802.1Q / VLAN

An IEEE standard defining the tagging of Ethernet frames for VLAN networks. A 4-byte field (tag) is inserted into the Ethernet header, comprising 12 bits of VLAN identifier (VID — 4,096 possible VLANs). Essential for the logical segmentation of corporate networks.

 

— A —

 

ACK  /  ACKNOWLEDGEMENT

(Acknowledgement): A message sent to confirm that data has been received correctly and without errors. A fundamental mechanism of the TCP protocol that ensures the reliability of transmissions.

 

AIOPS

Artificial Intelligence for IT Operations. The application of AI and machine learning to IT and network operations, to automate the predictive detection of faults (LSTM, isolation forests), their correlation (RCA — Root Cause Analysis) and their autonomous resolution. Examples: Cisco ThousandEyes, Juniper Mist AI, Aruba Central.

 

ANSI

(American National Standards Institute): An American non-governmental organisation founded in 1918, a member of the ISO, responsible for proposing and publishing standards in the fields of information technology and telecommunications.

 

API

(Application Programming Interface): A programming interface that exposes a service’s functionality to other applications via primitives, libraries or HTTP/REST calls. REST APIs (JSON/HTTP) are the dominant standard for interconnecting modern web and cloud services.

 

APPLET JAVA ⚠

A small Java programme run in a web browser from a remote server. Applets have been phased out in all modern browsers for security reasons, replaced by JavaScript, WebAssembly and native web APIs.

 

ARP

(Address Resolution Protocol): A protocol that maps an IP address (Layer 3) to a physical MAC address (Layer 2). An ARP request is a local broadcast that does not pass through routers. ARP is specific to IPv4; IPv6 uses NDP (Neighbour Discovery Protocol).

 

ARPANET ⚠

An experimental network created in 1969 by the US military agency ARPA, the direct predecessor of the Internet. As the first large-scale operational packet-switched network, it served as a testing ground for TCP/IP protocols until it was integrated into the NSFNET in 1990.

 

ASCII

(American Standard Code for Information Interchange): A 7-bit character encoding scheme (128 characters), extended to 8 bits by IBM in 1981 (256 characters, including accented letters and graphic characters). It has now been superseded by Unicode/UTF-8, which supports all characters in all languages.

 

ATM ⚠

(Asynchronous Transfer Mode): A switching technique using fixed-size cells (53 bytes) that enables the multiplexing of voice, video and data with guaranteed Quality of Service (QoS). Deployed in operators’ network cores during the 1990s and 2000s. Largely replaced by MPLS and high-speed Ethernet.

 

— B —

 

BACKBONE  /  SPINE

A very high-speed network serving as the main backbone connecting several sub-networks or sites. Currently based on 100G/400G Ethernet and DWDM (Dense Wavelength Division Multiplexing) over optical fibre.

 

BANDWIDTH  /  BANDWIDTH

The maximum data rate of a link or network, expressed in bits per second (bps, Mbps, Gbps, Tbps). This should be distinguished from actual throughput, which takes into account protocol overhead and transmission conditions.

 

BGP  /  INTER-DOMAIN ROUTING PROTOCOL

(Border Gateway Protocol, RFC 4271): A dynamic routing protocol used between autonomous systems (AS) on the Internet. It is the Internet’s routing protocol itself, maintaining a global routing table of approximately 900,000 prefixes. BGP4 is the current version; BGP4+ supports IPv6.

 

BIT

(Binary Digit): The basic unit of information in computing. A bit is either 0 or 1. It is the smallest unit that a digital system can process. Eight bits make up a byte.

 

BPS

(Bits Per Second): A unit of measurement for the data rate of a connection. Multiples: Kbps (kilobits per second), Mbps (megabits per second), Gbps (gigabits per second), Tbps (terabits per second). Not to be confused with bytes per second (B/s = 8 × bps).

 

BRIDGE  /  PONT ⚠

Network equipment that connects two segments at OSI Layer 2 using MAC addresses. It has now been replaced by switches, which offer the same functions with significantly better performance thanks to their CAM tables and dedicated full-duplex ports.

 

BROADCAST  /  DIFFUSION

A message sent simultaneously to all devices on a network segment or VLAN. The IPv4 broadcast address for a subnet ends with 255. Broadcasts do not pass through routers. IPv6 does not use broadcasts but uses multicast.

 

BROWSER  /  NAVIGATOR

Software that allows users to access web resources and view HTML, CSS and JavaScript pages. Modern browsers (Chrome, Firefox, Edge, Safari) support HTML5, WebAssembly, WebRTC and advanced web APIs.

 

BUG

An English term referring to a design flaw in software or hardware that can cause unexpected or incorrect behaviour. An exploitable security bug is known as a vulnerability.

