CT 702 · BCT · Year IV Part I · 80 marks · 3 hours
Computer Network
A working reader for Computer Network, built from the syllabus, the Insights on Computer Networks book and every board paper on record: 27 sittings, 2066 Bhadra to 2082 Bhadra. Every topic is taught in full with drawn diagrams and an example to remember it by, every question the papers asked is answered in the words to write, and every calculation is worked with its numbers computed rather than typed.
Where the marks areWhat the papers actually set, chapter by chapter
Each bar is a chapter's average share of an 80 mark paper over all 27 sittings, measured from the marks printed on every question (the syllabus gives hours, not marks). Chapters 4 and 8, Network layer and Network security, carry the most: about 17 and 11 marks a paper. Point at a chapter's name to see how many of the 269 questions touched it.
What to study first
These topics were asked in 9 or more of the 27 sittings. Learn them before anything else; each link opens its card.
- Subnetting and VLSM: dividing a block with the least waste TOP 24/27
- From IPv4 to IPv6: coexistence, dual stack, tunneling and translation TOP 18/27
- RSA: the public key algorithm, step by step TOP 16/27
- Switching: circuit, message and packet TOP 13/27
- Routing: what it is, what a good algorithm needs, static against dynamic TOP 13/27
- Why IPv6: the problems of IPv4 and what IPv6 fixes TOP 13/27
- Firewalls: what they are, how they protect, their types, and router ACLs TOP 13/27
- Link state routing: properties, five steps, and distance vector compared TOP 11/27
- DNS: the Internet's distributed directory of names TOP 11/27
- Electronic mail: user agents, mail servers, SMTP, POP3, IMAP and MIME TOP 11/27
- Network security and the properties of secure communication TOP 11/27
- Client/server and peer to peer: the two networking models TOP 10/27
- Framing: character count, byte stuffing and bit stuffing TOP 10/27
- Distance vector routing, count to infinity, and loop prevention TOP 10/27
- Layered architecture: why network software is a hierarchy of layers TOP 9/27
- OSI and TCP/IP compared: similarities and differences TOP 9/27
- CSMA/CD: carrier sense with collision detection TOP 9/27
- TCP: the reliable byte stream, its segment header, and how reliability is provided TOP 9/27
- The token bucket: saving up permission to burst TOP 9/27
How to use this reader
- Chapters 1 to 8 are the study content: each topic explained in plain language, with drawn diagrams, an example to remember it by, and at the foot of each card every question the papers set on it, word for word, with the part the card answers lit. The copy button on a card copies it to paste into Claude and ask about.
- Theory answers give the exam answer to every question that asks what a thing is, why it matters or how two things compare, at the length its marks deserve.
- Practical answers give the ones that ask how a thing works, step by step: CSMA/CD, the three-way handshake, sliding window, DNS resolution and the like.
- Numericals work every calculation the papers set (subnetting, CRC, Hamming code, delays, efficiency, routing tables, RSA, the buckets), grouped by method, with the method once at the top of each group.
- Summary gives every topic as the skeleton of its answer, for the last read before the exam, and ends with the Recall sheet: every topic again as bare keywords.
- Compact chapters keep every detail of a chapter with the teaching prose taken out; one button copies a whole chapter to give Claude as context.
- Question bank reproduces all 269 questions word for word, by paper or by chapter, each linked to its answer and its card.
- Mind map draws each chapter as its lists; Close all turns it into a test. Flashcards drill the definitions and every question.
Writing the paper
- About two minutes a mark: 180 minutes for 80 marks, so an 8 mark question gets about 16 minutes.
- Most questions come in parts (2+6, 4+4, 2+3+3). Answer the parts in the order asked and give each its share of the time: a 2 mark definition is two or three lines.
- Draw what has a drawing: the layer models, the header and frame formats, the CSMA/CD flowchart, the handshake, the switching and tunnelling pictures each earn marks.
- Numericals show their working: the given values, the formula or the method, every step, then the answer in bold. A subnet plan is a table; a CRC is the long division.
- The last question is short notes, any two of four, about 4 marks each: a definition, three or four points and a small diagram.
The 27 sittings, question by question
Each paper opens to its questions, the chapter each belongs to and the card that teaches it. The board repeats itself: OSI and TCP/IP, CRC, subnetting, CSMA/CD, routing, TCP and UDP, DNS and IPv6 come back paper after paper.
2082 Bhadraregular paper, 10 questions: Attempt All questions.
2082 Baishakhback paper, 10 questions: Attempt All questions.
2081 Bhadraregular paper, 10 questions: Attempt All questions.
2081 Baishakhback paper, 10 questions: Attempt All questions.
2080 Bhadraregular paper, 10 questions: Attempt All questions.
2080 Baishakhback paper, 10 questions: Attempt All questions.
2079 Bhadraregular paper, 10 questions: Attempt All questions.
2078 Bhadraregular paper, 10 questions: Attempt All questions.
2076 Chaitraregular paper, 10 questions: Attempt All questions.
2076 Ashwinback paper, 10 questions: Attempt All questions.
2075 Chaitraregular / back paper, 10 questions: Attempt All questions.
2075 Ashwinback paper, 10 questions: Attempt All questions.
2074 Chaitraregular paper, 10 questions: Attempt All questions.
2074 Ashwinback paper, 10 questions: Attempt All questions.
2073 Shrawannew back (2066 & later batch) paper, 10 questions: Attempt All questions.
2072 Chaitraregular paper, 10 questions: Attempt All questions.
2072 Kartiknew back (2066 & later batch) paper, 10 questions: Attempt All questions.
2071 Chaitraregular paper, 10 questions: Attempt All questions.
2071 Shrawannew back (2066 & later batch) paper, 10 questions: Attempt All questions.
2070 Chaitraregular paper, 10 questions: Attempt All questions.
2070 Ashadold back (2065 & earlier batch) paper, 10 questions: Attempt All questions.
2069 Chaitraregular paper, 10 questions: Attempt All questions.
2068 Chaitraregular / back paper, 9 questions: Attempt All questions.
2068 Baishakhregular / back paper, 10 questions: Attempt All questions.
2067 Ashadregular / back paper, 10 questions: Attempt All questions.
2066 Poushback paper, 10 questions: Attempt All questions.
2066 Bhadraregular / back paper, 10 questions: Attempt All questions.
The whole subject on one page
Eight chapters and every topic card in them. The number beside a topic is how many of the 27 sittings asked it.
How to read the chips
| Chip | Means |
|---|---|
| TOP n/27 | Asked in 9 or more of the 27 sittings. |
| HOT n/27 | Asked in 5 to 8. |
| PIN n/27 | Asked in 1 to 4. |
| No chip | A syllabus topic no paper has asked yet: taught, summarised and recalled like the rest. |
| 2+6 | The marks the question has carried. |
Under each chip is the list of sittings that asked it: 81 Bh is the 2081 Bhadra regular paper (bold, a regular sitting); 81 Ba is the 2081 Baishakh back paper.
Chapter 1 · 5 hours · about 10 marks a paper · in 26 of the 27 sittings
Introduction to computer network
What a computer network is and what it is for, how the work is shared out (client/server, peer to peer, active networks), and how network software is built as a stack of layers, described by the OSI and TCP/IP models; then the classic example networks: the Internet, X.25, Frame Relay, ATM, Ethernet, VoIP, NGN, MPLS and xDSL. Question 1 of the paper came from this chapter in 25 of the 27 sittings on record, so it is the first answer written in the hall.
- Networks and their uses: the definition, the uses at work, at home and on the move, the sizes from PAN to WAN, and the topologies from bus to mesh.
- Networking models: client/server against peer to peer, and the active network against the legacy, passive one.
- Protocols and layers: what a protocol and a standard are, why network software is a hierarchy of layers, the design issues every layer faces, and the services a layer offers.
- The two reference models: the seven OSI layers, the four TCP/IP layers, encapsulation with headers and trailers, and the comparison the board sets most often.
- Example networks: the Internet, X.25, Frame Relay, ATM, Ethernet, VoIP, NGN, MPLS and xDSL, with X.25 against Frame Relay and Frame Relay against ATM.
- Every later chapter is one layer: the physical layer in chapter 2 (physical layer), the data link layer in chapter 3 (data link layer), the network layer in chapter 4 (network layer), the transport layer in chapter 5 (transport service) and the application layer in chapter 6 (HTTP).
- The example networks lean on chapter 2: X.25, Frame Relay and ATM are virtual circuit networks (datagram and virtual circuit), and xDSL is set beside ISDN (ISDN).
- Ethernet is introduced here and taught in full in chapter 3 (Ethernet); the protocols each layer uses (IP, TCP, UDP, DNS) are taught in their own chapters.
- 1.1 Computer networks: uses, sizes and topologies
- 1.2 Networking models: client/server, peer to peer, active networks
- 1.3 Protocols and standards, layered architecture, services
- 1.4 The OSI and TCP/IP models, and data encapsulation
- 1.5 OSI and TCP/IP compared
- 1.6 Example networks: the Internet, X.25, Frame Relay, ATM, Ethernet, VoIP, NGN, MPLS, xDSL
- 1.7 Last minute recall, chapter 1
- Client/server against peer to peer is the most asked topic (10 sittings): define, draw, compare in a table, add advantages and disadvantages.
- Layered architecture (9) and OSI against TCP/IP (9) come next, then the OSI layers with their functions (8) and X.25 (7); protocol and Frame Relay have 5 sittings each.
- Draw the two stacks side by side, the protocol hierarchy with its headers, the client/server and P2P sketch, the X.25 packet, the Frame Relay frame and the ATM cell.
1.1Computer networks: uses, sizes and topologies
What a computer network is, and what it is used for PIN 4/27
81 Bh · 72 Ch · 71 Shr · 66 Po2+65+3
Autonomous is the word to keep. Each computer can work on its own; the network only lets them talk. A mainframe with dumb terminals is not a network in this sense, because a terminal can do nothing alone. Two computers are interconnected when they can exchange information, whatever the medium between them.
Every network has four parts:
- Nodes: end systems (hosts) that run the applications, such as laptops, phones and servers, and the intermediate devices that move data between them: switches, routers and access points (devices).
- Links: the transmission media: twisted pair, coaxial cable, optical fibre, radio (media).
- Protocols: the rules both ends follow to understand each other (protocols).
- Services: what the users finally get: the web, mail, file sharing, voice and video calls.
Three criteria judge a network: performance (throughput and delay, see chapter 2), reliability (how often it fails and how quickly it recovers) and security (protection of the data against unauthorised access and damage, chapter 8).
The uses of computer networks, under the book's three headings, with the effect on society added:
| Who | Use | What the network makes possible |
|---|---|---|
| Business | Resource sharing | many PCs share one printer, scanner, database or internet line, wherever they are |
| Business | High reliability | files replicated on two or more machines: if one fails, another copy is used |
| Business | Saving money | cheap PCs working as clients of a few servers replace one costly mainframe |
| Business | Scalability | when the load grows, another server or PC is added instead of replacing the whole system |
| Business | Communication and e-commerce | email, video meetings, and orders placed electronically with suppliers and customers |
| Home | Access to remote information | the web, news, online banking, exam results |
| Home | Person to person communication | chat, voice and video calls, cheaper and faster than ordinary phone calls |
| Home | Interactive entertainment | video on demand, multiplayer games, social networking |
| Home | E-commerce and online education | paying bills, sending money, shopping; online classes, notes and assignments |
| Mobile users | Anywhere access | phones and laptops on Wi-Fi or 4G send mail, browse, use maps, reach remote files and log on to remote machines |
| Society | Public services, and new problems | e-government and online public services; also loss of privacy, misinformation, fraud such as phishing, and copyright disputes |
Five instances of networks in a student's day (the 2072 Chaitra paper asks for exactly five):
- Paying by phone: scanning a fonepay QR code at the canteen or loading an eSewa or Khalti wallet: the app is a client talking to the bank's server over mobile data.
- Calling family: a WhatsApp or Viber video call to a relative working abroad travels as IP packets (VoIP), for the price of the data instead of an international call.
- Studying: online classes, notes shared in the class group, and exam results checked on the exam board's website.
- Entertainment: a YouTube video streamed on demand, or an online multiplayer game whose moves must arrive within milliseconds.
- Daily services: booking a Pathao or inDrive ride (the phone's GPS position sent over mobile data), or paying the NEA electricity bill online instead of queuing at the office.
To remember the idea, picture a hostel kitchen: every student can cook alone (autonomous), but sharing one gas cylinder and one fridge (resources) works only with agreed rules about turns and shelves (protocols). The hostel Wi-Fi is the same thing in network form: one fibre line from the ISP shared by every room.
- Define Network. List a function of each layer of OSI reference model and compare it with TCPI/IP model. 2081 Bhadra Q1 · 2+6
- Explain five instances of how networks are a part of your life today. Through we have MAC address, why do we use IP address to represent the host in networks? Explain your answer. 2072 Chaitra Q2 · 5+3
- What is computer network? Distinguish between OSI and TCP/IP reference model. 2071 Shrawan Q1 · 2+6
- Define network and protocol for network. Explain peer-to-peer network process with example. 2066 Poush Q1 · 2+6
Networks by size and geography: PAN, LAN, MAN and WAN PIN 1/27
70 Asa3+5
Distance decides almost everything else. Over a few metres a cheap radio is enough. Inside one building an organisation can lay its own cable, so a LAN is privately owned, fast and nearly error free. Across a country nobody lays private cable: the links are leased from telecom carriers, cost more per bit and add delay. So the size of a network fixes its owner, its speed, its delay and its error rate.
| Type | Span | Owner | Speed and delay | Technology | Example |
|---|---|---|---|---|---|
| PAN | about 1 to 10 m | one person | low data rate, tiny delay | Bluetooth, USB, NFC | earbuds and a smartwatch paired with a phone |
| LAN | a room, building or campus, up to a few km | one organisation (private) | high: 100 Mbps to 10 Gbps and more; very low delay and error rate | Ethernet (IEEE 802.3), Wi-Fi (IEEE 802.11) | a college computer lab, a hostel Wi-Fi |
| MAN | a city, roughly 10 to 50 km | an ISP, a cable operator or a city body | high, usually over fibre | fibre rings, Metro Ethernet, cable TV networks, WiMAX (IEEE 802.16) | an ISP's fibre ring joining its exchanges across the Kathmandu valley |
| WAN | a country or a continent: hundreds to thousands of km | telecom carriers; users lease capacity | lower speed for the money, higher delay | leased lines, X.25, Frame Relay, ATM, MPLS, satellite | a bank linking its head office with branches all over Nepal |
| Internetwork | worldwide | many owners | varies | routers joining unlike networks, TCP/IP | the Internet |
The WAN's structure. A WAN joins hosts through a communication subnet: switching elements (routers) joined by transmission lines. Packets travel store and forward: each router receives a whole packet, stores it, then sends it on along the next line (switching). The hosts belong to the users; the subnet usually belongs to a carrier or an ISP.
Two other ways to classify networks:
- By transmission technology: broadcast networks share one channel that every machine hears (classic Ethernet, Wi-Fi), so an address in each frame says whom it is for; point-to-point networks join pairs of machines, so a packet may cross several intermediate nodes on its way (most WANs).
- By architecture and shape: client/server or peer to peer (networking models); bus, star, ring or mesh (topologies).
To remember it, follow one video call outwards: earbuds paired with the phone (PAN), the phone on the hostel Wi-Fi (LAN), the hostel on the ISP's fibre ring across the valley (MAN), the ISP's links across the border to the rest of the world (WAN), and all of them together (the Internet).
- How do you define network topology? Discuss the types of network topologies based on its size and geographical distributions. 2070 Ashad Q2 · 3+5
Network topologies: bus, star, ring, mesh, tree and hybrid PIN 1/27
70 Asa3+5
Physical and logical can differ. A classic Ethernet hub is wired as a star but behaves as a bus, since every frame it receives is repeated out of every port; a Token Ring is wired as a star into a central access unit, yet the token travels round it as a ring.
| Topology | How it is built | Merits | Demerits | Example |
|---|---|---|---|---|
| Bus | one backbone cable; nodes tapped on with drop lines; a terminator at each end stops reflections | least cable, cheap, easy to add a node | a break in the backbone stops everything; collisions; faults hard to locate; limited length and number of nodes | early coaxial Ethernet (10BASE5, 10BASE2) |
| Star | every node has its own link to a central hub or switch | a cut link loses one node only; easy to add, remove and troubleshoot | the central device is a single point of failure; more cable than a bus | today's switched Ethernet LAN; a home Wi-Fi router |
| Ring | each node joined to the next, the last back to the first; data goes one way round and each node repeats it | no collisions (a token gives turns); equal access; predictable delay | one break or one dead node stops the ring (a dual ring, as in FDDI, survives one); adding a node breaks the ring | IEEE 802.5 Token Ring, FDDI |
| Mesh | every node joined to every other by a dedicated link | robust: no single point of failure; a link carries no one else's traffic; private; faults easy to isolate | cables and ports grow with the square of the number of nodes: costly and bulky | links between core routers (usually a partial mesh) |
| Tree | stars joined in a hierarchy below a root: a star of stars | grows easily; a branch can be isolated | if the root or a backbone link fails, the branches below are cut off | a campus: core switch, building switches, floor switches |
| Hybrid | two or more topologies joined | each part uses the shape that suits it | complex to design and manage | buildings on a fibre ring, each building a star |
The mesh formula. A full mesh of nodes needs one link for every pair, and every node needs ports:
A full mesh needs cables and 5 ports in every PC. A star needs 6 cables and one 8-port switch. A bus needs one cable with six taps. That is why LANs are stars, and only a few core routers are joined in a (partial) mesh.
To remember them, think of how a village gets its water: a bus is one pipe along the road with every house tapped onto it (cut the pipe and the whole lane is dry); a star is a tank with a separate pipe to each house; a ring is a loop main round the village; a mesh is a pipe from every house to every other house: nothing ever runs dry, and nobody can afford it.
- How do you define network topology? Discuss the types of network topologies based on its size and geographical distributions. 2070 Ashad Q2 · 3+5
1.2Networking models
Client/server and peer to peer: the two networking models TOP 10/27
82 Ba · 81 Ba · 80 Bh · 78 Bh · 76 Ash · 75 Ch · 74 Ch · 70 Ch · 66 Po · 66 Bh3+54+42+6
Client/server architecture. Each computer or process on the network is either a client or a server. A server is a powerful, always-on machine (or process) that holds the data and the programs: a web, mail, file, database or print server. Clients are the users' machines that ask for its services. Every exchange involves two processes, one on the client machine and one on the server machine.
How the client/server model works: request and reply.
- The server waits: the server process starts first and listens on a known address and port (a web server on port 80 or 443).
- The client requests: the client process sends a request message across the network, and waits.
- The server processes: it receives the request and does the work: reads a file, queries a database, checks a password.
- The server replies: it sends the reply message back.
- The client uses the reply: the waiting client shows the result; the server goes back to serving others.
Opening a web page works exactly so: the browser on a laptop is the client, the remote web server is the server.
Features of the client/server architecture:
- Asymmetric roles: clients always start the conversation and servers only respond; one server serves many clients at once (many to one).
- Centralised resources and data: files, databases and applications live on the server, so everyone works on one up-to-date copy.
- Centralised administration and security: user accounts, access rights, backups and updates are managed in one place, by an administrator.
- Dedicated, powerful server: server hardware and a network operating system (Windows Server, Linux), switched on all the time.
- Scalability: clients can be added freely; capacity grows by upgrading the server or adding servers that share the load.
- Location transparency: the client needs only the server's name or address, not where or how the data is stored.
- Tiers: two-tier (client and database server) or three-tier (client, application server, database server), as in online banking.
The peer to peer model. A P2P network is created when two or more PCs or devices connect and share their resources without a separate server computer. Each peer has equivalent capabilities and responsibilities: it stores data on its own disk and can share it with every other peer, so it is a client and a server at the same time.
The P2P process, as a file sharing system runs it:
- Join: a new peer contacts a few known peers, a tracker or a bootstrap node; in a small workgroup it simply announces itself on the LAN.
- Search: it asks for a resource by flooding a query to its neighbours, by asking an index (hybrid P2P), or by looking it up in a distributed hash table (chapter 6 covers the P2P applications).
- Connect directly: it opens connections straight to the peers that hold the resource.
- Exchange: it downloads pieces from many peers at once, and uploads the pieces it already has to others.
- Leave: when it goes offline its resources leave with it; the rest carry on.
Kinds of P2P: pure (no central element at all, as in Gnutella), hybrid (a central index or tracker only finds the peers and the transfer is peer to peer, as in Napster and BitTorrent with a tracker), and the simple workgroup of a small office or home.
Examples: BitTorrent, where a large file is cut into pieces and every downloader also uploads; a Windows workgroup of four PCs sharing folders and one printer; phone to phone sharing apps such as SHAREit and Nearby Share, which send a file over a direct Wi-Fi link; and blockchains such as Bitcoin, where every node keeps its own copy of the ledger.
The two models compared (the board's favourite question):
| Basis | Client/server | Peer to peer |
|---|---|---|
| Roles | fixed: servers serve, clients request | every peer is both client and server |
| Central server | one or more dedicated servers | none (at most an index or a tracker) |
| Data | stored centrally on the server | spread over the peers' own disks |
| Administration and security | central: one administrator, strong control | each user runs a machine: weak, uneven control |
| Backup | central and simple | machine by machine, often skipped |
| Cost | high: server hardware, server OS, administrator | low: ordinary PCs, no server |
| Scalability | limited by the server: more clients slow it unless it is upgraded | self-scaling: each new peer adds capacity as well as demand |
| Reliability | the server is a single point of failure | no single point of failure, but a peer that leaves takes its files with it |
| Performance | fast and predictable while the server copes; a bottleneck under load | depends on the peers; a popular file gets faster as more peers hold it |
| Suited to | large networks: banks, the web, mail, online services | small networks (about ten PCs), file sharing, spreading large files |
| Example | browser and web server; an ATM and the bank's server | BitTorrent; a home workgroup |
| Model | Advantages | Disadvantages |
|---|---|---|
| Client/server | central control of data, users and security; easy backup and recovery; one up-to-date copy of the data; grows by upgrading or adding servers; clients can be cheap | costly server, server software and administrator; the server is a single point of failure, and a bottleneck when overloaded; traffic piles up at the server |
| Peer to peer | cheap: no server and no administrator; easy to set up; no single point of failure; capacity grows as peers join | weak security and no central control; no central backup; data scattered and duplicated; a peer that is off takes its files with it; slow when the shared PCs are busy |
To remember the difference: client/server is a restaurant: the customers (clients) order, one kitchen (the server) cooks for everyone, and if the kitchen closes nobody eats. Peer to peer is a class picnic where every friend brings one dish: everyone brings and everyone eats, more friends mean more food, but nobody is in charge if a dish goes bad.
- Explain client/server and P2P network model with their advantages and disadvantages. Discuss the layer of TCP/IP model with suitable diagram. 2082 Baishakh Q1 · 4+4
- What is a protocol? List out the common protocols used at each layer of TCP/IP model. Differentiate between client-server is P2P network. 2081 Baishakh Q1 · 1+3+4
- Differentiate between Client Server and Peer to Peer architecture. Discuss the functions of each layer of Open System Interconnection (OSI) model. 2080 Bhadra Q1 · 3+5
- How does the client-server model work? Differentiate it with peer-to-peer network with advantages and disadvantages. 2078 Bhadra Q1 · 3+5
- What are the features of Client/Server Architecture? What are headers and trailers and how do they get added and removed? 2076 Ashwin Q1 · 4+4
- Draw the architecture for Client/Server network model. Explain in details about P2P network model with supportive examples. 2075 Chaitra Q1 · 2+6
- Distinguish between Client-Server network and Peer-Peer network. Explain Open System Interconnection (OSI) model. 2074 Chaitra Q1 · 3+5
- What are the features of Client/Server Architecture? What are headers and trailers and how do they get added and removed? Explain. 2070 Chaitra Q1 · 4+4
- Define network and protocol for network. Explain peer-to-peer network process with example. 2066 Poush Q1 · 2+6
- What is client/server networking? Explain Active Networking model framework comparing with traditional legacy network. 2066 Bhadra Q1b · 3+5
Active networking, compared with the traditional legacy network PIN 1/27
66 Bh3+5
The legacy network is passive. A traditional router only stores and forwards: it reads the header, looks up the route and sends the packet on, never touching the payload. Its functions are fixed by the vendor, so a new network service (a new multicast or quality of service scheme) needs years of standardisation and then a firmware upgrade of every router. Active networking, proposed by Tennenhouse and Wetherall at MIT in the mid 1990s and funded by DARPA, attacks exactly that slowness: it puts the new service into the network as a program.
Two ways to get the code into the node:
- Discrete approach (programmable switches): programs are loaded into the nodes beforehand, out of band, by an operator or an authorised user; arriving packets carry only a header that says which program should process them.
- Integrated approach (capsules): every packet, called a capsule, carries a small program as well as data; each node it reaches executes that code, which decides what happens to the capsule. The MIT ANTS toolkit worked this way.
The framework of an active node (the DARPA active network architecture) has three layers of software on the node's hardware:
- NodeOS: the node operating system. It owns the node's resources (the links, called channels, processor time, memory and storage), shares them among the execution environments, and enforces security so that no program takes more than its share.
- Execution environments (EEs): each is like a virtual machine or interpreter (a Java virtual machine, for example) that runs active code. One node may host several, and a management EE lets the operator control the node.
- Active applications (AAs): the user programs that run inside an EE and give a flow its custom service.
An arriving packet is matched to the right EE by a small header (the Active Network Encapsulation Protocol, ANEP), is processed there, and leaves possibly changed: forwarded, merged, shrunk, copied or dropped.
| Point | Legacy (passive) network | Active network |
|---|---|---|
| What a node does | stores and forwards packets by their header | forwards and also computes on the packets' contents |
| Processing | the same for every packet, fixed | customised per user, per flow or per packet |
| Who programs the node | the vendor, in firmware | users and applications, by injecting code |
| A new service | years: standardise, then upgrade every router | days: load the program, or send it in capsules |
| Packet | header and data | capsule: code and data (or a header that names a loaded program) |
| Intelligence | at the end systems only (the end to end principle) | at the end systems and inside the network |
| Data and algorithms | fixed | mutable and fluid |
| Security and performance | simpler; fast hardware forwarding | harder: foreign code must be isolated, and running it costs time |
What it is good for: shrinking a video stream at the node nearest a slow link; caching popular content inside the network; merging the readings of thousands of sensors on the way instead of carrying them all; deploying a new multicast or congestion control scheme without waiting for a standard; pushing firewall rules to the right node during an attack; network management by mobile agents.
Where the idea went. Few active networks were deployed, because running other people's code inside routers raised hard security and performance problems. The idea of a programmable network survived in software-defined networking (SDN), where a central controller programs the switches, and in programmable switch hardware.
To remember it: a legacy network is the postal service, which reads only the address and passes the parcel on. An active network is a courier who also obeys a note on the parcel: "if the road to the village is slow, open me and send only the small photos".
- What is client/server networking? Explain Active Networking model framework comparing with traditional legacy network. 2066 Bhadra Q1b · 3+5
1.3Protocols, standards and layered architecture
Protocols, standards and interfaces HOT 5/27
82 Bh · 81 Ba · 76 Ch · 70 Asa · 66 Po1+2+51+3+42+2+4
Why rules are needed. Two machines built by different vendors, running different operating systems, understand each other only if both follow the same rules, exactly as two people talk only if they share a language and take turns. Without a protocol the bits arrive but mean nothing.
The three key elements of a protocol:
- Syntax: the structure or format of the data: which field comes where and how long it is. In an IPv4 header the first 4 bits are the version, the next 4 the header length.
- Semantics: the meaning of each field and the action it calls for: does this bit pattern mean "data" or "error, send again"?
- Timing: when data may be sent and how fast: speed matching, sequencing, timeouts. A sender at 100 Mbps swamps a receiver that handles 1 Mbps unless the protocol prevents it.
What a protocol specifies, as the book lists it: how the physical network is built, how computers connect to it, how the data is formatted for transmission, how it is sent over the network, and how errors are dealt with.
| Protocol | Layer | What it does |
|---|---|---|
| HTTP, HTTPS | application | fetches web pages (HTTP) |
| SMTP, POP3, IMAP | application | sends and reads email (email) |
| DNS | application | turns names into IP addresses (DNS) |
| TCP | transport | a reliable, ordered byte stream between processes (TCP) |
| UDP | transport | fast, connectionless datagrams (UDP) |
| IP | network (internet) | addresses and routes packets between networks (IPv4) |
| Ethernet (IEEE 802.3), Wi-Fi (IEEE 802.11) | data link and physical | moves frames over one link (Ethernet) |
A human protocol makes the idea concrete. A phone call opens with "Hello" or "Namaste", each side takes turns, a missed word gets a "Hajur?" (send it again), and it closes with an agreed goodbye before either side hangs up. Opening, turn taking, error recovery and release: every network protocol has the same parts.
Standards are agreed, published specifications that let equipment from different vendors work together in one network. A de jure standard is set by an official body; a de facto standard is one that won in practice before, or without, such approval (TCP/IP itself grew this way).
| Body | Full name | Known for |
|---|---|---|
| ISO | International Organization for Standardization | the OSI reference model (ISO 7498) |
| ITU-T | International Telecommunication Union, Telecommunication Standardization Sector (called CCITT until 1993) | X.25, the V series modem standards, ISDN, ADSL (G.992) |
| IEEE | Institute of Electrical and Electronics Engineers | the 802 LAN standards: 802.3 Ethernet, 802.11 Wi-Fi |
| IETF | Internet Engineering Task Force | the Internet's protocols, published as RFCs: IP (RFC 791), TCP (RFC 9293) |
| ANSI | American National Standards Institute | US national standards; the US member of ISO; FDDI |
| EIA (its standards now with TIA) | Electronic Industries Alliance | the EIA-232 (RS-232) serial interface |
Forums and regulators stand beside the bodies: industry forums such as the Frame Relay Forum and the ATM Forum sped up the standards for their technologies, and national regulators license the airwaves and telecom services; in Nepal that is the Nepal Telecommunications Authority (NTA).
Protocols, services and interfaces are three different things (layered architecture, services):
- Protocol: horizontal: the rules between peer entities, the same layer on two different machines.
- Service: vertical: what a layer offers the layer above it, as a set of primitive operations.
- Interface: the boundary between two adjacent layers on the same machine. It tells the upper layer how to reach the lower layer's services: the operations, their parameters and the results to expect.
- Protocol stack: the list of protocols a system uses, one per layer.
Post office analogy: the counter is the interface, "registered delivery" is the service, and the rules post offices follow among themselves to route and hand over the mail bags are the protocol. The counter can stay the same while the rules behind it change.
- Define protocol with examples. Why do we have layered architecture in networks? Differentiate between TCP/IP and OSI model. 2082 Bhadra Q1 · 2+2+4
- What is a protocol? List out the common protocols used at each layer of TCP/IP model. Differentiate between client-server is P2P network. 2081 Baishakh Q1 · 1+3+4
- What is protocol? What are the reasons for using layered network architecture? Compare OSI with TCP/IP reference model. 2076 Chaitra Q1 · 1+2+5
- What do you mean by protocol and interfaces? Write the protocols used in each layer of ICP/IP model. 2070 Ashad Q1 · 4+4
- Define network and protocol for network. Explain peer-to-peer network process with example. 2066 Poush Q1 · 2+6
Layered architecture: why network software is a hierarchy of layers TOP 9/27
82 Bh · 80 Ba · 76 Ch · 75 Ash · 71 Ch · 69 Ch · 68 Ch · 67 Asa · 66 Bh2+2+43+51+2+5
Why a hierarchy at all. Getting a file from one program to another across a world of different cables, radios, routers and operating systems is too big a problem to solve in one piece. Layering splits it into small problems stacked on each other: one layer moves bits on a wire, the next makes one link reliable, the next finds a route, the next makes the whole path reliable for a program, and so on. Each layer uses only the services of the layer below and offers its own to the layer above.
Reasons for layering (asked in nine sittings):
- It reduces design complexity: a complex system is broken into smaller, understandable parts, each designed, built and tested on its own.
- Modularity and independence: a layer can be changed or replaced without touching the others, as long as its service and interface stay the same. A laptop moves from Wi-Fi to an Ethernet cable and the browser never notices.
- Standardisation and interoperability: each layer's job and protocols are defined, so equipment and software from different vendors work together.
- Easier troubleshooting: a fault is located layer by layer (cable, link, route, port) and isolated quickly.
- Specialisation and reuse: a specialist team handles each layer, and one layer serves many users: IP carries every application over every kind of link.
- Flexibility: new technology slots in at one layer (fibre for copper, 5G for 4G) without redesigning the rest.
The price of layering: every layer adds a header (overhead), some functions are repeated in several layers (error control at both the data link and the transport layer), and strict layering can cost performance when one layer could use information another layer has.
The protocol hierarchy. Networks are organised as a series of layers; the number, names, contents and functions of the layers differ from network to network. The entities in corresponding layers on different machines are called peers, and peers communicate using the layer's protocol. But no data passes directly from layer n of one machine to layer n of another: each layer passes data and control information down to the layer below, until the lowest layer, where the physical medium carries it. The peers' conversation is virtual; only the medium carries real signals. Between each pair of adjacent layers is an interface that defines the primitive operations and services the lower layer offers the upper one.
Reading the drawing, a five-layer example from Tanenbaum that the book reproduces:
- Layer 5: an application process produces a message M and passes it to layer 4.
- Layer 4: adds header H4, with control information such as sequence numbers so that the receiving layer 4 can deliver the pieces in order, and passes it to layer 3.
- Layer 3: its packets have a size limit, so it breaks the message into M1 and M2 and puts its header H3 on each; H3 carries the addresses the routers use.
- Layer 2: adds a header H2 and a trailer T2 to each piece and hands them to layer 1.
- Layer 1: transmits the bits over the physical medium. At the destination each layer removes its own header (and trailer) and passes the rest up; no header of a lower layer ever reaches layer n.
Network architecture is the name for the set of layers and protocols. Its specification must give an implementer enough detail to write the program or build the hardware for each layer so that it obeys the protocol. The details of the implementation and the interfaces inside one machine are not part of the architecture, because they are hidden from the outside. TCP/IP and IBM's Systems Network Architecture (SNA) are network architectures; the OSI model on its own is not, because it names no protocols (OSI).
Design issues for the layers. The same handful of problems turns up at several layers, and each layer that meets one must solve it:
| Issue | The problem | How layers answer it |
|---|---|---|
| Addressing | a network holds many machines and each runs many processes: whom is the data for? | MAC addresses (data link), IP addresses (network), port numbers (transport) |
| Direction of data transfer | may data flow one way, either way in turn, or both ways at once, and on how many logical channels? | simplex, half duplex or full duplex; separate channels for data and control |
| Error control | physical circuits are not perfect | error detecting or correcting codes, and acknowledgements so the sender knows what arrived |
| Ordering (sequencing) | some channels do not keep messages in order | number the pieces and reorder them at the receiver |
| Flow control | a fast sender can swamp a slow receiver | receiver feedback, windows, agreed rates |
| Segmentation (message size) | a process or a link cannot take arbitrarily long (or very short) messages | break messages up and reassemble them; gather small ones together |
| Multiplexing | a separate connection for every pair of processes is costly | many conversations share one connection or channel, and are separated again at the far end |
| Routing | there are several paths from source to destination | choose the best route, at the network layer |
Later texts group the same concerns under reliability, resource allocation (including congestion and quality of service), evolution and security.
To remember why layering helps, think of a momo delivery to the hostel: the order is placed in the app, the restaurant packs the box with a slip naming the buyer, the rider's app picks the route to Pulchowk, the rider rides it one road segment at a time, on the road itself. The restaurant does not care whether the rider comes on a bike or a scooter: change one layer and the rest is untouched.
- Define protocol with examples. Why do we have layered architecture in networks? Differentiate between TCP/IP and OSI model. 2082 Bhadra Q1 · 2+2+4
- Why do we need layered architecture in computer network? Discuss the function of each layer of TCP/IP networking model. 2080 Baishakh Q1 · 3+5
- What is protocol? What are the reasons for using layered network architecture? Compare OSI with TCP/IP reference model. 2076 Chaitra Q1 · 1+2+5
- Why layering is important? Explain design issues for layers in detail. Mention service primitives for implementing connection oriented service. 2075 Ashwin Q1 · 2+4+2
- What do you mean by network architecture? Compare TCP/IP and OSI reference models. Explain X.25 Network with its key feature. 2071 Chaitra Q1 · 2+3+3
- Explain the need of Networking Software in the form of Hierarchy? Mention in which level layer of OSI reference model following tasks are done. i) Timing and voltage of received signal ii) Encryption and decryption of data iii) Data framing iv) Point-to-point connection of socket. 2069 Chaitra Q1 · 6+2
- Why are the network softwares defined with distinct layers stacked on top of one another? What are the factors to be considered when designing these layers? 2068 Chaitra Q1 · 2+6
- Why network software should be in hierarchical form? Explain in detail about OSI layer. 2067 Ashad Q1 · 3+5
- Why do communication process within computer network is divided into layers? How the process of data encapsulation occurs in transmission mode described by seven layers of OSI model. Compare OSI model with TCP/IP model. 2066 Bhadra Q1a · 2+2+4
Services: connection-oriented and connectionless, and the service primitives PIN 1/27
75 Ash2+4+2
Connection-oriented service is modelled on the telephone system: the user first establishes a connection, uses it to send data, then releases it. The connection acts like a tube: bits go in at one end and come out in the same order at the other. The two sides may negotiate parameters, such as the maximum message size or the quality of service, when the connection opens. Examples: TCP, X.25 virtual circuits, a phone call.
Connectionless service is modelled on the postal system: each message (datagram) carries the full destination address and is routed independently of the others, so two messages to the same place may take different routes and arrive out of order. Examples: UDP, IP.
| Service | Kind | Example |
|---|---|---|
| Reliable message stream | connection-oriented | a sequence of pages |
| Reliable byte stream | connection-oriented | a movie download, a remote login |
| Unreliable connection | connection-oriented | digitised voice, where a late correction is useless |
| Unreliable datagram | connectionless | electronic junk mail |
| Acknowledged datagram | connectionless | registered mail |
| Request and reply | connectionless | a database query |
Reliable means the receiver acknowledges every message, so the sender knows it arrived; the acknowledgements cost delay, which is why voice and video often prefer an unreliable service.
Service primitives are the operations a user process calls to use a service; in an operating system they are usually system calls. Five primitives are enough for a simple connection-oriented service:
| Primitive | Meaning |
|---|---|
LISTEN | block, waiting for an incoming connection |
CONNECT | establish a connection with a waiting peer |
RECEIVE | block, waiting for an incoming message |
SEND | send a message to the peer |
DISCONNECT | terminate the connection |
How a client and a server use them (six packets in all):
- LISTEN: the server calls LISTEN and blocks until a connection request arrives.
- CONNECT: the client calls CONNECT, which sends a connection request packet (1) to the server; the client is suspended until there is a response.
- Accepted: the server's operating system sees the request, unblocks the server and sends back a packet accepting the connection (2); the client is released and the connection is up.
- RECEIVE: the server calls RECEIVE to wait for the first request.
- SEND: the client SENDs its request (3) and calls RECEIVE to wait for the answer; the server processes the request and SENDs the reply (4).
- DISCONNECT: the client calls DISCONNECT (5); the server answers with its own DISCONNECT (6), and the connection is released.
Later editions of Tanenbaum add a sixth primitive, ACCEPT, for step 3. The Berkeley socket
calls are the same idea in code: listen(), connect(),
accept(), send(), recv() and close()
(sockets, socket programming).
The four classes of OSI primitive: request (a user asks for a service, as in CONNECT.request), indication (the peer is told of the event), response (the peer answers) and confirm (the first user learns the result). A confirmed service uses all four; an unconfirmed service only the request and the indication.
Services and protocols are not the same. A service is what a layer does for the layer above (vertical: the operations it offers, not how they work); a protocol is the set of rules that peers on different machines use to carry out that service (horizontal: the format and meaning of the packets). A layer can change its protocol freely as long as the service it offers stays the same, much as a program keeps calling one function while the function's code is rewritten.
To remember it: a phone call is connection-oriented (dial, talk, hang up; the words arrive in order); a letter is connectionless (each envelope carries the full address, and two letters posted together may arrive on different days).
- Why layering is important? Explain design issues for layers in detail. Mention service primitives for implementing connection oriented service. 2075 Ashwin Q1 · 2+4+2
1.4The OSI and TCP/IP models
The OSI reference model: seven layers and what each does HOT 8/27
81 Bh · 80 Bh · 74 Ch · 74 Ash · 72 Ch · 69 Ch · 67 Asa · 66 Po3+52+65+3
Open systems are systems open for communication with other systems, whatever their vendor. ISO started the work in 1977 and published the model in 1984. It is a model and not a network architecture, because it does not specify the exact services and protocols of each layer; it only says what each layer should do. ISO did publish OSI protocols separately, but they never caught on; the model survived as the way everyone describes networks.
Five principles fixed the seven layers (Tanenbaum): a layer wherever a different abstraction is needed; a well-defined function for each layer; functions chosen with internationally standardised protocols in mind; layer boundaries chosen to keep the information flowing across interfaces small; and enough layers to keep distinct functions apart, but few enough that the architecture does not become unwieldy.
Two groups. The bottom three layers (physical, data link, network) are the network support layers: they work hop by hop, between a host and a router or between two routers, and every router runs them. The top three (session, presentation, application) are the user support layers. The transport layer joins the two groups, and from it upwards the layers work end to end, only in the two hosts. The book groups the same seven as the top three, which define how applications communicate, and the bottom four, which define how data travels end to end.
| Layer | Main functions | Unit | Example protocols and devices |
|---|---|---|---|
| 7 Application | the window through which users and programs reach the network: services such as file transfer and access, mail, directory services, remote login, the network virtual terminal | message (APDU) | HTTP, FTP, SMTP, POP3, IMAP, DNS, Telnet, SSH, SNMP, DHCP |
| 6 Presentation | the syntax and semantics of the data: translation between character codes (ASCII, EBCDIC, Unicode) and machine formats; encryption and decryption; compression | PPDU | TLS encryption, JPEG, MPEG, ASN.1 with BER, XDR, MIME |
| 5 Session | dialog control (who may talk and when: half or full duplex, token management); synchronisation by checkpoints, so a long transfer resumes after a crash from the last checkpoint; opening, maintaining and closing sessions | SPDU | NetBIOS, RPC, the OSI session protocol (ISO 8327) |
| 4 Transport | process to process delivery of the whole message: port (service point) addressing; segmentation and reassembly with sequence numbers; connection control; end to end flow control and error control by retransmission; multiplexing | segment (TPDU) | TCP, UDP, SCTP |
| 3 Network | source to destination delivery of packets across many networks: logical addressing (IP addresses), routing and forwarding, fragmentation, congestion control, internetworking | packet | IP (IPv4, IPv6), ICMP, IPsec, the X.25 packet layer; device: router |
| 2 Data link | node to node delivery of frames on one link: framing, physical addressing (MAC addresses), error control (CRC, retransmission), flow control, medium access control on a shared link; sublayers LLC and MAC | frame | Ethernet (IEEE 802.3), Wi-Fi (IEEE 802.11), HDLC, PPP, Frame Relay; devices: switch, bridge, network card |
| 1 Physical | moving raw bits over the medium: mechanical and electrical specifications (connectors, pins, the voltage levels for 0 and 1), bit timing and data rate, encoding and modulation, bit synchronisation, line configuration, topology, transmission mode (simplex, half or full duplex) | bit | RS-232, V.35, 10BASE-T, 1000BASE-T, DSL, SONET/SDH; devices: hub, repeater, modem, cable |
Which layer does it? The board asks this as a short question; the answer is one layer with its reason:
| Task | Layer | Reason |
|---|---|---|
| Timing and voltage of the received signal | Physical | it defines the voltage levels, bit duration and bit synchronisation |
| Data framing | Data link | it groups bits into frames with a header and a trailer |
| Physical identification of a computer (MAC address) | Data link | MAC addresses travel in the frame header |
| Error detection and correction | Data link | the frame's CRC checks every link; the transport layer also checks end to end |
| Access to a shared channel | Data link (MAC sublayer) | it decides which station may transmit |
| Logical identification of a computer (IP address) | Network | IP addresses identify hosts across networks |
| Routing, choosing the path | Network | routers forward packets by their destination address |
| Point to point connection of sockets (process to process) | Transport | a socket is an IP address plus a port, and the transport layer joins two ports end to end |
| Segmentation and reassembly, port addressing | Transport | it numbers the segments and delivers them to the right process |
| Dialog control, synchronisation, checkpoints | Session | it manages who talks when, and where to resume |
| Encryption and decryption, compression, code translation | Presentation | it handles how the data is represented |
| File transfer, email, remote login | Application | services offered directly to users |
The significance of the OSI model: it is the common vocabulary of networking (everyone says "a layer 2 switch" or "a layer 3 problem"); it separates services, interfaces and protocols, so a layer can change without disturbing the others; it is the reference for designing and comparing real protocol stacks and for interoperability between vendors; it guides troubleshooting layer by layer, from the cable upwards; and it is the standard way networking is taught.
Walk one web request down the model, from a laptop on the hostel Wi-Fi: the browser asks for a page with HTTP (application); TLS encrypts the request and the page's text is in UTF-8 (presentation); the browser keeps the logged-in session open (session); TCP cuts the request into segments for port 443 and will resend anything lost (transport); IP puts the server's address on each packet and routers pick the path through the ISP (network); Wi-Fi frames carry the laptop's and the access point's MAC addresses and a CRC (data link); and radio signals at 2.4 or 5 GHz carry the bits (physical).
- Define Network. List a function of each layer of OSI reference model and compare it with TCPI/IP model. 2081 Bhadra Q1 · 2+6
- Differentiate between Client Server and Peer to Peer architecture. Discuss the functions of each layer of Open System Interconnection (OSI) model. 2080 Bhadra Q1 · 3+5
- Distinguish between Client-Server network and Peer-Peer network. Explain Open System Interconnection (OSI) model. 2074 Chaitra Q1 · 3+5
- What is the significance of OSI layer? Explain different layers of OSI with its functionalities. 2074 Ashwin Q1 · 2+6
- Compare OSI layer with TCP/IP Layer? Explain in which level of OSI layer following tasks are done. i) Error detection and correction ii) Encryption and Decryption of data iii) Logical identification of computer iv) Point-to-point connection of socket v) Dialogue control vi) Physical identification of computer 2072 Chaitra Q1 · 5+3
- Explain the need of Networking Software in the form of Hierarchy? Mention in which level layer of OSI reference model following tasks are done. i) Timing and voltage of received signal ii) Encryption and decryption of data iii) Data framing iv) Point-to-point connection of socket. 2069 Chaitra Q1 · 6+2
- Why network software should be in hierarchical form? Explain in detail about OSI layer. 2067 Ashad Q1 · 3+5
- Explain the seven layers of OSI model with their example protocols. 2066 Poush Q7 · 8
The TCP/IP model: four layers and their protocols PIN 4/27
82 Ba · 81 Ba · 80 Ba · 70 Asa4+41+3+43+5
Where it came from. TCP/IP grew out of the ARPANET, the research network funded by the US Department of Defense's Advanced Research Projects Agency (ARPA). Vinton Cerf and Robert Kahn described TCP in 1974; the ARPANET switched to TCP/IP on 1 January 1983, and the Internet grew from it. Its main goal was to interconnect many different networks and give universal communication services over them: connections had to survive the loss of routers and lines in between as long as the two ends kept working, and the design had to carry very different applications, from file transfer to real-time speech. The protocols came first; the model was written afterwards to describe them.
The four layers, bottom up:
- Host-to-network (network access, link) layer: the lowest layer. The original model says little more than that the host must connect to the network with some protocol so that it can send IP packets over it. In practice it covers framing, physical (MAC) addressing and putting the bits on the medium: OSI's data link and physical layers together. Protocols: Ethernet (IEEE 802.3), Wi-Fi (IEEE 802.11), PPP, DSL, Frame Relay, ATM.
- Internet layer: the linchpin that holds the whole architecture together. It lets a host inject packets into any network and have them travel independently to the destination, possibly by different routes and out of order: a connectionless, best effort service, like letters in the post. It defines an official packet format and protocol, IP, and handles logical addressing and routing. Protocols: IP (IPv4, RFC 791; IPv6, RFC 8200), ICMP for error and control messages, IGMP for multicast groups, ARP to find a MAC address (often placed at the boundary with the layer below).
- Transport layer: lets peer processes on the source and destination hosts carry on a conversation, as OSI's transport layer does. It segments the data, reassembles it, and names the process by a port number. Two protocols: TCP, reliable and connection-oriented, which delivers a byte stream without error and in order, with flow control (used where accuracy matters: the web, mail, file transfer); and UDP, unreliable and connectionless, with no sequencing or flow control (used where prompt delivery matters more: DNS lookups, voice and video calls, online games).
- Application layer: all the higher-level protocols users work with. TCP/IP has no session or presentation layer: applications include those functions themselves when they need them. Protocols: HTTP and HTTPS (web), SMTP, POP3 and IMAP (mail), FTP (files), DNS (names), DHCP (address assignment), SNMP (management), Telnet and SSH (remote login).
The protocols at each layer, with the well known port numbers of the application protocols (ports):
| Layer | Protocols | Unit |
|---|---|---|
| Application | HTTP 80, HTTPS 443, FTP 20 and 21, SSH 22, Telnet 23, SMTP 25, DNS 53, DHCP 67 and 68, POP3 110, IMAP 143, SNMP 161 | message |
| Transport | TCP, UDP (and SCTP) | segment (TCP), datagram (UDP) |
| Internet | IPv4, IPv6, ICMP, IGMP, ARP, RARP, IPsec | packet (IP datagram) |
| Host-to-network | Ethernet, Wi-Fi, PPP, DSL, Frame Relay, ATM | frame, then bits |
The hourglass. Many applications sit on two transport protocols, which sit on one internet protocol, which runs over every kind of link. IP is the narrow waist: anything that can carry IP packets can join the Internet, and any application written for IP works over any link. That one design choice is why the same browser works on the hostel Wi-Fi, a fibre line at home and a 4G phone.
Four layers or five? Tanenbaum's TCP/IP model, which the book follows, has four layers. Kurose and Ross, and Tanenbaum's own "hybrid model" for teaching, use five: application, transport, network, data link and physical. Both are right, as long as the answer says which one it draws.
To remember it, follow one Messenger video call from the hostel: the app (application) hands its audio and video to UDP (transport), which hands it to IP with the server's address (internet), which rides Wi-Fi frames to the router and then the ISP's fibre (host-to-network). Four handovers, four layers.
- Explain client/server and P2P network model with their advantages and disadvantages. Discuss the layer of TCP/IP model with suitable diagram. 2082 Baishakh Q1 · 4+4
- What is a protocol? List out the common protocols used at each layer of TCP/IP model. Differentiate between client-server is P2P network. 2081 Baishakh Q1 · 1+3+4
- Why do we need layered architecture in computer network? Discuss the function of each layer of TCP/IP networking model. 2080 Baishakh Q1 · 3+5
- What do you mean by protocol and interfaces? Write the protocols used in each layer of ICP/IP model. 2070 Ashad Q1 · 4+4
Data encapsulation: how headers and trailers are added and removed PIN 3/27
76 Ash · 70 Ch · 66 Bh4+42+2+4
Headers and trailers. A header is control information placed in front of the data: addresses (MAC, IP, port), sequence and acknowledgement numbers, a length, a type, a time to live, a checksum. A trailer is control information placed after the data; in practice it is the data link layer's frame check sequence (FCS), a CRC computed over the whole frame, and sometimes an end marker. The trailer goes at the end because the CRC can be calculated while the frame is being sent, and appended last.
PDU and SDU. What a layer receives from the layer above is its service data unit (SDU); the SDU plus the layer's header (and trailer) is its protocol data unit (PDU), which becomes the SDU of the layer below. Each PDU has its own name:
At the sender, five steps, as the book counts them in the OSI model:
- Data: the application, presentation and session layers create the data from the user's input (a request, a message, a file).
- Segment: the transport layer cuts the data into pieces and adds a TCP or UDP header (source and destination ports, sequence number, checksum).
- Packet: the network layer adds an IP header (source and destination IP addresses, time to live, protocol number).
- Frame: the data link layer adds a frame header (destination and source MAC addresses, type) and the trailer (FCS).
- Bits: the physical layer turns the frame into a stream of bits, as electrical, light or radio signals on the medium.
At the receiver, the same steps in reverse. The physical layer turns the signals back into bits. The data link layer checks the FCS (a damaged frame is discarded), checks that the destination MAC address is its own, strips the header and trailer, and passes the packet up. The network layer checks the destination IP address and removes the IP header. The transport layer uses the port number to find the right process, puts the segments in order and removes its header, and the application receives the original data. Each layer reads only the header its peer wrote: the headers are how peers talk (virtual communication).
At a router the frame is opened only up to the network layer: the router reads the IP header, chooses the next hop, and wraps the packet in a new frame for the next link, with new MAC addresses. The IP addresses stay the same end to end; the MAC addresses change at every hop.
A file is sent over Ethernet in chunks of 1460 bytes. TCP adds 20 bytes and IP 20 bytes, which makes 1500 bytes, the Ethernet maximum for a packet; Ethernet adds a 14-byte header and a 4-byte FCS, so the frame is 1518 bytes. Of each frame, is file data; the rest is the price of four layers of control information.
To remember it, post a letter: the letter itself is the data; it is sealed in an envelope with the friend's name (transport); the post office puts it in a bag tagged with the destination district (network); the bag rides a truck with a trip sheet in front and a seal at the back that is checked on arrival (the data link header and trailer); and the truck drives on the road (physical). At the other end each office opens only its own wrapping.
- What are the features of Client/Server Architecture? What are headers and trailers and how do they get added and removed? 2076 Ashwin Q1 · 4+4
- What are the features of Client/Server Architecture? What are headers and trailers and how do they get added and removed? Explain. 2070 Chaitra Q1 · 4+4
- Why do communication process within computer network is divided into layers? How the process of data encapsulation occurs in transmission mode described by seven layers of OSI model. Compare OSI model with TCP/IP model. 2066 Bhadra Q1a · 2+2+4
1.5Comparing OSI and TCP/IP
OSI and TCP/IP compared: similarities and differences TOP 9/27
82 Bh · 81 Bh · 79 Bh · 76 Ch · 73 Shr · 72 Ch · 71 Ch · 71 Shr · 66 Bh2+2+42+65+3
How the layers line up: TCP/IP's application layer does the work of OSI's application, presentation and session layers; the two transport layers match; TCP/IP's internet layer matches OSI's network layer; and TCP/IP's host-to-network layer covers OSI's data link and physical layers.
Similarities:
- Both are layered: each is a stack of independent protocols, each layer serving the one above, with peers talking by protocols.
- Both have an end to end transport layer: in both, the layers up to and including transport give the communicating processes an end to end, network-independent transport service.
- Both have an application layer at the top through which the users' programs work.
- Both have a network (internet) layer that routes packets between networks, and both are built on packet switching.
- Both use encapsulation: each layer adds its header on the way down and removes it on the way up.
- Both describe real networks: their layer numbers (layer 2, layer 3) are the everyday language of network engineers.
Differences:
| Basis | OSI model | TCP/IP model |
|---|---|---|
| Stands for | Open Systems Interconnection | Transmission Control Protocol / Internet Protocol |
| Developed by | ISO (published as ISO 7498, 1984) | the US Department of Defense's ARPA, for the ARPANET, in the 1970s; maintained by the IETF |
| Number of layers | 7 | 4 (5 when the lowest is split) |
| How it was made | model first, protocols later: general, not tied to any protocol | protocols first, model described later: it fits only its own protocols |
| Services, interfaces and protocols | clearly distinguished: the model's central idea | not clearly distinguished |
| Network layer service | connection-oriented and connectionless | connectionless only (IP) |
| Transport layer service | connection-oriented only | both: TCP connection-oriented, UDP connectionless |
| Session and presentation | separate layers | none: left to the application |
| Data link and physical | separate layers | merged into one host-to-network layer, barely specified |
| Replacing protocols | protocols well hidden, so they can be replaced as technology changes | protocols not easily replaced |
| Internetworking | not considered at first (one network per country was expected) | the main goal from the start |
| Use today | a reference and teaching model; its own protocols are hardly used | the protocol suite the Internet runs on |
Why OSI's protocols lost, in Tanenbaum's four reasons:
- Bad timing: the OSI protocols arrived when TCP/IP was already spreading in universities, shipped free with Berkeley UNIX.
- Bad technology: the session and presentation layers are nearly empty while the data link and network layers are overfull; addressing, flow control and error control turn up again in several layers; the standards were huge and complex.
- Bad implementations: the first ones were large, slow and unwieldy.
- Bad politics: OSI was seen as a creature of European telecom ministries and governments, pushed onto researchers.
TCP/IP's weaknesses, in turn: it does not separate service, interface and protocol clearly; it is not general and cannot describe other protocol stacks; its host-to-network layer is an interface rather than a layer, and does not tell physical from data link; and some early protocols (Telnet) were ad hoc yet became entrenched. Hence the modern habit: the OSI model to talk about networks, the TCP/IP protocols to build them.
To remember the difference: OSI is a syllabus a committee wrote before any class was taught: complete, tidy, and never followed to the letter. TCP/IP is the set of notes the seniors wrote after passing: shorter, a little messy, and what everyone actually uses.
- Define protocol with examples. Why do we have layered architecture in networks? Differentiate between TCP/IP and OSI model. 2082 Bhadra Q1 · 2+2+4
- Define Network. List a function of each layer of OSI reference model and compare it with TCPI/IP model. 2081 Bhadra Q1 · 2+6
- Compare the OSI reference model and TCP/IP reference model mentioning their similarities and differences. 2079 Bhadra Q1 · 8
- What is protocol? What are the reasons for using layered network architecture? Compare OSI with TCP/IP reference model. 2076 Chaitra Q1 · 1+2+5
- Differentiate between TCP/IP and OSI Model. Define Frame Relay in detail. 2073 Shrawan Q1 · 5+3
- Compare OSI layer with TCP/IP Layer? Explain in which level of OSI layer following tasks are done. i) Error detection and correction ii) Encryption and Decryption of data iii) Logical identification of computer iv) Point-to-point connection of socket v) Dialogue control vi) Physical identification of computer 2072 Chaitra Q1 · 5+3
- What do you mean by network architecture? Compare TCP/IP and OSI reference models. Explain X.25 Network with its key feature. 2071 Chaitra Q1 · 2+3+3
- What is computer network? Distinguish between OSI and TCP/IP reference model. 2071 Shrawan Q1 · 2+6
- Why do communication process within computer network is divided into layers? How the process of data encapsulation occurs in transmission mode described by seven layers of OSI model. Compare OSI model with TCP/IP model. 2066 Bhadra Q1a · 2+2+4
1.6Example networks
The Internet: a network of networks
How it grew:
- 1969, the ARPANET: four nodes in the US (UCLA, SRI, UC Santa Barbara and the University of Utah), funded by ARPA: the first large packet switched network.
- 1974 to 1983, TCP/IP: Cerf and Kahn's internetworking protocol, which the ARPANET adopted on 1 January 1983.
- 1986 to 1995, NSFNET: the US National Science Foundation's backbone joined the universities; it was retired in 1995, when commercial ISPs took over the backbone.
- 1989 to 1991, the World Wide Web: Tim Berners-Lee at CERN created the web (HTTP, HTML, URLs), which brought the Internet to the public.
How it is built:
- End systems (hosts): phones, laptops and servers at the edge.
- Access networks: the last link to the user: DSL, cable, fibre to the home, Wi-Fi, 4G and 5G.
- ISPs in tiers: local access ISPs buy transit from national and international ISPs, which connect to global (tier 1) backbones; ISPs of similar size often exchange traffic with each other free (peering).
- Internet exchange points (IXPs): places where many ISPs connect to swap traffic directly. In Kathmandu the Nepal Internet Exchange (NPIX) lets Nepali ISPs hand local traffic to each other without sending it abroad and back.
- Content providers' networks: large companies run their own global networks and place caches inside ISPs, so a popular video often comes from a server in the same city.
Who runs what. The Internet has no central government; each network sets its own policies. Only the two main name spaces are coordinated centrally: IP addresses (allocated by IANA, under ICANN, to five regional registries, of which APNIC serves the Asia Pacific region, Nepal included) and the root of the Domain Name System (under ICANN), below which .np is Nepal's country code domain (DNS). Standards come from the IETF as RFCs, with the Internet Society (ISOC) behind them.
Internet, intranet, extranet: an internet (small i) is any set of networks joined by routers; the Internet (capital I) is the global one; an intranet is a private network inside one organisation built with the same TCP/IP technology (a college portal reachable only on campus); an extranet opens part of an intranet to partners (suppliers logging in to a company's order system).
To remember it: run tracert (Windows) or traceroute (Linux)
to a foreign website from the hostel. The list of hops shows the trip from the Wi-Fi router to the
ISP, across the border and on to the server's network: a dozen independently owned networks
passing the same packets along.
X.25: the reliable, slow packet switched WAN HOT 7/27
82 Ba · 75 Ash · 71 Ch · 68 Ch · 68 Ba · 67 Asa · 66 Po4+42+3+32+6
Designed for bad lines. In the 1970s long distance data travelled over noisy analog telephone circuits, and the terminals at the ends were too simple to recover lost data themselves. So X.25 made the network itself reliable: every link and every packet switch checks, acknowledges and, when needed, retransmits, and packets arrive error free and in order. The price is speed: access lines typically ran at up to 64 kbps, and the processing at every hop adds delay.
The parts of an X.25 network (the book's figure 1.9):
- DTE: the user's terminal, computer or router.
- DCE: the device that joins the DTE to the network, usually a modem or the network's access port.
- PSE (packet switching exchange): the switches inside the carrier's network, joined by trunk lines. X.25 defines only the DTE to DCE interface; how the PSEs talk to each other is the carrier's choice.
- PAD (packet assembler and disassembler): lets a simple character terminal use the network, collecting characters into packets and back (ITU-T X.3, X.28 and X.29).
Three layers, matching OSI's bottom three:
| Layer | OSI | Job |
|---|---|---|
| Physical | 1 | the electrical interface between DTE and DCE: X.21 (digital), or X.21bis and V.24 on analog modems |
| Link access (frame) | 2 | LAPB (Link Access Procedure, Balanced), a subset of HDLC (HDLC): frames with sequence numbers, CRC error detection, acknowledgements and retransmission, and flow control on the DTE to DCE link |
| Packet (PLP) | 3 | the packet layer protocol: sets up and clears virtual circuits, multiplexes up to 4095 of them on one link, numbers packets and controls flow on each circuit, recovers by reset and restart |
Virtual circuits. A switched virtual circuit (SVC) is set up for a call and cleared after it, like a phone call; a permanent virtual circuit (PVC) is set up by the carrier at subscription and always present, like a leased line, so it needs no call setup. On a link each circuit is known by a 12-bit number: a 4-bit logical channel group number (LCGN) and an 8-bit logical channel number (LCN). That gives values, of which 0 is reserved, so up to 4095 circuits share one physical line (virtual circuits).
The packet format, for a data packet with 3-bit sequence numbers (modulo 8):
| Octet | Field | Bits | Meaning |
|---|---|---|---|
| 1 | Q bit | 1 | qualifier: 1 marks control information for a device such as a PAD, 0 ordinary user data |
| 1 | D bit | 1 | delivery confirmation: 1 asks for an end to end acknowledgement, 0 a local one from the network |
| 1 | Modulo | 2 | 01 for sequence numbers modulo 8, 10 for modulo 128; Q, D and these two bits form the general format identifier (GFI) |
| 1 | LCGN | 4 | logical channel group number |
| 2 | LCN | 8 | logical channel number; with the LCGN, the 12-bit virtual circuit number |
| 3 | P(R) | 3 | receive sequence number: the next packet expected, which acknowledges everything before it |
| 3 | M bit | 1 | more data: 1 means the user's message continues in the next packet |
| 3 | P(S) | 3 | send sequence number of this packet |
| 3 | Type | 1 | 0 marks a data packet (control packets end in 1 and use the whole octet as a type code) |
| 4 onwards | User data | variable | up to 128 bytes by default (other sizes can be agreed) |
Control packets keep the first two octets; the third is the packet type identifier. A call request also carries the calling and called DTE addresses (X.121 numbers) and optional facilities after these three octets.
| Packet (DTE to DCE / DCE to DTE) | Type octet |
|---|---|
| Call request / Incoming call | 0000 1011 |
| Call accepted / Call connected | 0000 1111 |
| Clear request / Clear indication | 0001 0011 |
| Clear confirmation | 0001 0111 |
| Receive ready (RR) | xxx0 0001 (xxx is P(R)) |
| Receive not ready (RNR) | xxx0 0101 |
| Reset request / Reset indication | 0001 1011 |
| Restart request / Restart indication | 1111 1011 |
The virtual circuit connection, in three phases:
- Call setup: DTE A picks a free logical channel and sends a Call request packet carrying B's address to its DCE. The network routes it once through its PSEs, and each PSE on the route records the circuit in a table. B's DCE delivers it as an Incoming call on one of B's free channels. B answers Call accepted, and A receives Call connected. The virtual circuit now exists.
- Data transfer: data packets carry only the short channel number, not the full address. Each PSE switches by table lookup: a packet that arrives on link 1 with channel 5 leaves on link 3 with channel 9, say. P(S) and P(R) number and acknowledge the packets, a window (2 by default) limits how many may be outstanding, and RR and RNR packets start and stop the flow. Packets arrive in order.
- Clearing: either DTE sends a Clear request; the other receives a Clear indication and answers Clear confirmation; the first DTE receives a Clear confirmation too, and both channel numbers are free again.
Beside these, an interrupt packet sends a few urgent bytes outside the flow control, a reset reinitialises one circuit (its sequence numbers return to 0) after an error, and a restart clears every circuit on the interface.
Key features and advantages: reliable, error free, in-order delivery even over poor lines; many virtual circuits multiplexed on one physical line; flow control on every circuit; both SVCs and PVCs; an international standard used by public data networks worldwide; a user pays for what is sent instead of renting a whole line.
Disadvantages: slow (low line rates, and every node stores, checks and acknowledges each packet), with high overhead and delay; unsuited to voice and video. Once fibre made lines nearly error free, the hop by hop checking became wasted work, and Frame Relay, ATM and later IP and MPLS replaced X.25, though it ran card payment and airline reservation networks for decades.
X.25 against Frame Relay is compared in full on the next card (Frame Relay): Frame Relay keeps the virtual circuits but drops the packet layer and the error correction.
To remember it: X.25 is a careful old postman who checks every letter at every post office on the route and goes back for any that is torn. Nothing is ever lost, but the post is slow.
- Write Short Notes on: (Any Two) a) 802.5 Token Ring b) PGP c) Socket programming fundamentals d) X.25 Network 2082 Baishakh Q10 · 2×4
- Write short notes on: (any two) i) Flow control in D22 ii) X.25 iii) ALOHA 2075 Ashwin Q10 · 4+4
- What do you mean by network architecture? Compare TCP/IP and OSI reference models. Explain X.25 Network with its key feature. 2071 Chaitra Q1 · 2+3+3
- What is X.25? Explain the format of X.25 packet in detail. 2068 Chaitra Q6 · 3+5
- Compare x.25 and frame relay network. A bit string 0111101111101111110 needs to be transmitted at the data link layer. What is the string actually transmitted after bit stuffing? 2068 Baishakh Q10 · 6+2
- Explain along with the packet format about the virtual circuit connection of X.25. 2067 Ashad Q6 · 4+4
- What do you understand by virtual circuit switching? Explain the X.25 virtual circuit switching. 2066 Poush Q6 · 2+6
Frame Relay: fast virtual circuits at the data link layer HOT 5/27
78 Bh · 73 Shr · 70 Asa · 68 Ba · 66 Bh2+62×45+3
Why it replaced X.25. By the late 1980s digital and fibre lines had made bit errors rare, and the computers at the ends ran TCP, which recovers lost data by itself. X.25's checking at every hop had become wasted effort. Frame Relay keeps the virtual circuits but removes the packet layer and the per-hop acknowledgements, so a switch can relay a frame as soon as it has read the address. It was standardised by the ITU-T (I.122, Q.922) and ANSI (T1.618) with the Frame Relay Forum, and sold at access speeds from 56 or 64 kbps through 1.544 Mbps (T1) and 2.048 Mbps (E1) up to 44.736 Mbps (T3).
Devices. Devices attached to a Frame Relay WAN are of two kinds: DTEs, the customer's terminating equipment (routers, bridges, terminals), usually on the customer's premises; and DCEs, the carrier's packet switches, which provide clocking and switching and actually move the data through the WAN.
Virtual circuits. Each logical connection between two DTEs is a virtual circuit through the carrier's switches. A PVC (permanent virtual circuit) is configured by the carrier and always present, for steady traffic between fixed sites; it has only two states, data transfer and idle. An SVC (switched virtual circuit) is set up on demand with Q.933 signalling and cleared afterwards, for occasional traffic (its steps are below). Many virtual circuits share one access line: a head office needs one physical line, not one per branch.
The DLCI (data link connection identifier) names a virtual circuit on one link. It has local significance: the same circuit may be DLCI 102 on the head office's access line and DLCI 201 at the branch, and every switch changes it as it relays the frame. DLCI 0 carries signalling; user circuits are usually given values from 16 to 1007.
The frame (the Q.922 core, with the default 2-byte address):
| Field | Size | Contents |
|---|---|---|
| Flag | 8 bits | 01111110, marks the start and the end; bit stuffing keeps it unique (framing) |
| Address | 16 bits (can be extended to 24 or 32) | the DLCI (10 bits, split 6 and 4); C/R (command or response, for the end systems); EA (address extension: 0 means another address octet follows, 1 marks the last); FECN, BECN and DE (below) |
| Information | variable | the user's data, for example an IP packet; there is no control field, since there is no sequencing and no acknowledgement |
| FCS | 16 bits | a CRC over the address and information fields: errors are detected, and a bad frame is discarded |
| Flag | 8 bits | 01111110 |
Congestion control without flow control. The network does not slow senders down hop by hop; it tells them, and drops what it must:
- CIR (committed information rate): the rate the carrier promises on a circuit, say 256 kbps on a 2 Mbps access line. A site may burst above it when the network has room.
- DE (discard eligibility): frames sent above the CIR get DE = 1, and a congested switch drops those first.
- FECN (forward explicit congestion notification): set on frames travelling towards the receiver through a congested switch, telling the receiver that its traffic meets congestion.
- BECN (backward explicit congestion notification): set on frames going back towards the sender, telling the sender to slow down.
- LMI (local management interface): status messages on the access line (on DLCI 0 or 1023) that report which PVCs are active and check that the link is alive.
The operation of a Frame Relay network: one frame from a bank's Kathmandu head office to its Pokhara branch, over a PVC.
- Encapsulate: the head office router (DTE) puts the IP packet in a frame with DLCI 102, the local number of the PVC to Pokhara, and sends it on its access line to the carrier's switch (DCE).
- Check: the switch checks the FCS; a damaged frame is discarded at once, with no message to anyone.
- Look up and relay: the switch looks up (incoming port, DLCI 102) in its table, finds (outgoing port 3, DLCI 310), rewrites the DLCI and relays the frame. Every switch on the path repeats this, and no acknowledgement is sent.
- Under congestion: a busy switch sets FECN on the frame and BECN on frames heading back, and drops DE frames first.
- Deliver: the last switch delivers the frame to the Pokhara router with DLCI 201, the PVC's number on that line. If a frame was lost, TCP in the two hosts notices and sends it again.
How an SVC is established, maintained and torn down. An SVC session passes through four operational states, driven by Q.933 signalling messages carried on DLCI 0:
- Call setup: the calling DTE sends SETUP (the called address and the traffic parameters, such as the CIR); the network answers CALL PROCEEDING and passes SETUP to the called DTE; the called DTE answers CONNECT, which the network passes back to the caller. During setup the network tells each end the DLCI to use, and the virtual circuit between the two DTEs is established.
- Data transfer: frames flow both ways on the assigned DLCI, relayed by the switches exactly as on a PVC.
- Idle: the connection is still active but no data is sent. It is maintained (STATUS ENQUIRY and STATUS messages check the link), and if it stays idle beyond a set time the call can be terminated.
- Call termination: either DTE sends DISCONNECT; the network answers RELEASE, and the DTE confirms with RELEASE COMPLETE. The other DTE gets the same three messages from its side, and the DLCI is freed.
Advantages: higher data rates than X.25; low overhead and delay; suits bursty LAN traffic, since a site can burst above its CIR; many virtual circuits on one access line cut the cost of joining many sites (cheaper than a leased line for every pair); independent of the protocol it carries. Disadvantages: no error correction or guaranteed delivery inside the network; frames are dropped under congestion; variable delay makes it poor for voice and video; MPLS and Ethernet services have now largely replaced it.
X.25 against Frame Relay:
| Basis | X.25 | Frame Relay |
|---|---|---|
| Layers used | physical, link (LAPB) and network (packet) | physical and data link only |
| Error control | detects and corrects at every hop, by retransmission | detects only; bad frames dropped; the end systems recover |
| Flow control | hop by hop and per circuit, with windows and RR/RNR | none in the network; FECN, BECN and DE instead |
| Acknowledgements | at every hop | none |
| Speed | low: typically up to 64 kbps | higher: 56 kbps to 44.736 Mbps |
| Delay and overhead | high: every node processes every packet | low: frames relayed once the address is read |
| Circuit number | 12-bit LCGN and LCN | 10-bit DLCI (default) |
| Multiplexing | at the network (packet) layer | at the data link layer |
| Signalling | in band: call request packets on the circuit itself | out of band: on DLCI 0 (Q.933) |
| Lines suited | noisy analog lines | clean digital and fibre lines |
| Traffic | terminal to host, low volume | LAN to LAN, bursty |
Frame Relay against ATM: both are virtual circuit WANs, but ATM cuts everything into fixed 53-byte cells (ATM):
| Basis | Frame Relay | ATM |
|---|---|---|
| Unit | variable-length frame | fixed 53-byte cell (5-byte header, 48-byte payload) |
| Speed | 56 kbps to 44.736 Mbps | typically 155.52 or 622.08 Mbps on SONET/SDH, also T1 to T3 rates for access |
| Circuit identifier | DLCI | VPI and VCI |
| Traffic designed for | data, especially bursty LAN traffic | voice, video and data together |
| Delay | variable: a long frame holds up the short ones behind it | low and predictable: small fixed cells, switched in hardware |
| Quality of service | CIR and DE only | service categories CBR, VBR, ABR, UBR |
| Error check | FCS over the whole frame | HEC over the cell header only; the payload is checked by the AAL |
| Overhead | small: about 6 bytes per frame of any size | 5 of every 53 bytes (9.4%), the cell tax |
| Congestion signals | FECN, BECN, DE | the CLP bit, a congestion bit in PT, traffic contracts |
| Cost and complexity | low, simple | high, complex |
| Typical use | joining an enterprise's branch LANs | carrier backbones, broadband ISDN, DSL aggregation |
To remember it: X.25 is the careful postman; Frame Relay is the express courier who reads only the label, never checks inside, throws away a parcel that arrives soaked, and leaves the sender to complain and post it again. Faster, because the checking moved to the two ends.
- Write short notes on: (Any Two) a) Frame relay b) TCP sliding window c) HDLC 2078 Bhadra Q10 · 2×4
- Differentiate between TCP/IP and OSI Model. Define Frame Relay in detail. 2073 Shrawan Q1 · 5+3
- What is virus circuit switching? Describe the operation of Frame-Relay network. 2070 Ashad Q6 · 2+6
- Compare x.25 and frame relay network. A bit string 0111101111101111110 needs to be transmitted at the data link layer. What is the string actually transmitted after bit stuffing? 2068 Baishakh Q10 · 6+2
- Differentiate between circuit switching and packet switching technology. Explain the operation how switched virtual circuit in frame relay network is established, maintained and teardown. 2066 Bhadra Q3b · 2+6
ATM: fixed 53-byte cells, virtual paths and the adaptation layers PIN 3/27
81 Bh · 80 Bh · 66 Bh2×43+3
Asynchronous because a source sends a cell whenever it has data, not in a fixed time slot of its own as in synchronous TDM (multiplexing), so no slot is wasted on an idle source. Cells rather than frames, because small cells of one size can be switched in hardware at very high speed, and a voice cell never waits behind a 1500-byte data frame: the delay stays low and predictable.
Why 48 bytes: a compromise. The US wanted 64-byte payloads for efficiency, Europe 32 bytes for low voice delay, and the committee settled between them on 48. Filling 48 bytes with 64 kbps voice takes ms.
The cell header at the user network interface (UNI):
| Field | Bits | Job |
|---|---|---|
| GFC (generic flow control) | 4 | local flow control between the user and the network (UNI only) |
| VPI (virtual path identifier) | 8 | which virtual path the cell belongs to |
| VCI (virtual channel identifier) | 16 | which virtual channel inside that path |
| PT (payload type) | 3 | user data or a management (OAM) cell; a congestion experienced bit; in AAL5, the end of a message |
| CLP (cell loss priority) | 1 | 1 means the cell may be dropped first under congestion |
| HEC (header error control) | 8 | a CRC-8 over the first four header bytes: corrects single-bit errors and detects most others; also used to find where cells begin |
Between two switches, at the network network interface (NNI), there is no GFC: its four bits extend the VPI to 12.
Virtual paths and virtual channels. A physical link (the transmission path) carries many virtual paths, and each virtual path bundles many virtual channels. A connection is named by the pair VPI/VCI on each link, which has local significance like a DLCI. A VP switch (cross-connect) switches whole paths and changes only the VPI, so thousands of channels are rerouted with one table entry; a VC switch changes both. As in X.25 and Frame Relay, connections may be permanent (PVCs) or switched (SVCs, set up with Q.2931 signalling).
The ATM reference model has three layers (and three planes: user, control and management):
| Layer | Sublayers | Job |
|---|---|---|
| ATM adaptation layer (AAL) | convergence sublayer (CS); segmentation and reassembly (SAR) | adapts the user's data to cells: the CS adds what the service needs (timing, sequence numbers, a CRC), and the SAR cuts the result into 48-byte payloads and rebuilds it at the far end |
| ATM layer | none | adds and removes the 5-byte header, multiplexes the cells of many connections onto one link, translates VPI/VCI in the switches, generic flow control, traffic management |
| Physical layer | transmission convergence (TC); physical medium dependent (PMD) | TC generates and checks the HEC, finds the cell boundaries, inserts idle cells and fits cells into SONET/SDH frames; PMD sends the bits on fibre or copper (155.52 Mbps OC-3/STM-1, 622.08 Mbps OC-12/STM-4) |
The AAL types, one for each class of service:
| AAL | Class of traffic | Used for | How it adapts |
|---|---|---|---|
| AAL1 | class A: constant bit rate, timing between the ends, connection-oriented | uncompressed voice; emulating T1/E1 circuits | a 1-byte SAR header (sequence number and its protection), 47 bytes of data in each cell |
| AAL2 | class B: variable bit rate with timing | compressed voice and video, mobile voice | packs short packets from several users into one cell, each with its own channel ID |
| AAL3/4 | classes C and D: variable rate data without timing, connection-oriented or connectionless | data; the old SMDS service | 4 bytes of SAR header and trailer in each cell (segment type, sequence number, multiplexing ID, length, CRC-10), 44 bytes of data |
| AAL5 | classes C and D, made simple and efficient | IP over ATM, LAN emulation, signalling | no overhead in each cell: an 8-byte trailer (length and CRC-32) and padding once per message, 48 bytes of data per cell, the last cell flagged in PT |
Service categories (ATM Forum) state what each connection is promised: CBR (constant bit rate: voice, video), rt-VBR (real-time variable: compressed video), nrt-VBR (non real-time variable: data with delay bounds), ABR (available bit rate: data that adapts to what is free) and UBR (unspecified: best effort, like IP).
A 1500-byte IP packet sent over AAL5 gains an 8-byte trailer (1508 bytes), padded to 32 cells of 48 bytes (1536 bytes, so 28 bytes of padding). On the wire that is bytes, so is the packet; the rest is cell headers, trailer and padding.
Advantages: very high speed; voice, video and data on one network with real quality of service; low, predictable delay; scales from the desktop to the backbone. Disadvantages: the 9.4% cell tax, complexity and cost; for data it lost to cheaper switched Ethernet and to IP over MPLS. It ran telephone and Internet backbones in the 1990s, and carried ADSL traffic between home modems and the exchange (xDSL).
To remember it: ATM is a supermarket that ships everything, rice, eggs or a television, in identical 53-litre crates on a conveyor: the crates move fast and never jam, though a lot of crate travels with every egg.
- Write Short notes on: (Any Two) a) 802.4 Token Bus b) Framing with bit stuffing c) Server Socket programming for bind, listen and accept d) ATM 2081 Bhadra Q10 · 2×4
- Write short notes on: (Any Two) a) Go Back-N ARQ b) Dual Stack method in IPv6 c) Diffie-Hellman algorithm d) ATM 2080 Bhadra Q10 · 2×4
- Write short notes on (any two) i) TCP Sliding Window Protocol ii) Secrete Key Algorithm: DES iii) ISDN Signaling and ATM AAL iv) ICMP Message Types 2066 Bhadra Q5b · 3+3
Ethernet as an example network
From a shared cable to a switched star. Ethernet was invented at Xerox PARC by Robert Metcalfe and David Boggs in 1973; DEC, Intel and Xerox published the DIX Ethernet specification (10 Mbps, 1980, revised as Ethernet II in 1982), and the IEEE standardised it as 802.3 in 1983. The first Ethernets were a coaxial bus that every station shared, taking turns by CSMA/CD (CSMA/CD). Today every station has its own full-duplex link to a switch: a star with no collisions at all, which is why modern Ethernet no longer needs CSMA/CD.
| Generation | IEEE standard (year) | Speed | Common media |
|---|---|---|---|
| Ethernet | 802.3 (1983) | 10 Mbps | thick and thin coaxial cable (10BASE5, 10BASE2), later twisted pair (10BASE-T, 1990) |
| Fast Ethernet | 802.3u (1995) | 100 Mbps | Category 5 twisted pair (100BASE-TX), fibre |
| Gigabit Ethernet | 802.3z (1998), 802.3ab (1999) | 1 Gbps | fibre; Category 5e twisted pair (1000BASE-T) |
| 10 Gigabit Ethernet | 802.3ae (2002), 802.3an (2006) | 10 Gbps | fibre; Category 6a twisted pair (10GBASE-T) |
| 40 and 100 Gigabit | 802.3ba (2010) | 40 and 100 Gbps | fibre, in data centres and backbones |
| 400 Gigabit | 802.3bs (2017) | 400 Gbps | fibre, in data centre and carrier links |
The name code reads speed, signalling and medium: 10BASE-T is 10 Mbps, baseband, twisted pair; 100BASE-TX is Fast Ethernet over two pairs of Category 5 cable; 1000BASE-T is gigabit over four pairs; 10GBASE-SR is 10 gigabit over short-reach multimode fibre.
What every version keeps is the frame (preamble, 48-bit destination and source MAC addresses, type or length, 46 to 1500 bytes of data, a 32-bit CRC), so a frame from an old card is still understood by a switch bought today. The frame, MAC addressing and the access rules are taught in chapter 3 (Ethernet in detail).
Why it won: it is cheap and simple, every new generation is backward compatible, its speed has been multiplied by ten again and again, and the switch replaced the shared bus without changing the frame. Carriers now sell Metro Ethernet and Carrier Ethernet as MAN and WAN services, which is why the book calls it a technology "used in LANs and MANs".
To remember it: the blue cable from the hostel router to a desktop is Ethernet: most likely 1000BASE-T on Category 5e or 6 cable, a star point to the switch inside the router, and the same frame format Ethernet has used since the 1980s.
VoIP: voice calls as IP packets
Circuit against packet. A PSTN call reserves a 64 kbps circuit end to end for the whole call, silences included (the telephone network); VoIP sends the voice as packets that share the network with everything else, which is why it avoids the tolls of the traditional network and costs only the data.
How a VoIP call works:
- Signalling: a signalling protocol finds the other party and sets up the call: SIP (the Session Initiation Protocol, RFC 3261: INVITE, ringing, 200 OK, ACK, and BYE to hang up) or the older ITU-T H.323.
- Digitise and compress: the microphone's signal is sampled (8000 times a second for ordinary telephone quality) and compressed by a codec: G.711 (64 kbps, the PSTN's own coding), G.729 (8 kbps), or Opus (adaptive, used by many apps).
- Packetise: every 20 ms of speech goes into one packet with an RTP header (sequence number and timestamp), inside UDP, inside IP. UDP is used because a late voice packet is useless: sending it again would only make things worse.
- Carry: the packets cross the networks like any others; routers that support quality of service send them first.
- Play out: the receiver's jitter buffer holds packets for a few tens of milliseconds to even out their varying delay, reorders them by sequence number, covers a lost packet by repeating or smoothing the sound, decodes and plays. RTCP reports loss and delay back to the sender.
20 ms of speech at 64 kbps is 160 bytes. With the RTP (12 bytes), UDP (8) and IP (20) headers a packet is 200 bytes, sent 50 times a second: kbps in each direction, before the link layer adds its own header.
Quality depends on three numbers: one-way delay (ITU-T G.114 advises keeping it under about 150 ms for natural conversation), jitter (the variation in delay, smoothed by the buffer) and packet loss (a few percent already sounds broken).
Kinds of VoIP: app to app (WhatsApp, Viber, Messenger, Zoom); IP phones on an office IP-PBX; an analog telephone adapter that lets an ordinary phone use VoIP; gateways that connect VoIP calls to the PSTN, under a softswitch that controls them; and VoLTE, voice over the 4G mobile network, which is VoIP inside the operator's own network.
Advantages: cheap, above all for international calls; one network for voice, video and data; extra features (video, conferencing, voicemail by email, a number that works anywhere). Disadvantages: quality depends on the internet connection and on power; an emergency call cannot easily locate the caller; open to eavesdropping, spam calls and toll fraud unless encrypted and secured (SRTP, TLS).
To remember it: the Viber call a student makes to a parent working in Qatar costs a few megabytes, not an international call rate: the voice was cut into fifty small packets every second and put back together on the other side.
NGN: the next generation network
The problem it solves. A traditional operator ran a separate network for each service: circuit switches for fixed telephones, another core for mobile, another network for data, and often another for television. Each had its own equipment, staff and billing, and a new service had to be built into one of them. An NGN replaces them all with one IP-based packet core that carries voice, video and data together: convergence.
The key ideas:
- Packet-based transport: everything travels as IP packets over one core, often with MPLS underneath for traffic engineering and quality of service (MPLS).
- Service separated from transport: ITU-T Y.2011 splits the network into a transport stratum (moving packets: access and core) and a service stratum (controlling calls and sessions, and providing the applications). A new service can be added without touching the transport, and the transport upgraded without breaking the services.
- Call control in software: a softswitch, or the IP Multimedia Subsystem (IMS) defined by 3GPP, controls calls with SIP, while media gateways connect to the old PSTN.
- QoS-enabled broadband access: DSL, fibre to the home, cable, 4G and 5G radio, all feeding the same core.
- Open interfaces: third parties can build services on the operator's network, and users can reach competing providers.
- Generalised mobility: the same services on any access, fixed or mobile, as the user moves (fixed mobile convergence).
Often drawn as four layers: access (how users connect), transport or core (the IP/MPLS backbone), control (softswitch or IMS) and service or application (voice, video, messaging, third-party applications).
Benefits and challenges: one network to build and run is cheaper, and new services arrive faster; but telephone-grade quality and reliability over shared IP, the security of an open network, and working alongside the old network are all hard.
To remember it: an NGN is a city that replaces its separate pipes for water, gas and drainage with one big service tunnel carrying them all: dig once, maintain once, and add a new service by laying one more line in the same tunnel.
MPLS: forwarding by short labels
Why labels. A normal IP router matches each packet's destination address against a table of perhaps a million routes, looking for the longest matching prefix, at every hop. MPLS does that classification once, at the edge of the network: the packet gets a label, and every router inside simply looks the label up in a small exact-match table, swaps it and forwards. The labels identify virtual paths between distant nodes rather than endpoints, much as a DLCI or a VPI/VCI identifies a circuit.
The label (shim) header, 32 bits placed between the layer 2 header and the IP header:
| Field | Bits | Job |
|---|---|---|
| Label | 20 | the value the routers look up |
| TC (traffic class, once called EXP) | 3 | quality of service class |
| S (bottom of stack) | 1 | 1 on the last label, since labels can be stacked |
| TTL | 8 | time to live, as in IP, so a loop cannot run forever |
The parts: a label edge router (LER) at the ingress sorts each packet into a forwarding equivalence class (FEC) (packets to be treated alike, such as one destination prefix with one class of service) and pushes a label; label switching routers (LSRs) in the core swap labels; the egress LER pops the label and forwards by IP. The path a sequence of labels follows is a label switched path (LSP), and it runs one way only. Neighbours agree on labels with LDP, RSVP-TE or BGP.
- Build the paths: OSPF or IS-IS learns the topology; LDP or RSVP-TE builds the LSPs and the label tables.
- Push: the ingress LER classifies the packet into an FEC and pushes, say, label 17.
- Swap: each LSR reads only the label: 17 in becomes 42 out on port 2, and so on.
- Pop: the egress LER (or the router just before it) removes the label and delivers the plain IP packet.
What it is used for: traffic engineering (steering traffic onto lightly loaded links instead of only the shortest path); MPLS VPNs, which join a company's branches privately across a carrier's shared network and replaced Frame Relay and ATM circuits; quality of service by traffic class; and fast reroute around a failed link within tens of milliseconds. It carries IP, Ethernet, ATM and Frame Relay traffic over T1/E1, ATM, Frame Relay, DSL or Ethernet links: hence multiprotocol.
To remember it: a label is a token number at a busy hospital: the reception reads the whole case once and hands over token 17, and after that every counter reads only the token, not the patient's history.
xDSL: broadband over the telephone line
The last mile. The copper pair from the exchange to a home (the local loop) was built for voice, which needs only about 4 kHz; the wire itself can carry frequencies of a few megahertz over short distances. DSL uses those higher frequencies for data. It covers only the link from the exchange to the home or office, never the links between exchanges: hence a "last mile" technology.
How it works:
- Splitter or microfilter: at the home, it separates the voice band (to the telephone) from the data band (to the DSL modem).
- DSL modem: in the home, puts the data onto the line.
- DSLAM (DSL access multiplexer): at the exchange, ends hundreds of lines and passes their traffic on to the ISP's network.
- DMT modulation (discrete multitone): the band is divided into many 4.3125 kHz subchannels (256 of them in ADSL, up to 1.104 MHz); each carries as many bits as its signal to noise ratio allows, so a noisy part of the band simply carries less.
- Asymmetric speeds: most variants give far more bandwidth downstream (towards the customer) than upstream, which suits browsing and streaming.
| Variant | Symmetry | Typical top speed | Standard |
|---|---|---|---|
| ADSL | asymmetric | about 8 Mbps down, 1 Mbps up | ITU-T G.992.1 (1999) |
| ADSL2+ | asymmetric | about 24 Mbps down, 1 Mbps up | ITU-T G.992.5 (2003) |
| VDSL2 | asymmetric or symmetric | about 100 Mbps on loops of a few hundred metres | ITU-T G.993.2 (2006) |
| HDSL | symmetric | 1.544 or 2.048 Mbps (T1 or E1) over two or three pairs | replaced leased T1/E1 lines |
| SDSL | symmetric | about 2 Mbps on one pair | business lines |
Distance is everything: the speed falls as the loop gets longer, because high frequencies fade in copper. ADSL works to about 5 km; VDSL2's top speeds need the customer within a few hundred metres of the equipment.
DSL and ISDN (ISDN) both use the existing copper telephone lines, and both need the customer fairly close to the exchange (the book says usually under 20,000 feet), but DSL is far faster: ISDN's basic rate is 144 kbps (2B+D), while DSL runs to megabits. ADSL traffic between the modem and the exchange was usually carried in ATM cells (ATM). Fibre to the home (FTTH) has since overtaken both.
In Nepal, Nepal Telecom sold ADSL broadband over its landline copper for years; most homes have since moved to fibre to the home from ISPs such as Nepal Telecom, WorldLink and Vianet.
To remember it: the same copper pair that carried grandfather's landline calls carries the internet above them: voice in the bottom 4 kHz, data in the megahertz above, split by a small box at the phone socket.
1.7Last minute recall
Chapter 1 in one screen
- Network: autonomous computers and devices joined by links and protocols to exchange data and share resources; parts: nodes, links, protocols, services.
- Uses: business (sharing, reliability, saving money, scalability), home (information, communication, entertainment, e-commerce, education), mobile, society.
- Sizes: PAN (1 to 10 m), LAN (campus), MAN (city), WAN (country); internetwork, the Internet.
- Topologies: bus, star, ring, mesh ( links), tree, hybrid; physical against logical.
- Client/server: server listens, client requests, server processes and replies; central data, security, backup; single point of failure.
- Peer to peer: every peer client and server; join, search, connect, exchange; BitTorrent, workgroup; cheap, weak security.
- Active network: programmable nodes computing on packets; capsule (integrated) or programmable switch (discrete); NodeOS, EEs, AAs, ANEP.
- Protocol: rules for communication; syntax, semantics, timing; bodies ISO, ITU-T, IEEE, IETF, ANSI, EIA.
- Layering: less complexity, modularity, standards, troubleshooting, reuse; peers, interfaces, virtual communication; architecture = layers + protocols.
- Design issues: addressing, direction, error control, flow control, multiplexing, routing, ordering, segmentation.
- Primitives: LISTEN, CONNECT, RECEIVE, SEND, DISCONNECT; request, indication, response, confirm.
- OSI: physical, data link, network, transport, session, presentation, application (ISO 7498, 1984); bit, frame, packet, segment.
- Which layer: voltage and timing physical; framing, MAC, error control data link; IP address network; socket connection transport; dialog session; encryption presentation.
- TCP/IP: host-to-network, internet (IP), transport (TCP, UDP), application (HTTP, SMTP, DNS, FTP); no session or presentation layer.
- Encapsulation: data, segment, packet, frame (header and FCS trailer), bits; removed in reverse at the receiver.
- OSI against TCP/IP: 7 against 4; model first against protocols first; service, interface, protocol clear against blurred; network layer both against connectionless; transport connection-oriented against both.
- X.25: DTE to DCE interface; physical X.21, LAPB, PLP; LCGN + LCN; Q, D, P(R), M, P(S); call request, incoming call, call accepted, call connected, clear.
- Frame Relay: layers 1 and 2; DLCI (local); PVC and SVC; FECN, BECN, DE, CIR; SVC: SETUP, CALL PROCEEDING, CONNECT, DISCONNECT, RELEASE, RELEASE COMPLETE.
- ATM: 53-byte cells, 5 header + 48 payload; GFC, VPI, VCI, PT, CLP, HEC; AAL1, AAL2, AAL3/4, AAL5; CS and SAR.
- Others: Ethernet IEEE 802.3; VoIP (SIP, RTP over UDP, 80 kbps for G.711); NGN (Y.2001, convergence); MPLS (20-bit label, push, swap, pop); xDSL (ADSL, DSLAM, asymmetric).
Chapter 2 · 5 hours · about 8 marks a paper · in 25 of the 27 sittings
Physical layer
The physical layer moves raw bits as signals: voltages on copper, pulses of light in glass, radio waves through the air. This chapter covers how a network's performance is measured (delay, latency, throughput, capacity), the media that carry the bits, how many signals share one link (multiplexing), how a network joins any sender to any receiver (circuit, message and packet switching, datagram and virtual circuit), the telephone network and its exchanges, and ISDN. Switching was set in 13 of the 27 sittings on record, more than any other topic of the chapter, and transmission media in 7.
- Network performance: the four delays (processing, queuing, transmission, propagation), latency, throughput, and the channel capacity limits of Nyquist and Shannon.
- Transmission media: guided (twisted pair, coaxial cable, optical fiber) and unguided (radio, microwave, infrared, satellite), how waves propagate, and how to choose a medium.
- Multiplexing: FDM, WDM, synchronous and statistical TDM, and CDM.
- Switching: circuit, message and packet switching, and packet switching's two forms, datagram and virtual circuit.
- The telephone network: local loops, exchanges and trunks, the T1 and E1 digital hierarchy, and the switching systems inside the exchanges.
- ISDN: its channels, interfaces, functional groups, reference points and signalling.
- Layer 1 of chapter 1's models (OSI, TCP/IP): every frame of chapter 3 and every packet of chapter 4 finally travels as these signals.
- Virtual circuits are how X.25, Frame Relay and ATM work (X.25, Frame Relay, ATM); datagram switching is how IP routers work (routing).
- On the wire: repeaters and hubs are physical layer devices (internetworking devices); Ethernet runs over UTP and fiber (Ethernet), Wi-Fi over radio (wireless LAN).
- Delay meets the upper layers: queuing delay is where congestion shows (congestion control), and the bandwidth-delay product sizes the sliding window (flow control).
- 2.1 The physical layer, delay, throughput and channel capacity
- 2.2 Transmission media: guided, fiber, unguided, satellite
- 2.3 Multiplexing
- 2.4 Switching: circuit, message, packet; datagram and virtual circuit
- 2.5 The telephone network, T1 and E1, and the exchanges
- 2.6 ISDN
- 2.7 Last minute recall, chapter 2
- Switching is the banker: circuit switching against packet switching, as a table, was set in seven sittings; defining switching, its types with examples, and why circuit switching suits real-time traffic make up the rest.
- Transmission media: define and classify them, explain them with merits and demerits, compare twisted pair, coaxial and fiber, or list the factors for choosing one.
- Multiplexing and ISDN: the types of multiplexing, switching against multiplexing, the E1 hierarchy; ISDN's purpose, architecture, channels and signalling in five sittings.
- Calculations: throughput (2080 Bhadra, 2078 Bhadra) and SNR with Shannon capacity (2066 Bhadra), worked in full in the Numericals panel.
- Draw: the circuit, message and packet timing; the datagram and virtual circuit networks; the ISDN reference points; the optical fiber system.
2.1The physical layer and network performance
The physical layer: moving raw bits as signals PIN 1/27
72 Ka2+6
It moves bits, not meaning. The physical layer does not know whether a bit belongs to an address, a password or a photo; it only makes sure that a 1 sent at one end is read as a 1 at the other. Every frame, packet and segment of the layers above finally travels as these signals.
Four kinds of rule describe a physical interface; standards such as EIA-232 and ITU-T X.21 are written this way:
- Mechanical: the connector's shape, size and number of pins (an RJ-45 jack has eight).
- Electrical: the voltage levels, how long one bit lasts, the longest cable allowed.
- Functional: what each pin or circuit does: transmit data, receive data, clock, ground.
- Procedural: the order of events that brings the link up, uses it and takes it down.
Its functions, the list every answer is built from:
| Function | What it decides | Example |
|---|---|---|
| Physical characteristics of interface and medium | the cable, connector and medium | Cat 6 UTP with RJ-45 connectors |
| Representation of bits | the encoding: how 0s and 1s become signals | Manchester code on 10 Mbps Ethernet: a transition in the middle of every bit |
| Data rate | bits per second, so the duration of one bit | at 100 Mbps a bit lasts 10 ns |
| Synchronization of bits | sender and receiver clocks agree where each bit starts | the 7-byte preamble in front of an Ethernet frame |
| Line configuration | point-to-point or multipoint (shared) link | a leased line; an old shared coaxial bus |
| Physical topology | how the devices are wired together | star, bus, ring, mesh, hybrid |
| Transmission mode | which way the bits flow | simplex, half-duplex, full-duplex |
| Mode | Direction | Example |
|---|---|---|
| Simplex | one way only | keyboard to computer, TV broadcast |
| Half-duplex | both ways, one at a time | walkie-talkie, Ethernet on a shared hub |
| Full-duplex | both ways at once | telephone call, switched Ethernet |
Bit rate is not baud rate. Bit rate counts bits per second; baud rate (signal rate) counts signal elements, or symbols, per second. When each symbol carries bits, bit rate = baud rate × : a modem sending 2,400 symbols a second at 4 bits a symbol (16 levels) gives 9,600 bps. The bandwidth limits the baud rate, and noise limits how many levels can be told apart (channel capacity).
In the TCP/IP reference model the physical layer is not a layer of its own: the lowest layer, called host-to-network, network access or link layer, covers both the physical and the data link functions. TCP/IP defines no protocol there; it runs over whatever the network below specifies, such as IEEE 802.3 Ethernet over UTP or fiber, IEEE 802.11 Wi-Fi over radio, or DSL over a telephone line. So the functions in the table are the same in both models; only their place differs (Forouzan's five-layer version of TCP/IP does draw a separate physical layer). The models themselves are chapter 1's (TCP/IP, OSI).
Devices that work only at this layer: repeaters, which regenerate a weakened signal; hubs, multiport repeaters that copy every bit to every port; modems, which put bits onto an analog carrier; transceivers; and the cables and connectors themselves (internetworking devices). None of them reads an address.
To remember it: when Bikash sends a file over the hostel LAN, the physical layer of his laptop's network card turns each bit into a voltage pattern on the four copper pairs of the Cat 6 cable, and the switch port in the corridor turns the voltages back into bits. Over the hostel Wi-Fi the same bits leave as 2.4 or 5 GHz radio waves. The file, its packets and its frames are other layers' business: the physical layer only carries ones and zeros.
- List out the functions of physical layer in TCP/IP reference model. Explain different types of transmission media. 2072 Kartik Q2 · 2+6
Delay, latency and throughput: measuring a network PIN 3/27
80 Bh · 78 Bh · 74 Ash1+3+43+3+22+6
Four measures describe how a network performs:
| Measure | Meaning | Unit | Example |
|---|---|---|---|
| Bandwidth | the capacity of a link: the most data it can carry per second (for a signal, the range of frequencies it passes) | bps (Hz) | a 100 Mbps Ethernet port |
| Throughput | the data actually delivered successfully per second over a period | bps | 60 Mbps measured on that port during a backup |
| Latency (delay) | how long data takes to reach the destination | s, ms | 20 ms to a nearby server |
| Jitter | the variation in delay between packets of one flow | ms | packets 20 ms apart arriving 15, 30 and 18 ms apart |
Throughput , and it is always at most the bandwidth. It falls below the bandwidth because of headers, retransmissions, collisions, congestion, slow end hosts and the slowest link on the path, the bottleneck. The Ring Road in Kathmandu is the bandwidth; the crawl at rush hour is the throughput. Both board calculations of throughput (2080 Bhadra, 2078 Bhadra) are worked in the Numericals panel; the trap in both is the units: bytes to bits (× 8), minutes to seconds (÷ 60).
The four delays at each node. A packet crossing a router is delayed four times (the book's Figure 2.1):
| Delay | Cause | Formula | Typical size |
|---|---|---|---|
| Processing | examine the header, check for bit errors, look up the output link | set by the router | microseconds |
| Queuing | wait in the output buffer behind earlier packets | set by the load | 0 to milliseconds, varying |
| Transmission | push all L bits of the packet onto a link of rate R | microseconds to milliseconds | |
| Propagation | one bit travels the link length d at the signal speed s | 5 µs per km of cable |
The signal speed s is about m/s in copper and fiber (two thirds of the speed of light) and m/s through air and space.
Transmission is not propagation. Transmission delay depends on the size of the packet and the rate of the link, not on the distance; propagation delay depends on the distance and the medium, not on the packet. Picture a bus at the Kathmandu bus park: boarding every passenger through one door is the transmission delay (more passengers or a narrower door, longer), and the drive to Pokhara is the propagation delay (a longer road, a longer drive), whoever is on board.
Queuing delay and traffic intensity. If packets of L bits arrive at an average rate of a packets a second at a link of rate R, the traffic intensity is . Near 0 the queue is short; as it approaches 1 the queuing delay grows sharply; above 1 the queue grows without limit and packets are dropped. This is where congestion shows (congestion control).
Latency is the total time from the first bit leaving the source to the last bit arriving: propagation + transmission + queuing + processing, added over every hop. The round-trip time (RTT) is the time there and back, the figure ping reports.
Bandwidth-delay product : the number of bits that fill the link, in flight, before the first one reaches the far end. It says how much a sender may send before an acknowledgment can possibly return, which is why it sizes sliding windows (flow control).
A host sends a 1,500-byte packet (L = 12,000 bits) over a 10 Mbps link.
- 2 km of fiber to the campus router (s = m/s): = 1.2 ms and = 10 µs. Transmission dominates.
- A geostationary satellite hop, 35,786 km up and 35,786 km down (s = m/s): = 71,572,000 / () ≈ 238.6 ms, while is still 1.2 ms. Propagation dominates.
- Bandwidth-delay product of the satellite hop: ≈ 2.39 million bits, about 199 such packets in flight before the first one lands.
Causes of packet delay, in one list:
- Router processing: header checks, table lookups, encryption on a busy router.
- Congestion: long queues as the traffic intensity nears 1, and loss when a buffer overflows.
- Slow links and big packets: transmission delay L/R at every hop.
- Distance and medium: propagation delay, worst on satellite links.
- Number of hops: store-and-forward means a packet must arrive whole at each router before it is sent on, so every hop adds a transmission delay.
- Retransmissions after errors or loss (error control), and flow and congestion control holding the sender back.
- Slow end systems: a busy server, an overloaded phone.
Jitter hurts voice and video most: a call whose packets leave 20 ms apart but arrive 15, 30 and 18 ms apart sounds broken, so the receiver holds packets in a jitter (playout) buffer to even them out.
- a) Discuss about the different factors of choosing the transmission media." Circuit switching is suitable for real-time communication", give your reasons. If a file of 1000 bytes was sent over a network in 2 seconds, calculate throughput. 2080 Bhadra Q2 · 3+3+2
- Define Throughput. A network with bandwidth of 20 Mbps can pass only an average of 18,000 frames per minute with each frame carrying an average of 20,000 bits. Calculate the throughput of this network. Differentiate between Packet switching and Virtual Circuit switching. 2078 Bhadra Q2 · 1+3+4
- What are the causes of packet delay in computer networks? What are the differences between circuit switching and packet switching? 2074 Ashwin Q3 · 2+6
Bandwidth and channel capacity: Nyquist and Shannon PIN 1/27
66 Bh4+4
Bandwidth has two meanings. For a signal or a channel it is the width of the range of frequencies passed, in hertz: a telephone voice channel passes about 300 to 3,400 Hz, a bandwidth of about 3.1 kHz (4 kHz with guard bands). For a link it is the bit rate, in bits per second. The two are tied: more hertz allow more bits per second, and Nyquist and Shannon say exactly how many.
Nyquist (1924): the noiseless channel. A channel of bandwidth B can carry at most 2B signal changes a second, and each change between L levels carries bits:
A noiseless 3 kHz channel carries 2 × 3000 × 1 = 6 kbps with 2 levels, and 2 × 3000 × 4 = 24 kbps with 16 levels. More levels raise the rate, but the receiver must still tell them apart, and noise makes levels that are close together impossible to distinguish. That is Shannon's limit.
Shannon (1948): the noisy channel. No number of levels can beat
where SNR is the signal power divided by the noise power, as a plain ratio. In decibels, : 10 dB is a ratio of 10, 20 dB of 100, 30 dB of 1000. Always turn decibels back into a ratio before using Shannon.
- Example, a telephone line: B = 3,000 Hz and SNR = 30 dB (1,000): ≈ 29.9 kbps. That is why dial-up modems on analog lines stopped near 33.6 kbps.
- Using both together: Shannon gives the ceiling, Nyquist the levels needed. For B = 2 MHz and SNR = 255, Shannon gives = 16 Mbps. Choosing a safer 12 Mbps, Nyquist gives , so and L = 8 levels.
Why the received signal is worse than the one sent (transmission impairments):
| Impairment | What happens | Example |
|---|---|---|
| Attenuation | the signal loses power with distance, measured in decibels | amplifiers or repeaters every few km on copper |
| Distortion | the frequency components of a signal travel at different speeds, so its shape changes | pulses spreading in a long cable or a multimode fiber |
| Noise | unwanted energy is added: thermal (moving electrons), induced (motors, power lines), crosstalk (one pair into another), impulse (spikes from lightning or switching) | the hiss on a phone line |
Loss in decibels is : a signal that falls to half its power has lost about 3 dB.
The board question (2066 Bhadra) gives the signal as 2 mW and the noise as 200 µW: put both in milliwatts first (200 µW = 0.2 mW), so SNR = 10, which is 10 dB; then ≈ 1.04 Gbps. It is worked in full in the Numericals panel.
To remember: bandwidth is the width of the road, the number of levels is how many lanes the drivers can keep apart, and noise is the dust that makes lane markings unreadable; Shannon is the road authority's limit that no lane painting can beat.
- Calculate SNR and maximum channel capacity of a cat6 channel having bandwidth 300 MHz with 2mW and 200 μW as signal and noise power respectively. 2066 Bhadra Q2b · 4+4
2.2Transmission media
Transmission media: the kinds, and how to choose one HOT 7/27
81 Bh · 81 Ba · 80 Bh · 76 Ch · 74 Ch · 72 Ka · 71 Shr2+63+53+3+2
Guided media confine the signal to a solid path: twisted pair, coaxial cable and optical fiber. The cable decides where the signal goes, so they are fast, secure and predictable, but only reach where a cable can be laid. Unguided media radiate the signal from an antenna into air, water or space: radio, microwave and infrared. No cable means mobility and reach, but the signal is open to anyone in range and to the weather.
| Point | Guided (wired) | Unguided (wireless) |
|---|---|---|
| Signal path | along a cable | through air or space, from an antenna |
| Examples | twisted pair, coaxial cable, optical fiber | radio, microwave (terrestrial, satellite), infrared |
| Data rate | high: up to terabits on fiber | lower, and shared by every user in range |
| Security | must be tapped physically | anyone in range can receive it |
| Interference | low (shielding; none on fiber) | weather, obstacles, other transmitters |
| Mobility | none | users move freely |
| Installation | cable must be laid: costly over hills and rivers | towers and antennas only |
| Cost with distance | grows with the cable length | almost independent of distance (satellite) |
Factors in choosing a medium. No medium is best everywhere; the designer weighs these:
| Factor | The question to ask | Who wins |
|---|---|---|
| 1. Bandwidth and data rate | How many bits per second now, and in five years? | fiber, then coaxial, then twisted pair |
| 2. Distance and attenuation | How far before a repeater is needed? | single mode fiber (tens of km); UTP Ethernet stops at 100 m |
| 3. Cost | Cable, connectors, equipment, labour and upkeep? | UTP is cheapest; fiber optics and satellites cost most |
| 4. Noise immunity | Motors, power lines or lightning nearby? | fiber is immune to EMI; STP and coaxial beat UTP |
| 5. Security | Can someone tap it unnoticed? | fiber is hardest to tap; radio is easiest to intercept |
| 6. Ease of installation | Flexibility, weight, bend radius, skills? | UTP is light and easy; fiber needs splicing |
| 7. Environment and terrain | Indoors or outdoors, across a river or a ridge? | microwave or satellite where a cable cannot go |
| 8. Mobility | Do the users move? | only wireless |
Also weighed: reliability (rain fade, cable cuts), scalability (room to add users) and regulation (radio spectrum needs a licence).
- Offices and labs within 90 m of the floor switch: Cat 6 UTP, cheap and easy, 1 Gbps.
- The link of about 400 m between the main block and the library: multimode fiber. It is beyond UTP's 100 m, and an outdoor copper run would invite lightning (1000BASE-SX reaches 550 m on OM2 multimode).
- The hostel across the river, where no cable can be laid: a point-to-point microwave or Wi-Fi bridge between two masts in line of sight.
- Laptops and phones in the canteen: Wi-Fi.
- The internet connection from the ISP: single mode fiber.
Merits and demerits, one line each: twisted pair is cheap and easy, but noisy and short; coaxial cable has better shielding and bandwidth, but is bulky; fiber has enormous bandwidth and immunity to EMI, but is costly to install; radio reaches everywhere through walls, but at low rates in a crowded spectrum; microwave carries high rates over long hops, but needs line of sight and fades in rain; infrared is private to a room, but short and blocked by walls. The next four cards explain each (guided media, optical fiber, unguided media, satellite).
- What are the factors to be considered while selecting media for communication? Differentiate between datagram and virtual circuit switching approach with respect to Frame Relay Network. 2081 Bhadra Q2 · 2+6
- List out the most common guided and unguided transmission media used in computer networks now a days. Explain any one of the guided transmission media with examples. 2081 Baishakh Q2 · 3+5
- a) Discuss about the different factors of choosing the transmission media." Circuit switching is suitable for real-time communication", give your reasons. If a file of 1000 bytes was sent over a network in 2 seconds, calculate throughput. 2080 Bhadra Q2 · 3+3+2
- What is transmission medium? Explain different transmission medium with their merits and demerits. 2076 Chaitra Q2 · 1+7
- Define transmission media. Compare among Twisted Pair, Coaxial cable and Fiber optic. 2074 Chaitra Q2 · 3+5
- List out the functions of physical layer in TCP/IP reference model. Explain different types of transmission media. 2072 Kartik Q2 · 2+6
- What is transmission media? Explain about any three transmission media in detail. 2071 Shrawan Q2 · 2+6
Twisted pair and coaxial cable, compared with fiber HOT 7/27
81 Ba · 76 Ch · 74 Ch · 74 Ash · 71 Shr · 68 Ba · 66 Po2+63+51+7
Twisted pair cable is two insulated copper conductors, each about half a millimetre across (22 to 26 AWG), twisted around each other; a LAN cable bundles four pairs in one jacket, a telephone drop has one or two. It is the cheapest and most widely used medium.
Why twist: a noise source induces almost the same voltage in both wires of a pair, and the receiver reads only the difference between them, so the noise cancels. Giving neighbouring pairs different twist rates keeps them from coupling into each other (crosstalk).
Types of twisted pair cable are named three ways.
1. By shielding:
| Type | Construction | Merits | Demerits | Use |
|---|---|---|---|---|
| UTP (unshielded) | no shield | cheap, thin, flexible, easy to terminate | picks up EMI; more crosstalk | almost every office LAN; telephone lines |
| STP (shielded) | a grounded foil or braid around each pair, the whole cable, or both | less EMI and crosstalk; higher rates | costlier, stiffer, must be grounded | factories, runs beside power cables, 10 Gbps and above |
ISO/IEC 11801 names the shields exactly: U/UTP (none), F/UTP (foil around all pairs), U/FTP (foil around each pair), S/FTP (braid overall and foil on each pair).
2. By category (ANSI/TIA-568):
| Category | Bandwidth | Typical use |
|---|---|---|
| Cat 3 | 16 MHz | telephone; 10BASE-T Ethernet (10 Mbps) |
| Cat 5 | 100 MHz | 100BASE-TX (100 Mbps) |
| Cat 5e | 100 MHz | 1000BASE-T (1 Gbps) |
| Cat 6 | 250 MHz | 1 Gbps; 10 Gbps up to about 55 m |
| Cat 6A | 500 MHz | 10GBASE-T to 100 m |
| Cat 7 (ISO class F) | 600 MHz | shielded 10 Gbps |
| Cat 8 | 2000 MHz | 25 and 40 Gbps up to 30 m, in data centres |
3. By the wiring at the RJ-45 ends (T568A and T568B are the two pin orders):
- Straight-through: the same order at both ends; joins unlike devices, such as a PC to a switch or a router to a switch.
- Crossover: T568A at one end and T568B at the other, so transmit meets receive; joins like devices, a PC to a PC or a switch to a switch. Most modern ports (auto-MDIX) cross over by themselves.
- Rollover (console): the pin order fully reversed; joins a PC's serial port to the console port of a router or switch.
Characteristics (the book): analog loops need amplifiers every 5 to 6 km and digital links repeaters every 2 to 3 km; an Ethernet segment over UTP stops at 100 m (90 m of fixed cable plus patch cords). Uses: the telephone local loop, DSL, Ethernet LANs (Ethernet), Power over Ethernet for IP cameras and access points. Merits: cheapest, light, flexible, easy to install and extend. Demerits: noise and crosstalk, short range, less bandwidth than coaxial or fiber, easy to tap.
Coaxial cable, from the centre out: a copper conductor; a layer of insulation (the dielectric); an outer conductor of braided wire or foil, which is both the return path and a shield; and a plastic jacket. The two conductors share one axis, hence "coaxial". The shield keeps noise out and the signal in, so coaxial cable carries far higher frequencies than twisted pair, up to about 1 GHz. Common cables are 5 to 7 mm thick (RG-58, RG-6); heavy trunk cables run to 1 to 2.5 cm (the book's figure).
- Grades: RG-59 and RG-6 (75 Ω) for cable TV and CCTV; RG-58 (50 Ω) for thin Ethernet, 10BASE2; RG-8 (50 Ω) for thick Ethernet, 10BASE5. Connectors: BNC, F-type (TV), N-type.
- Uses: cable TV and cable internet, CCTV, antenna leads; once, long-distance telephone trunks and early Ethernet, now replaced by fiber and UTP.
- Merits: wide bandwidth, good noise immunity, longer runs than twisted pair.
- Demerits: thicker, stiffer and dearer than UTP; on a shared bus one fault takes every station down; amplifiers needed every few km.
The three compared:
| Point | Twisted pair | Coaxial cable | Optical fiber |
|---|---|---|---|
| Signal | electrical | electrical | light |
| Structure | two insulated copper wires, twisted | central conductor, insulation, braid shield, jacket | glass core, cladding, buffer, jacket |
| Bandwidth | lowest: 16 MHz to 2 GHz by category | moderate: up to about 1 GHz | highest: terahertz range |
| Data rate | 10 Mbps to 10 Gbps (40 on Cat 8) | 10 Mbps (old Ethernet) to a few Gbps (cable TV networks) | 10 Gbps a wavelength; terabits with WDM |
| Distance without repeater | 100 m for Ethernet | hundreds of metres to a few km | km on multimode, tens of km on single mode |
| Noise immunity | low (STP better) | good | complete: no EMI, no crosstalk |
| Attenuation | high | moderate | lowest: about 0.2 dB/km at 1550 nm |
| Power loss by (book) | conduction and radiation | conduction | absorption, scattering, dispersion, bending |
| Security | easy to tap | harder | very hard to tap |
| Cost | cheapest | moderate | highest to install |
| Installation | easiest | moderate | needs skilled splicing |
| Typical use | LANs, telephone loops | cable TV, CCTV | backbones, FTTH, submarine links |
The Cat 6 UTP from each room's wall jack to the floor switch; the coaxial lead from the rooftop dish to the TV in the common room; the single strand of fiber from the ISP's pole to the building's router. And when the new computer lab turns out to be 160 m from the switch, UTP cannot reach (100 m): a second switch half way, or fiber, solves it.
- List out the most common guided and unguided transmission media used in computer networks now a days. Explain any one of the guided transmission media with examples. 2081 Baishakh Q2 · 3+5
- What is transmission medium? Explain different transmission medium with their merits and demerits. 2076 Chaitra Q2 · 1+7
- Define transmission media. Compare among Twisted Pair, Coaxial cable and Fiber optic. 2074 Chaitra Q2 · 3+5
- Define switching and multiplexing. Explain about any two guided transmission media in detail. 2074 Ashwin Q2 · 2+6
- What is transmission media? Explain about any three transmission media in detail. 2071 Shrawan Q2 · 2+6
- What are types of twisted pair cable? Calculate the efficiency of slotted Aloha. 2068 Baishakh Q2 · 4+4
- Describe guided and unguided media used in computer network with their advantages. 2066 Poush Q2 · 8
Optical fiber: light in glass PIN 1/27
82 Bh4+2
Structure, from the centre out: the core of glass (8 to 10 µm across in single mode fiber, 50 or 62.5 µm in multimode); the cladding, glass of a lower refractive index, 125 µm across; a plastic buffer coating, 250 µm; strength members of aramid yarn (Kevlar); and the outer jacket. The cross section is drawn on the guided media card (guided media).
How the light stays in: total internal reflection. Light passing from a denser medium (the core, index ) into a rarer one (the cladding, , smaller than ) bends away from the normal. Beyond the critical angle it does not cross at all: it is reflected back into the core, and does so again at every bounce along the fiber.
Example: with = 1.48 and = 1.46, the critical angle is ≈ 80.6°, so a ray must meet the boundary at more than 80.6° from the normal, almost parallel to the axis. The numerical aperture NA = ≈ 0.243, so light entering within about 14° of the axis is caught.
Propagation modes:
| Mode | Core | How light travels | Source | Reach and use |
|---|---|---|---|---|
| Multimode step index | large (50 µm or more), one refractive index throughout | rays bounce at many angles; paths of different lengths spread the pulse (modal dispersion) | LED | shortest; old LANs, plastic fiber |
| Multimode graded index | 50 or 62.5 µm, index falling from the axis outward | rays curve back gently; outer rays travel faster in the lower index, so arrivals bunch up | LED or VCSEL laser | up to about 550 m at 1 Gbps; building backbones |
| Single mode | 8 to 10 µm | essentially one ray along the axis: no modal dispersion | laser diode | tens of km and more; ISP backbones, FTTH, submarine cables |
Sources and detectors (the book):
- LED: cheaper, longer life, works over a wider temperature range; incoherent, broad spectrum, low power: short multimode links.
- Injection laser diode (ILD): coherent, narrow spectrum, far more power, very fast to modulate: long single mode links.
- Detectors: the PIN photodiode (simple, cheap) or the avalanche photodiode, APD (internal gain, more sensitive, for long links).
Wavelength windows, and "its RF range". Fiber is used where glass absorbs least: 850 nm (multimode, short reach), 1310 nm (single mode, least dispersion) and 1550 nm (lowest loss, about 0.2 dB/km; used with erbium-doped fiber amplifiers and DWDM). With , these are about 353 THz, 229 THz and 193 THz: near-infrared light, between about 190 and 355 THz, some 650 to 1,200 times higher than the top of the radio frequency (RF) range at 300 GHz. That enormous carrier frequency is why fiber's bandwidth is so large. The electrical signal fed to the transmitter can itself be anything from voice to a radio signal: radio-over-fiber links carry mobile radio signals to antenna sites this way.
A generic optical fiber communication system (2082 Bhadra):
- Message source: the information as an electrical signal (voice, video, data).
- Electrical transmitter: codes and modulates it and drives the light source with a matching current.
- Optical source: an LED or laser diode turns the current into light pulses, which are coupled into the fiber.
- Optical fiber cable, the channel, with connectors and splices; on long links, repeaters (light to electrical to light) or optical amplifiers (EDFAs, which amplify the light directly) make up for attenuation.
- Optical detector: a PIN or avalanche photodiode turns the light back into a current.
- Electrical receiver: amplifies, equalizes, regenerates and decodes the signal.
- Destination: the user gets the message.
Advantages: very high bandwidth; low attenuation, so repeaters can be tens of km apart; immune to electromagnetic interference and lightning; no crosstalk; very hard to tap; thin and light; no sparks and no shock hazard, so safe near fuel; no corrosion; long life. Disadvantages: costly to install, terminate and test; fragile, with a minimum bend radius; splicing needs skill and equipment; light goes one way, so a duplex link needs two fibers or two wavelengths; it cannot carry power to devices as copper can.
To remember: a fiber-to-the-home (FTTH) connection, of the kind WorldLink and Vianet run in Nepali cities: single mode fiber from the ISP's equipment to a passive splitter, which shares it among many houses, and in each house an ONT box that is the optical detector and receiver, turning the light back into Ethernet and Wi-Fi.
- Explain line of sight (LOS) propagation modes. Draw block diagram generic optical fiber (OF) communication system and its RF range. 2082 Bhadra Q2 · 4+2
Unguided media: radio, microwave, infrared and how waves travel HOT 5/27
82 Bh · 81 Ba · 76 Ch · 71 Shr · 66 Po1+72+63+5
Antennas are either omnidirectional, radiating all round (a radio mast, a Wi-Fi access point), or directional, focusing a narrow beam (the parabolic dish and horn antennas of microwave and satellite links).
The three unguided media, with the frequency bands the book uses:
| Medium | Frequency | Direction | Properties | Uses |
|---|---|---|---|---|
| Radio waves | 3 kHz to 1 GHz | omnidirectional | travel far and pass through walls; low data rates; a crowded, licensed spectrum | AM and FM radio, TV, cordless phones, paging: one sender, many receivers |
| Microwaves | 1 to 300 GHz | unidirectional, line of sight | high data rates; antennas must be aligned; the higher bands do not pass walls, and rain fades them above about 10 GHz | terrestrial links between towers, satellite links, cellular networks, Wi-Fi at 2.4, 5 and 6 GHz |
| Infrared | 300 GHz to 400 THz | line of sight, short range | high rates, but cannot pass walls (private to one room); sunlight interferes | TV remotes, short links between devices |
Terrestrial microwave (the book) uses the 4 to 6 GHz and 21 to 23 GHz bands between parabolic dishes on towers, hills or tall buildings; its repeaters stand farther apart than coaxial cable's, and it is the choice across rivers and mountains where a cable is impractical. Satellite links have their own card (satellite communication).
Propagation methods. How a wave reaches the receiver depends mainly on its frequency (the book's Figures 2.13 to 2.15):
| Method | Frequency | How the wave travels | Uses |
|---|---|---|---|
| Ground (surface) wave | below 2 MHz | low frequency waves follow the curvature of the earth; the range is set by the transmitter's power | AM medium wave broadcasting, maritime and navigation beacons |
| Sky (ionospheric) wave | 2 to 30 MHz | the wave goes up and the ionosphere bends it back to earth far away: long distances with low power, varying between day and night | shortwave broadcasting, amateur radio |
| Line of sight (space wave) | above 30 MHz | a straight line between antennas that can see each other; the range is limited by the earth's curvature | FM, TV, microwave links, mobile phones, satellites |
Line of sight propagation, closely (2082 Bhadra):
- Direct wave: the main path, straight from antenna to antenna.
- Ground-reflected wave: a second path bouncing off the ground or water. Together with the direct wave it forms the space wave, and the two can add or cancel, one cause of multipath fading.
- Optical and radio line of sight: the atmosphere bends radio waves slightly towards the earth, so they reach a little beyond the visible horizon. With the antenna height h in metres and K = 4/3 (Stallings):
- Two antennas can be up to km apart. Two 50 m towers each reach ≈ 29.2 km, so they can stand about 58 km apart; that is why microwave and broadcast towers stand on hilltops.
- Impairments on a line of sight link: free-space loss (rising with distance and frequency), absorption by rain and water vapour (above about 10 GHz), multipath reflections, refraction, and obstacles such as hills, buildings and trees in the path.
- Satellites are also line of sight to their earth stations, and the way round the earth's curvature for long distances.
Wi-Fi, Bluetooth and mobile networks all use microwave bands, chiefly the 2.4 and 5 GHz ISM bands; how stations share the air is chapter 3's subject (wireless LAN), and securing them chapter 8's (WEP).
To remember: a medium wave AM station is heard beyond the hills, and farther still at night (ground and sky waves); an FM station fades once a ridge stands between the radio and its tower (line of sight); and the TV remote stops working the moment a roommate stands in front of the TV (infrared).
- Explain line of sight (LOS) propagation modes. Draw block diagram generic optical fiber (OF) communication system and its RF range. 2082 Bhadra Q2 · 4+2
- List out the most common guided and unguided transmission media used in computer networks now a days. Explain any one of the guided transmission media with examples. 2081 Baishakh Q2 · 3+5
- What is transmission medium? Explain different transmission medium with their merits and demerits. 2076 Chaitra Q2 · 1+7
- What is transmission media? Explain about any three transmission media in detail. 2071 Shrawan Q2 · 2+6
- Describe guided and unguided media used in computer network with their advantages. 2066 Poush Q2 · 8
Satellite communication
The transponder is the receiver and transmitter pair on board; its two jobs are amplification and frequency translation. A satellite carries many transponders, each serving one band of frequencies.
The uplink is higher than the downlink: about 6 GHz up and 4 GHz down in the C band, about 14 GHz up and 11 to 12 GHz down in the Ku band. Different frequencies keep the strong outgoing signal from drowning the weak incoming one, and the higher frequency, which fades more, goes to the earth station, which can afford a bigger transmitter than the satellite.
| Orbit | Altitude | One orbit | Features | Example |
|---|---|---|---|---|
| LEO (low earth orbit) | about 500 to 2,000 km | about 90 to 120 minutes | delay of a few ms; small footprint, so many satellites are needed | Starlink, Iridium satellite phones |
| MEO (medium earth orbit) | from about 2,000 km up to the geostationary height | hours (GPS: about 12 h) | used mainly for navigation | GPS, at about 20,200 km |
| GEO (geostationary) | 35,786 km above the equator | 23 h 56 min 4 s, one turn of the earth | appears fixed, so dishes need no tracking; three satellites 120° apart cover almost all the earth but the poles; long delay | TV broadcasting (DTH), VSAT |
Up and down is at least 2 × 35,786 = 71,572 km. At m/s that takes 71,572,000 / () ≈ 0.239 s. A question and its reply each cross the hop, so a conversation waits about 0.48 s for every answer: the pause heard on satellite telephone calls. A LEO satellite at 550 km gives 2 × 550 km / ( m/s) ≈ 3.7 ms.
Frequency bands (the IEEE letter bands, the book's Table 2.2): L 1 to 2 GHz, S 2 to 4, C 4 to 8, X 8 to 12, Ku 12 to 18, K 18 to 27, Ka 27 to 40, V 40 to 75 and W 75 to 110 GHz. The L band carries GPS and satellite phones, the C band TV distribution (it suffers least from rain), the Ku band direct-to-home TV and VSAT, the Ka band high-throughput broadband.
Merits: one satellite covers a whole country or continent; within the footprint the cost does not depend on distance; it broadcasts naturally to many receivers; it reaches mountains and islands where a cable cannot go. Demerits: the long delay of GEO; the high cost of building and launching; a life of about 12 to 15 years (the book), so a replacement must be planned; rain fade in the Ku and Ka bands; and the orbit must be watched and corrected (station keeping).
Other kinds of satellite (the book): astronomical, biosatellites, communication, earth observation (weather, mapping), navigation (GPS) and killer satellites (anti-satellite weapons).
To remember: every direct-to-home TV dish on a Kathmandu rooftop points south and never moves: its geostationary satellite sits over the equator, south of Nepal, keeping pace with the turning earth.
2.3Multiplexing
Multiplexing: many signals on one link HOT 6/27
80 Ba · 79 Bh · 74 Ash · 73 Shr · 69 Ch · 67 Asa4+41+2+52+2+4
Why it matters:
- Efficiency: a link's capacity is usually far more than one user needs; one fiber can carry thousands of telephone calls.
- Cost: one cable or one radio band instead of n, so less cable, installation and upkeep.
- It makes networks possible: trunks, broadcasting, cable TV, mobile networks and the internet's backbone all depend on it.
- Scalability: users are added without laying new lines.
One bus carrying forty passengers on one road, instead of forty taxis, is the idea.
FDM (frequency division multiplexing) is analog. The link's bandwidth is divided into frequency bands, one per signal; each signal modulates its own carrier; unused strips called guard bands keep neighbours from overlapping; and all the signals travel at the same time. Uses: AM radio (530 to 1700 kHz), FM radio (88 to 108 MHz), TV channels, first generation mobile phones, cable TV. The old analog telephone network packed 12 voice channels of 4 kHz into a 48 kHz group.
WDM (wavelength division multiplexing) is FDM for light: each signal rides its own wavelength (colour) on one fiber, and a prism or diffraction grating combines and separates them. Dense WDM (DWDM) packs dozens of wavelengths, 0.8 nm (100 GHz) apart in the 1550 nm band, onto one fiber, each carrying 10 to 100 Gbps or more.
TDM (time division multiplexing) is digital. The link's time is divided into slots, and the inputs take turns, each sending one unit (a bit, a byte or a block) in its slot; one round of slots is a frame, marked by framing bits. The link rate must be n times an input's rate.
- Synchronous TDM: every input owns a fixed slot in every frame, even when it has nothing to send, so idle slots are wasted. T1 and E1 work this way (the digital hierarchy).
- Statistical (asynchronous) TDM: slots go only to inputs that have data, so a frame has fewer slots than there are inputs and none is wasted; each slot carries the address of its input, and buffers absorb bursts. It suits bursty data.
Four 64 kbps voice inputs are multiplexed by synchronous TDM, one byte per slot, with one framing bit per frame.
- Each input delivers 8,000 bytes a second, so the multiplexer sends 8,000 frames a second, one every 125 µs.
- Frame = 4 × 8 + 1 = 33 bits; link rate = 33 × 8,000 = 264 kbps.
- Each slot lasts 8 / 264,000 s ≈ 30.3 µs. The same sum with 24 inputs gives T1: 193 bits a frame, 1.544 Mbps.
CDM (code division multiplexing), as CDMA, lets every station send at the same time over the whole band. Each multiplies its data by its own chip code; the codes are orthogonal (the inner product of two different codes is zero); and a receiver multiplies the sum on the channel by one station's code to get that station's data back. Used in 3G mobile networks (CDMA2000, W-CDMA) and GPS.
Example: codes a = (+1, +1) and b = (+1, −1). A sends bit 1 as +1, B sends bit 0 as −1, and the channel carries + = . A's receiver computes (0 × 1 + 2 × 1) / 2 = +1, bit 1; B's computes (0 × 1 + 2 × (−1)) / 2 = −1, bit 0.
| Point | FDM | WDM | TDM | CDM |
|---|---|---|---|---|
| Shares | frequency | wavelength | time | codes |
| Signal | analog | optical | digital | digital |
| Kept apart by | guard bands | wavelength spacing | framing and slot position | orthogonal codes |
| Example | FM radio, cable TV | fiber backbones | T1, E1, GSM | 3G CDMA, GPS |
Switching against multiplexing in one line: multiplexing shares one link among many signals; switching chooses the path through the network. The full comparison is on the switching card (switching).
To remember: every FM station in the Kathmandu valley has its own frequency between 88 and 108 MHz, and the radio picks one: that is FDM. A call between two cities rides one 64 kbps time slot of an E1 trunk: that is TDM.
- What is multiplexing? What is its importance in communication? Explain different types of multiplexing techniques. 2080 Baishakh Q2 · 1+2+5
- What is switching and multiplexing? Explain switching technique used in modern computer networks. 2079 Bhadra Q2 · 4+4
- Define switching and multiplexing. Explain about any two guided transmission media in detail. 2074 Ashwin Q2 · 2+6
- What do you mean by switching in communication? Compare switching with multiplexing. Explain the E1 Telephone hierarchy system. 2073 Shrawan Q2 · 2+2+4
- Define switching and multiplexing. Differentiate between circuit switching and packet switching. 2069 Chaitra Q2 · 4+4
- What do you mean by ISDN and what is it contribution in the field of data communication? Explain various types of multiplexing mechanism used in communication. 2067 Ashad Q3 · 3+5
2.4Switching
Switching: circuit, message and packet TOP 13/27
80 Bh · 79 Bh · 75 Ch · 75 Ash · 74 Ch · 74 Ash · 73 Shr · 70 Ch · 69 Ch · 68 Ch · 68 Ba · 67 Asa · 66 Bh2+64+41+2+5
Why switch at all. Linking n devices directly needs a mesh of links: 1,000 telephones would need 499,500 lines. With switching each needs one line to a switch, and the switches are linked to each other.
The three techniques (the book's Figure 2.18): circuit switching, message switching, and packet switching, the last in two forms, datagram and virtual circuit. Inside a switch, circuits are themselves made by space division or time division (switching systems). The same message sent all three ways:
Circuit switching reserves a dedicated path, the circuit, from end to end before any data flows, and holds it for the whole session; on each link the circuit is one channel, a frequency band in FDM or a time slot in TDM. It works in three phases:
- Setup (circuit establishment): a call request travels from switch to switch; each switch reserves a channel on its next link; an acceptance comes back.
- Data transfer: data flows continuously along the reserved path, with no addresses, no store-and-forward and no queuing at the switches.
- Teardown (disconnect): a release signal frees every reserved channel.
Example: a call on the public switched telephone network (PSTN).
Message switching has no setup and no reserved path. The whole message, with the destination address attached, goes to the next node, is stored there (on disk) until the next link is free, then is forwarded: a store-and-forward network. Its drawbacks (the book): every node needs storage for the largest message; the delays add up hop by hop; and it is useless for interactive or real-time traffic. It was used in telegraph and telex networks and has been replaced by packet switching.
Packet switching cuts the message into packets of limited size, each with a header (addresses, a sequence number). Each node stores and forwards packets one at a time; the links are shared by every user, and capacity is used only when there is data (statistical multiplexing). Because packets overlap on successive links, a pipeline, a message crosses many hops far faster than by message switching. It has two forms, datagram and virtual circuit (datagram and virtual circuit). Example: the internet.
A 1 Mbit file crosses 3 links of 1 Mbps each (ignoring propagation, queuing and headers).
- Message switching: each link takes 1 s, and each node waits for the whole message: 3 × 1 = 3 s.
- Packet switching in 1,000 packets of 1 kbit: the last packet leaves the source after 1 s and needs two more hops of 1 ms each: 1 + 2 × 0.001 = 1.002 s.
In general, L bits over N links of rate R take by message switching and by packet switching with packets of P bits.
Circuit switching against packet switching:
| Point | Circuit switching | Packet switching |
|---|---|---|
| Path | a dedicated path for the whole session | no dedicated path; links shared |
| Setup | needed: setup, transfer, teardown | none in the datagram form |
| Bandwidth | fixed and reserved | dynamic, on demand |
| Idle capacity | wasted while the line is silent | used by other users' packets |
| Transfer | a continuous stream; no store-and-forward | store-and-forward at every node |
| Addressing | only during setup | a header on every packet |
| Delay | setup delay, then constant and small | no setup; variable queuing delay (jitter) |
| Order | always in order | may arrive out of order (datagram) |
| Congestion | at setup: the call is blocked (busy tone) | on every packet: queuing and loss |
| A switch fails | the call is cut | packets are rerouted |
| Charging | by time (and distance) | by data volume |
| Suits | real-time, constant-rate voice | bursty data |
| Example | a telephone call (PSTN) | the internet (IP) |
Why circuit switching suits real-time communication:
- Guaranteed bandwidth: the channel is reserved for the whole call, so no other traffic competes with it and no congestion arises once the call is up.
- Constant, low delay with no jitter: no queuing and no store-and-forward at the switches; the voice flows at propagation speed. ITU-T G.114 recommends keeping one-way delay under 150 ms for natural conversation.
- In-order delivery: one fixed path, so nothing arrives out of order and nothing needs reassembling or buffering.
- No per-packet overhead, and no loss from overflowing buffers.
- The only extra wait, the setup, is paid once, before the conversation starts.
Packet networks carry voice (VoIP) only by adding priorities, jitter buffers and spare capacity, to come close to what a circuit gives by design.
Switching against multiplexing:
| Point | Switching | Multiplexing |
|---|---|---|
| Purpose | connects a sender to a receiver across the network | shares one link among many signals |
| Where | at the nodes inside the network | at the two ends of a link |
| Device | switch, router, telephone exchange | multiplexer and demultiplexer |
| Kinds | circuit, message, packet | FDM, WDM, TDM, CDM |
| Example | an exchange connecting a call to Pokhara | an E1 trunk carrying 30 calls at once |
They work together: a circuit-switched call is one time slot of a multiplexed trunk on every link of its path (multiplexing).
Switching in modern computer networks: packet switching everywhere. IP routers switch datagrams by destination address; ISP backbones use MPLS, a virtual circuit technique with short labels; inside a LAN, Ethernet switches forward frames by MAC address, store and forward or cut-through (switches and routers). Circuit switching survives only in the legacy telephone network, and even voice now travels as packets (VoIP, VoLTE on 4G).
To remember: a landline call to your mother in Pokhara holds a path for as long as you talk, silences included: circuit switching. A Viber voice message to her is cut into packets that share every link with everyone else's traffic: packet switching. And on a festival morning when everyone calls home at once, the circuit-switched network answers some callers with a busy tone: no circuit is free.
- a) Discuss about the different factors of choosing the transmission media." Circuit switching is suitable for real-time communication", give your reasons. If a file of 1000 bytes was sent over a network in 2 seconds, calculate throughput. 2080 Bhadra Q2 · 3+3+2
- What is switching and multiplexing? Explain switching technique used in modern computer networks. 2079 Bhadra Q2 · 4+4
- What is switching? What are the various switching techniques? Elaborate packet switching with a proper diagram. 2075 Chaitra Q2 · 1+2+5
- Compare circuit switching and packet switching. Explain ISDN channels with architecture. 2075 Ashwin Q2 · 3+5
- What is the main functionality of data link layer? Differentiate between circuit switching and packet switching. 2074 Chaitra Q3 · 4+4
- Define switching and multiplexing. Explain about any two guided transmission media in detail. 2074 Ashwin Q2 · 2+6
- What are the causes of packet delay in computer networks? What are the differences between circuit switching and packet switching? 2074 Ashwin Q3 · 2+6
- What do you mean by switching in communication? Compare switching with multiplexing. Explain the E1 Telephone hierarchy system. 2073 Shrawan Q2 · 2+2+4
- What do you mean by data switching? Explain about various types of switching with practical implementation example. 2070 Chaitra Q2 · 8
- Define switching and multiplexing. Differentiate between circuit switching and packet switching. 2069 Chaitra Q2 · 4+4
- Differentiate: a) Distance vector and link state routing algorithm b) Circuit switching and packet switching 2068 Chaitra Q5 · 2×5
- What is a switching? Differentiate between packet switching and circuit switching. 2068 Baishakh Q1 · 2+6
- Describe what do you understand by switching along with various types of switching mechanism. Explain the fault tolerance mechanism of FDDI. 2067 Ashad Q4 · 4+4
- Differentiate between circuit switching and packet switching technology. Explain the operation how switched virtual circuit in frame relay network is established, maintained and teardown. 2066 Bhadra Q3b · 2+6
Datagram and virtual circuit: two ways to switch packets HOT 6/27
81 Bh · 78 Bh · 76 Ash · 75 Ch · 70 Asa · 66 Po2+61+2+51+3+4
The datagram approach (the book's Figure 2.21): each packet, a datagram, has a header with the full source and destination address, and a payload. Every router looks up the destination in its routing table and forwards the packet at once; routers keep no record of connections. The packets of one message may take different paths, arrive out of order, be lost or be duplicated, and the destination puts them back in order (TCP, chapter 5). Example: IP in the internet (routing).
The virtual circuit approach (the book's Figures 2.22 and 2.23) is a cross between circuit and datagram switching: it has a circuit's phases and a datagram network's packets.
- Setup: a setup request carrying the full destination address travels to the destination; each switch chooses the next hop and writes an entry in its VC table: incoming port and VCI, outgoing port and VCI. An acknowledgment comes back. Buffers and bandwidth can be reserved now.
- Data transfer: every packet carries only its VCI. A switch looks up (incoming port, incoming VCI), replaces the VCI with the outgoing one (label swapping), and sends the packet out of the outgoing port. All the packets follow one path and arrive in order.
- Teardown: a release request removes the entries from every switch on the path.
A VCI means something on one link only, so it can be small, and each switch may reuse the same values on its other links. In the drawing one circuit is 12 on the first link, then 25, 7 and 31.
| Network | Its VCI is called | Size |
|---|---|---|
| X.25 | logical channel number | 12 bits |
| Frame Relay | DLCI (data link connection identifier) | 10 bits (default) |
| ATM | VPI and VCI | 8 or 12 bits, and 16 bits |
| MPLS | label | 20 bits |
Types of virtual circuit:
- Permanent virtual circuit (PVC): set up in advance by the network operator and left in place, like a leased line; no setup for each session.
- Switched virtual circuit (SVC): set up on demand by signalling at the start of each session and torn down at its end, like a telephone call.
The comparison (the book's Table 2.3, after Tanenbaum):
| Issue | Datagram | Virtual circuit |
|---|---|---|
| Circuit setup | not needed | needed |
| Addressing | each packet carries the full source and destination addresses | each packet carries a short VC number |
| State information | routers hold no state for a connection | each VC needs table space in every switch on its path |
| Routing | each packet routed independently | route chosen at setup; every packet follows it |
| A router fails | no effect, except packets lost in the crash | every VC through that router is terminated |
| Order | may arrive out of order | in order |
| Quality of service | difficult | easy if resources are reserved at setup |
| Congestion control | difficult | easy if resources are reserved at setup |
| Header overhead | large | small |
| Examples | IP | X.25, Frame Relay, ATM, MPLS |
With respect to Frame Relay (2081 Bhadra): Frame Relay is a virtual circuit network. Each frame carries a 10-bit DLCI in its address field, and the switches forward frames by looking up (incoming port, DLCI) and swapping the DLCI, never by a destination address. Its circuits are mostly PVCs set up by the carrier; SVCs are set up by Q.933 signalling. Frames follow their circuit in order; the network only checks the CRC and discards damaged frames, leaving recovery to the end systems; and congestion is signalled with the FECN, BECN and DE bits. A datagram network such as IP over the same links would route every packet by its full address, with no setup and no per-circuit state. Frame Relay itself is chapter 1's (Frame Relay).
"Packet switching against virtual circuit switching" (2078 Bhadra) uses packet switching to mean the datagram approach, so this comparison is the answer. The 2070 Ashad paper prints "virus circuit switching": it means virtual circuit switching.
To remember: datagrams are taxis: every passenger states the full address and each driver picks his own road, so two friends leaving together can arrive in either order. A virtual circuit is a bus route: fixed before the first bus runs, and each bus shows only a short route number that the conductor at every stop understands.
- What are the factors to be considered while selecting media for communication? Differentiate between datagram and virtual circuit switching approach with respect to Frame Relay Network. 2081 Bhadra Q2 · 2+6
- Define Throughput. A network with bandwidth of 20 Mbps can pass only an average of 18,000 frames per minute with each frame carrying an average of 20,000 bits. Calculate the throughput of this network. Differentiate between Packet switching and Virtual Circuit switching. 2078 Bhadra Q2 · 1+3+4
- Write short notes on: (Any two) a) Firewall and their types b) 803 Token Bus c) Virtual circuit switching 2076 Ashwin Q10 · 4+4
- What is switching? What are the various switching techniques? Elaborate packet switching with a proper diagram. 2075 Chaitra Q2 · 1+2+5
- What is virus circuit switching? Describe the operation of Frame-Relay network. 2070 Ashad Q6 · 2+6
- What do you understand by virtual circuit switching? Explain the X.25 virtual circuit switching. 2066 Poush Q6 · 2+6
2.5The telephone network
The telephone network, and the T1 and E1 hierarchy PIN 2/27
73 Shr · 68 Ch2+2+42+6
The telephone set (Alexander Graham Bell's patent, 1876):
| Part | Job |
|---|---|
| Transmitter (microphone) | turns sound into a varying electric current |
| Receiver (earpiece) | turns the current back into sound |
| Hook switch | off-hook closes the loop and asks for service; on-hook ends the call |
| Dialler | sends the number as pulses (rotary) or DTMF tones: each key is two tones, one from a low group (697 to 941 Hz) and one from a high group (1209 to 1477 Hz) |
| Ringer | rings when the exchange sends ringing current |
| Hybrid (induction coil) | joins the two-wire line to the four wires of the handset, keeping a little of the speaker's own voice in the earpiece (sidetone) |
The exchange powers the line with about 48 V DC, which is why a basic telephone works even when the house has no electricity.
The network's three parts (Forouzan):
- Local loop: the twisted pair from each subscriber to the nearest end office (the local exchange), carrying the 300 to 3,400 Hz voice band: the last analog part of the network.
- Switching offices: end offices connect their own subscribers; tandem offices connect the end offices of one area; toll offices carry long-distance calls. The old AT&T hierarchy had five levels: regional centre (class 1), sectional centre (2), primary centre (3), toll centre (4) and end office (5).
- Trunks: high-capacity links between offices, multiplexed: once by FDM, now by digital TDM (E1, T1) over fiber.
Numbering follows the same hierarchy: country code, area (trunk) code, subscriber number. Nepal is +977; Kathmandu's area code is 01 and Pokhara's 061.
How the system works: one call, step by step:
- Off-hook: lifting the handset closes the loop; the end office detects the current.
- Dial tone: the exchange is ready for digits.
- Dialling: the number reaches the exchange as DTMF tones (or pulses) and is stored.
- Switching: for a local number the end office joins the two lines through its own switching network; otherwise it seizes a free trunk towards a tandem or toll office, and signalling between the exchanges (SS7) sets the circuit up hop by hop to the called end office.
- Ringing: if the called line is free its telephone rings and the caller hears ringback; if it is busy, the caller hears busy tone.
- Answer and conversation: when the called party lifts the handset the circuit is complete; the voice is analog on the two local loops and travels as 64 kbps PCM in one time slot on every digital trunk.
- Hang up: going on-hook at either end releases every reserved channel, and the exchange records the call for billing by time and distance.
The digital hierarchy. The trunks are digital. A voice channel of 4 kHz is sampled 8,000 times a second (Nyquist: twice the highest frequency) and each sample is coded in 8 bits: 8,000 × 8 = 64 kbps, the basic channel, DS0 in North America and E0 in the ITU system. Synchronous TDM then stacks these channels into higher levels.
T1 (North America, Japan): 24 channels; a frame is 24 × 8 = 192 bits plus one framing bit, 193 bits, sent 8,000 times a second:
| Service | Line | Rate | Voice channels |
|---|---|---|---|
| DS-1 | T-1 | 1.544 Mbps | 24 |
| DS-2 | T-2 | 6.312 Mbps | 96 |
| DS-3 | T-3 | 44.736 Mbps | 672 |
| DS-4 | T-4 | 274.176 Mbps | 4032 |
E1 (ITU-T: Europe and most of the world, Nepal and India included):
- Frame: 32 time slots, TS0 to TS31, of 8 bits: 256 bits, sent 8,000 times a second, one frame every 125 µs.
- TS0: frame alignment (synchronization), alarms and messages; it carries a fixed pattern in alternate frames.
- TS16: signalling for the channels (call setup and teardown), or data.
- TS1 to TS15 and TS17 to TS31: 30 voice channels of 64 kbps.
| Level | Rate | Voice channels | Made of |
|---|---|---|---|
| E0 | 64 kbps | 1 | one channel |
| E1 | 2.048 Mbps | 30 | 32 time slots |
| E2 | 8.448 Mbps | 120 | 4 × E1 + 256 kbps |
| E3 | 34.368 Mbps | 480 | 4 × E2 + 576 kbps |
| E4 | 139.264 Mbps | 1920 | 4 × E3 + 1.792 Mbps |
Each level adds framing and justification bits (bit stuffing), because the four streams below it run on slightly different clocks: hence the name plesiochronous digital hierarchy (PDH). It was later replaced by SDH, whose first level, STM-1, runs at 155.52 Mbps.
T1 and E1 compared: T1 has 24 channels and borrows signalling bits from the voice samples (robbed-bit signalling); E1 has 30 channels and keeps separate slots for framing (TS0) and signalling (TS16). Both carry ISDN's primary rate interface: 23B + D on T1, 30B + D on E1 (ISDN).
To remember: an E1 trunk between Kathmandu and Pokhara is a train of 32 compartments passing 8,000 times a second: the engine (TS0) and the guard's van (TS16) carry no passengers, and the other 30 compartments are 30 telephone calls.
- What do you mean by switching in communication? Compare switching with multiplexing. Explain the E1 Telephone hierarchy system. 2073 Shrawan Q2 · 2+2+4
- What is a telephone? With a simple diagram of a telephone network explain how the system works. 2068 Chaitra Q3 · 2+6
Telecommunication switching systems: from operators to digital exchanges
The classification (the book's Figure 2.24):
- Manual: operators joined lines with cords and jacks on a switchboard; slow and dependent on the operator, so it was soon replaced.
- Automatic, electromechanical:
- Step-by-step (Strowger), after Almon B. Strowger (1891): the dialled pulses move selector switches one step at a time; control is spread over the switches themselves.
- Crossbar: a grid of horizontal and vertical bars whose crossing points are closed by relays and latches; hard-wired control, so it is very hard to change or extend.
- Automatic, electronic (stored program control, SPC): a computer runs the exchange
from a stored program, so new services are added by changing software (the first, Bell's No.
1 ESS, opened in 1965).
- Space division: a separate physical path through the switch for each call.
- Time division: calls share a common path in turn, as samples at fixed intervals; analog (sampled voltages sent as they are) or digital (binary-coded samples), the digital kind built from space switches, time switches and combinations of the two.
Space division switching. A crossbar with N inputs and N outputs needs crosspoints, of which only N are in use at once: 1,000 lines would need 1,000,000. Multistage switches, several smaller crossbars in stages, need far fewer crosspoints, at the risk of blocking when no path through the stages is free.
Time division switching. A time slot interchange (TSI) writes the slots of an incoming TDM frame into memory in order and reads them out in the order of the outgoing slots, so moving a call from slot 3 to slot 1 is just reading the memory in a different order. A digital exchange connects the 64 kbps time slots of its E1 lines this way; large exchanges combine time and space stages (time-space-time, TST).
The incoming frame carries callers A, B, C and D in slots 1 to 4. The control memory says: output slot 1 takes input slot 3, output 2 takes input 1, output 3 takes input 4, output 4 takes input 2. So the outgoing frame carries C, A, D, B: caller C now reaches whoever owns output slot 1, with no wire moved.
Networking of telephone exchanges. Exchanges are joined by trunks into the hierarchy of local, tandem and toll exchanges drawn on the telephone network card (telephone network). Between exchanges, signalling was first channel associated (CAS: inside the call's own channel or its partner slot, such as E1's TS16) and is now common channel signalling (CCS): a separate signalling network, Signalling System No. 7 (SS7), carries the setup messages for all calls, which makes setup faster and keeps the voice channels free.
To remember: a Strowger exchange can be heard, each dialled digit moving a selector with a clatter; a digital exchange is silent, because its switch is only memory being read in a different order.
2.6ISDN
ISDN: one digital network for voice and data HOT 5/27
76 Ash · 75 Ash · 71 Ch · 67 Asa · 66 Bh2+63+53+3
Why the telephone companies developed ISDN:
- The last analog link: by the 1980s trunks and exchanges were digital (PCM and TDM), but the local loop was still analog, limited to the 300 to 3,400 Hz voice band and to slow modems. ISDN made the loop digital too.
- One network instead of several: voice (the PSTN), telex and data (X.25) needed separate networks and lines; ISDN puts all services on one network, one line, one number and one bill.
- Out-of-band signalling on the D channel gives faster call setup and new services: caller identification, call waiting, several numbers on one line.
- End-to-end digital quality: no noise added at each analog stage.
- Standard interfaces: any vendor's terminal plugs in.
Its contribution to data communication: digital access at 64 or 128 kbps on an ordinary line, when analog modems gave 28.8 to 56 kbps, and 1.5 or 2 Mbps on a PRI; voice and data at the same time on one line; fast dial-up connections for internet access and between offices; backup links for routers (dial on demand); videoconferencing (H.320); PRI trunks for PBXs; and the move to broadband ISDN, which led to ATM. DSL, cable and fiber have since replaced it.
Channels:
| Channel | Rate | Carries |
|---|---|---|
| B (bearer) | 64 kbps | user traffic: digitized voice, data, video; circuit switched end to end |
| D (delta, data) | 16 kbps on a BRI, 64 kbps on a PRI | signalling for the B channels (call setup and release); low-rate packet data when free |
| H (hybrid) | H0 = 384 kbps (6 B); H11 = 1,536 kbps (24 B); H12 = 1,920 kbps (30 B) | wider pipes for video and fast data |
Interfaces (access rates):
- BRI (basic rate interface) = 2B + D: 2 × 64 + 16 = 144 kbps of user channels; with 48 kbps of framing and synchronization bits the S/T interface runs at 192 kbps. For homes and small offices, over one ordinary twisted pair.
- PRI (primary rate interface): 23B + D (D at 64 kbps) = 1.544 Mbps, the T1 rate (North America, Japan); or 30B + D = 2.048 Mbps, the E1 rate (Europe and Asia), with the 30 B channels in TS1 to TS15 and TS17 to TS31, D in TS16 and framing in TS0. For PBXs and ISPs.
The architecture: functional groups and reference points. A functional group is a kind of device; a reference point is the interface between two groups.
| Functional group | What it is | Example |
|---|---|---|
| TE1 (terminal equipment type 1) | a device built for ISDN; connects at S | ISDN telephone, PC with an ISDN card |
| TE2 (terminal equipment type 2) | a non-ISDN device; needs a TA; connects at R | analog telephone, PC with a serial (RS-232) port |
| TA (terminal adapter) | converts TE2's signals to ISDN: R in, S out | an ISDN adapter box |
| NT2 (network termination 2) | customer switching and concentration, layers 2 and 3 | a PBX, a router, a LAN |
| NT1 (network termination 1) | the end of the carrier's line, layer 1 only: turns the four-wire S/T bus into the two-wire local loop, monitors the line and supplies timing | the NT1 box on the wall |
| LT and ET | line termination and exchange termination inside the ISDN exchange | the carrier's switch |
Reference points: R (TE2 to TA), S (TE1 or TA to NT2), T (NT2 to NT1) and U (NT1 to the exchange, over the local loop). They run R, S, T, U in alphabetical order from the old terminal outward to the exchange. With no NT2, S and T merge into one S/T interface, and up to eight terminals can share one BRI's S bus.
The protocol layers of the user-network interface: layer 1 is I.430 (BRI) or I.431 (PRI); layer 2 on the D channel is LAPD (Q.921), an HDLC-type protocol whose address field holds a SAPI and a TEI (terminal endpoint identifier), so several terminals can share the D channel (HDLC); layer 3 is Q.931 call control. The B channels carry whatever the users run.
How it works: a terminal asks for a call with a SETUP message on the D channel; the exchange routes the request through the network with SS7; when the called terminal answers, the network assigns a B channel at each end and joins them; 64 kbps of digital voice or data then flows end to end on the B channel, while the D channel stays free for more signalling (a second call, a packet of data). Release again takes three messages on the D channel.
ISDN signalling is out-of-band, common channel signalling: every call-control message travels on the D channel, never on the B channels.
- User to network (access signalling): Q.931 messages in LAPD frames on the D channel. Setup: SETUP (with the called number and the kind of bearer needed), CALL PROCEEDING, ALERTING (the called telephone rings), CONNECT, CONNECT ACKNOWLEDGE. Release: DISCONNECT, RELEASE, RELEASE COMPLETE.
- Inside the network: Signalling System No. 7 (SS7) between exchanges; its ISDN user part (ISUP) sends IAM (initial address), ACM (address complete), ANM (answer), REL (release) and RLC (release complete).
- User to user: a little signalling can pass between the two terminals through the network.
- Why out-of-band: the B channel is free for data from the first moment to the last; setup is fast; many calls share one signalling channel.
Broadband ISDN: the narrowband ISDN above stops at about 2 Mbps; broadband ISDN (B-ISDN) was defined for 155.52 and 622.08 Mbps over fiber using ATM, which is chapter 1's (ATM).
The receptionist's ISDN telephone (a TE1) and the old fax machine behind a terminal adapter (a TE2 with a TA) share the S bus. She talks on one B channel while the office PC uses the other B channel for a 64 kbps internet session, and the D channel quietly set up both calls. An NT1 on the wall joins the S bus to the single pair of copper from the exchange.
- Why the telephone companies developed ISDN? Explain the working principle of ISDN with its interface and functional group. 2076 Ashwin Q2 · 2+6
- Compare circuit switching and packet switching. Explain ISDN channels with architecture. 2075 Ashwin Q2 · 3+5
- What is ISDN? Explain about the ISDN architecture in detail with example. 2071 Chaitra Q2 · 2+6
- What do you mean by ISDN and what is it contribution in the field of data communication? Explain various types of multiplexing mechanism used in communication. 2067 Ashad Q3 · 3+5
- Write short notes on (any two) i) TCP Sliding Window Protocol ii) Secrete Key Algorithm: DES iii) ISDN Signaling and ATM AAL iv) ICMP Message Types 2066 Bhadra Q5b · 3+3
2.7Last minute recall
Chapter 2 in one screen
- Physical layer: moves raw bits; mechanical, electrical, functional, procedural; functions: physical characteristics, bit representation, data rate, synchronization, line configuration, topology, transmission mode; in TCP/IP it sits inside host-to-network.
- Performance: bandwidth, throughput (data / time, never above bandwidth), latency, jitter; delays: processing, queuing, transmission L/R, propagation d/s; bandwidth-delay product R × dprop.
- Capacity: Nyquist C = 2B log2 L; Shannon C = B log2(1 + SNR); SNRdB = 10 log10(S/N); impairments: attenuation, distortion, noise.
- Media: guided (twisted pair, coaxial, fiber) and unguided (radio 3 kHz to 1 GHz, microwave 1 to 300 GHz, infrared 300 GHz to 400 THz); factors: security, bandwidth, environment, noise, installation, mobility, cost, distance.
- Twisted pair: UTP, STP; Cat 3 to Cat 8; straight, crossover, rollover; 100 m Ethernet. Coaxial: conductor, insulation, braid, jacket; RG-6, RG-58, RG-59.
- Fiber: core, cladding, buffer, jacket; total internal reflection; step index, graded index, single mode; LED or laser, PIN or APD; 850, 1310, 1550 nm (193 to 353 THz).
- Propagation: ground (below 2 MHz), sky (2 to 30 MHz), line of sight (above 30 MHz); radio horizon 4.12 √h km.
- Satellite: transponder: amplify and translate; uplink above downlink; LEO, MEO, GEO at 35,786 km (about 0.24 s a hop); bands L, S, C, X, Ku, K, Ka, V, W.
- Multiplexing: FDM (guard bands), WDM, synchronous TDM (fixed slots), statistical TDM (addressed slots), CDM (orthogonal codes).
- Switching: circuit (setup, transfer, teardown), message (store and forward whole messages), packet (datagram, virtual circuit); circuit against packet in ten rows; circuit suits real time: reserved bandwidth, constant delay, in order.
- Datagram and VC: full address and independent routing against setup, short VCI and one path; PVC and SVC; X.25, Frame Relay (DLCI), ATM (VPI/VCI), MPLS.
- Telephone network: local loop, end office, tandem and toll offices, trunks; call: off-hook, dial tone, dialling, switching, ringing, answer, hang up.
- Digital hierarchy: 64 kbps channel; T1 = 193 bits × 8000 = 1.544 Mbps (24); E1 = 32 × 8 × 8000 = 2.048 Mbps (30; TS0 sync, TS16 signalling); E2 8.448, E3 34.368, E4 139.264 Mbps.
- Exchanges: manual; electromechanical (Strowger, crossbar); electronic SPC (space division, time division, TSI); signalling CAS and CCS (SS7).
- ISDN: B 64, D 16 or 64, H0, H11, H12; BRI 2B + D (144, 192 kbps); PRI 23B + D (1.544) or 30B + D (2.048); TE1, TE2, TA, NT2, NT1; R, S, T, U; Q.931 over LAPD on D, SS7 inside.
Chapter 3 · 5 hours · about 11 marks a paper · in all 27 sittings
Data link layer
The data link layer turns the physical layer's raw bit pipe into a link that carries frames between two neighbouring machines: it marks where each frame starts and ends, catches the bits that noise has flipped, keeps a fast sender from drowning a slow receiver, and on a shared cable or radio channel decides who may send next. It is one of the most examined chapters: framing, CSMA/CD, the functions of the layer, the MAC sublayer and ALOHA come up again and again, and every few papers set a CRC or a bit stuffing calculation.
- The layer itself: its functions, its services to the network layer, its design issues, and the LLC and MAC sublayers.
- Framing: character count, byte stuffing, bit stuffing and coding violations.
- Errors: single bit and burst errors, parity, the checksum, CRC and the Hamming code; detecting an error against correcting it.
- Flow and error control: stop and wait, the sliding window, piggybacking, and the ARQ protocols (stop and wait, go-back-N, selective repeat).
- Link protocols: HDLC and PPP.
- Sharing one channel: the channel allocation problem, ALOHA, CSMA, CSMA/CD, controlled access and channelization.
- The LANs: Ethernet (IEEE 802.3), token bus (802.4), token ring (802.5), FDDI, wireless LAN (802.11) and VLANs.
- Below it, the physical layer of chapter 2 moves raw bits over the media (physical layer, guided media, optical fiber); static channel sharing by FDM and TDM is multiplexing, and the propagation delay that causes collisions is measured in delay.
- Above it, the network layer of chapter 4 hands down IP packets; ARP finds the MAC address a frame needs (ARP), and bridges and switches are data link layer devices (devices, bridges).
- Beside it, the OSI model places the layer (OSI model); TCP runs the same sliding window end to end (TCP flow control); UDP and TCP reuse the checksum (UDP); X.25 and frame relay run HDLC-family links (X.25, frame relay); wireless LAN security is chapter 8's (WEP).
- 3.1 The data link layer: functions, services and design issues
- 3.2 Framing: character count, byte stuffing, bit stuffing
- 3.3 Errors, error detection and correction, parity and checksum
- 3.4 CRC: the cyclic redundancy check
- 3.5 Hamming distance and the Hamming code
- 3.6 Flow control: stop and wait, sliding window, piggybacking
- 3.7 Error control by ARQ: stop and wait, go-back-N, selective repeat
- 3.8 HDLC
- 3.9 PPP
- 3.10 The MAC sublayer and the channel allocation problem
- 3.11 ALOHA: pure and slotted
- 3.12 CSMA and its persistence methods
- 3.13 CSMA/CD
- 3.14 Controlled access: reservation, polling, token passing
- 3.15 Channelization: FDMA, TDMA, CDMA
- 3.16 The IEEE 802 family
- 3.17 Ethernet (IEEE 802.3): frame, addresses, data transfer, cabling
- 3.18 Token bus (IEEE 802.4)
- 3.19 Token ring (IEEE 802.5)
- 3.20 FDDI
- 3.21 Wireless LAN (IEEE 802.11) and CSMA/CA
- 3.22 Virtual LANs and IEEE 802.1Q
- 3.23 Last minute recall, chapter 3
- The bankers: framing (10 of the 27 sittings), CSMA/CD (9), the functions of the layer (8), the MAC sublayer (7) and ALOHA (6).
- The calculations: a CRC by modulo-2 division (three papers), bit stuffing (three papers, each with a different string) and the efficiency of slotted ALOHA; all are worked in the Numericals panel.
- Draw: the CSMA/CD flowchart, the Ethernet, HDLC and token ring frames, the go-back-N and selective repeat timing diagrams, FDDI's wrap and the VLAN design.
3.1Functions of the data link layer
The data link layer: functions, services and design issues HOT 8/27
82 Ba · 75 Ash · 74 Ch · 72 Ka · 71 Shr · 70 Asa · 66 Po · 66 Bh2+3+33+52+2+6
Hop to hop, not end to end. A packet from a laptop in a hostel to a server abroad crosses many links: laptop to the Wi-Fi access point, access point to a switch, switch to the router, router to the ISP, and so on. The network layer chooses the route; the data link layer does the work on each single hop, and on every hop the frame is new: a fresh header with that link's addresses and a fresh check of its bits. It is a relay race: the route is planned once, but every runner carries the baton over one leg only and checks it at the hand-over.
Its functions. Forouzan's five are the ones to write, each tied to a card of this chapter:
- Framing: divides the bit stream into frames and marks where each starts and ends (framing).
- Physical addressing: puts the sender's and the receiver's hardware (MAC) addresses in the header, such as the 48-bit addresses of Ethernet.
- Flow control: stops a fast sender from overrunning a slow receiver (flow control).
- Error control: detects damaged frames with a CRC or checksum in the trailer, and recovers damaged, lost and duplicate frames by retransmission (CRC, ARQ).
- Access control: when several stations share one medium, decides which may transmit now (MAC sublayer).
Two more, from Tanenbaum: it provides a well-defined service interface to the network layer, and it does link management: setting up, maintaining and releasing a connection where the service is connection-oriented.
Services to the network layer. Three kinds, chosen by how reliable the link is:
| Service | How it works | Suits | Example |
|---|---|---|---|
| Unacknowledged connectionless | frames are sent with no connection and no acknowledgement; a lost frame is not recovered at this layer | links with very few errors, and real-time traffic where a late frame is useless anyway | Ethernet |
| Acknowledged connectionless | no connection, but every frame is acknowledged; a frame not acknowledged in time is sent again | unreliable links such as radio | IEEE 802.11 Wi-Fi |
| Acknowledged connection-oriented | a connection is set up, frames are numbered, and each is delivered exactly once and in order; three phases: connection establishment, frame transfer, connection release | long or noisy links where reliability matters, such as WAN serial lines and satellite links | HDLC, LLC type 2 |
Design issues (the question "state the design issues" wants these): what service to give the network layer; framing; error control (detection, ACKs, timers, sequence numbers); flow control; and, on a broadcast link, medium access and addressing. Each is a section of this chapter.
Two sublayers. On LANs, IEEE 802 splits the layer in two, so that one interface to the network layer can sit on top of many kinds of LAN:
| Sublayer | Standard | Functions |
|---|---|---|
| LLC, logical link control (upper) | IEEE 802.2, the same for every LAN | the interface to the network layer; multiplexes several network protocols on one link with service access points (DSAP, SSAP); optional flow and error control; three service types: type 1 unacknowledged connectionless, type 2 connection-oriented, type 3 acknowledged connectionless |
| MAC, medium access control (lower) | one per LAN: 802.3, 802.4, 802.5, 802.11 | builds the frame for its LAN; adds the MAC addresses and the FCS; decides access to the shared medium (CSMA/CD, token passing, CSMA/CA); detects errors |
- What are the functions of data link layer? How to detect signal collision in CSMA/CD? List the ethernet cable specification standards for 802.3 ethernet standards. 2082 Baishakh Q2 · 2+3+3
- State the various design issues for the data link layer. What is piggybacking? A bit string 01111011111101111110 needs to be transmitted at the data link layer. What is the string actually transmitted after bit stuffing? 2075 Ashwin Q3 · 3+3+2
- What is the main functionality of data link layer? Differentiate between circuit switching and packet switching. 2074 Chaitra Q3 · 4+4
- What are the functions of data-link layer? Explain the channel allocation problem with example. 2072 Kartik Q3 · 3+5
- What are the major functions of data link layer? Explain about framing in detail. 2071 Shrawan Q3 · 3+5
- What are the functions of LLC and MAC sub-layer? Discuss different farming approaches used in data link layer. 2070 Ashad Q3 · 2+2+6
- List the functions of Data Link Control Layer. Explain any two sliding window protocols with the advantages of piggybacking. 2066 Poush Q4 · 5+3
- What are the services provided by data link layer? Explain any one methods of framing and flow control. 2066 Bhadra Q2a · 2+3+3
3.2Framing
Framing: character count, byte stuffing and bit stuffing TOP 10/27
81 Bh · 75 Ch · 75 Ash · 72 Ch · 71 Shr · 70 Ch · 70 Asa · 69 Ch · 68 Ba · 66 Bh82+2+62+3+3
Why frames at all. The physical layer delivers bits with no idea where a message begins. If the whole file were one block, one flipped bit would mean sending everything again; in frames of a few hundred bytes, only the damaged frame is resent. A frame has three parts: a header (addresses and control), the payload (the network layer's data) and a trailer (the error check). Fixed-size frames, like ATM's 53-byte cells, need no delimiters at all; variable-size frames need one of the methods below, and real protocols often combine two of them for safety.
1. Character (byte) count. A field in the header gives the number of bytes in the frame; the receiver counts that many and knows where the next frame starts. The flaw: if noise garbles the count, the receiver loses step for good. The CRC tells it the frame is bad, but not where the next frame begins, and the sender cannot tell how much to resend. So a count is never used alone.
2. Flag bytes with byte (character) stuffing. Each frame starts and ends with a
special FLAG byte; a receiver that loses step just searches for the next FLAG. If a FLAG
pattern occurs inside the data, the sender puts an ESC byte in front of it, and an ESC in
the data is sent as ESC ESC; the receiver removes each escape and treats the byte after it as
plain data. PPP uses this, with FLAG 0x7E and ESC 0x7D. Drawbacks:
it is tied to 8-bit bytes, and a frame full of FLAG bytes can double in size.
To remember byte stuffing: it is exactly how a quote is written inside a quoted string
in C: "He said \"namaste\"". The backslash is the ESC, and a real backslash in the
text is written \\, ESC ESC.
3. Flag bits with bit stuffing. Each frame starts and ends with the flag
01111110 (six 1s between two 0s). Whenever the sender's data contains five 1s in a
row, it stuffs a 0 after them, so six 1s never appear inside a frame. The receiver, after
five 1s, looks at the next bit: a 0 is a stuffed bit and is deleted; a 1 followed by 0 is the
flag. It works for any number of bits, not only whole bytes. HDLC uses it, and USB stuffs a bit
after six 1s for the same reason.
Data 01001111110111110 (17 bits). A 0 goes after the first five 1s and after
the second run of five 1s:
data 0100 11111 1 0 11111 0 stuffed 0100 11111 0 1 0 11111 0 0 sent 01111110 0100111110101111100 01111110
Two bits were stuffed, so 19 bits travel between the flags; the receiver deletes the 0 after each run of five 1s and gets the 17 bits back. The three papers' strings are worked in the Numericals panel.
4. Physical layer coding violations. Some line codes have signal patterns that never occur in data. In Manchester coding each bit is a pair of half-bit levels, high-low or low-high; high-high and low-low never carry data, so they can mark a frame's boundary. In 4B/5B coding only 16 of the 32 five-bit code groups carry data; 100BASE-X Ethernet and FDDI start a frame with the spare J and K symbols. It works only where the physical layer has such spare patterns.
| Method | Frame marked by | Weakness | Used in |
|---|---|---|---|
| Character count | a length field in the header | one bad count loses every later boundary | only with another method |
| Byte stuffing | FLAG bytes; ESC before FLAG or ESC in the data | needs 8-bit bytes; frames can grow | PPP |
| Bit stuffing | flag 01111110; a 0 after five 1s | up to one extra bit per five | HDLC, its family |
| Coding violations | signal patterns that data never uses | needs a redundant line code | 100BASE-X, FDDI |
- Write Short notes on: (Any Two) a) 802.4 Token Bus b) Framing with bit stuffing c) Server Socket programming for bind, listen and accept d) ATM 2081 Bhadra Q10 · 2×4
- What are multiple access protocols? Describe the various framing techniques at data link layer. 2075 Chaitra Q3 · 2+6
- State the various design issues for the data link layer. What is piggybacking? A bit string 01111011111101111110 needs to be transmitted at the data link layer. What is the string actually transmitted after bit stuffing? 2075 Ashwin Q3 · 3+3+2
- Briefly explain different types of Data Link Layer framing mechanisms. List the features of FDDI. 2072 Chaitra Q3 · 8
- What are the major functions of data link layer? Explain about framing in detail. 2071 Shrawan Q3 · 3+5
- What is the difference between Error Correcting and Error detection process? A bit string 01111011111011111110 needs to be transmitted at the data link layer what is string actually transmitted after bit stuffing, if flag patterns is 01111110. 2070 Chaitra Q3 · 5+3
- What are the functions of LLC and MAC sub-layer? Discuss different farming approaches used in data link layer. 2070 Ashad Q3 · 2+2+6
- Explain different types of Data link layer framing mechanisms. 2069 Chaitra Q3 · 8
- Compare x.25 and frame relay network. A bit string 0111101111101111110 needs to be transmitted at the data link layer. What is the string actually transmitted after bit stuffing? 2068 Baishakh Q10 · 6+2
- What are the services provided by data link layer? Explain any one methods of framing and flow control. 2066 Bhadra Q2a · 2+3+3
3.3Error detection and correction
Errors, detection against correction, parity and the checksum PIN 1/27
70 Ch5+3
Types of error.
- Single-bit error: only one bit of the frame changes, a 0 to 1 or a 1 to 0. Rare on serial links, because noise usually lasts longer than one bit.
- Burst error: two or more bits change. Its length is counted from the first wrong bit to the last, whether or not the bits between are wrong. A noise burst of 1 ms damages about 10 bits at 10 kbps but about 10,000 bits at 10 Mbps, so bursts are the usual case.
- The book adds: a content error (the bits of the message change) and a flow integrity error (a frame is lost, duplicated or delivered to the wrong destination).
Detection against correction. Detection only asks did an error happen; the frame is then thrown away and sent again (ARQ, also called backward error correction). Correction asks which bits are wrong and fixes them at the receiver (forward error correction, FEC). Correction needs many more redundant bits, so it pays only where a retransmission is slow or impossible.
| Point | Error detection | Error correction |
|---|---|---|
| Goal | find that the frame has an error | find which bits are wrong and fix them |
| Redundancy | small: 1 parity bit, a 16 or 32-bit CRC | large: 3 check bits for 4 data bits in the Hamming (7,4) code |
| After an error | discard; the sender retransmits (ARQ, backward error correction) | the receiver repairs it at once (FEC) |
| Hamming distance | detects errors | corrects errors |
| Suits | wired LANs and links with a return channel and few errors | noisy or long-delay links, or none back: satellite, mobile, Wi-Fi, CDs, QR codes |
| Codes | parity, checksum, CRC | Hamming, Reed-Solomon, convolutional, LDPC |
To remember FEC: the QR code on a shop's payment sticker (Fonepay, eSewa) still scans when a corner is torn or smudged, because QR codes carry Reed-Solomon correction that rebuilds up to 30 percent of the code at the highest level. Nobody can ask the sticker to send itself again.
Simple parity. One parity bit makes the count of 1s even (even parity) or odd (odd
parity). The book's example: the 7 bits 1001101 have four 1s, so even parity adds a
0 and 01001101 is sent. If 00001101 arrives, the count is odd: error
detected. If 00001001 arrives (two bits flipped), the count is even again and the
error is missed. Parity detects every odd number of wrong bits and no even number; it cannot
correct anything.
Two-dimensional parity. The data is written as a table of rows; each row gets a parity bit (VRC) and each column a parity bit (LRC). It detects all 1, 2 and 3-bit errors, misses some 4-bit patterns, and can locate and correct a single wrong bit, which sits where the failing row meets the failing column.
The checksum. Used by the upper layers (IP, UDP and TCP use the 16-bit Internet checksum, UDP). The sender divides the data into segments of bits, adds them in one's complement arithmetic (a carry out of the top is wrapped round and added at the bottom), and sends the complement of the sum as the checksum. The receiver adds all the segments and the checksum; if the complement of that sum is all 0s, the data is accepted.
k = 4, m = 8 10011001 + 11100010 = 1 01111011 wrap: 01111100 + 00100100 = 10100000 + 10000100 = 1 00100100 wrap: 00100101 sum 00100101, checksum = complement = 11011010 receiver: 00100101 + 11011010 = 11111111, complement 00000000: accept
Its weakness: errors that cancel in the sum (one word one higher, another one lower) or two words swapped pass unseen, which is why the link itself uses the stronger CRC.
- What is the difference between Error Correcting and Error detection process? A bit string 01111011111011111110 needs to be transmitted at the data link layer what is string actually transmitted after bit stuffing, if flag patterns is 01111110. 2070 Chaitra Q3 · 5+3
CRC: the cyclic redundancy check PIN 3/27
82 Ba · 81 Bh · 80 Bh1+2+53+5
Bits as polynomials. A string of bits is read as the coefficients of a polynomial:
1101 is . The generator is agreed in advance; a
generator of degree has bits, beginning and ending with 1.
Modulo-2 arithmetic has no carries and no borrows: addition and subtraction are both XOR (). A long division therefore subtracts the generator by XOR wherever the leading bit is 1, and subtracts zeros where it is 0.
At the sender:
- Append zeros to the message , which is .
- Divide it by in modulo 2.
- The remainder , exactly bits (keep leading zeros), is the CRC.
- Send followed by , that is .
At the receiver: divide the received frame by the same . A remainder of zero means accept; anything else means the frame was damaged and is discarded (ARQ then gets it sent again).
Message 1101, generator 1011 (, so
): divide 1101000.
1111 quotient
1011 ) 1101000
1011
----
1100
1011
----
1110
1011
----
1010
1011
----
001 remainder = CRC
Sent: 1101001. At the receiver 1101001 divided by
1011 leaves 000: accepted.
Why it works. is a multiple of by construction (in modulo 2, adding the remainder is the same as subtracting it). If noise adds an error pattern , the receiver's remainder is that of alone, so the error escapes only when happens to divide . A good generator makes that very unlikely. It detects:
- all single-bit errors, when has at least two terms;
- all double-bit errors, when divides no for up to the frame length;
- every odd number of errors, when is a factor of ;
- every burst of length or less, a burst of with probability , and a longer one with probability .
Standard generators: CRC-8 (ATM's header check), CRC-16-CCITT (HDLC, PPP) and CRC-32 (Ethernet and Wi-Fi's 4-byte FCS). In hardware, a CRC is a shift register with an XOR gate for each term of the generator, computed bit by bit as the frame goes out, which is why the book says a CRC can be described by modulo-2 arithmetic, by polynomials or by digital logic.
To remember it: a CRC is like a teacher who checks a long sum by dividing it by 9 and looking at the remainder: if the remainder is not what it should be, something was copied wrong, though the remainder does not say where.
- What is hamming distance? How do you apply it in data link layer error control mechanism? Calculate the CRC for a 8 bit sequence 11001101. The generator polynomial is x⁴ + x² + 1. Also find the transmitted bit frame. 2082 Baishakh Q3 · 1+2+5
- What is piggy-backing? How do you apply it in data link layer flow control mechanism? Calculate the CRC for a 10 bit sequence 1010001101. The generator polynomial is x⁵ + x⁴ + x² + 1. Also find the transmitted bit frame. 2081 Bhadra Q3 · 1+2+5
- Explain how does CRC detect the errors. Given message is M (x) = x7 + x4 +x3 +x2 + 1 and the generator is G (x) = x3 + 1. Show the actual bit string transmitted, suppose the third bit from the left is inverted during the transmission. Show how the error is detected at the receiver's end. 2080 Bhadra Q3 · 3+5
Hamming distance and the Hamming code PIN 1/27
82 Ba1+2+5
Example: 10101 XOR 11110 = 01011, three 1s, so
the distance is 3. To remember it: the names SITA and GITA differ in one letter, distance
1: one wrong letter turns a valid name into another valid name and nobody notices. If every
valid name differed from every other in at least three letters, one wrong letter would leave a
word that is not a name at all, and closest to exactly one real name.
The two rules:
| Code | Detects | Corrects | |
|---|---|---|---|
| Even parity | 2 | 1 error | none |
| Repetition code 000, 111 | 3 | 2 errors | 1 error |
| Hamming (7,4) | 3 | 2 errors (if not correcting) | 1 error |
| Extended Hamming (8,4), SECDED | 4 | 2 errors | 1 error (ECC memory) |
How it is used in error control. The data link layer picks a code whose fits the link. On a link with a return channel it uses a detecting code (CRC) and retransmits (ARQ). On a link where retransmission is costly it uses a correcting code such as the Hamming code (FEC). Either way the receiver's test is the same: a received word that is not a valid codeword shows an error, and correction means replacing it by the nearest valid codeword.
The Hamming code. With data bits it adds parity bits, enough that (4 data bits need 3, giving the (7,4) code). The parity bits sit at the positions that are powers of 2 (1, 2, 4, 8, ...), and each checks every position whose binary number contains its bit:
| Parity bit | Checks positions | The book's rule |
|---|---|---|
| P1 | 1, 3, 5, 7 | check 1, skip 1 |
| P2 | 2, 3, 6, 7 | check 2, skip 2 |
| P4 | 4, 5, 6, 7 | check 4, skip 4 |
The 7-bit word is written D7 D6 D5 P4 D3 P2 P1 (even parity).
Encode the data 1011 (D7 D6 D5 D3 = 1 0 1 1):
P1 = D3 xor D5 xor D7 = 1 xor 1 xor 1 = 1 P2 = D3 xor D6 xor D7 = 1 xor 0 xor 1 = 0 P4 = D5 xor D6 xor D7 = 1 xor 0 xor 1 = 0 codeword D7 D6 D5 P4 D3 P2 P1 = 1 0 1 0 1 0 1
Bit 6 flips on the way, and 1110101 arrives. Recompute each check:
C1 = P1 D3 D5 D7 = 1 1 1 1 even: 0 C2 = P2 D3 D6 D7 = 0 1 1 1 odd: 1 C4 = P4 D5 D6 D7 = 0 1 1 1 odd: 1 syndrome C4 C2 C1 = 110 = 6: bit 6 is wrong
Flip bit 6 back: 1010101, the word that was sent. A syndrome of 000 means no
error.
1110111, finds the
syndrome 100 = 4 and stops at "the 4th bit in the codeword is incorrect". The question asks for
the correct code, which it never writes: flipping bit 4 gives 1111111 (data 1111). Worked
in full in the Numericals panel.- What is hamming distance? How do you apply it in data link layer error control mechanism? Calculate the CRC for a 8 bit sequence 11001101. The generator polynomial is x⁴ + x² + 1. Also find the transmitted bit frame. 2082 Baishakh Q3 · 1+2+5
3.4Flow control and error control
Flow control: stop and wait, the sliding window and piggybacking HOT 5/27
81 Bh · 75 Ash · 74 Ash · 66 Po · 66 Bh4+41+2+52+3+3
Why it is needed. A receiver stores incoming frames in a buffer and must check and hand each one up. If frames arrive faster than that, the buffer fills and frames are dropped, only to be sent again: wasted time. Flow control makes the receiver's pace the limit. Two methods: stop and wait, and the sliding window.
To remember it: a teacher dictating notes. In stop and wait the teacher reads one line and waits until the student says "OK". In the sliding window the teacher reads ahead up to seven lines while the student writes, and the student calls out "done up to line 5" now and then.
1. Stop and wait. The sender sends one frame and waits for its acknowledgement before sending the next. It is simple and never overruns the receiver, but the link sits idle for a whole round trip after every frame. With , the fraction of time the link carries data is:
Example: 1000-bit frames at 1 Mbps ( = 1 ms) over a satellite with = 270 ms give = 270 and , about 0.18 percent: the link idles 99.8 percent of the time.
2. Sliding window. The sender may send up to frames before it needs an acknowledgement. Frames carry -bit sequence numbers, counted modulo (0 to 7 for 3 bits). The send window covers the frames sent but not yet acknowledged plus those that may be sent now; the receive window covers the frames the receiver will accept. An ACK carries the number of the next frame expected and so acknowledges every frame before it; each ACK slides the window right, letting new frames go.
On the same satellite link a window of 7 gives , about 1.3 percent; filling the pipe needs , so 10-bit sequence numbers. TCP grows its window for the same reason (TCP flow control).
3. Piggybacking. When data flows both ways, the receiver does not send a separate ACK frame; it carries the acknowledgement in a field of the header of its own next data frame going back. So every data frame has two numbers: seq, its own sequence number, and ack, the next frame expected from the other side.
- Advantages: fewer frames on the link (no separate ACK frames, their headers and trailers), so better use of the bandwidth; fewer frames to process and fewer interrupts at each end; the window still slides as the piggybacked acks arrive.
- The cost: an ACK may wait for outgoing data. So the receiver starts an ack timer; if no data frame leaves in time, it sends a separate ACK, before the sender's own timer runs out and it resends for nothing.
- Where: HDLC carries the piggybacked ACK in N(R) of every I-frame (HDLC); TCP sets its ACK flag on data segments.
To remember piggybacking: in a phone call, "yes, got it" is said at the start of your own next sentence, not in a separate call.
- What is piggy-backing? How do you apply it in data link layer flow control mechanism? Calculate the CRC for a 10 bit sequence 1010001101. The generator polynomial is x⁵ + x⁴ + x² + 1. Also find the transmitted bit frame. 2081 Bhadra Q3 · 1+2+5
- State the various design issues for the data link layer. What is piggybacking? A bit string 01111011111101111110 needs to be transmitted at the data link layer. What is the string actually transmitted after bit stuffing? 2075 Ashwin Q3 · 3+3+2
- Write short notes on: (any two) i) Flow control in D22 ii) X.25 iii) ALOHA 2075 Ashwin Q10 · 4+4
- Write short notes on: (Any two) a) SMTP and POP b) Diffie Hellman’s Algorithm c) CSMA/CD d) DLL Flow Control Mechanisms 2074 Ashwin Q10 · 4+4
- List the functions of Data Link Control Layer. Explain any two sliding window protocols with the advantages of piggybacking. 2066 Poush Q4 · 5+3
- What are the services provided by data link layer? Explain any one methods of framing and flow control. 2066 Bhadra Q2a · 2+3+3
Error control by ARQ: stop and wait, go-back-N and selective repeat PIN 4/27
82 Bh · 80 Bh · 78 Bh · 66 Po4+42×45+3
The tools every ARQ uses: sequence numbers on frames (to spot gaps and duplicates), ACKs (positive acknowledgements), NAKs (negative ones), a timer per outstanding frame, and a copy of every unacknowledged frame kept by the sender. The three ARQ protocols below are the "ways of backward error correction".
1. Stop and wait ARQ. Stop and wait flow control plus a timer and 1-bit sequence numbers (frames 0, 1, 0, 1, ...). It recovers from three cases (the right half of the figure under flow control):
- Damaged frame: the receiver discards it (or sends a NAK); the sender's timer runs out and it resends.
- Lost frame: nothing comes back; the timer runs out and the frame is resent.
- Lost ACK: the timer runs out and the frame is resent; the receiver sees by its sequence number that it is a duplicate, discards it and sends the ACK again. Without the sequence number it would accept the same frame twice.
2. Go-back-N ARQ. A sliding window protocol. The sender may have up to frames outstanding; the receiver's window is 1, so it accepts frames only in order and discards any frame after a gap. ACKs are cumulative. When frame is lost or damaged (a NAK or a timeout), the sender goes back and resends frame and every frame after it, even those that arrived safely.
3. Selective repeat ARQ. Also a sliding window, but the receiver keeps frames that arrive after a gap in its buffer and asks with a NAK for the missing one only; the sender resends just that frame, and the receiver hands the frames up in order once the gap is filled. Both windows may be at most . The book lists what it costs: the receiver needs sorting logic and a buffer big enough for every frame held after a NAK, and the sender needs to search out the one frame asked for.
| Point | Stop and wait | Go-back-N | Selective repeat |
|---|---|---|---|
| Frames outstanding | 1 | up to | up to |
| Receiver window | 1 | 1 (in order only) | up to |
| On an error resend | that frame | that frame and all after it | that frame only |
| Receiver buffer | one frame | one frame | a window of frames |
| Efficiency | low | good on clean links | best on noisy links |
| Complexity | least | moderate | most (sorting, searching) |
Why the windows are limited. With 3-bit numbers, suppose go-back-N used a window of 8 and every ACK was lost: the sender would resend the old frame 0, and the receiver, now expecting a new frame 0, would accept the old one as new. A window of 7 avoids it; selective repeat must stay at 4 so that the old and new receive windows never overlap.
To remember them: a student misses line 3 of the dictation. Go-back-N is the teacher who re-reads from line 3 to the end; selective repeat is the teacher who re-reads only line 3 while the student leaves a gap for it.
- Write different ways to correct backward error correction. Compare pure Aloha and slotted Aloha mentioning the condition for no collision. 2082 Bhadra Q3 · 4+4
- Write short notes on: (Any Two) a) Go Back-N ARQ b) Dual Stack method in IPv6 c) Diffie-Hellman algorithm d) ATM 2080 Bhadra Q10 · 2×4
- Explain Go-back-N ARQ and selective Repeat ARQ with example. How carrier sense multiple access with collision detection (CSMA/CD) is better than CSMA? 2078 Bhadra Q3 · 4+4
- List the functions of Data Link Control Layer. Explain any two sliding window protocols with the advantages of piggybacking. 2066 Poush Q4 · 5+3
3.5Data link protocols: HDLC and PPP
HDLC: stations, modes, the frame and its three frame types PIN 2/27
78 Bh · 73 Shr2×44×2
01111110 and bit
stuffing, and gives flow and error control with a sliding window and ARQ.
Three kinds of station.
- Primary: controls the link; its frames are commands.
- Secondary: works under a primary; its frames are responses.
- Combined: both at once; it may send commands and responses.
Three configurations. Unbalanced: one primary and one or more secondaries, point to point or multipoint. Balanced: two combined stations, point to point, with equal responsibility. Symmetric (in the book): each physical station is two logical ones, a primary and a secondary.
Three modes of operation.
| Mode | Configuration | Who may send |
|---|---|---|
| NRM, normal response mode | unbalanced | the primary starts every exchange; a secondary sends only when the primary polls it |
| ARM, asynchronous response mode | unbalanced | a secondary may send without permission; the primary still owns the line (start-up, error recovery, disconnection) |
| ABM, asynchronous balanced mode | balanced | either combined station may send at any time; the mode used on point-to-point links today |
The frame fields.
- Flag (8 bits,
01111110): marks both ends; bit stuffing keeps it out of the data. - Address (8 bits, extendable): the secondary station; in a command it is the receiver, in a response the sender.
- Control (8 or 16 bits): says which of the three frame types this is and carries the sequence numbers; 16 bits gives 7-bit numbers (modulo 128) instead of 3-bit (modulo 8).
- Information (variable): the network layer's data, or management information in a U-frame.
- FCS (16 or 32 bits): a CRC over the frame between the flags.
Three frame types.
- I-frame (information): carries user data plus N(S), its own number, and N(R), the next frame expected from the other side: a piggybacked ACK.
- S-frame (supervisory): flow and error control with no data: RR (receive ready, an ACK), RNR (receive not ready, stop), REJ (reject: go back to N(R)) and SREJ (selective reject: resend frame N(R) only).
- U-frame (unnumbered): link management: set a mode (SNRM, SABM), disconnect (DISC), acknowledge (UA), report a bad frame (FRMR).
P/F is the poll bit in a command (a reply is wanted) and the final bit in a response.
Its family: LAPB (the link layer of X.25), LAPD (the ISDN D channel, ISDN), LAPF (frame relay) and PPP's framing all come from HDLC. To remember it: the default encapsulation on a Cisco router's serial port, the kind of leased line that joins a bank's branch to its head office, is HDLC (Cisco's own variant of it).
- Write short notes on: (Any Two) a) Frame relay b) TCP sliding window c) HDLC 2078 Bhadra Q10 · 2×4
- Write short notes on: i) HDLC ii) Web Server 2073 Shrawan Q10 · 4×2
PPP: the Point-to-Point Protocol
Three parts (the book's three features):
- Framing: an unambiguous frame with error detection, using byte stuffing.
- LCP (Link Control Protocol): brings the line up, tests it, negotiates options (maximum frame size, authentication, compression) and takes it down.
- NCPs (Network Control Protocols): one per network protocol; IPCP configures IPv4, for example giving each end its IP address.
The frame. Flag 0x7E; address 0xFF (all stations, since
there are only two); control 0x03 (an unnumbered frame: PPP numbers nothing);
protocol, 2 bytes (1 if LCP agrees to compress it), naming what the payload holds; payload, up to
1500 bytes by default; FCS, 2 bytes (4 if negotiated); closing flag. Inside the frame a
0x7E is sent as 0x7D 0x5E and a 0x7D as
0x7D 0x5D.
The phases of a link: Dead (no carrier) to Establish (LCP agrees the options) to Authenticate (optional: PAP sends a password in clear; CHAP sends a challenge and checks a hashed reply) to Network (NCP, such as IPCP) to Open (data flows) to Terminate (LCP closes the link) and back to Dead. A failed option or login also ends the link.
| Point | HDLC | PPP |
|---|---|---|
| Orientation | bit-oriented, bit stuffing | byte-oriented, byte stuffing |
| Addressing | station address | none (always 0xFF) |
| Flow and error control | sliding window, ACKs, ARQ | none by default: errors are only detected |
| Extras | none | option negotiation, authentication, several network protocols |
SLIP (Serial Line IP, RFC 1055) came first: it only wraps IP packets between END bytes, with no error detection, no address negotiation, no authentication and no protocol field, so PPP replaced it. To remember PPP: a home fibre router that asks for a PPPoE username and password is running PPP over Ethernet (RFC 2516) to log in to the ISP.
3.6The MAC sublayer and the channel allocation problem
The MAC sublayer and the channel allocation problem HOT 7/27
81 Ba · 75 Ch · 73 Shr · 72 Ka · 71 Ch · 68 Ch · 67 Asa2+62+2+42×4
Two kinds of link. A point-to-point link joins exactly two stations, and there is no question of who talks. A broadcast link is shared: every station hears every frame. On a broadcast link the key issue is who gets the channel when several want it, and that is the MAC sublayer's job.
Why channel access control is essential (its significance in the data link layer):
- Collisions: if two stations send at once their signals mix and both frames are lost; the bandwidth used is wasted and both must be resent.
- Efficiency: a good method keeps the channel busy with useful frames, with few collisions and little idle time.
- Fairness: every station gets a chance; no station can hog the channel.
- Delay and priority: some methods (token passing) guarantee a worst-case delay and priorities, which real-time and factory traffic needs.
- Cost: many cheap stations can share one medium instead of each needing its own link.
To remember it: a class discussion without a moderator: everyone talks at once and nothing is heard (collisions); with a rule (raise a hand, pass a microphone) everyone is heard in turn.
The channel allocation problem is how to allocate a single broadcast channel among competing users. There are two families of answers.
Static allocation. The channel is divided in fixed portions: users get of the bandwidth each (FDM) or one time slot in (TDM) (multiplexing). It suits a few users with steady traffic, such as radio and TV broadcasting or telephone trunks, and wastes capacity on bursty data: an idle user's share is lost, and a busy user cannot use the idle shares. The queueing result shows the cost. For a channel of capacity bps, frames of mean length bits arriving at frames per second, the mean delay is:
A 100 Mbps channel, frames of 10,000 bits ( = 10,000 frames/s), 5000 frames/s arriving: = 200 µs. Split statically into 10 channels of 10 Mbps, each with a tenth of the traffic: = 2 ms, ten times worse. Sharing one big channel beats ten small fixed ones.
Dynamic allocation. The channel goes to whoever needs it, when they need it. Tanenbaum's five assumptions behind it: independent stations generating frames at random (the station model); one channel shared by all; collisions are observable; time is continuous or slotted; stations can sense the carrier, or not.
Multiple access protocols are the methods of dynamic sharing, in three classes:
- Random access (contention): no station controls another; each sends when it decides to and collisions are resolved by retrying: ALOHA, CSMA, CSMA/CD, CSMA/CA (wireless LAN).
- Controlled access: stations take turns by agreement, so there are no collisions: reservation, polling, token passing (controlled access).
- Channelization: the channel itself is divided by frequency, time or code: FDMA, TDMA, CDMA (channelization).
- Write short notes on: (Any Two) a) MAC sublayer b) Digital signature c) Firewall 2081 Baishakh Q10 · 2×4
- What are multiple access protocols? Describe the various framing techniques at data link layer. 2075 Chaitra Q3 · 2+6
- What do you understand by Media Access Control? What is its significance in data link layer? Explain why token bus is also called as the token ring. 2073 Shrawan Q3 · 2+2+4
- What are the functions of data-link layer? Explain the channel allocation problem with example. 2072 Kartik Q3 · 3+5
- What are multiple access protocols? Explain how multiple access is achieved in IEEE 802.5. 2071 Chaitra Q3 · 2+6
- Why channel access mechanism is important in computer networking? Explain the operation of IEEE 802.5 with its frame format. 2068 Chaitra Q4 · 3+7
- Why access control of channel is essential? Compare operating details of IEEE 802.4 and IEEE 802.5. 2067 Ashad Q5 · 2+6
3.7Multiple access protocols
ALOHA: pure and slotted HOT 6/27
82 Bh · 79 Bh · 75 Ash · 70 Asa · 68 Ba · 66 Po4+42×4
Pure ALOHA. The original. A station sends a frame the moment it has one, then waits for an acknowledgement (the timeout is about twice the longest propagation delay). If none comes, it assumes a collision, waits a random backoff time (Forouzan: a random from 0 to frame or propagation times after the th attempt, giving up after about 15) and sends again. The wait must be random, or the same two frames would collide forever.
Vulnerable time. Let be the time to send one frame. A frame sent at survives only if no other frame starts in : one starting earlier overlaps its head, one starting later overlaps its tail. So pure ALOHA's vulnerable time is 2T. Even if the first bit of a new frame overlaps only the last bit of another, both are destroyed.
Slotted ALOHA (Roberts, 1972). Time is cut into slots of length , and a station may start only at the beginning of a slot; one that misses the start waits for the next. Now a frame collides only with another sent in the same slot: the vulnerable time halves to T. It needs every station's clock synchronised to the slots.
