<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Networking on IT Comparison</title><link>https://comparison.metacog.co.kr/tags/networking/</link><description>Recent content in Networking on IT Comparison</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 06 Sep 2026 10:02:10 +0900</lastBuildDate><atom:link href="https://comparison.metacog.co.kr/tags/networking/index.xml" rel="self" type="application/rss+xml"/><item><title>Push vs Pull: Who Initiates the Data Transfer</title><link>https://comparison.metacog.co.kr/posts/2026-09-06-push-vs-pull-who-initiates-the-data-transfer/</link><pubDate>Sun, 06 Sep 2026 10:02:10 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-09-06-push-vs-pull-who-initiates-the-data-transfer/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;Push and pull describe which side initiates a data transfer between two systems: in a &lt;strong class="kw"&gt;push&lt;/strong&gt; model the source sends data as soon as it&amp;rsquo;s ready, while in a &lt;strong class="kw"&gt;pull&lt;/strong&gt; model the consumer requests data on its own schedule. The choice shapes latency, backpressure handling, and how tightly the two sides are coupled in time.&lt;/p&gt;
&lt;h2 id="comparison-diagram"&gt;Comparison Diagram&lt;/h2&gt;
&lt;div class="compare-diagram"&gt;
&lt;svg viewBox="0 0 640 360" xmlns="http://www.w3.org/2000/svg"&gt;&lt;text x="160" y="36" text-anchor="middle" font-size="18" style="fill:var(--primary)"&gt;Push&lt;/text&gt;&lt;text x="480" y="36" text-anchor="middle" font-size="18" style="fill:var(--primary)"&gt;Pull&lt;/text&gt;&lt;rect x="60" y="70" width="110" height="56" rx="6" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="115" y="103" text-anchor="middle" font-size="13" style="fill:var(--content)"&gt;Source&lt;/text&gt;&lt;rect x="60" y="200" width="110" height="56" rx="6" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="115" y="233" text-anchor="middle" font-size="13" style="fill:var(--content)"&gt;Consumer&lt;/text&gt;&lt;line x1="115" y1="126" x2="115" y2="200" style="stroke:var(--compare-a)" stroke-width="2" marker-end="url(#arrowA)"/&gt;&lt;text x="140" y="165" font-size="11" style="fill:var(--secondary)"&gt;sends data&lt;/text&gt;&lt;text x="140" y="178" font-size="11" style="fill:var(--secondary)"&gt;when ready&lt;/text&gt;&lt;circle cx="115" cy="85" r="4" style="fill:var(--compare-a)"/&gt;&lt;rect x="380" y="70" width="110" height="56" rx="6" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="435" y="103" text-anchor="middle" font-size="13" style="fill:var(--content)"&gt;Source&lt;/text&gt;&lt;rect x="380" y="200" width="110" height="56" rx="6" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="435" y="233" text-anchor="middle" font-size="13" style="fill:var(--content)"&gt;Consumer&lt;/text&gt;&lt;line x1="435" y1="200" x2="435" y2="126" style="stroke:var(--compare-b)" stroke-width="2" marker-end="url(#arrowB)"/&gt;&lt;text x="460" y="165" font-size="11" style="fill:var(--secondary)"&gt;requests data&lt;/text&gt;&lt;text x="460" y="178" font-size="11" style="fill:var(--secondary)"&gt;on its schedule&lt;/text&gt;&lt;line x1="120" y1="126" x2="120" y2="126" style="stroke:var(--border)"/&gt;&lt;text x="115" y="280" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;Source controls timing&lt;/text&gt;&lt;text x="435" y="280" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;Consumer controls timing&lt;/text&gt;&lt;defs&gt;&lt;marker id="arrowA" markerWidth="8" markerHeight="8" refX="4" refY="4" orient="auto"&gt;&lt;path d="M0,0 L8,4 L0,8 Z" style="fill:var(--compare-a)"/&gt;&lt;/marker&gt;&lt;marker id="arrowB" markerWidth="8" markerHeight="8" refX="4" refY="4" orient="auto"&gt;&lt;path d="M0,0 L8,4 L0,8 Z" style="fill:var(--compare-b)"/&gt;&lt;/marker&gt;&lt;/defs&gt;&lt;/svg&gt;
&lt;/div&gt;
&lt;h2 id="comparison-table"&gt;Comparison Table&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Aspect&lt;/th&gt;
&lt;th&gt;Push&lt;/th&gt;
&lt;th&gt;Pull&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Initiator&lt;/td&gt;
&lt;td&gt;Source system triggers the transfer&lt;/td&gt;
&lt;td&gt;Consumer system triggers the transfer&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Timing control&lt;/td&gt;
&lt;td&gt;Source decides when data is sent&lt;/td&gt;
&lt;td&gt;Consumer decides when to fetch&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Latency to consumer&lt;/td&gt;
&lt;td&gt;Near-immediate once source has data&lt;/td&gt;
&lt;td&gt;Bounded by polling interval, not source readiness&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Backpressure handling&lt;/td&gt;
&lt;td&gt;Source must slow down or buffer if consumer is overwhelmed&lt;/td&gt;
&lt;td&gt;Consumer naturally paces itself by requesting only when ready&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Coupling&lt;/td&gt;
&lt;td&gt;Source needs to know consumer&amp;rsquo;s address/endpoint&lt;/td&gt;
&lt;td&gt;Consumer needs to know source&amp;rsquo;s address/endpoint&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Resource cost when idle&lt;/td&gt;
&lt;td&gt;No wasted work; nothing sent if no updates&lt;/td&gt;
&lt;td&gt;Repeated requests even when nothing changed&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Failure handling&lt;/td&gt;
&lt;td&gt;Source retries or queues if delivery fails&lt;/td&gt;
&lt;td&gt;Consumer retries the pull on its own next cycle&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Typical mechanisms&lt;/td&gt;
&lt;td&gt;Webhooks, pub/sub, server-sent events&lt;/td&gt;
&lt;td&gt;Polling, cron jobs, request/response APIs&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="key-differences"&gt;Key Differences&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong class="kw"&gt;Push&lt;/strong&gt; minimizes latency by sending data the instant it&amp;rsquo;s available, while &lt;strong class="kw"&gt;pull&lt;/strong&gt; bounds latency to the polling interval.&lt;/li&gt;
&lt;li&gt;Pull gives the consumer natural &lt;strong class="kw"&gt;backpressure&lt;/strong&gt; control since it only asks for data when ready to process it.&lt;/li&gt;
&lt;li&gt;Push requires the source to hold a reference to every consumer&amp;rsquo;s endpoint, increasing &lt;strong class="kw"&gt;fan-out coupling&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Pull wastes resources on &lt;strong class="kw"&gt;empty polls&lt;/strong&gt; when there&amp;rsquo;s nothing new to fetch.&lt;/li&gt;
&lt;li&gt;Push systems need retry or queueing logic on the sender side; pull systems just retry the request on the next cycle.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="when-to-use-each"&gt;When to Use Each&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Push&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>Stateful vs Stateless: Where the Session Lives</title><link>https://comparison.metacog.co.kr/posts/2026-09-06-stateful-vs-stateless-where-the-session-lives/</link><pubDate>Sun, 06 Sep 2026 09:51:46 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-09-06-stateful-vs-stateless-where-the-session-lives/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;This comparison covers whether a server or protocol retains &lt;strong class="kw"&gt;session state&lt;/strong&gt; between requests, or treats every request as a fully &lt;strong class="kw"&gt;self-contained&lt;/strong&gt; unit with no memory of prior ones. The choice determines how you scale, fail over, and route traffic across instances.&lt;/p&gt;
&lt;h2 id="comparison-diagram"&gt;Comparison Diagram&lt;/h2&gt;
&lt;div class="compare-diagram"&gt;
&lt;svg viewBox="0 0 640 360" xmlns="http://www.w3.org/2000/svg"&gt;&lt;text x="160" y="32" text-anchor="middle" font-size="16" style="fill:var(--primary)"&gt;Stateful&lt;/text&gt;&lt;text x="480" y="32" text-anchor="middle" font-size="16" style="fill:var(--primary)"&gt;Stateless&lt;/text&gt;&lt;rect x="40" y="60" width="110" height="50" rx="6" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="95" y="90" text-anchor="middle" font-size="13" style="fill:var(--content)"&gt;Client&lt;/text&gt;&lt;path d="M150 85 L230 85" style="stroke:var(--compare-a)" stroke-width="1.5" marker-end="url(#arrowA)"/&gt;&lt;rect x="230" y="60" width="120" height="50" rx="6" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="290" y="84" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Server A&lt;/text&gt;&lt;text x="290" y="100" text-anchor="middle" font-size="10" style="fill:var(--secondary)"&gt;session: id=42&lt;/text&gt;&lt;path d="M290 110 L290 150" style="stroke:var(--border)" stroke-width="1.5" stroke-dasharray="4,3" marker-end="url(#arrowN)"/&gt;&lt;text x="330" y="135" font-size="10" style="fill:var(--secondary)"&gt;must return&lt;/text&gt;&lt;text x="330" y="148" font-size="10" style="fill:var(--secondary)"&gt;to same server&lt;/text&gt;&lt;rect x="230" y="160" width="120" height="50" rx="6" style="fill:none;stroke:var(--border)" stroke-width="1.5" stroke-dasharray="4,3"/&gt;&lt;text x="290" y="189" text-anchor="middle" font-size="12" style="fill:var(--secondary)"&gt;Server B&lt;/text&gt;&lt;text x="290" y="204" text-anchor="middle" font-size="10" style="fill:var(--secondary)"&gt;no session data&lt;/text&gt;&lt;path d="M95 110 L95 200 L230 200" style="stroke:var(--compare-a)" stroke-width="1.5" fill="none" marker-end="url(#arrowA)"/&gt;&lt;line x1="20" y1="260" x2="620" y2="260" style="stroke:var(--border)" stroke-width="1"/&gt;&lt;rect x="360" y="60" width="110" height="50" rx="6" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="415" y="90" text-anchor="middle" font-size="13" style="fill:var(--content)"&gt;Client&lt;/text&gt;&lt;text x="415" y="106" text-anchor="middle" font-size="9" style="fill:var(--secondary)"&gt;carries token&lt;/text&gt;&lt;path d="M470 85 L540 85" style="stroke:var(--compare-b)" stroke-width="1.5" marker-end="url(#arrowB)"/&gt;&lt;rect x="540 " y="60" width="70" height="50" rx="6" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="575" y="90" text-anchor="middle" font-size="11" style="fill:var(--content)"&gt;Server&lt;/text&gt;&lt;path d="M470 85 L540 160" style="stroke:var(--compare-b)" stroke-width="1.5" fill="none" marker-end="url(#arrowB)"/&gt;&lt;rect x="540" y="150" width="70" height="50" rx="6" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="575" y="180" text-anchor="middle" font-size="11" style="fill:var(--content)"&gt;Server&lt;/text&gt;&lt;text x="415" y="200" font-size="10" style="fill:var(--secondary)"&gt;any server can&lt;/text&gt;&lt;text x="415" y="213" font-size="10" style="fill:var(--secondary)"&gt;handle the request&lt;/text&gt;&lt;text x="320" y="300" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Stateful: server pins session context and routing depends on it&lt;/text&gt;&lt;text x="320" y="325" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Stateless: request carries all context, any node can serve it&lt;/text&gt;&lt;defs&gt;&lt;marker id="arrowA" markerWidth="8" markerHeight="8" refX="6" refY="4" orient="auto"&gt;&lt;path d="M0,0 L8,4 L0,8 z" style="fill:var(--compare-a)"/&gt;&lt;/marker&gt;&lt;marker id="arrowB" markerWidth="8" markerHeight="8" refX="6" refY="4" orient="auto"&gt;&lt;path d="M0,0 L8,4 L0,8 z" style="fill:var(--compare-b)"/&gt;&lt;/marker&gt;&lt;marker id="arrowN" markerWidth="8" markerHeight="8" refX="6" refY="4" orient="auto"&gt;&lt;path d="M0,0 L8,4 L0,8 z" style="fill:var(--border)"/&gt;&lt;/marker&gt;&lt;/defs&gt;&lt;/svg&gt;
&lt;/div&gt;
&lt;h2 id="comparison-table"&gt;Comparison Table&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Aspect&lt;/th&gt;
&lt;th&gt;Stateful&lt;/th&gt;
&lt;th&gt;Stateless&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Request context&lt;/td&gt;
&lt;td&gt;Server retains prior interaction data across requests&lt;/td&gt;
&lt;td&gt;Each request carries all context needed to process it&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Session storage&lt;/td&gt;
&lt;td&gt;Held in server memory or local session store&lt;/td&gt;
&lt;td&gt;None on server; state lives in client token or database&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Routing requirement&lt;/td&gt;
&lt;td&gt;Requests must reach the same server (sticky sessions)&lt;/td&gt;
&lt;td&gt;Any server instance can handle any request&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Scaling model&lt;/td&gt;
&lt;td&gt;Vertical or sticky-session horizontal scaling only&lt;/td&gt;
&lt;td&gt;Trivial horizontal scaling, load balance freely&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Failure recovery&lt;/td&gt;
&lt;td&gt;Server crash loses in-memory session unless replicated&lt;/td&gt;
&lt;td&gt;Server crash has no session impact, retry hits any node&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Client design&lt;/td&gt;
&lt;td&gt;Client can be thin, server tracks progress&lt;/td&gt;
&lt;td&gt;Client or token must resend full context each call&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Typical examples&lt;/td&gt;
&lt;td&gt;Database connections, WebSocket sessions, FTP&lt;/td&gt;
&lt;td&gt;REST APIs, HTTP with JWT, DNS lookups&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="key-differences"&gt;Key Differences&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Stateful servers keep &lt;strong class="kw"&gt;session memory&lt;/strong&gt;; stateless servers keep none between calls&lt;/li&gt;
&lt;li&gt;Stateless systems need &lt;strong class="kw"&gt;no sticky routing&lt;/strong&gt;, simplifying load balancers&lt;/li&gt;
&lt;li&gt;Stateful failover requires &lt;strong class="kw"&gt;session replication&lt;/strong&gt; to avoid data loss&lt;/li&gt;
&lt;li&gt;Stateless designs push state into the &lt;strong class="kw"&gt;client or token&lt;/strong&gt; instead of the server&lt;/li&gt;
&lt;li&gt;Horizontal scaling is &lt;strong class="kw"&gt;near-free&lt;/strong&gt; for stateless architectures&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="when-to-use-each"&gt;When to Use Each&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Stateful&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>Latency vs Throughput: Response Time vs Processing Volume</title><link>https://comparison.metacog.co.kr/posts/2026-09-06-latency-vs-throughput-response-time-vs-processing-volume/</link><pubDate>Sun, 06 Sep 2026 09:34:39 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-09-06-latency-vs-throughput-response-time-vs-processing-volume/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;Latency and throughput are two orthogonal measures of system performance: &lt;strong class="kw"&gt;latency&lt;/strong&gt; is the time a single request takes to complete, while &lt;strong class="kw"&gt;throughput&lt;/strong&gt; is the volume of work a system finishes per unit of time. The distinction matters because architectures optimized for one can quietly degrade the other.&lt;/p&gt;
&lt;h2 id="comparison-diagram"&gt;Comparison Diagram&lt;/h2&gt;
&lt;div class="compare-diagram"&gt;
&lt;svg viewBox="0 0 640 360" xmlns="http://www.w3.org/2000/svg"&gt;
&lt;text x="320" y="28" text-anchor="middle" font-size="20" font-weight="bold" style="fill:var(--primary)"&gt;Latency&lt;/text&gt;
&lt;rect x="40" y="50" width="60" height="40" rx="4" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;
&lt;text x="70" y="75" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Client&lt;/text&gt;
&lt;rect x="540" y="50" width="60" height="40" rx="4" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;
&lt;text x="570" y="75" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Server&lt;/text&gt;
&lt;line x1="100" y1="70" x2="540" y2="70" style="stroke:var(--border)" stroke-width="2" stroke-dasharray="4 4"/&gt;
&lt;circle cx="320" cy="70" r="9" style="fill:var(--compare-a);stroke:var(--compare-a)"/&gt;
&lt;path d="M330,64 L342,70 L330,76 Z" style="fill:var(--compare-a)"/&gt;
&lt;line x1="100" y1="120" x2="540" y2="120" style="stroke:var(--compare-a)" stroke-width="1.5"/&gt;
&lt;line x1="100" y1="113" x2="100" y2="127" style="stroke:var(--compare-a)" stroke-width="1.5"/&gt;
&lt;line x1="540" y1="113" x2="540" y2="127" style="stroke:var(--compare-a)" stroke-width="1.5"/&gt;
&lt;path d="M100,120 L108,116 L108,124 Z" style="fill:var(--compare-a)"/&gt;
&lt;path d="M540,120 L532,116 L532,124 Z" style="fill:var(--compare-a)"/&gt;
&lt;text x="320" y="145" text-anchor="middle" font-size="13" style="fill:var(--secondary)"&gt;Time for ONE request to complete&lt;/text&gt;
&lt;line x1="20" y1="180" x2="620" y2="180" style="stroke:var(--border)" stroke-width="1" stroke-dasharray="2 4"/&gt;
&lt;text x="320" y="208" text-anchor="middle" font-size="20" font-weight="bold" style="fill:var(--primary)"&gt;Throughput&lt;/text&gt;
&lt;rect x="40" y="225" width="60" height="40" rx="4" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;
&lt;text x="70" y="250" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Client&lt;/text&gt;
&lt;rect x="540" y="225" width="60" height="40" rx="4" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;
&lt;text x="570" y="250" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Server&lt;/text&gt;
&lt;rect x="100" y="235" width="440" height="20" rx="10" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;
&lt;circle cx="140" cy="245" r="6" style="fill:var(--compare-b);stroke:var(--compare-b)"/&gt;
&lt;circle cx="200" cy="245" r="6" style="fill:var(--compare-b);stroke:var(--compare-b)"/&gt;
&lt;circle cx="260" cy="245" r="6" style="fill:var(--compare-b);stroke:var(--compare-b)"/&gt;
&lt;circle cx="320" cy="245" r="6" style="fill:var(--compare-b);stroke:var(--compare-b)"/&gt;
&lt;circle cx="380" cy="245" r="6" style="fill:var(--compare-b);stroke:var(--compare-b)"/&gt;
&lt;circle cx="440" cy="245" r="6" style="fill:var(--compare-b);stroke:var(--compare-b)"/&gt;
&lt;circle cx="500" cy="245" r="6" style="fill:var(--compare-b);stroke:var(--compare-b)"/&gt;
&lt;path d="M545,245 L557,239 L557,251 Z" style="fill:var(--compare-b)"/&gt;
&lt;text x="320" y="300" text-anchor="middle" font-size="13" style="fill:var(--secondary)"&gt;Total requests completed per second&lt;/text&gt;
&lt;/svg&gt;
&lt;/div&gt;
&lt;h2 id="comparison-table"&gt;Comparison Table&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Aspect&lt;/th&gt;
&lt;th&gt;Latency&lt;/th&gt;
&lt;th&gt;Throughput&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Definition&lt;/td&gt;
&lt;td&gt;Time elapsed for one request to travel and complete&lt;/td&gt;
&lt;td&gt;Amount of work completed across all requests per unit time&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;What is measured&lt;/td&gt;
&lt;td&gt;A single request&amp;rsquo;s round trip or processing delay&lt;/td&gt;
&lt;td&gt;Aggregate output of the system over an observation window&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Unit of measurement&lt;/td&gt;
&lt;td&gt;Milliseconds, microseconds, or seconds&lt;/td&gt;
&lt;td&gt;Requests/sec, transactions/sec, or Mbps&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Primary driver&lt;/td&gt;
&lt;td&gt;Network round-trip time, serialization, and processing delay&lt;/td&gt;
&lt;td&gt;Available bandwidth, parallel capacity, and resource pool size&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Effect of concurrency&lt;/td&gt;
&lt;td&gt;Individual request latency can rise as queueing builds up&lt;/td&gt;
&lt;td&gt;Throughput rises with more parallel workers, up to a capacity limit&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Behavior under overload&lt;/td&gt;
&lt;td&gt;Tail latency spikes as queues grow (p95/p99 degrade)&lt;/td&gt;
&lt;td&gt;Throughput plateaus or drops once the system saturates&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Typical optimization&lt;/td&gt;
&lt;td&gt;Reduce round trips, cache results, shorten the critical path&lt;/td&gt;
&lt;td&gt;Batch requests, add parallel workers, scale out capacity&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Measurement method&lt;/td&gt;
&lt;td&gt;Ping, request timers, percentile latency (p50/p95/p99)&lt;/td&gt;
&lt;td&gt;Requests-per-second counters, load testing, capacity benchmarks&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="key-differences"&gt;Key Differences&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Latency measures the &lt;strong class="kw"&gt;time&lt;/strong&gt; for one request; throughput measures the &lt;strong class="kw"&gt;volume&lt;/strong&gt; processed per unit time.&lt;/li&gt;
&lt;li&gt;Batching to raise throughput can increase &lt;strong class="kw"&gt;tail latency&lt;/strong&gt; for individual requests.&lt;/li&gt;
