UNIT 4: DATA COMMUNICATION LAB - SHORT NOTES
4.0 UNIT OVERVIEW & PREREQUISITES
4.0.1 Recap of Fundamental Concepts
-
OSI/TCP-IP Models: Remember the 7-layer OSI model (Physical, Data Link, Network, Transport, Session, Presentation, Application) and the 4-layer TCP/IP model (Link, Internet, Transport, Application). Labs often map tools to specific layers.
-
Signal Types: Analog vs. Digital signals.
-
Transmission Media: Guided (Twisted Pair, Coaxial, Fiber) vs. Unguided (Radio, Microwave, Infrared).
-
Multiplexing: FDM, TDM, WDM.
4.0.2 Essential Lab Software & Tools
| Tool Category | Examples | Primary Use |
|---|---|---|
| Network Simulators | NS2/NS3, GNS3, Cisco Packet Tracer | Build virtual topologies, configure routers/switches, test protocols without hardware. |
| Protocol Analyzers | Wireshark | Capture, decode, and analyze live network packets. |
| Virtualization | VMware, VirtualBox | Run multiple OS instances (e.g., client, server, firewall) on one physical machine. |
| CLI Utilities | ping, traceroute (tracert), ipconfig/ifconfig, netstat |
Basic connectivity testing, path tracing, interface config, active connection monitoring. |
4.1 CORE NETWORK CONFIGURATION & TROUBLESHOOTING LABS
4.1.1 TCP/IP Stack Configuration & Verification
-
Static vs. Dynamic IP:
-
Static: Manual assignment (
ipconfig /static ...). Used for servers, printers. -
Dynamic (DHCP): Automatic lease from a DHCP server.
-
-
Subnetting Exercise: Given an IP and subnet mask, calculate:
-
Network Address:
IP & Subnet Mask -
Broadcast Address:
Network Address | ~Subnet Mask -
First/Last Usable Host.
-
-
Key Configuration Parameters: IP Address, Subnet Mask, Default Gateway, DNS Server(s).
-
Verification Commands:
-
ipconfig /all(Win) /ifconfigorip addr(Linux): View all adapter details. -
ping <gateway>: Test L2/L3 connectivity to local router. -
arp -a: View ARP cache (IP to MAC resolution). -
nslookup <domain>: Test DNS resolution.
-
[!TIP] Common Pitfall: Forgetting to set the correct Default Gateway when accessing outside the local subnet.
pingfails beyond the gateway if this is wrong.
4.1.2 Local Area Network (LAN) Setup & Testing
-
Cable Types:
-
Straight-through: Device to switch/hub (PC-Switch, Switch-Router).
-
Crossover: Like device to like device (PC-PC, Switch-Switch, Router-Router).
-
Modern devices often have Auto-MDI/MDIX, making crossover less critical.
-
-
Basic Switch Configuration (CLI):
Switch> enable Switch# configure terminal Switch(config)# hostname SW1 SW1(config)# interface vlan 1 SW1(config-if)# ip address 192.168.1.1 255.255.255.0 // For management SW1(config-if)# no shutdown SW1(config-if)# exit SW1(config)# ip default-gateway 192.168.1.254 -
VLANs (Intro):
vlan 10,name Sales; assign port:interface fa0/1,switchport access vlan 10.
4.1.3 Network Troubleshooting Methodology
Follow the OSI Model Top-Down approach:
-
Physical Layer: Check link lights, cable integrity (use cable tester), correct port.
-
Data Link Layer: Check MAC address table (
show mac-address-table), VLAN membership, duplex mismatch. -
Network Layer:
pinggateway,tracerouteto destination, check IP config, routing tables (show ip route). -
Transport+: Check port status (
netstat -an), firewall rules.
-
tracerouteAnalysis: Shows each hop (router) and round-trip time (RTT). High RTT or timeouts (* * *) indicate congestion or a down hop. -
netstatOutput:Proto, Local Address (IP:Port), Foreign Address (IP:Port), State (LISTENING, ESTABLISHED, TIME_WAIT).
4.2 PROTOCOL ANALYSIS & PACKET INSPECTION (WIRESHARK-CENTRIC)
4.2.1 Wireshark Fundamentals
-
Capture Filters: Define what to capture (use BPF syntax). Example:
host 192.168.1.1 and tcp port 80. -
Display Filters: Define what to show from captured data (more powerful). Example:
http.requestortcp.flags.syn == 1. -
Packet List Pane: Summary line.
-
Packet Details Pane: Expandable protocol hierarchy (Ethernet II -> IP -> TCP -> HTTP).
-
Follow TCP/UDP Stream: Reassembles a conversation into a readable text/hex view.
