CT 702 · BCT · Year IV Part I · 80 marks · 3 hours

Computer Network

A working reader for Computer Network, built from the syllabus, the Insights on Computer Networks book and every board paper on record: 27 sittings, 2066 Bhadra to 2082 Bhadra. Every topic is taught in full with drawn diagrams and an example to remember it by, every question the papers asked is answered in the words to write, and every calculation is worked with its numbers computed rather than typed.

27
sittings on record
269
questions, all answered
49
calculations worked
19
topics in a third of the papers
11 regular, 11 back, 5 both Attempt all questions Short notes: any two of four Pass 32 of 80

Where the marks areWhat the papers actually set, chapter by chapter

Each bar is a chapter's average share of an 80 mark paper over all 27 sittings, measured from the marks printed on every question (the syllabus gives hours, not marks). Chapters 4 and 8, Network layer and Network security, carry the most: about 17 and 11 marks a paper. Point at a chapter's name to see how many of the 269 questions touched it.

How to use this reader

  • Chapters 1 to 8 are the study content: each topic explained in plain language, with drawn diagrams, an example to remember it by, and at the foot of each card every question the papers set on it, word for word, with the part the card answers lit. The copy button on a card copies it to paste into Claude and ask about.
  • Theory answers give the exam answer to every question that asks what a thing is, why it matters or how two things compare, at the length its marks deserve.
  • Practical answers give the ones that ask how a thing works, step by step: CSMA/CD, the three-way handshake, sliding window, DNS resolution and the like.
  • Numericals work every calculation the papers set (subnetting, CRC, Hamming code, delays, efficiency, routing tables, RSA, the buckets), grouped by method, with the method once at the top of each group.
  • Summary gives every topic as the skeleton of its answer, for the last read before the exam, and ends with the Recall sheet: every topic again as bare keywords.
  • Compact chapters keep every detail of a chapter with the teaching prose taken out; one button copies a whole chapter to give Claude as context.
  • Question bank reproduces all 269 questions word for word, by paper or by chapter, each linked to its answer and its card.
  • Mind map draws each chapter as its lists; Close all turns it into a test. Flashcards drill the definitions and every question.

Writing the paper

  • About two minutes a mark: 180 minutes for 80 marks, so an 8 mark question gets about 16 minutes.
  • Most questions come in parts (2+6, 4+4, 2+3+3). Answer the parts in the order asked and give each its share of the time: a 2 mark definition is two or three lines.
  • Draw what has a drawing: the layer models, the header and frame formats, the CSMA/CD flowchart, the handshake, the switching and tunnelling pictures each earn marks.
  • Numericals show their working: the given values, the formula or the method, every step, then the answer in bold. A subnet plan is a table; a CRC is the long division.
  • The last question is short notes, any two of four, about 4 marks each: a definition, three or four points and a small diagram.

The 27 sittings, question by question

Each paper opens to its questions, the chapter each belongs to and the card that teaches it. The board repeats itself: OSI and TCP/IP, CRC, subnetting, CSMA/CD, routing, TCP and UDP, DNS and IPv6 come back paper after paper.

2082 Bhadraregular paper, 10 questions: Attempt All questions.
2082 Baishakhback paper, 10 questions: Attempt All questions.
2081 Bhadraregular paper, 10 questions: Attempt All questions.
QuestionChapterTaught onMarks
Q11What a computer network is, and what it is used for; The OSI reference model: seven layers and what each does; OSI and TCP/IP compared: similarities and differences2+6
Q22Transmission media: the kinds, and how to choose one; Datagram and virtual circuit: two ways to switch packets2+6
Q33Flow control: stop and wait, the sliding window and piggybacking; CRC: the cyclic redundancy check1+2+5
Q44Routing: what it is, what a good algorithm needs, static against dynamic; Link state routing: properties, five steps, and distance vector compared; OSPF: areas, DR and BDR, and the road to full adjacency2+2+4
Q54Classless addressing: CIDR and supernetting; Subnetting and VLSM: dividing a block with the least waste1+7
Q65TCP: the reliable byte stream, its segment header, and how reliability is provided; Congestion: causes, the parameters that affect it, prevention and control; The token bucket: saving up permission to burst2+2+4
Q76DNS: the Internet's distributed directory of names; Electronic mail: user agents, mail servers, SMTP, POP3, IMAP and MIME2+6
Q87The IPv6 datagram: a fixed 40-byte header, compared with IPv4; From IPv4 to IPv6: coexistence, dual stack, tunneling and translation4+4
Q98DES and AES: the symmetric block ciphers2+6
Q103, 6, 1Token bus (IEEE 802.4): a physical bus, a logical ring; Framing: character count, byte stuffing and bit stuffing; Socket programming: the calls, and a TCP server and client; ATM: fixed 53-byte cells, virtual paths and the adaptation layers2×4
2081 Baishakhback paper, 10 questions: Attempt All questions.
2080 Bhadraregular paper, 10 questions: Attempt All questions.
2080 Baishakhback paper, 10 questions: Attempt All questions.
2079 Bhadraregular paper, 10 questions: Attempt All questions.
2078 Bhadraregular paper, 10 questions: Attempt All questions.
2076 Chaitraregular paper, 10 questions: Attempt All questions.
2076 Ashwinback paper, 10 questions: Attempt All questions.
2075 Chaitraregular / back paper, 10 questions: Attempt All questions.
2075 Ashwinback paper, 10 questions: Attempt All questions.
2074 Chaitraregular paper, 10 questions: Attempt All questions.
2074 Ashwinback paper, 10 questions: Attempt All questions.
2073 Shrawannew back (2066 & later batch) paper, 10 questions: Attempt All questions.
2072 Chaitraregular paper, 10 questions: Attempt All questions.
2072 Kartiknew back (2066 & later batch) paper, 10 questions: Attempt All questions.
2071 Chaitraregular paper, 10 questions: Attempt All questions.
2071 Shrawannew back (2066 & later batch) paper, 10 questions: Attempt All questions.
2070 Chaitraregular paper, 10 questions: Attempt All questions.
2070 Ashadold back (2065 & earlier batch) paper, 10 questions: Attempt All questions.
2069 Chaitraregular paper, 10 questions: Attempt All questions.
2068 Chaitraregular / back paper, 9 questions: Attempt All questions.
2068 Baishakhregular / back paper, 10 questions: Attempt All questions.
2067 Ashadregular / back paper, 10 questions: Attempt All questions.
2066 Poushback paper, 10 questions: Attempt All questions.
2066 Bhadraregular / back paper, 10 questions: Attempt All questions.
QuestionChapterTaught onMarks
Q1a1Layered architecture: why network software is a hierarchy of layers; Data encapsulation: how headers and trailers are added and removed; OSI and TCP/IP compared: similarities and differences2+2+4
Q1b1Client/server and peer to peer: the two networking models; Active networking, compared with the traditional legacy network3+5
Q2a3The data link layer: functions, services and design issues; Framing: character count, byte stuffing and bit stuffing; Flow control: stop and wait, the sliding window and piggybacking2+3+3
Q2b2Bandwidth and channel capacity: Nyquist and Shannon4+4
Q3a3Ethernet (IEEE 802.3): the frame, MAC addresses, data transfer and cabling; Token bus (IEEE 802.4): a physical bus, a logical ring; Wireless LAN (IEEE 802.11): architecture, CSMA/CA and the physical layer5+3
Q3b2, 1Switching: circuit, message and packet; Frame Relay: fast virtual circuits at the data link layer2+6
Q4a4Unicast and multicast routing, and their protocols; Routing: what it is, what a good algorithm needs, static against dynamic; OSPF: areas, DR and BDR, and the road to full adjacency2+6
Q4b5Congestion: causes, the parameters that affect it, prevention and control; The token bucket: saving up permission to burst2+6
Q5a7, 4Why IPv6: the problems of IPv4 and what IPv6 fixes; IPv6 addresses: notation, types and autoconfiguration; Subnetting and VLSM: dividing a block with the least waste2+2+6
Q5b5, 8, 2, 1, 4Flow control and buffering: TCP's sliding window; DES and AES: the symmetric block ciphers; ISDN: one digital network for voice and data; ATM: fixed 53-byte cells, virtual paths and the adaptation layers; ICMP: the network layer's error reports and queries3+3

The whole subject on one page

Eight chapters and every topic card in them. The number beside a topic is how many of the 27 sittings asked it.

THE WHOLE SUBJECT ON ONE PAGE Every chapter and every topic card, with the number of the 27 sittings that asked it. Bold: 9 or more. CT 702 80 marks, 3 hours 1. Introduction 4 What a computer network is, and what... 1 Networks by size and geography 1 Network topologies 10 Client/server and peer to peer 1 Active networking, compared with the... 5 Protocols, standards and interfaces 9 Layered architecture 1 Services 8 The OSI reference model 4 The TCP/IP model 3 Data encapsulation 9 OSI and TCP/IP compared 0 The Internet 7 X.25 5 Frame Relay 3 ATM 0 Ethernet as an example network 0 VoIP 0 NGN 0 MPLS 0 xDSL 2. Physical layer 1 The physical layer 3 Delay, latency and throughput 1 Bandwidth and channel capacity 7 Transmission media 7 Twisted pair and coaxial cable, comp... 1 Optical fiber 5 Unguided media 0 Satellite communication 6 Multiplexing 13 Switching 6 Datagram and virtual circuit 2 The telephone network, and the T1 an... 0 Telecommunication switching systems 5 ISDN 3. Data link layer 8 The data link layer 10 Framing 1 Errors, detection against correction... 3 CRC 1 Hamming distance and the Hamming code 5 Flow control 4 Error control by ARQ 2 HDLC 0 PPP 7 The MAC sublayer and the channel all... 6 ALOHA 1 CSMA 9 CSMA/CD 0 Controlled access 0 Channelization 0 The IEEE 802 family of LAN standards 4 Ethernet (IEEE 802.3) 5 Token bus (IEEE 802.4) 4 Token ring (IEEE 802.5) 3 FDDI 3 Wireless LAN (IEEE 802.11) 3 Virtual LANs and IEEE 802.1Q, with a... 4. Network layer 1 The network layer 4 Internetworking devices, layer by la... 1 Bridges 5 IPv4 addresses 24 Subnetting and VLSM 2 Classless addressing 0 NAT 5 The IPv4 datagram 4 ARP and RARP 5 ICMP 13 Routing 0 The routing table, and forwarding wi... 1 Dijkstra's shortest path algorithm... 0 Flooding 10 Distance vector routing, count to in... 11 Link state routing 0 Hierarchical routing 4 Routing protocols 2 RIP 5 OSPF 0 BGP 3 Unicast and multicast routing, and t... 2 Designing a network for a real site 5. Transport layer 5 The transport layer 0 Services to the upper layer 6 UDP 9 TCP 6 TCP against UDP, and why the transpo... 4 Ports and sockets 7 Opening and closing a TCP connection 2 Flow control and buffering 0 Multiplexing and demultiplexing 4 Congestion 5 The leaky bucket 9 The token bucket 6. Application layer 0 The application layer 5 HTTP and HTTPS 4 FTP and TFTP 0 Remote login and secure transfer 11 Electronic mail 11 DNS 1 DHCP 0 Peer-to-peer applications 5 Socket programming 3 Proxy servers and web caching 0 Web, mail and DNS server optimization 1 RAID 0, RAID 1 and RAID 5 0 SNMP 0 Traffic graphers 0 Wireshark and Packet Tracer 7. IPv6 13 Why IPv6 6 The IPv6 datagram 1 Extension headers 3 IPv6 addresses 0 IPv6 multicasting 18 From IPv4 to IPv6 8. Network security 11 Network security and the properties... 8 Cryptography 0 Classical ciphers 4 DES and AES 16 RSA 2 Diffie-Hellman key exchange 5 Digital signatures 3 PGP 3 SSL and TLS 3 IPsec 5 VPN 2 Securing wireless LANs 13 Firewalls 1 Intrusion detection systems

How to read the chips

ChipMeans
TOP n/27Asked in 9 or more of the 27 sittings.
HOT n/27Asked in 5 to 8.
PIN n/27Asked in 1 to 4.
No chipA syllabus topic no paper has asked yet: taught, summarised and recalled like the rest.
2+6The marks the question has carried.

Under each chip is the list of sittings that asked it: 81 Bh is the 2081 Bhadra regular paper (bold, a regular sitting); 81 Ba is the 2081 Baishakh back paper.

Chapter 1 · 5 hours · about 10 marks a paper · in 26 of the 27 sittings

Introduction to computer network

What a computer network is and what it is for, how the work is shared out (client/server, peer to peer, active networks), and how network software is built as a stack of layers, described by the OSI and TCP/IP models; then the classic example networks: the Internet, X.25, Frame Relay, ATM, Ethernet, VoIP, NGN, MPLS and xDSL. Question 1 of the paper came from this chapter in 25 of the 27 sittings on record, so it is the first answer written in the hall.

What this chapter is about
  • Networks and their uses: the definition, the uses at work, at home and on the move, the sizes from PAN to WAN, and the topologies from bus to mesh.
  • Networking models: client/server against peer to peer, and the active network against the legacy, passive one.
  • Protocols and layers: what a protocol and a standard are, why network software is a hierarchy of layers, the design issues every layer faces, and the services a layer offers.
  • The two reference models: the seven OSI layers, the four TCP/IP layers, encapsulation with headers and trailers, and the comparison the board sets most often.
  • Example networks: the Internet, X.25, Frame Relay, ATM, Ethernet, VoIP, NGN, MPLS and xDSL, with X.25 against Frame Relay and Frame Relay against ATM.
Where it fits
  • Every later chapter is one layer: the physical layer in chapter 2 (physical layer), the data link layer in chapter 3 (data link layer), the network layer in chapter 4 (network layer), the transport layer in chapter 5 (transport service) and the application layer in chapter 6 (HTTP).
  • The example networks lean on chapter 2: X.25, Frame Relay and ATM are virtual circuit networks (datagram and virtual circuit), and xDSL is set beside ISDN (ISDN).
  • Ethernet is introduced here and taught in full in chapter 3 (Ethernet); the protocols each layer uses (IP, TCP, UDP, DNS) are taught in their own chapters.
What you will learn
  1. 1.1 Computer networks: uses, sizes and topologies
  2. 1.2 Networking models: client/server, peer to peer, active networks
  3. 1.3 Protocols and standards, layered architecture, services
  4. 1.4 The OSI and TCP/IP models, and data encapsulation
  5. 1.5 OSI and TCP/IP compared
  6. 1.6 Example networks: the Internet, X.25, Frame Relay, ATM, Ethernet, VoIP, NGN, MPLS, xDSL
  7. 1.7 Last minute recall, chapter 1
How it is examined
  • Client/server against peer to peer is the most asked topic (10 sittings): define, draw, compare in a table, add advantages and disadvantages.
  • Layered architecture (9) and OSI against TCP/IP (9) come next, then the OSI layers with their functions (8) and X.25 (7); protocol and Frame Relay have 5 sittings each.
  • Draw the two stacks side by side, the protocol hierarchy with its headers, the client/server and P2P sketch, the X.25 packet, the Frame Relay frame and the ATM cell.

1.1Computer networks: uses, sizes and topologies

What a computer network is, and what it is used for PIN 4/27

81 Bh · 72 Ch · 71 Shr · 66 Po2+65+3

Computer network A collection of autonomous computers and other devices (nodes) interconnected by communication links and following common protocols, so that they can exchange data and share resources. The links may be copper wire, optical fibre, radio, microwave, infrared or satellite.

Autonomous is the word to keep. Each computer can work on its own; the network only lets them talk. A mainframe with dumb terminals is not a network in this sense, because a terminal can do nothing alone. Two computers are interconnected when they can exchange information, whatever the medium between them.

Every network has four parts:

  • Nodes: end systems (hosts) that run the applications, such as laptops, phones and servers, and the intermediate devices that move data between them: switches, routers and access points (devices).
  • Links: the transmission media: twisted pair, coaxial cable, optical fibre, radio (media).
  • Protocols: the rules both ends follow to understand each other (protocols).
  • Services: what the users finally get: the web, mail, file sharing, voice and video calls.

Three criteria judge a network: performance (throughput and delay, see chapter 2), reliability (how often it fails and how quickly it recovers) and security (protection of the data against unauthorised access and damage, chapter 8).

The uses of computer networks, under the book's three headings, with the effect on society added:

WhoUseWhat the network makes possible
BusinessResource sharingmany PCs share one printer, scanner, database or internet line, wherever they are
BusinessHigh reliabilityfiles replicated on two or more machines: if one fails, another copy is used
BusinessSaving moneycheap PCs working as clients of a few servers replace one costly mainframe
BusinessScalabilitywhen the load grows, another server or PC is added instead of replacing the whole system
BusinessCommunication and e-commerceemail, video meetings, and orders placed electronically with suppliers and customers
HomeAccess to remote informationthe web, news, online banking, exam results
HomePerson to person communicationchat, voice and video calls, cheaper and faster than ordinary phone calls
HomeInteractive entertainmentvideo on demand, multiplayer games, social networking
HomeE-commerce and online educationpaying bills, sending money, shopping; online classes, notes and assignments
Mobile usersAnywhere accessphones and laptops on Wi-Fi or 4G send mail, browse, use maps, reach remote files and log on to remote machines
SocietyPublic services, and new problemse-government and online public services; also loss of privacy, misinformation, fraud such as phishing, and copyright disputes

Five instances of networks in a student's day (the 2072 Chaitra paper asks for exactly five):

  1. Paying by phone: scanning a fonepay QR code at the canteen or loading an eSewa or Khalti wallet: the app is a client talking to the bank's server over mobile data.
  2. Calling family: a WhatsApp or Viber video call to a relative working abroad travels as IP packets (VoIP), for the price of the data instead of an international call.
  3. Studying: online classes, notes shared in the class group, and exam results checked on the exam board's website.
  4. Entertainment: a YouTube video streamed on demand, or an online multiplayer game whose moves must arrive within milliseconds.
  5. Daily services: booking a Pathao or inDrive ride (the phone's GPS position sent over mobile data), or paying the NEA electricity bill online instead of queuing at the office.

To remember the idea, picture a hostel kitchen: every student can cook alone (autonomous), but sharing one gas cylinder and one fridge (resources) works only with agreed rules about turns and shelves (protocols). The hostel Wi-Fi is the same thing in network form: one fibre line from the ISP shared by every room.

Asked on the paper, word for word
  • Define Network. List a function of each layer of OSI reference model and compare it with TCPI/IP model. 2081 Bhadra Q1 · 2+6
  • Explain five instances of how networks are a part of your life today. Through we have MAC address, why do we use IP address to represent the host in networks? Explain your answer. 2072 Chaitra Q2 · 5+3
  • What is computer network? Distinguish between OSI and TCP/IP reference model. 2071 Shrawan Q1 · 2+6
  • Define network and protocol for network. Explain peer-to-peer network process with example. 2066 Poush Q1 · 2+6
In the exam "Define network" (2 marks): the definition with "autonomous" and "share resources", the four parts in one line, one example. "Five instances" (5 marks): five numbered uses, each naming the network service behind it (client/server, VoIP, streaming).

Networks by size and geography: PAN, LAN, MAN and WAN PIN 1/27

70 Asa3+5

Types of network by size Networks are classified by the area they cover: a personal area network (PAN) around one person, a local area network (LAN) in a room, building or campus, a metropolitan area network (MAN) across a city, and a wide area network (WAN) across a country or continent. Networks joined by routers form an internetwork; the Internet is the largest.

Distance decides almost everything else. Over a few metres a cheap radio is enough. Inside one building an organisation can lay its own cable, so a LAN is privately owned, fast and nearly error free. Across a country nobody lays private cable: the links are leased from telecom carriers, cost more per bit and add delay. So the size of a network fixes its owner, its speed, its delay and its error rate.

TypeSpanOwnerSpeed and delayTechnologyExample
PANabout 1 to 10 mone personlow data rate, tiny delayBluetooth, USB, NFCearbuds and a smartwatch paired with a phone
LANa room, building or campus, up to a few kmone organisation (private)high: 100 Mbps to 10 Gbps and more; very low delay and error rateEthernet (IEEE 802.3), Wi-Fi (IEEE 802.11)a college computer lab, a hostel Wi-Fi
MANa city, roughly 10 to 50 kman ISP, a cable operator or a city bodyhigh, usually over fibrefibre rings, Metro Ethernet, cable TV networks, WiMAX (IEEE 802.16)an ISP's fibre ring joining its exchanges across the Kathmandu valley
WANa country or a continent: hundreds to thousands of kmtelecom carriers; users lease capacitylower speed for the money, higher delayleased lines, X.25, Frame Relay, ATM, MPLS, satellitea bank linking its head office with branches all over Nepal
Internetworkworldwidemany ownersvariesrouters joining unlike networks, TCP/IPthe Internet

The WAN's structure. A WAN joins hosts through a communication subnet: switching elements (routers) joined by transmission lines. Packets travel store and forward: each router receives a whole packet, stores it, then sends it on along the next line (switching). The hosts belong to the users; the subnet usually belongs to a carrier or an ISP.

Two other ways to classify networks:

  • By transmission technology: broadcast networks share one channel that every machine hears (classic Ethernet, Wi-Fi), so an address in each frame says whom it is for; point-to-point networks join pairs of machines, so a packet may cross several intermediate nodes on its way (most WANs).
  • By architecture and shape: client/server or peer to peer (networking models); bus, star, ring or mesh (topologies).

To remember it, follow one video call outwards: earbuds paired with the phone (PAN), the phone on the hostel Wi-Fi (LAN), the hostel on the ISP's fibre ring across the valley (MAN), the ISP's links across the border to the rest of the world (WAN), and all of them together (the Internet).

Reading the 2070 Ashad question. It asks for "the types of network topologies based on its size and geographical distributions". Size and geography classify networks, not topologies, so the answer is PAN, LAN, MAN and WAN (and the internetwork); the shapes (bus, star, ring) belong to its first part, on topology.
Asked on the paper, word for word
  • How do you define network topology? Discuss the types of network topologies based on its size and geographical distributions. 2070 Ashad Q2 · 3+5
In the exam A table of the four types with span, owner, speed, technology and an example, then one line each on the WAN's subnet and on internetworks.

Network topologies: bus, star, ring, mesh, tree and hybrid PIN 1/27

70 Asa3+5

Network topology The arrangement of the nodes and the links that connect them. The physical topology is the actual layout of the devices and cables; the logical topology is the path the signals or data actually follow from one node to another.

Physical and logical can differ. A classic Ethernet hub is wired as a star but behaves as a bus, since every frame it receives is repeated out of every port; a Token Ring is wired as a star into a central access unit, yet the token travels round it as a ring.

NETWORK TOPOLOGIES How the nodes and links are arranged; the physical layout and the logical signal path can differ. Bus one shared backbone: cheap, least cable; one break stops the whole network Star a cut link loses only one node; a failed switch stops every node Ring one way round; a token gives turns; one break or dead node stops the ring Mesh every pair linked: n(n-1)/2 links; robust and private, but costly to cable Tree stars in a hierarchy under a root; root fails: the branches are cut off Hybrid two topologies joined, star and ring; flexible, but complex to design terminator switch one way root switch switch star ring backbone
TopologyHow it is builtMeritsDemeritsExample
Busone backbone cable; nodes tapped on with drop lines; a terminator at each end stops reflectionsleast cable, cheap, easy to add a nodea break in the backbone stops everything; collisions; faults hard to locate; limited length and number of nodesearly coaxial Ethernet (10BASE5, 10BASE2)
Starevery node has its own link to a central hub or switcha cut link loses one node only; easy to add, remove and troubleshootthe central device is a single point of failure; more cable than a bustoday's switched Ethernet LAN; a home Wi-Fi router
Ringeach node joined to the next, the last back to the first; data goes one way round and each node repeats itno collisions (a token gives turns); equal access; predictable delayone break or one dead node stops the ring (a dual ring, as in FDDI, survives one); adding a node breaks the ringIEEE 802.5 Token Ring, FDDI
Meshevery node joined to every other by a dedicated linkrobust: no single point of failure; a link carries no one else's traffic; private; faults easy to isolatecables and ports grow with the square of the number of nodes: costly and bulkylinks between core routers (usually a partial mesh)
Treestars joined in a hierarchy below a root: a star of starsgrows easily; a branch can be isolatedif the root or a backbone link fails, the branches below are cut offa campus: core switch, building switches, floor switches
Hybridtwo or more topologies joinedeach part uses the shape that suits itcomplex to design and managebuildings on a fibre ring, each building a star

The mesh formula. A full mesh of n nodes needs one link for every pair, and every node needs n−1 ports:

L=n(n−1)2
Worked example: six PCs in a small office

A full mesh needs 6×5/2=15 cables and 5 ports in every PC. A star needs 6 cables and one 8-port switch. A bus needs one cable with six taps. That is why LANs are stars, and only a few core routers are joined in a (partial) mesh.

To remember them, think of how a village gets its water: a bus is one pipe along the road with every house tapped onto it (cut the pipe and the whole lane is dry); a star is a tank with a separate pipe to each house; a ring is a loop main round the village; a mesh is a pipe from every house to every other house: nothing ever runs dry, and nobody can afford it.

Asked on the paper, word for word
  • How do you define network topology? Discuss the types of network topologies based on its size and geographical distributions. 2070 Ashad Q2 · 3+5
In the exam Define topology with physical against logical, draw the six small sketches, and give one merit and one demerit of each; quote the mesh formula.

1.2Networking models

Client/server and peer to peer: the two networking models TOP 10/27

82 Ba · 81 Ba · 80 Bh · 78 Bh · 76 Ash · 75 Ch · 74 Ch · 70 Ch · 66 Po · 66 Bh3+54+42+6

Networking model How work and resources are divided among the computers of a network. In the client/server model dedicated servers provide services and clients request them; in the peer to peer (P2P) model every computer is an equal peer, acting as both client and server and sharing its resources directly with the others.
CLIENT/SERVER AND PEER TO PEER Left: fixed roles, one server answers many clients. Right: equal peers, each both client and server. CLIENT/SERVER Server always on, holds the data Client laptop browser Client phone app Client ATM terminal request reply Clients start every exchange; the server only answers. If the server fails, every client stops. PEER TO PEER Peer A client and server Peer B client and server Peer C client and server Peer D client and server Every peer requests and serves; no central server. Each new peer adds capacity as well as demand.

Client/server architecture. Each computer or process on the network is either a client or a server. A server is a powerful, always-on machine (or process) that holds the data and the programs: a web, mail, file, database or print server. Clients are the users' machines that ask for its services. Every exchange involves two processes, one on the client machine and one on the server machine.

How the client/server model works: request and reply.

  1. The server waits: the server process starts first and listens on a known address and port (a web server on port 80 or 443).
  2. The client requests: the client process sends a request message across the network, and waits.
  3. The server processes: it receives the request and does the work: reads a file, queries a database, checks a password.
  4. The server replies: it sends the reply message back.
  5. The client uses the reply: the waiting client shows the result; the server goes back to serving others.

Opening a web page works exactly so: the browser on a laptop is the client, the remote web server is the server.

Features of the client/server architecture:

  • Asymmetric roles: clients always start the conversation and servers only respond; one server serves many clients at once (many to one).
  • Centralised resources and data: files, databases and applications live on the server, so everyone works on one up-to-date copy.
  • Centralised administration and security: user accounts, access rights, backups and updates are managed in one place, by an administrator.
  • Dedicated, powerful server: server hardware and a network operating system (Windows Server, Linux), switched on all the time.
  • Scalability: clients can be added freely; capacity grows by upgrading the server or adding servers that share the load.
  • Location transparency: the client needs only the server's name or address, not where or how the data is stored.
  • Tiers: two-tier (client and database server) or three-tier (client, application server, database server), as in online banking.

The peer to peer model. A P2P network is created when two or more PCs or devices connect and share their resources without a separate server computer. Each peer has equivalent capabilities and responsibilities: it stores data on its own disk and can share it with every other peer, so it is a client and a server at the same time.

The P2P process, as a file sharing system runs it:

  1. Join: a new peer contacts a few known peers, a tracker or a bootstrap node; in a small workgroup it simply announces itself on the LAN.
  2. Search: it asks for a resource by flooding a query to its neighbours, by asking an index (hybrid P2P), or by looking it up in a distributed hash table (chapter 6 covers the P2P applications).
  3. Connect directly: it opens connections straight to the peers that hold the resource.
  4. Exchange: it downloads pieces from many peers at once, and uploads the pieces it already has to others.
  5. Leave: when it goes offline its resources leave with it; the rest carry on.

Kinds of P2P: pure (no central element at all, as in Gnutella), hybrid (a central index or tracker only finds the peers and the transfer is peer to peer, as in Napster and BitTorrent with a tracker), and the simple workgroup of a small office or home.

Examples: BitTorrent, where a large file is cut into pieces and every downloader also uploads; a Windows workgroup of four PCs sharing folders and one printer; phone to phone sharing apps such as SHAREit and Nearby Share, which send a file over a direct Wi-Fi link; and blockchains such as Bitcoin, where every node keeps its own copy of the ledger.

The two models compared (the board's favourite question):

BasisClient/serverPeer to peer
Rolesfixed: servers serve, clients requestevery peer is both client and server
Central serverone or more dedicated serversnone (at most an index or a tracker)
Datastored centrally on the serverspread over the peers' own disks
Administration and securitycentral: one administrator, strong controleach user runs a machine: weak, uneven control
Backupcentral and simplemachine by machine, often skipped
Costhigh: server hardware, server OS, administratorlow: ordinary PCs, no server
Scalabilitylimited by the server: more clients slow it unless it is upgradedself-scaling: each new peer adds capacity as well as demand
Reliabilitythe server is a single point of failureno single point of failure, but a peer that leaves takes its files with it
Performancefast and predictable while the server copes; a bottleneck under loaddepends on the peers; a popular file gets faster as more peers hold it
Suited tolarge networks: banks, the web, mail, online servicessmall networks (about ten PCs), file sharing, spreading large files
Examplebrowser and web server; an ATM and the bank's serverBitTorrent; a home workgroup
ModelAdvantagesDisadvantages
Client/servercentral control of data, users and security; easy backup and recovery; one up-to-date copy of the data; grows by upgrading or adding servers; clients can be cheapcostly server, server software and administrator; the server is a single point of failure, and a bottleneck when overloaded; traffic piles up at the server
Peer to peercheap: no server and no administrator; easy to set up; no single point of failure; capacity grows as peers joinweak security and no central control; no central backup; data scattered and duplicated; a peer that is off takes its files with it; slow when the shared PCs are busy

To remember the difference: client/server is a restaurant: the customers (clients) order, one kitchen (the server) cooks for everyone, and if the kitchen closes nobody eats. Peer to peer is a class picnic where every friend brings one dish: everyone brings and everyone eats, more friends mean more food, but nobody is in charge if a dish goes bad.

Asked on the paper, word for word
  • Explain client/server and P2P network model with their advantages and disadvantages. Discuss the layer of TCP/IP model with suitable diagram. 2082 Baishakh Q1 · 4+4
  • What is a protocol? List out the common protocols used at each layer of TCP/IP model. Differentiate between client-server is P2P network. 2081 Baishakh Q1 · 1+3+4
  • Differentiate between Client Server and Peer to Peer architecture. Discuss the functions of each layer of Open System Interconnection (OSI) model. 2080 Bhadra Q1 · 3+5
  • How does the client-server model work? Differentiate it with peer-to-peer network with advantages and disadvantages. 2078 Bhadra Q1 · 3+5
  • What are the features of Client/Server Architecture? What are headers and trailers and how do they get added and removed? 2076 Ashwin Q1 · 4+4
  • Draw the architecture for Client/Server network model. Explain in details about P2P network model with supportive examples. 2075 Chaitra Q1 · 2+6
  • Distinguish between Client-Server network and Peer-Peer network. Explain Open System Interconnection (OSI) model. 2074 Chaitra Q1 · 3+5
  • What are the features of Client/Server Architecture? What are headers and trailers and how do they get added and removed? Explain. 2070 Chaitra Q1 · 4+4
  • Define network and protocol for network. Explain peer-to-peer network process with example. 2066 Poush Q1 · 2+6
  • What is client/server networking? Explain Active Networking model framework comparing with traditional legacy network. 2066 Bhadra Q1b · 3+5
In the exam Draw the two sketches, then the comparison table (six to eight rows), then advantages and disadvantages. "How does client/server work" wants the request and reply steps; "P2P with examples" wants the process and BitTorrent or a workgroup.

Active networking, compared with the traditional legacy network PIN 1/27

66 Bh3+5

Active network A network whose nodes are programmable: besides carrying bits from one end system to another, the routers and switches perform computations on the data flowing through them, running code that users, or the packets themselves, supply.

The legacy network is passive. A traditional router only stores and forwards: it reads the header, looks up the route and sends the packet on, never touching the payload. Its functions are fixed by the vendor, so a new network service (a new multicast or quality of service scheme) needs years of standardisation and then a firmware upgrade of every router. Active networking, proposed by Tennenhouse and Wetherall at MIT in the mid 1990s and funded by DARPA, attacks exactly that slowness: it puts the new service into the network as a program.

Two ways to get the code into the node:

  • Discrete approach (programmable switches): programs are loaded into the nodes beforehand, out of band, by an operator or an authorised user; arriving packets carry only a header that says which program should process them.
  • Integrated approach (capsules): every packet, called a capsule, carries a small program as well as data; each node it reaches executes that code, which decides what happens to the capsule. The MIT ANTS toolkit worked this way.

The framework of an active node (the DARPA active network architecture) has three layers of software on the node's hardware:

ACTIVE NODE AGAINST LEGACY ROUTER A legacy node only forwards; an active node also runs code on the packets passing through it. LEGACY ROUTER (PASSIVE) header data in read the header look up the route forward the packet header data out The data is never read or changed; new services wait for new firmware. ACTIVE NODE (DARPA ARCHITECTURE) AA 1 AA 2 AA 3 active apps EE 1 (Java VM) EE 2 management EE NodeOS shares channels, CPU, memory, storage; isolates the EEs node hardware and its links ANEP header code data out: forwarded, changed or dropped capsule in: its ANEP header names the EE, where its code runs Capsule (integrated) approach: code rides in every packet. Programmable switch (discrete) approach: code is loaded first, packets name it.
  1. NodeOS: the node operating system. It owns the node's resources (the links, called channels, processor time, memory and storage), shares them among the execution environments, and enforces security so that no program takes more than its share.
  2. Execution environments (EEs): each is like a virtual machine or interpreter (a Java virtual machine, for example) that runs active code. One node may host several, and a management EE lets the operator control the node.
  3. Active applications (AAs): the user programs that run inside an EE and give a flow its custom service.

An arriving packet is matched to the right EE by a small header (the Active Network Encapsulation Protocol, ANEP), is processed there, and leaves possibly changed: forwarded, merged, shrunk, copied or dropped.

PointLegacy (passive) networkActive network
What a node doesstores and forwards packets by their headerforwards and also computes on the packets' contents
Processingthe same for every packet, fixedcustomised per user, per flow or per packet
Who programs the nodethe vendor, in firmwareusers and applications, by injecting code
A new serviceyears: standardise, then upgrade every routerdays: load the program, or send it in capsules
Packetheader and datacapsule: code and data (or a header that names a loaded program)
Intelligenceat the end systems only (the end to end principle)at the end systems and inside the network
Data and algorithmsfixedmutable and fluid
Security and performancesimpler; fast hardware forwardingharder: foreign code must be isolated, and running it costs time

What it is good for: shrinking a video stream at the node nearest a slow link; caching popular content inside the network; merging the readings of thousands of sensors on the way instead of carrying them all; deploying a new multicast or congestion control scheme without waiting for a standard; pushing firewall rules to the right node during an attack; network management by mobile agents.

Where the idea went. Few active networks were deployed, because running other people's code inside routers raised hard security and performance problems. The idea of a programmable network survived in software-defined networking (SDN), where a central controller programs the switches, and in programmable switch hardware.

To remember it: a legacy network is the postal service, which reads only the address and passes the parcel on. An active network is a courier who also obeys a note on the parcel: "if the road to the village is slow, open me and send only the small photos".

The book says an active network "can be at least as secure as the legacy network" and "has faster hardware". Read both as the designers' goals: security was the hardest problem active networking faced, and executing code costs time compared with plain forwarding.
Asked on the paper, word for word
  • What is client/server networking? Explain Active Networking model framework comparing with traditional legacy network. 2066 Bhadra Q1b · 3+5
In the exam Define it, draw the node (NodeOS, EEs, AAs, a capsule), name the discrete and integrated approaches, then the comparison table against the legacy network.

1.3Protocols, standards and layered architecture

Protocols, standards and interfaces HOT 5/27

82 Bh · 81 Ba · 76 Ch · 70 Asa · 66 Po1+2+51+3+42+2+4

Protocol A set of rules that governs communication between two or more entities: the format and order of the messages exchanged, what each message means, and the actions taken when one is sent or received. It is an agreement on how a link or a conversation is established, maintained and released.

Why rules are needed. Two machines built by different vendors, running different operating systems, understand each other only if both follow the same rules, exactly as two people talk only if they share a language and take turns. Without a protocol the bits arrive but mean nothing.

The three key elements of a protocol:

  • Syntax: the structure or format of the data: which field comes where and how long it is. In an IPv4 header the first 4 bits are the version, the next 4 the header length.
  • Semantics: the meaning of each field and the action it calls for: does this bit pattern mean "data" or "error, send again"?
  • Timing: when data may be sent and how fast: speed matching, sequencing, timeouts. A sender at 100 Mbps swamps a receiver that handles 1 Mbps unless the protocol prevents it.

What a protocol specifies, as the book lists it: how the physical network is built, how computers connect to it, how the data is formatted for transmission, how it is sent over the network, and how errors are dealt with.

ProtocolLayerWhat it does
HTTP, HTTPSapplicationfetches web pages (HTTP)
SMTP, POP3, IMAPapplicationsends and reads email (email)
DNSapplicationturns names into IP addresses (DNS)
TCPtransporta reliable, ordered byte stream between processes (TCP)
UDPtransportfast, connectionless datagrams (UDP)
IPnetwork (internet)addresses and routes packets between networks (IPv4)
Ethernet (IEEE 802.3), Wi-Fi (IEEE 802.11)data link and physicalmoves frames over one link (Ethernet)

A human protocol makes the idea concrete. A phone call opens with "Hello" or "Namaste", each side takes turns, a missed word gets a "Hajur?" (send it again), and it closes with an agreed goodbye before either side hangs up. Opening, turn taking, error recovery and release: every network protocol has the same parts.

Standards are agreed, published specifications that let equipment from different vendors work together in one network. A de jure standard is set by an official body; a de facto standard is one that won in practice before, or without, such approval (TCP/IP itself grew this way).

BodyFull nameKnown for
ISOInternational Organization for Standardizationthe OSI reference model (ISO 7498)
ITU-TInternational Telecommunication Union, Telecommunication Standardization Sector (called CCITT until 1993)X.25, the V series modem standards, ISDN, ADSL (G.992)
IEEEInstitute of Electrical and Electronics Engineersthe 802 LAN standards: 802.3 Ethernet, 802.11 Wi-Fi
IETFInternet Engineering Task Forcethe Internet's protocols, published as RFCs: IP (RFC 791), TCP (RFC 9293)
ANSIAmerican National Standards InstituteUS national standards; the US member of ISO; FDDI
EIA (its standards now with TIA)Electronic Industries Alliancethe EIA-232 (RS-232) serial interface

Forums and regulators stand beside the bodies: industry forums such as the Frame Relay Forum and the ATM Forum sped up the standards for their technologies, and national regulators license the airwaves and telecom services; in Nepal that is the Nepal Telecommunications Authority (NTA).

Protocols, services and interfaces are three different things (layered architecture, services):

  • Protocol: horizontal: the rules between peer entities, the same layer on two different machines.
  • Service: vertical: what a layer offers the layer above it, as a set of primitive operations.
  • Interface: the boundary between two adjacent layers on the same machine. It tells the upper layer how to reach the lower layer's services: the operations, their parameters and the results to expect.
  • Protocol stack: the list of protocols a system uses, one per layer.

Post office analogy: the counter is the interface, "registered delivery" is the service, and the rules post offices follow among themselves to route and hand over the mail bags are the protocol. The counter can stay the same while the rules behind it change.

The book says ISO is the "International Standards Organization" and IEEE the "Institute of Electrical and Electrical Engineer". The official names are the International Organization for Standardization and the Institute of Electrical and Electronics Engineers; the book's CCITT has been called ITU-T since 1993.
Asked on the paper, word for word
  • Define protocol with examples. Why do we have layered architecture in networks? Differentiate between TCP/IP and OSI model. 2082 Bhadra Q1 · 2+2+4
  • What is a protocol? List out the common protocols used at each layer of TCP/IP model. Differentiate between client-server is P2P network. 2081 Baishakh Q1 · 1+3+4
  • What is protocol? What are the reasons for using layered network architecture? Compare OSI with TCP/IP reference model. 2076 Chaitra Q1 · 1+2+5
  • What do you mean by protocol and interfaces? Write the protocols used in each layer of ICP/IP model. 2070 Ashad Q1 · 4+4
  • Define network and protocol for network. Explain peer-to-peer network process with example. 2066 Poush Q1 · 2+6
In the exam "Define protocol" (1 or 2 marks): one sentence, syntax, semantics and timing, two examples. "Protocol and interfaces" (4 marks): add the interface, the service, and the layer drawing.

Layered architecture: why network software is a hierarchy of layers TOP 9/27

82 Bh · 80 Ba · 76 Ch · 75 Ash · 71 Ch · 69 Ch · 68 Ch · 67 Asa · 66 Bh2+2+43+51+2+5

Layered architecture Network software organised as a stack of layers, each built on the one below it, each offering services to the layer above while hiding how they are carried out. Layer n on one machine talks to layer n on another machine through the layer n protocol.

Why a hierarchy at all. Getting a file from one program to another across a world of different cables, radios, routers and operating systems is too big a problem to solve in one piece. Layering splits it into small problems stacked on each other: one layer moves bits on a wire, the next makes one link reliable, the next finds a route, the next makes the whole path reliable for a program, and so on. Each layer uses only the services of the layer below and offers its own to the layer above.

Reasons for layering (asked in nine sittings):

  1. It reduces design complexity: a complex system is broken into smaller, understandable parts, each designed, built and tested on its own.
  2. Modularity and independence: a layer can be changed or replaced without touching the others, as long as its service and interface stay the same. A laptop moves from Wi-Fi to an Ethernet cable and the browser never notices.
  3. Standardisation and interoperability: each layer's job and protocols are defined, so equipment and software from different vendors work together.
  4. Easier troubleshooting: a fault is located layer by layer (cable, link, route, port) and isolated quickly.
  5. Specialisation and reuse: a specialist team handles each layer, and one layer serves many users: IP carries every application over every kind of link.
  6. Flexibility: new technology slots in at one layer (fibre for copper, 5G for 4G) without redesigning the rest.

The price of layering: every layer adds a header (overhead), some functions are repeated in several layers (error control at both the data link and the transport layer), and strict layering can cost performance when one layer could use information another layer has.

The protocol hierarchy. Networks are organised as a series of layers; the number, names, contents and functions of the layers differ from network to network. The entities in corresponding layers on different machines are called peers, and peers communicate using the layer's protocol. But no data passes directly from layer n of one machine to layer n of another: each layer passes data and control information down to the layer below, until the lowest layer, where the physical medium carries it. The peers' conversation is virtual; only the medium carries real signals. Between each pair of adjacent layers is an interface that defines the primitive operations and services the lower layer offers the upper one.

PROTOCOL HIERARCHY AND VIRTUAL COMMUNICATION Five layers: layer n on one machine talks to layer n on the other through the layer n protocol, but data really travels down, across and up. LAYER 5 LAYER 4 LAYER 3 LAYER 2 LAYER 1 SOURCE MACHINE DESTINATION MACHINE M H4 M H3 H4 M1 H3 M2 H2 H3 H4 M1 T2 H2 H3 M2 T2 0 1 1 0 1 0 0 1 1 1 0 1 ... M H4 M H3 H4 M1 H3 M2 H2 H3 H4 M1 T2 H2 H3 M2 T2 0 1 1 0 1 0 0 1 1 1 0 1 ... physical medium layer 5 protocol layer 4 protocol layer 3 protocol layer 2 protocol Dashed: virtual communication between peers, by each layer protocol. Solid: the actual path, down, across the medium and up. Between each pair of adjacent layers is an interface. M message, H header, T trailer.

Reading the drawing, a five-layer example from Tanenbaum that the book reproduces:

  1. Layer 5: an application process produces a message M and passes it to layer 4.
  2. Layer 4: adds header H4, with control information such as sequence numbers so that the receiving layer 4 can deliver the pieces in order, and passes it to layer 3.
  3. Layer 3: its packets have a size limit, so it breaks the message into M1 and M2 and puts its header H3 on each; H3 carries the addresses the routers use.
  4. Layer 2: adds a header H2 and a trailer T2 to each piece and hands them to layer 1.
  5. Layer 1: transmits the bits over the physical medium. At the destination each layer removes its own header (and trailer) and passes the rest up; no header of a lower layer ever reaches layer n.

Network architecture is the name for the set of layers and protocols. Its specification must give an implementer enough detail to write the program or build the hardware for each layer so that it obeys the protocol. The details of the implementation and the interfaces inside one machine are not part of the architecture, because they are hidden from the outside. TCP/IP and IBM's Systems Network Architecture (SNA) are network architectures; the OSI model on its own is not, because it names no protocols (OSI).

Design issues for the layers. The same handful of problems turns up at several layers, and each layer that meets one must solve it:

IssueThe problemHow layers answer it
Addressinga network holds many machines and each runs many processes: whom is the data for?MAC addresses (data link), IP addresses (network), port numbers (transport)
Direction of data transfermay data flow one way, either way in turn, or both ways at once, and on how many logical channels?simplex, half duplex or full duplex; separate channels for data and control
Error controlphysical circuits are not perfecterror detecting or correcting codes, and acknowledgements so the sender knows what arrived
Ordering (sequencing)some channels do not keep messages in ordernumber the pieces and reorder them at the receiver
Flow controla fast sender can swamp a slow receiverreceiver feedback, windows, agreed rates
Segmentation (message size)a process or a link cannot take arbitrarily long (or very short) messagesbreak messages up and reassemble them; gather small ones together
Multiplexinga separate connection for every pair of processes is costlymany conversations share one connection or channel, and are separated again at the far end
Routingthere are several paths from source to destinationchoose the best route, at the network layer

Later texts group the same concerns under reliability, resource allocation (including congestion and quality of service), evolution and security.

To remember why layering helps, think of a momo delivery to the hostel: the order is placed in the app, the restaurant packs the box with a slip naming the buyer, the rider's app picks the route to Pulchowk, the rider rides it one road segment at a time, on the road itself. The restaurant does not care whether the rider comes on a bike or a scooter: change one layer and the rest is untouched.

The book says, in step 4 of its information flow, that layer 2 adds a header and a trailer to each packet "obtained from layer 2". The packets come from layer 3.
Asked on the paper, word for word
  • Define protocol with examples. Why do we have layered architecture in networks? Differentiate between TCP/IP and OSI model. 2082 Bhadra Q1 · 2+2+4
  • Why do we need layered architecture in computer network? Discuss the function of each layer of TCP/IP networking model. 2080 Baishakh Q1 · 3+5
  • What is protocol? What are the reasons for using layered network architecture? Compare OSI with TCP/IP reference model. 2076 Chaitra Q1 · 1+2+5
  • Why layering is important? Explain design issues for layers in detail. Mention service primitives for implementing connection oriented service. 2075 Ashwin Q1 · 2+4+2
  • What do you mean by network architecture? Compare TCP/IP and OSI reference models. Explain X.25 Network with its key feature. 2071 Chaitra Q1 · 2+3+3
  • Explain the need of Networking Software in the form of Hierarchy? Mention in which level layer of OSI reference model following tasks are done. i) Timing and voltage of received signal ii) Encryption and decryption of data iii) Data framing iv) Point-to-point connection of socket. 2069 Chaitra Q1 · 6+2
  • Why are the network softwares defined with distinct layers stacked on top of one another? What are the factors to be considered when designing these layers? 2068 Chaitra Q1 · 2+6
  • Why network software should be in hierarchical form? Explain in detail about OSI layer. 2067 Ashad Q1 · 3+5
  • Why do communication process within computer network is divided into layers? How the process of data encapsulation occurs in transmission mode described by seven layers of OSI model. Compare OSI model with TCP/IP model. 2066 Bhadra Q1a · 2+2+4
In the exam "Why layering" (2 to 6 marks): the divide-and-conquer idea, then the numbered reasons, with the protocol hierarchy drawing for the larger sizes. "Network architecture" (2): the set of layers and protocols. "Design issues" (4 to 6): the eight issues, each with its problem and the answer.

Services: connection-oriented and connectionless, and the service primitives PIN 1/27

75 Ash2+4+2

Service The set of operations (primitives) a layer offers to the layer above it. A connection-oriented service sets up a connection, uses it and releases it, like a telephone call; a connectionless service sends each message on its own, carrying the full destination address, like a letter in the post.

Connection-oriented service is modelled on the telephone system: the user first establishes a connection, uses it to send data, then releases it. The connection acts like a tube: bits go in at one end and come out in the same order at the other. The two sides may negotiate parameters, such as the maximum message size or the quality of service, when the connection opens. Examples: TCP, X.25 virtual circuits, a phone call.

Connectionless service is modelled on the postal system: each message (datagram) carries the full destination address and is routed independently of the others, so two messages to the same place may take different routes and arrive out of order. Examples: UDP, IP.

ServiceKindExample
Reliable message streamconnection-orienteda sequence of pages
Reliable byte streamconnection-orienteda movie download, a remote login
Unreliable connectionconnection-orienteddigitised voice, where a late correction is useless
Unreliable datagramconnectionlesselectronic junk mail
Acknowledged datagramconnectionlessregistered mail
Request and replyconnectionlessa database query

Reliable means the receiver acknowledges every message, so the sender knows it arrived; the acknowledgements cost delay, which is why voice and video often prefer an unreliable service.

Service primitives are the operations a user process calls to use a service; in an operating system they are usually system calls. Five primitives are enough for a simple connection-oriented service:

PrimitiveMeaning
LISTENblock, waiting for an incoming connection
CONNECTestablish a connection with a waiting peer
RECEIVEblock, waiting for an incoming message
SENDsend a message to the peer
DISCONNECTterminate the connection

How a client and a server use them (six packets in all):

  1. LISTEN: the server calls LISTEN and blocks until a connection request arrives.
  2. CONNECT: the client calls CONNECT, which sends a connection request packet (1) to the server; the client is suspended until there is a response.
  3. Accepted: the server's operating system sees the request, unblocks the server and sends back a packet accepting the connection (2); the client is released and the connection is up.
  4. RECEIVE: the server calls RECEIVE to wait for the first request.
  5. SEND: the client SENDs its request (3) and calls RECEIVE to wait for the answer; the server processes the request and SENDs the reply (4).
  6. DISCONNECT: the client calls DISCONNECT (5); the server answers with its own DISCONNECT (6), and the connection is released.

Later editions of Tanenbaum add a sixth primitive, ACCEPT, for step 3. The Berkeley socket calls are the same idea in code: listen(), connect(), accept(), send(), recv() and close() (sockets, socket programming).

The four classes of OSI primitive: request (a user asks for a service, as in CONNECT.request), indication (the peer is told of the event), response (the peer answers) and confirm (the first user learns the result). A confirmed service uses all four; an unconfirmed service only the request and the indication.

Services and protocols are not the same. A service is what a layer does for the layer above (vertical: the operations it offers, not how they work); a protocol is the set of rules that peers on different machines use to carry out that service (horizontal: the format and meaning of the packets). A layer can change its protocol freely as long as the service it offers stays the same, much as a program keeps calling one function while the function's code is rewritten.

To remember it: a phone call is connection-oriented (dial, talk, hang up; the words arrive in order); a letter is connectionless (each envelope carries the full address, and two letters posted together may arrive on different days).

Asked on the paper, word for word
  • Why layering is important? Explain design issues for layers in detail. Mention service primitives for implementing connection oriented service. 2075 Ashwin Q1 · 2+4+2
In the exam "Service primitives for a connection-oriented service" (2 marks): the five primitives in a table, one line each; for more, the six-packet client and server sequence.

1.4The OSI and TCP/IP models

The OSI reference model: seven layers and what each does HOT 8/27

81 Bh · 80 Bh · 74 Ch · 74 Ash · 72 Ch · 69 Ch · 67 Asa · 66 Po3+52+65+3

OSI reference model The International Organization for Standardization's seven-layer framework (ISO 7498, 1984) for communication between open systems, from the physical layer at the bottom to the application layer at the top. It is a reference model: it says what each layer should do, not which protocols must do it.

Open systems are systems open for communication with other systems, whatever their vendor. ISO started the work in 1977 and published the model in 1984. It is a model and not a network architecture, because it does not specify the exact services and protocols of each layer; it only says what each layer should do. ISO did publish OSI protocols separately, but they never caught on; the model survived as the way everyone describes networks.

Five principles fixed the seven layers (Tanenbaum): a layer wherever a different abstraction is needed; a well-defined function for each layer; functions chosen with internationally standardised protocols in mind; layer boundaries chosen to keep the information flowing across interfaces small; and enough layers to keep distinct functions apart, but few enough that the architecture does not become unwieldy.

THE OSI REFERENCE MODEL Seven layers in each host; the routers of the subnet run only the bottom three. COMMUNICATION SUBNET: ROUTERS RUN LAYERS 1 TO 3 ONLY HOST A Application Presentation Session Transport Network Data link Physical HOST B Application Presentation Session Transport Network Data link Physical ROUTER Network Data link Physical ROUTER Network Data link Physical 7 APDU 6 PPDU 5 SPDU 4 TPDU 3 Packet 2 Frame 1 Bit application protocol presentation protocol session protocol transport protocol Layers 4 to 7 work end to end, only in the two hosts; layers 1 to 3 work hop by hop, host to router and router to router. Bottom up: physical, data link, network, transport, session, presentation, application.

Two groups. The bottom three layers (physical, data link, network) are the network support layers: they work hop by hop, between a host and a router or between two routers, and every router runs them. The top three (session, presentation, application) are the user support layers. The transport layer joins the two groups, and from it upwards the layers work end to end, only in the two hosts. The book groups the same seven as the top three, which define how applications communicate, and the bottom four, which define how data travels end to end.

LayerMain functionsUnitExample protocols and devices
7 Applicationthe window through which users and programs reach the network: services such as file transfer and access, mail, directory services, remote login, the network virtual terminalmessage (APDU)HTTP, FTP, SMTP, POP3, IMAP, DNS, Telnet, SSH, SNMP, DHCP
6 Presentationthe syntax and semantics of the data: translation between character codes (ASCII, EBCDIC, Unicode) and machine formats; encryption and decryption; compressionPPDUTLS encryption, JPEG, MPEG, ASN.1 with BER, XDR, MIME
5 Sessiondialog control (who may talk and when: half or full duplex, token management); synchronisation by checkpoints, so a long transfer resumes after a crash from the last checkpoint; opening, maintaining and closing sessionsSPDUNetBIOS, RPC, the OSI session protocol (ISO 8327)
4 Transportprocess to process delivery of the whole message: port (service point) addressing; segmentation and reassembly with sequence numbers; connection control; end to end flow control and error control by retransmission; multiplexingsegment (TPDU)TCP, UDP, SCTP
3 Networksource to destination delivery of packets across many networks: logical addressing (IP addresses), routing and forwarding, fragmentation, congestion control, internetworkingpacketIP (IPv4, IPv6), ICMP, IPsec, the X.25 packet layer; device: router
2 Data linknode to node delivery of frames on one link: framing, physical addressing (MAC addresses), error control (CRC, retransmission), flow control, medium access control on a shared link; sublayers LLC and MACframeEthernet (IEEE 802.3), Wi-Fi (IEEE 802.11), HDLC, PPP, Frame Relay; devices: switch, bridge, network card
1 Physicalmoving raw bits over the medium: mechanical and electrical specifications (connectors, pins, the voltage levels for 0 and 1), bit timing and data rate, encoding and modulation, bit synchronisation, line configuration, topology, transmission mode (simplex, half or full duplex)bitRS-232, V.35, 10BASE-T, 1000BASE-T, DSL, SONET/SDH; devices: hub, repeater, modem, cable

Which layer does it? The board asks this as a short question; the answer is one layer with its reason:

TaskLayerReason
Timing and voltage of the received signalPhysicalit defines the voltage levels, bit duration and bit synchronisation
Data framingData linkit groups bits into frames with a header and a trailer
Physical identification of a computer (MAC address)Data linkMAC addresses travel in the frame header
Error detection and correctionData linkthe frame's CRC checks every link; the transport layer also checks end to end
Access to a shared channelData link (MAC sublayer)it decides which station may transmit
Logical identification of a computer (IP address)NetworkIP addresses identify hosts across networks
Routing, choosing the pathNetworkrouters forward packets by their destination address
Point to point connection of sockets (process to process)Transporta socket is an IP address plus a port, and the transport layer joins two ports end to end
Segmentation and reassembly, port addressingTransportit numbers the segments and delivers them to the right process
Dialog control, synchronisation, checkpointsSessionit manages who talks when, and where to resume
Encryption and decryption, compression, code translationPresentationit handles how the data is represented
File transfer, email, remote loginApplicationservices offered directly to users

The significance of the OSI model: it is the common vocabulary of networking (everyone says "a layer 2 switch" or "a layer 3 problem"); it separates services, interfaces and protocols, so a layer can change without disturbing the others; it is the reference for designing and comparing real protocol stacks and for interoperability between vendors; it guides troubleshooting layer by layer, from the cable upwards; and it is the standard way networking is taught.

Walk one web request down the model, from a laptop on the hostel Wi-Fi: the browser asks for a page with HTTP (application); TLS encrypts the request and the page's text is in UTF-8 (presentation); the browser keeps the logged-in session open (session); TCP cuts the request into segments for port 443 and will resend anything lost (transport); IP puts the server's address on each packet and routers pick the path through the ISP (network); Wi-Fi frames carry the laptop's and the access point's MAC addresses and a CRC (data link); and radio signals at 2.4 or 5 GHz carry the bits (physical).

The book says ISO developed the model "in 1977". That is when the work began; the reference model was published as the standard ISO 7498 in 1984.
Asked on the paper, word for word
  • Define Network. List a function of each layer of OSI reference model and compare it with TCPI/IP model. 2081 Bhadra Q1 · 2+6
  • Differentiate between Client Server and Peer to Peer architecture. Discuss the functions of each layer of Open System Interconnection (OSI) model. 2080 Bhadra Q1 · 3+5
  • Distinguish between Client-Server network and Peer-Peer network. Explain Open System Interconnection (OSI) model. 2074 Chaitra Q1 · 3+5
  • What is the significance of OSI layer? Explain different layers of OSI with its functionalities. 2074 Ashwin Q1 · 2+6
  • Compare OSI layer with TCP/IP Layer? Explain in which level of OSI layer following tasks are done. i) Error detection and correction ii) Encryption and Decryption of data iii) Logical identification of computer iv) Point-to-point connection of socket v) Dialogue control vi) Physical identification of computer 2072 Chaitra Q1 · 5+3
  • Explain the need of Networking Software in the form of Hierarchy? Mention in which level layer of OSI reference model following tasks are done. i) Timing and voltage of received signal ii) Encryption and decryption of data iii) Data framing iv) Point-to-point connection of socket. 2069 Chaitra Q1 · 6+2
  • Why network software should be in hierarchical form? Explain in detail about OSI layer. 2067 Ashad Q1 · 3+5
  • Explain the seven layers of OSI model with their example protocols. 2066 Poush Q7 · 8
In the exam For 5 to 8 marks: draw the two hosts and the subnet, then one paragraph per layer with its functions and two example protocols. "Which layer" questions: one line each, layer and reason.

The TCP/IP model: four layers and their protocols PIN 4/27

82 Ba · 81 Ba · 80 Ba · 70 Asa4+41+3+43+5

TCP/IP model The layered model of the Internet protocol suite, named after its two main protocols, the Transmission Control Protocol and the Internet Protocol. It has four layers: host-to-network (network access), internet, transport and application; many texts split the lowest into data link and physical, giving five.

Where it came from. TCP/IP grew out of the ARPANET, the research network funded by the US Department of Defense's Advanced Research Projects Agency (ARPA). Vinton Cerf and Robert Kahn described TCP in 1974; the ARPANET switched to TCP/IP on 1 January 1983, and the Internet grew from it. Its main goal was to interconnect many different networks and give universal communication services over them: connections had to survive the loss of routers and lines in between as long as the two ends kept working, and the design had to carry very different applications, from file transfer to real-time speech. The protocols came first; the model was written afterwards to describe them.

THE TCP/IP MODEL Four layers; many applications above and many links below meet in one internet protocol, IP. LAYER 4 APPLICATION LAYER 3 TRANSPORT LAYER 2 INTERNET LAYER 1 HOST-TO-NETWORK HTTP, HTTPS, SMTP, POP3, IMAP, FTP, DNS, DHCP, SSH, SNMP, Telnet TCP UDP IP ICMP, IGMP, ARP Ethernet, Wi-Fi, PPP, DSL, fibre, 4G and 5G user services; unit: message no session or presentation layer process to process, by port segment (TCP), datagram (UDP) host to host across networks: IP addressing, routing; packet one link: framing, MAC address, bits on the medium; frame IP is the narrow waist: every application runs over IP, and IP runs over every kind of link.

The four layers, bottom up:

  1. Host-to-network (network access, link) layer: the lowest layer. The original model says little more than that the host must connect to the network with some protocol so that it can send IP packets over it. In practice it covers framing, physical (MAC) addressing and putting the bits on the medium: OSI's data link and physical layers together. Protocols: Ethernet (IEEE 802.3), Wi-Fi (IEEE 802.11), PPP, DSL, Frame Relay, ATM.
  2. Internet layer: the linchpin that holds the whole architecture together. It lets a host inject packets into any network and have them travel independently to the destination, possibly by different routes and out of order: a connectionless, best effort service, like letters in the post. It defines an official packet format and protocol, IP, and handles logical addressing and routing. Protocols: IP (IPv4, RFC 791; IPv6, RFC 8200), ICMP for error and control messages, IGMP for multicast groups, ARP to find a MAC address (often placed at the boundary with the layer below).
  3. Transport layer: lets peer processes on the source and destination hosts carry on a conversation, as OSI's transport layer does. It segments the data, reassembles it, and names the process by a port number. Two protocols: TCP, reliable and connection-oriented, which delivers a byte stream without error and in order, with flow control (used where accuracy matters: the web, mail, file transfer); and UDP, unreliable and connectionless, with no sequencing or flow control (used where prompt delivery matters more: DNS lookups, voice and video calls, online games).
  4. Application layer: all the higher-level protocols users work with. TCP/IP has no session or presentation layer: applications include those functions themselves when they need them. Protocols: HTTP and HTTPS (web), SMTP, POP3 and IMAP (mail), FTP (files), DNS (names), DHCP (address assignment), SNMP (management), Telnet and SSH (remote login).

The protocols at each layer, with the well known port numbers of the application protocols (ports):

LayerProtocolsUnit
ApplicationHTTP 80, HTTPS 443, FTP 20 and 21, SSH 22, Telnet 23, SMTP 25, DNS 53, DHCP 67 and 68, POP3 110, IMAP 143, SNMP 161message
TransportTCP, UDP (and SCTP)segment (TCP), datagram (UDP)
InternetIPv4, IPv6, ICMP, IGMP, ARP, RARP, IPsecpacket (IP datagram)
Host-to-networkEthernet, Wi-Fi, PPP, DSL, Frame Relay, ATMframe, then bits

The hourglass. Many applications sit on two transport protocols, which sit on one internet protocol, which runs over every kind of link. IP is the narrow waist: anything that can carry IP packets can join the Internet, and any application written for IP works over any link. That one design choice is why the same browser works on the hostel Wi-Fi, a fibre line at home and a 4G phone.

Four layers or five? Tanenbaum's TCP/IP model, which the book follows, has four layers. Kurose and Ross, and Tanenbaum's own "hybrid model" for teaching, use five: application, transport, network, data link and physical. Both are right, as long as the answer says which one it draws.

To remember it, follow one Messenger video call from the hostel: the app (application) hands its audio and video to UDP (transport), which hands it to IP with the server's address (internet), which rides Wi-Fi frames to the router and then the ISP's fibre (host-to-network). Four handovers, four layers.

The book says UDP "is an unreliable connection protocol". It is an unreliable connectionless protocol: it sets up no connection at all. The book also expands ARPANET as "Advanced Research Project Agency": ARPA, the Advanced Research Projects Agency, was the agency, and the ARPANET its network.
Asked on the paper, word for word
  • Explain client/server and P2P network model with their advantages and disadvantages. Discuss the layer of TCP/IP model with suitable diagram. 2082 Baishakh Q1 · 4+4
  • What is a protocol? List out the common protocols used at each layer of TCP/IP model. Differentiate between client-server is P2P network. 2081 Baishakh Q1 · 1+3+4
  • Why do we need layered architecture in computer network? Discuss the function of each layer of TCP/IP networking model. 2080 Baishakh Q1 · 3+5
  • What do you mean by protocol and interfaces? Write the protocols used in each layer of ICP/IP model. 2070 Ashad Q1 · 4+4
In the exam Draw the four layers with the protocols beside each, then one paragraph per layer. "Protocols at each layer" wants the table, with port numbers for the extra mark.

Data encapsulation: how headers and trailers are added and removed PIN 3/27

76 Ash · 70 Ch · 66 Bh4+42+2+4

Data encapsulation The process by which each layer at the sender wraps the data it receives from the layer above with its own control information: a header, and at the data link layer also a trailer, forming that layer's protocol data unit. Decapsulation is the reverse at the receiver: each layer reads and removes its own header and trailer and passes the rest up.

Headers and trailers. A header is control information placed in front of the data: addresses (MAC, IP, port), sequence and acknowledgement numbers, a length, a type, a time to live, a checksum. A trailer is control information placed after the data; in practice it is the data link layer's frame check sequence (FCS), a CRC computed over the whole frame, and sometimes an end marker. The trailer goes at the end because the CRC can be calculated while the frame is being sent, and appended last.

PDU and SDU. What a layer receives from the layer above is its service data unit (SDU); the SDU plus the layer's header (and trailer) is its protocol data unit (PDU), which becomes the SDU of the layer below. Each PDU has its own name:

DATA ENCAPSULATION Each layer wraps what it gets from above in its own header; the data link layer adds a trailer too. SENDER: ADD, GOING DOWN RECEIVER: REMOVE, GOING UP Data TCP hdr Data IP hdr TCP hdr Data Frame hdr IP hdr TCP hdr Data FCS 0110100111010110010110... Data TCP hdr Data IP hdr TCP hdr Data Frame hdr IP hdr TCP hdr Data FCS 0110100111010110010110... APPLICATION data TRANSPORT segment NETWORK packet DATA LINK frame PHYSICAL bits medium Headers go in front; only the data link layer adds a trailer, the FCS (a CRC over the whole frame). A router opens a frame only up to the IP header, then builds a new frame for the next link.

At the sender, five steps, as the book counts them in the OSI model:

  1. Data: the application, presentation and session layers create the data from the user's input (a request, a message, a file).
  2. Segment: the transport layer cuts the data into pieces and adds a TCP or UDP header (source and destination ports, sequence number, checksum).
  3. Packet: the network layer adds an IP header (source and destination IP addresses, time to live, protocol number).
  4. Frame: the data link layer adds a frame header (destination and source MAC addresses, type) and the trailer (FCS).
  5. Bits: the physical layer turns the frame into a stream of bits, as electrical, light or radio signals on the medium.

At the receiver, the same steps in reverse. The physical layer turns the signals back into bits. The data link layer checks the FCS (a damaged frame is discarded), checks that the destination MAC address is its own, strips the header and trailer, and passes the packet up. The network layer checks the destination IP address and removes the IP header. The transport layer uses the port number to find the right process, puts the segments in order and removes its header, and the application receives the original data. Each layer reads only the header its peer wrote: the headers are how peers talk (virtual communication).

At a router the frame is opened only up to the network layer: the router reads the IP header, chooses the next hop, and wraps the packet in a new frame for the next link, with new MAC addresses. The IP addresses stay the same end to end; the MAC addresses change at every hop.

Worked example: the cost of the wrapping

A file is sent over Ethernet in chunks of 1460 bytes. TCP adds 20 bytes and IP 20 bytes, which makes 1500 bytes, the Ethernet maximum for a packet; Ethernet adds a 14-byte header and a 4-byte FCS, so the frame is 1518 bytes. Of each frame, 1460/1518=96.2% is file data; the rest is the price of four layers of control information.

To remember it, post a letter: the letter itself is the data; it is sealed in an envelope with the friend's name (transport); the post office puts it in a bag tagged with the destination district (network); the bag rides a truck with a trip sheet in front and a seal at the back that is checked on arrival (the data link header and trailer); and the truck drives on the road (physical). At the other end each office opens only its own wrapping.

Asked on the paper, word for word
  • What are the features of Client/Server Architecture? What are headers and trailers and how do they get added and removed? 2076 Ashwin Q1 · 4+4
  • What are the features of Client/Server Architecture? What are headers and trailers and how do they get added and removed? Explain. 2070 Chaitra Q1 · 4+4
  • Why do communication process within computer network is divided into layers? How the process of data encapsulation occurs in transmission mode described by seven layers of OSI model. Compare OSI model with TCP/IP model. 2066 Bhadra Q1a · 2+2+4
In the exam Define header and trailer, draw the encapsulation figure, list the five steps down, then the removal up in one paragraph. Name the PDU at each layer.

1.5Comparing OSI and TCP/IP

OSI and TCP/IP compared: similarities and differences TOP 9/27

82 Bh · 81 Bh · 79 Bh · 76 Ch · 73 Shr · 72 Ch · 71 Ch · 71 Shr · 66 Bh2+2+42+65+3

OSI against TCP/IP OSI is a seven-layer reference model defined by ISO before its protocols existed; TCP/IP is the four-layer model of the protocols the Internet actually uses, described after they were built. Both are layered stacks with an end to end transport layer.
OSI AND TCP/IP, LAYER BY LAYER Seven layers against four: the dashed lines show which OSI layers each TCP/IP layer does the work of. OSI MODEL AND OSI PROTOCOLS TCP/IP MODEL TCP/IP PROTOCOLS 7 Application FTAM, X.400, X.500 user services 6 Presentation ISO 8823, ASN.1 format, encrypt 5 Session ISO 8327 dialog, sync 4 Transport TP0 to TP4 (ISO 8073) end to end, ports 3 Network CLNP, X.25 packet layer routing, IP address 2 Data link HDLC, LAPB, LLC framing, MAC, errors 1 Physical X.21, RS-232, V.35 bits, voltage, timing Application layer 4 Transport layer 3 Internet layer 2 Host-to-network layer 1 HTTP, HTTPS, FTP, SMTP, POP3, IMAP, DNS, DHCP, SNMP, SSH, Telnet TCP, UDP IP, ICMP, IGMP, ARP Ethernet, Wi-Fi, PPP, DSL, Frame Relay TCP/IP has no session or presentation layer: the application does that work. Its host-to-network layer covers OSI layers 2 and 1. The OSI protocols in the left boxes were little used; the TCP/IP protocols on the right run the Internet.

How the layers line up: TCP/IP's application layer does the work of OSI's application, presentation and session layers; the two transport layers match; TCP/IP's internet layer matches OSI's network layer; and TCP/IP's host-to-network layer covers OSI's data link and physical layers.

Similarities:

  1. Both are layered: each is a stack of independent protocols, each layer serving the one above, with peers talking by protocols.
  2. Both have an end to end transport layer: in both, the layers up to and including transport give the communicating processes an end to end, network-independent transport service.
  3. Both have an application layer at the top through which the users' programs work.
  4. Both have a network (internet) layer that routes packets between networks, and both are built on packet switching.
  5. Both use encapsulation: each layer adds its header on the way down and removes it on the way up.
  6. Both describe real networks: their layer numbers (layer 2, layer 3) are the everyday language of network engineers.

Differences:

BasisOSI modelTCP/IP model
Stands forOpen Systems InterconnectionTransmission Control Protocol / Internet Protocol
Developed byISO (published as ISO 7498, 1984)the US Department of Defense's ARPA, for the ARPANET, in the 1970s; maintained by the IETF
Number of layers74 (5 when the lowest is split)
How it was mademodel first, protocols later: general, not tied to any protocolprotocols first, model described later: it fits only its own protocols
Services, interfaces and protocolsclearly distinguished: the model's central ideanot clearly distinguished
Network layer serviceconnection-oriented and connectionlessconnectionless only (IP)
Transport layer serviceconnection-oriented onlyboth: TCP connection-oriented, UDP connectionless
Session and presentationseparate layersnone: left to the application
Data link and physicalseparate layersmerged into one host-to-network layer, barely specified
Replacing protocolsprotocols well hidden, so they can be replaced as technology changesprotocols not easily replaced
Internetworkingnot considered at first (one network per country was expected)the main goal from the start
Use todaya reference and teaching model; its own protocols are hardly usedthe protocol suite the Internet runs on

Why OSI's protocols lost, in Tanenbaum's four reasons:

  • Bad timing: the OSI protocols arrived when TCP/IP was already spreading in universities, shipped free with Berkeley UNIX.
  • Bad technology: the session and presentation layers are nearly empty while the data link and network layers are overfull; addressing, flow control and error control turn up again in several layers; the standards were huge and complex.
  • Bad implementations: the first ones were large, slow and unwieldy.
  • Bad politics: OSI was seen as a creature of European telecom ministries and governments, pushed onto researchers.

TCP/IP's weaknesses, in turn: it does not separate service, interface and protocol clearly; it is not general and cannot describe other protocol stacks; its host-to-network layer is an interface rather than a layer, and does not tell physical from data link; and some early protocols (Telnet) were ad hoc yet became entrenched. Hence the modern habit: the OSI model to talk about networks, the TCP/IP protocols to build them.

To remember the difference: OSI is a syllabus a committee wrote before any class was taught: complete, tidy, and never followed to the letter. TCP/IP is the set of notes the seniors wrote after passing: shorter, a little messy, and what everyone actually uses.

The book's table says internetworking "is not supported" in OSI. Read it as Tanenbaum's point: the OSI committee did not think about internetworking at first, since it expected each country to run one network; an internetworking sublayer was added to its network layer later. TCP/IP was designed for internetworking from the start.
Asked on the paper, word for word
  • Define protocol with examples. Why do we have layered architecture in networks? Differentiate between TCP/IP and OSI model. 2082 Bhadra Q1 · 2+2+4
  • Define Network. List a function of each layer of OSI reference model and compare it with TCPI/IP model. 2081 Bhadra Q1 · 2+6
  • Compare the OSI reference model and TCP/IP reference model mentioning their similarities and differences. 2079 Bhadra Q1 · 8
  • What is protocol? What are the reasons for using layered network architecture? Compare OSI with TCP/IP reference model. 2076 Chaitra Q1 · 1+2+5
  • Differentiate between TCP/IP and OSI Model. Define Frame Relay in detail. 2073 Shrawan Q1 · 5+3
  • Compare OSI layer with TCP/IP Layer? Explain in which level of OSI layer following tasks are done. i) Error detection and correction ii) Encryption and Decryption of data iii) Logical identification of computer iv) Point-to-point connection of socket v) Dialogue control vi) Physical identification of computer 2072 Chaitra Q1 · 5+3
  • What do you mean by network architecture? Compare TCP/IP and OSI reference models. Explain X.25 Network with its key feature. 2071 Chaitra Q1 · 2+3+3
  • What is computer network? Distinguish between OSI and TCP/IP reference model. 2071 Shrawan Q1 · 2+6
  • Why do communication process within computer network is divided into layers? How the process of data encapsulation occurs in transmission mode described by seven layers of OSI model. Compare OSI model with TCP/IP model. 2066 Bhadra Q1a · 2+2+4
In the exam For 8 marks: draw the two stacks side by side with the mapping, write four similarities, then a differences table of eight rows. For 4 or 5 marks: the drawing and five rows. This is the most repeated comparison in the bank.

1.6Example networks

The Internet: a network of networks

The Internet The worldwide network of networks that interconnects billions of devices using the TCP/IP protocol suite. Nobody owns it: thousands of independently run networks agree to exchange traffic using common protocols.

How it grew:

  • 1969, the ARPANET: four nodes in the US (UCLA, SRI, UC Santa Barbara and the University of Utah), funded by ARPA: the first large packet switched network.
  • 1974 to 1983, TCP/IP: Cerf and Kahn's internetworking protocol, which the ARPANET adopted on 1 January 1983.
  • 1986 to 1995, NSFNET: the US National Science Foundation's backbone joined the universities; it was retired in 1995, when commercial ISPs took over the backbone.
  • 1989 to 1991, the World Wide Web: Tim Berners-Lee at CERN created the web (HTTP, HTML, URLs), which brought the Internet to the public.

How it is built:

  • End systems (hosts): phones, laptops and servers at the edge.
  • Access networks: the last link to the user: DSL, cable, fibre to the home, Wi-Fi, 4G and 5G.
  • ISPs in tiers: local access ISPs buy transit from national and international ISPs, which connect to global (tier 1) backbones; ISPs of similar size often exchange traffic with each other free (peering).
  • Internet exchange points (IXPs): places where many ISPs connect to swap traffic directly. In Kathmandu the Nepal Internet Exchange (NPIX) lets Nepali ISPs hand local traffic to each other without sending it abroad and back.
  • Content providers' networks: large companies run their own global networks and place caches inside ISPs, so a popular video often comes from a server in the same city.

Who runs what. The Internet has no central government; each network sets its own policies. Only the two main name spaces are coordinated centrally: IP addresses (allocated by IANA, under ICANN, to five regional registries, of which APNIC serves the Asia Pacific region, Nepal included) and the root of the Domain Name System (under ICANN), below which .np is Nepal's country code domain (DNS). Standards come from the IETF as RFCs, with the Internet Society (ISOC) behind them.

Internet, intranet, extranet: an internet (small i) is any set of networks joined by routers; the Internet (capital I) is the global one; an intranet is a private network inside one organisation built with the same TCP/IP technology (a college portal reachable only on campus); an extranet opens part of an intranet to partners (suppliers logging in to a company's order system).

To remember it: run tracert (Windows) or traceroute (Linux) to a foreign website from the hostel. The list of hops shows the trip from the Wi-Fi router to the ISP, across the border and on to the server's network: a dozen independently owned networks passing the same packets along.

In the exam Not asked yet. Define it as a network of networks running TCP/IP, then its structure (hosts, access networks, ISPs, IXPs) and who governs the addresses and names.

X.25: the reliable, slow packet switched WAN HOT 7/27

82 Ba · 75 Ash · 71 Ch · 68 Ch · 68 Ba · 67 Asa · 66 Po4+42+3+32+6

X.25 An ITU-T standard (approved by the CCITT in 1976) for the interface between a user's data terminal equipment (DTE) and the data circuit-terminating equipment (DCE) of a public packet switched network. It is connection-oriented, carries packets over virtual circuits, and checks and corrects errors at every hop.

Designed for bad lines. In the 1970s long distance data travelled over noisy analog telephone circuits, and the terminals at the ends were too simple to recover lost data themselves. So X.25 made the network itself reliable: every link and every packet switch checks, acknowledges and, when needed, retransmits, and packets arrive error free and in order. The price is speed: access lines typically ran at up to 64 kbps, and the processing at every hop adds delay.

The parts of an X.25 network (the book's figure 1.9):

  • DTE: the user's terminal, computer or router.
  • DCE: the device that joins the DTE to the network, usually a modem or the network's access port.
  • PSE (packet switching exchange): the switches inside the carrier's network, joined by trunk lines. X.25 defines only the DTE to DCE interface; how the PSEs talk to each other is the carrier's choice.
  • PAD (packet assembler and disassembler): lets a simple character terminal use the network, collecting characters into packets and back (ITU-T X.3, X.28 and X.29).

Three layers, matching OSI's bottom three:

X.25 LAYERS AND PACKET FORMAT X.25 covers the bottom three OSI layers of the DTE to DCE interface; the packet layer carries the virtual circuits. DTE (USER) DCE (NETWORK) Packet layer PLP: virtual circuits Packet layer PLP: virtual circuits packets Link layer LAPB (HDLC subset) Link layer LAPB (HDLC subset) frames Physical X.21, V.24 Physical X.21, V.24 bits X.25 defines only the DTE to DCE interface. DATA PACKET, MODULO 8 8 7 6 5 4 3 2 1 Q D 0 1 LCGN OCTET 1 LCN: logical channel number OCTET 2 P(R) M P(S) 0 OCTET 3 User data: up to 128 bytes by default OCTET 4 ON GFI: Q, D and 01 (modulo 8) or 10 (modulo 128) LCGN and LCN: one 12-bit virtual circuit number THE PACKET TRAVELS INSIDE A LAPB FRAME ON THE DTE TO DCE LINK Flag Address Control X.25 header user data FCS Flag 8 bits 8 bits 8 bits 3 octets variable 16 bits 8 bits the X.25 packet (layer 3) LAPB header (layer 2)
LayerOSIJob
Physical1the electrical interface between DTE and DCE: X.21 (digital), or X.21bis and V.24 on analog modems
Link access (frame)2LAPB (Link Access Procedure, Balanced), a subset of HDLC (HDLC): frames with sequence numbers, CRC error detection, acknowledgements and retransmission, and flow control on the DTE to DCE link
Packet (PLP)3the packet layer protocol: sets up and clears virtual circuits, multiplexes up to 4095 of them on one link, numbers packets and controls flow on each circuit, recovers by reset and restart

Virtual circuits. A switched virtual circuit (SVC) is set up for a call and cleared after it, like a phone call; a permanent virtual circuit (PVC) is set up by the carrier at subscription and always present, like a leased line, so it needs no call setup. On a link each circuit is known by a 12-bit number: a 4-bit logical channel group number (LCGN) and an 8-bit logical channel number (LCN). That gives 212=4096 values, of which 0 is reserved, so up to 4095 circuits share one physical line (virtual circuits).

The packet format, for a data packet with 3-bit sequence numbers (modulo 8):

OctetFieldBitsMeaning
1Q bit1qualifier: 1 marks control information for a device such as a PAD, 0 ordinary user data
1D bit1delivery confirmation: 1 asks for an end to end acknowledgement, 0 a local one from the network
1Modulo201 for sequence numbers modulo 8, 10 for modulo 128; Q, D and these two bits form the general format identifier (GFI)
1LCGN4logical channel group number
2LCN8logical channel number; with the LCGN, the 12-bit virtual circuit number
3P(R)3receive sequence number: the next packet expected, which acknowledges everything before it
3M bit1more data: 1 means the user's message continues in the next packet
3P(S)3send sequence number of this packet
3Type10 marks a data packet (control packets end in 1 and use the whole octet as a type code)
4 onwardsUser datavariableup to 128 bytes by default (other sizes can be agreed)

Control packets keep the first two octets; the third is the packet type identifier. A call request also carries the calling and called DTE addresses (X.121 numbers) and optional facilities after these three octets.

Packet (DTE to DCE / DCE to DTE)Type octet
Call request / Incoming call0000 1011
Call accepted / Call connected0000 1111
Clear request / Clear indication0001 0011
Clear confirmation0001 0111
Receive ready (RR)xxx0 0001 (xxx is P(R))
Receive not ready (RNR)xxx0 0101
Reset request / Reset indication0001 1011
Restart request / Restart indication1111 1011

The virtual circuit connection, in three phases:

AN X.25 VIRTUAL CALL Setup routes the call once; afterwards packets carry only the logical channel number. X.25 NETWORK (PSEs) DTE A DCE A DCE B DTE B Call request Incoming call Call accepted Call connected Data P(S)=0 RR P(R)=1 Data P(S)=0 RR P(R)=1 Clear request Clear indication Clear confirmation Clear confirmation CALL SETUP DATA CLEARING Data packets carry only the channel number; each PSE switches them by table lookup, in order, acknowledged hop by hop.
  1. Call setup: DTE A picks a free logical channel and sends a Call request packet carrying B's address to its DCE. The network routes it once through its PSEs, and each PSE on the route records the circuit in a table. B's DCE delivers it as an Incoming call on one of B's free channels. B answers Call accepted, and A receives Call connected. The virtual circuit now exists.
  2. Data transfer: data packets carry only the short channel number, not the full address. Each PSE switches by table lookup: a packet that arrives on link 1 with channel 5 leaves on link 3 with channel 9, say. P(S) and P(R) number and acknowledge the packets, a window (2 by default) limits how many may be outstanding, and RR and RNR packets start and stop the flow. Packets arrive in order.
  3. Clearing: either DTE sends a Clear request; the other receives a Clear indication and answers Clear confirmation; the first DTE receives a Clear confirmation too, and both channel numbers are free again.

Beside these, an interrupt packet sends a few urgent bytes outside the flow control, a reset reinitialises one circuit (its sequence numbers return to 0) after an error, and a restart clears every circuit on the interface.

Key features and advantages: reliable, error free, in-order delivery even over poor lines; many virtual circuits multiplexed on one physical line; flow control on every circuit; both SVCs and PVCs; an international standard used by public data networks worldwide; a user pays for what is sent instead of renting a whole line.

Disadvantages: slow (low line rates, and every node stores, checks and acknowledges each packet), with high overhead and delay; unsuited to voice and video. Once fibre made lines nearly error free, the hop by hop checking became wasted work, and Frame Relay, ATM and later IP and MPLS replaced X.25, though it ran card payment and airline reservation networks for decades.

X.25 against Frame Relay is compared in full on the next card (Frame Relay): Frame Relay keeps the virtual circuits but drops the packet layer and the error correction.

To remember it: X.25 is a careful old postman who checks every letter at every post office on the route and goes back for any that is torn. Nothing is ever lost, but the post is slow.

Asked on the paper, word for word
  • Write Short Notes on: (Any Two) a) 802.5 Token Ring b) PGP c) Socket programming fundamentals d) X.25 Network 2082 Baishakh Q10 · 2×4
  • Write short notes on: (any two) i) Flow control in D22 ii) X.25 iii) ALOHA 2075 Ashwin Q10 · 4+4
  • What do you mean by network architecture? Compare TCP/IP and OSI reference models. Explain X.25 Network with its key feature. 2071 Chaitra Q1 · 2+3+3
  • What is X.25? Explain the format of X.25 packet in detail. 2068 Chaitra Q6 · 3+5
  • Compare x.25 and frame relay network. A bit string 0111101111101111110 needs to be transmitted at the data link layer. What is the string actually transmitted after bit stuffing? 2068 Baishakh Q10 · 6+2
  • Explain along with the packet format about the virtual circuit connection of X.25. 2067 Ashad Q6 · 4+4
  • What do you understand by virtual circuit switching? Explain the X.25 virtual circuit switching. 2066 Poush Q6 · 2+6
In the exam A short note: the definition, the three layers, SVC and PVC, features, one advantage and one disadvantage. "Packet format": the octet drawing with every field explained. "Virtual circuit": the three phases with the packet names and the sequence drawing.

Frame Relay: fast virtual circuits at the data link layer HOT 5/27

78 Bh · 73 Shr · 70 Asa · 68 Ba · 66 Bh2+62×45+3

Frame Relay A connection-oriented, packet switched WAN technology that carries variable-length frames over virtual circuits identified by a DLCI, using only the physical and data link layers. It detects errors but does not correct them: a bad frame is simply dropped, and the end systems recover.

Why it replaced X.25. By the late 1980s digital and fibre lines had made bit errors rare, and the computers at the ends ran TCP, which recovers lost data by itself. X.25's checking at every hop had become wasted effort. Frame Relay keeps the virtual circuits but removes the packet layer and the per-hop acknowledgements, so a switch can relay a frame as soon as it has read the address. It was standardised by the ITU-T (I.122, Q.922) and ANSI (T1.618) with the Frame Relay Forum, and sold at access speeds from 56 or 64 kbps through 1.544 Mbps (T1) and 2.048 Mbps (E1) up to 44.736 Mbps (T3).

Devices. Devices attached to a Frame Relay WAN are of two kinds: DTEs, the customer's terminating equipment (routers, bridges, terminals), usually on the customer's premises; and DCEs, the carrier's packet switches, which provide clocking and switching and actually move the data through the WAN.

Virtual circuits. Each logical connection between two DTEs is a virtual circuit through the carrier's switches. A PVC (permanent virtual circuit) is configured by the carrier and always present, for steady traffic between fixed sites; it has only two states, data transfer and idle. An SVC (switched virtual circuit) is set up on demand with Q.933 signalling and cleared afterwards, for occasional traffic (its steps are below). Many virtual circuits share one access line: a head office needs one physical line, not one per branch.

The DLCI (data link connection identifier) names a virtual circuit on one link. It has local significance: the same circuit may be DLCI 102 on the head office's access line and DLCI 201 at the branch, and every switch changes it as it relays the frame. DLCI 0 carries signalling; user circuits are usually given values from 16 to 1007.

FRAME RELAY: THE FRAME AND A PVC NETWORK No control field and no sequence numbers: the address carries the circuit number and the congestion bits. Flag Address Information (user data) FCS (CRC) Flag 8 bits 16 bits variable 16 bits 8 bits DLCI (high 6 bits) C/R EA 0 DLCI (low 4 bits) FECN BECN DE EA 1 octet 1 octet 2 DLCI: 10 bits, names the virtual circuit C/R: command or response, for the ends EA: 0 means another address octet follows FECN, BECN: congestion ahead, behind DE: drop this frame first if congested FRAME RELAY NETWORK (CARRIER) switch S1 switch S2 switch S3 Kathmandu HQ DLCI 102: to Pokhara DLCI 103: to Biratnagar Pokhara branch DLCI 201: to Kathmandu Biratnagar branch DLCI 301: to Kathmandu each switch: (in port, DLCI) to (out port, new DLCI) One PVC is DLCI 102 at Kathmandu and DLCI 201 at Pokhara: a DLCI has only local significance.

The frame (the Q.922 core, with the default 2-byte address):

FieldSizeContents
Flag8 bits01111110, marks the start and the end; bit stuffing keeps it unique (framing)
Address16 bits (can be extended to 24 or 32)the DLCI (10 bits, split 6 and 4); C/R (command or response, for the end systems); EA (address extension: 0 means another address octet follows, 1 marks the last); FECN, BECN and DE (below)
Informationvariablethe user's data, for example an IP packet; there is no control field, since there is no sequencing and no acknowledgement
FCS16 bitsa CRC over the address and information fields: errors are detected, and a bad frame is discarded
Flag8 bits01111110

Congestion control without flow control. The network does not slow senders down hop by hop; it tells them, and drops what it must:

  • CIR (committed information rate): the rate the carrier promises on a circuit, say 256 kbps on a 2 Mbps access line. A site may burst above it when the network has room.
  • DE (discard eligibility): frames sent above the CIR get DE = 1, and a congested switch drops those first.
  • FECN (forward explicit congestion notification): set on frames travelling towards the receiver through a congested switch, telling the receiver that its traffic meets congestion.
  • BECN (backward explicit congestion notification): set on frames going back towards the sender, telling the sender to slow down.
  • LMI (local management interface): status messages on the access line (on DLCI 0 or 1023) that report which PVCs are active and check that the link is alive.

The operation of a Frame Relay network: one frame from a bank's Kathmandu head office to its Pokhara branch, over a PVC.

  1. Encapsulate: the head office router (DTE) puts the IP packet in a frame with DLCI 102, the local number of the PVC to Pokhara, and sends it on its access line to the carrier's switch (DCE).
  2. Check: the switch checks the FCS; a damaged frame is discarded at once, with no message to anyone.
  3. Look up and relay: the switch looks up (incoming port, DLCI 102) in its table, finds (outgoing port 3, DLCI 310), rewrites the DLCI and relays the frame. Every switch on the path repeats this, and no acknowledgement is sent.
  4. Under congestion: a busy switch sets FECN on the frame and BECN on frames heading back, and drops DE frames first.
  5. Deliver: the last switch delivers the frame to the Pokhara router with DLCI 201, the PVC's number on that line. If a frame was lost, TCP in the two hosts notices and sends it again.

How an SVC is established, maintained and torn down. An SVC session passes through four operational states, driven by Q.933 signalling messages carried on DLCI 0:

A FRAME RELAY SVC: ESTABLISHED, MAINTAINED, TORN DOWN Q.933 signalling messages on DLCI 0; the data then uses the DLCI the network assigned. Calling DTE Frame Relay network Called DTE SETUP (called address, CIR) CALL PROCEEDING SETUP CONNECT CONNECT data frames both ways on the assigned DLCI no data: the circuit is kept; an idle timer runs DISCONNECT DISCONNECT RELEASE RELEASE RELEASE COMPLETE RELEASE COMPLETE SETUP DATA IDLE TEARDOWN Maintained: STATUS ENQUIRY and STATUS messages check the link while the call is up. A PVC skips setup and teardown: it only moves between data transfer and idle.
  1. Call setup: the calling DTE sends SETUP (the called address and the traffic parameters, such as the CIR); the network answers CALL PROCEEDING and passes SETUP to the called DTE; the called DTE answers CONNECT, which the network passes back to the caller. During setup the network tells each end the DLCI to use, and the virtual circuit between the two DTEs is established.
  2. Data transfer: frames flow both ways on the assigned DLCI, relayed by the switches exactly as on a PVC.
  3. Idle: the connection is still active but no data is sent. It is maintained (STATUS ENQUIRY and STATUS messages check the link), and if it stays idle beyond a set time the call can be terminated.
  4. Call termination: either DTE sends DISCONNECT; the network answers RELEASE, and the DTE confirms with RELEASE COMPLETE. The other DTE gets the same three messages from its side, and the DLCI is freed.

Advantages: higher data rates than X.25; low overhead and delay; suits bursty LAN traffic, since a site can burst above its CIR; many virtual circuits on one access line cut the cost of joining many sites (cheaper than a leased line for every pair); independent of the protocol it carries. Disadvantages: no error correction or guaranteed delivery inside the network; frames are dropped under congestion; variable delay makes it poor for voice and video; MPLS and Ethernet services have now largely replaced it.

X.25 against Frame Relay:

BasisX.25Frame Relay
Layers usedphysical, link (LAPB) and network (packet)physical and data link only
Error controldetects and corrects at every hop, by retransmissiondetects only; bad frames dropped; the end systems recover
Flow controlhop by hop and per circuit, with windows and RR/RNRnone in the network; FECN, BECN and DE instead
Acknowledgementsat every hopnone
Speedlow: typically up to 64 kbpshigher: 56 kbps to 44.736 Mbps
Delay and overheadhigh: every node processes every packetlow: frames relayed once the address is read
Circuit number12-bit LCGN and LCN10-bit DLCI (default)
Multiplexingat the network (packet) layerat the data link layer
Signallingin band: call request packets on the circuit itselfout of band: on DLCI 0 (Q.933)
Lines suitednoisy analog linesclean digital and fibre lines
Trafficterminal to host, low volumeLAN to LAN, bursty

Frame Relay against ATM: both are virtual circuit WANs, but ATM cuts everything into fixed 53-byte cells (ATM):

BasisFrame RelayATM
Unitvariable-length framefixed 53-byte cell (5-byte header, 48-byte payload)
Speed56 kbps to 44.736 Mbpstypically 155.52 or 622.08 Mbps on SONET/SDH, also T1 to T3 rates for access
Circuit identifierDLCIVPI and VCI
Traffic designed fordata, especially bursty LAN trafficvoice, video and data together
Delayvariable: a long frame holds up the short ones behind itlow and predictable: small fixed cells, switched in hardware
Quality of serviceCIR and DE onlyservice categories CBR, VBR, ABR, UBR
Error checkFCS over the whole frameHEC over the cell header only; the payload is checked by the AAL
Overheadsmall: about 6 bytes per frame of any size5 of every 53 bytes (9.4%), the cell tax
Congestion signalsFECN, BECN, DEthe CLP bit, a congestion bit in PT, traffic contracts
Cost and complexitylow, simplehigh, complex
Typical usejoining an enterprise's branch LANscarrier backbones, broadband ISDN, DSL aggregation

To remember it: X.25 is the careful postman; Frame Relay is the express courier who reads only the label, never checks inside, throws away a parcel that arrives soaked, and leaves the sender to complain and post it again. Faster, because the checking moved to the two ends.

The book says Frame Relay runs from "1.544 Mbps to 44.376 Mbps" (twice, on pages 18 and 19). The T3 rate is 44.736 Mbps: two digits are swapped. Frame Relay access also ran below T1, at 56 or 64 kbps.
Asked on the paper, word for word
  • Write short notes on: (Any Two) a) Frame relay b) TCP sliding window c) HDLC 2078 Bhadra Q10 · 2×4
  • Differentiate between TCP/IP and OSI Model. Define Frame Relay in detail. 2073 Shrawan Q1 · 5+3
  • What is virus circuit switching? Describe the operation of Frame-Relay network. 2070 Ashad Q6 · 2+6
  • Compare x.25 and frame relay network. A bit string 0111101111101111110 needs to be transmitted at the data link layer. What is the string actually transmitted after bit stuffing? 2068 Baishakh Q10 · 6+2
  • Differentiate between circuit switching and packet switching technology. Explain the operation how switched virtual circuit in frame relay network is established, maintained and teardown. 2066 Bhadra Q3b · 2+6
In the exam A short note or "define in detail": the definition, DLCI, PVC and SVC, the frame, FECN, BECN and DE. "Operation": the five relay steps with the network drawing. "SVC established, maintained and torn down": the four states with the Q.933 messages. "Compare with X.25": the table.

ATM: fixed 53-byte cells, virtual paths and the adaptation layers PIN 3/27

81 Bh · 80 Bh · 66 Bh2×43+3

ATM (Asynchronous Transfer Mode) A connection-oriented, cell switching technology standardised by the ITU-T and the ATM Forum, which carries voice, video and data alike in fixed-size 53-byte cells (a 5-byte header and a 48-byte payload) over virtual circuits named by a VPI and a VCI. It was chosen as the transfer mode of broadband ISDN.

Asynchronous because a source sends a cell whenever it has data, not in a fixed time slot of its own as in synchronous TDM (multiplexing), so no slot is wasted on an idle source. Cells rather than frames, because small cells of one size can be switched in hardware at very high speed, and a voice cell never waits behind a 1500-byte data frame: the delay stays low and predictable.

Why 48 bytes: a compromise. The US wanted 64-byte payloads for efficiency, Europe 32 bytes for low voice delay, and the committee settled between them on 48. Filling 48 bytes with 64 kbps voice takes 48×8/64000=6 ms.

ATM: THE CELL AND THE LAYERS Every cell is 53 bytes; a connection is named by its VPI and VCI on each link. header 5 B payload 48 bytes UNI HEADER, BIT BY BIT 8 7 6 5 4 3 2 1 GFC VPI byte 1 VPI VCI byte 2 VCI byte 3 VCI PT CLP byte 4 HEC: CRC-8 byte 5 GFC 4, VPI 8, VCI 16, PT 3, CLP 1, HEC 8 bits NNI: no GFC; the VPI takes 12 bits HEC: CRC-8 over the first four bytes 5 of every 53 bytes is header: a 9.4% cell tax a small fixed cell keeps voice delay low ATM REFERENCE MODEL AAL: adapts user data to 48-byte payloads CS: convergence SAR: segment, reassemble ATM layer header, VPI/VCI switching, multiplexing Physical layer TC: HEC, cell boundaries PMD: bits on the medium VIRTUAL PATHS AND CHANNELS VPI 1 VPI 2 transmission path (the physical link) A VP switch changes only the VPI; a VC switch changes VPI and VCI.

The cell header at the user network interface (UNI):

FieldBitsJob
GFC (generic flow control)4local flow control between the user and the network (UNI only)
VPI (virtual path identifier)8which virtual path the cell belongs to
VCI (virtual channel identifier)16which virtual channel inside that path
PT (payload type)3user data or a management (OAM) cell; a congestion experienced bit; in AAL5, the end of a message
CLP (cell loss priority)11 means the cell may be dropped first under congestion
HEC (header error control)8a CRC-8 over the first four header bytes: corrects single-bit errors and detects most others; also used to find where cells begin

Between two switches, at the network network interface (NNI), there is no GFC: its four bits extend the VPI to 12.

Virtual paths and virtual channels. A physical link (the transmission path) carries many virtual paths, and each virtual path bundles many virtual channels. A connection is named by the pair VPI/VCI on each link, which has local significance like a DLCI. A VP switch (cross-connect) switches whole paths and changes only the VPI, so thousands of channels are rerouted with one table entry; a VC switch changes both. As in X.25 and Frame Relay, connections may be permanent (PVCs) or switched (SVCs, set up with Q.2931 signalling).

The ATM reference model has three layers (and three planes: user, control and management):

LayerSublayersJob
ATM adaptation layer (AAL)convergence sublayer (CS); segmentation and reassembly (SAR)adapts the user's data to cells: the CS adds what the service needs (timing, sequence numbers, a CRC), and the SAR cuts the result into 48-byte payloads and rebuilds it at the far end
ATM layernoneadds and removes the 5-byte header, multiplexes the cells of many connections onto one link, translates VPI/VCI in the switches, generic flow control, traffic management
Physical layertransmission convergence (TC); physical medium dependent (PMD)TC generates and checks the HEC, finds the cell boundaries, inserts idle cells and fits cells into SONET/SDH frames; PMD sends the bits on fibre or copper (155.52 Mbps OC-3/STM-1, 622.08 Mbps OC-12/STM-4)

The AAL types, one for each class of service:

AALClass of trafficUsed forHow it adapts
AAL1class A: constant bit rate, timing between the ends, connection-orienteduncompressed voice; emulating T1/E1 circuitsa 1-byte SAR header (sequence number and its protection), 47 bytes of data in each cell
AAL2class B: variable bit rate with timingcompressed voice and video, mobile voicepacks short packets from several users into one cell, each with its own channel ID
AAL3/4classes C and D: variable rate data without timing, connection-oriented or connectionlessdata; the old SMDS service4 bytes of SAR header and trailer in each cell (segment type, sequence number, multiplexing ID, length, CRC-10), 44 bytes of data
AAL5classes C and D, made simple and efficientIP over ATM, LAN emulation, signallingno overhead in each cell: an 8-byte trailer (length and CRC-32) and padding once per message, 48 bytes of data per cell, the last cell flagged in PT

Service categories (ATM Forum) state what each connection is promised: CBR (constant bit rate: voice, video), rt-VBR (real-time variable: compressed video), nrt-VBR (non real-time variable: data with delay bounds), ABR (available bit rate: data that adapts to what is free) and UBR (unspecified: best effort, like IP).

Worked example: the cell tax on one IP packet

A 1500-byte IP packet sent over AAL5 gains an 8-byte trailer (1508 bytes), padded to 32 cells of 48 bytes (1536 bytes, so 28 bytes of padding). On the wire that is 32×53=1696 bytes, so 1500/1696=88.4% is the packet; the rest is cell headers, trailer and padding.

Advantages: very high speed; voice, video and data on one network with real quality of service; low, predictable delay; scales from the desktop to the backbone. Disadvantages: the 9.4% cell tax, complexity and cost; for data it lost to cheaper switched Ethernet and to IP over MPLS. It ran telephone and Internet backbones in the 1990s, and carried ADSL traffic between home modems and the exchange (xDSL).

To remember it: ATM is a supermarket that ships everything, rice, eggs or a television, in identical 53-litre crates on a conveyor: the crates move fast and never jam, though a lot of crate travels with every egg.

Asked on the paper, word for word
  • Write Short notes on: (Any Two) a) 802.4 Token Bus b) Framing with bit stuffing c) Server Socket programming for bind, listen and accept d) ATM 2081 Bhadra Q10 · 2×4
  • Write short notes on: (Any Two) a) Go Back-N ARQ b) Dual Stack method in IPv6 c) Diffie-Hellman algorithm d) ATM 2080 Bhadra Q10 · 2×4
  • Write short notes on (any two) i) TCP Sliding Window Protocol ii) Secrete Key Algorithm: DES iii) ISDN Signaling and ATM AAL iv) ICMP Message Types 2066 Bhadra Q5b · 3+3
In the exam A short note: the definition, the cell and its header fields, VP and VC, the three layers. "ATM AAL": the CS and SAR sublayers and the table of AAL1, 2, 3/4 and 5.

Ethernet as an example network

Ethernet The family of wired LAN technologies standardised as IEEE 802.3: it describes how devices on one network segment format data into frames and put them on the medium. It is by far the most widely used LAN technology, and now also runs metropolitan and wide area links.

From a shared cable to a switched star. Ethernet was invented at Xerox PARC by Robert Metcalfe and David Boggs in 1973; DEC, Intel and Xerox published the DIX Ethernet specification (10 Mbps, 1980, revised as Ethernet II in 1982), and the IEEE standardised it as 802.3 in 1983. The first Ethernets were a coaxial bus that every station shared, taking turns by CSMA/CD (CSMA/CD). Today every station has its own full-duplex link to a switch: a star with no collisions at all, which is why modern Ethernet no longer needs CSMA/CD.

GenerationIEEE standard (year)SpeedCommon media
Ethernet802.3 (1983)10 Mbpsthick and thin coaxial cable (10BASE5, 10BASE2), later twisted pair (10BASE-T, 1990)
Fast Ethernet802.3u (1995)100 MbpsCategory 5 twisted pair (100BASE-TX), fibre
Gigabit Ethernet802.3z (1998), 802.3ab (1999)1 Gbpsfibre; Category 5e twisted pair (1000BASE-T)
10 Gigabit Ethernet802.3ae (2002), 802.3an (2006)10 Gbpsfibre; Category 6a twisted pair (10GBASE-T)
40 and 100 Gigabit802.3ba (2010)40 and 100 Gbpsfibre, in data centres and backbones
400 Gigabit802.3bs (2017)400 Gbpsfibre, in data centre and carrier links

The name code reads speed, signalling and medium: 10BASE-T is 10 Mbps, baseband, twisted pair; 100BASE-TX is Fast Ethernet over two pairs of Category 5 cable; 1000BASE-T is gigabit over four pairs; 10GBASE-SR is 10 gigabit over short-reach multimode fibre.

What every version keeps is the frame (preamble, 48-bit destination and source MAC addresses, type or length, 46 to 1500 bytes of data, a 32-bit CRC), so a frame from an old card is still understood by a switch bought today. The frame, MAC addressing and the access rules are taught in chapter 3 (Ethernet in detail).

Why it won: it is cheap and simple, every new generation is backward compatible, its speed has been multiplied by ten again and again, and the switch replaced the shared bus without changing the frame. Carriers now sell Metro Ethernet and Carrier Ethernet as MAN and WAN services, which is why the book calls it a technology "used in LANs and MANs".

To remember it: the blue cable from the hostel router to a desktop is Ethernet: most likely 1000BASE-T on Category 5e or 6 cable, a star point to the switch inside the router, and the same frame format Ethernet has used since the 1980s.

In the exam Not asked yet as an example network. Define it as IEEE 802.3, give the move from shared bus to switched star and the speed generations, and leave the frame and CSMA/CD to the chapter 3 answer.

VoIP: voice calls as IP packets

VoIP (voice over Internet Protocol) The set of technologies that carry voice calls and multimedia sessions as packets over IP networks such as the Internet, instead of over the circuit switched public telephone network (PSTN). Also called IP telephony, Internet telephony or broadband phone service.

Circuit against packet. A PSTN call reserves a 64 kbps circuit end to end for the whole call, silences included (the telephone network); VoIP sends the voice as packets that share the network with everything else, which is why it avoids the tolls of the traditional network and costs only the data.

How a VoIP call works:

  1. Signalling: a signalling protocol finds the other party and sets up the call: SIP (the Session Initiation Protocol, RFC 3261: INVITE, ringing, 200 OK, ACK, and BYE to hang up) or the older ITU-T H.323.
  2. Digitise and compress: the microphone's signal is sampled (8000 times a second for ordinary telephone quality) and compressed by a codec: G.711 (64 kbps, the PSTN's own coding), G.729 (8 kbps), or Opus (adaptive, used by many apps).
  3. Packetise: every 20 ms of speech goes into one packet with an RTP header (sequence number and timestamp), inside UDP, inside IP. UDP is used because a late voice packet is useless: sending it again would only make things worse.
  4. Carry: the packets cross the networks like any others; routers that support quality of service send them first.
  5. Play out: the receiver's jitter buffer holds packets for a few tens of milliseconds to even out their varying delay, reorders them by sequence number, covers a lost packet by repeating or smoothing the sound, decodes and plays. RTCP reports loss and delay back to the sender.
Worked example: the bandwidth of one G.711 call

20 ms of speech at 64 kbps is 160 bytes. With the RTP (12 bytes), UDP (8) and IP (20) headers a packet is 200 bytes, sent 50 times a second: 200×8×50=80 kbps in each direction, before the link layer adds its own header.

Quality depends on three numbers: one-way delay (ITU-T G.114 advises keeping it under about 150 ms for natural conversation), jitter (the variation in delay, smoothed by the buffer) and packet loss (a few percent already sounds broken).

Kinds of VoIP: app to app (WhatsApp, Viber, Messenger, Zoom); IP phones on an office IP-PBX; an analog telephone adapter that lets an ordinary phone use VoIP; gateways that connect VoIP calls to the PSTN, under a softswitch that controls them; and VoLTE, voice over the 4G mobile network, which is VoIP inside the operator's own network.

Advantages: cheap, above all for international calls; one network for voice, video and data; extra features (video, conferencing, voicemail by email, a number that works anywhere). Disadvantages: quality depends on the internet connection and on power; an emergency call cannot easily locate the caller; open to eavesdropping, spam calls and toll fraud unless encrypted and secured (SRTP, TLS).

To remember it: the Viber call a student makes to a parent working in Qatar costs a few megabytes, not an international call rate: the voice was cut into fifty small packets every second and put back together on the other side.

In the exam Not asked yet. Define it against the PSTN, give the call steps (SIP, codec, RTP over UDP, jitter buffer), the 80 kbps example, and the advantages and disadvantages.

NGN: the next generation network

NGN (next generation network) A packet-based network, defined by ITU-T Y.2001 (2004), able to provide telecommunication services using multiple broadband, QoS-enabled transport technologies, in which the service functions are independent of the underlying transport. It gives users unrestricted access to competing service providers and supports generalised mobility.

The problem it solves. A traditional operator ran a separate network for each service: circuit switches for fixed telephones, another core for mobile, another network for data, and often another for television. Each had its own equipment, staff and billing, and a new service had to be built into one of them. An NGN replaces them all with one IP-based packet core that carries voice, video and data together: convergence.

The key ideas:

  • Packet-based transport: everything travels as IP packets over one core, often with MPLS underneath for traffic engineering and quality of service (MPLS).
  • Service separated from transport: ITU-T Y.2011 splits the network into a transport stratum (moving packets: access and core) and a service stratum (controlling calls and sessions, and providing the applications). A new service can be added without touching the transport, and the transport upgraded without breaking the services.
  • Call control in software: a softswitch, or the IP Multimedia Subsystem (IMS) defined by 3GPP, controls calls with SIP, while media gateways connect to the old PSTN.
  • QoS-enabled broadband access: DSL, fibre to the home, cable, 4G and 5G radio, all feeding the same core.
  • Open interfaces: third parties can build services on the operator's network, and users can reach competing providers.
  • Generalised mobility: the same services on any access, fixed or mobile, as the user moves (fixed mobile convergence).

Often drawn as four layers: access (how users connect), transport or core (the IP/MPLS backbone), control (softswitch or IMS) and service or application (voice, video, messaging, third-party applications).

Benefits and challenges: one network to build and run is cheaper, and new services arrive faster; but telephone-grade quality and reliability over shared IP, the security of an open network, and working alongside the old network are all hard.

To remember it: an NGN is a city that replaces its separate pipes for water, gas and drainage with one big service tunnel carrying them all: dig once, maintain once, and add a new service by laying one more line in the same tunnel.

In the exam Not asked yet. The ITU-T definition, convergence, the transport and service strata, softswitch and IMS, and the four layers.

MPLS: forwarding by short labels

MPLS (Multiprotocol Label Switching) An IETF technique (RFC 3031) that forwards packets along pre-established paths using short fixed-length labels instead of looking up the destination IP address at every router. It carries many protocols over many link types, and sits between layers 2 and 3, so it is called a layer 2.5 protocol.

Why labels. A normal IP router matches each packet's destination address against a table of perhaps a million routes, looking for the longest matching prefix, at every hop. MPLS does that classification once, at the edge of the network: the packet gets a label, and every router inside simply looks the label up in a small exact-match table, swaps it and forwards. The labels identify virtual paths between distant nodes rather than endpoints, much as a DLCI or a VPI/VCI identifies a circuit.

The label (shim) header, 32 bits placed between the layer 2 header and the IP header:

FieldBitsJob
Label20the value the routers look up
TC (traffic class, once called EXP)3quality of service class
S (bottom of stack)11 on the last label, since labels can be stacked
TTL8time to live, as in IP, so a loop cannot run forever

The parts: a label edge router (LER) at the ingress sorts each packet into a forwarding equivalence class (FEC) (packets to be treated alike, such as one destination prefix with one class of service) and pushes a label; label switching routers (LSRs) in the core swap labels; the egress LER pops the label and forwards by IP. The path a sequence of labels follows is a label switched path (LSP), and it runs one way only. Neighbours agree on labels with LDP, RSVP-TE or BGP.

  1. Build the paths: OSPF or IS-IS learns the topology; LDP or RSVP-TE builds the LSPs and the label tables.
  2. Push: the ingress LER classifies the packet into an FEC and pushes, say, label 17.
  3. Swap: each LSR reads only the label: 17 in becomes 42 out on port 2, and so on.
  4. Pop: the egress LER (or the router just before it) removes the label and delivers the plain IP packet.

What it is used for: traffic engineering (steering traffic onto lightly loaded links instead of only the shortest path); MPLS VPNs, which join a company's branches privately across a carrier's shared network and replaced Frame Relay and ATM circuits; quality of service by traffic class; and fast reroute around a failed link within tens of milliseconds. It carries IP, Ethernet, ATM and Frame Relay traffic over T1/E1, ATM, Frame Relay, DSL or Ethernet links: hence multiprotocol.

To remember it: a label is a token number at a busy hospital: the reception reads the whole case once and hands over token 17, and after that every counter reads only the token, not the patient's history.

In the exam Not asked yet. Define it, draw the 32-bit label and where it sits, then push, swap and pop along an LSP, and its uses.

xDSL: broadband over the telephone line

DSL (digital subscriber line) Originally the digital subscriber loop: a family of technologies (xDSL) that carry high-speed digital data over the existing copper telephone line (the POTS line, plain old telephone service) between a customer and the telephone exchange, in frequencies above the voice band, so the telephone and the internet work at the same time.

The last mile. The copper pair from the exchange to a home (the local loop) was built for voice, which needs only about 4 kHz; the wire itself can carry frequencies of a few megahertz over short distances. DSL uses those higher frequencies for data. It covers only the link from the exchange to the home or office, never the links between exchanges: hence a "last mile" technology.

How it works:

  • Splitter or microfilter: at the home, it separates the voice band (to the telephone) from the data band (to the DSL modem).
  • DSL modem: in the home, puts the data onto the line.
  • DSLAM (DSL access multiplexer): at the exchange, ends hundreds of lines and passes their traffic on to the ISP's network.
  • DMT modulation (discrete multitone): the band is divided into many 4.3125 kHz subchannels (256 of them in ADSL, up to 1.104 MHz); each carries as many bits as its signal to noise ratio allows, so a noisy part of the band simply carries less.
  • Asymmetric speeds: most variants give far more bandwidth downstream (towards the customer) than upstream, which suits browsing and streaming.
VariantSymmetryTypical top speedStandard
ADSLasymmetricabout 8 Mbps down, 1 Mbps upITU-T G.992.1 (1999)
ADSL2+asymmetricabout 24 Mbps down, 1 Mbps upITU-T G.992.5 (2003)
VDSL2asymmetric or symmetricabout 100 Mbps on loops of a few hundred metresITU-T G.993.2 (2006)
HDSLsymmetric1.544 or 2.048 Mbps (T1 or E1) over two or three pairsreplaced leased T1/E1 lines
SDSLsymmetricabout 2 Mbps on one pairbusiness lines

Distance is everything: the speed falls as the loop gets longer, because high frequencies fade in copper. ADSL works to about 5 km; VDSL2's top speeds need the customer within a few hundred metres of the equipment.

DSL and ISDN (ISDN) both use the existing copper telephone lines, and both need the customer fairly close to the exchange (the book says usually under 20,000 feet), but DSL is far faster: ISDN's basic rate is 144 kbps (2B+D), while DSL runs to megabits. ADSL traffic between the modem and the exchange was usually carried in ATM cells (ATM). Fibre to the home (FTTH) has since overtaken both.

In Nepal, Nepal Telecom sold ADSL broadband over its landline copper for years; most homes have since moved to fibre to the home from ISPs such as Nepal Telecom, WorldLink and Vianet.

To remember it: the same copper pair that carried grandfather's landline calls carries the internet above them: voice in the bottom 4 kHz, data in the megahertz above, split by a small box at the phone socket.

The book says xDSL offers "up to 32 Mbps for upstream traffic, and from 32 Kbps to over 1 Mbps for downstream traffic". The directions are swapped: in asymmetric DSL the large rate is downstream, towards the customer, and the small one upstream.
In the exam Not asked yet. Define it, explain the splitter, the DSLAM and asymmetric speeds, tabulate the variants, and set it against ISDN.

1.7Last minute recall

Chapter 1 in one screen

  • Network: autonomous computers and devices joined by links and protocols to exchange data and share resources; parts: nodes, links, protocols, services.
  • Uses: business (sharing, reliability, saving money, scalability), home (information, communication, entertainment, e-commerce, education), mobile, society.
  • Sizes: PAN (1 to 10 m), LAN (campus), MAN (city), WAN (country); internetwork, the Internet.
  • Topologies: bus, star, ring, mesh (n(n−1)/2 links), tree, hybrid; physical against logical.
  • Client/server: server listens, client requests, server processes and replies; central data, security, backup; single point of failure.
  • Peer to peer: every peer client and server; join, search, connect, exchange; BitTorrent, workgroup; cheap, weak security.
  • Active network: programmable nodes computing on packets; capsule (integrated) or programmable switch (discrete); NodeOS, EEs, AAs, ANEP.
  • Protocol: rules for communication; syntax, semantics, timing; bodies ISO, ITU-T, IEEE, IETF, ANSI, EIA.
  • Layering: less complexity, modularity, standards, troubleshooting, reuse; peers, interfaces, virtual communication; architecture = layers + protocols.
  • Design issues: addressing, direction, error control, flow control, multiplexing, routing, ordering, segmentation.
  • Primitives: LISTEN, CONNECT, RECEIVE, SEND, DISCONNECT; request, indication, response, confirm.
  • OSI: physical, data link, network, transport, session, presentation, application (ISO 7498, 1984); bit, frame, packet, segment.
  • Which layer: voltage and timing physical; framing, MAC, error control data link; IP address network; socket connection transport; dialog session; encryption presentation.
  • TCP/IP: host-to-network, internet (IP), transport (TCP, UDP), application (HTTP, SMTP, DNS, FTP); no session or presentation layer.
  • Encapsulation: data, segment, packet, frame (header and FCS trailer), bits; removed in reverse at the receiver.
  • OSI against TCP/IP: 7 against 4; model first against protocols first; service, interface, protocol clear against blurred; network layer both against connectionless; transport connection-oriented against both.
  • X.25: DTE to DCE interface; physical X.21, LAPB, PLP; LCGN + LCN; Q, D, P(R), M, P(S); call request, incoming call, call accepted, call connected, clear.
  • Frame Relay: layers 1 and 2; DLCI (local); PVC and SVC; FECN, BECN, DE, CIR; SVC: SETUP, CALL PROCEEDING, CONNECT, DISCONNECT, RELEASE, RELEASE COMPLETE.
  • ATM: 53-byte cells, 5 header + 48 payload; GFC, VPI, VCI, PT, CLP, HEC; AAL1, AAL2, AAL3/4, AAL5; CS and SAR.
  • Others: Ethernet IEEE 802.3; VoIP (SIP, RTP over UDP, 80 kbps for G.711); NGN (Y.2001, convergence); MPLS (20-bit label, push, swap, pop); xDSL (ADSL, DSLAM, asymmetric).

Chapter 2 · 5 hours · about 8 marks a paper · in 25 of the 27 sittings

Physical layer

The physical layer moves raw bits as signals: voltages on copper, pulses of light in glass, radio waves through the air. This chapter covers how a network's performance is measured (delay, latency, throughput, capacity), the media that carry the bits, how many signals share one link (multiplexing), how a network joins any sender to any receiver (circuit, message and packet switching, datagram and virtual circuit), the telephone network and its exchanges, and ISDN. Switching was set in 13 of the 27 sittings on record, more than any other topic of the chapter, and transmission media in 7.

What this chapter is about
  • Network performance: the four delays (processing, queuing, transmission, propagation), latency, throughput, and the channel capacity limits of Nyquist and Shannon.
  • Transmission media: guided (twisted pair, coaxial cable, optical fiber) and unguided (radio, microwave, infrared, satellite), how waves propagate, and how to choose a medium.
  • Multiplexing: FDM, WDM, synchronous and statistical TDM, and CDM.
  • Switching: circuit, message and packet switching, and packet switching's two forms, datagram and virtual circuit.
  • The telephone network: local loops, exchanges and trunks, the T1 and E1 digital hierarchy, and the switching systems inside the exchanges.
  • ISDN: its channels, interfaces, functional groups, reference points and signalling.
Where it fits
  • Layer 1 of chapter 1's models (OSI, TCP/IP): every frame of chapter 3 and every packet of chapter 4 finally travels as these signals.
  • Virtual circuits are how X.25, Frame Relay and ATM work (X.25, Frame Relay, ATM); datagram switching is how IP routers work (routing).
  • On the wire: repeaters and hubs are physical layer devices (internetworking devices); Ethernet runs over UTP and fiber (Ethernet), Wi-Fi over radio (wireless LAN).
  • Delay meets the upper layers: queuing delay is where congestion shows (congestion control), and the bandwidth-delay product sizes the sliding window (flow control).
What you will learn
  1. 2.1 The physical layer, delay, throughput and channel capacity
  2. 2.2 Transmission media: guided, fiber, unguided, satellite
  3. 2.3 Multiplexing
  4. 2.4 Switching: circuit, message, packet; datagram and virtual circuit
  5. 2.5 The telephone network, T1 and E1, and the exchanges
  6. 2.6 ISDN
  7. 2.7 Last minute recall, chapter 2
How it is examined
  • Switching is the banker: circuit switching against packet switching, as a table, was set in seven sittings; defining switching, its types with examples, and why circuit switching suits real-time traffic make up the rest.
  • Transmission media: define and classify them, explain them with merits and demerits, compare twisted pair, coaxial and fiber, or list the factors for choosing one.
  • Multiplexing and ISDN: the types of multiplexing, switching against multiplexing, the E1 hierarchy; ISDN's purpose, architecture, channels and signalling in five sittings.
  • Calculations: throughput (2080 Bhadra, 2078 Bhadra) and SNR with Shannon capacity (2066 Bhadra), worked in full in the Numericals panel.
  • Draw: the circuit, message and packet timing; the datagram and virtual circuit networks; the ISDN reference points; the optical fiber system.

2.1The physical layer and network performance

The physical layer: moving raw bits as signals PIN 1/27

72 Ka2+6

Physical layer The lowest layer (layer 1) of the OSI model. It transmits a raw stream of bits over a physical medium, and defines the mechanical, electrical, functional and procedural characteristics needed to activate, maintain and deactivate the physical link between two devices.

It moves bits, not meaning. The physical layer does not know whether a bit belongs to an address, a password or a photo; it only makes sure that a 1 sent at one end is read as a 1 at the other. Every frame, packet and segment of the layers above finally travels as these signals.

Four kinds of rule describe a physical interface; standards such as EIA-232 and ITU-T X.21 are written this way:

  • Mechanical: the connector's shape, size and number of pins (an RJ-45 jack has eight).
  • Electrical: the voltage levels, how long one bit lasts, the longest cable allowed.
  • Functional: what each pin or circuit does: transmit data, receive data, clock, ground.
  • Procedural: the order of events that brings the link up, uses it and takes it down.

Its functions, the list every answer is built from:

FunctionWhat it decidesExample
Physical characteristics of interface and mediumthe cable, connector and mediumCat 6 UTP with RJ-45 connectors
Representation of bitsthe encoding: how 0s and 1s become signalsManchester code on 10 Mbps Ethernet: a transition in the middle of every bit
Data ratebits per second, so the duration of one bitat 100 Mbps a bit lasts 10 ns
Synchronization of bitssender and receiver clocks agree where each bit startsthe 7-byte preamble in front of an Ethernet frame
Line configurationpoint-to-point or multipoint (shared) linka leased line; an old shared coaxial bus
Physical topologyhow the devices are wired togetherstar, bus, ring, mesh, hybrid
Transmission modewhich way the bits flowsimplex, half-duplex, full-duplex
ModeDirectionExample
Simplexone way onlykeyboard to computer, TV broadcast
Half-duplexboth ways, one at a timewalkie-talkie, Ethernet on a shared hub
Full-duplexboth ways at oncetelephone call, switched Ethernet

Bit rate is not baud rate. Bit rate counts bits per second; baud rate (signal rate) counts signal elements, or symbols, per second. When each symbol carries r bits, bit rate = baud rate × r: a modem sending 2,400 symbols a second at 4 bits a symbol (16 levels) gives 9,600 bps. The bandwidth limits the baud rate, and noise limits how many levels can be told apart (channel capacity).

In the TCP/IP reference model the physical layer is not a layer of its own: the lowest layer, called host-to-network, network access or link layer, covers both the physical and the data link functions. TCP/IP defines no protocol there; it runs over whatever the network below specifies, such as IEEE 802.3 Ethernet over UTP or fiber, IEEE 802.11 Wi-Fi over radio, or DSL over a telephone line. So the functions in the table are the same in both models; only their place differs (Forouzan's five-layer version of TCP/IP does draw a separate physical layer). The models themselves are chapter 1's (TCP/IP, OSI).

Devices that work only at this layer: repeaters, which regenerate a weakened signal; hubs, multiport repeaters that copy every bit to every port; modems, which put bits onto an analog carrier; transceivers; and the cables and connectors themselves (internetworking devices). None of them reads an address.

To remember it: when Bikash sends a file over the hostel LAN, the physical layer of his laptop's network card turns each bit into a voltage pattern on the four copper pairs of the Cat 6 cable, and the switch port in the corridor turns the voltages back into bits. Over the hostel Wi-Fi the same bits leave as 2.4 or 5 GHz radio waves. The file, its packets and its frames are other layers' business: the physical layer only carries ones and zeros.

Asked on the paper, word for word
  • List out the functions of physical layer in TCP/IP reference model. Explain different types of transmission media. 2072 Kartik Q2 · 2+6
In the exam For "functions of the physical layer in the TCP/IP model", write one line on where it sits in TCP/IP (inside the host-to-network layer), then the seven functions, one line and one example each.

Delay, latency and throughput: measuring a network PIN 3/27

80 Bh · 78 Bh · 74 Ash1+3+43+3+22+6

Network monitoring Measuring how well a network carries traffic, chiefly by its bandwidth, throughput, latency (delay) and jitter. Delay is the time data takes to travel from one node to another; at every hop it is the sum of processing, queuing, transmission and propagation delay.

Four measures describe how a network performs:

MeasureMeaningUnitExample
Bandwidththe capacity of a link: the most data it can carry per second (for a signal, the range of frequencies it passes)bps (Hz)a 100 Mbps Ethernet port
Throughputthe data actually delivered successfully per second over a periodbps60 Mbps measured on that port during a backup
Latency (delay)how long data takes to reach the destinations, ms20 ms to a nearby server
Jitterthe variation in delay between packets of one flowmspackets 20 ms apart arriving 15, 30 and 18 ms apart

Throughput =data deliveredtime taken, and it is always at most the bandwidth. It falls below the bandwidth because of headers, retransmissions, collisions, congestion, slow end hosts and the slowest link on the path, the bottleneck. The Ring Road in Kathmandu is the bandwidth; the crawl at rush hour is the throughput. Both board calculations of throughput (2080 Bhadra, 2078 Bhadra) are worked in the Numericals panel; the trap in both is the units: bytes to bits (× 8), minutes to seconds (÷ 60).

The four delays at each node. A packet crossing a router is delayed four times (the book's Figure 2.1):

THE FOUR DELAYS AT A ROUTER A packet crossing router A towards router B is delayed four times; their sum is the nodal delay. packet ROUTER A Processing check, look up output queue (buffer) Output port sends bit by bit bits link: rate R, length d Router B 1 Processing delay check header, errors, pick output link: µs 2 Queuing delay waits for the link; grows with the load 3 Transmission delay all L bits onto link at rate R: L / R 4 Propagation delay a bit crosses length d at speed s: d / s Nodal delay = processing + queuing + transmission + propagation
DelayCauseFormulaTypical size
Processing dprocexamine the header, check for bit errors, look up the output linkset by the routermicroseconds
Queuing dqueuewait in the output buffer behind earlier packetsset by the load0 to milliseconds, varying
Transmission dtranspush all L bits of the packet onto a link of rate RL/Rmicroseconds to milliseconds
Propagation dpropone bit travels the link length d at the signal speed sd/s5 µs per km of cable
dnodal=dproc+dqueue+dtrans+dprop

The signal speed s is about 2×108 m/s in copper and fiber (two thirds of the speed of light) and 3×108 m/s through air and space.

Transmission is not propagation. Transmission delay depends on the size of the packet and the rate of the link, not on the distance; propagation delay depends on the distance and the medium, not on the packet. Picture a bus at the Kathmandu bus park: boarding every passenger through one door is the transmission delay (more passengers or a narrower door, longer), and the drive to Pokhara is the propagation delay (a longer road, a longer drive), whoever is on board.

Queuing delay and traffic intensity. If packets of L bits arrive at an average rate of a packets a second at a link of rate R, the traffic intensity is La/R. Near 0 the queue is short; as it approaches 1 the queuing delay grows sharply; above 1 the queue grows without limit and packets are dropped. This is where congestion shows (congestion control).

Latency is the total time from the first bit leaving the source to the last bit arriving: propagation + transmission + queuing + processing, added over every hop. The round-trip time (RTT) is the time there and back, the figure ping reports.

Bandwidth-delay product =R×dprop: the number of bits that fill the link, in flight, before the first one reaches the far end. It says how much a sender may send before an acknowledgment can possibly return, which is why it sizes sliding windows (flow control).

Worked example: one packet, two very different links

A host sends a 1,500-byte packet (L = 12,000 bits) over a 10 Mbps link.

  • 2 km of fiber to the campus router (s = 2×108 m/s): dtrans=12000/107 = 1.2 ms and dprop=2000/(2×108) = 10 µs. Transmission dominates.
  • A geostationary satellite hop, 35,786 km up and 35,786 km down (s = 3×108 m/s): dprop = 71,572,000 / (3×108) ≈ 238.6 ms, while dtrans is still 1.2 ms. Propagation dominates.
  • Bandwidth-delay product of the satellite hop: 107×0.2386 ≈ 2.39 million bits, about 199 such packets in flight before the first one lands.

Causes of packet delay, in one list:

  • Router processing: header checks, table lookups, encryption on a busy router.
  • Congestion: long queues as the traffic intensity nears 1, and loss when a buffer overflows.
  • Slow links and big packets: transmission delay L/R at every hop.
  • Distance and medium: propagation delay, worst on satellite links.
  • Number of hops: store-and-forward means a packet must arrive whole at each router before it is sent on, so every hop adds a transmission delay.
  • Retransmissions after errors or loss (error control), and flow and congestion control holding the sender back.
  • Slow end systems: a busy server, an overloaded phone.

Jitter hurts voice and video most: a call whose packets leave 20 ms apart but arrive 15, 30 and 18 ms apart sounds broken, so the receiver holds packets in a jitter (playout) buffer to even them out.

The book says total latency is the one-way latency to the destination plus the one-way latency back. That sum is the round-trip time; latency on its own usually means the one-way delay (Forouzan: latency = propagation time + transmission time + queuing time + processing delay). Write it that way, and call the two-way figure RTT.
Asked on the paper, word for word
  • a) Discuss about the different factors of choosing the transmission media." Circuit switching is suitable for real-time communication", give your reasons. If a file of 1000 bytes was sent over a network in 2 seconds, calculate throughput. 2080 Bhadra Q2 · 3+3+2
  • Define Throughput. A network with bandwidth of 20 Mbps can pass only an average of 18,000 frames per minute with each frame carrying an average of 20,000 bits. Calculate the throughput of this network. Differentiate between Packet switching and Virtual Circuit switching. 2078 Bhadra Q2 · 1+3+4
  • What are the causes of packet delay in computer networks? What are the differences between circuit switching and packet switching? 2074 Ashwin Q3 · 2+6
In the exam "Define throughput" takes one line, the formula, and "never more than the bandwidth". "Causes of packet delay" wants the four delays with the router drawn, then congestion, retransmission and distance.

Bandwidth and channel capacity: Nyquist and Shannon PIN 1/27

66 Bh4+4

Channel capacity The highest data rate a channel can carry. For a noiseless channel the Nyquist limit is C=2Blog2L; for a real, noisy channel the Shannon limit is C=Blog2(1+SNR), where B is the bandwidth in hertz.

Bandwidth has two meanings. For a signal or a channel it is the width of the range of frequencies passed, in hertz: a telephone voice channel passes about 300 to 3,400 Hz, a bandwidth of about 3.1 kHz (4 kHz with guard bands). For a link it is the bit rate, in bits per second. The two are tied: more hertz allow more bits per second, and Nyquist and Shannon say exactly how many.

Nyquist (1924): the noiseless channel. A channel of bandwidth B can carry at most 2B signal changes a second, and each change between L levels carries log2L bits:

C=2Blog2Lbits per second

A noiseless 3 kHz channel carries 2 × 3000 × 1 = 6 kbps with 2 levels, and 2 × 3000 × 4 = 24 kbps with 16 levels. More levels raise the rate, but the receiver must still tell them apart, and noise makes levels that are close together impossible to distinguish. That is Shannon's limit.

Shannon (1948): the noisy channel. No number of levels can beat

C=Blog2(1+SNR)

where SNR is the signal power divided by the noise power, as a plain ratio. In decibels, SNRdB=10log10(S/N): 10 dB is a ratio of 10, 20 dB of 100, 30 dB of 1000. Always turn decibels back into a ratio before using Shannon.

  • Example, a telephone line: B = 3,000 Hz and SNR = 30 dB (1,000): C=3000log21001 ≈ 29.9 kbps. That is why dial-up modems on analog lines stopped near 33.6 kbps.
  • Using both together: Shannon gives the ceiling, Nyquist the levels needed. For B = 2 MHz and SNR = 255, Shannon gives 2×106log2256 = 16 Mbps. Choosing a safer 12 Mbps, Nyquist gives 12×106=2×2×106log2L, so log2L=3 and L = 8 levels.

Why the received signal is worse than the one sent (transmission impairments):

ImpairmentWhat happensExample
Attenuationthe signal loses power with distance, measured in decibelsamplifiers or repeaters every few km on copper
Distortionthe frequency components of a signal travel at different speeds, so its shape changespulses spreading in a long cable or a multimode fiber
Noiseunwanted energy is added: thermal (moving electrons), induced (motors, power lines), crosstalk (one pair into another), impulse (spikes from lightning or switching)the hiss on a phone line

Loss in decibels is 10log10(Pout/Pin): a signal that falls to half its power has lost about 3 dB.

The board question (2066 Bhadra) gives the signal as 2 mW and the noise as 200 µW: put both in milliwatts first (200 µW = 0.2 mW), so SNR = 10, which is 10 dB; then C=300×106log211 ≈ 1.04 Gbps. It is worked in full in the Numericals panel.

To remember: bandwidth is the width of the road, the number of levels is how many lanes the drivers can keep apart, and noise is the dust that makes lane markings unreadable; Shannon is the road authority's limit that no lane painting can beat.

Asked on the paper, word for word
  • Calculate SNR and maximum channel capacity of a cat6 channel having bandwidth 300 MHz with 2mW and 200 μW as signal and noise power respectively. 2066 Bhadra Q2b · 4+4
In the exam Write the formula, name every symbol with its unit, turn dB into a ratio, then substitute. Without a log2 key, use log2x=log10x/log102.

2.2Transmission media

Transmission media: the kinds, and how to choose one HOT 7/27

81 Bh · 81 Ba · 80 Bh · 76 Ch · 74 Ch · 72 Ka · 71 Shr2+63+53+3+2

Transmission medium The physical path between a transmitter and a receiver that carries the signal (electric current, light or electromagnetic waves) from source to destination. It lies below the physical layer, which controls it, and is either guided (wired) or unguided (wireless).
TRANSMISSION MEDIA Guided media keep the signal on a cable; unguided media radiate it from an antenna into air or space. Transmission media Guided (wired) signal on a solid path Unguided (wireless) signal from an antenna Twisted pair UTP, STP telephone, LAN Coaxial cable thin, thick; RG-6 cable TV, CCTV Optical fiber single, multimode backbone, FTTH Radio waves 3 kHz to 1 GHz AM, FM, TV Microwaves 1 to 300 GHz terrestrial, satellite Infrared 300 GHz to 400 THz remotes, short links bounded: speed and security, limited by the cable unbounded: mobility and reach, open to anyone

Guided media confine the signal to a solid path: twisted pair, coaxial cable and optical fiber. The cable decides where the signal goes, so they are fast, secure and predictable, but only reach where a cable can be laid. Unguided media radiate the signal from an antenna into air, water or space: radio, microwave and infrared. No cable means mobility and reach, but the signal is open to anyone in range and to the weather.

PointGuided (wired)Unguided (wireless)
Signal pathalong a cablethrough air or space, from an antenna
Examplestwisted pair, coaxial cable, optical fiberradio, microwave (terrestrial, satellite), infrared
Data ratehigh: up to terabits on fiberlower, and shared by every user in range
Securitymust be tapped physicallyanyone in range can receive it
Interferencelow (shielding; none on fiber)weather, obstacles, other transmitters
Mobilitynoneusers move freely
Installationcable must be laid: costly over hills and riverstowers and antennas only
Cost with distancegrows with the cable lengthalmost independent of distance (satellite)

Factors in choosing a medium. No medium is best everywhere; the designer weighs these:

FactorThe question to askWho wins
1. Bandwidth and data rateHow many bits per second now, and in five years?fiber, then coaxial, then twisted pair
2. Distance and attenuationHow far before a repeater is needed?single mode fiber (tens of km); UTP Ethernet stops at 100 m
3. CostCable, connectors, equipment, labour and upkeep?UTP is cheapest; fiber optics and satellites cost most
4. Noise immunityMotors, power lines or lightning nearby?fiber is immune to EMI; STP and coaxial beat UTP
5. SecurityCan someone tap it unnoticed?fiber is hardest to tap; radio is easiest to intercept
6. Ease of installationFlexibility, weight, bend radius, skills?UTP is light and easy; fiber needs splicing
7. Environment and terrainIndoors or outdoors, across a river or a ridge?microwave or satellite where a cable cannot go
8. MobilityDo the users move?only wireless

Also weighed: reliability (rain fade, cable cuts), scalability (room to add users) and regulation (radio spectrum needs a licence).

Worked example: media for a new college campus
  • Offices and labs within 90 m of the floor switch: Cat 6 UTP, cheap and easy, 1 Gbps.
  • The link of about 400 m between the main block and the library: multimode fiber. It is beyond UTP's 100 m, and an outdoor copper run would invite lightning (1000BASE-SX reaches 550 m on OM2 multimode).
  • The hostel across the river, where no cable can be laid: a point-to-point microwave or Wi-Fi bridge between two masts in line of sight.
  • Laptops and phones in the canteen: Wi-Fi.
  • The internet connection from the ISP: single mode fiber.

Merits and demerits, one line each: twisted pair is cheap and easy, but noisy and short; coaxial cable has better shielding and bandwidth, but is bulky; fiber has enormous bandwidth and immunity to EMI, but is costly to install; radio reaches everywhere through walls, but at low rates in a crowded spectrum; microwave carries high rates over long hops, but needs line of sight and fades in rain; infrared is private to a room, but short and blocked by walls. The next four cards explain each (guided media, optical fiber, unguided media, satellite).

Asked on the paper, word for word
  • What are the factors to be considered while selecting media for communication? Differentiate between datagram and virtual circuit switching approach with respect to Frame Relay Network. 2081 Bhadra Q2 · 2+6
  • List out the most common guided and unguided transmission media used in computer networks now a days. Explain any one of the guided transmission media with examples. 2081 Baishakh Q2 · 3+5
  • a) Discuss about the different factors of choosing the transmission media." Circuit switching is suitable for real-time communication", give your reasons. If a file of 1000 bytes was sent over a network in 2 seconds, calculate throughput. 2080 Bhadra Q2 · 3+3+2
  • What is transmission medium? Explain different transmission medium with their merits and demerits. 2076 Chaitra Q2 · 1+7
  • Define transmission media. Compare among Twisted Pair, Coaxial cable and Fiber optic. 2074 Chaitra Q2 · 3+5
  • List out the functions of physical layer in TCP/IP reference model. Explain different types of transmission media. 2072 Kartik Q2 · 2+6
  • What is transmission media? Explain about any three transmission media in detail. 2071 Shrawan Q2 · 2+6
In the exam A definition wants the definition, then guided and unguided with examples (draw the tree). A factors question wants six to eight factors, one line each; a campus example like the one above earns the last marks.

Twisted pair and coaxial cable, compared with fiber HOT 7/27

81 Ba · 76 Ch · 74 Ch · 74 Ash · 71 Shr · 68 Ba · 66 Po2+63+51+7

Guided media Cables that carry the signal along a solid path. Twisted pair and coaxial cable carry it as an electric current in copper; optical fiber carries it as light in glass (its own card: optical fiber).
GUIDED MEDIA IN CROSS SECTION Copper carries current in twisted pairs or round a common axis; glass carries light in a core. Twisted pair (UTP) copper conductor insulation, colour coded jacket (STP adds a shield) one pair from the side: the twists cancel noise Coaxial cable inner copper conductor insulation (dielectric) braid: outer conductor, shield plastic jacket Optical fiber core: glass, 8 to 62.5 µm cladding: 125 µm buffer coating jacket (Kevlar inside)

Twisted pair cable is two insulated copper conductors, each about half a millimetre across (22 to 26 AWG), twisted around each other; a LAN cable bundles four pairs in one jacket, a telephone drop has one or two. It is the cheapest and most widely used medium.

Why twist: a noise source induces almost the same voltage in both wires of a pair, and the receiver reads only the difference between them, so the noise cancels. Giving neighbouring pairs different twist rates keeps them from coupling into each other (crosstalk).

Types of twisted pair cable are named three ways.

1. By shielding:

TypeConstructionMeritsDemeritsUse
UTP (unshielded)no shieldcheap, thin, flexible, easy to terminatepicks up EMI; more crosstalkalmost every office LAN; telephone lines
STP (shielded)a grounded foil or braid around each pair, the whole cable, or bothless EMI and crosstalk; higher ratescostlier, stiffer, must be groundedfactories, runs beside power cables, 10 Gbps and above

ISO/IEC 11801 names the shields exactly: U/UTP (none), F/UTP (foil around all pairs), U/FTP (foil around each pair), S/FTP (braid overall and foil on each pair).

2. By category (ANSI/TIA-568):

CategoryBandwidthTypical use
Cat 316 MHztelephone; 10BASE-T Ethernet (10 Mbps)
Cat 5100 MHz100BASE-TX (100 Mbps)
Cat 5e100 MHz1000BASE-T (1 Gbps)
Cat 6250 MHz1 Gbps; 10 Gbps up to about 55 m
Cat 6A500 MHz10GBASE-T to 100 m
Cat 7 (ISO class F)600 MHzshielded 10 Gbps
Cat 82000 MHz25 and 40 Gbps up to 30 m, in data centres

3. By the wiring at the RJ-45 ends (T568A and T568B are the two pin orders):

  • Straight-through: the same order at both ends; joins unlike devices, such as a PC to a switch or a router to a switch.
  • Crossover: T568A at one end and T568B at the other, so transmit meets receive; joins like devices, a PC to a PC or a switch to a switch. Most modern ports (auto-MDIX) cross over by themselves.
  • Rollover (console): the pin order fully reversed; joins a PC's serial port to the console port of a router or switch.

Characteristics (the book): analog loops need amplifiers every 5 to 6 km and digital links repeaters every 2 to 3 km; an Ethernet segment over UTP stops at 100 m (90 m of fixed cable plus patch cords). Uses: the telephone local loop, DSL, Ethernet LANs (Ethernet), Power over Ethernet for IP cameras and access points. Merits: cheapest, light, flexible, easy to install and extend. Demerits: noise and crosstalk, short range, less bandwidth than coaxial or fiber, easy to tap.

Coaxial cable, from the centre out: a copper conductor; a layer of insulation (the dielectric); an outer conductor of braided wire or foil, which is both the return path and a shield; and a plastic jacket. The two conductors share one axis, hence "coaxial". The shield keeps noise out and the signal in, so coaxial cable carries far higher frequencies than twisted pair, up to about 1 GHz. Common cables are 5 to 7 mm thick (RG-58, RG-6); heavy trunk cables run to 1 to 2.5 cm (the book's figure).

  • Grades: RG-59 and RG-6 (75 Ω) for cable TV and CCTV; RG-58 (50 Ω) for thin Ethernet, 10BASE2; RG-8 (50 Ω) for thick Ethernet, 10BASE5. Connectors: BNC, F-type (TV), N-type.
  • Uses: cable TV and cable internet, CCTV, antenna leads; once, long-distance telephone trunks and early Ethernet, now replaced by fiber and UTP.
  • Merits: wide bandwidth, good noise immunity, longer runs than twisted pair.
  • Demerits: thicker, stiffer and dearer than UTP; on a shared bus one fault takes every station down; amplifiers needed every few km.

The three compared:

PointTwisted pairCoaxial cableOptical fiber
Signalelectricalelectricallight
Structuretwo insulated copper wires, twistedcentral conductor, insulation, braid shield, jacketglass core, cladding, buffer, jacket
Bandwidthlowest: 16 MHz to 2 GHz by categorymoderate: up to about 1 GHzhighest: terahertz range
Data rate10 Mbps to 10 Gbps (40 on Cat 8)10 Mbps (old Ethernet) to a few Gbps (cable TV networks)10 Gbps a wavelength; terabits with WDM
Distance without repeater100 m for Ethernethundreds of metres to a few kmkm on multimode, tens of km on single mode
Noise immunitylow (STP better)goodcomplete: no EMI, no crosstalk
Attenuationhighmoderatelowest: about 0.2 dB/km at 1550 nm
Power loss by (book)conduction and radiationconductionabsorption, scattering, dispersion, bending
Securityeasy to taphardervery hard to tap
Costcheapestmoderatehighest to install
Installationeasiestmoderateneeds skilled splicing
Typical useLANs, telephone loopscable TV, CCTVbackbones, FTTH, submarine links
To remember: one hostel, three cables

The Cat 6 UTP from each room's wall jack to the floor switch; the coaxial lead from the rooftop dish to the TV in the common room; the single strand of fiber from the ISP's pole to the building's router. And when the new computer lab turns out to be 160 m from the switch, UTP cannot reach (100 m): a second switch half way, or fiber, solves it.