&lt;li&gt;Latency is bounded by physical &lt;strong class="kw"&gt;round-trip time&lt;/strong&gt;; throughput is bounded by system &lt;strong class="kw"&gt;capacity&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Under heavy load, latency &lt;strong class="kw"&gt;spikes&lt;/strong&gt; from queueing while throughput &lt;strong class="kw"&gt;plateaus&lt;/strong&gt; at a ceiling.&lt;/li&gt;
&lt;li&gt;&lt;strong class="kw"&gt;Little&amp;rsquo;s Law&lt;/strong&gt; links the two: average latency times concurrency roughly equals throughput.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="when-to-use-each"&gt;When to Use Each&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Latency&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>Client-Server vs Peer-to-Peer: Network Architecture Compared</title><link>https://comparison.metacog.co.kr/posts/2026-08-04-client-server-vs-peer-to-peer-network-architecture-compared/</link><pubDate>Tue, 04 Aug 2026 05:15:26 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-08-04-client-server-vs-peer-to-peer-network-architecture-compared/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;Client-Server and peer-to-peer describe who talks to whom on a network: one funnels every request through a &lt;strong class="kw"&gt;central server&lt;/strong&gt;, the other lets nodes exchange data directly as &lt;strong class="kw"&gt;equal peers&lt;/strong&gt;. The choice shapes scalability, fault tolerance, and who ultimately controls the data.&lt;/p&gt;
&lt;h2 id="comparison-diagram"&gt;Comparison Diagram&lt;/h2&gt;
&lt;div class="compare-diagram"&gt;
&lt;svg viewBox="0 0 640 360" xmlns="http://www.w3.org/2000/svg"&gt;&lt;text x="160" y="30" text-anchor="middle" font-size="16" style="fill:var(--primary)"&gt;Client-Server&lt;/text&gt;&lt;text x="480" y="30" text-anchor="middle" font-size="16" style="fill:var(--primary)"&gt;Peer-to-Peer&lt;/text&gt;&lt;line x1="320" y1="50" x2="320" y2="340" style="stroke:var(--border)" stroke-width="1" stroke-dasharray="4,4"/&gt;&lt;rect x="130" y="70" width="100" height="40" rx="6" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="180" y="95" text-anchor="middle" font-size="13" style="fill:var(--content)"&gt;Server&lt;/text&gt;&lt;line x1="180" y1="110" x2="70" y2="240" style="stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;line x1="180" y1="110" x2="180" y2="280" style="stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;line x1="180" y1="110" x2="290" y2="240" style="stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;circle cx="70" cy="255" r="22" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;circle cx="180" cy="295" r="22" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;circle cx="290" cy="255" r="22" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="70" y="259" text-anchor="middle" font-size="11" style="fill:var(--content)"&gt;C&lt;/text&gt;&lt;text x="180" y="299" text-anchor="middle" font-size="11" style="fill:var(--content)"&gt;C&lt;/text&gt;&lt;text x="290" y="259" text-anchor="middle" font-size="11" style="fill:var(--content)"&gt;C&lt;/text&gt;&lt;text x="180" y="330" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;All requests routed through server&lt;/text&gt;&lt;g style="stroke:var(--compare-b)" stroke-width="1" opacity="0.55"&gt;&lt;line x1="480" y1="90" x2="575" y2="159"/&gt;&lt;line x1="480" y1="90" x2="539" y2="271"/&gt;&lt;line x1="480" y1="90" x2="421" y2="271"/&gt;&lt;line x1="480" y1="90" x2="385" y2="159"/&gt;&lt;line x1="575" y1="159" x2="539" y2="271"/&gt;&lt;line x1="575" y1="159" x2="421" y2="271"/&gt;&lt;line x1="575" y1="159" x2="385" y2="159"/&gt;&lt;line x1="539" y1="271" x2="421" y2="271"/&gt;&lt;line x1="539" y1="271" x2="385" y2="159"/&gt;&lt;line x1="421" y1="271" x2="385" y2="159"/&gt;&lt;/g&gt;&lt;circle cx="480" cy="90" r="20" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;circle cx="575" cy="159" r="20" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;circle cx="539" cy="271" r="20" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;circle cx="421" cy="271" r="20" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;circle cx="385" cy="159" r="20" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="480" y="94" text-anchor="middle" font-size="11" style="fill:var(--content)"&gt;P&lt;/text&gt;&lt;text x="575" y="163" text-anchor="middle" font-size="11" style="fill:var(--content)"&gt;P&lt;/text&gt;&lt;text x="539" y="275" text-anchor="middle" font-size="11" style="fill:var(--content)"&gt;P&lt;/text&gt;&lt;text x="421" y="275" text-anchor="middle" font-size="11" style="fill:var(--content)"&gt;P&lt;/text&gt;&lt;text x="385" y="163" text-anchor="middle" font-size="11" style="fill:var(--content)"&gt;P&lt;/text&gt;&lt;text x="480" y="330" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;Peers connect directly to each other&lt;/text&gt;&lt;/svg&gt;
&lt;/div&gt;
&lt;h2 id="comparison-table"&gt;Comparison Table&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Aspect&lt;/th&gt;
&lt;th&gt;Client-Server&lt;/th&gt;
&lt;th&gt;Peer-to-Peer&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Node roles&lt;/td&gt;
&lt;td&gt;Clients and servers have fixed, asymmetric roles&lt;/td&gt;
&lt;td&gt;Every node acts as both client and server (servent)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Connection establishment&lt;/td&gt;
&lt;td&gt;Clients connect to a known server address (DNS/IP)&lt;/td&gt;
&lt;td&gt;Nodes discover peers via bootstrap lists, DHTs, or trackers&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Request handling&lt;/td&gt;
&lt;td&gt;Server processes and responds to each client request&lt;/td&gt;
&lt;td&gt;Any peer can serve or request data from any other peer&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Resource provisioning&lt;/td&gt;
&lt;td&gt;Server owns the compute, storage, and bandwidth&lt;/td&gt;
&lt;td&gt;Resources are contributed and shared across participating peers&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Scalability pattern&lt;/td&gt;
&lt;td&gt;Scaling requires adding server capacity or replicas&lt;/td&gt;
&lt;td&gt;Scaling often improves as more peers join and share load&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Fault tolerance&lt;/td&gt;
&lt;td&gt;Server outage disrupts all clients (single point of failure)&lt;/td&gt;
&lt;td&gt;Network tolerates individual peer failures; no single point of failure&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Security &amp;amp; trust&lt;/td&gt;
&lt;td&gt;Trust is centralized; server enforces auth and access control&lt;/td&gt;
&lt;td&gt;Trust is distributed; peers must verify each other independently&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Typical examples&lt;/td&gt;
&lt;td&gt;Web apps, REST APIs, email, banking systems&lt;/td&gt;
&lt;td&gt;BitTorrent, blockchain networks, LAN gaming&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="key-differences"&gt;Key Differences&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Client-Server relies on a &lt;strong class="kw"&gt;central server&lt;/strong&gt; as the single source of truth; peer-to-peer distributes data with no authoritative hub.&lt;/li&gt;
&lt;li&gt;Adding capacity in client-server means scaling the &lt;strong class="kw"&gt;server tier&lt;/strong&gt;; in peer-to-peer, each new node can add capacity to the network.&lt;/li&gt;
&lt;li&gt;A server outage is a &lt;strong class="kw"&gt;single point of failure&lt;/strong&gt; for client-server, while peer-to-peer degrades gracefully as peers leave.&lt;/li&gt;
&lt;li&gt;Client-server centralizes &lt;strong class="kw"&gt;access control&lt;/strong&gt;, while peer-to-peer pushes trust and verification onto each peer.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="when-to-use-each"&gt;When to Use Each&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Client-Server&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>Load Balancer vs Reverse Proxy: Traffic Distribution vs Request Mediation</title><link>https://comparison.metacog.co.kr/posts/2026-08-03-load-balancer-vs-reverse-proxy-traffic-distribution-vs-reque/</link><pubDate>Mon, 03 Aug 2026 06:30:57 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-08-03-load-balancer-vs-reverse-proxy-traffic-distribution-vs-reque/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;A &lt;strong class="kw"&gt;load balancer&lt;/strong&gt; spreads incoming traffic across many identical backend servers so no single machine gets overwhelmed, while a &lt;strong class="kw"&gt;reverse proxy&lt;/strong&gt; sits in front of one or more servers to mediate, secure, and transform requests on their behalf. The two overlap heavily in practice — most modern reverse proxies (NGINX, Envoy, HAProxy) can also load balance — but the distinction matters when you&amp;rsquo;re deciding which capability you actually need to configure or scale for.&lt;/p&gt;</description></item><item><title>NAT Gateway vs Internet Gateway: Who Gets to Talk to the Internet</title><link>https://comparison.metacog.co.kr/posts/2026-08-03-nat-gateway-vs-internet-gateway-who-gets-to-talk-to-the-inte/</link><pubDate>Mon, 03 Aug 2026 06:27:51 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-08-03-nat-gateway-vs-internet-gateway-who-gets-to-talk-to-the-inte/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;Both connect a VPC to the internet, but they serve opposite purposes: an &lt;strong class="kw"&gt;Internet Gateway&lt;/strong&gt; lets public-facing resources send and receive traffic directly, while a &lt;strong class="kw"&gt;NAT Gateway&lt;/strong&gt; lets private resources reach out without ever being reachable from outside. Picking the wrong one either exposes resources you meant to keep private or silently blocks the outbound access your servers need.&lt;/p&gt;
&lt;h2 id="comparison-diagram"&gt;Comparison Diagram&lt;/h2&gt;
&lt;div class="compare-diagram"&gt;
&lt;svg viewBox="0 0 640 360" xmlns="http://www.w3.org/2000/svg"&gt;&lt;defs&gt;&lt;marker id="arrowA" viewBox="0 0 10 10" refX="5" refY="5" markerWidth="6" markerHeight="6" orient="auto-start-reverse"&gt;&lt;path d="M0,0 L10,5 L0,10 Z" style="fill:var(--compare-a)"/&gt;&lt;/marker&gt;&lt;marker id="arrowB" viewBox="0 0 10 10" refX="5" refY="5" markerWidth="6" markerHeight="6" orient="auto-start-reverse"&gt;&lt;path d="M0,0 L10,5 L0,10 Z" style="fill:var(--compare-b)"/&gt;&lt;/marker&gt;&lt;/defs&gt;&lt;line x1="320" y1="20" x2="320" y2="340" style="stroke:var(--border)" stroke-width="1" stroke-dasharray="4 4"/&gt;&lt;text x="160" y="25" text-anchor="middle" font-size="16" font-weight="bold" style="fill:var(--primary)"&gt;Internet Gateway&lt;/text&gt;&lt;text x="480" y="25" text-anchor="middle" font-size="16" font-weight="bold" style="fill:var(--primary)"&gt;NAT Gateway&lt;/text&gt;&lt;rect x="110" y="45" width="100" height="36" rx="18" style="fill:none;stroke:var(--border)" stroke-width="1.5"/&gt;&lt;text x="160" y="68" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Internet&lt;/text&gt;&lt;rect x="430" y="45" width="100" height="36" rx="18" style="fill:none;stroke:var(--border)" stroke-width="1.5"/&gt;&lt;text x="480" y="68" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Internet&lt;/text&gt;&lt;line x1="160" y1="82" x2="160" y2="109" style="stroke:var(--compare-a)" stroke-width="2" marker-start="url(#arrowA)" marker-end="url(#arrowA)"/&gt;&lt;line x1="480" y1="110" x2="480" y2="82" style="stroke:var(--compare-b)" stroke-width="2" marker-end="url(#arrowB)"/&gt;&lt;circle cx="560" cy="95" r="10" style="fill:none;stroke:var(--secondary)" stroke-width="1.5"/&gt;&lt;line x1="553" y1="88" x2="567" y2="102" style="stroke:var(--secondary)" stroke-width="1.5"/&gt;&lt;text x="560" y="120" text-anchor="middle" font-size="9" style="fill:var(--secondary)"&gt;no inbound&lt;/text&gt;&lt;rect x="110" y="110" width="100" height="40" rx="6" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="160" y="134" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;IGW&lt;/text&gt;&lt;rect x="430" y="110" width="100" height="40" rx="6" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="480" y="134" text-anchor="middle" font-size="11" style="fill:var(--content)"&gt;NAT Gateway&lt;/text&gt;&lt;line x1="160" y1="150" x2="160" y2="189" style="stroke:var(--compare-a)" stroke-width="2" marker-start="url(#arrowA)" marker-end="url(#arrowA)"/&gt;&lt;line x1="480" y1="190" x2="480" y2="151" style="stroke:var(--compare-b)" stroke-width="2" marker-end="url(#arrowB)"/&gt;&lt;rect x="70" y="190" width="180" height="120" rx="8" style="fill:none;stroke:var(--border)" stroke-width="1.5" stroke-dasharray="4 3"/&gt;&lt;text x="160" y="206" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;Public Subnet&lt;/text&gt;&lt;rect x="110" y="228" width="100" height="40" rx="6" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="160" y="252" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Instance&lt;/text&gt;&lt;text x="160" y="285" text-anchor="middle" font-size="10" style="fill:var(--secondary)"&gt;has public IP&lt;/text&gt;&lt;rect x="390" y="190" width="180" height="120" rx="8" style="fill:none;stroke:var(--border)" stroke-width="1.5" stroke-dasharray="4 3"/&gt;&lt;text x="480" y="206" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;Private Subnet&lt;/text&gt;&lt;rect x="430" y="228" width="100" height="40" rx="6" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="480" y="252" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Instance&lt;/text&gt;&lt;text x="480" y="285" text-anchor="middle" font-size="10" style="fill:var(--secondary)"&gt;private IP only&lt;/text&gt;&lt;text x="160" y="330" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;bidirectional traffic&lt;/text&gt;&lt;text x="480" y="330" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;outbound only&lt;/text&gt;&lt;/svg&gt;
&lt;/div&gt;
&lt;h2 id="comparison-table"&gt;Comparison Table&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Aspect&lt;/th&gt;
&lt;th&gt;Internet Gateway&lt;/th&gt;
&lt;th&gt;NAT Gateway&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Primary purpose&lt;/td&gt;
&lt;td&gt;Enables communication between a VPC and the internet in both directions&lt;/td&gt;
&lt;td&gt;Enables outbound-only internet access for resources without public IPs&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Traffic direction&lt;/td&gt;
&lt;td&gt;Bidirectional — accepts inbound connections and sends outbound&lt;/td&gt;
&lt;td&gt;Outbound only — inbound traffic allowed only as replies to established connections&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Placement&lt;/td&gt;
&lt;td&gt;Attaches directly to the VPC as a whole&lt;/td&gt;
&lt;td&gt;Deployed inside a specific public subnet&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;IP address handling&lt;/td&gt;
&lt;td&gt;1:1 NAT between a private IP and an Elastic/public IP&lt;/td&gt;
&lt;td&gt;Many-to-one PAT — many private IPs share the gateway&amp;rsquo;s public IP&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Which resources use it&lt;/td&gt;
&lt;td&gt;Instances with a public/Elastic IP routed via a public subnet route table&lt;/td&gt;
&lt;td&gt;Instances with only private IPs routed via a private subnet route table&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Scaling and availability&lt;/td&gt;
&lt;td&gt;Managed, horizontally scaled, highly available with no bandwidth cap&lt;/td&gt;
&lt;td&gt;Bandwidth-bounded per gateway; needs one per AZ for high availability&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Cost model&lt;/td&gt;
&lt;td&gt;No hourly charge and no data processing fee&lt;/td&gt;
&lt;td&gt;Hourly charge plus per-GB data processing fee&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Failure impact&lt;/td&gt;
&lt;td&gt;Loss cuts off all direct internet reachability for the public subnet&lt;/td&gt;
&lt;td&gt;Loss cuts off outbound internet access for the private subnet only&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="key-differences"&gt;Key Differences&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Internet Gateway provides &lt;strong class="kw"&gt;bidirectional&lt;/strong&gt; access; NAT Gateway only permits &lt;strong class="kw"&gt;outbound&lt;/strong&gt; connections.&lt;/li&gt;
&lt;li&gt;Internet Gateway attaches to the whole &lt;strong class="kw"&gt;VPC&lt;/strong&gt;; NAT Gateway lives inside a specific &lt;strong class="kw"&gt;subnet&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Internet Gateway does 1:1 &lt;strong class="kw"&gt;Elastic IP&lt;/strong&gt; mapping; NAT Gateway does many-to-one &lt;strong class="kw"&gt;PAT&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;NAT Gateway bills per &lt;strong class="kw"&gt;GB processed&lt;/strong&gt;; Internet Gateway is &lt;strong class="kw"&gt;free&lt;/strong&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="when-to-use-each"&gt;When to Use Each&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Internet Gateway&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>Availability Zone vs Region: Scope of Cloud Infrastructure Isolation</title><link>https://comparison.metacog.co.kr/posts/2026-08-03-availability-zone-vs-region-scope-of-cloud-infrastructure-is/</link><pubDate>Mon, 03 Aug 2026 06:26:19 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-08-03-availability-zone-vs-region-scope-of-cloud-infrastructure-is/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;An &lt;strong class="kw"&gt;Availability Zone&lt;/strong&gt; is one or more physically isolated data centers with independent power, cooling, and networking, while a &lt;strong class="kw"&gt;Region&lt;/strong&gt; is a broader geographic area made up of multiple such zones connected by low-latency links. The distinction matters because it determines what kind of failure your architecture survives — a single data-center outage versus a region-wide disaster — and what compliance jurisdiction your data falls under.&lt;/p&gt;
&lt;h2 id="comparison-diagram"&gt;Comparison Diagram&lt;/h2&gt;
&lt;div class="compare-diagram"&gt;
&lt;svg viewBox="0 0 640 360" xmlns="http://www.w3.org/2000/svg"&gt;&lt;text x="150" y="30" text-anchor="middle" font-size="18" font-weight="bold" style="fill:var(--primary)"&gt;Availability Zone&lt;/text&gt;&lt;rect x="50" y="50" width="200" height="250" rx="6" style="fill:none;stroke:var(--compare-a)" stroke-width="1.5" stroke-dasharray="5 4"/&gt;&lt;rect x="75" y="100" width="70" height="90" rx="4" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;rect x="175" y="140" width="70" height="90" rx="4" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="110" y="148" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;DC&lt;/text&gt;&lt;text x="210" y="188" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;DC&lt;/text&gt;&lt;text x="150" y="280" text-anchor="middle" font-size="12" style="fill:var(--secondary)"&gt;1+ data centers,&lt;/text&gt;&lt;text x="150" y="296" text-anchor="middle" font-size="12" style="fill:var(--secondary)"&gt;independent power &amp;amp; network&lt;/text&gt;&lt;text x="475" y="30" text-anchor="middle" font-size="18" font-weight="bold" style="fill:var(--primary)"&gt;Region&lt;/text&gt;&lt;rect x="330" y="50" width="260" height="250" rx="6" style="fill:none;stroke:var(--compare-b)" stroke-width="1.5" stroke-dasharray="5 4"/&gt;&lt;line x1="385" y1="115" x2="515" y2="115" style="stroke:var(--border)" stroke-width="1.5" stroke-dasharray="3 3"/&gt;&lt;line x1="385" y1="115" x2="450" y2="225" style="stroke:var(--border)" stroke-width="1.5" stroke-dasharray="3 3"/&gt;&lt;line x1="515" y1="115" x2="450" y2="225" style="stroke:var(--border)" stroke-width="1.5" stroke-dasharray="3 3"/&gt;&lt;rect x="350" y="80" width="70" height="70" rx="4" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;rect x="480" y="80" width="70" height="70" rx="4" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;rect x="415" y="190" width="70" height="70" rx="4" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="385" y="120" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;AZ&lt;/text&gt;&lt;text x="515" y="120" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;AZ&lt;/text&gt;&lt;text x="450" y="230" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;AZ&lt;/text&gt;&lt;text x="460" y="280" text-anchor="middle" font-size="12" style="fill:var(--secondary)"&gt;Multiple AZs,&lt;/text&gt;&lt;text x="460" y="296" text-anchor="middle" font-size="12" style="fill:var(--secondary)"&gt;low-latency links&lt;/text&gt;&lt;/svg&gt;