4.2.2 Analysis of Key Layer 3 & 4 Protocols
| Protocol | Key Fields & Concepts | Wireshark Filter Example |
|---|---|---|
| IP | Version, Header Length, TTL (decrements per hop), Protocol (6=TCP, 17=UDP), Source/Dest IP, Total Length, Checksum. | ip.ttl == 64 (common for Linux) |
| ICMP | Type (8=Echo Request/ping, 0=Echo Reply), Code, Checksum, Identifier, Sequence Number, Data. | icmp.type == 8 |
| TCP | Source/Dest Port, Sequence Number, Acknowledgment Number, Flags (SYN, ACK, FIN, RST, PSH, URG), Window Size, Checksum. | tcp.flags.syn == 1 and tcp.flags.ack == 0 (SYN) |
| UDP | Source/Dest Port, Length, Checksum. Connectionless. | udp.port == 53 (DNS) |
[!TIP] TCP Three-Way Handshake: Must see SYN -> SYN/ACK -> ACK sequence for a new connection. Look for matching
SeqandAcknumbers (Ack = Seq+1).
4.2.3 Analysis of Application Layer Protocols
-
HTTP:
-
Request:
GET /index.html HTTP/1.1,Host:,User-Agent:. -
Response:
HTTP/1.1 200 OK,Content-Type:,Content-Length:. -
Filter:
http.request.method == "GET".
-
-
DNS:
-
Query: Transaction ID, Flags (Standard Query), Questions (QName, QType, QClass).
-
Response: Answers section contains Resource Records (RR) (Type: A=IPv4, AAAA=IPv6, MX=Mail).
-
DORA Process: See DHCP below.
-
Filter:
dns.qry.name == "www.google.com".
-
-
DHCP (DORA Process):
-
Discover (Client -> Broadcast)
-
Offer (Server -> Client)
-
Request (Client -> Server)
-
Acknowledgment (Server -> Client)
- Filter:
bootp(old name) ordhcp.
-
-
FTP: Separate Command Channel (TCP 21) and Data Channel (TCP 20 or dynamic).
PORTandPASVmodes change data connection direction. -
SMTP: Commands like
HELO,MAIL FROM:,RCPT TO:,DATA.
4.3 ROUTING & SWITCHING CONCEPTS (SIMULATION-BASED)
4.3.1 Static Routing Configuration
-
Topology: Router1 -- Router2 -- Router3, each with a LAN on the other side.
-
Command (Cisco IOS):
Router(config)# ip route <destination_network> <subnet_mask> <next_hop_ip> // Example: ip route 192.168.3.0 255.255.255.0 10.0.0.2 -
Verification:
show ip route. Static routes marked withS. Look for the exact destination network and next-hop IP/exit interface.
4.3.2 Dynamic Routing Protocols (Introductory)
| Feature | RIP (v1/v2) | OSPF (v2) |
|---|---|---|
| Type | Distance Vector | Link-State |
| Metric | Hop Count (max 15) | Cost (based on bandwidth) |
| Convergence | Slower (periodic updates) | Faster (event-triggered, LSA flooding) |
| VLSM Support | RIP v2 only | Yes |
| Config Command | router rip, version 2, network <network_id> |
router ospf 1, network <network> <wildcard> area 0 |
[!TIP] Key Difference: RIP sends entire routing table periodically. OSPF sends only changes (LSA) and builds a complete network map (LSDB).
4.3.3 Switch Configuration & VLANs
-
Create VLAN:
vlan 20,name Engineering. -
Assign Access Port:
interface fa0/5,switchport mode access,switchport access vlan 20. -
Trunking (802.1Q): Encapsulates frames with a VLAN tag.
interface fa0/24 switchport mode trunk switchport trunk allowed vlan 10,20,30 -
Inter-VLAN Routing (Router-on-a-Stick):
-
Configure sub-interfaces on router connected to trunk port.
-
Encapsulate each sub-interface with 802.1Q.
interface g0/0.10 encapsulation dot1Q 10 ip address 192.168.10.1 255.255.255.0 -
4.4 ADVANCED TOPICS & PERFORMANCE EVALUATION
4.4.1 Network Performance Measurement
-
Throughput: Actual data transfer rate (bps). Use
iperf(client/server).# Server: iperf -s # Client: iperf -c <server_ip> -t 10 // Test for 10 seconds -
Latency (Delay): Time for a bit to travel from source to destination. Measured by
ping(RTT/2 approx). -
Jitter: Variation in latency. Critical for real-time apps (VoIP, video).
iperfcan report jitter with-u(UDP). -
Factors: Bandwidth, Congestion, Protocol Overhead (headers), Distance, Processing Delay.
4.4.2 Introduction to Network Security Labs
-
ARP Poisoning (Spoofing): Attacker sends forged ARP messages, linking their MAC to the gateway's IP, enabling Man-in-the-Middle (MitM). Analyze in Wireshark: see duplicate ARP replies.
