UNIT 4: COMPUTER NETWORKS - EXAM-FOCUSED SHORT NOTES
1. NETWORK MODELS & FUNDAMENTAL ARCHITECTURES
ISO-OSI Reference Model (Frequent)
A 7-layer architectural framework for network communication. Each layer provides services to the layer above it.
| Layer | Function | Protocols/Devices |
|---|---|---|
| 7. Application | Network services to end-user applications. | HTTP, SMTP, DNS |
| 6. Presentation | Data translation, encryption/decryption, compression. | SSL/TLS (security), JPEG, MPEG |
| 5. Session | Establishes, manages, terminates sessions (dialog control). | NetBIOS, RPC |
| 4. Transport | End-to-end connection, reliability, flow control. | TCP (reliable), UDP (unreliable) |
| 3. Network | Path determination (routing), logical addressing (IP). | IP, ICMP, ARP, Routers |
| 2. Data Link | Framing, physical addressing (MAC), error control. | Ethernet (802.3), PPP, Switches, Bridges |
| 1. Physical | Bit transmission over medium (voltage, timing). | RJ45, fiber, repeaters, hubs |
Critique: Theoretically elegant but historically slow to implement; protocols were hard to design and deploy. TCP/IP became the practical de facto standard.
TCP/IP Protocol Suite / Model (Frequent)
A 4/5-layer practical model that underpins the modern Internet.
| Layer | Function | OSI Mapping |
|---|---|---|
| 5. Application | Combines OSI's Application, Presentation, Session. | 5,6,7 |
| 4. Transport | Same as OSI Transport. Host-to-host connectivity. | 4 |
| 3. Internet | Same as OSI Network. Routing & logical addressing (IP). | 3 |
| 2. Link/Network Interface | Combines OSI's Data Link & Physical. | 1,2 |
| (Optional) 1. Physical | Sometimes shown separately. | 1 |
Comparison:
-
Layer Mapping: TCP/IP's Application layer is broader; its Link layer is narrower.
-
Functionality: OSI strictly separates services, interfaces, and protocols. TCP/IP assumes a robust network layer and focuses on interoperability.
-
Implementation: TCP/IP protocols (IP, TCP, UDP) are the Internet's foundation. OSI remains a teaching/reference model.
Network Types & Components (Common)
-
PAN (Personal Area Network): Very short range (e.g., Bluetooth). <10m.
-
LAN (Local Area Network): Single building/campus (e.g., Ethernet). High speed.
-
MAN (Metropolitan Area Network): City-wide (e.g., Cable TV network).
-
WAN (Wide Area Network): Country/continent (e.g., Internet). Uses public infrastructure.
-
Internetwork: Connection of multiple networks (e.g., The Internet).
-
Components: Hosts (end systems), Links (wired/wireless), Intermediate devices (Hubs, Switches, Routers, Gateways).
-
Relationships: Peer-to-peer (equal status, e.g., two hosts). Primary-secondary (master-slave, e.g., client-server).
2. PHYSICAL LAYER & TRANSMISSION MEDIA
Transmission Media (Frequent)
Guided (Wired):
| Medium | Properties | Applications |
|---|---|---|
| Twisted Pair (UTP/STP) | 2 insulated copper wires. UTP unshielded, STP shielded. Low cost, easy install. Limited bandwidth & distance. | Telephone lines, Ethernet (10/100BASE-T). |
| Coaxial Cable | Central conductor, insulator, shield. Higher bandwidth than TP. Rigid. | Cable TV, older Ethernet (10BASE2/5). |
| Fiber Optic | Glass/plastic fiber, light pulses. Single-mode: long distance, high cost. Multi-mode: shorter distance, lower cost. Very high bandwidth, low loss, immune to EMI. | Backbones, long-haul telecom, high-speed LANs (FDDI, GigE). |
Unguided (Wireless):
| Medium | Properties | Applications |
|---|---|---|
| Radio | Omnidirectional, penetrate walls. Regulated frequencies. | Wi-Fi (802.11), Bluetooth, cellular. |
| Microwave | Directional (line-of-sight), high frequency. | Satellite, terrestrial point-to-point links. |
| Infrared | Very short range, line-of-sight, cannot penetrate walls. | Remote controls, IrDA. |
| Satellite | Geostationary (high delay) or LEO/MEO. Wide area coverage. | Global TV broadcast, GPS, internet backhaul. |
Channel Capacity & Performance (Frequent)
- Nyquist Formula (Noiseless): Maximum bit rate for a noiseless channel of bandwidth
BHz usingLsignal levels.
$$R_{max} = 2B \log_2 L \text{ (bps)}$$
> **Example:** B=3kHz, L=4 (2 bits/signal) → R = 2*3000*2 = 12,000 bps.