Throughput. Let be the offered load (frames tried per frame time, new and retried, Poisson-distributed) and the throughput (frames that succeed per frame time). The probability that no other frame starts in an interval of frame times is , so:
| Point | Pure ALOHA | Slotted ALOHA |
|---|---|---|
| When a station sends | at any time | only at the start of a slot |
| Time | continuous, no clock needed | slotted, stations synchronised |
| Vulnerable time | ||
| Condition for no collision | no other frame starts within before or after the frame's start | no other station sends in the same slot |
| Probability a frame succeeds | ||
| Throughput | ||
| Maximum | 18.4 % at | 36.8 % at |
A 200 kbps channel carries 200-bit frames, so = 1 ms. Pure ALOHA: if the stations offer 1000 frames/s, and = 0.135: about 135 frames/s get through. At 500 frames/s, , = 0.184: about 92. At 250 frames/s, , = 0.152: about 38. Slotted ALOHA at 1000 frames/s: = 0.368, about 368 frames/s, more than double.
To remember it: students shouting answers whenever they like is pure ALOHA; shouting only right after the teacher's bell is slotted ALOHA. Fewer answers overlap, but even at its best a third of the bells hear silence and a quarter hear a clash.
- Write different ways to correct backward error correction. Compare pure Aloha and slotted Aloha mentioning the condition for no collision. 2082 Bhadra Q3 · 4+4
- Write short notes on: (Any Two) a) ALOHA b) OSPF c) VPN 2079 Bhadra Q10 · 2×4
- Write short notes on: (any two) i) Flow control in D22 ii) X.25 iii) ALOHA 2075 Ashwin Q10 · 4+4
- Write short notes on: a) ALOHA system b) TCP header 2070 Ashad Q10 · 4+4
- What are types of twisted pair cable? Calculate the efficiency of slotted Aloha. 2068 Baishakh Q2 · 4+4
- Explain the operation of pure ALOHA system. How CSMA/CD works? 2066 Poush Q3 · 4+4
CSMA: listen before talking PIN 1/27
70 Asa2+2+4
Why it beats ALOHA. ALOHA sends blindly; CSMA never starts while another transmission is under way, so it avoids most collisions, and at light load its throughput comes close to 1.
Why collisions still happen: propagation delay. Station A starts sending; its signal takes time to reach station B. If B senses the medium inside that time it hears nothing, decides the medium is idle, and also sends: collision. So CSMA's vulnerable time is the propagation time , much shorter than ALOHA's, but not zero.
What a station does when the medium is busy is its persistence method:
| Method | Medium idle | Medium busy | Result |
|---|---|---|---|
| 1-persistent | sends at once (with probability 1) | keeps sensing, sends the moment it goes idle | no idle time, but stations waiting for the same busy period all start together and collide; used by Ethernet |
| Non-persistent | sends at once | waits a random time, then senses again | fewer collisions, but the medium may lie idle while all are waiting |
| p-persistent | (slotted channel) sends with probability ; with waits for the next slot and repeats | waits until idle, then as for idle | a balance of the two, set by |
To remember them: in a group call, the 1-persistent friend starts talking the instant there is silence (and clashes with the other eager one); the non-persistent friend gives up for a while and checks again later; the p-persistent friend, at each pause, tosses a coin before speaking.
Its limit. When two stations do collide, plain CSMA does not notice: both keep sending their whole frames, so the channel is wasted for a full frame time. Adding collision detection fixes that: CSMA/CD, which also compares the two.
- Discuss how CSMA works? Differentiate it with CSMA-CD. Explain the optical fiber cabling standards with examples. 2070 Ashad Q5 · 2+2+4
CSMA/CD: carrier sense with collision detection TOP 9/27
82 Ba · 81 Ba · 79 Bh · 78 Bh · 76 Ch · 76 Ash · 74 Ash · 70 Asa · 66 Po4+42+2+41+1+6
Collision is the event it handles: two or more frames on a shared medium at overlapping times, so their signals add and both frames are garbled. It occurs when stations transmit at almost the same moment: each sensed the medium idle because the other's signal had not yet reached it (propagation delay), or both were waiting for the same busy period to end and started together the moment it did.
How it works, step by step:
- Sense: the station listens to the medium; while it is busy it keeps listening (1-persistent).
- Transmit: once the medium is idle (and the 96-bit interframe gap has passed) it sends, and keeps monitoring the medium while it sends.
- Success: if the whole frame goes out with no collision, the frame is done.
- Collision: if it detects one, it aborts the frame at once and sends a 32-bit jam signal, so that every station, including the other sender, knows of it.
- Count: it adds 1 to its attempt counter ; after 16 attempts it gives up and reports an error.
- Back off: it picks at random from 0 to , with , waits slot times of 512 bit times, and starts again at step 1.
How a collision is detected. The station compares what it sends with what it hears on the medium. On coaxial cable the transceiver sees a signal level (voltage, energy) higher than its own transmission could make; on twisted pair (10BASE-T) it sees activity on its receive pair while it is transmitting. Detection must happen while the station is still sending, or it would never connect the collision with its frame. So a frame must last at least one round trip:
For 10 Mbps Ethernet the round-trip budget (2500 m with four repeaters) is 51.2 µs, so = 512 bits = 64 bytes, the minimum Ethernet frame, and 512 bit times is the slot time of the backoff.
Binary exponential backoff. After the 1st collision is 0 or 1; after the 2nd, 0 to 3; after the 3rd, 0 to 7; from the 10th on, 0 to 1023. Doubling the range after each collision spreads the retries out exactly when many stations are competing, and keeps waits short when few are.
Why CSMA/CD is better than CSMA.
| Point | CSMA | CSMA/CD |
|---|---|---|
| Listens | before sending only | before and while sending |
| On a collision | keeps sending the whole damaged frame | stops at once and sends a short jam |
| Time wasted per collision | a whole frame time | at most about plus the jam |
| Retry | by the persistence method | binary exponential backoff, at most 16 attempts |
| Needs | carrier sensing | also the ability to hear while sending, and a minimum frame size |
| Throughput | lower | higher; less delay |
Today. On a switch, every port is a separate full-duplex link with only two stations, so there are no collisions and CSMA/CD is switched off. It runs only in half duplex (hubs), and Ethernet from 10 Gbps up dropped half duplex altogether.
To remember it: a polite argument. Speak only when the room is quiet; keep listening as you speak; if someone else starts too, both stop and say "sorry" (the jam); each then waits a random moment before trying again, and waits longer each time it clashes.
- What are the functions of data link layer? How to detect signal collision in CSMA/CD? List the ethernet cable specification standards for 802.3 ethernet standards. 2082 Baishakh Q2 · 2+3+3
- What is CSMA/CD? Why is it not applicable in wireless LAN? What are the techniques used to avoid the possible collisions in WLAN? Explain. 2081 Baishakh Q3 · 2+2+4
- How CSMA/CD works? Describe Ethernet (IEEE 802.3) frame structure with function of each field. 2079 Bhadra Q3 · 4+4
- Explain Go-back-N ARQ and selective Repeat ARQ with example. How carrier sense multiple access with collision detection (CSMA/CD) is better than CSMA? 2078 Bhadra Q3 · 4+4
- What is collision? How is it occured? How the possibility of collision is reduced in IEEE 802.3 and IEEE 802.11? Explain. 2076 Chaitra Q3 · 1+1+6
- Explain the working principle of CSMA/CD with appropriate figure. 2076 Ashwin Q3 · 8
- Write short notes on: (Any two) a) SMTP and POP b) Diffie Hellman’s Algorithm c) CSMA/CD d) DLL Flow Control Mechanisms 2074 Ashwin Q10 · 4+4
- Discuss how CSMA works? Differentiate it with CSMA-CD. Explain the optical fiber cabling standards with examples. 2070 Ashad Q5 · 2+2+4
- Explain the operation of pure ALOHA system. How CSMA/CD works? 2066 Poush Q3 · 4+4
Controlled access: reservation, polling and token passing
- Reservation: time is divided into intervals, and each interval begins with a reservation frame of mini-slots, one per station. A station with data sets its own mini-slot; the stations that reserved then send their data frames in order. Example: booking a slot at a futsal ground in advance.
- Polling: one primary station controls the link and every exchange goes through it. With poll it asks each secondary in turn "anything to send?"; with select it asks a secondary "ready to receive?" and waits for its ACK before sending. Weaknesses: polling overhead, and the whole link stops if the primary fails. Examples: HDLC's normal response mode, the master of a Bluetooth piconet, a teacher taking roll call.
- Token passing: a special frame, the token, circulates round a logical ring; only the station holding it may send, for a limited time, after which it passes the token on. It needs token management: a limit on holding time, priorities, and a way to recover a lost or duplicated token. The ring may be physical (token ring), a dual ring (FDDI) or a bus (token bus). Example: the talking stick passed round a circle.
| Point | Random access | Controlled access |
|---|---|---|
| Collisions | possible | none |
| Delay at light load | very low | must wait for a turn |
| Behaviour at heavy load | throughput falls, delay unpredictable | fair; delay bounded and predictable |
| Weak point | contention | overhead; a failed primary or a lost token |
Channelization: FDMA, TDMA and CDMA
- FDMA (frequency division): each station gets its own frequency band, with guard bands between them, and may use it all the time. First-generation analog mobile phones used it. FDM is the same idea done by one multiplexer at the physical layer (multiplexing); FDMA is an access method shared by many stations.
- TDMA (time division): all stations use the same band, each in its own time slot, with guard times and tight synchronisation. GSM, the 2G network of NTC and Ncell, uses both: each 200 kHz carrier (FDMA) is shared by 8 time slots (TDMA).
- CDMA (code division): all stations send at the same time on the same band; each multiplies its data by its own chip sequence. The sequences are orthogonal (the inner product of two different ones is 0, of one with itself is the number of chips), so the receiver recovers one station's bit by multiplying the combined signal by that station's code. 3G networks used it.
Codes (Walsh): , , , . A bit 1 is sent as +1, a 0 as -1, and silence as 0. Station 1 sends 1 and station 2 sends 0; 3 and 4 are silent. The channel carries the sum = .
Receiver for station 1: , a 1. For station 2: , a 0. For station 3: , silent.
To remember them: at a wedding party, FDMA is couples talking in separate rooms, TDMA is everyone taking turns at one microphone, and CDMA is pairs talking at the same time in one hall, one in Nepali, one in Newari, one in Maithili, one in English: each listener follows only their own language and hears the rest as noise.
3.8Ethernet and the IEEE 802 family
The IEEE 802 family of LAN standards
| Standard | What it covers | Status |
|---|---|---|
| 802.1 | above all LANs: bridging and the spanning tree (802.1D), VLAN tagging (802.1Q), port authentication (802.1X), management | active |
| 802.2 | logical link control, the interface to the network layer | stable |
| 802.3 | Ethernet: CSMA/CD on a bus, now switched, 10 Mbps to 400 Gbps | dominant wired LAN |
| 802.4 | token bus: a token on a logical ring over a bus | withdrawn |
| 802.5 | token ring: a token on a physical ring | withdrawn |
| 802.11 | wireless LAN (Wi-Fi), CSMA/CA | dominant wireless LAN |
| 802.15 | personal area networks: Bluetooth (802.15.1), low-rate sensor networks (802.15.4, under Zigbee) | active |
| 802.16 | broadband wireless access (WiMAX) | little used now |
Why the split. The network layer sees the same LLC interface whatever the LAN, so IP runs unchanged over Ethernet, Wi-Fi or token ring; each LAN keeps the access method that suits its medium. To remember it: a laptop in a college lab uses three of them at once: its Ethernet port speaks 802.3, its Wi-Fi card 802.11, and the lab switch keeps students and staff apart with 802.1Q VLANs.
Ethernet (IEEE 802.3): the frame, MAC addresses, data transfer and cabling PIN 4/27
82 Ba · 79 Bh · 70 Asa · 66 Bh2+2+42+3+34+4
History. Invented at Xerox PARC by Robert Metcalfe and David Boggs in 1973, running at about 3 Mbps; DEC, Intel and Xerox then made it 10 Mbps (Ethernet II), and IEEE standardised it as 802.3 in 1983. Generations: Standard Ethernet (10 Mbps), Fast Ethernet (100 Mbps, 802.3u, 1995), Gigabit Ethernet (1 Gbps, 802.3z and 802.3ab), 10 Gigabit Ethernet (802.3ae, 2002), and since then 40, 100 and 400 Gbps.
The frame and each field.
| Field | Bytes | Function |
|---|---|---|
| Preamble | 7 | 10101010 seven times: wakes the receiver
and lets its clock lock on to the bit timing |
| SFD, start frame delimiter | 1 | 10101011: the last two
1s say the frame starts now |
| Destination address | 6 | the receiver's MAC address: unicast, multicast or broadcast; it comes first so each station can decide early whether the frame is for it |
| Source address | 6 | the sender's MAC address, always unicast |
| Length/Type | 2 | a value up to 1500 is the length of the data (IEEE
802.3, an LLC header follows); 1536 (0x0600) or more is the EtherType naming the
payload's protocol: 0x0800 IPv4, 0x0806 ARP, 0x86DD
IPv6 |
| Data and pad | 46 to 1500 | the network layer's packet; padded up to 46 bytes if shorter |
| FCS | 4 | CRC-32 over the addresses, length/type and data; a bad frame is dropped |
From destination address to FCS a frame is 64 to 1518 bytes (1522 with an 802.1Q tag): the 64-byte minimum is what lets CSMA/CD detect a collision while the frame is still being sent. Frames are separated by an interframe gap of 96 bit times.
The MAC address. 48 bits, written as six hexadecimal bytes. The first 24 bits are
the OUI, the number the IEEE gives the maker; the last 24 are the maker's own serial for
that interface. The lowest bit of the first byte (I/G) is 0 for a unicast address and 1 for a
multicast; the next bit (U/L) marks a globally assigned or a locally set address; all 48 bits 1
(FF:FF:FF:FF:FF:FF) is the broadcast address. To remember it: run
ipconfig /all on a Windows laptop: the "Physical Address" line is its Wi-Fi or
Ethernet card's MAC address. Examples in this reader use 00:00:5E:00:53:01, from the
block kept for documentation (RFC 7042).
How data is transferred in an Ethernet:
- Address: the sender knows the receiver's IP address; ARP finds its MAC address (ARP).
- Encapsulate: the NIC builds the frame (destination and source MAC, type, data, pad) and computes the CRC-32 FCS.
- Access the medium: on a shared segment (half duplex, a hub) it uses 1-persistent CSMA/CD; on a switch port in full duplex it simply sends.
- Signal: the physical layer sends the preamble and SFD for synchronisation, then the frame, line-coded (Manchester at 10 Mbps).
- Deliver: on a shared bus every station hears the frame; a switch instead looks up the destination in its MAC address table (learned from source addresses) and forwards the frame only to that port, or floods it if unknown (switches).
- Receive: each NIC keeps the frame only if the destination is its own address, the broadcast or a multicast group it has joined; it checks the FCS, drops bad frames and frames under 64 or over 1518 bytes, and hands the data up by its type.
Ethernet is connectionless and unacknowledged at this layer: a dropped frame is recovered, if at all, by TCP above.
Cabling standards. The name says the speed in Mbps, the signalling (Base = baseband) and the medium or the segment length in hundreds of metres: 10Base5 runs 10 Mbps baseband over 500 m.
| Standard | Medium | Max segment | Notes |
|---|---|---|---|
| 10Base5 (thick Ethernet) | thick coaxial cable | 500 m | bus, 1983 |
| 10Base2 (thin Ethernet) | thin coaxial, BNC T-connectors | 185 m | bus |
| 10BaseT | 2 pairs of UTP (Cat 3 or better) | 100 m | star, hub |
| 10BaseF (10Base-FL) | multimode fiber pair | 2000 m | star |
| 100BaseTX | 2 pairs of Cat 5 UTP | 100 m | Fast Ethernet, 4B/5B |
| 100BaseFX | multimode fiber pair | 2000 m (full duplex) | Fast Ethernet |
| 1000BaseT | 4 pairs of Cat 5e UTP | 100 m | Gigabit, 802.3ab |
| 1000BaseSX | multimode fiber, 850 nm short-wave laser | 220 to 550 m | Gigabit, 802.3z |
| 1000BaseLX | 1310 nm long-wave laser: multimode or single-mode | 550 m or 5 km | Gigabit, 802.3z |
| 10GBase-SR, LR, ER | fiber: 850 nm multimode; 1310 and 1550 nm single-mode | up to 300 m, 10 km, 40 km | 10 Gigabit, 802.3ae |
Optical fiber standards, with examples. Fiber is used where copper's 100 m runs out or where electrical noise and lightning matter: between buildings and up risers. Short-wave (850 nm) lasers on multimode fiber are cheap and reach hundreds of metres: 1000BaseSX joins two floors of a block or two blocks of a campus close together. Long-wave (1310 nm) on single-mode fiber reaches kilometres: 1000BaseLX or 10GBase-LR joins a campus's distant buildings, such as a library 2 km from the main data centre. 100BaseFX and 10BaseF are the older 100 and 10 Mbps versions of the same idea.
- What are the functions of data link layer? How to detect signal collision in CSMA/CD? List the ethernet cable specification standards for 802.3 ethernet standards. 2082 Baishakh Q2 · 2+3+3
- How CSMA/CD works? Describe Ethernet (IEEE 802.3) frame structure with function of each field. 2079 Bhadra Q3 · 4+4
- How data transfer occurs in Ethernet network? Explain. 2070 Ashad Q4 · 6
- Discuss how CSMA works? Differentiate it with CSMA-CD. Explain the optical fiber cabling standards with examples. 2070 Ashad Q5 · 2+2+4
- Describe the 802.3 Ethernet standard for CSMA/CD and compare it with 802.4 token bus technology. Explain how DSSS technique is applied in wireless transmission. 2066 Bhadra Q3a · 5+3
3.9Token bus, token ring and FDDI
Token bus (IEEE 802.4): a physical bus, a logical ring HOT 5/27
81 Bh · 76 Ash · 73 Shr · 67 Asa · 66 Bh2+2+42+62×4
Why token bus is also called a token ring. Physically it is a bus: every frame on the cable reaches every station at once. But access follows a ring. Each station knows the address of the station before it (its predecessor) and after it (its successor); the token goes in descending order of address, and the station with the lowest address passes it back to the highest, closing the circle. The ring exists only in the stations' tables, not in the wiring, so it is a logical ring: in the figure, 112 to 90 to 70 to 45 to 20 and back to 112, whatever their places on the cable.
Operation.
- Sending: a station that receives the token may send frames until its token holding time runs out, then sends the token to its successor.
- Priorities: four access classes, 0, 2, 4 and 6 (highest), each with its own timer, so urgent traffic goes first.
- Ring maintenance by special frames: claim token to start the ring or replace a lost token; solicit successor to let new stations join; who follows and set successor to close the gap when a station leaves or fails.
- Physical layer: 75-ohm broadband coaxial cable (the cable TV kind) at 1, 5 or 10 Mbps.
- Frame: preamble, start delimiter, frame control, destination and source addresses (2 or 6 bytes each), data up to 8182 bytes, a 4-byte FCS and an end delimiter.
Where it was used: factory automation (General Motors' MAP), where a guaranteed worst-case delay matters more than average speed: a robot arm must get its command within a known time, which Ethernet's random backoff cannot promise.
| Point | 802.3 Ethernet | 802.4 Token bus | 802.5 Token ring |
|---|---|---|---|
| Topology | bus, now a star on a switch | physical bus, logical ring | physical ring (star-wired) |
| Access | CSMA/CD, contention | token passed by address | token passed to the next station downstream |
| Collisions | yes | none | none |
| Worst-case delay | unbounded (random backoff) | bounded | bounded |
| Priorities | none in the MAC | 4 classes: 0, 2, 4, 6 | 8 levels (3 bits) with reservation |
| Medium and speed | coax, UTP, fiber; 10 Mbps up | broadband coax; 1, 5, 10 Mbps | shielded twisted pair; 4, 16 Mbps |
| Frame removed by | nobody (it ends on the bus) | nobody (it ends on the bus) | the sender, when it comes round |
| Ring upkeep | none needed | distributed (claim token, solicit successor) | an active monitor station |
| Light load | very short delay | waits for the token | waits for the token |
To remember it: pass the parcel at a birthday party, but the parcel goes by roll number, not to whoever sits next to you: the children are scattered round the room (the bus), yet the parcel still travels in a fixed circle (the logical ring).
- Write Short notes on: (Any Two) a) 802.4 Token Bus b) Framing with bit stuffing c) Server Socket programming for bind, listen and accept d) ATM 2081 Bhadra Q10 · 2×4
- Write short notes on: (Any two) a) Firewall and their types b) 803 Token Bus c) Virtual circuit switching 2076 Ashwin Q10 · 4+4
- What do you understand by Media Access Control? What is its significance in data link layer? Explain why token bus is also called as the token ring. 2073 Shrawan Q3 · 2+2+4
- Why access control of channel is essential? Compare operating details of IEEE 802.4 and IEEE 802.5. 2067 Ashad Q5 · 2+6
- Describe the 802.3 Ethernet standard for CSMA/CD and compare it with 802.4 token bus technology. Explain how DSSS technique is applied in wireless transmission. 2066 Bhadra Q3a · 5+3
Token ring (IEEE 802.5): operation and frame format PIN 4/27
82 Ba · 71 Ch · 68 Ch · 67 Asa2+62×43+7
How multiple access is achieved. The token is the permission to send, and there is only one, so only one station transmits at a time and frames never collide.
- Wait: a station with data waits for the free token: start delimiter, access control and end delimiter.
- Seize: it sets the token bit (T) in the access control byte to 1, which turns the token into the start of a frame, and appends the rest of its frame.
- Circulate: each station repeats the bits on to the next (a one-bit delay each). The destination copies the frame as it passes and sets the A (address recognised) and C (frame copied) bits in the frame status byte.
- Remove: when the frame comes back to the sender, the sender strips it off the ring and reads A and C: 1 and 1 means delivered; 1 and 0, the station was there but did not copy it; 0, no such station.
- Release: the sender issues a new free token. It may hold the token for at most the token holding time, 10 ms by default; at 16 Mbps it may release the token right after its frame (early token release).
Frame format.
| Field | Bytes | Function |
|---|---|---|
| SD, start delimiter | 1 | announces a token or frame; uses deliberate coding violations, so it cannot occur in data |
| AC, access control | 1 | PPPTMRRR: 3 priority bits, the
token bit (0 token, 1 frame), the monitor bit, 3 reservation bits |
| FC, frame control | 1 | data frame or ring management frame |
| DA, SA | 2 or 6 each | destination and source addresses |
| Data | no fixed limit | limited only by the token holding time |
| FCS | 4 | CRC-32 for error detection |
| ED, end delimiter | 1 | ends the token or frame; also flags an error spotted on the way |
| FS, frame status | 1 | the A and C bits, written twice because the FCS does not cover this byte |
Priority and reservation. A station waiting with an urgent frame writes its priority into the reservation bits of a frame passing by; when the token is next released it carries that priority, and only stations with frames of that priority or higher may seize it. The station that raised the priority lowers it again afterwards.
The active monitor. One station is elected to keep the ring healthy: it issues a new token when none has been seen for too long (a lost token); it removes an orphan frame whose sender has died, which it recognises by the monitor bit it set when the frame first passed; and it adds delay so that the ring is always long enough to hold the 24-bit token.
Physical layer. 4 or 16 Mbps over shielded twisted pair, with differential Manchester coding. The ring is wired as a star: each station is cabled to a wiring centre (MAU) whose relay bypasses a station that is switched off, so one dead station does not break the ring.
To remember it: the talking stick at a circle meeting. Only the one holding the stick speaks; the stick goes round to the next person; a person's message goes all the way round so the speaker hears it come back and knows everyone heard it.
- Write Short Notes on: (Any Two) a) 802.5 Token Ring b) PGP c) Socket programming fundamentals d) X.25 Network 2082 Baishakh Q10 · 2×4
- What are multiple access protocols? Explain how multiple access is achieved in IEEE 802.5. 2071 Chaitra Q3 · 2+6
- Why channel access mechanism is important in computer networking? Explain the operation of IEEE 802.5 with its frame format. 2068 Chaitra Q4 · 3+7
- Why access control of channel is essential? Compare operating details of IEEE 802.4 and IEEE 802.5. 2067 Ashad Q5 · 2+6
FDDI: dual counter-rotating rings and fault tolerance PIN 3/27
74 Ch · 72 Ch · 67 Asa4+48
Features (the list to write):
- 100 Mbps over multimode fiber, later also over copper (CDDI); 4B/5B coding, so the line runs at 125 Mbaud.
- Dual counter-rotating rings: traffic on the two rings flows in opposite directions; the secondary ring is idle until a fault.
- Large: up to 1000 physical connections (about 500 dual attachment stations) on up to 200 km of fiber, with stations up to 2 km apart: a campus or city backbone.
- Timed token protocol: a target token rotation time is agreed when the ring starts, which gives synchronous traffic a guaranteed share and lets asynchronous traffic use what is left; the token is released right after a frame (early release).
- Frames of up to 4500 bytes, protected by a CRC-32.
- Station types: a dual attachment station (DAS) joins both rings; a single attachment station (SAS), such as a PC, joins the primary ring through a concentrator, which routers and servers usually are not.
- Fault tolerance by wrapping, optical bypass and dual homing, below.
The fault tolerance mechanism.
- A cable cut: the two stations on either side of the break detect the loss of signal and wrap: each joins the primary ring to the secondary inside itself. The dual ring becomes one ring of twice the length, and every station is still reached (the right half of the figure).
- A failed station: its two neighbours wrap in the same way, cutting it out; or an optical bypass switch passes the light straight through a station that is switched off, so the rings do not need to wrap at all.
- A failed single attachment station: the concentrator it hangs from simply cuts it off, and the ring never notices.
- Dual homing: a critical server or router is connected to two concentrators; if the main connection fails, the backup takes over.
Its limit: two faults at once split the network into two separate rings that cannot reach each other.
To remember it: Kathmandu's Ring Road has lanes running both ways round the valley; if one stretch is blocked, traffic turns back before the block and goes round the other way, and every chowk on the road can still be reached.
- Write short notes on: (any two) i) Types of firewals ii) FDDI iii) Socket programming 2074 Chaitra Q10 · 4+4
- Briefly explain different types of Data Link Layer framing mechanisms. List the features of FDDI. 2072 Chaitra Q3 · 8
- Describe what do you understand by switching along with various types of switching mechanism. Explain the fault tolerance mechanism of FDDI. 2067 Ashad Q4 · 4+4
3.10Wireless LAN (IEEE 802.11)
Wireless LAN (IEEE 802.11): architecture, CSMA/CA and the physical layer PIN 3/27
81 Ba · 76 Ch · 66 Bh1+1+62+2+45+3
Architecture. The building block is the basic service set (BSS): stations that share one radio channel. In an ad hoc BSS (an independent BSS) the stations talk directly; in an infrastructure BSS every frame goes through an access point (AP). Several BSSs joined by a distribution system, usually a wired Ethernet, form an extended service set (ESS) with one network name (SSID), and a station can roam from one AP to another.
Why CSMA/CD is not applicable in a wireless LAN.
- A radio cannot listen while it sends: its own signal is millions of times stronger than any arriving one, so collision detection would need costly full-duplex radios.
- Hidden station: A and C are both in range of B but not of each other. While A sends to B, C senses the air idle and sends too; the frames collide at B, and neither sender can know.
- A collision happens at the receiver, but a sender can only sense the air where it is, and signals fade with distance, so what the sender hears is not what the receiver hears.
- Exposed station: C hears B sending to A and holds back, although its frame to D could not disturb A: sensing wastes chances too.
CSMA/CA: avoiding collisions instead. The distributed coordination function, step by step:
- Sense: the station waits until the channel has been idle for a DIFS (distributed interframe space).
- Back off: it picks a random number of slots from its contention window and counts down only while the channel stays idle, freezing the count while it is busy.
- Send when the count reaches zero.
- Acknowledge: the receiver waits a SIFS (short interframe space) and sends an ACK. No ACK means a collision was likely: the sender doubles its contention window and tries again.
- RTS and CTS (for large frames): the sender first sends a short request to send carrying the time the whole exchange will take; the receiver answers clear to send with the same time. Every station that hears either one sets its NAV (network allocation vector) and keeps quiet for that time: virtual carrier sensing. A hidden station cannot hear the RTS, but it does hear the CTS.
Interframe spaces set priority: SIFS < PIFS < DIFS. ACKs and CTS wait only a SIFS, so they always take the channel before any new frame can start after its DIFS. The optional point coordination function lets the AP poll stations instead.
Collision reduction in 802.3 and 802.11, side by side.
| Point | IEEE 802.3 Ethernet | IEEE 802.11 Wi-Fi |
|---|---|---|
| Access method | CSMA/CD | CSMA/CA |
| Strategy | detect a collision fast and stop | avoid the collision beforehand |
| Before sending | sense, send when idle (1-persistent) | sense, wait DIFS and a random backoff |
| During sending | listen; on a collision, jam and back off | cannot listen; relies on the ACK |
| Extra tools | minimum frame of 64 bytes, binary exponential backoff; switches remove collisions | RTS and CTS with the NAV, ACK for every frame, contention window doubling |
The physical layer. The original 802.11 (1997) ran at 1 and 2 Mbps in the 2.4 GHz band with frequency hopping or direct sequence spread spectrum (and infrared).
- FHSS (frequency hopping): the carrier hops among 79 channels of 1 MHz in a pseudo-random order known to both ends, staying at most 400 ms on each; narrowband interference spoils only a hop or two. Bluetooth hops the same way.
- DSSS (direct sequence): each data bit is replaced by an 11-chip Barker
sequence,
10110111000for a 1 and its inverse01001000111for a 0, sent at 11 Mchips/s. The signal is spread over a 22 MHz channel. The receiver correlates the incoming chips with the same sequence: the wanted signal adds up while narrowband interference and echoes are spread out and suppressed (a processing gain of about 10.4 dB, 10 log 11). 802.11b kept the 22 MHz DSSS channel and raised the rate to 11 Mbps with a different coding (CCK). - OFDM splits a channel into many narrow subcarriers sent at once; it carries every later version.
| Version | Year | Band | Top rate | Technique |
|---|---|---|---|---|
| 802.11b | 1999 | 2.4 GHz | 11 Mbps | DSSS (CCK) |
| 802.11a | 1999 | 5 GHz | 54 Mbps | OFDM |
| 802.11g | 2003 | 2.4 GHz | 54 Mbps | OFDM |
| 802.11n (Wi-Fi 4) | 2009 | 2.4 and 5 GHz | 600 Mbps | OFDM, MIMO |
| 802.11ac (Wi-Fi 5) | 2013 | 5 GHz | about 6.9 Gbps | wider channels, multi-user MIMO |
| 802.11ax (Wi-Fi 6, 6E) | 2021 | 2.4, 5 and 6 GHz | about 9.6 Gbps | OFDMA |
The frame (the book's Figure 3.41): frame control (2 bytes: version, type, subtype, To DS, From DS, more fragments, retry, power management, more data, protected (WEP), order), duration (2, the NAV value), up to four addresses (6 each), sequence control (2), the body (0 to 2312 bytes) and a 4-byte CRC. Its security, WEP and WPA, is chapter 8's (WEP).
To remember the hidden station: two students shout answers to a teacher from opposite ends of a big exam hall. Each thinks the hall is quiet, because neither hears the other; only the teacher in the middle hears both at once. RTS and CTS is raising a hand and waiting for the teacher to say "yes, you": everyone hears the teacher's "yes".
- What is CSMA/CD? Why is it not applicable in wireless LAN? What are the techniques used to avoid the possible collisions in WLAN? Explain. 2081 Baishakh Q3 · 2+2+4
- What is collision? How is it occured? How the possibility of collision is reduced in IEEE 802.3 and IEEE 802.11? Explain. 2076 Chaitra Q3 · 1+1+6
- Describe the 802.3 Ethernet standard for CSMA/CD and compare it with 802.4 token bus technology. Explain how DSSS technique is applied in wireless transmission. 2066 Bhadra Q3a · 5+3
3.11Virtual LANs
Virtual LANs and IEEE 802.1Q, with a two-VLAN design PIN 3/27
82 Bh · 80 Ba · 68 Ba2×42+6
The problem it solves. Every port of a plain switch is in one broadcast domain: an ARP request or a DHCP broadcast from any PC reaches every other PC. Grouping users by department would need a separate switch per department, rewired whenever someone moves. A VLAN-capable switch does it in software.
Why use VLANs.
- Smaller broadcast domains: broadcasts stay inside their VLAN, so less traffic floods every port.
- Security: students' PCs cannot reach the department's servers at layer 2; traffic between VLANs passes through a router where it can be filtered.
- Flexibility: users are grouped by function, not location; a moved PC is moved by changing one port's VLAN, not the cabling.
- Cost and performance: one switch serves several groups, and the network is easier to manage.
Membership (the book's four ways): by switch port (static, the most common), by MAC address, by IP address, or by the application in use. The book also separates single-switch VLANs from multi-switch VLANs, which need a trunk.
IEEE 802.1Q tagging. Between switches (or a switch and a router) one link, a trunk, carries frames of many VLANs; each frame gets a 4-byte tag inserted after the source address:
- TPID (16 bits) =
0x8100: marks the frame as tagged. - PCP (3 bits): the priority (802.1p).
- DEI (1 bit): the frame may be dropped first under congestion.
- VID (12 bits): the VLAN ID, 4096 values, of which 0 and 4095 are reserved, so VLANs 1 to 4094.
An access port belongs to one VLAN and carries untagged frames to an ordinary PC; the switch adds the tag when a frame enters a trunk and removes it at the access port. Untagged frames on a trunk belong to its native VLAN.
Routing between VLANs. Two VLANs are two IP subnets, so a router (or a layer 3 switch) must join them: router on a stick uses one router port split into one subinterface per VLAN, over a single trunk.
| VLAN | Switch ports | Subnet | Gateway | Hosts |
|---|---|---|---|---|
| 10 STUDENT | Fa0/1 to Fa0/12 | 192.168.10.0/24 | 192.168.10.1 | 192.168.10.11, .12, ... |
| 20 DEPARTMENT | Fa0/13 to Fa0/24 | 192.168.20.0/24 | 192.168.20.1 | 192.168.20.11, .12, ... |
Switch S1 (Cisco IOS):
S1(config)# vlan 10 S1(config-vlan)# name STUDENT S1(config-vlan)# vlan 20 S1(config-vlan)# name DEPARTMENT S1(config-vlan)# exit S1(config)# interface range fastEthernet 0/1 - 12 S1(config-if-range)# switchport mode access S1(config-if-range)# switchport access vlan 10 S1(config-if-range)# interface range fastEthernet 0/13 - 24 S1(config-if-range)# switchport mode access S1(config-if-range)# switchport access vlan 20 S1(config-if-range)# interface gigabitEthernet 0/1 S1(config-if)# switchport mode trunk
Router R1, one subinterface per VLAN on the trunk port:
R1(config)# interface gigabitEthernet 0/0 R1(config-if)# no shutdown R1(config-if)# interface gigabitEthernet 0/0.10 R1(config-subif)# encapsulation dot1Q 10 R1(config-subif)# ip address 192.168.10.1 255.255.255.0 R1(config-subif)# interface gigabitEthernet 0/0.20 R1(config-subif)# encapsulation dot1Q 20 R1(config-subif)# ip address 192.168.20.1 255.255.255.0
Each PC gets an address in its VLAN's subnet with that VLAN's gateway. show vlan
brief on S1 lists the ports in each VLAN; a ping from a student PC to a department PC
succeeds only through R1. With a layer 3 switch, the router is replaced by
interface vlan 10 and interface vlan 20 with the gateway addresses,
and ip routing.
To remember it: two WhatsApp groups on the same phone. The phone (the switch) is one piece of hardware, but a message to the class group never reaches the staff group; to pass something between them someone must forward it on purpose (the router).
- Write short notes on: (Any Two) a) ARP and NDP b) AH and ESP c) VPN d) vLAN 2082 Bhadra Q10 · 2×4
- Write short notes on: (Any Two) a) VLAN b) ARP c) IPSec 2080 Baishakh Q10 · 2×4
- What is a virtual LAN? Design a network which consists of two VLAN named student and department. Explain with necessary diagram, IP addresses and configurations. 2068 Baishakh Q3 · 2+6
3.12Last minute recall
Chapter 3 in one screen
- Functions: framing, physical addressing, flow control, error control, access control; services: unacknowledged connectionless, acknowledged connectionless, acknowledged connection-oriented; LLC (802.2) over MAC.
- Framing: character count (one bad count loses sync), byte stuffing (FLAG, ESC; PPP), bit stuffing (flag 01111110, a 0 after five 1s; HDLC), coding violations.
- Errors: single-bit, burst; detection (parity, checksum, CRC) against correction (Hamming, FEC); parity catches odd counts only; checksum is one's complement.
- CRC: append r zeros, divide by G mod 2, remainder is the CRC, receiver's zero remainder means accept; CRC-32 in Ethernet.
- Hamming: distance by XOR; detect s needs d ≥ s + 1, correct t needs d ≥ 2t + 1; (7,4) code, parity at 1, 2, 4, syndrome gives the wrong bit.
- Flow control: stop and wait (U = 1/(1 + 2a)), sliding window (W frames, seq mod 2^k), piggybacking (ack in the data frame, ack timer).
- ARQ: stop and wait (1-bit seq, timer), go-back-N (window 2^k - 1, resend from the lost one), selective repeat (window 2^(k-1), resend only the lost one).
- HDLC: primary, secondary, combined; NRM, ARM, ABM; flag, address, control, information, FCS, flag; I, S (RR, RNR, REJ, SREJ), U frames.
- PPP: byte stuffing, 7E FF 03, LCP, PAP or CHAP, NCP (IPCP); dead, establish, authenticate, network, open, terminate.
- MAC: who sends next on a broadcast channel; static (FDM, TDM: delay N times) against dynamic; random, controlled, channelization.
- ALOHA: pure, vulnerable 2T, S = G e^-2G, max 18.4 % at G = 0.5; slotted, vulnerable T, S = G e^-G, max 36.8 % at G = 1.
- CSMA: listen before talk; vulnerable time = propagation time; 1-persistent, non-persistent, p-persistent.
- CSMA/CD: sense, send and listen, jam (32 bits), back off K from 0 to 2^min(n,10) - 1 slots of 512 bit times, 16 attempts; minimum frame 64 bytes as T_frame ≥ 2 T_prop.
- Controlled access and channelization: reservation, polling, token passing; FDMA, TDMA (GSM), CDMA (orthogonal chip codes).
- Ethernet: preamble 7, SFD 1, DA 6, SA 6, length/type 2, data 46 to 1500, FCS 4; 64 to 1518 bytes; 48-bit MAC (OUI + NIC); 10Base5, 10Base2, 10BaseT, 100BaseTX, 100BaseFX, 1000BaseSX and LX.
- Token bus (802.4): physical bus, logical ring by descending address, so "token ring"; priorities 0, 2, 4, 6; broadband coax; factories.
- Token ring (802.5): seize the token (T bit), frame circles, destination sets A and C, sender strips it and releases the token; SD, AC, FC, DA, SA, data, FCS, ED, FS; active monitor; 4 or 16 Mbps.
- FDDI: 100 Mbps fiber, dual counter-rotating rings, timed token; DAS, SAS, concentrator; a cut makes both neighbours wrap into one ring; optical bypass, dual homing.
- WLAN: BSS (ad hoc, infrastructure), ESS; no CSMA/CD (cannot hear while sending, hidden and exposed stations); CSMA/CA: DIFS, backoff, SIFS, ACK, RTS/CTS and NAV; FHSS, DSSS (11-chip Barker), OFDM.
- VLAN: one broadcast domain by configuration; 802.1Q tag (TPID 0x8100, PCP, DEI, 12-bit VID); access and trunk ports; router on a stick; STUDENT 192.168.10.0/24, DEPARTMENT 192.168.20.0/24.
Chapter 4 · 9 hours · about 17 marks a paper · in all 27 sittings
Network layer
The network layer carries a packet from the source host to the destination host across many networks: it gives every interface a logical (IP) address, and routers choose the path one hop at a time. It is the heaviest chapter of the course, about 17 of every 80 marks: a subnetting design has been set in 24 of the 27 sittings on record, and routing (distance vector against link state, OSPF, RIP) appears in almost every paper as well.
- The layer and its devices: host-to-host delivery, and the repeaters, hubs, bridges, switches, routers and gateways that join segments and networks, each at its own layer.
- Addressing: the 32-bit IPv4 address and its classes, subnetting with VLSM, classless addressing (CIDR) and supernetting, and NAT.
- The IP datagram and its helpers: the IPv4 header, fragmentation and reassembly, ARP and RARP for addresses, ICMP for error reports.
- Routing: static and dynamic routing, the routing table, and the algorithms: Dijkstra's shortest path, flooding, distance vector, link state and hierarchical routing.
- Routing protocols: RIP, OSPF, BGP, IGRP and EIGRP, and unicast against multicast routing (IGMP, DVMRP, MOSPF, PIM).
- Design: a hotel or a campus network, with the devices, cabling, wireless, servers and addressing chosen and justified.
- Below it, the data link layer moves a frame across one link by MAC address (the MAC sublayer, Ethernet); switches and VLANs work there (VLAN). Datagram and virtual circuit service are compared in chapter 2 (datagram and virtual circuit).
- Above it, TCP and UDP ride inside IP datagrams (TCP, UDP), and ports pick the process (port and socket); DHCP hands out the addresses and DNS names them (DHCP, DNS).
- Beyond it, IPv6 is the successor (IPv6 header, IPv6 addresses), and IPsec, VPNs and firewalls secure this layer (IPsec, VPN, firewalls).
- 4.1 The network layer: functions, and why it is the key layer
- 4.2 Internetworking devices, bridges
- 4.3 IPv4 addressing, subnetting and VLSM, CIDR and supernetting, NAT
- 4.4 The IPv4 datagram, ARP and RARP, ICMP
- 4.5 Routing, the routing table
- 4.6 Shortest path, flooding, distance vector, link state, hierarchical routing
- 4.7 Routing protocols, RIP, OSPF, BGP, unicast and multicast routing
- 4.8 Designing a network: a hotel, a campus
- 4.9 Last minute recall, chapter 4
- A subnetting design (VLSM from a given block, 8 to 10 marks) is the chapter's banker: 24 of the 27 sittings set one. The subnet card teaches the method; every paper's design is worked in full in the Numericals panel.
- Distance vector against link state has been compared in ten sittings: the table on the link state card is the answer. Count to infinity and loop prevention go with it.
- Routing basics (what routing is, why it is essential, a good algorithm's properties, adaptive against non-adaptive, routed against routing protocols) appear in 13 sittings, usually as the 2 or 3 mark first part.
- One of the rest in most papers: OSPF (DR and BDR, full adjacency), RIP and its timers, ICMP message types, ARP, the IPv4 header and fragmentation, the devices.
- The order here puts the routing algorithms (syllabus 4.6) before the protocols (4.5), because RIP is distance vector and OSPF is link state: each protocol card builds on its algorithm.
4.1The network layer
The network layer: what it does, and why it is the key layer PIN 1/27
72 Ka2+6
Three scopes of delivery keep the layers apart. The data link layer moves a frame across one link, from a node to the next (hop to hop). The network layer moves a packet from the source host to the destination host across all the links in between (host to host). The transport layer moves a message between two processes inside those hosts (process to process, ports).
The drawing shows the split. Hosts run all five layers of the TCP/IP stack; a router runs only the bottom three. At every router the frame is opened, the packet is read, a new frame is built for the next link with new MAC addresses, but the packet's source and destination IP addresses stay the same from end to end.
Its functions, each one a line in the answer:
- Logical addressing: every host and router interface gets an IP address that is unique across the internetwork; each packet's header carries the source and the destination address. A MAC address only works inside one link.
- Routing: routers run routing algorithms and protocols to learn the networks and build their routing tables (routing).
- Forwarding: for each arriving packet, a router looks up the destination in its table and sends the packet out of the matching interface.
- Packetizing: the layer wraps the transport segment in a packet with its own header at the source and unwraps it at the destination (encapsulation).
- Fragmentation and reassembly: a packet bigger than the next link's MTU is split into fragments, and the destination puts them back together (the IPv4 datagram).
- Internetworking: one packet format and one address space hide the different link technologies (Ethernet, Wi-Fi, fibre and leased WAN lines) underneath.
- Error reporting and diagnostics: ICMP tells the source why a packet could not be delivered, and supports ping and traceroute (ICMP).
- Congestion control and quality of service: routers queue, drop or prioritise packets (the type of service field); end-to-end control belongs to the transport layer (congestion control).
Two kinds of service are possible. In datagram (connectionless) service each packet carries the full destination address and is routed on its own, as IP does. In virtual circuit (connection-oriented) service a path is set up first and packets carry only a short circuit number, as X.25, ATM and MPLS do. Chapter 2 compares them (datagram and virtual circuit).
| Layer | Delivers | Unit | Address | Device |
|---|---|---|---|---|
| Data link (2) | node to node, over one link | frame | MAC, 48 bits | switch, bridge |
| Network (3) | host to host, across networks | packet (datagram) | IP, 32 bits | router |
| Transport (4) | process to process | segment | port, 16 bits | the end hosts only |
Why it is the key layer of the OSI model:
- The highest layer on the path: routers implement layers 1 to 3, so layer 3 is the top layer that every node between the two hosts understands. The path is decided here.
- The narrow waist: many applications and two transport protocols above, dozens of link technologies below, and one network protocol in the middle (IP over everything, everything over IP). Replace Wi-Fi with fibre and no application notices.
- Global addressing that scales: hierarchical addresses let a router keep one route per network, not one per host, so a few hundred thousand routes reach billions of hosts.
- Without it a frame could never leave its own LAN: there would be no Internet, only islands.
To remember it, post a parcel from Pulchowk to a friend in Pokhara. The address on it (district, municipality, ward, name) is the IP address. Each post office is a router: it looks only at the district and sends the bag on to the next office. The bus that carries the bag between two offices is the data link, and it changes at every office; the address on the parcel never does.
- What are the functions of network layer? Explain briefly about multicast routing protocols and unicast routing protocols. 2072 Kartik Q4 · 2+6
- Network layer is one of the key layers in OSI reference model, why? Differentiate between distance vector routing and static link routing. 2072 Kartik Q5 · 2+6
4.2Internetworking devices
Internetworking devices, layer by layer PIN 4/27
79 Bh · 70 Ch · 68 Ch · 66 Po2×53+34+4
The rule behind the whole topic: a device can only decide on what its layer can read. A repeater sees only a signal, so it can only copy it. A switch reads MAC addresses, so it can pick one port. A router reads IP addresses, so it can pick a path between networks. A gateway reads whole messages, so it can translate one protocol into another.
- Repeater (physical layer): receives a weakened, noisy signal on one port and regenerates it at full strength on the other. It restores bits without reading them, so it extends a cable beyond its distance limit (500 m for a thick coaxial 10BASE5 segment). It has two ports and no intelligence: every bit, collisions included, is copied, so both sides stay one collision domain. Classic 10 Mbps Ethernet capped them with the 5-4-3 rule: at most five segments joined by four repeaters, with stations on only three. A repeater is not an amplifier: an amplifier boosts the noise with the signal, a repeater rebuilds a clean digital signal.
- Hub (physical layer): a multiport repeater. A signal arriving on one port is copied out of every other port, so all ports share one bandwidth and one collision domain, and the hub works half duplex. An active hub is powered and regenerates the signal; a passive hub only joins the wires.
- Bridge (data link layer): joins two LAN segments, reads the MAC addresses, records which station lives on which side and forwards a frame only when its destination is on the other side. Each side becomes its own collision domain; broadcasts still cross. It has its own card (bridges).
- Switch (data link layer): a multiport bridge. It keeps a MAC address table and sends each frame only to the port where the destination lives, flooding only unknown and broadcast frames. Every port is a separate collision domain, and on a full-duplex port there are no collisions at all. It forwards in one of three ways: store-and-forward (receives the whole frame and checks its FCS first: reliable, the usual default), cut-through (starts sending as soon as the destination MAC is read: fastest, but passes bad frames) or fragment-free (waits for the first 64 bytes, where collision fragments show). Managed switches add VLANs (VLAN), port security and monitoring; a layer 3 switch also routes between VLANs.
- Router (network layer): joins different networks (one subnet to another, a LAN to a WAN) and forwards packets by destination IP address, using a routing table that is configured by hand or built by routing protocols. Each interface is its own network and its own broadcast domain, because a router does not forward broadcasts. It also decrements TTL, fragments when needed and often does NAT and packet filtering.
- Gateway (up to the application layer): a protocol converter. It joins networks that use different protocol stacks and translates between them: an email gateway between two mail systems, a VoIP gateway between IP phones and the telephone exchange, an IoT gateway between Zigbee sensors and an IP network. In TCP/IP, the "default gateway" of a host simply means the router it sends off-subnet packets to.
Two more devices appear in every network: the NIC (network interface card) works at layers 1 and 2 and carries the MAC address; the modem (or the ONT of a fibre connection) converts the digital signal to the line's analogue or optical signal, a layer 1 job.
| Device | Layer | Reads | Sends a unicast to | Collision domains | Broadcast domains |
|---|---|---|---|---|---|
| Repeater | 1, physical | the signal | the other port | one, shared | one |
| Hub | 1, physical | the signal | every other port | one for all ports | one |
| Bridge | 2, data link | MAC address | the destination's side only | one per port | one |
| Switch | 2, data link | MAC address | the destination's port only | one per port | one (one per VLAN) |
| Router | 3, network | IP address | the next hop on the best path | one per interface | one per interface |
| Gateway | up to 7 | the whole message | the other network, translated | separate | separate |
Why a switch, not a hub, for a LAN:
- Dedicated bandwidth: a 24-port 100 Mbps hub shares 100 Mbps among all 24 PCs; a switch gives every port its own 100 Mbps, and its backplane carries many conversations at once.
- No collisions: each switch port is its own collision domain, and with full duplex the CSMA/CD rules never fire (CSMA/CD); a hub's single collision domain collapses as the load grows.
- Full duplex: a switch port sends and receives at the same time; a hub is half duplex.
- Privacy and security: a switch delivers a unicast frame only to its owner; on a hub every PC receives every frame, so anyone running a packet sniffer sees all the traffic.
- Features: VLANs, port security, quality of service, link aggregation and monitoring; a hub has none.
- Cost: the price gap has closed; hubs are no longer made.
Router against gateway (a short note on its own in one sitting):
| Point | Router | Gateway |
|---|---|---|
| Job | forwards packets between networks | translates between networks that use different protocols |
| Layer | 3, network | any layer, usually 4 to 7 (up to the application) |
| Protocols on its two sides | the same network protocol (IP) | different protocol stacks |
| Decides by | destination IP address and the routing table | the message's protocol and content |
| Changes in the data | only header fields (TTL, checksum) | the format itself (protocol conversion) |
| Examples | an ISP's core router, a home Wi-Fi router | email gateway, VoIP to telephone gateway, IoT gateway |
To remember them, picture the letters for a hostel floor. A hub is a warden who reads every letter aloud in the corridor: everyone hears it. A switch is a warden who slides each letter under the right door. A router is the post office that sends letters on to other cities. A gateway is a translator who rewrites a letter from Japanese into Nepali before delivering it.
- Why do we prefer a switch as networking device instead of Hub for LAN connection? Give reasons. Discuss the characteristics of a good routing algorithm. 2079 Bhadra Q4 · 4+4
- Explain the working principle of different types of network devices Repeater, HUB, Bridge, Switch and Router. 2070 Chaitra Q4 · 8
- Write short notes on: a) Network Security b) Router and Gateway 2068 Chaitra Q9 · 2×5
- Write short notes on (any two): a) UDP and its application b) Network Devices: Hubs, Switches and Routers c) IPv4 Header Structure 2066 Poush Q10 · 3+3
Bridges: learning, filtering and forwarding PIN 1/27
80 Ba8
The everyday bridge is transparent (IEEE 802.1D): the stations do not know it is there, and it needs no setup. It listens to every frame on every port and builds its MAC table, also called the forwarding database, from the source addresses it sees. Ethernet switches work exactly this way; a bridge is a switch with two or a few ports.
How it handles one frame, in order:
- Receive: the frame arrives on a port (the bridge hears every frame on both segments).
- Learn: it records the frame's source MAC address against the arrival port, with the time.
- Look up the destination MAC address in the table, then do one of three things:
- Filter: the destination is on the same port the frame came in on, so the frame is local: drop it.
- Forward: the destination is on another port: send the frame out of that port only.
- Flood: the destination is not in the table yet, or the frame is a broadcast or multicast: send it out of every port except the one it came in on.
- Age: an entry that is not refreshed within the ageing time (300 seconds by default) is deleted, so a station that moves is found again.
Setting: stations A and B sit on segment 1 (port 1), C and D on segment 2 (port 2); the table starts empty.
| Frame | Learns | Destination | Action | Table after |
|---|---|---|---|---|
| A to C | A on port 1 | C unknown | flood to port 2 | A-1 |
| C to A | C on port 2 | A on port 1 | forward to port 1 | A-1, C-2 |
| B to A | B on port 1 | A on port 1, the arrival port | filter (drop) | A-1, C-2, B-1 |
| D to all (broadcast) | D on port 2 | broadcast | flood to port 1 | A-1, C-2, B-1, D-2 |
After four frames the table is complete: from now on the B to A frame never disturbs segment 2, and the C to A frame never touches more than the one segment it must cross.
Why a bridge raises the throughput of an extended LAN where a repeater does not:
- A repeater copies every bit to the other side, so the two segments remain one collision domain sharing one channel: their total throughput can never exceed one segment's capacity C, and every station added makes collisions more frequent.
- A bridge keeps local frames local, so the two segments carry their own traffic at the same time; only frames for the other side cross. If each segment offers a load L and a fraction f of it crosses, each segment carries , so the total is With 100 Mbps segments and a fifth of the traffic crossing (f = 0.2), the bridged LAN carries 166.7 Mbps against the repeater's 100 Mbps; with all traffic local it doubles to 200 Mbps.
- Collisions stay on their own segment, and because the bridge stores the whole frame before sending it, each side gets its own CSMA/CD distance limit (CSMA/CD): the LAN can grow longer than repeaters allow.
- Bad frames are dropped (FCS errors, collision fragments) instead of being copied on, and segments of different speeds (10 and 100 Mbps) can be joined.
- The limits: broadcasts still cross every bridge, and storing frames adds a little delay.
Loops, and the spanning tree. Two bridges between the same pair of LANs give a spare path, but also a loop: one broadcast circulates for ever (a broadcast storm) and the MAC tables flap as frames arrive from both sides. The Spanning Tree Protocol (IEEE 802.1D, from Radia Perlman's 1985 algorithm) fixes it: the bridges exchange BPDU messages, elect a root bridge (the lowest bridge ID: a priority, 32768 by default, then the MAC address) and block the redundant ports so that the active links form a tree. A blocked port opens if an active link fails; Rapid STP (802.1w) does it in seconds.
| Type of bridge | How it works | Where |
|---|---|---|
| Transparent (learning) | builds its own table; stations unaware | Ethernet (802.1D) |
| Source routing | the sender writes the route of bridges into the frame | token ring (802.5) |
| Translational | converts between frame formats | Ethernet to token ring or FDDI |
| Remote | a pair joins two LANs over a WAN link | two offices |
To remember it, think of the guard at the gate between two hostel blocks. From the letters people send, he notes which student lives in which block. A letter for someone in the same block never goes through the gate; a letter for the other block does; a letter for a name he has never seen is shown in both blocks; and a notice for everyone goes everywhere.
- What is a bridge? How does it work? How can a bridge increase the throughout as compared with a repeater while extending a LAN? Explain with suitable diagrams. 2080 Baishakh Q3 · 8
4.3IPv4 addressing
IPv4 addresses: classes, special and private addresses HOT 5/27
82 Ba · 74 Ash · 72 Ch · 70 Asa · 68 Ba1+72+64+4
The notation: 32 bits are written as four bytes, each 0 to 255, separated by dots.
192.168.10.37 is 11000000.10101000.00001010.00100101 in binary.
There are addresses in all, and the free pool ran out
in 2011: IANA handed out its last blocks in February, and APNIC, the registry that serves
Nepal and the rest of Asia-Pacific, reached its final block in April.
Network part and host part work like a telephone number's area code and line number: routers look only at the network part to find the way, and only the last network delivers to the host part.
Logical against physical address. An IP address is a logical address: it is given by the network's administrator (or DHCP), not built into the hardware, and it says where the host sits. A MAC address is a physical address: burned into the network card, it says only which card it is.
| Point | Physical (MAC) address | Logical (IP) address |
|---|---|---|
| Layer | data link (2) | network (3) |
| Size | 48 bits, written as 12 hex digits (00:1a:2b:3c:4d:5e) | 32 bits for IPv4, 128 for IPv6 |
| Assigned by | the manufacturer, in the NIC | the administrator or DHCP |
| Structure | flat: maker's code (OUI) and a serial number, no location | hierarchical: network and host |
| Scope | one link: replaced at every hop | end to end: unchanged across routers (unless NAT) |
| Changes when | the card is replaced | the host moves to another network |
| Used by | switches, to deliver inside a LAN | routers, to find the path between networks |
Why use an IP address when every host already has a MAC address?
- A MAC address says who, not where. It is flat, so a router would need a table entry for every device in the world. The network part of an IP address lets one route cover a whole network, and many networks can be summarised as one.
- A MAC address works on one link only. Frames are re-addressed at every hop, while the IP address stays the same from source to destination.
- Links differ. Ethernet and Wi-Fi have MAC addresses, but serial lines, PPP and cellular links use other schemes or none; IP gives one uniform address over all of them.
- Hardware changes. Replace a server's card and its MAC changes, but its IP address (and DNS name) stays; move a laptop to another network and its new IP tells routers where it now is.
- Planning. IP addresses can be laid out by department and floor, and subnetted; MAC addresses cannot. ARP joins the two at the last hop (ARP).
To remember it, a citizenship certificate number stays with you wherever you live and tells nobody where to find you; a postal address (district, municipality, ward) tells the postman where to go, and changes when you move. Delivery needs both: the address to reach the house, the name to find the person inside.
Classful addressing (1981 to 1993) cut the address space into five classes, told apart by the first bits of the first octet. The class fixed where the network part ended.
| Class | First bits | Address range | Default mask | Networks | Hosts per network | Use |
|---|---|---|---|---|---|---|
| A | 0 | 0.0.0.0 to 127.255.255.255 | 255.0.0.0 (/8) | = 128 (126 usable) | = 16,777,214 | very large networks |
| B | 10 | 128.0.0.0 to 191.255.255.255 | 255.255.0.0 (/16) | = 16,384 | = 65,534 | medium networks |
| C | 110 | 192.0.0.0 to 223.255.255.255 | 255.255.255.0 (/24) | = 2,097,152 | = 254 | small networks |
| D | 1110 | 224.0.0.0 to 239.255.255.255 | none | multicast group addresses, no hosts | multicast | |
| E | 1111 | 240.0.0.0 to 255.255.255.255 | none | no hosts | reserved, experimental | |
The minus two in every host count: a host part of all 0s names the network itself,
and a host part of all 1s is the network's broadcast address, so neither can be given to a
host. Finding the class needs only the first octet: 172.20.5.9 starts
with 172, between 128 and 191, so it is class B: network 172.20.0.0, host
5.9.
| Special address | Meaning |
|---|---|
| host part all 0s (192.168.1.0) | the network itself; never given to a host |
| host part all 1s (192.168.1.255) | directed broadcast to every host on that network |
| 255.255.255.255 | limited broadcast: this network only, never routed |
| 0.0.0.0 | "this host", used before a host has an address (a DHCP request); as 0.0.0.0/0, the default route |
| 127.0.0.0/8 (127.0.0.1) | loopback: the packet never leaves the host |
| 169.254.0.0/16 | link-local: picked by a host itself when DHCP does not answer |
Private addresses (RFC 1918) may be used inside any organisation without asking
anyone, and are never routed on the Internet: 10.0.0.0/8 (one class A,
16,777,216 addresses), 172.16.0.0/12 (172.16 to 172.31, sixteen class B
networks, 1,048,576 addresses) and 192.168.0.0/16 (256 class C networks, 65,536
addresses). The hostel Wi-Fi that hands a phone 192.168.1.23 is using one; the
router's NAT carries it to the Internet (NAT). ISPs short of public
addresses also use 100.64.0.0/10 (RFC 6598) for carrier-grade NAT.
Why classful addressing failed:
- Waste: a company with 2,000 hosts was too big for a class C (254), so it took a class B and left 63,534 addresses unused.
- Too few medium blocks: only 16,384 class B networks existed, and they ran out first.
- Routing tables grew: every class C network needed its own route.
- Rigid: a block could not be cut to fit, and classes D and E could not be given to hosts at all.
The fixes followed: subnetting (1985) cuts a network up (subnetting), CIDR (1993) drops the classes (CIDR and supernetting), NAT hides many hosts behind one address, and IPv6 gives 128-bit addresses (IPv6 addresses).
0.0.0.0/8 and 127.0.0.0/8, are reserved, so 126 can actually be
used. Its notation example prints the first octet of 128.11.3.31 with nine bits; it is
10000000.- List the range of IPv4 address classes. You have to assign addresses to four departmental LANs with following hosts 14, 55, 10 and 29 addresses respectively from the given IP address block: 202.97.43.0/25. Perform the subnetting and find out subnet mask, network address, broadcast address and usable host IP ranges. 2082 Baishakh Q5 · 1+7
- What is classful and classless address? Differentiate between link state and distance vector routing protocol. 2074 Ashwin Q4 · 8
- Explain five instances of how networks are a part of your life today. Through we have MAC address, why do we use IP address to represent the host in networks? Explain your answer. 2072 Chaitra Q2 · 5+3
- What are the major problems with existing IPv4 network? Explain IPv4 addressing and sub-netting with example. 2070 Ashad Q9 · 4+4
- What is a logical address? You are given the IP address block 200.10.80.32/25. If there are five departments which require 5, 40, 28, 12, 6 hosts respectively. Design the subnet. 2068 Baishakh Q4 · 2+6
Subnetting and VLSM: dividing a block with the least waste TOP 24/27
82 Bh · 82 Ba · 81 Bh · 81 Ba · 80 Bh · 80 Ba · 79 Bh · 78 Bh · 76 Ch · 76 Ash · 75 Ch · 75 Ash · 74 Ch · 74 Ash · 73 Shr · 72 Ch · 71 Ch · 70 Ch · 70 Asa · 69 Ch · 68 Ch · 68 Ba · 67 Asa · 66 Bh81+710
The subnet mask is 32 bits with 1s over the network (and subnet) bits and 0s over the host bits, written in dotted decimal (255.255.255.192) or as a prefix length (/26: twenty-six 1s). ANDing any address with its mask clears the host bits and leaves the network address. The book's first example, worked bit by bit:
Address 130.45.32.56 10000010.00101101.00100000.00111000 Mask 255.255.0.0 11111111.11111111.00000000.00000000 AND 130.45.0.0 10000010.00101101.00000000.00000000
Inside an octet: with a mask that ends inside an octet, only that octet needs the binary:
192.168.10.150/26 has mask 255.255.255.192, and 150 AND 192 is
10010110 AND 11000000 = 10000000 = 128, so the address
lies in subnet 192.168.10.128/26, whose broadcast is .191 and whose hosts run
from .129 to .190.
What subnetting contributes to address management:
- Less waste: one block is cut to fit the departments, instead of each department taking a whole classful network.
- Smaller broadcast domains: ARP requests and other broadcasts stay inside one subnet, so traffic falls and performance rises.
- Security and policy: traffic between subnets passes a router or firewall where access rules apply: the accounts office can be shut off from the student labs.
- Easier management: an address tells the department or floor, and a fault stays inside one subnet.
- Hierarchy: the outside world sees one route for the whole block; the internal detail stays inside.
- Room to grow: each department can be given its own range to manage.
The numbers, for s borrowed subnet bits and h host bits left:
Here m is the last octet of the mask that is not 255. Network addresses are the multiples of the block size; each broadcast is one less than the next network address; the usable hosts lie in between.
| Prefix | Mask | Block size | Usable hosts |
|---|---|---|---|
| /24 | 255.255.255.0 | 256 | 254 |
| /25 | 255.255.255.128 | 128 | 126 |
| /26 | 255.255.255.192 | 64 | 62 |
| /27 | 255.255.255.224 | 32 | 30 |
| /28 | 255.255.255.240 | 16 | 14 |
| /29 | 255.255.255.248 | 8 | 6 |
| /30 | 255.255.255.252 | 4 | 2 |
Above /24 the same table moves one octet left: a /23 is 512 addresses (2 in the third octet), a /22 is 1,024 (4 in the third octet), a /21 is 2,048 and a /20 is 4,096, each with 2 fewer usable hosts.
Fixed-length subnetting (FLSM) gives every subnet the same mask. Four equal subnets
of 192.168.10.0/24 need 2 borrowed bits (): /26 subnets at .0,
.64, .128 and .192, with 62 hosts each. To split a block into N equal parts, borrow the
smallest s with : five departments need 3 bits, giving 8 subnets, of which
3 stay spare.
VLSM (variable length subnet mask) gives each subnet its own mask. It is used when the subnets need different numbers of hosts: departments of unequal size, and point-to-point links between routers that need only two addresses. With one mask for all, the mask must fit the biggest subnet, and every small subnet wastes most of its block: a department of 100 and one of 10 given two /25s waste 26 + 116 = 142 usable addresses, while VLSM's /25 and /28 waste 26 + 4 = 30. VLSM also keeps the plan hierarchical, so the subnets still summarise into one route. It needs a classless routing protocol that carries the mask in its updates (RIPv2, OSPF, EIGRP, IS-IS, BGP; not RIPv1 or IGRP).
The VLSM method, the same for every design question:
- Find the block. If the given address has host bits set
(
202.83.54.91/25), AND it with the mask first: the block is202.83.54.0/25, addresses .0 to .127. - Size each demand: find the smallest h with hosts; its prefix is 32 minus h and its block size . A point-to-point link needs 2 addresses: a /30 (block of 4).
- Sort largest first. Allocating the biggest blocks first keeps every subnet starting on a multiple of its own size.
- Allocate from the start of the block: each subnet begins where the previous one ended; the links go last.
- Write each subnet's row: network address, mask, first usable (network + 1), last usable (broadcast minus 1) and broadcast (next network minus 1).
- Count the waste: in each subnet, wasted = () minus the hosts needed. The unused range is everything from the end of the last subnet to the end of the block, kept for growth.
- Check: the blocks must add up to no more than the given block.
Given: Accounts 60 hosts, Library 25, Hostel office 10, and two router-to-router links. Sorted: 60 needs 64 (/26), 25 needs 32 (/27), 10 needs 16 (/28), each link 4 (/30).
| Subnet | Hosts | Block | Network | Mask | Usable range | Broadcast | Wasted |
|---|---|---|---|---|---|---|---|
| Accounts | 60 | 64 | 192.168.10.0/26 | 255.255.255.192 | .1 to .62 | .63 | 2 |
| Library | 25 | 32 | 192.168.10.64/27 | 255.255.255.224 | .65 to .94 | .95 | 5 |
| Hostel office | 10 | 16 | 192.168.10.96/28 | 255.255.255.240 | .97 to .110 | .111 | 4 |
| Link R1 to R2 | 2 | 4 | 192.168.10.112/30 | 255.255.255.252 | .113 to .114 | .115 | 0 |
| Link R2 to R3 | 2 | 4 | 192.168.10.116/30 | 255.255.255.252 | .117 to .118 | .119 | 0 |
Unused range: 192.168.10.120 to 192.168.10.255, 136
addresses left for new subnets. Only 11 usable addresses are wasted inside the five
subnets.
Points that cost marks:
- Hosts need two extra addresses: 30 hosts fit a /27 (30 usable), but 31 need a /26.
- A block always starts on a multiple of its size: a /27 can start at .0, .32, .64 and so on, never at .40.
- Point-to-point links take a /30 each. RFC 3021 also allows a /31 for a link, with no network or broadcast address, but the papers expect /30.
- Subnet zero: the old rule (RFC 950) threw away the first and last subnets (); since RFC 1878 every subnet is used (), as the book does.
- The router's address: each LAN's default gateway takes one of the usable addresses; a host count is taken to include it unless the question says otherwise.
To remember it, think of seating departments in a 256-seat exam hall in blocks whose size must be a power of two: the biggest department chooses first, so every block starts on a clean row, and the first and last seat of every block stay empty for the invigilators (the network and the broadcast address).
- Suppose a company XYZ has an IP address of 160.24.96.0/21 and it has 6 departments containing 1024, 750, 254, 500, 151 and 45 users and also include point-point links. List out the CIDR, network address, broadcast address, usable host range and wasted IP address in each subnet. 2082 Bhadra Q5 · 8
- List the range of IPv4 address classes. You have to assign addresses to four departmental LANs with following hosts 14, 55, 10 and 29 addresses respectively from the given IP address block: 202.97.43.0/25. Perform the subnetting and find out subnet mask, network address, broadcast address and usable host IP ranges. 2082 Baishakh Q5 · 1+7
- What is super-netting? Perform the subnetting of IPv4 address block 200.74.20.0/24 for five different departments having 4, 54, 120, 12 and 30 hosts. List out the network address, broadcast address, usable host range and wasted IP address in each subnet. 2081 Bhadra Q5 · 1+7
- In which case VLSM is used while dividing the given block of IP addresses for different subnets and why? Suppose your company has IP address block of 16.16.16.0/21. Divide this IP address for five different departments of the company equally. List out the network address, broadcast address, subnet mask and usable IP address range for each subnet. 2081 Baishakh Q4 · 3+5
- Suppose a company has IP address of 10.20.30.0/24 and it has 4 LANs containing 4,64,24,18 number of hosts. Also, there are 4 WAN links to connect LAN1 - LAN2, LAN2 - LAN3, LAN3 - LAN4 and LAN1 - LAN3. List out the subnet wasted IP addresses for each LAN. 2080 Bhadra Q4 · 8
- Suppose a company has IP address of 200.80.40.0/24 with 5 departments containing 29, 5, 16, 43, 14, number of hosts. Also there are point to point links between the departments. List out the subnet mask, network address, broadcast address, usable host IP ranges and no. of wasted IP addresses for each subnet. 2080 Baishakh Q5 · 8
- An ISP provided you an IP address block of 172.24.96.0/21. Suppose you need to divide this for four different departments A, B, C and D having 750, 200, 500 and 45 hosts respectively with minimum wastage of IP addresses. Also allocate IP addresses for three point-to-point links in the network. Find out the network address, broadcast address, subnet mash and usable host range of IP addresses for each subnet. 2079 Bhadra Q5 · 8
- Consider IP block of 202.50.0.0/24 and six departments with 125, 59, 27, 14, 4 and 2 hosts respectively. Perform the subnetting so that wastage of IP addresses is minimum and find out the subnet mask, network address, broadcast address, wasted IP addresses and usable host ranges in each network. 2078 Bhadra Q4 · 8
- Suppose your company has leased the IP address of 222.70.94.0/24 from your ISP. Divide it far five different departments containing 50, 30, 25, 12, 10 no of hosts. There are also two points to point links far interconnection between routers. List out the network address, broadcast address, usable IP address range and subnet mask for each subnet. Also mention the unused range of IP addresses. 2076 Chaitra Q4 · 8
- Institute of Engineering has six departments having 16, 32, 61, 8, 6 and 24 computers. Use 192.168.1.0/24 to distribute the network. Find the network address, broadcast address, usable IP range and subnet mask in each department. 2076 Ashwin Q4 · 8
- Suppose you are a private consultant hired by the large company to setup the network for their enterprise and you are given a large number of consecutive. IP address starting at 120.89.96.0/19. Suppose that four departments A, B, C and D request 100, 500, 800 and 400 addresses respectively, how the subnetting can be performed so, that address wastage will be minimum? 2075 Chaitra Q4 · 8
- Design a network for 5 departments containing 29, 14, 15, 23 and 5 computers. Take a network example IP 202.83.54.91/25. 2075 Ashwin Q5 · 8
- How can you dedicate 32, 65, 10, 21, 9 public IP address to the departments A, B, C, D and E respectively form the pool of class C IP addresses with minimum loss. Explain. 2074 Chaitra Q5 · 8
- Suppose you are a private consultant hired by a company to setup the network for their enterprise and you are given a large number of consecutive IP address starting at 120.89.96.0/19. Suppose that four departments A, B, C and D request 100, 500, 800 and 400 addresses respectively, how the subnetting can be performed so that address wastage will be minimum? 2074 Ashwin Q5 · 8
- You are a private contractor hired by the large company to setup the network for their enterprise and you are given a large number of consecutive IP address starting at 202.70.64.0/19. Suppose that four department A, B, C and D request 100, 500, 800 and 400 addresses respectively, how the subnetting can be performed so, that address wastage will be minimum? 2073 Shrawan Q4 · 8
- Explain how can you allocate 30, 24, 25 and 20 IP addresses to the four different department of ABC company with minimum wastage. Specify the range of IP addresses, Broadcast Address, Network Address and Subnet mask for each department form the given address pool 202.77.19.0/24. 2072 Chaitra Q4 · 8
- You are given the following address space 10.10.10.0/24. You have to assign addresses to 4 departments with the following hosts 5, 16, 23 and 27 respectively. Perform the subnetting in such a way that the IP address wastage in each department are minimum. Also find out the subnet mask, network address, broadcast address and unassigned range in each department. 2071 Chaitra Q5 · 10
- How can you dedicate 10, 12, 8, 14 public IP addresses to department A, B, C and D respectively from the pool of class C with minimum losses of IP? Explain. 2070 Chaitra Q5 · 8
- What are the major problems with existing IPv4 network? Explain IPv4 addressing and sub-netting with example. 2070 Ashad Q9 · 4+4
- What is the contribution of sub-netting in IP address management? Show the importance in this case. Banijya bank need to allocate 15 IPs in HR department, 30 in finance department, 24 in customer care unit and 25 in ATM machines. If you have one network of class C range public IP address. Describe how you will manage it. 2069 Chaitra Q4 · 8
- Suppose there are 4 departments A, B, C and D. The department A has 23 hosts, B has 16, C has 28 and D has 13 hosts. You are given a networks 202.70.64.0/24. Perform the subnetting in such a way that the IP address wastage in each department are minimum and also find out the sunbet mask, network address, broadcast, and unable host range in each department. 2068 Chaitra Q8 · 10
- What is a logical address? You are given the IP address block 200.10.80.32/25. If there are five departments which require 5, 40, 28, 12, 6 hosts respectively. Design the subnet. 2068 Baishakh Q4 · 2+6
- If you need to assign IP addresses to all computers of question no. 2 making each department as network. What will be your approach? Explain with IP address ranges you are suggesting. 2067 Ashad Q9 · 8
- Give the reason why the current world is moving to IPv6 addressing mechanism. Describe the IPv6 address types with its representation format. You are given the IPv4 address block 203.71.53.0/26; assign the IP subnet for the following network. [Figure, as text: Net A: 6 Hosts (LAN on router R1); Net B: 2 Hosts (link R1 to R2); Net C: 12 Hosts (LAN on router R2); Net E: 2 Hosts (link R2 to R3); Net F: 29 Hosts (LAN on router R3). The routers are unlabelled in the print and no Net D is drawn.] 2066 Bhadra Q5a · 2+2+6
Classless addressing: CIDR and supernetting PIN 2/27
81 Bh · 74 Ash1+78
CIDR (classless inter-domain routing, RFC 1519 in 1993, now RFC 4632) is what made
it possible. It drops the classes: a block is any power-of-two run of addresses written
a.b.c.d/n, where n, the prefix length, says how many leading bits are the network
part. ISPs could then hand out blocks that fit (a /22 for 1,000 hosts) instead of a whole
class B, and the routing table could shrink.
The rules for a CIDR block: it holds addresses; its first address is divisible by that size (it is aligned); the first address is the network address and the last is the broadcast address.
The rules for supernetting follow from them: the networks must be contiguous, their number must be a power of two, and the first one must sit on a boundary of the combined size.
Given: 192.168.4.0/24, 192.168.5.0/24,
192.168.6.0/24 and 192.168.7.0/24. Their third octets in binary
are 00000100, 00000101, 00000110 and
00000111: the first six bits agree and the last two take all four values.
So the common prefix is 16 + 6 = 22 bits: the supernet is
192.168.4.0/22, mask 255.255.252.0, 1,024 addresses from 192.168.4.0 to
192.168.7.255. One route replaces four.
A trap: 192.168.5.0 to 192.168.8.0 are also four contiguous /24s, but 5 is not a
multiple of 4, so they do not form one /22; the best that can be done is
192.168.5.0/24, 192.168.6.0/23 and
192.168.8.0/24.
Where it is used: an ISP that gives its customers small blocks out of one large block advertises only the large block to the rest of the Internet. A router then picks among overlapping routes by the longest prefix match: the most specific route that matches wins (the routing table).
| Point | Classful address | Classless address (CIDR) |
|---|---|---|
| Network part | fixed by the class: 8, 16 or 24 bits | any length, given by /n |
| Block sizes | only 16,777,216, 65,536 or 256 | any power of two |
| Mask | implied by the first bits | must be carried with the address |
| Waste | large | small: the block fits the need |
| Routing table | one route per classful network | aggregated routes, longest prefix match |
| Example | 192.168.1.0 is class C, so /24 | 192.168.1.0/26 is a block of 64 |
| Point | Subnetting | Supernetting |
|---|---|---|
| Does | divides one network into smaller ones | joins several networks into one larger block |
| Mask | longer than the original (bits borrowed from the host part) | shorter (bits given back from the network part) |
| Purpose | organise and conserve addresses inside an organisation | shrink routing tables between networks |
| Used by | network administrators | ISPs and backbone routers |
To remember it, a bus company in Kathmandu does not list each of the four houses on a lane as a separate stop: it stops once at the lane's mouth. Supernetting is that one stop for four networks; it works only if the houses are next to each other on the same lane.
- What is super-netting? Perform the subnetting of IPv4 address block 200.74.20.0/24 for five different departments having 4, 54, 120, 12 and 30 hosts. List out the network address, broadcast address, usable host range and wasted IP address in each subnet. 2081 Bhadra Q5 · 1+7
- What is classful and classless address? Differentiate between link state and distance vector routing protocol. 2074 Ashwin Q4 · 8
NAT: many private hosts behind one public address
Why it exists: private addresses (RFC 1918) are free but never routed on the Internet, and public IPv4 addresses ran out. NAT lets a whole hostel or office share one or a few public addresses.
- Static NAT: one private address always maps to one public address; used to publish a server.
- Dynamic NAT: private addresses take public ones from a pool while they need them.
- PAT, also NAPT or NAT overload: many private hosts share one public address, told apart by the port number. This is what every home and hostel router does.
How PAT works:
- Outgoing: a laptop at
192.168.1.10, port 51000, opens a web page; the router replaces the source with its public address203.0.113.5and a free port, 62001, and records the pair in its translation table. - Incoming: the reply arrives for
203.0.113.5:62001; the router looks up the table and rewrites the destination back to192.168.1.10:51000. - Timeout: the entry is removed when the connection ends or stays idle.
Inside (private) Outside (public) Remote server 192.168.1.10:51000 -> 203.0.113.5:62001 -> 198.51.100.20:443 192.168.1.11:49200 -> 203.0.113.5:62002 -> 198.51.100.20:443
Gains: saves public addresses; the inside layout stays hidden; the ISP can be
changed without renumbering the inside. Costs: it breaks the end-to-end idea (an
outside host cannot start a connection to an inside one without port forwarding),
complicates peer-to-peer applications, games and VoIP, upsets protocols that carry
addresses inside their data (FTP needs help), and rewriting the header defeats IPsec AH.
ISPs short of addresses run carrier-grade NAT on 100.64.0.0/10 as well, so
a customer may sit behind two NATs.
To remember it, a hostel has one postal address; the hostel office writes the room number on the register when a student posts a letter, and hands each reply to the right room.
Where the private address comes from: the same router usually runs a DHCP server that hands each device its private address, mask, gateway and DNS server (DHCP).
4.4The IP datagram, ARP and ICMP
The IPv4 datagram: the header, fragmentation, and why 65,495 HOT 5/27
76 Ch · 71 Shr · 68 Ba · 67 Asa · 66 Po4+44+1+33+3
What "best effort" means: IP tries to deliver every datagram but sends no acknowledgements, keeps no connection and retransmits nothing. A datagram can be lost, duplicated, delayed or overtaken by a later one, and only its header is checked for errors. Reliability is added above it by TCP (TCP) where an application needs it; problems are reported by ICMP (ICMP). Posting ordinary letters without registered post is the same service.
What IP does: addresses every datagram (source and destination), forwards it hop by hop by routing tables, fragments it when a link's MTU is too small, limits its lifetime with TTL, and tells the destination which upper-layer protocol gets the data.
The header is drawn in rows of 32 bits, the way the standard draws it: five fixed rows make the minimum 20 bytes, and options can add up to 40 more.
| Field | Bits | What it does |
|---|---|---|
| Version | 4 | 4 for IPv4 (6 for IPv6), so the receiver parses the right format |
| IHL (header length) | 4 | header length in 32-bit words: 5 (20 bytes) to 15 (60 bytes) |
| Type of service | 8 | how to treat the packet; today 6 bits of DSCP for quality of service and 2 bits of ECN for congestion signals |
| Total length | 16 | header plus data in bytes: at most = 65,535 |
| Identification | 16 | one number shared by every fragment of the same datagram |
| Flags | 3 | a reserved 0, DF (do not fragment) and MF (more fragments follow) |
| Fragment offset | 13 | where this fragment's data belongs in the original, in units of 8 bytes |
| Time to live (TTL) | 8 | hop limit: every router subtracts 1 and drops the datagram at 0 |
| Protocol | 8 | which protocol the data belongs to: 1 ICMP, 2 IGMP, 6 TCP, 17 UDP, 89 OSPF |
| Header checksum | 16 | error check over the header only; recomputed at every hop because TTL changes |
| Source address | 32 | the sender's IP address |
| Destination address | 32 | the final receiver's IP address |
| Options and padding | 0 to 320 | rarely used (record route, timestamp, source route); padded to a whole 32-bit word |
TTL and the protocol field, the two most asked:
- TTL limits a datagram's lifetime so that one caught in a routing loop dies instead of circling for ever. Each router subtracts 1; a router that brings it to 0 discards the datagram and sends ICMP "time exceeded" to the source. Senders start it at 64 (Linux), 128 (Windows) or 255 (many routers), so no datagram crosses more than 255 routers. Traceroute uses it on purpose (ICMP).
- Protocol tells the destination which upper-layer module gets the data: it is the network layer's own demultiplexing number, as a port number is the transport layer's. With 6 the data goes to TCP, with 17 to UDP, with 1 to ICMP; IPsec uses 50 (ESP) and 51 (AH).
Fragmentation and reassembly. Every link has an MTU (maximum transmission unit), the largest datagram its frame can carry: 1,500 bytes on Ethernet. A datagram can be up to 65,535 bytes, so a router that must send one onto a link with a smaller MTU splits it into fragments:
- Check DF: if the do-not-fragment flag is set, the router drops the datagram and sends ICMP "fragmentation needed" back, with the link's MTU (path MTU discovery uses this to find the largest size that fits).
- Split the data into pieces that fit the MTU after the header; every piece but the last must be a multiple of 8 bytes.
- Copy the header onto each piece with the same Identification, its own Total length, MF = 1 on every fragment but the last, and Fragment offset = the piece's first byte position divided by 8.
- Send the fragments as independent datagrams; a later router may fragment them again.
- Reassemble only at the destination host: it gathers the fragments with the same source, destination, protocol and Identification, puts them in order by offset, knows the last one by MF = 0, and runs a reassembly timer. If any fragment is still missing when it expires, the whole datagram is thrown away.
Given: total length 4,000 bytes (20 of header, 3,980 of data), Identification 4321, next link's MTU 1,500. Each fragment can carry 1,500 minus 20 = 1,480 bytes of data, which is a multiple of 8 (185 times 8).
| Fragment | Data bytes | Bytes of the original data | Offset field | MF | Total length |
|---|---|---|---|---|---|
| 1 | 1,480 | 0 to 1,479 | 0 | 1 | 1,500 |
| 2 | 1,480 | 1,480 to 2,959 | 185 | 1 | 1,500 |
| 3 | 1,020 | 2,960 to 3,979 | 370 | 0 | 1,040 |
Check: 1,480 + 1,480 + 1,020 = 3,980 bytes of data; the offsets are 0, 1,480 and 2,960 divided by 8. All three carry Identification 4321.
Why fragment at the destination only: fragments may take different paths, so no router in the middle is sure to see them all. IPv6 goes further: routers never fragment, only the source does (the IPv6 header).
Why the largest TCP payload is the odd number 65,495 bytes. A TCP segment travels inside one IP datagram, and the 16-bit Total length field caps a datagram at 65,535 bytes, header included. Take away the smallest IPv4 header (20 bytes) and the smallest TCP header (20 bytes):
For UDP, whose header is 8 bytes, the same sum gives 65,535 minus 20 minus 8 = 65,507 bytes. On Ethernet the MTU of 1,500 cuts a segment to 1,500 minus 40 = 1,460 bytes of data, which is the usual TCP maximum segment size.
- What is the purpose of Time to live (TTL) and protocol field in header of IPv4 datagram. Which protocol is used in internet layer to provide feedback to hosts/routers about the problems in the network environment? What is ARP and how does it work? 2076 Chaitra Q5 · 4+1+3
- Write short notes on: (any two) a) ARP b) ICMP c) IP 2071 Shrawan Q5 · 4+4
- What is a fragmentation and re-assembly? Explain about any intra-AS routing protocol. 2068 Baishakh Q6 · 3+5
- What are the advantages of IPV6? The maximum payload segment is 65495 byte. Why was such strange number chosen? 2068 Baishakh Q7 · 4+4
- Explain in detail about IP frame format. 2067 Ashad Q8 · 8
- Write short notes on (any two): a) UDP and its application b) Network Devices: Hubs, Switches and Routers c) IPv4 Header Structure 2066 Poush Q10 · 3+3
ARP and RARP: from IP address to MAC address and back PIN 4/27
82 Bh · 80 Ba · 76 Ch · 71 Shr2×44+1+34+4
Why it is needed: a frame can only be delivered to a MAC address, but software knows only the IP address of the next hop. If the destination is on the sender's own subnet, the sender asks for the destination's MAC; if not, it asks for the MAC of its default gateway (the router), never for the distant host.
How it works, for a laptop at 192.168.1.10 printing to a printer at
192.168.1.20 on the same LAN:
- Check the cache: the laptop looks for 192.168.1.20 in its ARP cache; there is no entry, so the IP packet waits.
- Broadcast a request: it sends an ARP request in an Ethernet frame to the
broadcast address
ff:ff:ff:ff:ff:ff(EtherType 0x0806): "who has 192.168.1.20? Tell 192.168.1.10", carrying its own IP and MAC address. - Only the owner answers: every host on the LAN receives the request; the others drop it, and the printer, which owns 192.168.1.20, keeps the laptop's mapping for later.
- Unicast reply: the printer sends an ARP reply straight to the laptop's MAC: "192.168.1.20 is at 3c:52:82:10:aa:07".
- Cache and send: the laptop stores the pair, with a timeout, and sends the waiting packet in a frame addressed to the printer's MAC. Later packets skip the request altogether.
| ARP packet field | Size | For IPv4 over Ethernet |
|---|---|---|
| Hardware type | 2 bytes | 1 (Ethernet) |
| Protocol type | 2 bytes | 0x0800 (IPv4) |
| Hardware and protocol address lengths | 1 byte each | 6 and 4 |
| Operation | 2 bytes | 1 request, 2 reply |
| Sender MAC, sender IP | 6 + 4 bytes | the asker's addresses |
| Target MAC, target IP | 6 + 4 bytes | MAC all zeros in a request; the IP being asked about |
The whole ARP packet is 28 bytes, carried straight in an Ethernet frame, not inside
IP. The command arp -a shows the cache on Windows and Linux.
- Gratuitous ARP: a host announces its own mapping (when it boots or changes its card), to refresh others' caches and to detect a duplicate address.
- Proxy ARP: a router answers on behalf of hosts on another network.
- ARP spoofing: ARP has no authentication, so an attacker on the LAN can answer with its own MAC and pull traffic through itself; switches defend with dynamic ARP inspection, and critical hosts can use static entries.
RARP (Reverse ARP, RFC 903) does the opposite: a diskless workstation that knows only its own MAC broadcasts "what is my IP address?", and a RARP server on the same LAN replies. It needs a server on every network (its broadcast cannot cross a router) and returns only an IP address (no mask, no gateway), so BOOTP and then DHCP replaced it (DHCP).
NDP, ARP's IPv6 replacement. IPv6 has no ARP and no broadcast. Its Neighbour Discovery Protocol (RFC 4861) does the same job with ICMPv6 messages, and several more jobs besides:
| Point | ARP (IPv4) | NDP (IPv6) |
|---|---|---|
| Defined in | RFC 826, 1982 | RFC 4861, 2007 |
| Carried in | its own Ethernet frame type, 0x0806 | ICMPv6 messages inside IPv6 |
| Request sent to | broadcast: every host on the LAN | solicited-node multicast: only hosts whose address ends in the same 24 bits |
| Messages | request, reply | neighbour solicitation and advertisement (135, 136), router solicitation and advertisement (133, 134), redirect (137) |
| Jobs | address resolution only | address resolution, finding routers and prefixes, autoconfiguration (SLAAC), duplicate address detection, checking a neighbour is still reachable, redirect |
| Security | none: spoofing is easy | can be protected with SEND (RFC 3971) |
To remember it, a teacher who knows only roll numbers calls out in class, "who is roll 20?" (the broadcast); only roll 20 stands up (the reply), and the teacher remembers the face (the cache). RARP is a student asking the class, "what is my own roll number?"
- Write short notes on: (Any Two) a) ARP and NDP b) AH and ESP c) VPN d) vLAN 2082 Bhadra Q10 · 2×4
- Write short notes on: (Any Two) a) VLAN b) ARP c) IPSec 2080 Baishakh Q10 · 2×4
- What is the purpose of Time to live (TTL) and protocol field in header of IPv4 datagram. Which protocol is used in internet layer to provide feedback to hosts/routers about the problems in the network environment? What is ARP and how does it work? 2076 Chaitra Q5 · 4+1+3
- Write short notes on: (any two) a) ARP b) ICMP c) IP 2071 Shrawan Q5 · 4+4
ICMP: the network layer's error reports and queries HOT 5/27
81 Ba · 76 Ch · 71 Shr · 66 Po · 66 Bh84+1+33+3
Why it exists: IP is best effort and has no way of its own to say what went wrong, so without ICMP a datagram that could not be delivered would simply vanish. ICMP is the protocol of the internet layer that gives hosts and routers feedback about problems in the network.
The message format: every ICMP message starts with a type (8 bits: which message), a code (8 bits: the reason within that type) and a checksum (16 bits, over the whole ICMP message), then 32 bits whose use depends on the type (an identifier and a sequence number in an echo). An error message then carries the IP header and the first 8 bytes of data of the datagram that caused it: enough for the source to see which connection failed, since those 8 bytes hold the TCP or UDP port numbers.
Error-reporting messages, sent back to the source of a datagram that had a problem:
| Type | Message | Sent when | Codes |
|---|---|---|---|
| 3 | Destination unreachable | a router cannot reach the network or host, or the host has no process on that port | 0 network, 1 host, 2 protocol, 3 port, 4 fragmentation needed but DF set, 13 blocked by policy |
| 4 | Source quench | a congested router asked the source to slow down (withdrawn by RFC 6633 in 2012) | 0 |
| 11 | Time exceeded | TTL reached 0 in a router, or the reassembly timer ran out | 0 TTL, 1 reassembly |
| 12 | Parameter problem | a header field is wrong or a needed option is missing | a pointer to the bad byte |
| 5 | Redirect | a router sees that a host on the same network should use another router | for a network or a host |
Query (informational) messages come in request and reply pairs:
| Types | Pair | Used for |
|---|---|---|
| 8 and 0 | Echo request and echo reply | ping: is the host alive, and the round-trip time |
| 13 and 14 | Timestamp request and reply | round-trip time and the difference between two clocks |
| 17 and 18 | Address mask request and reply | a host asking its subnet mask (now done by DHCP) |
| 10 and 9 | Router solicitation and advertisement | a host finding the routers on its network |
Rules that stop ICMP making things worse: no error message is sent about an ICMP error message, about any fragment but the first, about a datagram sent to a broadcast or multicast address, or about one whose source is a special address such as 0.0.0.0 or 127.0.0.1. Without them, one fault could set off a storm of messages.
Its importance and uses in TCP/IP:
- Error feedback to the transport layer: an unreachable message tells TCP or UDP why its data is not getting through, so the application can report "port unreachable" (nothing is listening) or "host unreachable" instead of waiting blindly; RFC 1122 makes TCP abort a connection on "protocol unreachable" or "port unreachable".
- ping: echo request and reply test whether a host is reachable and measure the round-trip time.
- traceroute: probes are sent with TTL 1, 2, 3 and so on; each router where the TTL
runs out answers "time exceeded", which reveals the path hop by hop. Windows'
tracertuses echo requests; Unixtracerouteuses UDP probes and stops at the destination's "port unreachable". - Path MTU discovery: TCP sets DF, and "fragmentation needed" messages tell it the largest datagram the path can carry, so it never needs fragmenting.
- Better routes: redirect corrects a host's choice of first router; router solicitation and advertisement find routers.
- Network management: monitoring tools ping every device to see what is up.
C:\> tracert -d 203.0.113.10 1 1 ms 1 ms 1 ms 192.168.1.1 2 5 ms 6 ms 5 ms 198.51.100.1 3 17 ms 18 ms 17 ms 198.51.100.77 4 20 ms 21 ms 20 ms 203.0.113.10
Reading it: the first probes leave with TTL 1, which dies at the home router; it answers "time exceeded" and becomes line 1. TTL 2 dies at the ISP's router (line 2), TTL 3 one router further. The fourth set reaches the server itself, which answers with an echo reply, and the trace stops. Each line shows three probes' round-trip times.
Security: firewalls often block echo requests to hide hosts, but blocking all ICMP breaks path MTU discovery and leaves connections that hang on large packets; the safe rule is to let the error messages through.
To remember it, ICMP is the returned-letter slip of the post office: it does not deliver anything itself, it tells the sender why the letter came back ("no such address", "took too long", "wrong format").
- What is ICMP? Explain the importance and uses of ICMP in TCP/IP protocol suit. 2081 Baishakh Q5 · 8
- What is the purpose of Time to live (TTL) and protocol field in header of IPv4 datagram. Which protocol is used in internet layer to provide feedback to hosts/routers about the problems in the network environment? What is ARP and how does it work? 2076 Chaitra Q5 · 4+1+3
- Write short notes on: (any two) a) ARP b) ICMP c) IP 2071 Shrawan Q5 · 4+4
- Briefly describe ICMP error and informational message types in IPv4 network infrastructure. 2066 Poush Q8 · 8
- Write short notes on (any two) i) TCP Sliding Window Protocol ii) Secrete Key Algorithm: DES iii) ISDN Signaling and ATM AAL iv) ICMP Message Types 2066 Bhadra Q5b · 3+3
4.5Routing
Routing: what it is, what a good algorithm needs, static against dynamic TOP 13/27
82 Ba · 81 Bh · 79 Bh · 78 Bh · 76 Ash · 75 Ch · 75 Ash · 74 Ch · 72 Ch · 71 Shr · 70 Asa · 67 Asa · 66 Bh2+63+54+4
Routing against forwarding. A router runs two jobs. Forwarding handles each packet as it arrives: look up the destination in the table, send the packet out of the right interface, in microseconds. Routing fills in and updates that table: it runs the routing algorithm, talks to other routers, and reacts to failures, over seconds or minutes. Forwarding is the driver following the signs; routing is the department that puts the signs up.
Why routing is essential:
- Delivery beyond one network: a packet for another network can only arrive if every router on the way knows the next hop; without routing tables the Internet is a set of islands.
- Many possible paths: networks are meshes, and routing picks the best path by the chosen metric (hops, delay, bandwidth, cost).
- Survival: when a link or router fails, dynamic routing finds another path without anyone touching the routers.
- Efficiency: good routes spread the load, cut delay and avoid congested links.
- Scale and policy: routes to whole networks, aggregated, keep tables small; between organisations, routing carries their policies (who may carry whose traffic).
The properties (goals) of a good routing algorithm, which Tanenbaum lists and the papers ask as "criteria":
- Correctness: it must deliver every packet to the right destination.
- Simplicity: little computation and few messages, so routers stay fast.
- Robustness: it must keep working through router and link failures and topology and load changes, for years, without rebooting the whole network.
- Stability: it must settle on fixed routes quickly (converge) and not swing between paths or form loops.
- Fairness: every source-destination pair gets reasonable service, not only the nearby ones.
- Optimality (efficiency): it minimises the mean delay or maximises the total throughput. Fairness and optimality pull apart: starving long flows can raise throughput, so a balance is struck.
Adaptive and non-adaptive routing are the two routing techniques:
| Point | Non-adaptive (static) | Adaptive (dynamic) |
|---|---|---|
| Routes chosen | in advance, offline, and entered by the administrator | continuously by the routers, from the current topology and load |
| On a failure | nothing changes until someone edits the table | reroutes on its own |
| Methods | static and default routes; flooding | distance vector and link state: RIP, OSPF, EIGRP, BGP |
| Overhead | no routing traffic, little CPU and memory | updates use bandwidth, CPU and memory |
| Security | higher: nothing is advertised | lower: routing messages can be forged unless authenticated |
| Suits | small, stable networks; a branch with one link out | large networks with many paths |
Adaptive algorithms differ in where they get their information (only locally, from their neighbours, or from every router), when they change routes (on a timer, or when the topology or load changes) and what they measure (distance, hops, delay). A static route is still the right answer where there is no choice: the single link from a campus to its ISP is a static default route.
Routed and routing protocols are easy to confuse:
| Point | Routed protocol | Routing protocol |
|---|---|---|
| What it is | a network protocol whose packets carry user data and get routed | a protocol routers use to swap route information and build their tables |
| It provides | addresses for hosts and a packet format | the paths: which networks exist and how far |
| Used by | hosts and routers | routers only |
| Examples | IPv4, IPv6 (once IPX and AppleTalk) | RIP, OSPF, EIGRP, IS-IS, BGP |
In short, the routing protocol prepares the roads; the routed protocol is the traffic on them. RIP messages themselves travel inside routed IP datagrams.
The optimality principle. If router J is on the optimal path from router I to router K, then the optimal path from J to K falls along the same route. Call the part from I to J r1 and the rest r2: if a better route than r2 existed from J to K, joining it to r1 would give a better route from I to K, which contradicts r1r2 being optimal.
Its consequence is the sink tree: the optimal routes from every router to one destination together form a tree rooted at that destination. A tree has no loops, so every packet arrives in a finite number of hops, and the job of a routing algorithm is to find and use the sink trees of all destinations. If the shortest bus route from Kalanki to Pulchowk passes Balkhu, the shortest route from Balkhu to Pulchowk is the rest of that same route.
Autonomous system (AS): a group of networks and routers under one administration that shows the Internet one routing policy, identified by an AS number (16 bits, 1 to 65,535 at first; 32 bits since 2007, RFC 4893, now RFC 6793). An ISP, a university or a large bank can each be one. Inside an AS, the administration picks its own interior gateway protocol (IGP: RIP, OSPF, EIGRP, IS-IS); between ASes, all use the one exterior gateway protocol, BGP (routing protocols). A stub AS has one link out, a multihomed AS several providers, and a transit AS (an ISP) carries other ASes' traffic. Nepal's larger ISPs each run their own AS and exchange local traffic at the Nepal Internet Exchange (NPIX) over BGP.
To remember it, a microbus route is static routing: the same stops every day even if a road is blocked. A traffic police officer at Kalanki who waves cars onto the ring road when the main road jams is adaptive routing.
- Define routed and routing protocol. Explain RIP routing operation with is timer details. 2082 Baishakh Q4 · 2+6
- What is adaptive and non-adaptive routing? List the properties of link state routing and mention the method that how Designated Router (DR) is elected in OSPF routing. 2081 Bhadra Q4 · 2+2+4
- Why do we prefer a switch as networking device instead of Hub for LAN connection? Give reasons. Discuss the characteristics of a good routing algorithm. 2079 Bhadra Q4 · 4+4
- Define routing algorithm. List out the properties/goals of routing algorithm. What is link state routing algorithm? Show how routing tables is populated in LSR with example. 2078 Bhadra Q5 · 3+5
- What is routing? Differentiate between distance vector and link state routing algorithms. 2076 Ashwin Q5 · 2+6
- What do you mean by autonomous system? Explain how routing loops are prevented in Distance Vector Routing with examples. 2075 Chaitra Q5 · 2+6
- Why routing is essential in computer networking? Compare working of distance vector routing algorithm with link state routing algorithm. 2075 Ashwin Q4 · 3+5
- Mention the criteria for good routing. Explain RIP, OSPF, BGP, IGRP and EIGRP. 2074 Chaitra Q4 · 2+6
- What is routed and routing protocol? Give examples. Explain Token Bucket algorithm. 2072 Chaitra Q5 · 4+4
- What is routing? Differentiate between link state routing and distance vector routing. 2071 Shrawan Q4 · 2+6
- Differentiate between adaptive and non-adaptive routing. Explain shortest path finding algorithm in link state routing. 2070 Ashad Q7 · 3+5
- Why routing is essential in computer networking? Compare working of distance vector routing algorithm with link state routing algorithm. 2067 Ashad Q7 · 2+6
- What is unicast and multicast routing? Describe the concept of optimality principle. Describe how the routers in its link state routing come into fully adjacency state. 2066 Bhadra Q4a · 2+6
The routing table, and forwarding with classful addresses
- Destination and mask: the network the route leads to. Routes name networks, not hosts, which is what keeps tables small (next-hop and network-specific routing).
- Next hop: the IP address of the neighbouring router to hand the packet to; empty for a directly connected network, where the packet goes straight to the host.
- Interface: the port to send it out of.
- Metric: the route's cost (hops for RIP, cost for OSPF), to choose between routes.
- Source: connected, static (typed in by an administrator) or learned by a routing protocol; dynamic entries time out if not refreshed.
- Default route (
0.0.0.0with mask0.0.0.0): the route of last resort, used when nothing else matches; a stub network often needs nothing else.
Forwarding with classful addresses. In a classful network the mask is implied by the address, so a router finds the destination's class from the first octet, applies the default mask, and looks the network up:
Router R1 Destination Mask Next hop Interface Source 10.0.0.0 255.0.0.0 (direct) Gi0/0 connected 172.16.0.0 255.255.0.0 (direct) Gi0/1 connected 192.168.1.0 255.255.255.0 (direct) Se0/0/0 connected 192.168.2.0 255.255.255.0 192.168.1.2 Se0/0/0 RIP, 1 hop 0.0.0.0 0.0.0.0 192.168.1.2 Se0/0/0 static default
- To 172.16.40.9: 172 lies in 128 to 191, so class B, mask 255.255.0.0, network 172.16.0.0: directly connected on Gi0/1, so R1 delivers it to the host (after ARP for 172.16.40.9).
- To 192.168.2.77: class C, network 192.168.2.0: send to next hop 192.168.1.2 through Se0/0/0.
- To 203.0.113.50: class C, network 203.0.113.0: no entry, so the default route sends it to 192.168.1.2.
Classless tables carry a mask with every route, and routes can overlap. The router
then takes the longest prefix match: with routes to 10.0.0.0/8 via A,
10.1.0.0/16 via B and 10.1.2.0/24 via C, a packet to 10.1.2.5 goes
to C, one to 10.1.9.9 to B, and one to 10.200.0.1 to A. The default route, /0, matches
everything and always loses to anything longer.
A static route by hand, in Cisco's syntax: ip route 192.168.2.0
255.255.255.0 192.168.1.2; a default route: ip route 0.0.0.0 0.0.0.0
192.168.1.2. On a computer, route print (Windows) or ip
route (Linux) shows the host's own small table: its subnet, and a default route to
the gateway.
To remember it, the routing table is the board at a bus park that says which counter sells tickets for which district; "everything else, counter 1" is the default route.
4.6Routing algorithms
Dijkstra's shortest path algorithm, worked on a graph PIN 1/27
70 Asa3+5
Where routing uses it: in link state routing every router holds the whole graph (routers as nodes, links as edges weighted by cost) and runs Dijkstra with itself as the source; the result, its shortest path tree, gives the first hop to every destination (link state routing). OSPF and IS-IS call it the SPF (shortest path first) calculation.
The steps, with a label (distance, previous node) on every node:
- Start: the source gets the label (0, none) and is made permanent; every other node is (infinity, none).
- Relax: for each neighbour of the node just made permanent, add the link's cost to that node's distance; if the sum is smaller than the neighbour's label, relabel it (new distance, via this node). These labels are tentative.
- Fix the nearest: among all tentative nodes, make the one with the smallest distance permanent; it is the new working node.
- Repeat steps 2 and 3 until the destination (or every node) is permanent.
- Read the path backwards from the destination through the "via" fields.
Given the graph above: A-B 2, A-G 6, B-C 7, B-E 2, E-F 2, E-G 1, F-C 3, F-H 2, G-H 4, C-D 3, H-D 2. A packet goes from A to D.
| Step | Made permanent | Tentative labels after the step |
|---|---|---|
| 1 | A (0) | B (2, A), G (6, A) |
| 2 | B (2, A) | G (6, A), E (4, B), C (9, B) |
| 3 | E (4, B) | G (5, E), F (6, E), C (9, B) |
| 4 | G (5, E) | F (6, E), C (9, B), H (9, G) |
| 5 | F (6, E) | C (9, B), H (8, F) |
| 6 | H (8, F) | C (9, B), D (10, H) |
| 7 | C (9, B) | D (10, H) |
| 8 | D (10, H) | none left |
Reading back from D: D came via H, H via F, F via E, E via B, B via A. The shortest path is A, B, E, F, H, D, with cost 2 + 2 + 2 + 2 + 2 = 10.
Two details: in step 3, G's label falls from (6, A) to (5, E), because A-B-E-G costs 5 against the direct link's 6; in step 5, F offers C at 6 + 3 = 9, which ties B's offer, so the label stays (9, B). C is made permanent after H, but too late to help: its route to D costs 9 + 3 = 12.
Cost of the algorithm: with N nodes, the simple version does about steps; with a priority queue it does about for E links, which is why routers can run it in milliseconds. It needs costs that are not negative. Distance vector routing uses the Bellman-Ford method instead, which works out the same shortest paths piece by piece across the routers (distance vector).
To remember it, think of a fire spreading from A through dry grass along the links, at one metre a second for every unit of cost: the order in which the nodes catch fire is the order Dijkstra makes them permanent, and each node's fire came along its shortest path.
- Differentiate between adaptive and non-adaptive routing. Explain shortest path finding algorithm in link state routing. 2070 Ashad Q7 · 3+5
Flooding: send every packet out of every line
Its problem is duplicates: on any network with loops, each copy is copied again at the next router, and the number of packets grows without end. Three ways damp it:
- Hop counter: the packet carries a counter, set at the source to the length of the path (or the network's diameter if that is unknown); each router subtracts 1 and drops the packet at 0. The book's example floods with a hop count of 3: first, second and third hops.
- Sequence numbers: the source numbers each packet; every router keeps, per source, the numbers it has already seen and drops repeats. This is how link state packets are flooded (link state).
- Selective flooding: a router sends the packet only on the lines that lead roughly the right way.
Why use it at all:
- Delivery is all but certain: if any path exists, a copy finds it, so flooding suits networks that must survive heavy damage (the military idea behind the early ARPANET).
- It always finds the shortest path, since it tries every path at once; the first copy to arrive took it. That makes flooding a benchmark for other algorithms.
- It needs no knowledge of the network, so it is how information is spread before anyone knows the topology: link state packets and broadcasts.
Its cost is the bandwidth spent on copies, so it is never used for ordinary traffic.
To remember it, it is a rumour in a village: each person tells everyone they meet except the one who told them, and to stop it going round for ever each person repeats it only once.
Distance vector routing, count to infinity, and loop prevention TOP 10/27
80 Ba · 76 Ash · 75 Ch · 75 Ash · 74 Ash · 73 Shr · 72 Ka · 71 Shr · 68 Ch · 67 Asa2+62+2+42×5
Three keys describe it: each router shares knowledge about the whole network; it shares it only with its neighbours; and it shares it at regular intervals (RIP every 30 seconds). It is sometimes called routing by rumour: a router believes what its neighbours say about distant networks.
The update rule: router x's distance to destination y is the smallest, over its neighbours v, of the cost of reaching v plus v's own distance to y:
In practice: when a neighbour's table arrives, add the cost of the link to that neighbour to every entry; for each destination, keep the new route if it is shorter than the current one, or if it comes from the neighbour already used as next hop (that neighbour's news about its own route is always accepted, good or bad).
Given: six routers join seven networks. A is on networks 14, 78 and 23; its neighbours are B (on 14 and 55), E (on 08 and 23) and F (on 78 and 92). Each router starts knowing only its own networks, at distance 1. A receives the three neighbours' tables and adds one hop to each entry:
| Network | A's old table | From B, +1 | From E, +1 | From F, +1 | A's new table |
|---|---|---|---|---|---|
| 08 | none | none | 2, E | none | 2, via E |
| 14 | 1, direct | 2, B | none | none | 1, direct |
| 23 | 1, direct | none | 2, E | none | 1, direct |
| 55 | none | 2, B | none | none | 2, via B |
| 78 | 1, direct | none | none | 2, F | 1, direct |
| 92 | none | none | none | 2, F | 2, via F |
Network 66 is not in A's table yet, because no neighbour knows it; it arrives in the next round, at 3 hops (through B or through E). A few rounds later no table changes any more: the network has converged.
Count to infinity. Good news spreads fast, bad news slowly. Take three routers in a line, A, B and C, with network N attached to C: C reaches N at 1 hop, B at 2 (via C), A at 3 (via B). Now C's link to N fails:
- C loses N, but before it can tell anyone, B's regular update arrives saying "N, 2 hops". C believes it and records N at 3 hops via B, not knowing that B's route runs through C itself.
- B hears C's 3 and, since C is its next hop for N, accepts it: 4 hops. C then hears 4 and goes to 5, B to 6, and so on: the two count upward while packets for N bounce between them, a routing loop.
- It ends only at "infinity": RIP calls 16 hops unreachable, so after about 14 exchanges both routers finally mark N as gone.
How routing loops are prevented, each with the same example:
- Maximum hop count: defining infinity as a small number (16 in RIP) makes the counting stop, at the price of limiting the network to 15 hops.
- Split horizon: a router never advertises a route back out of the interface it learned it from. B learned N from C, so B never tells C about N; when C loses N, there is no false news for it to believe.
- Split horizon with poison reverse: B does advertise N back to C, but with metric 16 ("do not reach N through me"). It kills the loop at once, at the cost of larger updates.
- Route poisoning: C advertises N with metric 16 the moment it fails, instead of just deleting it, so the bad news travels as fast as good news.
- Triggered updates: a router sends an update as soon as a route changes, without waiting for the 30 second timer.
- Hold-down timers: once a route goes bad, the router ignores any news of a worse route to it for a while (RIP: 180 seconds), so stale information still circulating cannot bring it back; only better news, or the timer's end, is accepted.
Split horizon is not enough everywhere: in a loop of three or more routers, a router can hear the false route from a neighbour it did not learn it from (Tanenbaum's example). Hold-down timers and triggered updates cover that case, and link state routing avoids the problem altogether.
Strengths and weaknesses: it is simple and needs little memory or CPU, but it converges slowly, can loop while converging, usually counts hops whatever the link speed, and sends whole tables even when nothing has changed. The ARPANET used it until 1979, then switched to link state; RIP and IGRP are distance vector protocols, and EIGRP is an advanced one (RIP, routing protocols).
To remember it, think of villagers giving directions by rumour: each tells only the next village how far it thinks the bazaar is. When the bridge to the bazaar falls, the village beside it says "closed", but the next village still repeats "two hours from here", and the rumour of a road that no longer exists goes round the hills for days.
- What is unicast and multicast? Compare distance vector routing protocol and link state routing protocol with examples. 2080 Baishakh Q4 · 4+4
- What is routing? Differentiate between distance vector and link state routing algorithms. 2076 Ashwin Q5 · 2+6
- What do you mean by autonomous system? Explain how routing loops are prevented in Distance Vector Routing with examples. 2075 Chaitra Q5 · 2+6
- Why routing is essential in computer networking? Compare working of distance vector routing algorithm with link state routing algorithm. 2075 Ashwin Q4 · 3+5
- What is classful and classless address? Differentiate between link state and distance vector routing protocol. 2074 Ashwin Q4 · 8
- Discuss about the network congestion? Explain how different network parameters effect the congestion. Compare operation of link state routing with the distance vector routing. 2073 Shrawan Q5 · 2+2+4
- Network layer is one of the key layers in OSI reference model, why? Differentiate between distance vector routing and static link routing. 2072 Kartik Q5 · 2+6
- What is routing? Differentiate between link state routing and distance vector routing. 2071 Shrawan Q4 · 2+6
- Differentiate: a) Distance vector and link state routing algorithm b) Circuit switching and packet switching 2068 Chaitra Q5 · 2×5
- Why routing is essential in computer networking? Compare working of distance vector routing algorithm with link state routing algorithm. 2067 Ashad Q7 · 2+6
Link state routing: properties, five steps, and distance vector compared TOP 11/27
81 Bh · 80 Ba · 78 Bh · 76 Ash · 75 Ash · 74 Ash · 73 Shr · 72 Ka · 71 Shr · 68 Ch · 67 Asa2+62+2+43+5
Three keys, the mirror image of distance vector: each router shares knowledge about its neighbourhood only (not its routing table); it shares it with every router (by flooding, not only with neighbours); and it shares it when there is a change (plus a slow refresh), not every few seconds.
Its properties:
- Full topology: every router builds the same link state database, the complete graph of its area.
- Independent computation: each router runs Dijkstra itself, so one router's error does not spread as rumour.
- Fast convergence, no count to infinity: a change is flooded at once, and loops are rare.
- Real costs: the metric is a cost from bandwidth or delay, not a hop count.
- Low traffic when stable, but more memory (the database) and CPU (Dijkstra) than distance vector.
- Scales with hierarchy: large networks are divided into areas (OSPF, IS-IS).
The five steps every router follows:
- Discover its neighbours: send a HELLO packet on each link; each neighbour replies with its router ID.
- Measure the cost to each neighbour: by delay (time an ECHO packet's round trip) or, more usually, by a cost set from the link's bandwidth.
- Build a link state packet (LSP): its own ID, a sequence number, an age, and the list of neighbours with the cost of each link.
- Flood the LSP to every router: each router forwards a new LSP on all its other links; the sequence number lets it drop duplicates and old copies, and the age makes stale LSPs expire.
- Compute the shortest paths: with every LSP in hand, the router has the whole graph; it runs Dijkstra from itself and puts the first hop of each path in its routing table.
Given five routers and their links: A-B 2, A-C 1, B-C 2, B-D 3, C-E 4, D-E 1. After steps 1 to 3, each router's LSP lists its neighbours:
| LSP of | A | B | C | D | E |
|---|---|---|---|---|---|
| Neighbours and costs | B 2, C 1 | A 2, C 2, D 3 | A 1, B 2, E 4 | B 3, E 1 | C 4, D 1 |
Step 4: flooding gives every router all five LSPs, the same database. Step 5: A runs Dijkstra from itself: permanent in turn are C (1), B (2), D (5, via B) and E (5, via C). A's routing table holds only the first hop of each path:
| Destination | Cost | Path | Next hop |
|---|---|---|---|
| B | 2 | A, B | B |
| C | 1 | A, C | C |
| D | 5 | A, B, D | B |
| E | 5 | A, C, E | C |
If the D-E link fails, D and E flood new LSPs; every router reruns Dijkstra at once, and no router ever counts to infinity.
Distance vector against link state, the comparison set in ten sittings:
| Point | Distance vector | Link state |
|---|---|---|
| What a router knows | only distances and next hops, as its neighbours report them | the whole topology of its area (the link state database) |
| What it sends | its whole routing table | only the state of its own links (an LSP) |
| To whom | its neighbours only | every router, by flooding |
| When | periodically (RIP every 30 s), plus triggered updates | when a link changes, plus a slow refresh (OSPF every 30 minutes) |
| Algorithm | Bellman-Ford, shared across the routers | Dijkstra, run by each router on its own copy |
| Convergence | slow; count to infinity possible | fast; no count to infinity |
| Routing loops | possible while converging; need split horizon, hold-down | rare: every router computes from the same map |
| Metric | usually hop count | a cost from bandwidth or delay |
| Memory and CPU | little | more: the database and Dijkstra |
| Bandwidth when stable | wasted on periodic full tables | little: only hellos and refreshes |
| Scale and setup | small networks (RIP: 15 hops); simple | large networks, with areas; more complex |
| Examples | RIP, IGRP (EIGRP is an advanced distance vector) | OSPF, IS-IS |
With examples: a small office of four routers runs RIP happily, configured in minutes; an ISP or a large campus runs OSPF or IS-IS, whose areas keep the databases small and whose instant flooding reroutes around a cut fibre in well under a second, where RIP could take minutes.
To remember the difference, distance vector is villagers passing on directions by word of mouth; link state is every village sending its own sketch of nearby roads to all the others, so that each holds the full district map and plans its own trips.
- What is adaptive and non-adaptive routing? List the properties of link state routing and mention the method that how Designated Router (DR) is elected in OSPF routing. 2081 Bhadra Q4 · 2+2+4
- What is unicast and multicast? Compare distance vector routing protocol and link state routing protocol with examples. 2080 Baishakh Q4 · 4+4
- Define routing algorithm. List out the properties/goals of routing algorithm. What is link state routing algorithm? Show how routing tables is populated in LSR with example. 2078 Bhadra Q5 · 3+5
- What is routing? Differentiate between distance vector and link state routing algorithms. 2076 Ashwin Q5 · 2+6
- Why routing is essential in computer networking? Compare working of distance vector routing algorithm with link state routing algorithm. 2075 Ashwin Q4 · 3+5
- What is classful and classless address? Differentiate between link state and distance vector routing protocol. 2074 Ashwin Q4 · 8
- Discuss about the network congestion? Explain how different network parameters effect the congestion. Compare operation of link state routing with the distance vector routing. 2073 Shrawan Q5 · 2+2+4
- Network layer is one of the key layers in OSI reference model, why? Differentiate between distance vector routing and static link routing. 2072 Kartik Q5 · 2+6
- What is routing? Differentiate between link state routing and distance vector routing. 2071 Shrawan Q4 · 2+6
- Differentiate: a) Distance vector and link state routing algorithm b) Circuit switching and packet switching 2068 Chaitra Q5 · 2×5
- Why routing is essential in computer networking? Compare working of distance vector routing algorithm with link state routing algorithm. 2067 Ashad Q7 · 2+6
Hierarchical routing: regions instead of every router
Why: as a network grows, flat routing tables, the messages that keep them current and the time to compute them all grow with the number of routers. Past some size, no router can keep a route to every other router.
The book's example (Tanenbaum's): 17 routers in five regions. Router 1A's flat table needs 17 entries, one per router. Its hierarchical table needs only 7: itself, the two other routers of region 1 (1B and 1C, one hop each), and one entry for each of regions 2, 3, 4 and 5 (via 1B for region 2, via 1C for the others).
Router 1A, hierarchical table Destination Line Hops 1A - - 1B 1B 1 1C 1C 1 Region 2 1B 2 Region 3 1C 2 Region 4 1C 3 Region 5 1C 4
The saving grows with size. With 720 routers, a flat table has 720 entries. Split into 24 regions of 30 routers, each router needs 30 local entries plus 23 for the other regions: 53. With three levels (8 clusters of 9 regions of 10 routers), 10 + 8 + 7 = 25 entries. Kamoun and Kleinrock showed that the best number of levels for N routers is about , needing about entries per router: for 720 routers, about 18.
The price: a longer path. A router sends everything for a region through the same entry point, even when another entry would be shorter for a particular destination, so some paths grow.
Where it is used: OSPF divides an autonomous system into areas joined by a backbone (OSPF), and the Internet itself is a hierarchy of autonomous systems joined by BGP (BGP).
To remember it, a parcel from Kathmandu to a village in Jhapa is first sent "to Jhapa": only the Jhapa district office needs to know the village.
4.7Routing protocols
Routing protocols: why they are needed, IGP and EGP, and the main five PIN 4/27
82 Bh · 74 Ch · 69 Ch · 68 Ba2+63+5
Why a routing protocol is necessary:
- Static routes do not scale: every router needs a route to every network, typed in by hand, and one new subnet means editing every router.
- Discovery: routers find out on their own which networks exist and where.
- Adaptation: when a link fails or a new one appears, the routers reroute by themselves, in seconds, at three in the morning.
- Best paths and no loops: a metric picks the best path, and the protocol's rules keep routes loop free while all routers converge on a consistent view.
- Policy between organisations: between autonomous systems, BGP carries who may use whose links.
Three ways to classify them:
- By scope: an interior gateway protocol (IGP) routes inside one autonomous system (intra-AS): RIP, OSPF, IS-IS, EIGRP. An exterior gateway protocol (EGP) routes between autonomous systems (inter-AS): BGP.
- By algorithm: distance vector (RIP, IGRP), link state (OSPF, IS-IS), advanced distance vector (EIGRP), and path vector (BGP).
- By masks: classful protocols send no subnet mask in their updates (RIPv1, IGRP); classless ones do, so they support VLSM and CIDR (RIPv2, OSPF, EIGRP, IS-IS, BGP-4).
| Point | Intra-AS (IGP) | Inter-AS (EGP) |
|---|---|---|
| Scope | inside one autonomous system | between autonomous systems |
| Goal | performance: the shortest, fastest path | policy and reachability: who carries whose traffic |
| Chosen by | each AS for itself | everyone uses BGP-4 |
| Size | hundreds to thousands of routes | the whole Internet's routes |
| Examples | RIP, OSPF, IS-IS, EIGRP | BGP |
| Protocol | Type | Algorithm | Metric | Updates | Origin |
|---|---|---|---|---|---|
| RIP | IGP | distance vector | hop count, at most 15 | whole table every 30 s | open: RFC 1058, RFC 2453 |
| OSPF | IGP | link state (Dijkstra) | cost from bandwidth | on change; refresh every 30 min | open: RFC 2328 |
| IGRP | IGP | distance vector | composite: bandwidth and delay | whole table every 90 s | Cisco, 1980s; obsolete |
| EIGRP | IGP | advanced distance vector (DUAL) | composite: bandwidth and delay | partial, only on change | Cisco; published as RFC 7868 |
| BGP | EGP | path vector | policy; the AS path length | incremental, over TCP port 179 | open: RFC 4271 |
- RIP (Routing Information Protocol): the oldest and simplest; counts hops, calls 16 infinity, sends its whole table to its neighbours every 30 seconds. Fine for a small network; slow to converge (RIP).
- OSPF (Open Shortest Path First): the open-standard link state IGP; floods link states within areas, elects a DR and BDR on LANs, runs Dijkstra, converges fast and supports VLSM and authentication (OSPF).
- IGRP (Interior Gateway Routing Protocol): Cisco's 1980s answer to RIP's limits: distance vector, but with a composite metric (bandwidth and delay by default, load and reliability optional), a hop limit of 100 by default (up to 255) and updates every 90 seconds. It is classful, and Cisco has replaced it with EIGRP.
- EIGRP (Enhanced IGRP): Cisco's advanced distance vector protocol, sometimes called hybrid. It keeps neighbour and topology tables like a link state protocol but still exchanges distances; its DUAL algorithm keeps a ready backup route (the feasible successor), so it switches paths almost at once and stays loop free. It sends small updates only when something changes, supports VLSM and unequal-cost load balancing, and multicasts to 224.0.0.10.
- BGP (Border Gateway Protocol): the Internet's EGP: a path vector protocol that advertises each route with the list of ASes it passes, and chooses by policy over TCP (BGP).
- IS-IS (Intermediate System to Intermediate System): a link state IGP from the ISO world, much like OSPF, run by many large ISPs.
An intra-AS protocol in practice: a campus or an ISP's internal network runs one IGP, usually OSPF; it reaches the Internet through a static default route, or through BGP if it owns an AS number and has more than one provider.
To remember it, inside a city the traffic office chooses the fastest roads (an IGP); between countries, border agreements decide which highways may carry whose goods, whatever the distance (an EGP).
- What are routing protocols? Explain open short path first (OSPF) process in link state routing. 2082 Bhadra Q4 · 2+6
- Mention the criteria for good routing. Explain RIP, OSPF, BGP, IGRP and EIGRP. 2074 Chaitra Q4 · 2+6
- Why is routing protocol necessary? Explain the working process of Routing Information protocol (RIP) with example. 2069 Chaitra Q5 · 3+5
- What is a fragmentation and re-assembly? Explain about any intra-AS routing protocol. 2068 Baishakh Q6 · 3+5
RIP: hop counts, 30 second updates, and its timers PIN 2/27
82 Ba · 69 Ch2+63+5
How RIP works, in order:
- Start up: a router knows only its directly connected networks; it sends a request message on each RIP interface asking the neighbours for their tables.
- Respond: neighbours answer with response messages holding their tables; the same response is then sent every 30 seconds by the update timer, whether anything changed or not.
- Update: for each route received, the router adds one hop. A route to a new network is added; a shorter route replaces the old one; news from the current next hop is always believed, even if worse; a metric that reaches 16 means unreachable.
- Triggered update: when a route changes, the router sends an update at once instead of waiting for the timer.
- Age out: the timers below remove routes whose neighbour has gone silent.
- Loop control: split horizon, poison reverse and hold-down keep the count to infinity short (distance vector).
Its timers, with Cisco's defaults (the values the papers expect):
| Timer | Default | What happens |
|---|---|---|
| Update | 30 s | every 30 seconds each router sends its whole table out of every RIP interface |
| Invalid | 180 s | a route not refreshed for 180 seconds (six missed updates) is declared invalid: its metric becomes 16 and it is advertised as unreachable |
| Hold-down | 180 s | once the route is invalid, the router refuses news of another route to that network unless it is clearly better, so stale news cannot revive it |
| Flush | 240 s | 240 seconds after the last update, the route is removed from the table altogether |
The flush timer is counted from the last update, so it fires 60 seconds after the route went invalid, before the hold-down would end (at 360 seconds). RFC 2453 itself names only two timers: a timeout of 180 seconds and a garbage-collection timer of 120 seconds after it, so the route is deleted 300 seconds after the last update; hold-down is Cisco's addition. The RFC also adds a small random offset to the 30 seconds, so that routers do not all send at the same moment.
Given: R1 has LAN 10.1.0.0/16; R1 and R2 share link 10.2.0.0/16; R2 and R3 share link 10.3.0.0/16; R3 has LAN 10.4.0.0/16. At the start each router knows only its own two networks.
- First update (about 30 s): R1 hears from R2 that 10.3.0.0 is one of R2's networks: R1 adds it at 1 hop via R2. R2 likewise adds 10.1.0.0 (via R1) and 10.4.0.0 (via R3), each at 1 hop.
- Second update (about 60 s): R2 now advertises 10.4.0.0 at 1 hop; R1 adds one and stores it at 2 hops via R2. R3 does the same for 10.1.0.0. The network has converged.
R1# show ip route C 10.1.0.0/16 is directly connected, GigabitEthernet0/0 C 10.2.0.0/16 is directly connected, Serial0/0/0 R 10.3.0.0/16 [120/1] via 10.2.0.2, 00:00:12, Serial0/0/0 R 10.4.0.0/16 [120/2] via 10.2.0.2, 00:00:12, Serial0/0/0
Reading it: C means connected, R learned by RIP; [120/2] is RIP's administrative distance (120) and the hop count (2); 00:00:12 is the time since the last update, which the invalid and flush timers watch. If R3 dies, 10.4.0.0 goes invalid at 180 s and is flushed at 240 s.
The RIP message: a 4-byte header (command: 1 request, 2 response; version) and up to 25 route entries of 20 bytes each (address family, IP address, metric; version 2 adds a route tag, the subnet mask and the next hop), so at most 504 bytes, sent in UDP.
| Point | RIPv1 | RIPv2 | RIPng |
|---|---|---|---|
| Defined in | RFC 1058, 1988 | RFC 2453, 1998 | RFC 2080, 1997 |
| Addressing | classful: no mask in updates | classless: mask and next hop carried | IPv6 prefixes |
| Updates sent to | broadcast 255.255.255.255 | multicast 224.0.0.9 | multicast ff02::9 |
| Authentication | none | plain text or MD5 | left to IPsec |
| Transport | UDP 520 | UDP 520 | UDP 521 |
Its limits: a 15-hop diameter; slow convergence and the count to infinity; a hop count that ignores bandwidth, so one hop over a 2 Mbps line beats two hops over gigabit fibre; and the whole table every 30 seconds even when nothing changes. RIP suits small, simple networks; larger ones use OSPF.
To remember it, RIP counts bus stops, not minutes: a route with one stop through the Kalanki jam beats a two-stop route along the empty ring road. Its four timers are half a minute, three minutes, three minutes and four minutes.
- Define routed and routing protocol. Explain RIP routing operation with is timer details. 2082 Baishakh Q4 · 2+6
- Why is routing protocol necessary? Explain the working process of Routing Information protocol (RIP) with example. 2069 Chaitra Q5 · 3+5
OSPF: areas, DR and BDR, and the road to full adjacency HOT 5/27
82 Bh · 81 Bh · 80 Bh · 79 Bh · 66 Bh2+62+2+42×4
"Open" means it is a public standard any vendor may implement, unlike Cisco's EIGRP; "shortest path first" is the Dijkstra calculation (Dijkstra). OSPF messages travel straight inside IP (protocol 89), to the multicast address 224.0.0.5 (all OSPF routers) or 224.0.0.6 (the DR and BDR).
Its metric is a cost worked out from each interface's bandwidth:
With Cisco's default reference of 100 Mbps, a 10 Mbps link costs 10 and a 100 Mbps link 1 (so does gigabit, unless the reference is raised). A path's cost is the sum of its links' costs.
The OSPF process, from power-on to a routing table:
- Find neighbours: every OSPF interface sends a Hello every 10 seconds; routers whose hellos agree (same area, subnet, timers and authentication) become neighbours. A neighbour silent for 40 seconds (the dead interval) is declared down.
- Elect a DR and BDR on each multi-access network such as Ethernet (below).
- Form adjacencies and synchronise: adjacent routers swap database descriptions, request the LSAs they lack and receive them, until their databases match: the Full state.
- Flood LSAs: each router floods an LSA describing its own links through the area; the DR adds one for the LAN segment. LSAs are flooded again when a link changes, and refreshed every 30 minutes.
- Run SPF: each router runs Dijkstra on its database, with itself as the root, and gets its shortest path tree.
- Install the routes: the best path to every network goes into the routing table; a change floods new LSAs and the SPF run repeats.
| Type | OSPF packet | Job |
|---|---|---|
| 1 | Hello | find neighbours, keep them alive, carry the DR election |
| 2 | Database description (DBD) | list the LSA headers each router holds |
| 3 | Link state request (LSR) | ask for LSAs that are missing or out of date |
| 4 | Link state update (LSU) | carry the full LSAs |
| 5 | Link state acknowledgement (LSAck) | confirm each LSA received |
Areas. A large autonomous system is divided into areas, all attached to the backbone, area 0. Routers keep a detailed database only of their own area, so SPF runs are quick and a fault in one area is not flooded everywhere; an area border router (ABR) joins an area to the backbone and summarises its routes, and an AS boundary router (ASBR) brings in routes from outside (BGP or static). This is hierarchical routing (hierarchical routing).
DR and BDR. On a multi-access network, if every router formed an adjacency with every other, n routers would need adjacencies, and every LSA would be flooded over and over: ten routers on one Ethernet would need 45. So OSPF elects a designated router (DR): every router forms its full adjacency only with the DR and a backup designated router (BDR). Routers send their updates to the DR (224.0.0.6), and the DR floods them to all (224.0.0.5) and speaks for the segment with one network LSA. The BDR listens to everything and takes over at once if the DR fails. The ten routers now need only = 17 adjacencies. The other routers are called DROthers.
How the DR is elected, from the values each router puts in its Hello:
- Highest interface priority (0 to 255, default 1) becomes DR, the next highest BDR.
- A tie is broken by the highest router ID: set by hand, or else the highest loopback address, or else the highest address of an active interface.
- Priority 0 means the router never becomes DR or BDR.
- Timing: a new interface waits one dead interval (40 s) before electing, so routers that start together all take part.
- No pre-emption: a better router that joins later does not take over. Only when the DR fails does the BDR become DR, and a new BDR is elected.
The road to full adjacency: two OSPF neighbours pass through these states (RFC 2328):
- Down: no Hello heard from the neighbour (or the dead interval ran out).
- Init: a Hello has arrived from the neighbour, but it does not list this router yet: one-way.
- 2-Way: each router sees its own router ID in the other's Hello: two-way talk. The DR and BDR are elected here, and two DROthers stay in this state for good.
- ExStart: the pair chooses master and slave (the higher router ID is master) and the first sequence number for the exchange.
- Exchange: they swap DBD packets listing the headers of their LSAs.
- Loading: each sends LSRs for the LSAs it lacks or holds old copies of, receives them in LSUs and acknowledges them.
- Full: the two databases are identical: the routers are fully adjacent, and each lists the other in its router LSA.
Why OSPF is the usual IGP: it converges in seconds, never counts to infinity, has no hop limit, carries masks (VLSM and CIDR), authenticates its messages, balances load over equal-cost paths, and sends little once stable. Its costs are more memory and CPU than RIP and a harder setup (areas, router IDs, DR priorities).
To remember DR and BDR, think of a class of forty: instead of every student passing every notice to every other, the class elects a CR (the DR) and an assistant CR (the BDR). Everyone tells the CR, the CR tells everyone, and if the CR is absent the assistant steps in without a new election.
- What are routing protocols? Explain open short path first (OSPF) process in link state routing. 2082 Bhadra Q4 · 2+6
- What is adaptive and non-adaptive routing? List the properties of link state routing and mention the method that how Designated Router (DR) is elected in OSPF routing. 2081 Bhadra Q4 · 2+2+4
- What is DR and BDR in OSPF? How do OSPF routers come into fully adacency states? Explain. 2080 Bhadra Q5 · 3+5
- Write short notes on: (Any Two) a) ALOHA b) OSPF c) VPN 2079 Bhadra Q10 · 2×4
- What is unicast and multicast routing? Describe the concept of optimality principle. Describe how the routers in its link state routing come into fully adjacency state. 2066 Bhadra Q4a · 2+6
BGP: routing between autonomous systems
Why RIP or OSPF cannot do this job: between ASes the goal is not the fastest path but the permitted one (an ISP carries a customer's traffic, not a competitor's); each AS hides its inside from the others; their internal metrics cannot be compared; and the Internet's routing table is far too large to flood.
Path vector: a route is advertised as a prefix plus its AS_PATH, for example
203.0.113.0/24 with path 64501 64502. When an AS passes the route on, it adds its
own number at the front. An AS that sees its own number in a path rejects the route: that is
how BGP avoids loops without any count to infinity.
- Sessions over TCP port 179: two BGP routers (peers) open a TCP connection and exchange the full table once, then only changes.
- eBGP and iBGP: external BGP runs between routers of different ASes, usually directly connected; internal BGP carries the outside routes among the border routers of the same AS.
- Policy: each AS sets which routes it accepts and which it advertises, and ranks routes by attributes such as local preference, then the shortest AS_PATH, then others.
| BGP message | Job |
|---|---|
| OPEN | starts a session over TCP: AS number, hold time, router ID |
| UPDATE | advertises new routes with their path attributes, and withdraws dead ones |
| KEEPALIVE | says "still here" when there is nothing to update, every third of the hold time (commonly 60 s with a 180 s hold time) |
| NOTIFICATION | reports an error and closes the session |
An internet exchange point is where many ASes meet to exchange traffic directly over BGP sessions instead of paying an upstream provider to carry it. Nepali ISPs peer at the Nepal Internet Exchange (NPIX), so that a page on a Nepali server can reach a Nepali customer of another member ISP without leaving the country.
To remember it, BGP is the travel agent's itinerary: "Kathmandu, Delhi, Dubai, London". Every stop is listed, so nobody books a trip through a city twice, and an agent can refuse any route that passes through a country it does not deal with.
Unicast and multicast routing, and their protocols PIN 3/27
80 Ba · 72 Ka · 66 Bh2+64+4
| Point | Unicast | Multicast | Broadcast |
|---|---|---|---|
| Receivers | one | a group that joined | everyone on the network |
| Destination address | one host's address | a group address, class D (224.0.0.0 to 239.255.255.255) | all 1s in the host part |
| Copies for N receivers | N, from the source | one per link, made by routers | one, to all |
| Crosses routers | yes | yes, with multicast routing | no |
| Example | loading a web page | a live lecture or IPTV channel | an ARP request |
Unicast routing is everything in the earlier cards: the router looks up the one destination and sends one copy to one next hop. Unicast routing protocols build those tables: RIP and IGRP (distance vector), OSPF and IS-IS (link state), EIGRP (advanced distance vector) inside an AS, and BGP between ASes (routing protocols).
Multicast routing must answer two questions: which hosts want a group, and along which tree to copy its packets.
- Group membership, host to router: IGMP (Internet Group Management Protocol, IP protocol 2; version 3 in RFC 3376). A host sends a membership report to join a group; the router sends periodic queries (to 224.0.0.1) to see whether anyone on the LAN still wants it; version 2 added an explicit leave message.
- Distribution trees, router to router: a source-based tree is a shortest path tree from each source to the members (best paths, but one tree per source); a shared tree is one tree per group rooted at a chosen core or rendezvous point (fewer trees, longer paths).
- Reverse path forwarding (RPF): a router accepts a multicast packet only if it arrived on the interface the router would use to send unicast traffic back to the source; this stops loops and duplicates without any extra tables.
| Multicast routing protocol | Built on | How it builds the tree |
|---|---|---|
| DVMRP (Distance Vector Multicast Routing Protocol, RFC 1075) | distance vector | flood and prune: send everywhere by RPF, then branches with no members ask to be cut off; source-based trees |
| MOSPF (Multicast OSPF, RFC 1584) | OSPF link state | group-membership LSAs added to OSPF; each router computes the source's shortest path tree with Dijkstra |
| PIM-DM (Protocol Independent Multicast, dense mode) | any unicast protocol | flood and prune, like DVMRP; suits groups whose members are everywhere |
| PIM-SM (sparse mode, RFC 7761) | any unicast protocol | explicit joins towards a rendezvous point (shared tree), switching to source trees for heavy flows; suits scattered members and is the most used |
| CBT (Core Based Trees, RFC 2201) | any unicast protocol | one shared tree per group, rooted at a core router |
"Protocol independent" means PIM uses whatever unicast routing table the router already has for its RPF checks, instead of running its own routing algorithm.
To remember it, unicast is a teacher phoning each of 200 students with the same notice; multicast is the notice read once over the campus speakers in only the halls whose students signed up for it; broadcast is the siren that everyone hears.
- What is unicast and multicast? Compare distance vector routing protocol and link state routing protocol with examples. 2080 Baishakh Q4 · 4+4
- What are the functions of network layer? Explain briefly about multicast routing protocols and unicast routing protocols. 2072 Kartik Q4 · 2+6
- What is unicast and multicast routing? Describe the concept of optimality principle. Describe how the routers in its link state routing come into fully adjacency state. 2066 Bhadra Q4a · 2+6
4.8Designing a network
Designing a network for a real site: a hotel, a campus PIN 2/27
72 Ka · 67 Asa6+28
The method, which turns a vague question into a marked answer:
- Requirements and assumptions: how many users and devices, rooms, floors and buildings; which services (Internet, Wi-Fi, phones, CCTV, servers); how much growth; any budget. Write each assumption down: the answer is judged on them.
- Topology: a hierarchical star (core, distribution, access), which isolates faults and grows by adding branches (topologies).
- Devices: managed switches (PoE where access points, phones and cameras plug in), a router and firewall at the edge, wireless access points with a controller (devices).
- Cabling: Cat6 UTP for runs up to 100 m; fibre between buildings, up risers or for long runs: multimode (OM3 or OM4: 10 Gbps up to 300 to 400 m) inside a campus, single-mode beyond (fibre). Fibre also ignores the lightning and electrical noise that copper picks up.
- Wireless: enough access points for coverage and for the number of devices, 802.11ax (Wi-Fi 6) or 802.11ac, separate SSIDs for staff and guests, WPA2 or WPA3 (wireless LAN).
- Addressing: private addresses (RFC 1918), one VLAN and one subnet per department or function, DHCP for the clients, NAT to the ISP's public address (VLAN, subnetting).
- Servers and services: DHCP and DNS, file and print, web and mail, the site's own applications, a recorder for the cameras.
- Security and reliability: firewall rules between VLANs, guest isolation, antivirus and backups; two ISPs, a UPS, and redundant core links where downtime costs money (firewalls).
- Management: SNMP monitoring, labelled cables and ports, a written plan.
| Layer | Job | Device |
|---|---|---|
| Core | fast backbone joining the distribution blocks and the server room | layer 3 core switch, fibre links |
| Distribution | joins the access switches of one building or department, routes between VLANs, applies policy | layer 3 switch |
| Access | connects the end devices | layer 2 switches (PoE), access points |
Given: 5 departments, each with 100 computers in 5 rooms of 20: 500 computers. Assumed: the departments are in separate buildings within a few hundred metres of a central server room, rooms are within 100 m of their department's network closet, and the campus has one ISP link plus room to add another.
| Item | Quantity | Why |
|---|---|---|
| Access switch, managed, 24 gigabit ports, with uplinks | 25, one per room | 20 PCs plus an uplink and spare ports; a switch, not a hub, so each PC has its own collision-free gigabit port |
| Distribution switch, layer 3, fibre (SFP) ports | 5, one per department | joins the 5 room switches, routes the department's VLAN, keeps its broadcasts inside |
| Core switch, layer 3, 10 Gbps fibre ports | 1 (2 for redundancy) | joins the 5 departments and the server room at full speed |
| Router and firewall | 1 | link to the ISP, NAT, the security policy |
| Wireless access points, Wi-Fi 6, PoE | 2 or 3 per department | laptops and phones in corridors and halls |
| Cat6 UTP drops and patch cords | 500 drops | each PC to its room switch, under 100 m, gigabit |
| Multimode fibre (OM3 or OM4) | 5 department links to the core | 10 Gbps over hundreds of metres, immune to lightning surges |
| Racks, patch panels, UPS | in every room closet, department and the core | tidy, labelled cabling that keeps running through power cuts |
| Servers | DHCP and DNS, file, web and mail, authentication | in the central server room |
Accessories: RJ45 connectors and keystone jacks, faceplates, cable trays and conduit, SFP modules for the fibre ports, labels, and a crimping tool and LAN tester.
Addressing: one VLAN and one private subnet per department (each needs 100 hosts and room to grow), DHCP from the server room, NAT at the firewall. The next paper question on this campus works the address ranges; they are in the Numericals panel.
Assumed: 60 guest rooms on 4 floors; a lobby and reception, a restaurant and bar, a conference hall and back offices (front desk, accounts, kitchen, store); about 30 staff computers and POS terminals; 40 CCTV cameras; an IP phone in every room.
- Internet: two ISP links (a fibre line from one ISP and a backup from another) on a firewall with two WAN ports, for failover and load balancing: guests judge a hotel by its Wi-Fi.
- Firewall (UTM): NAT, rules between the VLANs, content filtering, a VPN for remote management, and a captive portal where guests log in with their room number.
- Core: a stackable layer 3 switch in the server room, routing between the VLANs.
- Access: one 48-port PoE+ switch per floor, powering the access points, phones and cameras over the data cable, with a fibre uplink up the riser to the core.
- Wireless: Wi-Fi 6 access points, about one per three or four rooms plus the lobby, restaurant and conference hall, under one controller so guests roam without dropping; WPA3 for staff, an isolated guest SSID with a speed limit per device.
- Voice and video: an IP PBX with a gateway to the telephone network, IP phones, and a network video recorder for the cameras.
- Software: a hotel property management system (reservations, check-in, billing, linked to the keycard locks and the restaurant POS), accounting software, the hotspot manager for guest Wi-Fi, antivirus, backup, and SNMP monitoring.
| VLAN | Who | Example subnet | Rule |
|---|---|---|---|
| 10 Staff | office PCs, front desk, POS | 10.10.10.0/24 | reaches the PMS and the Internet |
| 20 Guests | guests' phones and laptops | 10.10.20.0/22 | Internet only, guests isolated from each other |
| 30 Voice | IP phones | 10.10.30.0/24 | priority (QoS) |
| 40 CCTV | cameras, recorder | 10.10.40.0/24 | no Internet |
| 50 Servers | PMS, file, DHCP, DNS | 10.10.50.0/24 | staff only |
Why this design: VLANs keep guests away from the billing and card systems; PoE saves a power socket at every access point, phone and camera; managed switches allow the VLANs and monitoring; two ISPs and a UPS keep the hotel online; Cat6 gives gigabit to every room, and fibre carries the floor uplinks.
To remember the method, think of planning a wedding venue: first count the guests (requirements), then lay out the halls (topology), hire the tables and chairs (devices), lay the carpets between halls (cabling), seat families together (VLANs and subnets), and put guards on the doors (security).
- You are assigned to design a network infrastructure for a 3-star hotel. Recommend a network solution with hardwares and softwares in current trend that can be used in the hotel. Make necessary assumptions and justify your recommadation with logical arguments where possible. 2072 Kartik Q1 · 8
- If you are assigned to design a LAN for Pulchowk Campus having 5 departments. Each department will have 100 computers locating in 5 rooms each equipped with 20 computers. Make your own justification while selecting connecting devices and accessories. 2067 Ashad Q2 · 6+2
4.9Last minute recall
Chapter 4 in one screen
- Network layer: host to host across networks; logical addressing, routing, forwarding, packetizing, fragmentation, internetworking, ICMP; key layer: highest layer every router runs, the narrow waist.
- Devices: repeater and hub layer 1 (one collision domain); bridge and switch layer 2 (MAC table, a collision domain per port); router layer 3 (IP, a broadcast domain per interface); gateway up to 7 (protocol conversion).
- Bridge: receive, learn source, filter, forward or flood, age (300 s); throughput against a repeater's C; STP for loops.
- IPv4: 32 bits, dotted decimal; A 0 to 127 /8, B 128 to 191 /16, C 192 to 223 /24, D 224 to 239 multicast, E 240 to 255 reserved; private 10/8, 172.16/12, 192.168/16.
- Subnetting: hosts , block ; VLSM: find the block, size, sort largest first, allocate from the start, links /30, wasted and unused range.
- CIDR and supernetting: a.b.c.d/n; contiguous, power of two, aligned; four /24s into one /22; longest prefix match.
- IPv4 header: 20 to 60 bytes; TTL hop limit, protocol 1 ICMP, 6 TCP, 17 UDP; fragments share Identification, offset in 8 bytes, MF; 65,535 minus 20 minus 20 = 65,495.
- ARP: broadcast request, unicast reply, cache; RARP MAC to IP (replaced by DHCP); NDP in IPv6 with ICMPv6 and multicast.
- ICMP: errors: destination unreachable 3, source quench 4, time exceeded 11, parameter problem 12, redirect 5; queries: echo 8 and 0, timestamp, address mask, router discovery; ping, traceroute, path MTU.
- Routing: routing builds tables, forwarding uses them; good algorithm: correctness, simplicity, robustness, stability, fairness, optimality; static against dynamic; routed (IP) against routing (RIP, OSPF); optimality principle and sink tree; AS.
- Algorithms: Dijkstra (A to D: ABEFHD, cost 10); flooding with hop count; distance vector (Bellman-Ford, neighbours, periodic, count to infinity, split horizon, poison reverse, hold-down); link state (discover, measure, build, flood, compute); hierarchical regions.
- Protocols: RIP hop count 15, timers 30, 180, 180, 240; OSPF areas, DR and BDR by priority then router ID, states Down, Init, 2-Way, ExStart, Exchange, Loading, Full; IGRP, EIGRP (DUAL); BGP path vector over TCP 179.
- Multicast: IGMP for membership; source and shared trees, RPF; DVMRP, MOSPF, PIM-DM, PIM-SM, CBT.
- Design: assumptions, hierarchical star, managed PoE switches, router and firewall, Wi-Fi 6, Cat6 and fibre, a VLAN per department, servers, security, UPS and two ISPs.
Chapter 5 · 5 hours · about 8 marks a paper · in 26 of the 27 sittings
Transport layer
The transport layer is where the network stops being host to host and becomes process to process. It takes IP's best-effort packets and gives each application one of two services, addressed by port numbers: a reliable, ordered byte stream (TCP) or a fast, bare datagram (UDP). It is the steadiest question on the paper: 26 of the 27 sittings on record set it, usually as Q6 with two asks, and the token bucket, the TCP header and its reliability, the three-way handshake and UDP come back again and again.
- The transport service: process-to-process delivery, the layer's functions, and the two kinds of service it offers the application layer (connection-oriented and connectionless).
- Two protocols: UDP, an 8-byte header and no promises, and TCP, a 20 to 60 byte header and a reliable byte stream; how they compare, and why both exist over one IP.
- Ports and sockets: the 16-bit numbers that pick the process, the IANA ranges, and the socket pair that names one connection.
- Connection management: the three-way handshake, the graceful four-segment release and TIME-WAIT.
- Flow control, buffering and multiplexing: TCP's sliding window, the receiver's buffers, and how many sockets share one IP address.
- Congestion: its causes, the policies that prevent it, and the two traffic shaping algorithms, the leaky bucket and the token bucket.
- On the layer models: layer 4 of OSI and the transport layer of TCP/IP (OSI model, TCP/IP model). Each segment rides inside an IP datagram whose protocol field says 6 for TCP or 17 for UDP (IPv4 header, encapsulation).
- The same ideas one layer down: chapter 3's flow control and ARQ work hop by hop on one link (flow control, ARQ); TCP does them end to end across the whole internet. The checksum idea is chapter 3's (error detection).
- Above it: every application picks TCP or UDP and a port (HTTP, e-mail, DNS, DHCP), and socket programming is chapter 6's (socket programming). SSL and TLS run on top of TCP (SSL), and firewalls filter on ports (firewalls).
- 5.1 The transport service: process-to-process delivery, functions, services to the upper layer
- 5.2 Transport protocols: UDP, TCP, and TCP against UDP
- 5.3 Ports and sockets
- 5.4 Connection establishment and release
- 5.5 Flow control and buffering: the sliding window
- 5.6 Multiplexing and demultiplexing
- 5.7 Congestion, the leaky bucket and the token bucket
- 5.8 Last minute recall, chapter 5
- Nine sittings each have set the token bucket (alone or against the leaky bucket) and TCP (its header, or why and how it is reliable); seven the handshake and release; six UDP, and six TCP against UDP.
- Draw: the TCP header as a 32-bit grid, the UDP header, the handshake and the release as sequence diagrams with SYN, ACK, FIN and the sequence numbers, and both buckets.
- A common pairing is a protocol ask (about 4 marks) with a bucket ask (about 4 marks); a few papers set a short note on the TCP sliding window or the TCP header.
5.1The transport service
The transport layer: process-to-process delivery and its services HOT 5/27
80 Bh · 78 Bh · 76 Ch · 71 Ch · 68 Ba3+51+2+54+4
Three scopes of delivery. Each layer delivers over a different distance:
- Node to node: the data link layer moves a frame one hop, using MAC addresses.
- Host to host: the network layer moves a packet across the internet, but an IP address names only a machine.
- Process to process: a laptop may run a browser, a video call and a software update at once, so something must still decide which program a packet is for. That is the transport layer's job, done with port numbers.
To remember it, think of a letter to a hostel. The postal address brings the letter to the hostel gate (the IP address: host to host); the warden reads the room number and puts it in the right room's box (the port: process to process). The postal van that carries it from one sorting office to the next is the data link layer, one hop at a time.
Its services and functions, which the papers call services, functions or major tasks: they are the same list.
| Service (function) | What it does | How TCP and UDP do it |
|---|---|---|
| Process-to-process delivery (addressing) | delivers to a process, not just to a host | 16-bit source and destination ports in both headers (ports) |
| Segmentation and reassembly | cuts a long message into pieces the network can carry, and rebuilds it | TCP numbers every byte and sizes segments to the MSS; UDP sends each message as one datagram |
| Connection control | sets up, uses and releases a logical connection, or sends with no connection at all | TCP: three-way handshake and FIN release (5.4); UDP: connectionless |
| Reliability (error control) | detects corrupt, lost and duplicate data and recovers it | TCP: checksum, ACK, timer, retransmission; UDP: checksum only, a bad datagram is dropped |
| Ordered delivery | hands data up in the order it was sent | TCP: reorders by sequence number; UDP: none |
| Flow control and buffering | keeps a fast sender from flooding a slow receiver's buffer | TCP: the receive window (5.5); UDP: none |
| Multiplexing and demultiplexing | lets many processes share one IP address | ports in every header (5.6) |
| Congestion control | keeps all the senders together from flooding the network | TCP: slow start and AIMD; shaping with the buckets (5.7) |
Why a separate layer at all, when IP already delivers packets?
- The network belongs to the carrier: users do not own the routers and cannot fix what they lose.
- The transport layer runs in the users' own hosts, so it can improve on the network's service, recovering lost packets and restoring their order.
- One standard interface for every application, whatever networks lie in between. In OSI terms, layers 1 to 4 are the transport service provider and layers 5 to 7 its user.
How the complete message arrives, and in order. IP may lose, duplicate, corrupt or reorder packets. TCP turns that into a perfect byte stream with a chain of mechanisms, each covering a different failure:
- Synchronize: the three-way handshake agrees the initial sequence numbers, so both sides know where the numbering starts.
- Number every byte: each segment carries the sequence number of its first byte, so a gap, a duplicate or a misordering shows at once.
- Check: the checksum catches a corrupted segment, which is dropped and so becomes a loss.
- Acknowledge: the receiver returns a cumulative ACK, the number of the next byte it expects.
- Retransmit: a segment not acknowledged before the retransmission timer (RTO) runs out, or reported missing by three duplicate ACKs, is sent again.
- Reorder and drop duplicates: the receive buffer keeps early segments and discards repeats; data goes up to the application only when no gap lies before it.
- Flow control: the advertised window keeps the sender from overflowing the receiver's buffer, which would lose data.
- Close cleanly: FIN goes only after the data and carries the next sequence number, so the receiver knows exactly where the stream ends and that nothing is missing.
After the handshake the sender's first data byte is 1001. It sends three 1,000-byte segments, seq 1001, 2001 and 3001, and the second is lost on the way.
- Segment 1001 arrives: bytes 1001 to 2000 go up to the application; the receiver sends ACK 2001.
- Segment 3001 arrives early: it is kept in the buffer, not delivered, and the receiver repeats ACK 2001 (a duplicate ACK).
- The timer for 2001 runs out: the sender, which kept a copy, sends seq 2001 again.
- The gap is filled: bytes 2001 to 4000 go up, so all 3,000 bytes have arrived whole and in order, and the receiver sends ACK 4001.
UDP does none of this beyond the checksum: it delivers to the right port, and leaves loss and order to the application (UDP).
- How does the transport layer ensure that the complete message arrive at the destination and in the proper order? How does Token Bucket control the congestion over the Leaky Bucket algorithm? 2080 Bhadra Q6 · 4+4
- What are services provided by Transport layer? Explain about Leaky-Bucket algorithm for congestion control? 2078 Bhadra Q6 · 3+5
- What are the major task of transport layer? Explain. What is token bucket algorithm? 2076 Chaitra Q6 · 5+3
- Why port number is used in networking? What are the services of transport layer? Differentiate between TCP and UDP protocol. 2071 Chaitra Q6 · 1+2+5
- What are the functions of transport layer? Draw the segment structure of TCP. 2068 Baishakh Q5 · 3+5
Services to the upper layer: connection-oriented, connectionless, and the primitives
| Point | Connection-oriented | Connectionless |
|---|---|---|
| Phases | establish, transfer data, release | send only |
| Addressing | the full address once, at setup | the full address in every datagram |
| Reliability | acknowledged, retransmitted, in order | none promised: data may be lost, repeated or reordered |
| Delay before data | a setup round trip | none |
| State | both ends keep the connection's state | none |
| Everyday picture | a phone call | a letter or a postcard |
| Internet protocol | TCP | UDP |
To remember it: calling home from the hostel is connection-oriented: the phone rings, someone answers, both say hello before anything else (setup), you talk, and you say bye (release). Posting a letter is connectionless: every envelope carries the full address, and two letters posted on the same day may arrive in either order, or one may not arrive at all.
Service primitives are the calls an application makes to use the service (the general idea is chapter 1's, services and primitives). The classic simple transport service has five, and the unit that peer transport entities exchange is a TPDU (transport protocol data unit), called a segment in TCP and a user datagram in UDP:
| Primitive | TPDU sent | Meaning |
|---|---|---|
| LISTEN | none | block until some process tries to connect |
| CONNECT | CONNECTION REQUEST | actively try to set up a connection |
| SEND | DATA | send information |
| RECEIVE | none | block until a DATA TPDU arrives |
| DISCONNECT | DISCONNECTION REQUEST | this side wants to release the connection |
The internet's version is the Berkeley socket interface (4.2BSD, 1983): SOCKET (create an endpoint), BIND (attach a local address and port), LISTEN (be ready to accept, with a queue), ACCEPT (take the next incoming connection), CONNECT (actively open), SEND and RECEIVE, and CLOSE. A server calls SOCKET, BIND, LISTEN, ACCEPT; a client calls SOCKET, CONNECT. The code itself is chapter 6's (socket programming).
Why the transport layer is harder than the data link layer, though both do error control, sequencing and flow control. On a link the other end is fixed and directly wired; across a network:
- Addressing: the destination must be named explicitly.
- Connection setup needs care: the network can store packets and deliver old duplicates late (5.4).
- Buffering: a host may hold hundreds of connections at once, so it cannot keep one fixed buffer per line (5.5).
Quality of service parameters a transport user may ask for, in the classic OSI list: connection establishment delay, connection establishment failure probability, throughput, transit delay, residual error ratio, protection, priority and resilience. The internet's transport protocols promise none of them as numbers; they simply do their best.
5.2Transport protocols: UDP and TCP
UDP: the 8-byte header, its features, and why an unreliable protocol is used HOT 6/27
82 Bh · 82 Ba · 81 Ba · 79 Bh · 70 Ch · 66 Po2+2+42+3+33+3
The whole header is four 16-bit fields. That is all UDP adds to IP: enough to reach the right process and to notice a damaged datagram.
| Field | Bits | What it carries |
|---|---|---|
| Source port | 16 | the sending process's port, where any reply should go; optional: 0 when no reply is wanted |
| Destination port | 16 | the receiving process; always present |
| Length | 16 | the whole datagram in bytes, header plus data: at least 8 (a header alone), at most 65,535; over IPv4, whose header takes at least 20 bytes, that leaves at most 65,507 bytes of data |
| Checksum | 16 | a one's complement checksum over a pseudo-header, the UDP header and the data (checksums); optional in IPv4, where 0 means not computed (a computed 0 is sent as all ones), mandatory in IPv6 |
The pseudo-header is 12 bytes built from the IP header for the checksum only and never sent: source IP address, destination IP address, a zero byte, the protocol number 17 and the UDP length. Including the addresses means that a datagram delivered to the wrong host, or handed to the wrong protocol, fails the check.
A laptop asks its resolver for the address of ioe.edu.np. The DNS message is
28 bytes: a 12-byte DNS header and a 16-byte question (the name coded as
3ioe3edu2np0, 12 bytes, plus 2 bytes of type and 2 of class). The operating
system picks the free port 50000.
Source port 50000 = 0xC350 Destination port 53 (DNS) = 0x0035 Length 8 + 28 = 36 = 0x0024 Checksum over the pseudo-header, the header and the 28 bytes On the wire: C3 50 00 35 00 24 (checksum) then the 28 bytes of DNS
The IP datagram that carries it has protocol 17 and total length 20 + 36 = 56 bytes. One datagram goes out and one comes back: no handshake, no acknowledgement. If the answer does not come, the resolver simply asks again.
Features of UDP:
- Connectionless: no setup and no release; the first datagram already carries data.
- Unreliable (best effort): no acknowledgement and no retransmission; a lost datagram is simply lost.
- No ordering: datagrams may arrive in any order.
- Message-oriented: each send is one datagram and its boundaries are kept, unlike TCP's byte stream.
- No flow or congestion control: it sends as fast as the application writes.
- Small overhead: 8 bytes of header against TCP's 20 to 60.
- Stateless: the server keeps nothing per client, so one server can answer very many clients.
- Broadcast and multicast: supported; TCP is unicast only.
- Error detection only: a datagram that fails the checksum is silently dropped, never repaired.
Why it is used though it is unreliable. Unreliable here means "promises nothing", not "usually fails": most datagrams arrive. For many jobs, TCP's guarantees cost more than they give:
- Speed: no handshake, so a DNS lookup takes one round trip; over TCP the handshake alone would take another.
- Timeliness over completeness: in a voice or video call or a game, a late packet is useless. TCP would hold back all newer data until the lost piece was resent (head-of-line blocking); UDP lets the application skip the gap.
- Small and stateless: fewer bytes per message and no per-client state, which suits busy servers and small devices.
- Broadcast and multicast: DHCP must broadcast before the host has an address, and IPTV sends one stream to many receivers.
- The application adds only the reliability it needs: DNS retries, TFTP waits for an acknowledgement of each block, and QUIC, under HTTP/3, builds its own reliable, encrypted streams on top of UDP.
To remember it, think of live cricket commentary on the radio. If the line crackles for a second, nobody wants that second replayed later, because the next ball matters more: that is UDP's kind of traffic. A downloaded file of the match highlights must arrive whole, every byte: that is TCP's.
Where UDP is preferred, with practical examples:
| Application | Port | Why UDP |
|---|---|---|
| DNS queries | 53 | one small question, one answer; the client retries itself |
| DHCP | 67 server, 68 client | the client has no IP address yet, so it must broadcast (DHCP) |
| Voice and video calls (VoIP, carried by RTP) | chosen per call | late audio is useless; a few lost milliseconds are barely heard |
| Online multiplayer games | the game's own | only the newest position counts, not an old one resent |
| Live TV over IP (IPTV) | multicast | one stream to many viewers at once |
| SNMP, NTP, TFTP, RIP, syslog | 161, 123, 69, 520, 514 | short messages, simple devices, the application handles loss |
| QUIC (HTTP/3) | 443 | its own reliability and encryption, without TCP's handshake and head-of-line blocking |
Recorded video is different: a video watched on demand is usually sent over TCP (or QUIC) with a large playback buffer, since a few seconds of waiting at the start are acceptable and every frame should arrive.
- Write UDP header field and functions. Explain TCP 3-way hand shaking for connection establishment and release. 2082 Bhadra Q6 · 2+3+3
- Discuss UDP header and compare it with TCP. What is port address? Explain briefly about leaky-bucket algorithm used for traffic shaping. 2082 Baishakh Q6 · 2+2+4
- Though UDP is said to be unreliable protocol, it is used in Internet. Why? Explain the three way handshake principle of a TCP connection between client and server. 2081 Baishakh Q6 · 3+5
- What are the features of UDP protocol? In which case is UDP preferred as a transport layer protocol? Discuss with practical examples. 2079 Bhadra Q6 · 4+4
- Explain the UDP segment structure. Illustrate your answer with appropriate figures. 2070 Chaitra Q6 · 8
- Write short notes on (any two): a) UDP and its application b) Network Devices: Hubs, Switches and Routers c) IPv4 Header Structure 2066 Poush Q10 · 3+3
TCP: the reliable byte stream, its segment header, and how reliability is provided TOP 9/27
81 Bh · 76 Ash · 75 Ash · 74 Ash · 72 Ch · 72 Ka · 70 Asa · 68 Ch · 68 Ba3+54+42+2+4
A TCP connection is a logical, full-duplex, point-to-point association between two sockets, named by four values: source IP, source port, destination IP, destination port.
- Its state lives only in the two end hosts: the sequence numbers, windows, buffers and timers, kept in a transmission control block (TCB).
- The routers know nothing of it: they see independent IP packets, so a TCP connection is a virtual connection, not a reserved circuit (switching).
Features of TCP:
- Connection-oriented: a three-way handshake before data, a graceful release after (5.4).
- Reliable and ordered: nothing lost, nothing repeated, nothing out of order.
- Byte stream: no message boundaries. If an application writes 100 bytes three times, the receiver may read all 300 at once, or 150 and 150.
- Full duplex, point to point: data flows both ways at once between exactly two endpoints, and an ACK can ride on a data segment going the other way (piggybacking). No broadcast or multicast.
- Flow control and congestion control: the receive window protects the receiver (5.5), the congestion window protects the network (5.7).
- Mandatory checksum over a pseudo-header (with protocol 6), the header and the data.
The segment structure. A TCP segment is a header of 20 to 60 bytes followed by the data. The fixed part is five 32-bit rows; options, if any, follow in multiples of 4 bytes.
| Field | Bits | What it carries |
|---|---|---|
| Source port | 16 | the sending process |
| Destination port | 16 | the receiving process |
| Sequence number | 32 | the number of the first data byte in this segment; on a SYN, the initial sequence number (ISN) |
| Acknowledgement number | 32 | the next byte the sender of this segment expects to receive; valid when ACK = 1 |
| Header length (HLEN, data offset) | 4 | header length in 32-bit words, 5 to 15, so 20 to 60 bytes |
| Reserved | 4 (6 in RFC 793) | zero, kept for future use |
| Flags | 8 (6 in RFC 793) | CWR, ECE, URG, ACK, PSH, RST, SYN, FIN, one bit each |
| Window size | 16 | the receive window: how many more bytes the sender of this segment can accept |
| Checksum | 16 | error detection over the pseudo-header, header and data; mandatory |
| Urgent pointer | 16 | valid when URG = 1: the offset from the sequence number to the end of the urgent data |
| Options and padding | 0 to 320 | 0 to 40 bytes: MSS, window scale, SACK permitted, SACK, timestamps; padded to a 32-bit boundary |
The flags, one bit each:
- SYN: synchronize sequence numbers; set only on the first segment from each side, to open a connection.
- ACK: the acknowledgement number is valid; set on every segment after the first SYN.
- FIN: the sender has finished sending; closes its direction.
- RST: reset: abort the connection at once, or refuse a SYN sent to a port where nothing listens.
- PSH: push: hand the data to the application now, without waiting to fill a buffer (for example a keystroke in SSH).
- URG: the urgent pointer is valid: some data at the start is urgent, such as an interrupt key.
- CWR and ECE: explicit congestion notification (RFC 3168): a router marks congestion instead of dropping, and the sender slows down.
The options are agreed mostly in the SYN segments:
- MSS (maximum segment size): the largest data a host will take in one segment; 1460 bytes on Ethernet (1500 minus 20 of IP header and 20 of TCP header); 536 bytes is assumed for IPv4 when no option is sent.
- Window scale: multiplies the 16-bit window by up to 214, for windows up to about 1 GB.
- SACK: selective acknowledgement of blocks that arrived out of order.
- Timestamps: to measure the round-trip time.
The sequence space is 32 bits: it counts 4,294,967,296 bytes and then wraps round. The ISN is picked at random.
A laptop opens a connection to a web server. The first 20 bytes of its SYN segment, in hexadecimal:
C3 50 00 50 | 00 00 1F 40 | 00 00 00 00 | A0 02 FA F0 | (checksum) 00 00 C3 50 source port 50000 (a free port the client picked) 00 50 destination port 80 (HTTP) 00 00 1F 40 sequence number 8000, the client's ISN 00 00 00 00 ack number 0, not valid: the ACK flag is off A header length 10 words = 40 bytes, so 20 bytes of options follow 0 reserved 0000 02 flags 0000 0010: only SYN is set FA F0 window 64,240 bytes the client can receive 00 00 urgent pointer 0, not used
So this is a SYN from port 50000 to port 80, ISN 8000, with a 40-byte header whose options carry the MSS and the like.
Why TCP is called reliable: IP underneath may lose, corrupt, duplicate or reorder packets, yet TCP promises the application every byte, once, in order, or a clear error. It keeps that promise with these mechanisms (the lost-segment example on the transport service card shows them working together):
- Connection establishment: the handshake makes sure both sides are ready and agree the starting sequence numbers.
- Sequence numbers on every byte: the receiver detects gaps, puts segments back in order and throws away duplicates.
- Positive, cumulative acknowledgements: each ACK names the next byte expected, so one ACK confirms everything before it.
- Retransmission on timeout: the sender keeps a copy of each unacknowledged segment and a timer; if no ACK comes within the retransmission timeout (RTO), it resends and doubles the timeout.
- Fast retransmit: three duplicate ACKs mean a segment is missing, so it is resent at once without waiting for the timer.
- Checksum: a damaged segment is discarded, and so is recovered like a lost one.
- Flow control: the receive window stops the sender from overflowing the receiver, which would throw data away.
- Congestion control: slow start and the congestion window stop the senders from overflowing the routers.
- Graceful release: FIN and its ACK in each direction, so no data is cut off at the end.
How the timer is set: TCP measures the round-trip time R of segments and keeps a smoothed average SRTT and its variation RTTVAR (RFC 6298, which updates RTTVAR first, with the old SRTT):
So the timeout follows the network: a short, steady path gets a short timeout; a long, jittery one gets a longer one, which avoids resending segments that are only late.
To remember it, think of sending exam forms by courier to the campus office: every page is numbered (sequence numbers), the office phones to say "got pages 1 to 20, send 21 next" (cumulative ACK), any page not confirmed in time is sent again (timer and retransmission), and a torn page is treated as missing (checksum).
- Flags: Figure 5.4 shows six flags with the reserved bits unlabelled, RFC 793's layout with 6 reserved bits; RFC 9293 has 4 reserved bits and 8 flags, since RFC 3168 (2001) took two for CWR and ECE. Either drawing earns the marks if each row adds up to 32 bits.
- Window: it calls the window "the window size of the sending TCP"; precisely, it is the receive window that the sender of the segment advertises.
- Options: it says options provide "congestion control"; the options are MSS, window scale, SACK and timestamps, and congestion control works through TCP's window.
- Why TCP is known as reliable protocol? What are the congestion control techniques applied in network communication? Discuss Token Bucket approach and compare it with leaky bucket. 2081 Bhadra Q6 · 2+2+4
- Explain the TCP segment structure. Why TCP is known as reliable protocol and also describe how reliability is provided by TCP? 2076 Ashwin Q6 · 4+4
- What are the differences between TCP and UDP services? Explain the TCP datagram format in detail. 2075 Ashwin Q6 · 3+5
- Explain the TCP protocol with its Header. What do you understand by socket? Explain with its importance. 2074 Ashwin Q6 · 5+3
- For the client-server application over TCP, why must the server program be executed before the client program? TCP is known as reliable process how, describe reliability is provided by TCP. 2072 Chaitra Q6 · 3+5
- What is a TCP connection? Explain how a TCP connection can be gracefully terminated. 2072 Kartik Q6 · 2+6
- Write short notes on: a) ALOHA system b) TCP header 2070 Ashad Q10 · 4+4
- What are the differences between TCP and UDP services? Explain the TCP datagram format in detail. 2068 Chaitra Q7 · 3+5
- What are the functions of transport layer? Draw the segment structure of TCP. 2068 Baishakh Q5 · 3+5
TCP against UDP, and why the transport layer has two protocols HOT 6/27
82 Ba · 75 Ash · 71 Ch · 71 Shr · 69 Ch · 68 Ch3+51+2+52+2+4
| Point | TCP | UDP |
|---|---|---|
| Connection | connection-oriented: handshake, then release | connectionless |
| Reliability | reliable: acknowledgements and retransmission | unreliable: no ACK, no retransmission |
| Order | delivered in order (sequence numbers) | no ordering |
| Data unit | segment; a byte stream with no boundaries | user datagram; each message kept whole |
| Header | 20 to 60 bytes | 8 bytes |
| Flow and congestion control | yes: receive window, congestion window | none |
| Error checking | mandatory checksum; errors repaired by retransmission | checksum (optional in IPv4); a bad datagram is just dropped |
| Speed and delay | slower: a round trip to set up, waits for lost data | faster: sends at once, never waits |
| Casting | unicast only | unicast, broadcast and multicast |
| State at the server | a TCB and buffers per connection | none |
| IP protocol number | 6 | 17 |
| Used by | HTTP and HTTPS (80, 443), SMTP (25), FTP (20, 21), SSH (22), Telnet (23) | DNS (53), DHCP (67, 68), SNMP (161), TFTP (69), NTP (123), voice and video calls, games, QUIC |
To remember it: TCP is a phone call home. It rings, someone says "hello", you say "hajur, bhannus" before anything else (the handshake), and when a word is lost you ask "feri bhannu ta?" (retransmission). UDP is shouting the cricket score down the hostel corridor: no setup, nobody answers, and if one shout is missed the next one carries the new score anyway.
Why two transport protocols, when the internet layer has only one? The question asks why diversity is useful at the top of the stack and harmful in the middle.
- Applications want opposite things: a file transfer or a web page must arrive complete and in order, whatever the delay; a voice call must arrive on time, whatever is lost. One protocol cannot give both, because recovering a loss means waiting, and waiting is exactly what real-time traffic cannot do.
- The transport layer runs only in the end hosts (the end-to-end principle: put reliability where it is needed, at the ends). Two choices there cost the routers nothing.
- IP is the common meeting point: every router of every network must understand the network protocol, and every link technology (Ethernet, WiFi, 4G, fibre) must be able to carry it. One protocol, with a minimal best-effort service that any network can offer, is what lets any host reach any other: the narrow waist of the hourglass.
- Changing the waist is very costly: a new transport protocol needs only the end hosts to change, but a new network protocol needs every router to change. IPv6 shows the cost: decades into its rollout, IPv4 still carries much of the traffic (IPv4 to IPv6 transition).
- UDP keeps the door open: it exposes IP's raw service with ports added, so any application that wants its own reliability can build it, as QUIC does, without touching the network.
- Discuss UDP header and compare it with TCP. What is port address? Explain briefly about leaky-bucket algorithm used for traffic shaping. 2082 Baishakh Q6 · 2+2+4
- What are the differences between TCP and UDP services? Explain the TCP datagram format in detail. 2075 Ashwin Q6 · 3+5
- Why port number is used in networking? What are the services of transport layer? Differentiate between TCP and UDP protocol. 2071 Chaitra Q6 · 1+2+5
- Distinguish between TCP and UDP. How is TCP connection established? Explain. 2071 Shrawan Q6 · 3+5
- Why do you think that there exist two protocols in transport layer where as there exists only one protocol in Internet layer in TCP/IP reference model. Explain token bucket algorithm for congestion control. 2069 Chaitra Q6 · 5+3
- What are the differences between TCP and UDP services? Explain the TCP datagram format in detail. 2068 Chaitra Q7 · 3+5
5.3Port and socket
Ports and sockets: how a segment finds its process PIN 4/27
82 Ba · 80 Ba · 74 Ash · 71 Ch1+2+52+2+42+4+2
203.0.113.5:80; one TCP connection is named by a
pair of sockets.
Why port numbers are needed. An IP address brings data to a host, but a host runs many processes at once: a browser, a mail client, a game. Arrival at the host is not the end of the journey; the data must reach one process, so each process needs a label of its own. The book counts four levels of address in TCP/IP, one per layer:
| Address | Layer | Size | Names | Example |
|---|---|---|---|---|
| Physical (MAC) | data link | 48 bits | a network card on one link; changes hop to hop | 00:1A:2B:3C:4D:5E |
| Logical (IP) | network | 32 bits (IPv4) | a host anywhere on the internet; stays the same end to end | 203.0.113.5 |
| Port | transport | 16 bits | a process on that host | 80 |
| Application-specific | application | varies | a user or a document, turned into the others before sending | an e-mail address, a URL |
To remember it, think of a campus phone system. The college has one phone number (the IP address) and internal extensions: one for the accounts section, another for the exam section (ports). The extension numbers are printed on the notice board, so nobody has to ask (well-known ports). Whoever calls in is given a line for the length of the call (an ephemeral port).
The three ranges set by IANA (RFC 6335):
| Range | Numbers | Who sets them | Examples |
|---|---|---|---|
| Well-known (system) | 0 to 1023 | assigned by IANA to standard services; on Unix only the administrator (root) may open them | 22 SSH, 25 SMTP, 53 DNS, 80 HTTP, 443 HTTPS |
| Registered (user) | 1024 to 49151 | registered with IANA by vendors to avoid clashes, but not controlled | 3306 MySQL, 3389 Remote Desktop, 8080 HTTP alternate |
| Dynamic (private, ephemeral) | 49152 to 65535 | never assigned; free for anyone | a client's temporary port for one connection |
| Service | Transport | Port | Service | Transport | Port |
|---|---|---|---|---|---|
| FTP data, control | TCP | 20, 21 | POP3 | TCP | 110 |
| SSH | TCP | 22 | NTP | UDP | 123 |
| Telnet | TCP | 23 | IMAP | TCP | 143 |
| SMTP | TCP | 25 | SNMP, SNMP trap | UDP | 161, 162 |
| DNS | UDP and TCP | 53 | BGP | TCP | 179 |
| DHCP server, client | UDP | 67, 68 | HTTPS | TCP (and UDP for QUIC) | 443 |
| TFTP | UDP | 69 | RIP | UDP | 520 |
| HTTP | TCP | 80 |
Clients use ephemeral ports. When a browser opens a connection, the operating system gives it a free port for that connection only (Windows uses the IANA range 49152 to 65535; Linux by default 32768 to 60999). No standard is needed: the server reads the client's port from the SYN and replies to it.
Why the well-known ports are standardized:
- A meeting point known in advance: a client must know where to knock before any conversation starts. It learns the server's IP address from DNS, but nothing tells it the port, so the port must be agreed beforehand: every browser knows a web server is on 80 (443 for HTTPS), every mail server knows to reach another on 25.
- Interoperability: any client from any vendor reaches any server with no configuration and no extra lookup step.
- Defaults in software: a URL such as
http://ioe.edu.np/carries no port because port 80 is implied. - Administration and security: firewalls, NAT rules and intrusion detection are written per port (allow 443, block 23), and on Unix only the administrator can open a port below 1024, so a client knows a system service, not an ordinary user's program, is listening there.
- No clashes: one registry means two services never claim the same number.
A web service on port 8765 instead of 80. TCP does not care: the server works as well on 8765. What changes is how clients find it:
- The port must be written in the address:
http://www.example.com:8765/. Typed without it, the browser connects to port 80; if nothing listens there, the server's TCP answers the SYN with RST and the browser shows that the connection was refused. If some other service listens on 80, that service answers instead. - Every link, bookmark and search result must carry the port, and users must be told it.
- Firewalls may block it: many office and campus networks let out only 80 and 443.
- It is no real protection: hiding a service on an odd port is security through obscurity; a port scanner finds it in seconds.
- It has one convenience: 8765 is above 1023, so an ordinary user can run the server
without administrator rights. A student testing a site runs
python -m http.server 8765and browseshttp://localhost:8765/.
The socket and its importance. The word has two meanings that belong together:
- The address: socket = IP address : port, with the protocol. A TCP connection is the
pair of sockets, the four-tuple (source IP, source port, destination IP, destination port), so
one server socket
203.0.113.5:80can hold thousands of connections at once: each client socket differs in IP address or port. - The programming interface: the socket is also the door between an application and the transport layer in the host, the API (Berkeley sockets) through which every network program sends and receives. The application controls everything on its side of the door; on the transport side it chooses only the protocol (TCP or UDP) and a few settings such as buffer sizes and the maximum segment size.
- Why it matters: it identifies one process uniquely across the whole internet, lets many connections share one server port, separates the traffic of each connection, and is the interface on which every network application is written (socket programming).
- Discuss UDP header and compare it with TCP. What is port address? Explain briefly about leaky-bucket algorithm used for traffic shaping. 2082 Baishakh Q6 · 2+2+4
- What is port number? Why is it necessary to standardize the port numbers for well-known servers? What happens when a web service is hosted at some different port such as 8765 instead of 80? Explain. 2080 Baishakh Q6 · 2+4+2
- Explain the TCP protocol with its Header. What do you understand by socket? Explain with its importance. 2074 Ashwin Q6 · 5+3
- Why port number is used in networking? What are the services of transport layer? Differentiate between TCP and UDP protocol. 2071 Chaitra Q6 · 1+2+5
5.4Connection establishment and release
Opening and closing a TCP connection: the three-way handshake and the graceful release HOT 7/27
82 Bh · 81 Ba · 75 Ch · 74 Ch · 72 Ch · 72 Ka · 71 Shr3+54+42+3+3
Passive and active open. The two ends do not start alike. The server does a passive open: its program creates a socket, binds it to its well-known port, calls listen and waits in the LISTEN state. The client does an active open: it calls connect, which sends the first SYN.
Why the server program must run before the client. A shop must open its shutter before customers can walk in:
- Only a socket in LISTEN accepts a SYN. If no program listens on the port when the SYN arrives, the server host's TCP answers with RST, and the client's connect fails at once with "connection refused".
- TCP does not queue a SYN in the hope that a server appears later, so the server must be started first and be waiting.
- UDP is no different: a datagram to a port with no socket is dropped, and the host returns an ICMP port unreachable message (ICMP).
The handshake, step by step, with the numbers of the book's own figure (client ISN 8000, server ISN 15000):
- SYN (client to server): SYN = 1, seq = 8000, no data. The client moves from CLOSED to SYN-SENT. A SYN uses up one sequence number, and it usually carries options such as the MSS and the window scale.
- SYN + ACK (server to client): SYN = 1, ACK = 1, seq = 15000, ack = 8001. The server allocates its buffers and connection record and moves from LISTEN to SYN-RECEIVED.
- ACK (client to server): ACK = 1, seq = 8001, ack = 15001. The client becomes ESTABLISHED on sending it, the server on receiving it. This third segment may already carry data.
Why three segments and not two:
- Both starting numbers must be confirmed. Each side picks its own ISN and must know that the other received it: the SYN + ACK confirms the client's, the final ACK confirms the server's.
- Old duplicates must not open connections. The network can delay a SYN from an earlier attempt and deliver it late. With a two-way scheme the server would open a connection nobody wants. With three, the server's SYN + ACK reaches the client, which recognizes an acknowledgement of a request it never made and answers RST, so the server drops it (the book's Figure 5.9).
- The ISN is random, not 0, so that segments of an old connection on the same ports are not mistaken for new ones, and so an attacker cannot guess the numbers and inject data.
To remember it, think of a phone call home. "Hello Aama, can you hear me?" (SYN). "Yes, I can hear you; can you hear me?" (SYN + ACK). "Yes!" (ACK). Only now does the real talk start.
The SYN flood, an attack on the handshake: an attacker sends floods of SYNs from forged addresses and never sends the third ACK. Each half-open connection takes the server's memory until its queue is full and real clients are refused. Defences: SYN cookies (the server encodes the connection's details in its ISN and keeps no state until the ACK returns), shorter timeouts, and filtering at the firewall (firewalls).
The release, graceful and in four segments, continuing the same connection after the client sent 1,000 bytes (8001 to 9000) and the server 500 (15001 to 15500):
- FIN (client to server): seq = 9001, ack = 15501. The client application has finished sending; the client enters FIN-WAIT-1. A FIN uses up one sequence number, like a SYN.
- ACK (server to client): seq = 15501, ack = 9002. The server enters CLOSE-WAIT and tells its application; the client enters FIN-WAIT-2. The connection is now half-closed: the server may still send data to the client.
- FIN (server to client): seq = 15501, ack = 9002, when the server application closes too. The server enters LAST-ACK.
- ACK (client to server): seq = 9002, ack = 15502. The server closes on receiving it; the client waits in TIME-WAIT for twice the maximum segment lifetime (2 MSL), then closes.
Why four segments: TCP is full duplex, so each direction is a separate stream that must be closed on its own; the side that has finished says FIN, the other acknowledges, and can keep sending until it is done too. When the server has nothing left to send, it may combine its ACK and FIN in one segment, and the release takes three segments.
Why TIME-WAIT: if the last ACK is lost, the server resends its FIN, and the client must still be there to acknowledge it again; and waiting lets any delayed segments of this connection die out, so a new connection on the same pair of ports cannot receive them. RFC 793 suggested an MSL of 2 minutes (TIME-WAIT of 4 minutes); real systems wait less, Linux for 60 seconds.
Abrupt release: RST ends a connection at once, without the exchange of FINs, and any data still in flight is lost: used when a program crashes or a segment arrives that matches no connection.
| State | Meaning | State | Meaning |
|---|---|---|---|
| CLOSED | no connection | FIN-WAIT-2 | own FIN acknowledged; waiting for the other side's FIN |
| LISTEN | server waiting for a SYN | CLOSE-WAIT | got a FIN; waiting for the local application to close |
| SYN-SENT | client sent SYN; waiting for SYN + ACK | LAST-ACK | sent its own FIN after CLOSE-WAIT; waiting for the last ACK |
| SYN-RECEIVED | server got SYN, sent SYN + ACK; waiting for ACK | CLOSING | both sides sent FIN at the same moment |
| ESTABLISHED | open: data flows both ways | TIME-WAIT | waiting 2 MSL after the final ACK |
| FIN-WAIT-1 | sent FIN; waiting for its ACK |
- Write UDP header field and functions. Explain TCP 3-way hand shaking for connection establishment and release. 2082 Bhadra Q6 · 2+3+3
- Though UDP is said to be unreliable protocol, it is used in Internet. Why? Explain the three way handshake principle of a TCP connection between client and server. 2081 Baishakh Q6 · 3+5
- Explain connection establishment and termination in TCP. Explain briefly about Leaky-Bucket algorithm for congestion control? 2075 Chaitra Q6 · 4+4
- How connection is established and released in TCP. Explain Token Bucket algorithm. 2074 Chaitra Q6 · 4+4
- For the client-server application over TCP, why must the server program be executed before the client program? TCP is known as reliable process how, describe reliability is provided by TCP. 2072 Chaitra Q6 · 3+5
- What is a TCP connection? Explain how a TCP connection can be gracefully terminated. 2072 Kartik Q6 · 2+6
- Distinguish between TCP and UDP. How is TCP connection established? Explain. 2071 Shrawan Q6 · 3+5
5.5Flow control and buffering
Flow control and buffering: TCP's sliding window PIN 2/27
78 Bh · 66 Bh2×43+3
Why the receiver needs protecting. The receiving application may read slowly (a busy phone, a program doing other work), so data piles up in TCP's receive buffer. If the sender kept going, the buffer would overflow and data would be thrown away. So the receiver tells the sender, in the window field of every segment it sends, how much more it can take.
The window on the byte stream. The sender sees its bytes in four groups: sent and acknowledged; sent but not yet acknowledged (in flight); not yet sent but allowed (the usable window); and not allowed until the window moves. The window's left edge is the last acknowledgement; its right edge is that plus rwnd.
- Start: the last ACK was 3001 and rwnd = 4000, so the sender may have bytes 3001 to 7000 outstanding. It has sent up to 6000: 3,000 bytes are in flight and 1,000 more (6001 to 7000) may go now.
- An ACK arrives: ack = 5001, window = 4000. The left edge moves to 5001 and the window now covers 5001 to 9000: 1,000 bytes are in flight and 3,000 may be sent. The window has slid 2,000 bytes to the right.
- The application reads slowly: if the next ACK said ack = 5001 but window = 2000, the right edge would stay at 7000: only 1,000 bytes could go.
- The buffer fills: window = 0 stops the sender. It then sends small window probes on a persist timer until the receiver advertises space again; without them, a lost window update would leave both sides waiting for ever.
To remember it, think of a water tanker filling a household tank: the driver asks how much room is left before pumping, and pumps no more than that; as the family uses water, the room grows and he can pump again. The tank's free space is the receive window.
Two refinements:
- Silly window syndrome: if a receiver frees one byte at a time and advertises one-byte windows, the sender sends one-byte segments with 40 bytes of headers each. Clark's fix: the receiver waits to advertise until it can take a full segment or half its buffer. Nagle's algorithm (RFC 896): a sender with small pieces of data sends one and holds the rest until it is acknowledged or a full segment has gathered.
- Window scaling: the 16-bit field allows only 65,535 bytes, and a sender can send at most one window per round trip. With a 100 ms round trip that caps a connection at 65,535 × 8 / 0.1, about 5.24 Mbps, however fast the line. A 100 Mbps path with a 100 ms round trip needs 100,000,000 × 0.1 / 8 = 1,250,000 bytes in flight (the bandwidth-delay product), so the window scale option multiplies the field by up to 214.
With congestion control, the sender's real limit is the smaller of the two windows: min(rwnd, cwnd), where cwnd is its own estimate of what the network can take (5.7).
Buffering. A host may have hundreds of connections at once, so the data link layer's habit of one fixed set of buffers per line does not work. Buffer space is shared, and its size is agreed at connection setup and adjusted as the receiver advertises. The book gives three ways to organize it:
| Scheme | How | Good for | Weakness |
|---|---|---|---|
| Chained fixed-size buffers | a pool of identical buffers, one segment (TPDU) each | segments all about the same size | a small segment wastes most of a buffer; a big one needs several |
| Chained variable-size buffers | each buffer cut to fit its segment | sizes that vary from a few bytes to thousands | harder memory management |
| One large circular buffer per connection | a ring the connection's data flows round | busy connections that keep it full | wastes memory on lightly loaded connections |
Where to buffer depends on the traffic: for low-rate, bursty traffic such as an interactive terminal it is better to buffer at the sender and let the receiver grab buffers when data arrives; for bulk transfer such as a file download the receiver should set aside a full window of buffers, so the data can flow at full speed.
| Point | Link-level sliding window (chapter 3) | TCP's window |
|---|---|---|
| Counts | frames | bytes |
| Sequence numbers | small, such as 3 bits (0 to 7) | 32 bits |
| Window size | fixed when the protocol is set up | changes in every segment: the receiver advertises it |
| Scope | one link, hop by hop | end to end, across many networks |
| Recovery | go-back-N or selective repeat (ARQ) | cumulative ACKs like go-back-N, but early segments are kept and SACK resends only gaps, like selective repeat |
- Write short notes on: (Any Two) a) Frame relay b) TCP sliding window c) HDLC 2078 Bhadra Q10 · 2×4
- Write short notes on (any two) i) TCP Sliding Window Protocol ii) Secrete Key Algorithm: DES iii) ISDN Signaling and ATM AAL iv) ICMP Message Types 2066 Bhadra Q5b · 3+3
5.6Multiplexing and demultiplexing
Multiplexing and demultiplexing: many processes, one IP address
Every host does both all the time. A laptop with two browser tabs open and a DNS query in progress has three sockets but one IP address. Segments for all three arrive at that one address; the transport layer sorts them by port.
- UDP demultiplexes by two values: destination IP and destination port. Datagrams from any number of senders to the same port land in the same socket, and the application tells them apart by their source addresses if it cares.
- TCP demultiplexes by four values: source IP, source port, destination IP and destination port. A web server listening on port 80 has a separate socket for every client connection; two connections to port 80 differ in the client's IP address or port (socket pairs).
To remember it, think of the hostel's mail. One postbag arrives at the gate for the whole hostel (one IP address); the warden sorts it by room number into the residents' boxes (demultiplexing). In the morning the residents drop their letters in one outgoing bag, each with its own room number as the return address (multiplexing).
The older sense of the word, which the book also uses, is about network connections rather than processes:
- Upward multiplexing: several transport connections share one network connection or address, which saves cost where network connections are scarce or charged for (as virtual circuits once were). Worth it while the shared bandwidth covers the needs of all.
- Downward (inverse) multiplexing: one transport connection is spread over several network paths to add their bandwidth or survive a failure, as Multipath TCP (RFC 8684) and SCTP with several addresses do.
Not the physical layer's multiplexing: FDM and TDM share one cable among several signals (multiplexing in chapter 2); here it is one IP address shared by several processes, and the "channel number" is the port.
5.7Congestion control: the leaky bucket and the token bucket
Congestion: causes, the parameters that affect it, prevention and control PIN 4/27
81 Bh · 73 Shr · 66 Po · 66 Bh2+2+42+64+6
Congestion control is not flow control. Flow control protects one receiver from one sender (5.5); congestion control protects the network, its links and router buffers, from all the senders together. A fast laptop sending to a slow phone needs flow control; a whole hostel uploading through one shared link needs congestion control.
To remember it, think of the day exam results come out. Thousands of students open the same results page within minutes. The links and the server have not changed, only the load, and pages that open in a second on other days time out; every refresh adds more load. That is congestion, and refreshing harder is the congestion collapse.
Causes, the factors behind congestion, in a WAN or any packet-switched network:
- Arrival rate above the outgoing capacity: several input lines feeding one output line; the queue for that line grows without limit.
- Too little buffer memory in routers, so packets are dropped when queues fill. Yet more memory is no cure: packets then wait so long that they time out and are resent as duplicates, adding load (Nagle, 1987).
- Bursty traffic: many sources sending in bursts at once exceed capacity for a while, even when the average load is fine.
- Slow processors and slow lines: a router that cannot queue, route and forward fast enough, or a low-bandwidth link, becomes the bottleneck.
- Retransmissions: every lost or late packet is sent again, so congestion feeds itself.
- Poor routing and long packet lifetimes: traffic piled onto one path while others stand idle, and old packets wandering about.
How the parameters affect it: the policies chosen at each layer push congestion up or down. Each row is a parameter a designer sets:
| Layer | Policy (parameter) | How it affects congestion |
|---|---|---|
| Transport | retransmission policy | a hasty timer or go-back-N resends more, adding load |
| Transport | out-of-order caching policy | throwing away early segments forces them to be sent again |
| Transport | acknowledgement policy | an ACK for every segment adds traffic; delayed and piggybacked ACKs cut it |
| Transport | flow control policy | a small window keeps the sending rate, and so the load, down |
| Transport | timeout determination | too short: needless duplicates; too long: slow recovery |
| Network | virtual circuits against datagrams | circuits allow admission control and reserved resources |
| Network | packet queueing and service policy | one queue or one per line, first come first served or fair turns |
| Network | packet discard policy | which packet is dropped when a queue is full |
| Network | routing algorithm | spreading traffic over many paths relieves a hot spot |
| Network | packet lifetime management | too long: old packets clog queues; too short: packets die and are resent |
| Data link | retransmission, out-of-order caching, acknowledgement and flow control policies | the same effects as at the transport layer, on each link |
Load and delay: queueing theory shows why delay explodes near capacity. For a link that can serve μ packets a second, fed λ packets a second at random (the M/M/1 queue), the average time a packet spends there is
With μ = 1,000 packets per second: at λ = 500 a packet takes 2 ms; at 900, 10 ms; at 990, 100 ms. The last 10% of load costs ten times the delay, which is why networks are run well below full load.
Prevention policies (open loop: design the system so that congestion does not start):
- Retransmission policy: good timers, so packets are not resent while merely late.
- Window policy: selective repeat rather than go-back-N, so only the lost packet is resent.
- Acknowledgement policy: cumulative, delayed and piggybacked ACKs, fewer packets in all.
- Discard policy: routers drop the least important packets first, such as some packets of an audio stream, without harming quality much.
- Admission policy: a virtual circuit network refuses a new flow that would congest it.
- Traffic shaping: each source agrees a rate and burst size, and its traffic is smoothed to fit before entering the network: the leaky and token buckets (leaky bucket, token bucket).
The congestion control techniques come in two families:
| Family | Idea | Techniques |
|---|---|---|
| Open loop (prevention) | good design, no feedback | the policies above, admission control, traffic shaping with the leaky and token buckets, resource reservation |
| Closed loop (removal) | monitor, feed the news back, adjust | backpressure (a congested router asks the router before it to slow down), choke packets sent to the source, implicit signalling (the source infers congestion from loss or delay, as TCP does), explicit signalling (ECN bits set by routers), load shedding (dropping packets), random early detection (RED: dropping a few packets early, before the queue is full) |
Closed loop works in three steps: detect the congestion (queue lengths, drops, delay), send the information to the places that can act, and adjust the system (slow the sources).
TCP's own congestion control is the closed loop at the hosts (RFC 5681): the sender keeps a congestion window, cwnd, beside the receiver's window.
- Slow start: cwnd begins small and doubles every round trip until it reaches a threshold.
- Congestion avoidance: after that it grows by one segment per round trip (additive increase).
- On three duplicate ACKs: it is halved (multiplicative decrease), with fast retransmit and fast recovery.
- On a timeout: it drops back to one segment and slow start begins again.
Traffic shaping and policing. Shaping regulates the average rate and the burstiness of a flow before it enters the network, holding packets back to make it conform; policing only monitors a flow and drops (or tags) the packets that break its agreed profile. Both use the buckets that follow.
- Why TCP is known as reliable protocol? What are the congestion control techniques applied in network communication? Discuss Token Bucket approach and compare it with leaky bucket. 2081 Bhadra Q6 · 2+2+4
- Discuss about the network congestion? Explain how different network parameters effect the congestion. Compare operation of link state routing with the distance vector routing. 2073 Shrawan Q5 · 2+2+4
- Describe the policies that help in preventing the congestions within the network? Differentiate between leaky bucket and token bucket algorithm with their operation and working of token bucket. 2066 Poush Q5 · 4+6
- What are the factors that cause congestion within WAN? Propose your best traffic shaping approach to manage congestion in packet switched network. 2066 Bhadra Q4b · 2+6
The leaky bucket: bursty in, steady out HOT 5/27
82 Ba · 78 Bh · 75 Ch · 70 Asa · 66 Po3+52+2+44+4
The picture is a bucket with a small hole in the bottom. However fast water pours in, it leaves through the hole at the same steady rate while there is any in the bucket, and not at all when it is empty; once the bucket is full, more water spills over the side and is lost. Put packets for water and a host's interface queue for the bucket.
The algorithm, for packets of one fixed size:
- A packet arrives from the host. If the bucket (queue) is full, the packet is discarded.
- Otherwise it joins the queue.
- At every clock tick, one packet leaves the head of the queue for the network; if the queue is empty, nothing leaves.
- The result: however bursty the input, the output is a smooth stream at the fixed rate, at most one packet per tick.
For packets of different sizes, count bytes instead (the book's version):
- At each tick, set a counter to n bytes.
- While the packet at the head fits (its size is not more than the counter), send it and subtract its size from the counter.
- When the next packet does not fit, stop until the next tick.
- Reset the counter at the next tick and go back to step 2. What was left of n is not carried forward, so no tick sends more than n bytes.
Four packets wait: 200, 700, 500 and 300 bytes.
- Tick 1: counter 1,000. Send 200 (800 left), send 700 (100 left); 500 does not fit in 100, so stop. 900 bytes went out; the 100 left over is lost, not saved.
- Tick 2: counter reset to 1,000. Send 500 (500 left), send 300 (200 left). The queue is empty.
And with fixed-size packets: a bucket that holds 6 packets and sends 1 per millisecond, hit by a burst of 10 packets at once, keeps 6 and discards 4; the 6 leave one per millisecond. The burst has been spread out, at the cost of 4 packets.
To remember it, think of the ceramic water filter found in many Nepali kitchens: pour a whole jug in at once, and clean water still drips from the tap at the same slow rate; pour in more than the top pot holds and it overflows.
What it is good at, and what it is not:
- Good: it removes burstiness completely, so the network sees a predictable, constant-rate flow that is easy to plan for; it is simple, a queue and a clock.
- Rigid: the output rate is the same when the network is idle and could take more; an idle host saves up nothing for later.
- Lossy: a burst bigger than the bucket loses packets.
- Slow to respond: a sudden burst of urgent data is still drained at the fixed rate. The token bucket fixes these (token bucket).
- Discuss UDP header and compare it with TCP. What is port address? Explain briefly about leaky-bucket algorithm used for traffic shaping. 2082 Baishakh Q6 · 2+2+4
- What are services provided by Transport layer? Explain about Leaky-Bucket algorithm for congestion control? 2078 Bhadra Q6 · 3+5
- Explain connection establishment and termination in TCP. Explain briefly about Leaky-Bucket algorithm for congestion control? 2075 Chaitra Q6 · 4+4
- Compare between leaky bucket and token bucket algorithm with the operation how token bucket works. 2070 Ashad Q8 · 3+5
- Describe the policies that help in preventing the congestions within the network? Differentiate between leaky bucket and token bucket algorithm with their operation and working of token bucket. 2066 Poush Q5 · 4+6
The token bucket: saving up permission to burst TOP 9/27
81 Bh · 80 Bh · 76 Ch · 74 Ch · 72 Ch · 70 Asa · 69 Ch · 66 Po · 66 Bh4+45+32+2+4
The bucket holds permission, not data. The leaky bucket stores packets and lets them out at one rate. The token bucket stores tokens; packets wait in the host's queue and go as fast as the line allows while tokens last.