Asked on the paper, word for word
  • List out the most common guided and unguided transmission media used in computer networks now a days. Explain any one of the guided transmission media with examples. 2081 Baishakh Q2 · 3+5
  • What is transmission medium? Explain different transmission medium with their merits and demerits. 2076 Chaitra Q2 · 1+7
  • Define transmission media. Compare among Twisted Pair, Coaxial cable and Fiber optic. 2074 Chaitra Q2 · 3+5
  • Define switching and multiplexing. Explain about any two guided transmission media in detail. 2074 Ashwin Q2 · 2+6
  • What is transmission media? Explain about any three transmission media in detail. 2071 Shrawan Q2 · 2+6
  • What are types of twisted pair cable? Calculate the efficiency of slotted Aloha. 2068 Baishakh Q2 · 4+4
  • Describe guided and unguided media used in computer network with their advantages. 2066 Poush Q2 · 8
In the exam "Types of twisted pair" wants UTP and STP, the categories and the three wirings. "Explain any one guided medium" wants construction (draw the cross section), types, characteristics, uses, merits and demerits. A comparison wants the three-column table, eight to ten rows.

Optical fiber: light in glass PIN 1/27

82 Bh4+2

Optical fiber A thin strand of very pure glass (or plastic) that carries information as pulses of light, kept inside by total internal reflection at the boundary between a core of higher refractive index and the cladding of lower refractive index around it.

Structure, from the centre out: the core of glass (8 to 10 µm across in single mode fiber, 50 or 62.5 µm in multimode); the cladding, glass of a lower refractive index, 125 µm across; a plastic buffer coating, 250 µm; strength members of aramid yarn (Kevlar); and the outer jacket. The cross section is drawn on the guided media card (guided media).

How the light stays in: total internal reflection. Light passing from a denser medium (the core, index n1) into a rarer one (the cladding, n2, smaller than n1) bends away from the normal. Beyond the critical angle it does not cross at all: it is reflected back into the core, and does so again at every bounce along the fiber.

θc=sin−1(n2n1)NA=n12−n22

Example: with n1 = 1.48 and n2 = 1.46, the critical angle is sin−1(1.46/1.48) ≈ 80.6°, so a ray must meet the boundary at more than 80.6° from the normal, almost parallel to the axis. The numerical aperture NA = 1.482−1.462 ≈ 0.243, so light entering within about 14° of the axis is caught.

Propagation modes:

PROPAGATION MODES IN OPTICAL FIBER The thinner the core, the fewer the paths, and the less a pulse spreads on its way. Multimode step index core 50 µm or more pulse spreads most: short links only Multimode graded index 50 or 62.5 µm core less spreading: LAN backbones Single mode 8 to 10 µm core pulse keeps its shape: long haul, FTTH green band: cladding, lower refractive index; blue band: core, higher refractive index
ModeCoreHow light travelsSourceReach and use
Multimode step indexlarge (50 µm or more), one refractive index throughoutrays bounce at many angles; paths of different lengths spread the pulse (modal dispersion)LEDshortest; old LANs, plastic fiber
Multimode graded index50 or 62.5 µm, index falling from the axis outwardrays curve back gently; outer rays travel faster in the lower index, so arrivals bunch upLED or VCSEL laserup to about 550 m at 1 Gbps; building backbones
Single mode8 to 10 µmessentially one ray along the axis: no modal dispersionlaser diodetens of km and more; ISP backbones, FTTH, submarine cables

Sources and detectors (the book):

  • LED: cheaper, longer life, works over a wider temperature range; incoherent, broad spectrum, low power: short multimode links.
  • Injection laser diode (ILD): coherent, narrow spectrum, far more power, very fast to modulate: long single mode links.
  • Detectors: the PIN photodiode (simple, cheap) or the avalanche photodiode, APD (internal gain, more sensitive, for long links).

Wavelength windows, and "its RF range". Fiber is used where glass absorbs least: 850 nm (multimode, short reach), 1310 nm (single mode, least dispersion) and 1550 nm (lowest loss, about 0.2 dB/km; used with erbium-doped fiber amplifiers and DWDM). With f=c/λ, these are about 353 THz, 229 THz and 193 THz: near-infrared light, between about 190 and 355 THz, some 650 to 1,200 times higher than the top of the radio frequency (RF) range at 300 GHz. That enormous carrier frequency is why fiber's bandwidth is so large. The electrical signal fed to the transmitter can itself be anything from voice to a radio signal: radio-over-fiber links carry mobile radio signals to antenna sites this way.

A generic optical fiber communication system (2082 Bhadra):

AN OPTICAL FIBER COMMUNICATION SYSTEM Electrical to light at one end, light through glass, light to electrical at the other. Message source voice, video or data, electrical Electrical transmitter coder, modulator, driver Optical source LED or laser diode: current to light Destination the user gets the message Electrical receiver amplifier, equalizer, decoder Optical detector PIN or APD diode: light to current Repeater or optical amplifier light light Optical fiber cable connectors and splices; light at 850, 1310 or 1550 nm TRANSMITTER electrical in, light out CHANNEL light, weakened and spread RECEIVER light in, electrical out
  1. Message source: the information as an electrical signal (voice, video, data).
  2. Electrical transmitter: codes and modulates it and drives the light source with a matching current.
  3. Optical source: an LED or laser diode turns the current into light pulses, which are coupled into the fiber.
  4. Optical fiber cable, the channel, with connectors and splices; on long links, repeaters (light to electrical to light) or optical amplifiers (EDFAs, which amplify the light directly) make up for attenuation.
  5. Optical detector: a PIN or avalanche photodiode turns the light back into a current.
  6. Electrical receiver: amplifies, equalizes, regenerates and decodes the signal.
  7. Destination: the user gets the message.

Advantages: very high bandwidth; low attenuation, so repeaters can be tens of km apart; immune to electromagnetic interference and lightning; no crosstalk; very hard to tap; thin and light; no sparks and no shock hazard, so safe near fuel; no corrosion; long life. Disadvantages: costly to install, terminate and test; fragile, with a minimum bend radius; splicing needs skill and equipment; light goes one way, so a duplex link needs two fibers or two wavelengths; it cannot carry power to devices as copper can.

To remember: a fiber-to-the-home (FTTH) connection, of the kind WorldLink and Vianet run in Nepali cities: single mode fiber from the ISP's equipment to a passive splitter, which shares it among many houses, and in each house an ONT box that is the optical detector and receiver, turning the light back into Ethernet and Wi-Fi.

The book says fiber reaches 2 to 5 km on multimode and 25 km on single mode. Reach depends on the data rate and the optics: at 1 Gbps multimode reaches about 550 m, and single mode 10 km with ordinary optics and 40 to 80 km with long-reach optics.
Asked on the paper, word for word
  • Explain line of sight (LOS) propagation modes. Draw block diagram generic optical fiber (OF) communication system and its RF range. 2082 Bhadra Q2 · 4+2
In the exam For the block diagram, draw the U with its seven blocks, mark the electrical and optical parts, and for "its RF range" give the three wavelength windows and their frequencies. For modes, draw the three fibers with the pulses spreading.

Unguided media: radio, microwave, infrared and how waves travel HOT 5/27

82 Bh · 81 Ba · 76 Ch · 71 Shr · 66 Po1+72+63+5

Unguided (wireless) media Media that carry electromagnetic waves through air, water or space without a conductor: an antenna radiates the signal at the transmitter and another antenna collects it at the receiver.

Antennas are either omnidirectional, radiating all round (a radio mast, a Wi-Fi access point), or directional, focusing a narrow beam (the parabolic dish and horn antennas of microwave and satellite links).

The three unguided media, with the frequency bands the book uses:

MediumFrequencyDirectionPropertiesUses
Radio waves3 kHz to 1 GHzomnidirectionaltravel far and pass through walls; low data rates; a crowded, licensed spectrumAM and FM radio, TV, cordless phones, paging: one sender, many receivers
Microwaves1 to 300 GHzunidirectional, line of sighthigh data rates; antennas must be aligned; the higher bands do not pass walls, and rain fades them above about 10 GHzterrestrial links between towers, satellite links, cellular networks, Wi-Fi at 2.4, 5 and 6 GHz
Infrared300 GHz to 400 THzline of sight, short rangehigh rates, but cannot pass walls (private to one room); sunlight interferesTV remotes, short links between devices

Terrestrial microwave (the book) uses the 4 to 6 GHz and 21 to 23 GHz bands between parabolic dishes on towers, hills or tall buildings; its repeaters stand farther apart than coaxial cable's, and it is the choice across rivers and mountains where a cable is impractical. Satellite links have their own card (satellite communication).

Propagation methods. How a wave reaches the receiver depends mainly on its frequency (the book's Figures 2.13 to 2.15):

HOW A RADIO WAVE TRAVELS The frequency decides the path: low hugs the ground, middle bounces off the ionosphere, high goes straight. Ground wave below 2 MHz AM medium wave, navigation earth Sky wave 2 to 30 MHz shortwave radio, amateur earth Line of sight above 30 MHz FM, TV, microwave, satellite earth follows the curve of the earth ionosphere long range, low power antennas must see each other the earth’s curve limits the range: tall towers reach further one antenna: d = 4.12 √h km (h in metres, with refraction)
MethodFrequencyHow the wave travelsUses
Ground (surface) wavebelow 2 MHzlow frequency waves follow the curvature of the earth; the range is set by the transmitter's powerAM medium wave broadcasting, maritime and navigation beacons
Sky (ionospheric) wave2 to 30 MHzthe wave goes up and the ionosphere bends it back to earth far away: long distances with low power, varying between day and nightshortwave broadcasting, amateur radio
Line of sight (space wave)above 30 MHza straight line between antennas that can see each other; the range is limited by the earth's curvatureFM, TV, microwave links, mobile phones, satellites

Line of sight propagation, closely (2082 Bhadra):

  • Direct wave: the main path, straight from antenna to antenna.
  • Ground-reflected wave: a second path bouncing off the ground or water. Together with the direct wave it forms the space wave, and the two can add or cancel, one cause of multipath fading.
  • Optical and radio line of sight: the atmosphere bends radio waves slightly towards the earth, so they reach a little beyond the visible horizon. With the antenna height h in metres and K = 4/3 (Stallings):
doptical=3.57h km,dradio=3.57Kh≈4.12h km
  • Two antennas can be up to 3.57(Kh1+Kh2) km apart. Two 50 m towers each reach 3.5766.7 ≈ 29.2 km, so they can stand about 58 km apart; that is why microwave and broadcast towers stand on hilltops.
  • Impairments on a line of sight link: free-space loss (rising with distance and frequency), absorption by rain and water vapour (above about 10 GHz), multipath reflections, refraction, and obstacles such as hills, buildings and trees in the path.
  • Satellites are also line of sight to their earth stations, and the way round the earth's curvature for long distances.

Wi-Fi, Bluetooth and mobile networks all use microwave bands, chiefly the 2.4 and 5 GHz ISM bands; how stations share the air is chapter 3's subject (wireless LAN), and securing them chapter 8's (WEP).

To remember: a medium wave AM station is heard beyond the hills, and farther still at night (ground and sky waves); an FM station fades once a ridge stands between the radio and its tower (line of sight); and the TV remote stops working the moment a roommate stands in front of the TV (infrared).

Asked on the paper, word for word
  • Explain line of sight (LOS) propagation modes. Draw block diagram generic optical fiber (OF) communication system and its RF range. 2082 Bhadra Q2 · 4+2
  • List out the most common guided and unguided transmission media used in computer networks now a days. Explain any one of the guided transmission media with examples. 2081 Baishakh Q2 · 3+5
  • What is transmission medium? Explain different transmission medium with their merits and demerits. 2076 Chaitra Q2 · 1+7
  • What is transmission media? Explain about any three transmission media in detail. 2071 Shrawan Q2 · 2+6
  • Describe guided and unguided media used in computer network with their advantages. 2066 Poush Q2 · 8
In the exam "Line of sight propagation modes": the three modes with their bands (draw the three panels), then the direct and ground-reflected waves, the radio horizon formula and the impairments.

Satellite communication

Communication satellite A microwave relay station in orbit. An earth station sends a signal up (the uplink); the satellite's transponder receives it, amplifies it and shifts it to another frequency; and it is sent down (the downlink) to one or many earth stations.

The transponder is the receiver and transmitter pair on board; its two jobs are amplification and frequency translation. A satellite carries many transponders, each serving one band of frequencies.

The uplink is higher than the downlink: about 6 GHz up and 4 GHz down in the C band, about 14 GHz up and 11 to 12 GHz down in the Ku band. Different frequencies keep the strong outgoing signal from drowning the weak incoming one, and the higher frequency, which fades more, goes to the earth station, which can afford a bigger transmitter than the satellite.

OrbitAltitudeOne orbitFeaturesExample
LEO (low earth orbit)about 500 to 2,000 kmabout 90 to 120 minutesdelay of a few ms; small footprint, so many satellites are neededStarlink, Iridium satellite phones
MEO (medium earth orbit)from about 2,000 km up to the geostationary heighthours (GPS: about 12 h)used mainly for navigationGPS, at about 20,200 km
GEO (geostationary)35,786 km above the equator23 h 56 min 4 s, one turn of the earthappears fixed, so dishes need no tracking; three satellites 120° apart cover almost all the earth but the poles; long delayTV broadcasting (DTH), VSAT
Worked example: how long a geostationary hop takes

Up and down is at least 2 × 35,786 = 71,572 km. At 3×108 m/s that takes 71,572,000 / (3×108) ≈ 0.239 s. A question and its reply each cross the hop, so a conversation waits about 0.48 s for every answer: the pause heard on satellite telephone calls. A LEO satellite at 550 km gives 2 × 550 km / (3×108 m/s) ≈ 3.7 ms.

Frequency bands (the IEEE letter bands, the book's Table 2.2): L 1 to 2 GHz, S 2 to 4, C 4 to 8, X 8 to 12, Ku 12 to 18, K 18 to 27, Ka 27 to 40, V 40 to 75 and W 75 to 110 GHz. The L band carries GPS and satellite phones, the C band TV distribution (it suffers least from rain), the Ku band direct-to-home TV and VSAT, the Ka band high-throughput broadband.

Merits: one satellite covers a whole country or continent; within the footprint the cost does not depend on distance; it broadcasts naturally to many receivers; it reaches mountains and islands where a cable cannot go. Demerits: the long delay of GEO; the high cost of building and launching; a life of about 12 to 15 years (the book), so a replacement must be planned; rain fade in the Ku and Ka bands; and the orbit must be watched and corrected (station keeping).

Other kinds of satellite (the book): astronomical, biosatellites, communication, earth observation (weather, mapping), navigation (GPS) and killer satellites (anti-satellite weapons).

To remember: every direct-to-home TV dish on a Kathmandu rooftop points south and never moves: its geostationary satellite sits over the equator, south of Nepal, keeping pace with the turning earth.

The book says LEO satellites fly at 500 to 1,500 km and MEO satellites at 5,000 to 15,000 km, yet names GPS, at about 20,200 km, as the commonest MEO satellite. The usual boundaries are those in the table: LEO up to about 2,000 km, MEO from there to the geostationary height.

2.3Multiplexing

Multiplexing: many signals on one link HOT 6/27

80 Ba · 79 Bh · 74 Ash · 73 Shr · 69 Ch · 67 Asa4+41+2+52+2+4

Multiplexing The set of techniques that let several signals share one link at the same time. A multiplexer (MUX) combines n input lines into one high-capacity link; a demultiplexer (DEMUX) at the far end separates them back onto n output lines.

Why it matters:

  • Efficiency: a link's capacity is usually far more than one user needs; one fiber can carry thousands of telephone calls.
  • Cost: one cable or one radio band instead of n, so less cable, installation and upkeep.
  • It makes networks possible: trunks, broadcasting, cable TV, mobile networks and the internet's backbone all depend on it.
  • Scalability: users are added without laying new lines.

One bus carrying forty passengers on one road, instead of forty taxis, is the idea.

HOW A LINK IS SHARED Three senders A, B and C on one link; in every picture time runs left to right. FDM a band per sender; grey: guard bands; WDM: same, with light Synchronous TDM fixed slot per sender every frame; idle slot wasted; F tab: framing Statistical TDM slots on demand; each slot carries its sender address CDM all at once, whole band; orthogonal codes separate senders A on band f1, all the time B on band f2, all the time C on band f3, all the time A1 B1 C1 frame 1 A2 B2 empty frame 2 A3 empty C3 frame 3 A4 empty empty frame 4 4 of 12 slots wasted A A1 B B1 frame 1 C C1 A A2 frame 2 B B2 A A3 frame 3 C C3 A A4 frame 4 grey tab: address A × code a + B × code b + C × code c sent together over the whole band; multiplying by code a gives back A

FDM (frequency division multiplexing) is analog. The link's bandwidth is divided into frequency bands, one per signal; each signal modulates its own carrier; unused strips called guard bands keep neighbours from overlapping; and all the signals travel at the same time. Uses: AM radio (530 to 1700 kHz), FM radio (88 to 108 MHz), TV channels, first generation mobile phones, cable TV. The old analog telephone network packed 12 voice channels of 4 kHz into a 48 kHz group.

WDM (wavelength division multiplexing) is FDM for light: each signal rides its own wavelength (colour) on one fiber, and a prism or diffraction grating combines and separates them. Dense WDM (DWDM) packs dozens of wavelengths, 0.8 nm (100 GHz) apart in the 1550 nm band, onto one fiber, each carrying 10 to 100 Gbps or more.

TDM (time division multiplexing) is digital. The link's time is divided into slots, and the inputs take turns, each sending one unit (a bit, a byte or a block) in its slot; one round of slots is a frame, marked by framing bits. The link rate must be n times an input's rate.

  • Synchronous TDM: every input owns a fixed slot in every frame, even when it has nothing to send, so idle slots are wasted. T1 and E1 work this way (the digital hierarchy).
  • Statistical (asynchronous) TDM: slots go only to inputs that have data, so a frame has fewer slots than there are inputs and none is wasted; each slot carries the address of its input, and buffers absorb bursts. It suits bursty data.
Worked example: four voice inputs on one line

Four 64 kbps voice inputs are multiplexed by synchronous TDM, one byte per slot, with one framing bit per frame.

  • Each input delivers 8,000 bytes a second, so the multiplexer sends 8,000 frames a second, one every 125 µs.
  • Frame = 4 × 8 + 1 = 33 bits; link rate = 33 × 8,000 = 264 kbps.
  • Each slot lasts 8 / 264,000 s ≈ 30.3 µs. The same sum with 24 inputs gives T1: 193 bits a frame, 1.544 Mbps.

CDM (code division multiplexing), as CDMA, lets every station send at the same time over the whole band. Each multiplies its data by its own chip code; the codes are orthogonal (the inner product of two different codes is zero); and a receiver multiplies the sum on the channel by one station's code to get that station's data back. Used in 3G mobile networks (CDMA2000, W-CDMA) and GPS.

Example: codes a = (+1, +1) and b = (+1, −1). A sends bit 1 as +1, B sends bit 0 as −1, and the channel carries (+1)(+1,+1) + (−1)(+1,−1) = (0,+2). A's receiver computes (0 × 1 + 2 × 1) / 2 = +1, bit 1; B's computes (0 × 1 + 2 × (−1)) / 2 = −1, bit 0.

PointFDMWDMTDMCDM
Sharesfrequencywavelengthtimecodes
Signalanalogopticaldigitaldigital
Kept apart byguard bandswavelength spacingframing and slot positionorthogonal codes
ExampleFM radio, cable TVfiber backbonesT1, E1, GSM3G CDMA, GPS

Switching against multiplexing in one line: multiplexing shares one link among many signals; switching chooses the path through the network. The full comparison is on the switching card (switching).

To remember: every FM station in the Kathmandu valley has its own frequency between 88 and 108 MHz, and the radio picks one: that is FDM. A call between two cities rides one 64 kbps time slot of an E1 trunk: that is TDM.

Asked on the paper, word for word
  • What is multiplexing? What is its importance in communication? Explain different types of multiplexing techniques. 2080 Baishakh Q2 · 1+2+5
  • What is switching and multiplexing? Explain switching technique used in modern computer networks. 2079 Bhadra Q2 · 4+4
  • Define switching and multiplexing. Explain about any two guided transmission media in detail. 2074 Ashwin Q2 · 2+6
  • What do you mean by switching in communication? Compare switching with multiplexing. Explain the E1 Telephone hierarchy system. 2073 Shrawan Q2 · 2+2+4
  • Define switching and multiplexing. Differentiate between circuit switching and packet switching. 2069 Chaitra Q2 · 4+4
  • What do you mean by ISDN and what is it contribution in the field of data communication? Explain various types of multiplexing mechanism used in communication. 2067 Ashad Q3 · 3+5
In the exam Define it with the MUX and DEMUX sentence; give its importance in four points; then the types, FDM (guard bands), WDM, TDM (synchronous and statistical) and CDM, each with an example and the drawing.

2.4Switching

Switching: circuit, message and packet TOP 13/27

80 Bh · 79 Bh · 75 Ch · 75 Ash · 74 Ch · 74 Ash · 73 Shr · 70 Ch · 69 Ch · 68 Ch · 68 Ba · 67 Asa · 66 Bh2+64+41+2+5

Switching The method by which a network connects a sender to a receiver through intermediate nodes (switches) instead of a dedicated link between every pair. A switch forwards what arrives on an input port (ingress) to the output port (egress) that leads towards the destination.

Why switch at all. Linking n devices directly needs a mesh of n(n−1)/2 links: 1,000 telephones would need 499,500 lines. With switching each needs one line to a switch, and the switches are linked to each other.

The three techniques (the book's Figure 2.18): circuit switching, message switching, and packet switching, the last in two forms, datagram and virtual circuit. Inside a switch, circuits are themselves made by space division or time division (switching systems). The same message sent all three ways:

CIRCUIT, MESSAGE AND PACKET SWITCHING One message from A to D through switches B and C; time runs downward in each panel. Circuit switching A B C D Message switching A B C D Packet switching A B C D call request call accepted data, one stream release whole message stored at each node arrives last 1 1 1 2 2 2 3 3 3 packets pipelined arrives first setup first, then one stream: no stop at B or C B and C store the whole message before passing it on packets overlap on the links; no setup, no reservation

Circuit switching reserves a dedicated path, the circuit, from end to end before any data flows, and holds it for the whole session; on each link the circuit is one channel, a frequency band in FDM or a time slot in TDM. It works in three phases:

  1. Setup (circuit establishment): a call request travels from switch to switch; each switch reserves a channel on its next link; an acceptance comes back.
  2. Data transfer: data flows continuously along the reserved path, with no addresses, no store-and-forward and no queuing at the switches.
  3. Teardown (disconnect): a release signal frees every reserved channel.

Example: a call on the public switched telephone network (PSTN).

Message switching has no setup and no reserved path. The whole message, with the destination address attached, goes to the next node, is stored there (on disk) until the next link is free, then is forwarded: a store-and-forward network. Its drawbacks (the book): every node needs storage for the largest message; the delays add up hop by hop; and it is useless for interactive or real-time traffic. It was used in telegraph and telex networks and has been replaced by packet switching.

Packet switching cuts the message into packets of limited size, each with a header (addresses, a sequence number). Each node stores and forwards packets one at a time; the links are shared by every user, and capacity is used only when there is data (statistical multiplexing). Because packets overlap on successive links, a pipeline, a message crosses many hops far faster than by message switching. It has two forms, datagram and virtual circuit (datagram and virtual circuit). Example: the internet.

Worked example: why packets beat whole messages

A 1 Mbit file crosses 3 links of 1 Mbps each (ignoring propagation, queuing and headers).

  • Message switching: each link takes 1 s, and each node waits for the whole message: 3 × 1 = 3 s.
  • Packet switching in 1,000 packets of 1 kbit: the last packet leaves the source after 1 s and needs two more hops of 1 ms each: 1 + 2 × 0.001 = 1.002 s.

In general, L bits over N links of rate R take NL/R by message switching and L/R+(N−1)P/R by packet switching with packets of P bits.

Circuit switching against packet switching:

PointCircuit switchingPacket switching
Patha dedicated path for the whole sessionno dedicated path; links shared
Setupneeded: setup, transfer, teardownnone in the datagram form
Bandwidthfixed and reserveddynamic, on demand
Idle capacitywasted while the line is silentused by other users' packets
Transfera continuous stream; no store-and-forwardstore-and-forward at every node
Addressingonly during setupa header on every packet
Delaysetup delay, then constant and smallno setup; variable queuing delay (jitter)
Orderalways in ordermay arrive out of order (datagram)
Congestionat setup: the call is blocked (busy tone)on every packet: queuing and loss
A switch failsthe call is cutpackets are rerouted
Chargingby time (and distance)by data volume
Suitsreal-time, constant-rate voicebursty data
Examplea telephone call (PSTN)the internet (IP)

Why circuit switching suits real-time communication:

  1. Guaranteed bandwidth: the channel is reserved for the whole call, so no other traffic competes with it and no congestion arises once the call is up.
  2. Constant, low delay with no jitter: no queuing and no store-and-forward at the switches; the voice flows at propagation speed. ITU-T G.114 recommends keeping one-way delay under 150 ms for natural conversation.
  3. In-order delivery: one fixed path, so nothing arrives out of order and nothing needs reassembling or buffering.
  4. No per-packet overhead, and no loss from overflowing buffers.
  5. The only extra wait, the setup, is paid once, before the conversation starts.

Packet networks carry voice (VoIP) only by adding priorities, jitter buffers and spare capacity, to come close to what a circuit gives by design.

Switching against multiplexing:

PointSwitchingMultiplexing
Purposeconnects a sender to a receiver across the networkshares one link among many signals
Whereat the nodes inside the networkat the two ends of a link
Deviceswitch, router, telephone exchangemultiplexer and demultiplexer
Kindscircuit, message, packetFDM, WDM, TDM, CDM
Examplean exchange connecting a call to Pokharaan E1 trunk carrying 30 calls at once

They work together: a circuit-switched call is one time slot of a multiplexed trunk on every link of its path (multiplexing).

Switching in modern computer networks: packet switching everywhere. IP routers switch datagrams by destination address; ISP backbones use MPLS, a virtual circuit technique with short labels; inside a LAN, Ethernet switches forward frames by MAC address, store and forward or cut-through (switches and routers). Circuit switching survives only in the legacy telephone network, and even voice now travels as packets (VoIP, VoLTE on 4G).

To remember: a landline call to your mother in Pokhara holds a path for as long as you talk, silences included: circuit switching. A Viber voice message to her is cut into packets that share every link with everyone else's traffic: packet switching. And on a festival morning when everyone calls home at once, the circuit-switched network answers some callers with a busy tone: no circuit is free.

Asked on the paper, word for word
  • a) Discuss about the different factors of choosing the transmission media." Circuit switching is suitable for real-time communication", give your reasons. If a file of 1000 bytes was sent over a network in 2 seconds, calculate throughput. 2080 Bhadra Q2 · 3+3+2
  • What is switching and multiplexing? Explain switching technique used in modern computer networks. 2079 Bhadra Q2 · 4+4
  • What is switching? What are the various switching techniques? Elaborate packet switching with a proper diagram. 2075 Chaitra Q2 · 1+2+5
  • Compare circuit switching and packet switching. Explain ISDN channels with architecture. 2075 Ashwin Q2 · 3+5
  • What is the main functionality of data link layer? Differentiate between circuit switching and packet switching. 2074 Chaitra Q3 · 4+4
  • Define switching and multiplexing. Explain about any two guided transmission media in detail. 2074 Ashwin Q2 · 2+6
  • What are the causes of packet delay in computer networks? What are the differences between circuit switching and packet switching? 2074 Ashwin Q3 · 2+6
  • What do you mean by switching in communication? Compare switching with multiplexing. Explain the E1 Telephone hierarchy system. 2073 Shrawan Q2 · 2+2+4
  • What do you mean by data switching? Explain about various types of switching with practical implementation example. 2070 Chaitra Q2 · 8
  • Define switching and multiplexing. Differentiate between circuit switching and packet switching. 2069 Chaitra Q2 · 4+4
  • Differentiate: a) Distance vector and link state routing algorithm b) Circuit switching and packet switching 2068 Chaitra Q5 · 2×5
  • What is a switching? Differentiate between packet switching and circuit switching. 2068 Baishakh Q1 · 2+6
  • Describe what do you understand by switching along with various types of switching mechanism. Explain the fault tolerance mechanism of FDDI. 2067 Ashad Q4 · 4+4
  • Differentiate between circuit switching and packet switching technology. Explain the operation how switched virtual circuit in frame relay network is established, maintained and teardown. 2066 Bhadra Q3b · 2+6
In the exam The comparison is the commonest question of the chapter: write eight to ten rows and draw the timing diagram. "Types of switching with practical examples": circuit (a PSTN call), message (telegraph), packet (the internet), and its forms, datagram (IP) and virtual circuit (Frame Relay, ATM, MPLS).

Datagram and virtual circuit: two ways to switch packets HOT 6/27

81 Bh · 78 Bh · 76 Ash · 75 Ch · 70 Asa · 66 Po2+61+2+51+3+4

Datagram and virtual circuit The two forms of packet switching. In datagram switching (connectionless) each packet carries the full destination address and is routed on its own. In virtual circuit switching (connection-oriented) a path is set up first and every packet follows it, carrying only a short virtual circuit identifier (VCI).
DATAGRAM AND VIRTUAL CIRCUIT NETWORKS The same four routers used two ways: every packet on its own, or every packet on one path set up first. Datagram network connectionless: each packet routed on its own R1 R2 R3 R4 A B 1 3 2 4 arrive: 2, 1, 4, 3 PACKET HEADER to B from A seq 3 data no setup; full address in every packet routers keep no state per connection packets may take different paths, out of order example: IP, the Internet Virtual circuit network connection oriented: set up, transfer, tear down R1 R2 R3 R4 A B VCI 12 VCI 25 VCI 7 VCI 31 1 2 arrive: 1, 2, 3, 4 R2’S VC TABLE from R1 in port 25 in VCI to R4 out port 7 out VCI a short VCI, swapped at every hop every packet on one path, in order a packet carries only the VCI and data examples: X.25, Frame Relay, ATM, MPLS

The datagram approach (the book's Figure 2.21): each packet, a datagram, has a header with the full source and destination address, and a payload. Every router looks up the destination in its routing table and forwards the packet at once; routers keep no record of connections. The packets of one message may take different paths, arrive out of order, be lost or be duplicated, and the destination puts them back in order (TCP, chapter 5). Example: IP in the internet (routing).

The virtual circuit approach (the book's Figures 2.22 and 2.23) is a cross between circuit and datagram switching: it has a circuit's phases and a datagram network's packets.

  1. Setup: a setup request carrying the full destination address travels to the destination; each switch chooses the next hop and writes an entry in its VC table: incoming port and VCI, outgoing port and VCI. An acknowledgment comes back. Buffers and bandwidth can be reserved now.
  2. Data transfer: every packet carries only its VCI. A switch looks up (incoming port, incoming VCI), replaces the VCI with the outgoing one (label swapping), and sends the packet out of the outgoing port. All the packets follow one path and arrive in order.
  3. Teardown: a release request removes the entries from every switch on the path.

A VCI means something on one link only, so it can be small, and each switch may reuse the same values on its other links. In the drawing one circuit is 12 on the first link, then 25, 7 and 31.

NetworkIts VCI is calledSize
X.25logical channel number12 bits
Frame RelayDLCI (data link connection identifier)10 bits (default)
ATMVPI and VCI8 or 12 bits, and 16 bits
MPLSlabel20 bits

Types of virtual circuit:

  • Permanent virtual circuit (PVC): set up in advance by the network operator and left in place, like a leased line; no setup for each session.
  • Switched virtual circuit (SVC): set up on demand by signalling at the start of each session and torn down at its end, like a telephone call.

The comparison (the book's Table 2.3, after Tanenbaum):

IssueDatagramVirtual circuit
Circuit setupnot neededneeded
Addressingeach packet carries the full source and destination addresseseach packet carries a short VC number
State informationrouters hold no state for a connectioneach VC needs table space in every switch on its path
Routingeach packet routed independentlyroute chosen at setup; every packet follows it
A router failsno effect, except packets lost in the crashevery VC through that router is terminated
Ordermay arrive out of orderin order
Quality of servicedifficulteasy if resources are reserved at setup
Congestion controldifficulteasy if resources are reserved at setup
Header overheadlargesmall
ExamplesIPX.25, Frame Relay, ATM, MPLS

With respect to Frame Relay (2081 Bhadra): Frame Relay is a virtual circuit network. Each frame carries a 10-bit DLCI in its address field, and the switches forward frames by looking up (incoming port, DLCI) and swapping the DLCI, never by a destination address. Its circuits are mostly PVCs set up by the carrier; SVCs are set up by Q.933 signalling. Frames follow their circuit in order; the network only checks the CRC and discards damaged frames, leaving recovery to the end systems; and congestion is signalled with the FECN, BECN and DE bits. A datagram network such as IP over the same links would route every packet by its full address, with no setup and no per-circuit state. Frame Relay itself is chapter 1's (Frame Relay).

"Packet switching against virtual circuit switching" (2078 Bhadra) uses packet switching to mean the datagram approach, so this comparison is the answer. The 2070 Ashad paper prints "virus circuit switching": it means virtual circuit switching.

To remember: datagrams are taxis: every passenger states the full address and each driver picks his own road, so two friends leaving together can arrive in either order. A virtual circuit is a bus route: fixed before the first bus runs, and each bus shows only a short route number that the conductor at every stop understands.

Asked on the paper, word for word
  • What are the factors to be considered while selecting media for communication? Differentiate between datagram and virtual circuit switching approach with respect to Frame Relay Network. 2081 Bhadra Q2 · 2+6
  • Define Throughput. A network with bandwidth of 20 Mbps can pass only an average of 18,000 frames per minute with each frame carrying an average of 20,000 bits. Calculate the throughput of this network. Differentiate between Packet switching and Virtual Circuit switching. 2078 Bhadra Q2 · 1+3+4
  • Write short notes on: (Any two) a) Firewall and their types b) 803 Token Bus c) Virtual circuit switching 2076 Ashwin Q10 · 4+4
  • What is switching? What are the various switching techniques? Elaborate packet switching with a proper diagram. 2075 Chaitra Q2 · 1+2+5
  • What is virus circuit switching? Describe the operation of Frame-Relay network. 2070 Ashad Q6 · 2+6
  • What do you understand by virtual circuit switching? Explain the X.25 virtual circuit switching. 2066 Poush Q6 · 2+6
In the exam For "packet switching with a diagram", draw both networks. For a note on virtual circuit switching, give the three phases, the VC table and PVC against SVC. For the comparison, eight to ten rows.

2.5The telephone network

The telephone network, and the T1 and E1 hierarchy PIN 2/27

73 Shr · 68 Ch2+2+42+6

Telephone and the telephone network A telephone is an instrument that turns speech into an electrical signal for transmission over a line, and turns the received signal back into sound. The public switched telephone network (PSTN) is the worldwide circuit-switched network of telephones, local loops, exchanges and trunks that can connect any telephone to any other.

The telephone set (Alexander Graham Bell's patent, 1876):

PartJob
Transmitter (microphone)turns sound into a varying electric current
Receiver (earpiece)turns the current back into sound
Hook switchoff-hook closes the loop and asks for service; on-hook ends the call
Diallersends the number as pulses (rotary) or DTMF tones: each key is two tones, one from a low group (697 to 941 Hz) and one from a high group (1209 to 1477 Hz)
Ringerrings when the exchange sends ringing current
Hybrid (induction coil)joins the two-wire line to the four wires of the handset, keeping a little of the speaker's own voice in the earpiece (sidetone)

The exchange powers the line with about 48 V DC, which is why a basic telephone works even when the house has no electricity.

The network's three parts (Forouzan):

THE TELEPHONE NETWORK Telephones, local loops, exchanges in a hierarchy, and trunks between them; one call path in colour. Regional office top of the hierarchy Toll office long distance Toll office long distance End office local exchange End office local exchange End office local exchange End office local exchange trunk: multiplexed digital (E1, fiber) trunk local loop: twisted pair, 300 to 3400 Hz Kathmandu (area code 01) Pokhara (area code 061) telephones: the subscribers calling phone to called phone: loop, end office, toll, toll, end office, loop
  • Local loop: the twisted pair from each subscriber to the nearest end office (the local exchange), carrying the 300 to 3,400 Hz voice band: the last analog part of the network.
  • Switching offices: end offices connect their own subscribers; tandem offices connect the end offices of one area; toll offices carry long-distance calls. The old AT&T hierarchy had five levels: regional centre (class 1), sectional centre (2), primary centre (3), toll centre (4) and end office (5).
  • Trunks: high-capacity links between offices, multiplexed: once by FDM, now by digital TDM (E1, T1) over fiber.

Numbering follows the same hierarchy: country code, area (trunk) code, subscriber number. Nepal is +977; Kathmandu's area code is 01 and Pokhara's 061.

How the system works: one call, step by step:

  1. Off-hook: lifting the handset closes the loop; the end office detects the current.
  2. Dial tone: the exchange is ready for digits.
  3. Dialling: the number reaches the exchange as DTMF tones (or pulses) and is stored.
  4. Switching: for a local number the end office joins the two lines through its own switching network; otherwise it seizes a free trunk towards a tandem or toll office, and signalling between the exchanges (SS7) sets the circuit up hop by hop to the called end office.
  5. Ringing: if the called line is free its telephone rings and the caller hears ringback; if it is busy, the caller hears busy tone.
  6. Answer and conversation: when the called party lifts the handset the circuit is complete; the voice is analog on the two local loops and travels as 64 kbps PCM in one time slot on every digital trunk.
  7. Hang up: going on-hook at either end releases every reserved channel, and the exchange records the call for billing by time and distance.

The digital hierarchy. The trunks are digital. A voice channel of 4 kHz is sampled 8,000 times a second (Nyquist: twice the highest frequency) and each sample is coded in 8 bits: 8,000 × 8 = 64 kbps, the basic channel, DS0 in North America and E0 in the ITU system. Synchronous TDM then stacks these channels into higher levels.

T1 (North America, Japan): 24 channels; a frame is 24 × 8 = 192 bits plus one framing bit, 193 bits, sent 8,000 times a second:

193×8000=1544000 bps=1.544 Mbps(24×64=1536 kbps of voice+8 kbps of framing)
ServiceLineRateVoice channels
DS-1T-11.544 Mbps24
DS-2T-26.312 Mbps96
DS-3T-344.736 Mbps672
DS-4T-4274.176 Mbps4032

E1 (ITU-T: Europe and most of the world, Nepal and India included):

THE E1 FRAME AND THE E HIERARCHY ITU-T G.704: 32 slots of 8 bits every 125 µs; each level carries four of the one below, plus overhead. One E1 frame: 32 time slots × 8 bits = 256 bits, every 125 µs 0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 TS1 to TS15: voice channels 1 to 15 TS17 to TS31: voice channels 16 to 30 TS0: frame alignment, alarms TS16: signalling 256 bits × 8000 frames a second = 2.048 Mbps; each slot is a 64 kbps channel E0 64 kbps 1 channel ×32 E1 2.048 Mbps 30 channels ×4 E2 8.448 Mbps 120 channels ×4 E3 34.368 Mbps 480 channels ×4 E4 139.264 Mbps 1920 channels Each step: four streams plus framing and justification bits, so E2 = 4 × 2.048 + 0.256 Mbps North America and Japan use T1: 24 × 8 + 1 = 193 bits a frame × 8000 = 1.544 Mbps
  • Frame: 32 time slots, TS0 to TS31, of 8 bits: 256 bits, sent 8,000 times a second, one frame every 125 µs.
  • TS0: frame alignment (synchronization), alarms and messages; it carries a fixed pattern in alternate frames.
  • TS16: signalling for the channels (call setup and teardown), or data.
  • TS1 to TS15 and TS17 to TS31: 30 voice channels of 64 kbps.
32×8×8000=2048000 bps=2.048 Mbps
LevelRateVoice channelsMade of
E064 kbps1one channel
E12.048 Mbps3032 time slots
E28.448 Mbps1204 × E1 + 256 kbps
E334.368 Mbps4804 × E2 + 576 kbps
E4139.264 Mbps19204 × E3 + 1.792 Mbps

Each level adds framing and justification bits (bit stuffing), because the four streams below it run on slightly different clocks: hence the name plesiochronous digital hierarchy (PDH). It was later replaced by SDH, whose first level, STM-1, runs at 155.52 Mbps.

T1 and E1 compared: T1 has 24 channels and borrows signalling bits from the voice samples (robbed-bit signalling); E1 has 30 channels and keeps separate slots for framing (TS0) and signalling (TS16). Both carry ISDN's primary rate interface: 23B + D on T1, 30B + D on E1 (ISDN).

To remember: an E1 trunk between Kathmandu and Pokhara is a train of 32 compartments passing 8,000 times a second: the engine (TS0) and the guard's van (TS16) carry no passengers, and the other 30 compartments are 30 telephone calls.

Asked on the paper, word for word
  • What do you mean by switching in communication? Compare switching with multiplexing. Explain the E1 Telephone hierarchy system. 2073 Shrawan Q2 · 2+2+4
  • What is a telephone? With a simple diagram of a telephone network explain how the system works. 2068 Chaitra Q3 · 2+6
In the exam For the E1 hierarchy, draw the 32-slot frame, give the 2.048 Mbps arithmetic and the E0 to E4 table. For "how a telephone network works", draw the hierarchy and write the call in seven steps.

Telecommunication switching systems: from operators to digital exchanges

Telecommunication switching system The equipment in a telephone exchange that connects any incoming line to any outgoing line or trunk on demand, holds the connection for the call, and releases it afterwards.

The classification (the book's Figure 2.24):

  • Manual: operators joined lines with cords and jacks on a switchboard; slow and dependent on the operator, so it was soon replaced.
  • Automatic, electromechanical:
    • Step-by-step (Strowger), after Almon B. Strowger (1891): the dialled pulses move selector switches one step at a time; control is spread over the switches themselves.
    • Crossbar: a grid of horizontal and vertical bars whose crossing points are closed by relays and latches; hard-wired control, so it is very hard to change or extend.
  • Automatic, electronic (stored program control, SPC): a computer runs the exchange from a stored program, so new services are added by changing software (the first, Bell's No. 1 ESS, opened in 1965).
    • Space division: a separate physical path through the switch for each call.
    • Time division: calls share a common path in turn, as samples at fixed intervals; analog (sampled voltages sent as they are) or digital (binary-coded samples), the digital kind built from space switches, time switches and combinations of the two.

Space division switching. A crossbar with N inputs and N outputs needs N2 crosspoints, of which only N are in use at once: 1,000 lines would need 1,000,000. Multistage switches, several smaller crossbars in stages, need far fewer crosspoints, at the risk of blocking when no path through the stages is free.

Time division switching. A time slot interchange (TSI) writes the slots of an incoming TDM frame into memory in order and reads them out in the order of the outgoing slots, so moving a call from slot 3 to slot 1 is just reading the memory in a different order. A digital exchange connects the 64 kbps time slots of its E1 lines this way; large exchanges combine time and space stages (time-space-time, TST).

Worked example: a four-slot time slot interchange

The incoming frame carries callers A, B, C and D in slots 1 to 4. The control memory says: output slot 1 takes input slot 3, output 2 takes input 1, output 3 takes input 4, output 4 takes input 2. So the outgoing frame carries C, A, D, B: caller C now reaches whoever owns output slot 1, with no wire moved.

Networking of telephone exchanges. Exchanges are joined by trunks into the hierarchy of local, tandem and toll exchanges drawn on the telephone network card (telephone network). Between exchanges, signalling was first channel associated (CAS: inside the call's own channel or its partner slot, such as E1's TS16) and is now common channel signalling (CCS): a separate signalling network, Signalling System No. 7 (SS7), carries the setup messages for all calls, which makes setup faster and keeps the voice channels free.

To remember: a Strowger exchange can be heard, each dialled digit moving a selector with a clatter; a digital exchange is silent, because its switch is only memory being read in a different order.

2.6ISDN

ISDN: one digital network for voice and data HOT 5/27

76 Ash · 75 Ash · 71 Ch · 67 Asa · 66 Bh2+63+53+3

ISDN (Integrated Services Digital Network) A set of ITU-T standards (the I series, from the 1980s) for a fully digital, circuit-switched telephone network that carries voice, data, fax and video together, end to end, over the existing copper telephone line, through standard channels (64 kbps B channels for user data, a D channel for signalling) and standard interfaces (BRI and PRI).

Why the telephone companies developed ISDN:

  1. The last analog link: by the 1980s trunks and exchanges were digital (PCM and TDM), but the local loop was still analog, limited to the 300 to 3,400 Hz voice band and to slow modems. ISDN made the loop digital too.
  2. One network instead of several: voice (the PSTN), telex and data (X.25) needed separate networks and lines; ISDN puts all services on one network, one line, one number and one bill.
  3. Out-of-band signalling on the D channel gives faster call setup and new services: caller identification, call waiting, several numbers on one line.
  4. End-to-end digital quality: no noise added at each analog stage.
  5. Standard interfaces: any vendor's terminal plugs in.

Its contribution to data communication: digital access at 64 or 128 kbps on an ordinary line, when analog modems gave 28.8 to 56 kbps, and 1.5 or 2 Mbps on a PRI; voice and data at the same time on one line; fast dial-up connections for internet access and between offices; backup links for routers (dial on demand); videoconferencing (H.320); PRI trunks for PBXs; and the move to broadband ISDN, which led to ATM. DSL, cable and fiber have since replaced it.

Channels:

ChannelRateCarries
B (bearer)64 kbpsuser traffic: digitized voice, data, video; circuit switched end to end
D (delta, data)16 kbps on a BRI, 64 kbps on a PRIsignalling for the B channels (call setup and release); low-rate packet data when free
H (hybrid)H0 = 384 kbps (6 B); H11 = 1,536 kbps (24 B); H12 = 1,920 kbps (30 B)wider pipes for video and fast data

Interfaces (access rates):

  • BRI (basic rate interface) = 2B + D: 2 × 64 + 16 = 144 kbps of user channels; with 48 kbps of framing and synchronization bits the S/T interface runs at 192 kbps. For homes and small offices, over one ordinary twisted pair.
  • PRI (primary rate interface): 23B + D (D at 64 kbps) = 1.544 Mbps, the T1 rate (North America, Japan); or 30B + D = 2.048 Mbps, the E1 rate (Europe and Asia), with the 30 B channels in TS1 to TS15 and TS17 to TS31, D in TS16 and framing in TS0. For PBXs and ISPs.
23×64+64+8=1544 kbps30×64+64+64=2048 kbps

The architecture: functional groups and reference points. A functional group is a kind of device; a reference point is the interface between two groups.

ISDN FUNCTIONAL GROUPS AND REFERENCE POINTS Devices (functional groups) in boxes; the interfaces between them (reference points) in circles. TE1 ISDN phone, PC card TE2 analog phone, PC TA adapter NT2 PBX or router layers 2 and 3 NT1 line end, layer 1 ISDN exchange (LT, ET) S R S T U circuit network packet network leased lines SS7 signalling CUSTOMER PREMISES TELEPHONE COMPANY BRI: 2B + D = 144 kbps; 192 kbps on the four wire S/T bus with framing; the U loop is one twisted pair. PRI: 23B + D at 1.544 Mbps (T1) or 30B + D at 2.048 Mbps (E1); NT2 is then usually a PBX.
Functional groupWhat it isExample
TE1 (terminal equipment type 1)a device built for ISDN; connects at SISDN telephone, PC with an ISDN card
TE2 (terminal equipment type 2)a non-ISDN device; needs a TA; connects at Ranalog telephone, PC with a serial (RS-232) port
TA (terminal adapter)converts TE2's signals to ISDN: R in, S outan ISDN adapter box
NT2 (network termination 2)customer switching and concentration, layers 2 and 3a PBX, a router, a LAN
NT1 (network termination 1)the end of the carrier's line, layer 1 only: turns the four-wire S/T bus into the two-wire local loop, monitors the line and supplies timingthe NT1 box on the wall
LT and ETline termination and exchange termination inside the ISDN exchangethe carrier's switch

Reference points: R (TE2 to TA), S (TE1 or TA to NT2), T (NT2 to NT1) and U (NT1 to the exchange, over the local loop). They run R, S, T, U in alphabetical order from the old terminal outward to the exchange. With no NT2, S and T merge into one S/T interface, and up to eight terminals can share one BRI's S bus.

The protocol layers of the user-network interface: layer 1 is I.430 (BRI) or I.431 (PRI); layer 2 on the D channel is LAPD (Q.921), an HDLC-type protocol whose address field holds a SAPI and a TEI (terminal endpoint identifier), so several terminals can share the D channel (HDLC); layer 3 is Q.931 call control. The B channels carry whatever the users run.

How it works: a terminal asks for a call with a SETUP message on the D channel; the exchange routes the request through the network with SS7; when the called terminal answers, the network assigns a B channel at each end and joins them; 64 kbps of digital voice or data then flows end to end on the B channel, while the D channel stays free for more signalling (a second call, a packet of data). Release again takes three messages on the D channel.

ISDN signalling is out-of-band, common channel signalling: every call-control message travels on the D channel, never on the B channels.

AN ISDN CALL OVER THE D CHANNEL Q.931 messages, carried in LAPD frames on the D channel; the B channel carries only the call itself. Calling terminal ISDN network Called terminal SETUP (called number) CALL PROCEEDING SETUP ALERTING (phone rings) ALERTING (ringback) CONNECT (answered) CONNECT ACK CONNECT CONNECT ACK B channel: 64 kbps voice or data, both ways DISCONNECT RELEASE RELEASE COMPLETE DISCONNECT RELEASE RELEASE COMPLETE CALL SET UP RELEASE Between the exchanges the network signals with SS7 (IAM, ACM, ANM, REL, RLC); the terminals never see it.
  • User to network (access signalling): Q.931 messages in LAPD frames on the D channel. Setup: SETUP (with the called number and the kind of bearer needed), CALL PROCEEDING, ALERTING (the called telephone rings), CONNECT, CONNECT ACKNOWLEDGE. Release: DISCONNECT, RELEASE, RELEASE COMPLETE.
  • Inside the network: Signalling System No. 7 (SS7) between exchanges; its ISDN user part (ISUP) sends IAM (initial address), ACM (address complete), ANM (answer), REL (release) and RLC (release complete).
  • User to user: a little signalling can pass between the two terminals through the network.
  • Why out-of-band: the B channel is free for data from the first moment to the last; setup is fast; many calls share one signalling channel.

Broadband ISDN: the narrowband ISDN above stops at about 2 Mbps; broadband ISDN (B-ISDN) was defined for 155.52 and 622.08 Mbps over fiber using ATM, which is chapter 1's (ATM).

To remember: a small office on one BRI line

The receptionist's ISDN telephone (a TE1) and the old fax machine behind a terminal adapter (a TE2 with a TA) share the S bus. She talks on one B channel while the office PC uses the other B channel for a 64 kbps internet session, and the D channel quietly set up both calls. An NT1 on the wall joins the S bus to the single pair of copper from the exchange.

The book says "D-Channel (Bearer Channel)" in its list of channels. That is a slip: B is the bearer channel, and D is the signalling channel (the delta or data channel), as its own description beside the label says.
Asked on the paper, word for word
  • Why the telephone companies developed ISDN? Explain the working principle of ISDN with its interface and functional group. 2076 Ashwin Q2 · 2+6
  • Compare circuit switching and packet switching. Explain ISDN channels with architecture. 2075 Ashwin Q2 · 3+5
  • What is ISDN? Explain about the ISDN architecture in detail with example. 2071 Chaitra Q2 · 2+6
  • What do you mean by ISDN and what is it contribution in the field of data communication? Explain various types of multiplexing mechanism used in communication. 2067 Ashad Q3 · 3+5
  • Write short notes on (any two) i) TCP Sliding Window Protocol ii) Secrete Key Algorithm: DES iii) ISDN Signaling and ATM AAL iv) ICMP Message Types 2066 Bhadra Q5b · 3+3
In the exam For the architecture, draw the reference point diagram, then the functional groups, the B, D and H channels, and BRI and PRI with their rate sums. For signalling, the D channel, LAPD and Q.931, the messages in order, and SS7 inside the network.

2.7Last minute recall

Chapter 2 in one screen

  • Physical layer: moves raw bits; mechanical, electrical, functional, procedural; functions: physical characteristics, bit representation, data rate, synchronization, line configuration, topology, transmission mode; in TCP/IP it sits inside host-to-network.
  • Performance: bandwidth, throughput (data / time, never above bandwidth), latency, jitter; delays: processing, queuing, transmission L/R, propagation d/s; bandwidth-delay product R × dprop.
  • Capacity: Nyquist C = 2B log2 L; Shannon C = B log2(1 + SNR); SNRdB = 10 log10(S/N); impairments: attenuation, distortion, noise.
  • Media: guided (twisted pair, coaxial, fiber) and unguided (radio 3 kHz to 1 GHz, microwave 1 to 300 GHz, infrared 300 GHz to 400 THz); factors: security, bandwidth, environment, noise, installation, mobility, cost, distance.
  • Twisted pair: UTP, STP; Cat 3 to Cat 8; straight, crossover, rollover; 100 m Ethernet. Coaxial: conductor, insulation, braid, jacket; RG-6, RG-58, RG-59.
  • Fiber: core, cladding, buffer, jacket; total internal reflection; step index, graded index, single mode; LED or laser, PIN or APD; 850, 1310, 1550 nm (193 to 353 THz).
  • Propagation: ground (below 2 MHz), sky (2 to 30 MHz), line of sight (above 30 MHz); radio horizon 4.12 √h km.
  • Satellite: transponder: amplify and translate; uplink above downlink; LEO, MEO, GEO at 35,786 km (about 0.24 s a hop); bands L, S, C, X, Ku, K, Ka, V, W.
  • Multiplexing: FDM (guard bands), WDM, synchronous TDM (fixed slots), statistical TDM (addressed slots), CDM (orthogonal codes).
  • Switching: circuit (setup, transfer, teardown), message (store and forward whole messages), packet (datagram, virtual circuit); circuit against packet in ten rows; circuit suits real time: reserved bandwidth, constant delay, in order.
  • Datagram and VC: full address and independent routing against setup, short VCI and one path; PVC and SVC; X.25, Frame Relay (DLCI), ATM (VPI/VCI), MPLS.
  • Telephone network: local loop, end office, tandem and toll offices, trunks; call: off-hook, dial tone, dialling, switching, ringing, answer, hang up.
  • Digital hierarchy: 64 kbps channel; T1 = 193 bits × 8000 = 1.544 Mbps (24); E1 = 32 × 8 × 8000 = 2.048 Mbps (30; TS0 sync, TS16 signalling); E2 8.448, E3 34.368, E4 139.264 Mbps.
  • Exchanges: manual; electromechanical (Strowger, crossbar); electronic SPC (space division, time division, TSI); signalling CAS and CCS (SS7).
  • ISDN: B 64, D 16 or 64, H0, H11, H12; BRI 2B + D (144, 192 kbps); PRI 23B + D (1.544) or 30B + D (2.048); TE1, TE2, TA, NT2, NT1; R, S, T, U; Q.931 over LAPD on D, SS7 inside.

Chapter 3 · 5 hours · about 11 marks a paper · in all 27 sittings

Data link layer

The data link layer turns the physical layer's raw bit pipe into a link that carries frames between two neighbouring machines: it marks where each frame starts and ends, catches the bits that noise has flipped, keeps a fast sender from drowning a slow receiver, and on a shared cable or radio channel decides who may send next. It is one of the most examined chapters: framing, CSMA/CD, the functions of the layer, the MAC sublayer and ALOHA come up again and again, and every few papers set a CRC or a bit stuffing calculation.

What this chapter is about
  • The layer itself: its functions, its services to the network layer, its design issues, and the LLC and MAC sublayers.
  • Framing: character count, byte stuffing, bit stuffing and coding violations.
  • Errors: single bit and burst errors, parity, the checksum, CRC and the Hamming code; detecting an error against correcting it.
  • Flow and error control: stop and wait, the sliding window, piggybacking, and the ARQ protocols (stop and wait, go-back-N, selective repeat).
  • Link protocols: HDLC and PPP.
  • Sharing one channel: the channel allocation problem, ALOHA, CSMA, CSMA/CD, controlled access and channelization.
  • The LANs: Ethernet (IEEE 802.3), token bus (802.4), token ring (802.5), FDDI, wireless LAN (802.11) and VLANs.
Where it fits
  • Below it, the physical layer of chapter 2 moves raw bits over the media (physical layer, guided media, optical fiber); static channel sharing by FDM and TDM is multiplexing, and the propagation delay that causes collisions is measured in delay.
  • Above it, the network layer of chapter 4 hands down IP packets; ARP finds the MAC address a frame needs (ARP), and bridges and switches are data link layer devices (devices, bridges).
  • Beside it, the OSI model places the layer (OSI model); TCP runs the same sliding window end to end (TCP flow control); UDP and TCP reuse the checksum (UDP); X.25 and frame relay run HDLC-family links (X.25, frame relay); wireless LAN security is chapter 8's (WEP).
What you will learn
  1. 3.1 The data link layer: functions, services and design issues
  2. 3.2 Framing: character count, byte stuffing, bit stuffing
  3. 3.3 Errors, error detection and correction, parity and checksum
  4. 3.4 CRC: the cyclic redundancy check
  5. 3.5 Hamming distance and the Hamming code
  6. 3.6 Flow control: stop and wait, sliding window, piggybacking
  7. 3.7 Error control by ARQ: stop and wait, go-back-N, selective repeat
  8. 3.8 HDLC
  9. 3.9 PPP
  10. 3.10 The MAC sublayer and the channel allocation problem
  11. 3.11 ALOHA: pure and slotted
  12. 3.12 CSMA and its persistence methods
  13. 3.13 CSMA/CD
  14. 3.14 Controlled access: reservation, polling, token passing
  15. 3.15 Channelization: FDMA, TDMA, CDMA
  16. 3.16 The IEEE 802 family
  17. 3.17 Ethernet (IEEE 802.3): frame, addresses, data transfer, cabling
  18. 3.18 Token bus (IEEE 802.4)
  19. 3.19 Token ring (IEEE 802.5)
  20. 3.20 FDDI
  21. 3.21 Wireless LAN (IEEE 802.11) and CSMA/CA
  22. 3.22 Virtual LANs and IEEE 802.1Q
  23. 3.23 Last minute recall, chapter 3
How it is examined
  • The bankers: framing (10 of the 27 sittings), CSMA/CD (9), the functions of the layer (8), the MAC sublayer (7) and ALOHA (6).
  • The calculations: a CRC by modulo-2 division (three papers), bit stuffing (three papers, each with a different string) and the efficiency of slotted ALOHA; all are worked in the Numericals panel.
  • Draw: the CSMA/CD flowchart, the Ethernet, HDLC and token ring frames, the go-back-N and selective repeat timing diagrams, FDDI's wrap and the VLAN design.

3.1Functions of the data link layer

The data link layer: functions, services and design issues HOT 8/27

82 Ba · 75 Ash · 74 Ch · 72 Ka · 71 Shr · 70 Asa · 66 Po · 66 Bh2+3+33+52+2+6

Data link layer The second layer of the OSI model. It takes the network layer's packets, packs them into frames, and moves them reliably from one node to the next over a single link, hiding the noise and the sharing of the medium from the layers above.

Hop to hop, not end to end. A packet from a laptop in a hostel to a server abroad crosses many links: laptop to the Wi-Fi access point, access point to a switch, switch to the router, router to the ISP, and so on. The network layer chooses the route; the data link layer does the work on each single hop, and on every hop the frame is new: a fresh header with that link's addresses and a fresh check of its bits. It is a relay race: the route is planned once, but every runner carries the baton over one leg only and checks it at the hand-over.

THE DATA LINK LAYER AND ITS TWO SUBLAYERS IEEE 802 splits layer 2: one LLC on top for every LAN, and a different MAC (with its own physical layer) for each kind of LAN. Network layer: IP packets come down to the data link layer LAYER 3 LLC sublayer, IEEE 802.2: the same for every LAN interface to the network layer, protocol multiplexing (DSAP, SSAP), optional flow and error control 802.3 Ethernet CSMA/CD, bus or switch Physical coax, twisted pair, fiber 802.4 Token bus token on a logical ring Physical broadband coaxial cable 802.5 Token ring token on a physical ring Physical shielded twisted pair 802.11 Wireless LAN CSMA/CA, RTS and CTS Physical radio: 2.4, 5 and 6 GHz LAYER 2 LLC MAC LAYER 1 MAC sublayer jobs: framing for its own LAN, 48-bit MAC addresses, channel access (who sends next), error detection with the FCS. IEEE 802.1 sits over them all: bridging, VLANs (802.1Q) and management.

Its functions. Forouzan's five are the ones to write, each tied to a card of this chapter:

  • Framing: divides the bit stream into frames and marks where each starts and ends (framing).
  • Physical addressing: puts the sender's and the receiver's hardware (MAC) addresses in the header, such as the 48-bit addresses of Ethernet.
  • Flow control: stops a fast sender from overrunning a slow receiver (flow control).
  • Error control: detects damaged frames with a CRC or checksum in the trailer, and recovers damaged, lost and duplicate frames by retransmission (CRC, ARQ).
  • Access control: when several stations share one medium, decides which may transmit now (MAC sublayer).

Two more, from Tanenbaum: it provides a well-defined service interface to the network layer, and it does link management: setting up, maintaining and releasing a connection where the service is connection-oriented.

Services to the network layer. Three kinds, chosen by how reliable the link is:

ServiceHow it worksSuitsExample
Unacknowledged connectionlessframes are sent with no connection and no acknowledgement; a lost frame is not recovered at this layerlinks with very few errors, and real-time traffic where a late frame is useless anywayEthernet
Acknowledged connectionlessno connection, but every frame is acknowledged; a frame not acknowledged in time is sent againunreliable links such as radioIEEE 802.11 Wi-Fi
Acknowledged connection-orienteda connection is set up, frames are numbered, and each is delivered exactly once and in order; three phases: connection establishment, frame transfer, connection releaselong or noisy links where reliability matters, such as WAN serial lines and satellite linksHDLC, LLC type 2

Design issues (the question "state the design issues" wants these): what service to give the network layer; framing; error control (detection, ACKs, timers, sequence numbers); flow control; and, on a broadcast link, medium access and addressing. Each is a section of this chapter.

Two sublayers. On LANs, IEEE 802 splits the layer in two, so that one interface to the network layer can sit on top of many kinds of LAN:

SublayerStandardFunctions
LLC, logical link control (upper)IEEE 802.2, the same for every LANthe interface to the network layer; multiplexes several network protocols on one link with service access points (DSAP, SSAP); optional flow and error control; three service types: type 1 unacknowledged connectionless, type 2 connection-oriented, type 3 acknowledged connectionless
MAC, medium access control (lower)one per LAN: 802.3, 802.4, 802.5, 802.11builds the frame for its LAN; adds the MAC addresses and the FCS; decides access to the shared medium (CSMA/CD, token passing, CSMA/CA); detects errors
Asked on the paper, word for word
  • What are the functions of data link layer? How to detect signal collision in CSMA/CD? List the ethernet cable specification standards for 802.3 ethernet standards. 2082 Baishakh Q2 · 2+3+3
  • State the various design issues for the data link layer. What is piggybacking? A bit string 01111011111101111110 needs to be transmitted at the data link layer. What is the string actually transmitted after bit stuffing? 2075 Ashwin Q3 · 3+3+2
  • What is the main functionality of data link layer? Differentiate between circuit switching and packet switching. 2074 Chaitra Q3 · 4+4
  • What are the functions of data-link layer? Explain the channel allocation problem with example. 2072 Kartik Q3 · 3+5
  • What are the major functions of data link layer? Explain about framing in detail. 2071 Shrawan Q3 · 3+5
  • What are the functions of LLC and MAC sub-layer? Discuss different farming approaches used in data link layer. 2070 Ashad Q3 · 2+2+6
  • List the functions of Data Link Control Layer. Explain any two sliding window protocols with the advantages of piggybacking. 2066 Poush Q4 · 5+3
  • What are the services provided by data link layer? Explain any one methods of framing and flow control. 2066 Bhadra Q2a · 2+3+3
In the exam For "functions", write the five with a line each, then the services table in three lines. For "LLC and MAC", draw the sublayer figure and give each sublayer's jobs.

3.2Framing

Framing: character count, byte stuffing and bit stuffing TOP 10/27

81 Bh · 75 Ch · 75 Ash · 72 Ch · 71 Shr · 70 Ch · 70 Asa · 69 Ch · 68 Ba · 66 Bh82+2+62+3+3

Framing Dividing the stream of bits from the physical layer into frames, and marking where each frame starts and ends, so that the receiver can find the boundaries, check each frame on its own and ask again for only the damaged one.

Why frames at all. The physical layer delivers bits with no idea where a message begins. If the whole file were one block, one flipped bit would mean sending everything again; in frames of a few hundred bytes, only the damaged frame is resent. A frame has three parts: a header (addresses and control), the payload (the network layer's data) and a trailer (the error check). Fixed-size frames, like ATM's 53-byte cells, need no delimiters at all; variable-size frames need one of the methods below, and real protocols often combine two of them for safety.

FRAMING: WHERE DOES A FRAME START AND END? Character count, byte stuffing and bit stuffing (physical layer coding violations need no drawing). 1. CHARACTER COUNT: THE FIRST BYTE OF EACH FRAME GIVES ITS LENGTH Sent 5 1 2 3 4 5 6 7 8 9 8 0 1 2 3 4 5 6 8 7 8 9 0 1 2 3 Frame 1 Frame 2 Frame 3 Frame 4 Received one count garbled 5 1 2 3 4 7 6 7 8 9 8 0 1 2 3 4 5 6 8 7 8 9 0 1 2 3 ok wrong Count 5 garbled to 7: every later boundary is now wrong. 2. BYTE STUFFING: FLAG AT BOTH ENDS; ESC BEFORE ANY FLAG OR ESC IN THE DATA FLAG Header Payload (the data bytes) Trailer FLAG Data A FLAG B A ESC FLAG B A ESC B A ESC ESC B The added ESC (pink) is removed by the receiver; a lone FLAG can only be a frame boundary. PPP uses this. 3. BIT STUFFING: FLAG 01111110; A 0 IS STUFFED AFTER EVERY FIVE 1s OF DATA Data 0 1 0 0 1 1 1 1 1 1 0 1 1 1 1 1 0 Sent 0 1 1 1 1 1 1 0 0 1 0 0 1 1 1 1 1 0 1 0 1 1 1 1 1 0 0 0 1 1 1 1 1 1 0 flag flag stuffed 0s in pink: the receiver deletes them

1. Character (byte) count. A field in the header gives the number of bytes in the frame; the receiver counts that many and knows where the next frame starts. The flaw: if noise garbles the count, the receiver loses step for good. The CRC tells it the frame is bad, but not where the next frame begins, and the sender cannot tell how much to resend. So a count is never used alone.

2. Flag bytes with byte (character) stuffing. Each frame starts and ends with a special FLAG byte; a receiver that loses step just searches for the next FLAG. If a FLAG pattern occurs inside the data, the sender puts an ESC byte in front of it, and an ESC in the data is sent as ESC ESC; the receiver removes each escape and treats the byte after it as plain data. PPP uses this, with FLAG 0x7E and ESC 0x7D. Drawbacks: it is tied to 8-bit bytes, and a frame full of FLAG bytes can double in size.

To remember byte stuffing: it is exactly how a quote is written inside a quoted string in C: "He said \"namaste\"". The backslash is the ESC, and a real backslash in the text is written \\, ESC ESC.

3. Flag bits with bit stuffing. Each frame starts and ends with the flag 01111110 (six 1s between two 0s). Whenever the sender's data contains five 1s in a row, it stuffs a 0 after them, so six 1s never appear inside a frame. The receiver, after five 1s, looks at the next bit: a 0 is a stuffed bit and is deleted; a 1 followed by 0 is the flag. It works for any number of bits, not only whole bytes. HDLC uses it, and USB stuffs a bit after six 1s for the same reason.

Worked example (the book's, checked)

Data 01001111110111110 (17 bits). A 0 goes after the first five 1s and after the second run of five 1s:

data      0100 11111 1 0 11111 0
stuffed   0100 11111 0 1 0 11111 0 0
sent      01111110 0100111110101111100 01111110

Two bits were stuffed, so 19 bits travel between the flags; the receiver deletes the 0 after each run of five 1s and gets the 17 bits back. The three papers' strings are worked in the Numericals panel.

4. Physical layer coding violations. Some line codes have signal patterns that never occur in data. In Manchester coding each bit is a pair of half-bit levels, high-low or low-high; high-high and low-low never carry data, so they can mark a frame's boundary. In 4B/5B coding only 16 of the 32 five-bit code groups carry data; 100BASE-X Ethernet and FDDI start a frame with the spare J and K symbols. It works only where the physical layer has such spare patterns.

MethodFrame marked byWeaknessUsed in
Character counta length field in the headerone bad count loses every later boundaryonly with another method
Byte stuffingFLAG bytes; ESC before FLAG or ESC in the dataneeds 8-bit bytes; frames can growPPP
Bit stuffingflag 01111110; a 0 after five 1sup to one extra bit per fiveHDLC, its family
Coding violationssignal patterns that data never usesneeds a redundant line code100BASE-X, FDDI
Asked on the paper, word for word
  • Write Short notes on: (Any Two) a) 802.4 Token Bus b) Framing with bit stuffing c) Server Socket programming for bind, listen and accept d) ATM 2081 Bhadra Q10 · 2×4
  • What are multiple access protocols? Describe the various framing techniques at data link layer. 2075 Chaitra Q3 · 2+6
  • State the various design issues for the data link layer. What is piggybacking? A bit string 01111011111101111110 needs to be transmitted at the data link layer. What is the string actually transmitted after bit stuffing? 2075 Ashwin Q3 · 3+3+2
  • Briefly explain different types of Data Link Layer framing mechanisms. List the features of FDDI. 2072 Chaitra Q3 · 8
  • What are the major functions of data link layer? Explain about framing in detail. 2071 Shrawan Q3 · 3+5
  • What is the difference between Error Correcting and Error detection process? A bit string 01111011111011111110 needs to be transmitted at the data link layer what is string actually transmitted after bit stuffing, if flag patterns is 01111110. 2070 Chaitra Q3 · 5+3
  • What are the functions of LLC and MAC sub-layer? Discuss different farming approaches used in data link layer. 2070 Ashad Q3 · 2+2+6
  • Explain different types of Data link layer framing mechanisms. 2069 Chaitra Q3 · 8
  • Compare x.25 and frame relay network. A bit string 0111101111101111110 needs to be transmitted at the data link layer. What is the string actually transmitted after bit stuffing? 2068 Baishakh Q10 · 6+2
  • What are the services provided by data link layer? Explain any one methods of framing and flow control. 2066 Bhadra Q2a · 2+3+3
In the exam "Types of framing" wants all four methods, with the character count error, the byte stuffing figure and a bit stuffing example. For a bit stuffing calculation, mark every run of five 1s, insert the 0s, then add the flags at both ends if the question names the flag.

3.3Error detection and correction

Errors, detection against correction, parity and the checksum PIN 1/27

70 Ch5+3

Error A change in the bits of a frame between sender and receiver, caused by noise, interference, attenuation or a faulty device. It is caught by sending redundant bits computed from the data, which the receiver computes again and compares.

Types of error.

  • Single-bit error: only one bit of the frame changes, a 0 to 1 or a 1 to 0. Rare on serial links, because noise usually lasts longer than one bit.
  • Burst error: two or more bits change. Its length is counted from the first wrong bit to the last, whether or not the bits between are wrong. A noise burst of 1 ms damages about 10 bits at 10 kbps but about 10,000 bits at 10 Mbps, so bursts are the usual case.
  • The book adds: a content error (the bits of the message change) and a flow integrity error (a frame is lost, duplicated or delivered to the wrong destination).

Detection against correction. Detection only asks did an error happen; the frame is then thrown away and sent again (ARQ, also called backward error correction). Correction asks which bits are wrong and fixes them at the receiver (forward error correction, FEC). Correction needs many more redundant bits, so it pays only where a retransmission is slow or impossible.

PointError detectionError correction
Goalfind that the frame has an errorfind which bits are wrong and fix them
Redundancysmall: 1 parity bit, a 16 or 32-bit CRClarge: 3 check bits for 4 data bits in the Hamming (7,4) code
After an errordiscard; the sender retransmits (ARQ, backward error correction)the receiver repairs it at once (FEC)
Hamming distancedmin≥s+1 detects s errorsdmin≥2t+1 corrects t errors
Suitswired LANs and links with a return channel and few errorsnoisy or long-delay links, or none back: satellite, mobile, Wi-Fi, CDs, QR codes
Codesparity, checksum, CRCHamming, Reed-Solomon, convolutional, LDPC

To remember FEC: the QR code on a shop's payment sticker (Fonepay, eSewa) still scans when a corner is torn or smudged, because QR codes carry Reed-Solomon correction that rebuilds up to 30 percent of the code at the highest level. Nobody can ask the sticker to send itself again.

Simple parity. One parity bit makes the count of 1s even (even parity) or odd (odd parity). The book's example: the 7 bits 1001101 have four 1s, so even parity adds a 0 and 01001101 is sent. If 00001101 arrives, the count is odd: error detected. If 00001001 arrives (two bits flipped), the count is even again and the error is missed. Parity detects every odd number of wrong bits and no even number; it cannot correct anything.

Two-dimensional parity. The data is written as a table of rows; each row gets a parity bit (VRC) and each column a parity bit (LRC). It detects all 1, 2 and 3-bit errors, misses some 4-bit patterns, and can locate and correct a single wrong bit, which sits where the failing row meets the failing column.

The checksum. Used by the upper layers (IP, UDP and TCP use the 16-bit Internet checksum, UDP). The sender divides the data into k segments of m bits, adds them in one's complement arithmetic (a carry out of the top is wrapped round and added at the bottom), and sends the complement of the sum as the checksum. The receiver adds all the segments and the checksum; if the complement of that sum is all 0s, the data is accepted.

Worked example (the book's, checked)
k = 4, m = 8
  10011001
+ 11100010  = 1 01111011  wrap: 01111100
+ 00100100  =   10100000
+ 10000100  = 1 00100100  wrap: 00100101
sum 00100101, checksum = complement = 11011010
receiver: 00100101 + 11011010 = 11111111, complement 00000000: accept

Its weakness: errors that cancel in the sum (one word one higher, another one lower) or two words swapped pass unseen, which is why the link itself uses the stronger CRC.

Asked on the paper, word for word
  • What is the difference between Error Correcting and Error detection process? A bit string 01111011111011111110 needs to be transmitted at the data link layer what is string actually transmitted after bit stuffing, if flag patterns is 01111110. 2070 Chaitra Q3 · 5+3
In the exam For "difference between error detection and error correction", give the table (goal, redundancy, what happens next, Hamming distance, where used) with parity and CRC as detection examples and the Hamming code as the correction example.

CRC: the cyclic redundancy check PIN 3/27

82 Ba · 81 Bh · 80 Bh1+2+53+5

CRC An error-detecting code based on binary polynomial division. The sender appends r check bits, the remainder of dividing the data (with r zeros added) by a generator of degree r in modulo-2 arithmetic, so that the whole frame divides exactly; the receiver divides again, and a nonzero remainder means an error.

Bits as polynomials. A string of bits is read as the coefficients of a polynomial: 1101 is x3+x2+1. The generator G(x) is agreed in advance; a generator of degree r has r+1 bits, beginning and ending with 1.

Modulo-2 arithmetic has no carries and no borrows: addition and subtraction are both XOR (1+1=0). A long division therefore subtracts the generator by XOR wherever the leading bit is 1, and subtracts zeros where it is 0.

CRC: THE SENDER APPENDS A REMAINDER; THE RECEIVER DIVIDES AGAIN Example: data 1101, generator 1011 (x³ + x + 1), so r = 3 check bits. SENDER 1 Data M 1101 (m = 4 bits) 2 Append r zeros 1101 000 3 Divide by G, mod 2 G = 1011, XOR 4 Remainder = CRC R = 001 (r bits) 5 Send M then R T = 1101 001 the channel: noise may flip some bits RECEIVER 6 Receive T' T' = T if no error 7 Divide by G the same 1011 8 Check remainder all zero, or not? 9 Zero: accept remainder 000 10 Not zero: reject error detected: resend any other remainder T(x) is a multiple of G(x), so it divides with no remainder; an error E(x) is missed only if G(x) also divides E(x).

At the sender:

  1. Append r zeros to the message M, which is xrM(x).
  2. Divide it by G(x) in modulo 2.
  3. The remainder R, exactly r bits (keep leading zeros), is the CRC.
  4. Send T=M followed by R, that is T(x)=xrM(x)+R(x).

At the receiver: divide the received frame by the same G(x). A remainder of zero means accept; anything else means the frame was damaged and is discarded (ARQ then gets it sent again).

Worked example

Message 1101, generator 1011 (x3+x+1, so r=3): divide 1101000.

          1111        quotient
1011 ) 1101000
       1011
       ----
        1100
        1011
        ----
         1110
         1011
         ----
          1010
          1011
          ----
           001        remainder = CRC

Sent: 1101001. At the receiver 1101001 divided by 1011 leaves 000: accepted.

Why it works. T(x) is a multiple of G(x) by construction (in modulo 2, adding the remainder is the same as subtracting it). If noise adds an error pattern E(x), the receiver's remainder is that of E(x) alone, so the error escapes only when G(x) happens to divide E(x). A good generator makes that very unlikely. It detects:

  • all single-bit errors, when G(x) has at least two terms;
  • all double-bit errors, when G(x) divides no xt+1 for t up to the frame length;
  • every odd number of errors, when x+1 is a factor of G(x);
  • every burst of length r or less, a burst of r+1 with probability 1−2−(r−1), and a longer one with probability 1−2−r.

Standard generators: CRC-8 x8+x2+x+1 (ATM's header check), CRC-16-CCITT x16+x12+x5+1 (HDLC, PPP) and CRC-32 (Ethernet and Wi-Fi's 4-byte FCS). In hardware, a CRC is a shift register with an XOR gate for each term of the generator, computed bit by bit as the frame goes out, which is why the book says a CRC can be described by modulo-2 arithmetic, by polynomials or by digital logic.

To remember it: a CRC is like a teacher who checks a long sum by dividing it by 9 and looking at the remainder: if the remainder is not what it should be, something was copied wrong, though the remainder does not say where.

Asked on the paper, word for word
  • What is hamming distance? How do you apply it in data link layer error control mechanism? Calculate the CRC for a 8 bit sequence 11001101. The generator polynomial is x⁴ + x² + 1. Also find the transmitted bit frame. 2082 Baishakh Q3 · 1+2+5
  • What is piggy-backing? How do you apply it in data link layer flow control mechanism? Calculate the CRC for a 10 bit sequence 1010001101. The generator polynomial is x⁵ + x⁴ + x² + 1. Also find the transmitted bit frame. 2081 Bhadra Q3 · 1+2+5
  • Explain how does CRC detect the errors. Given message is M (x) = x7 + x4 +x3 +x2 + 1 and the generator is G (x) = x3 + 1. Show the actual bit string transmitted, suppose the third bit from the left is inverted during the transmission. Show how the error is detected at the receiver's end. 2080 Bhadra Q3 · 3+5
In the exam Write the generator as bits first, append r zeros (r = degree, one less than the number of bits), lay out the division in full, and state the remainder with r bits and the transmitted frame. For "show how the error is detected", flip the bit, divide the received frame and show the nonzero remainder.

Hamming distance and the Hamming code PIN 1/27

82 Ba1+2+5

Hamming distance The number of bit positions in which two codewords of the same length differ, found by XORing them and counting the 1s. The minimum Hamming distance dmin of a code is the smallest distance between any two of its valid codewords, and it decides how many errors the code can detect and correct.

Example: 10101 XOR 11110 = 01011, three 1s, so the distance is 3. To remember it: the names SITA and GITA differ in one letter, distance 1: one wrong letter turns a valid name into another valid name and nobody notices. If every valid name differed from every other in at least three letters, one wrong letter would leave a word that is not a name at all, and closest to exactly one real name.

The two rules:

dmin≥s+1to detect s errors,dmin≥2t+1to correct t errors
CodedminDetectsCorrects
Even parity21 errornone
Repetition code 000, 11132 errors1 error
Hamming (7,4)32 errors (if not correcting)1 error
Extended Hamming (8,4), SECDED42 errors1 error (ECC memory)

How it is used in error control. The data link layer picks a code whose dmin fits the link. On a link with a return channel it uses a detecting code (CRC) and retransmits (ARQ). On a link where retransmission is costly it uses a correcting code such as the Hamming code (FEC). Either way the receiver's test is the same: a received word that is not a valid codeword shows an error, and correction means replacing it by the nearest valid codeword.

The Hamming code. With m data bits it adds r parity bits, enough that 2r≥m+r+1 (4 data bits need 3, giving the (7,4) code). The parity bits sit at the positions that are powers of 2 (1, 2, 4, 8, ...), and each checks every position whose binary number contains its bit:

Parity bitChecks positionsThe book's rule
P11, 3, 5, 7check 1, skip 1
P22, 3, 6, 7check 2, skip 2
P44, 5, 6, 7check 4, skip 4

The 7-bit word is written D7 D6 D5 P4 D3 P2 P1 (even parity).

Worked example: encode, then correct

Encode the data 1011 (D7 D6 D5 D3 = 1 0 1 1):

P1 = D3 xor D5 xor D7 = 1 xor 1 xor 1 = 1
P2 = D3 xor D6 xor D7 = 1 xor 0 xor 1 = 0
P4 = D5 xor D6 xor D7 = 1 xor 0 xor 1 = 0
codeword  D7 D6 D5 P4 D3 P2 P1 = 1 0 1 0 1 0 1

Bit 6 flips on the way, and 1110101 arrives. Recompute each check:

C1 = P1 D3 D5 D7 = 1 1 1 1  even: 0
C2 = P2 D3 D6 D7 = 0 1 1 1  odd:  1
C4 = P4 D5 D6 D7 = 0 1 1 1  odd:  1
syndrome C4 C2 C1 = 110 = 6: bit 6 is wrong

Flip bit 6 back: 1010101, the word that was sent. A syndrome of 000 means no error.

The book's example. It receives 1110111, finds the syndrome 100 = 4 and stops at "the 4th bit in the codeword is incorrect". The question asks for the correct code, which it never writes: flipping bit 4 gives 1111111 (data 1111). Worked in full in the Numericals panel.
Asked on the paper, word for word
  • What is hamming distance? How do you apply it in data link layer error control mechanism? Calculate the CRC for a 8 bit sequence 11001101. The generator polynomial is x⁴ + x² + 1. Also find the transmitted bit frame. 2082 Baishakh Q3 · 1+2+5
In the exam Define the distance with an XOR example, give both rules, and say the receiver flags any word that is not a codeword and corrects to the nearest. For a Hamming code question, lay out D7 to P1, compute each check and read the syndrome as a binary number.

3.4Flow control and error control

Flow control: stop and wait, the sliding window and piggybacking HOT 5/27

81 Bh · 75 Ash · 74 Ash · 66 Po · 66 Bh4+41+2+52+3+3

Flow control The set of procedures that tells the sender how much data it may send before it must wait for an acknowledgement, so that a fast sender does not overrun the limited buffer and processing speed of a slow receiver.

Why it is needed. A receiver stores incoming frames in a buffer and must check and hand each one up. If frames arrive faster than that, the buffer fills and frames are dropped, only to be sent again: wasted time. Flow control makes the receiver's pace the limit. Two methods: stop and wait, and the sliding window.

To remember it: a teacher dictating notes. In stop and wait the teacher reads one line and waits until the student says "OK". In the sliding window the teacher reads ahead up to seven lines while the student writes, and the student calls out "done up to line 5" now and then.

1. Stop and wait. The sender sends one frame and waits for its acknowledgement before sending the next. It is simple and never overruns the receiver, but the link sits idle for a whole round trip after every frame. With a=Tprop/Tframe, the fraction of time the link carries data is:

Ustop and wait=11+2a

Example: 1000-bit frames at 1 Mbps (Tframe = 1 ms) over a satellite with Tprop = 270 ms give a = 270 and U=1/541, about 0.18 percent: the link idles 99.8 percent of the time.

STOP AND WAIT: ONE FRAME, THEN WAIT FOR ITS ACK Frames carry a 1-bit sequence number (0, 1, 0, ...); an ACK names the next frame expected. NORMAL OPERATION Sender Receiver Frame 0 ACK 1 Frame 1 ACK 0 Frame 0 (the next one) waits one round trip LOST FRAME, THEN LOST ACK: THE TIMER RECOVERS BOTH Sender Receiver Frame 0 lost timeout Frame 0 again delivered ACK 1 lost timeout Frame 0 again duplicate: discard, ACK again ACK 1 Frame 1

2. Sliding window. The sender may send up to W frames before it needs an acknowledgement. Frames carry k-bit sequence numbers, counted modulo 2k (0 to 7 for 3 bits). The send window covers the frames sent but not yet acknowledged plus those that may be sent now; the receive window covers the frames the receiver will accept. An ACK carries the number of the next frame expected and so acknowledges every frame before it; each ACK slides the window right, letting new frames go.

THE SLIDING WINDOW 3-bit sequence numbers (0 to 7, then 0 again); send window 7 frames for go-back-N. Sender 0 1 2 3 4 5 6 7 0 1 2 3 4 5 6 7 SEND WINDOW: 7 FRAMES left edge moves right when an ACK arrives right edge follows: new frames may be sent sent and acknowledged sent, waiting for an ACK may be sent now outside the window: not yet Receiver 0 1 2 3 4 5 6 7 0 1 2 3 4 5 6 7 go-back-N receive window: 1 frame, the next in order (frame 2 only) selective repeat: up to 4 frames (2, 3, 4, 5), half of the 8 numbers
Usliding window={1W≥1+2aW1+2aW<1+2a

On the same satellite link a window of 7 gives U=7/541, about 1.3 percent; filling the pipe needs W≥541, so 10-bit sequence numbers. TCP grows its window for the same reason (TCP flow control).

3. Piggybacking. When data flows both ways, the receiver does not send a separate ACK frame; it carries the acknowledgement in a field of the header of its own next data frame going back. So every data frame has two numbers: seq, its own sequence number, and ack, the next frame expected from the other side.

  • Advantages: fewer frames on the link (no separate ACK frames, their headers and trailers), so better use of the bandwidth; fewer frames to process and fewer interrupts at each end; the window still slides as the piggybacked acks arrive.
  • The cost: an ACK may wait for outgoing data. So the receiver starts an ack timer; if no data frame leaves in time, it sends a separate ACK, before the sender's own timer runs out and it resends for nothing.
  • Where: HDLC carries the piggybacked ACK in N(R) of every I-frame (HDLC); TCP sets its ACK flag on data segments.

To remember piggybacking: in a phone call, "yes, got it" is said at the start of your own next sentence, not in a separate call.

Asked on the paper, word for word
  • What is piggy-backing? How do you apply it in data link layer flow control mechanism? Calculate the CRC for a 10 bit sequence 1010001101. The generator polynomial is x⁵ + x⁴ + x² + 1. Also find the transmitted bit frame. 2081 Bhadra Q3 · 1+2+5
  • State the various design issues for the data link layer. What is piggybacking? A bit string 01111011111101111110 needs to be transmitted at the data link layer. What is the string actually transmitted after bit stuffing? 2075 Ashwin Q3 · 3+3+2
  • Write short notes on: (any two) i) Flow control in D22 ii) X.25 iii) ALOHA 2075 Ashwin Q10 · 4+4
  • Write short notes on: (Any two) a) SMTP and POP b) Diffie Hellman’s Algorithm c) CSMA/CD d) DLL Flow Control Mechanisms 2074 Ashwin Q10 · 4+4
  • List the functions of Data Link Control Layer. Explain any two sliding window protocols with the advantages of piggybacking. 2066 Poush Q4 · 5+3
  • What are the services provided by data link layer? Explain any one methods of framing and flow control. 2066 Bhadra Q2a · 2+3+3
In the exam For a short note on flow control, define it, draw stop and wait (normal case) and the sliding window, and end with piggybacking and its advantages. "How do you apply piggybacking in flow control" wants the seq and ack fields and the ack timer.

Error control by ARQ: stop and wait, go-back-N and selective repeat PIN 4/27

82 Bh · 80 Bh · 78 Bh · 66 Po4+42×45+3

ARQ (automatic repeat request) Error control by retransmission, also called backward error correction: the receiver detects damaged frames (by CRC) and the sender resends any frame that is damaged or lost, prompted by a timeout or a negative acknowledgement (NAK; the book writes NACK).

The tools every ARQ uses: sequence numbers on frames (to spot gaps and duplicates), ACKs (positive acknowledgements), NAKs (negative ones), a timer per outstanding frame, and a copy of every unacknowledged frame kept by the sender. The three ARQ protocols below are the "ways of backward error correction".

1. Stop and wait ARQ. Stop and wait flow control plus a timer and 1-bit sequence numbers (frames 0, 1, 0, 1, ...). It recovers from three cases (the right half of the figure under flow control):

  • Damaged frame: the receiver discards it (or sends a NAK); the sender's timer runs out and it resends.
  • Lost frame: nothing comes back; the timer runs out and the frame is resent.
  • Lost ACK: the timer runs out and the frame is resent; the receiver sees by its sequence number that it is a duplicate, discards it and sends the ACK again. Without the sequence number it would accept the same frame twice.

2. Go-back-N ARQ. A sliding window protocol. The sender may have up to 2k−1 frames outstanding; the receiver's window is 1, so it accepts frames only in order and discards any frame after a gap. ACKs are cumulative. When frame n is lost or damaged (a NAK or a timeout), the sender goes back and resends frame n and every frame after it, even those that arrived safely.

3. Selective repeat ARQ. Also a sliding window, but the receiver keeps frames that arrive after a gap in its buffer and asks with a NAK for the missing one only; the sender resends just that frame, and the receiver hands the frames up in order once the gap is filled. Both windows may be at most 2k−1. The book lists what it costs: the receiver needs sorting logic and a buffer big enough for every frame held after a NAK, and the sender needs to search out the one frame asked for.

GO-BACK-N AND SELECTIVE REPEAT: FRAME 2 IS LOST Same five frames, same loss; go-back-N resends three frames, selective repeat resends one. GO-BACK-N: RESEND FROM THE LOST FRAME ON Sender Receiver F0 F1 F2 lost F3 F4 F0, F1 ok, acknowledged F3 discarded F4 discarded NAK 2 F2 F3 F4 go back to 2 2, 3, 4 again ACK 5 SELECTIVE REPEAT: RESEND ONLY THE LOST FRAME Sender Receiver F0 F1 F2 lost F3 F4 F0, F1 ok, acknowledged F3 buffered F4 buffered NAK 2 F2 again (only) deliver 2, 3, 4 in order ACK 5
PointStop and waitGo-back-NSelective repeat
Frames outstanding1up to 2k−1up to 2k−1
Receiver window11 (in order only)up to 2k−1
On an error resendthat framethat frame and all after itthat frame only
Receiver bufferone frameone framea window of frames
Efficiencylowgood on clean linksbest on noisy links
Complexityleastmoderatemost (sorting, searching)

Why the windows are limited. With 3-bit numbers, suppose go-back-N used a window of 8 and every ACK was lost: the sender would resend the old frame 0, and the receiver, now expecting a new frame 0, would accept the old one as new. A window of 7 avoids it; selective repeat must stay at 4 so that the old and new receive windows never overlap.

To remember them: a student misses line 3 of the dictation. Go-back-N is the teacher who re-reads from line 3 to the end; selective repeat is the teacher who re-reads only line 3 while the student leaves a gap for it.

Asked on the paper, word for word
  • Write different ways to correct backward error correction. Compare pure Aloha and slotted Aloha mentioning the condition for no collision. 2082 Bhadra Q3 · 4+4
  • Write short notes on: (Any Two) a) Go Back-N ARQ b) Dual Stack method in IPv6 c) Diffie-Hellman algorithm d) ATM 2080 Bhadra Q10 · 2×4
  • Explain Go-back-N ARQ and selective Repeat ARQ with example. How carrier sense multiple access with collision detection (CSMA/CD) is better than CSMA? 2078 Bhadra Q3 · 4+4
  • List the functions of Data Link Control Layer. Explain any two sliding window protocols with the advantages of piggybacking. 2066 Poush Q4 · 5+3
In the exam Draw the go-back-N and selective repeat timing diagrams with the same lost frame; that drawing is the "example" the question wants. For "ways of backward error correction", name all three ARQs with a line each.

3.5Data link protocols: HDLC and PPP

HDLC: stations, modes, the frame and its three frame types PIN 2/27

78 Bh · 73 Shr2×44×2

HDLC (High-level Data Link Control) A bit-oriented ISO data link protocol (ISO 3309 and 4335, now ISO/IEC 13239) for point-to-point and multipoint links. It frames data with the flag 01111110 and bit stuffing, and gives flow and error control with a sliding window and ARQ.

Three kinds of station.

  • Primary: controls the link; its frames are commands.
  • Secondary: works under a primary; its frames are responses.
  • Combined: both at once; it may send commands and responses.

Three configurations. Unbalanced: one primary and one or more secondaries, point to point or multipoint. Balanced: two combined stations, point to point, with equal responsibility. Symmetric (in the book): each physical station is two logical ones, a primary and a secondary.

Three modes of operation.

ModeConfigurationWho may send
NRM, normal response modeunbalancedthe primary starts every exchange; a secondary sends only when the primary polls it
ARM, asynchronous response modeunbalanceda secondary may send without permission; the primary still owns the line (start-up, error recovery, disconnection)
ABM, asynchronous balanced modebalancedeither combined station may send at any time; the mode used on point-to-point links today
THE HDLC FRAME AND ITS THREE CONTROL FIELDS Bit-oriented: the flag 01111110 marks both ends, and bit stuffing keeps it out of the data. Flag 01111110 8 bits Address station 8 or more Control I, S or U 8 or 16 Information network layer data variable FCS CRC-16 or CRC-32 16 or 32 Flag 01111110 8 bits 1 2 3 4 5 6 7 8 I-frame information 0 N(S) P/F N(R) S-frame supervisory 1 0 S S P/F N(R) U-frame unnumbered 1 1 M M P/F M M M S BITS IN AN S-FRAME 00 RR: receive ready 01 REJ: reject (go-back-N) 10 RNR: receive not ready 11 SREJ: selective reject U-FRAME COMMANDS SNRM, SABM, DISC, UA, FRMR N(S): this frame's number; N(R): the next frame expected (a piggybacked ACK); P/F: poll from a primary, final from a secondary.

The frame fields.

  • Flag (8 bits, 01111110): marks both ends; bit stuffing keeps it out of the data.
  • Address (8 bits, extendable): the secondary station; in a command it is the receiver, in a response the sender.
  • Control (8 or 16 bits): says which of the three frame types this is and carries the sequence numbers; 16 bits gives 7-bit numbers (modulo 128) instead of 3-bit (modulo 8).
  • Information (variable): the network layer's data, or management information in a U-frame.
  • FCS (16 or 32 bits): a CRC over the frame between the flags.

Three frame types.

  • I-frame (information): carries user data plus N(S), its own number, and N(R), the next frame expected from the other side: a piggybacked ACK.
  • S-frame (supervisory): flow and error control with no data: RR (receive ready, an ACK), RNR (receive not ready, stop), REJ (reject: go back to N(R)) and SREJ (selective reject: resend frame N(R) only).
  • U-frame (unnumbered): link management: set a mode (SNRM, SABM), disconnect (DISC), acknowledge (UA), report a bad frame (FRMR).

P/F is the poll bit in a command (a reply is wanted) and the final bit in a response.

Its family: LAPB (the link layer of X.25), LAPD (the ISDN D channel, ISDN), LAPF (frame relay) and PPP's framing all come from HDLC. To remember it: the default encapsulation on a Cisco router's serial port, the kind of leased line that joins a bank's branch to its head office, is HDLC (Cisco's own variant of it).

Asked on the paper, word for word
  • Write short notes on: (Any Two) a) Frame relay b) TCP sliding window c) HDLC 2078 Bhadra Q10 · 2×4
  • Write short notes on: i) HDLC ii) Web Server 2073 Shrawan Q10 · 4×2
In the exam A short note on HDLC: the three stations, the three modes, the frame drawn with sizes, and the three frame types with the control field formats.

PPP: the Point-to-Point Protocol

PPP (Point-to-Point Protocol) The standard data link protocol for a point-to-point link, such as a dial-up, DSL or leased line (RFC 1661). It is byte-oriented, with HDLC-like framing (RFC 1662), and adds LCP to manage the link and an NCP for each network protocol.

Three parts (the book's three features):

  • Framing: an unambiguous frame with error detection, using byte stuffing.
  • LCP (Link Control Protocol): brings the line up, tests it, negotiates options (maximum frame size, authentication, compression) and takes it down.
  • NCPs (Network Control Protocols): one per network protocol; IPCP configures IPv4, for example giving each end its IP address.
PPP: THE FRAME AND THE LIFE OF A LINK Byte-oriented HDLC-like framing (RFC 1662); the link is set up by LCP, authentication and an NCP (RFC 1661). Flag 0x7E 1 byte Address 0xFF 1 Control 0x03 1 Protocol what is inside 1 or 2 Payload up to 1500 by default variable FCS CRC 2 or 4 Flag 0x7E 1 Protocol field: 0x0021 IPv4, 0x0057 IPv6, 0xC021 LCP, 0x8021 IPCP, 0xC023 PAP, 0xC223 CHAP Inside the payload a 0x7E is sent as 0x7D 0x5E and a 0x7D as 0x7D 0x5D (byte stuffing). Dead no carrier Establish LCP options Authenticate PAP or CHAP Network NCP, e.g. IPCP Open data flows Terminate LCP closes carrier up agreed passed IP set done link down, or a failed option or login: back to Dead

The frame. Flag 0x7E; address 0xFF (all stations, since there are only two); control 0x03 (an unnumbered frame: PPP numbers nothing); protocol, 2 bytes (1 if LCP agrees to compress it), naming what the payload holds; payload, up to 1500 bytes by default; FCS, 2 bytes (4 if negotiated); closing flag. Inside the frame a 0x7E is sent as 0x7D 0x5E and a 0x7D as 0x7D 0x5D.

The phases of a link: Dead (no carrier) to Establish (LCP agrees the options) to Authenticate (optional: PAP sends a password in clear; CHAP sends a challenge and checks a hashed reply) to Network (NCP, such as IPCP) to Open (data flows) to Terminate (LCP closes the link) and back to Dead. A failed option or login also ends the link.

PointHDLCPPP
Orientationbit-oriented, bit stuffingbyte-oriented, byte stuffing
Addressingstation addressnone (always 0xFF)
Flow and error controlsliding window, ACKs, ARQnone by default: errors are only detected
Extrasnoneoption negotiation, authentication, several network protocols

SLIP (Serial Line IP, RFC 1055) came first: it only wraps IP packets between END bytes, with no error detection, no address negotiation, no authentication and no protocol field, so PPP replaced it. To remember PPP: a home fibre router that asks for a PPPoE username and password is running PPP over Ethernet (RFC 2516) to log in to the ISP.

3.6The MAC sublayer and the channel allocation problem

The MAC sublayer and the channel allocation problem HOT 7/27

81 Ba · 75 Ch · 73 Shr · 72 Ka · 71 Ch · 68 Ch · 67 Asa2+62+2+42×4

MAC (medium access control) sublayer The lower sublayer of the data link layer, which decides which station may transmit next when many stations share one broadcast channel (a cable, a ring or a radio band), using a multiple access protocol.

Two kinds of link. A point-to-point link joins exactly two stations, and there is no question of who talks. A broadcast link is shared: every station hears every frame. On a broadcast link the key issue is who gets the channel when several want it, and that is the MAC sublayer's job.

Why channel access control is essential (its significance in the data link layer):

  • Collisions: if two stations send at once their signals mix and both frames are lost; the bandwidth used is wasted and both must be resent.
  • Efficiency: a good method keeps the channel busy with useful frames, with few collisions and little idle time.
  • Fairness: every station gets a chance; no station can hog the channel.
  • Delay and priority: some methods (token passing) guarantee a worst-case delay and priorities, which real-time and factory traffic needs.
  • Cost: many cheap stations can share one medium instead of each needing its own link.

To remember it: a class discussion without a moderator: everyone talks at once and nothing is heard (collisions); with a rule (raise a hand, pass a microphone) everyone is heard in turn.

The channel allocation problem is how to allocate a single broadcast channel among competing users. There are two families of answers.

Static allocation. The channel is divided in fixed portions: N users get 1/N of the bandwidth each (FDM) or one time slot in N (TDM) (multiplexing). It suits a few users with steady traffic, such as radio and TV broadcasting or telephone trunks, and wastes capacity on bursty data: an idle user's share is lost, and a busy user cannot use the idle shares. The queueing result shows the cost. For a channel of capacity C bps, frames of mean length 1/μ bits arriving at λ frames per second, the mean delay is:

T=1μC−λ,TN=1μ(C/N)−(λ/N)=NT
Worked example (Tanenbaum's numbers)

A 100 Mbps channel, frames of 10,000 bits (μC = 10,000 frames/s), 5000 frames/s arriving: T=1/(10000−5000) = 200 µs. Split statically into 10 channels of 10 Mbps, each with a tenth of the traffic: T=1/(1000−500) = 2 ms, ten times worse. Sharing one big channel beats ten small fixed ones.

Dynamic allocation. The channel goes to whoever needs it, when they need it. Tanenbaum's five assumptions behind it: independent stations generating frames at random (the station model); one channel shared by all; collisions are observable; time is continuous or slotted; stations can sense the carrier, or not.

Multiple access protocols are the methods of dynamic sharing, in three classes:

MULTIPLE ACCESS PROTOCOLS Three ways to share one broadcast channel among many stations. Multiple access protocols Random access contend; nobody controls ALOHA CSMA CSMA/CD CSMA/CA USED IN Ethernet (CSMA/CD), Wi-Fi (CSMA/CA) Controlled access stations take turns Reservation Polling Token passing USED IN token bus, token ring, FDDI Channelization the channel is divided FDMA TDMA CDMA USED IN GSM (FDMA with TDMA), 3G (CDMA) Random access wins at light load; controlled access and channelization guarantee each station its share at heavy load.
  • Random access (contention): no station controls another; each sends when it decides to and collisions are resolved by retrying: ALOHA, CSMA, CSMA/CD, CSMA/CA (wireless LAN).
  • Controlled access: stations take turns by agreement, so there are no collisions: reservation, polling, token passing (controlled access).
  • Channelization: the channel itself is divided by frequency, time or code: FDMA, TDMA, CDMA (channelization).
Asked on the paper, word for word
  • Write short notes on: (Any Two) a) MAC sublayer b) Digital signature c) Firewall 2081 Baishakh Q10 · 2×4
  • What are multiple access protocols? Describe the various framing techniques at data link layer. 2075 Chaitra Q3 · 2+6
  • What do you understand by Media Access Control? What is its significance in data link layer? Explain why token bus is also called as the token ring. 2073 Shrawan Q3 · 2+2+4
  • What are the functions of data-link layer? Explain the channel allocation problem with example. 2072 Kartik Q3 · 3+5
  • What are multiple access protocols? Explain how multiple access is achieved in IEEE 802.5. 2071 Chaitra Q3 · 2+6
  • Why channel access mechanism is important in computer networking? Explain the operation of IEEE 802.5 with its frame format. 2068 Chaitra Q4 · 3+7
  • Why access control of channel is essential? Compare operating details of IEEE 802.4 and IEEE 802.5. 2067 Ashad Q5 · 2+6
In the exam "What are multiple access protocols" wants the definition and the three classes with their members (the tree). "Channel allocation problem with example" wants static against dynamic, with the 200 µs against 2 ms example.

3.7Multiple access protocols

ALOHA: pure and slotted HOT 6/27

82 Bh · 79 Bh · 75 Ash · 70 Asa · 68 Ba · 66 Po4+42×4

ALOHA The first random access protocol (ALOHAnet, University of Hawaii, Norman Abramson, 1971), in which a station transmits whenever it has data; frames that overlap in time collide and are lost, and each sender retries after a random time.

Pure ALOHA. The original. A station sends a frame the moment it has one, then waits for an acknowledgement (the timeout is about twice the longest propagation delay). If none comes, it assumes a collision, waits a random backoff time (Forouzan: a random R from 0 to 2K−1 frame or propagation times after the Kth attempt, giving up after about 15) and sends again. The wait must be random, or the same two frames would collide forever.

ALOHA: THE VULNERABLE TIME T = the time to send one frame. No other frame may start inside the shaded interval. PURE ALOHA: SEND AT ANY TIME; VULNERABLE TIME 2T vulnerable time: 2T B starts before t A's frame C starts before t + T t - T t t + T B overlaps the head of A, C overlaps its tail: all of them are lost. SLOTTED ALOHA: SEND ONLY AT A SLOT START; VULNERABLE TIME T vulnerable: T A's frame B, same slot: collides C, next slot: safe slot boundaries every T

Vulnerable time. Let T be the time to send one frame. A frame sent at t survives only if no other frame starts in (t−T,t+T): one starting earlier overlaps its head, one starting later overlaps its tail. So pure ALOHA's vulnerable time is 2T. Even if the first bit of a new frame overlaps only the last bit of another, both are destroyed.

Slotted ALOHA (Roberts, 1972). Time is cut into slots of length T, and a station may start only at the beginning of a slot; one that misses the start waits for the next. Now a frame collides only with another sent in the same slot: the vulnerable time halves to T. It needs every station's clock synchronised to the slots.

Throughput. Let G be the offered load (frames tried per frame time, new and retried, Poisson-distributed) and S the throughput (frames that succeed per frame time). The probability that no other frame starts in an interval of k frame times is e−kG, so:

Spure=Ge−2G,Smax=12e=0.184 at G=0.5
Sslotted=Ge−G,Smax=1e=0.368 at G=1
ALOHA: THROUGHPUT AGAINST OFFERED LOAD G = frames offered per frame time (new and retried); S = frames that succeed per frame time. 0 0.5 1 1.5 2 2.5 3 0.1 0.2 0.3 0.4 G (offered load) S (throughput) slotted: max 0.368 at G = 1 pure: max 0.184 at G = 0.5 S = G e -G S = G e -2G READING THE CURVES Slotted ALOHA doubles the best throughput: 36.8 % against 18.4 %. Past the peak, more traffic brings more collisions and less useful work. Even at its best, slotted ALOHA leaves 37 % of slots empty and 26 % in collision.
PointPure ALOHASlotted ALOHA
When a station sendsat any timeonly at the start of a slot
Timecontinuous, no clock neededslotted, stations synchronised
Vulnerable time2TT
Condition for no collisionno other frame starts within T before or after the frame's startno other station sends in the same slot
Probability a frame succeedse−2Ge−G
Throughput SGe−2GGe−G
Maximum18.4 % at G=0.536.8 % at G=1
Worked example (Forouzan's numbers, checked)

A 200 kbps channel carries 200-bit frames, so T = 1 ms. Pure ALOHA: if the stations offer 1000 frames/s, G=1 and S=e−2 = 0.135: about 135 frames/s get through. At 500 frames/s, G=0.5, S = 0.184: about 92. At 250 frames/s, G=0.25, S = 0.152: about 38. Slotted ALOHA at 1000 frames/s: S=e−1 = 0.368, about 368 frames/s, more than double.

To remember it: students shouting answers whenever they like is pure ALOHA; shouting only right after the teacher's bell is slotted ALOHA. Fewer answers overlap, but even at its best a third of the bells hear silence and a quarter hear a clash.

The book's table. Insights (Table 3.1, p. 82) labels Ge−2G and Ge−G as the "probability of successful transmission". They are the throughputs; the probability that one frame succeeds is e−2G (pure) and e−G (slotted).
Asked on the paper, word for word
  • Write different ways to correct backward error correction. Compare pure Aloha and slotted Aloha mentioning the condition for no collision. 2082 Bhadra Q3 · 4+4
  • Write short notes on: (Any Two) a) ALOHA b) OSPF c) VPN 2079 Bhadra Q10 · 2×4
  • Write short notes on: (any two) i) Flow control in D22 ii) X.25 iii) ALOHA 2075 Ashwin Q10 · 4+4
  • Write short notes on: a) ALOHA system b) TCP header 2070 Ashad Q10 · 4+4
  • What are types of twisted pair cable? Calculate the efficiency of slotted Aloha. 2068 Baishakh Q2 · 4+4
  • Explain the operation of pure ALOHA system. How CSMA/CD works? 2066 Poush Q3 · 4+4
In the exam A short note on ALOHA: both kinds, the vulnerable time figure, the two throughput formulas and their maxima. The efficiency of slotted ALOHA is derived in full in the Numericals panel.

CSMA: listen before talking PIN 1/27

70 Asa2+2+4

CSMA (carrier sense multiple access) A random access method in which a station first listens to the medium (senses the carrier) and transmits only if it is idle: listen before talk.

Why it beats ALOHA. ALOHA sends blindly; CSMA never starts while another transmission is under way, so it avoids most collisions, and at light load its throughput comes close to 1.

Why collisions still happen: propagation delay. Station A starts sending; its signal takes time Tp to reach station B. If B senses the medium inside that time it hears nothing, decides the medium is idle, and also sends: collision. So CSMA's vulnerable time is the propagation time Tp, much shorter than ALOHA's, but not zero.

What a station does when the medium is busy is its persistence method:

MethodMedium idleMedium busyResult
1-persistentsends at once (with probability 1)keeps sensing, sends the moment it goes idleno idle time, but stations waiting for the same busy period all start together and collide; used by Ethernet
Non-persistentsends at oncewaits a random time, then senses againfewer collisions, but the medium may lie idle while all are waiting
p-persistent(slotted channel) sends with probability p; with 1−p waits for the next slot and repeatswaits until idle, then as for idlea balance of the two, set by p

To remember them: in a group call, the 1-persistent friend starts talking the instant there is silence (and clashes with the other eager one); the non-persistent friend gives up for a while and checks again later; the p-persistent friend, at each pause, tosses a coin before speaking.

Its limit. When two stations do collide, plain CSMA does not notice: both keep sending their whole frames, so the channel is wasted for a full frame time. Adding collision detection fixes that: CSMA/CD, which also compares the two.

Asked on the paper, word for word
  • Discuss how CSMA works? Differentiate it with CSMA-CD. Explain the optical fiber cabling standards with examples. 2070 Ashad Q5 · 2+2+4

CSMA/CD: carrier sense with collision detection TOP 9/27

82 Ba · 81 Ba · 79 Bh · 78 Bh · 76 Ch · 76 Ash · 74 Ash · 70 Asa · 66 Po4+42+2+41+1+6

CSMA/CD The access method of classic half-duplex Ethernet (IEEE 802.3): sense the carrier and send when the medium is idle, keep listening while sending, and on detecting a collision stop at once, send a jam signal and retry after a random binary exponential backoff.

Collision is the event it handles: two or more frames on a shared medium at overlapping times, so their signals add and both frames are garbled. It occurs when stations transmit at almost the same moment: each sensed the medium idle because the other's signal had not yet reached it (propagation delay), or both were waiting for the same busy period to end and started together the moment it did.

How it works, step by step:

  1. Sense: the station listens to the medium; while it is busy it keeps listening (1-persistent).
  2. Transmit: once the medium is idle (and the 96-bit interframe gap has passed) it sends, and keeps monitoring the medium while it sends.
  3. Success: if the whole frame goes out with no collision, the frame is done.
  4. Collision: if it detects one, it aborts the frame at once and sends a 32-bit jam signal, so that every station, including the other sender, knows of it.
  5. Count: it adds 1 to its attempt counter n; after 16 attempts it gives up and reports an error.
  6. Back off: it picks K at random from 0 to 2m−1, with m=min(n,10), waits K slot times of 512 bit times, and starts again at step 1.
CSMA/CD: THE FLOWCHART Ethernet (IEEE 802.3), half duplex: listen before talking, listen while talking, back off after a collision. Start: a frame to send attempts n = 0 Sense the channel Channel idle? no: keep sensing (1-persistent) yes Transmit the frame and listen while sending Collision detected? no Whole frame sent? no: keep sending yes Success the next frame may start yes Stop at once; send jam 32-bit jam: all stations learn n = n + 1 n > 15? yes Abort: too many collisions report the error upward no Pick K at random from 0 to 2 m - 1, m = min(n, 10) Wait K slot times slot = 512 bit times then sense again Slot time 512 bit times = 51.2 µs at 10 Mbps; jam 32 bits; at most 16 attempts per frame (truncated binary exponential backoff).

How a collision is detected. The station compares what it sends with what it hears on the medium. On coaxial cable the transceiver sees a signal level (voltage, energy) higher than its own transmission could make; on twisted pair (10BASE-T) it sees activity on its receive pair while it is transmitting. Detection must happen while the station is still sending, or it would never connect the collision with its frame. So a frame must last at least one round trip:

Tframe≥2Tprop⇒Lmin=2Tprop×B

For 10 Mbps Ethernet the round-trip budget (2500 m with four repeaters) is 51.2 µs, so Lmin=51.2 μs×10 Mbps = 512 bits = 64 bytes, the minimum Ethernet frame, and 512 bit times is the slot time of the backoff.

Binary exponential backoff. After the 1st collision K is 0 or 1; after the 2nd, 0 to 3; after the 3rd, 0 to 7; from the 10th on, 0 to 1023. Doubling the range after each collision spreads the retries out exactly when many stations are competing, and keeps waits short when few are.

Why CSMA/CD is better than CSMA.

PointCSMACSMA/CD
Listensbefore sending onlybefore and while sending
On a collisionkeeps sending the whole damaged framestops at once and sends a short jam
Time wasted per collisiona whole frame timeat most about 2Tprop plus the jam
Retryby the persistence methodbinary exponential backoff, at most 16 attempts
Needscarrier sensingalso the ability to hear while sending, and a minimum frame size
Throughputlowerhigher; less delay

Today. On a switch, every port is a separate full-duplex link with only two stations, so there are no collisions and CSMA/CD is switched off. It runs only in half duplex (hubs), and Ethernet from 10 Gbps up dropped half duplex altogether.

To remember it: a polite argument. Speak only when the room is quiet; keep listening as you speak; if someone else starts too, both stop and say "sorry" (the jam); each then waits a random moment before trying again, and waits longer each time it clashes.

Asked on the paper, word for word
  • What are the functions of data link layer? How to detect signal collision in CSMA/CD? List the ethernet cable specification standards for 802.3 ethernet standards. 2082 Baishakh Q2 · 2+3+3
  • What is CSMA/CD? Why is it not applicable in wireless LAN? What are the techniques used to avoid the possible collisions in WLAN? Explain. 2081 Baishakh Q3 · 2+2+4
  • How CSMA/CD works? Describe Ethernet (IEEE 802.3) frame structure with function of each field. 2079 Bhadra Q3 · 4+4
  • Explain Go-back-N ARQ and selective Repeat ARQ with example. How carrier sense multiple access with collision detection (CSMA/CD) is better than CSMA? 2078 Bhadra Q3 · 4+4
  • What is collision? How is it occured? How the possibility of collision is reduced in IEEE 802.3 and IEEE 802.11? Explain. 2076 Chaitra Q3 · 1+1+6
  • Explain the working principle of CSMA/CD with appropriate figure. 2076 Ashwin Q3 · 8
  • Write short notes on: (Any two) a) SMTP and POP b) Diffie Hellman’s Algorithm c) CSMA/CD d) DLL Flow Control Mechanisms 2074 Ashwin Q10 · 4+4
  • Discuss how CSMA works? Differentiate it with CSMA-CD. Explain the optical fiber cabling standards with examples. 2070 Ashad Q5 · 2+2+4
  • Explain the operation of pure ALOHA system. How CSMA/CD works? 2066 Poush Q3 · 4+4
In the exam "How CSMA/CD works" wants the six steps and the flowchart, with the jam, the backoff formula and the 64-byte minimum. "How to detect a collision" wants the signal comparison and Tframe≥2Tprop.

Controlled access: reservation, polling and token passing

Controlled access Multiple access in which the stations consult one another, or a controller, to decide who may send; only the station that holds the right transmits, so there are no collisions.
  • Reservation: time is divided into intervals, and each interval begins with a reservation frame of N mini-slots, one per station. A station with data sets its own mini-slot; the stations that reserved then send their data frames in order. Example: booking a slot at a futsal ground in advance.
  • Polling: one primary station controls the link and every exchange goes through it. With poll it asks each secondary in turn "anything to send?"; with select it asks a secondary "ready to receive?" and waits for its ACK before sending. Weaknesses: polling overhead, and the whole link stops if the primary fails. Examples: HDLC's normal response mode, the master of a Bluetooth piconet, a teacher taking roll call.
  • Token passing: a special frame, the token, circulates round a logical ring; only the station holding it may send, for a limited time, after which it passes the token on. It needs token management: a limit on holding time, priorities, and a way to recover a lost or duplicated token. The ring may be physical (token ring), a dual ring (FDDI) or a bus (token bus). Example: the talking stick passed round a circle.
PointRandom accessControlled access
Collisionspossiblenone
Delay at light loadvery lowmust wait for a turn
Behaviour at heavy loadthroughput falls, delay unpredictablefair; delay bounded and predictable
Weak pointcontentionoverhead; a failed primary or a lost token

Channelization: FDMA, TDMA and CDMA

Channelization Multiple access in which the channel's bandwidth is shared out among the stations by frequency (FDMA), by time (TDMA) or by code (CDMA), so each station has its own share and does not contend for it.
  • FDMA (frequency division): each station gets its own frequency band, with guard bands between them, and may use it all the time. First-generation analog mobile phones used it. FDM is the same idea done by one multiplexer at the physical layer (multiplexing); FDMA is an access method shared by many stations.
  • TDMA (time division): all stations use the same band, each in its own time slot, with guard times and tight synchronisation. GSM, the 2G network of NTC and Ncell, uses both: each 200 kHz carrier (FDMA) is shared by 8 time slots (TDMA).
  • CDMA (code division): all stations send at the same time on the same band; each multiplies its data by its own chip sequence. The sequences are orthogonal (the inner product of two different ones is 0, of one with itself is the number of chips), so the receiver recovers one station's bit by multiplying the combined signal by that station's code. 3G networks used it.
Worked example: CDMA with four 4-chip codes

Codes (Walsh): c1=(+1,+1,+1,+1), c2=(+1,−1,+1,−1), c3=(+1,+1,−1,−1), c4=(+1,−1,−1,+1). A bit 1 is sent as +1, a 0 as -1, and silence as 0. Station 1 sends 1 and station 2 sends 0; 3 and 4 are silent. The channel carries the sum (+1)c1+(−1)c2 = (0,+2,0,+2).

Receiver for station 1: (0+2+0+2)/4=+1, a 1. For station 2: (0−2+0−2)/4=−1, a 0. For station 3: (0+2−0−2)/4=0, silent.

To remember them: at a wedding party, FDMA is couples talking in separate rooms, TDMA is everyone taking turns at one microphone, and CDMA is pairs talking at the same time in one hall, one in Nepali, one in Newari, one in Maithili, one in English: each listener follows only their own language and hears the rest as noise.

3.8Ethernet and the IEEE 802 family

The IEEE 802 family of LAN standards

IEEE 802 The IEEE's family of standards for local and metropolitan area networks, which splits the data link layer into one common LLC sublayer (802.2) and a MAC sublayer and physical layer for each kind of LAN (the figure under the data link layer).
StandardWhat it coversStatus
802.1above all LANs: bridging and the spanning tree (802.1D), VLAN tagging (802.1Q), port authentication (802.1X), managementactive
802.2logical link control, the interface to the network layerstable
802.3Ethernet: CSMA/CD on a bus, now switched, 10 Mbps to 400 Gbpsdominant wired LAN
802.4token bus: a token on a logical ring over a buswithdrawn
802.5token ring: a token on a physical ringwithdrawn
802.11wireless LAN (Wi-Fi), CSMA/CAdominant wireless LAN
802.15personal area networks: Bluetooth (802.15.1), low-rate sensor networks (802.15.4, under Zigbee)active
802.16broadband wireless access (WiMAX)little used now

Why the split. The network layer sees the same LLC interface whatever the LAN, so IP runs unchanged over Ethernet, Wi-Fi or token ring; each LAN keeps the access method that suits its medium. To remember it: a laptop in a college lab uses three of them at once: its Ethernet port speaks 802.3, its Wi-Fi card 802.11, and the lab switch keeps students and staff apart with 802.1Q VLANs.

Ethernet (IEEE 802.3): the frame, MAC addresses, data transfer and cabling PIN 4/27

82 Ba · 79 Bh · 70 Asa · 66 Bh2+2+42+3+34+4

Ethernet (IEEE 802.3) The dominant wired LAN technology: frames with 48-bit MAC addresses and a CRC-32, sent at 10 Mbps up to 400 Gbps over coaxial cable, twisted pair or fiber. Classic shared Ethernet uses 1-persistent CSMA/CD; switched full-duplex Ethernet needs no access method at all.

History. Invented at Xerox PARC by Robert Metcalfe and David Boggs in 1973, running at about 3 Mbps; DEC, Intel and Xerox then made it 10 Mbps (Ethernet II), and IEEE standardised it as 802.3 in 1983. Generations: Standard Ethernet (10 Mbps), Fast Ethernet (100 Mbps, 802.3u, 1995), Gigabit Ethernet (1 Gbps, 802.3z and 802.3ab), 10 Gigabit Ethernet (802.3ae, 2002), and since then 40, 100 and 400 Gbps.

THE ETHERNET (IEEE 802.3) FRAME Sizes in bytes. The frame proper runs from the destination address to the FCS. Preamble 10101010 x 7 7 SFD 10101011 1 Destination MAC address 6 Source MAC address 6 Length/Type 0x0800 = IPv4 2 Data and pad 46 to 1500 bytes 46 to 1500 FCS CRC-32 4 synchronisation: not counted the frame: 64 to 1518 bytes (minimum 64 for collision detection) A MAC ADDRESS: 48 BITS, WRITTEN AS SIX HEX BYTES 00 00 5E 00 53 01 OUI: the maker (24 bits) NIC-specific (24 bits) 00:00:5E:00:53:01 (an address kept for examples, RFC 7042) first byte, bit 0 (I/G): 0 unicast, 1 multicast bit 1 (U/L): 0 global, 1 locally set Broadcast: FF:FF:FF:FF:FF:FF Bytes go left to right, each least significant bit first, so the I/G bit is the first on the wire.

The frame and each field.

FieldBytesFunction
Preamble710101010 seven times: wakes the receiver and lets its clock lock on to the bit timing
SFD, start frame delimiter110101011: the last two 1s say the frame starts now
Destination address6the receiver's MAC address: unicast, multicast or broadcast; it comes first so each station can decide early whether the frame is for it
Source address6the sender's MAC address, always unicast
Length/Type2a value up to 1500 is the length of the data (IEEE 802.3, an LLC header follows); 1536 (0x0600) or more is the EtherType naming the payload's protocol: 0x0800 IPv4, 0x0806 ARP, 0x86DD IPv6
Data and pad46 to 1500the network layer's packet; padded up to 46 bytes if shorter
FCS4CRC-32 over the addresses, length/type and data; a bad frame is dropped

From destination address to FCS a frame is 64 to 1518 bytes (1522 with an 802.1Q tag): the 64-byte minimum is what lets CSMA/CD detect a collision while the frame is still being sent. Frames are separated by an interframe gap of 96 bit times.

The MAC address. 48 bits, written as six hexadecimal bytes. The first 24 bits are the OUI, the number the IEEE gives the maker; the last 24 are the maker's own serial for that interface. The lowest bit of the first byte (I/G) is 0 for a unicast address and 1 for a multicast; the next bit (U/L) marks a globally assigned or a locally set address; all 48 bits 1 (FF:FF:FF:FF:FF:FF) is the broadcast address. To remember it: run ipconfig /all on a Windows laptop: the "Physical Address" line is its Wi-Fi or Ethernet card's MAC address. Examples in this reader use 00:00:5E:00:53:01, from the block kept for documentation (RFC 7042).

How data is transferred in an Ethernet:

  1. Address: the sender knows the receiver's IP address; ARP finds its MAC address (ARP).
  2. Encapsulate: the NIC builds the frame (destination and source MAC, type, data, pad) and computes the CRC-32 FCS.
  3. Access the medium: on a shared segment (half duplex, a hub) it uses 1-persistent CSMA/CD; on a switch port in full duplex it simply sends.
  4. Signal: the physical layer sends the preamble and SFD for synchronisation, then the frame, line-coded (Manchester at 10 Mbps).
  5. Deliver: on a shared bus every station hears the frame; a switch instead looks up the destination in its MAC address table (learned from source addresses) and forwards the frame only to that port, or floods it if unknown (switches).
  6. Receive: each NIC keeps the frame only if the destination is its own address, the broadcast or a multicast group it has joined; it checks the FCS, drops bad frames and frames under 64 or over 1518 bytes, and hands the data up by its type.

Ethernet is connectionless and unacknowledged at this layer: a dropped frame is recovered, if at all, by TCP above.

Cabling standards. The name says the speed in Mbps, the signalling (Base = baseband) and the medium or the segment length in hundreds of metres: 10Base5 runs 10 Mbps baseband over 500 m.

StandardMediumMax segmentNotes
10Base5 (thick Ethernet)thick coaxial cable500 mbus, 1983
10Base2 (thin Ethernet)thin coaxial, BNC T-connectors185 mbus
10BaseT2 pairs of UTP (Cat 3 or better)100 mstar, hub
10BaseF (10Base-FL)multimode fiber pair2000 mstar
100BaseTX2 pairs of Cat 5 UTP100 mFast Ethernet, 4B/5B
100BaseFXmultimode fiber pair2000 m (full duplex)Fast Ethernet
1000BaseT4 pairs of Cat 5e UTP100 mGigabit, 802.3ab
1000BaseSXmultimode fiber, 850 nm short-wave laser220 to 550 mGigabit, 802.3z
1000BaseLX1310 nm long-wave laser: multimode or single-mode550 m or 5 kmGigabit, 802.3z
10GBase-SR, LR, ERfiber: 850 nm multimode; 1310 and 1550 nm single-modeup to 300 m, 10 km, 40 km10 Gigabit, 802.3ae

Optical fiber standards, with examples. Fiber is used where copper's 100 m runs out or where electrical noise and lightning matter: between buildings and up risers. Short-wave (850 nm) lasers on multimode fiber are cheap and reach hundreds of metres: 1000BaseSX joins two floors of a block or two blocks of a campus close together. Long-wave (1310 nm) on single-mode fiber reaches kilometres: 1000BaseLX or 10GBase-LR joins a campus's distant buildings, such as a library 2 km from the main data centre. 100BaseFX and 10BaseF are the older 100 and 10 Mbps versions of the same idea.

The book's frame. Insights (Figure 3.34, p. 89) prints the data and padding field as "0-46" bytes; it is 46 to 1500 (46 is the minimum, reached by padding). It also describes the Length field as naming the upper-layer protocol, which is the EtherType meaning; in IEEE 802.3 a value up to 1500 is a length, and 1536 or more a type.
Asked on the paper, word for word
  • What are the functions of data link layer? How to detect signal collision in CSMA/CD? List the ethernet cable specification standards for 802.3 ethernet standards. 2082 Baishakh Q2 · 2+3+3
  • How CSMA/CD works? Describe Ethernet (IEEE 802.3) frame structure with function of each field. 2079 Bhadra Q3 · 4+4
  • How data transfer occurs in Ethernet network? Explain. 2070 Ashad Q4 · 6
  • Discuss how CSMA works? Differentiate it with CSMA-CD. Explain the optical fiber cabling standards with examples. 2070 Ashad Q5 · 2+2+4
  • Describe the 802.3 Ethernet standard for CSMA/CD and compare it with 802.4 token bus technology. Explain how DSSS technique is applied in wireless transmission. 2066 Bhadra Q3a · 5+3
In the exam Draw the frame with byte sizes and give one line per field. For cabling, a table of five to eight standards with medium and length; for fiber, SX, LX and FX with their wavelengths and an example each.

3.9Token bus, token ring and FDDI

Token bus (IEEE 802.4): a physical bus, a logical ring HOT 5/27

81 Bh · 76 Ash · 73 Shr · 67 Asa · 66 Bh2+2+42+62×4

Token bus (IEEE 802.4) A LAN whose stations hang off a physical bus (a linear or tree-shaped cable) but pass a token among themselves in a logical ring ordered by address; only the station holding the token may transmit, for a limited time, and then it passes the token to its successor.
TOKEN BUS: A PHYSICAL BUS, A LOGICAL RING IEEE 802.4: the token goes to the next lower address, whatever the stations' places on the cable. PHYSICAL: ONE BUS CABLE terminator terminator station 90 station 45 station 112 station 70 station 20 Stations sit anywhere on the cable; a frame on the bus reaches all of them at once. LOGICAL: THE ORDER THE TOKEN FOLLOWS 112 90 70 45 20 token goes to the next lower address The lowest, 20, passes back to 112: the circle closes.

Why token bus is also called a token ring. Physically it is a bus: every frame on the cable reaches every station at once. But access follows a ring. Each station knows the address of the station before it (its predecessor) and after it (its successor); the token goes in descending order of address, and the station with the lowest address passes it back to the highest, closing the circle. The ring exists only in the stations' tables, not in the wiring, so it is a logical ring: in the figure, 112 to 90 to 70 to 45 to 20 and back to 112, whatever their places on the cable.

Operation.

  • Sending: a station that receives the token may send frames until its token holding time runs out, then sends the token to its successor.
  • Priorities: four access classes, 0, 2, 4 and 6 (highest), each with its own timer, so urgent traffic goes first.
  • Ring maintenance by special frames: claim token to start the ring or replace a lost token; solicit successor to let new stations join; who follows and set successor to close the gap when a station leaves or fails.
  • Physical layer: 75-ohm broadband coaxial cable (the cable TV kind) at 1, 5 or 10 Mbps.
  • Frame: preamble, start delimiter, frame control, destination and source addresses (2 or 6 bytes each), data up to 8182 bytes, a 4-byte FCS and an end delimiter.

Where it was used: factory automation (General Motors' MAP), where a guaranteed worst-case delay matters more than average speed: a robot arm must get its command within a known time, which Ethernet's random backoff cannot promise.

Point802.3 Ethernet802.4 Token bus802.5 Token ring
Topologybus, now a star on a switchphysical bus, logical ringphysical ring (star-wired)
AccessCSMA/CD, contentiontoken passed by addresstoken passed to the next station downstream
Collisionsyesnonenone
Worst-case delayunbounded (random backoff)boundedbounded
Prioritiesnone in the MAC4 classes: 0, 2, 4, 68 levels (3 bits) with reservation
Medium and speedcoax, UTP, fiber; 10 Mbps upbroadband coax; 1, 5, 10 Mbpsshielded twisted pair; 4, 16 Mbps
Frame removed bynobody (it ends on the bus)nobody (it ends on the bus)the sender, when it comes round
Ring upkeepnone neededdistributed (claim token, solicit successor)an active monitor station
Light loadvery short delaywaits for the tokenwaits for the token

To remember it: pass the parcel at a birthday party, but the parcel goes by roll number, not to whoever sits next to you: the children are scattered round the room (the bus), yet the parcel still travels in a fixed circle (the logical ring).

Asked on the paper, word for word
  • Write Short notes on: (Any Two) a) 802.4 Token Bus b) Framing with bit stuffing c) Server Socket programming for bind, listen and accept d) ATM 2081 Bhadra Q10 · 2×4
  • Write short notes on: (Any two) a) Firewall and their types b) 803 Token Bus c) Virtual circuit switching 2076 Ashwin Q10 · 4+4
  • What do you understand by Media Access Control? What is its significance in data link layer? Explain why token bus is also called as the token ring. 2073 Shrawan Q3 · 2+2+4
  • Why access control of channel is essential? Compare operating details of IEEE 802.4 and IEEE 802.5. 2067 Ashad Q5 · 2+6
  • Describe the 802.3 Ethernet standard for CSMA/CD and compare it with 802.4 token bus technology. Explain how DSSS technique is applied in wireless transmission. 2066 Bhadra Q3a · 5+3
In the exam "Why token bus is called a token ring" wants the logical ring by address, with the bus and ring figure. For "compare 802.4 and 802.5" give the table's 802.4 and 802.5 columns.

Token ring (IEEE 802.5): operation and frame format PIN 4/27

82 Ba · 71 Ch · 68 Ch · 67 Asa2+62×43+7

Token ring (IEEE 802.5) A LAN (IBM's Token Ring, 4 or 16 Mbps) whose stations are joined in a physical ring of point-to-point links around which a 3-byte token circulates; a station may send only after seizing the free token, its frame travels round the ring, the destination copies it, and the sender removes it and releases a new token.
TOKEN RING (IEEE 802.5): THE RING, THE STEPS, THE FRAME 4 or 16 Mbps; a station may transmit only while it holds the token (at most about 10 ms). A B C D token one-way ring 1 Wait a station with data waits for the free token (SD, AC, ED: 3 bytes). 2 Seize it sets the token bit T in AC to 1: the token becomes a frame header; it sends. 3 Copy each station repeats the bits on; the destination copies the frame, sets A and C. 4 Remove the frame returns to the sender, which strips it and checks the A and C bits. 5 Release the sender puts a new free token on the ring; the next station downstream may use it. DATA FRAME (BYTES) SD 1 AC 1 FC 1 DA 2 or 6 SA 2 or 6 Data no fixed limit FCS 4 ED 1 FS 1 TOKEN SD AC ED 3 bytes: a free token AC BYTE P P P T M R R R P priority, T token bit, M monitor bit, R reservation; FS carries A (address recognised) and C (frame copied).

How multiple access is achieved. The token is the permission to send, and there is only one, so only one station transmits at a time and frames never collide.

  1. Wait: a station with data waits for the free token: start delimiter, access control and end delimiter.
  2. Seize: it sets the token bit (T) in the access control byte to 1, which turns the token into the start of a frame, and appends the rest of its frame.
  3. Circulate: each station repeats the bits on to the next (a one-bit delay each). The destination copies the frame as it passes and sets the A (address recognised) and C (frame copied) bits in the frame status byte.
  4. Remove: when the frame comes back to the sender, the sender strips it off the ring and reads A and C: 1 and 1 means delivered; 1 and 0, the station was there but did not copy it; 0, no such station.
  5. Release: the sender issues a new free token. It may hold the token for at most the token holding time, 10 ms by default; at 16 Mbps it may release the token right after its frame (early token release).

Frame format.

FieldBytesFunction
SD, start delimiter1announces a token or frame; uses deliberate coding violations, so it cannot occur in data
AC, access control1PPPTMRRR: 3 priority bits, the token bit (0 token, 1 frame), the monitor bit, 3 reservation bits
FC, frame control1data frame or ring management frame
DA, SA2 or 6 eachdestination and source addresses
Datano fixed limitlimited only by the token holding time
FCS4CRC-32 for error detection
ED, end delimiter1ends the token or frame; also flags an error spotted on the way
FS, frame status1the A and C bits, written twice because the FCS does not cover this byte

Priority and reservation. A station waiting with an urgent frame writes its priority into the reservation bits of a frame passing by; when the token is next released it carries that priority, and only stations with frames of that priority or higher may seize it. The station that raised the priority lowers it again afterwards.

The active monitor. One station is elected to keep the ring healthy: it issues a new token when none has been seen for too long (a lost token); it removes an orphan frame whose sender has died, which it recognises by the monitor bit it set when the frame first passed; and it adds delay so that the ring is always long enough to hold the 24-bit token.

Physical layer. 4 or 16 Mbps over shielded twisted pair, with differential Manchester coding. The ring is wired as a star: each station is cabled to a wiring centre (MAU) whose relay bypasses a station that is switched off, so one dead station does not break the ring.

To remember it: the talking stick at a circle meeting. Only the one holding the stick speaks; the stick goes round to the next person; a person's message goes all the way round so the speaker hears it come back and knows everyone heard it.

Asked on the paper, word for word
  • Write Short Notes on: (Any Two) a) 802.5 Token Ring b) PGP c) Socket programming fundamentals d) X.25 Network 2082 Baishakh Q10 · 2×4
  • What are multiple access protocols? Explain how multiple access is achieved in IEEE 802.5. 2071 Chaitra Q3 · 2+6
  • Why channel access mechanism is important in computer networking? Explain the operation of IEEE 802.5 with its frame format. 2068 Chaitra Q4 · 3+7
  • Why access control of channel is essential? Compare operating details of IEEE 802.4 and IEEE 802.5. 2067 Ashad Q5 · 2+6
In the exam "Operation of 802.5 with its frame format" wants the five steps, the ring and the frame with sizes, the AC byte and the A and C bits. "How multiple access is achieved" is the same answer, led by the token.

FDDI: dual counter-rotating rings and fault tolerance PIN 3/27

74 Ch · 72 Ch · 67 Asa4+48

FDDI (Fiber Distributed Data Interface) A 100 Mbps token-passing LAN or backbone on optical fiber (ANSI X3T9.5, ISO 9314), built as two counter-rotating rings: a primary that carries the data and a secondary that stands by, so the network survives a cut cable or a failed station.
FDDI: DUAL COUNTER-ROTATING RINGS, AND THE WRAP AFTER A FAULT 100 Mbps token ring on fiber; the secondary ring stands by until a link or a station fails. NORMAL: PRIMARY CARRIES DATA, SECONDARY STANDS BY A DAS B DAS C DAS D DAS primary (outer, clockwise) secondary (inner, anticlockwise) FIBER CUT BETWEEN A AND B: BOTH WRAP wrap wrap A DAS B DAS C DAS D DAS one ring of twice the length: B, C, D, A on the primary, then back A, D, C, B on the secondary A failed station is bypassed the same way: its two neighbours wrap.

Features (the list to write):

  • 100 Mbps over multimode fiber, later also over copper (CDDI); 4B/5B coding, so the line runs at 125 Mbaud.
  • Dual counter-rotating rings: traffic on the two rings flows in opposite directions; the secondary ring is idle until a fault.
  • Large: up to 1000 physical connections (about 500 dual attachment stations) on up to 200 km of fiber, with stations up to 2 km apart: a campus or city backbone.
  • Timed token protocol: a target token rotation time is agreed when the ring starts, which gives synchronous traffic a guaranteed share and lets asynchronous traffic use what is left; the token is released right after a frame (early release).
  • Frames of up to 4500 bytes, protected by a CRC-32.
  • Station types: a dual attachment station (DAS) joins both rings; a single attachment station (SAS), such as a PC, joins the primary ring through a concentrator, which routers and servers usually are not.
  • Fault tolerance by wrapping, optical bypass and dual homing, below.

The fault tolerance mechanism.

  1. A cable cut: the two stations on either side of the break detect the loss of signal and wrap: each joins the primary ring to the secondary inside itself. The dual ring becomes one ring of twice the length, and every station is still reached (the right half of the figure).
  2. A failed station: its two neighbours wrap in the same way, cutting it out; or an optical bypass switch passes the light straight through a station that is switched off, so the rings do not need to wrap at all.
  3. A failed single attachment station: the concentrator it hangs from simply cuts it off, and the ring never notices.
  4. Dual homing: a critical server or router is connected to two concentrators; if the main connection fails, the backup takes over.

Its limit: two faults at once split the network into two separate rings that cannot reach each other.

To remember it: Kathmandu's Ring Road has lanes running both ways round the valley; if one stretch is blocked, traffic turns back before the block and goes round the other way, and every chowk on the road can still be reached.

The book's name. Insights (p. 93) expands FDDI as "Fiber Distribution Data Interface"; the standard's name is Fiber Distributed Data Interface.
Asked on the paper, word for word
  • Write short notes on: (any two) i) Types of firewals ii) FDDI iii) Socket programming 2074 Chaitra Q10 · 4+4
  • Briefly explain different types of Data Link Layer framing mechanisms. List the features of FDDI. 2072 Chaitra Q3 · 8
  • Describe what do you understand by switching along with various types of switching mechanism. Explain the fault tolerance mechanism of FDDI. 2067 Ashad Q4 · 4+4
In the exam For features, six to eight bullets as above. For fault tolerance, draw the dual ring and the wrapped ring side by side and name the wrap, the bypass switch and dual homing.

3.10Wireless LAN (IEEE 802.11)

Wireless LAN (IEEE 802.11): architecture, CSMA/CA and the physical layer PIN 3/27

81 Ba · 76 Ch · 66 Bh1+1+62+2+45+3

IEEE 802.11 (Wi-Fi) The standard for wireless LANs. It defines the physical layer (radio in the 2.4, 5 and 6 GHz bands) and the MAC sublayer, whose access method is CSMA/CA, carrier sense with collision avoidance, optionally with an RTS and CTS exchange.

Architecture. The building block is the basic service set (BSS): stations that share one radio channel. In an ad hoc BSS (an independent BSS) the stations talk directly; in an infrastructure BSS every frame goes through an access point (AP). Several BSSs joined by a distribution system, usually a wired Ethernet, form an extended service set (ESS) with one network name (SSID), and a station can roam from one AP to another.

IEEE 802.11 ARCHITECTURE: BSS AND ESS A basic service set (BSS) is the building block; access points and a distribution system grow it into an extended service set (ESS). AD HOC BSS (NO AP) STA STA STA stations talk directly INFRASTRUCTURE BSS STA STA STA STA AP all traffic goes through the AP ESS: BSSs ON ONE BACKBONE distribution system (wired LAN) AP STA BSS 1 AP STA BSS 2 roaming one SSID: the ESS looks like one LAN

Why CSMA/CD is not applicable in a wireless LAN.

  • A radio cannot listen while it sends: its own signal is millions of times stronger than any arriving one, so collision detection would need costly full-duplex radios.
  • Hidden station: A and C are both in range of B but not of each other. While A sends to B, C senses the air idle and sends too; the frames collide at B, and neither sender can know.
  • A collision happens at the receiver, but a sender can only sense the air where it is, and signals fade with distance, so what the sender hears is not what the receiver hears.
  • Exposed station: C hears B sending to A and holds back, although its frame to D could not disturb A: sensing wastes chances too.
WHY CARRIER SENSING FAILS IN WIRELESS: HIDDEN AND EXPOSED STATIONS Each dashed circle is one station's radio range. A collision matters at the receiver, but a sender can only sense the air at its own place. HIDDEN STATION: C CANNOT HEAR A A B C collision A's range C's range Both A and C sense "idle"; their frames collide at B. EXPOSED STATION: C WAITS FOR NOTHING A B C D B sends C to D held back B's range C's range C senses B and defers, though A is out of C's range.

CSMA/CA: avoiding collisions instead. The distributed coordination function, step by step:

  1. Sense: the station waits until the channel has been idle for a DIFS (distributed interframe space).
  2. Back off: it picks a random number of slots from its contention window and counts down only while the channel stays idle, freezing the count while it is busy.
  3. Send when the count reaches zero.
  4. Acknowledge: the receiver waits a SIFS (short interframe space) and sends an ACK. No ACK means a collision was likely: the sender doubles its contention window and tries again.
  5. RTS and CTS (for large frames): the sender first sends a short request to send carrying the time the whole exchange will take; the receiver answers clear to send with the same time. Every station that hears either one sets its NAV (network allocation vector) and keeps quiet for that time: virtual carrier sensing. A hidden station cannot hear the RTS, but it does hear the CTS.
CSMA/CA WITH RTS AND CTS (IEEE 802.11) Virtual carrier sense: the RTS and the CTS carry the time the exchange needs; every station that hears either one keeps quiet (its NAV). Sender A wants to send Receiver B Station C hears A only Station D hears B only (hidden) DIFS backoff RTS SIFS CTS SIFS DATA SIFS ACK NAV from the RTS: keep quiet NAV from the CTS DIFS backoff DIFS backoff DIFS backoff SIFS < DIFS: the reply always takes the channel before anyone else may start.

Interframe spaces set priority: SIFS < PIFS < DIFS. ACKs and CTS wait only a SIFS, so they always take the channel before any new frame can start after its DIFS. The optional point coordination function lets the AP poll stations instead.

Collision reduction in 802.3 and 802.11, side by side.

PointIEEE 802.3 EthernetIEEE 802.11 Wi-Fi
Access methodCSMA/CDCSMA/CA
Strategydetect a collision fast and stopavoid the collision beforehand
Before sendingsense, send when idle (1-persistent)sense, wait DIFS and a random backoff
During sendinglisten; on a collision, jam and back offcannot listen; relies on the ACK
Extra toolsminimum frame of 64 bytes, binary exponential backoff; switches remove collisionsRTS and CTS with the NAV, ACK for every frame, contention window doubling

The physical layer. The original 802.11 (1997) ran at 1 and 2 Mbps in the 2.4 GHz band with frequency hopping or direct sequence spread spectrum (and infrared).

  • FHSS (frequency hopping): the carrier hops among 79 channels of 1 MHz in a pseudo-random order known to both ends, staying at most 400 ms on each; narrowband interference spoils only a hop or two. Bluetooth hops the same way.
  • DSSS (direct sequence): each data bit is replaced by an 11-chip Barker sequence, 10110111000 for a 1 and its inverse 01001000111 for a 0, sent at 11 Mchips/s. The signal is spread over a 22 MHz channel. The receiver correlates the incoming chips with the same sequence: the wanted signal adds up while narrowband interference and echoes are spread out and suppressed (a processing gain of about 10.4 dB, 10 log 11). 802.11b kept the 22 MHz DSSS channel and raised the rate to 11 Mbps with a different coding (CCK).
  • OFDM splits a channel into many narrow subcarriers sent at once; it carries every later version.
VersionYearBandTop rateTechnique
802.11b19992.4 GHz11 MbpsDSSS (CCK)
802.11a19995 GHz54 MbpsOFDM
802.11g20032.4 GHz54 MbpsOFDM
802.11n (Wi-Fi 4)20092.4 and 5 GHz600 MbpsOFDM, MIMO
802.11ac (Wi-Fi 5)20135 GHzabout 6.9 Gbpswider channels, multi-user MIMO
802.11ax (Wi-Fi 6, 6E)20212.4, 5 and 6 GHzabout 9.6 GbpsOFDMA

The frame (the book's Figure 3.41): frame control (2 bytes: version, type, subtype, To DS, From DS, more fragments, retry, power management, more data, protected (WEP), order), duration (2, the NAV value), up to four addresses (6 each), sequence control (2), the body (0 to 2312 bytes) and a 4-byte CRC. Its security, WEP and WPA, is chapter 8's (WEP).

To remember the hidden station: two students shout answers to a teacher from opposite ends of a big exam hall. Each thinks the hall is quiet, because neither hears the other; only the teacher in the middle hears both at once. RTS and CTS is raising a hand and waiting for the teacher to say "yes, you": everyone hears the teacher's "yes".

The book's list of versions. Insights (p. 92) gives 802.11a, b and g and calls 802.11n the latest. Wi-Fi 5 (802.11ac) and Wi-Fi 6 and 6E (802.11ax) have come since, as in the table.
Asked on the paper, word for word
  • What is CSMA/CD? Why is it not applicable in wireless LAN? What are the techniques used to avoid the possible collisions in WLAN? Explain. 2081 Baishakh Q3 · 2+2+4
  • What is collision? How is it occured? How the possibility of collision is reduced in IEEE 802.3 and IEEE 802.11? Explain. 2076 Chaitra Q3 · 1+1+6
  • Describe the 802.3 Ethernet standard for CSMA/CD and compare it with 802.4 token bus technology. Explain how DSSS technique is applied in wireless transmission. 2066 Bhadra Q3a · 5+3
In the exam "Why is CSMA/CD not applicable" wants the four reasons with the hidden station drawn. "Techniques to avoid collisions in WLAN" wants IFS, the contention window, ACKs and RTS/CTS with the NAV, drawn as the timing diagram. "How DSSS is applied" wants the Barker code, the chips and the despreading.

3.11Virtual LANs

Virtual LANs and IEEE 802.1Q, with a two-VLAN design PIN 3/27

82 Bh · 80 Ba · 68 Ba2×42+6

VLAN (virtual LAN) A logical group of stations on one or more switches that behaves as a separate LAN, one broadcast domain, defined by configuration (by switch port, MAC address, IP address or application) rather than by physical wiring.