&lt;/div&gt;
&lt;h2 id="comparison-table"&gt;Comparison Table&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Aspect&lt;/th&gt;
&lt;th&gt;Availability Zone&lt;/th&gt;
&lt;th&gt;Region&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Definition&lt;/td&gt;
&lt;td&gt;One or more discrete data centers with independent power, cooling, and networking&lt;/td&gt;
&lt;td&gt;A geographic area containing multiple availability zones&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Physical composition&lt;/td&gt;
&lt;td&gt;Typically 1+ physical data center buildings&lt;/td&gt;
&lt;td&gt;Multiple AZs (often 3 or more) plus regional network backbone&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Inter-node latency&lt;/td&gt;
&lt;td&gt;Sub-millisecond to a few milliseconds over private links between AZs&lt;/td&gt;
&lt;td&gt;Tens to hundreds of milliseconds over public/backbone links between regions&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Failure isolation&lt;/td&gt;
&lt;td&gt;Isolates against power, cooling, or single data-center failures&lt;/td&gt;
&lt;td&gt;Isolates against natural disasters or systemic events affecting an entire geography&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Redundancy pattern used for&lt;/td&gt;
&lt;td&gt;High availability within one geographic area&lt;/td&gt;
&lt;td&gt;Disaster recovery and global latency reduction across geographies&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Data residency &amp;amp; compliance&lt;/td&gt;
&lt;td&gt;No effect — all AZs in a region share the same jurisdiction&lt;/td&gt;
&lt;td&gt;Determines the legal jurisdiction and data residency boundary&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Data transfer cost&lt;/td&gt;
&lt;td&gt;Low intra-region rate for traffic between AZs&lt;/td&gt;
&lt;td&gt;Higher inter-region or egress rate for traffic between regions&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="key-differences"&gt;Key Differences&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;An Availability Zone is one or more &lt;strong class="kw"&gt;data centers&lt;/strong&gt;, while a Region is the &lt;strong class="kw"&gt;geographic area&lt;/strong&gt; that groups several AZs together&lt;/li&gt;
&lt;li&gt;Inter-AZ traffic uses low-latency &lt;strong class="kw"&gt;private links&lt;/strong&gt;; inter-region traffic crosses &lt;strong class="kw"&gt;public backbone&lt;/strong&gt; networks with far higher latency&lt;/li&gt;
&lt;li&gt;Multi-AZ deployments protect against &lt;strong class="kw"&gt;data-center outages&lt;/strong&gt;; multi-region deployments protect against &lt;strong class="kw"&gt;regional disasters&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;Region choice fixes your &lt;strong class="kw"&gt;data residency&lt;/strong&gt; and compliance jurisdiction — AZ choice does not&lt;/li&gt;
&lt;li&gt;Cross-AZ transfer is cheap; cross-region transfer incurs higher &lt;strong class="kw"&gt;egress costs&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="when-to-use-each"&gt;When to Use Each&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Availability Zone&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>CDN vs Origin Server: Who Actually Serves the Request</title><link>https://comparison.metacog.co.kr/posts/2026-08-03-cdn-vs-origin-server-who-actually-serves-the-request/</link><pubDate>Mon, 03 Aug 2026 06:23:28 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-08-03-cdn-vs-origin-server-who-actually-serves-the-request/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;A &lt;strong class="kw"&gt;CDN&lt;/strong&gt; is a distributed network of edge servers that caches and delivers content close to users, while the &lt;strong class="kw"&gt;origin server&lt;/strong&gt; is the single authoritative source where that content is created or stored. The distinction matters for latency, scalability, and resilience, since most requests should never need to reach the origin at all.&lt;/p&gt;
&lt;h2 id="comparison-diagram"&gt;Comparison Diagram&lt;/h2&gt;
&lt;div class="compare-diagram"&gt;
&lt;svg viewBox="0 0 640 360" xmlns="http://www.w3.org/2000/svg"&gt;&lt;circle cx="70" cy="200" r="24" style="fill:none;stroke:var(--border)" stroke-width="1.5"/&gt;&lt;text x="70" y="205" text-anchor="middle" style="fill:var(--content)" font-size="11"&gt;Client&lt;/text&gt;&lt;rect x="150" y="70" width="200" height="220" rx="8" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="250" y="52" text-anchor="middle" style="fill:var(--primary)" font-size="16" font-weight="bold"&gt;CDN&lt;/text&gt;&lt;text x="250" y="90" text-anchor="middle" style="fill:var(--content)" font-size="11"&gt;Distributed edge locations&lt;/text&gt;&lt;circle cx="200" cy="140" r="16" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;circle cx="300" cy="140" r="16" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;circle cx="250" cy="200" r="16" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;circle cx="200" cy="250" r="16" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;circle cx="300" cy="250" r="16" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="250" y="278" text-anchor="middle" style="fill:var(--secondary)" font-size="10"&gt;Cache: static &amp;amp; edge-computed content&lt;/text&gt;&lt;rect x="460" y="150" width="140" height="90" rx="8" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="530" y="133" text-anchor="middle" style="fill:var(--primary)" font-size="16" font-weight="bold"&gt;Origin Server&lt;/text&gt;&lt;text x="530" y="192" text-anchor="middle" style="fill:var(--content)" font-size="11"&gt;Single source&lt;/text&gt;&lt;text x="530" y="207" text-anchor="middle" style="fill:var(--content)" font-size="11"&gt;of truth&lt;/text&gt;&lt;line x1="95" y1="190" x2="148" y2="165" style="stroke:var(--content)" stroke-width="1.5"/&gt;&lt;polygon points="148,165 139,163 143,171" style="fill:var(--content)"/&gt;&lt;text x="115" y="150" text-anchor="middle" style="fill:var(--secondary)" font-size="9"&gt;request&lt;/text&gt;&lt;line x1="148" y1="215" x2="95" y2="210" style="stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;polygon points="95,210 104,206 104,215" style="fill:var(--compare-a)"/&gt;&lt;text x="118" y="235" text-anchor="middle" style="fill:var(--secondary)" font-size="9"&gt;cached response&lt;/text&gt;&lt;line x1="352" y1="180" x2="458" y2="185" style="stroke:var(--compare-b)" stroke-width="1.5" stroke-dasharray="5,4"/&gt;&lt;polygon points="458,185 449,181 450,190" style="fill:var(--compare-b)"/&gt;&lt;text x="405" y="165" text-anchor="middle" style="fill:var(--secondary)" font-size="9"&gt;on cache miss&lt;/text&gt;&lt;line x1="458" y1="215" x2="352" y2="210" style="stroke:var(--compare-b)" stroke-width="1.5" stroke-dasharray="5,4"/&gt;&lt;polygon points="352,210 361,206 361,215" style="fill:var(--compare-b)"/&gt;&lt;text x="405" y="233" text-anchor="middle" style="fill:var(--secondary)" font-size="9"&gt;origin pull &amp;amp; cache&lt;/text&gt;&lt;text x="320" y="330" text-anchor="middle" style="fill:var(--secondary)" font-size="10"&gt;Most requests resolve at the edge; only misses/dynamic content reach the origin&lt;/text&gt;&lt;/svg&gt;
&lt;/div&gt;
&lt;h2 id="comparison-table"&gt;Comparison Table&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Aspect&lt;/th&gt;
&lt;th&gt;CDN&lt;/th&gt;
&lt;th&gt;Origin Server&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Role in request path&lt;/td&gt;
&lt;td&gt;Intercepts requests at the edge and serves cached content directly&lt;/td&gt;
&lt;td&gt;Authoritative backend that generates or stores the original content&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Geographic distribution&lt;/td&gt;
&lt;td&gt;Many points of presence worldwide, close to end users&lt;/td&gt;
&lt;td&gt;Typically one or a few fixed data center locations&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Content served&lt;/td&gt;
&lt;td&gt;Cached copies of static assets or cacheable API responses&lt;/td&gt;
&lt;td&gt;Dynamically generated pages or master copies of files&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Cache miss handling&lt;/td&gt;
&lt;td&gt;Forwards uncached requests to the origin and stores the response per TTL&lt;/td&gt;
&lt;td&gt;Processes every request that reaches it; has no caching layer of its own&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Latency&lt;/td&gt;
&lt;td&gt;Low, since content is served from the nearest edge node&lt;/td&gt;
&lt;td&gt;Higher, since every request travels to one fixed location&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Load on backend&lt;/td&gt;
&lt;td&gt;Absorbs most traffic, shielding the origin from direct load&lt;/td&gt;
&lt;td&gt;Only handles cache misses and non-cacheable requests&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Resilience to outages&lt;/td&gt;
&lt;td&gt;Can keep serving stale cached content if the origin goes down&lt;/td&gt;
&lt;td&gt;Site is effectively unavailable for anything not already cached elsewhere&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Scaling and cost&lt;/td&gt;
&lt;td&gt;Scales via the CDN provider&amp;rsquo;s global network, billed per bandwidth/requests&lt;/td&gt;
&lt;td&gt;Must be scaled and provisioned directly, billed for compute and hosting&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="key-differences"&gt;Key Differences&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;CDN content lives on distributed &lt;strong class="kw"&gt;edge nodes&lt;/strong&gt;; the origin server is the single &lt;strong class="kw"&gt;source of truth&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;CDN caching cuts &lt;strong class="kw"&gt;latency&lt;/strong&gt; for users, but every &lt;strong class="kw"&gt;cache miss&lt;/strong&gt; still lands on the origin.&lt;/li&gt;
&lt;li&gt;CDN edge caching gives resilience against &lt;strong class="kw"&gt;origin outages&lt;/strong&gt; by serving stale content.&lt;/li&gt;
&lt;li&gt;Origin servers own &lt;strong class="kw"&gt;dynamic content&lt;/strong&gt; generation; CDNs only store what&amp;rsquo;s actually &lt;strong class="kw"&gt;cacheable&lt;/strong&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="when-to-use-each"&gt;When to Use Each&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;CDN&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>Service Mesh vs API Gateway: North-South vs East-West Traffic</title><link>https://comparison.metacog.co.kr/posts/2026-08-03-service-mesh-vs-api-gateway-north-south-vs-east-west-traffic/</link><pubDate>Mon, 03 Aug 2026 05:19:35 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-08-03-service-mesh-vs-api-gateway-north-south-vs-east-west-traffic/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;An &lt;strong class="kw"&gt;API gateway&lt;/strong&gt; sits at the edge of your system, managing traffic between external clients and your services. A &lt;strong class="kw"&gt;service mesh&lt;/strong&gt; operates inside the cluster, managing traffic between services themselves. Confusing the two leads teams to either duplicate cross-cutting concerns or push edge-only features into infrastructure that was never designed for public-facing traffic.&lt;/p&gt;
&lt;h2 id="comparison-diagram"&gt;Comparison Diagram&lt;/h2&gt;
&lt;div class="compare-diagram"&gt;
&lt;svg viewBox="0 0 640 360" xmlns="http://www.w3.org/2000/svg"&gt;&lt;text x="235" y="24" text-anchor="middle" font-size="16" font-weight="bold" style="fill:var(--compare-a)"&gt;API Gateway&lt;/text&gt;&lt;text x="480" y="24" text-anchor="middle" font-size="16" font-weight="bold" style="fill:var(--compare-b)"&gt;Service Mesh&lt;/text&gt;&lt;rect x="20" y="160" width="80" height="50" rx="6" style="fill:none;stroke:var(--content)" stroke-width="1.5"/&gt;&lt;text x="60" y="190" text-anchor="middle" font-size="13" style="fill:var(--content)"&gt;Client&lt;/text&gt;&lt;line x1="100" y1="185" x2="165" y2="185" style="stroke:var(--content)" stroke-width="1.5"/&gt;&lt;polygon points="165,180 175,185 165,190" style="fill:var(--content)"/&gt;&lt;rect x="175" y="130" width="120" height="110" rx="8" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="235" y="158" text-anchor="middle" font-size="12" font-weight="bold" style="fill:var(--compare-a)"&gt;API Gateway&lt;/text&gt;&lt;text x="235" y="178" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;authN · rate limit&lt;/text&gt;&lt;text x="235" y="194" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;routing · transform&lt;/text&gt;&lt;line x1="295" y1="185" x2="335" y2="185" style="stroke:var(--content)" stroke-width="1.5"/&gt;&lt;polygon points="335,180 345,185 335,190" style="fill:var(--content)"/&gt;&lt;rect x="345" y="45" width="270" height="280" rx="10" style="fill:none;stroke:var(--border)" stroke-width="1.5" stroke-dasharray="6,4"/&gt;&lt;text x="480" y="64" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;cluster&lt;/text&gt;&lt;rect x="380" y="85" width="90" height="45" rx="6" style="fill:none;stroke:var(--content)" stroke-width="1.5"/&gt;&lt;text x="425" y="111" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Service A&lt;/text&gt;&lt;rect x="475" y="95" width="22" height="22" rx="4" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;rect x="380" y="165" width="90" height="45" rx="6" style="fill:none;stroke:var(--content)" stroke-width="1.5"/&gt;&lt;text x="425" y="191" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Service B&lt;/text&gt;&lt;rect x="475" y="175" width="22" height="22" rx="4" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;rect x="380" y="245" width="90" height="45" rx="6" style="fill:none;stroke:var(--content)" stroke-width="1.5"/&gt;&lt;text x="425" y="271" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Service C&lt;/text&gt;&lt;rect x="475" y="255" width="22" height="22" rx="4" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;line x1="497" y1="106" x2="497" y2="186" style="stroke:var(--compare-b)" stroke-width="1.5" stroke-dasharray="4,3"/&gt;&lt;line x1="497" y1="186" x2="497" y2="266" style="stroke:var(--compare-b)" stroke-width="1.5" stroke-dasharray="4,3"/&gt;&lt;path d="M497,106 C560,150 560,220 497,266" style="fill:none;stroke:var(--compare-b)" stroke-width="1.5" stroke-dasharray="4,3"/&gt;&lt;text x="600" y="100" text-anchor="end" font-size="10" style="fill:var(--secondary)"&gt;sidecar proxy&lt;/text&gt;&lt;text x="600" y="196" text-anchor="end" font-size="10" style="fill:var(--secondary)"&gt;mTLS · retries&lt;/text&gt;&lt;text x="235" y="345" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;north–south: client-to-service&lt;/text&gt;&lt;text x="480" y="345" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;east–west: service-to-service&lt;/text&gt;&lt;/svg&gt;
&lt;/div&gt;
&lt;h2 id="comparison-table"&gt;Comparison Table&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Aspect&lt;/th&gt;
&lt;th&gt;API Gateway&lt;/th&gt;
&lt;th&gt;Service Mesh&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Traffic direction&lt;/td&gt;
&lt;td&gt;North-south: external clients entering the system&lt;/td&gt;
&lt;td&gt;East-west: internal service-to-service calls&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Deployment topology&lt;/td&gt;
&lt;td&gt;Centralized cluster of edge instances fronting all traffic&lt;/td&gt;
&lt;td&gt;Sidecar proxy injected alongside every service instance&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Primary concerns&lt;/td&gt;
&lt;td&gt;AuthN/authZ, rate limiting, request/response transformation, API versioning&lt;/td&gt;
&lt;td&gt;mTLS, load balancing, retries, circuit breaking between services&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Routing basis&lt;/td&gt;
&lt;td&gt;Public API path, host, or version mapped to a backend service&lt;/td&gt;
&lt;td&gt;Service identity and destination within the internal network&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Observability scope&lt;/td&gt;
&lt;td&gt;Per-endpoint metrics: request volume, latency, errors by client&lt;/td&gt;
&lt;td&gt;Full service dependency graph: per-hop latency and error rates&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Failure containment&lt;/td&gt;
&lt;td&gt;Blocks or throttles bad traffic before it reaches any backend&lt;/td&gt;
&lt;td&gt;Isolates failures at individual hops so one bad service doesn&amp;rsquo;t cascade&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Operational overhead&lt;/td&gt;
&lt;td&gt;Few instances to scale and configure centrally&lt;/td&gt;
&lt;td&gt;One proxy per workload, plus a control plane to manage them all&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="key-differences"&gt;Key Differences&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;An &lt;strong class="kw"&gt;API gateway&lt;/strong&gt; is the single entry point clients hit; a &lt;strong class="kw"&gt;service mesh&lt;/strong&gt; has no single entry point, it&amp;rsquo;s woven through every service.&lt;/li&gt;
&lt;li&gt;Gateways enforce policy once at the edge; meshes enforce policy per &lt;strong class="kw"&gt;sidecar&lt;/strong&gt; on every call.&lt;/li&gt;
&lt;li&gt;Gateways typically run as a small number of centralized instances; meshes scale linearly with your &lt;strong class="kw"&gt;service count&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Meshes give you &lt;strong class="kw"&gt;mTLS&lt;/strong&gt; and retries between internal services, something a gateway never sees because that traffic never reaches it.&lt;/li&gt;
&lt;li&gt;Many production systems run both together, not as alternatives, since they solve problems at different layers.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="when-to-use-each"&gt;When to Use Each&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;API Gateway&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>VPN vs Proxy: Encrypting Everything or Rerouting One App</title><link>https://comparison.metacog.co.kr/posts/2026-08-03-vpn-vs-proxy-encrypting-everything-or-rerouting-one-app/</link><pubDate>Mon, 03 Aug 2026 04:31:13 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-08-03-vpn-vs-proxy-encrypting-everything-or-rerouting-one-app/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;A &lt;strong class="kw"&gt;VPN&lt;/strong&gt; creates an encrypted tunnel for all of a device&amp;rsquo;s network traffic through a remote server, while a &lt;strong class="kw"&gt;proxy&lt;/strong&gt; forwards traffic from a single app or protocol through an intermediary server, typically without encryption. The distinction matters because it determines what&amp;rsquo;s protected, how much overhead is added, and what happens when the connection fails.&lt;/p&gt;
&lt;h2 id="comparison-diagram"&gt;Comparison Diagram&lt;/h2&gt;
&lt;div class="compare-diagram"&gt;
