← all topics

Review sheet

The two interviews at a glance · protocol one-liners · question bank with model answers · named coding problems · traps · links go to the full topic

1. Shape of the interviews · 2. Protocol one-liners · 3. The three walk-throughs · 4. Network question bank · 5. Coding question bank · 6. Big-O and Python cheat · 7. Command cheat · 8. Traps checklist

1. Shape of the interviews (from Meta's guide and firsthand reports)

RoundFormatWhat is gradedWhat people were actually asked
Coding screen45 min on CoderPad, usually 2 problems, ~30-35 min of coding, no code execution, any language (use Python)Efficiency, structure, syntax fluency, bugs, correctness, communication; follow-ups add constraintsOne file-parsing task (two-CSV join and sort by computed value, word frequency over a file, record file bigger than RAM) plus one LeetCode easy/medium (palindrome, valid parentheses, Battleship, Minesweeper, group IPs with a hashmap, closest value in a BST)
Network screen45 min, conversational, scenario-basedDepth on at least two protocols with pros/cons and comparison; reasoning when you don't knowBGP (13 of 22 reports), TCP (9), life of a packet / OSI (10), OSPF mostly as "vs BGP" (8), troubleshooting scenarios (8), ARP, DHCP DORA, DNS
Later loop (if any)coding, networking in depth, behavioral; some roles add a network design roundSame plus stories and "Why Meta""Tell me about yourself", a complex issue you troubleshot, enterprise LAN design 100→1000 hosts
Scripts to have cold: the coding script (clarify → baseline → optimise → test → complexity) and the protocol deep-dive script (overview → mechanics → what breaks → trade-offs → where you used it).

2. Protocol one-liners (say these, then go deeper on request)

ProtocolOne-linerDepth
Ethernet / switchFrames carry MACs; a switch learns source MACs per port, forwards known unicasts, floods unknowns and broadcasts, never reads IP.2, 10
ARPBroadcast "who has IP X" on the local link; unicast reply with the MAC; cached with a timeout. Hosts ARP for the next hop, never for a remote IP.6
IP / routingHierarchical addresses; each router does longest-prefix match, decrements TTL, rewrites the L2 header. Longest prefix beats everything, then AD, then metric, then ECMP.4, 12
ICMPControl messages: echo (ping), destination unreachable (codes: net, host, protocol, port, frag needed), time exceeded (traceroute), redirect.6
DHCPDiscover, Offer, Request, Ack over UDP 67/68 from 0.0.0.0 to broadcast; relay agents carry it across routers; renew at T1 (50%), rebind at T2 (87.5%). 169.254.x.x means it failed.6
DNSStub asks a recursive resolver; it walks root → TLD → authoritative, caches by TTL. UDP 53 with TCP for large answers and zone transfers. NXDOMAIN = name doesn't exist, SERVFAIL = resolver couldn't answer.6
TCPReliable ordered byte stream: 3-way handshake exchanges random ISNs and options; seq/ack count bytes; cumulative ACKs; loss detected by RTO or 3 dup ACKs; receive window = flow control, cwnd = congestion control; FIN polite close, RST abort; throughput ≈ window / RTT.8
UDPPorts and a checksum on top of IP; no handshake, ordering or retries. DNS, DHCP, NTP, VoIP, QUIC, VXLAN.8
TLSAfter the TCP handshake: ClientHello (SNI, ciphers) → ServerHello + certificate → key exchange → encrypted. TLS 1.3 is 1 RTT. Cert errors mean name mismatch, expiry or untrusted chain.19
VLAN / STP / LAG802.1Q tags split one switch into broadcast domains; trunks carry many VLANs. STP elects a root bridge and blocks redundant ports because L2 has no TTL. LACP bundles links and hashes per flow.10
OSPFLink-state IGP: hellos form adjacencies, LSAs flood the topology into the LSDB, every router runs Dijkstra; cost from bandwidth; areas limit flooding; fast convergence; trusts every router; protocol 89.12
IS-ISLink-state like OSPF but runs directly over layer 2 with TLVs; L1/L2 levels instead of areas; common in ISP and DC backbones; a preferred qualification in the posting.12
BGPPath-vector protocol between autonomous systems over TCP 179; prefixes carry attributes; AS_PATH prevents loops; best path by weight → local-pref → AS path → origin → MED → eBGP over iBGP → IGP metric; iBGP needs full mesh or route reflectors; policy steers traffic.14
Clos / ECMPLeaf-spine fabric: every leaf connects to every spine, equal-cost paths hashed per flow; Meta runs eBGP per link with private ASNs and summarisation; FBOSS switch software is applications on Linux.16
MPLSPush/swap/pop 20-bit labels so core routers forward on labels, not IP; used for traffic engineering, VPNs and fast reroute; segment routing does it without LDP.16
NATRewrites source IP (and port, for PAT) at the edge; keeps a translation table; breaks inbound connections and some protocols; a definition is enough here.19