 

— C —

 

CACHE

A storage area (RAM, disk or remote server) that temporarily stores recently used data to speed up future access. Content Delivery Networks (CDNs) use geographically distributed caches to reduce the latency of web content.

 

CASB  /  CLOUD ACCESS SECURITY BROKER

(Cloud Access Security Broker): A SASE component that provides visibility and control over access to SaaS applications (Microsoft 365, Salesforce, Google Workspace). It detects unauthorised use, enforces security policies and prevents data leaks.

 

CCITT ⚠

International Consultative Committee for Telegraph and Telephone. A telecommunications standards body under the ITU, based in Geneva. Replaced in 1993 by ITU-T (International Telecommunication Union — Telecommunication Standardisation Sector).

 

CDN  /  Content Delivery Network

(Content Delivery Network): A global network of distributed servers that cache content (web pages, videos, APIs) as close as possible to users, reducing latency and the load on origin servers. Modern CDNs (Cloudflare, Akamai, AWS CloudFront, Fastly) also incorporate edge computing, DDoS mitigation and WAF capabilities.

 

CERT ★

(Computer Emergency Response Team): An organisation responsible for responding to cybersecurity incidents. Founded in 1988 by DARPA in the wake of the Morris worm. In France: ANSSI and CERT-FR coordinate the response to national cyber threats.

 

CGNAT / Operator-Grade NAT

(Carrier-Grade NAT): Shared NAT implemented by an ISP, allowing multiple subscribers to share the same public IPv4 address. Deployed to address the shortage of IPv4 addresses. Creates a double NAT, which complicates troubleshooting, forensic tracing and certain peer-to-peer services.

 

CIDR

(Classless Inter-Domain Routing): A notation format for IP addresses and subnet masks introduced in 1993, replacing the rigid A/B/C class system. Slash notation: 192.168.1.0/24 indicates a 24-bit network portion. It enables more efficient allocation and reduces the size of global routing tables.

 

CONTAINER

A lightweight software unit that encapsulates an application and its dependencies within an isolated, portable environment, sharing the host system’s kernel (unlike a virtual machine). Docker is the most widely used container runtime. Kubernetes orchestrates containers at scale.

 

COOKIES ★

Small text files created by a web server and stored in the user’s browser, used to maintain state between HTTP sessions (authentication, preferences, shopping basket). The GDPR requires consent to be obtained before setting cookies that are not strictly necessary.

 

CSMA/CD ⚠

(Carrier Sense Multiple Access / Collision Detection): The medium access protocol used in traditional Ethernet (IEEE 802.3) in half-duplex mode. Devices listen before transmitting and detect collisions. Obsolete in modern switched networks, where each port operates in dedicated full-duplex mode.

 

— D —

 

DATAGRAM

A self-contained unit of data in a packet-switched network, containing all the information required for its routing (source and destination addresses). Each datagram may take a different path to its destination. The model on which IP (Internet Protocol) is based.

 

DHCP  /  Dynamic Host Configuration Protocol

(Dynamic Host Configuration Protocol, RFC 2131): A protocol that automatically assigns network settings to devices (IP address, subnet mask, gateway, DNS). UDP ports 67 (server) and 68 (client). DHCPv6 is the version for IPv6, often used in conjunction with SLAAC autoconfiguration.

 

DKIM

(DomainKeys Identified Mail): An email authentication standard that adds a cryptographic signature to the header, enabling the receiving server to verify that the email originates from the declared domain and has not been tampered with. It complements SPF and DMARC.

 

DMARC

(Domain-based Message Authentication, Reporting and Conformance): A standard that combines SPF and DKIM to define the policy for handling unauthenticated emails (quarantine or rejection) and to generate abuse reports for the domain administrator.

 

DNS  /  Domain Name System ★

(Domain Name System): A distributed Internet directory that translates www.example.com into IP addresses. Hierarchical architecture: root servers → TLD servers (.com, .fr, etc.) → authoritative servers → ISP resolvers. UDP/TCP port 53. DNSSEC adds cryptographic validation of responses.

 

DNSSEC  /  DNS SECURITY

(DNS Security Extensions, RFC 4033–4035): A DNS extension that adds cryptographic signatures to responses to prevent cache poisoning attacks. DoH (DNS over HTTPS) and DoT (DNS over TLS) also encrypt DNS queries to preserve confidentiality.

 

DOWNLOAD

The process of copying files from a remote server to a local device via a network. Download speed refers to the rate at which data is received. The reverse operation (sending data to a server) is known as an upload.

 

— E —

 

EBPF

(Extended Berkeley Packet Filter): A Linux kernel technology that enables verified and sandboxed programmes to run in kernel space without modifying the kernel source code. It is revolutionising network observability (Cilium), load balancing (Cloudflare, Facebook Katran) and security (Tetragon) in cloud-native environments.

