traffic. Reverse the order and the deny becomes dead configuration that the console still shows and nothing enforces.

open as a page

An encrypted internet tunnel carries synchronous replication that stalls every afternoon while its average round-trip time looks fine — which property of the path is failing?

level: middleimportance: should knowfreq 44%

basics

~20 s

Latency consistency, not average latency. A lock-step protocol waits for each round trip, so its throughput is set by the slow tail, and a tunnel over a shared internet path has a tail that widens whenever anything upstream or on your own uplink is busy.

open as a page

Your managed entry point appears on the bill in a month it served almost nothing, so what is a rented door's charge shape?

level: middleimportance: should knowfreq 48%

basics

~20 s

Two elements: a standing charge for the entry point existing, owed per hour whether or not anyone called, and a metered charge for the work it did, counted in connections, requests or processed capacity. An idle door is never free.

open as a page

Your network's address range was drawn in week one and is nearly full - what can you realistically still change?

level: middleimportance: should knowfreq 55%

basics

~20 s

Mostly what is not deployed yet. A prefix carrying live workloads is not widened in place on mainstream platforms, so the realistic move is to add unallocated space or a new subnet and migrate tier by tier - a rolling replacement, not an edit.

open as a page

Two subnets in one private network reach the internet differently — which route table decides that for each subnet?

level: middleimportance: should knowfreq 50%

basics

~20 s

The one table effective for that subnet decides: either a table explicitly associated with it, or the network's default table where nothing was associated. Within a table the most specific matching destination wins, and the default route is simply the least specific entry.

open as a page

A volumetric flood saturates the path to a public search tier — which layer absorbs that, and why can the workload's own rule set not?

level: seniorimportance: should knowfreq 44%

basics

~20 s

Volume is absorbed upstream, in the platform's own capacity in front of your boundary, where aggregate bandwidth dwarfs any tenant's. A rule set at the workload decides only after the traffic has already crossed the saturated path, and dropping a packet still costs the resource the flood is consuming.

open as a page

A managed entry point faces a tenfold traffic step at a scheduled sale start, so why does the rented pool lag, and what can you arrange beforehand?

level: seniorimportance: should knowfreq 45%

basics

~20 s

The pool is the platform's capacity, sized to your recent traffic and grown on the platform's own reaction schedule, which is minutes rather than seconds. Before a known step, ramp traffic through the real entry point and ask the provider to pre-scale it.

open as a page

During a merger both estates turn out to use the same private range, so why can the networks not simply be linked, and what actually fixes it?

level: seniorimportance: should knowfreq 52%

basics

~20 s

Forwarding picks a target by destination prefix, so an identical prefix on both sides makes the choice undecidable and platforms refuse the link. Real fixes are re-addressing one side, translating at the boundary, or joining only the ranges that do not collide.

open as a page

Your zonal subnet stops accepting new instances at peak although capacity and quota are fine - why?

level: seniorimportance: should knowfreq 47%

basics

~20 s

The subnet has no free addresses left. Every attached interface consumes one, including interfaces you did not create, the platform holds back a few per subnet, and a rolling deployment runs old and new instances together - so peak demand exceeds the steady-state count.

open as a page

Workloads in a peered network are refused by the managed store while the endpoint's own network succeeds — what is the usual cause?

level: seniorimportance: should knowfreq 38%

basics

~20 s

The private answer was attached only to the network holding the endpoint, so the peered network resolves the store's public address, takes the public path, and is refused by the rule that accepts only requests arriving through the endpoint.

open as a page

An auditor asks you to prove a managed store cannot be reached from the internet — why is a private endpoint alone not proof?

level: seniorimportance: should knowfreq 47%

basics

~20 s

An endpoint adds a private route; it does not retract the service's public front door. Any caller holding a valid credential still reaches that store from anywhere. The proof needs a resource-attached rule that refuses calls not arriving through the named endpoint.

open as a page

Your partner only accepts calls from one fixed source address — which outbound path makes every call from an autoscaled batch arrive from it?

level: seniorimportance: should knowfreq 44%

basics

~20 s

Route all of the batch's outbound traffic through one address-translating gateway holding a reserved public address, and give the workloads no public addresses of their own. Replica count, restarts and replacements then do not change the address the partner sees.

open as a page

At what point do you stop adding point-to-point links between private networks and put a transit hub in the middle?

level: principalimportance: should knowfreq 42%

basics

~20 s

When the pairs that must talk stop being a short list. Links grow with pairs and hub attachments grow with networks, so a hub wins on arithmetic — at the price of a standing charge per attachment, a shared route-table ceiling and one component in everybody's path.

open as a page

How would you hand out private address ranges across many teams so networks can still be joined later?

level: principalimportance: should knowfreq 38%

basics

~20 s

One authority allocates non-overlapping blocks out of one reserved supernet, in standard sizes per environment and region, recorded in a registry that lives with the infrastructure and is checked automatically. Self-service picking guarantees collisions that only renumbering can undo.

open as a page

When traffic to a managed service moves onto a private endpoint, how does the shape of the charge change?

level: middleimportance: nice to knowfreq 30%

basics

~20 s

It gains a floor. Internet transfer is metered per unit moved and costs nothing in a quiet month; a private endpoint typically adds a standing charge for existing, per placement, plus a per-unit processing charge for bytes passing through it.

open as a page

You delete an allow rule from a workload's stateful rule set, yet the traffic it permitted keeps flowing — why?

level: seniorimportance: nice to knowfreq 30%

basics

~20 s

The decision was already made. A stateful filter matches established flows against its connection table rather than re-deciding them against the rules, so on many platforms a long-lived connection outlives the rule that admitted it until it closes or its tracking entry expires.

open as a page

Your managed entry point is published as a name, but a partner allowlisted the single address it resolved once, so why does that break?

level: seniorimportance: nice to knowfreq 32%

basics

~20 s

A published name fronts a set of addresses the platform changes as the pool grows, moves or heals. An address resolved once is a snapshot with a lifetime, so the partner's outbound rule eventually points at an address your door no longer answers on.

open as a page

showing 1–30 of 33