Skip to content
EC-605 · DATA COMMUNICATION LAB/Quick Revision Short Notes

DATA COMMUNICATION LAB (EC-605) - Unit 4 Short Notes

UNIT 4: DATA COMMUNICATION LAB - SHORT NOTES

4.0 UNIT OVERVIEW & PREREQUISITES

4.0.1 Recap of Fundamental Concepts

  • OSI/TCP-IP Models: Remember the 7-layer OSI model (Physical, Data Link, Network, Transport, Session, Presentation, Application) and the 4-layer TCP/IP model (Link, Internet, Transport, Application). Labs often map tools to specific layers.

  • Signal Types: Analog vs. Digital signals.

  • Transmission Media: Guided (Twisted Pair, Coaxial, Fiber) vs. Unguided (Radio, Microwave, Infrared).

  • Multiplexing: FDM, TDM, WDM.

4.0.2 Essential Lab Software & Tools

Tool Category Examples Primary Use
Network Simulators NS2/NS3, GNS3, Cisco Packet Tracer Build virtual topologies, configure routers/switches, test protocols without hardware.
Protocol Analyzers Wireshark Capture, decode, and analyze live network packets.
Virtualization VMware, VirtualBox Run multiple OS instances (e.g., client, server, firewall) on one physical machine.
CLI Utilities ping, traceroute (tracert), ipconfig/ifconfig, netstat Basic connectivity testing, path tracing, interface config, active connection monitoring.

4.1 CORE NETWORK CONFIGURATION & TROUBLESHOOTING LABS

4.1.1 TCP/IP Stack Configuration & Verification

  • Static vs. Dynamic IP:

    • Static: Manual assignment (ipconfig /static ...). Used for servers, printers.

    • Dynamic (DHCP): Automatic lease from a DHCP server.

  • Subnetting Exercise: Given an IP and subnet mask, calculate:

    • Network Address: IP & Subnet Mask

    • Broadcast Address: Network Address | ~Subnet Mask

    • First/Last Usable Host.

  • Key Configuration Parameters: IP Address, Subnet Mask, Default Gateway, DNS Server(s).

  • Verification Commands:

    • ipconfig /all (Win) / ifconfig or ip addr (Linux): View all adapter details.

    • ping <gateway>: Test L2/L3 connectivity to local router.

    • arp -a: View ARP cache (IP to MAC resolution).

    • nslookup <domain>: Test DNS resolution.

[!TIP] Common Pitfall: Forgetting to set the correct Default Gateway when accessing outside the local subnet. ping fails beyond the gateway if this is wrong.

4.1.2 Local Area Network (LAN) Setup & Testing

  • Cable Types:

    • Straight-through: Device to switch/hub (PC-Switch, Switch-Router).

    • Crossover: Like device to like device (PC-PC, Switch-Switch, Router-Router).

    • Modern devices often have Auto-MDI/MDIX, making crossover less critical.

  • Basic Switch Configuration (CLI):

    
    Switch> enable
    
    Switch# configure terminal
    
    Switch(config)# hostname SW1
    
    SW1(config)# interface vlan 1
    
    SW1(config-if)# ip address 192.168.1.1 255.255.255.0  // For management
    
    SW1(config-if)# no shutdown
    
    SW1(config-if)# exit
    
    SW1(config)# ip default-gateway 192.168.1.254
    
    
  • VLANs (Intro): vlan 10, name Sales; assign port: interface fa0/1, switchport access vlan 10.

4.1.3 Network Troubleshooting Methodology

Follow the OSI Model Top-Down approach:

  1. Physical Layer: Check link lights, cable integrity (use cable tester), correct port.

  2. Data Link Layer: Check MAC address table (show mac-address-table), VLAN membership, duplex mismatch.

  3. Network Layer: ping gateway, traceroute to destination, check IP config, routing tables (show ip route).

  4. Transport+: Check port status (netstat -an), firewall rules.

  • traceroute Analysis: Shows each hop (router) and round-trip time (RTT). High RTT or timeouts (* * *) indicate congestion or a down hop.

  • netstat Output: Proto, Local Address (IP:Port), Foreign Address (IP:Port), State (LISTENING, ESTABLISHED, TIME_WAIT).


4.2 PROTOCOL ANALYSIS & PACKET INSPECTION (WIRESHARK-CENTRIC)

4.2.1 Wireshark Fundamentals

  • Capture Filters: Define what to capture (use BPF syntax). Example: host 192.168.1.1 and tcp port 80.

  • Display Filters: Define what to show from captured data (more powerful). Example: http.request or tcp.flags.syn == 1.

  • Packet List Pane: Summary line.

  • Packet Details Pane: Expandable protocol hierarchy (Ethernet II -> IP -> TCP -> HTTP).

  • Follow TCP/UDP Stream: Reassembles a conversation into a readable text/hex view.