-
Port Scan: Attacker probes target ports to find open services. Filter in Wireshark:
tcp.flags.syn == 1 and tcp.flags.ack == 0(SYN scan). -
Basic Firewall (Stateless): Rules based on IP/Port only. Example (Linux
iptables):iptables -A INPUT -p tcp --dport 22 -j ACCEPT. -
VPN (Tunneling): Encapsulates original packet inside a new packet. Common protocols: IPsec (L3), SSL/TLS (L4/App). Look for ESP (IP protocol 50) or GRE packets.
4.4.3 Wireless LAN (WLAN) Analysis
-
802.11 Frame Types:
-
Management: Association Request/Response, Beacon, Authentication.
-
Control: RTS/CTS, ACK.
-
Data: Actual payload.
-
-
Capture Mode: Monitor mode (not managed mode) to capture all traffic in the channel.
-
WPA2 Handshake (4-way): Captured during client association. Contains nonces and MIC. Used for offline password cracking (with tools like aircrack-ng).
-
Wireshark Filter:
wlan.fc.type_subtype == 0x08(Beacon frame).
4.5 MINI-PROJECT & INTEGRATED SCENARIO-BASED LABS
4.5.1 Designing a Small Business Network
-
Requirements: Number of departments, devices, internet access, security needs.
-
IP Scheme: Use private IP ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16). Plan subnets per VLAN/department.
-
Topology Diagram: Include routers, switches (with VLANs), firewalls, servers (DHCP, DNS), workstations.
-
Implementation Steps:
-
Configure router interfaces and static routes (or dynamic protocol).
-
Configure switch VLANs and trunk ports.
-
Configure DHCP pool on router/server.
-
Test inter-VLAN and internet connectivity.
-
4.5.2 End-to-End Application Flow Analysis (Web Request)
-
Capture on Client.
-
Sequence:
-
DNS Query/Response:
Standard query->Response(A record). -
TCP Three-Way Handshake: SYN, SYN/ACK, ACK to server IP:80.
-
HTTP Request:
GET / HTTP/1.1,Host: example.com. -
HTTP Response:
HTTP/1.1 200 OK, followed by HTML data (often multiple TCP segments). -
TCP Connection Termination: FIN/ACK exchange.
-
-
Use "Follow -> TCP Stream" to see the entire HTTP conversation in order.
4.5.3 Troubleshooting a Faulty Network Scenario
-
Methodology:
-
Identify Symptom: "PC1 cannot ping Server1."
-
Gather Info:
ipconfigon PC1,pinggateway,pingServer1's IP. -
Isolate: Can PC1 ping other devices in its VLAN? Can other devices ping Server1?
-
Check Physical/Link: LED lights, cable test.
-
Check Data Link:
show mac-address-tableon switch. Is PC1's MAC present on correct port? Is Server1's MAC present? -
Check Network:
tracerouteto Server1. Where does it stop? Check routing tables on intervening routers. -
Check Higher Layers:
telnet <server_ip> 80(if HTTP service expected). Check server firewall.
-
-
Common Faults: Wrong VLAN assignment, incorrect static route, disabled port, duplex mismatch, ACL blocking.
4.6 LAB REPORTING & DOCUMENTATION
4.6.1 Standard Lab Report Structure
-
Objective: What you intended to learn/verify.
-
Theory: Brief background on protocols/configurations used.
-
Topology/Setup: Network diagram (draw.io, Visio) with IP addressing scheme table.
-
Procedure: Step-by-step commands and actions taken.
-
Observations: Screenshots of command outputs (
showcommands,pingresults), Wireshark packet details (highlight key fields). -
Analysis: Explain why the results occurred. Correlate output with theory (e.g., "The
pingRTT of 2ms indicates local network connectivity"). -
Conclusion: Summarize findings, state if objective was met, note any issues.
4.6.2 Presenting Packet Capture Screenshots
-
Always zoom to the relevant packet in the packet list.
-
Expand the protocol tree in the details pane to show the specific field being discussed (e.g., expand TCP to show SYN flag, or HTTP to show GET request).
-
Use a red box or arrow (in image editor) to point to the exact field.
-
Caption: "Figure 1: Wireshark capture showing TCP three-way handshake initiation (SYN packet)."
4.6.3 Analyzing Tabular Data
-
pingStatistics: Focus on Average RTT (latency), Packet Loss % (indicates congestion/failure), TTL (hint at OS/distance). -
iperfResults: Report Bandwidth (Mbits/sec) for both directions. Note if it matches expected link speed. Jitter value for UDP tests.
4.6.4 Drawing Accurate Network Diagrams
-
Use standard symbols: cloud (internet/WAN), router (cylinder), switch (box with arrows), PC (monitor icon).
-
Label all interfaces with IP address/subnet mask.
-
Show VLAN assignments on switch ports (e.g.,
Fa0/1: VLAN 10). -
Indicate trunk links with a double line or tag symbol.