UNIT 2: DATA LINK LAYER & LOCAL NETWORKING LAB
2.1 Ethernet Fundamentals & LAN Device Configuration
2.1.1 Ethernet Frame Structure & Field Analysis
-
MAC Addressing (48-bit): Format
XX:XX:XX:XX:XX:XX. First byte's LSB determines type:-
Unicast: LSB = 0 (e.g.,
00:1A:2B:3C:4D:5E) -
Multicast: LSB = 1 (e.g.,
01:00:5E:00:00:01for IPv4 multicast) -
Broadcast:
FF:FF:FF:FF:FF:FF
-
-
Standard Ethernet II Frame Fields:
| Field | Size (Bytes) | Purpose |
|---|---|---|
| Preamble | 7 | Clock synchronization (101010... pattern) |
| SFD | 1 | Start Frame Delimiter (10101011) marks start of frame |
| Destination MAC | 6 | Recipient's MAC address |
| Source MAC | 6 | Sender's MAC address |
| Type | 2 | Indicates upper-layer protocol (e.g., 0x0800=IPv4, 0x0806=ARP) |
| Data & Pad | 46-1500 | Payload (e.g., IP packet). Pad if <46 bytes. |
| FCS | 4 | Frame Check Sequence (CRC) for error detection |
-
Ethernet II vs. IEEE 802.3:
-
Ethernet II: Uses Type field (e.g., 0x0800). Dominant in TCP/IP networks.
-
IEEE 802.3: Uses Length field (indicates data size) + 802.2 LLC/SNAP header for protocol identification. Rarely used in modern IP networks.
-
[!TIP] Exam Focus: Know the 6 MAC address fields in order. Distinguish Type (Ethernet II) from Length (802.3). FCS is computed by sender and checked by receiver.
2.1.2 Switch Operation & MAC Address Table Management
-
Switching Methods:
-
Store-and-Forward: Receives entire frame, checks FCS, then forwards. Error-checking, higher latency.
-
Cut-Through: Forwards after reading Destination MAC only. Lower latency, no error-checking.
-
-
MAC Address Table (CAM Table): Built dynamically.
-
Learning: Switch records Source MAC and incoming port.
-
Aging: Entries deleted after ~5 minutes of inactivity (default).
-
-
Frame Forwarding Decision:
-
If Destination MAC in table: Forward out associated port (unicast).
-
If Destination MAC unknown/broadcast/multicast: Flood out all ports in same VLAN except incoming port.
-
If Destination MAC on same port as incoming: Filter (do not forward).
-
[!TIP] Common Pitfall: A switch floods unknown unicast frames, not just broadcasts. This is a key behavior.
2.1.3 Basic Switch CLI Configuration (Cisco)
Switch> enable
Switch# configure terminal
Switch(config)# hostname SW1
SW1(config)# line console 0
SW1(config-line)# password cisco
SW1(config-line)# login
SW1(config-line)# exit
SW1(config)# line vty 0 15
SW1(config-line)# password cisco
SW1(config-line)# login
SW1(config-line)# exit
SW1(config)# banner motd #Unauthorized Access Prohibited#
SW1(config)# interface vlan 1
SW1(config-if)# ip address 192.168.1.10 255.255.255.0
SW1(config-if)# no shutdown
SW1(config-if)# exit
SW1(config)# ip default-gateway 192.168.1.1 ! For Layer 2 switch management
SW1(config)# end
SW1# copy running-config startup-config
[!TIP] Critical:
no shutdownenables an interface.ip default-gatewayis needed on Layer 2 switches for remote management; Layer 3 switches use SVIs with routing.
2.2 VLANs (Virtual LANs) & Trunking
2.2.1 VLAN Concept & Benefits
-
Definition: A VLAN is a logical broadcast domain. Ports in same VLAN act as if connected to same switch.
-
Benefits:
-
Security: Segment sensitive departments (e.g., Finance VLAN).
-
Broadcast Control: Reduce broadcast traffic size.