&lt;svg viewBox="0 0 640 360" xmlns="http://www.w3.org/2000/svg"&gt;&lt;defs&gt;&lt;marker id="arrowA" viewBox="0 0 10 10" refX="8" refY="5" markerWidth="6" markerHeight="6" orient="auto-start-reverse"&gt;&lt;path d="M0,0 L10,5 L0,10 z" style="fill:var(--compare-a)"/&gt;&lt;/marker&gt;&lt;marker id="arrowB" viewBox="0 0 10 10" refX="8" refY="5" markerWidth="6" markerHeight="6" orient="auto-start-reverse"&gt;&lt;path d="M0,0 L10,5 L0,10 z" style="fill:var(--compare-b)"/&gt;&lt;/marker&gt;&lt;marker id="arrowN" viewBox="0 0 10 10" refX="8" refY="5" markerWidth="6" markerHeight="6" orient="auto-start-reverse"&gt;&lt;path d="M0,0 L10,5 L0,10 z" style="fill:var(--border)"/&gt;&lt;/marker&gt;&lt;/defs&gt;&lt;line x1="320" y1="20" x2="320" y2="340" style="stroke:var(--border)" stroke-width="1" stroke-dasharray="4,4"/&gt;&lt;text x="160" y="36" text-anchor="middle" style="fill:var(--primary)" font-size="18" font-weight="bold"&gt;VPN&lt;/text&gt;&lt;text x="480" y="36" text-anchor="middle" style="fill:var(--primary)" font-size="18" font-weight="bold"&gt;Proxy&lt;/text&gt;&lt;rect x="30" y="90" width="90" height="40" rx="4" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="75" y="114" text-anchor="middle" style="fill:var(--content)" font-size="12"&gt;Device (OS)&lt;/text&gt;&lt;text x="75" y="145" text-anchor="middle" style="fill:var(--secondary)" font-size="10"&gt;all apps &amp;amp; traffic&lt;/text&gt;&lt;line x1="120" y1="110" x2="185" y2="110" style="stroke:var(--compare-a)" stroke-width="4" stroke-dasharray="6,4" marker-end="url(#arrowA)"/&gt;&lt;text x="152" y="98" text-anchor="middle" style="fill:var(--secondary)" font-size="9"&gt;encrypted tunnel&lt;/text&gt;&lt;rect x="190" y="90" width="90" height="40" rx="4" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="235" y="114" text-anchor="middle" style="fill:var(--content)" font-size="12"&gt;VPN Server&lt;/text&gt;&lt;line x1="280" y1="112" x2="298" y2="148" style="stroke:var(--compare-a)" stroke-width="2" marker-end="url(#arrowA)"/&gt;&lt;circle cx="300" cy="155" r="3" style="fill:var(--content)"/&gt;&lt;text x="300" y="175" text-anchor="middle" style="fill:var(--content)" font-size="10"&gt;Internet&lt;/text&gt;&lt;text x="160" y="230" text-anchor="middle" style="fill:var(--secondary)" font-size="10"&gt;Encrypts &amp;amp; routes ALL device traffic&lt;/text&gt;&lt;rect x="340" y="90" width="90" height="40" rx="4" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="385" y="114" text-anchor="middle" style="fill:var(--content)" font-size="12"&gt;Browser&lt;/text&gt;&lt;line x1="430" y1="110" x2="495" y2="110" style="stroke:var(--compare-b)" stroke-width="2" marker-end="url(#arrowB)"/&gt;&lt;text x="462" y="98" text-anchor="middle" style="fill:var(--secondary)" font-size="9"&gt;app traffic&lt;/text&gt;&lt;rect x="500" y="90" width="90" height="40" rx="4" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="545" y="114" text-anchor="middle" style="fill:var(--content)" font-size="12"&gt;Proxy Server&lt;/text&gt;&lt;line x1="590" y1="112" x2="608" y2="148" style="stroke:var(--compare-b)" stroke-width="2" marker-end="url(#arrowB)"/&gt;&lt;rect x="340" y="200" width="90" height="40" rx="4" style="fill:none;stroke:var(--border)" stroke-width="1.5" stroke-dasharray="3,3"/&gt;&lt;text x="385" y="224" text-anchor="middle" style="fill:var(--content)" font-size="12"&gt;Other Apps&lt;/text&gt;&lt;line x1="430" y1="218" x2="606" y2="162" style="stroke:var(--border)" stroke-width="1.5" stroke-dasharray="4,3" marker-end="url(#arrowN)"/&gt;&lt;text x="500" y="235" text-anchor="middle" style="fill:var(--secondary)" font-size="9"&gt;bypasses proxy (direct, unencrypted)&lt;/text&gt;&lt;circle cx="610" cy="155" r="3" style="fill:var(--content)"/&gt;&lt;text x="610" y="175" text-anchor="middle" style="fill:var(--content)" font-size="10"&gt;Internet&lt;/text&gt;&lt;text x="480" y="270" text-anchor="middle" style="fill:var(--secondary)" font-size="10"&gt;Routes only configured app/protocol traffic&lt;/text&gt;&lt;/svg&gt;
&lt;/div&gt;
&lt;h2 id="comparison-table"&gt;Comparison Table&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Aspect&lt;/th&gt;
&lt;th&gt;VPN&lt;/th&gt;
&lt;th&gt;Proxy&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Scope of traffic routed&lt;/td&gt;
&lt;td&gt;All network traffic from the device (OS-level)&lt;/td&gt;
&lt;td&gt;Traffic from a specific app or protocol the client is configured to use&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Where it&amp;rsquo;s configured&lt;/td&gt;
&lt;td&gt;System network settings / dedicated client that creates a virtual interface&lt;/td&gt;
&lt;td&gt;Individual app settings (browser, OS network stack per-app, or system-wide proxy field)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Encryption&lt;/td&gt;
&lt;td&gt;Encrypts traffic between device and VPN server by default&lt;/td&gt;
&lt;td&gt;No encryption by default; only as strong as the underlying protocol (e.g. HTTPS)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Authentication to server&lt;/td&gt;
&lt;td&gt;Client authenticates with certificates/credentials to establish the tunnel&lt;/td&gt;
&lt;td&gt;Often none, or simple username/password at the app layer&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Visibility to local network/ISP&lt;/td&gt;
&lt;td&gt;ISP and local network see only encrypted tunnel traffic to one endpoint&lt;/td&gt;
&lt;td&gt;ISP sees the proxy connection plus any traffic from unproxied apps&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Performance overhead&lt;/td&gt;
&lt;td&gt;Higher — encryption and full traffic redirection add latency&lt;/td&gt;
&lt;td&gt;Lower — only proxied traffic is redirected, often with caching&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Typical use case&lt;/td&gt;
&lt;td&gt;Secure remote access to a private network, or system-wide privacy on untrusted Wi-Fi&lt;/td&gt;
&lt;td&gt;Per-app geo-bypass, content filtering, or caching for a single protocol&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Behavior on failure&lt;/td&gt;
&lt;td&gt;Well-configured clients include a kill switch that blocks all traffic if the tunnel drops&lt;/td&gt;
&lt;td&gt;Only the proxied app&amp;rsquo;s connection fails; other traffic is unaffected&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="key-differences"&gt;Key Differences&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;A VPN operates at the &lt;strong class="kw"&gt;OS network layer&lt;/strong&gt;, capturing all traffic, while a proxy operates at the &lt;strong class="kw"&gt;application layer&lt;/strong&gt; for one app or protocol&lt;/li&gt;
&lt;li&gt;VPN traffic is &lt;strong class="kw"&gt;encrypted&lt;/strong&gt; by default; proxy traffic is &lt;strong class="kw"&gt;unencrypted&lt;/strong&gt; unless the underlying protocol adds it&lt;/li&gt;
&lt;li&gt;VPNs require dedicated &lt;strong class="kw"&gt;client software&lt;/strong&gt; creating a virtual interface; proxies need only an &lt;strong class="kw"&gt;IP:port&lt;/strong&gt; entry in an app&amp;rsquo;s settings&lt;/li&gt;
&lt;li&gt;A VPN&amp;rsquo;s &lt;strong class="kw"&gt;kill switch&lt;/strong&gt; can block all traffic on disconnect; a proxy failure only drops that &lt;strong class="kw"&gt;single app&amp;rsquo;s&lt;/strong&gt; connection&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="when-to-use-each"&gt;When to Use Each&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;VPN&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>Blocking vs Non-blocking I/O: How a Thread Waits for Data</title><link>https://comparison.metacog.co.kr/posts/2026-08-02-blocking-vs-non-blocking-i-o-how-a-thread-waits-for-data/</link><pubDate>Sun, 02 Aug 2026 09:10:28 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-08-02-blocking-vs-non-blocking-i-o-how-a-thread-waits-for-data/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;Blocking and non-blocking I/O differ in what happens to the calling thread when a read or write can&amp;rsquo;t complete immediately. Blocking I/O suspends the thread until data is ready; non-blocking I/O returns at once and lets the caller check back later. The choice shapes how a system scales to many simultaneous connections.&lt;/p&gt;
&lt;h2 id="comparison-diagram"&gt;Comparison Diagram&lt;/h2&gt;
&lt;div class="compare-diagram"&gt;
&lt;svg viewBox="0 0 640 360" xmlns="http://www.w3.org/2000/svg"&gt;&lt;line x1="320" y1="45" x2="320" y2="315" style="stroke:var(--border)" stroke-width="1" stroke-dasharray="4,4"/&gt;&lt;text x="160" y="28" text-anchor="middle" font-size="16" font-weight="600" style="fill:var(--primary)"&gt;Blocking I/O&lt;/text&gt;&lt;text x="480" y="28" text-anchor="middle" font-size="16" font-weight="600" style="fill:var(--primary)"&gt;Non-blocking I/O&lt;/text&gt;&lt;rect x="100" y="50" width="120" height="30" rx="4" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="160" y="70" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Thread&lt;/text&gt;&lt;line x1="160" y1="80" x2="160" y2="102" style="stroke:var(--secondary)" stroke-width="1.5"/&gt;&lt;polygon points="160,105 156,98 164,98" style="fill:var(--secondary)"/&gt;&lt;rect x="70" y="105" width="180" height="30" rx="4" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="160" y="125" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;call read()&lt;/text&gt;&lt;line x1="160" y1="135" x2="160" y2="157" style="stroke:var(--secondary)" stroke-width="1.5"/&gt;&lt;polygon points="160,160 156,153 164,153" style="fill:var(--secondary)"/&gt;&lt;rect x="70" y="160" width="180" height="85" rx="4" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5" stroke-dasharray="5,3"/&gt;&lt;text x="160" y="198" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;thread blocked&lt;/text&gt;&lt;text x="160" y="216" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;no other work possible&lt;/text&gt;&lt;text x="160" y="234" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;until data arrives&lt;/text&gt;&lt;line x1="160" y1="245" x2="160" y2="267" style="stroke:var(--secondary)" stroke-width="1.5"/&gt;&lt;polygon points="160,270 156,263 164,263" style="fill:var(--secondary)"/&gt;&lt;rect x="70" y="270" width="180" height="30" rx="4" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="160" y="290" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;data ready, resumes&lt;/text&gt;&lt;text x="160" y="330" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;1 thread ≈ 1 in-flight call&lt;/text&gt;&lt;rect x="390" y="50" width="180" height="30" rx="4" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="480" y="70" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;thread / event loop&lt;/text&gt;&lt;line x1="480" y1="80" x2="480" y2="102" style="stroke:var(--secondary)" stroke-width="1.5"/&gt;&lt;polygon points="480,105 476,98 484,98" style="fill:var(--secondary)"/&gt;&lt;rect x="390" y="105" width="180" height="30" rx="4" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="480" y="125" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;read() returns at once&lt;/text&gt;&lt;line x1="480" y1="135" x2="480" y2="157" style="stroke:var(--secondary)" stroke-width="1.5"/&gt;&lt;polygon points="480,160 476,153 484,153" style="fill:var(--secondary)"/&gt;&lt;rect x="390" y="160" width="180" height="35" rx="4" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="480" y="182" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;poll / epoll check&lt;/text&gt;&lt;path d="M 570 168 C 595 168 595 190 572 190" style="stroke:var(--compare-b);fill:none" stroke-width="1.3"/&gt;&lt;polygon points="572,190 579,187 578,194" style="fill:var(--compare-b)"/&gt;&lt;text x="596" y="182" font-size="9" style="fill:var(--secondary)"&gt;retry&lt;/text&gt;&lt;line x1="480" y1="195" x2="480" y2="207" style="stroke:var(--secondary)" stroke-width="1.5"/&gt;&lt;polygon points="480,210 476,203 484,203" style="fill:var(--secondary)"/&gt;&lt;rect x="390" y="210" width="180" height="35" rx="4" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="480" y="228" text-anchor="middle" font-size="11" style="fill:var(--content)"&gt;meanwhile: serves other&lt;/text&gt;&lt;text x="480" y="241" text-anchor="middle" font-size="11" style="fill:var(--content)"&gt;connections&lt;/text&gt;&lt;line x1="480" y1="245" x2="480" y2="267" style="stroke:var(--secondary)" stroke-width="1.5"/&gt;&lt;polygon points="480,270 476,263 484,263" style="fill:var(--secondary)"/&gt;&lt;rect x="390" y="270" width="180" height="30" rx="4" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="480" y="290" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;ready → callback fires&lt;/text&gt;&lt;text x="480" y="330" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;1 thread ≈ many in-flight calls&lt;/text&gt;&lt;/svg&gt;
&lt;/div&gt;
&lt;h2 id="comparison-table"&gt;Comparison Table&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Aspect&lt;/th&gt;
&lt;th&gt;Blocking I/O&lt;/th&gt;
&lt;th&gt;Non-blocking I/O&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Call behavior&lt;/td&gt;
&lt;td&gt;Call halts the calling thread until the operation completes&lt;/td&gt;
&lt;td&gt;Call returns immediately, with data or an EWOULDBLOCK/EAGAIN error&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Thread state while I/O is pending&lt;/td&gt;
&lt;td&gt;Thread is suspended off the run queue — no CPU used, but unavailable for other work&lt;/td&gt;
&lt;td&gt;Thread stays runnable and can be reused to serve other requests&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;How readiness is discovered&lt;/td&gt;
&lt;td&gt;OS wakes the thread automatically once data is ready&lt;/td&gt;
&lt;td&gt;Caller polls or registers with select/poll/epoll/kqueue&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Concurrency model&lt;/td&gt;
&lt;td&gt;One thread (or process) per concurrent connection&lt;/td&gt;
&lt;td&gt;Single or few threads multiplex many connections via an event loop&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Resource overhead at scale&lt;/td&gt;
&lt;td&gt;Grows linearly with connections — thread stacks, context switches&lt;/td&gt;
&lt;td&gt;Stays flat, bounded by CPU cores rather than connection count&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Code / control-flow complexity&lt;/td&gt;
&lt;td&gt;Simple, sequential, top-to-bottom logic&lt;/td&gt;
&lt;td&gt;Callback, promise, or async/await structure; state tracked across suspensions&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Failure / edge-case handling&lt;/td&gt;
&lt;td&gt;A slow or hung peer blocks the thread indefinitely without a timeout&lt;/td&gt;
&lt;td&gt;A slow peer only delays its own event; a stalled callback can starve the whole loop&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="key-differences"&gt;Key Differences&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Blocking I/O ties up a &lt;strong class="kw"&gt;thread&lt;/strong&gt; for the full call; non-blocking frees it immediately.&lt;/li&gt;
&lt;li&gt;Non-blocking servers rely on an &lt;strong class="kw"&gt;event loop&lt;/strong&gt; to learn when data is finally ready.&lt;/li&gt;
&lt;li&gt;Blocking scales concurrency with more &lt;strong class="kw"&gt;threads&lt;/strong&gt;; non-blocking scales with more &lt;strong class="kw"&gt;callbacks&lt;/strong&gt; on fewer threads.&lt;/li&gt;
&lt;li&gt;Blocking code reads &lt;strong class="kw"&gt;sequentially&lt;/strong&gt;; non-blocking code needs explicit &lt;strong class="kw"&gt;state management&lt;/strong&gt; across suspensions.&lt;/li&gt;
&lt;li&gt;At high connection counts, blocking hits a &lt;strong class="kw"&gt;C10K&lt;/strong&gt; wall that non-blocking avoids.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="when-to-use-each"&gt;When to Use Each&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Blocking I/O&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>Latency vs Bandwidth: Delay vs Capacity</title><link>https://comparison.metacog.co.kr/posts/2026-08-03-latency-vs-bandwidth-delay-vs-capacity/</link><pubDate>Sat, 01 Aug 2026 20:14:00 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-08-03-latency-vs-bandwidth-delay-vs-capacity/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;Latency and bandwidth both describe network performance, but they measure completely different things: &lt;strong class="kw"&gt;latency&lt;/strong&gt; is how long a single piece of data takes to travel from source to destination, while &lt;strong class="kw"&gt;bandwidth&lt;/strong&gt; is how much data can move through the connection per second. A link can have huge bandwidth and still feel laggy, or tiny bandwidth and still respond instantly — understanding which one is limiting you determines whether the fix is a faster link or a shorter path.&lt;/p&gt;</description></item><item><title>Circuit Switching vs Packet Switching: Dedicated Paths vs Independent Packets</title><link>https://comparison.metacog.co.kr/posts/2026-08-03-circuit-switching-vs-packet-switching-dedicated-paths-vs-ind/</link><pubDate>Sat, 01 Aug 2026 20:13:00 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-08-03-circuit-switching-vs-packet-switching-dedicated-paths-vs-ind/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;Circuit switching and packet switching are the two fundamental ways a network can move data between endpoints. Circuit switching reserves a &lt;strong class="kw"&gt;dedicated path&lt;/strong&gt; for the full duration of a session, like a traditional phone call, while packet switching breaks data into &lt;strong class="kw"&gt;independent packets&lt;/strong&gt; that share network links and find their own way to the destination. The choice affects everything from latency predictability to how efficiently bandwidth gets used.&lt;/p&gt;
&lt;h2 id="comparison-diagram"&gt;Comparison Diagram&lt;/h2&gt;
&lt;div class="compare-diagram"&gt;
&lt;svg viewBox="0 0 640 360" xmlns="http://www.w3.org/2000/svg"&gt;
&lt;text x="165" y="28" text-anchor="middle" font-size="18" font-weight="bold" style="fill:var(--primary)"&gt;Circuit Switching&lt;/text&gt;
&lt;text x="480" y="28" text-anchor="middle" font-size="18" font-weight="bold" style="fill:var(--primary)"&gt;Packet Switching&lt;/text&gt;
&lt;line x1="320" y1="10" x2="320" y2="350" stroke-width="1" stroke-dasharray="4,4" style="stroke:var(--border)"/&gt;
&lt;circle cx="55" cy="190" r="16" stroke-width="1.5" style="fill:var(--compare-a-soft);stroke:var(--compare-a)"/&gt;
&lt;text x="55" y="195" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;A&lt;/text&gt;
&lt;circle cx="275" cy="190" r="16" stroke-width="1.5" style="fill:var(--compare-a-soft);stroke:var(--compare-a)"/&gt;
&lt;text x="275" y="195" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;B&lt;/text&gt;
&lt;rect x="110" y="175" width="30" height="30" rx="4" stroke-width="1.5" style="fill:var(--compare-a-soft);stroke:var(--compare-a)"/&gt;
&lt;rect x="180" y="175" width="30" height="30" rx="4" stroke-width="1.5" style="fill:var(--compare-a-soft);stroke:var(--compare-a)"/&gt;
&lt;line x1="71" y1="190" x2="110" y2="190" stroke-width="5" style="stroke:var(--compare-a)"/&gt;
&lt;line x1="140" y1="190" x2="180" y2="190" stroke-width="5" style="stroke:var(--compare-a)"/&gt;
&lt;line x1="210" y1="190" x2="259" y2="190" stroke-width="5" style="stroke:var(--compare-a)"/&gt;
&lt;text x="165" y="250" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;Dedicated path reserved&lt;/text&gt;
&lt;text x="165" y="264" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;for the entire call&lt;/text&gt;
&lt;circle cx="365" cy="190" r="16" stroke-width="1.5" style="fill:var(--compare-b-soft);stroke:var(--compare-b)"/&gt;
&lt;text x="365" y="195" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;A&lt;/text&gt;
&lt;circle cx="585" cy="190" r="16" stroke-width="1.5" style="fill:var(--compare-b-soft);stroke:var(--compare-b)"/&gt;
&lt;text x="585" y="195" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;B&lt;/text&gt;
&lt;circle cx="430" cy="140" r="12" stroke-width="1.5" style="fill:var(--compare-b-soft);stroke:var(--compare-b)"/&gt;
&lt;circle cx="430" cy="240" r="12" stroke-width="1.5" style="fill:var(--compare-b-soft);stroke:var(--compare-b)"/&gt;
&lt;circle cx="505" cy="140" r="12" stroke-width="1.5" style="fill:var(--compare-b-soft);stroke:var(--compare-b)"/&gt;
&lt;circle cx="505" cy="240" r="12" stroke-width="1.5" style="fill:var(--compare-b-soft);stroke:var(--compare-b)"/&gt;
&lt;line x1="381" y1="182" x2="419" y2="146" stroke-width="2" style="stroke:var(--compare-b)"/&gt;
&lt;line x1="381" y1="198" x2="419" y2="234" stroke-width="2" style="stroke:var(--compare-b)"/&gt;
&lt;line x1="442" y1="140" x2="493" y2="140" stroke-width="2" style="stroke:var(--compare-b)"/&gt;
&lt;line x1="442" y1="240" x2="493" y2="240" stroke-width="2" style="stroke:var(--compare-b)"/&gt;
&lt;line x1="517" y1="146" x2="569" y2="182" stroke-width="2" style="stroke:var(--compare-b)"/&gt;
&lt;line x1="517" y1="234" x2="569" y2="198" stroke-width="2" style="stroke:var(--compare-b)"/&gt;
&lt;line x1="440" y1="148" x2="497" y2="232" stroke-width="1" stroke-dasharray="3,3" style="stroke:var(--border)"/&gt;
&lt;line x1="440" y1="232" x2="497" y2="148" stroke-width="1" stroke-dasharray="3,3" style="stroke:var(--border)"/&gt;
&lt;rect x="392" y="150" width="14" height="14" rx="2" stroke-width="1.5" style="fill:var(--compare-b-soft);stroke:var(--compare-b)"/&gt;
&lt;text x="399" y="160" text-anchor="middle" font-size="9" style="fill:var(--content)"&gt;1&lt;/text&gt;
&lt;rect x="392" y="222" width="14" height="14" rx="2" stroke-width="1.5" style="fill:var(--compare-b-soft);stroke:var(--compare-b)"/&gt;
&lt;text x="399" y="232" text-anchor="middle" font-size="9" style="fill:var(--content)"&gt;2&lt;/text&gt;
&lt;text x="480" y="250" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;Packets routed independently,&lt;/text&gt;
&lt;text x="480" y="264" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;paths may differ, may arrive out of order&lt;/text&gt;
&lt;/svg&gt;
&lt;/div&gt;
&lt;h2 id="comparison-table"&gt;Comparison Table&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Aspect&lt;/th&gt;
&lt;th&gt;Circuit Switching&lt;/th&gt;
&lt;th&gt;Packet Switching&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Connection setup&lt;/td&gt;
