Skip to content
EC-605 · DATA COMMUNICATION LAB/Quick Revision Short Notes

DATA COMMUNICATION LAB (EC-605) - Unit 3 Short Notes

UNIT 3: NETWORK LAYER & TRANSPORT LAYER PROTOCOLS & SERVICES (LAB FOCUS)


3.1 IP Addressing & Subnetting (Core Practical Foundation)

IPv4 Address Classes & Special Addresses

  • Classful Ranges:

    | Class | Range (First Octet) | Default Subnet Mask | Purpose | | :--- | :--- | :--- | :--- | | A | 1 - 126 | 255.0.0.0 | Large networks | | B | 128 - 191 | 255.255.0.0 | Medium networks | | C | 192 - 223 | 255.255.255.0 | Small networks | | D | 224 - 239 | N/A | Multicast | | E | 240 - 255 | N/A | Experimental |

  • Special Addresses:

    • Network Address: First address in a subnet (all host bits 0). Not assignable to a host.

    • Broadcast Address: Last address in a subnet (all host bits 1). Not assignable.

    • Loopback: 127.0.0.1 to 127.255.255.254. Tests local TCP/IP stack.

    • APIPA (Automatic Private IP Addressing): 169.254.0.0/16. Self-assigned when DHCP fails.

    • Private IP Ranges (RFC 1918):

      • 10.0.0.0 - 10.255.255.255 (10.0.0.0/8)

      • 172.16.0.0 - 172.31.255.255 (172.16.0.0/12)

      • 192.168.0.0 - 192.168.255.255 (192.168.0.0/16)

Subnet Masking & Custom Subnetting (FLSM)

  • Purpose: Divide a large network into smaller logical subnets.

  • Fixed-Length Subnet Masking (FLSM): All subnets are the same size.

  • Key Formula: Number of Subnets = $$\displaystyle 2^{\text{new bits borrowed}} $$

    Number of Hosts per Subnet = $$\displaystyle 2^{\text{host bits remaining}} - 2 $$

  • Example: Subnet 192.168.1.0/24 into 4 subnets.

    • Borrow 2 bits (from host portion). New mask: /26 (255.255.255.192).

    • Subnet Increment = $$\displaystyle 2^{\text{borrowed bits}} = 2^2 = 4 $$ (in the 4th octet: 0, 64, 128, 192).

    • Subnets: 192.168.1.0/26, 192.168.1.64/26, 192.168.1.128/26, 192.168.1.192/26.

    • Hosts per subnet: $$\displaystyle 2^{6} - 2 = 62 $$.

Calculating Network ID, Broadcast ID, Usable Host Range

Given an IP address and subnet mask:

  1. Convert IP and mask to binary.

  2. Network ID: Perform bitwise AND between IP and mask.

  3. Broadcast ID: Set all host bits of Network ID to 1.

  4. Usable Range: Network ID + 1 to Broadcast ID - 1.

[!TIP] Exam Tip: Practice converting between dotted-decimal and binary quickly. The subnet mask's binary form (consecutive 1s) is key to all calculations.

IPv6 Addressing Fundamentals

  • Length: 128 bits, represented as 8 groups of 4 hexadecimal digits.

  • Notation: 2001:0db8:85a3:0000:0000:8a2e:0370:7334

    • Leading zeros can be omitted: 2001:db8:85a3::8a2e:370:7334

    • Consecutive zeros can be compressed once with ::.

  • Types:

    • Unicast: Global (2000::/3), Link-Local (fe80::/10).

    • Multicast: ff00::/8.

    • Anycast: Assigned to multiple interfaces, nearest one receives packet.

  • EUI-64: Method to generate Interface ID from 48-bit MAC.

    1. Split MAC: 0011.2233.4455 -> 00-11-22-33-44-55.

    2. Insert ff:fe in middle: 00-11-22-**ff-fe**-33-44-55.

    3. Invert 7th bit (Universal/Local bit). 00 -> 02 (if MAC is globally unique).

    Result: 0211.22ff.fe33.4455 -> 0211:22ff:fe33:4455.


3.2 Routing Concepts & Configuration

Routing Table Components

Field Description
Destination Network Target network prefix.
Mask Subnet mask for the destination.
Next Hop IP address of the next router.
Interface Local exit interface (e.g., Gig0/0).
Metric Cost/value to reach the network (hop count, bandwidth, delay).
Administrative Distance (AD) Trustworthiness of the route source (lower is better).

Static Routing

  • Configuration (Cisco IOS): ip route <destination_network> <mask> <next_hop_ip> [administrative_distance]

  • Advantages: Secure, predictable, low resource usage.

  • Disadvantages: Not scalable, manual maintenance, no fault tolerance.