- Shannon's Theorem (Noisy): Maximum theoretical capacity
Cof a channel of bandwidthBHz with signal-to-noise ratioSNR.
$$C = B \log_2 (1 + \text{SNR}) \text{ (bps)}$$
> **Key:** SNR is often in dB: $$\displaystyle \text{SNR}_{\text{linear}} = 10^{\text{SNR}_{\text{dB}}/10} $$.
> **Example:** B=3kHz, SNR=30dB → SNR_lin=1000 → C ≈ 3000 * 9.97 ≈ 29.9 kbps.
Multiplexing (Common)
-
FDM (Frequency Division): Each signal gets a dedicated frequency band. Used in radio/TV broadcasting, traditional telephony.
-
TDM (Time Division): Each signal gets a dedicated time slot (time slice) in a repeating frame.
-
Synchronous TDM: Fixed slots, even if a source has no data (inefficient).
-
Statistical TDM: Dynamic slot allocation based on demand (more efficient).
-
-
WDM (Wavelength Division): Fiber optic version of FDM. Multiple light wavelengths (colors) on same fiber. DWDM (Dense WDM) packs channels very closely.
Line Coding & Digital Transmission (Common)
Purpose: Convert digital bits (1s/0s) into physical signals (voltage/light patterns) for transmission over a medium.
| Scheme | Encoding Rule | Example (Data: 101) | Sync? |
|---|---|---|---|
| NRZ (Non-Return to Zero) | 1=high, 0=low (or vice versa) | High-Low-High |
No (DC imbalance) |
| RZ (Return to Zero) | 1=high->mid, 0=low->mid (mid=0) | High-Mid-Low-Mid |
Yes (mid transition) |
| Manchester | 1=high->low transition, 0=low->high transition (in middle of bit) | ↓↑↓ |
Yes (transition each bit) |
| Diff. Manchester | Transition at start of bit: 1=no transition, 0=transition. | ↓↑↓ (depends on prev) |
Yes (transition at start) |
TDM Frame Calculation: For
nchannels each at rateRbps, frame size =n * (bits per channel). Frame rate =R / (bits per channel). Frame duration =1 / frame rate.
3. DATA LINK LAYER
Functions (Common)
-
Framing: Encapsulating network layer packets into frames (add header/trailer).
-
Physical Addressing: Using MAC addresses in frame header.
-
Error Control: Detection (CRC) and correction (Hamming).
-
Flow Control: Prevent fast sender overwhelming slow receiver.
-
Link Management: Establishing, maintaining, releasing link.
Error Detection & Correction (Frequent)
Detection:
-
Parity: Single bit (detect odd # errors). Double parity (2D) for burst errors.
-
Checksum: Sum of data words (1's complement). Used in higher layers (TCP/IP).
-
CRC (Cyclic Redundancy Check): Most powerful. Uses polynomial division.
Steps:
-
Append
rzeros to data, wherer= degree of generator polynomialG(x). -
Divide augmented data by
G(x)(modulo-2 division). -
Remainder (CRC bits) replaces appended zeros.
-
Transmit Codeword = Data + CRC.
-
Receiver divides received codeword by same
G(x). Remainder = 0 → No error.
-
Example: Data
1101011011(D(x)), G(x)=10011(degree 4).
- Append 4 zeros:
11010110110000.
- Divide by
10011→ Remainder =1110.
- Final Codeword:
11010110111110.
Correction:
-
Hamming Codes: Add
kparity bits tomdata bits to correct single-bit errors. Distanced_min=3. -
FEC (Forward Error Correction): Receiver corrects errors without retransmission. Used in noisy/long-delay links (satellite).
Data Link Protocols & Flow Control (Frequent)
Stop-and-Wait:
-
Sender sends 1 frame, waits for ACK before next.
-
Efficiency (Link Utilization): $$\displaystyle U = \frac{1}{1 + 2a} $$, where $$\displaystyle a = \frac{\text{Propagation Time}}{\text{Frame Transmission Time}} $$.