The algorithm:
- Every ΔT seconds a token is added to the bucket (a rate r = 1/ΔT tokens a second). If the bucket already holds C tokens, the new token is thrown away.
- A packet may be sent only if a token is available; sending it removes one token (in the byte version, one token per byte, so a packet takes as many tokens as its size).
- With no token, the packet waits in the queue until one arrives. The bucket throws away tokens, never packets.
- The implementation is one counter: add 1 every ΔT (up to C), subtract 1 for every packet sent; while the counter is 0, nothing is sent.
The book's example: a host with 5 packets waiting and 3 saved tokens sends 3 packets at once, a burst; the other 2 wait for the next two tokens. A leaky bucket would have let the 5 out one tick apart.
How long can a burst last? Let C be the bucket capacity (in bits or bytes), r the token rate, M the maximum output rate of the line, and S the length of the burst in seconds. During the burst the host sends M·S. It can pay for that with the C tokens it had saved plus the rS that arrive during the burst:
A router shapes a hostel's upload. Line rate M = 10 Mbps, token rate r = 2 Mbps, and the bucket is full with C = 6 Mb of tokens (750 KB). A student's laptop sends a 12 Mb file at full speed.
- The burst: for 0.75 s the file goes at the full 10 Mbps, carrying 10 × 0.75 = 7.5 Mb. Check: the 6 Mb saved plus 2 × 0.75 = 1.5 Mb that arrived on the way make exactly 7.5 Mb.
- Then the average rate: the remaining 12 − 7.5 = 4.5 Mb goes at r = 2 Mbps, taking 2.25 s. The whole file is out after 0.75 + 2.25 = 3.0 s.
- A leaky bucket at the same 2 Mbps would take 12 / 2 = 6 s, and if it could hold only 6 Mb, 3.6 Mb of the burst would overflow and be lost.
Same average rate, same long-run load on the network; the token bucket finished in half the time and lost nothing.
To remember it, think of meal coupons in a hostel mess: each student gets one coupon a day, and unused coupons pile up to at most three. On a hungry day after two light ones you can eat three meals at once (the burst), but over a month nobody eats more than one meal a day on average (the rate). The leaky bucket is a mess that serves exactly one plate a day, hungry or not.
Leaky bucket and token bucket compared:
| Point | Leaky bucket | Token bucket |
|---|---|---|
| Bucket holds | packets (the data) | tokens (permission to send) |
| Output | constant rate r, always | average r, with bursts up to C at the line rate |
| Idle host | saves nothing | saves tokens, up to C |
| When the bucket is full | arriving packets are discarded | arriving tokens are discarded; packets wait |
| Burstiness | removed entirely | allowed, but bounded by C |
| Response to a sudden burst | slow: drained at r | fast: sent at once while tokens last |
| Use of an idle network | wasted | used by the saved burst |
| Parameters | queue size, output rate | token rate r, bucket size C |
| Implementation | a queue drained by a clock (or a byte counter reset each tick) | a token counter and a queue |
How the token bucket controls congestion better than the leaky bucket: both hold the long-run rate at r, so the network's average load is the same and is still guaranteed. On top of that, the token bucket:
- uses idle capacity: a host that was quiet may spend the capacity it left unused;
- responds at once: a burst goes out immediately instead of queueing;
- loses no data when the bucket fills: only tokens are thrown away;
- still bounds the worst case: no burst exceeds C, so the network knows the most it must absorb.
Both together: a burst at the full line rate M may still be too much for the network. Putting a leaky bucket of rate p (r < p < M) after the token bucket caps the peak rate as well, while the token bucket keeps the average at r.
A proposed traffic shaping approach for a packet-switched network, built from these parts:
- Agree a profile with each source at the network's edge: an average rate r and a burst size C (and a peak rate p if needed).
- Shape at the source with a token bucket (r, C), followed by a leaky bucket at p to cap the peak.
- Police at the edge router with the same token bucket: packets within the profile go through; packets beyond it are dropped, or tagged low priority to be dropped first if a queue fills.
- Back it with closed-loop control inside the network: TCP's congestion window at the hosts and early dropping or ECN at the routers.
Why this is the best choice: the average load each source can impose is fixed, so the network can be planned; bursts are allowed but bounded; nothing is lost while a source keeps to its profile; and an idle network is used rather than wasted. This is how ISPs enforce the speed of a plan, and how the Internet's quality of service schemes describe a flow (a token bucket rate and depth).
- Why TCP is known as reliable protocol? What are the congestion control techniques applied in network communication? Discuss Token Bucket approach and compare it with leaky bucket. 2081 Bhadra Q6 · 2+2+4
- How does the transport layer ensure that the complete message arrive at the destination and in the proper order? How does Token Bucket control the congestion over the Leaky Bucket algorithm? 2080 Bhadra Q6 · 4+4
- What are the major task of transport layer? Explain. What is token bucket algorithm? 2076 Chaitra Q6 · 5+3
- How connection is established and released in TCP. Explain Token Bucket algorithm. 2074 Chaitra Q6 · 4+4
- What is routed and routing protocol? Give examples. Explain Token Bucket algorithm. 2072 Chaitra Q5 · 4+4
- Compare between leaky bucket and token bucket algorithm with the operation how token bucket works. 2070 Ashad Q8 · 3+5
- Why do you think that there exist two protocols in transport layer where as there exists only one protocol in Internet layer in TCP/IP reference model. Explain token bucket algorithm for congestion control. 2069 Chaitra Q6 · 5+3
- Describe the policies that help in preventing the congestions within the network? Differentiate between leaky bucket and token bucket algorithm with their operation and working of token bucket. 2066 Poush Q5 · 4+6
- What are the factors that cause congestion within WAN? Propose your best traffic shaping approach to manage congestion in packet switched network. 2066 Bhadra Q4b · 2+6
5.8Last minute recall
Chapter 5 in one screen
- Transport layer: process-to-process delivery, end to end, only in hosts; services: addressing (ports), segmentation, connection control, reliability, ordering, flow control, multiplexing, congestion control.
- Complete and in order: handshake, numbered bytes, checksum, cumulative ACK, retransmission on timeout or three duplicate ACKs, reordering buffer, window, FIN.
- Services to the upper layer: connection-oriented (TCP, a phone call) and connectionless (UDP, a letter); primitives LISTEN, CONNECT, SEND, RECEIVE, DISCONNECT; TPDU.
- UDP (RFC 768): 8-byte header: source port, destination port, length (at least 8), checksum (optional in IPv4, mandatory in IPv6, with a pseudo-header, protocol 17); used for DNS, DHCP, VoIP, games, SNMP, TFTP, QUIC.
- TCP (RFC 9293): reliable, ordered, full-duplex byte stream; header 20 to 60 bytes: ports, sequence, acknowledgement, HLEN, reserved, flags (CWR ECE URG ACK PSH RST SYN FIN), window, checksum, urgent pointer, options.
- TCP against UDP: reliability against speed; protocol 6 against 17; two transports but one IP: end hosts choose, every router must share one waist.
- Ports: 16 bits; well-known 0 to 1023, registered 1024 to 49151, dynamic 49152 to 65535; socket = IP : port; a connection = a socket pair (four-tuple).
- Handshake: SYN seq 8000; SYN + ACK seq 15000 ack 8001; ACK seq 8001 ack 15001; server opens passively first, or the client gets RST.
- Release: FIN, ACK, FIN, ACK; half-close; FIN-WAIT-1, FIN-WAIT-2, TIME-WAIT 2 MSL; CLOSE-WAIT, LAST-ACK.
- Sliding window: rwnd in every segment; in flight at most rwnd; slides on ACK; zero window and persist timer; buffers: chained fixed, chained variable, circular.
- Demultiplexing: UDP by destination IP and port, TCP by the four-tuple.
- Congestion: load above capacity; causes: arrival rate, memory, bursts, slow processors, retransmissions; open loop (policies, shaping) and closed loop (choke packets, backpressure, ECN, RED, TCP slow start and AIMD).
- Leaky bucket: packets in a finite queue, out at a constant rate, dropped when full; byte counting n a tick.
- Token bucket: tokens at rate r up to C; bursts up to C; S = C / (M − r); with C = 6 Mb, M = 10 Mbps, r = 2 Mbps, S = 0.75 s.
Chapter 6 · 5 hours · about 8 marks a paper · in 24 of the 27 sittings
Application layer
The application layer is where a network finally does something a person can see: a web page opens, a mail arrives, a file lands on a laptop. This chapter teaches the protocols behind those services (HTTP, FTP, SMTP, POP3, IMAP, DNS and DHCP), how a program reaches the network through sockets, how busy servers are kept fast and running, and the tools that watch the traffic. The board sets it almost every time: 24 of the 27 sittings on record ask a question on it, as Question 7 in 19 of them, and DNS and electronic mail have each been set 11 times.
- The application layer and the web: what the layer does, the well-known ports, and HTTP and HTTPS: how a browser's request is served by a web server.
- File transfer: FTP's two connections (port 21 for control, port 20 for data), TFTP, and secure remote access with SSH, PuTTY and WinSCP.
- Electronic mail: user agents and mail servers, SMTP to send, POP3 and IMAP to read, and MIME for pictures and attachments.
- Names and addresses: DNS, the Internet's distributed directory (the name space, the servers, recursive and iterative queries, resource records, delegation, the message format), and DHCP, which hands a host its address.
- Programs and servers: P2P applications, socket programming in C, proxy servers and web caching, server optimization and RAID.
- Watching the network: SNMP, MRTG and PRTG, Wireshark and Packet Tracer.
- It sits on chapter 5's transport layer: every protocol here chooses TCP or UDP and a port (ports and sockets, TCP, UDP), and every TCP conversation below begins with the three-way handshake.
- Client-server and peer-to-peer are chapter 1's networking models (networking models); here they run as real applications.
- Securing these services is chapter 8's job: HTTPS rests on TLS (SSL and TLS), secure mail on PGP (PGP), and a proxy is a kind of application gateway (firewalls).
- DHCP hands out chapter 4's IPv4 addresses (IPv4 addressing), and DNS's AAAA records carry chapter 7's IPv6 addresses (IPv6 addressing).
- 6.1 The application layer and its ports; HTTP and HTTPS
- 6.2 FTP and TFTP; SSH, PuTTY and WinSCP
- 6.3 Electronic mail: SMTP, POP3, IMAP and MIME
- 6.4 DNS; DHCP
- 6.5 P2P applications
- 6.6 Socket programming
- 6.7 Proxy servers and web caching; server optimization; RAID
- 6.8 SNMP; MRTG and PRTG; Wireshark and Packet Tracer
- 6.9 Last minute recall, chapter 6
- DNS and electronic mail are the chapter's bankers, 11 sittings each. For DNS: what it is and why, recursive against iterative queries drawn with numbered steps, resource records, delegation and the message format. For mail: the components, SMTP step by step, POP3 against IMAP in a table, and MIME for images.
- HTTP and socket programming come next, 5 sittings each: how a request is served, HTTP against HTTPS, a web server, and the socket calls with a short client and server.
- FTP (4 sittings), proxy servers (3), DHCP and RAID (1 each) complete the list. FTP's answer is a drawing of the two connections with their ports.
- Draw the DNS lookup with numbered arrows, the mail system with SMTP and POP3 or IMAP, the SMTP exchange, FTP's control and data connections, and the DHCP lease timeline. The syllabus does not list DHCP; the 2082 Baishakh paper set it beside DNS, so it is taught beside DNS in 6.4.
6.1The application layer and the web
The application layer: what it does, and the ports its protocols use
Only the end systems run it. The routers and switches in between work at the network layer and below; a browser on a laptop in a Pulchowk hostel and the web server it talks to are the only two machines that read the HTTP messages passing between them (the TCP/IP model). That is why a new application can spread across the Internet without changing a single router.
Two architectures carry almost every application (networking models):
- Client-server: an always-on server with a fixed address and a well-known port serves many clients, which never talk to each other directly: the web, mail, FTP, DNS.
- Peer-to-peer (P2P): ordinary hosts (peers) both ask and serve, with little or no central server: BitTorrent (P2P applications).
Processes talk through sockets. A process hands its message to its socket, the door between the application and the transport layer. The message is addressed by the destination host's IP address and the receiving process's port number (ports and sockets, socket programming). Servers wait on well-known ports (0 to 1023), so a client knows where to knock; the client's own port is a temporary one its operating system picks.
What an application asks of the transport layer: reliable delivery, enough throughput, low delay and security. TCP gives reliability, so the web, mail and file transfer use it; UDP gives speed and no connection setup, so DNS queries, DHCP, SNMP, TFTP and live voice use it, and repair any loss themselves or live with it.
| Protocol | Job | Transport | Server port |
|---|---|---|---|
| HTTP | fetch web pages and their objects | TCP | 80 |
| HTTPS | HTTP inside TLS | TCP | 443 |
| FTP | file transfer with a login | TCP | 21 control, 20 data (active mode) |
| SSH, SCP, SFTP | encrypted remote login and file copy | TCP | 22 |
| Telnet | plain-text remote login | TCP | 23 |
| SMTP | send and relay mail | TCP | 25 between servers, 587 from a user agent |
| DNS | names to addresses | UDP; TCP for zone transfers and long replies | 53 |
| DHCP | give a host its IP settings | UDP | 67 server, 68 client |
| TFTP | simple file transfer, no login | UDP | 69 |
| POP3 | download mail from a mailbox | TCP | 110 (995 with TLS) |
| IMAP | manage mail kept on the server | TCP | 143 (993 with TLS) |
| SNMP | monitor and manage devices | UDP | 161 agent, 162 traps |
To remember the idea: the IP address is the ward office building and the port is the counter number inside it. The building gets the citizen to the right office; the counter decides which clerk (process) takes the form. Counter 25 takes letters, counter 53 answers "where is this name?", counter 80 hands out pages.
HTTP and HTTPS: how a browser's request is served HOT 5/27
81 Ba · 75 Ch · 75 Ash · 73 Shr · 69 Ch2+66+24+4
A web page is many objects. A page is a base HTML file plus everything it
references: images, style sheets, scripts. Each object is named by a URL (uniform
resource locator). In https://www.example.com:443/notes/ch6.html?lang=np the
scheme is https, the host www.example.com, the port 443
(left out when it is the default), the path /notes/ch6.html and the query
lang=np. A page with ten images costs the browser eleven requests.
How a request is served, step by step (the drawing follows one request):
- Name to address: the browser takes the host name from the URL and asks DNS for its IP address (DNS).
- Connection: it opens a TCP connection to that address, port 80, with the three-way handshake (three-way handshake); for HTTPS it connects to port 443 and runs the TLS handshake as well.
- Request: it sends a request message, such as
GET /index.html HTTP/1.1followed by header lines. - Processing: the web server parses the request, maps the path to a file under its document root (or runs a program, such as a PHP script, for a dynamic page) and builds a response.
- Response: it sends a status line (
HTTP/1.1 200 OK), header lines and the object as the body. - Render and repeat: the browser parses the HTML, finds the images and scripts it references, requests each of them, and draws the page.
- Close or keep: the connection is closed, or kept open for the next request (persistent HTTP).
The request message is plain text: a request line (method, path, version), header
lines of the form Name: value, a blank line, and an optional body (a form's data
with POST).
GET /notes/ch6.html HTTP/1.1 Host: www.example.com User-Agent: Mozilla/5.0 Accept: text/html Accept-Language: en, ne Connection: keep-alive
The response message mirrors it: a status line (version, status code, phrase), header lines, a blank line, and the object as the body.
HTTP/1.1 200 OK Date: Sun, 04 Oct 2026 09:00:00 GMT Server: Apache Last-Modified: Fri, 02 Oct 2026 16:30:00 GMT Content-Type: text/html; charset=UTF-8 Content-Length: 5120 <!DOCTYPE html><html> ... the page ... </html>
| Method | What it asks the server |
|---|---|
| GET | send the object at this URL (most requests) |
| HEAD | the headers GET would send, without the body: is it there, how big, how new |
| POST | take this data and process it: a login form, a file upload |
| PUT | store this body at this URL, creating or replacing it |
| DELETE | remove the object at this URL |
| PATCH, OPTIONS, CONNECT, TRACE | change part of an object; list the methods allowed; open a tunnel through a proxy (used for HTTPS); echo the request back |
| Class | Meaning | Common codes |
|---|---|---|
| 1xx | informational | 100 Continue, 101 Switching Protocols |
| 2xx | success | 200 OK, 201 Created, 204 No Content |
| 3xx | redirection | 301 Moved Permanently, 302 Found, 304 Not Modified |
| 4xx | client error | 400 Bad Request, 401 Unauthorized, 403 Forbidden, 404 Not Found |
| 5xx | server error | 500 Internal Server Error, 502 Bad Gateway, 503 Service Unavailable |
HTTP is stateless: the server keeps no memory of earlier requests, so each request
carries everything needed to answer it. That keeps servers simple and easy to multiply. When a
site needs memory (a login, a cart), it uses cookies: one response carries
Set-Cookie: session=8f2a, the browser stores it and sends
Cookie: session=8f2a with every later request to that site, and the server
looks the number up in its own database. It works like a canteen token: the cashier forgets
the student, but the token number ties the student to the order.
Non-persistent and persistent connections. With non-persistent HTTP (the
HTTP/1.0 default) every object gets its own TCP connection, so each costs two round-trip times
(RTT), one for the handshake and one for the request and response, plus the time to transmit
the object. With persistent HTTP (the HTTP/1.1 default, Connection:
keep-alive) the server leaves the connection open, and each later object costs one RTT,
or less when the requests are sent back to back (pipelined).
A page is one HTML file and 10 small images; the RTT is 50 ms and transmission times are small enough to ignore.
- Non-persistent, one object at a time: 11 objects × 2 RTT = 22 RTT = 1,100 ms.
- Persistent, one request at a time: 2 RTT for the handshake and the HTML, then 1 RTT for each image: 12 RTT = 600 ms.
- Persistent with pipelining: the handshake, the HTML, then all ten image requests sent together: 3 RTT = 150 ms.
| Version | Year | What it brought |
|---|---|---|
| HTTP/1.0 | 1996, RFC 1945 | one object per connection by default |
| HTTP/1.1 | 1997, now RFC 9112 | persistent connections, pipelining, the Host header (many sites on one IP address), chunked transfer |
| HTTP/2 | 2015, now RFC 9113 | binary frames, many requests multiplexed over one connection, compressed headers |
| HTTP/3 | 2022, RFC 9114 | HTTP over QUIC, which runs on UDP with TLS 1.3 built in: a faster start, and one lost packet no longer stalls every stream |
HTTPS is HTTP inside TLS. The browser opens TCP to port 443 and runs the TLS handshake (SSL and TLS): the server presents its certificate, signed by a certificate authority the browser trusts, and the two agree on session keys. From then on every HTTP message travels encrypted and integrity-checked. It gives three things:
- Server authentication: the certificate proves that this really is the bank's site, which defeats a fake copy on a hostile Wi-Fi network (a man-in-the-middle attack).
- Confidentiality: encryption hides passwords, card numbers and the pages themselves from everyone on the path.
- Integrity: a message altered on the way fails its check and is thrown away.
What HTTPS does not hide: the server's IP address, usually the site's name (sent in the TLS handshake), and the size and timing of the traffic. Browsers now label plain HTTP pages "Not secure", and search engines give HTTPS sites a small ranking boost.
| Point | HTTP | HTTPS |
|---|---|---|
| Full name | HyperText Transfer Protocol | HTTP Secure: HTTP over TLS (formerly SSL) |
| Default port | 80 | 443 |
| URL begins | http:// | https:// |
| Layering | HTTP over TCP | HTTP over TLS over TCP |
| Data on the wire | plain text: anyone on the path can read or change it | encrypted and integrity-checked |
| Server identity | not proved | proved by a certificate from a certificate authority |
| Setup cost | TCP handshake only | TCP handshake plus the TLS handshake (one round trip in TLS 1.3) |
| Used for | now rare: redirects to HTTPS, local test servers | logins, payments (a wallet such as eSewa), and every modern site |
The web server is the program on the server side; Apache httpd, Nginx and Microsoft
IIS are the common ones. It listens on ports 80 and 443 and, for each request, parses it,
checks access, maps the URL path to a file under its document root (for
GET /index.html, the file /var/www/html/index.html) or hands it to a
program that builds the page (PHP, Python, Node.js), then sends the response with the right
status code and headers, and writes a line to its access log. It serves many clients at once,
with a process or thread per connection (Apache's classic model) or an event loop that juggles
thousands of connections in one process (Nginx). One server can host many sites on one IP
address (virtual hosting): it reads the Host: header to decide which site
a request is for.
Web server communication, layer by layer: DNS (UDP 53) turns the name into an address, TCP gives a reliable connection to port 80 or 443, TLS secures it for HTTPS, HTTP carries the request and the response, and IP routes every packet between the two hosts.
To remember it: plain HTTP is a postcard. Every post office it passes through (the canteen Wi-Fi, the ISP's routers) can read it, and could even rewrite it. HTTPS is a sealed envelope with a verified stamp: the post offices still see the address on the outside (the server's IP and name), but nobody can read or change the letter inside.
- What is a proxy server? Why is it used? Discuss briefly on HTTP and HTTPS services. 2081 Baishakh Q7 · 4+4
- Why we need proxy servers? What are the importance of DNS and HTTP(S) while you are browsing any website? 2075 Chaitra Q7 · 2+6
- Define socket programming. How web server communication and file server communication are possible in network. Explain with used protocols. 2075 Ashwin Q7 · 6+2
- How web server communication and file server communication are possible in network, explain with used protocols. Define socket programming. 2073 Shrawan Q6 · 6+2
- Write short notes on: i) HDLC ii) Web Server 2073 Shrawan Q10 · 4×2
- What is HTTP protocol? With an example explain how a request initiated by a HTTP client is served by a HTTP server. 2069 Chaitra Q7 · 2+6
6.2File transfer
FTP and TFTP: copying files across the network PIN 4/27
80 Bh · 76 Ash · 75 Ash · 73 Shr6+22+64+4
Why two connections. FTP sends its control information out of band: commands
never mix with file bytes, so the client can send ABOR to stop a transfer midway,
and the control channel stays a simple exchange of text lines (one command, one reply) while
the data channel copes with any kind of file. HTTP, by contrast, sends its headers and its data
on one connection (in band).
The model. Each side has a control process (the protocol interpreter, which speaks the commands) and a data transfer process (which moves the bytes between its file system and the data connection); the client adds the user interface. The control processes talk over the control connection, the data transfer processes over the data connection.
How a client connects to an FTP server, step by step:
- Control connection: the client opens TCP to the server's port 21; the server
greets with
220 Service ready. - Login:
USER anujdraws331 Password required;PASSwith the password draws230 User logged in(or530if it is wrong). Public archives accept the user name anonymous. - Settings:
TYPE Ifor binary (image) transfer,TYPE Afor text; the server replies200. - Data connection: in active mode the client sends
PORT 192,168,1,10,195,80, its address and a port (195 × 256 + 80 = 50000), and the server connects from its port 20 to that port. In passive mode the client sendsPASV, the server answers227 Entering Passive Modewith a high port of its own, and the client connects to it. - Transfer:
RETR notes.pdfdownloads,STORuploads,LISTlists a directory; the server replies150, the bytes flow on the data connection, the data connection closes, and226 Transfer completearrives on the control connection. - Repeat, then quit: steps 4 and 5 repeat for every file, each with a new data
connection;
QUITdraws221 Goodbyeand the control connection closes.
| Point | Active mode (PORT) | Passive mode (PASV) |
|---|---|---|
| Who opens the data connection | the server, from its port 20 | the client |
| To which port | the client's port named in PORT | the server's high port named in the 227 reply |
| Through NAT and firewalls | often blocked: the client's side refuses incoming connections | passes: both connections go outward from the client |
| Today | rare | the default in most clients (FileZilla, WinSCP) |
| Command | Meaning | Typical reply |
|---|---|---|
USER, PASS | log in | 331, then 230 (530 on failure) |
CWD, PWD | change, print the working directory | 250, 257 |
LIST | directory listing, sent on a data connection | 150, then 226 |
RETR, STOR | download, upload a file | 150, then 226 |
TYPE A, TYPE I | ASCII text or binary image | 200 |
PORT, PASV | active or passive data connection | 200, 227 |
QUIT | end the session | 221 |
Reply codes follow one pattern: the first digit 1 means "started, wait for more", 2 done, 3 "send the next part" (as after USER), 4 a temporary failure (try again), 5 a permanent failure. Data types are ASCII, EBCDIC and image (binary); transmission modes are stream (the default), block and compressed. A photo sent in ASCII mode is damaged by line-ending conversion, so anything that is not plain text goes in binary.
FTP is stateful: the server remembers the logged-in user, the current directory and the transfer type for the whole session, unlike stateless HTTP. And it is not secure: the password crosses the network in plain text, readable by anyone running Wireshark on the same network. FTPS (FTP over TLS) or SFTP (SSH file transfer) replace it wherever security matters.
To remember it: a shop counter. The control connection is the counter, where the customer and the shopkeeper talk for the whole visit. For each parcel the shopkeeper opens the back door (a data connection), hands it over and shuts it. In active mode the shopkeeper carries the parcel to the address the customer gave, and finds the gate locked if there is NAT; in passive mode he names a door and the customer collects the parcel there.
TFTP (Trivial File Transfer Protocol, RFC 1350) is FTP cut to the bone: it runs over UDP port 69, with no login, no directory listing and no commands beyond read and write.
- Five packet types: RRQ (read request, opcode 1), WRQ (write request, 2), DATA (3), ACK (4) and ERROR (5).
- Lock-step blocks: data travels in numbered 512-byte blocks, and each block must be acknowledged before the next is sent (stop and wait, ARQ); a lost block or ACK is resent after a timeout. A block shorter than 512 bytes marks the end: a 2,000-byte file goes as three blocks of 512 and one of 464, and a file of exactly 1,024 bytes needs a final empty block.
- Ports: the request goes to port 69; the server answers from a fresh port of its own, which carries the rest of the transfer.
- Uses: booting diskless machines over the network (PXE), loading firmware and
configuration files onto routers, switches and IP phones (a router's
copy tftpcommand). Its code is small enough to fit in a boot ROM.
| Point | FTP | TFTP |
|---|---|---|
| Transport | TCP | UDP |
| Ports | 21 control, 20 data | 69, then a fresh port |
| Login | user name and password | none |
| Commands | dozens: list, rename, delete, change directory | read or write a file, nothing else |
| Reliability | TCP's | its own: every 512-byte block acknowledged |
| Typical use | general file transfer | booting, router and switch images |
File server communication on the Internet uses FTP (or its secure cousins); inside a LAN, file servers more often speak SMB (Windows file sharing, TCP 445) or NFS (Unix, port 2049), which let a client mount a remote folder and open its files as if they were local.
- How does an FTP client connect to an FTP server? Compare POP3 and IMAP protocols. 2080 Bhadra Q7 · 4+4
- What is TFTP? Explain working principle of FTP with data transfer process including proper port connection. Use proper diagram to justify your answer. 2076 Ashwin Q7 · 2+6
- Define socket programming. How web server communication and file server communication are possible in network. Explain with used protocols. 2075 Ashwin Q7 · 6+2
- How web server communication and file server communication are possible in network, explain with used protocols. Define socket programming. 2073 Shrawan Q6 · 6+2
Remote login and secure transfer: Telnet, SSH, PuTTY and WinSCP
Telnet came first (RFC 854, TCP port 23): it gives a remote terminal, but sends everything, the password included, in plain text. SSH replaced it. SSH-1 appeared in 1995 and SSH-2, the version in use, was standardised in 2006 (RFC 4251 to 4254). It has three layers:
- Transport layer: the server proves its identity with its host key, the two sides agree on session keys, and everything after is encrypted and integrity-checked. On the first connection the client shows the host key's fingerprint and asks whether to trust it.
- User authentication: by password, or better by a key pair: the public key sits in
the server's
~/.ssh/authorized_keysand the private key never leaves the laptop. - Connection layer: many channels in one connection: a shell, a file transfer, forwarded ports.
| Tool or protocol | What it does | Port | Encrypted |
|---|---|---|---|
| Telnet | remote terminal | 23 | no |
| SSH | remote terminal and commands | 22 | yes |
| SCP | copy files over SSH, nothing more | 22 | yes |
| SFTP | SSH File Transfer Protocol: list, rename, delete, resume, over SSH | 22 | yes |
| FTPS | classic FTP wrapped in TLS (not the same as SFTP) | 21 (990 implicit) | yes |
PuTTY is a free, open-source terminal emulator for Windows, written by Simon Tatham,
that acts as a client for SSH, Telnet, rlogin, raw TCP and serial connections. With it a
student logs in to a Linux server, or configures a router through its console cable. Its
companions: PuTTYgen makes key pairs (saved as .ppk files),
Pageant holds keys in memory, and pscp and psftp copy files from the
command line.
WinSCP is a free, open-source Windows client for SFTP, SCP and FTP (including FTPS) with a two-panel graphical interface: the laptop's folders on one side, the server's on the other, and files dragged between them. Its SSH code comes from PuTTY and its FTP code from FileZilla.
To remember it: a final-year team deploying its project to the college's Linux server uses PuTTY to log in and run commands, and WinSCP to drag the build folder across. Both use port 22, so nothing they type is readable on the hostel Wi-Fi, while the same work over Telnet and FTP would hand the password to anyone listening.
6.3Electronic mail
Electronic mail: user agents, mail servers, SMTP, POP3, IMAP and MIME TOP 11/27
81 Bh · 80 Bh · 76 Ch · 74 Ch · 74 Ash · 72 Ch · 72 Ka · 71 Shr · 70 Ch · 68 Ba · 67 Asa2+63+54+4
Asynchronous means the two people need not be online together. Sita sends at night
from Pokhara, the mail waits on Ram's mail server, and Ram reads it the next morning in
Kathmandu. The addresses in this card are written defanged, as ram@example[.]org:
the user's mailbox name, then the mail domain.
| Component | What it is | Examples |
|---|---|---|
| User agent (UA) | the program a person uses to compose, read, reply to, forward and file mail | Outlook, Thunderbird, the Gmail app, a browser for webmail |
| Mail server | the host that keeps a mailbox per user and a queue of outgoing mail, and runs the agents below | a college's or a company's mail server; Gmail's servers |
| Message transfer agent (MTA) | the SMTP software that moves mail from server to server | Postfix, Sendmail, Exim, Microsoft Exchange |
| Message delivery agent (MDA) | puts each arriving message into the right mailbox, often after a spam filter | procmail, Dovecot's delivery agent |
| Message access agent (MAA) | the POP3 or IMAP server that the reader's agent pulls mail from | Dovecot, Courier |
| Mailbox and queue | where received mail waits for its reader; where outgoing mail waits for delivery | one mailbox per user |
An email server, then, is a host running these programs. It accepts mail for its own domain (the domain's DNS MX record tells other servers where to send it), stores it in mailboxes, lets its users fetch it, and relays their outgoing mail to other servers.
How one mail travels, step by step:
- Compose: Sita writes to
ram@example[.]orgin her user agent and presses Send. - Submit: her agent hands the mail to her own mail server with SMTP (port 587, after she logs in), where it waits in the outgoing queue.
- Find the receiver's server: her server asks DNS for the MX record of
example.org. - Transfer: it opens a TCP connection to that server's port 25 and pushes the message with SMTP. If the receiving server is down, the message stays in the queue and is retried, typically for several days, before a failure notice (a bounce) comes back.
- Deliver: the receiving server's delivery agent places it in Ram's mailbox.
- Read: when Ram opens his agent, it pulls the message from the mailbox with POP3 or IMAP; with webmail he reads it in a browser over HTTPS instead.
Push, then pull. SMTP is a push protocol: the side that holds the mail opens the connection and sends it. It cannot fetch mail out of a mailbox, and the reader's computer is not always on, so the last hop needs a pull protocol that the reader starts when it suits him: POP3 or IMAP. This is why mail is delivered to a server that is always on, and not straight to Ram's laptop.
SMTP (Simple Mail Transfer Protocol, RFC 821 of 1982, now RFC 5321) is a text protocol: the client sends commands as lines of ASCII and the server answers each with a three-digit code and a phrase. Every mail server runs both sides: it is an SMTP client when it sends and an SMTP server when it receives. A session has three phases:
- Connection setup: TCP to port 25; the server greets with
220; the client names itself withHELO(orEHLO, which also asks which extensions the server supports);250. - Mail transfer:
MAIL FROM:the sender's address (250);RCPT TO:each recipient's address, once per recipient (250, or550if no such mailbox exists);DATA(354); then the message itself, header lines, a blank line and the body, ended by a line holding only a full stop;250. - Termination:
QUIT;221; the TCP connection closes. Several messages may go in one session before QUIT.
S: 220 mail.example.org ESMTP ready C: HELO mail.example.com S: 250 mail.example.org C: MAIL FROM:<sita@example[.]com> S: 250 OK C: RCPT TO:<ram@example[.]org> S: 250 OK C: DATA S: 354 End data with <CR><LF>.<CR><LF> C: From: Sita <sita@example[.]com> C: To: Ram <ram@example[.]org> C: Subject: Lab report C: C: Ram, the lab report is attached. C: . S: 250 OK: queued C: QUIT S: 221 Bye
| Command | Meaning | Usual reply |
|---|---|---|
HELO, EHLO | the client names itself (after the server's 220 greeting) | 250 |
MAIL FROM: | the sender, where a bounce would go | 250 OK |
RCPT TO: | one recipient; repeated for each | 250 OK, or 550 no such mailbox |
DATA | the message follows | 354 start input; 250 after the final "." |
QUIT | end the session | 221 closing |
RSET, VRFY, NOOP | abort this mail; check a user; do nothing | 250 |
The reply codes follow FTP's pattern: 2xx done, 3xx "send the rest", 4xx a temporary failure to retry later (421 service not available, 450 mailbox busy), 5xx a permanent failure (550 no such mailbox).
SMTP's rules and limits. Commands, headers and body are 7-bit ASCII (byte
values 0 to 127); a line may hold at most 1,000 characters with its CR LF; a body line that
starts with a full stop gets a second one added by the sender and removed by the receiver, so
it is never taken for the end. MAIL FROM and RCPT TO are the
envelope, read by the servers; the From: and To: lines inside
DATA are the letter's own header, which the reader sees. SMTP checks no sender by itself, which
is how spam and forged senders spread; today domains publish SPF, DKIM and DMARC records in DNS
so receivers can check a sender, STARTTLS encrypts each server-to-server hop, and only PGP or
S/MIME protects a message end to end (PGP).
POP3 (Post Office Protocol version 3, RFC 1939, TCP port 110, 995 with TLS) is the
simple way to read mail: the agent logs in, downloads the messages and usually deletes them
from the server. A session passes through three states: authorization (USER,
PASS), transaction (STAT, LIST,
RETR, DELE) and update (after QUIT, the server
really deletes what was marked). It runs in download-and-delete mode, for a single
computer, or download-and-keep mode, which leaves copies on the server.
S: +OK POP3 server ready C: USER ram S: +OK C: PASS ******** S: +OK 2 messages (6800 octets) C: LIST S: 1 1200 S: 2 5600 S: . C: RETR 1 S: +OK 1200 octets ... (the whole message) ... . C: DELE 1 S: +OK message 1 deleted C: QUIT S: +OK bye
IMAP (Internet Message Access Protocol, IMAP4rev1 RFC 3501, now IMAP4rev2 RFC 9051; TCP port 143, 993 with TLS) keeps the mail on the server. The user's folders live there, and the server remembers each message's state (read, answered, flagged, deleted) across sessions, so a phone, a laptop and a lab computer all see the same mailbox. An IMAP agent can fetch only the headers, or one part of a message (the text without the 10 MB attachment), and can ask the server to search. Each command carries a tag that its reply repeats:
C: a1 LOGIN ram ******** S: a1 OK LOGIN completed C: a2 SELECT INBOX S: * 2 EXISTS S: a2 OK [READ-WRITE] SELECT completed C: a3 FETCH 1 (BODY.PEEK[HEADER.FIELDS (FROM SUBJECT)]) S: * 1 FETCH (... From: Sita ... Subject: Lab report ...) S: a3 OK FETCH completed C: a4 LOGOUT
| Point | POP3 | IMAP |
|---|---|---|
| Where mail lives | downloaded to one computer, usually deleted from the server | stays on the server until the user deletes it |
| Folders | only the INBOX on the server; folders are local | folders created, renamed and deleted on the server |
| Several devices | mail scatters across devices | every device sees the same mailbox |
| State kept | none between sessions | read, answered, flagged across sessions |
| Partial download | whole messages | headers only, or one part of a message |
| Search | on the local copy only | on the server, before downloading |
| Offline reading | easy: everything is local | needs a local cache |
| Server storage | small: mail leaves the server | large: every message stays |
| Complexity | simple | more complex, for client and server |
| Port | 110 (995 with TLS) | 143 (993 with TLS) |
MIME: pictures through a 7-bit pipe. SMTP was built for 7-bit ASCII text: a photo, a PDF or a Nepali sentence contains bytes from 128 to 255, and long runs without line breaks, which SMTP may damage or refuse. MIME (Multipurpose Internet Mail Extensions, RFC 2045 to 2049) solves it without changing SMTP: it adds header lines that describe each part of the message, and it encodes any bytes as 7-bit text, which the receiver's agent decodes back.
| MIME header | What it says | Example |
|---|---|---|
MIME-Version | this message uses MIME | 1.0 |
Content-Type | the media type of the body or part | text/plain, text/html, image/jpeg, application/pdf, multipart/mixed |
Content-Transfer-Encoding | how the bytes were made 7-bit safe | 7bit, quoted-printable, base64 |
Content-Disposition | shown inline or saved as an attachment | attachment; filename="phewa.jpg" |
Content-ID, Content-Description | a label to refer to the part; a short description | an image shown inside an HTML mail |
Base64, the encoding for images and other binary files, takes the data 3 bytes (24
bits) at a time, cuts the 24 bits into four groups of 6, and writes each group as one of 64
printable characters: A to Z for 0 to 25, a to
z for 26 to 51, 0 to 9 for 52 to 61, + for
62 and / for 63, with = padding the end when the data is not a
multiple of 3 bytes. Lines are broken every 76 characters. Three bytes become four characters,
so the size grows by a third: a 3 MB phone photo travels as about 4 MB of text.
- Text, "Ram": bytes
52 61 6D(hex) =01010010 01100001 01101101; regrouped as010100 100110 000101 101101= 20, 38, 5, 45 =U,m,F,t, so "Ram" travels asUmFt. - An image: every JPEG file begins with the bytes
FF D8 FF, all above 127 and so illegal in 7-bit mail:11111111 11011000 11111111regroups as 63, 61, 35, 63 =/9j/. That is why every base64-encoded JPEG starts with/9j/.
Quoted-printable suits text that is mostly ASCII: plain characters pass unchanged and
each other byte becomes = and two hex digits. The Nepali letter न is
E0 A4 A8 in UTF-8, so it travels as =E0=A4=A8. A Nepali subject line
is encoded inside the header itself, as an encoded word: the subject नमस्ते becomes
=?UTF-8?B?4KSo4KSu4KS44KWN4KSk4KWH?=.
A mail with a photo attached is a multipart/mixed message: a boundary
string, chosen so it never occurs in the data, separates the parts.
From: Sita <sita@example[.]com> To: Ram <ram@example[.]org> Subject: Photo from Phewa Lake MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="XyZ42" --XyZ42 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit Here is the photo from the boat. --XyZ42 Content-Type: image/jpeg; name="phewa.jpg" Content-Transfer-Encoding: base64 Content-Disposition: attachment; filename="phewa.jpg" /9j/4AAQSkZJRgAB ... (about 4 MB of base64 text) ... --XyZ42--
To remember the whole system: the postal service. The user agent is the person writing the letter; her mail server is the local post office; SMTP is the mail van that runs between post offices (and only ever delivers, never collects); the mailbox is Ram's PO box at his post office. POP3 is Ram emptying the PO box and carrying everything home; IMAP is Ram reading at the post office counter, where the letters stay in his own labelled folders.
- What do you mean by DNS delegation? List the step-by-step working principle of SMTP. 2081 Bhadra Q7 · 2+6
- How does an FTP client connect to an FTP server? Compare POP3 and IMAP protocols. 2080 Bhadra Q7 · 4+4
- What is DNS? Explain the working principle of DNS with a proper diagram. Compare IMAP and POP3 protocols. 2076 Chaitra Q7 · 1+4+3
- Which protocols are used in sending and receiving an email? Illustrate with necessary figure. Give a comparison of POP3 and IMAP. 2074 Chaitra Q7 · 5+3
- Write short notes on: (Any two) a) SMTP and POP b) Diffie Hellman’s Algorithm c) CSMA/CD d) DLL Flow Control Mechanisms 2074 Ashwin Q10 · 4+4
- Write short notes on: a) Simple Mail Transfer Protocol b) Doman Name Server 2072 Chaitra Q10 · 4×2
- What are the different components of email server? Explain different types of electronic mail sending and accessing protocol. 2072 Kartik Q7 · 2+6
- SMTP is a text based protocol and uses 7 bit ascii. How can this be used to transmit sometimes like images? Explain. 2071 Shrawan Q7 · 8
- What do you mean by email server? What are the protocols used on it? 2070 Chaitra Q7 · 2+6
- What is the function of proxy server? Explain about electronic mail. 2068 Baishakh Q8 · 3+5
- How the protocol SMTP does operate? Explain the procedures to make your network secured. 2067 Ashad Q10 · 3+5
6.4DNS, and DHCP beside it
DNS: the Internet's distributed directory of names TOP 11/27
82 Bh · 82 Ba · 81 Bh · 80 Ba · 79 Bh · 78 Bh · 76 Ch · 75 Ch · 74 Ash · 72 Ch · 71 Ch2+61+4+32+2+4
www.ioe.edu.np to the IP address that routing needs (and back), and it
answers mostly over UDP port 53.
Why it is used:
- Names for people, numbers for machines: people remember
youtube.com; routers forward on 32-bit or 128-bit addresses (IPv4 addressing). - Freedom to move: a site can change its server and its address, and only the DNS record changes; every bookmark and link keeps working.
- One name, many servers: a busy name can map to several addresses, spreading the load, and a content network can hand each user the address of its nearest copy.
- More than addresses: DNS also says which server takes a domain's mail (MX), what a name is an alias of (CNAME), and which name an address belongs to (PTR).
- Distributed, because one table cannot scale: before DNS (designed in 1983) every host copied a single file, HOSTS.TXT, from one computer at the SRI Network Information Center. With millions of names one table would be a single point of failure, a traffic jam and impossible to keep current, so DNS splits the database among countless servers, each run by whoever owns that part of the name space.
To remember it: DNS is the phone's contact list for the whole Internet. Nobody dials Aama's number from memory; the phone looks it up from the name. When she changes her SIM, only the entry changes, and "Aama" still works.
The domain name space is an inverted tree. Each node has a label of up to 63
characters; the root's label is empty. A node's domain name is its labels read upward to
the root and joined by dots, www.youtube.com., the final dot standing for the
root. A name ending in that dot is a fully qualified domain name (FQDN); one without it,
such as a bare www typed inside a campus network, is partially qualified
(PQDN), and the resolver completes it with a default suffix. A full name may be at most 255
bytes long.
- The root: one, unnamed, served by 13 named root server identities
(
a.root-servers.nettom.root-servers.net) run by 12 organizations, each copied to many sites around the world by anycast. - Top-level domains (TLDs): generic ones (com, org, net, edu, gov, info and many newer ones), country codes (np for Nepal, in, uk, jp), and arpa for reverse lookups. Verisign runs com and net; the np domain is run by Mercantile Communications.
- Second level and below: under np sit second-level zones such as com.np, edu.np,
gov.np and org.np; under edu.np sit names such as
ioe.edu.npandpcampus.edu.np. Each owner then creates whatever names it likes below its own.
| Name server | What it holds or does | Example |
|---|---|---|
| Root | knows the servers of every TLD; answers with referrals | a to m.root-servers.net |
| TLD | knows the authoritative servers of every domain under its TLD | a.gtld-servers.net for com |
| Authoritative | holds a zone's actual records, from its zone file; a primary server and secondaries that copy the zone by zone transfer | ns1.google.com for youtube.com |
| Local (the resolver) | outside the tree: the server a host is told to ask (by DHCP), which resolves names on the host's behalf and caches the answers | an ISP's resolver (NTC, WorldLink), or a public one such as 8.8.8.8 or 1.1.1.1 |
Caching keeps DNS fast. Every answer carries a time to live (TTL, in seconds), and a resolver keeps it that long. Once the first student in a hostel looks up youtube.com, the next hundred get the answer from the ISP's resolver without touching the root, the TLD or Google. Resolvers also cache the TLD servers' addresses, so the root is rarely asked at all, and they remember failed lookups for a while too (negative caching).
Two ways to resolve a name. In a recursive query the server asked takes the whole job: it must return the answer, or an error, asking other servers itself as needed. In an iterative query the server asked replies at once with the best it has: the answer if it knows it, otherwise a referral, the names and addresses of servers closer to the answer, and the asker goes on to ask those itself. The asker states its wish in the RD (recursion desired) flag.
- Host to local server: the browser's resolver library sends a query for
www.youtube.com, type A, with RD set, to the ISP's resolver, which has nothing cached. - Local server to root: it asks a root server.
- Root's referral: "ask com": the NS records of com
(
a.gtld-servers.netand its siblings) in the authority section, their addresses (glue) in the additional section. - Local server to TLD: it asks a com server.
- TLD's referral: "ask youtube.com's servers":
ns1.google.comand its siblings, with their addresses. - Local server to authoritative: it asks
ns1.google.com. - The answer: the authoritative server replies with the A record, AA set. (If the name is an alias, the reply is a CNAME, and the resolver looks up the canonical name the same way.)
- Back to the host: the resolver caches every record it saw for its TTL and returns the address; the browser opens its TCP connection.
The host sent one query and got one reply; the local server did the iterating, with three queries.
Fully recursive resolution chains the work instead: the root asks the TLD server, the TLD server asks the authoritative server, and the answer climbs back the same way. It saves the asker work but loads the servers up the tree, which would have to hold state for millions of waiting queries; so root and TLD servers refuse recursion (they answer with RA clear). In practice the two are combined: a host's query to its local server is recursive, and the local server's own queries are iterative.
| Point | Recursive query | Iterative query |
|---|---|---|
| Who does the work | the server asked: it chases the answer | the asker: it follows the referrals |
| Reply | the final answer, or an error | the answer, or a referral to other servers |
| Load | heavy on the server asked, which must wait and keep state | light: every server answers at once |
| Messages for the asker | one query, one reply | one query for each server visited |
| Caching | the server caches what it learned | the asker caches the whole chain |
| Flags | RD set, and RA set in the reply | RD clear, or recursion not offered |
| Typical use | host to its local server | local server to root, TLD and authoritative servers |
A third kind, in older texts, is the inverse query: finding the name for an
address. It is now done as an ordinary query for a PTR record: the address 192.0.2.80 becomes
the name 80.2.0.192.in-addr.arpa (the bytes reversed), looked up like any other
name; the old inverse opcode is obsolete.
Resource records. A zone's data is a set of resource records (RRs), each with five fields: NAME (the owner), TYPE, CLASS (IN, for the Internet), TTL (how many seconds it may be cached) and the record's data (RDATA, whose length goes in RDLENGTH on the wire).
| Type | Code | What its data is | Example, zone example.com |
|---|---|---|---|
| A | 1 | an IPv4 address | www A 192.0.2.80 |
| AAAA | 28 | an IPv6 address (IPv6 addressing) | www AAAA 2001:db8::80 |
| CNAME | 5 | the canonical name an alias stands for | ftp CNAME www.example.com. |
| MX | 15 | a mail server for the domain, with a preference: the lower number is tried first | example.com. MX 10 mail.example.com. |
| NS | 2 | an authoritative name server for the zone | example.com. NS ns1.example.com. |
| PTR | 12 | the name for an address (reverse lookup) | 80.2.0.192.in-addr.arpa. PTR www.example.com. |
| SOA | 6 | start of authority: the zone's primary server, its administrator's mailbox, a serial number and timers | one per zone, at its top |
| TXT | 16 | free text: SPF and DKIM mail checks, site-ownership proofs | example.com. TXT "v=spf1 mx -all" |
A zone file is where an authoritative server keeps its records. A small one, with documentation addresses:
$TTL 3600
example.com. IN SOA ns1.example.com. admin.example.com. (
2026100401 ; serial: raised on every change
7200 ; refresh: secondaries check every 2 hours
900 ; retry
1209600 ; expire: 14 days
300 ) ; TTL for "no such name" answers
example.com. IN NS ns1.example.com.
example.com. IN NS ns2.example.com.
example.com. IN MX 10 mail.example.com.
ns1 IN A 192.0.2.53
www IN A 192.0.2.80
www IN AAAA 2001:db8::80
mail IN A 192.0.2.25
ftp IN CNAME www.example.com.
example.com. IN TXT "v=spf1 mx -all"
Delegation is how DNS becomes distributed. A zone is the part of the tree
that one set of authoritative servers answers for. A parent zone hands (delegates) a subtree to
another set of servers by putting NS records for the child into its own zone, plus
glue A records when the child's name servers are named inside the child itself. From
then on the child's owner adds and changes names without asking the parent. The root delegates
np to the np registry's servers; the np zone delegates edu.np; the edu.np zone delegates
ioe.edu.np to the name servers IOE names, so IOE can add a host the same afternoon with nobody
above it involved. A referral in an iterative lookup is simply the parent reading out its
delegation. Glue is needed when a zone names servers inside itself: pcampus.edu.np is served by
dns1.pcampus.edu.np and dns2.pcampus.edu.np, so the edu.np zone must
also hold their addresses, or no resolver could ever reach them.
; inside the com zone, run by Verisign youtube.com. NS ns1.google.com. ; delegation to Google's servers example.com. NS ns1.example.com. ; delegation ns1.example.com. A 192.0.2.53 ; glue: the server sits inside the child
The DNS message. A query and its response share one format: a 12-byte header, then four sections. The header holds an identification number (the reply copies it, so the asker can match each reply to its query), the flags (QR query or response; Opcode; AA authoritative answer; TC truncated; RD recursion desired; RA recursion available; RCODE the result, 0 no error and 3 no such name) and four counts. The question section carries the name, type and class asked; the answer section the records that answer it; the authority section NS records, as in a referral; the additional section useful extras, such as the glue addresses of those servers.
- Query: ID
0x1A2B(6699), QR 0, Opcode 0, RD 1, QDCOUNT 1, other counts 0; questionwww.example.com, type A, class IN. On the wire the name is a series of labels, each led by its length:3 www 7 example 3 com 0, 17 bytes. Size: 12 + 17 + 4 = 33 bytes, one UDP datagram to port 53. - Response: the same ID, QR 1, RD 1, RA 1, AA 0 when it comes from a resolver's
cache, RCODE 0, QDCOUNT 1, ANCOUNT 1; the question repeated; the answer
www.example.com 3600 IN A 192.0.2.80, whose name is a 2-byte pointer back to the question (name compression). Size: 33 + 16 = 49 bytes.
dig www.example.com A ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 6699 ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0 ;; QUESTION SECTION: ;www.example.com. IN A ;; ANSWER SECTION: www.example.com. 3600 IN A 192.0.2.80
UDP, and sometimes TCP. A query and its reply fit in one datagram each, so UDP's lack of a handshake makes lookups fast, and a lost query is simply asked again. DNS falls back to TCP port 53 for zone transfers between primary and secondary servers, and when a reply is too long for the UDP limit (512 bytes in the original rules; EDNS raises it), in which case the server sets TC and the resolver repeats the query over TCP.
The book's four DNS components are the name space (the tree of names), the name servers (which hold its parts), the resolvers (which ask on behalf of programs) and the cache (answers kept for their TTL). DNS was not built with security: forged replies can poison a cache, and DNSSEC answers this by signing records.
- Compare DNS recursive query vs. iterative query. Explain iterative query for browsing www.youtube.com 2082 Bhadra Q7 · 2+6
- How does a DNS recursive query work? Discuss DHCP lease renew process with example diagram. 2082 Baishakh Q7 · 2+6
- What do you mean by DNS delegation? List the step-by-step working principle of SMTP. 2081 Bhadra Q7 · 2+6
- What is DNS server? Explain the recursive and iterative query. 2080 Baishakh Q7 · 2+6
- What is DNS? Why is it used? How is the DNS request from a client computer resolved from the authoritative server? Explain with necessary diagrams. 2079 Bhadra Q7 · 2+2+4
- What are resource records in DNS? Explain the types of DNS queries with example. 2078 Bhadra Q7 · 3+5
- What is DNS? Explain the working principle of DNS with a proper diagram. Compare IMAP and POP3 protocols. 2076 Chaitra Q7 · 1+4+3
- Why we need proxy servers? What are the importance of DNS and HTTP(S) while you are browsing any website? 2075 Chaitra Q7 · 2+6
- What is recursive and iterative query? Explain with suitable diagram. Discuss the DNS records. 2074 Ashwin Q7 · 6+2
- Write short notes on: a) Simple Mail Transfer Protocol b) Doman Name Server 2072 Chaitra Q10 · 4×2
- What is DNS? Explain the structure of DNS request and response with practical example. 2071 Chaitra Q7 · 2+6
DHCP: how a host gets its address, and how the lease is renewed PIN 1/27
82 Ba2+6
Why it is used: a laptop or phone that joins a new network works at once; a limited pool of addresses is shared, since the addresses of devices that leave return to the pool when their leases run out; settings are changed in one place; and no two hosts are given the same address. A server can also hand out reserved (fixed) addresses, matched to a device's MAC address, for printers and servers. DHCP grew out of the older BOOTP and keeps its message format.
Getting an address: DORA. Four messages, the first and third broadcast because the client has no address yet:
- DHCPDISCOVER: the client broadcasts from
0.0.0.0:68to255.255.255.255:67: is there a DHCP server? - DHCPOFFER: each server that hears it offers an address (say
192.168.1.23), the mask, the gateway, the DNS servers and a lease time. - DHCPREQUEST: the client broadcasts its choice, naming the chosen server, so the other servers take back their offers.
- DHCPACK: the chosen server confirms and the lease begins. The client usually checks with ARP that no one else is using the address (ARP); if someone is, it sends DHCPDECLINE and starts again.
The other messages: DHCPNAK (the server refuses a request), DHCPRELEASE (the client hands its address back), DHCPDECLINE (the address is already in use) and DHCPINFORM (a host with a fixed address asks only for the other settings).
The lease and its renewal. An address is lent, never given. The DHCPACK carries the lease time and two timers, which by default are:
- Bound (0 to T1): the client simply uses the address.
- Renewing (from T1): the client sends a DHCPREQUEST by unicast to the server that granted the lease. A DHCPACK renews the lease (a fresh full lease from now) and restarts both timers; a DHCPNAK makes the client stop using the address and start again with DISCOVER. With no reply, it keeps asking from time to time.
- Rebinding (from T2): the original server seems gone, so the client broadcasts the DHCPREQUEST to any DHCP server; an ACK from any of them renews the lease.
- Expiry: with no ACK by the end of the lease, the client must stop using the address at once and go back to the beginning (INIT, then DISCOVER).
A phone joins at 07:00 and is leased 192.168.1.23 for 24 hours. T1 = 0.5 × 24 = 12 hours, so at 19:00 it unicasts a renewal; normally the router answers at once and the phone holds the address until 19:00 the next day, renewing again at 07:00. If the router were rebooting all evening, the phone would keep trying until T2 = 0.875 × 24 = 21 hours, 04:00, then broadcast to any server; with still no answer by 07:00 it would drop the address and start DORA again. For an 8-day lease the same rules give T1 = 4 days and T2 = 7 days.
The client's states follow from this: INIT (no address), SELECTING (collecting offers), REQUESTING (asking for one), BOUND (using it), RENEWING (after T1) and REBINDING (after T2).
Across routers: the relay agent. Broadcasts stop at a router, so a college with one
DHCP server and twenty department subnets puts a relay agent on each router interface
(on a Cisco router, the ip helper-address command). The relay hears the
broadcast, forwards it by unicast to the server, and writes its own address in the message's
gateway field, so the server picks an address from the right subnet's pool
(IPv4 addressing).
To remember it: a library book. Borrowing it is DORA; halfway through the loan the student asks the same desk to renew it (T1); if that desk stays closed, near the due date he asks any desk in the library (T2); and on the due date, renewed or not, the book goes back.
- How does a DNS recursive query work? Discuss DHCP lease renew process with example diagram. 2082 Baishakh Q7 · 2+6
6.5P2P applications
Peer-to-peer applications: BitTorrent and distributed hash tables
Four designs have been used to find who holds what:
- Central index: one server knows which peer has which file, and files move peer to peer (Napster, 1999). Simple, but the index is a single point of failure.
- Query flooding: each peer passes a search to its neighbours, who pass it on (Gnutella). No centre, but searches flood the network.
- Super peers: well-connected peers keep indexes for their neighbours (KaZaA).
- Structured, with a distributed hash table (DHT): every key has one well-defined home among the peers, found in a few hops (Chord, Kademlia).
Why P2P scales. A server must upload a copy to every client alone; in P2P every peer that has received a part also uploads it, so each newcomer adds capacity as well as demand. For a file of bits sent to hosts, with server upload rate , peer upload rates and the slowest download rate , the shortest distribution times are:
F = 800 Mbit (100 MB), N = 100, server upload 100 Mbit/s, each peer uploads 10 Mbit/s and downloads 50 Mbit/s. Client-server: NF/us = 100 × 800 / 100 = 800 s, larger than F/d = 16 s, so about 800 s. P2P: NF/(us + N u) = 80,000 / (100 + 1,000) = 72.7 s, larger than F/us = 8 s and F/d = 16 s, so about 73 s, eleven times faster, and the gap widens as N grows.
BitTorrent (Bram Cohen, 2001) is the best-known P2P application:
- The torrent: a small
.torrentfile (or a magnet link) gives the file's name, its piece size, a hash of every piece and the tracker's address. - Tracker and swarm: the tracker keeps the list of peers sharing the file, the swarm; a new peer gets a list of some of them and connects to several.
- Seeders and leechers: seeders hold the whole file; leechers are still downloading, and upload the pieces they already have.
- Pieces, rarest first: the file is split into equal pieces; a peer asks first for the pieces fewest of its neighbours have, so rare pieces spread before their owners leave. Every piece is checked against its hash, so a corrupt piece from a bad peer is thrown away.
- Tit for tat: a peer uploads to the four neighbours that upload to it fastest, re-chosen every 10 seconds, plus one random neighbour every 30 seconds (the optimistic unchoke), so newcomers get a start and free riders are slowed.
A distributed hash table stores (key, value) pairs across the peers with no central index. Peers and keys get IDs from the same space, for example 160 bits; a key is stored at the peer whose ID is closest to it, and each peer knows a few peers at every distance, so a lookup halves the remaining distance at each hop and finds any key among N peers in about log2 N hops: about 20 hops for a million peers. BitTorrent's trackerless mode uses a Kademlia DHT, where the key is the torrent's info-hash and the value the list of peers.
Good and bad: P2P has no single point of failure and grows with its users, but it uses a lot of upload bandwidth, works badly behind NAT, is hard to control, is notorious for pirated content, and a file from an unknown peer may carry malware. Other P2P systems include early Skype, Bitcoin's network and peer-to-peer video calls in the browser (WebRTC).
To remember it: the night before an exam, a class shares notes. Instead of everyone queueing at the one photocopy shop by the gate (the server), each student copies one chapter and swaps; the more students join, the faster everyone has the whole set.
6.6Socket programming
Socket programming: the calls, and a TCP server and client HOT 5/27
82 Ba · 81 Bh · 75 Ash · 74 Ch · 73 Shr2×46+24+4
The Berkeley (BSD) socket API, from 4.2BSD Unix in 1983, is the model that Linux, Windows (Winsock), Java and Python all copy. It treats a network connection much like a file: open it, read and write it, close it.
| Socket type | Transport | What it gives | Used by |
|---|---|---|---|
Stream (SOCK_STREAM) | TCP | a reliable, ordered byte stream over a connection | HTTP, FTP, SSH, SMTP |
Datagram (SOCK_DGRAM) | UDP | separate messages, no connection, no delivery guarantee | DNS, DHCP, TFTP, SNMP |
Raw (SOCK_RAW) | none: IP itself | direct access to IP and ICMP packets; needs administrator rights | ping, traceroute |
| Call | Who | What it does |
|---|---|---|
socket() | both | create an endpoint: family (IPv4), type (stream or datagram); returns a descriptor |
bind() | server | attach a local IP address and port to the socket |
listen() | server | make the socket passive, ready to accept connections, with a queue length for waiting clients |
accept() | server | block until a client connects, then return a new socket for that client |
connect() | client | open a connection to the server's address and port: TCP's three-way handshake happens here |
send(), recv() | both | write and read data on a connected socket (sendto() and recvfrom() for UDP) |
close() | both | release the connection: TCP sends its FIN |
The order of the calls is what the exam tests. The server prepares a socket and
waits: socket, bind, listen, then accept,
which blocks. The client needs no bind (its operating system picks a temporary port):
socket, then connect. When connect's handshake completes, accept
returns, and the two exchange data and close.
A TCP server in C, which greets one client at a time:
/* server.c: a TCP server on port 5000 (BSD sockets, Linux) */
#include <stdio.h>
#include <string.h>
#include <unistd.h>
#include <sys/socket.h>
#include <arpa/inet.h>
int main(void) {
int lfd = socket(AF_INET, SOCK_STREAM, 0); /* 1. a TCP socket */
struct sockaddr_in me;
memset(&me, 0, sizeof me);
me.sin_family = AF_INET;
me.sin_port = htons(5000); /* port, network byte order */
me.sin_addr.s_addr = htonl(INADDR_ANY); /* every local address */
bind(lfd, (struct sockaddr *)&me, sizeof me); /* 2. name it: IP + port */
listen(lfd, 5); /* 3. passive, queue of 5 */
for (;;) {
int cfd = accept(lfd, NULL, NULL); /* 4. wait for a client */
char buf[100];
int n = recv(cfd, buf, sizeof buf - 1, 0); /* 5. read its request */
if (n > 0) {
buf[n] = '\0';
printf("client says: %s\n", buf);
send(cfd, "Namaste from server\n", 20, 0); /* 6. reply */
}
close(cfd); /* 7. end this client only */
}
}
A TCP client in C, which sends one line and prints the reply:
/* client.c: talks to the server above */
#include <stdio.h>
#include <string.h>
#include <unistd.h>
#include <sys/socket.h>
#include <arpa/inet.h>
int main(void) {
int fd = socket(AF_INET, SOCK_STREAM, 0); /* 1. a TCP socket */
struct sockaddr_in srv;
memset(&srv, 0, sizeof srv);
srv.sin_family = AF_INET;
srv.sin_port = htons(5000); /* the server's port */
inet_pton(AF_INET, "192.168.1.10", &srv.sin_addr); /* the server's IP */
if (connect(fd, (struct sockaddr *)&srv, sizeof srv) < 0) { /* 2. handshake */
perror("connect"); /* no server listening: refused */
return 1;
}
send(fd, "Hello", 5, 0); /* 3. the request */
char buf[100];
int n = recv(fd, buf, sizeof buf - 1, 0); /* 4. the reply */
if (n > 0) { buf[n] = '\0'; printf("%s", buf); }
close(fd); /* 5. FIN */
return 0;
}
Reading the code. htons and htonl turn the port and the
address into network byte order (big-endian), whatever the machine's own order;
INADDR_ANY lets the server accept on every interface it has; the listening socket
lfd never carries data: each accepted client gets its own socket
cfd. Real programs check every return value; a busy server handles each client in
its own process (fork) or thread so that one slow client does not block the rest.
Compile with gcc server.c -o server, run ./server, then the client in
a second terminal.
Why the server must run first. connect() sends a SYN to the server's
address and port. If no socket there is in the listening state, the server's TCP answers with
RST and connect() fails with "connection refused" (ECONNREFUSED);
there is nothing for the client to wait on. So the server is started first, binds its
well-known port and sits in accept(), and clients come and go.
UDP is simpler: no listen, no accept, no connect. The server binds and loops on
recvfrom(), which also returns the sender's address, and answers with
sendto() to that address; every datagram stands alone.
Other languages, the same calls: in Java, new ServerSocket(5000) does
socket, bind and listen at once, accept() returns a Socket, and the
client's new Socket("192.168.1.10", 5000) connects (the book's Java version); in
Python the calls keep their C names: s.bind(), s.listen(),
s.accept().
SOCK_RAW.To remember it: a hostel's landline. bind is getting a number from
the telephone office, listen is switching the ringer on, accept is
picking up when it rings, and connect is a friend dialling the number. Dial a
number whose phone is not yet connected and the exchange answers "the number does not
exist": that is connection refused, and why the server runs first.
- Write Short Notes on: (Any Two) a) 802.5 Token Ring b) PGP c) Socket programming fundamentals d) X.25 Network 2082 Baishakh Q10 · 2×4
- Write Short notes on: (Any Two) a) 802.4 Token Bus b) Framing with bit stuffing c) Server Socket programming for bind, listen and accept d) ATM 2081 Bhadra Q10 · 2×4
- Define socket programming. How web server communication and file server communication are possible in network. Explain with used protocols. 2075 Ashwin Q7 · 6+2
- Write short notes on: (any two) i) Types of firewals ii) FDDI iii) Socket programming 2074 Chaitra Q10 · 4+4
- How web server communication and file server communication are possible in network, explain with used protocols. Define socket programming. 2073 Shrawan Q6 · 6+2
6.7Application server concepts
Proxy servers and web caching PIN 3/27
81 Ba · 75 Ch · 68 Ba2+63+54+4
How web caching works:
- Every request goes to the proxy: the browsers are set to use it, or the network redirects their traffic to it without their knowing (a transparent proxy).
- The proxy checks its cache for the URL.
- Hit, and still fresh (within its
Cache-Control: max-ageorExpirestime): the proxy returns its copy at once, from the LAN. - Hit, but perhaps stale: it sends the origin a conditional GET, with
If-Modified-Since:the date of its copy; the origin replies304 Not Modifiedwith no body if nothing changed, and the copy is served, or200 OKwith the new version. - Miss: the proxy opens its own TCP connection to the origin server, fetches the object, stores a copy, and forwards it to the client.
Why proxies are used:
- Faster pages: a hit comes from the LAN in milliseconds instead of crossing the Internet.
- Less traffic on the access link: the link to the ISP is the slow, paid-for part; every hit is a request that never crosses it.
- Less load on origin servers, which see one request where a hundred students clicked.
- Filtering and access control: block sites, or allow them only in certain hours, in one place for a whole office or campus.
- Logging and monitoring: one place to see who used what.
- Privacy and security: the origin sees the proxy's address, not the client's; the proxy can scan downloads for malware, and is the single exit that a firewall allows (an application gateway).
- Sharing one connection among many users.
How much a cache saves. With a hit ratio (the share of requests the cache answers), the average response time is:
A campus proxy answers 40 percent of requests (h = 0.4) in 10 ms; a miss takes 2 s over the busy access link. Tavg = 0.4 × 0.01 + 0.6 × 2 = 1.204 s, against 2 s with no cache; and the access link now carries only 60 percent of the requests, which also shortens the misses.
| Kind | Where it sits, whom it serves | Example |
|---|---|---|
| Forward proxy | near the clients, acting for them toward the whole Internet | a campus or office proxy (Squid) |
| Reverse proxy | in front of web servers, acting for the servers toward clients: caching, load balancing, TLS | Nginx in front of an application; a content delivery network |
| Transparent | intercepts traffic with no browser setting, passes the client's IP on in a header, says it is a proxy | an ISP's or a school's interception cache |
| Anonymous | hides the client's IP, but says it is a proxy | a privacy proxy |
| Distorting | sends a false client IP, and says it is a proxy | a privacy proxy |
| High anonymity | hides the client's IP and does not say it is a proxy | an "elite" proxy |
A content delivery network (CDN) is caching at world scale: many reverse-proxy caches placed near users, so a video is served from a nearby copy rather than from one origin on another continent.
To remember it: the hostel's copy of a popular book. The first student who asks waits while it is fetched from the central library (a miss); the next forty borrow the hostel copy at once (hits); and once a week the warden asks the central library whether a new edition has come out (a conditional GET).
- What is a proxy server? Why is it used? Discuss briefly on HTTP and HTTPS services. 2081 Baishakh Q7 · 4+4
- Why we need proxy servers? What are the importance of DNS and HTTP(S) while you are browsing any website? 2075 Chaitra Q7 · 2+6
- What is the function of proxy server? Explain about electronic mail. 2068 Baishakh Q8 · 3+5
Web, mail and DNS server optimization
Each kind of server has its own bottleneck, so each is tuned differently:
| Server | Bottleneck | How it is optimized |
|---|---|---|
| Web | many connections at once; disk reads; slow pages built from a database | caching in memory, in a reverse proxy and in a CDN; compression (gzip, Brotli); persistent connections and HTTP/2; an event-driven server (Nginx) for static files; a load balancer across a farm of servers; caching database results; expiry headers so browsers keep copies |
| queues; the volume of spam; storage | two or more MX records with preferences (a backup server); spam filtering at the edge (blocklists, SPF, DKIM, DMARC checks); separate submission (587) from relay (25); tuned queue and retry times; mailboxes on RAID; quotas; indexes for IMAP search | |
| DNS | query volume; delay; attacks | caching with sensible TTLs; at least two authoritative servers on different networks, kept in step by zone transfer; anycast copies; separate authoritative and recursive servers; rate limits against amplification attacks; resolvers placed close to the users |
Shared by all three: reliable disks (RAID), enough memory, solid-state drives, redundant power (a UPS and a generator, which Nepali server rooms needed through the load-shedding years), two network links, and monitoring (SNMP, MRTG and PRTG).
How the result is measured: throughput (requests per second), response time, and availability, the share of time the service is up. 99.9 percent sounds high but still allows 8.76 hours of downtime a year; 99.99 percent allows 52.6 minutes.
To remember it: a results website on result day, when thousands of students open the same page within minutes. The page is cached, served by several servers behind a load balancer, its name resolved by two DNS servers, and its disks mirrored; take away any one of these and the site falls over at exactly the moment everyone needs it.
RAID 0, RAID 1 and RAID 5: why servers need them PIN 1/27
68 Ch2+6
Why networks need RAID. A server is shared: a web, mail, DNS, file or database server answers hundreds of users at once.
- Availability: hard disks are among the parts most likely to fail; without redundancy one dead disk stops the service for every user and loses the mail and data on it. With RAID 1 or 5 the server keeps running on the remaining disks while the failed one is swapped (often without switching off, hot swap) and rebuilt.
- Performance: striping spreads reads and writes across several disks working in parallel, which suits a server facing many requests at once.
- Capacity: several disks appear as one large volume.
- But RAID is not a backup: a deleted file, a virus or ransomware is deleted or encrypted on every disk at once. Backups are still needed.
RAID 0, striping. Blocks go round-robin across n disks (A1 on disk 1, A2 on disk 2, A3 on disk 1 ...). All the capacity is usable and reads and writes run up to n times faster, but there is no redundancy at all: one failed disk destroys the whole volume, so an array of n disks is less reliable than one disk. It suits scratch space for video editing and other data that is easy to recreate. At least 2 disks.
RAID 1, mirroring. Every block is written to two disks. The usable capacity is one disk's; reads can come from either copy (faster), writes go to both (the speed of one disk); it survives the failure of either disk, and rebuilding is a simple copy. It suits operating system disks and small critical servers (DNS, mail). At least 2 disks.
RAID 5, striping with distributed parity. Data and parity blocks are striped across n disks, at least 3, with the parity block moving to a different disk in each stripe so that no single disk becomes a bottleneck. The parity is the XOR of the data blocks in its stripe, so any one lost block is the XOR of all the others. The usable capacity is n − 1 disks; reads are fast; small writes are slower, since each must read the old data and the old parity and write both anew (four disk operations, the write penalty). It survives any one failed disk; a second failure during the long rebuild of a large disk loses everything, which is why RAID 6 keeps two parity blocks. It suits file and web servers that mostly read.
A stripe holds D1 = 1011, D2 = 0110 and D3 = 1100.
Parity P = D1 XOR D2 XOR D3 = 0001. Disk 2 fails. Its block is rebuilt from the
survivors: D1 XOR D3 XOR P = 1011 XOR 1100 XOR 0001 =
0110, which is D2.
| Point | RAID 0 | RAID 1 | RAID 5 |
|---|---|---|---|
| Technique | striping | mirroring | striping with distributed parity |
| Minimum disks | 2 | 2 | 3 |
| Usable capacity (n disks of size S) | n × S | S (one copy) | (n − 1) × S |
| Example capacity | 2 × 2 TB disks: 4 TB | 2 × 2 TB disks: 2 TB | 4 × 2 TB disks: 6 TB |
| Disks that may fail | none | one (of the pair) | any one |
| Read speed | fastest | fast | fast |
| Write speed | fastest | like one disk | slower (the parity update) |
| Best for | temporary, easily recreated data | system disks, small critical servers | file and web servers, mostly reading |
RAID 10 (a stripe of mirrors) combines the speed of RAID 0 with the safety of RAID 1, at half the raw capacity; RAID can be done by a hardware controller or by the operating system (software RAID), and a hot spare disk lets the rebuild begin the moment a disk fails.
To remember it: three friends and the semester's notes. RAID 0: two of them split the chapters and copy twice as fast, but if one loses his notebook half the course is gone. RAID 1: each writes the whole set, so either can lose his. RAID 5: three split the chapters and also keep a "check sheet", which lets them rebuild whichever one notebook goes missing.
- Why do we need RAID in the computer networks? Define and discuss the differences between RAID 0, RAID 1 and RAID 5. 2068 Chaitra Q2 · 2+6
6.8Traffic analysers and network management
SNMP: managing network devices
- Manager (the network management station): software that polls the agents, stores and graphs the values and raises alerts: MRTG, PRTG, Zabbix.
- Agent: a small process on each managed device that answers the manager and watches the device.
- MIB (Management Information Base): the collection of objects an agent exposes, arranged as a tree. MIB-II (RFC 1213) defines the standard ones every device has.
- SMI (Structure of Management Information): the rules for naming objects, their data types (integer, counter, gauge, string) and how they are encoded.
- OID (object identifier): each object's address in the tree, a string of numbers.
1.3.6.1.2.1.1.3.0is sysUpTime;1.3.6.1.2.1.2.2.1.10is ifInOctets, the count of bytes received on an interface.
| Message | Direction | What it does |
|---|---|---|
| GetRequest | manager to agent (UDP 161) | read one or more variables |
| GetNextRequest | manager to agent | read the next variable in the tree: walking a table |
| GetBulkRequest (v2) | manager to agent | read a large block in one request |
| SetRequest | manager to agent | change a variable: shut an interface, reset a counter |
| Response | agent to manager | the values, or an error |
| Trap | agent to manager (UDP 162) | report an event unasked: a link went down, a fan failed |
| InformRequest (v2) | agent to manager | a trap that must be acknowledged |
Versions: SNMPv1 (RFC 1157, 1990) and SNMPv2c protect access only with a community string sent in plain text (the default read-only community is "public", a well-known risk); SNMPv3 (RFC 3411 to 3418) adds real user authentication and encryption.
A manager reads a router interface's ifInOctets twice, 300 seconds apart: 1,200,000,000 and then 1,575,000,000 bytes. Average incoming rate = (1,575,000,000 − 1,200,000,000) × 8 / 300 = 10,000,000 bit/s = 10 Mbit/s. This is exactly what MRTG does every five minutes (MRTG and PRTG).
To remember it: a hostel warden (the manager) checks each room's meter (the agents' MIB) on a round every five minutes (polling, Get), can switch a room's power off from the office (Set), and a room with a short circuit calls the warden at once without waiting for the round (a trap).
Traffic graphers: MRTG and PRTG
MRTG (Multi Router Traffic Grapher), free and open source, was written by Tobias Oetiker in 1995 in Perl, with a small helper in C. Every 5 minutes, by default, it reads each interface's SNMP byte counters (ifInOctets and ifOutOctets), works out the rate from the difference (SNMP), and redraws four graphs on a web page: a daily graph of 5-minute averages, a weekly one of 30-minute averages, a monthly one of 2-hour averages and a yearly one of daily averages. Its ideas live on in RRDtool, by the same author, and in tools built on it such as Cacti.
PRTG Network Monitor (Paessler Router Traffic Grapher), from the German company Paessler, is a commercial tool that runs on Windows (free for up to 100 sensors). It discovers devices automatically and watches them through sensors, each one measured value: ping time, SNMP traffic, CPU load, disk space, an HTTP response, NetFlow records or sniffed packets. It keeps the history, draws dashboards and maps, and sends alerts by email or SMS when a value crosses a limit.
| Point | MRTG | PRTG |
|---|---|---|
| Licence | free, open source | commercial (free up to 100 sensors) |
| Platform | Unix and Windows; configured by text files | Windows server, web interface |
| Data collection | SNMP counters, mainly traffic | SNMP, ping, NetFlow, packet sniffing, WMI and more |
| Output | PNG graphs on HTML pages | dashboards, maps, reports, alerts |
| Best for | a simple traffic history per link | monitoring a whole network, with alarms |
What the graphs answer: how full a link is and when (bandwidth utilisation), whether errors and discards are rising, which device is overloaded, and whether a link needs upgrading before users complain. Throughput and delay themselves are chapter 2's (delay and throughput).
To remember it: MRTG is the electricity meter with a chart. Suppose a hostel's 100 Mbit/s link shows peaks near 90 Mbit/s every night from 8 to 11 pm and almost nothing at 4 am: the graph tells the network admin the link is full only in the evening streaming hours, and whether an upgrade or a better plan is the answer.
Wireshark and Packet Tracer: real packets, simulated networks
Wireshark began in 1998 as Ethereal, by Gerald Combs, and was renamed in 2006. It captures through libpcap (Npcap on Windows), usually in promiscuous mode, so it sees every frame reaching the interface, not just its own. The window has three panes: the packet list, the packet details (each layer as a tree: Ethernet, IP, TCP, HTTP) and the packet bytes in hex.
- Capture filters decide what is recorded, in BPF syntax:
port 53,host 192.168.1.10. - Display filters decide what is shown:
dns,http.request,ip.addr == 192.168.1.10,tcp.port == 80,tcp.flags.syn == 1. - Follow TCP Stream rebuilds a whole conversation as text; the Statistics menu gives conversations, protocol shares and traffic graphs; TShark is the command-line version.
What a student can see with it: the three-way handshake (three-way handshake), a DNS query and the reply with the same ID (DNS), the four DORA messages (DHCP), an FTP password in plain text, and the difference between HTTP, readable, and HTTPS, only TLS records. Capture only on a network that is yours or where permission is given: other people's traffic is private.
Packet Tracer is free with a Cisco Networking Academy account. Devices are dragged onto a workspace, cabled, and configured with real IOS commands; its servers run DHCP, DNS, HTTP, FTP, TFTP and email services, so every protocol of this chapter can be practised in one file. In realtime mode the network simply runs; in simulation mode time stops, each packet appears as an envelope moving along the cables, and a click opens its contents layer by layer.
| Point | Wireshark | Packet Tracer |
|---|---|---|
| Works on | real traffic, on a real interface | a simulated network |
| Purpose | troubleshooting, security analysis, learning protocols | designing, configuring and learning networks |
| Shows | every field of every captured packet | packets moving step by step through devices |
| Made by | an open-source community (free) | Cisco (free with Networking Academy) |
| Limit | sees only traffic that reaches the interface | a subset of real device features |
To remember it: Packet Tracer is the flight simulator, Wireshark the black box of a
real flight. A lab exercise uses both: build a PC, a switch and a server running DHCP and DNS
in Packet Tracer and watch DORA in simulation mode; then run Wireshark on a real laptop with
the filter dhcp or dns while reconnecting to Wi-Fi, and see the same messages
for real.
6.9Last minute recall
Chapter 6 in one screen
- Ports: HTTP 80, HTTPS 443, FTP 21 and 20, SSH 22, Telnet 23, SMTP 25 and 587, DNS 53, DHCP 67 and 68, TFTP 69, POP3 110, IMAP 143, SNMP 161 and 162.
- HTTP: stateless request and response over TCP; request line, headers, blank line, body; GET, POST, HEAD, PUT, DELETE; 1xx to 5xx; non-persistent 2 RTT per object, persistent reuses the connection.
- HTTPS: HTTP over TLS, port 443; certificate, encryption, integrity.
- FTP: control connection port 21 for the session, data connection port 20 per file; active PORT, passive PASV; USER, PASS, RETR, STOR, QUIT; stateful, plain-text password.
- TFTP: UDP 69, no login, 512-byte blocks each ACKed.
- Mail: UA, mail server, MTA, MDA, MAA; SMTP push (25), POP3 (110) and IMAP (143) pull.
- SMTP: 220, HELO, MAIL FROM, RCPT TO, DATA 354, message ending ".", 250, QUIT 221; 7-bit ASCII.
- POP3 against IMAP: download and delete, one device; against mail on the server, folders, state, many devices, partial fetch.
- MIME: Content-Type, Content-Transfer-Encoding; base64 3 bytes to 4 characters (+33 percent); quoted-printable.
- DNS: distributed hierarchical name database, UDP 53; root, TLD, authoritative, local; recursive (server does the work) against iterative (referrals); TTL caching.
- Records: A, AAAA, CNAME, MX, NS, PTR, SOA, TXT; fields name, type, class, TTL, data.
- Delegation: NS records (plus glue) in the parent hand a zone to the child's servers.
- DNS message: 12-byte header (ID, flags QR AA TC RD RA RCODE, 4 counts); question, answer, authority, additional.
- DHCP: DORA over UDP 67 and 68; T1 50 percent unicast renew, T2 87.5 percent broadcast rebind, expiry back to DISCOVER.
- P2P: peers serve and download; BitTorrent tracker, pieces, rarest first, tit for tat; DHT in about log N hops.
- Sockets: server socket, bind, listen, accept; client socket, connect; send, recv, close; the server runs first.
- Proxy: web cache, hit or miss, conditional GET and 304; speed, bandwidth, filtering, privacy; forward and reverse.
- RAID: 0 striping, no safety; 1 mirroring, half capacity; 5 parity, n − 1, one disk may fail; not a backup.
- Monitoring: SNMP manager, agent, MIB, OID, Get, Set, Trap; MRTG 5-minute graphs; PRTG sensors; Wireshark captures; Packet Tracer simulates.
Chapter 7 · 4 hours · about 7 marks a paper · in 24 of the 27 sittings
Introduction to IPv6
IPv6 replaces IPv4 now that the world has run short of 32-bit addresses: 128-bit addresses, a simpler fixed header, options moved into extension headers, and hosts that configure themselves. IPv4 cannot simply be switched off, so the board's favourite question is how the two coexist. Every sitting since 2069 Chaitra has set one IPv6 question, usually Q8 for 8 marks.
- Why IPv6: the problems of IPv4 (address exhaustion, NAT, a complex header, weak security and QoS, manual configuration) and the IPv6 feature that answers each.
- The packet: the fixed 40-byte base header, field by field, and how it differs from the IPv4 header in routing and in what a router must do to each packet.
- Extension headers: the optional headers chained behind the base header by the next header field, and their recommended order.
- Addresses: hexadecimal colon notation and its shortening rules; unicast, anycast and multicast; IPv4 addresses written as IPv6; and how a host configures itself (SLAAC, DHCPv6).
- Multicasting: the
ff00::/8format with its scope, the solicited-node groups that replace ARP's broadcast, and MLD. - Transition: coexistence; dual stack; tunneling (configured, 6to4, ISATAP, 6RD, Teredo); header translation (SIIT, NAT-PT, NAT64 with DNS64, 464XLAT); and which to choose.
- IPv4 is chapter 4's: the IPv4 header (IPv4 header), classful addressing and NAT (IPv4 addressing), CIDR (supernetting); this chapter compares against them.
- Neighbour discovery replaces ARP: ARP and NDP are compared in chapter 4 (ARP); ICMPv6 carries them, as ICMP does for IPv4 (ICMP).
- Security and multicast routing: the AH and ESP extension headers are IPsec (IPsec); multicast between routers is chapter 4's (multicast routing).
- Configuration and names: DHCPv6 extends DHCP (DHCP), and DNS AAAA records decide which protocol a dual-stack host uses (DNS).
- 7.1 Why IPv6: the problems of IPv4 and the advantages of IPv6
- 7.2 The IPv6 datagram and the IPv4 comparison
- 7.3 Extension headers
- 7.4 IPv6 addresses and autoconfiguration
- 7.5 IPv6 multicasting
- 7.6 Transition from IPv4 to IPv6
- 7.7 Last minute recall, chapter 7
- Transition is the banker: dual stack, tunneling and header translation, each with a figure; the recent papers add 6to4, ISATAP and 6RD by name, and "which method would you suggest".
- Why IPv6 opens most questions for 2 to 4 marks: the problems of IPv4, the advantages of IPv6, the factors behind it.
- The datagram has been a whole 8-mark question: draw the 40-byte header 32 bits wide and give the job of each field; or compare it with IPv4's.
- Order: the syllabus lists transition (7.4) before multicasting (7.5). The reader teaches addresses and multicasting first, because the transition methods are built out of addresses (6to4, ISATAP, IPv4-mapped).
7.1Why IPv6
Why IPv6: the problems of IPv4 and what IPv6 fixes TOP 13/27
80 Ba · 79 Bh · 78 Bh · 76 Ash · 74 Ch · 74 Ash · 73 Shr · 72 Ka · 71 Ch · 71 Shr · 70 Asa · 68 Ba · 66 Bh2+64+42+2+4
The same job in a new format. TCP, UDP and every application run over IPv6 unchanged; what changes is the address and the packet. Its history is short:
- IPng: in the early 1990s the IETF saw that 32-bit addresses would run out and began work on "IP next generation".
- The standards: first specified in RFC 1883 (1995), revised in RFC 2460 (1998), and a full Internet Standard as RFC 8200 (2017).
- Why "6": version number 5 had already gone to an experimental streaming protocol, the Internet Stream Protocol (ST), so the new IP became version 6.
IPv4's problems, and IPv6's answer to each. IPv4 (RFC 791, 1981) was designed for a research network; it now carries billions of devices. Each deficiency is paired with the IPv6 feature that removes it:
| IPv4 problem | What goes wrong | What IPv6 does |
|---|---|---|
| Address exhaustion | 32 bits give = 4,294,967,296 addresses, fewer once private, multicast and reserved blocks are set aside, and classful allocation wasted many. IANA gave out its last free blocks on 3 February 2011; APNIC, the registry that serves Nepal, reached its last block on 15 April 2011. | 128-bit addresses, ; one /64 subnet alone holds , which is times the whole IPv4 Internet |
| NAT everywhere | private addresses behind NAT share one public address, so outside hosts cannot reach inside ones; peer-to-peer, VoIP, online games and IPsec struggle, and ISPs run carrier-grade NAT with many customers behind one address | every device gets a global address and end-to-end connectivity returns; a firewall, not NAT, decides what may come in |
| Slow, complex header | 20 to 60 bytes, options every router must check, a checksum recomputed at every hop, fragmentation by routers | fixed 40-byte header: no checksum, no router fragmentation, options in extension headers |
| Routing table growth | classful history and scattered allocations aggregate poorly | hierarchical allocation (registry, ISP, site /48, subnet /64) aggregates into few routes |
| No IP-layer security | no authentication or encryption; IPsec came later as an option | AH and ESP are defined as extension headers (IPsec) |
| Weak real-time support | type of service used inconsistently; no way to mark a flow | traffic class plus a 20-bit flow label let routers recognise a flow |
| Configuration | addresses set by hand or by a DHCP server (DHCP) | stateless autoconfiguration (SLAAC): plug and play, easy renumbering; DHCPv6 if wanted |
| Broadcast | ARP and other broadcasts interrupt every host on the link | no broadcast at all: scoped multicast and anycast |
| Mobility | Mobile IPv4 sends traffic through a home agent (triangle routing) | Mobile IPv6 (RFC 6275) can route straight to the moving host |
The advantages of IPv6 over IPv4, as a list; the book gives the first seven:
- Larger address space: addresses, enough for every phone, laptop, sensor and bulb.
- Better header format: fixed 40 bytes, options separated out, no checksum, so faster processing.
- Possibility of extension: a new feature is a new extension header or option, with no redesign of the base header.
- Smaller routing tables: globally unique, hierarchical prefixes in place of classes keep backbone routing efficient.
- Security: authentication (AH) and encryption (ESP) at the IP layer.
- Resource allocation: the traffic class and the flow label let a source ask for special handling of real-time audio and video.
- Multicast with scopes: every multicast address says how far it may travel (multicasting); anycast reaches the nearest server.
- Autoconfiguration: a host builds its own address from the router's advertisement (SLAAC).
- End-to-end connectivity: no NAT needed, which suits peer-to-peer, VoIP and IoT.
- Mobility and jumbograms: Mobile IPv6, and payloads over 65,535 bytes with the jumbo payload option.
The factors behind its development, and behind the world now moving to it:
- Growth of the Internet: the free pools of IPv4 addresses, forecast to empty in the early 1990s, did empty from 2011.
- New kinds of devices: smartphones, always-on broadband and IoT sensors each need an address, and developing countries, where many people are only now coming online, need the most.
- The cost of NAT: carrier-grade NAT is expensive to run and breaks applications.
- Real-time multimedia: audio and video need special handling the IPv4 design never provided.
- Security: the demand for authentication and encryption at the network layer.
- Simpler routing and configuration: a faster header, smaller tables, plug-and-play hosts.
- Deployment pushes: World IPv6 Day (8 June 2011), a 24-hour trial, then World IPv6 Launch (6 June 2012), when major websites and ISPs switched IPv6 on for good; mobile operators now run IPv6-only networks.
To picture it: IPv4 is a hostel with four billion rooms for eight billion people, each with a phone and a laptop. NAT puts a whole floor behind one room number, so nobody outside can call a student by name. IPv6 gives every device its own number: one floor of the new hostel has more rooms than the whole old building.
- What are the advantages of IPv6? Briefly explain the different transition strategies. 2080 Baishakh Q8 · 2+6
- What are the problems of IPV4? How can IPV6 reduce these problems? Explain header translation mechanism for transition from IPV4 to IPV6. 2079 Bhadra Q8 · 2+2+4
- List advantages of IPv6 over IPv4. Explain any two suitable transition strategies for IPv4 to IPv6. 2078 Bhadra Q8 · 2+6
- List the advantages of IPv6 over IPv4. Explain any two transition strategies for IPv4 to IPv6. 2076 Ashwin Q8 · 2+6
- What are the factors that lead to the speedy development of IPv6? Define the process of transition from IPv4 to IPv6. 2074 Chaitra Q8 · 4+4
- List the advantages of IPv6 over IPv4. Explain header translation and tunneling approach used for migrating IPv4 to IPv6. 2074 Ashwin Q8 · 4+4
- What are the factors that lead to the development of IPv6? Define the process of transition from IPv4 to IPv6. 2073 Shrawan Q7 · 4+4
- What is IPV6? What methods are used so that IPV6 and IPV4 networks are interoperable? 2072 Kartik Q8 · 2+6
- What are the problems of IPv4? How IPv6 reduce these problems? Explain different strategies to transit from IPv4 and IPv6. 2071 Chaitra Q8 · 2+2+4
- What are the drawbacks in IPV4? Which of these drawbacks do IPV6 solve? Explain. 2071 Shrawan Q8 · 2+6
- What are the major problems with existing IPv4 network? Explain IPv4 addressing and sub-netting with example. 2070 Ashad Q9 · 4+4
- What are the advantages of IPV6? The maximum payload segment is 65495 byte. Why was such strange number chosen? 2068 Baishakh Q7 · 4+4
- Give the reason why the current world is moving to IPv6 addressing mechanism. Describe the IPv6 address types with its representation format. You are given the IPv4 address block 203.71.53.0/26; assign the IP subnet for the following network. [Figure, as text: Net A: 6 Hosts (LAN on router R1); Net B: 2 Hosts (link R1 to R2); Net C: 12 Hosts (LAN on router R2); Net E: 2 Hosts (link R2 to R3); Net F: 29 Hosts (LAN on router R3). The routers are unlabelled in the print and no Net D is drawn.] 2066 Bhadra Q5a · 2+2+6
7.2The IPv6 packet format
The IPv6 datagram: a fixed 40-byte header, compared with IPv4 HOT 6/27
81 Bh · 81 Ba · 75 Ash · 72 Ch · 70 Ch · 69 Ch4+486+2
Eight fields, in 32-bit rows like IPv4's, but every field sits at a fixed place, so a router finds each one without first reading a length field.
| Field | Bits | What it does |
|---|---|---|
| Version | 4 | the IP version, 6 (binary 0110), in the same place as IPv4's, so a node can tell the two apart |
| Traffic class | 8 | the class of service: a 6-bit DSCP for differentiated services and 2 ECN bits for congestion notification; the job of IPv4's type of service |
| Flow label | 20 | set by the source to mark the packets of one flow (one video call, one download) so routers can treat them alike, for example keep them on one path, without reading the transport header; 0 when unused (RFC 6437) |
| Payload length | 16 | bytes after the base header, extension headers included, up to 65,535; the base header is never counted, being always 40 bytes |
| Next header | 8 | what follows the base header: an extension header (0, 43, 44, 50, 51, 60) or the upper layer (6 TCP, 17 UDP, 58 ICMPv6); the same numbers as IPv4's protocol field |
| Hop limit | 8 | lowered by 1 at each router; at 0 the packet is dropped and an ICMPv6 Time Exceeded message goes back to the source: IPv4's time to live under an honest name |
| Source address | 128 | the sender's IPv6 address |
| Destination address | 128 | the receiver's address, or the next node to visit when a routing header is present |
To picture it: an IPv6 header is a courier slip with fixed printed boxes. The courier office in Butwal (a router) reads only the "to" box and stamps the hop counter; it never measures the slip or checks a seal. Extra sheets clipped behind the slip, "part 2 of 3" or "sealed", are for the receiver: those are the extension headers.
Against the IPv4 header, field by field (the IPv4 header is chapter 4's): six IPv4 fields are gone, four renamed, three kept, and one field is new.
| IPv4 field (bits) | In IPv6 | Why |
|---|---|---|
| Version (4) | kept, value 6 | tells the two versions apart |
| Header length, IHL (4) | removed | the header is always 40 bytes |
| Type of service (8) | renamed traffic class | the same DSCP and ECN bits |
| Total length (16) | renamed payload length | now counts only what follows the fixed header |
| Identification (16), flags (3), fragment offset (13) | removed, into the fragment extension header | routers never fragment; only the source does, and only when it must |
| Time to live (8) | renamed hop limit | it always counted hops, never seconds |
| Protocol (8) | renamed next header | it may now point to an extension header too |
| Header checksum (16) | removed | link layers (the Ethernet CRC) and transport checksums already catch errors, and no router has to recompute it after changing the TTL |
| Source, destination (32 each) | kept, 128 bits each | the larger address space |
| Options and padding (up to 320) | removed | moved into extension headers |
| (none) | added: flow label (20) | flow identification for quality of service |
A consequence of the missing checksum: the UDP checksum, optional over IPv4, is mandatory over IPv6 (RFC 8200), and the TCP, UDP and ICMPv6 checksums cover a pseudo-header that includes both 128-bit addresses.
IPv4 and IPv6 compared overall:
| Point | IPv4 | IPv6 |
|---|---|---|
| Address | 32 bits, dotted decimal: 192.168.1.20 | 128 bits, hexadecimal with colons: 2001:db8:acad:1::20 |
| Header | 20 to 60 bytes, 12 fields and options | 40 bytes fixed, 8 fields |
| Checksum | in the header | none |
| Fragmentation | by the sender and by routers | by the sender only; routers send ICMPv6 Packet Too Big |
| Smallest link MTU | 68 bytes (hosts must accept 576) | 1,280 bytes |
| Options | inside the header | extension headers |
| Configuration | manual or DHCP | SLAAC, DHCPv6 or manual |
| Delivery | unicast, multicast, broadcast | unicast, multicast, anycast; no broadcast |
| Neighbour's MAC address | ARP, by broadcast | neighbour discovery (ICMPv6), by multicast |
| Security | IPsec optional, added later | AH and ESP as extension headers |
| Quality of service | type of service | traffic class and flow label |
| NAT | common; breaks end-to-end | not needed |
| DNS record | A | AAAA |
| Loopback | 127.0.0.1 | ::1 |
Routing and header manipulation. What a router does to each packet is where the new header pays off:
| At each router | IPv4 | IPv6 |
|---|---|---|
| Find the fields | read IHL first: the header is 20 to 60 bytes | fixed offsets in 40 bytes |
| Checksum | verify it, then recompute it after changing the TTL | none to verify or recompute |
| Lifetime | TTL minus 1 | hop limit minus 1, the only field a router changes |
| Options | examine any options, often in slow software | skip extension headers, except hop-by-hop |
| Too big for the next link | fragment it, unless DF is set | drop it and send ICMPv6 Packet Too Big; the source resends smaller |
| Address rewriting | NAT rewrites addresses, ports and checksums | none: addresses stay end to end |
| Recognising a flow | read port numbers deep in the packet | read the flow label in the header |
| Route lookup | longest prefix match on 32 bits | longest prefix match on 128 bits |
| Routing protocols | RIP, OSPFv2, BGP | RIPng, OSPFv3, multiprotocol BGP (MP-BGP), IS-IS |
Critically, the gains are not free:
- Lookups: a 128-bit route lookup needs more router memory (TCAM) for each route.
- Two of everything: during the transition a dual-stack router keeps two routing tables and runs two sets of routing protocols.
- Extension headers: packets carrying them, hop-by-hop above all, leave the fast hardware path and are often dropped on the real Internet (RFC 7872 measured it).
- ICMPv6 filtering: a network that blocks ICMPv6 breaks path MTU discovery, so large packets silently vanish.
- Aggregation: the IPv6 table stays small only if providers announce their blocks whole.
A hostel PC sends a 1,500-byte packet through the campus router towards a link whose MTU is 1,280 bytes.
- IPv4: the router reads IHL (5, so 20 bytes), checks the checksum, lowers the TTL from 64 to 63, recomputes the checksum, and, the packet being too big with DF clear, splits its 1,480 data bytes into two fragments of 1,276 and 244 bytes, each with a header and checksum of its own.
- IPv6: the router lowers the hop limit from 64 to 63, finds the packet too big, drops it and returns ICMPv6 Packet Too Big (MTU 1,280). The PC sends later packets at no more than 1,280 bytes (TCP just uses smaller segments), and they pass straight through.
- Critically compare IPv4 and IPv6 in terms of routing and head manipulation. Explain the importance and implementation approach of 6RD for IPv6 based services on the existing IPv4 networking. 2081 Bhadra Q8 · 4+4
- Compare the IPv4 header with IPv6 header. Explain the dual stack strategy to transit from IPv4 to IPv6. 2081 Baishakh Q8 · 4+4
- What are the methods used to interoperate IPv6 and IPv4. Show IPv6 datagram format. 2075 Ashwin Q8 · 6+2
- Compare the header fields of IPV6 and IPV4. Which method do you suggest for the migration of IPv6 and why? 2072 Chaitra Q7 · 4+4
- Explain the IPv6 datagram format with appropriate figures. 2070 Chaitra Q8 · 8
- Explain the IPv6 datagram format and the function of each field with necessary figure. 2069 Chaitra Q8 · 8
7.3Extension headers
Extension headers: the options moved out of the base header PIN 1/27
82 Bh2+6
Why move the options out. IPv4 options sit inside the header, so every router must check for them, though most packets carry none. IPv6 keeps the base header fixed and adds an extension header only where it is needed; a new feature is just a new header type.
The chain of next headers. The base header's next header field names the first extension header; that header's own next header field names the second; and so on, until a value names the upper layer (6 TCP, 17 UDP, 58 ICMPv6) or 59, no next header.
Format. Each extension header starts with an 8-bit next header and, except the fixed 8-byte fragment header, an 8-bit length (in 8-byte units, not counting the first 8 bytes). Each is padded to a multiple of 8 bytes, so the next one starts on an 8-byte boundary.
| Order | Header | Code | Read by | What it does |
|---|---|---|---|---|
| 1 | Hop-by-hop options | 0 | every node on the path | must come first, straight after the base header. Options: Pad1 (1 byte) and PadN (2 or more bytes) for alignment; Jumbo Payload for packets over 65,535 bytes (up to ); Router Alert, used by MLD |
| 2 | Destination options | 60 | the destination and every node a routing header lists | options for each of those nodes |
| 3 | Routing | 43 | the nodes listed | addresses to visit on the way: the IPv6 form of IPv4's loose and strict source routing |
| 4 | Fragment | 44 | the final destination | 13-bit fragment offset, a more-fragments flag and a 32-bit identification; only the source fragments |
| 5 | Authentication header (AH) | 51 | the final destination | proves the sender and the integrity of the packet (IPsec, chapter 8) |
| 6 | Encapsulating security payload (ESP) | 50 | the final destination | encrypts what follows and protects its integrity |
| 7 | Destination options | 60 | the final destination only | options for the receiver alone |
| 8 | Upper-layer header | 6, 17, 58 | TCP, UDP or ICMPv6 at the destination | the data itself |
- Once each: every header appears at most once, except destination options, at most twice (before a routing header and before the upper layer).
- Hop-by-hop first: when present it must follow the base header directly; since RFC 8200 a router processes it only if configured to.
- Untouched on the way: no router inserts or deletes an extension header.
To picture it: a parcel from Kathmandu to Pokhara with stickers stacked behind the label in a fixed order: "fragile", read by every handler (hop-by-hop); "via the Mugling office" (routing); "box 2 of 3" (fragment); a wax seal (AH); a locked inner box (ESP). Only "fragile" concerns the handlers on the way.
Fragmentation, only at the source. A router never fragments an IPv6 packet:
- Path MTU discovery (RFC 8201): the source sends at its own link's MTU.
- Packet Too Big: a router that cannot forward the packet drops it and returns an ICMPv6 Packet Too Big message giving the next link's MTU.
- Resend smaller: the source sends smaller packets, adding a fragment header only if the data cannot be cut some other way.
Every IPv6 link must carry at least 1,280 bytes, so a packet of 1,280 bytes or less never needs fragmenting.
- List the IPv6 extension headers in order. Explain ISATAP and 6 to 4 tunneling with their address format for IPv4 to IPv6 transition. 2082 Bhadra Q8 · 2+6
7.4IPv6 addressing
IPv6 addresses: notation, types and autoconfiguration PIN 3/27
82 Ba · 80 Bh · 66 Bh2+2+42+2+63+5
2001:db8:acad:1::/64 (RFC 4291).
Hexadecimal colon notation. The 128 bits are cut into eight 16-bit groups, each written
as four hexadecimal digits: 2001:0db8:0000:0000:0000:ff00:0042:8329. Two rules
shorten it:
- Drop leading zeros in any group:
0db8becomesdb8,0042becomes42,0000becomes0. - Replace one run of all-zero groups by
::, once only:2001:db8:0:0:0:ff00:42:8329becomes2001:db8::ff00:42:8329.
- Expanding: count the groups shown;
::stands for the missing ones, 8 minus that count. - Why only once: in
2001:db8::1::1four groups are missing, and nothing says how they split:2001:db8:0:1:0:0:0:1or2001:db8:0:0:1:0:0:1. - The canonical form (RFC 5952): lower case, the longest run of zeros shortened (the
first, if two are equal), and never
::for a single zero group.
Prefixes work as in CIDR (supernetting):
2001:db8:acad:1::/64 means the first 64 bits name the network and the last 64 the
interface.
- A typical plan: an ISP holds a /32 and gives a site a /48 (a home a /56); the site cuts /64 subnets from it, = 65,536 of them in a /48.
- In a URL a literal address goes in brackets:
http://[2001:db8::1]:8080/.
Three types of address, and no broadcast:
| Type | Delivered to | Ranges and examples |
|---|---|---|
| Unicast | one interface (one to one) | global unicast 2000::/3, such as 2001:db8:acad:1::20; link-local fe80::/10; unique local fc00::/7; loopback ::1; unspecified :: |
| Anycast | the nearest of a set of interfaces, by routing distance (one to nearest) | taken from the unicast space and given to several interfaces; the subnet-router anycast address is the prefix with an all-zero interface ID, 2001:db8:acad:1:: |
| Multicast | every member of a group (one to many) | ff00::/8: ff02::1 all nodes, ff02::2 all routers (multicasting) |
- Global unicast (
2000::/3): routable on the Internet, like a public IPv4 address. A global routing prefix (48 bits for a typical site), a 16-bit subnet ID and a 64-bit interface ID. - Link-local (
fe80::/10): every IPv6 interface makes one for itself; it is valid on its own link only and never forwarded. Neighbour discovery and routing protocols use it, and a host's default gateway is the router's link-local address. - Unique local (
fc00::/7, in practicefd00::/8with a random 40-bit global ID, RFC 4193): private addresses inside a site, like RFC 1918's10.0.0.0/8, never routed on the Internet. - Site-local (
fec0::/10): the older private kind, deprecated in 2004 (RFC 3879) and replaced by unique local addresses.
IPv4 addresses inside IPv6 addresses. To map an IPv4 address to IPv6, write each of its
bytes as two hexadecimal digits and place the 32 bits at the end of a 128-bit pattern:
192.0.2.33 is c0, 00, 02, 21, so c000:0221. Mixed notation may keep the
last 32 bits in dotted decimal.
| Form | Layout | 192.0.2.33 becomes | Used for |
|---|---|---|---|
| IPv4-mapped | 80 zero bits, 16 one bits, the IPv4 address | ::ffff:192.0.2.33, that is ::ffff:c000:221 | an IPv4 peer as an IPv6 socket on a dual-stack host sees it; SIIT translation |
| IPv4-compatible | 96 zero bits, the IPv4 address | ::192.0.2.33 | deprecated (RFC 4291) |
| NAT64 well-known prefix | 64:ff9b::/96, the IPv4 address | 64:ff9b::c000:221 | IPv6-only hosts reaching IPv4 servers (translation) |
| 6to4 site prefix | 2002, the IPv4 address, then subnet and interface | 2002:c000:221::/48 | automatic tunnels |
How a host gets an address automatically. Flags in the router's advertisements choose one of three ways:
- SLAAC (stateless address autoconfiguration, RFC 4862): the host builds its own address from the router's prefix; no server keeps a record.
- Stateless DHCPv6: SLAAC for the address, DHCPv6 for DNS and other settings.
- Stateful DHCPv6 (RFC 8415): a server leases addresses, as DHCP does in IPv4.
SLAAC runs on neighbour discovery (RFC 4861), five ICMPv6 messages: router solicitation (133), router advertisement (134), neighbour solicitation (135), neighbour advertisement (136) and redirect (137). The two neighbour messages also do ARP's job (ARP and NDP).
- Link-local address: the host makes a 64-bit interface ID and puts
fe80::/64in front:fe80::200:5eff:fe00:5301. - Duplicate address detection (DAD): from the unspecified address
::it sends a neighbour solicitation for the new address to that address's solicited-node group,ff02::1:ff00:5301. A neighbour advertisement in reply means someone already has it; silence for about a second means the address is the host's. - Router solicitation to all routers,
ff02::2: rather than wait for the next periodic advertisement, the host asks. - Router advertisement to all nodes,
ff02::1: the prefix2001:db8:acad:1::/64with its valid and preferred lifetimes, the hop limit and MTU to use, the M (managed) and O (other configuration) flags, and often the DNS servers (the RDNSS option, RFC 8106). The router's link-local address becomes the default gateway. - Global address: prefix plus interface ID,
2001:db8:acad:1:200:5eff:fe00:5301, checked by DAD in turn. - DHCPv6 if flagged: with M set the address comes from a DHCPv6 server (UDP ports 546 and 547); with O set, only DNS and other settings do.
The interface ID. The classic method is modified EUI-64: split the 48-bit MAC
address in half, insert FF-FE in the middle, and flip the seventh bit of the first
byte (the universal/local bit). 00-00-5E-00-53-01 becomes
02-00-5E-FF-FE-00-53-01, so the interface ID is 0200:5eff:fe00:5301.
Privacy: an ID built from the MAC follows the device to every network, so websites could track a laptop by it. Current systems use random interface IDs instead, stable for each network (RFC 7217) or temporary and changing (RFC 8981).
Renumbering is easy too: when the ISP changes the prefix, the router advertises the new one, the old one's preferred lifetime runs out, and hosts move over by themselves.
To picture SLAAC: a hostel room with no warden on duty. The corridor notice gives the block and floor (the prefix); you add your roll number (the interface ID); you shout once, "is anyone using this number?" (DAD); and if nobody answers, the room is yours. Nobody keeps a register: that is stateless.
FE80:0000:0000:0001:0800:23E7:F5DB, has only seven groups (112 bits). Its shortened
form, FE80::1:0800:23E7:F5DB, is valid but stands for
fe80:0:0:0:1:800:23e7:f5db (three zero groups) and keeps the leading zero of
0800; both its examples are worked in the Numericals panel. It also lists
site-local, deprecated in 2004.- Map IPv4 addresses with its IPv6 equivalent. What are the latest best IPv6 transition methodologies? Explain anyone of them. 2082 Baishakh Q8 · 2+2+4
- Explain the three address types in IPv6 with the IP notations. How does on IPv6 machine acquire IPv6 address automatically? 2080 Bhadra Q8 · 3+5
- Give the reason why the current world is moving to IPv6 addressing mechanism. Describe the IPv6 address types with its representation format. You are given the IPv4 address block 203.71.53.0/26; assign the IP subnet for the following network. [Figure, as text: Net A: 6 Hosts (LAN on router R1); Net B: 2 Hosts (link R1 to R2); Net C: 12 Hosts (LAN on router R2); Net E: 2 Hosts (link R2 to R3); Net F: 29 Hosts (LAN on router R3). The routers are unlabelled in the print and no Net D is drawn.] 2066 Bhadra Q5a · 2+2+6
7.5Multicasting
IPv6 multicasting: groups, scopes and MLD
ff00::/8. IPv6 has no broadcast, so what IPv4 did by broadcast is done with
multicast groups; every multicast address carries a scope, and routers learn which
groups have listeners with MLD.
How it works. As in IPv4, any node may join or leave a group at any time, and a sender needs no list of members. A group address is only ever a destination, never a source or a stop in a routing header; each link delivers one copy to each member by hardware multicast.
- Prefix: the first 8 bits are
1111 1111, so every multicast address begins withff. - Flags (4 bits,
0RPT): T = 0 for a permanent, well-known group assigned by IANA, T = 1 for a temporary one; P = 1 for an address built from a unicast prefix (RFC 3306); R = 1 when a rendezvous point's address is embedded (RFC 3956). - Scope (4 bits): how far the group reaches; a router never forwards a packet beyond
its scope. IPv4 marked scope only by convention (the
239.0.0.0/8block, TTL limits). - Group ID (112 bits): which group within that scope.
| Scope | Reach |
|---|---|
| 1 | interface-local: within one node, for loopback |
| 2 | link-local: one link, never routed |
| 4 | admin-local: the smallest scope set by configuration |
| 5 | site-local: one site |
| 8 | organization-local: the sites of one organization |
| e | global: the whole Internet |
Well-known groups, all on the link (scope 2) unless stated:
| Address | Group |
|---|---|
ff02::1 | all nodes: the nearest thing to a broadcast |
ff02::2 | all routers |
ff02::5, ff02::6 | OSPFv3 routers, OSPFv3 designated routers |
ff02::9 | RIPng routers |
ff02::a | EIGRP routers |
ff02::16 | MLDv2-capable routers |
ff02::1:2 | all DHCPv6 relay agents and servers |
ff05::1:3 | all DHCPv6 servers in the site (scope 5) |
The solicited-node group: multicast in place of ARP's broadcast. Every unicast address
automatically joins the group ff02::1:ff followed by its own last 24 bits, so
2001:db8:acad:1:200:5eff:fe00:5301 joins ff02::1:ff00:5301. To find a
neighbour's MAC address, or to check an address by DAD, a host sends its neighbour solicitation
to that group, not to everyone.
- On Ethernet an IPv6 multicast address maps to the MAC address
33:33followed by its last 32 bits (RFC 2464):33:33:ff:00:53:01here,33:33:00:00:00:01forff02::1. - In hardware: the network card filters frames by that MAC address, so the only hosts disturbed are those whose addresses share the last 24 bits, usually just one.
MLD, the IPv6 IGMP. Multicast Listener Discovery lets a router learn which groups have listeners on each of its links, as IGMP does for IPv4 (multicast routing is chapter 4's).
- Versions: MLDv1 (RFC 2710) matches IGMPv2; MLDv2 (RFC 3810) matches IGMPv3 and adds source filtering. Both are ICMPv6 messages.
- Messages: the router sends queries (type 130); hosts answer with reports (131 in MLDv1, 143 in MLDv2) and say done (132) when they leave.
- Kept on the link: a link-local source, a hop limit of 1 and the Router Alert hop-by-hop option; switches snoop on MLD to send a group's traffic only to the ports that asked for it.
- Between routers, PIM-SM and PIM-SSM carry IPv6 multicast as they carry IPv4's.
To picture it: the warden shouting "room 301!" down every corridor is ARP's broadcast: everyone wakes for nothing. Calling only the rooms ending in 301, usually one, is the solicited-node group; "second-years, this block only" is a scoped group.
7.6Transition from IPv4 to IPv6
From IPv4 to IPv6: coexistence, dual stack, tunneling and translation TOP 18/27
82 Bh · 82 Ba · 81 Bh · 81 Ba · 80 Bh · 80 Ba · 79 Bh · 78 Bh · 76 Ch · 76 Ash · 75 Ch · 75 Ash · 74 Ch · 74 Ash · 73 Shr · 72 Ch · 72 Ka · 71 Ch4+42+62+2+4
Why there is no switch-over day. IPv6 is not backward compatible: an IPv4-only host cannot read an IPv6 header. Billions of devices cannot all change at once, as the ARPANET's hosts did when it switched to TCP/IP on 1 January 1983, so for many years the two protocols must coexist.
Coexistence. "IPv4 and IPv6 coexistence" means the two protocols running side by side on the same Internet, often on the same hosts, links and routers, through the long migration. Nodes may be IPv4-only, IPv6-only or both, and the transition mechanisms let any two communicate:
| Situation | Mechanism |
|---|---|
| a node must talk to both IPv4 and IPv6 hosts | dual stack |
| two IPv6 hosts or networks separated by an IPv4-only network | tunneling: IPv6 inside IPv4 (configured, 6to4, ISATAP, 6RD, Teredo) |
| an IPv6-only host must reach an IPv4-only host | header translation (SIIT, NAT64 with DNS64) |
| IPv4 customers on an IPv6-only provider network | IPv4 tunnelled or translated over IPv6 (DS-Lite, 464XLAT, MAP) |
To picture the three: an English letter must cross a district whose post office reads only Nepali. A clerk who reads both is dual stack; sealing the letter in a Nepali-addressed envelope, opened on the far side, is tunneling; an interpreter rewriting the letter in Nepali is translation, and some meaning can be lost.
1. Dual stack (RFC 4213). Every node runs both stacks: one application layer and one TCP/UDP layer over two network layers, IPv4 and IPv6, on the same link. Each interface holds an IPv4 address and an IPv6 address; each router keeps two routing tables and runs both sets of routing protocols (OSPFv2 and OSPFv3, say).
- Choosing the version: the source asks DNS (DNS) for the name's A (IPv4) and AAAA (IPv6) records. An AAAA record means IPv6, which the default address selection rules prefer (RFC 6724); only an A record means IPv4.
- Happy Eyeballs (RFC 8305): if the IPv6 connection has not answered within a short delay (250 milliseconds is the recommended default), the host tries IPv4 as well and keeps whichever connects first, so a broken IPv6 path costs the user almost nothing.
- For it: the simplest method; native speed for both protocols; nothing encapsulated or translated; each service moves to IPv6 when ready. The IETF's guidance (RFC 6180) recommends it wherever it is possible.
- Against it: every node still needs an IPv4 address, so it does nothing about exhaustion; and two stacks mean two sets of addresses, firewall rules and routing tables to manage, secure and troubleshoot.
Example: a laptop on the college Wi-Fi gets 192.168.1.20 from DHCP and
2001:db8:acad:1::20 by SLAAC. A site with an AAAA record is fetched over IPv6, an
older site with only an A record over IPv4 through the college's NAT, and the user never sees
the difference.
2. Tunneling. When two IPv6 nodes or networks are separated by an IPv4-only region, the IPv6 packet travels as the payload of an IPv4 packet:
- Encapsulate: the dual-stack router at the tunnel entry puts the whole IPv6 packet behind an IPv4 header whose protocol field is 41 (IPv6) and whose destination is the tunnel exit.
- Carry: the IPv4 routers forward it like any IPv4 packet, never looking inside.
- Decapsulate: the exit router strips the IPv4 header and sends the original IPv6 packet on. To IPv6 the whole IPv4 region looks like one hop: the packet enters a tunnel at one end and emerges at the other.
Costs: 20 bytes of extra header, so a smaller MTU; harder troubleshooting, since a traceroute sees the tunnel as one hop; and security risk, since tunnelled traffic slips past a firewall that does not look inside protocol 41. Tunnels are configured or automatic:
| Tunnel | Connects | Far end found from | Address | Status |
|---|---|---|---|---|
| Configured (manual), RFC 4213 | two routers, or a host and a tunnel broker | set by hand at both ends | any | common for router links |
| 6to4, RFC 3056 | IPv6 sites across the IPv4 Internet | the IPv4 address inside the destination's 6to4 prefix | 2002:WWXX:YYZZ::/48 | public relays deprecated in 2015 (RFC 7526) |
| ISATAP, RFC 5214 | dual-stack hosts inside one IPv4 site | the IPv4 address in the interface ID | prefix + 0:5efe:a.b.c.d | little used now |
| 6RD, RFC 5969 | an ISP's customers over its IPv4 network | the IPv4 bits inside the ISP's 6rd prefix | ISP prefix + IPv4 bits | ISP deployments |
| Teredo, RFC 4380 | hosts behind IPv4 NAT | Teredo servers and relays, over UDP port 3544 | 2001::/32 | a last resort, little used now |
6to4 in detail. A site whose router has a public IPv4 address takes the 48-bit prefix
made of 2002 and that address in hexadecimal; 16 bits of subnet ID and the 64-bit
interface IDs follow. Router 192.0.2.4 (c0, 00, 02, 04) gives the site
2002:c000:204::/48.
- Between 6to4 sites: the sending router copies bits 17 to 48 of the destination address, the far router's IPv4 address, and tunnels straight to it. The address is the configuration.
- To the native IPv6 Internet: packets go through a 6to4 relay router, once reached at
the anycast address
192.88.99.1. - Its weakness: it needs a public IPv4 address, so it fails behind NAT, and the public relays belonged to no one in particular, so paths were slow, one-sided or broken. RFC 7526 deprecated the anycast relay prefix in 2015.
ISATAP in detail (Intra-Site Automatic Tunnel Addressing Protocol). It gives dual-stack hosts inside an organization IPv6 while the internal network routes only IPv4, by treating that IPv4 network as one big link for IPv6.
- Address format: a 64-bit prefix, then the interface ID
0000:5efeand the host's 32-bit IPv4 address;0200:5efewhen that IPv4 address is globally unique (the universal/local bit). Host10.1.1.5gets the link-local addressfe80::5efe:a01:105, also writtenfe80::5efe:10.1.1.5. - Finding the router: the host learns the ISATAP router's IPv4 address (Windows looked
up the DNS name
isatap), sends it a router solicitation inside IPv4, and gets back the site's prefix, say2001:db8:acad:5::/64; its global address is then2001:db8:acad:5:0:5efe:a01:105. - Forwarding: to another ISATAP host in the site, it tunnels straight to the IPv4 address in the destination's last 32 bits; to anywhere else, through the ISATAP router.
6RD in detail (IPv6 rapid deployment) is 6to4 rebuilt inside one ISP. The French ISP Free first used it, in 2007, to give its subscribers IPv6 over its existing IPv4 network; RFC 5569 (2010) describes that deployment and RFC 5969 (2010) made it a standard.
- Importance: an ISP with an IPv4-only access network can offer IPv6 without upgrading that network first; the prefix and the relays are the ISP's own, unlike 6to4's, so the service is as reliable as the ISP; it is stateless, so it scales to millions of customers; and each customer gets a stable delegated prefix.
- Parts: the customer edge (CE) router in each home, and the ISP's border relay (BR) routers between its IPv4 network and the IPv6 Internet.
- Configuration: each CE learns four values, usually through DHCPv4 option 212: the 6rd prefix, its length, how many leading IPv4 bits all the ISP's customers share (and can be left out), and the BR's IPv4 address.
- The delegated prefix: the 6rd prefix followed by the CE's remaining IPv4 bits:
2001:db8::/32, no shared bits and the CE address203.0.113.5(cb00:7105) give2001:db8:cb00:7105::/64. - Leaving out shared bits: if every customer's address lay in
198.51.100.0/24, the ISP could drop those 24 bits and, from2001:db8:ab00::/40, give the CE198.51.100.7a whole /48,2001:db8:ab07::/48. - Forwarding: the CE wraps IPv6 in IPv4 (protocol 41) to the BR, or straight to another CE of the same ISP; the BR unwraps it and forwards it natively, and for the replies reads the CE's IPv4 address back out of the destination prefix.
Teredo, briefly (RFC 4380): for a host behind an IPv4 NAT, which protocol 41 cannot
cross, IPv6 rides inside UDP (port 3544) inside IPv4. The address, in 2001::/32,
holds the Teredo server's IPv4 address and, obscured, the client's public port and IPv4
address. It was a last resort and is little used now.
3. Header translation, also called address family translation. When one end understands only IPv6 and the other only IPv4, neither dual stack nor a tunnel helps. A translator between the two networks rewrites each packet's header in the other version and maps the addresses between the two address families.
Which way round: the book's case is a mostly IPv6 Internet with some hosts still on IPv4. Today the usual case is the reverse: an IPv6-only network, a mobile operator's say, reaching servers that still have only IPv4.
The translation procedure for IPv6 to IPv4, by the SIIT rules (RFC 7915):
- Addresses: the IPv4 destination is taken from the low 32 bits of the IPv6 destination
(an IPv4-mapped address, or the NAT64 form
64:ff9b::c000:221, which gives192.0.2.33); the IPv6 source becomes an IPv4 address, fixed by a mapping or, in NAT64, a shared address and port from the translator's pool. - Version 6 becomes 4, with a 20-byte header (header length 5, no options).
- Traffic class is copied into type of service (or replaced by a configured value).
- Flow label is dropped: IPv4 has no such field.
- Payload length plus 20 becomes total length.
- Next header becomes protocol (ICMPv6, 58, becomes ICMP, 1); hop-by-hop, routing and destination options headers are dropped, and a fragment header becomes IPv4's identification, flags and fragment offset.
- Hop limit becomes time to live, lowered by one, since the translator is a router.
- Header checksum is computed and inserted; TCP and UDP checksums are adjusted for the new addresses, and ICMPv6 messages are rewritten as ICMP ones.
Replies go through the same steps in reverse, IPv4 to IPv6. The translators in use:
| Translator | How it works | Status |
|---|---|---|
| SIIT (stateless IP/ICMP translation), RFC 7915 | rewrites each packet on its own, with a fixed one-to-one mapping between IPv4 and IPv6 addresses | current; the base of the others |
| NAT-PT, RFC 2766 (2000) | stateful translation with a DNS gateway built in | moved to Historic in 2007 (RFC 4966): fragile DNS handling, broken applications |
| NAT64, RFC 6146 (2011) | stateful: many IPv6 clients share the translator's IPv4 addresses, told apart by port, as NAT does in IPv4 | current, with DNS64 |
| DNS64, RFC 6147 | for a name with only an A record, answers with a made-up AAAA record: 192.0.2.33 becomes 64:ff9b::c000:221 | current |
| 464XLAT, RFC 6877 (2013) | a stateless translator on the device (CLAT) turns an IPv4 app's packets into IPv6; NAT64 in the network (PLAT) turns them back into IPv4 | current on IPv6-only mobile networks |
The limits of translation: applications that carry addresses inside their data (FTP, SIP) break unless a helper (an ALG) rewrites them; end-to-end IPsec fails, since the headers change; what IPv4 has no field for (the flow label, extension headers) is lost; and a stateful translator must hold every flow's state.
The latest methods. Since the IPv4 free pools ran out, providers have moved to IPv6-only networks that carry IPv4 as a service:
- NAT64 with DNS64, and 464XLAT: on mobile networks.
- DS-Lite (dual-stack lite, RFC 6333): the home router tunnels IPv4 inside IPv6 to the ISP's carrier-grade NAT, the AFTR.
- MAP-E and MAP-T (RFC 7597, RFC 7599): IPv4 addresses shared statelessly, each customer given a range of ports.
- Compared: RFC 9313 (2022) weighs five of them against each other: 464XLAT, DS-Lite, lightweight 4over6, MAP-E and MAP-T.
Which method to choose:
| Situation | Choose | Why |
|---|---|---|
| hosts, routers and the ISP can run both, and IPv4 addresses are still to hand | dual stack | native, simplest, nothing translated; the IETF's first choice (RFC 6180) |
| IPv6 islands separated by an IPv4-only network | a tunnel: configured between routers, or 6RD from the ISP | reuses the IPv4 network until it is upgraded |
| an IPv6-only network that must reach IPv4-only content | NAT64 with DNS64; 464XLAT on phones | no IPv4 addresses needed inside |
| an ISP short of IPv4 addresses | DS-Lite, MAP, 464XLAT | IPv4 as a service over IPv6-only access |
For a campus or a company network, dual stack is the suggestion, with a tunnel only as a stop-gap and translation where part of the network goes IPv6-only: both protocols stay native, each service moves when ready, and nothing is translated or relayed.
- List the IPv6 extension headers in order. Explain ISATAP and 6 to 4 tunneling with their address format for IPv4 to IPv6 transition. 2082 Bhadra Q8 · 2+6
- Map IPv4 addresses with its IPv6 equivalent. What are the latest best IPv6 transition methodologies? Explain anyone of them. 2082 Baishakh Q8 · 2+2+4
- Critically compare IPv4 and IPv6 in terms of routing and head manipulation. Explain the importance and implementation approach of 6RD for IPv6 based services on the existing IPv4 networking. 2081 Bhadra Q8 · 4+4
- Compare the IPv4 header with IPv6 header. Explain the dual stack strategy to transit from IPv4 to IPv6. 2081 Baishakh Q8 · 4+4
- Write short notes on: (Any Two) a) Go Back-N ARQ b) Dual Stack method in IPv6 c) Diffie-Hellman algorithm d) ATM 2080 Bhadra Q10 · 2×4
- What are the advantages of IPv6? Briefly explain the different transition strategies. 2080 Baishakh Q8 · 2+6
- What are the problems of IPV4? How can IPV6 reduce these problems? Explain header translation mechanism for transition from IPV4 to IPV6. 2079 Bhadra Q8 · 2+2+4
- List advantages of IPv6 over IPv4. Explain any two suitable transition strategies for IPv4 to IPv6. 2078 Bhadra Q8 · 2+6
- "IPv4 and IPv6 coexistence" what does this mean? Explain Dual stack approach with an appropriate figure. 2076 Chaitra Q8 · 3+5
- List the advantages of IPv6 over IPv4. Explain any two transition strategies for IPv4 to IPv6. 2076 Ashwin Q8 · 2+6
- “IPv4 and IPv6 coexistence” what does this mean? Explain what you mean by address family translation in IPv4/IPv6 migration process with an appropriate figure. 2075 Chaitra Q8 · 3+5
- What are the methods used to interoperate IPv6 and IPv4. Show IPv6 datagram format. 2075 Ashwin Q8 · 6+2
- What are the factors that lead to the speedy development of IPv6? Define the process of transition from IPv4 to IPv6. 2074 Chaitra Q8 · 4+4
- List the advantages of IPv6 over IPv4. Explain header translation and tunneling approach used for migrating IPv4 to IPv6. 2074 Ashwin Q8 · 4+4
- What are the factors that lead to the development of IPv6? Define the process of transition from IPv4 to IPv6. 2073 Shrawan Q7 · 4+4
- Compare the header fields of IPV6 and IPV4. Which method do you suggest for the migration of IPv6 and why? 2072 Chaitra Q7 · 4+4
- What is IPV6? What methods are used so that IPV6 and IPV4 networks are interoperable? 2072 Kartik Q8 · 2+6
- What are the problems of IPv4? How IPv6 reduce these problems? Explain different strategies to transit from IPv4 and IPv6. 2071 Chaitra Q8 · 2+2+4
7.7Last minute recall
Chapter 7 in one screen
- Why IPv6: 128-bit addresses (), IPv4 pools empty from 2011, no NAT, fixed header, IPsec headers, flow label, SLAAC, scoped multicast, mobility.
- Header, 40 bytes: version 4, traffic class 8, flow label 20, payload length 16, next header 8, hop limit 8, source 128, destination 128 (bits).
- Against IPv4: removed IHL, identification, flags, fragment offset, checksum, options; renamed TOS, total length, TTL, protocol; added flow label.
- Extension order: hop-by-hop 0, destination options 60, routing 43, fragment 44, AH 51, ESP 50, destination options 60, upper layer (TCP 6, UDP 17, ICMPv6 58).
- Addresses: eight groups of four hex digits; drop leading zeros;
::once; global2000::/3, link-localfe80::/10, unique localfc00::/7, multicastff00::/8, anycast from unicast; IPv4-mapped::ffff:a.b.c.d. - SLAAC: link-local, DAD, RS 133, RA 134, prefix plus interface ID (EUI-64 or random), DHCPv6 if M or O.
- Multicast: ff, flags, scope, group ID; solicited-node
ff02::1:ffplus the last 24 bits; MLD. - Transition: dual stack (DNS decides); tunnels with protocol 41 (configured, 6to4
2002::/16, ISATAP::0:5efe:a.b.c.d, 6RD, Teredo); translation (SIIT, NAT64 with DNS64, 464XLAT); choose dual stack first.
Chapter 8 · 7 hours · about 11 marks a paper · in 26 of the 27 sittings
Network security
How two parties talk safely across a network that anyone can tap: the properties secure communication needs, the cryptography that provides them (symmetric ciphers, RSA, Diffie-Hellman, digital signatures), the protocols that apply it at each layer (PGP for e-mail, SSL and TLS for TCP, IPsec and VPNs for IP, WEP and WPA2 for Wi-Fi), and the firewalls and intrusion detection systems that guard the boundary. It fills Q9 and Q10 of almost every paper: an RSA calculation on a word, a firewall question and a pair of short notes.
- The goal: confidentiality, integrity, authentication, non-repudiation, availability and access control for messages that cross an insecure network.
- The tools: symmetric ciphers (DES, AES), public key cryptography (RSA, Diffie-Hellman), hash functions and digital signatures.
- Security at each layer: PGP secures an e-mail, SSL and TLS a TCP connection, IPsec and VPNs the IP packet, WEP and WPA2 the wireless link.
- Guarding the boundary: firewalls (packet filters and router ACLs, stateful inspection, application gateways) and intrusion detection systems.
- Every layer of the model (the OSI model) gets its own protection here: TLS sits between TCP (TCP) and HTTP (HTTP and HTTPS), IPsec's AH and ESP double as IPv6 extension headers (extension headers), and WEP protects the 802.11 frame (wireless LAN).
- PGP rides on the mail system (SMTP, POP3 and IMAP); router ACLs run on the routers of chapter 4 (internetworking devices) and name its address blocks (subnetting).
- Checksums and CRC (CRC) catch accidental errors only; the hashes, MACs and signatures here catch deliberate changes, and WEP's CRC-32 shows what goes wrong when one is used for the other.
- 8.1 Network security and the properties of secure communication
- 8.2 Cryptography: symmetric key and public key, classical ciphers, DES and AES
- 8.3 The RSA algorithm and Diffie-Hellman key exchange
- 8.4 Digital signatures
- 8.5 Securing e-mail: PGP
- 8.6 Securing TCP connections: SSL and TLS
- 8.7 Network layer security: IPsec and VPNs
- 8.8 Securing wireless LANs: WEP, WPA and WPA2
- 8.9 Firewalls and router ACLs and intrusion detection systems
- 8.10 Last minute recall, chapter 8
- RSA on a word is the chapter's banker: 15 of the 27 sittings set it, usually for 6 marks after a short theory part. The words are worked in the Numericals panel; the method is on the RSA card.
- Firewalls come next, in 13 sittings: what a firewall is, its types with figures, how a packet filter works, and lately a router ACL.
- The properties of secure communication (11 sittings) and symmetric against public key cryptography (8) are the usual 2 to 4-mark openers.
- Short notes in Q10 rotate through digital signatures, VPN, IPsec, AH and ESP, SSL, WEP, IDS, PGP and Diffie-Hellman; only 2070 Ashad of the 27 sittings set nothing from this chapter.
8.1Properties of secure communication
Network security and the properties of secure communication TOP 11/27
80 Bh · 76 Ch · 76 Ash · 75 Ch · 74 Ash · 71 Ch · 70 Ch · 69 Ch · 68 Ch · 67 Asa · 66 Po2+64+43+5
The setting is always the same three parties. A sender (Alice) and a receiver (Bob) exchange messages over a medium they do not control, the Internet or a radio link, on which an intruder (Trudy) may intercept, read, change, delete or inject messages. Network security is everything that lets Alice and Bob trust the conversation anyway; the book puts its basic objective as communicating securely over an insecure medium.
What the intruder can do falls into four classic attacks, each breaking one property:
- Interruption: the message is destroyed or blocked (a cut cable, a jammed radio, a flooded server): an attack on availability.
- Interception: an unauthorised party reads the message (sniffing an open Wi-Fi): an attack on confidentiality.
- Modification: the message is changed in transit: an attack on integrity.
- Fabrication: a false message is inserted as if from a genuine sender: an attack on authenticity.
Passive and active attacks. Interception and traffic analysis are passive: nothing changes, so they are hard to detect and are defeated by prevention, which means encryption. Interruption, modification, fabrication, replay (re-sending a captured valid message, such as a login) and denial of service are active: they alter the stream, so the aim is to detect them and recover.
The properties of secure communication are what Alice and Bob need in return. Six are named, and each is provided by a tool from later in this chapter:
| Property | What it means | Attack it answers | Provided by |
|---|---|---|---|
| Confidentiality | only the sender and the intended receiver can understand the content | interception, eavesdropping | encryption (AES, TLS, WPA2) |
| Integrity | the content arrives exactly as sent, not altered by accident or on purpose | modification | hash with a MAC, digital signature |
| Authentication | each end can confirm that the other is who it claims to be, and that a message came from its claimed sender | fabrication, masquerade | passwords, certificates, signatures |
| Non-repudiation | the sender cannot later deny having sent a message (nor the receiver deny receiving it) | repudiation | digital signature |
| Availability | the network and its services are usable by authorised users when needed | interruption, denial of service | redundancy, filtering, backups |
| Access control | only authorised users reach a resource, and only with the rights they hold | unauthorised access | firewalls, ACLs, permissions |
The CIA triad (confidentiality, integrity, availability) is the core of the list, the three every security text starts from; authentication, non-repudiation and access control complete it for two parties who communicate.
To remember them as one story, think of a cheque paid into a bank:
- Confidentiality: nobody else reads the account number.
- Integrity: the amount does not grow from Rs 500 to Rs 5,000 on the way.
- Authentication: the bank checks that the signature is the account holder's.
- Non-repudiation: the writer cannot later claim never to have written it.
- Availability: the bank is open when the customer arrives.
- Access control: only the cashier may open the cash drawer.
How security is maintained in a network. No single device gives all six properties, so a network is protected in layers, defense in depth: if one control fails, the next still stands. The usual procedures, in the order an administrator puts them in place:
- Policy and risk assessment: list the assets (servers, data, links), the threats to them and the rules: who may use what, and how.
- Access control: individual accounts, strong passwords or multi-factor login, least privilege, accounts removed when people leave.
- Encryption: TLS for web and mail, a VPN for remote and branch links, WPA2 or WPA3 on Wi-Fi, encrypted disks and backups.
- Perimeter control: a firewall and router ACLs at every boundary, public servers in a DMZ.
- Segmentation: VLANs that keep the hostel, office and server networks apart, and a separate guest Wi-Fi.
- Hardening and patching: updates for routers, servers and PCs; unused services and ports switched off; default passwords changed.
- Malware protection: antivirus or endpoint protection, and filtering of e-mail attachments and links.
- Monitoring: an IDS or IPS, logs collected and reviewed, alerts acted on.
- Availability measures: backups kept offline, redundant links and power, protection against flooding.
- Physical security and people: locked racks and wiring closets, users trained to spot phishing, and an incident response plan for the day something still goes wrong.
The hostel Wi-Fi runs WPA2 with a separate password for each block and a guest network apart; the router's ACL drops Telnet and remote-desktop traffic from outside; the warden's office PCs sit on their own VLAN; the router firmware is updated each semester; the rack is in a locked room; and a notice reminds students never to share the result-portal password. Each line answers one of the six properties.
- What are the properties of secure communication? Use RSA algorithm to encrypt and decrypt the message "network". 2080 Bhadra Q9 · 2+6
- Explain briefly the desirable properties of secure communication. Explain how packet filtering firewall works. 2076 Chaitra Q10 · 4+4
- List the properties of secure communication. Encrypt and decrypt “ROSE” using RSA algorithm. 2076 Ashwin Q9 · 2+6
- Explain briefly the desirable properties of secure communication. Explain how Packet filtering firewall Works. 2075 Chaitra Q9 · 4+4
- Explain briefly the desirable properties of secure communication. Explain how Packet filtering firewall Works. 2074 Ashwin Q9 · 4+4
- What is network security? Explain Virtual Private Network (VPN) with an example. 2071 Chaitra Q4 · 2+4
- What do you mean by Network security? Explain the operation of Data Encryption Standard Algorithm? 2070 Chaitra Q10 · 3+5
- What is network security? How can firewalls enhance network security? Explain how firewalls can protect a system. 2069 Chaitra Q10 · 2+2+4
- Write short notes on: a) Network Security b) Router and Gateway 2068 Chaitra Q9 · 2×5
- How the protocol SMTP does operate? Explain the procedures to make your network secured. 2067 Ashad Q10 · 3+5
- How can we maintain the security within the communication network? Explain any one cryptography algorithm with example. 2066 Poush Q9 · 2+6
8.2Principles of cryptography
Cryptography: symmetric key and public key HOT 8/27
81 Ba · 75 Ch · 74 Ch · 73 Shr · 71 Ch · 71 Shr · 69 Ch · 66 Po2+64+41+7
The vocabulary every answer uses:
- Plaintext (P): the original, readable message.
- Ciphertext (C): the scrambled message that travels: , and decryption gives back .
- Cipher: the encryption and decryption algorithms together.
- Key (K): the secret value the algorithm works with; the same algorithm with another key gives another ciphertext.
- Cryptanalysis: breaking a cipher without the key; cryptology covers both the making and the breaking.
Kerckhoffs's principle: the algorithm is public, only the key is secret. DES, AES and RSA are published standards that anyone may study; their security comes from the size of the key space, so large that trying every key (brute force) takes too long.
Symmetric key (secret key, conventional) cryptography. The sender and the receiver share one secret key, used both to encrypt and to decrypt. It is fast enough for bulk data: disk encryption, TLS records, VPN tunnels and Wi-Fi all run on it.
Its weakness is key distribution: the key must reach the other side secretly before the first message, and every pair of users needs its own key, so users need keys (100 users: 4,950 keys). It comes in two kinds:
- Block ciphers encrypt a fixed block at a time: DES (64-bit blocks), 3DES, AES (128-bit blocks), IDEA, Blowfish.
- Stream ciphers XOR the data with a keystream, bit by bit or byte by byte: RC4 (used in WEP), ChaCha20.
Public key (asymmetric) cryptography. Each user has a key pair: a public key, published to everyone, and a private key that never leaves its owner; what one key encrypts, only the other decrypts. Whitfield Diffie and Martin Hellman published the idea in 1976.
- For secrecy: to send a secret to B, A encrypts with B's public key, and only B's private key can decrypt it.
- For signing: B encrypts a digest with its private key, and anyone checks it with B's public key (digital signatures).
- Gain and cost: it solves key distribution, as nothing secret is shared and users need only keys, but it is slow, computing with numbers hundreds of digits long.
- Examples: RSA, Diffie-Hellman, ElGamal, elliptic curve cryptography (ECC) and DSA.
To remember the difference, think of padlocks. Symmetric key is one lock with two identical keys: you keep one and must somehow get the other to a friend in Dharan without anyone copying it on the way. Public key is a pile of open padlocks handed out to anyone: a stranger can snap one shut on a box addressed to you, but only your one key opens it.
| Point | Symmetric key | Public key (asymmetric) |
|---|---|---|
| Keys | one shared secret key | a pair: a public key and a private key |
| Who holds them | both parties, kept secret | public key: anyone; private key: its owner only |
| Encrypt, decrypt | the same key | one key of the pair encrypts, the other decrypts |
| Speed | fast; suits long messages and bulk data | slow; suits short data such as keys and digests |
| Key distribution | the hard part: the key must be shared secretly first | easy: publish the public key (a certificate vouches for it) |
| Keys for users | ||
| Key length for equal strength | 128 bits (AES-128) | 3072 bits (RSA-3072), by NIST SP 800-57 |
| Services | confidentiality | confidentiality, authentication, non-repudiation, key exchange |
| Examples | DES, 3DES, AES, IDEA, RC4 | RSA, Diffie-Hellman, ElGamal, ECC, DSA |
Hybrid use, the best of both. Real protocols use public key cryptography only to agree on or protect a fresh random session key, then encrypt the data with a fast symmetric cipher under that key: PGP, TLS and IPsec all work this way.
The types of encryption used in security, as one paper asks it: symmetric key and asymmetric (public key) encryption are the two types. Beside them sits the hash function (MD5, SHA-1, SHA-256), a keyless, one-way transformation of any message into a fixed-length digest; it cannot be decrypted, so it gives integrity rather than secrecy. The oldest ciphers, substitution and transposition, are on the next card (classical ciphers).
- What is public key cryptography? Encrypt the word "security" using the RSA algorithm. Also show the decryption to obtain the plaintext. 2081 Baishakh Q9 · 1+7
- Write short notes on: (Any two) a) Digital Signature b) VPN c) Symmetric key cryptography 2075 Chaitra Q10 · 4+4
- Define type of Encryption used in security. How PGP can secure email communication? 2074 Chaitra Q9 · 5+3
- Compare symmetric key encryption method with asymmetric key encryption. Explain RSA algorithm with example. 2073 Shrawan Q8 · 3+5
- What is public key cryptography? Explain about RSA algorithm in detail. 2071 Chaitra Q9 · 2+6
- What is cryptography? Differentiate between symmetric key and public key cryptography. 2071 Shrawan Q9 · 2+6
- Compare symmetric key encryption method with asymmetric key encryption. Describe the operation of RSA algorithm. 2069 Chaitra Q9 · 4+4
- How can we maintain the security within the communication network? Explain any one cryptography algorithm with example. 2066 Poush Q9 · 2+6
Classical ciphers: substitution and transposition
Why they still matter: every modern symmetric cipher is built from these two operations, repeated many times under a key. DES's S-boxes substitute and its P-boxes transpose; AES's SubBytes substitutes and its ShiftRows transposes (DES and AES).
Caesar cipher (shift cipher): each letter moves places along the alphabet, wrapping round from z to a.
i am a student becomes k co c uvwfgpv: i to k, a to c, m to o, s
to u, t to v, u to w, d to f, e to g, n to p. With only 25 useful keys, an attacker simply
tries them all.
Monoalphabetic cipher: any rearrangement of the alphabet is the key, so there are keys and brute force is hopeless. It still falls to frequency analysis: e, t and a are the commonest English letters, and the commonest ciphertext letters give them away. With Kurose and Ross's key:
plaintext: abcdefghijklmnopqrstuvwxyz ciphertext: mnbvcxzasdfghjklpoiuytrewq attack becomes muumbf
Polyalphabetic cipher: several substitutions used in turn, so the same plaintext letter can become different ciphertext letters and the frequencies blur. The Vigenère cipher is the classic one: a key word gives the shifts.
The book's example uses two Caesar ciphers, C1 with and C2 with
, in the repeating pattern C1, C2, C1: i am a student becomes
k fo c xvwigpy, its two a's turning into f and c.
Transposition (columnar) cipher: write the message in rows under a numbered key, then read the columns off in the order of the key. The letters are untouched; only their positions change.
key: 3 1 4 2
M E E T
A T R A
T N A P
A R K X (X pads the last row)
read the column under 1, then 2, 3 and 4:
ETNR TAPX MATA ERAK gives ETNRTAPXMATAERAK
The receiver, knowing the key, writes the four groups back into their columns and reads the rows: MEET AT RATNAPARK.
| Point | Substitution | Transposition |
|---|---|---|
| Changes | the letters | the order of the letters |
| Letter frequencies | hidden only by polyalphabetic forms | unchanged: the same letters appear |
| Examples | Caesar, monoalphabetic, Vigenère | columnar, rail fence |
| In modern ciphers | S-boxes, SubBytes | P-boxes, ShiftRows |
To remember it: a note passed in class with every letter written two places on is a Caesar cipher; the same note written in a grid and read down the columns is a transposition. Both fool a casual reader and neither survives a determined one, which is why modern ciphers repeat both, ten or sixteen times over, under a long key.
k co c uvwfgpv. Its monoalphabetic key repeats the letter
i (the sixteenth letter should be l, as in Kurose and Ross), and its answer QZZQEA for "attack"
comes from another key, the keyboard order qwerty..., in which a becomes q, t becomes z, c
becomes e and k becomes a. With the printed key, "attack" is muumbf.DES and AES: the symmetric block ciphers PIN 4/27
82 Ba · 81 Bh · 70 Ch · 66 Bh2+63+33+5
A block cipher takes a fixed-size block of plaintext and a key, and gives a ciphertext block of the same size. It is built from three parts repeated in rounds: P-boxes that permute (transpose) bits, S-boxes that substitute groups of bits non-linearly, and an XOR with a round key drawn from the main key.
Shannon's two goals guide the design: confusion (each ciphertext bit depends on the key in a complicated way) and diffusion (each plaintext bit affects many ciphertext bits).
DES in numbers: designed at IBM from its Lucifer cipher and adopted by the US National Bureau of Standards (now NIST) in 1977. It takes a 64-bit plaintext block and a 64-bit key, of which 8 bits are parity bits, leaving a 56-bit effective key; it runs 16 rounds, each with its own 48-bit round key, and gives a 64-bit ciphertext block. The same algorithm decrypts.
The operation of DES, step by step:
- Initial permutation (IP): the 64 input bits are rearranged by a fixed table (bit 58 moves to position 1, bit 50 to position 2, and so on).
- Split: the result is cut into a left half and a right half of 32 bits each.
- Sixteen Feistel rounds: in round , and : the right half passes to the left unchanged, and the left half is XORed with a function of the right half and the round key.
- 32-bit swap: after round 16 the two halves are exchanged.
- Final permutation (): the inverse of the initial permutation gives the 64-bit ciphertext.
The round function f takes the 32-bit right half and the 48-bit round key:
- Expansion E: 32 bits become 48 by repeating 16 of them, to match the key.
- XOR with the 48-bit round key .
- Eight S-boxes: the 48 bits are cut into eight 6-bit groups, and each S-box turns 6 bits into 4: the outer two bits pick one of 4 rows, the inner four one of 16 columns. 48 bits become 32. The S-boxes are the only non-linear step and the heart of DES's security.
- Permutation P: a straight permutation of the 32 bits.
The 6-bit input 011011 enters S-box S1. Its outer bits, 0 and 1, give row
01 = 1; its inner bits 1101 give column 13. Row 1 of S1 reads 0 15 7
4 14 2 13 1 10 6 12 11 9 5 3 8, and its entry in column 13 (counting from 0) is 5, so the
output is 0101.
The key schedule makes the 16 round keys: permuted choice 1 (PC-1) drops the 8 parity bits and permutes the other 56; they are split into two 28-bit halves, each rotated left by 1 bit (in rounds 1, 2, 9 and 16) or 2 bits (in the others), and permuted choice 2 (PC-2) picks 48 of the 56 bits as .
Decryption runs the same steps with the round keys in reverse, first. A
Feistel structure never needs the inverse of f, which is why one circuit serves both directions.
A standard test: the key 133457799BBCDFF1 encrypts 0123456789ABCDEF
to 85E813540F0AB405.
Why DES was retired: a 56-bit key allows only keys, and in 1998 the Electronic Frontier Foundation's purpose-built DES Cracker found a key by brute force in under three days. Triple DES (3DES) encrypts, decrypts and encrypts again with two or three keys (112 or 168 bits): strong, but a third the speed, and now being retired in favour of AES too.
AES was chosen by NIST in an open competition, 1997 to 2000, from fifteen candidates. The winner, Rijndael, by the Belgian cryptographers Joan Daemen and Vincent Rijmen, became FIPS 197 in 2001. It is the cipher behind WPA2 Wi-Fi, TLS, VPNs and disk encryption today.
- Block: 128 bits, held as a 4 x 4 state of 16 bytes, filled column by column.
- Key and rounds: a 128-bit key takes 10 rounds, a 192-bit key 12, a 256-bit key 14.
- Structure: a substitution-permutation network, not a Feistel cipher: every round changes all 16 bytes.
One AES round has four steps:
- SubBytes: every byte is replaced through a fixed 16 x 16 S-box (the multiplicative
inverse in followed by an affine map); for example
00becomes63and53becomesED. This is the non-linear step. - ShiftRows: row 0 stays, row 1 rotates one byte left, row 2 two bytes, row 3 three bytes.
- MixColumns: each column is multiplied by a fixed matrix over , so every output byte depends on all four bytes of its column.
- AddRoundKey: the state is XORed with the 128-bit round key.
The whole cipher: an initial AddRoundKey with , then rounds 1 to 9 with all four steps, then round 10 without MixColumns. Key expansion turns the 128-bit key into 44 words of 32 bits, the 11 round keys to . Decryption applies the inverse steps (InvShiftRows, InvSubBytes, AddRoundKey, InvMixColumns) with the round keys in reverse order.
- Bytes: the word becomes its ASCII codes;
NEPALis4E 45 50 41 4C, padded to 16 bytes (PKCS#7 padding adds 11 bytes, each of value0B). - State: the bytes fill the 4 x 4 grid column by column, so
4E,45,50and41make column 0. - Initial AddRoundKey: with the key of the standard's example,
2B 7E 15 16 ..., the first byte becomes4EXOR2B=65. - SubBytes then turns
65into4D, and the round goes on with ShiftRows and MixColumns.
The standard's own test (FIPS 197, Appendix B): the plaintext 32 43 F6 A8 88
5A 30 8D 31 31 98 A2 E0 37 07 34 under that key gives the ciphertext 39 25 84 1D
02 DC 09 FB DC 11 85 97 19 6A 0B 32.
| Point | DES | AES |
|---|---|---|
| Standard | FIPS 46, 1977 | FIPS 197, 2001 |
| Designer | IBM (from Lucifer) | Daemen and Rijmen (Rijndael) |
| Block size | 64 bits | 128 bits |
| Key size | 56 bits (64 with parity) | 128, 192 or 256 bits |
| Rounds | 16 | 10, 12 or 14 |
| Structure | Feistel network: half the block changes per round | substitution-permutation network: the whole block changes per round |
| Round steps | expansion, XOR with the key, 8 S-boxes, permutation | SubBytes, ShiftRows, MixColumns, AddRoundKey |
| Decryption | the same steps, round keys reversed | the inverse steps, in reverse order |
| Security today | broken by brute force ( keys) | no practical attack; the current standard |
| Speed | slow in software (bit-level permutations) | fast, with instructions for it built into most processors |
By hand in the hall: ten AES rounds with key expansion do not fit the time, so "encrypt the word using any suitable AES technique" is answered with the structure above and the first round worked on the state, or with simplified AES (S-AES), a teaching version with a 16-bit block, a 16-bit key and two rounds. The Numericals panel works both papers' words.
To remember it: the phone that joins the hostel Wi-Fi encrypts every frame with AES-128 under WPA2; DES survives mostly in old systems and in exam questions.
- What is router ACL? How do you apply ACL to block the IP network 202.70.91.0/24 incoming to interface Fast Ethernet of a router? Encrypt the word “ISPNet” using anyone suitable AES technique. 2082 Baishakh Q9 · 2+6
- What are the fundamental difference between AES and DES? Encrypt the word “ComNet” using anyone suitable AES technique. 2081 Bhadra Q9 · 2+6
- What do you mean by Network security? Explain the operation of Data Encryption Standard Algorithm? 2070 Chaitra Q10 · 3+5
- Write short notes on (any two) i) TCP Sliding Window Protocol ii) Secrete Key Algorithm: DES iii) ISDN Signaling and ATM AAL iv) ICMP Message Types 2066 Bhadra Q5b · 3+3
8.3The RSA algorithm, and Diffie-Hellman
RSA: the public key algorithm, step by step TOP 16/27
82 Bh · 81 Ba · 80 Bh · 80 Ba · 79 Bh · 78 Bh · 76 Ch · 76 Ash · 75 Ash · 73 Shr · 72 Ch · 72 Ka · 71 Ch · 69 Ch · 68 Ba · 66 Po2+61+73+5
The idea in one line: multiplying two primes is easy, but given only their product, finding the primes again is practically impossible when the product is hundreds of digits long. RSA hides the private key behind exactly that problem.
The steps of the RSA algorithm. Key generation is done once, by the receiver:
- Choose two primes and , large and distinct.
- Compute the modulus ; its length in bits is the key size (2048 bits today).
- Compute , Euler's totient (the book calls it ).
- Choose the public exponent with and : shares no factor with . In practice .
- Compute the private exponent , the inverse of modulo : .
- Publish the public key ; keep the private key secret, and with it , and .
Then for every message , a number with :
Why decryption undoes encryption: for some whole number , and Euler's theorem gives , so = .
Why it is secure: to find from the public , an attacker needs , and needs and , the factors of . A 2048-bit has 617 decimal digits, and no known method factors it in any useful time. The small numbers of an exam example can be factored at a glance; they only show the method.
Keys: , , so and . works, as .
Finding d: try until is whole: gives , so (check: = ). Public key (13, 77); private key (37, 77).
Encrypt E, the 5th letter, , by repeated squaring, every step reduced mod 77:
5^1 = 5 5^2 = 25 5^4 = 25^2 = 625 mod 77 = 9 5^8 = 9^2 = 81 mod 77 = 4 5^13 = 5^8 x 5^4 x 5^1 = 4 x 9 x 5 = 180 mod 77 = 26 C = 26
Decrypt with :
26^2 = 676 mod 77 = 60
26^4 = 60^2 = 3600 mod 77 = 58
26^8 = 58^2 = 3364 mod 77 = 53
26^16 = 53^2 = 2809 mod 77 = 37
26^32 = 37^2 = 1369 mod 77 = 60
26^37 = 26^32 x 26^4 x 26^1 = 60 x 58 x 26
: 60 x 58 = 3480 mod 77 = 15; 15 x 26 = 390 mod 77 = 5 M = 5 = E
Repeated squaring is the hall method for a big power: write the exponent as a sum of powers of two (37 = 32 + 4 + 1), square repeatedly while reducing mod , then multiply the needed squares, reducing after each product. No number ever exceeds .
Finding d has two hall methods:
- Trial: for , stopping at the first whole number, as above.
- Extended Euclidean algorithm: for 60 and 13 it runs 60 = 4 x 13 + 8, 13 = 1 x 8 + 5, 8 = 1 x 5 + 3, 5 = 1 x 3 + 2, 3 = 1 x 2 + 1, and back-substitution gives the same 37.
Encrypting a word, the usual paper question:
- Number the letters: A = 1 to Z = 26 is common; A = 0 to Z = 25 also works, if stated.
- Choose p and q so that exceeds the largest letter value (here ), and make the keys.
- Encrypt and decrypt each letter on its own, in a table of letter, , and the decrypted .
The book's second example does SUZANNE with , , , , and gets 28 21 20 1 5 5 26. Every word the papers set is worked in the Numericals panel.
A weakness of letter-by-letter RSA: the two N's of SUZANNE both become 5, so the ciphertext is really a substitution cipher open to frequency analysis. Real RSA encrypts one large padded number at a time (OAEP padding), and in practice encrypts only a session key or a digest, never the message itself (hybrid use, signatures).
Signing uses the same keys the other way round: with the private key, checked by anyone as . With the keys above, signs to , and .
To remember it: anyone in Kathmandu can multiply 7 by 11 in their head; given 77, a child finds 7 and 11 again. Given a 617-digit product, no computer known today can find the two primes. That gap, easy one way and hopeless back, is the whole of RSA.
- What do you mean by firewall? Encrypt and decrypt the “attack” using RSA. 2082 Bhadra Q9 · 2+4+2
- What is public key cryptography? Encrypt the word "security" using the RSA algorithm. Also show the decryption to obtain the plaintext. 2081 Baishakh Q9 · 1+7
- What are the properties of secure communication? Use RSA algorithm to encrypt and decrypt the message "network". 2080 Bhadra Q9 · 2+6
- What is PGP? Use RSA algorithm to encrypt/decrypt the word COW. 2080 Baishakh Q9 · 3+5
- What is a digital signature? Encrypt the message "PANDEMIC" using RSA algorithm. Also obtain the plaintext from the ciphertext. 2079 Bhadra Q9 · 1+7
- Write down the steps involved in RSA encryption algorithm. Encrypt the word "Computer" using RSA algorithm. 2078 Bhadra Q9 · 8
- How does a Digital Signature work? Encrypt the world HELLO using RSA algorithm. Also decrypt it by showing steps. 2076 Chaitra Q9 · 2+6
- List the properties of secure communication. Encrypt and decrypt “ROSE” using RSA algorithm. 2076 Ashwin Q9 · 2+6
- What is VPN? Encrypt a message "network" using RSA algorithm. 2075 Ashwin Q9 · 2+6
- Compare symmetric key encryption method with asymmetric key encryption. Explain RSA algorithm with example. 2073 Shrawan Q8 · 3+5
- Write down the steps involved in RSA encryption algorithm. Encrypt the word CAT using RSA algorithm, choose the suitable data for encryption by yourself according to RSA algorithm. 2072 Chaitra Q9 · 8
- What is firewall? What are their types? Encrypt and decrypt "OVEL" message using RSA algorithm. 2072 Kartik Q9 · 1+1+6
- What is public key cryptography? Explain about RSA algorithm in detail. 2071 Chaitra Q9 · 2+6
- Compare symmetric key encryption method with asymmetric key encryption. Describe the operation of RSA algorithm. 2069 Chaitra Q9 · 4+4
- What is a secure socket layer? Encrypt the message “DANGER” using RSA algorithm. 2068 Baishakh Q9 · 2+6
- How can we maintain the security within the communication network? Explain any one cryptography algorithm with example. 2066 Poush Q9 · 2+6
Diffie-Hellman key exchange PIN 2/27
80 Bh · 74 Ash2×44+4
The problem it solves: symmetric ciphers need a shared key, and the network is the only channel. Diffie-Hellman makes a key appear at both ends without the key itself ever being sent.
The steps: first, both agree on two public numbers, a large prime and a generator (a primitive root of ); these may be sent openly.
- A chooses a large random secret and computes .
- A sends to B, never .
- B chooses a large random secret and computes .
- B sends to A, never .
- Both compute the key: A finds , B finds .
Why the two keys are equal: and , both mod .
- Public: , .
- A chooses : = .
- B chooses : = .
- A computes = .
- B computes (as and ).
Both hold . The book's working is right.
Why an eavesdropper fails: it sees , , and . To get it needs from : the discrete logarithm problem, infeasible for a prime of 2048 bits. (For 23 it is trivial: only gives 21.)
The weakness: man in the middle. Plain Diffie-Hellman authenticates nobody. Trudy, sitting between A and B, runs one exchange with A and another with B, so each holds a key shared with Trudy, who decrypts, reads and re-encrypts everything.
The cure is to authenticate the exchanged values with signatures and certificates, as TLS does (SSL and TLS) and as IKE does for IPsec (IPsec). TLS 1.3, IKE and SSH all use ephemeral Diffie-Hellman, a fresh and each session, so that a stolen long-term key cannot unlock past sessions (forward secrecy).
To remember it, mix paint. Both start from the same public yellow; each adds a secret colour of their own and sends the mixture; each adds their own secret colour again to what arrives. Both end with the same brown, and a watcher holding the two mixtures cannot un-mix the secret colours out of them.
- Write short notes on: (Any Two) a) Go Back-N ARQ b) Dual Stack method in IPv6 c) Diffie-Hellman algorithm d) ATM 2080 Bhadra Q10 · 2×4
- Write short notes on: (Any two) a) SMTP and POP b) Diffie Hellman’s Algorithm c) CSMA/CD d) DLL Flow Control Mechanisms 2074 Ashwin Q10 · 4+4
8.4Digital signatures
Digital signatures: how they work HOT 5/27
81 Ba · 79 Bh · 76 Ch · 75 Ch · 72 Ka1+72+62×4
Why it is needed: on paper, a handwritten signature or a seal identifies the author of a cheque or a contract. An electronic document can be copied and edited without a trace, so its "signature" must depend on the document's exact content and on a secret only the signer holds. Public key cryptography provides exactly that.
How a digital signature works. Signing, at the sender A:
- Hash the message with a hash function such as SHA-256, giving a short, fixed-length digest .
- Encrypt the digest with A's private key: (for RSA, ). This is the signature.
- Send together with , and usually A's certificate.
Verifying, at the receiver B:
- Hash the received message again with the same function: digest .
- Decrypt the signature with A's public key: digest .
- Compare: if , the signature is valid: only A's private key could have made it, and the message is unchanged. If they differ, the message was altered or the signature forged, and it is rejected.
Why sign the hash and not the message: RSA on a long document would be very slow; the digest is small (256 bits for SHA-256) whatever the document's size; and changing even one bit of the message changes about half the digest's bits.
A good hash is one-way (the message cannot be rebuilt from the digest) and collision resistant (no one can find two messages with the same digest). MD5 and SHA-1 have known collisions and are no longer used for signatures; SHA-256 is.
The properties a signature must have (the book's list): verifiable (anyone can prove that the signer signed it), non-forgeable (no one else can produce it) and non-repudiable (the signer cannot later deny it). Unlike a handwritten signature, it is different for every document, so it cannot be cut from one and pasted on another.
What it does not give: confidentiality. The message travels in the clear unless it is also encrypted, which PGP does in the same step.
Where the public key comes from. B must be sure that the public key really is A's, or Trudy could sign with her own key and pass hers off as A's. A certificate (X.509) binds a name to a public key and is itself signed by a certification authority (CA) that B already trusts; browsers and operating systems ship with a list of trusted root CAs. This system of CAs and certificates is the public key infrastructure (PKI).
In Nepal, the Electronic Transactions Act, 2063 gives digital signatures legal force, with certifying authorities licensed under the Office of the Controller of Certification.
| Point | Message authentication code (MAC) | Digital signature |
|---|---|---|
| Key | one secret key shared by both ends | the signer's private key; checked with its public key |
| Who can verify | only the holders of the shared key | anyone |
| Non-repudiation | no: either end could have made it | yes: only the signer could |
| Speed | fast (HMAC) | slower (RSA, ECDSA) |
| Used in | TLS records, IPsec packets | certificates, PGP mail, software updates |
With , and , take the digest to be . A signs: . B verifies with the public key: , equal to its own hash of the message, so the signature is valid. A digest of 6 from a tampered message would not match the 5 recovered from .
To remember it: before Windows installs an update, it checks Microsoft's digital signature on the file; a file changed by even one byte, or signed by anyone else, is refused. Algorithms in use: RSA signatures, DSA, ECDSA and EdDSA.
- Write short notes on: (Any Two) a) MAC sublayer b) Digital signature c) Firewall 2081 Baishakh Q10 · 2×4
- What is a digital signature? Encrypt the message "PANDEMIC" using RSA algorithm. Also obtain the plaintext from the ciphertext. 2079 Bhadra Q9 · 1+7
- How does a Digital Signature work? Encrypt the world HELLO using RSA algorithm. Also decrypt it by showing steps. 2076 Chaitra Q9 · 2+6
- Write short notes on: (Any two) a) Digital Signature b) VPN c) Symmetric key cryptography 2075 Chaitra Q10 · 4+4
- Write short notes on: a) Digital signature b) IPSec 2072 Kartik Q10 · 4×2
8.5Securing e-mail: PGP
PGP: how an e-mail is secured PIN 3/27
82 Ba · 80 Ba · 74 Ch2×43+55+3
Why mail needs it: SMTP carries a message in plain text through several mail servers (SMTP, POP3 and IMAP); anyone with access to a server or a link on the way can read it, and a forged sender address costs nothing. PGP protects the message itself, end to end, whatever servers it passes.
How PGP secures one mail from A to B, in order:
- Hash: A's PGP computes a digest of the message (SHA-256 now; MD5 or SHA-1 in early versions).
- Sign: it encrypts the digest with A's private key (RSA or DSA) and attaches this signature to the message.
- Compress: it compresses the message and signature together (ZIP).
- Encrypt: it generates a fresh random session key, used for this one message only, and encrypts the compressed bundle with a symmetric cipher (IDEA, 3DES, CAST-128 or AES).
- Lock the key: it encrypts the session key with B's public key (RSA or ElGamal) and attaches it.
- Convert: it turns the binary result into radix-64 (base64) text, which any mail system carries unharmed, and sends it.
At B, the same steps backwards: decode the base64; decrypt the session key with B's private key; decrypt the bundle with the session key; decompress; then hash the message again and compare it with the digest recovered from the signature by A's public key. A match proves the mail came from A, unchanged.
Why this order:
- Sign before compressing, so that the signature covers the message as written and can be checked later without recompressing it.
- Compress before encrypting, because compression removes the redundancy that cryptanalysis feeds on, and leaves less to encrypt.
- A session key, because public key encryption is slow: the long message goes through a fast symmetric cipher, and only the short session key through RSA (hybrid use).
The services PGP offers:
- Authentication and integrity: the digital signature (digital signatures).
- Confidentiality: the session key and symmetric encryption.
- Compression: ZIP, saving space and transfer time.
- E-mail compatibility: radix-64 conversion, since mail carries 7-bit text.
- Segmentation: a long message is split to fit mail size limits and rejoined at B.
Keys in PGP. Installing PGP makes a key pair for the user. The private key is stored encrypted under a passphrase, which must be typed each time it is used; public keys are posted on the user's website or a key server.
- Key rings: each user keeps a public key ring (other people's public keys) and a private key ring (their own key pairs).
- Web of trust: users sign one another's keys, and a key signed by someone already trusted is accepted; no central authority is needed.
S/MIME, the alternative built into mail programs, secures MIME mail with the same ingredients but takes its public keys from X.509 certificates issued by certification authorities instead of a web of trust.
To remember the steps, post an answer sheet across the country: sign it, fold it small, lock it in a box with a brand-new padlock, put the padlock's only key in an envelope that only the exam office can open, and write the address in plain letters the post office can read. Signature, compression, session key, B's public key, base64.
- Write Short Notes on: (Any Two) a) 802.5 Token Ring b) PGP c) Socket programming fundamentals d) X.25 Network 2082 Baishakh Q10 · 2×4
- What is PGP? Use RSA algorithm to encrypt/decrypt the word COW. 2080 Baishakh Q9 · 3+5
- Define type of Encryption used in security. How PGP can secure email communication? 2074 Chaitra Q9 · 5+3
8.6Securing TCP connections: SSL
SSL and TLS: securing a TCP connection PIN 3/27
71 Ch · 71 Shr · 68 Ba4×22+6
Where it sits: above TCP, which it needs for reliable, in-order delivery (TCP), and below the application, which barely notices it. HTTP over TLS is HTTPS on port 443 (HTTP and HTTPS); mail and file transfer have their own TLS ports (SMTPS on 465, IMAPS on 993) or switch to TLS with STARTTLS.
Its four protocols: the handshake protocol (authenticates and agrees keys), the change cipher spec protocol (one message: switch to the new keys now), the alert protocol (warnings and fatal errors, such as a bad certificate) and the record protocol, which carries everything, the application's data included.
The handshake, in the classic RSA form of SSL 3.0 and TLS 1.2:
- ClientHello: the client sends the versions and cipher suites it supports and a random number.
- ServerHello: the server picks the version and cipher suite and sends its own random number.
- Certificate: the server sends its certificate, its public key signed by a CA; the client checks it against the CAs it trusts and that the name matches the site.
- ServerHelloDone closes the server's turn.
- ClientKeyExchange: the client makes a random pre-master secret, encrypts it with the server's public key and sends it; only the real server can decrypt it.
- Key derivation: both sides compute the master secret from the pre-master secret and the two random numbers, and from it the session keys: an encryption key and a MAC key for each direction.
- ChangeCipherSpec and Finished, from each side: the Finished message is a MAC over the whole handshake, so any tampering with the earlier messages is caught.
- Application data now flows, encrypted and authenticated by the record protocol.
The record protocol treats the data in blocks: fragment it (up to = 16,384 bytes), compress it (optional, and dropped in TLS 1.3), add a MAC (a keyed hash, HMAC), encrypt with the symmetric session key (AES or ChaCha20 today), and add a 5-byte header (content type, version, length). The book lists the same as fragmentation, compression, message integrity, confidentiality and framing.
The services SSL gives: server authentication by certificate, optional client authentication, confidentiality by symmetric encryption, integrity by MAC, and key exchange by public key cryptography: exactly the hybrid scheme of the cryptography card.
| Version | Year | Status |
|---|---|---|
| SSL 2.0, SSL 3.0 | 1995, 1996 (Netscape) | broken; prohibited (RFC 6176, RFC 7568) |
| TLS 1.0, TLS 1.1 | 1999 (RFC 2246), 2006 (RFC 4346) | deprecated (RFC 8996) |
| TLS 1.2 | 2008 (RFC 5246) | in use |
| TLS 1.3 | 2018 (RFC 8446) | current: one round trip, ephemeral Diffie-Hellman only, no RSA key transport |
Uses (the book's list of advantages): online card payments, logins, webmail, secure file transfer (HTTPS, FTPS), and SSL VPNs that give remote users access to an office network through the browser (VPN).
To remember it: paying an exam form fee through a digital wallet in the browser, the address starts with https and a padlock appears. In the second before that, the browser checked the wallet's certificate and agreed session keys with its server; the NTC or WorldLink line in between carries only ciphertext.
- Write short notes on: a) SSL b) WEP 2071 Chaitra Q10 · 4×2
- Write short notes on: (any two) a) WEP b) IDS c) SSL 2071 Shrawan Q10 · 4×2
- What is a secure socket layer? Encrypt the message “DANGER” using RSA algorithm. 2068 Baishakh Q9 · 2+6
8.7Network layer security: IPsec and VPN
IPsec: AH and ESP, transport and tunnel mode PIN 3/27
82 Bh · 80 Ba · 72 Ka2×44×2
Why at the network layer: once IP is protected, every protocol above it is protected too, TCP, UDP, ICMP and routing updates alike, without changing a single application. IPsec works with IPv4 and IPv6; in IPv6, AH and ESP are extension headers (IPv6 extension headers).
The two modes differ in what is protected:
- Transport mode: the IPsec header goes between the original IP header and the transport header. Only the payload (the TCP or UDP segment) is protected; the original IP header, with the real addresses, travels as it is. Used end to end, host to host.
- Tunnel mode: the whole original IP packet, header included, becomes the payload of a new IP packet with a new header, usually addressed from one security gateway to another. The inner addresses are hidden too. Used gateway to gateway, which is how VPNs are built.
Authentication Header (AH), IP protocol number 51, gives source authentication, data integrity and protection against replay, but no confidentiality: nothing is encrypted. Its fields:
- Next header (8 bits): the type of the payload that follows (6 for TCP).
- Payload length (8 bits): the length of the AH itself.
- Reserved (16 bits).
- Security parameter index, SPI (32 bits): names the security association, much as a virtual circuit number names a circuit.
- Sequence number (32 bits): rises by one per packet, to defeat replay.
- Authentication data (variable): the integrity check value, a keyed hash over the packet, with the fields that change in transit (TTL, header checksum) counted as zero.
Encapsulating Security Payload (ESP), IP protocol number 50, gives confidentiality by encryption, plus source authentication, integrity and anti-replay. It wraps the payload:
- ESP header in front: the SPI and the sequence number, 32 bits each.
- The payload itself, encrypted.
- ESP trailer: padding of 0 to 255 bytes, an 8-bit pad length and an 8-bit next header; encrypted with the payload.
- ESP authentication data at the end, covering the header to the trailer; placed last so it can be computed in one pass as the packet goes out.
| Point | AH | ESP |
|---|---|---|
| IP protocol number | 51 | 50 |
| Confidentiality | no | yes, encryption (AES) |
| Integrity and source authentication | yes | yes (optional) |
| Anti-replay | yes, sequence number | yes, sequence number |
| Covers the outer IP header | yes, its fixed fields | no |
| Through NAT | fails, as NAT changes the authenticated addresses | works, with UDP encapsulation |
| Use today | rare | almost every IPsec VPN |
Security association (SA). Before protected packets flow, the two ends agree a one-way relationship holding everything needed: the protocol (AH or ESP), the mode, the algorithms and keys, the sequence counter, the replay window and the lifetime.
- Identified by its SPI, the destination address and the protocol; a two-way conversation needs two SAs, one each way.
- Stored in the security association database (SAD), while the security policy database (SPD) decides for each packet whether to protect it, pass it or drop it.
IKE (Internet Key Exchange, version 2 in RFC 7296) creates the SAs automatically: it authenticates the two ends by certificates or a pre-shared key and agrees fresh keys with Diffie-Hellman.
To remember it: a branch office router in Pokhara and the head office router in Kathmandu run IPsec in tunnel mode with ESP. Every packet between the two LANs leaves Pokhara wrapped and encrypted, crosses the ISP's network as gibberish addressed router to router, and is unwrapped in Kathmandu: the staff notice nothing.
- Write short notes on: (Any Two) a) ARP and NDP b) AH and ESP c) VPN d) vLAN 2082 Bhadra Q10 · 2×4
- Write short notes on: (Any Two) a) VLAN b) ARP c) IPSec 2080 Baishakh Q10 · 2×4
- Write short notes on: a) Digital signature b) IPSec 2072 Kartik Q10 · 4×2
VPN: a private network over a public one HOT 5/27
82 Bh · 79 Bh · 75 Ch · 75 Ash · 71 Ch2×42+42+6
Why it exists: a private leased line between two offices is secure but expensive, and the Internet is cheap but public. A VPN gets the privacy of the first at the price of the second: virtual because no private wires are laid, private because no outsider can read or join the traffic.
How a VPN works, step by step:
- Authenticate: the VPN client or the remote gateway proves who it is, with a certificate, a pre-shared key, or a username and password with a one-time code.
- Agree keys: the two ends agree session keys (IKE for IPsec, a TLS handshake for an SSL VPN).
- Encapsulate: a packet bound for the private network is encrypted and authenticated, then wrapped in a new packet addressed to the far VPN endpoint.
- Cross the Internet: routers forward it like any other packet, seeing only the endpoints' public addresses and ciphertext.
- Decapsulate: the far endpoint checks it, decrypts it and delivers the original packet inside its LAN; replies return the same way.
| Type | What it joins | Typical example |
|---|---|---|
| Remote access (host to gateway) | one user's device to the organisation's network, through client software | a staff member at home reaching the office file server |
| Site to site, intranet (gateway to gateway) | the LANs of one organisation's sites, permanently | a head office and its branches |
| Site to site, extranet | an organisation's network to a partner's, with limited access | a company and its supplier sharing an ordering system |
The protocols used: IPsec in tunnel mode with ESP (the usual site-to-site choice); SSL/TLS VPNs such as OpenVPN, or a browser-based portal (common for remote access); L2TP carried over IPsec; WireGuard, a modern, small design; and PPTP, an old protocol now considered insecure.
- Advantages: far cheaper than leased lines; confidentiality, integrity and authentication over a public network; remote users join from anywhere; new sites are added in software.
- Disadvantages: encryption and the extra headers cost speed and bandwidth; performance depends on the Internet in between; setup and keys must be managed; a stolen or infected laptop with VPN access is an attacker inside the network.
A company's head office in Kathmandu (192.168.1.0/24) and its branch in Pokhara (192.168.2.0/24) each have an ordinary Internet connection from a local ISP.
- Site to site: their two routers run an IPsec VPN, so a branch PC opens the accounts server at 192.168.1.10 as if it were down the corridor, while the ISPs carry only encrypted packets between the routers' public addresses.
- Remote access: an accountant working from home in Bhaktapur starts a VPN client on her laptop and gets the same access.
To remember it: a VPN is a sealed pipe laid inside a public road. The road (the Internet) is shared by everyone; what flows inside the pipe is invisible to them. The consumer "VPN apps" that make a phone appear to be in another country use the same tunnel, from one user to the provider's server.
- Write short notes on: (Any Two) a) ARP and NDP b) AH and ESP c) VPN d) vLAN 2082 Bhadra Q10 · 2×4
- Write short notes on: (Any Two) a) ALOHA b) OSPF c) VPN 2079 Bhadra Q10 · 2×4
- Write short notes on: (Any two) a) Digital Signature b) VPN c) Symmetric key cryptography 2075 Chaitra Q10 · 4+4
- What is VPN? Encrypt a message "network" using RSA algorithm. 2075 Ashwin Q9 · 2+6
- What is network security? Explain Virtual Private Network (VPN) with an example. 2071 Chaitra Q4 · 2+4
8.8Securing wireless LANs: WEP
Securing wireless LANs: WEP, and why WPA2 replaced it PIN 2/27
71 Ch · 71 Shr4×2
Why wireless needs its own protection: a radio signal passes through walls, and anyone in range can capture every frame without touching a cable (wireless LAN). WEP had three goals: confidentiality (no eavesdropping), access control (only stations with the key may join) and integrity (frames not modified in transit).
How WEP encrypts a frame:
- Integrity value: the CRC-32 of the data, the 32-bit integrity check value (ICV), is appended to the data.
- Seed: a 24-bit initialization vector (IV), meant to change with every frame, is joined in front of the shared secret key: 24 + 40 = 64 bits, or 24 + 104 = 128 bits.
- Keystream: RC4, keyed with this seed, produces a keystream as long as the frame.
- Encrypt: the data and ICV are XORed with the keystream.
- Send: the frame carries the IV in the clear, a key ID, and the ciphertext.
Decryption reverses it: the receiver takes the IV from the frame, joins its own copy of
the key, runs RC4 to get the same keystream, XORs it with the ciphertext, and checks the CRC. The
book's toy example: keystream 0101 XOR plaintext 1100 gives ciphertext
1001, and XORing 1001 with 0101 again gives back
1100.
Key sizes as typed into a router: 10 hexadecimal digits are 40 bits, which with the 24-bit IV make "64-bit WEP"; 26 hexadecimal digits are 104 bits, which make "128-bit WEP". Station authentication is either open system (none at all) or shared key, a challenge the station encrypts with WEP, which hands an eavesdropper a sample of keystream.
Why WEP is weak:
- The IV is too short: 24 bits give only 16,777,216 keystreams. A busy access point sending 1500-byte frames at 11 Mbps uses them all in about 5 hours, and by the birthday effect a repeated IV is more likely than not after about 4,800 frames. Two frames under the same IV and key share a keystream, so : the keystream cancels.
- Weak RC4 keys: because the IV is sent in the clear and placed in front of the key, certain IVs leak bytes of the key itself (the Fluhrer, Mantin and Shamir attack, 2001). Free tools collect enough frames and recover the key in minutes.
- CRC-32 is no integrity check against an attacker: it is linear and keyless, so bits flipped in the ciphertext can be matched by fixing the ICV, and the forged frame is accepted. There is no replay protection either.
- One static key: every user shares the same key, rarely changed, with no key management; one leak exposes everyone.
The replacements:
| Point | WEP | WPA | WPA2 | WPA3 |
|---|---|---|---|---|
| Year | 1997 | 2003 | 2004 | 2018 |
| Basis | 802.11 | Wi-Fi Alliance, interim | IEEE 802.11i | Wi-Fi Alliance |
| Cipher | RC4 | RC4 with TKIP | AES (CCMP) | AES (CCMP or GCMP) |
| Keys | one static shared key, 24-bit IV | a new key per packet, 48-bit sequence counter | fresh session keys from a 4-way handshake | SAE handshake, forward secrecy |
| Integrity | CRC-32 | Michael MIC | CBC-MAC (in CCMP) | CCMP or GCMP |
| Status | broken | deprecated | the usual minimum | current |
WPA2 and WPA3 come in two flavours: Personal, one passphrase for the network (a pre-shared key in WPA2, protected against offline guessing by SAE in WPA3), and Enterprise, where each user logs in through IEEE 802.1X and EAP to an authentication server (RADIUS).
To remember it: a hostel router still offering WEP is a locked door with the key taped to it: anyone in the corridor with a laptop and free software is inside within minutes. The fix is one setting, WPA2-AES or WPA3.
- Write short notes on: a) SSL b) WEP 2071 Chaitra Q10 · 4×2
- Write short notes on: (any two) a) WEP b) IDS c) SSL 2071 Shrawan Q10 · 4×2
8.9Firewalls: application gateway and packet filtering, and IDS
Firewalls: what they are, how they protect, their types, and router ACLs TOP 13/27
82 Bh · 82 Ba · 81 Ba · 76 Ch · 76 Ash · 75 Ch · 74 Ch · 74 Ash · 73 Shr · 72 Ch · 72 Ka · 70 Ch · 69 Ch4+42+68
Three design goals (Cheswick and Bellovin): all traffic between inside and outside must pass through the firewall; only traffic authorised by the local security policy may pass; and the firewall itself must resist penetration. The book's picture is a wall between the corporate LAN and the outside world, through which a valid web request passes while an invalid Telnet request bounces off.
How a firewall protects a network:
- A single choke point: every connection crosses one place, where the policy is enforced and every attempt can be logged and audited.
- Filtering by rule: it blocks unwanted source addresses, ports and protocols (Telnet, file sharing and remote desktop from outside) and, best of all, denies by default whatever is not explicitly allowed.
- Only expected replies get in: a stateful firewall admits inbound packets only when they belong to a connection started from inside.
- Hiding the inside: with NAT, outsiders see one public address, not the internal hosts and their layout.
- Content control: a proxy can inspect and block malware, banned sites, file types and dangerous commands, and require users to log in.
- Containment and alerting: it separates zones (a DMZ for public servers), slows the spread of a worm between segments, resists floods such as SYN floods, and alerts the administrator.
The book's reasons for a firewall: to stop intruders interfering with the daily running of the network (denial of service, SYN and FIN attacks), deleting or modifying stored information, or obtaining secrets; to allow only authorised access to the inside; and to stop illegal changes, such as an attacker replacing the official homepage.
The types of firewall, by the layer they inspect:
- Packet filtering firewall (first generation, stateless): a router or host that
checks each packet on its own against a rule table, by its IP and TCP/UDP headers: source and
destination IP address, protocol, ports, TCP flags, interface and direction. The first matching
rule permits or denies.
- For: fast, cheap and invisible to users; any router can do it.
- Against: it keeps no state (a forged packet that claims to be a reply looks valid), reads no content, cannot spot a spoofed source address, and long rule lists are easy to get wrong.
- Stateful inspection firewall (dynamic packet filter): a packet filter that also keeps a state table of open connections (addresses, ports, TCP state). An inbound packet is admitted only if it belongs to a connection already open or is explicitly allowed, so an out-of-the-blue ACK is dropped. Most firewalls today work this way.
- Application-level gateway (proxy firewall): works at the application layer. The
client connects to the proxy, which checks the request (the URL, the FTP command, the mail and
its attachments, the user's identity) and, if it is allowed, opens a second connection to the
real server and relays the reply. It needs a proxy program for each service (HTTP, SMTP, FTP,
DNS).
- For: the most secure type; it understands the content and logs everything.
- Against: slower, since every connection is handled twice, and a new application needs a new proxy.
- Circuit-level gateway: works at the session layer. It checks that the TCP handshake (and the user) is legitimate, then relays bytes between the two connections without reading them. SOCKS is the standard example; it is often used for outgoing connections from trusted insiders.
- Next-generation firewall (NGFW): a stateful firewall with deep packet inspection, recognition of applications whatever port they use, intrusion prevention, TLS inspection and user identity, in one box.
Where they run: a network firewall guards a whole network at its edge; a host-based firewall (Windows Defender Firewall, Linux nftables) guards one machine. A home Wi-Fi router's built-in firewall is a small stateful one.
| Point | Packet filter | Stateful inspection | Application gateway |
|---|---|---|---|
| Layer | network and transport | network and transport, with state | application |
| Decides on | each packet's header alone | header plus the connection's state | the content and the user |
| Speed | fastest | fast | slowest |
| Security | lowest | good | highest |
| Example | a router ACL | a home router, a perimeter firewall | an HTTP proxy with filtering |
To remember the types, picture the hostel gate's chowkidar:
- Packet filter: he checks each visitor's name against a list, and nothing else.
- Stateful inspection: he remembers who went out, and lets only them back in.
- Application gateway: he walks each visitor to the room, checking the bag on the way.
- Circuit-level gateway: he checks the entry in the visitors' book once, then lets the visitor through unwatched.
How a packet filtering firewall works, step by step:
- Receive: a packet arrives on an interface, inbound or outbound.
- Read the header: source and destination IP address, protocol (TCP, UDP, ICMP), source and destination port, TCP flags.
- Compare with the rules, top down: each rule names values (or "any") for these fields and an action.
- First match decides: the packet is forwarded (permit) or dropped (deny), and the rest of the list is not read.
- No match: the implicit deny at the end of every list drops it.
- Log the packets denied, for the administrator.
The book's filter table blocks four things: incoming packets from the network 121.34.0.0, incoming packets for any internal Telnet server (port 23), incoming packets for the internal host 192.168.0.8, and outgoing packets to web servers (port 80), so that staff cannot browse.
Router ACLs. A router turns into a packet filtering firewall with an access control
list (ACL): an ordered list of permit and deny statements, applied to one interface in one
direction (in or out). Each packet is compared top down; the first
match decides; and every list ends with an invisible implicit "deny any".
| Point | Standard ACL | Extended ACL |
|---|---|---|
| Cisco numbers | 1 to 99, 1300 to 1999 | 100 to 199, 2000 to 2699 |
| Matches | the source address only | source and destination address, protocol, ports |
| Placed | near the destination | near the source |
The wildcard mask says which address bits must match: it is the subnet mask inverted,
0 for "must match" and 1 for "ignore". A /24 network has the mask 255.255.255.0, so its
wildcard is 0.0.0.255 (subnetting).
The paper's network 202.70.91.0/24 is to be blocked on the router's FastEthernet 0/0 interface, in the incoming direction, while all other traffic still passes. With a standard ACL:
Router(config)# access-list 10 deny 202.70.91.0 0.0.0.255 Router(config)# access-list 10 permit any Router(config)# interface FastEthernet0/0 Router(config-if)# ip access-group 10 in
Or with an extended ACL, which can be narrowed later to particular destinations or ports:
Router(config)# access-list 110 deny ip 202.70.91.0 0.0.0.255 any Router(config)# access-list 110 permit ip any any Router(config)# interface FastEthernet0/0 Router(config-if)# ip access-group 110 in
- Line 1 denies every packet whose source is 202.70.91.0 to 202.70.91.255 (wildcard 0.0.0.255).
- Line 2 permits everything else. It is essential: without it the implicit deny at the end of the list would drop all traffic arriving on the interface.
- Lines 3 and 4 apply the list to FastEthernet 0/0 in the in direction, so the router drops those packets as they arrive, before routing them.
- Check with
show access-lists, whose match counters rise as packets are denied, andshow ip interface FastEthernet0/0.
Where the firewall sits. The classic arrangement is the screened subnet: a border router filters first, the firewall second, and the servers the public must reach (web, mail) sit in a DMZ (demilitarised zone) of their own, so that a hacked web server is still outside the trusted LAN. Simpler set-ups use a single screening router, or a dual-homed host with one interface on each side.
What a firewall cannot do: stop traffic that goes around it (a phone's mobile hotspot, an infected USB drive), stop an insider already inside, see malware hidden in allowed or encrypted traffic without deeper inspection, or prevent phishing. That is why an IDS watches behind it.
- What do you mean by firewall? Encrypt and decrypt the “attack” using RSA. 2082 Bhadra Q9 · 2+4+2
- What is router ACL? How do you apply ACL to block the IP network 202.70.91.0/24 incoming to interface Fast Ethernet of a router? Encrypt the word “ISPNet” using anyone suitable AES technique. 2082 Baishakh Q9 · 2+6
- Write short notes on: (Any Two) a) MAC sublayer b) Digital signature c) Firewall 2081 Baishakh Q10 · 2×4
- Explain briefly the desirable properties of secure communication. Explain how packet filtering firewall works. 2076 Chaitra Q10 · 4+4
- Write short notes on: (Any two) a) Firewall and their types b) 803 Token Bus c) Virtual circuit switching 2076 Ashwin Q10 · 4+4
- Explain briefly the desirable properties of secure communication. Explain how Packet filtering firewall Works. 2075 Chaitra Q9 · 4+4
- Write short notes on: (any two) i) Types of firewals ii) FDDI iii) Socket programming 2074 Chaitra Q10 · 4+4
- Explain briefly the desirable properties of secure communication. Explain how Packet filtering firewall Works. 2074 Ashwin Q9 · 4+4
- What do you mean by firewall? Explain different types of firewall. 2073 Shrawan Q9 · 2+6
- Explain briefly how firewalls protect network and also explain different types of Firewall. Illustrate your answer with appropriate figures. 2072 Chaitra Q8 · 8
- What is firewall? What are their types? Encrypt and decrypt "OVEL" message using RSA algorithm. 2072 Kartik Q9 · 1+1+6
- Explain briefly how firewalls protect network and also explain different types of Firewall. Illustrate your answer with appropriate figures. 2070 Chaitra Q9 · 8
- What is network security? How can firewalls enhance network security? Explain how firewalls can protect a system. 2069 Chaitra Q10 · 2+2+4
Intrusion detection systems PIN 1/27
71 Shr4×2
Why a firewall is not enough: a firewall decides at the gate, by rules. Attacks hidden inside allowed traffic (an exploit sent to the web server's open port 443), attacks from insiders, and attacks the rules never imagined pass straight through. The IDS watches what gets past.
By where it watches:
| Point | Network IDS (NIDS) | Host IDS (HIDS) |
|---|---|---|
| Placed | at a key point of the network (behind the firewall, in the DMZ), fed a copy of the traffic by a switch's mirror (SPAN) port or a tap | on each host it protects, as an agent |
| Watches | the packets of a whole segment | the host's own traffic, logs, processes and system files |
| Catches | scans, floods, exploits on the wire | changed or deleted system files, logins, malware on the host |
| Misses | encrypted payloads, what never crosses its segment | attacks on other hosts; can be disabled by an attacker who owns the host |
| Examples | Snort, Suricata, Zeek | OSSEC, Wazuh, Tripwire |
By how it decides:
- Signature-based (misuse) detection: matches traffic against patterns of known attacks, like antivirus signatures. Few false alarms and a clear explanation, but blind to new (zero-day) attacks until a signature exists, so the rules need constant updating.
- Anomaly-based detection: learns a baseline of normal behaviour (traffic volumes, ports, login times) and flags deviations. It can catch new attacks, but it raises more false alarms and needs a training period.
An example signature, a Snort rule that alerts on any Telnet attempt into a hostel network:
alert tcp any any -> 192.168.10.0/24 23 (msg:"Telnet attempt"; sid:1000001; rev:1;)
The book also splits NIDS by timing: an on-line NIDS analyses the packets in real time, an off-line one analyses stored data afterwards. A HIDS typically takes a snapshot of the critical system files and compares later snapshots with it, alerting when a file has been changed or deleted.
Judging the alerts: a true positive is a real attack flagged; a false positive is an alarm on harmless activity (too many, and staff stop reading them); a false negative is an attack missed, the worst case.
| Point | Firewall | IDS | IPS |
|---|---|---|---|
| Job | allow or block by policy | detect and alert | detect and block |
| Position | inline, at the boundary | beside the traffic (a copy) | inline |
| Effect on traffic | passes or drops it | none | drops the attack packets |
To remember it: the firewall is the hostel gate with its chowkidar; the IDS is the CCTV in the corridors, which records and alerts the warden but stops no one; the IPS is a guard who also steps in when the camera spots trouble.
- Write short notes on: (any two) a) WEP b) IDS c) SSL 2071 Shrawan Q10 · 4×2
8.10Last minute recall
Chapter 8 in one screen
- Attacks: interruption (availability), interception (confidentiality), modification (integrity), fabrication (authenticity); passive versus active.
- Six properties: confidentiality, integrity, authentication, non-repudiation, availability, access control; the cheque story: account number hidden, amount unchanged, signature checked, writer cannot deny, bank open, only the cashier at the drawer.
- Maintaining security: policy, access control, encryption, firewall, segmentation, patching, anti-malware, IDS and logs, backups, physical security and training.
- Cryptography: plaintext, key, ciphertext; symmetric (one shared key, fast, keys) against public key (key pair, slow, keys); hybrid with a session key.
- Classical: Caesar ; monoalphabetic; polyalphabetic; columnar transposition.
- DES: 64-bit block, 56-bit key, 16 Feistel rounds; IP, rounds, swap, ; f = expansion, XOR, 8 S-boxes (6 to 4), P.
- AES: 128-bit block; 128, 192, 256-bit key; 10, 12, 14 rounds; SubBytes, ShiftRows, MixColumns, AddRoundKey; last round without MixColumns.
- RSA: , , , ; , ; example 7, 11, 13, 37: E = 5 to 26 and back.
- Diffie-Hellman: , , ; G = 7, N = 23, x = 3, y = 6 gives K = 18; man in the middle.
- Digital signature: hash, encrypt the digest with the private key; verify with the public key and compare; authentication, integrity, non-repudiation; certificates from a CA.
- PGP: hash, sign, compress, session key, lock it with B's public key, base64; web of trust.
- SSL/TLS: between TCP and the application, port 443; handshake (hellos, certificate, key exchange, finished) and record protocol (fragment, compress, MAC, encrypt, header).
- IPsec: AH (51: authentication, no secrecy) and ESP (50: encryption too); transport (host to host) and tunnel (gateway to gateway); SA, SPI, IKE.
- VPN: a tunnel over the Internet; remote access and site to site (intranet, extranet); IPsec, SSL VPN, WireGuard.
- WEP: RC4 with a 24-bit IV and a 40 or 104-bit key, CRC-32; IV reuse, weak keys, linear CRC, one static key; WPA (TKIP), WPA2 (AES, 802.11i), WPA3 (SAE).
- Firewall: packet filter, stateful inspection, application gateway (proxy), circuit-level gateway, NGFW; first match, implicit deny; DMZ.
- ACL:
access-list 10 deny 202.70.91.0 0.0.0.255,access-list 10 permit any,ip access-group 10 in. - IDS: NIDS and HIDS; signature and anomaly; IDS alerts, IPS blocks.
209 questions · asked 412 times in 27 sittings · exam answers only
Theory answers
Every theory question the 27 papers have asked, each with the answer as it is written in the exam: the direct answer for the marks, nothing else. Only what a paper has actually set is here; the topics no paper has asked yet are taught on their chapter cards. A question with several parts is split into them. How a process is carried out, step by step, is in Practical answers, and the chapter card behind each answer teaches the topic in full. Read them by chapter, each question once with every source that set it, or by paper, question by question.
1Introduction to computer network
OSI and TCP/IP compared: similarities and differences TOP 9/27
2082 Bhadra · Q1
2081 Bhadra · Q1
2079 Bhadra · Q1
2076 Chaitra · Q1
2073 Shrawan · Q1
2072 Chaitra · Q1
2071 Chaitra · Q1
2071 Shrawan · Q1
2066 Bhadra · Q1a
The OSI model is ISO's seven-layer reference model, defined before its protocols; the TCP/IP model is the four-layer model of the protocols the Internet uses, described after them. TCP/IP's application layer covers OSI layers 7, 6 and 5, its transport and internet layers match OSI layers 4 and 3, and its host-to-network layer covers OSI layers 2 and 1.
Similarities:
- Both are layered stacks of independent protocols, with peers communicating by protocols.
- Both have a transport layer giving an end to end, network-independent service to processes.
- Both have a network (internet) layer for routing and an application layer at the top.
- Both use packet switching and encapsulation, and both are used to describe real networks.
Differences:
| Basis | OSI | TCP/IP |
|---|---|---|
| Stands for | Open Systems Interconnection | Transmission Control Protocol / Internet Protocol |
| Layers | 7 | 4 |
| Developed by | ISO (ISO 7498, 1984) | US DoD (ARPA), for the ARPANET |
| Approach | model first, protocols later; general | protocols first, model later; fits only TCP/IP |
| Service, interface, protocol | clearly distinguished | not clearly distinguished |
| Network layer | connection-oriented and connectionless | connectionless only (IP) |
| Transport layer | connection-oriented only | both (TCP and UDP) |
| Session and presentation | separate layers | part of the application layer |
| Physical and data link | separate layers | one host-to-network layer |
| Protocol replacement | easy; protocols well hidden | difficult |
| Internetworking | not considered at first | the main design goal |
| Use | reference and teaching model | implemented on the Internet |
OSI's own protocols lost through bad timing, complexity, slow implementations and politics, while TCP/IP was already free and working. OSI remains the better model for describing networks; TCP/IP is the suite actually used.
Why network software is built as a hierarchy of layers HOT 8/27
2082 Bhadra · Q1
2080 Baishakh · Q1
2076 Chaitra · Q1
2075 Ashwin · Q1
2069 Chaitra · Q1
2068 Chaitra · Q1
2067 Ashad · Q1
2066 Bhadra · Q1a
Network software is organised as a hierarchy of layers, each built on the one below, because communication across different hardware, media and systems is too complex to design as one piece. Each layer offers services to the layer above and hides how they are implemented; layer n on one machine communicates with layer n on another through the layer n protocol, while the data actually passes down to the physical medium and up again.
- Reduced complexity: a large problem is divided into small, manageable parts, each designed and tested separately.
- Modularity: a layer can be changed or replaced without affecting the others while its interface stays the same, for example Wi-Fi in place of Ethernet under the same browser.
- Standardisation and interoperability: defined functions for each layer let products of different vendors work together.
- Easy troubleshooting: faults are isolated layer by layer.
- Reuse and specialisation: one layer serves many users above it, and teams specialise by layer.
- Flexibility: new technology is added at one layer only.
Example of the flow: a message M gets header H4 at layer 4, is split and gets H3 at layer 3, and gets header H2 and trailer T2 at layer 2 before transmission; the receiver removes them in reverse order.
The seven layers of the OSI model, their functions and example protocols HOT 6/27
2081 Bhadra · Q1
2080 Bhadra · Q1
2074 Chaitra · Q1
2074 Ashwin · Q1
2067 Ashad · Q1
2066 Poush · Q7
The OSI (Open Systems Interconnection) reference model is ISO's seven-layer framework (ISO 7498, 1984) for communication between open systems. It defines what each layer does, not the exact protocols. Layers 1 to 3 work hop by hop; layers 4 to 7 work end to end between the hosts.
- Physical layer: transmits raw bits over the medium; defines connectors, voltage levels, bit timing, data rate, encoding and transmission mode. Examples: RS-232, 10BASE-T, DSL; devices: hub, repeater.
- Data link layer: node to node delivery of frames: framing, physical (MAC) addressing, error detection by CRC, flow control and medium access. Examples: Ethernet, HDLC, PPP; devices: switch, bridge.
- Network layer: source to destination delivery of packets across networks: logical (IP) addressing, routing, forwarding, fragmentation, congestion control. Examples: IP, ICMP, IPsec; device: router.
- Transport layer: process to process delivery: port addressing, segmentation and reassembly, connection control, end to end flow and error control. Examples: TCP, UDP.
- Session layer: establishes, maintains and ends sessions; dialog control (who talks when) and synchronisation with checkpoints. Examples: NetBIOS, RPC.
- Presentation layer: syntax and semantics of data: translation between formats (ASCII, EBCDIC), encryption and decryption, compression. Examples: TLS, JPEG, MPEG, ASN.1.
- Application layer: interface between user programs and the network: file transfer, email, remote login, directory services. Examples: HTTP, FTP, SMTP, DNS, Telnet.
The units are bits, frames, packets and segments in layers 1 to 4, and data above them.