  • Default Route (Gateway of Last Resort): ip route 0.0.0.0 0.0.0.0 <next_hop_ip>

Dynamic Routing Protocols Overview

Type Principle Examples Pros Cons
Distance Vector "Rumor mill" (shares entire table with neighbors). Uses hop count. RIP Simple, low overhead. Slow convergence, count-to-infinity.
Link-State "Map maker" (each router knows full topology). Uses cost (bandwidth). OSPF, EIGRP Fast convergence, scalable. Higher memory/CPU, complex.

RIP (Routing Information Protocol)

  • Operation: Distance Vector, max hop count 15 (16 = unreachable). Updates every 30 sec.

  • Configuration:

    
    router rip
    
     version 2
    
     network <network_id>  # Classful network statement
    
     no auto-summary      # Disable classful summarization
    
    
  • Verification: show ip route rip, debug ip rip

OSPF (Open Shortest Path First)

  • Operation: Link-State, uses Dijkstra's algorithm. Hierarchical (Areas). Area 0 is backbone.

  • Basic Single-Area Config:

    
    router ospf <process_id>
    
     network <network> <wildcard_mask> area <area_id>
    
    
    • Router ID: Highest IP on an active interface, or manually set router-id x.x.x.x.

    • Hello/Dead Intervals: Must match on adjacent routers (default: Hello 10s, Dead 40s on multi-access).

  • DR/BDR Election: On multi-access networks (like Ethernet). Elects Designated Router (DR) and Backup DR to reduce LSA flooding. Election based on highest OSPF priority (0-255), then highest Router ID.

  • Verification: show ip ospf neighbor, show ip route ospf

[!TIP] Common Pitfall: In OSPF network command, the wildcard mask is the inverse of the subnet mask (e.g., 255.255.255.0 -> 0.0.0.255).


3.3 Switching & VLANs (Layer 2 Technologies)

Switch Operation

  • MAC Address Table (CAM Table): Learned dynamically. Format: <MAC Address> | <VLAN> | <Port> | <Aging Timer>.

  • Frame Forwarding/Filtering:

    • Unicast: Forward out single port if MAC known.

    • Broadcast/Multicast/Unknown Unicast: Flood out all ports in same VLAN except incoming port.

    • Filtering: Discard frame if destination MAC is on same port as source.

VLANs (Virtual Local Area Networks)

  • Purpose: Logical segmentation at Layer 2. Improves security, reduces broadcast domains, simplifies management.

  • Configuration (Cisco):

    
    vlan <vlan_id>
    
     name <vlan_name>
    
    interface <interface_id>
    
     switchport mode access
    
     switchport access vlan <vlan_id>
    
    
  • Port Types:

    • Access Port: Carries traffic for ONE VLAN. End-station connection.

    • Trunk Port: Carries traffic for MULTIPLE VLANs. Switch-to-switch/router link.

  • Native VLAN: The VLAN that is untagged on a trunk (default is VLAN 1). Should be changed for security.

VLAN Trunking Protocol: IEEE 802.1Q

  • Frame Tagging: Inserts a 4-byte VLAN Tag into the Ethernet frame header.

    • TPID (Tag Protocol Identifier): 0x8100 (identifies 802.1Q frame).

    • TCI (Tag Control Information): Contains PRI (Priority), CFI (Canonical Format), VID (VLAN ID, 12 bits -> 4094 VLANs).

  • Native VLAN frames are transmitted untagged.

Inter-VLAN Routing (Router-on-a-Stick)

  • Requires a trunk link between router and switch.

  • Router Configuration (Sub-interfaces):

    
    interface gig0/0.10   # Sub-interface for VLAN 10
    
     encapsulation dot1q 10
    
     ip address 192.168.10.1 255.255.255.0
    
    interface gig0/0.20   # Sub-interface for VLAN 20
    
     encapsulation dot1q 20
    
     ip address 192.168.20.1 255.255.255.0
    
    
  • Hosts in each VLAN use the sub-interface IP as their default gateway.

Spanning Tree Protocol (STP) Fundamentals

  • Purpose: Prevent Layer 2 loops in redundant topologies. Creates a loop-free logical topology.

  • Root Bridge Election: Bridge with lowest Bridge ID (BID = Priority + MAC). Default priority 32768.

  • Port Roles:

    • Root Port (RP): Non-root bridge's best path to Root Bridge.

    • Designated Port (DP): Forwarding port for a given segment.

    • Blocked/Alternate Port: Provides backup, does not forward frames.

  • Port States (802.1D):

    1. Blocking: No learning/forwarding. Listens for BPDUs.

    2. Listening: No learning/forwarding. Processes BPDUs, participates in election.

    3. Learning: Learns MACs, does not forward frames.

    4. Forwarding: Learns MACs, forwards frames.

    5. Disabled: Administratively down.

  • Convergence: Process of transitioning ports to Forwarding/Blocking after a topology change. Can be slow (30-50 sec) in classic STP.