-
Limitation: Very inefficient for long propagation delays or high bandwidth.
Sliding Window Protocols:
-
Go-Back-N (GBN):
-
Sender window size
N, receiver window size1. -
Cumulative ACKs: ACK
nmeans all frames ≤nreceived correctly. -
Timeout: If ACK not received, sender re-transmits frame
nand all subsequent frames in window. -
Utilization: $$\displaystyle U \approx \frac{N}{1 + 2a} $$ (for large N, no errors).
-
-
Selective Repeat (SR):
-
Sender & receiver window size
N(typically ≤ half sequence space). -
Individual ACKs: Can ACK out-of-order frames.
-
Timeout: Retransmit only the missing frame.
-
Window Constraint: $$\displaystyle N \leq 2^{m-1} $$ (where
m= sequence # bits) to avoid ambiguity.
-
-
Piggybacking: Attaching ACK to a data frame going in the reverse direction (instead of separate ACK frame). Improves efficiency in full-duplex links.
Multiple Access Protocols / MAC Sublayer (Frequent)
Static Allocation: FDM, TDM, WDM. Efficient if traffic is constant, inefficient if bursty.
Random Access (Contention-Based):
| Protocol | Principle | Throughput (Max) | Key Point |
|---|---|---|---|
| Pure ALOHA | Transmit anytime; collisions destroy frames. | $$\displaystyle S = G e^{-2G} $$ → 18.4% at $$\displaystyle G=0.5 $$ | Vulnerable window = 2 x frame time. |
| Slotted ALOHA | Transmit only at slot start (synchronized). | $$\displaystyle S = G e^{-G} $$ → 36.8% at $$\displaystyle G=1 $$ | Halves vulnerable window. |
| 1-Persistent CSMA | Sense channel; if idle, transmit immediately; if busy, sense continuously. | Better than ALOHA, but high collision under load. | "1-persistent" = always transmit when idle. |
| Non-Persistent CSMA | Sense; if idle, transmit; if busy, wait random time, then re-sense. | Lower collision, but higher delay. | Less collision-prone. |
| p-Persistent CSMA | (For slotted channels) If idle, transmit with probability p; defer with 1-p to next slot. |
Balances collision vs. delay. | Used in some wireless systems. |
| CSMA/CD | Collision Detection: Abort transmission on collision (Ethernet). Min Frame Size: Must be ≥ $2 \times \text{Propagation Delay} \times \text{Bandwidth}$ to detect collision before finish. | Standard for wired Ethernet (bus/star). | Requires ability to hear while talking. |
| CSMA/CA | Collision Avoidance: (Wireless 802.11). Uses RTS/CTS handshake to reserve channel. | Solves hidden terminal problem. | Cannot reliably detect collision (wireless). |
| Binary Exponential Backoff (BEB) | After k-th collision, wait random time from 0 to $$\displaystyle (2^k - 1) $$ slot times. |
Reduces collision probability under heavy load. | k capped (e.g., 10 in Ethernet). |
Controlled Access: Token Passing (Token Ring, Token Bus), Reservation, Polling.
LAN Standards & MAC Protocols (Frequent)
| Standard | Access Method | Topology | Key Features |
|---|---|---|---|
| IEEE 802.3 (Ethernet) | CSMA/CD | Bus (logical), Star (physical) | Dominant LAN tech. Frame: Preamble, Dest/Src MAC, Type, Data, FCS. |
| IEEE 802.4 (Token Bus) | Token Passing | Bus (logical) | Token passed in numerical order of MAC addresses. |
| IEEE 802.5 (Token Ring) | Token Passing | Ring | Uses monitor station for ring maintenance. Frame: Delimiter, Access Control, Frame Control, Dest/Src MAC, Data, FCS. |
| IEEE 802.11 (Wi-Fi) | CSMA/CA with RTS/CTS | Star (with AP) | Hidden terminal problem. Uses DIFS, SIFS, NAV. |
| FDDI | Token Passing | Dual ring (primary/secondary) | High-speed (100 Mbps), fiber, fault-tolerant (ring wraps). |
Framing & Stuffing (Common)
-
Bit Stuffing: (Flag-based framing). Insert a
0after any five consecutive1s in data to avoid confusion with flag01111110. Receiver removes stuffed0.Example: Data
01111110111→ After stuffing:01111110 0 111(flag01111110not in data). -
Byte Stuffing: (Character-oriented). Use special escape character (e.g.,
DLE) before any flag-like character in data.