Client/server against peer to peer, with advantages and disadvantages HOT 5/27
2082 Baishakh · Q1
2081 Baishakh · Q1
2080 Bhadra · Q1
2078 Bhadra · Q1
2074 Chaitra · Q1
In the client/server model dedicated servers provide services that clients request; in the peer to peer (P2P) model every computer is an equal peer, both client and server, sharing resources directly.
| Basis | Client/server | Peer to peer |
|---|---|---|
| Roles | fixed: server serves, client requests | each peer both |
| Data and control | centralised on the server | spread over the peers |
| Security and backup | central, strong | per machine, weak |
| Cost | high (server, administrator) | low |
| Scalability | limited by the server | grows as peers join |
| Failure | server is a single point of failure | no single point of failure |
| Example | web, online banking | BitTorrent, home workgroup |
Client/server advantages: central control, easy backup, one consistent copy of the data. Disadvantages: costly; the server is a bottleneck and a single point of failure.
P2P advantages: cheap, easy to set up, no single point of failure. Disadvantages: weak security, no central backup, data unavailable when a peer is off.
Client/server networking and its features PIN 4/27
2076 Ashwin · Q1
2075 Chaitra · Q1
2070 Chaitra · Q1
2066 Bhadra · Q1b
Client/server networking is a model in which dedicated, always-on servers hold the data and services, and client machines request them; every exchange is a request from a client process answered by a server process.
- Asymmetric roles: clients start every exchange and servers only respond; many clients share one server.
- Centralised data and resources: one up-to-date copy of the data, on the server.
- Central administration and security: accounts, access rights and backups managed in one place.
- Dedicated server: powerful hardware and a network operating system, always on.
- Scalability: clients added freely; capacity grows by upgrading or adding servers.
- Location transparency: a client needs only the server's address.
- Tiers: two-tier, or three-tier (client, application server, database server).
- Single point of failure: if the server fails, every client stops.
What a protocol is, with examples PIN 4/27
2082 Bhadra · Q1
2081 Baishakh · Q1
2076 Chaitra · Q1
2066 Poush · Q1
A protocol is a set of rules that governs communication between entities: the format and order of the messages exchanged, their meaning, and the actions taken on sending or receiving them. Its key elements are syntax (format), semantics (meaning) and timing (when and how fast).
Examples: HTTP for web pages, SMTP for email, TCP and IP for delivery, Ethernet on a LAN.
X.25 and its key features PIN 4/27
2082 Baishakh · Q10
2075 Ashwin · Q10
2071 Chaitra · Q1
2068 Chaitra · Q6
X.25 is an ITU-T (CCITT, 1976) standard for the interface between a user's DTE and the DCE of a public packet switched network. It is connection-oriented and uses virtual circuits, with error and flow control at every hop, designed for the noisy analog lines of the 1970s.
- Three layers: physical (X.21), link (LAPB, a subset of HDLC) and packet (PLP), matching OSI layers 1 to 3.
- Virtual circuits: switched (SVC) and permanent (PVC); up to 4095 on one line, named by a 12-bit LCGN and LCN.
- Reliability: packets acknowledged and retransmitted hop by hop, and delivered in order.
- Multiplexing of many circuits on one line; PADs connect simple terminals.
- Limits: slow (typically up to 64 kbps), with high delay and overhead; replaced by Frame Relay.
What a computer network is PIN 3/27
2081 Bhadra · Q1
2071 Shrawan · Q1
2066 Poush · Q1
A computer network is a collection of autonomous computers and other devices (nodes) interconnected by communication links, such as copper wire, optical fibre or radio, that follow common protocols so that they can exchange data and share resources.
Its parts are the nodes (hosts, switches, routers), the links, the protocols and the services. Example: the PCs of a college lab sharing one printer and one internet line.
Frame Relay and the operation of a Frame Relay network PIN 3/27
2078 Bhadra · Q10
2073 Shrawan · Q1
2070 Ashad · Q6
Frame Relay is a connection-oriented, packet switched WAN technology that carries variable-length frames over virtual circuits, working only at the physical and data link layers. It detects errors but does not correct them: damaged frames are dropped and the end systems recover. It runs from 56 kbps to 44.736 Mbps (T3).
- DLCI: a 10-bit data link connection identifier in the 2-byte address names the virtual circuit; it has local significance and changes at each switch.
- Circuits: PVCs configured by the carrier; SVCs set up on demand by Q.933 signalling.
- Frame: flag, address (DLCI, C/R, EA, FECN, BECN, DE), information, 16-bit FCS, flag; no control field.
- Congestion: FECN and BECN warn the receiver and the sender; frames above the CIR get DE = 1 and are dropped first.
Operation:
- The customer router (DTE) puts the packet in a frame with the circuit's DLCI and sends it to the carrier's switch (DCE).
- The switch checks the FCS and silently discards a bad frame.
- It looks up the incoming port and DLCI, rewrites the DLCI for the outgoing link and relays the frame without any acknowledgement.
- The last switch delivers it to the destination DTE; TCP in the hosts recovers any loss.
The peer to peer model, its process and examples PIN 2/27
2075 Chaitra · Q1
2066 Poush · Q1
A peer to peer (P2P) network is formed when two or more computers connect and share their resources (files, printers, storage, bandwidth) directly, without a separate server. Every peer has equal capabilities and responsibilities: it stores its own data and acts as both client and server.
The P2P process:
- Join: a new peer contacts known peers, a tracker or a bootstrap node, or announces itself on the LAN.
- Search: it locates a resource by flooding a query to its neighbours, by asking a central index (hybrid P2P) or through a distributed hash table.
- Connect: it opens direct connections to the peers holding the resource.
- Exchange: it downloads pieces from many peers at once and uploads the pieces it has to others.
- Leave: its shared resources disappear with it; the other peers continue.
Types: pure P2P (Gnutella), hybrid P2P with an index or tracker (Napster, BitTorrent) and the small office or home workgroup.
Examples: BitTorrent, where a large file is split into pieces and every downloader also uploads; four PCs in a Windows workgroup sharing folders and a printer; phone to phone sharing apps over direct Wi-Fi; Bitcoin, where every node keeps a copy of the ledger.
Merits: low cost, easy setup, no single point of failure, capacity grows with the peers. Demerits: weak security, no central backup or control.
The design issues for the layers PIN 2/27
2075 Ashwin · Q1
2068 Chaitra · Q1
Every layer of a network must solve some common problems, called the design issues of the layers:
- Addressing: a network has many machines and each runs many processes, so every layer needs a way to identify senders and receivers (MAC, IP and port addresses).
- Direction of data transfer: whether data flows in one direction (simplex), both directions in turn (half duplex) or both at once (full duplex), and how many logical channels are used.
- Error control: circuits are imperfect, so error detecting or correcting codes are used and the receiver tells the sender which messages arrived correctly.
- Ordering (sequencing): some channels do not preserve order, so pieces are numbered and reordered.
- Flow control: a fast sender must not swamp a slow receiver; feedback or windows control the rate.
- Segmentation and reassembly: long messages are broken into pieces and reassembled; small ones may be combined.
- Multiplexing and demultiplexing: several conversations share one connection or channel when separate ones are costly.
- Routing: when several paths exist, the best route is chosen, mainly at the network layer.
Further issues are connection establishment and release, quality of service and security.
Which OSI layer does each task PIN 2/27
2072 Chaitra · Q1
2069 Chaitra · Q1
| Task | OSI layer |
|---|---|
| Timing and voltage of the received signal | Physical layer |
| Data framing | Data link layer |
| Error detection and correction | Data link layer (hop by hop; transport also checks end to end) |
| Physical identification of a computer (MAC address) | Data link layer |
| Logical identification of a computer (IP address) | Network layer |
| Point-to-point connection of sockets | Transport layer |
| Dialogue control | Session layer |
| Encryption and decryption of data | Presentation layer |
A socket is an IP address plus a port, and the transport layer joins two such end points; MAC addresses travel in frame headers, IP addresses in packet headers.
The layers of the TCP/IP model and their functions PIN 2/27
2082 Baishakh · Q1
2080 Baishakh · Q1
The TCP/IP model is the four-layer model of the Internet protocol suite, developed for the ARPANET; its main goal is to interconnect different networks.
- Host-to-network (network access) layer: connects the host to the network so that it can send IP packets: framing, MAC addressing and transmission of bits; it combines the OSI data link and physical layers. Ethernet, Wi-Fi, PPP, DSL.
- Internet layer: lets hosts inject packets into any network and have them travel independently to the destination; defines IP, logical addressing and routing; connectionless, best effort. IP, ICMP, IGMP, ARP.
- Transport layer: end to end communication between processes, identified by ports: TCP (reliable, connection-oriented, ordered, flow controlled) and UDP (unreliable, connectionless, fast).
- Application layer: the protocols users work with; it also does the work of the OSI session and presentation layers. HTTP, SMTP, FTP, DNS, SSH, SNMP.
The protocols at each layer of the TCP/IP model PIN 2/27
2081 Baishakh · Q1
2070 Ashad · Q1
The TCP/IP model has four layers, and each uses its own protocols:
| Layer | Common protocols |
|---|---|
| Application | HTTP (80), HTTPS (443), FTP (20, 21), SMTP (25), POP3 (110), IMAP (143), DNS (53), DHCP (67, 68), Telnet (23), SSH (22), SNMP (161) |
| Transport | TCP (reliable, connection-oriented), UDP (connectionless, fast) |
| Internet | IP (IPv4, IPv6), ICMP, IGMP, ARP, RARP |
| Host-to-network | Ethernet (IEEE 802.3), Wi-Fi (IEEE 802.11), PPP, DSL, Frame Relay, ATM |
The port numbers in brackets identify the application protocols to the transport layer. Routing protocols (RIP, OSPF, BGP) serve the internet layer. IP is the single protocol every packet uses, so any application runs over any link.
ATM, a short note PIN 2/27
2081 Bhadra · Q10
2080 Bhadra · Q10
ATM (Asynchronous Transfer Mode) is a connection-oriented cell switching technology, the transfer mode of broadband ISDN, that carries voice, video and data in fixed 53-byte cells: a 5-byte header and a 48-byte payload. Small fixed cells are switched in hardware, with low and predictable delay.
- Header (UNI): GFC 4 bits, VPI 8, VCI 16, PT 3, CLP 1, HEC 8 (a CRC-8 over the header).
- Virtual paths and channels: a link carries virtual paths, each bundling virtual channels; the VPI/VCI pair names a connection (PVC or SVC).
- Layers: physical (TC, PMD), the ATM layer (headers, switching, multiplexing) and the AAL (CS, SAR), with types AAL1, AAL2, AAL3/4 and AAL5.
- Quality of service: CBR, VBR, ABR and UBR service categories.
- Drawback: 5 of every 53 bytes (9.4%) is overhead.
Five instances of networks in daily life PIN 1/27
2072 Chaitra · Q2
Networks are part of everyday life wherever two devices exchange data. Five instances:
- Digital payments: paying a canteen bill by scanning a QR code or using a mobile wallet; the phone app is a client that sends the payment request to the bank's server over mobile data.
- Communication: voice and video calls over WhatsApp or Viber to relatives abroad travel as IP packets (VoIP), far cheaper than international phone calls; email and chat work the same way.
- Education: online classes, notes shared in class groups, assignments submitted online and exam results published on the web.
- Entertainment: videos streamed on demand from YouTube, social media, and online multiplayer games that exchange moves in real time.
- Daily services and work: booking a ride or a bus ticket, paying electricity bills, online banking, and offices sharing printers, files and databases over a LAN.
In each case the network provides resource sharing, communication and access to remote information.
Types of network by size and geography PIN 1/27
2070 Ashad · Q2
By size and geographical spread, networks are of four types; networks joined together form an internetwork.
| Type | Area covered | Features | Example |
|---|---|---|---|
| PAN | 1 to 10 m, one person | low data rate, short range | Bluetooth earbuds and a phone |
| LAN | a room, building or campus, up to a few km | privately owned; high speed (100 Mbps to 10 Gbps); low delay and error rate | college lab Ethernet, Wi-Fi |
| MAN | a city, about 10 to 50 km | owned by ISPs or cable operators; usually fibre rings | a city fibre ring, a cable TV network |
| WAN | a country or continent | links leased from carriers; lower speed, higher delay; hosts joined through a subnet of routers | bank branches joined by leased lines, X.25, Frame Relay or MPLS |
Internetwork: different networks joined by routers or gateways; the Internet is the largest, joining LANs, MANs and WANs worldwide with TCP/IP. The span of a network decides its owner, speed, delay and error rate.
Network topology defined PIN 1/27
2070 Ashad · Q2
Network topology is the arrangement of the nodes and links of a network. The physical topology is the actual layout of the devices and cables; the logical topology is the path the signals actually follow (a hub wired as a star works logically as a bus).
- Bus: one shared backbone; cheap, but one break stops all.
- Star: each node linked to a central switch; easy to manage, but the switch is a weak point.
- Ring: nodes in a closed loop, with token passing.
- Mesh: every pair linked, links; robust but costly.
- Tree and hybrid: hierarchies and combinations of these.
The active networking framework against the legacy network PIN 1/27
2066 Bhadra · Q1b
An active network is a network whose nodes are programmable: besides forwarding packets, the routers execute code supplied by users or carried in the packets, and so perform computations on the data passing through them. A legacy (traditional) network is passive: its nodes only store and forward packets by their headers.
Framework of an active node: the NodeOS manages the node's channels, processor, memory and storage and isolates the programs; execution environments (such as a Java virtual machine) run the active code; active applications are the user programs inside them. An ANEP header directs each packet to its environment. Code arrives in every packet (capsule, the integrated approach) or is loaded in advance (programmable switch, the discrete approach).
| Point | Legacy network | Active network |
|---|---|---|
| Node's work | store and forward by header | forward and compute on contents |
| Programmed by | vendor firmware | users and packets |
| New service | years of standardisation | deployed quickly as code |
| Packet | header and data | code and data (capsule) |
| Intelligence | end systems only | end systems and network |
| Security, speed | simpler, faster | harder, slower |
Protocols and interfaces PIN 1/27
2070 Ashad · Q1
A protocol is a set of rules that peer entities, the same layer on two machines, use to communicate: the format, meaning and timing of the messages they exchange (syntax, semantics, timing). Examples: HTTP, TCP, IP, Ethernet.
An interface is the boundary between two adjacent layers on the same machine. It defines the primitive operations and services the lower layer offers the upper layer, with their parameters and results.
- Direction: a protocol is horizontal (peer to peer); an interface is vertical (layer to layer).
- Independence: a protocol can change without changing the interface, so layers stay replaceable.
- Example: TCP is the transport protocol between two hosts; the socket calls are the interface an application uses to reach it.
What a network architecture is PIN 1/27
2071 Chaitra · Q1
A network architecture is the set of layers and protocols of a network. Its specification gives enough detail for an implementer to build the software or hardware of each layer so that it obeys the correct protocol; implementation details and the interfaces inside one machine are not part of it. Examples: the TCP/IP architecture and IBM's SNA.
Service primitives for a connection-oriented service PIN 1/27
2075 Ashwin · Q1
A connection-oriented service is used through five service primitives:
| Primitive | Meaning |
|---|---|
LISTEN | block, waiting for an incoming connection |
CONNECT | establish a connection with a waiting peer |
RECEIVE | block, waiting for an incoming message |
SEND | send a message to the peer |
DISCONNECT | terminate the connection |
The server calls LISTEN, the client CONNECTs, both sides SEND and RECEIVE, and either side DISCONNECTs.
The significance of the OSI model PIN 1/27
2074 Ashwin · Q1
The OSI model is significant because it provides a common reference for describing and designing networks. It divides communication into seven layers with defined functions, separates services, interfaces and protocols so that a layer can change without disturbing the others, enables interoperability between vendors, guides layer by layer troubleshooting, and gives networking a common vocabulary ("layer 2 switch", "layer 3 router").
The X.25 packet format PIN 1/27
2068 Chaitra · Q6
X.25 is the ITU-T packet switching interface between a DTE and a DCE; at its packet layer, data travels in packets with a 3-octet header. The data packet with modulo 8 numbering is:
- GFI (4 bits): the Q bit (qualifier: control data for a PAD, or user data), the D bit (delivery confirmation: end to end or local acknowledgement) and two bits giving the numbering (01 modulo 8, 10 modulo 128).
- LCGN (4 bits) and LCN (8 bits): together a 12-bit virtual circuit number, up to 4095 circuits on a link.
- P(R) (3 bits): receive sequence number, the next packet expected; it acknowledges earlier packets.
- M bit: more data follows in the next packet.
- P(S) (3 bits): send sequence number.
- Last bit 0: a data packet; control packets end in 1 and use the octet as a type code (call request
00001011, call accepted00001111, clear request00010011). - User data: up to 128 bytes by default.
The packet travels inside a LAPB frame, between its flag, address and control fields and its FCS.
X.25 and Frame Relay compared PIN 1/27
2068 Baishakh · Q10
X.25 is a reliable packet switching interface using three layers, while Frame Relay is its faster successor, which keeps the virtual circuits but works only up to the data link layer.
| Basis | X.25 | Frame Relay |
|---|---|---|
| Layers | physical, link (LAPB), packet (PLP) | physical and data link only |
| Error control | detection and correction at every hop, by retransmission | detection only; bad frames dropped |
| Flow control | hop by hop and per circuit (windows, RR/RNR) | none; congestion notified by FECN, BECN, DE |
| Acknowledgements | at every hop | none in the network |
| Speed | low, typically up to 64 kbps | 56 kbps to 44.736 Mbps |
| Delay and overhead | high | low |
| Circuit identifier | 12-bit LCGN and LCN | 10-bit DLCI |
| Multiplexing | at layer 3 | at layer 2 |
| Signalling | in band (call packets) | out of band (DLCI 0, Q.933) |
| Suited to | noisy analog lines, terminal traffic | reliable digital lines, bursty LAN traffic |
Frame Relay is faster because lines became nearly error free and the end systems (TCP) recover lost data, so the per-hop checking was dropped.
The ATM adaptation layer PIN 1/27
2066 Bhadra · Q5b
The ATM adaptation layer (AAL) adapts user data to 48-byte cell payloads. Its convergence sublayer (CS) adds service-specific information (timing, sequence numbers, a CRC); its segmentation and reassembly (SAR) sublayer cuts the data into 48-byte payloads and rebuilds it at the far end.
| Type | Traffic | Use |
|---|---|---|
| AAL1 | constant bit rate with timing (class A) | voice, T1/E1 emulation |
| AAL2 | variable bit rate with timing (class B) | compressed voice and video |
| AAL3/4 | variable rate data, connection-oriented or connectionless (classes C, D) | data; 44-byte payload per cell |
| AAL5 | simple, efficient data (classes C, D) | IP over ATM; 8-byte trailer with CRC-32 |
2Physical layer
Circuit switching compared with packet switching HOT 7/27
2075 Ashwin · Q2
2074 Chaitra · Q3
2074 Ashwin · Q3
2069 Chaitra · Q2
2068 Chaitra · Q5
2068 Baishakh · Q1
2066 Bhadra · Q3b
Circuit switching reserves a dedicated path for the whole session, in three phases: setup, data transfer and teardown. Packet switching splits the data into packets, each with a header, that are stored and forwarded node by node over links shared with other users, as datagrams or along virtual circuits.
| Basis | Circuit switching | Packet switching |
|---|---|---|
| Path | dedicated for the session | no dedicated path; links shared |
| Setup | required before transfer | not required (datagram) |
| Bandwidth | fixed, reserved | dynamic, on demand |
| Idle capacity | wasted when silent | used by other packets |
| Transfer | continuous; no store-and-forward | store-and-forward at each node |
| Addressing | only during setup | header on every packet |
| Delay | setup delay, then constant | variable queuing delay |
| Order | always in order | may arrive out of order |
| Congestion | at setup: call blocked | per packet: queuing, loss |
| Switch failure | call is cut | packets rerouted |
| Charging | by time and distance | by data volume |
| Suited to | real-time voice | bursty data |
| Example | telephone network (PSTN) | the internet (IP) |
For the same message, packet switching finishes first because its packets overlap on successive links, while circuit switching pays a setup delay before its continuous stream starts.
Transmission media defined PIN 3/27
2076 Chaitra · Q2
2074 Chaitra · Q2
2071 Shrawan · Q2
A transmission medium is the physical path between a transmitter and a receiver that carries the signal (electric current, light or electromagnetic waves) from source to destination. It lies below the physical layer and is controlled by it.
- Guided (wired) media: the signal is confined to a solid path: twisted pair cable, coaxial cable, optical fiber.
- Unguided (wireless) media: an antenna radiates the signal through air or space: radio waves, microwaves (terrestrial and satellite), infrared.
The medium's bandwidth, attenuation and noise immunity decide a link's data rate and distance: a campus uses UTP in its labs, fiber in its backbone and Wi-Fi for laptops.
The transmission media, with their merits and demerits PIN 3/27
2076 Chaitra · Q2
2072 Kartik · Q2
2066 Poush · Q2
Transmission media are of two types: guided (wired), where the signal follows a cable, and unguided (wireless), where an antenna radiates it through air or space.
Guided media:
- Twisted pair: two insulated copper wires twisted to cancel noise; UTP and STP; Cat 5e to Cat 6A for LANs, also telephone lines. Merits: cheapest, easy to install. Demerits: noise, short range (100 m for Ethernet), easy to tap.
- Coaxial cable: a central conductor, insulation, a braided shield and a jacket; cable TV, CCTV. Merits: wider bandwidth and better shielding than twisted pair. Demerits: bulky, costlier, amplifiers needed every few km.
- Optical fiber: light guided in a glass core by total internal reflection; single mode and multimode; backbones and fiber to the home. Merits: very high bandwidth, low loss, immune to EMI, secure. Demerits: costly installation, fragile, needs splicing.
Unguided media:
- Radio waves (3 kHz to 1 GHz): omnidirectional; AM, FM, TV. Merits: long range, pass through walls, no alignment. Demerits: low data rate, interference, crowded spectrum.
- Microwaves (1 to 300 GHz): directional, line of sight; terrestrial links, satellites, mobile networks, Wi-Fi. Merits: high data rate, no cabling over rough terrain; satellites cover huge areas. Demerits: antennas must see each other, rain fade, satellite delay and cost.
- Infrared (300 GHz to 400 THz): short range, line of sight; remote controls. Merits: private to a room, no licence. Demerits: blocked by walls, disturbed by sunlight.
Switching defined PIN 3/27
2075 Chaitra · Q2
2073 Shrawan · Q2
2068 Baishakh · Q1
Switching is the process of forwarding data from a sender to a receiver through intermediate nodes (switches), each connecting an input port (ingress) to the output port (egress) that leads toward the destination. It avoids a dedicated link between every pair of devices: a mesh of n devices would need links.
Types: circuit switching (telephone network), message switching (telegraph) and packet switching (the internet), the last as datagram or virtual circuit.
Switching and multiplexing defined PIN 3/27
2079 Bhadra · Q2
2074 Ashwin · Q2
2069 Chaitra · Q2
Switching is the technique of connecting a sender to a receiver through intermediate nodes (switches or routers) that forward data from an input port to the output port leading to the destination, so that no dedicated link is needed between every pair of devices. Types: circuit, message and packet (datagram, virtual circuit) switching. Example: a telephone exchange connecting a call.
Multiplexing is the technique of sharing one link among several signals at the same time: a multiplexer combines n input channels into one link and a demultiplexer separates them at the other end. Types: FDM, WDM, TDM (synchronous, statistical) and CDM. Example: one E1 trunk carrying 30 calls.
Switching chooses the path through the network; multiplexing shares the capacity of each link on that path.
Virtual circuit switching PIN 3/27
2076 Ashwin · Q10
2070 Ashad · Q6
2066 Poush · Q6
Virtual circuit switching is a connection-oriented form of packet switching: a logical path, the virtual circuit, is set up between source and destination before data flows, and every packet then follows that path carrying only a short virtual circuit identifier (VCI).
- Setup: a setup request travels to the destination; each switch records an entry (incoming port and VCI to outgoing port and VCI) in its table; an acknowledgment returns.
- Data transfer: each switch looks up the packet's incoming VCI, replaces it with the outgoing VCI and forwards the packet; packets arrive in order.
- Teardown: a release request removes the table entries.
Types: PVC (permanent, configured by the operator) and SVC (switched, set up for each session). A VCI has only local significance and changes at each hop. Examples: X.25, Frame Relay (DLCI), ATM (VPI/VCI), MPLS (label).
ISDN: what it is, why it was developed, and its contribution PIN 3/27
2076 Ashwin · Q2
2071 Chaitra · Q2
2067 Ashad · Q3
ISDN (Integrated Services Digital Network) is an ITU-T standard for a fully digital, circuit-switched telephone network carrying voice, data, fax and video together, end to end, over the existing copper line: 64 kbps B channels carry user data, a D channel carries signalling, through the BRI (2B + D) and PRI (23B + D or 30B + D) interfaces.
Why developed: the analog local loop limited data rates, and voice, telex and data used separate networks; one integrated digital network gives one line, one interface and faster out-of-band signalling.
Contribution: digital access at 64 to 128 kbps (BRI) and 2.048 Mbps (PRI), voice and data together on one line, fast call setup, and the path to ATM.
ISDN architecture: channels, interfaces, functional groups and reference points PIN 3/27
2076 Ashwin · Q2
2075 Ashwin · Q2
2071 Chaitra · Q2
ISDN connects user devices to a digital ISDN exchange through standard functional groups joined at standard reference points:
- TE1: ISDN-compatible terminal (digital phone, PC with an ISDN card).
- TE2: non-ISDN terminal (analog phone); needs a TA (terminal adapter) to convert its signals.
- NT2: customer switching such as a PBX or router (layers 2 and 3).
- NT1: terminates the line, converting the four-wire S/T bus to the two-wire local loop (layer 1).
- Reference points: R (TE2 to TA), S (TE1 or TA to NT2), T (NT2 to NT1), U (NT1 to the exchange).
Channels: B (bearer) 64 kbps for user voice and data; D 16 or 64 kbps for signalling and packet data; H for higher rates (H0 384, H11 1536, H12 1920 kbps).
Interfaces: BRI = 2B + D = 144 kbps (192 kbps with framing) for homes and small offices; PRI = 23B + D at 1.544 Mbps (T1) or 30B + D at 2.048 Mbps (E1) for PBXs and businesses.
Working principle: a terminal sends a SETUP message on the D channel (Q.931 over LAPD); the exchange signals the call through the network (SS7) and assigns a B channel, which then carries 64 kbps of digital data end to end; release also goes over D.
Example: a small office BRI: a digital phone and a PC on the S bus, an old fax through a TA; one call and a 64 kbps data session at the same time.
Factors in choosing a transmission medium PIN 2/27
2081 Bhadra · Q2
2080 Bhadra · Q2
The factors weighed in choosing a transmission medium:
- Bandwidth and data rate needed, now and in future.
- Distance and attenuation: how far the signal goes before a repeater is needed.
- Cost: cable, connectors, equipment, installation and maintenance.
- Noise immunity: resistance to electromagnetic interference and crosstalk.
- Security: how easily the medium can be tapped.
- Ease of installation: weight, flexibility, skills needed.
- Environment and terrain: indoor or outdoor, rivers, hills.
- Mobility of the users, and the reliability and scalability required.
Example: Cat 6 UTP inside a building, fiber between buildings, Wi-Fi for laptops.
Types of multiplexing PIN 2/27
2080 Baishakh · Q2
2067 Ashad · Q3
The main types of multiplexing:
- FDM (frequency division): analog; the link bandwidth is divided into frequency bands, each signal modulated onto its own carrier, with guard bands between; all signals travel at once. Example: FM radio (88 to 108 MHz), cable TV.
- WDM (wavelength division): FDM for light; each signal on its own wavelength in one fiber, combined and separated by a prism or grating. Example: DWDM fiber backbones.
- TDM (time division): digital; the link's time is divided into slots used in turn, grouped into frames.
- Synchronous TDM: each input owns a fixed slot in every frame, even when idle, so slots are wasted. Example: T1, E1.
- Statistical TDM: slots are given only to inputs with data, each slot carrying its input's address. Example: data concentrators.
- CDM (code division): all stations send at once over the whole band, each multiplied by a unique orthogonal code; the receiver extracts one station by correlating with its code. Example: CDMA in 3G, GPS.
Switching and its types PIN 2/27
2075 Chaitra · Q2
2067 Ashad · Q4
Switching connects a sender to a receiver through intermediate switching nodes, which forward data from an input port to the output port toward the destination. Its types:
- Circuit switching: a dedicated path is set up before communication (setup, data transfer, teardown) and its bandwidth reserved for the whole session. Example: a telephone call.
- Message switching: the whole message is stored at each node and forwarded when the next link is free (store and forward); no setup, long delays. Example: telegraph.
- Packet switching: the message is divided into packets forwarded store-and-forward, sharing links on demand.
- Datagram: each packet routed independently by its full address (IP).
- Virtual circuit: a logical path set up first; packets carry a short VCI (Frame Relay, ATM).
Datagram and virtual circuit switching compared, with Frame Relay PIN 2/27
2081 Bhadra · Q2
2078 Bhadra · Q2
Datagram (packet) switching is connectionless: each packet carries the full destination address and is routed independently. Virtual circuit switching is connection-oriented: a path is set up first (setup, data transfer, teardown) and every packet follows it, carrying only a short virtual circuit identifier (VCI).
| Basis | Datagram | Virtual circuit |
|---|---|---|
| Setup | not needed | needed |
| Addressing | full source and destination address | short VC number |
| Routing | each packet independently | once at setup; all packets follow |
| Router state | none per connection | table entry per VC |
| Order | may arrive out of order | in order |
| Router failure | only packets in it lost | all VCs through it terminated |
| QoS, congestion control | difficult | easy with reserved resources |
| Examples | IP | X.25, Frame Relay, ATM, MPLS |
With respect to Frame Relay: Frame Relay is a virtual circuit network. Each frame carries a 10-bit DLCI, its VCI, instead of a destination address; switches forward frames by (input port, DLCI) table lookups and swap the DLCI hop by hop; circuits are PVCs set up by the carrier or SVCs set up by signalling; frames arrive in order, and congestion is signalled with the FECN, BECN and DE bits. A datagram network such as IP over the same links would route every packet by its full address, with no setup and no per-circuit state.
Functions of the physical layer in the TCP/IP model PIN 1/27
2072 Kartik · Q2
In the TCP/IP reference model the physical layer forms the lower part of the host-to-network (network access) layer; it moves raw bits as signals over the medium. Its functions:
- Physical characteristics: the medium, connectors and interface.
- Representation of bits: encoding bits as electrical, light or radio signals.
- Data rate: the number of bits sent per second.
- Synchronization of the sender's and receiver's clocks.
- Line configuration and topology: point-to-point or multipoint; star, bus, ring, mesh.
- Transmission mode: simplex, half-duplex or full-duplex.
Throughput defined PIN 1/27
2078 Bhadra · Q2
Throughput is the actual rate at which data is successfully delivered across a link or network over a period of time, measured in bits per second. It never exceeds the bandwidth, the link's maximum rate, because of overheads, congestion and retransmissions.
Causes of packet delay PIN 1/27
2074 Ashwin · Q3
A packet is delayed at every node by four causes, which add up to the nodal delay:
- Processing delay: checking the header and bit errors, choosing the output link.
- Queuing delay: waiting in the output buffer behind other packets; grows with congestion.
- Transmission delay: pushing all L bits onto a link of rate R, .
- Propagation delay: the signal crossing the link, .
Retransmissions after loss and many store-and-forward hops add more.
The common guided and unguided media in use today PIN 1/27
2081 Baishakh · Q2
Guided (wired) media in common use:
- Twisted pair: UTP Cat 5e, Cat 6 and Cat 6A for Ethernet LANs; telephone lines and DSL.
- Coaxial cable: cable TV and cable internet, CCTV.
- Optical fiber: single mode for backbones, fiber to the home and long-haul links; multimode inside buildings.
Unguided (wireless) media in common use:
- Radio waves: AM and FM radio, TV broadcasting.
- Microwaves: Wi-Fi (2.4, 5 and 6 GHz), 4G and 5G mobile networks, Bluetooth, terrestrial point-to-point links, satellite links (VSAT, satellite TV and internet).
- Infrared: TV remotes and short device-to-device links.
Three transmission media in detail PIN 1/27
2071 Shrawan · Q2
1. Twisted pair cable: two insulated copper wires twisted together, four pairs in an Ethernet cable; the twisting cancels noise and crosstalk. UTP is unshielded and cheap; STP adds a grounded shield. Categories Cat 5e to Cat 6A carry 1 to 10 Gbps up to 100 m. Uses: LANs, telephone loops, DSL. Merits: cheap, easy to install. Demerits: noise, short range.
2. Optical fiber: a glass core of higher refractive index inside a cladding of lower index; light pulses from an LED or laser are guided by total internal reflection and detected by a photodiode. Modes: multimode (step index, graded index) and single mode. Uses: backbones, fiber to the home, submarine cables. Merits: very high bandwidth, low loss, immune to EMI, secure. Demerits: costly and fragile.
3. Microwave (1 to 300 GHz): a focused beam between dish antennas in line of sight. Terrestrial links join towers tens of km apart (4 to 6 GHz and 21 to 23 GHz); satellite links relay through a transponder in orbit (uplink and downlink). Uses: long-haul telephony, mobile backhaul, TV distribution, VSAT. Merits: no cable over rivers and mountains, high data rate. Demerits: needs alignment and line of sight, rain fade, satellite delay.
One guided medium explained: twisted pair cable PIN 1/27
2081 Baishakh · Q2
Twisted pair cable consists of two insulated copper conductors twisted around each other; an Ethernet cable holds four such pairs in one jacket. The twisting makes external noise couple equally into both wires, so it cancels at the receiver, and different twist rates on neighbouring pairs reduce crosstalk.
- UTP (unshielded): no shield; cheap, light, flexible; the usual LAN cable.
- STP (shielded): a grounded foil or braid around the pairs; better noise immunity; costlier and stiffer.
- Categories: Cat 3 (16 MHz, 10 Mbps), Cat 5e (100 MHz, 1 Gbps), Cat 6 (250 MHz, 1 Gbps), Cat 6A (500 MHz, 10 Gbps), with RJ-45 connectors.
- Characteristics: an Ethernet segment reaches 100 m; analog lines need amplifiers every 5 to 6 km, digital lines repeaters every 2 to 3 km.
- Examples: the telephone local loop and ADSL; 100BASE-TX and 1000BASE-T Ethernet in a college lab; Power over Ethernet for IP cameras.
- Merits: cheapest, easy to install and extend. Demerits: susceptible to noise, short range, limited bandwidth, easy to tap.
Two guided media in detail: twisted pair and optical fiber PIN 1/27
2074 Ashwin · Q2
1. Twisted pair cable: two insulated copper wires twisted together (four pairs in an Ethernet cable); the twists cancel external noise and reduce crosstalk.
- Types: UTP (unshielded: cheap, flexible, common in LANs) and STP (a grounded foil or braid shield: better noise immunity, costlier).
- Categories: Cat 5e (1 Gbps), Cat 6 (250 MHz), Cat 6A (10 Gbps to 100 m), with RJ-45 connectors; Ethernet runs up to 100 m.
- Uses: telephone local loop, DSL, LANs. Merits: cheap, easy to install. Demerits: noise, attenuation, short range, easy to tap.
2. Optical fiber: a glass core of higher refractive index inside a cladding of lower index, then a buffer and a jacket; light is guided by total internal reflection.
- Modes: multimode step index and graded index (50 or 62.5 µm core, LED, short reach) and single mode (8 to 10 µm core, laser, tens of km).
- Uses: backbones, fiber to the home, submarine links. Merits: very high bandwidth, low loss (about 0.2 dB/km at 1550 nm), immune to EMI, secure, light. Demerits: costly installation and splicing, fragile.
Twisted pair, coaxial cable and optical fiber compared PIN 1/27
2074 Chaitra · Q2
| Basis | Twisted pair | Coaxial cable | Fiber optic |
|---|---|---|---|
| Signal | electrical | electrical | light |
| Structure | two insulated copper wires, twisted | central conductor, insulation, braided shield, jacket | glass core, cladding, buffer, jacket |
| Bandwidth | low | moderate, up to about 1 GHz | very high |
| Data rate | up to 10 Gbps over 100 m | up to a few Gbps | 10 Gbps a wavelength; terabits with WDM |
| Distance | 100 m (Ethernet) | hundreds of metres to a few km | km to tens of km |
| Noise immunity | low | good | immune to EMI |
| Attenuation | high | moderate | very low |
| Security | easy to tap | harder to tap | very hard to tap |
| Cost | cheapest | moderate | highest |
| Installation | easiest | moderate | difficult, needs splicing |
| Uses | LANs, telephone lines | cable TV, CCTV | backbones, fiber to the home |
All three are guided media: fiber leads on every count except cost and ease of installation, where twisted pair leads.
Types of twisted pair cable PIN 1/27
2068 Baishakh · Q2
Twisted pair cable (insulated copper pairs twisted to cancel noise) is classified three ways:
- By shielding: UTP (unshielded): no shield, cheap, flexible, used in most LANs; STP (shielded): a grounded foil or braid shield that cuts EMI and crosstalk, costlier and stiffer; variants F/UTP (foil over all pairs) and S/FTP (braid overall, foil on each pair).
- By category (TIA/EIA-568): Cat 3 (16 MHz, 10 Mbps), Cat 5 (100 MHz, 100 Mbps), Cat 5e (100 MHz, 1 Gbps), Cat 6 (250 MHz, 1 Gbps), Cat 6A (500 MHz, 10 Gbps), Cat 7 (600 MHz), Cat 8 (2000 MHz, 25 to 40 Gbps up to 30 m).
- By wiring at the RJ-45 ends: straight-through (the same pin order, T568B, at both ends: PC to switch), crossover (T568A at one end, T568B at the other: PC to PC, switch to switch), rollover (pins reversed: PC to a router's console port).
Block diagram of an optical fiber communication system, and its range PIN 1/27
2082 Bhadra · Q2
The transmitter turns the electrical message into light (LED or laser); the fiber, with repeaters or optical amplifiers on long links, carries it; the receiver (PIN or avalanche photodiode, amplifier, decoder) turns it back into the message.
Range: near-infrared light at 850, 1310 and 1550 nm, about 190 to 355 THz, far above the radio frequency range (up to 300 GHz).
Line of sight propagation PIN 1/27
2082 Bhadra · Q2
Radio waves travel by three modes: ground wave (below 2 MHz, following the earth's curve), sky wave (2 to 30 MHz, bent back by the ionosphere) and line of sight (above 30 MHz).
In line of sight (space wave) propagation very high frequency signals travel in straight lines, so the transmitting and receiving antennas must see each other, and the earth's curvature limits the range. The signal arrives two ways:
- Direct wave: straight from antenna to antenna.
- Ground-reflected wave: bounced off the ground; it adds to or cancels the direct wave (multipath fading).
Refraction bends radio waves slightly, so radio line of sight exceeds optical: km, with K = 4/3 and h in metres. Uses: FM, TV, microwave links, mobile phones, satellites.
Multiplexing and its importance PIN 1/27
2080 Baishakh · Q2
Multiplexing is the technique of sending several signals over one shared link at the same time: a multiplexer (MUX) combines n input channels into one link, and a demultiplexer (DEMUX) separates them at the far end.
Importance:
- Efficient use of bandwidth: a link's capacity is far larger than one user needs.
- Lower cost: one cable or trunk instead of n, with less installation and maintenance.
- Enables large networks: telephone trunks, radio and TV broadcasting, cable TV, mobile networks and fiber backbones.
- Scalability: more users are added without new lines.
Example: one E1 trunk carries 30 telephone calls on one link.
Switching compared with multiplexing PIN 1/27
2073 Shrawan · Q2
| Basis | Switching | Multiplexing |
|---|---|---|
| Purpose | connects a sender to a receiver across the network | shares one link among many signals |
| Where | at nodes inside the network | at the two ends of a link |
| Device | switch, router, exchange | MUX and DEMUX |
| Types | circuit, message, packet | FDM, WDM, TDM, CDM |
| Example | exchange routing a call | E1 trunk carrying 30 calls |
Data switching and its types, with practical examples PIN 1/27
2070 Chaitra · Q2
Data switching is the forwarding of data from a sender to a receiver through intermediate switching nodes, each passing what arrives on an input port to the output port that leads toward the destination. It avoids a dedicated link between every pair of devices (a mesh of n devices needs links).
1. Circuit switching: a dedicated path is reserved end to end before transfer, in three phases: setup, data transfer, teardown. Bandwidth is guaranteed and the delay constant, but the circuit stays idle during silences. Practical example: a landline call through the PSTN; ISDN B channels.
2. Message switching: the whole message, with its destination address, is stored at each node and forwarded when the next link is free (store and forward); no setup, but large storage and long delays. Practical example: the old telegraph and telex networks.
3. Packet switching: the message is split into packets with headers; nodes store and forward them, sharing links on demand, and packets pipeline across hops.
- Datagram: connectionless; each packet carries the full address and is routed independently, possibly out of order. Practical example: IP routers in the internet.
- Virtual circuit: a logical path is set up first; packets carry a short VCI and follow it in order; PVC or SVC. Practical example: X.25, Frame Relay, ATM, MPLS in ISP backbones.
Circuit switching suits constant-rate real-time voice; packet switching suits bursty data and carries almost all traffic today.
Switching in modern computer networks PIN 1/27
2079 Bhadra · Q2
Modern computer networks use packet switching: data is split into packets with headers, and each node stores, checks and forwards them (store and forward), sharing links statistically among all users.
- Datagram switching: the internet's IP routers forward every packet independently by its destination address using routing tables; no setup, connectionless, robust to failures.
- Virtual circuit switching: MPLS in ISP backbones, and earlier Frame Relay and ATM, set up a path and forward by short labels (VCIs), giving traffic engineering and QoS.
- Frame switching in LANs: Ethernet switches forward frames by MAC address, store-and-forward or cut-through.
Circuit switching survives only in the legacy telephone network; voice now travels as VoIP and VoLTE packets.
Why circuit switching suits real-time communication PIN 1/27
2080 Bhadra · Q2
Circuit switching suits real-time communication (voice, live video) because:
- Dedicated bandwidth: a fixed channel is reserved for the whole call, so no other traffic competes and no congestion arises during the call.
- Constant, low delay: no store-and-forward and no queuing at switches; data flows at propagation speed, with no jitter.
- In-order delivery: all data follows one fixed path, so nothing is reordered or reassembled.
- No per-packet overhead: no headers to process, no loss from buffer overflow.
- Setup is paid once, before the conversation starts.
Example: a telephone call on the PSTN.
The telephone defined PIN 1/27
2068 Chaitra · Q3
A telephone is an instrument that converts speech (sound waves) into an electrical signal for transmission over a line, and converts the received signal back into sound, so that two people can talk at a distance (Alexander Graham Bell, patented 1876). Its parts: transmitter (microphone), receiver (earpiece), hook switch, dialler (rotary pulses or DTMF tones), ringer, and a hybrid circuit that couples the two-wire line to the handset.
The E1 telephone hierarchy PIN 1/27
2073 Shrawan · Q2
E1 is the ITU-T (European) digital carrier that time-division multiplexes 32 channels of 64 kbps into one 2.048 Mbps stream.
- Basic channel (E0): voice sampled 8000 times a second at 8 bits a sample: 64 kbps.
- Frame: 32 time slots of 8 bits (256 bits) every 125 µs: = 2.048 Mbps.
- TS0: frame synchronization and alarms; TS16: signalling; TS1 to TS15 and TS17 to TS31: 30 voice channels.
| Level | Rate | Voice channels |
|---|---|---|
| E1 | 2.048 Mbps | 30 |
| E2 (4 E1) | 8.448 Mbps | 120 |
| E3 (4 E2) | 34.368 Mbps | 480 |
| E4 (4 E3) | 139.264 Mbps | 1920 |
Each level adds framing and justification bits. E1 is used in Europe and most of the world; North America uses T1 (24 channels, 1.544 Mbps).
3Data link layer
Functions of the data link layer HOT 5/27
2082 Baishakh · Q2
2074 Chaitra · Q3
2072 Kartik · Q3
2071 Shrawan · Q3
2066 Poush · Q4
The data link layer (layer 2 of the OSI model) delivers frames reliably from one node to the next over a single link. Its functions:
- Framing: divides the bit stream from the physical layer into frames and delimits the start and end of each frame (character count, byte stuffing, bit stuffing).
- Physical addressing: puts the MAC addresses of the sender and the receiver in the frame header.
- Flow control: prevents a fast sender from overrunning a slow receiver (stop and wait, sliding window).
- Error control: detects damaged frames with a CRC in the trailer and recovers damaged or lost frames by retransmission (ARQ), using acknowledgements, timers and sequence numbers.
- Access control: on a shared medium, decides which station may transmit next (CSMA/CD, token passing).
- Service interface and link management: gives the network layer unacknowledged connectionless, acknowledged connectionless or acknowledged connection-oriented service, and sets up and releases connections.
In IEEE 802 LANs these jobs are shared by the LLC sublayer (interface to the network layer, flow and error control) and the MAC sublayer (framing, addressing, medium access, error detection).
Framing and the framing methods HOT 5/27
2075 Chaitra · Q3
2072 Chaitra · Q3
2071 Shrawan · Q3
2070 Ashad · Q3
2069 Chaitra · Q3
Framing is the division of the bit stream from the physical layer into frames, with the start and the end of each frame delimited, so that the receiver can find frame boundaries and check each frame separately. A frame has a header (addresses, control), a payload (data) and a trailer (error check). The framing methods are:
- Character count: a field in the header gives the number of characters (bytes) in the frame, and the receiver counts that many to find the end. If the count is corrupted in transit, the receiver loses synchronisation and cannot find the start of the next frame, so it is rarely used alone.
- Flag bytes with byte stuffing: each frame begins and ends with a special FLAG byte. If the FLAG pattern appears in the data, the sender inserts an escape byte (ESC) before it, and an ESC in the data is sent as ESC ESC; the receiver removes the escapes. Example: A FLAG B is sent as A ESC FLAG B. Used in PPP (FLAG 0x7E, ESC 0x7D); it depends on 8-bit characters.
- Starting and ending flags with bit stuffing: each frame begins and ends with the flag
01111110. After every five consecutive 1s in the data, the sender stuffs a 0; the receiver deletes the 0 that follows five 1s. Example:01001111110111110is sent as01111110 0100111110101111100 01111110. It works with any number of bits per character; used in HDLC. - Physical layer coding violations: possible where the line code has redundancy. In Manchester coding each bit is high-low or low-high, so the unused high-high and low-low patterns delimit frames; 4B/5B uses spare code groups (J, K) as delimiters.
Many protocols combine a count with flags for extra safety.
Why channel access control is essential PIN 3/27
2073 Shrawan · Q3
2068 Chaitra · Q4
2067 Ashad · Q5
On a broadcast link many stations share one channel; if two transmit at the same time, their signals collide and both frames are lost. A channel access mechanism is therefore essential:
- It avoids or resolves collisions, so bandwidth is not wasted on garbled frames.
- It uses the channel efficiently, keeping it busy with useful frames.
- It gives fair access to every station, so none monopolises the channel.
- It bounds delay and supports priority (token passing), which real-time traffic needs.
- It lets many stations share one medium at low cost.
So medium access control is a core function of the data link layer, performed by its MAC sublayer.
ALOHA PIN 3/27
2079 Bhadra · Q10
2075 Ashwin · Q10
2070 Ashad · Q10
ALOHA is the earliest random access protocol (University of Hawaii, 1971): a station transmits whenever it has data, waits for an acknowledgement, and if none arrives assumes a collision and retransmits after a random backoff time.
- Pure ALOHA: frames are sent at any time; a frame collides with any frame started within one frame time before or after it, so the vulnerable time is . Throughput , at most 18.4 % at .
- Slotted ALOHA: time is divided into slots of length and frames start only at slot boundaries, so the vulnerable time is . Throughput , at most 36.8 % at .
Here is the mean number of frames offered per frame time. ALOHA is simple but efficient only at light load; CSMA improves on it by sensing the channel first.
Virtual LAN (VLAN) PIN 3/27
2082 Bhadra · Q10
2080 Baishakh · Q10
2068 Baishakh · Q3
A VLAN (virtual LAN) is a logical group of stations on one or more switches that forms a separate broadcast domain, as if it were its own LAN, defined by configuration rather than by physical wiring.
- Membership: by switch port (the most common), MAC address, IP address or application.
- Tagging (IEEE 802.1Q): on a trunk link carrying several VLANs, a 4-byte tag is inserted after the source address: TPID
0x8100, 3-bit priority, 1-bit DEI and a 12-bit VLAN ID (1 to 4094). Access ports carry untagged frames of one VLAN. - Inter-VLAN routing: traffic between VLANs passes through a router (router on a stick) or a layer 3 switch.
- Advantages: smaller broadcast domains, better security by separating groups, users grouped by function rather than location, moves without rewiring, and lower cost.
Piggybacking PIN 2/27
2081 Bhadra · Q3
2075 Ashwin · Q3
Piggybacking is the technique of carrying the acknowledgement for received frames in an outgoing data frame instead of sending a separate acknowledgement frame. In two-way communication each data frame holds two numbers: its own sequence number and an acknowledgement number, the next frame expected from the other side.
- Advantages: better use of the bandwidth (fewer frames, headers and trailers), less processing and fewer interrupts at both ends.
- Drawback: an acknowledgement may be held up waiting for outgoing data, so an ack timer sends a separate ACK if no data frame is ready in time.
Example: the N(R) field of an HDLC I-frame, and TCP's acknowledgement number on data segments.
Flow control at the data link layer PIN 2/27
2075 Ashwin · Q10
2074 Ashwin · Q10
Flow control at the data link layer is the set of procedures that limits how much data the sender may transmit before it receives an acknowledgement, so that a fast sender does not overflow the buffer of a slow receiver. Two mechanisms:
- Stop and wait: the sender sends one frame and waits for its ACK before sending the next. Simple, but the link idles for a round trip after each frame: , with .
- Sliding window: the sender may send up to frames, numbered modulo , before waiting; each ACK names the next frame expected and slides the window forward. , or 1 when .
With two-way traffic the ACKs are piggybacked on data frames, and with retransmission added the sliding window becomes go-back-N or selective repeat ARQ.
HDLC PIN 2/27
2078 Bhadra · Q10
2073 Shrawan · Q10
HDLC (High-level Data Link Control) is a bit-oriented ISO protocol for point-to-point and multipoint links, using bit stuffing and sliding window flow and error control.
- Stations: primary (sends commands), secondary (sends responses), combined (both).
- Configurations: unbalanced (one primary, one or more secondaries) and balanced (two combined stations).
- Modes: NRM (a secondary sends only when polled), ARM (a secondary may send without permission), ABM (combined stations, either may send at any time).
- Frame: flag
01111110, address, control (8 or 16 bits), information, FCS (16 or 32-bit CRC), flag. - Frame types: I-frames carry data with N(S) and a piggybacked N(R); S-frames carry flow and error control (RR, RNR, REJ, SREJ); U-frames carry link management (SNRM, SABM, DISC, UA).
The MAC sublayer PIN 2/27
2081 Baishakh · Q10
2073 Shrawan · Q3
The MAC (medium access control) sublayer is the lower sublayer of the data link layer that controls access to a shared (broadcast) medium: it decides which station may transmit next when several stations compete for one channel.
- Functions: builds frames for its LAN, adds 48-bit MAC (physical) addresses, runs the multiple access protocol, and detects errors with the FCS.
- Protocols: random access (ALOHA, CSMA, CSMA/CD in Ethernet, CSMA/CA in Wi-Fi), controlled access (reservation, polling, token passing in token bus and token ring) and channelization (FDMA, TDMA, CDMA).
- Standards: IEEE 802.3, 802.4, 802.5 and 802.11 each define their own MAC under the common LLC (802.2).
Without it, simultaneous transmissions would collide and the channel would be wasted.
Multiple access protocols PIN 2/27
2075 Chaitra · Q3
2071 Chaitra · Q3
Multiple access protocols are the rules by which many stations sharing one broadcast channel decide who transmits and when, so as to avoid or resolve collisions. They are of three types:
- Random access: ALOHA, CSMA, CSMA/CD, CSMA/CA.
- Controlled access: reservation, polling, token passing.
- Channelization: FDMA, TDMA, CDMA.
CSMA against CSMA/CD PIN 2/27
2078 Bhadra · Q3
2070 Ashad · Q5
Both sense the carrier before transmitting, but CSMA/CD also listens while transmitting and reacts to a collision at once.
| Point | CSMA | CSMA/CD |
|---|---|---|
| Listening | before transmitting only | before and during transmission |
| On a collision | keeps sending the whole damaged frame | stops at once and sends a short jam signal |
| Time wasted per collision | a whole frame time | about two propagation delays plus the jam |
| Retransmission | by the persistence method | binary exponential backoff, up to 16 attempts |
| Requirements | carrier sensing | also listening while sending, and a minimum frame size |
| Throughput and delay | lower throughput, more delay | higher throughput, less delay |
So CSMA/CD wastes far less channel time per collision, which is why classic Ethernet uses it.
IEEE 802.4 token bus PIN 2/27
2081 Bhadra · Q10
2076 Ashwin · Q10
Token bus (IEEE 802.4) is a LAN whose stations are connected to a physical bus but pass a token among themselves in a logical ring; only the token holder may transmit.
- Logical ring: each station knows its successor and predecessor; the token passes in descending order of address, and the lowest address passes it back to the highest.
- Operation: the token holder sends frames until its token holding time expires, then passes the token to its successor.
- Priority: four access classes, 0, 2, 4 and 6.
- Ring maintenance: claim token (start-up, lost token), solicit successor (new stations join), set successor (a station leaves or fails).
- Physical layer: 75-ohm broadband coaxial cable at 1, 5 or 10 Mbps.
Collision-free with a bounded delay, it was used in factory automation (MAP).
FDDI and its features PIN 2/27
2074 Chaitra · Q10
2072 Chaitra · Q3
FDDI (Fiber Distributed Data Interface) is a 100 Mbps token passing LAN and backbone standard (ANSI X3T9.5) using optical fiber in two counter-rotating rings. Its features:
- 100 Mbps over multimode fiber (copper version CDDI), with 4B/5B coding at 125 Mbaud.
- Dual counter-rotating rings: the primary carries data, the secondary stands by for faults.
- Large coverage: up to 1000 physical connections (about 500 dual attachment stations) on up to 200 km of fiber, with up to 2 km between stations.
- Timed token protocol: guaranteed bandwidth for synchronous traffic and the rest for asynchronous traffic; early token release.
- Frames of up to 4500 bytes with a 32-bit CRC.
- Station types: dual attachment stations (DAS) and single attachment stations (SAS) through concentrators.
- Fault tolerance: the rings wrap on a fault; optical bypass switches; dual homing.
Services provided by the data link layer PIN 1/27
2066 Bhadra · Q2a
The data link layer provides three kinds of service to the network layer:
- Unacknowledged connectionless: frames are sent independently with no acknowledgement; a lost frame is not recovered at this layer. Used on low-error links such as Ethernet.
- Acknowledged connectionless: no connection, but each frame is acknowledged and resent if no acknowledgement arrives in time. Used on unreliable links such as Wi-Fi.
- Acknowledged connection-oriented: a connection is established, numbered frames are delivered exactly once and in order, and the connection is released (HDLC).
Design issues of the data link layer PIN 1/27
2075 Ashwin · Q3
The design issues of the data link layer are:
- Service to the network layer: whether to offer unacknowledged connectionless, acknowledged connectionless or acknowledged connection-oriented service.
- Framing: breaking the bit stream into frames and finding the frame boundaries.
- Error control: detecting errors (CRC) and recovering lost or damaged frames with acknowledgements, timers and sequence numbers.
- Flow control: keeping a fast sender from swamping a slow receiver.
- Medium access and addressing: on broadcast links, deciding who may transmit and identifying stations by MAC address.
Functions of the LLC and MAC sublayers PIN 1/27
2070 Ashad · Q3
IEEE 802 divides the data link layer into two sublayers.
LLC (logical link control, IEEE 802.2), the upper sublayer:
- gives one interface to the network layer for every type of LAN;
- multiplexes several network protocols over one link using service access points (DSAP, SSAP);
- provides flow control and error control (sequencing, acknowledgements) when needed;
- offers unacknowledged connectionless (type 1), connection-oriented (type 2) and acknowledged connectionless (type 3) service.
MAC (medium access control), the lower sublayer:
- builds the frame in the format of its own LAN;
- adds 48-bit MAC (physical) addresses;
- controls access to the shared medium: CSMA/CD (802.3), token passing (802.4, 802.5), CSMA/CA (802.11);
- detects errors with the FCS (CRC) in the trailer.
Framing with bit stuffing PIN 1/27
2081 Bhadra · Q10
Framing with bit stuffing is a bit-oriented framing method in which every frame begins and ends with the flag pattern 01111110.
- Stuffing at the sender: whenever the data contains five consecutive 1s, the sender inserts (stuffs) a 0 after them, so six 1s, the flag pattern, never appear inside the data.
- Destuffing at the receiver: after five consecutive 1s, a following 0 is removed; a 1 followed by 0 is the flag, the end of the frame.
- Transparency: any bit pattern can be carried, and a frame need not be a whole number of bytes.
- Used in: HDLC and its family (LAPB, LAPD).
Example: the data 01001111110111110 becomes 0100111110101111100 (two 0s stuffed), and the frame sent is 01111110 0100111110101111100 01111110.
One method of framing and one of flow control PIN 1/27
2066 Bhadra · Q2a
Framing method: bit stuffing. Each frame starts and ends with the flag 01111110. The sender inserts a 0 after every five consecutive 1s in the data, so the flag never appears inside a frame, and the receiver removes the 0 after every five 1s. For example, the data 01001111110111110 is sent as 01111110 0100111110101111100 01111110. It works with any number of bits per character and is used in HDLC.
Flow control method: stop and wait. Flow control prevents a fast sender from overrunning a slow receiver.
- The sender transmits one frame and starts a timer.
- The receiver accepts the frame and returns an acknowledgement (ACK) when ready for the next.
- The sender transmits the next frame only after the ACK arrives.
- If the timer expires without an ACK, the frame is sent again; frames are numbered 0 and 1, so the receiver discards duplicates.
It is simple and never overruns the receiver, but the link idles for a round trip after each frame: efficiency , where .
Error detection against error correction PIN 1/27
2070 Chaitra · Q3
Error detection only finds out whether a received frame contains errors; error correction finds which bits are wrong and repairs them at the receiver.
| Point | Error detection | Error correction |
|---|---|---|
| Purpose | to know that an error occurred | to locate the wrong bits and fix them |
| Redundant bits | few (one parity bit, a 16 or 32-bit CRC) | many (3 check bits for 4 data bits in Hamming (7,4)) |
| Action on an error | discard the frame; the sender retransmits (ARQ, backward error correction) | the receiver corrects it itself (forward error correction, FEC) |
| Hamming distance needed | to detect errors | to correct errors |
| Return channel | needed, for retransmission | not needed |
| Techniques | parity, checksum, CRC | Hamming code, Reed-Solomon, convolutional codes |
| Suited to | low-error wired links | noisy or long-delay links: satellite, wireless, storage |
Example: an even parity bit on 1001101 detects one flipped bit but cannot tell which; the Hamming (7,4) code computes a syndrome that gives the position of the wrong bit, which is then flipped back.
Hamming distance PIN 1/27
2082 Baishakh · Q3
The Hamming distance between two codewords of equal length is the number of bit positions in which they differ, found by XORing them and counting the 1s. Example: 10101 XOR 11110 = 01011, so the distance is 3. The smallest distance between any two valid codewords of a code is its minimum distance .
Using the Hamming distance in error control PIN 1/27
2082 Baishakh · Q3
The minimum Hamming distance of a code fixes its error control power: detecting up to errors needs , and correcting up to errors needs . So the data link layer chooses a code to suit the link: even parity () detects one error; the Hamming (7,4) code () corrects one. A received word that is not a valid codeword shows an error; the receiver either corrects it to the nearest codeword (FEC) or discards it and asks for retransmission (ARQ).
Piggybacking in data link flow control PIN 1/27
2081 Bhadra · Q3
In sliding window flow control with traffic in both directions, every data frame carries seq, its own sequence number, and ack, the number of the next frame expected from the other station. The ack field acknowledges all earlier frames and slides the other sender's window forward, so it can send new frames without separate ACK frames. If no data frame is ready before the ack timer expires, a separate ACK is sent so that the other sender does not time out.
Two sliding window protocols and the advantages of piggybacking PIN 1/27
2066 Poush · Q4
- Go-back-N: the sender may have up to unacknowledged frames; the receiver accepts frames only in order (window 1). When a frame is lost or damaged, the sender resends it and every frame sent after it.
- Selective repeat: both windows are up to ; the receiver buffers out-of-order frames and sends a NAK for the missing one, and only that frame is resent.
Advantages of piggybacking (the ACK carried in a returning data frame): fewer separate ACK frames, so better use of the bandwidth; less processing and fewer interrupts; the window advances without extra frames.
The ways of backward error correction (ARQ) PIN 1/27
2082 Bhadra · Q3
Backward error correction means the receiver only detects an error and the sender corrects it by retransmission, called ARQ (automatic repeat request), using sequence numbers, ACKs, NAKs and timers. Its three ways are:
- Stop and wait ARQ: one frame at a time with 1-bit sequence numbers; the sender keeps a copy and resends it when its timer expires (damaged or lost frame, or lost ACK); duplicates are discarded by sequence number.
- Go-back-N ARQ: up to frames outstanding; the receiver accepts frames in order only; on a NAK or a timeout the sender resends the erroneous frame and all frames after it.
- Selective repeat ARQ: windows up to ; the receiver buffers out-of-order frames and only the damaged or lost frame is resent.
Go-back-N ARQ PIN 1/27
2080 Bhadra · Q10
Go-back-N ARQ is a sliding window error control protocol in which the sender transmits several frames before receiving an acknowledgement and, on an error, goes back and resends from the erroneous frame.
- Sender window: up to outstanding frames with -bit sequence numbers (7 for ); a copy of each is kept until acknowledged.
- Receiver window: 1; frames are accepted only in order, and any frame after a missing one is discarded.
- Acknowledgements: cumulative; ACK confirms all frames before ; a NAK may report the missing frame.
- Retransmission: when frame is lost or damaged (NAK or timeout), the sender resends frame and every frame after it.
Example: frames 0 to 4 are sent and frame 2 is lost; the receiver discards 3 and 4 and sends NAK 2; the sender resends 2, 3 and 4.
The receiver is simple, but good frames are resent, which wastes bandwidth on noisy links.
The channel allocation problem PIN 1/27
2072 Kartik · Q3
The channel allocation problem is how to allocate a single broadcast channel among many competing users. There are two approaches.
Static allocation: the channel is divided into fixed parts, frequency bands (FDM) or time slots (TDM), one per user. It suits a few users with steady traffic (radio broadcasting, telephone trunks) but wastes capacity for bursty data: idle users' shares are lost and busy users cannot borrow them. With fixed subchannels the mean delay grows times:
Example: a 100 Mbps channel with 10,000-bit frames arriving at 5000 frames/s gives = 200 µs; divided statically into ten 10 Mbps channels, = 2 ms.
Dynamic allocation: the channel is given on demand, assuming independent stations, one shared channel, observable collisions, continuous or slotted time, and carrier sense or not. Multiple access protocols (ALOHA, CSMA/CD, token passing) implement it and use the channel far better for bursty traffic.
Pure ALOHA against slotted ALOHA, with the condition for no collision PIN 1/27
2082 Bhadra · Q3
| Point | Pure ALOHA | Slotted ALOHA |
|---|---|---|
| Transmission | at any time | only at the start of a slot |
| Time | continuous; no synchronisation | slots of one frame time; clocks synchronised |
| Vulnerable time | ||
| Condition for no collision | no other station starts a frame within before or after the frame's start | no other station transmits in the same slot |
| Probability of success | ||
| Throughput | ||
| Maximum throughput | 18.4 % at | 36.8 % at |
| Complexity | simpler | needs slot timing |
Here is the frame time and the frames offered per frame time. Slotted ALOHA halves the vulnerable time and so doubles the maximum throughput.
How CSMA works PIN 1/27
2070 Ashad · Q5
CSMA (carrier sense multiple access) works on "listen before talk": a station first senses the medium and transmits only if it is idle. If it is busy, the station follows its persistence method: 1-persistent (keep sensing, send as soon as it is idle), non-persistent (wait a random time, then sense again) or p-persistent (when idle, send with probability ). Collisions can still occur through propagation delay: a station may sense the medium idle before another's signal reaches it, so the vulnerable time equals the propagation time.
How a collision is detected in CSMA/CD PIN 1/27
2082 Baishakh · Q2
In CSMA/CD a station keeps monitoring the medium while it transmits and compares what it receives with what it sends:
- On coaxial cable: the transceiver measures the signal level (voltage, energy) on the cable; a level higher than its own transmission produces shows that another signal is present: a collision.
- On twisted pair: activity on the receive pair while the station is transmitting signals a collision.
On detection the station aborts and sends a 32-bit jam signal so that all stations recognise the collision. Detection works only while the frame is still being transmitted, so the frame time must be at least twice the propagation delay (): hence Ethernet's minimum frame of 64 bytes.
What a collision is and how it occurs PIN 1/27
2076 Chaitra · Q3
A collision occurs when two or more stations on a shared medium transmit at overlapping times, so their signals add together and all the frames involved are garbled and lost. It happens because a station senses the medium idle before another station's signal has reached it (propagation delay), so both start transmitting; or because several stations waiting for a busy medium all start the moment it becomes idle.
How collisions are reduced in IEEE 802.3 and IEEE 802.11 PIN 1/27
2076 Chaitra · Q3
IEEE 802.3 (Ethernet) uses CSMA/CD:
- Carrier sense: a station transmits only when the medium is idle (1-persistent), after a 96-bit interframe gap.
- Collision detection: it listens while transmitting, aborts at once on a collision and sends a 32-bit jam.
- Binary exponential backoff: after the th collision it waits a random 0 to slot times, which spreads the retries out; at most 16 attempts.
- Minimum frame of 64 bytes, so every collision is detected; switched full-duplex Ethernet removes collisions entirely.
IEEE 802.11 (Wi-Fi) uses CSMA/CA, since a radio cannot detect collisions:
- Interframe spaces: a station waits for a DIFS of idle channel before contending; ACKs wait only a SIFS and so go first.
- Contention window: a random backoff counted down only while the channel is idle, doubled after each failure.
- Acknowledgements: every frame is acknowledged; no ACK means retransmission.
- RTS/CTS with NAV: every station that hears either frame defers for the announced time, which solves the hidden station problem.
Why CSMA/CD is not applicable in a wireless LAN PIN 1/27
2081 Baishakh · Q3
CSMA/CD cannot be used in a wireless LAN because:
- a radio cannot receive while it transmits (its own signal swamps incoming ones), so it cannot detect collisions;
- of the hidden station problem: two stations out of range of each other both sense an idle channel and their frames collide at the receiver;
- signals fade, so the sender's view of the channel differs from the receiver's, where collisions actually occur.
How DSSS is applied in wireless transmission PIN 1/27
2066 Bhadra · Q3a
DSSS (direct sequence spread spectrum) spreads each data bit over a wide band by replacing it with a sequence of chips:
- Spreading: each bit is XORed with a chip code; IEEE 802.11 uses the 11-chip Barker sequence, so a 1 is sent as
10110111000and a 0 as01001000111, at 11 Mchips/s for 1 Mbps. - Transmission: the chips occupy a 22 MHz channel in the 2.4 GHz band at low power density.
- Despreading: the receiver correlates the chips with the same code to recover each bit; narrowband interference and multipath echoes are spread out and suppressed (a processing gain of about 10.4 dB).
It is used in 802.11 (1 and 2 Mbps) and 802.11b (up to 11 Mbps).
The Ethernet (IEEE 802.3) frame and its fields PIN 1/27
2079 Bhadra · Q3
- Preamble (7 bytes): alternating
10101010, for the receiver's clock synchronisation. - SFD (1 byte):
10101011, signals the start of the frame. - Destination address (6 bytes): MAC address of the receiver (unicast, multicast or broadcast).
- Source address (6 bytes): MAC address of the sender.
- Length/Type (2 bytes): up to 1500, the length of the data field; 1536 or more, the type of the encapsulated protocol (
0x0800IPv4,0x0806ARP). - Data and padding (46 to 1500 bytes): the network layer packet, padded to the 46-byte minimum.
- FCS (4 bytes): CRC-32 for error detection.
From destination address to FCS the frame is 64 to 1518 bytes; the 64-byte minimum lets CSMA/CD detect a collision while the frame is still being sent.
Ethernet (802.3) cable standards PIN 1/27
2082 Baishakh · Q2
In each name the number is the speed in Mbps, "Base" means baseband, and the last part is the segment length in hundreds of metres or the medium (T twisted pair, F or X fiber).
| Standard | Medium | Max segment |
|---|---|---|
| 10Base5 | thick coaxial cable | 500 m |
| 10Base2 | thin coaxial cable | 185 m |
| 10BaseT | UTP, Cat 3 or better | 100 m |
| 10BaseF | multimode fiber | 2000 m |
| 100BaseTX | UTP, Cat 5 | 100 m |
| 100BaseFX | multimode fiber | 2000 m |
| 1000BaseT | UTP, Cat 5e | 100 m |
| 1000BaseSX | multimode fiber | 550 m |
| 1000BaseLX | single-mode fiber | 5 km |
| 10GBase-SR, LR, ER | multimode, single-mode fiber | 300 m, 10 km, 40 km |
Optical fiber Ethernet standards with examples PIN 1/27
2070 Ashad · Q5
The optical fiber Ethernet standards carry light over multimode or single-mode fiber; they reach much farther than copper's 100 m and are immune to electrical interference and lightning.
| Standard | Speed | Fiber and light | Reach | Example use |
|---|---|---|---|---|
| 10BaseF (10Base-FL) | 10 Mbps | multimode, 850 nm | 2 km | early links between buildings |
| 100BaseFX | 100 Mbps | multimode, 1300 nm | 2 km (full duplex) | a switch in one block to a switch in another |
| 1000BaseSX | 1 Gbps | multimode, 850 nm short-wave laser | 220 to 550 m | backbone up the floors of a building |
| 1000BaseLX | 1 Gbps | 1310 nm long-wave laser, multimode or single-mode | 550 m or 5 km | campus backbone to distant buildings |
| 10GBase-SR, LR, ER | 10 Gbps | 850 nm multimode; 1310 and 1550 nm single-mode | 300 m, 10 km, 40 km | data centres and metro links |
Short-wave multimode links are cheaper for short runs; long-wave single-mode links serve kilometres.
The 802.3 Ethernet standard compared with 802.4 token bus PIN 1/27
2066 Bhadra · Q3a
IEEE 802.3 is the Ethernet standard: stations share a bus (or a hub) and use 1-persistent CSMA/CD: sense the carrier, transmit when idle, listen while transmitting, and on a collision send a jam signal and retry after binary exponential backoff. Frames carry 48-bit MAC addresses, a length/type field, 46 to 1500 data bytes and a CRC-32; the 64-byte minimum frame lets collisions be detected. Speeds run from 10 Mbps (10Base5, 10Base2, 10BaseT) upwards.
| Point | 802.3 Ethernet | 802.4 Token bus |
|---|---|---|
| Access method | CSMA/CD (contention) | token passing on a logical ring |
| Collisions | possible | none |
| Access delay | random, unbounded | bounded, deterministic |
| Priority | none | four classes (0, 2, 4, 6) |
| Medium | baseband coax, twisted pair, fiber | broadband coaxial cable |
| Speed | 10 Mbps and above | 1, 5 or 10 Mbps |
| At light load | sends at once | waits for the token |
| Complexity and use | simple; office LANs | complex ring maintenance; factory automation |
Why token bus is also called a token ring PIN 1/27
2073 Shrawan · Q3
Token bus (IEEE 802.4) is physically a bus: all stations are attached to one linear or tree-shaped cable, and every frame reaches all of them. Access, however, is controlled by a token that circulates in a logical ring:
- each station knows the address of its predecessor and of its successor;
- the token is passed in descending order of station address;
- the station with the lowest address passes the token back to the one with the highest, closing the ring;
- only the token holder transmits, and then passes the token to its successor.
Since the token travels round this ring exactly as in a token ring, token bus is also called a token ring, although the ring is logical (by address) and not physical (the cable is a bus). In the figure the token goes 112, 90, 70, 45, 20 and back to 112.
IEEE 802.4 against IEEE 802.5 PIN 1/27
2067 Ashad · Q5
IEEE 802.4 (token bus) and IEEE 802.5 (token ring) are both collision-free token passing LANs with a bounded access delay; they differ in how the token and the frames travel.
| Point | IEEE 802.4 Token bus | IEEE 802.5 Token ring |
|---|---|---|
| Topology | physical bus or tree, logical ring | physical ring, star-wired through wiring centres |
| Token passing | to the successor, by descending address | to the next station downstream |
| Frame delivery | broadcast on the bus; all stations hear it at once | passes from station to station, each repeating it |
| Frame removal | absorbed at the bus terminators | removed by the sender after one circuit |
| Delivery confirmation | none in the frame | A and C bits in the frame status |
| Medium and speed | broadband coaxial cable; 1, 5, 10 Mbps | shielded twisted pair; 4, 16 Mbps |
| Priority | four classes (0, 2, 4, 6) with timers | eight levels with reservation bits |
| Ring maintenance | distributed: claim token, solicit successor, set successor | an active monitor station |
| Data field | up to 8182 bytes | limited by the token holding time |
| Main use | factory automation (MAP) | office LANs (IBM) |
4Network layer
Distance vector and link state routing compared TOP 9/27
2080 Baishakh · Q4
2076 Ashwin · Q5
2075 Ashwin · Q4
2074 Ashwin · Q4
2073 Shrawan · Q5
2072 Kartik · Q5
2071 Shrawan · Q4
2068 Chaitra · Q5
2067 Ashad · Q7
In distance vector routing each router periodically sends its whole routing table (its distance to every destination) to its neighbours and updates its own table by the Bellman-Ford rule. In link state routing each router floods the state of its own links to every router, builds the complete topology, and computes its shortest paths with Dijkstra's algorithm.
| Point | Distance vector | Link state |
|---|---|---|
| Knowledge | distances reported by neighbours | the whole topology |
| Sends | whole routing table | state of its own links |
| To | neighbours only | all routers, by flooding |
| When | periodically (RIP every 30 s) | on a change, slow refresh |
| Algorithm | Bellman-Ford | Dijkstra |
| Convergence | slow, count to infinity | fast, no count to infinity |
| Loops | possible while converging | rare |
| Metric | usually hop count | cost from bandwidth or delay |
| Resources | little memory and CPU | more memory and CPU |
| Scale | small networks | large networks, with areas |
| Examples | RIP, IGRP | OSPF, IS-IS |
Examples: a small office of a few routers runs RIP, simple to configure; an ISP or large campus runs OSPF, whose areas keep databases small and whose flooding reroutes around a failed link in under a second.
Routing: what it is and why it is essential PIN 4/27
2076 Ashwin · Q5
2075 Ashwin · Q4
2071 Shrawan · Q4
2067 Ashad · Q7
Routing is the process of finding paths through an internetwork and building the routing tables that routers use to forward each packet, hop by hop, from the source network to the destination network. A routing algorithm, usually run as a routing protocol, chooses the path by a metric such as hops, delay or cost.
Why it is essential: a packet for another network can only be delivered if every router knows the next hop; networks are meshes with many possible paths, and routing chooses the best; it reroutes around failed links automatically; it balances load across links; and aggregated routes let the Internet scale.
The routing algorithm and the properties of a good one PIN 3/27
2079 Bhadra · Q4
2078 Bhadra · Q5
2074 Chaitra · Q4
A routing algorithm is the part of the network layer software that decides on which output line an incoming packet is transmitted, by computing paths and filling the routing table. A good routing algorithm has these properties (goals):
- Correctness: it delivers every packet to the correct destination.
- Simplicity: it needs little computation and few control messages.
- Robustness: it keeps working through router and link failures and changes in topology and load, without restarting the network.
- Stability: it converges quickly to fixed routes, without oscillating or forming loops.
- Fairness: every source and destination pair gets reasonable service.
- Optimality (efficiency): it minimizes the mean delay or maximizes the total throughput, balanced against fairness.
The IPv4 datagram (IP frame) format PIN 2/27
2067 Ashad · Q8
2066 Poush · Q10
An IPv4 datagram is a header of 20 to 60 bytes followed by data, at most 65,535 bytes in all. IP gives connectionless, best-effort delivery, so the header carries everything each router needs to forward the datagram on its own. The header is laid out in rows of 32 bits:
- Version (4 bits): 4 for IPv4.
- IHL (4 bits): header length in 32-bit words, 5 to 15 (20 to 60 bytes).
- Type of service (8 bits): priority and handling of the datagram (now DSCP and ECN).
- Total length (16 bits): header plus data in bytes, at most 65,535.
- Identification (16 bits): the same for every fragment of one datagram.
- Flags (3 bits): reserved, DF (do not fragment) and MF (more fragments).
- Fragment offset (13 bits): position of the fragment's data in the original, in 8-byte units.
- Time to live (8 bits): hop limit, decremented by every router; at 0 the datagram is discarded.
- Protocol (8 bits): the upper-layer protocol of the data: 1 ICMP, 6 TCP, 17 UDP.
- Header checksum (16 bits): error check over the header only, recomputed at every hop.
- Source and destination addresses (32 bits each): the sender's and the final receiver's IP addresses.
- Options and padding (0 to 40 bytes): record route, timestamp, source routing, padded to a 32-bit boundary.
- Data: the transport segment or ICMP message being carried.
ICMP: what it is, its importance and its uses in TCP/IP PIN 2/27
2081 Baishakh · Q5
2071 Shrawan · Q5
ICMP (Internet Control Message Protocol, RFC 792) is the companion protocol of IP at the network layer. It reports errors in delivering datagrams back to their source and provides query messages for diagnostics. ICMP messages are carried inside IP datagrams with protocol number 1.
Format: type (8 bits), code (8 bits) and checksum (16 bits), then 32 bits that depend on the type, then data; an error message carries the IP header and the first 8 bytes of data of the datagram that caused it.
Importance: IP is connectionless and best effort, with no acknowledgement or error reporting of its own. ICMP gives hosts and routers this feedback, so delivery failures are reported instead of passing silently.
Uses in TCP/IP:
- Error reporting: destination unreachable (network, host, protocol or port), time exceeded, parameter problem and redirect; TCP and UDP pass these to applications.
- ping: echo request and echo reply (types 8 and 0) test whether a host is reachable and measure the round-trip time.
- traceroute: probes sent with TTL 1, 2, 3 and so on draw time exceeded messages from each router in turn, revealing the path.
- Path MTU discovery: "fragmentation needed" messages tell TCP the largest datagram the path can carry.
- Routing help: redirect gives a host a better first-hop router, and router solicitation and advertisement find routers.
- Network management: monitoring tools ping devices, and timestamp messages measure delay.
No ICMP error message is sent about another ICMP error, a non-first fragment, or a broadcast or multicast datagram, which prevents message storms.
ICMP error and informational message types PIN 2/27
2066 Poush · Q8
2066 Bhadra · Q5b
ICMP messages, carried in IP datagrams with protocol number 1, are of two kinds: error-reporting messages, sent back to the source when a router or host cannot process a datagram, and informational (query) messages, sent as request and reply pairs. Every message begins with a type, a code and a checksum.
Error-reporting messages:
| Type | Message | Meaning |
|---|---|---|
| 3 | Destination unreachable | cannot deliver: network, host, protocol or port unreachable, or fragmentation needed with DF set |
| 4 | Source quench | a congested router asks the source to slow down (now deprecated) |
| 11 | Time exceeded | TTL reached zero (code 0) or reassembly timed out (code 1) |
| 12 | Parameter problem | an invalid header field or a missing option |
| 5 | Redirect | a better first-hop router exists on the same network |
Informational (query) messages:
| Types | Pair | Use |
|---|---|---|
| 8 and 0 | Echo request and reply | ping: reachability and round-trip time |
| 13 and 14 | Timestamp request and reply | delay and clock difference |
| 17 and 18 | Address mask request and reply | finding the subnet mask |
| 10 and 9 | Router solicitation and advertisement | finding the routers |
Error messages carry the original IP header and 8 bytes of its data, and none is sent about an ICMP error, a non-first fragment, or a broadcast or multicast datagram.
Adaptive and non-adaptive routing PIN 2/27
2081 Bhadra · Q4
2070 Ashad · Q7
Non-adaptive (static) routing computes routes in advance, offline, and the administrator enters them in the routers; they do not change with traffic or topology. Adaptive (dynamic) routing changes routes automatically as routers exchange information about topology and load through routing protocols.
| Point | Non-adaptive | Adaptive |
|---|---|---|
| Routes | fixed, entered manually | computed continuously |
| On a failure | manual change needed | automatic reroute |
| Overhead | none | updates, CPU, memory |
| Security | higher | lower |
| Suits | small, stable networks | large networks |
| Examples | static routes, flooding | RIP, OSPF |
Routed and routing protocols, with examples PIN 2/27
2082 Baishakh · Q4
2072 Chaitra · Q5
A routed protocol is a network layer protocol that carries user data across an internetwork and whose packets are forwarded by routers; it defines the addressing and the packet format. Examples: IPv4 and IPv6 (formerly IPX and AppleTalk).
A routing protocol is used by routers to exchange route information and build their routing tables, so that the routed packets can be forwarded. Examples: RIP, OSPF, EIGRP, IS-IS and BGP.
| Point | Routed protocol | Routing protocol |
|---|---|---|
| Purpose | carries user data | finds paths, builds tables |
| Used by | hosts and routers | routers only |
| Provides | addresses and packet format | reachability and metrics |
| Examples | IPv4, IPv6 | RIP, OSPF, BGP |
A routing protocol's own messages travel inside routed IP packets: RIP in UDP over IP, OSPF directly in IP.
Routing protocols: what they are and why they are necessary PIN 2/27
2082 Bhadra · Q4
2069 Chaitra · Q5
A routing protocol is a set of rules and messages by which routers exchange information about the networks they can reach, and the cost of reaching them, so that each router builds and updates its routing table automatically. Examples: RIP, OSPF and EIGRP inside an autonomous system, and BGP between autonomous systems.
Why it is necessary:
- Scale: static routes for every network on every router are impossible to maintain in a large internetwork.
- Adaptation: when a link fails, the routers reroute automatically.
- Best path: a metric chooses the best of many paths, without loops.
- Policy: between autonomous systems, BGP carries routing policy.
Unicast and multicast, and their routing PIN 2/27
2080 Baishakh · Q4
2066 Bhadra · Q4a
Unicast is one-to-one delivery: a packet goes from one source to one destination address, and unicast routing forwards it along a single best path using the routing table (RIP, OSPF, BGP).
Multicast is one-to-many delivery to a group of receivers that have joined a group address (class D, 224.0.0.0 to 239.255.255.255). Multicast routing builds a distribution tree so that the source sends one copy and routers duplicate it only where the paths branch; hosts join groups with IGMP, and routers use protocols such as DVMRP, MOSPF and PIM.
Example: sending one stream to three receivers takes 9 link transmissions by unicast but only 6 by multicast in the network drawn.
The functions of the network layer PIN 1/27
2072 Kartik · Q4
The network layer delivers packets from the source host to the destination host across networks. Its functions are: logical addressing (IP addresses); routing, to find paths and build routing tables; forwarding each packet to the right output line; packetizing segments into packets; fragmentation and reassembly for links with a smaller MTU; internetworking of different link technologies; error reporting through ICMP; and congestion control and quality of service at routers.
Why the network layer is a key layer of the OSI model PIN 1/27
2072 Kartik · Q5
The network layer is a key layer because it alone provides host-to-host delivery across many interconnected networks: it gives every host a globally unique logical address, chooses the route, and is the highest layer that every router implements. It is the narrow waist of the stack (IP over every link, every application over IP), hiding the differences between link technologies; without it, frames could never leave their own LAN.
Why a switch is preferred to a hub for a LAN PIN 1/27
2079 Bhadra · Q4
A hub is a physical layer multiport repeater that copies every signal to all ports; a switch is a data link layer device that forwards each frame only to the destination's port using a MAC address table. A switch is preferred because:
- Dedicated bandwidth: every switch port gets its full speed, while all hub ports share one bandwidth.
- No collisions: each switch port is a separate collision domain, and full-duplex links have no collisions at all; a hub is one collision domain that degrades as load grows.
- Full duplex: a switch port sends and receives at the same time; a hub is half duplex.
- Security: a unicast frame reaches only its destination; on a hub every host receives all traffic.
- Features: VLANs, port security, quality of service and monitoring.
- Cost: the price difference is now negligible.
Router and gateway PIN 1/27
2068 Chaitra · Q9
A router is a network layer device that connects networks using the same network protocol (IP) and forwards each packet toward its destination by the destination IP address and its routing table. It builds the table statically or with routing protocols (RIP, OSPF, BGP), decrements TTL, separates broadcast domains, and often performs NAT and packet filtering.
A gateway is a device or software that connects networks using different protocol stacks and converts between them, working up to the application layer: an email gateway between two mail systems, or a VoIP gateway between IP phones and the telephone network. In TCP/IP, a host's default gateway is simply the router for traffic leaving its subnet.
| Point | Router | Gateway |
|---|---|---|
| Layer | 3, network | any, up to 7 |
| Protocols on the two sides | the same (IP) | different |
| Main job | path selection and forwarding | protocol conversion |
| Changes | only header fields | the data format |
The ranges of the IPv4 address classes PIN 1/27
2082 Baishakh · Q5
The IPv4 address classes are set by the first bits of the first octet:
| Class | First bits | Range | Default mask |
|---|---|---|---|
| A | 0 | 0.0.0.0 to 127.255.255.255 | 255.0.0.0 |
| B | 10 | 128.0.0.0 to 191.255.255.255 | 255.255.0.0 |
| C | 110 | 192.0.0.0 to 223.255.255.255 | 255.255.255.0 |
| D | 1110 | 224.0.0.0 to 239.255.255.255 | multicast |
| E | 1111 | 240.0.0.0 to 255.255.255.255 | reserved |
The logical address PIN 1/27
2068 Baishakh · Q4
A logical address is a network layer address assigned to an interface by software (by an administrator or DHCP) rather than built into the hardware, such as the IPv4 address 192.168.1.10. It is hierarchical, with a network part and a host part, so it identifies where the host is across networks; it stays the same from source to destination and changes when the host moves to another network, unlike the physical (MAC) address, which works only on one link.
Why an IP address is needed when every host has a MAC address PIN 1/27
2072 Chaitra · Q2
A MAC address identifies a network card but not where it is, so an IP (logical) address is also needed:
- Hierarchy: a MAC address is flat; an IP address has a network part, so routers keep one route per network instead of one per device in the world.
- Scope: a MAC address works only within one link and is replaced in every new frame; an IP address stays the same end to end.
- Different links: IP gives one uniform address over Ethernet, Wi-Fi, serial and cellular links.
- Flexibility: replacing a card changes the MAC but not the IP; moving to another network changes the IP to show the new location.
ARP maps the IP address to the MAC address for the final hop.
Classful and classless addresses PIN 1/27
2074 Ashwin · Q4
Classful addressing divides the IPv4 address space into five fixed classes identified by the first bits, and the class fixes the network part: class A /8 (first octet 0 to 127), B /16 (128 to 191), C /24 (192 to 223), D for multicast (224 to 239) and E reserved (240 to 255). Blocks come in only three sizes, so many addresses are wasted.
Classless addressing (CIDR) removes the classes: a block of any power-of-two size is written a.b.c.d/n, where n is the prefix length, for example 192.168.10.0/26 (64 addresses). The mask travels with every route, which allows VLSM, supernetting and route aggregation.
| Point | Classful | Classless |
|---|---|---|
| Network part | 8, 16 or 24 bits by class | any length, given by /n |
| Waste | high | low |
| Routing | one route per classful network | aggregated routes, longest prefix match |
IPv4 addressing and subnetting with an example PIN 1/27
2070 Ashad · Q9
An IPv4 address is a 32-bit logical address written in dotted decimal (192.168.10.37), made of a network part and a host part. Classful addressing fixes the split by class: A /8 (first octet 0 to 127), B /16 (128 to 191) and C /24 (192 to 223), with D for multicast and E reserved. The private ranges are 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16.
Subnetting borrows s bits from the host part to divide one network into smaller subnets with a longer mask, giving subnets of usable hosts each. Example: 192.168.10.0/24 with 2 borrowed bits gives four /26 subnets (mask 255.255.255.192) starting at .0, .64, .128 and .192, each with 62 hosts; the first runs from .1 to .62 with broadcast .63.
The contribution of subnetting to IP address management PIN 1/27
2069 Chaitra · Q4
Subnetting divides one network into smaller subnets by borrowing host bits. Its contribution to IP address management:
- Efficient use: the block is cut to fit each department, reducing wasted addresses.
- Smaller broadcast domains: less broadcast traffic and better performance.
- Security: traffic between subnets passes routers or firewalls that apply policy.
- Easier administration: addresses map to departments or floors, and a fault stays inside one subnet.
- Route summarization: outside routers see one route for the whole block.
- Growth: spare subnets are kept for expansion.
When VLSM is used, and why PIN 1/27
2081 Baishakh · Q4
VLSM (variable length subnet mask) gives each subnet its own mask. It is used when the subnets need different numbers of hosts: departments of unequal size, and point-to-point links between routers that need only 2 addresses.
Why: with one fixed mask, every subnet must be as large as the biggest one, so the small subnets waste most of their addresses. For 100 and 10 hosts, two /25 subnets waste 142 usable addresses, while a /25 and a /28 waste only 30. VLSM therefore conserves addresses, leaves a larger unused block for growth, and keeps the plan hierarchical for route summarization; it needs classless routing protocols such as RIPv2, OSPF and EIGRP.
Supernetting PIN 1/27
2081 Bhadra · Q5
Supernetting combines several contiguous networks into one larger network with a shorter prefix, so that a single route advertises all of them (route aggregation). For example, 192.168.4.0/24 to 192.168.7.0/24 combine into 192.168.4.0/22 (mask 255.255.252.0). The networks must be contiguous, a power of two in number, and aligned on the combined block size.
IP (Internet Protocol) PIN 1/27
2071 Shrawan · Q5
IP (Internet Protocol, version 4, RFC 791) is the network layer protocol of the TCP/IP suite. It gives a connectionless, unreliable, best-effort datagram service: each datagram is routed independently and may be lost, duplicated or delivered out of order, with no acknowledgement; reliability is left to TCP and error reports to ICMP.
Functions: logical addressing with 32-bit addresses; routing and forwarding hop by hop; fragmentation and reassembly; limiting a datagram's lifetime with TTL; and identifying the upper-layer protocol. Its header is 20 to 60 bytes long.
The purpose of the TTL and protocol fields of the IPv4 header PIN 1/27
2076 Chaitra · Q5
Time to live (TTL, 8 bits) limits the lifetime of a datagram so that one caught in a routing loop does not circulate for ever. The sender sets it (typically 64 or 128); every router decrements it by 1, and a router that reduces it to 0 discards the datagram and sends an ICMP time exceeded message to the source. It also limits a path to 255 hops, and traceroute uses it to discover the routers on a path.
Protocol (8 bits) identifies the upper-layer protocol whose data the datagram carries, so that the destination hands the payload to the right module (demultiplexing): 1 ICMP, 2 IGMP, 6 TCP, 17 UDP, 89 OSPF, 50 ESP and 51 AH. It does at the network layer what the port number does at the transport layer.
Fragmentation and reassembly PIN 1/27
2068 Baishakh · Q6
Fragmentation is the splitting of an IP datagram that is larger than the next link's MTU (1,500 bytes on Ethernet) into smaller fragments, each with its own header carrying the same Identification, a Fragment offset in 8-byte units, and the MF flag, set on all but the last. Reassembly is the rebuilding of the original datagram at the destination host from these fields; if a fragment is still missing when the reassembly timer expires, the whole datagram is discarded. For example, a 4,000 byte datagram becomes fragments of 1,500, 1,500 and 1,040 bytes with offsets 0, 185 and 370.
Why the maximum TCP payload is 65,495 bytes PIN 1/27
2068 Baishakh · Q7
The number comes from the IPv4 header. A TCP segment must fit inside one IP datagram, and the IPv4 Total length field is 16 bits, so a datagram, header included, is at most = 65,535 bytes. The minimum IPv4 header takes 20 bytes and the minimum TCP header another 20 bytes, which leaves:
So 65,495 bytes is the largest payload one TCP segment can carry: it is not a chosen number but what remains after both headers. For UDP, whose header is 8 bytes, the limit is 65,535 minus 20 minus 8 = 65,507 bytes. In practice the Ethernet MTU of 1,500 bytes limits each segment to 1,460 bytes of data.
ARP and NDP PIN 1/27
2082 Bhadra · Q10
ARP (Address Resolution Protocol, RFC 826) maps a known IPv4 address to a MAC address on the same link: the sender broadcasts an ARP request ("who has 192.168.1.20?"), the owner unicasts a reply with its MAC address, and the pair is cached.
NDP (Neighbour Discovery Protocol, RFC 4861) replaces ARP in IPv6. It uses ICMPv6 neighbour solicitation and advertisement messages sent to a solicited-node multicast address instead of a broadcast, and also finds routers and prefixes.
| Point | ARP | NDP |
|---|---|---|
| Used with | IPv4 | IPv6 |
| Carried in | its own Ethernet frame (type 0x0806) | ICMPv6 inside IPv6 |
| Request sent to | broadcast | solicited-node multicast |
| Messages | request, reply | NS, NA, RS, RA, redirect |
| Functions | address resolution only | resolution, router and prefix discovery, SLAAC, duplicate address detection, reachability |
| Security | none | can use SEND |
The protocol that gives hosts and routers feedback about network problems PIN 1/27
2076 Chaitra · Q5
ICMP (Internet Control Message Protocol) provides this feedback: routers and hosts send ICMP error messages, such as destination unreachable and time exceeded, back to the source of a datagram that could not be delivered.
The optimality principle PIN 1/27
2066 Bhadra · Q4a
The optimality principle states that if router J is on the optimal path from router I to router K, then the optimal path from J to K also falls along the same route. Proof: call the part from I to J r1 and the rest r2; if a better route than r2 existed from J to K, joining it to r1 would improve the route from I to K, which contradicts the optimality of r1r2.
Consequence: the optimal routes from all sources to one destination form a tree rooted at that destination, the sink tree. A sink tree has no loops, so every packet is delivered in a finite number of hops; routing algorithms aim to discover and use the sink trees of all destinations.
The autonomous system PIN 1/27
2075 Chaitra · Q5
An autonomous system (AS) is a group of networks and routers under one administrative authority with a single routing policy, such as an ISP or a university, identified by an AS number of 16 or 32 bits. Inside an AS, routing uses an interior gateway protocol (RIP, OSPF) chosen by the AS itself; between autonomous systems, the exterior gateway protocol BGP is used.
How routing loops are prevented in distance vector routing PIN 1/27
2075 Chaitra · Q5
In distance vector routing a routing loop forms when routers believe stale information about a failed route, so packets bounce between them while their metrics count up to infinity. Example: routers A, B and C are in a line with network N on C. C's link to N fails; C then accepts B's old advertisement "N at 2 hops" and sets N at 3 via B; B in turn sets 4 via C, and so on up to 16.
Prevention methods:
- Maximum hop count: RIP defines 16 as infinity, so the counting stops.
- Split horizon: a router never advertises a route back out of the interface it came from; B never tells C about N, so C keeps N unreachable.
- Poison reverse: B advertises N back to C with metric 16, which breaks the loop at once.
- Route poisoning: C advertises N with metric 16 as soon as the link fails.
- Triggered updates: changes are sent immediately instead of after the 30 second timer.
- Hold-down timer: after a route fails, worse news about it is ignored for 180 seconds, so stale updates cannot reinstate it.
The properties of link state routing PIN 1/27
2081 Bhadra · Q4
Properties of link state routing:
- Each router knows the complete topology (the link state database).
- It shares only the state of its own links, flooded to every router.
- Updates are sent when a link changes, with a slow periodic refresh.
- Each router computes its own routes with Dijkstra's algorithm.
- Convergence is fast, with no count to infinity; the metric is a cost.
- It needs more memory and CPU and scales with areas (OSPF, IS-IS).
RIP, OSPF, BGP, IGRP and EIGRP PIN 1/27
2074 Chaitra · Q4
- RIP (Routing Information Protocol): a distance vector interior protocol (RFC 1058, 2453) with a hop count metric, at most 15 hops (16 means unreachable), sending whole tables every 30 seconds over UDP 520; simple but slow to converge, for small networks.
- OSPF (Open Shortest Path First): an open-standard link state interior protocol (RFC 2328); routers flood LSAs within areas, elect a DR and BDR on LANs and run Dijkstra; its cost metric comes from bandwidth; fast convergence, VLSM and authentication.
- BGP (Border Gateway Protocol): the exterior protocol between autonomous systems (BGP-4, RFC 4271); a path vector protocol that advertises routes with their AS path and chooses by policy, over TCP port 179; a route containing its own AS number is rejected, which prevents loops.
- IGRP (Interior Gateway Routing Protocol): Cisco's distance vector interior protocol with a composite metric of bandwidth and delay (load and reliability optional), updates every 90 seconds and a hop limit of 100 (up to 255); classful and now obsolete.
- EIGRP (Enhanced IGRP): Cisco's advanced distance vector (hybrid) protocol; its DUAL algorithm keeps a feasible successor for fast, loop-free convergence; it sends partial updates only on change and supports VLSM and unequal-cost load balancing.
An intra-AS routing protocol: OSPF PIN 1/27
2068 Baishakh · Q6
An intra-AS routing protocol (interior gateway protocol) routes inside one autonomous system; RIP, OSPF, IS-IS and EIGRP are examples. OSPF (Open Shortest Path First) is the most widely used:
- Type: an open-standard link state protocol (RFC 2328), carried directly in IP as protocol 89.
- Working: routers find neighbours with Hello packets every 10 seconds, elect a DR and BDR on multi-access networks, synchronize their link state databases with DBD, LSR, LSU and LSAck packets, flood LSAs on any change, and run Dijkstra's SPF algorithm to build their routing tables.
- Metric: cost, the reference bandwidth divided by the link bandwidth.
- Areas: the AS is divided into areas joined to backbone area 0 by area border routers, which keeps each database small.
- Advantages: fast convergence, no count to infinity, VLSM support, authentication and equal-cost load balancing.
Multicast and unicast routing protocols PIN 1/27
2072 Kartik · Q4
Unicast routing protocols build tables for one-to-one delivery along one best path: the interior protocols RIP (distance vector, hop count), OSPF and IS-IS (link state, cost) and EIGRP (advanced distance vector), and the exterior protocol BGP (path vector) between autonomous systems.
Multicast routing protocols deliver one stream to a group of receivers (a class D address) along a distribution tree, copying packets only where paths branch. Hosts join groups with IGMP; routers use reverse path forwarding (RPF) to avoid loops and build source-based or shared trees:
| Protocol | Working |
|---|---|
| DVMRP | distance vector based; flood and prune; source-based trees |
| MOSPF | OSPF extension; group membership LSAs; Dijkstra source trees |
| PIM-DM | protocol independent, dense mode; flood and prune |
| PIM-SM | sparse mode; explicit joins to a rendezvous point; shared tree, then source tree |
| CBT | core based tree; one shared tree per group |
5Transport layer
TCP and its segment (header) structure HOT 6/27
2076 Ashwin · Q6
2075 Ashwin · Q6
2074 Ashwin · Q6
2070 Ashad · Q10
2068 Chaitra · Q7
2068 Baishakh · Q5
TCP (Transmission Control Protocol) is a connection-oriented, reliable, full-duplex byte-stream transport protocol with flow and congestion control. Its segment is a header of 20 to 60 bytes followed by data:
- Source and destination port (16 bits each): the sending and receiving processes.
- Sequence number (32 bits): number of the first data byte in the segment; the ISN on a SYN.
- Acknowledgement number (32 bits): the next byte expected; valid when ACK is set.
- Header length (4 bits): header size in 32-bit words (5 to 15).
- Reserved (4 bits): zero (6 bits in RFC 793).
- Flags (1 bit each): URG urgent pointer valid, ACK acknowledgement valid, PSH push at once, RST reset, SYN synchronize (open), FIN finish (close); CWR and ECE for congestion notification.
- Window size (16 bits): receive window for flow control.
- Checksum (16 bits): over the pseudo-header, header and data; mandatory.
- Urgent pointer (16 bits): end of urgent data when URG is set.
- Options (0 to 40 bytes): MSS, window scale, SACK, timestamps, with padding.
TCP compared with UDP HOT 5/27
2082 Baishakh · Q6
2075 Ashwin · Q6
2071 Chaitra · Q6
2071 Shrawan · Q6
2068 Chaitra · Q7
| Basis | TCP | UDP |
|---|---|---|
| Connection | connection-oriented (three-way handshake) | connectionless |
| Reliability | reliable: ACK and retransmission | unreliable: no ACK, no retransmission |
| Ordering | in-order delivery by sequence numbers | no ordering |
| Data unit | segment; byte stream | user datagram; message boundaries kept |
| Header size | 20 to 60 bytes | 8 bytes |
| Flow and congestion control | yes (windows) | none |
| Checksum | mandatory | optional in IPv4 |
| Speed | slower: setup and retransmission delay | faster: low overhead |
| Casting | unicast only | unicast, broadcast, multicast |
| Protocol number | 6 | 17 |
| Applications | HTTP, HTTPS, SMTP, FTP, SSH, Telnet | DNS, DHCP, SNMP, TFTP, VoIP, online games |
The UDP header has only source port, destination port, length and checksum, while the TCP header adds sequence and acknowledgement numbers, header length, flags, window and urgent pointer. TCP suits data that must arrive complete (web pages, files, mail); UDP suits short or time-critical data.
Services, functions and major tasks of the transport layer PIN 4/27
2078 Bhadra · Q6
2076 Chaitra · Q6
2071 Chaitra · Q6
2068 Baishakh · Q5
The transport layer (layer 4) provides logical, end-to-end communication between processes running on different hosts. It runs only in the end hosts, accepts messages from the application layer and uses the network layer's host-to-host delivery to provide these services:
- Process-to-process delivery: port numbers in every segment identify the sending and receiving process, not only the host.
- Segmentation and reassembly: a long message is divided into numbered segments and rebuilt at the receiver.
- Connection control: a connection-oriented service (TCP: establish, transfer, release) or a connectionless service (UDP).
- Reliability (error control): checksum, acknowledgement and retransmission recover corrupted, lost and duplicate segments.
- Ordered delivery: sequence numbers restore the order in which data was sent.
- Flow control and buffering: the receiver's advertised window stops a fast sender from overflowing its buffer.
- Multiplexing and demultiplexing: many processes share one IP address, separated by their ports.
- Congestion control: senders reduce their rate when the network is overloaded (TCP slow start, traffic shaping).
The token bucket compared with the leaky bucket PIN 4/27
2081 Bhadra · Q6
2080 Bhadra · Q6
2070 Ashad · Q8
2066 Poush · Q5
Both are traffic shaping algorithms. The leaky bucket stores packets in a finite queue and sends them at a fixed rate, discarding packets when it is full; the token bucket stores tokens generated at rate r up to capacity C and sends a packet only by removing a token, so saved tokens allow bursts.
| Basis | Leaky bucket | Token bucket |
|---|---|---|
| Bucket holds | packets | tokens (permission) |
| Output rate | constant, whatever the input | average r, bursts up to C at line rate |
| Idle periods | no credit saved | tokens saved up to C |
| When full | packets discarded | tokens discarded; packets wait |
| Burst handling | bursts flattened, slow response | bounded bursts sent at once, fast response |
| Network utilization | idle capacity wasted | idle capacity used later |
| Parameters | queue size, output rate | token rate r, bucket size C |
How the token bucket controls congestion better: it holds the long-run rate at r just as the leaky bucket does, so the network's average load is still bounded, but it lets a host use capacity saved while idle, responds faster to sudden bursts, loses no packets when the bucket fills, and limits the worst-case burst to C (lasting ).
The UDP header (segment structure) and its fields PIN 3/27
2082 Bhadra · Q6
2082 Baishakh · Q6
2070 Chaitra · Q6
UDP (User Datagram Protocol, RFC 768) is a connectionless, unreliable transport protocol. Its segment, the user datagram, is an 8-byte header of four 16-bit fields followed by the application data, and the whole datagram travels as the data of an IP datagram whose protocol field is 17.
- Source port (16 bits): port of the sending process, to which a reply is sent; optional, set to 0 when no reply is needed.
- Destination port (16 bits): port of the receiving process, used to deliver the datagram to the correct socket (for example 53 for DNS).
- Length (16 bits): total length of header and data in bytes: minimum 8 (header only), maximum 65,535, so at most 65,507 bytes of data over IPv4.
- Checksum (16 bits): one's complement sum over a 12-byte pseudo-header (source IP, destination IP, a zero byte, protocol 17, UDP length), the header and the data. It detects corrupted and misdelivered datagrams, which are discarded. It is optional in IPv4 (0 means not used) and mandatory in IPv6.
Functions of UDP: process-to-process delivery through ports, multiplexing and demultiplexing, and error detection, without connection setup, acknowledgement, retransmission, ordering or flow control. Each message is sent as one datagram, so message boundaries are preserved.
Example: a 28-byte DNS query from port 50000 to port 53 begins C3 50 00 35 00 24: source port 50000, destination port 53, length 8 + 28 = 36 bytes, followed by the checksum.
Why TCP is called reliable, and how reliability is provided PIN 3/27
2081 Bhadra · Q6
2076 Ashwin · Q6
2072 Chaitra · Q6
TCP is called reliable because, over the unreliable, best-effort IP, it delivers every byte to the receiving process exactly once, without errors and in the order sent, or reports a failure. Reliability is provided by:
- Connection establishment: the three-way handshake ensures both ends are ready and synchronizes the initial sequence numbers.
- Sequence numbers: every byte is numbered, so lost, duplicate and out-of-order data are detected and reordered.
- Positive acknowledgement: the receiver sends cumulative ACKs naming the next byte expected.
- Retransmission: the sender keeps a copy and a timer; an unacknowledged segment is resent after the timeout () or after three duplicate ACKs (fast retransmit).
- Checksum: corrupted segments are discarded and then retransmitted.
- Flow control: the receive window prevents buffer overflow at the receiver.
- Congestion control: slow start and congestion avoidance prevent losses inside the network.
- Graceful release: FIN and ACK in each direction, so no data is lost at closing.
Port number (port address): what it is and why it is used PIN 3/27
2082 Baishakh · Q6
2080 Baishakh · Q6
2071 Chaitra · Q6
A port number (port address) is a 16-bit number (0 to 65,535) in the TCP or UDP header that identifies a process on a host. An IP address delivers data only to the host, which runs many processes at once; the port delivers it to the correct process, giving process-to-process delivery and multiplexing. Examples: HTTP 80, SMTP 25, DNS 53. Ranges: well-known 0 to 1023, registered 1024 to 49151, dynamic 49152 to 65535.
Where UDP is preferred: practical examples and applications PIN 2/27
2079 Bhadra · Q6
2066 Poush · Q10
UDP (User Datagram Protocol) is a connectionless, unreliable transport protocol with an 8-byte header (ports, length, checksum). It is preferred when speed and timeliness matter more than guaranteed delivery, when exchanges are short requests and replies, and when data must reach many receivers at once:
| Application | Port | Reason for UDP |
|---|---|---|
| DNS | 53 | one short query and reply; the client simply retries |
| DHCP | 67, 68 | the client has no IP address yet and must broadcast |
| VoIP and video calls (RTP) | dynamic | late packets are useless; small losses are tolerated |
| Online games | game specific | only the latest position update matters |
| IPTV, live streaming | multicast | one stream delivered to many receivers |
| SNMP, NTP, TFTP | 161, 123, 69 | short messages, simple devices |
| QUIC (HTTP/3) | 443 | builds its own reliability without TCP's delays |
Factors that cause congestion, and the parameters that affect it PIN 2/27
2073 Shrawan · Q5
2066 Bhadra · Q4b
- Arrival rate above link capacity: several input lines feeding one output line.
- Buffer memory: too little drops packets; too much delays them until they time out and are duplicated.
- Bursty traffic that exceeds capacity for short periods.
- Slow processors and low-bandwidth lines at routers.
- Retransmission and timeout policies: short timers add duplicate traffic.
- Routing and packet lifetime: traffic concentrated on one path, old packets circulating.
Why UDP is used on the Internet though it is unreliable PIN 1/27
2081 Baishakh · Q6
UDP is called unreliable because it has no acknowledgement, retransmission or ordering, yet it is widely used because these omissions make it fast and light:
- No connection setup: data goes in the first packet, so a DNS query or DHCP exchange completes in one round trip.
- Timeliness: in VoIP, video calls and online games a late packet is useless, and retransmission would only add delay.
- Low overhead: an 8-byte header and no per-client state at the server.
- Broadcast and multicast are possible (DHCP discovery, IPTV).
- Application control: applications add only the reliability they need (DNS retries, TFTP acknowledgements, QUIC).
Features of UDP PIN 1/27
2079 Bhadra · Q6
UDP (User Datagram Protocol, RFC 768) is the simple transport protocol of the TCP/IP suite. Its features are:
- Connectionless: no handshake or release; each datagram is independent.
- Unreliable (best effort): no acknowledgement or retransmission; lost datagrams are not recovered.
- No ordering: datagrams may arrive out of order.
- Message-oriented: each message is sent as one datagram, so boundaries are preserved.
- Small header: 8 bytes: source port, destination port, length and checksum.
- Error detection only: the checksum (optional in IPv4) causes damaged datagrams to be discarded.
- No flow or congestion control: data is sent at the application's rate.
- Stateless and fast: no per-client state and low delay, so one server serves many clients.
- Broadcast and multicast are supported.
What a TCP connection is PIN 1/27
2072 Kartik · Q6
A TCP connection is a logical, full-duplex, point-to-point communication path between two processes, identified by a socket pair (source IP, source port, destination IP, destination port). It is set up by the three-way handshake and released by FIN exchanges. Its state (sequence numbers, windows, buffers and timers) is kept only in the two end hosts; routers are unaware of it, so it is a virtual connection.
Why two transport protocols but one internet layer protocol PIN 1/27
2069 Chaitra · Q6
The transport layer has two protocols because applications need two opposite services, while the internet layer needs one common protocol that every network and router understands.
- Different needs: file transfer, e-mail and web pages need complete, ordered delivery (TCP); voice, video, games and DNS need low delay and tolerate loss (UDP). Reliability requires waiting for retransmission, which real-time traffic cannot afford, so one protocol cannot serve both.
- End-to-end principle: transport protocols run only in the end hosts, so offering a choice costs the routers nothing.
- Common network layer: IP must be implemented by every router and carried over every link technology; a single, simple best-effort protocol gives universal interoperability, the narrow waist of the hourglass model.
- Cost of change: a new transport protocol needs changes only in the hosts, but a new internet protocol needs every router changed, as the slow IPv4 to IPv6 transition shows.
- Flexibility: UDP exposes IP's service with ports added, so applications can build their own reliability (QUIC) without changing the network.
Why the port numbers of well-known servers are standardized PIN 1/27
2080 Baishakh · Q6
Well-known ports (0 to 1023) are assigned by IANA to standard servers, for example HTTP 80, HTTPS 443, SMTP 25, DNS 53, FTP 21 and SSH 22. Standardization is necessary because:
- Known meeting point: a client must know the server's port before contacting it; DNS supplies only the IP address, so the port must be fixed in advance.
- Interoperability: any client software reaches any server without extra configuration or lookup.
- Defaults: URLs and applications omit the port;
http://host/implies port 80. - Administration and security: firewall, NAT and intrusion detection rules are written per port, and only privileged processes may bind ports below 1024.
- No conflicts: a central registry prevents two services from claiming one number.
Clients use temporary (ephemeral) ports, which need no standard because the server reads them from the incoming segment.
A web service hosted on port 8765 instead of 80 PIN 1/27
2080 Baishakh · Q6
The web service still works, since TCP accepts any port, but clients no longer find it by default. A browser connects to port 80 for an http address, so users must give the port explicitly, as http://www.example.com:8765/. Without it the connection goes to port 80, where the server refuses it with RST or a different service answers. Firewalls that allow only ports 80 and 443 may also block port 8765.
The socket and its importance PIN 1/27
2074 Ashwin · Q6
A socket is an endpoint of communication, identified by an IP address and a port number together with the protocol, for example 203.0.113.5:80. A TCP connection is identified by a pair of sockets (source IP, source port, destination IP, destination port). The socket is also the programming interface between an application and the transport layer (the Berkeley socket API: socket, bind, listen, accept, connect, send, receive, close).
Importance: it identifies a process uniquely across the Internet, lets many connections share one server port, keeps the data of each connection separate, and is the interface on which every network application is built.
Why the server program must run before the client PIN 1/27
2072 Chaitra · Q6
In TCP the server performs a passive open: it creates a socket, binds it to a known port and calls listen, waiting in the LISTEN state. The client performs an active open by sending a SYN to that port, and a SYN is accepted only by a listening socket. If the server program is not running, no process listens on the port, so the server host's TCP replies with RST and the client's connect fails with "connection refused"; TCP does not hold the request until a server appears. Hence the server must be executed first and be waiting before the client starts.
Network congestion PIN 1/27
2073 Shrawan · Q5
Network congestion is the condition in which the load offered to a network, or to a part of it, exceeds its capacity. Router queues grow and overflow, so delay increases, packets are dropped and retransmitted, and throughput falls; severe congestion can cause congestion collapse, in which little useful data is delivered. It is handled by congestion control, such as traffic shaping and TCP's congestion window.
Congestion control techniques PIN 1/27
2081 Bhadra · Q6
Open-loop (prevention): good retransmission, window, acknowledgement and discard policies, admission control, and traffic shaping with the leaky bucket and token bucket algorithms. Closed-loop (removal): detect congestion and feed it back to the sources: backpressure, choke packets, implicit signalling (loss or delay), explicit signalling (ECN), load shedding and random early detection. At the hosts, TCP uses slow start and congestion avoidance with its congestion window.
Policies that prevent congestion PIN 1/27
2066 Poush · Q5
Congestion prevention (open-loop control) uses policies that stop congestion from starting, applied at several layers:
- Retransmission policy: well-tuned timers, so packets are not resent while merely delayed.
- Window policy: selective repeat instead of go-back-N, so only lost packets are resent.
- Acknowledgement policy: cumulative, delayed and piggybacked ACKs reduce extra traffic.
- Discard policy: routers drop less important packets first when queues fill.
- Admission policy: a new virtual circuit is refused if it would cause congestion.
- Traffic shaping: sources regulate their rate and bursts with the leaky bucket or token bucket.
- Network-layer policies: routing that spreads the load, fair queueing and service, and packet lifetime management.
A traffic shaping approach for a packet-switched network PIN 1/27
2066 Bhadra · Q4b
The best approach is a token bucket shaper followed by a leaky bucket that limits the peak rate, with policing at the network edge:
- Traffic contract: each source agrees an average rate r, a burst size C and, if needed, a peak rate p with the network.
- Token bucket shaping: tokens arrive at rate r up to C, and a packet leaves only by taking a token. Idle sources save tokens and may burst, but the average stays at r and the largest burst lasts at line rate M.
- Leaky bucket after it: drains at the peak rate p (r < p < M), smoothing the burst so routers are not flooded.
- Policing at the edge router: conforming packets pass; excess packets are dropped or tagged low priority.
- Closed-loop support: TCP's congestion window and router signals (ECN, random early detection) handle any remaining congestion.
Justification: with C = 6 Mb, r = 2 Mbps and M = 10 Mbps, a 12 Mb burst goes at 10 Mbps for 0.75 s and finishes in 3 s with no loss, whereas a 2 Mbps leaky bucket alone needs 6 s and drops what overflows. The average load stays predictable, bursts are bounded, idle capacity is used, and no packet is lost while the source keeps its contract.
6Application layer
Electronic mail: the sending and accessing protocols PIN 4/27
2074 Chaitra · Q7
2072 Kartik · Q7
2070 Chaitra · Q7
2068 Baishakh · Q8
Electronic mail is an asynchronous message service built from user agents, mail servers and two kinds of protocol: a sending (push) protocol, SMTP, and accessing (pull) protocols, POP3 and IMAP.
Sending, SMTP (Simple Mail Transfer Protocol, TCP port 25; 587 for submission from a user agent): a text command and reply protocol. The client connects and sends HELO, MAIL FROM, RCPT TO and DATA (the message ends with a line holding "."), then QUIT. It pushes mail from the user agent to the sender's server and from server to server, in 7-bit ASCII, with MIME encoding attachments.
Accessing, POP3 (Post Office Protocol 3, TCP 110): the user agent logs in (USER, PASS), lists and downloads the messages (LIST, RETR) and usually deletes them from the server (DELE). Simple, and suited to one computer.
Accessing, IMAP (Internet Message Access Protocol, TCP 143): mail stays on the server in folders, message state is kept, the agent can fetch headers or single parts and search on the server, and many devices share one mailbox.
Webmail: the user agent is a browser talking HTTPS to the mail server, which still uses SMTP towards other servers.
Flow: sender's agent, SMTP, sender's server (queue), SMTP, receiver's server (mailbox), POP3 or IMAP, receiver's agent.
Socket programming: definition and fundamentals PIN 4/27
2082 Baishakh · Q10
2075 Ashwin · Q7
2074 Chaitra · Q10
2073 Shrawan · Q6
Socket programming is writing network applications through the socket API, the interface between an application process and the transport layer. A socket is a communication endpoint identified by an IP address and a port number; programs create sockets and send and receive data through them with system calls.
Socket types: stream sockets (SOCK_STREAM) use TCP, a reliable connection (HTTP, FTP); datagram sockets (SOCK_DGRAM) use UDP, connectionless messages (DNS); raw sockets (SOCK_RAW) reach IP and ICMP directly (ping).
| Call | Purpose |
|---|---|
socket() | create an endpoint |
bind() | attach the local IP address and port (server) |
listen() | wait for connections, with a queue (server) |
accept() | take a connection, returning a new socket (server) |
connect() | open a connection to the server (client) |
send(), recv() | transfer data |
close() | release the connection |
Sequence: the server calls socket, bind and listen, then blocks in accept; the client calls socket and connect, which performs TCP's three-way handshake; both then send and recv, and close. The server must run first, or the client's connect is refused.
DNS: what it is and why it is used PIN 3/27
2079 Bhadra · Q7
2076 Chaitra · Q7
2071 Chaitra · Q7
DNS (Domain Name System, RFC 1034 and 1035) is a distributed, hierarchical database of names, together with the application layer protocol for querying it, that maps host names such as www.ioe.edu.np to IP addresses and back. It runs mainly over UDP port 53; root, top-level domain and authoritative name servers hold the database, and local DNS servers (resolvers) query them for hosts and cache the answers.
Why it is used:
- Names for people, numbers for machines: users type names, while IP routing needs numeric addresses.
- Freedom to move: a server can change its IP address; only its DNS record changes.
- Load distribution: one name can map to several servers.
- Mail and aliases: MX records name a domain's mail servers; CNAME records define aliases.
- Scale: no single host file could hold every name on the Internet.
Recursive and iterative DNS queries PIN 3/27
2080 Baishakh · Q7
2078 Bhadra · Q7
2074 Ashwin · Q7
DNS resolves names with two types of query, which differ in who does the work.
Recursive query: the server asked must return the final answer or an error; if it does not know the answer, it queries other servers itself and waits. Example, a host asking for www.youtube.com: the local server asks the root, the root asks the .com TLD server, the TLD asks youtube.com's authoritative server, and the address returns along the same chain.
Iterative query: the server asked replies at once with the best it has, the answer or a referral to servers closer to it, and the asker continues. Example: the local server asks the root (referral to the .com servers), then a .com server (referral to ns1.google.com), then ns1.google.com, which returns the address.
| Point | Recursive | Iterative |
|---|---|---|
| Work done by | the server asked | the asker |
| Reply | final answer or error | answer or referral |
| Server load | high | low |
| Used | host to local server | local server to root, TLD, authoritative |
In practice both are combined, since root and TLD servers refuse recursion. A third, older type, the inverse query, finds the name for an address; it is now an ordinary PTR lookup in in-addr.arpa.
POP3 compared with IMAP PIN 3/27
2080 Bhadra · Q7
2076 Chaitra · Q7
2074 Chaitra · Q7
POP3 and IMAP are both mail access (pull) protocols between a user agent and its mail server; they differ in where the mail is kept.
| Point | POP3 | IMAP |
|---|---|---|
| Port | TCP 110 (995 with TLS) | TCP 143 (993 with TLS) |
| Mail storage | downloaded, usually deleted from the server | stays on the server |
| Folders | only the inbox on the server | folders created on the server |
| Devices | suits one device | same mailbox on many devices |
| State | none kept between sessions | read and flagged state kept |
| Partial download | whole messages | headers or single parts |
| Search | on the local copy | on the server |
| Complexity | simple, little server storage | complex, more server storage |
The proxy server: what it is and why it is used PIN 3/27
2081 Baishakh · Q7
2075 Chaitra · Q7
2068 Baishakh · Q8
A proxy server is an intermediary between clients and the servers they reach: clients send their requests to it, and it forwards them on their behalf and relays the replies. A caching proxy (web cache) keeps copies of recently fetched objects and serves repeat requests from its own storage.
Functions and uses:
- Caching: a hit is served at LAN speed; a miss is fetched once, stored and forwarded; a stale copy is checked with a conditional GET (304 Not Modified).
- Bandwidth saving: less traffic on the costly access link and less load on the origin servers.
- Filtering and access control: blocking sites, or allowing them only at certain hours.
- Privacy and security: it hides the clients' IP addresses, scans downloads and is the single controlled exit.
- Logging: a record of web use; a reverse proxy also balances load.
The DNS server (domain name server) and its types PIN 2/27
2080 Baishakh · Q7
2072 Chaitra · Q10
A DNS server (name server) is a host running DNS software that stores part of the domain name database and answers queries about it, mainly over UDP port 53, translating host names into IP addresses and back. The servers form a hierarchy:
- Root servers: know the servers of every top-level domain; 13 named root servers, a to m, copied worldwide.
- TLD servers: know the name servers of every domain under com, org, np and the other top-level domains.
- Authoritative servers: hold a zone's actual resource records (A, MX, NS and others); a primary server and secondaries kept in step by zone transfer.
- Local DNS server (resolver): the ISP's or organization's server that hosts ask; it resolves names for them through the hierarchy and caches each answer for its TTL.
Resource records in DNS PIN 2/27
2078 Bhadra · Q7
2074 Ashwin · Q7
Resource records (RRs) are the entries of the DNS database: every zone is a set of RRs and every answer carries them. Each has the fields NAME, TYPE, CLASS (IN), TTL (seconds it may be cached) and RDATA (the value).
| Type | Holds | Example |
|---|---|---|
| A | IPv4 address | www A 192.0.2.80 |
| AAAA | IPv6 address | www AAAA 2001:db8::80 |
| CNAME | an alias's real name | ftp CNAME www |
| MX | mail server, with preference | MX 10 mail |
| NS | the zone's name server | NS ns1 |
| PTR | name for an address | reverse lookup |
| SOA | primary server, serial, timers | one per zone |
| TXT | text: SPF, verification | "v=spf1 mx -all" |
The email server and its components PIN 2/27
2072 Kartik · Q7
2070 Chaitra · Q7
An email server (mail server) is a host that sends, receives and stores mail for a domain's users: it keeps a mailbox per user and a queue of outgoing mail, and the domain's MX record points other servers to it.
Components: the message transfer agent (MTA: SMTP client and server), the mail queue, the message delivery agent (MDA) with the mailboxes, and the message access agent (POP3 or IMAP server).
DNS recursive query compared with iterative query PIN 1/27
2082 Bhadra · Q7
| Point | Recursive query | Iterative query |
|---|---|---|
| Work | the server asked finds the full answer itself | the asker follows the referrals itself |
| Reply | final answer or an error | answer, or a referral to other servers |
| Server load | high: it waits and keeps state | low: it answers at once |
| Typical use | host to its local DNS server | local server to root, TLD and authoritative servers |
DNS delegation PIN 1/27
2081 Bhadra · Q7
DNS delegation is the handing over of authority for a subdomain (a child zone) by its parent zone to another set of name servers. The parent stores NS records for the child, plus glue A records when those servers lie inside the child, and refers queries to them. Example: the edu.np zone delegates ioe.edu.np to IOE's own name servers, which manage its names independently. Delegation is what makes DNS distributed.
The structure of the DNS request and response PIN 1/27
2071 Chaitra · Q7
A DNS request and its response share one format: a 12-byte header followed by four sections.
- Identification (16 bits): set by the client; the response copies it, matching replies to queries.
- Flags (16 bits): QR (0 query, 1 response), Opcode (0 standard query), AA (authoritative answer), TC (truncated), RD (recursion desired), RA (recursion available), Z (zero), RCODE (0 no error, 3 name does not exist).
- Four counts: QDCOUNT, ANCOUNT, NSCOUNT, ARCOUNT, the entries in each section.
- Question section: QNAME, QTYPE (A, MX ...), QCLASS (IN).
- Answer, authority and additional sections: resource records (name, type, class, TTL, length, data): the answers, the NS records of a referral, and extras such as glue addresses.
Practical example, resolving www.example.com:
Request: ID=0x1A2B QR=0 RD=1 QDCOUNT=1 ANCOUNT=0
Question: www.example.com A IN (33 bytes, UDP to port 53)
Response: ID=0x1A2B QR=1 RD=1 RA=1 RCODE=0 QDCOUNT=1 ANCOUNT=1
Question: www.example.com A IN
Answer: www.example.com 3600 IN A 192.0.2.80 (49 bytes)
The response repeats the ID and the question, sets QR to 1, and adds the answer record, valid for 3600 seconds.
The importance of DNS and HTTP(S) in browsing a website PIN 1/27
2075 Chaitra · Q7
Browsing needs both: DNS finds where the website is, and HTTP or HTTPS fetches what it shows.
Importance of DNS:
- Name to address: the browser knows only the name in the URL; DNS returns the server's IP address, without which no connection can be opened.
- Speed: resolvers cache answers for their TTL, so repeat visits skip the lookup.
- Availability and load sharing: a name can map to several servers or to the nearest copy in a content delivery network.
- Flexibility: a site can move to new servers without changing its name.
Importance of HTTP(S):
- Fetching the page: HTTP requests (GET with headers) and responses (status code, headers, body) carry the HTML, images and scripts over TCP port 80.
- Status and state: codes such as 200, 301 and 404 tell the browser what happened; cookies keep a login across stateless requests.
- Security with HTTPS: TLS on port 443 authenticates the server by its certificate and encrypts and integrity-protects passwords, forms and payments.
Together: URL typed, DNS lookup, TCP connection, TLS handshake for HTTPS, HTTP GET, response, page rendered, further requests for the embedded objects.
SMTP and POP PIN 1/27
2074 Ashwin · Q10
SMTP (Simple Mail Transfer Protocol) is the push protocol that sends mail: from the user agent to its mail server (port 587) and between mail servers (TCP port 25). It exchanges text commands and reply codes, HELO, MAIL FROM, RCPT TO, DATA (the message ending with "."), QUIT, and carries 7-bit ASCII, so MIME encodes attachments.
POP (Post Office Protocol, version 3, TCP port 110) is a pull protocol by which a user agent fetches mail from its mailbox on the server. A session has three states: authorization (USER, PASS), transaction (LIST, RETR, DELE) and update (deletions applied after QUIT). It works in download-and-delete or download-and-keep mode.
SMTP cannot fetch mail out of a mailbox, so the two work together: SMTP delivers the mail to the receiver's server, and POP3 brings it to the receiver's computer.
HTTP and HTTPS services PIN 1/27
2081 Baishakh · Q7
HTTP (HyperText Transfer Protocol) is the web's application layer protocol: a stateless request and response protocol over TCP port 80. The browser sends a request (a method such as GET or POST, the URL, headers); the server returns a response (a status code such as 200 OK or 404, headers, the object). HTTP/1.1 keeps a connection open for several objects.
HTTPS is HTTP carried inside a TLS (formerly SSL) connection on TCP port 443. After a TLS handshake in which the server proves its identity with a certificate, every message is encrypted and integrity-checked.
| Point | HTTP | HTTPS |
|---|---|---|
| Port | 80 | 443 |
| Security | plain text | encrypted, server authenticated |
| Certificate | not needed | needed, from a certificate authority |
| URL | http:// | https:// |
| Use | public, non-sensitive pages | logins, payments, modern sites |
The HTTP protocol PIN 1/27
2069 Chaitra · Q7
HTTP (HyperText Transfer Protocol) is the application layer protocol of the World Wide Web. It is a stateless request and response protocol: a client, usually a browser, sends a request naming a resource by its URL with a method such as GET or POST, and a web server returns the resource with a status code. It runs over TCP, on port 80 by default (443 for HTTPS).
The web server PIN 1/27
2073 Shrawan · Q10
A web server is a program that stores web content and delivers it to clients over HTTP or HTTPS. It listens on TCP port 80 (443 for HTTPS); common web servers are Apache httpd, Nginx and Microsoft IIS.
Serving a request: it accepts the TCP connection, parses the HTTP request, maps the URL path to a file in its document root (static content) or passes it to a program such as PHP that builds the page (dynamic content), and returns a response with a status code (200, 404, 500), headers and the body; then it logs the request.
Features: many clients served at once (threads, processes or an event loop), persistent connections, virtual hosting of many sites on one IP address through the Host header, access control, TLS for HTTPS, and caching and compression for speed.
TFTP PIN 1/27
2076 Ashwin · Q7
TFTP (Trivial File Transfer Protocol, RFC 1350) is a minimal file transfer protocol over UDP port 69, with no login or authentication and no directory listing: it can only read or write a file. Data travels in numbered 512-byte blocks, each acknowledged before the next (stop and wait), and a shorter block ends the transfer. It is used to boot diskless machines and to load router and switch images.
Why computer networks need RAID PIN 1/27
2068 Chaitra · Q2
RAID is needed because network servers (web, mail, DNS, file, database) are shared by many users at once:
- Availability: with mirroring or parity the server keeps running when a disk fails, and the data survives.
- Performance: striping spreads reads and writes over several disks in parallel, serving many requests quickly.
- Capacity: several disks form one large volume.
RAID 0, RAID 1 and RAID 5 and their differences PIN 1/27
2068 Chaitra · Q2
RAID (Redundant Array of Independent Disks) combines several physical disks into one logical volume for speed, fault tolerance or both.
- RAID 0 (striping): data blocks are spread alternately across all the disks. The capacity is the sum of the disks and reads and writes are fastest, but there is no redundancy: one failed disk loses all the data. At least 2 disks.
- RAID 1 (mirroring): every block is written to two disks. The usable capacity is one disk; reads are fast and the array survives one disk failure; writes run at single-disk speed and the disk cost doubles. At least 2 disks.
- RAID 5 (striping with distributed parity): data and parity blocks are striped across n disks, the parity rotating between them. The usable capacity is n minus 1 disks; any one failed disk is rebuilt by XOR of the others (D1 = 1011, D2 = 0110, D3 = 1100 give parity 0001; a lost D2 = 1011 XOR 1100 XOR 0001 = 0110). Writes are slower, since the parity must be updated. At least 3 disks.
| Point | RAID 0 | RAID 1 | RAID 5 |
|---|---|---|---|
| Capacity | n × S | S | (n minus 1) × S |
| Fault tolerance | none | one disk | one disk |
| Speed | fastest | fast reads | fast reads, slower writes |
| Use | temporary data | system disks, small servers | file and web servers |
7Introduction to IPv6
Transition strategies from IPv4 to IPv6 HOT 8/27
2080 Baishakh · Q8
2078 Bhadra · Q8
2076 Ashwin · Q8
2075 Ashwin · Q8
2074 Chaitra · Q8
2073 Shrawan · Q7
2072 Kartik · Q8
2071 Chaitra · Q8
The transition from IPv4 to IPv6 is a gradual process with no switch-over day, since the two protocols are incompatible and billions of devices cannot change at once. Three strategies let the two coexist and interoperate:
- Dual stack: hosts and routers run IPv4 and IPv6 together, each interface holding both addresses. To reach a destination the host asks DNS: an AAAA record means IPv6, only an A record means IPv4. It is simple and native, but every node still needs an IPv4 address.
- Tunneling: when IPv6 nodes or networks are separated by an IPv4 region, the entry router puts the whole IPv6 packet inside an IPv4 packet (protocol 41) addressed to the exit router, which removes the IPv4 header. Tunnels are configured by hand or built automatically: 6to4, ISATAP, 6RD, Teredo.
- Header translation: when one side understands only IPv6 and the other only IPv4, a translator rewrites each header in the other version and maps the addresses (
64:ff9b::192.0.2.33to192.0.2.33): SIIT, or NAT64 with DNS64.
Process: dual stack is deployed first wherever possible, tunnels join IPv6 islands across IPv4 networks, and translation serves networks that become IPv6-only, until IPv4 is no longer needed.
Advantages of IPv6 over IPv4 HOT 5/27
2080 Baishakh · Q8
2078 Bhadra · Q8
2076 Ashwin · Q8
2074 Ashwin · Q8
2068 Baishakh · Q7
The main advantages of IPv6 over IPv4 are:
- Larger address space: 128-bit addresses, , against in IPv4, so every device can have a global address without NAT.
- Better header format: a fixed 40-byte header with no checksum and no fragmentation by routers, so it is processed faster.
- Extensibility: options sit in extension headers, so new features need no change to the base header.
- Smaller routing tables: hierarchical, aggregatable prefixes keep backbone routing efficient.
- Security: IPsec authentication (AH) and encryption (ESP) are defined as extension headers.
- Quality of service: the traffic class and flow label let routers give real-time audio and video special handling.
- Autoconfiguration: hosts configure their own addresses (SLAAC) without a DHCP server.
- Multicast and anycast: scoped multicast replaces broadcast; anycast reaches the nearest server.
- End-to-end connectivity and mobility: no NAT is needed, and Mobile IPv6 is supported.
Problems of IPv4 PIN 4/27
2079 Bhadra · Q8
2071 Chaitra · Q8
2071 Shrawan · Q8
2070 Ashad · Q9
IPv4 (RFC 791) was designed for a small research network and has these problems in today's Internet:
- Address exhaustion: 32-bit addresses give only , about 4.3 billion, far fewer than the devices in use; IANA's free pool ran out in February 2011.
- NAT: the workaround of private addresses behind NAT breaks end-to-end connectivity, peer-to-peer applications, VoIP and IPsec.
- Large routing tables: classful history and scattered allocations aggregate poorly.
- Complex header: a variable length of 20 to 60 bytes, options, a checksum recomputed at every hop and fragmentation by routers slow down forwarding.
- No built-in security: no authentication or encryption at the IP layer.
- Weak real-time support: no way to identify a flow of audio or video for special handling.
- Manual configuration: addresses are set by hand or by a DHCP server.
- Broadcast: ARP and other broadcasts disturb every host on the link.
How IPv6 solves the problems of IPv4 PIN 3/27
2079 Bhadra · Q8
2071 Chaitra · Q8
2071 Shrawan · Q8
IPv6 reduces or removes most of the drawbacks of IPv4:
| IPv4 drawback | How IPv6 solves it |
|---|---|
| Address exhaustion: only addresses | 128-bit addresses, ; one /64 subnet alone holds |
| NAT breaks end-to-end connectivity | every device gets a global address, so NAT is unnecessary |
| Slow, variable header with a checksum | fixed 40-byte header: no checksum, no options, no fragmentation by routers |
| Large routing tables | hierarchical prefixes (registry, ISP, site /48, subnet /64) aggregate into few routes |
| No IP-layer security | IPsec AH and ESP defined as extension headers |
| Poor real-time support | traffic class and a 20-bit flow label identify flows for special handling |
| Manual or DHCP configuration | stateless autoconfiguration (SLAAC) and easy renumbering; DHCPv6 optional |
| Broadcast load | no broadcast: scoped multicast and anycast |
| Rigid options | extension headers add features without changing the base header |
Not fully solved: IPv6 is not compatible with IPv4, so the two must coexist through dual stack, tunneling and translation for years; IPsec is now recommended rather than mandatory (RFC 6434); and routing tables stay small only if providers aggregate their prefixes.
Factors behind the development of IPv6 PIN 3/27
2074 Chaitra · Q8
2073 Shrawan · Q7
2066 Bhadra · Q5a
The factors that led to the speedy development of IPv6, and the reasons the world is now moving to it:
- Address exhaustion: the rapid growth of the Internet showed the IETF in the early 1990s that 32-bit addresses would run out; IANA's pool did run out in 2011, and APNIC, which serves Nepal, reached its last block in April 2011.
- New devices: smartphones, always-on broadband and IoT sensors each need an address, above all in developing countries now coming online.
- Limits of NAT: carrier-grade NAT is costly and breaks end-to-end applications.
- Real-time multimedia: audio and video need quality of service support.
- Security: the need for authentication and encryption at the IP layer.
- Efficiency: simpler headers, smaller routing tables, autoconfiguration and mobility.
- Industry push: at World IPv6 Launch (6 June 2012) major websites and ISPs switched IPv6 on permanently, and mobile operators now run IPv6-only networks.
The IPv6 datagram format and the function of each field PIN 3/27
2075 Ashwin · Q8
2070 Chaitra · Q8
2069 Chaitra · Q8
An IPv6 datagram consists of a fixed 40-byte base header followed by the payload: zero or more extension headers and then the upper-layer data (a TCP segment, a UDP datagram or an ICMPv6 message). The payload may be up to 65,535 bytes, or more with the jumbo payload option.
Function of each field:
- Version (4 bits): the IP version, 6 (0110).
- Traffic class (8 bits): the priority or class of service of the packet: a 6-bit DSCP for differentiated services and 2 ECN bits for congestion notification; it replaces IPv4's type of service.
- Flow label (20 bits): set by the source to identify the packets of one flow, such as a video call, so routers can give them the same handling without reading the transport header; 0 when unused.
- Payload length (16 bits): the length in bytes of everything after the base header (extension headers and data); the 40-byte base header is not counted.
- Next header (8 bits): the type of header that follows: an extension header (0 hop-by-hop, 43 routing, 44 fragment, 51 AH, 50 ESP, 60 destination options) or the upper-layer protocol (6 TCP, 17 UDP, 58 ICMPv6).
- Hop limit (8 bits): lowered by 1 at each router; at 0 the packet is discarded and an ICMPv6 Time Exceeded message is sent; it is IPv4's TTL renamed.
- Source address (128 bits): the IPv6 address of the sender.
- Destination address (128 bits): the IPv6 address of the receiver, or of the next node listed when a routing header is present.
Features of the format: the fixed size and 64-bit alignment allow fast hardware processing; there is no header checksum (the link and transport layers detect errors), no fragmentation fields (only the source fragments, using a fragment extension header), and no options (moved to extension headers, chained by the next header field).
The dual stack method PIN 3/27
2081 Baishakh · Q8
2080 Bhadra · Q10
2076 Chaitra · Q8
Dual stack (RFC 4213) is the transition strategy in which a node implements both IPv4 and IPv6, so it talks to IPv4-only nodes in IPv4 and to IPv6 nodes in IPv6 until the whole Internet uses IPv6.
- Structure: one application and transport layer (TCP, UDP) sits over two network layers, IPv4 and IPv6, sharing the same link layer; each interface holds an IPv4 address and an IPv6 address.
- Choosing the version: the source queries DNS; an AAAA record means it sends IPv6, only an A record means IPv4. Modern hosts try IPv6 first and fall back to IPv4 quickly (Happy Eyeballs).
- Routers: dual-stack routers forward both protocols, with two routing tables and two sets of routing protocols (OSPFv2 and OSPFv3).
- Advantages: simple, native performance, no encapsulation or translation, and services move to IPv6 one by one.
- Disadvantages: every node still needs an IPv4 address, and two stacks double the configuration, security policy and memory.
IPv4 header compared with IPv6 header PIN 2/27
2081 Baishakh · Q8
2072 Chaitra · Q7
The IPv6 header is a fixed 40 bytes with 8 fields; the IPv4 header is 20 to 60 bytes with 12 fields plus options. Field by field:
| IPv4 field | In IPv6 |
|---|---|
| Version | kept (value 6) |
| Header length (IHL) | removed: the length is fixed |
| Type of service | renamed traffic class |
| Total length | renamed payload length (excludes the header) |
| Identification, flags, fragment offset | removed: moved to the fragment extension header |
| Time to live | renamed hop limit |
| Protocol | renamed next header |
| Header checksum | removed |
| Source, destination (32 bits each) | kept, 128 bits each |
| Options and padding | removed: extension headers instead |
| None | added: flow label (20 bits) |
The result: addresses four times longer, a header only twice as long, and faster processing at every router.
IPv6 address types and their notation PIN 2/27
2080 Bhadra · Q8
2066 Bhadra · Q5a
An IPv6 address is 128 bits, written as eight groups of four hexadecimal digits separated by colons; leading zeros in a group may be dropped and one run of zero groups replaced by ::, so 2001:0db8:0000:0000:0000:ff00:0042:8329 is written 2001:db8::ff00:42:8329. A prefix takes a slash: 2001:db8:acad:1::/64.
| Type | Delivered to | Notation |
|---|---|---|
| Unicast | one interface | global 2000::/3, link-local fe80::/10, unique local fc00::/7 |
| Anycast | the nearest of a group | taken from unicast space, such as 2001:db8:acad:1:: |
| Multicast | every member of a group | ff00::/8, such as ff02::1 |
IPv6 has no broadcast.
What IPv4 and IPv6 coexistence means PIN 2/27
2076 Chaitra · Q8
2075 Chaitra · Q8
IPv4 and IPv6 coexistence means both protocols running side by side on the same Internet, often on the same hosts, links and routers, during the long transition. The two are not compatible: an IPv4-only node cannot read an IPv6 packet. Since billions of devices cannot change on one day, IPv4-only, IPv6-only and dual-stack nodes must all keep communicating. Coexistence is achieved by dual stack (nodes run both), tunneling (IPv6 carried inside IPv4 across IPv4 networks) and header translation (IPv6-only and IPv4-only nodes talking through a translator), until IPv4 can be switched off.
What IPv6 is PIN 1/27
2072 Kartik · Q8
IPv6 (Internet Protocol version 6) is the network layer protocol designed by the IETF to replace IPv4 (RFC 8200). Like IPv4 it delivers datagrams connectionlessly from source to destination, but it uses 128-bit addresses ( of them), a fixed 40-byte header with extension headers for options, stateless autoconfiguration, multicast and anycast in place of broadcast, and support for IPsec and flow labels.
IPv4 and IPv6 compared in routing and header manipulation PIN 1/27
2081 Bhadra · Q8
| Point | IPv4 | IPv6 |
|---|---|---|
| Header at each router | variable 20 to 60 bytes; IHL read first; options processed | fixed 40 bytes; extension headers skipped, except hop-by-hop |
| Checksum | verified and recomputed at every hop after the TTL change | none; only the hop limit is lowered |
| Fragmentation | routers fragment oversized packets | only the source; routers send ICMPv6 Packet Too Big |
| Address rewriting | NAT rewrites addresses, ports and checksums | NAT not needed; addresses stay end to end |
| Routing table | large, poorly aggregated | hierarchical prefixes aggregate |
| Flow handling | port numbers read deep in the packet | flow label in the header |
| Protocols | RIP, OSPFv2, BGP; ARP | RIPng, OSPFv3, MP-BGP; neighbour discovery |
Critically: IPv6 makes per-hop header manipulation much lighter, but 128-bit lookups need more router memory, packets with extension headers (hop-by-hop above all) take a slow path and are often dropped, dual-stack routers carry two routing tables during the transition, and filtering ICMPv6 breaks path MTU discovery.
IPv6 extension headers in order PIN 1/27
2082 Bhadra · Q8
The IPv6 extension headers follow the base header in this recommended order (RFC 8200), each named by the next header field of the header before it:
- Hop-by-hop options (0)
- Destination options, for the routing-header nodes (60)
- Routing (43)
- Fragment (44)
- Authentication header, AH (51)
- Encapsulating security payload, ESP (50)
- Destination options, for the final destination (60)
- Upper-layer header: TCP (6), UDP (17), ICMPv6 (58)
An IPv4 address mapped to its IPv6 equivalent PIN 1/27
2082 Baishakh · Q8
An IPv4 address is written in IPv6 as an IPv4-mapped IPv6 address: 80 zero bits, 16 one bits, then the 32-bit IPv4 address, written ::ffff:a.b.c.d. For example, 192.0.2.33 becomes ::ffff:192.0.2.33, in hexadecimal ::ffff:c000:221 (192 = c0, 0 = 00, 2 = 02, 33 = 21). Dual-stack sockets and translators use this form; NAT64 uses 64:ff9b::c000:221.
Header translation and tunneling PIN 1/27
2074 Ashwin · Q8
Tunneling carries IPv6 traffic across an IPv4-only network. The router at the tunnel entry encapsulates the complete IPv6 packet as the payload of an IPv4 packet (protocol field 41) addressed to the tunnel exit, where the IPv4 header is removed and the IPv6 packet continues. The IPv4 routers in between treat it as ordinary IPv4. Tunnels are manual or automatic (6to4, ISATAP, 6RD).
Header translation is used when one end understands only IPv6 and the other only IPv4. A translator rewrites each IPv6 header as an IPv4 header and back: the IPv4 address is taken from the last 32 bits of the mapped IPv6 address, hop limit becomes TTL, next header becomes protocol, the flow label is dropped and a checksum is computed (NAT64 with DNS64).
ISATAP and 6to4 tunneling with their address formats PIN 1/27
2082 Bhadra · Q8
Both are automatic tunnels: the IPv4 end of the tunnel is read from inside the IPv6 address, so no tunnel is configured by hand. IPv6 packets travel inside IPv4 packets with protocol number 41.
6to4 (RFC 3056) connects IPv6 sites across the IPv4 Internet. A site whose router has the public IPv4 address 192.0.2.4 (c000:0204) gets the prefix 2002:c000:204::/48.
- Format: 2002 (16 bits) | IPv4 address of the site router (32) | subnet ID (16) | interface ID (64).
- Operation: to reach another 6to4 site the router copies the IPv4 address out of bits 17 to 48 of the destination and tunnels straight to it; to reach native IPv6 it tunnels to a 6to4 relay router.
ISATAP (RFC 5214), the Intra-Site Automatic Tunnel Addressing Protocol, connects dual-stack hosts inside an IPv4-only site, treating the IPv4 network as one link.
- Format: 64-bit prefix |
0000:5efe(private IPv4) or0200:5efe(global IPv4) | IPv4 address of the host (32): host10.1.1.5getsfe80::5efe:a01:105. - Operation: the host sends a router solicitation tunnelled in IPv4 to the ISATAP router, receives the prefix and forms its global address; it tunnels directly to other ISATAP hosts at the IPv4 address in the last 32 bits, and through the ISATAP router to the rest of the IPv6 Internet.
The latest IPv6 transition methods, with one explained PIN 1/27
2082 Baishakh · Q8
Current best practice (RFC 6180) is dual stack wherever both protocols can run and, where IPv4 addresses are scarce, IPv6-only networks that carry IPv4 as a service:
- Dual stack with Happy Eyeballs: native IPv4 and IPv6 together.
- NAT64 with DNS64 (RFC 6146, RFC 6147): IPv6-only clients reach IPv4-only servers.
- 464XLAT (RFC 6877): IPv4 applications on IPv6-only mobile networks.
- DS-Lite (RFC 6333): IPv4 tunnelled inside IPv6 to the ISP's carrier-grade NAT.
- MAP-E and MAP-T (RFC 7597, RFC 7599): stateless IPv4 address and port sharing over IPv6.
- 6RD (RFC 5969): IPv6 over an ISP's IPv4 network.
464XLAT explained: on an IPv6-only mobile network, an IPv4-only application on the phone still sends IPv4 packets. The CLAT (customer-side translator) on the phone translates them statelessly into IPv6, embedding the IPv4 destination in the NAT64 prefix (192.0.2.33 becomes 64:ff9b::c000:221). The IPv6 packets cross the operator's network to the PLAT, a stateful NAT64, which translates them back into IPv4 from its shared public address. Replies return the same way, so IPv4 applications work while the network itself runs no IPv4.
The method to suggest for migration, and why PIN 1/27
2072 Chaitra · Q7
Dual stack is the method to suggest, with tunneling and translation only where dual stack is impossible.
- Native for both: each node speaks IPv4 to IPv4 hosts and IPv6 to IPv6 hosts, with no encapsulation overhead and no translation side effects.
- Gradual: services move to IPv6 one at a time, DNS records decide which protocol is used, and IPv4 is switched off later without a flag day.
- Simple and reliable: no relays or translators to fail; it is the IETF's recommended first step (RFC 6180).
Its limit is that every node still needs an IPv4 address. So an organisation short of IPv4 addresses runs IPv6-only inside, with NAT64 and DNS64 (464XLAT on phones) for IPv4 content, and an IPv6 site cut off by an IPv4 network uses a tunnel (6RD from its ISP) until native IPv6 arrives.
8Network security
The types of firewall, with figures HOT 7/27
2081 Baishakh · Q10
2076 Ashwin · Q10
2074 Chaitra · Q10
2073 Shrawan · Q9
2072 Chaitra · Q8
2072 Kartik · Q9
2070 Chaitra · Q9
A firewall controls the traffic between a trusted network and an untrusted one by a security policy. By the layer it inspects, there are four main types:
- Packet filtering firewall: a router or host that checks each packet on its own against a rule table, by source and destination IP address, protocol, port numbers and direction; the first matching rule permits or denies it, and an implicit deny drops the rest. It is fast, cheap and transparent, but keeps no state, reads no content and cannot detect a spoofed address.
- Stateful inspection firewall: a packet filter that also keeps a table of open connections and admits an inbound packet only if it belongs to one, so forged replies are dropped.
- Application-level gateway (proxy): works at the application layer; the client connects to the proxy, which checks the request (URL, FTP command, mail attachment, user) and opens its own connection to the server. It is the most secure and logs everything, but it is slower and needs a proxy for each service.
- Circuit-level gateway: works at the session layer; it validates the TCP handshake and then relays the connection without reading the data, as SOCKS does.
A next-generation firewall combines these with intrusion prevention and application awareness.
The properties of secure communication HOT 5/27
2080 Bhadra · Q9
2076 Chaitra · Q10
2076 Ashwin · Q9
2075 Chaitra · Q9
2074 Ashwin · Q9
Secure communication between a sender and a receiver over an insecure network needs six properties:
- Confidentiality: only the sender and the intended receiver can understand the message; provided by encryption.
- Integrity: the message is not altered in transit, by accident or by an attacker; provided by hashes, MACs and digital signatures.
- Authentication: each party can confirm the identity of the other, and that a message really came from its claimed sender.
- Non-repudiation: the sender cannot later deny having sent the message; provided by digital signatures.
- Availability: the network and its services stay usable by authorised users when needed, despite attacks such as denial of service.
- Access control: only authorised users reach a resource, and only with the rights they hold; enforced by firewalls, ACLs and permissions.
Each property answers an attack: interception breaks confidentiality, modification integrity, fabrication authentication, and interruption availability.
What network security is PIN 4/27
2071 Chaitra · Q4
2070 Chaitra · Q10
2069 Chaitra · Q10
2068 Chaitra · Q9
Network security is the set of policies, practices and technologies that protect a network and the data crossing it from unauthorised access, misuse, modification and disruption, so that a sender and a receiver can communicate securely over an insecure medium such as the Internet.
An intruder on the path may intercept (read), interrupt (block), modify or fabricate messages, passively or actively. Network security therefore provides:
- Confidentiality by encryption;
- Integrity by hashes and MACs;
- Authentication and non-repudiation by passwords, certificates and digital signatures;
- Availability by redundancy and protection against denial of service;
- Access control by firewalls and ACLs.
It is applied at every layer: PGP for e-mail, SSL/TLS for TCP connections, IPsec and VPNs for IP packets, WPA2 for wireless LANs, with firewalls and intrusion detection systems at the boundary. For example, an online banking session is encrypted by TLS, the bank's server proves its identity with a certificate, and the bank's firewall admits only HTTPS traffic to its web server.
Virtual private network (VPN), with an example PIN 4/27
2082 Bhadra · Q10
2079 Bhadra · Q10
2075 Chaitra · Q10
2071 Chaitra · Q4
A VPN (virtual private network) is a private network over a public one, created by tunnelling: each packet is encrypted, authenticated and carried inside a new packet between the VPN endpoints.
- Working: the endpoints authenticate each other and agree keys; outgoing packets are encrypted and wrapped with a header addressed to the far gateway; the Internet routes them; the far gateway decrypts and delivers them.
- Remote-access VPN: a user's device connects to the organisation's gateway through VPN client software.
- Site-to-site VPN: gateways join whole LANs, as an intranet (one organisation) or an extranet (partners).
- Protocols: IPsec, SSL/TLS (OpenVPN), L2TP over IPsec, WireGuard.
Example: a company's head office in Kathmandu and its branch in Pokhara join their LANs through an IPsec tunnel over ordinary Internet links; it costs far less than a leased line and keeps the traffic private.
How firewalls protect a network and enhance its security PIN 3/27
2072 Chaitra · Q8
2070 Chaitra · Q9
2069 Chaitra · Q10
2069 Chaitra · Q10
A firewall protects a network by standing at its only gateway to the outside, so that every packet in or out crosses one point where the security policy is enforced:
- Choke point: all traffic passes through one place, where it is checked and logged.
- Filtering: packets from unwanted addresses, ports and protocols (Telnet, remote desktop) are blocked; whatever is not explicitly allowed is denied.
- Stateful control: inbound packets are admitted only as replies to connections opened from inside.
- Hiding the inside: NAT and proxies hide internal addresses and hosts.
- Content control: a proxy blocks malware, banned sites and dangerous commands, and authenticates users.
- Zones and alerts: public servers sit in a DMZ, apart from the trusted LAN; floods and attacks are logged and reported.
In this way a firewall enforces access control and protects availability, though it cannot stop insiders or traffic that bypasses it.
Symmetric key against public key (asymmetric) cryptography PIN 3/27
2073 Shrawan · Q8
2071 Shrawan · Q9
2069 Chaitra · Q9
Symmetric key cryptography uses one secret key, shared by the sender and the receiver, both to encrypt and to decrypt. Public key (asymmetric) cryptography uses a key pair: the sender encrypts with the receiver's public key, and only the receiver's private key decrypts.
| Point | Symmetric key | Public key |
|---|---|---|
| Keys | one shared secret key | a public key and a private key |
| Key holders | both parties, secretly | public key: anyone; private key: owner only |
| Speed | fast, suits bulk data | slow, suits short data such as keys |
| Key distribution | difficult: the key must be shared secretly first | easy: the public key is published |
| Keys for n users | ||
| Key length | 128 to 256 bits | 2048 bits or more (RSA) |
| Services | confidentiality | confidentiality, authentication, non-repudiation, key exchange |
| Examples | DES, 3DES, AES, IDEA, RC4 | RSA, Diffie-Hellman, ElGamal, ECC |
In practice the two are combined: public key cryptography exchanges a random session key, and a symmetric cipher encrypts the data with it, as in TLS and PGP.
SSL: the secure socket layer PIN 3/27
2071 Chaitra · Q10
2071 Shrawan · Q10
2068 Baishakh · Q9
SSL (Secure Sockets Layer, Netscape), now succeeded by TLS, is a protocol layer between TCP and the application that secures a connection: it authenticates the server by its certificate, encrypts the data with symmetric session keys and protects its integrity with a MAC. HTTPS is HTTP over SSL/TLS, on port 443.
- Handshake protocol: client and server exchange hellos and random numbers and agree a cipher suite; the server sends its certificate; the client sends a pre-master secret encrypted with the server's public key; both derive the session keys.
- Change cipher spec protocol: both sides switch to the new keys, and Finished messages confirm the handshake was not tampered with.
- Record protocol: fragments the data, optionally compresses it, adds a MAC, encrypts it and adds a header.
- Alert protocol: reports errors.
What a firewall is PIN 3/27
2082 Bhadra · Q9
2073 Shrawan · Q9
2072 Kartik · Q9
A firewall is a hardware device or software placed at the boundary between a trusted internal network and an untrusted one such as the Internet. All traffic between them passes through it, and it permits or blocks each packet or connection according to a security policy, its rule set; for example, it lets web traffic out while blocking Telnet from outside.
What public key cryptography is PIN 2/27
2081 Baishakh · Q9
2071 Chaitra · Q9
Public key (asymmetric) cryptography gives each user a pair of keys: a public key, published to everyone, and a private key kept secret by its owner; what one key encrypts, only the other decrypts. To send a secret to B, A encrypts with B's public key and only B's private key can decrypt it; signing with a private key gives digital signatures. RSA and Diffie-Hellman are examples. No secret key has to be shared in advance.
What PGP is PIN 2/27
2082 Baishakh · Q10
2080 Baishakh · Q9
PGP (Pretty Good Privacy, Phil Zimmermann, 1991) is an e-mail security program, standardised as OpenPGP, that gives e-mail confidentiality, authentication, integrity and compression by combining public key and symmetric cryptography.
- Authentication and integrity: the sender signs a hash of the message with its private key.
- Confidentiality: the message is encrypted with a one-time symmetric session key (IDEA, 3DES, AES), and the session key with the receiver's public key.
- Compression: the signed message is compressed with ZIP before encryption.
- E-mail compatibility: the binary result is converted to radix-64 (base64) text.
- Segmentation: long messages are split and rejoined.
Keys are kept in public and private key rings, and public keys are trusted through a web of trust in which users sign one another's keys.
IPsec PIN 2/27
2080 Baishakh · Q10
2072 Kartik · Q10
IPsec (IP security) is an IETF suite of protocols that secures IP packets at the network layer, between hosts, routers or both, so that every application above IP is protected. It works with IPv4 and IPv6.
- AH (Authentication Header): source authentication, integrity and anti-replay, without encryption.
- ESP (Encapsulating Security Payload): encryption, plus authentication and integrity.
- Transport mode: protects only the payload, the original IP header stays; host to host.
- Tunnel mode: the whole packet is protected inside a new IP header; gateway to gateway, as in VPNs.
- Security association (SA): a one-way agreement of protocol, algorithms, keys and sequence numbers, identified by the SPI, the destination address and the protocol.
- IKE: authenticates the two ends and sets up the SAs using Diffie-Hellman.
WEP: wired equivalent privacy PIN 2/27
2071 Chaitra · Q10
2071 Shrawan · Q10
WEP (Wired Equivalent Privacy) is the security protocol of the original IEEE 802.11 standard, meant to give a wireless LAN the privacy of a wired one: confidentiality, access control and integrity.
- Encryption: a 24-bit initialization vector (IV) is joined to a shared 40 or 104-bit key to seed the RC4 stream cipher; a CRC-32 integrity check value is appended to the data; data and check value are XORed with the RC4 keystream; the IV travels in the clear with the frame.
- Decryption: the receiver makes the same keystream from the IV and the key, XORs, and checks the CRC.
- Weaknesses: the 24-bit IV repeats, so keystreams are reused; weak RC4 keys leak the key; CRC-32 is linear and lets frames be altered; one static key is shared by all.
WEP can be cracked in minutes, so it was replaced by WPA (TKIP) and WPA2 (AES with CCMP, IEEE 802.11i).
What cryptography is PIN 1/27
2071 Shrawan · Q9
Cryptography is the science of securing messages by transforming readable plaintext into unreadable ciphertext with an algorithm (a cipher) and a key, so that only the holder of the right key can recover the plaintext. It provides confidentiality and, with hashes and signatures, integrity, authentication and non-repudiation. Its two types are symmetric key cryptography (one shared secret key, as in AES) and public key cryptography (a public and private key pair, as in RSA).
The types of encryption used in security PIN 1/27
2074 Chaitra · Q9
Encryption turns plaintext into ciphertext with a key. It is of two types, with the hash function as a third, one-way tool:
- Symmetric key (secret key) encryption: the same secret key encrypts and decrypts, and . It is fast and suits bulk data, but the key must be shared secretly and users need keys. Block ciphers (DES, 3DES, AES, IDEA) encrypt fixed blocks; stream ciphers (RC4) XOR the data with a keystream.
- Asymmetric (public key) encryption: each user has a public key and a private key; data encrypted with the receiver's public key is decrypted only with its private key, and data signed with a private key is verified with the public key. It solves key distribution and gives digital signatures, but it is slow. Examples: RSA, Diffie-Hellman, ECC.
- Hashing: a keyless one-way function, such as SHA-256, that gives a fixed-length digest; it cannot be decrypted and serves integrity and signatures.
Real systems are hybrid: a public key method exchanges a session key, and a symmetric cipher encrypts the data.
Symmetric key cryptography PIN 1/27
2075 Chaitra · Q10
Symmetric key cryptography (secret key or conventional cryptography) uses a single secret key, shared by the sender and the receiver, for both encryption and decryption: , .
- Types: block ciphers encrypt fixed blocks (DES: 64-bit block, 56-bit key; AES: 128-bit block, 128 to 256-bit key); stream ciphers XOR the data with a keystream (RC4).
- Advantages: fast, with short keys; suits long messages and bulk data such as disk encryption, VPNs and Wi-Fi.
- Disadvantages: the key must reach the receiver secretly before use (the key distribution problem); users need keys; no non-repudiation, as both sides hold the same key.
It is therefore combined with public key cryptography, which exchanges the symmetric session key, as in TLS and PGP.
The fundamental differences between AES and DES PIN 1/27
2081 Bhadra · Q9
DES and AES are both symmetric block ciphers; AES (2001) replaced DES (1977).
| Point | DES | AES |
|---|---|---|
| Block size | 64 bits | 128 bits |
| Key size | 56 bits | 128, 192 or 256 bits |
| Rounds | 16 | 10, 12 or 14 |
| Structure | Feistel network | substitution-permutation network |
| Round steps | expansion, XOR, S-boxes, permutation | SubBytes, ShiftRows, MixColumns, AddRoundKey |
| Security | broken by brute force | secure; the current standard |
What a digital signature is PIN 1/27
2079 Bhadra · Q9
A digital signature is a value computed from a message and the sender's private key, usually by encrypting a hash of the message with that key, which anyone can verify with the sender's public key. It proves who sent the message (authentication), that it is unaltered (integrity), and that the sender cannot deny sending it (non-repudiation).
AH and ESP in IPsec PIN 1/27
2082 Bhadra · Q10
IPsec has two security protocols.
AH (Authentication Header, IP protocol 51) provides source authentication, data integrity and anti-replay, but no confidentiality. Its fields are next header, payload length, reserved, security parameter index (SPI), sequence number and authentication data: a keyed hash over the packet, with fields that change in transit, such as TTL, taken as zero.
ESP (Encapsulating Security Payload, IP protocol 50) provides confidentiality by encryption, plus authentication, integrity and anti-replay. It adds an ESP header (SPI, sequence number), an ESP trailer (padding, pad length, next header) and ESP authentication data; the payload and trailer are encrypted.
| Point | AH | ESP |
|---|---|---|
| Encryption | no | yes |
| Authenticates the outer IP header | yes | no |
| Works through NAT | no | yes |
What a VPN is PIN 1/27
2075 Ashwin · Q9
A VPN (virtual private network) is a private network built over a public network such as the Internet by tunnelling: packets are encrypted and authenticated, then carried inside other packets between VPN gateways or clients, so that remote sites and users communicate as if on one private LAN. Examples are a site-to-site IPsec VPN between a head office and its branch, and a remote-access VPN from a home laptop.
Intrusion detection system (IDS) PIN 1/27
2071 Shrawan · Q10
An intrusion detection system (IDS) is a device or software that monitors a network or its hosts for malicious activity or policy violations and alerts an administrator or a SIEM system.
- Network IDS (NIDS): a sensor on a mirror port or tap at a key point analyses the traffic of a whole segment (Snort, Suricata).
- Host IDS (HIDS): an agent on a host watches its logs, processes and system files, comparing file snapshots (OSSEC, Tripwire).
- Signature-based detection: matches known attack patterns; accurate, but blind to new attacks.
- Anomaly-based detection: builds a baseline of normal behaviour and flags deviations; catches new attacks, with more false alarms.
An IDS only detects and alerts; an intrusion prevention system (IPS) sits in the traffic's path and blocks. An IDS complements a firewall by finding attacks hidden in allowed traffic or coming from insiders.
2082 Bhadra Regular · 17 questions
Q12 marksDefine protocol with examples.Ch 1
Q12 marksWhy do we have layered architecture in networks?Ch 1
Q14 marksDifferentiate between TCP/IP and OSI model.Ch 1
Q24 marksExplain line of sight (LOS) propagation modes.Ch 2
Q22 marksDraw block diagram generic optical fiber (OF) communication system and its RF range.Ch 2
Q34 marksWrite different ways to correct backward error correction.Ch 3
Q34 marksCompare pure Aloha and slotted Aloha mentioning the condition for no collision.Ch 3
Q42 marksWhat are routing protocols?Ch 4
Q62 marksWrite UDP header field and functions.Ch 5
Q72 marksCompare DNS recursive query vs. iterative query.Ch 6
Q82 marksList the IPv6 extension headers in order.Ch 7
Q86 marksExplain ISATAP and 6 to 4 tunneling with their address format for IPv4 to IPv6 transition.Ch 7
Q92 marksWhat do you mean by firewall?Ch 8
Q104 marksa) ARP and NDPCh 4
Q104 marksb) AH and ESPCh 8
Q104 marksc) VPNCh 8
Q104 marksd) vLANCh 3
2082 Baishakh Back · 17 questions
Q14 marksExplain client/server and P2P network model with their advantages and disadvantages.Ch 1
Q14 marksDiscuss the layer of TCP/IP model with suitable diagram.Ch 1
Q22 marksWhat are the functions of data link layer?Ch 3
Q23 marksHow to detect signal collision in CSMA/CD?Ch 3
Q23 marksList the ethernet cable specification standards for 802.3 ethernet standards.Ch 3
Q31 markWhat is hamming distance?Ch 3
Q32 marksHow do you apply it in data link layer error control mechanism?Ch 3
Q42 marksDefine routed and routing protocol.Ch 4
Q51 markList the range of IPv4 address classes.Ch 4
Q62 marksDiscuss UDP headerCh 5
Q6compare it with TCPCh 5
Q62 marksWhat is port address?Ch 5
Q82 marksMap IPv4 addresses with its IPv6 equivalent.Ch 7
Q82+4 marksWhat are the latest best IPv6 transition methodologies? Explain anyone of them.Ch 7
Q104 marksb) PGPCh 8
Q104 marksSocket programming fundamentalsCh 6
Q104 marksX.25 NetworkCh 1
2081 Bhadra Regular · 19 questions
Q12 marksDefine Network.Ch 1
Q1List a function of each layer of OSI reference modelCh 1
Q1compare it with TCPI/IP model.Ch 1
Q22 marksWhat are the factors to be considered while selecting media for communication?Ch 2
Q26 marksDifferentiate between datagram and virtual circuit switching approach with respect to Frame Relay Network.Ch 2
Q31 markWhat is piggy-backing?Ch 3
Q32 marksHow do you apply it in data link layer flow control mechanism?Ch 3
Q42 marksWhat is adaptive and non-adaptive routing?Ch 4
Q42 marksList the properties of link state routingCh 4
Q51 markWhat is super-netting?Ch 4
Q62 marksWhy TCP is known as reliable protocol?Ch 5
Q62 marksWhat are the congestion control techniques applied in network communication?Ch 5
Q6compare it with leaky bucketCh 5
Q72 marksWhat do you mean by DNS delegation?Ch 6
Q84 marksCritically compare IPv4 and IPv6 in terms of routing and head manipulation.Ch 7
Q92 marksWhat are the fundamental difference between AES and DES?Ch 8
Q104 marksa) 802.4 Token BusCh 3
Q104 marksb) Framing with bit stuffingCh 3
Q104 marksATMCh 1
2081 Baishakh Back · 16 questions
Q11 markWhat is a protocol?Ch 1
Q13 marksList out the common protocols used at each layer of TCP/IP model.Ch 1
Q14 marksDifferentiate between client-server is P2P network.Ch 1
Q23 marksList out the most common guided and unguided transmission media used in computer networks now a days.Ch 2
Q25 marksExplain any one of the guided transmission media with examples.Ch 2
Q32 marksWhy is it not applicable in wireless LAN?Ch 3
Q43 marksIn which case VLSM is used while dividing the given block of IP addresses for different subnets and why?Ch 4
Q58 marksWhat is ICMP? Explain the importance and uses of ICMP in TCP/IP protocol suit.Ch 4
Q63 marksThough UDP is said to be unreliable protocol, it is used in Internet. Why?Ch 5
Q74 marksWhat is a proxy server? Why is it used?Ch 6
Q74 marksDiscuss briefly on HTTP and HTTPS services.Ch 6
Q84 marksCompare the IPv4 header with IPv6 header.Ch 7
Q84 marksExplain the dual stack strategy to transit from IPv4 to IPv6.Ch 7
Q91 markWhat is public key cryptography?Ch 8
Q104 marksa) MAC sublayerCh 3
Q104 marksc) FirewallCh 8
2080 Bhadra Regular · 11 questions
Q13 marksDifferentiate between Client Server and Peer to Peer architecture.Ch 1
Q15 marksDiscuss the functions of each layer of Open System Interconnection (OSI) model.Ch 1
Q23 marksDiscuss about the different factors of choosing the transmission media.Ch 2
Q23 marksCircuit switching is suitable for real-time communication", give your reasons.Ch 2
Q64 marksHow does Token Bucket control the congestion over the Leaky Bucket algorithm?Ch 5
Q74 marksCompare POP3 and IMAP protocols.Ch 6
Q83 marksExplain the three address types in IPv6 with the IP notations.Ch 7
Q92 marksWhat are the properties of secure communication?Ch 8
Q104 marksa) Go Back-N ARQCh 3
Q104 marksb) Dual Stack method in IPv6Ch 7
Q104 marksATMCh 1
2080 Baishakh Back · 16 questions
Q13 marksWhy do we need layered architecture in computer network?Ch 1
Q15 marksDiscuss the function of each layer of TCP/IP networking model.Ch 1
Q21+2 marksWhat is multiplexing? What is its importance in communication?Ch 2
Q25 marksExplain different types of multiplexing techniques.Ch 2
Q44 marksWhat is unicast and multicast?Ch 4
Q44 marksCompare distance vector routing protocol and link state routing protocol with examples.Ch 4
Q62 marksWhat is port number?Ch 5
Q64 marksWhy is it necessary to standardize the port numbers for well-known servers?Ch 5
Q62 marksWhat happens when a web service is hosted at some different port such as 8765 instead of 80? Explain.Ch 5
Q72 marksWhat is DNS server?Ch 6
Q76 marksExplain the recursive and iterative query.Ch 6
Q82 marksWhat are the advantages of IPv6?Ch 7
Q86 marksBriefly explain the different transition strategies.Ch 7
Q93 marksWhat is PGP?Ch 8
Q104 marksa) VLANCh 3
Q104 marksc) IPSecCh 8
2079 Bhadra Regular · 14 questions
Q18 marksCompare the OSI reference model and TCP/IP reference model mentioning their similarities and differences.Ch 1
Q24 marksWhat is switching and multiplexing?Ch 2
Q24 marksExplain switching technique used in modern computer networks.Ch 2
Q34 marksDescribe Ethernet (IEEE 802.3) frame structure with function of each field.Ch 3
Q44 marksWhy do we prefer a switch as networking device instead of Hub for LAN connection? Give reasons.Ch 4
Q44 marksDiscuss the characteristics of a good routing algorithm.Ch 4
Q64 marksWhat are the features of UDP protocol?Ch 5
Q64 marksIn which case is UDP preferred as a transport layer protocol? Discuss with practical examples.Ch 5
Q72+2 marksWhat is DNS? Why is it used?Ch 6
Q82 marksWhat are the problems of IPV4?Ch 7
Q82 marksHow can IPV6 reduce these problems?Ch 7
Q91 markWhat is a digital signature?Ch 8
Q104 marksa) ALOHACh 3
Q104 marksc) VPNCh 8
2078 Bhadra Regular · 12 questions
Q15 marksDifferentiate it with peer-to-peer network with advantages and disadvantages.Ch 1
Q21 markDefine Throughput.Ch 2
Q24 marksDifferentiate between Packet switching and Virtual Circuit switching.Ch 2
Q34 marksHow carrier sense multiple access with collision detection (CSMA/CD) is better than CSMA?Ch 3
Q53 marksDefine routing algorithm. List out the properties/goals of routing algorithm.Ch 4
Q63 marksWhat are services provided by Transport layer?Ch 5
Q73 marksWhat are resource records in DNS?Ch 6
Q75 marksExplain the types of DNS queries with example.Ch 6
Q82 marksList advantages of IPv6 over IPv4.Ch 7
Q86 marksExplain any two suitable transition strategies for IPv4 to IPv6.Ch 7
Q104 marksFrame relayCh 1
Q104 marksc) HDLCCh 3
2076 Chaitra Regular · 15 questions
Q11 markWhat is protocol?Ch 1
Q12 marksWhat are the reasons for using layered network architecture?Ch 1
Q15 marksCompare OSI with TCP/IP reference model.Ch 1
Q21 markWhat is transmission medium?Ch 2
Q27 marksExplain different transmission medium with their merits and demerits.Ch 2
Q31+1 marksWhat is collision? How is it occured?Ch 3
Q36 marksHow the possibility of collision is reduced in IEEE 802.3 and IEEE 802.11? Explain.Ch 3
Q54 marksWhat is the purpose of Time to live (TTL) and protocol field in header of IPv4 datagram.Ch 4
Q51 markWhich protocol is used in internet layer to provide feedback to hosts/routers about the problems in the network environment?Ch 4
Q65 marksWhat are the major task of transport layer? Explain.Ch 5
Q71 markWhat is DNS?Ch 6
Q73 marksCompare IMAP and POP3 protocols.Ch 6
Q83 marks"IPv4 and IPv6 coexistence" what does this mean?Ch 7
Q85 marksExplain Dual stack approach with an appropriate figure.Ch 7
Q104 marksExplain briefly the desirable properties of secure communication.Ch 8
2076 Ashwin Back · 14 questions
Q14 marksWhat are the features of Client/Server Architecture?Ch 1
Q22 marksWhy the telephone companies developed ISDN?Ch 2
Q26 marksExplain the working principle of ISDN with its interface and functional group.Ch 2
Q52 marksWhat is routing?Ch 4
Q56 marksDifferentiate between distance vector and link state routing algorithms.Ch 4
Q64 marksExplain the TCP segment structure.Ch 5
Q64 marksWhy TCP is known as reliable protocol and also describe how reliability is provided by TCP?Ch 5
Q72 marksWhat is TFTP?Ch 6
Q82 marksList the advantages of IPv6 over IPv4.Ch 7
Q86 marksExplain any two transition strategies for IPv4 to IPv6.Ch 7
Q92 marksList the properties of secure communication.Ch 8
Q104 marksa) Firewall and their typesCh 8
Q104 marksb) 803 Token BusCh 3
Q104 marksc) Virtual circuit switchingCh 2
2075 Chaitra Regular / Back · 14 questions
Q12 marksDraw the architecture for Client/Server network model.Ch 1
Q16 marksExplain in details about P2P network model with supportive examples.Ch 1
Q21 markWhat is switching?Ch 2
Q22 marksWhat are the various switching techniques?Ch 2
Q32 marksWhat are multiple access protocols?Ch 3
Q36 marksDescribe the various framing techniques at data link layer.Ch 3
Q52 marksWhat do you mean by autonomous system?Ch 4
Q56 marksExplain how routing loops are prevented in Distance Vector Routing with examples.Ch 4
Q72 marksWhy we need proxy servers?Ch 6
Q76 marksWhat are the importance of DNS and HTTP(S) while you are browsing any website?Ch 6
Q83 marks“IPv4 and IPv6 coexistence” what does this mean?Ch 7
Q94 marksExplain briefly the desirable properties of secure communication.Ch 8
Q104 marksb) VPNCh 8
Q104 marksc) Symmetric key cryptographyCh 8
2075 Ashwin Back · 18 questions
Q12 marksWhy layering is important?Ch 1
Q14 marksExplain design issues for layers in detail.Ch 1
Q12 marksMention service primitives for implementing connection oriented service.Ch 1
Q23 marksCompare circuit switching and packet switching.Ch 2
Q25 marksExplain ISDN channels with architecture.Ch 2
Q33 marksState the various design issues for the data link layer.Ch 3
Q33 marksWhat is piggybacking?Ch 3
Q43 marksWhy routing is essential in computer networking?Ch 4
Q45 marksCompare working of distance vector routing algorithm with link state routing algorithm.Ch 4
Q63 marksWhat are the differences between TCP and UDP services?Ch 5
Q65 marksExplain the TCP datagram format in detail.Ch 5
Q76 marksDefine socket programming.Ch 6
Q86 marksWhat are the methods used to interoperate IPv6 and IPv4.Ch 7
Q82 marksShow IPv6 datagram format.Ch 7
Q92 marksWhat is VPN?Ch 8
Q104 marksi) Flow control in D22Ch 3
Q104 marksX.25Ch 1
Q104 marksiii) ALOHACh 3
2074 Chaitra Regular · 16 questions
Q13 marksDistinguish between Client-Server network and Peer-Peer network.Ch 1
Q15 marksExplain Open System Interconnection (OSI) model.Ch 1
Q23 marksDefine transmission media.Ch 2
Q25 marksCompare among Twisted Pair, Coaxial cable and Fiber optic.Ch 2
Q34 marksWhat is the main functionality of data link layer?Ch 3
Q34 marksDifferentiate between circuit switching and packet switching.Ch 2
Q42 marksMention the criteria for good routing.Ch 4
Q46 marksExplain RIP, OSPF, BGP, IGRP and EIGRP.Ch 4
Q75 marksWhich protocols are used in sending and receiving an email? Illustrate with necessary figure.Ch 6
Q73 marksGive a comparison of POP3 and IMAP.Ch 6
Q84 marksWhat are the factors that lead to the speedy development of IPv6?Ch 7
Q84 marksDefine the process of transition from IPv4 to IPv6.Ch 7
Q95 marksDefine type of Encryption used in security.Ch 8
Q104 marksi) Types of firewalsCh 8
Q104 marksii) FDDICh 3
Q104 marksSocket programmingCh 6
2074 Ashwin Back · 17 questions
Q12 marksWhat is the significance of OSI layer?Ch 1
Q16 marksExplain different layers of OSI with its functionalities.Ch 1
Q22 marksDefine switching and multiplexing.Ch 2
Q26 marksExplain about any two guided transmission media in detail.Ch 2
Q32 marksWhat are the causes of packet delay in computer networks?Ch 2
Q36 marksWhat are the differences between circuit switching and packet switching?Ch 2
Q4What is classful and classless address?Ch 4
Q4Differentiate between link state and distance vector routing protocol.Ch 4
Q65 marksExplain the TCP protocol with its Header.Ch 5
Q63 marksWhat do you understand by socket? Explain with its importance.Ch 5
Q76 marksWhat is recursive and iterative query? Explain with suitable diagram.Ch 6
Q72 marksDiscuss the DNS records.Ch 6
Q84 marksList the advantages of IPv6 over IPv4.Ch 7
Q84 marksExplain header translation and tunneling approach used for migrating IPv4 to IPv6.Ch 7
Q94 marksExplain briefly the desirable properties of secure communication.Ch 8
Q104 marksSMTP and POPCh 6
Q104 marksd) DLL Flow Control MechanismsCh 3
2073 Shrawan New Back (2066 & Later Batch) · 19 questions
Q15 marksDifferentiate between TCP/IP and OSI Model.Ch 1
Q13 marksDefine Frame Relay in detail.Ch 1
Q22 marksWhat do you mean by switching in communication?Ch 2
Q22 marksCompare switching with multiplexing.Ch 2
Q24 marksExplain the E1 Telephone hierarchy system.Ch 2
Q32 marksWhat do you understand by Media Access Control?Ch 3
Q32 marksWhat is its significance in data link layer?Ch 3
Q34 marksExplain why token bus is also called as the token ring.Ch 3
Q52 marksDiscuss about the network congestion?Ch 5
Q52 marksExplain how different network parameters effect the congestion.Ch 5
Q54 marksCompare operation of link state routing with the distance vector routing.Ch 4
Q62 marksDefine socket programming.Ch 6
Q74 marksWhat are the factors that lead to the development of IPv6?Ch 7
Q74 marksDefine the process of transition from IPv4 to IPv6.Ch 7
Q83 marksCompare symmetric key encryption method with asymmetric key encryption.Ch 8
Q92 marksWhat do you mean by firewall?Ch 8
Q96 marksExplain different types of firewall.Ch 8
Q104 marksi) HDLCCh 3
Q104 marksWeb ServerCh 6
2072 Chaitra Regular · 14 questions
Q15 marksCompare OSI layer with TCP/IP Layer?Ch 1
Q13 marksExplain in which level of OSI layer following tasks are done. i) Error detection and correction ii) Encryption and Decryption of data iii) Logical identification of computer iv) Point-to-point connection of socket v) Dialogue control vi) Physical identification of computerCh 1
Q25 marksExplain five instances of how networks are a part of your life today.Ch 1
Q23 marksThrough we have MAC address, why do we use IP address to represent the host in networks? Explain your answer.Ch 4
Q3Briefly explain different types of Data Link Layer framing mechanisms.Ch 3
Q3List the features of FDDI.Ch 3
Q54 marksWhat is routed and routing protocol? Give examples.Ch 4
Q63 marksFor the client-server application over TCP, why must the server program be executed before the client program?Ch 5
Q65 marksTCP is known as reliable process how, describe reliability is provided by TCP.Ch 5
Q74 marksCompare the header fields of IPV6 and IPV4.Ch 7
Q74 marksWhich method do you suggest for the migration of IPv6 and why?Ch 7
Q8Explain briefly how firewalls protect networkCh 8
Q8and also explain different types of Firewall. Illustrate your answer with appropriate figures.Ch 8
Q104 marksDoman Name ServerCh 6
2072 Kartik New Back (2066 & Later Batch) · 16 questions
Q22 marksList out the functions of physical layer in TCP/IP reference model.Ch 2
Q26 marksExplain different types of transmission media.Ch 2
Q33 marksWhat are the functions of data-link layer?Ch 3
Q35 marksExplain the channel allocation problem with example.Ch 3
Q42 marksWhat are the functions of network layer?Ch 4
Q46 marksExplain briefly about multicast routing protocols and unicast routing protocols.Ch 4
Q52 marksNetwork layer is one of the key layers in OSI reference model, why?Ch 4
Q56 marksDifferentiate between distance vector routing and static link routing.Ch 4
Q62 marksWhat is a TCP connection?Ch 5
Q72 marksWhat are the different components of email server?Ch 6
Q76 marksExplain different types of electronic mail sending and accessing protocol.Ch 6
Q82 marksWhat is IPV6?Ch 7
Q86 marksWhat methods are used so that IPV6 and IPV4 networks are interoperable?Ch 7
Q91 markWhat is firewall?Ch 8
Q91 markWhat are their types?Ch 8
Q104 marksb) IPSecCh 8
2071 Chaitra Regular · 19 questions
Q12 marksWhat do you mean by network architecture?Ch 1
Q13 marksCompare TCP/IP and OSI reference models.Ch 1
Q13 marksExplain X.25 Network with its key feature.Ch 1
Q22 marksWhat is ISDN?Ch 2
Q26 marksExplain about the ISDN architecture in detail with example.Ch 2
Q32 marksWhat are multiple access protocols?Ch 3
Q42 marksWhat is network security?Ch 8
Q44 marksExplain Virtual Private Network (VPN) with an example.Ch 8
Q61 markWhy port number is used in networking?Ch 5
Q62 marksWhat are the services of transport layer?Ch 5
Q65 marksDifferentiate between TCP and UDP protocol.Ch 5
Q72 marksWhat is DNS?Ch 6
Q76 marksExplain the structure of DNS request and response with practical example.Ch 6
Q82 marksWhat are the problems of IPv4?Ch 7
Q82 marksHow IPv6 reduce these problems?Ch 7
Q84 marksExplain different strategies to transit from IPv4 and IPv6.Ch 7
Q92 marksWhat is public key cryptography?Ch 8
Q104 marksa) SSLCh 8
Q104 marksb) WEPCh 8
2071 Shrawan New Back (2066 & Later Batch) · 18 questions
Q12 marksWhat is computer network?Ch 1
Q16 marksDistinguish between OSI and TCP/IP reference model.Ch 1
Q22 marksWhat is transmission media?Ch 2
Q26 marksExplain about any three transmission media in detail.Ch 2
Q33 marksWhat are the major functions of data link layer?Ch 3
Q35 marksExplain about framing in detail.Ch 3
Q42 marksWhat is routing?Ch 4
Q46 marksDifferentiate between link state routing and distance vector routing.Ch 4
Q54 marksb) ICMPCh 4
Q54 marksc) IPCh 4
Q63 marksDistinguish between TCP and UDP.Ch 5
Q82 marksWhat are the drawbacks in IPV4?Ch 7
Q86 marksWhich of these drawbacks do IPV6 solve? Explain.Ch 7
Q92 marksWhat is cryptography?Ch 8
Q96 marksDifferentiate between symmetric key and public key cryptography.Ch 8
Q104 marksa) WEPCh 8
Q104 marksb) IDSCh 8
Q104 marksc) SSLCh 8
2070 Chaitra Regular · 10 questions
Q14 marksWhat are the features of Client/Server Architecture?Ch 1
Q28 marksWhat do you mean by data switching? Explain about various types of switching with practical implementation example.Ch 2
Q35 marksWhat is the difference between Error Correcting and Error detection process?Ch 3
Q68 marksExplain the UDP segment structure. Illustrate your answer with appropriate figures.Ch 5
Q72 marksWhat do you mean by email server?Ch 6
Q76 marksWhat are the protocols used on it?Ch 6
Q88 marksExplain the IPv6 datagram format with appropriate figures.Ch 7
Q9Explain briefly how firewalls protect networkCh 8
Q9and also explain different types of Firewall. Illustrate your answer with appropriate figures.Ch 8
Q103 marksWhat do you mean by Network security?Ch 8
2070 Ashad Old Back (2065 & Earlier Batch) · 17 questions
Q14 marksWhat do you mean by protocol and interfaces?Ch 1
Q14 marksWrite the protocols used in each layer of ICP/IP model.Ch 1
Q23 marksHow do you define network topology?Ch 1
Q25 marksDiscuss the types of network topologies based on its size and geographical distributions.Ch 1
Q32+2 marksWhat are the functions of LLC and MAC sub-layer?Ch 3
Q36 marksDiscuss different farming approaches used in data link layer.Ch 3
Q52 marksDiscuss how CSMA works?Ch 3
Q52 marksDifferentiate it with CSMA-CD.Ch 3
Q54 marksExplain the optical fiber cabling standards with examples.Ch 3
Q62 marksWhat is virus circuit switching?Ch 2
Q66 marksDescribe the operation of Frame-Relay network.Ch 1
Q73 marksDifferentiate between adaptive and non-adaptive routing.Ch 4
Q83 marksCompare between leaky bucket and token bucket algorithmCh 5
Q94 marksWhat are the major problems with existing IPv4 network?Ch 7
Q94 marksExplain IPv4 addressing and sub-netting with example.Ch 4
Q104 marksa) ALOHA systemCh 3
Q104 marksb) TCP headerCh 5
2069 Chaitra Regular · 14 questions
Q16 marksExplain the need of Networking Software in the form of Hierarchy?Ch 1
Q12 marksMention in which level layer of OSI reference model following tasks are done. i) Timing and voltage of received signal ii) Encryption and decryption of data iii) Data framing iv) Point-to-point connection of socket.Ch 1
Q24 marksDefine switching and multiplexing.Ch 2
Q24 marksDifferentiate between circuit switching and packet switching.Ch 2
Q38 marksExplain different types of Data link layer framing mechanisms.Ch 3
Q4What is the contribution of sub-netting in IP address management?Ch 4
Q53 marksWhy is routing protocol necessary?Ch 4
Q65 marksWhy do you think that there exist two protocols in transport layer where as there exists only one protocol in Internet layer in TCP/IP reference model.Ch 5
Q72 marksWhat is HTTP protocol?Ch 6
Q88 marksExplain the IPv6 datagram format and the function of each field with necessary figure.Ch 7
Q94 marksCompare symmetric key encryption method with asymmetric key encryption.Ch 8
Q102 marksWhat is network security?Ch 8
Q102 marksHow can firewalls enhance network security?Ch 8
Q104 marksExplain how firewalls can protect a system.Ch 8
2068 Chaitra Regular / Back · 14 questions
Q12 marksWhy are the network softwares defined with distinct layers stacked on top of one another?Ch 1
Q16 marksWhat are the factors to be considered when designing these layers?Ch 1
Q22 marksWhy do we need RAID in the computer networks?Ch 6
Q26 marksDefine and discuss the differences between RAID 0, RAID 1 and RAID 5.Ch 6
Q32 marksWhat is a telephone?Ch 2
Q43 marksWhy channel access mechanism is important in computer networking?Ch 3
Q55 marksDifferentiate: a) Distance vector and link state routing algorithmCh 4
Q55 marksb) Circuit switching and packet switchingCh 2
Q63 marksWhat is X.25?Ch 1
Q65 marksExplain the format of X.25 packet in detail.Ch 1
Q73 marksWhat are the differences between TCP and UDP services?Ch 5
Q75 marksExplain the TCP datagram format in detail.Ch 5
Q95 marksa) Network SecurityCh 8
Q95 marksb) Router and GatewayCh 4
2068 Baishakh Regular / Back · 15 questions
Q12 marksWhat is a switching?Ch 2
Q16 marksDifferentiate between packet switching and circuit switching.Ch 2
Q24 marksWhat are types of twisted pair cable?Ch 2
Q32 marksWhat is a virtual LAN?Ch 3
Q42 marksWhat is a logical address?Ch 4
Q53 marksWhat are the functions of transport layer?Ch 5
Q55 marksDraw the segment structure of TCP.Ch 5
Q63 marksWhat is a fragmentation and re-assembly?Ch 4
Q65 marksExplain about any intra-AS routing protocol.Ch 4
Q74 marksWhat are the advantages of IPV6?Ch 7
Q74 marksThe maximum payload segment is 65495 byte. Why was such strange number chosen?Ch 4
Q83 marksWhat is the function of proxy server?Ch 6
Q85 marksExplain about electronic mail.Ch 6
Q92 marksWhat is a secure socket layer?Ch 8
Q106 marksCompare x.25 and frame relay network.Ch 1
2067 Ashad Regular / Back · 10 questions
Q13 marksWhy network software should be in hierarchical form?Ch 1
Q15 marksExplain in detail about OSI layer.Ch 1
Q33 marksWhat do you mean by ISDN and what is it contribution in the field of data communication?Ch 2
Q35 marksExplain various types of multiplexing mechanism used in communication.Ch 2
Q44 marksDescribe what do you understand by switching along with various types of switching mechanism.Ch 2
Q52 marksWhy access control of channel is essential?Ch 3
Q56 marksCompare operating details of IEEE 802.4 and IEEE 802.5.Ch 3
Q72 marksWhy routing is essential in computer networking?Ch 4
Q76 marksCompare working of distance vector routing algorithm with link state routing algorithm.Ch 4
Q88 marksExplain in detail about IP frame format.Ch 4
2066 Poush Back · 13 questions
Q1Define networkCh 1
Q1protocol for networkCh 1
Q16 marksExplain peer-to-peer network process with example.Ch 1
Q28 marksDescribe guided and unguided media used in computer network with their advantages.Ch 2
Q45 marksList the functions of Data Link Control Layer.Ch 3
Q43 marksExplain any two sliding window protocols with the advantages of piggybacking.Ch 3
Q54 marksDescribe the policies that help in preventing the congestions within the network?Ch 5
Q56 marksDifferentiate between leaky bucket and token bucket algorithm with their operationCh 5
Q62 marksWhat do you understand by virtual circuit switching?Ch 2
Q78 marksExplain the seven layers of OSI model with their example protocols.Ch 1
Q88 marksBriefly describe ICMP error and informational message types in IPv4 network infrastructure.Ch 4
Q103 marksa) UDP and its applicationCh 5
Q103 marksc) IPv4 Header StructureCh 4
2066 Bhadra Regular / Back · 17 questions
Q1a2 marksWhy do communication process within computer network is divided into layers?Ch 1
Q1a4 marksCompare OSI model with TCP/IP model.Ch 1
Q1b3 marksWhat is client/server networking?Ch 1
Q1b5 marksExplain Active Networking model framework comparing with traditional legacy network.Ch 1
Q2a2 marksWhat are the services provided by data link layer?Ch 3
Q2a3+3 marksExplain any one methods of framing and flow control.Ch 3
Q3a5 marksDescribe the 802.3 Ethernet standard for CSMA/CD and compare it with 802.4 token bus technology.Ch 3
Q3a3 marksExplain how DSSS technique is applied in wireless transmission.Ch 3
Q3b2 marksDifferentiate between circuit switching and packet switching technology.Ch 2
Q4a2 marksWhat is unicast and multicast routing?Ch 4
Q4aDescribe the concept of optimality principle.Ch 4
Q4b2 marksWhat are the factors that cause congestion within WAN?Ch 5
Q4b6 marksPropose your best traffic shaping approach to manage congestion in packet switched network.Ch 5
Q5a2 marksGive the reason why the current world is moving to IPv6 addressing mechanism.Ch 7
Q5a2 marksDescribe the IPv6 address types with its representation format.Ch 7
Q5b3 marksATM AALCh 1
Q5b3 marksiv) ICMP Message TypesCh 4
56 procedures · asked 102 times in 27 sittings · the steps, in order
Practical answers
The questions the papers have asked about how a thing is done: incident handling and response, the risk calculations, the lifecycles and procedures. Each answer gives the steps in the order they happen, with the flow to draw beside it. What a thing is, and every comparison, stays in Theory answers.
1Introduction to computer network
Headers and trailers, and how they are added and removed PIN 3/27
2076 Ashwin · Q1
2070 Chaitra · Q1
2066 Bhadra · Q1a
Headers and trailers are control information the layers add to data: a header goes in front (addresses, sequence numbers, length, type, checksum) and a trailer after it (the frame check sequence, a CRC, added by the data link layer). They are added by encapsulation at the sender and removed by decapsulation at the receiver.
- Data: the upper layers produce the data.
- Segment: the transport layer adds a TCP or UDP header (ports, sequence number).
- Packet: the network layer adds an IP header (IP addresses).
- Frame: the data link layer adds a header (MAC addresses) and a trailer (FCS).
- Bits: the physical layer transmits the frame as signals.
Removal: at the receiver each layer checks and strips its own header (the data link layer also its trailer) and passes the rest up, until the application gets the original data.
X.25 virtual circuit connection and switching PIN 2/27
2067 Ashad · Q6
2066 Poush · Q6
X.25 is a virtual circuit packet switching network: before data moves, a logical connection is set up through the network, and every packet then follows it, carrying only a short logical channel number instead of the full address.
Packet format: octet 1 holds the GFI (Q bit, D bit, modulo bits) and the 4-bit LCGN; octet 2 the 8-bit LCN (together a 12-bit circuit number); octet 3 the packet type, which for data is P(R), the M bit, P(S) and 0; then up to 128 bytes of user data. Control packets carry a type code in octet 3, and a call request adds the DTE addresses.
- Call setup: DTE A chooses a free logical channel and sends a Call request with B's address. The network routes it once through its packet switches (PSEs), each recording the circuit in its table, and DTE B receives an Incoming call. B answers Call accepted, and A receives Call connected.
- Data transfer: data packets carry the channel number, and each PSE switches them by table lookup, for example link 1 channel 5 to link 3 channel 9. P(S) and P(R) number and acknowledge the packets, a window (2 by default) limits the outstanding packets, RR and RNR control the flow, and packets arrive in order.
- Clearing: one DTE sends a Clear request; the other receives a Clear indication and returns a Clear confirmation, which is also delivered to the first DTE. The channel numbers are freed.
Circuit types: a switched virtual circuit (SVC) goes through all three phases for every call; a permanent virtual circuit (PVC) is set up by the provider and has only the data transfer phase. A reset reinitialises one circuit; a restart clears every circuit on the interface.
How the client/server model works PIN 1/27
2078 Bhadra · Q1
In the client/server model two processes, one on the client and one on the server, communicate by request and reply:
- Listen: the server process starts first and waits on a known address and port.
- Request: the client process sends a request message over the network and waits.
- Process: the server receives it and performs the work, such as reading a file or querying a database.
- Reply: the server sends the result back in a reply message.
- Use: the client displays the result; the server serves other clients.
Example: a browser requests a page and the web server replies.
How a Frame Relay SVC is established, maintained and torn down PIN 1/27
2066 Bhadra · Q3b
A switched virtual circuit (SVC) in Frame Relay is a temporary connection between two DTEs, set up on demand and cleared after use by Q.933 signalling messages carried on DLCI 0. It passes through four states:
- Call setup (established): the calling DTE sends SETUP with the called address and traffic parameters such as the CIR; the network answers CALL PROCEEDING and forwards SETUP to the called DTE; the called DTE replies CONNECT, which the network passes to the caller. The network assigns the DLCI each end uses, and the circuit is established.
- Data transfer (maintained): frames flow in both directions on the assigned DLCI, relayed by the switches like PVC traffic; the congestion bits FECN, BECN and DE apply.
- Idle (maintained): the connection stays active with no data; STATUS ENQUIRY and STATUS messages check the link. If it stays idle beyond a set time, the call can be terminated.
- Call termination (teardown): either DTE sends DISCONNECT; the network replies RELEASE and the DTE confirms RELEASE COMPLETE; the other DTE receives DISCONNECT, sends RELEASE and receives RELEASE COMPLETE. The DLCI is freed.
A PVC, by contrast, is configured permanently and has only the data transfer and idle states.
2Physical layer
Packet switching explained with a diagram PIN 1/27
2075 Chaitra · Q2
Packet switching divides a message into small packets, each with a header (source and destination address, sequence number) and a payload, and forwards them through the network one hop at a time. Links are shared by all users, and resources are used only when there is data.
- Packetizing: the source splits the message into packets of bounded size and adds headers.
- Store and forward: each switch or router receives the whole packet, checks it, queues it and sends it on the chosen output link.
- Routing: in the datagram approach each packet is routed independently by its destination address and may take a different path; in the virtual circuit approach a path is set up first and every packet follows it, carrying only a short VCI.
- Reassembly: the destination puts the packets in order by sequence number and rebuilds the message.
Examples: the internet (IP datagrams); Frame Relay and ATM (virtual circuits). Merits: efficient for bursty data, no setup in the datagram form, robust. Demerits: variable delay, out-of-order arrival, header overhead.
How the telephone network works PIN 1/27
2068 Chaitra · Q3
The telephone network (PSTN) is a hierarchical, circuit-switched network made of three parts:
- Local loop: a twisted pair from each subscriber's telephone to the nearest end office (local exchange), carrying the 300 to 3400 Hz voice band.
- Switching offices: end offices connect their own subscribers; tandem and toll offices connect end offices for calls between areas, in a hierarchy up to regional offices.
- Trunks: high-capacity multiplexed links (E1, T1, fiber) between offices.
How a call works:
- Off-hook: lifting the handset closes the loop; the end office detects the current and sends dial tone.
- Dialling: the number is sent as DTMF tones or pulses and stored.
- Switching: a local call is connected inside the end office; otherwise a free trunk is seized to a tandem or toll office, and signalling (SS7) sets up the circuit to the called end office.
- Ringing: if the called line is free it rings and the caller hears ringback; if not, busy tone.
- Conversation: on answer the circuit is complete; voice travels as 64 kbps PCM in a time slot on each digital trunk.
- On-hook: hanging up releases the circuit and records the call for billing.
ISDN signalling PIN 1/27
2066 Bhadra · Q5b
ISDN signalling is out-of-band, common channel signalling: all call control travels on the D channel, separate from the B channels that carry user data. Between user and exchange it uses LAPD (Q.921) at layer 2 and Q.931 at layer 3; inside the network, SS7 between exchanges.
- SETUP: the caller sends the called number and bearer type.
- CALL PROCEEDING: the network accepts and sends SETUP to the called terminal.
- ALERTING: the called phone rings.
- CONNECT, CONNECT ACKNOWLEDGE: on answer, the B channel carries the call.
- DISCONNECT, RELEASE, RELEASE COMPLETE: the call is cleared.
3Data link layer
CSMA/CD and how it works HOT 5/27
2081 Baishakh · Q3
2079 Bhadra · Q3
2076 Ashwin · Q3
2074 Ashwin · Q10
2066 Poush · Q3
CSMA/CD (carrier sense multiple access with collision detection) is the medium access method of IEEE 802.3 half-duplex Ethernet. A station senses the carrier before transmitting, keeps listening while transmitting, and when it detects a collision it stops, sends a jam signal and retries after a random binary exponential backoff.