&lt;td&gt;Requires an explicit call-setup phase (signaling) before any data flows&lt;/td&gt;
&lt;td&gt;No setup phase; data is sent as soon as packets are ready&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Path allocation&lt;/td&gt;
&lt;td&gt;A fixed end-to-end path is established and used for the whole session&lt;/td&gt;
&lt;td&gt;No fixed path; each packet is routed hop-by-hop and may take a different route&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Resource reservation&lt;/td&gt;
&lt;td&gt;Bandwidth is exclusively reserved, so idle time on the circuit is wasted&lt;/td&gt;
&lt;td&gt;Bandwidth is statistically multiplexed and shared among many flows&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Data transfer format&lt;/td&gt;
&lt;td&gt;Continuous stream of data sent in the order it was generated&lt;/td&gt;
&lt;td&gt;Data split into discrete packets, each carrying its own header for routing&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Latency and jitter&lt;/td&gt;
&lt;td&gt;Predictable, constant latency once the circuit is established&lt;/td&gt;
&lt;td&gt;Variable latency and jitter caused by queuing and differing routes&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Ordering and reliability&lt;/td&gt;
&lt;td&gt;Data always arrives in the order sent, since the path never changes&lt;/td&gt;
&lt;td&gt;Packets can arrive out of order or be lost, requiring reassembly/retransmission&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Failure handling&lt;/td&gt;
&lt;td&gt;A link failure breaks the whole call, forcing re-establishment&lt;/td&gt;
&lt;td&gt;Traffic can be dynamically rerouted around a failed link&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Session teardown&lt;/td&gt;
&lt;td&gt;An explicit signal releases the reserved circuit when the call ends&lt;/td&gt;
&lt;td&gt;No teardown needed; the flow simply stops when packets stop being sent&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="key-differences"&gt;Key Differences&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Circuit switching reserves a &lt;strong class="kw"&gt;dedicated path&lt;/strong&gt; for the whole session; packet switching has no fixed path at all&lt;/li&gt;
&lt;li&gt;Circuit switching wastes idle capacity through exclusive reservation, while packet switching relies on &lt;strong class="kw"&gt;statistical multiplexing&lt;/strong&gt; to share bandwidth&lt;/li&gt;
&lt;li&gt;Packets can be independently &lt;strong class="kw"&gt;rerouted&lt;/strong&gt; around failures, while a circuit failure kills the entire call&lt;/li&gt;
&lt;li&gt;Circuit switching guarantees ordered, steady-latency delivery; packet switching risks &lt;strong class="kw"&gt;out-of-order&lt;/strong&gt; arrival and jitter&lt;/li&gt;
&lt;li&gt;A circuit needs an explicit &lt;strong class="kw"&gt;call setup&lt;/strong&gt; phase before data flows, while packet switching starts transmitting immediately&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="when-to-use-each"&gt;When to Use Each&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Circuit Switching&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>Full Duplex vs Half Duplex: Simultaneous vs Alternating Communication</title><link>https://comparison.metacog.co.kr/posts/2026-08-03-full-duplex-vs-half-duplex-simultaneous-vs-alternating-commu/</link><pubDate>Sat, 01 Aug 2026 20:12:00 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-08-03-full-duplex-vs-half-duplex-simultaneous-vs-alternating-commu/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;Full duplex and half duplex describe how a communication link handles data flowing in both directions. A &lt;strong class="kw"&gt;full duplex&lt;/strong&gt; link sends and receives at the same time over independent paths, while a &lt;strong class="kw"&gt;half duplex&lt;/strong&gt; link shares a single channel and must alternate between sending and receiving. The distinction determines whether devices collide, how much of the link&amp;rsquo;s bandwidth is usable, and how much delay is added when a device switches from listening to talking.&lt;/p&gt;</description></item><item><title>MAC Address vs IP Address: Hardware Identity vs Network Location</title><link>https://comparison.metacog.co.kr/posts/2026-08-03-mac-address-vs-ip-address-hardware-identity-vs-network-locat/</link><pubDate>Sat, 01 Aug 2026 20:11:00 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-08-03-mac-address-vs-ip-address-hardware-identity-vs-network-locat/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;A MAC address is a &lt;strong class="kw"&gt;hardware identifier&lt;/strong&gt; burned into a network interface card and used to move frames across a single local link. An IP address is a &lt;strong class="kw"&gt;logical network address&lt;/strong&gt; assigned to a device and used to route packets across interconnected networks, including the internet. They operate at different OSI layers, working together to get data from one physical wire to a destination anywhere in the world.&lt;/p&gt;
&lt;h2 id="comparison-diagram"&gt;Comparison Diagram&lt;/h2&gt;
&lt;div class="compare-diagram"&gt;
&lt;svg viewBox="0 0 640 360" xmlns="http://www.w3.org/2000/svg"&gt;&lt;rect x="40" y="140" width="110" height="60" rx="4" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="95" y="165" text-anchor="middle" style="fill:var(--primary)" font-size="14" font-weight="bold"&gt;Host A&lt;/text&gt;&lt;text x="95" y="183" text-anchor="middle" style="fill:var(--content)" font-size="11"&gt;IP 10.0.0.5&lt;/text&gt;&lt;rect x="265" y="140" width="110" height="60" rx="4" style="fill:none;stroke:var(--border)" stroke-width="1.5"/&gt;&lt;text x="320" y="165" text-anchor="middle" style="fill:var(--content)" font-size="14" font-weight="bold"&gt;Router&lt;/text&gt;&lt;text x="320" y="183" text-anchor="middle" style="fill:var(--secondary)" font-size="10"&gt;rewrites MAC per hop&lt;/text&gt;&lt;rect x="490" y="140" width="110" height="60" rx="4" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="545" y="165" text-anchor="middle" style="fill:var(--primary)" font-size="14" font-weight="bold"&gt;Host B&lt;/text&gt;&lt;text x="545" y="183" text-anchor="middle" style="fill:var(--content)" font-size="11"&gt;IP 10.0.0.9&lt;/text&gt;&lt;line x1="150" y1="170" x2="265" y2="170" style="stroke:var(--compare-a)" stroke-width="2"/&gt;&lt;polygon points="265,170 255,165 255,175" style="fill:var(--compare-a)"/&gt;&lt;text x="207" y="128" text-anchor="middle" style="fill:var(--compare-a)" font-size="10"&gt;MAC AA:01 to MAC RR:01&lt;/text&gt;&lt;line x1="375" y1="170" x2="490" y2="170" style="stroke:var(--compare-b)" stroke-width="2"/&gt;&lt;polygon points="490,170 480,165 480,175" style="fill:var(--compare-b)"/&gt;&lt;text x="432" y="128" text-anchor="middle" style="fill:var(--compare-b)" font-size="10"&gt;MAC RR:02 to MAC BB:01&lt;/text&gt;&lt;text x="320" y="108" text-anchor="middle" style="fill:var(--secondary)" font-size="11"&gt;Layer 2 - MAC changes at every hop&lt;/text&gt;&lt;line x1="95" y1="260" x2="545" y2="260" style="stroke:var(--primary)" stroke-dasharray="6,4" stroke-width="2"/&gt;&lt;polygon points="545,260 535,255 535,265" style="fill:var(--primary)"/&gt;&lt;text x="320" y="245" text-anchor="middle" style="fill:var(--primary)" font-size="12" font-weight="bold"&gt;IP 10.0.0.5 to 10.0.0.9&lt;/text&gt;&lt;text x="320" y="280" text-anchor="middle" style="fill:var(--secondary)" font-size="11"&gt;Layer 3 - IP stays constant end-to-end&lt;/text&gt;&lt;line x1="95" y1="200" x2="95" y2="260" style="stroke:var(--border)" stroke-dasharray="2,3" stroke-width="1"/&gt;&lt;line x1="545" y1="200" x2="545" y2="260" style="stroke:var(--border)" stroke-dasharray="2,3" stroke-width="1"/&gt;&lt;text x="320" y="330" text-anchor="middle" style="fill:var(--content)" font-size="13" font-weight="bold"&gt;MAC = local hop identity; IP = end-to-end address&lt;/text&gt;&lt;/svg&gt;
&lt;/div&gt;
&lt;h2 id="comparison-table"&gt;Comparison Table&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Aspect&lt;/th&gt;
&lt;th&gt;MAC Address&lt;/th&gt;
&lt;th&gt;IP Address&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;OSI layer&lt;/td&gt;
&lt;td&gt;Layer 2 (Data Link)&lt;/td&gt;
&lt;td&gt;Layer 3 (Network)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Format&lt;/td&gt;
&lt;td&gt;48-bit hex, e.g. 00:1A:2B:3C:4D:5E&lt;/td&gt;
&lt;td&gt;32-bit (IPv4) or 128-bit (IPv6) dotted/colon notation&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Assignment&lt;/td&gt;
&lt;td&gt;Burned in by the NIC manufacturer at production&lt;/td&gt;
&lt;td&gt;Assigned by a network admin or DHCP server&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Structure&lt;/td&gt;
&lt;td&gt;Flat, no hierarchy — vendor prefix plus serial&lt;/td&gt;
&lt;td&gt;Hierarchical — network portion plus host portion for routing&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Persistence&lt;/td&gt;
&lt;td&gt;Fixed to the physical interface (though spoofable)&lt;/td&gt;
&lt;td&gt;Can change when a device moves to a different network&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Role in delivery&lt;/td&gt;
&lt;td&gt;Identifies the next-hop device on the local link&lt;/td&gt;
&lt;td&gt;Identifies source and destination across the whole path&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Behavior across hops&lt;/td&gt;
&lt;td&gt;Rewritten by every router at each hop&lt;/td&gt;
&lt;td&gt;Preserved end-to-end (barring NAT)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Resolution mechanism&lt;/td&gt;
&lt;td&gt;Discovered via ARP (IPv4) or NDP (IPv6)&lt;/td&gt;
&lt;td&gt;Discovered via DNS for hostnames&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="key-differences"&gt;Key Differences&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;MAC address operates at &lt;strong class="kw"&gt;Layer 2&lt;/strong&gt; while IP address operates at &lt;strong class="kw"&gt;Layer 3&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;MAC is &lt;strong class="kw"&gt;burned into hardware&lt;/strong&gt; by the manufacturer, whereas IP is &lt;strong class="kw"&gt;assigned by the network&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;A frame&amp;rsquo;s MAC addresses are &lt;strong class="kw"&gt;rewritten at every hop&lt;/strong&gt;, but the packet&amp;rsquo;s IP addresses stay &lt;strong class="kw"&gt;end-to-end constant&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong class="kw"&gt;ARP&lt;/strong&gt; maps an IP address to the MAC address needed for delivery on the local segment.&lt;/li&gt;
&lt;li&gt;MAC addresses are &lt;strong class="kw"&gt;flat&lt;/strong&gt; with no structure, while IP addresses are &lt;strong class="kw"&gt;hierarchical&lt;/strong&gt; to support routing.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="when-to-use-each"&gt;When to Use Each&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;MAC Address&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>Ping vs Traceroute: Testing Reachability vs Mapping the Path</title><link>https://comparison.metacog.co.kr/posts/2026-08-03-ping-vs-traceroute-testing-reachability-vs-mapping-the-path/</link><pubDate>Sat, 01 Aug 2026 20:10:00 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-08-03-ping-vs-traceroute-testing-reachability-vs-mapping-the-path/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;Ping and Traceroute are both ICMP-based diagnostic tools, but they answer different questions: ping tests &lt;strong class="kw"&gt;reachability&lt;/strong&gt; between two hosts, while traceroute reveals the &lt;strong class="kw"&gt;path&lt;/strong&gt; packets take to get there. Ping reports simple round-trip latency and packet loss; traceroute manipulates TTL values to map every router hop along the route.&lt;/p&gt;
&lt;h2 id="comparison-diagram"&gt;Comparison Diagram&lt;/h2&gt;
&lt;div class="compare-diagram"&gt;
&lt;svg viewBox="0 0 640 360" xmlns="http://www.w3.org/2000/svg"&gt;&lt;defs&gt;&lt;marker id="arrowA" viewBox="0 0 10 10" refX="8" refY="5" markerWidth="6" markerHeight="6" orient="auto-start-reverse"&gt;&lt;path d="M0,0 L10,5 L0,10 z" style="fill:var(--compare-a)"/&gt;&lt;/marker&gt;&lt;marker id="arrowB" viewBox="0 0 10 10" refX="8" refY="5" markerWidth="6" markerHeight="6" orient="auto-start-reverse"&gt;&lt;path d="M0,0 L10,5 L0,10 z" style="fill:var(--compare-b)"/&gt;&lt;/marker&gt;&lt;/defs&gt;&lt;line x1="320" y1="20" x2="320" y2="340" style="stroke:var(--border)" stroke-width="1" stroke-dasharray="4 4"/&gt;&lt;text x="160" y="28" text-anchor="middle" style="fill:var(--primary)" font-size="18" font-weight="bold"&gt;PING&lt;/text&gt;&lt;text x="480" y="28" text-anchor="middle" style="fill:var(--primary)" font-size="18" font-weight="bold"&gt;TRACEROUTE&lt;/text&gt;&lt;circle cx="70" cy="200" r="20" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="70" y="204" text-anchor="middle" style="fill:var(--content)" font-size="10"&gt;Client&lt;/text&gt;&lt;circle cx="250" cy="200" r="20" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="250" y="204" text-anchor="middle" style="fill:var(--content)" font-size="10"&gt;Server&lt;/text&gt;&lt;line x1="88" y1="160" x2="232" y2="160" style="stroke:var(--compare-a)" stroke-width="1.5" marker-end="url(#arrowA)"/&gt;&lt;text x="160" y="150" text-anchor="middle" style="fill:var(--content)" font-size="11"&gt;Echo Request&lt;/text&gt;&lt;line x1="232" y1="240" x2="88" y2="240" style="stroke:var(--compare-a)" stroke-width="1.5" stroke-dasharray="4 3" marker-end="url(#arrowA)"/&gt;&lt;text x="160" y="258" text-anchor="middle" style="fill:var(--content)" font-size="11"&gt;Echo Reply&lt;/text&gt;&lt;text x="160" y="300" text-anchor="middle" style="fill:var(--secondary)" font-size="11"&gt;One round trip → RTT to destination&lt;/text&gt;&lt;circle cx="370" cy="290" r="18" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="370" y="294" text-anchor="middle" style="fill:var(--content)" font-size="9"&gt;Client&lt;/text&gt;&lt;circle cx="430" cy="230" r="13" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="430" y="234" text-anchor="middle" style="fill:var(--content)" font-size="9"&gt;R1&lt;/text&gt;&lt;circle cx="480" cy="180" r="13" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="480" y="184" text-anchor="middle" style="fill:var(--content)" font-size="9"&gt;R2&lt;/text&gt;&lt;circle cx="530" cy="130" r="13" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="530" y="134" text-anchor="middle" style="fill:var(--content)" font-size="9"&gt;R3&lt;/text&gt;&lt;circle cx="590" cy="80" r="16" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="590" y="84" text-anchor="middle" style="fill:var(--content)" font-size="9"&gt;Srv&lt;/text&gt;&lt;line x1="388" y1="276" x2="418" y2="240" style="stroke:var(--compare-b)" stroke-width="1.5" marker-end="url(#arrowB)"/&gt;&lt;text x="385" y="220" style="fill:var(--secondary)" font-size="9"&gt;TTL=1&lt;/text&gt;&lt;line x1="388" y1="276" x2="468" y2="190" style="stroke:var(--compare-b)" stroke-width="1.5" marker-end="url(#arrowB)"/&gt;&lt;text x="440" y="170" style="fill:var(--secondary)" font-size="9"&gt;TTL=2&lt;/text&gt;&lt;line x1="388" y1="276" x2="518" y2="140" style="stroke:var(--compare-b)" stroke-width="1.5" marker-end="url(#arrowB)"/&gt;&lt;text x="490" y="120" style="fill:var(--secondary)" font-size="9"&gt;TTL=3&lt;/text&gt;&lt;line x1="388" y1="276" x2="576" y2="93" style="stroke:var(--compare-b)" stroke-width="1.5" marker-end="url(#arrowB)"/&gt;&lt;text x="545" y="70" style="fill:var(--secondary)" font-size="9"&gt;TTL=4&lt;/text&gt;&lt;line x1="419" y1="242" x2="392" y2="270" style="stroke:var(--compare-b)" stroke-width="1" stroke-dasharray="3 2" marker-end="url(#arrowB)"/&gt;&lt;text x="335" y="258" style="fill:var(--secondary)" font-size="8"&gt;Time Exceeded reply&lt;/text&gt;&lt;text x="480" y="330" text-anchor="middle" style="fill:var(--secondary)" font-size="11"&gt;Each probe's TTL expires one hop further&lt;/text&gt;&lt;/svg&gt;
&lt;/div&gt;
&lt;h2 id="comparison-table"&gt;Comparison Table&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Aspect&lt;/th&gt;
&lt;th&gt;Ping&lt;/th&gt;
&lt;th&gt;Traceroute&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Primary purpose&lt;/td&gt;
&lt;td&gt;Tests whether a host is reachable and measures round-trip latency&lt;/td&gt;
&lt;td&gt;Maps the sequence of routers (hops) a packet crosses to reach a host&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Underlying mechanism&lt;/td&gt;
&lt;td&gt;Sends an ICMP Echo Request and waits for an ICMP Echo Reply&lt;/td&gt;
&lt;td&gt;Sends probes with incrementing TTL, capturing an ICMP Time Exceeded from each hop&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;TTL handling&lt;/td&gt;
&lt;td&gt;Uses a fixed, generous TTL (OS default, e.g. 64 or 128) meant to survive the whole path&lt;/td&gt;
&lt;td&gt;Deliberately starts TTL at 1 and increments it per probe to force expiry at each hop&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Who responds&lt;/td&gt;
&lt;td&gt;Only the final destination host replies&lt;/td&gt;
&lt;td&gt;Every intermediate router along the path replies, plus the destination&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Output produced&lt;/td&gt;
&lt;td&gt;Single or repeated RTT values and a packet loss percentage&lt;/td&gt;
&lt;td&gt;Ordered list of hop addresses with per-hop RTT samples&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Interpreting failure&lt;/td&gt;
&lt;td&gt;No reply means unreachable or blocked, without saying where&lt;/td&gt;
&lt;td&gt;A missing hop reply pinpoints exactly where the path breaks or gets filtered&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Typical runtime&lt;/td&gt;
&lt;td&gt;Fast, usually sub-second to a few seconds for a handful of probes&lt;/td&gt;
&lt;td&gt;Slower, since it waits on timeouts at each hop before moving to the next&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Common blocking issues&lt;/td&gt;
&lt;td&gt;Firewalls dropping ICMP Echo hide the host entirely, showing total silence&lt;/td&gt;
&lt;td&gt;Firewalls dropping Time Exceeded or Echo hide specific hops, shown as * * *&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="key-differences"&gt;Key Differences&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Ping only confirms &lt;strong class="kw"&gt;reachability&lt;/strong&gt; to the final host and reports nothing about the path in between.&lt;/li&gt;
&lt;li&gt;Traceroute exploits &lt;strong class="kw"&gt;TTL expiry&lt;/strong&gt; to make each router along the route reveal itself.&lt;/li&gt;
&lt;li&gt;A ping reply comes from the destination alone; traceroute yields one reply per &lt;strong class="kw"&gt;hop&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Traceroute is inherently slower since it waits on timeouts at every intermediate &lt;strong class="kw"&gt;router&lt;/strong&gt;, not just the endpoint.&lt;/li&gt;
&lt;li&gt;When ICMP is filtered, ping just times out, while traceroute pinpoints the exact &lt;strong class="kw"&gt;blackhole&lt;/strong&gt; hop.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="when-to-use-each"&gt;When to Use Each&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Ping&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>Static Routing vs Dynamic Routing: Manual Paths vs Self-Adapting Networks</title><link>https://comparison.metacog.co.kr/posts/2026-08-03-static-routing-vs-dynamic-routing-manual-paths-vs-self-adapt/</link><pubDate>Sat, 01 Aug 2026 20:09:00 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-08-03-static-routing-vs-dynamic-routing-manual-paths-vs-self-adapt/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;Static routing means an administrator manually enters every route into a router&amp;rsquo;s table, while dynamic routing lets routers automatically discover and adjust paths using a &lt;strong class="kw"&gt;routing protocol&lt;/strong&gt;. The choice comes down to a tradeoff between precise &lt;strong class="kw"&gt;manual control&lt;/strong&gt; and automatic adaptation to network changes.&lt;/p&gt;
&lt;h2 id="comparison-diagram"&gt;Comparison Diagram&lt;/h2&gt;
&lt;div class="compare-diagram"&gt;