4.2.2 Analysis of Key Layer 3 & 4 Protocols

Protocol Key Fields & Concepts Wireshark Filter Example
IP Version, Header Length, TTL (decrements per hop), Protocol (6=TCP, 17=UDP), Source/Dest IP, Total Length, Checksum. ip.ttl == 64 (common for Linux)
ICMP Type (8=Echo Request/ping, 0=Echo Reply), Code, Checksum, Identifier, Sequence Number, Data. icmp.type == 8
TCP Source/Dest Port, Sequence Number, Acknowledgment Number, Flags (SYN, ACK, FIN, RST, PSH, URG), Window Size, Checksum. tcp.flags.syn == 1 and tcp.flags.ack == 0 (SYN)
UDP Source/Dest Port, Length, Checksum. Connectionless. udp.port == 53 (DNS)

[!TIP] TCP Three-Way Handshake: Must see SYN -> SYN/ACK -> ACK sequence for a new connection. Look for matching Seq and Ack numbers (Ack = Seq+1).

4.2.3 Analysis of Application Layer Protocols

  • HTTP:

    • Request: GET /index.html HTTP/1.1, Host:, User-Agent:.

    • Response: HTTP/1.1 200 OK, Content-Type:, Content-Length:.

    • Filter: http.request.method == "GET".

  • DNS:

    • Query: Transaction ID, Flags (Standard Query), Questions (QName, QType, QClass).

    • Response: Answers section contains Resource Records (RR) (Type: A=IPv4, AAAA=IPv6, MX=Mail).

    • DORA Process: See DHCP below.

    • Filter: dns.qry.name == "www.google.com".

  • DHCP (DORA Process):

    1. Discover (Client -> Broadcast)

    2. Offer (Server -> Client)

    3. Request (Client -> Server)

    4. Acknowledgment (Server -> Client)

    • Filter: bootp (old name) or dhcp.
  • FTP: Separate Command Channel (TCP 21) and Data Channel (TCP 20 or dynamic). PORT and PASV modes change data connection direction.

  • SMTP: Commands like HELO, MAIL FROM:, RCPT TO:, DATA.


4.3 ROUTING & SWITCHING CONCEPTS (SIMULATION-BASED)

4.3.1 Static Routing Configuration

  • Topology: Router1 -- Router2 -- Router3, each with a LAN on the other side.

  • Command (Cisco IOS):

    
    Router(config)# ip route <destination_network> <subnet_mask> <next_hop_ip>
    
    // Example: ip route 192.168.3.0 255.255.255.0 10.0.0.2
    
    
  • Verification: show ip route. Static routes marked with S. Look for the exact destination network and next-hop IP/exit interface.

4.3.2 Dynamic Routing Protocols (Introductory)

Feature RIP (v1/v2) OSPF (v2)
Type Distance Vector Link-State
Metric Hop Count (max 15) Cost (based on bandwidth)
Convergence Slower (periodic updates) Faster (event-triggered, LSA flooding)
VLSM Support RIP v2 only Yes
Config Command router rip, version 2, network <network_id> router ospf 1, network <network> <wildcard> area 0

[!TIP] Key Difference: RIP sends entire routing table periodically. OSPF sends only changes (LSA) and builds a complete network map (LSDB).

4.3.3 Switch Configuration & VLANs

  • Create VLAN: vlan 20, name Engineering.

  • Assign Access Port: interface fa0/5, switchport mode access, switchport access vlan 20.

  • Trunking (802.1Q): Encapsulates frames with a VLAN tag.

    
    interface fa0/24
    
    switchport mode trunk
    
    switchport trunk allowed vlan 10,20,30
    
    
  • Inter-VLAN Routing (Router-on-a-Stick):

    1. Configure sub-interfaces on router connected to trunk port.

    2. Encapsulate each sub-interface with 802.1Q.

    
    interface g0/0.10
    
    encapsulation dot1Q 10
    
    ip address 192.168.10.1 255.255.255.0
    
    

4.4 ADVANCED TOPICS & PERFORMANCE EVALUATION

4.4.1 Network Performance Measurement

  • Throughput: Actual data transfer rate (bps). Use iperf (client/server).

    
    # Server: iperf -s
    
    # Client: iperf -c <server_ip> -t 10  // Test for 10 seconds
    
    
  • Latency (Delay): Time for a bit to travel from source to destination. Measured by ping (RTT/2 approx).

  • Jitter: Variation in latency. Critical for real-time apps (VoIP, video). iperf can report jitter with -u (UDP).

  • Factors: Bandwidth, Congestion, Protocol Overhead (headers), Distance, Processing Delay.

4.4.2 Introduction to Network Security Labs

  • ARP Poisoning (Spoofing): Attacker sends forged ARP messages, linking their MAC to the gateway's IP, enabling Man-in-the-Middle (MitM). Analyze in Wireshark: see duplicate ARP replies.

  • Port Scan: Attacker probes target ports to find open services. Filter in Wireshark: tcp.flags.syn == 1 and tcp.flags.ack == 0 (SYN scan).