Working principle:
- Carrier sense: a station with a frame listens to the medium; while it is busy, it keeps listening (1-persistent).
- Transmission: when the medium is idle (after the 96-bit interframe gap), it transmits and monitors the medium at the same time.
- Collision detection: it compares the signal on the medium with its own; a higher signal level (or activity on its receive pair) means a collision.
- Abort and jam: on a collision it stops at once and sends a 32-bit jam signal so that every station knows of the collision.
- Backoff: after the th collision it waits slot times of 512 bit times, chosen at random from 0 to , and starts again from step 1.
- Success or abort: if the whole frame goes without a collision, the transmission succeeded; after 16 attempts it gives up and reports an error.
Minimum frame size: a collision must be detected while the frame is still being sent, so , giving : 512 bits, 64 bytes, at 10 Mbps.
Because colliding stations stop within about two propagation delays, little channel time is wasted, which makes CSMA/CD much more efficient than plain CSMA. On switched full-duplex Ethernet there are no collisions and CSMA/CD is not used.
IEEE 802.5 token ring: operation, multiple access and frame format PIN 3/27
2082 Baishakh · Q10
2071 Chaitra · Q3
2068 Chaitra · Q4
IEEE 802.5 (token ring) connects stations in a physical ring of point-to-point links, at 4 or 16 Mbps over shielded twisted pair. Multiple access is achieved with a token, a small 3-byte frame that circulates round the ring: only the station holding the token may transmit, so collisions never occur.
Operation:
- A station with data waits for the free token.
- It seizes the token by setting the token bit in the access control field, which turns the token into a frame header, and sends its frame.
- Each station regenerates and passes the bits on; the destination copies the frame and sets the address recognised (A) and frame copied (C) bits in the frame status field.
- The frame returns to the sender, which removes it from the ring and checks the A and C bits.
- The sender releases a new free token. A station may hold the token for at most the token holding time (10 ms).
Priority: the access control byte PPPTMRRR holds 3 priority bits and 3 reservation bits; a waiting station reserves a higher priority in a passing frame. An active monitor station regenerates a lost token and removes orphan frames (monitor bit).
Frame format: SD (1 byte), AC (1), FC (1), DA (2 or 6), SA (2 or 6), data (limited by the token holding time), FCS (4), ED (1), FS (1); the token is SD, AC and ED only.
How CRC detects errors PIN 1/27
2080 Bhadra · Q3
CRC (cyclic redundancy check) detects errors by modulo-2 (XOR) division with a generator polynomial of degree known to both ends.
- Sender: appends zeros to the message, divides by and appends the -bit remainder (the CRC); the frame sent is then exactly divisible by .
- Receiver: divides the received frame by the same .
- Decision: remainder zero: no error, accept; nonzero remainder: error detected, reject.
An error pattern escapes only if divides it, so all single-bit errors, all odd numbers of errors (when is a factor) and all bursts up to bits are detected.
Go-back-N and selective repeat ARQ with an example PIN 1/27
2078 Bhadra · Q3
Both are sliding window ARQ protocols: the sender transmits several frames before waiting for acknowledgements and retransmits the frames that are lost or damaged.
Go-back-N ARQ: sender window up to , receiver window 1. The receiver accepts frames in order only and discards the frames that follow an error. On a NAK or a timeout the sender resends the erroneous frame and all frames after it.
Selective repeat ARQ: both windows up to . The receiver buffers correct frames that arrive out of order and sends a NAK for the missing one; the sender resends only that frame, and the receiver delivers the frames in order.
Example: frames 0 to 4 are sent and frame 2 is lost. Go-back-N resends 2, 3 and 4; selective repeat resends only 2.
Go-back-N needs less buffer space and logic; selective repeat uses the bandwidth better on noisy links.
Operation of pure ALOHA PIN 1/27
2066 Poush · Q3
Pure ALOHA is a random access protocol in which every station transmits a frame as soon as it has one:
- The station sends the frame at any time, without sensing the channel.
- It waits for an acknowledgement, with a time-out of about twice the maximum propagation delay.
- If the ACK arrives, the transmission succeeded.
- If not, the frame is taken as destroyed in a collision; the station waits a random backoff time (, with chosen from 0 to after the th attempt) and sends again.
- After a maximum number of attempts (about 15) it gives up.
A frame survives only if no other frame starts within one frame time before or after it (vulnerable time ), so the throughput peaks at only 18.4 % at .
Techniques to avoid collisions in a wireless LAN PIN 1/27
2081 Baishakh · Q3
IEEE 802.11 avoids collisions with CSMA/CA (carrier sense multiple access with collision avoidance):
- Interframe space (IFS): a station waits until the channel has been idle for a DIFS before contending; ACK and CTS frames wait only a SIFS, so they always go first.
- Contention window: it then waits a random number of slots, counting down only while the channel is idle and freezing while it is busy; the window doubles after each failed attempt.
- Acknowledgement: the receiver acknowledges every correct frame; no ACK means the sender retransmits.
- RTS/CTS: before a large frame the sender sends a short RTS and the receiver replies with a CTS, both carrying the duration of the exchange; every station that hears either sets its NAV (network allocation vector) and stays silent. This solves the hidden station problem.
How data transfer occurs in an Ethernet PIN 1/27
2070 Ashad · Q4
Ethernet (IEEE 802.3) transfers data as frames between network interface cards identified by 48-bit MAC addresses:
- Addressing: the sender finds the receiver's MAC address from its IP address with ARP.
- Framing: the NIC encapsulates the packet: preamble, SFD, destination and source MAC addresses, length/type, data (padded to 46 bytes) and a CRC-32 FCS.
- Medium access: on a shared half-duplex segment the NIC uses 1-persistent CSMA/CD (sense, transmit while listening, jam and back off on a collision); on a full-duplex switch port it transmits at once.
- Signalling: the bits are line coded (Manchester at 10 Mbps) and sent after the preamble, which synchronises the receiver's clock.
- Forwarding: on a bus or hub every station receives the frame; a switch reads the destination address, looks it up in its MAC address table (built from source addresses) and forwards the frame only to that port, flooding unknown and broadcast frames.
- Reception: a NIC keeps the frame only if the destination is its own address, the broadcast address or a multicast group it has joined; it checks the FCS, discards errored frames and frames under 64 or over 1518 bytes, and passes the data up according to the type field.
Ethernet is connectionless and unacknowledged: lost frames are recovered, if at all, by higher layers.
The fault tolerance mechanism of FDDI PIN 1/27
2067 Ashad · Q4
FDDI is built as two fiber rings that carry traffic in opposite directions: the primary ring carries data and the secondary ring stands by. Faults are tolerated as follows:
- Link failure (wrapping): when the fiber between two stations is cut, the two stations beside the break detect the loss of signal and wrap: each joins the primary ring to the secondary ring internally. The dual ring becomes a single ring of twice the length, and all stations stay connected.
- Station failure: the neighbours of the failed station wrap in the same way, or an optical bypass switch passes the light straight through the failed station.
- SAS failure: the concentrator isolates a failed single attachment station.
- Dual homing: a critical device is connected to two concentrators, so a backup path takes over.
A second fault at the same time divides the network into separate rings.
A network design with two VLANs, student and department PIN 1/27
2068 Baishakh · Q3
Design: one switch S1 holds both VLANs; router R1, connected by an 802.1Q trunk, routes between them (router on a stick).
| VLAN | Switch ports | Network | Gateway | Hosts |
|---|---|---|---|---|
| 10 STUDENT | Fa0/1 to Fa0/12 | 192.168.10.0/24 | 192.168.10.1 | 192.168.10.11, 192.168.10.12 |
| 20 DEPARTMENT | Fa0/13 to Fa0/24 | 192.168.20.0/24 | 192.168.20.1 | 192.168.20.11, 192.168.20.12 |
Switch S1:
S1(config)# vlan 10
S1(config-vlan)# name STUDENT
S1(config-vlan)# vlan 20
S1(config-vlan)# name DEPARTMENT
S1(config-vlan)# exit
S1(config)# interface range fastEthernet 0/1 - 12
S1(config-if-range)# switchport mode access
S1(config-if-range)# switchport access vlan 10
S1(config-if-range)# interface range fastEthernet 0/13 - 24
S1(config-if-range)# switchport mode access
S1(config-if-range)# switchport access vlan 20
S1(config-if-range)# interface gigabitEthernet 0/1
S1(config-if)# switchport mode trunk
Router R1:
R1(config)# interface gigabitEthernet 0/0
R1(config-if)# no shutdown
R1(config-if)# interface gigabitEthernet 0/0.10
R1(config-subif)# encapsulation dot1Q 10
R1(config-subif)# ip address 192.168.10.1 255.255.255.0
R1(config-subif)# interface gigabitEthernet 0/0.20
R1(config-subif)# encapsulation dot1Q 20
R1(config-subif)# ip address 192.168.20.1 255.255.255.0
Each PC uses its VLAN's gateway. Broadcasts stay within each VLAN, and traffic between student and department hosts passes through R1, where access lists can restrict it.
4Network layer
ARP and how it works PIN 3/27
2080 Baishakh · Q10
2076 Chaitra · Q5
2071 Shrawan · Q5
ARP (Address Resolution Protocol, RFC 826) finds the MAC (physical) address that belongs to a known IPv4 address on the same LAN, since a frame can only be delivered to a MAC address. For a destination on another network, ARP finds the MAC address of the default gateway.
- Cache check: host A (192.168.1.10) looks for 192.168.1.20 in its ARP cache.
- Request: finding no entry, it broadcasts an ARP request to ff:ff:ff:ff:ff:ff: "who has 192.168.1.20? Tell 192.168.1.10", including its own MAC address.
- Reply: only the owner of 192.168.1.20 answers, with a unicast ARP reply carrying its MAC address; the other hosts drop the request.
- Cache and send: A stores the pair with a timeout and sends the waiting packet in a frame to that MAC address.
ARP runs directly over Ethernet (type 0x0806) in a 28-byte packet, with operation 1 for a request and 2 for a reply. RARP does the reverse, mapping a MAC address to an IP address.
Working principle of the repeater, hub, bridge, switch and router PIN 2/27
2070 Chaitra · Q4
2066 Poush · Q10
Network devices join segments and networks. Each works at one OSI layer, and that layer decides what it can read and therefore what it can decide.
- Repeater (physical layer): receives a weakened, noisy signal on one port and regenerates it at full strength on the other, extending the cable distance. It copies every bit, collisions included, so both sides remain one collision domain.
- Hub (physical layer): a multiport repeater; a signal arriving on one port is copied out of all other ports. All ports share one bandwidth and one collision domain, and it works half duplex. An active hub regenerates the signal; a passive hub only joins the wires.
- Bridge (data link layer): joins two LAN segments, records the source MAC address of each frame against its port, and then filters, forwards or floods each frame by its destination MAC address. Each segment becomes a separate collision domain.
- Switch (data link layer): a multiport bridge with a MAC address table; it sends each frame only out of the destination's port, so every port is its own collision domain with dedicated, full-duplex bandwidth. It forwards by store-and-forward, cut-through or fragment-free switching.
- Router (network layer): joins different networks and forwards packets by destination IP address using a routing table built statically or by routing protocols. It chooses the best path, decrements TTL, and separates broadcast domains, one per interface.
RIP: its operation and timers, with an example PIN 2/27
2082 Baishakh · Q4
2069 Chaitra · Q5
RIP (Routing Information Protocol) is a distance vector interior routing protocol (RFC 1058; RIPv2, RFC 2453). Its metric is the hop count, at most 15, with 16 meaning unreachable. Routers exchange their whole routing tables with their neighbours every 30 seconds over UDP port 520.
Operation:
- A router starts with its directly connected networks and sends a request to its neighbours.
- The neighbours reply with response messages containing their tables, and repeat them every 30 seconds.
- For each route received the router adds 1 hop: it adds new networks, replaces a route by a shorter one, and always accepts news from its current next hop.
- Triggered updates announce changes at once; split horizon, poison reverse and hold-down prevent loops.
| Timer | Default | Action |
|---|---|---|
| Update | 30 s | whole table sent to neighbours |
| Invalid | 180 s | no update: route invalid, metric 16 |
| Hold-down | 180 s | worse news about the route ignored |
| Flush | 240 s | route removed from the table |
Example: routers R1, R2 and R3 in a line, with LAN 10.1.0.0 on R1 and LAN 10.4.0.0 on R3. After the first update, R1 reaches R2's link network 10.3.0.0 at 1 hop; after the second, it receives 10.4.0.0 at 2 hops via R2. If R3 fails, 10.4.0.0 becomes invalid at 180 seconds and is flushed at 240 seconds.
Limits: a 15-hop diameter, slow convergence, and a metric that ignores bandwidth.
The OSPF process in link state routing PIN 2/27
2082 Bhadra · Q4
2079 Bhadra · Q10
OSPF (Open Shortest Path First) is an open-standard link state interior gateway protocol (RFC 2328). Each router floods link state advertisements (LSAs) through its area, builds an identical link state database, and runs Dijkstra's shortest path first (SPF) algorithm. Its metric is a cost, the reference bandwidth divided by the link bandwidth.
The OSPF process:
- Neighbour discovery: Hello packets go every 10 seconds to 224.0.0.5; a neighbour silent for 40 seconds (the dead interval) is declared down.
- DR and BDR election on multi-access networks, by priority and then router ID.
- Database exchange: neighbours pass through the ExStart, Exchange and Loading states, swapping DBD, LSR, LSU and LSAck packets until their databases match (Full).
- Flooding: each router floods its LSAs through the area on any change, refreshed every 30 minutes.
- SPF calculation: each router runs Dijkstra with itself as the root, giving a shortest path tree.
- Routing table: the best paths are installed; a change triggers new LSAs and a new SPF run.
Areas: a large autonomous system is split into areas joined to backbone area 0 by area border routers, keeping each database small. Features: fast convergence, no count to infinity, VLSM and CIDR support, authentication and equal-cost load balancing.
DR and BDR in OSPF, and how the DR is elected PIN 2/27
2081 Bhadra · Q4
2080 Bhadra · Q5
On a multi-access network such as Ethernet, OSPF elects a designated router (DR) and a backup designated router (BDR). Every other router forms a full adjacency only with the DR and BDR, which cuts the adjacencies from to and stops repeated flooding. Routers send updates to the DR (224.0.0.6), which floods them to all (224.0.0.5); the BDR takes over at once if the DR fails.
Election method:
- The router with the highest interface priority (0 to 255, default 1) becomes DR, and the next highest BDR.
- A tie is broken by the highest router ID (configured, else the highest loopback address, else the highest interface address).
- A router with priority 0 never becomes DR or BDR.
- The election is non-preemptive: a better router that joins later waits until the DR fails.
How OSPF routers reach full adjacency PIN 2/27
2080 Bhadra · Q5
2066 Bhadra · Q4a
Two OSPF neighbours pass through seven states before their link state databases are synchronized (RFC 2328):
- Down: no Hello has been received from the neighbour.
- Init: a Hello has arrived, but it does not yet list this router's ID.
- 2-Way: each router sees its own ID in the other's Hello; on a multi-access network the DR and BDR are elected here, and two DROthers stay in this state.
- ExStart: master and slave are chosen (the higher router ID is master) with the initial sequence number.
- Exchange: DBD packets describing each database (the LSA headers) are exchanged.
- Loading: missing or newer LSAs are requested with LSR packets and received in LSU packets, acknowledged by LSAck.
- Full: both databases are identical; the routers are fully adjacent and run SPF on the same map.
The bridge: how it works and how it raises throughput over a repeater PIN 1/27
2080 Baishakh · Q3
A bridge is a data link layer device that connects two or more LAN segments and forwards frames by their destination MAC address. A transparent bridge (IEEE 802.1D) keeps a MAC table that maps each station to the port on which its frames arrive, and needs no configuration.
Working:
- Receive every frame on every port.
- Record the frame's source MAC address against the arrival port in the MAC table.
- Look up the destination MAC address: if it is on the arrival port, filter (discard) the frame; if it is on another port, forward it out of that port only; if it is unknown or a broadcast, flood it out of all other ports.
- Age out entries not refreshed within 300 seconds.
Throughput compared with a repeater: a repeater copies every bit to the other segment, so the extended LAN remains one collision domain and its total throughput cannot exceed the capacity C of one segment. A bridge keeps local frames on their own segment, so both segments carry traffic at the same time and only crossing frames load both. If a fraction f of the traffic crosses the bridge:
With C = 100 Mbps and f = 0.2, the bridged LAN carries 166.7 Mbps against the repeater's 100 Mbps, and 200 Mbps when all traffic is local. Collisions also stay inside each segment, store-and-forward gives each segment its own CSMA/CD length limit, and damaged frames are not passed on.
Network design for a 3-star hotel PIN 1/27
2072 Kartik · Q1
Assumptions: 60 guest rooms on 4 floors; a lobby, restaurant, conference hall and back offices; about 30 staff PCs and POS terminals; 40 CCTV cameras; an IP phone in every room.
Hardware:
- Internet: two ISP links (a fibre line and a backup) on a UTM firewall with dual WAN ports, for failover and load balancing, since guests judge the hotel by its Wi-Fi.
- Firewall: NAT, rules between VLANs, content filtering, a VPN for remote management and a captive portal for guest login.
- Core: a layer 3 switch in the server room, routing between the VLANs.
- Access: a 48-port managed PoE+ switch on each floor with a fibre uplink; PoE powers access points, phones and cameras without extra sockets.
- Wireless: Wi-Fi 6 (802.11ax) access points under one controller for seamless roaming; WPA3 for staff and an isolated guest SSID with a speed limit per device.
- Cabling: Cat6 to the rooms (gigabit up to 100 m) and fibre in the risers.
- Others: an IP PBX with a gateway to the telephone network, a network video recorder for CCTV, and UPS units.
Software: a hotel property management system (reservations, check-in, billing, linked to the keycard locks and POS), POS and accounting software, a hotspot manager for guest login by room number, antivirus, backup and SNMP monitoring.
Addressing: private addresses with VLANs for staff (10), guests (20, isolated), voice (30, QoS priority), CCTV (40, no Internet) and servers (50), assigned by DHCP and translated by NAT.
Justification: VLANs keep guests away from billing and card systems, managed switches and a wireless controller make the network easy to run, and dual ISPs with UPS keep the hotel online.
A LAN design for five departments of Pulchowk Campus PIN 1/27
2067 Ashad · Q2
Design: a hierarchical star LAN for 500 computers (5 departments, each of 5 rooms with 20 computers), with access, distribution and core layers.
- Access switches: 25 managed 24-port gigabit switches, one per room, for 20 PCs plus an uplink and spare ports. Switches, not hubs, give every PC dedicated, collision-free bandwidth.
- Distribution switches: 5 layer 3 switches, one per department, joining its 5 room switches, routing its VLAN and keeping its broadcasts inside.
- Core switch: one layer 3 switch (two for redundancy) with 10 Gbps fibre ports joining the departments and the server room.
- Router and firewall: the link to the ISP, with NAT and the security policy.
- Wireless: two or three Wi-Fi 6 access points per department for laptops and phones.
- Servers: DHCP, DNS, file, web and mail servers in a central server room.
Accessories: Cat6 UTP for the 500 drops (gigabit, under 100 m); multimode OM3 or OM4 fibre between buildings (10 Gbps over hundreds of metres, immune to lightning surges); RJ45 connectors, patch panels, racks, cable trays, SFP modules, and a UPS in each closet.
Justification: the star topology isolates faults and grows easily; one VLAN and one subnet per department keep traffic local and secure; fibre suits the distances between buildings; the UPS keeps the network running through power cuts.
The shortest path algorithm in link state routing PIN 1/27
2070 Ashad · Q7
Link state routing uses Dijkstra's shortest path algorithm: each router holds the whole topology as a weighted graph and finds the least-cost path from itself to every other node.
- Label the source 0 and make it permanent; every other node is infinity.
- For each neighbour of the newest permanent node, add the link cost to that node's distance; if the sum is smaller, relabel the neighbour tentatively (distance, via node).
- Make the tentative node with the smallest label permanent.
- Repeat until every node is permanent, then trace each path back through the labels.
Example from A: the nodes become permanent in the order B (2, A), E (4, B), G (5, E), F (6, E), H (8, F), C (9, B) and D (10, H). The shortest path from A to D is A, B, E, F, H, D, with cost 10.
Link state routing and how its routing tables are populated PIN 1/27
2078 Bhadra · Q5
Link state routing is an adaptive routing algorithm in which each router floods the state of its links to all routers, so that every router builds the full topology and computes its routes with Dijkstra's algorithm.
Populating the tables:
- Discover the neighbours with HELLO packets.
- Measure the cost of the link to each neighbour.
- Build a link state packet: ID, sequence number, age, and neighbours with costs.
- Flood the packet to all routers.
- Run Dijkstra on the complete database and enter the first hop of each path in the table.
Example: links A-B 2, A-C 1, B-C 2, B-D 3, C-E 4 and D-E 1. After flooding, router A computes:
| Destination | Cost | Next hop |
|---|---|---|
| B | 2 | B |
| C | 1 | C |
| D | 5 | B |
| E | 5 | C |
5Transport layer
The token bucket algorithm HOT 7/27
2081 Bhadra · Q6
2076 Chaitra · Q6
2074 Chaitra · Q6
2072 Chaitra · Q5
2070 Ashad · Q8
2069 Chaitra · Q6
2066 Poush · Q5
The token bucket algorithm is a traffic shaping algorithm that permits bursts while limiting the average rate. The bucket holds tokens, not packets: tokens are generated at a constant rate r (one every ΔT) up to a capacity C, and a packet may be transmitted only by removing a token.
- One token is added every ΔT; when the bucket is full, new tokens are discarded.
- A waiting packet is sent if a token is available, and one token is removed (one per byte in the byte-counting version).
- If no token is available, the packet waits in the queue; packets are not discarded for lack of tokens.
- Implementation: a counter incremented every ΔT up to C and decremented for each packet sent; at zero, nothing is sent.
An idle host saves tokens, so up to C can be sent at once at the full line rate M; the longest burst lasts . For C = 6 Mb, M = 10 Mbps and r = 2 Mbps, S = 0.75 s. With 3 saved tokens and 5 packets waiting, 3 packets leave at once and 2 wait for new tokens.
TCP connection establishment and release PIN 3/27
2082 Bhadra · Q6
2075 Chaitra · Q6
2074 Chaitra · Q6
Connection establishment (three-way handshake): the server first performs a passive open (socket, bind, listen) and waits in LISTEN; the client performs an active open.
- SYN: the client sends SYN with its initial sequence number, seq = x (8000), and enters SYN-SENT.
- SYN + ACK: the server replies with its own ISN, seq = y (15000), and ack = x + 1 (8001), and enters SYN-RECEIVED.
- ACK: the client sends ack = y + 1 (15001) with seq = x + 1; both sides enter ESTABLISHED and data transfer begins.
The third segment confirms the server's sequence number and lets an old, delayed SYN be rejected.
Connection release (graceful, four segments): each direction is closed separately, since TCP is full duplex.
- FIN: the client sends FIN (seq = u) and enters FIN-WAIT-1.
- ACK: the server acknowledges (ack = u + 1) and enters CLOSE-WAIT; the client enters FIN-WAIT-2. The server may still send data (half-close).
- FIN: when finished, the server sends its FIN (seq = v) and enters LAST-ACK.
- ACK: the client acknowledges (ack = v + 1), waits 2 MSL in TIME-WAIT and closes; the server closes on receiving the ACK.
The leaky bucket algorithm PIN 3/27
2082 Baishakh · Q6
2078 Bhadra · Q6
2075 Chaitra · Q6
The leaky bucket algorithm is a traffic shaping algorithm that turns bursty traffic into a steady stream. Each host's network interface holds a finite queue (the bucket) that releases packets into the network at a constant rate, like water dripping from a hole in a bucket however fast it is poured in.
- An arriving packet joins the queue if there is space; if the bucket is full, the packet is discarded.
- At each clock tick one packet is removed and transmitted; nothing is sent when the queue is empty.
- The output is therefore at a fixed rate, however bursty the input.
For variable-length packets a byte counter is used: at each tick the counter is set to n bytes, packets are sent while their size does not exceed the counter, which is reduced by each size, and unused count is not carried forward. With n = 1000 and packets of 200, 700, 500 and 300 bytes, the first tick sends 200 and 700, the second 500 and 300.
Limitations: packets are lost when the bucket overflows, and idle time cannot be saved for later bursts.
The TCP three-way handshake (connection establishment) PIN 2/27
2081 Baishakh · Q6
2071 Shrawan · Q6
TCP is connection-oriented, so before data transfer the client and server exchange three segments, the three-way handshake, which synchronizes their initial sequence numbers (ISN) and confirms that both are ready.
- Passive open: the server creates a socket, binds its well-known port, listens, and waits in the LISTEN state.
- SYN: the client (active open) sends a segment with SYN = 1 and seq = x, a random ISN (for example 8000), and enters SYN-SENT.
- SYN + ACK: the server allocates resources and replies with SYN = 1, ACK = 1, seq = y (15000) and ack = x + 1 (8001), entering SYN-RECEIVED.
- ACK: the client sends ACK = 1, seq = x + 1, ack = y + 1 (15001) and enters ESTABLISHED; the server enters ESTABLISHED on receiving it. Data may now flow both ways.
Three segments are needed so that each side's ISN is acknowledged and an old, delayed SYN cannot open a false connection: the client rejects an unexpected SYN + ACK with RST.
The TCP sliding window PIN 2/27
2078 Bhadra · Q10
2066 Bhadra · Q5b
The TCP sliding window is TCP's byte-oriented mechanism for flow control. In every segment the receiver advertises the free space in its buffer, the receive window (rwnd), and the sender may have at most rwnd bytes sent but unacknowledged.
- The sender's bytes fall into four regions: acknowledged, sent but unacknowledged, usable (may be sent now), and not yet allowed.
- The window starts at the last acknowledgement number and is rwnd bytes long: for ACK 3001 and rwnd 4000, bytes 3001 to 7000 may be outstanding.
- When ACK 5001 arrives with rwnd 4000, the window slides right to cover bytes 5001 to 9000.
- If the receiver's buffer fills, rwnd = 0 stops the sender; a persist timer sends probes until the window opens.
The window scale option enlarges the 16-bit window, and with congestion control the sender's limit is min(rwnd, cwnd).
How the transport layer delivers the complete message in proper order PIN 1/27
2080 Bhadra · Q6
The transport layer (TCP) turns IP's unreliable delivery into a complete, ordered byte stream through these steps:
- Connection setup: the three-way handshake synchronizes both initial sequence numbers.
- Sequence numbers: every byte is numbered, so gaps, duplicates and misordering are detected.
- Checksum: a corrupted segment is discarded and treated as lost.
- Acknowledgement: the receiver returns the next byte expected (cumulative ACK).
- Retransmission: a segment unacknowledged when its timer expires, or after three duplicate ACKs, is resent.
- Reordering: early segments wait in the receive buffer and data passes up only when no gap remains.
- Flow control and release: the window prevents overflow, and FIN shows where the stream ends.
Example: of segments 1001, 2001 and 3001, segment 2001 is lost; the receiver keeps 3001 and repeats ACK 2001; after the timeout 2001 is resent and bytes 1001 to 4000 are delivered in order (ACK 4001).
Graceful termination of a TCP connection PIN 1/27
2072 Kartik · Q6
A TCP connection is gracefully terminated when both sides close their direction of the full-duplex connection with FIN and ACK, so that no data in transit is lost. It takes four segments (shown with the client closing first):
- FIN from the client: after its application finishes sending, the client sends FIN = 1, seq = u (9001), and enters FIN-WAIT-1. The FIN consumes one sequence number.
- ACK from the server: the server replies ack = u + 1 (9002), informs its application and enters CLOSE-WAIT; on receiving it the client enters FIN-WAIT-2. The connection is half-closed: the server may still send its remaining data.
- FIN from the server: when its application closes, the server sends FIN = 1, seq = v (15501), and enters LAST-ACK.
- ACK from the client: the client replies ack = v + 1 (15502) and enters TIME-WAIT; the server closes on receiving it.
TIME-WAIT lasts twice the maximum segment lifetime (2 MSL), so that a lost final ACK can be sent again when the server repeats its FIN, and delayed segments of the old connection die out before the same socket pair is reused. If the server has no more data, it may combine its ACK and FIN, giving a three-segment close. By contrast, RST aborts a connection at once and discards unsent data.
6Application layer
SMTP: how it operates, step by step PIN 3/27
2081 Bhadra · Q7
2072 Chaitra · Q10
2067 Ashad · Q10
SMTP (Simple Mail Transfer Protocol, RFC 5321) transfers mail from the sender's mail server to the receiver's mail server over a TCP connection to port 25. It is a push protocol based on text: the client sends ASCII commands and the server answers each with a three-digit reply code. Step by step:
- Submit: the sender's user agent hands the message to its mail server, which queues it.
- Find the server: the sender's server looks up the MX record of the recipient's domain in DNS.
- Connect: it opens a TCP connection to that server's port 25; the server greets with 220.
- Handshake: the client sends HELO (or EHLO) with its name; the server replies 250.
- Envelope: MAIL FROM:<sender> (250 OK), then RCPT TO:<recipient> for each recipient (250 OK, or 550 for an unknown mailbox).
- Message: DATA (354); the client sends the header lines, a blank line and the body, ending with a line holding only "."; the server replies 250 and queues it.
- Close: QUIT (221) and the TCP connection is released.
- Delivery: the receiving server places the mail in the recipient's mailbox, from which POP3 or IMAP retrieves it.
If the receiving server is unreachable, the message stays in the queue and is retried before a failure notice is returned.
How a DNS request is resolved: the working principle of DNS PIN 2/27
2079 Bhadra · Q7
2076 Chaitra · Q7
A client's DNS request is resolved by its local DNS server, which walks the name server hierarchy from a root server down to the authoritative server of the domain and caches every answer. For www.youtube.com:
- The client's resolver sends a recursive query for the A record of www.youtube.com to its local DNS server (UDP port 53).
- If the answer is not cached, the local server asks a root server.
- The root replies with a referral to the .com TLD servers.
- The local server asks a .com TLD server.
- The TLD server refers it to the authoritative servers of youtube.com (ns1.google.com).
- The local server asks the authoritative server.
- The authoritative server returns the A record with the authoritative answer flag set.
- The local server caches the record for its TTL and returns the address to the client.
Web server and file server communication, with the protocols used PIN 2/27
2075 Ashwin · Q7
2073 Shrawan · Q6
Both follow the client-server model over TCP/IP: a client process connects to a server process identified by its IP address and a well-known port.
Web server communication (HTTP or HTTPS over TCP):
- DNS (UDP port 53) resolves the server's name to its IP address.
- The browser opens a TCP connection to port 80 (443, with TLS, for HTTPS).
- It sends an HTTP request: GET /index.html and the headers.
- The web server returns a response: status line (200 OK), headers, the page.
- Embedded objects come over the same persistent connection; IP routes every packet.
File server communication (FTP over TCP):
- The FTP client opens a control connection to the server's port 21; the server replies 220.
- It logs in with USER and PASS (331, then 230).
- For each file a data connection is set up: in active mode the server connects from port 20 (PORT); in passive mode the client connects to a port the server names (PASV).
- RETR downloads or STOR uploads the file on the data connection, which then closes (226).
- QUIT ends the session (221).
Other file server protocols: TFTP (UDP 69) for simple transfers, SFTP over SSH (port 22), and SMB (TCP 445) or NFS (2049) for shared folders in a LAN.
FTP: how a client connects, and the data transfer process with its ports PIN 2/27
2080 Bhadra · Q7
2076 Ashwin · Q7
FTP (File Transfer Protocol, RFC 959) copies files between a client and a server over two TCP connections: a control connection to server port 21, kept for the whole session for commands and replies, and a data connection, from server port 20 in active mode, opened for each file and closed after it. Each side has a control process and a data transfer process.
- Control connection: the client opens TCP to port 21; the server replies 220 Service ready.
- Login: USER (331 Password required), then PASS (230 User logged in).
- Transfer type: TYPE I for binary or TYPE A for text (200).
- Data connection: in active mode the client sends PORT with its IP address and a port, for example 192,168,1,10,195,80 = port 195 × 256 + 80 = 50000, and the server connects from port 20 to it; in passive mode the client sends PASV, the server replies 227 with a high port, and the client connects.
- Data transfer process: RETR (download) or STOR (upload); the server replies 150, the file flows on the data connection, the data connection closes, and 226 Transfer complete arrives on the control connection.
- Close: QUIT, 221 Goodbye, and the control connection closes.
Commands never mix with the file data (out-of-band control), and every file or listing uses a new data connection.
How a DNS recursive query works PIN 1/27
2082 Baishakh · Q7
In a recursive query the server asked takes full responsibility for the answer:
- The host asks its local DNS server for www.youtube.com with the RD (recursion desired) flag set.
- If it is not cached, each server passes the query on: local to root, root to .com TLD, TLD to authoritative.
- The answer returns along the chain; the local server caches it and gives the host the address or an error.
Iterative query for browsing www.youtube.com PIN 1/27
2082 Bhadra · Q7
In an iterative query each DNS server answers at once with the best it has, the answer or a referral to servers closer to it, and the asker (the local DNS server) then queries those servers itself. Browsing www.youtube.com with an empty cache:
- Host to local server: the browser's resolver asks the local DNS server (the ISP's resolver) for the A record of www.youtube.com.
- Local server to root: it sends the query to a root server.
- Root referral: the root returns the NS records of the .com TLD servers (a.gtld-servers.net and others) with their addresses.
- Local server to TLD: it asks a .com TLD server.
- TLD referral: the TLD returns the authoritative servers of youtube.com (ns1.google.com and others).
- Local server to authoritative server: it asks ns1.google.com.
- Answer: the authoritative server returns the A record of www.youtube.com (or a CNAME, resolved the same way).
- Reply to host: the local server caches the records for their TTL and returns the IP address; the browser connects to port 443 and fetches the page with HTTPS.
The host sends one query and the local server three, so the root and TLD servers stay lightly loaded; a second visit within the TTL is answered from the cache.
The DHCP lease renewal process PIN 1/27
2082 Baishakh · Q7
DHCP (UDP ports 67 and 68) lends a host an IP address for a fixed lease time. The lease starts with DORA (DISCOVER, OFFER, REQUEST, ACK) and must be renewed before it expires, using two timers carried in the DHCPACK: T1 = 50 percent and T2 = 87.5 percent of the lease.
- Bound (0 to T1): the client uses the address.
- Renewing (at T1): the client unicasts a DHCPREQUEST to the server that granted the lease. A DHCPACK renews the lease for a fresh full period and restarts T1 and T2; a DHCPNAK makes the client drop the address and start again with DISCOVER.
- Rebinding (at T2): if the original server has not answered, the client broadcasts the DHCPREQUEST to any DHCP server; an ACK from any of them renews the lease.
- Expiry: with no ACK by the end of the lease, the client stops using the address and returns to the INIT state to send DHCPDISCOVER.
Example: a phone joins hostel Wi-Fi at 07:00 with a 24-hour lease. T1 = 0.5 × 24 = 12 h, so it renews by unicast at 19:00; if the server is down, T2 = 0.875 × 24 = 21 h, so it rebinds by broadcast at 04:00; with no reply by 07:00 the next day the lease expires and DORA starts again.
Sending images over 7-bit SMTP: MIME PIN 1/27
2071 Shrawan · Q7
SMTP carries only 7-bit ASCII text in short lines, while an image is binary data with byte values from 0 to 255. MIME (Multipurpose Internet Mail Extensions, RFC 2045 to 2049) lets SMTP carry it unchanged: it adds headers that describe the content and encodes the binary data as 7-bit text, which the receiver's user agent decodes.
MIME headers:
- MIME-Version: 1.0 declares a MIME message.
- Content-Type: the media type, such as image/jpeg, text/plain, application/pdf, or multipart/mixed with a boundary string between the parts.
- Content-Transfer-Encoding: base64 for binary data, quoted-printable for mostly ASCII text, 7bit for plain text.
- Content-Disposition, Content-ID, Content-Description: the attachment's file name, a reference, a description.
Base64 encoding, step by step:
- Take the image 3 bytes (24 bits) at a time.
- Split the 24 bits into four 6-bit groups.
- Map each group (0 to 63) to a printable character: A to Z, a to z, 0 to 9, + and /.
- Pad the end with = and break the lines every 76 characters.
Example: a JPEG begins with FF D8 FF = 11111111 11011000 11111111; regrouped, 111111 111101 100011 111111 = 63, 61, 35, 63 = /9j/.
Content-Type: multipart/mixed; boundary="XyZ42"
--XyZ42
Content-Type: image/jpeg; name="photo.jpg"
Content-Transfer-Encoding: base64
/9j/4AAQSkZJRgAB...
--XyZ42--
At the receiver the user agent reads Content-Type and Content-Transfer-Encoding, decodes the base64 back into the original bytes, and displays or saves the image. The cost is size: every 3 bytes become 4 characters, about 33 percent more.
How a request from an HTTP client is served by an HTTP server PIN 1/27
2069 Chaitra · Q7
Example: a browser opens http://www.example.com/index.html.
- DNS lookup: the browser resolves www.example.com to its IP address, 192.0.2.80.
- TCP connection: it opens a connection to 192.0.2.80, port 80, with the three-way handshake.
- Request: it sends the request message:
GET /index.html HTTP/1.1 Host: www.example.com User-Agent: Mozilla/5.0 Connection: keep-alive - Processing: the web server process accepts the connection, parses the request line and headers, maps /index.html to the file in its document root (or runs a script for dynamic content), and checks that the file exists and that access is allowed.
- Response: it returns a status line, headers, a blank line and the page:
HTTP/1.1 200 OK Content-Type: text/html Content-Length: 5120 <html> ... </html> - Rendering: the browser parses the HTML and requests each embedded object (images, style sheets, scripts) the same way, over the same persistent connection.
- Close: the connection closes after the last object or an idle timeout. A missing file would give the status line 404 Not Found.
HTTP is stateless: the server keeps nothing from this exchange, and a later request is served afresh, with a cookie carrying any session.
Server socket programming: bind, listen and accept PIN 1/27
2081 Bhadra · Q10
A TCP server prepares its socket in three calls after creating it:
- bind(): attaches the server's IP address and well-known port to the socket, so clients know where to connect.
- listen(): makes the socket passive and sets the length of the queue of pending connections.
- accept(): blocks until a client's connection completes, then returns a new socket for that client while the listening socket keeps listening.
int lfd = socket(AF_INET, SOCK_STREAM, 0); /* TCP socket */
struct sockaddr_in a = {0};
a.sin_family = AF_INET;
a.sin_port = htons(5000); /* port 5000 */
a.sin_addr.s_addr = htonl(INADDR_ANY); /* any local address */
bind(lfd, (struct sockaddr *)&a, sizeof a); /* name the socket */
listen(lfd, 5); /* queue of 5 */
int cfd = accept(lfd, NULL, NULL); /* wait for a client */
/* then recv() and send() on cfd, and close(cfd) */
7Introduction to IPv6
Header translation (address family translation) PIN 2/27
2079 Bhadra · Q8
2075 Chaitra · Q8
Header translation, or address family translation, is used when an IPv6-only node must communicate with an IPv4-only node: tunneling cannot help, since the receiver understands only its own version. A translator between the two networks converts each packet's header to the other version and maps the addresses between the two address families.
- Address: the IPv4 address is taken from the rightmost 32 bits of the mapped IPv6 address (
64:ff9b::c000:221gives192.0.2.33); a stateful translator (NAT64) gives the IPv6 source a public IPv4 address and port. - Version 6 becomes 4, with a 20-byte header.
- Traffic class is copied into type of service; the flow label is discarded.
- Payload length plus 20 becomes total length.
- Next header becomes protocol (ICMPv6 58 becomes ICMP 1); extension headers are dropped, a fragment header becoming the IPv4 fragment fields.
- Hop limit becomes time to live.
- Header checksum is computed; TCP and UDP checksums are adjusted.
Replies are translated in the reverse direction, and DNS64 supplies the IPv6 form of an IPv4-only server's address.
How an IPv6 host acquires an address automatically PIN 1/27
2080 Bhadra · Q8
An IPv6 host acquires an address automatically by stateless address autoconfiguration (SLAAC, RFC 4862), using the ICMPv6 neighbour discovery messages:
- Link-local address: the host forms
fe80::/64plus a 64-bit interface ID, made from its MAC by modified EUI-64 (MAC 00-00-5E-00-53-01 givesfe80::200:5eff:fe00:5301) or chosen at random for privacy. - Duplicate address detection: it sends a neighbour solicitation to the solicited-node group of that address; with no neighbour advertisement in reply, the address is unique and is assigned.
- Router solicitation to all routers,
ff02::2. - Router advertisement from the router to all nodes,
ff02::1, carrying the 64-bit prefix (say2001:db8:acad:1::/64), its lifetimes and the M and O flags. - Global address: prefix plus interface ID, checked again by DAD; the router's link-local address becomes the default gateway.
- DHCPv6 if flagged: with the M flag set a stateful DHCPv6 server assigns the address; with the O flag set DHCPv6 supplies only DNS and other settings.
The importance and implementation of 6RD PIN 1/27
2081 Bhadra · Q8
6RD (IPv6 rapid deployment, RFC 5969) lets an ISP offer IPv6 over its existing IPv4 access network. Importance: the IPv4 network needs no upgrade; unlike 6to4 it uses the ISP's own prefix and relays, so the IPv6 service is reliable and under the ISP's control; it is stateless and scales; and customers get a stable delegated prefix.
Implementation approach:
- The ISP reserves a 6RD prefix from its own space and installs border relay (BR) routers between its IPv4 network and the IPv6 Internet.
- Each customer edge (CE) router receives the 6RD prefix, its length, the number of common IPv4 bits to drop and the BR address, through DHCPv4 option 212 or configuration.
- The CE builds its delegated prefix: the 6RD prefix followed by its IPv4 address bits (
2001:db8::/32and203.0.113.5give2001:db8:cb00:7105::/64). - The CE encapsulates IPv6 in IPv4 (protocol 41) to the BR, or straight to other CEs; the BR decapsulates and forwards natively.
8Network security
The steps and operation of the RSA algorithm HOT 5/27
2078 Bhadra · Q9
2073 Shrawan · Q8
2072 Chaitra · Q9
2071 Chaitra · Q9
2069 Chaitra · Q9
The RSA algorithm (Rivest, Shamir and Adleman, 1977) is a public key algorithm. The receiver makes a key pair once; anyone encrypts with the public key, and only the private key decrypts. Its security rests on the difficulty of factoring the product of two large primes.
- Choose two large primes and , with .
- Compute the modulus .
- Compute .
- Choose the public exponent , with and .
- Compute the private exponent , the inverse of : .
- Keys: the public key is , the private key .
- Encryption of a message number : .
- Decryption: .
Example: , , so and . Choose ; then , since . For the letter E, :
C = 5^13 mod 77: 5^2 = 25, 5^4 = 9, 5^8 = 4 so C = 4 x 9 x 5 mod 77 = 26
M = 26^37 mod 77: 26^32 = 60, 26^4 = 58 so M = 60 x 58 x 26 mod 77 = 5
Decryption recovers the message because and, by Euler's theorem, . The algorithm is secure because finding from the public key needs , which needs the factors of ; with a 2048-bit modulus, factoring is infeasible.
How a digital signature works PIN 4/27
2081 Baishakh · Q10
2076 Chaitra · Q9
2075 Chaitra · Q10
2072 Kartik · Q10
A digital signature is created with the sender's private key and checked with its public key, using a hash function.
Signing at the sender A:
- Hash the message (SHA-256) to a fixed-length digest.
- Encrypt the digest with A's private key: this is the signature .
- Send together with (and A's certificate).
Verifying at the receiver B:
- Hash the received message again: digest .
- Decrypt with A's public key: digest .
- If the signature is valid; otherwise the message was altered or the signature forged.
Only A's private key can produce , so the signature gives authentication, integrity and non-repudiation, but not confidentiality. Signing the short digest instead of the whole message keeps it fast, and a certificate from a certification authority binds A's public key to A.
How a packet filtering firewall works PIN 3/27
2076 Chaitra · Q10
2075 Chaitra · Q9
2074 Ashwin · Q9
A packet filtering firewall is a router or host that decides on each packet from its network and transport headers, using an ordered rule table (an access control list). It works as follows:
- Receive: a packet arrives on an interface, inbound or outbound.
- Read the header: source and destination IP address, protocol (TCP, UDP, ICMP), source and destination port.
- Compare with the rules, top down: each rule gives values, or "any", and an action, permit or deny.
- First match decides: the packet is forwarded or dropped, and later rules are not read.
- No match: the implicit deny at the end of the list drops it.
For example, a rule that denies TCP port 23 to 192.168.10.0/24 stops Telnet into the hostel network. A packet filter is fast and transparent, but it keeps no state and cannot read content.
How security is maintained in a network: the procedures PIN 2/27
2067 Ashad · Q10
2066 Poush · Q9
Security within a network is maintained by defense in depth: several layers of controls, so that the failure of one does not expose the network. The procedures, in order:
- Security policy and risk assessment: identify the assets and the threats, and set the rules of use.
- Access control: individual accounts, strong passwords or multi-factor authentication, least privilege.
- Encryption: TLS for web and mail, VPNs for remote and branch links, WPA2 or WPA3 on Wi-Fi.
- Firewalls and router ACLs: filter traffic at every boundary, with public servers in a DMZ.
- Segmentation: VLANs to separate user, server and guest networks.
- Patching and hardening: update systems, disable unused services and ports, change default passwords.
- Malware protection: antivirus and filtering of e-mail attachments.
- Monitoring: an IDS or IPS, log review and alerts.
- Backups and redundancy: for availability and recovery.
- Physical security and user training: locked equipment rooms, phishing awareness, and an incident response plan.
The operation of the Data Encryption Standard (DES) PIN 2/27
2070 Chaitra · Q10
2066 Bhadra · Q5b
DES (Data Encryption Standard, 1977) is a symmetric, secret key block cipher that encrypts a 64-bit block with a 56-bit key (64 bits with 8 parity bits) in 16 rounds of a Feistel structure. Its operation:
- Initial permutation (IP) rearranges the 64 plaintext bits.
- Split the block into halves and of 32 bits each.
- Sixteen rounds: and , each round with its own 48-bit key.
- The function f: expansion of the 32-bit half to 48 bits, XOR with , eight S-boxes that turn 6 bits into 4 each (48 bits to 32), then the permutation P.
- 32-bit swap of the two halves after round 16.
- Final permutation () gives the 64-bit ciphertext.
The key schedule drops the parity bits (PC-1), splits the 56 bits into two 28-bit halves, rotates them left by 1 or 2 bits each round, and selects 48 bits (PC-2) as each round key. Decryption runs the same algorithm with the round keys in reverse order. With only keys, DES is now broken by brute force, and AES has replaced it.
The Diffie-Hellman key exchange algorithm PIN 2/27
2080 Bhadra · Q10
2074 Ashwin · Q10
The Diffie-Hellman algorithm (1976) lets two parties agree on a shared secret key over an insecure channel without ever sending the key itself; a symmetric cipher then uses that key.
- Both agree on two public numbers: a large prime and a generator .
- A chooses a secret and sends to B.
- B chooses a secret and sends to A.
- A computes ; B computes . Both equal .
Example: with , , and : , , and both sides find .
An eavesdropper sees , , and , but finding or is the discrete logarithm problem, infeasible for large primes. Plain Diffie-Hellman is open to a man-in-the-middle attack, so the exchanged values are authenticated with signatures or certificates, as in TLS and IKE.
One cryptography algorithm with an example: RSA PIN 1/27
2066 Poush · Q9
The RSA algorithm (Rivest, Shamir and Adleman, 1977) is a public key algorithm: a public key encrypts, a private key decrypts, and its security rests on the difficulty of factoring the product of two large primes.
- Choose two primes and , and compute the modulus and .
- Choose the public exponent , sharing no factor with : .
- Find the private exponent such that .
- Publish the public key and keep the private key secret.
- Encrypt a message number as , and decrypt as .
Example: with and , and . Choose ; then , because . The letter E is ; by repeated squaring modulo 77:
5^2 = 25, 5^4 = 625 mod 77 = 9, 5^8 = 81 mod 77 = 4
C = 5^13 = 5^8 x 5^4 x 5 = 4 x 9 x 5 = 180 mod 77 = 26
To decrypt, write and square 26 repeatedly:
26^2 = 60, 26^4 = 58, 26^8 = 53, 26^16 = 37, 26^32 = 60 (mod 77)
M = 60 x 58 x 26 mod 77 = 5, the letter E again
An attacker who knows the public key (13, 77) needs , and so the factors of ; for a 2048-bit modulus no known method finds them in any useful time.
How PGP secures e-mail communication PIN 1/27
2074 Chaitra · Q9
PGP secures an e-mail from A to B in these steps:
- Hash the message and encrypt the digest with A's private key (the signature).
- Compress the message and signature (ZIP).
- Encrypt them with a new random session key, by a symmetric cipher.
- Encrypt the session key with B's public key and attach it.
- Convert the result to base64 text and send it.
B reverses the steps: its private key recovers the session key, which decrypts the message, and A's public key verifies the signature. This gives confidentiality, authentication, integrity and compression.
Router ACL, and blocking 202.70.91.0/24 coming in on FastEthernet PIN 1/27
2082 Baishakh · Q9
A router ACL (access control list) is an ordered list of permit and deny statements applied to a router interface in one direction; each packet is compared top down, the first match decides, and an implicit deny ends the list. To block 202.70.91.0/24 entering FastEthernet 0/0:
access-list 10 deny 202.70.91.0 0.0.0.255
access-list 10 permit any
interface FastEthernet0/0
ip access-group 10 in
The permit line is needed, or the implicit deny would drop all other traffic.
2082 Bhadra Regular · 3 questions
Q46 marksExplain open short path first (OSPF) process in link state routing.Ch 4
Q63+3 marksExplain TCP 3-way hand shaking for connection establishment and release.Ch 5
Q76 marksExplain iterative query for browsing www.youtube.comCh 6
2082 Baishakh Back · 6 questions
Q46 marksExplain RIP routing operation with is timer details.Ch 4
Q64 marksExplain briefly about leaky-bucket algorithm used for traffic shaping.Ch 5
Q72 marksHow does a DNS recursive query work?Ch 6
Q76 marksDiscuss DHCP lease renew process with example diagram.Ch 6
Q92 marksWhat is router ACL? How do you apply ACL to block the IP network 202.70.91.0/24 incoming to interface Fast Ethernet of a router?Ch 8
Q104 marksa) 802.5 Token RingCh 3
2081 Bhadra Regular · 5 questions
Q44 marksmention the method that how Designated Router (DR) is elected in OSPF routing.Ch 4
Q64 marksDiscuss Token Bucket approachCh 5
Q76 marksList the step-by-step working principle of SMTP.Ch 6
Q84 marksExplain the importance and implementation approach of 6RD for IPv6 based services on the existing IPv4 networking.Ch 7
Q104 marksServer Socket programming for bind, listen and acceptCh 6
2081 Baishakh Back · 4 questions
Q32 marksWhat is CSMA/CD?Ch 3
Q34 marksWhat are the techniques used to avoid the possible collisions in WLAN? Explain.Ch 3
Q65 marksExplain the three way handshake principle of a TCP connection between client and server.Ch 5
Q104 marksb) Digital signatureCh 8
2080 Bhadra Regular · 7 questions
Q33 marksExplain how does CRC detect the errors.Ch 3
Q53 marksWhat is DR and BDR in OSPF?Ch 4
Q55 marksHow do OSPF routers come into fully adacency states? Explain.Ch 4
Q64 marksHow does the transport layer ensure that the complete message arrive at the destination and in the proper order?Ch 5
Q74 marksHow does an FTP client connect to an FTP server?Ch 6
Q85 marksHow does on IPv6 machine acquire IPv6 address automatically?Ch 7
Q104 marksc) Diffie-Hellman algorithmCh 8
2080 Baishakh Back · 2 questions
Q38 marksWhat is a bridge? How does it work? How can a bridge increase the throughout as compared with a repeater while extending a LAN? Explain with suitable diagrams.Ch 4
Q104 marksb) ARPCh 4
2079 Bhadra Regular · 4 questions
Q34 marksHow CSMA/CD works?Ch 3
Q74 marksHow is the DNS request from a client computer resolved from the authoritative server? Explain with necessary diagrams.Ch 6
Q84 marksExplain header translation mechanism for transition from IPV4 to IPV6.Ch 7
Q104 marksb) OSPFCh 4
2078 Bhadra Regular · 6 questions
Q13 marksHow does the client-server model work?Ch 1
Q34 marksExplain Go-back-N ARQ and selective Repeat ARQ with example.Ch 3
Q55 marksWhat is link state routing algorithm? Show how routing tables is populated in LSR with example.Ch 4
Q65 marksExplain about Leaky-Bucket algorithm for congestion control?Ch 5
Q9Write down the steps involved in RSA encryption algorithm.Ch 8
Q104 marksb) TCP sliding windowCh 5
2076 Chaitra Regular · 5 questions
Q53 marksWhat is ARP and how does it work?Ch 4
Q63 marksWhat is token bucket algorithm?Ch 5
Q74 marksExplain the working principle of DNS with a proper diagram.Ch 6
Q92 marksHow does a Digital Signature work?Ch 8
Q104 marksExplain how packet filtering firewall works.Ch 8
2076 Ashwin Back · 3 questions
Q14 marksWhat are headers and trailers and how do they get added and removed?Ch 1
Q38 marksExplain the working principle of CSMA/CD with appropriate figure.Ch 3
Q76 marksExplain working principle of FTP with data transfer process including proper port connection. Use proper diagram to justify your answer.Ch 6
2075 Chaitra Regular / Back · 6 questions
Q25 marksElaborate packet switching with a proper diagram.Ch 2
Q64 marksExplain connection establishment and termination in TCP.Ch 5
Q64 marksExplain briefly about Leaky-Bucket algorithm for congestion control?Ch 5
Q85 marksExplain what you mean by address family translation in IPv4/IPv6 migration process with an appropriate figure.Ch 7
Q94 marksExplain how Packet filtering firewall Works.Ch 8
Q104 marksa) Digital SignatureCh 8
2075 Ashwin Back · 1 question
Q72 marksHow web server communication and file server communication are possible in network. Explain with used protocols.Ch 6
2074 Chaitra Regular · 3 questions
Q64 marksHow connection is established and released in TCP.Ch 5
Q64 marksExplain Token Bucket algorithm.Ch 5
Q93 marksHow PGP can secure email communication?Ch 8
2074 Ashwin Back · 3 questions
Q94 marksExplain how Packet filtering firewall Works.Ch 8
Q104 marksb) Diffie Hellman’s AlgorithmCh 8
Q104 marksc) CSMA/CDCh 3
2073 Shrawan New Back (2066 & Later Batch) · 2 questions
Q66 marksHow web server communication and file server communication are possible in network, explain with used protocols.Ch 6
Q85 marksExplain RSA algorithm with example.Ch 8
2072 Chaitra Regular · 3 questions
Q54 marksExplain Token Bucket algorithm.Ch 5
Q9Write down the steps involved in RSA encryption algorithm.Ch 8
Q104 marksSimple Mail Transfer ProtocolCh 6
2072 Kartik New Back (2066 & Later Batch) · 3 questions
Q18 marksYou are assigned to design a network infrastructure for a 3-star hotel. Recommend a network solution with hardwares and softwares in current trend that can be used in the hotel. Make necessary assumptions and justify your recommadation with logical arguments where possible.Ch 4
Q66 marksExplain how a TCP connection can be gracefully terminated.Ch 5
Q104 marksa) Digital signatureCh 8
2071 Chaitra Regular · 2 questions
Q36 marksExplain how multiple access is achieved in IEEE 802.5.Ch 3
Q96 marksExplain about RSA algorithm in detail.Ch 8
2071 Shrawan New Back (2066 & Later Batch) · 3 questions
Q54 marksa) ARPCh 4
Q65 marksHow is TCP connection established? Explain.Ch 5
Q78 marksSMTP is a text based protocol and uses 7 bit ascii. How can this be used to transmit sometimes like images? Explain.Ch 6
2070 Chaitra Regular · 3 questions
Q14 marksWhat are headers and trailers and how do they get added and removed? Explain.Ch 1
Q48 marksExplain the working principle of different types of network devices Repeater, HUB, Bridge, Switch and Router.Ch 4
Q105 marksExplain the operation of Data Encryption Standard Algorithm?Ch 8
2070 Ashad Old Back (2065 & Earlier Batch) · 3 questions
Q46 marksHow data transfer occurs in Ethernet network? Explain.Ch 3
Q75 marksExplain shortest path finding algorithm in link state routing.Ch 4
Q85 markswith the operation how token bucket worksCh 5
2069 Chaitra Regular · 4 questions
Q55 marksExplain the working process of Routing Information protocol (RIP) with example.Ch 4
Q63 marksExplain token bucket algorithm for congestion control.Ch 5
Q76 marksWith an example explain how a request initiated by a HTTP client is served by a HTTP server.Ch 6
Q94 marksDescribe the operation of RSA algorithm.Ch 8
2068 Chaitra Regular / Back · 2 questions
Q36 marksWith a simple diagram of a telephone network explain how the system works.Ch 2
Q47 marksExplain the operation of IEEE 802.5 with its frame format.Ch 3
2068 Baishakh Regular / Back · 1 question
Q36 marksDesign a network which consists of two VLAN named student and department. Explain with necessary diagram, IP addresses and configurations.Ch 3
2067 Ashad Regular / Back · 5 questions
Q26+2 marksIf you are assigned to design a LAN for Pulchowk Campus having 5 departments. Each department will have 100 computers locating in 5 rooms each equipped with 20 computers. Make your own justification while selecting connecting devices and accessories.Ch 4
Q44 marksExplain the fault tolerance mechanism of FDDI.Ch 3
Q64+4 marksExplain along with the packet format about the virtual circuit connection of X.25.Ch 1
Q103 marksHow the protocol SMTP does operate?Ch 6
Q105 marksExplain the procedures to make your network secured.Ch 8
2066 Poush Back · 7 questions
Q34 marksExplain the operation of pure ALOHA system.Ch 3
Q34 marksHow CSMA/CD works?Ch 3
Q5working of token bucketCh 5
Q66 marksExplain the X.25 virtual circuit switching.Ch 1
Q92 marksHow can we maintain the security within the communication network?Ch 8
Q96 marksExplain any one cryptography algorithm with example.Ch 8
Q103 marksb) Network Devices: Hubs, Switches and RoutersCh 4
2066 Bhadra Regular / Back · 6 questions
Q1a2 marksHow the process of data encapsulation occurs in transmission mode described by seven layers of OSI model.Ch 1
Q3b6 marksExplain the operation how switched virtual circuit in frame relay network is established, maintained and teardown.Ch 1
Q4aDescribe how the routers in its link state routing come into fully adjacency state.Ch 4
Q5b3 marksi) TCP Sliding Window ProtocolCh 5
Q5b3 marksii) Secrete Key Algorithm: DESCh 8
Q5b3 marksiii) ISDN SignalingCh 2
8 chapters · 127 topics · definition, points, flows
Summary
Every topic of the eight chapters as the skeleton of its exam answer: the definition of the main term, the points as one-line keywords, every process drawn as a flow and every set of types as tiles, by name. The topics the papers ask get the full skeleton, the rest a line or two, and an example only where it helps, the same few across the course. Each title opens its full card; the chip is how often the papers ask it. At the end, the recall sheet gives every topic again as bare keywords.
Chapter 1: Introduction to computer network
5 hours · about 10 marks a paper · in 26 of the 27 sittings
Computer network and its uses PIN 4/27
Computer network: autonomous computers and devices interconnected by links and common protocols, to exchange data and share resources
Parts
- Nodes
- Links
- Protocols
- Services
- Business: resource sharing, reliability, saving money, scalability, e-commerce
- Home: remote information, communication, entertainment, e-commerce, online education
- Mobile and society: anywhere access; e-government, privacy, fraud
- Five instances: wallet payments, Viber calls, online classes, video streaming, ride booking
PAN, LAN, MAN and WAN PIN 1/27
Network types by size: networks classified by the area they cover, from one person to the whole world
| Type | Span | Owner | Example |
|---|---|---|---|
| PAN | 1 to 10 m | one person | Bluetooth earbuds |
| LAN | room to campus | one organisation | college lab Ethernet, Wi-Fi |
| MAN | a city | ISP, cable operator | city fibre ring |
| WAN | country, continent | carriers, leased | bank branches over MPLS |
- Internetwork: networks joined by routers; the Internet is the largest
Network topologies PIN 1/27
Network topology: the arrangement of nodes and links; physical (layout of cables) or logical (path of the signals)
Types
- Bus
- Star
- Ring
- Mesh
- Tree
- Hybrid
- Bus: one backbone, cheap; one break stops all
- Star: own link to a switch; the switch is a single point of failure
- Ring: one way round, token; one break stops it
- Mesh: every pair linked; robust, costly
Client/server and peer to peer TOP 10/27
Networking model: how work and resources are shared: client/server (servers serve requesting clients) or peer to peer (every peer is client and server)
Client/server
- Server listens
- Client requests
- Server processes
- Server replies
| Basis | Client/server | Peer to peer |
|---|---|---|
| Control, data | central server | spread over peers |
| Cost, security | high, strong | low, weak |
| Scalability | server bottleneck | grows with peers |
| Failure | single point | none |
| Example | web, banking | BitTorrent, workgroup |
- P2P process: join, search, connect directly, exchange pieces, leave
Active networks PIN 1/27
Active network: a network of programmable nodes that compute on the packets passing through, running code from users or the packets
Active node
- Active applications
- Execution environments
- NodeOS
- Hardware
- Approaches: capsule (integrated, code in packets); programmable switch (discrete, code preloaded)
| Point | Legacy | Active |
|---|---|---|
| Node | stores and forwards | forwards and computes |
| Programmed by | vendor | users, packets |
| New service | years | quickly, as code |
| Security, speed | simpler, faster | harder, slower |
Protocols and standards HOT 5/27
Protocol: a set of rules for communication: the format, order and meaning of messages, and the actions on sending and receiving them
Elements
- Syntaxformat
- Semanticsmeaning
- Timingwhen, how fast
- Examples: HTTP, SMTP, DNS, TCP, UDP, IP, Ethernet
- Standards bodies: ISO, ITU-T (formerly CCITT), IEEE, IETF, ANSI, EIA
- Interface: boundary between adjacent layers; offers the lower layer's services
- Protocol against interface: horizontal, peer to peer; vertical, layer to layer
Layered architecture TOP 9/27
Layered architecture: network software as a stack of layers, each offering services to the layer above; layer n talks to its peer by the layer n protocol
- Reasons: less complexity, modularity, standards, easy troubleshooting, reuse, flexibility
- Hierarchy: peers, protocols, interfaces; virtual communication, real flow down and up
- Network architecture: the set of layers and protocols
Design issues
- Addressing
- Direction of transfer
- Error control
- Flow control
- Multiplexing
- Routing
- Ordering
- Segmentation
Services and primitives PIN 1/27
Service: the operations a layer offers the layer above; connection-oriented (set up, use, release) or connectionless (independent datagrams)
Primitives
- LISTEN
- CONNECT
- RECEIVE
- SEND
- DISCONNECT
- OSI classes: request, indication, response, confirm
- Examples: TCP connection-oriented; UDP and IP connectionless
- Service against protocol: what a layer offers; rules between peers
The OSI model HOT 8/27
OSI reference model: ISO's seven-layer framework (ISO 7498, 1984) saying what each layer does, not which protocols do it
Layers, bottom up
- Physical
- Data link
- Network
- Transport
- Session
- Presentation
- Application
- Functions: bits; frames, MAC, errors; routing, IP; ports, end to end; dialog; encrypt, translate; user services
- Which layer: voltage physical; framing, MAC data link; IP network; socket transport; dialog session; encryption presentation
The TCP/IP model PIN 4/27
TCP/IP model: the four-layer model of the Internet protocol suite, built for the ARPANET to interconnect different networks
Layers, bottom up
- Host-to-network
- Internet
- Transport
- Application
- Application: HTTP, HTTPS, SMTP, POP3, IMAP, FTP, DNS, DHCP, SSH, SNMP
- Transport: TCP reliable, connection-oriented; UDP fast, connectionless
- Internet: IP, ICMP, IGMP, ARP; routing, logical addressing
- Host-to-network: Ethernet, Wi-Fi, PPP, DSL; framing, bits
Data encapsulation PIN 3/27
Encapsulation: each layer wraps the data from above in its own header (and at the data link layer a trailer); decapsulation removes them at the receiver
Down at the sender
- Data
- Segment+ TCP header
- Packet+ IP header
- Frame+ header, FCS
- Bits
- Header: addresses, sequence numbers, length, type, checksum
- Trailer: FCS (CRC), data link layer only
OSI against TCP/IP TOP 9/27
OSI against TCP/IP: ISO's seven-layer reference model, made before its protocols, against the four-layer model of the Internet's protocols, described after them
Layer mapping
- ApplicationOSI 7, 6, 5
- TransportOSI 4
- InternetOSI 3
- Host-to-networkOSI 2, 1
| Basis | OSI | TCP/IP |
|---|---|---|
| Layers | 7 | 4 |
| Made | model first | protocols first |
| Service, interface, protocol | clearly separate | blurred |
| Network layer | both services | connectionless |
| Transport layer | connection-oriented | TCP and UDP |
- Similar: layered, end to end transport, network layer, application on top
The Internet
- Network of networks: TCP/IP worldwide; no single owner
- History: ARPANET 1969, TCP/IP 1983, NSFNET, the web 1991
- Structure: hosts, access networks, tiered ISPs, IXPs (NPIX in Kathmandu)
- Governance: ICANN, IANA, APNIC addresses; IETF RFCs
X.25 HOT 7/27
X.25: ITU-T standard interface between the DTE and DCE of a public packet switched network; virtual circuits, error and flow control at every hop
Layers
- PhysicalX.21
- LinkLAPB
- PacketPLP
- Packet header: GFI (Q, D, modulo) and LCGN; LCN; P(R), M, P(S), 0
Virtual call
- Call request
- Incoming call
- Call accepted
- Call connected
- Data transfer
- Clearing
- Circuits: SVC per call, PVC permanent; 4095 per line
- Limits: slow (64 kbps), high delay; replaced by Frame Relay
Frame Relay HOT 5/27
Frame Relay: connection-oriented WAN carrying variable-length frames over virtual circuits named by DLCIs, at layers 1 and 2 only; bad frames dropped
Address bits
- DLCI
- C/R
- EA
- FECN
- BECN
- DE
- Circuits: PVC; SVC by Q.933 on DLCI 0
SVC states
- Call setup
- Data transfer
- Idle
- Call termination
| Basis | X.25 | Frame Relay |
|---|---|---|
| Layers | 1 to 3 | 1 and 2 |
| Errors | corrected per hop | detected, dropped |
| Speed | up to 64 kbps | to 44.736 Mbps |
- Against ATM: variable frames against 53-byte cells; DLCI against VPI/VCI
ATM PIN 3/27
ATM: connection-oriented cell switching that carries voice, video and data in fixed 53-byte cells (5-byte header, 48-byte payload) over VPI/VCI circuits
UNI header
- GFC 4
- VPI 8
- VCI 16
- PT 3
- CLP 1
- HEC 8
Layers, top down
- AALCS, SAR
- ATM layer
- PhysicalTC, PMD
- AAL types: AAL1 CBR voice; AAL2 timed VBR; AAL3/4 data; AAL5 IP, 8-byte trailer
Ethernet
- Ethernet: IEEE 802.3 LAN family; shared coaxial bus, now a switched star
- Speeds: 10 Mbps (1983) to 400 Gbps (2017)
- Frame: MAC addresses, type, 46 to 1500 bytes of data, CRC
VoIP
- VoIP: voice as IP packets instead of PSTN circuits
- Call: SIP signalling; codec; RTP over UDP; jitter buffer
- G.711 call: 200-byte packets, 50 a second, 80 kbps
NGN
- NGN (ITU-T Y.2001): one packet IP core for voice, video and data
- Strata: transport and service separated; softswitch, IMS
- Also: QoS broadband access, open interfaces, generalised mobility
MPLS
- MPLS: forwarding by short labels, layer 2.5 (RFC 3031)
- Label: 20-bit label, TC 3, S 1, TTL 8
- Path: ingress LER pushes, LSRs swap, egress pops
- Uses: traffic engineering, VPNs, fast reroute
xDSL
- DSL: digital data on the telephone copper, above 4 kHz
- Parts: splitter, DSL modem, DSLAM, DMT tones
- Variants: ADSL 8 Mbps, ADSL2+ 24, VDSL2 100; HDSL, SDSL
Chapter 2: Physical layer
5 hours · about 8 marks a paper · in 25 of the 27 sittings
Physical layer PIN 1/27
Physical layer: layer 1; transmits raw bits over a medium, defining mechanical, electrical, functional and procedural characteristics of the link
Functions
- Physical characteristics
- Bit representation
- Data rate
- Bit synchronization
- Line configuration
- Physical topology
- Transmission mode
- Modes: simplex, half-duplex, full-duplex
- In TCP/IP: inside the host-to-network layer
- Devices: repeater, hub, modem, cables and connectors
Delay and throughput PIN 3/27
Network monitoring: measuring bandwidth, throughput, latency and jitter; each hop adds processing, queuing, transmission and propagation delay
- Throughput: data delivered / time; never above bandwidth
- Formulas: transmission ; propagation ; bandwidth-delay product
- Causes of delay: processing, congestion, slow links, distance, hops, retransmissions
- Example: 1,500 bytes at 10 Mbps: 1.2 ms; GEO hop: 238.6 ms
Channel capacity PIN 1/27
Channel capacity: the highest data rate a channel can carry; Nyquist for noiseless, Shannon for noisy channels
- SNR in dB: ; 10 dB = 10, 30 dB = 1000
- Impairments: attenuation, distortion, noise
- Example: 3 kHz line at 30 dB: about 29.9 kbps
Transmission media HOT 7/27
Transmission medium: the physical path between transmitter and receiver that carries the signal; guided (wired) or unguided (wireless)
Factors in choosing
- Bandwidth
- Distance
- Cost
- Noise immunity
- Security
- Installation
- Environment
- Mobility
- Example: UTP in labs, fiber between buildings, Wi-Fi in the canteen
Twisted pair and coaxial HOT 7/27
Guided media: cables carrying the signal on a solid path: twisted pair, coaxial (current), optical fiber (light)
Twisted pair types
- UTP
- STP
- Cat 3 to Cat 8
- Straight-through
- Crossover
- Rollover
- Coaxial: conductor, insulation, braid shield, jacket; RG-6, RG-58, RG-59
| Point | Twisted pair | Coaxial | Fiber |
|---|---|---|---|
| Signal | electrical | electrical | light |
| Bandwidth | low | moderate | very high |
| Noise immunity | low | good | immune |
| Cost | cheapest | moderate | highest |
Optical fiber PIN 1/27
Optical fiber: a glass strand carrying light pulses, held in the core by total internal reflection at the lower-index cladding
Modes
- Multimode step index
- Multimode graded index
- Single mode
- Layers: core, cladding, buffer, jacket
- Source and detector: LED or laser; PIN or APD photodiode
- Windows: 850, 1310, 1550 nm, about 190 to 355 THz
Unguided media HOT 5/27
Unguided media: electromagnetic waves through air or space without a conductor, radiated and collected by antennas
Media
- Radio3 kHz to 1 GHz
- Microwave1 to 300 GHz
- Infrared300 GHz to 400 THz
Propagation
- Groundbelow 2 MHz
- Sky2 to 30 MHz
- Line of sightabove 30 MHz
- LOS paths: direct wave, ground-reflected wave
- Radio horizon: km
Satellite
Communication satellite: a microwave relay in orbit; its transponder amplifies and translates uplink to downlink
Orbits
- LEO
- MEO
- GEO35,786 km
- Bands: L, S, C, X, Ku, K, Ka, V, W
Multiplexing HOT 6/27
Multiplexing: sharing one link among several signals at once; a MUX combines n inputs, a DEMUX separates them
Types
- FDMfrequency bands
- WDMwavelengths
- Synchronous TDMfixed slots
- Statistical TDMslots on demand
- CDMorthogonal codes
- Importance: efficiency, lower cost, trunks and broadcasting, scalability
- Example: FM stations at 88 to 108 MHz (FDM); E1 trunk of 30 calls (TDM)
Switching TOP 13/27
Switching: connecting a sender to a receiver through intermediate nodes that forward each input to the right output
Types
- Circuit
- Message
- Packetdatagram or virtual circuit
Circuit switching
- Setup
- Data transfer
- Teardown
| Point | Circuit | Packet |
|---|---|---|
| Path | dedicated, reserved | shared, on demand |
| Delay | setup, then constant | variable queuing |
| Order | in order | may be out of order |
| Suits | real-time voice | bursty data |
- Real time: reserved bandwidth, constant delay, no jitter, in order
Datagram and virtual circuit HOT 6/27
Datagram and virtual circuit: packet switching with each packet routed on its own, or along a path set up first
Virtual circuit phases
- Setup
- Data transfer
- Teardown
| Point | Datagram | Virtual circuit |
|---|---|---|
| Setup | none | needed |
| Header | full address | short VCI |
| Routing | per packet | once, at setup |
| Order | may vary | in order |
- VC types: PVC, SVC
- Examples: IP; X.25, Frame Relay (DLCI), ATM, MPLS
Telephone network and E1 PIN 2/27
Telephone network (PSTN): a circuit-switched hierarchy of telephones, local loops, exchanges and trunks
A call
- Off-hook
- Dial tone
- Dialling
- Switching
- Ringing
- Answer
- Hang up
- T1: 193 bits x 8000 = 1.544 Mbps, 24 channels
- E1: 32 slots x 8 bits x 8000 = 2.048 Mbps; TS0 sync, TS16 signalling
- E hierarchy: E2 8.448, E3 34.368, E4 139.264 Mbps
Switching systems
Telecommunication switching system: exchange equipment joining any line to any line or trunk on demand
Kinds
- Manual
- Strowger
- Crossbar
- Electronic SPC
- Signalling: CAS, CCS (SS7)
ISDN HOT 5/27
ISDN: an ITU-T all-digital, circuit-switched network carrying voice and data end to end over the telephone line
Channels
- B64 kbps
- D16 or 64 kbps
- H384 to 1,920 kbps
- BRI: 2B + D = 144 kbps (192 with framing); PRI: 23B + D or 30B + D
Functional groups
- TE1
- TE2
- TA
- NT2
- NT1
- Reference points: R, S, T, U
- Signalling: D channel, LAPD and Q.931; SS7 inside
Chapter 3: Data link layer
5 hours · about 11 marks a paper · in all 27 sittings
Data link layer functions HOT 8/27
Data link layer: layer 2; packs network layer packets into frames and moves them reliably node to node over one link
Functions
- Framing
- Physical addressing
- Flow control
- Error control
- Access control
Services
- Unacknowledged connectionless
- Acknowledged connectionless
- Acknowledged connection-oriented
- Design issues: service interface, framing, error control, flow control, medium access, addressing
- Sublayers: LLC (802.2): network layer interface, multiplexing; MAC: frame, addresses, medium access, FCS
Framing TOP 10/27
Framing: dividing the bit stream into frames and delimiting each frame's start and end
Methods
- Character count
- Byte stuffingFLAG, ESC
- Bit stuffingflag 01111110
- Coding violations
- Character count: one garbled count loses every later boundary
- Byte stuffing: ESC before a FLAG or ESC in the data; PPP
- Bit stuffing: a 0 after five 1s, deleted by the receiver; HDLC
- Example: 01001111110111110 sent as 0100111110101111100 between two flags
Errors and detection PIN 1/27
Error: a change in a frame's bits in transit; single-bit or burst
| Point | Detection | Correction |
|---|---|---|
| On error | resend (ARQ) | fix (FEC) |
| Bits added | few | many |
| Distance | ||
| Codes | parity, CRC | Hamming |
- Parity: catches odd numbers of errors; 2D parity corrects one bit
- Checksum: one's complement sum, complemented; receiver's complemented sum 0: accept
CRC PIN 3/27
CRC: error detection by modulo-2 division by a generator of degree r; the r-bit remainder is appended
Sender
- Append r zeros
- Divide by G, XOR
- Remainder is the CRC
- Send message, then CRC
- Receiver: divide by the same G; remainder 0 accept, otherwise reject
- Detects: all single-bit, odd counts (factor x + 1), bursts up to r bits
- Generators: CRC-16-CCITT (HDLC, PPP), CRC-32 (Ethernet)
- Example: 1101 with 1011: remainder 001, send 1101001
Hamming distance and code PIN 1/27
Hamming distance: the number of bit positions in which two equal-length codewords differ (XOR, count the 1s)
- Rules: detect s errors (left), correct t errors (right)
- Example: 10101 XOR 11110 = 01011: distance 3
Parity groups of the 7,4 code
- P11, 3, 5, 7
- P22, 3, 6, 7
- P44, 5, 6, 7
- Correct: syndrome C4 C2 C1 names the wrong bit; 1110111 becomes 1111111
Flow control HOT 5/27
Flow control: procedures limiting how much a sender transmits before an acknowledgement, protecting a slow receiver
- Stop and wait: one frame, then wait for its ACK;
- Sliding window: up to W frames, numbered modulo ; ACK names the next frame expected
- Piggybacking: ACK rides in the next data frame; fewer frames; ack timer
- Example: satellite, a = 270: stop and wait uses 0.18 % of the link
ARQ PIN 4/27
ARQ: error control by retransmission (backward error correction), triggered by a timeout or a NAK
- Stop and wait: one frame outstanding; resend that frame
- Go-back-N: window , receiver window 1; resend the lost frame and all after
- Selective repeat: both windows ; resend only the lost frame
- Example: frames 0 to 4, frame 2 lost: go-back-N resends 2, 3, 4; selective repeat resends 2
HDLC PIN 2/27
HDLC: a bit-oriented ISO protocol for point-to-point and multipoint links, with bit stuffing and sliding window ARQ
Stations
- Primary
- Secondary
- Combined
Modes
- NRMsecondary waits for a poll
- ARMsecondary may send
- ABMcombined, either sends
Frame
- Flag
- Address
- Control
- Information
- FCS
- Flag
Frame types
- Idata, N(S), N(R)
- SRR, RNR, REJ, SREJ
- USNRM, SABM, DISC, UA
PPP
PPP: the byte-oriented point-to-point link protocol: HDLC-like framing, LCP and NCPs
Phases
- Dead
- Establish
- Authenticate
- Network
- Open
- Terminate
- Frame: 7E, FF, 03, protocol, payload, FCS, 7E
MAC sublayer HOT 7/27
MAC sublayer: the lower data link sublayer that decides which station transmits next on a shared broadcast channel
- Why essential: avoids collisions; efficient use; fairness; bounded delay and priority
- Static allocation: fixed FDM or TDM shares; wasteful for bursty traffic; delay N times
- Example: one 100 Mbps channel: 200 µs; ten 10 Mbps channels: 2 ms
- Dynamic allocation: on demand; station model, one channel, collisions observed
Multiple access protocols
- RandomALOHA, CSMA, CSMA/CD, CSMA/CA
- Controlledreservation, polling, token
- ChannelizationFDMA, TDMA, CDMA
ALOHA HOT 6/27
ALOHA: random access (Hawaii, 1971): send whenever ready; with no ACK, retry after a random backoff
| Point | Pure | Slotted |
|---|---|---|
| Sends | any time | slot start |
| Vulnerable | 2T | T |
| Throughput | ||
| Maximum | 18.4 % | 36.8 % |
- Peak load: G = 0.5 (pure), G = 1 (slotted)
- No collision: pure, no other start within T either side; slotted, none in the same slot
CSMA PIN 1/27
CSMA: carrier sense multiple access: listen to the medium, transmit only when it is idle
- Vulnerable time: the propagation time
Persistence
- 1-persistentsend at once when idle
- Non-persistentwait a random time
- p-persistentsend with probability p
CSMA/CD TOP 9/27
CSMA/CD: Ethernet's access method: sense, transmit while listening, and on a collision jam and back off at random
- Sense until idle
- Transmit and listen
- Collision?
- Jam 32 bits
- Back off K slots
- Retry, 16 attempts
- Backoff: K from 0 to , m = min(n, 10), slots of 512 bit times
- Detect: higher signal level, or receive activity while sending
- Minimum frame: = 512 bits = 64 bytes at 10 Mbps
- Better than CSMA: stops at once; wastes only about
Controlled access
Controlled access: stations take turns by agreement or under a controller; no collisions
Methods
- Reservationmini-slots
- Pollingpoll and select
- Token passinglogical ring
- Example: roll call (polling), talking stick (token)
Channelization
Channelization: sharing a channel by frequency (FDMA), time (TDMA) or code (CDMA)
- Example: GSM: 200 kHz carriers (FDMA), 8 time slots each (TDMA)
- CDMA: orthogonal chip codes; an inner product recovers one station
IEEE 802 family
IEEE 802: the LAN and MAN standards: one LLC (802.2) over a MAC for each LAN
Standards
- 802.1bridging, VLANs
- 802.2LLC
- 802.3Ethernet
- 802.4token bus
- 802.5token ring
- 802.11wireless LAN
Ethernet PIN 4/27
Ethernet (IEEE 802.3): the wired LAN: 48-bit MAC addresses, CRC-32, 1-persistent CSMA/CD on shared media
Frame, bytes
- Preamble 7
- SFD 1
- DA 6
- SA 6
- Length/Type 2
- Data 46 to 1500
- FCS 4
- Frame size: 64 to 1518 bytes
- MAC address: 24-bit OUI and 24-bit NIC part; broadcast all 1s
- Cabling: 10Base5, 10Base2, 10BaseT, 100BaseTX, 1000BaseT
- Fiber: 10BaseF, 100BaseFX, 1000BaseSX (850 nm), 1000BaseLX (1310 nm)
Token bus HOT 5/27
Token bus (IEEE 802.4): stations on a physical bus pass a token round a logical ring ordered by address
- Why "token ring": token to the next lower address; the lowest returns it to the highest
- Priorities: classes 0, 2, 4, 6
- Maintenance: claim token, solicit successor, set successor
- Medium: broadband coax at 1, 5, 10 Mbps; factory automation
| Point | 802.4 | 802.5 |
|---|---|---|
| Topology | logical ring | physical ring |
| Frame end | terminators | sender strips |
| Upkeep | distributed | monitor |
Token ring PIN 4/27
Token ring (IEEE 802.5): stations on a physical ring; only the holder of the circulating 3-byte token transmits
Operation
- Wait for free token
- Seizeset T bit
- Frame circles
- Destination copies, sets A, C
- Sender strips frame
- Release new token
Frame
- SD
- AC
- FC
- DA
- SA
- Data
- FCS
- ED
- FS
- AC byte: PPPTMRRR: priority, token, monitor, reservation
- Monitor: restores a lost token, removes orphan frames
- Physical: 4 or 16 Mbps, shielded twisted pair; token holding 10 ms
FDDI PIN 3/27
FDDI: 100 Mbps token-passing fiber LAN on dual counter-rotating rings; primary carries data, secondary stands by
Features
- 100 Mbps fiber
- Dual rings
- 200 km, 1000 connections
- Timed token
- Frames up to 4500 bytes
- DAS, SAS, concentrators
Fault tolerance
- Cut detected
- Neighbours wrap
- One ring, double length
- Also: optical bypass switch, concentrator isolates a SAS, dual homing
Wireless LAN PIN 3/27
IEEE 802.11 (Wi-Fi): the wireless LAN standard; access by CSMA/CA, optionally with RTS and CTS
- Architecture: BSS (ad hoc, or infrastructure with an AP); ESS over a distribution system
- No CSMA/CD: cannot hear while sending; hidden and exposed stations; fading
CSMA/CA
- DIFS idle
- Random backoff
- Send
- SIFS, ACK
- RTS/CTS: both set the NAV; solves the hidden station
- DSSS: 11-chip Barker code 10110111000, 22 MHz channel
- Versions: b 11 Mbps; a, g 54 Mbps; n; ac; ax (Wi-Fi 6)
VLAN PIN 3/27
VLAN: a logical group of switch ports forming one broadcast domain, set by configuration, not wiring
802.1Q tag
- TPID 0x8100
- PCP 3 bits
- DEI 1 bit
- VID 12 bits
- Membership: port, MAC address, IP address, application
- Ports: access (one VLAN, untagged), trunk (many, tagged)
- Design: STUDENT VLAN 10, 192.168.10.0/24; DEPARTMENT VLAN 20, 192.168.20.0/24; router on a stick
- Benefits: smaller broadcast domains, security, flexibility, cost
Chapter 4: Network layer
9 hours · about 17 marks a paper · in all 27 sittings
Network layer functions PIN 1/27
Network layer: layer 3; delivers packets from the source host to the destination host across many networks, by logical addresses and routers choosing the path hop by hop
Functions
- Logical addressing
- Routing
- Forwarding
- Packetizing
- Fragmentation, reassembly
- Internetworking
- Error reporting (ICMP)
- Congestion control, QoS
- Key layer: highest layer every router runs; narrow waist (IP over everything); addressing that scales
- Delivery: data link hop to hop; network host to host; transport process to process
Internetworking devices PIN 4/27
Internetworking device: hardware joining segments or networks; its OSI layer fixes what it can read and decide
By layer
- Repeater, hublayer 1, signal
- Bridge, switchlayer 2, MAC
- Routerlayer 3, IP
- Gatewayup to 7, converts
- Domains: hub one collision domain; switch one per port; router one broadcast domain per port
- Switch over hub: dedicated bandwidth, no collisions, full duplex, privacy, VLANs
- Router vs gateway: same protocol, path choice; different protocols, conversion
Bridges PIN 1/27
Bridge: a data link layer device joining LAN segments; records each source MAC against its port and forwards frames only where needed
Each frame
- Receive
- Record source MAC
- Filter, forward or flood
- Age out (300 s)
- Versus repeater: two collision domains, not one; local traffic stays local
- Loops: Spanning Tree Protocol (IEEE 802.1D) blocks redundant ports
IPv4 addressing HOT 5/27
IPv4 address: a 32-bit logical address in dotted decimal, split into a network part and a host part
Classes, first octet
- A0 to 127, /8
- B128 to 191, /16
- C192 to 223, /24
- D224 to 239, multicast
- E240 to 255, reserved
- Private: 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16
- IP over MAC: hierarchical, end to end, any link, shows location
Subnetting and VLSM TOP 24/27
Subnetting: borrowing host bits to divide one network into smaller subnets, each with its own network address, broadcast address and host range
- Numbers: subnets ; hosts ; block
VLSM method
- AND to find the block
- Size each demand
- Sort largest first
- Allocate from the start
- Links as /30
- Network, range, broadcast
- Wasted, unused range
- VLSM when: subnets need different sizes; one fixed mask wastes addresses
- Example: 192.168.10.0/24: 60 hosts /26, 25 /27, 10 /28, two links /30
CIDR and supernetting PIN 2/27
Supernetting: combining contiguous networks into one larger block with a shorter prefix, one route for all
- CIDR: a.b.c.d/n; any power-of-two block; mask carried with routes
- Conditions: contiguous, a power of two, aligned
- Example: 192.168.4.0/24 to 192.168.7.0/24 make 192.168.4.0/22
| Point | Classful | Classless |
|---|---|---|
| Network part | 8, 16, 24 bits | any /n |
| Waste | high | low |
| Routing | per network | aggregated, longest prefix |
NAT
NAT: a router rewriting private source addresses (and ports) to a public address, and back for replies
Types
- Static
- Dynamic
- PAT (overload)
- Costs: breaks end to end; inbound needs port forwarding
The IPv4 datagram HOT 5/27
IP: the Internet's connectionless, best-effort datagram protocol; header 20 to 60 bytes
- TTL: hop limit; at 0 dropped, ICMP time exceeded
- Protocol: 1 ICMP, 6 TCP, 17 UDP, 89 OSPF
- Fragments: same Identification; offset in 8 bytes; MF 1 but last; reassembled at destination
- Largest TCP payload: bytes
ARP and RARP PIN 4/27
ARP: maps a known IPv4 address to the MAC address on the same link, by a broadcast request and a unicast reply
Steps
- Check cache
- Broadcast request
- Owner replies unicast
- Cache, send frame
- RARP: MAC to IP; replaced by BOOTP and DHCP
- NDP (IPv6): ICMPv6 solicitation and advertisement, multicast; router discovery, SLAAC
ICMP HOT 5/27
ICMP: IP's companion protocol (protocol 1) reporting delivery errors to the source and answering queries; it reports, never corrects
Errors, type
- Destination unreachable3
- Source quench4
- Time exceeded11
- Parameter problem12
- Redirect5
Queries, types
- Echo8, 0
- Timestamp13, 14
- Address mask17, 18
- Router10, 9
- Uses: ping, traceroute, path MTU discovery, redirects
Routing TOP 13/27
Routing: finding paths through an internetwork and building the tables forwarding uses; the routing algorithm picks the output line
Good algorithm
- Correctness
- Simplicity
- Robustness
- Stability
- Fairness
- Optimality
| Point | Static | Dynamic |
|---|---|---|
| Routes | manual, fixed | automatic |
| On failure | manual fix | rerouted |
- Routed vs routing: IPv4, IPv6 carry data; RIP, OSPF, BGP build tables
- Optimality principle: part of an optimal path is optimal; sink tree
- AS: one administration; IGP inside, BGP between
Routing table
Routing table: per destination network: mask, next hop, interface, metric, source
- Classful lookup: first octet, class, default mask, network
- Classless: longest prefix match; default route 0.0.0.0/0
Dijkstra's algorithm PIN 1/27
Dijkstra's algorithm: finds least-cost paths from one node to all others, each step making the nearest tentative node permanent
Steps
- Source 0, permanent
- Relabel neighbours
- Fix smallest tentative
- Repeat
- Trace back
- Example (book Figure 4.12): A to D: A, B, E, F, H, D; cost 10
Flooding
Flooding: every packet sent out on every line except the one it arrived on
- Damping: hop counter, sequence numbers, selective flooding
- Uses: robust delivery, LSPs, broadcast, benchmark
Distance vector routing TOP 10/27
Distance vector routing: each router keeps its distance to every destination and periodically sends its whole table to its neighbours, updating by Bellman-Ford
- Keys: whole-network knowledge, neighbours only, regular intervals (RIP 30 s)
- Count to infinity: bad news slow; routers count up to 16
Loop prevention
- Maximum hop count
- Split horizon
- Poison reverse
- Route poisoning
- Triggered updates
- Hold-down timer
Link state routing TOP 11/27
Link state routing: each router floods the state of its own links to all routers, builds the full map and runs Dijkstra
Five steps
- Discover neighbours
- Measure cost
- Build LSP
- Flood
- Compute (Dijkstra)
| Point | Distance vector | Link state |
|---|---|---|
| Sends | whole table, to neighbours | own links, to all |
| Algorithm | Bellman-Ford | Dijkstra |
| Convergence | slow, count to infinity | fast |
| Examples | RIP, IGRP | OSPF, IS-IS |
Hierarchical routing
Hierarchical routing: routers grouped into regions; full detail inside a region, one entry per other region
- Saving: 17 entries to 7; 720 routers: 53, or 25 with three levels
- Cost: some longer paths
Routing protocols PIN 4/27
Routing protocol: rules and messages by which routers exchange reachability and cost to build their tables automatically
- Why: scale, discovery, adaptation, loop-free best paths, policy
- IGP (intra-AS): RIP, OSPF, IS-IS, EIGRP; EGP (inter-AS): BGP
The five
- RIPdistance vector, hops
- OSPFlink state, cost
- IGRPCisco distance vector
- EIGRPCisco, DUAL
- BGPpath vector, policy
RIP PIN 2/27
RIP: distance vector interior protocol; hop count, 15 most, 16 unreachable; whole table to neighbours every 30 s over UDP 520
Timers
- Update 30 s
- Invalid 180 s
- Hold-down 180 s
- Flush 240 s
- Operation: request, responses, add one hop, triggered updates, split horizon
- Versions: RIPv1 classful, broadcast; RIPv2 classless, 224.0.0.9; RIPng for IPv6
- Limits: 15 hops, slow convergence, ignores bandwidth
OSPF HOT 5/27
OSPF: open link state interior protocol; floods LSAs within areas, builds one database, runs Dijkstra; cost from bandwidth
Process
- Hello
- DR, BDR election
- Database exchange
- Flood LSAs
- SPF
- Routing table
States
- Down
- Init
- 2-Way
- ExStart
- Exchange
- Loading
- Full
- DR election: highest priority, then router ID; priority 0 never; no pre-emption
- Areas: backbone area 0, ABR, ASBR
BGP
BGP: the Internet's path vector exterior protocol between autonomous systems, over TCP 179
Messages
- Open
- Update
- Keepalive
- Notification
- Loops: a route carrying its own AS number is rejected
Unicast and multicast PIN 3/27
Multicast routing: one-to-many delivery to a joined group (class D address), one copy per link along a tree
- Unicast: one-to-one; RIP, OSPF, IS-IS, EIGRP, BGP
- Membership: IGMP between hosts and routers
Multicast protocols
- DVMRP
- MOSPF
- PIM-DM
- PIM-SM
- CBT
- Trees: source-based or shared (rendezvous point); RPF check
Network design PIN 2/27
Network design: choosing topology, devices, cabling, wireless, addressing, servers and security for a site, with a reason for each
Method
- Requirements, assumptions
- Topology
- Devices
- Cabling
- Wireless
- VLANs, subnets
- Servers
- Security
- Campus (500 PCs): 25 room switches, 5 distribution, 1 core, fibre backbone
- Hotel: dual ISP, UTM firewall, PoE+ per floor, Wi-Fi 6, VLANs, PMS
Chapter 5: Transport layer
5 hours · about 8 marks a paper · in 26 of the 27 sittings
Transport layer services HOT 5/27
Transport layer: the end-to-end layer, run only in hosts, that delivers data between processes using ports, over IP's host-to-host delivery
Services
- Process-to-process delivery
- Segmentation, reassembly
- Connection control
- Reliability
- Ordered delivery
- Flow control
- Multiplexing
- Congestion control
Complete and in order
- Handshake syncs ISNs
- Number every byte
- Checksum
- Cumulative ACK
- Retransmit on timeout
- Reorder in buffer
- Scopes: data link node to node, network host to host, transport process to process
- Example: 2001 lost, 3001 buffered, duplicate ACK 2001, resent, ACK 4001
Services to the upper layer
- Two services: connection-oriented (TCP, a phone call), connectionless (UDP, a letter)
Primitives
- LISTEN
- CONNECT
- SEND
- RECEIVE
- DISCONNECT
- Sockets: SOCKET, BIND, LISTEN, ACCEPT, CONNECT, SEND, RECEIVE, CLOSE
UDP HOT 6/27
UDP: User Datagram Protocol (RFC 768): connectionless, unreliable transport with an 8-byte header of ports, length and checksum
Header, 16 bits each
- Source port
- Destination port
- Length
- Checksum
- Checksum: pseudo-header, header, data; optional in IPv4, mandatory in IPv6; protocol 17
- Features: connectionless, no ACK, no order, boundaries kept, no flow control, multicast
- Why used: no setup, timeliness, low overhead, broadcast, application adds reliability
- Uses: DNS 53, DHCP 67/68, VoIP, games, SNMP 161, TFTP 69, QUIC
TCP TOP 9/27
TCP: Transmission Control Protocol (RFC 9293): connection-oriented, reliable, full-duplex byte stream with flow and congestion control
Header, 20 to 60 bytes, in bits
- Source port16
- Destination port16
- Sequence number32
- Acknowledgement32
- HLEN4
- Reserved4
- Flags8
- Window16
- Checksum16
- Urgent pointer16
- Options0 to 40 bytes
- Flags: CWR, ECE, URG, ACK, PSH, RST, SYN, FIN
- Reliable by: handshake, sequence numbers, cumulative ACK, retransmission, checksum, windows
TCP versus UDP HOT 6/27
TCP against UDP: reliability against speed: a connection-oriented reliable stream against connectionless best-effort datagrams
| Basis | TCP | UDP |
|---|---|---|
| Setup | handshake | none |
| Delivery | reliable, ordered | best effort |
| Header | 20 to 60 B | 8 B |
| Control | flow, congestion | none |
| Uses | web, mail, SSH | DNS, VoIP |
- Two protocols, one IP: opposite needs; end hosts only; IP the hourglass waist; changing IP needs every router
Ports and sockets PIN 4/27
Port number: a 16-bit number (0 to 65,535) in the TCP or UDP header naming a process on a host
IANA ranges
- Well-known0 to 1023
- Registered1024 to 49151
- Dynamic49152 to 65535
- Socket: IP plus port; connection = socket pair; also the API
- Why standardize: known meeting point, interoperability, defaults, firewall rules, no clashes
- Port 8765: URL needs :8765; a plain URL tries 80, refused
- Common: FTP 21, SSH 22, SMTP 25, DNS 53, HTTP 80, HTTPS 443
Handshake and release HOT 7/27
Three-way handshake: TCP connection setup in three segments, SYN, SYN + ACK, ACK, that synchronize both initial sequence numbers
Open
- LISTENpassive open
- SYNseq 8000
- SYN + ACKseq 15000, ack 8001
- ACKseq 8001, ack 15001
Release
- FIN
- ACKhalf-close
- FIN
- ACKTIME-WAIT 2 MSL
- Server first: no listening socket gives RST, connection refused
- Why three: both ISNs confirmed; old duplicate SYN rejected with RST
- States: SYN-SENT, SYN-RECEIVED, ESTABLISHED, FIN-WAIT-1, FIN-WAIT-2, CLOSE-WAIT, LAST-ACK, TIME-WAIT
Sliding window PIN 2/27
Sliding window: TCP flow control: the receiver advertises rwnd, its free buffer space, and the sender keeps at most rwnd bytes unacknowledged
Byte regions
- Acknowledged
- In flight
- Usable now
- Must wait
- Slides: ACK 3001, rwnd 4000: 3001 to 7000; ACK 5001: 5001 to 9000
- Zero window: sender stops; persist timer probes
- Refinements: silly window (Clark, Nagle), window scale, min(rwnd, cwnd)
- Buffers: chained fixed-size, chained variable-size, one circular per connection
Multiplexing and demultiplexing
- Multiplexing: sender adds port headers; many sockets, one IP
- Demultiplexing: receiver reads ports, delivers to the socket
- Keys: UDP destination IP and port; TCP four-tuple
- Also: upward and downward (inverse) multiplexing
Congestion PIN 4/27
Congestion: offered load exceeds the capacity of the network or part of it: queues overflow, delay rises, throughput falls
- Causes: arrival rate above capacity, buffer too small or too big, bursts, slow routers, retransmissions, poor routing
- Prevention (open loop): retransmission, window, ACK, discard, admission policies; traffic shaping
- Removal (closed loop): backpressure, choke packets, implicit and explicit (ECN) signals, load shedding, RED
- TCP: slow start, congestion avoidance (AIMD), fast retransmit, fast recovery
Leaky bucket HOT 5/27
Leaky bucket: traffic shaping by a finite packet queue drained at a constant rate; packets arriving when it is full are discarded
Steps
- Packet arrives
- Fulldiscard
- Elsejoin queue
- One packet per tick out
- Byte counting: n bytes a tick; send while packets fit; leftover not saved
- Example: n = 1000: tick 1 sends 200 and 700, tick 2 sends 500 and 300
- Limits: loses bursts, saves no credit, rigid rate
Token bucket TOP 9/27
Token bucket: traffic shaping where tokens arrive at rate r up to capacity C; a packet leaves only by taking one, so saved tokens allow bursts
Steps
- Token every ΔT
- Fulltoken discarded
- Packet takes a token
- No tokenwaits
- Example: C = 6 Mb, M = 10 Mbps, r = 2 Mbps: S = 0.75 s
| Basis | Leaky | Token |
|---|---|---|
| Holds | packets | tokens |
| Output | fixed r | bursts to C |
| When full | drops packets | drops tokens |
Chapter 6: Application layer
5 hours · about 8 marks a paper · in 24 of the 27 sittings
Application layer and ports
- Models: client-server; peer-to-peer
TCP ports
- HTTP80
- HTTPS443
- FTP21, 20
- SSH22
- Telnet23
- SMTP25, 587
- POP3110
- IMAP143
UDP ports
- DNS53
- DHCP67, 68
- TFTP69
- SNMP161, 162
HTTP and HTTPS HOT 5/27
HTTP: the web's stateless request and response protocol over TCP port 80; HTTPS is HTTP inside TLS, port 443
Serving a request
- DNS lookup
- TCP handshake
- GET request
- Server finds the file
- 200 OK response
- Render, fetch objects
- Messages: request line or status line, headers, blank line, body
- Status: 2xx success, 3xx redirect, 4xx client error, 5xx server error
- Connections: non-persistent 2 RTT per object; persistent reuses one
- HTTPS adds: certificate, encryption, integrity
FTP and TFTP PIN 4/27
FTP: file transfer over two TCP connections: control to port 21 for the session, data from port 20 for each file
Session
- Connect to 21220
- USER, PASS230
- PORT or PASV
- RETR or STOR150
- Data on 20226
- QUIT221
- Modes: active, server connects from 20; passive, client connects
- TFTP: UDP 69, no login, 512-byte blocks each ACKed
SSH, PuTTY and WinSCP
SSH: encrypted remote login and file copy over TCP port 22
- PuTTY: SSH and Telnet client
- WinSCP: SFTP, SCP, FTP client, drag and drop
- Replaces: Telnet 23, plain FTP
Electronic mail TOP 11/27
Electronic mail: asynchronous messaging; SMTP pushes mail to and between servers, POP3 or IMAP pulls it from the mailbox
Components
- User agent
- Mail server
- MTA
- MDA
- MAA, mailbox
SMTP, port 25
- 220
- HELO250
- MAIL FROM250
- RCPT TO250
- DATA354
- Body, "."250
- QUIT221
| Point | POP3 (110) | IMAP (143) |
|---|---|---|
| downloaded | stays on server | |
| Devices | one | many |
- MIME: Content-Type; base64, 3 bytes to 4 characters
DNS TOP 11/27
DNS: distributed, hierarchical database mapping host names to IP addresses, queried over UDP port 53
Servers
- Root
- TLD
- Authoritative
- Local resolver
| Point | Recursive | Iterative |
|---|---|---|
| Work | server asked | asker |
| Reply | answer | referral |
- Records: A, AAAA, CNAME, MX, NS, PTR, SOA, TXT
- Delegation: parent's NS records, plus glue
- Message: ID, flags, counts; question, answer, authority, additional
DHCP PIN 1/27
DHCP: leases a host an IP address, mask, gateway and DNS server for a limited time, over UDP ports 67 and 68
Getting an address
- DISCOVER, broadcast
- OFFER
- REQUEST, broadcast
- ACK
Lease
- Bound
- T1 = 50%unicast renew
- T2 = 87.5%broadcast rebind
- ExpiryDISCOVER again
- Example: 24 h lease: T1 12 h, T2 21 h
P2P applications
P2P application: peers act as both client and server, with little or no central server
- BitTorrent: tracker, pieces, rarest first, tit for tat
- DHT: lookup in about log N hops
Socket programming HOT 5/27
Socket programming: writing network programs through the socket API, the interface between a process and TCP or UDP
Server
- socket()
- bind()
- listen()
- accept()
- recv(), send()
- close()
Client
- socket()
- connect()
- send(), recv()
- close()
Socket types
- StreamTCP
- DatagramUDP
- RawIP
- Rule: server runs first, else connect is refused
Proxy and web caching PIN 3/27
Proxy server: an intermediary that makes requests for clients; a web cache answers repeats from stored copies
A miss
- Request to proxy
- Cache check
- Fetch from origin
- Store a copy
- Forward to client
- Hit: copy returned at once, from the LAN
- Stale copy: conditional GET, 304 Not Modified
Uses
- Speed
- Bandwidth
- Filtering
- Privacy
- Logging
- Kinds: forward, reverse, transparent, anonymous
Server optimization
- Web: caching, CDN, compression, load balancing
- Mail: backup MX, spam filtering, RAID mailboxes
- DNS: caching, secondary servers, anycast
- All: RAID, UPS, monitoring
RAID PIN 1/27
RAID: several disks combined into one logical volume for speed, fault tolerance or both
Why servers need it
- Availability
- Performance
- Capacity
| Point | RAID 0 | RAID 1 | RAID 5 |
|---|---|---|---|
| Technique | striping | mirroring | parity |
| Capacity | n disks | one | n minus 1 |
| Survives | nothing | one disk | one disk |
- Parity: XOR; a lost block is the XOR of the rest
SNMP
SNMP: a manager reads and sets agents' MIB variables over UDP
Parts
- Manager
- Agent
- MIB
- OID
- Messages: Get, Set, Response, Trap; ports 161, 162
MRTG and PRTG
- MRTG: free; SNMP counters every 5 minutes; traffic graphs
- PRTG: Paessler, Windows; sensors, dashboards, alerts
Wireshark and Packet Tracer
- Wireshark: packet analyser; captures real traffic; filters
- Packet Tracer: Cisco simulator; simulation mode shows packets
Chapter 7: Introduction to IPv6
4 hours · about 7 marks a paper · in 24 of the 27 sittings
Why IPv6 TOP 13/27
IPv6: the IETF's replacement for IPv4 (RFC 8200): 128-bit addresses, fixed 40-byte header, extension headers, autoconfiguration, multicast, IPsec
| IPv4 problem | IPv6 answer |
|---|---|
| addresses | addresses |
| NAT, no end-to-end | global addresses |
| Complex header | fixed 40 bytes |
| No security, weak QoS | AH, ESP; flow label |
| Manual setup | SLAAC |
Advantages
- Larger address space
- Better header
- Extension headers
- Smaller routing tables
- Security
- QoS
- Autoconfiguration
- Multicast, anycast
- Factors: exhaustion (IANA, 2011), phones and IoT, NAT's cost, real-time media, security
IPv6 datagram HOT 6/27
IPv6 datagram: a fixed 40-byte base header, then optional extension headers and upper-layer data
Fields, in bits
- Version4
- Traffic class8
- Flow label20
- Payload length16
- Next header8
- Hop limit8
- Source128
- Destination128
- Removed from IPv4: IHL, identification, flags, fragment offset, checksum, options
- Renamed: TOS to traffic class, total length to payload length, TTL to hop limit, protocol to next header
- Added: flow label, 20 bits
- Router work: hop limit minus 1 only; no checksum, no fragmenting
Extension headers PIN 1/27
Extension headers: optional headers between base header and data, chained by next header; only hop-by-hop is read on the way
Order, with codes
- Hop-by-hop0
- Destination options60
- Routing43
- Fragment44
- AH51
- ESP50
- Destination options60
- Upper layer6, 17, 58
- Rules: each once, destination options twice; hop-by-hop first; only the source fragments
IPv6 addresses PIN 3/27
IPv6 address: 128 bits as eight groups of four hex digits; drop leading zeros, one :: per address
- Example:
2001:0db8:0000:0000:0000:ff00:0042:8329is2001:db8::ff00:42:8329
Types
- Unicastone interface
- Anycastthe nearest one
- Multicastevery member,
ff00::/8
- Unicast kinds: global
2000::/3, link-localfe80::/10, unique localfc00::/7, loopback::1 - IPv4-mapped:
::ffff:192.0.2.33, that is::ffff:c000:221
SLAAC
- Link-local address
- DAD
- Router solicitation
- Router advertisement
- Prefix + interface ID
- DHCPv6 if flagged
IPv6 multicasting
Format
- ff8 bits
- Flags4 bits
- Scope4 bits
- Group ID112 bits
- Scopes: 1 interface, 2 link, 5 site, 8 organization, e global
- Solicited-node:
ff02::1:ff+ last 24 bits; replaces broadcast - MLD: ICMPv6 group membership, the IPv6 IGMP
IPv4 to IPv6 transition TOP 18/27
Transition: gradual migration with IPv4 and IPv6 coexisting: dual stack, tunneling, header translation
Strategies
- Dual stackboth stacks, DNS picks
- TunnelingIPv6 inside IPv4
- Translationheader rewritten
- Tunnels: protocol 41; configured, 6to4, ISATAP, 6RD, Teredo
- 6to4:
2002:+ router's IPv4 + subnet + interface ID - ISATAP: 64-bit prefix +
0:5efe:+ host's IPv4 - 6RD: ISP's own prefix + CE's IPv4 bits; relays
- Translation: SIIT; NAT64 with DNS64,
64:ff9b::/96; 464XLAT - Choose: dual stack first; tunnels across IPv4; translation for IPv6-only
Chapter 8: Network security
7 hours · about 11 marks a paper · in 26 of the 27 sittings
Network security and its properties TOP 11/27
Network security: the policies, practices and technologies that protect a network and its data from unauthorised access, misuse, modification and disruption
Attacks and the property broken
- Interruptionavailability
- Interceptionconfidentiality
- Modificationintegrity
- Fabricationauthenticity
Six properties
- Confidentiality
- Integrity
- Authentication
- Non-repudiation
- Availability
- Access control
- Passive, active: interception; interruption, modification, fabrication, replay, denial of service
- Maintained by: policy, access control, encryption, firewalls, VLANs, patching, anti-malware, IDS, backups, training
Cryptography: symmetric and public key HOT 8/27
Cryptography: securing messages by turning plaintext into ciphertext with a cipher and a key; only the right key turns it back
| Point | Symmetric key | Public key |
|---|---|---|
| Keys | one shared secret key | public and private pair |
| Speed | fast: bulk data | slow: keys, digests |
| Keys for users | ||
| Examples | DES, AES, RC4 | RSA, Diffie-Hellman, ECC |
- Hybrid: public key sends a session key; a symmetric cipher encrypts the data
- Third tool: hash function (SHA-256): one-way, fixed-length digest
Classical ciphers
Two kinds
- Substitutionletters replaced
- Transpositionletters reordered
- Substitution: Caesar, monoalphabetic, polyalphabetic (Vigenère)
DES and AES PIN 4/27
DES and AES: symmetric block ciphers: DES, 64-bit block, 56-bit key, 16 Feistel rounds; AES, 128-bit block, 128, 192 or 256-bit key
DES
- Initial permutation
- 16 Feistel rounds
- 32-bit swap
- Final permutation
Function f
- Expand 32 to 48
- XOR round key
- 8 S-boxes, 6 to 4
- Permute P
AES round
- SubBytes
- ShiftRows
- MixColumns
- AddRoundKey
- AES rounds: 10, 12, 14; last round without MixColumns
- Structure: DES Feistel, broken by brute force; AES substitution-permutation, secure
RSA TOP 16/27
RSA: Rivest, Shamir and Adleman's public key algorithm: public key encrypts, private key decrypts; security from factoring
Key generation
- Choose primes p, q
- Choose e
- Find d
- Example: p 7, q 11, n 77, e 13, d 37; E (5) encrypts to 26
- Words: A = 1 to Z = 26; n above 26; each letter alone
Diffie-Hellman key exchange PIN 2/27
Diffie-Hellman: key agreement over an open channel: both ends compute the same secret , never sending it
Steps
- Public prime N, generator G
- A sends
- B sends
- Both compute K
- Example: G 7, N 23, x 3, y 6 give R1 21, R2 4, K 18
- Security: discrete logarithm; man in the middle unless authenticated
Digital signatures HOT 5/27
Digital signature: a digest of the message encrypted with the sender's private key, checked by anyone with the sender's public key
Sign at A
- Hash the message
- Encrypt digestA's private key
- Send message and signature
Verify at B
- Hash the message
- Decrypt signatureA's public key
- Compare the digests
Gives
- Authentication
- Integrity
- Non-repudiation
- Not given: confidentiality; a CA certificate binds the public key to its owner
PGP PIN 3/27
PGP: Pretty Good Privacy (Zimmermann, 1991): e-mail security from a signature, a one-time session key and the receiver's public key
At sender A
- Hash
- SignA's private key
- CompressZIP
- Encryptsession key
- Lock keyB's public key
- Base64
Services
- Authentication
- Confidentiality
- Compression
- E-mail compatibility
- Segmentation
- Trust: key rings, web of trust; S/MIME uses CA certificates
SSL and TLS PIN 3/27
SSL/TLS: a layer between TCP and the application that authenticates the server, agrees session keys, and encrypts and MACs the data
Handshake
- ClientHello
- ServerHello
- Certificate
- Key exchangepre-master secret
- Change cipher spec, Finished
- Encrypted data
Record protocol
- Fragment
- Compress
- Add MAC
- Encrypt
- Add header
- Port: HTTPS on 443; sub-protocols handshake, change cipher spec, alert, record
IPsec PIN 3/27
IPsec: IETF protocols that secure IP packets at the network layer, with AH or ESP, in transport or tunnel mode
- AH (protocol 51): authentication, integrity, anti-replay; no encryption
- ESP (protocol 50): encryption plus authentication, integrity, anti-replay
- Modes: transport: payload, host to host; tunnel: whole packet, gateway to gateway
- SA: one-way; SPI, destination, protocol; set up by IKE
VPN HOT 5/27
VPN: a private network over the public Internet, built from encrypted, authenticated tunnels between its endpoints
Working
- Authenticate
- Agree keys
- Encrypt, encapsulate
- Cross the Internet
- Decrypt, deliver
Types
- Remote accesshost to gateway
- Site to siteintranet, extranet
- Protocols: IPsec, SSL/TLS (OpenVPN), L2TP over IPsec, WireGuard
- Example: Kathmandu head office to Pokhara branch through an IPsec tunnel
WEP and wireless security PIN 2/27
WEP: Wired Equivalent Privacy, the original 802.11 security: RC4 keyed by a 24-bit IV and a 40 or 104-bit key, with a CRC-32 check
Encrypt a frame
- IV + key seed RC4
- Append CRC-32 ICV
- XOR with keystream
- Send, IV in clear
Weaknesses
- IV repeats
- Weak RC4 keys
- Linear CRC-32
- One static key
- Replaced by: WPA (TKIP), WPA2 (AES-CCMP, 802.11i), WPA3 (SAE)
Firewalls and router ACLs TOP 13/27
Firewall: a device or software at the boundary of a trusted network that permits or blocks traffic by a security policy
Types
- Packet filter
- Stateful inspection
- Application gateway (proxy)
- Circuit-level gateway
- Next-generation firewall
Packet filter
- Read the header
- Compare rules, top down
- First matchpermit or deny
- No matchimplicit deny
- Protects by: choke point, filtering, state table, NAT, content control, DMZ, logging
- ACL:
access-list 10 deny 202.70.91.0 0.0.0.255,access-list 10 permit any,ip access-group 10 in
Intrusion detection systems PIN 1/27
IDS: a device or software that monitors a network or hosts for malicious activity and raises alerts
Where
- NIDSa network segment
- HIDSone host
How
- Signatureknown patterns
- Anomalydeviation from baseline
- IDS, IPS: IDS detects and alerts; IPS sits inline and blocks
All eight chaptersRecall sheet
Only what is hard to remember: the steps and phases in order, the types, the advantages and disadvantages, the numbers. No reasons and no explanations; each topic name opens its full card.
Chapter 1: Introduction to computer network
Computer network PIN 4/27
- Definition: autonomous computers, links, protocols, exchange data, share resources
- Parts: nodes, links, protocols, services
- Business: resource sharing, reliability, saving money, scalability, e-commerce
- Home: remote information, communication, entertainment, e-commerce, online education
- Five instances: wallet payments, VoIP calls, online classes, streaming, ride booking
Network types PIN 1/27
- By size: PAN 1 to 10 m, LAN campus, MAN city, WAN country
- LAN: private, fast, Ethernet, Wi-Fi
- WAN: hosts plus a subnet of routers, leased lines, store and forward
- Other bases: broadcast or point to point; client/server or P2P
Topologies PIN 1/27
- Types: bus, star, ring, mesh, tree, hybrid
- Physical vs logical: cable layout, signal path
- Mesh: n(n-1)/2 links, n-1 ports each
- Weak points: bus backbone, star switch, ring break, tree root
Client/server and P2P TOP 10/27
- Client/server: server listens, client requests, server processes, server replies
- C/S features: central data, security, backup; tiers; single point of failure
- P2P process: join, search, connect, exchange, leave
- P2P kinds: pure (Gnutella), hybrid (Napster, BitTorrent), workgroup
- Compare on: control, cost, security, scalability, failure, example
Active networking PIN 1/27
- Idea: programmable nodes, computation on packets
- Approaches: capsule (integrated), programmable switch (discrete)
- Active node: NodeOS, execution environments, active applications, ANEP
- Legacy network: store and forward, vendor firmware, slow new services
- Successors: SDN, programmable switches
Protocols and standards HOT 5/27
- Protocol: rules, format, order, meaning, actions
- Elements: syntax, semantics, timing
- Bodies: ISO, ITU-T (CCITT), IEEE, IETF, ANSI, EIA
- Standards: de jure, de facto
- Interface: boundary between adjacent layers, primitives, services
Layered architecture TOP 9/27
- Reasons: complexity, modularity, standards, troubleshooting, reuse, flexibility
- Hierarchy: peers, protocols, interfaces, virtual communication
- Flow: M, H4, H3 with M1 and M2, H2 and T2, bits
- Architecture: layers and protocols; TCP/IP, SNA
- Design issues: addressing, direction, error control, flow control, multiplexing, routing, ordering, segmentation
Services and primitives PIN 1/27
- Kinds: connection-oriented (phone), connectionless (post)
- Primitives: LISTEN, CONNECT, RECEIVE, SEND, DISCONNECT; ACCEPT later
- OSI classes: request, indication, response, confirm
- Sockets: listen, connect, accept, send, recv, close
OSI model HOT 8/27
- Layers up: physical, data link, network, transport, session, presentation, application
- Units: bit, frame, packet, segment, SPDU, PPDU, APDU
- Hop by hop: layers 1 to 3; end to end, 4 to 7
- Which layer: voltage physical; framing, MAC, errors data link; IP network; sockets transport; dialog session; encryption presentation
- Origin: ISO 7498, 1984; work began 1977
TCP/IP model PIN 4/27
- Layers up: host-to-network, internet, transport, application
- Internet: IP, ICMP, IGMP, ARP; connectionless
- Transport: TCP reliable, UDP fast
- Application: HTTP 80, HTTPS 443, SMTP 25, DNS 53, FTP 21, SSH 22
- Origin: ARPANET, Cerf and Kahn 1974, switch on 1 January 1983
Encapsulation PIN 3/27
- Units down: data, segment, packet, frame, bits
- Header: addresses, sequence numbers, type, checksum
- Trailer: FCS (CRC), data link only
- Router: up to the IP header, new frame each hop
OSI vs TCP/IP TOP 9/27
- Layers: 7 vs 4
- Made: model first vs protocols first
- Network layer: both services vs connectionless
- Transport layer: connection-oriented vs TCP and UDP
- Similar: layered, transport end to end, network layer, application
- OSI lost on: timing, technology, implementations, politics
The Internet
- History: ARPANET 1969, TCP/IP 1983, NSFNET 1986 to 1995, web 1989 to 1991
- Structure: hosts, access networks, tiered ISPs, IXPs, NPIX
- Governance: ICANN, IANA, APNIC, IETF RFCs, .np
- Kinds: internet, Internet, intranet, extranet
X.25 HOT 7/27
- Layers: physical X.21, link LAPB, packet PLP
- Header: GFI (Q, D, modulo), LCGN 4, LCN 8, P(R), M, P(S), 0
- Call: request, incoming, accepted, connected, data, clear request, indication, confirmation
- Circuits: SVC, PVC; 4095 per line; window 2; 128-byte data
- Type codes: call request 00001011, accepted 00001111, clear 00010011
Frame Relay HOT 5/27
- Layers: physical and data link; errors detected, frames dropped
- Address: DLCI 10 bits, C/R, EA, FECN, BECN, DE
- Congestion: CIR, DE dropped first, FECN forward, BECN back
- SVC states: setup, data transfer, idle, termination
- Q.933 messages: SETUP, CALL PROCEEDING, CONNECT, DISCONNECT, RELEASE, RELEASE COMPLETE
- Speeds: 56 kbps to 44.736 Mbps
ATM PIN 3/27
- Cell: 53 bytes, 5 header, 48 payload
- UNI header: GFC 4, VPI 8, VCI 16, PT 3, CLP 1, HEC 8
- Layers: AAL (CS, SAR), ATM layer, physical (TC, PMD)
- AAL types: AAL1 CBR, AAL2 timed VBR, AAL3/4 data, AAL5 IP
- Services: CBR, rt-VBR, nrt-VBR, ABR, UBR
Ethernet
- Standard: IEEE 802.3, Xerox PARC 1973, DIX
- Speeds: 10 Mbps, 100 Mbps, 1 Gbps, 10 Gbps, 400 Gbps
- Change: shared coaxial bus to switched full-duplex star
VoIP
- Steps: SIP, codec, RTP over UDP, jitter buffer
- Codecs: G.711 64 kbps, G.729 8 kbps, Opus
- Quality: delay under 150 ms, jitter, loss
- G.711 call: 80 kbps
NGN
- Standard: ITU-T Y.2001, Y.2011
- Ideas: IP core, convergence, service and transport strata, IMS, mobility
- Layers: access, transport, control, service
MPLS
- Label: 20 bits, TC 3, S 1, TTL 8
- Routers: LER push, LSR swap, egress pop; FEC, LSP
- Uses: traffic engineering, VPN, QoS, fast reroute
xDSL
- Parts: splitter, modem, DSLAM, DMT
- Variants: ADSL, ADSL2+, VDSL2, HDSL, SDSL
- Against ISDN: same copper, far faster than 144 kbps
Chapter 2: Physical layer
Physical layer PIN 1/27
- Definition: layer 1, raw bits as signals; mechanical, electrical, functional, procedural
- Functions: physical characteristics, bit representation, data rate, synchronization, line configuration, topology, transmission mode
- Modes: simplex, half-duplex, full-duplex
- In TCP/IP: inside host-to-network (network access) layer
- Devices: repeater, hub, modem, transceiver, cable
Delay and throughput PIN 3/27
- Measures: bandwidth, throughput, latency, jitter
- Four delays: processing, queuing, transmission L/R, propagation d/s
- Throughput: data delivered / time; never above bandwidth
- Products: bandwidth-delay product R x propagation delay; RTT two-way
- Causes: congestion, slow links, distance, hops, retransmission, slow hosts
- Example: 1,500 bytes at 10 Mbps 1.2 ms; GEO hop 238.6 ms
Channel capacity PIN 1/27
- Nyquist: C = 2B log2 L, noiseless
- Shannon: C = B log2 (1 + SNR), noisy
- SNR dB: 10 log10 (S/N); 10 dB 10, 20 dB 100, 30 dB 1000
- Impairments: attenuation, distortion, noise (thermal, induced, crosstalk, impulse)
- Example: 3 kHz at 30 dB, 29.9 kbps; 2066 Bhadra 1.04 Gbps
Transmission media HOT 7/27
- Definition: physical path carrying the signal, below the physical layer
- Kinds: guided (twisted pair, coaxial, fiber); unguided (radio, microwave, infrared)
- Factors: security, bandwidth, environment, noise, installation, mobility, cost, distance
- Campus: UTP labs, multimode fiber backbone, microwave bridge, Wi-Fi, ISP fiber
Twisted pair and coaxial HOT 7/27
- Twisted pair: two copper wires twisted, noise cancels; four pairs, RJ-45
- Types: UTP, STP (F/UTP, U/FTP, S/FTP); straight-through, crossover, rollover
- Categories: Cat 3 16 MHz, Cat 5e 100 MHz, Cat 6 250 MHz, Cat 6A 500 MHz, Cat 8 2000 MHz
- Limits: Ethernet 100 m; amplifiers 5 to 6 km, repeaters 2 to 3 km
- Coaxial: conductor, dielectric, braid, jacket; RG-6, RG-59 75 ohm; RG-58, RG-8 50 ohm
- Compare: signal, bandwidth, distance, noise, attenuation, security, cost, installation
Optical fiber PIN 1/27
- Structure: core, cladding 125 micrometres, buffer 250, Kevlar, jacket
- Principle: total internal reflection; critical angle, numerical aperture
- Modes: step index, graded index (50, 62.5 micrometres), single mode (8 to 10)
- Parts: source LED or laser; detector PIN or APD; repeater or EDFA
- Windows: 850, 1310, 1550 nm; 353, 229, 193 THz
- Block diagram: source, transmitter, optical source, fiber, detector, receiver, destination
Unguided media HOT 5/27
- Media: radio 3 kHz to 1 GHz; microwave 1 to 300 GHz; infrared 300 GHz to 400 THz
- Antennas: omnidirectional, directional (dish, horn)
- Propagation: ground below 2 MHz; sky 2 to 30 MHz; line of sight above 30 MHz
- LOS: direct and ground-reflected waves; d = 3.57 root (Kh) km, K 4/3
- Impairments: free-space loss, rain, multipath, refraction, obstacles
Satellite communication
- Transponder: amplification, frequency translation; uplink above downlink
- Orbits: LEO 500 to 2,000 km; MEO, GPS 20,200 km; GEO 35,786 km
- Delay: GEO hop 0.24 s, reply 0.48 s; LEO 550 km 3.7 ms
- Bands: L, S, C, X, Ku, K, Ka, V, W
Multiplexing HOT 6/27
- Definition: many signals, one link; MUX and DEMUX
- Importance: efficiency, cost, trunks and broadcasting, scalability
- Types: FDM (guard bands), WDM, synchronous TDM, statistical TDM, CDM
- TDM example: 4 x 64 kbps, 33-bit frame, 264 kbps
- CDM: orthogonal chip codes; CDMA 3G, GPS
Switching TOP 13/27
- Definition: sender to receiver through intermediate switches; mesh needs n(n-1)/2 links
- Types: circuit, message, packet (datagram, virtual circuit)
- Circuit phases: setup, data transfer, teardown
- Compare: path, setup, bandwidth, store-and-forward, addressing, delay, order, congestion, charging
- Real time: reserved bandwidth, constant delay, no jitter, in order, one setup
- Versus multiplexing: path through network against sharing one link
Datagram and virtual circuit HOT 6/27
- Datagram: connectionless, full address, independent routing, out of order; IP
- Virtual circuit: setup, data transfer, teardown; short VCI swapped each hop
- VC types: PVC, SVC
- VCI names: X.25 LCN, Frame Relay DLCI, ATM VPI/VCI, MPLS label
- Frame Relay: DLCI 10 bits, PVC, Q.933 SVC, FECN, BECN, DE
Telephone network and E1 PIN 2/27
- Parts: telephone set, local loop, end office, tandem, toll office, trunks
- Telephone set: transmitter, receiver, hook switch, DTMF dialler, ringer, hybrid
- Call steps: off-hook, dial tone, dialling, switching, ringing, answer, hang up
- T1: 24 channels, 193 bits, 1.544 Mbps; DS2 6.312, DS3 44.736
- E1: 32 slots, TS0 sync, TS16 signalling, 2.048 Mbps; E2 8.448, E3 34.368, E4 139.264
Switching systems
- Kinds: manual; Strowger, crossbar; electronic SPC
- Electronic: space division, time division (analog, digital)
- Space: crossbar N squared crosspoints; multistage
- Time: time slot interchange; TST
- Signalling: CAS (TS16), CCS (SS7)
ISDN HOT 5/27
- Purpose: digital local loop, one network, out-of-band signalling, digital quality
- Channels: B 64 kbps; D 16 or 64 kbps; H0 384, H11 1536, H12 1920
- Interfaces: BRI 2B+D 144 (192) kbps; PRI 23B+D 1.544, 30B+D 2.048 Mbps
- Groups: TE1, TE2, TA, NT2, NT1; points R, S, T, U
- Signalling: D channel, LAPD (Q.921), Q.931; SS7 inside
- Messages: SETUP, CALL PROCEEDING, ALERTING, CONNECT, DISCONNECT, RELEASE
Chapter 3: Data link layer
Data link layer HOT 8/27
- Functions: framing, physical addressing, flow control, error control, access control
- Services: unacknowledged connectionless (Ethernet), acknowledged connectionless (Wi-Fi), acknowledged connection-oriented (HDLC)
- Design issues: service interface, framing, error control, flow control, medium access, addressing
- Sublayers: LLC 802.2, DSAP and SSAP, types 1, 2, 3; MAC per LAN
Framing TOP 10/27
- Methods: character count, byte stuffing, bit stuffing, coding violations
- Count flaw: one garbled count, every later boundary lost
- Byte stuffing: FLAG, ESC before FLAG or ESC; PPP 0x7E, 0x7D
- Bit stuffing: flag 01111110, a 0 after five 1s; HDLC
- Coding violations: Manchester high-high, low-low; 4B/5B J and K
- Example: 01001111110111110 to 0100111110101111100
Errors, parity, checksum PIN 1/27
- Types: single-bit, burst (first to last bad bit); content, flow integrity
- Detection: discard and resend, ARQ, backward correction; parity, checksum, CRC
- Correction: FEC, more redundancy; Hamming, Reed-Solomon; QR codes
- Parity: odd counts only; 2D parity corrects one bit
- Checksum: one's complement sum, complement sent; book example 11011010
CRC PIN 3/27
- Sender: append r zeros, divide by G mod 2, remainder is the CRC
- Receiver: divide by G; zero accept, nonzero reject
- Detects: single-bit, odd counts with x + 1, bursts up to r
- Generators: CRC-8 ATM, CRC-16-CCITT HDLC and PPP, CRC-32 Ethernet
- Example: 1101 with 1011, remainder 001, sent 1101001
Hamming distance, Hamming code PIN 1/27
- Distance: XOR, count the 1s; 10101 and 11110 give 3
- Rules: detect s if d ≥ s + 1; correct t if d ≥ 2t + 1
- Parity bits: positions 1, 2, 4; 2^r ≥ m + r + 1
- Groups: P1 1, 3, 5, 7; P2 2, 3, 6, 7; P4 4, 5, 6, 7
- Book example: 1110111, syndrome 100, bit 4, corrected 1111111
Flow control HOT 5/27
- Stop and wait: one frame then ACK; U = 1/(1 + 2a)
- Sliding window: W frames, seq modulo 2^k, ACK names next expected
- Piggybacking: ack field in data frames, ack timer; HDLC N(R), TCP
- Satellite example: a = 270, U 0.18 %; W = 7 gives 1.3 %
ARQ PIN 4/27
- Tools: sequence numbers, ACK, NAK, timers, copies kept
- Stop and wait: 1-bit seq; damaged frame, lost frame, lost ACK
- Go-back-N: window 2^k - 1, receiver window 1, resend from the lost frame
- Selective repeat: windows 2^(k-1), buffer, resend only the lost frame
- Window limits: 3 bits, GBN 7, SR 4
HDLC PIN 2/27
- Stations: primary, secondary, combined
- Configurations: unbalanced, balanced, symmetric
- Modes: NRM, ARM, ABM
- Frame: flag, address, control, information, FCS, flag
- Frame types: I with N(S), N(R); S with RR, RNR, REJ, SREJ; U with SNRM, SABM, DISC, UA
- Family: LAPB, LAPD, LAPF; Cisco serial default
PPP
- Parts: framing, LCP, NCPs (IPCP)
- Frame: 0x7E, 0xFF, 0x03, protocol, payload 1500, FCS, 0x7E
- Phases: dead, establish, authenticate, network, open, terminate
- Authentication: PAP clear password, CHAP challenge and hash
- Related: SLIP (RFC 1055), PPPoE
MAC sublayer HOT 7/27
- Job: who sends next on a broadcast channel
- Why essential: collisions, efficiency, fairness, delay, priority, cost
- Static: FDM, TDM; delay N times; 200 µs against 2 ms
- Dynamic: station model, one channel, collisions observed, slotted or continuous, carrier sense or not
- Classes: random, controlled, channelization
ALOHA HOT 6/27
- Origin: ALOHAnet, Hawaii, Abramson, 1971
- Pure: any time, vulnerable 2T, S = G e^-2G, 18.4 % at G = 0.5
- Slotted: slot starts, vulnerable T, S = G e^-G, 36.8 % at G = 1
- No collision: none within T either side; none in the same slot
- Example: 200 kbps, 200-bit frames; 135, 92, 38 frames/s
CSMA PIN 1/27
- Rule: listen before talk
- Vulnerable time: propagation time
- Persistence: 1-persistent (Ethernet), non-persistent, p-persistent
CSMA/CD TOP 9/27
- Steps: sense, transmit and listen, detect, jam 32 bits, back off, retry
- Backoff: K from 0 to 2^min(n,10) - 1, slot 512 bit times, 16 attempts
- Detection: higher signal level on coax; receive activity on twisted pair
- Minimum frame: 2 T_prop B; 51.2 µs, 512 bits, 64 bytes
- Collision: overlapping frames; propagation delay, waiting stations
- Today: switches, full duplex, no collisions
Controlled access
- Reservation: mini-slots before data
- Polling: poll and select, primary station; Bluetooth, HDLC NRM
- Token passing: logical ring; holding time, priority, lost token
Channelization
- FDMA: bands, guard bands; first-generation mobile
- TDMA: time slots, synchronisation; GSM 8 slots per 200 kHz carrier
- CDMA: orthogonal Walsh codes, inner product; 3G
IEEE 802 family
- Standards: 802.1 bridging, VLANs; 802.2 LLC; 802.3 Ethernet; 802.4 token bus; 802.5 token ring; 802.11 Wi-Fi; 802.15 Bluetooth; 802.16 WiMAX
- Status: 802.4 and 802.5 withdrawn
Ethernet PIN 4/27
- Frame: preamble 7, SFD 1, DA 6, SA 6, length/type 2, data 46 to 1500, FCS 4
- Sizes: 64 to 1518 bytes; gap 96 bits; type 0x0800 IPv4
- MAC address: 48 bits, OUI, I/G, U/L, broadcast FF:FF:FF:FF:FF:FF
- Cabling: 10Base5, 10Base2, 10BaseT, 10BaseF, 100BaseTX, 100BaseFX, 1000BaseT
- Fiber: 1000BaseSX 850 nm, 1000BaseLX 1310 nm, 10GBase-SR, LR, ER
Token bus HOT 5/27
- Idea: physical bus, logical ring by descending address
- Token ring name: token circles, lowest back to highest
- Priority: classes 0, 2, 4, 6
- Maintenance: claim token, solicit successor, who follows, set successor
- Physical: broadband coax, 1, 5, 10 Mbps; MAP factories
Token ring PIN 4/27
- Steps: wait, seize (T bit), circulate, copy (A, C), remove, release
- Frame: SD, AC, FC, DA, SA, data, FCS, ED, FS; token SD, AC, ED
- AC byte: PPPTMRRR
- Monitor: lost token, orphan frames, ring delay
- Physical: 4 or 16 Mbps, STP, differential Manchester, MAU, 10 ms
FDDI PIN 3/27
- Basics: 100 Mbps fiber, dual counter-rotating rings, 4B/5B
- Size: 1000 connections, 200 km, 2 km apart, 4500-byte frames
- Timed token: synchronous and asynchronous traffic, early release
- Stations: DAS, SAS, concentrators
- Fault tolerance: wrap, optical bypass, dual homing
Wireless LAN PIN 3/27
- Architecture: BSS ad hoc, infrastructure with AP; ESS, distribution system, SSID
- No CSMA/CD: cannot listen while sending; hidden, exposed stations; fading
- CSMA/CA: DIFS, contention window, SIFS, ACK, RTS, CTS, NAV
- DSSS: Barker 10110111000, 11 chips, 22 MHz, 10.4 dB
- Versions: 802.11b, a, g, n, ac, ax
VLAN PIN 3/27
- Definition: one broadcast domain by configuration
- Membership: port, MAC, IP, application
- 802.1Q tag: TPID 0x8100, PCP 3, DEI 1, VID 12; VLANs 1 to 4094
- Ports: access untagged, trunk tagged, native VLAN
- Routing: router on a stick, layer 3 switch
- Design: STUDENT 10, 192.168.10.0/24; DEPARTMENT 20, 192.168.20.0/24
Chapter 4: Network layer
Network layer PIN 1/27
- Delivery: host to host across networks; data link hop to hop; transport process to process
- Functions: logical addressing, routing, forwarding, packetizing, fragmentation, internetworking, ICMP error reporting, congestion control
- Key layer: highest layer in every router, narrow waist, global addressing
- Services: datagram (IP), virtual circuit (X.25, ATM, MPLS)
Internetworking devices PIN 4/27
- Layer 1: repeater (regenerates, 2 ports, 5-4-3 rule), hub (active, passive), one collision domain
- Layer 2: bridge, switch (MAC table, collision domain per port)
- Switch modes: store-and-forward, cut-through, fragment-free (64 bytes)
- Layer 3: router (IP, routing table, broadcast domain per interface, TTL, NAT)
- Gateway: up to layer 7, protocol conversion; email, VoIP, IoT
- Switch over hub: dedicated bandwidth, no collisions, full duplex, privacy, VLANs, cost
Bridges PIN 1/27
- Steps: receive, record source MAC, filter, forward, flood, age (300 s)
- Throughput: repeater C; bridge 2C/(1+f); 100 Mbps, f 0.2: 166.7 Mbps
- Gains: two collision domains, longer LAN, bad frames dropped, mixed speeds
- Loops: STP, IEEE 802.1D, root bridge lowest ID, priority 32768
- Types: transparent, source routing, translational, remote
IPv4 addresses HOT 5/27
- Format: 32 bits, dotted decimal, network part and host part
- Classes: A 0 /8 0 to 127; B 10 /16 128 to 191; C 110 /24 192 to 223; D 1110 multicast; E 1111 reserved
- Counts: A 126 networks, 16,777,214 hosts; B 16,384, 65,534; C 2,097,152, 254
- Special: network, directed broadcast, 255.255.255.255, 0.0.0.0, 127.0.0.0/8, 169.254.0.0/16
- Private: 10/8, 172.16/12, 192.168/16; CGNAT 100.64/10
- Logical vs MAC: hierarchical, end to end, any link, assigned, location
Subnetting and VLSM TOP 24/27
- Numbers: subnets 2^s, hosts 2^h minus 2, block 256 minus mask octet
- Masks: /25 128, /26 64, /27 32, /28 16, /29 8, /30 4
- VLSM steps: AND for block, size, sort largest first, allocate from start, links /30, network, range, broadcast
- Waste: usable minus hosts per subnet; unused range after the last subnet
- Contribution: less waste, smaller broadcast domains, security, management, summarization, growth
- Traps: 2 extra addresses, aligned blocks, subnet zero (RFC 1878), /31 (RFC 3021)
CIDR and supernetting PIN 2/27
- CIDR: RFC 1519 (1993), RFC 4632; a.b.c.d/n; aligned power-of-two blocks
- Supernet rules: contiguous, power of two, aligned
- Example: 192.168.4.0 to 7.0 /24s into 192.168.4.0/22, mask 255.255.252.0
- Routing: aggregation, longest prefix match
NAT
- Types: static, dynamic, PAT (NAPT, overload)
- Table: private IP and port to public IP and port
- Costs: breaks end to end, port forwarding, P2P and IPsec AH trouble
IPv4 datagram HOT 5/27
- Header: version, IHL, TOS, total length, identification, flags, fragment offset, TTL, protocol, checksum, source, destination, options
- Sizes: header 20 to 60 bytes; datagram 65,535; IHL 5 to 15
- TTL and protocol: hop limit 64, 128, 255; 1 ICMP, 6 TCP, 17 UDP, 89 OSPF, 50 ESP, 51 AH
- Fragmentation: MTU 1,500, same ID, offset in 8 bytes, MF, DF, destination reassembles
- Max TCP payload: 65,495 = 65,535 minus 20 IP minus 20 TCP; UDP 65,507
ARP and RARP PIN 4/27
- ARP steps: cache, broadcast request, unicast reply, cache, send
- Packet: 28 bytes, EtherType 0x0806, operation 1 request, 2 reply
- Variants: gratuitous ARP, proxy ARP, ARP spoofing
- RARP: MAC to IP, RFC 903, diskless hosts; replaced by BOOTP, DHCP
- NDP: RFC 4861, ICMPv6 133 to 137, solicited-node multicast, SLAAC, DAD, SEND
ICMP HOT 5/27
- Format: type, code, checksum, rest of header; errors carry IP header plus 8 bytes
- Errors: 3 unreachable, 4 source quench, 11 time exceeded, 12 parameter problem, 5 redirect
- Queries: echo 8 and 0, timestamp 13 and 14, address mask 17 and 18, router 10 and 9
- Uses: ping, traceroute, path MTU discovery, redirect, monitoring
- No error for: ICMP errors, non-first fragments, broadcast, multicast
Routing TOP 13/27
- Routing vs forwarding: builds tables vs per-packet lookup
- Good algorithm: correctness, simplicity, robustness, stability, fairness, optimality
- Static vs dynamic: manual, fixed, secure vs automatic, adaptive, overhead
- Routed vs routing: IPv4, IPv6 vs RIP, OSPF, EIGRP, BGP
- Optimality principle: I to K through J; r1, r2; sink tree, no loops
- Autonomous system: one administration, ASN 16 or 32 bits; IGP inside, BGP between
Routing table
- Fields: destination, mask, next hop, interface, metric, source
- Classful: first octet, class, default mask, network lookup
- Classless: longest prefix match; default route 0.0.0.0/0
Dijkstra's algorithm PIN 1/27
- Steps: source 0 permanent, relabel neighbours, fix smallest tentative, repeat, trace back
- Book graph: B 2, E 4, G 5, F 6, H 8, C 9, D 10
- A to D: A, B, E, F, H, D; cost 10
Flooding
- Rule: every line except the arrival line
- Damping: hop counter, sequence numbers, selective flooding
- Uses: robustness, LSPs, broadcast, benchmark
Distance vector TOP 10/27
- Keys: whole network, neighbours only, regular intervals
- Rule: Bellman-Ford, D x of y = min over v of c(x,v) + D v of y
- Count to infinity: C 3, B 4, C 5, up to 16
- Loop prevention: max hop count, split horizon, poison reverse, route poisoning, triggered updates, hold-down
Link state TOP 11/27
- Keys: neighbourhood, to all routers, on change
- Five steps: discover, measure, build LSP, flood, compute
- Properties: full map, Dijkstra, fast convergence, cost metric, more memory, areas
- DV vs LS: table vs own links, neighbours vs all, Bellman-Ford vs Dijkstra, slow vs fast, RIP vs OSPF
Hierarchical routing
- Regions: 1A table 17 to 7 entries
- 720 routers: 720 flat, 53 two-level, 25 three-level; levels ln N
- Cost: longer paths; used in OSPF areas, AS hierarchy
Routing protocols PIN 4/27
- Why: scale, discovery, adaptation, best loop-free paths, policy
- IGP: RIP, OSPF, IS-IS, EIGRP; EGP: BGP
- Classless: RIPv2, OSPF, EIGRP, IS-IS, BGP-4; classful: RIPv1, IGRP
- IGRP: Cisco, bandwidth and delay, 90 s, 100 hops
- EIGRP: DUAL, feasible successor, partial updates, 224.0.0.10
RIP PIN 2/27
- Basics: distance vector, hop count, 15 max, 16 infinity, UDP 520
- Timers: update 30, invalid 180, hold-down 180, flush 240 seconds
- RFC timers: timeout 180, garbage collection 120
- Versions: RIPv1 RFC 1058 broadcast, RIPv2 RFC 2453 224.0.0.9, RIPng UDP 521
- Limits: 15 hops, slow, ignores bandwidth, full tables
OSPF HOT 5/27
- Basics: link state, RFC 2328, protocol 89, 224.0.0.5 and 224.0.0.6
- Packets: Hello, DBD, LSR, LSU, LSAck; hello 10 s, dead 40 s
- DR election: priority 0 to 255, default 1; router ID; no pre-emption
- States: Down, Init, 2-Way, ExStart, Exchange, Loading, Full
- Areas: area 0 backbone, ABR, ASBR; cost 10^8 / bandwidth
BGP
- Basics: BGP-4, RFC 4271, path vector, TCP 179
- Messages: open, update, keepalive, notification
- Terms: AS path, eBGP, iBGP, local preference, NPIX
Unicast and multicast PIN 3/27
- Unicast: one to one; RIP, OSPF, IS-IS, EIGRP, BGP
- Multicast: one to group, class D, one copy per link
- Membership: IGMP v1, v2 leave, v3
- Protocols: DVMRP, MOSPF, PIM-DM, PIM-SM, CBT
- Trees: source-based, shared, rendezvous point, RPF
Network design PIN 2/27
- Method: requirements, topology, devices, cabling, wireless, VLANs, servers, security
- Layers: core, distribution, access
- Campus: 500 PCs, 25 room switches, 5 distribution, core, OM3 fibre, Cat6
- Hotel: dual ISP, UTM firewall, PoE+ switches, Wi-Fi 6, VLANs, PMS, IP PBX, NVR
Chapter 5: Transport layer
Transport service HOT 5/27
- Definition: process-to-process delivery, end to end, only in hosts
- Scopes: node to node (MAC), host to host (IP), process to process (port)
- Services: addressing, segmentation, connection control, reliability, ordering, flow control, multiplexing, congestion control
- In order: handshake, numbered bytes, checksum, cumulative ACK, RTO and three duplicate ACKs, reorder buffer, FIN
- Example: 1001, 2001 lost, 3001 kept, duplicate ACK 2001, resend, ACK 4001
Services to upper layer
- Two services: connection-oriented (TCP, phone call), connectionless (UDP, letter)
- Primitives: LISTEN, CONNECT, SEND, RECEIVE, DISCONNECT; TPDU, segment, user datagram
- Berkeley sockets: SOCKET, BIND, LISTEN, ACCEPT, CONNECT, SEND, RECEIVE, CLOSE
- QoS: establishment delay, failure probability, throughput, transit delay, residual error ratio, protection, priority, resilience
UDP HOT 6/27
- Standard: RFC 768, 1980; protocol 17
- Header: source port, destination port, length (8 to 65,535), checksum; 8 bytes
- Checksum: pseudo-header (source IP, destination IP, zero, 17, length); optional IPv4, mandatory IPv6
- Features: connectionless, unreliable, unordered, message-oriented, stateless, multicast, no flow control
- Why used: no setup, timeliness, low overhead, broadcast, own reliability (DNS, TFTP, QUIC)
- Uses: DNS 53, DHCP 67/68, VoIP RTP, games, IPTV, SNMP 161, NTP 123, TFTP 69, RIP 520
TCP TOP 9/27
- Standard: RFC 9293 (2022), RFC 793 (1981); protocol 6
- Features: connection-oriented, reliable, ordered, byte stream, full duplex, point to point, piggybacking
- Header: ports, sequence, acknowledgement, HLEN, reserved, flags, window, checksum, urgent pointer, options; 20 to 60 bytes
- Flags: CWR, ECE, URG, ACK, PSH, RST, SYN, FIN
- Reliability: handshake, sequence numbers, cumulative ACK, RTO = SRTT + 4 RTTVAR, fast retransmit, checksum, windows, FIN
TCP against UDP HOT 6/27
- TCP: handshake, ACK, order, 20 to 60 bytes, windows, unicast, HTTP, SMTP, FTP, SSH
- UDP: no setup, no ACK, 8 bytes, no control, multicast, DNS, DHCP, VoIP, games
- Two transports: opposite needs, end hosts only, end-to-end principle
- One IP: hourglass waist, every router, any link, costly to change (IPv6)
- Others: SCTP, DCCP, QUIC over UDP
Ports and sockets PIN 4/27
- Port: 16 bits, 0 to 65,535, names a process
- Ranges: well-known 0 to 1023, registered 1024 to 49151, dynamic 49152 to 65535
- Common: 20/21 FTP, 22 SSH, 23 Telnet, 25 SMTP, 53 DNS, 67/68 DHCP, 80 HTTP, 443 HTTPS
- Standardize: meeting point, interoperability, URL default, firewall rules, root below 1024, no clashes
- Port 8765: URL needs :8765, plain URL refused (RST), firewall may block
- Socket: IP plus port; socket pair four-tuple; Berkeley API
Handshake and release HOT 7/27
- Open: SYN seq 8000; SYN + ACK seq 15000 ack 8001; ACK seq 8001 ack 15001
- Roles: server passive open (LISTEN) first, client active open; no listener gives RST
- Why three: both ISNs confirmed, old duplicate SYN rejected, random ISN
- Release: FIN, ACK (half-close), FIN, ACK; three segments if FIN+ACK combined
- States: FIN-WAIT-1, FIN-WAIT-2, TIME-WAIT (2 MSL), CLOSE-WAIT, LAST-ACK, CLOSING
- Attack: SYN flood, SYN cookies
Sliding window PIN 2/27
- Window: rwnd advertised in every segment; in flight at most rwnd
- Regions: acknowledged, in flight, usable, must wait
- Example: ACK 3001 rwnd 4000 gives 3001 to 7000; ACK 5001 gives 5001 to 9000
- Zero window: persist timer probes
- Refinements: silly window, Clark, Nagle, window scale 2 to the 14, min(rwnd, cwnd)
- Buffers: chained fixed-size, chained variable-size, circular per connection
Multiplexing
- Multiplexing: sockets to one IP, port headers added
- Demultiplexing: ports pick the socket
- Keys: UDP destination IP and port; TCP four-tuple
- Older sense: upward (many on one), downward (one on many, Multipath TCP, SCTP)
Congestion PIN 4/27
- Definition: load above capacity; queues, delay, drops, collapse
- Causes: arrival rate, buffer memory, bursts, slow processors, retransmissions, routing
- Policies: retransmission, out-of-order caching, ACK, flow control, timeout; VC or datagram, queueing, discard, routing, lifetime
- Open loop: retransmission, window, ACK, discard, admission, shaping
- Closed loop: backpressure, choke packets, implicit, explicit (ECN), load shedding, RED
- TCP: slow start, congestion avoidance (AIMD), fast retransmit, fast recovery
Leaky bucket HOT 5/27
- Idea: finite queue, constant output rate, overflow discarded
- Steps: arrive, full then discard, queue, one packet per tick
- Byte counting: counter n per tick, send while fits, no carry over
- Example: n 1000; 200 and 700, then 500 and 300
- Limits: packet loss, no saved credit, rigid
Token bucket TOP 9/27
- Idea: tokens at rate r up to C; packet takes token; bursts up to C
- Steps: token every delta T, full discards token, no token waits, counter
- Formula: C + rS = MS, S = C / (M minus r)
- Example: C 6 Mb, M 10 Mbps, r 2 Mbps, S 0.75 s, 12 Mb in 3 s against 6 s
- Against leaky: holds tokens, bursts, no packet loss, idle credit, fast response
- Best shaping: token bucket, leaky for peak, edge policing, TCP and ECN
Chapter 6: Application layer
Application layer and ports
- Job: messages between processes, carried by TCP or UDP
- Models: client-server, peer-to-peer
- TCP ports: HTTP 80, HTTPS 443, FTP 21 and 20, SSH 22, Telnet 23, SMTP 25 and 587, POP3 110, IMAP 143
- UDP ports: DNS 53, DHCP 67 and 68, TFTP 69, SNMP 161 and 162
HTTP and HTTPS HOT 5/27
- Nature: stateless request and response, TCP 80
- Steps: DNS, TCP handshake, request, processing, response, render, close or keep
- Messages: request line or status line, headers, blank line, body
- Methods and codes: GET, POST, HEAD, PUT, DELETE; 1xx to 5xx, 200, 301, 304, 404, 500
- Connections: non-persistent 2 RTT per object; persistent, pipelining; HTTP/1.0, 1.1, 2, 3
- HTTPS: TLS, port 443, certificate, encryption, integrity; web servers Apache, Nginx, IIS
FTP and TFTP PIN 4/27
- Connections: control port 21 for the session, data port 20 per file, out of band
- Session: 220, USER, 331, PASS, 230, PORT or PASV, RETR or STOR, 150, 226, QUIT, 221
- Modes: active (server opens from 20), passive (227, client opens)
- Traits: stateful, plain-text password; types ASCII, image; FTPS, SFTP
- TFTP: UDP 69, no login, RRQ, WRQ, DATA, ACK, ERROR, 512-byte blocks, stop and wait
- File servers: SMB 445, NFS 2049
SSH, PuTTY, WinSCP
- SSH: port 22, host key, password or key login, three layers
- Copy: SCP, SFTP over SSH; FTPS is FTP over TLS
- PuTTY: SSH, Telnet, rlogin, serial client; PuTTYgen, Pageant
- WinSCP: SFTP, SCP, FTP, two-panel drag and drop
- Insecure: Telnet 23, FTP 21
Electronic mail TOP 11/27
- Components: user agent, mail server, MTA, MDA, MAA, mailbox, queue
- Flow: UA, SMTP 587, sender's server, MX lookup, SMTP 25, mailbox, POP3 or IMAP
- SMTP: 220, HELO, MAIL FROM, RCPT TO, DATA 354, body ending ".", 250, QUIT 221; 7-bit ASCII
- POP3: port 110, authorization, transaction, update; delete or keep mode
- IMAP: port 143, mail and folders on server, state kept, partial fetch, server search
- MIME: Content-Type, Content-Transfer-Encoding; base64 3 bytes to 4 characters; quoted-printable; /9j/
DNS TOP 11/27
- Basics: distributed hierarchical database, UDP 53, RFC 1034 and 1035, TTL caching
- Servers: root (13, a to m), TLD, authoritative, local resolver
- Queries: recursive (server does the work), iterative (referrals); inverse via PTR
- Records: A, AAAA, CNAME, MX, NS, PTR, SOA, TXT; name, type, class, TTL, data
- Delegation: NS records plus glue in the parent zone
- Message: 12-byte header, ID, QR AA TC RD RA RCODE, four counts; question, answer, authority, additional
DHCP PIN 1/27
- Basics: UDP 67 and 68, lease, mask, gateway, DNS
- DORA: DISCOVER, OFFER, REQUEST, ACK; also NAK, RELEASE, DECLINE, INFORM
- Timers: T1 50 percent unicast renew, T2 87.5 percent broadcast rebind, expiry back to INIT
- States: INIT, SELECTING, REQUESTING, BOUND, RENEWING, REBINDING
- Relay: ip helper-address, gateway field
P2P applications
- Designs: central index, flooding, super peers, DHT
- BitTorrent: torrent file, tracker, swarm, seeders, leechers, rarest first, tit for tat
- DHT: Kademlia, Chord, about log N hops
- Scaling: each peer adds upload capacity
Socket programming HOT 5/27
- Types: stream TCP, datagram UDP, raw IP
- Server: socket, bind, listen, accept, recv, send, close
- Client: socket, connect, send, recv, close
- Rules: accept returns a new socket; server first, else connection refused; htons
- UDP: sendto, recvfrom
Proxy and web caching PIN 3/27
- Cache: hit, miss, conditional GET, 304 Not Modified
- Uses: speed, bandwidth, origin load, filtering, privacy, security, logging
- Kinds: forward, reverse, transparent, anonymous, distorting, high anonymity
- Formula: average time = h x hit time + (1 - h) x miss time
Server optimization
- Web: caching, CDN, compression, HTTP/2, load balancing
- Mail: backup MX, spam filtering, separate 587 and 25
- DNS: TTL caching, secondary servers, anycast, rate limits
- All: RAID, RAM, SSD, UPS, monitoring
- Availability: 99.9 percent, 8.76 hours down a year
RAID PIN 1/27
- Why: availability, performance, capacity; not a backup
- RAID 0: striping, n disks, no fault tolerance
- RAID 1: mirroring, one disk usable, survives one failure
- RAID 5: distributed parity, n minus 1, at least 3, write penalty
- Parity: XOR of the stripe
SNMP
- Parts: manager, agent, MIB, SMI, OID
- Messages: GetRequest, GetNextRequest, GetBulkRequest, SetRequest, Response, Trap, InformRequest
- Ports: UDP 161 agent, 162 traps
- Versions: v1, v2c community string, v3 security
MRTG and PRTG
- MRTG: Tobias Oetiker, Perl, SNMP octet counters, 5 minutes, four graphs
- PRTG: Paessler, Windows, sensors, alerts, free to 100 sensors
Wireshark and Packet Tracer
- Wireshark: Ethereal 1998, capture and display filters, Follow TCP Stream, TShark
- Packet Tracer: Cisco simulator, realtime and simulation modes, server services
Chapter 7: Introduction to IPv6
Why IPv6 TOP 13/27
- Definition: IETF replacement for IPv4, RFC 8200 (2017); RFC 1883 (1995), RFC 2460 (1998); version 5 taken by ST
- IPv4 problems: exhaustion, NAT, complex header, routing tables, no security, weak QoS, manual setup, broadcast, mobility
- Numbers: = 4,294,967,296; ; /64 holds
- Dates: IANA pool empty 3 February 2011; APNIC last block 15 April 2011; World IPv6 Launch 6 June 2012
- Advantages: address space, better header, extension, smaller tables, security, resource allocation, scoped multicast, SLAAC, no NAT, mobility
- IPsec: mandatory in RFC 4294 (2006), "should" since RFC 6434 (2011)
The IPv6 datagram HOT 6/27
- Fields (bits): version 4, traffic class 8, flow label 20, payload length 16, next header 8, hop limit 8, source 128, destination 128
- Total: 320 bits, 40 bytes fixed; payload up to 65,535
- Removed: IHL, identification, flags, fragment offset, header checksum, options
- Renamed: TOS to traffic class, total length to payload length, TTL to hop limit, protocol to next header
- Router work: hop limit minus 1; no checksum, no fragmenting; Packet Too Big; minimum MTU 1,280
- Book slip: flow label printed 24 bits, really 20
Extension headers PIN 1/27
- Order: hop-by-hop 0, destination options 60, routing 43, fragment 44, AH 51, ESP 50, destination options 60, upper layer
- Upper layer: TCP 6, UDP 17, ICMPv6 58; none 59
- Hop-by-hop options: Pad1, PadN, jumbo payload, router alert
- Rules: once each, destination options twice; multiples of 8 bytes; source-only fragmentation, path MTU discovery
IPv6 addresses PIN 3/27
- Notation: 8 groups of 4 hex digits; drop leading zeros; one double colon; prefix /64
- Types: unicast, anycast, multicast; no broadcast
- Unicast: global 2000::/3, link-local fe80::/10, unique local fc00::/7, loopback ::1, site-local fec0::/10 deprecated
- IPv4 inside: mapped ::ffff:a.b.c.d, NAT64 64:ff9b::/96, 6to4 2002::/16
- SLAAC: link-local, DAD, RS 133, RA 134, global address, DHCPv6 if M or O
- Interface ID: EUI-64 (FF-FE, flip bit 7) or random (RFC 7217, RFC 8981)
IPv6 multicasting
- Format: ff, flags 0RPT, scope 4 bits, group ID 112 bits
- Scopes: 1 interface, 2 link, 4 admin, 5 site, 8 organization, e global
- Groups: ff02::1 nodes, ff02::2 routers, ff02::5 OSPFv3, ff02::9 RIPng, ff02::1:2 DHCPv6
- Solicited-node: ff02::1:ff + last 24 bits; MAC 33:33 + last 32 bits
- MLD: v1 RFC 2710, v2 RFC 3810; query 130, report 131 or 143, done 132
Transition from IPv4 TOP 18/27
- Coexistence: both protocols side by side, no flag day, incompatible headers
- Dual stack: RFC 4213, two stacks, DNS A or AAAA, Happy Eyeballs, needs IPv4 addresses
- Tunnels: protocol 41; configured, 6to4 RFC 3056, ISATAP RFC 5214, 6RD RFC 5969, Teredo RFC 4380
- Formats: 6to4 2002 + IPv4; ISATAP 0000:5efe or 0200:5efe + IPv4; 6RD ISP prefix + IPv4 bits
- Translation: SIIT RFC 7915, NAT-PT historic, NAT64 + DNS64, 464XLAT, DS-Lite, MAP
- Choice: dual stack first (RFC 6180), tunnels across IPv4, translation for IPv6-only
Chapter 8: Network security
Network security and properties TOP 11/27
- Attacks: interruption, interception, modification, fabrication; passive, active, replay, denial of service
- Properties: confidentiality, integrity, authentication, non-repudiation, availability, access control
- Maintaining: policy, access control, encryption, firewall, VLANs, patching, anti-malware, IDS, backups, physical security, training
Cryptography HOT 8/27
- Terms: plaintext, ciphertext, key, cipher, cryptanalysis, Kerckhoffs
- Symmetric: one shared key, fast, n(n-1)/2 keys; DES, AES, IDEA, RC4
- Public key: key pair, slow, 2n keys; RSA, Diffie-Hellman, ElGamal, ECC
- Others: block and stream ciphers, hash (SHA-256), hybrid session key
Classical ciphers
- Substitution: Caesar, monoalphabetic, polyalphabetic, Vigenère
- Transposition: columnar, rail fence
- Book examples: k = 2 gives k co c uvwfgpv; attack gives muumbf
DES and AES PIN 4/27
- DES: 64-bit block, 56-bit key, 16 Feistel rounds, IP, swap, IP inverse
- Function f: expansion 32 to 48, XOR key, 8 S-boxes, permutation P
- Key schedule: PC-1, 28 + 28, shift 1 or 2, PC-2
- AES: 128-bit block; 10, 12, 14 rounds; Rijndael, 2001
- AES round: SubBytes, ShiftRows, MixColumns, AddRoundKey
RSA TOP 16/27
- Keys: p, q; n = pq; phi = (p-1)(q-1); gcd(e, phi) = 1; ed mod phi = 1
- Formulas: C = M^e mod n; M = C^d mod n
- Example: 7, 11, 77, 60, e 13, d 37; E 5 to 26
- Security: factoring n; 2048-bit modulus
Diffie-Hellman PIN 2/27
- Steps: N, G public; R1 = G^x; R2 = G^y; K = G^xy mod N
- Example: G 7, N 23, x 3, y 6; R1 21, R2 4, K 18
- Weakness: man in the middle; authenticated in TLS, IKE
Digital signatures HOT 5/27
- Sign: hash, encrypt digest with private key
- Verify: hash, decrypt with public key, compare
- Gives: authentication, integrity, non-repudiation; no confidentiality
- Trust: certificate, CA, PKI, X.509
PGP PIN 3/27
- Origin: Phil Zimmermann, 1991; OpenPGP
- Steps: hash, sign, compress, session key, B's public key, base64
- Services: authentication, confidentiality, compression, compatibility, segmentation
- Keys: key rings, web of trust; S/MIME
SSL and TLS PIN 3/27
- Position: between TCP and application; HTTPS port 443
- Protocols: handshake, change cipher spec, alert, record
- Handshake: hellos, certificate, pre-master secret, master secret, finished
- Record: fragment, compress, MAC, encrypt, header
- Versions: SSL 2.0, 3.0; TLS 1.0, 1.1, 1.2, 1.3 (2018)
IPsec PIN 3/27
- AH: protocol 51, authentication, integrity, no encryption
- ESP: protocol 50, encryption plus authentication
- Modes: transport host to host; tunnel gateway to gateway
- SA: SPI, destination, protocol; SAD, SPD, IKE
VPN HOT 5/27
- Idea: encrypted tunnel across the Internet
- Types: remote access; site to site, intranet, extranet
- Protocols: IPsec, SSL/TLS, OpenVPN, L2TP, WireGuard, PPTP old
- Example: Kathmandu and Pokhara offices
WEP PIN 2/27
- Design: RC4, 24-bit IV, 40 or 104-bit key, CRC-32 ICV
- Weaknesses: IV reuse, weak keys (FMS), linear CRC, static key
- Successors: WPA TKIP, WPA2 AES-CCMP, WPA3 SAE
Firewalls and ACLs TOP 13/27
- Types: packet filter, stateful, application gateway, circuit-level, NGFW
- Packet filter: header, rules top down, first match, implicit deny
- Protection: choke point, filtering, NAT, proxy, DMZ, logs
- ACL lines: deny 202.70.91.0 0.0.0.255, permit any, ip access-group in
- ACL types: standard 1 to 99 source; extended 100 to 199
Intrusion detection PIN 1/27
- Where: NIDS, HIDS
- How: signature, anomaly
- Related: IPS inline, SIEM, false positive, false negative
- Examples: Snort, Suricata, Zeek, OSSEC, Tripwire
8 chapters · 127 topics · about 65100 words
Compact chapters
Each chapter with every definition, step, formula and example kept and the teaching prose taken out. The copy button on a chapter copies all of it, formulas as LaTeX, ready to paste into Claude as context before you ask about it.
Chapter 1: Introduction to computer network 10950 words
What a computer network is, and what it is used for
Computer network: a collection of autonomous computers and other devices (nodes) interconnected by communication links and following common protocols, so that they can exchange data and share resources. Links may be copper wire, optical fibre, radio, microwave, infrared or satellite.
Autonomous is the key word (Tanenbaum): each computer can work alone; the network only lets them talk. A mainframe with dumb terminals is not a network in this sense. Two computers are interconnected when they can exchange information.
Four parts of every network:
- Nodes: end systems (hosts: laptops, phones, servers) and intermediate devices (switches, routers, access points).
- Links: transmission media: twisted pair, coaxial cable, optical fibre, radio.
- Protocols: the rules both ends follow.
- Services: what users get: the web, mail, file sharing, voice and video calls.
Three criteria judge a network: performance (throughput, delay), reliability (how often it fails, how fast it recovers), security (protection against unauthorised access and damage).
| Who | Use | What the network makes possible |
|---|---|---|
| Business | Resource sharing | many PCs share one printer, scanner, database or internet line, wherever they are |
| Business | High reliability | files replicated on two or more machines; if one fails another copy is used |
| Business | Saving money | cheap PCs as clients of a few servers replace one costly mainframe |
| Business | Scalability | add a server or PC as load grows instead of replacing the system |
| Business | Communication, e-commerce | email, video meetings, orders placed electronically |
| Home | Remote information | the web, news, online banking, exam results |
| Home | Person to person communication | chat, voice and video calls, cheaper and faster than phone calls |
| Home | Interactive entertainment | video on demand, multiplayer games, social networking |
| Home | E-commerce, online education | paying bills, sending money, shopping; online classes, notes, assignments |
| Mobile users | Anywhere access | phones and laptops on Wi-Fi or 4G: mail, web, maps, remote files, remote login |
| Society | Public services, new problems | e-government; also privacy loss, misinformation, phishing fraud, copyright disputes |
Five instances of networks in a student's day (2072 Chaitra asks exactly this):
- Paying by phone: fonepay QR at the canteen, eSewa or Khalti wallet: the app is a client of the bank's server over mobile data.
- Calling family: WhatsApp or Viber video call to a relative abroad, as IP packets (VoIP), for the price of data instead of an international call.
- Studying: online classes, notes in the class group, exam results on the exam board's website.
- Entertainment: YouTube streamed on demand; online multiplayer games whose moves must arrive within milliseconds.
- Daily services: a Pathao or inDrive ride (GPS position over mobile data); paying the NEA electricity bill online.
Memory example: a hostel kitchen: every student can cook alone (autonomous), but sharing one gas cylinder and fridge (resources) needs agreed rules (protocols); the hostel Wi-Fi shares one ISP fibre line among all rooms.
Networks by size and geography: PAN, LAN, MAN and WAN
Types of network by size: classified by the area covered: PAN around one person, LAN in a room, building or campus, MAN across a city, WAN across a country or continent; networks joined by routers form an internetwork, the Internet being the largest.
Distance decides the owner, speed, delay and error rate: a LAN is privately cabled, fast, nearly error free; a WAN uses links leased from carriers, costs more per bit and adds delay.
| Type | Span | Owner | Speed and delay | Technology | Example |
|---|---|---|---|---|---|
| PAN | about 1 to 10 m | one person | low data rate, tiny delay | Bluetooth, USB, NFC | earbuds and smartwatch paired with a phone |
| LAN | room, building or campus, up to a few km | one organisation (private) | 100 Mbps to 10 Gbps and more; very low delay and error rate | Ethernet (IEEE 802.3), Wi-Fi (IEEE 802.11) | college lab, hostel Wi-Fi |
| MAN | a city, roughly 10 to 50 km | ISP, cable operator, city body | high, usually fibre | fibre rings, Metro Ethernet, cable TV networks, WiMAX (IEEE 802.16) | an ISP's fibre ring across the Kathmandu valley |
| WAN | country or continent, hundreds to thousands of km | telecom carriers; users lease capacity | lower speed for the money, higher delay | leased lines, X.25, Frame Relay, ATM, MPLS, satellite | a bank joining its head office and branches all over Nepal |
| Internetwork | worldwide | many owners | varies | routers joining unlike networks, TCP/IP | the Internet |
WAN structure: hosts joined through a communication subnet of switching elements (routers) and transmission lines; packets travel store and forward (each router stores a whole packet, then forwards it). Hosts belong to users; the subnet usually to a carrier or ISP.
Other classifications:
- By transmission technology: broadcast (one shared channel all machines hear: classic Ethernet, Wi-Fi; an address says whom a frame is for) or point-to-point (pairs of machines; a packet may cross intermediate nodes: most WANs).
- By architecture and shape: client/server or peer to peer; bus, star, ring, mesh.
Memory example: one video call outwards: earbuds and phone (PAN), hostel Wi-Fi (LAN), ISP fibre ring across the valley (MAN), links across the border (WAN), all together (the Internet).
The 2070 Ashad question says "types of network topologies based on its size and geographical distributions": size and geography classify networks, so answer PAN, LAN, MAN, WAN (and internetwork); bus, star, ring belong to its first part.
Network topologies: bus, star, ring, mesh, tree and hybrid
Network topology: the arrangement of nodes and links. Physical topology: the actual layout of devices and cables. Logical topology: the path signals or data actually follow. They can differ: an Ethernet hub is a physical star but a logical bus (it repeats every frame out of every port); Token Ring is wired as a star into a central access unit but the token travels as a ring.
Figure: six sketches: bus with terminators, star round a switch, ring with one-way flow, five-node full mesh, tree under a root, hybrid star joined to a ring by a backbone
| Topology | How it is built | Merits | Demerits | Example |
|---|---|---|---|---|
| Bus | one backbone cable; drop lines; terminator at each end stops reflections | least cable, cheap, easy to add a node | backbone break stops all; collisions; faults hard to find; limited length and nodes | early coaxial Ethernet (10BASE5, 10BASE2) |
| Star | each node has its own link to a central hub or switch | a cut link loses one node; easy to add, remove, troubleshoot | central device is a single point of failure; more cable than bus | switched Ethernet LAN, home Wi-Fi router |
| Ring | each node joined to the next, last to first; data one way round, each node repeats it | no collisions (token gives turns); equal access; predictable delay | one break or dead node stops it (dual ring, as FDDI, survives one); adding a node breaks the ring | IEEE 802.5 Token Ring, FDDI |
| Mesh | every node joined to every other by a dedicated link | robust, no single point of failure; no shared traffic; private; easy fault isolation | cables and ports grow with the square of n: costly, bulky | core router links (partial mesh) |
| Tree | stars in a hierarchy below a root (star of stars) | grows easily; a branch can be isolated | root or backbone failure cuts off branches | campus: core, building, floor switches |
| Hybrid | two or more topologies joined | each part uses what suits it | complex to design and manage | buildings on a fibre ring, each a star |
Full mesh of nodes: one link per pair, ports a node:
Example: six office PCs: mesh cables and 5 ports a PC; star 6 cables and one 8-port switch; bus one cable with six taps. So LANs are stars, and only core routers are (partially) meshed.
Memory example: village water: bus = one pipe along the road with every house tapped (cut it and the lane is dry); star = a tank with a pipe to each house; ring = a loop main; mesh = a pipe from every house to every other.
Client/server and peer to peer: the two networking models
Networking model: how work and resources are divided among the computers. Client/server: dedicated servers provide services, clients request them. Peer to peer (P2P): every computer is an equal peer, both client and server, sharing resources directly.
Figure: left, one server above three clients (laptop browser, phone app, ATM terminal) with request arrows up and reply arrows down; right, four peers fully interconnected
Client/server architecture: each computer or process is a client or a server. A server is a powerful, always-on machine or process holding data and programs (web, mail, file, database, print server); clients are users' machines asking for services. Every exchange involves two processes, one on each machine.
How it works (request and reply):
- Server waits: the server process starts first and listens on a known address and port (web server: 80 or 443).
- Client requests: the client process sends a request message and waits.
- Server processes: reads a file, queries a database, checks a password.
- Server replies: sends the reply message back.
- Client uses the reply: shows the result; the server goes on serving others.
Example: browser (client) and web server.
Features of the client/server architecture:
- Asymmetric roles: clients start every exchange, servers only respond; many clients to one server.
- Centralised resources and data: one up-to-date copy on the server.
- Centralised administration and security: accounts, access rights, backups, updates in one place.
- Dedicated, powerful server: server hardware, network OS (Windows Server, Linux), always on.
- Scalability: clients added freely; capacity grows by upgrading or adding servers.
- Location transparency: the client needs only the server's name or address.
- Tiers: two-tier (client, database server) or three-tier (client, application server, database server), as in online banking.
Peer to peer: a P2P network forms when two or more PCs or devices connect and share resources without a separate server; each peer has equivalent capabilities and responsibilities, stores data on its own disk and shares it, so it is client and server at once.
P2P process (file sharing):
- Join: contact known peers, a tracker or a bootstrap node; in a small workgroup, announce itself on the LAN.
- Search: flood a query to neighbours, ask an index (hybrid P2P) or look up a distributed hash table.
- Connect directly to the peers holding the resource.
- Exchange: download pieces from many peers at once, upload pieces it has.
- Leave: its resources leave with it; the rest carry on.
Kinds: pure P2P (no central element: Gnutella), hybrid (central index or tracker only finds peers: Napster, BitTorrent with a tracker), the small office or home workgroup.
Examples: BitTorrent (file cut into pieces, every downloader also uploads); Windows workgroup of four PCs sharing folders and a printer; SHAREit and Nearby Share (direct Wi-Fi between phones); Bitcoin and other blockchains (every node keeps a copy of the ledger).
| Basis | Client/server | Peer to peer |
|---|---|---|
| Roles | fixed: servers serve, clients request | every peer both |
| Central server | one or more dedicated servers | none (at most an index or tracker) |
| Data | central, on the server | spread over peers' disks |
| Administration, security | central, strong | each user, weak and uneven |
| Backup | central, simple | machine by machine, often skipped |
| Cost | high: server hardware, server OS, administrator | low: ordinary PCs |
| Scalability | limited by the server | self-scaling: each peer adds capacity and demand |
| Reliability | server is a single point of failure | none, but a peer that leaves takes its files |
| Performance | fast and predictable until the server is the bottleneck | depends on peers; a popular file gets faster |
| Suited to | large networks: banks, web, mail, online services | small networks (about ten PCs), file sharing |
| Example | browser and web server; ATM and bank server | BitTorrent; home workgroup |
| Model | Advantages | Disadvantages |
|---|---|---|
| Client/server | central control of data, users, security; easy backup and recovery; one consistent copy; grows by adding servers; cheap clients | costly server, software and administrator; single point of failure; bottleneck when overloaded; traffic piles up at the server |
| Peer to peer | cheap; easy setup; no single point of failure; capacity grows as peers join | weak security, no central control or backup; data scattered and duplicated; a peer that is off takes its files; slow when shared PCs are busy |
Memory example: client/server is a restaurant (customers order, one kitchen cooks, kitchen closed means nobody eats); P2P is a class picnic where every friend brings a dish (more friends, more food, nobody in charge).
Active networking, compared with the traditional legacy network
Active network: a network whose nodes are programmable: besides carrying bits, routers and switches compute on the data flowing through them, running code supplied by users or by the packets themselves.
Legacy network is passive: a router stores and forwards (reads the header, looks up the route, sends the packet on) without touching the payload; functions fixed by the vendor; a new service (new multicast or QoS scheme) needs years of standardisation and a firmware upgrade of every router. Active networking (Tennenhouse and Wetherall, MIT, mid 1990s, funded by DARPA) puts new services into the network as programs.
Two approaches:
- Discrete (programmable switch): programs loaded into nodes beforehand, out of band, by an operator or authorised user; packets carry a header naming the program.
- Integrated (capsule): every packet (capsule) carries a small program and data; each node executes it, deciding the capsule's fate. MIT's ANTS toolkit worked this way.
Framework of an active node (DARPA active network architecture):
- NodeOS: node operating system; owns the resources (links, called channels; processor time; memory; storage), shares them among EEs, enforces security and isolation.
- Execution environments (EEs): like a virtual machine or interpreter (Java VM) running active code; several per node; a management EE lets the operator control the node.
- Active applications (AAs): user programs inside an EE giving a flow its custom service.
An arriving packet is matched to its EE by the ANEP header (Active Network Encapsulation Protocol), processed, and leaves forwarded, merged, shrunk, copied or dropped.
Figure: a legacy router (read header, look up route, forward; data never touched) beside an active node (AAs on EEs on NodeOS on hardware; a capsule with ANEP header, code and data goes up to its EE)
| Point | Legacy (passive) network | Active network |
|---|---|---|
| Node's job | store and forward by header | forward and compute on contents |
| Processing | same for every packet | customised per user, flow or packet |
| Programmed by | the vendor, in firmware | users and applications, by injecting code |
| New service | years: standardise, upgrade every router | days: load the program or send it in capsules |
| Packet | header and data | capsule: code and data (or a header naming a loaded program) |
| Intelligence | end systems only (end to end principle) | end systems and inside the network |
| Data and algorithms | fixed | mutable and fluid |
| Security, performance | simpler; fast hardware forwarding | harder: foreign code must be isolated; running it costs time |
Uses: shrink a video stream at the node nearest a slow link; cache content in the network; merge sensor readings on the way; deploy new multicast or congestion control without a standard; push firewall rules to the right node during an attack; network management by mobile agents.
Few active networks were deployed (security and performance problems of running others' code in routers); the programmable network idea lives on in SDN (a central controller programs switches) and programmable switch hardware.
The book says an active network "can be at least as secure as the legacy network" and "has faster hardware": read both as design goals; security was its hardest problem and executing code costs time.
Memory example: legacy network = postal service reading only the address; active network = a courier who obeys a note on the parcel ("if the village road is slow, send only the small photos").
Protocols, standards and interfaces
Protocol: a set of rules governing communication between two or more entities: the format and order of messages, their meaning, and the actions on sending or receiving; an agreement on how a link or conversation is established, maintained and released. Without one, the bits arrive but mean nothing.
Three key elements:
- Syntax: structure or format of the data (in an IPv4 header the first 4 bits are the version, the next 4 the header length).
- Semantics: meaning of each field and the action it calls for ("data" or "error, resend").
- Timing: when data may be sent and how fast: speed matching, sequencing, timeouts (a 100 Mbps sender swamps a 1 Mbps receiver unless the protocol prevents it).
The book: a protocol explains how the physical network is built, how computers connect, how data is formatted, how it is sent, how errors are handled.
| Protocol | Layer | What it does |
|---|---|---|
| HTTP, HTTPS | application | fetches web pages |
| SMTP, POP3, IMAP | application | sends and reads email |
| DNS | application | names to IP addresses |
| TCP | transport | reliable ordered byte stream between processes |
| UDP | transport | fast connectionless datagrams |
| IP | network (internet) | addresses and routes packets between networks |
| Ethernet (802.3), Wi-Fi (802.11) | data link, physical | frames over one link |
Human protocol: a phone call opens with "Hello" or "Namaste", turns are taken, a missed word gets "Hajur?" (resend), an agreed goodbye closes it: opening, turn taking, error recovery, release.
Standards: agreed published specifications letting different vendors' equipment work together. De jure: set by an official body. De facto: won in practice before or without approval (TCP/IP grew this way).
| Body | Full name | Known for |
|---|---|---|
| ISO | International Organization for Standardization | OSI reference model (ISO 7498) |
| ITU-T | International Telecommunication Union, Telecommunication Standardization Sector (CCITT until 1993) | X.25, V series modems, ISDN, ADSL (G.992) |
| IEEE | Institute of Electrical and Electronics Engineers | 802 LAN standards: 802.3 Ethernet, 802.11 Wi-Fi |
| IETF | Internet Engineering Task Force | Internet protocols as RFCs: IP (RFC 791), TCP (RFC 9293) |
| ANSI | American National Standards Institute | US standards, US member of ISO; FDDI |
| EIA (standards now with TIA) | Electronic Industries Alliance | EIA-232 (RS-232) serial interface |
Forums (Frame Relay Forum, ATM Forum) sped up standards; regulators license airwaves and telecom services (Nepal: Nepal Telecommunications Authority, NTA).
Protocol, service, interface:
- Protocol: horizontal: rules between peers (same layer, two machines).
- Service: vertical: what a layer offers the layer above, as primitive operations.
- Interface: boundary between adjacent layers on one machine; tells the upper layer how to reach the lower layer's services (operations, parameters, results).
- Protocol stack: list of protocols a system uses, one per layer.
Analogy: post office counter = interface; "registered delivery" = service; rules among post offices = protocol; the counter can stay while the rules change.
The book says ISO is the "International Standards Organization" and IEEE the "Institute of Electrical and Electrical Engineer"; the official names are International Organization for Standardization and Institute of Electrical and Electronics Engineers; CCITT is ITU-T since 1993.
Layered architecture: why network software is a hierarchy of layers
Layered architecture: network software as a stack of layers, each built on the one below, each offering services to the layer above while hiding how they are done; layer n on one machine talks to layer n on another by the layer n protocol.
Why: communication across different cables, radios, routers and operating systems is too big for one piece of design; layering splits it (bits on a wire, a reliable link, a route, a reliable path for programs...), each layer using only the services below.
Reasons for layering (asked in nine sittings):
- Reduces design complexity: small understandable parts, designed, built and tested separately.
- Modularity and independence: a layer changes without touching others if its service and interface stay the same (Wi-Fi to Ethernet cable, the browser never notices).
- Standardisation and interoperability: defined jobs and protocols per layer let vendors' products work together.
- Easier troubleshooting: faults located layer by layer (cable, link, route, port).
- Specialisation and reuse: teams per layer; one layer serves many users (IP carries every application over every link).
- Flexibility: new technology at one layer (fibre for copper, 5G for 4G).
Price: header overhead at every layer; repeated functions (error control at data link and transport); strict layering can cost performance.
Protocol hierarchy: networks are a series of layers; their number, names, contents and functions differ from network to network. Entities in corresponding layers on different machines are peers and talk by the layer's protocol, but no data goes directly from layer n to layer n: each layer passes data and control down until the physical medium carries it. Peer communication is virtual; only the medium carries real signals. Between adjacent layers is an interface defining the primitive operations and services offered upward.
Figure: five-layer source and destination machines; M, then H4 M, then H3 H4 M1 and H3 M2, then H2 H3 H4 M1 T2 and H2 H3 M2 T2, then bits on the medium; dashed peer arrows labelled layer 5 to layer 2 protocol
Information flow (Tanenbaum's five-layer example, in the book):
- Layer 5 produces message M and passes it to layer 4.
- Layer 4 adds header H4 (control information such as sequence numbers so the receiving layer 4 delivers pieces in order).
- Layer 3 has a packet size limit: splits M into M1 and M2, puts header H3 (addresses for routers) on each.
- Layer 2 adds header H2 and trailer T2 to each piece.
- Layer 1 transmits the bits; at the destination each layer removes its own header (and trailer) and passes the rest up; no lower header reaches layer n.
Network architecture: the set of layers and protocols; its specification gives an implementer enough detail to build each layer so it obeys the protocol; implementation details and internal interfaces are not part of it. TCP/IP and IBM's SNA are architectures; the OSI model alone is not (it names no protocols).
Design issues for the layers:
| Issue | Problem | Answer |
|---|---|---|
| Addressing | many machines, each with many processes: whom is the data for? | MAC (data link), IP (network), port (transport) addresses |
| Direction of data transfer | one way, either way in turn, both at once; how many logical channels? | simplex, half duplex, full duplex; separate data and control channels |
| Error control | physical circuits are imperfect | detecting or correcting codes; acknowledgements |
| Ordering (sequencing) | some channels reorder messages | number pieces, reorder at receiver |
| Flow control | fast sender swamps slow receiver | receiver feedback, windows, agreed rates |
| Segmentation (message size) | processes or links cannot take arbitrarily long (or short) messages | break up and reassemble; gather small ones |
| Multiplexing | a connection per pair of processes is costly | many conversations share one channel, separated at the far end |
| Routing | several paths from source to destination | choose the best route (network layer) |
Later texts group these as reliability, resource allocation (congestion, QoS), evolution and security.
Memory example: momo delivery: order in the app (application), box packed with a slip naming the buyer (transport), rider's app picks the route to Pulchowk (network), the rider rides segment by segment (data link), on the road (physical); bike or scooter, the restaurant does not care.
The book's step 4 says layer 2 adds a header and trailer to each packet "obtained from layer 2": the packets come from layer 3.
Services: connection-oriented and connectionless, and the service primitives
Service: the operations (primitives) a layer offers the layer above. Connection-oriented: set up, use, release, like a telephone call; bits come out in order like a tube; parameters (maximum message size, QoS) may be negotiated at setup; TCP, X.25 virtual circuits. Connectionless: each message (datagram) carries the full destination address and is routed independently, possibly out of order, like the post; UDP, IP.
| Service | Kind | Example |
|---|---|---|
| Reliable message stream | connection-oriented | sequence of pages |
| Reliable byte stream | connection-oriented | movie download, remote login |
| Unreliable connection | connection-oriented | digitised voice |
| Unreliable datagram | connectionless | electronic junk mail |
| Acknowledged datagram | connectionless | registered mail |
| Request and reply | connectionless | database query |
Reliable = receiver acknowledges every message; acknowledgements cost delay, so voice and video often prefer unreliable service.
Service primitives: operations a user process calls to use a service (usually system calls). Five for a simple connection-oriented service:
| Primitive | Meaning |
|---|---|
LISTEN | block waiting for an incoming connection |
CONNECT | establish a connection with a waiting peer |
RECEIVE | block waiting for an incoming message |
SEND | send a message to the peer |
DISCONNECT | terminate the connection |
Client and server use (six packets):
- Server calls LISTEN, blocks.
- Client calls CONNECT: connection request packet (1); client suspended.
- Server OS unblocks the server, sends an acceptance (2); connection up.
- Server calls RECEIVE for the first request.
- Client SENDs the request (3), then RECEIVEs; server processes and SENDs the reply (4).
- Client DISCONNECTs (5); server answers DISCONNECT (6); released.
Later editions of Tanenbaum add a sixth primitive, ACCEPT, for step 3. Berkeley sockets: listen(), connect(), accept(), send(), recv(), close().
OSI primitive classes: request (user asks, as CONNECT.request), indication (peer told of the event), response (peer answers), confirm (first user told the result); confirmed service uses all four, unconfirmed only request and indication.
Service against protocol: service = what a layer does for the layer above (vertical; the operations, not how); protocol = rules peers on different machines use to implement it (horizontal; format and meaning of packets). The protocol can change while the service stays, like rewriting a function's code without changing its calls.
Memory example: phone call = connection-oriented (dial, talk, hang up; words in order); letter = connectionless (full address on each envelope; two letters may arrive on different days).
The OSI reference model: seven layers and what each does
OSI reference model: ISO's seven-layer framework (ISO 7498, 1984) for communication between open systems (systems open to communication with others, whatever the vendor), physical at the bottom to application at the top; a reference model saying what each layer should do, not which protocols. Work began 1977; published 1984. Not a network architecture (no exact services or protocols specified); ISO's OSI protocols never caught on, the model survived as the vocabulary of networking.
Tanenbaum's five principles: a layer where a different abstraction is needed; a well-defined function per layer; functions chosen with international standard protocols in mind; boundaries that minimise information flow across interfaces; enough layers to keep distinct functions apart, few enough not to be unwieldy.
Figure: hosts A and B with seven layers each, dashed end to end peer protocols for layers 7 to 4, and two routers in the communication subnet with only layers 3 to 1, hop by hop; units APDU, PPDU, SPDU, TPDU, packet, frame, bit
Two groups: layers 1 to 3 (physical, data link, network) are network support layers, working hop by hop (host to router, router to router), run by every router; layers 5 to 7 are user support; transport joins them, and from transport up layers work end to end, only in the two hosts. The book: top three define how applications communicate; bottom four define how data travels end to end.
| Layer | Main functions | Unit | Example protocols and devices |
|---|---|---|---|
| 7 Application | window to the network for users and programs: file transfer and access, mail, directory services, remote login, network virtual terminal | message (APDU) | HTTP, FTP, SMTP, POP3, IMAP, DNS, Telnet, SSH, SNMP, DHCP |
| 6 Presentation | syntax and semantics: code translation (ASCII, EBCDIC, Unicode) and machine formats; encryption, decryption; compression | PPDU | TLS encryption, JPEG, MPEG, ASN.1 with BER, XDR, MIME |
| 5 Session | dialog control (who talks when; half or full duplex; token management); synchronisation by checkpoints (resume after a crash); open, maintain, close sessions | SPDU | NetBIOS, RPC, OSI session protocol (ISO 8327) |
| 4 Transport | process to process delivery of the whole message: port addressing; segmentation and reassembly with sequence numbers; connection control; end to end flow and error control; multiplexing | segment (TPDU) | TCP, UDP, SCTP |
| 3 Network | source to destination delivery across networks: logical (IP) addressing, routing and forwarding, fragmentation, congestion control, internetworking | packet | IP (v4, v6), ICMP, IPsec, X.25 packet layer; router |
| 2 Data link | node to node delivery of frames: framing, physical (MAC) addressing, error control (CRC, retransmission), flow control, medium access control; sublayers LLC and MAC | frame | Ethernet (802.3), Wi-Fi (802.11), HDLC, PPP, Frame Relay; switch, bridge, NIC |
| 1 Physical | raw bits over the medium: mechanical and electrical specs (connectors, pins, voltage for 0 and 1), bit timing, data rate, encoding, modulation, bit synchronisation, line configuration, topology, transmission mode | bit | RS-232, V.35, 10BASE-T, 1000BASE-T, DSL, SONET/SDH; hub, repeater, modem, cable |
Which layer does it:
| Task | Layer | Reason |
|---|---|---|
| Timing and voltage of the received signal | Physical | voltage levels, bit duration, bit synchronisation |
| Data framing | Data link | groups bits into frames with header and trailer |
| Physical identification (MAC address) | Data link | MAC addresses in the frame header |
| Error detection and correction | Data link | CRC on every link (transport also checks end to end) |
| Access to a shared channel | Data link (MAC sublayer) | decides who transmits |
| Logical identification (IP address) | Network | IP addresses identify hosts across networks |
| Routing | Network | routers forward by destination address |
| Point to point connection of sockets | Transport | socket = IP address + port; transport joins two ports end to end |
| Segmentation, port addressing | Transport | numbers segments, delivers to the right process |
| Dialog control, synchronisation | Session | who talks when, where to resume |
| Encryption, compression, code translation | Presentation | representation of data |
| File transfer, email, remote login | Application | services to users |
Significance of OSI: common vocabulary ("layer 2 switch", "layer 3 problem"); separates services, interfaces, protocols so a layer can change alone; reference for designing and comparing stacks and for multi-vendor interoperability; layer by layer troubleshooting; the standard way networking is taught.
Example, one web request from hostel Wi-Fi: HTTP request (application); TLS encryption, UTF-8 text (presentation); logged-in session kept (session); TCP segments to port 443, lost ones resent (transport); IP packets with the server's address, routed through the ISP (network); Wi-Fi frames with laptop and access point MAC addresses and CRC (data link); radio at 2.4 or 5 GHz (physical).
The book says ISO developed the model "in 1977": that is when work began; ISO 7498 was published in 1984.
The TCP/IP model: four layers and their protocols
TCP/IP model: the layered model of the Internet protocol suite, named after TCP and IP; four layers: host-to-network (network access), internet, transport, application; many texts split the lowest into data link and physical (five layers).
Origin: the ARPANET, funded by the US DoD's Advanced Research Projects Agency (ARPA); Cerf and Kahn described TCP in 1974; the ARPANET switched to TCP/IP on 1 January 1983. Goals: interconnect many different networks with universal services; connections survive the loss of intermediate routers and lines while the ends work; carry applications from file transfer to real-time speech. Protocols came first, the model was written later.
Figure: the four layers as an hourglass: application protocols on top, TCP and UDP, IP alone at the narrow waist with ICMP, IGMP, ARP, and many link technologies below
- Host-to-network (network access, link): the original model only says the host connects with some protocol so it can send IP packets; in practice framing, MAC addressing, bits on the medium (OSI data link + physical). Ethernet (802.3), Wi-Fi (802.11), PPP, DSL, Frame Relay, ATM.
- Internet: the linchpin; hosts inject packets into any network, packets travel independently, possibly by different routes and out of order (connectionless, best effort, like letters); defines the packet format and protocol IP; logical addressing and routing. IP (IPv4 RFC 791, IPv6 RFC 8200), ICMP (errors, control), IGMP (multicast groups), ARP (MAC lookup, at the boundary with the layer below).
- Transport: peer processes on the two hosts converse, as in OSI; segments and reassembles; ports name processes. TCP: reliable, connection-oriented byte stream, error free, in order, flow control (web, mail, file transfer). UDP: unreliable, connectionless, no sequencing or flow control, prompt delivery (DNS lookups, voice and video calls, games).
- Application: all higher-level protocols; no session or presentation layer (applications do that themselves). HTTP and HTTPS, SMTP, POP3, IMAP, FTP, DNS, DHCP, SNMP, Telnet, SSH.
| Layer | Protocols (well known ports) | Unit |
|---|---|---|
| Application | HTTP 80, HTTPS 443, FTP 20 and 21, SSH 22, Telnet 23, SMTP 25, DNS 53, DHCP 67 and 68, POP3 110, IMAP 143, SNMP 161 | message |
| Transport | TCP, UDP (SCTP) | segment (TCP), datagram (UDP) |
| Internet | IPv4, IPv6, ICMP, IGMP, ARP, RARP, IPsec | packet (IP datagram) |
| Host-to-network | Ethernet, Wi-Fi, PPP, DSL, Frame Relay, ATM | frame, bits |
Hourglass: many applications over two transport protocols over one internet protocol over every kind of link; IP is the narrow waist: anything carrying IP joins the Internet; any IP application runs over any link (same browser on hostel Wi-Fi, home fibre, 4G).
Four or five layers: Tanenbaum's TCP/IP model and the book use four; Kurose and Ross, and Tanenbaum's hybrid teaching model, use five (application, transport, network, data link, physical); state which one is drawn.
Memory example: a Messenger video call: app (application) to UDP (transport) to IP with the server's address (internet) to Wi-Fi frames and the ISP's fibre (host-to-network): four handovers.
The book calls UDP "an unreliable connection protocol": it is unreliable and connectionless. It expands ARPANET as "Advanced Research Project Agency": ARPA (Advanced Research Projects Agency) was the agency, ARPANET its network.
Data encapsulation: how headers and trailers are added and removed
Data encapsulation: each layer at the sender wraps the data from the layer above with its own control information, a header (and at the data link layer a trailer), forming its PDU. Decapsulation: the reverse at the receiver; each layer reads and removes its own header and trailer.
Header: control information in front of the data: addresses (MAC, IP, port), sequence and acknowledgement numbers, length, type, time to live, checksum. Trailer: after the data: the data link layer's FCS (frame check sequence, a CRC over the frame), sometimes an end marker; at the end because the CRC is computed while the frame is sent and appended last.
SDU and PDU: what a layer receives from above is its service data unit; SDU plus the layer's header (and trailer) is its protocol data unit, which is the SDU of the layer below.
Figure: sender going down (Data; TCP header + data = segment; IP header + segment = packet; frame header + packet + FCS = frame; bits) and the receiver going up removing them
Sender, five steps (the book's OSI count):
- Data: application, presentation and session layers create data from user input.
- Segment: transport adds a TCP or UDP header (source and destination ports, sequence number, checksum).
- Packet: network adds an IP header (source and destination IP addresses, time to live, protocol number).
- Frame: data link adds a frame header (destination and source MAC addresses, type) and the trailer (FCS).
- Bits: physical sends the frame as electrical, light or radio signals.
Receiver: physical turns signals into bits; data link checks the FCS (bad frame discarded), checks the destination MAC, strips header and trailer; network checks the destination IP, removes the IP header; transport uses the port to find the process, orders segments, removes its header; the application gets the original data. Each layer reads only its peer's header (headers are how peers talk).
At a router: decapsulated only up to the network layer; IP header read, next hop chosen, packet wrapped in a new frame with new MAC addresses. IP addresses stay end to end; MAC addresses change every hop.
Example: 1460-byte file chunks over Ethernet: TCP 20 bytes + IP 20 bytes = 1500 (Ethernet's maximum packet), + 14-byte Ethernet header + 4-byte FCS = 1518-byte frame; is file data.
Memory example: posting a letter: letter (data), envelope with the friend's name (transport), bag tagged with the district (network), truck with a trip sheet in front and a seal behind checked on arrival (data link header and trailer), the road (physical); each office opens only its own wrapping.
OSI and TCP/IP compared: similarities and differences
OSI against TCP/IP: OSI is a seven-layer reference model defined by ISO before its protocols existed; TCP/IP is the four-layer model of the protocols the Internet uses, described after they were built; both are layered with an end to end transport layer.
Figure: the OSI layers 7 to 1 (with OSI protocols FTAM, X.400, X.500; ISO 8823, ASN.1; ISO 8327; TP0 to TP4 (ISO 8073); CLNP, X.25 packet layer; HDLC, LAPB, LLC; X.21, RS-232, V.35) mapped by dashed lines to TCP/IP application (7, 6, 5), transport (4), internet (3), host-to-network (2, 1), with TCP/IP protocols HTTP, HTTPS, FTP, SMTP, POP3, IMAP, DNS, DHCP, SNMP, SSH, Telnet; TCP, UDP; IP, ICMP, IGMP, ARP; Ethernet, Wi-Fi, PPP, DSL, Frame Relay
Mapping: TCP/IP application = OSI application + presentation + session; transport = transport; internet = network; host-to-network = data link + physical.
Similarities:
- Both layered: stacks of independent protocols, each layer serving the one above, peers talking by protocols.
- Both have an end to end transport layer: layers up to transport give processes an end to end, network-independent transport service.
- Both have an application layer on top.
- Both have a network (internet) layer routing between networks; both use packet switching.
- Both use encapsulation.
- Both describe real networks; their layer numbers are the engineers' everyday language.
| Basis | OSI model | TCP/IP model |
|---|---|---|
| Stands for | Open Systems Interconnection | Transmission Control Protocol / Internet Protocol |
| Developed by | ISO (ISO 7498, 1984) | US DoD's ARPA for the ARPANET, 1970s; maintained by the IETF |
| Layers | 7 | 4 (5 when the lowest is split) |
| How made | model first, protocols later: general | protocols first, model later: fits only its own protocols |
| Service, interface, protocol | clearly distinguished (central idea) | not clearly distinguished |
| Network layer service | connection-oriented and connectionless | connectionless only (IP) |
| Transport layer service | connection-oriented only | both: TCP connection-oriented, UDP connectionless |
| Session, presentation | separate layers | none: left to the application |
| Data link, physical | separate layers | one host-to-network layer, barely specified |
| Replacing protocols | well hidden, replaceable | not easily replaced |
| Internetworking | not considered at first (one network per country expected) | main goal from the start |
| Use today | reference and teaching model; own protocols hardly used | the protocol suite the Internet runs on |
Why OSI's protocols lost (Tanenbaum): bad timing (arrived when TCP/IP was spreading free with Berkeley UNIX); bad technology (session and presentation nearly empty, data link and network overfull; addressing, flow and error control repeated in several layers; huge complex standards); bad implementations (large, slow, unwieldy); bad politics (seen as pushed by European telecom ministries and governments).
TCP/IP's weaknesses: service, interface and protocol not clearly separated; not general (cannot describe other stacks); host-to-network is an interface rather than a layer and does not separate physical from data link; ad hoc early protocols (Telnet) became entrenched. Modern habit: OSI model to talk about networks, TCP/IP protocols to build them.
Memory example: OSI = a syllabus a committee wrote before any class (complete, tidy, never followed to the letter); TCP/IP = the seniors' notes written after passing (shorter, messier, what everyone uses).
The book's table says internetworking "is not supported" in OSI: Tanenbaum's point is that the OSI committee did not think of internetworking at first (one network per country), and an internetworking sublayer was added to its network layer later; TCP/IP was designed for internetworking.
The Internet: a network of networks
The Internet: the worldwide network of networks interconnecting billions of devices with the TCP/IP protocol suite; nobody owns it; thousands of independently run networks agree to exchange traffic using common protocols.
History:
- 1969, ARPANET: four US nodes (UCLA, SRI, UC Santa Barbara, University of Utah), funded by ARPA; the first large packet switched network.
- 1974 to 1983, TCP/IP: Cerf and Kahn's internetworking protocol; the ARPANET adopted it on 1 January 1983.
- 1986 to 1995, NSFNET: the US National Science Foundation backbone joined universities; retired in 1995 as commercial ISPs took over.