Data Link Layer Protocols (Common)
-
HDLC (High-Level Data Link Control):
-
Frame:
Flag (01111110)|Address|Control|Info|FCS|Flag -
Modes: NRM (Normal Response), ABM (Asynchronous Balanced), ARM (Asynchronous Response).
-
Operation: Uses
I-frames(data),S-frames(control),U-frames(management).
-
-
PPP (Point-to-Point Protocol):
-
Frame:
Flag|Address (0xFF)|Control (0x03)|Protocol|Data|FCS|Flag -
Phases: Link Establishment (LCP), Authentication (PAP/CHAP), Network Layer Protocol (NCP), Termination.
-
Use: Over serial links (dial-up, DSL).
-
-
SLIP (Serial Line IP): Predecessor to PPP. No error detection, no protocol field, no authentication. Limitation: Only supports IP, no dynamic IP assignment.
4. NETWORK LAYER
Functions & Design Issues (Common)
Packetizing, Routing (path selection), Congestion control, Internetworking (logical addressing), Fragmentation/Reassembly, Error handling (ICMP).
Routing Algorithms (Frequent)
Static vs. Dynamic: Static (manually configured, simple, no adaptation). Dynamic (adapt to topology/load changes, complex).
Distance Vector Routing (DVR - Bellman-Ford):
- Principle: Each router knows distance (cost) to neighbors. Shares its entire distance vector with neighbors periodically. Uses Bellman equation:
$$D_x(y) = \min_{v \in \text{neighbors}} \{ c(x,v) + D_v(y) \}$$
where `D_x(y)` = cost from `x` to `y`, `c(x,v)` = cost to neighbor `v`.
-
Process: Iterative, asynchronous. Each router updates its table based on received vectors.
-
Problems: Count-to-infinity (slow convergence), routing loops, bad news travels slowly.
-
RIP: Uses DVR. Metric = hop count (max 15). Updates every 30 sec. Slow convergence, limited scale.
Link State Routing (LSR - Dijkstra):
-
Principle: Each router discovers entire network topology (via flooding of link state packets). Builds a graph.
-
Algorithm: Dijkstra's Shortest Path First (SPF).
-
Start with source node
S. SetScost=0, others=∞. -
Pick lowest-cost node
Nnot in tree. AddNto tree. -
Update costs of
N's neighbors viaN. -
Repeat until all nodes in tree.
-
-
Advantages: Fast convergence (no loops), global view.
-
Disadvantages: High memory/CPU overhead for large networks. Requires reliable flooding.
Comparison:
| Feature | DVR (RIP) | LSR (OSPF) |
|---|---|---|
| Convergence | Slow (count-to-infinity) | Fast |
| Overhead | Periodic full table broadcast | Event-driven LSP flooding |
| Loop Prevention | Hard (split horizon, poison reverse help) | Inherent (SPF tree) |
| Scalability | Poor (max hop count) | Good (hierarchical areas in OSPF) |
| Knowledge | Only neighbor distances | Full network topology |
IP Addressing (Frequent)
Classful Addressing (Legacy):
| Class | Range (First Octet) | Default Mask | Networks | Hosts/Net |
|---|---|---|---|---|
| A | 1 - 126 | 255.0.0.0 (/8) | 2^7 | 2^24 |
| B | 128 - 191 | 255.255.0.0 (/16) | 2^14 | 2^16 |
| C | 192 - 223 | 255.255.255.0 (/24) | 2^21 | 2^8 |
| D | 224 - 239 | - (Multicast) | - | - |
| E | 240 - 255 | - (Experimental) | - | - |
Limitations: Wasted addresses (e.g., a company needing 500 hosts gets a Class B with 65k hosts), no flexibility, routing table explosion.
CIDR & Classless Addressing:
-
Notation:
a.b.c.d/n(prefix lengthn). e.g.,192.168.1.0/24. -
Address Block: All addresses with same first
nbits. Size = $$\displaystyle 2^{32-n} $$. -
Aggregation/Supernetting: Combining multiple contiguous prefixes into one larger prefix to reduce routing table size. e.g.,
192.168.0.0/24+192.168.1.0/24→192.168.0.0/23.