&lt;svg viewBox="0 0 640 360" xmlns="http://www.w3.org/2000/svg" font-family="sans-serif"&gt;&lt;line x1="320" y1="10" x2="320" y2="345" style="stroke:var(--border)" stroke-width="1"/&gt;&lt;text x="160" y="24" text-anchor="middle" font-size="15" font-weight="600" style="fill:var(--primary)"&gt;Static Routing&lt;/text&gt;&lt;text x="480" y="24" text-anchor="middle" font-size="15" font-weight="600" style="fill:var(--primary)"&gt;Dynamic Routing&lt;/text&gt;&lt;text x="160" y="44" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;Admin sets a fixed path&lt;/text&gt;&lt;text x="480" y="44" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;Routers exchange updates&lt;/text&gt;&lt;circle cx="160" cy="58" r="7" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;rect x="150" y="66" width="20" height="16" rx="3" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;line x1="160" y1="82" x2="160" y2="92" style="stroke:var(--compare-a)" stroke-width="1.5" stroke-dasharray="2,2"/&gt;&lt;circle cx="60" cy="110" r="16" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="60" y="114" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;A&lt;/text&gt;&lt;circle cx="260" cy="110" r="16" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="260" y="114" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;B&lt;/text&gt;&lt;line x1="78" y1="110" x2="236" y2="110" style="stroke:var(--compare-a)" stroke-width="2"/&gt;&lt;polygon points="236,110 226,105 226,115" style="fill:var(--compare-a)"/&gt;&lt;circle cx="380" cy="110" r="16" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="380" y="114" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;A&lt;/text&gt;&lt;circle cx="580" cy="110" r="16" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="580" y="114" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;B&lt;/text&gt;&lt;circle cx="480" cy="62" r="16" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="480" y="66" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;C&lt;/text&gt;&lt;line x1="394" y1="104" x2="468" y2="72" style="stroke:var(--compare-b)" stroke-width="1.5" stroke-dasharray="4,3"/&gt;&lt;line x1="492" y1="72" x2="566" y2="104" style="stroke:var(--compare-b)" stroke-width="1.5" stroke-dasharray="4,3"/&gt;&lt;line x1="396" y1="110" x2="564" y2="110" style="stroke:var(--compare-b)" stroke-width="1.5" stroke-dasharray="4,3"/&gt;&lt;text x="160" y="165" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;Link A-B fails&lt;/text&gt;&lt;text x="480" y="165" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;Link A-B fails&lt;/text&gt;&lt;circle cx="60" cy="215" r="16" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="60" y="219" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;A&lt;/text&gt;&lt;circle cx="260" cy="215" r="16" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="260" y="219" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;B&lt;/text&gt;&lt;line x1="78" y1="215" x2="150" y2="215" style="stroke:var(--compare-a)" stroke-width="2"/&gt;&lt;line x1="170" y1="215" x2="242" y2="215" style="stroke:var(--compare-a)" stroke-width="2" stroke-dasharray="3,3"/&gt;&lt;line x1="152" y1="207" x2="168" y2="223" style="stroke:var(--border)" stroke-width="2.5"/&gt;&lt;line x1="152" y1="223" x2="168" y2="207" style="stroke:var(--border)" stroke-width="2.5"/&gt;&lt;text x="160" y="255" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;Traffic still sent - blackholed&lt;/text&gt;&lt;circle cx="380" cy="215" r="16" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="380" y="219" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;A&lt;/text&gt;&lt;circle cx="580" cy="215" r="16" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="580" y="219" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;B&lt;/text&gt;&lt;circle cx="480" cy="170" r="16" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="480" y="174" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;C&lt;/text&gt;&lt;line x1="396" y1="215" x2="468" y2="215" style="stroke:var(--border)" stroke-width="2" stroke-dasharray="3,3"/&gt;&lt;line x1="470" y1="207" x2="486" y2="223" style="stroke:var(--border)" stroke-width="2.5"/&gt;&lt;line x1="470" y1="223" x2="486" y2="207" style="stroke:var(--border)" stroke-width="2.5"/&gt;&lt;path d="M 394,204 L 466,178" style="stroke:var(--compare-b);fill:none" stroke-width="2"/&gt;&lt;path d="M 494,178 L 566,204" style="stroke:var(--compare-b);fill:none" stroke-width="2"/&gt;&lt;polygon points="566,204 555,201 559,211" style="fill:var(--compare-b)"/&gt;&lt;text x="480" y="255" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;Auto-reroutes via C&lt;/text&gt;&lt;/svg&gt;
&lt;/div&gt;
&lt;h2 id="comparison-table"&gt;Comparison Table&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Aspect&lt;/th&gt;
&lt;th&gt;Static Routing&lt;/th&gt;
&lt;th&gt;Dynamic Routing&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Configuration&lt;/td&gt;
&lt;td&gt;Manually entered by an administrator on each router&lt;/td&gt;
&lt;td&gt;Learned automatically through a routing protocol (OSPF, EIGRP, BGP, etc.)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Path determination&lt;/td&gt;
&lt;td&gt;Fixed path defined once by the admin; never recalculated&lt;/td&gt;
&lt;td&gt;Computed algorithmically from real-time topology and link metrics&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Reaction to link/topology change&lt;/td&gt;
&lt;td&gt;No detection; route stays configured even if the path is down&lt;/td&gt;
&lt;td&gt;Protocol detects the failure and recalculates automatically&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Convergence time&lt;/td&gt;
&lt;td&gt;Instant to apply, but requires manual intervention to correct&lt;/td&gt;
&lt;td&gt;Seconds to minutes depending on protocol, then self-healing&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Resource overhead&lt;/td&gt;
&lt;td&gt;None - no CPU or bandwidth spent on updates&lt;/td&gt;
&lt;td&gt;Ongoing CPU for computation and bandwidth for update messages&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Scalability&lt;/td&gt;
&lt;td&gt;Impractical beyond a small, stable topology&lt;/td&gt;
&lt;td&gt;Scales to large, frequently changing networks&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Administrative control&lt;/td&gt;
&lt;td&gt;Exact, fully predictable path enforced by the admin&lt;/td&gt;
&lt;td&gt;Path chosen by the protocol based on metrics and policy, less predictable&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="key-differences"&gt;Key Differences&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Static routes are entered by hand; dynamic routes are learned via a &lt;strong class="kw"&gt;routing protocol&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Static routing has zero ongoing &lt;strong class="kw"&gt;CPU and bandwidth&lt;/strong&gt; cost; dynamic routing continuously spends both on updates.&lt;/li&gt;
&lt;li&gt;Only dynamic routing performs automatic &lt;strong class="kw"&gt;failover&lt;/strong&gt; when a link goes down.&lt;/li&gt;
&lt;li&gt;Static routing gives exact &lt;strong class="kw"&gt;predictable paths&lt;/strong&gt;; dynamic routing adapts them based on live metrics.&lt;/li&gt;
&lt;li&gt;Static doesn&amp;rsquo;t scale past a handful of routers; dynamic routing is required for &lt;strong class="kw"&gt;large networks&lt;/strong&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="when-to-use-each"&gt;When to Use Each&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Static Routing&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>OSI Model vs TCP/IP Model: 7 Conceptual Layers vs 4 Practical Layers</title><link>https://comparison.metacog.co.kr/posts/2026-08-03-osi-model-vs-tcp-ip-model-7-conceptual-layers-vs-4-practical/</link><pubDate>Sat, 01 Aug 2026 20:08:00 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-08-03-osi-model-vs-tcp-ip-model-7-conceptual-layers-vs-4-practical/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;The OSI Model is a conceptual &lt;strong class="kw"&gt;seven-layer framework&lt;/strong&gt; that ISO designed to standardize how network communication should be described, while the TCP/IP Model is the &lt;strong class="kw"&gt;four-layer protocol suite&lt;/strong&gt; that actually powers the internet. Real devices implement TCP/IP directly, but engineers still borrow OSI&amp;rsquo;s vocabulary to reason about and troubleshoot problems layer by layer.&lt;/p&gt;
&lt;h2 id="comparison-diagram"&gt;Comparison Diagram&lt;/h2&gt;
&lt;div class="compare-diagram"&gt;
&lt;svg viewBox="0 0 640 360" xmlns="http://www.w3.org/2000/svg"&gt;&lt;text x="160" y="28" text-anchor="middle" font-size="16" font-weight="600" style="fill:var(--primary)"&gt;OSI Model&lt;/text&gt;&lt;text x="480" y="28" text-anchor="middle" font-size="16" font-weight="600" style="fill:var(--primary)"&gt;TCP/IP Model&lt;/text&gt;&lt;g&gt;&lt;rect x="60" y="50" width="200" height="40" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="160" y="75" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;7. Application&lt;/text&gt;&lt;rect x="60" y="90" width="200" height="40" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="160" y="115" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;6. Presentation&lt;/text&gt;&lt;rect x="60" y="130" width="200" height="40" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="160" y="155" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;5. Session&lt;/text&gt;&lt;rect x="60" y="170" width="200" height="40" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="160" y="195" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;4. Transport&lt;/text&gt;&lt;rect x="60" y="210" width="200" height="40" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="160" y="235" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;3. Network&lt;/text&gt;&lt;rect x="60" y="250" width="200" height="40" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="160" y="275" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;2. Data Link&lt;/text&gt;&lt;rect x="60" y="290" width="200" height="40" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="160" y="315" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;1. Physical&lt;/text&gt;&lt;/g&gt;&lt;g&gt;&lt;rect x="380" y="50" width="200" height="120" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="480" y="114" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Application&lt;/text&gt;&lt;rect x="380" y="170" width="200" height="40" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="480" y="195" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Transport&lt;/text&gt;&lt;rect x="380" y="210" width="200" height="40" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="480" y="235" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Internet&lt;/text&gt;&lt;rect x="380" y="250" width="200" height="80" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="480" y="294" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Network Access&lt;/text&gt;&lt;/g&gt;&lt;g style="stroke:var(--border)" stroke-width="1" stroke-dasharray="3,3"&gt;&lt;line x1="260" y1="90" x2="380" y2="50"/&gt;&lt;line x1="260" y1="170" x2="380" y2="170"/&gt;&lt;line x1="260" y1="210" x2="380" y2="210"/&gt;&lt;line x1="260" y1="250" x2="380" y2="250"/&gt;&lt;line x1="260" y1="290" x2="380" y2="250"/&gt;&lt;line x1="260" y1="330" x2="380" y2="330"/&gt;&lt;/g&gt;&lt;/svg&gt;
&lt;/div&gt;
&lt;h2 id="comparison-table"&gt;Comparison Table&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Aspect&lt;/th&gt;
&lt;th&gt;OSI Model&lt;/th&gt;
&lt;th&gt;TCP/IP Model&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Purpose&lt;/td&gt;
&lt;td&gt;Theoretical reference model for describing how network communication should work&lt;/td&gt;
&lt;td&gt;Practical protocol suite that actually runs the internet&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Layer count&lt;/td&gt;
&lt;td&gt;7 layers&lt;/td&gt;
&lt;td&gt;4 layers (sometimes taught as 5)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Layer structure&lt;/td&gt;
&lt;td&gt;Application, Presentation, Session, Transport, Network, Data Link, Physical&lt;/td&gt;
&lt;td&gt;Application, Transport, Internet, Network Access&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Development origin&lt;/td&gt;
&lt;td&gt;Designed by ISO in the late 1970s/80s before matching protocols existed&lt;/td&gt;
&lt;td&gt;Grew out of DARPA&amp;rsquo;s ARPANET; protocols came first, the model was described afterward&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Protocol coupling&lt;/td&gt;
&lt;td&gt;Layers defined independently of any specific protocol&lt;/td&gt;
&lt;td&gt;Layers map directly onto real protocols like IP, TCP, and HTTP&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Encapsulation granularity&lt;/td&gt;
&lt;td&gt;Splits presentation and session concerns into their own distinct layers&lt;/td&gt;
&lt;td&gt;Folds presentation and session functions into the single Application layer&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Real-world adoption&lt;/td&gt;
&lt;td&gt;Rarely implemented exactly as specified; used mainly as a teaching and reference framework&lt;/td&gt;
&lt;td&gt;Implemented in essentially every networked device and across the internet&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Troubleshooting use&lt;/td&gt;
&lt;td&gt;Provides layer-by-layer vocabulary for isolating where a problem occurs&lt;/td&gt;
&lt;td&gt;Maps directly to the tools and protocols engineers actually configure and debug&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="key-differences"&gt;Key Differences&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;OSI has &lt;strong class="kw"&gt;seven layers&lt;/strong&gt; while TCP/IP condenses the same concerns into &lt;strong class="kw"&gt;four layers&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;OSI is a &lt;strong class="kw"&gt;theoretical reference model&lt;/strong&gt;; TCP/IP is the &lt;strong class="kw"&gt;actual protocol suite&lt;/strong&gt; running the internet&lt;/li&gt;
&lt;li&gt;OSI separates Session and Presentation into distinct layers; TCP/IP merges them into one &lt;strong class="kw"&gt;Application layer&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;TCP/IP&amp;rsquo;s protocols were built first and the model described them afterward, while OSI&amp;rsquo;s layers were designed &lt;strong class="kw"&gt;before implementation&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="when-to-use-each"&gt;When to Use Each&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;OSI Model&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>Unicast vs Multicast: One-to-One vs One-to-Many Delivery</title><link>https://comparison.metacog.co.kr/posts/2026-08-03-unicast-vs-multicast-one-to-one-vs-one-to-many-delivery/</link><pubDate>Sat, 01 Aug 2026 20:07:00 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-08-03-unicast-vs-multicast-one-to-one-vs-one-to-many-delivery/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;Unicast and multicast are IP transmission models that differ in how a sender&amp;rsquo;s data reaches its destinations. Unicast sends a &lt;strong class="kw"&gt;dedicated copy&lt;/strong&gt; to each individual recipient, while multicast sends a &lt;strong class="kw"&gt;single stream&lt;/strong&gt; that network devices replicate only where delivery paths actually diverge. The choice shapes bandwidth usage, routing complexity, and how receivers subscribe to traffic.&lt;/p&gt;
&lt;h2 id="comparison-diagram"&gt;Comparison Diagram&lt;/h2&gt;
&lt;div class="compare-diagram"&gt;
&lt;svg viewBox="0 0 640 360" xmlns="http://www.w3.org/2000/svg"&gt;&lt;line x1="320" y1="20" x2="320" y2="340" style="stroke:var(--border)" stroke-width="1.5" stroke-dasharray="4 4"/&gt;&lt;text x="160" y="32" text-anchor="middle" style="fill:var(--primary)" font-size="18" font-weight="bold"&gt;Unicast&lt;/text&gt;&lt;text x="480" y="32" text-anchor="middle" style="fill:var(--primary)" font-size="18" font-weight="bold"&gt;Multicast&lt;/text&gt;&lt;rect x="50" y="150" width="80" height="40" rx="4" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="90" y="174" text-anchor="middle" style="fill:var(--content)" font-size="13"&gt;Sender&lt;/text&gt;&lt;rect x="230" y="60" width="70" height="35" rx="4" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="265" y="82" text-anchor="middle" style="fill:var(--content)" font-size="12"&gt;R1&lt;/text&gt;&lt;rect x="230" y="152" width="70" height="35" rx="4" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="265" y="174" text-anchor="middle" style="fill:var(--content)" font-size="12"&gt;R2&lt;/text&gt;&lt;rect x="230" y="245" width="70" height="35" rx="4" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="265" y="267" text-anchor="middle" style="fill:var(--content)" font-size="12"&gt;R3&lt;/text&gt;&lt;line x1="130" y1="162" x2="230" y2="78" style="stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;line x1="130" y1="170" x2="230" y2="170" style="stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;line x1="130" y1="178" x2="230" y2="262" style="stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="160" y="310" text-anchor="middle" style="fill:var(--secondary)" font-size="11"&gt;3 separate packet copies&lt;/text&gt;&lt;text x="160" y="324" text-anchor="middle" style="fill:var(--secondary)" font-size="11"&gt;sent end-to-end&lt;/text&gt;&lt;rect x="370" y="150" width="80" height="40" rx="4" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="410" y="174" text-anchor="middle" style="fill:var(--content)" font-size="13"&gt;Sender&lt;/text&gt;&lt;line x1="450" y1="170" x2="484" y2="170" style="stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;circle cx="490" cy="170" r="6" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;line x1="496" y1="168" x2="555" y2="78" style="stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;line x1="496" y1="170" x2="555" y2="170" style="stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;line x1="496" y1="172" x2="555" y2="262" style="stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;rect x="555" y="60" width="70" height="35" rx="4" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="590" y="82" text-anchor="middle" style="fill:var(--content)" font-size="12"&gt;R1&lt;/text&gt;&lt;rect x="555" y="152" width="70" height="35" rx="4" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="590" y="174" text-anchor="middle" style="fill:var(--content)" font-size="12"&gt;R2&lt;/text&gt;&lt;rect x="555" y="245" width="70" height="35" rx="4" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="590" y="267" text-anchor="middle" style="fill:var(--content)" font-size="12"&gt;R3&lt;/text&gt;&lt;text x="480" y="310" text-anchor="middle" style="fill:var(--secondary)" font-size="11"&gt;single stream, replicated&lt;/text&gt;&lt;text x="480" y="324" text-anchor="middle" style="fill:var(--secondary)" font-size="11"&gt;only at the branch point&lt;/text&gt;&lt;/svg&gt;
&lt;/div&gt;
&lt;h2 id="comparison-table"&gt;Comparison Table&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Aspect&lt;/th&gt;
&lt;th&gt;Unicast&lt;/th&gt;
&lt;th&gt;Multicast&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Addressing model&lt;/td&gt;
&lt;td&gt;One-to-one; packet is addressed to a single destination IP&lt;/td&gt;
&lt;td&gt;One-to-many; packet is addressed to a shared multicast group IP&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Sender behavior&lt;/td&gt;
&lt;td&gt;Sends a separate copy of the data for each recipient&lt;/td&gt;
&lt;td&gt;Sends one copy regardless of how many receivers exist&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Network replication&lt;/td&gt;
&lt;td&gt;No replication; each copy travels its own end-to-end path&lt;/td&gt;
&lt;td&gt;Routers/switches replicate the packet only at points where paths diverge&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Receiver participation&lt;/td&gt;
&lt;td&gt;Implicit; determined solely by the destination address&lt;/td&gt;
&lt;td&gt;Explicit; hosts must join the group (IGMP/MLD membership)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Bandwidth scaling&lt;/td&gt;
&lt;td&gt;Grows linearly with the number of receivers&lt;/td&gt;
&lt;td&gt;Stays roughly constant on the sender&amp;rsquo;s link as receivers grow&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Routing requirements&lt;/td&gt;
&lt;td&gt;Standard unicast routing (OSPF, BGP, static routes)&lt;/td&gt;
&lt;td&gt;Requires multicast-aware routing (PIM-SM/DM plus IGMP)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Delivery reliability&lt;/td&gt;
&lt;td&gt;Can run over TCP for guaranteed, ordered delivery&lt;/td&gt;
&lt;td&gt;Almost always UDP-based, with no built-in delivery guarantee&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Typical use cases&lt;/td&gt;