- 1989 to 1991, the World Wide Web: Tim Berners-Lee at CERN (HTTP, HTML, URLs) brought the Internet to the public.
Structure: end systems (hosts); access networks (DSL, cable, fibre to the home, Wi-Fi, 4G, 5G); ISPs in tiers (local access ISPs buy transit from national and international ISPs, which connect to global tier 1 backbones; similar ISPs peer free); internet exchange points (IXPs) where many ISPs swap traffic directly (the Nepal Internet Exchange, NPIX, in Kathmandu keeps Nepali traffic local instead of going abroad and back); content providers' own networks with caches inside ISPs.
Governance: no central government; each network sets its own policy; only the name spaces are coordinated: IP addresses (IANA under ICANN to five regional registries; APNIC serves the Asia Pacific, Nepal included) and the DNS root (ICANN), under which .np is Nepal's country code domain; standards from the IETF as RFCs, supported by the Internet Society (ISOC).
Internet (capital I, the global one) against internet (any routed set of networks), intranet (private TCP/IP network inside one organisation, such as a campus-only portal) and extranet (part of an intranet opened to partners, such as suppliers on an order system).
Memory example: tracert (Windows) or traceroute (Linux) to a foreign website shows the hops: Wi-Fi router, ISP, across the border, the server's network: a dozen independently owned networks passing the packets.
X.25: the reliable, slow packet switched WAN
X.25: an ITU-T standard (CCITT, 1976) for the interface between a user's DTE (data terminal equipment) and the DCE (data circuit-terminating equipment) of a public packet switched network; connection-oriented, packets over virtual circuits, errors checked and corrected at every hop.
Designed for the noisy analog lines and simple terminals of the 1970s: every link and switch checks, acknowledges and retransmits; packets arrive error free and in order; price: speed (access lines typically up to 64 kbps) and per-hop delay.
Parts (the book's figure 1.9): DTE (user's terminal, computer, router); DCE (device joining the DTE to the network, usually a modem or access port); PSE (packet switching exchange: carrier switches joined by trunks; X.25 defines only the DTE to DCE interface, the PSEs talk as the carrier likes); PAD (packet assembler and disassembler for character terminals: X.3, X.28, X.29).
Figure: DTE and DCE each with packet layer (PLP), link layer (LAPB) and physical (X.21, V.24), exchanging packets, frames and bits; the modulo 8 data packet bit by bit; the packet inside a LAPB frame (flag, address, control, X.25 header, user data, FCS, flag)
| Layer | OSI | Job |
|---|---|---|
| Physical | 1 | DTE to DCE electrical interface: X.21 (digital), X.21bis and V.24 on analog modems |
| Link access (frame) | 2 | LAPB (Link Access Procedure, Balanced), a subset of HDLC: sequence numbers, CRC error detection, acknowledgement and retransmission, flow control on the DTE to DCE link |
| Packet (PLP) | 3 | sets up and clears virtual circuits, multiplexes up to 4095 on a link, numbers packets and controls flow per circuit, recovers by reset and restart |
Virtual circuits: SVC (switched) set up per call and cleared, like a phone call; PVC (permanent) set up by the carrier at subscription, always present, like a leased line, no call setup. A circuit is known on a link by a 12-bit number: 4-bit LCGN (logical channel group number) + 8-bit LCN (logical channel number): values, 0 reserved, up to 4095 circuits on one line.
Data packet, modulo 8:
| Octet | Field | Bits | Meaning |
|---|---|---|---|
| 1 | Q bit | 1 | qualifier: 1 control information for a device such as a PAD, 0 user data |
| 1 | D bit | 1 | delivery confirmation: 1 end to end acknowledgement, 0 local |
| 1 | Modulo | 2 | 01 modulo 8, 10 modulo 128; Q, D and these form the GFI |
| 1 | LCGN | 4 | logical channel group number |
| 2 | LCN | 8 | logical channel number; with LCGN the 12-bit circuit number |
| 3 | P(R) | 3 | receive sequence number: next packet expected, acknowledging those before |
| 3 | M bit | 1 | more data follows in the next packet |
| 3 | P(S) | 3 | send sequence number |
| 3 | Type | 1 | 0 = data packet (control packets end in 1, whole octet is a type code) |
| 4 on | User data | variable | up to 128 bytes by default (other sizes negotiable) |
Control packets keep octets 1 and 2; octet 3 is the type; a call request adds calling and called DTE addresses (X.121) and facilities.
| Packet (DTE to DCE / DCE to DTE) | Type octet |
|---|---|
| Call request / Incoming call | 0000 1011 |
| Call accepted / Call connected | 0000 1111 |
| Clear request / Clear indication | 0001 0011 |
| Clear confirmation | 0001 0111 |
| Receive ready (RR) | xxx0 0001 (xxx = P(R)) |
| Receive not ready (RNR) | xxx0 0101 |
| Reset request / Reset indication | 0001 1011 |
| Restart request / Restart indication | 1111 1011 |
Figure: sequence DTE A, DCE A, network (PSEs), DCE B, DTE B: call request, incoming call, call accepted, call connected; data P(S)=0 and RR P(R)=1 on each side; clear request, clear indication, clear confirmation on both sides
Virtual circuit connection, three phases:
- Call setup: DTE A picks a free channel, sends Call request with B's address; the network routes it once through the PSEs, each recording the circuit in a table; B gets Incoming call on a free channel; B answers Call accepted; A gets Call connected.
- Data transfer: data packets carry only the channel number; each PSE switches by table lookup (link 1 channel 5 to link 3 channel 9, say); P(S), P(R) number and acknowledge; window (default 2) limits outstanding packets; RR and RNR start and stop flow; in-order delivery.
- Clearing: a DTE sends Clear request; the other gets Clear indication, answers Clear confirmation; the first DTE gets Clear confirmation; channel numbers freed.
Also: interrupt (a few urgent bytes outside flow control), reset (reinitialise one circuit, sequence numbers to 0), restart (clear every circuit on the interface).
Advantages: reliable, error free, in-order delivery over poor lines; many circuits multiplexed on one line; per-circuit flow control; SVCs and PVCs; worldwide international standard; pay per data sent instead of renting a line. Disadvantages: slow (low line rates, every node stores, checks and acknowledges), high overhead and delay, unsuited to voice and video; once fibre made lines nearly error free the hop by hop checking was wasted; replaced by Frame Relay, ATM, IP and MPLS, though it ran card payment and airline reservation networks for decades.
X.25 against Frame Relay: compared on the Frame Relay card (Frame Relay keeps the virtual circuits, drops the packet layer and the error correction).
Memory example: a careful old postman checking every letter at every post office and going back for torn ones: nothing lost, slow post.
Frame Relay: fast virtual circuits at the data link layer
Frame Relay: a connection-oriented, packet switched WAN technology carrying variable-length frames over virtual circuits identified by a DLCI, using only the physical and data link layers; detects errors but does not correct them (bad frames dropped, end systems recover).
Why it replaced X.25: by the late 1980s digital and fibre lines made errors rare and end hosts ran TCP; per-hop checking was wasted; Frame Relay keeps virtual circuits, removes the packet layer and per-hop acknowledgements; a switch relays a frame once it has read the address. Standards: ITU-T I.122, Q.922; ANSI T1.618; Frame Relay Forum. Access speeds 56 or 64 kbps through 1.544 Mbps (T1) and 2.048 Mbps (E1) to 44.736 Mbps (T3).
Devices: DTEs (customer's routers, bridges, terminals, on the customer's premises) and DCEs (carrier's packet switches providing clocking and switching, moving data through the WAN).
Virtual circuits: PVC configured by the carrier, always present, steady traffic, only two states (data transfer, idle); SVC set up on demand by Q.933 signalling and cleared, occasional traffic. Many circuits share one access line (a head office needs one line, not one per branch).
DLCI (data link connection identifier): names a circuit on one link; local significance (same circuit DLCI 102 at the head office, DLCI 201 at the branch; every switch changes it); DLCI 0 carries signalling; user circuits usually 16 to 1007.
Figure: the frame (flag 8, address 16, information variable, FCS 16, flag 8); the address bits (DLCI high 6, C/R, EA 0; DLCI low 4, FECN, BECN, DE, EA 1); a carrier network of three switches joining Kathmandu HQ (DLCI 102 to Pokhara, 103 to Biratnagar), Pokhara (DLCI 201) and Biratnagar (DLCI 301)
| Field | Size | Contents |
|---|---|---|
| Flag | 8 bits | 01111110, start and end; bit stuffing keeps it unique |
| Address | 16 bits (extendable to 24 or 32) | DLCI (10 bits, split 6 and 4), C/R (command or response, for end systems), EA (0 = another octet follows, 1 = last), FECN, BECN, DE |
| Information | variable | user data such as an IP packet; no control field (no sequencing, no acknowledgement) |
| FCS | 16 bits | CRC over address and information; bad frame discarded |
| Flag | 8 bits | 01111110 |
Congestion control without flow control:
- CIR (committed information rate): rate promised on a circuit (256 kbps on a 2 Mbps line, say); bursts above it allowed when there is room.
- DE (discard eligibility): frames above the CIR get DE = 1; dropped first under congestion.
- FECN (forward explicit congestion notification): set on frames going towards the receiver through a congested switch.
- BECN (backward explicit congestion notification): set on frames going back to the sender: slow down.
- LMI (local management interface): status messages on the access line (DLCI 0 or 1023): which PVCs are active, link alive.
Operation (Kathmandu head office to Pokhara branch over a PVC):
- Encapsulate: HQ router (DTE) puts the IP packet in a frame with DLCI 102, sends it to the carrier switch (DCE).
- Check: switch checks the FCS; damaged frame discarded silently.
- Look up and relay: (incoming port, DLCI 102) to (outgoing port 3, DLCI 310), DLCI rewritten, frame relayed; every switch repeats; no acknowledgement.
- Congestion: busy switch sets FECN forward, BECN backward, drops DE frames first.
- Deliver: the last switch delivers to the Pokhara router with DLCI 201; TCP in the hosts resends any lost data.
SVC established, maintained and torn down: four operational states, Q.933 messages on DLCI 0:
Figure: calling DTE, Frame Relay network, called DTE: SETUP (called address, CIR), CALL PROCEEDING, SETUP, CONNECT, CONNECT; data frames both ways on the assigned DLCI; idle with an idle timer; DISCONNECT, RELEASE, RELEASE COMPLETE on each side
- Call setup: caller sends SETUP (called address, traffic parameters such as CIR); network answers CALL PROCEEDING and passes SETUP to the called DTE; called DTE answers CONNECT, passed back to the caller; the network tells each end its DLCI; circuit established.
- Data transfer: frames both ways on the assigned DLCI, relayed as on a PVC.
- Idle: connection active, no data; maintained (STATUS ENQUIRY and STATUS check the link); idle too long and the call can be terminated.
- Call termination: a DTE sends DISCONNECT; the network answers RELEASE; the DTE confirms RELEASE COMPLETE; the other DTE gets the same three; DLCI freed.
Advantages: higher rates than X.25; low overhead and delay; suits bursty LAN traffic (burst above CIR); many circuits on one access line (cheaper than a leased line per pair); protocol independent. Disadvantages: no error correction or guaranteed delivery; frames dropped under congestion; variable delay, poor for voice and video; now largely replaced by MPLS and Ethernet services.
| Basis | X.25 | Frame Relay |
|---|---|---|
| Layers used | physical, link (LAPB), network (packet) | physical, data link only |
| Error control | detects and corrects at every hop | detects only; bad frames dropped; ends recover |
| Flow control | hop by hop, per circuit (windows, RR/RNR) | none; FECN, BECN, DE instead |
| Acknowledgements | every hop | none |
| Speed | typically up to 64 kbps | 56 kbps to 44.736 Mbps |
| Delay, overhead | high: every node processes every packet | low: relayed once the address is read |
| Circuit number | 12-bit LCGN + LCN | 10-bit DLCI (default) |
| Multiplexing | network (packet) layer | data link layer |
| Signalling | in band (call request packets) | out of band (DLCI 0, Q.933) |
| Lines suited | noisy analog | clean digital and fibre |
| Traffic | terminal to host, low volume | LAN to LAN, bursty |
| Basis | Frame Relay | ATM |
|---|---|---|
| Unit | variable-length frame | fixed 53-byte cell (5 header, 48 payload) |
| Speed | 56 kbps to 44.736 Mbps | typically 155.52 or 622.08 Mbps (SONET/SDH), also T1 to T3 for access |
| Circuit identifier | DLCI | VPI and VCI |
| Designed for | data, bursty LAN traffic | voice, video and data together |
| Delay | variable: long frames hold up short ones | low, predictable: small fixed cells, hardware switching |
| Quality of service | CIR and DE only | CBR, VBR, ABR, UBR |
| Error check | FCS over the whole frame | HEC over the header; payload checked by the AAL |
| Overhead | about 6 bytes per frame of any size | 5 of 53 bytes (9.4%), the cell tax |
| Congestion | FECN, BECN, DE | CLP bit, congestion bit in PT, traffic contracts |
| Cost, complexity | low, simple | high, complex |
| Typical use | enterprise branch LANs | carrier backbones, broadband ISDN, DSL aggregation |
Memory example: X.25 the careful postman; Frame Relay the express courier reading only the label, throwing away soaked parcels, leaving the sender to post again: faster because checking moved to the ends.
The book says "1.544 Mbps to 44.376 Mbps" (pages 18 and 19): T3 is 44.736 Mbps (digits swapped); access also ran below T1, at 56 or 64 kbps.
ATM: fixed 53-byte cells, virtual paths and the adaptation layers
ATM (Asynchronous Transfer Mode): a connection-oriented cell switching technology (ITU-T, ATM Forum) carrying voice, video and data in fixed 53-byte cells (5-byte header, 48-byte payload) over virtual circuits named by VPI and VCI; the transfer mode chosen for broadband ISDN.
Asynchronous: a source sends a cell whenever it has data, not in a fixed own slot as in synchronous TDM; no slot wasted on idle sources. Cells not frames: small fixed cells switched in hardware at high speed; a voice cell never waits behind a 1500-byte frame: low, predictable delay.
48 bytes: compromise between the US (64 bytes, efficiency) and Europe (32 bytes, low voice delay). Filling 48 bytes with 64 kbps voice: ms.
Figure: the 53-byte cell; the UNI header bit by bit (GFC, VPI; VPI, VCI; VCI; VCI, PT, CLP; HEC); the ATM reference model (AAL with CS and SAR, ATM layer, physical with TC and PMD); a transmission path carrying two virtual paths of three channels each
| Field (UNI) | Bits | Job |
|---|---|---|
| GFC (generic flow control) | 4 | local user to network flow control (UNI only) |
| VPI (virtual path identifier) | 8 | which virtual path |
| VCI (virtual channel identifier) | 16 | which channel in the path |
| PT (payload type) | 3 | user or OAM cell; congestion experienced bit; AAL5 end of message |
| CLP (cell loss priority) | 1 | 1 = may be dropped first |
| HEC (header error control) | 8 | CRC-8 over the first four header bytes: corrects single-bit, detects most others; finds cell boundaries |
NNI (between switches): no GFC; VPI 12 bits.
Virtual paths and channels: a link (transmission path) carries virtual paths, each bundling virtual channels; VPI/VCI names a connection on each link (local, like a DLCI). VP switch (cross-connect) changes only the VPI (thousands of channels rerouted by one entry); VC switch changes both. PVCs and SVCs (Q.2931 signalling).
Reference model (planes: user, control, management):
| Layer | Sublayers | Job |
|---|---|---|
| AAL (ATM adaptation layer) | CS (convergence), SAR (segmentation and reassembly) | CS adds what the service needs (timing, sequence numbers, CRC); SAR cuts into 48-byte payloads and rebuilds |
| ATM layer | none | adds and removes the header, multiplexes cells, translates VPI/VCI, generic flow control, traffic management |
| Physical | TC (transmission convergence), PMD (physical medium dependent) | TC: HEC, cell boundaries, idle cells, SONET/SDH framing; PMD: bits on fibre or copper (155.52 Mbps OC-3/STM-1, 622.08 Mbps OC-12/STM-4) |
| AAL | Class | Used for | How it adapts |
|---|---|---|---|
| AAL1 | A: constant bit rate, timing, connection-oriented | uncompressed voice, T1/E1 emulation | 1-byte SAR header (sequence number and protection), 47 data bytes per cell |
| AAL2 | B: variable bit rate with timing | compressed voice and video, mobile voice | packs short packets of several users into one cell, each with a channel ID |
| AAL3/4 | C and D: variable rate data, no timing, connection-oriented or connectionless | data, old SMDS | 4 bytes SAR header and trailer per cell (segment type, sequence number, multiplexing ID, length, CRC-10), 44 data bytes |
| AAL5 | C and D, simple and efficient | IP over ATM, LAN emulation, signalling | no per-cell overhead: 8-byte trailer (length, CRC-32) and padding per message, 48 data bytes per cell, last cell flagged in PT |
Service categories (ATM Forum): CBR (constant: voice, video), rt-VBR (real-time variable: compressed video), nrt-VBR (non real-time variable), ABR (available bit rate: adapts), UBR (unspecified: best effort).
Example (cell tax): 1500-byte IP packet over AAL5: + 8-byte trailer = 1508, padded to 32 cells of 48 (1536, 28 bytes padding); wire: bytes; is the packet.
Advantages: very high speed; voice, video, data on one network with real QoS; low predictable delay; desktop to backbone. Disadvantages: 9.4% cell tax, complexity, cost; lost to switched Ethernet and IP over MPLS for data. Ran 1990s telephone and Internet backbones; carried ADSL traffic between home modems and the exchange.
Memory example: a supermarket shipping everything in identical 53-litre crates on a conveyor: fast, never jams, much crate per egg.
Ethernet as an example network
Ethernet: the family of wired LAN technologies standardised as IEEE 802.3, describing how devices on one segment format data into frames and put them on the medium; the most used LAN technology, now also on metropolitan and wide area links.
Invented at Xerox PARC by Robert Metcalfe and David Boggs, 1973; DIX (DEC, Intel, Xerox) Ethernet 10 Mbps, 1980, Ethernet II 1982; IEEE 802.3 in 1983. First a shared coaxial bus with CSMA/CD turn taking; now each station has its own full-duplex link to a switch (a star with no collisions; CSMA/CD no longer needed).
| Generation | IEEE standard (year) | Speed | Common media |
|---|---|---|---|
| Ethernet | 802.3 (1983) | 10 Mbps | thick and thin coax (10BASE5, 10BASE2), later twisted pair (10BASE-T, 1990) |
| Fast Ethernet | 802.3u (1995) | 100 Mbps | Category 5 (100BASE-TX), fibre |
| Gigabit | 802.3z (1998), 802.3ab (1999) | 1 Gbps | fibre; Category 5e (1000BASE-T) |
| 10 Gigabit | 802.3ae (2002), 802.3an (2006) | 10 Gbps | fibre; Category 6a (10GBASE-T) |
| 40 and 100 Gigabit | 802.3ba (2010) | 40, 100 Gbps | fibre, data centres, backbones |
| 400 Gigabit | 802.3bs (2017) | 400 Gbps | fibre, data centre and carrier links |
Name code: speed, signalling, medium: 10BASE-T (10 Mbps, baseband, twisted pair); 100BASE-TX (two pairs of Category 5); 1000BASE-T (four pairs); 10GBASE-SR (short-reach multimode fibre).
Every version keeps the frame (preamble, 48-bit destination and source MAC, type or length, 46 to 1500 data bytes, 32-bit CRC): an old card's frame is understood by a new switch. Frame, MAC addressing and access rules: chapter 3.
Why it won: cheap, simple, backward compatible, speed multiplied by ten repeatedly, switch replaced the bus without changing the frame. Metro Ethernet and Carrier Ethernet are sold as MAN and WAN services (the book: "used in LANs and MANs").
Memory example: the blue cable from the hostel router to a desktop: 1000BASE-T on Category 5e or 6, a star point to the router's switch, the same frame format since the 1980s.
VoIP: voice calls as IP packets
VoIP (voice over Internet Protocol): technologies carrying voice calls and multimedia sessions as packets over IP networks such as the Internet instead of the circuit switched PSTN; also IP telephony, Internet telephony, broadband phone.
Circuit against packet: a PSTN call reserves a 64 kbps circuit for the whole call, silences included; VoIP sends packets that share the network, avoiding PSTN tolls and costing only data.
How a call works:
- Signalling: SIP (RFC 3261: INVITE, ringing, 200 OK, ACK, BYE) or the older ITU-T H.323 finds the party and sets up the call.
- Digitise and compress: sampled 8000 times a second (telephone quality); codec G.711 (64 kbps, the PSTN's coding), G.729 (8 kbps), Opus (adaptive).
- Packetise: each 20 ms of speech in one packet with an RTP header (sequence number, timestamp), inside UDP, inside IP; UDP since a late voice packet is useless.
- Carry: like any packets; QoS routers send them first.
- Play out: jitter buffer holds packets a few tens of milliseconds to even delay, reorders by sequence number, conceals loss, decodes, plays; RTCP reports loss and delay.
Example: one G.711 call: 20 ms at 64 kbps = 160 bytes; + RTP 12 + UDP 8 + IP 20 = 200-byte packets, 50 a second: kbps each way, before the link header.
Quality: one-way delay under about 150 ms (ITU-T G.114), jitter (smoothed by the buffer), packet loss (a few percent sounds broken).
Kinds: app to app (WhatsApp, Viber, Messenger, Zoom); IP phones on an office IP-PBX; analog telephone adapter; gateways to the PSTN under a softswitch; VoLTE (VoIP inside the 4G operator network).
Advantages: cheap (international calls), one network for voice, video, data, features (video, conferencing, voicemail by email, number anywhere). Disadvantages: depends on internet and power; emergency calls hard to locate; eavesdropping, spam calls, toll fraud unless secured (SRTP, TLS).
Memory example: a Viber call to a parent working in Qatar costs a few megabytes: fifty packets a second, reassembled on the other side.
NGN: the next generation network
NGN (next generation network): a packet-based network (ITU-T Y.2001, 2004) able to provide telecommunication services using multiple broadband, QoS-enabled transport technologies, in which service functions are independent of the underlying transport; unrestricted user access to competing providers; generalised mobility.
Problem solved: an operator ran separate networks per service (circuit switches for fixed phones, a mobile core, a data network, television), each with its own equipment, staff, billing; NGN replaces them with one IP packet core for voice, video and data: convergence.
Key ideas:
- Packet transport: everything as IP packets over one core, often with MPLS for traffic engineering and QoS.
- Service separated from transport: ITU-T Y.2011's transport stratum (access and core, moving packets) and service stratum (call and session control, applications); add services without touching transport and the reverse.
- Software call control: softswitch, or IMS (IP Multimedia Subsystem, 3GPP) using SIP; media gateways to the PSTN.
- QoS-enabled broadband access: DSL, FTTH, cable, 4G, 5G into one core.
- Open interfaces: third-party services; access to competing providers.
- Generalised mobility: same services on any fixed or mobile access (fixed mobile convergence).
Four layers often drawn: access, transport (core IP/MPLS), control (softswitch, IMS), service or application.
Benefits: cheaper single network, faster new services. Challenges: telephone-grade quality and reliability over shared IP, security of an open network, working with the old network.
Memory example: a city replacing separate pipes for water, gas and drainage with one service tunnel: dig once, maintain once, add a service by laying a line in the same tunnel.
MPLS: forwarding by short labels
MPLS (Multiprotocol Label Switching): IETF technique (RFC 3031) forwarding packets along pre-established paths by short fixed-length labels instead of a destination IP lookup at every router; carries many protocols over many link types; between layers 2 and 3: "layer 2.5".
Why: an IP router does a longest-prefix match against perhaps a million routes at every hop; MPLS classifies once at the edge; inside, routers look up the label in a small exact-match table, swap it and forward; labels identify virtual paths between distant nodes (like a DLCI or VPI/VCI).
Label (shim) header, 32 bits between the layer 2 header and the IP header:
| Field | Bits | Job |
|---|---|---|
| Label | 20 | value routers look up |
| TC (traffic class, once EXP) | 3 | QoS class |
| S (bottom of stack) | 1 | 1 on the last label (labels stack) |
| TTL | 8 | time to live, loops cannot run forever |
Parts: ingress LER (label edge router) classifies packets into an FEC (forwarding equivalence class: packets treated alike, such as one prefix and class) and pushes a label; LSRs (label switching routers) swap; egress LER pops and forwards by IP; the path is an LSP (label switched path, one way). Labels agreed by LDP, RSVP-TE or BGP.
- OSPF or IS-IS learns the topology; LDP or RSVP-TE builds LSPs and label tables.
- Ingress LER classifies into an FEC, pushes label 17 (say).
- Each LSR reads only the label: 17 in, 42 out on port 2.
- Egress LER (or the router before it) pops the label, delivers the IP packet.
Uses: traffic engineering (load onto lightly used links), MPLS VPNs joining a company's branches across a carrier's shared network (replaced Frame Relay and ATM circuits), QoS by traffic class, fast reroute in tens of milliseconds. Carries IP, Ethernet, ATM, Frame Relay over T1/E1, ATM, Frame Relay, DSL or Ethernet: multiprotocol.
Memory example: a hospital token: reception reads the whole case once and gives token 17; every counter after reads only the token.
xDSL: broadband over the telephone line
DSL (digital subscriber line, originally digital subscriber loop): family of technologies (xDSL) carrying high-speed digital data over the existing copper telephone line between customer and exchange, in frequencies above the voice band, so phone and internet work at the same time.
Last mile: the local loop was built for voice (about 4 kHz), but the copper carries a few megahertz over short distances; DSL uses those for data; only the exchange to home link, never between exchanges.
How it works:
- Splitter or microfilter at home separates voice band (phone) and data band (modem).
- DSL modem at home puts data on the line.
- DSLAM (DSL access multiplexer) at the exchange ends hundreds of lines, passes traffic to the ISP.
- DMT (discrete multitone): band split into 4.3125 kHz subchannels (256 in ADSL, up to 1.104 MHz); each carries as many bits as its signal to noise ratio allows.
- Asymmetric: more bandwidth downstream (to the customer) than upstream.
| Variant | Symmetry | Typical top speed | Standard |
|---|---|---|---|
| ADSL | asymmetric | about 8 Mbps down, 1 Mbps up | ITU-T G.992.1 (1999) |
| ADSL2+ | asymmetric | about 24 Mbps down, 1 Mbps up | ITU-T G.992.5 (2003) |
| VDSL2 | asymmetric or symmetric | about 100 Mbps on loops of a few hundred metres | ITU-T G.993.2 (2006) |
| HDSL | symmetric | 1.544 or 2.048 Mbps over two or three pairs | replaced leased T1/E1 |
| SDSL | symmetric | about 2 Mbps on one pair | business lines |
Distance: speed falls as the loop lengthens (high frequencies fade in copper); ADSL to about 5 km; VDSL2's top speeds within a few hundred metres.
DSL and ISDN: both on existing copper, both need the customer near the exchange (the book: usually under 20,000 feet); DSL far faster (ISDN basic rate 144 kbps, 2B+D; DSL megabits). ADSL traffic between modem and exchange usually carried in ATM cells. FTTH has overtaken both.
Nepal: Nepal Telecom sold ADSL over its landline copper for years; most homes have moved to fibre to the home from ISPs such as Nepal Telecom, WorldLink and Vianet.
Memory example: grandfather's landline copper: voice in the bottom 4 kHz, internet in the megahertz above, split by a small box at the socket.
The book says xDSL offers "up to 32 Mbps for upstream traffic, and from 32 Kbps to over 1 Mbps for downstream traffic": directions swapped; in asymmetric DSL the large rate is downstream.
Chapter 2: Physical layer 6100 words
The physical layer: moving raw bits as signals
Physical layer: the lowest layer (layer 1) of the OSI model. It transmits a raw stream of bits over a physical medium and defines the mechanical, electrical, functional and procedural characteristics needed to activate, maintain and deactivate the physical link between two devices. It moves bits, not meaning: every frame, packet and segment finally travels as its signals.
Four kinds of rule describe a physical interface (EIA-232, ITU-T X.21):
- Mechanical: connector shape, size, pin count (RJ-45 has 8 pins).
- Electrical: voltage levels, bit duration, longest cable.
- Functional: what each pin or circuit does (transmit, receive, clock, ground).
- Procedural: the order of events to bring the link up, use it, take it down.
| Function | What it decides | Example |
|---|---|---|
| Physical characteristics | cable, connector, medium | Cat 6 UTP with RJ-45 |
| Representation of bits | encoding of 0s and 1s | Manchester code on 10 Mbps Ethernet |
| Data rate | bits per second, bit duration | 100 Mbps: a bit lasts 10 ns |
| Synchronization of bits | sender and receiver clocks agree | 7-byte Ethernet preamble |
| Line configuration | point-to-point or multipoint | leased line; old coaxial bus |
| Physical topology | how devices are wired | star, bus, ring, mesh, hybrid |
| Transmission mode | direction of flow | simplex, half-duplex, full-duplex |
| Mode | Direction | Example |
|---|---|---|
| Simplex | one way | keyboard to computer, TV broadcast |
| Half-duplex | both ways, one at a time | walkie-talkie, Ethernet on a hub |
| Full-duplex | both ways at once | telephone call, switched Ethernet |
- Bit rate vs baud rate: bit rate = baud rate x bits per symbol; 2,400 symbols a second at 4 bits a symbol (16 levels) gives 9,600 bps. Bandwidth limits the baud rate; noise limits the number of levels.
- In TCP/IP: no separate physical layer; the lowest layer (host-to-network, network access or link) covers physical and data link functions; TCP/IP defines no protocol there and runs over IEEE 802.3, 802.11, DSL. Forouzan's five-layer TCP/IP draws a separate physical layer. Same functions, different place.
- Devices: repeaters (regenerate), hubs (multiport repeaters), modems, transceivers, cables and connectors; none reads an address.
- Memory example: a laptop's network card turns each bit into voltages on the four pairs of a Cat 6 cable; on Wi-Fi the same bits leave as 2.4 or 5 GHz radio waves.
Delay, latency and throughput: measuring a network
Network monitoring: measuring how well a network carries traffic by its bandwidth, throughput, latency (delay) and jitter. Delay at every hop is the sum of processing, queuing, transmission and propagation delay.
| Measure | Meaning | Unit |
|---|---|---|
| Bandwidth | capacity: most data per second (for a signal, range of frequencies) | bps (Hz) |
| Throughput | data actually delivered successfully per second over a period | bps |
| Latency | time for data to reach the destination | s, ms |
| Jitter | variation in delay between packets of one flow | ms |
- Throughput , never above bandwidth; reduced by headers, retransmissions, collisions, congestion, slow hosts, the bottleneck link. Board calculations (2080 Bhadra, 2078 Bhadra) are in the Numericals panel: watch bytes to bits (x 8) and minutes to seconds (divide by 60).
Figure: a packet crossing router A towards router B, with processing, queuing, transmission and propagation delay marked.
| Delay | Cause | Formula | Size |
|---|---|---|---|
| Processing | header check, bit errors, output link lookup | router | microseconds |
| Queuing | waiting in the output buffer | load | 0 to ms, varies |
| Transmission | pushing L bits onto a link of rate R | µs to ms | |
| Propagation | one bit crossing length d at speed s | 5 µs per km of cable |
- Signal speed: about m/s in copper and fiber, m/s in air and space.
- Transmission vs propagation: transmission depends on packet size and link rate, not distance; propagation on distance and medium, not packet size (boarding the bus vs driving to Pokhara).
- Traffic intensity (a = packets per second): near 0 short queues; near 1 queuing delay grows sharply; above 1 queue grows without limit, packets dropped. Congestion appears here.
- Latency = propagation + transmission + queuing + processing, over every hop. RTT: there and back, as ping reports.
- Bandwidth-delay product : bits in flight on the link; sizes sliding windows.
- Worked example: 1,500-byte packet (12,000 bits) at 10 Mbps. Over 2 km of fiber: = 1.2 ms, = 10 µs (transmission dominates). Over a GEO hop (35,786 km up and down, m/s): about 238.6 ms (propagation dominates); bandwidth-delay product about 2.39 million bits, about 199 packets in flight.
- Causes of packet delay: router processing; congestion (queues, loss); slow links and big packets; distance and medium; number of hops (store-and-forward); retransmissions after errors or loss, flow and congestion control; slow end systems.
- Jitter: packets sent 20 ms apart arriving 15, 30, 18 ms apart; evened out by a jitter (playout) buffer.
- The book: defines total latency as one-way there plus one-way back, which is the RTT; latency usually means one-way (Forouzan: propagation + transmission + queuing + processing).
Bandwidth and channel capacity: Nyquist and Shannon
Channel capacity: the highest data rate a channel can carry; Nyquist limit for a noiseless channel, Shannon limit for a noisy one.
- Bandwidth: for a signal, the width of the frequency range in hertz (voice channel 300 to 3,400 Hz, about 3.1 kHz, 4 kHz with guard bands); for a link, the bit rate in bps.
- Nyquist (1924), noiseless channel, L signal levels: at most 2B signal changes a second.
- Nyquist example: 3 kHz channel: 2 levels give 6 kbps; 16 levels give 24 kbps.
- Shannon (1948), noisy channel, SNR as a plain power ratio:
- Decibels: ; 10 dB = 10, 20 dB = 100, 30 dB = 1000. Convert dB to a ratio before Shannon.
- Shannon example: telephone line, B = 3,000 Hz, SNR 30 dB: , about 29.9 kbps; dial-up modems stopped near 33.6 kbps.
- Both together: B = 2 MHz, SNR = 255: Shannon 16 Mbps; choose 12 Mbps; Nyquist gives , L = 8 levels.
| Impairment | What happens | Example |
|---|---|---|
| Attenuation | power lost with distance, in dB | amplifiers or repeaters every few km |
| Distortion | frequency components travel at different speeds | pulses spreading |
| Noise | thermal, induced, crosstalk, impulse | hiss on a phone line |
- Loss in dB: ; half the power is about 3 dB.
- 2066 Bhadra: 2 mW and 200 µW: SNR = 10 (10 dB); , about 1.04 Gbps (Numericals panel).
- Calculator: .
Transmission media: the kinds, and how to choose one
Transmission medium: the physical path between a transmitter and a receiver that carries the signal (electric current, light, electromagnetic waves); below the physical layer, controlled by it; guided (wired) or unguided (wireless).
Figure: tree of transmission media: guided (twisted pair UTP and STP, coaxial, optical fiber) and unguided (radio 3 kHz to 1 GHz, microwave 1 to 300 GHz terrestrial and satellite, infrared 300 GHz to 400 THz).
| Point | Guided | Unguided |
|---|---|---|
| Signal path | along a cable | from an antenna through air or space |
| Examples | twisted pair, coaxial, fiber | radio, microwave, infrared |
| Data rate | high, terabits on fiber | lower, shared |
| Security | must be tapped physically | anyone in range can receive |
| Interference | low; none on fiber | weather, obstacles, transmitters |
| Mobility | none | free |
| Installation | cable laid; costly over hills and rivers | towers and antennas |
| Cost with distance | grows with length | almost independent (satellite) |
| Factor | Question | Who wins |
|---|---|---|
| Bandwidth, data rate | bits per second now and later | fiber, coaxial, twisted pair |
| Distance, attenuation | how far before a repeater | single mode fiber (tens of km); UTP Ethernet 100 m |
| Cost | cable, equipment, labour, upkeep | UTP cheapest; fiber optics and satellite dearest |
| Noise immunity | motors, power lines, lightning | fiber immune; STP and coaxial beat UTP |
| Security | tapped unnoticed? | fiber hardest; radio easiest |
| Installation | flexibility, weight, skills | UTP easy; fiber needs splicing |
| Environment, terrain | outdoor, river, ridge | microwave or satellite |
| Mobility | users move? | only wireless |
- Also: reliability, scalability, regulation (spectrum licence).
- Campus example: labs within 90 m: Cat 6 UTP; 400 m library link: multimode fiber (1000BASE-SX 550 m on OM2; avoids lightning on copper); hostel across a river: microwave or Wi-Fi bridge; canteen: Wi-Fi; ISP: single mode fiber.
- One line each: twisted pair cheap, noisy, short; coaxial better shielding, bulky; fiber huge bandwidth, EMI immune, costly; radio through walls, low rate; microwave high rate, line of sight, rain fade; infrared private to a room, blocked by walls.
Twisted pair and coaxial cable, compared with fiber
Guided media: cables carrying the signal on a solid path: twisted pair and coaxial carry current in copper, optical fiber carries light in glass.
Figure: cross sections of a four pair UTP cable, a coaxial cable (conductor, insulation, braid, jacket) and an optical fiber (core, cladding, buffer, jacket).
- Twisted pair: two insulated copper conductors, about half a millimetre (22 to 26 AWG), twisted; four pairs per LAN cable, one or two per telephone drop; cheapest, most used.
- Why twist: noise induces nearly equal voltages in both wires; the receiver reads the difference, so noise cancels; different twist rates cut crosstalk.
| Type | Construction | Merits | Demerits | Use |
|---|---|---|---|---|
| UTP | no shield | cheap, thin, flexible | EMI, crosstalk | office LANs, phone lines |
| STP | grounded foil or braid | less EMI, higher rates | costly, stiff, needs ground | factories, near power cables |
- Shield names (ISO/IEC 11801): U/UTP, F/UTP (foil around all pairs), U/FTP (foil per pair), S/FTP (braid plus foil per pair).
| Category | Bandwidth | Use |
|---|---|---|
| Cat 3 | 16 MHz | telephone, 10BASE-T |
| Cat 5 | 100 MHz | 100BASE-TX |
| Cat 5e | 100 MHz | 1000BASE-T |
| Cat 6 | 250 MHz | 1 Gbps; 10 Gbps to about 55 m |
| Cat 6A | 500 MHz | 10GBASE-T to 100 m |
| Cat 7 (class F) | 600 MHz | shielded 10 Gbps |
| Cat 8 | 2000 MHz | 25 and 40 Gbps to 30 m |
- Wiring (T568A, T568B): straight-through (same order both ends: PC to switch); crossover (A one end, B the other: PC to PC, switch to switch; auto-MDIX does it automatically); rollover (fully reversed: PC to router console).
- Characteristics (book): analog amplifiers every 5 to 6 km, digital repeaters every 2 to 3 km; Ethernet over UTP 100 m (90 m fixed plus patch cords).
- Uses: local loop, DSL, Ethernet LANs, Power over Ethernet. Merits: cheapest, flexible, easy. Demerits: noise, crosstalk, short range, less bandwidth, easy to tap.
- Coaxial cable: central copper conductor, insulation (dielectric), braided or foil outer conductor (return path and shield), plastic jacket; one shared axis; up to about 1 GHz. 5 to 7 mm (RG-58, RG-6); trunk cables 1 to 2.5 cm (book).
- Grades: RG-59, RG-6 (75 ohm) cable TV, CCTV; RG-58 (50 ohm) thin Ethernet 10BASE2; RG-8 (50 ohm) thick Ethernet 10BASE5. Connectors BNC, F-type, N-type.
- Coaxial uses: cable TV and internet, CCTV, antenna leads; once trunks and early Ethernet. Merits: bandwidth, noise immunity, longer runs. Demerits: thick, stiff, dearer; one fault downs a shared bus; amplifiers every few km.
| Point | Twisted pair | Coaxial | Optical fiber |
|---|---|---|---|
| Signal | electrical | electrical | light |
| Bandwidth | 16 MHz to 2 GHz by category | up to about 1 GHz | terahertz range |
| Data rate | 10 Mbps to 10 Gbps (40 on Cat 8) | 10 Mbps to a few Gbps | 10 Gbps a wavelength, terabits with WDM |
| Distance | 100 m Ethernet | hundreds of m to a few km | km (multimode), tens of km (single mode) |
| Noise immunity | low | good | complete |
| Attenuation | high | moderate | about 0.2 dB/km at 1550 nm |
| Power loss (book) | conduction, radiation | conduction | absorption, scattering, dispersion, bending |
| Security | easy to tap | harder | very hard |
| Cost | cheapest | moderate | highest |
| Installation | easiest | moderate | skilled splicing |
| Use | LANs, phone loops | cable TV, CCTV | backbones, FTTH, submarine |
- Memory example: one hostel: Cat 6 UTP to the floor switch, coaxial from the rooftop dish, fiber from the ISP; a lab 160 m away needs a switch half way or fiber.
Optical fiber: light in glass
Optical fiber: a thin strand of pure glass (or plastic) carrying information as pulses of light, kept in by total internal reflection at the boundary between a higher-index core and a lower-index cladding.
- Structure: core (8 to 10 µm single mode; 50 or 62.5 µm multimode), cladding (125 µm, lower index), buffer coating (250 µm), strength members (Kevlar), jacket.
- Total internal reflection: light from denser core () to rarer cladding () bends away from the normal; beyond the critical angle it is reflected back, at every bounce.
- Example: = 1.48, = 1.46: critical angle about 80.6 degrees; NA about 0.243; acceptance about 14 degrees from the axis.
Figure: three fibers with a sharp input pulse: step index spreads it most, graded index less, single mode keeps its shape.
| Mode | Core | Light path | Source | Reach, use |
|---|---|---|---|---|
| Multimode step index | 50 µm or more, uniform index | many bounce angles; modal dispersion | LED | shortest; old LANs, plastic fiber |
| Multimode graded index | 50 or 62.5 µm, index falls outward | curved rays, arrivals bunch | LED or VCSEL | about 550 m at 1 Gbps; building backbones |
| Single mode | 8 to 10 µm | one ray on the axis, no modal dispersion | laser diode | tens of km; backbones, FTTH, submarine |
- Sources: LED (cheap, long life, wide temperature range, incoherent, low power, short multimode); injection laser diode (coherent, narrow spectrum, high power, fast, long single mode).
- Detectors: PIN photodiode (simple, cheap); avalanche photodiode APD (gain, sensitive, long links).
- Windows: 850 nm (multimode), 1310 nm (least dispersion), 1550 nm (lowest loss, about 0.2 dB/km; EDFA, DWDM). : about 353, 229, 193 THz; near infrared, 190 to 355 THz, 650 to 1,200 times the top of the RF range (300 GHz). Radio-over-fiber carries RF signals to antenna sites.
Figure: generic optical fiber system as a U: message source, electrical transmitter, optical source (LED, laser), fiber with repeater or optical amplifier, optical detector (PIN, APD), electrical receiver, destination.
- Message source: electrical signal.
- Electrical transmitter: code, modulate, drive.
- Optical source: current to light.
- Fiber cable: connectors, splices; repeaters or EDFAs on long links.
- Optical detector: light to current.
- Electrical receiver: amplify, equalize, regenerate, decode.
- Destination.
- Advantages: very high bandwidth; low attenuation (repeaters tens of km apart); immune to EMI and lightning; no crosstalk; hard to tap; thin, light; no sparks or shock; no corrosion; long life.
- Disadvantages: costly install, termination, test; fragile, bend radius; splicing skill; one way, so two fibers or wavelengths for duplex; no power to devices.
- FTTH example: single mode fiber from the ISP to a passive splitter shared by many houses; the ONT in each house is detector and receiver (WorldLink, Vianet).
- The book: 2 to 5 km multimode, 25 km single mode; reach depends on rate and optics: 1 Gbps multimode about 550 m; single mode 10 km, 40 to 80 km with long-reach optics.
Unguided media: radio, microwave, infrared and how waves travel
Unguided (wireless) media: carry electromagnetic waves through air, water or space without a conductor; an antenna radiates, another collects.
- Antennas: omnidirectional (radio mast, Wi-Fi access point) or directional (parabolic dish, horn).
| Medium | Frequency | Direction | Properties | Uses |
|---|---|---|---|---|
| Radio waves | 3 kHz to 1 GHz | omnidirectional | far, through walls; low rate; crowded, licensed | AM, FM, TV, cordless phones, paging |
| Microwaves | 1 to 300 GHz | directional, line of sight | high rate; aligned antennas; rain fade above about 10 GHz | terrestrial links, satellite, cellular, Wi-Fi 2.4, 5, 6 GHz |
| Infrared | 300 GHz to 400 THz | line of sight, short | cannot pass walls; sunlight interferes | remotes, short device links |
- Terrestrial microwave (book): 4 to 6 GHz and 21 to 23 GHz between dishes on towers or hills; repeaters farther apart than coaxial; across rivers and mountains.
Figure: three panels: ground wave hugging the earth, sky wave bent back by the ionosphere, line of sight between two towers.
| Method | Frequency | How | Uses |
|---|---|---|---|
| Ground wave | below 2 MHz | follows the earth's curvature; range by power | AM medium wave, navigation beacons |
| Sky wave | 2 to 30 MHz | bent back by the ionosphere; long range, low power; day and night differ | shortwave, amateur radio |
| Line of sight | above 30 MHz | straight line; antennas must see each other | FM, TV, microwave, mobile, satellite |
- LOS paths: direct wave; ground-reflected wave (with the direct wave forms the space wave; can add or cancel: multipath fading).
- Radio vs optical horizon (K = 4/3, h in metres):
- Two antennas: km; two 50 m towers: 29.2 km each, about 58 km apart; towers stand on hilltops.
- LOS impairments: free-space loss, rain and water vapour absorption (above about 10 GHz), multipath, refraction, obstacles.
- Wi-Fi, Bluetooth, mobile: microwave ISM bands 2.4 and 5 GHz (MAC in chapter 3, security in chapter 8).
- Memory example: AM heard beyond hills, farther at night; FM fades behind a ridge; TV remote blocked by a person.
Satellite communication
Communication satellite: a microwave relay station in orbit; earth station uplink, transponder amplifies and shifts frequency, downlink to earth stations.
- Transponder: receiver and transmitter; amplification and frequency translation; many per satellite.
- Uplink above downlink: C band about 6 GHz up, 4 GHz down; Ku band about 14 GHz up, 11 to 12 GHz down; separate frequencies keep the strong outgoing signal off the weak incoming one; the earth station affords more power for the fading higher frequency.
| Orbit | Altitude | Period | Features | Example |
|---|---|---|---|---|
| LEO | about 500 to 2,000 km | about 90 to 120 min | few ms delay, small footprint, many satellites | Starlink, Iridium |
| MEO | about 2,000 km to GEO height | hours (GPS about 12 h) | navigation | GPS at about 20,200 km |
| GEO | 35,786 km over the equator | 23 h 56 min 4 s | fixed in the sky; three cover the earth but the poles; long delay | DTH TV, VSAT |
- GEO delay: 2 x 35,786 = 71,572 km at m/s, about 0.239 s; a reply about 0.48 s. LEO at 550 km: about 3.7 ms.
- Bands (IEEE, book Table 2.2): L 1 to 2, S 2 to 4, C 4 to 8, X 8 to 12, Ku 12 to 18, K 18 to 27, Ka 27 to 40, V 40 to 75, W 75 to 110 GHz. L: GPS, satellite phones; C: TV distribution, least rain fade; Ku: DTH, VSAT; Ka: broadband.
- Merits: huge coverage, cost independent of distance, broadcast, remote reach. Demerits: GEO delay, build and launch cost, life about 12 to 15 years (book), rain fade in Ku and Ka, station keeping.
- Other kinds (book): astronomical, biosatellites, communication, earth observation, navigation, killer satellites.
- Memory example: DTH dishes in Kathmandu point south and never move.
- The book: LEO 500 to 1,500 km, MEO 5,000 to 15,000 km, yet names GPS (about 20,200 km) as MEO; usual bounds: LEO to about 2,000 km, MEO up to GEO height.
Multiplexing: many signals on one link
Multiplexing: techniques that let several signals share one link at the same time; a MUX combines n inputs into one link, a DEMUX separates them onto n outputs.
- Importance: efficiency (one fiber carries thousands of calls); lower cost (one cable, less installation and upkeep); makes trunks, broadcasting, cable TV, mobile networks and backbones possible; scalability. Like one bus instead of forty taxis.
Figure: three senders A, B, C sharing a link four ways: FDM bands with guard bands, synchronous TDM frames with empty slots, statistical TDM frames with addressed slots, CDM with codes.
- FDM: analog; bandwidth split into bands, one carrier each, guard bands between, all at once. Uses: AM 530 to 1700 kHz, FM 88 to 108 MHz, TV, 1G mobile, cable TV; old analog telephony put 12 voice channels of 4 kHz in a 48 kHz group.
- WDM: FDM for light; one wavelength per signal; prism or grating; DWDM: dozens of wavelengths 0.8 nm (100 GHz) apart near 1550 nm, 10 to 100 Gbps each.
- TDM: digital; time slots used in turn, a round of slots is a frame with framing bits; link rate n times an input's rate.
- Synchronous TDM: fixed slot per input every frame, idle slots wasted (T1, E1).
- Statistical TDM: slots only to inputs with data, fewer slots than inputs, each slot carries an address, buffers absorb bursts; for bursty data.
- Worked example: four 64 kbps inputs, one byte per slot, one framing bit: 8,000 frames a second (125 µs); frame 33 bits; 264 kbps; slot about 30.3 µs. With 24 inputs: T1, 193 bits, 1.544 Mbps.
- CDM (CDMA): all send at once over the whole band; data times an orthogonal chip code (inner product of different codes zero); receiver multiplies by one code. 3G (CDMA2000, W-CDMA), GPS.
- CDMA example: a = (+1, +1), b = (+1, -1); A sends 1 (+1), B sends 0 (-1); channel (0, +2); A recovers (0 + 2)/2 = +1, B recovers (0 - 2)/2 = -1.
| Point | FDM | WDM | TDM | CDM |
|---|---|---|---|---|
| Shares | frequency | wavelength | time | codes |
| Signal | analog | optical | digital | digital |
| Kept apart by | guard bands | wavelength spacing | framing, slot position | orthogonal codes |
| Example | FM, cable TV | fiber backbones | T1, E1, GSM | 3G CDMA, GPS |
- Versus switching: multiplexing shares one link; switching chooses the path.
- Memory example: Kathmandu FM stations each on their own frequency between 88 and 108 MHz (FDM); a call in one 64 kbps slot of an E1 trunk (TDM).
Switching: circuit, message and packet
Switching: connecting a sender to a receiver through intermediate nodes (switches) instead of a link between every pair; a switch forwards from an input port (ingress) to the output port (egress) towards the destination.
- Why: a mesh of n devices needs links; 1,000 phones would need 499,500 lines.
- Techniques (book Fig 2.18): circuit, message, packet (datagram, virtual circuit); inside a switch, circuits are made by space or time division.
Figure: one message from A to D through B and C, time downward: circuit (request, accept, one stream, release), message (stored whole at each node, arrives last), packet (three packets pipelined, arrives first).
- Circuit switching: a dedicated end-to-end path reserved before data and held for the session; one channel (FDM band or TDM slot) per link. Phases: setup (request hop by hop, reserve, accept), data transfer (continuous, no addresses, no store-and-forward, no queuing), teardown (release frees channels). Example: PSTN call.
- Message switching: no setup or reserved path; whole message with destination address stored at each node (on disk) and forwarded when the link is free; store-and-forward network. Drawbacks (book): storage for the largest message, delays add hop by hop, useless for real time. Telegraph, telex; replaced by packet switching.
- Packet switching: message cut into limited-size packets with headers (addresses, sequence number); store and forward per packet; links shared, capacity used only with data (statistical multiplexing); pipelining makes it faster than message switching. Forms: datagram and virtual circuit. Example: the internet.
- Worked example: 1 Mbit over 3 links of 1 Mbps: message switching 3 s; 1,000 packets of 1 kbit: 1 + 2 x 0.001 = 1.002 s. In general message , packet .
| Point | Circuit switching | Packet switching |
|---|---|---|
| Path | dedicated for the session | none; links shared |
| Setup | needed | none (datagram) |
| Bandwidth | fixed, reserved | dynamic, on demand |
| Idle capacity | wasted | used by others |
| Transfer | continuous, no store-and-forward | store-and-forward per node |
| Addressing | only at setup | header on every packet |
| Delay | setup, then constant | no setup; variable queuing |
| Order | in order | may be out of order |
| Congestion | at setup (busy tone) | per packet (queuing, loss) |
| Switch fails | call cut | packets rerouted |
| Charging | time and distance | data volume |
| Suits | real-time voice | bursty data |
| Example | PSTN | the internet |
- Circuit switching suits real time: guaranteed reserved bandwidth (no competition, no congestion once up); constant low delay, no jitter (no queuing, no store-and-forward; ITU-T G.114: one-way delay under 150 ms); in-order delivery on one path; no per-packet overhead or buffer loss; setup paid once. VoIP needs priorities, jitter buffers and spare capacity to approach this.
| Point | Switching | Multiplexing |
|---|---|---|
| Purpose | connects sender to receiver | shares one link among signals |
| Where | nodes inside the network | two ends of a link |
| Device | switch, router, exchange | MUX, DEMUX |
| Kinds | circuit, message, packet | FDM, WDM, TDM, CDM |
| Example | exchange connecting a call to Pokhara | E1 trunk with 30 calls |
- Together: a circuit-switched call is one time slot of a multiplexed trunk on every link.
- Modern networks: packet switching: IP routers (datagrams by destination address); MPLS in ISP backbones (virtual circuits with labels); Ethernet switches by MAC address, store-and-forward or cut-through. Circuit switching only in legacy telephony; voice now VoIP, VoLTE.
- Memory example: landline call to Pokhara holds a path (circuit); Viber voice message shares links (packet); festival morning busy tone: no free circuit.
Datagram and virtual circuit: two ways to switch packets
Datagram and virtual circuit: the two forms of packet switching. Datagram (connectionless): each packet carries the full destination address and is routed on its own. Virtual circuit (connection-oriented): a path set up first, every packet follows it with a short VCI.
Figure: two networks of routers R1 to R4 between hosts A and B: datagram packets 1 and 3 on the upper path, 2 and 4 on the lower, arriving 2, 1, 4, 3, header with destination, source, sequence; virtual circuit path A, R1, R2, R4, B with VCIs 12, 25, 7, 31 and R2's table (from R1, 25 to R4, 7).
- Datagram (book Fig 2.21): header with full source and destination address plus payload; routing table lookup per packet; no connection state; packets may take different paths, arrive out of order, be lost or duplicated; TCP reorders. IP.
- Virtual circuit (book Figs 2.22, 2.23): circuit's phases, datagram's packets.
- Setup: request with full destination address; each switch picks the next hop and writes in port, in VCI, out port, out VCI; acknowledgment returns; resources can be reserved.
- Data transfer: packets carry only the VCI; lookup (in port, in VCI), replace VCI (label swapping), send out; one path, in order.
- Teardown: release removes the entries.
- VCI: local meaning on one link only; small; reused.
| Network | VCI name | Size |
|---|---|---|
| X.25 | logical channel number | 12 bits |
| Frame Relay | DLCI | 10 bits (default) |
| ATM | VPI and VCI | 8 or 12 bits, and 16 bits |
| MPLS | label | 20 bits |
- PVC: set up in advance by the operator, like a leased line. SVC: set up on demand by signalling, torn down after, like a phone call.
| Issue | Datagram | Virtual circuit |
|---|---|---|
| Setup | not needed | needed |
| Addressing | full source and destination | short VC number |
| State | none per connection | table space per VC in every switch |
| Routing | each packet independently | at setup; all packets follow |
| Router failure | only packets in it lost | all VCs through it terminated |
| Order | may be out of order | in order |
| QoS | difficult | easy with reserved resources |
| Congestion control | difficult | easy with reserved resources |
| Header overhead | large | small |
| Examples | IP | X.25, Frame Relay, ATM, MPLS |
- Frame Relay (2081 Bhadra): a virtual circuit network; 10-bit DLCI in the address field; switches look up (in port, DLCI) and swap it; mostly PVCs by the carrier, SVCs by Q.933; frames in order; only CRC check and discard, recovery left to end systems; congestion bits FECN, BECN, DE. A datagram network (IP) would route each packet by full address with no setup or per-circuit state.
- 2078 Bhadra "packet switching vs virtual circuit": packet switching means datagram. 2070 Ashad prints "virus circuit switching": virtual circuit switching.
- Memory example: datagrams are taxis (full address, own road, either order); a virtual circuit is a bus route (fixed first, short route number).
The telephone network, and the T1 and E1 hierarchy
Telephone: an instrument turning speech into an electrical signal and back. PSTN: the worldwide circuit-switched network of telephones, local loops, exchanges and trunks.
| Part | Job |
|---|---|
| Transmitter (microphone) | sound to varying current |
| Receiver (earpiece) | current to sound |
| Hook switch | off-hook asks for service; on-hook ends the call |
| Dialler | pulses (rotary) or DTMF: one tone from 697 to 941 Hz, one from 1209 to 1477 Hz |
| Ringer | rings on ringing current |
| Hybrid (induction coil) | two-wire line to four-wire handset; sidetone |
- Bell's patent: 1876. Line power: about 48 V DC from the exchange; works without house electricity.
Figure: telephone network hierarchy: phones on local loops to end offices, end offices to toll offices, toll offices to a regional office; a call from Kathmandu (01) to Pokhara (061) through two toll offices.
- Local loop: twisted pair from subscriber to end office (local exchange), 300 to 3,400 Hz, the last analog part.
- Switching offices: end offices (own subscribers), tandem offices (end offices of one area), toll offices (long distance); AT&T classes: regional centre (1), sectional (2), primary (3), toll (4), end office (5).
- Trunks: multiplexed high-capacity links; once FDM, now TDM (E1, T1) over fiber.
- Numbering: country code, area code, subscriber number; Nepal +977, Kathmandu 01, Pokhara 061.
- Off-hook: loop closes, end office detects current.
- Dial tone: exchange ready.
- Dialling: DTMF tones or pulses stored.
- Switching: local call inside the end office; otherwise a trunk to tandem or toll office; SS7 sets up the circuit hop by hop.
- Ringing: free line rings, caller hears ringback; else busy tone.
- Answer and conversation: analog on loops, 64 kbps PCM in a time slot on each trunk.
- Hang up: channels released, call recorded for billing (time and distance).
- Basic channel: voice sampled 8,000 times a second (Nyquist for 4 kHz) x 8 bits = 64 kbps (DS0, E0).
- T1 (North America, Japan): 24 channels; frame 24 x 8 + 1 = 193 bits; 193 x 8,000 = 1.544 Mbps (1,536 kbps voice + 8 kbps framing).
| Service | Line | Rate | Voice channels |
|---|---|---|---|
| DS-1 | T-1 | 1.544 Mbps | 24 |
| DS-2 | T-2 | 6.312 Mbps | 96 |
| DS-3 | T-3 | 44.736 Mbps | 672 |
| DS-4 | T-4 | 274.176 Mbps | 4032 |
Figure: E1 frame of 32 slots (TS0 alignment, TS16 signalling, 30 voice) and the ladder E0 64 kbps, E1 2.048, E2 8.448, E3 34.368, E4 139.264 Mbps.
- E1 (ITU-T; Europe, most of the world, Nepal and India): 32 slots TS0 to TS31 of 8 bits = 256 bits, 8,000 frames a second (125 µs). TS0: frame alignment, alarms, messages (fixed pattern in alternate frames). TS16: signalling (setup, teardown) or data. TS1 to TS15 and TS17 to TS31: 30 voice channels of 64 kbps. 32 x 8 x 8,000 = 2.048 Mbps.
| Level | Rate | Voice channels | Made of |
|---|---|---|---|
| E0 | 64 kbps | 1 | one channel |
| E1 | 2.048 Mbps | 30 | 32 slots |
| E2 | 8.448 Mbps | 120 | 4 x E1 + 256 kbps |
| E3 | 34.368 Mbps | 480 | 4 x E2 + 576 kbps |
| E4 | 139.264 Mbps | 1920 | 4 x E3 + 1.792 Mbps |
- Justification bits: lower streams on slightly different clocks: plesiochronous digital hierarchy (PDH); replaced by SDH (STM-1 155.52 Mbps).
- T1 vs E1: T1 24 channels, robbed-bit signalling; E1 30 channels, separate TS0 and TS16. ISDN PRI: 23B + D on T1, 30B + D on E1.
- Memory example: an E1 is a train of 32 compartments passing 8,000 times a second: engine TS0, guard's van TS16, 30 calls.
Telecommunication switching systems: from operators to digital exchanges
Telecommunication switching system: exchange equipment that connects any incoming line to any outgoing line or trunk on demand, holds the connection for the call, and releases it.
- Manual: operators with cords and jacks; slow, operator-dependent, replaced.
- Electromechanical, step-by-step (Strowger, Almon B. Strowger, 1891): dialled pulses step selector switches; control spread over the switches.
- Electromechanical, crossbar: bars crossing, contacts closed by relays and latches; hard-wired control, hard to change.
- Electronic SPC (stored program control): a computer runs the exchange from a stored program; new services by software (Bell No. 1 ESS, 1965). Space division (separate path per call) or time division (shared path, samples at fixed intervals; analog or digital; digital from space switches, time switches and combinations).
- Space division: an N x N crossbar has crosspoints, only N in use (1,000 lines: 1,000,000); multistage switches need fewer but can block.
- Time division: time slot interchange (TSI): write the incoming frame to memory in order, read out in the outgoing order; digital exchanges switch the 64 kbps slots of E1 lines; large ones combine stages (time-space-time, TST).
- TSI example: incoming A, B, C, D in slots 1 to 4; control: out 1 takes in 3, out 2 takes in 1, out 3 takes in 4, out 4 takes in 2; outgoing C, A, D, B.
- Networking of exchanges: trunks join local, tandem and toll exchanges; signalling first channel associated (CAS, in the channel or E1 TS16), now common channel (CCS) over a separate network, SS7: faster setup, voice channels free.
- Memory example: a Strowger exchange clatters with each digit; a digital exchange is silent memory.
ISDN: one digital network for voice and data
ISDN (Integrated Services Digital Network): ITU-T I-series standards (1980s) for a fully digital, circuit-switched telephone network carrying voice, data, fax and video end to end over the existing copper line, through standard channels (64 kbps B, signalling D) and interfaces (BRI, PRI).
- Why developed: (1) the local loop was the last analog link (300 to 3,400 Hz, slow modems) while trunks and exchanges were digital; (2) separate networks for voice, telex and X.25 data, now one network, line, number, bill; (3) out-of-band D channel signalling: faster setup, caller identification, call waiting, several numbers; (4) end-to-end digital quality; (5) standard interfaces for any vendor.
- Contribution to data communication: 64 or 128 kbps on an ordinary line (modems gave 28.8 to 56 kbps), 1.5 or 2 Mbps on PRI; voice and data together; fast dial-up for internet and office links; router backup (dial on demand); videoconferencing (H.320); PRI trunks for PBXs; broadband ISDN led to ATM. Replaced by DSL, cable, fiber.
| Channel | Rate | Carries |
|---|---|---|
| B (bearer) | 64 kbps | user voice, data, video; circuit switched |
| D (delta, data) | 16 kbps (BRI), 64 kbps (PRI) | signalling; low-rate packet data |
| H (hybrid) | H0 384, H11 1,536, H12 1,920 kbps | video, fast data |
- BRI: 2B + D = 2 x 64 + 16 = 144 kbps; with 48 kbps framing and sync, 192 kbps on the S/T interface; homes, small offices, one twisted pair.
- PRI: 23B + D = 23 x 64 + 64 + 8 = 1,544 kbps (T1; North America, Japan); 30B + D = 30 x 64 + 64 + 64 = 2,048 kbps (E1; B in TS1 to 15 and 17 to 31, D in TS16, framing TS0); PBXs, ISPs.
Figure: ISDN reference point diagram: TE1 at S to NT2; TE2 at R to TA, TA at S to NT2; NT2 at T to NT1; NT1 at U to the exchange, which reaches circuit, packet, leased line and SS7 networks; customer premises up to NT1.
| Group | What | Example |
|---|---|---|
| TE1 | ISDN terminal, at S | ISDN phone, PC with ISDN card |
| TE2 | non-ISDN terminal, at R, needs TA | analog phone, RS-232 PC |
| TA | terminal adapter, R in, S out | ISDN adapter box |
| NT2 | customer switching, layers 2 and 3 | PBX, router, LAN |
| NT1 | line end, layer 1; four-wire S/T to two-wire loop, monitoring, timing | NT1 box |
| LT, ET | line and exchange termination | carrier's switch |
- Reference points: R (TE2 to TA), S (TE1 or TA to NT2), T (NT2 to NT1), U (NT1 to exchange); alphabetical outward; no NT2: S/T; up to 8 terminals on a BRI S bus.
- Layers: I.430 (BRI), I.431 (PRI); LAPD (Q.921) on D, HDLC-type, address with SAPI and TEI; Q.931 call control; B channels carry anything.
- Working: SETUP on D; exchange routes with SS7; B channel assigned at each end and joined; 64 kbps end to end; D free for more signalling; release by three D messages.
Figure: Q.931 sequence: SETUP, CALL PROCEEDING, SETUP to called, ALERTING, ALERTING, CONNECT, CONNECT ACK, CONNECT, CONNECT ACK; B channel; DISCONNECT, RELEASE, RELEASE COMPLETE on each side; SS7 inside.
- Signalling: out-of-band, common channel, on D only. User to network: Q.931 in LAPD frames; setup SETUP (called number, bearer), CALL PROCEEDING, ALERTING, CONNECT, CONNECT ACKNOWLEDGE; release DISCONNECT, RELEASE, RELEASE COMPLETE. Network: SS7 ISUP: IAM, ACM, ANM, REL, RLC. User to user signalling through the network. Benefits: B channel free throughout, fast setup, one channel for many calls.
- Broadband ISDN: narrowband stops near 2 Mbps; B-ISDN at 155.52 and 622.08 Mbps over fiber with ATM.
- Memory example: small office BRI: ISDN phone (TE1) and old fax through a TA on the S bus; a call on one B, 64 kbps internet on the other; D set up both; NT1 on the wall.
- The book: labels the D channel "(Bearer Channel)"; a slip: B is the bearer, D the signalling channel.
Chapter 3: Data link layer 8750 words
The data link layer: functions, services and design issues
Data link layer: layer 2 of the OSI model. It packs the network layer's packets into frames and moves them reliably from one node to the next over a single link, hiding noise and medium sharing from the layers above.
Hop to hop, not end to end: a packet from a hostel laptop to a server abroad crosses laptop to Wi-Fi AP, AP to switch, switch to router, router to ISP; the network layer picks the route, the data link layer works each hop, with a fresh header (that link's addresses) and a fresh bit check on every hop. Memory example: a relay race; route planned once, each runner carries the baton one leg and checks it at the hand-over.
Figure: the network layer above, the data link layer split into one LLC (802.2) and a MAC per LAN (802.3, 802.4, 802.5, 802.11), each over its own physical layer
Functions (Forouzan's five):
- Framing: divide the bit stream into frames, delimit start and end.
- Physical addressing: sender and receiver MAC addresses in the header (48-bit Ethernet addresses).
- Flow control: stop a fast sender overrunning a slow receiver.
- Error control: detect damaged frames (CRC or checksum in the trailer); recover damaged, lost and duplicate frames by retransmission (ARQ).
- Access control: on a shared medium, decide which station transmits now.
- Also (Tanenbaum): a well-defined service interface to the network layer; link management (set up, maintain, release connections).
| Service | How it works | Suits | Example |
|---|---|---|---|
| Unacknowledged connectionless | no connection, no ACK; lost frame not recovered here | low-error links, real-time traffic | Ethernet |
| Acknowledged connectionless | no connection; every frame ACKed, resent on timeout | unreliable links, radio | IEEE 802.11 |
| Acknowledged connection-oriented | connection set up; numbered frames, each exactly once, in order; establish, transfer, release | long or noisy links, WAN serial, satellite | HDLC, LLC type 2 |
Design issues: service to the network layer; framing; error control (detection, ACKs, timers, sequence numbers); flow control; on broadcast links, medium access and addressing.
| Sublayer | Standard | Functions |
|---|---|---|
| LLC (upper) | IEEE 802.2, same for all LANs | network layer interface; multiplexes protocols with service access points (DSAP, SSAP); optional flow and error control; type 1 unacknowledged connectionless, type 2 connection-oriented, type 3 acknowledged connectionless |
| MAC (lower) | one per LAN: 802.3, 802.4, 802.5, 802.11 | frame for its LAN; MAC addresses and FCS; medium access (CSMA/CD, token passing, CSMA/CA); error detection |
Framing: character count, byte stuffing and bit stuffing
Framing: dividing the physical layer's bit stream into frames and delimiting each frame's start and end, so the receiver finds boundaries, checks each frame and asks again for only the damaged one.
Why: one flipped bit in a whole-file block means resending everything; in frames of a few hundred bytes only the damaged frame is resent. Frame = header (addresses, control) + payload + trailer (error check). Fixed-size frames (ATM's 53-byte cells) need no delimiters; variable-size frames need a method; protocols often combine two.
Figure: character count (frames of 5, 5, 8, 8 bytes; one count garbled from 5 to 7 breaks every later boundary), byte stuffing (FLAG ends, ESC added before FLAG or ESC in data), bit stuffing (flag 01111110, stuffed 0s)
- Character count: a header field gives the frame's byte count. Flaw: a garbled count loses the receiver's step for good; the CRC says the frame is bad but not where the next one starts, and the sender cannot tell how much to resend. Never used alone.
- Flag bytes with byte (character) stuffing: FLAG byte at start and end; a lost receiver searches for the next FLAG. A FLAG in the data is sent as ESC FLAG, an ESC as ESC ESC; the receiver removes each escape. PPP: FLAG
0x7E, ESC0x7D. Drawbacks: tied to 8-bit bytes; a frame full of FLAGs can double. - Flag bits with bit stuffing: flag
01111110at both ends; after five consecutive 1s in the data the sender stuffs a 0, so six 1s never occur inside. Receiver: after five 1s, a 0 is stuffed (delete it); a 1 then 0 is the flag. Any number of bits, not only bytes. HDLC; USB stuffs after six 1s. - Physical layer coding violations: line codes with unused signal patterns. Manchester: each bit high-low or low-high, so high-high and low-low delimit frames. 4B/5B: 16 of 32 code groups carry data; 100BASE-X and FDDI start frames with J and K. Only where the line code has spare patterns.
Memory example: byte stuffing is a quote inside a C string, "He said \"namaste\"": backslash = ESC; a real backslash is written as two (ESC ESC).
Example (the book's, checked): data 01001111110111110 (17 bits):
data 0100 11111 1 0 11111 0
stuffed 0100 11111 0 1 0 11111 0 0
sent 01111110 0100111110101111100 01111110
Two bits stuffed, 19 bits between the flags.
| Method | Frame delimited by | Weakness | Used in |
|---|---|---|---|
| Character count | length field in header | one bad count loses every later boundary | only with another method |
| Byte stuffing | FLAG bytes; ESC before FLAG or ESC | needs 8-bit bytes; frames grow | PPP |
| Bit stuffing | flag 01111110; 0 after five 1s | up to one extra bit per five | HDLC family |
| Coding violations | patterns data never uses | needs a redundant line code | 100BASE-X, FDDI |
Errors, detection against correction, parity and the checksum
Error: a change in a frame's bits between sender and receiver (noise, interference, attenuation, faulty device), caught with redundant bits computed from the data and recomputed by the receiver.
- Single-bit error: one bit changes; rare on serial links (noise outlasts one bit).
- Burst error: two or more bits change; length from the first wrong bit to the last, bits between may be right. A 1 ms noise burst hits about 10 bits at 10 kbps, about 10,000 at 10 Mbps.
- The book adds: content error (message bits change) and flow integrity error (frame lost, duplicated or misdelivered).
Detection asks did an error happen; the frame is discarded and resent (ARQ, backward error correction). Correction asks which bits and fixes them at the receiver (forward error correction, FEC); it needs many more redundant bits, so it pays where retransmission is slow or impossible.
| Point | Error detection | Error correction |
|---|---|---|
| Goal | find that the frame has an error | find which bits and fix them |
| Redundancy | small: 1 parity bit, 16 or 32-bit CRC | large: 3 check bits per 4 data bits, Hamming (7,4) |
| After an error | discard; sender retransmits (ARQ) | receiver repairs at once (FEC) |
| Hamming distance | detects | corrects |
| Suits | wired LANs, links with a return channel | noisy or long-delay links, no return: satellite, mobile, Wi-Fi, CDs, QR codes |
| Codes | parity, checksum, CRC | Hamming, Reed-Solomon, convolutional, LDPC |
Memory example: a shop's payment QR sticker (Fonepay, eSewa) scans with a torn corner: Reed-Solomon correction rebuilds up to 30 percent of the code at the highest level.
- Simple parity: one bit makes the count of 1s even (or odd). Book example:
1001101(four 1s) sent with even parity as01001101;00001101arrives: odd count, detected;00001001(two flips): even, missed. Detects every odd number of errors, no even number; corrects nothing. - Two-dimensional parity: rows with a row parity bit (VRC), columns with a column parity bit (LRC); detects all 1, 2 and 3-bit errors, misses some 4-bit patterns; corrects a single bit at the failing row and column.
- Checksum: upper layers (IP, UDP, TCP use the 16-bit Internet checksum). Sender: segments of bits, added in one's complement (carry out of the top wrapped to the bottom); checksum = complement of the sum. Receiver: adds all segments and the checksum; complement all 0s means accept.
Book example (checked), , :
10011001
+ 11100010 = 1 01111011 wrap: 01111100
+ 00100100 = 10100000
+ 10000100 = 1 00100100 wrap: 00100101
sum 00100101, checksum 11011010
receiver: 00100101 + 11011010 = 11111111, complement 00000000: accept
Checksum weakness: errors that cancel (one word +1, another -1) and swapped words pass, so the link uses CRC.
CRC: the cyclic redundancy check
CRC: error detection by binary polynomial division: the sender appends check bits, the remainder of dividing the data (with zeros added) by a generator of degree in modulo-2 arithmetic, so the whole frame divides exactly; the receiver divides again and a nonzero remainder means an error.
- Bits as polynomials:
1101is ; a degree- generator has bits, first and last 1. - Modulo-2 arithmetic: no carries or borrows; addition = subtraction = XOR (); subtract the generator where the leading bit is 1, zeros where it is 0.
Figure: sender appends r zeros, divides, appends the remainder; receiver divides by the same generator; remainder 000 accept, otherwise reject (example data 1101, generator 1011)
Sender: 1. append zeros (); 2. divide by mod 2; 3. remainder ( bits, leading zeros kept) is the CRC; 4. send then , . Receiver: divide by the same ; zero remainder accept, else discard (ARQ resends).
Example: message 1101, generator 1011 (, ):
1111 quotient
1011 ) 1101000
1011
----
1100
1011
----
1110
1011
----
1010
1011
----
001 remainder = CRC
Sent 1101001; at the receiver 1101001 / 1011 leaves 000: accepted.
Why it works: is a multiple of (adding the remainder = subtracting it mod 2); with an error pattern the remainder is that of alone, missed only if divides . Detects:
- all single-bit errors, when has at least two terms;
- all double-bit errors, when divides no for up to the frame length;
- every odd number of errors, when is a factor;
- every burst of length or less; a burst of with probability ; longer ones with probability .
Generators: CRC-8 (ATM header), CRC-16-CCITT (HDLC, PPP), CRC-32 (Ethernet and Wi-Fi 4-byte FCS). Hardware: a shift register with an XOR per generator term, computed as bits go out; the book: CRC described by modulo-2 arithmetic, polynomials or digital logic. Memory example: a teacher checking a long sum by its remainder on division by 9: a wrong remainder shows a copying error but not where.
Method in the exam: generator as bits; append zeros ( = bits minus one); full division layout; remainder with bits; transmitted frame. To show detection: flip the bit, divide the received frame, show the nonzero remainder.
Hamming distance and the Hamming code
Hamming distance: the number of bit positions in which two equal-length codewords differ, found by XOR and counting the 1s. The minimum Hamming distance of a code is the smallest distance between any two valid codewords; it fixes how many errors the code detects and corrects.
Example: 10101 XOR 11110 = 01011: distance 3. Memory example: SITA and GITA differ in one letter (distance 1): one wrong letter makes another valid name, unnoticed; names at least three letters apart would turn a typo into a non-name closest to exactly one real name.
| Code | Detects | Corrects | |
|---|---|---|---|
| Even parity | 2 | 1 error | none |
| Repetition 000, 111 | 3 | 2 errors | 1 |
| Hamming (7,4) | 3 | 2 (if not correcting) | 1 |
| Extended Hamming (8,4), SECDED | 4 | 2 | 1 (ECC memory) |
Use in error control: pick a code whose fits the link; detecting code (CRC) plus retransmission (ARQ) where there is a return channel, correcting code (Hamming, FEC) where retransmission is costly. A received word that is not a codeword shows an error; correction = the nearest codeword.
Hamming code: parity bits for data bits with (4 data bits need 3: the (7,4) code). Parity bits at positions 1, 2, 4, 8, ...; each checks the positions whose binary number contains its bit: P1 checks 1, 3, 5, 7 (check 1, skip 1); P2 checks 2, 3, 6, 7 (check 2, skip 2); P4 checks 4, 5, 6, 7 (check 4, skip 4). Word layout D7 D6 D5 P4 D3 P2 P1, even parity.
Example, encode data 1011 (D7 D6 D5 D3 = 1 0 1 1), then correct:
P1 = D3 xor D5 xor D7 = 1 xor 1 xor 1 = 1
P2 = D3 xor D6 xor D7 = 1 xor 0 xor 1 = 0
P4 = D5 xor D6 xor D7 = 1 xor 0 xor 1 = 0
codeword = 1 0 1 0 1 0 1
bit 6 flips: 1110101 arrives
C1 = P1 D3 D5 D7 = 1 1 1 1 even: 0
C2 = P2 D3 D6 D7 = 0 1 1 1 odd: 1
C4 = P4 D5 D6 D7 = 0 1 1 1 odd: 1
syndrome C4 C2 C1 = 110 = 6: flip bit 6, 1010101
Syndrome 000 means no error. The book's example: 1110111 arrives, syndrome 100 = 4, "the 4th bit is incorrect", but the book never writes the corrected code: flipping bit 4 gives 1111111 (data 1111).
Flow control: stop and wait, the sliding window and piggybacking
Flow control: procedures telling the sender how much data it may send before it must wait for an acknowledgement, so a fast sender does not overrun a slow receiver's buffer and processing speed.
Without it the buffer fills, frames are dropped and resent: wasted time. Memory example: a teacher dictating; stop and wait reads one line and waits for "OK"; the sliding window reads up to seven lines ahead while the student calls out "done up to line 5".
Stop and wait: send one frame, wait for its ACK, then the next. Simple, never overruns, but the link idles a round trip per frame. With :
Example: 1000-bit frames at 1 Mbps ( = 1 ms), satellite = 270 ms: , , about 0.18 percent.
Figure: stop and wait timing; normal (frame 0, ACK 1, frame 1, ACK 0) and errors (frame 0 lost, timeout, resent; ACK 1 lost, timeout, duplicate frame 0 discarded and re-acknowledged)
Sliding window: up to frames before an ACK; -bit sequence numbers modulo (0 to 7 for 3 bits). Send window = sent but unacknowledged plus may-send-now; receive window = frames the receiver will accept. An ACK carries the next frame expected, acknowledging all before it, and slides the window right.
Same satellite link, : , about 1.3 percent; filling the pipe needs , so 10-bit sequence numbers. TCP grows its window for the same reason.
Figure: send window of 7 over 3-bit sequence numbers: 0, 1 acknowledged; 2 to 4 sent, waiting; 5, 6, 7, 0 may be sent; receive window 1 for go-back-N, up to 4 for selective repeat
Piggybacking: with two-way data the ACK rides in a header field of the receiver's next data frame instead of a separate ACK frame; each data frame carries seq (its own number) and ack (next frame expected from the other side).
- Advantages: fewer frames (no separate ACK frames, headers, trailers), better bandwidth use; less processing, fewer interrupts; window still slides.
- Cost: an ACK may wait for outgoing data; an ack timer sends a separate ACK if no data frame leaves in time (before the sender's timer resends needlessly).
- Where: HDLC N(R) in every I-frame; TCP's ACK flag on data segments.
Memory example: in a phone call, "yes, got it" said at the start of your own next sentence.
Error control by ARQ: stop and wait, go-back-N and selective repeat
ARQ (automatic repeat request): error control by retransmission, also called backward error correction; the receiver detects damaged frames (CRC) and the sender resends any frame damaged or lost, prompted by a timeout or a NAK.
Tools: sequence numbers (gaps, duplicates), ACKs, NAKs, a timer per outstanding frame, a copy of every unacknowledged frame at the sender. The three ARQs are the ways of backward error correction.
- Stop and wait ARQ: stop and wait flow control plus a timer and 1-bit sequence numbers (0, 1, 0, 1). Damaged frame: receiver discards (or NAKs), timer expires, resend. Lost frame: timeout, resend. Lost ACK: timeout, resend; receiver sees a duplicate by sequence number, discards it, re-ACKs (without sequence numbers it would accept it twice).
- Go-back-N ARQ: sliding window; up to outstanding; receiver window 1 (in order only, discards frames after a gap); cumulative ACKs; on a NAK or timeout for frame , resend and every frame after it, even those that arrived.
- Selective repeat ARQ: receiver buffers frames after a gap and NAKs only the missing one; sender resends just that frame; receiver delivers in order once the gap fills. Both windows at most . Costs (the book): sorting logic and a buffer at the receiver for frames held after a NAK; a search at the sender for the frame asked.
Figure: go-back-N and selective repeat with frames 0 to 4 and frame 2 lost; go-back-N discards 3 and 4 and resends 2, 3, 4; selective repeat buffers 3 and 4 and resends only 2, then ACK 5
| Point | Stop and wait | Go-back-N | Selective repeat |
|---|---|---|---|
| Frames outstanding | 1 | up to | up to |
| Receiver window | 1 | 1 (in order) | up to |
| On an error resend | that frame | that frame and all after | that frame only |
| Receiver buffer | one frame | one frame | a window |
| Efficiency | low | good on clean links | best on noisy links |
| Complexity | least | moderate | most |
Window limits: with 3-bit numbers, a go-back-N window of 8 and every ACK lost, the old frame 0 resent would be taken as the new frame 0; window 7 avoids it; selective repeat must stay at 4 so old and new receive windows never overlap. Memory example: a student misses line 3 of a dictation; go-back-N re-reads from line 3 to the end, selective repeat re-reads only line 3.
HDLC: stations, modes, the frame and its three frame types
HDLC (High-level Data Link Control): a bit-oriented ISO data link protocol (ISO 3309 and 4335, now ISO/IEC 13239) for point-to-point and multipoint links; flag 01111110 with bit stuffing; sliding window and ARQ for flow and error control.
- Stations: primary (controls the link, sends commands); secondary (under a primary, sends responses); combined (both).
- Configurations: unbalanced (one primary, one or more secondaries, point to point or multipoint); balanced (two combined stations, point to point, equal responsibility); symmetric (book: each physical station two logical ones, primary and secondary).
| Mode | Configuration | Who may send |
|---|---|---|
| NRM, normal response mode | unbalanced | primary starts every exchange; secondary only when polled |
| ARM, asynchronous response mode | unbalanced | secondary sends without permission; primary owns the line (start-up, error recovery, disconnection) |
| ABM, asynchronous balanced mode | balanced | either combined station any time; the usual mode today |
Figure: the HDLC frame (flag 8, address 8 or more, control 8 or 16, information variable, FCS 16 or 32, flag 8 bits) and the control field of I (0, N(S), P/F, N(R)), S (1 0, S S, P/F, N(R)) and U frames (1 1, M M, P/F, M M M)
- Flag (8 bits,
01111110): both ends; bit stuffing keeps it out of the data. - Address (8 bits, extendable): the secondary; receiver in a command, sender in a response.
- Control (8 or 16 bits): frame type and sequence numbers; 16 bits gives 7-bit numbers (modulo 128) instead of 3-bit (modulo 8).
- Information (variable): network layer data, or management information in a U-frame.
- FCS (16 or 32 bits): CRC over the frame between the flags.
Frame types:
- I-frame: user data with N(S) (own number) and N(R) (next expected from the other side, a piggybacked ACK).
- S-frame: flow and error control, no data: RR (00, receive ready, an ACK), REJ (01, reject, go back to N(R)), RNR (10, receive not ready, stop), SREJ (11, selective reject, resend N(R) only).
- U-frame: link management: SNRM, SABM (set a mode), DISC (disconnect), UA (unnumbered acknowledgement), FRMR (frame reject).
- P/F: poll bit in a command (reply wanted), final bit in a response.
Family: LAPB (X.25), LAPD (ISDN D channel), LAPF (frame relay) and PPP's framing come from HDLC. Memory example: the default encapsulation of a Cisco router's serial port (a bank branch's leased line) is HDLC, Cisco's own variant.
PPP: the Point-to-Point Protocol
PPP (Point-to-Point Protocol): the standard data link protocol for a point-to-point link (dial-up, DSL, leased line), RFC 1661; byte-oriented with HDLC-like framing (RFC 1662), plus LCP to manage the link and an NCP per network protocol.
- Framing: an unambiguous frame with error detection, byte stuffing.
- LCP (Link Control Protocol): brings the line up, tests it, negotiates options (maximum frame size, authentication, compression), takes it down.
- NCPs: one per network protocol; IPCP configures IPv4 (gives each end its address).
Figure: PPP frame (flag 0x7E, address 0xFF, control 0x03, protocol 1 or 2 bytes, payload up to 1500 by default, FCS 2 or 4, flag 0x7E) and the phases Dead, Establish, Authenticate, Network, Open, Terminate
Frame: flag 0x7E; address 0xFF (all stations, only two exist); control 0x03 (unnumbered, PPP numbers nothing); protocol 2 bytes (1 if LCP compresses it): 0x0021 IPv4, 0x0057 IPv6, 0xC021 LCP, 0x8021 IPCP, 0xC023 PAP, 0xC223 CHAP; payload up to 1500 bytes by default; FCS 2 bytes (4 if negotiated); flag. Inside: 0x7E sent as 0x7D 0x5E, 0x7D as 0x7D 0x5D.
Phases: Dead (no carrier), Establish (LCP options), Authenticate (optional; PAP clear password, CHAP challenge and hashed reply), Network (NCP, IPCP), Open (data), Terminate (LCP closes), back to Dead; a failed option or login also ends the link.
| Point | HDLC | PPP |
|---|---|---|
| Orientation | bit-oriented, bit stuffing | byte-oriented, byte stuffing |
| Addressing | station address | none (always 0xFF) |
| Flow and error control | sliding window, ACKs, ARQ | none by default; errors only detected |
| Extras | none | option negotiation, authentication, several network protocols |
SLIP (Serial Line IP, RFC 1055) came first: wraps IP packets between END bytes; no error detection, no address negotiation, no authentication, no protocol field; replaced by PPP. Memory example: a home fibre router asking for a PPPoE username and password runs PPP over Ethernet (RFC 2516) to log in to the ISP.
The MAC sublayer and the channel allocation problem
MAC (medium access control) sublayer: the lower data link sublayer that decides which station may transmit next when many share one broadcast channel (cable, ring, radio band), using a multiple access protocol.
Point-to-point links join two stations (no question who talks); a broadcast link is shared and every station hears every frame; who gets the channel under contention is the MAC sublayer's job.
Why channel access control is essential (its significance):
- Collisions: two stations sending at once garble both frames; bandwidth wasted, both resent.
- Efficiency: channel busy with useful frames, few collisions, little idle time.
- Fairness: every station gets a chance; none hogs the channel.
- Delay and priority: token passing guarantees worst-case delay and priorities (real-time, factory traffic).
- Cost: many cheap stations share one medium.
Memory example: a class discussion with no moderator (everyone at once, nothing heard) against a rule (raise a hand, pass a microphone).
The channel allocation problem: how to allocate one broadcast channel among competing users.
Static allocation: fixed portions, of the bandwidth each (FDM) or one slot in (TDM). Suits few users with steady traffic (radio, TV, telephone trunks); wastes capacity on bursty data (idle shares lost, busy users cannot borrow). Capacity bps, frames of mean length bits, frames per second:
Example (Tanenbaum's numbers): 100 Mbps, 10,000-bit frames ( = 10,000 frames/s), 5000 frames/s: = 200 µs; ten static 10 Mbps channels with a tenth of the traffic: = 2 ms, ten times worse.
Dynamic allocation: on demand. Tanenbaum's five assumptions: independent stations generating frames at random (station model); one shared channel; collisions observable; continuous or slotted time; carrier sense or not.
Figure: tree of multiple access protocols: random access (ALOHA, CSMA, CSMA/CD, CSMA/CA; Ethernet, Wi-Fi), controlled access (reservation, polling, token passing; token bus, token ring, FDDI), channelization (FDMA, TDMA, CDMA; GSM, 3G)
- Random access (contention): no station controls another; send when ready, collisions resolved by retrying: ALOHA, CSMA, CSMA/CD, CSMA/CA.
- Controlled access: turns by agreement, no collisions: reservation, polling, token passing.
- Channelization: the channel divided by frequency, time or code: FDMA, TDMA, CDMA.
ALOHA: pure and slotted
ALOHA: the first random access protocol (ALOHAnet, University of Hawaii, Norman Abramson, 1971): a station transmits whenever it has data; overlapping frames collide and are lost; each sender retries after a random time.
Pure ALOHA: send at once, wait for an ACK (time-out about twice the longest propagation delay); no ACK means a collision: wait a random backoff (Forouzan: from 0 to frame or propagation times after the th attempt, give up after about 15) and resend. Random, or the same two frames collide forever.
Figure: vulnerable time; pure ALOHA, frames starting in (t - T, t + T) overlap the frame sent at t (2T); slotted ALOHA, only a frame in the same slot collides (T)
Vulnerable time: frame time ; a frame sent at survives only if no other starts in (an earlier one overlaps its head, a later one its tail): 2T. Even a first bit overlapping a last bit destroys both.
Slotted ALOHA (Roberts, 1972): slots of length ; start only at a slot boundary (a station missing it waits for the next); collision only with a frame in the same slot: vulnerable time T. Needs synchronised clocks.
Throughput: = offered load (frames tried per frame time, new and retried, Poisson); = successful frames per frame time; probability of no other frame in frame times :
Figure: throughput S against G from 0 to 3; slotted peaks at 0.368 at G = 1, pure at 0.184 at G = 0.5; at G = 1 slotted leaves 37 percent of slots empty and 26 percent in collision
| Point | Pure ALOHA | Slotted ALOHA |
|---|---|---|
| Sends | any time | start of a slot only |
| Time | continuous, no clock | slotted, synchronised |
| Vulnerable time | ||
| No collision when | no other frame starts within before or after its start | no other station sends in the same slot |
| Success probability | ||
| Throughput | ||
| Maximum | 18.4 % at | 36.8 % at |
Example (Forouzan's numbers, checked): 200 kbps, 200-bit frames, = 1 ms. Pure at 1000 frames/s (): = 0.135, about 135 frames/s; at 500 (): 0.184, about 92; at 250 (): 0.152, about 38. Slotted at 1000 frames/s: = 0.368, about 368. Memory example: students shouting answers any time (pure) against only right after the teacher's bell (slotted).
The book's Table 3.1 (p. 82) labels and "probability of successful transmission"; they are throughputs; the success probabilities are and . Efficiency of slotted ALOHA derived in the Numericals panel.
CSMA: listen before talking
CSMA (carrier sense multiple access): random access in which a station first listens to the medium and transmits only if it is idle: listen before talk.
Beats ALOHA: never starts during another transmission; at light load throughput approaches 1. Collisions remain through propagation delay: A starts, its signal needs to reach B; B sensing within that time hears nothing and sends too. Vulnerable time = propagation time .
| Method | Medium idle | Medium busy | Result |
|---|---|---|---|
| 1-persistent | send at once (probability 1) | keep sensing, send the moment it is idle | no idle time; waiting stations collide together; Ethernet |
| Non-persistent | send at once | wait a random time, sense again | fewer collisions; idle medium while all wait |
| p-persistent | (slotted) send with probability ; with wait a slot and repeat | wait until idle, then as for idle | balance set by |
Memory example: in a group call, the 1-persistent friend talks the instant there is silence, the non-persistent one checks again later, the p-persistent one tosses a coin at each pause. Limit: plain CSMA does not notice a collision; both send whole frames, wasting a frame time; collision detection fixes it (CSMA/CD).
CSMA/CD: carrier sense with collision detection
CSMA/CD: the access method of classic half-duplex Ethernet (IEEE 802.3): sense the carrier, send when idle, keep listening while sending, and on a collision stop at once, send a jam signal and retry after a random binary exponential backoff.
Collision: two or more frames on a shared medium at overlapping times; signals add, both garbled. Cause: stations transmit almost together, each sensing idle before the other's signal arrived (propagation delay), or several waiting for one busy period start together when it ends.
- Sense: listen; while busy keep listening (1-persistent).
- Transmit: when idle (after the 96-bit interframe gap), send and monitor the medium.
- Success: whole frame out with no collision.
- Collision: abort at once; send a 32-bit jam signal so every station knows.
- Count: attempt counter + 1; after 16 attempts, give up and report an error.
- Back off: at random from 0 to , ; wait slot times of 512 bit times; back to step 1.
Figure: CSMA/CD flowchart: start (n = 0), sense, idle?, transmit and listen, collision?, whole frame sent? success; on collision jam, n = n + 1, n > 15? abort, else pick K, wait K slots, sense again
Detection: compare what is sent with what is heard; on coax a signal level (voltage, energy) higher than its own; on twisted pair (10BASE-T) activity on the receive pair while transmitting. Must happen while still sending, so a frame lasts at least one round trip:
10 Mbps Ethernet: round-trip budget (2500 m, four repeaters) 51.2 µs, = 512 bits = 64 bytes; 512 bit times is the slot time.
Binary exponential backoff: after the 1st collision; 0 to 3 after the 2nd; 0 to 7 after the 3rd; 0 to 1023 from the 10th on; the range doubles as contention grows.
| Point | CSMA | CSMA/CD |
|---|---|---|
| Listens | before sending | before and while sending |
| On a collision | sends the whole damaged frame | stops at once, short jam |
| Time wasted | a whole frame time | about plus the jam |
| Retry | persistence method | binary exponential backoff, 16 attempts |
| Needs | carrier sensing | hearing while sending, a minimum frame |
| Throughput | lower | higher, less delay |
Today: each switch port is a two-station full-duplex link, no collisions, CSMA/CD off; it runs only in half duplex (hubs); Ethernet from 10 Gbps up dropped half duplex. Memory example: a polite argument: speak when quiet, listen as you speak, both stop and say "sorry" (jam), wait a random moment, longer after each clash.
Controlled access: reservation, polling and token passing
Controlled access: stations consult one another, or a controller, to decide who may send; only the station with the right transmits, so no collisions.
- Reservation: time in intervals; a reservation frame of mini-slots (one per station) opens each; a station sets its mini-slot; reserved stations send in order. Example: booking a futsal slot in advance.
- Polling: one primary; every exchange through it. Poll: asks each secondary in turn if it has data; select: asks if a secondary is ready to receive, waits for its ACK, then sends. Weak: polling overhead; the link stops if the primary fails. Examples: HDLC normal response mode, a Bluetooth piconet master, a teacher's roll call.
- Token passing: a token circulates round a logical ring; only its holder sends, for a limited time, then passes it on. Token management: holding-time limit, priorities, recovery of a lost or duplicate token. Ring: physical (token ring), dual (FDDI) or a bus (token bus). Example: the talking stick in a circle.
| Point | Random access | Controlled access |
|---|---|---|
| Collisions | possible | none |
| Delay at light load | very low | wait for a turn |
| Heavy load | throughput falls, delay unpredictable | fair, delay bounded |
| Weak point | contention | overhead; failed primary, lost token |
Channelization: FDMA, TDMA and CDMA
Channelization: multiple access by sharing out the channel's bandwidth by frequency (FDMA), time (TDMA) or code (CDMA); each station has its own share and does not contend.
- FDMA: own frequency band with guard bands, used all the time; first-generation analog mobiles. FDM is the same idea in one multiplexer at the physical layer; FDMA is an access method for many stations.
- TDMA: one band, own time slot, guard times, tight synchronisation. GSM (2G of NTC and Ncell) uses both: each 200 kHz carrier (FDMA) shared by 8 time slots (TDMA).
- CDMA: all send at once on one band; each multiplies its data by its own chip sequence; codes orthogonal (inner product of two different codes 0, of a code with itself = number of chips); the receiver multiplies the sum by a station's code. 3G.
Example, Walsh codes , , , ; bit 1 as +1, 0 as -1, silence 0. Station 1 sends 1, station 2 sends 0: channel carries . Receiver for station 1: (a 1); station 2: (a 0); station 3: 0 (silent).
Memory example: at a wedding party, FDMA is couples in separate rooms, TDMA turns at one microphone, CDMA pairs talking at once in Nepali, Newari, Maithili and English, each listener following one language.
The IEEE 802 family of LAN standards
IEEE 802: the IEEE's standards for local and metropolitan networks, splitting the data link layer into one LLC sublayer (802.2) and a MAC sublayer plus physical layer per LAN.
| Standard | Covers | Status |
|---|---|---|
| 802.1 | bridging and spanning tree (802.1D), VLAN tagging (802.1Q), port authentication (802.1X), management | active |
| 802.2 | logical link control | stable |
| 802.3 | Ethernet, CSMA/CD, now switched, 10 Mbps to 400 Gbps | dominant wired LAN |
| 802.4 | token bus | withdrawn |
| 802.5 | token ring | withdrawn |
| 802.11 | wireless LAN (Wi-Fi), CSMA/CA | dominant wireless LAN |
| 802.15 | personal area networks: Bluetooth (802.15.1), low-rate (802.15.4, under Zigbee) | active |
| 802.16 | broadband wireless access (WiMAX) | little used now |
Why the split: the network layer sees one LLC interface on any LAN (IP runs unchanged over Ethernet, Wi-Fi, token ring); each LAN keeps the access method suited to its medium. Memory example: a lab laptop uses three at once: Ethernet port 802.3, Wi-Fi card 802.11, the switch's 802.1Q VLANs.
Ethernet (IEEE 802.3): the frame, MAC addresses, data transfer and cabling
Ethernet (IEEE 802.3): the dominant wired LAN: frames with 48-bit MAC addresses and a CRC-32, 10 Mbps to 400 Gbps over coax, twisted pair or fiber; shared Ethernet uses 1-persistent CSMA/CD; switched full-duplex Ethernet needs no access method.
History: Xerox PARC, Robert Metcalfe and David Boggs, 1973, about 3 Mbps; DEC, Intel and Xerox made it 10 Mbps (Ethernet II); IEEE 802.3 in 1983. Generations: Standard (10 Mbps), Fast (100 Mbps, 802.3u, 1995), Gigabit (802.3z, 802.3ab), 10 Gigabit (802.3ae, 2002), then 40, 100 and 400 Gbps.
Figure: Ethernet frame (preamble 7, SFD 1, destination 6, source 6, length/type 2, data and pad 46 to 1500, FCS 4 bytes) and a MAC address split into OUI and NIC-specific halves
| Field | Bytes | Function |
|---|---|---|
| Preamble | 7 | 10101010 seven times; wakes the receiver, locks its clock |
| SFD (start frame delimiter) | 1 | 10101011; the last two 1s say the frame starts |
| Destination address | 6 | receiver MAC: unicast, multicast or broadcast; first, so stations decide early |
| Source address | 6 | sender MAC, always unicast |
| Length/Type | 2 | up to 1500: data length (802.3, LLC follows); 1536 (0x0600) or more: EtherType, 0x0800 IPv4, 0x0806 ARP, 0x86DD IPv6 |
| Data and pad | 46 to 1500 | the packet, padded to 46 |
| FCS | 4 | CRC-32 over addresses, length/type, data; bad frame dropped |
Frame (destination to FCS) 64 to 1518 bytes (1522 with an 802.1Q tag); the 64-byte minimum lets CSMA/CD detect a collision while sending; interframe gap 96 bit times.
MAC address: 48 bits, six hex bytes; first 24 bits the OUI (IEEE number for the maker), last 24 the maker's serial; lowest bit of the first byte (I/G) 0 unicast, 1 multicast; next bit (U/L) global or locally set; all 1s (FF:FF:FF:FF:FF:FF) broadcast; bytes left to right, least significant bit first, so I/G goes first. Examples use 00:00:5E:00:53:01 (documentation block, RFC 7042). Memory example: ipconfig /all shows a laptop card's MAC as "Physical Address".
Data transfer:
- Address: ARP finds the receiver's MAC from its IP address.
- Encapsulate: the NIC builds the frame and computes the CRC-32 FCS.
- Access: half duplex (shared segment, hub): 1-persistent CSMA/CD; full-duplex switch port: just send.
- Signal: preamble and SFD for synchronisation, then the line-coded frame (Manchester at 10 Mbps).
- Deliver: on a bus every station hears it; a switch looks up the destination in its MAC table (from source addresses) and forwards to that port, or floods if unknown.
- Receive: keep only frames for its own, the broadcast or a joined multicast address; check the FCS; drop bad frames and frames under 64 or over 1518 bytes; hand the data up by type.
Connectionless, unacknowledged: a dropped frame is recovered, if at all, by TCP.
Cabling: speed in Mbps, Base = baseband, then medium or segment length in hundreds of metres (10Base5: 10 Mbps baseband, 500 m).
| Standard | Medium | Max segment | Notes |
|---|---|---|---|
| 10Base5 (thick) | thick coax | 500 m | bus, 1983 |
| 10Base2 (thin) | thin coax, BNC T-connectors | 185 m | bus |
| 10BaseT | 2 pairs UTP, Cat 3 or better | 100 m | star, hub |
| 10BaseF (10Base-FL) | multimode fiber pair | 2000 m | star |
| 100BaseTX | 2 pairs Cat 5 UTP | 100 m | Fast Ethernet, 4B/5B |
| 100BaseFX | multimode fiber pair | 2000 m (full duplex) | Fast Ethernet |
| 1000BaseT | 4 pairs Cat 5e UTP | 100 m | 802.3ab |
| 1000BaseSX | multimode, 850 nm short-wave laser | 220 to 550 m | 802.3z |
| 1000BaseLX | 1310 nm long-wave laser, multimode or single-mode | 550 m or 5 km | 802.3z |
| 10GBase-SR, LR, ER | 850 nm multimode; 1310, 1550 nm single-mode | 300 m, 10 km, 40 km | 802.3ae |
Fiber standards with examples: fiber beyond copper's 100 m and against electrical noise and lightning, between buildings and up risers. 850 nm multimode, cheap, hundreds of metres: 1000BaseSX between floors or close blocks. 1310 nm single-mode, kilometres: 1000BaseLX or 10GBase-LR to distant buildings (a library 2 km from the data centre). 100BaseFX and 10BaseF are the older 100 and 10 Mbps versions.
The book's Figure 3.34 (p. 89) prints data and padding as "0-46" bytes (it is 46 to 1500) and describes Length as naming the upper-layer protocol (the EtherType meaning; up to 1500 is a length, 1536 or more a type).
Token bus (IEEE 802.4): a physical bus, a logical ring
Token bus (IEEE 802.4): stations on a physical bus (linear or tree cable) pass a token in a logical ring ordered by address; only the token holder transmits, for a limited time, then passes the token to its successor.
Figure: five stations (90, 45, 112, 70, 20) on one bus cable, and the same stations as a logical ring 112, 90, 70, 45, 20 and back to 112
Why also called a token ring: physically a bus (every frame reaches all at once), but access follows a ring: each station knows its predecessor and successor; the token goes in descending order of address; the lowest passes it back to the highest. The ring is only in the stations' tables: a logical ring.
- Sending: the token holder sends until its token holding time runs out, then sends the token to its successor.
- Priorities: four access classes, 0, 2, 4, 6 (highest), each with a timer.
- Ring maintenance: claim token (start the ring, replace a lost token); solicit successor (new stations join); who follows and set successor (close the gap when a station leaves or fails).
- Physical: 75-ohm broadband coax (cable TV type), 1, 5 or 10 Mbps.
- Frame: preamble, start delimiter, frame control, destination and source addresses (2 or 6 bytes each), data up to 8182 bytes, 4-byte FCS, end delimiter.
- Use: factory automation (General Motors' MAP): a robot arm needs its command within a known time, which Ethernet's random backoff cannot promise.
| Point | 802.3 Ethernet | 802.4 Token bus | 802.5 Token ring |
|---|---|---|---|
| Topology | bus, now a switched star | physical bus, logical ring | physical ring, star-wired |
| Access | CSMA/CD | token by address | token to next station downstream |
| Collisions | yes | none | none |
| Worst-case delay | unbounded | bounded | bounded |
| Priorities | none in the MAC | 0, 2, 4, 6 | 8 levels with reservation |
| Medium, speed | coax, UTP, fiber; 10 Mbps up | broadband coax; 1, 5, 10 Mbps | STP; 4, 16 Mbps |
| Frame removed by | nobody (ends on the bus) | nobody (ends on the bus) | the sender |
| Ring upkeep | none | distributed | active monitor |
| Light load | very short delay | waits for token | waits for token |
Memory example: pass the parcel by roll number, not seat: children scattered (bus), parcel in a fixed circle (logical ring).
Token ring (IEEE 802.5): operation and frame format
Token ring (IEEE 802.5): IBM's LAN (4 or 16 Mbps): stations in a physical ring of point-to-point links round which a 3-byte token circulates; a station sends only after seizing the free token; its frame goes round, the destination copies it, the sender removes it and releases a new token.
Figure: ring of four stations with a circulating token, the five steps, the data frame (SD 1, AC 1, FC 1, DA 2 or 6, SA 2 or 6, data, FCS 4, ED 1, FS 1), the token (SD, AC, ED) and the AC byte (P P P T M R R R)
Multiple access: one token, so one transmitter at a time, no collisions.
- Wait: for the free token (SD, AC, ED).
- Seize: set the token bit T in AC to 1 (the token becomes a frame header); append the rest of the frame.
- Circulate: each station repeats the bits on (one-bit delay); the destination copies the frame and sets A (address recognised) and C (frame copied) in frame status.
- Remove: back at the sender, it strips the frame and reads A, C: 1, 1 delivered; 1, 0 present but not copied; 0, no such station.
- Release: a new free token; token holding time at most 10 ms by default; at 16 Mbps early token release right after the frame.
| Field | Bytes | Function |
|---|---|---|
| SD, start delimiter | 1 | announces token or frame; deliberate coding violations |
| AC, access control | 1 | PPPTMRRR: 3 priority bits, token bit (0 token, 1 frame), monitor bit, 3 reservation bits |
| FC, frame control | 1 | data or ring management frame |
| DA, SA | 2 or 6 each | destination, source |
| Data | no fixed limit | limited by token holding time |
| FCS | 4 | CRC-32 |
| ED, end delimiter | 1 | ends token or frame; flags an error seen on the way |
| FS, frame status | 1 | A and C bits, written twice (outside the FCS) |
Priority and reservation: a waiting station with an urgent frame writes its priority into the reservation bits of a passing frame; the next released token carries that priority; only equal or higher priority frames seize it; the raiser lowers it afterwards.
Active monitor (elected): new token when none seen too long (lost token); removes an orphan frame whose sender died (recognised by the monitor bit it set on the first pass); adds delay so the ring holds the 24-bit token.
Physical: 4 or 16 Mbps over shielded twisted pair, differential Manchester; star-wired to wiring centres (MAU) whose relays bypass a switched-off station. Memory example: the talking stick at a circle meeting; a message goes all the way round, so the speaker knows everyone heard it.
FDDI: dual counter-rotating rings and fault tolerance
FDDI (Fiber Distributed Data Interface): a 100 Mbps token-passing LAN or backbone on optical fiber (ANSI X3T9.5, ISO 9314), built as two counter-rotating rings: the primary carries data, the secondary stands by, surviving a cut cable or a failed station.
Figure: four dual attachment stations on two counter-rotating rings; after a fiber cut between A and B, both wrap and the rings become one ring of twice the length
Features:
- 100 Mbps over multimode fiber, later copper (CDDI); 4B/5B coding, line at 125 Mbaud.
- Dual counter-rotating rings: opposite directions; secondary idle until a fault.
- Large: up to 1000 physical connections (about 500 dual attachment stations; Tanenbaum rounds it to 1000 stations) on up to 200 km of fiber, stations up to 2 km apart: campus or city backbone.
- Timed token protocol: a target token rotation time agreed at start-up; guaranteed share for synchronous traffic, the rest for asynchronous; early token release.
- Frames up to 4500 bytes, CRC-32.
- Stations: dual attachment station (DAS) on both rings; single attachment station (SAS, such as a PC) on the primary through a concentrator.
- Fault tolerance: wrapping, optical bypass, dual homing.
Fault tolerance mechanism:
- Cable cut: the two stations beside the break detect loss of signal and wrap (join primary to secondary inside themselves); the dual ring becomes one ring of twice the length, every station still reached.
- Failed station: its neighbours wrap, cutting it out; or an optical bypass switch passes the light through a switched-off station, no wrap needed.
- Failed SAS: its concentrator cuts it off; the ring never notices.
- Dual homing: a critical server or router on two concentrators; the backup takes over.
Limit: two faults at once split the network into two separate rings. Memory example: Kathmandu's Ring Road with lanes both ways; a blocked stretch, traffic turns back and goes round the other way, every chowk still reached. The book (p. 93) expands FDDI as "Fiber Distribution Data Interface"; the name is Fiber Distributed Data Interface.
Wireless LAN (IEEE 802.11): architecture, CSMA/CA and the physical layer
IEEE 802.11 (Wi-Fi): the wireless LAN standard; physical layer (radio in 2.4, 5, 6 GHz) and MAC sublayer, whose access method is CSMA/CA (collision avoidance), optionally with RTS and CTS.
Architecture: basic service set (BSS), stations sharing one channel; ad hoc (independent BSS) stations talk directly; infrastructure BSS, every frame through an access point (AP); BSSs joined by a distribution system (usually wired Ethernet) form an extended service set (ESS) with one SSID; stations roam between APs.
Figure: ad hoc BSS, infrastructure BSS around an AP, and an ESS of two BSSs whose APs hang off a distribution system, a station roaming between them
Why CSMA/CD is not applicable:
- A radio cannot listen while sending: its own signal is millions of times stronger; detection needs costly full-duplex radios.
- Hidden station: A and C both reach B but not each other; while A sends to B, C senses idle and sends; collision at B, neither sender knows.
- Collisions happen at the receiver; a sender senses only where it is, and signals fade with distance.
- Exposed station: C hears B sending to A and holds back, though its frame to D could not disturb A.
Figure: hidden station (A and C out of each other's range, frames collide at B) and exposed station (C defers to B's transmission though its frame to D would not reach A)
CSMA/CA, the distributed coordination function:
- Sense: wait until the channel has been idle for a DIFS.
- Back off: random number of slots from the contention window, counted down only while idle, frozen while busy.
- Send when the count reaches zero.
- Acknowledge: receiver waits a SIFS and sends an ACK; no ACK means likely collision: double the contention window and retry.
- RTS and CTS (large frames): short RTS carrying the exchange's duration; receiver's CTS with the same time; every station hearing either sets its NAV (network allocation vector) and stays quiet: virtual carrier sensing. A hidden station misses the RTS but hears the CTS.
Figure: timing of DIFS, backoff, RTS, SIFS, CTS, SIFS, DATA, SIFS, ACK; station C's NAV from the RTS, hidden station D's NAV from the CTS; then DIFS and a new backoff
Interframe spaces: SIFS < PIFS < DIFS; ACK and CTS wait only a SIFS, so they always win the channel. The optional point coordination function lets the AP poll stations.
| Point | IEEE 802.3 Ethernet | IEEE 802.11 Wi-Fi |
|---|---|---|
| Access method | CSMA/CD | CSMA/CA |
| Strategy | detect fast and stop | avoid beforehand |
| Before sending | sense, send when idle (1-persistent) | sense, DIFS, random backoff |
| During sending | listen; on a collision jam and back off | cannot listen; relies on the ACK |
| Extra tools | 64-byte minimum frame, binary exponential backoff; switches remove collisions | RTS/CTS with NAV, ACK for every frame, contention window doubling |
Physical layer: original 802.11 (1997), 1 and 2 Mbps in 2.4 GHz, FHSS or DSSS (and infrared).
- FHSS: carrier hops among 79 channels of 1 MHz in a pseudo-random order known to both ends, at most 400 ms per hop; narrowband interference spoils a hop or two. Bluetooth hops too.
- DSSS: each bit replaced by the 11-chip Barker sequence (
10110111000for 1, its inverse01001000111for 0) at 11 Mchips/s; spread over a 22 MHz channel; the receiver correlates with the same sequence; the wanted signal adds up, narrowband interference and echoes are spread out and suppressed (processing gain about 10.4 dB, ). 802.11b kept the 22 MHz channel and reached 11 Mbps with CCK coding. - OFDM: many narrow subcarriers at once; every later version.
| Version | Year | Band | Top rate | Technique |
|---|---|---|---|---|
| 802.11b | 1999 | 2.4 GHz | 11 Mbps | DSSS (CCK) |
| 802.11a | 1999 | 5 GHz | 54 Mbps | OFDM |
| 802.11g | 2003 | 2.4 GHz | 54 Mbps | OFDM |
| 802.11n (Wi-Fi 4) | 2009 | 2.4 and 5 GHz | 600 Mbps | OFDM, MIMO |
| 802.11ac (Wi-Fi 5) | 2013 | 5 GHz | about 6.9 Gbps | wide channels, multi-user MIMO |
| 802.11ax (Wi-Fi 6, 6E) | 2021 | 2.4, 5, 6 GHz | about 9.6 Gbps | OFDMA |
Frame (book Figure 3.41): frame control (2: version, type, subtype, To DS, From DS, more fragments, retry, power management, more data, protected (WEP), order), duration (2, the NAV value), up to four addresses (6 each), sequence control (2), body (0 to 2312), CRC (4). Security (WEP, WPA) is chapter 8's. The book (p. 92) lists 802.11a, b, g and calls 802.11n the latest; 802.11ac and 802.11ax have come since. Memory example: two students shouting answers from opposite ends of a big hall, unheard by each other, clash at the teacher in the middle; RTS/CTS is raising a hand and waiting for the teacher's "yes, you", which everyone hears.
Virtual LANs and IEEE 802.1Q, with a two-VLAN design
VLAN (virtual LAN): a logical group of stations on one or more switches behaving as a separate LAN, one broadcast domain, defined by configuration (port, MAC address, IP address, application), not wiring.
Problem solved: all ports of a plain switch share one broadcast domain (ARP, DHCP broadcasts reach every PC); per-department switches would need rewiring on every move; a VLAN switch does it in software.
- Smaller broadcast domains: broadcasts stay inside their VLAN.
- Security: students cannot reach the department's servers at layer 2; inter-VLAN traffic passes a router that can filter.
- Flexibility: grouping by function, not location; a move is a port's VLAN change, not cabling.
- Cost and performance: one switch serves several groups; easier management.
Membership (the book's four): switch port (static, most common), MAC address, IP address, application. The book separates single-switch VLANs from multi-switch VLANs (which need a trunk).
IEEE 802.1Q: a trunk carries frames of many VLANs; a 4-byte tag after the source address: TPID (16 bits) 0x8100; PCP (3 bits) priority (802.1p); DEI (1 bit) drop first under congestion; VID (12 bits) VLAN ID, 4096 values, 0 and 4095 reserved, so 1 to 4094. An access port belongs to one VLAN and carries untagged frames; the switch tags on entering a trunk and untags at the access port; untagged trunk frames belong to the native VLAN.
Routing between VLANs (two subnets): router or layer 3 switch; router on a stick: one router port, one subinterface per VLAN, one trunk.
Figure: router R1 (G0/0.10 192.168.10.1/24, G0/0.20 192.168.20.1/24) on an 802.1Q trunk to switch S1; Fa0/1 to 0/12 VLAN 10 STUDENT, Fa0/13 to 0/24 VLAN 20 DEPARTMENT; the 802.1Q tag fields
| VLAN | Ports | Subnet | Gateway | Hosts |
|---|---|---|---|---|
| 10 STUDENT | Fa0/1 to Fa0/12 | 192.168.10.0/24 | 192.168.10.1 | 192.168.10.11, .12 |
| 20 DEPARTMENT | Fa0/13 to Fa0/24 | 192.168.20.0/24 | 192.168.20.1 | 192.168.20.11, .12 |
S1(config)# vlan 10
S1(config-vlan)# name STUDENT
S1(config-vlan)# vlan 20
S1(config-vlan)# name DEPARTMENT
S1(config-vlan)# exit
S1(config)# interface range fastEthernet 0/1 - 12
S1(config-if-range)# switchport mode access
S1(config-if-range)# switchport access vlan 10
S1(config-if-range)# interface range fastEthernet 0/13 - 24
S1(config-if-range)# switchport mode access
S1(config-if-range)# switchport access vlan 20
S1(config-if-range)# interface gigabitEthernet 0/1
S1(config-if)# switchport mode trunk
R1(config)# interface gigabitEthernet 0/0
R1(config-if)# no shutdown
R1(config-if)# interface gigabitEthernet 0/0.10
R1(config-subif)# encapsulation dot1Q 10
R1(config-subif)# ip address 192.168.10.1 255.255.255.0
R1(config-subif)# interface gigabitEthernet 0/0.20
R1(config-subif)# encapsulation dot1Q 20
R1(config-subif)# ip address 192.168.20.1 255.255.255.0
Each PC uses its VLAN's subnet and gateway; show vlan brief lists the ports per VLAN; a student-to-department ping succeeds only through R1. Layer 3 switch alternative: interface vlan 10 and interface vlan 20 with the gateway addresses, and ip routing. Memory example: two WhatsApp groups on one phone: same hardware (the switch), separate conversations; passing something between them takes a deliberate forward (the router).
Chapter 4: Network layer 11900 words
The network layer: what it does, and why it is the key layer
Network layer: layer 3 of the OSI model. Delivers a packet from the source host to the destination host, possibly across many networks, by giving every interface a logical address and having routers choose the path one hop at a time.
Three scopes of delivery: the data link layer moves a frame across one link, node to node (hop to hop); the network layer moves a packet from source host to destination host across all links between (host to host); the transport layer moves a message between two processes in those hosts (process to process, by port).
Figure: two hosts running all five layers and two routers running only network, data link and physical; the packet's source and destination IP stay the same end to end, while each link carries a new frame with new MAC addresses.
At every router the frame is opened, the packet read, and a new frame built for the next link with new MAC addresses; the IP addresses never change (only TTL does).
Functions
- Logical addressing: every host and router interface gets an IP address unique across the internetwork; each packet header carries source and destination address. A MAC address works only inside one link.
- Routing: routers run routing algorithms and protocols to learn the networks and build routing tables.
- Forwarding: for each arriving packet, look up the destination in the table and send it out of the matching interface.
- Packetizing: wrap the transport segment in a packet with its own header at the source, unwrap at the destination (encapsulation).
- Fragmentation and reassembly: a packet bigger than the next link's MTU is split; the destination rebuilds it.
- Internetworking: one packet format and one address space hide different link technologies (Ethernet, Wi-Fi, fibre, leased WAN lines).
- Error reporting and diagnostics: ICMP tells the source why delivery failed; ping and traceroute.
- Congestion control and QoS: routers queue, drop or prioritise packets (type of service field); end-to-end control belongs to the transport layer.
Two kinds of service: datagram (connectionless): each packet carries the full destination address and is routed on its own (IP); virtual circuit (connection-oriented): a path is set up first and packets carry a short circuit number (X.25, ATM, MPLS).
| Layer | Delivers | Unit | Address | Device |
|---|---|---|---|---|
| Data link (2) | node to node, one link | frame | MAC, 48 bits | switch, bridge |
| Network (3) | host to host, across networks | packet (datagram) | IP, 32 bits | router |
| Transport (4) | process to process | segment | port, 16 bits | end hosts only |
Why it is the key layer
- Highest layer on the path: routers implement layers 1 to 3, so layer 3 is the top layer every node between the hosts understands; the path is decided here.
- Narrow waist: many applications and two transport protocols above, many link technologies below, one network protocol in the middle (IP over everything, everything over IP); replacing Wi-Fi with fibre changes no application.
- Global addressing that scales: hierarchical addresses let a router keep one route per network, not per host.
- Without it a frame could never leave its own LAN.
Example: a parcel from Pulchowk to Pokhara: the address (district, municipality, ward, name) is the IP address; each post office is a router looking only at the district; the bus between two offices is the data link and changes at every office; the address never does.
Internetworking devices, layer by layer
Internetworking device: hardware joining network segments or whole networks. Each works at one OSI layer, and the layer fixes what it can read (bits, frames, packets, whole messages) and so how much it can decide. A repeater sees only a signal, so it copies it; a switch reads MAC addresses, so it picks one port; a router reads IP addresses, so it picks a path between networks; a gateway reads whole messages, so it translates protocols.
Figure: the seven OSI layers as rows, with repeater and hub at layer 1, bridge and switch at layer 2, router at layer 3 and the gateway spanning layers 4 to 7.
- Repeater (physical): receives a weakened, noisy signal and regenerates it at full strength on its other port; restores bits without reading them; extends a cable beyond its limit (500 m for a thick coaxial 10BASE5 segment). Two ports, no intelligence; every bit, collisions included, is copied, so both sides stay one collision domain. 10 Mbps Ethernet's 5-4-3 rule: at most five segments, four repeaters, stations on only three segments. Not an amplifier: an amplifier boosts noise too, a repeater rebuilds a clean digital signal.
- Hub (physical): multiport repeater; a signal on one port is copied to every other port; all ports share one bandwidth and one collision domain; half duplex. Active hub: powered, regenerates. Passive hub: only joins the wires.
- Bridge (data link): joins two LAN segments, reads MAC addresses, records which station is on which side, forwards a frame only when its destination is on the other side; each side its own collision domain; broadcasts still cross.
- Switch (data link): multiport bridge with a MAC address table; sends each frame only to the destination's port; floods unknown and broadcast frames; each port its own collision domain, and full-duplex ports have no collisions. Modes: store-and-forward (whole frame received, FCS checked: reliable, usual default), cut-through (forwards once the destination MAC is read: fastest, passes bad frames), fragment-free (waits for the first 64 bytes, where collision fragments show). Managed switches add VLANs, port security, monitoring; a layer 3 switch also routes between VLANs.
- Router (network): joins different networks (subnet to subnet, LAN to WAN); forwards packets by destination IP using a routing table configured by hand or built by routing protocols; each interface is its own network and broadcast domain (no broadcasts forwarded); decrements TTL, fragments, often does NAT and filtering.
- Gateway (up to application): protocol converter joining networks with different protocol stacks: email gateway, VoIP to telephone gateway, IoT (Zigbee to IP) gateway. In TCP/IP the "default gateway" of a host is the router for off-subnet packets.
- NIC: layers 1 and 2, carries the MAC address. Modem (or a fibre ONT): converts the digital signal to the line's analogue or optical signal, layer 1.
| Device | Layer | Reads | Unicast sent to | Collision domains | Broadcast domains |
|---|---|---|---|---|---|
| Repeater | 1 | signal | other port | one, shared | one |
| Hub | 1 | signal | every other port | one for all | one |
| Bridge | 2 | MAC | destination's side | one per port | one |
| Switch | 2 | MAC | destination's port | one per port | one (one per VLAN) |
| Router | 3 | IP | next hop on best path | one per interface | one per interface |
| Gateway | up to 7 | whole message | other network, translated | separate | separate |
Switch instead of hub
- Dedicated bandwidth: a 24-port 100 Mbps hub shares 100 Mbps among 24 PCs; a switch gives each port 100 Mbps and carries many conversations at once.
- No collisions: each port its own collision domain; with full duplex CSMA/CD never fires; a hub's one collision domain collapses under load.
- Full duplex: send and receive together; hub half duplex.
- Privacy and security: unicast frames reach only their owner; on a hub every PC receives every frame (sniffing).
- Features: VLANs, port security, QoS, link aggregation, monitoring.
- Cost: the gap has closed; hubs are no longer made.
Router against gateway
| Point | Router | Gateway |
|---|---|---|
| Job | forwards packets between networks | translates between networks with different protocols |
| Layer | 3 | any, usually 4 to 7 |
| Protocols on its sides | same (IP) | different stacks |
| Decides by | destination IP and routing table | the message's protocol and content |
| Changes | only header fields (TTL, checksum) | the format (protocol conversion) |
| Examples | ISP core router, home Wi-Fi router | email, VoIP, IoT gateways |
The book places the gateway at "the session layer and above"; most texts allow any layer up to application.
Example: hostel letters: hub, a warden reading every letter aloud in the corridor; switch, a warden sliding each letter under the right door; router, the post office sending letters to other cities; gateway, a translator rewriting a Japanese letter in Nepali.
Bridges: learning, filtering and forwarding
Bridge: a data link layer device that joins LAN segments and forwards each frame by its destination MAC address: it records which station lives on which port, filters frames that stay local and forwards only those meant for another segment.
Transparent bridge (IEEE 802.1D): stations do not know it exists; no setup; it hears every frame on every port and builds its MAC table (forwarding database) from source addresses. A switch works the same way with more ports.
Figure: segment 1 (A, B) and segment 2 (C, D) joined by a two-port bridge with its MAC table; a frame A to B filtered, A to C forwarded, A to an unknown address flooded.
Handling one frame
- Receive the frame on a port.
- Learn: record source MAC against arrival port, with the time.
- Look up the destination: filter (drop) if on the arrival port; forward out of that port only if elsewhere; flood to all ports except the arrival port if unknown, broadcast or multicast.
- Age: entries not refreshed within 300 seconds (default) are deleted, so a moved station is found again.
Example, empty table, A and B on port 1, C and D on port 2:
| Frame | Learns | Destination | Action | Table after |
|---|---|---|---|---|
| A to C | A on 1 | C unknown | flood to port 2 | A-1 |
| C to A | C on 2 | A on 1 | forward to port 1 | A-1, C-2 |
| B to A | B on 1 | A on 1 (arrival port) | filter | A-1, C-2, B-1 |
| D broadcast | D on 2 | broadcast | flood to port 1 | A-1, C-2, B-1, D-2 |
Throughput against a repeater
- Repeater: copies every bit, so the segments stay one collision domain sharing one channel: total throughput at most one segment's capacity C; more stations, more collisions.
- Bridge: local frames stay local; both segments carry traffic at once; only crossing frames load both. Each segment offers load L, fraction f crosses: , so
- With 100 Mbps segments and f = 0.2: 166.7 Mbps against 100 Mbps; all traffic local: 200 Mbps.
- Collisions stay on their own segment; store-and-forward gives each side its own CSMA/CD distance limit, so the LAN can be longer.
- Bad frames (FCS errors, collision fragments) dropped; segments of different speeds can be joined.
- Limits: broadcasts still cross; store-and-forward adds delay.
Loops and the Spanning Tree Protocol: two bridges between the same LANs make a loop: a broadcast circulates for ever (broadcast storm) and MAC tables flap. STP (IEEE 802.1D, Radia Perlman, 1985): bridges exchange BPDUs, elect a root bridge (lowest bridge ID: priority, default 32768, then MAC), block redundant ports to leave a tree; a blocked port opens if an active link fails. Rapid STP (802.1w) converges in seconds.
| Type | How it works | Where |
|---|---|---|
| Transparent (learning) | builds its own table; stations unaware | Ethernet (802.1D) |
| Source routing | sender writes the route of bridges into the frame | token ring (802.5) |
| Translational | converts frame formats | Ethernet to token ring or FDDI |
| Remote | a pair joins two LANs over a WAN | two offices |
The book calls source routing bridges "routing bridges" and the bridge "a two port switch".
Example: the guard at the gate between two hostel blocks notes who lives where; a letter within one block never passes the gate.
IPv4 addresses: classes, special and private addresses
IPv4 address: a 32-bit logical address of an interface, written in dotted decimal as four octets (192.168.10.37), split into a network part (which network) and a host part (which interface on it).
- Notation: four bytes 0 to 255; 192.168.10.37 =
11000000.10101000.00001010.00100101. - Address space: = 4,294,967,296 addresses; IANA gave out its last blocks in February 2011; APNIC (serving Nepal and Asia-Pacific) reached its final block in April 2011.
- Network and host part: like a phone number's area code and line number; routers look only at the network part.
Logical against physical address
| Point | Physical (MAC) | Logical (IP) |
|---|---|---|
| Layer | data link | network |
| Size | 48 bits, 12 hex digits | 32 bits (IPv4), 128 (IPv6) |
| Assigned by | manufacturer, in the NIC | administrator or DHCP |
| Structure | flat: OUI and serial, no location | hierarchical: network and host |
| Scope | one link, replaced at every hop | end to end (unless NAT) |
| Changes when | card replaced | host moves to another network |
| Used by | switches, within a LAN | routers, between networks |
Why IP although MAC exists:
- A MAC address says who, not where; flat, so routers would need an entry per device; IP's network part lets one route cover a network, and routes can be summarised.
- A MAC address works on one link only; frames are re-addressed each hop; the IP address stays end to end.
- Links differ: Ethernet and Wi-Fi have MACs, serial, PPP and cellular use other schemes or none; IP is uniform over all.
- Hardware changes: a new card changes the MAC, not the IP; a moved laptop's new IP shows its new location.
- Planning: IP addresses can be laid out by department and subnetted. ARP joins the two at the last hop.
Example: a citizenship certificate number (identity, no location) against a postal address (district, municipality, ward, which changes when you move).
Classful addressing
Figure: the five class formats as 32-bit bars with their first bits and network and host octets.
| Class | First bits | Range | Default mask | Networks | Hosts each |
|---|---|---|---|---|---|
| A | 0 | 0.0.0.0 to 127.255.255.255 | 255.0.0.0 (/8) | = 128 (126 usable) | = 16,777,214 |
| B | 10 | 128.0.0.0 to 191.255.255.255 | 255.255.0.0 (/16) | = 16,384 | = 65,534 |
| C | 110 | 192.0.0.0 to 223.255.255.255 | 255.255.255.0 (/24) | = 2,097,152 | = 254 |
| D | 1110 | 224.0.0.0 to 239.255.255.255 | none | multicast groups | none |
| E | 1111 | 240.0.0.0 to 255.255.255.255 | none | reserved, experimental | none |
- Minus two: host part all 0s is the network address, all 1s the directed broadcast.
- Finding the class: first octet; 172.20.5.9 is class B, network 172.20.0.0, host 5.9.
- The book counts class A networks; 0.0.0.0/8 and 127.0.0.0/8 are reserved, so 126 are usable. Its notation example prints the first octet of 128.11.3.31 with nine bits; it is
10000000.
| Special address | Meaning |
|---|---|
| host part all 0s | the network itself |
| host part all 1s | directed broadcast |
| 255.255.255.255 | limited broadcast, never routed |
| 0.0.0.0 | this host (before it has an address); 0.0.0.0/0 is the default route |
| 127.0.0.0/8 | loopback |
| 169.254.0.0/16 | link-local, self-assigned when DHCP fails |
Private addresses (RFC 1918): 10.0.0.0/8 (one class A, 16,777,216), 172.16.0.0/12 (172.16 to 172.31, sixteen class B, 1,048,576), 192.168.0.0/16 (256 class C, 65,536); never routed on the Internet; reach it through NAT. Carrier-grade NAT uses 100.64.0.0/10 (RFC 6598).
Why classful failed: waste (a company of 2,000 hosts took a class B, 63,534 unused); too few class B networks (16,384); a route per class C network; rigid sizes; D and E unusable for hosts. Fixes: subnetting (1985), CIDR (1993), NAT, IPv6.
Subnetting and VLSM: dividing a block with the least waste
Subnetting: dividing one network into smaller subnetworks by borrowing bits from the host part; each subnet has its own network address, broadcast address and host range, and a longer subnet mask shows where its network part ends.
Subnet mask: 32 bits, 1s over network and subnet bits, 0s over host bits; written 255.255.255.192 or /26. ANDing an address with its mask gives the network address:
Address 130.45.32.56 10000010.00101101.00100000.00111000
Mask 255.255.0.0 11111111.11111111.00000000.00000000
AND 130.45.0.0 10000010.00101101.00000000.00000000
Inside an octet: 192.168.10.150/26: 150 AND 192 = 10010110 AND 11000000 = 10000000 = 128: subnet 192.168.10.128/26, broadcast .191, hosts .129 to .190.
Contribution to address management
- Less waste: the block is cut to fit departments.
- Smaller broadcast domains: ARP and other broadcasts stay in one subnet.
- Security and policy: traffic between subnets passes a router or firewall with access rules.
- Easier management: an address tells the department or floor; faults stay in one subnet.
- Hierarchy: the outside world sees one route for the whole block.
- Room to grow: each department gets its own range.
The numbers
For s borrowed bits and h host bits left, with m the last non-255 mask octet:
Network addresses are multiples of the block size; each broadcast is one less than the next network; usable hosts lie between.
| Prefix | Mask | Block | Usable hosts |
|---|---|---|---|
| /24 | 255.255.255.0 | 256 | 254 |
| /25 | 255.255.255.128 | 128 | 126 |
| /26 | 255.255.255.192 | 64 | 62 |
| /27 | 255.255.255.224 | 32 | 30 |
| /28 | 255.255.255.240 | 16 | 14 |
| /29 | 255.255.255.248 | 8 | 6 |
| /30 | 255.255.255.252 | 4 | 2 |
Above /24 the same in the third octet: /23 = 512 (2 in the third octet), /22 = 1,024 (4), /21 = 2,048, /20 = 4,096.
FLSM (one mask for all): four equal subnets of 192.168.10.0/24 borrow 2 bits: /26 at .0, .64, .128, .192, 62 hosts each. N equal parts: smallest s with ; five departments need 3 bits, 8 subnets, 3 spare.
VLSM
VLSM (variable length subnet mask): each subnet gets its own mask. Used when subnets need different numbers of hosts (unequal departments; point-to-point links needing 2 addresses). With one mask all subnets must fit the largest: 100 and 10 hosts in two /25s waste 26 + 116 = 142 usable addresses; VLSM's /25 and /28 waste 26 + 4 = 30. Keeps the plan hierarchical and summarisable. Needs classless routing protocols (RIPv2, OSPF, EIGRP, IS-IS, BGP; not RIPv1 or IGRP).
Method:
- Find the block: if host bits are set, AND with the mask (202.83.54.91/25 gives block 202.83.54.0/25, .0 to .127).
- Size each demand: smallest h with hosts; prefix 32 minus h; block . Point-to-point link: /30 (block 4).
- Sort largest first: keeps every subnet aligned on a multiple of its own size.
- Allocate from the start of the block: each subnet begins where the last ended; links last.
- Each row: network, mask, first usable (network + 1), last usable (broadcast minus 1), broadcast (next network minus 1).
- Waste: per subnet, wasted = minus hosts; unused range = from the end of the last subnet to the end of the block.
- Check: blocks add up to no more than the given block.
Figure: 192.168.10.0/24 drawn to scale with the /26, /27, /28 and two /30 subnets and the unused range, with a zoom on .96 to .127.
Example: 192.168.10.0/24 for Accounts 60, Library 25, Hostel office 10 and two router links:
| Subnet | Hosts | Block | Network | Mask | Usable | Broadcast | Wasted |
|---|---|---|---|---|---|---|---|
| Accounts | 60 | 64 | 192.168.10.0/26 | 255.255.255.192 | .1 to .62 | .63 | 2 |
| Library | 25 | 32 | 192.168.10.64/27 | 255.255.255.224 | .65 to .94 | .95 | 5 |
| Hostel office | 10 | 16 | 192.168.10.96/28 | 255.255.255.240 | .97 to .110 | .111 | 4 |
| Link R1 to R2 | 2 | 4 | 192.168.10.112/30 | 255.255.255.252 | .113 to .114 | .115 | 0 |
| Link R2 to R3 | 2 | 4 | 192.168.10.116/30 | 255.255.255.252 | .117 to .118 | .119 | 0 |
Unused range: 192.168.10.120 to 192.168.10.255 (136 addresses); 11 usable addresses wasted inside the subnets.
Points that cost marks
- Hosts need two extra addresses: 30 hosts fit a /27, 31 need a /26.
- A block starts on a multiple of its size: a /27 at .0, .32, .64, never .40.
- Point-to-point links take a /30 each; RFC 3021 allows /31 but papers expect /30.
- Subnet zero: RFC 950 dropped the first and last subnets (); since RFC 1878 all are used, as the book does.
- Each LAN's default gateway takes one usable address; host counts include it unless stated.
- The book's worked problems print some ranges wrongly: the first usable host of 202.83.54.64/27 as .64 (it is .65), a range ending at the broadcast .127 (should be .126), a /22's block of 4 without saying it is in the third octet (1,024 addresses), and a "class C" pool written 190.16.0.0 (class B). Some answers count wasted as block minus hosts (including network and broadcast): state the count used.
Example: departments seated in a 256-seat hall in power-of-two blocks, biggest first; first and last seat of each block empty (network, broadcast).
Classless addressing: CIDR and supernetting
Supernetting: combining several contiguous networks (typically class C /24s) into one larger block with a shorter prefix, so a single route covers them all; also called route aggregation or summarisation.
CIDR (classless inter-domain routing): RFC 1519 (1993), now RFC 4632. Drops the classes: a block is any power-of-two run of addresses written a.b.c.d/n, n = prefix length (leading network bits). ISPs hand out blocks that fit (a /22 for 1,000 hosts) and routing tables shrink.
- CIDR block rules: addresses; first address divisible by the size (aligned); first address = network, last = broadcast.
- Supernetting rules: networks contiguous; number a power of two; first network on a boundary of the combined size.
Figure: the third octets of four /24 networks in binary, the first six bits equal, merging into 192.168.4.0/22.
Example: 192.168.4.0/24 to 192.168.7.0/24: third octets 00000100, 00000101, 00000110, 00000111; first six bits agree, last two take all values; common prefix 16 + 6 = 22 bits: supernet 192.168.4.0/22, mask 255.255.252.0, 1,024 addresses (192.168.4.0 to 192.168.7.255); one route replaces four.
Trap: 192.168.5.0 to 192.168.8.0 are contiguous but 5 is not a multiple of 4: no single /22; best is 192.168.5.0/24, 192.168.6.0/23, 192.168.8.0/24.
Use: an ISP advertises only its large block for many customer blocks. Overlapping routes are chosen by longest prefix match (most specific wins).
| Point | Classful | Classless (CIDR) |
|---|---|---|
| Network part | fixed by class: 8, 16 or 24 bits | any length /n |
| Block sizes | 16,777,216, 65,536 or 256 | any power of two |
| Mask | implied by first bits | carried with the address |
| Waste | large | small |
| Routing table | one route per classful network | aggregated, longest prefix match |
| Example | 192.168.1.0 is class C, /24 | 192.168.1.0/26 is a block of 64 |
| Point | Subnetting | Supernetting |
|---|---|---|
| Does | divides one network | joins several networks |
| Mask | longer (bits borrowed from host part) | shorter (bits given back) |
| Purpose | organise and conserve addresses inside an organisation | shrink routing tables |
| Used by | network administrators | ISPs, backbone routers |
Example: a bus stops once at the mouth of a lane instead of at each of four houses on it, only if the houses are adjacent on the same lane.
NAT: many private hosts behind one public address
NAT (network address translation, RFC 3022): a router function that rewrites the private source address (and port) of outgoing packets to a public address, records the pair, and reverses it for replies, so a private network can use the Internet.
- Why: private RFC 1918 addresses are free but never routed; public IPv4 addresses ran out.
- Static NAT: one private address always to one public address (publishing a server).
- Dynamic NAT: private addresses take public ones from a pool while needed.
- PAT (NAPT, overload): many private hosts share one public address, told apart by port; every home and hostel router does this.
PAT steps: outgoing: replace source 192.168.1.10:51000 with 203.0.113.5:62001 and record it; incoming reply to 203.0.113.5:62001 rewritten to 192.168.1.10:51000; entry removed when the connection ends or idles.
Inside (private) Outside (public) Remote server
192.168.1.10:51000 -> 203.0.113.5:62001 -> 198.51.100.20:443
192.168.1.11:49200 -> 203.0.113.5:62002 -> 198.51.100.20:443
- Gains: saves public addresses; hides the inside layout; ISP can change without renumbering.
- Costs: breaks end to end (inbound connections need port forwarding); trouble for peer-to-peer, games, VoIP; protocols carrying addresses in their data (FTP) need help; rewriting the header defeats IPsec AH. ISPs also run carrier-grade NAT on 100.64.0.0/10, so a customer may sit behind two NATs.
- DHCP: the same router usually hands each device its private address, mask, gateway and DNS server.
Example: a hostel with one postal address; the office notes the room number of each sender and hands replies to the right room.
The IPv4 datagram: the header, fragmentation, and why 65,495
IP (Internet Protocol, version 4, RFC 791): the Internet's network layer protocol: a connectionless, best-effort datagram service. Each datagram has a 20 to 60 byte header with source and destination addresses and is routed on its own; no promise it arrives, arrives once, or in order.
- Best effort: no acknowledgements, no connection, no retransmission; datagrams can be lost, duplicated, delayed, reordered; only the header is error-checked; TCP adds reliability, ICMP reports problems. Like ordinary (unregistered) post.
- What IP does: addresses each datagram, forwards hop by hop, fragments for small MTUs, limits lifetime with TTL, names the upper-layer protocol.
Figure: the IPv4 header as rows of 32 bits: version, IHL, type of service, total length; identification, flags, fragment offset; TTL, protocol, header checksum; source address; destination address; options and padding.
| Field | Bits | Job |
|---|---|---|
| Version | 4 | 4 for IPv4 |
| IHL | 4 | header length in 32-bit words: 5 (20 bytes) to 15 (60 bytes) |
| Type of service | 8 | treatment; now 6 bits DSCP (QoS) and 2 bits ECN (congestion) |
| Total length | 16 | header plus data in bytes, at most = 65,535 |
| Identification | 16 | same on every fragment of one datagram |
| Flags | 3 | reserved 0, DF (do not fragment), MF (more fragments) |
| Fragment offset | 13 | position of the fragment's data, in 8-byte units |
| Time to live | 8 | hop limit: each router subtracts 1, drops at 0 |
| Protocol | 8 | 1 ICMP, 2 IGMP, 6 TCP, 17 UDP, 89 OSPF |
| Header checksum | 16 | over the header only; recomputed every hop (TTL changes) |
| Source address | 32 | sender |
| Destination address | 32 | final receiver |
| Options and padding | 0 to 320 | record route, timestamp, source route; padded to 32 bits |
TTL and the protocol field
- TTL: limits lifetime so a datagram in a routing loop dies; each router subtracts 1; at 0 the router discards it and sends ICMP time exceeded to the source; initial values 64 (Linux), 128 (Windows), 255 (many routers); at most 255 hops; traceroute uses it.
- Protocol: the network layer's demultiplexing number (as a port is for transport): 6 TCP, 17 UDP, 1 ICMP; IPsec 50 (ESP), 51 (AH).
- The book says TTL is time in seconds: RFC 791 defined seconds but required each router to subtract at least 1, and no router counts seconds, so it is a hop count (IPv6: hop limit). The book also prints the maximum length as 65,635 on one page; it is 65,535.
Fragmentation and reassembly
MTU: largest datagram a link's frame carries (Ethernet 1,500 bytes); a datagram may be up to 65,535.
- Check DF: if set, drop and send ICMP "fragmentation needed" with the link MTU (path MTU discovery).
- Split the data to fit the MTU after the header; every piece but the last a multiple of 8 bytes.
- Copy the header onto each piece: same Identification, own Total length, MF = 1 except the last, Fragment offset = first byte position / 8.
- Send fragments as independent datagrams; later routers may fragment again.
- Reassemble at the destination host only: fragments with the same source, destination, protocol and Identification, ordered by offset, last one known by MF = 0, under a reassembly timer; a missing fragment at timeout discards the whole datagram.
Figure: a 4,000 byte datagram split into fragments carrying bytes 0 to 1,479, 1,480 to 2,959 and 2,960 to 3,979 with offsets 0, 185 and 370.
Example: total 4,000 bytes (20 header, 3,980 data), Identification 4321, MTU 1,500: data per fragment 1,500 minus 20 = 1,480 (185 x 8).
| Fragment | Data bytes | Original bytes | Offset | MF | Total length |
|---|---|---|---|---|---|
| 1 | 1,480 | 0 to 1,479 | 0 | 1 | 1,500 |
| 2 | 1,480 | 1,480 to 2,959 | 185 | 1 | 1,500 |
| 3 | 1,020 | 2,960 to 3,979 | 370 | 0 | 1,040 |
Check: 1,480 + 1,480 + 1,020 = 3,980. Reassembly only at the destination since fragments may take different paths; IPv6 routers never fragment, only the source.
Why 65,495
A TCP segment travels inside one IP datagram; the 16-bit Total length caps a datagram at 65,535 bytes including the header; minus the smallest IPv4 header (20) and the smallest TCP header (20):
UDP (8-byte header): 65,535 minus 20 minus 8 = 65,507. On Ethernet, MTU 1,500 minus 40 = 1,460 bytes of data per segment (the usual MSS).
ARP and RARP: from IP address to MAC address and back
ARP (Address Resolution Protocol, RFC 826): finds the MAC address belonging to a known IPv4 address on the same link: broadcast request, unicast reply, answer cached.
Why: frames are delivered to MAC addresses, but software knows the next hop's IP. Same subnet: ask for the destination's MAC; otherwise for the default gateway's MAC, never the distant host's.
Figure: a sequence: laptop A broadcasts "who has 192.168.1.20?", host C drops it, printer B replies unicast with 3c:52:82:10:aa:07, A caches it and sends the packet.
- Check the cache: laptop 192.168.1.10 finds no entry for printer 192.168.1.20; the IP packet waits.
- Broadcast a request to ff:ff:ff:ff:ff:ff (EtherType 0x0806): "who has 192.168.1.20? Tell 192.168.1.10", with its own IP and MAC.
- Only the owner answers: others drop the request; the printer keeps the laptop's mapping.
- Unicast reply: "192.168.1.20 is at 3c:52:82:10:aa:07".
- Cache and send: the laptop stores the pair with a timeout and sends the frame; later packets skip the request.
| ARP field | Size | IPv4 over Ethernet |
|---|---|---|
| Hardware type | 2 bytes | 1 (Ethernet) |
| Protocol type | 2 bytes | 0x0800 (IPv4) |
| Address lengths | 1 byte each | 6 and 4 |
| Operation | 2 bytes | 1 request, 2 reply |
| Sender MAC, IP | 6 + 4 bytes | asker's addresses |
| Target MAC, IP | 6 + 4 bytes | MAC zeros in a request; the IP asked about |
ARP packet: 28 bytes, carried directly in Ethernet, not in IP; arp -a shows the cache.
- Gratuitous ARP: a host announces its own mapping (boot, card change) to refresh caches and detect duplicate addresses.
- Proxy ARP: a router answers for hosts on another network.
- ARP spoofing: no authentication; an attacker answers with its own MAC to intercept traffic; defences: dynamic ARP inspection, static entries.
RARP (Reverse ARP, RFC 903): a diskless workstation knowing only its MAC broadcasts "what is my IP?"; a RARP server on the same LAN replies. Needs a server per network (broadcast cannot cross routers), gives only an IP (no mask, gateway); replaced by BOOTP and DHCP.
NDP (Neighbour Discovery Protocol, RFC 4861): ARP's IPv6 replacement, using ICMPv6:
| Point | ARP (IPv4) | NDP (IPv6) |
|---|---|---|
| Defined | RFC 826, 1982 | RFC 4861, 2007 |
| Carried in | own Ethernet type 0x0806 | ICMPv6 in IPv6 |
| Request to | broadcast | solicited-node multicast (same last 24 bits) |
| Messages | request, reply | NS 135, NA 136, RS 133, RA 134, redirect 137 |
| Jobs | resolution only | resolution, router and prefix discovery, SLAAC, duplicate address detection, unreachability detection, redirect |
| Security | none | SEND (RFC 3971) |
Example: a teacher calling "who is roll 20?" (broadcast); only roll 20 stands (reply); the teacher remembers the face (cache). RARP: a student asking the class for his own roll number.
ICMP: the network layer's error reports and queries
ICMP (Internet Control Message Protocol, RFC 792): IP's companion protocol that reports errors in delivering datagrams back to their source and answers diagnostic queries such as echo (ping); carried inside IP (protocol 1); reports problems, does not correct them.
Why: IP is best effort with no feedback of its own; without ICMP undeliverable datagrams vanish silently. It is the internet layer protocol giving hosts and routers feedback about network problems.
Figure: an Ethernet frame holding an IP header with protocol 1 and the ICMP message, expanded into type, code, checksum, the rest of the header, and data.
Format: type (8 bits, which message), code (8 bits, the reason), checksum (16 bits, whole message), 32 bits depending on type (identifier and sequence number for echo); error messages then carry the offending datagram's IP header and first 8 bytes of data (enough for the TCP or UDP ports).
Error-reporting messages
| Type | Message | Sent when | Codes |
|---|---|---|---|
| 3 | Destination unreachable | network or host unreachable, or no process on the port | 0 network, 1 host, 2 protocol, 3 port, 4 fragmentation needed with DF, 13 blocked by policy |
| 4 | Source quench | congested router asks the source to slow down (withdrawn, RFC 6633, 2012) | 0 |
| 11 | Time exceeded | TTL reached 0, or reassembly timer ran out | 0 TTL, 1 reassembly |
| 12 | Parameter problem | bad header field or missing option | pointer to the bad byte |
| 5 | Redirect | a host on the same network should use another router | network or host |
Query (informational) messages
| Types | Pair | Use |
|---|---|---|
| 8 and 0 | echo request and reply | ping: alive, round-trip time |
| 13 and 14 | timestamp request and reply | round-trip time, clock difference |
| 17 and 18 | address mask request and reply | subnet mask (now DHCP) |
| 10 and 9 | router solicitation and advertisement | finding routers |
No ICMP error is sent about an ICMP error, a non-first fragment, a broadcast or multicast datagram, or a special source address (0.0.0.0, 127.0.0.1): prevents message storms.
Importance and uses in TCP/IP
- Error feedback to transport: unreachable messages let applications report "port unreachable" or "host unreachable" instead of waiting; RFC 1122 makes TCP abort on protocol or port unreachable.
- ping: echo request and reply test reachability and round-trip time.
- traceroute: probes with TTL 1, 2, 3 ...; each router where TTL runs out answers time exceeded; Windows
tracertuses echo requests, UnixtracerouteUDP probes ending at the destination's port unreachable. - Path MTU discovery: TCP sets DF; "fragmentation needed" messages give the largest size, so no fragmentation is needed.
- Better routes: redirect; router solicitation and advertisement.
- Network management: monitoring tools ping devices.
C:\> tracert -d 203.0.113.10
1 1 ms 1 ms 1 ms 192.168.1.1
2 5 ms 6 ms 5 ms 198.51.100.1
3 17 ms 18 ms 17 ms 198.51.100.77
4 20 ms 21 ms 20 ms 203.0.113.10
TTL 1 dies at the home router (line 1), TTL 2 at the ISP router (line 2), TTL 3 one router further; the fourth probes reach the server, which answers with echo reply.
Security: firewalls often block echo requests, but blocking all ICMP breaks path MTU discovery; let error messages through. ICMPv6 (RFC 4443) also carries neighbour discovery and multicast group management.
Example: the post office's returned-letter slip: it delivers nothing, it says why the letter came back.
Routing: what it is, what a good algorithm needs, static against dynamic
Routing: the process by which routers find paths through an internetwork and build the tables forwarding uses. Routing algorithm: the part of the network layer software that decides which output line an incoming packet is sent on.
Routing against forwarding: forwarding handles each packet (table lookup, out of the right interface, microseconds); routing fills and updates the table (runs the algorithm, talks to other routers, reacts to failures, seconds to minutes).
Why routing is essential
- Delivery beyond one network: every router on the way must know the next hop.
- Many paths: networks are meshes; routing picks the best by the metric (hops, delay, bandwidth, cost).
- Survival: dynamic routing reroutes around failures without anyone touching the routers.
- Efficiency: spreads load, cuts delay, avoids congestion.
- Scale and policy: aggregated routes keep tables small; between organisations routing carries policies.
Properties of a good routing algorithm
- Correctness: delivers every packet to the right destination.
- Simplicity: little computation, few messages.
- Robustness: works through failures and topology and load changes for years without a network-wide reboot.
- Stability: converges quickly to fixed routes, no oscillation, no loops.
- Fairness: every source and destination pair served reasonably.
- Optimality (efficiency): minimises mean delay or maximises throughput; fairness and optimality conflict, so a balance is struck.
The book's list also has "cleverness" (detouring around congestion).
Adaptive and non-adaptive routing
| Point | Non-adaptive (static) | Adaptive (dynamic) |
|---|---|---|
| Routes chosen | in advance, offline, by the administrator | continuously by routers from current topology and load |
| On a failure | nothing changes until edited | reroutes itself |
| Methods | static and default routes; flooding | distance vector, link state: RIP, OSPF, EIGRP, BGP |
| Overhead | none | bandwidth, CPU, memory |
| Security | higher, nothing advertised | lower, messages can be forged unless authenticated |
| Suits | small, stable networks; branch with one link | large networks with many paths |
Adaptive algorithms differ in where they get information (locally, neighbours, all routers), when they change routes (timer, topology or load change) and the metric (distance, hops, delay). A single link to an ISP is best served by a static default route.
Routed and routing protocols
| Point | Routed protocol | Routing protocol |
|---|---|---|
| What | network protocol whose packets carry user data and are routed | protocol routers use to swap route information and build tables |
| Provides | addresses and packet format | paths: which networks, how far |
| Used by | hosts and routers | routers only |
| Examples | IPv4, IPv6 (once IPX, AppleTalk) | RIP, OSPF, EIGRP, IS-IS, BGP |
RIP messages themselves travel in routed IP datagrams.
Optimality principle
If router J is on the optimal path from I to K, the optimal path from J to K falls along the same route. Proof: call I to J r1 and the rest r2; a better route than r2 from J to K joined to r1 would beat r1r2, contradicting its optimality.
Figure: I, J and K with r1 and r2 and a dashed shorter r2 prime, beside a sink tree of routers A, C, D, E and F towards destination B.
Sink tree: the optimal routes from every router to one destination form a tree rooted at the destination; no loops, so delivery in finite hops; routing algorithms find and use the sink trees. Example: if the shortest bus route Kalanki to Pulchowk passes Balkhu, the shortest Balkhu to Pulchowk route is the rest of it.
Autonomous system
Autonomous system (AS): networks and routers under one administration with one routing policy, identified by an AS number (16 bits, 1 to 65,535; 32 bits since 2007, RFC 4893, now RFC 6793): an ISP, university, large bank. Inside: an interior gateway protocol chosen by the AS (RIP, OSPF, EIGRP, IS-IS); between ASes: BGP. Stub AS (one link out), multihomed (several providers), transit (an ISP carrying others' traffic). Nepal's larger ISPs each run an AS and exchange local traffic at the Nepal Internet Exchange (NPIX) over BGP.
Example: a microbus route is static routing (same stops even when a road is blocked); a traffic officer at Kalanki waving cars to the ring road when the main road jams is adaptive routing.
The routing table, and forwarding with classful addresses
Routing table: what a router consults for every packet: per destination network, its mask, the next hop, the outgoing interface, a metric, and how the route was learned.
- Destination and mask: routes name networks, not hosts (network-specific, next-hop routing), keeping tables small.
- Next hop: neighbouring router's IP; empty for a directly connected network.
- Interface: port to send out of.
- Metric: route cost (RIP hops, OSPF cost).
- Source: connected, static, or learned by a protocol (dynamic entries time out).
- Default route 0.0.0.0 mask 0.0.0.0: route of last resort.
Classful forwarding: class from the first octet, apply the default mask, look up the network.
Router R1
Destination Mask Next hop Interface Source
10.0.0.0 255.0.0.0 (direct) Gi0/0 connected
172.16.0.0 255.255.0.0 (direct) Gi0/1 connected
192.168.1.0 255.255.255.0 (direct) Se0/0/0 connected
192.168.2.0 255.255.255.0 192.168.1.2 Se0/0/0 RIP, 1 hop
0.0.0.0 0.0.0.0 192.168.1.2 Se0/0/0 static default
- To 172.16.40.9: 172 in 128 to 191, class B, network 172.16.0.0, connected on Gi0/1: delivered directly (after ARP).
- To 192.168.2.77: class C, 192.168.2.0: next hop 192.168.1.2 via Se0/0/0.
- To 203.0.113.50: class C, 203.0.113.0: no entry, default route to 192.168.1.2.
Classless tables carry a mask per route; overlaps resolved by longest prefix match: routes 10.0.0.0/8 via A, 10.1.0.0/16 via B, 10.1.2.0/24 via C: 10.1.2.5 to C, 10.1.9.9 to B, 10.200.0.1 to A; /0 loses to anything longer.
Static routes in Cisco syntax: ip route 192.168.2.0 255.255.255.0 192.168.1.2; default ip route 0.0.0.0 0.0.0.0 192.168.1.2. Hosts: route print (Windows), ip route (Linux).
Example: the board at a bus park saying which counter sells tickets for which district; "everything else, counter 1" is the default route.
Dijkstra's shortest path algorithm, worked on a graph
Dijkstra's algorithm (Edsger Dijkstra, 1959): finds the least-cost path from one node to every other node of a graph with non-negative link costs, making one node permanent at a time, always the nearest one not yet fixed.
In routing: in link state routing every router holds the whole graph and runs Dijkstra with itself as source; the shortest path tree gives the first hop to each destination; OSPF and IS-IS call it SPF (shortest path first).
Steps, with a label (distance, previous node) on each node:
- Start: source (0, none), permanent; all others (infinity, none).
- Relax: for each neighbour of the newest permanent node, distance + link cost; if smaller, relabel (new distance, via this node), tentative.
- Fix the nearest: the tentative node with the smallest distance becomes permanent and the new working node.
- Repeat 2 and 3 until the destination (or all) is permanent.
- Read the path backwards through the "via" fields.
Figure: the book's Figure 4.12 graph of eight routers with link costs, each node labelled with its final distance and predecessor, the path A, B, E, F, H, D in colour.
Example (book Figure 4.12): A-B 2, A-G 6, B-C 7, B-E 2, E-F 2, E-G 1, F-C 3, F-H 2, G-H 4, C-D 3, H-D 2; from A to D:
| Step | Made permanent | Tentative after the step |
|---|---|---|
| 1 | A (0) | B (2, A), G (6, A) |
| 2 | B (2, A) | G (6, A), E (4, B), C (9, B) |
| 3 | E (4, B) | G (5, E), F (6, E), C (9, B) |
| 4 | G (5, E) | F (6, E), C (9, B), H (9, G) |
| 5 | F (6, E) | C (9, B), H (8, F) |
| 6 | H (8, F) | C (9, B), D (10, H) |
| 7 | C (9, B) | D (10, H) |
| 8 | D (10, H) | none |
Shortest path A, B, E, F, H, D, cost 2 + 2 + 2 + 2 + 2 = 10. In step 3 G drops from (6, A) to (5, E) (A-B-E-G = 5); in step 5 F offers C at 9, a tie, so C stays (9, B); C's route to D costs 12. The book's figure is right; it omits the cost, 10.
Cost: about steps simply, about with a priority queue; costs must be non-negative. Distance vector uses Bellman-Ford instead, computing the same shortest paths piece by piece across routers.
Example: a fire spreading from A along the links at one metre per second per unit cost: the order nodes catch fire is Dijkstra's order.
Flooding: send every packet out of every line
Flooding: a non-adaptive routing algorithm in which a router sends every incoming packet out on every line except the one it arrived on.
Problem: duplicates multiply without end on networks with loops. Damping:
- Hop counter: set at the source to the path length (or network diameter); each router subtracts 1, drops at 0. The book floods with a hop count of 3 (first, second, third hops).
- Sequence numbers: source numbers each packet; routers keep the numbers seen per source and drop repeats (how link state packets are flooded).
- Selective flooding: send only on lines going roughly the right way.
Uses: delivery almost certain if any path exists (military robustness, early ARPANET idea); always finds the shortest path (the first copy took it), so a benchmark; needs no knowledge of the network, so used to spread link state packets and broadcasts. Cost: bandwidth for copies, so never for ordinary traffic.
Example: a village rumour, each person telling everyone met except the teller, and repeating it only once.
Distance vector routing, count to infinity, and loop prevention
Distance vector routing: each router keeps a vector of the best known distance to every destination and the line to use, and periodically shares the whole table with its neighbours only, updating by Bellman-Ford.
Three keys: knowledge about the whole network; shared only with neighbours; at regular intervals (RIP every 30 s). "Routing by rumour".
Update rule: router x's distance to y is the minimum over neighbours v of the link cost to v plus v's distance to y:
On receiving a neighbour's table: add the link cost to every entry; keep a route if shorter, or if it comes from the current next hop (its news is always believed).
Example (book Figures 4.14 and 4.15): A on networks 14, 78, 23; neighbours B (14, 55), E (08, 23), F (78, 92); each router starts with its own networks at distance 1; A adds one hop to each received entry:
| Network | A old | From B +1 | From E +1 | From F +1 | A new |
|---|---|---|---|---|---|
| 08 | none | none | 2, E | none | 2 via E |
| 14 | 1 direct | 2, B | none | none | 1 direct |
| 23 | 1 direct | none | 2, E | none | 1 direct |
| 55 | none | 2, B | none | none | 2 via B |
| 78 | 1 direct | none | none | 2, F | 1 direct |
| 92 | none | none | none | 2, F | 2 via F |
Network 66 arrives next round at 3 hops (through B or E); a few rounds later no table changes (converged).
Count to infinity
Good news spreads fast, bad news slowly. Line A, B, C, network N on C: C at 1, B at 2 via C, A at 3 via B. C's link to N fails:
- C loses N, but B's regular update "N, 2 hops" arrives first; C records 3 via B (not knowing B's route runs through C).
- B hears 3 from its next hop C and accepts 4; C goes to 5, B to 6: a routing loop, packets bounce between them.
- Ends only at infinity: RIP's 16; about 14 exchanges.
Figure: routers A, B and C in a line with network N cut off from C, and boxes showing C and B counting 3, 4, 5, 6 up to 16.
Loop prevention
- Maximum hop count: infinity defined as 16 (RIP); counting stops; network limited to 15 hops.
- Split horizon: never advertise a route back out of the interface it was learned from; B never tells C about N.
- Split horizon with poison reverse: B advertises N back to C with metric 16; kills the loop at once; larger updates.
- Route poisoning: C advertises N with metric 16 as soon as it fails.
- Triggered updates: send at once on a change, not after 30 s.
- Hold-down timer: once a route goes bad, ignore news of a worse route to it for a while (RIP 180 s); only better news or the timer's end accepted.
Split horizon fails in loops of three or more routers (Tanenbaum's example); hold-down and triggered updates cover it; link state avoids it.
Strengths and weaknesses: simple, little memory and CPU; slow convergence, loops while converging, usually hop count regardless of speed, whole tables even when nothing changes. ARPANET used it until 1979, then link state. RIP and IGRP are distance vector; EIGRP advanced distance vector.
Example: villagers passing directions by rumour; the fallen bridge's news spreads slowly while the old "two hours from here" goes round the hills.
Link state routing: properties, five steps, and distance vector compared
Link state routing: each router floods the state of its own links (neighbours and costs) to every router, so every router holds a map of the whole network and computes its own shortest paths with Dijkstra.
Three keys: knowledge of its neighbourhood only (not its table); sent to every router (flooding); sent when there is a change (plus a slow refresh).
Properties
- Full topology: same link state database (whole graph of the area) in every router.
- Independent computation: each runs Dijkstra itself; errors do not spread as rumour.
- Fast convergence, no count to infinity: changes flooded at once; loops rare.
- Real costs: metric from bandwidth or delay.
- Low traffic when stable; more memory (database) and CPU (Dijkstra).
- Scales with hierarchy: areas (OSPF, IS-IS).
Five steps
- Discover neighbours: HELLO on each link; neighbours reply with router IDs.
- Measure cost: ECHO round-trip delay, or a cost from bandwidth.
- Build a link state packet (LSP): own ID, sequence number, age, neighbours with link costs.
- Flood the LSP: each router forwards a new LSP on all other links; sequence number drops duplicates and old copies; age expires stale LSPs.
- Compute: with all LSPs, run Dijkstra from itself; the first hop of each path goes in the table.
Figure: five routers A to E with link costs and the link state packet of each router; A's shortest path tree in colour.
Example: A-B 2, A-C 1, B-C 2, B-D 3, C-E 4, D-E 1:
| LSP of | A | B | C | D | E |
|---|---|---|---|---|---|
| Neighbours, costs | B 2, C 1 | A 2, C 2, D 3 | A 1, B 2, E 4 | B 3, E 1 | C 4, D 1 |
Flooding gives every router all five LSPs; A's Dijkstra makes C (1), B (2), D (5 via B), E (5 via C) permanent:
| Destination | Cost | Path | Next hop |
|---|---|---|---|
| B | 2 | A, B | B |
| C | 1 | A, C | C |
| D | 5 | A, B, D | B |
| E | 5 | A, C, E | C |
If D-E fails, D and E flood new LSPs and every router reruns Dijkstra; no count to infinity.
Distance vector against link state
| Point | Distance vector | Link state |
|---|---|---|
| Knows | distances and next hops as neighbours report | whole topology of its area |
| Sends | whole routing table | state of its own links (LSP) |
| To whom | neighbours only | every router, flooding |
| When | periodically (RIP 30 s) plus triggered | on change, slow refresh (OSPF 30 min) |
| Algorithm | Bellman-Ford, shared across routers | Dijkstra, each router on its own copy |
| Convergence | slow, count to infinity | fast, none |
| Loops | possible; split horizon, hold-down | rare |
| Metric | usually hop count | cost from bandwidth or delay |
| Memory and CPU | little | more |
| Bandwidth when stable | wasted on periodic tables | little |
| Scale, setup | small (RIP 15 hops); simple | large, areas; more complex |
| Examples | RIP, IGRP (EIGRP advanced DV) | OSPF, IS-IS |
Examples: a small office of four routers runs RIP, configured in minutes; an ISP or large campus runs OSPF or IS-IS, rerouting around a cut fibre in under a second where RIP could take minutes. The 2072 Kartik paper's "static link routing" means link state routing.
Example: distance vector is directions by word of mouth; link state is every village sending its sketch of nearby roads to all, each holding the full district map.
Hierarchical routing: regions instead of every router
Hierarchical routing: routers grouped into regions; each knows every router of its own region in detail but treats each other region as one destination, so tables shrink.
Why: flat tables, update traffic and computation grow with the number of routers; past some size no router can keep a route to every other.
Example (Tanenbaum's, in the book): 17 routers in five regions; router 1A's flat table has 17 entries, its hierarchical table 7:
Router 1A, hierarchical table
Destination Line Hops
1A - -
1B 1B 1
1C 1C 1
Region 2 1B 2
Region 3 1C 2
Region 4 1C 3
Region 5 1C 4
Savings grow: 720 routers: flat 720 entries; 24 regions of 30: 30 + 23 = 53; three levels (8 clusters of 9 regions of 10): 10 + 8 + 7 = 25. Kamoun and Kleinrock: best number of levels about , about entries per router (720 routers: about 18).
Price: longer paths (everything for a region goes through one entry point). Used in: OSPF areas and the Internet's hierarchy of autonomous systems joined by BGP.
Example: a parcel from Kathmandu to a Jhapa village is sent "to Jhapa"; only the Jhapa office knows the village.
Routing protocols: why they are needed, IGP and EGP, and the main five
Routing protocol: the rules and messages by which routers tell each other which networks they can reach and at what cost, so each builds and updates its table automatically; a routing algorithm put to work between real routers.
Why necessary
- Static routes do not scale: every router needs a route to every network, typed by hand; one new subnet means editing every router.
- Discovery: routers find networks themselves.
- Adaptation: reroute by themselves in seconds on a failure.
- Best loop-free paths: a metric chooses; rules keep routes loop free while routers converge on a consistent view.
- Policy: between autonomous systems, BGP carries who may use whose links.
Classification
- By scope: IGP (intra-AS): RIP, OSPF, IS-IS, EIGRP; EGP (inter-AS): BGP.
- By algorithm: distance vector (RIP, IGRP), link state (OSPF, IS-IS), advanced distance vector (EIGRP), path vector (BGP).
- By masks: classful, no mask in updates (RIPv1, IGRP); classless, mask carried, VLSM and CIDR (RIPv2, OSPF, EIGRP, IS-IS, BGP-4).
Figure: two autonomous systems, one running OSPF and one RIP inside, their border routers joined by eBGP over TCP 179.
| Point | Intra-AS (IGP) | Inter-AS (EGP) |
|---|---|---|
| Scope | inside one AS | between ASes |
| Goal | performance, shortest path | policy and reachability |
| Chosen by | each AS | everyone uses BGP-4 |
| Size | hundreds to thousands of routes | whole Internet |
| Examples | RIP, OSPF, IS-IS, EIGRP | BGP |
| Protocol | Type | Algorithm | Metric | Updates | Origin |
|---|---|---|---|---|---|
| RIP | IGP | distance vector | hop count, 15 most | whole table every 30 s | RFC 1058, 2453 |
| OSPF | IGP | link state (Dijkstra) | cost from bandwidth | on change; refresh 30 min | RFC 2328 |
| IGRP | IGP | distance vector | bandwidth and delay | whole table every 90 s | Cisco, 1980s, obsolete |
| EIGRP | IGP | advanced distance vector (DUAL) | bandwidth and delay | partial, on change | Cisco; RFC 7868 |
| BGP | EGP | path vector | policy, AS path length | incremental, TCP 179 | RFC 4271 |
- RIP: oldest, simplest; hop count, 16 infinity, whole table every 30 s; small networks; slow.
- OSPF: open link state IGP; floods within areas, DR and BDR on LANs, Dijkstra; fast, VLSM, authentication.
- IGRP: Cisco's 1980s answer to RIP's limits; distance vector, composite metric (bandwidth and delay by default, load and reliability optional), hop limit 100 by default (up to 255), updates every 90 s; classful; replaced by EIGRP.
- EIGRP: Cisco's advanced distance vector ("hybrid"); neighbour and topology tables like link state but exchanges distances; DUAL keeps a backup route (feasible successor) so it switches almost at once, loop free; small updates only on change; VLSM, unequal-cost load balancing; multicast 224.0.0.10.
- BGP: the Internet's EGP; path vector; each route with its list of ASes; chooses by policy over TCP.
- IS-IS: ISO link state IGP like OSPF, used by many large ISPs.
Intra-AS in practice: a campus or ISP runs one IGP, usually OSPF; it reaches the Internet by a static default route, or BGP if it owns an AS number and has more than one provider.
Example: inside a city the traffic office picks the fastest roads (IGP); between countries border agreements decide which highways carry whose goods (EGP).
RIP: hop counts, 30 second updates, and its timers
RIP (Routing Information Protocol): distance vector interior protocol (RFC 1058; version 2 RFC 2453); metric = hop count, 15 the most, 16 unreachable; whole table to neighbours every 30 s over UDP port 520.
Operation
- Start up: knows only connected networks; sends a request on each RIP interface.
- Respond: neighbours answer with response messages (their tables); sent again every 30 s by the update timer, changed or not.
- Update: add one hop to each received route; add new networks; replace by shorter routes; always believe the current next hop; metric 16 = unreachable.
- Triggered update: send at once when a route changes.
- Age out by the timers.
- Loop control: split horizon, poison reverse, hold-down.
Figure: a time line from 0 to 360 seconds: updates due every 30 s, the route invalid at 180 s, hold-down from 180 s, and the route flushed at 240 s.
Timers (Cisco defaults)
| Timer | Default | What happens |
|---|---|---|
| Update | 30 s | whole table sent out of every RIP interface |
| Invalid | 180 s | no refresh for 180 s (six missed updates): route invalid, metric 16, advertised unreachable |
| Hold-down | 180 s | after invalid, news of another route to that network refused unless clearly better |
| Flush | 240 s | 240 s after the last update the route is removed |
Flush counts from the last update, so it fires 60 s after invalid, before hold-down would end (360 s). RFC 2453 names two timers: timeout 180 s and garbage collection 120 s after it (route deleted at 300 s); hold-down is Cisco's; the RFC adds a random offset to the 30 s.
Example: R1, R2, R3 in a line (RIPv2)
R1 LAN 10.1.0.0/16; R1 to R2 link 10.2.0.0/16; R2 to R3 link 10.3.0.0/16; R3 LAN 10.4.0.0/16.
- First update (about 30 s): R1 adds 10.3.0.0 at 1 hop via R2; R2 adds 10.1.0.0 (via R1) and 10.4.0.0 (via R3) at 1 hop.
- Second update (about 60 s): R1 adds 10.4.0.0 at 2 hops via R2; R3 adds 10.1.0.0; converged.
R1# show ip route
C 10.1.0.0/16 is directly connected, GigabitEthernet0/0
C 10.2.0.0/16 is directly connected, Serial0/0/0
R 10.3.0.0/16 [120/1] via 10.2.0.2, 00:00:12, Serial0/0/0
R 10.4.0.0/16 [120/2] via 10.2.0.2, 00:00:12, Serial0/0/0
C connected, R by RIP; [120/2] = administrative distance 120 and 2 hops; 00:00:12 = time since last update. If R3 dies: 10.4.0.0 invalid at 180 s, flushed at 240 s.
Message: 4-byte header (command 1 request, 2 response; version) and up to 25 entries of 20 bytes (address family, IP address, metric; v2 adds route tag, subnet mask, next hop): at most 504 bytes, in UDP.
| Point | RIPv1 | RIPv2 | RIPng |
|---|---|---|---|
| Defined | RFC 1058, 1988 | RFC 2453, 1998 | RFC 2080, 1997 |
| Addressing | classful, no mask | classless, mask and next hop | IPv6 prefixes |
| Sent to | broadcast 255.255.255.255 | multicast 224.0.0.9 | multicast ff02::9 |
| Authentication | none | plain text or MD5 | IPsec |
| Transport | UDP 520 | UDP 520 | UDP 521 |
Limits: 15-hop diameter; slow convergence and count to infinity; hop count ignores bandwidth (one hop over 2 Mbps beats two over gigabit fibre); whole table every 30 s. Suits small networks; larger use OSPF.
Counting hops: Cisco and most texts count routers to cross (a neighbour's network is 1 hop); the book's distance vector figure counts a directly connected network as 1, so its values are one higher; either, consistently.
Example: RIP counts bus stops, not minutes; one stop through the Kalanki jam beats two along the empty ring road. Timers: half a minute, three, three and four minutes.
OSPF: areas, DR and BDR, and the road to full adjacency
OSPF (Open Shortest Path First): open-standard link state interior protocol (OSPFv2, RFC 2328): each router floods LSAs through its area, builds the same link state database, and runs Dijkstra. "Open": public standard (unlike Cisco's EIGRP); "shortest path first": Dijkstra. Messages straight in IP (protocol 89) to 224.0.0.5 (all OSPF routers) or 224.0.0.6 (DR and BDR).
Metric: cost from bandwidth:
Cisco default reference 100 Mbps: 10 Mbps link costs 10, 100 Mbps costs 1 (gigabit too unless the reference is raised); path cost = sum of link costs.
The OSPF process
- Find neighbours: Hello every 10 s on each interface; matching area, subnet, timers and authentication make neighbours; silent 40 s (dead interval) means down.
- Elect DR and BDR on multi-access networks.
- Form adjacencies and synchronise: database descriptions, requests, updates until databases match (Full).
- Flood LSAs: each router's own links through the area; the DR adds one for the LAN; flooded on change, refreshed every 30 minutes.
- Run SPF: Dijkstra with itself as root.
- Install routes: best path to each network; changes flood new LSAs and SPF reruns.
| Type | Packet | Job |
|---|---|---|
| 1 | Hello | find neighbours, keep alive, DR election |
| 2 | Database description (DBD) | list LSA headers held |
| 3 | Link state request (LSR) | ask for missing or old LSAs |
| 4 | Link state update (LSU) | carry full LSAs |
| 5 | Link state acknowledgement (LSAck) | confirm each LSA |
Areas: all attached to the backbone, area 0; routers keep detailed databases only of their own area (quick SPF, faults not flooded everywhere); ABR joins an area to the backbone and summarises; ASBR brings in outside routes (BGP, static). Hierarchical routing.
Figure: an AS with backbone area 0, areas 1 and 2 behind ABR1 and ABR2, and an ASBR to another AS; beside it five routers on one Ethernet with R1 as DR, R2 as BDR, and three DROthers adjacent only to them.
DR and BDR
On a multi-access network n routers fully meshed need adjacencies (ten routers: 45) and flood each LSA repeatedly. So a designated router (DR) is elected: every router forms full adjacency only with the DR and a backup DR (BDR): adjacencies (ten routers: 17; five: 7 against 10). Routers send updates to the DR (224.0.0.6); the DR floods to all (224.0.0.5) and originates one network LSA for the segment; the BDR listens and takes over at once if the DR fails. Others are DROthers.
Election:
- Highest interface priority (0 to 255, default 1) becomes DR, next highest BDR.
- Tie: highest router ID (set by hand, else highest loopback address, else highest active interface address).
- Priority 0: never DR or BDR.
- Timing: a new interface waits one dead interval (40 s) before electing.
- No pre-emption: a better router joining later does not take over; only on DR failure does the BDR become DR and a new BDR is elected.
Neighbour states to full adjacency (RFC 2328)
Figure: the seven OSPF neighbour states left to right, Down to Full, with what happens in each; DROthers stop at 2-Way.
- Down: no Hello heard (or dead interval ran out).
- Init: Hello received, not yet listing this router (one-way).
- 2-Way: each sees its own router ID in the other's Hello; DR and BDR elected here; two DROthers stay here.
- ExStart: master and slave chosen (higher router ID is master), first sequence number.
- Exchange: DBD packets with LSA headers swapped.
- Loading: LSRs for missing or older LSAs, received in LSUs, acknowledged.
- Full: databases identical; fully adjacent; each lists the other in its router LSA.
(Attempt: on NBMA networks, Hellos sent to a configured neighbour.)
Why the usual IGP: converges in seconds, no count to infinity, no hop limit, VLSM and CIDR, authentication, equal-cost load balancing, little traffic when stable. Costs: more memory and CPU than RIP; harder setup (areas, router IDs, priorities). The book says OSPF "doesn't need a high memory and high-speed processor": it needs more than RIP (whole database, Dijkstra); areas exist to keep that down.
Example: a class elects a CR (DR) and an assistant CR (BDR); everyone tells the CR, the CR tells everyone; the assistant steps in without a new election.
BGP: routing between autonomous systems
BGP (Border Gateway Protocol, version 4, RFC 4271): the Internet's exterior gateway protocol: a path vector protocol by which autonomous systems advertise the networks they reach, each route carrying the list of ASes it passes through, chosen by policy.
Why not RIP or OSPF between ASes: the goal is the permitted path, not the fastest (an ISP carries customers' traffic, not a competitor's); each AS hides its inside; internal metrics are not comparable; the Internet's table is too large to flood.
Path vector: a route = prefix + AS_PATH, e.g. 203.0.113.0/24 with path 64501 64502; passing it on, an AS adds its own number in front; an AS seeing its own number in a path rejects the route, which prevents loops without count to infinity.
- Sessions over TCP port 179: peers exchange the full table once, then only changes.
- eBGP and iBGP: external between different ASes (usually directly connected); internal carries outside routes among the border routers of one AS.
- Policy: each AS chooses what it accepts and advertises; ranks routes by attributes such as local preference, then the shortest AS_PATH.
| Message | Job |
|---|---|
| OPEN | starts a session: AS number, hold time, router ID |
| UPDATE | advertises routes with path attributes, withdraws dead ones |
| KEEPALIVE | "still here", every third of the hold time (commonly 60 s with 180 s hold) |
| NOTIFICATION | reports an error and closes the session |
Internet exchange point: many ASes exchange traffic directly over BGP sessions instead of paying an upstream provider; Nepali ISPs peer at the Nepal Internet Exchange (NPIX), so traffic between member networks stays in the country.
Example: a travel itinerary "Kathmandu, Delhi, Dubai, London" lists every stop, so no city appears twice and an agent can refuse any route through a country it does not deal with.
Unicast and multicast routing, and their protocols
Unicast: one source to one destination. Multicast: one packet from a source to a group of receivers that joined; the network copies it only where the paths to members split, one copy per link.
Figure: the same network drawn twice: unicast sends three copies from the source (9 link transmissions), multicast one copy per link (6), to receivers that joined group 239.1.1.1 with IGMP.
| Point | Unicast | Multicast | Broadcast |
|---|---|---|---|
| Receivers | one | a group that joined | all on the network |
| Address | one host's | group, class D 224.0.0.0 to 239.255.255.255 | host part all 1s |
| Copies for N receivers | N from the source | one per link, by routers | one, to all |
| Crosses routers | yes | yes, with multicast routing | no |
| Example | a web page | live lecture, IPTV | ARP request |
Unicast routing: look up one destination, one copy to one next hop. Unicast routing protocols: RIP and IGRP (distance vector), OSPF and IS-IS (link state), EIGRP (advanced distance vector) inside an AS; BGP between ASes.
Multicast routing
Two questions: which hosts want a group, and along which tree to copy.
- Group membership (host to router): IGMP (IP protocol 2; v1 RFC 1112, v2 RFC 2236, v3 RFC 3376): a host sends a membership report to join; the router queries periodically (224.0.0.1); v2 added a leave message.
- Distribution trees (router to router): source-based tree (shortest path tree per source: best paths, one tree per source); shared tree (one per group rooted at a core or rendezvous point: fewer trees, longer paths).
- Reverse path forwarding (RPF): accept a multicast packet only if it arrived on the interface used to send unicast traffic back to the source; stops loops and duplicates.
| Protocol | Built on | Tree |
|---|---|---|
| DVMRP (RFC 1075) | distance vector | flood and prune by RPF; source-based trees |
| MOSPF (RFC 1584) | OSPF | group-membership LSAs; source tree by Dijkstra |
| PIM-DM (dense mode) | any unicast protocol | flood and prune; members everywhere |
| PIM-SM (sparse mode, RFC 7761) | any unicast protocol | explicit joins to a rendezvous point (shared tree), then source trees for heavy flows; scattered members; most used |
| CBT (RFC 2201) | any unicast protocol | one shared tree per group, rooted at a core |
"Protocol independent": PIM uses the existing unicast routing table for RPF checks instead of its own algorithm.
Example: unicast is a teacher phoning 200 students with the same notice; multicast is reading it once over the speakers only in the halls whose students signed up; broadcast is the siren everyone hears.
Designing a network for a real site: a hotel, a campus
Network design: choosing the topology, devices, cabling, wireless, addressing, servers and security that meet a site's needs, with a reason for each, from stated or written-down assumed requirements.
Method
- Requirements and assumptions: users, devices, rooms, floors, buildings; services (Internet, Wi-Fi, phones, CCTV, servers); growth; budget; write assumptions down.
- Topology: hierarchical star (core, distribution, access): isolates faults, grows by branches.
- Devices: managed switches (PoE where APs, phones, cameras plug in), router and firewall at the edge, access points with a controller.
- Cabling: Cat6 UTP up to 100 m; fibre between buildings, up risers, for long runs: multimode (OM3 or OM4, 10 Gbps up to 300 to 400 m) inside a campus, single-mode beyond; fibre ignores lightning and electrical noise.
- Wireless: enough APs for coverage and device count; 802.11ax (Wi-Fi 6) or 802.11ac; separate staff and guest SSIDs; WPA2 or WPA3.
- Addressing: private RFC 1918 addresses, one VLAN and subnet per department or function, DHCP, NAT to the public address.
- Servers and services: DHCP and DNS, file and print, web and mail, site applications, camera recorder.
- Security and reliability: firewall rules between VLANs, guest isolation, antivirus, backups; two ISPs, UPS, redundant core links.
- Management: SNMP monitoring, labelled cables and ports, a written plan.
| Layer | Job | Device |
|---|---|---|
| Core | fast backbone joining distribution blocks and server room | layer 3 core switch, fibre |
| Distribution | joins a building's or department's access switches; routes between VLANs; policy | layer 3 switch |
| Access | connects end devices | layer 2 PoE switches, APs |
Campus LAN: five departments of Pulchowk Campus
Given: 5 departments, each 100 computers in 5 rooms of 20: 500 computers. Assumed: separate buildings within a few hundred metres of a central server room; rooms within 100 m of their closet; one ISP link, room for another.
Figure: ISP, router and firewall, core switch and server room above five department distribution switches, each with five 24-port room switches over Cat6, joined to the core by fibre.
| Item | Quantity | Why |
|---|---|---|
| Access switch, managed, 24 gigabit ports | 25, one per room | 20 PCs, uplink, spares; collision-free gigabit per PC |
| Distribution switch, layer 3, SFP fibre ports | 5, one per department | joins 5 room switches, routes the VLAN, contains broadcasts |
| Core switch, layer 3, 10 Gbps fibre | 1 (2 for redundancy) | joins departments and server room |
| Router and firewall | 1 | ISP link, NAT, security policy |
| Wi-Fi 6 access points, PoE | 2 or 3 per department | laptops, phones |
| Cat6 UTP drops | 500 | under 100 m, gigabit |
| Multimode fibre (OM3, OM4) | 5 department links | 10 Gbps over hundreds of metres, lightning immune |
| Racks, patch panels, UPS | every closet and the core | tidy cabling, runs through power cuts |
| Servers | DHCP, DNS, file, web, mail, authentication | central server room |
Accessories: RJ45 connectors, keystone jacks, faceplates, cable trays and conduit, SFP modules, labels, crimping tool, LAN tester. Addressing: one VLAN and private subnet per department (100 hosts plus growth), DHCP, NAT at the firewall; the address ranges for this campus are worked in the Numericals panel.
3-star hotel
Assumed: 60 rooms on 4 floors; lobby, restaurant and bar, conference hall, back offices (front desk, accounts, kitchen, store); about 30 staff PCs and POS terminals; 40 CCTV cameras; an IP phone in every room.
Figure: two ISP links into a dual-WAN firewall, a layer 3 core switch with the server room, a PoE+ switch on each of four floors by fibre, and five VLANs.
- Internet: two ISP links (fibre plus a backup from another ISP) on a firewall with two WAN ports: failover and load balancing; guests judge a hotel by its Wi-Fi.
- Firewall (UTM): NAT, VLAN rules, content filtering, VPN for remote management, captive portal (guest login by room number).
- Core: stackable layer 3 switch in the server room, routing between VLANs.
- Access: one 48-port PoE+ switch per floor (powers APs, phones, cameras over the data cable), fibre uplink up the riser.
- Wireless: Wi-Fi 6 APs, about one per three or four rooms plus lobby, restaurant, conference hall, under one controller for roaming; WPA3 for staff; isolated guest SSID with per-device speed limit.
- Voice and video: IP PBX with a gateway to the telephone network, IP phones, network video recorder.
- Software: property management system (reservations, check-in, billing, linked to keycard locks and restaurant POS), accounting, hotspot manager, antivirus, backup, SNMP monitoring.
| VLAN | Who | Example subnet | Rule |
|---|---|---|---|
| 10 Staff | office PCs, front desk, POS | 10.10.10.0/24 | PMS and Internet |
| 20 Guests | guests' devices | 10.10.20.0/22 | Internet only, isolated |
| 30 Voice | IP phones | 10.10.30.0/24 | QoS priority |
| 40 CCTV | cameras, recorder | 10.10.40.0/24 | no Internet |
| 50 Servers | PMS, file, DHCP, DNS | 10.10.50.0/24 | staff only |
Why: VLANs keep guests away from billing and card systems; PoE saves sockets; managed switches allow VLANs and monitoring; two ISPs and a UPS keep the hotel online; Cat6 gigabit to rooms, fibre floor uplinks.
Example: planning a wedding venue: count guests (requirements), lay out halls (topology), hire tables and chairs (devices), lay carpets (cabling), seat families together (VLANs), guards at the doors (security).
Chapter 5: Transport layer 6960 words
The transport layer: process-to-process delivery and its services
Transport layer: provides logical communication between processes running on different hosts. It takes a message from an application, cuts it into segments, hands them to IP, and at the far end reassembles the data and gives it to the right process. It runs only in the end hosts, never in routers: an end-to-end layer.
Three scopes of delivery: data link layer, node to node (one hop, MAC addresses); network layer, host to host (IP addresses); transport layer, process to process (port numbers). An IP address names only a machine; a laptop running a browser, a video call and an update at once needs the port to pick the program.
Figure: one path from host A (198.51.100.10, browser on port 52344) through routers R1 and R2 to host B (203.0.113.5, web server on port 80), with the three scopes marked: three hops, host to host, process to process.
Memory example: a letter to a hostel. The postal address brings it to the gate (IP, host to host); the warden reads the room number and puts it in the right box (port, process to process); the postal van between sorting offices is the data link layer, one hop at a time.
Services, functions or major tasks (the same list):
| Service | What it does | TCP and UDP |
|---|---|---|
| Process-to-process delivery (addressing) | delivers to a process, not just a host | 16-bit source and destination ports in both headers |
| Segmentation and reassembly | cuts a long message into pieces and rebuilds it | TCP numbers every byte, sizes segments to the MSS; UDP sends each message as one datagram |
| Connection control | sets up, uses, releases a logical connection, or none | TCP: three-way handshake, FIN release; UDP: connectionless |
| Reliability (error control) | detects and recovers corrupt, lost, duplicate data | TCP: checksum, ACK, timer, retransmission; UDP: checksum only, bad datagram dropped |
| Ordered delivery | hands data up in the order sent | TCP: reorders by sequence number; UDP: none |
| Flow control and buffering | protects a slow receiver's buffer | TCP: receive window; UDP: none |
| Multiplexing and demultiplexing | many processes share one IP address | ports in every header |
| Congestion control | keeps all senders from flooding the network | TCP: slow start, AIMD; shaping with leaky and token buckets |
Why a separate layer: the network layer is run by the carrier; users do not own the routers and cannot fix their losses. The transport layer runs in the users' hosts, so it can improve on the network's service (recover losses, restore order) and give applications one standard interface whatever the networks in between. In OSI terms layers 1 to 4 are the transport service provider, layers 5 to 7 its user.
How the complete message arrives in order (TCP):
- Synchronize: the three-way handshake agrees both initial sequence numbers.
- Number every byte: each segment carries the number of its first byte; gaps, duplicates and misordering show at once.
- Check: the checksum catches a corrupted segment, which is dropped and so becomes a loss.
- Acknowledge: cumulative ACK, the number of the next byte expected.
- Retransmit: on retransmission timeout (RTO) or three duplicate ACKs.
- Reorder and drop duplicates: the receive buffer keeps early segments; data goes up only when no gap precedes it.
- Flow control: the advertised window prevents receiver overflow.
- Close cleanly: FIN after the data, carrying the next sequence number, so the receiver knows where the stream ends.
Worked example (3,000-byte message, first data byte 1001): segments seq 1001, 2001, 3001 of 1,000 bytes; 2001 is lost. Segment 1001 arrives: bytes 1001 to 2000 go up, ACK 2001. Segment 3001 arrives early: buffered, duplicate ACK 2001. Timer for 2001 runs out: sender resends 2001 from its copy. Gap filled: bytes 2001 to 4000 go up, all 3,000 bytes delivered in order, ACK 4001.
Figure: sequence diagram of that loss and recovery, with the RTO timer on the sender side; three duplicate ACKs would trigger fast retransmit sooner, and a corrupt segment fails its checksum and is treated as lost.
UDP does none of this beyond the checksum: right port, nothing more.
Services to the upper layer: connection-oriented, connectionless, and the primitives
Transport service: what the transport layer offers the application layer: a connection-oriented service (establish, transfer, release; a reliable stream, TCP) or a connectionless service (independent datagrams, each fully addressed, no guarantees, UDP), used through service primitives.
| Point | Connection-oriented | Connectionless |
|---|---|---|
| Phases | establish, transfer, release | send only |
| Addressing | full address once, at setup | full address in every datagram |
| Reliability | acknowledged, retransmitted, in order | none: loss, repeats, reordering possible |
| Delay before data | a setup round trip | none |
| State | both ends keep connection state | none |
| Picture | a phone call | a letter or postcard |
| Protocol | TCP | UDP |
Memory example: calling home from the hostel (ring, answer, hello, talk, bye) against posting letters (full address on each, may arrive in any order or not at all).
Service primitives (general idea in chapter 1). Unit exchanged: TPDU (transport protocol data unit), called a segment in TCP, a user datagram in UDP.
| Primitive | TPDU sent | Meaning |
|---|---|---|
| LISTEN | none | block until a process tries to connect |
| CONNECT | CONNECTION REQUEST | actively set up a connection |
| SEND | DATA | send information |
| RECEIVE | none | block until a DATA TPDU arrives |
| DISCONNECT | DISCONNECTION REQUEST | release the connection |
Berkeley sockets (4.2BSD, 1983): SOCKET (create endpoint), BIND (attach local address and port), LISTEN (be ready, with a queue), ACCEPT (take next incoming connection), CONNECT (active open), SEND, RECEIVE, CLOSE. Server: SOCKET, BIND, LISTEN, ACCEPT; client: SOCKET, CONNECT. Code is chapter 6.
Why harder than the data link layer: the destination must be addressed explicitly; connection setup must cope with the network storing and delivering old duplicates late; a host holds hundreds of connections, so buffering cannot be one fixed buffer per line.
Classic OSI quality of service parameters: connection establishment delay, connection establishment failure probability, throughput, transit delay, residual error ratio, protection, priority, resilience. The internet's protocols promise none as numbers.
UDP: the 8-byte header, its features, and why an unreliable protocol is used
UDP (User Datagram Protocol, RFC 768, 1980): connectionless, unreliable transport that adds to IP only port numbers, a length and a checksum, in an 8-byte header. Each message is one independent datagram: no handshake, no acknowledgement, no retransmission, no ordering, no flow or congestion control.
Figure: the UDP header as a 32-bit grid (source port, destination port; length, checksum), the 12-byte IPv4 pseudo-header below it, and the datagram inside an IP datagram with protocol 17.
| Field | Bits | Carries |
|---|---|---|
| Source port | 16 | sender's port for replies; optional, 0 when no reply wanted |
| Destination port | 16 | receiving process; always present |
| Length | 16 | header plus data in bytes: at least 8, at most 65,535; at most 65,507 data bytes over IPv4 (65,535 minus 20 minus 8) |
| Checksum | 16 | one's complement over pseudo-header, header, data; optional in IPv4 (0 = not computed, a computed 0 sent as all ones), mandatory in IPv6 |
Pseudo-header (12 bytes, IPv4, never sent): source IP, destination IP, zero byte, protocol 17, UDP length. Including the addresses makes a misdelivered datagram fail the check.
Worked example: DNS query for ioe.edu.np. DNS message 28 bytes (12-byte header plus 16-byte question: name coded 3ioe3edu2np0, 12 bytes, plus 2 type, 2 class). Ephemeral source port 50000.
Source port 50000 = 0xC350
Destination port 53 (DNS) = 0x0035
Length 8 + 28 = 36 = 0x0024
Checksum over the pseudo-header, the header and the 28 bytes
On the wire: C3 50 00 35 00 24 (checksum) then 28 bytes of DNS
IP datagram: protocol 17, total length 20 + 36 = 56 bytes. One datagram out, one back; the resolver retries if no answer.
Features:
- Connectionless: first datagram carries data.
- Unreliable (best effort): no ACK, no retransmission.
- No ordering.
- Message-oriented: boundaries kept (TCP is a byte stream).
- No flow or congestion control: sends at the application's rate.
- Small overhead: 8 bytes against TCP's 20 to 60.
- Stateless: nothing kept per client; one server serves very many.
- Broadcast and multicast supported (TCP unicast only).
- Error detection only: a failed datagram is silently dropped.
Why used though unreliable (unreliable means promises nothing, not usually fails):
- Speed: no handshake; a DNS lookup is one round trip.
- Timeliness over completeness: in calls and games a late packet is useless; TCP would hold back newer data until the lost piece is resent (head-of-line blocking).
- Small and stateless: suits busy servers and small devices.
- Broadcast and multicast: DHCP before the host has an address; IPTV.
- Application adds only the reliability it needs: DNS retries, TFTP block acknowledgements, QUIC (HTTP/3) builds reliable encrypted streams over UDP.
Memory example: live cricket commentary on the radio; a crackled second is not replayed, the next ball matters more (UDP). A downloaded highlights file must arrive whole (TCP).
| Application | Port | Why UDP |
|---|---|---|
| DNS | 53 | one small question and answer; client retries |
| DHCP | 67 server, 68 client | client has no IP address yet, must broadcast |
| VoIP, video calls (RTP) | chosen per call | late audio useless; small losses barely heard |
| Online games | game's own | only the newest position matters |
| IPTV | multicast | one stream to many viewers |
| SNMP, NTP, TFTP, RIP, syslog | 161, 123, 69, 520, 514 | short messages, simple devices |
| QUIC (HTTP/3) | 443 | own reliability and encryption, no TCP handshake or head-of-line blocking |
Recorded on-demand video usually goes over TCP (or QUIC) with a large playback buffer.
The book's Table 5.1 calls UDP "unsecured" for lacking flow control; unreliable is meant. Neither TCP nor UDP encrypts; that is TLS (chapter 8).
TCP: the reliable byte stream, its segment header, and how reliability is provided
TCP (Transmission Control Protocol, RFC 9293, 2022, replacing RFC 793 of 1981): connection-oriented, reliable, full-duplex byte-stream transport. Numbers every byte, acknowledges, retransmits, reorders, controls flow and congestion: the receiver gets exactly the bytes sent, in order.
TCP connection: a logical, full-duplex, point-to-point association between two sockets, named by (source IP, source port, destination IP, destination port). State (sequence numbers, windows, buffers, timers, in a transmission control block, TCB) lives only in the two end hosts; routers know nothing of it: a virtual connection, not a reserved circuit.
Features: connection-oriented (handshake, graceful release); reliable and ordered; byte stream with no message boundaries (100 bytes written three times may be read as 300 at once or 150 and 150); full duplex, point to point, piggybacked ACKs, no broadcast or multicast; flow control (receive window) and congestion control (congestion window); mandatory checksum over pseudo-header (protocol 6), header and data.
Figure: the TCP header as a 32-bit grid: source and destination port; sequence number; acknowledgement number; HLEN, reserved, eight flags, window; checksum, urgent pointer; options and padding; data.
| Field | Bits | Carries |
|---|---|---|
| Source port | 16 | sending process |
| Destination port | 16 | receiving process |
| Sequence number | 32 | number of the first data byte; on a SYN, the ISN |
| Acknowledgement number | 32 | next byte expected; valid when ACK = 1 |
| Header length (HLEN, data offset) | 4 | in 32-bit words, 5 to 15, so 20 to 60 bytes |
| Reserved | 4 (6 in RFC 793) | zero |
| Flags | 8 (6 in RFC 793) | CWR, ECE, URG, ACK, PSH, RST, SYN, FIN |
| Window size | 16 | receive window: bytes the segment's sender can still accept |
| Checksum | 16 | pseudo-header, header, data; mandatory |
| Urgent pointer | 16 | valid when URG = 1: offset from the sequence number to the end of urgent data |
| Options and padding | 0 to 320 | 0 to 40 bytes: MSS, window scale, SACK permitted, SACK, timestamps; padded to 32 bits |
Flags:
- SYN: synchronize sequence numbers; first segment from each side.
- ACK: acknowledgement field valid; every segment after the first SYN.
- FIN: sender has finished; closes its direction.
- RST: abort at once, or refuse a SYN to a port with no listener.
- PSH: deliver to the application now (a keystroke in SSH).
- URG: urgent pointer valid (an interrupt key).
- CWR, ECE: explicit congestion notification (RFC 3168).
Options (mostly in the SYNs): MSS, maximum data per segment, 1460 bytes on Ethernet (1500 minus 20 IP minus 20 TCP), 536 assumed for IPv4 if absent; window scale, multiplies the window by up to 2 to the 14 (windows up to about 1 GB); SACK, selective acknowledgement of out-of-order blocks; timestamps, for round-trip measurement. Sequence space 32 bits, 4,294,967,296 bytes, wraps round; ISN random.
Worked example, first 20 bytes of a SYN:
C3 50 00 50 | 00 00 1F 40 | 00 00 00 00 | A0 02 FA F0 | (checksum) 00 00
C3 50 source port 50000 (client's free port)
00 50 destination port 80 (HTTP)
00 00 1F 40 sequence number 8000, the client's ISN
00 00 00 00 ack number 0, not valid (ACK flag off)
A header length 10 words = 40 bytes, 20 bytes of options
0 reserved 0000
02 flags 0000 0010: only SYN
FA F0 window 64,240 bytes
00 00 urgent pointer 0
Why reliable: over IP, which may lose, corrupt, duplicate or reorder, TCP delivers every byte once, in order, or reports an error. Mechanisms:
- Connection establishment: both ready, starting numbers agreed.