  • Basic Firewall (Stateless): Rules based on IP/Port only. Example (Linux iptables): iptables -A INPUT -p tcp --dport 22 -j ACCEPT.

  • VPN (Tunneling): Encapsulates original packet inside a new packet. Common protocols: IPsec (L3), SSL/TLS (L4/App). Look for ESP (IP protocol 50) or GRE packets.

4.4.3 Wireless LAN (WLAN) Analysis

  • 802.11 Frame Types:

    • Management: Association Request/Response, Beacon, Authentication.

    • Control: RTS/CTS, ACK.

    • Data: Actual payload.

  • Capture Mode: Monitor mode (not managed mode) to capture all traffic in the channel.

  • WPA2 Handshake (4-way): Captured during client association. Contains nonces and MIC. Used for offline password cracking (with tools like aircrack-ng).

  • Wireshark Filter: wlan.fc.type_subtype == 0x08 (Beacon frame).


4.5 MINI-PROJECT & INTEGRATED SCENARIO-BASED LABS

4.5.1 Designing a Small Business Network

  1. Requirements: Number of departments, devices, internet access, security needs.

  2. IP Scheme: Use private IP ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16). Plan subnets per VLAN/department.

  3. Topology Diagram: Include routers, switches (with VLANs), firewalls, servers (DHCP, DNS), workstations.

  4. Implementation Steps:

    • Configure router interfaces and static routes (or dynamic protocol).

    • Configure switch VLANs and trunk ports.

    • Configure DHCP pool on router/server.

    • Test inter-VLAN and internet connectivity.

4.5.2 End-to-End Application Flow Analysis (Web Request)

  1. Capture on Client.

  2. Sequence:

    • DNS Query/Response: Standard query -> Response (A record).

    • TCP Three-Way Handshake: SYN, SYN/ACK, ACK to server IP:80.

    • HTTP Request: GET / HTTP/1.1, Host: example.com.

    • HTTP Response: HTTP/1.1 200 OK, followed by HTML data (often multiple TCP segments).

    • TCP Connection Termination: FIN/ACK exchange.

  3. Use "Follow -> TCP Stream" to see the entire HTTP conversation in order.

4.5.3 Troubleshooting a Faulty Network Scenario

  • Methodology:

    1. Identify Symptom: "PC1 cannot ping Server1."

    2. Gather Info: ipconfig on PC1, ping gateway, ping Server1's IP.

    3. Isolate: Can PC1 ping other devices in its VLAN? Can other devices ping Server1?

    4. Check Physical/Link: LED lights, cable test.

    5. Check Data Link: show mac-address-table on switch. Is PC1's MAC present on correct port? Is Server1's MAC present?

    6. Check Network: traceroute to Server1. Where does it stop? Check routing tables on intervening routers.

    7. Check Higher Layers: telnet <server_ip> 80 (if HTTP service expected). Check server firewall.

  • Common Faults: Wrong VLAN assignment, incorrect static route, disabled port, duplex mismatch, ACL blocking.


4.6 LAB REPORTING & DOCUMENTATION

4.6.1 Standard Lab Report Structure

  1. Objective: What you intended to learn/verify.

  2. Theory: Brief background on protocols/configurations used.

  3. Topology/Setup: Network diagram (draw.io, Visio) with IP addressing scheme table.

  4. Procedure: Step-by-step commands and actions taken.

  5. Observations: Screenshots of command outputs (show commands, ping results), Wireshark packet details (highlight key fields).

  6. Analysis: Explain why the results occurred. Correlate output with theory (e.g., "The ping RTT of 2ms indicates local network connectivity").

  7. Conclusion: Summarize findings, state if objective was met, note any issues.

4.6.2 Presenting Packet Capture Screenshots

  • Always zoom to the relevant packet in the packet list.

  • Expand the protocol tree in the details pane to show the specific field being discussed (e.g., expand TCP to show SYN flag, or HTTP to show GET request).

  • Use a red box or arrow (in image editor) to point to the exact field.

  • Caption: "Figure 1: Wireshark capture showing TCP three-way handshake initiation (SYN packet)."

4.6.3 Analyzing Tabular Data

  • ping Statistics: Focus on Average RTT (latency), Packet Loss % (indicates congestion/failure), TTL (hint at OS/distance).

  • iperf Results: Report Bandwidth (Mbits/sec) for both directions. Note if it matches expected link speed. Jitter value for UDP tests.

4.6.4 Drawing Accurate Network Diagrams

  • Use standard symbols: cloud (internet/WAN), router (cylinder), switch (box with arrows), PC (monitor icon).

  • Label all interfaces with IP address/subnet mask.

  • Show VLAN assignments on switch ports (e.g., Fa0/1: VLAN 10).

  • Indicate trunk links with a double line or tag symbol.

Go to where you left off?

Quick Add to Notes

Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.

Create free account

Have an account? Log in