The problem it solves. Every port of a plain switch is in one broadcast domain: an ARP request or a DHCP broadcast from any PC reaches every other PC. Grouping users by department would need a separate switch per department, rewired whenever someone moves. A VLAN-capable switch does it in software.

Why use VLANs.

  • Smaller broadcast domains: broadcasts stay inside their VLAN, so less traffic floods every port.
  • Security: students' PCs cannot reach the department's servers at layer 2; traffic between VLANs passes through a router where it can be filtered.
  • Flexibility: users are grouped by function, not location; a moved PC is moved by changing one port's VLAN, not the cabling.
  • Cost and performance: one switch serves several groups, and the network is easier to manage.

Membership (the book's four ways): by switch port (static, the most common), by MAC address, by IP address, or by the application in use. The book also separates single-switch VLANs from multi-switch VLANs, which need a trunk.

IEEE 802.1Q tagging. Between switches (or a switch and a router) one link, a trunk, carries frames of many VLANs; each frame gets a 4-byte tag inserted after the source address:

  • TPID (16 bits) = 0x8100: marks the frame as tagged.
  • PCP (3 bits): the priority (802.1p).
  • DEI (1 bit): the frame may be dropped first under congestion.
  • VID (12 bits): the VLAN ID, 4096 values, of which 0 and 4095 are reserved, so VLANs 1 to 4094.

An access port belongs to one VLAN and carries untagged frames to an ordinary PC; the switch adds the tag when a frame enters a trunk and removes it at the access port. Untagged frames on a trunk belong to its native VLAN.

Routing between VLANs. Two VLANs are two IP subnets, so a router (or a layer 3 switch) must join them: router on a stick uses one router port split into one subinterface per VLAN, over a single trunk.

TWO VLANS, STUDENT AND DEPARTMENT, ON ONE SWITCH One broadcast domain and one subnet per VLAN; the router (on a stick) routes between them over one 802.1Q trunk. Router R1 G0/0: trunk port G0/0.10: 192.168.10.1/24 (VLAN 10) G0/0.20: 192.168.20.1/24 (VLAN 20) 802.1Q trunk: G0/0 to S1 Gi0/1, carries both VLANs Switch S1 Fa0/1 to Fa0/12: VLAN 10 Fa0/13 to Fa0/24: VLAN 20 Student PC1 192.168.10.11 Student PC2 192.168.10.12 Dept PC3 192.168.20.11 Dept PC4 192.168.20.12 VLAN 10 STUDENT: 192.168.10.0/24, gateway .1 VLAN 20 DEPARTMENT: 192.168.20.0/24, gateway .1 ON THE TRUNK, EACH FRAME CARRIES A 4-BYTE 802.1Q TAG DA 6 SA 6 TPID 0x8100 2 PCP 3 bits DEI 1 bit VLAN ID 12 bits Type 2 Data 42 to 1500 FCS 4 the tag: 4 bytes, added on the trunk, removed at the access port
Worked design: two VLANs, STUDENT and DEPARTMENT
VLANSwitch portsSubnetGatewayHosts
10 STUDENTFa0/1 to Fa0/12192.168.10.0/24192.168.10.1192.168.10.11, .12, ...
20 DEPARTMENTFa0/13 to Fa0/24192.168.20.0/24192.168.20.1192.168.20.11, .12, ...

Switch S1 (Cisco IOS):

S1(config)# vlan 10
S1(config-vlan)# name STUDENT
S1(config-vlan)# vlan 20
S1(config-vlan)# name DEPARTMENT
S1(config-vlan)# exit
S1(config)# interface range fastEthernet 0/1 - 12
S1(config-if-range)# switchport mode access
S1(config-if-range)# switchport access vlan 10
S1(config-if-range)# interface range fastEthernet 0/13 - 24
S1(config-if-range)# switchport mode access
S1(config-if-range)# switchport access vlan 20
S1(config-if-range)# interface gigabitEthernet 0/1
S1(config-if)# switchport mode trunk

Router R1, one subinterface per VLAN on the trunk port:

R1(config)# interface gigabitEthernet 0/0
R1(config-if)# no shutdown
R1(config-if)# interface gigabitEthernet 0/0.10
R1(config-subif)# encapsulation dot1Q 10
R1(config-subif)# ip address 192.168.10.1 255.255.255.0
R1(config-subif)# interface gigabitEthernet 0/0.20
R1(config-subif)# encapsulation dot1Q 20
R1(config-subif)# ip address 192.168.20.1 255.255.255.0

Each PC gets an address in its VLAN's subnet with that VLAN's gateway. show vlan brief on S1 lists the ports in each VLAN; a ping from a student PC to a department PC succeeds only through R1. With a layer 3 switch, the router is replaced by interface vlan 10 and interface vlan 20 with the gateway addresses, and ip routing.

To remember it: two WhatsApp groups on the same phone. The phone (the switch) is one piece of hardware, but a message to the class group never reaches the staff group; to pass something between them someone must forward it on purpose (the router).

Asked on the paper, word for word
  • Write short notes on: (Any Two) a) ARP and NDP b) AH and ESP c) VPN d) vLAN 2082 Bhadra Q10 · 2×4
  • Write short notes on: (Any Two) a) VLAN b) ARP c) IPSec 2080 Baishakh Q10 · 2×4
  • What is a virtual LAN? Design a network which consists of two VLAN named student and department. Explain with necessary diagram, IP addresses and configurations. 2068 Baishakh Q3 · 2+6
In the exam A short note on VLANs: the definition, the benefits, membership and the 802.1Q tag. For the design question, draw the switch, trunk and router, give the address table, and write the configuration lines.

3.12Last minute recall

Chapter 3 in one screen

  • Functions: framing, physical addressing, flow control, error control, access control; services: unacknowledged connectionless, acknowledged connectionless, acknowledged connection-oriented; LLC (802.2) over MAC.
  • Framing: character count (one bad count loses sync), byte stuffing (FLAG, ESC; PPP), bit stuffing (flag 01111110, a 0 after five 1s; HDLC), coding violations.
  • Errors: single-bit, burst; detection (parity, checksum, CRC) against correction (Hamming, FEC); parity catches odd counts only; checksum is one's complement.
  • CRC: append r zeros, divide by G mod 2, remainder is the CRC, receiver's zero remainder means accept; CRC-32 in Ethernet.
  • Hamming: distance by XOR; detect s needs d ≥ s + 1, correct t needs d ≥ 2t + 1; (7,4) code, parity at 1, 2, 4, syndrome gives the wrong bit.
  • Flow control: stop and wait (U = 1/(1 + 2a)), sliding window (W frames, seq mod 2^k), piggybacking (ack in the data frame, ack timer).
  • ARQ: stop and wait (1-bit seq, timer), go-back-N (window 2^k - 1, resend from the lost one), selective repeat (window 2^(k-1), resend only the lost one).
  • HDLC: primary, secondary, combined; NRM, ARM, ABM; flag, address, control, information, FCS, flag; I, S (RR, RNR, REJ, SREJ), U frames.
  • PPP: byte stuffing, 7E FF 03, LCP, PAP or CHAP, NCP (IPCP); dead, establish, authenticate, network, open, terminate.
  • MAC: who sends next on a broadcast channel; static (FDM, TDM: delay N times) against dynamic; random, controlled, channelization.
  • ALOHA: pure, vulnerable 2T, S = G e^-2G, max 18.4 % at G = 0.5; slotted, vulnerable T, S = G e^-G, max 36.8 % at G = 1.
  • CSMA: listen before talk; vulnerable time = propagation time; 1-persistent, non-persistent, p-persistent.
  • CSMA/CD: sense, send and listen, jam (32 bits), back off K from 0 to 2^min(n,10) - 1 slots of 512 bit times, 16 attempts; minimum frame 64 bytes as T_frame ≥ 2 T_prop.
  • Controlled access and channelization: reservation, polling, token passing; FDMA, TDMA (GSM), CDMA (orthogonal chip codes).
  • Ethernet: preamble 7, SFD 1, DA 6, SA 6, length/type 2, data 46 to 1500, FCS 4; 64 to 1518 bytes; 48-bit MAC (OUI + NIC); 10Base5, 10Base2, 10BaseT, 100BaseTX, 100BaseFX, 1000BaseSX and LX.
  • Token bus (802.4): physical bus, logical ring by descending address, so "token ring"; priorities 0, 2, 4, 6; broadband coax; factories.
  • Token ring (802.5): seize the token (T bit), frame circles, destination sets A and C, sender strips it and releases the token; SD, AC, FC, DA, SA, data, FCS, ED, FS; active monitor; 4 or 16 Mbps.
  • FDDI: 100 Mbps fiber, dual counter-rotating rings, timed token; DAS, SAS, concentrator; a cut makes both neighbours wrap into one ring; optical bypass, dual homing.
  • WLAN: BSS (ad hoc, infrastructure), ESS; no CSMA/CD (cannot hear while sending, hidden and exposed stations); CSMA/CA: DIFS, backoff, SIFS, ACK, RTS/CTS and NAV; FHSS, DSSS (11-chip Barker), OFDM.
  • VLAN: one broadcast domain by configuration; 802.1Q tag (TPID 0x8100, PCP, DEI, 12-bit VID); access and trunk ports; router on a stick; STUDENT 192.168.10.0/24, DEPARTMENT 192.168.20.0/24.

Chapter 4 · 9 hours · about 17 marks a paper · in all 27 sittings

Network layer

The network layer carries a packet from the source host to the destination host across many networks: it gives every interface a logical (IP) address, and routers choose the path one hop at a time. It is the heaviest chapter of the course, about 17 of every 80 marks: a subnetting design has been set in 24 of the 27 sittings on record, and routing (distance vector against link state, OSPF, RIP) appears in almost every paper as well.

What this chapter is about
  • The layer and its devices: host-to-host delivery, and the repeaters, hubs, bridges, switches, routers and gateways that join segments and networks, each at its own layer.
  • Addressing: the 32-bit IPv4 address and its classes, subnetting with VLSM, classless addressing (CIDR) and supernetting, and NAT.
  • The IP datagram and its helpers: the IPv4 header, fragmentation and reassembly, ARP and RARP for addresses, ICMP for error reports.
  • Routing: static and dynamic routing, the routing table, and the algorithms: Dijkstra's shortest path, flooding, distance vector, link state and hierarchical routing.
  • Routing protocols: RIP, OSPF, BGP, IGRP and EIGRP, and unicast against multicast routing (IGMP, DVMRP, MOSPF, PIM).
  • Design: a hotel or a campus network, with the devices, cabling, wireless, servers and addressing chosen and justified.
Where it fits
What you will learn
  1. 4.1 The network layer: functions, and why it is the key layer
  2. 4.2 Internetworking devices, bridges
  3. 4.3 IPv4 addressing, subnetting and VLSM, CIDR and supernetting, NAT
  4. 4.4 The IPv4 datagram, ARP and RARP, ICMP
  5. 4.5 Routing, the routing table
  6. 4.6 Shortest path, flooding, distance vector, link state, hierarchical routing
  7. 4.7 Routing protocols, RIP, OSPF, BGP, unicast and multicast routing
  8. 4.8 Designing a network: a hotel, a campus
  9. 4.9 Last minute recall, chapter 4
How it is examined
  • A subnetting design (VLSM from a given block, 8 to 10 marks) is the chapter's banker: 24 of the 27 sittings set one. The subnet card teaches the method; every paper's design is worked in full in the Numericals panel.
  • Distance vector against link state has been compared in ten sittings: the table on the link state card is the answer. Count to infinity and loop prevention go with it.
  • Routing basics (what routing is, why it is essential, a good algorithm's properties, adaptive against non-adaptive, routed against routing protocols) appear in 13 sittings, usually as the 2 or 3 mark first part.
  • One of the rest in most papers: OSPF (DR and BDR, full adjacency), RIP and its timers, ICMP message types, ARP, the IPv4 header and fragmentation, the devices.
  • The order here puts the routing algorithms (syllabus 4.6) before the protocols (4.5), because RIP is distance vector and OSPF is link state: each protocol card builds on its algorithm.

4.1The network layer

The network layer: what it does, and why it is the key layer PIN 1/27

72 Ka2+6

Network layer Layer 3 of the OSI model. It delivers a packet from the source host to the destination host, possibly across many networks, by giving every interface a logical address and having routers choose the path one hop at a time.

Three scopes of delivery keep the layers apart. The data link layer moves a frame across one link, from a node to the next (hop to hop). The network layer moves a packet from the source host to the destination host across all the links in between (host to host). The transport layer moves a message between two processes inside those hosts (process to process, ports).

HOST TO HOST AND HOP TO HOP Hosts run five layers, routers three; the IP addresses stay the same end to end, the MAC addresses change on every link. Host A Application Transport Network Data link Physical Router R1 Network Data link Physical Router R2 Network Data link Physical Host B Application Transport Network Data link Physical IP packet IP packet IP packet transport: process to process (ports), the routers never look frame 1: MAC of A to MAC of R1 frame 2: R1 to R2 (new MACs) frame 3: R2 to MAC of B Network: one packet, source and destination IP unchanged end to end. Data link: a new frame, with new MACs, on every link.

The drawing shows the split. Hosts run all five layers of the TCP/IP stack; a router runs only the bottom three. At every router the frame is opened, the packet is read, a new frame is built for the next link with new MAC addresses, but the packet's source and destination IP addresses stay the same from end to end.

Its functions, each one a line in the answer:

  • Logical addressing: every host and router interface gets an IP address that is unique across the internetwork; each packet's header carries the source and the destination address. A MAC address only works inside one link.
  • Routing: routers run routing algorithms and protocols to learn the networks and build their routing tables (routing).
  • Forwarding: for each arriving packet, a router looks up the destination in its table and sends the packet out of the matching interface.
  • Packetizing: the layer wraps the transport segment in a packet with its own header at the source and unwraps it at the destination (encapsulation).
  • Fragmentation and reassembly: a packet bigger than the next link's MTU is split into fragments, and the destination puts them back together (the IPv4 datagram).
  • Internetworking: one packet format and one address space hide the different link technologies (Ethernet, Wi-Fi, fibre and leased WAN lines) underneath.
  • Error reporting and diagnostics: ICMP tells the source why a packet could not be delivered, and supports ping and traceroute (ICMP).
  • Congestion control and quality of service: routers queue, drop or prioritise packets (the type of service field); end-to-end control belongs to the transport layer (congestion control).

Two kinds of service are possible. In datagram (connectionless) service each packet carries the full destination address and is routed on its own, as IP does. In virtual circuit (connection-oriented) service a path is set up first and packets carry only a short circuit number, as X.25, ATM and MPLS do. Chapter 2 compares them (datagram and virtual circuit).

LayerDeliversUnitAddressDevice
Data link (2)node to node, over one linkframeMAC, 48 bitsswitch, bridge
Network (3)host to host, across networkspacket (datagram)IP, 32 bitsrouter
Transport (4)process to processsegmentport, 16 bitsthe end hosts only

Why it is the key layer of the OSI model:

  • The highest layer on the path: routers implement layers 1 to 3, so layer 3 is the top layer that every node between the two hosts understands. The path is decided here.
  • The narrow waist: many applications and two transport protocols above, dozens of link technologies below, and one network protocol in the middle (IP over everything, everything over IP). Replace Wi-Fi with fibre and no application notices.
  • Global addressing that scales: hierarchical addresses let a router keep one route per network, not one per host, so a few hundred thousand routes reach billions of hosts.
  • Without it a frame could never leave its own LAN: there would be no Internet, only islands.

To remember it, post a parcel from Pulchowk to a friend in Pokhara. The address on it (district, municipality, ward, name) is the IP address. Each post office is a router: it looks only at the district and sends the bag on to the next office. The bus that carries the bag between two offices is the data link, and it changes at every office; the address on the parcel never does.

Asked on the paper, word for word
  • What are the functions of network layer? Explain briefly about multicast routing protocols and unicast routing protocols. 2072 Kartik Q4 · 2+6
  • Network layer is one of the key layers in OSI reference model, why? Differentiate between distance vector routing and static link routing. 2072 Kartik Q5 · 2+6
In the exam For "functions", give six with a line each and draw two hosts and two routers with the layers each runs. For "why is it the key layer", give the three reasons: the highest layer every router runs, the narrow waist, and addressing that scales.

4.2Internetworking devices

Internetworking devices, layer by layer PIN 4/27

79 Bh · 70 Ch · 68 Ch · 66 Po2×53+34+4

Internetworking device Hardware that joins network segments or whole networks. Each works at one OSI layer, and the layer fixes what it can read (bits, frames, packets or whole messages) and so how much it can decide.
INTERNETWORKING DEVICES AND THE OSI LAYERS A device can only decide on what its layer can read. 7 Application 6 Presentation 5 Session 4 Transport 3 Network 2 Data link 1 Physical Gateway protocol converter, up to layer 7 Router (and layer 3 switch) Bridge Switch Repeater Hub reads whole messages; converts one protocol to another reads IP addresses; a broadcast domain per interface reads MAC addresses; a collision domain per port regenerates the signal; one collision domain Higher layer: the more it can read and decide, and the slower and costlier per port.

The rule behind the whole topic: a device can only decide on what its layer can read. A repeater sees only a signal, so it can only copy it. A switch reads MAC addresses, so it can pick one port. A router reads IP addresses, so it can pick a path between networks. A gateway reads whole messages, so it can translate one protocol into another.

  • Repeater (physical layer): receives a weakened, noisy signal on one port and regenerates it at full strength on the other. It restores bits without reading them, so it extends a cable beyond its distance limit (500 m for a thick coaxial 10BASE5 segment). It has two ports and no intelligence: every bit, collisions included, is copied, so both sides stay one collision domain. Classic 10 Mbps Ethernet capped them with the 5-4-3 rule: at most five segments joined by four repeaters, with stations on only three. A repeater is not an amplifier: an amplifier boosts the noise with the signal, a repeater rebuilds a clean digital signal.
  • Hub (physical layer): a multiport repeater. A signal arriving on one port is copied out of every other port, so all ports share one bandwidth and one collision domain, and the hub works half duplex. An active hub is powered and regenerates the signal; a passive hub only joins the wires.
  • Bridge (data link layer): joins two LAN segments, reads the MAC addresses, records which station lives on which side and forwards a frame only when its destination is on the other side. Each side becomes its own collision domain; broadcasts still cross. It has its own card (bridges).
  • Switch (data link layer): a multiport bridge. It keeps a MAC address table and sends each frame only to the port where the destination lives, flooding only unknown and broadcast frames. Every port is a separate collision domain, and on a full-duplex port there are no collisions at all. It forwards in one of three ways: store-and-forward (receives the whole frame and checks its FCS first: reliable, the usual default), cut-through (starts sending as soon as the destination MAC is read: fastest, but passes bad frames) or fragment-free (waits for the first 64 bytes, where collision fragments show). Managed switches add VLANs (VLAN), port security and monitoring; a layer 3 switch also routes between VLANs.
  • Router (network layer): joins different networks (one subnet to another, a LAN to a WAN) and forwards packets by destination IP address, using a routing table that is configured by hand or built by routing protocols. Each interface is its own network and its own broadcast domain, because a router does not forward broadcasts. It also decrements TTL, fragments when needed and often does NAT and packet filtering.
  • Gateway (up to the application layer): a protocol converter. It joins networks that use different protocol stacks and translates between them: an email gateway between two mail systems, a VoIP gateway between IP phones and the telephone exchange, an IoT gateway between Zigbee sensors and an IP network. In TCP/IP, the "default gateway" of a host simply means the router it sends off-subnet packets to.

Two more devices appear in every network: the NIC (network interface card) works at layers 1 and 2 and carries the MAC address; the modem (or the ONT of a fibre connection) converts the digital signal to the line's analogue or optical signal, a layer 1 job.

DeviceLayerReadsSends a unicast toCollision domainsBroadcast domains
Repeater1, physicalthe signalthe other portone, sharedone
Hub1, physicalthe signalevery other portone for all portsone
Bridge2, data linkMAC addressthe destination's side onlyone per portone
Switch2, data linkMAC addressthe destination's port onlyone per portone (one per VLAN)
Router3, networkIP addressthe next hop on the best pathone per interfaceone per interface
Gatewayup to 7the whole messagethe other network, translatedseparateseparate

Why a switch, not a hub, for a LAN:

  1. Dedicated bandwidth: a 24-port 100 Mbps hub shares 100 Mbps among all 24 PCs; a switch gives every port its own 100 Mbps, and its backplane carries many conversations at once.
  2. No collisions: each switch port is its own collision domain, and with full duplex the CSMA/CD rules never fire (CSMA/CD); a hub's single collision domain collapses as the load grows.
  3. Full duplex: a switch port sends and receives at the same time; a hub is half duplex.
  4. Privacy and security: a switch delivers a unicast frame only to its owner; on a hub every PC receives every frame, so anyone running a packet sniffer sees all the traffic.
  5. Features: VLANs, port security, quality of service, link aggregation and monitoring; a hub has none.
  6. Cost: the price gap has closed; hubs are no longer made.

Router against gateway (a short note on its own in one sitting):

PointRouterGateway
Jobforwards packets between networkstranslates between networks that use different protocols
Layer3, networkany layer, usually 4 to 7 (up to the application)
Protocols on its two sidesthe same network protocol (IP)different protocol stacks
Decides bydestination IP address and the routing tablethe message's protocol and content
Changes in the dataonly header fields (TTL, checksum)the format itself (protocol conversion)
Examplesan ISP's core router, a home Wi-Fi routeremail gateway, VoIP to telephone gateway, IoT gateway

To remember them, picture the letters for a hostel floor. A hub is a warden who reads every letter aloud in the corridor: everyone hears it. A switch is a warden who slides each letter under the right door. A router is the post office that sends letters on to other cities. A gateway is a translator who rewrites a letter from Japanese into Nepali before delivering it.

The book says a gateway "operates at the session layer and above". Most texts let a gateway work at any layer, up to the application layer, since protocol conversion can be needed at any of them; either way, it is the only device here that changes the data's format.
Asked on the paper, word for word
  • Why do we prefer a switch as networking device instead of Hub for LAN connection? Give reasons. Discuss the characteristics of a good routing algorithm. 2079 Bhadra Q4 · 4+4
  • Explain the working principle of different types of network devices Repeater, HUB, Bridge, Switch and Router. 2070 Chaitra Q4 · 8
  • Write short notes on: a) Network Security b) Router and Gateway 2068 Chaitra Q9 · 2×5
  • Write short notes on (any two): a) UDP and its application b) Network Devices: Hubs, Switches and Routers c) IPv4 Header Structure 2066 Poush Q10 · 3+3
In the exam For "working principle of the devices", draw the devices against the OSI layers, then give each device its layer, what it reads and what it does with a frame or packet. For "switch instead of hub", give the six reasons above. For "router and gateway", the table.

Bridges: learning, filtering and forwarding PIN 1/27

80 Ba8

Bridge A data link layer device that joins LAN segments and forwards each frame by its destination MAC address: it records which station lives on which port, filters the frames that stay local and forwards only those meant for another segment.

The everyday bridge is transparent (IEEE 802.1D): the stations do not know it is there, and it needs no setup. It listens to every frame on every port and builds its MAC table, also called the forwarding database, from the source addresses it sees. Ethernet switches work exactly this way; a bridge is a switch with two or a few ports.

A LEARNING BRIDGE BETWEEN TWO SEGMENTS It records each source address against its port, then filters, forwards or floods. SEGMENT 1: COLLISION DOMAIN 1 SEGMENT 2: COLLISION DOMAIN 2 A 00:aa B 00:bb C 00:cc D 00:dd Bridge port 1 port 2 MAC TABLE A 00:aa 1 B 00:bb 1 C 00:cc 2 D 00:dd 2 Filter A to B: B is on port 1, the arrival port, so the frame is dropped. Forward A to C: C is on port 2, so the frame goes out of port 2 only. Flood A to an unknown address, or a broadcast: sent out of every other port. Without the bridge (a repeater instead), both segments share one collision domain: total throughput is at most one segment's C. With it, local frames stay local: total throughput = 2C / (1 + f), where f is the share of frames that cross. Entries age out after 300 seconds unless refreshed; a station that moves is found again.

How it handles one frame, in order:

  1. Receive: the frame arrives on a port (the bridge hears every frame on both segments).
  2. Learn: it records the frame's source MAC address against the arrival port, with the time.
  3. Look up the destination MAC address in the table, then do one of three things:
    • Filter: the destination is on the same port the frame came in on, so the frame is local: drop it.
    • Forward: the destination is on another port: send the frame out of that port only.
    • Flood: the destination is not in the table yet, or the frame is a broadcast or multicast: send it out of every port except the one it came in on.
  4. Age: an entry that is not refreshed within the ageing time (300 seconds by default) is deleted, so a station that moves is found again.
Worked example: four frames through an empty table

Setting: stations A and B sit on segment 1 (port 1), C and D on segment 2 (port 2); the table starts empty.

FrameLearnsDestinationActionTable after
A to CA on port 1C unknownflood to port 2A-1
C to AC on port 2A on port 1forward to port 1A-1, C-2
B to AB on port 1A on port 1, the arrival portfilter (drop)A-1, C-2, B-1
D to all (broadcast)D on port 2broadcastflood to port 1A-1, C-2, B-1, D-2

After four frames the table is complete: from now on the B to A frame never disturbs segment 2, and the C to A frame never touches more than the one segment it must cross.

Why a bridge raises the throughput of an extended LAN where a repeater does not:

  • A repeater copies every bit to the other side, so the two segments remain one collision domain sharing one channel: their total throughput can never exceed one segment's capacity C, and every station added makes collisions more frequent.
  • A bridge keeps local frames local, so the two segments carry their own traffic at the same time; only frames for the other side cross. If each segment offers a load L and a fraction f of it crosses, each segment carries L+fL≤C, so the total is
    total throughput=2L=2C1+f
    With 100 Mbps segments and a fifth of the traffic crossing (f = 0.2), the bridged LAN carries 166.7 Mbps against the repeater's 100 Mbps; with all traffic local it doubles to 200 Mbps.
  • Collisions stay on their own segment, and because the bridge stores the whole frame before sending it, each side gets its own CSMA/CD distance limit (CSMA/CD): the LAN can grow longer than repeaters allow.
  • Bad frames are dropped (FCS errors, collision fragments) instead of being copied on, and segments of different speeds (10 and 100 Mbps) can be joined.
  • The limits: broadcasts still cross every bridge, and storing frames adds a little delay.

Loops, and the spanning tree. Two bridges between the same pair of LANs give a spare path, but also a loop: one broadcast circulates for ever (a broadcast storm) and the MAC tables flap as frames arrive from both sides. The Spanning Tree Protocol (IEEE 802.1D, from Radia Perlman's 1985 algorithm) fixes it: the bridges exchange BPDU messages, elect a root bridge (the lowest bridge ID: a priority, 32768 by default, then the MAC address) and block the redundant ports so that the active links form a tree. A blocked port opens if an active link fails; Rapid STP (802.1w) does it in seconds.

Type of bridgeHow it worksWhere
Transparent (learning)builds its own table; stations unawareEthernet (802.1D)
Source routingthe sender writes the route of bridges into the frametoken ring (802.5)
Translationalconverts between frame formatsEthernet to token ring or FDDI
Remotea pair joins two LANs over a WAN linktwo offices

To remember it, think of the guard at the gate between two hostel blocks. From the letters people send, he notes which student lives in which block. A letter for someone in the same block never goes through the gate; a letter for the other block does; a letter for a name he has never seen is shown in both blocks; and a notice for everyone goes everywhere.

The book calls the source routing bridge a "routing bridge" and the bridge "a two port switch"; both are the same ideas as above.
Asked on the paper, word for word
  • What is a bridge? How does it work? How can a bridge increase the throughout as compared with a repeater while extending a LAN? Explain with suitable diagrams. 2080 Baishakh Q3 · 8
In the exam Draw two segments, the bridge and its MAC table, and show one frame filtered, one forwarded and one flooded. For the throughput part, argue one collision domain against two and give the 2C/(1+f) result with numbers.

4.3IPv4 addressing

IPv4 addresses: classes, special and private addresses HOT 5/27

82 Ba · 74 Ash · 72 Ch · 70 Asa · 68 Ba1+72+64+4

IPv4 address A 32-bit logical address given to a network interface, written in dotted decimal as four octets (192.168.10.37), and split into a network part, which says which network, and a host part, which says which interface on that network.

The notation: 32 bits are written as four bytes, each 0 to 255, separated by dots. 192.168.10.37 is 11000000.10101000.00001010.00100101 in binary. There are 232=4,294,967,296 addresses in all, and the free pool ran out in 2011: IANA handed out its last blocks in February, and APNIC, the registry that serves Nepal and the rest of Asia-Pacific, reached its final block in April.

Network part and host part work like a telephone number's area code and line number: routers look only at the network part to find the way, and only the last network delivers to the host part.

Logical against physical address. An IP address is a logical address: it is given by the network's administrator (or DHCP), not built into the hardware, and it says where the host sits. A MAC address is a physical address: burned into the network card, it says only which card it is.

PointPhysical (MAC) addressLogical (IP) address
Layerdata link (2)network (3)
Size48 bits, written as 12 hex digits (00:1a:2b:3c:4d:5e)32 bits for IPv4, 128 for IPv6
Assigned bythe manufacturer, in the NICthe administrator or DHCP
Structureflat: maker's code (OUI) and a serial number, no locationhierarchical: network and host
Scopeone link: replaced at every hopend to end: unchanged across routers (unless NAT)
Changes whenthe card is replacedthe host moves to another network
Used byswitches, to deliver inside a LANrouters, to find the path between networks

Why use an IP address when every host already has a MAC address?

  1. A MAC address says who, not where. It is flat, so a router would need a table entry for every device in the world. The network part of an IP address lets one route cover a whole network, and many networks can be summarised as one.
  2. A MAC address works on one link only. Frames are re-addressed at every hop, while the IP address stays the same from source to destination.
  3. Links differ. Ethernet and Wi-Fi have MAC addresses, but serial lines, PPP and cellular links use other schemes or none; IP gives one uniform address over all of them.
  4. Hardware changes. Replace a server's card and its MAC changes, but its IP address (and DNS name) stays; move a laptop to another network and its new IP tells routers where it now is.
  5. Planning. IP addresses can be laid out by department and floor, and subnetted; MAC addresses cannot. ARP joins the two at the last hop (ARP).

To remember it, a citizenship certificate number stays with you wherever you live and tells nobody where to find you; a postal address (district, municipality, ward) tells the postman where to go, and changes when you move. Delivery needs both: the address to reach the house, the name to find the person inside.

Classful addressing (1981 to 1993) cut the address space into five classes, told apart by the first bits of the first octet. The class fixed where the network part ended.

THE CLASSFUL IPV4 ADDRESS FORMATS The first bits fix the class, and the class fixes where the network part ends. Class A 0 network host 0.0.0.0 to 127.255.255.255 /8; 126 networks of 16,777,214 hosts Class B 10 network host 128.0.0.0 to 191.255.255.255 /16; 16,384 networks of 65,534 hosts Class C 110 network host 192.0.0.0 to 223.255.255.255 /24; 2,097,152 networks of 254 hosts Class D 1110 multicast group address 224.0.0.0 to 239.255.255.255 multicast groups; no hosts, no mask Class E 1111 reserved 240.0.0.0 to 255.255.255.255 reserved for experiments The ticks mark the octet borders; usable hosts are 2 to the power of the host bits, minus 2 (the network and broadcast addresses).
ClassFirst bitsAddress rangeDefault maskNetworksHosts per networkUse
A00.0.0.0 to 127.255.255.255255.0.0.0 (/8)27 = 128 (126 usable)224−2 = 16,777,214very large networks
B10128.0.0.0 to 191.255.255.255255.255.0.0 (/16)214 = 16,384216−2 = 65,534medium networks
C110192.0.0.0 to 223.255.255.255255.255.255.0 (/24)221 = 2,097,15228−2 = 254small networks
D1110224.0.0.0 to 239.255.255.255nonemulticast group addresses, no hostsmulticast
E1111240.0.0.0 to 255.255.255.255noneno hostsreserved, experimental

The minus two in every host count: a host part of all 0s names the network itself, and a host part of all 1s is the network's broadcast address, so neither can be given to a host. Finding the class needs only the first octet: 172.20.5.9 starts with 172, between 128 and 191, so it is class B: network 172.20.0.0, host 5.9.

Special addressMeaning
host part all 0s (192.168.1.0)the network itself; never given to a host
host part all 1s (192.168.1.255)directed broadcast to every host on that network
255.255.255.255limited broadcast: this network only, never routed
0.0.0.0"this host", used before a host has an address (a DHCP request); as 0.0.0.0/0, the default route
127.0.0.0/8 (127.0.0.1)loopback: the packet never leaves the host
169.254.0.0/16link-local: picked by a host itself when DHCP does not answer

Private addresses (RFC 1918) may be used inside any organisation without asking anyone, and are never routed on the Internet: 10.0.0.0/8 (one class A, 16,777,216 addresses), 172.16.0.0/12 (172.16 to 172.31, sixteen class B networks, 1,048,576 addresses) and 192.168.0.0/16 (256 class C networks, 65,536 addresses). The hostel Wi-Fi that hands a phone 192.168.1.23 is using one; the router's NAT carries it to the Internet (NAT). ISPs short of public addresses also use 100.64.0.0/10 (RFC 6598) for carrier-grade NAT.

Why classful addressing failed:

  • Waste: a company with 2,000 hosts was too big for a class C (254), so it took a class B and left 63,534 addresses unused.
  • Too few medium blocks: only 16,384 class B networks existed, and they ran out first.
  • Routing tables grew: every class C network needed its own route.
  • Rigid: a block could not be cut to fit, and classes D and E could not be given to hosts at all.

The fixes followed: subnetting (1985) cuts a network up (subnetting), CIDR (1993) drops the classes (CIDR and supernetting), NAT hides many hosts behind one address, and IPv6 gives 128-bit addresses (IPv6 addresses).

The book counts 27 class A networks; two of them, 0.0.0.0/8 and 127.0.0.0/8, are reserved, so 126 can actually be used. Its notation example prints the first octet of 128.11.3.31 with nine bits; it is 10000000.
Asked on the paper, word for word
  • List the range of IPv4 address classes. You have to assign addresses to four departmental LANs with following hosts 14, 55, 10 and 29 addresses respectively from the given IP address block: 202.97.43.0/25. Perform the subnetting and find out subnet mask, network address, broadcast address and usable host IP ranges. 2082 Baishakh Q5 · 1+7
  • What is classful and classless address? Differentiate between link state and distance vector routing protocol. 2074 Ashwin Q4 · 8
  • Explain five instances of how networks are a part of your life today. Through we have MAC address, why do we use IP address to represent the host in networks? Explain your answer. 2072 Chaitra Q2 · 5+3
  • What are the major problems with existing IPv4 network? Explain IPv4 addressing and sub-netting with example. 2070 Ashad Q9 · 4+4
  • What is a logical address? You are given the IP address block 200.10.80.32/25. If there are five departments which require 5, 40, 28, 12, 6 hosts respectively. Design the subnet. 2068 Baishakh Q4 · 2+6
In the exam "List the ranges of the classes" wants the five rows of the table with first bits and default masks. "Classful and classless" wants the classes, their waste, and CIDR's /n blocks (CIDR). "Why IP when MAC exists" wants the flat-against-hierarchical argument with the postal analogy.

Subnetting and VLSM: dividing a block with the least waste TOP 24/27

82 Bh · 82 Ba · 81 Bh · 81 Ba · 80 Bh · 80 Ba · 79 Bh · 78 Bh · 76 Ch · 76 Ash · 75 Ch · 75 Ash · 74 Ch · 74 Ash · 73 Shr · 72 Ch · 71 Ch · 70 Ch · 70 Asa · 69 Ch · 68 Ch · 68 Ba · 67 Asa · 66 Bh81+710

Subnetting Dividing one network into smaller subnetworks by borrowing bits from the host part: each subnet gets its own network address, broadcast address and range of hosts, and a longer subnet mask shows where its network part ends.

The subnet mask is 32 bits with 1s over the network (and subnet) bits and 0s over the host bits, written in dotted decimal (255.255.255.192) or as a prefix length (/26: twenty-six 1s). ANDing any address with its mask clears the host bits and leaves the network address. The book's first example, worked bit by bit:

Address  130.45.32.56   10000010.00101101.00100000.00111000
Mask     255.255.0.0    11111111.11111111.00000000.00000000
AND      130.45.0.0     10000010.00101101.00000000.00000000

Inside an octet: with a mask that ends inside an octet, only that octet needs the binary: 192.168.10.150/26 has mask 255.255.255.192, and 150 AND 192 is 10010110 AND 11000000 = 10000000 = 128, so the address lies in subnet 192.168.10.128/26, whose broadcast is .191 and whose hosts run from .129 to .190.

What subnetting contributes to address management:

  • Less waste: one block is cut to fit the departments, instead of each department taking a whole classful network.
  • Smaller broadcast domains: ARP requests and other broadcasts stay inside one subnet, so traffic falls and performance rises.
  • Security and policy: traffic between subnets passes a router or firewall where access rules apply: the accounts office can be shut off from the student labs.
  • Easier management: an address tells the department or floor, and a fault stays inside one subnet.
  • Hierarchy: the outside world sees one route for the whole block; the internal detail stays inside.
  • Room to grow: each department can be given its own range to manage.

The numbers, for s borrowed subnet bits and h host bits left:

subnets=2susable hosts per subnet=2h−2block size=2h=256−m

Here m is the last octet of the mask that is not 255. Network addresses are the multiples of the block size; each broadcast is one less than the next network address; the usable hosts lie in between.

PrefixMaskBlock sizeUsable hosts
/24255.255.255.0256254
/25255.255.255.128128126
/26255.255.255.1926462
/27255.255.255.2243230
/28255.255.255.2401614
/29255.255.255.24886
/30255.255.255.25242

Above /24 the same table moves one octet left: a /23 is 512 addresses (2 in the third octet), a /22 is 1,024 (4 in the third octet), a /21 is 2,048 and a /20 is 4,096, each with 2 fewer usable hosts.

Fixed-length subnetting (FLSM) gives every subnet the same mask. Four equal subnets of 192.168.10.0/24 need 2 borrowed bits (22=4): /26 subnets at .0, .64, .128 and .192, with 62 hosts each. To split a block into N equal parts, borrow the smallest s with 2s≥N: five departments need 3 bits, giving 8 subnets, of which 3 stay spare.

VLSM (variable length subnet mask) gives each subnet its own mask. It is used when the subnets need different numbers of hosts: departments of unequal size, and point-to-point links between routers that need only two addresses. With one mask for all, the mask must fit the biggest subnet, and every small subnet wastes most of its block: a department of 100 and one of 10 given two /25s waste 26 + 116 = 142 usable addresses, while VLSM's /25 and /28 waste 26 + 4 = 30. VLSM also keeps the plan hierarchical, so the subnets still summarise into one route. It needs a classless routing protocol that carries the mask in its updates (RIPv2, OSPF, EIGRP, IS-IS, BGP; not RIPv1 or IGRP).

The VLSM method, the same for every design question:

  1. Find the block. If the given address has host bits set (202.83.54.91/25), AND it with the mask first: the block is 202.83.54.0/25, addresses .0 to .127.
  2. Size each demand: find the smallest h with 2h−2≥ hosts; its prefix is 32 minus h and its block size 2h. A point-to-point link needs 2 addresses: a /30 (block of 4).
  3. Sort largest first. Allocating the biggest blocks first keeps every subnet starting on a multiple of its own size.
  4. Allocate from the start of the block: each subnet begins where the previous one ended; the links go last.
  5. Write each subnet's row: network address, mask, first usable (network + 1), last usable (broadcast minus 1) and broadcast (next network minus 1).
  6. Count the waste: in each subnet, wasted = (2h−2) minus the hosts needed. The unused range is everything from the end of the last subnet to the end of the block, kept for growth.
  7. Check: the blocks must add up to no more than the given block.
VLSM: ONE BLOCK CUT TO FIT, LARGEST FIRST 192.168.10.0/24 drawn to scale: each subnet starts where the last one ended. Accounts /26 60 hosts in 62 Library /27 25 in 30 unused: .120 to .255 136 addresses left for growth .0 .64 .96 .120 .255 Hostel office /28 10 hosts in 14 Link 1 /30 Link 2 /30 unused from .120 .96 .112 .116 .120 .127 ZOOM: .96 TO .127 Wasted inside the subnets: 2 + 5 + 4 + 0 + 0 = 11 usable addresses.
Worked example: 192.168.10.0/24 for three departments and two links

Given: Accounts 60 hosts, Library 25, Hostel office 10, and two router-to-router links. Sorted: 60 needs 64 (/26), 25 needs 32 (/27), 10 needs 16 (/28), each link 4 (/30).

SubnetHostsBlockNetworkMaskUsable rangeBroadcastWasted
Accounts6064192.168.10.0/26255.255.255.192.1 to .62.632
Library2532192.168.10.64/27255.255.255.224.65 to .94.955
Hostel office1016192.168.10.96/28255.255.255.240.97 to .110.1114
Link R1 to R224192.168.10.112/30255.255.255.252.113 to .114.1150
Link R2 to R324192.168.10.116/30255.255.255.252.117 to .118.1190

Unused range: 192.168.10.120 to 192.168.10.255, 136 addresses left for new subnets. Only 11 usable addresses are wasted inside the five subnets.

Points that cost marks:

  • Hosts need two extra addresses: 30 hosts fit a /27 (30 usable), but 31 need a /26.
  • A block always starts on a multiple of its size: a /27 can start at .0, .32, .64 and so on, never at .40.
  • Point-to-point links take a /30 each. RFC 3021 also allows a /31 for a link, with no network or broadcast address, but the papers expect /30.
  • Subnet zero: the old rule (RFC 950) threw away the first and last subnets (2s−2); since RFC 1878 every subnet is used (2s), as the book does.
  • The router's address: each LAN's default gateway takes one of the usable addresses; a host count is taken to include it unless the question says otherwise.

To remember it, think of seating departments in a 256-seat exam hall in blocks whose size must be a power of two: the biggest department chooses first, so every block starts on a clean row, and the first and last seat of every block stay empty for the invigilators (the network and the broadcast address).

The book's worked problems print some ranges wrongly: the first usable host of 202.83.54.64/27 printed as .64 (it is .65), a range ending at the broadcast .127 instead of .126, a /22's block of 4 without saying it counts in the third octet (it is 1,024 addresses), and a "class C" pool written as 190.16.0.0, which is class B. The method above is right; the corrected designs are in the Numericals panel. Some answers count "wasted" as block size minus hosts, which includes the network and broadcast addresses: say which count is used.
Asked on the paper, word for word
  • Suppose a company XYZ has an IP address of 160.24.96.0/21 and it has 6 departments containing 1024, 750, 254, 500, 151 and 45 users and also include point-point links. List out the CIDR, network address, broadcast address, usable host range and wasted IP address in each subnet. 2082 Bhadra Q5 · 8
  • List the range of IPv4 address classes. You have to assign addresses to four departmental LANs with following hosts 14, 55, 10 and 29 addresses respectively from the given IP address block: 202.97.43.0/25. Perform the subnetting and find out subnet mask, network address, broadcast address and usable host IP ranges. 2082 Baishakh Q5 · 1+7
  • What is super-netting? Perform the subnetting of IPv4 address block 200.74.20.0/24 for five different departments having 4, 54, 120, 12 and 30 hosts. List out the network address, broadcast address, usable host range and wasted IP address in each subnet. 2081 Bhadra Q5 · 1+7
  • In which case VLSM is used while dividing the given block of IP addresses for different subnets and why? Suppose your company has IP address block of 16.16.16.0/21. Divide this IP address for five different departments of the company equally. List out the network address, broadcast address, subnet mask and usable IP address range for each subnet. 2081 Baishakh Q4 · 3+5
  • Suppose a company has IP address of 10.20.30.0/24 and it has 4 LANs containing 4,64,24,18 number of hosts. Also, there are 4 WAN links to connect LAN1 - LAN2, LAN2 - LAN3, LAN3 - LAN4 and LAN1 - LAN3. List out the subnet wasted IP addresses for each LAN. 2080 Bhadra Q4 · 8
  • Suppose a company has IP address of 200.80.40.0/24 with 5 departments containing 29, 5, 16, 43, 14, number of hosts. Also there are point to point links between the departments. List out the subnet mask, network address, broadcast address, usable host IP ranges and no. of wasted IP addresses for each subnet. 2080 Baishakh Q5 · 8
  • An ISP provided you an IP address block of 172.24.96.0/21. Suppose you need to divide this for four different departments A, B, C and D having 750, 200, 500 and 45 hosts respectively with minimum wastage of IP addresses. Also allocate IP addresses for three point-to-point links in the network. Find out the network address, broadcast address, subnet mash and usable host range of IP addresses for each subnet. 2079 Bhadra Q5 · 8
  • Consider IP block of 202.50.0.0/24 and six departments with 125, 59, 27, 14, 4 and 2 hosts respectively. Perform the subnetting so that wastage of IP addresses is minimum and find out the subnet mask, network address, broadcast address, wasted IP addresses and usable host ranges in each network. 2078 Bhadra Q4 · 8
  • Suppose your company has leased the IP address of 222.70.94.0/24 from your ISP. Divide it far five different departments containing 50, 30, 25, 12, 10 no of hosts. There are also two points to point links far interconnection between routers. List out the network address, broadcast address, usable IP address range and subnet mask for each subnet. Also mention the unused range of IP addresses. 2076 Chaitra Q4 · 8
  • Institute of Engineering has six departments having 16, 32, 61, 8, 6 and 24 computers. Use 192.168.1.0/24 to distribute the network. Find the network address, broadcast address, usable IP range and subnet mask in each department. 2076 Ashwin Q4 · 8
  • Suppose you are a private consultant hired by the large company to setup the network for their enterprise and you are given a large number of consecutive. IP address starting at 120.89.96.0/19. Suppose that four departments A, B, C and D request 100, 500, 800 and 400 addresses respectively, how the subnetting can be performed so, that address wastage will be minimum? 2075 Chaitra Q4 · 8
  • Design a network for 5 departments containing 29, 14, 15, 23 and 5 computers. Take a network example IP 202.83.54.91/25. 2075 Ashwin Q5 · 8
  • How can you dedicate 32, 65, 10, 21, 9 public IP address to the departments A, B, C, D and E respectively form the pool of class C IP addresses with minimum loss. Explain. 2074 Chaitra Q5 · 8
  • Suppose you are a private consultant hired by a company to setup the network for their enterprise and you are given a large number of consecutive IP address starting at 120.89.96.0/19. Suppose that four departments A, B, C and D request 100, 500, 800 and 400 addresses respectively, how the subnetting can be performed so that address wastage will be minimum? 2074 Ashwin Q5 · 8
  • You are a private contractor hired by the large company to setup the network for their enterprise and you are given a large number of consecutive IP address starting at 202.70.64.0/19. Suppose that four department A, B, C and D request 100, 500, 800 and 400 addresses respectively, how the subnetting can be performed so, that address wastage will be minimum? 2073 Shrawan Q4 · 8
  • Explain how can you allocate 30, 24, 25 and 20 IP addresses to the four different department of ABC company with minimum wastage. Specify the range of IP addresses, Broadcast Address, Network Address and Subnet mask for each department form the given address pool 202.77.19.0/24. 2072 Chaitra Q4 · 8
  • You are given the following address space 10.10.10.0/24. You have to assign addresses to 4 departments with the following hosts 5, 16, 23 and 27 respectively. Perform the subnetting in such a way that the IP address wastage in each department are minimum. Also find out the subnet mask, network address, broadcast address and unassigned range in each department. 2071 Chaitra Q5 · 10
  • How can you dedicate 10, 12, 8, 14 public IP addresses to department A, B, C and D respectively from the pool of class C with minimum losses of IP? Explain. 2070 Chaitra Q5 · 8
  • What are the major problems with existing IPv4 network? Explain IPv4 addressing and sub-netting with example. 2070 Ashad Q9 · 4+4
  • What is the contribution of sub-netting in IP address management? Show the importance in this case. Banijya bank need to allocate 15 IPs in HR department, 30 in finance department, 24 in customer care unit and 25 in ATM machines. If you have one network of class C range public IP address. Describe how you will manage it. 2069 Chaitra Q4 · 8
  • Suppose there are 4 departments A, B, C and D. The department A has 23 hosts, B has 16, C has 28 and D has 13 hosts. You are given a networks 202.70.64.0/24. Perform the subnetting in such a way that the IP address wastage in each department are minimum and also find out the sunbet mask, network address, broadcast, and unable host range in each department. 2068 Chaitra Q8 · 10
  • What is a logical address? You are given the IP address block 200.10.80.32/25. If there are five departments which require 5, 40, 28, 12, 6 hosts respectively. Design the subnet. 2068 Baishakh Q4 · 2+6
  • If you need to assign IP addresses to all computers of question no. 2 making each department as network. What will be your approach? Explain with IP address ranges you are suggesting. 2067 Ashad Q9 · 8
  • Give the reason why the current world is moving to IPv6 addressing mechanism. Describe the IPv6 address types with its representation format. You are given the IPv4 address block 203.71.53.0/26; assign the IP subnet for the following network. [Figure, as text: Net A: 6 Hosts (LAN on router R1); Net B: 2 Hosts (link R1 to R2); Net C: 12 Hosts (LAN on router R2); Net E: 2 Hosts (link R2 to R3); Net F: 29 Hosts (LAN on router R3). The routers are unlabelled in the print and no Net D is drawn.] 2066 Bhadra Q5a · 2+2+6
In the exam Write the steps once, then one table with these columns: department, hosts, block size, prefix and mask, network address, usable range, broadcast address and wasted addresses, and finish with the unused range. Every paper's design is worked in full in the Numericals panel.

Classless addressing: CIDR and supernetting PIN 2/27

81 Bh · 74 Ash1+78

Supernetting Combining several contiguous networks (typically class C /24s) into one larger block with a shorter prefix, so that a single route covers them all. It is also called route aggregation or summarisation.

CIDR (classless inter-domain routing, RFC 1519 in 1993, now RFC 4632) is what made it possible. It drops the classes: a block is any power-of-two run of addresses written a.b.c.d/n, where n, the prefix length, says how many leading bits are the network part. ISPs could then hand out blocks that fit (a /22 for 1,000 hosts) instead of a whole class B, and the routing table could shrink.

The rules for a CIDR block: it holds 232−n addresses; its first address is divisible by that size (it is aligned); the first address is the network address and the last is the broadcast address.

The rules for supernetting follow from them: the networks must be contiguous, their number must be a power of two, and the first one must sit on a boundary of the combined size.

SUPERNETTING FOUR /24S INTO ONE /22 Contiguous, a power of two in number, and the first one aligned on the combined size. NETWORK THIRD OCTET IN BINARY 192.168.4.0/24 0 0 0 0 0 1 0 0 192.168.5.0/24 0 0 0 0 0 1 0 1 192.168.6.0/24 0 0 0 0 0 1 1 0 192.168.7.0/24 0 0 0 0 0 1 1 1 192.168.4.0/22 mask 255.255.252.0 16 + 6 = 22 common bits 4 x 256 = 1,024 addresses, .4.0 to .7.255 same in all four varies one route replaces four
Worked example: four class C networks into one /22

Given: 192.168.4.0/24, 192.168.5.0/24, 192.168.6.0/24 and 192.168.7.0/24. Their third octets in binary are 00000100, 00000101, 00000110 and 00000111: the first six bits agree and the last two take all four values.

So the common prefix is 16 + 6 = 22 bits: the supernet is 192.168.4.0/22, mask 255.255.252.0, 1,024 addresses from 192.168.4.0 to 192.168.7.255. One route replaces four.

A trap: 192.168.5.0 to 192.168.8.0 are also four contiguous /24s, but 5 is not a multiple of 4, so they do not form one /22; the best that can be done is 192.168.5.0/24, 192.168.6.0/23 and 192.168.8.0/24.

Where it is used: an ISP that gives its customers small blocks out of one large block advertises only the large block to the rest of the Internet. A router then picks among overlapping routes by the longest prefix match: the most specific route that matches wins (the routing table).

PointClassful addressClassless address (CIDR)
Network partfixed by the class: 8, 16 or 24 bitsany length, given by /n
Block sizesonly 16,777,216, 65,536 or 256any power of two
Maskimplied by the first bitsmust be carried with the address
Wastelargesmall: the block fits the need
Routing tableone route per classful networkaggregated routes, longest prefix match
Example192.168.1.0 is class C, so /24192.168.1.0/26 is a block of 64
PointSubnettingSupernetting
Doesdivides one network into smaller onesjoins several networks into one larger block
Masklonger than the original (bits borrowed from the host part)shorter (bits given back from the network part)
Purposeorganise and conserve addresses inside an organisationshrink routing tables between networks
Used bynetwork administratorsISPs and backbone routers

To remember it, a bus company in Kathmandu does not list each of the four houses on a lane as a separate stop: it stops once at the lane's mouth. Supernetting is that one stop for four networks; it works only if the houses are next to each other on the same lane.

Asked on the paper, word for word
  • What is super-netting? Perform the subnetting of IPv4 address block 200.74.20.0/24 for five different departments having 4, 54, 120, 12 and 30 hosts. List out the network address, broadcast address, usable host range and wasted IP address in each subnet. 2081 Bhadra Q5 · 1+7
  • What is classful and classless address? Differentiate between link state and distance vector routing protocol. 2074 Ashwin Q4 · 8
In the exam "What is supernetting" wants the definition, the three conditions and one /24s-into-/22 example with the binary. "Classful and classless" wants the table above.

NAT: many private hosts behind one public address

NAT (network address translation) A router function (RFC 3022) that rewrites the private source address (and port) of every outgoing packet to a public address, records the pair, and reverses the change for the replies, so that a network of private addresses can use the Internet.

Why it exists: private addresses (RFC 1918) are free but never routed on the Internet, and public IPv4 addresses ran out. NAT lets a whole hostel or office share one or a few public addresses.

  • Static NAT: one private address always maps to one public address; used to publish a server.
  • Dynamic NAT: private addresses take public ones from a pool while they need them.
  • PAT, also NAPT or NAT overload: many private hosts share one public address, told apart by the port number. This is what every home and hostel router does.

How PAT works:

  1. Outgoing: a laptop at 192.168.1.10, port 51000, opens a web page; the router replaces the source with its public address 203.0.113.5 and a free port, 62001, and records the pair in its translation table.
  2. Incoming: the reply arrives for 203.0.113.5:62001; the router looks up the table and rewrites the destination back to 192.168.1.10:51000.
  3. Timeout: the entry is removed when the connection ends or stays idle.
Inside (private)        Outside (public)       Remote server
192.168.1.10:51000  -> 203.0.113.5:62001  -> 198.51.100.20:443
192.168.1.11:49200  -> 203.0.113.5:62002  -> 198.51.100.20:443

Gains: saves public addresses; the inside layout stays hidden; the ISP can be changed without renumbering the inside. Costs: it breaks the end-to-end idea (an outside host cannot start a connection to an inside one without port forwarding), complicates peer-to-peer applications, games and VoIP, upsets protocols that carry addresses inside their data (FTP needs help), and rewriting the header defeats IPsec AH. ISPs short of addresses run carrier-grade NAT on 100.64.0.0/10 as well, so a customer may sit behind two NATs.

To remember it, a hostel has one postal address; the hostel office writes the room number on the register when a student posts a letter, and hands each reply to the right room.

Where the private address comes from: the same router usually runs a DHCP server that hands each device its private address, mask, gateway and DNS server (DHCP).

4.4The IP datagram, ARP and ICMP

The IPv4 datagram: the header, fragmentation, and why 65,495 HOT 5/27

76 Ch · 71 Shr · 68 Ba · 67 Asa · 66 Po4+44+1+33+3

IP (Internet Protocol, version 4) The Internet's network layer protocol (RFC 791): a connectionless, best-effort datagram service. Each datagram carries a 20 to 60 byte header with the source and destination addresses and is routed on its own, with no promise that it arrives, arrives once, or arrives in order.

What "best effort" means: IP tries to deliver every datagram but sends no acknowledgements, keeps no connection and retransmits nothing. A datagram can be lost, duplicated, delayed or overtaken by a later one, and only its header is checked for errors. Reliability is added above it by TCP (TCP) where an application needs it; problems are reported by ICMP (ICMP). Posting ordinary letters without registered post is the same service.

What IP does: addresses every datagram (source and destination), forwards it hop by hop by routing tables, fragments it when a link's MTU is too small, limits its lifetime with TTL, and tells the destination which upper-layer protocol gets the data.

THE IPV4 HEADER Rows of 32 bits: five fixed rows (20 bytes), then up to 40 bytes of options. 0 4 8 16 19 31 Version 4 bits IHL 4 bits Type of service 8 bits Total length 16 bits Identification 16 bits Flags 3 bits Fragment offset 13 bits Time to live 8 bits Protocol 8 bits Header checksum 16 bits Source IP address 32 bits Destination IP address 32 bits Options and padding (0 to 40 bytes) rarely used 20 BYTES used in fragmentation TTL and protocol: the hop limit and the upper-layer protocol

The header is drawn in rows of 32 bits, the way the standard draws it: five fixed rows make the minimum 20 bytes, and options can add up to 40 more.

FieldBitsWhat it does
Version44 for IPv4 (6 for IPv6), so the receiver parses the right format
IHL (header length)4header length in 32-bit words: 5 (20 bytes) to 15 (60 bytes)
Type of service8how to treat the packet; today 6 bits of DSCP for quality of service and 2 bits of ECN for congestion signals
Total length16header plus data in bytes: at most 216−1 = 65,535
Identification16one number shared by every fragment of the same datagram
Flags3a reserved 0, DF (do not fragment) and MF (more fragments follow)
Fragment offset13where this fragment's data belongs in the original, in units of 8 bytes
Time to live (TTL)8hop limit: every router subtracts 1 and drops the datagram at 0
Protocol8which protocol the data belongs to: 1 ICMP, 2 IGMP, 6 TCP, 17 UDP, 89 OSPF
Header checksum16error check over the header only; recomputed at every hop because TTL changes
Source address32the sender's IP address
Destination address32the final receiver's IP address
Options and padding0 to 320rarely used (record route, timestamp, source route); padded to a whole 32-bit word

TTL and the protocol field, the two most asked:

  • TTL limits a datagram's lifetime so that one caught in a routing loop dies instead of circling for ever. Each router subtracts 1; a router that brings it to 0 discards the datagram and sends ICMP "time exceeded" to the source. Senders start it at 64 (Linux), 128 (Windows) or 255 (many routers), so no datagram crosses more than 255 routers. Traceroute uses it on purpose (ICMP).
  • Protocol tells the destination which upper-layer module gets the data: it is the network layer's own demultiplexing number, as a port number is the transport layer's. With 6 the data goes to TCP, with 17 to UDP, with 1 to ICMP; IPsec uses 50 (ESP) and 51 (AH).

Fragmentation and reassembly. Every link has an MTU (maximum transmission unit), the largest datagram its frame can carry: 1,500 bytes on Ethernet. A datagram can be up to 65,535 bytes, so a router that must send one onto a link with a smaller MTU splits it into fragments:

  1. Check DF: if the do-not-fragment flag is set, the router drops the datagram and sends ICMP "fragmentation needed" back, with the link's MTU (path MTU discovery uses this to find the largest size that fits).
  2. Split the data into pieces that fit the MTU after the header; every piece but the last must be a multiple of 8 bytes.
  3. Copy the header onto each piece with the same Identification, its own Total length, MF = 1 on every fragment but the last, and Fragment offset = the piece's first byte position divided by 8.
  4. Send the fragments as independent datagrams; a later router may fragment them again.
  5. Reassemble only at the destination host: it gathers the fragments with the same source, destination, protocol and Identification, puts them in order by offset, knows the last one by MF = 0, and runs a reassembly timer. If any fragment is still missing when it expires, the whole datagram is thrown away.
FRAGMENTING A 4,000 BYTE DATAGRAM FOR A 1,500 BYTE MTU Every fragment gets its own header with the same Identification; the offset counts 8-byte units. ORIGINAL DATAGRAM, ID 4321 IP data: 3,980 bytes (total length 4,000) FRAGMENT 1 IP bytes 0 to 1,479 offset 0, MF 1, total 1,500 FRAGMENT 2 IP bytes 1,480 to 2,959 offset 185, MF 1, total 1,500 FRAGMENT 3 IP bytes 2,960 to 3,979 offset 370, MF 0, total 1,040 Offsets: 0, 1,480 / 8 = 185 and 2,960 / 8 = 370. The destination reassembles; MF 0 marks the last fragment.
Worked example: a 4,000 byte datagram onto Ethernet

Given: total length 4,000 bytes (20 of header, 3,980 of data), Identification 4321, next link's MTU 1,500. Each fragment can carry 1,500 minus 20 = 1,480 bytes of data, which is a multiple of 8 (185 times 8).

FragmentData bytesBytes of the original dataOffset fieldMFTotal length
11,4800 to 1,479011,500
21,4801,480 to 2,95918511,500
31,0202,960 to 3,97937001,040

Check: 1,480 + 1,480 + 1,020 = 3,980 bytes of data; the offsets are 0, 1,480 and 2,960 divided by 8. All three carry Identification 4321.

Why fragment at the destination only: fragments may take different paths, so no router in the middle is sure to see them all. IPv6 goes further: routers never fragment, only the source does (the IPv6 header).

Why the largest TCP payload is the odd number 65,495 bytes. A TCP segment travels inside one IP datagram, and the 16-bit Total length field caps a datagram at 65,535 bytes, header included. Take away the smallest IPv4 header (20 bytes) and the smallest TCP header (20 bytes):

65535−20−20=65495 bytes of TCP data

For UDP, whose header is 8 bytes, the same sum gives 65,535 minus 20 minus 8 = 65,507 bytes. On Ethernet the MTU of 1,500 cuts a segment to 1,500 minus 40 = 1,460 bytes of data, which is the usual TCP maximum segment size.

The book says TTL is "the amount of time in seconds" a packet may stay in the network. RFC 791 did define it in seconds, but also made every router subtract at least 1, and no router measures the seconds, so it works as a hop count; IPv6 renamed it hop limit. The book also prints the maximum length as 65,635 bytes on one page; it is 65,535.
Asked on the paper, word for word
  • What is the purpose of Time to live (TTL) and protocol field in header of IPv4 datagram. Which protocol is used in internet layer to provide feedback to hosts/routers about the problems in the network environment? What is ARP and how does it work? 2076 Chaitra Q5 · 4+1+3
  • Write short notes on: (any two) a) ARP b) ICMP c) IP 2071 Shrawan Q5 · 4+4
  • What is a fragmentation and re-assembly? Explain about any intra-AS routing protocol. 2068 Baishakh Q6 · 3+5
  • What are the advantages of IPV6? The maximum payload segment is 65495 byte. Why was such strange number chosen? 2068 Baishakh Q7 · 4+4
  • Explain in detail about IP frame format. 2067 Ashad Q8 · 8
  • Write short notes on (any two): a) UDP and its application b) Network Devices: Hubs, Switches and Routers c) IPv4 Header Structure 2066 Poush Q10 · 3+3
In the exam For "IP frame format" or "IPv4 header", draw the 32-bit grid and give every field its size and job. For fragmentation, list the three fields (Identification, flags, offset) and work one example like the one above. For 65,495, the one-line subtraction and the reason behind each number.

ARP and RARP: from IP address to MAC address and back PIN 4/27

82 Bh · 80 Ba · 76 Ch · 71 Shr2×44+1+34+4

ARP (Address Resolution Protocol) The protocol (RFC 826) that finds the MAC address belonging to a known IPv4 address on the same link: the asker broadcasts a request, the owner of the address unicasts a reply, and the answer is kept in a cache.

Why it is needed: a frame can only be delivered to a MAC address, but software knows only the IP address of the next hop. If the destination is on the sender's own subnet, the sender asks for the destination's MAC; if not, it asks for the MAC of its default gateway (the router), never for the distant host.

ARP: BROADCAST REQUEST, UNICAST REPLY Laptop A knows the printer's IP address and needs its MAC address. Laptop A 192.168.1.10 Host C 192.168.1.30 Printer B 192.168.1.20 1 ARP request, broadcast to ff:ff:ff:ff:ff:ff "Who has 192.168.1.20? Tell 192.168.1.10" with the sender's MAC, 00:1a:2b:3c:4d:5e not my address: dropped 2 ARP reply, unicast to A "192.168.1.20 is at 3c:52:82:10:aa:07" 3 A caches 192.168.1.20 = 3c:52:82:10:aa:07 4 the IP packet, in a frame to 3c:52:82:10:aa:07

How it works, for a laptop at 192.168.1.10 printing to a printer at 192.168.1.20 on the same LAN:

  1. Check the cache: the laptop looks for 192.168.1.20 in its ARP cache; there is no entry, so the IP packet waits.
  2. Broadcast a request: it sends an ARP request in an Ethernet frame to the broadcast address ff:ff:ff:ff:ff:ff (EtherType 0x0806): "who has 192.168.1.20? Tell 192.168.1.10", carrying its own IP and MAC address.
  3. Only the owner answers: every host on the LAN receives the request; the others drop it, and the printer, which owns 192.168.1.20, keeps the laptop's mapping for later.
  4. Unicast reply: the printer sends an ARP reply straight to the laptop's MAC: "192.168.1.20 is at 3c:52:82:10:aa:07".
  5. Cache and send: the laptop stores the pair, with a timeout, and sends the waiting packet in a frame addressed to the printer's MAC. Later packets skip the request altogether.
ARP packet fieldSizeFor IPv4 over Ethernet
Hardware type2 bytes1 (Ethernet)
Protocol type2 bytes0x0800 (IPv4)
Hardware and protocol address lengths1 byte each6 and 4
Operation2 bytes1 request, 2 reply
Sender MAC, sender IP6 + 4 bytesthe asker's addresses
Target MAC, target IP6 + 4 bytesMAC all zeros in a request; the IP being asked about

The whole ARP packet is 28 bytes, carried straight in an Ethernet frame, not inside IP. The command arp -a shows the cache on Windows and Linux.

  • Gratuitous ARP: a host announces its own mapping (when it boots or changes its card), to refresh others' caches and to detect a duplicate address.
  • Proxy ARP: a router answers on behalf of hosts on another network.
  • ARP spoofing: ARP has no authentication, so an attacker on the LAN can answer with its own MAC and pull traffic through itself; switches defend with dynamic ARP inspection, and critical hosts can use static entries.

RARP (Reverse ARP, RFC 903) does the opposite: a diskless workstation that knows only its own MAC broadcasts "what is my IP address?", and a RARP server on the same LAN replies. It needs a server on every network (its broadcast cannot cross a router) and returns only an IP address (no mask, no gateway), so BOOTP and then DHCP replaced it (DHCP).

NDP, ARP's IPv6 replacement. IPv6 has no ARP and no broadcast. Its Neighbour Discovery Protocol (RFC 4861) does the same job with ICMPv6 messages, and several more jobs besides:

PointARP (IPv4)NDP (IPv6)
Defined inRFC 826, 1982RFC 4861, 2007
Carried inits own Ethernet frame type, 0x0806ICMPv6 messages inside IPv6
Request sent tobroadcast: every host on the LANsolicited-node multicast: only hosts whose address ends in the same 24 bits
Messagesrequest, replyneighbour solicitation and advertisement (135, 136), router solicitation and advertisement (133, 134), redirect (137)
Jobsaddress resolution onlyaddress resolution, finding routers and prefixes, autoconfiguration (SLAAC), duplicate address detection, checking a neighbour is still reachable, redirect
Securitynone: spoofing is easycan be protected with SEND (RFC 3971)

To remember it, a teacher who knows only roll numbers calls out in class, "who is roll 20?" (the broadcast); only roll 20 stands up (the reply), and the teacher remembers the face (the cache). RARP is a student asking the class, "what is my own roll number?"

Asked on the paper, word for word
  • Write short notes on: (Any Two) a) ARP and NDP b) AH and ESP c) VPN d) vLAN 2082 Bhadra Q10 · 2×4
  • Write short notes on: (Any Two) a) VLAN b) ARP c) IPSec 2080 Baishakh Q10 · 2×4
  • What is the purpose of Time to live (TTL) and protocol field in header of IPv4 datagram. Which protocol is used in internet layer to provide feedback to hosts/routers about the problems in the network environment? What is ARP and how does it work? 2076 Chaitra Q5 · 4+1+3
  • Write short notes on: (any two) a) ARP b) ICMP c) IP 2071 Shrawan Q5 · 4+4
In the exam For "ARP and how it works", draw the broadcast request and the unicast reply and give the five steps. For "ARP and NDP", add the table.

ICMP: the network layer's error reports and queries HOT 5/27

81 Ba · 76 Ch · 71 Shr · 66 Po · 66 Bh84+1+33+3

ICMP (Internet Control Message Protocol) The companion protocol of IP (RFC 792) that reports errors in delivering datagrams back to their source and answers diagnostic queries such as echo (ping). Its messages ride inside IP datagrams (protocol number 1); it reports problems but does not correct them.

Why it exists: IP is best effort and has no way of its own to say what went wrong, so without ICMP a datagram that could not be delivered would simply vanish. ICMP is the protocol of the internet layer that gives hosts and routers feedback about problems in the network.

THE ICMP MESSAGE, INSIDE IP ICMP rides in an IP datagram with protocol = 1; it reports problems, it does not fix them. Ethernet header IP header, protocol = 1 ICMP message FCS Type 8 bits Code 8 bits Checksum 16 bits Rest of header: depends on the type echo: identifier and sequence number Data errors: the offending IP header plus 8 bytes of its data 0 8 16 31 Type: which message Code: the reason in it Examples: type 8 code 0 echo request; type 3 code 3 port unreachable; type 11 code 0 TTL exceeded.

The message format: every ICMP message starts with a type (8 bits: which message), a code (8 bits: the reason within that type) and a checksum (16 bits, over the whole ICMP message), then 32 bits whose use depends on the type (an identifier and a sequence number in an echo). An error message then carries the IP header and the first 8 bytes of data of the datagram that caused it: enough for the source to see which connection failed, since those 8 bytes hold the TCP or UDP port numbers.

Error-reporting messages, sent back to the source of a datagram that had a problem:

TypeMessageSent whenCodes
3Destination unreachablea router cannot reach the network or host, or the host has no process on that port0 network, 1 host, 2 protocol, 3 port, 4 fragmentation needed but DF set, 13 blocked by policy
4Source quencha congested router asked the source to slow down (withdrawn by RFC 6633 in 2012)0
11Time exceededTTL reached 0 in a router, or the reassembly timer ran out0 TTL, 1 reassembly
12Parameter problema header field is wrong or a needed option is missinga pointer to the bad byte
5Redirecta router sees that a host on the same network should use another routerfor a network or a host

Query (informational) messages come in request and reply pairs:

TypesPairUsed for
8 and 0Echo request and echo replyping: is the host alive, and the round-trip time
13 and 14Timestamp request and replyround-trip time and the difference between two clocks
17 and 18Address mask request and replya host asking its subnet mask (now done by DHCP)
10 and 9Router solicitation and advertisementa host finding the routers on its network

Rules that stop ICMP making things worse: no error message is sent about an ICMP error message, about any fragment but the first, about a datagram sent to a broadcast or multicast address, or about one whose source is a special address such as 0.0.0.0 or 127.0.0.1. Without them, one fault could set off a storm of messages.

Its importance and uses in TCP/IP:

  • Error feedback to the transport layer: an unreachable message tells TCP or UDP why its data is not getting through, so the application can report "port unreachable" (nothing is listening) or "host unreachable" instead of waiting blindly; RFC 1122 makes TCP abort a connection on "protocol unreachable" or "port unreachable".
  • ping: echo request and reply test whether a host is reachable and measure the round-trip time.
  • traceroute: probes are sent with TTL 1, 2, 3 and so on; each router where the TTL runs out answers "time exceeded", which reveals the path hop by hop. Windows' tracert uses echo requests; Unix traceroute uses UDP probes and stops at the destination's "port unreachable".
  • Path MTU discovery: TCP sets DF, and "fragmentation needed" messages tell it the largest datagram the path can carry, so it never needs fragmenting.
  • Better routes: redirect corrects a host's choice of first router; router solicitation and advertisement find routers.
  • Network management: monitoring tools ping every device to see what is up.
Worked example: tracing the path to a server
C:\> tracert -d 203.0.113.10
  1     1 ms     1 ms     1 ms  192.168.1.1
  2     5 ms     6 ms     5 ms  198.51.100.1
  3    17 ms    18 ms    17 ms  198.51.100.77
  4    20 ms    21 ms    20 ms  203.0.113.10

Reading it: the first probes leave with TTL 1, which dies at the home router; it answers "time exceeded" and becomes line 1. TTL 2 dies at the ISP's router (line 2), TTL 3 one router further. The fourth set reaches the server itself, which answers with an echo reply, and the trace stops. Each line shows three probes' round-trip times.

Security: firewalls often block echo requests to hide hosts, but blocking all ICMP breaks path MTU discovery and leaves connections that hang on large packets; the safe rule is to let the error messages through.

To remember it, ICMP is the returned-letter slip of the post office: it does not deliver anything itself, it tells the sender why the letter came back ("no such address", "took too long", "wrong format").

In IPv6, ICMPv6 (RFC 4443) does all of this and also carries neighbour discovery and multicast group management (NDP).
Asked on the paper, word for word
  • What is ICMP? Explain the importance and uses of ICMP in TCP/IP protocol suit. 2081 Baishakh Q5 · 8
  • What is the purpose of Time to live (TTL) and protocol field in header of IPv4 datagram. Which protocol is used in internet layer to provide feedback to hosts/routers about the problems in the network environment? What is ARP and how does it work? 2076 Chaitra Q5 · 4+1+3
  • Write short notes on: (any two) a) ARP b) ICMP c) IP 2071 Shrawan Q5 · 4+4
  • Briefly describe ICMP error and informational message types in IPv4 network infrastructure. 2066 Poush Q8 · 8
  • Write short notes on (any two) i) TCP Sliding Window Protocol ii) Secrete Key Algorithm: DES iii) ISDN Signaling and ATM AAL iv) ICMP Message Types 2066 Bhadra Q5b · 3+3
In the exam "Error and informational messages" wants both tables with their type numbers. "Importance and uses" wants the format, why IP needs it, and ping, traceroute and path MTU discovery explained.

4.5Routing

Routing: what it is, what a good algorithm needs, static against dynamic TOP 13/27

82 Ba · 81 Bh · 79 Bh · 78 Bh · 76 Ash · 75 Ch · 75 Ash · 74 Ch · 72 Ch · 71 Shr · 70 Asa · 67 Asa · 66 Bh2+63+54+4

Routing The process by which routers find the paths through an internetwork and build the tables that forwarding uses. The routing algorithm is the part of the network layer software that decides which output line an incoming packet should be sent on.

Routing against forwarding. A router runs two jobs. Forwarding handles each packet as it arrives: look up the destination in the table, send the packet out of the right interface, in microseconds. Routing fills in and updates that table: it runs the routing algorithm, talks to other routers, and reacts to failures, over seconds or minutes. Forwarding is the driver following the signs; routing is the department that puts the signs up.

Why routing is essential:

  • Delivery beyond one network: a packet for another network can only arrive if every router on the way knows the next hop; without routing tables the Internet is a set of islands.
  • Many possible paths: networks are meshes, and routing picks the best path by the chosen metric (hops, delay, bandwidth, cost).
  • Survival: when a link or router fails, dynamic routing finds another path without anyone touching the routers.
  • Efficiency: good routes spread the load, cut delay and avoid congested links.
  • Scale and policy: routes to whole networks, aggregated, keep tables small; between organisations, routing carries their policies (who may carry whose traffic).

The properties (goals) of a good routing algorithm, which Tanenbaum lists and the papers ask as "criteria":

  • Correctness: it must deliver every packet to the right destination.
  • Simplicity: little computation and few messages, so routers stay fast.
  • Robustness: it must keep working through router and link failures and topology and load changes, for years, without rebooting the whole network.
  • Stability: it must settle on fixed routes quickly (converge) and not swing between paths or form loops.
  • Fairness: every source-destination pair gets reasonable service, not only the nearby ones.
  • Optimality (efficiency): it minimises the mean delay or maximises the total throughput. Fairness and optimality pull apart: starving long flows can raise throughput, so a balance is struck.

Adaptive and non-adaptive routing are the two routing techniques:

PointNon-adaptive (static)Adaptive (dynamic)
Routes chosenin advance, offline, and entered by the administratorcontinuously by the routers, from the current topology and load
On a failurenothing changes until someone edits the tablereroutes on its own
Methodsstatic and default routes; floodingdistance vector and link state: RIP, OSPF, EIGRP, BGP
Overheadno routing traffic, little CPU and memoryupdates use bandwidth, CPU and memory
Securityhigher: nothing is advertisedlower: routing messages can be forged unless authenticated
Suitssmall, stable networks; a branch with one link outlarge networks with many paths

Adaptive algorithms differ in where they get their information (only locally, from their neighbours, or from every router), when they change routes (on a timer, or when the topology or load changes) and what they measure (distance, hops, delay). A static route is still the right answer where there is no choice: the single link from a campus to its ISP is a static default route.

Routed and routing protocols are easy to confuse:

PointRouted protocolRouting protocol
What it isa network protocol whose packets carry user data and get routeda protocol routers use to swap route information and build their tables
It providesaddresses for hosts and a packet formatthe paths: which networks exist and how far
Used byhosts and routersrouters only
ExamplesIPv4, IPv6 (once IPX and AppleTalk)RIP, OSPF, EIGRP, IS-IS, BGP

In short, the routing protocol prepares the roads; the routed protocol is the traffic on them. RIP messages themselves travel inside routed IP datagrams.

The optimality principle. If router J is on the optimal path from router I to router K, then the optimal path from J to K falls along the same route. Call the part from I to J r1 and the rest r2: if a better route than r2 existed from J to K, joining it to r1 would give a better route from I to K, which contradicts r1r2 being optimal.

THE OPTIMALITY PRINCIPLE AND THE SINK TREE Part of an optimal path is itself optimal, so the best routes to one destination form a tree. I J K r1 r2 shorter r2'? If a shorter r2' existed from J to K, then r1 + r2' would beat the optimal r1 + r2: impossible. B D E A C F sink tree for destination B

Its consequence is the sink tree: the optimal routes from every router to one destination together form a tree rooted at that destination. A tree has no loops, so every packet arrives in a finite number of hops, and the job of a routing algorithm is to find and use the sink trees of all destinations. If the shortest bus route from Kalanki to Pulchowk passes Balkhu, the shortest route from Balkhu to Pulchowk is the rest of that same route.

Autonomous system (AS): a group of networks and routers under one administration that shows the Internet one routing policy, identified by an AS number (16 bits, 1 to 65,535 at first; 32 bits since 2007, RFC 4893, now RFC 6793). An ISP, a university or a large bank can each be one. Inside an AS, the administration picks its own interior gateway protocol (IGP: RIP, OSPF, EIGRP, IS-IS); between ASes, all use the one exterior gateway protocol, BGP (routing protocols). A stub AS has one link out, a multihomed AS several providers, and a transit AS (an ISP) carries other ASes' traffic. Nepal's larger ISPs each run their own AS and exchange local traffic at the Nepal Internet Exchange (NPIX) over BGP.

To remember it, a microbus route is static routing: the same stops every day even if a road is blocked. A traffic police officer at Kalanki who waves cars onto the ring road when the main road jams is adaptive routing.

Asked on the paper, word for word
  • Define routed and routing protocol. Explain RIP routing operation with is timer details. 2082 Baishakh Q4 · 2+6
  • What is adaptive and non-adaptive routing? List the properties of link state routing and mention the method that how Designated Router (DR) is elected in OSPF routing. 2081 Bhadra Q4 · 2+2+4
  • Why do we prefer a switch as networking device instead of Hub for LAN connection? Give reasons. Discuss the characteristics of a good routing algorithm. 2079 Bhadra Q4 · 4+4
  • Define routing algorithm. List out the properties/goals of routing algorithm. What is link state routing algorithm? Show how routing tables is populated in LSR with example. 2078 Bhadra Q5 · 3+5
  • What is routing? Differentiate between distance vector and link state routing algorithms. 2076 Ashwin Q5 · 2+6
  • What do you mean by autonomous system? Explain how routing loops are prevented in Distance Vector Routing with examples. 2075 Chaitra Q5 · 2+6
  • Why routing is essential in computer networking? Compare working of distance vector routing algorithm with link state routing algorithm. 2075 Ashwin Q4 · 3+5
  • Mention the criteria for good routing. Explain RIP, OSPF, BGP, IGRP and EIGRP. 2074 Chaitra Q4 · 2+6
  • What is routed and routing protocol? Give examples. Explain Token Bucket algorithm. 2072 Chaitra Q5 · 4+4
  • What is routing? Differentiate between link state routing and distance vector routing. 2071 Shrawan Q4 · 2+6
  • Differentiate between adaptive and non-adaptive routing. Explain shortest path finding algorithm in link state routing. 2070 Ashad Q7 · 3+5
  • Why routing is essential in computer networking? Compare working of distance vector routing algorithm with link state routing algorithm. 2067 Ashad Q7 · 2+6
  • What is unicast and multicast routing? Describe the concept of optimality principle. Describe how the routers in its link state routing come into fully adjacency state. 2066 Bhadra Q4a · 2+6
In the exam "What is routing" and "why is it essential" take a definition and four reasons. "Properties" take the six with a line each. "Adaptive and non-adaptive" and "routed and routing protocols" take the two tables. The optimality principle takes the statement, the r1 and r2 argument and the sink tree.

The routing table, and forwarding with classful addresses

Routing table The table a router consults for every packet: for each destination network, its mask, the next hop to send to, the outgoing interface, a metric, and how the route was learned.
  • Destination and mask: the network the route leads to. Routes name networks, not hosts, which is what keeps tables small (next-hop and network-specific routing).
  • Next hop: the IP address of the neighbouring router to hand the packet to; empty for a directly connected network, where the packet goes straight to the host.
  • Interface: the port to send it out of.
  • Metric: the route's cost (hops for RIP, cost for OSPF), to choose between routes.
  • Source: connected, static (typed in by an administrator) or learned by a routing protocol; dynamic entries time out if not refreshed.
  • Default route (0.0.0.0 with mask 0.0.0.0): the route of last resort, used when nothing else matches; a stub network often needs nothing else.

Forwarding with classful addresses. In a classful network the mask is implied by the address, so a router finds the destination's class from the first octet, applies the default mask, and looks the network up:

Router R1
Destination    Mask             Next hop       Interface   Source
10.0.0.0       255.0.0.0        (direct)       Gi0/0       connected
172.16.0.0     255.255.0.0      (direct)       Gi0/1       connected
192.168.1.0    255.255.255.0    (direct)       Se0/0/0     connected
192.168.2.0    255.255.255.0    192.168.1.2    Se0/0/0     RIP, 1 hop
0.0.0.0        0.0.0.0          192.168.1.2    Se0/0/0     static default
Worked example: three packets through R1
  1. To 172.16.40.9: 172 lies in 128 to 191, so class B, mask 255.255.0.0, network 172.16.0.0: directly connected on Gi0/1, so R1 delivers it to the host (after ARP for 172.16.40.9).
  2. To 192.168.2.77: class C, network 192.168.2.0: send to next hop 192.168.1.2 through Se0/0/0.
  3. To 203.0.113.50: class C, network 203.0.113.0: no entry, so the default route sends it to 192.168.1.2.

Classless tables carry a mask with every route, and routes can overlap. The router then takes the longest prefix match: with routes to 10.0.0.0/8 via A, 10.1.0.0/16 via B and 10.1.2.0/24 via C, a packet to 10.1.2.5 goes to C, one to 10.1.9.9 to B, and one to 10.200.0.1 to A. The default route, /0, matches everything and always loses to anything longer.

A static route by hand, in Cisco's syntax: ip route 192.168.2.0 255.255.255.0 192.168.1.2; a default route: ip route 0.0.0.0 0.0.0.0 192.168.1.2. On a computer, route print (Windows) or ip route (Linux) shows the host's own small table: its subnet, and a default route to the gateway.

To remember it, the routing table is the board at a bus park that says which counter sells tickets for which district; "everything else, counter 1" is the default route.

4.6Routing algorithms

Dijkstra's shortest path algorithm, worked on a graph PIN 1/27

70 Asa3+5

Dijkstra's algorithm The shortest path algorithm (Edsger Dijkstra, 1959) that finds the least-cost path from one node to every other node of a graph with non-negative link costs, by making one node permanent at a time, always the nearest one not yet fixed.

Where routing uses it: in link state routing every router holds the whole graph (routers as nodes, links as edges weighted by cost) and runs Dijkstra with itself as the source; the result, its shortest path tree, gives the first hop to every destination (link state routing). OSPF and IS-IS call it the SPF (shortest path first) calculation.

The steps, with a label (distance, previous node) on every node:

  1. Start: the source gets the label (0, none) and is made permanent; every other node is (infinity, none).
  2. Relax: for each neighbour of the node just made permanent, add the link's cost to that node's distance; if the sum is smaller than the neighbour's label, relabel it (new distance, via this node). These labels are tentative.
  3. Fix the nearest: among all tentative nodes, make the one with the smallest distance permanent; it is the new working node.
  4. Repeat steps 2 and 3 until the destination (or every node) is permanent.
  5. Read the path backwards from the destination through the "via" fields.
DIJKSTRA ON THE BOOK'S FIGURE 4.12 GRAPH Final labels (distance, previous node) from A; the shortest path A to D in colour. 2 6 7 2 2 1 3 2 4 3 2 A B C E F D G H A (0) B (2, A) C (9, B) E (4, B) F (6, E) G (5, E) H (8, F) D (10, H) A, B, E, F, H, D: 2 + 2 + 2 + 2 + 2 = 10
Worked example: the shortest path from A to D (the book's Figure 4.12)

Given the graph above: A-B 2, A-G 6, B-C 7, B-E 2, E-F 2, E-G 1, F-C 3, F-H 2, G-H 4, C-D 3, H-D 2. A packet goes from A to D.

StepMade permanentTentative labels after the step
1A (0)B (2, A), G (6, A)
2B (2, A)G (6, A), E (4, B), C (9, B)
3E (4, B)G (5, E), F (6, E), C (9, B)
4G (5, E)F (6, E), C (9, B), H (9, G)
5F (6, E)C (9, B), H (8, F)
6H (8, F)C (9, B), D (10, H)
7C (9, B)D (10, H)
8D (10, H)none left

Reading back from D: D came via H, H via F, F via E, E via B, B via A. The shortest path is A, B, E, F, H, D, with cost 2 + 2 + 2 + 2 + 2 = 10.

Two details: in step 3, G's label falls from (6, A) to (5, E), because A-B-E-G costs 5 against the direct link's 6; in step 5, F offers C at 6 + 3 = 9, which ties B's offer, so the label stays (9, B). C is made permanent after H, but too late to help: its route to D costs 9 + 3 = 12.

Cost of the algorithm: with N nodes, the simple version does about N2 steps; with a priority queue it does about ElogN for E links, which is why routers can run it in milliseconds. It needs costs that are not negative. Distance vector routing uses the Bellman-Ford method instead, which works out the same shortest paths piece by piece across the routers (distance vector).

To remember it, think of a fire spreading from A through dry grass along the links, at one metre a second for every unit of cost: the order in which the nodes catch fire is the order Dijkstra makes them permanent, and each node's fire came along its shortest path.

The book's figure (Figure 4.12, labels B (2, A), E (4, B), G (5, E), F (6, E), H (8, F), C (9, B)) is right; it states the path ABEFHD without its cost, which is 10.
Asked on the paper, word for word
  • Differentiate between adaptive and non-adaptive routing. Explain shortest path finding algorithm in link state routing. 2070 Ashad Q7 · 3+5
In the exam Draw the graph, give the steps, then a table of permanent and tentative labels, one row per step, and read the path back. Always state the final cost.

Flooding: send every packet out of every line

Flooding A non-adaptive routing algorithm in which a router sends every incoming packet out on every line except the one it arrived on.

Its problem is duplicates: on any network with loops, each copy is copied again at the next router, and the number of packets grows without end. Three ways damp it:

  • Hop counter: the packet carries a counter, set at the source to the length of the path (or the network's diameter if that is unknown); each router subtracts 1 and drops the packet at 0. The book's example floods with a hop count of 3: first, second and third hops.
  • Sequence numbers: the source numbers each packet; every router keeps, per source, the numbers it has already seen and drops repeats. This is how link state packets are flooded (link state).
  • Selective flooding: a router sends the packet only on the lines that lead roughly the right way.

Why use it at all:

  • Delivery is all but certain: if any path exists, a copy finds it, so flooding suits networks that must survive heavy damage (the military idea behind the early ARPANET).
  • It always finds the shortest path, since it tries every path at once; the first copy to arrive took it. That makes flooding a benchmark for other algorithms.
  • It needs no knowledge of the network, so it is how information is spread before anyone knows the topology: link state packets and broadcasts.

Its cost is the bandwidth spent on copies, so it is never used for ordinary traffic.

To remember it, it is a rumour in a village: each person tells everyone they meet except the one who told them, and to stop it going round for ever each person repeats it only once.

Distance vector routing, count to infinity, and loop prevention TOP 10/27

80 Ba · 76 Ash · 75 Ch · 75 Ash · 74 Ash · 73 Shr · 72 Ka · 71 Shr · 68 Ch · 67 Asa2+62+2+42×5

Distance vector routing An adaptive routing algorithm in which each router keeps a table (a vector) of the best known distance to every destination and the line to use, and periodically shares that whole table with its neighbours only, updating its own table from theirs by the Bellman-Ford rule.

Three keys describe it: each router shares knowledge about the whole network; it shares it only with its neighbours; and it shares it at regular intervals (RIP every 30 seconds). It is sometimes called routing by rumour: a router believes what its neighbours say about distant networks.

The update rule: router x's distance to destination y is the smallest, over its neighbours v, of the cost of reaching v plus v's own distance to y:

Dx(y)=minv{c(x,v)+Dv(y)}

In practice: when a neighbour's table arrives, add the cost of the link to that neighbour to every entry; for each destination, keep the new route if it is shorter than the current one, or if it comes from the neighbour already used as next hop (that neighbour's news about its own route is always accepted, good or bad).

Worked example: router A's first update (the book's Figures 4.14 and 4.15)

Given: six routers join seven networks. A is on networks 14, 78 and 23; its neighbours are B (on 14 and 55), E (on 08 and 23) and F (on 78 and 92). Each router starts knowing only its own networks, at distance 1. A receives the three neighbours' tables and adds one hop to each entry:

NetworkA's old tableFrom B, +1From E, +1From F, +1A's new table
08nonenone2, Enone2, via E
141, direct2, Bnonenone1, direct
231, directnone2, Enone1, direct
55none2, Bnonenone2, via B
781, directnonenone2, F1, direct
92nonenonenone2, F2, via F

Network 66 is not in A's table yet, because no neighbour knows it; it arrives in the next round, at 3 hops (through B or through E). A few rounds later no table changes any more: the network has converged.

Count to infinity. Good news spreads fast, bad news slowly. Take three routers in a line, A, B and C, with network N attached to C: C reaches N at 1 hop, B at 2 (via C), A at 3 (via B). Now C's link to N fails:

COUNT TO INFINITY, AND THE SPLIT HORIZON FIX Bad news travels slowly: B and C count up together until they reach 16. A B C network N link fails N: 3 via B N: 2 via C N: 1, direct BEFORE C: 1, direct B: 2 via C LINK FAILS C: 16, lost B: 2 via C C HEARS B C: 3 via B B: 2 via C B HEARS C C: 3 via B B: 4 via C C HEARS B C: 5 via B B: 4 via C B HEARS C C: 5 via B B: 6 via C AND SO ON C: 7, 9 ... B: 8, 10 ... AT LAST C: 16 B: 16 Split horizon: B learned N from C, so it never advertises N back to C. C keeps 16, tells B, and the loop never starts. Poison reverse: B does advertise N to C, but with metric 16. Hold-down: a lost route ignores worse news for 180 s.
  • C loses N, but before it can tell anyone, B's regular update arrives saying "N, 2 hops". C believes it and records N at 3 hops via B, not knowing that B's route runs through C itself.
  • B hears C's 3 and, since C is its next hop for N, accepts it: 4 hops. C then hears 4 and goes to 5, B to 6, and so on: the two count upward while packets for N bounce between them, a routing loop.
  • It ends only at "infinity": RIP calls 16 hops unreachable, so after about 14 exchanges both routers finally mark N as gone.

How routing loops are prevented, each with the same example:

  • Maximum hop count: defining infinity as a small number (16 in RIP) makes the counting stop, at the price of limiting the network to 15 hops.
  • Split horizon: a router never advertises a route back out of the interface it learned it from. B learned N from C, so B never tells C about N; when C loses N, there is no false news for it to believe.
  • Split horizon with poison reverse: B does advertise N back to C, but with metric 16 ("do not reach N through me"). It kills the loop at once, at the cost of larger updates.
  • Route poisoning: C advertises N with metric 16 the moment it fails, instead of just deleting it, so the bad news travels as fast as good news.
  • Triggered updates: a router sends an update as soon as a route changes, without waiting for the 30 second timer.
  • Hold-down timers: once a route goes bad, the router ignores any news of a worse route to it for a while (RIP: 180 seconds), so stale information still circulating cannot bring it back; only better news, or the timer's end, is accepted.

Split horizon is not enough everywhere: in a loop of three or more routers, a router can hear the false route from a neighbour it did not learn it from (Tanenbaum's example). Hold-down timers and triggered updates cover that case, and link state routing avoids the problem altogether.

Strengths and weaknesses: it is simple and needs little memory or CPU, but it converges slowly, can loop while converging, usually counts hops whatever the link speed, and sends whole tables even when nothing has changed. The ARPANET used it until 1979, then switched to link state; RIP and IGRP are distance vector protocols, and EIGRP is an advanced one (RIP, routing protocols).

To remember it, think of villagers giving directions by rumour: each tells only the next village how far it thinks the bazaar is. When the bridge to the bazaar falls, the village beside it says "closed", but the next village still repeats "two hours from here", and the rumour of a road that no longer exists goes round the hills for days.

Asked on the paper, word for word
  • What is unicast and multicast? Compare distance vector routing protocol and link state routing protocol with examples. 2080 Baishakh Q4 · 4+4
  • What is routing? Differentiate between distance vector and link state routing algorithms. 2076 Ashwin Q5 · 2+6
  • What do you mean by autonomous system? Explain how routing loops are prevented in Distance Vector Routing with examples. 2075 Chaitra Q5 · 2+6
  • Why routing is essential in computer networking? Compare working of distance vector routing algorithm with link state routing algorithm. 2075 Ashwin Q4 · 3+5
  • What is classful and classless address? Differentiate between link state and distance vector routing protocol. 2074 Ashwin Q4 · 8
  • Discuss about the network congestion? Explain how different network parameters effect the congestion. Compare operation of link state routing with the distance vector routing. 2073 Shrawan Q5 · 2+2+4
  • Network layer is one of the key layers in OSI reference model, why? Differentiate between distance vector routing and static link routing. 2072 Kartik Q5 · 2+6
  • What is routing? Differentiate between link state routing and distance vector routing. 2071 Shrawan Q4 · 2+6
  • Differentiate: a) Distance vector and link state routing algorithm b) Circuit switching and packet switching 2068 Chaitra Q5 · 2×5
  • Why routing is essential in computer networking? Compare working of distance vector routing algorithm with link state routing algorithm. 2067 Ashad Q7 · 2+6
In the exam For "how routing loops are prevented", draw the three-router line, show the count up to 16, then give split horizon, poison reverse, hold-down, triggered updates and the maximum hop count, each with the example. The comparison with link state is on the link state card.

Link state routing: properties, five steps, and distance vector compared TOP 11/27

81 Bh · 80 Ba · 78 Bh · 76 Ash · 75 Ash · 74 Ash · 73 Shr · 72 Ka · 71 Shr · 68 Ch · 67 Asa2+62+2+43+5

Link state routing An adaptive routing algorithm in which each router floods the state of its own links (its neighbours and their costs) to every router, so that every router holds a map of the whole network and computes its own shortest paths with Dijkstra's algorithm.

Three keys, the mirror image of distance vector: each router shares knowledge about its neighbourhood only (not its routing table); it shares it with every router (by flooding, not only with neighbours); and it shares it when there is a change (plus a slow refresh), not every few seconds.

Its properties:

  • Full topology: every router builds the same link state database, the complete graph of its area.
  • Independent computation: each router runs Dijkstra itself, so one router's error does not spread as rumour.
  • Fast convergence, no count to infinity: a change is flooded at once, and loops are rare.
  • Real costs: the metric is a cost from bandwidth or delay, not a hop count.
  • Low traffic when stable, but more memory (the database) and CPU (Dijkstra) than distance vector.
  • Scales with hierarchy: large networks are divided into areas (OSPF, IS-IS).

The five steps every router follows:

  1. Discover its neighbours: send a HELLO packet on each link; each neighbour replies with its router ID.
  2. Measure the cost to each neighbour: by delay (time an ECHO packet's round trip) or, more usually, by a cost set from the link's bandwidth.
  3. Build a link state packet (LSP): its own ID, a sequence number, an age, and the list of neighbours with the cost of each link.
  4. Flood the LSP to every router: each router forwards a new LSP on all its other links; the sequence number lets it drop duplicates and old copies, and the age makes stale LSPs expire.
  5. Compute the shortest paths: with every LSP in hand, the router has the whole graph; it runs Dijkstra from itself and puts the first hop of each path in its routing table.
LINK STATE: EACH ROUTER FLOODS ITS LINKS, THEN RUNS DIJKSTRA Each LSP lists only its own links; together they are the whole map. 2 1 2 3 4 1 A B C D E LINK STATE PACKETS (SENDER, SEQUENCE, AGE, NEIGHBOURS) LSP of A neighbours: B 2, C 1 seq, age LSP of B neighbours: A 2, C 2, D 3 seq, age LSP of C neighbours: A 1, B 2, E 4 seq, age LSP of D neighbours: B 3, E 1 seq, age LSP of E neighbours: C 4, D 1 seq, age A's table: B via B (2), C via C (1), D via B (5), E via C (5) A's shortest path tree in colour
Worked example: how router A's table is populated

Given five routers and their links: A-B 2, A-C 1, B-C 2, B-D 3, C-E 4, D-E 1. After steps 1 to 3, each router's LSP lists its neighbours:

LSP ofABCDE
Neighbours and costsB 2, C 1A 2, C 2, D 3A 1, B 2, E 4B 3, E 1C 4, D 1

Step 4: flooding gives every router all five LSPs, the same database. Step 5: A runs Dijkstra from itself: permanent in turn are C (1), B (2), D (5, via B) and E (5, via C). A's routing table holds only the first hop of each path:

DestinationCostPathNext hop
B2A, BB
C1A, CC
D5A, B, DB
E5A, C, EC

If the D-E link fails, D and E flood new LSPs; every router reruns Dijkstra at once, and no router ever counts to infinity.

Distance vector against link state, the comparison set in ten sittings:

PointDistance vectorLink state
What a router knowsonly distances and next hops, as its neighbours report themthe whole topology of its area (the link state database)
What it sendsits whole routing tableonly the state of its own links (an LSP)
To whomits neighbours onlyevery router, by flooding
Whenperiodically (RIP every 30 s), plus triggered updateswhen a link changes, plus a slow refresh (OSPF every 30 minutes)
AlgorithmBellman-Ford, shared across the routersDijkstra, run by each router on its own copy
Convergenceslow; count to infinity possiblefast; no count to infinity
Routing loopspossible while converging; need split horizon, hold-downrare: every router computes from the same map
Metricusually hop counta cost from bandwidth or delay
Memory and CPUlittlemore: the database and Dijkstra
Bandwidth when stablewasted on periodic full tableslittle: only hellos and refreshes
Scale and setupsmall networks (RIP: 15 hops); simplelarge networks, with areas; more complex
ExamplesRIP, IGRP (EIGRP is an advanced distance vector)OSPF, IS-IS

With examples: a small office of four routers runs RIP happily, configured in minutes; an ISP or a large campus runs OSPF or IS-IS, whose areas keep the databases small and whose instant flooding reroutes around a cut fibre in well under a second, where RIP could take minutes.

To remember the difference, distance vector is villagers passing on directions by word of mouth; link state is every village sending its own sketch of nearby roads to all the others, so that each holds the full district map and plans its own trips.

One paper (2072 Kartik) prints "static link routing" against distance vector; read it as link state routing, the comparison above.
Asked on the paper, word for word
  • What is adaptive and non-adaptive routing? List the properties of link state routing and mention the method that how Designated Router (DR) is elected in OSPF routing. 2081 Bhadra Q4 · 2+2+4
  • What is unicast and multicast? Compare distance vector routing protocol and link state routing protocol with examples. 2080 Baishakh Q4 · 4+4
  • Define routing algorithm. List out the properties/goals of routing algorithm. What is link state routing algorithm? Show how routing tables is populated in LSR with example. 2078 Bhadra Q5 · 3+5
  • What is routing? Differentiate between distance vector and link state routing algorithms. 2076 Ashwin Q5 · 2+6
  • Why routing is essential in computer networking? Compare working of distance vector routing algorithm with link state routing algorithm. 2075 Ashwin Q4 · 3+5
  • What is classful and classless address? Differentiate between link state and distance vector routing protocol. 2074 Ashwin Q4 · 8
  • Discuss about the network congestion? Explain how different network parameters effect the congestion. Compare operation of link state routing with the distance vector routing. 2073 Shrawan Q5 · 2+2+4
  • Network layer is one of the key layers in OSI reference model, why? Differentiate between distance vector routing and static link routing. 2072 Kartik Q5 · 2+6
  • What is routing? Differentiate between link state routing and distance vector routing. 2071 Shrawan Q4 · 2+6
  • Differentiate: a) Distance vector and link state routing algorithm b) Circuit switching and packet switching 2068 Chaitra Q5 · 2×5
  • Why routing is essential in computer networking? Compare working of distance vector routing algorithm with link state routing algorithm. 2067 Ashad Q7 · 2+6
In the exam For the comparison, give eight to ten rows of the table and name RIP and OSPF as examples. For "how routing tables are populated", the five steps, then a small graph with its LSPs and the Dijkstra result as a table.

Hierarchical routing: regions instead of every router

Hierarchical routing Routing in which routers are grouped into regions: each router knows every router of its own region in detail, but treats every other region as a single destination, so its table shrinks.

Why: as a network grows, flat routing tables, the messages that keep them current and the time to compute them all grow with the number of routers. Past some size, no router can keep a route to every other router.

The book's example (Tanenbaum's): 17 routers in five regions. Router 1A's flat table needs 17 entries, one per router. Its hierarchical table needs only 7: itself, the two other routers of region 1 (1B and 1C, one hop each), and one entry for each of regions 2, 3, 4 and 5 (via 1B for region 2, via 1C for the others).

Router 1A, hierarchical table
Destination   Line   Hops
1A            -      -
1B            1B     1
1C            1C     1
Region 2      1B     2
Region 3      1C     2
Region 4      1C     3
Region 5      1C     4

The saving grows with size. With 720 routers, a flat table has 720 entries. Split into 24 regions of 30 routers, each router needs 30 local entries plus 23 for the other regions: 53. With three levels (8 clusters of 9 regions of 10 routers), 10 + 8 + 7 = 25 entries. Kamoun and Kleinrock showed that the best number of levels for N routers is about lnN, needing about elnN entries per router: for 720 routers, about 18.

The price: a longer path. A router sends everything for a region through the same entry point, even when another entry would be shorter for a particular destination, so some paths grow.

Where it is used: OSPF divides an autonomous system into areas joined by a backbone (OSPF), and the Internet itself is a hierarchy of autonomous systems joined by BGP (BGP).

To remember it, a parcel from Kathmandu to a village in Jhapa is first sent "to Jhapa": only the Jhapa district office needs to know the village.

4.7Routing protocols

Routing protocols: why they are needed, IGP and EGP, and the main five PIN 4/27

82 Bh · 74 Ch · 69 Ch · 68 Ba2+63+5

Routing protocol The rules and messages by which routers tell each other which networks they can reach and at what cost, so that each builds and updates its routing table automatically: a routing algorithm put to work between real routers.

Why a routing protocol is necessary:

  • Static routes do not scale: every router needs a route to every network, typed in by hand, and one new subnet means editing every router.
  • Discovery: routers find out on their own which networks exist and where.
  • Adaptation: when a link fails or a new one appears, the routers reroute by themselves, in seconds, at three in the morning.
  • Best paths and no loops: a metric picks the best path, and the protocol's rules keep routes loop free while all routers converge on a consistent view.
  • Policy between organisations: between autonomous systems, BGP carries who may use whose links.

Three ways to classify them:

  • By scope: an interior gateway protocol (IGP) routes inside one autonomous system (intra-AS): RIP, OSPF, IS-IS, EIGRP. An exterior gateway protocol (EGP) routes between autonomous systems (inter-AS): BGP.
  • By algorithm: distance vector (RIP, IGRP), link state (OSPF, IS-IS), advanced distance vector (EIGRP), and path vector (BGP).
  • By masks: classful protocols send no subnet mask in their updates (RIPv1, IGRP); classless ones do, so they support VLSM and CIDR (RIPv2, OSPF, EIGRP, IS-IS, BGP-4).
INTERIOR AND EXTERIOR ROUTING Each autonomous system picks its own IGP; between systems everyone speaks BGP. AUTONOMOUS SYSTEM 64500 AUTONOMOUS SYSTEM 64501 R1 R2 R3 IGP: OSPF R4 R5 R6 IGP: RIP eBGP, TCP 179 the exterior protocol Intra-AS (interior): RIP, OSPF, IS-IS, EIGRP, chosen by each AS. Inter-AS (exterior): BGP, used by all.
PointIntra-AS (IGP)Inter-AS (EGP)
Scopeinside one autonomous systembetween autonomous systems
Goalperformance: the shortest, fastest pathpolicy and reachability: who carries whose traffic
Chosen byeach AS for itselfeveryone uses BGP-4
Sizehundreds to thousands of routesthe whole Internet's routes
ExamplesRIP, OSPF, IS-IS, EIGRPBGP
ProtocolTypeAlgorithmMetricUpdatesOrigin
RIPIGPdistance vectorhop count, at most 15whole table every 30 sopen: RFC 1058, RFC 2453
OSPFIGPlink state (Dijkstra)cost from bandwidthon change; refresh every 30 minopen: RFC 2328
IGRPIGPdistance vectorcomposite: bandwidth and delaywhole table every 90 sCisco, 1980s; obsolete
EIGRPIGPadvanced distance vector (DUAL)composite: bandwidth and delaypartial, only on changeCisco; published as RFC 7868
BGPEGPpath vectorpolicy; the AS path lengthincremental, over TCP port 179open: RFC 4271
  • RIP (Routing Information Protocol): the oldest and simplest; counts hops, calls 16 infinity, sends its whole table to its neighbours every 30 seconds. Fine for a small network; slow to converge (RIP).
  • OSPF (Open Shortest Path First): the open-standard link state IGP; floods link states within areas, elects a DR and BDR on LANs, runs Dijkstra, converges fast and supports VLSM and authentication (OSPF).
  • IGRP (Interior Gateway Routing Protocol): Cisco's 1980s answer to RIP's limits: distance vector, but with a composite metric (bandwidth and delay by default, load and reliability optional), a hop limit of 100 by default (up to 255) and updates every 90 seconds. It is classful, and Cisco has replaced it with EIGRP.
  • EIGRP (Enhanced IGRP): Cisco's advanced distance vector protocol, sometimes called hybrid. It keeps neighbour and topology tables like a link state protocol but still exchanges distances; its DUAL algorithm keeps a ready backup route (the feasible successor), so it switches paths almost at once and stays loop free. It sends small updates only when something changes, supports VLSM and unequal-cost load balancing, and multicasts to 224.0.0.10.
  • BGP (Border Gateway Protocol): the Internet's EGP: a path vector protocol that advertises each route with the list of ASes it passes, and chooses by policy over TCP (BGP).
  • IS-IS (Intermediate System to Intermediate System): a link state IGP from the ISO world, much like OSPF, run by many large ISPs.

An intra-AS protocol in practice: a campus or an ISP's internal network runs one IGP, usually OSPF; it reaches the Internet through a static default route, or through BGP if it owns an AS number and has more than one provider.

To remember it, inside a city the traffic office chooses the fastest roads (an IGP); between countries, border agreements decide which highways may carry whose goods, whatever the distance (an EGP).

Asked on the paper, word for word
  • What are routing protocols? Explain open short path first (OSPF) process in link state routing. 2082 Bhadra Q4 · 2+6
  • Mention the criteria for good routing. Explain RIP, OSPF, BGP, IGRP and EIGRP. 2074 Chaitra Q4 · 2+6
  • Why is routing protocol necessary? Explain the working process of Routing Information protocol (RIP) with example. 2069 Chaitra Q5 · 3+5
  • What is a fragmentation and re-assembly? Explain about any intra-AS routing protocol. 2068 Baishakh Q6 · 3+5
In the exam "Why is a routing protocol necessary" takes the five reasons above. "Explain RIP, OSPF, BGP, IGRP and EIGRP" takes the survey table and a short paragraph on each. "Any intra-AS routing protocol" is best answered with OSPF.

RIP: hop counts, 30 second updates, and its timers PIN 2/27

82 Ba · 69 Ch2+63+5

RIP (Routing Information Protocol) A distance vector interior routing protocol (RFC 1058, version 2 in RFC 2453) whose metric is the hop count, with 15 the most and 16 meaning unreachable; each router sends its whole routing table to its neighbours every 30 seconds over UDP port 520.

How RIP works, in order:

  1. Start up: a router knows only its directly connected networks; it sends a request message on each RIP interface asking the neighbours for their tables.
  2. Respond: neighbours answer with response messages holding their tables; the same response is then sent every 30 seconds by the update timer, whether anything changed or not.
  3. Update: for each route received, the router adds one hop. A route to a new network is added; a shorter route replaces the old one; news from the current next hop is always believed, even if worse; a metric that reaches 16 means unreachable.
  4. Triggered update: when a route changes, the router sends an update at once instead of waiting for the timer.
  5. Age out: the timers below remove routes whose neighbour has gone silent.
  6. Loop control: split horizon, poison reverse and hold-down keep the count to infinity short (distance vector).
THE RIP TIMERS (CISCO DEFAULTS) Seconds after the last update heard for a route whose neighbour has gone silent. 0 30 60 90 120 150 180 210 240 270 300 330 360 route valid, but no update arrives hold-down: 180 s updates due every 30 s INVALID AT 180 S: METRIC 16 FLUSH AT 240 S: ROUTE REMOVED last update Update 30 s, invalid 180 s, hold-down 180 s, flush 240 s (counted from the last update, so the route goes before hold-down ends). RFC 2453 names two: timeout 180 s, then garbage collection 120 s (deleted at 300 s).

Its timers, with Cisco's defaults (the values the papers expect):

TimerDefaultWhat happens
Update30 severy 30 seconds each router sends its whole table out of every RIP interface
Invalid180 sa route not refreshed for 180 seconds (six missed updates) is declared invalid: its metric becomes 16 and it is advertised as unreachable
Hold-down180 sonce the route is invalid, the router refuses news of another route to that network unless it is clearly better, so stale news cannot revive it
Flush240 s240 seconds after the last update, the route is removed from the table altogether

The flush timer is counted from the last update, so it fires 60 seconds after the route went invalid, before the hold-down would end (at 360 seconds). RFC 2453 itself names only two timers: a timeout of 180 seconds and a garbage-collection timer of 120 seconds after it, so the route is deleted 300 seconds after the last update; hold-down is Cisco's addition. The RFC also adds a small random offset to the 30 seconds, so that routers do not all send at the same moment.

Worked example: three routers in a line, running RIPv2

Given: R1 has LAN 10.1.0.0/16; R1 and R2 share link 10.2.0.0/16; R2 and R3 share link 10.3.0.0/16; R3 has LAN 10.4.0.0/16. At the start each router knows only its own two networks.

  • First update (about 30 s): R1 hears from R2 that 10.3.0.0 is one of R2's networks: R1 adds it at 1 hop via R2. R2 likewise adds 10.1.0.0 (via R1) and 10.4.0.0 (via R3), each at 1 hop.
  • Second update (about 60 s): R2 now advertises 10.4.0.0 at 1 hop; R1 adds one and stores it at 2 hops via R2. R3 does the same for 10.1.0.0. The network has converged.
R1# show ip route
C    10.1.0.0/16 is directly connected, GigabitEthernet0/0
C    10.2.0.0/16 is directly connected, Serial0/0/0
R    10.3.0.0/16 [120/1] via 10.2.0.2, 00:00:12, Serial0/0/0
R    10.4.0.0/16 [120/2] via 10.2.0.2, 00:00:12, Serial0/0/0

Reading it: C means connected, R learned by RIP; [120/2] is RIP's administrative distance (120) and the hop count (2); 00:00:12 is the time since the last update, which the invalid and flush timers watch. If R3 dies, 10.4.0.0 goes invalid at 180 s and is flushed at 240 s.

The RIP message: a 4-byte header (command: 1 request, 2 response; version) and up to 25 route entries of 20 bytes each (address family, IP address, metric; version 2 adds a route tag, the subnet mask and the next hop), so at most 504 bytes, sent in UDP.

PointRIPv1RIPv2RIPng
Defined inRFC 1058, 1988RFC 2453, 1998RFC 2080, 1997
Addressingclassful: no mask in updatesclassless: mask and next hop carriedIPv6 prefixes
Updates sent tobroadcast 255.255.255.255multicast 224.0.0.9multicast ff02::9
Authenticationnoneplain text or MD5left to IPsec
TransportUDP 520UDP 520UDP 521

Its limits: a 15-hop diameter; slow convergence and the count to infinity; a hop count that ignores bandwidth, so one hop over a 2 Mbps line beats two hops over gigabit fibre; and the whole table every 30 seconds even when nothing changes. RIP suits small, simple networks; larger ones use OSPF.

To remember it, RIP counts bus stops, not minutes: a route with one stop through the Kalanki jam beats a two-stop route along the empty ring road. Its four timers are half a minute, three minutes, three minutes and four minutes.

Two ways of counting hops. Cisco and most texts count the routers to cross: a neighbour's own network is 1 hop, as in the example above. The book's distance vector figure counts a directly connected network as 1, so each of its values is one higher. Either is right if used consistently in one answer.
Asked on the paper, word for word
  • Define routed and routing protocol. Explain RIP routing operation with is timer details. 2082 Baishakh Q4 · 2+6
  • Why is routing protocol necessary? Explain the working process of Routing Information protocol (RIP) with example. 2069 Chaitra Q5 · 3+5
In the exam Give the definition, the steps of the operation, the four timers with their values, and a three-router example; draw the timer line. The limits make a good closing paragraph.

OSPF: areas, DR and BDR, and the road to full adjacency HOT 5/27

82 Bh · 81 Bh · 80 Bh · 79 Bh · 66 Bh2+62+2+42×4

OSPF (Open Shortest Path First) An open-standard link state interior routing protocol (OSPFv2, RFC 2328): each router floods link state advertisements (LSAs) through its area, builds the same link state database as every other router there, and runs Dijkstra's algorithm to compute its routes.

"Open" means it is a public standard any vendor may implement, unlike Cisco's EIGRP; "shortest path first" is the Dijkstra calculation (Dijkstra). OSPF messages travel straight inside IP (protocol 89), to the multicast address 224.0.0.5 (all OSPF routers) or 224.0.0.6 (the DR and BDR).

Its metric is a cost worked out from each interface's bandwidth:

cost=reference bandwidthinterface bandwidth=108 bit/sbandwidth

With Cisco's default reference of 100 Mbps, a 10 Mbps link costs 10 and a 100 Mbps link 1 (so does gigabit, unless the reference is raised). A path's cost is the sum of its links' costs.

The OSPF process, from power-on to a routing table:

  1. Find neighbours: every OSPF interface sends a Hello every 10 seconds; routers whose hellos agree (same area, subnet, timers and authentication) become neighbours. A neighbour silent for 40 seconds (the dead interval) is declared down.
  2. Elect a DR and BDR on each multi-access network such as Ethernet (below).
  3. Form adjacencies and synchronise: adjacent routers swap database descriptions, request the LSAs they lack and receive them, until their databases match: the Full state.
  4. Flood LSAs: each router floods an LSA describing its own links through the area; the DR adds one for the LAN segment. LSAs are flooded again when a link changes, and refreshed every 30 minutes.
  5. Run SPF: each router runs Dijkstra on its database, with itself as the root, and gets its shortest path tree.
  6. Install the routes: the best path to every network goes into the routing table; a change floods new LSAs and the SPF run repeats.
TypeOSPF packetJob
1Hellofind neighbours, keep them alive, carry the DR election
2Database description (DBD)list the LSA headers each router holds
3Link state request (LSR)ask for LSAs that are missing or out of date
4Link state update (LSU)carry the full LSAs
5Link state acknowledgement (LSAck)confirm each LSA received

Areas. A large autonomous system is divided into areas, all attached to the backbone, area 0. Routers keep a detailed database only of their own area, so SPF runs are quick and a fault in one area is not flooded everywhere; an area border router (ABR) joins an area to the backbone and summarises its routes, and an AS boundary router (ASBR) brings in routes from outside (BGP or static). This is hierarchical routing (hierarchical routing).

OSPF AREAS, AND A DR AND BDR ON A LAN Areas keep each database small; a DR and BDR cut the adjacencies on a shared segment. AREA 0 (BACKBONE) AREA 1 AREA 2 other AS R0 ABR1 ABR2 ASBR one Ethernet segment R1 R2 R3 R4 R5 DR BDR DROthers 7 adjacencies, not 10

DR and BDR. On a multi-access network, if every router formed an adjacency with every other, n routers would need n(n−1)/2 adjacencies, and every LSA would be flooded over and over: ten routers on one Ethernet would need 45. So OSPF elects a designated router (DR): every router forms its full adjacency only with the DR and a backup designated router (BDR). Routers send their updates to the DR (224.0.0.6), and the DR floods them to all (224.0.0.5) and speaks for the segment with one network LSA. The BDR listens to everything and takes over at once if the DR fails. The ten routers now need only 2(n−2)+1 = 17 adjacencies. The other routers are called DROthers.

How the DR is elected, from the values each router puts in its Hello:

  1. Highest interface priority (0 to 255, default 1) becomes DR, the next highest BDR.
  2. A tie is broken by the highest router ID: set by hand, or else the highest loopback address, or else the highest address of an active interface.
  3. Priority 0 means the router never becomes DR or BDR.
  4. Timing: a new interface waits one dead interval (40 s) before electing, so routers that start together all take part.
  5. No pre-emption: a better router that joins later does not take over. Only when the DR fails does the BDR become DR, and a new BDR is elected.

The road to full adjacency: two OSPF neighbours pass through these states (RFC 2328):

OSPF: FROM DOWN TO FULL ADJACENCY The first three states make neighbours; the last four build the adjacency. NEIGHBOURS BUILDING THE ADJACENCY Down 1 no Hello heard yet Init 2 Hello arrives, not yet listing this router 2-Way 3 own ID seen in Hello; DR, BDR elected ExStart 4 master and slave chosen Exchange 5 DBD packets swapped Loading 6 LSR, LSU and LSAck for the missing LSAs Full 7 databases match DROthers stay here Down, Init, 2-Way, ExStart, Exchange, Loading, Full: the DR and BDR are chosen at 2-Way, and only routers that must become adjacent go further.
  1. Down: no Hello heard from the neighbour (or the dead interval ran out).
  2. Init: a Hello has arrived from the neighbour, but it does not list this router yet: one-way.
  3. 2-Way: each router sees its own router ID in the other's Hello: two-way talk. The DR and BDR are elected here, and two DROthers stay in this state for good.
  4. ExStart: the pair chooses master and slave (the higher router ID is master) and the first sequence number for the exchange.
  5. Exchange: they swap DBD packets listing the headers of their LSAs.
  6. Loading: each sends LSRs for the LSAs it lacks or holds old copies of, receives them in LSUs and acknowledges them.
  7. Full: the two databases are identical: the routers are fully adjacent, and each lists the other in its router LSA.

Why OSPF is the usual IGP: it converges in seconds, never counts to infinity, has no hop limit, carries masks (VLSM and CIDR), authenticates its messages, balances load over equal-cost paths, and sends little once stable. Its costs are more memory and CPU than RIP and a harder setup (areas, router IDs, DR priorities).

To remember DR and BDR, think of a class of forty: instead of every student passing every notice to every other, the class elects a CR (the DR) and an assistant CR (the BDR). Everyone tells the CR, the CR tells everyone, and if the CR is absent the assistant steps in without a new election.

The book says OSPF "doesn't need a high memory and high-speed processor". It needs more of both than a distance vector protocol such as RIP: it keeps the whole link state database and runs Dijkstra; areas exist largely to keep that load down.
Asked on the paper, word for word
  • What are routing protocols? Explain open short path first (OSPF) process in link state routing. 2082 Bhadra Q4 · 2+6
  • What is adaptive and non-adaptive routing? List the properties of link state routing and mention the method that how Designated Router (DR) is elected in OSPF routing. 2081 Bhadra Q4 · 2+2+4
  • What is DR and BDR in OSPF? How do OSPF routers come into fully adacency states? Explain. 2080 Bhadra Q5 · 3+5
  • Write short notes on: (Any Two) a) ALOHA b) OSPF c) VPN 2079 Bhadra Q10 · 2×4
  • What is unicast and multicast routing? Describe the concept of optimality principle. Describe how the routers in its link state routing come into fully adjacency state. 2066 Bhadra Q4a · 2+6
In the exam For "the OSPF process", the six steps and the five packet types. For "DR and BDR", the n(n minus 1)/2 problem, the election rules and the non-pre-emption. For "full adjacency", draw the seven states with what happens in each.

BGP: routing between autonomous systems

BGP (Border Gateway Protocol, version 4) The Internet's exterior gateway protocol (RFC 4271): a path vector protocol by which autonomous systems advertise the networks they can reach, each route carrying the list of ASes it passes through, and choose among routes by policy.

Why RIP or OSPF cannot do this job: between ASes the goal is not the fastest path but the permitted one (an ISP carries a customer's traffic, not a competitor's); each AS hides its inside from the others; their internal metrics cannot be compared; and the Internet's routing table is far too large to flood.

Path vector: a route is advertised as a prefix plus its AS_PATH, for example 203.0.113.0/24 with path 64501 64502. When an AS passes the route on, it adds its own number at the front. An AS that sees its own number in a path rejects the route: that is how BGP avoids loops without any count to infinity.

  • Sessions over TCP port 179: two BGP routers (peers) open a TCP connection and exchange the full table once, then only changes.
  • eBGP and iBGP: external BGP runs between routers of different ASes, usually directly connected; internal BGP carries the outside routes among the border routers of the same AS.
  • Policy: each AS sets which routes it accepts and which it advertises, and ranks routes by attributes such as local preference, then the shortest AS_PATH, then others.
BGP messageJob
OPENstarts a session over TCP: AS number, hold time, router ID
UPDATEadvertises new routes with their path attributes, and withdraws dead ones
KEEPALIVEsays "still here" when there is nothing to update, every third of the hold time (commonly 60 s with a 180 s hold time)
NOTIFICATIONreports an error and closes the session

An internet exchange point is where many ASes meet to exchange traffic directly over BGP sessions instead of paying an upstream provider to carry it. Nepali ISPs peer at the Nepal Internet Exchange (NPIX), so that a page on a Nepali server can reach a Nepali customer of another member ISP without leaving the country.

To remember it, BGP is the travel agent's itinerary: "Kathmandu, Delhi, Dubai, London". Every stop is listed, so nobody books a trip through a city twice, and an agent can refuse any route that passes through a country it does not deal with.

Unicast and multicast routing, and their protocols PIN 3/27

80 Ba · 72 Ka · 66 Bh2+64+4

Unicast and multicast Unicast sends a packet from one source to one destination. Multicast sends one packet from a source to a group of receivers that asked to join, and the network copies it only where the paths to the members split, so each link carries one copy.
UNICAST AGAINST MULTICAST TO THREE RECEIVERS Unicast repeats the data per receiver; multicast copies it only where the paths split. UNICAST: ONE COPY PER RECEIVER 3 2 1 1 1 1 S R1 R2 R3 H1 H2 H3 MULTICAST: ONE COPY PER LINK 1 1 1 1 1 1 S R1 R2 R3 H1 H2 H3 Copies on each link; 9 link transmissions in all H1, H2, H3 joined group 239.1.1.1 with IGMP Copies on each link; 6 link transmissions in all
PointUnicastMulticastBroadcast
Receiversonea group that joinedeveryone on the network
Destination addressone host's addressa group address, class D (224.0.0.0 to 239.255.255.255)all 1s in the host part
Copies for N receiversN, from the sourceone per link, made by routersone, to all
Crosses routersyesyes, with multicast routingno
Exampleloading a web pagea live lecture or IPTV channelan ARP request

Unicast routing is everything in the earlier cards: the router looks up the one destination and sends one copy to one next hop. Unicast routing protocols build those tables: RIP and IGRP (distance vector), OSPF and IS-IS (link state), EIGRP (advanced distance vector) inside an AS, and BGP between ASes (routing protocols).

Multicast routing must answer two questions: which hosts want a group, and along which tree to copy its packets.

  • Group membership, host to router: IGMP (Internet Group Management Protocol, IP protocol 2; version 3 in RFC 3376). A host sends a membership report to join a group; the router sends periodic queries (to 224.0.0.1) to see whether anyone on the LAN still wants it; version 2 added an explicit leave message.
  • Distribution trees, router to router: a source-based tree is a shortest path tree from each source to the members (best paths, but one tree per source); a shared tree is one tree per group rooted at a chosen core or rendezvous point (fewer trees, longer paths).
  • Reverse path forwarding (RPF): a router accepts a multicast packet only if it arrived on the interface the router would use to send unicast traffic back to the source; this stops loops and duplicates without any extra tables.
Multicast routing protocolBuilt onHow it builds the tree
DVMRP (Distance Vector Multicast Routing Protocol, RFC 1075)distance vectorflood and prune: send everywhere by RPF, then branches with no members ask to be cut off; source-based trees
MOSPF (Multicast OSPF, RFC 1584)OSPF link stategroup-membership LSAs added to OSPF; each router computes the source's shortest path tree with Dijkstra
PIM-DM (Protocol Independent Multicast, dense mode)any unicast protocolflood and prune, like DVMRP; suits groups whose members are everywhere
PIM-SM (sparse mode, RFC 7761)any unicast protocolexplicit joins towards a rendezvous point (shared tree), switching to source trees for heavy flows; suits scattered members and is the most used
CBT (Core Based Trees, RFC 2201)any unicast protocolone shared tree per group, rooted at a core router

"Protocol independent" means PIM uses whatever unicast routing table the router already has for its RPF checks, instead of running its own routing algorithm.

To remember it, unicast is a teacher phoning each of 200 students with the same notice; multicast is the notice read once over the campus speakers in only the halls whose students signed up for it; broadcast is the siren that everyone hears.

Asked on the paper, word for word
  • What is unicast and multicast? Compare distance vector routing protocol and link state routing protocol with examples. 2080 Baishakh Q4 · 4+4
  • What are the functions of network layer? Explain briefly about multicast routing protocols and unicast routing protocols. 2072 Kartik Q4 · 2+6
  • What is unicast and multicast routing? Describe the concept of optimality principle. Describe how the routers in its link state routing come into fully adjacency state. 2066 Bhadra Q4a · 2+6
In the exam "Unicast and multicast" wants the two definitions with the table and the drawing. "Multicast and unicast routing protocols" wants IGMP, the two kinds of tree, RPF, and DVMRP, MOSPF and PIM in a table, plus a line naming the unicast protocols.

4.8Designing a network

Designing a network for a real site: a hotel, a campus PIN 2/27

72 Ka · 67 Asa6+28

Network design Choosing the topology, devices, cabling, wireless, addressing, servers and security that meet a site's needs, and giving a reason for every choice, from requirements that are stated or, where the question leaves them out, assumed and written down.

The method, which turns a vague question into a marked answer:

  1. Requirements and assumptions: how many users and devices, rooms, floors and buildings; which services (Internet, Wi-Fi, phones, CCTV, servers); how much growth; any budget. Write each assumption down: the answer is judged on them.
  2. Topology: a hierarchical star (core, distribution, access), which isolates faults and grows by adding branches (topologies).
  3. Devices: managed switches (PoE where access points, phones and cameras plug in), a router and firewall at the edge, wireless access points with a controller (devices).
  4. Cabling: Cat6 UTP for runs up to 100 m; fibre between buildings, up risers or for long runs: multimode (OM3 or OM4: 10 Gbps up to 300 to 400 m) inside a campus, single-mode beyond (fibre). Fibre also ignores the lightning and electrical noise that copper picks up.
  5. Wireless: enough access points for coverage and for the number of devices, 802.11ax (Wi-Fi 6) or 802.11ac, separate SSIDs for staff and guests, WPA2 or WPA3 (wireless LAN).
  6. Addressing: private addresses (RFC 1918), one VLAN and one subnet per department or function, DHCP for the clients, NAT to the ISP's public address (VLAN, subnetting).
  7. Servers and services: DHCP and DNS, file and print, web and mail, the site's own applications, a recorder for the cameras.
  8. Security and reliability: firewall rules between VLANs, guest isolation, antivirus and backups; two ISPs, a UPS, and redundant core links where downtime costs money (firewalls).
  9. Management: SNMP monitoring, labelled cables and ports, a written plan.
LayerJobDevice
Corefast backbone joining the distribution blocks and the server roomlayer 3 core switch, fibre links
Distributionjoins the access switches of one building or department, routes between VLANs, applies policylayer 3 switch
Accessconnects the end deviceslayer 2 switches (PoE), access points
A CAMPUS LAN: CORE, DISTRIBUTION, ACCESS Five departments, five rooms each, twenty computers per room: 500 computers. ISP (or NREN) Router and firewall Core switch, layer 3 Server room: DHCP, DNS, file, web Department 1 distribution switch 5 room switches 24-port, 20 PCs each Department 2 distribution switch 5 room switches 24-port, 20 PCs each Department 3 distribution switch 5 room switches 24-port, 20 PCs each Department 4 distribution switch 5 room switches 24-port, 20 PCs each Department 5 distribution switch 5 room switches 24-port, 20 PCs each fibre (OM3 or OM4) Cat6 Each department: one VLAN and one subnet, two or three Wi-Fi access points, a UPS in every closet.
Worked design 1: a LAN for five departments of Pulchowk Campus

Given: 5 departments, each with 100 computers in 5 rooms of 20: 500 computers. Assumed: the departments are in separate buildings within a few hundred metres of a central server room, rooms are within 100 m of their department's network closet, and the campus has one ISP link plus room to add another.

ItemQuantityWhy
Access switch, managed, 24 gigabit ports, with uplinks25, one per room20 PCs plus an uplink and spare ports; a switch, not a hub, so each PC has its own collision-free gigabit port
Distribution switch, layer 3, fibre (SFP) ports5, one per departmentjoins the 5 room switches, routes the department's VLAN, keeps its broadcasts inside
Core switch, layer 3, 10 Gbps fibre ports1 (2 for redundancy)joins the 5 departments and the server room at full speed
Router and firewall1link to the ISP, NAT, the security policy
Wireless access points, Wi-Fi 6, PoE2 or 3 per departmentlaptops and phones in corridors and halls
Cat6 UTP drops and patch cords500 dropseach PC to its room switch, under 100 m, gigabit
Multimode fibre (OM3 or OM4)5 department links to the core10 Gbps over hundreds of metres, immune to lightning surges
Racks, patch panels, UPSin every room closet, department and the coretidy, labelled cabling that keeps running through power cuts
ServersDHCP and DNS, file, web and mail, authenticationin the central server room

Accessories: RJ45 connectors and keystone jacks, faceplates, cable trays and conduit, SFP modules for the fibre ports, labels, and a crimping tool and LAN tester.

Addressing: one VLAN and one private subnet per department (each needs 100 hosts and room to grow), DHCP from the server room, NAT at the firewall. The next paper question on this campus works the address ranges; they are in the Numericals panel.

A 3-STAR HOTEL: TWO ISPS, ONE FIREWALL, VLANS PER USE The firewall ties together dual WAN, NAT, VLAN rules and the guest captive portal. ISP 1: fibre ISP 2: backup Firewall (UTM), dual WAN Core switch, layer 3 Servers: PMS, POS, NVR, IP PBX Floor 1 48-port PoE+ switch APs, IP phones, cameras Floor 2 48-port PoE+ switch APs, IP phones, cameras Floor 3 48-port PoE+ switch APs, IP phones, cameras Floor 4 48-port PoE+ switch APs, IP phones, cameras fibre up the riser VLANS VLAN 10 Staff, front desk, POS VLAN 20 Guest Wi-Fi, isolated VLAN 30 Voice, priority VLAN 40 CCTV, no Internet VLAN 50 Servers Wi-Fi 6 access points under one controller; WPA3 for staff; a captive portal by room number for guests.
Worked design 2: a 3-star hotel

Assumed: 60 guest rooms on 4 floors; a lobby and reception, a restaurant and bar, a conference hall and back offices (front desk, accounts, kitchen, store); about 30 staff computers and POS terminals; 40 CCTV cameras; an IP phone in every room.

  • Internet: two ISP links (a fibre line from one ISP and a backup from another) on a firewall with two WAN ports, for failover and load balancing: guests judge a hotel by its Wi-Fi.
  • Firewall (UTM): NAT, rules between the VLANs, content filtering, a VPN for remote management, and a captive portal where guests log in with their room number.
  • Core: a stackable layer 3 switch in the server room, routing between the VLANs.
  • Access: one 48-port PoE+ switch per floor, powering the access points, phones and cameras over the data cable, with a fibre uplink up the riser to the core.
  • Wireless: Wi-Fi 6 access points, about one per three or four rooms plus the lobby, restaurant and conference hall, under one controller so guests roam without dropping; WPA3 for staff, an isolated guest SSID with a speed limit per device.
  • Voice and video: an IP PBX with a gateway to the telephone network, IP phones, and a network video recorder for the cameras.
  • Software: a hotel property management system (reservations, check-in, billing, linked to the keycard locks and the restaurant POS), accounting software, the hotspot manager for guest Wi-Fi, antivirus, backup, and SNMP monitoring.
VLANWhoExample subnetRule
10 Staffoffice PCs, front desk, POS10.10.10.0/24reaches the PMS and the Internet
20 Guestsguests' phones and laptops10.10.20.0/22Internet only, guests isolated from each other
30 VoiceIP phones10.10.30.0/24priority (QoS)
40 CCTVcameras, recorder10.10.40.0/24no Internet
50 ServersPMS, file, DHCP, DNS10.10.50.0/24staff only

Why this design: VLANs keep guests away from the billing and card systems; PoE saves a power socket at every access point, phone and camera; managed switches allow the VLANs and monitoring; two ISPs and a UPS keep the hotel online; Cat6 gives gigabit to every room, and fibre carries the floor uplinks.

To remember the method, think of planning a wedding venue: first count the guests (requirements), then lay out the halls (topology), hire the tables and chairs (devices), lay the carpets between halls (cabling), seat families together (VLANs and subnets), and put guards on the doors (security).

Asked on the paper, word for word
  • You are assigned to design a network infrastructure for a 3-star hotel. Recommend a network solution with hardwares and softwares in current trend that can be used in the hotel. Make necessary assumptions and justify your recommadation with logical arguments where possible. 2072 Kartik Q1 · 8
  • If you are assigned to design a LAN for Pulchowk Campus having 5 departments. Each department will have 100 computers locating in 5 rooms each equipped with 20 computers. Make your own justification while selecting connecting devices and accessories. 2067 Ashad Q2 · 6+2
In the exam Write the assumptions first, draw the topology, then give devices, cabling, wireless, addressing (VLANs), servers and software, and security, each with its reason. A table of items with quantity and reason earns the justification marks.

4.9Last minute recall

Chapter 4 in one screen

  • Network layer: host to host across networks; logical addressing, routing, forwarding, packetizing, fragmentation, internetworking, ICMP; key layer: highest layer every router runs, the narrow waist.
  • Devices: repeater and hub layer 1 (one collision domain); bridge and switch layer 2 (MAC table, a collision domain per port); router layer 3 (IP, a broadcast domain per interface); gateway up to 7 (protocol conversion).
  • Bridge: receive, learn source, filter, forward or flood, age (300 s); throughput 2C/(1+f) against a repeater's C; STP for loops.
  • IPv4: 32 bits, dotted decimal; A 0 to 127 /8, B 128 to 191 /16, C 192 to 223 /24, D 224 to 239 multicast, E 240 to 255 reserved; private 10/8, 172.16/12, 192.168/16.
  • Subnetting: hosts 2h−2, block 256−m; VLSM: find the block, size, sort largest first, allocate from the start, links /30, wasted and unused range.
  • CIDR and supernetting: a.b.c.d/n; contiguous, power of two, aligned; four /24s into one /22; longest prefix match.
  • IPv4 header: 20 to 60 bytes; TTL hop limit, protocol 1 ICMP, 6 TCP, 17 UDP; fragments share Identification, offset in 8 bytes, MF; 65,535 minus 20 minus 20 = 65,495.
  • ARP: broadcast request, unicast reply, cache; RARP MAC to IP (replaced by DHCP); NDP in IPv6 with ICMPv6 and multicast.
  • ICMP: errors: destination unreachable 3, source quench 4, time exceeded 11, parameter problem 12, redirect 5; queries: echo 8 and 0, timestamp, address mask, router discovery; ping, traceroute, path MTU.
  • Routing: routing builds tables, forwarding uses them; good algorithm: correctness, simplicity, robustness, stability, fairness, optimality; static against dynamic; routed (IP) against routing (RIP, OSPF); optimality principle and sink tree; AS.
  • Algorithms: Dijkstra (A to D: ABEFHD, cost 10); flooding with hop count; distance vector (Bellman-Ford, neighbours, periodic, count to infinity, split horizon, poison reverse, hold-down); link state (discover, measure, build, flood, compute); hierarchical regions.
  • Protocols: RIP hop count 15, timers 30, 180, 180, 240; OSPF areas, DR and BDR by priority then router ID, states Down, Init, 2-Way, ExStart, Exchange, Loading, Full; IGRP, EIGRP (DUAL); BGP path vector over TCP 179.
  • Multicast: IGMP for membership; source and shared trees, RPF; DVMRP, MOSPF, PIM-DM, PIM-SM, CBT.
  • Design: assumptions, hierarchical star, managed PoE switches, router and firewall, Wi-Fi 6, Cat6 and fibre, a VLAN per department, servers, security, UPS and two ISPs.

Chapter 5 · 5 hours · about 8 marks a paper · in 26 of the 27 sittings

Transport layer

The transport layer is where the network stops being host to host and becomes process to process. It takes IP's best-effort packets and gives each application one of two services, addressed by port numbers: a reliable, ordered byte stream (TCP) or a fast, bare datagram (UDP). It is the steadiest question on the paper: 26 of the 27 sittings on record set it, usually as Q6 with two asks, and the token bucket, the TCP header and its reliability, the three-way handshake and UDP come back again and again.

What this chapter is about
  • The transport service: process-to-process delivery, the layer's functions, and the two kinds of service it offers the application layer (connection-oriented and connectionless).
  • Two protocols: UDP, an 8-byte header and no promises, and TCP, a 20 to 60 byte header and a reliable byte stream; how they compare, and why both exist over one IP.
  • Ports and sockets: the 16-bit numbers that pick the process, the IANA ranges, and the socket pair that names one connection.
  • Connection management: the three-way handshake, the graceful four-segment release and TIME-WAIT.
  • Flow control, buffering and multiplexing: TCP's sliding window, the receiver's buffers, and how many sockets share one IP address.
  • Congestion: its causes, the policies that prevent it, and the two traffic shaping algorithms, the leaky bucket and the token bucket.
Where it fits
  • On the layer models: layer 4 of OSI and the transport layer of TCP/IP (OSI model, TCP/IP model). Each segment rides inside an IP datagram whose protocol field says 6 for TCP or 17 for UDP (IPv4 header, encapsulation).
  • The same ideas one layer down: chapter 3's flow control and ARQ work hop by hop on one link (flow control, ARQ); TCP does them end to end across the whole internet. The checksum idea is chapter 3's (error detection).
  • Above it: every application picks TCP or UDP and a port (HTTP, e-mail, DNS, DHCP), and socket programming is chapter 6's (socket programming). SSL and TLS run on top of TCP (SSL), and firewalls filter on ports (firewalls).
What you will learn
  1. 5.1 The transport service: process-to-process delivery, functions, services to the upper layer
  2. 5.2 Transport protocols: UDP, TCP, and TCP against UDP
  3. 5.3 Ports and sockets
  4. 5.4 Connection establishment and release
  5. 5.5 Flow control and buffering: the sliding window
  6. 5.6 Multiplexing and demultiplexing
  7. 5.7 Congestion, the leaky bucket and the token bucket
  8. 5.8 Last minute recall, chapter 5
How it is examined
  • Nine sittings each have set the token bucket (alone or against the leaky bucket) and TCP (its header, or why and how it is reliable); seven the handshake and release; six UDP, and six TCP against UDP.
  • Draw: the TCP header as a 32-bit grid, the UDP header, the handshake and the release as sequence diagrams with SYN, ACK, FIN and the sequence numbers, and both buckets.
  • A common pairing is a protocol ask (about 4 marks) with a bucket ask (about 4 marks); a few papers set a short note on the TCP sliding window or the TCP header.

5.1The transport service

The transport layer: process-to-process delivery and its services HOT 5/27

80 Bh · 78 Bh · 76 Ch · 71 Ch · 68 Ba3+51+2+54+4

Transport layer The layer that provides logical communication between processes running on different hosts. It takes a message from an application, cuts it into segments, hands them to IP, and at the far end puts the data back together and gives it to the right process. It runs only in the end hosts, never in the routers, which is why it is called an end-to-end layer.

Three scopes of delivery. Each layer delivers over a different distance:

  • Node to node: the data link layer moves a frame one hop, using MAC addresses.
  • Host to host: the network layer moves a packet across the internet, but an IP address names only a machine.
  • Process to process: a laptop may run a browser, a video call and a software update at once, so something must still decide which program a packet is for. That is the transport layer's job, done with port numbers.
THREE SCOPES OF DELIVERY A frame moves one hop, a packet moves host to host, and a segment reaches its process. Browser port 52344 Web server process port 80 PROCESS TO PROCESS: transport layer, ports Host A 198.51.100.10 Router R1 Router R2 Host B 203.0.113.5 HOST TO HOST: network layer, IP addresses hop 1 hop 2 hop 3 NODE TO NODE: data link layer, MAC addresses, one hop at a time Only the two hosts run the transport layer; the routers stop at IP.

To remember it, think of a letter to a hostel. The postal address brings the letter to the hostel gate (the IP address: host to host); the warden reads the room number and puts it in the right room's box (the port: process to process). The postal van that carries it from one sorting office to the next is the data link layer, one hop at a time.

Its services and functions, which the papers call services, functions or major tasks: they are the same list.

Service (function)What it doesHow TCP and UDP do it
Process-to-process delivery (addressing)delivers to a process, not just to a host16-bit source and destination ports in both headers (ports)
Segmentation and reassemblycuts a long message into pieces the network can carry, and rebuilds itTCP numbers every byte and sizes segments to the MSS; UDP sends each message as one datagram
Connection controlsets up, uses and releases a logical connection, or sends with no connection at allTCP: three-way handshake and FIN release (5.4); UDP: connectionless
Reliability (error control)detects corrupt, lost and duplicate data and recovers itTCP: checksum, ACK, timer, retransmission; UDP: checksum only, a bad datagram is dropped
Ordered deliveryhands data up in the order it was sentTCP: reorders by sequence number; UDP: none
Flow control and bufferingkeeps a fast sender from flooding a slow receiver's bufferTCP: the receive window (5.5); UDP: none
Multiplexing and demultiplexinglets many processes share one IP addressports in every header (5.6)
Congestion controlkeeps all the senders together from flooding the networkTCP: slow start and AIMD; shaping with the buckets (5.7)

Why a separate layer at all, when IP already delivers packets?

  • The network belongs to the carrier: users do not own the routers and cannot fix what they lose.
  • The transport layer runs in the users' own hosts, so it can improve on the network's service, recovering lost packets and restoring their order.
  • One standard interface for every application, whatever networks lie in between. In OSI terms, layers 1 to 4 are the transport service provider and layers 5 to 7 its user.

How the complete message arrives, and in order. IP may lose, duplicate, corrupt or reorder packets. TCP turns that into a perfect byte stream with a chain of mechanisms, each covering a different failure:

  1. Synchronize: the three-way handshake agrees the initial sequence numbers, so both sides know where the numbering starts.
  2. Number every byte: each segment carries the sequence number of its first byte, so a gap, a duplicate or a misordering shows at once.
  3. Check: the checksum catches a corrupted segment, which is dropped and so becomes a loss.
  4. Acknowledge: the receiver returns a cumulative ACK, the number of the next byte it expects.
  5. Retransmit: a segment not acknowledged before the retransmission timer (RTO) runs out, or reported missing by three duplicate ACKs, is sent again.
  6. Reorder and drop duplicates: the receive buffer keeps early segments and discards repeats; data goes up to the application only when no gap lies before it.
  7. Flow control: the advertised window keeps the sender from overflowing the receiver's buffer, which would lose data.
  8. Close cleanly: FIN goes only after the data and carries the next sequence number, so the receiver knows exactly where the stream ends and that nothing is missing.
Worked example: a 3,000-byte message with one segment lost

After the handshake the sender's first data byte is 1001. It sends three 1,000-byte segments, seq 1001, 2001 and 3001, and the second is lost on the way.

  1. Segment 1001 arrives: bytes 1001 to 2000 go up to the application; the receiver sends ACK 2001.
  2. Segment 3001 arrives early: it is kept in the buffer, not delivered, and the receiver repeats ACK 2001 (a duplicate ACK).
  3. The timer for 2001 runs out: the sender, which kept a copy, sends seq 2001 again.
  4. The gap is filled: bytes 2001 to 4000 go up, so all 3,000 bytes have arrived whole and in order, and the receiver sends ACK 4001.
HOW TCP RECOVERS A LOST SEGMENT Sequence numbers show the gap, the ACK reports it, the timer resends it: 3,000 bytes arrive whole and in order. Sender keeps a copy until ACKed Receiver buffers, reorders, ACKs seq 1001, 1000 bytes lost seq 2001, 1000 bytes seq 3001, 1000 bytes ACK 2001 duplicate ACK 2001 bytes 1001 to 2000 in order 3001 to 4000 arrive early: kept in the buffer retransmission timer for 2001 (RTO) runs out seq 2001 again ACK 4001 gap filled: bytes 1001 to 4000 go to the application in order Three duplicate ACKs would trigger the resend sooner (fast retransmit); a corrupt segment fails its checksum and is treated as lost.

UDP does none of this beyond the checksum: it delivers to the right port, and leaves loss and order to the application (UDP).

Asked on the paper, word for word
  • How does the transport layer ensure that the complete message arrive at the destination and in the proper order? How does Token Bucket control the congestion over the Leaky Bucket algorithm? 2080 Bhadra Q6 · 4+4
  • What are services provided by Transport layer? Explain about Leaky-Bucket algorithm for congestion control? 2078 Bhadra Q6 · 3+5
  • What are the major task of transport layer? Explain. What is token bucket algorithm? 2076 Chaitra Q6 · 5+3
  • Why port number is used in networking? What are the services of transport layer? Differentiate between TCP and UDP protocol. 2071 Chaitra Q6 · 1+2+5
  • What are the functions of transport layer? Draw the segment structure of TCP. 2068 Baishakh Q5 · 3+5
In the exam For services, functions or major tasks, give the eight rows of the table with a line each, opening with process-to-process delivery. For "how does the transport layer ensure the complete message arrives in proper order", give the mechanisms in order and the lost-segment example with its drawing.