 

EDGE COMPUTING  /  EDGE COMPUTING

An IT architecture that brings data processing closer to the source (IoT sensors, industrial robots, vehicles) rather than centralising everything in the cloud. It reduces latency for real-time applications, lowers WAN bandwidth consumption and improves resilience in the event of a network outage.

 

ETHERNET ★

Local Area Network (LAN) technology standardised by the IEEE (802.3). Evolution of data rates: 10 Mbps → 100 Mbps (Fast Ethernet) → 1 Gbps (Gigabit Ethernet) → 10/25/40/100/400 Gbps (data centres). The dominant wired LAN standard in businesses, incorporating PoE (Power over Ethernet) for powering equipment.

 

— F —

 

FAQ

(Frequently Asked Questions): A document compiling the most frequently asked questions on a particular topic, along with their answers. A standard format for online documentation.

 

FDDI ⚠

(Fibre Distributed Data Interface): A standard for dual-ring local area networks over fibre optics operating at 100 Mbps. A standard from the 1990s for campus backbones. It has been completely superseded by Gigabit Ethernet and 10 GbE since the 2000s.

 

FIREWALL  /  FIREWALL ★

A system that enhances security between an internal network and an unsecured network (the Internet) by filtering traffic according to rules that define what is permitted. Types: stateless filtering (packets), stateful filtering (connections), WAF (web application firewall), NGFW (Next Generation Firewall: SSL/TLS inspection, IPS, sandboxing). A central component of any network security architecture.

 

FLOW CONTROL  /  FLOW CONTROL ★

A mechanism that regulates the data rate between a sender and a receiver to prevent congestion. In TCP: sliding window and congestion control (slow start, CUBIC, BBR). In Ethernet: the PAUSE protocol (802.3x) and PFC (Priority Flow Control, 802.1Qbb) for converged networks.

 

FTP ★

(File Transfer Protocol): File Transfer Protocol (TCP ports 20/21). FTP transmits credentials and data in plain text — this should be avoided on the internet. It has been replaced by SFTP (via SSH, port 22) or FTPS (FTP over TLS) for secure transfers.

 

FTTH / Fibre to the Home

(Fibre to the Home): Deployment of fibre-optic cables directly to the home, offering symmetrical speeds of 1 to several Gbps. The leading broadband access solution in France, deployed via PON (GPON/XGS-PON). France Very High-Speed Broadband Plan: 100% coverage of the country by 2025–2027.

 

FULL-DUPLEX ★

A communication mode that allows simultaneous transmission and reception over the same link. Modern switched Ethernet networks operate in full-duplex mode, eliminating CSMA/CD collisions. Opposite: half-duplex (alternating transmission and reception).

 

— G —

 

GATEWAY  /  GATEWAY ★

Equipment that enables interconnection between networks using different protocols by performing protocol conversions (OSI layers 4 to 7). Examples: VoIP gateways (PSTN to SIP/IP), IoT gateways (proprietary protocols to IP), cloud gateways (local network to cloud VPC).

 

GPON

(Gigabit Passive Optical Network, ITU-T G.984): A standard for passive fibre access networks that shares a single fibre amongst 64 subscribers using passive optical splitters (which require no power supply). Downlink speed: 2.5 Gbps; uplink speed: 1.2 Gbps. The dominant technology in French FTTH deployments.

 

— H —

 

HDLC ⚠

(High-Level Data Link Control): A bit-oriented Layer 2 protocol operating in synchronous mode with cyclic redundancy checking. It forms the basis of many historical WAN protocols (SDLC/SNA, LAP-B/X.25, LAP-D/ISDN). It has been replaced by Ethernet and MPLS in modern networks.

 

HERTZ

Unit of frequency measurement (Hz), corresponding to one cycle per second. Multiples: kHz, MHz, GHz, THz. In networking, frequency defines radio bands (Wi-Fi 2.4/5/6 GHz, 5G sub-6 GHz, 5G mmWave 26–40 GHz, 6G terahertz).

 

HTML ★

(HyperText Markup Language): A standard markup language for creating web pages. HTML5 (2014) introduced native multimedia capabilities (audio, video, canvas, WebSockets, Web Workers), reducing reliance on plugins. It is interpreted by browsers in conjunction with CSS and JavaScript.

 

HTTP ★

(HyperText Transfer Protocol): An application protocol for transferring web pages (port 80 / 443 for HTTPS). HTTP/2 improves performance by multiplexing requests. HTTP/3 uses QUIC (over UDP) to further reduce latency and improve resilience to packet loss.

 

HUB  /  CONCENTRATOR ⚠

Layer 1 (physical) equipment that regenerates and redistributes the electrical signal across all its ports, creating a shared collision domain. Now completely superseded by switches in all modern networks.