- Sequence numbers on every byte: detect gaps, reorder, discard duplicates.
- Positive cumulative acknowledgements: each ACK names the next byte expected.
- Retransmission on timeout: sender keeps a copy and a timer; resends after RTO and doubles the timeout.
- Fast retransmit: three duplicate ACKs, resend at once.
- Checksum: damaged segment discarded, recovered like a loss.
- Flow control: receive window prevents receiver overflow.
- Congestion control: slow start and congestion window prevent router overflow.
- Graceful release: FIN and ACK each way.
Timer (RFC 6298), R the measured round-trip time; RTTVAR is updated first, with the old SRTT:
The timeout follows the path: short and steady gives a short RTO, long and jittery a longer one.
Memory example: exam forms sent by courier; pages numbered, the office phones "got 1 to 20, send 21" (cumulative ACK), unconfirmed pages resent, torn page treated as missing.
The book's Figure 5.4 shows 6 flags with unlabelled reserved bits (RFC 793, 6 reserved bits); RFC 9293 has 4 reserved bits and 8 flags (CWR, ECE from RFC 3168, 2001); either drawing is right if each row adds to 32 bits. The book calls the window "the window size of the sending TCP": precisely, the receive window the segment's sender advertises. It says options give "congestion control": options are MSS, window scale, SACK, timestamps; congestion control works through the window.
TCP against UDP, and why the transport layer has two protocols
TCP and UDP: the two transport protocols of TCP/IP, a trade between reliability and speed: TCP buys a reliable, ordered, connection-oriented byte stream with a handshake, a bigger header and waiting; UDP drops every guarantee for no setup, 8 bytes of header, no waiting.
| Point | TCP | UDP |
|---|---|---|
| Connection | connection-oriented: handshake, release | connectionless |
| Reliability | ACK and retransmission | none |
| Order | in order (sequence numbers) | none |
| Data unit | segment; byte stream | user datagram; message kept whole |
| Header | 20 to 60 bytes | 8 bytes |
| Flow, congestion control | receive and congestion windows | none |
| Error checking | mandatory checksum; repaired by retransmission | checksum (optional in IPv4); bad datagram dropped |
| Speed | slower: setup round trip, waits for losses | faster: sends at once |
| Casting | unicast only | unicast, broadcast, multicast |
| Server state | TCB and buffers per connection | none |
| IP protocol number | 6 | 17 |
| Used by | HTTP/HTTPS 80, 443; SMTP 25; FTP 20, 21; SSH 22; Telnet 23 | DNS 53; DHCP 67, 68; SNMP 161; TFTP 69; NTP 123; calls; games; QUIC |
Memory example: TCP is a phone call home ("hello", "hajur, bhannus" before talking; "feri bhannu ta?" for a lost word). UDP is shouting the cricket score down the hostel corridor: no setup, no answer, the next shout carries the new score.
Why two transport protocols but one internet protocol:
Figure: the hourglass: many applications on top, TCP and UDP below them (end hosts only), IP alone at the waist (every router), many link technologies at the bottom (Ethernet, WiFi, 4G and 5G, fibre, DSL).
- Opposite needs: files and web pages must arrive complete and in order; a voice call must arrive on time. Recovering a loss means waiting, which real-time traffic cannot afford: one protocol cannot give both.
- End-to-end principle: transport runs only in the end hosts; two choices cost routers nothing.
- IP is the common meeting point: every router and every link technology must handle it; one minimal best-effort protocol any network can offer gives universal reach: the narrow waist.
- Changing the waist is costly: a new transport needs only hosts to change; a new network protocol needs every router changed (IPv6 still not complete after decades).
- UDP keeps the door open: IP's raw service plus ports, so applications build their own reliability (QUIC) without touching the network.
Strictly: the transport layer also has SCTP (RFC 9260) and DCCP (RFC 4340), QUIC (RFC 9000) runs over UDP, and the internet layer has IPv4 and IPv6 plus helpers such as ICMP; TCP and UDP still carry nearly all application data over one routed IP.
Ports and sockets: how a segment finds its process
Port number (port address): a 16-bit number, 0 to 65,535, in every TCP and UDP header, naming a process on a host. Socket (socket address): IP address plus port, such as 203.0.113.5:80; one TCP connection is named by a pair of sockets.
Why ports: IP brings data to a host that runs many processes at once; each process needs its own label. Four levels of address in TCP/IP:
| Address | Layer | Size | Names | Example |
|---|---|---|---|---|
| Physical (MAC) | data link | 48 bits | a network card; changes hop to hop | 00:1A:2B:3C:4D:5E |
| Logical (IP) | network | 32 bits (IPv4) | a host; same end to end | 203.0.113.5 |
| Port | transport | 16 bits | a process | 80 |
| Application-specific | application | varies | user or document, converted to the others | an e-mail address, a URL |
Memory example: a college with one phone number (IP) and extensions (ports) printed on the notice board (well-known); a caller is given a line for the call (ephemeral port).
Figure: the three IANA ranges, and three client sockets (198.51.100.10:52344, 198.51.100.10:52345, 198.51.100.20:49200) connected to one server socket 203.0.113.5:80, told apart by their four-tuples.
| Range | Numbers | Who sets them | Examples |
|---|---|---|---|
| Well-known (system) | 0 to 1023 | assigned by IANA; on Unix only root may open | 22 SSH, 25 SMTP, 53 DNS, 80 HTTP, 443 HTTPS |
| Registered (user) | 1024 to 49151 | registered with IANA by vendors, not controlled | 3306 MySQL, 3389 Remote Desktop, 8080 HTTP alternate |
| Dynamic (private, ephemeral) | 49152 to 65535 | never assigned | a client's temporary port |
Common ports: FTP 20 (data), 21 (control) TCP; SSH 22 TCP; Telnet 23 TCP; SMTP 25 TCP; DNS 53 UDP and TCP; DHCP 67 server, 68 client UDP; TFTP 69 UDP; HTTP 80 TCP; POP3 110 TCP; NTP 123 UDP; IMAP 143 TCP; SNMP 161, trap 162 UDP; BGP 179 TCP; HTTPS 443 TCP (and UDP for QUIC); RIP 520 UDP.
Ephemeral ports: the operating system gives a client a free port per connection (Windows: IANA range 49152 to 65535; Linux default 32768 to 60999). No standard needed: the server reads the client's port from the SYN.
Why well-known ports are standardized:
- Meeting point known in advance: the client must know where to knock; DNS gives the IP address but not the port.
- Interoperability: any client reaches any server with no configuration or lookup.
- Defaults: http://ioe.edu.np/ carries no port; 80 is implied.
- Administration and security: firewall, NAT and IDS rules written per port (allow 443, block 23); only root opens ports below 1024, so a system service is behind them.
- No clashes: one registry, no two services on one number.
Web service on port 8765 instead of 80: TCP works the same. The port must be written in the URL (http://www.example.com:8765/); without it the browser tries 80, and if nothing listens there the server's TCP sends RST (connection refused), or another service on 80 answers. Every link, bookmark and search result must carry the port. Firewalls that allow only 80 and 443 may block it. Hiding on an odd port is security through obscurity; a scanner finds it. Convenience: above 1023, an ordinary user can run it (python -m http.server 8765, then http://localhost:8765/).
Socket, two meanings:
- Address: IP : port with the protocol; a connection is the socket pair (four-tuple), so one server socket 203.0.113.5:80 holds thousands of connections, each client socket differing in IP or port.
- Programming interface: the door between an application and the transport layer (Berkeley sockets API); the application controls its side, and on the transport side chooses only the protocol and a few settings (buffer sizes, MSS).
- Importance: identifies a process uniquely across the internet, lets many connections share one server port, separates each connection's traffic, and is the interface every network application is written on.
The book's Table 5.2 lists ICMP 1, IPv6 41, OSPF 89 and "17/6" for IP beside real ports: those are IP protocol numbers (the IPv4 protocol field); ICMP, IPv6-in-IPv4 and OSPF run directly on IP with no port, and 17 and 6 are UDP and TCP. Its socket example writes port 96 in the text while Figure 5.7 shows 69 (the TFTP port).
Opening and closing a TCP connection: the three-way handshake and the graceful release
Three-way handshake: TCP connection setup in three segments: SYN (client ISN x), SYN + ACK (server ISN y, ack x + 1), ACK (ack y + 1); synchronizes both sequence numbers and proves both sides ready. Release is graceful: each direction closed by its own FIN and ACK, four segments.
Passive and active open: the server creates a socket, binds its well-known port, listens and waits in LISTEN (passive open); the client calls connect, which sends the SYN (active open).
Why the server program runs first: only a socket in LISTEN accepts a SYN. With no listener on the port, the server host's TCP replies RST and the client's connect fails ("connection refused"); TCP does not queue a SYN until a server appears. UDP: a datagram to a port with no socket is dropped and the host returns ICMP port unreachable. A shop must open its shutter before customers can enter.
Handshake with the book's numbers (client ISN 8000, server ISN 15000):
- SYN (client to server): SYN = 1, seq = 8000, no data; CLOSED to SYN-SENT. A SYN consumes one sequence number; carries options (MSS, window scale).
- SYN + ACK (server to client): SYN = 1, ACK = 1, seq = 15000, ack = 8001; server allocates buffers and record; LISTEN to SYN-RECEIVED.
- ACK (client to server): ACK = 1, seq = 8001, ack = 15001; client ESTABLISHED on sending, server on receiving; may carry data.
Figure: sequence diagram of the handshake with states, then data: client seq 8001 (1000 bytes) ack 15001; server seq 15001 (500 bytes) ack 9001.
Why three, not two:
- Both ISNs confirmed: SYN + ACK confirms the client's, the final ACK the server's.
- Old duplicates: a delayed SYN from an earlier attempt would open an unwanted connection with two segments; with three, the client receives a SYN + ACK it never asked for and answers RST, so the server drops it (book Figure 5.9).
- Random ISN: old segments on the same ports are not mistaken for new ones, and attackers cannot guess numbers to inject data.
Memory example: phone call home: "Hello Aama, can you hear me?" (SYN); "Yes, can you hear me?" (SYN + ACK); "Yes!" (ACK); then the real talk.
SYN flood: floods of SYNs from forged addresses, third ACK never sent; half-open connections exhaust the server's queue. Defences: SYN cookies (state encoded in the ISN, none kept until the ACK), shorter timeouts, firewall filtering.
Release, continuing after client sent 1,000 bytes (8001 to 9000) and server 500 (15001 to 15500):
- FIN (client): seq = 9001, ack = 15501; FIN-WAIT-1. A FIN consumes one sequence number.
- ACK (server): seq = 15501, ack = 9002; server CLOSE-WAIT (tells its application); client FIN-WAIT-2. Half-closed: the server may still send.
- FIN (server): seq = 15501, ack = 9002, when its application closes; LAST-ACK.
- ACK (client): seq = 9002, ack = 15502; server CLOSED on receipt; client TIME-WAIT for 2 MSL, then CLOSED.
Figure: sequence diagram of the four-segment release with states and the TIME-WAIT bracket.
Why four segments: full duplex, each direction closed on its own. If the server has nothing left to send it can combine ACK and FIN: a three-segment release.
Why TIME-WAIT: a lost final ACK makes the server resend FIN, which the client must re-acknowledge; delayed segments of the connection die out before the same port pair is reused. RFC 793 suggested MSL 2 minutes (TIME-WAIT 4 minutes); Linux waits 60 seconds.
Abrupt release: RST ends the connection at once, data in flight lost (a crashed program, or a segment matching no connection).
| State | Meaning |
|---|---|
| CLOSED | no connection |
| LISTEN | server waiting for SYN |
| SYN-SENT | client sent SYN, waiting for SYN + ACK |
| SYN-RECEIVED | server got SYN, sent SYN + ACK, waiting for ACK |
| ESTABLISHED | open, data both ways |
| FIN-WAIT-1 | sent FIN, waiting for its ACK |
| FIN-WAIT-2 | FIN acknowledged, waiting for the other FIN |
| CLOSE-WAIT | got FIN, waiting for the local application to close |
| LAST-ACK | sent own FIN after CLOSE-WAIT, waiting for last ACK |
| CLOSING | both sent FIN at once |
| TIME-WAIT | waiting 2 MSL after the final ACK |
The book's Figure 5.11 labels the third segment "seq: 8000, ack: 15001" and Figure 5.8 "Data (seq = x, ACK = y + 1)"; the SYN used up x, so the third segment carries seq = x + 1 (8001), as in RFC 9293's example. The acknowledgement numbers are right.
Flow control and buffering: TCP's sliding window
Transport flow control: end-to-end control that stops a fast sender overflowing a slow receiver's buffer. TCP uses a byte-oriented sliding window: every segment advertises the receive window (rwnd), the free space in the receiver's buffer; the sender keeps at most rwnd bytes sent but unacknowledged.
Why: a slow application leaves data piling up in TCP's receive buffer; overflow would lose data, so the receiver states in each segment's window field how much more it can take.
Four regions of the sender's bytes: sent and acknowledged; in flight (sent, not acknowledged); usable window (allowed, not sent); not allowed until the window moves. Left edge = last ACK; right edge = last ACK + rwnd.
Figure: byte blocks 1001 to 9001; before, ACK 3001 and rwnd 4000 give the window 3001 to 7000 (3001 to 6000 in flight, 6001 to 7000 usable); after ACK 5001 with rwnd 4000 the window is 5001 to 9000 (5001 to 6000 in flight, 6001 to 9000 usable).
Worked example:
- Start: last ACK 3001, rwnd 4000: 3001 to 7000 may be outstanding; sent up to 6000, so 3,000 in flight and 6001 to 7000 may go.
- ACK 5001, window 4000: window 5001 to 9000; 1,000 in flight, 3,000 may be sent; slid 2,000 bytes right.
- Slow reader: ACK 5001 with window 2000 keeps the right edge at 7000: only 1,000 bytes may go.
- Buffer full: window 0 stops the sender; a persist timer sends small window probes until space is advertised, so a lost window update cannot deadlock both sides.
Memory example: a water tanker filling a household tank asks how much room is left and pumps no more; as water is used, the room grows.
Refinements:
- Silly window syndrome: one-byte windows lead to one-byte segments with 40 bytes of headers. Clark: the receiver advertises only when it can take a full segment or half its buffer. Nagle (RFC 896): a sender with small data sends one piece and holds the rest until it is acknowledged or a full segment gathers.
- Window scaling: the 16-bit field allows 65,535 bytes; at most one window per round trip, so with a 100 ms round trip a connection is capped at 65,535 times 8 / 0.1, about 5.24 Mbps. A 100 Mbps, 100 ms path needs 100,000,000 times 0.1 / 8 = 1,250,000 bytes in flight (bandwidth-delay product); the window scale option multiplies the field by up to 2 to the 14.
With congestion control the sender's limit is min(rwnd, cwnd).
Buffering: hundreds of connections per host, so not one fixed buffer set per line; buffer space shared, size agreed at setup and adjusted by the receiver's advertisements.
| Scheme | How | Good for | Weakness |
|---|---|---|---|
| Chained fixed-size buffers | pool of identical buffers, one TPDU each | segments of similar size | small segment wastes a buffer; big one needs several |
| Chained variable-size buffers | each buffer cut to fit | sizes from a few bytes to thousands | harder memory management |
| One large circular buffer per connection | a ring the data flows round | busy connections | wastes memory on light connections |
Where to buffer: low-rate bursty traffic (an interactive terminal): buffer at the sender, receiver grabs buffers as data arrives; bulk transfer (file download): receiver sets aside a full window of buffers.
| Point | Link-level window (chapter 3) | TCP's window |
|---|---|---|
| Counts | frames | bytes |
| Sequence numbers | small, such as 3 bits (0 to 7) | 32 bits |
| Window size | fixed | advertised in every segment |
| Scope | one link, hop by hop | end to end |
| Recovery | go-back-N or selective repeat | cumulative ACKs like go-back-N; early segments kept and SACK resends only gaps, like selective repeat |
Multiplexing and demultiplexing: many processes, one IP address
Multiplexing (sender): gather data from many sockets, add a header with source and destination ports to each chunk, pass all segments to the one network layer. Demultiplexing (receiver): read the ports in each arriving segment and deliver its data to the right socket.
Figure: a laptop 198.51.100.10 with browser tab 1 (TCP 52344), browser tab 2 (TCP 52345) and a DNS resolver (UDP 50000); three segments arrive at the one IP (TCP from 203.0.113.5:80 to 52344, TCP from 203.0.113.5:80 to 52345, UDP from 198.51.100.53:53 to 50000) and are sorted by port.
- UDP demultiplexes by two values: destination IP and destination port; datagrams from any senders to one port share one socket.
- TCP demultiplexes by four values: source IP, source port, destination IP, destination port; a web server on port 80 has one socket per client connection.
Memory example: one postbag for the whole hostel sorted by room number into residents' boxes (demultiplexing); outgoing letters dropped in one bag, each with its room number as return address (multiplexing).
Older sense (also in the book): upward multiplexing, several transport connections share one network connection or address (saves cost where network connections are scarce or charged, like old virtual circuits; works while the shared bandwidth covers all needs); downward (inverse) multiplexing, one transport connection spread over several paths for bandwidth or resilience (Multipath TCP, RFC 8684; SCTP with several addresses).
Not the physical layer's multiplexing (FDM, TDM share a cable among signals, chapter 2): here one IP address is shared by processes and the port is the channel number.
Congestion: causes, the parameters that affect it, prevention and control
Congestion: the load offered to a network, or part of it, exceeds its capacity: router queues fill, delay climbs, packets are dropped and resent, useful throughput falls; at worst congestion collapse, the network busy with retransmissions and delivering almost nothing.
Congestion control is not flow control: flow control protects one receiver from one sender; congestion control protects the network's links and router buffers from all senders together. A fast laptop and a slow phone need flow control; a hostel uploading through one link needs congestion control.
Memory example: results day; thousands open the same results page at once; same links and server, only more load; pages time out, every refresh adds load (the collapse).
Causes (factors), in a WAN or any packet-switched network:
- Arrival rate above outgoing capacity: several inputs feeding one output line; its queue grows without limit.
- Too little buffer memory: drops when queues fill; more memory is no cure, packets wait until they time out and are resent as duplicates (Nagle, 1987).
- Bursty traffic: sources bursting together exceed capacity briefly.
- Slow processors and slow lines: a router that cannot queue, route and forward fast enough, or a low-bandwidth link.
- Retransmissions: congestion feeds itself.
- Poor routing, long packet lifetimes: one path overloaded while others idle; old packets wandering.
Parameters (policies) and their effect:
| Layer | Policy | Effect on congestion |
|---|---|---|
| Transport | retransmission policy | hasty timer or go-back-N resends more |
| Transport | out-of-order caching policy | discarding early segments forces resends |
| Transport | acknowledgement policy | ACK per segment adds traffic; delayed, piggybacked ACKs cut it |
| Transport | flow control policy | small window keeps the rate down |
| Transport | timeout determination | too short: duplicates; too long: slow recovery |
| Network | virtual circuits against datagrams | circuits allow admission control, reserved resources |
| Network | packet queueing and service policy | one queue or one per line; FIFO or fair turns |
| Network | packet discard policy | which packet is dropped when a queue is full |
| Network | routing algorithm | spreading traffic relieves hot spots |
| Network | packet lifetime management | too long: old packets clog; too short: packets die, resent |
| Data link | retransmission, out-of-order caching, acknowledgement, flow control | same effects on each link |
Load and delay (M/M/1 queue, service rate packets per second, random arrivals per second):
With = 1,000: = 500 gives 2 ms, 900 gives 10 ms, 990 gives 100 ms; the last 10% of load costs ten times the delay.
Prevention policies (open loop):
- Retransmission policy: good timers, no resending of merely late packets.
- Window policy: selective repeat instead of go-back-N.
- Acknowledgement policy: cumulative, delayed, piggybacked ACKs.
- Discard policy: routers drop least important packets first (some audio packets).
- Admission policy: a virtual circuit network refuses a flow that would congest it.
- Traffic shaping: agreed rate and burst size, smoothed before entry (leaky and token buckets).
| Family | Idea | Techniques |
|---|---|---|
| Open loop (prevention) | good design, no feedback | the policies, admission control, traffic shaping, resource reservation |
| Closed loop (removal) | monitor, feed back, adjust | backpressure (congested router asks the router before it to slow), choke packets to the source, implicit signalling (loss or delay, as TCP), explicit signalling (ECN bits), load shedding, random early detection (RED: drop a few early) |
Closed loop in three steps: detect congestion (queue lengths, drops, delay); send the information where action can be taken; adjust (slow the sources).
TCP's congestion control (RFC 5681): congestion window cwnd beside rwnd. Slow start: cwnd starts small, doubles each round trip up to a threshold. Congestion avoidance: plus one segment per round trip (additive increase). Three duplicate ACKs: halve cwnd (multiplicative decrease) with fast retransmit and fast recovery. Timeout: cwnd back to one segment, slow start again.
Traffic shaping regulates the average rate and burstiness of a flow before it enters the network, holding packets back to conform; policing only monitors and drops (or tags) packets that break the agreed profile. Both use the buckets.
The leaky bucket: bursty in, steady out
Leaky bucket algorithm: traffic shaping in which each host's interface holds a finite queue (the bucket) that accepts packets at any rate but releases them into the network at a constant rate; a packet arriving when the bucket is full is discarded.
Picture: a bucket with a hole; water in at any rate, out at a steady rate while any remains, none when empty; overflow spills and is lost. Packets for water, the interface queue for the bucket.
Figure: (a) water from a tap into a full bucket, overflow lost, steady drops below; (b) host, "full?" test (yes: discard; no: queue), packets removed at a constant rate into the network.
Fixed-size packets:
- Packet arrives; if the bucket is full, discard.
- Otherwise it joins the queue.
- Each clock tick one packet leaves; none if empty.
- Output: smooth, at most one packet per tick, however bursty the input.
Variable-size packets (byte counting, the book's version):
- At each tick set a counter to n bytes.
- While the head packet fits (size not more than the counter), send it and subtract its size.
- When the next packet does not fit, stop until the next tick.
- Reset the counter at the next tick; leftover count not carried forward, so no tick sends more than n bytes.
Worked example, n = 1,000 bytes a tick, packets 200, 700, 500, 300: tick 1 sends 200 (800 left) and 700 (100 left), 500 does not fit, 900 bytes sent, 100 not saved; tick 2 sends 500 (500 left) and 300 (200 left), queue empty. Fixed-size: a bucket of 6 packets draining 1 per millisecond, hit by 10 at once, keeps 6, discards 4, sends the 6 one per millisecond.
Memory example: the ceramic water filter in many Nepali kitchens; pour a whole jug in, clean water still drips at the same slow rate; overfill and it overflows.
- Good: removes burstiness completely; predictable constant-rate flow; simple (a queue and a clock).
- Rigid: same rate even when the network is idle; idle host saves nothing.
- Lossy: bursts bigger than the bucket lose packets.
- Slow to respond: urgent bursts still drained at the fixed rate.
The book captions the implementation figure on page 185 "Figure 4.15" in a chapter numbered 5.x.
The token bucket: saving up permission to burst
Token bucket algorithm: traffic shaping in which tokens drop into a bucket at constant rate r, up to capacity C, and a packet (or byte) leaves only by taking a token; an idle host saves tokens and may later burst up to C at the full line rate, while its long-run average stays r.
The bucket holds permission, not data; packets wait in the host's queue and go as fast as the line allows while tokens last.
Figure: (a) host with 5 packets waiting, bucket of capacity 3 holding 3 tokens, one token added every delta T, a new token discarded when full; (b) after: 3 packets sent at once, bucket empty, 2 waiting for tokens.
- Every delta T a token is added (r = 1/delta T per second); a full bucket (C tokens) discards the new token.
- A packet is sent only if a token is available, removing one (byte version: one token per byte).
- No token: the packet waits; the bucket throws away tokens, never packets.
- Implementation: one counter, plus 1 every delta T up to C, minus 1 per packet sent; at 0 nothing is sent.
Book example: 5 packets waiting, 3 tokens saved: 3 sent at once (a burst), 2 wait for the next tokens; a leaky bucket would release the 5 one tick apart.
Burst length: C capacity, r token rate, M maximum line rate, S burst length in seconds. During the burst the host sends MS, paid by the C saved plus rS arriving:
Worked example: a router shapes a hostel's upload; M = 10 Mbps, r = 2 Mbps, bucket full with C = 6 Mb (750 KB); a 12 Mb file sent at full speed.
- Burst: 0.75 s at 10 Mbps, 7.5 Mb (check: 6 saved plus 2 times 0.75 = 1.5 arriving = 7.5).
- Then 12 minus 7.5 = 4.5 Mb at 2 Mbps, 2.25 s; done at 3.0 s.
- A 2 Mbps leaky bucket takes 12 / 2 = 6 s; holding only 6 Mb it would lose 3.6 Mb of the burst.
Same average rate and long-run load; the token bucket finishes in half the time and loses nothing.
Figure: rate against time for the same 12 Mb burst: input 10 Mbps for 1.2 s; leaky bucket 2 Mbps for 6 s; token bucket 10 Mbps for 0.75 s then 2 Mbps until 3.0 s; equal areas (12 Mb).
Memory example: hostel meal coupons; one a day, unused ones pile up to three; after two light days eat three meals at once (burst), never more than one a day on average (rate). The leaky bucket is a mess serving exactly one plate a day, hungry or not.
| Point | Leaky bucket | Token bucket |
|---|---|---|
| Bucket holds | packets | tokens (permission) |
| Output | constant r | average r, bursts up to C at line rate |
| Idle host | saves nothing | saves tokens up to C |
| Bucket full | arriving packets discarded | arriving tokens discarded; packets wait |
| Burstiness | removed | allowed, bounded by C |
| Sudden burst | drained slowly at r | sent at once while tokens last |
| Idle network | wasted | used by the saved burst |
| Parameters | queue size, output rate | token rate r, bucket size C |
| Implementation | queue and clock (or byte counter reset each tick) | token counter and queue |
Why the token bucket controls congestion better: both hold the long-run rate at r, so the average load is bounded as before; but a quiet host can use the capacity it left unused, bursts go at once, no data is lost when the bucket fills (only tokens), and the worst-case burst is capped at C, so the network knows the most it must absorb.
Both together: a leaky bucket of rate p (r below p below M) after the token bucket caps the peak rate, while the token bucket keeps the average at r.
Proposed traffic shaping approach for a packet-switched network:
- Agree a profile with each source at the edge: average r, burst C, peak p if needed.
- Shape at the source: token bucket (r, C), then a leaky bucket at p.
- Police at the edge router: in-profile packets pass; excess dropped or tagged low priority.
- Closed-loop backing: TCP's congestion window at hosts, early dropping or ECN at routers.
Why best: fixed average load per source (plannable), bounded bursts, no loss while the source keeps its profile, idle capacity used. ISPs enforce plan speeds this way; the Internet's quality of service schemes describe a flow by a token bucket rate and depth.
On "never discards packets" (the book, like Tanenbaum): true of the bucket itself; a shaper's packet queue is finite and can overflow, and a policer built on a token bucket drops or tags packets that find no token. The point: a full bucket of tokens costs no data.
Chapter 6: Application layer 8240 words
The application layer: what it does, and the ports its protocols use
Application layer: the top layer of the TCP/IP model, home of network applications and their protocols. An application layer protocol defines the messages two application processes exchange: their types (request, reply), syntax (fields), meaning, and the rules for when a process sends what. It hands its messages to TCP or UDP to carry.
- Only end systems run it: routers and switches work at the network layer and below; only the browser and the web server read the HTTP messages. New applications spread without changing routers.
- Client-server: an always-on server with a fixed address and a well-known port serves many clients that never talk to each other directly (web, mail, FTP, DNS).
- Peer-to-peer (P2P): ordinary hosts both ask and serve, with little or no central server (BitTorrent).
- Sockets: a process hands its message to its socket, the door between the application and the transport layer; the message is addressed by the destination IP address and port. Servers wait on well-known ports (0 to 1023); the client's port is a temporary one picked by its operating system.
- Transport needs: reliability, throughput, low delay, security. TCP for the web, mail and file transfer; UDP (no connection setup) for DNS queries, DHCP, SNMP, TFTP and live voice.
| Protocol | Job | Transport | Server port |
|---|---|---|---|
| HTTP | fetch web pages and objects | TCP | 80 |
| HTTPS | HTTP inside TLS | TCP | 443 |
| FTP | file transfer with a login | TCP | 21 control, 20 data (active mode) |
| SSH, SCP, SFTP | encrypted remote login and copy | TCP | 22 |
| Telnet | plain-text remote login | TCP | 23 |
| SMTP | send and relay mail | TCP | 25 between servers, 587 from a user agent |
| DNS | names to addresses | UDP; TCP for zone transfers and long replies | 53 |
| DHCP | give a host its IP settings | UDP | 67 server, 68 client |
| TFTP | simple file transfer, no login | UDP | 69 |
| POP3 | download mail from a mailbox | TCP | 110 (995 with TLS) |
| IMAP | manage mail kept on the server | TCP | 143 (993 with TLS) |
| SNMP | monitor and manage devices | UDP | 161 agent, 162 traps |
Memory example: the IP address is the ward office building, the port the counter number inside; counter 25 takes letters, 53 answers "where is this name?", 80 hands out pages.
HTTP and HTTPS: how a browser's request is served
HTTP (HyperText Transfer Protocol): the web's application layer protocol, a stateless request and response protocol: the client (browser) sends a request naming an object by its URL; the web server returns it in a response; both over a TCP connection to port 80. HTTPS: HTTP inside an encrypted TLS connection, port 443.
- Web page: a base HTML file plus referenced objects (images, style sheets, scripts), each named by a URL. In
https://www.example.com:443/notes/ch6.html?lang=np: schemehttps, hostwww.example.com, port443(omitted when default), path/notes/ch6.html, querylang=np. A page with ten images costs eleven requests.
How a request is served:
- Name to address: DNS lookup of the host name.
- Connection: TCP three-way handshake to port 80 (443 plus the TLS handshake for HTTPS).
- Request: request message, for example
GET /index.html HTTP/1.1and header lines. - Processing: the server parses it, maps the path to a file under its document root, or runs a program (PHP) for a dynamic page, and builds the response.
- Response: status line (
HTTP/1.1 200 OK), header lines, the object as body. - Render and repeat: the browser parses the HTML, requests each referenced object, draws the page.
- Close or keep: close, or keep the connection for the next request (persistent HTTP).
Figure: a time sequence of SYN, SYN+ACK, ACK with GET, 200 OK with the page, a second GET on the same connection, and FIN; one RTT for the handshake, one RTT plus transfer for the page; the request and response messages beside it.
GET /notes/ch6.html HTTP/1.1
Host: www.example.com
User-Agent: Mozilla/5.0
Accept: text/html
Accept-Language: en, ne
Connection: keep-alive
HTTP/1.1 200 OK
Date: Sun, 04 Oct 2026 09:00:00 GMT
Server: Apache
Last-Modified: Fri, 02 Oct 2026 16:30:00 GMT
Content-Type: text/html; charset=UTF-8
Content-Length: 5120
<!DOCTYPE html><html> ... the page ... </html>
Request message: request line (method, path, version), header lines Name: value, blank line, optional body (form data with POST). Response: status line (version, code, phrase), headers, blank line, body.
| Method | What it asks |
|---|---|
| GET | send the object at this URL |
| HEAD | the headers GET would send, no body |
| POST | process this data (login form, upload) |
| PUT | store this body at this URL |
| DELETE | remove the object |
| PATCH, OPTIONS, CONNECT, TRACE | partial change; allowed methods; tunnel through a proxy (HTTPS); echo |
| Class | Meaning | Common codes |
|---|---|---|
| 1xx | informational | 100 Continue, 101 Switching Protocols |
| 2xx | success | 200 OK, 201 Created, 204 No Content |
| 3xx | redirection | 301 Moved Permanently, 302 Found, 304 Not Modified |
| 4xx | client error | 400 Bad Request, 401 Unauthorized, 403 Forbidden, 404 Not Found |
| 5xx | server error | 500 Internal Server Error, 502 Bad Gateway, 503 Service Unavailable |
- Stateless: the server keeps no memory of earlier requests; simple, easy to multiply. Cookies add memory:
Set-Cookie: session=8f2ain a response,Cookie: session=8f2ain every later request; the server looks the number up in its database (a canteen token). - Non-persistent (HTTP/1.0 default): one TCP connection per object, 2 RTT each plus transmission time. Persistent (HTTP/1.1 default,
Connection: keep-alive): one RTT per later object, less with pipelining.
Example: one HTML file and 10 images, RTT 50 ms: non-persistent 11 x 2 RTT = 22 RTT = 1,100 ms; persistent 2 + 10 = 12 RTT = 600 ms; persistent with pipelining 3 RTT = 150 ms.
| Version | Year | What it brought |
|---|---|---|
| HTTP/1.0 | 1996, RFC 1945 | one object per connection |
| HTTP/1.1 | 1997, now RFC 9112 | persistent connections, pipelining, Host header, chunked transfer |
| HTTP/2 | 2015, now RFC 9113 | binary frames, multiplexed requests, header compression |
| HTTP/3 | 2022, RFC 9114 | over QUIC on UDP with TLS 1.3; faster start, no stall of all streams on one loss |
HTTPS: TCP to port 443, then the TLS handshake: the server's certificate (signed by a trusted certificate authority) and agreed session keys; then every message encrypted and integrity-checked. It gives server authentication (defeats a fake site, man in the middle), confidentiality, integrity. It does not hide the server's IP, usually the site name (sent in the handshake), or traffic size and timing. Browsers label plain HTTP pages "Not secure"; search engines give HTTPS a small ranking boost.
| Point | HTTP | HTTPS |
|---|---|---|
| Full name | HyperText Transfer Protocol | HTTP Secure: HTTP over TLS (formerly SSL) |
| Default port | 80 | 443 |
| URL | http:// | https:// |
| Layering | HTTP over TCP | HTTP over TLS over TCP |
| On the wire | plain text, readable and changeable | encrypted, integrity-checked |
| Server identity | not proved | certificate from a CA |
| Setup cost | TCP handshake | TCP plus TLS handshake (one round trip in TLS 1.3) |
| Used for | redirects, local tests | logins, payments (eSewa), every modern site |
- Web server: Apache httpd, Nginx, Microsoft IIS. Listens on 80 and 443; per request: parse, check access, map the path to a file under the document root (
GET /index.htmlgives/var/www/html/index.html) or hand it to a program (PHP, Python, Node.js), respond with status and headers, log it. Concurrency: process or thread per connection (Apache) or an event loop (Nginx). Virtual hosting: many sites on one IP, chosen by theHost:header. - Web server communication: DNS (UDP 53) for the address, TCP for the connection (80 or 443), TLS for HTTPS, HTTP for request and response, IP for routing.
- The book's claim that HTTPS is slower: only a new connection pays for TLS (one round trip in TLS 1.3); with persistent connections and HTTP/2 rarely slower.
Memory example: HTTP is a postcard every post office can read and rewrite; HTTPS a sealed, verified envelope, only the address visible.
FTP and TFTP: copying files across the network
FTP (File Transfer Protocol, RFC 959): the standard TCP/IP protocol for copying files between client and server after a login, over two TCP connections: a control connection to server port 21, open for the whole session (commands and replies), and a data connection, server port 20 in active mode, opened for each file or listing and closed after it.
- Out of band: commands never mix with file bytes; ABOR can stop a transfer; the control channel is one text command, one reply. HTTP is in band.
- Model: each side has a control process (protocol interpreter) and a data transfer process; the client adds the user interface.
How a client connects:
- Control connection: TCP to port 21;
220 Service ready. - Login:
USER anuj,331 Password required;PASS,230 User logged in(530 if wrong). Public archives accept user anonymous. - Settings:
TYPE Ibinary,TYPE Atext;200. - Data connection: active:
PORT 192,168,1,10,195,80(port 195 x 256 + 80 = 50000), the server connects from port 20; passive:PASV,227 Entering Passive Modewith a high port, the client connects. - Transfer:
RETRdownload,STORupload,LISTlisting;150, bytes on the data connection, data connection closes,226 Transfer complete. - Repeat, then quit: a new data connection per file;
QUIT,221 Goodbye.
Figure: an FTP session in active mode: control messages to port 21 and back, then the data connection from port 20 to client port 50000, then 226 and QUIT; notes on control, data and passive mode.
| Point | Active (PORT) | Passive (PASV) |
|---|---|---|
| Opens the data connection | server, from port 20 | client |
| To | client's port in PORT | server's high port in the 227 reply |
| NAT and firewalls | often blocked | passes: both connections outward from the client |
| Today | rare | default in most clients (FileZilla, WinSCP) |
| Command | Meaning | Typical reply |
|---|---|---|
| USER, PASS | log in | 331, then 230 (530 on failure) |
| CWD, PWD | change, print directory | 250, 257 |
| LIST | listing on a data connection | 150, then 226 |
| RETR, STOR | download, upload | 150, then 226 |
| TYPE A, TYPE I | ASCII or binary image | 200 |
| PORT, PASV | active or passive data connection | 200, 227 |
| QUIT | end the session | 221 |
- Reply codes: first digit 1 started (wait), 2 done, 3 send the next part, 4 temporary failure, 5 permanent failure.
- Data types: ASCII, EBCDIC, image (binary). Modes: stream (default), block, compressed. A photo in ASCII mode is damaged by line-ending conversion.
- Stateful: the server remembers user, directory and type for the session (HTTP is stateless).
- Not secure: password in plain text (visible in Wireshark); FTPS (FTP over TLS) or SFTP instead.
Memory example: a shop counter (control connection) for the whole visit; a back door opened for each parcel (data connection); active, the shopkeeper delivers to the customer's gate (locked by NAT); passive, he names a door and the customer collects.
TFTP (Trivial File Transfer Protocol, RFC 1350): UDP port 69, no login, no listing, only read and write.
- Packets: RRQ (opcode 1), WRQ (2), DATA (3), ACK (4), ERROR (5).
- Lock step: numbered 512-byte blocks, each ACKed before the next (stop and wait); resent after a timeout; a block under 512 bytes ends the file: 2,000 bytes go as 512, 512, 512, 464; exactly 1,024 bytes needs a final empty block.
- Ports: request to 69; the server answers from a fresh port that carries the transfer.
- Uses: booting diskless machines (PXE), loading firmware and configuration onto routers, switches and IP phones (
copy tftp); small enough for a boot ROM.
| Point | FTP | TFTP |
|---|---|---|
| Transport | TCP | UDP |
| Ports | 21 control, 20 data | 69, then a fresh port |
| Login | user name, password | none |
| Commands | dozens | read or write only |
| Reliability | TCP's | each 512-byte block ACKed |
| Use | general file transfer | booting, device images |
- File servers in a LAN: SMB (Windows file sharing, TCP 445), NFS (Unix, port 2049): mount a remote folder.
- The book gives port 20 for data without saying it holds only in active mode; in passive mode the server names a high port in its 227 reply.
Remote login and secure transfer: Telnet, SSH, PuTTY and WinSCP
SSH (Secure Shell): encrypted remote login and command execution over TCP port 22; the same channel carries file transfer (SCP, SFTP) and forwarded ports.
- Telnet (RFC 854, TCP 23): remote terminal in plain text, password included; replaced by SSH.
- SSH versions: SSH-1 1995; SSH-2 standardised 2006 (RFC 4251 to 4254).
- Transport layer: server's host key, key agreement, encryption and integrity; fingerprint prompt on first connection.
- User authentication: password, or a key pair (public key in
~/.ssh/authorized_keys, private key stays on the laptop). - Connection layer: many channels: shell, file transfer, forwarded ports.
| Tool or protocol | Does | Port | Encrypted |
|---|---|---|---|
| Telnet | remote terminal | 23 | no |
| SSH | remote terminal and commands | 22 | yes |
| SCP | copy files over SSH | 22 | yes |
| SFTP | SSH File Transfer Protocol: list, rename, delete, resume | 22 | yes |
| FTPS | FTP inside TLS (not SFTP) | 21 (990 implicit) | yes |
- PuTTY: free, open-source Windows terminal emulator by Simon Tatham; client for SSH, Telnet, rlogin, raw TCP, serial; log in to a Linux server or a router console. PuTTYgen makes key pairs (
.ppk), Pageant holds keys, pscp and psftp copy files. - WinSCP: free, open-source Windows client for SFTP, SCP and FTP (FTPS) with two panels and drag and drop; SSH code from PuTTY, FTP code from FileZilla.
Memory example: a final-year team logs in to the college Linux server with PuTTY and drags the build folder over with WinSCP, both on port 22; Telnet and FTP would expose the password on the hostel Wi-Fi.
Electronic mail: user agents, mail servers, SMTP, POP3, IMAP and MIME
Electronic mail: an asynchronous message service of user agents (write, read), mail servers (a mailbox per user, a queue of outgoing mail) and protocols: SMTP pushes mail to and between servers (TCP 25); POP3 or IMAP pulls it from the mailbox to the reader.
- Asynchronous: sender and receiver need not be online together (Sita in Pokhara at night, Ram in Kathmandu next morning). Addresses here are defanged:
ram@example[.]org.
| Component | What it is | Examples |
|---|---|---|
| User agent (UA) | compose, read, reply, forward, file mail | Outlook, Thunderbird, Gmail app, browser (webmail) |
| Mail server | mailbox per user, outgoing queue, runs the agents | a college's or company's server, Gmail's servers |
| MTA (message transfer agent) | SMTP software moving mail between servers | Postfix, Sendmail, Exim, Microsoft Exchange |
| MDA (message delivery agent) | places arriving mail in the right mailbox, often after a spam filter | procmail, Dovecot's delivery agent |
| MAA (message access agent) | the POP3 or IMAP server the reader pulls from | Dovecot, Courier |
- Email server: a host running these programs; accepts mail for its domain (the DNS MX record points other servers to it), stores it, lets users fetch it, relays their outgoing mail.
How one mail travels:
- Compose: Sita writes to
ram@example[.]organd presses Send. - Submit: her agent hands it to her mail server with SMTP (port 587, after login); it waits in the queue.
- Find the server: her server looks up the MX record of
example.org. - Transfer: TCP to that server's port 25, SMTP push; if it is down, the mail stays queued and is retried for days before a bounce.
- Deliver: the receiving MDA puts it in Ram's mailbox.
- Read: Ram's agent pulls it with POP3 or IMAP; webmail uses HTTPS in a browser.
Figure: the mail system: Sita's agent, SMTP 587, sender's server, DNS MX lookup, SMTP 25, receiver's server with Ram's mailbox, POP3 or IMAP (110 or 143), Ram's agent; push on the left, pull on the right.
- Push, then pull: SMTP is push (the holder of the mail starts); it cannot fetch from a mailbox and the reader's computer is not always on, so the last hop is pull (POP3, IMAP). Mail goes to an always-on server, not to the laptop.
SMTP (Simple Mail Transfer Protocol, RFC 821 of 1982, now RFC 5321): text commands, three-digit replies; every mail server is an SMTP client when sending and a server when receiving. Three phases:
- Connection setup: TCP to 25;
220greeting;HELO(orEHLO, which asks for extensions);250. - Mail transfer:
MAIL FROM:sender (250);RCPT TO:per recipient (250, or550no such mailbox);DATA(354); header lines, blank line, body, a line holding only ".";250. - Termination:
QUIT;221; TCP closes. Several messages may go before QUIT.
Figure: an SMTP session as a sequence diagram, grouped into connection setup, mail transfer and termination.
S: 220 mail.example.org ESMTP ready
C: HELO mail.example.com
S: 250 mail.example.org
C: MAIL FROM:<sita@example[.]com>
S: 250 OK
C: RCPT TO:<ram@example[.]org>
S: 250 OK
C: DATA
S: 354 End data with <CR><LF>.<CR><LF>
C: From: Sita <sita@example[.]com>
C: To: Ram <ram@example[.]org>
C: Subject: Lab report
C:
C: Ram, the lab report is attached.
C: .
S: 250 OK: queued
C: QUIT
S: 221 Bye
| Command | Meaning | Usual reply |
|---|---|---|
| HELO, EHLO | client names itself (after 220) | 250 |
| MAIL FROM: | sender, where a bounce goes | 250 OK |
| RCPT TO: | one recipient, repeated | 250 OK, or 550 |
| DATA | the message follows | 354; 250 after the "." |
| QUIT | end | 221 |
| RSET, VRFY, NOOP | abort mail; check user; nothing | 250 |
- Reply codes: 2xx done, 3xx send the rest, 4xx temporary (421 service not available, 450 mailbox busy), 5xx permanent (550).
- Rules: 7-bit ASCII (0 to 127) in commands, headers and body; lines at most 1,000 characters with CR LF; a body line starting with "." gets an extra dot (dot stuffing).
- Envelope and header:
MAIL FROMandRCPT TOare the envelope for servers;From:andTo:inside DATA are the letter's header for the reader. - Security: SMTP checks no sender (spam, forgery); SPF, DKIM, DMARC records in DNS let receivers check; STARTTLS encrypts each hop; PGP or S/MIME for end to end.
POP3 (RFC 1939, TCP 110, 995 with TLS): log in, download, usually delete. States: authorization (USER, PASS), transaction (STAT, LIST, RETR, DELE), update (deletions applied after QUIT). Modes: download-and-delete (one computer), download-and-keep.
S: +OK POP3 server ready
C: USER ram
S: +OK
C: PASS ********
S: +OK 2 messages (6800 octets)
C: LIST
S: 1 1200
S: 2 5600
S: .
C: RETR 1
S: +OK 1200 octets ... (the whole message) ... .
C: DELE 1
S: +OK message 1 deleted
C: QUIT
S: +OK bye
IMAP (IMAP4rev1 RFC 3501, IMAP4rev2 RFC 9051; TCP 143, 993 with TLS): mail and folders stay on the server; state (read, answered, flagged, deleted) kept across sessions; many devices see one mailbox; fetch headers only or one part; search on the server; tagged commands.
C: a1 LOGIN ram ********
S: a1 OK LOGIN completed
C: a2 SELECT INBOX
S: * 2 EXISTS
S: a2 OK [READ-WRITE] SELECT completed
C: a3 FETCH 1 (BODY.PEEK[HEADER.FIELDS (FROM SUBJECT)])
S: * 1 FETCH (... From: Sita ... Subject: Lab report ...)
S: a3 OK FETCH completed
C: a4 LOGOUT
| Point | POP3 | IMAP |
|---|---|---|
| Where mail lives | downloaded, usually deleted from server | on the server until deleted |
| Folders | only INBOX on the server | created, renamed, deleted on the server |
| Several devices | mail scatters | same mailbox everywhere |
| State | none between sessions | read, answered, flagged kept |
| Partial download | whole messages | headers or one part |
| Search | local copy | on the server |
| Offline | easy | needs a local cache |
| Server storage | small | large |
| Complexity | simple | complex |
| Port | 110 (995) | 143 (993) |
MIME (Multipurpose Internet Mail Extensions, RFC 2045 to 2049): SMTP carries 7-bit ASCII; photos, PDFs and Nepali text have bytes 128 to 255 and long unbroken runs. MIME adds headers describing each part and encodes any bytes as 7-bit text; the receiving agent decodes.
| Header | Says | Example |
|---|---|---|
| MIME-Version | MIME is used | 1.0 |
| Content-Type | media type | text/plain, text/html, image/jpeg, application/pdf, multipart/mixed |
| Content-Transfer-Encoding | how made 7-bit safe | 7bit, quoted-printable, base64 |
| Content-Disposition | inline or attachment | attachment; filename="phewa.jpg" |
| Content-ID, Content-Description | a label; a description | an image inside an HTML mail |
- Base64: 3 bytes (24 bits) at a time, four 6-bit groups, each one of 64 characters: A to Z (0 to 25), a to z (26 to 51), 0 to 9 (52 to 61), + (62), / (63); = pads the end; lines every 76 characters; size grows by a third (a 3 MB photo travels as about 4 MB).
- Example "Ram":
52 61 6D=01010010 01100001 01101101, regrouped010100 100110 000101 101101= 20, 38, 5, 45 =UmFt. - Example JPEG: every JPEG starts
FF D8 FF=11111111 11011000 11111111= 63, 61, 35, 63 =/9j/. - Quoted-printable: for mostly ASCII text; other bytes become = and two hex digits: Nepali न (UTF-8
E0 A4 A8) is=E0=A4=A8. A Nepali subject नमस्ते becomes the encoded word=?UTF-8?B?4KSo4KSu4KS44KWN4KSk4KWH?=.
Figure: base64 of FF D8 FF: 24 bits, four 6-bit groups, values 63, 61, 35, 63, characters /9j/, the alphabet and the MIME headers.
From: Sita <sita@example[.]com>
To: Ram <ram@example[.]org>
Subject: Photo from Phewa Lake
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="XyZ42"
--XyZ42
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 7bit
Here is the photo from the boat.
--XyZ42
Content-Type: image/jpeg; name="phewa.jpg"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="phewa.jpg"
/9j/4AAQSkZJRgAB ... (about 4 MB of base64 text) ...
--XyZ42--
- The book's table slips: POP3's one folder is the INBOX (the book prints "index folder"); "IMAP storage limited to 2 GB" is a provider's quota, not an IMAP limit.
Memory example: the postal service: UA the letter writer, her mail server the local post office, SMTP the van between post offices (delivers, never collects), the mailbox a PO box; POP3 empties the PO box and takes everything home, IMAP reads at the counter with letters kept in labelled folders.
DNS: the Internet's distributed directory of names
DNS (Domain Name System, RFC 1034 and 1035): a distributed, hierarchical database of names and the application layer protocol to query it; maps host names such as www.ioe.edu.np to IP addresses (and back); mostly UDP port 53.
Why it is used:
- Names for people, numbers for machines: people remember
youtube.com; routers forward on 32-bit or 128-bit addresses. - Freedom to move: a site changes server and address; only the record changes.
- One name, many servers: load spreading; a CDN gives each user its nearest copy.
- More than addresses: MX (mail server), CNAME (alias), PTR (name of an address).
- Distributed: before DNS (designed 1983) every host copied one HOSTS.TXT from the SRI Network Information Center; one table would be a single point of failure, a traffic jam, impossible to keep current; DNS splits it among countless servers, each run by the owner of its part.
Memory example: the phone's contact list: dial "Aama", not her number; a new SIM changes only the entry.
- Name space: an inverted tree; each node a label of up to 63 characters; the root's label empty. A domain name is the labels read upward, joined by dots:
www.youtube.com., the final dot the root. With the dot: FQDN (fully qualified); without (wwwinside a campus): PQDN, completed by the resolver. A full name is at most 255 bytes. - Root: one, unnamed; 13 root server identities
a.root-servers.nettom.root-servers.net, run by 12 organizations, copied worldwide by anycast. - TLDs: generic (com, org, net, edu, gov, info, newer ones), country codes (np, in, uk, jp), arpa for reverse lookups. Verisign runs com and net; np is run by Mercantile Communications.
- Below: com.np, edu.np, gov.np, org.np under np;
ioe.edu.np,pcampus.edu.npunder edu.np; owners create names below their own.
Figure: the name space tree: root; com, org, net, edu, np; youtube and example under com, wikipedia under org, mit under edu, edu and gov under np; www under youtube; ioe and pcampus under edu.np; the path www.youtube.com highlighted; zones youtube.com and ioe.edu.np outlined.
| Name server | What it holds or does | Example |
|---|---|---|
| Root | servers of every TLD; answers with referrals | a to m.root-servers.net |
| TLD | authoritative servers of every domain under its TLD | a.gtld-servers.net for com |
| Authoritative | a zone's records from its zone file; primary plus secondaries by zone transfer | ns1.google.com for youtube.com |
| Local (resolver) | outside the tree; the server a host asks (set by DHCP); resolves for hosts, caches | ISP resolver (NTC, WorldLink), public 8.8.8.8 or 1.1.1.1 |
- Caching: every answer has a TTL in seconds; the resolver keeps it that long; after the first hostel student looks up youtube.com, the next hundred are answered from the ISP's resolver; TLD server addresses are cached too, so the root is rarely asked; failed lookups are cached too (negative caching).
- Recursive query: the server asked must return the answer or an error, asking other servers itself.
- Iterative query: the server asked replies at once: the answer, or a referral (servers closer to the answer); the asker continues. The RD (recursion desired) flag states the wish.
Figure: iterative resolution of www.youtube.com in eight numbered steps among host, local server, root, .com TLD and authoritative server.
Iterative lookup of www.youtube.com:
- Host to local server: query for
www.youtube.com, type A, RD set, to the ISP's resolver (nothing cached). - Local server to root.
- Root's referral: NS records of com (
a.gtld-servers.netand siblings) in the authority section, their addresses (glue) in the additional section. - Local server to a com server.
- TLD's referral:
ns1.google.comand siblings, with addresses. - Local server to
ns1.google.com. - Answer: the A record, AA set (a CNAME is looked up again the same way).
- Back to the host: every record cached for its TTL; the address returned; the browser connects.
The host sent one query; the local server three.
Figure: recursive resolution of www.youtube.com: host to local, local to root, root to TLD, TLD to authoritative, and the answer back along the chain in steps 5 to 8.
- Fully recursive: root asks TLD, TLD asks authoritative, answer climbs back; loads servers up the tree, which would hold state for millions of queries; root and TLD servers refuse (RA clear). In practice: host to local server recursive, local server's queries iterative.
| Point | Recursive | Iterative |
|---|---|---|
| Who works | the server asked | the asker |
| Reply | answer or error | answer or referral |
| Load | heavy: waits, keeps state | light: answers at once |
| Messages for asker | one query, one reply | one per server visited |
| Caching | the server caches | the asker caches the chain |
| Flags | RD set, RA set | RD clear, or no recursion offered |
| Typical use | host to local server | local to root, TLD, authoritative |
- Inverse query (older texts): the name for an address; now an ordinary PTR query: 192.0.2.80 becomes
80.2.0.192.in-addr.arpa(bytes reversed); the inverse opcode is obsolete. - Resource record fields: NAME (owner), TYPE, CLASS (IN), TTL (seconds cacheable), data (RDATA; RDLENGTH on the wire).
| Type | Code | Data | Example (zone example.com) |
|---|---|---|---|
| A | 1 | IPv4 address | www A 192.0.2.80 |
| AAAA | 28 | IPv6 address | www AAAA 2001:db8::80 |
| CNAME | 5 | canonical name of an alias | ftp CNAME www.example.com. |
| MX | 15 | mail server, preference (lower first) | example.com. MX 10 mail.example.com. |
| NS | 2 | authoritative name server | example.com. NS ns1.example.com. |
| PTR | 12 | name for an address | 80.2.0.192.in-addr.arpa. PTR www.example.com. |
| SOA | 6 | primary server, admin mailbox, serial, timers | one per zone |
| TXT | 16 | free text: SPF, DKIM, ownership proofs | example.com. TXT "v=spf1 mx -all" |
$TTL 3600
example.com. IN SOA ns1.example.com. admin.example.com. (
2026100401 ; serial: raised on every change
7200 ; refresh: secondaries check every 2 hours
900 ; retry
1209600 ; expire: 14 days
300 ) ; TTL for "no such name" answers
example.com. IN NS ns1.example.com.
example.com. IN NS ns2.example.com.
example.com. IN MX 10 mail.example.com.
ns1 IN A 192.0.2.53
www IN A 192.0.2.80
www IN AAAA 2001:db8::80
mail IN A 192.0.2.25
ftp IN CNAME www.example.com.
example.com. IN TXT "v=spf1 mx -all"
- Delegation: a zone is the part of the tree one set of authoritative servers answers for; a parent delegates a subtree by NS records for the child in its own zone, plus glue A records when the child's servers are named inside the child; then the child's owner changes names without asking. Root delegates np; np delegates edu.np; edu.np delegates ioe.edu.np to IOE's name servers. A referral is the parent reading out its delegation. Glue example: pcampus.edu.np is served by
dns1.pcampus.edu.npanddns2.pcampus.edu.np, inside the child, so the edu.np zone also holds their addresses.
; inside the com zone, run by Verisign
youtube.com. NS ns1.google.com. ; delegation to Google's servers
example.com. NS ns1.example.com. ; delegation
ns1.example.com. A 192.0.2.53 ; glue: the server sits inside the child
- Message: one format for query and response: a 12-byte header (identification copied by the reply; flags QR, Opcode, AA, TC, RD, RA, Z, RCODE with 0 no error and 3 no such name; QDCOUNT, ANCOUNT, NSCOUNT, ARCOUNT), then question (name, type, class), answer (records), authority (NS records, referrals), additional (extras such as glue).
Figure: the DNS header 16 bits wide (ID; QR, Opcode, AA, TC, RD, RA, Z, RCODE; four counts), the four sections, and a resource record's fields (NAME, TYPE 16, CLASS 16, TTL 32, RDLENGTH 16, RDATA).
Example: query ID 0x1A2B (6699), QR 0, Opcode 0, RD 1, QDCOUNT 1; question www.example.com A IN; name on the wire 3 www 7 example 3 com 0, 17 bytes; 12 + 17 + 4 = 33 bytes in one UDP datagram to port 53. Response: same ID, QR 1, RD 1, RA 1, AA 0 from a cache, RCODE 0, ANCOUNT 1; answer www.example.com 3600 IN A 192.0.2.80, its name a 2-byte pointer to the question (compression); 33 + 16 = 49 bytes.
dig www.example.com A
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 6699
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0
;; QUESTION SECTION:
;www.example.com. IN A
;; ANSWER SECTION:
www.example.com. 3600 IN A 192.0.2.80
- UDP and TCP: one datagram each way, no handshake, lost queries simply repeated; TCP 53 for zone transfers and replies over the UDP limit (512 bytes originally, raised by EDNS): the server sets TC, the resolver retries over TCP.
- The book's four components: name space, name servers, resolvers, cache. Forged replies can poison a cache; DNSSEC signs records.
- The book's slips: "it is easier to remember an IP address" (names are easier); Network Solutions managing the root and com (1990s); today IANA (ICANN) manages the root zone and Verisign, which bought Network Solutions, runs com.
DHCP: how a host gets its address, and how the lease is renewed
DHCP (Dynamic Host Configuration Protocol, RFC 2131): client-server over UDP (server 67, client 68); leases a host an IP address for a limited time, with subnet mask, default gateway and DNS servers; no manual configuration.
- Why: devices work at once on a new network; a limited pool is shared (addresses return when leases end); settings changed in one place; no duplicate addresses. Reserved (fixed) addresses by MAC for printers and servers. Grew out of BOOTP, keeps its message format.
DORA:
- DHCPDISCOVER: broadcast from
0.0.0.0:68to255.255.255.255:67. - DHCPOFFER: each server offers an address (
192.168.1.23), mask, gateway, DNS, lease time. - DHCPREQUEST: broadcast, naming the chosen server; others withdraw their offers.
- DHCPACK: the lease starts; the client checks the address with ARP (DHCPDECLINE if in use).
Figure: DORA between a laptop with no address and the DHCP server at 192.168.1.1, with the addresses and ports of each message.
- Other messages: DHCPNAK (refuse), DHCPRELEASE (give back), DHCPDECLINE (in use), DHCPINFORM (fixed address, other settings only).
- Bound (0 to T1): use the address.
- Renewing (from T1): unicast DHCPREQUEST to the granting server; DHCPACK renews (fresh full lease) and restarts the timers; DHCPNAK: stop, DISCOVER again; no reply: keep asking.
- Rebinding (from T2): broadcast DHCPREQUEST to any server; any ACK renews.
- Expiry: no ACK by the end: stop using the address at once; INIT, then DISCOVER.
Figure: the 24-hour lease on a time line: bound to 12 h, renewing to 21 h, rebinding to 24 h, an arrow back to the start for an ACK, and the action at T1, T2 and expiry.
Example: a phone joins hostel Wi-Fi at 07:00 with a 24-hour lease; T1 = 12 h, renewal at 19:00 (normally answered, held until 19:00 next day); if the router is down, T2 = 21 h, broadcast at 04:00; no answer by 07:00 next day: drop the address, DORA again. An 8-day lease gives T1 = 4 days, T2 = 7 days.
- Client states: INIT, SELECTING, REQUESTING, BOUND, RENEWING, REBINDING.
- Relay agent: broadcasts stop at routers; a relay on each router interface (Cisco
ip helper-address) forwards by unicast to the server and writes its address in the gateway field, so the server picks the right subnet's pool.
Memory example: a library book: borrowing is DORA; renew at the same desk halfway (T1); any desk near the due date (T2); return on the due date.
Peer-to-peer applications: BitTorrent and distributed hash tables
P2P application: end hosts (peers) talk directly, each both client and server, with little or no always-on server.
- Central index: one server knows who has what; files peer to peer (Napster, 1999); single point of failure.
- Query flooding: searches passed neighbour to neighbour (Gnutella); floods the network.
- Super peers: well-connected peers index their neighbours (KaZaA).
- Structured DHT: each key has one home, found in a few hops (Chord, Kademlia).
- Scaling: each peer that receives a part also uploads it; newcomers add capacity.
Example: F = 800 Mbit (100 MB), N = 100, server upload 100 Mbit/s, peers upload 10 and download 50 Mbit/s: client-server max(800 s, 16 s) = 800 s; P2P max(8 s, 16 s, 80,000 / 1,100 = 72.7 s) = about 73 s, eleven times faster.
- BitTorrent (Bram Cohen, 2001):
.torrentfile or magnet link (name, piece size, a hash per piece, tracker address); tracker lists the swarm; seeders (whole file) and leechers (downloading, uploading what they have); equal pieces, rarest first; each piece checked against its hash; tit for tat: upload to the 4 fastest uploaders, re-chosen every 10 s, plus one optimistic unchoke every 30 s. - DHT: peers and keys share an ID space (for example 160 bits); a key is stored at the closest peer ID; each lookup hop halves the distance: about log2 N hops (about 20 for a million peers). BitTorrent's trackerless mode: Kademlia, key = info-hash, value = peer list.
- Good and bad: no single point of failure, grows with users; heavy upload use, NAT trouble, hard to control, piracy, malware risk. Others: early Skype, Bitcoin, WebRTC calls.
Memory example: classmates sharing notes the night before an exam: each copies one chapter and swaps instead of queueing at the one photocopy shop.
Socket programming: the calls, and a TCP server and client
Socket programming: writing network applications against the socket API, the interface between an application process and the transport layer; a socket is an endpoint named by an IP address and a port; programs create, connect, read, write and close sockets with system calls.
- Berkeley (BSD) sockets: 4.2BSD Unix, 1983; copied by Linux, Windows (Winsock), Java, Python; a connection treated like a file.
| Type | Transport | Gives | Used by |
|---|---|---|---|
Stream (SOCK_STREAM) | TCP | reliable ordered byte stream | HTTP, FTP, SSH, SMTP |
Datagram (SOCK_DGRAM) | UDP | separate messages, no connection | DNS, DHCP, TFTP, SNMP |
Raw (SOCK_RAW) | IP itself | IP and ICMP packets, admin rights | ping, traceroute |
| Call | Who | Does |
|---|---|---|
socket() | both | create an endpoint (family, type); returns a descriptor |
bind() | server | attach a local IP address and port |
listen() | server | make the socket passive, with a queue length |
accept() | server | block until a client connects; return a new socket |
connect() | client | connect to the server; TCP three-way handshake |
send(), recv() | both | write, read (sendto(), recvfrom() for UDP) |
close() | both | release; TCP sends FIN |
- Order: server
socket,bind,listen,accept(blocks); clientsocket,connect(no bind: a temporary port); accept returns when the handshake completes; data; close.
Figure: the server's calls and the client's calls in two columns, with the handshake between connect and accept, request and reply data, and FIN at close.
/* server.c: a TCP server on port 5000 (BSD sockets, Linux) */
#include <stdio.h>
#include <string.h>
#include <unistd.h>
#include <sys/socket.h>
#include <arpa/inet.h>
int main(void) {
int lfd = socket(AF_INET, SOCK_STREAM, 0); /* 1. a TCP socket */
struct sockaddr_in me;
memset(&me, 0, sizeof me);
me.sin_family = AF_INET;
me.sin_port = htons(5000); /* port, network byte order */
me.sin_addr.s_addr = htonl(INADDR_ANY); /* every local address */
bind(lfd, (struct sockaddr *)&me, sizeof me); /* 2. name it: IP + port */
listen(lfd, 5); /* 3. passive, queue of 5 */
for (;;) {
int cfd = accept(lfd, NULL, NULL); /* 4. wait for a client */
char buf[100];
int n = recv(cfd, buf, sizeof buf - 1, 0); /* 5. read its request */
if (n > 0) {
buf[n] = '\0';
printf("client says: %s\n", buf);
send(cfd, "Namaste from server\n", 20, 0); /* 6. reply */
}
close(cfd); /* 7. end this client only */
}
}
/* client.c: talks to the server above */
#include <stdio.h>
#include <string.h>
#include <unistd.h>
#include <sys/socket.h>
#include <arpa/inet.h>
int main(void) {
int fd = socket(AF_INET, SOCK_STREAM, 0); /* 1. a TCP socket */
struct sockaddr_in srv;
memset(&srv, 0, sizeof srv);
srv.sin_family = AF_INET;
srv.sin_port = htons(5000); /* the server's port */
inet_pton(AF_INET, "192.168.1.10", &srv.sin_addr); /* the server's IP */
if (connect(fd, (struct sockaddr *)&srv, sizeof srv) < 0) { /* 2. handshake */
perror("connect"); /* no server listening: refused */
return 1;
}
send(fd, "Hello", 5, 0); /* 3. the request */
char buf[100];
int n = recv(fd, buf, sizeof buf - 1, 0); /* 4. the reply */
if (n > 0) { buf[n] = '\0'; printf("%s", buf); }
close(fd); /* 5. FIN */
return 0;
}
- Reading it:
htons,htonlgive network byte order (big-endian);INADDR_ANYaccepts on every interface; the listening socketlfdnever carries data, each client getscfd; real code checks every return value; busy servers useforkor threads per client. Compilegcc server.c -o server, run the server, then the client in a second terminal. - Server first:
connect()sends a SYN; with no listening socket, the server's TCP answers RST and connect fails, "connection refused" (ECONNREFUSED). - UDP: no listen, accept or connect; the server binds and loops on
recvfrom()(which gives the sender's address) and replies withsendto(). - The book's slips: a datagram socket sends "with having logical connection" (it means without: UDP is connectionless); SOCK-RAW for
SOCK_RAW. - Other languages: Java
new ServerSocket(5000)(socket, bind, listen),accept()returns aSocket, clientnew Socket("192.168.1.10", 5000)(the book's version); Python keeps the C names.
Memory example: a hostel landline: bind is getting a number, listen switching the ringer on, accept picking up, connect a friend dialling; a number not yet connected gives "does not exist", connection refused.
Proxy servers and web caching
Proxy server: an intermediary that receives clients' requests and makes them to the destination on their behalf. A caching proxy (web cache) keeps copies of recently fetched objects and answers repeat requests from them.
- Every request to the proxy: browsers configured, or traffic redirected (transparent proxy).
- Cache check for the URL.
- Fresh hit: copy returned from the LAN (within
Cache-Control: max-ageorExpires). - Possibly stale hit: conditional GET with
If-Modified-Since;304 Not Modified(no body, copy served) or200 OKwith the new version. - Miss: the proxy fetches from the origin, stores a copy, forwards it.
Figure: a campus LAN with two clients and the proxy; client A's request is a hit (steps 1, 2); client B's a miss (steps 1, 3, 4, 5) across the access link to the origin server.
- Uses: faster pages (LAN hits); less access-link traffic (the slow, paid part); less origin load; filtering and access control (sites, hours); logging and monitoring; privacy (origin sees the proxy's address) and security (malware scanning, single exit, an application gateway); sharing one connection.
Example: h = 0.4, hit 10 ms, miss 2 s: 0.4 x 0.01 + 0.6 x 2 = 1.204 s against 2 s; the access link carries only 60 percent of requests.
| Kind | Where, for whom | Example |
|---|---|---|
| Forward | near clients, for them | campus or office proxy (Squid) |
| Reverse | in front of web servers: caching, load balancing, TLS | Nginx, a CDN |
| Transparent | intercepts with no browser setting; passes client IP; says it is a proxy | ISP or school interception cache |
| Anonymous | hides client IP; says it is a proxy | privacy proxy |
| Distorting | false client IP; says it is a proxy | privacy proxy |
| High anonymity | hides IP; does not say it is a proxy | "elite" proxy |
- CDN: caching at world scale, reverse-proxy caches near users.
Memory example: the hostel copy of a popular book: the first student waits while it is fetched (miss), the next forty borrow it at once (hits), the warden checks weekly for a new edition (conditional GET).
Web, mail and DNS server optimization
Server optimization: tuning a server's hardware, software and placement to answer more clients, faster, without interruption: caching, load balancing, replication, efficient protocols, reliable storage.
| Server | Bottleneck | Optimization |
|---|---|---|
| Web | many connections, disk reads, database-built pages | caching in memory, reverse proxy, CDN; gzip, Brotli; persistent connections, HTTP/2; event-driven server (Nginx) for static files; load balancer over a farm; cached database results; expiry headers |
| queues, spam volume, storage | two or more MX records with preferences (backup); edge spam filtering (blocklists, SPF, DKIM, DMARC); submission 587 apart from relay 25; tuned queue and retry times; mailboxes on RAID; quotas; IMAP search indexes | |
| DNS | query volume, delay, attacks | caching with sensible TTLs; at least two authoritative servers on different networks (zone transfer); anycast; separate authoritative and recursive servers; rate limits against amplification; resolvers near users |
- Shared: RAID, enough memory, SSDs, redundant power (UPS and generator, needed through Nepal's load-shedding years), two network links, monitoring (SNMP, MRTG, PRTG).
- Measures: throughput (requests per second), response time, availability: 99.9 percent allows 8.76 hours down a year, 99.99 percent 52.6 minutes.
Memory example: a results website on result day: cached page, several servers behind a load balancer, two DNS servers, mirrored disks.
RAID 0, RAID 1 and RAID 5: why servers need them
RAID (Redundant Array of Independent, originally Inexpensive, Disks; Patterson, Gibson and Katz, 1988): several physical disks as one logical volume for speed (striping), protection against disk failure (mirroring, parity), or both.
- Availability: shared servers (web, mail, DNS, file, database); a dead disk would stop the service and lose data; RAID 1 or 5 keeps running while the disk is hot-swapped and rebuilt.
- Performance: striping spreads I/O over disks in parallel.
- Capacity: one large volume.
- Not a backup: deletion, viruses and ransomware hit every disk.
Figure: RAID 0 (A1, A3, A5, A7 on disk 1; A2, A4, A6, A8 on disk 2), RAID 1 (A1 to A4 on both disks), RAID 5 over three disks (A1, A2, Ap; B1, Bp, B2; Cp, C1, C2; D1, D2, Dp) with capacity, speed and fault tolerance for each.
- RAID 0, striping: blocks round-robin over n disks; all capacity; up to n times faster; no redundancy: one failure destroys the volume (less reliable than one disk); scratch space, easily recreated data; at least 2 disks.
- RAID 1, mirroring: every block on two disks; one disk's capacity; reads from either (faster); writes at one disk's speed; survives either disk failing; rebuild is a copy; OS disks, small critical servers (DNS, mail); at least 2 disks.
- RAID 5, distributed parity: data and parity striped over n disks (at least 3), the parity block rotating; parity = XOR of the stripe's data; capacity n minus 1 disks; fast reads; small writes read old data and parity and write both (four operations, the write penalty); survives any one disk; a second failure during a long rebuild loses everything (RAID 6 keeps two parities); file and web servers that mostly read.
Example: D1 = 1011, D2 = 0110, D3 = 1100; P = D1 XOR D2 XOR D3 = 0001; disk 2 fails; D1 XOR D3 XOR P = 0110 = D2.
| Point | RAID 0 | RAID 1 | RAID 5 |
|---|---|---|---|
| Technique | striping | mirroring | striping, distributed parity |
| Minimum disks | 2 | 2 | 3 |
| Usable capacity | n x S | S | (n minus 1) x S |
| Example | 2 x 2 TB: 4 TB | 2 x 2 TB: 2 TB | 4 x 2 TB: 6 TB |
| Disks that may fail | none | one of the pair | any one |
| Read speed | fastest | fast | fast |
| Write speed | fastest | one disk's | slower (parity) |
| Best for | temporary data | system disks, small servers | file, web servers |
- Also: RAID 10 (stripe of mirrors, half capacity); hardware controller or software RAID; a hot spare starts the rebuild at once.
Memory example: friends and the semester's notes: RAID 0 two split the chapters (fast, but one lost notebook loses half); RAID 1 each writes everything; RAID 5 three split them and keep a check sheet that rebuilds any one lost notebook.
SNMP: managing network devices
SNMP (Simple Network Management Protocol): an application layer protocol over UDP by which a manager reads and changes variables held by agents on routers, switches, servers and printers, and agents report events unasked.
- Manager (network management station): polls, stores, graphs, alerts (MRTG, PRTG, Zabbix).
- Agent: a process on each managed device.
- MIB (Management Information Base): the objects an agent exposes, as a tree; MIB-II (RFC 1213) the standard set.
- SMI (Structure of Management Information): naming rules, data types (integer, counter, gauge, string), encoding.
- OID: an object's address in the tree:
1.3.6.1.2.1.1.3.0sysUpTime;1.3.6.1.2.1.2.2.1.10ifInOctets (bytes received on an interface).
Figure: the manager sends GetRequest, GetNextRequest or SetRequest to the agent's UDP port 161, the agent answers with a Response, and sends Traps to the manager's port 162; the agent holds the MIB.
| Message | Direction | Does |
|---|---|---|
| GetRequest | manager to agent (UDP 161) | read variables |
| GetNextRequest | manager to agent | read the next variable: walk a table |
| GetBulkRequest (v2) | manager to agent | read a large block |
| SetRequest | manager to agent | change a variable |
| Response | agent to manager | values or an error |
| Trap | agent to manager (UDP 162) | unasked event report |
| InformRequest (v2) | agent to manager | acknowledged trap |
- Versions: SNMPv1 (RFC 1157, 1990) and v2c: community string in plain text (default read-only "public", a risk); SNMPv3 (RFC 3411 to 3418): authentication and encryption.
Example: ifInOctets read 300 s apart: 1,200,000,000 then 1,575,000,000 bytes; (375,000,000 x 8) / 300 = 10,000,000 bit/s = 10 Mbit/s, which MRTG does every five minutes.
Memory example: a hostel warden (manager) reads each room's meter on a five-minute round (Get), switches a room off from the office (Set), and a room with a short circuit calls him at once (trap).
Traffic graphers: MRTG and PRTG
Traffic grapher: a monitoring tool that polls devices at regular intervals, mostly over SNMP, stores the counters and draws graphs of link load and device health over time.
- MRTG (Multi Router Traffic Grapher): free, open source, Tobias Oetiker, 1995, Perl with a C helper; every 5 minutes by default reads ifInOctets and ifOutOctets, computes rates from the difference, redraws four graphs on a web page: daily (5-minute averages), weekly (30-minute), monthly (2-hour), yearly (1-day). Succeeded by RRDtool (same author) and tools on it such as Cacti.
- PRTG Network Monitor (Paessler Router Traffic Grapher): Paessler (Germany), commercial, Windows, free up to 100 sensors; auto-discovery; sensors (ping, SNMP traffic, CPU, disk, HTTP response, NetFlow, sniffed packets); history, dashboards, maps, email or SMS alerts.
| Point | MRTG | PRTG |
|---|---|---|
| Licence | free, open source | commercial (free to 100 sensors) |
| Platform | Unix, Windows; text configuration | Windows server, web interface |
| Data | SNMP counters, mainly traffic | SNMP, ping, NetFlow, sniffing, WMI |
| Output | PNG graphs on HTML pages | dashboards, maps, reports, alerts |
| Best for | per-link traffic history | whole-network monitoring with alarms |
- Questions answered: how full a link is and when, rising errors and discards, overloaded devices, when to upgrade. Throughput and delay themselves are chapter 2's.
Memory example: an electricity meter with a chart; suppose a hostel's 100 Mbit/s link peaks near 90 Mbit/s from 8 to 11 pm and idles at 4 am: full only in the streaming hours.
Wireshark and Packet Tracer: real packets, simulated networks
Wireshark: a free, open-source packet analyser that captures frames on a real interface and decodes every layer. Packet Tracer: Cisco's network simulator: virtual routers, switches and PCs built, configured and watched packet by packet, no hardware.
- Wireshark history: Ethereal by Gerald Combs, 1998; renamed 2006; captures through libpcap (Npcap on Windows), usually in promiscuous mode.
- Panes: packet list, packet details (layer tree: Ethernet, IP, TCP, HTTP), packet bytes (hex).
- Capture filters (BPF):
port 53,host 192.168.1.10. Display filters:dns,http.request,ip.addr == 192.168.1.10,tcp.port == 80,tcp.flags.syn == 1. - Tools: Follow TCP Stream; Statistics (conversations, protocol shares, graphs); TShark command line.
- What it shows students: the three-way handshake, DNS query and reply with the same ID, DHCP's DORA, an FTP password in plain text, HTTP readable against HTTPS as TLS records. Capture only with permission.
- Packet Tracer: free with a Cisco Networking Academy account; devices dragged, cabled, configured with real IOS commands; servers run DHCP, DNS, HTTP, FTP, TFTP, email; realtime mode, and simulation mode (time stops, packets as envelopes, each opened layer by layer).
- The book says Wireshark uses GTK+; it moved to Qt in 2015 and dropped the GTK version in 2019.
| Point | Wireshark | Packet Tracer |
|---|---|---|
| Works on | real traffic, a real interface | a simulated network |
| Purpose | troubleshooting, security analysis, learning protocols | designing, configuring, learning networks |
| Shows | every field of every captured packet | packets moving through devices |
| Made by | open-source community (free) | Cisco (free with Networking Academy) |
| Limit | only traffic reaching the interface | a subset of device features |
Memory example: Packet Tracer is the flight simulator, Wireshark the black box of a real flight; build DHCP and DNS in Packet Tracer and watch DORA, then capture dhcp or dns with Wireshark on a real laptop.
Chapter 7: Introduction to IPv6 4490 words
Why IPv6: the problems of IPv4 and what IPv6 fixes
IPv6 (Internet Protocol version 6): the network layer protocol designed by the IETF to replace IPv4. Same job (connectionless, best-effort datagram delivery across many networks), but 128-bit addresses, a simpler fixed 40-byte header, options moved into extension headers, and built-in autoconfiguration, multicast and IPsec support (RFC 8200). TCP, UDP and applications run over it unchanged.
- IPng: in the early 1990s the IETF saw 32-bit addresses would run out and began "IP next generation".
- Standards: RFC 1883 (1995), RFC 2460 (1998), full Internet Standard RFC 8200 (2017).
- Why "6": version 5 had gone to the experimental Internet Stream Protocol (ST).
IPv4 (RFC 791, 1981) was designed for a research network; it now carries billions of devices.
| IPv4 problem | What goes wrong | What IPv6 does |
|---|---|---|
| Address exhaustion | = 4,294,967,296 addresses, fewer after private, multicast and reserved blocks; classful waste. IANA's last free blocks 3 February 2011; APNIC (serves Nepal) last block 15 April 2011 | 128 bits: ; one /64 holds , times the whole IPv4 Internet |
| NAT everywhere | outside hosts cannot reach inside ones; peer-to-peer, VoIP, games, IPsec struggle; carrier-grade NAT puts many customers behind one address | a global address per device; end-to-end restored; a firewall, not NAT, filters |
| Slow, complex header | 20 to 60 bytes, options, checksum recomputed per hop, router fragmentation | fixed 40 bytes, no checksum, no router fragmentation, extension headers |
| Routing table growth | classful history, scattered allocations aggregate poorly | hierarchical allocation: registry, ISP, site /48, subnet /64 |
| No IP-layer security | IPsec added later as an option | AH and ESP as extension headers |
| Weak real-time support | TOS used inconsistently; no flow marking | traffic class plus a 20-bit flow label |
| Configuration | manual or DHCP | SLAAC (plug and play, easy renumbering); DHCPv6 optional |
| Broadcast | ARP and others interrupt every host | no broadcast: scoped multicast, anycast |
| Mobility | Mobile IPv4 triangle routing via home agent | Mobile IPv6 (RFC 6275) routes straight to the moving host |
Advantages of IPv6 over IPv4 (the book's first seven):
- Larger address space: addresses.
- Better header format: fixed 40 bytes, options separated, no checksum, faster processing.
- Possibility of extension: new features as new extension headers or options.
- Smaller routing tables: hierarchical prefixes instead of classes.
- Security: authentication (AH) and encryption (ESP) at the IP layer.
- Resource allocation: traffic class and flow label for real-time audio and video.
- Multicast with scopes; anycast reaches the nearest server.
- Autoconfiguration (SLAAC).
- End-to-end connectivity: no NAT; suits peer-to-peer, VoIP, IoT.
- Mobility and jumbograms: Mobile IPv6; payloads over 64 KiB with the jumbo payload option.
Factors behind its development and adoption: growth of the Internet (pools forecast to empty in the early 1990s, emptied from 2011); new devices (smartphones, always-on broadband, IoT; developing countries coming online); the cost of NAT; real-time multimedia; security; simpler routing and configuration; deployment pushes: World IPv6 Day (8 June 2011) and World IPv6 Launch (6 June 2012), and IPv6-only mobile networks.
Memory example: IPv4 is a hostel with about four billion rooms for eight billion people; NAT puts a whole floor behind one room number; IPv6 gives every device its own number, and one floor of the new hostel has more rooms than the whole old building.
IPsec caveat: the book calls IPsec built in. RFC 4294 (2006) made IPsec support mandatory for IPv6 nodes; RFC 6434 (2011) relaxed it to "should"; IPsec also runs over IPv4.
The IPv6 datagram: a fixed 40-byte header, compared with IPv4
IPv6 datagram: a fixed 40-byte base header followed by the payload: zero or more extension headers, then upper-layer data (TCP segment, UDP datagram or ICMPv6 message); payload length allows up to 65,535 bytes after the base header.
Figure: the 40-byte base header as a 32-bit-wide grid, with the whole packet (base header, extension headers, upper-layer data) under it
| Field | Bits | What it does |
|---|---|---|
| Version | 4 | 6 (0110); same position as IPv4's |
| Traffic class | 8 | 6-bit DSCP plus 2 ECN bits; the job of IPv4's TOS |
| Flow label | 20 | set by the source to identify one flow so routers treat its packets alike without reading the transport header; 0 when unused (RFC 6437) |
| Payload length | 16 | bytes after the base header, extension headers included, up to 65,535; base header never counted |
| Next header | 8 | extension header (0, 43, 44, 50, 51, 60) or upper layer (6 TCP, 17 UDP, 58 ICMPv6); same numbers as IPv4's protocol field |
| Hop limit | 8 | minus 1 per router; at 0 dropped, ICMPv6 Time Exceeded sent; IPv4's TTL renamed |
| Source address | 128 | sender |
| Destination address | 128 | receiver, or next node when a routing header is present |
Memory example: a courier slip with fixed printed boxes; the office in Butwal (a router) reads only the "to" box and stamps the hop counter; extra sheets behind the slip are extension headers, read by the receiver, except one marked for every office (hop-by-hop).
Against the IPv4 header
Six IPv4 fields gone, four renamed, three kept, one added.
Figure: the IPv4 and IPv6 headers side by side at the same scale, every field coloured kept, renamed, removed or added
| IPv4 field (bits) | In IPv6 | Why |
|---|---|---|
| Version (4) | kept, value 6 | tells the versions apart |
| IHL (4) | removed | header always 40 bytes |
| Type of service (8) | renamed traffic class | same DSCP and ECN bits |
| Total length (16) | renamed payload length | counts only what follows the header |
| Identification (16), flags (3), fragment offset (13) | removed, into the fragment extension header | only the source fragments |
| Time to live (8) | renamed hop limit | it always counted hops |
| Protocol (8) | renamed next header | may point to an extension header |
| Header checksum (16) | removed | Ethernet CRC and transport checksums catch errors; no recomputation per hop |
| Source, destination (32 each) | kept, 128 bits each | larger space |
| Options and padding (up to 320) | removed | extension headers |
| none | added: flow label (20) | flow identification |
The UDP checksum, optional over IPv4, is mandatory over IPv6 (RFC 8200); TCP, UDP and ICMPv6 checksums cover a pseudo-header with both 128-bit addresses.
| Point | IPv4 | IPv6 |
|---|---|---|
| Address | 32 bits, dotted decimal, 192.168.1.20 | 128 bits, hex with colons, 2001:db8:acad:1::20 |
| Header | 20 to 60 bytes, 12 fields and options | 40 bytes, 8 fields |
| Checksum | yes | none |
| Fragmentation | sender and routers | sender only; routers send Packet Too Big |
| Smallest link MTU | 68 bytes (hosts accept 576) | 1,280 bytes |
| Options | in the header | extension headers |
| Configuration | manual or DHCP | SLAAC, DHCPv6, manual |
| Delivery | unicast, multicast, broadcast | unicast, multicast, anycast, no broadcast |
| Neighbour's MAC | ARP, broadcast | neighbour discovery (ICMPv6), multicast |
| Security | IPsec optional, later | AH, ESP extension headers |
| QoS | TOS | traffic class, flow label |
| NAT | common | not needed |
| DNS record | A | AAAA |
| Loopback | 127.0.0.1 | ::1 |
Routing and header manipulation
| At each router | IPv4 | IPv6 |
|---|---|---|
| Find the fields | read IHL first | fixed offsets |
| Checksum | verify, recompute after TTL change | none |
| Lifetime | TTL minus 1 | hop limit minus 1, the only change |
| Options | examine, often in slow software | skip extension headers except hop-by-hop |
| Too big | fragment unless DF | drop, ICMPv6 Packet Too Big; source resends smaller |
| Address rewriting | NAT rewrites addresses, ports, checksums | none |
| Flow recognition | ports, deep in the packet | flow label |
| Lookup | longest prefix match, 32 bits | longest prefix match, 128 bits |
| Routing protocols | RIP, OSPFv2, BGP | RIPng, OSPFv3, MP-BGP, IS-IS |
Critical points: 128-bit lookups need more TCAM per route; dual-stack routers keep two tables and two protocol sets; extension headers (hop-by-hop above all) leave the fast path and are often dropped (RFC 7872); filtering ICMPv6 breaks path MTU discovery; tables stay small only if providers announce whole blocks.
Worked example: a 1,500-byte packet meets a 1,280-byte MTU link. IPv4 router: read IHL 5 (20 bytes), check checksum, TTL 64 to 63, recompute checksum, split the 1,480 data bytes into fragments of 1,276 and 244 bytes, each with its own header and checksum. IPv6 router: hop limit 64 to 63, too big, drop, return Packet Too Big (MTU 1,280); the PC sends later packets at most 1,280 bytes (TCP uses smaller segments).
Book slip: the book gives the flow label 24 bits (first row would be 36 bits); it is 20 bits (RFC 2460, RFC 8200); 24 bits belonged to the 1995 header (RFC 1883) with a 4-bit priority field. The book counts TOS as removed and traffic class as added; most comparisons call it renamed.
Extension headers: the options moved out of the base header
Extension headers: optional headers between the base header and the upper-layer data, each naming the next in its next header field; they carry what IPv4 kept in options and fragmentation fields, and except hop-by-hop options are examined only where the packet is addressed.
Why: IPv4 options sit in the header, so every router checks for them; IPv6 keeps the base header fixed and adds extension headers only where needed: a compromise between generality and efficiency, and extensible (a new feature is a new header type).
Figure: a packet whose base header says next header 0, then hop-by-hop (43), routing (44), fragment (6), TCP; and the eight places of the recommended order with their codes
Chain: base header's next header gives the first extension header; each extension header's next header gives the following one; the chain ends at the upper layer (6 TCP, 17 UDP, 58 ICMPv6) or 59 (no next header).
Format: each starts with an 8-bit next header and (except the fixed 8-byte fragment header) an 8-bit length in 8-byte units not counting the first 8; each padded to a multiple of 8 bytes.
| Order | Header | Code | Read by | What it does |
|---|---|---|---|---|
| 1 | Hop-by-hop options | 0 | every node on the path | first, right after the base header; Pad1, PadN, Jumbo Payload (over 65,535, up to ), Router Alert (MLD) |
| 2 | Destination options | 60 | destination and nodes the routing header lists | options for those nodes |
| 3 | Routing | 43 | listed nodes | addresses to visit; IPv4's loose and strict source routing |
| 4 | Fragment | 44 | final destination | 13-bit offset, more-fragments flag, 32-bit identification; source-only |
| 5 | Authentication header (AH) | 51 | final destination | sender and integrity (IPsec) |
| 6 | Encapsulating security payload (ESP) | 50 | final destination | encryption and integrity |
| 7 | Destination options | 60 | final destination only | options for the receiver |
| 8 | Upper-layer header | 6, 17, 58 | TCP, UDP, ICMPv6 | the data |
Rules (RFC 8200): each at most once, except destination options (at most twice); hop-by-hop must follow the base header directly and, since RFC 8200, is processed by a router only if configured to; no router inserts or deletes extension headers.
Memory example: a parcel from Kathmandu to Pokhara with stickers in order: "fragile" read by every handler (hop-by-hop), "via the Mugling office" (routing), "box 2 of 3" (fragment), wax seal (AH), locked inner box (ESP).
Fragmentation only at the source: path MTU discovery (RFC 8201) sends at the link MTU; a router that cannot forward drops and returns ICMPv6 Packet Too Big with the next link's MTU; the source sends smaller, using a fragment header only when it must. Every IPv6 link carries at least 1,280 bytes.
Book slips: the next header table gives ICMP as 2; ICMPv6 is 58 (2 is IGMP in IPv4; IPv4 ICMP is 1). "Only three hop-by-hop options": Router Alert is a fourth. The "source routing" header is the routing header; type 0 deprecated in 2007 (RFC 5095), as attackers bounced traffic between routers with it. "Up to six extension headers" counts the six types a full implementation supports; destination options may appear twice.
IPv6 addresses: notation, types and autoconfiguration
IPv6 address: a 128-bit identifier for an interface (unicast, anycast) or a set of interfaces (multicast), written as eight groups of four hexadecimal digits separated by colons, with a prefix length after a slash: 2001:db8:acad:1::/64 (RFC 4291).
Shortening 2001:0db8:0000:0000:0000:ff00:0042:8329:
- Drop leading zeros in each group:
0db8todb8,0042to42,0000to0. - Replace one run of zero groups by
::, once only:2001:db8:0:0:0:ff00:42:8329becomes2001:db8::ff00:42:8329.
- Expanding:
::stands for 8 minus the number of groups shown. - Only once:
2001:db8::1::1could be2001:db8:0:1:0:0:0:1or2001:db8:0:0:1:0:0:1. - Canonical form (RFC 5952): lower case, longest zero run shortened (the first if equal), never
::for a single zero group.
Prefixes as in CIDR: /64 leaves 64 bits of interface ID; an ISP holds a /32, a site gets a /48 (a home a /56), subnets are /64; a /48 holds = 65,536 subnets. In a URL: http://[2001:db8::1]:8080/.
| Type | Delivered to | Ranges and examples |
|---|---|---|
| Unicast | one interface | global 2000::/3 (2001:db8:acad:1::20), link-local fe80::/10, unique local fc00::/7, loopback ::1, unspecified :: |
| Anycast | the nearest of a set, by routing | from unicast space; subnet-router anycast = prefix with all-zero interface ID, 2001:db8:acad:1:: |
| Multicast | every group member | ff00::/8: ff02::1 all nodes, ff02::2 all routers |
No broadcast in IPv6.
Figure: five 128-bit layouts: global unicast, link-local, unique local, multicast, IPv4-mapped
- Global unicast (
2000::/3): routable; global routing prefix (48 bits for a typical site), 16-bit subnet ID, 64-bit interface ID. - Link-local (
fe80::/10): every interface makes one; its own link only, never forwarded; used by neighbour discovery and routing protocols; the default gateway is the router's link-local address. - Unique local (
fc00::/7, in practicefd00::/8with a random 40-bit global ID, RFC 4193): private, like10.0.0.0/8. - Site-local (
fec0::/10): deprecated 2004 (RFC 3879), replaced by unique local.
IPv4 inside IPv6: write each IPv4 byte as two hex digits: 192.0.2.33 is c0, 00, 02, 21, so c000:0221.
| Form | Layout | 192.0.2.33 becomes | Used for |
|---|---|---|---|
| IPv4-mapped | 80 zero bits, 16 one bits, IPv4 | ::ffff:192.0.2.33 = ::ffff:c000:221 | an IPv4 peer seen by an IPv6 socket on a dual-stack host; SIIT |
| IPv4-compatible | 96 zero bits, IPv4 | ::192.0.2.33 | deprecated (RFC 4291) |
| NAT64 well-known prefix | 64:ff9b::/96, IPv4 | 64:ff9b::c000:221 | IPv6-only hosts reaching IPv4 servers |
| 6to4 site prefix | 2002, IPv4, subnet, interface | 2002:c000:221::/48 | automatic tunnels |
Getting an address automatically
Three ways, chosen by router advertisement flags: SLAAC (RFC 4862, the host builds its own address, no server record); stateless DHCPv6 (SLAAC address, DHCPv6 for DNS and settings); stateful DHCPv6 (RFC 8415, a server leases addresses). SLAAC runs on neighbour discovery (RFC 4861), ICMPv6 messages that also replace ARP: router solicitation 133, router advertisement 134, neighbour solicitation 135, neighbour advertisement 136, redirect 137.
Figure: SLAAC as a message sequence between the new host, the other nodes and the router, with the EUI-64 interface ID derivation
- Link-local address:
fe80::/64plus a 64-bit interface ID:fe80::200:5eff:fe00:5301. - DAD: from
::, a neighbour solicitation for the new address to its solicited-node groupff02::1:ff00:5301; a neighbour advertisement means duplicate; silence for about a second means the address is the host's. - Router solicitation to
ff02::2(all routers). - Router advertisement to
ff02::1(all nodes): prefix2001:db8:acad:1::/64, valid and preferred lifetimes, hop limit, MTU, M (managed) and O (other) flags, often DNS servers (RDNSS, RFC 8106); the router's link-local address becomes the default gateway. - Global address:
2001:db8:acad:1:200:5eff:fe00:5301, checked by DAD. - DHCPv6 if flagged: M set, address from DHCPv6 (UDP 546 and 547); O set, only DNS and settings.
Modified EUI-64: split the MAC, insert FF-FE, flip bit 7 of the first byte (universal/local): 00-00-5E-00-53-01 gives 02-00-5E-FF-FE-00-53-01, interface ID 0200:5eff:fe00:5301. Privacy: a MAC-based ID lets sites track a device across networks; current systems use random IDs, stable per network (RFC 7217) or temporary (RFC 8981). Renumbering: the router advertises the new prefix, the old preferred lifetime runs out, hosts move by themselves.
Memory example: a hostel room with no warden: the corridor notice gives block and floor (prefix), you add your roll number (interface ID), shout once "anyone using this number?" (DAD), and with no answer the room is yours; no register: stateless.
Book slips: its example FE80:0000:0000:0001:0800:23E7:F5DB has only seven groups (112 bits); its shortened FE80::1:0800:23E7:F5DB is valid but means fe80:0:0:0:1:800:23e7:f5db (three zero groups) and keeps the leading zero of 0800. It lists site-local as a unicast type (deprecated 2004).
IPv6 multicasting: groups, scopes and MLD
IPv6 multicasting: delivery of one packet to every member of a group named by an address in ff00::/8; no broadcast exists, so broadcast jobs use multicast groups; every multicast address carries a scope; routers find listeners with MLD.
Any node may join or leave at any time; a sender needs no member list; a group address is only a destination, never a source nor a routing-header stop; one copy reaches each member, by hardware multicast on each link.
Figure: the multicast address (ff, flags, scope, group ID), the scope values, and the solicited-node group derived from a unicast address
- Prefix: first 8 bits
1111 1111, soff. - Flags (4 bits, 0RPT): T = 0 permanent (IANA), T = 1 temporary; P = 1 prefix-based (RFC 3306); R = 1 rendezvous point embedded (RFC 3956).
- Scope (4 bits): a router never forwards beyond it; IPv4 marked scope only by convention (
239.0.0.0/8, TTL limits). - Group ID (112 bits).
| Scope | Reach |
|---|---|
| 1 | interface-local (loopback) |
| 2 | link-local, never routed |
| 4 | admin-local, set by configuration |
| 5 | site-local |
| 8 | organization-local |
| e | global |
| Address | Group |
|---|---|
ff02::1 | all nodes (nearest thing to broadcast) |
ff02::2 | all routers |
ff02::5, ff02::6 | OSPFv3 routers, OSPFv3 designated routers |
ff02::9 | RIPng routers |
ff02::a | EIGRP routers |
ff02::16 | MLDv2-capable routers |
ff02::1:2 | all DHCPv6 relay agents and servers |
ff05::1:3 | all DHCPv6 servers in the site |
Solicited-node group: every unicast address joins ff02::1:ff plus its last 24 bits: 2001:db8:acad:1:200:5eff:fe00:5301 joins ff02::1:ff00:5301; neighbour solicitations (address resolution, DAD) go there, not to everyone. On Ethernet the MAC is 33:33 plus the last 32 bits (RFC 2464): 33:33:ff:00:53:01; ff02::1 maps to 33:33:00:00:00:01. The card filters in hardware, so only hosts sharing the last 24 bits (usually one) are disturbed.
MLD (Multicast Listener Discovery), part of ICMPv6: MLDv1 (RFC 2710) like IGMPv2, MLDv2 (RFC 3810) like IGMPv3 with source filtering. Query 130; report 131 (v1) or 143 (v2); done 132. Link-local source, hop limit 1, Router Alert option; switches snoop MLD. Between routers, PIM-SM and PIM-SSM.
Memory example: the warden shouting "room 301!" down every corridor is broadcast; calling only rooms ending in 301 is the solicited-node group; "second-year students, this block only" is a scoped group.
From IPv4 to IPv6: coexistence, dual stack, tunneling and translation
Transition from IPv4 to IPv6: the gradual migration of hosts, routers and applications from IPv4 to IPv6 while both keep working, by dual stack, tunneling and header (address family) translation.
No switch-over day: IPv6 is not backward compatible (an IPv4-only host cannot read an IPv6 header); billions of devices cannot change at once, unlike the ARPANET's switch to TCP/IP on 1 January 1983.
Coexistence: IPv4 and IPv6 running side by side on the same Internet, often on the same hosts, links and routers, through the migration; nodes are IPv4-only, IPv6-only or dual stack, and the mechanisms let any two communicate until IPv4 is switched off.
| Situation | Mechanism |
|---|---|
| a node must talk to IPv4 and IPv6 hosts | dual stack |
| IPv6 networks separated by IPv4 | tunneling (configured, 6to4, ISATAP, 6RD, Teredo) |
| IPv6-only host to IPv4-only host | header translation (SIIT, NAT64 with DNS64) |
| IPv4 customers on IPv6-only provider networks | DS-Lite, 464XLAT, MAP |
Figure: the three strategies in rows: a dual-stack host between IPv4-only and IPv6-only hosts; an IPv6 packet inside an IPv4 packet (protocol 41) between R1 and R2; a NAT64 translator rewriting an IPv6 header as IPv4
Memory example: an English letter crossing a Nepali-only post office: a clerk reading both scripts is dual stack; the letter sealed in a Nepali-addressed envelope is tunneling; an interpreter rewriting it in Nepali is translation (some meaning may be lost).
1. Dual stack (RFC 4213)
Every node runs both stacks: one application and TCP/UDP layer over IPv4 and IPv6 network layers on the same link; each interface has an IPv4 and an IPv6 address; routers keep two routing tables and run both protocol sets (OSPFv2 and OSPFv3).
Figure: a dual-stack host's layers, with IPv4 reaching an IPv4-only server (A record) and IPv6 an IPv6 server (AAAA record)
- Choosing: DNS A and AAAA records; AAAA means IPv6, preferred by default address selection (RFC 6724); only A means IPv4.
- Happy Eyeballs (RFC 8305): if IPv6 has not answered within about 250 ms (recommended default), try IPv4 too and keep the first to connect.
- For: simplest, native speed, nothing encapsulated or translated, services move when ready; recommended wherever possible (RFC 6180).
- Against: every node still needs an IPv4 address (no help with exhaustion); two sets of addresses, firewall rules and routing tables.
Example: a laptop on college Wi-Fi with 192.168.1.20 (DHCP) and 2001:db8:acad:1::20 (SLAAC) fetches AAAA sites over IPv6 and A-only sites over IPv4 through NAT.
2. Tunneling
IPv6 nodes separated by an IPv4-only region: the entry router (dual stack) encapsulates the whole IPv6 packet behind an IPv4 header with protocol 41 addressed to the tunnel exit; IPv4 routers forward it as ordinary IPv4; the exit router decapsulates and forwards the IPv6 packet. The IPv4 region looks like one hop.
Figure: IPv6 host A, router R1 (192.0.2.1), an IPv4-only network, router R2 (198.51.100.1), IPv6 host B, with the packet on each stretch
Costs: 20 extra bytes (smaller MTU), harder troubleshooting (one hop in traceroute), firewalls bypassed if protocol 41 is not inspected.
| Tunnel | Connects | Far end from | Address | Status |
|---|---|---|---|---|
| Configured (RFC 4213) | two routers, or host and tunnel broker | set by hand | any | common for router links |
| 6to4 (RFC 3056) | IPv6 sites across the IPv4 Internet | IPv4 inside the 6to4 prefix | 2002:WWXX:YYZZ::/48 | relays deprecated 2015 (RFC 7526) |
| ISATAP (RFC 5214) | dual-stack hosts in one IPv4 site | IPv4 in the interface ID | prefix + 0:5efe:a.b.c.d | little used now |
| 6RD (RFC 5969) | ISP customers over its IPv4 network | IPv4 bits in the ISP's 6rd prefix | ISP prefix + IPv4 bits | ISP deployments |
| Teredo (RFC 4380) | hosts behind IPv4 NAT, UDP 3544 | Teredo servers and relays | 2001::/32 | last resort, little used now |
Figure: the address formats of 6to4, ISATAP, 6RD and Teredo as 128-bit bars
6to4: prefix 2002 plus the site router's public IPv4 in hex (48 bits), then 16-bit subnet ID and 64-bit interface ID. Router 192.0.2.4 gives 2002:c000:204::/48. Between 6to4 sites the router copies bits 17 to 48 of the destination (the far router's IPv4) and tunnels straight there; to native IPv6, through a 6to4 relay (once anycast 192.88.99.1). Weakness: needs public IPv4 (fails behind NAT); unowned public relays gave slow, one-sided or broken paths; anycast relay prefix deprecated 2015 (RFC 7526).
ISATAP (Intra-Site Automatic Tunnel Addressing Protocol): IPv6 for dual-stack hosts inside an IPv4-only organization network, treated as one link. Interface ID 0000:5efe + host IPv4 (0200:5efe if the IPv4 address is globally unique, the universal/local bit). Host 10.1.1.5 gets fe80::5efe:a01:105 (fe80::5efe:10.1.1.5). The host finds the ISATAP router (Windows looked up the DNS name isatap), sends a router solicitation inside IPv4, receives the prefix 2001:db8:acad:5::/64, forms 2001:db8:acad:5:0:5efe:a01:105. To ISATAP hosts: tunnel straight to the IPv4 in the last 32 bits; elsewhere: via the ISATAP router.
6RD (IPv6 rapid deployment): 6to4 rebuilt inside one ISP; first used by the French ISP Free in 2007 (described in RFC 5569, 2010), standardised in RFC 5969 (2010).
- Importance: IPv6 over an IPv4-only access network without upgrading it; the ISP's own prefix and relays (reliable, under its control); stateless, scales; stable delegated prefix per customer.
- Parts: customer edge (CE) router; border relay (BR) routers.
- Configuration: usually DHCPv4 option 212: 6rd prefix, its length, the number of shared leading IPv4 bits left out, BR IPv4 address.
- Delegated prefix: 6rd prefix + remaining IPv4 bits.
2001:db8::/32, no shared bits, CE203.0.113.5(cb00:7105) gives2001:db8:cb00:7105::/64. With all customers in198.51.100.0/24(24 bits left out),2001:db8:ab00::/40gives CE198.51.100.7the /482001:db8:ab07::/48. - Forwarding: CE wraps IPv6 in IPv4 (protocol 41) to the BR or another CE; the BR unwraps and forwards natively, and for replies reads the CE's IPv4 out of the destination prefix.
Teredo (RFC 4380): for hosts behind IPv4 NAT, IPv6 inside UDP (port 3544) inside IPv4; address in 2001::/32 with the Teredo server's IPv4 and the client's obscured public port and IPv4.
3. Header translation (address family translation)
One end IPv6-only, the other IPv4-only: a translator rewrites each header in the other version and maps addresses between the address families. The book's case: a mostly IPv6 Internet with IPv4 stragglers; today usually IPv6-only networks (mobile operators) reaching IPv4-only servers.
Figure: an IPv6-only host, DNS64, a NAT64 translator and an IPv4-only server, with the field mapping table
Procedure, IPv6 to IPv4 (SIIT rules, RFC 7915):
- Addresses: IPv4 destination from the low 32 bits (
64:ff9b::c000:221gives192.0.2.33); IPv6 source to an IPv4 address by a fixed mapping or, in NAT64, a shared pool address and port. - Version 6 to 4; 20-byte header (IHL 5, no options).
- Traffic class copied into TOS (or replaced by a configured value).
- Flow label dropped.
- Payload length plus 20 becomes total length.
- Next header to protocol (ICMPv6 58 to ICMP 1); hop-by-hop, routing and destination options dropped; a fragment header becomes identification, flags, fragment offset.
- Hop limit to TTL, lowered by one (the translator is a router).
- Header checksum computed; TCP and UDP checksums adjusted; ICMPv6 messages rewritten as ICMP.
Replies: the same in reverse.
| Translator | How it works | Status |
|---|---|---|
| SIIT (RFC 7915) | stateless, one packet at a time, fixed one-to-one address mapping | current; base of the others |
| NAT-PT (RFC 2766, 2000) | stateful with a built-in DNS gateway | Historic since 2007 (RFC 4966) |
| NAT64 (RFC 6146, 2011) | stateful; IPv6 clients share IPv4 addresses by port | current, with DNS64 |
| DNS64 (RFC 6147) | synthesizes AAAA from A: 192.0.2.33 to 64:ff9b::c000:221 | current |
| 464XLAT (RFC 6877, 2013) | CLAT on the device (stateless, IPv4 to IPv6) plus PLAT (NAT64) in the network | IPv6-only mobile networks |
Limits: applications carrying addresses in their data (FTP, SIP) break without an ALG; end-to-end IPsec fails; the flow label and extension headers are lost; a stateful translator holds every flow's state.
The latest methods and which to choose
IPv6-only provider networks carrying IPv4 as a service: NAT64 with DNS64 and 464XLAT on mobile networks; DS-Lite (RFC 6333: home router tunnels IPv4 in IPv6 to the ISP's carrier-grade NAT, the AFTR); MAP-E and MAP-T (RFC 7597, RFC 7599: stateless IPv4 sharing by port range). RFC 9313 (2022) compares five: 464XLAT, DS-Lite, lightweight 4over6, MAP-E, MAP-T.
| Situation | Choose | Why |
|---|---|---|
| both protocols possible, IPv4 addresses to hand | dual stack | native, simplest; IETF's first choice (RFC 6180) |
| IPv6 islands across an IPv4-only network | configured tunnel, or 6RD from the ISP | reuses IPv4 until upgraded |
| IPv6-only network reaching IPv4-only content | NAT64 with DNS64; 464XLAT on phones | no IPv4 needed inside |
| ISP short of IPv4 addresses | DS-Lite, MAP, 464XLAT | IPv4 as a service over IPv6 |
For a campus or company: dual stack, a tunnel only as a stop-gap, translation where part of the network goes IPv6-only.
Book slip: its eight translation steps (from older textbooks) set TOS to zero, discard a "priority" field and convert extension headers to IPv4 options; RFC 7915 copies the traffic class into TOS by default, drops hop-by-hop, routing and destination options headers, and maps only the fragment header; "priority" was the 4-bit field of the 1995 header (RFC 1883).
Chapter 8: Network security 7690 words
Network security and the properties of secure communication
Network security: the policies, practices and technologies that protect a network and the data crossing it from unauthorised access, misuse, modification and disruption, so that a sender and a receiver can communicate securely over an insecure medium. The setting: a sender (Alice) and a receiver (Bob) exchange messages over a medium they do not control (the Internet, a radio link), where an intruder (Trudy) may intercept, read, change, delete or inject messages. The book: the basic objective is to communicate securely over an insecure medium.
Figure: four panels, A sending to B with intruder T: interruption, interception, modification, fabrication, each with the property it violates
The four classic attacks:
- Interruption: the message is destroyed or blocked (cut cable, jammed radio, flooded server); attacks availability.
- Interception: an unauthorised party reads it (sniffing open Wi-Fi); attacks confidentiality.
- Modification: the message is changed in transit; attacks integrity.
- Fabrication: a false message inserted as if from a genuine sender; attacks authenticity.
Passive attacks (interception, traffic analysis) change nothing, are hard to detect, and are defeated by prevention (encryption). Active attacks (interruption, modification, fabrication, replay of a captured valid message such as a login, denial of service) alter the stream; the aim is to detect them and recover.
| Property | Meaning | Attack it answers | Provided by |
|---|---|---|---|
| Confidentiality | only sender and intended receiver understand the content | interception, eavesdropping | encryption (AES, TLS, WPA2) |
| Integrity | content arrives exactly as sent, not altered by accident or on purpose | modification | hash with a MAC, digital signature |
| Authentication | each end confirms the other is who it claims, and a message came from its claimed sender | fabrication, masquerade | passwords, certificates, signatures |
| Non-repudiation | sender cannot later deny sending (nor receiver deny receiving) | repudiation | digital signature |
| Availability | network and services usable by authorised users when needed | interruption, denial of service | redundancy, filtering, backups |
| Access control | only authorised users reach a resource, only with their rights | unauthorised access | firewalls, ACLs, permissions |
CIA triad: confidentiality, integrity, availability, the core; authentication, non-repudiation and access control complete it for two communicating parties.
Memory example, a cheque paid into a bank: nobody else reads the account number (confidentiality); Rs 500 does not become Rs 5,000 (integrity); the bank checks the signature (authentication); the writer cannot deny it (non-repudiation); the bank is open (availability); only the cashier opens the drawer (access control).
Maintaining security: defense in depth
No single device gives all six properties; protect in layers, so one failure leaves the next control standing. Procedures, in order:
- Policy and risk assessment: assets (servers, data, links), threats, rules of use.
- Access control: individual accounts, strong passwords or multi-factor login, least privilege, accounts removed when people leave.
- Encryption: TLS for web and mail, VPN for remote and branch links, WPA2 or WPA3 on Wi-Fi, encrypted disks and backups.
- Perimeter control: firewall and router ACLs at every boundary; public servers in a DMZ.
- Segmentation: VLANs keep hostel, office and server networks apart; separate guest Wi-Fi.
- Hardening and patching: updates for routers, servers, PCs; unused services and ports off; default passwords changed.
- Malware protection: antivirus or endpoint protection, filtering of e-mail attachments and links.
- Monitoring: IDS or IPS, logs collected and reviewed, alerts acted on.
- Availability measures: offline backups, redundant links and power, flood protection.
- Physical security and people: locked racks and wiring closets, phishing training, an incident response plan.
Example, a campus hostel network: WPA2 with a password per block and a separate guest network; router ACL drops Telnet and remote desktop from outside; warden's office PCs on their own VLAN; router firmware updated each semester; rack in a locked room; students told never to share the result-portal password.
The book gives five headings: confidentiality, authentication, non-repudiation, message integrity, and access control with availability as one; heading 4 is printed "Message Integrity and Non-reliability" (the text means integrity and non-repudiation). It offers checksums for integrity, but a checksum or CRC stops only accidents (an attacker recomputes it); integrity against an attacker needs a keyed MAC or a signature. Kurose and Ross name four: confidentiality, message integrity, end-point authentication, operational security.
Cryptography: symmetric key and public key
Cryptography: the science of keeping messages secure by transforming them into an unreadable form (encryption) that only the holder of the right key can turn back (decryption). Two families: symmetric key (one shared secret key) and public key or asymmetric (a key pair, one public, one private).
- Plaintext (P): the original readable message.
- Ciphertext (C): the scrambled message that travels, ; decryption gives .
- Cipher: the encryption and decryption algorithms together.
- Key (K): the secret value the algorithm uses; another key gives another ciphertext.
- Cryptanalysis: breaking a cipher without the key; cryptology covers making and breaking.
Kerckhoffs's principle: the algorithm is public, only the key is secret (DES, AES, RSA are published standards); security comes from a key space too large to try every key (brute force).
Figure: two rows; symmetric: plaintext, encrypt with shared key K, ciphertext, decrypt with the same K; public key: encrypt with B's public key, decrypt with B's private key
Symmetric key (secret key, conventional): one shared key encrypts and decrypts; fast enough for bulk data (disk encryption, TLS records, VPN tunnels, Wi-Fi). Weakness: key distribution, the key must reach the other side secretly before the first message, and every pair needs its own key: keys for users (100 users: 4,950 keys).
- Block ciphers: a fixed block at a time: DES (64-bit blocks), 3DES, AES (128-bit blocks), IDEA, Blowfish.
- Stream ciphers: XOR the data with a keystream, bit or byte at a time: RC4 (WEP), ChaCha20.
Public key (asymmetric): each user has a key pair, a public key published to everyone and a private key that never leaves its owner; what one encrypts, only the other decrypts. To send a secret to B, encrypt with B's public key; only B's private key decrypts. To sign, B encrypts a digest with its private key; anyone checks with B's public key. Solves key distribution ( keys for users, nothing secret shared) but slow (numbers hundreds of digits long). Examples: RSA, Diffie-Hellman, ElGamal, ECC, DSA. Diffie and Hellman published the idea in 1976.
Memory example, padlocks: symmetric is one lock with two identical keys, one of which must reach a friend in Dharan uncopied; public key is open padlocks handed to anyone, which anyone can snap shut, but only one key opens.
| Point | Symmetric key | Public key (asymmetric) |
|---|---|---|
| Keys | one shared secret key | a public key and a private key |
| Who holds them | both parties, secretly | public: anyone; private: owner only |
| Encrypt, decrypt | the same key | one key of the pair each |
| Speed | fast: long messages, bulk data | slow: short data, keys, digests |
| Key distribution | hard: shared secretly first | easy: publish, with a certificate |
| Keys for users | ||
| Equal strength | 128 bits (AES-128) | 3072 bits (RSA-3072), NIST SP 800-57 |
| Services | confidentiality | confidentiality, authentication, non-repudiation, key exchange |
| Examples | DES, 3DES, AES, IDEA, RC4 | RSA, Diffie-Hellman, ElGamal, ECC, DSA |
Hybrid use: public key cryptography only agrees or protects a fresh random session key; a fast symmetric cipher encrypts the data under it (PGP, TLS, IPsec).
Types of encryption used in security: symmetric key and asymmetric (public key) encryption; beside them the hash function (MD5, SHA-1, SHA-256), a keyless one-way transformation of any message to a fixed-length digest, which cannot be decrypted and so gives integrity, not secrecy. The oldest ciphers, substitution and transposition, are the classical ciphers.
Classical ciphers: substitution and transposition
Classical ciphers: traditional pre-computer ciphers on letters. Substitution replaces each letter and keeps the order; transposition keeps the letters and changes their order. Every modern symmetric cipher repeats both under a key: DES S-boxes substitute and P-boxes transpose; AES SubBytes substitutes, ShiftRows transposes.
Caesar (shift) cipher: each letter moves places, wrapping z to a.
Book's example, : i am a student becomes k co c uvwfgpv. Only 25 useful keys: brute force.
Monoalphabetic: any rearrangement of the alphabet is the key: keys, but frequency analysis (e, t, a commonest in English) breaks it. Kurose and Ross's key:
plaintext: abcdefghijklmnopqrstuvwxyz
ciphertext: mnbvcxzasdfghjklpoiuytrewq
attack becomes muumbf
Polyalphabetic: several substitutions in turn, so one plaintext letter maps to different letters and frequencies blur. Book: C1 (), C2 (), pattern C1, C2, C1: i am a student becomes k fo c xvwigpy (the two a's become f and c). Vigenère: a key word gives the shifts.
Transposition (columnar): write in rows under a numbered key, read columns in key order.
key: 3 1 4 2
M E E T
A T R A
T N A P
A R K X (X pads)
read columns 1, 2, 3, 4 of the key: ETNR TAPX MATA ERAK = ETNRTAPXMATAERAK
The receiver writes the groups back into columns and reads the rows: MEET AT RATNAPARK.
| Point | Substitution | Transposition |
|---|---|---|
| Changes | the letters | their order |
| Letter frequencies | hidden only by polyalphabetic forms | unchanged |
| Examples | Caesar, monoalphabetic, Vigenère | columnar, rail fence |
| In modern ciphers | S-boxes, SubBytes | P-boxes, ShiftRows |
Memory example: a class note with each letter written two on (Caesar), or written in a grid and read down the columns (transposition).
Book's slips: its Caesar answer "k co c UV FG PV" drops the w (correct: k co c uvwfgpv); its monoalphabetic key repeats i (the 16th letter should be l, as in Kurose and Ross); its answer QZZQEA comes from the keyboard key qwerty... (a to q, t to z, c to e, k to a); the printed key gives muumbf.
DES and AES: the symmetric block ciphers
DES (Data Encryption Standard, FIPS 46, 1977): 64-bit blocks, 56-bit key, 16 Feistel rounds. AES (Advanced Encryption Standard, FIPS 197, 2001): 128-bit blocks, 128, 192 or 256-bit key, 10, 12 or 14 rounds; has replaced DES.
Block cipher: a fixed-size block plus a key gives a ciphertext block of the same size; built from P-boxes (permute bits), S-boxes (non-linear substitution) and XOR with a round key, repeated in rounds. Shannon's goals: confusion (ciphertext depends on the key in a complicated way) and diffusion (each plaintext bit affects many ciphertext bits).
DES in numbers: designed at IBM from Lucifer, adopted by the US National Bureau of Standards (now NIST) in 1977. 64-bit plaintext block, 64-bit key with 8 parity bits (56-bit effective key), 16 rounds each with a 48-bit round key, 64-bit ciphertext; the same algorithm decrypts.
Figure: DES structure (IP, rounds 1 to 16 fed K1 to K16 by the key schedule, 32-bit swap, final permutation), one Feistel round, and the f function
The operation of DES:
- Initial permutation (IP): the 64 bits rearranged by a fixed table (bit 58 to position 1, bit 50 to position 2, and so on).
- Split: left half , right half , 32 bits each.
- Sixteen Feistel rounds: , .
- 32-bit swap of the halves after round 16.
- Final permutation gives the 64-bit ciphertext.
Round function f (32-bit half, 48-bit key):
- Expansion E: 32 bits to 48 by repeating 16 of them.
- XOR with the round key .
- Eight S-boxes: eight 6-bit groups, each to 4 bits; outer two bits pick one of 4 rows, inner four one of 16 columns; 48 to 32 bits; the only non-linear step, the heart of DES security.
- Permutation P: straight permutation of 32 bits.
S-box example: input 011011 to S1: row 01 = 1, column 1101 = 13; row 1 of S1 is 0 15 7 4 14 2 13 1 10 6 12 11 9 5 3 8; column 13 (from 0) is 5; output 0101.
Key schedule: PC-1 drops the 8 parity bits and permutes 56; two 28-bit halves, each rotated left 1 bit (rounds 1, 2, 9, 16) or 2 bits (others); PC-2 picks 48 bits as .
Decryption: the same steps, round keys reversed ( first); a Feistel structure never needs the inverse of f. Test vector: key 133457799BBCDFF1 encrypts 0123456789ABCDEF to 85E813540F0AB405.
Retired: only keys; in 1998 the EFF DES Cracker found a key by brute force in under three days. Triple DES (3DES): encrypt, decrypt, encrypt with two or three keys (112 or 168 bits); strong but a third the speed; being retired for AES.
AES: NIST open competition 1997 to 2000, fifteen candidates; winner Rijndael by the Belgian cryptographers Joan Daemen and Vincent Rijmen; FIPS 197 in 2001; used in WPA2, TLS, VPNs, disk encryption.
- Block: 128 bits as a 4 x 4 state of 16 bytes, filled column by column.
- Key, rounds: 128-bit key 10 rounds; 192-bit 12; 256-bit 14.
- Structure: substitution-permutation network, not Feistel; every round changes all 16 bytes.
Figure: AES-128 flow: round 0 AddRoundKey with K0, rounds 1 to 9 with all four steps, round 10 without MixColumns; key expansion to K0 to K10; the state grid before and after ShiftRows
One AES round:
- SubBytes: each byte through a fixed 16 x 16 S-box (inverse in , then an affine map):
00to63,53toED; the non-linear step. - ShiftRows: row 0 stays; rows 1, 2, 3 rotate 1, 2, 3 bytes left.
- MixColumns: each column multiplied by a fixed matrix over ; each output byte depends on its whole column.
- AddRoundKey: XOR with the 128-bit round key.
Whole cipher: initial AddRoundKey with ; rounds 1 to 9 all four steps; round 10 without MixColumns. Key expansion: 128-bit key to 44 words of 32 bits (11 round keys, to ). Decryption: InvShiftRows, InvSubBytes, AddRoundKey, InvMixColumns, round keys reversed.
A word in AES: ASCII bytes, NEPAL = 4E 45 50 41 4C, padded to 16 (PKCS#7: 11 bytes of value 0B) and filled column by column. With the FIPS 197 example key 2B 7E 15 16 ...: 4E XOR 2B = 65; SubBytes gives 4D. FIPS 197 Appendix B: plaintext 32 43 F6 A8 88 5A 30 8D 31 31 98 A2 E0 37 07 34 gives ciphertext 39 25 84 1D 02 DC 09 FB DC 11 85 97 19 6A 0B 32.
| Point | DES | AES |
|---|---|---|
| Standard | FIPS 46, 1977 | FIPS 197, 2001 |
| Designer | IBM (from Lucifer) | Daemen and Rijmen (Rijndael) |
| Block | 64 bits | 128 bits |
| Key | 56 bits (64 with parity) | 128, 192 or 256 bits |
| Rounds | 16 | 10, 12 or 14 |
| Structure | Feistel: half the block per round | substitution-permutation: whole block per round |
| Round steps | expansion, XOR key, 8 S-boxes, permutation | SubBytes, ShiftRows, MixColumns, AddRoundKey |
| Decryption | same steps, keys reversed | inverse steps, reverse order |
| Security | broken by brute force ( keys) | no practical attack; current standard |
| Speed | slow in software (bit permutations) | fast, processor instructions for it |
By hand: ten AES rounds do not fit the time; "encrypt the word using any suitable AES technique" is answered with the structure and the first round on the state, or with simplified AES (S-AES: 16-bit block, 16-bit key, two rounds). The Numericals panel works both papers' words.
Memory example: the hostel Wi-Fi encrypts every frame with AES-128 under WPA2; DES survives mostly in old systems and exam questions.
Book's slip: its DES operation says "a 6-bit block of ciphertext comes out"; the ciphertext block is 64 bits.
RSA: the public key algorithm, step by step
RSA (Rivest, Shamir, Adleman, MIT, 1977): public key encrypts, private key decrypts; , ; security rests on factoring , the product of two large primes. Idea: multiplying two primes is easy, recovering them from a product hundreds of digits long is practically impossible.
Figure: key generation steps with p 7, q 11 (n 77, phi 60, e 13, d 37), public key (13, 77), private key (37, 77); A encrypts E = 5 to 26, B decrypts 26 to 5
Key generation, once, by the receiver:
- Choose two primes , , large and distinct.
- Modulus ; its bit length is the key size (2048 bits today).
- , Euler's totient (the book's ).
- Public exponent : , ; in practice .
- Private exponent : inverse of modulo , .
- Publish ; keep , , , secret.
For every message with :
Why it works: and Euler's theorem , so .
Why it is secure: from needs , which needs the factors , of ; a 2048-bit has 617 decimal digits and no known method factors it in useful time. Exam-sized numbers only show the method.
The book's letter E, finished
, : , ; (); : smallest with whole is , , so (). Public (13, 77), private (37, 77). E is the 5th letter, .
5^2 = 25
5^4 = 625 mod 77 = 9
5^8 = 81 mod 77 = 4
5^13 = 5^8 x 5^4 x 5 = 4 x 9 x 5 = 180 mod 77 = 26 C = 26
26^2 = 676 mod 77 = 60
26^4 = 3600 mod 77 = 58
26^8 = 3364 mod 77 = 53
26^16 = 2809 mod 77 = 37
26^32 = 1369 mod 77 = 60
26^37 = 60 x 58 x 26: 3480 mod 77 = 15; 15 x 26 = 390 mod 77 = 5 M = 5 = E
Repeated squaring: write the exponent as powers of two (37 = 32 + 4 + 1), square repeatedly mod , multiply the needed squares, reducing after each product; no number exceeds .
Finding d: trial, for ; or the extended Euclidean algorithm (60 = 4 x 13 + 8, 13 = 1 x 8 + 5, 8 = 1 x 5 + 3, 5 = 1 x 3 + 2, 3 = 1 x 2 + 1, back-substituted to 37).
Encrypting a word: number the letters (A = 1 to Z = 26 common, A = 0 to Z = 25 if stated); choose , with above the largest value (); encrypt and decrypt each letter alone. Book example 2, SUZANNE with , , , , : ciphertext 28 21 20 1 5 5 26. The papers' words are worked in the Numericals panel.
Weakness of letter-by-letter RSA: the two N's of SUZANNE both give 5; a substitution cipher open to frequency analysis. Real RSA encrypts one large padded number (OAEP), and in practice only a session key or a digest.
Signing: , checked as ; with the keys above, signs to and .
Memory example: 7 x 11 = 77 is instant both ways, but a 617-digit number defeats every computer on Earth: easy one way, hopeless back.
Book's slips: example 1 sets up and stops (it is 5, the letter E); example 2 says may be any value other than the factors 1, 2, 4, 5, 10 of , but the rule is (6 is no factor of 20 yet shares the factor 2, and has no ).
Diffie-Hellman key exchange
Diffie-Hellman (Whitfield Diffie and Martin Hellman, 1976): key agreement by which two parties sharing no secret exchange public values over an open channel and each computes the same secret key , which an eavesdropper cannot compute. It creates a symmetric session key; it neither encrypts nor signs. Problem solved: a shared key appears at both ends without ever being sent.
Figure: public N = 23, G = 7; A's secret x = 3, R1 = 21; B's secret y = 6, R2 = 4; both reach K = 18; the eavesdropper sees 23, 7, 21, 4
Steps (public: large prime , generator , a primitive root of ):
- A chooses a large random secret , computes .
- A sends to B, never .
- B chooses a large random secret , computes .
- B sends to A, never .
- A computes ; B computes .
Equal because , all mod .
Book's example (correct): , ; : = ; : = ; A: = ; B: (, ); .
Eavesdropper: sees , , , ; needs from , the discrete logarithm problem, infeasible for a 2048-bit prime (for 23, only gives 21).
Man in the middle: plain DH authenticates nobody; Trudy runs one exchange with A and one with B, then decrypts, reads and re-encrypts everything. Cure: authenticate the exchanged values with signatures and certificates (TLS, IKE for IPsec). TLS 1.3, IKE and SSH use ephemeral DH (fresh , per session): forward secrecy, a stolen long-term key cannot unlock past sessions.
Memory example, paint: common public yellow; each adds a secret colour, sends the mixture, adds the secret colour again to what arrives; both get the same brown; a watcher cannot un-mix the secrets.
The book: a large prime with also prime (a safe prime: 23 = 2 x 11 + 1) and "also a prime number"; the real requirement is that is a primitive root of (its powers run through 1 to ); 7 is a primitive root of 23 (first returns to 1 at ).
Digital signatures: how they work
Digital signature: a value computed from a message and the signer's private key that anyone with the signer's public key can check; proves who sent it (authentication), that it was not changed (integrity), and that the sender cannot deny it (non-repudiation). Needed because an electronic document can be copied and edited without a trace, so its signature must depend on the exact content and a secret only the signer holds.
Figure: signing at A (hash, encrypt the digest with A's private key, send M with S); verifying at B (hash M to H1, decrypt S with A's public key to H2, compare)
Signing at A:
- Hash the message (SHA-256): a short fixed-length digest .
- Encrypt the digest with A's private key: the signature (RSA: ).
- Send with , usually with A's certificate.
Verifying at B:
- Hash the received message: .
- Decrypt the signature with A's public key: .
- Compare: means valid (only A's private key could make it, message unchanged); different means altered or forged, reject.
Why sign the hash: RSA on a long document is slow; the digest is small (256 bits for SHA-256) whatever the size; one changed bit changes about half the digest's bits. A good hash is one-way and collision resistant; MD5 and SHA-1 have known collisions and are no longer used for signatures; SHA-256 is.
Properties (book): verifiable, non-forgeable, non-repudiable. Different for every document, so it cannot be cut from one and pasted on another. No confidentiality: the message travels in the clear unless also encrypted (as PGP does).
Where the public key comes from: a certificate (X.509) binds a name to a public key and is signed by a certification authority (CA) the receiver trusts; browsers and operating systems ship trusted root CAs; this is the public key infrastructure (PKI). Nepal's Electronic Transactions Act, 2063 gives digital signatures legal force, with certifying authorities licensed under the Office of the Controller of Certification.
| Point | MAC | Digital signature |
|---|---|---|
| Key | one shared secret key | signer's private key; checked with its public key |
| Who can verify | holders of the shared key | anyone |
| Non-repudiation | no: either end could make it | yes: only the signer could |
| Speed | fast (HMAC) | slower (RSA, ECDSA) |
| Used in | TLS records, IPsec packets | certificates, PGP mail, software updates |
Example with the RSA card's keys (, , ): digest ; A signs ; B checks , equal to its own hash; a tampered message's digest (say 6) would not match.
Memory example: Windows checks Microsoft's signature on an update before installing it; a file changed by one byte, or signed by anyone else, is refused. Algorithms: RSA signatures, DSA, ECDSA, EdDSA.
Book's slip: it says signing generates a hash "through a complex mathematical computation that generates a large prime number"; a hash gives a fixed-length digest, not a prime; primes belong to the RSA key pair.
PGP: how an e-mail is secured
PGP (Pretty Good Privacy, Phil Zimmermann, 1991): e-mail security program giving confidentiality, authentication, integrity and compression by combining a hash, a digital signature, a one-time symmetric session key and the receiver's public key; message format standardised as OpenPGP (RFC 4880). Mail needs it because SMTP carries messages in plain text through several servers, readable by anyone with access, and a forged sender costs nothing; PGP protects the message end to end.
Figure: six sending steps at A (hash, sign, compress, encrypt, lock the key, base64) with the services they give, and five receiving steps at B
Securing one mail from A to B:
- Hash the message (SHA-256 now; MD5 or SHA-1 in early versions).
- Sign: encrypt the digest with A's private key (RSA or DSA), attach it.
- Compress message and signature (ZIP).
- Encrypt the bundle with a fresh random session key, for this message only (IDEA, 3DES, CAST-128, AES).
- Lock the key: encrypt the session key with B's public key (RSA or ElGamal), attach it.
- Convert to radix-64 (base64) text and send.
At B, backwards: decode base64; decrypt the session key with B's private key; decrypt the bundle; decompress; hash the message and compare with the digest recovered from the signature with A's public key.
Order: sign before compressing (the signature covers the message as written, checkable without recompressing); compress before encrypting (less redundancy for cryptanalysis, less to encrypt); session key (public key encryption is slow: only the short key goes through RSA).
Services: authentication and integrity (signature); confidentiality (session key, symmetric encryption); compression (ZIP); e-mail compatibility (radix-64, mail carries 7-bit text); segmentation (long messages split and rejoined).
Keys: installing PGP makes a key pair; the private key stored encrypted under a passphrase typed at each use; public keys on websites or key servers; public key ring (others' keys) and private key ring (own pairs); web of trust: users sign each other's keys, no central authority.
S/MIME: the alternative in mail programs; same ingredients, but public keys from X.509 certificates issued by CAs.
Memory example: posting an answer sheet: sign it, fold it small, lock it in a box with a new padlock, put the padlock's only key in an envelope only the exam office can open, and write the address in plain letters.
Book's slips: it dates PGP to 1995 (released 1991); it says "MD5 or SHA for calculating the message digest such as CAST, Triple-DES or IDEA" (MD5 and SHA make the digest; CAST, 3DES, IDEA encrypt).
SSL and TLS: securing a TCP connection
SSL (Secure Sockets Layer, Netscape, 1995) and successor TLS (Transport Layer Security, IETF; 1.3 is RFC 8446): a layer between TCP and the application that authenticates the server (optionally the client), agrees session keys, and gives the application's data confidentiality and integrity. Needs TCP below for reliable in-order delivery. HTTPS is HTTP over TLS on port 443; SMTPS 465, IMAPS 993, or STARTTLS.
Figure: the stack (application, SSL/TLS with handshake, alert and change cipher spec over the record protocol, TCP port 443, IP) and the eight-step handshake between a browser and a bank site
Four protocols: handshake (authenticates, agrees keys); change cipher spec (switch to the new keys now); alert (warnings, fatal errors such as a bad certificate); record (carries everything).
Handshake, classic RSA form (SSL 3.0, TLS 1.2):
- ClientHello: supported versions, cipher suites, a client random.
- ServerHello: chosen version and suite, a server random.
- Certificate: server's public key signed by a CA; the client checks it against trusted CAs and the site name.
- ServerHelloDone.
- ClientKeyExchange: a random pre-master secret encrypted with the server's public key (only the real server decrypts it).
- Key derivation: master secret from the pre-master secret and both randoms; from it the session keys (encryption and MAC key each way).
- ChangeCipherSpec and Finished from each side; Finished is a MAC over the whole handshake, catching tampering.
- Application data, encrypted and authenticated by the record protocol.
Record protocol: fragment (up to = 16,384 bytes); compress (optional, dropped in TLS 1.3); add a MAC (HMAC); encrypt (AES, ChaCha20); add a 5-byte header (content type, version, length). The book: fragmentation, compression, message integrity, confidentiality, framing.
Services: server authentication by certificate, optional client authentication, confidentiality (symmetric), integrity (MAC), key exchange (public key): the hybrid scheme.
| Version | Year | Status |
|---|---|---|
| SSL 2.0, 3.0 | 1995, 1996 (Netscape) | broken; prohibited (RFC 6176, RFC 7568) |
| TLS 1.0, 1.1 | 1999 (RFC 2246), 2006 (RFC 4346) | deprecated (RFC 8996) |
| TLS 1.2 | 2008 (RFC 5246) | in use |
| TLS 1.3 | 2018 (RFC 8446) | current: one round trip, ephemeral DH only, no RSA key transport |
Uses (book's advantages): online card payments, logins, webmail, secure file transfer (HTTPS, FTPS), SSL VPNs for remote access through a browser.
Memory example: paying an exam form fee through a digital wallet in the browser: https and a padlock; the browser checked the certificate and agreed session keys; the NTC or WorldLink line carries only ciphertext.
IPsec: AH and ESP, transport and tunnel mode
IPsec (IETF, RFC 4301): protocols securing the IP packets themselves, between two hosts, two routers, or a host and a router; two protocols (AH: authentication and integrity; ESP: also confidentiality), two modes (transport, tunnel), security associations set up by IKE. At the network layer it protects TCP, UDP, ICMP and routing updates without changing applications; works with IPv4 and IPv6 (AH and ESP are IPv6 extension headers).
Figure: packet layouts: original, transport with AH, transport with ESP, tunnel with ESP, tunnel with AH; shaded fields encrypted, brackets authenticated
Modes:
- Transport mode: IPsec header between the original IP header and the transport header; protects only the payload; the original header (real addresses) travels as is; end to end, host to host.
- Tunnel mode: the whole original packet becomes the payload of a new IP packet with a new header, usually gateway to gateway; inner addresses hidden; builds VPNs.
AH (Authentication Header), IP protocol 51: source authentication, integrity, anti-replay; no confidentiality. Fields: next header (8 bits, e.g. 6 for TCP); payload length (8, the AH's own length); reserved (16); SPI (32, names the SA like a virtual circuit number); sequence number (32, up by one per packet, against replay); authentication data (variable: integrity check value, a keyed hash over the packet with fields that change in transit, TTL and header checksum, counted as zero).
ESP (Encapsulating Security Payload), IP protocol 50: confidentiality by encryption plus authentication, integrity, anti-replay. ESP header (SPI and sequence number, 32 bits each); encrypted payload; ESP trailer (padding 0 to 255 bytes, 8-bit pad length, 8-bit next header); ESP authentication data at the end (computed in one pass on the way out). Payload and trailer encrypted; header to trailer authenticated.
| Point | AH | ESP |
|---|---|---|
| IP protocol number | 51 | 50 |
| Confidentiality | no | yes, encryption (AES) |
| Integrity, source authentication | yes | yes (optional) |
| Anti-replay | yes, sequence number | yes, sequence number |
| Covers outer IP header | yes, fixed fields | no |
| Through NAT | fails (NAT changes authenticated addresses) | works, with UDP encapsulation |
| Use today | rare | almost every IPsec VPN |
Security association (SA): a one-way agreement holding protocol, mode, algorithms, keys, sequence counter, replay window, lifetime; identified by SPI, destination address and protocol; two SAs for two-way traffic; stored in the security association database (SAD); the security policy database (SPD) decides per packet: protect, pass or drop.
IKE (Internet Key Exchange, IKEv2 RFC 7296): authenticates the ends (certificates or pre-shared key) and agrees fresh keys with Diffie-Hellman.
Memory example: Pokhara branch and Kathmandu head office routers in tunnel mode with ESP; packets cross the ISP as gibberish addressed router to router; staff notice nothing.
The book says AH's authentication data covers "the entire IP datagram"; fields changing in transit (TTL, header checksum) are set to zero for the calculation, and the hash is keyed (a MAC).
VPN: a private network over a public one
Virtual private network: a private network built over a public one (the Internet) by tunnelling: each packet encrypted and authenticated, then carried inside another packet between the VPN endpoints, so distant sites and users communicate as if on one private LAN. A leased line is secure but expensive, the Internet cheap but public; a VPN gives the privacy of the first at the price of the second (virtual: no private wires; private: no outsider reads or joins).
Figure: Kathmandu head office LAN (192.168.1.0/24) and Pokhara branch LAN (192.168.2.0/24) behind VPN gateways joined by a site-to-site IPsec tunnel across the Internet; a remote user's laptop with its own tunnel to the head office; inside a tunnel, a new IP header, ESP, the encrypted original packet
How it works:
- Authenticate: client or gateway proves its identity (certificate, pre-shared key, username and password with a one-time code).
- Agree keys: IKE for IPsec, a TLS handshake for an SSL VPN.
- Encapsulate: a packet for the private network is encrypted, authenticated and wrapped in a new packet addressed to the far endpoint.
- Cross the Internet: routers see only public endpoint addresses and ciphertext.
- Decapsulate: the far endpoint checks, decrypts and delivers inside its LAN; replies return the same way.
| Type | Joins | Example |
|---|---|---|
| Remote access (host to gateway) | a user's device to the organisation, via client software | staff at home reaching the office file server |
| Site to site, intranet (gateway to gateway) | one organisation's sites, permanently | head office and branches |
| Site to site, extranet | an organisation to a partner, limited access | a company and its supplier's ordering system |
Protocols: IPsec tunnel mode with ESP (usual site to site); SSL/TLS VPNs (OpenVPN, browser portal; common for remote access); L2TP over IPsec; WireGuard (modern, small); PPTP (old, insecure).
- Advantages: far cheaper than leased lines; confidentiality, integrity, authentication over a public network; remote users join from anywhere; sites added in software.
- Disadvantages: encryption and extra headers cost speed and bandwidth; performance depends on the Internet; setup and keys to manage; a stolen or infected laptop with VPN access is an attacker inside.
Example: head office in Kathmandu (192.168.1.0/24) and branch in Pokhara (192.168.2.0/24), each on an ordinary ISP connection; their routers run a site-to-site IPsec VPN; a branch PC opens the accounts server at 192.168.1.10 as if down the corridor; an accountant at home in Bhaktapur uses a remote-access VPN client.
Memory example: a sealed pipe inside a public road. Consumer "VPN apps" that make a phone appear in another country use the same tunnel, from one user to the provider's server.
Securing wireless LANs: WEP, and why WPA2 replaced it
WEP (Wired Equivalent Privacy): security protocol of the original IEEE 802.11 (1997), meant to make a wireless LAN as private as a wired one; encrypts each frame with the RC4 stream cipher keyed by a 24-bit IV plus a shared 40 or 104-bit key, and appends a CRC-32 integrity check; broken, replaced by WPA2. Radio passes through walls, so anyone in range can capture frames. Goals: confidentiality, access control, integrity.
Figure: IV (24 bits) and shared key (40 or 104) seed RC4; the keystream is XORed with the data plus its CRC-32 ICV; the frame carries the IV in the clear, a key ID and the ciphertext; the book's example 0101 XOR 1100 = 1001
Encrypting a frame:
- Integrity value: CRC-32 of the data, the 32-bit ICV, appended.
- Seed: the 24-bit IV (meant to change per frame) in front of the shared key: 24 + 40 = 64 or 24 + 104 = 128 bits.
- Keystream: RC4 keyed with the seed, as long as the frame.
- Encrypt: data and ICV XORed with the keystream.
- Send: IV in the clear, a key ID, the ciphertext.
Decryption: IV from the frame plus the receiver's key, RC4, same keystream, XOR, check the CRC. Book's example: keystream 0101 XOR plaintext 1100 = 1001; XOR with 0101 again gives 1100.
Key sizes: 10 hexadecimal digits = 40 bits, with the IV "64-bit WEP"; 26 hexadecimal digits = 104 bits, "128-bit WEP". Authentication: open system (none) or shared key (a challenge encrypted with WEP, which hands an eavesdropper keystream).
Weaknesses:
- IV too short: 24 bits, 16,777,216 keystreams; a busy access point (1500-byte frames at 11 Mbps) uses all in about 5 hours; by the birthday effect a repeat is likely after about 4,800 frames; same IV and key, same keystream: .
- Weak RC4 keys: the IV, sent in the clear and placed before the key, leaks key bytes for certain values (Fluhrer, Mantin and Shamir attack, 2001); free tools recover the key in minutes.
- CRC-32 no integrity against an attacker: linear and keyless; flipped ciphertext bits matched by fixing the ICV; no replay protection.
- One static key: shared by every user, rarely changed, no key management; one leak exposes everyone.
| Point | WEP | WPA | WPA2 | WPA3 |
|---|---|---|---|---|
| Year, basis | 1997, 802.11 | 2003, Wi-Fi Alliance interim | 2004, IEEE 802.11i | 2018, Wi-Fi Alliance |
| Cipher | RC4 | RC4 with TKIP | AES (CCMP) | AES (CCMP or GCMP) |
| Keys | static shared key, 24-bit IV | new key per packet, 48-bit sequence counter | fresh session keys, 4-way handshake | SAE handshake, forward secrecy |
| Integrity, status | CRC-32; broken | Michael MIC; deprecated | CBC-MAC in CCMP; usual minimum | CCMP or GCMP; current |
Personal (one passphrase: pre-shared key in WPA2, SAE against offline guessing in WPA3) and Enterprise (each user logs in through IEEE 802.1X and EAP to a RADIUS server).
Memory example: a hostel router still on WEP is a locked door with the key taped to it; the fix is one setting, WPA2-AES or WPA3.
Firewalls: what they are, how they protect, their types, and router ACLs
Firewall: a device or program at the boundary between a trusted internal network and an untrusted one (the Internet) that examines traffic crossing it and passes or blocks each packet or connection by a security policy, its rule set. Design goals (Cheswick and Bellovin): all traffic between inside and outside passes through it; only policy-authorised traffic passes; the firewall resists penetration. Book's picture: a wall between the corporate LAN and the outside world; a valid web request passes, an invalid Telnet request bounces off.
How a firewall protects a network:
- Single choke point: every connection crosses one place; policy enforced, attempts logged and audited.
- Filtering by rule: blocks unwanted source addresses, ports, protocols (Telnet, file sharing, remote desktop from outside); default deny.
- Only expected replies: stateful firewalls admit inbound packets only for connections started inside.
- Hiding the inside: NAT shows one public address, not internal hosts and layout.
- Content control: a proxy blocks malware, banned sites, file types, dangerous commands; can require login.
- Containment and alerting: separates zones (DMZ), slows worms between segments, resists floods (SYN floods), alerts the administrator.
Book's reasons: stop intruders interfering with daily running (denial of service, SYN and FIN attacks), deleting or modifying information, obtaining secrets; allow only authorised access; stop illegal changes (replacing the official homepage).
Figure: layers (application, session, transport, network, data link) with the type that inspects each: application gateway, circuit-level gateway, stateful inspection, packet filter
Types, by layer inspected:
- Packet filtering (first generation, stateless): router or host checks each packet alone against a rule table using IP and TCP/UDP headers: source and destination IP, protocol, source and destination port, TCP flags, interface and direction; permit or deny; first match decides. Fast, cheap, invisible; but no state (a forged "reply" looks valid), no content, cannot tell spoofed sources, rule lists error-prone.
- Stateful inspection (dynamic packet filter): also keeps a state table of open connections (addresses, ports, TCP state); admits inbound packets only for open connections or explicit rules; an out-of-the-blue ACK is dropped; most firewalls today.
- Application-level gateway (proxy): application layer; the client connects to the proxy, which checks the request (URL, FTP command, mail and attachments, user) and opens a second connection to the server, relaying the reply; one proxy per service (HTTP, SMTP, FTP, DNS); most secure, full logs; slower (each connection handled twice), new applications need new proxies.
- Circuit-level gateway: session layer; checks the TCP handshake (and user), then relays bytes without reading them; SOCKS is the standard example; often for outgoing connections from trusted insiders.
- Next-generation firewall (NGFW): stateful plus deep packet inspection, application recognition whatever the port, intrusion prevention, TLS inspection, user identity.
Network firewall guards a whole network at its edge; host-based firewall (Windows Defender Firewall, Linux nftables) one machine; a home Wi-Fi router has a small stateful one.
| Point | Packet filter | Stateful inspection | Application gateway |
|---|---|---|---|
| Layer | network, transport | network, transport, with state | application |
| Decides on | each packet's header | header plus connection state | content and user |
| Speed | fastest | fast | slowest |
| Security | lowest | good | highest |
| Example | router ACL | home router, perimeter firewall | filtering HTTP proxy |
Memory example, the hostel gate's chowkidar: checking each name against a list (packet filter); remembering who went out so only they come back (stateful); walking each visitor to the room and checking the bag (application gateway); checking the visitors' book once and then not watching (circuit-level).
Figure: packet filter flowchart (packet arrives, read header, rule k matches?, permit or deny, more rules?, implicit deny) with a hostel router's five rules and three traced packets
How a packet filter works:
- Receive a packet on an interface, inbound or outbound.
- Read the header: source and destination IP, protocol (TCP, UDP, ICMP), source and destination port, TCP flags.
- Compare with the rules, top down: each rule gives values (or "any") and an action.
- First match decides: forward (permit) or drop (deny); the rest is not read.
- No match: the implicit deny drops it.
- Log the denied packets.
Hostel router's rules (example): 1 deny anything from 203.0.113.0/24; 2 deny TCP 23 (Telnet) to 192.168.10.0/24; 3 permit TCP 443 to the web server 192.168.10.5; 4 permit 192.168.10.0/24 out on TCP 80 and 443; 5 deny everything else. Traces: 198.51.100.7 to 192.168.10.5:443, rules 1 and 2 miss, rule 3 permits; 203.0.113.9 to the same server, rule 1 denies first; 198.51.100.7 to 192.168.10.20:23, rule 2 denies.
Book's filter table blocks: incoming from network 121.34.0.0; incoming to any internal Telnet server (port 23); incoming to internal host 192.168.0.8; outgoing to web servers (port 80), so staff cannot browse.
Router ACLs
Access control list (ACL): ordered permit and deny statements applied to one router interface in one direction (in or out); compared top down; first match decides; every list ends in an implicit "deny any". Turns a router into a packet filtering firewall.
| Point | Standard ACL | Extended ACL |
|---|---|---|
| Cisco numbers | 1 to 99, 1300 to 1999 | 100 to 199, 2000 to 2699 |
| Matches | source address only | source, destination, protocol, ports |
| Placed | near the destination | near the source |
Wildcard mask: the subnet mask inverted, 0 must match, 1 ignore; /24 (255.255.255.0) gives 0.0.0.255.
Blocking the paper's network 202.70.91.0/24 coming in on FastEthernet 0/0, all else passing:
Router(config)# access-list 10 deny 202.70.91.0 0.0.0.255
Router(config)# access-list 10 permit any
Router(config)# interface FastEthernet0/0
Router(config-if)# ip access-group 10 in
Extended equivalent: access-list 110 deny ip 202.70.91.0 0.0.0.255 any, access-list 110 permit ip any any, then ip access-group 110 in on FastEthernet0/0. Line 1 denies sources 202.70.91.0 to 202.70.91.255; line 2 is essential (otherwise the implicit deny drops all traffic on the interface); lines 3 and 4 apply it inbound, so packets are dropped on arrival, before routing. Check with show access-lists (match counters) and show ip interface FastEthernet0/0.
Placement: screened subnet: border router filters first, firewall second, public servers (web, mail) in a DMZ (demilitarised zone), so a hacked web server is still outside the trusted LAN; simpler set-ups: a single screening router, or a dual-homed host.
Figure: Internet, border router (ACL), firewall (stateful or NGFW), a DMZ with web and mail servers, the trusted LAN with PCs and a database server, a NIDS sensor on a mirror port, HIDS on the servers
Limits: cannot stop traffic going around it (a phone's mobile hotspot, an infected USB drive), insiders, malware in allowed or encrypted traffic without deeper inspection, or phishing; an IDS watches behind it.
The book's table is captioned "Figure 2.26" in chapter 8 (between figures 8.25 and 8.27).
Intrusion detection systems
Intrusion detection system (IDS): a device or program that monitors a network or its hosts for malicious activity or policy violations and raises an alert, to an administrator or a SIEM (security information and event management) system. An IDS detects and reports; an intrusion prevention system (IPS) sits in the traffic's path and also blocks. A firewall decides at the gate by rules; attacks inside allowed traffic (an exploit to the web server's port 443), insiders and unforeseen attacks pass, and the IDS watches what gets past.
| Point | Network IDS (NIDS) | Host IDS (HIDS) |
|---|---|---|
| Placed | key points (behind the firewall, in the DMZ), fed by a mirror (SPAN) port or tap | on each protected host, as an agent |
| Watches | packets of a whole segment | the host's traffic, logs, processes, system files |
| Catches | scans, floods, exploits on the wire | changed or deleted system files, logins, malware |
| Misses | encrypted payloads, other segments | other hosts; disabled by an attacker owning the host |
| Examples | Snort, Suricata, Zeek | OSSEC, Wazuh, Tripwire |
- Signature-based (misuse): matches known attack patterns like antivirus signatures; few false alarms, clear explanation; blind to new (zero-day) attacks until a signature exists; constant updates.
- Anomaly-based: a baseline of normal behaviour (volumes, ports, login times), deviations flagged; can catch new attacks; more false alarms; needs a training period.
Example signature (Snort): alert tcp any any -> 192.168.10.0/24 23 (msg:"Telnet attempt"; sid:1000001; rev:1;).
The book splits NIDS by timing: on-line (real time) and off-line (stored data afterwards); a HIDS snapshots critical system files and alerts when a later snapshot shows a change or deletion.
Alerts: true positive (real attack flagged); false positive (alarm on harmless activity; too many and staff stop reading); false negative (attack missed, the worst case).
| Point | Firewall | IDS | IPS |
|---|---|---|---|
| Job | allow or block by policy | detect and alert | detect and block |
| Position | inline, at the boundary | beside the traffic (a copy) | inline |
| Effect on traffic | passes or drops | none | drops attack packets |
Figure: the network placement drawing again: NIDS on the LAN switch's mirror port, HIDS on the servers
Memory example: the firewall is the hostel gate's chowkidar; the IDS is the corridor CCTV, which records and alerts the warden but stops no one; the IPS is a guard who also steps in when the camera spots trouble.
49 calculations from 25 of the 27 sittings · 19 more the Insights book works · grouped by method
Numericals
Every calculation the board papers have set, worked in full and grouped by the method it needs, with the method once at the top of each group; then the examples the Insights book works that no paper has set yet. Every number is recomputed when the page is built, so none of them is typed.
How to use this page
- Learn the method, then the numbers do not matter: the same methods come back with new values.
- Write the given values first, then the formula, then the substitution, then the answer in bold with its unit. The working is what earns the marks.
- Where a paper is misprinted, the reading used is stated above the solution rather than assumed.
Throughput: the data actually delivered per second PIN 2/27
Ch 2 · Physical layer2 from 2 of the 27 sittings
- Find the amount of data actually delivered, in bits (1 byte = 8 bits).
- Find the time it took, in seconds (1 minute = 60 s).
- Divide the data delivered by the time taken: , in bits per second.
- Compare with the bandwidth: utilization = throughput / bandwidth, never above 100 %.
2080 Bhadra · Q22 marksIf a file of 1000 bytes was sent over a network in 2 seconds, calculate throughput.
Given: data delivered = 1,000 bytes; time taken t = 2 s.
In bits: 1,000 bytes × 8 = 8,000 bits.
In bytes the same rate is 1,000 / 2 = 500 bytes per second.
Answer: throughput = 4,000 bps = 4 kbps (500 bytes per second).
2078 Bhadra · Q23 marksA network with bandwidth of 20 Mbps can pass only an average of 18,000 frames per minute with each frame carrying an average of 20,000 bits. Calculate the throughput of this network.
Given: bandwidth = 20 Mbps; 18,000 frames per minute; 20,000 bits per frame.
Bits delivered in one minute: 18,000 × 20,000 = 360,000,000 bits.
Per second (1 minute = 60 s):
Compared with the bandwidth: 6 / 20 = 0.3, so the network delivers only 30 % of its 20 Mbps capacity.
Answer: throughput = 6 Mbps, 30 % of the bandwidth.
Channel capacity: SNR and the Shannon limit PIN 1/27
Ch 2 · Physical layer1 from 1 of the 27 sittings
- Put the signal and noise powers in the same unit, then , a plain ratio.
- In decibels: .
- Shannon capacity: , with B in hertz and SNR as a ratio, never in dB.
- On a calculator, .
2066 Bhadra · Q2b4+4 marksCalculate SNR and maximum channel capacity of a cat6 channel having bandwidth 300 MHz with 2mW and 200 μW as signal and noise power respectively.
How this is readCat 6 cable is specified up to 250 MHz (Cat 6A to 500 MHz); the 300 MHz given is used as set.
Given: bandwidth B = 300 MHz = Hz; signal power S = 2 mW; noise power N = 200 µW = 0.2 mW.
1. SNR, with both powers in milliwatts:
2. Maximum channel capacity (Shannon), with SNR as a ratio:
Answer: SNR = 10 (10 dB); maximum channel capacity = 1.04 Gbps (about 1,037.8 Mbps).
CRC by modulo-2 division PIN 3/27
Ch 3 · Data link layer3 from 3 of the 27 sittings
- Write the generator as bits (a coefficient for every power, 0s included); its degree is one less than its number of bits.
- Append zeros to the message .
- Divide by the generator in modulo 2: wherever the leading bit is 1, XOR the generator under it; where it is 0, XOR zeros; bring down the next bit each time.
- The last bits are the remainder , the CRC (keep its leading 0s).
- Transmit followed by ; it divides by with remainder 0.
- At the receiver, divide what arrived by the same : remainder 0 means accept; any other remainder means an error is detected.
2082 Baishakh · Q35 marksCalculate the CRC for a 8 bit sequence 11001101. The generator polynomial is x⁴ + x² + 1. Also find the transmitted bit frame.
Given: message 11001101 (8 bits), generator .
Generator as bits: =
10101, degree , so 4 zeros are appended: dividend
110011010000.
Modulo-2 division:
11111101 quotient
10101 ) 110011010000
10101
-----
11001
10101
-----
11000
10101
-----
11011
10101
-----
11100
10101
-----
10010
10101
-----
01110
00000
-----
11100
10101
-----
1001 remainder
CRC (remainder, 4 bits) = 1001.
Check at the receiver: 110011011001 divided by 10101:
11111101 quotient
10101 ) 110011011001
10101
-----
11001
10101
-----
11000
10101
-----
11011
10101
-----
11101
10101
-----
10000
10101
-----
01010
00000
-----
10101
10101
-----
0000 remainder
The remainder is 0000, so the frame is accepted.
Answer: CRC = 1001; transmitted frame = 110011011001 (the message followed by the CRC).
2081 Bhadra · Q35 marksCalculate the CRC for a 10 bit sequence 1010001101. The generator polynomial is x⁵ + x⁴ + x² + 1. Also find the transmitted bit frame.
Given: message 1010001101 (10 bits), generator
.
Generator as bits: =
110101, degree ; append 5 zeros: dividend
101000110100000.
Modulo-2 division:
1101010110 quotient
110101 ) 101000110100000
110101
------
111011
110101
------
011101
000000
------
111010
110101
------
011111
000000
------
111110
110101
------
010110
000000
------
101100
110101
------
110010
110101
------
001110
000000
------
01110 remainder
CRC (remainder, 5 bits, the leading 0 kept) = 01110.
Check at the receiver: 101000110101110 divided by 110101:
1101010110 quotient
110101 ) 101000110101110
110101
------
111011
110101
------
011101
000000
------
111010
110101
------
011111
000000
------
111110
110101
------
010111
000000
------
101111
110101
------
110101
110101
------
000000
000000
------
00000 remainder
The remainder is 00000: no error, the frame is accepted.
Answer: CRC = 01110; transmitted frame = 101000110101110.
2080 Bhadra · Q35 marksGiven message is M (x) = x7 + x4 +x3 +x2 + 1 and the generator is G (x) = x3 + 1. Show the actual bit string transmitted, suppose the third bit from the left is inverted during the transmission. Show how the error is detected at the receiver's end.
How this is readThe powers are printed on the line (x7, x4, x3, x2, x3); they are read as and .
Given: , .
As bits: has the powers 7, 4, 3, 2 and 0, so 10011101;
= 1001, degree . Append 3 zeros: dividend
10011101000.
Modulo-2 division at the sender:
10001100 quotient
1001 ) 10011101000
1001
----
0001
0000
----
0011
0000
----
0110
0000
----
1101
1001
----
1000
1001
----
0010
0000
----
0100
0000
----
100 remainder
CRC = 100, so the bit string transmitted is
10011101100.
The error: the third bit from the left is inverted (0 becomes 1), so the
receiver gets 10111101100.
Detection at the receiver: it divides the received string by the same generator:
10101000 quotient
1001 ) 10111101100
1001
----
0101
0000
----
1011
1001
----
0100
0000
----
1001
1001
----
0001
0000
----
0010
0000
----
0100
0000
----
100 remainder, not zero
The remainder is 100, not zero, so the receiver knows the frame is damaged,
discards it and the frame is retransmitted. (Without the error the remainder would be
000.)
Answer: transmitted 10011101100; received 10111101100; remainder 100 ≠ 0, so the error is detected.
Bit stuffing PIN 3/27
Ch 3 · Data link layer3 from 3 of the 27 sittings, 1 from the book
- Scan the data from the left, counting consecutive 1s.
- After every run of five 1s, insert (stuff) a 0 and start counting again; a 0 in the data also resets the count.
- The flag
01111110is added at both ends of the frame, if the question asks for the frame. - Check: the receiver deletes the 0 after every five 1s and must get the data back.
2075 Ashwin · Q32 marksA bit string 01111011111101111110 needs to be transmitted at the data link layer. What is the string actually transmitted after bit stuffing?
Given: the bit string 01111011111101111110 (20 bits). Rule: after every five
consecutive 1s, the sender stuffs a 0.
Working: split the string into runs; every run of five 1s gets a stuffed 0 after it (shown as [0]):
data 01111011111101111110 runs 0 1111 0 111111 0 111111 0 stuffed ([0]) 0 1111 0 11111[0]1 0 11111[0]1 0 sent 0111101111101011111010
2 bits are stuffed, so 22 bits are sent. Check: the receiver deletes the 0 after
each run of five 1s and gets 01111011111101111110 back; six 1s in a row now occur only in the
flag.
Answer: the string actually transmitted is 0111101111101011111010.
2070 Chaitra · Q33 marksA bit string 01111011111011111110 needs to be transmitted at the data link layer what is string actually transmitted after bit stuffing, if flag patterns is 01111110.
Given: the bit string 01111011111011111110 (20 bits), flag 01111110. Rule: after every five
consecutive 1s, the sender stuffs a 0.
Working: split the string into runs; every run of five 1s gets a stuffed 0 after it (shown as [0]):
data 01111011111011111110 runs 0 1111 0 11111 0 1111111 0 stuffed ([0]) 0 1111 0 11111[0] 0 11111[0]11 0 sent 0111101111100111110110 frame 01111110 0111101111100111110110 01111110
2 bits are stuffed, so 22 bits are sent. Check: the receiver deletes the 0 after
each run of five 1s and gets 01111011111011111110 back; six 1s in a row now occur only in the
flag.
Answer: the string actually transmitted is 0111101111100111110110, and the whole frame with its flags is 01111110 0111101111100111110110 01111110.
2068 Baishakh · Q102 marksA bit string 0111101111101111110 needs to be transmitted at the data link layer. What is the string actually transmitted after bit stuffing?
Given: the bit string 0111101111101111110 (19 bits). Rule: after every five
consecutive 1s, the sender stuffs a 0.
Working: split the string into runs; every run of five 1s gets a stuffed 0 after it (shown as [0]):
data 0111101111101111110 runs 0 1111 0 11111 0 111111 0 stuffed ([0]) 0 1111 0 11111[0] 0 11111[0]1 0 sent 011110111110011111010
2 bits are stuffed, so 21 bits are sent. Check: the receiver deletes the 0 after
each run of five 1s and gets 0111101111101111110 back; six 1s in a row now occur only in the
flag.
Answer: the string actually transmitted is 011110111110011111010.
Insights on Computer Networks, p. 59Find the data stream sent after framing with the flag 01111110 and bit stuffing, for the data 01001111110111110.
Given: the bit string 01001111110111110 (17 bits), flag 01111110. Rule: after every five
consecutive 1s, the sender stuffs a 0.
Working: split the string into runs; every run of five 1s gets a stuffed 0 after it (shown as [0]):
data 01001111110111110 runs 0 1 00 111111 0 11111 0 stuffed ([0]) 0 1 00 11111[0]1 0 11111[0] 0 sent 0100111110101111100 frame 01111110 0100111110101111100 01111110
2 bits are stuffed, so 19 bits are sent. Check: the receiver deletes the 0 after
each run of five 1s and gets 01001111110111110 back; six 1s in a row now occur only in the
flag.
Answer: the string actually transmitted is 0100111110101111100, and the whole frame with its flags is 01111110 0100111110101111100 01111110.
ALOHA throughput and its maximum PIN 1/27
Ch 3 · Data link layer1 from 1 of the 27 sittings
- Take as the mean number of frames offered per frame time, Poisson-distributed: .
- A frame succeeds only if no other frame starts in its vulnerable time: one frame time (one slot) for slotted ALOHA, two for pure ALOHA.
- Throughput = times that probability: (slotted), (pure).
- Set for the best load, and substitute it back for the maximum.
2068 Baishakh · Q24 marksCalculate the efficiency of slotted Aloha.
Given: slotted ALOHA: time is divided into slots of one frame time , and frames are sent only at the start of a slot. Let be the mean number of frames (new and retransmitted) offered per slot, Poisson-distributed:
Success: a frame gets through only if no other frame is sent in the same slot (the vulnerable time is one slot):
Throughput (successful frames per slot, the efficiency):
Maximum: differentiate and set to zero:
(The second derivative is negative at , so this is a maximum.)
For contrast, pure ALOHA: the vulnerable time is two frame times, so ; gives and = 0.1839, about 18.4 %.
At in slotted ALOHA, 36.8 % of the slots carry a good frame, 36.8 % are empty () and 26.4 % hold collisions.
Answer: the maximum efficiency of slotted ALOHA is 1/e = 0.3679, about 36.8 %, reached when frame per slot: twice that of pure ALOHA (18.4 %).
The one's complement checksum BOOK
Ch 3 · Data link layernot set by a paper yet, 1 from the book
- Divide the data into segments of bits.
- Add the segments in one's complement arithmetic: a carry out of the top bit is wrapped round and added to the bottom bit.
- The checksum is the complement (every bit inverted) of the sum; send it with the data.
- The receiver adds all the segments and the checksum the same way; if the complement of that sum is all 0s, it accepts the data.
Insights on Computer Networks, p. 65Compute the checksum of the data 10011001 11100010 00100100 10000100 (k = 4 segments of m = 8 bits), and check it at the receiver.
Given: data 10011001 11100010 00100100 10000100, segments of bits.
Sender: add the segments in one's complement arithmetic (a carry out of the 8th bit is added back at the bottom):
10011001 + 11100010 = 101111011 wrap: 01111100 + 00100100 = 10100000 + 10000100 = 100100100 wrap: 00100101
Sum = 00100101; checksum = its complement = 11011010.
Receiver: add the four segments and the checksum: 00100101 +
11011010 = 11111111; complement = 00000000, all zeros, so
the data is accepted.
Answer: checksum 11011010; at the receiver the complemented sum is 00000000: accept.
The Hamming (7,4) code: finding and correcting one wrong bit BOOK
Ch 3 · Data link layernot set by a paper yet, 1 from the book
- Write the 7 received bits as
D7 D6 D5 P4 D3 P2 P1. - Check each parity group (even parity): over positions 1, 3, 5, 7; over 2, 3, 6, 7; over 4, 5, 6, 7. An even number of 1s gives 0, an odd number gives 1.
- Read the syndrome as a binary number: 0 means no error; otherwise it is the position of the wrong bit.
- Flip that bit to get the corrected codeword; the data bits are D7 D6 D5 D3.
Insights on Computer Networks, pp. 69 and 70A seven-bit Hamming code is received as 1110111. Find the correct code.
How this is readInsights finds the syndrome 100 = 4 and stops at "the 4th bit in the codeword is incorrect"; it never writes the corrected code the example asks for. It is 1111111.
Given: received 7-bit Hamming code 1110111, even parity, laid out as:
D7 D6 D5 P4 D3 P2 P1 1 1 1 0 1 1 1
Parity checks (P1 checks 1, skips 1; P2 checks 2, skips 2; P4 checks 4, skips 4):
C1: D7 D5 D3 P1 = 1111 4 ones, even: 0 C2: D7 D6 D3 P2 = 1111 4 ones, even: 0 C4: D7 D6 D5 P4 = 1110 3 ones, odd: 1
Syndrome = 100 = 4, so bit 4 (P4) is wrong. Flip it: 0 becomes 1.
Answer: the correct code is 1111111, carrying the data bits D7 D6 D5 D3 = 1111. All three checks on 1111111 give 0.
VLSM: a subnet sized to each department, minimum wastage TOP 21/27
Ch 4 · Network layer21 from 21 of the 27 sittings, 7 from the book
- Find the block: AND the given address with its mask; an address with host bits set stands for its network. A /p block holds addresses.
- Size each subnet: for H hosts take the smallest block of addresses with (the network and broadcast addresses carry no host); its prefix is /. A point-to-point link has 2 hosts, so it takes a /30.
- Check the fit: the block sizes must add up to no more than the given block; if they do not, state it and name the smallest block that does fit.
- Allocate largest first (equal host counts keep the order given) from the start of the block, each subnet starting where the previous one ends; a block of then always starts on a multiple of .
- Fill each row: network = its first address; broadcast = network + ; usable hosts from network + 1 to broadcast - 1; mask from the prefix; wasted = .
- State what is left: the unused range after the last subnet, kept for growth.
2082 Bhadra · Q58 marksSuppose a company XYZ has an IP address of 160.24.96.0/21 and it has 6 departments containing 1024, 750, 254, 500, 151 and 45 users and also include point-point links. List out the CIDR, network address, broadcast address, usable host range and wasted IP address in each subnet.
How this is readAs printed the design cannot fit. The 1,024-user department needs 1,024 + 2 = 1,026 addresses, so it needs a /21 (2,048) and fills 160.24.96.0/21 by itself; the other five departments and their links need 2,132 more. All of it needs 4,180 addresses, more than even a /20 (4,096). The block is therefore read as 160.24.96.0/19 (8,192 addresses; 96 is a multiple of 32, so it is a valid /19 network), whose first /21 is exactly the printed block. The number of point-to-point links is not printed: 5 are taken, the fewest that join 6 department routers, and each further link takes the next /30 from the unused range.
Given: block 160.24.96.0/21 (2,048 addresses, 160.24.96.0 to 160.24.103.255); users: Dept 1 1,024, Dept 2 750, Dept 3 254, Dept 4 500, Dept 5 151, Dept 6 45; 5 point-to-point links (Link 1, Link 2, Link 3, Link 4, Link 5), 2 hosts each.
Step 1, size each subnet (largest first; a block of addresses holds hosts):
| Subnet | Hosts H | H + 2 | h | Block | Prefix | Mask |
|---|---|---|---|---|---|---|
| Dept 1 | 1,024 | 1,026 | 11 | 2,048 | /21 | 255.255.248.0 |
| Dept 2 | 750 | 752 | 10 | 1,024 | /22 | 255.255.252.0 |
| Dept 4 | 500 | 502 | 9 | 512 | /23 | 255.255.254.0 |
| Dept 3 | 254 | 256 | 8 | 256 | /24 | 255.255.255.0 |
| Dept 5 | 151 | 153 | 8 | 256 | /24 | 255.255.255.0 |
| Dept 6 | 45 | 47 | 6 | 64 | /26 | 255.255.255.192 |
| Link 1 | 2 | 4 | 2 | 4 | /30 | 255.255.255.252 |
| Link 2 | 2 | 4 | 2 | 4 | /30 | 255.255.255.252 |
| Link 3 | 2 | 4 | 2 | 4 | /30 | 255.255.255.252 |
| Link 4 | 2 | 4 | 2 | 4 | /30 | 255.255.255.252 |
| Link 5 | 2 | 4 | 2 | 4 | /30 | 255.255.255.252 |
Step 2, check the fit: 2,048 + 1,024 + 512 + 256 + 256 + 64 + 4 + 4 + 4 + 4 + 4 = 4,180 addresses are needed. The printed /21 holds only 2,048, and the 1,024 users alone fill it (a /22 holds only 1,022 hosts); a /20 holds 4,096, still 84 short. The smallest block that holds the design is a /19 of 8,192 addresses, 160.24.96.0/19 (160.24.96.0 to 160.24.127.255), which leaves 4,012 to spare.
Step 3, allocate from 160.24.96.0, each subnet starting where the previous one ends:
| Subnet | Hosts | Network (CIDR) | Subnet mask | Usable host range | Broadcast | Wasted |
|---|---|---|---|---|---|---|
| Dept 1 | 1,024 | 160.24.96.0/21 | 255.255.248.0 | 160.24.96.1 to 160.24.103.254 | 160.24.103.255 | 1,022 |
| Dept 2 | 750 | 160.24.104.0/22 | 255.255.252.0 | 160.24.104.1 to 160.24.107.254 | 160.24.107.255 | 272 |
| Dept 4 | 500 | 160.24.108.0/23 | 255.255.254.0 | 160.24.108.1 to 160.24.109.254 | 160.24.109.255 | 10 |
| Dept 3 | 254 | 160.24.110.0/24 | 255.255.255.0 | 160.24.110.1 to 160.24.110.254 | 160.24.110.255 | 0 |
| Dept 5 | 151 | 160.24.111.0/24 | 255.255.255.0 | 160.24.111.1 to 160.24.111.254 | 160.24.111.255 | 103 |
| Dept 6 | 45 | 160.24.112.0/26 | 255.255.255.192 | 160.24.112.1 to 160.24.112.62 | 160.24.112.63 | 17 |
| Link 1 | 2 | 160.24.112.64/30 | 255.255.255.252 | 160.24.112.65 to 160.24.112.66 | 160.24.112.67 | 0 |
| Link 2 | 2 | 160.24.112.68/30 | 255.255.255.252 | 160.24.112.69 to 160.24.112.70 | 160.24.112.71 | 0 |
| Link 3 | 2 | 160.24.112.72/30 | 255.255.255.252 | 160.24.112.73 to 160.24.112.74 | 160.24.112.75 | 0 |
| Link 4 | 2 | 160.24.112.76/30 | 255.255.255.252 | 160.24.112.77 to 160.24.112.78 | 160.24.112.79 | 0 |
| Link 5 | 2 | 160.24.112.80/30 | 255.255.255.252 | 160.24.112.81 to 160.24.112.82 | 160.24.112.83 | 0 |
Unused range: 160.24.112.84 to 160.24.127.255 (4,012 addresses), kept for growth.
Wasted in all: 1,424 addresses inside the subnets, most of it in the 1,024-user /21 (1,022).
Answer: Dept 1 160.24.96.0/21, Dept 2 160.24.104.0/22, Dept 4 160.24.108.0/23, Dept 3 160.24.110.0/24, Dept 5 160.24.111.0/24, Dept 6 160.24.112.0/26, Link 1 160.24.112.64/30, Link 2 160.24.112.68/30, Link 3 160.24.112.72/30, Link 4 160.24.112.76/30, Link 5 160.24.112.80/30; the CIDR, network, broadcast, usable range and wasted count of each are in the table.
2082 Baishakh · Q57 marksYou have to assign addresses to four departmental LANs with following hosts 14, 55, 10 and 29 addresses respectively from the given IP address block: 202.97.43.0/25. Perform the subnetting and find out subnet mask, network address, broadcast address and usable host IP ranges.
Given: block 202.97.43.0/25 (128 addresses, 202.97.43.0 to 202.97.43.127); hosts: LAN 1 14, LAN 2 55, LAN 3 10, LAN 4 29.
Step 1, size each subnet (largest first; a block of addresses holds hosts):
| Subnet | Hosts H | H + 2 | h | Block | Prefix | Mask |
|---|---|---|---|---|---|---|
| LAN 2 | 55 | 57 | 6 | 64 | /26 | 255.255.255.192 |
| LAN 4 | 29 | 31 | 5 | 32 | /27 | 255.255.255.224 |
| LAN 1 | 14 | 16 | 4 | 16 | /28 | 255.255.255.240 |
| LAN 3 | 10 | 12 | 4 | 16 | /28 | 255.255.255.240 |
Step 2, check the fit: 64 + 32 + 16 + 16 = 128 addresses are needed and the /25 holds 128, so it fits exactly.
Step 3, allocate from 202.97.43.0, each subnet starting where the previous one ends:
| Subnet | Hosts | Network (CIDR) | Subnet mask | Usable host range | Broadcast | Wasted |
|---|---|---|---|---|---|---|
| LAN 2 | 55 | 202.97.43.0/26 | 255.255.255.192 | 202.97.43.1 to 202.97.43.62 | 202.97.43.63 | 7 |
| LAN 4 | 29 | 202.97.43.64/27 | 255.255.255.224 | 202.97.43.65 to 202.97.43.94 | 202.97.43.95 | 1 |
| LAN 1 | 14 | 202.97.43.96/28 | 255.255.255.240 | 202.97.43.97 to 202.97.43.110 | 202.97.43.111 | 0 |
| LAN 3 | 10 | 202.97.43.112/28 | 255.255.255.240 | 202.97.43.113 to 202.97.43.126 | 202.97.43.127 | 4 |
Unused range: none; the block is used exactly.
Answer: LAN 2 202.97.43.0/26, LAN 4 202.97.43.64/27, LAN 1 202.97.43.96/28, LAN 3 202.97.43.112/28; masks, broadcasts and usable ranges as in the table.
2081 Bhadra · Q57 marksPerform the subnetting of IPv4 address block 200.74.20.0/24 for five different departments having 4, 54, 120, 12 and 30 hosts. List out the network address, broadcast address, usable host range and wasted IP address in each subnet.
Given: block 200.74.20.0/24 (256 addresses, 200.74.20.0 to 200.74.20.255); hosts: Dept 1 4, Dept 2 54, Dept 3 120, Dept 4 12, Dept 5 30.
Step 1, size each subnet (largest first; a block of addresses holds hosts):
| Subnet | Hosts H | H + 2 | h | Block | Prefix | Mask |
|---|---|---|---|---|---|---|
| Dept 3 | 120 | 122 | 7 | 128 | /25 | 255.255.255.128 |
| Dept 2 | 54 | 56 | 6 | 64 | /26 | 255.255.255.192 |
| Dept 5 | 30 | 32 | 5 | 32 | /27 | 255.255.255.224 |
| Dept 4 | 12 | 14 | 4 | 16 | /28 | 255.255.255.240 |
| Dept 1 | 4 | 6 | 3 | 8 | /29 | 255.255.255.248 |
Step 2, check the fit: 128 + 64 + 32 + 16 + 8 = 248 addresses are needed and the /24 holds 256, so it fits, with 8 addresses to spare.
Step 3, allocate from 200.74.20.0, each subnet starting where the previous one ends:
| Subnet | Hosts | Network (CIDR) | Subnet mask | Usable host range | Broadcast | Wasted |
|---|---|---|---|---|---|---|
| Dept 3 | 120 | 200.74.20.0/25 | 255.255.255.128 | 200.74.20.1 to 200.74.20.126 | 200.74.20.127 | 6 |
| Dept 2 | 54 | 200.74.20.128/26 | 255.255.255.192 | 200.74.20.129 to 200.74.20.190 | 200.74.20.191 | 8 |
| Dept 5 | 30 | 200.74.20.192/27 | 255.255.255.224 | 200.74.20.193 to 200.74.20.222 | 200.74.20.223 | 0 |
| Dept 4 | 12 | 200.74.20.224/28 | 255.255.255.240 | 200.74.20.225 to 200.74.20.238 | 200.74.20.239 | 2 |
| Dept 1 | 4 | 200.74.20.240/29 | 255.255.255.248 | 200.74.20.241 to 200.74.20.246 | 200.74.20.247 | 2 |
Unused range: 200.74.20.248 to 200.74.20.255 (8 addresses), kept for growth.
Answer: Dept 3 200.74.20.0/25, Dept 2 200.74.20.128/26, Dept 5 200.74.20.192/27, Dept 4 200.74.20.224/28, Dept 1 200.74.20.240/29; wasted 18 addresses in all inside the subnets.
2080 Bhadra · Q48 marksSuppose a company has IP address of 10.20.30.0/24 and it has 4 LANs containing 4,64,24,18 number of hosts. Also, there are 4 WAN links to connect LAN1 - LAN2, LAN2 - LAN3, LAN3 - LAN4 and LAN1 - LAN3. List out the subnet wasted IP addresses for each LAN.
How this is read"List out the subnet wasted IP addresses" is read as: list each subnet and its wasted addresses. LAN1 to LAN4 are the LANs in the order given; each WAN link joins two LAN routers and takes a /30.
Given: block 10.20.30.0/24 (256 addresses, 10.20.30.0 to 10.20.30.255); hosts: LAN1 4, LAN2 64, LAN3 24, LAN4 18; 4 point-to-point links (LAN1-LAN2, LAN2-LAN3, LAN3-LAN4, LAN1-LAN3), 2 hosts each.
The trap: 64 hosts need 64 + 2 = 66 addresses, but a /26 holds only 62 hosts, so LAN2 needs a /25 and wastes 62.
Step 1, size each subnet (largest first; a block of addresses holds hosts):
| Subnet | Hosts H | H + 2 | h | Block | Prefix | Mask |
|---|---|---|---|---|---|---|
| LAN2 | 64 | 66 | 7 | 128 | /25 | 255.255.255.128 |
| LAN3 | 24 | 26 | 5 | 32 | /27 | 255.255.255.224 |
| LAN4 | 18 | 20 | 5 | 32 | /27 | 255.255.255.224 |
| LAN1 | 4 | 6 | 3 | 8 | /29 | 255.255.255.248 |
| LAN1-LAN2 | 2 | 4 | 2 | 4 | /30 | 255.255.255.252 |
| LAN2-LAN3 | 2 | 4 | 2 | 4 | /30 | 255.255.255.252 |
| LAN3-LAN4 | 2 | 4 | 2 | 4 | /30 | 255.255.255.252 |
| LAN1-LAN3 | 2 | 4 | 2 | 4 | /30 | 255.255.255.252 |
Step 2, check the fit: 128 + 32 + 32 + 8 + 4 + 4 + 4 + 4 = 216 addresses are needed and the /24 holds 256, so it fits, with 40 addresses to spare.
Step 3, allocate from 10.20.30.0, each subnet starting where the previous one ends:
| Subnet | Hosts | Network (CIDR) | Subnet mask | Usable host range | Broadcast | Wasted |
|---|---|---|---|---|---|---|
| LAN2 | 64 | 10.20.30.0/25 | 255.255.255.128 | 10.20.30.1 to 10.20.30.126 | 10.20.30.127 | 62 |
| LAN3 | 24 | 10.20.30.128/27 | 255.255.255.224 | 10.20.30.129 to 10.20.30.158 | 10.20.30.159 | 6 |
| LAN4 | 18 | 10.20.30.160/27 | 255.255.255.224 | 10.20.30.161 to 10.20.30.190 | 10.20.30.191 | 12 |
| LAN1 | 4 | 10.20.30.192/29 | 255.255.255.248 | 10.20.30.193 to 10.20.30.198 | 10.20.30.199 | 2 |
| LAN1-LAN2 | 2 | 10.20.30.200/30 | 255.255.255.252 | 10.20.30.201 to 10.20.30.202 | 10.20.30.203 | 0 |
| LAN2-LAN3 | 2 | 10.20.30.204/30 | 255.255.255.252 | 10.20.30.205 to 10.20.30.206 | 10.20.30.207 | 0 |
| LAN3-LAN4 | 2 | 10.20.30.208/30 | 255.255.255.252 | 10.20.30.209 to 10.20.30.210 | 10.20.30.211 | 0 |
| LAN1-LAN3 | 2 | 10.20.30.212/30 | 255.255.255.252 | 10.20.30.213 to 10.20.30.214 | 10.20.30.215 | 0 |
Unused range: 10.20.30.216 to 10.20.30.255 (40 addresses), kept for growth.
Answer: LAN2 10.20.30.0/25, LAN3 10.20.30.128/27, LAN4 10.20.30.160/27, LAN1 10.20.30.192/29, LAN1-LAN2 10.20.30.200/30, LAN2-LAN3 10.20.30.204/30, LAN3-LAN4 10.20.30.208/30, LAN1-LAN3 10.20.30.212/30; wasted per LAN: LAN2 62, LAN3 6, LAN4 12, LAN1 2.
2080 Baishakh · Q58 marksSuppose a company has IP address of 200.80.40.0/24 with 5 departments containing 29, 5, 16, 43, 14, number of hosts. Also there are point to point links between the departments. List out the subnet mask, network address, broadcast address, usable host IP ranges and no. of wasted IP addresses for each subnet.
How this is readThe number of point-to-point links is not printed: 4 are taken, the fewest that join 5 department routers (a chain or a tree); each further link takes the next /30 from the unused range.
Given: block 200.80.40.0/24 (256 addresses, 200.80.40.0 to 200.80.40.255); hosts: Dept 1 29, Dept 2 5, Dept 3 16, Dept 4 43, Dept 5 14; 4 point-to-point links (Link 1, Link 2, Link 3, Link 4), 2 hosts each.
Step 1, size each subnet (largest first; a block of addresses holds hosts):
| Subnet | Hosts H | H + 2 | h | Block | Prefix | Mask |
|---|---|---|---|---|---|---|
| Dept 4 | 43 | 45 | 6 | 64 | /26 | 255.255.255.192 |
| Dept 1 | 29 | 31 | 5 | 32 | /27 | 255.255.255.224 |
| Dept 3 | 16 | 18 | 5 | 32 | /27 | 255.255.255.224 |
| Dept 5 | 14 | 16 | 4 | 16 | /28 | 255.255.255.240 |
| Dept 2 | 5 | 7 | 3 | 8 | /29 | 255.255.255.248 |
| Link 1 | 2 | 4 | 2 | 4 | /30 | 255.255.255.252 |
| Link 2 | 2 | 4 | 2 | 4 | /30 | 255.255.255.252 |
| Link 3 | 2 | 4 | 2 | 4 | /30 | 255.255.255.252 |
| Link 4 | 2 | 4 | 2 | 4 | /30 | 255.255.255.252 |
Step 2, check the fit: 64 + 32 + 32 + 16 + 8 + 4 + 4 + 4 + 4 = 168 addresses are needed and the /24 holds 256, so it fits, with 88 addresses to spare.
Step 3, allocate from 200.80.40.0, each subnet starting where the previous one ends:
| Subnet | Hosts | Network (CIDR) | Subnet mask | Usable host range | Broadcast | Wasted |
|---|---|---|---|---|---|---|
| Dept 4 | 43 | 200.80.40.0/26 | 255.255.255.192 | 200.80.40.1 to 200.80.40.62 | 200.80.40.63 | 19 |
| Dept 1 | 29 | 200.80.40.64/27 | 255.255.255.224 | 200.80.40.65 to 200.80.40.94 | 200.80.40.95 | 1 |
| Dept 3 | 16 | 200.80.40.96/27 | 255.255.255.224 | 200.80.40.97 to 200.80.40.126 | 200.80.40.127 | 14 |
| Dept 5 | 14 | 200.80.40.128/28 | 255.255.255.240 | 200.80.40.129 to 200.80.40.142 | 200.80.40.143 | 0 |
| Dept 2 | 5 | 200.80.40.144/29 | 255.255.255.248 | 200.80.40.145 to 200.80.40.150 | 200.80.40.151 | 1 |
| Link 1 | 2 | 200.80.40.152/30 | 255.255.255.252 | 200.80.40.153 to 200.80.40.154 | 200.80.40.155 | 0 |
| Link 2 | 2 | 200.80.40.156/30 | 255.255.255.252 | 200.80.40.157 to 200.80.40.158 | 200.80.40.159 | 0 |
| Link 3 | 2 | 200.80.40.160/30 | 255.255.255.252 | 200.80.40.161 to 200.80.40.162 | 200.80.40.163 | 0 |
| Link 4 | 2 | 200.80.40.164/30 | 255.255.255.252 | 200.80.40.165 to 200.80.40.166 | 200.80.40.167 | 0 |
Unused range: 200.80.40.168 to 200.80.40.255 (88 addresses), kept for growth.
Answer: Dept 4 200.80.40.0/26, Dept 1 200.80.40.64/27, Dept 3 200.80.40.96/27, Dept 5 200.80.40.128/28, Dept 2 200.80.40.144/29, Link 1 200.80.40.152/30, Link 2 200.80.40.156/30, Link 3 200.80.40.160/30, Link 4 200.80.40.164/30; masks, ranges, broadcasts and wasted counts as in the table.
2079 Bhadra · Q58 marksAn ISP provided you an IP address block of 172.24.96.0/21. Suppose you need to divide this for four different departments A, B, C and D having 750, 200, 500 and 45 hosts respectively with minimum wastage of IP addresses. Also allocate IP addresses for three point-to-point links in the network. Find out the network address, broadcast address, subnet mash and usable host range of IP addresses for each subnet.
How this is read"subnet mash" is read as subnet mask.
Given: block 172.24.96.0/21 (2,048 addresses, 172.24.96.0 to 172.24.103.255); hosts: A 750, B 200, C 500, D 45; 3 point-to-point links (Link 1, Link 2, Link 3), 2 hosts each.
Step 1, size each subnet (largest first; a block of addresses holds hosts):
| Subnet | Hosts H | H + 2 | h | Block | Prefix | Mask |
|---|---|---|---|---|---|---|
| A | 750 | 752 | 10 | 1,024 | /22 | 255.255.252.0 |
| C | 500 | 502 | 9 | 512 | /23 | 255.255.254.0 |
| B | 200 | 202 | 8 | 256 | /24 | 255.255.255.0 |
| D | 45 | 47 | 6 | 64 | /26 | 255.255.255.192 |
| Link 1 | 2 | 4 | 2 | 4 | /30 | 255.255.255.252 |
| Link 2 | 2 | 4 | 2 | 4 | /30 | 255.255.255.252 |
| Link 3 | 2 | 4 | 2 | 4 | /30 | 255.255.255.252 |
Step 2, check the fit: 1,024 + 512 + 256 + 64 + 4 + 4 + 4 = 1,868 addresses are needed and the /21 holds 2,048, so it fits, with 180 addresses to spare.
Step 3, allocate from 172.24.96.0, each subnet starting where the previous one ends:
| Subnet | Hosts | Network (CIDR) | Subnet mask | Usable host range | Broadcast | Wasted |
|---|---|---|---|---|---|---|
| A | 750 | 172.24.96.0/22 | 255.255.252.0 | 172.24.96.1 to 172.24.99.254 | 172.24.99.255 | 272 |
| C | 500 | 172.24.100.0/23 | 255.255.254.0 | 172.24.100.1 to 172.24.101.254 | 172.24.101.255 | 10 |
| B | 200 | 172.24.102.0/24 | 255.255.255.0 | 172.24.102.1 to 172.24.102.254 | 172.24.102.255 | 54 |
| D | 45 | 172.24.103.0/26 | 255.255.255.192 | 172.24.103.1 to 172.24.103.62 | 172.24.103.63 | 17 |
| Link 1 | 2 | 172.24.103.64/30 | 255.255.255.252 | 172.24.103.65 to 172.24.103.66 | 172.24.103.67 | 0 |
| Link 2 | 2 | 172.24.103.68/30 | 255.255.255.252 | 172.24.103.69 to 172.24.103.70 | 172.24.103.71 | 0 |
| Link 3 | 2 | 172.24.103.72/30 | 255.255.255.252 | 172.24.103.73 to 172.24.103.74 | 172.24.103.75 | 0 |
Unused range: 172.24.103.76 to 172.24.103.255 (180 addresses), kept for growth.
Answer: A 172.24.96.0/22, C 172.24.100.0/23, B 172.24.102.0/24, D 172.24.103.0/26, Link 1 172.24.103.64/30, Link 2 172.24.103.68/30, Link 3 172.24.103.72/30; masks, ranges and broadcasts as in the table.
2078 Bhadra · Q48 marksConsider IP block of 202.50.0.0/24 and six departments with 125, 59, 27, 14, 4 and 2 hosts respectively. Perform the subnetting so that wastage of IP addresses is minimum and find out the subnet mask, network address, broadcast address, wasted IP addresses and usable host ranges in each network.
Given: block 202.50.0.0/24 (256 addresses, 202.50.0.0 to 202.50.0.255); hosts: Dept 1 125, Dept 2 59, Dept 3 27, Dept 4 14, Dept 5 4, Dept 6 2.
Step 1, size each subnet (largest first; a block of addresses holds hosts):
| Subnet | Hosts H | H + 2 | h | Block | Prefix | Mask |
|---|---|---|---|---|---|---|
| Dept 1 | 125 | 127 | 7 | 128 | /25 | 255.255.255.128 |
| Dept 2 | 59 | 61 | 6 | 64 | /26 | 255.255.255.192 |
| Dept 3 | 27 | 29 | 5 | 32 | /27 | 255.255.255.224 |
| Dept 4 | 14 | 16 | 4 | 16 | /28 | 255.255.255.240 |
| Dept 5 | 4 | 6 | 3 | 8 | /29 | 255.255.255.248 |
| Dept 6 | 2 | 4 | 2 | 4 | /30 | 255.255.255.252 |
Step 2, check the fit: 128 + 64 + 32 + 16 + 8 + 4 = 252 addresses are needed and the /24 holds 256, so it fits, with 4 addresses to spare.
Step 3, allocate from 202.50.0.0, each subnet starting where the previous one ends:
| Subnet | Hosts | Network (CIDR) | Subnet mask | Usable host range | Broadcast | Wasted |
|---|---|---|---|---|---|---|
| Dept 1 | 125 | 202.50.0.0/25 | 255.255.255.128 | 202.50.0.1 to 202.50.0.126 | 202.50.0.127 | 1 |
| Dept 2 | 59 | 202.50.0.128/26 | 255.255.255.192 | 202.50.0.129 to 202.50.0.190 | 202.50.0.191 | 3 |
| Dept 3 | 27 | 202.50.0.192/27 | 255.255.255.224 | 202.50.0.193 to 202.50.0.222 | 202.50.0.223 | 3 |
| Dept 4 | 14 | 202.50.0.224/28 | 255.255.255.240 | 202.50.0.225 to 202.50.0.238 | 202.50.0.239 | 0 |
| Dept 5 | 4 | 202.50.0.240/29 | 255.255.255.248 | 202.50.0.241 to 202.50.0.246 | 202.50.0.247 | 2 |
| Dept 6 | 2 | 202.50.0.248/30 | 255.255.255.252 | 202.50.0.249 to 202.50.0.250 | 202.50.0.251 | 0 |
Unused range: 202.50.0.252 to 202.50.0.255 (4 addresses), kept for growth.
Answer: Dept 1 202.50.0.0/25, Dept 2 202.50.0.128/26, Dept 3 202.50.0.192/27, Dept 4 202.50.0.224/28, Dept 5 202.50.0.240/29, Dept 6 202.50.0.248/30; 9 addresses wasted in all inside the subnets.
2076 Chaitra · Q48 marksSuppose your company has leased the IP address of 222.70.94.0/24 from your ISP. Divide it far five different departments containing 50, 30, 25, 12, 10 no of hosts. There are also two points to point links far interconnection between routers. List out the network address, broadcast address, usable IP address range and subnet mask for each subnet. Also mention the unused range of IP addresses.
How this is read"far" is read as "for" (printed twice). "Unused range" is answered both ways: the addresses each subnet leaves unused after its hosts (hosts numbered from the first usable address), and the part of the block no subnet takes. Insights works this as Problem 15 (p. 163 to 166) with the same subnets, but it opens with "given mask is /25" (the block is a /24); it sizes the 30 hosts as "32 = 2^n - 2" and prints their range as 202.10.10.65 to 202.10.10.94 (it is 222.70.94.65 to 222.70.94.94); its table gives the 12-host department .129 to .141 and calls .142 to .143 unused, though .143 is the broadcast (hosts .129 to .140, unused .141 to .142); and it never gives the unused range of the block, 222.70.94.168 to 222.70.94.255.
Given: block 222.70.94.0/24 (256 addresses, 222.70.94.0 to 222.70.94.255); hosts: Dept 1 50, Dept 2 30, Dept 3 25, Dept 4 12, Dept 5 10; 2 point-to-point links (Link 1, Link 2), 2 hosts each.
Step 1, size each subnet (largest first; a block of addresses holds hosts):
| Subnet | Hosts H | H + 2 | h | Block | Prefix | Mask |
|---|---|---|---|---|---|---|
| Dept 1 | 50 | 52 | 6 | 64 | /26 | 255.255.255.192 |
| Dept 2 | 30 | 32 | 5 | 32 | /27 | 255.255.255.224 |
| Dept 3 | 25 | 27 | 5 | 32 | /27 | 255.255.255.224 |
| Dept 4 | 12 | 14 | 4 | 16 | /28 | 255.255.255.240 |
| Dept 5 | 10 | 12 | 4 | 16 | /28 | 255.255.255.240 |
| Link 1 | 2 | 4 | 2 | 4 | /30 | 255.255.255.252 |
| Link 2 | 2 | 4 | 2 | 4 | /30 | 255.255.255.252 |
Step 2, check the fit: 64 + 32 + 32 + 16 + 16 + 4 + 4 = 168 addresses are needed and the /24 holds 256, so it fits, with 88 addresses to spare.
Step 3, allocate from 222.70.94.0, each subnet starting where the previous one ends:
| Subnet | Hosts | Network (CIDR) | Subnet mask | Usable host range | Assigned to the hosts | Unassigned (count) | Broadcast |
|---|---|---|---|---|---|---|---|
| Dept 1 | 50 | 222.70.94.0/26 | 255.255.255.192 | 222.70.94.1 to 222.70.94.62 | 222.70.94.1 to 222.70.94.50 | 222.70.94.51 to 222.70.94.62 (12) | 222.70.94.63 |
| Dept 2 | 30 | 222.70.94.64/27 | 255.255.255.224 | 222.70.94.65 to 222.70.94.94 | 222.70.94.65 to 222.70.94.94 | none | 222.70.94.95 |
| Dept 3 | 25 | 222.70.94.96/27 | 255.255.255.224 | 222.70.94.97 to 222.70.94.126 | 222.70.94.97 to 222.70.94.121 | 222.70.94.122 to 222.70.94.126 (5) | 222.70.94.127 |
| Dept 4 | 12 | 222.70.94.128/28 | 255.255.255.240 | 222.70.94.129 to 222.70.94.142 | 222.70.94.129 to 222.70.94.140 | 222.70.94.141 to 222.70.94.142 (2) | 222.70.94.143 |
| Dept 5 | 10 | 222.70.94.144/28 | 255.255.255.240 | 222.70.94.145 to 222.70.94.158 | 222.70.94.145 to 222.70.94.154 | 222.70.94.155 to 222.70.94.158 (4) | 222.70.94.159 |
| Link 1 | 2 | 222.70.94.160/30 | 255.255.255.252 | 222.70.94.161 to 222.70.94.162 | 222.70.94.161 to 222.70.94.162 | none | 222.70.94.163 |
| Link 2 | 2 | 222.70.94.164/30 | 255.255.255.252 | 222.70.94.165 to 222.70.94.166 | 222.70.94.165 to 222.70.94.166 | none | 222.70.94.167 |
Unused range of the block: 222.70.94.168 to 222.70.94.255 (88 addresses), kept for growth.
Answer: Dept 1 222.70.94.0/26, Dept 2 222.70.94.64/27, Dept 3 222.70.94.96/27, Dept 4 222.70.94.128/28, Dept 5 222.70.94.144/28, Link 1 222.70.94.160/30, Link 2 222.70.94.164/30; unused inside the subnets as in the table, and 222.70.94.168 to 222.70.94.255 of the block unused.
2076 Ashwin · Q48 marksInstitute of Engineering has six departments having 16, 32, 61, 8, 6 and 24 computers. Use 192.168.1.0/24 to distribute the network. Find the network address, broadcast address, usable IP range and subnet mask in each department.
Given: block 192.168.1.0/24 (256 addresses, 192.168.1.0 to 192.168.1.255); computers: Dept 1 16, Dept 2 32, Dept 3 61, Dept 4 8, Dept 5 6, Dept 6 24.
The trap: 32 computers need 32 + 2 = 34 addresses, but a /27 holds only 30 hosts, so Dept 2 needs a /26 and wastes 30.
Step 1, size each subnet (largest first; a block of addresses holds hosts):
| Subnet | Hosts H | H + 2 | h | Block | Prefix | Mask |
|---|---|---|---|---|---|---|
| Dept 3 | 61 | 63 | 6 | 64 | /26 | 255.255.255.192 |
| Dept 2 | 32 | 34 | 6 | 64 | /26 | 255.255.255.192 |
| Dept 6 | 24 | 26 | 5 | 32 | /27 | 255.255.255.224 |
| Dept 1 | 16 | 18 | 5 | 32 | /27 | 255.255.255.224 |
| Dept 4 | 8 | 10 | 4 | 16 | /28 | 255.255.255.240 |
| Dept 5 | 6 | 8 | 3 | 8 | /29 | 255.255.255.248 |
Step 2, check the fit: 64 + 64 + 32 + 32 + 16 + 8 = 216 addresses are needed and the /24 holds 256, so it fits, with 40 addresses to spare.
Step 3, allocate from 192.168.1.0, each subnet starting where the previous one ends:
| Subnet | Hosts | Network (CIDR) | Subnet mask | Usable host range | Broadcast | Wasted |
|---|---|---|---|---|---|---|
| Dept 3 | 61 | 192.168.1.0/26 | 255.255.255.192 | 192.168.1.1 to 192.168.1.62 | 192.168.1.63 | 1 |
| Dept 2 | 32 | 192.168.1.64/26 | 255.255.255.192 | 192.168.1.65 to 192.168.1.126 | 192.168.1.127 | 30 |
| Dept 6 | 24 | 192.168.1.128/27 | 255.255.255.224 | 192.168.1.129 to 192.168.1.158 | 192.168.1.159 | 6 |
| Dept 1 | 16 | 192.168.1.160/27 | 255.255.255.224 | 192.168.1.161 to 192.168.1.190 | 192.168.1.191 | 14 |
| Dept 4 | 8 | 192.168.1.192/28 | 255.255.255.240 | 192.168.1.193 to 192.168.1.206 | 192.168.1.207 | 6 |
| Dept 5 | 6 | 192.168.1.208/29 | 255.255.255.248 | 192.168.1.209 to 192.168.1.214 | 192.168.1.215 | 0 |
Unused range: 192.168.1.216 to 192.168.1.255 (40 addresses), kept for growth.