-
Flexibility: Group users by function, not physical location.
-
-
VLAN ID Range:
-
Normal Range (1-1005): Stored in
vlan.datfile. VLAN 1 is default (cannot be deleted). -
Extended Range (1006-4094): Supported in VTP transparent mode only.
-
2.2.2 Access Port Configuration
SW1(config)# interface fastEthernet 0/1
SW1(config-if)# switchport mode access ! Force access mode
SW1(config-if)# switchport access vlan 10 ! Assign to VLAN 10
[!TIP] Native VLAN: On a trunk, frames for the Native VLAN are sent untagged. Default is VLAN 1. Change for security.
2.2.3 Trunking Protocols: IEEE 802.1Q
-
Tagging Mechanism: Inserts 4-byte header between Source MAC and Type fields.
-
TPID (Tag Protocol Identifier):
0x8100(identifies 802.1Q frame). -
TCI (Tag Control Information):
-
PCP (Priority Code Point): 3 bits for QoS.
-
DEI (Drop Eligible Indicator): 1 bit (formerly CFI).
-
VLAN ID: 12 bits (1-4094).
-
-
-
Trunk Configuration:
SW1(config)# interface fastEthernet 0/24
SW1(config-if)# switchport mode trunk
SW1(config-if)# switchport trunk allowed vlan 10,20,30 ! Restrict allowed VLANs
-
DTP (Dynamic Trunking Protocol) Modes:
| Mode | Behavior | | :--- | :--- | |
access| Never trunk (force access) | |trunk| Always trunk (force trunk) | |dynamic desirable| Actively attempt to form trunk | |dynamic auto| Passively wait for other side to request trunk | |nonegotiate| Disable DTP (use with non-Cisco devices) |
[!TIP] Security Best Practice: Set trunk ports to
trunkornonegotiateand explicitly list allowed VLANs (switchport trunk allowed vlan ...). Avoiddynamic autoas it can form unintended trunks.
2.2.4 VLAN Trunking Lab Verification
SW1# show vlan brief ! Lists VLANs and their member ports
SW1# show interfaces trunk ! Shows trunk status, native VLAN, allowed VLANs
SW1# show interfaces fastEthernet 0/24 switchport ! Detailed port mode info
2.3 IPv4 Subnetting & IP Addressing on Network Devices
2.3.1 Subnet Mask Interpretation & Custom Subnet Masks
-
Notations:
255.255.255.0=/24=11111111.11111111.11111111.00000000 -
Key Formulas:
-
Number of Subnets: $$\displaystyle 2^n $$ (where
n= bits borrowed from host portion). Note: Modern practice counts all-zeros and all-ones subnets. -
Hosts per Subnet: $$\displaystyle 2^h - 2 $$ (where
h= remaining host bits). Subtract 2 for network & broadcast addresses. -
Subnet Increment: $$\displaystyle 2^{(number\ of\ host\ bits)} $$ in the octet where subnetting occurs.
-
-
Example: Subnet
192.168.1.0/24into subnets with min. 20 hosts.-
Need 20 hosts → $$\displaystyle 2^h - 2 \geq 20 $$ → $$\displaystyle h=5 $$ (since $$\displaystyle 2^5-2=30 $$).
-
Original host bits = 8. Borrow $$\displaystyle 8-5=3 $$ bits for subnetting.
-
New mask:
/27=255.255.255.224. -
Subnet increment = $$\displaystyle 2^5 = 32 $$ in 4th octet.
-
Subnets:
192.168.1.0/27,192.168.1.32/27,192.168.1.64/27, etc.
-
[!TIP] Step-by-Step Subnetting: 1) Determine required hosts → find
h. 2) Calculate new prefix (/). 3) Find increment. 4) List subnets. Always draw the subnet block!
2.3.2 Configuring IP Addresses
-
On Host (Windows CLI):
ipconfig /allto view. Static via GUI ornetsh. -
On Router Interface:
R1(config)# interface gigabitEthernet 0/0
R1(config-if)# ip address 192.168.10.1 255.255.255.0
R1(config-if)# no shutdown
- On Switch (SVI - Switched Virtual Interface): For management or Layer 3 switch routing.