Services to the upper layer: connection-oriented, connectionless, and the primitives

Transport service What the transport layer offers the application layer through its interface: either a connection-oriented service (establish, transfer, release: a reliable stream, as TCP gives) or a connectionless service (independent datagrams, each carrying the full address, with no guarantees, as UDP gives), used through a small set of service primitives.
PointConnection-orientedConnectionless
Phasesestablish, transfer data, releasesend only
Addressingthe full address once, at setupthe full address in every datagram
Reliabilityacknowledged, retransmitted, in ordernone promised: data may be lost, repeated or reordered
Delay before dataa setup round tripnone
Stateboth ends keep the connection's statenone
Everyday picturea phone calla letter or a postcard
Internet protocolTCPUDP

To remember it: calling home from the hostel is connection-oriented: the phone rings, someone answers, both say hello before anything else (setup), you talk, and you say bye (release). Posting a letter is connectionless: every envelope carries the full address, and two letters posted on the same day may arrive in either order, or one may not arrive at all.

Service primitives are the calls an application makes to use the service (the general idea is chapter 1's, services and primitives). The classic simple transport service has five, and the unit that peer transport entities exchange is a TPDU (transport protocol data unit), called a segment in TCP and a user datagram in UDP:

PrimitiveTPDU sentMeaning
LISTENnoneblock until some process tries to connect
CONNECTCONNECTION REQUESTactively try to set up a connection
SENDDATAsend information
RECEIVEnoneblock until a DATA TPDU arrives
DISCONNECTDISCONNECTION REQUESTthis side wants to release the connection

The internet's version is the Berkeley socket interface (4.2BSD, 1983): SOCKET (create an endpoint), BIND (attach a local address and port), LISTEN (be ready to accept, with a queue), ACCEPT (take the next incoming connection), CONNECT (actively open), SEND and RECEIVE, and CLOSE. A server calls SOCKET, BIND, LISTEN, ACCEPT; a client calls SOCKET, CONNECT. The code itself is chapter 6's (socket programming).

Why the transport layer is harder than the data link layer, though both do error control, sequencing and flow control. On a link the other end is fixed and directly wired; across a network:

  • Addressing: the destination must be named explicitly.
  • Connection setup needs care: the network can store packets and deliver old duplicates late (5.4).
  • Buffering: a host may hold hundreds of connections at once, so it cannot keep one fixed buffer per line (5.5).

Quality of service parameters a transport user may ask for, in the classic OSI list: connection establishment delay, connection establishment failure probability, throughput, transit delay, residual error ratio, protection, priority and resilience. The internet's transport protocols promise none of them as numbers; they simply do their best.

In the exam "Services provided to the upper layer" wants the two types with this table and one example of each (TCP for web pages, UDP for DNS); a line on the primitives adds depth.

5.2Transport protocols: UDP and TCP

UDP: the 8-byte header, its features, and why an unreliable protocol is used HOT 6/27

82 Bh · 82 Ba · 81 Ba · 79 Bh · 70 Ch · 66 Po2+2+42+3+33+3

UDP User Datagram Protocol (RFC 768, 1980): a connectionless, unreliable transport protocol that adds to IP only port numbers, a length and a checksum, in an 8-byte header. Each application message travels as one independent datagram: no handshake, no acknowledgement, no retransmission, no ordering, and no flow or congestion control.

The whole header is four 16-bit fields. That is all UDP adds to IP: enough to reach the right process and to notice a damaged datagram.

THE UDP HEADER (RFC 768) Eight bytes: four 16-bit fields. The checksum also covers a pseudo-header taken from IP. 0 15 16 31 Source port 16 bits, 0 when not used Destination port 16 bits, the receiving process Length header + data in bytes, at least 8 Checksum optional in IPv4, mandatory in IPv6 Data: the application message, up to 65,507 bytes over IPv4 header 8 bytes PSEUDO-HEADER (IPv4): ONLY FOR THE CHECKSUM, NEVER SENT Source IP address 32 bits, from the IP header Destination IP address 32 bits Zero 8 bits Protocol 17 = UDP UDP length 16 bits, same as Length 12 bytes INSIDE AN IP DATAGRAM IP header 20 bytes or more, protocol = 17 UDP header 8 bytes UDP data the message The UDP datagram (header + data) is the IP datagram's payload.
FieldBitsWhat it carries
Source port16the sending process's port, where any reply should go; optional: 0 when no reply is wanted
Destination port16the receiving process; always present
Length16the whole datagram in bytes, header plus data: at least 8 (a header alone), at most 65,535; over IPv4, whose header takes at least 20 bytes, that leaves at most 65,507 bytes of data
Checksum16a one's complement checksum over a pseudo-header, the UDP header and the data (checksums); optional in IPv4, where 0 means not computed (a computed 0 is sent as all ones), mandatory in IPv6

The pseudo-header is 12 bytes built from the IP header for the checksum only and never sent: source IP address, destination IP address, a zero byte, the protocol number 17 and the UDP length. Including the addresses means that a datagram delivered to the wrong host, or handed to the wrong protocol, fails the check.

Worked example: the header of one DNS query

A laptop asks its resolver for the address of ioe.edu.np. The DNS message is 28 bytes: a 12-byte DNS header and a 16-byte question (the name coded as 3ioe3edu2np0, 12 bytes, plus 2 bytes of type and 2 of class). The operating system picks the free port 50000.

Source port        50000          = 0xC350
Destination port   53 (DNS)       = 0x0035
Length             8 + 28 = 36    = 0x0024
Checksum           over the pseudo-header, the header and the 28 bytes

On the wire:  C3 50  00 35  00 24  (checksum)  then the 28 bytes of DNS

The IP datagram that carries it has protocol 17 and total length 20 + 36 = 56 bytes. One datagram goes out and one comes back: no handshake, no acknowledgement. If the answer does not come, the resolver simply asks again.

Features of UDP:

  • Connectionless: no setup and no release; the first datagram already carries data.
  • Unreliable (best effort): no acknowledgement and no retransmission; a lost datagram is simply lost.
  • No ordering: datagrams may arrive in any order.
  • Message-oriented: each send is one datagram and its boundaries are kept, unlike TCP's byte stream.
  • No flow or congestion control: it sends as fast as the application writes.
  • Small overhead: 8 bytes of header against TCP's 20 to 60.
  • Stateless: the server keeps nothing per client, so one server can answer very many clients.
  • Broadcast and multicast: supported; TCP is unicast only.
  • Error detection only: a datagram that fails the checksum is silently dropped, never repaired.

Why it is used though it is unreliable. Unreliable here means "promises nothing", not "usually fails": most datagrams arrive. For many jobs, TCP's guarantees cost more than they give:

  1. Speed: no handshake, so a DNS lookup takes one round trip; over TCP the handshake alone would take another.
  2. Timeliness over completeness: in a voice or video call or a game, a late packet is useless. TCP would hold back all newer data until the lost piece was resent (head-of-line blocking); UDP lets the application skip the gap.
  3. Small and stateless: fewer bytes per message and no per-client state, which suits busy servers and small devices.
  4. Broadcast and multicast: DHCP must broadcast before the host has an address, and IPTV sends one stream to many receivers.
  5. The application adds only the reliability it needs: DNS retries, TFTP waits for an acknowledgement of each block, and QUIC, under HTTP/3, builds its own reliable, encrypted streams on top of UDP.

To remember it, think of live cricket commentary on the radio. If the line crackles for a second, nobody wants that second replayed later, because the next ball matters more: that is UDP's kind of traffic. A downloaded file of the match highlights must arrive whole, every byte: that is TCP's.

Where UDP is preferred, with practical examples:

ApplicationPortWhy UDP
DNS queries53one small question, one answer; the client retries itself
DHCP67 server, 68 clientthe client has no IP address yet, so it must broadcast (DHCP)
Voice and video calls (VoIP, carried by RTP)chosen per calllate audio is useless; a few lost milliseconds are barely heard
Online multiplayer gamesthe game's ownonly the newest position counts, not an old one resent
Live TV over IP (IPTV)multicastone stream to many viewers at once
SNMP, NTP, TFTP, RIP, syslog161, 123, 69, 520, 514short messages, simple devices, the application handles loss
QUIC (HTTP/3)443its own reliability and encryption, without TCP's handshake and head-of-line blocking

Recorded video is different: a video watched on demand is usually sent over TCP (or QUIC) with a large playback buffer, since a few seconds of waiting at the start are acceptable and every frame should arrive.

The book says. Table 5.1 says UDP has "no flow control mechanism so unsecured communication"; the word meant is unreliable. Neither TCP nor UDP encrypts anything: that is TLS's job (SSL and TLS).
Asked on the paper, word for word
  • Write UDP header field and functions. Explain TCP 3-way hand shaking for connection establishment and release. 2082 Bhadra Q6 · 2+3+3
  • Discuss UDP header and compare it with TCP. What is port address? Explain briefly about leaky-bucket algorithm used for traffic shaping. 2082 Baishakh Q6 · 2+2+4
  • Though UDP is said to be unreliable protocol, it is used in Internet. Why? Explain the three way handshake principle of a TCP connection between client and server. 2081 Baishakh Q6 · 3+5
  • What are the features of UDP protocol? In which case is UDP preferred as a transport layer protocol? Discuss with practical examples. 2079 Bhadra Q6 · 4+4
  • Explain the UDP segment structure. Illustrate your answer with appropriate figures. 2070 Chaitra Q6 · 8
  • Write short notes on (any two): a) UDP and its application b) Network Devices: Hubs, Switches and Routers c) IPv4 Header Structure 2066 Poush Q10 · 3+3
In the exam "UDP header" or "UDP segment structure" wants the 32-bit drawing with the four fields, a line on each, the pseudo-header and the encapsulation in IP. "Why is UDP used though unreliable" wants the five reasons with an example each; "where is UDP preferred" wants the applications table.

TCP: the reliable byte stream, its segment header, and how reliability is provided TOP 9/27

81 Bh · 76 Ash · 75 Ash · 74 Ash · 72 Ch · 72 Ka · 70 Asa · 68 Ch · 68 Ba3+54+42+2+4

TCP Transmission Control Protocol (RFC 9293, 2022, which replaced RFC 793 of 1981): a connection-oriented, reliable, full-duplex byte-stream transport protocol. It numbers every byte it sends, acknowledges and retransmits, puts data back in order, and controls flow and congestion, so that the receiving process gets exactly the bytes that were sent, in the same order.

A TCP connection is a logical, full-duplex, point-to-point association between two sockets, named by four values: source IP, source port, destination IP, destination port.

  • Its state lives only in the two end hosts: the sequence numbers, windows, buffers and timers, kept in a transmission control block (TCB).
  • The routers know nothing of it: they see independent IP packets, so a TCP connection is a virtual connection, not a reserved circuit (switching).

Features of TCP:

  • Connection-oriented: a three-way handshake before data, a graceful release after (5.4).
  • Reliable and ordered: nothing lost, nothing repeated, nothing out of order.
  • Byte stream: no message boundaries. If an application writes 100 bytes three times, the receiver may read all 300 at once, or 150 and 150.
  • Full duplex, point to point: data flows both ways at once between exactly two endpoints, and an ACK can ride on a data segment going the other way (piggybacking). No broadcast or multicast.
  • Flow control and congestion control: the receive window protects the receiver (5.5), the congestion window protects the network (5.7).
  • Mandatory checksum over a pseudo-header (with protocol 6), the header and the data.

The segment structure. A TCP segment is a header of 20 to 60 bytes followed by the data. The fixed part is five 32-bit rows; options, if any, follow in multiples of 4 bytes.

THE TCP HEADER (RFC 9293) Twenty bytes fixed, then 0 to 40 bytes of options; each row is 32 bits. 0 4 8 15 16 31 Source port 16 bits Destination port 16 bits Sequence number 32 bits: number of the first data byte (the ISN on a SYN) Acknowledgement number 32 bits: next byte expected, valid when ACK = 1 HLEN 4 bits Reserved 4 bits Window size 16 bits: receive window, bytes C W R E C E U R G A C K P S H R S T S Y N F I N Checksum pseudo-header, header and data Urgent pointer valid when URG = 1 Options and padding MSS, window scale, SACK permitted, SACK, timestamps Data: the bytes this segment carries fixed header, 20 bytes 0 to 40 bytes Flags: CWR and ECE explicit congestion notification; URG urgent data; ACK ack field valid; PSH push now; RST reset; SYN open, synchronize sequence numbers; FIN close, sender has finished. RFC 793 (1981) drew 6 reserved bits and 6 flags; RFC 3168 (2001) took two reserved bits for CWR and ECE.
FieldBitsWhat it carries
Source port16the sending process
Destination port16the receiving process
Sequence number32the number of the first data byte in this segment; on a SYN, the initial sequence number (ISN)
Acknowledgement number32the next byte the sender of this segment expects to receive; valid when ACK = 1
Header length (HLEN, data offset)4header length in 32-bit words, 5 to 15, so 20 to 60 bytes
Reserved4 (6 in RFC 793)zero, kept for future use
Flags8 (6 in RFC 793)CWR, ECE, URG, ACK, PSH, RST, SYN, FIN, one bit each
Window size16the receive window: how many more bytes the sender of this segment can accept
Checksum16error detection over the pseudo-header, header and data; mandatory
Urgent pointer16valid when URG = 1: the offset from the sequence number to the end of the urgent data
Options and padding0 to 3200 to 40 bytes: MSS, window scale, SACK permitted, SACK, timestamps; padded to a 32-bit boundary

The flags, one bit each:

  • SYN: synchronize sequence numbers; set only on the first segment from each side, to open a connection.
  • ACK: the acknowledgement number is valid; set on every segment after the first SYN.
  • FIN: the sender has finished sending; closes its direction.
  • RST: reset: abort the connection at once, or refuse a SYN sent to a port where nothing listens.
  • PSH: push: hand the data to the application now, without waiting to fill a buffer (for example a keystroke in SSH).
  • URG: the urgent pointer is valid: some data at the start is urgent, such as an interrupt key.
  • CWR and ECE: explicit congestion notification (RFC 3168): a router marks congestion instead of dropping, and the sender slows down.

The options are agreed mostly in the SYN segments:

  • MSS (maximum segment size): the largest data a host will take in one segment; 1460 bytes on Ethernet (1500 minus 20 of IP header and 20 of TCP header); 536 bytes is assumed for IPv4 when no option is sent.
  • Window scale: multiplies the 16-bit window by up to 214, for windows up to about 1 GB.
  • SACK: selective acknowledgement of blocks that arrived out of order.
  • Timestamps: to measure the round-trip time.

The sequence space is 32 bits: it counts 4,294,967,296 bytes and then wraps round. The ISN is picked at random.

Worked example: reading the header of a SYN

A laptop opens a connection to a web server. The first 20 bytes of its SYN segment, in hexadecimal:

C3 50 00 50 | 00 00 1F 40 | 00 00 00 00 | A0 02 FA F0 | (checksum) 00 00

C3 50        source port        50000 (a free port the client picked)
00 50        destination port   80 (HTTP)
00 00 1F 40  sequence number    8000, the client's ISN
00 00 00 00  ack number         0, not valid: the ACK flag is off
A            header length      10 words = 40 bytes, so 20 bytes of options follow
0            reserved           0000
02           flags              0000 0010: only SYN is set
FA F0        window             64,240 bytes the client can receive
00 00        urgent pointer     0, not used

So this is a SYN from port 50000 to port 80, ISN 8000, with a 40-byte header whose options carry the MSS and the like.

Why TCP is called reliable: IP underneath may lose, corrupt, duplicate or reorder packets, yet TCP promises the application every byte, once, in order, or a clear error. It keeps that promise with these mechanisms (the lost-segment example on the transport service card shows them working together):

  1. Connection establishment: the handshake makes sure both sides are ready and agree the starting sequence numbers.
  2. Sequence numbers on every byte: the receiver detects gaps, puts segments back in order and throws away duplicates.
  3. Positive, cumulative acknowledgements: each ACK names the next byte expected, so one ACK confirms everything before it.
  4. Retransmission on timeout: the sender keeps a copy of each unacknowledged segment and a timer; if no ACK comes within the retransmission timeout (RTO), it resends and doubles the timeout.
  5. Fast retransmit: three duplicate ACKs mean a segment is missing, so it is resent at once without waiting for the timer.
  6. Checksum: a damaged segment is discarded, and so is recovered like a lost one.
  7. Flow control: the receive window stops the sender from overflowing the receiver, which would throw data away.
  8. Congestion control: slow start and the congestion window stop the senders from overflowing the routers.
  9. Graceful release: FIN and its ACK in each direction, so no data is cut off at the end.

How the timer is set: TCP measures the round-trip time R of segments and keeps a smoothed average SRTT and its variation RTTVAR (RFC 6298, which updates RTTVAR first, with the old SRTT):

RTTVAR←34RTTVAR+14|SRTT−R|,SRTT←78SRTT+18R
RTO=SRTT+4×RTTVAR

So the timeout follows the network: a short, steady path gets a short timeout; a long, jittery one gets a longer one, which avoids resending segments that are only late.

To remember it, think of sending exam forms by courier to the campus office: every page is numbered (sequence numbers), the office phones to say "got pages 1 to 20, send 21 next" (cumulative ACK), any page not confirmed in time is sent again (timer and retransmission), and a torn page is treated as missing (checksum).

The book says. Three points in its TCP pages need care:
  • Flags: Figure 5.4 shows six flags with the reserved bits unlabelled, RFC 793's layout with 6 reserved bits; RFC 9293 has 4 reserved bits and 8 flags, since RFC 3168 (2001) took two for CWR and ECE. Either drawing earns the marks if each row adds up to 32 bits.
  • Window: it calls the window "the window size of the sending TCP"; precisely, it is the receive window that the sender of the segment advertises.
  • Options: it says options provide "congestion control"; the options are MSS, window scale, SACK and timestamps, and congestion control works through TCP's window.
Asked on the paper, word for word
  • Why TCP is known as reliable protocol? What are the congestion control techniques applied in network communication? Discuss Token Bucket approach and compare it with leaky bucket. 2081 Bhadra Q6 · 2+2+4
  • Explain the TCP segment structure. Why TCP is known as reliable protocol and also describe how reliability is provided by TCP? 2076 Ashwin Q6 · 4+4
  • What are the differences between TCP and UDP services? Explain the TCP datagram format in detail. 2075 Ashwin Q6 · 3+5
  • Explain the TCP protocol with its Header. What do you understand by socket? Explain with its importance. 2074 Ashwin Q6 · 5+3
  • For the client-server application over TCP, why must the server program be executed before the client program? TCP is known as reliable process how, describe reliability is provided by TCP. 2072 Chaitra Q6 · 3+5
  • What is a TCP connection? Explain how a TCP connection can be gracefully terminated. 2072 Kartik Q6 · 2+6
  • Write short notes on: a) ALOHA system b) TCP header 2070 Ashad Q10 · 4+4
  • What are the differences between TCP and UDP services? Explain the TCP datagram format in detail. 2068 Chaitra Q7 · 3+5
  • What are the functions of transport layer? Draw the segment structure of TCP. 2068 Baishakh Q5 · 3+5
In the exam For the header (segment or "datagram" format), draw the 32-bit grid with every field and its width, then one line a field; for the TCP protocol "with its header", put four or five features first. For "why reliable" (2 marks), say it guarantees complete, ordered, error-free delivery over unreliable IP; for "how", list the mechanisms and add the lost-segment drawing.

TCP against UDP, and why the transport layer has two protocols HOT 6/27

82 Ba · 75 Ash · 71 Ch · 71 Shr · 69 Ch · 68 Ch3+51+2+52+2+4

TCP and UDP The two transport protocols of the TCP/IP suite, and a trade between reliability and speed: TCP buys a reliable, ordered, connection-oriented byte stream with a handshake, a bigger header and waiting; UDP gives up every guarantee for no setup, an 8-byte header and no waiting.
PointTCPUDP
Connectionconnection-oriented: handshake, then releaseconnectionless
Reliabilityreliable: acknowledgements and retransmissionunreliable: no ACK, no retransmission
Orderdelivered in order (sequence numbers)no ordering
Data unitsegment; a byte stream with no boundariesuser datagram; each message kept whole
Header20 to 60 bytes8 bytes
Flow and congestion controlyes: receive window, congestion windownone
Error checkingmandatory checksum; errors repaired by retransmissionchecksum (optional in IPv4); a bad datagram is just dropped
Speed and delayslower: a round trip to set up, waits for lost datafaster: sends at once, never waits
Castingunicast onlyunicast, broadcast and multicast
State at the servera TCB and buffers per connectionnone
IP protocol number617
Used byHTTP and HTTPS (80, 443), SMTP (25), FTP (20, 21), SSH (22), Telnet (23)DNS (53), DHCP (67, 68), SNMP (161), TFTP (69), NTP (123), voice and video calls, games, QUIC

To remember it: TCP is a phone call home. It rings, someone says "hello", you say "hajur, bhannus" before anything else (the handshake), and when a word is lost you ask "feri bhannu ta?" (retransmission). UDP is shouting the cricket score down the hostel corridor: no setup, nobody answers, and if one shout is missed the next one carries the new score anyway.

Why two transport protocols, when the internet layer has only one? The question asks why diversity is useful at the top of the stack and harmful in the middle.

WHY ONE IP BUT TWO TRANSPORTS Many applications above, many links below, one protocol at the waist that every router speaks. Applications HTTP, SMTP, FTP, SSH | DNS, DHCP, voice calls, games TCP reliable stream UDP fast datagrams IP Link technologies Ethernet, WiFi, 4G and 5G, fibre, DSL Many applications, each with its own needs Two services to choose from: reliable or fast; run only in the two end hosts One protocol that every router must run: best-effort, host to host Any link technology can carry IP A new transport (QUIC, built over UDP) needs only the end hosts to change; a new network protocol needs every router to change, which is why IPv6 is slow to spread.
  1. Applications want opposite things: a file transfer or a web page must arrive complete and in order, whatever the delay; a voice call must arrive on time, whatever is lost. One protocol cannot give both, because recovering a loss means waiting, and waiting is exactly what real-time traffic cannot do.
  2. The transport layer runs only in the end hosts (the end-to-end principle: put reliability where it is needed, at the ends). Two choices there cost the routers nothing.
  3. IP is the common meeting point: every router of every network must understand the network protocol, and every link technology (Ethernet, WiFi, 4G, fibre) must be able to carry it. One protocol, with a minimal best-effort service that any network can offer, is what lets any host reach any other: the narrow waist of the hourglass.
  4. Changing the waist is very costly: a new transport protocol needs only the end hosts to change, but a new network protocol needs every router to change. IPv6 shows the cost: decades into its rollout, IPv4 still carries much of the traffic (IPv4 to IPv6 transition).
  5. UDP keeps the door open: it exposes IP's raw service with ports added, so any application that wants its own reliability can build it, as QUIC does, without touching the network.
Strictly speaking. The transport layer has more than two protocols: SCTP (RFC 9260) and DCCP (RFC 4340) exist, and QUIC (RFC 9000) runs over UDP. And the internet layer now has two versions, IPv4 and IPv6, plus helpers such as ICMP that ride inside IP. The question's point stands: TCP and UDP carry nearly all application data, and one routed protocol, IP, carries both.
Asked on the paper, word for word
  • Discuss UDP header and compare it with TCP. What is port address? Explain briefly about leaky-bucket algorithm used for traffic shaping. 2082 Baishakh Q6 · 2+2+4
  • What are the differences between TCP and UDP services? Explain the TCP datagram format in detail. 2075 Ashwin Q6 · 3+5
  • Why port number is used in networking? What are the services of transport layer? Differentiate between TCP and UDP protocol. 2071 Chaitra Q6 · 1+2+5
  • Distinguish between TCP and UDP. How is TCP connection established? Explain. 2071 Shrawan Q6 · 3+5
  • Why do you think that there exist two protocols in transport layer where as there exists only one protocol in Internet layer in TCP/IP reference model. Explain token bucket algorithm for congestion control. 2069 Chaitra Q6 · 5+3
  • What are the differences between TCP and UDP services? Explain the TCP datagram format in detail. 2068 Chaitra Q7 · 3+5
In the exam A "difference" question wants the table, eight to ten rows, with applications in the last row. "Why two protocols in the transport layer but one in the internet layer" wants the reasons above with the hourglass drawn.

5.3Port and socket

Ports and sockets: how a segment finds its process PIN 4/27

82 Ba · 80 Ba · 74 Ash · 71 Ch1+2+52+2+42+4+2

Port number and socket A port number (port address) is a 16-bit number, 0 to 65,535, carried in every TCP and UDP header, that names a process on a host. A socket (socket address) is an IP address with a port, such as 203.0.113.5:80; one TCP connection is named by a pair of sockets.

Why port numbers are needed. An IP address brings data to a host, but a host runs many processes at once: a browser, a mail client, a game. Arrival at the host is not the end of the journey; the data must reach one process, so each process needs a label of its own. The book counts four levels of address in TCP/IP, one per layer:

AddressLayerSizeNamesExample
Physical (MAC)data link48 bitsa network card on one link; changes hop to hop00:1A:2B:3C:4D:5E
Logical (IP)network32 bits (IPv4)a host anywhere on the internet; stays the same end to end203.0.113.5
Porttransport16 bitsa process on that host80
Application-specificapplicationvariesa user or a document, turned into the others before sendingan e-mail address, a URL

To remember it, think of a campus phone system. The college has one phone number (the IP address) and internal extensions: one for the accounts section, another for the exam section (ports). The extension numbers are printed on the notice board, so nobody has to ask (well-known ports). Whoever calls in is given a line for the length of the call (an ephemeral port).

The three ranges set by IANA (RFC 6335):

PORT RANGES AND SOCKET PAIRS A port is 16 bits (0 to 65,535); a socket is an IP address plus a port; a TCP connection is a pair of sockets. Well-known (system) 0 to 1023, assigned by IANA 22 SSH, 25 SMTP, 53 DNS, 80 HTTP, 443 HTTPS Registered (user) 1024 to 49151, registered with IANA 3306 MySQL, 3389 RDP, 8080 HTTP alternate Dynamic (private, ephemeral) 49152 to 65535, never assigned picked by a client for one connection, then freed CLIENT SOCKETS ONE SERVER, ONE LISTENING PORT Web server 203.0.113.5 listening socket: port 80, and one socket per connection (its 4-tuple): Laptop, browser tab 1 198.51.100.10 : 52344 (198.51.100.10, 52344, 203.0.113.5, 80) Laptop, browser tab 2 198.51.100.10 : 52345 (198.51.100.10, 52345, 203.0.113.5, 80) Phone, browser 198.51.100.20 : 49200 (198.51.100.20, 49200, 203.0.113.5, 80) All three reach port 80; the server separates them by the client's IP address and port.
RangeNumbersWho sets themExamples
Well-known (system)0 to 1023assigned by IANA to standard services; on Unix only the administrator (root) may open them22 SSH, 25 SMTP, 53 DNS, 80 HTTP, 443 HTTPS
Registered (user)1024 to 49151registered with IANA by vendors to avoid clashes, but not controlled3306 MySQL, 3389 Remote Desktop, 8080 HTTP alternate
Dynamic (private, ephemeral)49152 to 65535never assigned; free for anyonea client's temporary port for one connection
ServiceTransportPortServiceTransportPort
FTP data, controlTCP20, 21POP3TCP110
SSHTCP22NTPUDP123
TelnetTCP23IMAPTCP143
SMTPTCP25SNMP, SNMP trapUDP161, 162
DNSUDP and TCP53BGPTCP179
DHCP server, clientUDP67, 68HTTPSTCP (and UDP for QUIC)443
TFTPUDP69RIPUDP520
HTTPTCP80

Clients use ephemeral ports. When a browser opens a connection, the operating system gives it a free port for that connection only (Windows uses the IANA range 49152 to 65535; Linux by default 32768 to 60999). No standard is needed: the server reads the client's port from the SYN and replies to it.

Why the well-known ports are standardized:

  1. A meeting point known in advance: a client must know where to knock before any conversation starts. It learns the server's IP address from DNS, but nothing tells it the port, so the port must be agreed beforehand: every browser knows a web server is on 80 (443 for HTTPS), every mail server knows to reach another on 25.
  2. Interoperability: any client from any vendor reaches any server with no configuration and no extra lookup step.
  3. Defaults in software: a URL such as http://ioe.edu.np/ carries no port because port 80 is implied.
  4. Administration and security: firewalls, NAT rules and intrusion detection are written per port (allow 443, block 23), and on Unix only the administrator can open a port below 1024, so a client knows a system service, not an ordinary user's program, is listening there.
  5. No clashes: one registry means two services never claim the same number.

A web service on port 8765 instead of 80. TCP does not care: the server works as well on 8765. What changes is how clients find it:

  • The port must be written in the address: http://www.example.com:8765/. Typed without it, the browser connects to port 80; if nothing listens there, the server's TCP answers the SYN with RST and the browser shows that the connection was refused. If some other service listens on 80, that service answers instead.
  • Every link, bookmark and search result must carry the port, and users must be told it.
  • Firewalls may block it: many office and campus networks let out only 80 and 443.
  • It is no real protection: hiding a service on an odd port is security through obscurity; a port scanner finds it in seconds.
  • It has one convenience: 8765 is above 1023, so an ordinary user can run the server without administrator rights. A student testing a site runs python -m http.server 8765 and browses http://localhost:8765/.

The socket and its importance. The word has two meanings that belong together:

  • The address: socket = IP address : port, with the protocol. A TCP connection is the pair of sockets, the four-tuple (source IP, source port, destination IP, destination port), so one server socket 203.0.113.5:80 can hold thousands of connections at once: each client socket differs in IP address or port.
  • The programming interface: the socket is also the door between an application and the transport layer in the host, the API (Berkeley sockets) through which every network program sends and receives. The application controls everything on its side of the door; on the transport side it chooses only the protocol (TCP or UDP) and a few settings such as buffer sizes and the maximum segment size.
  • Why it matters: it identifies one process uniquely across the whole internet, lets many connections share one server port, separates the traffic of each connection, and is the interface on which every network application is written (socket programming).
The book says. Table 5.2 lists ICMP 1, IPv6 41, OSPF 89 and "17/6" for IP beside real port numbers. Those are IP protocol numbers, the value of the protocol field of the IPv4 header: ICMP, IPv6 carried in IPv4, and OSPF run directly on IP and have no port, and 17 and 6 are UDP and TCP themselves. Its socket example also writes port 96 in the text while Figure 5.7 shows port 69 (the TFTP port).
Asked on the paper, word for word
  • Discuss UDP header and compare it with TCP. What is port address? Explain briefly about leaky-bucket algorithm used for traffic shaping. 2082 Baishakh Q6 · 2+2+4
  • What is port number? Why is it necessary to standardize the port numbers for well-known servers? What happens when a web service is hosted at some different port such as 8765 instead of 80? Explain. 2080 Baishakh Q6 · 2+4+2
  • Explain the TCP protocol with its Header. What do you understand by socket? Explain with its importance. 2074 Ashwin Q6 · 5+3
  • Why port number is used in networking? What are the services of transport layer? Differentiate between TCP and UDP protocol. 2071 Chaitra Q6 · 1+2+5
In the exam "What is a port number" (1 or 2 marks): the definition, 16 bits, and why (many processes per host). "Why standardize well-known ports" (4 marks): the five reasons, with 80 and 25 as examples. "Port 8765" (2 marks): it works, but the port must be given in the URL, else port 80 is tried and refused. "Socket and its importance": both meanings, the socket pair, and the API.

5.4Connection establishment and release

Opening and closing a TCP connection: the three-way handshake and the graceful release HOT 7/27

82 Bh · 81 Ba · 75 Ch · 74 Ch · 72 Ch · 72 Ka · 71 Shr3+54+42+3+3

Three-way handshake TCP's connection establishment in three segments: SYN (the client's initial sequence number x), SYN + ACK (the server's initial sequence number y, acknowledging x + 1) and ACK (acknowledging y + 1). It synchronizes both sequence numbers and proves both sides are ready. The release is graceful: each direction is closed on its own by a FIN and its ACK, four segments in all.

Passive and active open. The two ends do not start alike. The server does a passive open: its program creates a socket, binds it to its well-known port, calls listen and waits in the LISTEN state. The client does an active open: it calls connect, which sends the first SYN.

Why the server program must run before the client. A shop must open its shutter before customers can walk in:

  • Only a socket in LISTEN accepts a SYN. If no program listens on the port when the SYN arrives, the server host's TCP answers with RST, and the client's connect fails at once with "connection refused".
  • TCP does not queue a SYN in the hope that a server appears later, so the server must be started first and be waiting.
  • UDP is no different: a datagram to a port with no socket is dropped, and the host returns an ICMP port unreachable message (ICMP).

The handshake, step by step, with the numbers of the book's own figure (client ISN 8000, server ISN 15000):

  1. SYN (client to server): SYN = 1, seq = 8000, no data. The client moves from CLOSED to SYN-SENT. A SYN uses up one sequence number, and it usually carries options such as the MSS and the window scale.
  2. SYN + ACK (server to client): SYN = 1, ACK = 1, seq = 15000, ack = 8001. The server allocates its buffers and connection record and moves from LISTEN to SYN-RECEIVED.
  3. ACK (client to server): ACK = 1, seq = 8001, ack = 15001. The client becomes ESTABLISHED on sending it, the server on receiving it. This third segment may already carry data.
THE THREE-WAY HANDSHAKE, THEN THE FIRST DATA Client ISN 8000, server ISN 15000 (the numbers of the book's figure). A SYN uses up one sequence number. Client active open: connect() Server passive open: listen() CLOSED LISTEN SYN-SENT SYN-RECEIVED ESTABLISHED ESTABLISHED socket, bind port 80, listen, wait for a SYN SYN seq = 8000 SYN + ACK seq = 15000, ack = 8001 ACK seq = 8001, ack = 15001 may carry data data seq = 8001 (1000 bytes), ack = 15001 next expected: 9001 data seq = 15001 (500 bytes), ack = 9001 next expected: 15501

Why three segments and not two:

  • Both starting numbers must be confirmed. Each side picks its own ISN and must know that the other received it: the SYN + ACK confirms the client's, the final ACK confirms the server's.
  • Old duplicates must not open connections. The network can delay a SYN from an earlier attempt and deliver it late. With a two-way scheme the server would open a connection nobody wants. With three, the server's SYN + ACK reaches the client, which recognizes an acknowledgement of a request it never made and answers RST, so the server drops it (the book's Figure 5.9).
  • The ISN is random, not 0, so that segments of an old connection on the same ports are not mistaken for new ones, and so an attacker cannot guess the numbers and inject data.

To remember it, think of a phone call home. "Hello Aama, can you hear me?" (SYN). "Yes, I can hear you; can you hear me?" (SYN + ACK). "Yes!" (ACK). Only now does the real talk start.

The SYN flood, an attack on the handshake: an attacker sends floods of SYNs from forged addresses and never sends the third ACK. Each half-open connection takes the server's memory until its queue is full and real clients are refused. Defences: SYN cookies (the server encodes the connection's details in its ISN and keeps no state until the ACK returns), shorter timeouts, and filtering at the firewall (firewalls).

The release, graceful and in four segments, continuing the same connection after the client sent 1,000 bytes (8001 to 9000) and the server 500 (15001 to 15500):

  1. FIN (client to server): seq = 9001, ack = 15501. The client application has finished sending; the client enters FIN-WAIT-1. A FIN uses up one sequence number, like a SYN.
  2. ACK (server to client): seq = 15501, ack = 9002. The server enters CLOSE-WAIT and tells its application; the client enters FIN-WAIT-2. The connection is now half-closed: the server may still send data to the client.
  3. FIN (server to client): seq = 15501, ack = 9002, when the server application closes too. The server enters LAST-ACK.
  4. ACK (client to server): seq = 9002, ack = 15502. The server closes on receiving it; the client waits in TIME-WAIT for twice the maximum segment lifetime (2 MSL), then closes.
GRACEFUL RELEASE IN FOUR SEGMENTS Each direction closes on its own (a half-close); the side that closes first waits 2 MSL in TIME-WAIT. Client closes first (active close) Server passive close ESTABLISHED ESTABLISHED FIN-WAIT-1 CLOSE-WAIT FIN-WAIT-2 LAST-ACK TIME-WAIT CLOSED CLOSED FIN seq = 9001, ack = 15501 tells its application ACK seq = 15501, ack = 9002 may still send data (half-closed) FIN seq = 15501, ack = 9002 ACK seq = 9002, ack = 15502 waits 2 MSL: re-ACKs a lost FIN, old segments die out

Why four segments: TCP is full duplex, so each direction is a separate stream that must be closed on its own; the side that has finished says FIN, the other acknowledges, and can keep sending until it is done too. When the server has nothing left to send, it may combine its ACK and FIN in one segment, and the release takes three segments.

Why TIME-WAIT: if the last ACK is lost, the server resends its FIN, and the client must still be there to acknowledge it again; and waiting lets any delayed segments of this connection die out, so a new connection on the same pair of ports cannot receive them. RFC 793 suggested an MSL of 2 minutes (TIME-WAIT of 4 minutes); real systems wait less, Linux for 60 seconds.

Abrupt release: RST ends a connection at once, without the exchange of FINs, and any data still in flight is lost: used when a program crashes or a segment arrives that matches no connection.

StateMeaningStateMeaning
CLOSEDno connectionFIN-WAIT-2own FIN acknowledged; waiting for the other side's FIN
LISTENserver waiting for a SYNCLOSE-WAITgot a FIN; waiting for the local application to close
SYN-SENTclient sent SYN; waiting for SYN + ACKLAST-ACKsent its own FIN after CLOSE-WAIT; waiting for the last ACK
SYN-RECEIVEDserver got SYN, sent SYN + ACK; waiting for ACKCLOSINGboth sides sent FIN at the same moment
ESTABLISHEDopen: data flows both waysTIME-WAITwaiting 2 MSL after the final ACK
FIN-WAIT-1sent FIN; waiting for its ACK
The book says. Figure 5.11 labels the client's third segment "seq: 8000, ack: 15001", and Figure 5.8 shows it as "Data (seq = x, ACK = y + 1)". In TCP the SYN has used up sequence number x, so the third segment carries seq = x + 1 (8001), as RFC 9293's own example does; the acknowledgement numbers in both figures are right.
Asked on the paper, word for word
  • Write UDP header field and functions. Explain TCP 3-way hand shaking for connection establishment and release. 2082 Bhadra Q6 · 2+3+3
  • Though UDP is said to be unreliable protocol, it is used in Internet. Why? Explain the three way handshake principle of a TCP connection between client and server. 2081 Baishakh Q6 · 3+5
  • Explain connection establishment and termination in TCP. Explain briefly about Leaky-Bucket algorithm for congestion control? 2075 Chaitra Q6 · 4+4
  • How connection is established and released in TCP. Explain Token Bucket algorithm. 2074 Chaitra Q6 · 4+4
  • For the client-server application over TCP, why must the server program be executed before the client program? TCP is known as reliable process how, describe reliability is provided by TCP. 2072 Chaitra Q6 · 3+5
  • What is a TCP connection? Explain how a TCP connection can be gracefully terminated. 2072 Kartik Q6 · 2+6
  • Distinguish between TCP and UDP. How is TCP connection established? Explain. 2071 Shrawan Q6 · 3+5
In the exam Draw the client and server time lines, the three segments with SYN, ACK, seq and ack, and the states; for release, the four segments with FIN, the half-close and TIME-WAIT. Numbers (8000, 15000) look better than letters, but x and y earn the same marks if every ack is right.

5.5Flow control and buffering

Flow control and buffering: TCP's sliding window PIN 2/27

78 Bh · 66 Bh2×43+3

Transport flow control End-to-end control that stops a fast sender from overflowing a slow receiver's buffer. TCP uses a byte-oriented sliding window: every segment advertises the receive window (rwnd), the free space left in the receiver's buffer, and the sender keeps at most that many bytes sent but not yet acknowledged.

Why the receiver needs protecting. The receiving application may read slowly (a busy phone, a program doing other work), so data piles up in TCP's receive buffer. If the sender kept going, the buffer would overflow and data would be thrown away. So the receiver tells the sender, in the window field of every segment it sends, how much more it can take.

The window on the byte stream. The sender sees its bytes in four groups: sent and acknowledged; sent but not yet acknowledged (in flight); not yet sent but allowed (the usable window); and not allowed until the window moves. The window's left edge is the last acknowledgement; its right edge is that plus rwnd.

TCP'S SLIDING WINDOW The receiver advertises rwnd in every segment; the sender may have at most rwnd bytes unacknowledged. 1001 2001 3001 4001 5001 6001 7001 8001 9001 window = rwnd = 4000 bytes: 3001 to 7000 sent, acknowledged in flight (sent, not ACKed) usable now cannot send yet byte ... An ACK arrives: ack = 5001, window = 4000. The window now covers bytes 5001 to 9000. 1001 2001 3001 4001 5001 6001 7001 8001 9001 window slides 2000 bytes right: 5001 to 9000 sent, acknowledged in flight usable now cannot send yet byte ... rwnd = 0 stops the sender; a persist timer then sends small probes until the window opens. With congestion control the sender's limit is min(rwnd, cwnd). The 16-bit field allows 65,535 bytes; window scaling allows more.
Worked example: the window slides
  1. Start: the last ACK was 3001 and rwnd = 4000, so the sender may have bytes 3001 to 7000 outstanding. It has sent up to 6000: 3,000 bytes are in flight and 1,000 more (6001 to 7000) may go now.
  2. An ACK arrives: ack = 5001, window = 4000. The left edge moves to 5001 and the window now covers 5001 to 9000: 1,000 bytes are in flight and 3,000 may be sent. The window has slid 2,000 bytes to the right.
  3. The application reads slowly: if the next ACK said ack = 5001 but window = 2000, the right edge would stay at 7000: only 1,000 bytes could go.
  4. The buffer fills: window = 0 stops the sender. It then sends small window probes on a persist timer until the receiver advertises space again; without them, a lost window update would leave both sides waiting for ever.

To remember it, think of a water tanker filling a household tank: the driver asks how much room is left before pumping, and pumps no more than that; as the family uses water, the room grows and he can pump again. The tank's free space is the receive window.

Two refinements:

  • Silly window syndrome: if a receiver frees one byte at a time and advertises one-byte windows, the sender sends one-byte segments with 40 bytes of headers each. Clark's fix: the receiver waits to advertise until it can take a full segment or half its buffer. Nagle's algorithm (RFC 896): a sender with small pieces of data sends one and holds the rest until it is acknowledged or a full segment has gathered.
  • Window scaling: the 16-bit field allows only 65,535 bytes, and a sender can send at most one window per round trip. With a 100 ms round trip that caps a connection at 65,535 × 8 / 0.1, about 5.24 Mbps, however fast the line. A 100 Mbps path with a 100 ms round trip needs 100,000,000 × 0.1 / 8 = 1,250,000 bytes in flight (the bandwidth-delay product), so the window scale option multiplies the field by up to 214.

With congestion control, the sender's real limit is the smaller of the two windows: min(rwnd, cwnd), where cwnd is its own estimate of what the network can take (5.7).

Buffering. A host may have hundreds of connections at once, so the data link layer's habit of one fixed set of buffers per line does not work. Buffer space is shared, and its size is agreed at connection setup and adjusted as the receiver advertises. The book gives three ways to organize it:

SchemeHowGood forWeakness
Chained fixed-size buffersa pool of identical buffers, one segment (TPDU) eachsegments all about the same sizea small segment wastes most of a buffer; a big one needs several
Chained variable-size bufferseach buffer cut to fit its segmentsizes that vary from a few bytes to thousandsharder memory management
One large circular buffer per connectiona ring the connection's data flows roundbusy connections that keep it fullwastes memory on lightly loaded connections

Where to buffer depends on the traffic: for low-rate, bursty traffic such as an interactive terminal it is better to buffer at the sender and let the receiver grab buffers when data arrives; for bulk transfer such as a file download the receiver should set aside a full window of buffers, so the data can flow at full speed.

PointLink-level sliding window (chapter 3)TCP's window
Countsframesbytes
Sequence numberssmall, such as 3 bits (0 to 7)32 bits
Window sizefixed when the protocol is set upchanges in every segment: the receiver advertises it
Scopeone link, hop by hopend to end, across many networks
Recoverygo-back-N or selective repeat (ARQ)cumulative ACKs like go-back-N, but early segments are kept and SACK resends only gaps, like selective repeat
Asked on the paper, word for word
  • Write short notes on: (Any Two) a) Frame relay b) TCP sliding window c) HDLC 2078 Bhadra Q10 · 2×4
  • Write short notes on (any two) i) TCP Sliding Window Protocol ii) Secrete Key Algorithm: DES iii) ISDN Signaling and ATM AAL iv) ICMP Message Types 2066 Bhadra Q5b · 3+3
In the exam A short note on the TCP sliding window wants the definition, the four regions with the drawing, the window sliding on an ACK, the zero window, and one line on window scaling or silly windows. Buffering, if asked, is the three-scheme table.

5.6Multiplexing and demultiplexing

Multiplexing and demultiplexing: many processes, one IP address

Multiplexing and demultiplexing Multiplexing is the sender's job: gather data from many sockets, give each chunk a header with its source and destination ports, and pass all the segments to the one network layer. Demultiplexing is the receiver's: read the port numbers in each arriving segment and deliver its data to the right socket.

Every host does both all the time. A laptop with two browser tabs open and a DNS query in progress has three sockets but one IP address. Segments for all three arrive at that one address; the transport layer sorts them by port.

MULTIPLEXING AND DEMULTIPLEXING Sending: many sockets share one IP. Receiving: the port numbers in each header pick the socket. 1 Browser tab 1 TCP port 52344 2 Browser tab 2 TCP port 52345 3 DNS resolver UDP port 50000 Transport layer of 198.51.100.10 demultiplexing: read the ports, pick the socket IP: every segment arrives at 198.51.100.10 ARRIVING SEGMENTS 1 TCP from 203.0.113.5 : 80 to 198.51.100.10 : 52344 2 TCP from 203.0.113.5 : 80 to 198.51.100.10 : 52345 3 UDP from 198.51.100.53 : 53 to 198.51.100.10 : 50000 UDP picks its socket by destination IP and port alone (a 2-tuple): any sender reaching port 50000 lands in one socket. TCP picks by the 4-tuple (source IP, source port, destination IP, destination port): one socket per connection. Sending is the mirror image (multiplexing): data from all three sockets gets a header with its ports, and every segment leaves through the one IP address.
  • UDP demultiplexes by two values: destination IP and destination port. Datagrams from any number of senders to the same port land in the same socket, and the application tells them apart by their source addresses if it cares.
  • TCP demultiplexes by four values: source IP, source port, destination IP and destination port. A web server listening on port 80 has a separate socket for every client connection; two connections to port 80 differ in the client's IP address or port (socket pairs).

To remember it, think of the hostel's mail. One postbag arrives at the gate for the whole hostel (one IP address); the warden sorts it by room number into the residents' boxes (demultiplexing). In the morning the residents drop their letters in one outgoing bag, each with its own room number as the return address (multiplexing).

The older sense of the word, which the book also uses, is about network connections rather than processes:

  • Upward multiplexing: several transport connections share one network connection or address, which saves cost where network connections are scarce or charged for (as virtual circuits once were). Worth it while the shared bandwidth covers the needs of all.
  • Downward (inverse) multiplexing: one transport connection is spread over several network paths to add their bandwidth or survive a failure, as Multipath TCP (RFC 8684) and SCTP with several addresses do.

Not the physical layer's multiplexing: FDM and TDM share one cable among several signals (multiplexing in chapter 2); here it is one IP address shared by several processes, and the "channel number" is the port.

In the exam Define both in a line each, draw the processes, ports and one IP, and state the UDP two-value and TCP four-value rule with an example.

5.7Congestion control: the leaky bucket and the token bucket

Congestion: causes, the parameters that affect it, prevention and control PIN 4/27

81 Bh · 73 Shr · 66 Po · 66 Bh2+2+42+64+6

Congestion The state in which the load offered to a network, or to part of it, exceeds its capacity: router queues fill, delay climbs, packets are dropped and resent, and the useful throughput falls. In the worst case the network is busy carrying retransmissions and delivers almost nothing useful: congestion collapse.

Congestion control is not flow control. Flow control protects one receiver from one sender (5.5); congestion control protects the network, its links and router buffers, from all the senders together. A fast laptop sending to a slow phone needs flow control; a whole hostel uploading through one shared link needs congestion control.

To remember it, think of the day exam results come out. Thousands of students open the same results page within minutes. The links and the server have not changed, only the load, and pages that open in a second on other days time out; every refresh adds more load. That is congestion, and refreshing harder is the congestion collapse.

Causes, the factors behind congestion, in a WAN or any packet-switched network:

  • Arrival rate above the outgoing capacity: several input lines feeding one output line; the queue for that line grows without limit.
  • Too little buffer memory in routers, so packets are dropped when queues fill. Yet more memory is no cure: packets then wait so long that they time out and are resent as duplicates, adding load (Nagle, 1987).
  • Bursty traffic: many sources sending in bursts at once exceed capacity for a while, even when the average load is fine.
  • Slow processors and slow lines: a router that cannot queue, route and forward fast enough, or a low-bandwidth link, becomes the bottleneck.
  • Retransmissions: every lost or late packet is sent again, so congestion feeds itself.
  • Poor routing and long packet lifetimes: traffic piled onto one path while others stand idle, and old packets wandering about.

How the parameters affect it: the policies chosen at each layer push congestion up or down. Each row is a parameter a designer sets:

LayerPolicy (parameter)How it affects congestion
Transportretransmission policya hasty timer or go-back-N resends more, adding load
Transportout-of-order caching policythrowing away early segments forces them to be sent again
Transportacknowledgement policyan ACK for every segment adds traffic; delayed and piggybacked ACKs cut it
Transportflow control policya small window keeps the sending rate, and so the load, down
Transporttimeout determinationtoo short: needless duplicates; too long: slow recovery
Networkvirtual circuits against datagramscircuits allow admission control and reserved resources
Networkpacket queueing and service policyone queue or one per line, first come first served or fair turns
Networkpacket discard policywhich packet is dropped when a queue is full
Networkrouting algorithmspreading traffic over many paths relieves a hot spot
Networkpacket lifetime managementtoo long: old packets clog queues; too short: packets die and are resent
Data linkretransmission, out-of-order caching, acknowledgement and flow control policiesthe same effects as at the transport layer, on each link

Load and delay: queueing theory shows why delay explodes near capacity. For a link that can serve μ packets a second, fed λ packets a second at random (the M/M/1 queue), the average time a packet spends there is

T=1μ−λ

With μ = 1,000 packets per second: at λ = 500 a packet takes 2 ms; at 900, 10 ms; at 990, 100 ms. The last 10% of load costs ten times the delay, which is why networks are run well below full load.

Prevention policies (open loop: design the system so that congestion does not start):

  • Retransmission policy: good timers, so packets are not resent while merely late.
  • Window policy: selective repeat rather than go-back-N, so only the lost packet is resent.
  • Acknowledgement policy: cumulative, delayed and piggybacked ACKs, fewer packets in all.
  • Discard policy: routers drop the least important packets first, such as some packets of an audio stream, without harming quality much.
  • Admission policy: a virtual circuit network refuses a new flow that would congest it.
  • Traffic shaping: each source agrees a rate and burst size, and its traffic is smoothed to fit before entering the network: the leaky and token buckets (leaky bucket, token bucket).

The congestion control techniques come in two families:

FamilyIdeaTechniques
Open loop (prevention)good design, no feedbackthe policies above, admission control, traffic shaping with the leaky and token buckets, resource reservation
Closed loop (removal)monitor, feed the news back, adjustbackpressure (a congested router asks the router before it to slow down), choke packets sent to the source, implicit signalling (the source infers congestion from loss or delay, as TCP does), explicit signalling (ECN bits set by routers), load shedding (dropping packets), random early detection (RED: dropping a few packets early, before the queue is full)

Closed loop works in three steps: detect the congestion (queue lengths, drops, delay), send the information to the places that can act, and adjust the system (slow the sources).

TCP's own congestion control is the closed loop at the hosts (RFC 5681): the sender keeps a congestion window, cwnd, beside the receiver's window.

  • Slow start: cwnd begins small and doubles every round trip until it reaches a threshold.
  • Congestion avoidance: after that it grows by one segment per round trip (additive increase).
  • On three duplicate ACKs: it is halved (multiplicative decrease), with fast retransmit and fast recovery.
  • On a timeout: it drops back to one segment and slow start begins again.

Traffic shaping and policing. Shaping regulates the average rate and the burstiness of a flow before it enters the network, holding packets back to make it conform; policing only monitors a flow and drops (or tags) the packets that break its agreed profile. Both use the buckets that follow.

Asked on the paper, word for word
  • Why TCP is known as reliable protocol? What are the congestion control techniques applied in network communication? Discuss Token Bucket approach and compare it with leaky bucket. 2081 Bhadra Q6 · 2+2+4
  • Discuss about the network congestion? Explain how different network parameters effect the congestion. Compare operation of link state routing with the distance vector routing. 2073 Shrawan Q5 · 2+2+4
  • Describe the policies that help in preventing the congestions within the network? Differentiate between leaky bucket and token bucket algorithm with their operation and working of token bucket. 2066 Poush Q5 · 4+6
  • What are the factors that cause congestion within WAN? Propose your best traffic shaping approach to manage congestion in packet switched network. 2066 Bhadra Q4b · 2+6
In the exam "Network congestion" (2 marks): the definition and its effects. "Factors that cause it" or "parameters that affect it": the causes list, and the policy table for the second. "Policies that prevent it": the open-loop list. "Techniques": open against closed loop, with the buckets and TCP's slow start named.

The leaky bucket: bursty in, steady out HOT 5/27

82 Ba · 78 Bh · 75 Ch · 70 Asa · 66 Po3+52+2+44+4

Leaky bucket algorithm A traffic shaping algorithm in which each host's interface holds a finite queue (the bucket) that accepts packets at any rate but releases them into the network at a constant rate; a packet that arrives when the bucket is full is discarded.

The picture is a bucket with a small hole in the bottom. However fast water pours in, it leaves through the hole at the same steady rate while there is any in the bucket, and not at all when it is empty; once the bucket is full, more water spills over the side and is lost. Put packets for water and a host's interface queue for the bucket.

THE LEAKY BUCKET In at any rate, out through the hole at one steady rate; whatever overflows is lost. bursty input finite bucket, full overflow: lost constant output rate (a) water Host bursty Full? yes discard no queue (bucket) remove packets at a constant rate Network smooth Byte counting, for packets of different sizes: each tick allows n bytes; send while the next packet fits; what is left of n is not carried to the next tick. (b) packets at a host interface

The algorithm, for packets of one fixed size:

  1. A packet arrives from the host. If the bucket (queue) is full, the packet is discarded.
  2. Otherwise it joins the queue.
  3. At every clock tick, one packet leaves the head of the queue for the network; if the queue is empty, nothing leaves.
  4. The result: however bursty the input, the output is a smooth stream at the fixed rate, at most one packet per tick.

For packets of different sizes, count bytes instead (the book's version):

  1. At each tick, set a counter to n bytes.
  2. While the packet at the head fits (its size is not more than the counter), send it and subtract its size from the counter.
  3. When the next packet does not fit, stop until the next tick.
  4. Reset the counter at the next tick and go back to step 2. What was left of n is not carried forward, so no tick sends more than n bytes.
Worked example: byte counting, n = 1,000 bytes a tick

Four packets wait: 200, 700, 500 and 300 bytes.

  1. Tick 1: counter 1,000. Send 200 (800 left), send 700 (100 left); 500 does not fit in 100, so stop. 900 bytes went out; the 100 left over is lost, not saved.
  2. Tick 2: counter reset to 1,000. Send 500 (500 left), send 300 (200 left). The queue is empty.

And with fixed-size packets: a bucket that holds 6 packets and sends 1 per millisecond, hit by a burst of 10 packets at once, keeps 6 and discards 4; the 6 leave one per millisecond. The burst has been spread out, at the cost of 4 packets.

To remember it, think of the ceramic water filter found in many Nepali kitchens: pour a whole jug in at once, and clean water still drips from the tap at the same slow rate; pour in more than the top pot holds and it overflows.

What it is good at, and what it is not:

  • Good: it removes burstiness completely, so the network sees a predictable, constant-rate flow that is easy to plan for; it is simple, a queue and a clock.
  • Rigid: the output rate is the same when the network is idle and could take more; an idle host saves up nothing for later.
  • Lossy: a burst bigger than the bucket loses packets.
  • Slow to respond: a sudden burst of urgent data is still drained at the fixed rate. The token bucket fixes these (token bucket).
The book says. The implementation figure of the leaky bucket on page 185 is captioned "Figure 4.15" in a chapter whose figures are numbered 5.x; it is the chapter 5 leaky bucket figure.
Asked on the paper, word for word
  • Discuss UDP header and compare it with TCP. What is port address? Explain briefly about leaky-bucket algorithm used for traffic shaping. 2082 Baishakh Q6 · 2+2+4
  • What are services provided by Transport layer? Explain about Leaky-Bucket algorithm for congestion control? 2078 Bhadra Q6 · 3+5
  • Explain connection establishment and termination in TCP. Explain briefly about Leaky-Bucket algorithm for congestion control? 2075 Chaitra Q6 · 4+4
  • Compare between leaky bucket and token bucket algorithm with the operation how token bucket works. 2070 Ashad Q8 · 3+5
  • Describe the policies that help in preventing the congestions within the network? Differentiate between leaky bucket and token bucket algorithm with their operation and working of token bucket. 2066 Poush Q5 · 4+6
In the exam Draw the bucket (or the host, queue and "full? discard" flow), give the four steps, the byte-counting variant, and one line on its limits. A small numerical example like the one above earns the extra mark.

The token bucket: saving up permission to burst TOP 9/27

81 Bh · 80 Bh · 76 Ch · 74 Ch · 72 Ch · 70 Asa · 69 Ch · 66 Po · 66 Bh4+45+32+2+4

Token bucket algorithm A traffic shaping algorithm in which tokens drop into a bucket at a constant rate r, up to its capacity C, and a packet (or a byte) may leave only by taking a token. An idle host saves tokens, so it may later send a burst of up to C at the full line rate, while its long-run average stays at r.

The bucket holds permission, not data. The leaky bucket stores packets and lets them out at one rate. The token bucket stores tokens; packets wait in the host's queue and go as fast as the line allows while tokens last.

THE TOKEN BUCKET A token drops in every ΔT up to the capacity; a packet leaves only by taking one, so saved tokens allow a burst. Host T T T network (a) before: 3 tokens saved 5 packets waiting one token added every ΔT capacity 3, full: a new token is discarded Host network (b) after: a burst of 3 2 packets wait for new tokens 3 packets sent at once empty

The algorithm:

  1. Every ΔT seconds a token is added to the bucket (a rate r = 1/ΔT tokens a second). If the bucket already holds C tokens, the new token is thrown away.
  2. A packet may be sent only if a token is available; sending it removes one token (in the byte version, one token per byte, so a packet takes as many tokens as its size).
  3. With no token, the packet waits in the queue until one arrives. The bucket throws away tokens, never packets.
  4. The implementation is one counter: add 1 every ΔT (up to C), subtract 1 for every packet sent; while the counter is 0, nothing is sent.

The book's example: a host with 5 packets waiting and 3 saved tokens sends 3 packets at once, a burst; the other 2 wait for the next two tokens. A leaky bucket would have let the 5 out one tick apart.

How long can a burst last? Let C be the bucket capacity (in bits or bytes), r the token rate, M the maximum output rate of the line, and S the length of the burst in seconds. During the burst the host sends M·S. It can pay for that with the C tokens it had saved plus the rS that arrive during the burst:

C+rS=MS⟹S=CM−r
Worked example: a 12 Mb burst through each bucket

A router shapes a hostel's upload. Line rate M = 10 Mbps, token rate r = 2 Mbps, and the bucket is full with C = 6 Mb of tokens (750 KB). A student's laptop sends a 12 Mb file at full speed.

S=CM−r=610−2=0.75 s
  1. The burst: for 0.75 s the file goes at the full 10 Mbps, carrying 10 × 0.75 = 7.5 Mb. Check: the 6 Mb saved plus 2 × 0.75 = 1.5 Mb that arrived on the way make exactly 7.5 Mb.
  2. Then the average rate: the remaining 12 − 7.5 = 4.5 Mb goes at r = 2 Mbps, taking 2.25 s. The whole file is out after 0.75 + 2.25 = 3.0 s.
  3. A leaky bucket at the same 2 Mbps would take 12 / 2 = 6 s, and if it could hold only 6 Mb, 3.6 Mb of the burst would overflow and be lost.

Same average rate, same long-run load on the network; the token bucket finished in half the time and lost nothing.

ONE BURST OF 12 MEGABITS THROUGH EACH BUCKET Line rate M = 10 Mbps. Leaky bucket r = 2 Mbps. Token bucket r = 2 Mbps with C = 6 Mb of tokens saved. 10 Mbps 0 (a) Input the burst 10 0 (b) Leaky bucket r = 2 Mbps 10 0 (c) Token bucket C = 6 Mb, r = 2 Mbps 10 Mbps for 1.2 s = 12 Mb 2 Mbps for 6 s = 12 Mb: smooth, but slow S = C / (M − r) = 6 / 8 = 0.75 s at 10 Mbps (7.5 Mb) then 2 Mbps; done at 3.0 s 0 1 2 3 4 5 6 time (s) Same area each time: 10 × 1.2 = 2 × 6 = 10 × 0.75 + 2 × 2.25 = 12 Mb.

To remember it, think of meal coupons in a hostel mess: each student gets one coupon a day, and unused coupons pile up to at most three. On a hungry day after two light ones you can eat three meals at once (the burst), but over a month nobody eats more than one meal a day on average (the rate). The leaky bucket is a mess that serves exactly one plate a day, hungry or not.

Leaky bucket and token bucket compared:

PointLeaky bucketToken bucket
Bucket holdspackets (the data)tokens (permission to send)
Outputconstant rate r, alwaysaverage r, with bursts up to C at the line rate
Idle hostsaves nothingsaves tokens, up to C
When the bucket is fullarriving packets are discardedarriving tokens are discarded; packets wait
Burstinessremoved entirelyallowed, but bounded by C
Response to a sudden burstslow: drained at rfast: sent at once while tokens last
Use of an idle networkwastedused by the saved burst
Parametersqueue size, output ratetoken rate r, bucket size C
Implementationa queue drained by a clock (or a byte counter reset each tick)a token counter and a queue

How the token bucket controls congestion better than the leaky bucket: both hold the long-run rate at r, so the network's average load is the same and is still guaranteed. On top of that, the token bucket:

  • uses idle capacity: a host that was quiet may spend the capacity it left unused;
  • responds at once: a burst goes out immediately instead of queueing;
  • loses no data when the bucket fills: only tokens are thrown away;
  • still bounds the worst case: no burst exceeds C, so the network knows the most it must absorb.

Both together: a burst at the full line rate M may still be too much for the network. Putting a leaky bucket of rate p (r < p < M) after the token bucket caps the peak rate as well, while the token bucket keeps the average at r.

A proposed traffic shaping approach for a packet-switched network, built from these parts:

  1. Agree a profile with each source at the network's edge: an average rate r and a burst size C (and a peak rate p if needed).
  2. Shape at the source with a token bucket (r, C), followed by a leaky bucket at p to cap the peak.
  3. Police at the edge router with the same token bucket: packets within the profile go through; packets beyond it are dropped, or tagged low priority to be dropped first if a queue fills.
  4. Back it with closed-loop control inside the network: TCP's congestion window at the hosts and early dropping or ECN at the routers.

Why this is the best choice: the average load each source can impose is fixed, so the network can be planned; bursts are allowed but bounded; nothing is lost while a source keeps to its profile; and an idle network is used rather than wasted. This is how ISPs enforce the speed of a plan, and how the Internet's quality of service schemes describe a flow (a token bucket rate and depth).

On "never discards packets". The book, like Tanenbaum, says the token bucket throws away tokens but never packets. That holds for the bucket itself: a shaper still has a finite packet queue that can overflow, and a policer built on a token bucket drops (or tags) packets that find no token. The contrast with the leaky bucket is that a full bucket of tokens costs no data.
Asked on the paper, word for word
  • Why TCP is known as reliable protocol? What are the congestion control techniques applied in network communication? Discuss Token Bucket approach and compare it with leaky bucket. 2081 Bhadra Q6 · 2+2+4
  • How does the transport layer ensure that the complete message arrive at the destination and in the proper order? How does Token Bucket control the congestion over the Leaky Bucket algorithm? 2080 Bhadra Q6 · 4+4
  • What are the major task of transport layer? Explain. What is token bucket algorithm? 2076 Chaitra Q6 · 5+3
  • How connection is established and released in TCP. Explain Token Bucket algorithm. 2074 Chaitra Q6 · 4+4
  • What is routed and routing protocol? Give examples. Explain Token Bucket algorithm. 2072 Chaitra Q5 · 4+4
  • Compare between leaky bucket and token bucket algorithm with the operation how token bucket works. 2070 Ashad Q8 · 3+5
  • Why do you think that there exist two protocols in transport layer where as there exists only one protocol in Internet layer in TCP/IP reference model. Explain token bucket algorithm for congestion control. 2069 Chaitra Q6 · 5+3
  • Describe the policies that help in preventing the congestions within the network? Differentiate between leaky bucket and token bucket algorithm with their operation and working of token bucket. 2066 Poush Q5 · 4+6
  • What are the factors that cause congestion within WAN? Propose your best traffic shaping approach to manage congestion in packet switched network. 2066 Bhadra Q4b · 2+6
In the exam Draw the bucket with tokens, the host and the queue (before and after a burst), give the four steps, then the comparison table. The burst formula with a small example is what sets a strong answer apart. "Propose the best traffic shaping approach" wants the token bucket, a leaky bucket for the peak, and policing at the edge.

5.8Last minute recall

Chapter 5 in one screen

  • Transport layer: process-to-process delivery, end to end, only in hosts; services: addressing (ports), segmentation, connection control, reliability, ordering, flow control, multiplexing, congestion control.
  • Complete and in order: handshake, numbered bytes, checksum, cumulative ACK, retransmission on timeout or three duplicate ACKs, reordering buffer, window, FIN.
  • Services to the upper layer: connection-oriented (TCP, a phone call) and connectionless (UDP, a letter); primitives LISTEN, CONNECT, SEND, RECEIVE, DISCONNECT; TPDU.
  • UDP (RFC 768): 8-byte header: source port, destination port, length (at least 8), checksum (optional in IPv4, mandatory in IPv6, with a pseudo-header, protocol 17); used for DNS, DHCP, VoIP, games, SNMP, TFTP, QUIC.
  • TCP (RFC 9293): reliable, ordered, full-duplex byte stream; header 20 to 60 bytes: ports, sequence, acknowledgement, HLEN, reserved, flags (CWR ECE URG ACK PSH RST SYN FIN), window, checksum, urgent pointer, options.
  • TCP against UDP: reliability against speed; protocol 6 against 17; two transports but one IP: end hosts choose, every router must share one waist.
  • Ports: 16 bits; well-known 0 to 1023, registered 1024 to 49151, dynamic 49152 to 65535; socket = IP : port; a connection = a socket pair (four-tuple).
  • Handshake: SYN seq 8000; SYN + ACK seq 15000 ack 8001; ACK seq 8001 ack 15001; server opens passively first, or the client gets RST.
  • Release: FIN, ACK, FIN, ACK; half-close; FIN-WAIT-1, FIN-WAIT-2, TIME-WAIT 2 MSL; CLOSE-WAIT, LAST-ACK.
  • Sliding window: rwnd in every segment; in flight at most rwnd; slides on ACK; zero window and persist timer; buffers: chained fixed, chained variable, circular.
  • Demultiplexing: UDP by destination IP and port, TCP by the four-tuple.
  • Congestion: load above capacity; causes: arrival rate, memory, bursts, slow processors, retransmissions; open loop (policies, shaping) and closed loop (choke packets, backpressure, ECN, RED, TCP slow start and AIMD).
  • Leaky bucket: packets in a finite queue, out at a constant rate, dropped when full; byte counting n a tick.
  • Token bucket: tokens at rate r up to C; bursts up to C; S = C / (M − r); with C = 6 Mb, M = 10 Mbps, r = 2 Mbps, S = 0.75 s.

Chapter 6 · 5 hours · about 8 marks a paper · in 24 of the 27 sittings

Application layer

The application layer is where a network finally does something a person can see: a web page opens, a mail arrives, a file lands on a laptop. This chapter teaches the protocols behind those services (HTTP, FTP, SMTP, POP3, IMAP, DNS and DHCP), how a program reaches the network through sockets, how busy servers are kept fast and running, and the tools that watch the traffic. The board sets it almost every time: 24 of the 27 sittings on record ask a question on it, as Question 7 in 19 of them, and DNS and electronic mail have each been set 11 times.

What this chapter is about
  • The application layer and the web: what the layer does, the well-known ports, and HTTP and HTTPS: how a browser's request is served by a web server.
  • File transfer: FTP's two connections (port 21 for control, port 20 for data), TFTP, and secure remote access with SSH, PuTTY and WinSCP.
  • Electronic mail: user agents and mail servers, SMTP to send, POP3 and IMAP to read, and MIME for pictures and attachments.
  • Names and addresses: DNS, the Internet's distributed directory (the name space, the servers, recursive and iterative queries, resource records, delegation, the message format), and DHCP, which hands a host its address.
  • Programs and servers: P2P applications, socket programming in C, proxy servers and web caching, server optimization and RAID.
  • Watching the network: SNMP, MRTG and PRTG, Wireshark and Packet Tracer.
Where it fits
  • It sits on chapter 5's transport layer: every protocol here chooses TCP or UDP and a port (ports and sockets, TCP, UDP), and every TCP conversation below begins with the three-way handshake.
  • Client-server and peer-to-peer are chapter 1's networking models (networking models); here they run as real applications.
  • Securing these services is chapter 8's job: HTTPS rests on TLS (SSL and TLS), secure mail on PGP (PGP), and a proxy is a kind of application gateway (firewalls).
  • DHCP hands out chapter 4's IPv4 addresses (IPv4 addressing), and DNS's AAAA records carry chapter 7's IPv6 addresses (IPv6 addressing).
What you will learn
  1. 6.1 The application layer and its ports; HTTP and HTTPS
  2. 6.2 FTP and TFTP; SSH, PuTTY and WinSCP
  3. 6.3 Electronic mail: SMTP, POP3, IMAP and MIME
  4. 6.4 DNS; DHCP
  5. 6.5 P2P applications
  6. 6.6 Socket programming
  7. 6.7 Proxy servers and web caching; server optimization; RAID
  8. 6.8 SNMP; MRTG and PRTG; Wireshark and Packet Tracer
  9. 6.9 Last minute recall, chapter 6
How it is examined
  • DNS and electronic mail are the chapter's bankers, 11 sittings each. For DNS: what it is and why, recursive against iterative queries drawn with numbered steps, resource records, delegation and the message format. For mail: the components, SMTP step by step, POP3 against IMAP in a table, and MIME for images.
  • HTTP and socket programming come next, 5 sittings each: how a request is served, HTTP against HTTPS, a web server, and the socket calls with a short client and server.
  • FTP (4 sittings), proxy servers (3), DHCP and RAID (1 each) complete the list. FTP's answer is a drawing of the two connections with their ports.
  • Draw the DNS lookup with numbered arrows, the mail system with SMTP and POP3 or IMAP, the SMTP exchange, FTP's control and data connections, and the DHCP lease timeline. The syllabus does not list DHCP; the 2082 Baishakh paper set it beside DNS, so it is taught beside DNS in 6.4.

6.1The application layer and the web

The application layer: what it does, and the ports its protocols use

Application layer The top layer of the TCP/IP model, home of the network applications and their protocols. An application layer protocol defines the messages two application processes exchange: their types (request, reply), their syntax (the fields), their meaning, and the rules for when a process sends what. It hands its messages to the transport layer, TCP or UDP, to carry.

Only the end systems run it. The routers and switches in between work at the network layer and below; a browser on a laptop in a Pulchowk hostel and the web server it talks to are the only two machines that read the HTTP messages passing between them (the TCP/IP model). That is why a new application can spread across the Internet without changing a single router.

Two architectures carry almost every application (networking models):

  • Client-server: an always-on server with a fixed address and a well-known port serves many clients, which never talk to each other directly: the web, mail, FTP, DNS.
  • Peer-to-peer (P2P): ordinary hosts (peers) both ask and serve, with little or no central server: BitTorrent (P2P applications).

Processes talk through sockets. A process hands its message to its socket, the door between the application and the transport layer. The message is addressed by the destination host's IP address and the receiving process's port number (ports and sockets, socket programming). Servers wait on well-known ports (0 to 1023), so a client knows where to knock; the client's own port is a temporary one its operating system picks.

What an application asks of the transport layer: reliable delivery, enough throughput, low delay and security. TCP gives reliability, so the web, mail and file transfer use it; UDP gives speed and no connection setup, so DNS queries, DHCP, SNMP, TFTP and live voice use it, and repair any loss themselves or live with it.

ProtocolJobTransportServer port
HTTPfetch web pages and their objectsTCP80
HTTPSHTTP inside TLSTCP443
FTPfile transfer with a loginTCP21 control, 20 data (active mode)
SSH, SCP, SFTPencrypted remote login and file copyTCP22
Telnetplain-text remote loginTCP23
SMTPsend and relay mailTCP25 between servers, 587 from a user agent
DNSnames to addressesUDP; TCP for zone transfers and long replies53
DHCPgive a host its IP settingsUDP67 server, 68 client
TFTPsimple file transfer, no loginUDP69
POP3download mail from a mailboxTCP110 (995 with TLS)
IMAPmanage mail kept on the serverTCP143 (993 with TLS)
SNMPmonitor and manage devicesUDP161 agent, 162 traps

To remember the idea: the IP address is the ward office building and the port is the counter number inside it. The building gets the citizen to the right office; the counter decides which clerk (process) takes the form. Counter 25 takes letters, counter 53 answers "where is this name?", counter 80 hands out pages.

In the exam No paper asks this card on its own, but every answer in the chapter is sharper with the right transport and port: "SMTP runs over TCP port 25", "DNS uses UDP port 53". The table is worth knowing cold.

HTTP and HTTPS: how a browser's request is served HOT 5/27

81 Ba · 75 Ch · 75 Ash · 73 Shr · 69 Ch2+66+24+4

HTTP HyperText Transfer Protocol, the web's application layer protocol: a stateless request and response protocol in which a client (the browser) sends a request naming an object by its URL, and a web server returns the object in a response, both carried over a TCP connection to the server's port 80. HTTPS is HTTP sent inside an encrypted TLS connection, on port 443.

A web page is many objects. A page is a base HTML file plus everything it references: images, style sheets, scripts. Each object is named by a URL (uniform resource locator). In https://www.example.com:443/notes/ch6.html?lang=np the scheme is https, the host www.example.com, the port 443 (left out when it is the default), the path /notes/ch6.html and the query lang=np. A page with ten images costs the browser eleven requests.

How a request is served, step by step (the drawing follows one request):

  1. Name to address: the browser takes the host name from the URL and asks DNS for its IP address (DNS).
  2. Connection: it opens a TCP connection to that address, port 80, with the three-way handshake (three-way handshake); for HTTPS it connects to port 443 and runs the TLS handshake as well.
  3. Request: it sends a request message, such as GET /index.html HTTP/1.1 followed by header lines.
  4. Processing: the web server parses the request, maps the path to a file under its document root (or runs a program, such as a PHP script, for a dynamic page) and builds a response.
  5. Response: it sends a status line (HTTP/1.1 200 OK), header lines and the object as the body.
  6. Render and repeat: the browser parses the HTML, finds the images and scripts it references, requests each of them, and draws the page.
  7. Close or keep: the connection is closed, or kept open for the next request (persistent HTTP).
SERVING ONE HTTP REQUEST Browser and web server, time running down the page: a TCP connection, then requests and responses. Browser the client Web server listening on port 80 SYN SYN + ACK ACK, then GET /index.html finds index.html 200 OK + the page GET /logo.png (same connection) 200 OK + the image FIN: close the connection 1 RTT 1 RTT + transfer REQUEST MESSAGE GET /index.html HTTP/1.1 Host: www.example.com User-Agent: Mozilla/5.0 Accept: text/html Connection: keep-alive (a blank line ends the headers) request line header lines RESPONSE MESSAGE HTTP/1.1 200 OK Content-Type: text/html Content-Length: 5120 Cache-Control: max-age=3600 (blank line) <html> ... the page ... </html> status line header lines body Non-persistent (HTTP/1.0): a new TCP connection for every object, 2 RTT each. Persistent (HTTP/1.1 default): one connection carries the page and all its objects.

The request message is plain text: a request line (method, path, version), header lines of the form Name: value, a blank line, and an optional body (a form's data with POST).

GET /notes/ch6.html HTTP/1.1
Host: www.example.com
User-Agent: Mozilla/5.0
Accept: text/html
Accept-Language: en, ne
Connection: keep-alive

The response message mirrors it: a status line (version, status code, phrase), header lines, a blank line, and the object as the body.

HTTP/1.1 200 OK
Date: Sun, 04 Oct 2026 09:00:00 GMT
Server: Apache
Last-Modified: Fri, 02 Oct 2026 16:30:00 GMT
Content-Type: text/html; charset=UTF-8
Content-Length: 5120

<!DOCTYPE html><html> ... the page ... </html>
MethodWhat it asks the server
GETsend the object at this URL (most requests)
HEADthe headers GET would send, without the body: is it there, how big, how new
POSTtake this data and process it: a login form, a file upload
PUTstore this body at this URL, creating or replacing it
DELETEremove the object at this URL
PATCH, OPTIONS, CONNECT, TRACEchange part of an object; list the methods allowed; open a tunnel through a proxy (used for HTTPS); echo the request back
ClassMeaningCommon codes
1xxinformational100 Continue, 101 Switching Protocols
2xxsuccess200 OK, 201 Created, 204 No Content
3xxredirection301 Moved Permanently, 302 Found, 304 Not Modified
4xxclient error400 Bad Request, 401 Unauthorized, 403 Forbidden, 404 Not Found
5xxserver error500 Internal Server Error, 502 Bad Gateway, 503 Service Unavailable

HTTP is stateless: the server keeps no memory of earlier requests, so each request carries everything needed to answer it. That keeps servers simple and easy to multiply. When a site needs memory (a login, a cart), it uses cookies: one response carries Set-Cookie: session=8f2a, the browser stores it and sends Cookie: session=8f2a with every later request to that site, and the server looks the number up in its own database. It works like a canteen token: the cashier forgets the student, but the token number ties the student to the order.

Non-persistent and persistent connections. With non-persistent HTTP (the HTTP/1.0 default) every object gets its own TCP connection, so each costs two round-trip times (RTT), one for the handshake and one for the request and response, plus the time to transmit the object. With persistent HTTP (the HTTP/1.1 default, Connection: keep-alive) the server leaves the connection open, and each later object costs one RTT, or less when the requests are sent back to back (pipelined).

Tobject=2RTT+Ttransmit(non-persistent)
Worked example: one page, three ways

A page is one HTML file and 10 small images; the RTT is 50 ms and transmission times are small enough to ignore.

  • Non-persistent, one object at a time: 11 objects × 2 RTT = 22 RTT = 1,100 ms.
  • Persistent, one request at a time: 2 RTT for the handshake and the HTML, then 1 RTT for each image: 12 RTT = 600 ms.
  • Persistent with pipelining: the handshake, the HTML, then all ten image requests sent together: 3 RTT = 150 ms.
VersionYearWhat it brought
HTTP/1.01996, RFC 1945one object per connection by default
HTTP/1.11997, now RFC 9112persistent connections, pipelining, the Host header (many sites on one IP address), chunked transfer
HTTP/22015, now RFC 9113binary frames, many requests multiplexed over one connection, compressed headers
HTTP/32022, RFC 9114HTTP over QUIC, which runs on UDP with TLS 1.3 built in: a faster start, and one lost packet no longer stalls every stream

HTTPS is HTTP inside TLS. The browser opens TCP to port 443 and runs the TLS handshake (SSL and TLS): the server presents its certificate, signed by a certificate authority the browser trusts, and the two agree on session keys. From then on every HTTP message travels encrypted and integrity-checked. It gives three things:

  • Server authentication: the certificate proves that this really is the bank's site, which defeats a fake copy on a hostile Wi-Fi network (a man-in-the-middle attack).
  • Confidentiality: encryption hides passwords, card numbers and the pages themselves from everyone on the path.
  • Integrity: a message altered on the way fails its check and is thrown away.

What HTTPS does not hide: the server's IP address, usually the site's name (sent in the TLS handshake), and the size and timing of the traffic. Browsers now label plain HTTP pages "Not secure", and search engines give HTTPS sites a small ranking boost.

PointHTTPHTTPS
Full nameHyperText Transfer ProtocolHTTP Secure: HTTP over TLS (formerly SSL)
Default port80443
URL beginshttp://https://
LayeringHTTP over TCPHTTP over TLS over TCP
Data on the wireplain text: anyone on the path can read or change itencrypted and integrity-checked
Server identitynot provedproved by a certificate from a certificate authority
Setup costTCP handshake onlyTCP handshake plus the TLS handshake (one round trip in TLS 1.3)
Used fornow rare: redirects to HTTPS, local test serverslogins, payments (a wallet such as eSewa), and every modern site

The web server is the program on the server side; Apache httpd, Nginx and Microsoft IIS are the common ones. It listens on ports 80 and 443 and, for each request, parses it, checks access, maps the URL path to a file under its document root (for GET /index.html, the file /var/www/html/index.html) or hands it to a program that builds the page (PHP, Python, Node.js), then sends the response with the right status code and headers, and writes a line to its access log. It serves many clients at once, with a process or thread per connection (Apache's classic model) or an event loop that juggles thousands of connections in one process (Nginx). One server can host many sites on one IP address (virtual hosting): it reads the Host: header to decide which site a request is for.

Web server communication, layer by layer: DNS (UDP 53) turns the name into an address, TCP gives a reliable connection to port 80 or 443, TLS secures it for HTTPS, HTTP carries the request and the response, and IP routes every packet between the two hosts.

To remember it: plain HTTP is a postcard. Every post office it passes through (the canteen Wi-Fi, the ISP's routers) can read it, and could even rewrite it. HTTPS is a sealed envelope with a verified stamp: the post offices still see the address on the outside (the server's IP and name), but nobody can read or change the letter inside.

The book says HTTPS "is slower than HTTP". Only a new connection pays for the TLS handshake; with TLS 1.3 that is one round trip, and with persistent connections and HTTP/2 a modern HTTPS site is rarely slower in practice.
Asked on the paper, word for word
  • What is a proxy server? Why is it used? Discuss briefly on HTTP and HTTPS services. 2081 Baishakh Q7 · 4+4
  • Why we need proxy servers? What are the importance of DNS and HTTP(S) while you are browsing any website? 2075 Chaitra Q7 · 2+6
  • Define socket programming. How web server communication and file server communication are possible in network. Explain with used protocols. 2075 Ashwin Q7 · 6+2
  • How web server communication and file server communication are possible in network, explain with used protocols. Define socket programming. 2073 Shrawan Q6 · 6+2
  • Write short notes on: i) HDLC ii) Web Server 2073 Shrawan Q10 · 4×2
  • What is HTTP protocol? With an example explain how a request initiated by a HTTP client is served by a HTTP server. 2069 Chaitra Q7 · 2+6
In the exam For how a request is served, write the seven steps and draw the time sequence with the request and response messages. For HTTP against HTTPS, a table: port, layering, security, certificate, URL scheme. A short note on a web server: what it is, how it handles one request, two examples of server software.

6.2File transfer

FTP and TFTP: copying files across the network PIN 4/27

80 Bh · 76 Ash · 75 Ash · 73 Shr6+22+64+4

FTP File Transfer Protocol (RFC 959): the standard TCP/IP protocol for copying files between a client and a server after a login. It uses two TCP connections: a control connection to server port 21, open for the whole session, for commands and replies, and a separate data connection (server port 20 in active mode), opened for each file or directory listing and closed after it.

Why two connections. FTP sends its control information out of band: commands never mix with file bytes, so the client can send ABOR to stop a transfer midway, and the control channel stays a simple exchange of text lines (one command, one reply) while the data channel copes with any kind of file. HTTP, by contrast, sends its headers and its data on one connection (in band).

The model. Each side has a control process (the protocol interpreter, which speaks the commands) and a data transfer process (which moves the bytes between its file system and the data connection); the client adds the user interface. The control processes talk over the control connection, the data transfer processes over the data connection.

How a client connects to an FTP server, step by step:

  1. Control connection: the client opens TCP to the server's port 21; the server greets with 220 Service ready.
  2. Login: USER anuj draws 331 Password required; PASS with the password draws 230 User logged in (or 530 if it is wrong). Public archives accept the user name anonymous.
  3. Settings: TYPE I for binary (image) transfer, TYPE A for text; the server replies 200.
  4. Data connection: in active mode the client sends PORT 192,168,1,10,195,80, its address and a port (195 × 256 + 80 = 50000), and the server connects from its port 20 to that port. In passive mode the client sends PASV, the server answers 227 Entering Passive Mode with a high port of its own, and the client connects to it.
  5. Transfer: RETR notes.pdf downloads, STOR uploads, LIST lists a directory; the server replies 150, the bytes flow on the data connection, the data connection closes, and 226 Transfer complete arrives on the control connection.
  6. Repeat, then quit: steps 4 and 5 repeat for every file, each with a new data connection; QUIT draws 221 Goodbye and the control connection closes.
AN FTP SESSION: TWO CONNECTIONS Active mode: commands on the control connection to port 21; the file on a separate data connection from port 20. FTP client 192.168.1.10 FTP server port 21 control, 20 data connect to port 21 (TCP handshake) 220 Service ready USER anuj 331 Password required PASS ******** 230 User logged in PORT 192,168,1,10,195,80 (port 50000) 200 PORT command OK RETR notes.pdf 150 Opening data connection data: port 20 connects to port 50000 data: the file's bytes, then close 226 Transfer complete QUIT 221 Goodbye: control connection closes Control connection server port 21, opened by the client open for the whole session commands and replies, one text line at a time Data connection server port 20 in active mode a new one for each file or listing closed when the transfer ends Passive mode (PASV) the server replies 227 with a high port and the client opens the data connection itself, so it passes NAT and firewalls PORT h1,h2,h3,h4,p1,p2: data port = p1 x 256 + p2 = 195 x 256 + 80 = 50000
PointActive mode (PORT)Passive mode (PASV)
Who opens the data connectionthe server, from its port 20the client
To which portthe client's port named in PORTthe server's high port named in the 227 reply
Through NAT and firewallsoften blocked: the client's side refuses incoming connectionspasses: both connections go outward from the client
Todayrarethe default in most clients (FileZilla, WinSCP)
CommandMeaningTypical reply
USER, PASSlog in331, then 230 (530 on failure)
CWD, PWDchange, print the working directory250, 257
LISTdirectory listing, sent on a data connection150, then 226
RETR, STORdownload, upload a file150, then 226
TYPE A, TYPE IASCII text or binary image200
PORT, PASVactive or passive data connection200, 227
QUITend the session221

Reply codes follow one pattern: the first digit 1 means "started, wait for more", 2 done, 3 "send the next part" (as after USER), 4 a temporary failure (try again), 5 a permanent failure. Data types are ASCII, EBCDIC and image (binary); transmission modes are stream (the default), block and compressed. A photo sent in ASCII mode is damaged by line-ending conversion, so anything that is not plain text goes in binary.

FTP is stateful: the server remembers the logged-in user, the current directory and the transfer type for the whole session, unlike stateless HTTP. And it is not secure: the password crosses the network in plain text, readable by anyone running Wireshark on the same network. FTPS (FTP over TLS) or SFTP (SSH file transfer) replace it wherever security matters.

To remember it: a shop counter. The control connection is the counter, where the customer and the shopkeeper talk for the whole visit. For each parcel the shopkeeper opens the back door (a data connection), hands it over and shuts it. In active mode the shopkeeper carries the parcel to the address the customer gave, and finds the gate locked if there is NAT; in passive mode he names a door and the customer collects the parcel there.

TFTP (Trivial File Transfer Protocol, RFC 1350) is FTP cut to the bone: it runs over UDP port 69, with no login, no directory listing and no commands beyond read and write.

  • Five packet types: RRQ (read request, opcode 1), WRQ (write request, 2), DATA (3), ACK (4) and ERROR (5).
  • Lock-step blocks: data travels in numbered 512-byte blocks, and each block must be acknowledged before the next is sent (stop and wait, ARQ); a lost block or ACK is resent after a timeout. A block shorter than 512 bytes marks the end: a 2,000-byte file goes as three blocks of 512 and one of 464, and a file of exactly 1,024 bytes needs a final empty block.
  • Ports: the request goes to port 69; the server answers from a fresh port of its own, which carries the rest of the transfer.
  • Uses: booting diskless machines over the network (PXE), loading firmware and configuration files onto routers, switches and IP phones (a router's copy tftp command). Its code is small enough to fit in a boot ROM.
PointFTPTFTP
TransportTCPUDP
Ports21 control, 20 data69, then a fresh port
Loginuser name and passwordnone
Commandsdozens: list, rename, delete, change directoryread or write a file, nothing else
ReliabilityTCP'sits own: every 512-byte block acknowledged
Typical usegeneral file transferbooting, router and switch images

File server communication on the Internet uses FTP (or its secure cousins); inside a LAN, file servers more often speak SMB (Windows file sharing, TCP 445) or NFS (Unix, port 2049), which let a client mount a remote folder and open its files as if they were local.

The book says FTP's data connection uses port 20, without adding that this holds only in active mode: in passive mode the server's data port is a high port it names in its 227 reply.
Asked on the paper, word for word
  • How does an FTP client connect to an FTP server? Compare POP3 and IMAP protocols. 2080 Bhadra Q7 · 4+4
  • What is TFTP? Explain working principle of FTP with data transfer process including proper port connection. Use proper diagram to justify your answer. 2076 Ashwin Q7 · 2+6
  • Define socket programming. How web server communication and file server communication are possible in network. Explain with used protocols. 2075 Ashwin Q7 · 6+2
  • How web server communication and file server communication are possible in network, explain with used protocols. Define socket programming. 2073 Shrawan Q6 · 6+2
In the exam For how FTP works, draw the two connections with their ports, then the command sequence (220, USER, PASS, 230, PORT or PASV, RETR, 150, data, 226, QUIT); name active and passive mode. For TFTP, two lines are enough: UDP port 69, no authentication, 512-byte blocks each acknowledged, used for booting and device images.

Remote login and secure transfer: Telnet, SSH, PuTTY and WinSCP

SSH Secure Shell: a protocol for encrypted remote login and command execution over TCP port 22. The same encrypted channel carries file transfer, as SCP and SFTP, and forwarded ports.

Telnet came first (RFC 854, TCP port 23): it gives a remote terminal, but sends everything, the password included, in plain text. SSH replaced it. SSH-1 appeared in 1995 and SSH-2, the version in use, was standardised in 2006 (RFC 4251 to 4254). It has three layers:

  • Transport layer: the server proves its identity with its host key, the two sides agree on session keys, and everything after is encrypted and integrity-checked. On the first connection the client shows the host key's fingerprint and asks whether to trust it.
  • User authentication: by password, or better by a key pair: the public key sits in the server's ~/.ssh/authorized_keys and the private key never leaves the laptop.
  • Connection layer: many channels in one connection: a shell, a file transfer, forwarded ports.
Tool or protocolWhat it doesPortEncrypted
Telnetremote terminal23no
SSHremote terminal and commands22yes
SCPcopy files over SSH, nothing more22yes
SFTPSSH File Transfer Protocol: list, rename, delete, resume, over SSH22yes
FTPSclassic FTP wrapped in TLS (not the same as SFTP)21 (990 implicit)yes

PuTTY is a free, open-source terminal emulator for Windows, written by Simon Tatham, that acts as a client for SSH, Telnet, rlogin, raw TCP and serial connections. With it a student logs in to a Linux server, or configures a router through its console cable. Its companions: PuTTYgen makes key pairs (saved as .ppk files), Pageant holds keys in memory, and pscp and psftp copy files from the command line.

WinSCP is a free, open-source Windows client for SFTP, SCP and FTP (including FTPS) with a two-panel graphical interface: the laptop's folders on one side, the server's on the other, and files dragged between them. Its SSH code comes from PuTTY and its FTP code from FileZilla.

To remember it: a final-year team deploying its project to the college's Linux server uses PuTTY to log in and run commands, and WinSCP to drag the build folder across. Both use port 22, so nothing they type is readable on the hostel Wi-Fi, while the same work over Telnet and FTP would hand the password to anyone listening.

In the exam No paper has asked these yet. If one does, define SSH (encrypted remote login, port 22, host key, key or password login), then say what PuTTY and WinSCP are and which protocols each speaks, and contrast them with Telnet and FTP.

6.3Electronic mail

Electronic mail: user agents, mail servers, SMTP, POP3, IMAP and MIME TOP 11/27

81 Bh · 80 Bh · 76 Ch · 74 Ch · 74 Ash · 72 Ch · 72 Ka · 71 Shr · 70 Ch · 68 Ba · 67 Asa2+63+54+4

Electronic mail An asynchronous message service with three kinds of part: user agents, where people write and read mail; mail servers, which keep a mailbox for each user and a queue of outgoing mail; and the protocols between them: SMTP pushes mail to and between servers over TCP port 25, and POP3 or IMAP pulls it from the mailbox to the reader.

Asynchronous means the two people need not be online together. Sita sends at night from Pokhara, the mail waits on Ram's mail server, and Ram reads it the next morning in Kathmandu. The addresses in this card are written defanged, as ram@example[.]org: the user's mailbox name, then the mail domain.

ComponentWhat it isExamples
User agent (UA)the program a person uses to compose, read, reply to, forward and file mailOutlook, Thunderbird, the Gmail app, a browser for webmail
Mail serverthe host that keeps a mailbox per user and a queue of outgoing mail, and runs the agents belowa college's or a company's mail server; Gmail's servers
Message transfer agent (MTA)the SMTP software that moves mail from server to serverPostfix, Sendmail, Exim, Microsoft Exchange
Message delivery agent (MDA)puts each arriving message into the right mailbox, often after a spam filterprocmail, Dovecot's delivery agent
Message access agent (MAA)the POP3 or IMAP server that the reader's agent pulls mail fromDovecot, Courier
Mailbox and queuewhere received mail waits for its reader; where outgoing mail waits for deliveryone mailbox per user

An email server, then, is a host running these programs. It accepts mail for its own domain (the domain's DNS MX record tells other servers where to send it), stores it in mailboxes, lets its users fetch it, and relays their outgoing mail to other servers.

How one mail travels, step by step:

  1. Compose: Sita writes to ram@example[.]org in her user agent and presses Send.
  2. Submit: her agent hands the mail to her own mail server with SMTP (port 587, after she logs in), where it waits in the outgoing queue.
  3. Find the receiver's server: her server asks DNS for the MX record of example.org.
  4. Transfer: it opens a TCP connection to that server's port 25 and pushes the message with SMTP. If the receiving server is down, the message stays in the queue and is retried, typically for several days, before a failure notice (a bounce) comes back.
  5. Deliver: the receiving server's delivery agent places it in Ram's mailbox.
  6. Read: when Ram opens his agent, it pulls the message from the mailbox with POP3 or IMAP; with webmail he reads it in a browser over HTTPS instead.
THE INTERNET MAIL SYSTEM SMTP pushes the message from server to server; POP3 or IMAP pulls it out of the mailbox. Sita's user agent writes the mail Sender's mail server SMTP client (MTA) outgoing queue Receiver's server SMTP server, MDA Ram's mailbox Ram's user agent reads the mail SMTP port 587 SMTP port 25 POP3 / IMAP 110 / 143 DNS MX record of example.org PUSH: SMTP, started by the side that holds the mail PULL: Ram's agent asks The message waits in Ram's mailbox until his agent fetches it, so his computer need not be on when the mail arrives. With webmail the agent is a browser: HTTPS to the server, and SMTP between the servers as before.

Push, then pull. SMTP is a push protocol: the side that holds the mail opens the connection and sends it. It cannot fetch mail out of a mailbox, and the reader's computer is not always on, so the last hop needs a pull protocol that the reader starts when it suits him: POP3 or IMAP. This is why mail is delivered to a server that is always on, and not straight to Ram's laptop.

SMTP (Simple Mail Transfer Protocol, RFC 821 of 1982, now RFC 5321) is a text protocol: the client sends commands as lines of ASCII and the server answers each with a three-digit code and a phrase. Every mail server runs both sides: it is an SMTP client when it sends and an SMTP server when it receives. A session has three phases:

  1. Connection setup: TCP to port 25; the server greets with 220; the client names itself with HELO (or EHLO, which also asks which extensions the server supports); 250.
  2. Mail transfer: MAIL FROM: the sender's address (250); RCPT TO: each recipient's address, once per recipient (250, or 550 if no such mailbox exists); DATA (354); then the message itself, header lines, a blank line and the body, ended by a line holding only a full stop; 250.
  3. Termination: QUIT; 221; the TCP connection closes. Several messages may go in one session before QUIT.
AN SMTP SESSION Sender's mail server (client) to receiver's mail server (server), TCP port 25: text commands, three-digit replies. SMTP client sender's mail server SMTP server receiver's server, port 25 TCP connection to port 25 (three-way handshake) 220 mail.example.org Service ready HELO mail.example.com 250 Hello mail.example.com MAIL FROM:<sita@example[.]com> 250 OK RCPT TO:<ram@example[.]org> 250 OK DATA 354 Start mail input; end with a line holding only "." header lines, blank line, body, then "." 250 OK, message queued QUIT 221 Service closing TCP connection closed CONNECTION SETUP greeting, then HELO MAIL TRANSFER envelope, then DATA TERMINATION QUIT and close MAIL FROM and RCPT TO are the envelope; the From: and To: lines inside DATA are the letter's own header
S: 220 mail.example.org ESMTP ready
C: HELO mail.example.com
S: 250 mail.example.org
C: MAIL FROM:<sita@example[.]com>
S: 250 OK
C: RCPT TO:<ram@example[.]org>
S: 250 OK
C: DATA
S: 354 End data with <CR><LF>.<CR><LF>
C: From: Sita <sita@example[.]com>
C: To: Ram <ram@example[.]org>
C: Subject: Lab report
C:
C: Ram, the lab report is attached.
C: .
S: 250 OK: queued
C: QUIT
S: 221 Bye
CommandMeaningUsual reply
HELO, EHLOthe client names itself (after the server's 220 greeting)250
MAIL FROM:the sender, where a bounce would go250 OK
RCPT TO:one recipient; repeated for each250 OK, or 550 no such mailbox
DATAthe message follows354 start input; 250 after the final "."
QUITend the session221 closing
RSET, VRFY, NOOPabort this mail; check a user; do nothing250

The reply codes follow FTP's pattern: 2xx done, 3xx "send the rest", 4xx a temporary failure to retry later (421 service not available, 450 mailbox busy), 5xx a permanent failure (550 no such mailbox).

SMTP's rules and limits. Commands, headers and body are 7-bit ASCII (byte values 0 to 127); a line may hold at most 1,000 characters with its CR LF; a body line that starts with a full stop gets a second one added by the sender and removed by the receiver, so it is never taken for the end. MAIL FROM and RCPT TO are the envelope, read by the servers; the From: and To: lines inside DATA are the letter's own header, which the reader sees. SMTP checks no sender by itself, which is how spam and forged senders spread; today domains publish SPF, DKIM and DMARC records in DNS so receivers can check a sender, STARTTLS encrypts each server-to-server hop, and only PGP or S/MIME protects a message end to end (PGP).

POP3 (Post Office Protocol version 3, RFC 1939, TCP port 110, 995 with TLS) is the simple way to read mail: the agent logs in, downloads the messages and usually deletes them from the server. A session passes through three states: authorization (USER, PASS), transaction (STAT, LIST, RETR, DELE) and update (after QUIT, the server really deletes what was marked). It runs in download-and-delete mode, for a single computer, or download-and-keep mode, which leaves copies on the server.

S: +OK POP3 server ready
C: USER ram
S: +OK
C: PASS ********
S: +OK 2 messages (6800 octets)
C: LIST
S: 1 1200
S: 2 5600
S: .
C: RETR 1
S: +OK 1200 octets ... (the whole message) ... .
C: DELE 1
S: +OK message 1 deleted
C: QUIT
S: +OK bye

IMAP (Internet Message Access Protocol, IMAP4rev1 RFC 3501, now IMAP4rev2 RFC 9051; TCP port 143, 993 with TLS) keeps the mail on the server. The user's folders live there, and the server remembers each message's state (read, answered, flagged, deleted) across sessions, so a phone, a laptop and a lab computer all see the same mailbox. An IMAP agent can fetch only the headers, or one part of a message (the text without the 10 MB attachment), and can ask the server to search. Each command carries a tag that its reply repeats:

C: a1 LOGIN ram ********
S: a1 OK LOGIN completed
C: a2 SELECT INBOX
S: * 2 EXISTS
S: a2 OK [READ-WRITE] SELECT completed
C: a3 FETCH 1 (BODY.PEEK[HEADER.FIELDS (FROM SUBJECT)])
S: * 1 FETCH (... From: Sita ... Subject: Lab report ...)
S: a3 OK FETCH completed
C: a4 LOGOUT
PointPOP3IMAP
Where mail livesdownloaded to one computer, usually deleted from the serverstays on the server until the user deletes it
Foldersonly the INBOX on the server; folders are localfolders created, renamed and deleted on the server
Several devicesmail scatters across devicesevery device sees the same mailbox
State keptnone between sessionsread, answered, flagged across sessions
Partial downloadwhole messagesheaders only, or one part of a message
Searchon the local copy onlyon the server, before downloading
Offline readingeasy: everything is localneeds a local cache
Server storagesmall: mail leaves the serverlarge: every message stays
Complexitysimplemore complex, for client and server
Port110 (995 with TLS)143 (993 with TLS)

MIME: pictures through a 7-bit pipe. SMTP was built for 7-bit ASCII text: a photo, a PDF or a Nepali sentence contains bytes from 128 to 255, and long runs without line breaks, which SMTP may damage or refuse. MIME (Multipurpose Internet Mail Extensions, RFC 2045 to 2049) solves it without changing SMTP: it adds header lines that describe each part of the message, and it encodes any bytes as 7-bit text, which the receiver's agent decodes back.

MIME headerWhat it saysExample
MIME-Versionthis message uses MIME1.0
Content-Typethe media type of the body or parttext/plain, text/html, image/jpeg, application/pdf, multipart/mixed
Content-Transfer-Encodinghow the bytes were made 7-bit safe7bit, quoted-printable, base64
Content-Dispositionshown inline or saved as an attachmentattachment; filename="phewa.jpg"
Content-ID, Content-Descriptiona label to refer to the part; a short descriptionan image shown inside an HTML mail

Base64, the encoding for images and other binary files, takes the data 3 bytes (24 bits) at a time, cuts the 24 bits into four groups of 6, and writes each group as one of 64 printable characters: A to Z for 0 to 25, a to z for 26 to 51, 0 to 9 for 52 to 61, + for 62 and / for 63, with = padding the end when the data is not a multiple of 3 bytes. Lines are broken every 76 characters. Three bytes become four characters, so the size grows by a third: a 3 MB phone photo travels as about 4 MB of text.

BASE64: AN IMAGE AS 7-BIT TEXT Every 3 bytes (24 bits) become 4 characters of 6 bits each, all printable ASCII that SMTP can carry. BYTES (HEX) BITS 6-BIT GROUPS VALUES CHARACTERS FF D8 FF 1 1 1 1 1 1 1 1 1 1 0 1 1 0 0 0 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 0 1 1 0 0 0 1 1 1 1 1 1 1 1 63 / 61 9 35 j 63 / regroup THE 64 CHARACTERS 0 to 25: A to Z 26 to 51: a to z 52 to 61: 0 to 9 62: + and 63: / padding at the end: = SIZE 3 bytes in, 4 characters out: a 3 MB photo travels as about 4 MB of text IN THE MAIL Content-Type: image/jpeg Content-Transfer-Encoding: base64 /9j/4AAQSkZJRgAB... (every JPEG starts /9j/)
Worked example: base64 by hand
  • Text, "Ram": bytes 52 61 6D (hex) = 01010010 01100001 01101101; regrouped as 010100 100110 000101 101101 = 20, 38, 5, 45 = U, m, F, t, so "Ram" travels as UmFt.
  • An image: every JPEG file begins with the bytes FF D8 FF, all above 127 and so illegal in 7-bit mail: 11111111 11011000 11111111 regroups as 63, 61, 35, 63 = /9j/. That is why every base64-encoded JPEG starts with /9j/.

Quoted-printable suits text that is mostly ASCII: plain characters pass unchanged and each other byte becomes = and two hex digits. The Nepali letter न is E0 A4 A8 in UTF-8, so it travels as =E0=A4=A8. A Nepali subject line is encoded inside the header itself, as an encoded word: the subject नमस्ते becomes =?UTF-8?B?4KSo4KSu4KS44KWN4KSk4KWH?=.

A mail with a photo attached is a multipart/mixed message: a boundary string, chosen so it never occurs in the data, separates the parts.

From: Sita <sita@example[.]com>
To: Ram <ram@example[.]org>
Subject: Photo from Phewa Lake
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="XyZ42"

--XyZ42
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 7bit

Here is the photo from the boat.
--XyZ42
Content-Type: image/jpeg; name="phewa.jpg"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="phewa.jpg"

/9j/4AAQSkZJRgAB ... (about 4 MB of base64 text) ...
--XyZ42--

To remember the whole system: the postal service. The user agent is the person writing the letter; her mail server is the local post office; SMTP is the mail van that runs between post offices (and only ever delivers, never collects); the mailbox is Ram's PO box at his post office. POP3 is Ram emptying the PO box and carrying everything home; IMAP is Ram reading at the post office counter, where the letters stay in his own labelled folders.

The book says, in its POP3 against IMAP table, that POP3 has "only one folder ... i.e., index folder": the one folder POP3 sees is the INBOX. Its row "the message storage capacity is limited to 2 GB" for IMAP describes some provider's mailbox quota, not a limit of the IMAP protocol, which sets none.
Asked on the paper, word for word
  • What do you mean by DNS delegation? List the step-by-step working principle of SMTP. 2081 Bhadra Q7 · 2+6
  • How does an FTP client connect to an FTP server? Compare POP3 and IMAP protocols. 2080 Bhadra Q7 · 4+4
  • What is DNS? Explain the working principle of DNS with a proper diagram. Compare IMAP and POP3 protocols. 2076 Chaitra Q7 · 1+4+3
  • Which protocols are used in sending and receiving an email? Illustrate with necessary figure. Give a comparison of POP3 and IMAP. 2074 Chaitra Q7 · 5+3
  • Write short notes on: (Any two) a) SMTP and POP b) Diffie Hellman’s Algorithm c) CSMA/CD d) DLL Flow Control Mechanisms 2074 Ashwin Q10 · 4+4
  • Write short notes on: a) Simple Mail Transfer Protocol b) Doman Name Server 2072 Chaitra Q10 · 4×2
  • What are the different components of email server? Explain different types of electronic mail sending and accessing protocol. 2072 Kartik Q7 · 2+6
  • SMTP is a text based protocol and uses 7 bit ascii. How can this be used to transmit sometimes like images? Explain. 2071 Shrawan Q7 · 8
  • What do you mean by email server? What are the protocols used on it? 2070 Chaitra Q7 · 2+6
  • What is the function of proxy server? Explain about electronic mail. 2068 Baishakh Q8 · 3+5
  • How the protocol SMTP does operate? Explain the procedures to make your network secured. 2067 Ashad Q10 · 3+5
In the exam "Which protocols send and receive mail?" wants the mail system drawing with SMTP (push, 25), POP3 (110) and IMAP (143) on it. "Working of SMTP" wants the three phases with the command exchange. POP3 against IMAP is a table. The 7-bit question wants MIME's headers and base64 worked on three bytes.

6.4DNS, and DHCP beside it

DNS: the Internet's distributed directory of names TOP 11/27

82 Bh · 82 Ba · 81 Bh · 80 Ba · 79 Bh · 78 Bh · 76 Ch · 75 Ch · 74 Ash · 72 Ch · 71 Ch2+61+4+32+2+4

DNS Domain Name System (RFC 1034 and 1035): a distributed, hierarchical database of names, and the application layer protocol for querying it. Its main job is to map a host name such as www.ioe.edu.np to the IP address that routing needs (and back), and it answers mostly over UDP port 53.

Why it is used:

  • Names for people, numbers for machines: people remember youtube.com; routers forward on 32-bit or 128-bit addresses (IPv4 addressing).
  • Freedom to move: a site can change its server and its address, and only the DNS record changes; every bookmark and link keeps working.
  • One name, many servers: a busy name can map to several addresses, spreading the load, and a content network can hand each user the address of its nearest copy.
  • More than addresses: DNS also says which server takes a domain's mail (MX), what a name is an alias of (CNAME), and which name an address belongs to (PTR).
  • Distributed, because one table cannot scale: before DNS (designed in 1983) every host copied a single file, HOSTS.TXT, from one computer at the SRI Network Information Center. With millions of names one table would be a single point of failure, a traffic jam and impossible to keep current, so DNS splits the database among countless servers, each run by whoever owns that part of the name space.

To remember it: DNS is the phone's contact list for the whole Internet. Nobody dials Aama's number from memory; the phone looks it up from the name. When she changes her SIM, only the entry changes, and "Aama" still works.

The domain name space is an inverted tree. Each node has a label of up to 63 characters; the root's label is empty. A node's domain name is its labels read upward to the root and joined by dots, www.youtube.com., the final dot standing for the root. A name ending in that dot is a fully qualified domain name (FQDN); one without it, such as a bare www typed inside a campus network, is partially qualified (PQDN), and the resolver completes it with a default suffix. A full name may be at most 255 bytes long.

THE DOMAIN NAME SPACE An inverted tree: every node is a label, and a full name is read from the node up to the root. ROOT TOP LEVEL SECOND LEVEL THIRD LEVEL . (root) served by 13 root server names, a to m com org net edu np youtube example wikipedia mit edu gov www ioe pcampus www.youtube.com. the full name: labels from the node up to the root zone youtube.com zone ioe.edu.np Label: up to 63 characters. Full name: up to 255 bytes. A fully qualified name ends with the root's dot. Zone: the part of the tree one set of name servers answers for. Delegation: a parent zone hands a subtree to other servers with NS records, as com does for youtube.com and edu.np does for ioe.edu.np.
  • The root: one, unnamed, served by 13 named root server identities (a.root-servers.net to m.root-servers.net) run by 12 organizations, each copied to many sites around the world by anycast.
  • Top-level domains (TLDs): generic ones (com, org, net, edu, gov, info and many newer ones), country codes (np for Nepal, in, uk, jp), and arpa for reverse lookups. Verisign runs com and net; the np domain is run by Mercantile Communications.
  • Second level and below: under np sit second-level zones such as com.np, edu.np, gov.np and org.np; under edu.np sit names such as ioe.edu.np and pcampus.edu.np. Each owner then creates whatever names it likes below its own.
Name serverWhat it holds or doesExample
Rootknows the servers of every TLD; answers with referralsa to m.root-servers.net
TLDknows the authoritative servers of every domain under its TLDa.gtld-servers.net for com
Authoritativeholds a zone's actual records, from its zone file; a primary server and secondaries that copy the zone by zone transferns1.google.com for youtube.com
Local (the resolver)outside the tree: the server a host is told to ask (by DHCP), which resolves names on the host's behalf and caches the answersan ISP's resolver (NTC, WorldLink), or a public one such as 8.8.8.8 or 1.1.1.1

Caching keeps DNS fast. Every answer carries a time to live (TTL, in seconds), and a resolver keeps it that long. Once the first student in a hostel looks up youtube.com, the next hundred get the answer from the ISP's resolver without touching the root, the TLD or Google. Resolvers also cache the TLD servers' addresses, so the root is rarely asked at all, and they remember failed lookups for a while too (negative caching).

Two ways to resolve a name. In a recursive query the server asked takes the whole job: it must return the answer, or an error, asking other servers itself as needed. In an iterative query the server asked replies at once with the best it has: the answer if it knows it, otherwise a referral, the names and addresses of servers closer to the answer, and the asker goes on to ask those itself. The asker states its wish in the RD (recursion desired) flag.

ITERATIVE QUERY: WWW.YOUTUBE.COM The local server asks each server in turn; every server but the last replies with a referral, not the answer. Root server one of 13 names, a to m TLD server for .com a.gtld-servers.net Authoritative server ns1.google.com (youtube.com) Requesting host browser wants www.youtube.com Local DNS server the ISP's resolver, with a cache 1 8 2 3 4 5 6 7 Root and TLD reply with a referral: the next servers to ask. Only the authoritative server gives the answer. THE EIGHT STEPS 1 Host asks the local server: address of www.youtube.com? 2 Local server asks a root server 3 Root refers it to the .com TLD servers 4 Local server asks a .com TLD server 5 TLD refers it to youtube.com's servers (ns1.google.com) 6 Local server asks the authoritative server 7 Authoritative server answers with the A record 8 Local server caches it and returns it to the host
Worked example: the iterative lookup of www.youtube.com
  1. Host to local server: the browser's resolver library sends a query for www.youtube.com, type A, with RD set, to the ISP's resolver, which has nothing cached.
  2. Local server to root: it asks a root server.
  3. Root's referral: "ask com": the NS records of com (a.gtld-servers.net and its siblings) in the authority section, their addresses (glue) in the additional section.
  4. Local server to TLD: it asks a com server.
  5. TLD's referral: "ask youtube.com's servers": ns1.google.com and its siblings, with their addresses.
  6. Local server to authoritative: it asks ns1.google.com.
  7. The answer: the authoritative server replies with the A record, AA set. (If the name is an alias, the reply is a CNAME, and the resolver looks up the canonical name the same way.)
  8. Back to the host: the resolver caches every record it saw for its TTL and returns the address; the browser opens its TCP connection.

The host sent one query and got one reply; the local server did the iterating, with three queries.

RECURSIVE QUERY: WWW.YOUTUBE.COM Each server takes the whole job: it asks the next server itself and waits, and the answer comes back along the chain. Root server one of 13 names, a to m TLD server for .com a.gtld-servers.net Authoritative server ns1.google.com (youtube.com) Requesting host browser wants www.youtube.com Local DNS server the ISP's resolver, with a cache 1 8 2 7 3 6 4 5 Every server keeps state and waits for the server below it. That load is why root and TLD servers refuse recursion in practice: a host asks its local server recursively, and the local server works iteratively. THE EIGHT STEPS 1 Host asks the local server: address of www.youtube.com? 2 Local server passes the query to a root server 3 Root server passes it to the .com TLD server 4 TLD server passes it to youtube.com's server 5 Authoritative server returns the address to the TLD 6 TLD server returns it to the root server 7 Root server returns it to the local server 8 Local server caches it and answers the host

Fully recursive resolution chains the work instead: the root asks the TLD server, the TLD server asks the authoritative server, and the answer climbs back the same way. It saves the asker work but loads the servers up the tree, which would have to hold state for millions of waiting queries; so root and TLD servers refuse recursion (they answer with RA clear). In practice the two are combined: a host's query to its local server is recursive, and the local server's own queries are iterative.

PointRecursive queryIterative query
Who does the workthe server asked: it chases the answerthe asker: it follows the referrals
Replythe final answer, or an errorthe answer, or a referral to other servers
Loadheavy on the server asked, which must wait and keep statelight: every server answers at once
Messages for the askerone query, one replyone query for each server visited
Cachingthe server caches what it learnedthe asker caches the whole chain
FlagsRD set, and RA set in the replyRD clear, or recursion not offered
Typical usehost to its local serverlocal server to root, TLD and authoritative servers

A third kind, in older texts, is the inverse query: finding the name for an address. It is now done as an ordinary query for a PTR record: the address 192.0.2.80 becomes the name 80.2.0.192.in-addr.arpa (the bytes reversed), looked up like any other name; the old inverse opcode is obsolete.

Resource records. A zone's data is a set of resource records (RRs), each with five fields: NAME (the owner), TYPE, CLASS (IN, for the Internet), TTL (how many seconds it may be cached) and the record's data (RDATA, whose length goes in RDLENGTH on the wire).

TypeCodeWhat its data isExample, zone example.com
A1an IPv4 addresswww A 192.0.2.80
AAAA28an IPv6 address (IPv6 addressing)www AAAA 2001:db8::80
CNAME5the canonical name an alias stands forftp CNAME www.example.com.
MX15a mail server for the domain, with a preference: the lower number is tried firstexample.com. MX 10 mail.example.com.
NS2an authoritative name server for the zoneexample.com. NS ns1.example.com.
PTR12the name for an address (reverse lookup)80.2.0.192.in-addr.arpa. PTR www.example.com.
SOA6start of authority: the zone's primary server, its administrator's mailbox, a serial number and timersone per zone, at its top
TXT16free text: SPF and DKIM mail checks, site-ownership proofsexample.com. TXT "v=spf1 mx -all"

A zone file is where an authoritative server keeps its records. A small one, with documentation addresses:

$TTL 3600
example.com.   IN SOA   ns1.example.com. admin.example.com. (
                        2026100401 ; serial: raised on every change
                        7200       ; refresh: secondaries check every 2 hours
                        900        ; retry
                        1209600    ; expire: 14 days
                        300 )      ; TTL for "no such name" answers
example.com.   IN NS    ns1.example.com.
example.com.   IN NS    ns2.example.com.
example.com.   IN MX 10 mail.example.com.
ns1            IN A     192.0.2.53
www            IN A     192.0.2.80
www            IN AAAA  2001:db8::80
mail           IN A     192.0.2.25
ftp            IN CNAME www.example.com.
example.com.   IN TXT   "v=spf1 mx -all"

Delegation is how DNS becomes distributed. A zone is the part of the tree that one set of authoritative servers answers for. A parent zone hands (delegates) a subtree to another set of servers by putting NS records for the child into its own zone, plus glue A records when the child's name servers are named inside the child itself. From then on the child's owner adds and changes names without asking the parent. The root delegates np to the np registry's servers; the np zone delegates edu.np; the edu.np zone delegates ioe.edu.np to the name servers IOE names, so IOE can add a host the same afternoon with nobody above it involved. A referral in an iterative lookup is simply the parent reading out its delegation. Glue is needed when a zone names servers inside itself: pcampus.edu.np is served by dns1.pcampus.edu.np and dns2.pcampus.edu.np, so the edu.np zone must also hold their addresses, or no resolver could ever reach them.

; inside the com zone, run by Verisign
youtube.com.       NS  ns1.google.com.    ; delegation to Google's servers
example.com.       NS  ns1.example.com.   ; delegation
ns1.example.com.   A   192.0.2.53         ; glue: the server sits inside the child

The DNS message. A query and its response share one format: a 12-byte header, then four sections. The header holds an identification number (the reply copies it, so the asker can match each reply to its query), the flags (QR query or response; Opcode; AA authoritative answer; TC truncated; RD recursion desired; RA recursion available; RCODE the result, 0 no error and 3 no such name) and four counts. The question section carries the name, type and class asked; the answer section the records that answer it; the authority section NS records, as in a referral; the additional section useful extras, such as the glue addresses of those servers.

THE DNS MESSAGE One format for the query and the response: a 12-byte header, then four sections. 0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 Identification: the reply copies it QR Opcode AA TC RD RA Z RCODE QDCOUNT: number of questions ANCOUNT: number of answer records NSCOUNT: number of authority records ARCOUNT: number of additional records QR: 0 query, 1 response. AA: authoritative answer. TC: truncated. RD: recursion desired. RA: recursion available. Z: zero. RCODE: 0 no error, 3 the name does not exist (NXDOMAIN). FOUR SECTIONS AFTER THE HEADER Question QNAME www.example.com, QTYPE A, QCLASS IN Answer resource records that answer the question Authority NS records of the zone: a referral Additional helpful records, such as glue A records EVERY RESOURCE RECORD NAME variable TYPE 16 bits CLASS 16 bits TTL 32 bits RDLENGTH 16 bits RDATA variable The response keeps the ID and the question, sets QR to 1 and fills the answer; each travels in one UDP datagram to or from port 53.
Worked example: one query and its response
  • Query: ID 0x1A2B (6699), QR 0, Opcode 0, RD 1, QDCOUNT 1, other counts 0; question www.example.com, type A, class IN. On the wire the name is a series of labels, each led by its length: 3 www 7 example 3 com 0, 17 bytes. Size: 12 + 17 + 4 = 33 bytes, one UDP datagram to port 53.
  • Response: the same ID, QR 1, RD 1, RA 1, AA 0 when it comes from a resolver's cache, RCODE 0, QDCOUNT 1, ANCOUNT 1; the question repeated; the answer www.example.com 3600 IN A 192.0.2.80, whose name is a 2-byte pointer back to the question (name compression). Size: 33 + 16 = 49 bytes.
dig www.example.com A
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 6699
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0
;; QUESTION SECTION:
;www.example.com.            IN   A
;; ANSWER SECTION:
www.example.com.     3600    IN   A    192.0.2.80

UDP, and sometimes TCP. A query and its reply fit in one datagram each, so UDP's lack of a handshake makes lookups fast, and a lost query is simply asked again. DNS falls back to TCP port 53 for zone transfers between primary and secondary servers, and when a reply is too long for the UDP limit (512 bytes in the original rules; EDNS raises it), in which case the server sets TC and the resolver repeats the query over TCP.

The book's four DNS components are the name space (the tree of names), the name servers (which hold its parts), the resolvers (which ask on behalf of programs) and the cache (answers kept for their TTL). DNS was not built with security: forged replies can poison a cache, and DNSSEC answers this by signing records.

The book says "it is easier to remember an IP address"; it means the opposite, as its next sentences show: names are easier to remember than addresses. It also says Network Solutions manages the root domain and the com servers. That was true in the 1990s; today the root zone is managed by IANA (part of ICANN), and Verisign, which bought Network Solutions, runs com.
Asked on the paper, word for word
  • Compare DNS recursive query vs. iterative query. Explain iterative query for browsing www.youtube.com 2082 Bhadra Q7 · 2+6
  • How does a DNS recursive query work? Discuss DHCP lease renew process with example diagram. 2082 Baishakh Q7 · 2+6
  • What do you mean by DNS delegation? List the step-by-step working principle of SMTP. 2081 Bhadra Q7 · 2+6
  • What is DNS server? Explain the recursive and iterative query. 2080 Baishakh Q7 · 2+6
  • What is DNS? Why is it used? How is the DNS request from a client computer resolved from the authoritative server? Explain with necessary diagrams. 2079 Bhadra Q7 · 2+2+4
  • What are resource records in DNS? Explain the types of DNS queries with example. 2078 Bhadra Q7 · 3+5
  • What is DNS? Explain the working principle of DNS with a proper diagram. Compare IMAP and POP3 protocols. 2076 Chaitra Q7 · 1+4+3
  • Why we need proxy servers? What are the importance of DNS and HTTP(S) while you are browsing any website? 2075 Chaitra Q7 · 2+6
  • What is recursive and iterative query? Explain with suitable diagram. Discuss the DNS records. 2074 Ashwin Q7 · 6+2
  • Write short notes on: a) Simple Mail Transfer Protocol b) Doman Name Server 2072 Chaitra Q10 · 4×2
  • What is DNS? Explain the structure of DNS request and response with practical example. 2071 Chaitra Q7 · 2+6
In the exam Recursive against iterative is the favourite: draw both with numbered arrows for a real name (www.youtube.com), then a comparison table. "Working principle" or "resolved from the authoritative server" wants the iterative drawing with the eight steps. Resource records: the five fields and a table of types with examples. Delegation: NS records in the parent, with the edu.np example. The message: the header fields and the four sections, with a query and response for one name.

DHCP: how a host gets its address, and how the lease is renewed PIN 1/27

82 Ba2+6

DHCP Dynamic Host Configuration Protocol (RFC 2131): a client-server protocol over UDP (server port 67, client port 68) that leases a host an IP address for a limited time, together with its subnet mask, default gateway and DNS servers, so that no one has to configure hosts by hand.

Why it is used: a laptop or phone that joins a new network works at once; a limited pool of addresses is shared, since the addresses of devices that leave return to the pool when their leases run out; settings are changed in one place; and no two hosts are given the same address. A server can also hand out reserved (fixed) addresses, matched to a device's MAC address, for printers and servers. DHCP grew out of the older BOOTP and keeps its message format.

Getting an address: DORA. Four messages, the first and third broadcast because the client has no address yet:

  1. DHCPDISCOVER: the client broadcasts from 0.0.0.0:68 to 255.255.255.255:67: is there a DHCP server?
  2. DHCPOFFER: each server that hears it offers an address (say 192.168.1.23), the mask, the gateway, the DNS servers and a lease time.
  3. DHCPREQUEST: the client broadcasts its choice, naming the chosen server, so the other servers take back their offers.
  4. DHCPACK: the chosen server confirms and the lease begins. The client usually checks with ARP that no one else is using the address (ARP); if someone is, it sends DHCPDECLINE and starts again.
DHCP: GETTING AN ADDRESS (DORA) A new laptop with no address and the DHCP server on the hostel router, over UDP (client port 68, server port 67). DHCP client no IP address yet DHCP server 192.168.1.1, port 67 1 DHCPDISCOVER (broadcast) from 0.0.0.0:68 to 255.255.255.255:67: is there a server? 2 DHCPOFFER take 192.168.1.23, mask /24, gateway, DNS, lease 24 h 3 DHCPREQUEST (broadcast) I take 192.168.1.23 from server 192.168.1.1 4 DHCPACK lease starts: renew at 12 h (T1), rebind at 21 h (T2) Why broadcast? the client has no address yet and does not know any server Why broadcast the REQUEST? every server that made an offer sees which one was chosen and takes its own offer back Then: ARP check, use the address

The other messages: DHCPNAK (the server refuses a request), DHCPRELEASE (the client hands its address back), DHCPDECLINE (the address is already in use) and DHCPINFORM (a host with a fixed address asks only for the other settings).

The lease and its renewal. An address is lent, never given. The DHCPACK carries the lease time and two timers, which by default are:

T1=0.5×lease,T2=0.875×lease
  1. Bound (0 to T1): the client simply uses the address.
  2. Renewing (from T1): the client sends a DHCPREQUEST by unicast to the server that granted the lease. A DHCPACK renews the lease (a fresh full lease from now) and restarts both timers; a DHCPNAK makes the client stop using the address and start again with DISCOVER. With no reply, it keeps asking from time to time.
  3. Rebinding (from T2): the original server seems gone, so the client broadcasts the DHCPREQUEST to any DHCP server; an ACK from any of them renews the lease.
  4. Expiry: with no ACK by the end of the lease, the client must stop using the address at once and go back to the beginning (INIT, then DISCOVER).
RENEWING A DHCP LEASE A 24-hour lease: renew at T1 = 50 percent, rebind at T2 = 87.5 percent, give up at expiry. Example: a phone joins the hostel Wi-Fi at 07:00. T1 falls at 19:00, T2 at 04:00, and the lease expires at 07:00 the next day. ACK at any point: a fresh 24 h lease from now BOUND: USE THE ADDRESS RENEWING REBINDING 0 h lease starts 12 h T1 = 50% 21 h T2 = 87.5% 24 h expiry From 0 to T1: bound the client uses its address and sends nothing; the lease time, T1 and T2 came in the DHCPACK At T1: renewing unicast DHCPREQUEST to the server that granted the lease; ACK: renewed, timers restart; NAK: stop, and start again with DISCOVER At T2: rebinding broadcast DHCPREQUEST to any DHCP server; an ACK from any of them renews it At expiry no ACK: stop using the address, go back to DISCOVER
Worked example: a 24-hour lease on hostel Wi-Fi

A phone joins at 07:00 and is leased 192.168.1.23 for 24 hours. T1 = 0.5 × 24 = 12 hours, so at 19:00 it unicasts a renewal; normally the router answers at once and the phone holds the address until 19:00 the next day, renewing again at 07:00. If the router were rebooting all evening, the phone would keep trying until T2 = 0.875 × 24 = 21 hours, 04:00, then broadcast to any server; with still no answer by 07:00 it would drop the address and start DORA again. For an 8-day lease the same rules give T1 = 4 days and T2 = 7 days.

The client's states follow from this: INIT (no address), SELECTING (collecting offers), REQUESTING (asking for one), BOUND (using it), RENEWING (after T1) and REBINDING (after T2).

Across routers: the relay agent. Broadcasts stop at a router, so a college with one DHCP server and twenty department subnets puts a relay agent on each router interface (on a Cisco router, the ip helper-address command). The relay hears the broadcast, forwards it by unicast to the server, and writes its own address in the message's gateway field, so the server picks an address from the right subnet's pool (IPv4 addressing).

To remember it: a library book. Borrowing it is DORA; halfway through the loan the student asks the same desk to renew it (T1); if that desk stays closed, near the due date he asks any desk in the library (T2); and on the due date, renewed or not, the book goes back.

Asked on the paper, word for word
  • How does a DNS recursive query work? Discuss DHCP lease renew process with example diagram. 2082 Baishakh Q7 · 2+6
In the exam For the lease renewal, draw the time line with T1 at 50 percent and T2 at 87.5 percent, and write the unicast renew, the broadcast rebind and the expiry, with the numbers for one lease (24 hours: 12 and 21). Add DORA as the start of the lease.

6.5P2P applications

Peer-to-peer applications: BitTorrent and distributed hash tables

P2P application An application in which end hosts (peers) talk directly to one another, each acting as both client and server, with little or no reliance on an always-on server.

Four designs have been used to find who holds what:

  • Central index: one server knows which peer has which file, and files move peer to peer (Napster, 1999). Simple, but the index is a single point of failure.
  • Query flooding: each peer passes a search to its neighbours, who pass it on (Gnutella). No centre, but searches flood the network.
  • Super peers: well-connected peers keep indexes for their neighbours (KaZaA).
  • Structured, with a distributed hash table (DHT): every key has one well-defined home among the peers, found in a few hops (Chord, Kademlia).

Why P2P scales. A server must upload a copy to every client alone; in P2P every peer that has received a part also uploads it, so each newcomer adds capacity as well as demand. For a file of F bits sent to N hosts, with server upload rate us, peer upload rates ui and the slowest download rate dmin, the shortest distribution times are:

Dcs≥max(NFus, Fdmin)Dp2p≥max(Fus, Fdmin, NFus+∑ui)
Worked example: 100 students, one 100 MB file

F = 800 Mbit (100 MB), N = 100, server upload 100 Mbit/s, each peer uploads 10 Mbit/s and downloads 50 Mbit/s. Client-server: NF/us = 100 × 800 / 100 = 800 s, larger than F/d = 16 s, so about 800 s. P2P: NF/(us + N u) = 80,000 / (100 + 1,000) = 72.7 s, larger than F/us = 8 s and F/d = 16 s, so about 73 s, eleven times faster, and the gap widens as N grows.

BitTorrent (Bram Cohen, 2001) is the best-known P2P application:

  • The torrent: a small .torrent file (or a magnet link) gives the file's name, its piece size, a hash of every piece and the tracker's address.
  • Tracker and swarm: the tracker keeps the list of peers sharing the file, the swarm; a new peer gets a list of some of them and connects to several.
  • Seeders and leechers: seeders hold the whole file; leechers are still downloading, and upload the pieces they already have.
  • Pieces, rarest first: the file is split into equal pieces; a peer asks first for the pieces fewest of its neighbours have, so rare pieces spread before their owners leave. Every piece is checked against its hash, so a corrupt piece from a bad peer is thrown away.
  • Tit for tat: a peer uploads to the four neighbours that upload to it fastest, re-chosen every 10 seconds, plus one random neighbour every 30 seconds (the optimistic unchoke), so newcomers get a start and free riders are slowed.

A distributed hash table stores (key, value) pairs across the peers with no central index. Peers and keys get IDs from the same space, for example 160 bits; a key is stored at the peer whose ID is closest to it, and each peer knows a few peers at every distance, so a lookup halves the remaining distance at each hop and finds any key among N peers in about log2 N hops: about 20 hops for a million peers. BitTorrent's trackerless mode uses a Kademlia DHT, where the key is the torrent's info-hash and the value the list of peers.

Good and bad: P2P has no single point of failure and grows with its users, but it uses a lot of upload bandwidth, works badly behind NAT, is hard to control, is notorious for pirated content, and a file from an unknown peer may carry malware. Other P2P systems include early Skype, Bitcoin's network and peer-to-peer video calls in the browser (WebRTC).

To remember it: the night before an exam, a class shares notes. Instead of everyone queueing at the one photocopy shop by the gate (the server), each student copies one chapter and swaps; the more students join, the faster everyone has the whole set.

In the exam No paper has asked P2P applications yet. If one does: define P2P against client-server (networking models), then BitTorrent's torrent, tracker, pieces, rarest first and tit for tat, and one line on a DHT.

6.6Socket programming

Socket programming: the calls, and a TCP server and client HOT 5/27

82 Ba · 81 Bh · 75 Ash · 74 Ch · 73 Shr2×46+24+4

Socket programming Writing network applications against the socket API, the interface between an application process and the transport layer. A socket is an endpoint named by an IP address and a port (ports and sockets), and a program creates, connects, reads, writes and closes sockets through a fixed set of system calls.

The Berkeley (BSD) socket API, from 4.2BSD Unix in 1983, is the model that Linux, Windows (Winsock), Java and Python all copy. It treats a network connection much like a file: open it, read and write it, close it.

Socket typeTransportWhat it givesUsed by
Stream (SOCK_STREAM)TCPa reliable, ordered byte stream over a connectionHTTP, FTP, SSH, SMTP
Datagram (SOCK_DGRAM)UDPseparate messages, no connection, no delivery guaranteeDNS, DHCP, TFTP, SNMP
Raw (SOCK_RAW)none: IP itselfdirect access to IP and ICMP packets; needs administrator rightsping, traceroute
CallWhoWhat it does
socket()bothcreate an endpoint: family (IPv4), type (stream or datagram); returns a descriptor
bind()serverattach a local IP address and port to the socket
listen()servermake the socket passive, ready to accept connections, with a queue length for waiting clients
accept()serverblock until a client connects, then return a new socket for that client
connect()clientopen a connection to the server's address and port: TCP's three-way handshake happens here
send(), recv()bothwrite and read data on a connected socket (sendto() and recvfrom() for UDP)
close()bothrelease the connection: TCP sends its FIN

The order of the calls is what the exam tests. The server prepares a socket and waits: socket, bind, listen, then accept, which blocks. The client needs no bind (its operating system picks a temporary port): socket, then connect. When connect's handshake completes, accept returns, and the two exchange data and close.

TCP SOCKETS: THE CALLS IN ORDER The server must be listening before the client connects; accept() returns a new socket for each client. SERVER CLIENT socket() create an endpoint bind() attach IP and port 5000 listen() become passive, queue of 5 accept() wait; return a new socket recv() read the request send() write the reply close() end this connection socket() create an endpoint connect() to 192.168.1.10, port 5000 send() write the request recv() read the reply close() end the connection three-way handshake connection set up request data reply data FIN and ACK each way No server listening on port 5000: the client's SYN is answered with RST, and connect() fails with "connection refused".

A TCP server in C, which greets one client at a time:

/* server.c: a TCP server on port 5000 (BSD sockets, Linux) */
#include <stdio.h>
#include <string.h>
#include <unistd.h>
#include <sys/socket.h>
#include <arpa/inet.h>

int main(void) {
    int lfd = socket(AF_INET, SOCK_STREAM, 0);       /* 1. a TCP socket          */
    struct sockaddr_in me;
    memset(&me, 0, sizeof me);
    me.sin_family = AF_INET;
    me.sin_port = htons(5000);                       /* port, network byte order */
    me.sin_addr.s_addr = htonl(INADDR_ANY);          /* every local address      */
    bind(lfd, (struct sockaddr *)&me, sizeof me);    /* 2. name it: IP + port    */
    listen(lfd, 5);                                  /* 3. passive, queue of 5   */
    for (;;) {
        int cfd = accept(lfd, NULL, NULL);           /* 4. wait for a client     */
        char buf[100];
        int n = recv(cfd, buf, sizeof buf - 1, 0);   /* 5. read its request      */
        if (n > 0) {
            buf[n] = '\0';
            printf("client says: %s\n", buf);
            send(cfd, "Namaste from server\n", 20, 0);   /* 6. reply             */
        }
        close(cfd);                                  /* 7. end this client only  */
    }
}

A TCP client in C, which sends one line and prints the reply:

/* client.c: talks to the server above */
#include <stdio.h>
#include <string.h>
#include <unistd.h>
#include <sys/socket.h>
#include <arpa/inet.h>

int main(void) {
    int fd = socket(AF_INET, SOCK_STREAM, 0);              /* 1. a TCP socket    */
    struct sockaddr_in srv;
    memset(&srv, 0, sizeof srv);
    srv.sin_family = AF_INET;
    srv.sin_port = htons(5000);                            /* the server's port  */
    inet_pton(AF_INET, "192.168.1.10", &srv.sin_addr);     /* the server's IP    */
    if (connect(fd, (struct sockaddr *)&srv, sizeof srv) < 0) {  /* 2. handshake */
        perror("connect");               /* no server listening: refused         */
        return 1;
    }
    send(fd, "Hello", 5, 0);                               /* 3. the request     */
    char buf[100];
    int n = recv(fd, buf, sizeof buf - 1, 0);              /* 4. the reply       */
    if (n > 0) { buf[n] = '\0'; printf("%s", buf); }
    close(fd);                                             /* 5. FIN             */
    return 0;
}

Reading the code. htons and htonl turn the port and the address into network byte order (big-endian), whatever the machine's own order; INADDR_ANY lets the server accept on every interface it has; the listening socket lfd never carries data: each accepted client gets its own socket cfd. Real programs check every return value; a busy server handles each client in its own process (fork) or thread so that one slow client does not block the rest. Compile with gcc server.c -o server, run ./server, then the client in a second terminal.

Why the server must run first. connect() sends a SYN to the server's address and port. If no socket there is in the listening state, the server's TCP answers with RST and connect() fails with "connection refused" (ECONNREFUSED); there is nothing for the client to wait on. So the server is started first, binds its well-known port and sits in accept(), and clients come and go.

UDP is simpler: no listen, no accept, no connect. The server binds and loops on recvfrom(), which also returns the sender's address, and answers with sendto() to that address; every datagram stands alone.

Other languages, the same calls: in Java, new ServerSocket(5000) does socket, bind and listen at once, accept() returns a Socket, and the client's new Socket("192.168.1.10", 5000) connects (the book's Java version); in Python the calls keep their C names: s.bind(), s.listen(), s.accept().

The book says a datagram socket sends messages "with having logical connection"; it means without one: UDP is connectionless, and every datagram stands alone. It also prints the raw socket's constant as SOCK-RAW; it is SOCK_RAW.

To remember it: a hostel's landline. bind is getting a number from the telephone office, listen is switching the ringer on, accept is picking up when it rings, and connect is a friend dialling the number. Dial a number whose phone is not yet connected and the exchange answers "the number does not exist": that is connection refused, and why the server runs first.

Asked on the paper, word for word
  • Write Short Notes on: (Any Two) a) 802.5 Token Ring b) PGP c) Socket programming fundamentals d) X.25 Network 2082 Baishakh Q10 · 2×4
  • Write Short notes on: (Any Two) a) 802.4 Token Bus b) Framing with bit stuffing c) Server Socket programming for bind, listen and accept d) ATM 2081 Bhadra Q10 · 2×4
  • Define socket programming. How web server communication and file server communication are possible in network. Explain with used protocols. 2075 Ashwin Q7 · 6+2
  • Write short notes on: (any two) i) Types of firewals ii) FDDI iii) Socket programming 2074 Chaitra Q10 · 4+4
  • How web server communication and file server communication are possible in network, explain with used protocols. Define socket programming. 2073 Shrawan Q6 · 6+2
In the exam A short note on socket programming wants the definition, the three socket types, the table of calls and the server and client sequences drawn side by side. For "bind, listen and accept", explain each call and write the server code with comments. Say why the server must run first.

6.7Application server concepts

Proxy servers and web caching PIN 3/27

81 Ba · 75 Ch · 68 Ba2+63+54+4

Proxy server An intermediary that receives clients' requests and makes them to the destination on the clients' behalf. A caching proxy, or web cache, keeps copies of recently fetched objects on its own disk and answers repeat requests from its copies instead of fetching them again from the origin server.

How web caching works:

  1. Every request goes to the proxy: the browsers are set to use it, or the network redirects their traffic to it without their knowing (a transparent proxy).
  2. The proxy checks its cache for the URL.
  3. Hit, and still fresh (within its Cache-Control: max-age or Expires time): the proxy returns its copy at once, from the LAN.
  4. Hit, but perhaps stale: it sends the origin a conditional GET, with If-Modified-Since: the date of its copy; the origin replies 304 Not Modified with no body if nothing changed, and the copy is served, or 200 OK with the new version.
  5. Miss: the proxy opens its own TCP connection to the origin server, fetches the object, stores a copy, and forwards it to the client.
A PROXY SERVER AS A WEB CACHE Clients send every request to the proxy; it answers from its cache when it can and asks the origin server only on a miss. CAMPUS LAN Client A browser Client B browser Proxy server web cache: copies of recent objects Origin server www.example.com 1 2 1 5 3 GET, or a conditional GET 4 the object, or 304 Not Modified access link to the Internet: slow, and paid for Hit (client A): 1, 2, served from the LAN at once. Miss (client B): 1, 3, 4, 5, and the proxy keeps a copy for the next client. Hit ratio = hits / requests: the higher it is, the less traffic crosses the access link.

Why proxies are used:

  • Faster pages: a hit comes from the LAN in milliseconds instead of crossing the Internet.
  • Less traffic on the access link: the link to the ISP is the slow, paid-for part; every hit is a request that never crosses it.
  • Less load on origin servers, which see one request where a hundred students clicked.
  • Filtering and access control: block sites, or allow them only in certain hours, in one place for a whole office or campus.
  • Logging and monitoring: one place to see who used what.
  • Privacy and security: the origin sees the proxy's address, not the client's; the proxy can scan downloads for malware, and is the single exit that a firewall allows (an application gateway).
  • Sharing one connection among many users.

How much a cache saves. With a hit ratio h (the share of requests the cache answers), the average response time is:

Tavg=h×Thit+(1−h)×Tmiss
Worked example

A campus proxy answers 40 percent of requests (h = 0.4) in 10 ms; a miss takes 2 s over the busy access link. Tavg = 0.4 × 0.01 + 0.6 × 2 = 1.204 s, against 2 s with no cache; and the access link now carries only 60 percent of the requests, which also shortens the misses.

KindWhere it sits, whom it servesExample
Forward proxynear the clients, acting for them toward the whole Interneta campus or office proxy (Squid)
Reverse proxyin front of web servers, acting for the servers toward clients: caching, load balancing, TLSNginx in front of an application; a content delivery network
Transparentintercepts traffic with no browser setting, passes the client's IP on in a header, says it is a proxyan ISP's or a school's interception cache
Anonymoushides the client's IP, but says it is a proxya privacy proxy
Distortingsends a false client IP, and says it is a proxya privacy proxy
High anonymityhides the client's IP and does not say it is a proxyan "elite" proxy

A content delivery network (CDN) is caching at world scale: many reverse-proxy caches placed near users, so a video is served from a nearby copy rather than from one origin on another continent.

To remember it: the hostel's copy of a popular book. The first student who asks waits while it is fetched from the central library (a miss); the next forty borrow the hostel copy at once (hits); and once a week the warden asks the central library whether a new edition has come out (a conditional GET).

Asked on the paper, word for word
  • What is a proxy server? Why is it used? Discuss briefly on HTTP and HTTPS services. 2081 Baishakh Q7 · 4+4
  • Why we need proxy servers? What are the importance of DNS and HTTP(S) while you are browsing any website? 2075 Chaitra Q7 · 2+6
  • What is the function of proxy server? Explain about electronic mail. 2068 Baishakh Q8 · 3+5
In the exam Define a proxy server, draw the cache with a hit and a miss, then list its uses: caching (speed and bandwidth), filtering, privacy and security, logging. One line on forward against reverse proxies earns the rest.

Web, mail and DNS server optimization

Server optimization Tuning a server's hardware, software and placement so that it answers more clients, faster, without interruption: caching, load balancing, replication, efficient protocols and reliable storage.

Each kind of server has its own bottleneck, so each is tuned differently:

ServerBottleneckHow it is optimized
Webmany connections at once; disk reads; slow pages built from a databasecaching in memory, in a reverse proxy and in a CDN; compression (gzip, Brotli); persistent connections and HTTP/2; an event-driven server (Nginx) for static files; a load balancer across a farm of servers; caching database results; expiry headers so browsers keep copies
Mailqueues; the volume of spam; storagetwo or more MX records with preferences (a backup server); spam filtering at the edge (blocklists, SPF, DKIM, DMARC checks); separate submission (587) from relay (25); tuned queue and retry times; mailboxes on RAID; quotas; indexes for IMAP search
DNSquery volume; delay; attackscaching with sensible TTLs; at least two authoritative servers on different networks, kept in step by zone transfer; anycast copies; separate authoritative and recursive servers; rate limits against amplification attacks; resolvers placed close to the users

Shared by all three: reliable disks (RAID), enough memory, solid-state drives, redundant power (a UPS and a generator, which Nepali server rooms needed through the load-shedding years), two network links, and monitoring (SNMP, MRTG and PRTG).

How the result is measured: throughput (requests per second), response time, and availability, the share of time the service is up. 99.9 percent sounds high but still allows 8.76 hours of downtime a year; 99.99 percent allows 52.6 minutes.

To remember it: a results website on result day, when thousands of students open the same page within minutes. The page is cached, served by several servers behind a load balancer, its name resolved by two DNS servers, and its disks mirrored; take away any one of these and the site falls over at exactly the moment everyone needs it.

In the exam Not asked on its own so far. A RAID question's "why do networks need it" draws on this card: shared servers must stay up and stay fast.

RAID 0, RAID 1 and RAID 5: why servers need them PIN 1/27

68 Ch2+6

RAID Redundant Array of Independent (originally Inexpensive) Disks, described by Patterson, Gibson and Katz in 1988: several physical disks combined into one logical volume to gain speed (striping), protection against a disk failure (mirroring or parity), or both.

Why networks need RAID. A server is shared: a web, mail, DNS, file or database server answers hundreds of users at once.

  • Availability: hard disks are among the parts most likely to fail; without redundancy one dead disk stops the service for every user and loses the mail and data on it. With RAID 1 or 5 the server keeps running on the remaining disks while the failed one is swapped (often without switching off, hot swap) and rebuilt.
  • Performance: striping spreads reads and writes across several disks working in parallel, which suits a server facing many requests at once.
  • Capacity: several disks appear as one large volume.
  • But RAID is not a backup: a deleted file, a virus or ransomware is deleted or encrypted on every disk at once. Backups are still needed.
RAID 0, RAID 1 AND RAID 5 One volume's blocks A1, A2, ... laid out on the disks; Ap, Bp, ... are parity blocks. RAID 0: striping Capacity: all n disks Speed: fastest reads and writes Fault tolerance: none One disk fails: all data lost RAID 1: mirroring Capacity: one disk of the pair Speed: fast reads, normal writes Fault tolerance: one failed disk Cost: twice the disks RAID 5: striping + parity Capacity: n - 1 disks Speed: fast reads, slower writes Fault tolerance: any one disk Rebuild: XOR of the others A1 A3 A5 A7 Disk 1 A2 A4 A6 A8 Disk 2 A1 A2 A3 A4 Disk 1 A1 A2 A3 A4 Disk 2 (copy) A1 B1 Cp D1 Disk 1 A2 Bp C1 D2 Disk 2 Ap B2 C2 Dp Disk 3

RAID 0, striping. Blocks go round-robin across n disks (A1 on disk 1, A2 on disk 2, A3 on disk 1 ...). All the capacity is usable and reads and writes run up to n times faster, but there is no redundancy at all: one failed disk destroys the whole volume, so an array of n disks is less reliable than one disk. It suits scratch space for video editing and other data that is easy to recreate. At least 2 disks.