  • Rapid STP (RSTP, 802.1w): Faster convergence (1-2 sec). Port roles: Alternate, Backup.

[!TIP] Lab Focus: Always verify VLAN membership with show vlan brief. For trunk status, use show interfaces trunk. STP root bridge should be a core switch (manually set priority: spanning-tree vlan 1 priority 4096).


3.4 Transport Layer Protocols (TCP & UDP)

TCP (Transmission Control Protocol)

  • Connection-Oriented: Establishes a reliable connection via 3-Way Handshake before data transfer.

  • 3-Way Handshake:

    1. SYN: Client -> Server (Seq = x).

    2. SYN-ACK: Server -> Client (Seq = y, Ack = x+1).

    3. ACK: Client -> Server (Seq = x+1, Ack = y+1).

  • Reliability Mechanisms:

    • Sequencing & Acknowledgments (ACKs): Guarantees in-order delivery.

    • Retransmission: Lost packets are resent after timeout (RTO).

    • Flow Control (Sliding Window): Receiver advertises Window Size (buffer space) to control sender rate.

    • Error Control: Checksum for header/data integrity.

  • Congestion Control: Adjusts sending rate based on network congestion (algorithms: Slow Start, Congestion Avoidance, Fast Retransmit, Fast Recovery).

  • Key Header Fields:

    • Sequence Number (32-bit): Byte number of first data byte in segment.

    • Acknowledgment Number (32-bit): Next expected byte (cumulative ACK).

    • Flags (Control Bits): URG, ACK, PSH, RST, SYN, FIN.

    • Window Size (16-bit): Receiver's available buffer space.

  • Full-Duplex: Separate channels for send/receive.

UDP (User Datagram Protocol)

  • Connectionless: No connection setup/teardown.

  • Unreliable: No ACKs, sequencing, or retransmission. "Best-effort" delivery.

  • Header Simplicity: 8 bytes (Source Port, Dest Port, Length, Checksum).

  • Use Cases: DNS, VoIP, Streaming Media, DHCP, SNMP. Where speed is critical, and some loss is acceptable.

  • No Flow/Congestion Control: Can flood network.

Port Numbers & Socket Addressing

  • Socket: (IP Address, Port Number) uniquely identifies a process.

  • Port Ranges:

    • Well-Known (0-1023): System services (HTTP:80, HTTPS:443, DNS:53, SSH:22).

    • Registered (1024-49151): User processes (MySQL:3306).

    • Dynamic/Private (49152-65535): Client-side ephemeral ports.

[!TIP] Wireshark Analysis: Filter for tcp.flags.syn==1 and tcp.flags.ack==0 to see SYN packets. Use Follow -> TCP Stream to reconstruct application data. Compare UDP's single packet exchange vs. TCP's multi-packet handshake.


3.5 Core Application Layer Protocols & Services

HTTP/HTTPS

  • Model: Client (Browser) sends Request -> Server sends Response.

  • Ports: HTTP: 80, HTTPS: 443 (TLS/SSL encrypted).

  • Methods: GET, POST, PUT, DELETE, HEAD.

  • Commands: curl http://example.com, wget https://example.com.

DNS (Domain Name System)

  • Purpose: Hierarchical, distributed database translating FQDN to IP Address.

  • Resolution Process:

    1. Recursive Query: Client/Resolver asks a DNS server for an answer (server does all work).

    2. Iterative Query: DNS server returns a referral to another server if it doesn't know.

  • Common Record Types:

    • A: IPv4 address.

    • AAAA: IPv6 address.

    • CNAME: Canonical name (alias).

    • MX: Mail exchange server.

  • Commands: nslookup example.com, dig example.com A.

DHCP (Dynamic Host Configuration Protocol)

  • Purpose: Automatically assign IP config (IP, mask, gateway, DNS) to clients.

  • DORA Process:

    1. Discover (Client broadcast).

    2. Offer (Server unicast/broadcast).

    3. Request (Client broadcast, selects one offer).

    4. Acknowledge (Server unicast, final config).

  • Server Config (Cisco):

    
    ip dhcp pool <pool_name>
    
     network <network> <mask>
    
     default-router <gateway_ip>
    
     dns-server <dns_ip>
    
     lease <days> <hours> <minutes>
    
    
  • Client View: ipconfig /release, ipconfig /renew (Windows).

FTP (File Transfer Protocol)

  • Connections: Separate Control Connection (TCP 21, persistent) and Data Connection (TCP 20 for active, ephemeral for passive).

  • Active Mode: Server initiates data connection to client (port 20 -> client's specified port). Firewall issues common.