3. The three walk-throughs (practice out loud, 2 minutes each)

A. Two hosts on one switch have just booted. How do they start communicating? (and in IPv6) Link comes up (speed/duplex autoneg). Each host DHCPs: Discover (broadcast, from 0.0.0.0), Offer, Request, Ack; now it has IP, mask, gateway, DNS. The switch learned both MACs from those frames. Host A wants B: same subnet by mask → ARP broadcast "who has B" → B replies unicast → A caches it and sends the frame to B's MAC; the switch forwards on its MAC table. IPv6: link-local fe80:: from the MAC/random, DAD via neighbor solicitation, router solicitation → router advertisement → SLAAC (or DHCPv6 if the RA says so); neighbor discovery (ICMPv6 NS/NA to a solicited-node multicast) replaces ARP.
B. Host A pings host B in another network (host-switch-router-switch-host). What changes at each hop? A: B is remote by mask → route table → default gateway → ARP for the gateway → frame dst MAC = router, dst IP = B, TTL 64. Switch 1 forwards on dst MAC. Router: dst MAC is mine → strip L2 → longest-prefix match → TTL 63 → ARP for B (directly connected) → new frame src MAC = router's other interface, dst MAC = B. Switch 2 forwards. B: ICMP echo reply with the roles swapped. IPs never change; MACs change on every segment; TTL drops by one per router. The reply needs its own route back.
C. You type https://www.facebook.com. What happens and where can it fail? Browser cache → OS resolver → DNS query to the configured recursive resolver (UDP 53) → root/TLD/authoritative or cache → A/AAAA record (failure: NXDOMAIN, SERVFAIL, timeout). Decide local vs remote → ARP for gateway → TCP SYN to port 443 (failure: SYN timeout = no route/drop, RST = reachable but not listening). 3-way handshake. TLS ClientHello with SNI → certificate → keys (failure: cert errors, version/cipher mismatch). HTTP GET → 200 with HTML → more requests for assets, often over the same keep-alive or HTTP/2 connection, via a CDN edge chosen by DNS/anycast (failure: 4xx/5xx, slow TTFB = server, slow transfer = loss/window). Render.

4. Network question bank (reported questions, with the answer skeleton)

BGP

Explain BGP, then list the attributes used for path selection in order.Path-vector EGP over TCP 179 between ASes; prefixes with attributes; AS_PATH loop prevention; policy per neighbour. Order: next-hop reachable → weight → local-pref → locally originated → shortest AS_PATH → origin → MED → eBGP over iBGP → lowest IGP metric to next hop → oldest / router-ID / neighbour IP. 14
eBGP vs iBGP; split horizon in iBGP.Different AS vs same AS; eBGP prepends AS and rewrites next hop, TTL 1 by default; iBGP changes neither and won't re-advertise iBGP-learned routes to iBGP peers (that is the split-horizon rule), hence full mesh or route reflectors. AD 20 vs 200.
Why not OSPF for the whole Internet? Why not iBGP instead of OSPF inside?OSPF needs every router to hold the full topology and trust every other router, has no policy and doesn't scale to a million prefixes across untrusting organisations. Inside an AS, iBGP still needs an IGP to reach next hops and converge quickly; BGP converges slowly and carries external reachability, the IGP carries internal topology. (Data centers do run eBGP-only, but with a tiny, flat design: topic 16.)
How do BGP and OSPF each avoid loops?BGP: reject routes whose AS_PATH contains my AS; iBGP split horizon; RR originator-ID/cluster-list. OSPF: everyone computes SPF on the same LSDB, a tree has no loops; sequence numbers age out stale LSAs; area 0 backbone rule prevents inter-area loops.
Route reflectors and confederations: what problem, what cost?Both remove the iBGP full mesh (n²). RR reflects its best path only (less diversity, suboptimal exits); deploy in pairs. Confederations split the AS into sub-ASes.
How do you control inbound vs outbound traffic?Outbound: local-pref. Inbound: AS-path prepending, MED to one neighbour, communities the provider honours, more-specific prefixes. You can only influence other ASes, not command them.
What is route dampening? Communities? Peer groups?Dampening suppresses prefixes that flap repeatedly (mostly off today). Communities are 32-bit tags that carry policy intent (NO_EXPORT, "set local-pref 80"). Peer groups apply one policy to many neighbours and reuse the update generation.
Does a router filter routes before sending them to a neighbour?Yes: outbound policy (prefix lists, route maps, communities) applied per neighbour between Loc-RIB and RIB-out; also max-prefix on inbound and RPKI origin validation.
A BGP session is stuck in Active. Idle?Active: TCP can't connect (reachability, port 179 blocked, multihop missing, wrong update source). Idle: not trying (admin down, max-prefix cease, waiting on a timer after a NOTIFICATION).