&lt;td&gt;Web browsing, file transfer, email, SSH&lt;/td&gt;
&lt;td&gt;Live video/audio streaming, market data feeds, routing protocol updates&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="key-differences"&gt;Key Differences&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Unicast requires a separate &lt;strong class="kw"&gt;packet copy&lt;/strong&gt; per receiver; multicast needs only one.&lt;/li&gt;
&lt;li&gt;Multicast pushes replication into the &lt;strong class="kw"&gt;network fabric&lt;/strong&gt; instead of the sender.&lt;/li&gt;
&lt;li&gt;Multicast receivers must &lt;strong class="kw"&gt;explicitly join&lt;/strong&gt; a group via IGMP before traffic arrives.&lt;/li&gt;
&lt;li&gt;Unicast bandwidth &lt;strong class="kw"&gt;scales linearly&lt;/strong&gt; with recipients; multicast stays flat.&lt;/li&gt;
&lt;li&gt;Multicast typically rides over &lt;strong class="kw"&gt;UDP&lt;/strong&gt;, sacrificing delivery guarantees for efficiency.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="when-to-use-each"&gt;When to Use Each&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Unicast&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>Subnet vs VLAN: Layer 3 IP Segmentation vs Layer 2 Port Segmentation</title><link>https://comparison.metacog.co.kr/posts/2026-08-03-subnet-vs-vlan-layer-3-ip-segmentation-vs-layer-2-port-segme/</link><pubDate>Sat, 01 Aug 2026 20:06:00 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-08-03-subnet-vs-vlan-layer-3-ip-segmentation-vs-layer-2-port-segme/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;A subnet and a VLAN both carve a large network into smaller, more manageable pieces, but they operate at different layers and are configured in different places. A &lt;strong class="kw"&gt;subnet&lt;/strong&gt; divides IP address space at Layer 3 based on address range and mask, independent of physical wiring, while a &lt;strong class="kw"&gt;VLAN&lt;/strong&gt; divides switch ports at Layer 2, creating separate broadcast domains on shared physical hardware. In most enterprise designs the two are paired one-to-one, but knowing which layer each governs matters for troubleshooting, security, and scaling.&lt;/p&gt;</description></item><item><title>Switch vs Router: Layer 2 Switching vs Layer 3 Routing</title><link>https://comparison.metacog.co.kr/posts/2026-08-03-switch-vs-router-layer-2-switching-vs-layer-3-routing/</link><pubDate>Sat, 01 Aug 2026 20:05:00 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-08-03-switch-vs-router-layer-2-switching-vs-layer-3-routing/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;A switch connects devices within a single network by forwarding traffic based on &lt;strong class="kw"&gt;MAC addresses&lt;/strong&gt;, while a router connects separate networks together by forwarding traffic based on &lt;strong class="kw"&gt;IP addresses&lt;/strong&gt;. Plugging a device into the wrong one is a common source of confusion — one expands a LAN, the other bridges LANs to each other or to the internet.&lt;/p&gt;
&lt;h2 id="comparison-diagram"&gt;Comparison Diagram&lt;/h2&gt;
&lt;div class="compare-diagram"&gt;
&lt;svg viewBox="0 0 640 360" xmlns="http://www.w3.org/2000/svg"&gt;&lt;text x="160" y="35" text-anchor="middle" style="fill:var(--primary)" font-size="20" font-weight="bold"&gt;Switch&lt;/text&gt;&lt;text x="480" y="35" text-anchor="middle" style="fill:var(--primary)" font-size="20" font-weight="bold"&gt;Router&lt;/text&gt;&lt;rect x="20" y="55" width="280" height="260" rx="8" style="fill:none;stroke:var(--border)" stroke-width="1.5" stroke-dasharray="6,4"/&gt;&lt;text x="160" y="75" text-anchor="middle" style="fill:var(--secondary)" font-size="12"&gt;Single broadcast domain&lt;/text&gt;&lt;rect x="130" y="165" width="60" height="30" rx="4" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="160" y="185" text-anchor="middle" style="fill:var(--content)" font-size="12"&gt;Switch&lt;/text&gt;&lt;circle cx="60" cy="100" r="18" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="60" y="104" text-anchor="middle" style="fill:var(--content)" font-size="10"&gt;PC1&lt;/text&gt;&lt;circle cx="260" cy="100" r="18" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="260" y="104" text-anchor="middle" style="fill:var(--content)" font-size="10"&gt;PC2&lt;/text&gt;&lt;circle cx="160" cy="280" r="18" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="160" y="284" text-anchor="middle" style="fill:var(--content)" font-size="10"&gt;PC3&lt;/text&gt;&lt;line x1="70" y1="112" x2="140" y2="172" style="stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;line x1="250" y1="112" x2="180" y2="172" style="stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;line x1="160" y1="262" x2="160" y2="195" style="stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="160" y="330" text-anchor="middle" style="fill:var(--secondary)" font-size="11"&gt;Forwards by MAC address&lt;/text&gt;&lt;rect x="330" y="60" width="110" height="90" rx="8" style="fill:none;stroke:var(--border)" stroke-width="1.5" stroke-dasharray="6,4"/&gt;&lt;text x="385" y="78" text-anchor="middle" style="fill:var(--secondary)" font-size="10"&gt;10.0.1.0/24&lt;/text&gt;&lt;circle cx="360" cy="115" r="14" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="360" y="118" text-anchor="middle" style="fill:var(--content)" font-size="9"&gt;PC&lt;/text&gt;&lt;circle cx="410" cy="115" r="14" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="410" y="118" text-anchor="middle" style="fill:var(--content)" font-size="9"&gt;PC&lt;/text&gt;&lt;rect x="520" y="60" width="100" height="90" rx="8" style="fill:none;stroke:var(--border)" stroke-width="1.5" stroke-dasharray="6,4"/&gt;&lt;text x="570" y="78" text-anchor="middle" style="fill:var(--secondary)" font-size="10"&gt;Internet&lt;/text&gt;&lt;circle cx="570" cy="115" r="16" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="570" y="118" text-anchor="middle" style="fill:var(--content)" font-size="9"&gt;WAN&lt;/text&gt;&lt;rect x="430" y="195" width="90" height="40" rx="4" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="475" y="219" text-anchor="middle" style="fill:var(--content)" font-size="12"&gt;Router&lt;/text&gt;&lt;line x1="390" y1="150" x2="450" y2="197" style="stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;line x1="560" y1="150" x2="500" y2="197" style="stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="480" y="330" text-anchor="middle" style="fill:var(--secondary)" font-size="11"&gt;Forwards by IP address, links networks&lt;/text&gt;&lt;/svg&gt;
&lt;/div&gt;
&lt;h2 id="comparison-table"&gt;Comparison Table&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Aspect&lt;/th&gt;
&lt;th&gt;Switch&lt;/th&gt;
&lt;th&gt;Router&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;OSI layer&lt;/td&gt;
&lt;td&gt;Layer 2 (Data Link)&lt;/td&gt;
&lt;td&gt;Layer 3 (Network)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Addressing used&lt;/td&gt;
&lt;td&gt;MAC addresses&lt;/td&gt;
&lt;td&gt;IP addresses&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Forwarding table&lt;/td&gt;
&lt;td&gt;MAC address table (CAM table), learned automatically&lt;/td&gt;
&lt;td&gt;Routing table, built via static routes or routing protocols&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Broadcast domain&lt;/td&gt;
&lt;td&gt;Devices share one broadcast domain (unless VLANs are configured)&lt;/td&gt;
&lt;td&gt;Separates traffic into distinct broadcast domains per interface&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Typical placement&lt;/td&gt;
&lt;td&gt;Connects devices within a single LAN segment&lt;/td&gt;
&lt;td&gt;Connects different networks together, e.g. LAN to LAN or LAN to WAN&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Unknown-destination handling&lt;/td&gt;
&lt;td&gt;Floods frame to all ports in the VLAN when MAC is unknown&lt;/td&gt;
&lt;td&gt;Drops or rejects packets with no matching route&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Built-in services&lt;/td&gt;
&lt;td&gt;Basic switching only, plus optional VLANs/QoS on managed models&lt;/td&gt;
&lt;td&gt;Often includes NAT, DHCP, firewall, and VPN functions&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Typical device&lt;/td&gt;
&lt;td&gt;Cisco Catalyst switch in a wiring closet&lt;/td&gt;
&lt;td&gt;Home router or edge router linking a LAN to an ISP&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="key-differences"&gt;Key Differences&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Switches forward traffic using &lt;strong class="kw"&gt;MAC addresses&lt;/strong&gt; at Layer 2, while routers forward using &lt;strong class="kw"&gt;IP addresses&lt;/strong&gt; at Layer 3.&lt;/li&gt;
&lt;li&gt;A switch keeps connected devices in one &lt;strong class="kw"&gt;broadcast domain&lt;/strong&gt;; a router splits traffic into separate domains.&lt;/li&gt;
&lt;li&gt;Switches &lt;strong class="kw"&gt;flood&lt;/strong&gt; frames to unknown destinations within a VLAN; routers simply drop packets they can&amp;rsquo;t route.&lt;/li&gt;
&lt;li&gt;Routers commonly bundle &lt;strong class="kw"&gt;NAT&lt;/strong&gt; and firewall features that switches don&amp;rsquo;t provide.&lt;/li&gt;
&lt;li&gt;Switches scale port count for a single network; routers scale the number of distinct networks a device can reach.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="when-to-use-each"&gt;When to Use Each&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Switch&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>DNS vs DHCP: Naming the Network vs Configuring It</title><link>https://comparison.metacog.co.kr/posts/2026-08-03-dns-vs-dhcp-naming-the-network-vs-configuring-it/</link><pubDate>Sat, 01 Aug 2026 20:04:00 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-08-03-dns-vs-dhcp-naming-the-network-vs-configuring-it/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;DHCP and DNS are both foundational network services, but they solve different problems in a device&amp;rsquo;s journey onto the network. &lt;strong class="kw"&gt;DHCP&lt;/strong&gt; automatically assigns a device its IP address and network configuration when it joins a subnet, while &lt;strong class="kw"&gt;DNS&lt;/strong&gt; translates human-readable domain names into the IP addresses needed to actually reach other hosts.&lt;/p&gt;
&lt;h2 id="comparison-diagram"&gt;Comparison Diagram&lt;/h2&gt;
&lt;div class="compare-diagram"&gt;
&lt;svg viewBox="0 0 640 360" xmlns="http://www.w3.org/2000/svg"&gt;
&lt;text x="170" y="45" text-anchor="middle" font-size="18" style="fill:var(--primary)"&gt;DHCP&lt;/text&gt;
&lt;text x="490" y="45" text-anchor="middle" font-size="18" style="fill:var(--primary)"&gt;DNS&lt;/text&gt;
&lt;line x1="320" y1="15" x2="320" y2="345" stroke-dasharray="4,4" style="stroke:var(--border)" stroke-width="1"/&gt;
&lt;rect x="40" y="140" width="100" height="50" rx="4" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;
&lt;text x="90" y="169" text-anchor="middle" font-size="11" style="fill:var(--content)"&gt;Client (no IP)&lt;/text&gt;
&lt;rect x="200" y="140" width="100" height="50" rx="4" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;
&lt;text x="250" y="163" text-anchor="middle" font-size="11" style="fill:var(--content)"&gt;DHCP&lt;/text&gt;
&lt;text x="250" y="177" text-anchor="middle" font-size="11" style="fill:var(--content)"&gt;Server&lt;/text&gt;
&lt;line x1="140" y1="155" x2="196" y2="155" style="stroke:var(--compare-a)" stroke-width="1.5"/&gt;
&lt;polygon points="200,155 194,151 194,159" style="fill:var(--compare-a)"/&gt;
&lt;text x="170" y="146" text-anchor="middle" font-size="9" style="fill:var(--secondary)"&gt;DHCPDISCOVER&lt;/text&gt;
&lt;line x1="200" y1="175" x2="144" y2="175" style="stroke:var(--compare-a)" stroke-width="1.5"/&gt;
&lt;polygon points="140,175 146,171 146,179" style="fill:var(--compare-a)"/&gt;
&lt;text x="170" y="197" text-anchor="middle" font-size="9" style="fill:var(--secondary)"&gt;leased IP + gateway&lt;/text&gt;
&lt;text x="170" y="230" text-anchor="middle" font-size="10" style="fill:var(--secondary)"&gt;local subnet, broadcast&lt;/text&gt;
&lt;rect x="360" y="140" width="100" height="50" rx="4" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;
&lt;text x="410" y="169" text-anchor="middle" font-size="11" style="fill:var(--content)"&gt;Client (has IP)&lt;/text&gt;
&lt;rect x="520" y="140" width="100" height="50" rx="4" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;
&lt;text x="570" y="163" text-anchor="middle" font-size="11" style="fill:var(--content)"&gt;DNS&lt;/text&gt;
&lt;text x="570" y="177" text-anchor="middle" font-size="11" style="fill:var(--content)"&gt;Resolver&lt;/text&gt;
&lt;line x1="460" y1="155" x2="516" y2="155" style="stroke:var(--compare-b)" stroke-width="1.5"/&gt;
&lt;polygon points="520,155 514,151 514,159" style="fill:var(--compare-b)"/&gt;
&lt;text x="490" y="146" text-anchor="middle" font-size="9" style="fill:var(--secondary)"&gt;example.com?&lt;/text&gt;
&lt;line x1="520" y1="175" x2="464" y2="175" style="stroke:var(--compare-b)" stroke-width="1.5"/&gt;
&lt;polygon points="460,175 466,171 466,179" style="fill:var(--compare-b)"/&gt;
&lt;text x="490" y="197" text-anchor="middle" font-size="9" style="fill:var(--secondary)"&gt;93.184.216.34&lt;/text&gt;
&lt;text x="490" y="230" text-anchor="middle" font-size="10" style="fill:var(--secondary)"&gt;global, hierarchical&lt;/text&gt;
&lt;text x="170" y="280" text-anchor="middle" font-size="11" style="fill:var(--content)"&gt;gives device an address&lt;/text&gt;
&lt;text x="490" y="280" text-anchor="middle" font-size="11" style="fill:var(--content)"&gt;gives a name an address&lt;/text&gt;
&lt;/svg&gt;
&lt;/div&gt;
&lt;h2 id="comparison-table"&gt;Comparison Table&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Aspect&lt;/th&gt;
&lt;th&gt;DHCP&lt;/th&gt;
&lt;th&gt;DNS&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Primary purpose&lt;/td&gt;
&lt;td&gt;Assigns an IP address and network configuration to a device&lt;/td&gt;
&lt;td&gt;Translates a domain name into an IP address&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Triggered by&lt;/td&gt;
&lt;td&gt;A device connecting or booting onto the network&lt;/td&gt;
&lt;td&gt;An application needing to resolve a hostname&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Transport protocol&lt;/td&gt;
&lt;td&gt;UDP, ports 67 (server) and 68 (client)&lt;/td&gt;
&lt;td&gt;UDP or TCP, port 53&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Discovery mechanism&lt;/td&gt;
&lt;td&gt;Client broadcasts DHCPDISCOVER on the local subnet&lt;/td&gt;
&lt;td&gt;Client sends a unicast query to a configured resolver address&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Data returned&lt;/td&gt;
&lt;td&gt;IP address, subnet mask, default gateway, DNS server list&lt;/td&gt;
&lt;td&gt;IP address (A/AAAA record) or other record types like MX, CNAME, TXT&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;State and validity&lt;/td&gt;
&lt;td&gt;Lease with an expiration time that must be renewed&lt;/td&gt;
&lt;td&gt;Record with a TTL, cached locally then re-queried after expiry&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Scope&lt;/td&gt;
&lt;td&gt;Local network segment or subnet&lt;/td&gt;
&lt;td&gt;Global, hierarchical, distributed across the internet&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="key-differences"&gt;Key Differences&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;DHCP assigns &lt;strong class="kw"&gt;IP addresses&lt;/strong&gt; to devices; DNS resolves &lt;strong class="kw"&gt;domain names&lt;/strong&gt; to those addresses.&lt;/li&gt;
&lt;li&gt;DHCP requests use &lt;strong class="kw"&gt;broadcast&lt;/strong&gt; discovery on the local subnet; DNS clients send &lt;strong class="kw"&gt;unicast queries&lt;/strong&gt; to a configured resolver.&lt;/li&gt;
&lt;li&gt;DHCP assignments are &lt;strong class="kw"&gt;leases&lt;/strong&gt; that expire and renew; DNS answers are &lt;strong class="kw"&gt;cached&lt;/strong&gt; per record TTL.&lt;/li&gt;
&lt;li&gt;DHCP typically hands out the &lt;strong class="kw"&gt;DNS server addresses&lt;/strong&gt; a client should use, linking the two protocols at boot time.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="when-to-use-each"&gt;When to Use Each&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;DHCP&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>IPv4 vs IPv6: 32-bit vs 128-bit Addressing</title><link>https://comparison.metacog.co.kr/posts/2026-08-03-ipv4-vs-ipv6-32-bit-vs-128-bit-addressing/</link><pubDate>Sat, 01 Aug 2026 20:03:00 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-08-03-ipv4-vs-ipv6-32-bit-vs-128-bit-addressing/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;IPv4 and IPv6 are the two versions of the Internet Protocol responsible for addressing and routing packets across networks. IPv4 relies on &lt;strong class="kw"&gt;32-bit addresses&lt;/strong&gt; that ran out of unique combinations, while IPv6 was designed around &lt;strong class="kw"&gt;128-bit addresses&lt;/strong&gt; to give every device a globally unique, non-NAT&amp;rsquo;d address. The distinction matters because it affects address exhaustion, header processing overhead, and whether NAT traversal is required for peer-to-peer connectivity.&lt;/p&gt;
&lt;h2 id="comparison-diagram"&gt;Comparison Diagram&lt;/h2&gt;
&lt;div class="compare-diagram"&gt;
&lt;svg viewBox="0 0 640 360" xmlns="http://www.w3.org/2000/svg"&gt;&lt;text x="157" y="40" text-anchor="middle" font-size="20" font-weight="bold" style="fill:var(--primary)"&gt;IPv4&lt;/text&gt;&lt;text x="477" y="40" text-anchor="middle" font-size="20" font-weight="bold" style="fill:var(--primary)"&gt;IPv6&lt;/text&gt;&lt;g&gt;&lt;rect x="40" y="60" width="55" height="40" rx="4" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="67" y="85" text-anchor="middle" font-size="14" style="fill:var(--content)"&gt;192&lt;/text&gt;&lt;rect x="100" y="60" width="55" height="40" rx="4" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="127" y="85" text-anchor="middle" font-size="14" style="fill:var(--content)"&gt;168&lt;/text&gt;&lt;rect x="160" y="60" width="55" height="40" rx="4" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="187" y="85" text-anchor="middle" font-size="14" style="fill:var(--content)"&gt;1&lt;/text&gt;&lt;rect x="220" y="60" width="55" height="40" rx="4" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="247" y="85" text-anchor="middle" font-size="14" style="fill:var(--content)"&gt;1&lt;/text&gt;&lt;/g&gt;&lt;text x="157" y="118" text-anchor="middle" font-size="12" style="fill:var(--secondary)"&gt;32 bits · dotted-decimal&lt;/text&gt;&lt;g&gt;&lt;rect x="350" y="60" width="30" height="40" rx="3" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="365" y="83" text-anchor="middle" font-size="8" style="fill:var(--content)"&gt;2001&lt;/text&gt;&lt;rect x="382" y="60" width="30" height="40" rx="3" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="397" y="83" text-anchor="middle" font-size="8" style="fill:var(--content)"&gt;0db8&lt;/text&gt;&lt;rect x="414" y="60" width="30" height="40" rx="3" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="429" y="83" text-anchor="middle" font-size="8" style="fill:var(--content)"&gt;85a3&lt;/text&gt;&lt;rect x="446" y="60" width="30" height="40" rx="3" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="461" y="83" text-anchor="middle" font-size="8" style="fill:var(--content)"&gt;0000&lt;/text&gt;&lt;rect x="478" y="60" width="30" height="40" rx="3" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="493" y="83" text-anchor="middle" font-size="8" style="fill:var(--content)"&gt;0000&lt;/text&gt;&lt;rect x="510" y="60" width="30" height="40" rx="3" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="525" y="83" text-anchor="middle" font-size="8" style="fill:var(--content)"&gt;8a2e&lt;/text&gt;&lt;rect x="542" y="60" width="30" height="40" rx="3" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="557" y="83" text-anchor="middle" font-size="8" style="fill:var(--content)"&gt;0370&lt;/text&gt;&lt;rect x="574" y="60" width="30" height="40" rx="3" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="589" y="83" text-anchor="middle" font-size="8" style="fill:var(--content)"&gt;7334&lt;/text&gt;&lt;/g&gt;&lt;text x="477" y="118" text-anchor="middle" font-size="12" style="fill:var(--secondary)"&gt;128 bits · hex colon-notation&lt;/text&gt;&lt;text x="157" y="150" text-anchor="middle" font-size="13" style="fill:var(--content)"&gt;~4.3 billion addresses&lt;/text&gt;&lt;text x="477" y="150" text-anchor="middle" font-size="13" style="fill:var(--content)"&gt;~340 undecillion addresses&lt;/text&gt;&lt;line x1="320" y1="30" x2="320" y2="330" style="stroke:var(--border)" stroke-width="1" stroke-dasharray="4 4"/&gt;&lt;text x="40" y="200" font-size="12" style="fill:var(--secondary)"&gt;Relative address length&lt;/text&gt;&lt;rect x="40" y="215" width="48" height="18" rx="2" style="fill:var(--compare-a);stroke:var(--compare-a)"/&gt;&lt;text x="94" y="228" font-size="12" style="fill:var(--content)"&gt;32 bits (IPv4)&lt;/text&gt;&lt;rect x="40" y="245" width="192" height="18" rx="2" style="fill:var(--compare-b);stroke:var(--compare-b)"/&gt;&lt;text x="238" y="258" font-size="12" style="fill:var(--content)"&gt;128 bits (IPv6) — 4x longer&lt;/text&gt;&lt;g&gt;&lt;rect x="360" y="200" width="240" height="70" rx="6" style="fill:none;stroke:var(--border)" stroke-width="1"/&gt;&lt;text x="480" y="220" text-anchor="middle" font-size="12" style="fill:var(--secondary)"&gt;NAT dependency&lt;/text&gt;&lt;text x="480" y="242" text-anchor="middle" font-size="12" style="fill:var(--compare-a)"&gt;IPv4: needs NAT (scarce space)&lt;/text&gt;&lt;text x="480" y="260" text-anchor="middle" font-size="12" style="fill:var(--compare-b)"&gt;IPv6: end-to-end, no NAT needed&lt;/text&gt;&lt;/g&gt;&lt;/svg&gt;