Subnetting (Frequent):
-
Concept: Divide a large network (e.g., /24) into smaller logical subnets.
-
Subnet Mask: Borrow
kbits from host part. New prefix = original +k. Mask =255.255.255.0→255.255.255.192for 2 subnets (k=1). -
Design Problem Steps (Given
Network/OriginalPrefix):-
Determine
kneeded:2^k >= N(required subnets). -
New prefix =
OriginalPrefix + k. New mask. -
Each Subnet Range:
-
Network Address:
Base + (i * BlockSize), whereBlockSize = 2^{HostBits}. -
First Host:
Network + 1. -
Last Host:
Broadcast - 1. -
Broadcast Address:
Network + BlockSize - 1.
-
-
Usable Hosts/Subnet: $$\displaystyle 2^{\text{HostBits}} - 2 $$ (subtract network & broadcast).
-
Example:
192.168.10.0/24→ 4 subnets (k=2, /26, mask=255.255.255.192).
BlockSize = $$\displaystyle 2^{6} = 64 $$.
Subnet 0: Net=
192.168.10.0, Hosts=192.168.10.1-192.168.10.62, BC=192.168.10.63.
Subnet 1: Net=
192.168.10.64, Hosts=65-126, BC=127.
Subnet 2: Net=
192.168.10.128, Hosts=129-190, BC=191.
Subnet 3: Net=
192.168.10.192, Hosts=193-254, BC=255.
VLSM (Variable Length Subnet Masking): Apply subnetting recursively. Allocate addresses efficiently (larger subnets first).
IPv4 vs. IPv6 (Frequent):
| Feature | IPv4 | IPv6 |
|---|---|---|
| Address Size | 32-bit | 128-bit |
| Notation | Dotted decimal (e.g., 192.168.1.1) | Hexadecimal (e.g., 2001:0db8:85a3::8a2e:0370:7334) |
| Header | Variable (20-60 bytes), complex | Fixed 40 bytes, simplified (no checksum, no options) |
| Fragmentation | Done by routers & source | Only by source (router don't fragment) |
| Addressing | Classful (legacy) / CIDR | Aggregation-friendly, hierarchical |
| Features | Broadcast, optional security | No broadcast (multicast/anycast), IPsec mandatory, autoconfiguration, extension headers |
| Header Fields | 12 fields | 8 fields + extension headers |
Network Layer Protocols & Devices (Frequent)
-
ICMP (Internet Control Message Protocol): Network layer protocol for error reporting & diagnostics.
-
Messages:
Destination Unreachable,Time Exceeded(TTL expired),Echo Request/Reply(ping),Redirect,Source Quench(deprecated). -
Use:
ping(ICMP Echo),traceroute(ICMP Time Exceeded).
-
-
ARP (Address Resolution Protocol): Maps IP address → MAC address on a local network.
-
Operation: Host broadcasts ARP Request: "Who has IP X? Tell Y (MAC)". Owner replies with ARP Reply (unicast).
-
ARP Cache: Stores recent mappings (timeout-based).
-
Need: IP addresses are logical; frames need physical (MAC) addresses for delivery on LAN.
-
-
RARP (Reverse ARP): Maps MAC address → IP address. Used by diskless workstations to discover their IP at boot. Replaced by BOOTP and DHCP.
Network Devices Comparison:
| Device | Layer | Function | Addressing | Intelligence |
|---|---|---|---|---|
| Hub | Physical (1) | Signal regeneration, broadcast. | None | None |
| Bridge | Data Link (2) | Connects LAN segments, filters by MAC. Learns MACs. | MAC | Low (forwarding table) |
| Switch | Data Link (2) | Multiport bridge. Frame forwarding (store-and-forward or cut-through). | MAC | Medium (MAC table, VLANs) |
| Router | Network (3) | Inter-LAN/WAN routing. Path determination (routing table). | IP | High (routing algorithms) |
| Gateway | Application (7) | Protocol conversion. e.g., Email gateway, VoIP gateway. | Application data | Very High |
Remote Bridging: Connecting two LANs via a bridge over a WAN link (e.g., leased line). Challenges: High latency (breaks real-time protocols), loop prevention (spanning tree over WAN is slow), cost.
Congestion Control (Frequent)
-
Congestion vs. Flow Control: Flow control is point-to-point (sender→receiver). Congestion is global (network-wide resource depletion).