 

— I —

 

IAB

(Internet Architecture Board): A body responsible for overseeing the technical architecture of the Internet and coordinating the activities of the IETF (Internet Engineering Task Force, publisher of RFCs) and the IRTF (Internet Research Task Force).

 

IBN  /  INTENTION-DRIVEN NETWORK

(Intent-Based Networking): A network architecture in which the administrator defines their objective in business terms (the intent), and the system automatically translates this into configurations deployed across the entire network (activation), then continuously verifies compliance (assurance). Examples: Cisco Catalyst Center, Juniper Apstra.

 

IEEE

(Institute of Electrical and Electronics Engineers): The leading standards body for electrical and information technology. Publisher of the IEEE 802 network standards: 802.3 (Ethernet), 802.11 (Wi-Fi), 802.1Q (VLAN), 802.1X (network authentication), 802.3af/at/bt (PoE).

 

IMAP ★

(Internet Message Access Protocol, RFC 3501): A protocol for accessing emails on a remote server, which keeps messages on the server and synchronises their status across multiple devices. Port 143 / 993 (IMAPS/TLS). It is a better alternative to POP3 for users with multiple devices.

 

IP ★

(Internet Protocol): A network layer protocol (OSI Layer 3) that handles packet addressing and routing. IPv4 (RFC 791, 32 bits, ~4.3 billion addresses, address space exhausted) and IPv6 (RFC 2460, 128 bits, virtually unlimited). The universal Internet protocol.

 

IPv6  /  Internet Protocol Version 6

(Internet Protocol version 6, RFC 2460): The successor to IPv4, providing 2¹²⁸ addresses (340 sextillion). 128-bit addresses in hexadecimal, separated by ‘:’ (e.g. 2001:db8::1). SLAAC autoconfiguration, native multicast, simplified header. Global adoption ~45% by 2025; France ~40%.

 

IRC ⚠

(Internet Relay Chat): A real-time instant messaging protocol organised into topic-based channels. It was very popular in the 1990s and 2000s. It has largely been replaced by Slack, Discord, Microsoft Teams and mobile messaging apps.

 

ISDN / RNIS ⚠

(Integrated Services Digital Network): A digital network capable of carrying voice, data and images over telephone lines (64 Kbps per B channel). It has been completely replaced by fibre optics, ADSL and 4G/5G mobile networks.

 

ISP / Internet Service Provider

(Internet Service Provider): A provider offering internet access via its own infrastructure (fibre, ADSL, mobile) on a subscription basis. Also provides email, web hosting, VoIP and IPTV. In France: Orange, SFR, Bouygues Telecom, Free.

 

— J —

 

JAVA ★

An object-oriented programming language created by Sun Microsystems (1995). Based on the ‘write once, run anywhere’ principle via the JVM (Java Virtual Machine). Widely used for server-side enterprise applications, Android applications and embedded systems.

 

— K —

 

Kubernetes

(K8s) An open-source container orchestration platform created by Google (2014). It automates the deployment, scaling, load balancing and management of containerised applications across server clusters. It is the de facto standard for cloud-native architectures.

 

— L —

 

LACP  /  LINK AGGREGATION

(Link Aggregation Control Protocol, IEEE 802.3ad/802.1AX): A protocol that combines multiple physical Ethernet links into a single logical link (LAG — Link Aggregation Group), increasing bandwidth and providing redundancy in the event of a physical link failure.

 

LAN ★

(Local Area Network): A computer network covering a small geographical area (building, campus) with high-speed connectivity. Based on Ethernet (wired) and Wi-Fi (wireless). Typical speeds in 2025: 1 Gbps to workstations, 10/25/100 Gbps in the network core.

 

LINUX ★

A free and open-source operating system based on Unix, created in 1991 by Linus Torvalds. Distributed under the GPL licence. Widely used in servers (over 70% of web servers), cloud systems (AWS, Azure, GCP), networking equipment, smartphones (Android) and supercomputers.

 

— M —

 

MAC

(Media Access Control): The lower sublayer of OSI Layer 2 that manages access to the physical medium. Each network interface has a unique 48-bit MAC address (6 hexadecimal bytes, e.g. 00:1A:2B:3C:4D:5E) assigned by the manufacturer (OUI — Organizationally Unique Identifier).

 

MEC / IT in the Mobile Access Periphery

(Multi-Access Edge Computing): An ETSI architecture that places computing and storage capabilities at the edge of the 5G access network (within or near gNB base stations), offering latencies of less than 5 ms. Applications: Industry 4.0 (machine vision, quality control), V2X (connected vehicles), augmented reality.