&lt;/div&gt;
&lt;h2 id="comparison-table"&gt;Comparison Table&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Aspect&lt;/th&gt;
&lt;th&gt;IPv4&lt;/th&gt;
&lt;th&gt;IPv6&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Address length &amp;amp; notation&lt;/td&gt;
&lt;td&gt;32-bit, dotted-decimal (e.g. 192.168.1.1)&lt;/td&gt;
&lt;td&gt;128-bit, hexadecimal colon-separated (e.g. 2001:0db8::7334)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Address space size&lt;/td&gt;
&lt;td&gt;~4.3 billion addresses&lt;/td&gt;
&lt;td&gt;~340 undecillion addresses&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Address assignment&lt;/td&gt;
&lt;td&gt;Manual configuration or DHCP&lt;/td&gt;
&lt;td&gt;Stateless Address Autoconfiguration (SLAAC) or DHCPv6&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Header structure&lt;/td&gt;
&lt;td&gt;Variable-length header with options field and checksum&lt;/td&gt;
&lt;td&gt;Fixed 40-byte header, no checksum, optional extension headers&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;NAT requirement&lt;/td&gt;
&lt;td&gt;Commonly required due to address scarcity&lt;/td&gt;
&lt;td&gt;Not needed; supports true end-to-end addressing&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Broadcast/discovery&lt;/td&gt;
&lt;td&gt;Uses broadcast (e.g. ARP) for local discovery&lt;/td&gt;
&lt;td&gt;Broadcast eliminated; uses multicast Neighbor Discovery&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Built-in security&lt;/td&gt;
&lt;td&gt;IPsec is an optional add-on&lt;/td&gt;
&lt;td&gt;IPsec support is part of the core protocol spec&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Adoption &amp;amp; compatibility&lt;/td&gt;
&lt;td&gt;Universally supported, legacy infrastructure&lt;/td&gt;
&lt;td&gt;Growing adoption, requires dual-stack or tunneling for legacy interop&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="key-differences"&gt;Key Differences&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;IPv6 addresses are &lt;strong class="kw"&gt;128-bit&lt;/strong&gt;, four times longer than IPv4&amp;rsquo;s &lt;strong class="kw"&gt;32-bit&lt;/strong&gt; addresses, resolving address exhaustion&lt;/li&gt;
&lt;li&gt;IPv6 removes the need for &lt;strong class="kw"&gt;NAT&lt;/strong&gt;, restoring true end-to-end connectivity between hosts&lt;/li&gt;
&lt;li&gt;IPv6 uses a simplified, &lt;strong class="kw"&gt;fixed-length header&lt;/strong&gt; that speeds up router processing compared to IPv4&amp;rsquo;s variable header&lt;/li&gt;
&lt;li&gt;IPv6 replaces ARP broadcasts with &lt;strong class="kw"&gt;Neighbor Discovery&lt;/strong&gt; multicast for local address resolution&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="when-to-use-each"&gt;When to Use Each&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;IPv4&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>HTTP vs HTTPS: Plaintext vs Encrypted Web Traffic</title><link>https://comparison.metacog.co.kr/posts/2026-08-03-http-vs-https-plaintext-vs-encrypted-web-traffic/</link><pubDate>Sat, 01 Aug 2026 20:01:00 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-08-03-http-vs-https-plaintext-vs-encrypted-web-traffic/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;HTTP and HTTPS are the same application-layer protocol for transferring web resources, but HTTPS wraps every request and response in a &lt;strong class="kw"&gt;TLS&lt;/strong&gt; tunnel before it touches the network. That single layer determines whether credentials, cookies, and page content travel as &lt;strong class="kw"&gt;plaintext&lt;/strong&gt; visible to anyone on the path, or as ciphertext only the two endpoints can read.&lt;/p&gt;
&lt;h2 id="comparison-diagram"&gt;Comparison Diagram&lt;/h2&gt;
&lt;div class="compare-diagram"&gt;
&lt;svg viewBox="0 0 640 360" xmlns="http://www.w3.org/2000/svg"&gt;&lt;text x="20" y="32" font-size="18" font-weight="700" style="fill:var(--primary)"&gt;HTTP&lt;/text&gt;&lt;rect x="40" y="70" width="110" height="50" rx="6" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="95" y="100" font-size="13" text-anchor="middle" style="fill:var(--content)"&gt;Client&lt;/text&gt;&lt;rect x="490" y="70" width="110" height="50" rx="6" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="545" y="100" font-size="13" text-anchor="middle" style="fill:var(--content)"&gt;Server&lt;/text&gt;&lt;line x1="150" y1="95" x2="490" y2="95" style="stroke:var(--compare-a)" stroke-width="2" stroke-dasharray="5,4" marker-end="url(#arrowA)"/&gt;&lt;text x="320" y="82" font-size="12" text-anchor="middle" style="fill:var(--content)"&gt;GET /login?pwd=hunter2&lt;/text&gt;&lt;circle cx="320" cy="140" r="14" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;path d="M310 140 Q320 132 330 140 Q320 148 310 140 Z" style="fill:none;stroke:var(--compare-a)" stroke-width="1.3"/&gt;&lt;circle cx="320" cy="140" r="2.5" style="fill:var(--compare-a)"/&gt;&lt;text x="320" y="165" font-size="11" text-anchor="middle" style="fill:var(--secondary)"&gt;visible to anyone on path&lt;/text&gt;&lt;line x1="0" y1="195" x2="640" y2="195" style="stroke:var(--border)" stroke-width="1" stroke-dasharray="3,3"/&gt;&lt;text x="20" y="225" font-size="18" font-weight="700" style="fill:var(--primary)"&gt;HTTPS&lt;/text&gt;&lt;rect x="40" y="260" width="110" height="50" rx="6" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="95" y="290" font-size="13" text-anchor="middle" style="fill:var(--content)"&gt;Client&lt;/text&gt;&lt;rect x="490" y="260" width="110" height="50" rx="6" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="545" y="290" font-size="13" text-anchor="middle" style="fill:var(--content)"&gt;Server&lt;/text&gt;&lt;line x1="150" y1="285" x2="490" y2="285" style="stroke:var(--compare-b)" stroke-width="2" marker-end="url(#arrowB)"/&gt;&lt;text x="320" y="272" font-size="12" text-anchor="middle" style="fill:var(--content)"&gt;x8f#9a2$qL0e...&lt;/text&gt;&lt;rect x="308" y="296" width="24" height="18" rx="3" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;path d="M313 296 v-8 a7 7 0 0 1 14 0 v8" style="fill:none;stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="320" y="335" font-size="11" text-anchor="middle" style="fill:var(--secondary)"&gt;TLS-encrypted, tamper-evident&lt;/text&gt;&lt;defs&gt;&lt;marker id="arrowA" markerWidth="8" markerHeight="8" refX="6" refY="4" orient="auto"&gt;&lt;path d="M0,0 L8,4 L0,8 Z" style="fill:var(--compare-a)"/&gt;&lt;/marker&gt;&lt;marker id="arrowB" markerWidth="8" markerHeight="8" refX="6" refY="4" orient="auto"&gt;&lt;path d="M0,0 L8,4 L0,8 Z" style="fill:var(--compare-b)"/&gt;&lt;/marker&gt;&lt;/defs&gt;&lt;/svg&gt;
&lt;/div&gt;
&lt;h2 id="comparison-table"&gt;Comparison Table&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Aspect&lt;/th&gt;
&lt;th&gt;HTTP&lt;/th&gt;
&lt;th&gt;HTTPS&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Default port&lt;/td&gt;
&lt;td&gt;80&lt;/td&gt;
&lt;td&gt;443&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Connection establishment&lt;/td&gt;
&lt;td&gt;Single TCP three-way handshake&lt;/td&gt;
&lt;td&gt;TCP handshake plus a TLS handshake to negotiate cipher and exchange keys&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Certificate requirement&lt;/td&gt;
&lt;td&gt;None&lt;/td&gt;
&lt;td&gt;X.509 certificate issued by a trusted CA (or self-signed) required&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Data encryption&lt;/td&gt;
&lt;td&gt;Plaintext — headers, cookies, and body sent unencrypted&lt;/td&gt;
&lt;td&gt;Encrypted end-to-end using TLS/SSL symmetric ciphers&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Data integrity&lt;/td&gt;
&lt;td&gt;No built-in tamper detection&lt;/td&gt;
&lt;td&gt;MAC/AEAD in TLS detects in-transit tampering&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Browser indicator&lt;/td&gt;
&lt;td&gt;&amp;ldquo;Not secure&amp;rdquo; warning in modern browsers&lt;/td&gt;
&lt;td&gt;Padlock icon; no warning shown&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Performance overhead&lt;/td&gt;
&lt;td&gt;Lower — no crypto or extra round trip&lt;/td&gt;
&lt;td&gt;Slightly higher handshake/CPU cost, largely offset by TLS 1.3 and session resumption&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Typical use case&lt;/td&gt;
&lt;td&gt;Local development, internal tools on trusted networks, legacy static content&lt;/td&gt;
&lt;td&gt;Any production site, especially logins, payments, and APIs handling sensitive data&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="key-differences"&gt;Key Differences&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;HTTPS is HTTP tunneled through &lt;strong class="kw"&gt;TLS&lt;/strong&gt;, not a separate application protocol&lt;/li&gt;
&lt;li&gt;HTTP traffic is readable in plaintext by anyone with network access; HTTPS traffic is &lt;strong class="kw"&gt;encrypted&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;HTTPS requires a valid &lt;strong class="kw"&gt;certificate&lt;/strong&gt; from a trusted CA to establish trust&lt;/li&gt;
&lt;li&gt;Modern browsers flag HTTP sites as &lt;strong class="kw"&gt;not secure&lt;/strong&gt;, pushing HTTPS as the default&lt;/li&gt;
&lt;li&gt;TLS 1.3 has shrunk the historical HTTPS &lt;strong class="kw"&gt;handshake&lt;/strong&gt; cost to near parity with plain TCP&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="when-to-use-each"&gt;When to Use Each&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;HTTP&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>TCP vs UDP: Reliable Streams vs Fast Datagrams</title><link>https://comparison.metacog.co.kr/posts/2026-08-03-tcp-vs-udp-reliable-streams-vs-fast-datagrams/</link><pubDate>Sat, 01 Aug 2026 20:00:00 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-08-03-tcp-vs-udp-reliable-streams-vs-fast-datagrams/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;TCP and UDP are the two core transport-layer protocols used to move data between hosts, but they trade reliability for speed in opposite directions. TCP prioritizes &lt;strong class="kw"&gt;reliable delivery&lt;/strong&gt; through handshakes, acknowledgments, and retransmission, while UDP prioritizes &lt;strong class="kw"&gt;low-latency delivery&lt;/strong&gt; by sending datagrams with no setup or delivery guarantees. Choosing between them shapes how an application handles packet loss, ordering, and throughput.&lt;/p&gt;
&lt;h2 id="comparison-diagram"&gt;Comparison Diagram&lt;/h2&gt;
&lt;div class="compare-diagram"&gt;
&lt;svg viewBox="0 0 640 360" xmlns="http://www.w3.org/2000/svg"&gt;&lt;defs&gt;&lt;marker id="arrowA" viewBox="0 0 10 10" refX="8" refY="5" markerWidth="6" markerHeight="6" orient="auto-start-reverse"&gt;&lt;path d="M0,0 L10,5 L0,10 z" style="fill:var(--compare-a)"/&gt;&lt;/marker&gt;&lt;marker id="arrowB" viewBox="0 0 10 10" refX="8" refY="5" markerWidth="6" markerHeight="6" orient="auto-start-reverse"&gt;&lt;path d="M0,0 L10,5 L0,10 z" style="fill:var(--compare-b)"/&gt;&lt;/marker&gt;&lt;/defs&gt;&lt;text x="180" y="28" text-anchor="middle" font-size="16" font-weight="bold" style="fill:var(--primary)"&gt;TCP&lt;/text&gt;&lt;text x="490" y="28" text-anchor="middle" font-size="16" font-weight="bold" style="fill:var(--primary)"&gt;UDP&lt;/text&gt;&lt;line x1="340" y1="45" x2="340" y2="330" stroke-dasharray="4 4" style="stroke:var(--border)"/&gt;&lt;line x1="100" y1="50" x2="100" y2="330" style="stroke:var(--border)"/&gt;&lt;line x1="260" y1="50" x2="260" y2="330" style="stroke:var(--border)"/&gt;&lt;line x1="400" y1="50" x2="400" y2="330" style="stroke:var(--border)"/&gt;&lt;line x1="580" y1="50" x2="580" y2="330" style="stroke:var(--border)"/&gt;&lt;circle cx="100" cy="50" r="5" style="fill:var(--compare-a-soft);stroke:var(--compare-a)"/&gt;&lt;circle cx="260" cy="50" r="5" style="fill:var(--compare-a-soft);stroke:var(--compare-a)"/&gt;&lt;circle cx="400" cy="50" r="5" style="fill:var(--compare-b-soft);stroke:var(--compare-b)"/&gt;&lt;circle cx="580" cy="50" r="5" style="fill:var(--compare-b-soft);stroke:var(--compare-b)"/&gt;&lt;text x="100" y="42" text-anchor="middle" font-size="10" style="fill:var(--content)"&gt;Client&lt;/text&gt;&lt;text x="260" y="42" text-anchor="middle" font-size="10" style="fill:var(--content)"&gt;Server&lt;/text&gt;&lt;text x="400" y="42" text-anchor="middle" font-size="10" style="fill:var(--content)"&gt;Sender&lt;/text&gt;&lt;text x="580" y="42" text-anchor="middle" font-size="10" style="fill:var(--content)"&gt;Receiver&lt;/text&gt;&lt;line x1="100" y1="65" x2="260" y2="65" stroke-width="1.5" marker-end="url(#arrowA)" style="stroke:var(--compare-a)"/&gt;&lt;text x="180" y="60" text-anchor="middle" font-size="11" style="fill:var(--content)"&gt;SYN&lt;/text&gt;&lt;line x1="260" y1="90" x2="100" y2="90" stroke-width="1.5" marker-end="url(#arrowA)" style="stroke:var(--compare-a)"/&gt;&lt;text x="180" y="85" text-anchor="middle" font-size="11" style="fill:var(--content)"&gt;SYN-ACK&lt;/text&gt;&lt;line x1="100" y1="115" x2="260" y2="115" stroke-width="1.5" marker-end="url(#arrowA)" style="stroke:var(--compare-a)"/&gt;&lt;text x="180" y="110" text-anchor="middle" font-size="11" style="fill:var(--content)"&gt;ACK&lt;/text&gt;&lt;text x="180" y="138" text-anchor="middle" font-size="10" font-style="italic" style="fill:var(--secondary)"&gt;connection established&lt;/text&gt;&lt;line x1="100" y1="163" x2="260" y2="163" stroke-width="1.5" marker-end="url(#arrowA)" style="stroke:var(--compare-a)"/&gt;&lt;text x="180" y="158" text-anchor="middle" font-size="11" style="fill:var(--content)"&gt;Data&lt;/text&gt;&lt;line x1="260" y1="188" x2="100" y2="188" stroke-width="1.5" marker-end="url(#arrowA)" style="stroke:var(--compare-a)"/&gt;&lt;text x="180" y="183" text-anchor="middle" font-size="11" style="fill:var(--content)"&gt;ACK&lt;/text&gt;&lt;line x1="100" y1="213" x2="260" y2="213" stroke-width="1.5" marker-end="url(#arrowA)" style="stroke:var(--compare-a)"/&gt;&lt;text x="180" y="208" text-anchor="middle" font-size="11" style="fill:var(--content)"&gt;Data&lt;/text&gt;&lt;line x1="260" y1="238" x2="100" y2="238" stroke-width="1.5" marker-end="url(#arrowA)" style="stroke:var(--compare-a)"/&gt;&lt;text x="180" y="233" text-anchor="middle" font-size="11" style="fill:var(--content)"&gt;ACK&lt;/text&gt;&lt;text x="180" y="265" text-anchor="middle" font-size="10" style="fill:var(--secondary)"&gt;FIN / ACK teardown&lt;/text&gt;&lt;line x1="400" y1="65" x2="580" y2="65" stroke-width="1.5" marker-end="url(#arrowB)" style="stroke:var(--compare-b)"/&gt;&lt;text x="490" y="60" text-anchor="middle" font-size="11" style="fill:var(--content)"&gt;Datagram&lt;/text&gt;&lt;line x1="400" y1="90" x2="580" y2="90" stroke-width="1.5" marker-end="url(#arrowB)" style="stroke:var(--compare-b)"/&gt;&lt;text x="490" y="85" text-anchor="middle" font-size="11" style="fill:var(--content)"&gt;Datagram&lt;/text&gt;&lt;line x1="400" y1="115" x2="500" y2="115" stroke-dasharray="4 3" style="stroke:var(--border)"/&gt;&lt;line x1="496" y1="111" x2="504" y2="119" style="stroke:var(--secondary)"/&gt;&lt;line x1="504" y1="111" x2="496" y2="119" style="stroke:var(--secondary)"/&gt;&lt;text x="490" y="131" text-anchor="middle" font-size="10" style="fill:var(--secondary)"&gt;lost, no retry&lt;/text&gt;&lt;line x1="400" y1="153" x2="580" y2="153" stroke-width="1.5" marker-end="url(#arrowB)" style="stroke:var(--compare-b)"/&gt;&lt;text x="490" y="148" text-anchor="middle" font-size="11" style="fill:var(--content)"&gt;Datagram&lt;/text&gt;&lt;line x1="400" y1="178" x2="580" y2="178" stroke-width="1.5" marker-end="url(#arrowB)" style="stroke:var(--compare-b)"/&gt;&lt;text x="490" y="173" text-anchor="middle" font-size="11" style="fill:var(--content)"&gt;Datagram&lt;/text&gt;&lt;text x="490" y="205" text-anchor="middle" font-size="10" style="fill:var(--secondary)"&gt;no ACKs, no ordering&lt;/text&gt;&lt;/svg&gt;
&lt;/div&gt;
&lt;h2 id="comparison-table"&gt;Comparison Table&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Aspect&lt;/th&gt;
&lt;th&gt;TCP&lt;/th&gt;
&lt;th&gt;UDP&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Connection setup&lt;/td&gt;
&lt;td&gt;Three-way handshake (SYN, SYN-ACK, ACK) establishes a stateful connection before any data moves&lt;/td&gt;
&lt;td&gt;No handshake — sender transmits datagrams immediately with no prior negotiation&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Delivery guarantee&lt;/td&gt;
&lt;td&gt;Guaranteed via sequence numbers and acknowledgments; lost segments are detected and resent&lt;/td&gt;
&lt;td&gt;Best-effort only; lost packets vanish silently with no notification to either side&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Ordering&lt;/td&gt;
&lt;td&gt;Segments are reassembled in the original order regardless of arrival sequence&lt;/td&gt;
&lt;td&gt;No ordering guarantee; packets are delivered to the application in whatever order they arrive&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Flow &amp;amp; congestion control&lt;/td&gt;
&lt;td&gt;Dynamic window sizing and congestion-avoidance algorithms throttle the sender to match network capacity&lt;/td&gt;
&lt;td&gt;None; the application sends at whatever rate it chooses, independent of network conditions&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Error handling&lt;/td&gt;
&lt;td&gt;Checksum plus automatic retransmission recovers corrupted or missing segments&lt;/td&gt;
&lt;td&gt;Checksum only; corrupted or missing packets are simply dropped, not recovered&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Overhead &amp;amp; latency&lt;/td&gt;
&lt;td&gt;Larger 20+ byte header and handshake/ACK round trips add processing and latency&lt;/td&gt;
&lt;td&gt;Minimal 8-byte header and no round trips keep per-packet overhead and latency low&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Connection teardown&lt;/td&gt;
&lt;td&gt;Explicit four-way FIN/ACK exchange formally closes the connection on both sides&lt;/td&gt;
&lt;td&gt;No connection state exists, so transmission simply stops with nothing to tear down&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="key-differences"&gt;Key Differences&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;TCP is &lt;strong class="kw"&gt;connection-oriented&lt;/strong&gt;, requiring a handshake before data flows, while UDP is connectionless&lt;/li&gt;
&lt;li&gt;TCP guarantees &lt;strong class="kw"&gt;reliable delivery&lt;/strong&gt; through acknowledgments and retransmission; UDP offers none&lt;/li&gt;
&lt;li&gt;TCP performs &lt;strong class="kw"&gt;congestion control&lt;/strong&gt; to avoid overwhelming the network; UDP has no such mechanism&lt;/li&gt;
&lt;li&gt;UDP&amp;rsquo;s minimal &lt;strong class="kw"&gt;header overhead&lt;/strong&gt; gives it consistently lower latency than TCP&lt;/li&gt;
&lt;li&gt;TCP preserves &lt;strong class="kw"&gt;packet ordering&lt;/strong&gt; end-to-end; UDP delivers packets in whatever order they arrive&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="when-to-use-each"&gt;When to Use Each&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;TCP&lt;/strong&gt;&lt;/p&gt;</description></item></channel></rss>