TCP and the packet path

Walk through the handshake and the header fields.SYN (ISN, MSS, wscale, SACK) → SYN+ACK → ACK; fields: ports, seq, ack, offset, flags, window, checksum, options. 8
Flow control vs congestion control; how is congestion detected and resolved?Receiver window vs sender cwnd; sender obeys the min. Congestion detected by loss (RTO, 3 dup ACKs), ECN marks or delay (BBR); resolved by cutting cwnd (halve, or back to slow start on timeout) and probing up again.
TCP vs UDP and when to use each.Reliability/order/backpressure vs latency/simplicity/one-shot exchanges; QUIC puts reliability on UDP.
What happens when you type a URL / life of a packet / two hosts just booted.Section 3 above.
OSI model: what runs at each layer? Favourite L2 and L3 protocol and why?Topic 2 table. Pick ones you can defend: Ethernet/802.1Q or STP at L2, IP/OSPF at L3 (BGP is an application over TCP, say so).
ARP: what, where is the table, what happens when it expires?IP→MAC on the local link; cache on every host and router with a timeout (seconds to minutes; Linux marks STALE and re-verifies); on expiry the next packet triggers a new request. Wrong entry → frames to the wrong MAC → silent loss until it ages out (gratuitous ARP fixes it on failover).
DHCP DORA and DNS resolution end to end.Section 2 one-liners; depth in 6.
IPv4 to IPv6 transition mechanisms.Dual stack (both addresses, preferred), tunnelling (6in4, 6rd, GRE), translation (NAT64 with DNS64, 464XLAT). Dual stack is the honest default.
What OS runs inside a switch or router?Vendor NOS (IOS-XE, NX-OS, Junos, EOS) are mostly Linux or BSD based with a forwarding ASIC programmed by an SDK; Meta's FBOSS is a set of applications on standard Linux on open hardware (Wedge/Minipack), with OpenBMC on the management controller.

Troubleshooting

Server unreachable: walk me through it.Scope (one client/all, one server/all, by IP/by name, since when, what changed) → from the client: ip addr/route/neigh, ping gateway, ping server, traceroute → split the path with a capture on the server (did SYNs arrive? did replies leave?) → routes both directions → firewall/ACL → server listening (ss -tlnp). 19
Latency and packet loss across regions: possible causes and narrowing steps.Baseline vs now; mtr both directions; loss that persists to the last hop vs ICMP rate-limiting; interface errors/drops per hop; congestion (utilisation, queue drops) vs bad optic (CRC) vs a single bad ECMP member (only some flows suffer; test with different source ports); MTU; fix and verify with the same measurement.
Slow website.curl -w timings split DNS/connect/TLS/TTFB/transfer; TTFB = server; transfer = loss or window (ss -ti retrans, cwnd); check for window 0 and PMTUD symptoms; compare from another vantage point.
Linux: high CPU causes; detecting a Python memory leak.top/uptime load, per-process pcpu, iowait vs user vs sys, runaway loops, GC, interrupt storms. Leak: RSS growing over time (ps/smem), tracemalloc snapshots, objgraph growth, unbounded caches/lists, un-closed sockets/files.