-
Causes: High load, slow processors, low bandwidth, bad routing (packet loops).
-
Principles:
-
Open-loop (Prevention): Policies to prevent congestion (good routing, admission control).
-
Closed-loop (Feedback & Reaction): Detect congestion, feed back to senders to reduce rate.
-
-
Techniques:
-
Load Shedding: Discard packets when buffer full. Policies: Random, Priority-based (discard low-priority first).
-
Traffic-aware Routing: Avoid congested paths.
-
Admission Control: For virtual circuits (e.g., ATM, MPLS). Deny new connections if network congested.
-
TCP Congestion Control (Closed-loop):
-
Slow Start: Start with
cwnd=1(congestion window). Doublecwndevery RTT until thresholdssthresh. -
Congestion Avoidance: After
ssthresh, increasecwndby 1 per RTT (linear). -
Fast Retransmit: After 3 duplicate ACKs, retransmit missing packet (no wait for timeout).
-
Fast Recovery: Set
ssthresh = cwnd/2,cwnd = ssthresh + 3, then congestion avoidance.
-
-
QoS (Quality of Service) (Common)
Techniques to guarantee performance (delay, jitter, bandwidth, loss).
-
Integrated Services (IntServ): Per-flow resource reservation (RSVP). Fine-grained but not scalable.
-
Differentiated Services (DiffServ): Per-class service. Mark packets with DSCP (6 bits in IP TOS field) for PHB (Per-Hop Behavior). Scalable.
-
Traffic Shaping: Regulate traffic rate (Leaky Bucket, Token Bucket).
-
Resource Reservation: Reserve bandwidth/buffers for critical flows.
5. TRANSPORT LAYER
Functions & Services (Common)
Process-to-process delivery (ports), Segmentation/Reassembly, Connection control (estab/term), Flow control, Error control (retransmission), Congestion control.
Transport Layer Protocols (Frequent)
UDP (User Datagram Protocol):
-
Connectionless, unreliable. No flow/congestion control, no retransmission.
-
Header (8 bytes): Source Port (16), Dest Port (16), Length (16), Checksum (16).
-
Applications: DNS, streaming media, VoIP, TFTP, SNMP. Where speed > reliability.
TCP (Transmission Control Protocol):
-
Connection-oriented, reliable. Full duplex, byte-stream.
-
Header Format (20-60 bytes):
-
Source Port (16), Dest Port (16)
-
Sequence Number (32): Byte number of first byte in segment.
-
Acknowledgment Number (32): Next expected byte (cumulative ACK).
-
Data Offset (4): Header length in 32-bit words.
-
Reserved (3)
-
Flags (9):
URG,ACK,PSH,RST,SYN,FIN. -
Window Size (16): Receiver's advertised window (bytes).
-
Checksum (16)
-
Urgent Pointer (16) (if URG set)
-
Options (variable)
-
-
Connection Management:
-
Three-Way Handshake (Establishment):
-
Client → Server:
SYN=1, seq=x -
Server → Client:
SYN=1, ACK=1, seq=y, ack=x+1 -
Client → Server:
ACK=1, seq=x+1, ack=y+1
Why 3-way? Prevents old duplicate connection initiations (security). Both sides agree on initial sequence numbers.
-
-
Four-Way Handshake (Termination / Graceful Release):
-
Client → Server:
FIN=1, seq=u -
Server → Client:
ACK=1, ack=u+1(may still send data) -
Server → Client:
FIN=1, seq=v -
Client → Server:
ACK=1, ack=v+1
Why 4-way? Each side closes independently (full duplex). Graceful release ensures all data is delivered before connection closed (no data loss).
TIME_WAITstate (2MSL) handles delayed packets. -
-
Comparison: TCP vs. UDP (Frequent)
| Feature | TCP | UDP |
|---|---|---|
| Connection | Connection-oriented (handshake) | Connectionless |
| Reliability | Guaranteed (ACKs, retransmission) | Not guaranteed |
| Flow Control | Yes (sliding window) | No |
| Congestion Control | Yes (slow start, etc.) | No |
| Ordering | In-order delivery | No ordering |
| Header Size | 20-60 bytes | 8 bytes |
| Speed | Slower (overhead) | Faster (minimal overhead) |
| Applications | Web (HTTP), Email (SMTP), FTP | DNS, VoIP, streaming, DHCP |
6. APPLICATION LAYER
Domain Name System (DNS) (Frequent)
-
Role: Hierarchical, distributed database mapping domain names (e.g.,
www.rgpvonline.com) to IP addresses. -
Components:
-
Resolvers: Client-side library/software (e.g., in OS).