 

MIB ★

(Management Information Base): A hierarchical database describing the manageable objects of a network device, used by SNMP. It is structured as an OID (Object Identifier) tree. MIB-II (RFC 1213) defines the standard objects; manufacturers extend this database with proprietary MIBs.

 

MIME ★

(Multipurpose Internet Mail Extensions): A standard that extends the email format to support non-ASCII content: attachments (images, audio, documents), encoded text, and character sets. Also used by HTTP to specify the content type (Content-Type: text/html, application/json…).

 

MODEM ★

(Modulator/Demodulator): A device that converts digital signals into analogue signals for transmission (and vice versa). Built into modern ISP boxes (ADSL modems, ONTs — Optical Network Terminals for FTTH fibre).

 

MPLS  /  LABEL SWITCHING

(Multi-Protocol Label Switching): A technique for routing network packets based on labels rather than IP address analysis, enabling carrier VPNs with guaranteed QoS and traffic engineering. Used in carrier network cores. Gradually facing competition from SD-WAN on the internet.

 

 

— N —

 

NAT / Network Address Translation

(Network Address Translation): A mechanism that allows multiple devices on a private network to share a single public IP address. It addresses the shortage of IPv4 addresses but complicates peer-to-peer protocols. It has been rendered obsolete by IPv6, which restores end-to-end connectivity.

 

NETIQUETTE

The set of conventions and rules of good conduct in electronic communications (emails, forums, social media). A portmanteau of ‘Net’ and ‘Etiquette’. Principles: politeness, brevity, respect for privacy, and avoiding excessive use of capital letters.

 

NFS ★

(Network File System): A protocol developed by Sun Microsystems that allows remote files to be accessed and used as if they were local. Standard on Unix/Linux. NFSv4 (RFC 7530) improves security and performance. A competitor to SMB/CIFS (Windows).

 

— O —

 

OCTET

A unit of information consisting of 8 bits. A byte can represent 256 values (0 to 255). IPv4 addresses are made up of 4 bytes. In English, the common term is ‘byte’.

 

OSI

(Open Systems Interconnection): A 7-layer reference model defined by ISO to standardise network communications: 1-Physical, 2-Data Link, 3-Network, 4-Transport, 5-Session, 6-Presentation, 7-Application. Theoretical reference model; in practice, the TCP/IP suite uses four layers (network access, Internet, transport, application).

 

OSPF  /  INTRA-DOMAIN ROUTING PROTOCOL

(Open Shortest Path First, RFC 2328): A link-state dynamic routing protocol used in an autonomous system. Each router builds a complete map of the network (LSDB) and calculates the best routes using Dijkstra’s algorithm. Fast convergence; supports VLSM and CIDR. OSPFv3 for IPv6.

 

— P —

 

Private branch exchange

(Private Automatic Branch eXchange): A private telephone exchange that manages a company’s internal calls and connects them to the public network. Modern PABX systems are IP-PBXs (IP-PBX) that operate using the Session Initiation Protocol (SIP), integrating telephony into IP networks.

 

PACKAGE

A transmission unit in a packet-switched network. It comprises a header (source and destination addresses, sequence number, protocol) and a payload (data). The maximum size of an IP packet is the MTU (Maximum Transmission Unit): 1,500 bytes by default on Ethernet.

 

PDH ⚠

(Plesiochronous Digital Hierarchy): The digital multiplexing hierarchy used by incumbent operators (E1 2 Mbps to E4 140 Mbps in Europe). Replaced by SDH and subsequently by Ethernet and DWDM over optical fibre.

 

PHISHING  /  PHISHING

A social engineering attack that impersonates a trusted entity (such as a bank, telecoms provider or government department) via email or text message in order to steal login details, bank details or trigger malware. Spear phishing targets a specific individual with a personalised message.

 

PING

A network utility that uses the ICMP protocol to test the reachability of a remote host and measure round-trip time (RTT). An essential diagnostic tool. Command: ping <IP address or domain name>.

 

POE  /  Power over Ethernet

(Power over Ethernet, IEEE 802.3af/at/bt): A technology that supplies power to devices (IP phones, IP cameras, Wi-Fi access points, IoT sensors) via the Ethernet cable, without the need for a dedicated mains power supply. PoE (802.3af): 15.4 W — PoE+ (802.3at): 30 W — PoE++ (802.3bt): up to 90 W.

 

POP3 ★

(Post Office Protocol 3): A protocol for retrieving emails from a mail server (port 110 / 995 over TLS). By default, POP3 downloads and deletes messages from the server. It has been largely superseded by IMAP for users with multiple devices.

 

PQC  /  POST-QUANTUM CRYPTOGRAPHY

(Post-Quantum Cryptography): Cryptographic algorithms resistant to attacks by quantum computers (Shor’s and Grover’s algorithms), running on classical computers. NIST standards published in 2024: ML-KEM/Kyber (FIPS 203), ML-DSA/Dilithium (FIPS 204), SLH-DSA/SPHINCS+ (FIPS 205). Intended to replace RSA, ECDSA and ECDH.