5. Coding question bank (named in reports) with the approach

ProblemApproachComplexityPractice
Dinosaur CSVs: join two files on name, compute speed, print bipedal fastest firstDictReader; index the smaller file in a dict; stream the other; compute; sort by -speed; skip or count missing keys; check header columns onceO(a+b) read, O(m log m) sort, O(a) space5, lab 7
Word frequency over a file; follow-ups on time/spacestream lines, normalise, Counter; most_common(k)O(n) words, O(u) distinct, O(u log k) top-k5, lab 4
Fortune-cookie file (% delimited), random fortune; file bigger than RAMgenerator yielding records; offsets with tell/seek in binary mode, or reservoir samplingO(n) one pass; O(records) offsets or O(1) reservoir5
Palindrome ignoring punctuation and casetwo pointers skipping non-alnum, compare lowercasedO(n), O(1)LC 125
Valid parenthesesstack; map closers to openers; empty at the endO(n), O(n)LC 20
Battleships in a board (count ships; variants: ship sizes, bomb placement)count only top-left cells (no X above or to the left); or DFS per ship marking visited; for sizes, walk right/down from each headO(rows×cols), O(1) or O(visited)LC 419, 11
Minesweeper revealBFS/DFS from the click: count adjacent mines; if zero, expand to 8 neighbours; mark visited by mutating the boardO(cells)LC 529, 13
Group IP addresses / records by keydefaultdict(list) keyed by the attribute (subnet via ipaddress, first octets, user, status)O(n), O(n)3
Closest value to K in a BSTwalk from the root toward K, track best |node−K|, go left if K < node else rightO(h)LC 270 (premium) / 17
Count cells in a 2D array meeting a condition; binary search for an element meeting a conditionrow/col loops; half-open binary search on a monotonic predicateO(rc); O(log n)11, 17
Split an array into two parts with equal sumtotal must be even; prefix running sum hits total/2 (contiguous) or subset-sum DP (any split)O(n) / O(n·sum)LC 724 / 416
Log into 100 devices, run a command, parse, scale to 1000function per device; ThreadPoolExecutor with a bounded pool; timeouts and retries; normalise output to dicts; write results incrementallywall time ≈ n/pool × per-device15, 21

6. Big-O and Python cheat

NeedUseCost
membership / dedupsetO(1) expected
count / groupCounter, defaultdict(list)O(n) build, O(u) space
sort by several keyssorted(key=lambda x: (-x.count, x.name))O(n log n), stable
top kheapq.nlargest(k, iterable, key=…)O(n log k)
queue / sliding window of recent itemsdeque: append, popleftO(1)
stacklist: append, pop()O(1)
sorted input, find boundarybisect / binary searchO(log n)
grid or graph reachabilityBFS with deque + visited set; DFS recursion (depth ≤ ~1000) or explicit stackO(V+E)
large filefor line in f; state dict onlyO(1) per line memory

Say the variables: n lines, u distinct keys, k results, r×c cells. Expected O(1) for hashing; worst case O(n) if asked.

7. Command cheat (question → command)

QuestionCommand
Is the link up, what's my IP/MTU?ip -br addr, ip -s link
Which route will this packet take?ip route get 10.2.2.30
Did ARP/ND resolve?ip neigh (REACHABLE / STALE / FAILED)
Is anything listening? What state are my connections in?ss -tlnp, ss -tni (rtt, cwnd, retrans)
Where does the path break?mtr -n -c 50 host both directions; traceroute -T -p 443 for TCP probes
Does the name resolve, and from where?dig +short host, dig @8.8.8.8 host, dig +trace host
Which phase is slow?curl -sv -o /dev/null -w '%{time_namelookup} %{time_connect} %{time_appconnect} %{time_starttransfer} %{time_total}\n' URL
Did the packet leave / arrive?tcpdump -ni eth0 host X and port 443 -c 20 on both ends
Is the path MTU smaller?ping -M do -s 1472 host (1472 + 28 = 1500)
Is the local firewall dropping it?nft list ruleset / iptables -S; counters
Errors on the interface?ethtool -S eth0 | grep -i -E 'err|drop|crc'
Why is the box slow?uptime, top, free -m, dmesg -T | tail, journalctl -u svc -n 100

8. Traps checklist

← 21 · network interview script · all topics · final mock →