RAID 1, mirroring. Every block is written to two disks. The usable capacity is one disk's; reads can come from either copy (faster), writes go to both (the speed of one disk); it survives the failure of either disk, and rebuilding is a simple copy. It suits operating system disks and small critical servers (DNS, mail). At least 2 disks.

RAID 5, striping with distributed parity. Data and parity blocks are striped across n disks, at least 3, with the parity block moving to a different disk in each stripe so that no single disk becomes a bottleneck. The parity is the XOR of the data blocks in its stripe, so any one lost block is the XOR of all the others. The usable capacity is n − 1 disks; reads are fast; small writes are slower, since each must read the old data and the old parity and write both anew (four disk operations, the write penalty). It survives any one failed disk; a second failure during the long rebuild of a large disk loses everything, which is why RAID 6 keeps two parity blocks. It suits file and web servers that mostly read.

Worked example: rebuilding a lost block from parity

A stripe holds D1 = 1011, D2 = 0110 and D3 = 1100. Parity P = D1 XOR D2 XOR D3 = 0001. Disk 2 fails. Its block is rebuilt from the survivors: D1 XOR D3 XOR P = 1011 XOR 1100 XOR 0001 = 0110, which is D2.

PointRAID 0RAID 1RAID 5
Techniquestripingmirroringstriping with distributed parity
Minimum disks223
Usable capacity (n disks of size S)n × SS (one copy)(n − 1) × S
Example capacity2 × 2 TB disks: 4 TB2 × 2 TB disks: 2 TB4 × 2 TB disks: 6 TB
Disks that may failnoneone (of the pair)any one
Read speedfastestfastfast
Write speedfastestlike one diskslower (the parity update)
Best fortemporary, easily recreated datasystem disks, small critical serversfile and web servers, mostly reading

RAID 10 (a stripe of mirrors) combines the speed of RAID 0 with the safety of RAID 1, at half the raw capacity; RAID can be done by a hardware controller or by the operating system (software RAID), and a hot spare disk lets the rebuild begin the moment a disk fails.

To remember it: three friends and the semester's notes. RAID 0: two of them split the chapters and copy twice as fast, but if one loses his notebook half the course is gone. RAID 1: each writes the whole set, so either can lose his. RAID 5: three split the chapters and also keep a "check sheet", which lets them rebuild whichever one notebook goes missing.

Asked on the paper, word for word
  • Why do we need RAID in the computer networks? Define and discuss the differences between RAID 0, RAID 1 and RAID 5. 2068 Chaitra Q2 · 2+6
In the exam Start with why: shared servers must survive a disk failure and serve many users fast. Then draw the three layouts and give the comparison table: technique, minimum disks, capacity, fault tolerance, speed, use.

6.8Traffic analysers and network management

SNMP: managing network devices

SNMP Simple Network Management Protocol: an application layer protocol, over UDP, by which a manager reads and changes the variables held by agents on routers, switches, servers and printers, and by which agents report events on their own.
  • Manager (the network management station): software that polls the agents, stores and graphs the values and raises alerts: MRTG, PRTG, Zabbix.
  • Agent: a small process on each managed device that answers the manager and watches the device.
  • MIB (Management Information Base): the collection of objects an agent exposes, arranged as a tree. MIB-II (RFC 1213) defines the standard ones every device has.
  • SMI (Structure of Management Information): the rules for naming objects, their data types (integer, counter, gauge, string) and how they are encoded.
  • OID (object identifier): each object's address in the tree, a string of numbers. 1.3.6.1.2.1.1.3.0 is sysUpTime; 1.3.6.1.2.1.2.2.1.10 is ifInOctets, the count of bytes received on an interface.
SNMP: MANAGER, AGENT AND MIB The manager polls agents on UDP port 161; agents report events to the manager's port 162 as traps. Manager (NMS) MRTG, PRTG, Zabbix polls, graphs, alerts Agent on a router MIB sysUpTime, ifInOctets, ifOutOctets, ifOperStatus GetRequest, GetNextRequest, SetRequest: to UDP 161 Response: the values asked for Trap: an event report, to UDP 162 OID example: 1.3.6.1.2.1.2.2.1.10 = ifInOctets (iso.org.dod.internet.mgmt.mib-2.interfaces...), the byte counter MRTG graphs. Versions: SNMPv1 and v2c send a community string in plain text; SNMPv3 adds authentication and encryption. Agents: routers, switches, servers, printers, UPS units. Each value in the MIB is named by an object identifier (OID).
MessageDirectionWhat it does
GetRequestmanager to agent (UDP 161)read one or more variables
GetNextRequestmanager to agentread the next variable in the tree: walking a table
GetBulkRequest (v2)manager to agentread a large block in one request
SetRequestmanager to agentchange a variable: shut an interface, reset a counter
Responseagent to managerthe values, or an error
Trapagent to manager (UDP 162)report an event unasked: a link went down, a fan failed
InformRequest (v2)agent to managera trap that must be acknowledged

Versions: SNMPv1 (RFC 1157, 1990) and SNMPv2c protect access only with a community string sent in plain text (the default read-only community is "public", a well-known risk); SNMPv3 (RFC 3411 to 3418) adds real user authentication and encryption.

Worked example: link load from two readings

A manager reads a router interface's ifInOctets twice, 300 seconds apart: 1,200,000,000 and then 1,575,000,000 bytes. Average incoming rate = (1,575,000,000 − 1,200,000,000) × 8 / 300 = 10,000,000 bit/s = 10 Mbit/s. This is exactly what MRTG does every five minutes (MRTG and PRTG).

To remember it: a hostel warden (the manager) checks each room's meter (the agents' MIB) on a round every five minutes (polling, Get), can switch a room's power off from the office (Set), and a room with a short circuit calls the warden at once without waiting for the round (a trap).

In the exam No paper has asked SNMP yet. If one does: manager, agent, MIB with an OID, the message types with UDP 161 and 162, and the three versions.

Traffic graphers: MRTG and PRTG

Traffic grapher A monitoring tool that polls network devices at regular intervals, mostly over SNMP, stores the counters they report, and draws graphs of link load and device health over time.

MRTG (Multi Router Traffic Grapher), free and open source, was written by Tobias Oetiker in 1995 in Perl, with a small helper in C. Every 5 minutes, by default, it reads each interface's SNMP byte counters (ifInOctets and ifOutOctets), works out the rate from the difference (SNMP), and redraws four graphs on a web page: a daily graph of 5-minute averages, a weekly one of 30-minute averages, a monthly one of 2-hour averages and a yearly one of daily averages. Its ideas live on in RRDtool, by the same author, and in tools built on it such as Cacti.

PRTG Network Monitor (Paessler Router Traffic Grapher), from the German company Paessler, is a commercial tool that runs on Windows (free for up to 100 sensors). It discovers devices automatically and watches them through sensors, each one measured value: ping time, SNMP traffic, CPU load, disk space, an HTTP response, NetFlow records or sniffed packets. It keeps the history, draws dashboards and maps, and sends alerts by email or SMS when a value crosses a limit.

PointMRTGPRTG
Licencefree, open sourcecommercial (free up to 100 sensors)
PlatformUnix and Windows; configured by text filesWindows server, web interface
Data collectionSNMP counters, mainly trafficSNMP, ping, NetFlow, packet sniffing, WMI and more
OutputPNG graphs on HTML pagesdashboards, maps, reports, alerts
Best fora simple traffic history per linkmonitoring a whole network, with alarms

What the graphs answer: how full a link is and when (bandwidth utilisation), whether errors and discards are rising, which device is overloaded, and whether a link needs upgrading before users complain. Throughput and delay themselves are chapter 2's (delay and throughput).

To remember it: MRTG is the electricity meter with a chart. Suppose a hostel's 100 Mbit/s link shows peaks near 90 Mbit/s every night from 8 to 11 pm and almost nothing at 4 am: the graph tells the network admin the link is full only in the evening streaming hours, and whether an upgrade or a better plan is the answer.

In the exam Not asked yet. A short note: what each tool is, that both poll with SNMP, MRTG's 5-minute graphs, PRTG's sensors and alerts.

Wireshark and Packet Tracer: real packets, simulated networks

Wireshark and Packet Tracer Wireshark is a free, open-source packet analyser that captures the frames on a real network interface and decodes every layer of each one. Packet Tracer is Cisco's network simulator, in which virtual routers, switches and PCs are built, configured and watched packet by packet, with no hardware at all.

Wireshark began in 1998 as Ethereal, by Gerald Combs, and was renamed in 2006. It captures through libpcap (Npcap on Windows), usually in promiscuous mode, so it sees every frame reaching the interface, not just its own. The window has three panes: the packet list, the packet details (each layer as a tree: Ethernet, IP, TCP, HTTP) and the packet bytes in hex.

  • Capture filters decide what is recorded, in BPF syntax: port 53, host 192.168.1.10.
  • Display filters decide what is shown: dns, http.request, ip.addr == 192.168.1.10, tcp.port == 80, tcp.flags.syn == 1.
  • Follow TCP Stream rebuilds a whole conversation as text; the Statistics menu gives conversations, protocol shares and traffic graphs; TShark is the command-line version.

What a student can see with it: the three-way handshake (three-way handshake), a DNS query and the reply with the same ID (DNS), the four DORA messages (DHCP), an FTP password in plain text, and the difference between HTTP, readable, and HTTPS, only TLS records. Capture only on a network that is yours or where permission is given: other people's traffic is private.

Packet Tracer is free with a Cisco Networking Academy account. Devices are dragged onto a workspace, cabled, and configured with real IOS commands; its servers run DHCP, DNS, HTTP, FTP, TFTP and email services, so every protocol of this chapter can be practised in one file. In realtime mode the network simply runs; in simulation mode time stops, each packet appears as an envelope moving along the cables, and a click opens its contents layer by layer.

PointWiresharkPacket Tracer
Works onreal traffic, on a real interfacea simulated network
Purposetroubleshooting, security analysis, learning protocolsdesigning, configuring and learning networks
Showsevery field of every captured packetpackets moving step by step through devices
Made byan open-source community (free)Cisco (free with Networking Academy)
Limitsees only traffic that reaches the interfacea subset of real device features

To remember it: Packet Tracer is the flight simulator, Wireshark the black box of a real flight. A lab exercise uses both: build a PC, a switch and a server running DHCP and DNS in Packet Tracer and watch DORA in simulation mode; then run Wireshark on a real laptop with the filter dhcp or dns while reconnecting to Wi-Fi, and see the same messages for real.

The book says Wireshark "uses the GTK+ widget toolkit". It moved to Qt in 2015, and the GTK version was dropped in 2019.
In the exam Not asked yet. A short note on each: what it is, what it is used for, two features (Wireshark's filters and stream following; Packet Tracer's simulation mode and real IOS commands).

6.9Last minute recall

Chapter 6 in one screen

  • Ports: HTTP 80, HTTPS 443, FTP 21 and 20, SSH 22, Telnet 23, SMTP 25 and 587, DNS 53, DHCP 67 and 68, TFTP 69, POP3 110, IMAP 143, SNMP 161 and 162.
  • HTTP: stateless request and response over TCP; request line, headers, blank line, body; GET, POST, HEAD, PUT, DELETE; 1xx to 5xx; non-persistent 2 RTT per object, persistent reuses the connection.
  • HTTPS: HTTP over TLS, port 443; certificate, encryption, integrity.
  • FTP: control connection port 21 for the session, data connection port 20 per file; active PORT, passive PASV; USER, PASS, RETR, STOR, QUIT; stateful, plain-text password.
  • TFTP: UDP 69, no login, 512-byte blocks each ACKed.
  • Mail: UA, mail server, MTA, MDA, MAA; SMTP push (25), POP3 (110) and IMAP (143) pull.
  • SMTP: 220, HELO, MAIL FROM, RCPT TO, DATA 354, message ending ".", 250, QUIT 221; 7-bit ASCII.
  • POP3 against IMAP: download and delete, one device; against mail on the server, folders, state, many devices, partial fetch.
  • MIME: Content-Type, Content-Transfer-Encoding; base64 3 bytes to 4 characters (+33 percent); quoted-printable.
  • DNS: distributed hierarchical name database, UDP 53; root, TLD, authoritative, local; recursive (server does the work) against iterative (referrals); TTL caching.
  • Records: A, AAAA, CNAME, MX, NS, PTR, SOA, TXT; fields name, type, class, TTL, data.
  • Delegation: NS records (plus glue) in the parent hand a zone to the child's servers.
  • DNS message: 12-byte header (ID, flags QR AA TC RD RA RCODE, 4 counts); question, answer, authority, additional.
  • DHCP: DORA over UDP 67 and 68; T1 50 percent unicast renew, T2 87.5 percent broadcast rebind, expiry back to DISCOVER.
  • P2P: peers serve and download; BitTorrent tracker, pieces, rarest first, tit for tat; DHT in about log N hops.
  • Sockets: server socket, bind, listen, accept; client socket, connect; send, recv, close; the server runs first.
  • Proxy: web cache, hit or miss, conditional GET and 304; speed, bandwidth, filtering, privacy; forward and reverse.
  • RAID: 0 striping, no safety; 1 mirroring, half capacity; 5 parity, n − 1, one disk may fail; not a backup.
  • Monitoring: SNMP manager, agent, MIB, OID, Get, Set, Trap; MRTG 5-minute graphs; PRTG sensors; Wireshark captures; Packet Tracer simulates.

Chapter 7 · 4 hours · about 7 marks a paper · in 24 of the 27 sittings

Introduction to IPv6

IPv6 replaces IPv4 now that the world has run short of 32-bit addresses: 128-bit addresses, a simpler fixed header, options moved into extension headers, and hosts that configure themselves. IPv4 cannot simply be switched off, so the board's favourite question is how the two coexist. Every sitting since 2069 Chaitra has set one IPv6 question, usually Q8 for 8 marks.

What this chapter is about
  • Why IPv6: the problems of IPv4 (address exhaustion, NAT, a complex header, weak security and QoS, manual configuration) and the IPv6 feature that answers each.
  • The packet: the fixed 40-byte base header, field by field, and how it differs from the IPv4 header in routing and in what a router must do to each packet.
  • Extension headers: the optional headers chained behind the base header by the next header field, and their recommended order.
  • Addresses: hexadecimal colon notation and its shortening rules; unicast, anycast and multicast; IPv4 addresses written as IPv6; and how a host configures itself (SLAAC, DHCPv6).
  • Multicasting: the ff00::/8 format with its scope, the solicited-node groups that replace ARP's broadcast, and MLD.
  • Transition: coexistence; dual stack; tunneling (configured, 6to4, ISATAP, 6RD, Teredo); header translation (SIIT, NAT-PT, NAT64 with DNS64, 464XLAT); and which to choose.
Where it fits
  • IPv4 is chapter 4's: the IPv4 header (IPv4 header), classful addressing and NAT (IPv4 addressing), CIDR (supernetting); this chapter compares against them.
  • Neighbour discovery replaces ARP: ARP and NDP are compared in chapter 4 (ARP); ICMPv6 carries them, as ICMP does for IPv4 (ICMP).
  • Security and multicast routing: the AH and ESP extension headers are IPsec (IPsec); multicast between routers is chapter 4's (multicast routing).
  • Configuration and names: DHCPv6 extends DHCP (DHCP), and DNS AAAA records decide which protocol a dual-stack host uses (DNS).
What you will learn
  1. 7.1 Why IPv6: the problems of IPv4 and the advantages of IPv6
  2. 7.2 The IPv6 datagram and the IPv4 comparison
  3. 7.3 Extension headers
  4. 7.4 IPv6 addresses and autoconfiguration
  5. 7.5 IPv6 multicasting
  6. 7.6 Transition from IPv4 to IPv6
  7. 7.7 Last minute recall, chapter 7
How it is examined
  • Transition is the banker: dual stack, tunneling and header translation, each with a figure; the recent papers add 6to4, ISATAP and 6RD by name, and "which method would you suggest".
  • Why IPv6 opens most questions for 2 to 4 marks: the problems of IPv4, the advantages of IPv6, the factors behind it.
  • The datagram has been a whole 8-mark question: draw the 40-byte header 32 bits wide and give the job of each field; or compare it with IPv4's.
  • Order: the syllabus lists transition (7.4) before multicasting (7.5). The reader teaches addresses and multicasting first, because the transition methods are built out of addresses (6to4, ISATAP, IPv4-mapped).

7.1Why IPv6

Why IPv6: the problems of IPv4 and what IPv6 fixes TOP 13/27

80 Ba · 79 Bh · 78 Bh · 76 Ash · 74 Ch · 74 Ash · 73 Shr · 72 Ka · 71 Ch · 71 Shr · 70 Asa · 68 Ba · 66 Bh2+64+42+2+4

IPv6 (Internet Protocol version 6) The network layer protocol designed by the IETF to replace IPv4. It does the same job, connectionless best-effort delivery of datagrams across many networks, but with 128-bit addresses, a simpler fixed 40-byte header, options moved into extension headers, and built-in autoconfiguration, multicast and IPsec support (RFC 8200).

The same job in a new format. TCP, UDP and every application run over IPv6 unchanged; what changes is the address and the packet. Its history is short:

  • IPng: in the early 1990s the IETF saw that 32-bit addresses would run out and began work on "IP next generation".
  • The standards: first specified in RFC 1883 (1995), revised in RFC 2460 (1998), and a full Internet Standard as RFC 8200 (2017).
  • Why "6": version number 5 had already gone to an experimental streaming protocol, the Internet Stream Protocol (ST), so the new IP became version 6.

IPv4's problems, and IPv6's answer to each. IPv4 (RFC 791, 1981) was designed for a research network; it now carries billions of devices. Each deficiency is paired with the IPv6 feature that removes it:

IPv4 problemWhat goes wrongWhat IPv6 does
Address exhaustion32 bits give 232 = 4,294,967,296 addresses, fewer once private, multicast and reserved blocks are set aside, and classful allocation wasted many. IANA gave out its last free blocks on 3 February 2011; APNIC, the registry that serves Nepal, reached its last block on 15 April 2011.128-bit addresses, 2128≈3.4×1038; one /64 subnet alone holds 264≈1.8×1019, which is 232 times the whole IPv4 Internet
NAT everywhereprivate addresses behind NAT share one public address, so outside hosts cannot reach inside ones; peer-to-peer, VoIP, online games and IPsec struggle, and ISPs run carrier-grade NAT with many customers behind one addressevery device gets a global address and end-to-end connectivity returns; a firewall, not NAT, decides what may come in
Slow, complex header20 to 60 bytes, options every router must check, a checksum recomputed at every hop, fragmentation by routersfixed 40-byte header: no checksum, no router fragmentation, options in extension headers
Routing table growthclassful history and scattered allocations aggregate poorlyhierarchical allocation (registry, ISP, site /48, subnet /64) aggregates into few routes
No IP-layer securityno authentication or encryption; IPsec came later as an optionAH and ESP are defined as extension headers (IPsec)
Weak real-time supporttype of service used inconsistently; no way to mark a flowtraffic class plus a 20-bit flow label let routers recognise a flow
Configurationaddresses set by hand or by a DHCP server (DHCP)stateless autoconfiguration (SLAAC): plug and play, easy renumbering; DHCPv6 if wanted
BroadcastARP and other broadcasts interrupt every host on the linkno broadcast at all: scoped multicast and anycast
MobilityMobile IPv4 sends traffic through a home agent (triangle routing)Mobile IPv6 (RFC 6275) can route straight to the moving host

The advantages of IPv6 over IPv4, as a list; the book gives the first seven:

  1. Larger address space: 2128 addresses, enough for every phone, laptop, sensor and bulb.
  2. Better header format: fixed 40 bytes, options separated out, no checksum, so faster processing.
  3. Possibility of extension: a new feature is a new extension header or option, with no redesign of the base header.
  4. Smaller routing tables: globally unique, hierarchical prefixes in place of classes keep backbone routing efficient.
  5. Security: authentication (AH) and encryption (ESP) at the IP layer.
  6. Resource allocation: the traffic class and the flow label let a source ask for special handling of real-time audio and video.
  7. Multicast with scopes: every multicast address says how far it may travel (multicasting); anycast reaches the nearest server.
  8. Autoconfiguration: a host builds its own address from the router's advertisement (SLAAC).
  9. End-to-end connectivity: no NAT needed, which suits peer-to-peer, VoIP and IoT.
  10. Mobility and jumbograms: Mobile IPv6, and payloads over 65,535 bytes with the jumbo payload option.

The factors behind its development, and behind the world now moving to it:

  • Growth of the Internet: the free pools of IPv4 addresses, forecast to empty in the early 1990s, did empty from 2011.
  • New kinds of devices: smartphones, always-on broadband and IoT sensors each need an address, and developing countries, where many people are only now coming online, need the most.
  • The cost of NAT: carrier-grade NAT is expensive to run and breaks applications.
  • Real-time multimedia: audio and video need special handling the IPv4 design never provided.
  • Security: the demand for authentication and encryption at the network layer.
  • Simpler routing and configuration: a faster header, smaller tables, plug-and-play hosts.
  • Deployment pushes: World IPv6 Day (8 June 2011), a 24-hour trial, then World IPv6 Launch (6 June 2012), when major websites and ISPs switched IPv6 on for good; mobile operators now run IPv6-only networks.

To picture it: IPv4 is a hostel with four billion rooms for eight billion people, each with a phone and a laptop. NAT puts a whole floor behind one room number, so nobody outside can call a student by name. IPv6 gives every device its own number: one floor of the new hostel has more rooms than the whole old building.

IPsec, a claim to qualify. The book, like many older texts, calls IPsec built into IPv6. The first IPv6 node requirements did make IPsec support mandatory (RFC 4294, 2006), but RFC 6434 (2011) relaxed that to "should", and IPsec runs over IPv4 too. What IPv6 really gives is a clean place for it: the AH and ESP extension headers.
Asked on the paper, word for word
  • What are the advantages of IPv6? Briefly explain the different transition strategies. 2080 Baishakh Q8 · 2+6
  • What are the problems of IPV4? How can IPV6 reduce these problems? Explain header translation mechanism for transition from IPV4 to IPV6. 2079 Bhadra Q8 · 2+2+4
  • List advantages of IPv6 over IPv4. Explain any two suitable transition strategies for IPv4 to IPv6. 2078 Bhadra Q8 · 2+6
  • List the advantages of IPv6 over IPv4. Explain any two transition strategies for IPv4 to IPv6. 2076 Ashwin Q8 · 2+6
  • What are the factors that lead to the speedy development of IPv6? Define the process of transition from IPv4 to IPv6. 2074 Chaitra Q8 · 4+4
  • List the advantages of IPv6 over IPv4. Explain header translation and tunneling approach used for migrating IPv4 to IPv6. 2074 Ashwin Q8 · 4+4
  • What are the factors that lead to the development of IPv6? Define the process of transition from IPv4 to IPv6. 2073 Shrawan Q7 · 4+4
  • What is IPV6? What methods are used so that IPV6 and IPV4 networks are interoperable? 2072 Kartik Q8 · 2+6
  • What are the problems of IPv4? How IPv6 reduce these problems? Explain different strategies to transit from IPv4 and IPv6. 2071 Chaitra Q8 · 2+2+4
  • What are the drawbacks in IPV4? Which of these drawbacks do IPV6 solve? Explain. 2071 Shrawan Q8 · 2+6
  • What are the major problems with existing IPv4 network? Explain IPv4 addressing and sub-netting with example. 2070 Ashad Q9 · 4+4
  • What are the advantages of IPV6? The maximum payload segment is 65495 byte. Why was such strange number chosen? 2068 Baishakh Q7 · 4+4
  • Give the reason why the current world is moving to IPv6 addressing mechanism. Describe the IPv6 address types with its representation format. You are given the IPv4 address block 203.71.53.0/26; assign the IP subnet for the following network. [Figure, as text: Net A: 6 Hosts (LAN on router R1); Net B: 2 Hosts (link R1 to R2); Net C: 12 Hosts (LAN on router R2); Net E: 2 Hosts (link R2 to R3); Net F: 29 Hosts (LAN on router R3). The routers are unlabelled in the print and no Net D is drawn.] 2066 Bhadra Q5a · 2+2+6
In the exam Two marks buy four or five advantages, a line each. For "the problems of IPv4 and how IPv6 reduces them", the first and last columns of the table are the answer. "Factors that led to IPv6" wants the causes (exhaustion, new devices, NAT, real-time traffic, security), not a list of IPv6 features.

7.2The IPv6 packet format

The IPv6 datagram: a fixed 40-byte header, compared with IPv4 HOT 6/27

81 Bh · 81 Ba · 75 Ash · 72 Ch · 70 Ch · 69 Ch4+486+2

IPv6 datagram A fixed 40-byte base header followed by the payload: zero or more extension headers and then the upper-layer data (a TCP segment, a UDP datagram or an ICMPv6 message). The payload length field allows up to 65,535 bytes after the base header.
THE IPV6 BASE HEADER RFC 8200: eight fields in a fixed 40 bytes, drawn 32 bits wide; the payload follows it. BIT 0 4 12 16 24 31 Version 4 bits, = 6 Traffic class 8 bits: DSCP + ECN Flow label 20 bits: marks the packets of one flow Payload length 16 bits: bytes after the base header Next header 8 bits: 6 TCP, 17 UDP Hop limit 8 bits: the TTL renamed Source address 128 bits, four rows of 32: the sender, such as 2001:db8:acad:1::20 Destination address 128 bits: the receiver, or the next node named in a routing header 0 4 8 24 40 BYTE OFFSET 40 bytes fixed THE WHOLE PACKET Base header, 40 bytes Extension headers (optional) Upper layer: TCP, UDP, ICMPv6 payload: up to 65,535 bytes, as counted by the payload length field

Eight fields, in 32-bit rows like IPv4's, but every field sits at a fixed place, so a router finds each one without first reading a length field.

FieldBitsWhat it does
Version4the IP version, 6 (binary 0110), in the same place as IPv4's, so a node can tell the two apart
Traffic class8the class of service: a 6-bit DSCP for differentiated services and 2 ECN bits for congestion notification; the job of IPv4's type of service
Flow label20set by the source to mark the packets of one flow (one video call, one download) so routers can treat them alike, for example keep them on one path, without reading the transport header; 0 when unused (RFC 6437)
Payload length16bytes after the base header, extension headers included, up to 65,535; the base header is never counted, being always 40 bytes
Next header8what follows the base header: an extension header (0, 43, 44, 50, 51, 60) or the upper layer (6 TCP, 17 UDP, 58 ICMPv6); the same numbers as IPv4's protocol field
Hop limit8lowered by 1 at each router; at 0 the packet is dropped and an ICMPv6 Time Exceeded message goes back to the source: IPv4's time to live under an honest name
Source address128the sender's IPv6 address
Destination address128the receiver's address, or the next node to visit when a routing header is present
4+8+20+16+8+8+128+128=320 bits=40 bytes

To picture it: an IPv6 header is a courier slip with fixed printed boxes. The courier office in Butwal (a router) reads only the "to" box and stamps the hop counter; it never measures the slip or checks a seal. Extra sheets clipped behind the slip, "part 2 of 3" or "sealed", are for the receiver: those are the extension headers.

Against the IPv4 header, field by field (the IPv4 header is chapter 4's): six IPv4 fields are gone, four renamed, three kept, and one field is new.

IPV4 HEADER AGAINST IPV6 HEADER Same scale, 32 bits wide: what IPv6 kept, renamed, removed and added. IPV4 HEADER: 20 TO 60 BYTES IPV6 HEADER: 40 BYTES, FIXED Version kept IHL removed Type of service renamed Total length now payload length Identification removed: fragment header Flags Fragment offset removed Time to live now hop limit Protocol now next header Header checksum removed Source address, 32 bits kept, grows to 128 bits Destination address, 32 bits kept, grows to 128 bits Options + padding, 0 to 40 bytes removed: extension headers instead Version kept Traffic class was TOS Flow label added, 20 bits Payload length was total length Next header was protocol Hop limit was TTL Source address 128 bits Destination address 128 bits kept renamed removed added in IPv6 IPv4: 12 fields plus options, 20 to 60 bytes. IPv6: 8 fields in 40 bytes, so the addresses grow four times but the header only twice.
IPv4 field (bits)In IPv6Why
Version (4)kept, value 6tells the two versions apart
Header length, IHL (4)removedthe header is always 40 bytes
Type of service (8)renamed traffic classthe same DSCP and ECN bits
Total length (16)renamed payload lengthnow counts only what follows the fixed header
Identification (16), flags (3), fragment offset (13)removed, into the fragment extension headerrouters never fragment; only the source does, and only when it must
Time to live (8)renamed hop limitit always counted hops, never seconds
Protocol (8)renamed next headerit may now point to an extension header too
Header checksum (16)removedlink layers (the Ethernet CRC) and transport checksums already catch errors, and no router has to recompute it after changing the TTL
Source, destination (32 each)kept, 128 bits eachthe larger address space
Options and padding (up to 320)removedmoved into extension headers
(none)added: flow label (20)flow identification for quality of service

A consequence of the missing checksum: the UDP checksum, optional over IPv4, is mandatory over IPv6 (RFC 8200), and the TCP, UDP and ICMPv6 checksums cover a pseudo-header that includes both 128-bit addresses.

IPv4 and IPv6 compared overall:

PointIPv4IPv6
Address32 bits, dotted decimal: 192.168.1.20128 bits, hexadecimal with colons: 2001:db8:acad:1::20
Header20 to 60 bytes, 12 fields and options40 bytes fixed, 8 fields
Checksumin the headernone
Fragmentationby the sender and by routersby the sender only; routers send ICMPv6 Packet Too Big
Smallest link MTU68 bytes (hosts must accept 576)1,280 bytes
Optionsinside the headerextension headers
Configurationmanual or DHCPSLAAC, DHCPv6 or manual
Deliveryunicast, multicast, broadcastunicast, multicast, anycast; no broadcast
Neighbour's MAC addressARP, by broadcastneighbour discovery (ICMPv6), by multicast
SecurityIPsec optional, added laterAH and ESP as extension headers
Quality of servicetype of servicetraffic class and flow label
NATcommon; breaks end-to-endnot needed
DNS recordAAAAA
Loopback127.0.0.1::1

Routing and header manipulation. What a router does to each packet is where the new header pays off:

At each routerIPv4IPv6
Find the fieldsread IHL first: the header is 20 to 60 bytesfixed offsets in 40 bytes
Checksumverify it, then recompute it after changing the TTLnone to verify or recompute
LifetimeTTL minus 1hop limit minus 1, the only field a router changes
Optionsexamine any options, often in slow softwareskip extension headers, except hop-by-hop
Too big for the next linkfragment it, unless DF is setdrop it and send ICMPv6 Packet Too Big; the source resends smaller
Address rewritingNAT rewrites addresses, ports and checksumsnone: addresses stay end to end
Recognising a flowread port numbers deep in the packetread the flow label in the header
Route lookuplongest prefix match on 32 bitslongest prefix match on 128 bits
Routing protocolsRIP, OSPFv2, BGPRIPng, OSPFv3, multiprotocol BGP (MP-BGP), IS-IS

Critically, the gains are not free:

  • Lookups: a 128-bit route lookup needs more router memory (TCAM) for each route.
  • Two of everything: during the transition a dual-stack router keeps two routing tables and runs two sets of routing protocols.
  • Extension headers: packets carrying them, hop-by-hop above all, leave the fast hardware path and are often dropped on the real Internet (RFC 7872 measured it).
  • ICMPv6 filtering: a network that blocks ICMPv6 breaks path MTU discovery, so large packets silently vanish.
  • Aggregation: the IPv6 table stays small only if providers announce their blocks whole.
Worked example: one packet, one router

A hostel PC sends a 1,500-byte packet through the campus router towards a link whose MTU is 1,280 bytes.

  1. IPv4: the router reads IHL (5, so 20 bytes), checks the checksum, lowers the TTL from 64 to 63, recomputes the checksum, and, the packet being too big with DF clear, splits its 1,480 data bytes into two fragments of 1,276 and 244 bytes, each with a header and checksum of its own.
  2. IPv6: the router lowers the hop limit from 64 to 63, finds the packet too big, drops it and returns ICMPv6 Packet Too Big (MTU 1,280). The PC sends later packets at no more than 1,280 bytes (TCP just uses smaller segments), and they pass straight through.
The book says. It gives the flow label 24 bits, which would make the first row 36 bits wide. The flow label is 20 bits (RFC 2460, RFC 8200); 24 bits belonged to the 1995 header (RFC 1883), whose 4-bit priority field the traffic class replaced. It also counts type of service as removed and traffic class as added; most comparisons call it renamed.
Asked on the paper, word for word
  • Critically compare IPv4 and IPv6 in terms of routing and head manipulation. Explain the importance and implementation approach of 6RD for IPv6 based services on the existing IPv4 networking. 2081 Bhadra Q8 · 4+4
  • Compare the IPv4 header with IPv6 header. Explain the dual stack strategy to transit from IPv4 to IPv6. 2081 Baishakh Q8 · 4+4
  • What are the methods used to interoperate IPv6 and IPv4. Show IPv6 datagram format. 2075 Ashwin Q8 · 6+2
  • Compare the header fields of IPV6 and IPV4. Which method do you suggest for the migration of IPv6 and why? 2072 Chaitra Q7 · 4+4
  • Explain the IPv6 datagram format with appropriate figures. 2070 Chaitra Q8 · 8
  • Explain the IPv6 datagram format and the function of each field with necessary figure. 2069 Chaitra Q8 · 8
In the exam "Explain the IPv6 datagram format" has been a whole 8-mark question: draw the grid 32 bits wide with the bit positions and the 40-byte brace, then a line per field. To compare, draw the IPv4 header with each field marked kept, renamed or removed, plus the new flow label.

7.3Extension headers

Extension headers: the options moved out of the base header PIN 1/27

82 Bh2+6

Extension headers Optional headers placed between the IPv6 base header and the upper-layer data, each naming the next in its next header field. They carry what IPv4 kept in its options and its fragmentation fields, and except for hop-by-hop options they are examined only where the packet is addressed, never by the routers on the way.

Why move the options out. IPv4 options sit inside the header, so every router must check for them, though most packets carry none. IPv6 keeps the base header fixed and adds an extension header only where it is needed; a new feature is just a new header type.

EXTENSION HEADERS: THE CHAIN AND THE ORDER Each header names the next in its next header field, until the upper layer is reached. ONE PACKET WITH THREE EXTENSION HEADERS IPv6 base header next header = 0 40 bytes Hop-by-hop options next header = 43 every router reads it Routing next header = 44 the nodes to visit Fragment next header = 6 offset, M flag, ID TCP segment header and data the upper layer RECOMMENDED ORDER (RFC 8200), WITH THE NEXT HEADER CODE OF EACH 1 Hop-by-hop options 0 2 Destination options (1st) 60 3 Routing 43 4 Fragment 44 5 Authentication header (AH) 51 6 Encapsulating security payload 50 7 Destination options (last) 60 8 Upper layer TCP, UDP, ICMPv6 6, 17, 58 order inside the packet, after the base header Hop-by-hop comes first and is read by every router; the others are read only where the packet is addressed (routing: each listed node). Each appears at most once, except destination options (at most twice); next header 59 means nothing follows.

The chain of next headers. The base header's next header field names the first extension header; that header's own next header field names the second; and so on, until a value names the upper layer (6 TCP, 17 UDP, 58 ICMPv6) or 59, no next header.

Format. Each extension header starts with an 8-bit next header and, except the fixed 8-byte fragment header, an 8-bit length (in 8-byte units, not counting the first 8 bytes). Each is padded to a multiple of 8 bytes, so the next one starts on an 8-byte boundary.

OrderHeaderCodeRead byWhat it does
1Hop-by-hop options0every node on the pathmust come first, straight after the base header. Options: Pad1 (1 byte) and PadN (2 or more bytes) for alignment; Jumbo Payload for packets over 65,535 bytes (up to 232−1); Router Alert, used by MLD
2Destination options60the destination and every node a routing header listsoptions for each of those nodes
3Routing43the nodes listedaddresses to visit on the way: the IPv6 form of IPv4's loose and strict source routing
4Fragment44the final destination13-bit fragment offset, a more-fragments flag and a 32-bit identification; only the source fragments
5Authentication header (AH)51the final destinationproves the sender and the integrity of the packet (IPsec, chapter 8)
6Encapsulating security payload (ESP)50the final destinationencrypts what follows and protects its integrity
7Destination options60the final destination onlyoptions for the receiver alone
8Upper-layer header6, 17, 58TCP, UDP or ICMPv6 at the destinationthe data itself
  • Once each: every header appears at most once, except destination options, at most twice (before a routing header and before the upper layer).
  • Hop-by-hop first: when present it must follow the base header directly; since RFC 8200 a router processes it only if configured to.
  • Untouched on the way: no router inserts or deletes an extension header.

To picture it: a parcel from Kathmandu to Pokhara with stickers stacked behind the label in a fixed order: "fragile", read by every handler (hop-by-hop); "via the Mugling office" (routing); "box 2 of 3" (fragment); a wax seal (AH); a locked inner box (ESP). Only "fragile" concerns the handlers on the way.

Fragmentation, only at the source. A router never fragments an IPv6 packet:

  1. Path MTU discovery (RFC 8201): the source sends at its own link's MTU.
  2. Packet Too Big: a router that cannot forward the packet drops it and returns an ICMPv6 Packet Too Big message giving the next link's MTU.
  3. Resend smaller: the source sends smaller packets, adding a fragment header only if the data cannot be cut some other way.

Every IPv6 link must carry at least 1,280 bytes, so a packet of 1,280 bytes or less never needs fragmenting.

The book says. Its next header table gives ICMP as 2: ICMPv6 is 58 (2 is IGMP's number in IPv4). Its "only three" hop-by-hop options leave out Router Alert, used by MLD. Its "source routing" header is the routing header, whose type 0 was deprecated in 2007 (RFC 5095) after attackers used it to bounce traffic. Its "up to six extension headers" means the six types every full implementation supports.
Asked on the paper, word for word
  • List the IPv6 extension headers in order. Explain ISATAP and 6 to 4 tunneling with their address format for IPv4 to IPv6 transition. 2082 Bhadra Q8 · 2+6
In the exam "List the extension headers in order" is two marks: the eight places with their codes. For more, draw the chain (base header with next header 0, hop-by-hop with 43, routing with 44, fragment with 6, then TCP) and a line on each.

7.4IPv6 addressing

IPv6 addresses: notation, types and autoconfiguration PIN 3/27

82 Ba · 80 Bh · 66 Bh2+2+42+2+63+5

IPv6 address A 128-bit identifier for an interface (unicast, anycast) or a set of interfaces (multicast), written as eight groups of four hexadecimal digits separated by colons, with the prefix length after a slash: 2001:db8:acad:1::/64 (RFC 4291).

Hexadecimal colon notation. The 128 bits are cut into eight 16-bit groups, each written as four hexadecimal digits: 2001:0db8:0000:0000:0000:ff00:0042:8329. Two rules shorten it:

  1. Drop leading zeros in any group: 0db8 becomes db8, 0042 becomes 42, 0000 becomes 0.
  2. Replace one run of all-zero groups by ::, once only: 2001:db8:0:0:0:ff00:42:8329 becomes 2001:db8::ff00:42:8329.
  • Expanding: count the groups shown; :: stands for the missing ones, 8 minus that count.
  • Why only once: in 2001:db8::1::1 four groups are missing, and nothing says how they split: 2001:db8:0:1:0:0:0:1 or 2001:db8:0:0:1:0:0:1.
  • The canonical form (RFC 5952): lower case, the longest run of zeros shortened (the first, if two are equal), and never :: for a single zero group.

Prefixes work as in CIDR (supernetting): 2001:db8:acad:1::/64 means the first 64 bits name the network and the last 64 the interface.

  • A typical plan: an ISP holds a /32 and gives a site a /48 (a home a /56); the site cuts /64 subnets from it, 216 = 65,536 of them in a /48.
  • In a URL a literal address goes in brackets: http://[2001:db8::1]:8080/.

Three types of address, and no broadcast:

TypeDelivered toRanges and examples
Unicastone interface (one to one)global unicast 2000::/3, such as 2001:db8:acad:1::20; link-local fe80::/10; unique local fc00::/7; loopback ::1; unspecified ::
Anycastthe nearest of a set of interfaces, by routing distance (one to nearest)taken from the unicast space and given to several interfaces; the subnet-router anycast address is the prefix with an all-zero interface ID, 2001:db8:acad:1::
Multicastevery member of a group (one to many)ff00::/8: ff02::1 all nodes, ff02::2 all routers (multicasting)
IPV6 ADDRESS LAYOUTS 128 bits each, widths not to scale; the first bits decide the type. Global unicast 2000::/3 Global routing prefix 48 bits (typical), from the ISP Subnet ID 16 bits Interface ID 64 bits e.g. 2001:db8:acad:1:200:5eff:fe00:5301 (site /48, subnet 1) Link-local fe80::/10 1111111010 10 bits all zero 54 bits Interface ID 64 bits e.g. fe80::200:5eff:fe00:5301 (one link only, never routed) Unique local fc00::/7 fd 8 bits Global ID, random 40 bits Subnet ID 16 bits Interface ID 64 bits e.g. fd4b:91c2:7e33:1::10 (private, like 10.0.0.0/8) Multicast ff00::/8 ff 8 bits flags 4 bits scope 4 bits Group ID 112 bits e.g. ff02::1, all nodes on this link (no broadcast in IPv6) IPv4-mapped ::ffff:0:0/96 all zero 80 bits ffff 16 bits IPv4 address 32 bits e.g. ::ffff:192.0.2.33, written in hexadecimal ::ffff:c000:221 Anycast: a unicast address given to several interfaces; routing delivers to the nearest. Subnet-router anycast = prefix + ID 0. Also: :: unspecified, ::1 loopback, 2001:db8::/32 documentation, fec0::/10 site-local (deprecated, RFC 3879). Written as eight groups of four hex digits: drop leading zeros, and replace one run of zero groups by :: (once only).
  • Global unicast (2000::/3): routable on the Internet, like a public IPv4 address. A global routing prefix (48 bits for a typical site), a 16-bit subnet ID and a 64-bit interface ID.
  • Link-local (fe80::/10): every IPv6 interface makes one for itself; it is valid on its own link only and never forwarded. Neighbour discovery and routing protocols use it, and a host's default gateway is the router's link-local address.
  • Unique local (fc00::/7, in practice fd00::/8 with a random 40-bit global ID, RFC 4193): private addresses inside a site, like RFC 1918's 10.0.0.0/8, never routed on the Internet.
  • Site-local (fec0::/10): the older private kind, deprecated in 2004 (RFC 3879) and replaced by unique local addresses.

IPv4 addresses inside IPv6 addresses. To map an IPv4 address to IPv6, write each of its bytes as two hexadecimal digits and place the 32 bits at the end of a 128-bit pattern: 192.0.2.33 is c0, 00, 02, 21, so c000:0221. Mixed notation may keep the last 32 bits in dotted decimal.

FormLayout192.0.2.33 becomesUsed for
IPv4-mapped80 zero bits, 16 one bits, the IPv4 address::ffff:192.0.2.33, that is ::ffff:c000:221an IPv4 peer as an IPv6 socket on a dual-stack host sees it; SIIT translation
IPv4-compatible96 zero bits, the IPv4 address::192.0.2.33deprecated (RFC 4291)
NAT64 well-known prefix64:ff9b::/96, the IPv4 address64:ff9b::c000:221IPv6-only hosts reaching IPv4 servers (translation)
6to4 site prefix2002, the IPv4 address, then subnet and interface2002:c000:221::/48automatic tunnels

How a host gets an address automatically. Flags in the router's advertisements choose one of three ways:

  • SLAAC (stateless address autoconfiguration, RFC 4862): the host builds its own address from the router's prefix; no server keeps a record.
  • Stateless DHCPv6: SLAAC for the address, DHCPv6 for DNS and other settings.
  • Stateful DHCPv6 (RFC 8415): a server leases addresses, as DHCP does in IPv4.

SLAAC runs on neighbour discovery (RFC 4861), five ICMPv6 messages: router solicitation (133), router advertisement (134), neighbour solicitation (135), neighbour advertisement (136) and redirect (137). The two neighbour messages also do ARP's job (ARP and NDP).

HOW A HOST CONFIGURES ITSELF: SLAAC RFC 4862 with neighbour discovery (ICMPv6, RFC 4861): no server needed, the router only advertises the prefix. New host MAC 00-00-5E-00-53-01 Other nodes on the link Router fe80::1, advertises the prefix link-local fe80::200:5eff:fe00:5301 1 NS (135) to ff02::1:ff00:5301 DAD: is this address in use? 2 no reply in 1 second: the address is unique RS (133) to ff02::2, all routers router solicitation: any router here? 3 RA (134) to ff02::1, all nodes prefix 2001:db8:acad:1::/64, lifetimes, M and O flags 4 global 2001:db8:acad:1:200:5eff:fe00:5301, checked by DAD; the router becomes the default gateway 5 M flag set: DHCPv6 assigns the address. O flag set: DHCPv6 gives only DNS and other settings. 6 THE INTERFACE ID BY MODIFIED EUI-64 (OR A RANDOM ID, FOR PRIVACY) MAC address 00-00-5E-00-53-01 split in half 00-00-5E | 00-53-01 insert FF-FE 00-00-5E-FF-FE-00-53-01 flip bit 7 (U/L) 02-00-5E-FF-FE-00-53-01 interface ID 0200:5eff:fe00:5301 64-bit prefix from the RA + 64-bit interface ID = the full 128-bit address.
  1. Link-local address: the host makes a 64-bit interface ID and puts fe80::/64 in front: fe80::200:5eff:fe00:5301.
  2. Duplicate address detection (DAD): from the unspecified address :: it sends a neighbour solicitation for the new address to that address's solicited-node group, ff02::1:ff00:5301. A neighbour advertisement in reply means someone already has it; silence for about a second means the address is the host's.
  3. Router solicitation to all routers, ff02::2: rather than wait for the next periodic advertisement, the host asks.
  4. Router advertisement to all nodes, ff02::1: the prefix 2001:db8:acad:1::/64 with its valid and preferred lifetimes, the hop limit and MTU to use, the M (managed) and O (other configuration) flags, and often the DNS servers (the RDNSS option, RFC 8106). The router's link-local address becomes the default gateway.
  5. Global address: prefix plus interface ID, 2001:db8:acad:1:200:5eff:fe00:5301, checked by DAD in turn.
  6. DHCPv6 if flagged: with M set the address comes from a DHCPv6 server (UDP ports 546 and 547); with O set, only DNS and other settings do.

The interface ID. The classic method is modified EUI-64: split the 48-bit MAC address in half, insert FF-FE in the middle, and flip the seventh bit of the first byte (the universal/local bit). 00-00-5E-00-53-01 becomes 02-00-5E-FF-FE-00-53-01, so the interface ID is 0200:5eff:fe00:5301.

Privacy: an ID built from the MAC follows the device to every network, so websites could track a laptop by it. Current systems use random interface IDs instead, stable for each network (RFC 7217) or temporary and changing (RFC 8981).

Renumbering is easy too: when the ISP changes the prefix, the router advertises the new one, the old one's preferred lifetime runs out, and hosts move over by themselves.

To picture SLAAC: a hostel room with no warden on duty. The corridor notice gives the block and floor (the prefix); you add your roll number (the interface ID); you shout once, "is anyone using this number?" (DAD); and if nobody answers, the room is yours. Nobody keeps a register: that is stateless.

The book says. Its example address, FE80:0000:0000:0001:0800:23E7:F5DB, has only seven groups (112 bits). Its shortened form, FE80::1:0800:23E7:F5DB, is valid but stands for fe80:0:0:0:1:800:23e7:f5db (three zero groups) and keeps the leading zero of 0800; both its examples are worked in the Numericals panel. It also lists site-local, deprecated in 2004.
Asked on the paper, word for word
  • Map IPv4 addresses with its IPv6 equivalent. What are the latest best IPv6 transition methodologies? Explain anyone of them. 2082 Baishakh Q8 · 2+2+4
  • Explain the three address types in IPv6 with the IP notations. How does on IPv6 machine acquire IPv6 address automatically? 2080 Bhadra Q8 · 3+5
  • Give the reason why the current world is moving to IPv6 addressing mechanism. Describe the IPv6 address types with its representation format. You are given the IPv4 address block 203.71.53.0/26; assign the IP subnet for the following network. [Figure, as text: Net A: 6 Hosts (LAN on router R1); Net B: 2 Hosts (link R1 to R2); Net C: 12 Hosts (LAN on router R2); Net E: 2 Hosts (link R2 to R3); Net F: 29 Hosts (LAN on router R3). The routers are unlabelled in the print and no Net D is drawn.] 2066 Bhadra Q5a · 2+2+6
In the exam "Address types with notation": the hexadecimal colon form, the two shortening rules with an example, and unicast, anycast and multicast with a prefix each. "How does a machine get an address automatically": SLAAC in order, with the message sequence drawn.

7.5Multicasting

IPv6 multicasting: groups, scopes and MLD

IPv6 multicasting Delivery of one packet to every member of a group named by an address in ff00::/8. IPv6 has no broadcast, so what IPv4 did by broadcast is done with multicast groups; every multicast address carries a scope, and routers learn which groups have listeners with MLD.

How it works. As in IPv4, any node may join or leave a group at any time, and a sender needs no list of members. A group address is only ever a destination, never a source or a stop in a routing header; each link delivers one copy to each member by hardware multicast.

IPV6 MULTICAST ADDRESSES RFC 4291: ff00::/8, a scope in every address, and no broadcast at all. 1111 1111 8 bits: ff flags 0 R P T 4 bits scope 4 bits Group ID 112 bits Flags: T = 0 permanent (assigned by IANA), T = 1 temporary; P = 1 built from a unicast prefix; R = 1 rendezvous point embedded. SCOPE: HOW FAR THE GROUP REACHES scope 1 interface-local scope 2 link-local scope 4 admin-local scope 5 site-local scope 8 organization-local scope e global SOLICITED-NODE GROUP: HOW NEIGHBOUR DISCOVERY AVOIDS BROADCAST unicast address 2001:db8:acad:1:200:5eff:fe00:5301 its last 24 bits 00:5301 ff02::1:ff + those bits ff02::1:ff00:5301 Ethernet multicast MAC 33:33:ff:00:53:01 Only hosts whose address ends in 00:5301 hear it (usually one); ARP's broadcast woke every host on the link. Well-known groups: ff02::1 all nodes, ff02::2 all routers, ff02::5 OSPFv3, ff02::9 RIPng, ff02::a EIGRP, ff02::1:2 DHCPv6 agents. Routers learn which groups have listeners with MLD (ICMPv6), the IPv6 form of IGMP.
  • Prefix: the first 8 bits are 1111 1111, so every multicast address begins with ff.
  • Flags (4 bits, 0RPT): T = 0 for a permanent, well-known group assigned by IANA, T = 1 for a temporary one; P = 1 for an address built from a unicast prefix (RFC 3306); R = 1 when a rendezvous point's address is embedded (RFC 3956).
  • Scope (4 bits): how far the group reaches; a router never forwards a packet beyond its scope. IPv4 marked scope only by convention (the 239.0.0.0/8 block, TTL limits).
  • Group ID (112 bits): which group within that scope.
ScopeReach
1interface-local: within one node, for loopback
2link-local: one link, never routed
4admin-local: the smallest scope set by configuration
5site-local: one site
8organization-local: the sites of one organization
eglobal: the whole Internet

Well-known groups, all on the link (scope 2) unless stated:

AddressGroup
ff02::1all nodes: the nearest thing to a broadcast
ff02::2all routers
ff02::5, ff02::6OSPFv3 routers, OSPFv3 designated routers
ff02::9RIPng routers
ff02::aEIGRP routers
ff02::16MLDv2-capable routers
ff02::1:2all DHCPv6 relay agents and servers
ff05::1:3all DHCPv6 servers in the site (scope 5)

The solicited-node group: multicast in place of ARP's broadcast. Every unicast address automatically joins the group ff02::1:ff followed by its own last 24 bits, so 2001:db8:acad:1:200:5eff:fe00:5301 joins ff02::1:ff00:5301. To find a neighbour's MAC address, or to check an address by DAD, a host sends its neighbour solicitation to that group, not to everyone.

  • On Ethernet an IPv6 multicast address maps to the MAC address 33:33 followed by its last 32 bits (RFC 2464): 33:33:ff:00:53:01 here, 33:33:00:00:00:01 for ff02::1.
  • In hardware: the network card filters frames by that MAC address, so the only hosts disturbed are those whose addresses share the last 24 bits, usually just one.

MLD, the IPv6 IGMP. Multicast Listener Discovery lets a router learn which groups have listeners on each of its links, as IGMP does for IPv4 (multicast routing is chapter 4's).

  • Versions: MLDv1 (RFC 2710) matches IGMPv2; MLDv2 (RFC 3810) matches IGMPv3 and adds source filtering. Both are ICMPv6 messages.
  • Messages: the router sends queries (type 130); hosts answer with reports (131 in MLDv1, 143 in MLDv2) and say done (132) when they leave.
  • Kept on the link: a link-local source, a hop limit of 1 and the Router Alert hop-by-hop option; switches snoop on MLD to send a group's traffic only to the ports that asked for it.
  • Between routers, PIM-SM and PIM-SSM carry IPv6 multicast as they carry IPv4's.

To picture it: the warden shouting "room 301!" down every corridor is ARP's broadcast: everyone wakes for nothing. Calling only the rooms ending in 301, usually one, is the solicited-node group; "second-years, this block only" is a scoped group.

In the exam No paper on record has set IPv6 multicasting on its own; the syllabus lists it. Draw the format (ff, flags, scope, group ID), give the scope values, and explain the solicited-node group as the replacement for broadcast.

7.6Transition from IPv4 to IPv6

From IPv4 to IPv6: coexistence, dual stack, tunneling and translation TOP 18/27

82 Bh · 82 Ba · 81 Bh · 81 Ba · 80 Bh · 80 Ba · 79 Bh · 78 Bh · 76 Ch · 76 Ash · 75 Ch · 75 Ash · 74 Ch · 74 Ash · 73 Shr · 72 Ch · 72 Ka · 71 Ch4+42+62+2+4

Transition from IPv4 to IPv6 The gradual migration of the Internet's hosts, routers and applications from IPv4 to IPv6 while both keep working, using three families of mechanisms: dual stack, tunneling and header (address family) translation.

Why there is no switch-over day. IPv6 is not backward compatible: an IPv4-only host cannot read an IPv6 header. Billions of devices cannot all change at once, as the ARPANET's hosts did when it switched to TCP/IP on 1 January 1983, so for many years the two protocols must coexist.

Coexistence. "IPv4 and IPv6 coexistence" means the two protocols running side by side on the same Internet, often on the same hosts, links and routers, through the long migration. Nodes may be IPv4-only, IPv6-only or both, and the transition mechanisms let any two communicate:

SituationMechanism
a node must talk to both IPv4 and IPv6 hostsdual stack
two IPv6 hosts or networks separated by an IPv4-only networktunneling: IPv6 inside IPv4 (configured, 6to4, ISATAP, 6RD, Teredo)
an IPv6-only host must reach an IPv4-only hostheader translation (SIIT, NAT64 with DNS64)
IPv4 customers on an IPv6-only provider networkIPv4 tunnelled or translated over IPv6 (DS-Lite, 464XLAT, MAP)
THREE WAYS TO MOVE FROM IPV4 TO IPV6 Dual stack, tunneling and header translation: each answers a different situation. Dual stack both protocols on every node; DNS picks the version Tunneling IPv6 carried inside IPv4 across an IPv4-only region Header translation IPv6-only talks to IPv4-only; the header is rewritten IPv4-only host 192.0.2.33 Dual-stack host IPv4 + IPv6 stacks 2 addresses IPv6-only host 2001:db8:cafe::80 IPv4 IPv6 IPv6 host R1 IPv4-only network IPv4 header protocol 41 IPv6 header data R1 wraps, R2 unwraps R2 IPv6 host IPv6-only host phone, 2001:db8::20 IPv6 hdr data Translator NAT64: rewrites the header IPv4 hdr data IPv4-only server Order of use: dual stack wherever possible, tunnels to join IPv6 islands, translation once networks run IPv6 only.

To picture the three: an English letter must cross a district whose post office reads only Nepali. A clerk who reads both is dual stack; sealing the letter in a Nepali-addressed envelope, opened on the far side, is tunneling; an interpreter rewriting the letter in Nepali is translation, and some meaning can be lost.

1. Dual stack (RFC 4213). Every node runs both stacks: one application layer and one TCP/UDP layer over two network layers, IPv4 and IPv6, on the same link. Each interface holds an IPv4 address and an IPv6 address; each router keeps two routing tables and runs both sets of routing protocols (OSPFv2 and OSPFv3, say).

DUAL STACK: ONE HOST, TWO NETWORK LAYERS RFC 4213: the node runs IPv4 and IPv6 side by side and speaks to each host in its own version. DUAL-STACK HOST Application browser, mail, games Transport TCP, UDP IPv4 192.168.1.20 for A records IPv6 2001:db8:acad:1::20 for AAAA records Link layer Ethernet or Wi-Fi, one card both network layers share the link IPv4-only server 192.0.2.33 DNS has only an A record IPv6 server 2001:db8:cafe::80 DNS has an AAAA record IPv4 IPv6 HOW THE HOST CHOOSES THE VERSION Ask DNS for A and AAAA AAAA found? use IPv6, tried first only an A? use IPv4 IPv6 fails? fall back to IPv4 fast Happy Eyeballs (RFC 8305) races the two so a broken IPv6 path costs the user almost nothing.
  • Choosing the version: the source asks DNS (DNS) for the name's A (IPv4) and AAAA (IPv6) records. An AAAA record means IPv6, which the default address selection rules prefer (RFC 6724); only an A record means IPv4.
  • Happy Eyeballs (RFC 8305): if the IPv6 connection has not answered within a short delay (250 milliseconds is the recommended default), the host tries IPv4 as well and keeps whichever connects first, so a broken IPv6 path costs the user almost nothing.
  • For it: the simplest method; native speed for both protocols; nothing encapsulated or translated; each service moves to IPv6 when ready. The IETF's guidance (RFC 6180) recommends it wherever it is possible.
  • Against it: every node still needs an IPv4 address, so it does nothing about exhaustion; and two stacks mean two sets of addresses, firewall rules and routing tables to manage, secure and troubleshoot.

Example: a laptop on the college Wi-Fi gets 192.168.1.20 from DHCP and 2001:db8:acad:1::20 by SLAAC. A site with an AAAA record is fetched over IPv6, an older site with only an A record over IPv4 through the college's NAT, and the user never sees the difference.

2. Tunneling. When two IPv6 nodes or networks are separated by an IPv4-only region, the IPv6 packet travels as the payload of an IPv4 packet:

  1. Encapsulate: the dual-stack router at the tunnel entry puts the whole IPv6 packet behind an IPv4 header whose protocol field is 41 (IPv6) and whose destination is the tunnel exit.
  2. Carry: the IPv4 routers forward it like any IPv4 packet, never looking inside.
  3. Decapsulate: the exit router strips the IPv4 header and sends the original IPv6 packet on. To IPv6 the whole IPv4 region looks like one hop: the packet enters a tunnel at one end and emerges at the other.
TUNNELING: AN IPV6 PACKET INSIDE AN IPV4 PACKET RFC 4213: the IPv4 network carries IPv6 without knowing it; protocol number 41 marks the cargo. IPv6 host A 2001:db8:1::10 Router R1 192.0.2.1, entry IPv4-only network IPv4 router IPv4 router Router R2 198.51.100.1, exit IPv6 host B 2001:db8:2::20 encapsulates decapsulates WHAT TRAVELS ON EACH STRETCH IPv6 header A to B data IPv6 link: a plain IPv6 packet IPv4 header, protocol 41 192.0.2.1 to 198.51.100.1 IPv6 header A to B data inside the tunnel: IPv6 as the payload of IPv4 IPv6 header A to B data IPv6 again after R2 The IPv4 routers read only the outer header; protocol 41 tells R2 an IPv6 packet is inside. The outer header adds 20 bytes, so the tunnel MTU is 20 bytes smaller. Configured tunnels set R1 and R2 by hand; automatic ones read them from the address.

Costs: 20 bytes of extra header, so a smaller MTU; harder troubleshooting, since a traceroute sees the tunnel as one hop; and security risk, since tunnelled traffic slips past a firewall that does not look inside protocol 41. Tunnels are configured or automatic:

TunnelConnectsFar end found fromAddressStatus
Configured (manual), RFC 4213two routers, or a host and a tunnel brokerset by hand at both endsanycommon for router links
6to4, RFC 3056IPv6 sites across the IPv4 Internetthe IPv4 address inside the destination's 6to4 prefix2002:WWXX:YYZZ::/48public relays deprecated in 2015 (RFC 7526)
ISATAP, RFC 5214dual-stack hosts inside one IPv4 sitethe IPv4 address in the interface IDprefix + 0:5efe:a.b.c.dlittle used now
6RD, RFC 5969an ISP's customers over its IPv4 networkthe IPv4 bits inside the ISP's 6rd prefixISP prefix + IPv4 bitsISP deployments
Teredo, RFC 4380hosts behind IPv4 NATTeredo servers and relays, over UDP port 35442001::/32a last resort, little used now
AUTOMATIC TUNNELS: THE IPV4 ADDRESS INSIDE THE IPV6 ADDRESS Widths not to scale. Reading the IPv4 endpoint out of the address is what makes a tunnel automatic. 6to4 RFC 3056 2002 16 bits IPv4 of the site router 32 bits, public Subnet ID 16 bits Interface ID 64 bits 192.0.2.4 = c000:0204, so the site prefix is 2002:c000:204::/48 ISATAP RFC 5214 64-bit prefix fe80:: or from the ISATAP router 0000 or 0200 private or global 5efe 16 bits IPv4 of the host 32 bits 10.1.1.5 gives fe80::5efe:a01:105 and 2001:db8:acad:5:0:5efe:a01:105 6RD RFC 5969 ISP's 6rd prefix n bits, its own IPv4 of the CE 32 bits minus common Subnet ID the rest Interface ID 64 bits 2001:db8::/32 + 203.0.113.5 (cb00:7105) gives the customer 2001:db8:cb00:7105::/64 Teredo RFC 4380 2001:0000 32 bits Teredo server IPv4 32 bits flags 16 bits client port 16, obscured client public IPv4 32 bits, obscured IPv6 inside UDP (port 3544) inside IPv4, to cross a NAT: a last resort, now retired 6to4 and Teredo use fixed prefixes and public relays; 6RD is 6to4 rebuilt inside one ISP with its own prefix and relays. ISATAP works inside one site; the u bit (0200) says the embedded IPv4 address is globally unique. All four carry IPv6 in IPv4 with protocol 41, except Teredo, which uses UDP to pass through NAT.

6to4 in detail. A site whose router has a public IPv4 address takes the 48-bit prefix made of 2002 and that address in hexadecimal; 16 bits of subnet ID and the 64-bit interface IDs follow. Router 192.0.2.4 (c0, 00, 02, 04) gives the site 2002:c000:204::/48.

  • Between 6to4 sites: the sending router copies bits 17 to 48 of the destination address, the far router's IPv4 address, and tunnels straight to it. The address is the configuration.
  • To the native IPv6 Internet: packets go through a 6to4 relay router, once reached at the anycast address 192.88.99.1.
  • Its weakness: it needs a public IPv4 address, so it fails behind NAT, and the public relays belonged to no one in particular, so paths were slow, one-sided or broken. RFC 7526 deprecated the anycast relay prefix in 2015.

ISATAP in detail (Intra-Site Automatic Tunnel Addressing Protocol). It gives dual-stack hosts inside an organization IPv6 while the internal network routes only IPv4, by treating that IPv4 network as one big link for IPv6.

  • Address format: a 64-bit prefix, then the interface ID 0000:5efe and the host's 32-bit IPv4 address; 0200:5efe when that IPv4 address is globally unique (the universal/local bit). Host 10.1.1.5 gets the link-local address fe80::5efe:a01:105, also written fe80::5efe:10.1.1.5.
  • Finding the router: the host learns the ISATAP router's IPv4 address (Windows looked up the DNS name isatap), sends it a router solicitation inside IPv4, and gets back the site's prefix, say 2001:db8:acad:5::/64; its global address is then 2001:db8:acad:5:0:5efe:a01:105.
  • Forwarding: to another ISATAP host in the site, it tunnels straight to the IPv4 address in the destination's last 32 bits; to anywhere else, through the ISATAP router.

6RD in detail (IPv6 rapid deployment) is 6to4 rebuilt inside one ISP. The French ISP Free first used it, in 2007, to give its subscribers IPv6 over its existing IPv4 network; RFC 5569 (2010) describes that deployment and RFC 5969 (2010) made it a standard.

  • Importance: an ISP with an IPv4-only access network can offer IPv6 without upgrading that network first; the prefix and the relays are the ISP's own, unlike 6to4's, so the service is as reliable as the ISP; it is stateless, so it scales to millions of customers; and each customer gets a stable delegated prefix.
  • Parts: the customer edge (CE) router in each home, and the ISP's border relay (BR) routers between its IPv4 network and the IPv6 Internet.
  • Configuration: each CE learns four values, usually through DHCPv4 option 212: the 6rd prefix, its length, how many leading IPv4 bits all the ISP's customers share (and can be left out), and the BR's IPv4 address.
  • The delegated prefix: the 6rd prefix followed by the CE's remaining IPv4 bits: 2001:db8::/32, no shared bits and the CE address 203.0.113.5 (cb00:7105) give 2001:db8:cb00:7105::/64.
  • Leaving out shared bits: if every customer's address lay in 198.51.100.0/24, the ISP could drop those 24 bits and, from 2001:db8:ab00::/40, give the CE 198.51.100.7 a whole /48, 2001:db8:ab07::/48.
  • Forwarding: the CE wraps IPv6 in IPv4 (protocol 41) to the BR, or straight to another CE of the same ISP; the BR unwraps it and forwards it natively, and for the replies reads the CE's IPv4 address back out of the destination prefix.

Teredo, briefly (RFC 4380): for a host behind an IPv4 NAT, which protocol 41 cannot cross, IPv6 rides inside UDP (port 3544) inside IPv4. The address, in 2001::/32, holds the Teredo server's IPv4 address and, obscured, the client's public port and IPv4 address. It was a last resort and is little used now.

3. Header translation, also called address family translation. When one end understands only IPv6 and the other only IPv4, neither dual stack nor a tunnel helps. A translator between the two networks rewrites each packet's header in the other version and maps the addresses between the two address families.

Which way round: the book's case is a mostly IPv6 Internet with some hosts still on IPv4. Today the usual case is the reverse: an IPv6-only network, a mobile operator's say, reaching servers that still have only IPv4.

HEADER TRANSLATION: NAT64 WITH DNS64 RFC 6146 and RFC 6147, on the SIIT field rules of RFC 7915: one header rewritten as the other. DNS64: A 192.0.2.33 becomes AAAA 64:ff9b::c000:221 IPv6-only host 2001:db8:acad:1::20 NAT64 translator IPv4 pool 203.0.113.9 keeps a state table IPv4-only server 192.0.2.33 AAAA query IPv6 packet to 64:ff9b::c000:221 IPv4 packet 203.0.113.9 to 192.0.2.33 HOW EACH IPV6 FIELD IS REWRITTEN AS IPV4 IPv6 field becomes in IPv4 Version 6 Version 4, header length 5 (20 bytes, no options) Traffic class Type of service (copied) Flow label dropped: IPv4 has no such field Payload length Total length = payload length + 20 Next header Protocol (ICMPv6 58 becomes ICMP 1); extension headers dropped Hop limit Time to live (decremented, as a router does) 128-bit addresses 32-bit: the last 32 bits, or an address from the pool (no checksum) Header checksum computed; TCP and UDP checksums adjusted

The translation procedure for IPv6 to IPv4, by the SIIT rules (RFC 7915):

  1. Addresses: the IPv4 destination is taken from the low 32 bits of the IPv6 destination (an IPv4-mapped address, or the NAT64 form 64:ff9b::c000:221, which gives 192.0.2.33); the IPv6 source becomes an IPv4 address, fixed by a mapping or, in NAT64, a shared address and port from the translator's pool.
  2. Version 6 becomes 4, with a 20-byte header (header length 5, no options).
  3. Traffic class is copied into type of service (or replaced by a configured value).
  4. Flow label is dropped: IPv4 has no such field.
  5. Payload length plus 20 becomes total length.
  6. Next header becomes protocol (ICMPv6, 58, becomes ICMP, 1); hop-by-hop, routing and destination options headers are dropped, and a fragment header becomes IPv4's identification, flags and fragment offset.
  7. Hop limit becomes time to live, lowered by one, since the translator is a router.
  8. Header checksum is computed and inserted; TCP and UDP checksums are adjusted for the new addresses, and ICMPv6 messages are rewritten as ICMP ones.

Replies go through the same steps in reverse, IPv4 to IPv6. The translators in use:

TranslatorHow it worksStatus
SIIT (stateless IP/ICMP translation), RFC 7915rewrites each packet on its own, with a fixed one-to-one mapping between IPv4 and IPv6 addressescurrent; the base of the others
NAT-PT, RFC 2766 (2000)stateful translation with a DNS gateway built inmoved to Historic in 2007 (RFC 4966): fragile DNS handling, broken applications
NAT64, RFC 6146 (2011)stateful: many IPv6 clients share the translator's IPv4 addresses, told apart by port, as NAT does in IPv4current, with DNS64
DNS64, RFC 6147for a name with only an A record, answers with a made-up AAAA record: 192.0.2.33 becomes 64:ff9b::c000:221current
464XLAT, RFC 6877 (2013)a stateless translator on the device (CLAT) turns an IPv4 app's packets into IPv6; NAT64 in the network (PLAT) turns them back into IPv4current on IPv6-only mobile networks

The limits of translation: applications that carry addresses inside their data (FTP, SIP) break unless a helper (an ALG) rewrites them; end-to-end IPsec fails, since the headers change; what IPv4 has no field for (the flow label, extension headers) is lost; and a stateful translator must hold every flow's state.

The latest methods. Since the IPv4 free pools ran out, providers have moved to IPv6-only networks that carry IPv4 as a service:

  • NAT64 with DNS64, and 464XLAT: on mobile networks.
  • DS-Lite (dual-stack lite, RFC 6333): the home router tunnels IPv4 inside IPv6 to the ISP's carrier-grade NAT, the AFTR.
  • MAP-E and MAP-T (RFC 7597, RFC 7599): IPv4 addresses shared statelessly, each customer given a range of ports.
  • Compared: RFC 9313 (2022) weighs five of them against each other: 464XLAT, DS-Lite, lightweight 4over6, MAP-E and MAP-T.

Which method to choose:

SituationChooseWhy
hosts, routers and the ISP can run both, and IPv4 addresses are still to handdual stacknative, simplest, nothing translated; the IETF's first choice (RFC 6180)
IPv6 islands separated by an IPv4-only networka tunnel: configured between routers, or 6RD from the ISPreuses the IPv4 network until it is upgraded
an IPv6-only network that must reach IPv4-only contentNAT64 with DNS64; 464XLAT on phonesno IPv4 addresses needed inside
an ISP short of IPv4 addressesDS-Lite, MAP, 464XLATIPv4 as a service over IPv6-only access

For a campus or a company network, dual stack is the suggestion, with a tunnel only as a stop-gap and translation where part of the network goes IPv6-only: both protocols stay native, each service moves when ready, and nothing is translated or relayed.

The book says. Its eight translation steps, from older textbooks, set the type of service to zero, discard a "priority" field and turn extension headers into IPv4 options. RFC 7915 copies the traffic class into the type of service by default, drops the hop-by-hop, routing and destination options headers, and maps only the fragment header; "priority" was the 1995 header's field (RFC 1883).
Asked on the paper, word for word
  • List the IPv6 extension headers in order. Explain ISATAP and 6 to 4 tunneling with their address format for IPv4 to IPv6 transition. 2082 Bhadra Q8 · 2+6
  • Map IPv4 addresses with its IPv6 equivalent. What are the latest best IPv6 transition methodologies? Explain anyone of them. 2082 Baishakh Q8 · 2+2+4
  • Critically compare IPv4 and IPv6 in terms of routing and head manipulation. Explain the importance and implementation approach of 6RD for IPv6 based services on the existing IPv4 networking. 2081 Bhadra Q8 · 4+4
  • Compare the IPv4 header with IPv6 header. Explain the dual stack strategy to transit from IPv4 to IPv6. 2081 Baishakh Q8 · 4+4
  • Write short notes on: (Any Two) a) Go Back-N ARQ b) Dual Stack method in IPv6 c) Diffie-Hellman algorithm d) ATM 2080 Bhadra Q10 · 2×4
  • What are the advantages of IPv6? Briefly explain the different transition strategies. 2080 Baishakh Q8 · 2+6
  • What are the problems of IPV4? How can IPV6 reduce these problems? Explain header translation mechanism for transition from IPV4 to IPV6. 2079 Bhadra Q8 · 2+2+4
  • List advantages of IPv6 over IPv4. Explain any two suitable transition strategies for IPv4 to IPv6. 2078 Bhadra Q8 · 2+6
  • "IPv4 and IPv6 coexistence" what does this mean? Explain Dual stack approach with an appropriate figure. 2076 Chaitra Q8 · 3+5
  • List the advantages of IPv6 over IPv4. Explain any two transition strategies for IPv4 to IPv6. 2076 Ashwin Q8 · 2+6
  • “IPv4 and IPv6 coexistence” what does this mean? Explain what you mean by address family translation in IPv4/IPv6 migration process with an appropriate figure. 2075 Chaitra Q8 · 3+5
  • What are the methods used to interoperate IPv6 and IPv4. Show IPv6 datagram format. 2075 Ashwin Q8 · 6+2
  • What are the factors that lead to the speedy development of IPv6? Define the process of transition from IPv4 to IPv6. 2074 Chaitra Q8 · 4+4
  • List the advantages of IPv6 over IPv4. Explain header translation and tunneling approach used for migrating IPv4 to IPv6. 2074 Ashwin Q8 · 4+4
  • What are the factors that lead to the development of IPv6? Define the process of transition from IPv4 to IPv6. 2073 Shrawan Q7 · 4+4
  • Compare the header fields of IPV6 and IPV4. Which method do you suggest for the migration of IPv6 and why? 2072 Chaitra Q7 · 4+4
  • What is IPV6? What methods are used so that IPV6 and IPV4 networks are interoperable? 2072 Kartik Q8 · 2+6
  • What are the problems of IPv4? How IPv6 reduce these problems? Explain different strategies to transit from IPv4 and IPv6. 2071 Chaitra Q8 · 2+2+4
In the exam The chapter's banker. "The transition strategies": name all three, one small figure each. One named method: when it is used, how it works step by step, its address format (6to4, ISATAP, 6RD) and a limitation. "Which method do you suggest": dual stack, with the reason.

7.7Last minute recall

Chapter 7 in one screen

  • Why IPv6: 128-bit addresses (2128), IPv4 pools empty from 2011, no NAT, fixed header, IPsec headers, flow label, SLAAC, scoped multicast, mobility.
  • Header, 40 bytes: version 4, traffic class 8, flow label 20, payload length 16, next header 8, hop limit 8, source 128, destination 128 (bits).
  • Against IPv4: removed IHL, identification, flags, fragment offset, checksum, options; renamed TOS, total length, TTL, protocol; added flow label.
  • Extension order: hop-by-hop 0, destination options 60, routing 43, fragment 44, AH 51, ESP 50, destination options 60, upper layer (TCP 6, UDP 17, ICMPv6 58).
  • Addresses: eight groups of four hex digits; drop leading zeros; :: once; global 2000::/3, link-local fe80::/10, unique local fc00::/7, multicast ff00::/8, anycast from unicast; IPv4-mapped ::ffff:a.b.c.d.
  • SLAAC: link-local, DAD, RS 133, RA 134, prefix plus interface ID (EUI-64 or random), DHCPv6 if M or O.
  • Multicast: ff, flags, scope, group ID; solicited-node ff02::1:ff plus the last 24 bits; MLD.
  • Transition: dual stack (DNS decides); tunnels with protocol 41 (configured, 6to4 2002::/16, ISATAP ::0:5efe:a.b.c.d, 6RD, Teredo); translation (SIIT, NAT64 with DNS64, 464XLAT); choose dual stack first.

Chapter 8 · 7 hours · about 11 marks a paper · in 26 of the 27 sittings

Network security

How two parties talk safely across a network that anyone can tap: the properties secure communication needs, the cryptography that provides them (symmetric ciphers, RSA, Diffie-Hellman, digital signatures), the protocols that apply it at each layer (PGP for e-mail, SSL and TLS for TCP, IPsec and VPNs for IP, WEP and WPA2 for Wi-Fi), and the firewalls and intrusion detection systems that guard the boundary. It fills Q9 and Q10 of almost every paper: an RSA calculation on a word, a firewall question and a pair of short notes.

What this chapter is about
  • The goal: confidentiality, integrity, authentication, non-repudiation, availability and access control for messages that cross an insecure network.
  • The tools: symmetric ciphers (DES, AES), public key cryptography (RSA, Diffie-Hellman), hash functions and digital signatures.
  • Security at each layer: PGP secures an e-mail, SSL and TLS a TCP connection, IPsec and VPNs the IP packet, WEP and WPA2 the wireless link.
  • Guarding the boundary: firewalls (packet filters and router ACLs, stateful inspection, application gateways) and intrusion detection systems.
Where it fits
  • Every layer of the model (the OSI model) gets its own protection here: TLS sits between TCP (TCP) and HTTP (HTTP and HTTPS), IPsec's AH and ESP double as IPv6 extension headers (extension headers), and WEP protects the 802.11 frame (wireless LAN).
  • PGP rides on the mail system (SMTP, POP3 and IMAP); router ACLs run on the routers of chapter 4 (internetworking devices) and name its address blocks (subnetting).
  • Checksums and CRC (CRC) catch accidental errors only; the hashes, MACs and signatures here catch deliberate changes, and WEP's CRC-32 shows what goes wrong when one is used for the other.
What you will learn
  1. 8.1 Network security and the properties of secure communication
  2. 8.2 Cryptography: symmetric key and public key, classical ciphers, DES and AES
  3. 8.3 The RSA algorithm and Diffie-Hellman key exchange
  4. 8.4 Digital signatures
  5. 8.5 Securing e-mail: PGP
  6. 8.6 Securing TCP connections: SSL and TLS
  7. 8.7 Network layer security: IPsec and VPNs
  8. 8.8 Securing wireless LANs: WEP, WPA and WPA2
  9. 8.9 Firewalls and router ACLs and intrusion detection systems
  10. 8.10 Last minute recall, chapter 8
How it is examined
  • RSA on a word is the chapter's banker: 15 of the 27 sittings set it, usually for 6 marks after a short theory part. The words are worked in the Numericals panel; the method is on the RSA card.
  • Firewalls come next, in 13 sittings: what a firewall is, its types with figures, how a packet filter works, and lately a router ACL.
  • The properties of secure communication (11 sittings) and symmetric against public key cryptography (8) are the usual 2 to 4-mark openers.
  • Short notes in Q10 rotate through digital signatures, VPN, IPsec, AH and ESP, SSL, WEP, IDS, PGP and Diffie-Hellman; only 2070 Ashad of the 27 sittings set nothing from this chapter.

8.1Properties of secure communication

Network security and the properties of secure communication TOP 11/27

80 Bh · 76 Ch · 76 Ash · 75 Ch · 74 Ash · 71 Ch · 70 Ch · 69 Ch · 68 Ch · 67 Asa · 66 Po2+64+43+5

Network security The policies, practices and technologies that protect a network and the data crossing it from unauthorised access, misuse, modification and disruption, so that a sender and a receiver can communicate securely over an insecure medium.

The setting is always the same three parties. A sender (Alice) and a receiver (Bob) exchange messages over a medium they do not control, the Internet or a radio link, on which an intruder (Trudy) may intercept, read, change, delete or inject messages. Network security is everything that lets Alice and Bob trust the conversation anyway; the book puts its basic objective as communicating securely over an insecure medium.

What the intruder can do falls into four classic attacks, each breaking one property:

FOUR ATTACKS ON A MESSAGE, AND THE PROPERTY EACH BREAKS A sends to B; the intruder T interrupts, intercepts, modifies or fabricates. Interruption A B the message never arrives Violates: availability cut cable, DoS flood Interception A B T the intruder reads a copy Violates: confidentiality sniffing open Wi-Fi Modification A B T changed on the way Violates: integrity Rs 500 made Rs 5,000 Fabrication A B T sent as if from A Violates: authentication fake mail 'from the bank' Passive attack: interception, which only reads, so it is hard to detect; encryption prevents it. Active attacks: interruption, modification and fabrication (and replay, denial of service): detect them and recover.
  • Interruption: the message is destroyed or blocked (a cut cable, a jammed radio, a flooded server): an attack on availability.
  • Interception: an unauthorised party reads the message (sniffing an open Wi-Fi): an attack on confidentiality.
  • Modification: the message is changed in transit: an attack on integrity.
  • Fabrication: a false message is inserted as if from a genuine sender: an attack on authenticity.

Passive and active attacks. Interception and traffic analysis are passive: nothing changes, so they are hard to detect and are defeated by prevention, which means encryption. Interruption, modification, fabrication, replay (re-sending a captured valid message, such as a login) and denial of service are active: they alter the stream, so the aim is to detect them and recover.

The properties of secure communication are what Alice and Bob need in return. Six are named, and each is provided by a tool from later in this chapter:

PropertyWhat it meansAttack it answersProvided by
Confidentialityonly the sender and the intended receiver can understand the contentinterception, eavesdroppingencryption (AES, TLS, WPA2)
Integritythe content arrives exactly as sent, not altered by accident or on purposemodificationhash with a MAC, digital signature
Authenticationeach end can confirm that the other is who it claims to be, and that a message came from its claimed senderfabrication, masqueradepasswords, certificates, signatures
Non-repudiationthe sender cannot later deny having sent a message (nor the receiver deny receiving it)repudiationdigital signature
Availabilitythe network and its services are usable by authorised users when neededinterruption, denial of serviceredundancy, filtering, backups
Access controlonly authorised users reach a resource, and only with the rights they holdunauthorised accessfirewalls, ACLs, permissions

The CIA triad (confidentiality, integrity, availability) is the core of the list, the three every security text starts from; authentication, non-repudiation and access control complete it for two parties who communicate.

To remember them as one story, think of a cheque paid into a bank:

  • Confidentiality: nobody else reads the account number.
  • Integrity: the amount does not grow from Rs 500 to Rs 5,000 on the way.
  • Authentication: the bank checks that the signature is the account holder's.
  • Non-repudiation: the writer cannot later claim never to have written it.
  • Availability: the bank is open when the customer arrives.
  • Access control: only the cashier may open the cash drawer.

How security is maintained in a network. No single device gives all six properties, so a network is protected in layers, defense in depth: if one control fails, the next still stands. The usual procedures, in the order an administrator puts them in place:

  1. Policy and risk assessment: list the assets (servers, data, links), the threats to them and the rules: who may use what, and how.
  2. Access control: individual accounts, strong passwords or multi-factor login, least privilege, accounts removed when people leave.
  3. Encryption: TLS for web and mail, a VPN for remote and branch links, WPA2 or WPA3 on Wi-Fi, encrypted disks and backups.
  4. Perimeter control: a firewall and router ACLs at every boundary, public servers in a DMZ.
  5. Segmentation: VLANs that keep the hostel, office and server networks apart, and a separate guest Wi-Fi.
  6. Hardening and patching: updates for routers, servers and PCs; unused services and ports switched off; default passwords changed.
  7. Malware protection: antivirus or endpoint protection, and filtering of e-mail attachments and links.
  8. Monitoring: an IDS or IPS, logs collected and reviewed, alerts acted on.
  9. Availability measures: backups kept offline, redundant links and power, protection against flooding.
  10. Physical security and people: locked racks and wiring closets, users trained to spot phishing, and an incident response plan for the day something still goes wrong.
Example: securing a campus hostel network

The hostel Wi-Fi runs WPA2 with a separate password for each block and a guest network apart; the router's ACL drops Telnet and remote-desktop traffic from outside; the warden's office PCs sit on their own VLAN; the router firmware is updated each semester; the rack is in a locked room; and a notice reminds students never to share the result-portal password. Each line answers one of the six properties.

The book's list. The book gives five headings: confidentiality, authentication, non-repudiation, message integrity, and access control with availability as one; its fourth heading is printed "Message Integrity and Non-reliability", where the text beneath means integrity and non-repudiation. It also offers checksum techniques for integrity: a plain checksum or CRC stops only accidents, because an attacker who changes the message simply recomputes it, so integrity against an attacker needs a keyed MAC or a digital signature. Kurose and Ross name four properties: confidentiality, message integrity, end-point authentication and operational security. All are the six above, grouped differently.
Asked on the paper, word for word
  • What are the properties of secure communication? Use RSA algorithm to encrypt and decrypt the message "network". 2080 Bhadra Q9 · 2+6
  • Explain briefly the desirable properties of secure communication. Explain how packet filtering firewall works. 2076 Chaitra Q10 · 4+4
  • List the properties of secure communication. Encrypt and decrypt “ROSE” using RSA algorithm. 2076 Ashwin Q9 · 2+6
  • Explain briefly the desirable properties of secure communication. Explain how Packet filtering firewall Works. 2075 Chaitra Q9 · 4+4
  • Explain briefly the desirable properties of secure communication. Explain how Packet filtering firewall Works. 2074 Ashwin Q9 · 4+4
  • What is network security? Explain Virtual Private Network (VPN) with an example. 2071 Chaitra Q4 · 2+4
  • What do you mean by Network security? Explain the operation of Data Encryption Standard Algorithm? 2070 Chaitra Q10 · 3+5
  • What is network security? How can firewalls enhance network security? Explain how firewalls can protect a system. 2069 Chaitra Q10 · 2+2+4
  • Write short notes on: a) Network Security b) Router and Gateway 2068 Chaitra Q9 · 2×5
  • How the protocol SMTP does operate? Explain the procedures to make your network secured. 2067 Ashad Q10 · 3+5
  • How can we maintain the security within the communication network? Explain any one cryptography algorithm with example. 2066 Poush Q9 · 2+6
In the exam For "the properties of secure communication" list the six with one line each; for 4 marks add the attack each answers (the table, cut to three columns) and the four-attack figure. "What is network security" is the definition plus the three-party setting; "how to maintain security" or "the procedures to secure a network" is the defense-in-depth list with one example.

8.2Principles of cryptography

Cryptography: symmetric key and public key HOT 8/27

81 Ba · 75 Ch · 74 Ch · 73 Shr · 71 Ch · 71 Shr · 69 Ch · 66 Po2+64+41+7

Cryptography The science of keeping messages secure by transforming them into an unreadable form (encryption) that only the holder of the right key can turn back (decryption). Its two families differ in their keys: symmetric key cryptography uses one shared secret key, public key (asymmetric) cryptography a pair of keys, one public and one private.

The vocabulary every answer uses:

  • Plaintext (P): the original, readable message.
  • Ciphertext (C): the scrambled message that travels: C=EK(P), and decryption gives back P=DK(C).
  • Cipher: the encryption and decryption algorithms together.
  • Key (K): the secret value the algorithm works with; the same algorithm with another key gives another ciphertext.
  • Cryptanalysis: breaking a cipher without the key; cryptology covers both the making and the breaking.

Kerckhoffs's principle: the algorithm is public, only the key is secret. DES, AES and RSA are published standards that anyone may study; their security comes from the size of the key space, so large that trying every key (brute force) takes too long.

SYMMETRIC KEY AND PUBLIC KEY CRYPTOGRAPHY One shared secret key at both ends, or a key pair of which only the receiver holds the private half. SYMMETRIC (SECRET KEY): ONE SHARED KEY Plaintext the message Encrypt DES, AES Ciphertext unreadable Decrypt same algorithm Plaintext at B key K (shared secret) the same key K K must reach B secretly first PUBLIC KEY (ASYMMETRIC): A KEY PAIR FOR EACH USER Plaintext the message Encrypt RSA, ECC Ciphertext unreadable Decrypt RSA Plaintext at B B's public key (anyone) B's private key (B only) only the public key travels Symmetric: fast; but n users need n(n-1)/2 keys, each shared in secret. Public key: slow; 2n keys and nothing secret to share, so real systems use it to send a symmetric session key (hybrid).

Symmetric key (secret key, conventional) cryptography. The sender and the receiver share one secret key, used both to encrypt and to decrypt. It is fast enough for bulk data: disk encryption, TLS records, VPN tunnels and Wi-Fi all run on it.

Its weakness is key distribution: the key must reach the other side secretly before the first message, and every pair of users needs its own key, so n users need n(n−1)/2 keys (100 users: 4,950 keys). It comes in two kinds:

  • Block ciphers encrypt a fixed block at a time: DES (64-bit blocks), 3DES, AES (128-bit blocks), IDEA, Blowfish.
  • Stream ciphers XOR the data with a keystream, bit by bit or byte by byte: RC4 (used in WEP), ChaCha20.

Public key (asymmetric) cryptography. Each user has a key pair: a public key, published to everyone, and a private key that never leaves its owner; what one key encrypts, only the other decrypts. Whitfield Diffie and Martin Hellman published the idea in 1976.

  • For secrecy: to send a secret to B, A encrypts with B's public key, and only B's private key can decrypt it.
  • For signing: B encrypts a digest with its private key, and anyone checks it with B's public key (digital signatures).
  • Gain and cost: it solves key distribution, as nothing secret is shared and n users need only 2n keys, but it is slow, computing with numbers hundreds of digits long.
  • Examples: RSA, Diffie-Hellman, ElGamal, elliptic curve cryptography (ECC) and DSA.

To remember the difference, think of padlocks. Symmetric key is one lock with two identical keys: you keep one and must somehow get the other to a friend in Dharan without anyone copying it on the way. Public key is a pile of open padlocks handed out to anyone: a stranger can snap one shut on a box addressed to you, but only your one key opens it.

PointSymmetric keyPublic key (asymmetric)
Keysone shared secret keya pair: a public key and a private key
Who holds themboth parties, kept secretpublic key: anyone; private key: its owner only
Encrypt, decryptthe same keyone key of the pair encrypts, the other decrypts
Speedfast; suits long messages and bulk dataslow; suits short data such as keys and digests
Key distributionthe hard part: the key must be shared secretly firsteasy: publish the public key (a certificate vouches for it)
Keys for n usersn(n−1)/22n
Key length for equal strength128 bits (AES-128)3072 bits (RSA-3072), by NIST SP 800-57
Servicesconfidentialityconfidentiality, authentication, non-repudiation, key exchange
ExamplesDES, 3DES, AES, IDEA, RC4RSA, Diffie-Hellman, ElGamal, ECC, DSA

Hybrid use, the best of both. Real protocols use public key cryptography only to agree on or protect a fresh random session key, then encrypt the data with a fast symmetric cipher under that key: PGP, TLS and IPsec all work this way.

The types of encryption used in security, as one paper asks it: symmetric key and asymmetric (public key) encryption are the two types. Beside them sits the hash function (MD5, SHA-1, SHA-256), a keyless, one-way transformation of any message into a fixed-length digest; it cannot be decrypted, so it gives integrity rather than secrecy. The oldest ciphers, substitution and transposition, are on the next card (classical ciphers).

Asked on the paper, word for word
  • What is public key cryptography? Encrypt the word "security" using the RSA algorithm. Also show the decryption to obtain the plaintext. 2081 Baishakh Q9 · 1+7
  • Write short notes on: (Any two) a) Digital Signature b) VPN c) Symmetric key cryptography 2075 Chaitra Q10 · 4+4
  • Define type of Encryption used in security. How PGP can secure email communication? 2074 Chaitra Q9 · 5+3
  • Compare symmetric key encryption method with asymmetric key encryption. Explain RSA algorithm with example. 2073 Shrawan Q8 · 3+5
  • What is public key cryptography? Explain about RSA algorithm in detail. 2071 Chaitra Q9 · 2+6
  • What is cryptography? Differentiate between symmetric key and public key cryptography. 2071 Shrawan Q9 · 2+6
  • Compare symmetric key encryption method with asymmetric key encryption. Describe the operation of RSA algorithm. 2069 Chaitra Q9 · 4+4
  • How can we maintain the security within the communication network? Explain any one cryptography algorithm with example. 2066 Poush Q9 · 2+6
In the exam "What is cryptography" (2 marks): the definition and the plaintext, key and ciphertext vocabulary. "What is public key cryptography" (1 or 2): the key pair and who uses which key. "Differentiate symmetric and public key" (3 to 6): the table, six rows or more, with the figure. "Types of encryption" (5): symmetric and asymmetric with examples, the hash function beside them, and the hybrid scheme.

Classical ciphers: substitution and transposition

Classical ciphers The traditional, pre-computer ciphers that work on letters, in two kinds: a substitution cipher replaces each letter by another and keeps the order; a transposition cipher keeps the letters but changes their order.

Why they still matter: every modern symmetric cipher is built from these two operations, repeated many times under a key. DES's S-boxes substitute and its P-boxes transpose; AES's SubBytes substitutes and its ShiftRows transposes (DES and AES).

Caesar cipher (shift cipher): each letter moves k places along the alphabet, wrapping round from z to a.

C=(P+k)mod26,P=(C−k)mod26
Worked example: Caesar with k = 2 (the book's)

i am a student becomes k co c uvwfgpv: i to k, a to c, m to o, s to u, t to v, u to w, d to f, e to g, n to p. With only 25 useful keys, an attacker simply tries them all.

Monoalphabetic cipher: any rearrangement of the alphabet is the key, so there are 26!≈4×1026 keys and brute force is hopeless. It still falls to frequency analysis: e, t and a are the commonest English letters, and the commonest ciphertext letters give them away. With Kurose and Ross's key:

plaintext:  abcdefghijklmnopqrstuvwxyz
ciphertext: mnbvcxzasdfghjklpoiuytrewq
attack  becomes  muumbf

Polyalphabetic cipher: several substitutions used in turn, so the same plaintext letter can become different ciphertext letters and the frequencies blur. The Vigenère cipher is the classic one: a key word gives the shifts.

The book's example uses two Caesar ciphers, C1 with k=2 and C2 with k=5, in the repeating pattern C1, C2, C1: i am a student becomes k fo c xvwigpy, its two a's turning into f and c.

Transposition (columnar) cipher: write the message in rows under a numbered key, then read the columns off in the order of the key. The letters are untouched; only their positions change.

Worked example: columnar transposition with the key 3 1 4 2
key:    3 1 4 2
        M E E T
        A T R A
        T N A P
        A R K X      (X pads the last row)

read the column under 1, then 2, 3 and 4:
ETNR  TAPX  MATA  ERAK   gives   ETNRTAPXMATAERAK

The receiver, knowing the key, writes the four groups back into their columns and reads the rows: MEET AT RATNAPARK.

PointSubstitutionTransposition
Changesthe lettersthe order of the letters
Letter frequencieshidden only by polyalphabetic formsunchanged: the same letters appear
ExamplesCaesar, monoalphabetic, Vigenèrecolumnar, rail fence
In modern ciphersS-boxes, SubBytesP-boxes, ShiftRows

To remember it: a note passed in class with every letter written two places on is a Caesar cipher; the same note written in a grid and read down the columns is a transposition. Both fool a casual reader and neither survives a determined one, which is why modern ciphers repeat both, ten or sixteen times over, under a long key.

The book's slips. Its Caesar answer, printed "k co c UV FG PV", drops the w: the ciphertext is k co c uvwfgpv. Its monoalphabetic key repeats the letter i (the sixteenth letter should be l, as in Kurose and Ross), and its answer QZZQEA for "attack" comes from another key, the keyboard order qwerty..., in which a becomes q, t becomes z, c becomes e and k becomes a. With the printed key, "attack" is muumbf.

DES and AES: the symmetric block ciphers PIN 4/27

82 Ba · 81 Bh · 70 Ch · 66 Bh2+63+33+5

DES and AES Two standard symmetric block ciphers. DES (Data Encryption Standard, FIPS 46, 1977) encrypts 64-bit blocks with a 56-bit key in 16 Feistel rounds. AES (Advanced Encryption Standard, FIPS 197, 2001) encrypts 128-bit blocks with a 128, 192 or 256-bit key in 10, 12 or 14 rounds, and has replaced DES.

A block cipher takes a fixed-size block of plaintext and a key, and gives a ciphertext block of the same size. It is built from three parts repeated in rounds: P-boxes that permute (transpose) bits, S-boxes that substitute groups of bits non-linearly, and an XOR with a round key drawn from the main key.

Shannon's two goals guide the design: confusion (each ciphertext bit depends on the key in a complicated way) and diffusion (each plaintext bit affects many ciphertext bits).

DES in numbers: designed at IBM from its Lucifer cipher and adopted by the US National Bureau of Standards (now NIST) in 1977. It takes a 64-bit plaintext block and a 64-bit key, of which 8 bits are parity bits, leaving a 56-bit effective key; it runs 16 rounds, each with its own 48-bit round key, and gives a 64-bit ciphertext block. The same algorithm decrypts.

DES: THE STRUCTURE, ONE ROUND AND THE F FUNCTION 64-bit block, 56-bit key, 16 Feistel rounds between an initial and a final permutation. 64-bit plaintext Initial permutation (IP) Round 1 Round 2 Round 16 32-bit swap Final permutation (IP inverse) rounds 3 to 15 64-bit ciphertext KEY SCHEDULE 64-bit key in, the 8 parity bits out: 56 bits (PC-1), split 28 + 28, shift 1 or 2 bits a round, PC-2 picks 48 bits: K1 to K16 64-bit key K1 K2 K16 Decryption: the same steps, with the round keys used in reverse (K16 first). Weakness: only 2^56 keys; found by brute force in 1998 (the EFF DES Cracker). ONE ROUND (A FEISTEL ROUND) L(i-1): 32 bits R(i-1): 32 bits f(R, Ki) Ki: 48 bits L(i) = R(i-1) R(i) = L(i-1) XOR f INSIDE f Expand E 32 to 48 bits XOR Ki 48 bits 8 S-boxes 48 to 32 bits Permute P 32 bits L(i) = R(i-1), and R(i) = L(i-1) XOR f(R(i-1), Ki) S-box example: input 011011 to S1; outer bits 0, 1 give row 1, inner bits 1101 give column 13; S1[1][13] = 5, so the output is 0101. Each S-box maps 6 bits to 4: the only non-linear step, the heart of DES security.

The operation of DES, step by step:

  1. Initial permutation (IP): the 64 input bits are rearranged by a fixed table (bit 58 moves to position 1, bit 50 to position 2, and so on).
  2. Split: the result is cut into a left half L0 and a right half R0 of 32 bits each.
  3. Sixteen Feistel rounds: in round i, Li=Ri−1 and Ri=Li−1⊕f(Ri−1,Ki): the right half passes to the left unchanged, and the left half is XORed with a function of the right half and the round key.
  4. 32-bit swap: after round 16 the two halves are exchanged.
  5. Final permutation (IP−1): the inverse of the initial permutation gives the 64-bit ciphertext.

The round function f takes the 32-bit right half and the 48-bit round key:

  • Expansion E: 32 bits become 48 by repeating 16 of them, to match the key.
  • XOR with the 48-bit round key Ki.
  • Eight S-boxes: the 48 bits are cut into eight 6-bit groups, and each S-box turns 6 bits into 4: the outer two bits pick one of 4 rows, the inner four one of 16 columns. 48 bits become 32. The S-boxes are the only non-linear step and the heart of DES's security.
  • Permutation P: a straight permutation of the 32 bits.
Worked example: one S-box lookup

The 6-bit input 011011 enters S-box S1. Its outer bits, 0 and 1, give row 01 = 1; its inner bits 1101 give column 13. Row 1 of S1 reads 0 15 7 4 14 2 13 1 10 6 12 11 9 5 3 8, and its entry in column 13 (counting from 0) is 5, so the output is 0101.

The key schedule makes the 16 round keys: permuted choice 1 (PC-1) drops the 8 parity bits and permutes the other 56; they are split into two 28-bit halves, each rotated left by 1 bit (in rounds 1, 2, 9 and 16) or 2 bits (in the others), and permuted choice 2 (PC-2) picks 48 of the 56 bits as Ki.

Decryption runs the same steps with the round keys in reverse, K16 first. A Feistel structure never needs the inverse of f, which is why one circuit serves both directions. A standard test: the key 133457799BBCDFF1 encrypts 0123456789ABCDEF to 85E813540F0AB405.

Why DES was retired: a 56-bit key allows only 256≈7.2×1016 keys, and in 1998 the Electronic Frontier Foundation's purpose-built DES Cracker found a key by brute force in under three days. Triple DES (3DES) encrypts, decrypts and encrypts again with two or three keys (112 or 168 bits): strong, but a third the speed, and now being retired in favour of AES too.

AES was chosen by NIST in an open competition, 1997 to 2000, from fifteen candidates. The winner, Rijndael, by the Belgian cryptographers Joan Daemen and Vincent Rijmen, became FIPS 197 in 2001. It is the cipher behind WPA2 Wi-Fi, TLS, VPNs and disk encryption today.

  • Block: 128 bits, held as a 4 x 4 state of 16 bytes, filled column by column.
  • Key and rounds: a 128-bit key takes 10 rounds, a 192-bit key 12, a 256-bit key 14.
  • Structure: a substitution-permutation network, not a Feistel cipher: every round changes all 16 bytes.
AES-128: TEN ROUNDS ON A 4 X 4 STATE OF BYTES Each round substitutes, shifts, mixes and adds a round key; the last round skips MixColumns. Plaintext 128 bits, 16 bytes Round 0 AddRoundKey with K0 Rounds 1 to 9 1 SubBytes: S-box per byte 2 ShiftRows: row r, r bytes left 3 MixColumns: mix columns 4 AddRoundKey: XOR Ki Round 10 SubBytes ShiftRows AddRoundKey K10 no MixColumns Ciphertext 128 bits Key expansion: one 128-bit key gives 11 round keys, K0 to K10 (44 words of 32 bits) K0 K1 to K9 K10 THE STATE: 16 BYTES, FILLED COLUMN BY COLUMN b0 b4 b8 b12 b1 b5 b9 b13 b2 b6 b10 b14 b3 b7 b11 b15 row 0 row 1 row 2 row 3 ShiftRows b0 b4 b8 b12 b5 b9 b13 b1 b10 b14 b2 b6 b15 b3 b7 b11 stays 1 left 2 left 3 left Key sizes: 128-bit key, 10 rounds; 192-bit, 12; 256-bit, 14. Not a Feistel cipher: every round changes all 16 bytes. SubBytes is the non-linear step (an inverse in GF(2^8), then an affine map); MixColumns spreads each byte over its column. Decryption runs the inverse steps (InvSubBytes, InvShiftRows, InvMixColumns) backwards.

One AES round has four steps:

  1. SubBytes: every byte is replaced through a fixed 16 x 16 S-box (the multiplicative inverse in GF(28) followed by an affine map); for example 00 becomes 63 and 53 becomes ED. This is the non-linear step.
  2. ShiftRows: row 0 stays, row 1 rotates one byte left, row 2 two bytes, row 3 three bytes.
  3. MixColumns: each column is multiplied by a fixed matrix over GF(28), so every output byte depends on all four bytes of its column.
  4. AddRoundKey: the state is XORed with the 128-bit round key.

The whole cipher: an initial AddRoundKey with K0, then rounds 1 to 9 with all four steps, then round 10 without MixColumns. Key expansion turns the 128-bit key into 44 words of 32 bits, the 11 round keys K0 to K10. Decryption applies the inverse steps (InvShiftRows, InvSubBytes, AddRoundKey, InvMixColumns) with the round keys in reverse order.

Worked example: a word entering AES
  1. Bytes: the word becomes its ASCII codes; NEPAL is 4E 45 50 41 4C, padded to 16 bytes (PKCS#7 padding adds 11 bytes, each of value 0B).
  2. State: the bytes fill the 4 x 4 grid column by column, so 4E, 45, 50 and 41 make column 0.
  3. Initial AddRoundKey: with the key of the standard's example, 2B 7E 15 16 ..., the first byte becomes 4E XOR 2B = 65.
  4. SubBytes then turns 65 into 4D, and the round goes on with ShiftRows and MixColumns.

The standard's own test (FIPS 197, Appendix B): the plaintext 32 43 F6 A8 88 5A 30 8D 31 31 98 A2 E0 37 07 34 under that key gives the ciphertext 39 25 84 1D 02 DC 09 FB DC 11 85 97 19 6A 0B 32.

PointDESAES
StandardFIPS 46, 1977FIPS 197, 2001
DesignerIBM (from Lucifer)Daemen and Rijmen (Rijndael)
Block size64 bits128 bits
Key size56 bits (64 with parity)128, 192 or 256 bits
Rounds1610, 12 or 14
StructureFeistel network: half the block changes per round substitution-permutation network: the whole block changes per round
Round stepsexpansion, XOR with the key, 8 S-boxes, permutation SubBytes, ShiftRows, MixColumns, AddRoundKey
Decryptionthe same steps, round keys reversedthe inverse steps, in reverse order
Security todaybroken by brute force (256 keys)no practical attack; the current standard
Speedslow in software (bit-level permutations)fast, with instructions for it built into most processors

By hand in the hall: ten AES rounds with key expansion do not fit the time, so "encrypt the word using any suitable AES technique" is answered with the structure above and the first round worked on the state, or with simplified AES (S-AES), a teaching version with a 16-bit block, a 16-bit key and two rounds. The Numericals panel works both papers' words.

To remember it: the phone that joins the hostel Wi-Fi encrypts every frame with AES-128 under WPA2; DES survives mostly in old systems and in exam questions.

The book's slip. Its DES operation says a 64-bit block goes in and "a 6-bit block of ciphertext comes out": the ciphertext block is 64 bits, the same size as the plaintext.
Asked on the paper, word for word
  • What is router ACL? How do you apply ACL to block the IP network 202.70.91.0/24 incoming to interface Fast Ethernet of a router? Encrypt the word “ISPNet” using anyone suitable AES technique. 2082 Baishakh Q9 · 2+6
  • What are the fundamental difference between AES and DES? Encrypt the word “ComNet” using anyone suitable AES technique. 2081 Bhadra Q9 · 2+6
  • What do you mean by Network security? Explain the operation of Data Encryption Standard Algorithm? 2070 Chaitra Q10 · 3+5
  • Write short notes on (any two) i) TCP Sliding Window Protocol ii) Secrete Key Algorithm: DES iii) ISDN Signaling and ATM AAL iv) ICMP Message Types 2066 Bhadra Q5b · 3+3
In the exam "The operation of DES" (5 marks): the structure figure, the five steps with the round equations, the f function, and the key schedule in two lines. "DES as a secret key algorithm" (a 3-mark note): 64-bit block, 56-bit key, 16 Feistel rounds, IP and final permutation, f with S-boxes. "Fundamental differences between AES and DES" (2 marks): block, key, rounds, structure and security, as five rows of the table.

8.3The RSA algorithm, and Diffie-Hellman

RSA: the public key algorithm, step by step TOP 16/27

82 Bh · 81 Ba · 80 Bh · 80 Ba · 79 Bh · 78 Bh · 76 Ch · 76 Ash · 75 Ash · 73 Shr · 72 Ch · 72 Ka · 71 Ch · 69 Ch · 68 Ba · 66 Po2+61+73+5

RSA The public key algorithm of Rivest, Shamir and Adleman (MIT, 1977). A user's public key (e, n) encrypts and private key (d, n) decrypts, with C=Memodn and M=Cdmodn; its security rests on how hard it is to factor n, the product of two large primes.

The idea in one line: multiplying two primes is easy, but given only their product, finding the primes again is practically impossible when the product is hundreds of digits long. RSA hides the private key behind exactly that problem.

RSA: MAKE THE KEYS ONCE, THEN ENCRYPT AND DECRYPT The card's example: p = 7, q = 11, e = 13, and the letter E sent as M = 5 (A = 1 to Z = 26). KEY GENERATION (DONE ONCE, BY THE RECEIVER B) 1 Choose two primes p and q p = 7, q = 11 2 n = p × q n = 7 × 11 = 77 3 φ(n) = (p - 1)(q - 1) φ = 6 × 10 = 60 4 Choose e: 1 < e < φ, gcd(e, φ) = 1 e = 13 5 Find d: (e × d) mod φ = 1 d = 37: 13 × 37 = 481 = 8 × 60 + 1 Public key (13, 77) (e, n): anyone may have it Private key (37, 77) (d, n): B keeps it secret USE (EVERY MESSAGE) A encrypts with B's public key C = Me mod n E: M = 5, C = 513 mod 77 = 26 ciphertext 26 crosses the network B decrypts with its private key M = Cd mod n M = 2637 mod 77 = 5, the letter E Signing swaps the keys: S = Md mod n; anyone checks Se mod n = M. Security: d needs φ(n), and φ(n) needs the factors p and q; with n of 2048 bits, factoring n is out of reach. Rule for words: n must exceed the largest letter value (n > 26 for A = 1 to Z = 26); each letter is encrypted alone.

The steps of the RSA algorithm. Key generation is done once, by the receiver:

  1. Choose two primes p and q, large and distinct.
  2. Compute the modulus n=p×q; its length in bits is the key size (2048 bits today).
  3. Compute ϕ(n)=(p−1)(q−1), Euler's totient (the book calls it z).
  4. Choose the public exponent e with 1<e<ϕ(n) and gcd(e,ϕ(n))=1: e shares no factor with ϕ(n). In practice e=65537.
  5. Compute the private exponent d, the inverse of e modulo ϕ(n): (e×d)modϕ(n)=1.
  6. Publish the public key (e,n); keep the private key (d,n) secret, and with it p, q and ϕ(n).

Then for every message M, a number with 0≤M<n:

Encryption: C=MemodnDecryption: M=Cdmodn

Why decryption undoes encryption: e·d=1+kϕ(n) for some whole number k, and Euler's theorem gives Mϕ(n)≡1(modn), so Cd=Med = M·(Mϕ(n))k ≡M(modn).

Why it is secure: to find d from the public (e,n), an attacker needs ϕ(n), and ϕ(n) needs p and q, the factors of n. A 2048-bit n has 617 decimal digits, and no known method factors it in any useful time. The small numbers of an exam example can be factored at a glance; they only show the method.

Worked example: the book's letter E, finished

Keys: p=7, q=11, so n=77 and ϕ(n)=6×10=60. e=13 works, as gcd(13,60)=1.

Finding d: try k=1,2,3,… until (1+60k)/13 is whole: k=8 gives 481/13=37, so d=37 (check: 13×37=481 = 8×60+1). Public key (13, 77); private key (37, 77).

Encrypt E, the 5th letter, M=5, by repeated squaring, every step reduced mod 77:

5^1 = 5
5^2 = 25
5^4 = 25^2 = 625 mod 77 = 9
5^8 = 9^2  = 81  mod 77 = 4
5^13 = 5^8 x 5^4 x 5^1 = 4 x 9 x 5 = 180 mod 77 = 26      C = 26

Decrypt C=26 with d=37=32+4+1:

26^2  = 676  mod 77 = 60
26^4  = 60^2 = 3600 mod 77 = 58
26^8  = 58^2 = 3364 mod 77 = 53
26^16 = 53^2 = 2809 mod 77 = 37
26^32 = 37^2 = 1369 mod 77 = 60
26^37 = 26^32 x 26^4 x 26^1 = 60 x 58 x 26
      : 60 x 58 = 3480 mod 77 = 15;  15 x 26 = 390 mod 77 = 5      M = 5 = E

Repeated squaring is the hall method for a big power: write the exponent as a sum of powers of two (37 = 32 + 4 + 1), square repeatedly while reducing mod n, then multiply the needed squares, reducing after each product. No number ever exceeds (n−1)2.

Finding d has two hall methods:

  • Trial: d=(1+kϕ(n))/e for k=1,2,3,…, stopping at the first whole number, as above.
  • Extended Euclidean algorithm: for 60 and 13 it runs 60 = 4 x 13 + 8, 13 = 1 x 8 + 5, 8 = 1 x 5 + 3, 5 = 1 x 3 + 2, 3 = 1 x 2 + 1, and back-substitution gives the same 37.

Encrypting a word, the usual paper question:

  1. Number the letters: A = 1 to Z = 26 is common; A = 0 to Z = 25 also works, if stated.
  2. Choose p and q so that n exceeds the largest letter value (here n=77>26), and make the keys.
  3. Encrypt and decrypt each letter on its own, in a table of letter, M, C and the decrypted M.

The book's second example does SUZANNE with p=3, q=11, n=33, e=3, d=7 and gets 28 21 20 1 5 5 26. Every word the papers set is worked in the Numericals panel.

A weakness of letter-by-letter RSA: the two N's of SUZANNE both become 5, so the ciphertext is really a substitution cipher open to frequency analysis. Real RSA encrypts one large padded number at a time (OAEP padding), and in practice encrypts only a session key or a digest, never the message itself (hybrid use, signatures).

Signing uses the same keys the other way round: S=Mdmodn with the private key, checked by anyone as Semodn=M. With the keys above, M=5 signs to S=47, and 4713mod77=5.

To remember it: anyone in Kathmandu can multiply 7 by 11 in their head; given 77, a child finds 7 and 11 again. Given a 617-digit product, no computer known today can find the two primes. That gap, easy one way and hopeless back, is the whole of RSA.

The book's slips. Its first example sets up the decryption, m=2637mod77, and stops; worked through as above it gives 5, the letter E. Its second example says e "can be any value other than" the factors 1, 2, 4, 5 and 10 of z=20; the rule is gcd(e,z)=1. The number 6 is not a factor of 20 yet shares the factor 2 with it, and fails: no d exists for e=6.
Asked on the paper, word for word
  • What do you mean by firewall? Encrypt and decrypt the “attack” using RSA. 2082 Bhadra Q9 · 2+4+2
  • What is public key cryptography? Encrypt the word "security" using the RSA algorithm. Also show the decryption to obtain the plaintext. 2081 Baishakh Q9 · 1+7
  • What are the properties of secure communication? Use RSA algorithm to encrypt and decrypt the message "network". 2080 Bhadra Q9 · 2+6
  • What is PGP? Use RSA algorithm to encrypt/decrypt the word COW. 2080 Baishakh Q9 · 3+5
  • What is a digital signature? Encrypt the message "PANDEMIC" using RSA algorithm. Also obtain the plaintext from the ciphertext. 2079 Bhadra Q9 · 1+7
  • Write down the steps involved in RSA encryption algorithm. Encrypt the word "Computer" using RSA algorithm. 2078 Bhadra Q9 · 8
  • How does a Digital Signature work? Encrypt the world HELLO using RSA algorithm. Also decrypt it by showing steps. 2076 Chaitra Q9 · 2+6
  • List the properties of secure communication. Encrypt and decrypt “ROSE” using RSA algorithm. 2076 Ashwin Q9 · 2+6
  • What is VPN? Encrypt a message "network" using RSA algorithm. 2075 Ashwin Q9 · 2+6
  • Compare symmetric key encryption method with asymmetric key encryption. Explain RSA algorithm with example. 2073 Shrawan Q8 · 3+5
  • Write down the steps involved in RSA encryption algorithm. Encrypt the word CAT using RSA algorithm, choose the suitable data for encryption by yourself according to RSA algorithm. 2072 Chaitra Q9 · 8
  • What is firewall? What are their types? Encrypt and decrypt "OVEL" message using RSA algorithm. 2072 Kartik Q9 · 1+1+6
  • What is public key cryptography? Explain about RSA algorithm in detail. 2071 Chaitra Q9 · 2+6
  • Compare symmetric key encryption method with asymmetric key encryption. Describe the operation of RSA algorithm. 2069 Chaitra Q9 · 4+4
  • What is a secure socket layer? Encrypt the message “DANGER” using RSA algorithm. 2068 Baishakh Q9 · 2+6
  • How can we maintain the security within the communication network? Explain any one cryptography algorithm with example. 2066 Poush Q9 · 2+6
In the exam "Write down the steps of RSA" or "the operation of RSA": the six key-generation steps, the two formulas, and one line on why it is secure. "Explain RSA with an example" or "in detail": add the worked letter above, showing the squarings. For a word: state the letter numbering, choose p and q with n above the largest value, then a table of letter, M, C and the decrypted M.

Diffie-Hellman key exchange PIN 2/27

80 Bh · 74 Ash2×44+4

Diffie-Hellman A key agreement protocol (Whitfield Diffie and Martin Hellman, 1976) by which two parties who share no secret exchange public values over an open channel and each computes the same secret key K=GxymodN, which an eavesdropper cannot compute. It creates a symmetric session key; it neither encrypts nor signs anything itself.

The problem it solves: symmetric ciphers need a shared key, and the network is the only channel. Diffie-Hellman makes a key appear at both ends without the key itself ever being sent.

DIFFIE-HELLMAN: A SHARED KEY THAT IS NEVER SENT The book's example: N = 23 and G = 7 are public; x = 3 stays with A and y = 6 with B. Public, known to everyone: the prime N = 23 and the generator G = 7 HOST A HOST B 1 Secret x = 3 chosen at random, never sent 2 R1 = Gx mod N 73 mod 23 = 343 mod 23 = 21 5 K = R2x mod N 43 mod 23 = 64 mod 23 = 18 3 Secret y = 6 chosen at random, never sent 4 R2 = Gy mod N 76 mod 23 = 117649 mod 23 = 4 5 K = R1y mod N 216 mod 23 = 85766121 mod 23 = 18 A sends R1 = 21 B sends R2 = 4 The eavesdropper sees 23, 7, 21 and 4 only; x or y is a discrete logarithm Both reach K = Gxy mod N = 718 mod 23 = 18, the shared session key. Unauthenticated, it falls to a man in the middle; TLS and IPsec (IKE) sign or authenticate the values.

The steps: first, both agree on two public numbers, a large prime N and a generator G (a primitive root of N); these may be sent openly.

  1. A chooses a large random secret x and computes R1=GxmodN.
  2. A sends R1 to B, never x.
  3. B chooses a large random secret y and computes R2=GymodN.
  4. B sends R2 to A, never y.
  5. Both compute the key: A finds K=R2xmodN, B finds K=R1ymodN.

Why the two keys are equal: R2x=(Gy)x=Gxy and R1y=(Gx)y=Gxy, both mod N.

Worked example: the book's numbers
  • Public: G=7, N=23.
  • A chooses x=3: R1=73mod23 = 343mod23=21.
  • B chooses y=6: R2=76mod23 = 117649mod23=4.
  • A computes K=43mod23 = 64mod23=18.
  • B computes K=216mod23=18 (as 21≡−2 and (−2)6=64≡18).

Both hold K=18=718mod23. The book's working is right.

Why an eavesdropper fails: it sees N, G, R1 and R2. To get K it needs x from R1=GxmodN: the discrete logarithm problem, infeasible for a prime of 2048 bits. (For 23 it is trivial: only x=3 gives 21.)

The weakness: man in the middle. Plain Diffie-Hellman authenticates nobody. Trudy, sitting between A and B, runs one exchange with A and another with B, so each holds a key shared with Trudy, who decrypts, reads and re-encrypts everything.

The cure is to authenticate the exchanged values with signatures and certificates, as TLS does (SSL and TLS) and as IKE does for IPsec (IPsec). TLS 1.3, IKE and SSH all use ephemeral Diffie-Hellman, a fresh x and y each session, so that a stolen long-term key cannot unlock past sessions (forward secrecy).

To remember it, mix paint. Both start from the same public yellow; each adds a secret colour of their own and sends the mixture; each adds their own secret colour again to what arrives. Both end with the same brown, and a watcher holding the two mixtures cannot un-mix the secret colours out of them.

The book says that N is a large prime with (N−1)/2 also prime (a safe prime, as 23 = 2 x 11 + 1 is) and that G "is also a prime number". The real requirement on G is that it generates the group: a primitive root of N, whose powers run through every value from 1 to N−1. 7 is a primitive root of 23 (its powers first return to 1 at 722), so the example holds.
Asked on the paper, word for word
  • Write short notes on: (Any Two) a) Go Back-N ARQ b) Dual Stack method in IPv6 c) Diffie-Hellman algorithm d) ATM 2080 Bhadra Q10 · 2×4
  • Write short notes on: (Any two) a) SMTP and POP b) Diffie Hellman’s Algorithm c) CSMA/CD d) DLL Flow Control Mechanisms 2074 Ashwin Q10 · 4+4
In the exam A short note on Diffie-Hellman: the purpose (a shared key over an open channel), the five steps with R1, R2 and K, the figure, the book's example (K=18), and one line each on the discrete logarithm and the man in the middle.

8.4Digital signatures

Digital signatures: how they work HOT 5/27

81 Ba · 79 Bh · 76 Ch · 75 Ch · 72 Ka1+72+62×4

Digital signature A value computed from a message and the signer's private key that anyone holding the signer's public key can check. It proves who sent the message (authentication), that it was not changed (integrity), and that the sender cannot deny it (non-repudiation).

Why it is needed: on paper, a handwritten signature or a seal identifies the author of a cheque or a contract. An electronic document can be copied and edited without a trace, so its "signature" must depend on the document's exact content and on a secret only the signer holds. Public key cryptography provides exactly that.

DIGITAL SIGNATURE: SIGN WITH THE PRIVATE KEY, VERIFY WITH THE PUBLIC KEY Only a digest of the message is signed: small, fast, and any change to the message changes it. SIGNING, AT THE SENDER A Message M the document Hash function SHA-256 Digest 256 bits Encrypt the digest with A's private key Signature S sent with M M and S travel together; A's certificate gives B the public key VERIFYING, AT THE RECEIVER B Message M as received Hash function the same one Digest H1 from M Compare H1 = H2 ? Digest H2 from S Decrypt S with A's public key Equal: valid. A sent it (authentication), it is unchanged (integrity), and A cannot deny it (non-repudiation). Different: the message was altered or the signature forged; reject it. M itself is not encrypted: a signature alone gives no confidentiality.

How a digital signature works. Signing, at the sender A:

  1. Hash the message M with a hash function such as SHA-256, giving a short, fixed-length digest H(M).
  2. Encrypt the digest with A's private key: S=EprivA(H(M)) (for RSA, S=Hdmodn). This is the signature.
  3. Send M together with S, and usually A's certificate.

Verifying, at the receiver B:

  1. Hash the received message again with the same function: digest H1.
  2. Decrypt the signature with A's public key: digest H2.
  3. Compare: if H1=H2, the signature is valid: only A's private key could have made it, and the message is unchanged. If they differ, the message was altered or the signature forged, and it is rejected.

Why sign the hash and not the message: RSA on a long document would be very slow; the digest is small (256 bits for SHA-256) whatever the document's size; and changing even one bit of the message changes about half the digest's bits.

A good hash is one-way (the message cannot be rebuilt from the digest) and collision resistant (no one can find two messages with the same digest). MD5 and SHA-1 have known collisions and are no longer used for signatures; SHA-256 is.

The properties a signature must have (the book's list): verifiable (anyone can prove that the signer signed it), non-forgeable (no one else can produce it) and non-repudiable (the signer cannot later deny it). Unlike a handwritten signature, it is different for every document, so it cannot be cut from one and pasted on another.

What it does not give: confidentiality. The message travels in the clear unless it is also encrypted, which PGP does in the same step.

Where the public key comes from. B must be sure that the public key really is A's, or Trudy could sign with her own key and pass hers off as A's. A certificate (X.509) binds a name to a public key and is itself signed by a certification authority (CA) that B already trusts; browsers and operating systems ship with a list of trusted root CAs. This system of CAs and certificates is the public key infrastructure (PKI).

In Nepal, the Electronic Transactions Act, 2063 gives digital signatures legal force, with certifying authorities licensed under the Office of the Controller of Certification.

PointMessage authentication code (MAC)Digital signature
Keyone secret key shared by both endsthe signer's private key; checked with its public key
Who can verifyonly the holders of the shared keyanyone
Non-repudiationno: either end could have made ityes: only the signer could
Speedfast (HMAC)slower (RSA, ECDSA)
Used inTLS records, IPsec packetscertificates, PGP mail, software updates
Worked example: a signature with the RSA card's keys

With n=77, e=13 and d=37, take the digest to be H=5. A signs: S=537mod77=47. B verifies with the public key: 4713mod77=5, equal to its own hash of the message, so the signature is valid. A digest of 6 from a tampered message would not match the 5 recovered from S.

To remember it: before Windows installs an update, it checks Microsoft's digital signature on the file; a file changed by even one byte, or signed by anyone else, is refused. Algorithms in use: RSA signatures, DSA, ECDSA and EdDSA.

The book's slip. It says that signing generates a hash "through a complex mathematical computation that generates a large prime number". A hash function gives a fixed-length digest, not a prime; primes belong to the RSA key pair that encrypts the digest.
Asked on the paper, word for word
  • Write short notes on: (Any Two) a) MAC sublayer b) Digital signature c) Firewall 2081 Baishakh Q10 · 2×4
  • What is a digital signature? Encrypt the message "PANDEMIC" using RSA algorithm. Also obtain the plaintext from the ciphertext. 2079 Bhadra Q9 · 1+7
  • How does a Digital Signature work? Encrypt the world HELLO using RSA algorithm. Also decrypt it by showing steps. 2076 Chaitra Q9 · 2+6
  • Write short notes on: (Any two) a) Digital Signature b) VPN c) Symmetric key cryptography 2075 Chaitra Q10 · 4+4
  • Write short notes on: a) Digital signature b) IPSec 2072 Kartik Q10 · 4×2
In the exam "What is a digital signature" (1 mark): the definition with the three properties. "How does it work" or a 4-mark short note: the signing and verifying steps with the figure, why the hash, and the services (authentication, integrity, non-repudiation, but not confidentiality).

8.5Securing e-mail: PGP

PGP: how an e-mail is secured PIN 3/27

82 Ba · 80 Ba · 74 Ch2×43+55+3

PGP Pretty Good Privacy (Phil Zimmermann, 1991): an e-mail security program that gives a mail confidentiality, authentication, integrity and compression by combining a hash, a digital signature, a one-time symmetric session key and the receiver's public key. Its message format is the open standard OpenPGP (RFC 4880).

Why mail needs it: SMTP carries a message in plain text through several mail servers (SMTP, POP3 and IMAP); anyone with access to a server or a link on the way can read it, and a forged sender address costs nothing. PGP protects the message itself, end to end, whatever servers it passes.

PGP: HOW ONE EMAIL FROM A TO B IS PROTECTED Sign, compress, encrypt with a one-time session key, lock that key with B's public key, then base64. SENDING, AT A 1 Hash digest of the mail (SHA-256) 2 Sign digest with A's private key 3 Compress mail + signature with ZIP 4 Encrypt one-time session key (AES, IDEA) 5 Lock the key session key with B's public key 6 Base64 binary to plain email text authentication compression confidentiality email compatibility RECEIVING, AT B: THE SAME STEPS BACKWARDS Decode base64 back to binary Unlock the key with B's private key Decrypt with the session key Decompress mail + signature Verify with A's public key Sign before compressing: the signature covers the mail as written. Compress before encrypting: less redundancy, less to encrypt. Keys: PGP trusts public keys through a web of trust (users sign each other's keys); S/MIME uses CA certificates instead.

How PGP secures one mail from A to B, in order:

  1. Hash: A's PGP computes a digest of the message (SHA-256 now; MD5 or SHA-1 in early versions).
  2. Sign: it encrypts the digest with A's private key (RSA or DSA) and attaches this signature to the message.
  3. Compress: it compresses the message and signature together (ZIP).
  4. Encrypt: it generates a fresh random session key, used for this one message only, and encrypts the compressed bundle with a symmetric cipher (IDEA, 3DES, CAST-128 or AES).
  5. Lock the key: it encrypts the session key with B's public key (RSA or ElGamal) and attaches it.
  6. Convert: it turns the binary result into radix-64 (base64) text, which any mail system carries unharmed, and sends it.

At B, the same steps backwards: decode the base64; decrypt the session key with B's private key; decrypt the bundle with the session key; decompress; then hash the message again and compare it with the digest recovered from the signature by A's public key. A match proves the mail came from A, unchanged.

Why this order:

  • Sign before compressing, so that the signature covers the message as written and can be checked later without recompressing it.
  • Compress before encrypting, because compression removes the redundancy that cryptanalysis feeds on, and leaves less to encrypt.
  • A session key, because public key encryption is slow: the long message goes through a fast symmetric cipher, and only the short session key through RSA (hybrid use).

The services PGP offers:

  • Authentication and integrity: the digital signature (digital signatures).
  • Confidentiality: the session key and symmetric encryption.
  • Compression: ZIP, saving space and transfer time.
  • E-mail compatibility: radix-64 conversion, since mail carries 7-bit text.
  • Segmentation: a long message is split to fit mail size limits and rejoined at B.

Keys in PGP. Installing PGP makes a key pair for the user. The private key is stored encrypted under a passphrase, which must be typed each time it is used; public keys are posted on the user's website or a key server.

  • Key rings: each user keeps a public key ring (other people's public keys) and a private key ring (their own key pairs).
  • Web of trust: users sign one another's keys, and a key signed by someone already trusted is accepted; no central authority is needed.

S/MIME, the alternative built into mail programs, secures MIME mail with the same ingredients but takes its public keys from X.509 certificates issued by certification authorities instead of a web of trust.

To remember the steps, post an answer sheet across the country: sign it, fold it small, lock it in a box with a brand-new padlock, put the padlock's only key in an envelope that only the exam office can open, and write the address in plain letters the post office can read. Signature, compression, session key, B's public key, base64.

The book's slips. It dates PGP to 1995; Zimmermann released it in 1991. It also says PGP uses "MD5 or SHA for calculating the message digest such as CAST, Triple-DES or IDEA": MD5 and SHA compute the digest, while CAST, Triple DES and IDEA are the symmetric ciphers that encrypt the message.
Asked on the paper, word for word
  • Write Short Notes on: (Any Two) a) 802.5 Token Ring b) PGP c) Socket programming fundamentals d) X.25 Network 2082 Baishakh Q10 · 2×4
  • What is PGP? Use RSA algorithm to encrypt/decrypt the word COW. 2080 Baishakh Q9 · 3+5
  • Define type of Encryption used in security. How PGP can secure email communication? 2074 Chaitra Q9 · 5+3
In the exam "What is PGP" (3 marks) or a short note: the definition, the services and the six steps in one line each. "How PGP secures email": the steps in order at A, the reverse at B, and the figure.

8.6Securing TCP connections: SSL

SSL and TLS: securing a TCP connection PIN 3/27

71 Ch · 71 Shr · 68 Ba4×22+6

SSL and TLS SSL (Secure Sockets Layer, Netscape, 1995) and its successor TLS (Transport Layer Security, IETF; version 1.3 is RFC 8446) form a protocol layer between TCP and the application that authenticates the server (and optionally the client), agrees session keys, and then gives the application's data confidentiality and integrity.

Where it sits: above TCP, which it needs for reliable, in-order delivery (TCP), and below the application, which barely notices it. HTTP over TLS is HTTPS on port 443 (HTTP and HTTPS); mail and file transfer have their own TLS ports (SMTPS on 465, IMAPS on 993) or switch to TLS with STARTTLS.

SSL/TLS: WHERE IT SITS, AND THE HANDSHAKE Between TCP and the application; the handshake authenticates the server and agrees the keys the record protocol uses. Application HTTP, SMTP, FTP SSL / TLS Handshake Alert Change cipher spec Record protocol TCP port 443 for HTTPS IP RECORD PROTOCOL, PER BLOCK fragment (up to 16 KB), compress, add a MAC, encrypt, add a header VERSIONS SSL 2.0, 3.0 (Netscape); TLS 1.0 (1999), 1.2 (2008), 1.3 (2018): use 1.2 or 1.3 Client the browser Server the bank site ClientHello: TLS versions, cipher suites, client random 1 ServerHello: the chosen suite, server random 2 Certificate: the server's public key, signed by a CA 3 ServerHelloDone 4 ClientKeyExchange: pre-master secret, under the server's public key 5 ChangeCipherSpec, Finished (a MAC of the whole handshake) 6 ChangeCipherSpec, Finished 7 the client checks the certificate against its trusted CAs both derive the master secret and the session keys from the pre-master secret and the two randoms 8 Application data, both ways: encrypted and MACed by the record protocol TLS 1.3 shortens this to one round trip, with ephemeral Diffie-Hellman keys.

Its four protocols: the handshake protocol (authenticates and agrees keys), the change cipher spec protocol (one message: switch to the new keys now), the alert protocol (warnings and fatal errors, such as a bad certificate) and the record protocol, which carries everything, the application's data included.

The handshake, in the classic RSA form of SSL 3.0 and TLS 1.2:

  1. ClientHello: the client sends the versions and cipher suites it supports and a random number.
  2. ServerHello: the server picks the version and cipher suite and sends its own random number.
  3. Certificate: the server sends its certificate, its public key signed by a CA; the client checks it against the CAs it trusts and that the name matches the site.
  4. ServerHelloDone closes the server's turn.
  5. ClientKeyExchange: the client makes a random pre-master secret, encrypts it with the server's public key and sends it; only the real server can decrypt it.
  6. Key derivation: both sides compute the master secret from the pre-master secret and the two random numbers, and from it the session keys: an encryption key and a MAC key for each direction.
  7. ChangeCipherSpec and Finished, from each side: the Finished message is a MAC over the whole handshake, so any tampering with the earlier messages is caught.
  8. Application data now flows, encrypted and authenticated by the record protocol.

The record protocol treats the data in blocks: fragment it (up to 214 = 16,384 bytes), compress it (optional, and dropped in TLS 1.3), add a MAC (a keyed hash, HMAC), encrypt with the symmetric session key (AES or ChaCha20 today), and add a 5-byte header (content type, version, length). The book lists the same as fragmentation, compression, message integrity, confidentiality and framing.

The services SSL gives: server authentication by certificate, optional client authentication, confidentiality by symmetric encryption, integrity by MAC, and key exchange by public key cryptography: exactly the hybrid scheme of the cryptography card.

VersionYearStatus
SSL 2.0, SSL 3.01995, 1996 (Netscape)broken; prohibited (RFC 6176, RFC 7568)
TLS 1.0, TLS 1.11999 (RFC 2246), 2006 (RFC 4346)deprecated (RFC 8996)
TLS 1.22008 (RFC 5246)in use
TLS 1.32018 (RFC 8446)current: one round trip, ephemeral Diffie-Hellman only, no RSA key transport

Uses (the book's list of advantages): online card payments, logins, webmail, secure file transfer (HTTPS, FTPS), and SSL VPNs that give remote users access to an office network through the browser (VPN).

To remember it: paying an exam form fee through a digital wallet in the browser, the address starts with https and a padlock appears. In the second before that, the browser checked the wallet's certificate and agreed session keys with its server; the NTC or WorldLink line in between carries only ciphertext.

Asked on the paper, word for word
  • Write short notes on: a) SSL b) WEP 2071 Chaitra Q10 · 4×2
  • Write short notes on: (any two) a) WEP b) IDS c) SSL 2071 Shrawan Q10 · 4×2
  • What is a secure socket layer? Encrypt the message “DANGER” using RSA algorithm. 2068 Baishakh Q9 · 2+6
In the exam "What is SSL" (2 marks): the definition, its place between TCP and the application, and HTTPS on port 443. A 4-mark note adds the four protocols, the handshake in five or six steps with the figure, and the record protocol's steps.

8.7Network layer security: IPsec and VPN

IPsec: AH and ESP, transport and tunnel mode PIN 3/27

82 Bh · 80 Ba · 72 Ka2×44×2

IPsec IP security (IETF, RFC 4301): a suite of protocols that secures the IP packets themselves, between two hosts, two routers or a host and a router. It offers two protocols, AH for authentication and integrity and ESP for confidentiality as well, in two modes, transport and tunnel, using security associations set up by IKE.

Why at the network layer: once IP is protected, every protocol above it is protected too, TCP, UDP, ICMP and routing updates alike, without changing a single application. IPsec works with IPv4 and IPv6; in IPv6, AH and ESP are extension headers (IPv6 extension headers).

IPSEC: TRANSPORT AND TUNNEL MODE, WITH AH AND ESP AH (protocol 51) authenticates; ESP (protocol 50) encrypts and can authenticate. Original packet IP header TCP Data as a host sends it Transport + AH IP header AH TCP Data authenticated host to host; no secrecy Transport + ESP IP header ESP hdr TCP Data ESP trailer ESP auth authenticated encrypted host to host; secret Tunnel + ESP New IP header ESP hdr IP header TCP Data ESP trailer ESP auth authenticated encrypted gateway to gateway: VPN Tunnel + AH New IP header AH IP header TCP Data authenticated gateways; no secrecy encrypted (ESP only) added by IPsec authenticated: origin and integrity

The two modes differ in what is protected:

  • Transport mode: the IPsec header goes between the original IP header and the transport header. Only the payload (the TCP or UDP segment) is protected; the original IP header, with the real addresses, travels as it is. Used end to end, host to host.
  • Tunnel mode: the whole original IP packet, header included, becomes the payload of a new IP packet with a new header, usually addressed from one security gateway to another. The inner addresses are hidden too. Used gateway to gateway, which is how VPNs are built.

Authentication Header (AH), IP protocol number 51, gives source authentication, data integrity and protection against replay, but no confidentiality: nothing is encrypted. Its fields:

  • Next header (8 bits): the type of the payload that follows (6 for TCP).
  • Payload length (8 bits): the length of the AH itself.
  • Reserved (16 bits).
  • Security parameter index, SPI (32 bits): names the security association, much as a virtual circuit number names a circuit.
  • Sequence number (32 bits): rises by one per packet, to defeat replay.
  • Authentication data (variable): the integrity check value, a keyed hash over the packet, with the fields that change in transit (TTL, header checksum) counted as zero.

Encapsulating Security Payload (ESP), IP protocol number 50, gives confidentiality by encryption, plus source authentication, integrity and anti-replay. It wraps the payload:

  • ESP header in front: the SPI and the sequence number, 32 bits each.
  • The payload itself, encrypted.
  • ESP trailer: padding of 0 to 255 bytes, an 8-bit pad length and an 8-bit next header; encrypted with the payload.
  • ESP authentication data at the end, covering the header to the trailer; placed last so it can be computed in one pass as the packet goes out.
PointAHESP
IP protocol number5150
Confidentialitynoyes, encryption (AES)
Integrity and source authenticationyesyes (optional)
Anti-replayyes, sequence numberyes, sequence number
Covers the outer IP headeryes, its fixed fieldsno
Through NATfails, as NAT changes the authenticated addressesworks, with UDP encapsulation
Use todayrarealmost every IPsec VPN

Security association (SA). Before protected packets flow, the two ends agree a one-way relationship holding everything needed: the protocol (AH or ESP), the mode, the algorithms and keys, the sequence counter, the replay window and the lifetime.

  • Identified by its SPI, the destination address and the protocol; a two-way conversation needs two SAs, one each way.
  • Stored in the security association database (SAD), while the security policy database (SPD) decides for each packet whether to protect it, pass it or drop it.

IKE (Internet Key Exchange, version 2 in RFC 7296) creates the SAs automatically: it authenticates the two ends by certificates or a pre-shared key and agrees fresh keys with Diffie-Hellman.

To remember it: a branch office router in Pokhara and the head office router in Kathmandu run IPsec in tunnel mode with ESP. Every packet between the two LANs leaves Pokhara wrapped and encrypted, crosses the ISP's network as gibberish addressed router to router, and is unwrapped in Kathmandu: the staff notice nothing.

The book says AH's authentication data is "the result of applying a hash function to the entire IP datagram". The fields that change on the way, such as TTL and the header checksum, cannot be covered, so they are set to zero for the calculation; and the hash is keyed (a MAC), or anyone could recompute it.
Asked on the paper, word for word
  • Write short notes on: (Any Two) a) ARP and NDP b) AH and ESP c) VPN d) vLAN 2082 Bhadra Q10 · 2×4
  • Write short notes on: (Any Two) a) VLAN b) ARP c) IPSec 2080 Baishakh Q10 · 2×4
  • Write short notes on: a) Digital signature b) IPSec 2072 Kartik Q10 · 4×2
In the exam A note on IPsec: the definition, the two modes, AH and ESP in a line each, and SA and IKE, with the figure. "AH and ESP": the services of each, AH's six fields, ESP's header, trailer and authentication data, and the comparison table.

VPN: a private network over a public one HOT 5/27

82 Bh · 79 Bh · 75 Ch · 75 Ash · 71 Ch2×42+42+6

Virtual private network A private network built over a public one, usually the Internet, by tunnelling: each packet is encrypted and authenticated, then carried inside another packet between the VPN endpoints, so that distant sites and users communicate as if they were on one private LAN.

Why it exists: a private leased line between two offices is secure but expensive, and the Internet is cheap but public. A VPN gets the privacy of the first at the price of the second: virtual because no private wires are laid, private because no outsider can read or join the traffic.

VPN: A PRIVATE TUNNEL ACROSS THE PUBLIC INTERNET Site to site joins two LANs through their gateways; remote access joins one laptop to the office. THE INTERNET (PUBLIC) Head office LAN Kathmandu 192.168.1.0/24 Branch LAN Pokhara 192.168.2.0/24 VPN gateway VPN gateway site-to-site IPsec tunnel encrypted, authenticated Remote user laptop with a VPN client remote-access tunnel (TLS or IPsec), from home INSIDE A TUNNEL new IP hdr ESP orig. packet gateway to gateway encrypted Cheaper than a leased line, and private: an eavesdropper on the Internet sees only gateway addresses and ciphertext.

How a VPN works, step by step:

  1. Authenticate: the VPN client or the remote gateway proves who it is, with a certificate, a pre-shared key, or a username and password with a one-time code.
  2. Agree keys: the two ends agree session keys (IKE for IPsec, a TLS handshake for an SSL VPN).
  3. Encapsulate: a packet bound for the private network is encrypted and authenticated, then wrapped in a new packet addressed to the far VPN endpoint.
  4. Cross the Internet: routers forward it like any other packet, seeing only the endpoints' public addresses and ciphertext.
  5. Decapsulate: the far endpoint checks it, decrypts it and delivers the original packet inside its LAN; replies return the same way.
TypeWhat it joinsTypical example
Remote access (host to gateway)one user's device to the organisation's network, through client softwarea staff member at home reaching the office file server
Site to site, intranet (gateway to gateway)the LANs of one organisation's sites, permanentlya head office and its branches
Site to site, extranetan organisation's network to a partner's, with limited accessa company and its supplier sharing an ordering system

The protocols used: IPsec in tunnel mode with ESP (the usual site-to-site choice); SSL/TLS VPNs such as OpenVPN, or a browser-based portal (common for remote access); L2TP carried over IPsec; WireGuard, a modern, small design; and PPTP, an old protocol now considered insecure.

  • Advantages: far cheaper than leased lines; confidentiality, integrity and authentication over a public network; remote users join from anywhere; new sites are added in software.
  • Disadvantages: encryption and the extra headers cost speed and bandwidth; performance depends on the Internet in between; setup and keys must be managed; a stolen or infected laptop with VPN access is an attacker inside the network.
Example: a company with two offices

A company's head office in Kathmandu (192.168.1.0/24) and its branch in Pokhara (192.168.2.0/24) each have an ordinary Internet connection from a local ISP.

  • Site to site: their two routers run an IPsec VPN, so a branch PC opens the accounts server at 192.168.1.10 as if it were down the corridor, while the ISPs carry only encrypted packets between the routers' public addresses.
  • Remote access: an accountant working from home in Bhaktapur starts a VPN client on her laptop and gets the same access.

To remember it: a VPN is a sealed pipe laid inside a public road. The road (the Internet) is shared by everyone; what flows inside the pipe is invisible to them. The consumer "VPN apps" that make a phone appear to be in another country use the same tunnel, from one user to the provider's server.

Asked on the paper, word for word
  • Write short notes on: (Any Two) a) ARP and NDP b) AH and ESP c) VPN d) vLAN 2082 Bhadra Q10 · 2×4
  • Write short notes on: (Any Two) a) ALOHA b) OSPF c) VPN 2079 Bhadra Q10 · 2×4
  • Write short notes on: (Any two) a) Digital Signature b) VPN c) Symmetric key cryptography 2075 Chaitra Q10 · 4+4
  • What is VPN? Encrypt a message "network" using RSA algorithm. 2075 Ashwin Q9 · 2+6
  • What is network security? Explain Virtual Private Network (VPN) with an example. 2071 Chaitra Q4 · 2+4
In the exam "What is VPN" (2 marks): the definition and the tunnel. A 4-mark note, or "explain VPN with an example": add how it works, the types (remote access, site to site), the protocols, and the two-office example with the figure.

8.8Securing wireless LANs: WEP

Securing wireless LANs: WEP, and why WPA2 replaced it PIN 2/27

71 Ch · 71 Shr4×2

WEP Wired Equivalent Privacy: the security protocol of the original IEEE 802.11 standard (1997), meant to make a wireless LAN as private as a wired one. It encrypts each frame with the RC4 stream cipher, keyed by a 24-bit IV plus a shared 40 or 104-bit key, and appends a CRC-32 integrity check. Its design is broken, and WPA2 has replaced it.

Why wireless needs its own protection: a radio signal passes through walls, and anyone in range can capture every frame without touching a cable (wireless LAN). WEP had three goals: confidentiality (no eavesdropping), access control (only stations with the key may join) and integrity (frames not modified in transit).

WEP: HOW A FRAME IS ENCRYPTED, AND WHY IT FAILS RC4 keyed with IV + shared key; CRC-32 for integrity; the IV travels in the clear. IV 24 bits, new per frame + Shared secret key 40 or 104 bits seed: IV then key = 64 or 128 bits RC4 stream cipher keystream Plaintext the frame data CRC-32 gives the ICV data ICV the data itself Ciphertext (data + ICV) XOR key FRAME SENT IV in the clear key ID ciphertext (data + ICV) THE BOOK'S EXAMPLE keystream 0101 plaintext 1100 XOR gives 1001 WHY IT FAILS 24-bit IV: only 16,777,216 keystreams, so they repeat; two frames under one keystream give C1 XOR C2 = P1 XOR P2. CRC-32 is linear: bits flipped in the ciphertext can be matched by fixing the ICV, so tampering goes unseen. One static key shared by every user, and weak RC4 keys leak key bytes (the FMS attack): cracked in minutes.

How WEP encrypts a frame:

  1. Integrity value: the CRC-32 of the data, the 32-bit integrity check value (ICV), is appended to the data.
  2. Seed: a 24-bit initialization vector (IV), meant to change with every frame, is joined in front of the shared secret key: 24 + 40 = 64 bits, or 24 + 104 = 128 bits.
  3. Keystream: RC4, keyed with this seed, produces a keystream as long as the frame.
  4. Encrypt: the data and ICV are XORed with the keystream.
  5. Send: the frame carries the IV in the clear, a key ID, and the ciphertext.

Decryption reverses it: the receiver takes the IV from the frame, joins its own copy of the key, runs RC4 to get the same keystream, XORs it with the ciphertext, and checks the CRC. The book's toy example: keystream 0101 XOR plaintext 1100 gives ciphertext 1001, and XORing 1001 with 0101 again gives back 1100.

Key sizes as typed into a router: 10 hexadecimal digits are 40 bits, which with the 24-bit IV make "64-bit WEP"; 26 hexadecimal digits are 104 bits, which make "128-bit WEP". Station authentication is either open system (none at all) or shared key, a challenge the station encrypts with WEP, which hands an eavesdropper a sample of keystream.