Answer: Dept 3 192.168.1.0/26, Dept 2 192.168.1.64/26, Dept 6 192.168.1.128/27, Dept 1 192.168.1.160/27, Dept 4 192.168.1.192/28, Dept 5 192.168.1.208/29; masks, ranges and broadcasts as in the table.
2075 Chaitra · Q48 marksSuppose you are a private consultant hired by the large company to setup the network for their enterprise and you are given a large number of consecutive. IP address starting at 120.89.96.0/19. Suppose that four departments A, B, C and D request 100, 500, 800 and 400 addresses respectively, how the subnetting can be performed so, that address wastage will be minimum?
How this is readThe same four requests are set on 120.89.96.0/19 again in 2074 Ashwin Q5 and on 202.70.64.0/19 in 2073 Shrawan Q4.
Given: block 120.89.96.0/19 (8,192 addresses, 120.89.96.0 to 120.89.127.255); addresses requested: A 100, B 500, C 800, D 400.
Step 1, size each subnet (largest first; a block of addresses holds hosts):
| Subnet | Hosts H | H + 2 | h | Block | Prefix | Mask |
|---|---|---|---|---|---|---|
| C | 800 | 802 | 10 | 1,024 | /22 | 255.255.252.0 |
| B | 500 | 502 | 9 | 512 | /23 | 255.255.254.0 |
| D | 400 | 402 | 9 | 512 | /23 | 255.255.254.0 |
| A | 100 | 102 | 7 | 128 | /25 | 255.255.255.128 |
Step 2, check the fit: 1,024 + 512 + 512 + 128 = 2,176 addresses are needed and the /19 holds 8,192, so it fits, with 6,016 addresses to spare.
Step 3, allocate from 120.89.96.0, each subnet starting where the previous one ends:
| Subnet | Hosts | Network (CIDR) | Subnet mask | Usable host range | Broadcast | Wasted |
|---|---|---|---|---|---|---|
| C | 800 | 120.89.96.0/22 | 255.255.252.0 | 120.89.96.1 to 120.89.99.254 | 120.89.99.255 | 222 |
| B | 500 | 120.89.100.0/23 | 255.255.254.0 | 120.89.100.1 to 120.89.101.254 | 120.89.101.255 | 10 |
| D | 400 | 120.89.102.0/23 | 255.255.254.0 | 120.89.102.1 to 120.89.103.254 | 120.89.103.255 | 110 |
| A | 100 | 120.89.104.0/25 | 255.255.255.128 | 120.89.104.1 to 120.89.104.126 | 120.89.104.127 | 26 |
Unused range: 120.89.104.128 to 120.89.127.255 (6,016 addresses), kept for growth.
How it is performed: each request gets the smallest power-of-two block that holds it plus its network and broadcast addresses; placing the biggest block first keeps every later block on its own boundary, so no addresses are lost between blocks. The four take 2,176 of the 8,192 addresses and leave 6,016 free in one piece.
Answer: C 120.89.96.0/22, B 120.89.100.0/23, D 120.89.102.0/23, A 120.89.104.0/25; masks, ranges and broadcasts as in the table.
2075 Ashwin · Q58 marksDesign a network for 5 departments containing 29, 14, 15, 23 and 5 computers. Take a network example IP 202.83.54.91/25.
How this is read202.83.54.91 has host bits set under /25 (91 is below 128), so the block is its network, 202.83.54.0/25. Insights works this twice, as Problem 1 (p. 134 to 136) and Problem 13 (p. 159 to 161), with the same subnets; both tables start the 15-computer range at 202.83.54.64, its network address (the first host is 202.83.54.65); Problem 13's table gives the masks as 255.255.255.192 for the three /27 rows and 255.255.255.224 for the /28 and /29 rows (they are 255.255.255.224, 255.255.255.240 and 255.255.255.248); both workings call the /28 step a "difference of 32" (it is 16); and neither gives the unused 202.83.54.120 to 202.83.54.127.
Given: block 202.83.54.91/25; computers: Dept 1 29, Dept 2 14, Dept 3 15, Dept 4 23, Dept 5 5.
Find the block: the /25 mask is 255.255.255.128; in octet 4, 91 = 01011011 AND 10000000 = 00000000 = 0, so the block is the network 202.83.54.0/25 (202.83.54.0 to 202.83.54.127).
Step 1, size each subnet (largest first; a block of addresses holds hosts):
| Subnet | Hosts H | H + 2 | h | Block | Prefix | Mask |
|---|---|---|---|---|---|---|
| Dept 1 | 29 | 31 | 5 | 32 | /27 | 255.255.255.224 |
| Dept 4 | 23 | 25 | 5 | 32 | /27 | 255.255.255.224 |
| Dept 3 | 15 | 17 | 5 | 32 | /27 | 255.255.255.224 |
| Dept 2 | 14 | 16 | 4 | 16 | /28 | 255.255.255.240 |
| Dept 5 | 5 | 7 | 3 | 8 | /29 | 255.255.255.248 |
Step 2, check the fit: 32 + 32 + 32 + 16 + 8 = 120 addresses are needed and the /25 holds 128, so it fits, with 8 addresses to spare.
Step 3, allocate from 202.83.54.0, each subnet starting where the previous one ends:
| Subnet | Hosts | Network (CIDR) | Subnet mask | Usable host range | Broadcast | Wasted |
|---|---|---|---|---|---|---|
| Dept 1 | 29 | 202.83.54.0/27 | 255.255.255.224 | 202.83.54.1 to 202.83.54.30 | 202.83.54.31 | 1 |
| Dept 4 | 23 | 202.83.54.32/27 | 255.255.255.224 | 202.83.54.33 to 202.83.54.62 | 202.83.54.63 | 7 |
| Dept 3 | 15 | 202.83.54.64/27 | 255.255.255.224 | 202.83.54.65 to 202.83.54.94 | 202.83.54.95 | 15 |
| Dept 2 | 14 | 202.83.54.96/28 | 255.255.255.240 | 202.83.54.97 to 202.83.54.110 | 202.83.54.111 | 0 |
| Dept 5 | 5 | 202.83.54.112/29 | 255.255.255.248 | 202.83.54.113 to 202.83.54.118 | 202.83.54.119 | 1 |
Unused range: 202.83.54.120 to 202.83.54.127 (8 addresses), kept for growth.
Answer: Dept 1 202.83.54.0/27, Dept 4 202.83.54.32/27, Dept 3 202.83.54.64/27, Dept 2 202.83.54.96/28, Dept 5 202.83.54.112/29; masks, ranges and broadcasts as in the table.
2074 Chaitra · Q58 marksHow can you dedicate 32, 65, 10, 21, 9 public IP address to the departments A, B, C, D and E respectively form the pool of class C IP addresses with minimum loss. Explain.
How this is readNo address is given. 192.0.2.0/24, a class C block reserved for documentation (RFC 5737), stands for "the pool of class C"; with a real allocation only the first three octets change. "form" is read as "from".
Given: block 192.0.2.0/24, standing for the class C pool (256 addresses, 192.0.2.0 to 192.0.2.255); addresses: A 32, B 65, C 10, D 21, E 9.
Step 1, size each subnet (largest first; a block of addresses holds hosts):
| Subnet | Hosts H | H + 2 | h | Block | Prefix | Mask |
|---|---|---|---|---|---|---|
| B | 65 | 67 | 7 | 128 | /25 | 255.255.255.128 |
| A | 32 | 34 | 6 | 64 | /26 | 255.255.255.192 |
| D | 21 | 23 | 5 | 32 | /27 | 255.255.255.224 |
| C | 10 | 12 | 4 | 16 | /28 | 255.255.255.240 |
| E | 9 | 11 | 4 | 16 | /28 | 255.255.255.240 |
Step 2, check the fit: 128 + 64 + 32 + 16 + 16 = 256 addresses are needed and the /24 holds 256, so it fits exactly.
Step 3, allocate from 192.0.2.0, each subnet starting where the previous one ends:
| Subnet | Hosts | Network (CIDR) | Subnet mask | Usable host range | Broadcast | Wasted |
|---|---|---|---|---|---|---|
| B | 65 | 192.0.2.0/25 | 255.255.255.128 | 192.0.2.1 to 192.0.2.126 | 192.0.2.127 | 61 |
| A | 32 | 192.0.2.128/26 | 255.255.255.192 | 192.0.2.129 to 192.0.2.190 | 192.0.2.191 | 30 |
| D | 21 | 192.0.2.192/27 | 255.255.255.224 | 192.0.2.193 to 192.0.2.222 | 192.0.2.223 | 9 |
| C | 10 | 192.0.2.224/28 | 255.255.255.240 | 192.0.2.225 to 192.0.2.238 | 192.0.2.239 | 4 |
| E | 9 | 192.0.2.240/28 | 255.255.255.240 | 192.0.2.241 to 192.0.2.254 | 192.0.2.255 | 5 |
Unused range: none; the block is used exactly.
Why the loss is least: each department gets the smallest block that holds it, and the blocks are packed largest first, so nothing is lost between blocks. The 109 wasted addresses are forced by the counts: B's 65 just misses a /26 (62 hosts) and A's 32 just misses a /27 (30 hosts), so each needs a block twice as big.
Answer: B 192.0.2.0/25, A 192.0.2.128/26, D 192.0.2.192/27, C 192.0.2.224/28, E 192.0.2.240/28; the five fill the class C network exactly.
2074 Ashwin · Q58 marksSuppose you are a private consultant hired by a company to setup the network for their enterprise and you are given a large number of consecutive IP address starting at 120.89.96.0/19. Suppose that four departments A, B, C and D request 100, 500, 800 and 400 addresses respectively, how the subnetting can be performed so that address wastage will be minimum?
Given: block 120.89.96.0/19 (8,192 addresses, 120.89.96.0 to 120.89.127.255); addresses requested: A 100, B 500, C 800, D 400.
Step 1, size each subnet (largest first; a block of addresses holds hosts):
| Subnet | Hosts H | H + 2 | h | Block | Prefix | Mask |
|---|---|---|---|---|---|---|
| C | 800 | 802 | 10 | 1,024 | /22 | 255.255.252.0 |
| B | 500 | 502 | 9 | 512 | /23 | 255.255.254.0 |
| D | 400 | 402 | 9 | 512 | /23 | 255.255.254.0 |
| A | 100 | 102 | 7 | 128 | /25 | 255.255.255.128 |
Step 2, check the fit: 1,024 + 512 + 512 + 128 = 2,176 addresses are needed and the /19 holds 8,192, so it fits, with 6,016 addresses to spare.
Step 3, allocate from 120.89.96.0, each subnet starting where the previous one ends:
| Subnet | Hosts | Network (CIDR) | Subnet mask | Usable host range | Broadcast | Wasted |
|---|---|---|---|---|---|---|
| C | 800 | 120.89.96.0/22 | 255.255.252.0 | 120.89.96.1 to 120.89.99.254 | 120.89.99.255 | 222 |
| B | 500 | 120.89.100.0/23 | 255.255.254.0 | 120.89.100.1 to 120.89.101.254 | 120.89.101.255 | 10 |
| D | 400 | 120.89.102.0/23 | 255.255.254.0 | 120.89.102.1 to 120.89.103.254 | 120.89.103.255 | 110 |
| A | 100 | 120.89.104.0/25 | 255.255.255.128 | 120.89.104.1 to 120.89.104.126 | 120.89.104.127 | 26 |
Unused range: 120.89.104.128 to 120.89.127.255 (6,016 addresses), kept for growth.
How it is performed: each request gets the smallest power-of-two block that holds it plus its network and broadcast addresses; placing the biggest block first keeps every later block on its own boundary, so no addresses are lost between blocks. The four take 2,176 of the 8,192 addresses and leave 6,016 free in one piece.
Answer: C 120.89.96.0/22, B 120.89.100.0/23, D 120.89.102.0/23, A 120.89.104.0/25; masks, ranges and broadcasts as in the table.
2073 Shrawan · Q48 marksYou are a private contractor hired by the large company to setup the network for their enterprise and you are given a large number of consecutive IP address starting at 202.70.64.0/19. Suppose that four department A, B, C and D request 100, 500, 800 and 400 addresses respectively, how the subnetting can be performed so, that address wastage will be minimum?
How this is readInsights works this as Problem 3 (p. 138 to 140) and tags it 2070 Magh and 2073 Shrawan; 2070 Magh is not among the 27 papers on record. Its subnets agree with these, but its working prints the usable range of A as 202.70.72.1 to 202.70.72.127, and .127 is the broadcast (its table rightly ends at .126); it gives no unused range.
Given: block 202.70.64.0/19 (8,192 addresses, 202.70.64.0 to 202.70.95.255); addresses requested: A 100, B 500, C 800, D 400.
Step 1, size each subnet (largest first; a block of addresses holds hosts):
| Subnet | Hosts H | H + 2 | h | Block | Prefix | Mask |
|---|---|---|---|---|---|---|
| C | 800 | 802 | 10 | 1,024 | /22 | 255.255.252.0 |
| B | 500 | 502 | 9 | 512 | /23 | 255.255.254.0 |
| D | 400 | 402 | 9 | 512 | /23 | 255.255.254.0 |
| A | 100 | 102 | 7 | 128 | /25 | 255.255.255.128 |
Step 2, check the fit: 1,024 + 512 + 512 + 128 = 2,176 addresses are needed and the /19 holds 8,192, so it fits, with 6,016 addresses to spare.
Step 3, allocate from 202.70.64.0, each subnet starting where the previous one ends:
| Subnet | Hosts | Network (CIDR) | Subnet mask | Usable host range | Broadcast | Wasted |
|---|---|---|---|---|---|---|
| C | 800 | 202.70.64.0/22 | 255.255.252.0 | 202.70.64.1 to 202.70.67.254 | 202.70.67.255 | 222 |
| B | 500 | 202.70.68.0/23 | 255.255.254.0 | 202.70.68.1 to 202.70.69.254 | 202.70.69.255 | 10 |
| D | 400 | 202.70.70.0/23 | 255.255.254.0 | 202.70.70.1 to 202.70.71.254 | 202.70.71.255 | 110 |
| A | 100 | 202.70.72.0/25 | 255.255.255.128 | 202.70.72.1 to 202.70.72.126 | 202.70.72.127 | 26 |
Unused range: 202.70.72.128 to 202.70.95.255 (6,016 addresses), kept for growth.
How it is performed: each request gets the smallest power-of-two block that holds it plus its network and broadcast addresses; placing the biggest block first keeps every later block on its own boundary, so no addresses are lost between blocks. The four take 2,176 of the 8,192 addresses and leave 6,016 free in one piece.
Answer: C 202.70.64.0/22, B 202.70.68.0/23, D 202.70.70.0/23, A 202.70.72.0/25; masks, ranges and broadcasts as in the table.
2072 Chaitra · Q48 marksExplain how can you allocate 30, 24, 25 and 20 IP addresses to the four different department of ABC company with minimum wastage. Specify the range of IP addresses, Broadcast Address, Network Address and Subnet mask for each department form the given address pool 202.77.19.0/24.
How this is read"form" is read as "from". Insights works this as Problem 10 (p. 154 to 155) and gets the same subnets.
Given: block 202.77.19.0/24 (256 addresses, 202.77.19.0 to 202.77.19.255); addresses: Dept 1 30, Dept 2 24, Dept 3 25, Dept 4 20.
Step 1, size each subnet (largest first; a block of addresses holds hosts):
| Subnet | Hosts H | H + 2 | h | Block | Prefix | Mask |
|---|---|---|---|---|---|---|
| Dept 1 | 30 | 32 | 5 | 32 | /27 | 255.255.255.224 |
| Dept 3 | 25 | 27 | 5 | 32 | /27 | 255.255.255.224 |
| Dept 2 | 24 | 26 | 5 | 32 | /27 | 255.255.255.224 |
| Dept 4 | 20 | 22 | 5 | 32 | /27 | 255.255.255.224 |
Step 2, check the fit: 32 + 32 + 32 + 32 = 128 addresses are needed and the /24 holds 256, so it fits, with 128 addresses to spare.
Step 3, allocate from 202.77.19.0, each subnet starting where the previous one ends:
| Subnet | Hosts | Network (CIDR) | Subnet mask | Usable host range | Broadcast | Wasted |
|---|---|---|---|---|---|---|
| Dept 1 | 30 | 202.77.19.0/27 | 255.255.255.224 | 202.77.19.1 to 202.77.19.30 | 202.77.19.31 | 0 |
| Dept 3 | 25 | 202.77.19.32/27 | 255.255.255.224 | 202.77.19.33 to 202.77.19.62 | 202.77.19.63 | 5 |
| Dept 2 | 24 | 202.77.19.64/27 | 255.255.255.224 | 202.77.19.65 to 202.77.19.94 | 202.77.19.95 | 6 |
| Dept 4 | 20 | 202.77.19.96/27 | 255.255.255.224 | 202.77.19.97 to 202.77.19.126 | 202.77.19.127 | 10 |
Unused range: 202.77.19.128 to 202.77.19.255 (128 addresses), kept for growth.
How: all four counts lie between 15 and 30 hosts, so each department gets a /27 (mask 255.255.255.224, 30 hosts); four /27s take the first half of the pool and leave 202.77.19.128 to 202.77.19.255 free in one piece.
Answer: Dept 1 202.77.19.0/27, Dept 3 202.77.19.32/27, Dept 2 202.77.19.64/27, Dept 4 202.77.19.96/27; ranges, broadcasts and masks as in the table.
2071 Chaitra · Q510 marksYou are given the following address space 10.10.10.0/24. You have to assign addresses to 4 departments with the following hosts 5, 16, 23 and 27 respectively. Perform the subnetting in such a way that the IP address wastage in each department are minimum. Also find out the subnet mask, network address, broadcast address and unassigned range in each department.
How this is read"Unassigned range in each department" is answered both ways: the addresses each subnet leaves unassigned after its hosts (hosts numbered from the first usable address), and the part of the address space no department takes. Insights works this as Problem 7 (p. 147 to 149) with the same subnets but never gives either unassigned range.
Given: block 10.10.10.0/24 (256 addresses, 10.10.10.0 to 10.10.10.255); hosts: Dept 1 5, Dept 2 16, Dept 3 23, Dept 4 27.
Step 1, size each subnet (largest first; a block of addresses holds hosts):
| Subnet | Hosts H | H + 2 | h | Block | Prefix | Mask |
|---|---|---|---|---|---|---|
| Dept 4 | 27 | 29 | 5 | 32 | /27 | 255.255.255.224 |
| Dept 3 | 23 | 25 | 5 | 32 | /27 | 255.255.255.224 |
| Dept 2 | 16 | 18 | 5 | 32 | /27 | 255.255.255.224 |
| Dept 1 | 5 | 7 | 3 | 8 | /29 | 255.255.255.248 |
Step 2, check the fit: 32 + 32 + 32 + 8 = 104 addresses are needed and the /24 holds 256, so it fits, with 152 addresses to spare.
Step 3, allocate from 10.10.10.0, each subnet starting where the previous one ends:
| Subnet | Hosts | Network (CIDR) | Subnet mask | Usable host range | Assigned to the hosts | Unassigned (count) | Broadcast |
|---|---|---|---|---|---|---|---|
| Dept 4 | 27 | 10.10.10.0/27 | 255.255.255.224 | 10.10.10.1 to 10.10.10.30 | 10.10.10.1 to 10.10.10.27 | 10.10.10.28 to 10.10.10.30 (3) | 10.10.10.31 |
| Dept 3 | 23 | 10.10.10.32/27 | 255.255.255.224 | 10.10.10.33 to 10.10.10.62 | 10.10.10.33 to 10.10.10.55 | 10.10.10.56 to 10.10.10.62 (7) | 10.10.10.63 |
| Dept 2 | 16 | 10.10.10.64/27 | 255.255.255.224 | 10.10.10.65 to 10.10.10.94 | 10.10.10.65 to 10.10.10.80 | 10.10.10.81 to 10.10.10.94 (14) | 10.10.10.95 |
| Dept 1 | 5 | 10.10.10.96/29 | 255.255.255.248 | 10.10.10.97 to 10.10.10.102 | 10.10.10.97 to 10.10.10.101 | 10.10.10.102 (1) | 10.10.10.103 |
Unassigned range of the address space: 10.10.10.104 to 10.10.10.255 (152 addresses), kept for growth.
Answer: Dept 4 10.10.10.0/27, Dept 3 10.10.10.32/27, Dept 2 10.10.10.64/27, Dept 1 10.10.10.96/29; unassigned inside each department as in the table, and 10.10.10.104 to 10.10.10.255 of the space unassigned.
2070 Chaitra · Q58 marksHow can you dedicate 10, 12, 8, 14 public IP addresses to department A, B, C and D respectively from the pool of class C with minimum losses of IP? Explain.
How this is readNo address is given; 192.0.2.0/24, a class C documentation block (RFC 5737), stands for the pool. Insights works this as Problem 5 (p. 142 to 144) on 190.16.0.0/24, which is a class B address (first octet 128 to 191), not class C; it calls the /28 step a "difference of 4" (it is 16), labels the rows of its table D(14), B(12), C(10), D(8) (they are D, B, A and C) and prints one range as "190.16.33-190.16.0.46" (190.16.0.33 to 190.16.0.46). Its /28 layout is right.
Given: block 192.0.2.0/24, standing for the class C pool (256 addresses, 192.0.2.0 to 192.0.2.255); addresses: A 10, B 12, C 8, D 14.
Step 1, size each subnet (largest first; a block of addresses holds hosts):
| Subnet | Hosts H | H + 2 | h | Block | Prefix | Mask |
|---|---|---|---|---|---|---|
| D | 14 | 16 | 4 | 16 | /28 | 255.255.255.240 |
| B | 12 | 14 | 4 | 16 | /28 | 255.255.255.240 |
| A | 10 | 12 | 4 | 16 | /28 | 255.255.255.240 |
| C | 8 | 10 | 4 | 16 | /28 | 255.255.255.240 |
Step 2, check the fit: 16 + 16 + 16 + 16 = 64 addresses are needed and the /24 holds 256, so it fits, with 192 addresses to spare.
Step 3, allocate from 192.0.2.0, each subnet starting where the previous one ends:
| Subnet | Hosts | Network (CIDR) | Subnet mask | Usable host range | Broadcast | Wasted |
|---|---|---|---|---|---|---|
| D | 14 | 192.0.2.0/28 | 255.255.255.240 | 192.0.2.1 to 192.0.2.14 | 192.0.2.15 | 0 |
| B | 12 | 192.0.2.16/28 | 255.255.255.240 | 192.0.2.17 to 192.0.2.30 | 192.0.2.31 | 2 |
| A | 10 | 192.0.2.32/28 | 255.255.255.240 | 192.0.2.33 to 192.0.2.46 | 192.0.2.47 | 4 |
| C | 8 | 192.0.2.48/28 | 255.255.255.240 | 192.0.2.49 to 192.0.2.62 | 192.0.2.63 | 6 |
Unused range: 192.0.2.64 to 192.0.2.255 (192 addresses), kept for growth.
Why the loss is least: every count fits a /28 (14 hosts), the smallest block that holds 14; a /29 holds only 6. The four /28s lose 12 addresses inside the subnets and leave 192.0.2.64 to 192.0.2.255 free in one piece.
Answer: D 192.0.2.0/28, B 192.0.2.16/28, A 192.0.2.32/28, C 192.0.2.48/28; masks, ranges and broadcasts as in the table.
2069 Chaitra · Q48 marksShow the importance in this case. Banijya bank need to allocate 15 IPs in HR department, 30 in finance department, 24 in customer care unit and 25 in ATM machines. If you have one network of class C range public IP address. Describe how you will manage it.
How this is readNo address is given; 192.0.2.0/24, a class C documentation block (RFC 5737), stands for the public class C network. Insights works this as Problem 2 (p. 136 to 138) on an assumed 200.10.10.0/24 with the same layout.
Given: block 192.0.2.0/24, standing for the public class C network (256 addresses, 192.0.2.0 to 192.0.2.255); addresses: HR 15, Finance 30, Customer care 24, ATM machines 25.
The importance here: without subnetting all 94 hosts of the four units share one network: one broadcast domain, and nothing between the ATM machines and the staff PCs. Subnetting gives each unit its own network, so the ATM subnet can be fenced off by router rules, broadcasts stay inside a unit, and the four subnets use only 128 of the 256 addresses, leaving 192.0.2.128/25 for new units.
Step 1, size each subnet (largest first; a block of addresses holds hosts):
| Subnet | Hosts H | H + 2 | h | Block | Prefix | Mask |
|---|---|---|---|---|---|---|
| Finance | 30 | 32 | 5 | 32 | /27 | 255.255.255.224 |
| ATM machines | 25 | 27 | 5 | 32 | /27 | 255.255.255.224 |
| Customer care | 24 | 26 | 5 | 32 | /27 | 255.255.255.224 |
| HR | 15 | 17 | 5 | 32 | /27 | 255.255.255.224 |
Step 2, check the fit: 32 + 32 + 32 + 32 = 128 addresses are needed and the /24 holds 256, so it fits, with 128 addresses to spare.
Step 3, allocate from 192.0.2.0, each subnet starting where the previous one ends:
| Subnet | Hosts | Network (CIDR) | Subnet mask | Usable host range | Broadcast | Wasted |
|---|---|---|---|---|---|---|
| Finance | 30 | 192.0.2.0/27 | 255.255.255.224 | 192.0.2.1 to 192.0.2.30 | 192.0.2.31 | 0 |
| ATM machines | 25 | 192.0.2.32/27 | 255.255.255.224 | 192.0.2.33 to 192.0.2.62 | 192.0.2.63 | 5 |
| Customer care | 24 | 192.0.2.64/27 | 255.255.255.224 | 192.0.2.65 to 192.0.2.94 | 192.0.2.95 | 6 |
| HR | 15 | 192.0.2.96/27 | 255.255.255.224 | 192.0.2.97 to 192.0.2.126 | 192.0.2.127 | 15 |
Unused range: 192.0.2.128 to 192.0.2.255 (128 addresses), kept for growth.
Answer: Finance 192.0.2.0/27, ATM machines 192.0.2.32/27, Customer care 192.0.2.64/27, HR 192.0.2.96/27; all four with mask 255.255.255.224, and 192.0.2.128/25 left for growth.
2068 Chaitra · Q810 marksSuppose there are 4 departments A, B, C and D. The department A has 23 hosts, B has 16, C has 28 and D has 13 hosts. You are given a networks 202.70.64.0/24. Perform the subnetting in such a way that the IP address wastage in each department are minimum and also find out the sunbet mask, network address, broadcast, and unable host range in each department.
How this is read"sunbet mask" is read as subnet mask, "unable host range" as usable host range and "a networks" as a network.
Given: block 202.70.64.0/24 (256 addresses, 202.70.64.0 to 202.70.64.255); hosts: A 23, B 16, C 28, D 13.
Step 1, size each subnet (largest first; a block of addresses holds hosts):
| Subnet | Hosts H | H + 2 | h | Block | Prefix | Mask |
|---|---|---|---|---|---|---|
| C | 28 | 30 | 5 | 32 | /27 | 255.255.255.224 |
| A | 23 | 25 | 5 | 32 | /27 | 255.255.255.224 |
| B | 16 | 18 | 5 | 32 | /27 | 255.255.255.224 |
| D | 13 | 15 | 4 | 16 | /28 | 255.255.255.240 |
Step 2, check the fit: 32 + 32 + 32 + 16 = 112 addresses are needed and the /24 holds 256, so it fits, with 144 addresses to spare.
Step 3, allocate from 202.70.64.0, each subnet starting where the previous one ends:
| Subnet | Hosts | Network (CIDR) | Subnet mask | Usable host range | Broadcast | Wasted |
|---|---|---|---|---|---|---|
| C | 28 | 202.70.64.0/27 | 255.255.255.224 | 202.70.64.1 to 202.70.64.30 | 202.70.64.31 | 2 |
| A | 23 | 202.70.64.32/27 | 255.255.255.224 | 202.70.64.33 to 202.70.64.62 | 202.70.64.63 | 7 |
| B | 16 | 202.70.64.64/27 | 255.255.255.224 | 202.70.64.65 to 202.70.64.94 | 202.70.64.95 | 14 |
| D | 13 | 202.70.64.96/28 | 255.255.255.240 | 202.70.64.97 to 202.70.64.110 | 202.70.64.111 | 1 |
Unused range: 202.70.64.112 to 202.70.64.255 (144 addresses), kept for growth.
Answer: C 202.70.64.0/27, A 202.70.64.32/27, B 202.70.64.64/27, D 202.70.64.96/28; masks, broadcasts and usable ranges as in the table.
2068 Baishakh · Q46 marksYou are given the IP address block 200.10.80.32/25. If there are five departments which require 5, 40, 28, 12, 6 hosts respectively. Design the subnet.
How this is read200.10.80.32 has host bits set under /25 (32 is below 128), so the block is its network, 200.10.80.0/25. Starting at .32 instead would leave only 96 addresses (.32 to .127), too few for the 128 the five subnets need.
Given: block 200.10.80.32/25; hosts: Dept 1 5, Dept 2 40, Dept 3 28, Dept 4 12, Dept 5 6.
Find the block: the /25 mask is 255.255.255.128; in octet 4, 32 = 00100000 AND 10000000 = 00000000 = 0, so the block is the network 200.10.80.0/25 (200.10.80.0 to 200.10.80.127).
Step 1, size each subnet (largest first; a block of addresses holds hosts):
| Subnet | Hosts H | H + 2 | h | Block | Prefix | Mask |
|---|---|---|---|---|---|---|
| Dept 2 | 40 | 42 | 6 | 64 | /26 | 255.255.255.192 |
| Dept 3 | 28 | 30 | 5 | 32 | /27 | 255.255.255.224 |
| Dept 4 | 12 | 14 | 4 | 16 | /28 | 255.255.255.240 |
| Dept 5 | 6 | 8 | 3 | 8 | /29 | 255.255.255.248 |
| Dept 1 | 5 | 7 | 3 | 8 | /29 | 255.255.255.248 |
Step 2, check the fit: 64 + 32 + 16 + 8 + 8 = 128 addresses are needed and the /25 holds 128, so it fits exactly.
Step 3, allocate from 200.10.80.0, each subnet starting where the previous one ends:
| Subnet | Hosts | Network (CIDR) | Subnet mask | Usable host range | Broadcast | Wasted |
|---|---|---|---|---|---|---|
| Dept 2 | 40 | 200.10.80.0/26 | 255.255.255.192 | 200.10.80.1 to 200.10.80.62 | 200.10.80.63 | 22 |
| Dept 3 | 28 | 200.10.80.64/27 | 255.255.255.224 | 200.10.80.65 to 200.10.80.94 | 200.10.80.95 | 2 |
| Dept 4 | 12 | 200.10.80.96/28 | 255.255.255.240 | 200.10.80.97 to 200.10.80.110 | 200.10.80.111 | 2 |
| Dept 5 | 6 | 200.10.80.112/29 | 255.255.255.248 | 200.10.80.113 to 200.10.80.118 | 200.10.80.119 | 0 |
| Dept 1 | 5 | 200.10.80.120/29 | 255.255.255.248 | 200.10.80.121 to 200.10.80.126 | 200.10.80.127 | 1 |
Unused range: none; the block is used exactly.
Answer: Dept 2 200.10.80.0/26, Dept 3 200.10.80.64/27, Dept 4 200.10.80.96/28, Dept 5 200.10.80.112/29, Dept 1 200.10.80.120/29; masks, ranges and broadcasts as in the table.
2066 Bhadra · Q5a6 marksYou are given the IPv4 address block 203.71.53.0/26; assign the IP subnet for the following network. [Figure, as text: Net A: 6 Hosts (LAN on router R1); Net B: 2 Hosts (link R1 to R2); Net C: 12 Hosts (LAN on router R2); Net E: 2 Hosts (link R2 to R3); Net F: 29 Hosts (LAN on router R3). The routers are unlabelled in the print and no Net D is drawn.]
How this is readThe host counts are taken to include the router interfaces, as the 2 hosts of Nets B and E are the two router ends of each link; on that reading the five nets fill the /26 exactly. (With one more address on each LAN for its router, Net A would need a /28 and the nets would need 72 addresses, more than the 64 of the /26.)
Given: block 203.71.53.0/26 (64 addresses, 203.71.53.0 to 203.71.53.63); hosts: Net A 6, Net B 2, Net C 12, Net E 2, Net F 29.
Step 1, size each subnet (largest first; a block of addresses holds hosts):
| Subnet | Hosts H | H + 2 | h | Block | Prefix | Mask |
|---|---|---|---|---|---|---|
| Net F (LAN on R3) | 29 | 31 | 5 | 32 | /27 | 255.255.255.224 |
| Net C (LAN on R2) | 12 | 14 | 4 | 16 | /28 | 255.255.255.240 |
| Net A (LAN on R1) | 6 | 8 | 3 | 8 | /29 | 255.255.255.248 |
| Net B (link R1 to R2) | 2 | 4 | 2 | 4 | /30 | 255.255.255.252 |
| Net E (link R2 to R3) | 2 | 4 | 2 | 4 | /30 | 255.255.255.252 |
Step 2, check the fit: 32 + 16 + 8 + 4 + 4 = 64 addresses are needed and the /26 holds 64, so it fits exactly.
Step 3, allocate from 203.71.53.0, each subnet starting where the previous one ends:
| Subnet | Hosts | Network (CIDR) | Subnet mask | Usable host range | Broadcast | Wasted |
|---|---|---|---|---|---|---|
| Net F (LAN on R3) | 29 | 203.71.53.0/27 | 255.255.255.224 | 203.71.53.1 to 203.71.53.30 | 203.71.53.31 | 1 |
| Net C (LAN on R2) | 12 | 203.71.53.32/28 | 255.255.255.240 | 203.71.53.33 to 203.71.53.46 | 203.71.53.47 | 2 |
| Net A (LAN on R1) | 6 | 203.71.53.48/29 | 255.255.255.248 | 203.71.53.49 to 203.71.53.54 | 203.71.53.55 | 0 |
| Net B (link R1 to R2) | 2 | 203.71.53.56/30 | 255.255.255.252 | 203.71.53.57 to 203.71.53.58 | 203.71.53.59 | 0 |
| Net E (link R2 to R3) | 2 | 203.71.53.60/30 | 255.255.255.252 | 203.71.53.61 to 203.71.53.62 | 203.71.53.63 | 0 |
Unused range: none; the block is used exactly.
Answer: Net F (LAN on R3) 203.71.53.0/27, Net C (LAN on R2) 203.71.53.32/28, Net A (LAN on R1) 203.71.53.48/29, Net B (link R1 to R2) 203.71.53.56/30, Net E (link R2 to R3) 203.71.53.60/30; the two router links take the two /30s.
Insights on Computer Networks, p. 156 to 157From 201.40.58.0/24 design subnets for groups of 49, 27, 11 and 45 hosts with minimum wastage; give the mask, network, broadcast, assigned and unassigned range of each.
How this is readInsights tags this 2073 Magh, a sitting not among the 27 papers on record. Its subnets agree, but it never gives the assigned and unassigned ranges the question asks for; they are in the table below, and 201.40.58.176 to 201.40.58.255 of the block is unassigned.
Given: block 201.40.58.0/24 (256 addresses, 201.40.58.0 to 201.40.58.255); hosts: Group 1 49, Group 2 27, Group 3 11, Group 4 45.
Step 1, size each subnet (largest first; a block of addresses holds hosts):
| Subnet | Hosts H | H + 2 | h | Block | Prefix | Mask |
|---|---|---|---|---|---|---|
| Group 1 | 49 | 51 | 6 | 64 | /26 | 255.255.255.192 |
| Group 4 | 45 | 47 | 6 | 64 | /26 | 255.255.255.192 |
| Group 2 | 27 | 29 | 5 | 32 | /27 | 255.255.255.224 |
| Group 3 | 11 | 13 | 4 | 16 | /28 | 255.255.255.240 |
Step 2, check the fit: 64 + 64 + 32 + 16 = 176 addresses are needed and the /24 holds 256, so it fits, with 80 addresses to spare.
Step 3, allocate from 201.40.58.0, each subnet starting where the previous one ends:
| Subnet | Hosts | Network (CIDR) | Subnet mask | Usable host range | Assigned to the hosts | Unassigned (count) | Broadcast |
|---|---|---|---|---|---|---|---|
| Group 1 | 49 | 201.40.58.0/26 | 255.255.255.192 | 201.40.58.1 to 201.40.58.62 | 201.40.58.1 to 201.40.58.49 | 201.40.58.50 to 201.40.58.62 (13) | 201.40.58.63 |
| Group 4 | 45 | 201.40.58.64/26 | 255.255.255.192 | 201.40.58.65 to 201.40.58.126 | 201.40.58.65 to 201.40.58.109 | 201.40.58.110 to 201.40.58.126 (17) | 201.40.58.127 |
| Group 2 | 27 | 201.40.58.128/27 | 255.255.255.224 | 201.40.58.129 to 201.40.58.158 | 201.40.58.129 to 201.40.58.155 | 201.40.58.156 to 201.40.58.158 (3) | 201.40.58.159 |
| Group 3 | 11 | 201.40.58.160/28 | 255.255.255.240 | 201.40.58.161 to 201.40.58.174 | 201.40.58.161 to 201.40.58.171 | 201.40.58.172 to 201.40.58.174 (3) | 201.40.58.175 |
Unassigned range of the block: 201.40.58.176 to 201.40.58.255 (80 addresses), kept for growth.
Answer: Group 1 201.40.58.0/26, Group 4 201.40.58.64/26, Group 2 201.40.58.128/27, Group 3 201.40.58.160/28; assigned and unassigned ranges as in the table.
Insights on Computer Networks, p. 157 to 159Departments A, B, C and D have 25, 16, 29 and 11 hosts. From 202.70.91.0/24 design subnets with minimum wastage and give the mask, network, broadcast and usable host range of each.
How this is readInsights tags this 2073 Chaitra, a sitting not among the 27 papers on record. Its subnets agree; its table prints the broadcast of A (25 hosts) as 202.70.91.94.63, which is 202.70.91.63.
Given: block 202.70.91.0/24 (256 addresses, 202.70.91.0 to 202.70.91.255); hosts: A 25, B 16, C 29, D 11.
Step 1, size each subnet (largest first; a block of addresses holds hosts):
| Subnet | Hosts H | H + 2 | h | Block | Prefix | Mask |
|---|---|---|---|---|---|---|
| C | 29 | 31 | 5 | 32 | /27 | 255.255.255.224 |
| A | 25 | 27 | 5 | 32 | /27 | 255.255.255.224 |
| B | 16 | 18 | 5 | 32 | /27 | 255.255.255.224 |
| D | 11 | 13 | 4 | 16 | /28 | 255.255.255.240 |
Step 2, check the fit: 32 + 32 + 32 + 16 = 112 addresses are needed and the /24 holds 256, so it fits, with 144 addresses to spare.
Step 3, allocate from 202.70.91.0, each subnet starting where the previous one ends:
| Subnet | Hosts | Network (CIDR) | Subnet mask | Usable host range | Broadcast | Wasted |
|---|---|---|---|---|---|---|
| C | 29 | 202.70.91.0/27 | 255.255.255.224 | 202.70.91.1 to 202.70.91.30 | 202.70.91.31 | 1 |
| A | 25 | 202.70.91.32/27 | 255.255.255.224 | 202.70.91.33 to 202.70.91.62 | 202.70.91.63 | 5 |
| B | 16 | 202.70.91.64/27 | 255.255.255.224 | 202.70.91.65 to 202.70.91.94 | 202.70.91.95 | 14 |
| D | 11 | 202.70.91.96/28 | 255.255.255.240 | 202.70.91.97 to 202.70.91.110 | 202.70.91.111 | 3 |
Unused range: 202.70.91.112 to 202.70.91.255 (144 addresses), kept for growth.
Answer: C 202.70.91.0/27, A 202.70.91.32/27, B 202.70.91.64/27, D 202.70.91.96/28; masks, broadcasts and usable ranges as in the table.
Insights on Computer Networks, p. 162 to 163A company has departments of 20, 32, 60 and 24 computers. Assume a class C public network and design VLSM blocks with the network, broadcast, usable range and mask of each.
How this is readInsights tags this 2076 Bhadra, a sitting not among the 27 papers on record. No block is given; 192.0.2.0/24, a class C documentation block (RFC 5737), stands for it. Insights says it assumes 200.10.10.0/24 and then computes every row with 202.10.10.x; its layout is right.
Given: block 192.0.2.0/24, standing for the public class C network (256 addresses, 192.0.2.0 to 192.0.2.255); computers: Dept 1 20, Dept 2 32, Dept 3 60, Dept 4 24.
The trap: 32 computers need 32 + 2 = 34 addresses, but a /27 holds only 30 hosts, so Dept 2 needs a /26 and wastes 30.
Step 1, size each subnet (largest first; a block of addresses holds hosts):
| Subnet | Hosts H | H + 2 | h | Block | Prefix | Mask |
|---|---|---|---|---|---|---|
| Dept 3 | 60 | 62 | 6 | 64 | /26 | 255.255.255.192 |
| Dept 2 | 32 | 34 | 6 | 64 | /26 | 255.255.255.192 |
| Dept 4 | 24 | 26 | 5 | 32 | /27 | 255.255.255.224 |
| Dept 1 | 20 | 22 | 5 | 32 | /27 | 255.255.255.224 |
Step 2, check the fit: 64 + 64 + 32 + 32 = 192 addresses are needed and the /24 holds 256, so it fits, with 64 addresses to spare.
Step 3, allocate from 192.0.2.0, each subnet starting where the previous one ends:
| Subnet | Hosts | Network (CIDR) | Subnet mask | Usable host range | Broadcast | Wasted |
|---|---|---|---|---|---|---|
| Dept 3 | 60 | 192.0.2.0/26 | 255.255.255.192 | 192.0.2.1 to 192.0.2.62 | 192.0.2.63 | 2 |
| Dept 2 | 32 | 192.0.2.64/26 | 255.255.255.192 | 192.0.2.65 to 192.0.2.126 | 192.0.2.127 | 30 |
| Dept 4 | 24 | 192.0.2.128/27 | 255.255.255.224 | 192.0.2.129 to 192.0.2.158 | 192.0.2.159 | 6 |
| Dept 1 | 20 | 192.0.2.160/27 | 255.255.255.224 | 192.0.2.161 to 192.0.2.190 | 192.0.2.191 | 10 |
Unused range: 192.0.2.192 to 192.0.2.255 (64 addresses), kept for growth.
Answer: Dept 3 192.0.2.0/26, Dept 2 192.0.2.64/26, Dept 4 192.0.2.128/27, Dept 1 192.0.2.160/27; masks, ranges and broadcasts as in the table.
Insights on Computer Networks, p. 140 to 142Consecutive addresses are available starting at 192.122.2.1. Four organisations, Pulchowk, Thapathali, WRC and ERC, request 6000, 2000, 4000 and 2500 addresses. Design the blocks and give the first and last address and the mask, in x.y.z.w/s notation, for each.
How this is readInsights tags this 2070 Bhadra, a sitting not among the 27 papers on record. The start, 192.122.2.1, is no block boundary, so the blocks begin at the first /19 boundary inside the pool. Insights instead gives Pulchowk 192.122.0.0/19, which takes in 192.122.0.0 to 192.122.2.0, addresses before the pool starts; from WRC onwards, and in its whole table, it writes 192.221 for 192.122; and it starts the ERC range at .49.1, though its own ERC block starts at .48.0 (first host .48.1).
Given: a pool starting at 192.122.2.1; requests: Pulchowk 6,000, Thapathali 2,000, WRC 4,000, ERC 2,500.
Step 1, size each block (largest first):
| Subnet | Hosts H | H + 2 | h | Block | Prefix | Mask |
|---|---|---|---|---|---|---|
| Pulchowk | 6,000 | 6,002 | 13 | 8,192 | /19 | 255.255.224.0 |
| WRC | 4,000 | 4,002 | 12 | 4,096 | /20 | 255.255.240.0 |
| ERC | 2,500 | 2,502 | 12 | 4,096 | /20 | 255.255.240.0 |
| Thapathali | 2,000 | 2,002 | 11 | 2,048 | /21 | 255.255.248.0 |
Step 2, place the blocks: a /19 must start where the third octet is a multiple of 32; the pool starts inside 192.122.0.0/19, so the first /19 wholly inside the pool is 192.122.32.0/19. Each later block starts where the previous one ends, already on its own boundary.
| Organisation | Requested | Block (x.y.z.w/s) | First to last address | First to last valid host | Mask |
|---|---|---|---|---|---|
| Pulchowk | 6,000 | 192.122.32.0/19 | 192.122.32.0 to 192.122.63.255 | 192.122.32.1 to 192.122.63.254 | 255.255.224.0 |
| WRC | 4,000 | 192.122.64.0/20 | 192.122.64.0 to 192.122.79.255 | 192.122.64.1 to 192.122.79.254 | 255.255.240.0 |
| ERC | 2,500 | 192.122.80.0/20 | 192.122.80.0 to 192.122.95.255 | 192.122.80.1 to 192.122.95.254 | 255.255.240.0 |
| Thapathali | 2,000 | 192.122.96.0/21 | 192.122.96.0 to 192.122.103.255 | 192.122.96.1 to 192.122.103.254 | 255.255.248.0 |
Left free: 192.122.2.1 to 192.122.31.255 (7,679 addresses) before the first block, for smaller blocks later; its biggest whole blocks are 192.122.16.0/20 and 192.122.8.0/21.
Answer: Pulchowk 192.122.32.0/19, WRC 192.122.64.0/20, ERC 192.122.80.0/20, Thapathali 192.122.96.0/21; first and last valid hosts and masks as in the table.
Insights on Computer Networks, p. 144 to 147What is subnet masking? Five departments need 27, 28, 7, 12 and 8 hosts. Design the subnets with minimum loss of addresses and write the starting and ending address of each.
How this is readInsights tags this 2071 Magh, a sitting not among the 27 papers on record. Its subnets are right, but after assuming 192.168.0.0/24 it writes "Given mask: 255.255.224.0 (/19)", sizes 7 hosts as "8 = 2^n - 2", and its table drops an octet from four broadcasts (192.168.31 for 192.168.0.31, and likewise .63, .79, .95).
Given: block 192.168.0.0/24, the block Insights assumes (256 addresses, 192.168.0.0 to 192.168.0.255); hosts: Dept 1 27, Dept 2 28, Dept 3 7, Dept 4 12, Dept 5 8.
Subnet masking: ANDing an address with its mask keeps the network bits and clears the host bits, giving the (sub)network address a router forwards on. For example 130.45.34.56 = 10000010.00101101.00100010.00111000 AND 255.255.0.0 gives 130.45.0.0.
Step 1, size each subnet (largest first):
| Subnet | Hosts H | H + 2 | h | Block | Prefix | Mask |
|---|---|---|---|---|---|---|
| Dept 2 | 28 | 30 | 5 | 32 | /27 | 255.255.255.224 |
| Dept 1 | 27 | 29 | 5 | 32 | /27 | 255.255.255.224 |
| Dept 4 | 12 | 14 | 4 | 16 | /28 | 255.255.255.240 |
| Dept 5 | 8 | 10 | 4 | 16 | /28 | 255.255.255.240 |
| Dept 3 | 7 | 9 | 4 | 16 | /28 | 255.255.255.240 |
Step 2, check the fit: 32 + 32 + 16 + 16 + 16 = 112 addresses are needed and the /24 holds 256, so it fits, with 144 addresses to spare.
Step 3, allocate from 192.168.0.0:
| Subnet | Hosts | Network (CIDR) | Starting address | Ending address | Usable host range |
|---|---|---|---|---|---|
| Dept 2 | 28 | 192.168.0.0/27 | 192.168.0.0 | 192.168.0.31 | 192.168.0.1 to 192.168.0.30 |
| Dept 1 | 27 | 192.168.0.32/27 | 192.168.0.32 | 192.168.0.63 | 192.168.0.33 to 192.168.0.62 |
| Dept 4 | 12 | 192.168.0.64/28 | 192.168.0.64 | 192.168.0.79 | 192.168.0.65 to 192.168.0.78 |
| Dept 5 | 8 | 192.168.0.80/28 | 192.168.0.80 | 192.168.0.95 | 192.168.0.81 to 192.168.0.94 |
| Dept 3 | 7 | 192.168.0.96/28 | 192.168.0.96 | 192.168.0.111 | 192.168.0.97 to 192.168.0.110 |
Unused range: 192.168.0.112 to 192.168.0.255 (144 addresses), kept for growth.
Answer: Dept 2 192.168.0.0/27, Dept 1 192.168.0.32/27, Dept 4 192.168.0.64/28, Dept 5 192.168.0.80/28, Dept 3 192.168.0.96/28; each subnet starts at its network address and ends at its broadcast.
Insights on Computer Networks, p. 149 to 151Design IPv4 subnets from 192.168.5.0/24 for departments of 16, 48, 61, 32 and 24 computers.
How this is readInsights tags this 2072 Magh, a sitting not among the 27 papers on record. Its subnets agree; its table prints the 61-computer range as 192.168.5.1 to 192.168.5.63, which is the broadcast (its working rightly ends at 192.168.5.62).
Given: block 192.168.5.0/24 (256 addresses, 192.168.5.0 to 192.168.5.255); computers: Dept 1 16, Dept 2 48, Dept 3 61, Dept 4 32, Dept 5 24.
The trap: 32 computers need 32 + 2 = 34 addresses, but a /27 holds only 30 hosts, so Dept 4 needs a /26 and wastes 30.
Step 1, size each subnet (largest first; a block of addresses holds hosts):
| Subnet | Hosts H | H + 2 | h | Block | Prefix | Mask |
|---|---|---|---|---|---|---|
| Dept 3 | 61 | 63 | 6 | 64 | /26 | 255.255.255.192 |
| Dept 2 | 48 | 50 | 6 | 64 | /26 | 255.255.255.192 |
| Dept 4 | 32 | 34 | 6 | 64 | /26 | 255.255.255.192 |
| Dept 5 | 24 | 26 | 5 | 32 | /27 | 255.255.255.224 |
| Dept 1 | 16 | 18 | 5 | 32 | /27 | 255.255.255.224 |
Step 2, check the fit: 64 + 64 + 64 + 32 + 32 = 256 addresses are needed and the /24 holds 256, so it fits exactly.
Step 3, allocate from 192.168.5.0, each subnet starting where the previous one ends:
| Subnet | Hosts | Network (CIDR) | Subnet mask | Usable host range | Broadcast | Wasted |
|---|---|---|---|---|---|---|
| Dept 3 | 61 | 192.168.5.0/26 | 255.255.255.192 | 192.168.5.1 to 192.168.5.62 | 192.168.5.63 | 1 |
| Dept 2 | 48 | 192.168.5.64/26 | 255.255.255.192 | 192.168.5.65 to 192.168.5.126 | 192.168.5.127 | 14 |
| Dept 4 | 32 | 192.168.5.128/26 | 255.255.255.192 | 192.168.5.129 to 192.168.5.190 | 192.168.5.191 | 30 |
| Dept 5 | 24 | 192.168.5.192/27 | 255.255.255.224 | 192.168.5.193 to 192.168.5.222 | 192.168.5.223 | 6 |
| Dept 1 | 16 | 192.168.5.224/27 | 255.255.255.224 | 192.168.5.225 to 192.168.5.254 | 192.168.5.255 | 14 |
Unused range: none; the block is used exactly.
Answer: Dept 3 192.168.5.0/26, Dept 2 192.168.5.64/26, Dept 4 192.168.5.128/26, Dept 5 192.168.5.192/27, Dept 1 192.168.5.224/27; the five fill the /24 exactly.
Insights on Computer Networks, p. 151 to 153Design a network with public addresses for five departments of IOE Pulchowk Campus with 45, 35, 40, 23 and 30 computers, with minimum loss; assume the address block.
How this is readInsights tags this 2072 Ashwin, a sitting not among the 27 papers on record. No block is given; 192.0.2.0/24, a class C documentation block (RFC 5737), stands for the public network. Insights assumes 200.10.10.0/24 and gets the same layout; it is right.
Given: block 192.0.2.0/24, standing for the public class C network (256 addresses, 192.0.2.0 to 192.0.2.255); computers: Dept 1 45, Dept 2 35, Dept 3 40, Dept 4 23, Dept 5 30.
Step 1, size each subnet (largest first; a block of addresses holds hosts):
| Subnet | Hosts H | H + 2 | h | Block | Prefix | Mask |
|---|---|---|---|---|---|---|
| Dept 1 | 45 | 47 | 6 | 64 | /26 | 255.255.255.192 |
| Dept 3 | 40 | 42 | 6 | 64 | /26 | 255.255.255.192 |
| Dept 2 | 35 | 37 | 6 | 64 | /26 | 255.255.255.192 |
| Dept 5 | 30 | 32 | 5 | 32 | /27 | 255.255.255.224 |
| Dept 4 | 23 | 25 | 5 | 32 | /27 | 255.255.255.224 |
Step 2, check the fit: 64 + 64 + 64 + 32 + 32 = 256 addresses are needed and the /24 holds 256, so it fits exactly.
Step 3, allocate from 192.0.2.0, each subnet starting where the previous one ends:
| Subnet | Hosts | Network (CIDR) | Subnet mask | Usable host range | Broadcast | Wasted |
|---|---|---|---|---|---|---|
| Dept 1 | 45 | 192.0.2.0/26 | 255.255.255.192 | 192.0.2.1 to 192.0.2.62 | 192.0.2.63 | 17 |
| Dept 3 | 40 | 192.0.2.64/26 | 255.255.255.192 | 192.0.2.65 to 192.0.2.126 | 192.0.2.127 | 22 |
| Dept 2 | 35 | 192.0.2.128/26 | 255.255.255.192 | 192.0.2.129 to 192.0.2.190 | 192.0.2.191 | 27 |
| Dept 5 | 30 | 192.0.2.192/27 | 255.255.255.224 | 192.0.2.193 to 192.0.2.222 | 192.0.2.223 | 0 |
| Dept 4 | 23 | 192.0.2.224/27 | 255.255.255.224 | 192.0.2.225 to 192.0.2.254 | 192.0.2.255 | 7 |
Unused range: none; the block is used exactly.
Answer: Dept 1 192.0.2.0/26, Dept 3 192.0.2.64/26, Dept 2 192.0.2.128/26, Dept 5 192.0.2.192/27, Dept 4 192.0.2.224/27; the five fill the class C network exactly.
Fixed length subnetting: equal subnets PIN 3/27
Ch 4 · Network layer3 from 3 of the 27 sittings
- Borrow bits: for n equal subnets borrow s bits with ; where a host count H sets the size instead, keep h host bits with .
- New prefix and mask: /p becomes /(p + s); each subnet holds addresses, and the mask octet where the boundary falls is 256 minus the block size in that octet.
- List the subnets: subnet k starts at network + k × block size; its broadcast is one below the next start; the usable hosts lie in between.
- Assign: the first n subnets go to the departments; the other stay spare.
2081 Baishakh · Q45 marksSuppose your company has IP address block of 16.16.16.0/21. Divide this IP address for five different departments of the company equally. List out the network address, broadcast address, subnet mask and usable IP address range for each subnet.
How this is read"Divide equally" asks for fixed length subnetting, not VLSM: equal subnets come in powers of two, so five departments take 5 of 8 equal /24 subnets and the other 3 stay spare.
Given: block 16.16.16.0/21 (2,048 addresses, 16.16.16.0 to 16.16.23.255); 5 departments, equal subnets.
Step 1, borrow bits: gives s = 3 ( is too few), so the /21 splits into = 8 subnets.
Step 2, new prefix and mask: /21 + 3 = /24, mask 255.255.255.0; each subnet holds = 256 addresses, 254 usable hosts.
Step 3, list the subnets (each starts 256 addresses, one step of the third octet, after the last):
| Department | Network (CIDR) | Subnet mask | Usable host range | Broadcast |
|---|---|---|---|---|
| Dept 1 | 16.16.16.0/24 | 255.255.255.0 | 16.16.16.1 to 16.16.16.254 | 16.16.16.255 |
| Dept 2 | 16.16.17.0/24 | 255.255.255.0 | 16.16.17.1 to 16.16.17.254 | 16.16.17.255 |
| Dept 3 | 16.16.18.0/24 | 255.255.255.0 | 16.16.18.1 to 16.16.18.254 | 16.16.18.255 |
| Dept 4 | 16.16.19.0/24 | 255.255.255.0 | 16.16.19.1 to 16.16.19.254 | 16.16.19.255 |
| Dept 5 | 16.16.20.0/24 | 255.255.255.0 | 16.16.20.1 to 16.16.20.254 | 16.16.20.255 |
| Spare | 16.16.21.0/24 | 255.255.255.0 | 16.16.21.1 to 16.16.21.254 | 16.16.21.255 |
| Spare | 16.16.22.0/24 | 255.255.255.0 | 16.16.22.1 to 16.16.22.254 | 16.16.22.255 |
| Spare | 16.16.23.0/24 | 255.255.255.0 | 16.16.23.1 to 16.16.23.254 | 16.16.23.255 |
Answer: departments 1 to 5 get 16.16.16.0/24 to 16.16.20.0/24, each with mask 255.255.255.0 and 254 usable hosts; 16.16.21.0/24, 16.16.22.0/24, 16.16.23.0/24 stay spare for new departments.
2070 Ashad · Q94 markssub-netting with example
How this is readThe question asks for an example and gives no numbers, so one clean example of subnetting is chosen: a private (RFC 1918) campus block cut into four equal subnets.
Example: a campus network 192.168.10.0/24 (256 addresses) is cut into 4 equal subnets, one per department, so that each department is its own network behind one router interface.
Step 1, borrow bits: gives s = 2.
Step 2, new prefix and mask: /24 + 2 = /26; mask 255.255.255.192 (last octet 11000000); each subnet holds = 64 addresses, 62 usable hosts.
Step 3, list the subnets (each starts 64 after the last):
| Department | Network (CIDR) | Subnet mask | Usable host range | Broadcast |
|---|---|---|---|---|
| Dept 1 | 192.168.10.0/26 | 255.255.255.192 | 192.168.10.1 to 192.168.10.62 | 192.168.10.63 |
| Dept 2 | 192.168.10.64/26 | 255.255.255.192 | 192.168.10.65 to 192.168.10.126 | 192.168.10.127 |
| Dept 3 | 192.168.10.128/26 | 255.255.255.192 | 192.168.10.129 to 192.168.10.190 | 192.168.10.191 |
| Dept 4 | 192.168.10.192/26 | 255.255.255.192 | 192.168.10.193 to 192.168.10.254 | 192.168.10.255 |
Finding the subnet of a host: AND its address with the mask. For 192.168.10.75, the last octet 75 = 01001011 AND 11000000 = 01000000 = 64, so the host is on 192.168.10.64/26 (Dept 2), whose broadcast is 192.168.10.127.
Answer: 192.168.10.0/24 with 2 bits borrowed gives 4 subnets of 62 hosts: 192.168.10.0/26, 192.168.10.64/26, 192.168.10.128/26, 192.168.10.192/26, all with mask 255.255.255.192.
2067 Ashad · Q98 marksIf you need to assign IP addresses to all computers of question no. 2 making each department as network. What will be your approach? Explain with IP address ranges you are suggesting.
How this is readQuestion 2 of 2067 Ashad sets the campus: 5 departments of 100 computers each, in 5 rooms of 20. No block is given; the computers sit inside a campus LAN, so a private block is chosen, and 192.168.0.0/22 is the smallest one that holds 5 department /25 networks.
Given (question 2 of the same sitting): Pulchowk Campus, 5 departments, each with 100 computers in 5 rooms of 20; each department is to be one network.
Approach: one subnet per department, sized from its host count, cut from a private block (RFC 1918): campus PCs need no public addresses and reach the Internet through NAT on the campus router, which also routes between the department subnets.
Step 1, size a department subnet: 100 computers + 1 router interface (the department gateway) = 101 hosts; gives h = 7, a /25 of 128 addresses (126 hosts, mask 255.255.255.128), leaving 25 spare in each department for printers, access points and growth.
Step 2, size the block: 5 departments × 128 = 640 addresses; the smallest power of two that holds them is 1,024, a /22. Chosen: 192.168.0.0/22 (192.168.0.0 to 192.168.3.255).
Step 3, cut the /22 into /25 subnets (3 bits borrowed, 8 subnets):
| Department | Network (CIDR) | Subnet mask | Usable host range | Gateway (router) | Broadcast |
|---|---|---|---|---|---|
| Dept 1 | 192.168.0.0/25 | 255.255.255.128 | 192.168.0.1 to 192.168.0.126 | 192.168.0.1 | 192.168.0.127 |
| Dept 2 | 192.168.0.128/25 | 255.255.255.128 | 192.168.0.129 to 192.168.0.254 | 192.168.0.129 | 192.168.0.255 |
| Dept 3 | 192.168.1.0/25 | 255.255.255.128 | 192.168.1.1 to 192.168.1.126 | 192.168.1.1 | 192.168.1.127 |
| Dept 4 | 192.168.1.128/25 | 255.255.255.128 | 192.168.1.129 to 192.168.1.254 | 192.168.1.129 | 192.168.1.255 |
| Dept 5 | 192.168.2.0/25 | 255.255.255.128 | 192.168.2.1 to 192.168.2.126 | 192.168.2.1 | 192.168.2.127 |
| Spare | 192.168.2.128/25 | 255.255.255.128 | 192.168.2.129 to 192.168.2.254 | 192.168.2.255 | |
| Spare | 192.168.3.0/25 | 255.255.255.128 | 192.168.3.1 to 192.168.3.126 | 192.168.3.127 | |
| Spare | 192.168.3.128/25 | 255.255.255.128 | 192.168.3.129 to 192.168.3.254 | 192.168.3.255 |
Rooms: the 20 computers of each room hang off one 24-port switch, and the room switches uplink to the department switch, all on the department subnet; a room needs no subnet of its own.
Trade-off: private space is not scarce, so one /24 per department (192.168.1.0/24 to 192.168.5.0/24, 254 hosts each) is an equally valid plan, simpler to read and with more room to grow; the /25 plan above wastes less.
Answer: departments 1 to 5 get 192.168.0.0/25, 192.168.0.128/25, 192.168.1.0/25, 192.168.1.128/25, 192.168.2.0/25, each with mask 255.255.255.128 and its first host as gateway; 192.168.2.128/25, 192.168.3.0/25, 192.168.3.128/25 stay spare.
Dijkstra's shortest path BOOK
Ch 4 · Network layernot set by a paper yet, 1 from the book
- Start: make the source permanent with cost 0; every other node is tentative, labelled (∞, -).
- Relabel: for each neighbour of the node made permanent last, if its cost plus the link cost is less than the neighbour's label, relabel the neighbour (new cost, via that node).
- Pick: make the tentative node with the smallest cost permanent.
- Repeat steps 2 and 3 until the destination is permanent; read the path backwards through the "via" labels.
Insights on Computer Networks, p. 118 to 119Find the shortest path from A to D by Dijkstra's algorithm on the graph of Figure 4.12: links A-B 2, A-G 6, B-C 7, B-E 2, E-F 2, E-G 1, F-C 3, F-H 2, C-D 3, H-D 2 and G-H 4.
How this is readInsights draws the steps as Figure 4.12 (b) to (f) and stops with H at (8, F) and D still unlabelled: the last steps (C permanent at 9, then D at 10 via H) and the cost 10 are not shown, and panel (d) labels D (∞, 1) where it should read (∞, -). Its path, ABEFHD, is right.
Given: the graph of Figure 4.12, links A-B 2, A-G 6, B-C 7, B-E 2, E-F 2, E-G 1, F-C 3, F-H 2, C-D 3, H-D 2, G-H 4; source A, destination D.
Working: each row makes one node permanent and relabels its tentative neighbours; a label is (cost from A, via node), permanent labels in bold.
| Step | Made permanent | B | C | D | E | F | G | H |
|---|---|---|---|---|---|---|---|---|
| 1 | A (0) | (2, A) | ∞ | ∞ | ∞ | ∞ | (6, A) | ∞ |
| 2 | B (2) | (2, A) | (9, B) | ∞ | (4, B) | ∞ | (6, A) | ∞ |
| 3 | E (4) | (2, A) | (9, B) | ∞ | (4, B) | (6, E) | (5, E) | ∞ |
| 4 | G (5) | (2, A) | (9, B) | ∞ | (4, B) | (6, E) | (5, E) | (9, G) |
| 5 | F (6) | (2, A) | (9, B) | ∞ | (4, B) | (6, E) | (5, E) | (8, F) |
| 6 | H (8) | (2, A) | (9, B) | (10, H) | (4, B) | (6, E) | (5, E) | (8, F) |
| 7 | C (9) | (2, A) | (9, B) | (10, H) | (4, B) | (6, E) | (5, E) | (8, F) |
| 8 | D (10) | (2, A) | (9, B) | (10, H) | (4, B) | (6, E) | (5, E) | (8, F) |
Path: back from D through the via labels: D from H, H from F, F from E, E from B, B from A. Cost: 2 + 2 + 2 + 2 + 2 = 10.
Answer: the shortest path from A to D is A B E F H D, cost 10.
Distance vector routing: updating a routing table BOOK
Ch 4 · Network layernot set by a paper yet, 1 from the book
- Receive: each router gets its neighbours' tables (destination, cost, next hop) at regular intervals.
- Adjust: add the cost of reaching that neighbour (1 hop) to every cost it sent, and make that neighbour the next hop.
- Combine: put the router's own table and the adjusted tables together.
- Keep the best: for each destination keep the entry with the least cost (on a tie the existing entry stays). The result is the new table, sent out at the next interval; the tables settle when an exchange changes nothing.
Insights on Computer Networks, p. 121 to 122In the network of Figure 4.14 (routers A to F joined by networks 08, 14, 23, 55, 66, 78 and 92) every router starts knowing only its own networks at 1 hop. Update router A's table from the tables of its neighbours B, E and F, and give the tables once they settle.
How this is readRecomputed, Figures 4.15 and 4.16 are right. Where two neighbours give the same cost, Figure 4.16 shows one of them (A to 66 via E; via B is as short); the last table lists both.
Given: routers A to F joined through networks 08, 14, 23, 55, 66, 78, 92 (Figure 4.14): A on 14, 23, 78; B on 14, 55; C on 55, 66; D on 08, 66; E on 08, 23; F on 78, 92. Each router starts knowing only its own networks, at cost 1 (one hop). A's neighbours are B (on net 14), E (on net 23), F (on net 78).
Step 1, A's own table (network, cost, next hop):
| Network | Cost, next hop |
|---|---|
| 14 | 1, direct |
| 23 | 1, direct |
| 78 | 1, direct |
Step 2, add one hop to each table received, the sender becoming the next hop:
| From | Network | Cost | Next hop |
|---|---|---|---|
| B | 14 | 1 + 1 = 2 | B |
| B | 55 | 1 + 1 = 2 | B |
| E | 08 | 1 + 1 = 2 | E |
| E | 23 | 1 + 1 = 2 | E |
| F | 78 | 1 + 1 = 2 | F |
| F | 92 | 1 + 1 = 2 | F |
Step 3, combine and keep the least cost for each network:
| Network | Candidates (cost, next hop) | Kept |
|---|---|---|
| 08 | 2, E | 2, E |
| 14 | 1, direct; 2, B | 1, direct |
| 23 | 1, direct; 2, E | 1, direct |
| 55 | 2, B | 2, B |
| 78 | 1, direct; 2, F | 1, direct |
| 92 | 2, F | 2, F |
Answer, A's new table:
| Network | Cost | Next hop |
|---|---|---|
| 08 | 2 | E |
| 14 | 1 | direct |
| 23 | 1 | direct |
| 55 | 2 | B |
| 78 | 1 | direct |
| 92 | 2 | F |
Network 66 is still missing: none of A's neighbours knew it yet.
The tables settle after 3 exchanges (each router repeats the three steps every interval); a cell is cost, next hop, with both next hops where two give the same cost:
| Network | A | B | C | D | E | F |
|---|---|---|---|---|---|---|
| 08 | 2, E | 3, A or C | 2, D | 1, direct | 1, direct | 3, A |
| 14 | 1, direct | 1, direct | 2, B | 3, C or E | 2, A | 2, A |
| 23 | 1, direct | 2, A | 3, B or D | 2, E | 1, direct | 2, A |
| 55 | 2, B | 1, direct | 1, direct | 2, C | 3, A or D | 3, A |
| 66 | 3, B or E | 2, C | 1, direct | 1, direct | 2, D | 4, A |
| 78 | 1, direct | 2, A | 3, B | 3, E | 2, A | 1, direct |
| 92 | 2, F | 3, A | 4, B | 4, E | 3, A | 1, direct |
A reaches 66 at 3 hops via B (which goes on through C) or via E (which goes on through D), at equal cost; Figure 4.16 keeps E.
IPv6 address shortening: leading zeros, then one double colon BOOK
Ch 7 · Introduction to IPv6not set by a paper yet, 2 from the book
- Write the address as eight groups of four hexadecimal digits; any other number of groups means the address is incomplete.
- Drop the leading zeros of every group:
0db8becomesdb8,0000becomes0. - Replace the longest run of consecutive all-zero groups by
::(the first run, if two are equally long); use::only once, and never for a single zero group. - To expand, count the groups shown:
::stands for 8 minus that count, each0000.
Insights on Computer Networks, p. 219Shorten the IPv6 address FE80:0000:0000:0001:0800:23E7:F5DB: drop the leading zeros, then replace the zero groups by a double colon.
How this is readAs printed the address has seven groups, 112 bits, one short of the 128 an IPv6 address needs, so as it stands it cannot be shortened, or even read. It is read here as FE80:0000:0000:0000:0001:0800:23E7:F5DB, the eight groups that the printed answer FE80::1:0800:23E7:F5DB stands for. The printed middle step, FE80:0:0:1:0800:23E7:F5DB, also keeps the leading zero of 0800, which the first rule drops.
Given: FE80:0000:0000:0000:0001:0800:23E7:F5DB, eight groups.
Step 1, drop the leading zeros of each group (0000 to 0, 0001 to 1, 0800 to 800):
FE80:0000:0000:0000:0001:0800:23E7:F5DB FE80:0:0:0:1:800:23E7:F5DB
Step 2, replace the run of zero groups by :: Groups 2, 3 and 4 are zero, one run of three, so they become :::
FE80:0:0:0:1:800:23E7:F5DB FE80::1:800:23E7:F5DB
Check by expanding: 5 groups are written out, so :: stands for zero groups, which gives back the eight groups above.
Answer: FE80::1:800:23E7:F5DB, or in the canonical lower case fe80::1:800:23e7:f5db.
Insights on Computer Networks, p. 219Shorten the IPv6 address 0000:0000:1212:2341:0000:0000:1212:251E, using the double colon only once.
How this is readThe printed answers, ::1212:2341:0000:0000:1212:251E and 0000:0000:1212:2341::1212:251E, are valid, but each keeps the leading zeros of the run that was not replaced; dropping them as well gives the shortest forms below.
Given: 0000:0000:1212:2341:0000:0000:1212:251E, eight groups, with two runs of two zero groups (groups 1 and 2, groups 5 and 6).
Step 1, drop the leading zeros:
0000:0000:1212:2341:0000:0000:1212:251E 0:0:1212:2341:0:0:1212:251E
Step 2, replace ONE run by :: Either run may go:
first run replaced: ::1212:2341:0:0:1212:251E second run replaced: 0:0:1212:2341::1212:251E
Why not both: ::1212:2341::1212:251E writes out 4 groups, so 4 are missing, and nothing says how they divide between the two gaps (1 + 3, 2 + 2, 3 + 1): the address would be ambiguous.
Answer: ::1212:2341:0:0:1212:251E or 0:0:1212:2341::1212:251E; the canonical form (RFC 5952: the first of two equal runs, lower case) is ::1212:2341:0:0:1212:251e.
RSA on a word, letter by letter TOP 13/27
Ch 8 · Network security13 from 13 of the 27 sittings, 1 from the book
- Number the letters A = 1, B = 2, ..., Z = 26 (lower case takes the same numbers); each letter is one block .
- Choose two primes , small enough for hand arithmetic, with , so that every is below and no two letters collide.
- Compute and .
- Choose e with and . Any shared factor fails, even when e does not divide : e = 6 shares the factor 2 with 20.
- Find d by the extended Euclidean algorithm: start , , , ; in each row , , , then move up to and to . When , and (plus if negative). Check .
- Keys: public , private .
- Encrypt each letter, ; decrypt, . For a large power use repeated squaring: write the exponent as a sum of powers of 2, square and reduce mod , then multiply the powers needed, reducing after each product.
- Write the ciphertext as numbers (a value above 26 has no letter) and check that every letter comes back. A letter may encrypt to itself (A = 1 always does, as ): a property of small RSA keys, not a slip.
2082 Bhadra · Q94+2 marksEncrypt and decrypt the “attack” using RSA.
Given: the word attack, in lower case. Lower-case letters take the same numbers as capitals: a = 1, b = 2, ..., z = 26. Each letter is one block .
Step 1: key generation. Choose the primes and .
Choose : and . The data works: and are distinct primes, keeps every letter number below (so no two letters can share a ciphertext), and shares no factor with , so exists.
Step 2: private exponent , by the extended Euclidean algorithm. Start , , , ; each row , , ; stop when .
| 6 | 20 | 3 | 2 | 0 | 1 | −6 |
| 1 | 3 | 2 | 1 | 1 | −6 | 7 |
| 2 | 2 | 1 | 0 | −6 | 7 | −20 |
| 1 | 0 | 7 | −20 |
confirms , and . Check: .
Public key ; private key .
Step 3: encryption, , and step 4: decryption, , letter by letter:
| Letter | Letter | ||||
|---|---|---|---|---|---|
| a | 1 | 1 | 1 | 1 | a |
| t | 20 | 8000 | 14 | 20 | t |
| t | 20 | 8000 | 14 | 20 | t |
| a | 1 | 1 | 1 | 1 | a |
| c | 3 | 27 | 27 | 3 | c |
| k | 11 | 1331 | 11 | 11 | k |
Decryption of one letter in full by repeated squaring, with d written as a sum of powers of 2:
Decrypt C = 14: M = 147 mod 33
d = 7 = 4 + 2 + 1
141 = 14
142 = 196 mod 33 = 31
144 = 312 = 961 mod 33 = 4
147 = 144 × 142 × 141 = 4 × 31 × 14
4 × 31 = 124 mod 33 = 25
25 × 14 = 350 mod 33 = 20
so M = 20 = t
The letters a and k encrypt to their own numbers (1, 11): for any key, and = . Every RSA key has a few such fixed values; decryption still returns them, so this is no slip.
Answer: with the public key (3, 33), attack encrypts to the ciphertext 1, 14, 14, 1, 27, 11; decryption with the private key (7, 33) gives 1, 20, 20, 1, 3, 11, the plaintext attack.
2081 Baishakh · Q97 marksEncrypt the word "security" using the RSA algorithm. Also show the decryption to obtain the plaintext.
Given: the word security, in lower case. Lower-case letters take the same numbers as capitals: a = 1, b = 2, ..., z = 26. Each letter is one block .
Step 1: key generation. Choose the primes and .
Choose : and . The data works: and are distinct primes, keeps every letter number below (so no two letters can share a ciphertext), and shares no factor with , so exists.
Step 2: private exponent , by the extended Euclidean algorithm. Start , , , ; each row , , ; stop when .
| 8 | 44 | 5 | 4 | 0 | 1 | −8 |
| 1 | 5 | 4 | 1 | 1 | −8 | 9 |
| 4 | 4 | 1 | 0 | −8 | 9 | −44 |
| 1 | 0 | 9 | −44 |
confirms , and . Check: .
Public key ; private key .
Step 3: encryption, , and step 4: decryption, , letter by letter:
| Letter | Letter | |||
|---|---|---|---|---|
| s | 19 | 34 | 19 | s |
| e | 5 | 20 | 5 | e |
| c | 3 | 36 | 3 | c |
| u | 21 | 60 | 21 | u |
| r | 18 | 3 | 18 | r |
| i | 9 | 54 | 9 | i |
| t | 20 | 56 | 20 | t |
| y | 25 | 55 | 25 | y |
Encryption in full by repeated squaring (write e as a sum of powers of 2, square and reduce mod 69, then multiply the powers needed):
Encrypt s: C = 195 mod 69
e = 5 = 4 + 1
191 = 19
192 = 361 mod 69 = 16
194 = 162 = 256 mod 69 = 49
195 = 194 × 191 = 49 × 19
49 × 19 = 931 mod 69 = 34
so C = 34
Decryption of two letters in full by repeated squaring:
Decrypt C = 34: M = 349 mod 69
d = 9 = 8 + 1
341 = 34
342 = 1156 mod 69 = 52
344 = 522 = 2704 mod 69 = 13
348 = 132 = 169 mod 69 = 31
349 = 348 × 341 = 31 × 34
31 × 34 = 1054 mod 69 = 19
so M = 19 = s
Decrypt C = 20: M = 209 mod 69
d = 9 = 8 + 1
201 = 20
202 = 400 mod 69 = 55
204 = 552 = 3025 mod 69 = 58
208 = 582 = 3364 mod 69 = 52
209 = 208 × 201 = 52 × 20
52 × 20 = 1040 mod 69 = 5
so M = 5 = e
Answer: with the public key (5, 69), security encrypts to the ciphertext 34, 20, 36, 60, 3, 54, 56, 55; decryption with the private key (9, 69) gives 19, 5, 3, 21, 18, 9, 20, 25, the plaintext security.
2080 Bhadra · Q96 marksUse RSA algorithm to encrypt and decrypt the message "network".
Given: the word network, in lower case. Lower-case letters take the same numbers as capitals: a = 1, b = 2, ..., z = 26. Each letter is one block .
Step 1: key generation. Choose the primes and .
Choose : and . The data works: and are distinct primes, keeps every letter number below (so no two letters can share a ciphertext), and shares no factor with , so exists.
Step 2: private exponent , by the extended Euclidean algorithm. Start , , , ; each row , , ; stop when .
| 10 | 32 | 3 | 2 | 0 | 1 | −10 |
| 1 | 3 | 2 | 1 | 1 | −10 | 11 |
| 2 | 2 | 1 | 0 | −10 | 11 | −32 |
| 1 | 0 | 11 | −32 |
confirms , and . Check: .
Public key ; private key .
Step 3: encryption, , and step 4: decryption, , letter by letter:
| Letter | Letter | ||||
|---|---|---|---|---|---|
| n | 14 | 2744 | 41 | 14 | n |
| e | 5 | 125 | 23 | 5 | e |
| t | 20 | 8000 | 44 | 20 | t |
| w | 23 | 12167 | 29 | 23 | w |
| o | 15 | 3375 | 9 | 15 | o |
| r | 18 | 5832 | 18 | 18 | r |
| k | 11 | 1331 | 5 | 11 | k |
Decryption of one letter in full by repeated squaring, with d written as a sum of powers of 2:
Decrypt C = 41: M = 4111 mod 51
d = 11 = 8 + 2 + 1
411 = 41
412 = 1681 mod 51 = 49
414 = 492 = 2401 mod 51 = 4
418 = 42 = 16
4111 = 418 × 412 × 411 = 16 × 49 × 41
16 × 49 = 784 mod 51 = 19
19 × 41 = 779 mod 51 = 14
so M = 14 = n
The letter r encrypts to its own number (18): = . Every RSA key has a few such fixed values; decryption still returns them, so this is no slip.
Answer: with the public key (3, 51), network encrypts to the ciphertext 41, 23, 44, 29, 9, 18, 5; decryption with the private key (11, 51) gives 14, 5, 20, 23, 15, 18, 11, the plaintext network.
2080 Baishakh · Q95 marksUse RSA algorithm to encrypt/decrypt the word COW.
Given: the word COW. Letters are numbered A = 1, B = 2, ..., Z = 26. Each letter is one block .
Step 1: key generation. Choose the primes and .
Choose : and . The data works: and are distinct primes, keeps every letter number below (so no two letters can share a ciphertext), and shares no factor with , so exists.
Step 2: private exponent , by the extended Euclidean algorithm. Start , , , ; each row , , ; stop when .
| 10 | 32 | 3 | 2 | 0 | 1 | −10 |
| 1 | 3 | 2 | 1 | 1 | −10 | 11 |
| 2 | 2 | 1 | 0 | −10 | 11 | −32 |
| 1 | 0 | 11 | −32 |
confirms , and . Check: .
Public key ; private key .
Step 3: encryption, , and step 4: decryption, , letter by letter:
| Letter | Letter | ||||
|---|---|---|---|---|---|
| C | 3 | 27 | 27 | 3 | C |
| O | 15 | 3375 | 9 | 15 | O |
| W | 23 | 12167 | 29 | 23 | W |
Decryption of one letter in full by repeated squaring, with d written as a sum of powers of 2:
Decrypt C = 29: M = 2911 mod 51
d = 11 = 8 + 2 + 1
291 = 29
292 = 841 mod 51 = 25
294 = 252 = 625 mod 51 = 13
298 = 132 = 169 mod 51 = 16
2911 = 298 × 292 × 291 = 16 × 25 × 29
16 × 25 = 400 mod 51 = 43
43 × 29 = 1247 mod 51 = 23
so M = 23 = W
Answer: with the public key (3, 51), COW encrypts to the ciphertext 27, 9, 29; decryption with the private key (11, 51) gives 3, 15, 23, the plaintext COW.
2079 Bhadra · Q97 marksEncrypt the message "PANDEMIC" using RSA algorithm. Also obtain the plaintext from the ciphertext.
Given: the word PANDEMIC. Letters are numbered A = 1, B = 2, ..., Z = 26. Each letter is one block .
Step 1: key generation. Choose the primes and .
Choose : and . The data works: and are distinct primes, keeps every letter number below (so no two letters can share a ciphertext), and shares no factor with , so exists.
Step 2: private exponent , by the extended Euclidean algorithm. Start , , , ; each row , , ; stop when .
| 6 | 20 | 3 | 2 | 0 | 1 | −6 |
| 1 | 3 | 2 | 1 | 1 | −6 | 7 |
| 2 | 2 | 1 | 0 | −6 | 7 | −20 |
| 1 | 0 | 7 | −20 |
confirms , and . Check: .
Public key ; private key .
Step 3: encryption, , and step 4: decryption, , letter by letter:
| Letter | Letter | ||||
|---|---|---|---|---|---|
| P | 16 | 4096 | 4 | 16 | P |
| A | 1 | 1 | 1 | 1 | A |
| N | 14 | 2744 | 5 | 14 | N |
| D | 4 | 64 | 31 | 4 | D |
| E | 5 | 125 | 26 | 5 | E |
| M | 13 | 2197 | 19 | 13 | M |
| I | 9 | 729 | 3 | 9 | I |
| C | 3 | 27 | 27 | 3 | C |
Decryption of two letters in full by repeated squaring, with d written as a sum of powers of 2:
Decrypt C = 4: M = 47 mod 33
d = 7 = 4 + 2 + 1
41 = 4
42 = 16
44 = 162 = 256 mod 33 = 25
47 = 44 × 42 × 41 = 25 × 16 × 4
25 × 16 = 400 mod 33 = 4
4 × 4 = 16
so M = 16 = P
Decrypt C = 31: M = 317 mod 33
d = 7 = 4 + 2 + 1
311 = 31
312 = 961 mod 33 = 4
314 = 42 = 16
317 = 314 × 312 × 311 = 16 × 4 × 31
16 × 4 = 64 mod 33 = 31
31 × 31 = 961 mod 33 = 4
so M = 4 = D
The letter A encrypts to its own number (1): for any key. Every RSA key has a few such fixed values; decryption still returns them, so this is no slip.
Answer: with the public key (3, 33), PANDEMIC encrypts to the ciphertext 4, 1, 5, 31, 26, 19, 3, 27; decryption with the private key (7, 33) gives 16, 1, 14, 4, 5, 13, 9, 3, the plaintext PANDEMIC.
2078 Bhadra · Q98 marksEncrypt the word "Computer" using RSA algorithm.
Given: the word Computer. Letters are numbered A = 1, B = 2, ..., Z = 26, capital and lower case alike. Each letter is one block .
Step 1: key generation. Choose the primes and .
Choose : and . The data works: and are distinct primes, keeps every letter number below (so no two letters can share a ciphertext), and shares no factor with , so exists.
Step 2: private exponent , by the extended Euclidean algorithm. Start , , , ; each row , , ; stop when .
| 8 | 44 | 5 | 4 | 0 | 1 | −8 |
| 1 | 5 | 4 | 1 | 1 | −8 | 9 |
| 4 | 4 | 1 | 0 | −8 | 9 | −44 |
| 1 | 0 | 9 | −44 |
confirms , and . Check: .
Public key ; private key .
Step 3: encryption, , and step 4: check by decryption, , letter by letter:
| Letter | Letter | |||
|---|---|---|---|---|
| C | 3 | 36 | 3 | C |
| o | 15 | 30 | 15 | o |
| m | 13 | 4 | 13 | m |
| p | 16 | 52 | 16 | p |
| u | 21 | 60 | 21 | u |
| t | 20 | 56 | 20 | t |
| e | 5 | 20 | 5 | e |
| r | 18 | 3 | 18 | r |
Encryption in full by repeated squaring (write e as a sum of powers of 2, square and reduce mod 69, then multiply the powers needed):
Encrypt C: C = 35 mod 69
e = 5 = 4 + 1
31 = 3
32 = 9
34 = 92 = 81 mod 69 = 12
35 = 34 × 31 = 12 × 3
12 × 3 = 36
so C = 36
Decryption of one letter in full by repeated squaring:
Decrypt C = 36: M = 369 mod 69
d = 9 = 8 + 1
361 = 36
362 = 1296 mod 69 = 54
364 = 542 = 2916 mod 69 = 18
368 = 182 = 324 mod 69 = 48
369 = 368 × 361 = 48 × 36
48 × 36 = 1728 mod 69 = 3
so M = 3 = C
Answer: with the public key (5, 69), Computer encrypts to the ciphertext 36, 30, 4, 52, 60, 56, 20, 3 (written as numbers: a value above 26 has no letter). The private key (9, 69) decrypts it back to Computer.
2076 Chaitra · Q96 marksEncrypt the world HELLO using RSA algorithm. Also decrypt it by showing steps.
How this is readRead as “Encrypt the word HELLO”: the printed “world” is a slip for “word”.
Given: the word HELLO. Letters are numbered A = 1, B = 2, ..., Z = 26. Each letter is one block .
Step 1: key generation. Choose the primes and .
Choose : and . The data works: and are distinct primes, keeps every letter number below (so no two letters can share a ciphertext), and shares no factor with , so exists.
Step 2: private exponent , by the extended Euclidean algorithm. Start , , , ; each row , , ; stop when .
| 8 | 44 | 5 | 4 | 0 | 1 | −8 |
| 1 | 5 | 4 | 1 | 1 | −8 | 9 |
| 4 | 4 | 1 | 0 | −8 | 9 | −44 |
| 1 | 0 | 9 | −44 |
confirms , and . Check: .
Public key ; private key .
Step 3: encryption, , and step 4: decryption, , letter by letter:
| Letter | Letter | |||
|---|---|---|---|---|
| H | 8 | 62 | 8 | H |
| E | 5 | 20 | 5 | E |
| L | 12 | 18 | 12 | L |
| L | 12 | 18 | 12 | L |
| O | 15 | 30 | 15 | O |
Encryption in full by repeated squaring (write e as a sum of powers of 2, square and reduce mod 69, then multiply the powers needed):
Encrypt H: C = 85 mod 69
e = 5 = 4 + 1
81 = 8
82 = 64
84 = 642 = 4096 mod 69 = 25
85 = 84 × 81 = 25 × 8
25 × 8 = 200 mod 69 = 62
so C = 62
Decryption of every letter, step by step, by repeated squaring:
Decrypt C = 62: M = 629 mod 69
d = 9 = 8 + 1
621 = 62
622 = 3844 mod 69 = 49
624 = 492 = 2401 mod 69 = 55
628 = 552 = 3025 mod 69 = 58
629 = 628 × 621 = 58 × 62
58 × 62 = 3596 mod 69 = 8
so M = 8 = H
Decrypt C = 20: M = 209 mod 69
d = 9 = 8 + 1
201 = 20
202 = 400 mod 69 = 55
204 = 552 = 3025 mod 69 = 58
208 = 582 = 3364 mod 69 = 52
209 = 208 × 201 = 52 × 20
52 × 20 = 1040 mod 69 = 5
so M = 5 = E
Decrypt C = 18: M = 189 mod 69
d = 9 = 8 + 1
181 = 18
182 = 324 mod 69 = 48
184 = 482 = 2304 mod 69 = 27
188 = 272 = 729 mod 69 = 39
189 = 188 × 181 = 39 × 18
39 × 18 = 702 mod 69 = 12
so M = 12 = L
Decrypt C = 30: M = 309 mod 69
d = 9 = 8 + 1
301 = 30
302 = 900 mod 69 = 3
304 = 32 = 9
308 = 92 = 81 mod 69 = 12
309 = 308 × 301 = 12 × 30
12 × 30 = 360 mod 69 = 15
so M = 15 = O
Answer: with the public key (5, 69), HELLO encrypts to the ciphertext 62, 20, 18, 18, 30; decryption with the private key (9, 69) gives 8, 5, 12, 12, 15, the plaintext HELLO.
2076 Ashwin · Q96 marksEncrypt and decrypt “ROSE” using RSA algorithm.
Given: the word ROSE. Letters are numbered A = 1, B = 2, ..., Z = 26. Each letter is one block .
Step 1: key generation. Choose the primes and .
Choose : and . The data works: and are distinct primes, keeps every letter number below (so no two letters can share a ciphertext), and shares no factor with , so exists.
Step 2: private exponent , by the extended Euclidean algorithm. Start , , , ; each row , , ; stop when .
| 2 | 20 | 7 | 6 | 0 | 1 | −2 |
| 1 | 7 | 6 | 1 | 1 | −2 | 3 |
| 6 | 6 | 1 | 0 | −2 | 3 | −20 |
| 1 | 0 | 3 | −20 |
confirms , and . Check: .
Public key ; private key .
Step 3: encryption, , and step 4: decryption, , letter by letter:
| Letter | Letter | ||||
|---|---|---|---|---|---|
| R | 18 | 6 | 216 | 18 | R |
| O | 15 | 27 | 19683 | 15 | O |
| S | 19 | 13 | 2197 | 19 | S |
| E | 5 | 14 | 2744 | 5 | E |
Encryption in full by repeated squaring (write e as a sum of powers of 2, square and reduce mod 33, then multiply the powers needed):
Encrypt R: C = 187 mod 33
e = 7 = 4 + 2 + 1
181 = 18
182 = 324 mod 33 = 27
184 = 272 = 729 mod 33 = 3
187 = 184 × 182 × 181 = 3 × 27 × 18
3 × 27 = 81 mod 33 = 15
15 × 18 = 270 mod 33 = 6
so C = 6
Decryption of one letter in full by repeated squaring:
Decrypt C = 6: M = 63 mod 33
d = 3 = 2 + 1
61 = 6
62 = 36 mod 33 = 3
63 = 62 × 61 = 3 × 6
3 × 6 = 18
so M = 18 = R
Answer: with the public key (7, 33), ROSE encrypts to the ciphertext 6, 27, 13, 14; decryption with the private key (3, 33) gives 18, 15, 19, 5, the plaintext ROSE.
2075 Ashwin · Q96 marksEncrypt a message "network" using RSA algorithm.
Given: the word network, in lower case. Lower-case letters take the same numbers as capitals: a = 1, b = 2, ..., z = 26. Each letter is one block .
Step 1: key generation. Choose the primes and .
Choose : and . The data works: and are distinct primes, keeps every letter number below (so no two letters can share a ciphertext), and shares no factor with , so exists.
Step 2: private exponent , by the extended Euclidean algorithm. Start , , , ; each row , , ; stop when .
| 6 | 20 | 3 | 2 | 0 | 1 | −6 |
| 1 | 3 | 2 | 1 | 1 | −6 | 7 |
| 2 | 2 | 1 | 0 | −6 | 7 | −20 |
| 1 | 0 | 7 | −20 |
confirms , and . Check: .
Public key ; private key .
Step 3: encryption, , and step 4: check by decryption, , letter by letter:
| Letter | Letter | ||||
|---|---|---|---|---|---|
| n | 14 | 2744 | 5 | 14 | n |
| e | 5 | 125 | 26 | 5 | e |
| t | 20 | 8000 | 14 | 20 | t |
| w | 23 | 12167 | 23 | 23 | w |
| o | 15 | 3375 | 9 | 15 | o |
| r | 18 | 5832 | 24 | 18 | r |
| k | 11 | 1331 | 11 | 11 | k |
Decryption of one letter in full by repeated squaring, with d written as a sum of powers of 2:
Decrypt C = 5: M = 57 mod 33
d = 7 = 4 + 2 + 1
51 = 5
52 = 25
54 = 252 = 625 mod 33 = 31
57 = 54 × 52 × 51 = 31 × 25 × 5
31 × 25 = 775 mod 33 = 16
16 × 5 = 80 mod 33 = 14
so M = 14 = n
The letters w and k encrypt to their own numbers (23, 11): = , and = . Every RSA key has a few such fixed values; decryption still returns them, so this is no slip.
Answer: with the public key (3, 33), network encrypts to the ciphertext 5, 26, 14, 23, 9, 24, 11 (written as numbers: a value above 26 has no letter). The private key (7, 33) decrypts it back to network.
2073 Shrawan · Q85 marksExplain RSA algorithm with example.
Example: the word IOE. Letters are numbered A = 1, B = 2, ..., Z = 26. Each letter is one block .
IOE, for the Institute of Engineering, is encrypted and decrypted with the smallest comfortable key, and , through the four steps of RSA in order: key generation, the private exponent d, encryption, decryption.
Step 1: key generation. Choose the primes and .
Choose : and . The data works: and are distinct primes, keeps every letter number below (so no two letters can share a ciphertext), and shares no factor with , so exists.
Step 2: private exponent , by the extended Euclidean algorithm. Start , , , ; each row , , ; stop when .
| 6 | 20 | 3 | 2 | 0 | 1 | −6 |
| 1 | 3 | 2 | 1 | 1 | −6 | 7 |
| 2 | 2 | 1 | 0 | −6 | 7 | −20 |
| 1 | 0 | 7 | −20 |
confirms , and . Check: .
Public key ; private key .
Step 3: encryption, , and step 4: decryption, , letter by letter:
| Letter | Letter | ||||
|---|---|---|---|---|---|
| I | 9 | 729 | 3 | 9 | I |
| O | 15 | 3375 | 9 | 15 | O |
| E | 5 | 125 | 26 | 5 | E |
Decryption of one letter in full by repeated squaring, with d written as a sum of powers of 2:
Decrypt C = 3: M = 37 mod 33
d = 7 = 4 + 2 + 1
31 = 3
32 = 9
34 = 92 = 81 mod 33 = 15
37 = 34 × 32 × 31 = 15 × 9 × 3
15 × 9 = 135 mod 33 = 3
3 × 3 = 9
so M = 9 = I
Answer: with the public key (3, 33), IOE encrypts to the ciphertext 3, 9, 26; decryption with the private key (7, 33) gives 9, 15, 5, the plaintext IOE.
2072 Chaitra · Q98 marksEncrypt the word CAT using RSA algorithm, choose the suitable data for encryption by yourself according to RSA algorithm.
Given: the word CAT. Letters are numbered A = 1, B = 2, ..., Z = 26. Each letter is one block .
Data chosen, and why it is suitable:
- p = 3, q = 11: two different primes, small enough to work by hand.
- n = 33: above 26, so the 26 letter numbers are 26 different values below n. A smaller n fails: p = 3, q = 7 gives n = 21, and V = 22 would act as 22 − 21 = 1, the same block as A.
- e = 3: e must share no factor with = 20, so 2, 4, 5, 6, 8 and 10 all fail (6 is not a factor of 20, yet shares the factor 2); 3 is the smallest e that works.
- d = 7: follows from e by the extended Euclidean algorithm below.
Step 1: key generation. Choose the primes and .
Choose : and . The data works: and are distinct primes, keeps every letter number below (so no two letters can share a ciphertext), and shares no factor with , so exists.
Step 2: private exponent , by the extended Euclidean algorithm. Start , , , ; each row , , ; stop when .
| 6 | 20 | 3 | 2 | 0 | 1 | −6 |
| 1 | 3 | 2 | 1 | 1 | −6 | 7 |
| 2 | 2 | 1 | 0 | −6 | 7 | −20 |
| 1 | 0 | 7 | −20 |
confirms , and . Check: .
Public key ; private key .
Step 3: encryption, , and step 4: check by decryption, , letter by letter:
| Letter | Letter | ||||
|---|---|---|---|---|---|
| C | 3 | 27 | 27 | 3 | C |
| A | 1 | 1 | 1 | 1 | A |
| T | 20 | 8000 | 14 | 20 | T |
Decryption of one letter in full by repeated squaring, with d written as a sum of powers of 2:
Decrypt C = 27: M = 277 mod 33
d = 7 = 4 + 2 + 1
271 = 27
272 = 729 mod 33 = 3
274 = 32 = 9
277 = 274 × 272 × 271 = 9 × 3 × 27
9 × 3 = 27
27 × 27 = 729 mod 33 = 3
so M = 3 = C
The letter A encrypts to its own number (1): for any key. Every RSA key has a few such fixed values; decryption still returns them, so this is no slip.
Answer: with the public key (3, 33), CAT encrypts to the ciphertext 27, 1, 14 (written as numbers: a value above 26 has no letter). The private key (7, 33) decrypts it back to CAT.
2072 Kartik · Q96 marksEncrypt and decrypt "OVEL" message using RSA algorithm.
Given: the word OVEL. Letters are numbered A = 1, B = 2, ..., Z = 26. Each letter is one block .
Step 1: key generation. Choose the primes and .
Choose : and . The data works: and are distinct primes, keeps every letter number below (so no two letters can share a ciphertext), and shares no factor with , so exists.
Step 2: private exponent , by the extended Euclidean algorithm. Start , , , ; each row , , ; stop when .
| 10 | 32 | 3 | 2 | 0 | 1 | −10 |
| 1 | 3 | 2 | 1 | 1 | −10 | 11 |
| 2 | 2 | 1 | 0 | −10 | 11 | −32 |
| 1 | 0 | 11 | −32 |
confirms , and . Check: .
Public key ; private key .
Step 3: encryption, , and step 4: decryption, , letter by letter:
| Letter | Letter | ||||
|---|---|---|---|---|---|
| O | 15 | 3375 | 9 | 15 | O |
| V | 22 | 10648 | 40 | 22 | V |
| E | 5 | 125 | 23 | 5 | E |
| L | 12 | 1728 | 45 | 12 | L |
Decryption of one letter in full by repeated squaring, with d written as a sum of powers of 2:
Decrypt C = 40: M = 4011 mod 51
d = 11 = 8 + 2 + 1
401 = 40
402 = 1600 mod 51 = 19
404 = 192 = 361 mod 51 = 4
408 = 42 = 16
4011 = 408 × 402 × 401 = 16 × 19 × 40
16 × 19 = 304 mod 51 = 49
49 × 40 = 1960 mod 51 = 22
so M = 22 = V
Answer: with the public key (3, 51), OVEL encrypts to the ciphertext 9, 40, 23, 45; decryption with the private key (11, 51) gives 15, 22, 5, 12, the plaintext OVEL.
2068 Baishakh · Q96 marksEncrypt the message “DANGER” using RSA algorithm.
Given: the word DANGER. Letters are numbered A = 1, B = 2, ..., Z = 26. Each letter is one block .
Step 1: key generation. Choose the primes and .
Choose : and . The data works: and are distinct primes, keeps every letter number below (so no two letters can share a ciphertext), and shares no factor with , so exists.
Step 2: private exponent , by the extended Euclidean algorithm. Start , , , ; each row , , ; stop when .
| 6 | 20 | 3 | 2 | 0 | 1 | −6 |
| 1 | 3 | 2 | 1 | 1 | −6 | 7 |
| 2 | 2 | 1 | 0 | −6 | 7 | −20 |
| 1 | 0 | 7 | −20 |
confirms , and . Check: .
Public key ; private key .
Step 3: encryption, , and step 4: check by decryption, , letter by letter:
| Letter | Letter | ||||
|---|---|---|---|---|---|
| D | 4 | 64 | 31 | 4 | D |
| A | 1 | 1 | 1 | 1 | A |
| N | 14 | 2744 | 5 | 14 | N |
| G | 7 | 343 | 13 | 7 | G |
| E | 5 | 125 | 26 | 5 | E |
| R | 18 | 5832 | 24 | 18 | R |
Decryption of one letter in full by repeated squaring, with d written as a sum of powers of 2:
Decrypt C = 31: M = 317 mod 33
d = 7 = 4 + 2 + 1
311 = 31
312 = 961 mod 33 = 4
314 = 42 = 16
317 = 314 × 312 × 311 = 16 × 4 × 31
16 × 4 = 64 mod 33 = 31
31 × 31 = 961 mod 33 = 4
so M = 4 = D
The letter A encrypts to its own number (1): for any key. Every RSA key has a few such fixed values; decryption still returns them, so this is no slip.
Answer: with the public key (3, 33), DANGER encrypts to the ciphertext 31, 1, 5, 13, 26, 24 (written as numbers: a value above 26 has no letter). The private key (7, 33) decrypts it back to DANGER.
Insights on Computer Networks, p. 238Encrypt the plaintext “E” with RSA, taking p = 7, q = 11 and e = 13, and decrypt the result.
How this is readInsights (p. 238) sets the decryption up as m = 2637 mod 77 and stops there; evaluated below, it gives 5, the letter E. Its other numbers (n = 77, z = 60, its name for , e = 13, C = 26, d = 37) are right.
Given: the letter E. Letters are numbered A = 1, B = 2, ..., Z = 26. Each letter is one block .
Step 1: key generation. Given the primes , and .
Take : and . The data works: and are distinct primes, keeps every letter number below (so no two letters can share a ciphertext), and shares no factor with , so exists.
Step 2: private exponent , by the extended Euclidean algorithm. Start , , , ; each row , , ; stop when .
| 4 | 60 | 13 | 8 | 0 | 1 | −4 |
| 1 | 13 | 8 | 5 | 1 | −4 | 5 |
| 1 | 8 | 5 | 3 | −4 | 5 | −9 |
| 1 | 5 | 3 | 2 | 5 | −9 | 14 |
| 1 | 3 | 2 | 1 | −9 | 14 | −23 |
| 2 | 2 | 1 | 0 | 14 | −23 | 60 |
| 1 | 0 | −23 | 60 |
confirms , and = . Check: .
Public key ; private key .
Step 3: encryption, , and step 4: decryption, , letter by letter:
| Letter | Letter | |||
|---|---|---|---|---|
| E | 5 | 26 | 5 | E |
Encryption in full by repeated squaring (write e as a sum of powers of 2, square and reduce mod 77, then multiply the powers needed):
Encrypt E: C = 513 mod 77
e = 13 = 8 + 4 + 1
51 = 5
52 = 25
54 = 252 = 625 mod 77 = 9
58 = 92 = 81 mod 77 = 4
513 = 58 × 54 × 51 = 4 × 9 × 5
4 × 9 = 36
36 × 5 = 180 mod 77 = 26
so C = 26
Decryption of one letter in full by repeated squaring:
Decrypt C = 26: M = 2637 mod 77
d = 37 = 32 + 4 + 1
261 = 26
262 = 676 mod 77 = 60
264 = 602 = 3600 mod 77 = 58
268 = 582 = 3364 mod 77 = 53
2616 = 532 = 2809 mod 77 = 37
2632 = 372 = 1369 mod 77 = 60
2637 = 2632 × 264 × 261 = 60 × 58 × 26
60 × 58 = 3480 mod 77 = 15
15 × 26 = 390 mod 77 = 5
so M = 5 = E
Answer: with the public key (13, 77), E encrypts to the ciphertext 26; decryption with the private key (37, 77) gives 5, the plaintext E.
AES-128 on a word: one block, ten rounds PIN 2/27
Ch 8 · Network security2 from 2 of the 27 sittings
- Bytes: write the word in ASCII (hex) and pad it to one 16-byte block by PKCS#7: when k bytes are missing, append k bytes, each of value k.
- State: fill a 4 × 4 byte matrix column by column (bytes 0 to 3 form column 0); the 16-byte key the same way.
- Key expansion: the key gives the words to ; then , except that for every fourth word first goes through g: RotWord (one byte left), SubWord (S-box on each byte), XOR Rcon (01, 02, 04, 08, 10, 20, 40, 80, 1b, 36 in the first byte). Words to are round key : 11 keys.
- Round 0: AddRoundKey, the state XOR .
- Rounds 1 to 9, four steps each: SubBytes (each byte from the S-box: row = first hex digit, column = second); ShiftRows (row r rotated r bytes left); MixColumns (each column times the matrix 02 03 01 01 / 01 02 03 01 / 01 01 02 03 / 03 01 01 02 in , adding by XOR; 02·x is a left shift, XOR 1b when a 1 falls off the top; 03·x = 02·x XOR x); AddRoundKey with .
- Round 10: SubBytes, ShiftRows, AddRoundKey with ; no MixColumns.
- Ciphertext: the final state read column by column, 16 bytes (32 hex digits). Decryption runs the inverse steps in reverse order with the same key.
2082 Baishakh · Q96 marksEncrypt the word “ISPNet” using anyone suitable AES technique.
How this is read“Anyone suitable AES technique” is read as AES-128 (16-byte key, 10 rounds) in ECB mode on one 16-byte block, with a chosen key (any 16-character key serves).
Given: the word ISPNet, 6 characters. Technique: AES-128 (128-bit key, 10 rounds) on one 16-byte block, ECB mode.
Step 1: plaintext block. ASCII codes in hex: I = 49, S = 53, P = 50, N = 4e, e = 65, t = 74. PKCS#7 padding fills the block with 16 − 6 = 10 bytes, each of value 10 = 0a:
49 53 50 4e 65 74 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a
Step 2: key (chosen): the 16 characters Pulchowk Campus!, in hex:
50 75 6c 63 68 6f 77 6b 20 43 61 6d 70 75 73 21
Step 3: state matrices. The 16 bytes fill a 4 × 4 matrix column by column (bytes 0 to 3 are column 0); the key the same way, as round key :
Plaintext Key = K0 49 65 0a 0a 50 68 20 70 53 74 0a 0a 75 6f 43 75 50 0a 0a 0a 6c 77 61 73 4e 0a 0a 0a 63 6b 6d 21
Step 4: key expansion. The key columns are the words to . Every fourth word is , g = RotWord, SubWord, XOR Rcon; the others are . Round key ( to ):
w3 70 75 73 21 RotWord(w3) 75 73 21 70 SubWord 9d 8f fd 51 Rcon(1) 01 00 00 00 g(w3) 9c 8f fd 51 w0 50 75 6c 63 w4 = w0 XOR g cc fa 91 32 w5 = w4 XOR w1 a4 95 e6 59 w6 = w5 XOR w2 84 d6 87 34 w7 = w6 XOR w3 f4 a3 f4 15
All eleven round keys, computed the same way (four words each):
K0 50756c63 686f776b 2043616d 70757321 K1 ccfa9132 a495e659 84d68734 f4a3f415 K2 c445c88d 60d02ed4 e406a9e0 10a55df5 K3 c6092e47 a6d90093 42dfa973 527af486 K4 14b66a47 b26f6ad4 f0b0c3a7 a2ca3721 K5 702c977d c243fda9 32f33e0e 9039092f K6 422d821d 806e7fb4 b29d41ba 22a44895 K7 4b7fa88e cb11d73a 798c9680 5b28de15 K8 ff62f1b7 3473268d 4dffb00d 16d76e18 K9 eafd5cf0 de8e7a7d 9371ca70 85a6a468 K10 f8b41967 263a631a b54ba96a 30ed0d02
Step 5: round 0, AddRoundKey: the state XOR , byte by byte (first byte: 49 XOR 50 = 0100 1001 XOR 0101 0000 = 0001 1001 = 19):
Plaintext K0 After round 0 49 65 0a 0a 50 68 20 70 19 0d 2a 7a 53 74 0a 0a 75 6f 43 75 26 1b 49 7f 50 0a 0a 0a 6c 77 61 73 3c 7d 6b 79 4e 0a 0a 0a 63 6b 6d 21 2d 61 67 2b
Step 6: round 1. SubBytes replaces every byte from the S-box (row = first hex digit, column = second; S(19) = d4). ShiftRows rotates row r by r bytes to the left (row 0 stays):
After round 0 SubBytes ShiftRows 19 0d 2a 7a d4 d7 e5 da d4 d7 e5 da 26 1b 49 7f f7 af 3b d2 af 3b d2 f7 3c 7d 6b 79 eb ff 7f b6 7f b6 eb ff 2d 61 67 2b d8 ef 85 f1 f1 d8 ef 85
MixColumns multiplies each column by the fixed matrix (rows 02 03 01 01, 01 02 03 01, 01 01 02 03, 03 01 01 02) in , adding by XOR. 02·x shifts x one bit left and XORs 1b when a 1 falls off the top (02·d4: 1101 0100 becomes 1010 1000 = a8, XOR 1b = b3); 03·x = 02·x XOR x. Column 0 in full:
byte a 02·a 03·a a0 d4 b3 67 a1 af 45 ea a2 7f fe 81 a3 f1 f9 08 b0 = 02·a0 XOR 03·a1 XOR a2 XOR a3 = b3 XOR ea XOR 7f XOR f1 = d7 b1 = a0 XOR 02·a1 XOR 03·a2 XOR a3 = d4 XOR 45 XOR 81 XOR f1 = e1 b2 = a0 XOR a1 XOR 02·a2 XOR 03·a3 = d4 XOR af XOR fe XOR 08 = 8d b3 = 03·a0 XOR a1 XOR a2 XOR 02·a3 = 67 XOR af XOR 7f XOR f9 = 4e
The other three columns the same way; then AddRoundKey with :
MixColumns K1 After round 1 d7 96 b8 d7 cc a4 84 f4 1b 32 3c 23 e1 b8 93 b0 fa 95 d6 a3 1b 2d 45 13 8d e8 d0 5c 91 e6 87 f4 1c 0e 57 a8 4e 44 c8 6c 32 59 34 15 7c 1d fc 79
Step 7: rounds 2 to 10. Rounds 2 to 9 repeat the same four steps (SubBytes, ShiftRows, MixColumns, AddRoundKey with to ); round 10 leaves out MixColumns and adds . Computed, the state at the end of each round (read column by column) is:
Round 0 19263c2d 0d1b7d61 2a496b67 7a7f792b Round 1 1b1b1c7c 322d0e1d 3c4557fc 2313a879 Round 2 1f1ac893 4662cc3d 960ceb74 ad9052e0 Round 3 b047b586 d7b8db20 168bfb1e 47fff8f4 Round 4 c5272573 ec9c1732 2608e1d8 c993c827 Round 5 6af24b29 7241423d a4c50ea9 ef0d40ad Round 6 e641ea02 5dc77f8a d688cb4b f8d528f7 Round 7 6a2f660e 47e5aef0 7290f4f9 26aa6dfa Round 8 193e388d 58fc7867 9d25b551 a1a4efc2 Round 9 6213e6b8 c9bd6d99 763147cd 41e52f89 Round 10 52ceb9c0 fbfd7676 8d922784 b39031bf
Answer: with the key Pulchowk Campus!, ISPNet (padded to 16 bytes) encrypts under AES-128 to the ciphertext 52ceb9c0fbfd76768d922784b39031bf (hex). Decryption with the same key (InvShiftRows, InvSubBytes, AddRoundKey, InvMixColumns, rounds in reverse) returns the padded block, and so the word ISPNet.
2081 Bhadra · Q96 marksEncrypt the word “ComNet” using anyone suitable AES technique.
How this is read“Anyone suitable AES technique” is read as AES-128 (16-byte key, 10 rounds) in ECB mode on one 16-byte block, with a chosen key (any 16-character key serves).
Given: the word ComNet, 6 characters. Technique: AES-128 (128-bit key, 10 rounds) on one 16-byte block, ECB mode.
Step 1: plaintext block. ASCII codes in hex: C = 43, o = 6f, m = 6d, N = 4e, e = 65, t = 74. PKCS#7 padding fills the block with 16 − 6 = 10 bytes, each of value 10 = 0a:
43 6f 6d 4e 65 74 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a
Step 2: key (chosen): the 16 characters Pulchowk Campus!, in hex:
50 75 6c 63 68 6f 77 6b 20 43 61 6d 70 75 73 21
Step 3: state matrices. The 16 bytes fill a 4 × 4 matrix column by column (bytes 0 to 3 are column 0); the key the same way, as round key :
Plaintext Key = K0 43 65 0a 0a 50 68 20 70 6f 74 0a 0a 75 6f 43 75 6d 0a 0a 0a 6c 77 61 73 4e 0a 0a 0a 63 6b 6d 21
Step 4: key expansion. The key columns are the words to . Every fourth word is , g = RotWord, SubWord, XOR Rcon; the others are . Round key ( to ):
w3 70 75 73 21 RotWord(w3) 75 73 21 70 SubWord 9d 8f fd 51 Rcon(1) 01 00 00 00 g(w3) 9c 8f fd 51 w0 50 75 6c 63 w4 = w0 XOR g cc fa 91 32 w5 = w4 XOR w1 a4 95 e6 59 w6 = w5 XOR w2 84 d6 87 34 w7 = w6 XOR w3 f4 a3 f4 15
All eleven round keys, computed the same way (four words each):
K0 50756c63 686f776b 2043616d 70757321 K1 ccfa9132 a495e659 84d68734 f4a3f415 K2 c445c88d 60d02ed4 e406a9e0 10a55df5 K3 c6092e47 a6d90093 42dfa973 527af486 K4 14b66a47 b26f6ad4 f0b0c3a7 a2ca3721 K5 702c977d c243fda9 32f33e0e 9039092f K6 422d821d 806e7fb4 b29d41ba 22a44895 K7 4b7fa88e cb11d73a 798c9680 5b28de15 K8 ff62f1b7 3473268d 4dffb00d 16d76e18 K9 eafd5cf0 de8e7a7d 9371ca70 85a6a468 K10 f8b41967 263a631a b54ba96a 30ed0d02
Step 5: round 0, AddRoundKey: the state XOR , byte by byte (first byte: 43 XOR 50 = 0100 0011 XOR 0101 0000 = 0001 0011 = 13):
Plaintext K0 After round 0 43 65 0a 0a 50 68 20 70 13 0d 2a 7a 6f 74 0a 0a 75 6f 43 75 1a 1b 49 7f 6d 0a 0a 0a 6c 77 61 73 01 7d 6b 79 4e 0a 0a 0a 63 6b 6d 21 2d 61 67 2b
Step 6: round 1. SubBytes replaces every byte from the S-box (row = first hex digit, column = second; S(13) = 7d). ShiftRows rotates row r by r bytes to the left (row 0 stays):
After round 0 SubBytes ShiftRows 13 0d 2a 7a 7d d7 e5 da 7d d7 e5 da 1a 1b 49 7f a2 af 3b d2 af 3b d2 a2 01 7d 6b 79 7c ff 7f b6 7f b6 7c ff 2d 61 67 2b d8 ef 85 f1 f1 d8 ef 85
MixColumns multiplies each column by the fixed matrix (rows 02 03 01 01, 01 02 03 01, 01 01 02 03, 03 01 01 02) in , adding by XOR. 02·x shifts x one bit left and XORs 1b when a 1 falls off the top (02·af: 1010 1111 becomes 0101 1110 = 5e, XOR 1b = 45); 03·x = 02·x XOR x. Column 0 in full:
byte a 02·a 03·a a0 7d fa 87 a1 af 45 ea a2 7f fe 81 a3 f1 f9 08 b0 = 02·a0 XOR 03·a1 XOR a2 XOR a3 = fa XOR ea XOR 7f XOR f1 = 9e b1 = a0 XOR 02·a1 XOR 03·a2 XOR a3 = 7d XOR 45 XOR 81 XOR f1 = 48 b2 = a0 XOR a1 XOR 02·a2 XOR 03·a3 = 7d XOR af XOR fe XOR 08 = 24 b3 = 03·a0 XOR a1 XOR a2 XOR 02·a3 = 87 XOR af XOR 7f XOR f9 = ae
The other three columns the same way; then AddRoundKey with :
MixColumns K1 After round 1 9e 96 2f 28 cc a4 84 f4 52 32 ab dc 48 b8 31 1a fa 95 d6 a3 b2 2d e7 b9 24 e8 e5 09 91 e6 87 f4 b5 0e 62 fd ae 44 5f 39 32 59 34 15 9c 1d 6b 2c
Step 7: rounds 2 to 10. Rounds 2 to 9 repeat the same four steps (SubBytes, ShiftRows, MixColumns, AddRoundKey with to ); round 10 leaves out MixColumns and adds . Computed, the state at the end of each round (read column by column) is:
Round 0 131a012d 0d1b7d61 2a496b67 7a7f792b Round 1 52b2b59c 322d0e1d abe7626b dcb9fd2c Round 2 6c7acc1d 0be248d6 ab08db96 8ad42006 Round 3 03cd3e48 b3f4993a e3061421 19cd5fb7 Round 4 6b14a1c6 44c41b67 3c8d8b80 deab85f4 Round 5 289354b8 30f4493d ee0f4769 ddece7dc Round 6 d601c349 ea4d8a82 ac758e62 067233c3 Round 7 b551fd29 9ad21d80 bdfc2e60 d597d4e9 Round 8 a58bd16b 79cd4af7 a3bfa6de 0c4a84d3 Round 9 789005af 91b6fb15 b0e6d256 ee5ef7a0 Round 10 44faac87 a7b40b63 5213c233 188d02b3
Answer: with the key Pulchowk Campus!, ComNet (padded to 16 bytes) encrypts under AES-128 to the ciphertext 44faac87a7b40b635213c233188d02b3 (hex). Decryption with the same key (InvShiftRows, InvSubBytes, AddRoundKey, InvMixColumns, rounds in reverse) returns the padded block, and so the word ComNet.
Classical ciphers: Caesar, monoalphabetic, polyalphabetic BOOK
Ch 8 · Network securitynot set by a paper yet, 3 from the book
- Caesar: number the letters a = 0 to z = 25 and move each one k places on, wrapping z round to a: ; decryption . There are only 25 useful keys, so trying them all breaks it.
- Monoalphabetic: a fixed table gives every plaintext letter its own ciphertext letter (any rearrangement of the alphabet, 26! keys). Encrypt by looking each letter up, decrypt by the reverse lookup; letter frequencies still show through.
- Polyalphabetic: several Caesar (or monoalphabetic) ciphers used in turn by the position of the letter, for example C1, C2, C1 repeating, so one plaintext letter encrypts to different letters at different places.
- Spaces are kept and are not counted as positions; capital and lower case are treated alike.
Insights on Computer Networks, p. 231Using the Caesar cipher with key k = 2, encrypt the plaintext “I am a student”.
How this is readInsights (p. 231) prints the answer as “k co c UV FG PV”: the w that u becomes is missing. The full ciphertext is k co c uvwfgpv. Its rule says k places “behind” the letter; the shift runs forward (i to k), as its own example shows.
Given: plaintext I am a student, Caesar cipher with key k = 2: each letter moves 2 places on in the alphabet (y becomes a and z becomes b); spaces stay, and case is ignored.
Encryption, , letter by letter:
| Plaintext | i | a | m | a | s | t | u | d | e | n | t |
|---|---|---|---|---|---|---|---|---|---|---|---|
| Number (a = 0) | 8 | 0 | 12 | 0 | 18 | 19 | 20 | 3 | 4 | 13 | 19 |
| + 2, mod 26 | 10 | 2 | 14 | 2 | 20 | 21 | 22 | 5 | 6 | 15 | 21 |
| Ciphertext | k | c | o | c | u | v | w | f | g | p | v |
Decryption moves every letter 2 places back, , and returns i am a student. Only 25 useful keys exist, so trying each one breaks the cipher at once.
Answer: k co c uvwfgpv.
Insights on Computer Networks, p. 231Encrypt the plaintext “attack” with the monoalphabetic key as printed: plaintext abcdefghijklmnopqrstuvwxyz, ciphertext mnbvcxzasdfghjkipoiuytrewq.
How this is readInsights (p. 231) prints the answer QZZQEA. That is what the keyboard key qwertyuiopasdfghjklzxcvbnm gives (a to q, t to z, c to e, k to a), not the key printed above it, which gives muumbf. The printed key also has i twice (16th and 19th places) and no l, so two letters would decrypt alike; with l in the 16th place it is a true key, and attack still gives muumbf.
Given: the monoalphabetic key (each plaintext letter above its ciphertext letter, with l in the 16th place) and the plaintext attack:
plain a b c d e f g h i j k l m cipher m n b v c x z a s d f g h plain n o p q r s t u v w x y z cipher j k l p o i u y t r e w q
Encryption looks each letter up: a → m, t → u, t → u, a → m, c → b, k → f.
Decryption is the reverse lookup: m → a, u → t, b → c, f → k. There are 26! keys, far too many to try, yet letter frequencies (e is the commonest letter in English) still break it.
Answer: muumbf.
Insights on Computer Networks, p. 231Encrypt “I am a student” with two Caesar ciphers, C1 (k = 2) and C2 (k = 5), used in the repeating pattern C1, C2, C1.
Given: plaintext I am a student; C1 is a Caesar cipher with k = 2, C2 one with k = 5, used in the repeating pattern C1, C2, C1 over the letters (spaces skipped).
| Plaintext | i | a | m | a | s | t | u | d | e | n | t |
|---|---|---|---|---|---|---|---|---|---|---|---|
| Position | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 |
| Cipher | C1 | C2 | C1 | C1 | C2 | C1 | C1 | C2 | C1 | C1 | C2 |
| Shift | +2 | +5 | +2 | +2 | +5 | +2 | +2 | +5 | +2 | +2 | +5 |
| Ciphertext | k | f | o | c | x | v | w | i | g | p | y |
The two a’s encrypt differently (f at position 2, c at position 4), which is what defeats simple letter counting. Decryption needs both keys and the pattern.
Answer: k fo c xvwigpy, as Insights gives it.
Diffie-Hellman key exchange BOOK
Ch 8 · Network securitynot set by a paper yet, 1 from the book
- Public values: a large prime N (ideally with also prime) and a base G that is a primitive root modulo N: its powers take every value 1 to .
- A picks a secret x and sends .
- B picks a secret y and sends .
- A computes ; B computes .
- Both now hold , the shared symmetric key. An eavesdropper sees N, G, and , but finding x or y from them is the discrete logarithm problem.
Insights on Computer Networks, p. 240Diffie-Hellman with N = 23 and G = 7: A chooses x = 3 and B chooses y = 6. Find R1, R2 and the shared key K.
How this is readInsights (p. 239) asks for G to be a prime number. The condition is that G is a primitive root modulo N: 7 is one for N = 23, while the prime 2 is not (211 mod 23 = 1, so its powers take only 11 values). The arithmetic of the example is right.
Given: N = 23 (a prime, and is prime too), G = 7; A's secret x = 3, B's secret y = 6.
Step 1, A: = = . A sends 21 to B.
Step 2, B: by repeated squaring:
y = 6 = 4 + 2
71 = 7
72 = 49 mod 23 = 3
74 = 32 = 9
76 = 74 × 72 = 9 × 3
9 × 3 = 27 mod 23 = 4
So . B sends 4 to A.
Step 3, A: = = .
Step 4, B: = :
y = 6 = 4 + 2
211 = 21
212 = 441 mod 23 = 4
214 = 42 = 16
216 = 214 × 212 = 16 × 4
16 × 4 = 64 mod 23 = 18
Check: = . The base is sound: 7 is a primitive root modulo 23, since and , neither 1, so its powers run through all 22 values.
Answer: , , and both sides compute the same shared key K = 18.
Every question the papers asked · 27 sittings · 2066 Bhadra to 2082 Bhadra
The complete question bank
All 269 questions of the 27 sittings, reproduced verbatim: only what a paper has actually asked. Read them by paper, newest first, or by chapter, where repeats are merged and counted. Every question links to its written answer and to the card that teaches it.
How to use the bank
- By paper: sit a paper from the top, then open each answer. The board papers, 2081 and 2082 Bhadra, are the best guide to the next one.
- By chapter: revise a chapter, then answer its questions. A question set in several sittings appears once, with how many times and when, and every other wording under it.
- Answer links open the exact answer to write; Study links open the card that teaches the topic. A question with two answer links has two parts.
Regular2082 Bhadra
2082 Bhadra · Regular · BCT · 10 questions
Q1. Define protocol with examples. Why do we have layered architecture in networks? Differentiate between TCP/IP and OSI model.
Q2. Explain line of sight (LOS) propagation modes. Draw block diagram generic optical fiber (OF) communication system and its RF range.
Q3. Write different ways to correct backward error correction. Compare pure Aloha and slotted Aloha mentioning the condition for no collision.
Q4. What are routing protocols? Explain open short path first (OSPF) process in link state routing.
Q5. Suppose a company XYZ has an IP address of 160.24.96.0/21 and it has 6 departments containing 1024, 750, 254, 500, 151 and 45 users and also include point-point links. List out the CIDR, network address, broadcast address, usable host range and wasted IP address in each subnet.
Q6. Write UDP header field and functions. Explain TCP 3-way hand shaking for connection establishment and release.
Q7. Compare DNS recursive query vs. iterative query. Explain iterative query for browsing www.youtube.com
Q8. List the IPv6 extension headers in order. Explain ISATAP and 6 to 4 tunneling with their address format for IPv4 to IPv6 transition.
Q9. What do you mean by firewall? Encrypt and decrypt the “attack” using RSA.
Q10. Write short notes on: (Any Two) a) ARP and NDP b) AH and ESP c) VPN d) vLAN
Back2082 Baishakh
2082 Baishakh · Back · BCT · 10 questions
Q1. Explain client/server and P2P network model with their advantages and disadvantages. Discuss the layer of TCP/IP model with suitable diagram.
Q2. What are the functions of data link layer? How to detect signal collision in CSMA/CD? List the ethernet cable specification standards for 802.3 ethernet standards.
Q3. What is hamming distance? How do you apply it in data link layer error control mechanism? Calculate the CRC for a 8 bit sequence 11001101. The generator polynomial is x⁴ + x² + 1. Also find the transmitted bit frame.
Q4. Define routed and routing protocol. Explain RIP routing operation with is timer details.
Q5. List the range of IPv4 address classes. You have to assign addresses to four departmental LANs with following hosts 14, 55, 10 and 29 addresses respectively from the given IP address block: 202.97.43.0/25. Perform the subnetting and find out subnet mask, network address, broadcast address and usable host IP ranges.
Q6. Discuss UDP header and compare it with TCP. What is port address? Explain briefly about leaky-bucket algorithm used for traffic shaping.
Q7. How does a DNS recursive query work? Discuss DHCP lease renew process with example diagram.
Q8. Map IPv4 addresses with its IPv6 equivalent. What are the latest best IPv6 transition methodologies? Explain anyone of them.
Q9. What is router ACL? How do you apply ACL to block the IP network 202.70.91.0/24 incoming to interface Fast Ethernet of a router? Encrypt the word “ISPNet” using anyone suitable AES technique.
Q10. Write Short Notes on: (Any Two) a) 802.5 Token Ring b) PGP c) Socket programming fundamentals d) X.25 Network
Regular2081 Bhadra
2081 Bhadra · Regular · BCT · 10 questions
Q1. Define Network. List a function of each layer of OSI reference model and compare it with TCPI/IP model.
Q2. What are the factors to be considered while selecting media for communication? Differentiate between datagram and virtual circuit switching approach with respect to Frame Relay Network.
Q3. What is piggy-backing? How do you apply it in data link layer flow control mechanism? Calculate the CRC for a 10 bit sequence 1010001101. The generator polynomial is x⁵ + x⁴ + x² + 1. Also find the transmitted bit frame.
Q4. What is adaptive and non-adaptive routing? List the properties of link state routing and mention the method that how Designated Router (DR) is elected in OSPF routing.
Q5. What is super-netting? Perform the subnetting of IPv4 address block 200.74.20.0/24 for five different departments having 4, 54, 120, 12 and 30 hosts. List out the network address, broadcast address, usable host range and wasted IP address in each subnet.
Q6. Why TCP is known as reliable protocol? What are the congestion control techniques applied in network communication? Discuss Token Bucket approach and compare it with leaky bucket.
Q7. What do you mean by DNS delegation? List the step-by-step working principle of SMTP.
Q8. Critically compare IPv4 and IPv6 in terms of routing and head manipulation. Explain the importance and implementation approach of 6RD for IPv6 based services on the existing IPv4 networking.
Q9. What are the fundamental difference between AES and DES? Encrypt the word “ComNet” using anyone suitable AES technique.
Q10. Write Short notes on: (Any Two) a) 802.4 Token Bus b) Framing with bit stuffing c) Server Socket programming for bind, listen and accept d) ATM
Back2081 Baishakh
2081 Baishakh · Back · BCT · 10 questions
Q1. What is a protocol? List out the common protocols used at each layer of TCP/IP model. Differentiate between client-server is P2P network.
Q2. List out the most common guided and unguided transmission media used in computer networks now a days. Explain any one of the guided transmission media with examples.
Q3. What is CSMA/CD? Why is it not applicable in wireless LAN? What are the techniques used to avoid the possible collisions in WLAN? Explain.
Q4. In which case VLSM is used while dividing the given block of IP addresses for different subnets and why? Suppose your company has IP address block of 16.16.16.0/21. Divide this IP address for five different departments of the company equally. List out the network address, broadcast address, subnet mask and usable IP address range for each subnet.
Q5. What is ICMP? Explain the importance and uses of ICMP in TCP/IP protocol suit.
Q6. Though UDP is said to be unreliable protocol, it is used in Internet. Why? Explain the three way handshake principle of a TCP connection between client and server.
Q7. What is a proxy server? Why is it used? Discuss briefly on HTTP and HTTPS services.
Q8. Compare the IPv4 header with IPv6 header. Explain the dual stack strategy to transit from IPv4 to IPv6.
Q9. What is public key cryptography? Encrypt the word "security" using the RSA algorithm. Also show the decryption to obtain the plaintext.
Q10. Write short notes on: (Any Two) a) MAC sublayer b) Digital signature c) Firewall
Regular2080 Bhadra
2080 Bhadra · Regular · BCT · 10 questions
Q1. Differentiate between Client Server and Peer to Peer architecture. Discuss the functions of each layer of Open System Interconnection (OSI) model.
Q2. a) Discuss about the different factors of choosing the transmission media." Circuit switching is suitable for real-time communication", give your reasons. If a file of 1000 bytes was sent over a network in 2 seconds, calculate throughput.
Q3. Explain how does CRC detect the errors. Given message is M (x) = x7 + x4 +x3 +x2 + 1 and the generator is G (x) = x3 + 1. Show the actual bit string transmitted, suppose the third bit from the left is inverted during the transmission. Show how the error is detected at the receiver's end.
Q4. Suppose a company has IP address of 10.20.30.0/24 and it has 4 LANs containing 4,64,24,18 number of hosts. Also, there are 4 WAN links to connect LAN1 - LAN2, LAN2 - LAN3, LAN3 - LAN4 and LAN1 - LAN3. List out the subnet wasted IP addresses for each LAN.
Q5. What is DR and BDR in OSPF? How do OSPF routers come into fully adacency states? Explain.
Q6. How does the transport layer ensure that the complete message arrive at the destination and in the proper order? How does Token Bucket control the congestion over the Leaky Bucket algorithm?
Q7. How does an FTP client connect to an FTP server? Compare POP3 and IMAP protocols.
Q8. Explain the three address types in IPv6 with the IP notations. How does on IPv6 machine acquire IPv6 address automatically?
Q9. What are the properties of secure communication? Use RSA algorithm to encrypt and decrypt the message "network".
Q10. Write short notes on: (Any Two) a) Go Back-N ARQ b) Dual Stack method in IPv6 c) Diffie-Hellman algorithm d) ATM
Back2080 Baishakh
2080 Baishakh · Back · BCT · 10 questions
Q1. Why do we need layered architecture in computer network? Discuss the function of each layer of TCP/IP networking model.
Q2. What is multiplexing? What is its importance in communication? Explain different types of multiplexing techniques.
Q3. What is a bridge? How does it work? How can a bridge increase the throughout as compared with a repeater while extending a LAN? Explain with suitable diagrams.
Q4. What is unicast and multicast? Compare distance vector routing protocol and link state routing protocol with examples.
Q5. Suppose a company has IP address of 200.80.40.0/24 with 5 departments containing 29, 5, 16, 43, 14, number of hosts. Also there are point to point links between the departments. List out the subnet mask, network address, broadcast address, usable host IP ranges and no. of wasted IP addresses for each subnet.
Q6. What is port number? Why is it necessary to standardize the port numbers for well-known servers? What happens when a web service is hosted at some different port such as 8765 instead of 80? Explain.
Q7. What is DNS server? Explain the recursive and iterative query.
Q8. What are the advantages of IPv6? Briefly explain the different transition strategies.
Q9. What is PGP? Use RSA algorithm to encrypt/decrypt the word COW.
Q10. Write short notes on: (Any Two) a) VLAN b) ARP c) IPSec
Regular2079 Bhadra
2079 Bhadra · Regular · BCT · 10 questions
Q1. Compare the OSI reference model and TCP/IP reference model mentioning their similarities and differences.
Q2. What is switching and multiplexing? Explain switching technique used in modern computer networks.
Q3. How CSMA/CD works? Describe Ethernet (IEEE 802.3) frame structure with function of each field.
Q4. Why do we prefer a switch as networking device instead of Hub for LAN connection? Give reasons. Discuss the characteristics of a good routing algorithm.
Q5. An ISP provided you an IP address block of 172.24.96.0/21. Suppose you need to divide this for four different departments A, B, C and D having 750, 200, 500 and 45 hosts respectively with minimum wastage of IP addresses. Also allocate IP addresses for three point-to-point links in the network. Find out the network address, broadcast address, subnet mash and usable host range of IP addresses for each subnet.
Q6. What are the features of UDP protocol? In which case is UDP preferred as a transport layer protocol? Discuss with practical examples.
Q7. What is DNS? Why is it used? How is the DNS request from a client computer resolved from the authoritative server? Explain with necessary diagrams.
Q8. What are the problems of IPV4? How can IPV6 reduce these problems? Explain header translation mechanism for transition from IPV4 to IPV6.
Q9. What is a digital signature? Encrypt the message "PANDEMIC" using RSA algorithm. Also obtain the plaintext from the ciphertext.
Q10. Write short notes on: (Any Two) a) ALOHA b) OSPF c) VPN
Regular2078 Bhadra
2078 Bhadra · Regular · BCT · 10 questions
Q1. How does the client-server model work? Differentiate it with peer-to-peer network with advantages and disadvantages.
Q2. Define Throughput. A network with bandwidth of 20 Mbps can pass only an average of 18,000 frames per minute with each frame carrying an average of 20,000 bits. Calculate the throughput of this network. Differentiate between Packet switching and Virtual Circuit switching.
Q3. Explain Go-back-N ARQ and selective Repeat ARQ with example. How carrier sense multiple access with collision detection (CSMA/CD) is better than CSMA?
Q4. Consider IP block of 202.50.0.0/24 and six departments with 125, 59, 27, 14, 4 and 2 hosts respectively. Perform the subnetting so that wastage of IP addresses is minimum and find out the subnet mask, network address, broadcast address, wasted IP addresses and usable host ranges in each network.
Q5. Define routing algorithm. List out the properties/goals of routing algorithm. What is link state routing algorithm? Show how routing tables is populated in LSR with example.
Q6. What are services provided by Transport layer? Explain about Leaky-Bucket algorithm for congestion control?
Q7. What are resource records in DNS? Explain the types of DNS queries with example.
Q8. List advantages of IPv6 over IPv4. Explain any two suitable transition strategies for IPv4 to IPv6.
Q9. Write down the steps involved in RSA encryption algorithm. Encrypt the word "Computer" using RSA algorithm.
Q10. Write short notes on: (Any Two) a) Frame relay b) TCP sliding window c) HDLC
Regular2076 Chaitra
2076 Chaitra · Regular · BCT · 10 questions
Q1. What is protocol? What are the reasons for using layered network architecture? Compare OSI with TCP/IP reference model.
Q2. What is transmission medium? Explain different transmission medium with their merits and demerits.
Q3. What is collision? How is it occured? How the possibility of collision is reduced in IEEE 802.3 and IEEE 802.11? Explain.
Q4. Suppose your company has leased the IP address of 222.70.94.0/24 from your ISP. Divide it far five different departments containing 50, 30, 25, 12, 10 no of hosts. There are also two points to point links far interconnection between routers. List out the network address, broadcast address, usable IP address range and subnet mask for each subnet. Also mention the unused range of IP addresses.
Q5. What is the purpose of Time to live (TTL) and protocol field in header of IPv4 datagram. Which protocol is used in internet layer to provide feedback to hosts/routers about the problems in the network environment? What is ARP and how does it work?
Q6. What are the major task of transport layer? Explain. What is token bucket algorithm?
Q7. What is DNS? Explain the working principle of DNS with a proper diagram. Compare IMAP and POP3 protocols.
Q8. "IPv4 and IPv6 coexistence" what does this mean? Explain Dual stack approach with an appropriate figure.
Q9. How does a Digital Signature work? Encrypt the world HELLO using RSA algorithm. Also decrypt it by showing steps.
Q10. Explain briefly the desirable properties of secure communication. Explain how packet filtering firewall works.
Back2076 Ashwin
2076 Ashwin · Back · BCT · 10 questions
Q1. What are the features of Client/Server Architecture? What are headers and trailers and how do they get added and removed?
Q2. Why the telephone companies developed ISDN? Explain the working principle of ISDN with its interface and functional group.
Q3. Explain the working principle of CSMA/CD with appropriate figure.
Q4. Institute of Engineering has six departments having 16, 32, 61, 8, 6 and 24 computers. Use 192.168.1.0/24 to distribute the network. Find the network address, broadcast address, usable IP range and subnet mask in each department.
Q5. What is routing? Differentiate between distance vector and link state routing algorithms.
Q6. Explain the TCP segment structure. Why TCP is known as reliable protocol and also describe how reliability is provided by TCP?
Q7. What is TFTP? Explain working principle of FTP with data transfer process including proper port connection. Use proper diagram to justify your answer.
Q8. List the advantages of IPv6 over IPv4. Explain any two transition strategies for IPv4 to IPv6.
Q9. List the properties of secure communication. Encrypt and decrypt “ROSE” using RSA algorithm.
Q10. Write short notes on: (Any two) a) Firewall and their types b) 803 Token Bus c) Virtual circuit switching
Regular / Back2075 Chaitra
2075 Chaitra · Regular / Back · BCT · 10 questions
Q1. Draw the architecture for Client/Server network model. Explain in details about P2P network model with supportive examples.
Q2. What is switching? What are the various switching techniques? Elaborate packet switching with a proper diagram.
Q3. What are multiple access protocols? Describe the various framing techniques at data link layer.
Q4. Suppose you are a private consultant hired by the large company to setup the network for their enterprise and you are given a large number of consecutive. IP address starting at 120.89.96.0/19. Suppose that four departments A, B, C and D request 100, 500, 800 and 400 addresses respectively, how the subnetting can be performed so, that address wastage will be minimum?
Q5. What do you mean by autonomous system? Explain how routing loops are prevented in Distance Vector Routing with examples.
Q6. Explain connection establishment and termination in TCP. Explain briefly about Leaky-Bucket algorithm for congestion control?
Q7. Why we need proxy servers? What are the importance of DNS and HTTP(S) while you are browsing any website?
Q8. “IPv4 and IPv6 coexistence” what does this mean? Explain what you mean by address family translation in IPv4/IPv6 migration process with an appropriate figure.
Q9. Explain briefly the desirable properties of secure communication. Explain how Packet filtering firewall Works.
Q10. Write short notes on: (Any two) a) Digital Signature b) VPN c) Symmetric key cryptography
Back2075 Ashwin
2075 Ashwin · Back · BCT · 10 questions
Q1. Why layering is important? Explain design issues for layers in detail. Mention service primitives for implementing connection oriented service.
Q2. Compare circuit switching and packet switching. Explain ISDN channels with architecture.
Q3. State the various design issues for the data link layer. What is piggybacking? A bit string 01111011111101111110 needs to be transmitted at the data link layer. What is the string actually transmitted after bit stuffing?
Q4. Why routing is essential in computer networking? Compare working of distance vector routing algorithm with link state routing algorithm.
Q5. Design a network for 5 departments containing 29, 14, 15, 23 and 5 computers. Take a network example IP 202.83.54.91/25.
Q6. What are the differences between TCP and UDP services? Explain the TCP datagram format in detail.
Q7. Define socket programming. How web server communication and file server communication are possible in network. Explain with used protocols.
Q8. What are the methods used to interoperate IPv6 and IPv4. Show IPv6 datagram format.
Q9. What is VPN? Encrypt a message "network" using RSA algorithm.
Q10. Write short notes on: (any two) i) Flow control in D22 ii) X.25 iii) ALOHA
Regular2074 Chaitra
2074 Chaitra · Regular · BCT · 10 questions
Q1. Distinguish between Client-Server network and Peer-Peer network. Explain Open System Interconnection (OSI) model.
Q2. Define transmission media. Compare among Twisted Pair, Coaxial cable and Fiber optic.
Q3. What is the main functionality of data link layer? Differentiate between circuit switching and packet switching.
Q4. Mention the criteria for good routing. Explain RIP, OSPF, BGP, IGRP and EIGRP.
Q5. How can you dedicate 32, 65, 10, 21, 9 public IP address to the departments A, B, C, D and E respectively form the pool of class C IP addresses with minimum loss. Explain.
Q6. How connection is established and released in TCP. Explain Token Bucket algorithm.
Q7. Which protocols are used in sending and receiving an email? Illustrate with necessary figure. Give a comparison of POP3 and IMAP.
Q8. What are the factors that lead to the speedy development of IPv6? Define the process of transition from IPv4 to IPv6.
Q9. Define type of Encryption used in security. How PGP can secure email communication?
Q10. Write short notes on: (any two) i) Types of firewals ii) FDDI iii) Socket programming
Back2074 Ashwin
2074 Ashwin · Back · BCT · 10 questions
Q1. What is the significance of OSI layer? Explain different layers of OSI with its functionalities.
Q2. Define switching and multiplexing. Explain about any two guided transmission media in detail.
Q3. What are the causes of packet delay in computer networks? What are the differences between circuit switching and packet switching?
Q4. What is classful and classless address? Differentiate between link state and distance vector routing protocol.
Q5. Suppose you are a private consultant hired by a company to setup the network for their enterprise and you are given a large number of consecutive IP address starting at 120.89.96.0/19. Suppose that four departments A, B, C and D request 100, 500, 800 and 400 addresses respectively, how the subnetting can be performed so that address wastage will be minimum?
Q6. Explain the TCP protocol with its Header. What do you understand by socket? Explain with its importance.
Q7. What is recursive and iterative query? Explain with suitable diagram. Discuss the DNS records.
Q8. List the advantages of IPv6 over IPv4. Explain header translation and tunneling approach used for migrating IPv4 to IPv6.
Q9. Explain briefly the desirable properties of secure communication. Explain how Packet filtering firewall Works.
Q10. Write short notes on: (Any two) a) SMTP and POP b) Diffie Hellman’s Algorithm c) CSMA/CD d) DLL Flow Control Mechanisms
New Back (2066 & Later Batch)2073 Shrawan
2073 Shrawan · New Back (2066 & Later Batch) · BCT · 10 questions
Q1. Differentiate between TCP/IP and OSI Model. Define Frame Relay in detail.
Q2. What do you mean by switching in communication? Compare switching with multiplexing. Explain the E1 Telephone hierarchy system.
Q3. What do you understand by Media Access Control? What is its significance in data link layer? Explain why token bus is also called as the token ring.
Q4. You are a private contractor hired by the large company to setup the network for their enterprise and you are given a large number of consecutive IP address starting at 202.70.64.0/19. Suppose that four department A, B, C and D request 100, 500, 800 and 400 addresses respectively, how the subnetting can be performed so, that address wastage will be minimum?
Q5. Discuss about the network congestion? Explain how different network parameters effect the congestion. Compare operation of link state routing with the distance vector routing.
Q6. How web server communication and file server communication are possible in network, explain with used protocols. Define socket programming.
Q7. What are the factors that lead to the development of IPv6? Define the process of transition from IPv4 to IPv6.
Q8. Compare symmetric key encryption method with asymmetric key encryption. Explain RSA algorithm with example.
Q9. What do you mean by firewall? Explain different types of firewall.
Q10. Write short notes on: i) HDLC ii) Web Server
Regular2072 Chaitra
2072 Chaitra · Regular · BCT · 10 questions
Q1. Compare OSI layer with TCP/IP Layer? Explain in which level of OSI layer following tasks are done. i) Error detection and correction ii) Encryption and Decryption of data iii) Logical identification of computer iv) Point-to-point connection of socket v) Dialogue control vi) Physical identification of computer
Q2. Explain five instances of how networks are a part of your life today. Through we have MAC address, why do we use IP address to represent the host in networks? Explain your answer.
Q3. Briefly explain different types of Data Link Layer framing mechanisms. List the features of FDDI.
Q4. Explain how can you allocate 30, 24, 25 and 20 IP addresses to the four different department of ABC company with minimum wastage. Specify the range of IP addresses, Broadcast Address, Network Address and Subnet mask for each department form the given address pool 202.77.19.0/24.
Q5. What is routed and routing protocol? Give examples. Explain Token Bucket algorithm.
Q6. For the client-server application over TCP, why must the server program be executed before the client program? TCP is known as reliable process how, describe reliability is provided by TCP.
Q7. Compare the header fields of IPV6 and IPV4. Which method do you suggest for the migration of IPv6 and why?
Q8. Explain briefly how firewalls protect network and also explain different types of Firewall. Illustrate your answer with appropriate figures.
Q9. Write down the steps involved in RSA encryption algorithm. Encrypt the word CAT using RSA algorithm, choose the suitable data for encryption by yourself according to RSA algorithm.
Q10. Write short notes on: a) Simple Mail Transfer Protocol b) Doman Name Server
New Back (2066 & Later Batch)2072 Kartik
2072 Kartik · New Back (2066 & Later Batch) · BCT · 10 questions
Q1. You are assigned to design a network infrastructure for a 3-star hotel. Recommend a network solution with hardwares and softwares in current trend that can be used in the hotel. Make necessary assumptions and justify your recommadation with logical arguments where possible.
Q2. List out the functions of physical layer in TCP/IP reference model. Explain different types of transmission media.
Q3. What are the functions of data-link layer? Explain the channel allocation problem with example.
Q4. What are the functions of network layer? Explain briefly about multicast routing protocols and unicast routing protocols.
Q5. Network layer is one of the key layers in OSI reference model, why? Differentiate between distance vector routing and static link routing.
Q6. What is a TCP connection? Explain how a TCP connection can be gracefully terminated.
Q7. What are the different components of email server? Explain different types of electronic mail sending and accessing protocol.
Q8. What is IPV6? What methods are used so that IPV6 and IPV4 networks are interoperable?
Q9. What is firewall? What are their types? Encrypt and decrypt "OVEL" message using RSA algorithm.
Q10. Write short notes on: a) Digital signature b) IPSec
Regular2071 Chaitra
2071 Chaitra · Regular · BCT · 10 questions
Q1. What do you mean by network architecture? Compare TCP/IP and OSI reference models. Explain X.25 Network with its key feature.
Q2. What is ISDN? Explain about the ISDN architecture in detail with example.
Q3. What are multiple access protocols? Explain how multiple access is achieved in IEEE 802.5.
Q4. What is network security? Explain Virtual Private Network (VPN) with an example.
Q5. You are given the following address space 10.10.10.0/24. You have to assign addresses to 4 departments with the following hosts 5, 16, 23 and 27 respectively. Perform the subnetting in such a way that the IP address wastage in each department are minimum. Also find out the subnet mask, network address, broadcast address and unassigned range in each department.
Q6. Why port number is used in networking? What are the services of transport layer? Differentiate between TCP and UDP protocol.
Q7. What is DNS? Explain the structure of DNS request and response with practical example.
Q8. What are the problems of IPv4? How IPv6 reduce these problems? Explain different strategies to transit from IPv4 and IPv6.
Q9. What is public key cryptography? Explain about RSA algorithm in detail.
Q10. Write short notes on: a) SSL b) WEP
New Back (2066 & Later Batch)2071 Shrawan
2071 Shrawan · New Back (2066 & Later Batch) · BCT · 10 questions
Q1. What is computer network? Distinguish between OSI and TCP/IP reference model.
Q2. What is transmission media? Explain about any three transmission media in detail.
Q3. What are the major functions of data link layer? Explain about framing in detail.
Q4. What is routing? Differentiate between link state routing and distance vector routing.
Q5. Write short notes on: (any two) a) ARP b) ICMP c) IP
Q6. Distinguish between TCP and UDP. How is TCP connection established? Explain.
Q7. SMTP is a text based protocol and uses 7 bit ascii. How can this be used to transmit sometimes like images? Explain.
Q8. What are the drawbacks in IPV4? Which of these drawbacks do IPV6 solve? Explain.
Q9. What is cryptography? Differentiate between symmetric key and public key cryptography.
Q10. Write short notes on: (any two) a) WEP b) IDS c) SSL
Regular2070 Chaitra
2070 Chaitra · Regular · BCT · 10 questions
Q1. What are the features of Client/Server Architecture? What are headers and trailers and how do they get added and removed? Explain.
Q2. What do you mean by data switching? Explain about various types of switching with practical implementation example.
Q3. What is the difference between Error Correcting and Error detection process? A bit string 01111011111011111110 needs to be transmitted at the data link layer what is string actually transmitted after bit stuffing, if flag patterns is 01111110.
Q4. Explain the working principle of different types of network devices Repeater, HUB, Bridge, Switch and Router.
Q5. How can you dedicate 10, 12, 8, 14 public IP addresses to department A, B, C and D respectively from the pool of class C with minimum losses of IP? Explain.
Q6. Explain the UDP segment structure. Illustrate your answer with appropriate figures.
Q7. What do you mean by email server? What are the protocols used on it?
Q8. Explain the IPv6 datagram format with appropriate figures.
Q9. Explain briefly how firewalls protect network and also explain different types of Firewall. Illustrate your answer with appropriate figures.
Q10. What do you mean by Network security? Explain the operation of Data Encryption Standard Algorithm?
Old Back (2065 & Earlier Batch)2070 Ashad
2070 Ashad · Old Back (2065 & Earlier Batch) · BCT · 10 questions
Q1. What do you mean by protocol and interfaces? Write the protocols used in each layer of ICP/IP model.
Q2. How do you define network topology? Discuss the types of network topologies based on its size and geographical distributions.
Q3. What are the functions of LLC and MAC sub-layer? Discuss different farming approaches used in data link layer.
Q4. How data transfer occurs in Ethernet network? Explain.
Q5. Discuss how CSMA works? Differentiate it with CSMA-CD. Explain the optical fiber cabling standards with examples.
Q6. What is virus circuit switching? Describe the operation of Frame-Relay network.
Q7. Differentiate between adaptive and non-adaptive routing. Explain shortest path finding algorithm in link state routing.
Q8. Compare between leaky bucket and token bucket algorithm with the operation how token bucket works.
Q9. What are the major problems with existing IPv4 network? Explain IPv4 addressing and sub-netting with example.
Q10. Write short notes on: a) ALOHA system b) TCP header
Regular2069 Chaitra
2069 Chaitra · Regular · BCT · 10 questions
Q1. Explain the need of Networking Software in the form of Hierarchy? Mention in which level layer of OSI reference model following tasks are done. i) Timing and voltage of received signal ii) Encryption and decryption of data iii) Data framing iv) Point-to-point connection of socket.
Q2. Define switching and multiplexing. Differentiate between circuit switching and packet switching.
Q3. Explain different types of Data link layer framing mechanisms.
Q4. What is the contribution of sub-netting in IP address management? Show the importance in this case. Banijya bank need to allocate 15 IPs in HR department, 30 in finance department, 24 in customer care unit and 25 in ATM machines. If you have one network of class C range public IP address. Describe how you will manage it.
Q5. Why is routing protocol necessary? Explain the working process of Routing Information protocol (RIP) with example.
Q6. Why do you think that there exist two protocols in transport layer where as there exists only one protocol in Internet layer in TCP/IP reference model. Explain token bucket algorithm for congestion control.
Q7. What is HTTP protocol? With an example explain how a request initiated by a HTTP client is served by a HTTP server.
Q8. Explain the IPv6 datagram format and the function of each field with necessary figure.
Q9. Compare symmetric key encryption method with asymmetric key encryption. Describe the operation of RSA algorithm.
Q10. What is network security? How can firewalls enhance network security? Explain how firewalls can protect a system.
Regular / Back2068 Chaitra
2068 Chaitra · Regular / Back · BCT · 9 questions
Q1. Why are the network softwares defined with distinct layers stacked on top of one another? What are the factors to be considered when designing these layers?
Q2. Why do we need RAID in the computer networks? Define and discuss the differences between RAID 0, RAID 1 and RAID 5.
Q3. What is a telephone? With a simple diagram of a telephone network explain how the system works.
Q4. Why channel access mechanism is important in computer networking? Explain the operation of IEEE 802.5 with its frame format.
Q5. Differentiate: a) Distance vector and link state routing algorithm b) Circuit switching and packet switching
Q6. What is X.25? Explain the format of X.25 packet in detail.
Q7. What are the differences between TCP and UDP services? Explain the TCP datagram format in detail.
Q8. Suppose there are 4 departments A, B, C and D. The department A has 23 hosts, B has 16, C has 28 and D has 13 hosts. You are given a networks 202.70.64.0/24. Perform the subnetting in such a way that the IP address wastage in each department are minimum and also find out the sunbet mask, network address, broadcast, and unable host range in each department.
Q9. Write short notes on: a) Network Security b) Router and Gateway
Regular / Back2068 Baishakh
2068 Baishakh · Regular / Back · BCT · 10 questions
Q1. What is a switching? Differentiate between packet switching and circuit switching.
Q2. What are types of twisted pair cable? Calculate the efficiency of slotted Aloha.
Q3. What is a virtual LAN? Design a network which consists of two VLAN named student and department. Explain with necessary diagram, IP addresses and configurations.
Q4. What is a logical address? You are given the IP address block 200.10.80.32/25. If there are five departments which require 5, 40, 28, 12, 6 hosts respectively. Design the subnet.
Q5. What are the functions of transport layer? Draw the segment structure of TCP.
Q6. What is a fragmentation and re-assembly? Explain about any intra-AS routing protocol.
Q7. What are the advantages of IPV6? The maximum payload segment is 65495 byte. Why was such strange number chosen?
Q8. What is the function of proxy server? Explain about electronic mail.
Q9. What is a secure socket layer? Encrypt the message “DANGER” using RSA algorithm.
Q10. Compare x.25 and frame relay network. A bit string 0111101111101111110 needs to be transmitted at the data link layer. What is the string actually transmitted after bit stuffing?
Regular / Back2067 Ashad
2067 Ashad · Regular / Back · BCT · 10 questions
Q1. Why network software should be in hierarchical form? Explain in detail about OSI layer.
Q2. If you are assigned to design a LAN for Pulchowk Campus having 5 departments. Each department will have 100 computers locating in 5 rooms each equipped with 20 computers. Make your own justification while selecting connecting devices and accessories.
Q3. What do you mean by ISDN and what is it contribution in the field of data communication? Explain various types of multiplexing mechanism used in communication.
Q4. Describe what do you understand by switching along with various types of switching mechanism. Explain the fault tolerance mechanism of FDDI.
Q5. Why access control of channel is essential? Compare operating details of IEEE 802.4 and IEEE 802.5.
Q6. Explain along with the packet format about the virtual circuit connection of X.25.
Q7. Why routing is essential in computer networking? Compare working of distance vector routing algorithm with link state routing algorithm.
Q8. Explain in detail about IP frame format.
Q9. If you need to assign IP addresses to all computers of question no. 2 making each department as network. What will be your approach? Explain with IP address ranges you are suggesting.
Q10. How the protocol SMTP does operate? Explain the procedures to make your network secured.
Back2066 Poush
2066 Poush · Back · BCT · 10 questions
Q1. Define network and protocol for network. Explain peer-to-peer network process with example.
Q2. Describe guided and unguided media used in computer network with their advantages.
Q3. Explain the operation of pure ALOHA system. How CSMA/CD works?
Q4. List the functions of Data Link Control Layer. Explain any two sliding window protocols with the advantages of piggybacking.
Q5. Describe the policies that help in preventing the congestions within the network? Differentiate between leaky bucket and token bucket algorithm with their operation and working of token bucket.
Q6. What do you understand by virtual circuit switching? Explain the X.25 virtual circuit switching.
Q7. Explain the seven layers of OSI model with their example protocols.
Q8. Briefly describe ICMP error and informational message types in IPv4 network infrastructure.
Q9. How can we maintain the security within the communication network? Explain any one cryptography algorithm with example.
Q10. Write short notes on (any two): a) UDP and its application b) Network Devices: Hubs, Switches and Routers c) IPv4 Header Structure
Regular / Back2066 Bhadra
2066 Bhadra · Regular / Back · BCT · 10 questions
Q1a. Why do communication process within computer network is divided into layers? How the process of data encapsulation occurs in transmission mode described by seven layers of OSI model. Compare OSI model with TCP/IP model.
Q1b. What is client/server networking? Explain Active Networking model framework comparing with traditional legacy network.
Q2a. What are the services provided by data link layer? Explain any one methods of framing and flow control.
Q2b. Calculate SNR and maximum channel capacity of a cat6 channel having bandwidth 300 MHz with 2mW and 200 μW as signal and noise power respectively.
Q3a. Describe the 802.3 Ethernet standard for CSMA/CD and compare it with 802.4 token bus technology. Explain how DSSS technique is applied in wireless transmission.
Q3b. Differentiate between circuit switching and packet switching technology. Explain the operation how switched virtual circuit in frame relay network is established, maintained and teardown.
Q4a. What is unicast and multicast routing? Describe the concept of optimality principle. Describe how the routers in its link state routing come into fully adjacency state.
Q4b. What are the factors that cause congestion within WAN? Propose your best traffic shaping approach to manage congestion in packet switched network.
Q5a. Give the reason why the current world is moving to IPv6 addressing mechanism. Describe the IPv6 address types with its representation format. You are given the IPv4 address block 203.71.53.0/26; assign the IP subnet for the following network. [Figure, as text: Net A: 6 Hosts (LAN on router R1); Net B: 2 Hosts (link R1 to R2); Net C: 12 Hosts (LAN on router R2); Net E: 2 Hosts (link R2 to R3); Net F: 29 Hosts (LAN on router R3). The routers are unlabelled in the print and no Net D is drawn.]
Q5b. Write short notes on (any two) i) TCP Sliding Window Protocol ii) Secrete Key Algorithm: DES iii) ISDN Signaling and ATM AAL iv) ICMP Message Types
Chapter 1 · Introduction to computer network 27 distinct questions, from 26 of the 27 sittings
Write Short Notes on: (Any Two) a) 802.5 Token Ring b) PGP c) Socket programming fundamentals d) X.25 Network
Also set as:
- Write short notes on: (any two) i) Flow control in D22 ii) X.25 iii) ALOHA (2075 Ashwin Q10)
- What is X.25? Explain the format of X.25 packet in detail. (2068 Chaitra Q6)
- Explain along with the packet format about the virtual circuit connection of X.25. (2067 Ashad Q6)
- What do you understand by virtual circuit switching? Explain the X.25 virtual circuit switching. (2066 Poush Q6)
Write Short notes on: (Any Two) a) 802.4 Token Bus b) Framing with bit stuffing c) Server Socket programming for bind, listen and accept d) ATM
Also set as:
- Write short notes on: (Any Two) a) Go Back-N ARQ b) Dual Stack method in IPv6 c) Diffie-Hellman algorithm d) ATM (2080 Bhadra Q10)
- Write short notes on (any two) i) TCP Sliding Window Protocol ii) Secrete Key Algorithm: DES iii) ISDN Signaling and ATM AAL iv) ICMP Message Types (2066 Bhadra Q5b)
Write short notes on: (Any Two) a) Frame relay b) TCP sliding window c) HDLC
Also set as:
- What is virus circuit switching? Describe the operation of Frame-Relay network. (2070 Ashad Q6)
- Differentiate between circuit switching and packet switching technology. Explain the operation how switched virtual circuit in frame relay network is established, maintained and teardown. (2066 Bhadra Q3b)
Define protocol with examples. Why do we have layered architecture in networks? Differentiate between TCP/IP and OSI model.
Also set as:
- What is protocol? What are the reasons for using layered network architecture? Compare OSI with TCP/IP reference model. (2076 Chaitra Q1)
Differentiate between Client Server and Peer to Peer architecture. Discuss the functions of each layer of Open System Interconnection (OSI) model.
Also set as:
- Distinguish between Client-Server network and Peer-Peer network. Explain Open System Interconnection (OSI) model. (2074 Chaitra Q1)
How does the client-server model work? Differentiate it with peer-to-peer network with advantages and disadvantages.
Also set as:
- Draw the architecture for Client/Server network model. Explain in details about P2P network model with supportive examples. (2075 Chaitra Q1)
What are the features of Client/Server Architecture? What are headers and trailers and how do they get added and removed?
Also set as:
- What are the features of Client/Server Architecture? What are headers and trailers and how do they get added and removed? Explain. (2070 Chaitra Q1)
What is the significance of OSI layer? Explain different layers of OSI with its functionalities.
Also set as:
- Explain the seven layers of OSI model with their example protocols. (2066 Poush Q7)
Explain the need of Networking Software in the form of Hierarchy? Mention in which level layer of OSI reference model following tasks are done. i) Timing and voltage of received signal ii) Encryption and decryption of data iii) Data framing iv) Point-to-point connection of socket.
Also set as:
- Why network software should be in hierarchical form? Explain in detail about OSI layer. (2067 Ashad Q1)
Explain client/server and P2P network model with their advantages and disadvantages. Discuss the layer of TCP/IP model with suitable diagram.
Define Network. List a function of each layer of OSI reference model and compare it with TCPI/IP model.
What is a protocol? List out the common protocols used at each layer of TCP/IP model. Differentiate between client-server is P2P network.
Why do we need layered architecture in computer network? Discuss the function of each layer of TCP/IP networking model.
Compare the OSI reference model and TCP/IP reference model mentioning their similarities and differences.
Why layering is important? Explain design issues for layers in detail. Mention service primitives for implementing connection oriented service.
Differentiate between TCP/IP and OSI Model. Define Frame Relay in detail.
Compare OSI layer with TCP/IP Layer? Explain in which level of OSI layer following tasks are done. i) Error detection and correction ii) Encryption and Decryption of data iii) Logical identification of computer iv) Point-to-point connection of socket v) Dialogue control vi) Physical identification of computer
Explain five instances of how networks are a part of your life today. Through we have MAC address, why do we use IP address to represent the host in networks? Explain your answer.
What do you mean by network architecture? Compare TCP/IP and OSI reference models. Explain X.25 Network with its key feature.
What is computer network? Distinguish between OSI and TCP/IP reference model.
What do you mean by protocol and interfaces? Write the protocols used in each layer of ICP/IP model.
How do you define network topology? Discuss the types of network topologies based on its size and geographical distributions.
Why are the network softwares defined with distinct layers stacked on top of one another? What are the factors to be considered when designing these layers?
Compare x.25 and frame relay network. A bit string 0111101111101111110 needs to be transmitted at the data link layer. What is the string actually transmitted after bit stuffing?
Define network and protocol for network. Explain peer-to-peer network process with example.
Why do communication process within computer network is divided into layers? How the process of data encapsulation occurs in transmission mode described by seven layers of OSI model. Compare OSI model with TCP/IP model.
What is client/server networking? Explain Active Networking model framework comparing with traditional legacy network.
Chapter 2 · Physical layer 22 distinct questions, from 25 of the 27 sittings
What is the main functionality of data link layer? Differentiate between circuit switching and packet switching.
Also set as:
- What do you mean by data switching? Explain about various types of switching with practical implementation example. (2070 Chaitra Q2)
- Differentiate: a) Distance vector and link state routing algorithm b) Circuit switching and packet switching (2068 Chaitra Q5)
- What is a switching? Differentiate between packet switching and circuit switching. (2068 Baishakh Q1)
- Describe what do you understand by switching along with various types of switching mechanism. Explain the fault tolerance mechanism of FDDI. (2067 Ashad Q4)
- Differentiate between circuit switching and packet switching technology. Explain the operation how switched virtual circuit in frame relay network is established, maintained and teardown. (2066 Bhadra Q3b)
List out the most common guided and unguided transmission media used in computer networks now a days. Explain any one of the guided transmission media with examples.
Also set as:
- What is transmission medium? Explain different transmission medium with their merits and demerits. (2076 Chaitra Q2)
- What is transmission media? Explain about any three transmission media in detail. (2071 Shrawan Q2)
Why the telephone companies developed ISDN? Explain the working principle of ISDN with its interface and functional group.
Also set as:
- What is ISDN? Explain about the ISDN architecture in detail with example. (2071 Chaitra Q2)
- Write short notes on (any two) i) TCP Sliding Window Protocol ii) Secrete Key Algorithm: DES iii) ISDN Signaling and ATM AAL iv) ICMP Message Types (2066 Bhadra Q5b)
Write short notes on: (Any two) a) Firewall and their types b) 803 Token Bus c) Virtual circuit switching
Also set as:
- What is virus circuit switching? Describe the operation of Frame-Relay network. (2070 Ashad Q6)
- What do you understand by virtual circuit switching? Explain the X.25 virtual circuit switching. (2066 Poush Q6)
What is switching and multiplexing? Explain switching technique used in modern computer networks.
Also set as:
- Define switching and multiplexing. Differentiate between circuit switching and packet switching. (2069 Chaitra Q2)
Explain line of sight (LOS) propagation modes. Draw block diagram generic optical fiber (OF) communication system and its RF range.
What are the factors to be considered while selecting media for communication? Differentiate between datagram and virtual circuit switching approach with respect to Frame Relay Network.
a) Discuss about the different factors of choosing the transmission media." Circuit switching is suitable for real-time communication", give your reasons. If a file of 1000 bytes was sent over a network in 2 seconds, calculate throughput.
What is multiplexing? What is its importance in communication? Explain different types of multiplexing techniques.
Define Throughput. A network with bandwidth of 20 Mbps can pass only an average of 18,000 frames per minute with each frame carrying an average of 20,000 bits. Calculate the throughput of this network. Differentiate between Packet switching and Virtual Circuit switching.
What is switching? What are the various switching techniques? Elaborate packet switching with a proper diagram.
Compare circuit switching and packet switching. Explain ISDN channels with architecture.
Define transmission media. Compare among Twisted Pair, Coaxial cable and Fiber optic.
Define switching and multiplexing. Explain about any two guided transmission media in detail.
What are the causes of packet delay in computer networks? What are the differences between circuit switching and packet switching?
What do you mean by switching in communication? Compare switching with multiplexing. Explain the E1 Telephone hierarchy system.
List out the functions of physical layer in TCP/IP reference model. Explain different types of transmission media.
What is a telephone? With a simple diagram of a telephone network explain how the system works.
What are types of twisted pair cable? Calculate the efficiency of slotted Aloha.
What do you mean by ISDN and what is it contribution in the field of data communication? Explain various types of multiplexing mechanism used in communication.
Describe guided and unguided media used in computer network with their advantages.
Calculate SNR and maximum channel capacity of a cat6 channel having bandwidth 300 MHz with 2mW and 200 μW as signal and noise power respectively.
Chapter 3 · Data link layer 36 distinct questions, from 27 of the 27 sittings
Write short notes on: (Any Two) a) ARP and NDP b) AH and ESP c) VPN d) vLAN
Also set as:
- Write short notes on: (Any Two) a) VLAN b) ARP c) IPSec (2080 Baishakh Q10)
- What is a virtual LAN? Design a network which consists of two VLAN named student and department. Explain with necessary diagram, IP addresses and configurations. (2068 Baishakh Q3)
Write short notes on: (Any Two) a) ALOHA b) OSPF c) VPN
Also set as:
- Write short notes on: a) ALOHA system b) TCP header (2070 Ashad Q10)
- What are types of twisted pair cable? Calculate the efficiency of slotted Aloha. (2068 Baishakh Q2)
What is CSMA/CD? Why is it not applicable in wireless LAN? What are the techniques used to avoid the possible collisions in WLAN? Explain.
Also set as:
- What is collision? How is it occured? How the possibility of collision is reduced in IEEE 802.3 and IEEE 802.11? Explain. (2076 Chaitra Q3)
Write short notes on: (Any Two) a) Frame relay b) TCP sliding window c) HDLC
Also set as:
- Write short notes on: i) HDLC ii) Web Server (2073 Shrawan Q10)
State the various design issues for the data link layer. What is piggybacking? A bit string 01111011111101111110 needs to be transmitted at the data link layer. What is the string actually transmitted after bit stuffing?
Also set as:
- What are the services provided by data link layer? Explain any one methods of framing and flow control. (2066 Bhadra Q2a)
Write short notes on: (any two) i) Types of firewals ii) FDDI iii) Socket programming
Also set as:
- Describe what do you understand by switching along with various types of switching mechanism. Explain the fault tolerance mechanism of FDDI. (2067 Ashad Q4)
What are multiple access protocols? Explain how multiple access is achieved in IEEE 802.5.
Also set as:
- Why channel access mechanism is important in computer networking? Explain the operation of IEEE 802.5 with its frame format. (2068 Chaitra Q4)
What are the major functions of data link layer? Explain about framing in detail.
Also set as:
- What are the functions of LLC and MAC sub-layer? Discuss different farming approaches used in data link layer. (2070 Ashad Q3)
Explain different types of Data link layer framing mechanisms.
Also set as:
- Compare x.25 and frame relay network. A bit string 0111101111101111110 needs to be transmitted at the data link layer. What is the string actually transmitted after bit stuffing? (2068 Baishakh Q10)
Write different ways to correct backward error correction. Compare pure Aloha and slotted Aloha mentioning the condition for no collision.
What are the functions of data link layer? How to detect signal collision in CSMA/CD? List the ethernet cable specification standards for 802.3 ethernet standards.
What is hamming distance? How do you apply it in data link layer error control mechanism? Calculate the CRC for a 8 bit sequence 11001101. The generator polynomial is x⁴ + x² + 1. Also find the transmitted bit frame.
Write Short Notes on: (Any Two) a) 802.5 Token Ring b) PGP c) Socket programming fundamentals d) X.25 Network
What is piggy-backing? How do you apply it in data link layer flow control mechanism? Calculate the CRC for a 10 bit sequence 1010001101. The generator polynomial is x⁵ + x⁴ + x² + 1. Also find the transmitted bit frame.
Write Short notes on: (Any Two) a) 802.4 Token Bus b) Framing with bit stuffing c) Server Socket programming for bind, listen and accept d) ATM
Write short notes on: (Any Two) a) MAC sublayer b) Digital signature c) Firewall
Explain how does CRC detect the errors. Given message is M (x) = x7 + x4 +x3 +x2 + 1 and the generator is G (x) = x3 + 1. Show the actual bit string transmitted, suppose the third bit from the left is inverted during the transmission. Show how the error is detected at the receiver's end.
Write short notes on: (Any Two) a) Go Back-N ARQ b) Dual Stack method in IPv6 c) Diffie-Hellman algorithm d) ATM
How CSMA/CD works? Describe Ethernet (IEEE 802.3) frame structure with function of each field.
Explain Go-back-N ARQ and selective Repeat ARQ with example. How carrier sense multiple access with collision detection (CSMA/CD) is better than CSMA?
Explain the working principle of CSMA/CD with appropriate figure.
Write short notes on: (Any two) a) Firewall and their types b) 803 Token Bus c) Virtual circuit switching
What are multiple access protocols? Describe the various framing techniques at data link layer.
Write short notes on: (any two) i) Flow control in D22 ii) X.25 iii) ALOHA
What is the main functionality of data link layer? Differentiate between circuit switching and packet switching.
Write short notes on: (Any two) a) SMTP and POP b) Diffie Hellman’s Algorithm c) CSMA/CD d) DLL Flow Control Mechanisms
What do you understand by Media Access Control? What is its significance in data link layer? Explain why token bus is also called as the token ring.
Briefly explain different types of Data Link Layer framing mechanisms. List the features of FDDI.
What are the functions of data-link layer? Explain the channel allocation problem with example.
What is the difference between Error Correcting and Error detection process? A bit string 01111011111011111110 needs to be transmitted at the data link layer what is string actually transmitted after bit stuffing, if flag patterns is 01111110.
How data transfer occurs in Ethernet network? Explain.
Discuss how CSMA works? Differentiate it with CSMA-CD. Explain the optical fiber cabling standards with examples.
Why access control of channel is essential? Compare operating details of IEEE 802.4 and IEEE 802.5.
Explain the operation of pure ALOHA system. How CSMA/CD works?
List the functions of Data Link Control Layer. Explain any two sliding window protocols with the advantages of piggybacking.
Describe the 802.3 Ethernet standard for CSMA/CD and compare it with 802.4 token bus technology. Explain how DSSS technique is applied in wireless transmission.
Chapter 4 · Network layer 31 distinct questions, from 27 of the 27 sittings
Suppose a company XYZ has an IP address of 160.24.96.0/21 and it has 6 departments containing 1024, 750, 254, 500, 151 and 45 users and also include point-point links. List out the CIDR, network address, broadcast address, usable host range and wasted IP address in each subnet.
Also set as:
- In which case VLSM is used while dividing the given block of IP addresses for different subnets and why? Suppose your company has IP address block of 16.16.16.0/21. Divide this IP address for five different departments of the company equally. List out the network address, broadcast address, subnet mask and usable IP address range for each subnet. (2081 Baishakh Q4)
- Suppose a company has IP address of 10.20.30.0/24 and it has 4 LANs containing 4,64,24,18 number of hosts. Also, there are 4 WAN links to connect LAN1 - LAN2, LAN2 - LAN3, LAN3 - LAN4 and LAN1 - LAN3. List out the subnet wasted IP addresses for each LAN. (2080 Bhadra Q4)
- Suppose a company has IP address of 200.80.40.0/24 with 5 departments containing 29, 5, 16, 43, 14, number of hosts. Also there are point to point links between the departments. List out the subnet mask, network address, broadcast address, usable host IP ranges and no. of wasted IP addresses for each subnet. (2080 Baishakh Q5)
- An ISP provided you an IP address block of 172.24.96.0/21. Suppose you need to divide this for four different departments A, B, C and D having 750, 200, 500 and 45 hosts respectively with minimum wastage of IP addresses. Also allocate IP addresses for three point-to-point links in the network. Find out the network address, broadcast address, subnet mash and usable host range of IP addresses for each subnet. (2079 Bhadra Q5)
- Consider IP block of 202.50.0.0/24 and six departments with 125, 59, 27, 14, 4 and 2 hosts respectively. Perform the subnetting so that wastage of IP addresses is minimum and find out the subnet mask, network address, broadcast address, wasted IP addresses and usable host ranges in each network. (2078 Bhadra Q4)
- Suppose your company has leased the IP address of 222.70.94.0/24 from your ISP. Divide it far five different departments containing 50, 30, 25, 12, 10 no of hosts. There are also two points to point links far interconnection between routers. List out the network address, broadcast address, usable IP address range and subnet mask for each subnet. Also mention the unused range of IP addresses. (2076 Chaitra Q4)
- Institute of Engineering has six departments having 16, 32, 61, 8, 6 and 24 computers. Use 192.168.1.0/24 to distribute the network. Find the network address, broadcast address, usable IP range and subnet mask in each department. (2076 Ashwin Q4)
- Suppose you are a private consultant hired by the large company to setup the network for their enterprise and you are given a large number of consecutive. IP address starting at 120.89.96.0/19. Suppose that four departments A, B, C and D request 100, 500, 800 and 400 addresses respectively, how the subnetting can be performed so, that address wastage will be minimum? (2075 Chaitra Q4)
- Design a network for 5 departments containing 29, 14, 15, 23 and 5 computers. Take a network example IP 202.83.54.91/25. (2075 Ashwin Q5)
- How can you dedicate 32, 65, 10, 21, 9 public IP address to the departments A, B, C, D and E respectively form the pool of class C IP addresses with minimum loss. Explain. (2074 Chaitra Q5)
- Suppose you are a private consultant hired by a company to setup the network for their enterprise and you are given a large number of consecutive IP address starting at 120.89.96.0/19. Suppose that four departments A, B, C and D request 100, 500, 800 and 400 addresses respectively, how the subnetting can be performed so that address wastage will be minimum? (2074 Ashwin Q5)
- You are a private contractor hired by the large company to setup the network for their enterprise and you are given a large number of consecutive IP address starting at 202.70.64.0/19. Suppose that four department A, B, C and D request 100, 500, 800 and 400 addresses respectively, how the subnetting can be performed so, that address wastage will be minimum? (2073 Shrawan Q4)
- Explain how can you allocate 30, 24, 25 and 20 IP addresses to the four different department of ABC company with minimum wastage. Specify the range of IP addresses, Broadcast Address, Network Address and Subnet mask for each department form the given address pool 202.77.19.0/24. (2072 Chaitra Q4)
- You are given the following address space 10.10.10.0/24. You have to assign addresses to 4 departments with the following hosts 5, 16, 23 and 27 respectively. Perform the subnetting in such a way that the IP address wastage in each department are minimum. Also find out the subnet mask, network address, broadcast address and unassigned range in each department. (2071 Chaitra Q5)
- How can you dedicate 10, 12, 8, 14 public IP addresses to department A, B, C and D respectively from the pool of class C with minimum losses of IP? Explain. (2070 Chaitra Q5)
- What is the contribution of sub-netting in IP address management? Show the importance in this case. Banijya bank need to allocate 15 IPs in HR department, 30 in finance department, 24 in customer care unit and 25 in ATM machines. If you have one network of class C range public IP address. Describe how you will manage it. (2069 Chaitra Q4)
- Suppose there are 4 departments A, B, C and D. The department A has 23 hosts, B has 16, C has 28 and D has 13 hosts. You are given a networks 202.70.64.0/24. Perform the subnetting in such a way that the IP address wastage in each department are minimum and also find out the sunbet mask, network address, broadcast, and unable host range in each department. (2068 Chaitra Q8)
- If you need to assign IP addresses to all computers of question no. 2 making each department as network. What will be your approach? Explain with IP address ranges you are suggesting. (2067 Ashad Q9)
- Give the reason why the current world is moving to IPv6 addressing mechanism. Describe the IPv6 address types with its representation format. You are given the IPv4 address block 203.71.53.0/26; assign the IP subnet for the following network. [Figure, as text: Net A: 6 Hosts (LAN on router R1); Net B: 2 Hosts (link R1 to R2); Net C: 12 Hosts (LAN on router R2); Net E: 2 Hosts (link R2 to R3); Net F: 29 Hosts (LAN on router R3). The routers are unlabelled in the print and no Net D is drawn.] (2066 Bhadra Q5a)
What is routing? Differentiate between distance vector and link state routing algorithms.
Also set as:
- Why routing is essential in computer networking? Compare working of distance vector routing algorithm with link state routing algorithm. (2075 Ashwin Q4)
- What is routing? Differentiate between link state routing and distance vector routing. (2071 Shrawan Q4)
List the range of IPv4 address classes. You have to assign addresses to four departmental LANs with following hosts 14, 55, 10 and 29 addresses respectively from the given IP address block: 202.97.43.0/25. Perform the subnetting and find out subnet mask, network address, broadcast address and usable host IP ranges.
Also set as:
- What are the major problems with existing IPv4 network? Explain IPv4 addressing and sub-netting with example. (2070 Ashad Q9)
- What is a logical address? You are given the IP address block 200.10.80.32/25. If there are five departments which require 5, 40, 28, 12, 6 hosts respectively. Design the subnet. (2068 Baishakh Q4)
What is ICMP? Explain the importance and uses of ICMP in TCP/IP protocol suit.
Also set as:
- Briefly describe ICMP error and informational message types in IPv4 network infrastructure. (2066 Poush Q8)
- Write short notes on (any two) i) TCP Sliding Window Protocol ii) Secrete Key Algorithm: DES iii) ISDN Signaling and ATM AAL iv) ICMP Message Types (2066 Bhadra Q5b)
Write short notes on: (Any Two) a) ARP and NDP b) AH and ESP c) VPN d) vLAN
Also set as:
- Write short notes on: (Any Two) a) VLAN b) ARP c) IPSec (2080 Baishakh Q10)
What is DR and BDR in OSPF? How do OSPF routers come into fully adacency states? Explain.
Also set as:
- Write short notes on: (Any Two) a) ALOHA b) OSPF c) VPN (2079 Bhadra Q10)
What is the purpose of Time to live (TTL) and protocol field in header of IPv4 datagram. Which protocol is used in internet layer to provide feedback to hosts/routers about the problems in the network environment? What is ARP and how does it work?
Also set as:
- Write short notes on: (any two) a) ARP b) ICMP c) IP (2071 Shrawan Q5)
Discuss about the network congestion? Explain how different network parameters effect the congestion. Compare operation of link state routing with the distance vector routing.
Also set as:
- Differentiate: a) Distance vector and link state routing algorithm b) Circuit switching and packet switching (2068 Chaitra Q5)
You are assigned to design a network infrastructure for a 3-star hotel. Recommend a network solution with hardwares and softwares in current trend that can be used in the hotel. Make necessary assumptions and justify your recommadation with logical arguments where possible.
Also set as:
- If you are assigned to design a LAN for Pulchowk Campus having 5 departments. Each department will have 100 computers locating in 5 rooms each equipped with 20 computers. Make your own justification while selecting connecting devices and accessories. (2067 Ashad Q2)
Explain the working principle of different types of network devices Repeater, HUB, Bridge, Switch and Router.
Also set as:
- Write short notes on: a) Network Security b) Router and Gateway (2068 Chaitra Q9)
What are the advantages of IPV6? The maximum payload segment is 65495 byte. Why was such strange number chosen?
Also set as:
- Explain in detail about IP frame format. (2067 Ashad Q8)
What are routing protocols? Explain open short path first (OSPF) process in link state routing.
Define routed and routing protocol. Explain RIP routing operation with is timer details.
What is adaptive and non-adaptive routing? List the properties of link state routing and mention the method that how Designated Router (DR) is elected in OSPF routing.
What is super-netting? Perform the subnetting of IPv4 address block 200.74.20.0/24 for five different departments having 4, 54, 120, 12 and 30 hosts. List out the network address, broadcast address, usable host range and wasted IP address in each subnet.
What is a bridge? How does it work? How can a bridge increase the throughout as compared with a repeater while extending a LAN? Explain with suitable diagrams.
What is unicast and multicast? Compare distance vector routing protocol and link state routing protocol with examples.
Why do we prefer a switch as networking device instead of Hub for LAN connection? Give reasons. Discuss the characteristics of a good routing algorithm.
Define routing algorithm. List out the properties/goals of routing algorithm. What is link state routing algorithm? Show how routing tables is populated in LSR with example.
What do you mean by autonomous system? Explain how routing loops are prevented in Distance Vector Routing with examples.
Mention the criteria for good routing. Explain RIP, OSPF, BGP, IGRP and EIGRP.
What is classful and classless address? Differentiate between link state and distance vector routing protocol.
Explain five instances of how networks are a part of your life today. Through we have MAC address, why do we use IP address to represent the host in networks? Explain your answer.
What is routed and routing protocol? Give examples. Explain Token Bucket algorithm.
What are the functions of network layer? Explain briefly about multicast routing protocols and unicast routing protocols.
Network layer is one of the key layers in OSI reference model, why? Differentiate between distance vector routing and static link routing.
Differentiate between adaptive and non-adaptive routing. Explain shortest path finding algorithm in link state routing.
Why is routing protocol necessary? Explain the working process of Routing Information protocol (RIP) with example.
What is a fragmentation and re-assembly? Explain about any intra-AS routing protocol.
Write short notes on (any two): a) UDP and its application b) Network Devices: Hubs, Switches and Routers c) IPv4 Header Structure
What is unicast and multicast routing? Describe the concept of optimality principle. Describe how the routers in its link state routing come into fully adjacency state.
Chapter 5 · Transport layer 23 distinct questions, from 26 of the 27 sittings
What are the features of UDP protocol? In which case is UDP preferred as a transport layer protocol? Discuss with practical examples.
Also set as:
- Explain the UDP segment structure. Illustrate your answer with appropriate figures. (2070 Chaitra Q6)
- Write short notes on (any two): a) UDP and its application b) Network Devices: Hubs, Switches and Routers c) IPv4 Header Structure (2066 Poush Q10)
Write UDP header field and functions. Explain TCP 3-way hand shaking for connection establishment and release.
Also set as:
- Though UDP is said to be unreliable protocol, it is used in Internet. Why? Explain the three way handshake principle of a TCP connection between client and server. (2081 Baishakh Q6)
How does the transport layer ensure that the complete message arrive at the destination and in the proper order? How does Token Bucket control the congestion over the Leaky Bucket algorithm?
Also set as:
- What are the major task of transport layer? Explain. What is token bucket algorithm? (2076 Chaitra Q6)
Write short notes on: (Any Two) a) Frame relay b) TCP sliding window c) HDLC
Also set as:
- Write short notes on (any two) i) TCP Sliding Window Protocol ii) Secrete Key Algorithm: DES iii) ISDN Signaling and ATM AAL iv) ICMP Message Types (2066 Bhadra Q5b)
Explain the TCP segment structure. Why TCP is known as reliable protocol and also describe how reliability is provided by TCP?
Also set as:
- Write short notes on: a) ALOHA system b) TCP header (2070 Ashad Q10)
What are the differences between TCP and UDP services? Explain the TCP datagram format in detail.
For the client-server application over TCP, why must the server program be executed before the client program? TCP is known as reliable process how, describe reliability is provided by TCP.
Also set as:
- What is a TCP connection? Explain how a TCP connection can be gracefully terminated. (2072 Kartik Q6)
Discuss UDP header and compare it with TCP. What is port address? Explain briefly about leaky-bucket algorithm used for traffic shaping.
Why TCP is known as reliable protocol? What are the congestion control techniques applied in network communication? Discuss Token Bucket approach and compare it with leaky bucket.
What is port number? Why is it necessary to standardize the port numbers for well-known servers? What happens when a web service is hosted at some different port such as 8765 instead of 80? Explain.
What are services provided by Transport layer? Explain about Leaky-Bucket algorithm for congestion control?
Explain connection establishment and termination in TCP. Explain briefly about Leaky-Bucket algorithm for congestion control?
How connection is established and released in TCP. Explain Token Bucket algorithm.
Explain the TCP protocol with its Header. What do you understand by socket? Explain with its importance.
Discuss about the network congestion? Explain how different network parameters effect the congestion. Compare operation of link state routing with the distance vector routing.
What is routed and routing protocol? Give examples. Explain Token Bucket algorithm.
Why port number is used in networking? What are the services of transport layer? Differentiate between TCP and UDP protocol.
Distinguish between TCP and UDP. How is TCP connection established? Explain.
Compare between leaky bucket and token bucket algorithm with the operation how token bucket works.
Why do you think that there exist two protocols in transport layer where as there exists only one protocol in Internet layer in TCP/IP reference model. Explain token bucket algorithm for congestion control.
What are the functions of transport layer? Draw the segment structure of TCP.
Describe the policies that help in preventing the congestions within the network? Differentiate between leaky bucket and token bucket algorithm with their operation and working of token bucket.
What are the factors that cause congestion within WAN? Propose your best traffic shaping approach to manage congestion in packet switched network.
Chapter 6 · Application layer 13 distinct questions, from 24 of the 27 sittings
Compare DNS recursive query vs. iterative query. Explain iterative query for browsing www.youtube.com
Also set as:
- What is DNS server? Explain the recursive and iterative query. (2080 Baishakh Q7)
- What is DNS? Why is it used? How is the DNS request from a client computer resolved from the authoritative server? Explain with necessary diagrams. (2079 Bhadra Q7)
- What are resource records in DNS? Explain the types of DNS queries with example. (2078 Bhadra Q7)
- What is recursive and iterative query? Explain with suitable diagram. Discuss the DNS records. (2074 Ashwin Q7)
- What is DNS? Explain the structure of DNS request and response with practical example. (2071 Chaitra Q7)
Which protocols are used in sending and receiving an email? Illustrate with necessary figure. Give a comparison of POP3 and IMAP.
Also set as:
- Write short notes on: (Any two) a) SMTP and POP b) Diffie Hellman’s Algorithm c) CSMA/CD d) DLL Flow Control Mechanisms (2074 Ashwin Q10)
- What are the different components of email server? Explain different types of electronic mail sending and accessing protocol. (2072 Kartik Q7)
- SMTP is a text based protocol and uses 7 bit ascii. How can this be used to transmit sometimes like images? Explain. (2071 Shrawan Q7)
- What do you mean by email server? What are the protocols used on it? (2070 Chaitra Q7)
- How the protocol SMTP does operate? Explain the procedures to make your network secured. (2067 Ashad Q10)
Write Short Notes on: (Any Two) a) 802.5 Token Ring b) PGP c) Socket programming fundamentals d) X.25 Network
Also set as:
- Write Short notes on: (Any Two) a) 802.4 Token Bus b) Framing with bit stuffing c) Server Socket programming for bind, listen and accept d) ATM (2081 Bhadra Q10)
- Write short notes on: (any two) i) Types of firewals ii) FDDI iii) Socket programming (2074 Chaitra Q10)
What do you mean by DNS delegation? List the step-by-step working principle of SMTP.
Also set as:
- What is DNS? Explain the working principle of DNS with a proper diagram. Compare IMAP and POP3 protocols. (2076 Chaitra Q7)
- Write short notes on: a) Simple Mail Transfer Protocol b) Doman Name Server (2072 Chaitra Q10)
Define socket programming. How web server communication and file server communication are possible in network. Explain with used protocols.
Also set as:
- How web server communication and file server communication are possible in network, explain with used protocols. Define socket programming. (2073 Shrawan Q6)
Write short notes on: i) HDLC ii) Web Server
Also set as:
- What is HTTP protocol? With an example explain how a request initiated by a HTTP client is served by a HTTP server. (2069 Chaitra Q7)
How does a DNS recursive query work? Discuss DHCP lease renew process with example diagram.
What is a proxy server? Why is it used? Discuss briefly on HTTP and HTTPS services.
How does an FTP client connect to an FTP server? Compare POP3 and IMAP protocols.
What is TFTP? Explain working principle of FTP with data transfer process including proper port connection. Use proper diagram to justify your answer.
Why we need proxy servers? What are the importance of DNS and HTTP(S) while you are browsing any website?
Why do we need RAID in the computer networks? Define and discuss the differences between RAID 0, RAID 1 and RAID 5.
What is the function of proxy server? Explain about electronic mail.
Chapter 7 · Introduction to IPv6 9 distinct questions, from 24 of the 27 sittings
What are the advantages of IPv6? Briefly explain the different transition strategies.
Also set as:
- What are the problems of IPV4? How can IPV6 reduce these problems? Explain header translation mechanism for transition from IPV4 to IPV6. (2079 Bhadra Q8)
- List advantages of IPv6 over IPv4. Explain any two suitable transition strategies for IPv4 to IPv6. (2078 Bhadra Q8)
- List the advantages of IPv6 over IPv4. Explain any two transition strategies for IPv4 to IPv6. (2076 Ashwin Q8)
- What are the factors that lead to the speedy development of IPv6? Define the process of transition from IPv4 to IPv6. (2074 Chaitra Q8)
- List the advantages of IPv6 over IPv4. Explain header translation and tunneling approach used for migrating IPv4 to IPv6. (2074 Ashwin Q8)
- What are the factors that lead to the development of IPv6? Define the process of transition from IPv4 to IPv6. (2073 Shrawan Q7)
- What is IPV6? What methods are used so that IPV6 and IPV4 networks are interoperable? (2072 Kartik Q8)
- What are the problems of IPv4? How IPv6 reduce these problems? Explain different strategies to transit from IPv4 and IPv6. (2071 Chaitra Q8)
Critically compare IPv4 and IPv6 in terms of routing and head manipulation. Explain the importance and implementation approach of 6RD for IPv6 based services on the existing IPv4 networking.
Also set as:
- Compare the IPv4 header with IPv6 header. Explain the dual stack strategy to transit from IPv4 to IPv6. (2081 Baishakh Q8)
- What are the methods used to interoperate IPv6 and IPv4. Show IPv6 datagram format. (2075 Ashwin Q8)
- Compare the header fields of IPV6 and IPV4. Which method do you suggest for the migration of IPv6 and why? (2072 Chaitra Q7)
Write short notes on: (Any Two) a) Go Back-N ARQ b) Dual Stack method in IPv6 c) Diffie-Hellman algorithm d) ATM
Also set as:
- "IPv4 and IPv6 coexistence" what does this mean? Explain Dual stack approach with an appropriate figure. (2076 Chaitra Q8)
- “IPv4 and IPv6 coexistence” what does this mean? Explain what you mean by address family translation in IPv4/IPv6 migration process with an appropriate figure. (2075 Chaitra Q8)
What are the drawbacks in IPV4? Which of these drawbacks do IPV6 solve? Explain.
Also set as:
- What are the major problems with existing IPv4 network? Explain IPv4 addressing and sub-netting with example. (2070 Ashad Q9)
- What are the advantages of IPV6? The maximum payload segment is 65495 byte. Why was such strange number chosen? (2068 Baishakh Q7)
Explain the IPv6 datagram format with appropriate figures.
Also set as:
- Explain the IPv6 datagram format and the function of each field with necessary figure. (2069 Chaitra Q8)
List the IPv6 extension headers in order. Explain ISATAP and 6 to 4 tunneling with their address format for IPv4 to IPv6 transition.
Map IPv4 addresses with its IPv6 equivalent. What are the latest best IPv6 transition methodologies? Explain anyone of them.
Explain the three address types in IPv6 with the IP notations. How does on IPv6 machine acquire IPv6 address automatically?
Give the reason why the current world is moving to IPv6 addressing mechanism. Describe the IPv6 address types with its representation format. You are given the IPv4 address block 203.71.53.0/26; assign the IP subnet for the following network. [Figure, as text: Net A: 6 Hosts (LAN on router R1); Net B: 2 Hosts (link R1 to R2); Net C: 12 Hosts (LAN on router R2); Net E: 2 Hosts (link R2 to R3); Net F: 29 Hosts (LAN on router R3). The routers are unlabelled in the print and no Net D is drawn.]
Chapter 8 · Network security 28 distinct questions, from 26 of the 27 sittings
Write short notes on: (Any two) a) Firewall and their types b) 803 Token Bus c) Virtual circuit switching
Also set as:
- Write short notes on: (any two) i) Types of firewals ii) FDDI iii) Socket programming (2074 Chaitra Q10)
- What do you mean by firewall? Explain different types of firewall. (2073 Shrawan Q9)
- Explain briefly how firewalls protect network and also explain different types of Firewall. Illustrate your answer with appropriate figures. (2072 Chaitra Q8)
What is public key cryptography? Encrypt the word "security" using the RSA algorithm. Also show the decryption to obtain the plaintext.
Also set as:
- Compare symmetric key encryption method with asymmetric key encryption. Explain RSA algorithm with example. (2073 Shrawan Q8)
- What is public key cryptography? Explain about RSA algorithm in detail. (2071 Chaitra Q9)
- Compare symmetric key encryption method with asymmetric key encryption. Describe the operation of RSA algorithm. (2069 Chaitra Q9)
Explain briefly the desirable properties of secure communication. Explain how packet filtering firewall works.
Also set as:
- What is network security? How can firewalls enhance network security? Explain how firewalls can protect a system. (2069 Chaitra Q10)
What do you mean by firewall? Encrypt and decrypt the “attack” using RSA.
Also set as:
- What is firewall? What are their types? Encrypt and decrypt "OVEL" message using RSA algorithm. (2072 Kartik Q9)
What are the fundamental difference between AES and DES? Encrypt the word “ComNet” using anyone suitable AES technique.
Also set as:
- Write short notes on (any two) i) TCP Sliding Window Protocol ii) Secrete Key Algorithm: DES iii) ISDN Signaling and ATM AAL iv) ICMP Message Types (2066 Bhadra Q5b)
What are the properties of secure communication? Use RSA algorithm to encrypt and decrypt the message "network".
Also set as:
- List the properties of secure communication. Encrypt and decrypt “ROSE” using RSA algorithm. (2076 Ashwin Q9)
Write short notes on: (Any Two) a) Go Back-N ARQ b) Dual Stack method in IPv6 c) Diffie-Hellman algorithm d) ATM
Also set as:
- Write short notes on: (Any two) a) SMTP and POP b) Diffie Hellman’s Algorithm c) CSMA/CD d) DLL Flow Control Mechanisms (2074 Ashwin Q10)
What is a digital signature? Encrypt the message "PANDEMIC" using RSA algorithm. Also obtain the plaintext from the ciphertext.
Also set as:
- How does a Digital Signature work? Encrypt the world HELLO using RSA algorithm. Also decrypt it by showing steps. (2076 Chaitra Q9)
Write down the steps involved in RSA encryption algorithm. Encrypt the word "Computer" using RSA algorithm.
Also set as:
- Write down the steps involved in RSA encryption algorithm. Encrypt the word CAT using RSA algorithm, choose the suitable data for encryption by yourself according to RSA algorithm. (2072 Chaitra Q9)
Write short notes on: a) Network Security b) Router and Gateway
Also set as:
- How the protocol SMTP does operate? Explain the procedures to make your network secured. (2067 Ashad Q10)
Write short notes on: (Any Two) a) ARP and NDP b) AH and ESP c) VPN d) vLAN
What is router ACL? How do you apply ACL to block the IP network 202.70.91.0/24 incoming to interface Fast Ethernet of a router? Encrypt the word “ISPNet” using anyone suitable AES technique.
Write Short Notes on: (Any Two) a) 802.5 Token Ring b) PGP c) Socket programming fundamentals d) X.25 Network
Write short notes on: (Any Two) a) MAC sublayer b) Digital signature c) Firewall
What is PGP? Use RSA algorithm to encrypt/decrypt the word COW.
Write short notes on: (Any Two) a) VLAN b) ARP c) IPSec
Write short notes on: (Any Two) a) ALOHA b) OSPF c) VPN
Write short notes on: (Any two) a) Digital Signature b) VPN c) Symmetric key cryptography
What is VPN? Encrypt a message "network" using RSA algorithm.
Define type of Encryption used in security. How PGP can secure email communication?
Write short notes on: a) Digital signature b) IPSec
What is network security? Explain Virtual Private Network (VPN) with an example.
Write short notes on: a) SSL b) WEP
What is cryptography? Differentiate between symmetric key and public key cryptography.
Write short notes on: (any two) a) WEP b) IDS c) SSL
What do you mean by Network security? Explain the operation of Data Encryption Standard Algorithm?
What is a secure socket layer? Encrypt the message “DANGER” using RSA algorithm.
How can we maintain the security within the communication network? Explain any one cryptography algorithm with example.
392 cards · 127 definitions and 265 exam questions · what you miss comes back sooner
Flashcards
The definitions and every question the papers have asked, one at a time. Mark yourself honestly: a card you knew moves up a box and waits twice as long, a card you did not drops to box one and comes back before you leave the page. Your boxes are saved in this browser, and nothing leaves the device.
How this works
- Five boxes. A new card starts in box one. Knowing it moves it up; missing it sends it back to box one.
- The box sets the wait: one day, two, four, eight, then sixteen.
- A theory card shows the opening of the answer, the line to start with; its link opens the full answer.
- Saved in this browser only. Clearing site data resets it.
Space or Enter shows the answer, then 1 for not yet and 2 for knew it.
8 maps · 127 topics · 486 lists · 1729 items
Every chapter as one map
This is a theory paper, and theory marks are lost on “name the types”: you can explain a term and still go blank on the list. Each map opens whole: the chapter, its topics, every list and every member, with the size of each list beside its name. Press Close all and the items go while the names and counts stay, so “7 Stages of the Cyber Kill Chain” becomes a question. The canvas pans, zooms and goes full screen. Every map is built from the chapter cards themselves, so it always matches them.
How to use the maps
- Press anything to have it explained. A topic, a list or a single item opens a note beside the map; the arrow beside a topic opens its card.
- Close all turns the map into a test. Name the members of each list before you open it. Answering before you look is what moves a list into memory.
- The count is half the memory. Knowing there are six criteria tells you to keep going when you have named four.
- Drag to move, zoom with the buttons or ctrl and the wheel; Fit puts the whole chapter back on screen.
Drag to move · ctrl and wheel to zoom