-
Name Servers: Authoritative for a zone. Types:
-
Root Servers: Know TLD servers.
-
TLD Servers: (
.com,.org,.in). Know authoritative for domains in TLD. -
Authoritative Servers: Know IPs for specific domains.
-
-
Zones: Administrative domain (e.g.,
rgpvonline.com).
-
-
Resolution Process:
-
Resolver queries local DNS server (usually ISP's).
-
If not cached, local server may perform recursive query (asks chain on behalf of client) or iterative query (client/root follows referrals).
-
Typical iterative: Root → TLD → Authoritative.
-
Caching: At every level (resolver, local server) with TTL.
-
-
Resource Records (RR):
A(IPv4),AAAA(IPv6),CNAME(alias),MX(mail server),NS(name server).
Electronic Mail (Frequent)
-
Architecture:
-
MUA (Mail User Agent): User interface (Outlook, Thunderbird).
-
MTA (Mail Transfer Agent): Server-to-server transfer (Sendmail, Postfix). Uses SMTP.
-
MDA (Mail Delivery Agent): Local delivery to mailbox (procmail).
-
-
SMTP (Simple Mail Transfer Protocol):
-
Push protocol. Client (MUA) → Server (MTA) on port 25.
-
Commands:
HELO,MAIL FROM:,RCPT TO:,DATA(then message, ends with.),QUIT. -
Message Format: Headers (
From:,To:,Subject:,Date:) + blank line + Body. -
ESMTP (Extended SMTP): Adds
STARTTLS(encryption),AUTH(authentication),SIZE,8BITMIMEfor binary/MIME.
-
-
Email Access (Pull): POP3 (download & delete), IMAP (server-side folders, sync).
World Wide Web & HTTP (Frequent)
-
WWW Architecture: Client (Browser), Server (Apache, Nginx), Proxy/Cache.
-
HTTP (Hypertext Transfer Protocol):
-
Application layer protocol. Connectionless (each request/response uses new TCP connection in HTTP/1.0), stateless (server doesn't remember clients → use cookies).
-
HTTP/1.1: Persistent connections (default, multiple requests/responses on same TCP). Pipelining (send multiple requests without waiting).
-
Request Methods:
GET(fetch),POST(submit data),HEAD(headers only),PUT,DELETE. -
Response Status Codes:
-
1xx(Informational),2xx(Success:200 OK),3xx(Redirection:301 Moved Permanently), -
4xx(Client Error:404 Not Found),5xx(Server Error:500 Internal Server Error).
-
-
File Transfer (Common)
-
FTP (File Transfer Protocol):
-
Architecture: Separate control & data connections.
-
Control Connection: TCP port 21. Commands (USER, PASS, LIST, RETR, STOR) and replies.
-
Data Connection: TCP port 20 (active mode: server connects to client's port). Passive Mode (PASV): Client connects to server's high port (firewall-friendly).
-
-
Operation: Client initiates control connection, sends commands. Data connection opened/closed per transfer.
-
Network Management (Common)
-
SNMP (Simple Network Management Protocol):
-
Components:
-
Manager: Central console (e.g.,
snmpwalk). -
Agent: Software on managed device (router, switch).
-
MIB (Management Information Base): Database of manageable objects (variables) on agent.
-
-
Operations (PDU Types):
GET,GETNEXT,SET,GETBULK,TRAP(asynchronous alert from agent to manager). -
Versions: SNMPv1 (no security), SNMPv2c (community string), SNMPv3 (user-based security, encryption).
-
7. SWITCHING & INTERCONNECTING DEVICES
Switching Techniques (Frequent)
| Technique | Principle | Delay | Dedicated Path? | Example |
|---|---|---|---|---|
| Circuit Switching | Dedicated physical path established before data. Setup/teardown phases. | Low (after setup) | Yes (exclusive) | Telephone network (PSTN). |
| Message Switching | Store-and-forward of entire message. Buffering at each node. | High (store+forward) | No (shared) | Early telegraph networks, email store-and-forward. |
| Packet Switching | Data divided into packets. Each packet forwarded independently. |
* **Datagram:** No connection. Each packet routed independently (best-effort). **Network layer** (IP).