Why WEP is weak:

  • The IV is too short: 24 bits give only 16,777,216 keystreams. A busy access point sending 1500-byte frames at 11 Mbps uses them all in about 5 hours, and by the birthday effect a repeated IV is more likely than not after about 4,800 frames. Two frames under the same IV and key share a keystream, so C1⊕C2=P1⊕P2: the keystream cancels.
  • Weak RC4 keys: because the IV is sent in the clear and placed in front of the key, certain IVs leak bytes of the key itself (the Fluhrer, Mantin and Shamir attack, 2001). Free tools collect enough frames and recover the key in minutes.
  • CRC-32 is no integrity check against an attacker: it is linear and keyless, so bits flipped in the ciphertext can be matched by fixing the ICV, and the forged frame is accepted. There is no replay protection either.
  • One static key: every user shares the same key, rarely changed, with no key management; one leak exposes everyone.

The replacements:

PointWEPWPAWPA2WPA3
Year1997200320042018
Basis802.11Wi-Fi Alliance, interimIEEE 802.11iWi-Fi Alliance
CipherRC4RC4 with TKIPAES (CCMP)AES (CCMP or GCMP)
Keysone static shared key, 24-bit IVa new key per packet, 48-bit sequence counterfresh session keys from a 4-way handshakeSAE handshake, forward secrecy
IntegrityCRC-32Michael MICCBC-MAC (in CCMP)CCMP or GCMP
Statusbrokendeprecatedthe usual minimumcurrent

WPA2 and WPA3 come in two flavours: Personal, one passphrase for the network (a pre-shared key in WPA2, protected against offline guessing by SAE in WPA3), and Enterprise, where each user logs in through IEEE 802.1X and EAP to an authentication server (RADIUS).

To remember it: a hostel router still offering WEP is a locked door with the key taped to it: anyone in the corridor with a laptop and free software is inside within minutes. The fix is one setting, WPA2-AES or WPA3.

Asked on the paper, word for word
  • Write short notes on: a) SSL b) WEP 2071 Chaitra Q10 · 4×2
  • Write short notes on: (any two) a) WEP b) IDS c) SSL 2071 Shrawan Q10 · 4×2
In the exam A short note on WEP: its purpose, the encryption steps with the figure (IV and key into RC4, CRC-32 ICV, XOR, IV sent in the clear), three or four weaknesses, and WPA and WPA2 as the replacements.

8.9Firewalls: application gateway and packet filtering, and IDS

Firewalls: what they are, how they protect, their types, and router ACLs TOP 13/27

82 Bh · 82 Ba · 81 Ba · 76 Ch · 76 Ash · 75 Ch · 74 Ch · 74 Ash · 73 Shr · 72 Ch · 72 Ka · 70 Ch · 69 Ch4+42+68

Firewall A device or program at the boundary between a trusted internal network and an untrusted one (the Internet) that examines the traffic crossing it and lets each packet or connection through, or blocks it, according to a security policy, its rule set.

Three design goals (Cheswick and Bellovin): all traffic between inside and outside must pass through the firewall; only traffic authorised by the local security policy may pass; and the firewall itself must resist penetration. The book's picture is a wall between the corporate LAN and the outside world, through which a valid web request passes while an invalid Telnet request bounces off.

How a firewall protects a network:

  • A single choke point: every connection crosses one place, where the policy is enforced and every attempt can be logged and audited.
  • Filtering by rule: it blocks unwanted source addresses, ports and protocols (Telnet, file sharing and remote desktop from outside) and, best of all, denies by default whatever is not explicitly allowed.
  • Only expected replies get in: a stateful firewall admits inbound packets only when they belong to a connection started from inside.
  • Hiding the inside: with NAT, outsiders see one public address, not the internal hosts and their layout.
  • Content control: a proxy can inspect and block malware, banned sites, file types and dangerous commands, and require users to log in.
  • Containment and alerting: it separates zones (a DMZ for public servers), slows the spread of a worm between segments, resists floods such as SYN floods, and alerts the administrator.

The book's reasons for a firewall: to stop intruders interfering with the daily running of the network (denial of service, SYN and FIN attacks), deleting or modifying stored information, or obtaining secrets; to allow only authorised access to the inside; and to stop illegal changes, such as an attacker replacing the official homepage.

FIREWALL TYPES, BY THE LAYER THEY INSPECT The higher the layer a firewall reads, the more it understands, and the more each packet costs it. Application Session Transport (TCP, UDP) Network (IP) Data link, physical Application gateway (proxy) reads the content (URLs, FTP commands, mail); one proxy per service; slowest, safest Circuit-level gateway checks the TCP handshake, then relays the connection without reading it (SOCKS) Stateful inspection a packet filter with a connection table: replies get in only for connections already open Packet filter (router ACL) each packet alone, by its IP and TCP/UDP headers: addresses, protocol, ports; fastest Up the stack: more inspection and more security, but more processing delay. A next-generation firewall (NGFW) combines them, adding application awareness and intrusion prevention.

The types of firewall, by the layer they inspect:

  1. Packet filtering firewall (first generation, stateless): a router or host that checks each packet on its own against a rule table, by its IP and TCP/UDP headers: source and destination IP address, protocol, ports, TCP flags, interface and direction. The first matching rule permits or denies.
    • For: fast, cheap and invisible to users; any router can do it.
    • Against: it keeps no state (a forged packet that claims to be a reply looks valid), reads no content, cannot spot a spoofed source address, and long rule lists are easy to get wrong.
  2. Stateful inspection firewall (dynamic packet filter): a packet filter that also keeps a state table of open connections (addresses, ports, TCP state). An inbound packet is admitted only if it belongs to a connection already open or is explicitly allowed, so an out-of-the-blue ACK is dropped. Most firewalls today work this way.
  3. Application-level gateway (proxy firewall): works at the application layer. The client connects to the proxy, which checks the request (the URL, the FTP command, the mail and its attachments, the user's identity) and, if it is allowed, opens a second connection to the real server and relays the reply. It needs a proxy program for each service (HTTP, SMTP, FTP, DNS).
    • For: the most secure type; it understands the content and logs everything.
    • Against: slower, since every connection is handled twice, and a new application needs a new proxy.
  4. Circuit-level gateway: works at the session layer. It checks that the TCP handshake (and the user) is legitimate, then relays bytes between the two connections without reading them. SOCKS is the standard example; it is often used for outgoing connections from trusted insiders.
  5. Next-generation firewall (NGFW): a stateful firewall with deep packet inspection, recognition of applications whatever port they use, intrusion prevention, TLS inspection and user identity, in one box.

Where they run: a network firewall guards a whole network at its edge; a host-based firewall (Windows Defender Firewall, Linux nftables) guards one machine. A home Wi-Fi router's built-in firewall is a small stateful one.

PointPacket filterStateful inspectionApplication gateway
Layernetwork and transportnetwork and transport, with stateapplication
Decides oneach packet's header aloneheader plus the connection's statethe content and the user
Speedfastestfastslowest
Securitylowestgoodhighest
Examplea router ACLa home router, a perimeter firewallan HTTP proxy with filtering

To remember the types, picture the hostel gate's chowkidar:

  • Packet filter: he checks each visitor's name against a list, and nothing else.
  • Stateful inspection: he remembers who went out, and lets only them back in.
  • Application gateway: he walks each visitor to the room, checking the bag on the way.
  • Circuit-level gateway: he checks the entry in the visitors' book once, then lets the visitor through unwatched.
HOW A PACKET FILTER WORKS: EACH PACKET AGAINST THE RULES, TOP DOWN The first rule that matches decides; when none matches, the packet is dropped. A packet arrives Read its header IPs, protocol, ports, direction Rule k matches? yes Do its action permit: forward deny: drop no More rules? yes: k + 1 no Implicit deny: drop it no rule matched A HOSTEL ROUTER'S RULES # Source Destination Port Action 1 203.0.113.0/24 any any deny 2 any 192.168.10.0/24 TCP 23 deny 3 any 192.168.10.5 TCP 443 permit 4 192.168.10.0/24 any TCP 80, 443 permit 5 any any any deny THREE PACKETS, TRACED 1. 198.51.100.7 to 192.168.10.5, TCP 443: rules 1 and 2 miss, rule 3 matches: permit 2. 203.0.113.9 to 192.168.10.5, TCP 443: rule 1 matches first: deny 3. 198.51.100.7 to 192.168.10.20, TCP 23: rule 2 matches: deny (Telnet blocked) Order matters: the first match decides, and every list ends in an implicit deny.

How a packet filtering firewall works, step by step:

  1. Receive: a packet arrives on an interface, inbound or outbound.
  2. Read the header: source and destination IP address, protocol (TCP, UDP, ICMP), source and destination port, TCP flags.
  3. Compare with the rules, top down: each rule names values (or "any") for these fields and an action.
  4. First match decides: the packet is forwarded (permit) or dropped (deny), and the rest of the list is not read.
  5. No match: the implicit deny at the end of every list drops it.
  6. Log the packets denied, for the administrator.

The book's filter table blocks four things: incoming packets from the network 121.34.0.0, incoming packets for any internal Telnet server (port 23), incoming packets for the internal host 192.168.0.8, and outgoing packets to web servers (port 80), so that staff cannot browse.

Router ACLs. A router turns into a packet filtering firewall with an access control list (ACL): an ordered list of permit and deny statements, applied to one interface in one direction (in or out). Each packet is compared top down; the first match decides; and every list ends with an invisible implicit "deny any".

PointStandard ACLExtended ACL
Cisco numbers1 to 99, 1300 to 1999100 to 199, 2000 to 2699
Matchesthe source address onlysource and destination address, protocol, ports
Placednear the destinationnear the source

The wildcard mask says which address bits must match: it is the subnet mask inverted, 0 for "must match" and 1 for "ignore". A /24 network has the mask 255.255.255.0, so its wildcard is 0.0.0.255 (subnetting).

Worked example: block 202.70.91.0/24 coming in on FastEthernet

The paper's network 202.70.91.0/24 is to be blocked on the router's FastEthernet 0/0 interface, in the incoming direction, while all other traffic still passes. With a standard ACL:

Router(config)# access-list 10 deny 202.70.91.0 0.0.0.255
Router(config)# access-list 10 permit any
Router(config)# interface FastEthernet0/0
Router(config-if)# ip access-group 10 in

Or with an extended ACL, which can be narrowed later to particular destinations or ports:

Router(config)# access-list 110 deny ip 202.70.91.0 0.0.0.255 any
Router(config)# access-list 110 permit ip any any
Router(config)# interface FastEthernet0/0
Router(config-if)# ip access-group 110 in
  • Line 1 denies every packet whose source is 202.70.91.0 to 202.70.91.255 (wildcard 0.0.0.255).
  • Line 2 permits everything else. It is essential: without it the implicit deny at the end of the list would drop all traffic arriving on the interface.
  • Lines 3 and 4 apply the list to FastEthernet 0/0 in the in direction, so the router drops those packets as they arrive, before routing them.
  • Check with show access-lists, whose match counters rise as packets are denied, and show ip interface FastEthernet0/0.

Where the firewall sits. The classic arrangement is the screened subnet: a border router filters first, the firewall second, and the servers the public must reach (web, mail) sit in a DMZ (demilitarised zone) of their own, so that a hacked web server is still outside the trusted LAN. Simpler set-ups use a single screening router, or a dual-homed host with one interface on each side.

WHERE THE FIREWALL, THE DMZ AND THE IDS SIT The firewall is the one gate between three zones; the IDS watches what passes it. Internet untrusted Border router ACL filter Firewall stateful or NGFW DMZ: PUBLIC SERVERS, LIMITED TRUST switch Web server Mail server HIDS HIDS INSIDE: THE TRUSTED LAN switch Hostel PCs Database server HIDS NIDS sensor copy of the traffic (mirror port) Rules: the Internet reaches only the DMZ servers' ports (443, 25); the LAN may go out; nothing from outside opens a connection to the LAN. The NIDS watches copies of the traffic; HIDS agents watch each server's own files and logs.

What a firewall cannot do: stop traffic that goes around it (a phone's mobile hotspot, an infected USB drive), stop an insider already inside, see malware hidden in allowed or encrypted traffic without deeper inspection, or prevent phishing. That is why an IDS watches behind it.

The book's figure number. The packet filter's table is captioned "Figure 2.26" in the middle of chapter 8; it belongs with the chapter's own figures 8.25 and 8.27.
Asked on the paper, word for word
  • What do you mean by firewall? Encrypt and decrypt the “attack” using RSA. 2082 Bhadra Q9 · 2+4+2
  • What is router ACL? How do you apply ACL to block the IP network 202.70.91.0/24 incoming to interface Fast Ethernet of a router? Encrypt the word “ISPNet” using anyone suitable AES technique. 2082 Baishakh Q9 · 2+6
  • Write short notes on: (Any Two) a) MAC sublayer b) Digital signature c) Firewall 2081 Baishakh Q10 · 2×4
  • Explain briefly the desirable properties of secure communication. Explain how packet filtering firewall works. 2076 Chaitra Q10 · 4+4
  • Write short notes on: (Any two) a) Firewall and their types b) 803 Token Bus c) Virtual circuit switching 2076 Ashwin Q10 · 4+4
  • Explain briefly the desirable properties of secure communication. Explain how Packet filtering firewall Works. 2075 Chaitra Q9 · 4+4
  • Write short notes on: (any two) i) Types of firewals ii) FDDI iii) Socket programming 2074 Chaitra Q10 · 4+4
  • Explain briefly the desirable properties of secure communication. Explain how Packet filtering firewall Works. 2074 Ashwin Q9 · 4+4
  • What do you mean by firewall? Explain different types of firewall. 2073 Shrawan Q9 · 2+6
  • Explain briefly how firewalls protect network and also explain different types of Firewall. Illustrate your answer with appropriate figures. 2072 Chaitra Q8 · 8
  • What is firewall? What are their types? Encrypt and decrypt "OVEL" message using RSA algorithm. 2072 Kartik Q9 · 1+1+6
  • Explain briefly how firewalls protect network and also explain different types of Firewall. Illustrate your answer with appropriate figures. 2070 Chaitra Q9 · 8
  • What is network security? How can firewalls enhance network security? Explain how firewalls can protect a system. 2069 Chaitra Q10 · 2+2+4
In the exam "What is a firewall" (1 or 2 marks): the definition and its place at the boundary. "How firewalls protect a network" with "the types, with figures" (8 marks): the protection list, then packet filter, stateful inspection, application gateway and circuit-level gateway, each with a line of working, an advantage and a weakness, and the layer figure. "How a packet filter works" (4): the steps with a rule table. "Router ACL": the definition, then the four Cisco lines, and why the permit is needed.

Intrusion detection systems PIN 1/27

71 Shr4×2

Intrusion detection system (IDS) A device or program that monitors a network or its hosts for malicious activity or policy violations and raises an alert, to an administrator or a security information and event management (SIEM) system. An IDS detects and reports; an intrusion prevention system (IPS) sits in the traffic's path and also blocks.

Why a firewall is not enough: a firewall decides at the gate, by rules. Attacks hidden inside allowed traffic (an exploit sent to the web server's open port 443), attacks from insiders, and attacks the rules never imagined pass straight through. The IDS watches what gets past.

By where it watches:

PointNetwork IDS (NIDS)Host IDS (HIDS)
Placedat a key point of the network (behind the firewall, in the DMZ), fed a copy of the traffic by a switch's mirror (SPAN) port or a tapon each host it protects, as an agent
Watchesthe packets of a whole segmentthe host's own traffic, logs, processes and system files
Catchesscans, floods, exploits on the wirechanged or deleted system files, logins, malware on the host
Missesencrypted payloads, what never crosses its segmentattacks on other hosts; can be disabled by an attacker who owns the host
ExamplesSnort, Suricata, ZeekOSSEC, Wazuh, Tripwire

By how it decides:

  • Signature-based (misuse) detection: matches traffic against patterns of known attacks, like antivirus signatures. Few false alarms and a clear explanation, but blind to new (zero-day) attacks until a signature exists, so the rules need constant updating.
  • Anomaly-based detection: learns a baseline of normal behaviour (traffic volumes, ports, login times) and flags deviations. It can catch new attacks, but it raises more false alarms and needs a training period.

An example signature, a Snort rule that alerts on any Telnet attempt into a hostel network:

alert tcp any any -> 192.168.10.0/24 23 (msg:"Telnet attempt"; sid:1000001; rev:1;)

The book also splits NIDS by timing: an on-line NIDS analyses the packets in real time, an off-line one analyses stored data afterwards. A HIDS typically takes a snapshot of the critical system files and compares later snapshots with it, alerting when a file has been changed or deleted.

Judging the alerts: a true positive is a real attack flagged; a false positive is an alarm on harmless activity (too many, and staff stop reading them); a false negative is an attack missed, the worst case.

PointFirewallIDSIPS
Joballow or block by policydetect and alertdetect and block
Positioninline, at the boundarybeside the traffic (a copy) inline
Effect on trafficpasses or drops itnonedrops the attack packets
WHERE THE FIREWALL, THE DMZ AND THE IDS SIT The firewall is the one gate between three zones; the IDS watches what passes it. Internet untrusted Border router ACL filter Firewall stateful or NGFW DMZ: PUBLIC SERVERS, LIMITED TRUST switch Web server Mail server HIDS HIDS INSIDE: THE TRUSTED LAN switch Hostel PCs Database server HIDS NIDS sensor copy of the traffic (mirror port) Rules: the Internet reaches only the DMZ servers' ports (443, 25); the LAN may go out; nothing from outside opens a connection to the LAN. The NIDS watches copies of the traffic; HIDS agents watch each server's own files and logs.

To remember it: the firewall is the hostel gate with its chowkidar; the IDS is the CCTV in the corridors, which records and alerts the warden but stops no one; the IPS is a guard who also steps in when the camera spots trouble.

Asked on the paper, word for word
  • Write short notes on: (any two) a) WEP b) IDS c) SSL 2071 Shrawan Q10 · 4×2
In the exam A short note on IDS: the definition, NIDS against HIDS, signature against anomaly detection, IDS against IPS, and where the sensor sits, with the placement figure.

8.10Last minute recall

Chapter 8 in one screen

  • Attacks: interruption (availability), interception (confidentiality), modification (integrity), fabrication (authenticity); passive versus active.
  • Six properties: confidentiality, integrity, authentication, non-repudiation, availability, access control; the cheque story: account number hidden, amount unchanged, signature checked, writer cannot deny, bank open, only the cashier at the drawer.
  • Maintaining security: policy, access control, encryption, firewall, segmentation, patching, anti-malware, IDS and logs, backups, physical security and training.
  • Cryptography: plaintext, key, ciphertext; symmetric (one shared key, fast, n(n−1)/2 keys) against public key (key pair, slow, 2n keys); hybrid with a session key.
  • Classical: Caesar C=(P+k)mod26; monoalphabetic; polyalphabetic; columnar transposition.
  • DES: 64-bit block, 56-bit key, 16 Feistel rounds; IP, rounds, swap, IP−1; f = expansion, XOR, 8 S-boxes (6 to 4), P.
  • AES: 128-bit block; 128, 192, 256-bit key; 10, 12, 14 rounds; SubBytes, ShiftRows, MixColumns, AddRoundKey; last round without MixColumns.
  • RSA: n=pq, ϕ=(p−1)(q−1), gcd(e,ϕ)=1, edmodϕ=1; C=Memodn, M=Cdmodn; example 7, 11, 13, 37: E = 5 to 26 and back.
  • Diffie-Hellman: R1=Gx, R2=Gy, K=GxymodN; G = 7, N = 23, x = 3, y = 6 gives K = 18; man in the middle.
  • Digital signature: hash, encrypt the digest with the private key; verify with the public key and compare; authentication, integrity, non-repudiation; certificates from a CA.
  • PGP: hash, sign, compress, session key, lock it with B's public key, base64; web of trust.
  • SSL/TLS: between TCP and the application, port 443; handshake (hellos, certificate, key exchange, finished) and record protocol (fragment, compress, MAC, encrypt, header).
  • IPsec: AH (51: authentication, no secrecy) and ESP (50: encryption too); transport (host to host) and tunnel (gateway to gateway); SA, SPI, IKE.
  • VPN: a tunnel over the Internet; remote access and site to site (intranet, extranet); IPsec, SSL VPN, WireGuard.
  • WEP: RC4 with a 24-bit IV and a 40 or 104-bit key, CRC-32; IV reuse, weak keys, linear CRC, one static key; WPA (TKIP), WPA2 (AES, 802.11i), WPA3 (SAE).
  • Firewall: packet filter, stateful inspection, application gateway (proxy), circuit-level gateway, NGFW; first match, implicit deny; DMZ.
  • ACL: access-list 10 deny 202.70.91.0 0.0.0.255, access-list 10 permit any, ip access-group 10 in.
  • IDS: NIDS and HIDS; signature and anomaly; IDS alerts, IPS blocks.

209 questions · asked 412 times in 27 sittings · exam answers only

Theory answers

Every theory question the 27 papers have asked, each with the answer as it is written in the exam: the direct answer for the marks, nothing else. Only what a paper has actually set is here; the topics no paper has asked yet are taught on their chapter cards. A question with several parts is split into them. How a process is carried out, step by step, is in Practical answers, and the chapter card behind each answer teaches the topic in full. Read them by chapter, each question once with every source that set it, or by paper, question by question.

1Introduction to computer network

OSI and TCP/IP compared: similarities and differences TOP 9/27

Asked 9 times

2082 Bhadra · Q14 marksDifferentiate between TCP/IP and OSI model.

2081 Bhadra · Q1compare it with TCPI/IP model.

2079 Bhadra · Q18 marksCompare the OSI reference model and TCP/IP reference model mentioning their similarities and differences.

2076 Chaitra · Q15 marksCompare OSI with TCP/IP reference model.

2073 Shrawan · Q15 marksDifferentiate between TCP/IP and OSI Model.

2072 Chaitra · Q15 marksCompare OSI layer with TCP/IP Layer?

2071 Chaitra · Q13 marksCompare TCP/IP and OSI reference models.

2071 Shrawan · Q16 marksDistinguish between OSI and TCP/IP reference model.

2066 Bhadra · Q1a4 marksCompare OSI model with TCP/IP model.

The OSI model is ISO's seven-layer reference model, defined before its protocols; the TCP/IP model is the four-layer model of the protocols the Internet uses, described after them. TCP/IP's application layer covers OSI layers 7, 6 and 5, its transport and internet layers match OSI layers 4 and 3, and its host-to-network layer covers OSI layers 2 and 1.

OSI AND TCP/IP, LAYER BY LAYER Seven layers against four: the dashed lines show which OSI layers each TCP/IP layer does the work of. OSI MODEL AND OSI PROTOCOLS TCP/IP MODEL TCP/IP PROTOCOLS 7 Application FTAM, X.400, X.500 user services 6 Presentation ISO 8823, ASN.1 format, encrypt 5 Session ISO 8327 dialog, sync 4 Transport TP0 to TP4 (ISO 8073) end to end, ports 3 Network CLNP, X.25 packet layer routing, IP address 2 Data link HDLC, LAPB, LLC framing, MAC, errors 1 Physical X.21, RS-232, V.35 bits, voltage, timing Application layer 4 Transport layer 3 Internet layer 2 Host-to-network layer 1 HTTP, HTTPS, FTP, SMTP, POP3, IMAP, DNS, DHCP, SNMP, SSH, Telnet TCP, UDP IP, ICMP, IGMP, ARP Ethernet, Wi-Fi, PPP, DSL, Frame Relay TCP/IP has no session or presentation layer: the application does that work. Its host-to-network layer covers OSI layers 2 and 1. The OSI protocols in the left boxes were little used; the TCP/IP protocols on the right run the Internet.

Similarities:

  • Both are layered stacks of independent protocols, with peers communicating by protocols.
  • Both have a transport layer giving an end to end, network-independent service to processes.
  • Both have a network (internet) layer for routing and an application layer at the top.
  • Both use packet switching and encapsulation, and both are used to describe real networks.

Differences:

BasisOSITCP/IP
Stands forOpen Systems InterconnectionTransmission Control Protocol / Internet Protocol
Layers74
Developed byISO (ISO 7498, 1984)US DoD (ARPA), for the ARPANET
Approachmodel first, protocols later; generalprotocols first, model later; fits only TCP/IP
Service, interface, protocolclearly distinguishednot clearly distinguished
Network layerconnection-oriented and connectionlessconnectionless only (IP)
Transport layerconnection-oriented onlyboth (TCP and UDP)
Session and presentationseparate layerspart of the application layer
Physical and data linkseparate layersone host-to-network layer
Protocol replacementeasy; protocols well hiddendifficult
Internetworkingnot considered at firstthe main design goal
Usereference and teaching modelimplemented on the Internet

OSI's own protocols lost through bad timing, complexity, slow implementations and politics, while TCP/IP was already free and working. OSI remains the better model for describing networks; TCP/IP is the suite actually used.

Why network software is built as a hierarchy of layers HOT 8/27

Asked 8 times

2082 Bhadra · Q12 marksWhy do we have layered architecture in networks?

2080 Baishakh · Q13 marksWhy do we need layered architecture in computer network?

2076 Chaitra · Q12 marksWhat are the reasons for using layered network architecture?

2075 Ashwin · Q12 marksWhy layering is important?

2069 Chaitra · Q16 marksExplain the need of Networking Software in the form of Hierarchy?

2068 Chaitra · Q12 marksWhy are the network softwares defined with distinct layers stacked on top of one another?

2067 Ashad · Q13 marksWhy network software should be in hierarchical form?

2066 Bhadra · Q1a2 marksWhy do communication process within computer network is divided into layers?

Network software is organised as a hierarchy of layers, each built on the one below, because communication across different hardware, media and systems is too complex to design as one piece. Each layer offers services to the layer above and hides how they are implemented; layer n on one machine communicates with layer n on another through the layer n protocol, while the data actually passes down to the physical medium and up again.

PROTOCOL HIERARCHY AND VIRTUAL COMMUNICATION Five layers: layer n on one machine talks to layer n on the other through the layer n protocol, but data really travels down, across and up. LAYER 5 LAYER 4 LAYER 3 LAYER 2 LAYER 1 SOURCE MACHINE DESTINATION MACHINE M H4 M H3 H4 M1 H3 M2 H2 H3 H4 M1 T2 H2 H3 M2 T2 0 1 1 0 1 0 0 1 1 1 0 1 ... M H4 M H3 H4 M1 H3 M2 H2 H3 H4 M1 T2 H2 H3 M2 T2 0 1 1 0 1 0 0 1 1 1 0 1 ... physical medium layer 5 protocol layer 4 protocol layer 3 protocol layer 2 protocol Dashed: virtual communication between peers, by each layer protocol. Solid: the actual path, down, across the medium and up. Between each pair of adjacent layers is an interface. M message, H header, T trailer.
  1. Reduced complexity: a large problem is divided into small, manageable parts, each designed and tested separately.
  2. Modularity: a layer can be changed or replaced without affecting the others while its interface stays the same, for example Wi-Fi in place of Ethernet under the same browser.
  3. Standardisation and interoperability: defined functions for each layer let products of different vendors work together.
  4. Easy troubleshooting: faults are isolated layer by layer.
  5. Reuse and specialisation: one layer serves many users above it, and teams specialise by layer.
  6. Flexibility: new technology is added at one layer only.

Example of the flow: a message M gets header H4 at layer 4, is split and gets H3 at layer 3, and gets header H2 and trailer T2 at layer 2 before transmission; the receiver removes them in reverse order.

The seven layers of the OSI model, their functions and example protocols HOT 6/27

Asked 6 times

2081 Bhadra · Q1List a function of each layer of OSI reference model

2080 Bhadra · Q15 marksDiscuss the functions of each layer of Open System Interconnection (OSI) model.

2074 Chaitra · Q15 marksExplain Open System Interconnection (OSI) model.

2074 Ashwin · Q16 marksExplain different layers of OSI with its functionalities.

2067 Ashad · Q15 marksExplain in detail about OSI layer.

2066 Poush · Q78 marksExplain the seven layers of OSI model with their example protocols.

The OSI (Open Systems Interconnection) reference model is ISO's seven-layer framework (ISO 7498, 1984) for communication between open systems. It defines what each layer does, not the exact protocols. Layers 1 to 3 work hop by hop; layers 4 to 7 work end to end between the hosts.

THE OSI REFERENCE MODEL Seven layers in each host; the routers of the subnet run only the bottom three. COMMUNICATION SUBNET: ROUTERS RUN LAYERS 1 TO 3 ONLY HOST A Application Presentation Session Transport Network Data link Physical HOST B Application Presentation Session Transport Network Data link Physical ROUTER Network Data link Physical ROUTER Network Data link Physical 7 APDU 6 PPDU 5 SPDU 4 TPDU 3 Packet 2 Frame 1 Bit application protocol presentation protocol session protocol transport protocol Layers 4 to 7 work end to end, only in the two hosts; layers 1 to 3 work hop by hop, host to router and router to router. Bottom up: physical, data link, network, transport, session, presentation, application.
  1. Physical layer: transmits raw bits over the medium; defines connectors, voltage levels, bit timing, data rate, encoding and transmission mode. Examples: RS-232, 10BASE-T, DSL; devices: hub, repeater.
  2. Data link layer: node to node delivery of frames: framing, physical (MAC) addressing, error detection by CRC, flow control and medium access. Examples: Ethernet, HDLC, PPP; devices: switch, bridge.
  3. Network layer: source to destination delivery of packets across networks: logical (IP) addressing, routing, forwarding, fragmentation, congestion control. Examples: IP, ICMP, IPsec; device: router.
  4. Transport layer: process to process delivery: port addressing, segmentation and reassembly, connection control, end to end flow and error control. Examples: TCP, UDP.
  5. Session layer: establishes, maintains and ends sessions; dialog control (who talks when) and synchronisation with checkpoints. Examples: NetBIOS, RPC.
  6. Presentation layer: syntax and semantics of data: translation between formats (ASCII, EBCDIC), encryption and decryption, compression. Examples: TLS, JPEG, MPEG, ASN.1.
  7. Application layer: interface between user programs and the network: file transfer, email, remote login, directory services. Examples: HTTP, FTP, SMTP, DNS, Telnet.

The units are bits, frames, packets and segments in layers 1 to 4, and data above them.

Client/server against peer to peer, with advantages and disadvantages HOT 5/27

Asked 5 times

2082 Baishakh · Q14 marksExplain client/server and P2P network model with their advantages and disadvantages.

2081 Baishakh · Q14 marksDifferentiate between client-server is P2P network.

2080 Bhadra · Q13 marksDifferentiate between Client Server and Peer to Peer architecture.

2078 Bhadra · Q15 marksDifferentiate it with peer-to-peer network with advantages and disadvantages.

2074 Chaitra · Q13 marksDistinguish between Client-Server network and Peer-Peer network.

In the client/server model dedicated servers provide services that clients request; in the peer to peer (P2P) model every computer is an equal peer, both client and server, sharing resources directly.

CLIENT/SERVER AND PEER TO PEER Left: fixed roles, one server answers many clients. Right: equal peers, each both client and server. CLIENT/SERVER Server always on, holds the data Client laptop browser Client phone app Client ATM terminal request reply Clients start every exchange; the server only answers. If the server fails, every client stops. PEER TO PEER Peer A client and server Peer B client and server Peer C client and server Peer D client and server Every peer requests and serves; no central server. Each new peer adds capacity as well as demand.
BasisClient/serverPeer to peer
Rolesfixed: server serves, client requestseach peer both
Data and controlcentralised on the serverspread over the peers
Security and backupcentral, strongper machine, weak
Costhigh (server, administrator)low
Scalabilitylimited by the servergrows as peers join
Failureserver is a single point of failureno single point of failure
Exampleweb, online bankingBitTorrent, home workgroup

Client/server advantages: central control, easy backup, one consistent copy of the data. Disadvantages: costly; the server is a bottleneck and a single point of failure.

P2P advantages: cheap, easy to set up, no single point of failure. Disadvantages: weak security, no central backup, data unavailable when a peer is off.

Client/server networking and its features PIN 4/27

Asked 4 times

2076 Ashwin · Q14 marksWhat are the features of Client/Server Architecture?

2075 Chaitra · Q12 marksDraw the architecture for Client/Server network model.

2070 Chaitra · Q14 marksWhat are the features of Client/Server Architecture?

2066 Bhadra · Q1b3 marksWhat is client/server networking?

Client/server networking is a model in which dedicated, always-on servers hold the data and services, and client machines request them; every exchange is a request from a client process answered by a server process.

CLIENT/SERVER AND PEER TO PEER Left: fixed roles, one server answers many clients. Right: equal peers, each both client and server. CLIENT/SERVER Server always on, holds the data Client laptop browser Client phone app Client ATM terminal request reply Clients start every exchange; the server only answers. If the server fails, every client stops. PEER TO PEER Peer A client and server Peer B client and server Peer C client and server Peer D client and server Every peer requests and serves; no central server. Each new peer adds capacity as well as demand.
  • Asymmetric roles: clients start every exchange and servers only respond; many clients share one server.
  • Centralised data and resources: one up-to-date copy of the data, on the server.
  • Central administration and security: accounts, access rights and backups managed in one place.
  • Dedicated server: powerful hardware and a network operating system, always on.
  • Scalability: clients added freely; capacity grows by upgrading or adding servers.
  • Location transparency: a client needs only the server's address.
  • Tiers: two-tier, or three-tier (client, application server, database server).
  • Single point of failure: if the server fails, every client stops.

What a protocol is, with examples PIN 4/27

Asked 4 times

2082 Bhadra · Q12 marksDefine protocol with examples.

2081 Baishakh · Q11 markWhat is a protocol?

2076 Chaitra · Q11 markWhat is protocol?

2066 Poush · Q1protocol for network

A protocol is a set of rules that governs communication between entities: the format and order of the messages exchanged, their meaning, and the actions taken on sending or receiving them. Its key elements are syntax (format), semantics (meaning) and timing (when and how fast).

Examples: HTTP for web pages, SMTP for email, TCP and IP for delivery, Ethernet on a LAN.

X.25 and its key features PIN 4/27

Asked 4 times

2082 Baishakh · Q104 marksX.25 Network

2075 Ashwin · Q104 marksX.25

2071 Chaitra · Q13 marksExplain X.25 Network with its key feature.

2068 Chaitra · Q63 marksWhat is X.25?

X.25 is an ITU-T (CCITT, 1976) standard for the interface between a user's DTE and the DCE of a public packet switched network. It is connection-oriented and uses virtual circuits, with error and flow control at every hop, designed for the noisy analog lines of the 1970s.

X.25 LAYERS AND PACKET FORMAT X.25 covers the bottom three OSI layers of the DTE to DCE interface; the packet layer carries the virtual circuits. DTE (USER) DCE (NETWORK) Packet layer PLP: virtual circuits Packet layer PLP: virtual circuits packets Link layer LAPB (HDLC subset) Link layer LAPB (HDLC subset) frames Physical X.21, V.24 Physical X.21, V.24 bits X.25 defines only the DTE to DCE interface. DATA PACKET, MODULO 8 8 7 6 5 4 3 2 1 Q D 0 1 LCGN OCTET 1 LCN: logical channel number OCTET 2 P(R) M P(S) 0 OCTET 3 User data: up to 128 bytes by default OCTET 4 ON GFI: Q, D and 01 (modulo 8) or 10 (modulo 128) LCGN and LCN: one 12-bit virtual circuit number THE PACKET TRAVELS INSIDE A LAPB FRAME ON THE DTE TO DCE LINK Flag Address Control X.25 header user data FCS Flag 8 bits 8 bits 8 bits 3 octets variable 16 bits 8 bits the X.25 packet (layer 3) LAPB header (layer 2)
  • Three layers: physical (X.21), link (LAPB, a subset of HDLC) and packet (PLP), matching OSI layers 1 to 3.
  • Virtual circuits: switched (SVC) and permanent (PVC); up to 4095 on one line, named by a 12-bit LCGN and LCN.
  • Reliability: packets acknowledged and retransmitted hop by hop, and delivered in order.
  • Multiplexing of many circuits on one line; PADs connect simple terminals.
  • Limits: slow (typically up to 64 kbps), with high delay and overhead; replaced by Frame Relay.

What a computer network is PIN 3/27

Asked 3 times

2081 Bhadra · Q12 marksDefine Network.

2071 Shrawan · Q12 marksWhat is computer network?

2066 Poush · Q1Define network

A computer network is a collection of autonomous computers and other devices (nodes) interconnected by communication links, such as copper wire, optical fibre or radio, that follow common protocols so that they can exchange data and share resources.

Its parts are the nodes (hosts, switches, routers), the links, the protocols and the services. Example: the PCs of a college lab sharing one printer and one internet line.

Frame Relay and the operation of a Frame Relay network PIN 3/27

Asked 3 times

2078 Bhadra · Q104 marksFrame relay

2073 Shrawan · Q13 marksDefine Frame Relay in detail.

2070 Ashad · Q66 marksDescribe the operation of Frame-Relay network.

Frame Relay is a connection-oriented, packet switched WAN technology that carries variable-length frames over virtual circuits, working only at the physical and data link layers. It detects errors but does not correct them: damaged frames are dropped and the end systems recover. It runs from 56 kbps to 44.736 Mbps (T3).

FRAME RELAY: THE FRAME AND A PVC NETWORK No control field and no sequence numbers: the address carries the circuit number and the congestion bits. Flag Address Information (user data) FCS (CRC) Flag 8 bits 16 bits variable 16 bits 8 bits DLCI (high 6 bits) C/R EA 0 DLCI (low 4 bits) FECN BECN DE EA 1 octet 1 octet 2 DLCI: 10 bits, names the virtual circuit C/R: command or response, for the ends EA: 0 means another address octet follows FECN, BECN: congestion ahead, behind DE: drop this frame first if congested FRAME RELAY NETWORK (CARRIER) switch S1 switch S2 switch S3 Kathmandu HQ DLCI 102: to Pokhara DLCI 103: to Biratnagar Pokhara branch DLCI 201: to Kathmandu Biratnagar branch DLCI 301: to Kathmandu each switch: (in port, DLCI) to (out port, new DLCI) One PVC is DLCI 102 at Kathmandu and DLCI 201 at Pokhara: a DLCI has only local significance.
  • DLCI: a 10-bit data link connection identifier in the 2-byte address names the virtual circuit; it has local significance and changes at each switch.
  • Circuits: PVCs configured by the carrier; SVCs set up on demand by Q.933 signalling.
  • Frame: flag, address (DLCI, C/R, EA, FECN, BECN, DE), information, 16-bit FCS, flag; no control field.
  • Congestion: FECN and BECN warn the receiver and the sender; frames above the CIR get DE = 1 and are dropped first.

Operation:

  1. The customer router (DTE) puts the packet in a frame with the circuit's DLCI and sends it to the carrier's switch (DCE).
  2. The switch checks the FCS and silently discards a bad frame.
  3. It looks up the incoming port and DLCI, rewrites the DLCI for the outgoing link and relays the frame without any acknowledgement.
  4. The last switch delivers it to the destination DTE; TCP in the hosts recovers any loss.

The peer to peer model, its process and examples PIN 2/27

Asked 2 times

2075 Chaitra · Q16 marksExplain in details about P2P network model with supportive examples.

2066 Poush · Q16 marksExplain peer-to-peer network process with example.

A peer to peer (P2P) network is formed when two or more computers connect and share their resources (files, printers, storage, bandwidth) directly, without a separate server. Every peer has equal capabilities and responsibilities: it stores its own data and acts as both client and server.

CLIENT/SERVER AND PEER TO PEER Left: fixed roles, one server answers many clients. Right: equal peers, each both client and server. CLIENT/SERVER Server always on, holds the data Client laptop browser Client phone app Client ATM terminal request reply Clients start every exchange; the server only answers. If the server fails, every client stops. PEER TO PEER Peer A client and server Peer B client and server Peer C client and server Peer D client and server Every peer requests and serves; no central server. Each new peer adds capacity as well as demand.

The P2P process:

  1. Join: a new peer contacts known peers, a tracker or a bootstrap node, or announces itself on the LAN.
  2. Search: it locates a resource by flooding a query to its neighbours, by asking a central index (hybrid P2P) or through a distributed hash table.
  3. Connect: it opens direct connections to the peers holding the resource.
  4. Exchange: it downloads pieces from many peers at once and uploads the pieces it has to others.
  5. Leave: its shared resources disappear with it; the other peers continue.

Types: pure P2P (Gnutella), hybrid P2P with an index or tracker (Napster, BitTorrent) and the small office or home workgroup.

Examples: BitTorrent, where a large file is split into pieces and every downloader also uploads; four PCs in a Windows workgroup sharing folders and a printer; phone to phone sharing apps over direct Wi-Fi; Bitcoin, where every node keeps a copy of the ledger.

Merits: low cost, easy setup, no single point of failure, capacity grows with the peers. Demerits: weak security, no central backup or control.

The design issues for the layers PIN 2/27

Asked 2 times

2075 Ashwin · Q14 marksExplain design issues for layers in detail.

2068 Chaitra · Q16 marksWhat are the factors to be considered when designing these layers?

Every layer of a network must solve some common problems, called the design issues of the layers:

  1. Addressing: a network has many machines and each runs many processes, so every layer needs a way to identify senders and receivers (MAC, IP and port addresses).
  2. Direction of data transfer: whether data flows in one direction (simplex), both directions in turn (half duplex) or both at once (full duplex), and how many logical channels are used.
  3. Error control: circuits are imperfect, so error detecting or correcting codes are used and the receiver tells the sender which messages arrived correctly.
  4. Ordering (sequencing): some channels do not preserve order, so pieces are numbered and reordered.
  5. Flow control: a fast sender must not swamp a slow receiver; feedback or windows control the rate.
  6. Segmentation and reassembly: long messages are broken into pieces and reassembled; small ones may be combined.
  7. Multiplexing and demultiplexing: several conversations share one connection or channel when separate ones are costly.
  8. Routing: when several paths exist, the best route is chosen, mainly at the network layer.

Further issues are connection establishment and release, quality of service and security.

Which OSI layer does each task PIN 2/27

Asked 2 times

2072 Chaitra · Q13 marksExplain in which level of OSI layer following tasks are done. i) Error detection and correction ii) Encryption and Decryption of data iii) Logical identification of computer iv) Point-to-point connection of socket v) Dialogue control vi) Physical identification of computer

2069 Chaitra · Q12 marksMention in which level layer of OSI reference model following tasks are done. i) Timing and voltage of received signal ii) Encryption and decryption of data iii) Data framing iv) Point-to-point connection of socket.

TaskOSI layer
Timing and voltage of the received signalPhysical layer
Data framingData link layer
Error detection and correctionData link layer (hop by hop; transport also checks end to end)
Physical identification of a computer (MAC address)Data link layer
Logical identification of a computer (IP address)Network layer
Point-to-point connection of socketsTransport layer
Dialogue controlSession layer
Encryption and decryption of dataPresentation layer

A socket is an IP address plus a port, and the transport layer joins two such end points; MAC addresses travel in frame headers, IP addresses in packet headers.

The layers of the TCP/IP model and their functions PIN 2/27

Asked 2 times

2082 Baishakh · Q14 marksDiscuss the layer of TCP/IP model with suitable diagram.

2080 Baishakh · Q15 marksDiscuss the function of each layer of TCP/IP networking model.

The TCP/IP model is the four-layer model of the Internet protocol suite, developed for the ARPANET; its main goal is to interconnect different networks.

THE TCP/IP MODEL Four layers; many applications above and many links below meet in one internet protocol, IP. LAYER 4 APPLICATION LAYER 3 TRANSPORT LAYER 2 INTERNET LAYER 1 HOST-TO-NETWORK HTTP, HTTPS, SMTP, POP3, IMAP, FTP, DNS, DHCP, SSH, SNMP, Telnet TCP UDP IP ICMP, IGMP, ARP Ethernet, Wi-Fi, PPP, DSL, fibre, 4G and 5G user services; unit: message no session or presentation layer process to process, by port segment (TCP), datagram (UDP) host to host across networks: IP addressing, routing; packet one link: framing, MAC address, bits on the medium; frame IP is the narrow waist: every application runs over IP, and IP runs over every kind of link.
  1. Host-to-network (network access) layer: connects the host to the network so that it can send IP packets: framing, MAC addressing and transmission of bits; it combines the OSI data link and physical layers. Ethernet, Wi-Fi, PPP, DSL.
  2. Internet layer: lets hosts inject packets into any network and have them travel independently to the destination; defines IP, logical addressing and routing; connectionless, best effort. IP, ICMP, IGMP, ARP.
  3. Transport layer: end to end communication between processes, identified by ports: TCP (reliable, connection-oriented, ordered, flow controlled) and UDP (unreliable, connectionless, fast).
  4. Application layer: the protocols users work with; it also does the work of the OSI session and presentation layers. HTTP, SMTP, FTP, DNS, SSH, SNMP.

The protocols at each layer of the TCP/IP model PIN 2/27

Asked 2 times

2081 Baishakh · Q13 marksList out the common protocols used at each layer of TCP/IP model.

2070 Ashad · Q14 marksWrite the protocols used in each layer of ICP/IP model.

The TCP/IP model has four layers, and each uses its own protocols:

LayerCommon protocols
ApplicationHTTP (80), HTTPS (443), FTP (20, 21), SMTP (25), POP3 (110), IMAP (143), DNS (53), DHCP (67, 68), Telnet (23), SSH (22), SNMP (161)
TransportTCP (reliable, connection-oriented), UDP (connectionless, fast)
InternetIP (IPv4, IPv6), ICMP, IGMP, ARP, RARP
Host-to-networkEthernet (IEEE 802.3), Wi-Fi (IEEE 802.11), PPP, DSL, Frame Relay, ATM
THE TCP/IP MODEL Four layers; many applications above and many links below meet in one internet protocol, IP. LAYER 4 APPLICATION LAYER 3 TRANSPORT LAYER 2 INTERNET LAYER 1 HOST-TO-NETWORK HTTP, HTTPS, SMTP, POP3, IMAP, FTP, DNS, DHCP, SSH, SNMP, Telnet TCP UDP IP ICMP, IGMP, ARP Ethernet, Wi-Fi, PPP, DSL, fibre, 4G and 5G user services; unit: message no session or presentation layer process to process, by port segment (TCP), datagram (UDP) host to host across networks: IP addressing, routing; packet one link: framing, MAC address, bits on the medium; frame IP is the narrow waist: every application runs over IP, and IP runs over every kind of link.

The port numbers in brackets identify the application protocols to the transport layer. Routing protocols (RIP, OSPF, BGP) serve the internet layer. IP is the single protocol every packet uses, so any application runs over any link.

ATM, a short note PIN 2/27

Asked 2 times

2081 Bhadra · Q104 marksATM

2080 Bhadra · Q104 marksATM

ATM (Asynchronous Transfer Mode) is a connection-oriented cell switching technology, the transfer mode of broadband ISDN, that carries voice, video and data in fixed 53-byte cells: a 5-byte header and a 48-byte payload. Small fixed cells are switched in hardware, with low and predictable delay.

ATM: THE CELL AND THE LAYERS Every cell is 53 bytes; a connection is named by its VPI and VCI on each link. header 5 B payload 48 bytes UNI HEADER, BIT BY BIT 8 7 6 5 4 3 2 1 GFC VPI byte 1 VPI VCI byte 2 VCI byte 3 VCI PT CLP byte 4 HEC: CRC-8 byte 5 GFC 4, VPI 8, VCI 16, PT 3, CLP 1, HEC 8 bits NNI: no GFC; the VPI takes 12 bits HEC: CRC-8 over the first four bytes 5 of every 53 bytes is header: a 9.4% cell tax a small fixed cell keeps voice delay low ATM REFERENCE MODEL AAL: adapts user data to 48-byte payloads CS: convergence SAR: segment, reassemble ATM layer header, VPI/VCI switching, multiplexing Physical layer TC: HEC, cell boundaries PMD: bits on the medium VIRTUAL PATHS AND CHANNELS VPI 1 VPI 2 transmission path (the physical link) A VP switch changes only the VPI; a VC switch changes VPI and VCI.
  • Header (UNI): GFC 4 bits, VPI 8, VCI 16, PT 3, CLP 1, HEC 8 (a CRC-8 over the header).
  • Virtual paths and channels: a link carries virtual paths, each bundling virtual channels; the VPI/VCI pair names a connection (PVC or SVC).
  • Layers: physical (TC, PMD), the ATM layer (headers, switching, multiplexing) and the AAL (CS, SAR), with types AAL1, AAL2, AAL3/4 and AAL5.
  • Quality of service: CBR, VBR, ABR and UBR service categories.
  • Drawback: 5 of every 53 bytes (9.4%) is overhead.

Five instances of networks in daily life PIN 1/27

Asked once

2072 Chaitra · Q25 marksExplain five instances of how networks are a part of your life today.

Networks are part of everyday life wherever two devices exchange data. Five instances:

  1. Digital payments: paying a canteen bill by scanning a QR code or using a mobile wallet; the phone app is a client that sends the payment request to the bank's server over mobile data.
  2. Communication: voice and video calls over WhatsApp or Viber to relatives abroad travel as IP packets (VoIP), far cheaper than international phone calls; email and chat work the same way.
  3. Education: online classes, notes shared in class groups, assignments submitted online and exam results published on the web.
  4. Entertainment: videos streamed on demand from YouTube, social media, and online multiplayer games that exchange moves in real time.
  5. Daily services and work: booking a ride or a bus ticket, paying electricity bills, online banking, and offices sharing printers, files and databases over a LAN.

In each case the network provides resource sharing, communication and access to remote information.

Types of network by size and geography PIN 1/27

Asked once

2070 Ashad · Q25 marksDiscuss the types of network topologies based on its size and geographical distributions.

By size and geographical spread, networks are of four types; networks joined together form an internetwork.

TypeArea coveredFeaturesExample
PAN1 to 10 m, one personlow data rate, short rangeBluetooth earbuds and a phone
LANa room, building or campus, up to a few kmprivately owned; high speed (100 Mbps to 10 Gbps); low delay and error ratecollege lab Ethernet, Wi-Fi
MANa city, about 10 to 50 kmowned by ISPs or cable operators; usually fibre ringsa city fibre ring, a cable TV network
WANa country or continentlinks leased from carriers; lower speed, higher delay; hosts joined through a subnet of routersbank branches joined by leased lines, X.25, Frame Relay or MPLS

Internetwork: different networks joined by routers or gateways; the Internet is the largest, joining LANs, MANs and WANs worldwide with TCP/IP. The span of a network decides its owner, speed, delay and error rate.

Network topology defined PIN 1/27

Asked once

2070 Ashad · Q23 marksHow do you define network topology?

Network topology is the arrangement of the nodes and links of a network. The physical topology is the actual layout of the devices and cables; the logical topology is the path the signals actually follow (a hub wired as a star works logically as a bus).

NETWORK TOPOLOGIES How the nodes and links are arranged; the physical layout and the logical signal path can differ. Bus one shared backbone: cheap, least cable; one break stops the whole network Star a cut link loses only one node; a failed switch stops every node Ring one way round; a token gives turns; one break or dead node stops the ring Mesh every pair linked: n(n-1)/2 links; robust and private, but costly to cable Tree stars in a hierarchy under a root; root fails: the branches are cut off Hybrid two topologies joined, star and ring; flexible, but complex to design terminator switch one way root switch switch star ring backbone
  • Bus: one shared backbone; cheap, but one break stops all.
  • Star: each node linked to a central switch; easy to manage, but the switch is a weak point.
  • Ring: nodes in a closed loop, with token passing.
  • Mesh: every pair linked, n(n−1)/2 links; robust but costly.
  • Tree and hybrid: hierarchies and combinations of these.

The active networking framework against the legacy network PIN 1/27

Asked once

2066 Bhadra · Q1b5 marksExplain Active Networking model framework comparing with traditional legacy network.

An active network is a network whose nodes are programmable: besides forwarding packets, the routers execute code supplied by users or carried in the packets, and so perform computations on the data passing through them. A legacy (traditional) network is passive: its nodes only store and forward packets by their headers.

ACTIVE NODE AGAINST LEGACY ROUTER A legacy node only forwards; an active node also runs code on the packets passing through it. LEGACY ROUTER (PASSIVE) header data in read the header look up the route forward the packet header data out The data is never read or changed; new services wait for new firmware. ACTIVE NODE (DARPA ARCHITECTURE) AA 1 AA 2 AA 3 active apps EE 1 (Java VM) EE 2 management EE NodeOS shares channels, CPU, memory, storage; isolates the EEs node hardware and its links ANEP header code data out: forwarded, changed or dropped capsule in: its ANEP header names the EE, where its code runs Capsule (integrated) approach: code rides in every packet. Programmable switch (discrete) approach: code is loaded first, packets name it.

Framework of an active node: the NodeOS manages the node's channels, processor, memory and storage and isolates the programs; execution environments (such as a Java virtual machine) run the active code; active applications are the user programs inside them. An ANEP header directs each packet to its environment. Code arrives in every packet (capsule, the integrated approach) or is loaded in advance (programmable switch, the discrete approach).

PointLegacy networkActive network
Node's workstore and forward by headerforward and compute on contents
Programmed byvendor firmwareusers and packets
New serviceyears of standardisationdeployed quickly as code
Packetheader and datacode and data (capsule)
Intelligenceend systems onlyend systems and network
Security, speedsimpler, fasterharder, slower

Protocols and interfaces PIN 1/27

Asked once

2070 Ashad · Q14 marksWhat do you mean by protocol and interfaces?

A protocol is a set of rules that peer entities, the same layer on two machines, use to communicate: the format, meaning and timing of the messages they exchange (syntax, semantics, timing). Examples: HTTP, TCP, IP, Ethernet.

An interface is the boundary between two adjacent layers on the same machine. It defines the primitive operations and services the lower layer offers the upper layer, with their parameters and results.

PROTOCOL HIERARCHY AND VIRTUAL COMMUNICATION Five layers: layer n on one machine talks to layer n on the other through the layer n protocol, but data really travels down, across and up. LAYER 5 LAYER 4 LAYER 3 LAYER 2 LAYER 1 SOURCE MACHINE DESTINATION MACHINE M H4 M H3 H4 M1 H3 M2 H2 H3 H4 M1 T2 H2 H3 M2 T2 0 1 1 0 1 0 0 1 1 1 0 1 ... M H4 M H3 H4 M1 H3 M2 H2 H3 H4 M1 T2 H2 H3 M2 T2 0 1 1 0 1 0 0 1 1 1 0 1 ... physical medium layer 5 protocol layer 4 protocol layer 3 protocol layer 2 protocol Dashed: virtual communication between peers, by each layer protocol. Solid: the actual path, down, across the medium and up. Between each pair of adjacent layers is an interface. M message, H header, T trailer.
  • Direction: a protocol is horizontal (peer to peer); an interface is vertical (layer to layer).
  • Independence: a protocol can change without changing the interface, so layers stay replaceable.
  • Example: TCP is the transport protocol between two hosts; the socket calls are the interface an application uses to reach it.

What a network architecture is PIN 1/27

Asked once

2071 Chaitra · Q12 marksWhat do you mean by network architecture?

A network architecture is the set of layers and protocols of a network. Its specification gives enough detail for an implementer to build the software or hardware of each layer so that it obeys the correct protocol; implementation details and the interfaces inside one machine are not part of it. Examples: the TCP/IP architecture and IBM's SNA.

Service primitives for a connection-oriented service PIN 1/27

Asked once

2075 Ashwin · Q12 marksMention service primitives for implementing connection oriented service.

A connection-oriented service is used through five service primitives:

PrimitiveMeaning
LISTENblock, waiting for an incoming connection
CONNECTestablish a connection with a waiting peer
RECEIVEblock, waiting for an incoming message
SENDsend a message to the peer
DISCONNECTterminate the connection

The server calls LISTEN, the client CONNECTs, both sides SEND and RECEIVE, and either side DISCONNECTs.

The significance of the OSI model PIN 1/27

Asked once

2074 Ashwin · Q12 marksWhat is the significance of OSI layer?

The OSI model is significant because it provides a common reference for describing and designing networks. It divides communication into seven layers with defined functions, separates services, interfaces and protocols so that a layer can change without disturbing the others, enables interoperability between vendors, guides layer by layer troubleshooting, and gives networking a common vocabulary ("layer 2 switch", "layer 3 router").

The X.25 packet format PIN 1/27

Asked once

2068 Chaitra · Q65 marksExplain the format of X.25 packet in detail.

X.25 is the ITU-T packet switching interface between a DTE and a DCE; at its packet layer, data travels in packets with a 3-octet header. The data packet with modulo 8 numbering is:

X.25 LAYERS AND PACKET FORMAT X.25 covers the bottom three OSI layers of the DTE to DCE interface; the packet layer carries the virtual circuits. DTE (USER) DCE (NETWORK) Packet layer PLP: virtual circuits Packet layer PLP: virtual circuits packets Link layer LAPB (HDLC subset) Link layer LAPB (HDLC subset) frames Physical X.21, V.24 Physical X.21, V.24 bits X.25 defines only the DTE to DCE interface. DATA PACKET, MODULO 8 8 7 6 5 4 3 2 1 Q D 0 1 LCGN OCTET 1 LCN: logical channel number OCTET 2 P(R) M P(S) 0 OCTET 3 User data: up to 128 bytes by default OCTET 4 ON GFI: Q, D and 01 (modulo 8) or 10 (modulo 128) LCGN and LCN: one 12-bit virtual circuit number THE PACKET TRAVELS INSIDE A LAPB FRAME ON THE DTE TO DCE LINK Flag Address Control X.25 header user data FCS Flag 8 bits 8 bits 8 bits 3 octets variable 16 bits 8 bits the X.25 packet (layer 3) LAPB header (layer 2)
  • GFI (4 bits): the Q bit (qualifier: control data for a PAD, or user data), the D bit (delivery confirmation: end to end or local acknowledgement) and two bits giving the numbering (01 modulo 8, 10 modulo 128).
  • LCGN (4 bits) and LCN (8 bits): together a 12-bit virtual circuit number, up to 4095 circuits on a link.
  • P(R) (3 bits): receive sequence number, the next packet expected; it acknowledges earlier packets.
  • M bit: more data follows in the next packet.
  • P(S) (3 bits): send sequence number.
  • Last bit 0: a data packet; control packets end in 1 and use the octet as a type code (call request 00001011, call accepted 00001111, clear request 00010011).
  • User data: up to 128 bytes by default.

The packet travels inside a LAPB frame, between its flag, address and control fields and its FCS.

X.25 and Frame Relay compared PIN 1/27

Asked once

2068 Baishakh · Q106 marksCompare x.25 and frame relay network.

X.25 is a reliable packet switching interface using three layers, while Frame Relay is its faster successor, which keeps the virtual circuits but works only up to the data link layer.

BasisX.25Frame Relay
Layersphysical, link (LAPB), packet (PLP)physical and data link only
Error controldetection and correction at every hop, by retransmissiondetection only; bad frames dropped
Flow controlhop by hop and per circuit (windows, RR/RNR)none; congestion notified by FECN, BECN, DE
Acknowledgementsat every hopnone in the network
Speedlow, typically up to 64 kbps56 kbps to 44.736 Mbps
Delay and overheadhighlow
Circuit identifier12-bit LCGN and LCN10-bit DLCI
Multiplexingat layer 3at layer 2
Signallingin band (call packets)out of band (DLCI 0, Q.933)
Suited tonoisy analog lines, terminal trafficreliable digital lines, bursty LAN traffic

Frame Relay is faster because lines became nearly error free and the end systems (TCP) recover lost data, so the per-hop checking was dropped.

The ATM adaptation layer PIN 1/27

Asked once

2066 Bhadra · Q5b3 marksATM AAL

The ATM adaptation layer (AAL) adapts user data to 48-byte cell payloads. Its convergence sublayer (CS) adds service-specific information (timing, sequence numbers, a CRC); its segmentation and reassembly (SAR) sublayer cuts the data into 48-byte payloads and rebuilds it at the far end.

TypeTrafficUse
AAL1constant bit rate with timing (class A)voice, T1/E1 emulation
AAL2variable bit rate with timing (class B)compressed voice and video
AAL3/4variable rate data, connection-oriented or connectionless (classes C, D)data; 44-byte payload per cell
AAL5simple, efficient data (classes C, D)IP over ATM; 8-byte trailer with CRC-32

2Physical layer

Circuit switching compared with packet switching HOT 7/27

Asked 7 times

2075 Ashwin · Q23 marksCompare circuit switching and packet switching.

2074 Chaitra · Q34 marksDifferentiate between circuit switching and packet switching.

2074 Ashwin · Q36 marksWhat are the differences between circuit switching and packet switching?

2069 Chaitra · Q24 marksDifferentiate between circuit switching and packet switching.

2068 Chaitra · Q55 marksb) Circuit switching and packet switching

2068 Baishakh · Q16 marksDifferentiate between packet switching and circuit switching.

2066 Bhadra · Q3b2 marksDifferentiate between circuit switching and packet switching technology.

Circuit switching reserves a dedicated path for the whole session, in three phases: setup, data transfer and teardown. Packet switching splits the data into packets, each with a header, that are stored and forwarded node by node over links shared with other users, as datagrams or along virtual circuits.

BasisCircuit switchingPacket switching
Pathdedicated for the sessionno dedicated path; links shared
Setuprequired before transfernot required (datagram)
Bandwidthfixed, reserveddynamic, on demand
Idle capacitywasted when silentused by other packets
Transfercontinuous; no store-and-forwardstore-and-forward at each node
Addressingonly during setupheader on every packet
Delaysetup delay, then constantvariable queuing delay
Orderalways in ordermay arrive out of order
Congestionat setup: call blockedper packet: queuing, loss
Switch failurecall is cutpackets rerouted
Chargingby time and distanceby data volume
Suited toreal-time voicebursty data
Exampletelephone network (PSTN)the internet (IP)
CIRCUIT, MESSAGE AND PACKET SWITCHING One message from A to D through switches B and C; time runs downward in each panel. Circuit switching A B C D Message switching A B C D Packet switching A B C D call request call accepted data, one stream release whole message stored at each node arrives last 1 1 1 2 2 2 3 3 3 packets pipelined arrives first setup first, then one stream: no stop at B or C B and C store the whole message before passing it on packets overlap on the links; no setup, no reservation

For the same message, packet switching finishes first because its packets overlap on successive links, while circuit switching pays a setup delay before its continuous stream starts.

Transmission media defined PIN 3/27

Asked 3 times

2076 Chaitra · Q21 markWhat is transmission medium?

2074 Chaitra · Q23 marksDefine transmission media.

2071 Shrawan · Q22 marksWhat is transmission media?

A transmission medium is the physical path between a transmitter and a receiver that carries the signal (electric current, light or electromagnetic waves) from source to destination. It lies below the physical layer and is controlled by it.

  • Guided (wired) media: the signal is confined to a solid path: twisted pair cable, coaxial cable, optical fiber.
  • Unguided (wireless) media: an antenna radiates the signal through air or space: radio waves, microwaves (terrestrial and satellite), infrared.

The medium's bandwidth, attenuation and noise immunity decide a link's data rate and distance: a campus uses UTP in its labs, fiber in its backbone and Wi-Fi for laptops.

The transmission media, with their merits and demerits PIN 3/27

Asked 3 times

2076 Chaitra · Q27 marksExplain different transmission medium with their merits and demerits.

2072 Kartik · Q26 marksExplain different types of transmission media.

2066 Poush · Q28 marksDescribe guided and unguided media used in computer network with their advantages.

Transmission media are of two types: guided (wired), where the signal follows a cable, and unguided (wireless), where an antenna radiates it through air or space.

TRANSMISSION MEDIA Guided media keep the signal on a cable; unguided media radiate it from an antenna into air or space. Transmission media Guided (wired) signal on a solid path Unguided (wireless) signal from an antenna Twisted pair UTP, STP telephone, LAN Coaxial cable thin, thick; RG-6 cable TV, CCTV Optical fiber single, multimode backbone, FTTH Radio waves 3 kHz to 1 GHz AM, FM, TV Microwaves 1 to 300 GHz terrestrial, satellite Infrared 300 GHz to 400 THz remotes, short links bounded: speed and security, limited by the cable unbounded: mobility and reach, open to anyone

Guided media:

  • Twisted pair: two insulated copper wires twisted to cancel noise; UTP and STP; Cat 5e to Cat 6A for LANs, also telephone lines. Merits: cheapest, easy to install. Demerits: noise, short range (100 m for Ethernet), easy to tap.
  • Coaxial cable: a central conductor, insulation, a braided shield and a jacket; cable TV, CCTV. Merits: wider bandwidth and better shielding than twisted pair. Demerits: bulky, costlier, amplifiers needed every few km.
  • Optical fiber: light guided in a glass core by total internal reflection; single mode and multimode; backbones and fiber to the home. Merits: very high bandwidth, low loss, immune to EMI, secure. Demerits: costly installation, fragile, needs splicing.

Unguided media:

  • Radio waves (3 kHz to 1 GHz): omnidirectional; AM, FM, TV. Merits: long range, pass through walls, no alignment. Demerits: low data rate, interference, crowded spectrum.
  • Microwaves (1 to 300 GHz): directional, line of sight; terrestrial links, satellites, mobile networks, Wi-Fi. Merits: high data rate, no cabling over rough terrain; satellites cover huge areas. Demerits: antennas must see each other, rain fade, satellite delay and cost.
  • Infrared (300 GHz to 400 THz): short range, line of sight; remote controls. Merits: private to a room, no licence. Demerits: blocked by walls, disturbed by sunlight.

Switching defined PIN 3/27

Asked 3 times

2075 Chaitra · Q21 markWhat is switching?

2073 Shrawan · Q22 marksWhat do you mean by switching in communication?

2068 Baishakh · Q12 marksWhat is a switching?

Switching is the process of forwarding data from a sender to a receiver through intermediate nodes (switches), each connecting an input port (ingress) to the output port (egress) that leads toward the destination. It avoids a dedicated link between every pair of devices: a mesh of n devices would need n(n−1)/2 links.

Types: circuit switching (telephone network), message switching (telegraph) and packet switching (the internet), the last as datagram or virtual circuit.

Switching and multiplexing defined PIN 3/27

Asked 3 times

2079 Bhadra · Q24 marksWhat is switching and multiplexing?

2074 Ashwin · Q22 marksDefine switching and multiplexing.

2069 Chaitra · Q24 marksDefine switching and multiplexing.

Switching is the technique of connecting a sender to a receiver through intermediate nodes (switches or routers) that forward data from an input port to the output port leading to the destination, so that no dedicated link is needed between every pair of devices. Types: circuit, message and packet (datagram, virtual circuit) switching. Example: a telephone exchange connecting a call.

Multiplexing is the technique of sharing one link among several signals at the same time: a multiplexer combines n input channels into one link and a demultiplexer separates them at the other end. Types: FDM, WDM, TDM (synchronous, statistical) and CDM. Example: one E1 trunk carrying 30 calls.

Switching chooses the path through the network; multiplexing shares the capacity of each link on that path.

Virtual circuit switching PIN 3/27

Asked 3 times

2076 Ashwin · Q104 marksc) Virtual circuit switching

2070 Ashad · Q62 marksWhat is virus circuit switching?

2066 Poush · Q62 marksWhat do you understand by virtual circuit switching?

Virtual circuit switching is a connection-oriented form of packet switching: a logical path, the virtual circuit, is set up between source and destination before data flows, and every packet then follows that path carrying only a short virtual circuit identifier (VCI).

  1. Setup: a setup request travels to the destination; each switch records an entry (incoming port and VCI to outgoing port and VCI) in its table; an acknowledgment returns.
  2. Data transfer: each switch looks up the packet's incoming VCI, replaces it with the outgoing VCI and forwards the packet; packets arrive in order.
  3. Teardown: a release request removes the table entries.

Types: PVC (permanent, configured by the operator) and SVC (switched, set up for each session). A VCI has only local significance and changes at each hop. Examples: X.25, Frame Relay (DLCI), ATM (VPI/VCI), MPLS (label).

DATAGRAM AND VIRTUAL CIRCUIT NETWORKS The same four routers used two ways: every packet on its own, or every packet on one path set up first. Datagram network connectionless: each packet routed on its own R1 R2 R3 R4 A B 1 3 2 4 arrive: 2, 1, 4, 3 PACKET HEADER to B from A seq 3 data no setup; full address in every packet routers keep no state per connection packets may take different paths, out of order example: IP, the Internet Virtual circuit network connection oriented: set up, transfer, tear down R1 R2 R3 R4 A B VCI 12 VCI 25 VCI 7 VCI 31 1 2 arrive: 1, 2, 3, 4 R2’S VC TABLE from R1 in port 25 in VCI to R4 out port 7 out VCI a short VCI, swapped at every hop every packet on one path, in order a packet carries only the VCI and data examples: X.25, Frame Relay, ATM, MPLS

ISDN: what it is, why it was developed, and its contribution PIN 3/27

Asked 3 times

2076 Ashwin · Q22 marksWhy the telephone companies developed ISDN?

2071 Chaitra · Q22 marksWhat is ISDN?

2067 Ashad · Q33 marksWhat do you mean by ISDN and what is it contribution in the field of data communication?

ISDN (Integrated Services Digital Network) is an ITU-T standard for a fully digital, circuit-switched telephone network carrying voice, data, fax and video together, end to end, over the existing copper line: 64 kbps B channels carry user data, a D channel carries signalling, through the BRI (2B + D) and PRI (23B + D or 30B + D) interfaces.

Why developed: the analog local loop limited data rates, and voice, telex and data used separate networks; one integrated digital network gives one line, one interface and faster out-of-band signalling.

Contribution: digital access at 64 to 128 kbps (BRI) and 2.048 Mbps (PRI), voice and data together on one line, fast call setup, and the path to ATM.

ISDN architecture: channels, interfaces, functional groups and reference points PIN 3/27

Asked 3 times

2076 Ashwin · Q26 marksExplain the working principle of ISDN with its interface and functional group.

2075 Ashwin · Q25 marksExplain ISDN channels with architecture.

2071 Chaitra · Q26 marksExplain about the ISDN architecture in detail with example.

ISDN connects user devices to a digital ISDN exchange through standard functional groups joined at standard reference points:

ISDN FUNCTIONAL GROUPS AND REFERENCE POINTS Devices (functional groups) in boxes; the interfaces between them (reference points) in circles. TE1 ISDN phone, PC card TE2 analog phone, PC TA adapter NT2 PBX or router layers 2 and 3 NT1 line end, layer 1 ISDN exchange (LT, ET) S R S T U circuit network packet network leased lines SS7 signalling CUSTOMER PREMISES TELEPHONE COMPANY BRI: 2B + D = 144 kbps; 192 kbps on the four wire S/T bus with framing; the U loop is one twisted pair. PRI: 23B + D at 1.544 Mbps (T1) or 30B + D at 2.048 Mbps (E1); NT2 is then usually a PBX.
  • TE1: ISDN-compatible terminal (digital phone, PC with an ISDN card).
  • TE2: non-ISDN terminal (analog phone); needs a TA (terminal adapter) to convert its signals.
  • NT2: customer switching such as a PBX or router (layers 2 and 3).
  • NT1: terminates the line, converting the four-wire S/T bus to the two-wire local loop (layer 1).
  • Reference points: R (TE2 to TA), S (TE1 or TA to NT2), T (NT2 to NT1), U (NT1 to the exchange).

Channels: B (bearer) 64 kbps for user voice and data; D 16 or 64 kbps for signalling and packet data; H for higher rates (H0 384, H11 1536, H12 1920 kbps).

Interfaces: BRI = 2B + D = 144 kbps (192 kbps with framing) for homes and small offices; PRI = 23B + D at 1.544 Mbps (T1) or 30B + D at 2.048 Mbps (E1) for PBXs and businesses.

Working principle: a terminal sends a SETUP message on the D channel (Q.931 over LAPD); the exchange signals the call through the network (SS7) and assigns a B channel, which then carries 64 kbps of digital data end to end; release also goes over D.

Example: a small office BRI: a digital phone and a PC on the S bus, an old fax through a TA; one call and a 64 kbps data session at the same time.

Factors in choosing a transmission medium PIN 2/27

Asked 2 times

2081 Bhadra · Q22 marksWhat are the factors to be considered while selecting media for communication?

2080 Bhadra · Q23 marksDiscuss about the different factors of choosing the transmission media.

The factors weighed in choosing a transmission medium:

  1. Bandwidth and data rate needed, now and in future.
  2. Distance and attenuation: how far the signal goes before a repeater is needed.
  3. Cost: cable, connectors, equipment, installation and maintenance.
  4. Noise immunity: resistance to electromagnetic interference and crosstalk.
  5. Security: how easily the medium can be tapped.
  6. Ease of installation: weight, flexibility, skills needed.
  7. Environment and terrain: indoor or outdoor, rivers, hills.
  8. Mobility of the users, and the reliability and scalability required.

Example: Cat 6 UTP inside a building, fiber between buildings, Wi-Fi for laptops.

Types of multiplexing PIN 2/27

Asked 2 times

2080 Baishakh · Q25 marksExplain different types of multiplexing techniques.

2067 Ashad · Q35 marksExplain various types of multiplexing mechanism used in communication.

The main types of multiplexing:

HOW A LINK IS SHARED Three senders A, B and C on one link; in every picture time runs left to right. FDM a band per sender; grey: guard bands; WDM: same, with light Synchronous TDM fixed slot per sender every frame; idle slot wasted; F tab: framing Statistical TDM slots on demand; each slot carries its sender address CDM all at once, whole band; orthogonal codes separate senders A on band f1, all the time B on band f2, all the time C on band f3, all the time A1 B1 C1 frame 1 A2 B2 empty frame 2 A3 empty C3 frame 3 A4 empty empty frame 4 4 of 12 slots wasted A A1 B B1 frame 1 C C1 A A2 frame 2 B B2 A A3 frame 3 C C3 A A4 frame 4 grey tab: address A × code a + B × code b + C × code c sent together over the whole band; multiplying by code a gives back A
  1. FDM (frequency division): analog; the link bandwidth is divided into frequency bands, each signal modulated onto its own carrier, with guard bands between; all signals travel at once. Example: FM radio (88 to 108 MHz), cable TV.
  2. WDM (wavelength division): FDM for light; each signal on its own wavelength in one fiber, combined and separated by a prism or grating. Example: DWDM fiber backbones.
  3. TDM (time division): digital; the link's time is divided into slots used in turn, grouped into frames.
    • Synchronous TDM: each input owns a fixed slot in every frame, even when idle, so slots are wasted. Example: T1, E1.
    • Statistical TDM: slots are given only to inputs with data, each slot carrying its input's address. Example: data concentrators.
  4. CDM (code division): all stations send at once over the whole band, each multiplied by a unique orthogonal code; the receiver extracts one station by correlating with its code. Example: CDMA in 3G, GPS.

Switching and its types PIN 2/27

Asked 2 times

2075 Chaitra · Q22 marksWhat are the various switching techniques?

2067 Ashad · Q44 marksDescribe what do you understand by switching along with various types of switching mechanism.

Switching connects a sender to a receiver through intermediate switching nodes, which forward data from an input port to the output port toward the destination. Its types:

  1. Circuit switching: a dedicated path is set up before communication (setup, data transfer, teardown) and its bandwidth reserved for the whole session. Example: a telephone call.
  2. Message switching: the whole message is stored at each node and forwarded when the next link is free (store and forward); no setup, long delays. Example: telegraph.
  3. Packet switching: the message is divided into packets forwarded store-and-forward, sharing links on demand.
    • Datagram: each packet routed independently by its full address (IP).
    • Virtual circuit: a logical path set up first; packets carry a short VCI (Frame Relay, ATM).

Datagram and virtual circuit switching compared, with Frame Relay PIN 2/27

Asked 2 times

2081 Bhadra · Q26 marksDifferentiate between datagram and virtual circuit switching approach with respect to Frame Relay Network.

2078 Bhadra · Q24 marksDifferentiate between Packet switching and Virtual Circuit switching.

Datagram (packet) switching is connectionless: each packet carries the full destination address and is routed independently. Virtual circuit switching is connection-oriented: a path is set up first (setup, data transfer, teardown) and every packet follows it, carrying only a short virtual circuit identifier (VCI).

DATAGRAM AND VIRTUAL CIRCUIT NETWORKS The same four routers used two ways: every packet on its own, or every packet on one path set up first. Datagram network connectionless: each packet routed on its own R1 R2 R3 R4 A B 1 3 2 4 arrive: 2, 1, 4, 3 PACKET HEADER to B from A seq 3 data no setup; full address in every packet routers keep no state per connection packets may take different paths, out of order example: IP, the Internet Virtual circuit network connection oriented: set up, transfer, tear down R1 R2 R3 R4 A B VCI 12 VCI 25 VCI 7 VCI 31 1 2 arrive: 1, 2, 3, 4 R2’S VC TABLE from R1 in port 25 in VCI to R4 out port 7 out VCI a short VCI, swapped at every hop every packet on one path, in order a packet carries only the VCI and data examples: X.25, Frame Relay, ATM, MPLS
BasisDatagramVirtual circuit
Setupnot neededneeded
Addressingfull source and destination addressshort VC number
Routingeach packet independentlyonce at setup; all packets follow
Router statenone per connectiontable entry per VC
Ordermay arrive out of orderin order
Router failureonly packets in it lostall VCs through it terminated
QoS, congestion controldifficulteasy with reserved resources
ExamplesIPX.25, Frame Relay, ATM, MPLS

With respect to Frame Relay: Frame Relay is a virtual circuit network. Each frame carries a 10-bit DLCI, its VCI, instead of a destination address; switches forward frames by (input port, DLCI) table lookups and swap the DLCI hop by hop; circuits are PVCs set up by the carrier or SVCs set up by signalling; frames arrive in order, and congestion is signalled with the FECN, BECN and DE bits. A datagram network such as IP over the same links would route every packet by its full address, with no setup and no per-circuit state.

Functions of the physical layer in the TCP/IP model PIN 1/27

Asked once

2072 Kartik · Q22 marksList out the functions of physical layer in TCP/IP reference model.

In the TCP/IP reference model the physical layer forms the lower part of the host-to-network (network access) layer; it moves raw bits as signals over the medium. Its functions:

  • Physical characteristics: the medium, connectors and interface.
  • Representation of bits: encoding bits as electrical, light or radio signals.
  • Data rate: the number of bits sent per second.
  • Synchronization of the sender's and receiver's clocks.
  • Line configuration and topology: point-to-point or multipoint; star, bus, ring, mesh.
  • Transmission mode: simplex, half-duplex or full-duplex.

Throughput defined PIN 1/27

Asked once

2078 Bhadra · Q21 markDefine Throughput.

Throughput is the actual rate at which data is successfully delivered across a link or network over a period of time, measured in bits per second. It never exceeds the bandwidth, the link's maximum rate, because of overheads, congestion and retransmissions.

Throughput=data delivered (bits)time taken (s)

Causes of packet delay PIN 1/27

Asked once

2074 Ashwin · Q32 marksWhat are the causes of packet delay in computer networks?

A packet is delayed at every node by four causes, which add up to the nodal delay:

  • Processing delay: checking the header and bit errors, choosing the output link.
  • Queuing delay: waiting in the output buffer behind other packets; grows with congestion.
  • Transmission delay: pushing all L bits onto a link of rate R, L/R.
  • Propagation delay: the signal crossing the link, d/s.

Retransmissions after loss and many store-and-forward hops add more.

THE FOUR DELAYS AT A ROUTER A packet crossing router A towards router B is delayed four times; their sum is the nodal delay. packet ROUTER A Processing check, look up output queue (buffer) Output port sends bit by bit bits link: rate R, length d Router B 1 Processing delay check header, errors, pick output link: µs 2 Queuing delay waits for the link; grows with the load 3 Transmission delay all L bits onto link at rate R: L / R 4 Propagation delay a bit crosses length d at speed s: d / s Nodal delay = processing + queuing + transmission + propagation

The common guided and unguided media in use today PIN 1/27

Asked once

2081 Baishakh · Q23 marksList out the most common guided and unguided transmission media used in computer networks now a days.

Guided (wired) media in common use:

  • Twisted pair: UTP Cat 5e, Cat 6 and Cat 6A for Ethernet LANs; telephone lines and DSL.
  • Coaxial cable: cable TV and cable internet, CCTV.
  • Optical fiber: single mode for backbones, fiber to the home and long-haul links; multimode inside buildings.

Unguided (wireless) media in common use:

  • Radio waves: AM and FM radio, TV broadcasting.
  • Microwaves: Wi-Fi (2.4, 5 and 6 GHz), 4G and 5G mobile networks, Bluetooth, terrestrial point-to-point links, satellite links (VSAT, satellite TV and internet).
  • Infrared: TV remotes and short device-to-device links.

Three transmission media in detail PIN 1/27

Asked once

2071 Shrawan · Q26 marksExplain about any three transmission media in detail.

1. Twisted pair cable: two insulated copper wires twisted together, four pairs in an Ethernet cable; the twisting cancels noise and crosstalk. UTP is unshielded and cheap; STP adds a grounded shield. Categories Cat 5e to Cat 6A carry 1 to 10 Gbps up to 100 m. Uses: LANs, telephone loops, DSL. Merits: cheap, easy to install. Demerits: noise, short range.

2. Optical fiber: a glass core of higher refractive index inside a cladding of lower index; light pulses from an LED or laser are guided by total internal reflection and detected by a photodiode. Modes: multimode (step index, graded index) and single mode. Uses: backbones, fiber to the home, submarine cables. Merits: very high bandwidth, low loss, immune to EMI, secure. Demerits: costly and fragile.

3. Microwave (1 to 300 GHz): a focused beam between dish antennas in line of sight. Terrestrial links join towers tens of km apart (4 to 6 GHz and 21 to 23 GHz); satellite links relay through a transponder in orbit (uplink and downlink). Uses: long-haul telephony, mobile backhaul, TV distribution, VSAT. Merits: no cable over rivers and mountains, high data rate. Demerits: needs alignment and line of sight, rain fade, satellite delay.

TRANSMISSION MEDIA Guided media keep the signal on a cable; unguided media radiate it from an antenna into air or space. Transmission media Guided (wired) signal on a solid path Unguided (wireless) signal from an antenna Twisted pair UTP, STP telephone, LAN Coaxial cable thin, thick; RG-6 cable TV, CCTV Optical fiber single, multimode backbone, FTTH Radio waves 3 kHz to 1 GHz AM, FM, TV Microwaves 1 to 300 GHz terrestrial, satellite Infrared 300 GHz to 400 THz remotes, short links bounded: speed and security, limited by the cable unbounded: mobility and reach, open to anyone

One guided medium explained: twisted pair cable PIN 1/27

Asked once

2081 Baishakh · Q25 marksExplain any one of the guided transmission media with examples.

Twisted pair cable consists of two insulated copper conductors twisted around each other; an Ethernet cable holds four such pairs in one jacket. The twisting makes external noise couple equally into both wires, so it cancels at the receiver, and different twist rates on neighbouring pairs reduce crosstalk.

GUIDED MEDIA IN CROSS SECTION Copper carries current in twisted pairs or round a common axis; glass carries light in a core. Twisted pair (UTP) copper conductor insulation, colour coded jacket (STP adds a shield) one pair from the side: the twists cancel noise Coaxial cable inner copper conductor insulation (dielectric) braid: outer conductor, shield plastic jacket Optical fiber core: glass, 8 to 62.5 µm cladding: 125 µm buffer coating jacket (Kevlar inside)
  • UTP (unshielded): no shield; cheap, light, flexible; the usual LAN cable.
  • STP (shielded): a grounded foil or braid around the pairs; better noise immunity; costlier and stiffer.
  • Categories: Cat 3 (16 MHz, 10 Mbps), Cat 5e (100 MHz, 1 Gbps), Cat 6 (250 MHz, 1 Gbps), Cat 6A (500 MHz, 10 Gbps), with RJ-45 connectors.
  • Characteristics: an Ethernet segment reaches 100 m; analog lines need amplifiers every 5 to 6 km, digital lines repeaters every 2 to 3 km.
  • Examples: the telephone local loop and ADSL; 100BASE-TX and 1000BASE-T Ethernet in a college lab; Power over Ethernet for IP cameras.
  • Merits: cheapest, easy to install and extend. Demerits: susceptible to noise, short range, limited bandwidth, easy to tap.

Two guided media in detail: twisted pair and optical fiber PIN 1/27

Asked once

2074 Ashwin · Q26 marksExplain about any two guided transmission media in detail.

1. Twisted pair cable: two insulated copper wires twisted together (four pairs in an Ethernet cable); the twists cancel external noise and reduce crosstalk.

  • Types: UTP (unshielded: cheap, flexible, common in LANs) and STP (a grounded foil or braid shield: better noise immunity, costlier).
  • Categories: Cat 5e (1 Gbps), Cat 6 (250 MHz), Cat 6A (10 Gbps to 100 m), with RJ-45 connectors; Ethernet runs up to 100 m.
  • Uses: telephone local loop, DSL, LANs. Merits: cheap, easy to install. Demerits: noise, attenuation, short range, easy to tap.

2. Optical fiber: a glass core of higher refractive index inside a cladding of lower index, then a buffer and a jacket; light is guided by total internal reflection.

  • Modes: multimode step index and graded index (50 or 62.5 µm core, LED, short reach) and single mode (8 to 10 µm core, laser, tens of km).
  • Uses: backbones, fiber to the home, submarine links. Merits: very high bandwidth, low loss (about 0.2 dB/km at 1550 nm), immune to EMI, secure, light. Demerits: costly installation and splicing, fragile.
GUIDED MEDIA IN CROSS SECTION Copper carries current in twisted pairs or round a common axis; glass carries light in a core. Twisted pair (UTP) copper conductor insulation, colour coded jacket (STP adds a shield) one pair from the side: the twists cancel noise Coaxial cable inner copper conductor insulation (dielectric) braid: outer conductor, shield plastic jacket Optical fiber core: glass, 8 to 62.5 µm cladding: 125 µm buffer coating jacket (Kevlar inside)

Twisted pair, coaxial cable and optical fiber compared PIN 1/27

Asked once

2074 Chaitra · Q25 marksCompare among Twisted Pair, Coaxial cable and Fiber optic.

BasisTwisted pairCoaxial cableFiber optic
Signalelectricalelectricallight
Structuretwo insulated copper wires, twistedcentral conductor, insulation, braided shield, jacketglass core, cladding, buffer, jacket
Bandwidthlowmoderate, up to about 1 GHzvery high
Data rateup to 10 Gbps over 100 mup to a few Gbps10 Gbps a wavelength; terabits with WDM
Distance100 m (Ethernet)hundreds of metres to a few kmkm to tens of km
Noise immunitylowgoodimmune to EMI
Attenuationhighmoderatevery low
Securityeasy to tapharder to tapvery hard to tap
Costcheapestmoderatehighest
Installationeasiestmoderatedifficult, needs splicing
UsesLANs, telephone linescable TV, CCTVbackbones, fiber to the home

All three are guided media: fiber leads on every count except cost and ease of installation, where twisted pair leads.

GUIDED MEDIA IN CROSS SECTION Copper carries current in twisted pairs or round a common axis; glass carries light in a core. Twisted pair (UTP) copper conductor insulation, colour coded jacket (STP adds a shield) one pair from the side: the twists cancel noise Coaxial cable inner copper conductor insulation (dielectric) braid: outer conductor, shield plastic jacket Optical fiber core: glass, 8 to 62.5 µm cladding: 125 µm buffer coating jacket (Kevlar inside)

Types of twisted pair cable PIN 1/27

Asked once

2068 Baishakh · Q24 marksWhat are types of twisted pair cable?

Twisted pair cable (insulated copper pairs twisted to cancel noise) is classified three ways:

  1. By shielding: UTP (unshielded): no shield, cheap, flexible, used in most LANs; STP (shielded): a grounded foil or braid shield that cuts EMI and crosstalk, costlier and stiffer; variants F/UTP (foil over all pairs) and S/FTP (braid overall, foil on each pair).
  2. By category (TIA/EIA-568): Cat 3 (16 MHz, 10 Mbps), Cat 5 (100 MHz, 100 Mbps), Cat 5e (100 MHz, 1 Gbps), Cat 6 (250 MHz, 1 Gbps), Cat 6A (500 MHz, 10 Gbps), Cat 7 (600 MHz), Cat 8 (2000 MHz, 25 to 40 Gbps up to 30 m).
  3. By wiring at the RJ-45 ends: straight-through (the same pin order, T568B, at both ends: PC to switch), crossover (T568A at one end, T568B at the other: PC to PC, switch to switch), rollover (pins reversed: PC to a router's console port).

Block diagram of an optical fiber communication system, and its range PIN 1/27

Asked once

2082 Bhadra · Q22 marksDraw block diagram generic optical fiber (OF) communication system and its RF range.

AN OPTICAL FIBER COMMUNICATION SYSTEM Electrical to light at one end, light through glass, light to electrical at the other. Message source voice, video or data, electrical Electrical transmitter coder, modulator, driver Optical source LED or laser diode: current to light Destination the user gets the message Electrical receiver amplifier, equalizer, decoder Optical detector PIN or APD diode: light to current Repeater or optical amplifier light light Optical fiber cable connectors and splices; light at 850, 1310 or 1550 nm TRANSMITTER electrical in, light out CHANNEL light, weakened and spread RECEIVER light in, electrical out

The transmitter turns the electrical message into light (LED or laser); the fiber, with repeaters or optical amplifiers on long links, carries it; the receiver (PIN or avalanche photodiode, amplifier, decoder) turns it back into the message.

Range: near-infrared light at 850, 1310 and 1550 nm, about 190 to 355 THz, far above the radio frequency range (up to 300 GHz).

Line of sight propagation PIN 1/27

Asked once

2082 Bhadra · Q24 marksExplain line of sight (LOS) propagation modes.

Radio waves travel by three modes: ground wave (below 2 MHz, following the earth's curve), sky wave (2 to 30 MHz, bent back by the ionosphere) and line of sight (above 30 MHz).

HOW A RADIO WAVE TRAVELS The frequency decides the path: low hugs the ground, middle bounces off the ionosphere, high goes straight. Ground wave below 2 MHz AM medium wave, navigation earth Sky wave 2 to 30 MHz shortwave radio, amateur earth Line of sight above 30 MHz FM, TV, microwave, satellite earth follows the curve of the earth ionosphere long range, low power antennas must see each other the earth’s curve limits the range: tall towers reach further one antenna: d = 4.12 √h km (h in metres, with refraction)

In line of sight (space wave) propagation very high frequency signals travel in straight lines, so the transmitting and receiving antennas must see each other, and the earth's curvature limits the range. The signal arrives two ways:

  • Direct wave: straight from antenna to antenna.
  • Ground-reflected wave: bounced off the ground; it adds to or cancels the direct wave (multipath fading).

Refraction bends radio waves slightly, so radio line of sight exceeds optical: d=3.57Kh km, with K = 4/3 and h in metres. Uses: FM, TV, microwave links, mobile phones, satellites.

Multiplexing and its importance PIN 1/27

Asked once

2080 Baishakh · Q21+2 marksWhat is multiplexing? What is its importance in communication?

Multiplexing is the technique of sending several signals over one shared link at the same time: a multiplexer (MUX) combines n input channels into one link, and a demultiplexer (DEMUX) separates them at the far end.

Importance:

  • Efficient use of bandwidth: a link's capacity is far larger than one user needs.
  • Lower cost: one cable or trunk instead of n, with less installation and maintenance.
  • Enables large networks: telephone trunks, radio and TV broadcasting, cable TV, mobile networks and fiber backbones.
  • Scalability: more users are added without new lines.

Example: one E1 trunk carries 30 telephone calls on one link.

Switching compared with multiplexing PIN 1/27

Asked once

2073 Shrawan · Q22 marksCompare switching with multiplexing.

BasisSwitchingMultiplexing
Purposeconnects a sender to a receiver across the networkshares one link among many signals
Whereat nodes inside the networkat the two ends of a link
Deviceswitch, router, exchangeMUX and DEMUX
Typescircuit, message, packetFDM, WDM, TDM, CDM
Exampleexchange routing a callE1 trunk carrying 30 calls

Data switching and its types, with practical examples PIN 1/27

Asked once

2070 Chaitra · Q28 marksWhat do you mean by data switching? Explain about various types of switching with practical implementation example.

Data switching is the forwarding of data from a sender to a receiver through intermediate switching nodes, each passing what arrives on an input port to the output port that leads toward the destination. It avoids a dedicated link between every pair of devices (a mesh of n devices needs n(n−1)/2 links).

CIRCUIT, MESSAGE AND PACKET SWITCHING One message from A to D through switches B and C; time runs downward in each panel. Circuit switching A B C D Message switching A B C D Packet switching A B C D call request call accepted data, one stream release whole message stored at each node arrives last 1 1 1 2 2 2 3 3 3 packets pipelined arrives first setup first, then one stream: no stop at B or C B and C store the whole message before passing it on packets overlap on the links; no setup, no reservation

1. Circuit switching: a dedicated path is reserved end to end before transfer, in three phases: setup, data transfer, teardown. Bandwidth is guaranteed and the delay constant, but the circuit stays idle during silences. Practical example: a landline call through the PSTN; ISDN B channels.

2. Message switching: the whole message, with its destination address, is stored at each node and forwarded when the next link is free (store and forward); no setup, but large storage and long delays. Practical example: the old telegraph and telex networks.

3. Packet switching: the message is split into packets with headers; nodes store and forward them, sharing links on demand, and packets pipeline across hops.

  • Datagram: connectionless; each packet carries the full address and is routed independently, possibly out of order. Practical example: IP routers in the internet.
  • Virtual circuit: a logical path is set up first; packets carry a short VCI and follow it in order; PVC or SVC. Practical example: X.25, Frame Relay, ATM, MPLS in ISP backbones.

Circuit switching suits constant-rate real-time voice; packet switching suits bursty data and carries almost all traffic today.

Switching in modern computer networks PIN 1/27

Asked once

2079 Bhadra · Q24 marksExplain switching technique used in modern computer networks.

Modern computer networks use packet switching: data is split into packets with headers, and each node stores, checks and forwards them (store and forward), sharing links statistically among all users.

  • Datagram switching: the internet's IP routers forward every packet independently by its destination address using routing tables; no setup, connectionless, robust to failures.
  • Virtual circuit switching: MPLS in ISP backbones, and earlier Frame Relay and ATM, set up a path and forward by short labels (VCIs), giving traffic engineering and QoS.
  • Frame switching in LANs: Ethernet switches forward frames by MAC address, store-and-forward or cut-through.
DATAGRAM AND VIRTUAL CIRCUIT NETWORKS The same four routers used two ways: every packet on its own, or every packet on one path set up first. Datagram network connectionless: each packet routed on its own R1 R2 R3 R4 A B 1 3 2 4 arrive: 2, 1, 4, 3 PACKET HEADER to B from A seq 3 data no setup; full address in every packet routers keep no state per connection packets may take different paths, out of order example: IP, the Internet Virtual circuit network connection oriented: set up, transfer, tear down R1 R2 R3 R4 A B VCI 12 VCI 25 VCI 7 VCI 31 1 2 arrive: 1, 2, 3, 4 R2’S VC TABLE from R1 in port 25 in VCI to R4 out port 7 out VCI a short VCI, swapped at every hop every packet on one path, in order a packet carries only the VCI and data examples: X.25, Frame Relay, ATM, MPLS

Circuit switching survives only in the legacy telephone network; voice now travels as VoIP and VoLTE packets.

Why circuit switching suits real-time communication PIN 1/27

Asked once

2080 Bhadra · Q23 marksCircuit switching is suitable for real-time communication", give your reasons.

Circuit switching suits real-time communication (voice, live video) because:

  1. Dedicated bandwidth: a fixed channel is reserved for the whole call, so no other traffic competes and no congestion arises during the call.
  2. Constant, low delay: no store-and-forward and no queuing at switches; data flows at propagation speed, with no jitter.
  3. In-order delivery: all data follows one fixed path, so nothing is reordered or reassembled.
  4. No per-packet overhead: no headers to process, no loss from buffer overflow.
  5. Setup is paid once, before the conversation starts.

Example: a telephone call on the PSTN.

The telephone defined PIN 1/27

Asked once

2068 Chaitra · Q32 marksWhat is a telephone?

A telephone is an instrument that converts speech (sound waves) into an electrical signal for transmission over a line, and converts the received signal back into sound, so that two people can talk at a distance (Alexander Graham Bell, patented 1876). Its parts: transmitter (microphone), receiver (earpiece), hook switch, dialler (rotary pulses or DTMF tones), ringer, and a hybrid circuit that couples the two-wire line to the handset.

The E1 telephone hierarchy PIN 1/27

Asked once

2073 Shrawan · Q24 marksExplain the E1 Telephone hierarchy system.

E1 is the ITU-T (European) digital carrier that time-division multiplexes 32 channels of 64 kbps into one 2.048 Mbps stream.

  • Basic channel (E0): voice sampled 8000 times a second at 8 bits a sample: 64 kbps.
  • Frame: 32 time slots of 8 bits (256 bits) every 125 µs: 256×8000 = 2.048 Mbps.
  • TS0: frame synchronization and alarms; TS16: signalling; TS1 to TS15 and TS17 to TS31: 30 voice channels.
THE E1 FRAME AND THE E HIERARCHY ITU-T G.704: 32 slots of 8 bits every 125 µs; each level carries four of the one below, plus overhead. One E1 frame: 32 time slots × 8 bits = 256 bits, every 125 µs 0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 TS1 to TS15: voice channels 1 to 15 TS17 to TS31: voice channels 16 to 30 TS0: frame alignment, alarms TS16: signalling 256 bits × 8000 frames a second = 2.048 Mbps; each slot is a 64 kbps channel E0 64 kbps 1 channel ×32 E1 2.048 Mbps 30 channels ×4 E2 8.448 Mbps 120 channels ×4 E3 34.368 Mbps 480 channels ×4 E4 139.264 Mbps 1920 channels Each step: four streams plus framing and justification bits, so E2 = 4 × 2.048 + 0.256 Mbps North America and Japan use T1: 24 × 8 + 1 = 193 bits a frame × 8000 = 1.544 Mbps
LevelRateVoice channels
E12.048 Mbps30
E2 (4 E1)8.448 Mbps120
E3 (4 E2)34.368 Mbps480
E4 (4 E3)139.264 Mbps1920

Each level adds framing and justification bits. E1 is used in Europe and most of the world; North America uses T1 (24 channels, 1.544 Mbps).

3Data link layer

Functions of the data link layer HOT 5/27

Asked 5 times

2082 Baishakh · Q22 marksWhat are the functions of data link layer?

2074 Chaitra · Q34 marksWhat is the main functionality of data link layer?

2072 Kartik · Q33 marksWhat are the functions of data-link layer?

2071 Shrawan · Q33 marksWhat are the major functions of data link layer?

2066 Poush · Q45 marksList the functions of Data Link Control Layer.

The data link layer (layer 2 of the OSI model) delivers frames reliably from one node to the next over a single link. Its functions:

  1. Framing: divides the bit stream from the physical layer into frames and delimits the start and end of each frame (character count, byte stuffing, bit stuffing).
  2. Physical addressing: puts the MAC addresses of the sender and the receiver in the frame header.
  3. Flow control: prevents a fast sender from overrunning a slow receiver (stop and wait, sliding window).
  4. Error control: detects damaged frames with a CRC in the trailer and recovers damaged or lost frames by retransmission (ARQ), using acknowledgements, timers and sequence numbers.
  5. Access control: on a shared medium, decides which station may transmit next (CSMA/CD, token passing).
  6. Service interface and link management: gives the network layer unacknowledged connectionless, acknowledged connectionless or acknowledged connection-oriented service, and sets up and releases connections.
THE DATA LINK LAYER AND ITS TWO SUBLAYERS IEEE 802 splits layer 2: one LLC on top for every LAN, and a different MAC (with its own physical layer) for each kind of LAN. Network layer: IP packets come down to the data link layer LAYER 3 LLC sublayer, IEEE 802.2: the same for every LAN interface to the network layer, protocol multiplexing (DSAP, SSAP), optional flow and error control 802.3 Ethernet CSMA/CD, bus or switch Physical coax, twisted pair, fiber 802.4 Token bus token on a logical ring Physical broadband coaxial cable 802.5 Token ring token on a physical ring Physical shielded twisted pair 802.11 Wireless LAN CSMA/CA, RTS and CTS Physical radio: 2.4, 5 and 6 GHz LAYER 2 LLC MAC LAYER 1 MAC sublayer jobs: framing for its own LAN, 48-bit MAC addresses, channel access (who sends next), error detection with the FCS. IEEE 802.1 sits over them all: bridging, VLANs (802.1Q) and management.

In IEEE 802 LANs these jobs are shared by the LLC sublayer (interface to the network layer, flow and error control) and the MAC sublayer (framing, addressing, medium access, error detection).

Framing and the framing methods HOT 5/27

Asked 5 times

2075 Chaitra · Q36 marksDescribe the various framing techniques at data link layer.

2072 Chaitra · Q3Briefly explain different types of Data Link Layer framing mechanisms.

2071 Shrawan · Q35 marksExplain about framing in detail.

2070 Ashad · Q36 marksDiscuss different farming approaches used in data link layer.

2069 Chaitra · Q38 marksExplain different types of Data link layer framing mechanisms.

Framing is the division of the bit stream from the physical layer into frames, with the start and the end of each frame delimited, so that the receiver can find frame boundaries and check each frame separately. A frame has a header (addresses, control), a payload (data) and a trailer (error check). The framing methods are:

FRAMING: WHERE DOES A FRAME START AND END? Character count, byte stuffing and bit stuffing (physical layer coding violations need no drawing). 1. CHARACTER COUNT: THE FIRST BYTE OF EACH FRAME GIVES ITS LENGTH Sent 5 1 2 3 4 5 6 7 8 9 8 0 1 2 3 4 5 6 8 7 8 9 0 1 2 3 Frame 1 Frame 2 Frame 3 Frame 4 Received one count garbled 5 1 2 3 4 7 6 7 8 9 8 0 1 2 3 4 5 6 8 7 8 9 0 1 2 3 ok wrong Count 5 garbled to 7: every later boundary is now wrong. 2. BYTE STUFFING: FLAG AT BOTH ENDS; ESC BEFORE ANY FLAG OR ESC IN THE DATA FLAG Header Payload (the data bytes) Trailer FLAG Data A FLAG B A ESC FLAG B A ESC B A ESC ESC B The added ESC (pink) is removed by the receiver; a lone FLAG can only be a frame boundary. PPP uses this. 3. BIT STUFFING: FLAG 01111110; A 0 IS STUFFED AFTER EVERY FIVE 1s OF DATA Data 0 1 0 0 1 1 1 1 1 1 0 1 1 1 1 1 0 Sent 0 1 1 1 1 1 1 0 0 1 0 0 1 1 1 1 1 0 1 0 1 1 1 1 1 0 0 0 1 1 1 1 1 1 0 flag flag stuffed 0s in pink: the receiver deletes them
  1. Character count: a field in the header gives the number of characters (bytes) in the frame, and the receiver counts that many to find the end. If the count is corrupted in transit, the receiver loses synchronisation and cannot find the start of the next frame, so it is rarely used alone.
  2. Flag bytes with byte stuffing: each frame begins and ends with a special FLAG byte. If the FLAG pattern appears in the data, the sender inserts an escape byte (ESC) before it, and an ESC in the data is sent as ESC ESC; the receiver removes the escapes. Example: A FLAG B is sent as A ESC FLAG B. Used in PPP (FLAG 0x7E, ESC 0x7D); it depends on 8-bit characters.
  3. Starting and ending flags with bit stuffing: each frame begins and ends with the flag 01111110. After every five consecutive 1s in the data, the sender stuffs a 0; the receiver deletes the 0 that follows five 1s. Example: 01001111110111110 is sent as 01111110 0100111110101111100 01111110. It works with any number of bits per character; used in HDLC.
  4. Physical layer coding violations: possible where the line code has redundancy. In Manchester coding each bit is high-low or low-high, so the unused high-high and low-low patterns delimit frames; 4B/5B uses spare code groups (J, K) as delimiters.

Many protocols combine a count with flags for extra safety.

Why channel access control is essential PIN 3/27

Asked 3 times

2073 Shrawan · Q32 marksWhat is its significance in data link layer?

2068 Chaitra · Q43 marksWhy channel access mechanism is important in computer networking?

2067 Ashad · Q52 marksWhy access control of channel is essential?

On a broadcast link many stations share one channel; if two transmit at the same time, their signals collide and both frames are lost. A channel access mechanism is therefore essential:

  • It avoids or resolves collisions, so bandwidth is not wasted on garbled frames.
  • It uses the channel efficiently, keeping it busy with useful frames.
  • It gives fair access to every station, so none monopolises the channel.
  • It bounds delay and supports priority (token passing), which real-time traffic needs.
  • It lets many stations share one medium at low cost.

So medium access control is a core function of the data link layer, performed by its MAC sublayer.

ALOHA PIN 3/27

Asked 3 times

2079 Bhadra · Q104 marksa) ALOHA

2075 Ashwin · Q104 marksiii) ALOHA

2070 Ashad · Q104 marksa) ALOHA system

ALOHA is the earliest random access protocol (University of Hawaii, 1971): a station transmits whenever it has data, waits for an acknowledgement, and if none arrives assumes a collision and retransmits after a random backoff time.

  • Pure ALOHA: frames are sent at any time; a frame collides with any frame started within one frame time T before or after it, so the vulnerable time is 2T. Throughput S=Ge−2G, at most 18.4 % at G=0.5.
  • Slotted ALOHA: time is divided into slots of length T and frames start only at slot boundaries, so the vulnerable time is T. Throughput S=Ge−G, at most 36.8 % at G=1.
ALOHA: THE VULNERABLE TIME T = the time to send one frame. No other frame may start inside the shaded interval. PURE ALOHA: SEND AT ANY TIME; VULNERABLE TIME 2T vulnerable time: 2T B starts before t A's frame C starts before t + T t - T t t + T B overlaps the head of A, C overlaps its tail: all of them are lost. SLOTTED ALOHA: SEND ONLY AT A SLOT START; VULNERABLE TIME T vulnerable: T A's frame B, same slot: collides C, next slot: safe slot boundaries every T

Here G is the mean number of frames offered per frame time. ALOHA is simple but efficient only at light load; CSMA improves on it by sensing the channel first.

Virtual LAN (VLAN) PIN 3/27

Asked 3 times

2082 Bhadra · Q104 marksd) vLAN

2080 Baishakh · Q104 marksa) VLAN

2068 Baishakh · Q32 marksWhat is a virtual LAN?

A VLAN (virtual LAN) is a logical group of stations on one or more switches that forms a separate broadcast domain, as if it were its own LAN, defined by configuration rather than by physical wiring.

  • Membership: by switch port (the most common), MAC address, IP address or application.
  • Tagging (IEEE 802.1Q): on a trunk link carrying several VLANs, a 4-byte tag is inserted after the source address: TPID 0x8100, 3-bit priority, 1-bit DEI and a 12-bit VLAN ID (1 to 4094). Access ports carry untagged frames of one VLAN.
  • Inter-VLAN routing: traffic between VLANs passes through a router (router on a stick) or a layer 3 switch.
  • Advantages: smaller broadcast domains, better security by separating groups, users grouped by function rather than location, moves without rewiring, and lower cost.
TWO VLANS, STUDENT AND DEPARTMENT, ON ONE SWITCH One broadcast domain and one subnet per VLAN; the router (on a stick) routes between them over one 802.1Q trunk. Router R1 G0/0: trunk port G0/0.10: 192.168.10.1/24 (VLAN 10) G0/0.20: 192.168.20.1/24 (VLAN 20) 802.1Q trunk: G0/0 to S1 Gi0/1, carries both VLANs Switch S1 Fa0/1 to Fa0/12: VLAN 10 Fa0/13 to Fa0/24: VLAN 20 Student PC1 192.168.10.11 Student PC2 192.168.10.12 Dept PC3 192.168.20.11 Dept PC4 192.168.20.12 VLAN 10 STUDENT: 192.168.10.0/24, gateway .1 VLAN 20 DEPARTMENT: 192.168.20.0/24, gateway .1 ON THE TRUNK, EACH FRAME CARRIES A 4-BYTE 802.1Q TAG DA 6 SA 6 TPID 0x8100 2 PCP 3 bits DEI 1 bit VLAN ID 12 bits Type 2 Data 42 to 1500 FCS 4 the tag: 4 bytes, added on the trunk, removed at the access port

Piggybacking PIN 2/27

Asked 2 times

2081 Bhadra · Q31 markWhat is piggy-backing?

2075 Ashwin · Q33 marksWhat is piggybacking?

Piggybacking is the technique of carrying the acknowledgement for received frames in an outgoing data frame instead of sending a separate acknowledgement frame. In two-way communication each data frame holds two numbers: its own sequence number and an acknowledgement number, the next frame expected from the other side.

  • Advantages: better use of the bandwidth (fewer frames, headers and trailers), less processing and fewer interrupts at both ends.
  • Drawback: an acknowledgement may be held up waiting for outgoing data, so an ack timer sends a separate ACK if no data frame is ready in time.

Example: the N(R) field of an HDLC I-frame, and TCP's acknowledgement number on data segments.

Flow control at the data link layer PIN 2/27

Asked 2 times

2075 Ashwin · Q104 marksi) Flow control in D22

2074 Ashwin · Q104 marksd) DLL Flow Control Mechanisms

Flow control at the data link layer is the set of procedures that limits how much data the sender may transmit before it receives an acknowledgement, so that a fast sender does not overflow the buffer of a slow receiver. Two mechanisms:

  • Stop and wait: the sender sends one frame and waits for its ACK before sending the next. Simple, but the link idles for a round trip after each frame: U=1/(1+2a), with a=Tprop/Tframe.
  • Sliding window: the sender may send up to W frames, numbered modulo 2k, before waiting; each ACK names the next frame expected and slides the window forward. U=W/(1+2a), or 1 when W≥1+2a.
THE SLIDING WINDOW 3-bit sequence numbers (0 to 7, then 0 again); send window 7 frames for go-back-N. Sender 0 1 2 3 4 5 6 7 0 1 2 3 4 5 6 7 SEND WINDOW: 7 FRAMES left edge moves right when an ACK arrives right edge follows: new frames may be sent sent and acknowledged sent, waiting for an ACK may be sent now outside the window: not yet Receiver 0 1 2 3 4 5 6 7 0 1 2 3 4 5 6 7 go-back-N receive window: 1 frame, the next in order (frame 2 only) selective repeat: up to 4 frames (2, 3, 4, 5), half of the 8 numbers

With two-way traffic the ACKs are piggybacked on data frames, and with retransmission added the sliding window becomes go-back-N or selective repeat ARQ.

HDLC PIN 2/27

Asked 2 times

2078 Bhadra · Q104 marksc) HDLC

2073 Shrawan · Q104 marksi) HDLC

HDLC (High-level Data Link Control) is a bit-oriented ISO protocol for point-to-point and multipoint links, using bit stuffing and sliding window flow and error control.

  • Stations: primary (sends commands), secondary (sends responses), combined (both).
  • Configurations: unbalanced (one primary, one or more secondaries) and balanced (two combined stations).
  • Modes: NRM (a secondary sends only when polled), ARM (a secondary may send without permission), ABM (combined stations, either may send at any time).
  • Frame: flag 01111110, address, control (8 or 16 bits), information, FCS (16 or 32-bit CRC), flag.
  • Frame types: I-frames carry data with N(S) and a piggybacked N(R); S-frames carry flow and error control (RR, RNR, REJ, SREJ); U-frames carry link management (SNRM, SABM, DISC, UA).
THE HDLC FRAME AND ITS THREE CONTROL FIELDS Bit-oriented: the flag 01111110 marks both ends, and bit stuffing keeps it out of the data. Flag 01111110 8 bits Address station 8 or more Control I, S or U 8 or 16 Information network layer data variable FCS CRC-16 or CRC-32 16 or 32 Flag 01111110 8 bits 1 2 3 4 5 6 7 8 I-frame information 0 N(S) P/F N(R) S-frame supervisory 1 0 S S P/F N(R) U-frame unnumbered 1 1 M M P/F M M M S BITS IN AN S-FRAME 00 RR: receive ready 01 REJ: reject (go-back-N) 10 RNR: receive not ready 11 SREJ: selective reject U-FRAME COMMANDS SNRM, SABM, DISC, UA, FRMR N(S): this frame's number; N(R): the next frame expected (a piggybacked ACK); P/F: poll from a primary, final from a secondary.

The MAC sublayer PIN 2/27

Asked 2 times

2081 Baishakh · Q104 marksa) MAC sublayer

2073 Shrawan · Q32 marksWhat do you understand by Media Access Control?

The MAC (medium access control) sublayer is the lower sublayer of the data link layer that controls access to a shared (broadcast) medium: it decides which station may transmit next when several stations compete for one channel.

  • Functions: builds frames for its LAN, adds 48-bit MAC (physical) addresses, runs the multiple access protocol, and detects errors with the FCS.
  • Protocols: random access (ALOHA, CSMA, CSMA/CD in Ethernet, CSMA/CA in Wi-Fi), controlled access (reservation, polling, token passing in token bus and token ring) and channelization (FDMA, TDMA, CDMA).
  • Standards: IEEE 802.3, 802.4, 802.5 and 802.11 each define their own MAC under the common LLC (802.2).
MULTIPLE ACCESS PROTOCOLS Three ways to share one broadcast channel among many stations. Multiple access protocols Random access contend; nobody controls ALOHA CSMA CSMA/CD CSMA/CA USED IN Ethernet (CSMA/CD), Wi-Fi (CSMA/CA) Controlled access stations take turns Reservation Polling Token passing USED IN token bus, token ring, FDDI Channelization the channel is divided FDMA TDMA CDMA USED IN GSM (FDMA with TDMA), 3G (CDMA) Random access wins at light load; controlled access and channelization guarantee each station its share at heavy load.

Without it, simultaneous transmissions would collide and the channel would be wasted.

Multiple access protocols PIN 2/27

Asked 2 times

2075 Chaitra · Q32 marksWhat are multiple access protocols?

2071 Chaitra · Q32 marksWhat are multiple access protocols?

Multiple access protocols are the rules by which many stations sharing one broadcast channel decide who transmits and when, so as to avoid or resolve collisions. They are of three types:

  • Random access: ALOHA, CSMA, CSMA/CD, CSMA/CA.
  • Controlled access: reservation, polling, token passing.
  • Channelization: FDMA, TDMA, CDMA.
MULTIPLE ACCESS PROTOCOLS Three ways to share one broadcast channel among many stations. Multiple access protocols Random access contend; nobody controls ALOHA CSMA CSMA/CD CSMA/CA USED IN Ethernet (CSMA/CD), Wi-Fi (CSMA/CA) Controlled access stations take turns Reservation Polling Token passing USED IN token bus, token ring, FDDI Channelization the channel is divided FDMA TDMA CDMA USED IN GSM (FDMA with TDMA), 3G (CDMA) Random access wins at light load; controlled access and channelization guarantee each station its share at heavy load.

CSMA against CSMA/CD PIN 2/27

Asked 2 times

2078 Bhadra · Q34 marksHow carrier sense multiple access with collision detection (CSMA/CD) is better than CSMA?

2070 Ashad · Q52 marksDifferentiate it with CSMA-CD.

Both sense the carrier before transmitting, but CSMA/CD also listens while transmitting and reacts to a collision at once.

PointCSMACSMA/CD
Listeningbefore transmitting onlybefore and during transmission
On a collisionkeeps sending the whole damaged framestops at once and sends a short jam signal
Time wasted per collisiona whole frame timeabout two propagation delays plus the jam
Retransmissionby the persistence methodbinary exponential backoff, up to 16 attempts
Requirementscarrier sensingalso listening while sending, and a minimum frame size
Throughput and delaylower throughput, more delayhigher throughput, less delay

So CSMA/CD wastes far less channel time per collision, which is why classic Ethernet uses it.

IEEE 802.4 token bus PIN 2/27

Asked 2 times

2081 Bhadra · Q104 marksa) 802.4 Token Bus

2076 Ashwin · Q104 marksb) 803 Token Bus

Token bus (IEEE 802.4) is a LAN whose stations are connected to a physical bus but pass a token among themselves in a logical ring; only the token holder may transmit.

  • Logical ring: each station knows its successor and predecessor; the token passes in descending order of address, and the lowest address passes it back to the highest.
  • Operation: the token holder sends frames until its token holding time expires, then passes the token to its successor.
  • Priority: four access classes, 0, 2, 4 and 6.
  • Ring maintenance: claim token (start-up, lost token), solicit successor (new stations join), set successor (a station leaves or fails).
  • Physical layer: 75-ohm broadband coaxial cable at 1, 5 or 10 Mbps.
TOKEN BUS: A PHYSICAL BUS, A LOGICAL RING IEEE 802.4: the token goes to the next lower address, whatever the stations' places on the cable. PHYSICAL: ONE BUS CABLE terminator terminator station 90 station 45 station 112 station 70 station 20 Stations sit anywhere on the cable; a frame on the bus reaches all of them at once. LOGICAL: THE ORDER THE TOKEN FOLLOWS 112 90 70 45 20 token goes to the next lower address The lowest, 20, passes back to 112: the circle closes.

Collision-free with a bounded delay, it was used in factory automation (MAP).

FDDI and its features PIN 2/27

Asked 2 times

2074 Chaitra · Q104 marksii) FDDI

2072 Chaitra · Q3List the features of FDDI.

FDDI (Fiber Distributed Data Interface) is a 100 Mbps token passing LAN and backbone standard (ANSI X3T9.5) using optical fiber in two counter-rotating rings. Its features:

  • 100 Mbps over multimode fiber (copper version CDDI), with 4B/5B coding at 125 Mbaud.
  • Dual counter-rotating rings: the primary carries data, the secondary stands by for faults.
  • Large coverage: up to 1000 physical connections (about 500 dual attachment stations) on up to 200 km of fiber, with up to 2 km between stations.
  • Timed token protocol: guaranteed bandwidth for synchronous traffic and the rest for asynchronous traffic; early token release.
  • Frames of up to 4500 bytes with a 32-bit CRC.
  • Station types: dual attachment stations (DAS) and single attachment stations (SAS) through concentrators.
  • Fault tolerance: the rings wrap on a fault; optical bypass switches; dual homing.
FDDI: DUAL COUNTER-ROTATING RINGS, AND THE WRAP AFTER A FAULT 100 Mbps token ring on fiber; the secondary ring stands by until a link or a station fails. NORMAL: PRIMARY CARRIES DATA, SECONDARY STANDS BY A DAS B DAS C DAS D DAS primary (outer, clockwise) secondary (inner, anticlockwise) FIBER CUT BETWEEN A AND B: BOTH WRAP wrap wrap A DAS B DAS C DAS D DAS one ring of twice the length: B, C, D, A on the primary, then back A, D, C, B on the secondary A failed station is bypassed the same way: its two neighbours wrap.

Services provided by the data link layer PIN 1/27

Asked once

2066 Bhadra · Q2a2 marksWhat are the services provided by data link layer?

The data link layer provides three kinds of service to the network layer:

  • Unacknowledged connectionless: frames are sent independently with no acknowledgement; a lost frame is not recovered at this layer. Used on low-error links such as Ethernet.
  • Acknowledged connectionless: no connection, but each frame is acknowledged and resent if no acknowledgement arrives in time. Used on unreliable links such as Wi-Fi.
  • Acknowledged connection-oriented: a connection is established, numbered frames are delivered exactly once and in order, and the connection is released (HDLC).

Design issues of the data link layer PIN 1/27

Asked once

2075 Ashwin · Q33 marksState the various design issues for the data link layer.

The design issues of the data link layer are:

  • Service to the network layer: whether to offer unacknowledged connectionless, acknowledged connectionless or acknowledged connection-oriented service.
  • Framing: breaking the bit stream into frames and finding the frame boundaries.
  • Error control: detecting errors (CRC) and recovering lost or damaged frames with acknowledgements, timers and sequence numbers.
  • Flow control: keeping a fast sender from swamping a slow receiver.
  • Medium access and addressing: on broadcast links, deciding who may transmit and identifying stations by MAC address.

Functions of the LLC and MAC sublayers PIN 1/27

Asked once

2070 Ashad · Q32+2 marksWhat are the functions of LLC and MAC sub-layer?

IEEE 802 divides the data link layer into two sublayers.

LLC (logical link control, IEEE 802.2), the upper sublayer:

  • gives one interface to the network layer for every type of LAN;
  • multiplexes several network protocols over one link using service access points (DSAP, SSAP);
  • provides flow control and error control (sequencing, acknowledgements) when needed;
  • offers unacknowledged connectionless (type 1), connection-oriented (type 2) and acknowledged connectionless (type 3) service.

MAC (medium access control), the lower sublayer:

  • builds the frame in the format of its own LAN;
  • adds 48-bit MAC (physical) addresses;
  • controls access to the shared medium: CSMA/CD (802.3), token passing (802.4, 802.5), CSMA/CA (802.11);
  • detects errors with the FCS (CRC) in the trailer.
THE DATA LINK LAYER AND ITS TWO SUBLAYERS IEEE 802 splits layer 2: one LLC on top for every LAN, and a different MAC (with its own physical layer) for each kind of LAN. Network layer: IP packets come down to the data link layer LAYER 3 LLC sublayer, IEEE 802.2: the same for every LAN interface to the network layer, protocol multiplexing (DSAP, SSAP), optional flow and error control 802.3 Ethernet CSMA/CD, bus or switch Physical coax, twisted pair, fiber 802.4 Token bus token on a logical ring Physical broadband coaxial cable 802.5 Token ring token on a physical ring Physical shielded twisted pair 802.11 Wireless LAN CSMA/CA, RTS and CTS Physical radio: 2.4, 5 and 6 GHz LAYER 2 LLC MAC LAYER 1 MAC sublayer jobs: framing for its own LAN, 48-bit MAC addresses, channel access (who sends next), error detection with the FCS. IEEE 802.1 sits over them all: bridging, VLANs (802.1Q) and management.

Framing with bit stuffing PIN 1/27

Asked once

2081 Bhadra · Q104 marksb) Framing with bit stuffing

Framing with bit stuffing is a bit-oriented framing method in which every frame begins and ends with the flag pattern 01111110.

  • Stuffing at the sender: whenever the data contains five consecutive 1s, the sender inserts (stuffs) a 0 after them, so six 1s, the flag pattern, never appear inside the data.
  • Destuffing at the receiver: after five consecutive 1s, a following 0 is removed; a 1 followed by 0 is the flag, the end of the frame.
  • Transparency: any bit pattern can be carried, and a frame need not be a whole number of bytes.
  • Used in: HDLC and its family (LAPB, LAPD).

Example: the data 01001111110111110 becomes 0100111110101111100 (two 0s stuffed), and the frame sent is 01111110 0100111110101111100 01111110.

FRAMING: WHERE DOES A FRAME START AND END? Character count, byte stuffing and bit stuffing (physical layer coding violations need no drawing). 1. CHARACTER COUNT: THE FIRST BYTE OF EACH FRAME GIVES ITS LENGTH Sent 5 1 2 3 4 5 6 7 8 9 8 0 1 2 3 4 5 6 8 7 8 9 0 1 2 3 Frame 1 Frame 2 Frame 3 Frame 4 Received one count garbled 5 1 2 3 4 7 6 7 8 9 8 0 1 2 3 4 5 6 8 7 8 9 0 1 2 3 ok wrong Count 5 garbled to 7: every later boundary is now wrong. 2. BYTE STUFFING: FLAG AT BOTH ENDS; ESC BEFORE ANY FLAG OR ESC IN THE DATA FLAG Header Payload (the data bytes) Trailer FLAG Data A FLAG B A ESC FLAG B A ESC B A ESC ESC B The added ESC (pink) is removed by the receiver; a lone FLAG can only be a frame boundary. PPP uses this. 3. BIT STUFFING: FLAG 01111110; A 0 IS STUFFED AFTER EVERY FIVE 1s OF DATA Data 0 1 0 0 1 1 1 1 1 1 0 1 1 1 1 1 0 Sent 0 1 1 1 1 1 1 0 0 1 0 0 1 1 1 1 1 0 1 0 1 1 1 1 1 0 0 0 1 1 1 1 1 1 0 flag flag stuffed 0s in pink: the receiver deletes them

One method of framing and one of flow control PIN 1/27

Asked once

2066 Bhadra · Q2a3+3 marksExplain any one methods of framing and flow control.

Framing method: bit stuffing. Each frame starts and ends with the flag 01111110. The sender inserts a 0 after every five consecutive 1s in the data, so the flag never appears inside a frame, and the receiver removes the 0 after every five 1s. For example, the data 01001111110111110 is sent as 01111110 0100111110101111100 01111110. It works with any number of bits per character and is used in HDLC.

Flow control method: stop and wait. Flow control prevents a fast sender from overrunning a slow receiver.

  1. The sender transmits one frame and starts a timer.
  2. The receiver accepts the frame and returns an acknowledgement (ACK) when ready for the next.
  3. The sender transmits the next frame only after the ACK arrives.
  4. If the timer expires without an ACK, the frame is sent again; frames are numbered 0 and 1, so the receiver discards duplicates.
STOP AND WAIT: ONE FRAME, THEN WAIT FOR ITS ACK Frames carry a 1-bit sequence number (0, 1, 0, ...); an ACK names the next frame expected. NORMAL OPERATION Sender Receiver Frame 0 ACK 1 Frame 1 ACK 0 Frame 0 (the next one) waits one round trip LOST FRAME, THEN LOST ACK: THE TIMER RECOVERS BOTH Sender Receiver Frame 0 lost timeout Frame 0 again delivered ACK 1 lost timeout Frame 0 again duplicate: discard, ACK again ACK 1 Frame 1

It is simple and never overruns the receiver, but the link idles for a round trip after each frame: efficiency U=1/(1+2a), where a=Tprop/Tframe.

Error detection against error correction PIN 1/27

Asked once

2070 Chaitra · Q35 marksWhat is the difference between Error Correcting and Error detection process?

Error detection only finds out whether a received frame contains errors; error correction finds which bits are wrong and repairs them at the receiver.

PointError detectionError correction
Purposeto know that an error occurredto locate the wrong bits and fix them
Redundant bitsfew (one parity bit, a 16 or 32-bit CRC)many (3 check bits for 4 data bits in Hamming (7,4))
Action on an errordiscard the frame; the sender retransmits (ARQ, backward error correction)the receiver corrects it itself (forward error correction, FEC)
Hamming distance neededdmin≥s+1 to detect s errorsdmin≥2t+1 to correct t errors
Return channelneeded, for retransmissionnot needed
Techniquesparity, checksum, CRCHamming code, Reed-Solomon, convolutional codes
Suited tolow-error wired linksnoisy or long-delay links: satellite, wireless, storage

Example: an even parity bit on 1001101 detects one flipped bit but cannot tell which; the Hamming (7,4) code computes a syndrome that gives the position of the wrong bit, which is then flipped back.

Hamming distance PIN 1/27

Asked once

2082 Baishakh · Q31 markWhat is hamming distance?

The Hamming distance between two codewords of equal length is the number of bit positions in which they differ, found by XORing them and counting the 1s. Example: 10101 XOR 11110 = 01011, so the distance is 3. The smallest distance between any two valid codewords of a code is its minimum distance dmin.

Using the Hamming distance in error control PIN 1/27

Asked once

2082 Baishakh · Q32 marksHow do you apply it in data link layer error control mechanism?

The minimum Hamming distance of a code fixes its error control power: detecting up to s errors needs dmin≥s+1, and correcting up to t errors needs dmin≥2t+1. So the data link layer chooses a code to suit the link: even parity (dmin=2) detects one error; the Hamming (7,4) code (dmin=3) corrects one. A received word that is not a valid codeword shows an error; the receiver either corrects it to the nearest codeword (FEC) or discards it and asks for retransmission (ARQ).

Piggybacking in data link flow control PIN 1/27

Asked once

2081 Bhadra · Q32 marksHow do you apply it in data link layer flow control mechanism?

In sliding window flow control with traffic in both directions, every data frame carries seq, its own sequence number, and ack, the number of the next frame expected from the other station. The ack field acknowledges all earlier frames and slides the other sender's window forward, so it can send new frames without separate ACK frames. If no data frame is ready before the ack timer expires, a separate ACK is sent so that the other sender does not time out.

Two sliding window protocols and the advantages of piggybacking PIN 1/27

Asked once

2066 Poush · Q43 marksExplain any two sliding window protocols with the advantages of piggybacking.

  • Go-back-N: the sender may have up to 2k−1 unacknowledged frames; the receiver accepts frames only in order (window 1). When a frame is lost or damaged, the sender resends it and every frame sent after it.
  • Selective repeat: both windows are up to 2k−1; the receiver buffers out-of-order frames and sends a NAK for the missing one, and only that frame is resent.

Advantages of piggybacking (the ACK carried in a returning data frame): fewer separate ACK frames, so better use of the bandwidth; less processing and fewer interrupts; the window advances without extra frames.

The ways of backward error correction (ARQ) PIN 1/27

Asked once

2082 Bhadra · Q34 marksWrite different ways to correct backward error correction.

Backward error correction means the receiver only detects an error and the sender corrects it by retransmission, called ARQ (automatic repeat request), using sequence numbers, ACKs, NAKs and timers. Its three ways are:

  1. Stop and wait ARQ: one frame at a time with 1-bit sequence numbers; the sender keeps a copy and resends it when its timer expires (damaged or lost frame, or lost ACK); duplicates are discarded by sequence number.
  2. Go-back-N ARQ: up to 2k−1 frames outstanding; the receiver accepts frames in order only; on a NAK or a timeout the sender resends the erroneous frame and all frames after it.
  3. Selective repeat ARQ: windows up to 2k−1; the receiver buffers out-of-order frames and only the damaged or lost frame is resent.
GO-BACK-N AND SELECTIVE REPEAT: FRAME 2 IS LOST Same five frames, same loss; go-back-N resends three frames, selective repeat resends one. GO-BACK-N: RESEND FROM THE LOST FRAME ON Sender Receiver F0 F1 F2 lost F3 F4 F0, F1 ok, acknowledged F3 discarded F4 discarded NAK 2 F2 F3 F4 go back to 2 2, 3, 4 again ACK 5 SELECTIVE REPEAT: RESEND ONLY THE LOST FRAME Sender Receiver F0 F1 F2 lost F3 F4 F0, F1 ok, acknowledged F3 buffered F4 buffered NAK 2 F2 again (only) deliver 2, 3, 4 in order ACK 5

Go-back-N ARQ PIN 1/27

Asked once

2080 Bhadra · Q104 marksa) Go Back-N ARQ

Go-back-N ARQ is a sliding window error control protocol in which the sender transmits several frames before receiving an acknowledgement and, on an error, goes back and resends from the erroneous frame.

  • Sender window: up to 2k−1 outstanding frames with k-bit sequence numbers (7 for k=3); a copy of each is kept until acknowledged.
  • Receiver window: 1; frames are accepted only in order, and any frame after a missing one is discarded.
  • Acknowledgements: cumulative; ACK n confirms all frames before n; a NAK may report the missing frame.
  • Retransmission: when frame n is lost or damaged (NAK or timeout), the sender resends frame n and every frame after it.

Example: frames 0 to 4 are sent and frame 2 is lost; the receiver discards 3 and 4 and sends NAK 2; the sender resends 2, 3 and 4.

GO-BACK-N AND SELECTIVE REPEAT: FRAME 2 IS LOST Same five frames, same loss; go-back-N resends three frames, selective repeat resends one. GO-BACK-N: RESEND FROM THE LOST FRAME ON Sender Receiver F0 F1 F2 lost F3 F4 F0, F1 ok, acknowledged F3 discarded F4 discarded NAK 2 F2 F3 F4 go back to 2 2, 3, 4 again ACK 5 SELECTIVE REPEAT: RESEND ONLY THE LOST FRAME Sender Receiver F0 F1 F2 lost F3 F4 F0, F1 ok, acknowledged F3 buffered F4 buffered NAK 2 F2 again (only) deliver 2, 3, 4 in order ACK 5

The receiver is simple, but good frames are resent, which wastes bandwidth on noisy links.

The channel allocation problem PIN 1/27

Asked once

2072 Kartik · Q35 marksExplain the channel allocation problem with example.

The channel allocation problem is how to allocate a single broadcast channel among many competing users. There are two approaches.

Static allocation: the channel is divided into fixed parts, frequency bands (FDM) or time slots (TDM), one per user. It suits a few users with steady traffic (radio broadcasting, telephone trunks) but wastes capacity for bursty data: idle users' shares are lost and busy users cannot borrow them. With N fixed subchannels the mean delay grows N times:

T=1μC−λ,TN=1μ(C/N)−λ/N=NT

Example: a 100 Mbps channel with 10,000-bit frames arriving at 5000 frames/s gives T = 200 µs; divided statically into ten 10 Mbps channels, T = 2 ms.

Dynamic allocation: the channel is given on demand, assuming independent stations, one shared channel, observable collisions, continuous or slotted time, and carrier sense or not. Multiple access protocols (ALOHA, CSMA/CD, token passing) implement it and use the channel far better for bursty traffic.

Pure ALOHA against slotted ALOHA, with the condition for no collision PIN 1/27

Asked once

2082 Bhadra · Q34 marksCompare pure Aloha and slotted Aloha mentioning the condition for no collision.

PointPure ALOHASlotted ALOHA
Transmissionat any timeonly at the start of a slot
Timecontinuous; no synchronisationslots of one frame time; clocks synchronised
Vulnerable time2TT
Condition for no collisionno other station starts a frame within T before or after the frame's startno other station transmits in the same slot
Probability of successe−2Ge−G
ThroughputS=Ge−2GS=Ge−G
Maximum throughput18.4 % at G=0.536.8 % at G=1
Complexitysimplerneeds slot timing
ALOHA: THE VULNERABLE TIME T = the time to send one frame. No other frame may start inside the shaded interval. PURE ALOHA: SEND AT ANY TIME; VULNERABLE TIME 2T vulnerable time: 2T B starts before t A's frame C starts before t + T t - T t t + T B overlaps the head of A, C overlaps its tail: all of them are lost. SLOTTED ALOHA: SEND ONLY AT A SLOT START; VULNERABLE TIME T vulnerable: T A's frame B, same slot: collides C, next slot: safe slot boundaries every T

Here T is the frame time and G the frames offered per frame time. Slotted ALOHA halves the vulnerable time and so doubles the maximum throughput.

How CSMA works PIN 1/27

Asked once

2070 Ashad · Q52 marksDiscuss how CSMA works?

CSMA (carrier sense multiple access) works on "listen before talk": a station first senses the medium and transmits only if it is idle. If it is busy, the station follows its persistence method: 1-persistent (keep sensing, send as soon as it is idle), non-persistent (wait a random time, then sense again) or p-persistent (when idle, send with probability p). Collisions can still occur through propagation delay: a station may sense the medium idle before another's signal reaches it, so the vulnerable time equals the propagation time.

How a collision is detected in CSMA/CD PIN 1/27

Asked once

2082 Baishakh · Q23 marksHow to detect signal collision in CSMA/CD?

In CSMA/CD a station keeps monitoring the medium while it transmits and compares what it receives with what it sends:

  • On coaxial cable: the transceiver measures the signal level (voltage, energy) on the cable; a level higher than its own transmission produces shows that another signal is present: a collision.
  • On twisted pair: activity on the receive pair while the station is transmitting signals a collision.

On detection the station aborts and sends a 32-bit jam signal so that all stations recognise the collision. Detection works only while the frame is still being transmitted, so the frame time must be at least twice the propagation delay (Tframe≥2Tprop): hence Ethernet's minimum frame of 64 bytes.

What a collision is and how it occurs PIN 1/27

Asked once

2076 Chaitra · Q31+1 marksWhat is collision? How is it occured?

A collision occurs when two or more stations on a shared medium transmit at overlapping times, so their signals add together and all the frames involved are garbled and lost. It happens because a station senses the medium idle before another station's signal has reached it (propagation delay), so both start transmitting; or because several stations waiting for a busy medium all start the moment it becomes idle.

How collisions are reduced in IEEE 802.3 and IEEE 802.11 PIN 1/27

Asked once

2076 Chaitra · Q36 marksHow the possibility of collision is reduced in IEEE 802.3 and IEEE 802.11? Explain.

IEEE 802.3 (Ethernet) uses CSMA/CD:

  • Carrier sense: a station transmits only when the medium is idle (1-persistent), after a 96-bit interframe gap.
  • Collision detection: it listens while transmitting, aborts at once on a collision and sends a 32-bit jam.
  • Binary exponential backoff: after the nth collision it waits a random 0 to 2min(n,10)−1 slot times, which spreads the retries out; at most 16 attempts.
  • Minimum frame of 64 bytes, so every collision is detected; switched full-duplex Ethernet removes collisions entirely.

IEEE 802.11 (Wi-Fi) uses CSMA/CA, since a radio cannot detect collisions:

  • Interframe spaces: a station waits for a DIFS of idle channel before contending; ACKs wait only a SIFS and so go first.
  • Contention window: a random backoff counted down only while the channel is idle, doubled after each failure.
  • Acknowledgements: every frame is acknowledged; no ACK means retransmission.
  • RTS/CTS with NAV: every station that hears either frame defers for the announced time, which solves the hidden station problem.
CSMA/CA WITH RTS AND CTS (IEEE 802.11) Virtual carrier sense: the RTS and the CTS carry the time the exchange needs; every station that hears either one keeps quiet (its NAV). Sender A wants to send Receiver B Station C hears A only Station D hears B only (hidden) DIFS backoff RTS SIFS CTS SIFS DATA SIFS ACK NAV from the RTS: keep quiet NAV from the CTS DIFS backoff DIFS backoff DIFS backoff SIFS < DIFS: the reply always takes the channel before anyone else may start.

Why CSMA/CD is not applicable in a wireless LAN PIN 1/27

Asked once

2081 Baishakh · Q32 marksWhy is it not applicable in wireless LAN?

CSMA/CD cannot be used in a wireless LAN because:

  • a radio cannot receive while it transmits (its own signal swamps incoming ones), so it cannot detect collisions;
  • of the hidden station problem: two stations out of range of each other both sense an idle channel and their frames collide at the receiver;
  • signals fade, so the sender's view of the channel differs from the receiver's, where collisions actually occur.
WHY CARRIER SENSING FAILS IN WIRELESS: HIDDEN AND EXPOSED STATIONS Each dashed circle is one station's radio range. A collision matters at the receiver, but a sender can only sense the air at its own place. HIDDEN STATION: C CANNOT HEAR A A B C collision A's range C's range Both A and C sense "idle"; their frames collide at B. EXPOSED STATION: C WAITS FOR NOTHING A B C D B sends C to D held back B's range C's range C senses B and defers, though A is out of C's range.

How DSSS is applied in wireless transmission PIN 1/27

Asked once

2066 Bhadra · Q3a3 marksExplain how DSSS technique is applied in wireless transmission.

DSSS (direct sequence spread spectrum) spreads each data bit over a wide band by replacing it with a sequence of chips:

  • Spreading: each bit is XORed with a chip code; IEEE 802.11 uses the 11-chip Barker sequence, so a 1 is sent as 10110111000 and a 0 as 01001000111, at 11 Mchips/s for 1 Mbps.
  • Transmission: the chips occupy a 22 MHz channel in the 2.4 GHz band at low power density.
  • Despreading: the receiver correlates the chips with the same code to recover each bit; narrowband interference and multipath echoes are spread out and suppressed (a processing gain of about 10.4 dB).

It is used in 802.11 (1 and 2 Mbps) and 802.11b (up to 11 Mbps).

The Ethernet (IEEE 802.3) frame and its fields PIN 1/27

Asked once

2079 Bhadra · Q34 marksDescribe Ethernet (IEEE 802.3) frame structure with function of each field.

THE ETHERNET (IEEE 802.3) FRAME Sizes in bytes. The frame proper runs from the destination address to the FCS. Preamble 10101010 x 7 7 SFD 10101011 1 Destination MAC address 6 Source MAC address 6 Length/Type 0x0800 = IPv4 2 Data and pad 46 to 1500 bytes 46 to 1500 FCS CRC-32 4 synchronisation: not counted the frame: 64 to 1518 bytes (minimum 64 for collision detection) A MAC ADDRESS: 48 BITS, WRITTEN AS SIX HEX BYTES 00 00 5E 00 53 01 OUI: the maker (24 bits) NIC-specific (24 bits) 00:00:5E:00:53:01 (an address kept for examples, RFC 7042) first byte, bit 0 (I/G): 0 unicast, 1 multicast bit 1 (U/L): 0 global, 1 locally set Broadcast: FF:FF:FF:FF:FF:FF Bytes go left to right, each least significant bit first, so the I/G bit is the first on the wire.
  • Preamble (7 bytes): alternating 10101010, for the receiver's clock synchronisation.
  • SFD (1 byte): 10101011, signals the start of the frame.
  • Destination address (6 bytes): MAC address of the receiver (unicast, multicast or broadcast).
  • Source address (6 bytes): MAC address of the sender.
  • Length/Type (2 bytes): up to 1500, the length of the data field; 1536 or more, the type of the encapsulated protocol (0x0800 IPv4, 0x0806 ARP).
  • Data and padding (46 to 1500 bytes): the network layer packet, padded to the 46-byte minimum.
  • FCS (4 bytes): CRC-32 for error detection.

From destination address to FCS the frame is 64 to 1518 bytes; the 64-byte minimum lets CSMA/CD detect a collision while the frame is still being sent.

Ethernet (802.3) cable standards PIN 1/27

Asked once

2082 Baishakh · Q23 marksList the ethernet cable specification standards for 802.3 ethernet standards.

In each name the number is the speed in Mbps, "Base" means baseband, and the last part is the segment length in hundreds of metres or the medium (T twisted pair, F or X fiber).

StandardMediumMax segment
10Base5thick coaxial cable500 m
10Base2thin coaxial cable185 m
10BaseTUTP, Cat 3 or better100 m
10BaseFmultimode fiber2000 m
100BaseTXUTP, Cat 5100 m
100BaseFXmultimode fiber2000 m
1000BaseTUTP, Cat 5e100 m
1000BaseSXmultimode fiber550 m
1000BaseLXsingle-mode fiber5 km
10GBase-SR, LR, ERmultimode, single-mode fiber300 m, 10 km, 40 km

Optical fiber Ethernet standards with examples PIN 1/27

Asked once

2070 Ashad · Q54 marksExplain the optical fiber cabling standards with examples.

The optical fiber Ethernet standards carry light over multimode or single-mode fiber; they reach much farther than copper's 100 m and are immune to electrical interference and lightning.

StandardSpeedFiber and lightReachExample use
10BaseF (10Base-FL)10 Mbpsmultimode, 850 nm2 kmearly links between buildings
100BaseFX100 Mbpsmultimode, 1300 nm2 km (full duplex)a switch in one block to a switch in another
1000BaseSX1 Gbpsmultimode, 850 nm short-wave laser220 to 550 mbackbone up the floors of a building
1000BaseLX1 Gbps1310 nm long-wave laser, multimode or single-mode550 m or 5 kmcampus backbone to distant buildings
10GBase-SR, LR, ER10 Gbps850 nm multimode; 1310 and 1550 nm single-mode300 m, 10 km, 40 kmdata centres and metro links

Short-wave multimode links are cheaper for short runs; long-wave single-mode links serve kilometres.

The 802.3 Ethernet standard compared with 802.4 token bus PIN 1/27

Asked once

2066 Bhadra · Q3a5 marksDescribe the 802.3 Ethernet standard for CSMA/CD and compare it with 802.4 token bus technology.

IEEE 802.3 is the Ethernet standard: stations share a bus (or a hub) and use 1-persistent CSMA/CD: sense the carrier, transmit when idle, listen while transmitting, and on a collision send a jam signal and retry after binary exponential backoff. Frames carry 48-bit MAC addresses, a length/type field, 46 to 1500 data bytes and a CRC-32; the 64-byte minimum frame lets collisions be detected. Speeds run from 10 Mbps (10Base5, 10Base2, 10BaseT) upwards.

Point802.3 Ethernet802.4 Token bus
Access methodCSMA/CD (contention)token passing on a logical ring
Collisionspossiblenone
Access delayrandom, unboundedbounded, deterministic
Prioritynonefour classes (0, 2, 4, 6)
Mediumbaseband coax, twisted pair, fiberbroadband coaxial cable
Speed10 Mbps and above1, 5 or 10 Mbps
At light loadsends at oncewaits for the token
Complexity and usesimple; office LANscomplex ring maintenance; factory automation

Why token bus is also called a token ring PIN 1/27

Asked once

2073 Shrawan · Q34 marksExplain why token bus is also called as the token ring.

Token bus (IEEE 802.4) is physically a bus: all stations are attached to one linear or tree-shaped cable, and every frame reaches all of them. Access, however, is controlled by a token that circulates in a logical ring:

  • each station knows the address of its predecessor and of its successor;
  • the token is passed in descending order of station address;
  • the station with the lowest address passes the token back to the one with the highest, closing the ring;
  • only the token holder transmits, and then passes the token to its successor.
TOKEN BUS: A PHYSICAL BUS, A LOGICAL RING IEEE 802.4: the token goes to the next lower address, whatever the stations' places on the cable. PHYSICAL: ONE BUS CABLE terminator terminator station 90 station 45 station 112 station 70 station 20 Stations sit anywhere on the cable; a frame on the bus reaches all of them at once. LOGICAL: THE ORDER THE TOKEN FOLLOWS 112 90 70 45 20 token goes to the next lower address The lowest, 20, passes back to 112: the circle closes.

Since the token travels round this ring exactly as in a token ring, token bus is also called a token ring, although the ring is logical (by address) and not physical (the cable is a bus). In the figure the token goes 112, 90, 70, 45, 20 and back to 112.

IEEE 802.4 against IEEE 802.5 PIN 1/27

Asked once

2067 Ashad · Q56 marksCompare operating details of IEEE 802.4 and IEEE 802.5.

IEEE 802.4 (token bus) and IEEE 802.5 (token ring) are both collision-free token passing LANs with a bounded access delay; they differ in how the token and the frames travel.

PointIEEE 802.4 Token busIEEE 802.5 Token ring
Topologyphysical bus or tree, logical ringphysical ring, star-wired through wiring centres
Token passingto the successor, by descending addressto the next station downstream
Frame deliverybroadcast on the bus; all stations hear it at oncepasses from station to station, each repeating it
Frame removalabsorbed at the bus terminatorsremoved by the sender after one circuit
Delivery confirmationnone in the frameA and C bits in the frame status
Medium and speedbroadband coaxial cable; 1, 5, 10 Mbpsshielded twisted pair; 4, 16 Mbps
Priorityfour classes (0, 2, 4, 6) with timerseight levels with reservation bits
Ring maintenancedistributed: claim token, solicit successor, set successoran active monitor station
Data fieldup to 8182 byteslimited by the token holding time
Main usefactory automation (MAP)office LANs (IBM)

4Network layer

Distance vector and link state routing compared TOP 9/27

Asked 9 times

2080 Baishakh · Q44 marksCompare distance vector routing protocol and link state routing protocol with examples.

2076 Ashwin · Q56 marksDifferentiate between distance vector and link state routing algorithms.

2075 Ashwin · Q45 marksCompare working of distance vector routing algorithm with link state routing algorithm.

2074 Ashwin · Q4Differentiate between link state and distance vector routing protocol.

2073 Shrawan · Q54 marksCompare operation of link state routing with the distance vector routing.

2072 Kartik · Q56 marksDifferentiate between distance vector routing and static link routing.

2071 Shrawan · Q46 marksDifferentiate between link state routing and distance vector routing.

2068 Chaitra · Q55 marksDifferentiate: a) Distance vector and link state routing algorithm

2067 Ashad · Q76 marksCompare working of distance vector routing algorithm with link state routing algorithm.

In distance vector routing each router periodically sends its whole routing table (its distance to every destination) to its neighbours and updates its own table by the Bellman-Ford rule. In link state routing each router floods the state of its own links to every router, builds the complete topology, and computes its shortest paths with Dijkstra's algorithm.