SW1(config)# interface vlan 10
SW1(config-if)# ip address 192.168.10.10 255.255.255.0
SW1(config-if)# no shutdown
2.3.3 Practical Subnetting Lab Documentation Template
| Subnet | Network Address | First Usable IP | Last Usable IP | Broadcast Address | Default Gateway |
|---|---|---|---|---|---|
| VLAN 10 | 192.168.1.0/27 | 192.168.1.1 | 192.168.1.30 | 192.168.1.31 | 192.168.1.1 |
| VLAN 20 | 192.168.1.32/27 | 192.168.1.33 | 192.168.1.62 | 192.168.1.63 | 192.168.1.33 |
2.4 ARP, ICMP, and Basic Network Troubleshooting Tools
2.4.1 Address Resolution Protocol (ARP)
-
Purpose: Resolves known IPv4 address to unknown MAC address on local network.
-
Process:
-
Host A (IP_A, MAC_A) wants to send to IP_B on same subnet.
-
ARP Request: Broadcast (
FF:FF:FF:FF:FF:FF), "Who has IP_B? Tell IP_A." -
ARP Reply: Host B unicasts to MAC_A: "IP_B is at MAC_B."
-
Host A caches mapping (IP_B, MAC_B) in ARP table (typically 2-10 min).
-
-
Commands:
-
Windows:
arp -a(view),arp -d *(delete). -
Cisco:
show arporshow ip arp.
-
[!TIP] ARP Spoofing: Malicious host sends fake ARP replies to poison cache, enabling man-in-the-middle attacks. Use
arp -ato check for duplicate IP-MAC pairs.
2.4.2 Internet Control Message Protocol (ICMP)
-
Key Messages for Troubleshooting:
-
Echo Request (Type 8) / Echo Reply (Type 0): Used by
ping. -
Destination Unreachable (Type 3): Sent by router when no route or port unreachable.
-
Time Exceeded (Type 11): Sent by router when TTL reaches 0 (used by
traceroute).
-
-
Tools:
-
ping <IP>: Tests L3 reachability. Measures RTT (Round-Trip Time). -
tracert <IP>(Windows) /traceroute <IP>(Linux/Cisco): Shows path and RTT to each hop. Identifies routing loops or failures.
-
2.4.3 Command-Line Troubleshooting Utilities
| Command | Platform | Purpose |
|---|---|---|
ipconfig /all |
Windows | View full TCP/IP config (IP, mask, gateway, DNS) |
ifconfig |
Linux/macOS | View/configure network interfaces |
ping |
All | Test L3 connectivity |
arp -a |
Windows/Linux | View ARP cache |
tracert / traceroute |
Windows/Linux | Path tracing & TTL analysis |
show ip interface brief |
Cisco | Summary of interface IP and status |
show ip route |
Cisco | View routing table |
[!TIP] Systematic Troubleshooting: Start local (
ipconfig), then same subnet (ping gateway), then remote (ping remote IP). Usetracertif remote ping fails. Check ARP cache if same-subnet ping fails.
2.5 Introduction to Static Routing & Router Configuration
2.5.1 Router Fundamentals
-
Role: Connects different broadcast domains (subnets/VLANs). Operates at Layer 3.
-
Default Gateway: The router interface IP address that hosts use to send traffic outside their subnet.
2.5.2 Configuring Static Routes
-
Syntax:
R1(config)# ip route <destination-network> <subnet-mask> <next-hop-IP> R1(config)# ip route 192.168.2.0 255.255.255.0 10.0.0.2- Or using exit-interface (only for point-to-point links):
R1(config)# ip route 192.168.2.0 255.255.255.0 gigabitEthernet 0/1 -
Administrative Distance (AD): Static routes have AD = 1 (very trustworthy). Directly connected interfaces have AD = 0.