 

PROXY  /  PROXY SERVER ★

A proxy server that acts as an intermediary between clients on an internal network and external servers. It forwards HTTP/HTTPS requests, caches popular content, filters out unwanted URLs and anonymises connections. Reverse proxies (Nginx, HAProxy, Cloudflare) protect application servers.

 

— Q —

 

QKD / Quantum Key Distribution

(Quantum Key Distribution): A technology that uses the laws of quantum physics to distribute cryptographic keys with physically provable security: any interception is detectable because it disrupts the transmitted photons. Main protocol: BB84 (1984). Complementary to PQC for highly sensitive government and financial communications.

 

QOS  /  Quality of Service

(Quality of Service): A set of mechanisms that guarantee performance levels (minimum throughput, latency, jitter, packet loss rate) for certain priority traffic types (Voice over IP, video conferencing, mission-critical applications). Mechanisms: DSCP marking, policing, shaping, priority queues (FIFO, WFQ, LLQ).

 

— R —

 

RANSOMWARE  /  RANSOMWARE

Malware that encrypts files on a system and demands a ransom in cryptocurrency in exchange for the decryption key. The main cyber threat to businesses, hospitals and local authorities since 2015. Spread via phishing, exploitation of vulnerabilities or supply chain attacks.

 

RFC ★

(Request for Comments): Technical documents published by the IETF defining Internet standards, protocols and best practices (TCP/IP, HTTP, DNS, SMTP, IPv6, etc.). These are freely available at rfc-editor.org. RFCs serve as the reference documentation for all Internet protocols.

 

GDPR / GENERAL DATA PROTECTION REGULATION

European Regulation (2016/679, in force since 2018) governing the collection, processing and storage of personal data. It requires transparency, explicit consent, and the right to be forgotten and to data portability. Penalties of up to 4% of global turnover or €20 million. Supervised by national data protection authorities.

 

RIP ★

(Routing Information Protocol): A dynamic distance-vector routing protocol that uses the number of hops as a metric (maximum 15). Simple but slow to converge. Replaced by OSPF and EIGRP in the vast majority of enterprise networks. RIPng is the IPv6 version.

 

ROUTER ★

Network equipment operating at OSI Layer 3 (network layer), which forwards IP packets between different networks according to its routing table (static or dynamic routes via RIP, OSPF, BGP). Modern routers incorporate firewall, VPN, QoS and SD-WAN functions and are often virtualised (vRouter).

 

— S —

 

SASE / Secure Edge Access Service

(Secure Access Service Edge): An architecture that combines networking functions (SD-WAN) and cloud security (ZTNA, CASB, SWG, FWaaS, DLP) into a unified service delivered from the cloud. Formalised by Gartner in 2019. Designed for organisations whose users work from anywhere and whose applications are in the cloud. Key players: Palo Alto Prisma, Zscaler, Cisco, Cato Networks.

 

SDH ⚠

(Synchronous Digital Hierarchy): A standard for synchronous digital transmission over optical fibre (STM-1: 155 Mbps to STM-256: 40 Gbps). The successor to PDH in carrier networks. Now largely replaced by OTN (Optical Transport Network) and DWDM.

 

SD-WAN  /  Software-Defined Wide Area Network

(Software-Defined Wide Area Network): A WAN architecture that uses centralised software control to intelligently manage multiple heterogeneous WAN links (MPLS, Internet, 4G/5G) by selecting the best path in real time. Key players: Cisco Viptela, VMware VeloCloud, Fortinet, Cato Networks.

 

SLA  /  SERVICE LEVEL AGREEMENT

(Service Level Agreement): A contract setting out a service provider’s service quality commitments: guaranteed bandwidth, availability (uptime ≥ 99.9% or 99.99%), maximum latency, and recovery time (MTTR/RTO). Essential for business WAN access and cloud services.

 

SMB ★

(Server Message Block): A protocol for sharing files, printers and network resources on Windows (and Linux via Samba). SMB 3.1.1 (Windows 10/Server 2016) includes encryption of data in transit and performance improvements (multichannel, compression).

 

Simple Mail Transfer Protocol

(Simple Mail Transfer Protocol): A protocol for sending and transferring emails (port 25 between servers, 587 for clients). Used in conjunction with SPF, DKIM and DMARC for authentication. Modern connections use STARTTLS or SMTPS (port 465) for encryption.

 

SNMP

(Simple Network Management Protocol): A protocol for monitoring and managing network devices (routers, switches, servers) via UDP port 161 (requests) / 162 (traps). SNMPv3 adds authentication and encryption. Complemented by modern observability systems (Prometheus, Grafana, OpenTelemetry).