* **Virtual Circuit:** Connection established. All packets follow same path (VC#). **Data link/network layer** (Frame Relay, ATM). | Moderate (per-packet) | No (shared) | **Internet (IP - Datagram).** |
Network Devices (Frequent)
| Device | Layer | Function | Addressing | Forwarding Basis | Intelligence |
|---|---|---|---|---|---|
| Hub | Physical (1) | Repeater, broadcasts to all ports. | None | None (broadcast) | None |
| Bridge | Data Link (2) | Connects LAN segments, filters traffic. Learns MACs. | MAC | MAC address table | Low (learning, forwarding) |
| Switch | Data Link (2) | Multiport bridge. Store-and-forward (error check) or cut-through (fast, no error check). | MAC | MAC address table | Medium (VLANs, STP) |
| Router | Network (3) | Connects networks (LANs, WANs). Path determination (routing). | IP | Routing table (longest prefix match) | High (routing protocols) |
| Gateway | Application (7) | Protocol conversion. e.g., Email gateway (SMTP↔X.400), VoIP gateway. | Application data | Application-specific | Very High |
Key: Bridge/Switch = MAC-based, same network. Router = IP-based, different networks. Hub = dumb repeater.
📚 EXAM TIPS & COMMON PITFALLS:
[!TIP] CRC Calculation: Always show polynomial division steps. Remember: Append
rzeros, divide byG(x), remainder is CRC. Final codeword =Data || CRC. If remainder ≠ 0 at receiver → error.
[!TIP] Subnetting: Never forget to subtract 2 for network & broadcast addresses when calculating usable hosts. For
Nsubnets, borrowkwhere2^k >= N. New prefix = old +k.
[!TIP] Routing Algorithms: In DVR (Bellman-Ford), update happens when a neighbor's vector changes. Show the iteration table. In LSR (Dijkstra), draw the graph, mark tentative/permanent nodes step-by-step.
[!TIP] TCP Header from Hex Dump: Convert hex to binary/decimal. Remember: Source/Dest Port (16 bits each), Seq/ACK (32 bits), Flags (9 bits: URG, ACK, PSH, RST, SYN, FIN), Window (16 bits). Data Offset = header length in 32-bit words.
[!TIP] Stop-and-Wait Efficiency: $$\displaystyle U = \frac{1}{1+2a} $$. For efficiency ≥ 50%, $a \leq 0.5$ → Propagation Delay ≤ Frame Transmission Time.
[!TIP] CSMA/CD Minimum Frame Size: Must be ≥ $2 \times \text{Propagation Delay} \times \text{Bandwidth}$ (in bits). Ensures collision detected before transmission ends.
[!TIP] ALOHA Throughput: Pure: $$\displaystyle S = G e^{-2G} $$ (max 18.4% at G=0.5). Slotted: $$\displaystyle S = G e^{-G} $$ (max 36.8% at G=1).
G= offered load (attempts/frame time).
[!TIP] OSI vs TCP/IP: OSI has 7 layers, strict separation. TCP/IP has 4/5 layers, combines OSI's 5-7 into Application, 1-2 into Link. TCP/IP is implementation-focused, OSI is theoretical.
[!TIP] IPv4 vs IPv6: IPv6 has 128-bit addresses, no header checksum, no fragmentation by routers, mandatory IPsec, extension headers. IPv4 has broadcast, fragmentation by routers, optional security.
[!TIP] DNS Resolution: Usually iterative from local server. Root knows TLD servers, TLD knows authoritative for domain. Caching is critical for performance.
nslookup/digare tools.
[!TIP] SMTP vs HTTP: SMTP is push (client pushes to server on port 25). HTTP is pull (client pulls from server on port 80/443). SMTP uses 7-bit ASCII (MIME for binary). HTTP is binary-friendly.
[!TIP] Three-way vs Four-way Handshake: Three-way for connection establishment (both sides agree on ISN). Four-way for termination because TCP is full-duplex; each direction closed independently. TIME_WAIT (2MSL) ensures last ACK received and old duplicates expire.
[!TIP] Switching Device Layer: Hub=1, Bridge/Switch=2, Router=3, Gateway=7. This is a frequent comparison question.