[!TIP] When to use next-hop vs. exit-interface: Use next-hop IP for multi-access networks (like Ethernet). Use exit-interface for point-to-point serial links. Using exit-interface on Ethernet can cause routing issues if next-hop is down but interface is up.
2.5.3 Basic Router CLI Configuration
R1> enable
R1# configure terminal
R1(config)# hostname BranchRouter
BranchRouter(config)# banner login #Authorized Personnel Only#
BranchRouter(config)# enable secret cisco123 ! Encrypted
BranchRouter(config)# line console 0
BranchRouter(config-line)# password cisco
BranchRouter(config-line)# login
BranchRouter(config-line)# exit
BranchRouter(config)# line vty 0 4
BranchRouter(config-line)# password cisco
BranchRouter(config-line)# login
BranchRouter(config-line)# exit
BranchRouter(config)# interface gigabitEthernet 0/0
BranchRouter(config-if)# ip address 10.0.0.1 255.255.255.252
BranchRouter(config-if)# no shutdown
BranchRouter(config-if)# exit
BranchRouter(config)# ip route 192.168.2.0 255.255.255.0 10.0.0.2
BranchRouter(config)# end
BranchRouter# show ip route ! Verify static route (marked 'S')
BranchRouter# show ip interface brief ! Verify interface IP and status
BranchRouter# copy running-config startup-config
2.6 Network Analysis with Wireshark / Packet Tracer Simulation
2.6.1 Capturing and Filtering Traffic
-
Start Capture: Select interface → click shark fin.
-
Stop Capture: Click red square.
-
Essential Display Filters:
-
eth.addr == 00:11:22:33:44:55(specific MAC) -
ip.addr == 192.168.1.1(specific IP) -
arp(all ARP packets) -
icmp(all ICMP packets) -
vlan(all 802.1Q tagged frames) -
eth.type == 0x0800(IPv4 frames) -
eth.type == 0x0806(ARP frames)
-
2.6.2 Analyzing Key Protocols in Unit 2
| Protocol | Key Wireshark Identification | What to Look For |
|---|---|---|
| Ethernet Frame | Frame details pane | Source/Dest MAC, Type field (0x0800=IPv4, 0x0806=ARP) |
| ARP | Filter: arp |
Opcode: 1=Request, 2=Reply. Request is broadcast (Dest MAC=FF:FF:FF:FF:FF:FF). |
| IPv4 | Expand Internet Protocol layer | TTL (decrements per hop), Protocol (1=ICMP, 6=TCP, 17=UDP), Source/Dest IP. |
| ICMP | Filter: icmp |
Type: 8=Echo Request, 0=Echo Reply. Code field usually 0. |
| VLAN Tagged (802.1Q) | Expand Ethernet II → 802.1Q | TPID = 0x8100. VLAN ID in TCI field. Original Ethernet Type is pushed down. |
[!TIP] Packet Tracer Simulation Mode: Use "Edit Filters" to simulate Wireshark filters. Click a packet to see "Outbound" and "Inbound" PDU details layer-by-layer.
2.7 Integrated Lab Scenarios (Synthesis of Topics)
2.7.1 Multi-VLAN, Multi-Subnet Lab with Inter-VLAN Routing
Scenario: Two switches (SW1, SW2), one router (R1). VLANs 10 (Sales) and 20 (Engineering). Hosts in each VLAN on different switches. Steps:
-
Design Subnets: e.g.,
192.168.10.0/24for VLAN10,192.168.20.0/24for VLAN20. -
Configure VLANs on both switches:
SW1(config)# vlan 10 SW1(config-vlan)# name Sales SW1(config)# vlan 20 SW1(config-vlan)# name Engineering -
Assign Access Ports: Connect host ports to correct VLANs (
switchport access vlan 10). -
Configure Trunk between SW1 & SW2:
SW1(config-if)# switchport mode trunk SW1(config-if)# switchport trunk allowed vlan 10,20 -
Router-on-a-Stick (R1): Create sub-interfaces for each VLAN.