PointDistance vectorLink state
Knowledgedistances reported by neighboursthe whole topology
Sendswhole routing tablestate of its own links
Toneighbours onlyall routers, by flooding
Whenperiodically (RIP every 30 s)on a change, slow refresh
AlgorithmBellman-FordDijkstra
Convergenceslow, count to infinityfast, no count to infinity
Loopspossible while convergingrare
Metricusually hop countcost from bandwidth or delay
Resourceslittle memory and CPUmore memory and CPU
Scalesmall networkslarge networks, with areas
ExamplesRIP, IGRPOSPF, IS-IS

Examples: a small office of a few routers runs RIP, simple to configure; an ISP or large campus runs OSPF, whose areas keep databases small and whose flooding reroutes around a failed link in under a second.

Routing: what it is and why it is essential PIN 4/27

Asked 4 times

2076 Ashwin · Q52 marksWhat is routing?

2075 Ashwin · Q43 marksWhy routing is essential in computer networking?

2071 Shrawan · Q42 marksWhat is routing?

2067 Ashad · Q72 marksWhy routing is essential in computer networking?

Routing is the process of finding paths through an internetwork and building the routing tables that routers use to forward each packet, hop by hop, from the source network to the destination network. A routing algorithm, usually run as a routing protocol, chooses the path by a metric such as hops, delay or cost.

Why it is essential: a packet for another network can only be delivered if every router knows the next hop; networks are meshes with many possible paths, and routing chooses the best; it reroutes around failed links automatically; it balances load across links; and aggregated routes let the Internet scale.

The routing algorithm and the properties of a good one PIN 3/27

Asked 3 times

2079 Bhadra · Q44 marksDiscuss the characteristics of a good routing algorithm.

2078 Bhadra · Q53 marksDefine routing algorithm. List out the properties/goals of routing algorithm.

2074 Chaitra · Q42 marksMention the criteria for good routing.

A routing algorithm is the part of the network layer software that decides on which output line an incoming packet is transmitted, by computing paths and filling the routing table. A good routing algorithm has these properties (goals):

  • Correctness: it delivers every packet to the correct destination.
  • Simplicity: it needs little computation and few control messages.
  • Robustness: it keeps working through router and link failures and changes in topology and load, without restarting the network.
  • Stability: it converges quickly to fixed routes, without oscillating or forming loops.
  • Fairness: every source and destination pair gets reasonable service.
  • Optimality (efficiency): it minimizes the mean delay or maximizes the total throughput, balanced against fairness.

The IPv4 datagram (IP frame) format PIN 2/27

Asked 2 times

2067 Ashad · Q88 marksExplain in detail about IP frame format.

2066 Poush · Q103 marksc) IPv4 Header Structure

An IPv4 datagram is a header of 20 to 60 bytes followed by data, at most 65,535 bytes in all. IP gives connectionless, best-effort delivery, so the header carries everything each router needs to forward the datagram on its own. The header is laid out in rows of 32 bits:

THE IPV4 HEADER Rows of 32 bits: five fixed rows (20 bytes), then up to 40 bytes of options. 0 4 8 16 19 31 Version 4 bits IHL 4 bits Type of service 8 bits Total length 16 bits Identification 16 bits Flags 3 bits Fragment offset 13 bits Time to live 8 bits Protocol 8 bits Header checksum 16 bits Source IP address 32 bits Destination IP address 32 bits Options and padding (0 to 40 bytes) rarely used 20 BYTES used in fragmentation TTL and protocol: the hop limit and the upper-layer protocol
  • Version (4 bits): 4 for IPv4.
  • IHL (4 bits): header length in 32-bit words, 5 to 15 (20 to 60 bytes).
  • Type of service (8 bits): priority and handling of the datagram (now DSCP and ECN).
  • Total length (16 bits): header plus data in bytes, at most 65,535.
  • Identification (16 bits): the same for every fragment of one datagram.
  • Flags (3 bits): reserved, DF (do not fragment) and MF (more fragments).
  • Fragment offset (13 bits): position of the fragment's data in the original, in 8-byte units.
  • Time to live (8 bits): hop limit, decremented by every router; at 0 the datagram is discarded.
  • Protocol (8 bits): the upper-layer protocol of the data: 1 ICMP, 6 TCP, 17 UDP.
  • Header checksum (16 bits): error check over the header only, recomputed at every hop.
  • Source and destination addresses (32 bits each): the sender's and the final receiver's IP addresses.
  • Options and padding (0 to 40 bytes): record route, timestamp, source routing, padded to a 32-bit boundary.
  • Data: the transport segment or ICMP message being carried.

ICMP: what it is, its importance and its uses in TCP/IP PIN 2/27

Asked 2 times

2081 Baishakh · Q58 marksWhat is ICMP? Explain the importance and uses of ICMP in TCP/IP protocol suit.

2071 Shrawan · Q54 marksb) ICMP

ICMP (Internet Control Message Protocol, RFC 792) is the companion protocol of IP at the network layer. It reports errors in delivering datagrams back to their source and provides query messages for diagnostics. ICMP messages are carried inside IP datagrams with protocol number 1.

THE ICMP MESSAGE, INSIDE IP ICMP rides in an IP datagram with protocol = 1; it reports problems, it does not fix them. Ethernet header IP header, protocol = 1 ICMP message FCS Type 8 bits Code 8 bits Checksum 16 bits Rest of header: depends on the type echo: identifier and sequence number Data errors: the offending IP header plus 8 bytes of its data 0 8 16 31 Type: which message Code: the reason in it Examples: type 8 code 0 echo request; type 3 code 3 port unreachable; type 11 code 0 TTL exceeded.

Format: type (8 bits), code (8 bits) and checksum (16 bits), then 32 bits that depend on the type, then data; an error message carries the IP header and the first 8 bytes of data of the datagram that caused it.

Importance: IP is connectionless and best effort, with no acknowledgement or error reporting of its own. ICMP gives hosts and routers this feedback, so delivery failures are reported instead of passing silently.

Uses in TCP/IP:

  • Error reporting: destination unreachable (network, host, protocol or port), time exceeded, parameter problem and redirect; TCP and UDP pass these to applications.
  • ping: echo request and echo reply (types 8 and 0) test whether a host is reachable and measure the round-trip time.
  • traceroute: probes sent with TTL 1, 2, 3 and so on draw time exceeded messages from each router in turn, revealing the path.
  • Path MTU discovery: "fragmentation needed" messages tell TCP the largest datagram the path can carry.
  • Routing help: redirect gives a host a better first-hop router, and router solicitation and advertisement find routers.
  • Network management: monitoring tools ping devices, and timestamp messages measure delay.

No ICMP error message is sent about another ICMP error, a non-first fragment, or a broadcast or multicast datagram, which prevents message storms.

ICMP error and informational message types PIN 2/27

Asked 2 times

2066 Poush · Q88 marksBriefly describe ICMP error and informational message types in IPv4 network infrastructure.

2066 Bhadra · Q5b3 marksiv) ICMP Message Types

ICMP messages, carried in IP datagrams with protocol number 1, are of two kinds: error-reporting messages, sent back to the source when a router or host cannot process a datagram, and informational (query) messages, sent as request and reply pairs. Every message begins with a type, a code and a checksum.

THE ICMP MESSAGE, INSIDE IP ICMP rides in an IP datagram with protocol = 1; it reports problems, it does not fix them. Ethernet header IP header, protocol = 1 ICMP message FCS Type 8 bits Code 8 bits Checksum 16 bits Rest of header: depends on the type echo: identifier and sequence number Data errors: the offending IP header plus 8 bytes of its data 0 8 16 31 Type: which message Code: the reason in it Examples: type 8 code 0 echo request; type 3 code 3 port unreachable; type 11 code 0 TTL exceeded.

Error-reporting messages:

TypeMessageMeaning
3Destination unreachablecannot deliver: network, host, protocol or port unreachable, or fragmentation needed with DF set
4Source quencha congested router asks the source to slow down (now deprecated)
11Time exceededTTL reached zero (code 0) or reassembly timed out (code 1)
12Parameter probleman invalid header field or a missing option
5Redirecta better first-hop router exists on the same network

Informational (query) messages:

TypesPairUse
8 and 0Echo request and replyping: reachability and round-trip time
13 and 14Timestamp request and replydelay and clock difference
17 and 18Address mask request and replyfinding the subnet mask
10 and 9Router solicitation and advertisementfinding the routers

Error messages carry the original IP header and 8 bytes of its data, and none is sent about an ICMP error, a non-first fragment, or a broadcast or multicast datagram.

Adaptive and non-adaptive routing PIN 2/27

Asked 2 times

2081 Bhadra · Q42 marksWhat is adaptive and non-adaptive routing?

2070 Ashad · Q73 marksDifferentiate between adaptive and non-adaptive routing.

Non-adaptive (static) routing computes routes in advance, offline, and the administrator enters them in the routers; they do not change with traffic or topology. Adaptive (dynamic) routing changes routes automatically as routers exchange information about topology and load through routing protocols.

PointNon-adaptiveAdaptive
Routesfixed, entered manuallycomputed continuously
On a failuremanual change neededautomatic reroute
Overheadnoneupdates, CPU, memory
Securityhigherlower
Suitssmall, stable networkslarge networks
Examplesstatic routes, floodingRIP, OSPF

Routed and routing protocols, with examples PIN 2/27

Asked 2 times

2082 Baishakh · Q42 marksDefine routed and routing protocol.

2072 Chaitra · Q54 marksWhat is routed and routing protocol? Give examples.

A routed protocol is a network layer protocol that carries user data across an internetwork and whose packets are forwarded by routers; it defines the addressing and the packet format. Examples: IPv4 and IPv6 (formerly IPX and AppleTalk).

A routing protocol is used by routers to exchange route information and build their routing tables, so that the routed packets can be forwarded. Examples: RIP, OSPF, EIGRP, IS-IS and BGP.

PointRouted protocolRouting protocol
Purposecarries user datafinds paths, builds tables
Used byhosts and routersrouters only
Providesaddresses and packet formatreachability and metrics
ExamplesIPv4, IPv6RIP, OSPF, BGP

A routing protocol's own messages travel inside routed IP packets: RIP in UDP over IP, OSPF directly in IP.

Routing protocols: what they are and why they are necessary PIN 2/27

Asked 2 times

2082 Bhadra · Q42 marksWhat are routing protocols?

2069 Chaitra · Q53 marksWhy is routing protocol necessary?

A routing protocol is a set of rules and messages by which routers exchange information about the networks they can reach, and the cost of reaching them, so that each router builds and updates its routing table automatically. Examples: RIP, OSPF and EIGRP inside an autonomous system, and BGP between autonomous systems.

Why it is necessary:

  • Scale: static routes for every network on every router are impossible to maintain in a large internetwork.
  • Adaptation: when a link fails, the routers reroute automatically.
  • Best path: a metric chooses the best of many paths, without loops.
  • Policy: between autonomous systems, BGP carries routing policy.

Unicast and multicast, and their routing PIN 2/27

Asked 2 times

2080 Baishakh · Q44 marksWhat is unicast and multicast?

2066 Bhadra · Q4a2 marksWhat is unicast and multicast routing?

Unicast is one-to-one delivery: a packet goes from one source to one destination address, and unicast routing forwards it along a single best path using the routing table (RIP, OSPF, BGP).

Multicast is one-to-many delivery to a group of receivers that have joined a group address (class D, 224.0.0.0 to 239.255.255.255). Multicast routing builds a distribution tree so that the source sends one copy and routers duplicate it only where the paths branch; hosts join groups with IGMP, and routers use protocols such as DVMRP, MOSPF and PIM.

UNICAST AGAINST MULTICAST TO THREE RECEIVERS Unicast repeats the data per receiver; multicast copies it only where the paths split. UNICAST: ONE COPY PER RECEIVER 3 2 1 1 1 1 S R1 R2 R3 H1 H2 H3 MULTICAST: ONE COPY PER LINK 1 1 1 1 1 1 S R1 R2 R3 H1 H2 H3 Copies on each link; 9 link transmissions in all H1, H2, H3 joined group 239.1.1.1 with IGMP Copies on each link; 6 link transmissions in all

Example: sending one stream to three receivers takes 9 link transmissions by unicast but only 6 by multicast in the network drawn.

The functions of the network layer PIN 1/27

Asked once

2072 Kartik · Q42 marksWhat are the functions of network layer?

The network layer delivers packets from the source host to the destination host across networks. Its functions are: logical addressing (IP addresses); routing, to find paths and build routing tables; forwarding each packet to the right output line; packetizing segments into packets; fragmentation and reassembly for links with a smaller MTU; internetworking of different link technologies; error reporting through ICMP; and congestion control and quality of service at routers.

Why the network layer is a key layer of the OSI model PIN 1/27

Asked once

2072 Kartik · Q52 marksNetwork layer is one of the key layers in OSI reference model, why?

The network layer is a key layer because it alone provides host-to-host delivery across many interconnected networks: it gives every host a globally unique logical address, chooses the route, and is the highest layer that every router implements. It is the narrow waist of the stack (IP over every link, every application over IP), hiding the differences between link technologies; without it, frames could never leave their own LAN.

Why a switch is preferred to a hub for a LAN PIN 1/27

Asked once

2079 Bhadra · Q44 marksWhy do we prefer a switch as networking device instead of Hub for LAN connection? Give reasons.

A hub is a physical layer multiport repeater that copies every signal to all ports; a switch is a data link layer device that forwards each frame only to the destination's port using a MAC address table. A switch is preferred because:

  1. Dedicated bandwidth: every switch port gets its full speed, while all hub ports share one bandwidth.
  2. No collisions: each switch port is a separate collision domain, and full-duplex links have no collisions at all; a hub is one collision domain that degrades as load grows.
  3. Full duplex: a switch port sends and receives at the same time; a hub is half duplex.
  4. Security: a unicast frame reaches only its destination; on a hub every host receives all traffic.
  5. Features: VLANs, port security, quality of service and monitoring.
  6. Cost: the price difference is now negligible.

Router and gateway PIN 1/27

Asked once

2068 Chaitra · Q95 marksb) Router and Gateway

A router is a network layer device that connects networks using the same network protocol (IP) and forwards each packet toward its destination by the destination IP address and its routing table. It builds the table statically or with routing protocols (RIP, OSPF, BGP), decrements TTL, separates broadcast domains, and often performs NAT and packet filtering.

A gateway is a device or software that connects networks using different protocol stacks and converts between them, working up to the application layer: an email gateway between two mail systems, or a VoIP gateway between IP phones and the telephone network. In TCP/IP, a host's default gateway is simply the router for traffic leaving its subnet.

PointRouterGateway
Layer3, networkany, up to 7
Protocols on the two sidesthe same (IP)different
Main jobpath selection and forwardingprotocol conversion
Changesonly header fieldsthe data format

The ranges of the IPv4 address classes PIN 1/27

Asked once

2082 Baishakh · Q51 markList the range of IPv4 address classes.

The IPv4 address classes are set by the first bits of the first octet:

ClassFirst bitsRangeDefault mask
A00.0.0.0 to 127.255.255.255255.0.0.0
B10128.0.0.0 to 191.255.255.255255.255.0.0
C110192.0.0.0 to 223.255.255.255255.255.255.0
D1110224.0.0.0 to 239.255.255.255multicast
E1111240.0.0.0 to 255.255.255.255reserved

The logical address PIN 1/27

Asked once

2068 Baishakh · Q42 marksWhat is a logical address?

A logical address is a network layer address assigned to an interface by software (by an administrator or DHCP) rather than built into the hardware, such as the IPv4 address 192.168.1.10. It is hierarchical, with a network part and a host part, so it identifies where the host is across networks; it stays the same from source to destination and changes when the host moves to another network, unlike the physical (MAC) address, which works only on one link.

Why an IP address is needed when every host has a MAC address PIN 1/27

Asked once

2072 Chaitra · Q23 marksThrough we have MAC address, why do we use IP address to represent the host in networks? Explain your answer.

A MAC address identifies a network card but not where it is, so an IP (logical) address is also needed:

  • Hierarchy: a MAC address is flat; an IP address has a network part, so routers keep one route per network instead of one per device in the world.
  • Scope: a MAC address works only within one link and is replaced in every new frame; an IP address stays the same end to end.
  • Different links: IP gives one uniform address over Ethernet, Wi-Fi, serial and cellular links.
  • Flexibility: replacing a card changes the MAC but not the IP; moving to another network changes the IP to show the new location.

ARP maps the IP address to the MAC address for the final hop.

Classful and classless addresses PIN 1/27

Asked once

2074 Ashwin · Q4What is classful and classless address?

Classful addressing divides the IPv4 address space into five fixed classes identified by the first bits, and the class fixes the network part: class A /8 (first octet 0 to 127), B /16 (128 to 191), C /24 (192 to 223), D for multicast (224 to 239) and E reserved (240 to 255). Blocks come in only three sizes, so many addresses are wasted.

THE CLASSFUL IPV4 ADDRESS FORMATS The first bits fix the class, and the class fixes where the network part ends. Class A 0 network host 0.0.0.0 to 127.255.255.255 /8; 126 networks of 16,777,214 hosts Class B 10 network host 128.0.0.0 to 191.255.255.255 /16; 16,384 networks of 65,534 hosts Class C 110 network host 192.0.0.0 to 223.255.255.255 /24; 2,097,152 networks of 254 hosts Class D 1110 multicast group address 224.0.0.0 to 239.255.255.255 multicast groups; no hosts, no mask Class E 1111 reserved 240.0.0.0 to 255.255.255.255 reserved for experiments The ticks mark the octet borders; usable hosts are 2 to the power of the host bits, minus 2 (the network and broadcast addresses).

Classless addressing (CIDR) removes the classes: a block of any power-of-two size is written a.b.c.d/n, where n is the prefix length, for example 192.168.10.0/26 (64 addresses). The mask travels with every route, which allows VLSM, supernetting and route aggregation.

PointClassfulClassless
Network part8, 16 or 24 bits by classany length, given by /n
Wastehighlow
Routingone route per classful networkaggregated routes, longest prefix match

IPv4 addressing and subnetting with an example PIN 1/27

Asked once

2070 Ashad · Q94 marksExplain IPv4 addressing and sub-netting with example.

An IPv4 address is a 32-bit logical address written in dotted decimal (192.168.10.37), made of a network part and a host part. Classful addressing fixes the split by class: A /8 (first octet 0 to 127), B /16 (128 to 191) and C /24 (192 to 223), with D for multicast and E reserved. The private ranges are 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16.

Subnetting borrows s bits from the host part to divide one network into smaller subnets with a longer mask, giving 2s subnets of 2h−2 usable hosts each. Example: 192.168.10.0/24 with 2 borrowed bits gives four /26 subnets (mask 255.255.255.192) starting at .0, .64, .128 and .192, each with 62 hosts; the first runs from .1 to .62 with broadcast .63.

The contribution of subnetting to IP address management PIN 1/27

Asked once

2069 Chaitra · Q4What is the contribution of sub-netting in IP address management?

Subnetting divides one network into smaller subnets by borrowing host bits. Its contribution to IP address management:

  • Efficient use: the block is cut to fit each department, reducing wasted addresses.
  • Smaller broadcast domains: less broadcast traffic and better performance.
  • Security: traffic between subnets passes routers or firewalls that apply policy.
  • Easier administration: addresses map to departments or floors, and a fault stays inside one subnet.
  • Route summarization: outside routers see one route for the whole block.
  • Growth: spare subnets are kept for expansion.

When VLSM is used, and why PIN 1/27

Asked once

2081 Baishakh · Q43 marksIn which case VLSM is used while dividing the given block of IP addresses for different subnets and why?

VLSM (variable length subnet mask) gives each subnet its own mask. It is used when the subnets need different numbers of hosts: departments of unequal size, and point-to-point links between routers that need only 2 addresses.

Why: with one fixed mask, every subnet must be as large as the biggest one, so the small subnets waste most of their addresses. For 100 and 10 hosts, two /25 subnets waste 142 usable addresses, while a /25 and a /28 waste only 30. VLSM therefore conserves addresses, leaves a larger unused block for growth, and keeps the plan hierarchical for route summarization; it needs classless routing protocols such as RIPv2, OSPF and EIGRP.

Supernetting PIN 1/27

Asked once

2081 Bhadra · Q51 markWhat is super-netting?

Supernetting combines several contiguous networks into one larger network with a shorter prefix, so that a single route advertises all of them (route aggregation). For example, 192.168.4.0/24 to 192.168.7.0/24 combine into 192.168.4.0/22 (mask 255.255.252.0). The networks must be contiguous, a power of two in number, and aligned on the combined block size.

IP (Internet Protocol) PIN 1/27

Asked once

2071 Shrawan · Q54 marksc) IP

IP (Internet Protocol, version 4, RFC 791) is the network layer protocol of the TCP/IP suite. It gives a connectionless, unreliable, best-effort datagram service: each datagram is routed independently and may be lost, duplicated or delivered out of order, with no acknowledgement; reliability is left to TCP and error reports to ICMP.

Functions: logical addressing with 32-bit addresses; routing and forwarding hop by hop; fragmentation and reassembly; limiting a datagram's lifetime with TTL; and identifying the upper-layer protocol. Its header is 20 to 60 bytes long.

THE IPV4 HEADER Rows of 32 bits: five fixed rows (20 bytes), then up to 40 bytes of options. 0 4 8 16 19 31 Version 4 bits IHL 4 bits Type of service 8 bits Total length 16 bits Identification 16 bits Flags 3 bits Fragment offset 13 bits Time to live 8 bits Protocol 8 bits Header checksum 16 bits Source IP address 32 bits Destination IP address 32 bits Options and padding (0 to 40 bytes) rarely used 20 BYTES used in fragmentation TTL and protocol: the hop limit and the upper-layer protocol

The purpose of the TTL and protocol fields of the IPv4 header PIN 1/27

Asked once

2076 Chaitra · Q54 marksWhat is the purpose of Time to live (TTL) and protocol field in header of IPv4 datagram.

Time to live (TTL, 8 bits) limits the lifetime of a datagram so that one caught in a routing loop does not circulate for ever. The sender sets it (typically 64 or 128); every router decrements it by 1, and a router that reduces it to 0 discards the datagram and sends an ICMP time exceeded message to the source. It also limits a path to 255 hops, and traceroute uses it to discover the routers on a path.

Protocol (8 bits) identifies the upper-layer protocol whose data the datagram carries, so that the destination hands the payload to the right module (demultiplexing): 1 ICMP, 2 IGMP, 6 TCP, 17 UDP, 89 OSPF, 50 ESP and 51 AH. It does at the network layer what the port number does at the transport layer.

Fragmentation and reassembly PIN 1/27

Asked once

2068 Baishakh · Q63 marksWhat is a fragmentation and re-assembly?

Fragmentation is the splitting of an IP datagram that is larger than the next link's MTU (1,500 bytes on Ethernet) into smaller fragments, each with its own header carrying the same Identification, a Fragment offset in 8-byte units, and the MF flag, set on all but the last. Reassembly is the rebuilding of the original datagram at the destination host from these fields; if a fragment is still missing when the reassembly timer expires, the whole datagram is discarded. For example, a 4,000 byte datagram becomes fragments of 1,500, 1,500 and 1,040 bytes with offsets 0, 185 and 370.

Why the maximum TCP payload is 65,495 bytes PIN 1/27

Asked once

2068 Baishakh · Q74 marksThe maximum payload segment is 65495 byte. Why was such strange number chosen?

The number comes from the IPv4 header. A TCP segment must fit inside one IP datagram, and the IPv4 Total length field is 16 bits, so a datagram, header included, is at most 216−1 = 65,535 bytes. The minimum IPv4 header takes 20 bytes and the minimum TCP header another 20 bytes, which leaves:

65535−20−20=65495 bytes

So 65,495 bytes is the largest payload one TCP segment can carry: it is not a chosen number but what remains after both headers. For UDP, whose header is 8 bytes, the limit is 65,535 minus 20 minus 8 = 65,507 bytes. In practice the Ethernet MTU of 1,500 bytes limits each segment to 1,460 bytes of data.

ARP and NDP PIN 1/27

Asked once

2082 Bhadra · Q104 marksa) ARP and NDP

ARP (Address Resolution Protocol, RFC 826) maps a known IPv4 address to a MAC address on the same link: the sender broadcasts an ARP request ("who has 192.168.1.20?"), the owner unicasts a reply with its MAC address, and the pair is cached.

NDP (Neighbour Discovery Protocol, RFC 4861) replaces ARP in IPv6. It uses ICMPv6 neighbour solicitation and advertisement messages sent to a solicited-node multicast address instead of a broadcast, and also finds routers and prefixes.

PointARPNDP
Used withIPv4IPv6
Carried inits own Ethernet frame (type 0x0806)ICMPv6 inside IPv6
Request sent tobroadcastsolicited-node multicast
Messagesrequest, replyNS, NA, RS, RA, redirect
Functionsaddress resolution onlyresolution, router and prefix discovery, SLAAC, duplicate address detection, reachability
Securitynonecan use SEND

The protocol that gives hosts and routers feedback about network problems PIN 1/27

Asked once

2076 Chaitra · Q51 markWhich protocol is used in internet layer to provide feedback to hosts/routers about the problems in the network environment?

ICMP (Internet Control Message Protocol) provides this feedback: routers and hosts send ICMP error messages, such as destination unreachable and time exceeded, back to the source of a datagram that could not be delivered.

The optimality principle PIN 1/27

Asked once

2066 Bhadra · Q4aDescribe the concept of optimality principle.

The optimality principle states that if router J is on the optimal path from router I to router K, then the optimal path from J to K also falls along the same route. Proof: call the part from I to J r1 and the rest r2; if a better route than r2 existed from J to K, joining it to r1 would improve the route from I to K, which contradicts the optimality of r1r2.

THE OPTIMALITY PRINCIPLE AND THE SINK TREE Part of an optimal path is itself optimal, so the best routes to one destination form a tree. I J K r1 r2 shorter r2'? If a shorter r2' existed from J to K, then r1 + r2' would beat the optimal r1 + r2: impossible. B D E A C F sink tree for destination B

Consequence: the optimal routes from all sources to one destination form a tree rooted at that destination, the sink tree. A sink tree has no loops, so every packet is delivered in a finite number of hops; routing algorithms aim to discover and use the sink trees of all destinations.

The autonomous system PIN 1/27

Asked once

2075 Chaitra · Q52 marksWhat do you mean by autonomous system?

An autonomous system (AS) is a group of networks and routers under one administrative authority with a single routing policy, such as an ISP or a university, identified by an AS number of 16 or 32 bits. Inside an AS, routing uses an interior gateway protocol (RIP, OSPF) chosen by the AS itself; between autonomous systems, the exterior gateway protocol BGP is used.

How routing loops are prevented in distance vector routing PIN 1/27

Asked once

2075 Chaitra · Q56 marksExplain how routing loops are prevented in Distance Vector Routing with examples.

In distance vector routing a routing loop forms when routers believe stale information about a failed route, so packets bounce between them while their metrics count up to infinity. Example: routers A, B and C are in a line with network N on C. C's link to N fails; C then accepts B's old advertisement "N at 2 hops" and sets N at 3 via B; B in turn sets 4 via C, and so on up to 16.

COUNT TO INFINITY, AND THE SPLIT HORIZON FIX Bad news travels slowly: B and C count up together until they reach 16. A B C network N link fails N: 3 via B N: 2 via C N: 1, direct BEFORE C: 1, direct B: 2 via C LINK FAILS C: 16, lost B: 2 via C C HEARS B C: 3 via B B: 2 via C B HEARS C C: 3 via B B: 4 via C C HEARS B C: 5 via B B: 4 via C B HEARS C C: 5 via B B: 6 via C AND SO ON C: 7, 9 ... B: 8, 10 ... AT LAST C: 16 B: 16 Split horizon: B learned N from C, so it never advertises N back to C. C keeps 16, tells B, and the loop never starts. Poison reverse: B does advertise N to C, but with metric 16. Hold-down: a lost route ignores worse news for 180 s.

Prevention methods:

  • Maximum hop count: RIP defines 16 as infinity, so the counting stops.
  • Split horizon: a router never advertises a route back out of the interface it came from; B never tells C about N, so C keeps N unreachable.
  • Poison reverse: B advertises N back to C with metric 16, which breaks the loop at once.
  • Route poisoning: C advertises N with metric 16 as soon as the link fails.
  • Triggered updates: changes are sent immediately instead of after the 30 second timer.
  • Hold-down timer: after a route fails, worse news about it is ignored for 180 seconds, so stale updates cannot reinstate it.

The properties of link state routing PIN 1/27

Asked once

2081 Bhadra · Q42 marksList the properties of link state routing

Properties of link state routing:

  • Each router knows the complete topology (the link state database).
  • It shares only the state of its own links, flooded to every router.
  • Updates are sent when a link changes, with a slow periodic refresh.
  • Each router computes its own routes with Dijkstra's algorithm.
  • Convergence is fast, with no count to infinity; the metric is a cost.
  • It needs more memory and CPU and scales with areas (OSPF, IS-IS).

RIP, OSPF, BGP, IGRP and EIGRP PIN 1/27

Asked once

2074 Chaitra · Q46 marksExplain RIP, OSPF, BGP, IGRP and EIGRP.

  • RIP (Routing Information Protocol): a distance vector interior protocol (RFC 1058, 2453) with a hop count metric, at most 15 hops (16 means unreachable), sending whole tables every 30 seconds over UDP 520; simple but slow to converge, for small networks.
  • OSPF (Open Shortest Path First): an open-standard link state interior protocol (RFC 2328); routers flood LSAs within areas, elect a DR and BDR on LANs and run Dijkstra; its cost metric comes from bandwidth; fast convergence, VLSM and authentication.
  • BGP (Border Gateway Protocol): the exterior protocol between autonomous systems (BGP-4, RFC 4271); a path vector protocol that advertises routes with their AS path and chooses by policy, over TCP port 179; a route containing its own AS number is rejected, which prevents loops.
  • IGRP (Interior Gateway Routing Protocol): Cisco's distance vector interior protocol with a composite metric of bandwidth and delay (load and reliability optional), updates every 90 seconds and a hop limit of 100 (up to 255); classful and now obsolete.
  • EIGRP (Enhanced IGRP): Cisco's advanced distance vector (hybrid) protocol; its DUAL algorithm keeps a feasible successor for fast, loop-free convergence; it sends partial updates only on change and supports VLSM and unequal-cost load balancing.
INTERIOR AND EXTERIOR ROUTING Each autonomous system picks its own IGP; between systems everyone speaks BGP. AUTONOMOUS SYSTEM 64500 AUTONOMOUS SYSTEM 64501 R1 R2 R3 IGP: OSPF R4 R5 R6 IGP: RIP eBGP, TCP 179 the exterior protocol Intra-AS (interior): RIP, OSPF, IS-IS, EIGRP, chosen by each AS. Inter-AS (exterior): BGP, used by all.

An intra-AS routing protocol: OSPF PIN 1/27

Asked once

2068 Baishakh · Q65 marksExplain about any intra-AS routing protocol.

An intra-AS routing protocol (interior gateway protocol) routes inside one autonomous system; RIP, OSPF, IS-IS and EIGRP are examples. OSPF (Open Shortest Path First) is the most widely used:

  • Type: an open-standard link state protocol (RFC 2328), carried directly in IP as protocol 89.
  • Working: routers find neighbours with Hello packets every 10 seconds, elect a DR and BDR on multi-access networks, synchronize their link state databases with DBD, LSR, LSU and LSAck packets, flood LSAs on any change, and run Dijkstra's SPF algorithm to build their routing tables.
  • Metric: cost, the reference bandwidth divided by the link bandwidth.
  • Areas: the AS is divided into areas joined to backbone area 0 by area border routers, which keeps each database small.
  • Advantages: fast convergence, no count to infinity, VLSM support, authentication and equal-cost load balancing.
OSPF AREAS, AND A DR AND BDR ON A LAN Areas keep each database small; a DR and BDR cut the adjacencies on a shared segment. AREA 0 (BACKBONE) AREA 1 AREA 2 other AS R0 ABR1 ABR2 ASBR one Ethernet segment R1 R2 R3 R4 R5 DR BDR DROthers 7 adjacencies, not 10

Multicast and unicast routing protocols PIN 1/27

Asked once

2072 Kartik · Q46 marksExplain briefly about multicast routing protocols and unicast routing protocols.

Unicast routing protocols build tables for one-to-one delivery along one best path: the interior protocols RIP (distance vector, hop count), OSPF and IS-IS (link state, cost) and EIGRP (advanced distance vector), and the exterior protocol BGP (path vector) between autonomous systems.

Multicast routing protocols deliver one stream to a group of receivers (a class D address) along a distribution tree, copying packets only where paths branch. Hosts join groups with IGMP; routers use reverse path forwarding (RPF) to avoid loops and build source-based or shared trees:

ProtocolWorking
DVMRPdistance vector based; flood and prune; source-based trees
MOSPFOSPF extension; group membership LSAs; Dijkstra source trees
PIM-DMprotocol independent, dense mode; flood and prune
PIM-SMsparse mode; explicit joins to a rendezvous point; shared tree, then source tree
CBTcore based tree; one shared tree per group
UNICAST AGAINST MULTICAST TO THREE RECEIVERS Unicast repeats the data per receiver; multicast copies it only where the paths split. UNICAST: ONE COPY PER RECEIVER 3 2 1 1 1 1 S R1 R2 R3 H1 H2 H3 MULTICAST: ONE COPY PER LINK 1 1 1 1 1 1 S R1 R2 R3 H1 H2 H3 Copies on each link; 9 link transmissions in all H1, H2, H3 joined group 239.1.1.1 with IGMP Copies on each link; 6 link transmissions in all

5Transport layer

TCP and its segment (header) structure HOT 6/27

Asked 6 times

2076 Ashwin · Q64 marksExplain the TCP segment structure.

2075 Ashwin · Q65 marksExplain the TCP datagram format in detail.

2074 Ashwin · Q65 marksExplain the TCP protocol with its Header.

2070 Ashad · Q104 marksb) TCP header

2068 Chaitra · Q75 marksExplain the TCP datagram format in detail.

2068 Baishakh · Q55 marksDraw the segment structure of TCP.

TCP (Transmission Control Protocol) is a connection-oriented, reliable, full-duplex byte-stream transport protocol with flow and congestion control. Its segment is a header of 20 to 60 bytes followed by data:

THE TCP HEADER (RFC 9293) Twenty bytes fixed, then 0 to 40 bytes of options; each row is 32 bits. 0 4 8 15 16 31 Source port 16 bits Destination port 16 bits Sequence number 32 bits: number of the first data byte (the ISN on a SYN) Acknowledgement number 32 bits: next byte expected, valid when ACK = 1 HLEN 4 bits Reserved 4 bits Window size 16 bits: receive window, bytes C W R E C E U R G A C K P S H R S T S Y N F I N Checksum pseudo-header, header and data Urgent pointer valid when URG = 1 Options and padding MSS, window scale, SACK permitted, SACK, timestamps Data: the bytes this segment carries fixed header, 20 bytes 0 to 40 bytes Flags: CWR and ECE explicit congestion notification; URG urgent data; ACK ack field valid; PSH push now; RST reset; SYN open, synchronize sequence numbers; FIN close, sender has finished. RFC 793 (1981) drew 6 reserved bits and 6 flags; RFC 3168 (2001) took two reserved bits for CWR and ECE.
  • Source and destination port (16 bits each): the sending and receiving processes.
  • Sequence number (32 bits): number of the first data byte in the segment; the ISN on a SYN.
  • Acknowledgement number (32 bits): the next byte expected; valid when ACK is set.
  • Header length (4 bits): header size in 32-bit words (5 to 15).
  • Reserved (4 bits): zero (6 bits in RFC 793).
  • Flags (1 bit each): URG urgent pointer valid, ACK acknowledgement valid, PSH push at once, RST reset, SYN synchronize (open), FIN finish (close); CWR and ECE for congestion notification.
  • Window size (16 bits): receive window for flow control.
  • Checksum (16 bits): over the pseudo-header, header and data; mandatory.
  • Urgent pointer (16 bits): end of urgent data when URG is set.
  • Options (0 to 40 bytes): MSS, window scale, SACK, timestamps, with padding.

TCP compared with UDP HOT 5/27

Asked 5 times

2082 Baishakh · Q6compare it with TCP

2075 Ashwin · Q63 marksWhat are the differences between TCP and UDP services?

2071 Chaitra · Q65 marksDifferentiate between TCP and UDP protocol.

2071 Shrawan · Q63 marksDistinguish between TCP and UDP.

2068 Chaitra · Q73 marksWhat are the differences between TCP and UDP services?

BasisTCPUDP
Connectionconnection-oriented (three-way handshake)connectionless
Reliabilityreliable: ACK and retransmissionunreliable: no ACK, no retransmission
Orderingin-order delivery by sequence numbersno ordering
Data unitsegment; byte streamuser datagram; message boundaries kept
Header size20 to 60 bytes8 bytes
Flow and congestion controlyes (windows)none
Checksummandatoryoptional in IPv4
Speedslower: setup and retransmission delayfaster: low overhead
Castingunicast onlyunicast, broadcast, multicast
Protocol number617
ApplicationsHTTP, HTTPS, SMTP, FTP, SSH, TelnetDNS, DHCP, SNMP, TFTP, VoIP, online games

The UDP header has only source port, destination port, length and checksum, while the TCP header adds sequence and acknowledgement numbers, header length, flags, window and urgent pointer. TCP suits data that must arrive complete (web pages, files, mail); UDP suits short or time-critical data.

Services, functions and major tasks of the transport layer PIN 4/27

Asked 4 times

2078 Bhadra · Q63 marksWhat are services provided by Transport layer?

2076 Chaitra · Q65 marksWhat are the major task of transport layer? Explain.

2071 Chaitra · Q62 marksWhat are the services of transport layer?

2068 Baishakh · Q53 marksWhat are the functions of transport layer?

The transport layer (layer 4) provides logical, end-to-end communication between processes running on different hosts. It runs only in the end hosts, accepts messages from the application layer and uses the network layer's host-to-host delivery to provide these services:

  1. Process-to-process delivery: port numbers in every segment identify the sending and receiving process, not only the host.
  2. Segmentation and reassembly: a long message is divided into numbered segments and rebuilt at the receiver.
  3. Connection control: a connection-oriented service (TCP: establish, transfer, release) or a connectionless service (UDP).
  4. Reliability (error control): checksum, acknowledgement and retransmission recover corrupted, lost and duplicate segments.
  5. Ordered delivery: sequence numbers restore the order in which data was sent.
  6. Flow control and buffering: the receiver's advertised window stops a fast sender from overflowing its buffer.
  7. Multiplexing and demultiplexing: many processes share one IP address, separated by their ports.
  8. Congestion control: senders reduce their rate when the network is overloaded (TCP slow start, traffic shaping).

The token bucket compared with the leaky bucket PIN 4/27

Asked 4 times

2081 Bhadra · Q6compare it with leaky bucket

2080 Bhadra · Q64 marksHow does Token Bucket control the congestion over the Leaky Bucket algorithm?

2070 Ashad · Q83 marksCompare between leaky bucket and token bucket algorithm

2066 Poush · Q56 marksDifferentiate between leaky bucket and token bucket algorithm with their operation

Both are traffic shaping algorithms. The leaky bucket stores packets in a finite queue and sends them at a fixed rate, discarding packets when it is full; the token bucket stores tokens generated at rate r up to capacity C and sends a packet only by removing a token, so saved tokens allow bursts.

BasisLeaky bucketToken bucket
Bucket holdspacketstokens (permission)
Output rateconstant, whatever the inputaverage r, bursts up to C at line rate
Idle periodsno credit savedtokens saved up to C
When fullpackets discardedtokens discarded; packets wait
Burst handlingbursts flattened, slow responsebounded bursts sent at once, fast response
Network utilizationidle capacity wastedidle capacity used later
Parametersqueue size, output ratetoken rate r, bucket size C

How the token bucket controls congestion better: it holds the long-run rate at r just as the leaky bucket does, so the network's average load is still bounded, but it lets a host use capacity saved while idle, responds faster to sudden bursts, loses no packets when the bucket fills, and limits the worst-case burst to C (lasting S=C/(M−r)).

The UDP header (segment structure) and its fields PIN 3/27

Asked 3 times

2082 Bhadra · Q62 marksWrite UDP header field and functions.

2082 Baishakh · Q62 marksDiscuss UDP header

2070 Chaitra · Q68 marksExplain the UDP segment structure. Illustrate your answer with appropriate figures.

UDP (User Datagram Protocol, RFC 768) is a connectionless, unreliable transport protocol. Its segment, the user datagram, is an 8-byte header of four 16-bit fields followed by the application data, and the whole datagram travels as the data of an IP datagram whose protocol field is 17.

THE UDP HEADER (RFC 768) Eight bytes: four 16-bit fields. The checksum also covers a pseudo-header taken from IP. 0 15 16 31 Source port 16 bits, 0 when not used Destination port 16 bits, the receiving process Length header + data in bytes, at least 8 Checksum optional in IPv4, mandatory in IPv6 Data: the application message, up to 65,507 bytes over IPv4 header 8 bytes PSEUDO-HEADER (IPv4): ONLY FOR THE CHECKSUM, NEVER SENT Source IP address 32 bits, from the IP header Destination IP address 32 bits Zero 8 bits Protocol 17 = UDP UDP length 16 bits, same as Length 12 bytes INSIDE AN IP DATAGRAM IP header 20 bytes or more, protocol = 17 UDP header 8 bytes UDP data the message The UDP datagram (header + data) is the IP datagram's payload.
  • Source port (16 bits): port of the sending process, to which a reply is sent; optional, set to 0 when no reply is needed.
  • Destination port (16 bits): port of the receiving process, used to deliver the datagram to the correct socket (for example 53 for DNS).
  • Length (16 bits): total length of header and data in bytes: minimum 8 (header only), maximum 65,535, so at most 65,507 bytes of data over IPv4.
  • Checksum (16 bits): one's complement sum over a 12-byte pseudo-header (source IP, destination IP, a zero byte, protocol 17, UDP length), the header and the data. It detects corrupted and misdelivered datagrams, which are discarded. It is optional in IPv4 (0 means not used) and mandatory in IPv6.

Functions of UDP: process-to-process delivery through ports, multiplexing and demultiplexing, and error detection, without connection setup, acknowledgement, retransmission, ordering or flow control. Each message is sent as one datagram, so message boundaries are preserved.

Example: a 28-byte DNS query from port 50000 to port 53 begins C3 50 00 35 00 24: source port 50000, destination port 53, length 8 + 28 = 36 bytes, followed by the checksum.

Why TCP is called reliable, and how reliability is provided PIN 3/27

Asked 3 times

2081 Bhadra · Q62 marksWhy TCP is known as reliable protocol?

2076 Ashwin · Q64 marksWhy TCP is known as reliable protocol and also describe how reliability is provided by TCP?

2072 Chaitra · Q65 marksTCP is known as reliable process how, describe reliability is provided by TCP.

TCP is called reliable because, over the unreliable, best-effort IP, it delivers every byte to the receiving process exactly once, without errors and in the order sent, or reports a failure. Reliability is provided by:

  1. Connection establishment: the three-way handshake ensures both ends are ready and synchronizes the initial sequence numbers.
  2. Sequence numbers: every byte is numbered, so lost, duplicate and out-of-order data are detected and reordered.
  3. Positive acknowledgement: the receiver sends cumulative ACKs naming the next byte expected.
  4. Retransmission: the sender keeps a copy and a timer; an unacknowledged segment is resent after the timeout (RTO=SRTT+4×RTTVAR) or after three duplicate ACKs (fast retransmit).
  5. Checksum: corrupted segments are discarded and then retransmitted.
  6. Flow control: the receive window prevents buffer overflow at the receiver.
  7. Congestion control: slow start and congestion avoidance prevent losses inside the network.
  8. Graceful release: FIN and ACK in each direction, so no data is lost at closing.
HOW TCP RECOVERS A LOST SEGMENT Sequence numbers show the gap, the ACK reports it, the timer resends it: 3,000 bytes arrive whole and in order. Sender keeps a copy until ACKed Receiver buffers, reorders, ACKs seq 1001, 1000 bytes lost seq 2001, 1000 bytes seq 3001, 1000 bytes ACK 2001 duplicate ACK 2001 bytes 1001 to 2000 in order 3001 to 4000 arrive early: kept in the buffer retransmission timer for 2001 (RTO) runs out seq 2001 again ACK 4001 gap filled: bytes 1001 to 4000 go to the application in order Three duplicate ACKs would trigger the resend sooner (fast retransmit); a corrupt segment fails its checksum and is treated as lost.

Port number (port address): what it is and why it is used PIN 3/27

Asked 3 times

2082 Baishakh · Q62 marksWhat is port address?

2080 Baishakh · Q62 marksWhat is port number?

2071 Chaitra · Q61 markWhy port number is used in networking?

A port number (port address) is a 16-bit number (0 to 65,535) in the TCP or UDP header that identifies a process on a host. An IP address delivers data only to the host, which runs many processes at once; the port delivers it to the correct process, giving process-to-process delivery and multiplexing. Examples: HTTP 80, SMTP 25, DNS 53. Ranges: well-known 0 to 1023, registered 1024 to 49151, dynamic 49152 to 65535.

Where UDP is preferred: practical examples and applications PIN 2/27

Asked 2 times

2079 Bhadra · Q64 marksIn which case is UDP preferred as a transport layer protocol? Discuss with practical examples.

2066 Poush · Q103 marksa) UDP and its application

UDP (User Datagram Protocol) is a connectionless, unreliable transport protocol with an 8-byte header (ports, length, checksum). It is preferred when speed and timeliness matter more than guaranteed delivery, when exchanges are short requests and replies, and when data must reach many receivers at once:

ApplicationPortReason for UDP
DNS53one short query and reply; the client simply retries
DHCP67, 68the client has no IP address yet and must broadcast
VoIP and video calls (RTP)dynamiclate packets are useless; small losses are tolerated
Online gamesgame specificonly the latest position update matters
IPTV, live streamingmulticastone stream delivered to many receivers
SNMP, NTP, TFTP161, 123, 69short messages, simple devices
QUIC (HTTP/3)443builds its own reliability without TCP's delays

Factors that cause congestion, and the parameters that affect it PIN 2/27

Asked 2 times

2073 Shrawan · Q52 marksExplain how different network parameters effect the congestion.

2066 Bhadra · Q4b2 marksWhat are the factors that cause congestion within WAN?

  • Arrival rate above link capacity: several input lines feeding one output line.
  • Buffer memory: too little drops packets; too much delays them until they time out and are duplicated.
  • Bursty traffic that exceeds capacity for short periods.
  • Slow processors and low-bandwidth lines at routers.
  • Retransmission and timeout policies: short timers add duplicate traffic.
  • Routing and packet lifetime: traffic concentrated on one path, old packets circulating.

Why UDP is used on the Internet though it is unreliable PIN 1/27

Asked once

2081 Baishakh · Q63 marksThough UDP is said to be unreliable protocol, it is used in Internet. Why?

UDP is called unreliable because it has no acknowledgement, retransmission or ordering, yet it is widely used because these omissions make it fast and light:

  • No connection setup: data goes in the first packet, so a DNS query or DHCP exchange completes in one round trip.
  • Timeliness: in VoIP, video calls and online games a late packet is useless, and retransmission would only add delay.
  • Low overhead: an 8-byte header and no per-client state at the server.
  • Broadcast and multicast are possible (DHCP discovery, IPTV).
  • Application control: applications add only the reliability they need (DNS retries, TFTP acknowledgements, QUIC).

Features of UDP PIN 1/27

Asked once

2079 Bhadra · Q64 marksWhat are the features of UDP protocol?

UDP (User Datagram Protocol, RFC 768) is the simple transport protocol of the TCP/IP suite. Its features are:

  1. Connectionless: no handshake or release; each datagram is independent.
  2. Unreliable (best effort): no acknowledgement or retransmission; lost datagrams are not recovered.
  3. No ordering: datagrams may arrive out of order.
  4. Message-oriented: each message is sent as one datagram, so boundaries are preserved.
  5. Small header: 8 bytes: source port, destination port, length and checksum.
  6. Error detection only: the checksum (optional in IPv4) causes damaged datagrams to be discarded.
  7. No flow or congestion control: data is sent at the application's rate.
  8. Stateless and fast: no per-client state and low delay, so one server serves many clients.
  9. Broadcast and multicast are supported.

What a TCP connection is PIN 1/27

Asked once

2072 Kartik · Q62 marksWhat is a TCP connection?

A TCP connection is a logical, full-duplex, point-to-point communication path between two processes, identified by a socket pair (source IP, source port, destination IP, destination port). It is set up by the three-way handshake and released by FIN exchanges. Its state (sequence numbers, windows, buffers and timers) is kept only in the two end hosts; routers are unaware of it, so it is a virtual connection.

Why two transport protocols but one internet layer protocol PIN 1/27

Asked once

2069 Chaitra · Q65 marksWhy do you think that there exist two protocols in transport layer where as there exists only one protocol in Internet layer in TCP/IP reference model.

The transport layer has two protocols because applications need two opposite services, while the internet layer needs one common protocol that every network and router understands.

WHY ONE IP BUT TWO TRANSPORTS Many applications above, many links below, one protocol at the waist that every router speaks. Applications HTTP, SMTP, FTP, SSH | DNS, DHCP, voice calls, games TCP reliable stream UDP fast datagrams IP Link technologies Ethernet, WiFi, 4G and 5G, fibre, DSL Many applications, each with its own needs Two services to choose from: reliable or fast; run only in the two end hosts One protocol that every router must run: best-effort, host to host Any link technology can carry IP A new transport (QUIC, built over UDP) needs only the end hosts to change; a new network protocol needs every router to change, which is why IPv6 is slow to spread.
  1. Different needs: file transfer, e-mail and web pages need complete, ordered delivery (TCP); voice, video, games and DNS need low delay and tolerate loss (UDP). Reliability requires waiting for retransmission, which real-time traffic cannot afford, so one protocol cannot serve both.
  2. End-to-end principle: transport protocols run only in the end hosts, so offering a choice costs the routers nothing.
  3. Common network layer: IP must be implemented by every router and carried over every link technology; a single, simple best-effort protocol gives universal interoperability, the narrow waist of the hourglass model.
  4. Cost of change: a new transport protocol needs changes only in the hosts, but a new internet protocol needs every router changed, as the slow IPv4 to IPv6 transition shows.
  5. Flexibility: UDP exposes IP's service with ports added, so applications can build their own reliability (QUIC) without changing the network.

Why the port numbers of well-known servers are standardized PIN 1/27

Asked once

2080 Baishakh · Q64 marksWhy is it necessary to standardize the port numbers for well-known servers?

Well-known ports (0 to 1023) are assigned by IANA to standard servers, for example HTTP 80, HTTPS 443, SMTP 25, DNS 53, FTP 21 and SSH 22. Standardization is necessary because:

  1. Known meeting point: a client must know the server's port before contacting it; DNS supplies only the IP address, so the port must be fixed in advance.
  2. Interoperability: any client software reaches any server without extra configuration or lookup.
  3. Defaults: URLs and applications omit the port; http://host/ implies port 80.
  4. Administration and security: firewall, NAT and intrusion detection rules are written per port, and only privileged processes may bind ports below 1024.
  5. No conflicts: a central registry prevents two services from claiming one number.

Clients use temporary (ephemeral) ports, which need no standard because the server reads them from the incoming segment.

A web service hosted on port 8765 instead of 80 PIN 1/27

Asked once

2080 Baishakh · Q62 marksWhat happens when a web service is hosted at some different port such as 8765 instead of 80? Explain.

The web service still works, since TCP accepts any port, but clients no longer find it by default. A browser connects to port 80 for an http address, so users must give the port explicitly, as http://www.example.com:8765/. Without it the connection goes to port 80, where the server refuses it with RST or a different service answers. Firewalls that allow only ports 80 and 443 may also block port 8765.

The socket and its importance PIN 1/27

Asked once

2074 Ashwin · Q63 marksWhat do you understand by socket? Explain with its importance.

A socket is an endpoint of communication, identified by an IP address and a port number together with the protocol, for example 203.0.113.5:80. A TCP connection is identified by a pair of sockets (source IP, source port, destination IP, destination port). The socket is also the programming interface between an application and the transport layer (the Berkeley socket API: socket, bind, listen, accept, connect, send, receive, close).

Importance: it identifies a process uniquely across the Internet, lets many connections share one server port, keeps the data of each connection separate, and is the interface on which every network application is built.

Why the server program must run before the client PIN 1/27

Asked once

2072 Chaitra · Q63 marksFor the client-server application over TCP, why must the server program be executed before the client program?

In TCP the server performs a passive open: it creates a socket, binds it to a known port and calls listen, waiting in the LISTEN state. The client performs an active open by sending a SYN to that port, and a SYN is accepted only by a listening socket. If the server program is not running, no process listens on the port, so the server host's TCP replies with RST and the client's connect fails with "connection refused"; TCP does not hold the request until a server appears. Hence the server must be executed first and be waiting before the client starts.

Network congestion PIN 1/27

Asked once

2073 Shrawan · Q52 marksDiscuss about the network congestion?

Network congestion is the condition in which the load offered to a network, or to a part of it, exceeds its capacity. Router queues grow and overflow, so delay increases, packets are dropped and retransmitted, and throughput falls; severe congestion can cause congestion collapse, in which little useful data is delivered. It is handled by congestion control, such as traffic shaping and TCP's congestion window.

Congestion control techniques PIN 1/27

Asked once

2081 Bhadra · Q62 marksWhat are the congestion control techniques applied in network communication?

Open-loop (prevention): good retransmission, window, acknowledgement and discard policies, admission control, and traffic shaping with the leaky bucket and token bucket algorithms. Closed-loop (removal): detect congestion and feed it back to the sources: backpressure, choke packets, implicit signalling (loss or delay), explicit signalling (ECN), load shedding and random early detection. At the hosts, TCP uses slow start and congestion avoidance with its congestion window.

Policies that prevent congestion PIN 1/27

Asked once

2066 Poush · Q54 marksDescribe the policies that help in preventing the congestions within the network?

Congestion prevention (open-loop control) uses policies that stop congestion from starting, applied at several layers:

  • Retransmission policy: well-tuned timers, so packets are not resent while merely delayed.
  • Window policy: selective repeat instead of go-back-N, so only lost packets are resent.
  • Acknowledgement policy: cumulative, delayed and piggybacked ACKs reduce extra traffic.
  • Discard policy: routers drop less important packets first when queues fill.
  • Admission policy: a new virtual circuit is refused if it would cause congestion.
  • Traffic shaping: sources regulate their rate and bursts with the leaky bucket or token bucket.
  • Network-layer policies: routing that spreads the load, fair queueing and service, and packet lifetime management.

A traffic shaping approach for a packet-switched network PIN 1/27

Asked once

2066 Bhadra · Q4b6 marksPropose your best traffic shaping approach to manage congestion in packet switched network.

The best approach is a token bucket shaper followed by a leaky bucket that limits the peak rate, with policing at the network edge:

  1. Traffic contract: each source agrees an average rate r, a burst size C and, if needed, a peak rate p with the network.
  2. Token bucket shaping: tokens arrive at rate r up to C, and a packet leaves only by taking a token. Idle sources save tokens and may burst, but the average stays at r and the largest burst lasts S=C/(M−r) at line rate M.
  3. Leaky bucket after it: drains at the peak rate p (r < p < M), smoothing the burst so routers are not flooded.
  4. Policing at the edge router: conforming packets pass; excess packets are dropped or tagged low priority.
  5. Closed-loop support: TCP's congestion window and router signals (ECN, random early detection) handle any remaining congestion.
ONE BURST OF 12 MEGABITS THROUGH EACH BUCKET Line rate M = 10 Mbps. Leaky bucket r = 2 Mbps. Token bucket r = 2 Mbps with C = 6 Mb of tokens saved. 10 Mbps 0 (a) Input the burst 10 0 (b) Leaky bucket r = 2 Mbps 10 0 (c) Token bucket C = 6 Mb, r = 2 Mbps 10 Mbps for 1.2 s = 12 Mb 2 Mbps for 6 s = 12 Mb: smooth, but slow S = C / (M − r) = 6 / 8 = 0.75 s at 10 Mbps (7.5 Mb) then 2 Mbps; done at 3.0 s 0 1 2 3 4 5 6 time (s) Same area each time: 10 × 1.2 = 2 × 6 = 10 × 0.75 + 2 × 2.25 = 12 Mb.

Justification: with C = 6 Mb, r = 2 Mbps and M = 10 Mbps, a 12 Mb burst goes at 10 Mbps for 0.75 s and finishes in 3 s with no loss, whereas a 2 Mbps leaky bucket alone needs 6 s and drops what overflows. The average load stays predictable, bursts are bounded, idle capacity is used, and no packet is lost while the source keeps its contract.

6Application layer

Electronic mail: the sending and accessing protocols PIN 4/27

Asked 4 times

2074 Chaitra · Q75 marksWhich protocols are used in sending and receiving an email? Illustrate with necessary figure.

2072 Kartik · Q76 marksExplain different types of electronic mail sending and accessing protocol.

2070 Chaitra · Q76 marksWhat are the protocols used on it?

2068 Baishakh · Q85 marksExplain about electronic mail.

Electronic mail is an asynchronous message service built from user agents, mail servers and two kinds of protocol: a sending (push) protocol, SMTP, and accessing (pull) protocols, POP3 and IMAP.

THE INTERNET MAIL SYSTEM SMTP pushes the message from server to server; POP3 or IMAP pulls it out of the mailbox. Sita's user agent writes the mail Sender's mail server SMTP client (MTA) outgoing queue Receiver's server SMTP server, MDA Ram's mailbox Ram's user agent reads the mail SMTP port 587 SMTP port 25 POP3 / IMAP 110 / 143 DNS MX record of example.org PUSH: SMTP, started by the side that holds the mail PULL: Ram's agent asks The message waits in Ram's mailbox until his agent fetches it, so his computer need not be on when the mail arrives. With webmail the agent is a browser: HTTPS to the server, and SMTP between the servers as before.

Sending, SMTP (Simple Mail Transfer Protocol, TCP port 25; 587 for submission from a user agent): a text command and reply protocol. The client connects and sends HELO, MAIL FROM, RCPT TO and DATA (the message ends with a line holding "."), then QUIT. It pushes mail from the user agent to the sender's server and from server to server, in 7-bit ASCII, with MIME encoding attachments.

Accessing, POP3 (Post Office Protocol 3, TCP 110): the user agent logs in (USER, PASS), lists and downloads the messages (LIST, RETR) and usually deletes them from the server (DELE). Simple, and suited to one computer.

Accessing, IMAP (Internet Message Access Protocol, TCP 143): mail stays on the server in folders, message state is kept, the agent can fetch headers or single parts and search on the server, and many devices share one mailbox.

Webmail: the user agent is a browser talking HTTPS to the mail server, which still uses SMTP towards other servers.

Flow: sender's agent, SMTP, sender's server (queue), SMTP, receiver's server (mailbox), POP3 or IMAP, receiver's agent.

Socket programming: definition and fundamentals PIN 4/27

Asked 4 times

2082 Baishakh · Q104 marksSocket programming fundamentals

2075 Ashwin · Q76 marksDefine socket programming.

2074 Chaitra · Q104 marksSocket programming

2073 Shrawan · Q62 marksDefine socket programming.

Socket programming is writing network applications through the socket API, the interface between an application process and the transport layer. A socket is a communication endpoint identified by an IP address and a port number; programs create sockets and send and receive data through them with system calls.

Socket types: stream sockets (SOCK_STREAM) use TCP, a reliable connection (HTTP, FTP); datagram sockets (SOCK_DGRAM) use UDP, connectionless messages (DNS); raw sockets (SOCK_RAW) reach IP and ICMP directly (ping).

CallPurpose
socket()create an endpoint
bind()attach the local IP address and port (server)
listen()wait for connections, with a queue (server)
accept()take a connection, returning a new socket (server)
connect()open a connection to the server (client)
send(), recv()transfer data
close()release the connection
TCP SOCKETS: THE CALLS IN ORDER The server must be listening before the client connects; accept() returns a new socket for each client. SERVER CLIENT socket() create an endpoint bind() attach IP and port 5000 listen() become passive, queue of 5 accept() wait; return a new socket recv() read the request send() write the reply close() end this connection socket() create an endpoint connect() to 192.168.1.10, port 5000 send() write the request recv() read the reply close() end the connection three-way handshake connection set up request data reply data FIN and ACK each way No server listening on port 5000: the client's SYN is answered with RST, and connect() fails with "connection refused".

Sequence: the server calls socket, bind and listen, then blocks in accept; the client calls socket and connect, which performs TCP's three-way handshake; both then send and recv, and close. The server must run first, or the client's connect is refused.

DNS: what it is and why it is used PIN 3/27

Asked 3 times

2079 Bhadra · Q72+2 marksWhat is DNS? Why is it used?

2076 Chaitra · Q71 markWhat is DNS?

2071 Chaitra · Q72 marksWhat is DNS?

DNS (Domain Name System, RFC 1034 and 1035) is a distributed, hierarchical database of names, together with the application layer protocol for querying it, that maps host names such as www.ioe.edu.np to IP addresses and back. It runs mainly over UDP port 53; root, top-level domain and authoritative name servers hold the database, and local DNS servers (resolvers) query them for hosts and cache the answers.

Why it is used:

  • Names for people, numbers for machines: users type names, while IP routing needs numeric addresses.
  • Freedom to move: a server can change its IP address; only its DNS record changes.
  • Load distribution: one name can map to several servers.
  • Mail and aliases: MX records name a domain's mail servers; CNAME records define aliases.
  • Scale: no single host file could hold every name on the Internet.

Recursive and iterative DNS queries PIN 3/27

Asked 3 times

2080 Baishakh · Q76 marksExplain the recursive and iterative query.

2078 Bhadra · Q75 marksExplain the types of DNS queries with example.

2074 Ashwin · Q76 marksWhat is recursive and iterative query? Explain with suitable diagram.

DNS resolves names with two types of query, which differ in who does the work.

Recursive query: the server asked must return the final answer or an error; if it does not know the answer, it queries other servers itself and waits. Example, a host asking for www.youtube.com: the local server asks the root, the root asks the .com TLD server, the TLD asks youtube.com's authoritative server, and the address returns along the same chain.

RECURSIVE QUERY: WWW.YOUTUBE.COM Each server takes the whole job: it asks the next server itself and waits, and the answer comes back along the chain. Root server one of 13 names, a to m TLD server for .com a.gtld-servers.net Authoritative server ns1.google.com (youtube.com) Requesting host browser wants www.youtube.com Local DNS server the ISP's resolver, with a cache 1 8 2 7 3 6 4 5 Every server keeps state and waits for the server below it. That load is why root and TLD servers refuse recursion in practice: a host asks its local server recursively, and the local server works iteratively. THE EIGHT STEPS 1 Host asks the local server: address of www.youtube.com? 2 Local server passes the query to a root server 3 Root server passes it to the .com TLD server 4 TLD server passes it to youtube.com's server 5 Authoritative server returns the address to the TLD 6 TLD server returns it to the root server 7 Root server returns it to the local server 8 Local server caches it and answers the host

Iterative query: the server asked replies at once with the best it has, the answer or a referral to servers closer to it, and the asker continues. Example: the local server asks the root (referral to the .com servers), then a .com server (referral to ns1.google.com), then ns1.google.com, which returns the address.

ITERATIVE QUERY: WWW.YOUTUBE.COM The local server asks each server in turn; every server but the last replies with a referral, not the answer. Root server one of 13 names, a to m TLD server for .com a.gtld-servers.net Authoritative server ns1.google.com (youtube.com) Requesting host browser wants www.youtube.com Local DNS server the ISP's resolver, with a cache 1 8 2 3 4 5 6 7 Root and TLD reply with a referral: the next servers to ask. Only the authoritative server gives the answer. THE EIGHT STEPS 1 Host asks the local server: address of www.youtube.com? 2 Local server asks a root server 3 Root refers it to the .com TLD servers 4 Local server asks a .com TLD server 5 TLD refers it to youtube.com's servers (ns1.google.com) 6 Local server asks the authoritative server 7 Authoritative server answers with the A record 8 Local server caches it and returns it to the host
PointRecursiveIterative
Work done bythe server askedthe asker
Replyfinal answer or erroranswer or referral
Server loadhighlow
Usedhost to local serverlocal server to root, TLD, authoritative

In practice both are combined, since root and TLD servers refuse recursion. A third, older type, the inverse query, finds the name for an address; it is now an ordinary PTR lookup in in-addr.arpa.

POP3 compared with IMAP PIN 3/27

Asked 3 times

2080 Bhadra · Q74 marksCompare POP3 and IMAP protocols.

2076 Chaitra · Q73 marksCompare IMAP and POP3 protocols.

2074 Chaitra · Q73 marksGive a comparison of POP3 and IMAP.

POP3 and IMAP are both mail access (pull) protocols between a user agent and its mail server; they differ in where the mail is kept.

PointPOP3IMAP
PortTCP 110 (995 with TLS)TCP 143 (993 with TLS)
Mail storagedownloaded, usually deleted from the serverstays on the server
Foldersonly the inbox on the serverfolders created on the server
Devicessuits one devicesame mailbox on many devices
Statenone kept between sessionsread and flagged state kept
Partial downloadwhole messagesheaders or single parts
Searchon the local copyon the server
Complexitysimple, little server storagecomplex, more server storage

The proxy server: what it is and why it is used PIN 3/27

Asked 3 times

2081 Baishakh · Q74 marksWhat is a proxy server? Why is it used?

2075 Chaitra · Q72 marksWhy we need proxy servers?

2068 Baishakh · Q83 marksWhat is the function of proxy server?

A proxy server is an intermediary between clients and the servers they reach: clients send their requests to it, and it forwards them on their behalf and relays the replies. A caching proxy (web cache) keeps copies of recently fetched objects and serves repeat requests from its own storage.

A PROXY SERVER AS A WEB CACHE Clients send every request to the proxy; it answers from its cache when it can and asks the origin server only on a miss. CAMPUS LAN Client A browser Client B browser Proxy server web cache: copies of recent objects Origin server www.example.com 1 2 1 5 3 GET, or a conditional GET 4 the object, or 304 Not Modified access link to the Internet: slow, and paid for Hit (client A): 1, 2, served from the LAN at once. Miss (client B): 1, 3, 4, 5, and the proxy keeps a copy for the next client. Hit ratio = hits / requests: the higher it is, the less traffic crosses the access link.

Functions and uses:

  • Caching: a hit is served at LAN speed; a miss is fetched once, stored and forwarded; a stale copy is checked with a conditional GET (304 Not Modified).
  • Bandwidth saving: less traffic on the costly access link and less load on the origin servers.
  • Filtering and access control: blocking sites, or allowing them only at certain hours.
  • Privacy and security: it hides the clients' IP addresses, scans downloads and is the single controlled exit.
  • Logging: a record of web use; a reverse proxy also balances load.

The DNS server (domain name server) and its types PIN 2/27

Asked 2 times

2080 Baishakh · Q72 marksWhat is DNS server?

2072 Chaitra · Q104 marksDoman Name Server

A DNS server (name server) is a host running DNS software that stores part of the domain name database and answers queries about it, mainly over UDP port 53, translating host names into IP addresses and back. The servers form a hierarchy:

  • Root servers: know the servers of every top-level domain; 13 named root servers, a to m, copied worldwide.
  • TLD servers: know the name servers of every domain under com, org, np and the other top-level domains.
  • Authoritative servers: hold a zone's actual resource records (A, MX, NS and others); a primary server and secondaries kept in step by zone transfer.
  • Local DNS server (resolver): the ISP's or organization's server that hosts ask; it resolves names for them through the hierarchy and caches each answer for its TTL.
ITERATIVE QUERY: WWW.YOUTUBE.COM The local server asks each server in turn; every server but the last replies with a referral, not the answer. Root server one of 13 names, a to m TLD server for .com a.gtld-servers.net Authoritative server ns1.google.com (youtube.com) Requesting host browser wants www.youtube.com Local DNS server the ISP's resolver, with a cache 1 8 2 3 4 5 6 7 Root and TLD reply with a referral: the next servers to ask. Only the authoritative server gives the answer. THE EIGHT STEPS 1 Host asks the local server: address of www.youtube.com? 2 Local server asks a root server 3 Root refers it to the .com TLD servers 4 Local server asks a .com TLD server 5 TLD refers it to youtube.com's servers (ns1.google.com) 6 Local server asks the authoritative server 7 Authoritative server answers with the A record 8 Local server caches it and returns it to the host

Resource records in DNS PIN 2/27

Asked 2 times

2078 Bhadra · Q73 marksWhat are resource records in DNS?

2074 Ashwin · Q72 marksDiscuss the DNS records.

Resource records (RRs) are the entries of the DNS database: every zone is a set of RRs and every answer carries them. Each has the fields NAME, TYPE, CLASS (IN), TTL (seconds it may be cached) and RDATA (the value).

TypeHoldsExample
AIPv4 addresswww A 192.0.2.80
AAAAIPv6 addresswww AAAA 2001:db8::80
CNAMEan alias's real nameftp CNAME www
MXmail server, with preferenceMX 10 mail
NSthe zone's name serverNS ns1
PTRname for an addressreverse lookup
SOAprimary server, serial, timersone per zone
TXTtext: SPF, verification"v=spf1 mx -all"

The email server and its components PIN 2/27

Asked 2 times

2072 Kartik · Q72 marksWhat are the different components of email server?

2070 Chaitra · Q72 marksWhat do you mean by email server?

An email server (mail server) is a host that sends, receives and stores mail for a domain's users: it keeps a mailbox per user and a queue of outgoing mail, and the domain's MX record points other servers to it.

Components: the message transfer agent (MTA: SMTP client and server), the mail queue, the message delivery agent (MDA) with the mailboxes, and the message access agent (POP3 or IMAP server).

DNS recursive query compared with iterative query PIN 1/27

Asked once

2082 Bhadra · Q72 marksCompare DNS recursive query vs. iterative query.

PointRecursive queryIterative query
Workthe server asked finds the full answer itselfthe asker follows the referrals itself
Replyfinal answer or an erroranswer, or a referral to other servers
Server loadhigh: it waits and keeps statelow: it answers at once
Typical usehost to its local DNS serverlocal server to root, TLD and authoritative servers

DNS delegation PIN 1/27

Asked once

2081 Bhadra · Q72 marksWhat do you mean by DNS delegation?

DNS delegation is the handing over of authority for a subdomain (a child zone) by its parent zone to another set of name servers. The parent stores NS records for the child, plus glue A records when those servers lie inside the child, and refers queries to them. Example: the edu.np zone delegates ioe.edu.np to IOE's own name servers, which manage its names independently. Delegation is what makes DNS distributed.

The structure of the DNS request and response PIN 1/27

Asked once

2071 Chaitra · Q76 marksExplain the structure of DNS request and response with practical example.

A DNS request and its response share one format: a 12-byte header followed by four sections.

THE DNS MESSAGE One format for the query and the response: a 12-byte header, then four sections. 0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 Identification: the reply copies it QR Opcode AA TC RD RA Z RCODE QDCOUNT: number of questions ANCOUNT: number of answer records NSCOUNT: number of authority records ARCOUNT: number of additional records QR: 0 query, 1 response. AA: authoritative answer. TC: truncated. RD: recursion desired. RA: recursion available. Z: zero. RCODE: 0 no error, 3 the name does not exist (NXDOMAIN). FOUR SECTIONS AFTER THE HEADER Question QNAME www.example.com, QTYPE A, QCLASS IN Answer resource records that answer the question Authority NS records of the zone: a referral Additional helpful records, such as glue A records EVERY RESOURCE RECORD NAME variable TYPE 16 bits CLASS 16 bits TTL 32 bits RDLENGTH 16 bits RDATA variable The response keeps the ID and the question, sets QR to 1 and fills the answer; each travels in one UDP datagram to or from port 53.
  • Identification (16 bits): set by the client; the response copies it, matching replies to queries.
  • Flags (16 bits): QR (0 query, 1 response), Opcode (0 standard query), AA (authoritative answer), TC (truncated), RD (recursion desired), RA (recursion available), Z (zero), RCODE (0 no error, 3 name does not exist).
  • Four counts: QDCOUNT, ANCOUNT, NSCOUNT, ARCOUNT, the entries in each section.
  • Question section: QNAME, QTYPE (A, MX ...), QCLASS (IN).
  • Answer, authority and additional sections: resource records (name, type, class, TTL, length, data): the answers, the NS records of a referral, and extras such as glue addresses.

Practical example, resolving www.example.com:

Request:  ID=0x1A2B  QR=0 RD=1  QDCOUNT=1 ANCOUNT=0
                Question: www.example.com  A  IN          (33 bytes, UDP to port 53)
      Response: ID=0x1A2B  QR=1 RD=1 RA=1 RCODE=0  QDCOUNT=1 ANCOUNT=1
                Question: www.example.com  A  IN
                Answer:   www.example.com  3600  IN  A  192.0.2.80  (49 bytes)

The response repeats the ID and the question, sets QR to 1, and adds the answer record, valid for 3600 seconds.

The importance of DNS and HTTP(S) in browsing a website PIN 1/27

Asked once

2075 Chaitra · Q76 marksWhat are the importance of DNS and HTTP(S) while you are browsing any website?

Browsing needs both: DNS finds where the website is, and HTTP or HTTPS fetches what it shows.

Importance of DNS:

  • Name to address: the browser knows only the name in the URL; DNS returns the server's IP address, without which no connection can be opened.
  • Speed: resolvers cache answers for their TTL, so repeat visits skip the lookup.
  • Availability and load sharing: a name can map to several servers or to the nearest copy in a content delivery network.
  • Flexibility: a site can move to new servers without changing its name.

Importance of HTTP(S):

  • Fetching the page: HTTP requests (GET with headers) and responses (status code, headers, body) carry the HTML, images and scripts over TCP port 80.
  • Status and state: codes such as 200, 301 and 404 tell the browser what happened; cookies keep a login across stateless requests.
  • Security with HTTPS: TLS on port 443 authenticates the server by its certificate and encrypts and integrity-protects passwords, forms and payments.

Together: URL typed, DNS lookup, TCP connection, TLS handshake for HTTPS, HTTP GET, response, page rendered, further requests for the embedded objects.

SMTP and POP PIN 1/27

Asked once

2074 Ashwin · Q104 marksSMTP and POP

SMTP (Simple Mail Transfer Protocol) is the push protocol that sends mail: from the user agent to its mail server (port 587) and between mail servers (TCP port 25). It exchanges text commands and reply codes, HELO, MAIL FROM, RCPT TO, DATA (the message ending with "."), QUIT, and carries 7-bit ASCII, so MIME encodes attachments.

POP (Post Office Protocol, version 3, TCP port 110) is a pull protocol by which a user agent fetches mail from its mailbox on the server. A session has three states: authorization (USER, PASS), transaction (LIST, RETR, DELE) and update (deletions applied after QUIT). It works in download-and-delete or download-and-keep mode.

SMTP cannot fetch mail out of a mailbox, so the two work together: SMTP delivers the mail to the receiver's server, and POP3 brings it to the receiver's computer.

HTTP and HTTPS services PIN 1/27

Asked once

2081 Baishakh · Q74 marksDiscuss briefly on HTTP and HTTPS services.

HTTP (HyperText Transfer Protocol) is the web's application layer protocol: a stateless request and response protocol over TCP port 80. The browser sends a request (a method such as GET or POST, the URL, headers); the server returns a response (a status code such as 200 OK or 404, headers, the object). HTTP/1.1 keeps a connection open for several objects.

HTTPS is HTTP carried inside a TLS (formerly SSL) connection on TCP port 443. After a TLS handshake in which the server proves its identity with a certificate, every message is encrypted and integrity-checked.

PointHTTPHTTPS
Port80443
Securityplain textencrypted, server authenticated
Certificatenot neededneeded, from a certificate authority
URLhttp://https://
Usepublic, non-sensitive pageslogins, payments, modern sites

The HTTP protocol PIN 1/27

Asked once

2069 Chaitra · Q72 marksWhat is HTTP protocol?

HTTP (HyperText Transfer Protocol) is the application layer protocol of the World Wide Web. It is a stateless request and response protocol: a client, usually a browser, sends a request naming a resource by its URL with a method such as GET or POST, and a web server returns the resource with a status code. It runs over TCP, on port 80 by default (443 for HTTPS).

The web server PIN 1/27

Asked once

2073 Shrawan · Q104 marksWeb Server

A web server is a program that stores web content and delivers it to clients over HTTP or HTTPS. It listens on TCP port 80 (443 for HTTPS); common web servers are Apache httpd, Nginx and Microsoft IIS.

Serving a request: it accepts the TCP connection, parses the HTTP request, maps the URL path to a file in its document root (static content) or passes it to a program such as PHP that builds the page (dynamic content), and returns a response with a status code (200, 404, 500), headers and the body; then it logs the request.

Features: many clients served at once (threads, processes or an event loop), persistent connections, virtual hosting of many sites on one IP address through the Host header, access control, TLS for HTTPS, and caching and compression for speed.

TFTP PIN 1/27

Asked once

2076 Ashwin · Q72 marksWhat is TFTP?

TFTP (Trivial File Transfer Protocol, RFC 1350) is a minimal file transfer protocol over UDP port 69, with no login or authentication and no directory listing: it can only read or write a file. Data travels in numbered 512-byte blocks, each acknowledged before the next (stop and wait), and a shorter block ends the transfer. It is used to boot diskless machines and to load router and switch images.

Why computer networks need RAID PIN 1/27

Asked once

2068 Chaitra · Q22 marksWhy do we need RAID in the computer networks?

RAID is needed because network servers (web, mail, DNS, file, database) are shared by many users at once:

  • Availability: with mirroring or parity the server keeps running when a disk fails, and the data survives.
  • Performance: striping spreads reads and writes over several disks in parallel, serving many requests quickly.
  • Capacity: several disks form one large volume.

RAID 0, RAID 1 and RAID 5 and their differences PIN 1/27

Asked once

2068 Chaitra · Q26 marksDefine and discuss the differences between RAID 0, RAID 1 and RAID 5.

RAID (Redundant Array of Independent Disks) combines several physical disks into one logical volume for speed, fault tolerance or both.

RAID 0, RAID 1 AND RAID 5 One volume's blocks A1, A2, ... laid out on the disks; Ap, Bp, ... are parity blocks. RAID 0: striping Capacity: all n disks Speed: fastest reads and writes Fault tolerance: none One disk fails: all data lost RAID 1: mirroring Capacity: one disk of the pair Speed: fast reads, normal writes Fault tolerance: one failed disk Cost: twice the disks RAID 5: striping + parity Capacity: n - 1 disks Speed: fast reads, slower writes Fault tolerance: any one disk Rebuild: XOR of the others A1 A3 A5 A7 Disk 1 A2 A4 A6 A8 Disk 2 A1 A2 A3 A4 Disk 1 A1 A2 A3 A4 Disk 2 (copy) A1 B1 Cp D1 Disk 1 A2 Bp C1 D2 Disk 2 Ap B2 C2 Dp Disk 3
  • RAID 0 (striping): data blocks are spread alternately across all the disks. The capacity is the sum of the disks and reads and writes are fastest, but there is no redundancy: one failed disk loses all the data. At least 2 disks.
  • RAID 1 (mirroring): every block is written to two disks. The usable capacity is one disk; reads are fast and the array survives one disk failure; writes run at single-disk speed and the disk cost doubles. At least 2 disks.
  • RAID 5 (striping with distributed parity): data and parity blocks are striped across n disks, the parity rotating between them. The usable capacity is n minus 1 disks; any one failed disk is rebuilt by XOR of the others (D1 = 1011, D2 = 0110, D3 = 1100 give parity 0001; a lost D2 = 1011 XOR 1100 XOR 0001 = 0110). Writes are slower, since the parity must be updated. At least 3 disks.
PointRAID 0RAID 1RAID 5
Capacityn × SS(n minus 1) × S
Fault tolerancenoneone diskone disk
Speedfastestfast readsfast reads, slower writes
Usetemporary datasystem disks, small serversfile and web servers

7Introduction to IPv6

Transition strategies from IPv4 to IPv6 HOT 8/27

Asked 8 times

2080 Baishakh · Q86 marksBriefly explain the different transition strategies.

2078 Bhadra · Q86 marksExplain any two suitable transition strategies for IPv4 to IPv6.

2076 Ashwin · Q86 marksExplain any two transition strategies for IPv4 to IPv6.

2075 Ashwin · Q86 marksWhat are the methods used to interoperate IPv6 and IPv4.

2074 Chaitra · Q84 marksDefine the process of transition from IPv4 to IPv6.

2073 Shrawan · Q74 marksDefine the process of transition from IPv4 to IPv6.

2072 Kartik · Q86 marksWhat methods are used so that IPV6 and IPV4 networks are interoperable?

2071 Chaitra · Q84 marksExplain different strategies to transit from IPv4 and IPv6.

The transition from IPv4 to IPv6 is a gradual process with no switch-over day, since the two protocols are incompatible and billions of devices cannot change at once. Three strategies let the two coexist and interoperate:

THREE WAYS TO MOVE FROM IPV4 TO IPV6 Dual stack, tunneling and header translation: each answers a different situation. Dual stack both protocols on every node; DNS picks the version Tunneling IPv6 carried inside IPv4 across an IPv4-only region Header translation IPv6-only talks to IPv4-only; the header is rewritten IPv4-only host 192.0.2.33 Dual-stack host IPv4 + IPv6 stacks 2 addresses IPv6-only host 2001:db8:cafe::80 IPv4 IPv6 IPv6 host R1 IPv4-only network IPv4 header protocol 41 IPv6 header data R1 wraps, R2 unwraps R2 IPv6 host IPv6-only host phone, 2001:db8::20 IPv6 hdr data Translator NAT64: rewrites the header IPv4 hdr data IPv4-only server Order of use: dual stack wherever possible, tunnels to join IPv6 islands, translation once networks run IPv6 only.
  1. Dual stack: hosts and routers run IPv4 and IPv6 together, each interface holding both addresses. To reach a destination the host asks DNS: an AAAA record means IPv6, only an A record means IPv4. It is simple and native, but every node still needs an IPv4 address.
  2. Tunneling: when IPv6 nodes or networks are separated by an IPv4 region, the entry router puts the whole IPv6 packet inside an IPv4 packet (protocol 41) addressed to the exit router, which removes the IPv4 header. Tunnels are configured by hand or built automatically: 6to4, ISATAP, 6RD, Teredo.
  3. Header translation: when one side understands only IPv6 and the other only IPv4, a translator rewrites each header in the other version and maps the addresses (64:ff9b::192.0.2.33 to 192.0.2.33): SIIT, or NAT64 with DNS64.

Process: dual stack is deployed first wherever possible, tunnels join IPv6 islands across IPv4 networks, and translation serves networks that become IPv6-only, until IPv4 is no longer needed.

Advantages of IPv6 over IPv4 HOT 5/27

Asked 5 times

2080 Baishakh · Q82 marksWhat are the advantages of IPv6?

2078 Bhadra · Q82 marksList advantages of IPv6 over IPv4.

2076 Ashwin · Q82 marksList the advantages of IPv6 over IPv4.

2074 Ashwin · Q84 marksList the advantages of IPv6 over IPv4.

2068 Baishakh · Q74 marksWhat are the advantages of IPV6?

The main advantages of IPv6 over IPv4 are:

  1. Larger address space: 128-bit addresses, 2128≈3.4×1038, against 232 in IPv4, so every device can have a global address without NAT.
  2. Better header format: a fixed 40-byte header with no checksum and no fragmentation by routers, so it is processed faster.
  3. Extensibility: options sit in extension headers, so new features need no change to the base header.
  4. Smaller routing tables: hierarchical, aggregatable prefixes keep backbone routing efficient.
  5. Security: IPsec authentication (AH) and encryption (ESP) are defined as extension headers.
  6. Quality of service: the traffic class and flow label let routers give real-time audio and video special handling.
  7. Autoconfiguration: hosts configure their own addresses (SLAAC) without a DHCP server.
  8. Multicast and anycast: scoped multicast replaces broadcast; anycast reaches the nearest server.
  9. End-to-end connectivity and mobility: no NAT is needed, and Mobile IPv6 is supported.

Problems of IPv4 PIN 4/27

Asked 4 times

2079 Bhadra · Q82 marksWhat are the problems of IPV4?

2071 Chaitra · Q82 marksWhat are the problems of IPv4?

2071 Shrawan · Q82 marksWhat are the drawbacks in IPV4?

2070 Ashad · Q94 marksWhat are the major problems with existing IPv4 network?

IPv4 (RFC 791) was designed for a small research network and has these problems in today's Internet:

  1. Address exhaustion: 32-bit addresses give only 232, about 4.3 billion, far fewer than the devices in use; IANA's free pool ran out in February 2011.
  2. NAT: the workaround of private addresses behind NAT breaks end-to-end connectivity, peer-to-peer applications, VoIP and IPsec.
  3. Large routing tables: classful history and scattered allocations aggregate poorly.
  4. Complex header: a variable length of 20 to 60 bytes, options, a checksum recomputed at every hop and fragmentation by routers slow down forwarding.
  5. No built-in security: no authentication or encryption at the IP layer.
  6. Weak real-time support: no way to identify a flow of audio or video for special handling.
  7. Manual configuration: addresses are set by hand or by a DHCP server.
  8. Broadcast: ARP and other broadcasts disturb every host on the link.

How IPv6 solves the problems of IPv4 PIN 3/27

Asked 3 times

2079 Bhadra · Q82 marksHow can IPV6 reduce these problems?

2071 Chaitra · Q82 marksHow IPv6 reduce these problems?

2071 Shrawan · Q86 marksWhich of these drawbacks do IPV6 solve? Explain.

IPv6 reduces or removes most of the drawbacks of IPv4:

IPv4 drawbackHow IPv6 solves it
Address exhaustion: only 232 addresses128-bit addresses, 2128≈3.4×1038; one /64 subnet alone holds 264
NAT breaks end-to-end connectivityevery device gets a global address, so NAT is unnecessary
Slow, variable header with a checksumfixed 40-byte header: no checksum, no options, no fragmentation by routers
Large routing tableshierarchical prefixes (registry, ISP, site /48, subnet /64) aggregate into few routes
No IP-layer securityIPsec AH and ESP defined as extension headers
Poor real-time supporttraffic class and a 20-bit flow label identify flows for special handling
Manual or DHCP configurationstateless autoconfiguration (SLAAC) and easy renumbering; DHCPv6 optional
Broadcast loadno broadcast: scoped multicast and anycast
Rigid optionsextension headers add features without changing the base header

Not fully solved: IPv6 is not compatible with IPv4, so the two must coexist through dual stack, tunneling and translation for years; IPsec is now recommended rather than mandatory (RFC 6434); and routing tables stay small only if providers aggregate their prefixes.

Factors behind the development of IPv6 PIN 3/27

Asked 3 times

2074 Chaitra · Q84 marksWhat are the factors that lead to the speedy development of IPv6?

2073 Shrawan · Q74 marksWhat are the factors that lead to the development of IPv6?

2066 Bhadra · Q5a2 marksGive the reason why the current world is moving to IPv6 addressing mechanism.

The factors that led to the speedy development of IPv6, and the reasons the world is now moving to it:

  1. Address exhaustion: the rapid growth of the Internet showed the IETF in the early 1990s that 32-bit addresses would run out; IANA's pool did run out in 2011, and APNIC, which serves Nepal, reached its last block in April 2011.
  2. New devices: smartphones, always-on broadband and IoT sensors each need an address, above all in developing countries now coming online.
  3. Limits of NAT: carrier-grade NAT is costly and breaks end-to-end applications.
  4. Real-time multimedia: audio and video need quality of service support.
  5. Security: the need for authentication and encryption at the IP layer.
  6. Efficiency: simpler headers, smaller routing tables, autoconfiguration and mobility.
  7. Industry push: at World IPv6 Launch (6 June 2012) major websites and ISPs switched IPv6 on permanently, and mobile operators now run IPv6-only networks.

The IPv6 datagram format and the function of each field PIN 3/27

Asked 3 times

2075 Ashwin · Q82 marksShow IPv6 datagram format.

2070 Chaitra · Q88 marksExplain the IPv6 datagram format with appropriate figures.

2069 Chaitra · Q88 marksExplain the IPv6 datagram format and the function of each field with necessary figure.

An IPv6 datagram consists of a fixed 40-byte base header followed by the payload: zero or more extension headers and then the upper-layer data (a TCP segment, a UDP datagram or an ICMPv6 message). The payload may be up to 65,535 bytes, or more with the jumbo payload option.

THE IPV6 BASE HEADER RFC 8200: eight fields in a fixed 40 bytes, drawn 32 bits wide; the payload follows it. BIT 0 4 12 16 24 31 Version 4 bits, = 6 Traffic class 8 bits: DSCP + ECN Flow label 20 bits: marks the packets of one flow Payload length 16 bits: bytes after the base header Next header 8 bits: 6 TCP, 17 UDP Hop limit 8 bits: the TTL renamed Source address 128 bits, four rows of 32: the sender, such as 2001:db8:acad:1::20 Destination address 128 bits: the receiver, or the next node named in a routing header 0 4 8 24 40 BYTE OFFSET 40 bytes fixed THE WHOLE PACKET Base header, 40 bytes Extension headers (optional) Upper layer: TCP, UDP, ICMPv6 payload: up to 65,535 bytes, as counted by the payload length field

Function of each field:

  1. Version (4 bits): the IP version, 6 (0110).
  2. Traffic class (8 bits): the priority or class of service of the packet: a 6-bit DSCP for differentiated services and 2 ECN bits for congestion notification; it replaces IPv4's type of service.
  3. Flow label (20 bits): set by the source to identify the packets of one flow, such as a video call, so routers can give them the same handling without reading the transport header; 0 when unused.
  4. Payload length (16 bits): the length in bytes of everything after the base header (extension headers and data); the 40-byte base header is not counted.
  5. Next header (8 bits): the type of header that follows: an extension header (0 hop-by-hop, 43 routing, 44 fragment, 51 AH, 50 ESP, 60 destination options) or the upper-layer protocol (6 TCP, 17 UDP, 58 ICMPv6).
  6. Hop limit (8 bits): lowered by 1 at each router; at 0 the packet is discarded and an ICMPv6 Time Exceeded message is sent; it is IPv4's TTL renamed.
  7. Source address (128 bits): the IPv6 address of the sender.
  8. Destination address (128 bits): the IPv6 address of the receiver, or of the next node listed when a routing header is present.
4+8+20+16+8+8+128+128=320 bits=40 bytes

Features of the format: the fixed size and 64-bit alignment allow fast hardware processing; there is no header checksum (the link and transport layers detect errors), no fragmentation fields (only the source fragments, using a fragment extension header), and no options (moved to extension headers, chained by the next header field).

The dual stack method PIN 3/27

Asked 3 times

2081 Baishakh · Q84 marksExplain the dual stack strategy to transit from IPv4 to IPv6.

2080 Bhadra · Q104 marksb) Dual Stack method in IPv6

2076 Chaitra · Q85 marksExplain Dual stack approach with an appropriate figure.

Dual stack (RFC 4213) is the transition strategy in which a node implements both IPv4 and IPv6, so it talks to IPv4-only nodes in IPv4 and to IPv6 nodes in IPv6 until the whole Internet uses IPv6.

DUAL STACK: ONE HOST, TWO NETWORK LAYERS RFC 4213: the node runs IPv4 and IPv6 side by side and speaks to each host in its own version. DUAL-STACK HOST Application browser, mail, games Transport TCP, UDP IPv4 192.168.1.20 for A records IPv6 2001:db8:acad:1::20 for AAAA records Link layer Ethernet or Wi-Fi, one card both network layers share the link IPv4-only server 192.0.2.33 DNS has only an A record IPv6 server 2001:db8:cafe::80 DNS has an AAAA record IPv4 IPv6 HOW THE HOST CHOOSES THE VERSION Ask DNS for A and AAAA AAAA found? use IPv6, tried first only an A? use IPv4 IPv6 fails? fall back to IPv4 fast Happy Eyeballs (RFC 8305) races the two so a broken IPv6 path costs the user almost nothing.
  • Structure: one application and transport layer (TCP, UDP) sits over two network layers, IPv4 and IPv6, sharing the same link layer; each interface holds an IPv4 address and an IPv6 address.
  • Choosing the version: the source queries DNS; an AAAA record means it sends IPv6, only an A record means IPv4. Modern hosts try IPv6 first and fall back to IPv4 quickly (Happy Eyeballs).
  • Routers: dual-stack routers forward both protocols, with two routing tables and two sets of routing protocols (OSPFv2 and OSPFv3).
  • Advantages: simple, native performance, no encapsulation or translation, and services move to IPv6 one by one.
  • Disadvantages: every node still needs an IPv4 address, and two stacks double the configuration, security policy and memory.

IPv4 header compared with IPv6 header PIN 2/27

Asked 2 times

2081 Baishakh · Q84 marksCompare the IPv4 header with IPv6 header.

2072 Chaitra · Q74 marksCompare the header fields of IPV6 and IPV4.

The IPv6 header is a fixed 40 bytes with 8 fields; the IPv4 header is 20 to 60 bytes with 12 fields plus options. Field by field:

IPV4 HEADER AGAINST IPV6 HEADER Same scale, 32 bits wide: what IPv6 kept, renamed, removed and added. IPV4 HEADER: 20 TO 60 BYTES IPV6 HEADER: 40 BYTES, FIXED Version kept IHL removed Type of service renamed Total length now payload length Identification removed: fragment header Flags Fragment offset removed Time to live now hop limit Protocol now next header Header checksum removed Source address, 32 bits kept, grows to 128 bits Destination address, 32 bits kept, grows to 128 bits Options + padding, 0 to 40 bytes removed: extension headers instead Version kept Traffic class was TOS Flow label added, 20 bits Payload length was total length Next header was protocol Hop limit was TTL Source address 128 bits Destination address 128 bits kept renamed removed added in IPv6 IPv4: 12 fields plus options, 20 to 60 bytes. IPv6: 8 fields in 40 bytes, so the addresses grow four times but the header only twice.
IPv4 fieldIn IPv6
Versionkept (value 6)
Header length (IHL)removed: the length is fixed
Type of servicerenamed traffic class
Total lengthrenamed payload length (excludes the header)
Identification, flags, fragment offsetremoved: moved to the fragment extension header
Time to liverenamed hop limit
Protocolrenamed next header
Header checksumremoved
Source, destination (32 bits each)kept, 128 bits each
Options and paddingremoved: extension headers instead
Noneadded: flow label (20 bits)

The result: addresses four times longer, a header only twice as long, and faster processing at every router.

IPv6 address types and their notation PIN 2/27

Asked 2 times

2080 Bhadra · Q83 marksExplain the three address types in IPv6 with the IP notations.

2066 Bhadra · Q5a2 marksDescribe the IPv6 address types with its representation format.

An IPv6 address is 128 bits, written as eight groups of four hexadecimal digits separated by colons; leading zeros in a group may be dropped and one run of zero groups replaced by ::, so 2001:0db8:0000:0000:0000:ff00:0042:8329 is written 2001:db8::ff00:42:8329. A prefix takes a slash: 2001:db8:acad:1::/64.

TypeDelivered toNotation
Unicastone interfaceglobal 2000::/3, link-local fe80::/10, unique local fc00::/7
Anycastthe nearest of a grouptaken from unicast space, such as 2001:db8:acad:1::
Multicastevery member of a groupff00::/8, such as ff02::1

IPv6 has no broadcast.

IPV6 ADDRESS LAYOUTS 128 bits each, widths not to scale; the first bits decide the type. Global unicast 2000::/3 Global routing prefix 48 bits (typical), from the ISP Subnet ID 16 bits Interface ID 64 bits e.g. 2001:db8:acad:1:200:5eff:fe00:5301 (site /48, subnet 1) Link-local fe80::/10 1111111010 10 bits all zero 54 bits Interface ID 64 bits e.g. fe80::200:5eff:fe00:5301 (one link only, never routed) Unique local fc00::/7 fd 8 bits Global ID, random 40 bits Subnet ID 16 bits Interface ID 64 bits e.g. fd4b:91c2:7e33:1::10 (private, like 10.0.0.0/8) Multicast ff00::/8 ff 8 bits flags 4 bits scope 4 bits Group ID 112 bits e.g. ff02::1, all nodes on this link (no broadcast in IPv6) IPv4-mapped ::ffff:0:0/96 all zero 80 bits ffff 16 bits IPv4 address 32 bits e.g. ::ffff:192.0.2.33, written in hexadecimal ::ffff:c000:221 Anycast: a unicast address given to several interfaces; routing delivers to the nearest. Subnet-router anycast = prefix + ID 0. Also: :: unspecified, ::1 loopback, 2001:db8::/32 documentation, fec0::/10 site-local (deprecated, RFC 3879). Written as eight groups of four hex digits: drop leading zeros, and replace one run of zero groups by :: (once only).

What IPv4 and IPv6 coexistence means PIN 2/27

Asked 2 times

2076 Chaitra · Q83 marks"IPv4 and IPv6 coexistence" what does this mean?

2075 Chaitra · Q83 marks“IPv4 and IPv6 coexistence” what does this mean?

IPv4 and IPv6 coexistence means both protocols running side by side on the same Internet, often on the same hosts, links and routers, during the long transition. The two are not compatible: an IPv4-only node cannot read an IPv6 packet. Since billions of devices cannot change on one day, IPv4-only, IPv6-only and dual-stack nodes must all keep communicating. Coexistence is achieved by dual stack (nodes run both), tunneling (IPv6 carried inside IPv4 across IPv4 networks) and header translation (IPv6-only and IPv4-only nodes talking through a translator), until IPv4 can be switched off.

What IPv6 is PIN 1/27

Asked once

2072 Kartik · Q82 marksWhat is IPV6?

IPv6 (Internet Protocol version 6) is the network layer protocol designed by the IETF to replace IPv4 (RFC 8200). Like IPv4 it delivers datagrams connectionlessly from source to destination, but it uses 128-bit addresses (2128 of them), a fixed 40-byte header with extension headers for options, stateless autoconfiguration, multicast and anycast in place of broadcast, and support for IPsec and flow labels.

IPv4 and IPv6 compared in routing and header manipulation PIN 1/27

Asked once

2081 Bhadra · Q84 marksCritically compare IPv4 and IPv6 in terms of routing and head manipulation.

PointIPv4IPv6
Header at each routervariable 20 to 60 bytes; IHL read first; options processedfixed 40 bytes; extension headers skipped, except hop-by-hop
Checksumverified and recomputed at every hop after the TTL changenone; only the hop limit is lowered
Fragmentationrouters fragment oversized packetsonly the source; routers send ICMPv6 Packet Too Big
Address rewritingNAT rewrites addresses, ports and checksumsNAT not needed; addresses stay end to end
Routing tablelarge, poorly aggregatedhierarchical prefixes aggregate
Flow handlingport numbers read deep in the packetflow label in the header
ProtocolsRIP, OSPFv2, BGP; ARPRIPng, OSPFv3, MP-BGP; neighbour discovery

Critically: IPv6 makes per-hop header manipulation much lighter, but 128-bit lookups need more router memory, packets with extension headers (hop-by-hop above all) take a slow path and are often dropped, dual-stack routers carry two routing tables during the transition, and filtering ICMPv6 breaks path MTU discovery.

IPv6 extension headers in order PIN 1/27

Asked once

2082 Bhadra · Q82 marksList the IPv6 extension headers in order.

The IPv6 extension headers follow the base header in this recommended order (RFC 8200), each named by the next header field of the header before it:

  1. Hop-by-hop options (0)
  2. Destination options, for the routing-header nodes (60)
  3. Routing (43)
  4. Fragment (44)
  5. Authentication header, AH (51)
  6. Encapsulating security payload, ESP (50)
  7. Destination options, for the final destination (60)
  8. Upper-layer header: TCP (6), UDP (17), ICMPv6 (58)

An IPv4 address mapped to its IPv6 equivalent PIN 1/27

Asked once

2082 Baishakh · Q82 marksMap IPv4 addresses with its IPv6 equivalent.

An IPv4 address is written in IPv6 as an IPv4-mapped IPv6 address: 80 zero bits, 16 one bits, then the 32-bit IPv4 address, written ::ffff:a.b.c.d. For example, 192.0.2.33 becomes ::ffff:192.0.2.33, in hexadecimal ::ffff:c000:221 (192 = c0, 0 = 00, 2 = 02, 33 = 21). Dual-stack sockets and translators use this form; NAT64 uses 64:ff9b::c000:221.

Header translation and tunneling PIN 1/27

Asked once

2074 Ashwin · Q84 marksExplain header translation and tunneling approach used for migrating IPv4 to IPv6.

Tunneling carries IPv6 traffic across an IPv4-only network. The router at the tunnel entry encapsulates the complete IPv6 packet as the payload of an IPv4 packet (protocol field 41) addressed to the tunnel exit, where the IPv4 header is removed and the IPv6 packet continues. The IPv4 routers in between treat it as ordinary IPv4. Tunnels are manual or automatic (6to4, ISATAP, 6RD).

Header translation is used when one end understands only IPv6 and the other only IPv4. A translator rewrites each IPv6 header as an IPv4 header and back: the IPv4 address is taken from the last 32 bits of the mapped IPv6 address, hop limit becomes TTL, next header becomes protocol, the flow label is dropped and a checksum is computed (NAT64 with DNS64).

THREE WAYS TO MOVE FROM IPV4 TO IPV6 Dual stack, tunneling and header translation: each answers a different situation. Dual stack both protocols on every node; DNS picks the version Tunneling IPv6 carried inside IPv4 across an IPv4-only region Header translation IPv6-only talks to IPv4-only; the header is rewritten IPv4-only host 192.0.2.33 Dual-stack host IPv4 + IPv6 stacks 2 addresses IPv6-only host 2001:db8:cafe::80 IPv4 IPv6 IPv6 host R1 IPv4-only network IPv4 header protocol 41 IPv6 header data R1 wraps, R2 unwraps R2 IPv6 host IPv6-only host phone, 2001:db8::20 IPv6 hdr data Translator NAT64: rewrites the header IPv4 hdr data IPv4-only server Order of use: dual stack wherever possible, tunnels to join IPv6 islands, translation once networks run IPv6 only.

ISATAP and 6to4 tunneling with their address formats PIN 1/27

Asked once

2082 Bhadra · Q86 marksExplain ISATAP and 6 to 4 tunneling with their address format for IPv4 to IPv6 transition.

Both are automatic tunnels: the IPv4 end of the tunnel is read from inside the IPv6 address, so no tunnel is configured by hand. IPv6 packets travel inside IPv4 packets with protocol number 41.

AUTOMATIC TUNNELS: THE IPV4 ADDRESS INSIDE THE IPV6 ADDRESS Widths not to scale. Reading the IPv4 endpoint out of the address is what makes a tunnel automatic. 6to4 RFC 3056 2002 16 bits IPv4 of the site router 32 bits, public Subnet ID 16 bits Interface ID 64 bits 192.0.2.4 = c000:0204, so the site prefix is 2002:c000:204::/48 ISATAP RFC 5214 64-bit prefix fe80:: or from the ISATAP router 0000 or 0200 private or global 5efe 16 bits IPv4 of the host 32 bits 10.1.1.5 gives fe80::5efe:a01:105 and 2001:db8:acad:5:0:5efe:a01:105 6RD RFC 5969 ISP's 6rd prefix n bits, its own IPv4 of the CE 32 bits minus common Subnet ID the rest Interface ID 64 bits 2001:db8::/32 + 203.0.113.5 (cb00:7105) gives the customer 2001:db8:cb00:7105::/64 Teredo RFC 4380 2001:0000 32 bits Teredo server IPv4 32 bits flags 16 bits client port 16, obscured client public IPv4 32 bits, obscured IPv6 inside UDP (port 3544) inside IPv4, to cross a NAT: a last resort, now retired 6to4 and Teredo use fixed prefixes and public relays; 6RD is 6to4 rebuilt inside one ISP with its own prefix and relays. ISATAP works inside one site; the u bit (0200) says the embedded IPv4 address is globally unique. All four carry IPv6 in IPv4 with protocol 41, except Teredo, which uses UDP to pass through NAT.

6to4 (RFC 3056) connects IPv6 sites across the IPv4 Internet. A site whose router has the public IPv4 address 192.0.2.4 (c000:0204) gets the prefix 2002:c000:204::/48.

  • Format: 2002 (16 bits) | IPv4 address of the site router (32) | subnet ID (16) | interface ID (64).
  • Operation: to reach another 6to4 site the router copies the IPv4 address out of bits 17 to 48 of the destination and tunnels straight to it; to reach native IPv6 it tunnels to a 6to4 relay router.

ISATAP (RFC 5214), the Intra-Site Automatic Tunnel Addressing Protocol, connects dual-stack hosts inside an IPv4-only site, treating the IPv4 network as one link.

  • Format: 64-bit prefix | 0000:5efe (private IPv4) or 0200:5efe (global IPv4) | IPv4 address of the host (32): host 10.1.1.5 gets fe80::5efe:a01:105.
  • Operation: the host sends a router solicitation tunnelled in IPv4 to the ISATAP router, receives the prefix and forms its global address; it tunnels directly to other ISATAP hosts at the IPv4 address in the last 32 bits, and through the ISATAP router to the rest of the IPv6 Internet.

The latest IPv6 transition methods, with one explained PIN 1/27

Asked once

2082 Baishakh · Q82+4 marksWhat are the latest best IPv6 transition methodologies? Explain anyone of them.

Current best practice (RFC 6180) is dual stack wherever both protocols can run and, where IPv4 addresses are scarce, IPv6-only networks that carry IPv4 as a service:

  • Dual stack with Happy Eyeballs: native IPv4 and IPv6 together.
  • NAT64 with DNS64 (RFC 6146, RFC 6147): IPv6-only clients reach IPv4-only servers.
  • 464XLAT (RFC 6877): IPv4 applications on IPv6-only mobile networks.
  • DS-Lite (RFC 6333): IPv4 tunnelled inside IPv6 to the ISP's carrier-grade NAT.
  • MAP-E and MAP-T (RFC 7597, RFC 7599): stateless IPv4 address and port sharing over IPv6.
  • 6RD (RFC 5969): IPv6 over an ISP's IPv4 network.

464XLAT explained: on an IPv6-only mobile network, an IPv4-only application on the phone still sends IPv4 packets. The CLAT (customer-side translator) on the phone translates them statelessly into IPv6, embedding the IPv4 destination in the NAT64 prefix (192.0.2.33 becomes 64:ff9b::c000:221). The IPv6 packets cross the operator's network to the PLAT, a stateful NAT64, which translates them back into IPv4 from its shared public address. Replies return the same way, so IPv4 applications work while the network itself runs no IPv4.

The method to suggest for migration, and why PIN 1/27

Asked once

2072 Chaitra · Q74 marksWhich method do you suggest for the migration of IPv6 and why?

Dual stack is the method to suggest, with tunneling and translation only where dual stack is impossible.

  • Native for both: each node speaks IPv4 to IPv4 hosts and IPv6 to IPv6 hosts, with no encapsulation overhead and no translation side effects.
  • Gradual: services move to IPv6 one at a time, DNS records decide which protocol is used, and IPv4 is switched off later without a flag day.
  • Simple and reliable: no relays or translators to fail; it is the IETF's recommended first step (RFC 6180).

Its limit is that every node still needs an IPv4 address. So an organisation short of IPv4 addresses runs IPv6-only inside, with NAT64 and DNS64 (464XLAT on phones) for IPv4 content, and an IPv6 site cut off by an IPv4 network uses a tunnel (6RD from its ISP) until native IPv6 arrives.

8Network security

The types of firewall, with figures HOT 7/27

Asked 7 times

2081 Baishakh · Q104 marksc) Firewall

2076 Ashwin · Q104 marksa) Firewall and their types

2074 Chaitra · Q104 marksi) Types of firewals

2073 Shrawan · Q96 marksExplain different types of firewall.

2072 Chaitra · Q8and also explain different types of Firewall. Illustrate your answer with appropriate figures.

2072 Kartik · Q91 markWhat are their types?

2070 Chaitra · Q9and also explain different types of Firewall. Illustrate your answer with appropriate figures.

A firewall controls the traffic between a trusted network and an untrusted one by a security policy. By the layer it inspects, there are four main types:

FIREWALL TYPES, BY THE LAYER THEY INSPECT The higher the layer a firewall reads, the more it understands, and the more each packet costs it. Application Session Transport (TCP, UDP) Network (IP) Data link, physical Application gateway (proxy) reads the content (URLs, FTP commands, mail); one proxy per service; slowest, safest Circuit-level gateway checks the TCP handshake, then relays the connection without reading it (SOCKS) Stateful inspection a packet filter with a connection table: replies get in only for connections already open Packet filter (router ACL) each packet alone, by its IP and TCP/UDP headers: addresses, protocol, ports; fastest Up the stack: more inspection and more security, but more processing delay. A next-generation firewall (NGFW) combines them, adding application awareness and intrusion prevention.
  1. Packet filtering firewall: a router or host that checks each packet on its own against a rule table, by source and destination IP address, protocol, port numbers and direction; the first matching rule permits or denies it, and an implicit deny drops the rest. It is fast, cheap and transparent, but keeps no state, reads no content and cannot detect a spoofed address.
  2. Stateful inspection firewall: a packet filter that also keeps a table of open connections and admits an inbound packet only if it belongs to one, so forged replies are dropped.
  3. Application-level gateway (proxy): works at the application layer; the client connects to the proxy, which checks the request (URL, FTP command, mail attachment, user) and opens its own connection to the server. It is the most secure and logs everything, but it is slower and needs a proxy for each service.
  4. Circuit-level gateway: works at the session layer; it validates the TCP handshake and then relays the connection without reading the data, as SOCKS does.
HOW A PACKET FILTER WORKS: EACH PACKET AGAINST THE RULES, TOP DOWN The first rule that matches decides; when none matches, the packet is dropped. A packet arrives Read its header IPs, protocol, ports, direction Rule k matches? yes Do its action permit: forward deny: drop no More rules? yes: k + 1 no Implicit deny: drop it no rule matched A HOSTEL ROUTER'S RULES # Source Destination Port Action 1 203.0.113.0/24 any any deny 2 any 192.168.10.0/24 TCP 23 deny 3 any 192.168.10.5 TCP 443 permit 4 192.168.10.0/24 any TCP 80, 443 permit 5 any any any deny THREE PACKETS, TRACED 1. 198.51.100.7 to 192.168.10.5, TCP 443: rules 1 and 2 miss, rule 3 matches: permit 2. 203.0.113.9 to 192.168.10.5, TCP 443: rule 1 matches first: deny 3. 198.51.100.7 to 192.168.10.20, TCP 23: rule 2 matches: deny (Telnet blocked) Order matters: the first match decides, and every list ends in an implicit deny.

A next-generation firewall combines these with intrusion prevention and application awareness.

The properties of secure communication HOT 5/27

Asked 5 times

2080 Bhadra · Q92 marksWhat are the properties of secure communication?

2076 Chaitra · Q104 marksExplain briefly the desirable properties of secure communication.

2076 Ashwin · Q92 marksList the properties of secure communication.

2075 Chaitra · Q94 marksExplain briefly the desirable properties of secure communication.

2074 Ashwin · Q94 marksExplain briefly the desirable properties of secure communication.

Secure communication between a sender and a receiver over an insecure network needs six properties:

  1. Confidentiality: only the sender and the intended receiver can understand the message; provided by encryption.
  2. Integrity: the message is not altered in transit, by accident or by an attacker; provided by hashes, MACs and digital signatures.
  3. Authentication: each party can confirm the identity of the other, and that a message really came from its claimed sender.
  4. Non-repudiation: the sender cannot later deny having sent the message; provided by digital signatures.
  5. Availability: the network and its services stay usable by authorised users when needed, despite attacks such as denial of service.
  6. Access control: only authorised users reach a resource, and only with the rights they hold; enforced by firewalls, ACLs and permissions.
FOUR ATTACKS ON A MESSAGE, AND THE PROPERTY EACH BREAKS A sends to B; the intruder T interrupts, intercepts, modifies or fabricates. Interruption A B the message never arrives Violates: availability cut cable, DoS flood Interception A B T the intruder reads a copy Violates: confidentiality sniffing open Wi-Fi Modification A B T changed on the way Violates: integrity Rs 500 made Rs 5,000 Fabrication A B T sent as if from A Violates: authentication fake mail 'from the bank' Passive attack: interception, which only reads, so it is hard to detect; encryption prevents it. Active attacks: interruption, modification and fabrication (and replay, denial of service): detect them and recover.

Each property answers an attack: interception breaks confidentiality, modification integrity, fabrication authentication, and interruption availability.

What network security is PIN 4/27

Asked 4 times

2071 Chaitra · Q42 marksWhat is network security?

2070 Chaitra · Q103 marksWhat do you mean by Network security?

2069 Chaitra · Q102 marksWhat is network security?

2068 Chaitra · Q95 marksa) Network Security

Network security is the set of policies, practices and technologies that protect a network and the data crossing it from unauthorised access, misuse, modification and disruption, so that a sender and a receiver can communicate securely over an insecure medium such as the Internet.

An intruder on the path may intercept (read), interrupt (block), modify or fabricate messages, passively or actively. Network security therefore provides:

  • Confidentiality by encryption;
  • Integrity by hashes and MACs;
  • Authentication and non-repudiation by passwords, certificates and digital signatures;
  • Availability by redundancy and protection against denial of service;
  • Access control by firewalls and ACLs.

It is applied at every layer: PGP for e-mail, SSL/TLS for TCP connections, IPsec and VPNs for IP packets, WPA2 for wireless LANs, with firewalls and intrusion detection systems at the boundary. For example, an online banking session is encrypted by TLS, the bank's server proves its identity with a certificate, and the bank's firewall admits only HTTPS traffic to its web server.

Virtual private network (VPN), with an example PIN 4/27

Asked 4 times

2082 Bhadra · Q104 marksc) VPN

2079 Bhadra · Q104 marksc) VPN

2075 Chaitra · Q104 marksb) VPN

2071 Chaitra · Q44 marksExplain Virtual Private Network (VPN) with an example.

A VPN (virtual private network) is a private network over a public one, created by tunnelling: each packet is encrypted, authenticated and carried inside a new packet between the VPN endpoints.

  • Working: the endpoints authenticate each other and agree keys; outgoing packets are encrypted and wrapped with a header addressed to the far gateway; the Internet routes them; the far gateway decrypts and delivers them.
  • Remote-access VPN: a user's device connects to the organisation's gateway through VPN client software.
  • Site-to-site VPN: gateways join whole LANs, as an intranet (one organisation) or an extranet (partners).
  • Protocols: IPsec, SSL/TLS (OpenVPN), L2TP over IPsec, WireGuard.
VPN: A PRIVATE TUNNEL ACROSS THE PUBLIC INTERNET Site to site joins two LANs through their gateways; remote access joins one laptop to the office. THE INTERNET (PUBLIC) Head office LAN Kathmandu 192.168.1.0/24 Branch LAN Pokhara 192.168.2.0/24 VPN gateway VPN gateway site-to-site IPsec tunnel encrypted, authenticated Remote user laptop with a VPN client remote-access tunnel (TLS or IPsec), from home INSIDE A TUNNEL new IP hdr ESP orig. packet gateway to gateway encrypted Cheaper than a leased line, and private: an eavesdropper on the Internet sees only gateway addresses and ciphertext.

Example: a company's head office in Kathmandu and its branch in Pokhara join their LANs through an IPsec tunnel over ordinary Internet links; it costs far less than a leased line and keeps the traffic private.

How firewalls protect a network and enhance its security PIN 3/27

Asked 4 times, in 3 papers

2072 Chaitra · Q8Explain briefly how firewalls protect network

2070 Chaitra · Q9Explain briefly how firewalls protect network

2069 Chaitra · Q102 marksHow can firewalls enhance network security?

2069 Chaitra · Q104 marksExplain how firewalls can protect a system.

A firewall protects a network by standing at its only gateway to the outside, so that every packet in or out crosses one point where the security policy is enforced:

  • Choke point: all traffic passes through one place, where it is checked and logged.
  • Filtering: packets from unwanted addresses, ports and protocols (Telnet, remote desktop) are blocked; whatever is not explicitly allowed is denied.
  • Stateful control: inbound packets are admitted only as replies to connections opened from inside.
  • Hiding the inside: NAT and proxies hide internal addresses and hosts.
  • Content control: a proxy blocks malware, banned sites and dangerous commands, and authenticates users.
  • Zones and alerts: public servers sit in a DMZ, apart from the trusted LAN; floods and attacks are logged and reported.
WHERE THE FIREWALL, THE DMZ AND THE IDS SIT The firewall is the one gate between three zones; the IDS watches what passes it. Internet untrusted Border router ACL filter Firewall stateful or NGFW DMZ: PUBLIC SERVERS, LIMITED TRUST switch Web server Mail server HIDS HIDS INSIDE: THE TRUSTED LAN switch Hostel PCs Database server HIDS NIDS sensor copy of the traffic (mirror port) Rules: the Internet reaches only the DMZ servers' ports (443, 25); the LAN may go out; nothing from outside opens a connection to the LAN. The NIDS watches copies of the traffic; HIDS agents watch each server's own files and logs.

In this way a firewall enforces access control and protects availability, though it cannot stop insiders or traffic that bypasses it.

Symmetric key against public key (asymmetric) cryptography PIN 3/27

Asked 3 times

2073 Shrawan · Q83 marksCompare symmetric key encryption method with asymmetric key encryption.

2071 Shrawan · Q96 marksDifferentiate between symmetric key and public key cryptography.

2069 Chaitra · Q94 marksCompare symmetric key encryption method with asymmetric key encryption.

Symmetric key cryptography uses one secret key, shared by the sender and the receiver, both to encrypt and to decrypt. Public key (asymmetric) cryptography uses a key pair: the sender encrypts with the receiver's public key, and only the receiver's private key decrypts.

SYMMETRIC KEY AND PUBLIC KEY CRYPTOGRAPHY One shared secret key at both ends, or a key pair of which only the receiver holds the private half. SYMMETRIC (SECRET KEY): ONE SHARED KEY Plaintext the message Encrypt DES, AES Ciphertext unreadable Decrypt same algorithm Plaintext at B key K (shared secret) the same key K K must reach B secretly first PUBLIC KEY (ASYMMETRIC): A KEY PAIR FOR EACH USER Plaintext the message Encrypt RSA, ECC Ciphertext unreadable Decrypt RSA Plaintext at B B's public key (anyone) B's private key (B only) only the public key travels Symmetric: fast; but n users need n(n-1)/2 keys, each shared in secret. Public key: slow; 2n keys and nothing secret to share, so real systems use it to send a symmetric session key (hybrid).
PointSymmetric keyPublic key
Keysone shared secret keya public key and a private key
Key holdersboth parties, secretlypublic key: anyone; private key: owner only
Speedfast, suits bulk dataslow, suits short data such as keys
Key distributiondifficult: the key must be shared secretly firsteasy: the public key is published
Keys for n usersn(n−1)/22n
Key length128 to 256 bits2048 bits or more (RSA)
Servicesconfidentialityconfidentiality, authentication, non-repudiation, key exchange
ExamplesDES, 3DES, AES, IDEA, RC4RSA, Diffie-Hellman, ElGamal, ECC

In practice the two are combined: public key cryptography exchanges a random session key, and a symmetric cipher encrypts the data with it, as in TLS and PGP.

SSL: the secure socket layer PIN 3/27

Asked 3 times

2071 Chaitra · Q104 marksa) SSL

2071 Shrawan · Q104 marksc) SSL

2068 Baishakh · Q92 marksWhat is a secure socket layer?

SSL (Secure Sockets Layer, Netscape), now succeeded by TLS, is a protocol layer between TCP and the application that secures a connection: it authenticates the server by its certificate, encrypts the data with symmetric session keys and protects its integrity with a MAC. HTTPS is HTTP over SSL/TLS, on port 443.

  • Handshake protocol: client and server exchange hellos and random numbers and agree a cipher suite; the server sends its certificate; the client sends a pre-master secret encrypted with the server's public key; both derive the session keys.
  • Change cipher spec protocol: both sides switch to the new keys, and Finished messages confirm the handshake was not tampered with.
  • Record protocol: fragments the data, optionally compresses it, adds a MAC, encrypts it and adds a header.
  • Alert protocol: reports errors.
SSL/TLS: WHERE IT SITS, AND THE HANDSHAKE Between TCP and the application; the handshake authenticates the server and agrees the keys the record protocol uses. Application HTTP, SMTP, FTP SSL / TLS Handshake Alert Change cipher spec Record protocol TCP port 443 for HTTPS IP RECORD PROTOCOL, PER BLOCK fragment (up to 16 KB), compress, add a MAC, encrypt, add a header VERSIONS SSL 2.0, 3.0 (Netscape); TLS 1.0 (1999), 1.2 (2008), 1.3 (2018): use 1.2 or 1.3 Client the browser Server the bank site ClientHello: TLS versions, cipher suites, client random 1 ServerHello: the chosen suite, server random 2 Certificate: the server's public key, signed by a CA 3 ServerHelloDone 4 ClientKeyExchange: pre-master secret, under the server's public key 5 ChangeCipherSpec, Finished (a MAC of the whole handshake) 6 ChangeCipherSpec, Finished 7 the client checks the certificate against its trusted CAs both derive the master secret and the session keys from the pre-master secret and the two randoms 8 Application data, both ways: encrypted and MACed by the record protocol TLS 1.3 shortens this to one round trip, with ephemeral Diffie-Hellman keys.

What a firewall is PIN 3/27

Asked 3 times

2082 Bhadra · Q92 marksWhat do you mean by firewall?

2073 Shrawan · Q92 marksWhat do you mean by firewall?

2072 Kartik · Q91 markWhat is firewall?

A firewall is a hardware device or software placed at the boundary between a trusted internal network and an untrusted one such as the Internet. All traffic between them passes through it, and it permits or blocks each packet or connection according to a security policy, its rule set; for example, it lets web traffic out while blocking Telnet from outside.

What public key cryptography is PIN 2/27

Asked 2 times

2081 Baishakh · Q91 markWhat is public key cryptography?

2071 Chaitra · Q92 marksWhat is public key cryptography?

Public key (asymmetric) cryptography gives each user a pair of keys: a public key, published to everyone, and a private key kept secret by its owner; what one key encrypts, only the other decrypts. To send a secret to B, A encrypts with B's public key and only B's private key can decrypt it; signing with a private key gives digital signatures. RSA and Diffie-Hellman are examples. No secret key has to be shared in advance.

What PGP is PIN 2/27

Asked 2 times

2082 Baishakh · Q104 marksb) PGP

2080 Baishakh · Q93 marksWhat is PGP?

PGP (Pretty Good Privacy, Phil Zimmermann, 1991) is an e-mail security program, standardised as OpenPGP, that gives e-mail confidentiality, authentication, integrity and compression by combining public key and symmetric cryptography.

  • Authentication and integrity: the sender signs a hash of the message with its private key.
  • Confidentiality: the message is encrypted with a one-time symmetric session key (IDEA, 3DES, AES), and the session key with the receiver's public key.
  • Compression: the signed message is compressed with ZIP before encryption.
  • E-mail compatibility: the binary result is converted to radix-64 (base64) text.
  • Segmentation: long messages are split and rejoined.
PGP: HOW ONE EMAIL FROM A TO B IS PROTECTED Sign, compress, encrypt with a one-time session key, lock that key with B's public key, then base64. SENDING, AT A 1 Hash digest of the mail (SHA-256) 2 Sign digest with A's private key 3 Compress mail + signature with ZIP 4 Encrypt one-time session key (AES, IDEA) 5 Lock the key session key with B's public key 6 Base64 binary to plain email text authentication compression confidentiality email compatibility RECEIVING, AT B: THE SAME STEPS BACKWARDS Decode base64 back to binary Unlock the key with B's private key Decrypt with the session key Decompress mail + signature Verify with A's public key Sign before compressing: the signature covers the mail as written. Compress before encrypting: less redundancy, less to encrypt. Keys: PGP trusts public keys through a web of trust (users sign each other's keys); S/MIME uses CA certificates instead.

Keys are kept in public and private key rings, and public keys are trusted through a web of trust in which users sign one another's keys.

IPsec PIN 2/27

Asked 2 times

2080 Baishakh · Q104 marksc) IPSec

2072 Kartik · Q104 marksb) IPSec

IPsec (IP security) is an IETF suite of protocols that secures IP packets at the network layer, between hosts, routers or both, so that every application above IP is protected. It works with IPv4 and IPv6.

  • AH (Authentication Header): source authentication, integrity and anti-replay, without encryption.
  • ESP (Encapsulating Security Payload): encryption, plus authentication and integrity.
  • Transport mode: protects only the payload, the original IP header stays; host to host.
  • Tunnel mode: the whole packet is protected inside a new IP header; gateway to gateway, as in VPNs.
  • Security association (SA): a one-way agreement of protocol, algorithms, keys and sequence numbers, identified by the SPI, the destination address and the protocol.
  • IKE: authenticates the two ends and sets up the SAs using Diffie-Hellman.
IPSEC: TRANSPORT AND TUNNEL MODE, WITH AH AND ESP AH (protocol 51) authenticates; ESP (protocol 50) encrypts and can authenticate. Original packet IP header TCP Data as a host sends it Transport + AH IP header AH TCP Data authenticated host to host; no secrecy Transport + ESP IP header ESP hdr TCP Data ESP trailer ESP auth authenticated encrypted host to host; secret Tunnel + ESP New IP header ESP hdr IP header TCP Data ESP trailer ESP auth authenticated encrypted gateway to gateway: VPN Tunnel + AH New IP header AH IP header TCP Data authenticated gateways; no secrecy encrypted (ESP only) added by IPsec authenticated: origin and integrity

WEP: wired equivalent privacy PIN 2/27

Asked 2 times

2071 Chaitra · Q104 marksb) WEP

2071 Shrawan · Q104 marksa) WEP

WEP (Wired Equivalent Privacy) is the security protocol of the original IEEE 802.11 standard, meant to give a wireless LAN the privacy of a wired one: confidentiality, access control and integrity.

  • Encryption: a 24-bit initialization vector (IV) is joined to a shared 40 or 104-bit key to seed the RC4 stream cipher; a CRC-32 integrity check value is appended to the data; data and check value are XORed with the RC4 keystream; the IV travels in the clear with the frame.
  • Decryption: the receiver makes the same keystream from the IV and the key, XORs, and checks the CRC.
  • Weaknesses: the 24-bit IV repeats, so keystreams are reused; weak RC4 keys leak the key; CRC-32 is linear and lets frames be altered; one static key is shared by all.
WEP: HOW A FRAME IS ENCRYPTED, AND WHY IT FAILS RC4 keyed with IV + shared key; CRC-32 for integrity; the IV travels in the clear. IV 24 bits, new per frame + Shared secret key 40 or 104 bits seed: IV then key = 64 or 128 bits RC4 stream cipher keystream Plaintext the frame data CRC-32 gives the ICV data ICV the data itself Ciphertext (data + ICV) XOR key FRAME SENT IV in the clear key ID ciphertext (data + ICV) THE BOOK'S EXAMPLE keystream 0101 plaintext 1100 XOR gives 1001 WHY IT FAILS 24-bit IV: only 16,777,216 keystreams, so they repeat; two frames under one keystream give C1 XOR C2 = P1 XOR P2. CRC-32 is linear: bits flipped in the ciphertext can be matched by fixing the ICV, so tampering goes unseen. One static key shared by every user, and weak RC4 keys leak key bytes (the FMS attack): cracked in minutes.

WEP can be cracked in minutes, so it was replaced by WPA (TKIP) and WPA2 (AES with CCMP, IEEE 802.11i).

What cryptography is PIN 1/27

Asked once

2071 Shrawan · Q92 marksWhat is cryptography?

Cryptography is the science of securing messages by transforming readable plaintext into unreadable ciphertext with an algorithm (a cipher) and a key, so that only the holder of the right key can recover the plaintext. It provides confidentiality and, with hashes and signatures, integrity, authentication and non-repudiation. Its two types are symmetric key cryptography (one shared secret key, as in AES) and public key cryptography (a public and private key pair, as in RSA).

The types of encryption used in security PIN 1/27

Asked once

2074 Chaitra · Q95 marksDefine type of Encryption used in security.

Encryption turns plaintext into ciphertext with a key. It is of two types, with the hash function as a third, one-way tool:

  1. Symmetric key (secret key) encryption: the same secret key encrypts and decrypts, C=EK(P) and P=DK(C). It is fast and suits bulk data, but the key must be shared secretly and n users need n(n−1)/2 keys. Block ciphers (DES, 3DES, AES, IDEA) encrypt fixed blocks; stream ciphers (RC4) XOR the data with a keystream.
  2. Asymmetric (public key) encryption: each user has a public key and a private key; data encrypted with the receiver's public key is decrypted only with its private key, and data signed with a private key is verified with the public key. It solves key distribution and gives digital signatures, but it is slow. Examples: RSA, Diffie-Hellman, ECC.
  3. Hashing: a keyless one-way function, such as SHA-256, that gives a fixed-length digest; it cannot be decrypted and serves integrity and signatures.
SYMMETRIC KEY AND PUBLIC KEY CRYPTOGRAPHY One shared secret key at both ends, or a key pair of which only the receiver holds the private half. SYMMETRIC (SECRET KEY): ONE SHARED KEY Plaintext the message Encrypt DES, AES Ciphertext unreadable Decrypt same algorithm Plaintext at B key K (shared secret) the same key K K must reach B secretly first PUBLIC KEY (ASYMMETRIC): A KEY PAIR FOR EACH USER Plaintext the message Encrypt RSA, ECC Ciphertext unreadable Decrypt RSA Plaintext at B B's public key (anyone) B's private key (B only) only the public key travels Symmetric: fast; but n users need n(n-1)/2 keys, each shared in secret. Public key: slow; 2n keys and nothing secret to share, so real systems use it to send a symmetric session key (hybrid).

Real systems are hybrid: a public key method exchanges a session key, and a symmetric cipher encrypts the data.

Symmetric key cryptography PIN 1/27

Asked once

2075 Chaitra · Q104 marksc) Symmetric key cryptography

Symmetric key cryptography (secret key or conventional cryptography) uses a single secret key, shared by the sender and the receiver, for both encryption and decryption: C=EK(P), P=DK(C).

  • Types: block ciphers encrypt fixed blocks (DES: 64-bit block, 56-bit key; AES: 128-bit block, 128 to 256-bit key); stream ciphers XOR the data with a keystream (RC4).
  • Advantages: fast, with short keys; suits long messages and bulk data such as disk encryption, VPNs and Wi-Fi.
  • Disadvantages: the key must reach the receiver secretly before use (the key distribution problem); n users need n(n−1)/2 keys; no non-repudiation, as both sides hold the same key.
SYMMETRIC KEY AND PUBLIC KEY CRYPTOGRAPHY One shared secret key at both ends, or a key pair of which only the receiver holds the private half. SYMMETRIC (SECRET KEY): ONE SHARED KEY Plaintext the message Encrypt DES, AES Ciphertext unreadable Decrypt same algorithm Plaintext at B key K (shared secret) the same key K K must reach B secretly first PUBLIC KEY (ASYMMETRIC): A KEY PAIR FOR EACH USER Plaintext the message Encrypt RSA, ECC Ciphertext unreadable Decrypt RSA Plaintext at B B's public key (anyone) B's private key (B only) only the public key travels Symmetric: fast; but n users need n(n-1)/2 keys, each shared in secret. Public key: slow; 2n keys and nothing secret to share, so real systems use it to send a symmetric session key (hybrid).

It is therefore combined with public key cryptography, which exchanges the symmetric session key, as in TLS and PGP.

The fundamental differences between AES and DES PIN 1/27

Asked once

2081 Bhadra · Q92 marksWhat are the fundamental difference between AES and DES?

DES and AES are both symmetric block ciphers; AES (2001) replaced DES (1977).

PointDESAES
Block size64 bits128 bits
Key size56 bits128, 192 or 256 bits
Rounds1610, 12 or 14
StructureFeistel networksubstitution-permutation network
Round stepsexpansion, XOR, S-boxes, permutationSubBytes, ShiftRows, MixColumns, AddRoundKey
Securitybroken by brute forcesecure; the current standard

What a digital signature is PIN 1/27

Asked once

2079 Bhadra · Q91 markWhat is a digital signature?

A digital signature is a value computed from a message and the sender's private key, usually by encrypting a hash of the message with that key, which anyone can verify with the sender's public key. It proves who sent the message (authentication), that it is unaltered (integrity), and that the sender cannot deny sending it (non-repudiation).

AH and ESP in IPsec PIN 1/27

Asked once

2082 Bhadra · Q104 marksb) AH and ESP

IPsec has two security protocols.

AH (Authentication Header, IP protocol 51) provides source authentication, data integrity and anti-replay, but no confidentiality. Its fields are next header, payload length, reserved, security parameter index (SPI), sequence number and authentication data: a keyed hash over the packet, with fields that change in transit, such as TTL, taken as zero.

ESP (Encapsulating Security Payload, IP protocol 50) provides confidentiality by encryption, plus authentication, integrity and anti-replay. It adds an ESP header (SPI, sequence number), an ESP trailer (padding, pad length, next header) and ESP authentication data; the payload and trailer are encrypted.

PointAHESP
Encryptionnoyes
Authenticates the outer IP headeryesno
Works through NATnoyes
IPSEC: TRANSPORT AND TUNNEL MODE, WITH AH AND ESP AH (protocol 51) authenticates; ESP (protocol 50) encrypts and can authenticate. Original packet IP header TCP Data as a host sends it Transport + AH IP header AH TCP Data authenticated host to host; no secrecy Transport + ESP IP header ESP hdr TCP Data ESP trailer ESP auth authenticated encrypted host to host; secret Tunnel + ESP New IP header ESP hdr IP header TCP Data ESP trailer ESP auth authenticated encrypted gateway to gateway: VPN Tunnel + AH New IP header AH IP header TCP Data authenticated gateways; no secrecy encrypted (ESP only) added by IPsec authenticated: origin and integrity

What a VPN is PIN 1/27

Asked once

2075 Ashwin · Q92 marksWhat is VPN?

A VPN (virtual private network) is a private network built over a public network such as the Internet by tunnelling: packets are encrypted and authenticated, then carried inside other packets between VPN gateways or clients, so that remote sites and users communicate as if on one private LAN. Examples are a site-to-site IPsec VPN between a head office and its branch, and a remote-access VPN from a home laptop.

Intrusion detection system (IDS) PIN 1/27

Asked once

2071 Shrawan · Q104 marksb) IDS

An intrusion detection system (IDS) is a device or software that monitors a network or its hosts for malicious activity or policy violations and alerts an administrator or a SIEM system.

  • Network IDS (NIDS): a sensor on a mirror port or tap at a key point analyses the traffic of a whole segment (Snort, Suricata).
  • Host IDS (HIDS): an agent on a host watches its logs, processes and system files, comparing file snapshots (OSSEC, Tripwire).
  • Signature-based detection: matches known attack patterns; accurate, but blind to new attacks.
  • Anomaly-based detection: builds a baseline of normal behaviour and flags deviations; catches new attacks, with more false alarms.
WHERE THE FIREWALL, THE DMZ AND THE IDS SIT The firewall is the one gate between three zones; the IDS watches what passes it. Internet untrusted Border router ACL filter Firewall stateful or NGFW DMZ: PUBLIC SERVERS, LIMITED TRUST switch Web server Mail server HIDS HIDS INSIDE: THE TRUSTED LAN switch Hostel PCs Database server HIDS NIDS sensor copy of the traffic (mirror port) Rules: the Internet reaches only the DMZ servers' ports (443, 25); the LAN may go out; nothing from outside opens a connection to the LAN. The NIDS watches copies of the traffic; HIDS agents watch each server's own files and logs.

An IDS only detects and alerts; an intrusion prevention system (IPS) sits in the traffic's path and blocks. An IDS complements a firewall by finding attacks hidden in allowed traffic or coming from insiders.

56 procedures · asked 102 times in 27 sittings · the steps, in order

Practical answers

The questions the papers have asked about how a thing is done: incident handling and response, the risk calculations, the lifecycles and procedures. Each answer gives the steps in the order they happen, with the flow to draw beside it. What a thing is, and every comparison, stays in Theory answers.

1Introduction to computer network

Headers and trailers, and how they are added and removed PIN 3/27

Asked 3 times

2076 Ashwin · Q14 marksWhat are headers and trailers and how do they get added and removed?

2070 Chaitra · Q14 marksWhat are headers and trailers and how do they get added and removed? Explain.

2066 Bhadra · Q1a2 marksHow the process of data encapsulation occurs in transmission mode described by seven layers of OSI model.

Headers and trailers are control information the layers add to data: a header goes in front (addresses, sequence numbers, length, type, checksum) and a trailer after it (the frame check sequence, a CRC, added by the data link layer). They are added by encapsulation at the sender and removed by decapsulation at the receiver.

DATA ENCAPSULATION Each layer wraps what it gets from above in its own header; the data link layer adds a trailer too. SENDER: ADD, GOING DOWN RECEIVER: REMOVE, GOING UP Data TCP hdr Data IP hdr TCP hdr Data Frame hdr IP hdr TCP hdr Data FCS 0110100111010110010110... Data TCP hdr Data IP hdr TCP hdr Data Frame hdr IP hdr TCP hdr Data FCS 0110100111010110010110... APPLICATION data TRANSPORT segment NETWORK packet DATA LINK frame PHYSICAL bits medium Headers go in front; only the data link layer adds a trailer, the FCS (a CRC over the whole frame). A router opens a frame only up to the IP header, then builds a new frame for the next link.
  1. Data: the upper layers produce the data.
  2. Segment: the transport layer adds a TCP or UDP header (ports, sequence number).
  3. Packet: the network layer adds an IP header (IP addresses).
  4. Frame: the data link layer adds a header (MAC addresses) and a trailer (FCS).
  5. Bits: the physical layer transmits the frame as signals.

Removal: at the receiver each layer checks and strips its own header (the data link layer also its trailer) and passes the rest up, until the application gets the original data.

X.25 virtual circuit connection and switching PIN 2/27

Asked 2 times

2067 Ashad · Q64+4 marksExplain along with the packet format about the virtual circuit connection of X.25.

2066 Poush · Q66 marksExplain the X.25 virtual circuit switching.

X.25 is a virtual circuit packet switching network: before data moves, a logical connection is set up through the network, and every packet then follows it, carrying only a short logical channel number instead of the full address.

Packet format: octet 1 holds the GFI (Q bit, D bit, modulo bits) and the 4-bit LCGN; octet 2 the 8-bit LCN (together a 12-bit circuit number); octet 3 the packet type, which for data is P(R), the M bit, P(S) and 0; then up to 128 bytes of user data. Control packets carry a type code in octet 3, and a call request adds the DTE addresses.

AN X.25 VIRTUAL CALL Setup routes the call once; afterwards packets carry only the logical channel number. X.25 NETWORK (PSEs) DTE A DCE A DCE B DTE B Call request Incoming call Call accepted Call connected Data P(S)=0 RR P(R)=1 Data P(S)=0 RR P(R)=1 Clear request Clear indication Clear confirmation Clear confirmation CALL SETUP DATA CLEARING Data packets carry only the channel number; each PSE switches them by table lookup, in order, acknowledged hop by hop.
  1. Call setup: DTE A chooses a free logical channel and sends a Call request with B's address. The network routes it once through its packet switches (PSEs), each recording the circuit in its table, and DTE B receives an Incoming call. B answers Call accepted, and A receives Call connected.
  2. Data transfer: data packets carry the channel number, and each PSE switches them by table lookup, for example link 1 channel 5 to link 3 channel 9. P(S) and P(R) number and acknowledge the packets, a window (2 by default) limits the outstanding packets, RR and RNR control the flow, and packets arrive in order.
  3. Clearing: one DTE sends a Clear request; the other receives a Clear indication and returns a Clear confirmation, which is also delivered to the first DTE. The channel numbers are freed.

Circuit types: a switched virtual circuit (SVC) goes through all three phases for every call; a permanent virtual circuit (PVC) is set up by the provider and has only the data transfer phase. A reset reinitialises one circuit; a restart clears every circuit on the interface.

How the client/server model works PIN 1/27

Asked once

2078 Bhadra · Q13 marksHow does the client-server model work?

In the client/server model two processes, one on the client and one on the server, communicate by request and reply:

  1. Listen: the server process starts first and waits on a known address and port.
  2. Request: the client process sends a request message over the network and waits.
  3. Process: the server receives it and performs the work, such as reading a file or querying a database.
  4. Reply: the server sends the result back in a reply message.
  5. Use: the client displays the result; the server serves other clients.
CLIENT/SERVER AND PEER TO PEER Left: fixed roles, one server answers many clients. Right: equal peers, each both client and server. CLIENT/SERVER Server always on, holds the data Client laptop browser Client phone app Client ATM terminal request reply Clients start every exchange; the server only answers. If the server fails, every client stops. PEER TO PEER Peer A client and server Peer B client and server Peer C client and server Peer D client and server Every peer requests and serves; no central server. Each new peer adds capacity as well as demand.

Example: a browser requests a page and the web server replies.

How a Frame Relay SVC is established, maintained and torn down PIN 1/27

Asked once

2066 Bhadra · Q3b6 marksExplain the operation how switched virtual circuit in frame relay network is established, maintained and teardown.

A switched virtual circuit (SVC) in Frame Relay is a temporary connection between two DTEs, set up on demand and cleared after use by Q.933 signalling messages carried on DLCI 0. It passes through four states:

A FRAME RELAY SVC: ESTABLISHED, MAINTAINED, TORN DOWN Q.933 signalling messages on DLCI 0; the data then uses the DLCI the network assigned. Calling DTE Frame Relay network Called DTE SETUP (called address, CIR) CALL PROCEEDING SETUP CONNECT CONNECT data frames both ways on the assigned DLCI no data: the circuit is kept; an idle timer runs DISCONNECT DISCONNECT RELEASE RELEASE RELEASE COMPLETE RELEASE COMPLETE SETUP DATA IDLE TEARDOWN Maintained: STATUS ENQUIRY and STATUS messages check the link while the call is up. A PVC skips setup and teardown: it only moves between data transfer and idle.
  1. Call setup (established): the calling DTE sends SETUP with the called address and traffic parameters such as the CIR; the network answers CALL PROCEEDING and forwards SETUP to the called DTE; the called DTE replies CONNECT, which the network passes to the caller. The network assigns the DLCI each end uses, and the circuit is established.
  2. Data transfer (maintained): frames flow in both directions on the assigned DLCI, relayed by the switches like PVC traffic; the congestion bits FECN, BECN and DE apply.
  3. Idle (maintained): the connection stays active with no data; STATUS ENQUIRY and STATUS messages check the link. If it stays idle beyond a set time, the call can be terminated.
  4. Call termination (teardown): either DTE sends DISCONNECT; the network replies RELEASE and the DTE confirms RELEASE COMPLETE; the other DTE receives DISCONNECT, sends RELEASE and receives RELEASE COMPLETE. The DLCI is freed.

A PVC, by contrast, is configured permanently and has only the data transfer and idle states.

2Physical layer

Packet switching explained with a diagram PIN 1/27

Asked once

2075 Chaitra · Q25 marksElaborate packet switching with a proper diagram.

Packet switching divides a message into small packets, each with a header (source and destination address, sequence number) and a payload, and forwards them through the network one hop at a time. Links are shared by all users, and resources are used only when there is data.

  1. Packetizing: the source splits the message into packets of bounded size and adds headers.
  2. Store and forward: each switch or router receives the whole packet, checks it, queues it and sends it on the chosen output link.
  3. Routing: in the datagram approach each packet is routed independently by its destination address and may take a different path; in the virtual circuit approach a path is set up first and every packet follows it, carrying only a short VCI.
  4. Reassembly: the destination puts the packets in order by sequence number and rebuilds the message.
DATAGRAM AND VIRTUAL CIRCUIT NETWORKS The same four routers used two ways: every packet on its own, or every packet on one path set up first. Datagram network connectionless: each packet routed on its own R1 R2 R3 R4 A B 1 3 2 4 arrive: 2, 1, 4, 3 PACKET HEADER to B from A seq 3 data no setup; full address in every packet routers keep no state per connection packets may take different paths, out of order example: IP, the Internet Virtual circuit network connection oriented: set up, transfer, tear down R1 R2 R3 R4 A B VCI 12 VCI 25 VCI 7 VCI 31 1 2 arrive: 1, 2, 3, 4 R2’S VC TABLE from R1 in port 25 in VCI to R4 out port 7 out VCI a short VCI, swapped at every hop every packet on one path, in order a packet carries only the VCI and data examples: X.25, Frame Relay, ATM, MPLS

Examples: the internet (IP datagrams); Frame Relay and ATM (virtual circuits). Merits: efficient for bursty data, no setup in the datagram form, robust. Demerits: variable delay, out-of-order arrival, header overhead.

How the telephone network works PIN 1/27

Asked once

2068 Chaitra · Q36 marksWith a simple diagram of a telephone network explain how the system works.

The telephone network (PSTN) is a hierarchical, circuit-switched network made of three parts:

THE TELEPHONE NETWORK Telephones, local loops, exchanges in a hierarchy, and trunks between them; one call path in colour. Regional office top of the hierarchy Toll office long distance Toll office long distance End office local exchange End office local exchange End office local exchange End office local exchange trunk: multiplexed digital (E1, fiber) trunk local loop: twisted pair, 300 to 3400 Hz Kathmandu (area code 01) Pokhara (area code 061) telephones: the subscribers calling phone to called phone: loop, end office, toll, toll, end office, loop
  • Local loop: a twisted pair from each subscriber's telephone to the nearest end office (local exchange), carrying the 300 to 3400 Hz voice band.
  • Switching offices: end offices connect their own subscribers; tandem and toll offices connect end offices for calls between areas, in a hierarchy up to regional offices.
  • Trunks: high-capacity multiplexed links (E1, T1, fiber) between offices.

How a call works:

  1. Off-hook: lifting the handset closes the loop; the end office detects the current and sends dial tone.
  2. Dialling: the number is sent as DTMF tones or pulses and stored.
  3. Switching: a local call is connected inside the end office; otherwise a free trunk is seized to a tandem or toll office, and signalling (SS7) sets up the circuit to the called end office.
  4. Ringing: if the called line is free it rings and the caller hears ringback; if not, busy tone.
  5. Conversation: on answer the circuit is complete; voice travels as 64 kbps PCM in a time slot on each digital trunk.
  6. On-hook: hanging up releases the circuit and records the call for billing.

ISDN signalling PIN 1/27

Asked once

2066 Bhadra · Q5b3 marksiii) ISDN Signaling

ISDN signalling is out-of-band, common channel signalling: all call control travels on the D channel, separate from the B channels that carry user data. Between user and exchange it uses LAPD (Q.921) at layer 2 and Q.931 at layer 3; inside the network, SS7 between exchanges.

  1. SETUP: the caller sends the called number and bearer type.
  2. CALL PROCEEDING: the network accepts and sends SETUP to the called terminal.
  3. ALERTING: the called phone rings.
  4. CONNECT, CONNECT ACKNOWLEDGE: on answer, the B channel carries the call.
  5. DISCONNECT, RELEASE, RELEASE COMPLETE: the call is cleared.
AN ISDN CALL OVER THE D CHANNEL Q.931 messages, carried in LAPD frames on the D channel; the B channel carries only the call itself. Calling terminal ISDN network Called terminal SETUP (called number) CALL PROCEEDING SETUP ALERTING (phone rings) ALERTING (ringback) CONNECT (answered) CONNECT ACK CONNECT CONNECT ACK B channel: 64 kbps voice or data, both ways DISCONNECT RELEASE RELEASE COMPLETE DISCONNECT RELEASE RELEASE COMPLETE CALL SET UP RELEASE Between the exchanges the network signals with SS7 (IAM, ACM, ANM, REL, RLC); the terminals never see it.