  • Passive Mode (PASV): Client initiates both connections. Server opens ephemeral port, client connects. Works through firewalls.

  • Common Commands: user, pass, ls, get, put, bye.

SSH (Secure Shell)

  • Secure Remote Management: Encrypted terminal session. Replaces Telnet.

  • Port: 22.

  • Authentication: Password or Public-Key Cryptography (more secure).

  • Key-Based Auth: Client has private key, server has matching public key in ~/.ssh/authorized_keys.

  • Command: ssh username@hostname.


3.6 Network Address Translation (NAT) & Access Control

NAT (Network Address Translation)

  • Purpose: Conserves public IPv4 addresses, provides basic security (hides internal structure).

  • Types:

    • Static NAT: One-to-one mapping (public IP <-> private IP). For servers.

    • Dynamic NAT: Pool of public IPs, assigned dynamically to private hosts.

    • PAT (Port Address Translation / NAT Overload): Many private IPs to ONE public IP using unique port numbers. Most common for home/SME.

  • PAT Configuration (Cisco):

    
    access-list 1 permit 192.168.1.0 0.0.0.255   # Define inside network
    
    interface gig0/0  # Inside interface
    
     ip nat inside
    
    interface gig0/1  # Outside interface
    
     ip nat outside
    
    ip nat inside source list 1 interface gig0/1 overload
    
    

ACLs (Access Control Lists)

  • Purpose: Filter traffic based on rules (permit/deny). Applied to interfaces inbound/outbound.

  • Types:

    • Standard ACLs (1-99, 1300-1999): Filter only by SOURCE IP. Apply close to destination.

    • Extended ACLs (100-199, 2000-2699): Filter by source/dest IP, protocol, port. Apply close to source.

  • Logic: Processed top-down, first match wins. Implicit deny any at end.

  • Extended ACL Example (Block Web & Ping from 192.168.2.0/24 to 10.0.0.5):

    
    access-list 100 deny tcp 192.168.2.0 0.0.0.255 host 10.0.0.5 eq 80
    
    access-list 100 deny icmp 192.168.2.0 0.0.0.255 host 10.0.0.5
    
    access-list 100 permit ip any any   # Explicit permit for other traffic
    
    interface gig0/0
    
     ip access-group 100 out   # Apply outbound on interface towards 10.0.0.5
    
    
  • Wildcard Masks: Inverse of subnet mask. 0.0.0.255 = /24, 0.0.0.0 = single host.

[!TIP] Critical Rule: Extended ACLs should be placed as close to the SOURCE as possible to filter unwanted traffic early. Standard ACLs should be placed as close to the DESTINATION as possible since they don't filter by destination.


3.7 Network Troubleshooting Methodology & Tools

Systematic Troubleshooting Approach

  1. Identify the problem (symptoms, scope).

  2. Establish a theory of probable cause.

  3. Test the theory to determine cause.

  4. Establish a plan of action.

  5. Implement the solution.

  6. Verify system functionality.

  7. Document findings, actions, outcomes.

Command-Line Tools

Tool Protocol Purpose Key Output
ping ICMP Echo Basic reachability, latency, packet loss. Reply from x.x.x.x: bytes=32 time=10ms TTL=64
traceroute (Linux) / tracert (Windows) ICMP/UDP Path to destination, identify slow/failed hops. List of routers/hops with RTTs.
arp -a ARP View IP-to-MAC resolution cache. 192.168.1.1 aa-bb-cc-dd-ee-ff
ipconfig (Win) / ifconfig (Linux) N/A View local IP config, interface status. IPv4 Address, Subnet Mask, Default Gateway.
nslookup / dig DNS Query DNS records, test resolution. Server:, Address:, Non-authoritative answer:.
netstat -an TCP/UDP View all active connections and listening ports. Proto Local Address Foreign Address State

Protocol Analyzer (Wireshark) Basics

  • Capture: Start on relevant interface (e.g., Ethernet).

  • Display Filters: Filter traffic for analysis.

    • tcp.port == 80 or http

    • dns

    • dhcp

    • icmp

    • ip.addr == 192.168.1.10

  • Follow TCP Stream: Right-click a packet -> Follow -> TCP Stream. Reassembles application data.

  • Statistics: Statistics -> Conversations (see endpoints), Statistics -> Protocol Hierarchy.

[!TIP] Common Pitfalls:

  • ping fails but arp -a shows correct MAC: Likely firewall blocking ICMP on target.
  • traceroute shows * * * at a hop: That hop is blocking ICMP/UDP (common), not necessarily down.
  • No DHCP lease: Check ipconfig /release && ipconfig /renew, verify DHCP server is on same subnet or relay configured.
Go to where you left off?

Quick Add to Notes

Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.

Create free account

Have an account? Log in