R1(config)# interface gigabitEthernet 0/0.10 R1(config-subif)# encapsulation dot1Q 10 R1(config-subif)# ip address 192.168.10.1 255.255.255.0 R1(config)# interface gigabitEthernet 0/0.20 R1(config-subif)# encapsulation dot1Q 20 R1(config-subif)# ip address 192.168.20.1 255.255.255.0 R1(config)# interface gigabitEthernet 0/0 R1(config-if)# no shutdown -
Configure Hosts: Set IPs in correct subnet, default gateway = router sub-interface IP (e.g.,
192.168.10.1for VLAN10). -
Verification:
-
show vlan briefon switches (check trunk port shows VLANs). -
show interfaces trunk(check allowed VLANs). -
show ip routeon router (should see directly connected routes for each sub-interface). -
pingfrom host in VLAN10 to host in VLAN20 → should succeed. -
show arpon router → should see MACs for both VLANs.
-
2.7.2 Basic Network Troubleshooting Scenario
Symptom: Host A (VLAN10, 192.168.10.10/24) cannot ping Host B (VLAN20, 192.168.20.20/24).
Systematic Diagnosis:
-
Host A Local Config:
ipconfig→ Correct IP/mask/gateway (192.168.10.1)? ✅ -
Same-Subnet Connectivity: Ping Host A's default gateway (
192.168.10.1). Fails?-
Check switch port mode (
show interfaces fa0/1 switchport). Should beaccess vlan 10. -
Check VLAN membership (
show vlan brief). Is port in VLAN 10? -
Check trunk between switches (
show interfaces trunk). Is VLAN 10 allowed? -
Check router sub-interface config (
show running-config interface g0/0.10). Correctencapsulation dot1Q 10and IP?
-
-
If gateway ping succeeds: Issue is with VLAN20 or router config.
-
Repeat steps for Host B's side.
-
On router:
show ip route→ Are both192.168.10.0/24and192.168.20.0/24listed as connected (C)? If not, sub-interface is down (no shutdownmissing?).
-
-
Use Wireshark/Packet Tracer Simulation:
-
Capture on Host A. Does it send ARP for gateway? If no ARP request, gateway IP is wrong or same subnet.
-
Does ARP reply come? If not, check physical connectivity and switch VLAN.
-
Does ping packet leave Host A with VLAN 10 tag? (In simulation, check outbound PDU).
-
At router: Does sub-interface
g0/0.10receive the tagged frame? Does it strip tag and route? -
Does router send packet out
g0/0.20with VLAN 20 tag? -
Does Host B receive it? Check Host B's ARP for router's VLAN20 IP.
-
2.8 (Optional/Advanced) Spanning Tree Protocol (STP) Basics
2.8.1 Purpose of STP
-
Prevents Layer 2 Loops in redundant switched topologies.
-
Mechanism: Elects a Root Bridge. All other switches determine a single Root Port (best path to root) and Designated Port (forwarding port for each segment). All other ports become Blocking Ports (no forwarding, but listen for BPDUs).
2.8.2 Observing STP in Packet Tracer
-
BPDU (Bridge Protocol Data Unit) Types:
-
Configuration BPDU: Contains Bridge ID, Root ID, path cost. Sent every 2 seconds by Root.
-
Topology Change (TCN) BPDU: Notifies of topology change.
-
-
Port States:
Blocking→Listening→Learning→Forwarding(default 30-50 sec convergence). -
Commands:
SW1# show spanning-tree SW1# show spanning-tree summary SW1# show spanning-tree interface fastEthernet 0/1 detail ! See port role/state -
In Simulation Mode: Filter for
stp. Observe BPDUs flowing from Root Bridge. Non-root bridges forward superior BPDUs toward root.
[!TIP] Root Bridge Election: Lowest Bridge ID wins. Bridge ID = Priority (default 32768) + MAC address. To force a switch as root, set lower priority:
spanning-tree vlan 1 priority 4096.