 

Junk mail

Unsolicited bulk emails. These may contain viruses or ransomware, or lead to phishing sites. Modern anti-spam filters combine heuristic analysis, IP/domain reputation, SPF/DKIM/DMARC and artificial intelligence.

 

SPF

(Sender Policy Framework): An email authentication standard that publishes a list of servers authorised to send emails on behalf of a domain in the DNS. It helps combat spoofing and spam. It should be used in conjunction with DKIM and DMARC for comprehensive protection.

 

SQL ★

(Structured Query Language): A standardised language for querying and manipulating relational databases (SELECT, INSERT, UPDATE, DELETE). Standardised by ISO. SQL injection (SQLi) is one of the main vulnerabilities in inadequately secured web applications.

 

SSH

(Secure Shell, RFC 4251): Secure remote access protocol (port 22). Strong encryption (AES, ChaCha20), public/private key authentication (RSA, Ed25519), integrity (HMAC). Fully replaces Telnet. Also supports file transfer (SFTP, SCP) and port tunnelling.

 

SSL ⚠

(Secure Sockets Layer): The predecessor to TLS, developed by Netscape. SSL 2.0 and 3.0 are obsolete and contain critical vulnerabilities (POODLE, DROWN). All deployments must use TLS 1.2 as a minimum, and TLS 1.3 is preferred.

 

STP / RSTP  /  Spanning Tree Protocol

(Spanning Tree Protocol IEEE 802.1D / Rapid STP 802.1w): A Layer 2 protocol that eliminates loops in redundant Ethernet networks by logically blocking certain ports. RSTP converges in less than a second, compared to several tens of seconds for standard STP. MSTP (802.1s) supports multiple instances per VLAN.

 

STREAMING ★

Real-time delivery of multimedia content (audio, video) over the internet, without the need for a full download beforehand. Protocols: HLS, DASH, RTMP. Video streaming accounts for around 65% of global internet traffic. CDNs deliver content from servers located close to the user to reduce latency.

 

— T —

 

TCP/IP

(Transmission Control Protocol / Internet Protocol): A suite of protocols that forms the basis of the Internet. IP (Layer 3) handles addressing and routing. TCP (Layer 4) ensures reliability through acknowledgements and congestion control. UDP provides connectionless transport for real-time applications.

 

CT  /  TIME-DIVISION MULTIPLEXING

(Time Division Multiplexing): A multiplexing technique that divides transmission time into time slots allocated to each channel. It forms the basis of the PDH/E1 hierarchy and the SONET/SDH standard used by incumbent telecommunications operators.

 

TELNET ⚠

A remote access protocol operating in terminal mode (port 23), which transmits all data in plain text, including passwords. It has been completely superseded by SSH for the administration of systems and network equipment. It is disabled by default on all modern devices.

 

TLS / TRANSPORT LAYER SECURITY

(Transport Layer Security): A cryptographic protocol that ensures the confidentiality (encryption), integrity (HMAC) and authentication (X.509 certificates) of internet communications. It is the successor to SSL. TLS 1.3 (RFC 8446, 2018) is the recommended version. Used in HTTPS, SMTPS, IMAPS, LDAPS and SSL VPNs.

 

TOKEN RING  /  TOKEN RING ⚠

A local area network technology developed by IBM operating at 4 or 16 Mbps, which uses a token circulating around the ring to control access. A long-standing competitor to Ethernet in the 1980s and 1990s. It has been completely replaced by Ethernet switches since the 2000s.

 

Traceroute

A network utility (Unix/Linux traceroute, Windows tracert) that displays the path taken by IP packets from source to destination, along with the latency at each hop (intermediate router). An essential diagnostic tool for identifying bottlenecks and network faults.

 

— U —

 

UDP ★

(User Datagram Protocol, RFC 768): A connectionless transport protocol that does not use acknowledgements and offers no guarantee of delivery or order. It is the preferred choice for real-time applications (VoIP, streaming, DNS, online gaming, DHCP) where low latency takes precedence over reliability. QUIC (HTTP/3) is based on UDP.

 

ITU-T  /  INTERNATIONAL TELECOMMUNICATION UNION

Standardisation sector of the ITU (a UN agency). Publishes ITU-T Recommendations defining international telecommunications standards (G.711 voice, G.703 E1, X.25, V.35). Successor to the CCITT since 1993.

 

URL ★

(Uniform Resource Locator): A unique address that identifies a resource on the Internet. Format: protocol://host:port/path?parameters (e.g. https://www.example.com/page?id=1). URLs use DNS to resolve hostnames into IP addresses.

 

— V —

 

VLAN / Virtual Local Area Network

(Virtual Local Area Network, IEEE 802.1Q): The logical division of a physical network into several independent virtual networks, defined by software configuration on the switches. This improves security (traffic isolation), reduces the broadcast domain and simplifies management without altering the physical cabling.

 

VPN  /  VIRTUAL PRIVATE NETWORK ★

(Virtual Private Network): An encrypted tunnel that creates a secure connection over a public network (the Internet). Types: IPsec (site-to-site, IKEv2), SSL/TLS VPN (remote access), WireGuard (modern, ChaCha20/Poly1305, Linux kernel 5.6+). Traditional VPN is gradually being replaced by ZTNA in SASE architectures.

 

— W —

 

WAN

(Wide Area Network): A computer network covering a large geographical area (national or international). WAN technologies: dedicated lines, carrier MPLS, SD-WAN over the internet, LEO satellite links (Starlink). Data rates: from a few Mbps (ADSL/satellite access) to several Tbps (carrier backbones).

 

WebRTC

(Web Real-Time Communication): JavaScript APIs that enable peer-to-peer communication directly within the browser (voice, video, data transfer), without the need for plugins. Based on UDP/SRTP/DTLS. Used by Google Meet, Discord and web-based video conferencing platforms.

 

Wi-Fi 6 / 6E

(IEEE 802.11ax): Sixth generation of Wi-Fi (2019/2021). Innovations: OFDMA, 8×8 MU-MIMO, BSS Coloring, TWT (IoT). Wi-Fi 6E extends the standard to the 6 GHz band (160 MHz channels without interference). Maximum theoretical data rate: 9.6 Gbps.

 

Wi-Fi 7

(IEEE 802.11be — EHT): Seventh generation of Wi-Fi, finalised in 2024. Major innovation: MLO (Multi-Link Operation) — simultaneous use of the 2.4, 5 and 6 GHz bands. 320 MHz channels, 4096-QAM modulation. Maximum theoretical data rate: 46 Gbps.

 

WWW  /  WORLD WIDE WEB ★

(World Wide Web): A hypertext information system operating on the Internet, invented by Tim Berners-Lee at CERN in 1991. It is based on HTML, HTTP and URLs. There are over a billion active websites. The distinction between the ‘Internet’ (the infrastructure) and ‘the Web’ (one service among many operating on the Internet) is fundamental.

 

— X —

 

XGSPON

(10 Gigabit-capable Symmetric PON, ITU-T G.9807): An evolution of GPON offering symmetrical 10 Gbps speeds (upstream and downstream) over the same fibre. Deployed by French operators for new FTTH installations since 2022, enabling multi-gigabit commercial services.

 

XML ★

(Extensible Markup Language): A structured markup language developed by the W3C to define interoperable and customisable data formats. Used in data exchange (SOAP, NETCONF/YANG, configuration files). Competes with JSON for modern REST APIs.

 

— Z —

 

ZERO TRUST  /  ZERO TRUST

A network security model that moves away from the implicit trust perimeter (“everything within the corporate network is secure”) in favour of the “never trust, always verify” principle. Every user and device is authenticated and authorised for each access attempt. Implemented via ZTNA, enhanced MFA and microsegmentation.

 

ZTNA  /  ZERO-TRUST NETWORK ACCESS

(Zero Trust Network Access): A SASE component that replaces the traditional VPN. Every attempt to access an application is verified individually based on identity (MFA), the device’s security posture (MDM) and context. Principle of least privilege: users are granted access only to the resources they need, never to the entire network.

 

KEY ABBREVIATIONS — REFERENCE GUIDE

 

ℹ Core protocols

TCP/IP · UDP · IP v4/v6 · HTTP/2/3 · TLS 1.3 · DNS · DHCP · ARP · OSPF · BGP · MPLS · SSH · SMTP · IMAP · FTP/SFTP

 

 

ℹ Safety

ZTNA · SASE · TLS · PQC · QKD · SPF · DKIM · DMARC · CASB · SWG · Firewall / NGFW · Ransomware · Phishing · Zero Trust

 

 

ℹ LAN and access

Ethernet · VLAN (802.1Q) · STP/RSTP · LACP · PoE/PoE+ · Wi-Fi 6/6E · Wi-Fi 7 · LLC · MAC

 

 

ℹ WAN and cloud

WAN · SD-WAN · MPLS · VPN · FTTH · GPON · XGS-PON · CDN · Edge Computing · MEC · Container · Kubernetes

 

 

ℹ AI, automation and trends

AIOps · IBN · 5G · eBPF · RGPD · SLA · WebRTC · Zero Trust

 

 

ℹ Standards bodies

IEEE · IETF · ANSI · ETSI · ITU-T · IAB · CERT / ANSSI

 

134

Modifié le: vendredi 9 octobre 2026, 10:09