3Data link layer

CSMA/CD and how it works HOT 5/27

Asked 5 times

2081 Baishakh · Q32 marksWhat is CSMA/CD?

2079 Bhadra · Q34 marksHow CSMA/CD works?

2076 Ashwin · Q38 marksExplain the working principle of CSMA/CD with appropriate figure.

2074 Ashwin · Q104 marksc) CSMA/CD

2066 Poush · Q34 marksHow CSMA/CD works?

CSMA/CD (carrier sense multiple access with collision detection) is the medium access method of IEEE 802.3 half-duplex Ethernet. A station senses the carrier before transmitting, keeps listening while transmitting, and when it detects a collision it stops, sends a jam signal and retries after a random binary exponential backoff.

Working principle:

  1. Carrier sense: a station with a frame listens to the medium; while it is busy, it keeps listening (1-persistent).
  2. Transmission: when the medium is idle (after the 96-bit interframe gap), it transmits and monitors the medium at the same time.
  3. Collision detection: it compares the signal on the medium with its own; a higher signal level (or activity on its receive pair) means a collision.
  4. Abort and jam: on a collision it stops at once and sends a 32-bit jam signal so that every station knows of the collision.
  5. Backoff: after the nth collision it waits K slot times of 512 bit times, K chosen at random from 0 to 2min(n,10)−1, and starts again from step 1.
  6. Success or abort: if the whole frame goes without a collision, the transmission succeeded; after 16 attempts it gives up and reports an error.
CSMA/CD: THE FLOWCHART Ethernet (IEEE 802.3), half duplex: listen before talking, listen while talking, back off after a collision. Start: a frame to send attempts n = 0 Sense the channel Channel idle? no: keep sensing (1-persistent) yes Transmit the frame and listen while sending Collision detected? no Whole frame sent? no: keep sending yes Success the next frame may start yes Stop at once; send jam 32-bit jam: all stations learn n = n + 1 n > 15? yes Abort: too many collisions report the error upward no Pick K at random from 0 to 2 m - 1, m = min(n, 10) Wait K slot times slot = 512 bit times then sense again Slot time 512 bit times = 51.2 µs at 10 Mbps; jam 32 bits; at most 16 attempts per frame (truncated binary exponential backoff).

Minimum frame size: a collision must be detected while the frame is still being sent, so Tframe≥2Tprop, giving Lmin=2TpropB: 512 bits, 64 bytes, at 10 Mbps.

Because colliding stations stop within about two propagation delays, little channel time is wasted, which makes CSMA/CD much more efficient than plain CSMA. On switched full-duplex Ethernet there are no collisions and CSMA/CD is not used.

IEEE 802.5 token ring: operation, multiple access and frame format PIN 3/27

Asked 3 times

2082 Baishakh · Q104 marksa) 802.5 Token Ring

2071 Chaitra · Q36 marksExplain how multiple access is achieved in IEEE 802.5.

2068 Chaitra · Q47 marksExplain the operation of IEEE 802.5 with its frame format.

IEEE 802.5 (token ring) connects stations in a physical ring of point-to-point links, at 4 or 16 Mbps over shielded twisted pair. Multiple access is achieved with a token, a small 3-byte frame that circulates round the ring: only the station holding the token may transmit, so collisions never occur.

Operation:

  1. A station with data waits for the free token.
  2. It seizes the token by setting the token bit in the access control field, which turns the token into a frame header, and sends its frame.
  3. Each station regenerates and passes the bits on; the destination copies the frame and sets the address recognised (A) and frame copied (C) bits in the frame status field.
  4. The frame returns to the sender, which removes it from the ring and checks the A and C bits.
  5. The sender releases a new free token. A station may hold the token for at most the token holding time (10 ms).

Priority: the access control byte PPPTMRRR holds 3 priority bits and 3 reservation bits; a waiting station reserves a higher priority in a passing frame. An active monitor station regenerates a lost token and removes orphan frames (monitor bit).

TOKEN RING (IEEE 802.5): THE RING, THE STEPS, THE FRAME 4 or 16 Mbps; a station may transmit only while it holds the token (at most about 10 ms). A B C D token one-way ring 1 Wait a station with data waits for the free token (SD, AC, ED: 3 bytes). 2 Seize it sets the token bit T in AC to 1: the token becomes a frame header; it sends. 3 Copy each station repeats the bits on; the destination copies the frame, sets A and C. 4 Remove the frame returns to the sender, which strips it and checks the A and C bits. 5 Release the sender puts a new free token on the ring; the next station downstream may use it. DATA FRAME (BYTES) SD 1 AC 1 FC 1 DA 2 or 6 SA 2 or 6 Data no fixed limit FCS 4 ED 1 FS 1 TOKEN SD AC ED 3 bytes: a free token AC BYTE P P P T M R R R P priority, T token bit, M monitor bit, R reservation; FS carries A (address recognised) and C (frame copied).

Frame format: SD (1 byte), AC (1), FC (1), DA (2 or 6), SA (2 or 6), data (limited by the token holding time), FCS (4), ED (1), FS (1); the token is SD, AC and ED only.

How CRC detects errors PIN 1/27

Asked once

2080 Bhadra · Q33 marksExplain how does CRC detect the errors.

CRC (cyclic redundancy check) detects errors by modulo-2 (XOR) division with a generator polynomial G(x) of degree r known to both ends.

  1. Sender: appends r zeros to the message, divides by G(x) and appends the r-bit remainder (the CRC); the frame sent is then exactly divisible by G(x).
  2. Receiver: divides the received frame by the same G(x).
  3. Decision: remainder zero: no error, accept; nonzero remainder: error detected, reject.
CRC: THE SENDER APPENDS A REMAINDER; THE RECEIVER DIVIDES AGAIN Example: data 1101, generator 1011 (x³ + x + 1), so r = 3 check bits. SENDER 1 Data M 1101 (m = 4 bits) 2 Append r zeros 1101 000 3 Divide by G, mod 2 G = 1011, XOR 4 Remainder = CRC R = 001 (r bits) 5 Send M then R T = 1101 001 the channel: noise may flip some bits RECEIVER 6 Receive T' T' = T if no error 7 Divide by G the same 1011 8 Check remainder all zero, or not? 9 Zero: accept remainder 000 10 Not zero: reject error detected: resend any other remainder T(x) is a multiple of G(x), so it divides with no remainder; an error E(x) is missed only if G(x) also divides E(x).

An error pattern E(x) escapes only if G(x) divides it, so all single-bit errors, all odd numbers of errors (when x+1 is a factor) and all bursts up to r bits are detected.

Go-back-N and selective repeat ARQ with an example PIN 1/27

Asked once

2078 Bhadra · Q34 marksExplain Go-back-N ARQ and selective Repeat ARQ with example.

Both are sliding window ARQ protocols: the sender transmits several frames before waiting for acknowledgements and retransmits the frames that are lost or damaged.

Go-back-N ARQ: sender window up to 2k−1, receiver window 1. The receiver accepts frames in order only and discards the frames that follow an error. On a NAK or a timeout the sender resends the erroneous frame and all frames after it.

Selective repeat ARQ: both windows up to 2k−1. The receiver buffers correct frames that arrive out of order and sends a NAK for the missing one; the sender resends only that frame, and the receiver delivers the frames in order.

Example: frames 0 to 4 are sent and frame 2 is lost. Go-back-N resends 2, 3 and 4; selective repeat resends only 2.

GO-BACK-N AND SELECTIVE REPEAT: FRAME 2 IS LOST Same five frames, same loss; go-back-N resends three frames, selective repeat resends one. GO-BACK-N: RESEND FROM THE LOST FRAME ON Sender Receiver F0 F1 F2 lost F3 F4 F0, F1 ok, acknowledged F3 discarded F4 discarded NAK 2 F2 F3 F4 go back to 2 2, 3, 4 again ACK 5 SELECTIVE REPEAT: RESEND ONLY THE LOST FRAME Sender Receiver F0 F1 F2 lost F3 F4 F0, F1 ok, acknowledged F3 buffered F4 buffered NAK 2 F2 again (only) deliver 2, 3, 4 in order ACK 5

Go-back-N needs less buffer space and logic; selective repeat uses the bandwidth better on noisy links.

Operation of pure ALOHA PIN 1/27

Asked once

2066 Poush · Q34 marksExplain the operation of pure ALOHA system.

Pure ALOHA is a random access protocol in which every station transmits a frame as soon as it has one:

  1. The station sends the frame at any time, without sensing the channel.
  2. It waits for an acknowledgement, with a time-out of about twice the maximum propagation delay.
  3. If the ACK arrives, the transmission succeeded.
  4. If not, the frame is taken as destroyed in a collision; the station waits a random backoff time (R×T, with R chosen from 0 to 2K−1 after the Kth attempt) and sends again.
  5. After a maximum number of attempts (about 15) it gives up.
ALOHA: THE VULNERABLE TIME T = the time to send one frame. No other frame may start inside the shaded interval. PURE ALOHA: SEND AT ANY TIME; VULNERABLE TIME 2T vulnerable time: 2T B starts before t A's frame C starts before t + T t - T t t + T B overlaps the head of A, C overlaps its tail: all of them are lost. SLOTTED ALOHA: SEND ONLY AT A SLOT START; VULNERABLE TIME T vulnerable: T A's frame B, same slot: collides C, next slot: safe slot boundaries every T

A frame survives only if no other frame starts within one frame time T before or after it (vulnerable time 2T), so the throughput S=Ge−2G peaks at only 18.4 % at G=0.5.

Techniques to avoid collisions in a wireless LAN PIN 1/27

Asked once

2081 Baishakh · Q34 marksWhat are the techniques used to avoid the possible collisions in WLAN? Explain.

IEEE 802.11 avoids collisions with CSMA/CA (carrier sense multiple access with collision avoidance):

  1. Interframe space (IFS): a station waits until the channel has been idle for a DIFS before contending; ACK and CTS frames wait only a SIFS, so they always go first.
  2. Contention window: it then waits a random number of slots, counting down only while the channel is idle and freezing while it is busy; the window doubles after each failed attempt.
  3. Acknowledgement: the receiver acknowledges every correct frame; no ACK means the sender retransmits.
  4. RTS/CTS: before a large frame the sender sends a short RTS and the receiver replies with a CTS, both carrying the duration of the exchange; every station that hears either sets its NAV (network allocation vector) and stays silent. This solves the hidden station problem.
CSMA/CA WITH RTS AND CTS (IEEE 802.11) Virtual carrier sense: the RTS and the CTS carry the time the exchange needs; every station that hears either one keeps quiet (its NAV). Sender A wants to send Receiver B Station C hears A only Station D hears B only (hidden) DIFS backoff RTS SIFS CTS SIFS DATA SIFS ACK NAV from the RTS: keep quiet NAV from the CTS DIFS backoff DIFS backoff DIFS backoff SIFS < DIFS: the reply always takes the channel before anyone else may start.

How data transfer occurs in an Ethernet PIN 1/27

Asked once

2070 Ashad · Q46 marksHow data transfer occurs in Ethernet network? Explain.

Ethernet (IEEE 802.3) transfers data as frames between network interface cards identified by 48-bit MAC addresses:

  1. Addressing: the sender finds the receiver's MAC address from its IP address with ARP.
  2. Framing: the NIC encapsulates the packet: preamble, SFD, destination and source MAC addresses, length/type, data (padded to 46 bytes) and a CRC-32 FCS.
  3. Medium access: on a shared half-duplex segment the NIC uses 1-persistent CSMA/CD (sense, transmit while listening, jam and back off on a collision); on a full-duplex switch port it transmits at once.
  4. Signalling: the bits are line coded (Manchester at 10 Mbps) and sent after the preamble, which synchronises the receiver's clock.
  5. Forwarding: on a bus or hub every station receives the frame; a switch reads the destination address, looks it up in its MAC address table (built from source addresses) and forwards the frame only to that port, flooding unknown and broadcast frames.
  6. Reception: a NIC keeps the frame only if the destination is its own address, the broadcast address or a multicast group it has joined; it checks the FCS, discards errored frames and frames under 64 or over 1518 bytes, and passes the data up according to the type field.
THE ETHERNET (IEEE 802.3) FRAME Sizes in bytes. The frame proper runs from the destination address to the FCS. Preamble 10101010 x 7 7 SFD 10101011 1 Destination MAC address 6 Source MAC address 6 Length/Type 0x0800 = IPv4 2 Data and pad 46 to 1500 bytes 46 to 1500 FCS CRC-32 4 synchronisation: not counted the frame: 64 to 1518 bytes (minimum 64 for collision detection) A MAC ADDRESS: 48 BITS, WRITTEN AS SIX HEX BYTES 00 00 5E 00 53 01 OUI: the maker (24 bits) NIC-specific (24 bits) 00:00:5E:00:53:01 (an address kept for examples, RFC 7042) first byte, bit 0 (I/G): 0 unicast, 1 multicast bit 1 (U/L): 0 global, 1 locally set Broadcast: FF:FF:FF:FF:FF:FF Bytes go left to right, each least significant bit first, so the I/G bit is the first on the wire.

Ethernet is connectionless and unacknowledged: lost frames are recovered, if at all, by higher layers.

The fault tolerance mechanism of FDDI PIN 1/27

Asked once

2067 Ashad · Q44 marksExplain the fault tolerance mechanism of FDDI.

FDDI is built as two fiber rings that carry traffic in opposite directions: the primary ring carries data and the secondary ring stands by. Faults are tolerated as follows:

  1. Link failure (wrapping): when the fiber between two stations is cut, the two stations beside the break detect the loss of signal and wrap: each joins the primary ring to the secondary ring internally. The dual ring becomes a single ring of twice the length, and all stations stay connected.
  2. Station failure: the neighbours of the failed station wrap in the same way, or an optical bypass switch passes the light straight through the failed station.
  3. SAS failure: the concentrator isolates a failed single attachment station.
  4. Dual homing: a critical device is connected to two concentrators, so a backup path takes over.
FDDI: DUAL COUNTER-ROTATING RINGS, AND THE WRAP AFTER A FAULT 100 Mbps token ring on fiber; the secondary ring stands by until a link or a station fails. NORMAL: PRIMARY CARRIES DATA, SECONDARY STANDS BY A DAS B DAS C DAS D DAS primary (outer, clockwise) secondary (inner, anticlockwise) FIBER CUT BETWEEN A AND B: BOTH WRAP wrap wrap A DAS B DAS C DAS D DAS one ring of twice the length: B, C, D, A on the primary, then back A, D, C, B on the secondary A failed station is bypassed the same way: its two neighbours wrap.

A second fault at the same time divides the network into separate rings.

A network design with two VLANs, student and department PIN 1/27

Asked once

2068 Baishakh · Q36 marksDesign a network which consists of two VLAN named student and department. Explain with necessary diagram, IP addresses and configurations.

Design: one switch S1 holds both VLANs; router R1, connected by an 802.1Q trunk, routes between them (router on a stick).

TWO VLANS, STUDENT AND DEPARTMENT, ON ONE SWITCH One broadcast domain and one subnet per VLAN; the router (on a stick) routes between them over one 802.1Q trunk. Router R1 G0/0: trunk port G0/0.10: 192.168.10.1/24 (VLAN 10) G0/0.20: 192.168.20.1/24 (VLAN 20) 802.1Q trunk: G0/0 to S1 Gi0/1, carries both VLANs Switch S1 Fa0/1 to Fa0/12: VLAN 10 Fa0/13 to Fa0/24: VLAN 20 Student PC1 192.168.10.11 Student PC2 192.168.10.12 Dept PC3 192.168.20.11 Dept PC4 192.168.20.12 VLAN 10 STUDENT: 192.168.10.0/24, gateway .1 VLAN 20 DEPARTMENT: 192.168.20.0/24, gateway .1 ON THE TRUNK, EACH FRAME CARRIES A 4-BYTE 802.1Q TAG DA 6 SA 6 TPID 0x8100 2 PCP 3 bits DEI 1 bit VLAN ID 12 bits Type 2 Data 42 to 1500 FCS 4 the tag: 4 bytes, added on the trunk, removed at the access port
VLANSwitch portsNetworkGatewayHosts
10 STUDENTFa0/1 to Fa0/12192.168.10.0/24192.168.10.1192.168.10.11, 192.168.10.12
20 DEPARTMENTFa0/13 to Fa0/24192.168.20.0/24192.168.20.1192.168.20.11, 192.168.20.12

Switch S1:

S1(config)# vlan 10
      S1(config-vlan)# name STUDENT
      S1(config-vlan)# vlan 20
      S1(config-vlan)# name DEPARTMENT
      S1(config-vlan)# exit
      S1(config)# interface range fastEthernet 0/1 - 12
      S1(config-if-range)# switchport mode access
      S1(config-if-range)# switchport access vlan 10
      S1(config-if-range)# interface range fastEthernet 0/13 - 24
      S1(config-if-range)# switchport mode access
      S1(config-if-range)# switchport access vlan 20
      S1(config-if-range)# interface gigabitEthernet 0/1
      S1(config-if)# switchport mode trunk

Router R1:

R1(config)# interface gigabitEthernet 0/0
      R1(config-if)# no shutdown
      R1(config-if)# interface gigabitEthernet 0/0.10
      R1(config-subif)# encapsulation dot1Q 10
      R1(config-subif)# ip address 192.168.10.1 255.255.255.0
      R1(config-subif)# interface gigabitEthernet 0/0.20
      R1(config-subif)# encapsulation dot1Q 20
      R1(config-subif)# ip address 192.168.20.1 255.255.255.0

Each PC uses its VLAN's gateway. Broadcasts stay within each VLAN, and traffic between student and department hosts passes through R1, where access lists can restrict it.

4Network layer

ARP and how it works PIN 3/27

Asked 3 times

2080 Baishakh · Q104 marksb) ARP

2076 Chaitra · Q53 marksWhat is ARP and how does it work?

2071 Shrawan · Q54 marksa) ARP

ARP (Address Resolution Protocol, RFC 826) finds the MAC (physical) address that belongs to a known IPv4 address on the same LAN, since a frame can only be delivered to a MAC address. For a destination on another network, ARP finds the MAC address of the default gateway.

  1. Cache check: host A (192.168.1.10) looks for 192.168.1.20 in its ARP cache.
  2. Request: finding no entry, it broadcasts an ARP request to ff:ff:ff:ff:ff:ff: "who has 192.168.1.20? Tell 192.168.1.10", including its own MAC address.
  3. Reply: only the owner of 192.168.1.20 answers, with a unicast ARP reply carrying its MAC address; the other hosts drop the request.
  4. Cache and send: A stores the pair with a timeout and sends the waiting packet in a frame to that MAC address.
ARP: BROADCAST REQUEST, UNICAST REPLY Laptop A knows the printer's IP address and needs its MAC address. Laptop A 192.168.1.10 Host C 192.168.1.30 Printer B 192.168.1.20 1 ARP request, broadcast to ff:ff:ff:ff:ff:ff "Who has 192.168.1.20? Tell 192.168.1.10" with the sender's MAC, 00:1a:2b:3c:4d:5e not my address: dropped 2 ARP reply, unicast to A "192.168.1.20 is at 3c:52:82:10:aa:07" 3 A caches 192.168.1.20 = 3c:52:82:10:aa:07 4 the IP packet, in a frame to 3c:52:82:10:aa:07

ARP runs directly over Ethernet (type 0x0806) in a 28-byte packet, with operation 1 for a request and 2 for a reply. RARP does the reverse, mapping a MAC address to an IP address.

Working principle of the repeater, hub, bridge, switch and router PIN 2/27

Asked 2 times

2070 Chaitra · Q48 marksExplain the working principle of different types of network devices Repeater, HUB, Bridge, Switch and Router.

2066 Poush · Q103 marksb) Network Devices: Hubs, Switches and Routers

Network devices join segments and networks. Each works at one OSI layer, and that layer decides what it can read and therefore what it can decide.

INTERNETWORKING DEVICES AND THE OSI LAYERS A device can only decide on what its layer can read. 7 Application 6 Presentation 5 Session 4 Transport 3 Network 2 Data link 1 Physical Gateway protocol converter, up to layer 7 Router (and layer 3 switch) Bridge Switch Repeater Hub reads whole messages; converts one protocol to another reads IP addresses; a broadcast domain per interface reads MAC addresses; a collision domain per port regenerates the signal; one collision domain Higher layer: the more it can read and decide, and the slower and costlier per port.
  • Repeater (physical layer): receives a weakened, noisy signal on one port and regenerates it at full strength on the other, extending the cable distance. It copies every bit, collisions included, so both sides remain one collision domain.
  • Hub (physical layer): a multiport repeater; a signal arriving on one port is copied out of all other ports. All ports share one bandwidth and one collision domain, and it works half duplex. An active hub regenerates the signal; a passive hub only joins the wires.
  • Bridge (data link layer): joins two LAN segments, records the source MAC address of each frame against its port, and then filters, forwards or floods each frame by its destination MAC address. Each segment becomes a separate collision domain.
  • Switch (data link layer): a multiport bridge with a MAC address table; it sends each frame only out of the destination's port, so every port is its own collision domain with dedicated, full-duplex bandwidth. It forwards by store-and-forward, cut-through or fragment-free switching.
  • Router (network layer): joins different networks and forwards packets by destination IP address using a routing table built statically or by routing protocols. It chooses the best path, decrements TTL, and separates broadcast domains, one per interface.

RIP: its operation and timers, with an example PIN 2/27

Asked 2 times

2082 Baishakh · Q46 marksExplain RIP routing operation with is timer details.

2069 Chaitra · Q55 marksExplain the working process of Routing Information protocol (RIP) with example.

RIP (Routing Information Protocol) is a distance vector interior routing protocol (RFC 1058; RIPv2, RFC 2453). Its metric is the hop count, at most 15, with 16 meaning unreachable. Routers exchange their whole routing tables with their neighbours every 30 seconds over UDP port 520.

Operation:

  1. A router starts with its directly connected networks and sends a request to its neighbours.
  2. The neighbours reply with response messages containing their tables, and repeat them every 30 seconds.
  3. For each route received the router adds 1 hop: it adds new networks, replaces a route by a shorter one, and always accepts news from its current next hop.
  4. Triggered updates announce changes at once; split horizon, poison reverse and hold-down prevent loops.
TimerDefaultAction
Update30 swhole table sent to neighbours
Invalid180 sno update: route invalid, metric 16
Hold-down180 sworse news about the route ignored
Flush240 sroute removed from the table
THE RIP TIMERS (CISCO DEFAULTS) Seconds after the last update heard for a route whose neighbour has gone silent. 0 30 60 90 120 150 180 210 240 270 300 330 360 route valid, but no update arrives hold-down: 180 s updates due every 30 s INVALID AT 180 S: METRIC 16 FLUSH AT 240 S: ROUTE REMOVED last update Update 30 s, invalid 180 s, hold-down 180 s, flush 240 s (counted from the last update, so the route goes before hold-down ends). RFC 2453 names two: timeout 180 s, then garbage collection 120 s (deleted at 300 s).

Example: routers R1, R2 and R3 in a line, with LAN 10.1.0.0 on R1 and LAN 10.4.0.0 on R3. After the first update, R1 reaches R2's link network 10.3.0.0 at 1 hop; after the second, it receives 10.4.0.0 at 2 hops via R2. If R3 fails, 10.4.0.0 becomes invalid at 180 seconds and is flushed at 240 seconds.

Limits: a 15-hop diameter, slow convergence, and a metric that ignores bandwidth.

The OSPF process in link state routing PIN 2/27

Asked 2 times

2082 Bhadra · Q46 marksExplain open short path first (OSPF) process in link state routing.

2079 Bhadra · Q104 marksb) OSPF

OSPF (Open Shortest Path First) is an open-standard link state interior gateway protocol (RFC 2328). Each router floods link state advertisements (LSAs) through its area, builds an identical link state database, and runs Dijkstra's shortest path first (SPF) algorithm. Its metric is a cost, the reference bandwidth divided by the link bandwidth.

The OSPF process:

  1. Neighbour discovery: Hello packets go every 10 seconds to 224.0.0.5; a neighbour silent for 40 seconds (the dead interval) is declared down.
  2. DR and BDR election on multi-access networks, by priority and then router ID.
  3. Database exchange: neighbours pass through the ExStart, Exchange and Loading states, swapping DBD, LSR, LSU and LSAck packets until their databases match (Full).
  4. Flooding: each router floods its LSAs through the area on any change, refreshed every 30 minutes.
  5. SPF calculation: each router runs Dijkstra with itself as the root, giving a shortest path tree.
  6. Routing table: the best paths are installed; a change triggers new LSAs and a new SPF run.
OSPF AREAS, AND A DR AND BDR ON A LAN Areas keep each database small; a DR and BDR cut the adjacencies on a shared segment. AREA 0 (BACKBONE) AREA 1 AREA 2 other AS R0 ABR1 ABR2 ASBR one Ethernet segment R1 R2 R3 R4 R5 DR BDR DROthers 7 adjacencies, not 10

Areas: a large autonomous system is split into areas joined to backbone area 0 by area border routers, keeping each database small. Features: fast convergence, no count to infinity, VLSM and CIDR support, authentication and equal-cost load balancing.

DR and BDR in OSPF, and how the DR is elected PIN 2/27

Asked 2 times

2081 Bhadra · Q44 marksmention the method that how Designated Router (DR) is elected in OSPF routing.

2080 Bhadra · Q53 marksWhat is DR and BDR in OSPF?

On a multi-access network such as Ethernet, OSPF elects a designated router (DR) and a backup designated router (BDR). Every other router forms a full adjacency only with the DR and BDR, which cuts the adjacencies from n(n−1)/2 to 2(n−2)+1 and stops repeated flooding. Routers send updates to the DR (224.0.0.6), which floods them to all (224.0.0.5); the BDR takes over at once if the DR fails.

Election method:

  1. The router with the highest interface priority (0 to 255, default 1) becomes DR, and the next highest BDR.
  2. A tie is broken by the highest router ID (configured, else the highest loopback address, else the highest interface address).
  3. A router with priority 0 never becomes DR or BDR.
  4. The election is non-preemptive: a better router that joins later waits until the DR fails.

How OSPF routers reach full adjacency PIN 2/27

Asked 2 times

2080 Bhadra · Q55 marksHow do OSPF routers come into fully adacency states? Explain.

2066 Bhadra · Q4aDescribe how the routers in its link state routing come into fully adjacency state.

Two OSPF neighbours pass through seven states before their link state databases are synchronized (RFC 2328):

OSPF: FROM DOWN TO FULL ADJACENCY The first three states make neighbours; the last four build the adjacency. NEIGHBOURS BUILDING THE ADJACENCY Down 1 no Hello heard yet Init 2 Hello arrives, not yet listing this router 2-Way 3 own ID seen in Hello; DR, BDR elected ExStart 4 master and slave chosen Exchange 5 DBD packets swapped Loading 6 LSR, LSU and LSAck for the missing LSAs Full 7 databases match DROthers stay here Down, Init, 2-Way, ExStart, Exchange, Loading, Full: the DR and BDR are chosen at 2-Way, and only routers that must become adjacent go further.
  1. Down: no Hello has been received from the neighbour.
  2. Init: a Hello has arrived, but it does not yet list this router's ID.
  3. 2-Way: each router sees its own ID in the other's Hello; on a multi-access network the DR and BDR are elected here, and two DROthers stay in this state.
  4. ExStart: master and slave are chosen (the higher router ID is master) with the initial sequence number.
  5. Exchange: DBD packets describing each database (the LSA headers) are exchanged.
  6. Loading: missing or newer LSAs are requested with LSR packets and received in LSU packets, acknowledged by LSAck.
  7. Full: both databases are identical; the routers are fully adjacent and run SPF on the same map.

The bridge: how it works and how it raises throughput over a repeater PIN 1/27

Asked once

2080 Baishakh · Q38 marksWhat is a bridge? How does it work? How can a bridge increase the throughout as compared with a repeater while extending a LAN? Explain with suitable diagrams.

A bridge is a data link layer device that connects two or more LAN segments and forwards frames by their destination MAC address. A transparent bridge (IEEE 802.1D) keeps a MAC table that maps each station to the port on which its frames arrive, and needs no configuration.

A LEARNING BRIDGE BETWEEN TWO SEGMENTS It records each source address against its port, then filters, forwards or floods. SEGMENT 1: COLLISION DOMAIN 1 SEGMENT 2: COLLISION DOMAIN 2 A 00:aa B 00:bb C 00:cc D 00:dd Bridge port 1 port 2 MAC TABLE A 00:aa 1 B 00:bb 1 C 00:cc 2 D 00:dd 2 Filter A to B: B is on port 1, the arrival port, so the frame is dropped. Forward A to C: C is on port 2, so the frame goes out of port 2 only. Flood A to an unknown address, or a broadcast: sent out of every other port. Without the bridge (a repeater instead), both segments share one collision domain: total throughput is at most one segment's C. With it, local frames stay local: total throughput = 2C / (1 + f), where f is the share of frames that cross. Entries age out after 300 seconds unless refreshed; a station that moves is found again.

Working:

  1. Receive every frame on every port.
  2. Record the frame's source MAC address against the arrival port in the MAC table.
  3. Look up the destination MAC address: if it is on the arrival port, filter (discard) the frame; if it is on another port, forward it out of that port only; if it is unknown or a broadcast, flood it out of all other ports.
  4. Age out entries not refreshed within 300 seconds.

Throughput compared with a repeater: a repeater copies every bit to the other segment, so the extended LAN remains one collision domain and its total throughput cannot exceed the capacity C of one segment. A bridge keeps local frames on their own segment, so both segments carry traffic at the same time and only crossing frames load both. If a fraction f of the traffic crosses the bridge:

total throughput=2C1+f

With C = 100 Mbps and f = 0.2, the bridged LAN carries 166.7 Mbps against the repeater's 100 Mbps, and 200 Mbps when all traffic is local. Collisions also stay inside each segment, store-and-forward gives each segment its own CSMA/CD length limit, and damaged frames are not passed on.

Network design for a 3-star hotel PIN 1/27

Asked once

2072 Kartik · Q18 marksYou are assigned to design a network infrastructure for a 3-star hotel. Recommend a network solution with hardwares and softwares in current trend that can be used in the hotel. Make necessary assumptions and justify your recommadation with logical arguments where possible.

Assumptions: 60 guest rooms on 4 floors; a lobby, restaurant, conference hall and back offices; about 30 staff PCs and POS terminals; 40 CCTV cameras; an IP phone in every room.

A 3-STAR HOTEL: TWO ISPS, ONE FIREWALL, VLANS PER USE The firewall ties together dual WAN, NAT, VLAN rules and the guest captive portal. ISP 1: fibre ISP 2: backup Firewall (UTM), dual WAN Core switch, layer 3 Servers: PMS, POS, NVR, IP PBX Floor 1 48-port PoE+ switch APs, IP phones, cameras Floor 2 48-port PoE+ switch APs, IP phones, cameras Floor 3 48-port PoE+ switch APs, IP phones, cameras Floor 4 48-port PoE+ switch APs, IP phones, cameras fibre up the riser VLANS VLAN 10 Staff, front desk, POS VLAN 20 Guest Wi-Fi, isolated VLAN 30 Voice, priority VLAN 40 CCTV, no Internet VLAN 50 Servers Wi-Fi 6 access points under one controller; WPA3 for staff; a captive portal by room number for guests.

Hardware:

  • Internet: two ISP links (a fibre line and a backup) on a UTM firewall with dual WAN ports, for failover and load balancing, since guests judge the hotel by its Wi-Fi.
  • Firewall: NAT, rules between VLANs, content filtering, a VPN for remote management and a captive portal for guest login.
  • Core: a layer 3 switch in the server room, routing between the VLANs.
  • Access: a 48-port managed PoE+ switch on each floor with a fibre uplink; PoE powers access points, phones and cameras without extra sockets.
  • Wireless: Wi-Fi 6 (802.11ax) access points under one controller for seamless roaming; WPA3 for staff and an isolated guest SSID with a speed limit per device.
  • Cabling: Cat6 to the rooms (gigabit up to 100 m) and fibre in the risers.
  • Others: an IP PBX with a gateway to the telephone network, a network video recorder for CCTV, and UPS units.

Software: a hotel property management system (reservations, check-in, billing, linked to the keycard locks and POS), POS and accounting software, a hotspot manager for guest login by room number, antivirus, backup and SNMP monitoring.

Addressing: private addresses with VLANs for staff (10), guests (20, isolated), voice (30, QoS priority), CCTV (40, no Internet) and servers (50), assigned by DHCP and translated by NAT.

Justification: VLANs keep guests away from billing and card systems, managed switches and a wireless controller make the network easy to run, and dual ISPs with UPS keep the hotel online.

A LAN design for five departments of Pulchowk Campus PIN 1/27

Asked once

2067 Ashad · Q26+2 marksIf you are assigned to design a LAN for Pulchowk Campus having 5 departments. Each department will have 100 computers locating in 5 rooms each equipped with 20 computers. Make your own justification while selecting connecting devices and accessories.

Design: a hierarchical star LAN for 500 computers (5 departments, each of 5 rooms with 20 computers), with access, distribution and core layers.

A CAMPUS LAN: CORE, DISTRIBUTION, ACCESS Five departments, five rooms each, twenty computers per room: 500 computers. ISP (or NREN) Router and firewall Core switch, layer 3 Server room: DHCP, DNS, file, web Department 1 distribution switch 5 room switches 24-port, 20 PCs each Department 2 distribution switch 5 room switches 24-port, 20 PCs each Department 3 distribution switch 5 room switches 24-port, 20 PCs each Department 4 distribution switch 5 room switches 24-port, 20 PCs each Department 5 distribution switch 5 room switches 24-port, 20 PCs each fibre (OM3 or OM4) Cat6 Each department: one VLAN and one subnet, two or three Wi-Fi access points, a UPS in every closet.
  • Access switches: 25 managed 24-port gigabit switches, one per room, for 20 PCs plus an uplink and spare ports. Switches, not hubs, give every PC dedicated, collision-free bandwidth.
  • Distribution switches: 5 layer 3 switches, one per department, joining its 5 room switches, routing its VLAN and keeping its broadcasts inside.
  • Core switch: one layer 3 switch (two for redundancy) with 10 Gbps fibre ports joining the departments and the server room.
  • Router and firewall: the link to the ISP, with NAT and the security policy.
  • Wireless: two or three Wi-Fi 6 access points per department for laptops and phones.
  • Servers: DHCP, DNS, file, web and mail servers in a central server room.

Accessories: Cat6 UTP for the 500 drops (gigabit, under 100 m); multimode OM3 or OM4 fibre between buildings (10 Gbps over hundreds of metres, immune to lightning surges); RJ45 connectors, patch panels, racks, cable trays, SFP modules, and a UPS in each closet.

Justification: the star topology isolates faults and grows easily; one VLAN and one subnet per department keep traffic local and secure; fibre suits the distances between buildings; the UPS keeps the network running through power cuts.

The shortest path algorithm in link state routing PIN 1/27

Asked once

2070 Ashad · Q75 marksExplain shortest path finding algorithm in link state routing.

Link state routing uses Dijkstra's shortest path algorithm: each router holds the whole topology as a weighted graph and finds the least-cost path from itself to every other node.

  1. Label the source 0 and make it permanent; every other node is infinity.
  2. For each neighbour of the newest permanent node, add the link cost to that node's distance; if the sum is smaller, relabel the neighbour tentatively (distance, via node).
  3. Make the tentative node with the smallest label permanent.
  4. Repeat until every node is permanent, then trace each path back through the labels.
DIJKSTRA ON THE BOOK'S FIGURE 4.12 GRAPH Final labels (distance, previous node) from A; the shortest path A to D in colour. 2 6 7 2 2 1 3 2 4 3 2 A B C E F D G H A (0) B (2, A) C (9, B) E (4, B) F (6, E) G (5, E) H (8, F) D (10, H) A, B, E, F, H, D: 2 + 2 + 2 + 2 + 2 = 10

Example from A: the nodes become permanent in the order B (2, A), E (4, B), G (5, E), F (6, E), H (8, F), C (9, B) and D (10, H). The shortest path from A to D is A, B, E, F, H, D, with cost 10.

Link state routing and how its routing tables are populated PIN 1/27

Asked once

2078 Bhadra · Q55 marksWhat is link state routing algorithm? Show how routing tables is populated in LSR with example.

Link state routing is an adaptive routing algorithm in which each router floods the state of its links to all routers, so that every router builds the full topology and computes its routes with Dijkstra's algorithm.

Populating the tables:

  1. Discover the neighbours with HELLO packets.
  2. Measure the cost of the link to each neighbour.
  3. Build a link state packet: ID, sequence number, age, and neighbours with costs.
  4. Flood the packet to all routers.
  5. Run Dijkstra on the complete database and enter the first hop of each path in the table.
LINK STATE: EACH ROUTER FLOODS ITS LINKS, THEN RUNS DIJKSTRA Each LSP lists only its own links; together they are the whole map. 2 1 2 3 4 1 A B C D E LINK STATE PACKETS (SENDER, SEQUENCE, AGE, NEIGHBOURS) LSP of A neighbours: B 2, C 1 seq, age LSP of B neighbours: A 2, C 2, D 3 seq, age LSP of C neighbours: A 1, B 2, E 4 seq, age LSP of D neighbours: B 3, E 1 seq, age LSP of E neighbours: C 4, D 1 seq, age A's table: B via B (2), C via C (1), D via B (5), E via C (5) A's shortest path tree in colour

Example: links A-B 2, A-C 1, B-C 2, B-D 3, C-E 4 and D-E 1. After flooding, router A computes:

DestinationCostNext hop
B2B
C1C
D5B
E5C

5Transport layer

The token bucket algorithm HOT 7/27

Asked 7 times

2081 Bhadra · Q64 marksDiscuss Token Bucket approach

2076 Chaitra · Q63 marksWhat is token bucket algorithm?

2074 Chaitra · Q64 marksExplain Token Bucket algorithm.

2072 Chaitra · Q54 marksExplain Token Bucket algorithm.

2070 Ashad · Q85 markswith the operation how token bucket works

2069 Chaitra · Q63 marksExplain token bucket algorithm for congestion control.

2066 Poush · Q5working of token bucket

The token bucket algorithm is a traffic shaping algorithm that permits bursts while limiting the average rate. The bucket holds tokens, not packets: tokens are generated at a constant rate r (one every ΔT) up to a capacity C, and a packet may be transmitted only by removing a token.

THE TOKEN BUCKET A token drops in every ΔT up to the capacity; a packet leaves only by taking one, so saved tokens allow a burst. Host T T T network (a) before: 3 tokens saved 5 packets waiting one token added every ΔT capacity 3, full: a new token is discarded Host network (b) after: a burst of 3 2 packets wait for new tokens 3 packets sent at once empty
  1. One token is added every ΔT; when the bucket is full, new tokens are discarded.
  2. A waiting packet is sent if a token is available, and one token is removed (one per byte in the byte-counting version).
  3. If no token is available, the packet waits in the queue; packets are not discarded for lack of tokens.
  4. Implementation: a counter incremented every ΔT up to C and decremented for each packet sent; at zero, nothing is sent.

An idle host saves tokens, so up to C can be sent at once at the full line rate M; the longest burst lasts S=C/(M−r). For C = 6 Mb, M = 10 Mbps and r = 2 Mbps, S = 0.75 s. With 3 saved tokens and 5 packets waiting, 3 packets leave at once and 2 wait for new tokens.

TCP connection establishment and release PIN 3/27

Asked 3 times

2082 Bhadra · Q63+3 marksExplain TCP 3-way hand shaking for connection establishment and release.

2075 Chaitra · Q64 marksExplain connection establishment and termination in TCP.

2074 Chaitra · Q64 marksHow connection is established and released in TCP.

Connection establishment (three-way handshake): the server first performs a passive open (socket, bind, listen) and waits in LISTEN; the client performs an active open.

  1. SYN: the client sends SYN with its initial sequence number, seq = x (8000), and enters SYN-SENT.
  2. SYN + ACK: the server replies with its own ISN, seq = y (15000), and ack = x + 1 (8001), and enters SYN-RECEIVED.
  3. ACK: the client sends ack = y + 1 (15001) with seq = x + 1; both sides enter ESTABLISHED and data transfer begins.
THE THREE-WAY HANDSHAKE, THEN THE FIRST DATA Client ISN 8000, server ISN 15000 (the numbers of the book's figure). A SYN uses up one sequence number. Client active open: connect() Server passive open: listen() CLOSED LISTEN SYN-SENT SYN-RECEIVED ESTABLISHED ESTABLISHED socket, bind port 80, listen, wait for a SYN SYN seq = 8000 SYN + ACK seq = 15000, ack = 8001 ACK seq = 8001, ack = 15001 may carry data data seq = 8001 (1000 bytes), ack = 15001 next expected: 9001 data seq = 15001 (500 bytes), ack = 9001 next expected: 15501

The third segment confirms the server's sequence number and lets an old, delayed SYN be rejected.

Connection release (graceful, four segments): each direction is closed separately, since TCP is full duplex.

  1. FIN: the client sends FIN (seq = u) and enters FIN-WAIT-1.
  2. ACK: the server acknowledges (ack = u + 1) and enters CLOSE-WAIT; the client enters FIN-WAIT-2. The server may still send data (half-close).
  3. FIN: when finished, the server sends its FIN (seq = v) and enters LAST-ACK.
  4. ACK: the client acknowledges (ack = v + 1), waits 2 MSL in TIME-WAIT and closes; the server closes on receiving the ACK.
GRACEFUL RELEASE IN FOUR SEGMENTS Each direction closes on its own (a half-close); the side that closes first waits 2 MSL in TIME-WAIT. Client closes first (active close) Server passive close ESTABLISHED ESTABLISHED FIN-WAIT-1 CLOSE-WAIT FIN-WAIT-2 LAST-ACK TIME-WAIT CLOSED CLOSED FIN seq = 9001, ack = 15501 tells its application ACK seq = 15501, ack = 9002 may still send data (half-closed) FIN seq = 15501, ack = 9002 ACK seq = 9002, ack = 15502 waits 2 MSL: re-ACKs a lost FIN, old segments die out

The leaky bucket algorithm PIN 3/27

Asked 3 times

2082 Baishakh · Q64 marksExplain briefly about leaky-bucket algorithm used for traffic shaping.

2078 Bhadra · Q65 marksExplain about Leaky-Bucket algorithm for congestion control?

2075 Chaitra · Q64 marksExplain briefly about Leaky-Bucket algorithm for congestion control?

The leaky bucket algorithm is a traffic shaping algorithm that turns bursty traffic into a steady stream. Each host's network interface holds a finite queue (the bucket) that releases packets into the network at a constant rate, like water dripping from a hole in a bucket however fast it is poured in.

THE LEAKY BUCKET In at any rate, out through the hole at one steady rate; whatever overflows is lost. bursty input finite bucket, full overflow: lost constant output rate (a) water Host bursty Full? yes discard no queue (bucket) remove packets at a constant rate Network smooth Byte counting, for packets of different sizes: each tick allows n bytes; send while the next packet fits; what is left of n is not carried to the next tick. (b) packets at a host interface
  1. An arriving packet joins the queue if there is space; if the bucket is full, the packet is discarded.
  2. At each clock tick one packet is removed and transmitted; nothing is sent when the queue is empty.
  3. The output is therefore at a fixed rate, however bursty the input.

For variable-length packets a byte counter is used: at each tick the counter is set to n bytes, packets are sent while their size does not exceed the counter, which is reduced by each size, and unused count is not carried forward. With n = 1000 and packets of 200, 700, 500 and 300 bytes, the first tick sends 200 and 700, the second 500 and 300.

Limitations: packets are lost when the bucket overflows, and idle time cannot be saved for later bursts.

The TCP three-way handshake (connection establishment) PIN 2/27

Asked 2 times

2081 Baishakh · Q65 marksExplain the three way handshake principle of a TCP connection between client and server.

2071 Shrawan · Q65 marksHow is TCP connection established? Explain.

TCP is connection-oriented, so before data transfer the client and server exchange three segments, the three-way handshake, which synchronizes their initial sequence numbers (ISN) and confirms that both are ready.

  1. Passive open: the server creates a socket, binds its well-known port, listens, and waits in the LISTEN state.
  2. SYN: the client (active open) sends a segment with SYN = 1 and seq = x, a random ISN (for example 8000), and enters SYN-SENT.
  3. SYN + ACK: the server allocates resources and replies with SYN = 1, ACK = 1, seq = y (15000) and ack = x + 1 (8001), entering SYN-RECEIVED.
  4. ACK: the client sends ACK = 1, seq = x + 1, ack = y + 1 (15001) and enters ESTABLISHED; the server enters ESTABLISHED on receiving it. Data may now flow both ways.
THE THREE-WAY HANDSHAKE, THEN THE FIRST DATA Client ISN 8000, server ISN 15000 (the numbers of the book's figure). A SYN uses up one sequence number. Client active open: connect() Server passive open: listen() CLOSED LISTEN SYN-SENT SYN-RECEIVED ESTABLISHED ESTABLISHED socket, bind port 80, listen, wait for a SYN SYN seq = 8000 SYN + ACK seq = 15000, ack = 8001 ACK seq = 8001, ack = 15001 may carry data data seq = 8001 (1000 bytes), ack = 15001 next expected: 9001 data seq = 15001 (500 bytes), ack = 9001 next expected: 15501

Three segments are needed so that each side's ISN is acknowledged and an old, delayed SYN cannot open a false connection: the client rejects an unexpected SYN + ACK with RST.

The TCP sliding window PIN 2/27

Asked 2 times

2078 Bhadra · Q104 marksb) TCP sliding window

2066 Bhadra · Q5b3 marksi) TCP Sliding Window Protocol

The TCP sliding window is TCP's byte-oriented mechanism for flow control. In every segment the receiver advertises the free space in its buffer, the receive window (rwnd), and the sender may have at most rwnd bytes sent but unacknowledged.

  1. The sender's bytes fall into four regions: acknowledged, sent but unacknowledged, usable (may be sent now), and not yet allowed.
  2. The window starts at the last acknowledgement number and is rwnd bytes long: for ACK 3001 and rwnd 4000, bytes 3001 to 7000 may be outstanding.
  3. When ACK 5001 arrives with rwnd 4000, the window slides right to cover bytes 5001 to 9000.
  4. If the receiver's buffer fills, rwnd = 0 stops the sender; a persist timer sends probes until the window opens.
TCP'S SLIDING WINDOW The receiver advertises rwnd in every segment; the sender may have at most rwnd bytes unacknowledged. 1001 2001 3001 4001 5001 6001 7001 8001 9001 window = rwnd = 4000 bytes: 3001 to 7000 sent, acknowledged in flight (sent, not ACKed) usable now cannot send yet byte ... An ACK arrives: ack = 5001, window = 4000. The window now covers bytes 5001 to 9000. 1001 2001 3001 4001 5001 6001 7001 8001 9001 window slides 2000 bytes right: 5001 to 9000 sent, acknowledged in flight usable now cannot send yet byte ... rwnd = 0 stops the sender; a persist timer then sends small probes until the window opens. With congestion control the sender's limit is min(rwnd, cwnd). The 16-bit field allows 65,535 bytes; window scaling allows more.

The window scale option enlarges the 16-bit window, and with congestion control the sender's limit is min(rwnd, cwnd).

How the transport layer delivers the complete message in proper order PIN 1/27

Asked once

2080 Bhadra · Q64 marksHow does the transport layer ensure that the complete message arrive at the destination and in the proper order?

The transport layer (TCP) turns IP's unreliable delivery into a complete, ordered byte stream through these steps:

  1. Connection setup: the three-way handshake synchronizes both initial sequence numbers.
  2. Sequence numbers: every byte is numbered, so gaps, duplicates and misordering are detected.
  3. Checksum: a corrupted segment is discarded and treated as lost.
  4. Acknowledgement: the receiver returns the next byte expected (cumulative ACK).
  5. Retransmission: a segment unacknowledged when its timer expires, or after three duplicate ACKs, is resent.
  6. Reordering: early segments wait in the receive buffer and data passes up only when no gap remains.
  7. Flow control and release: the window prevents overflow, and FIN shows where the stream ends.

Example: of segments 1001, 2001 and 3001, segment 2001 is lost; the receiver keeps 3001 and repeats ACK 2001; after the timeout 2001 is resent and bytes 1001 to 4000 are delivered in order (ACK 4001).

HOW TCP RECOVERS A LOST SEGMENT Sequence numbers show the gap, the ACK reports it, the timer resends it: 3,000 bytes arrive whole and in order. Sender keeps a copy until ACKed Receiver buffers, reorders, ACKs seq 1001, 1000 bytes lost seq 2001, 1000 bytes seq 3001, 1000 bytes ACK 2001 duplicate ACK 2001 bytes 1001 to 2000 in order 3001 to 4000 arrive early: kept in the buffer retransmission timer for 2001 (RTO) runs out seq 2001 again ACK 4001 gap filled: bytes 1001 to 4000 go to the application in order Three duplicate ACKs would trigger the resend sooner (fast retransmit); a corrupt segment fails its checksum and is treated as lost.

Graceful termination of a TCP connection PIN 1/27

Asked once

2072 Kartik · Q66 marksExplain how a TCP connection can be gracefully terminated.

A TCP connection is gracefully terminated when both sides close their direction of the full-duplex connection with FIN and ACK, so that no data in transit is lost. It takes four segments (shown with the client closing first):

  1. FIN from the client: after its application finishes sending, the client sends FIN = 1, seq = u (9001), and enters FIN-WAIT-1. The FIN consumes one sequence number.
  2. ACK from the server: the server replies ack = u + 1 (9002), informs its application and enters CLOSE-WAIT; on receiving it the client enters FIN-WAIT-2. The connection is half-closed: the server may still send its remaining data.
  3. FIN from the server: when its application closes, the server sends FIN = 1, seq = v (15501), and enters LAST-ACK.
  4. ACK from the client: the client replies ack = v + 1 (15502) and enters TIME-WAIT; the server closes on receiving it.
GRACEFUL RELEASE IN FOUR SEGMENTS Each direction closes on its own (a half-close); the side that closes first waits 2 MSL in TIME-WAIT. Client closes first (active close) Server passive close ESTABLISHED ESTABLISHED FIN-WAIT-1 CLOSE-WAIT FIN-WAIT-2 LAST-ACK TIME-WAIT CLOSED CLOSED FIN seq = 9001, ack = 15501 tells its application ACK seq = 15501, ack = 9002 may still send data (half-closed) FIN seq = 15501, ack = 9002 ACK seq = 9002, ack = 15502 waits 2 MSL: re-ACKs a lost FIN, old segments die out

TIME-WAIT lasts twice the maximum segment lifetime (2 MSL), so that a lost final ACK can be sent again when the server repeats its FIN, and delayed segments of the old connection die out before the same socket pair is reused. If the server has no more data, it may combine its ACK and FIN, giving a three-segment close. By contrast, RST aborts a connection at once and discards unsent data.

6Application layer

SMTP: how it operates, step by step PIN 3/27

Asked 3 times

2081 Bhadra · Q76 marksList the step-by-step working principle of SMTP.

2072 Chaitra · Q104 marksSimple Mail Transfer Protocol

2067 Ashad · Q103 marksHow the protocol SMTP does operate?

SMTP (Simple Mail Transfer Protocol, RFC 5321) transfers mail from the sender's mail server to the receiver's mail server over a TCP connection to port 25. It is a push protocol based on text: the client sends ASCII commands and the server answers each with a three-digit reply code. Step by step:

  1. Submit: the sender's user agent hands the message to its mail server, which queues it.
  2. Find the server: the sender's server looks up the MX record of the recipient's domain in DNS.
  3. Connect: it opens a TCP connection to that server's port 25; the server greets with 220.
  4. Handshake: the client sends HELO (or EHLO) with its name; the server replies 250.
  5. Envelope: MAIL FROM:<sender> (250 OK), then RCPT TO:<recipient> for each recipient (250 OK, or 550 for an unknown mailbox).
  6. Message: DATA (354); the client sends the header lines, a blank line and the body, ending with a line holding only "."; the server replies 250 and queues it.
  7. Close: QUIT (221) and the TCP connection is released.
  8. Delivery: the receiving server places the mail in the recipient's mailbox, from which POP3 or IMAP retrieves it.
AN SMTP SESSION Sender's mail server (client) to receiver's mail server (server), TCP port 25: text commands, three-digit replies. SMTP client sender's mail server SMTP server receiver's server, port 25 TCP connection to port 25 (three-way handshake) 220 mail.example.org Service ready HELO mail.example.com 250 Hello mail.example.com MAIL FROM:<sita@example[.]com> 250 OK RCPT TO:<ram@example[.]org> 250 OK DATA 354 Start mail input; end with a line holding only "." header lines, blank line, body, then "." 250 OK, message queued QUIT 221 Service closing TCP connection closed CONNECTION SETUP greeting, then HELO MAIL TRANSFER envelope, then DATA TERMINATION QUIT and close MAIL FROM and RCPT TO are the envelope; the From: and To: lines inside DATA are the letter's own header

If the receiving server is unreachable, the message stays in the queue and is retried before a failure notice is returned.

How a DNS request is resolved: the working principle of DNS PIN 2/27

Asked 2 times

2079 Bhadra · Q74 marksHow is the DNS request from a client computer resolved from the authoritative server? Explain with necessary diagrams.

2076 Chaitra · Q74 marksExplain the working principle of DNS with a proper diagram.

A client's DNS request is resolved by its local DNS server, which walks the name server hierarchy from a root server down to the authoritative server of the domain and caches every answer. For www.youtube.com:

ITERATIVE QUERY: WWW.YOUTUBE.COM The local server asks each server in turn; every server but the last replies with a referral, not the answer. Root server one of 13 names, a to m TLD server for .com a.gtld-servers.net Authoritative server ns1.google.com (youtube.com) Requesting host browser wants www.youtube.com Local DNS server the ISP's resolver, with a cache 1 8 2 3 4 5 6 7 Root and TLD reply with a referral: the next servers to ask. Only the authoritative server gives the answer. THE EIGHT STEPS 1 Host asks the local server: address of www.youtube.com? 2 Local server asks a root server 3 Root refers it to the .com TLD servers 4 Local server asks a .com TLD server 5 TLD refers it to youtube.com's servers (ns1.google.com) 6 Local server asks the authoritative server 7 Authoritative server answers with the A record 8 Local server caches it and returns it to the host
  1. The client's resolver sends a recursive query for the A record of www.youtube.com to its local DNS server (UDP port 53).
  2. If the answer is not cached, the local server asks a root server.
  3. The root replies with a referral to the .com TLD servers.
  4. The local server asks a .com TLD server.
  5. The TLD server refers it to the authoritative servers of youtube.com (ns1.google.com).
  6. The local server asks the authoritative server.
  7. The authoritative server returns the A record with the authoritative answer flag set.
  8. The local server caches the record for its TTL and returns the address to the client.

Web server and file server communication, with the protocols used PIN 2/27

Asked 2 times

2075 Ashwin · Q72 marksHow web server communication and file server communication are possible in network. Explain with used protocols.

2073 Shrawan · Q66 marksHow web server communication and file server communication are possible in network, explain with used protocols.

Both follow the client-server model over TCP/IP: a client process connects to a server process identified by its IP address and a well-known port.

Web server communication (HTTP or HTTPS over TCP):

  1. DNS (UDP port 53) resolves the server's name to its IP address.
  2. The browser opens a TCP connection to port 80 (443, with TLS, for HTTPS).
  3. It sends an HTTP request: GET /index.html and the headers.
  4. The web server returns a response: status line (200 OK), headers, the page.
  5. Embedded objects come over the same persistent connection; IP routes every packet.

File server communication (FTP over TCP):

  1. The FTP client opens a control connection to the server's port 21; the server replies 220.
  2. It logs in with USER and PASS (331, then 230).
  3. For each file a data connection is set up: in active mode the server connects from port 20 (PORT); in passive mode the client connects to a port the server names (PASV).
  4. RETR downloads or STOR uploads the file on the data connection, which then closes (226).
  5. QUIT ends the session (221).
AN FTP SESSION: TWO CONNECTIONS Active mode: commands on the control connection to port 21; the file on a separate data connection from port 20. FTP client 192.168.1.10 FTP server port 21 control, 20 data connect to port 21 (TCP handshake) 220 Service ready USER anuj 331 Password required PASS ******** 230 User logged in PORT 192,168,1,10,195,80 (port 50000) 200 PORT command OK RETR notes.pdf 150 Opening data connection data: port 20 connects to port 50000 data: the file's bytes, then close 226 Transfer complete QUIT 221 Goodbye: control connection closes Control connection server port 21, opened by the client open for the whole session commands and replies, one text line at a time Data connection server port 20 in active mode a new one for each file or listing closed when the transfer ends Passive mode (PASV) the server replies 227 with a high port and the client opens the data connection itself, so it passes NAT and firewalls PORT h1,h2,h3,h4,p1,p2: data port = p1 x 256 + p2 = 195 x 256 + 80 = 50000

Other file server protocols: TFTP (UDP 69) for simple transfers, SFTP over SSH (port 22), and SMB (TCP 445) or NFS (2049) for shared folders in a LAN.

FTP: how a client connects, and the data transfer process with its ports PIN 2/27

Asked 2 times

2080 Bhadra · Q74 marksHow does an FTP client connect to an FTP server?

2076 Ashwin · Q76 marksExplain working principle of FTP with data transfer process including proper port connection. Use proper diagram to justify your answer.

FTP (File Transfer Protocol, RFC 959) copies files between a client and a server over two TCP connections: a control connection to server port 21, kept for the whole session for commands and replies, and a data connection, from server port 20 in active mode, opened for each file and closed after it. Each side has a control process and a data transfer process.

AN FTP SESSION: TWO CONNECTIONS Active mode: commands on the control connection to port 21; the file on a separate data connection from port 20. FTP client 192.168.1.10 FTP server port 21 control, 20 data connect to port 21 (TCP handshake) 220 Service ready USER anuj 331 Password required PASS ******** 230 User logged in PORT 192,168,1,10,195,80 (port 50000) 200 PORT command OK RETR notes.pdf 150 Opening data connection data: port 20 connects to port 50000 data: the file's bytes, then close 226 Transfer complete QUIT 221 Goodbye: control connection closes Control connection server port 21, opened by the client open for the whole session commands and replies, one text line at a time Data connection server port 20 in active mode a new one for each file or listing closed when the transfer ends Passive mode (PASV) the server replies 227 with a high port and the client opens the data connection itself, so it passes NAT and firewalls PORT h1,h2,h3,h4,p1,p2: data port = p1 x 256 + p2 = 195 x 256 + 80 = 50000
  1. Control connection: the client opens TCP to port 21; the server replies 220 Service ready.
  2. Login: USER (331 Password required), then PASS (230 User logged in).
  3. Transfer type: TYPE I for binary or TYPE A for text (200).
  4. Data connection: in active mode the client sends PORT with its IP address and a port, for example 192,168,1,10,195,80 = port 195 × 256 + 80 = 50000, and the server connects from port 20 to it; in passive mode the client sends PASV, the server replies 227 with a high port, and the client connects.
  5. Data transfer process: RETR (download) or STOR (upload); the server replies 150, the file flows on the data connection, the data connection closes, and 226 Transfer complete arrives on the control connection.
  6. Close: QUIT, 221 Goodbye, and the control connection closes.

Commands never mix with the file data (out-of-band control), and every file or listing uses a new data connection.

How a DNS recursive query works PIN 1/27

Asked once

2082 Baishakh · Q72 marksHow does a DNS recursive query work?

In a recursive query the server asked takes full responsibility for the answer:

  1. The host asks its local DNS server for www.youtube.com with the RD (recursion desired) flag set.
  2. If it is not cached, each server passes the query on: local to root, root to .com TLD, TLD to authoritative.
  3. The answer returns along the chain; the local server caches it and gives the host the address or an error.
RECURSIVE QUERY: WWW.YOUTUBE.COM Each server takes the whole job: it asks the next server itself and waits, and the answer comes back along the chain. Root server one of 13 names, a to m TLD server for .com a.gtld-servers.net Authoritative server ns1.google.com (youtube.com) Requesting host browser wants www.youtube.com Local DNS server the ISP's resolver, with a cache 1 8 2 7 3 6 4 5 Every server keeps state and waits for the server below it. That load is why root and TLD servers refuse recursion in practice: a host asks its local server recursively, and the local server works iteratively. THE EIGHT STEPS 1 Host asks the local server: address of www.youtube.com? 2 Local server passes the query to a root server 3 Root server passes it to the .com TLD server 4 TLD server passes it to youtube.com's server 5 Authoritative server returns the address to the TLD 6 TLD server returns it to the root server 7 Root server returns it to the local server 8 Local server caches it and answers the host

Iterative query for browsing www.youtube.com PIN 1/27

Asked once

2082 Bhadra · Q76 marksExplain iterative query for browsing www.youtube.com

In an iterative query each DNS server answers at once with the best it has, the answer or a referral to servers closer to it, and the asker (the local DNS server) then queries those servers itself. Browsing www.youtube.com with an empty cache:

ITERATIVE QUERY: WWW.YOUTUBE.COM The local server asks each server in turn; every server but the last replies with a referral, not the answer. Root server one of 13 names, a to m TLD server for .com a.gtld-servers.net Authoritative server ns1.google.com (youtube.com) Requesting host browser wants www.youtube.com Local DNS server the ISP's resolver, with a cache 1 8 2 3 4 5 6 7 Root and TLD reply with a referral: the next servers to ask. Only the authoritative server gives the answer. THE EIGHT STEPS 1 Host asks the local server: address of www.youtube.com? 2 Local server asks a root server 3 Root refers it to the .com TLD servers 4 Local server asks a .com TLD server 5 TLD refers it to youtube.com's servers (ns1.google.com) 6 Local server asks the authoritative server 7 Authoritative server answers with the A record 8 Local server caches it and returns it to the host
  1. Host to local server: the browser's resolver asks the local DNS server (the ISP's resolver) for the A record of www.youtube.com.
  2. Local server to root: it sends the query to a root server.
  3. Root referral: the root returns the NS records of the .com TLD servers (a.gtld-servers.net and others) with their addresses.
  4. Local server to TLD: it asks a .com TLD server.
  5. TLD referral: the TLD returns the authoritative servers of youtube.com (ns1.google.com and others).
  6. Local server to authoritative server: it asks ns1.google.com.
  7. Answer: the authoritative server returns the A record of www.youtube.com (or a CNAME, resolved the same way).
  8. Reply to host: the local server caches the records for their TTL and returns the IP address; the browser connects to port 443 and fetches the page with HTTPS.

The host sends one query and the local server three, so the root and TLD servers stay lightly loaded; a second visit within the TTL is answered from the cache.

The DHCP lease renewal process PIN 1/27

Asked once

2082 Baishakh · Q76 marksDiscuss DHCP lease renew process with example diagram.

DHCP (UDP ports 67 and 68) lends a host an IP address for a fixed lease time. The lease starts with DORA (DISCOVER, OFFER, REQUEST, ACK) and must be renewed before it expires, using two timers carried in the DHCPACK: T1 = 50 percent and T2 = 87.5 percent of the lease.

RENEWING A DHCP LEASE A 24-hour lease: renew at T1 = 50 percent, rebind at T2 = 87.5 percent, give up at expiry. Example: a phone joins the hostel Wi-Fi at 07:00. T1 falls at 19:00, T2 at 04:00, and the lease expires at 07:00 the next day. ACK at any point: a fresh 24 h lease from now BOUND: USE THE ADDRESS RENEWING REBINDING 0 h lease starts 12 h T1 = 50% 21 h T2 = 87.5% 24 h expiry From 0 to T1: bound the client uses its address and sends nothing; the lease time, T1 and T2 came in the DHCPACK At T1: renewing unicast DHCPREQUEST to the server that granted the lease; ACK: renewed, timers restart; NAK: stop, and start again with DISCOVER At T2: rebinding broadcast DHCPREQUEST to any DHCP server; an ACK from any of them renews it At expiry no ACK: stop using the address, go back to DISCOVER
  1. Bound (0 to T1): the client uses the address.
  2. Renewing (at T1): the client unicasts a DHCPREQUEST to the server that granted the lease. A DHCPACK renews the lease for a fresh full period and restarts T1 and T2; a DHCPNAK makes the client drop the address and start again with DISCOVER.
  3. Rebinding (at T2): if the original server has not answered, the client broadcasts the DHCPREQUEST to any DHCP server; an ACK from any of them renews the lease.
  4. Expiry: with no ACK by the end of the lease, the client stops using the address and returns to the INIT state to send DHCPDISCOVER.

Example: a phone joins hostel Wi-Fi at 07:00 with a 24-hour lease. T1 = 0.5 × 24 = 12 h, so it renews by unicast at 19:00; if the server is down, T2 = 0.875 × 24 = 21 h, so it rebinds by broadcast at 04:00; with no reply by 07:00 the next day the lease expires and DORA starts again.

Sending images over 7-bit SMTP: MIME PIN 1/27

Asked once

2071 Shrawan · Q78 marksSMTP is a text based protocol and uses 7 bit ascii. How can this be used to transmit sometimes like images? Explain.

SMTP carries only 7-bit ASCII text in short lines, while an image is binary data with byte values from 0 to 255. MIME (Multipurpose Internet Mail Extensions, RFC 2045 to 2049) lets SMTP carry it unchanged: it adds headers that describe the content and encodes the binary data as 7-bit text, which the receiver's user agent decodes.

MIME headers:

  • MIME-Version: 1.0 declares a MIME message.
  • Content-Type: the media type, such as image/jpeg, text/plain, application/pdf, or multipart/mixed with a boundary string between the parts.
  • Content-Transfer-Encoding: base64 for binary data, quoted-printable for mostly ASCII text, 7bit for plain text.
  • Content-Disposition, Content-ID, Content-Description: the attachment's file name, a reference, a description.

Base64 encoding, step by step:

  1. Take the image 3 bytes (24 bits) at a time.
  2. Split the 24 bits into four 6-bit groups.
  3. Map each group (0 to 63) to a printable character: A to Z, a to z, 0 to 9, + and /.
  4. Pad the end with = and break the lines every 76 characters.
BASE64: AN IMAGE AS 7-BIT TEXT Every 3 bytes (24 bits) become 4 characters of 6 bits each, all printable ASCII that SMTP can carry. BYTES (HEX) BITS 6-BIT GROUPS VALUES CHARACTERS FF D8 FF 1 1 1 1 1 1 1 1 1 1 0 1 1 0 0 0 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 0 1 1 0 0 0 1 1 1 1 1 1 1 1 63 / 61 9 35 j 63 / regroup THE 64 CHARACTERS 0 to 25: A to Z 26 to 51: a to z 52 to 61: 0 to 9 62: + and 63: / padding at the end: = SIZE 3 bytes in, 4 characters out: a 3 MB photo travels as about 4 MB of text IN THE MAIL Content-Type: image/jpeg Content-Transfer-Encoding: base64 /9j/4AAQSkZJRgAB... (every JPEG starts /9j/)

Example: a JPEG begins with FF D8 FF = 11111111 11011000 11111111; regrouped, 111111 111101 100011 111111 = 63, 61, 35, 63 = /9j/.

Content-Type: multipart/mixed; boundary="XyZ42"
      --XyZ42
      Content-Type: image/jpeg; name="photo.jpg"
      Content-Transfer-Encoding: base64
      
      /9j/4AAQSkZJRgAB...
      --XyZ42--

At the receiver the user agent reads Content-Type and Content-Transfer-Encoding, decodes the base64 back into the original bytes, and displays or saves the image. The cost is size: every 3 bytes become 4 characters, about 33 percent more.

How a request from an HTTP client is served by an HTTP server PIN 1/27

Asked once

2069 Chaitra · Q76 marksWith an example explain how a request initiated by a HTTP client is served by a HTTP server.

Example: a browser opens http://www.example.com/index.html.

  1. DNS lookup: the browser resolves www.example.com to its IP address, 192.0.2.80.
  2. TCP connection: it opens a connection to 192.0.2.80, port 80, with the three-way handshake.
  3. Request: it sends the request message:
    GET /index.html HTTP/1.1
          Host: www.example.com
          User-Agent: Mozilla/5.0
          Connection: keep-alive
  4. Processing: the web server process accepts the connection, parses the request line and headers, maps /index.html to the file in its document root (or runs a script for dynamic content), and checks that the file exists and that access is allowed.
  5. Response: it returns a status line, headers, a blank line and the page:
    HTTP/1.1 200 OK
          Content-Type: text/html
          Content-Length: 5120
          
          <html> ... </html>
  6. Rendering: the browser parses the HTML and requests each embedded object (images, style sheets, scripts) the same way, over the same persistent connection.
  7. Close: the connection closes after the last object or an idle timeout. A missing file would give the status line 404 Not Found.
SERVING ONE HTTP REQUEST Browser and web server, time running down the page: a TCP connection, then requests and responses. Browser the client Web server listening on port 80 SYN SYN + ACK ACK, then GET /index.html finds index.html 200 OK + the page GET /logo.png (same connection) 200 OK + the image FIN: close the connection 1 RTT 1 RTT + transfer REQUEST MESSAGE GET /index.html HTTP/1.1 Host: www.example.com User-Agent: Mozilla/5.0 Accept: text/html Connection: keep-alive (a blank line ends the headers) request line header lines RESPONSE MESSAGE HTTP/1.1 200 OK Content-Type: text/html Content-Length: 5120 Cache-Control: max-age=3600 (blank line) <html> ... the page ... </html> status line header lines body Non-persistent (HTTP/1.0): a new TCP connection for every object, 2 RTT each. Persistent (HTTP/1.1 default): one connection carries the page and all its objects.

HTTP is stateless: the server keeps nothing from this exchange, and a later request is served afresh, with a cookie carrying any session.

Server socket programming: bind, listen and accept PIN 1/27

Asked once

2081 Bhadra · Q104 marksServer Socket programming for bind, listen and accept

A TCP server prepares its socket in three calls after creating it:

  • bind(): attaches the server's IP address and well-known port to the socket, so clients know where to connect.
  • listen(): makes the socket passive and sets the length of the queue of pending connections.
  • accept(): blocks until a client's connection completes, then returns a new socket for that client while the listening socket keeps listening.
int lfd = socket(AF_INET, SOCK_STREAM, 0);     /* TCP socket        */
      struct sockaddr_in a = {0};
      a.sin_family = AF_INET;
      a.sin_port = htons(5000);                       /* port 5000         */
      a.sin_addr.s_addr = htonl(INADDR_ANY);          /* any local address */
      bind(lfd, (struct sockaddr *)&a, sizeof a);   /* name the socket   */
      listen(lfd, 5);                                 /* queue of 5        */
      int cfd = accept(lfd, NULL, NULL);              /* wait for a client */
      /* then recv() and send() on cfd, and close(cfd) */

7Introduction to IPv6

Header translation (address family translation) PIN 2/27

Asked 2 times

2079 Bhadra · Q84 marksExplain header translation mechanism for transition from IPV4 to IPV6.

2075 Chaitra · Q85 marksExplain what you mean by address family translation in IPv4/IPv6 migration process with an appropriate figure.

Header translation, or address family translation, is used when an IPv6-only node must communicate with an IPv4-only node: tunneling cannot help, since the receiver understands only its own version. A translator between the two networks converts each packet's header to the other version and maps the addresses between the two address families.

HEADER TRANSLATION: NAT64 WITH DNS64 RFC 6146 and RFC 6147, on the SIIT field rules of RFC 7915: one header rewritten as the other. DNS64: A 192.0.2.33 becomes AAAA 64:ff9b::c000:221 IPv6-only host 2001:db8:acad:1::20 NAT64 translator IPv4 pool 203.0.113.9 keeps a state table IPv4-only server 192.0.2.33 AAAA query IPv6 packet to 64:ff9b::c000:221 IPv4 packet 203.0.113.9 to 192.0.2.33 HOW EACH IPV6 FIELD IS REWRITTEN AS IPV4 IPv6 field becomes in IPv4 Version 6 Version 4, header length 5 (20 bytes, no options) Traffic class Type of service (copied) Flow label dropped: IPv4 has no such field Payload length Total length = payload length + 20 Next header Protocol (ICMPv6 58 becomes ICMP 1); extension headers dropped Hop limit Time to live (decremented, as a router does) 128-bit addresses 32-bit: the last 32 bits, or an address from the pool (no checksum) Header checksum computed; TCP and UDP checksums adjusted
  1. Address: the IPv4 address is taken from the rightmost 32 bits of the mapped IPv6 address (64:ff9b::c000:221 gives 192.0.2.33); a stateful translator (NAT64) gives the IPv6 source a public IPv4 address and port.
  2. Version 6 becomes 4, with a 20-byte header.
  3. Traffic class is copied into type of service; the flow label is discarded.
  4. Payload length plus 20 becomes total length.
  5. Next header becomes protocol (ICMPv6 58 becomes ICMP 1); extension headers are dropped, a fragment header becoming the IPv4 fragment fields.
  6. Hop limit becomes time to live.
  7. Header checksum is computed; TCP and UDP checksums are adjusted.

Replies are translated in the reverse direction, and DNS64 supplies the IPv6 form of an IPv4-only server's address.

How an IPv6 host acquires an address automatically PIN 1/27

Asked once

2080 Bhadra · Q85 marksHow does on IPv6 machine acquire IPv6 address automatically?

An IPv6 host acquires an address automatically by stateless address autoconfiguration (SLAAC, RFC 4862), using the ICMPv6 neighbour discovery messages:

HOW A HOST CONFIGURES ITSELF: SLAAC RFC 4862 with neighbour discovery (ICMPv6, RFC 4861): no server needed, the router only advertises the prefix. New host MAC 00-00-5E-00-53-01 Other nodes on the link Router fe80::1, advertises the prefix link-local fe80::200:5eff:fe00:5301 1 NS (135) to ff02::1:ff00:5301 DAD: is this address in use? 2 no reply in 1 second: the address is unique RS (133) to ff02::2, all routers router solicitation: any router here? 3 RA (134) to ff02::1, all nodes prefix 2001:db8:acad:1::/64, lifetimes, M and O flags 4 global 2001:db8:acad:1:200:5eff:fe00:5301, checked by DAD; the router becomes the default gateway 5 M flag set: DHCPv6 assigns the address. O flag set: DHCPv6 gives only DNS and other settings. 6 THE INTERFACE ID BY MODIFIED EUI-64 (OR A RANDOM ID, FOR PRIVACY) MAC address 00-00-5E-00-53-01 split in half 00-00-5E | 00-53-01 insert FF-FE 00-00-5E-FF-FE-00-53-01 flip bit 7 (U/L) 02-00-5E-FF-FE-00-53-01 interface ID 0200:5eff:fe00:5301 64-bit prefix from the RA + 64-bit interface ID = the full 128-bit address.
  1. Link-local address: the host forms fe80::/64 plus a 64-bit interface ID, made from its MAC by modified EUI-64 (MAC 00-00-5E-00-53-01 gives fe80::200:5eff:fe00:5301) or chosen at random for privacy.
  2. Duplicate address detection: it sends a neighbour solicitation to the solicited-node group of that address; with no neighbour advertisement in reply, the address is unique and is assigned.
  3. Router solicitation to all routers, ff02::2.
  4. Router advertisement from the router to all nodes, ff02::1, carrying the 64-bit prefix (say 2001:db8:acad:1::/64), its lifetimes and the M and O flags.
  5. Global address: prefix plus interface ID, checked again by DAD; the router's link-local address becomes the default gateway.
  6. DHCPv6 if flagged: with the M flag set a stateful DHCPv6 server assigns the address; with the O flag set DHCPv6 supplies only DNS and other settings.

The importance and implementation of 6RD PIN 1/27

Asked once

2081 Bhadra · Q84 marksExplain the importance and implementation approach of 6RD for IPv6 based services on the existing IPv4 networking.

6RD (IPv6 rapid deployment, RFC 5969) lets an ISP offer IPv6 over its existing IPv4 access network. Importance: the IPv4 network needs no upgrade; unlike 6to4 it uses the ISP's own prefix and relays, so the IPv6 service is reliable and under the ISP's control; it is stateless and scales; and customers get a stable delegated prefix.

Implementation approach:

  1. The ISP reserves a 6RD prefix from its own space and installs border relay (BR) routers between its IPv4 network and the IPv6 Internet.
  2. Each customer edge (CE) router receives the 6RD prefix, its length, the number of common IPv4 bits to drop and the BR address, through DHCPv4 option 212 or configuration.
  3. The CE builds its delegated prefix: the 6RD prefix followed by its IPv4 address bits (2001:db8::/32 and 203.0.113.5 give 2001:db8:cb00:7105::/64).
  4. The CE encapsulates IPv6 in IPv4 (protocol 41) to the BR, or straight to other CEs; the BR decapsulates and forwards natively.

8Network security

The steps and operation of the RSA algorithm HOT 5/27

Asked 5 times

2078 Bhadra · Q9Write down the steps involved in RSA encryption algorithm.

2073 Shrawan · Q85 marksExplain RSA algorithm with example.

2072 Chaitra · Q9Write down the steps involved in RSA encryption algorithm.

2071 Chaitra · Q96 marksExplain about RSA algorithm in detail.

2069 Chaitra · Q94 marksDescribe the operation of RSA algorithm.

The RSA algorithm (Rivest, Shamir and Adleman, 1977) is a public key algorithm. The receiver makes a key pair once; anyone encrypts with the public key, and only the private key decrypts. Its security rests on the difficulty of factoring the product of two large primes.

  1. Choose two large primes p and q, with p≠q.
  2. Compute the modulus n=p×q.
  3. Compute ϕ(n)=(p−1)(q−1).
  4. Choose the public exponent e, with 1<e<ϕ(n) and gcd(e,ϕ(n))=1.
  5. Compute the private exponent d, the inverse of e: (e×d)modϕ(n)=1.
  6. Keys: the public key is (e,n), the private key (d,n).
  7. Encryption of a message number M<n: C=Memodn.
  8. Decryption: M=Cdmodn.
RSA: MAKE THE KEYS ONCE, THEN ENCRYPT AND DECRYPT The card's example: p = 7, q = 11, e = 13, and the letter E sent as M = 5 (A = 1 to Z = 26). KEY GENERATION (DONE ONCE, BY THE RECEIVER B) 1 Choose two primes p and q p = 7, q = 11 2 n = p × q n = 7 × 11 = 77 3 φ(n) = (p - 1)(q - 1) φ = 6 × 10 = 60 4 Choose e: 1 < e < φ, gcd(e, φ) = 1 e = 13 5 Find d: (e × d) mod φ = 1 d = 37: 13 × 37 = 481 = 8 × 60 + 1 Public key (13, 77) (e, n): anyone may have it Private key (37, 77) (d, n): B keeps it secret USE (EVERY MESSAGE) A encrypts with B's public key C = Me mod n E: M = 5, C = 513 mod 77 = 26 ciphertext 26 crosses the network B decrypts with its private key M = Cd mod n M = 2637 mod 77 = 5, the letter E Signing swaps the keys: S = Md mod n; anyone checks Se mod n = M. Security: d needs φ(n), and φ(n) needs the factors p and q; with n of 2048 bits, factoring n is out of reach. Rule for words: n must exceed the largest letter value (n > 26 for A = 1 to Z = 26); each letter is encrypted alone.

Example: p=7, q=11, so n=77 and ϕ(n)=60. Choose e=13; then d=37, since 13×37=481=8×60+1. For the letter E, M=5:

C = 5^13 mod 77:   5^2 = 25, 5^4 = 9, 5^8 = 4   so C = 4 x 9 x 5 mod 77 = 26
      M = 26^37 mod 77:  26^32 = 60, 26^4 = 58          so M = 60 x 58 x 26 mod 77 = 5

Decryption recovers the message because ed=1+kϕ(n) and, by Euler's theorem, Med≡M(modn). The algorithm is secure because finding d from the public key needs ϕ(n), which needs the factors of n; with a 2048-bit modulus, factoring is infeasible.

How a digital signature works PIN 4/27

Asked 4 times

2081 Baishakh · Q104 marksb) Digital signature

2076 Chaitra · Q92 marksHow does a Digital Signature work?

2075 Chaitra · Q104 marksa) Digital Signature

2072 Kartik · Q104 marksa) Digital signature

A digital signature is created with the sender's private key and checked with its public key, using a hash function.

Signing at the sender A:

  1. Hash the message M (SHA-256) to a fixed-length digest.
  2. Encrypt the digest with A's private key: this is the signature S.
  3. Send M together with S (and A's certificate).

Verifying at the receiver B:

  1. Hash the received message again: digest H1.
  2. Decrypt S with A's public key: digest H2.
  3. If H1=H2 the signature is valid; otherwise the message was altered or the signature forged.
DIGITAL SIGNATURE: SIGN WITH THE PRIVATE KEY, VERIFY WITH THE PUBLIC KEY Only a digest of the message is signed: small, fast, and any change to the message changes it. SIGNING, AT THE SENDER A Message M the document Hash function SHA-256 Digest 256 bits Encrypt the digest with A's private key Signature S sent with M M and S travel together; A's certificate gives B the public key VERIFYING, AT THE RECEIVER B Message M as received Hash function the same one Digest H1 from M Compare H1 = H2 ? Digest H2 from S Decrypt S with A's public key Equal: valid. A sent it (authentication), it is unchanged (integrity), and A cannot deny it (non-repudiation). Different: the message was altered or the signature forged; reject it. M itself is not encrypted: a signature alone gives no confidentiality.

Only A's private key can produce S, so the signature gives authentication, integrity and non-repudiation, but not confidentiality. Signing the short digest instead of the whole message keeps it fast, and a certificate from a certification authority binds A's public key to A.

How a packet filtering firewall works PIN 3/27

Asked 3 times

2076 Chaitra · Q104 marksExplain how packet filtering firewall works.

2075 Chaitra · Q94 marksExplain how Packet filtering firewall Works.

2074 Ashwin · Q94 marksExplain how Packet filtering firewall Works.

A packet filtering firewall is a router or host that decides on each packet from its network and transport headers, using an ordered rule table (an access control list). It works as follows:

  1. Receive: a packet arrives on an interface, inbound or outbound.
  2. Read the header: source and destination IP address, protocol (TCP, UDP, ICMP), source and destination port.
  3. Compare with the rules, top down: each rule gives values, or "any", and an action, permit or deny.
  4. First match decides: the packet is forwarded or dropped, and later rules are not read.
  5. No match: the implicit deny at the end of the list drops it.
HOW A PACKET FILTER WORKS: EACH PACKET AGAINST THE RULES, TOP DOWN The first rule that matches decides; when none matches, the packet is dropped. A packet arrives Read its header IPs, protocol, ports, direction Rule k matches? yes Do its action permit: forward deny: drop no More rules? yes: k + 1 no Implicit deny: drop it no rule matched A HOSTEL ROUTER'S RULES # Source Destination Port Action 1 203.0.113.0/24 any any deny 2 any 192.168.10.0/24 TCP 23 deny 3 any 192.168.10.5 TCP 443 permit 4 192.168.10.0/24 any TCP 80, 443 permit 5 any any any deny THREE PACKETS, TRACED 1. 198.51.100.7 to 192.168.10.5, TCP 443: rules 1 and 2 miss, rule 3 matches: permit 2. 203.0.113.9 to 192.168.10.5, TCP 443: rule 1 matches first: deny 3. 198.51.100.7 to 192.168.10.20, TCP 23: rule 2 matches: deny (Telnet blocked) Order matters: the first match decides, and every list ends in an implicit deny.

For example, a rule that denies TCP port 23 to 192.168.10.0/24 stops Telnet into the hostel network. A packet filter is fast and transparent, but it keeps no state and cannot read content.

How security is maintained in a network: the procedures PIN 2/27

Asked 2 times

2067 Ashad · Q105 marksExplain the procedures to make your network secured.

2066 Poush · Q92 marksHow can we maintain the security within the communication network?

Security within a network is maintained by defense in depth: several layers of controls, so that the failure of one does not expose the network. The procedures, in order:

  1. Security policy and risk assessment: identify the assets and the threats, and set the rules of use.
  2. Access control: individual accounts, strong passwords or multi-factor authentication, least privilege.
  3. Encryption: TLS for web and mail, VPNs for remote and branch links, WPA2 or WPA3 on Wi-Fi.
  4. Firewalls and router ACLs: filter traffic at every boundary, with public servers in a DMZ.
  5. Segmentation: VLANs to separate user, server and guest networks.
  6. Patching and hardening: update systems, disable unused services and ports, change default passwords.
  7. Malware protection: antivirus and filtering of e-mail attachments.
  8. Monitoring: an IDS or IPS, log review and alerts.
  9. Backups and redundancy: for availability and recovery.
  10. Physical security and user training: locked equipment rooms, phishing awareness, and an incident response plan.

The operation of the Data Encryption Standard (DES) PIN 2/27

Asked 2 times

2070 Chaitra · Q105 marksExplain the operation of Data Encryption Standard Algorithm?

2066 Bhadra · Q5b3 marksii) Secrete Key Algorithm: DES

DES (Data Encryption Standard, 1977) is a symmetric, secret key block cipher that encrypts a 64-bit block with a 56-bit key (64 bits with 8 parity bits) in 16 rounds of a Feistel structure. Its operation:

  1. Initial permutation (IP) rearranges the 64 plaintext bits.
  2. Split the block into halves L0 and R0 of 32 bits each.
  3. Sixteen rounds: Li=Ri−1 and Ri=Li−1⊕f(Ri−1,Ki), each round with its own 48-bit key.
  4. The function f: expansion of the 32-bit half to 48 bits, XOR with Ki, eight S-boxes that turn 6 bits into 4 each (48 bits to 32), then the permutation P.
  5. 32-bit swap of the two halves after round 16.
  6. Final permutation (IP−1) gives the 64-bit ciphertext.
DES: THE STRUCTURE, ONE ROUND AND THE F FUNCTION 64-bit block, 56-bit key, 16 Feistel rounds between an initial and a final permutation. 64-bit plaintext Initial permutation (IP) Round 1 Round 2 Round 16 32-bit swap Final permutation (IP inverse) rounds 3 to 15 64-bit ciphertext KEY SCHEDULE 64-bit key in, the 8 parity bits out: 56 bits (PC-1), split 28 + 28, shift 1 or 2 bits a round, PC-2 picks 48 bits: K1 to K16 64-bit key K1 K2 K16 Decryption: the same steps, with the round keys used in reverse (K16 first). Weakness: only 2^56 keys; found by brute force in 1998 (the EFF DES Cracker). ONE ROUND (A FEISTEL ROUND) L(i-1): 32 bits R(i-1): 32 bits f(R, Ki) Ki: 48 bits L(i) = R(i-1) R(i) = L(i-1) XOR f INSIDE f Expand E 32 to 48 bits XOR Ki 48 bits 8 S-boxes 48 to 32 bits Permute P 32 bits L(i) = R(i-1), and R(i) = L(i-1) XOR f(R(i-1), Ki) S-box example: input 011011 to S1; outer bits 0, 1 give row 1, inner bits 1101 give column 13; S1[1][13] = 5, so the output is 0101. Each S-box maps 6 bits to 4: the only non-linear step, the heart of DES security.

The key schedule drops the parity bits (PC-1), splits the 56 bits into two 28-bit halves, rotates them left by 1 or 2 bits each round, and selects 48 bits (PC-2) as each round key. Decryption runs the same algorithm with the round keys in reverse order. With only 256 keys, DES is now broken by brute force, and AES has replaced it.

The Diffie-Hellman key exchange algorithm PIN 2/27

Asked 2 times

2080 Bhadra · Q104 marksc) Diffie-Hellman algorithm

2074 Ashwin · Q104 marksb) Diffie Hellman’s Algorithm

The Diffie-Hellman algorithm (1976) lets two parties agree on a shared secret key over an insecure channel without ever sending the key itself; a symmetric cipher then uses that key.

  1. Both agree on two public numbers: a large prime N and a generator G.
  2. A chooses a secret x and sends R1=GxmodN to B.
  3. B chooses a secret y and sends R2=GymodN to A.
  4. A computes K=R2xmodN; B computes K=R1ymodN. Both equal GxymodN.
DIFFIE-HELLMAN: A SHARED KEY THAT IS NEVER SENT The book's example: N = 23 and G = 7 are public; x = 3 stays with A and y = 6 with B. Public, known to everyone: the prime N = 23 and the generator G = 7 HOST A HOST B 1 Secret x = 3 chosen at random, never sent 2 R1 = Gx mod N 73 mod 23 = 343 mod 23 = 21 5 K = R2x mod N 43 mod 23 = 64 mod 23 = 18 3 Secret y = 6 chosen at random, never sent 4 R2 = Gy mod N 76 mod 23 = 117649 mod 23 = 4 5 K = R1y mod N 216 mod 23 = 85766121 mod 23 = 18 A sends R1 = 21 B sends R2 = 4 The eavesdropper sees 23, 7, 21 and 4 only; x or y is a discrete logarithm Both reach K = Gxy mod N = 718 mod 23 = 18, the shared session key. Unauthenticated, it falls to a man in the middle; TLS and IPsec (IKE) sign or authenticate the values.

Example: with G=7, N=23, x=3 and y=6: R1=73mod23=21, R2=76mod23=4, and both sides find K=43mod23=216mod23=18.

An eavesdropper sees N, G, R1 and R2, but finding x or y is the discrete logarithm problem, infeasible for large primes. Plain Diffie-Hellman is open to a man-in-the-middle attack, so the exchanged values are authenticated with signatures or certificates, as in TLS and IKE.

One cryptography algorithm with an example: RSA PIN 1/27

Asked once

2066 Poush · Q96 marksExplain any one cryptography algorithm with example.

The RSA algorithm (Rivest, Shamir and Adleman, 1977) is a public key algorithm: a public key encrypts, a private key decrypts, and its security rests on the difficulty of factoring the product of two large primes.

  1. Choose two primes p and q, and compute the modulus n=pq and ϕ(n)=(p−1)(q−1).
  2. Choose the public exponent e, sharing no factor with ϕ(n): gcd(e,ϕ(n))=1.
  3. Find the private exponent d such that (e×d)modϕ(n)=1.
  4. Publish the public key (e,n) and keep the private key (d,n) secret.
  5. Encrypt a message number M as C=Memodn, and decrypt as M=Cdmodn.

Example: with p=7 and q=11, n=77 and ϕ(n)=60. Choose e=13; then d=37, because 13×37=481=8×60+1. The letter E is M=5; by repeated squaring modulo 77:

5^2 = 25,  5^4 = 625 mod 77 = 9,  5^8 = 81 mod 77 = 4
      C = 5^13 = 5^8 x 5^4 x 5 = 4 x 9 x 5 = 180 mod 77 = 26

To decrypt, write 37=32+4+1 and square 26 repeatedly:

26^2 = 60, 26^4 = 58, 26^8 = 53, 26^16 = 37, 26^32 = 60   (mod 77)
      M = 60 x 58 x 26 mod 77 = 5, the letter E again
RSA: MAKE THE KEYS ONCE, THEN ENCRYPT AND DECRYPT The card's example: p = 7, q = 11, e = 13, and the letter E sent as M = 5 (A = 1 to Z = 26). KEY GENERATION (DONE ONCE, BY THE RECEIVER B) 1 Choose two primes p and q p = 7, q = 11 2 n = p × q n = 7 × 11 = 77 3 φ(n) = (p - 1)(q - 1) φ = 6 × 10 = 60 4 Choose e: 1 < e < φ, gcd(e, φ) = 1 e = 13 5 Find d: (e × d) mod φ = 1 d = 37: 13 × 37 = 481 = 8 × 60 + 1 Public key (13, 77) (e, n): anyone may have it Private key (37, 77) (d, n): B keeps it secret USE (EVERY MESSAGE) A encrypts with B's public key C = Me mod n E: M = 5, C = 513 mod 77 = 26 ciphertext 26 crosses the network B decrypts with its private key M = Cd mod n M = 2637 mod 77 = 5, the letter E Signing swaps the keys: S = Md mod n; anyone checks Se mod n = M. Security: d needs φ(n), and φ(n) needs the factors p and q; with n of 2048 bits, factoring n is out of reach. Rule for words: n must exceed the largest letter value (n > 26 for A = 1 to Z = 26); each letter is encrypted alone.

An attacker who knows the public key (13, 77) needs ϕ(n), and so the factors of n; for a 2048-bit modulus no known method finds them in any useful time.

How PGP secures e-mail communication PIN 1/27

Asked once

2074 Chaitra · Q93 marksHow PGP can secure email communication?

PGP secures an e-mail from A to B in these steps:

  1. Hash the message and encrypt the digest with A's private key (the signature).
  2. Compress the message and signature (ZIP).
  3. Encrypt them with a new random session key, by a symmetric cipher.
  4. Encrypt the session key with B's public key and attach it.
  5. Convert the result to base64 text and send it.
PGP: HOW ONE EMAIL FROM A TO B IS PROTECTED Sign, compress, encrypt with a one-time session key, lock that key with B's public key, then base64. SENDING, AT A 1 Hash digest of the mail (SHA-256) 2 Sign digest with A's private key 3 Compress mail + signature with ZIP 4 Encrypt one-time session key (AES, IDEA) 5 Lock the key session key with B's public key 6 Base64 binary to plain email text authentication compression confidentiality email compatibility RECEIVING, AT B: THE SAME STEPS BACKWARDS Decode base64 back to binary Unlock the key with B's private key Decrypt with the session key Decompress mail + signature Verify with A's public key Sign before compressing: the signature covers the mail as written. Compress before encrypting: less redundancy, less to encrypt. Keys: PGP trusts public keys through a web of trust (users sign each other's keys); S/MIME uses CA certificates instead.

B reverses the steps: its private key recovers the session key, which decrypts the message, and A's public key verifies the signature. This gives confidentiality, authentication, integrity and compression.

Router ACL, and blocking 202.70.91.0/24 coming in on FastEthernet PIN 1/27

Asked once

2082 Baishakh · Q92 marksWhat is router ACL? How do you apply ACL to block the IP network 202.70.91.0/24 incoming to interface Fast Ethernet of a router?

A router ACL (access control list) is an ordered list of permit and deny statements applied to a router interface in one direction; each packet is compared top down, the first match decides, and an implicit deny ends the list. To block 202.70.91.0/24 entering FastEthernet 0/0:

access-list 10 deny 202.70.91.0 0.0.0.255
      access-list 10 permit any
      interface FastEthernet0/0
       ip access-group 10 in

The permit line is needed, or the implicit deny would drop all other traffic.

8 chapters · 127 topics · definition, points, flows

Summary

Every topic of the eight chapters as the skeleton of its exam answer: the definition of the main term, the points as one-line keywords, every process drawn as a flow and every set of types as tiles, by name. The topics the papers ask get the full skeleton, the rest a line or two, and an example only where it helps, the same few across the course. Each title opens its full card; the chip is how often the papers ask it. At the end, the recall sheet gives every topic again as bare keywords.

Chapter 1: Introduction to computer network

5 hours · about 10 marks a paper · in 26 of the 27 sittings

Computer network and its uses PIN 4/27

Computer network: autonomous computers and devices interconnected by links and common protocols, to exchange data and share resources

Parts

  • Nodes
  • Links
  • Protocols
  • Services
  • Business: resource sharing, reliability, saving money, scalability, e-commerce
  • Home: remote information, communication, entertainment, e-commerce, online education
  • Mobile and society: anywhere access; e-government, privacy, fraud
  • Five instances: wallet payments, Viber calls, online classes, video streaming, ride booking

PAN, LAN, MAN and WAN PIN 1/27

Network types by size: networks classified by the area they cover, from one person to the whole world

TypeSpanOwnerExample
PAN1 to 10 mone personBluetooth earbuds
LANroom to campusone organisationcollege lab Ethernet, Wi-Fi
MANa cityISP, cable operatorcity fibre ring
WANcountry, continentcarriers, leasedbank branches over MPLS
  • Internetwork: networks joined by routers; the Internet is the largest

Network topologies PIN 1/27

Network topology: the arrangement of nodes and links; physical (layout of cables) or logical (path of the signals)

Types

  • Bus
  • Star
  • Ring
  • Mesh
  • Tree
  • Hybrid
  • Bus: one backbone, cheap; one break stops all
  • Star: own link to a switch; the switch is a single point of failure
  • Ring: one way round, token; one break stops it
  • Mesh: every pair linked; robust, costly
L=n(n−1)2

Client/server and peer to peer TOP 10/27

Networking model: how work and resources are shared: client/server (servers serve requesting clients) or peer to peer (every peer is client and server)

Client/server

  1. Server listens
  2. Client requests
  3. Server processes
  4. Server replies
BasisClient/serverPeer to peer
Control, datacentral serverspread over peers
Cost, securityhigh, stronglow, weak
Scalabilityserver bottleneckgrows with peers
Failuresingle pointnone
Exampleweb, bankingBitTorrent, workgroup
  • P2P process: join, search, connect directly, exchange pieces, leave

Active networks PIN 1/27

Active network: a network of programmable nodes that compute on the packets passing through, running code from users or the packets

Active node

  • Active applications
  • Execution environments
  • NodeOS
  • Hardware
  • Approaches: capsule (integrated, code in packets); programmable switch (discrete, code preloaded)
PointLegacyActive
Nodestores and forwardsforwards and computes
Programmed byvendorusers, packets
New serviceyearsquickly, as code
Security, speedsimpler, fasterharder, slower

Protocols and standards HOT 5/27

Protocol: a set of rules for communication: the format, order and meaning of messages, and the actions on sending and receiving them

Elements

  • Syntaxformat
  • Semanticsmeaning
  • Timingwhen, how fast
  • Examples: HTTP, SMTP, DNS, TCP, UDP, IP, Ethernet
  • Standards bodies: ISO, ITU-T (formerly CCITT), IEEE, IETF, ANSI, EIA
  • Interface: boundary between adjacent layers; offers the lower layer's services
  • Protocol against interface: horizontal, peer to peer; vertical, layer to layer

Layered architecture TOP 9/27

Layered architecture: network software as a stack of layers, each offering services to the layer above; layer n talks to its peer by the layer n protocol

  • Reasons: less complexity, modularity, standards, easy troubleshooting, reuse, flexibility
  • Hierarchy: peers, protocols, interfaces; virtual communication, real flow down and up
  • Network architecture: the set of layers and protocols

Design issues

  • Addressing
  • Direction of transfer
  • Error control
  • Flow control
  • Multiplexing
  • Routing
  • Ordering
  • Segmentation

Services and primitives PIN 1/27

Service: the operations a layer offers the layer above; connection-oriented (set up, use, release) or connectionless (independent datagrams)

Primitives

  1. LISTEN
  2. CONNECT
  3. RECEIVE
  4. SEND
  5. DISCONNECT
  • OSI classes: request, indication, response, confirm
  • Examples: TCP connection-oriented; UDP and IP connectionless
  • Service against protocol: what a layer offers; rules between peers

The OSI model HOT 8/27

OSI reference model: ISO's seven-layer framework (ISO 7498, 1984) saying what each layer does, not which protocols do it

Layers, bottom up

  1. Physical
  2. Data link
  3. Network
  4. Transport
  5. Session
  6. Presentation
  7. Application
  • Functions: bits; frames, MAC, errors; routing, IP; ports, end to end; dialog; encrypt, translate; user services
  • Which layer: voltage physical; framing, MAC data link; IP network; socket transport; dialog session; encryption presentation

The TCP/IP model PIN 4/27

TCP/IP model: the four-layer model of the Internet protocol suite, built for the ARPANET to interconnect different networks

Layers, bottom up

  1. Host-to-network
  2. Internet
  3. Transport
  4. Application
  • Application: HTTP, HTTPS, SMTP, POP3, IMAP, FTP, DNS, DHCP, SSH, SNMP
  • Transport: TCP reliable, connection-oriented; UDP fast, connectionless
  • Internet: IP, ICMP, IGMP, ARP; routing, logical addressing
  • Host-to-network: Ethernet, Wi-Fi, PPP, DSL; framing, bits

Data encapsulation PIN 3/27

Encapsulation: each layer wraps the data from above in its own header (and at the data link layer a trailer); decapsulation removes them at the receiver

Down at the sender

  1. Data
  2. Segment+ TCP header
  3. Packet+ IP header
  4. Frame+ header, FCS
  5. Bits
  • Header: addresses, sequence numbers, length, type, checksum
  • Trailer: FCS (CRC), data link layer only

OSI against TCP/IP TOP 9/27

OSI against TCP/IP: ISO's seven-layer reference model, made before its protocols, against the four-layer model of the Internet's protocols, described after them

Layer mapping

  • ApplicationOSI 7, 6, 5
  • TransportOSI 4
  • InternetOSI 3
  • Host-to-networkOSI 2, 1
BasisOSITCP/IP
Layers74
Mademodel firstprotocols first
Service, interface, protocolclearly separateblurred
Network layerboth servicesconnectionless
Transport layerconnection-orientedTCP and UDP
  • Similar: layered, end to end transport, network layer, application on top

The Internet

  • Network of networks: TCP/IP worldwide; no single owner
  • History: ARPANET 1969, TCP/IP 1983, NSFNET, the web 1991
  • Structure: hosts, access networks, tiered ISPs, IXPs (NPIX in Kathmandu)
  • Governance: ICANN, IANA, APNIC addresses; IETF RFCs

X.25 HOT 7/27

X.25: ITU-T standard interface between the DTE and DCE of a public packet switched network; virtual circuits, error and flow control at every hop

Layers

  • PhysicalX.21
  • LinkLAPB
  • PacketPLP
  • Packet header: GFI (Q, D, modulo) and LCGN; LCN; P(R), M, P(S), 0

Virtual call

  1. Call request
  2. Incoming call
  3. Call accepted
  4. Call connected
  5. Data transfer
  6. Clearing
  • Circuits: SVC per call, PVC permanent; 4095 per line
  • Limits: slow (64 kbps), high delay; replaced by Frame Relay

Frame Relay HOT 5/27

Frame Relay: connection-oriented WAN carrying variable-length frames over virtual circuits named by DLCIs, at layers 1 and 2 only; bad frames dropped

Address bits

  • DLCI
  • C/R
  • EA
  • FECN
  • BECN
  • DE
  • Circuits: PVC; SVC by Q.933 on DLCI 0

SVC states

  1. Call setup
  2. Data transfer
  3. Idle
  4. Call termination
BasisX.25Frame Relay
Layers1 to 31 and 2
Errorscorrected per hopdetected, dropped
Speedup to 64 kbpsto 44.736 Mbps
  • Against ATM: variable frames against 53-byte cells; DLCI against VPI/VCI

ATM PIN 3/27

ATM: connection-oriented cell switching that carries voice, video and data in fixed 53-byte cells (5-byte header, 48-byte payload) over VPI/VCI circuits

UNI header

  • GFC 4
  • VPI 8
  • VCI 16
  • PT 3
  • CLP 1
  • HEC 8

Layers, top down

  1. AALCS, SAR
  2. ATM layer
  3. PhysicalTC, PMD
  • AAL types: AAL1 CBR voice; AAL2 timed VBR; AAL3/4 data; AAL5 IP, 8-byte trailer

Ethernet

  • Ethernet: IEEE 802.3 LAN family; shared coaxial bus, now a switched star
  • Speeds: 10 Mbps (1983) to 400 Gbps (2017)
  • Frame: MAC addresses, type, 46 to 1500 bytes of data, CRC

VoIP

  • VoIP: voice as IP packets instead of PSTN circuits
  • Call: SIP signalling; codec; RTP over UDP; jitter buffer
  • G.711 call: 200-byte packets, 50 a second, 80 kbps

NGN

  • NGN (ITU-T Y.2001): one packet IP core for voice, video and data
  • Strata: transport and service separated; softswitch, IMS
  • Also: QoS broadband access, open interfaces, generalised mobility

MPLS

  • MPLS: forwarding by short labels, layer 2.5 (RFC 3031)
  • Label: 20-bit label, TC 3, S 1, TTL 8
  • Path: ingress LER pushes, LSRs swap, egress pops
  • Uses: traffic engineering, VPNs, fast reroute

xDSL

  • DSL: digital data on the telephone copper, above 4 kHz
  • Parts: splitter, DSL modem, DSLAM, DMT tones
  • Variants: ADSL 8 Mbps, ADSL2+ 24, VDSL2 100; HDSL, SDSL

Chapter 2: Physical layer

5 hours · about 8 marks a paper · in 25 of the 27 sittings

Physical layer PIN 1/27

Physical layer: layer 1; transmits raw bits over a medium, defining mechanical, electrical, functional and procedural characteristics of the link

Functions

  • Physical characteristics
  • Bit representation
  • Data rate
  • Bit synchronization
  • Line configuration
  • Physical topology
  • Transmission mode
  • Modes: simplex, half-duplex, full-duplex
  • In TCP/IP: inside the host-to-network layer
  • Devices: repeater, hub, modem, cables and connectors

Delay and throughput PIN 3/27

Network monitoring: measuring bandwidth, throughput, latency and jitter; each hop adds processing, queuing, transmission and propagation delay

THE FOUR DELAYS AT A ROUTER A packet crossing router A towards router B is delayed four times; their sum is the nodal delay. packet ROUTER A Processing check, look up output queue (buffer) Output port sends bit by bit bits link: rate R, length d Router B 1 Processing delay check header, errors, pick output link: µs 2 Queuing delay waits for the link; grows with the load 3 Transmission delay all L bits onto link at rate R: L / R 4 Propagation delay a bit crosses length d at speed s: d / s Nodal delay = processing + queuing + transmission + propagation
  • Throughput: data delivered / time; never above bandwidth
  • Formulas: transmission L/R; propagation d/s; bandwidth-delay product R×dprop
  • Causes of delay: processing, congestion, slow links, distance, hops, retransmissions
  • Example: 1,500 bytes at 10 Mbps: 1.2 ms; GEO hop: 238.6 ms

Channel capacity PIN 1/27

Channel capacity: the highest data rate a channel can carry; Nyquist for noiseless, Shannon for noisy channels

C=2Blog2L
C=Blog2(1+SNR)
  • SNR in dB: 10log10(S/N); 10 dB = 10, 30 dB = 1000
  • Impairments: attenuation, distortion, noise
  • Example: 3 kHz line at 30 dB: about 29.9 kbps

Transmission media HOT 7/27

Transmission medium: the physical path between transmitter and receiver that carries the signal; guided (wired) or unguided (wireless)

TRANSMISSION MEDIA Guided media keep the signal on a cable; unguided media radiate it from an antenna into air or space. Transmission media Guided (wired) signal on a solid path Unguided (wireless) signal from an antenna Twisted pair UTP, STP telephone, LAN Coaxial cable thin, thick; RG-6 cable TV, CCTV Optical fiber single, multimode backbone, FTTH Radio waves 3 kHz to 1 GHz AM, FM, TV Microwaves 1 to 300 GHz terrestrial, satellite Infrared 300 GHz to 400 THz remotes, short links bounded: speed and security, limited by the cable unbounded: mobility and reach, open to anyone

Factors in choosing

  • Bandwidth
  • Distance
  • Cost
  • Noise immunity
  • Security
  • Installation
  • Environment
  • Mobility
  • Example: UTP in labs, fiber between buildings, Wi-Fi in the canteen

Twisted pair and coaxial HOT 7/27

Guided media: cables carrying the signal on a solid path: twisted pair, coaxial (current), optical fiber (light)

Twisted pair types

  • UTP
  • STP
  • Cat 3 to Cat 8
  • Straight-through
  • Crossover
  • Rollover
  • Coaxial: conductor, insulation, braid shield, jacket; RG-6, RG-58, RG-59
PointTwisted pairCoaxialFiber
Signalelectricalelectricallight
Bandwidthlowmoderatevery high
Noise immunitylowgoodimmune
Costcheapestmoderatehighest

Optical fiber PIN 1/27

Optical fiber: a glass strand carrying light pulses, held in the core by total internal reflection at the lower-index cladding

Modes

  • Multimode step index
  • Multimode graded index
  • Single mode
AN OPTICAL FIBER COMMUNICATION SYSTEM Electrical to light at one end, light through glass, light to electrical at the other. Message source voice, video or data, electrical Electrical transmitter coder, modulator, driver Optical source LED or laser diode: current to light Destination the user gets the message Electrical receiver amplifier, equalizer, decoder Optical detector PIN or APD diode: light to current Repeater or optical amplifier light light Optical fiber cable connectors and splices; light at 850, 1310 or 1550 nm TRANSMITTER electrical in, light out CHANNEL light, weakened and spread RECEIVER light in, electrical out
  • Layers: core, cladding, buffer, jacket
  • Source and detector: LED or laser; PIN or APD photodiode
  • Windows: 850, 1310, 1550 nm, about 190 to 355 THz

Unguided media HOT 5/27

Unguided media: electromagnetic waves through air or space without a conductor, radiated and collected by antennas

Media

  • Radio3 kHz to 1 GHz
  • Microwave1 to 300 GHz
  • Infrared300 GHz to 400 THz

Propagation

  • Groundbelow 2 MHz
  • Sky2 to 30 MHz
  • Line of sightabove 30 MHz
  • LOS paths: direct wave, ground-reflected wave
  • Radio horizon: d=4.12h km

Satellite

Communication satellite: a microwave relay in orbit; its transponder amplifies and translates uplink to downlink

Orbits

  • LEO
  • MEO
  • GEO35,786 km
  • Bands: L, S, C, X, Ku, K, Ka, V, W

Multiplexing HOT 6/27

Multiplexing: sharing one link among several signals at once; a MUX combines n inputs, a DEMUX separates them

Types

  • FDMfrequency bands
  • WDMwavelengths
  • Synchronous TDMfixed slots
  • Statistical TDMslots on demand
  • CDMorthogonal codes
  • Importance: efficiency, lower cost, trunks and broadcasting, scalability
  • Example: FM stations at 88 to 108 MHz (FDM); E1 trunk of 30 calls (TDM)

Switching TOP 13/27

Switching: connecting a sender to a receiver through intermediate nodes that forward each input to the right output

Types

  • Circuit
  • Message
  • Packetdatagram or virtual circuit

Circuit switching

  1. Setup
  2. Data transfer
  3. Teardown
PointCircuitPacket
Pathdedicated, reservedshared, on demand
Delaysetup, then constantvariable queuing
Orderin ordermay be out of order
Suitsreal-time voicebursty data
  • Real time: reserved bandwidth, constant delay, no jitter, in order

Datagram and virtual circuit HOT 6/27

Datagram and virtual circuit: packet switching with each packet routed on its own, or along a path set up first

Virtual circuit phases

  1. Setup
  2. Data transfer
  3. Teardown
PointDatagramVirtual circuit
Setupnoneneeded
Headerfull addressshort VCI
Routingper packetonce, at setup
Ordermay varyin order
  • VC types: PVC, SVC
  • Examples: IP; X.25, Frame Relay (DLCI), ATM, MPLS

Telephone network and E1 PIN 2/27

Telephone network (PSTN): a circuit-switched hierarchy of telephones, local loops, exchanges and trunks

A call

  1. Off-hook
  2. Dial tone
  3. Dialling
  4. Switching
  5. Ringing
  6. Answer
  7. Hang up
  • T1: 193 bits x 8000 = 1.544 Mbps, 24 channels
  • E1: 32 slots x 8 bits x 8000 = 2.048 Mbps; TS0 sync, TS16 signalling
  • E hierarchy: E2 8.448, E3 34.368, E4 139.264 Mbps

Switching systems

Telecommunication switching system: exchange equipment joining any line to any line or trunk on demand

Kinds

  • Manual
  • Strowger
  • Crossbar
  • Electronic SPC
  • Signalling: CAS, CCS (SS7)

ISDN HOT 5/27

ISDN: an ITU-T all-digital, circuit-switched network carrying voice and data end to end over the telephone line

Channels

  • B64 kbps
  • D16 or 64 kbps
  • H384 to 1,920 kbps
  • BRI: 2B + D = 144 kbps (192 with framing); PRI: 23B + D or 30B + D

Functional groups

  • TE1
  • TE2
  • TA
  • NT2
  • NT1
  • Reference points: R, S, T, U
  • Signalling: D channel, LAPD and Q.931; SS7 inside

Chapter 3: Data link layer

5 hours · about 11 marks a paper · in all 27 sittings

Data link layer functions HOT 8/27

Data link layer: layer 2; packs network layer packets into frames and moves them reliably node to node over one link

Functions

  • Framing
  • Physical addressing
  • Flow control
  • Error control
  • Access control

Services

  • Unacknowledged connectionless
  • Acknowledged connectionless
  • Acknowledged connection-oriented
  • Design issues: service interface, framing, error control, flow control, medium access, addressing
  • Sublayers: LLC (802.2): network layer interface, multiplexing; MAC: frame, addresses, medium access, FCS

Framing TOP 10/27

Framing: dividing the bit stream into frames and delimiting each frame's start and end

Methods

  • Character count
  • Byte stuffingFLAG, ESC
  • Bit stuffingflag 01111110
  • Coding violations
  • Character count: one garbled count loses every later boundary
  • Byte stuffing: ESC before a FLAG or ESC in the data; PPP
  • Bit stuffing: a 0 after five 1s, deleted by the receiver; HDLC
  • Example: 01001111110111110 sent as 0100111110101111100 between two flags

Errors and detection PIN 1/27

Error: a change in a frame's bits in transit; single-bit or burst

PointDetectionCorrection
On errorresend (ARQ)fix (FEC)
Bits addedfewmany
Distanced≥s+1d≥2t+1
Codesparity, CRCHamming
  • Parity: catches odd numbers of errors; 2D parity corrects one bit
  • Checksum: one's complement sum, complemented; receiver's complemented sum 0: accept

CRC PIN 3/27

CRC: error detection by modulo-2 division by a generator of degree r; the r-bit remainder is appended

Sender

  1. Append r zeros
  2. Divide by G, XOR
  3. Remainder is the CRC
  4. Send message, then CRC
  • Receiver: divide by the same G; remainder 0 accept, otherwise reject
  • Detects: all single-bit, odd counts (factor x + 1), bursts up to r bits
  • Generators: CRC-16-CCITT (HDLC, PPP), CRC-32 (Ethernet)
  • Example: 1101 with 1011: remainder 001, send 1101001

Hamming distance and code PIN 1/27

Hamming distance: the number of bit positions in which two equal-length codewords differ (XOR, count the 1s)

dmin≥s+1,dmin≥2t+1
  • Rules: detect s errors (left), correct t errors (right)
  • Example: 10101 XOR 11110 = 01011: distance 3

Parity groups of the 7,4 code

  • P11, 3, 5, 7
  • P22, 3, 6, 7
  • P44, 5, 6, 7
  • Correct: syndrome C4 C2 C1 names the wrong bit; 1110111 becomes 1111111

Flow control HOT 5/27

Flow control: procedures limiting how much a sender transmits before an acknowledgement, protecting a slow receiver

  • Stop and wait: one frame, then wait for its ACK; U=1/(1+2a)
  • Sliding window: up to W frames, numbered modulo 2k; ACK names the next frame expected
  • Piggybacking: ACK rides in the next data frame; fewer frames; ack timer
  • Example: satellite, a = 270: stop and wait uses 0.18 % of the link

ARQ PIN 4/27

ARQ: error control by retransmission (backward error correction), triggered by a timeout or a NAK

  • Stop and wait: one frame outstanding; resend that frame
  • Go-back-N: window 2k−1, receiver window 1; resend the lost frame and all after
  • Selective repeat: both windows 2k−1; resend only the lost frame
  • Example: frames 0 to 4, frame 2 lost: go-back-N resends 2, 3, 4; selective repeat resends 2

HDLC PIN 2/27

HDLC: a bit-oriented ISO protocol for point-to-point and multipoint links, with bit stuffing and sliding window ARQ

Stations

  • Primary
  • Secondary
  • Combined

Modes

  • NRMsecondary waits for a poll
  • ARMsecondary may send
  • ABMcombined, either sends

Frame

  • Flag
  • Address
  • Control
  • Information
  • FCS
  • Flag

Frame types

  • Idata, N(S), N(R)
  • SRR, RNR, REJ, SREJ
  • USNRM, SABM, DISC, UA

PPP

PPP: the byte-oriented point-to-point link protocol: HDLC-like framing, LCP and NCPs

Phases

  1. Dead
  2. Establish
  3. Authenticate
  4. Network
  5. Open
  6. Terminate
  • Frame: 7E, FF, 03, protocol, payload, FCS, 7E

MAC sublayer HOT 7/27

MAC sublayer: the lower data link sublayer that decides which station transmits next on a shared broadcast channel

  • Why essential: avoids collisions; efficient use; fairness; bounded delay and priority
  • Static allocation: fixed FDM or TDM shares; wasteful for bursty traffic; delay N times
  • Example: one 100 Mbps channel: 200 µs; ten 10 Mbps channels: 2 ms
  • Dynamic allocation: on demand; station model, one channel, collisions observed

Multiple access protocols

  • RandomALOHA, CSMA, CSMA/CD, CSMA/CA
  • Controlledreservation, polling, token
  • ChannelizationFDMA, TDMA, CDMA

ALOHA HOT 6/27

ALOHA: random access (Hawaii, 1971): send whenever ready; with no ACK, retry after a random backoff

PointPureSlotted
Sendsany timeslot start
Vulnerable2TT
ThroughputGe−2GGe−G
Maximum18.4 %36.8 %
  • Peak load: G = 0.5 (pure), G = 1 (slotted)
  • No collision: pure, no other start within T either side; slotted, none in the same slot

CSMA PIN 1/27

CSMA: carrier sense multiple access: listen to the medium, transmit only when it is idle

  • Vulnerable time: the propagation time

Persistence

  • 1-persistentsend at once when idle
  • Non-persistentwait a random time
  • p-persistentsend with probability p

CSMA/CD TOP 9/27

CSMA/CD: Ethernet's access method: sense, transmit while listening, and on a collision jam and back off at random

  1. Sense until idle
  2. Transmit and listen
  3. Collision?
  4. Jam 32 bits
  5. Back off K slots
  6. Retry, 16 attempts
  • Backoff: K from 0 to 2m−1, m = min(n, 10), slots of 512 bit times
  • Detect: higher signal level, or receive activity while sending
  • Minimum frame: 2TpropB = 512 bits = 64 bytes at 10 Mbps
  • Better than CSMA: stops at once; wastes only about 2Tprop

Controlled access

Controlled access: stations take turns by agreement or under a controller; no collisions

Methods

  • Reservationmini-slots
  • Pollingpoll and select
  • Token passinglogical ring
  • Example: roll call (polling), talking stick (token)

Channelization

Channelization: sharing a channel by frequency (FDMA), time (TDMA) or code (CDMA)

  • Example: GSM: 200 kHz carriers (FDMA), 8 time slots each (TDMA)
  • CDMA: orthogonal chip codes; an inner product recovers one station

IEEE 802 family

IEEE 802: the LAN and MAN standards: one LLC (802.2) over a MAC for each LAN

Standards

  • 802.1bridging, VLANs
  • 802.2LLC
  • 802.3Ethernet
  • 802.4token bus
  • 802.5token ring
  • 802.11wireless LAN

Ethernet PIN 4/27

Ethernet (IEEE 802.3): the wired LAN: 48-bit MAC addresses, CRC-32, 1-persistent CSMA/CD on shared media

Frame, bytes

  • Preamble 7
  • SFD 1
  • DA 6
  • SA 6
  • Length/Type 2
  • Data 46 to 1500
  • FCS 4
  • Frame size: 64 to 1518 bytes
  • MAC address: 24-bit OUI and 24-bit NIC part; broadcast all 1s
  • Cabling: 10Base5, 10Base2, 10BaseT, 100BaseTX, 1000BaseT
  • Fiber: 10BaseF, 100BaseFX, 1000BaseSX (850 nm), 1000BaseLX (1310 nm)

Token bus HOT 5/27

Token bus (IEEE 802.4): stations on a physical bus pass a token round a logical ring ordered by address

  • Why "token ring": token to the next lower address; the lowest returns it to the highest
  • Priorities: classes 0, 2, 4, 6
  • Maintenance: claim token, solicit successor, set successor
  • Medium: broadband coax at 1, 5, 10 Mbps; factory automation
Point802.4802.5
Topologylogical ringphysical ring
Frame endterminatorssender strips
Upkeepdistributedmonitor

Token ring PIN 4/27

Token ring (IEEE 802.5): stations on a physical ring; only the holder of the circulating 3-byte token transmits

Operation

  1. Wait for free token
  2. Seizeset T bit
  3. Frame circles
  4. Destination copies, sets A, C
  5. Sender strips frame
  6. Release new token

Frame

  • SD
  • AC
  • FC
  • DA
  • SA
  • Data
  • FCS
  • ED
  • FS
  • AC byte: PPPTMRRR: priority, token, monitor, reservation
  • Monitor: restores a lost token, removes orphan frames
  • Physical: 4 or 16 Mbps, shielded twisted pair; token holding 10 ms

FDDI PIN 3/27

FDDI: 100 Mbps token-passing fiber LAN on dual counter-rotating rings; primary carries data, secondary stands by

Features

  • 100 Mbps fiber
  • Dual rings
  • 200 km, 1000 connections
  • Timed token
  • Frames up to 4500 bytes
  • DAS, SAS, concentrators

Fault tolerance

  1. Cut detected
  2. Neighbours wrap
  3. One ring, double length
  • Also: optical bypass switch, concentrator isolates a SAS, dual homing

Wireless LAN PIN 3/27

IEEE 802.11 (Wi-Fi): the wireless LAN standard; access by CSMA/CA, optionally with RTS and CTS

  • Architecture: BSS (ad hoc, or infrastructure with an AP); ESS over a distribution system
  • No CSMA/CD: cannot hear while sending; hidden and exposed stations; fading

CSMA/CA

  1. DIFS idle
  2. Random backoff
  3. Send
  4. SIFS, ACK
  • RTS/CTS: both set the NAV; solves the hidden station
  • DSSS: 11-chip Barker code 10110111000, 22 MHz channel
  • Versions: b 11 Mbps; a, g 54 Mbps; n; ac; ax (Wi-Fi 6)

VLAN PIN 3/27

VLAN: a logical group of switch ports forming one broadcast domain, set by configuration, not wiring

802.1Q tag

  • TPID 0x8100
  • PCP 3 bits
  • DEI 1 bit
  • VID 12 bits
  • Membership: port, MAC address, IP address, application
  • Ports: access (one VLAN, untagged), trunk (many, tagged)
  • Design: STUDENT VLAN 10, 192.168.10.0/24; DEPARTMENT VLAN 20, 192.168.20.0/24; router on a stick
  • Benefits: smaller broadcast domains, security, flexibility, cost

Chapter 4: Network layer

9 hours · about 17 marks a paper · in all 27 sittings

Network layer functions PIN 1/27

Network layer: layer 3; delivers packets from the source host to the destination host across many networks, by logical addresses and routers choosing the path hop by hop

Functions

  • Logical addressing
  • Routing
  • Forwarding
  • Packetizing
  • Fragmentation, reassembly
  • Internetworking
  • Error reporting (ICMP)
  • Congestion control, QoS
  • Key layer: highest layer every router runs; narrow waist (IP over everything); addressing that scales
  • Delivery: data link hop to hop; network host to host; transport process to process

Internetworking devices PIN 4/27

Internetworking device: hardware joining segments or networks; its OSI layer fixes what it can read and decide

By layer

  • Repeater, hublayer 1, signal
  • Bridge, switchlayer 2, MAC
  • Routerlayer 3, IP
  • Gatewayup to 7, converts
  • Domains: hub one collision domain; switch one per port; router one broadcast domain per port
  • Switch over hub: dedicated bandwidth, no collisions, full duplex, privacy, VLANs
  • Router vs gateway: same protocol, path choice; different protocols, conversion

Bridges PIN 1/27

Bridge: a data link layer device joining LAN segments; records each source MAC against its port and forwards frames only where needed

Each frame

  1. Receive
  2. Record source MAC
  3. Filter, forward or flood
  4. Age out (300 s)
  • Versus repeater: two collision domains, not one; local traffic stays local
throughput=2C1+f
  • Loops: Spanning Tree Protocol (IEEE 802.1D) blocks redundant ports

IPv4 addressing HOT 5/27

IPv4 address: a 32-bit logical address in dotted decimal, split into a network part and a host part

Classes, first octet

  • A0 to 127, /8
  • B128 to 191, /16
  • C192 to 223, /24
  • D224 to 239, multicast
  • E240 to 255, reserved
  • Private: 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16
  • IP over MAC: hierarchical, end to end, any link, shows location

Subnetting and VLSM TOP 24/27

Subnetting: borrowing host bits to divide one network into smaller subnets, each with its own network address, broadcast address and host range

  • Numbers: subnets 2s; hosts 2h−2; block 2h=256−m

VLSM method

  1. AND to find the block
  2. Size each demand
  3. Sort largest first
  4. Allocate from the start
  5. Links as /30
  6. Network, range, broadcast
  7. Wasted, unused range
  • VLSM when: subnets need different sizes; one fixed mask wastes addresses
  • Example: 192.168.10.0/24: 60 hosts /26, 25 /27, 10 /28, two links /30

CIDR and supernetting PIN 2/27

Supernetting: combining contiguous networks into one larger block with a shorter prefix, one route for all

  • CIDR: a.b.c.d/n; any power-of-two block; mask carried with routes
  • Conditions: contiguous, a power of two, aligned
  • Example: 192.168.4.0/24 to 192.168.7.0/24 make 192.168.4.0/22
PointClassfulClassless
Network part8, 16, 24 bitsany /n
Wastehighlow
Routingper networkaggregated, longest prefix

NAT

NAT: a router rewriting private source addresses (and ports) to a public address, and back for replies

Types

  • Static
  • Dynamic
  • PAT (overload)
  • Costs: breaks end to end; inbound needs port forwarding

The IPv4 datagram HOT 5/27

IP: the Internet's connectionless, best-effort datagram protocol; header 20 to 60 bytes

THE IPV4 HEADER Rows of 32 bits: five fixed rows (20 bytes), then up to 40 bytes of options. 0 4 8 16 19 31 Version 4 bits IHL 4 bits Type of service 8 bits Total length 16 bits Identification 16 bits Flags 3 bits Fragment offset 13 bits Time to live 8 bits Protocol 8 bits Header checksum 16 bits Source IP address 32 bits Destination IP address 32 bits Options and padding (0 to 40 bytes) rarely used 20 BYTES used in fragmentation TTL and protocol: the hop limit and the upper-layer protocol
  • TTL: hop limit; at 0 dropped, ICMP time exceeded
  • Protocol: 1 ICMP, 6 TCP, 17 UDP, 89 OSPF
  • Fragments: same Identification; offset in 8 bytes; MF 1 but last; reassembled at destination
  • Largest TCP payload: 65535−20−20=65495 bytes

ARP and RARP PIN 4/27

ARP: maps a known IPv4 address to the MAC address on the same link, by a broadcast request and a unicast reply

Steps

  1. Check cache
  2. Broadcast request
  3. Owner replies unicast
  4. Cache, send frame
  • RARP: MAC to IP; replaced by BOOTP and DHCP
  • NDP (IPv6): ICMPv6 solicitation and advertisement, multicast; router discovery, SLAAC

ICMP HOT 5/27

ICMP: IP's companion protocol (protocol 1) reporting delivery errors to the source and answering queries; it reports, never corrects

Errors, type

  • Destination unreachable3
  • Source quench4
  • Time exceeded11
  • Parameter problem12
  • Redirect5

Queries, types

  • Echo8, 0
  • Timestamp13, 14
  • Address mask17, 18
  • Router10, 9
  • Uses: ping, traceroute, path MTU discovery, redirects

Routing TOP 13/27

Routing: finding paths through an internetwork and building the tables forwarding uses; the routing algorithm picks the output line

Good algorithm

  • Correctness
  • Simplicity
  • Robustness
  • Stability
  • Fairness
  • Optimality
PointStaticDynamic
Routesmanual, fixedautomatic
On failuremanual fixrerouted
  • Routed vs routing: IPv4, IPv6 carry data; RIP, OSPF, BGP build tables
  • Optimality principle: part of an optimal path is optimal; sink tree
  • AS: one administration; IGP inside, BGP between

Routing table

Routing table: per destination network: mask, next hop, interface, metric, source

  • Classful lookup: first octet, class, default mask, network
  • Classless: longest prefix match; default route 0.0.0.0/0

Dijkstra's algorithm PIN 1/27

Dijkstra's algorithm: finds least-cost paths from one node to all others, each step making the nearest tentative node permanent

Steps

  1. Source 0, permanent
  2. Relabel neighbours
  3. Fix smallest tentative
  4. Repeat
  5. Trace back
DIJKSTRA ON THE BOOK'S FIGURE 4.12 GRAPH Final labels (distance, previous node) from A; the shortest path A to D in colour. 2 6 7 2 2 1 3 2 4 3 2 A B C E F D G H A (0) B (2, A) C (9, B) E (4, B) F (6, E) G (5, E) H (8, F) D (10, H) A, B, E, F, H, D: 2 + 2 + 2 + 2 + 2 = 10
  • Example (book Figure 4.12): A to D: A, B, E, F, H, D; cost 10

Flooding

Flooding: every packet sent out on every line except the one it arrived on

  • Damping: hop counter, sequence numbers, selective flooding
  • Uses: robust delivery, LSPs, broadcast, benchmark

Distance vector routing TOP 10/27

Distance vector routing: each router keeps its distance to every destination and periodically sends its whole table to its neighbours, updating by Bellman-Ford

Dx(y)=minv{c(x,v)+Dv(y)}
  • Keys: whole-network knowledge, neighbours only, regular intervals (RIP 30 s)
  • Count to infinity: bad news slow; routers count up to 16

Loop prevention

  • Maximum hop count
  • Split horizon
  • Poison reverse
  • Route poisoning
  • Triggered updates
  • Hold-down timer

Link state routing TOP 11/27

Link state routing: each router floods the state of its own links to all routers, builds the full map and runs Dijkstra

Five steps

  1. Discover neighbours
  2. Measure cost
  3. Build LSP
  4. Flood
  5. Compute (Dijkstra)
PointDistance vectorLink state
Sendswhole table, to neighboursown links, to all
AlgorithmBellman-FordDijkstra
Convergenceslow, count to infinityfast
ExamplesRIP, IGRPOSPF, IS-IS

Hierarchical routing

Hierarchical routing: routers grouped into regions; full detail inside a region, one entry per other region

  • Saving: 17 entries to 7; 720 routers: 53, or 25 with three levels
  • Cost: some longer paths

Routing protocols PIN 4/27

Routing protocol: rules and messages by which routers exchange reachability and cost to build their tables automatically

  • Why: scale, discovery, adaptation, loop-free best paths, policy
  • IGP (intra-AS): RIP, OSPF, IS-IS, EIGRP; EGP (inter-AS): BGP

The five

  • RIPdistance vector, hops
  • OSPFlink state, cost
  • IGRPCisco distance vector
  • EIGRPCisco, DUAL
  • BGPpath vector, policy

RIP PIN 2/27

RIP: distance vector interior protocol; hop count, 15 most, 16 unreachable; whole table to neighbours every 30 s over UDP 520

Timers

  • Update 30 s
  • Invalid 180 s
  • Hold-down 180 s
  • Flush 240 s
  • Operation: request, responses, add one hop, triggered updates, split horizon
  • Versions: RIPv1 classful, broadcast; RIPv2 classless, 224.0.0.9; RIPng for IPv6
  • Limits: 15 hops, slow convergence, ignores bandwidth

OSPF HOT 5/27

OSPF: open link state interior protocol; floods LSAs within areas, builds one database, runs Dijkstra; cost from bandwidth

Process

  1. Hello
  2. DR, BDR election
  3. Database exchange
  4. Flood LSAs
  5. SPF
  6. Routing table

States

  1. Down
  2. Init
  3. 2-Way
  4. ExStart
  5. Exchange
  6. Loading
  7. Full
  • DR election: highest priority, then router ID; priority 0 never; no pre-emption
  • Areas: backbone area 0, ABR, ASBR

BGP

BGP: the Internet's path vector exterior protocol between autonomous systems, over TCP 179

Messages

  • Open
  • Update
  • Keepalive
  • Notification
  • Loops: a route carrying its own AS number is rejected

Unicast and multicast PIN 3/27

Multicast routing: one-to-many delivery to a joined group (class D address), one copy per link along a tree

  • Unicast: one-to-one; RIP, OSPF, IS-IS, EIGRP, BGP
  • Membership: IGMP between hosts and routers

Multicast protocols

  • DVMRP
  • MOSPF
  • PIM-DM
  • PIM-SM
  • CBT
  • Trees: source-based or shared (rendezvous point); RPF check

Network design PIN 2/27

Network design: choosing topology, devices, cabling, wireless, addressing, servers and security for a site, with a reason for each

Method

  1. Requirements, assumptions
  2. Topology
  3. Devices
  4. Cabling
  5. Wireless
  6. VLANs, subnets
  7. Servers
  8. Security
  • Campus (500 PCs): 25 room switches, 5 distribution, 1 core, fibre backbone
  • Hotel: dual ISP, UTM firewall, PoE+ per floor, Wi-Fi 6, VLANs, PMS

Chapter 5: Transport layer

5 hours · about 8 marks a paper · in 26 of the 27 sittings

Transport layer services HOT 5/27

Transport layer: the end-to-end layer, run only in hosts, that delivers data between processes using ports, over IP's host-to-host delivery

Services

  • Process-to-process delivery
  • Segmentation, reassembly
  • Connection control
  • Reliability
  • Ordered delivery
  • Flow control
  • Multiplexing
  • Congestion control

Complete and in order

  1. Handshake syncs ISNs
  2. Number every byte
  3. Checksum
  4. Cumulative ACK
  5. Retransmit on timeout
  6. Reorder in buffer
  • Scopes: data link node to node, network host to host, transport process to process
  • Example: 2001 lost, 3001 buffered, duplicate ACK 2001, resent, ACK 4001

Services to the upper layer

  • Two services: connection-oriented (TCP, a phone call), connectionless (UDP, a letter)

Primitives

  • LISTEN
  • CONNECT
  • SEND
  • RECEIVE
  • DISCONNECT
  • Sockets: SOCKET, BIND, LISTEN, ACCEPT, CONNECT, SEND, RECEIVE, CLOSE

UDP HOT 6/27

UDP: User Datagram Protocol (RFC 768): connectionless, unreliable transport with an 8-byte header of ports, length and checksum

Header, 16 bits each

  • Source port
  • Destination port
  • Length
  • Checksum
  • Checksum: pseudo-header, header, data; optional in IPv4, mandatory in IPv6; protocol 17
  • Features: connectionless, no ACK, no order, boundaries kept, no flow control, multicast
  • Why used: no setup, timeliness, low overhead, broadcast, application adds reliability
  • Uses: DNS 53, DHCP 67/68, VoIP, games, SNMP 161, TFTP 69, QUIC

TCP TOP 9/27

TCP: Transmission Control Protocol (RFC 9293): connection-oriented, reliable, full-duplex byte stream with flow and congestion control

Header, 20 to 60 bytes, in bits

  • Source port16
  • Destination port16
  • Sequence number32
  • Acknowledgement32
  • HLEN4
  • Reserved4
  • Flags8
  • Window16
  • Checksum16
  • Urgent pointer16
  • Options0 to 40 bytes
  • Flags: CWR, ECE, URG, ACK, PSH, RST, SYN, FIN
  • Reliable by: handshake, sequence numbers, cumulative ACK, retransmission, checksum, windows

TCP versus UDP HOT 6/27

TCP against UDP: reliability against speed: a connection-oriented reliable stream against connectionless best-effort datagrams

BasisTCPUDP
Setuphandshakenone
Deliveryreliable, orderedbest effort
Header20 to 60 B8 B
Controlflow, congestionnone
Usesweb, mail, SSHDNS, VoIP
  • Two protocols, one IP: opposite needs; end hosts only; IP the hourglass waist; changing IP needs every router

Ports and sockets PIN 4/27

Port number: a 16-bit number (0 to 65,535) in the TCP or UDP header naming a process on a host

IANA ranges

  • Well-known0 to 1023
  • Registered1024 to 49151
  • Dynamic49152 to 65535
  • Socket: IP plus port; connection = socket pair; also the API
  • Why standardize: known meeting point, interoperability, defaults, firewall rules, no clashes
  • Port 8765: URL needs :8765; a plain URL tries 80, refused
  • Common: FTP 21, SSH 22, SMTP 25, DNS 53, HTTP 80, HTTPS 443

Handshake and release HOT 7/27

Three-way handshake: TCP connection setup in three segments, SYN, SYN + ACK, ACK, that synchronize both initial sequence numbers

Open

  1. LISTENpassive open
  2. SYNseq 8000
  3. SYN + ACKseq 15000, ack 8001
  4. ACKseq 8001, ack 15001

Release

  1. FIN
  2. ACKhalf-close
  3. FIN
  4. ACKTIME-WAIT 2 MSL
  • Server first: no listening socket gives RST, connection refused
  • Why three: both ISNs confirmed; old duplicate SYN rejected with RST
  • States: SYN-SENT, SYN-RECEIVED, ESTABLISHED, FIN-WAIT-1, FIN-WAIT-2, CLOSE-WAIT, LAST-ACK, TIME-WAIT

Sliding window PIN 2/27

Sliding window: TCP flow control: the receiver advertises rwnd, its free buffer space, and the sender keeps at most rwnd bytes unacknowledged

Byte regions

  • Acknowledged
  • In flight
  • Usable now
  • Must wait
  • Slides: ACK 3001, rwnd 4000: 3001 to 7000; ACK 5001: 5001 to 9000
  • Zero window: sender stops; persist timer probes
  • Refinements: silly window (Clark, Nagle), window scale, min(rwnd, cwnd)
  • Buffers: chained fixed-size, chained variable-size, one circular per connection

Multiplexing and demultiplexing

  • Multiplexing: sender adds port headers; many sockets, one IP
  • Demultiplexing: receiver reads ports, delivers to the socket
  • Keys: UDP destination IP and port; TCP four-tuple
  • Also: upward and downward (inverse) multiplexing

Congestion PIN 4/27

Congestion: offered load exceeds the capacity of the network or part of it: queues overflow, delay rises, throughput falls

  • Causes: arrival rate above capacity, buffer too small or too big, bursts, slow routers, retransmissions, poor routing
  • Prevention (open loop): retransmission, window, ACK, discard, admission policies; traffic shaping
  • Removal (closed loop): backpressure, choke packets, implicit and explicit (ECN) signals, load shedding, RED
  • TCP: slow start, congestion avoidance (AIMD), fast retransmit, fast recovery
T=1μ−λ

Leaky bucket HOT 5/27

Leaky bucket: traffic shaping by a finite packet queue drained at a constant rate; packets arriving when it is full are discarded

Steps

  1. Packet arrives
  2. Fulldiscard
  3. Elsejoin queue
  4. One packet per tick out
  • Byte counting: n bytes a tick; send while packets fit; leftover not saved
  • Example: n = 1000: tick 1 sends 200 and 700, tick 2 sends 500 and 300
  • Limits: loses bursts, saves no credit, rigid rate

Token bucket TOP 9/27

Token bucket: traffic shaping where tokens arrive at rate r up to capacity C; a packet leaves only by taking one, so saved tokens allow bursts

Steps

  1. Token every ΔT
  2. Fulltoken discarded
  3. Packet takes a token
  4. No tokenwaits
S=CM−r
  • Example: C = 6 Mb, M = 10 Mbps, r = 2 Mbps: S = 0.75 s
BasisLeakyToken
Holdspacketstokens
Outputfixed rbursts to C
When fulldrops packetsdrops tokens

Chapter 6: Application layer

5 hours · about 8 marks a paper · in 24 of the 27 sittings

Application layer and ports

  • Models: client-server; peer-to-peer

TCP ports

  • HTTP80
  • HTTPS443
  • FTP21, 20
  • SSH22
  • Telnet23
  • SMTP25, 587
  • POP3110
  • IMAP143

UDP ports

  • DNS53
  • DHCP67, 68
  • TFTP69
  • SNMP161, 162

HTTP and HTTPS HOT 5/27

HTTP: the web's stateless request and response protocol over TCP port 80; HTTPS is HTTP inside TLS, port 443

Serving a request

  1. DNS lookup
  2. TCP handshake
  3. GET request
  4. Server finds the file
  5. 200 OK response
  6. Render, fetch objects
  • Messages: request line or status line, headers, blank line, body
  • Status: 2xx success, 3xx redirect, 4xx client error, 5xx server error
  • Connections: non-persistent 2 RTT per object; persistent reuses one
  • HTTPS adds: certificate, encryption, integrity

FTP and TFTP PIN 4/27

FTP: file transfer over two TCP connections: control to port 21 for the session, data from port 20 for each file

Session

  1. Connect to 21220
  2. USER, PASS230
  3. PORT or PASV
  4. RETR or STOR150
  5. Data on 20226
  6. QUIT221
  • Modes: active, server connects from 20; passive, client connects
  • TFTP: UDP 69, no login, 512-byte blocks each ACKed

SSH, PuTTY and WinSCP

SSH: encrypted remote login and file copy over TCP port 22

  • PuTTY: SSH and Telnet client
  • WinSCP: SFTP, SCP, FTP client, drag and drop
  • Replaces: Telnet 23, plain FTP

Electronic mail TOP 11/27

Electronic mail: asynchronous messaging; SMTP pushes mail to and between servers, POP3 or IMAP pulls it from the mailbox

Components

  • User agent
  • Mail server
  • MTA
  • MDA
  • MAA, mailbox

SMTP, port 25

  1. 220
  2. HELO250
  3. MAIL FROM250
  4. RCPT TO250
  5. DATA354
  6. Body, "."250
  7. QUIT221
PointPOP3 (110)IMAP (143)
Maildownloadedstays on server
Devicesonemany
  • MIME: Content-Type; base64, 3 bytes to 4 characters

DNS TOP 11/27

DNS: distributed, hierarchical database mapping host names to IP addresses, queried over UDP port 53

Servers

  • Root
  • TLD
  • Authoritative
  • Local resolver
PointRecursiveIterative
Workserver askedasker
Replyanswerreferral
  • Records: A, AAAA, CNAME, MX, NS, PTR, SOA, TXT
  • Delegation: parent's NS records, plus glue
  • Message: ID, flags, counts; question, answer, authority, additional

DHCP PIN 1/27

DHCP: leases a host an IP address, mask, gateway and DNS server for a limited time, over UDP ports 67 and 68

Getting an address

  1. DISCOVER, broadcast
  2. OFFER
  3. REQUEST, broadcast
  4. ACK

Lease

  1. Bound
  2. T1 = 50%unicast renew
  3. T2 = 87.5%broadcast rebind
  4. ExpiryDISCOVER again
  • Example: 24 h lease: T1 12 h, T2 21 h

P2P applications

P2P application: peers act as both client and server, with little or no central server

  • BitTorrent: tracker, pieces, rarest first, tit for tat
  • DHT: lookup in about log N hops

Socket programming HOT 5/27

Socket programming: writing network programs through the socket API, the interface between a process and TCP or UDP

Server

  1. socket()
  2. bind()
  3. listen()
  4. accept()
  5. recv(), send()
  6. close()

Client

  1. socket()
  2. connect()
  3. send(), recv()
  4. close()

Socket types

  • StreamTCP
  • DatagramUDP
  • RawIP
  • Rule: server runs first, else connect is refused

Proxy and web caching PIN 3/27

Proxy server: an intermediary that makes requests for clients; a web cache answers repeats from stored copies

A miss

  1. Request to proxy
  2. Cache check
  3. Fetch from origin
  4. Store a copy
  5. Forward to client
  • Hit: copy returned at once, from the LAN
  • Stale copy: conditional GET, 304 Not Modified

Uses

  • Speed
  • Bandwidth
  • Filtering
  • Privacy
  • Logging
  • Kinds: forward, reverse, transparent, anonymous

Server optimization

  • Web: caching, CDN, compression, load balancing
  • Mail: backup MX, spam filtering, RAID mailboxes
  • DNS: caching, secondary servers, anycast
  • All: RAID, UPS, monitoring

RAID PIN 1/27

RAID: several disks combined into one logical volume for speed, fault tolerance or both

Why servers need it

  • Availability
  • Performance
  • Capacity
PointRAID 0RAID 1RAID 5
Techniquestripingmirroringparity
Capacityn disksonen minus 1
Survivesnothingone diskone disk
  • Parity: XOR; a lost block is the XOR of the rest

SNMP

SNMP: a manager reads and sets agents' MIB variables over UDP

Parts

  • Manager
  • Agent
  • MIB
  • OID
  • Messages: Get, Set, Response, Trap; ports 161, 162

MRTG and PRTG

  • MRTG: free; SNMP counters every 5 minutes; traffic graphs
  • PRTG: Paessler, Windows; sensors, dashboards, alerts

Wireshark and Packet Tracer

  • Wireshark: packet analyser; captures real traffic; filters
  • Packet Tracer: Cisco simulator; simulation mode shows packets

Chapter 7: Introduction to IPv6

4 hours · about 7 marks a paper · in 24 of the 27 sittings

Why IPv6 TOP 13/27

IPv6: the IETF's replacement for IPv4 (RFC 8200): 128-bit addresses, fixed 40-byte header, extension headers, autoconfiguration, multicast, IPsec

IPv4 problemIPv6 answer
232 addresses2128 addresses
NAT, no end-to-endglobal addresses
Complex headerfixed 40 bytes
No security, weak QoSAH, ESP; flow label
Manual setupSLAAC

Advantages

  • Larger address space
  • Better header
  • Extension headers
  • Smaller routing tables
  • Security
  • QoS
  • Autoconfiguration
  • Multicast, anycast
  • Factors: exhaustion (IANA, 2011), phones and IoT, NAT's cost, real-time media, security

IPv6 datagram HOT 6/27

IPv6 datagram: a fixed 40-byte base header, then optional extension headers and upper-layer data

Fields, in bits

  • Version4
  • Traffic class8
  • Flow label20
  • Payload length16
  • Next header8
  • Hop limit8
  • Source128
  • Destination128
  • Removed from IPv4: IHL, identification, flags, fragment offset, checksum, options
  • Renamed: TOS to traffic class, total length to payload length, TTL to hop limit, protocol to next header
  • Added: flow label, 20 bits
  • Router work: hop limit minus 1 only; no checksum, no fragmenting

Extension headers PIN 1/27

Extension headers: optional headers between base header and data, chained by next header; only hop-by-hop is read on the way

Order, with codes

  1. Hop-by-hop0
  2. Destination options60
  3. Routing43
  4. Fragment44
  5. AH51
  6. ESP50
  7. Destination options60
  8. Upper layer6, 17, 58
  • Rules: each once, destination options twice; hop-by-hop first; only the source fragments

IPv6 addresses PIN 3/27

IPv6 address: 128 bits as eight groups of four hex digits; drop leading zeros, one :: per address

  • Example: 2001:0db8:0000:0000:0000:ff00:0042:8329 is 2001:db8::ff00:42:8329

Types

  • Unicastone interface
  • Anycastthe nearest one
  • Multicastevery member, ff00::/8
  • Unicast kinds: global 2000::/3, link-local fe80::/10, unique local fc00::/7, loopback ::1
  • IPv4-mapped: ::ffff:192.0.2.33, that is ::ffff:c000:221

SLAAC

  1. Link-local address
  2. DAD
  3. Router solicitation
  4. Router advertisement
  5. Prefix + interface ID
  6. DHCPv6 if flagged

IPv6 multicasting

Format

  • ff8 bits
  • Flags4 bits
  • Scope4 bits
  • Group ID112 bits
  • Scopes: 1 interface, 2 link, 5 site, 8 organization, e global
  • Solicited-node: ff02::1:ff + last 24 bits; replaces broadcast
  • MLD: ICMPv6 group membership, the IPv6 IGMP

IPv4 to IPv6 transition TOP 18/27

Transition: gradual migration with IPv4 and IPv6 coexisting: dual stack, tunneling, header translation

Strategies

  • Dual stackboth stacks, DNS picks
  • TunnelingIPv6 inside IPv4
  • Translationheader rewritten
  • Tunnels: protocol 41; configured, 6to4, ISATAP, 6RD, Teredo
  • 6to4: 2002: + router's IPv4 + subnet + interface ID
  • ISATAP: 64-bit prefix + 0:5efe: + host's IPv4
  • 6RD: ISP's own prefix + CE's IPv4 bits; relays
  • Translation: SIIT; NAT64 with DNS64, 64:ff9b::/96; 464XLAT
  • Choose: dual stack first; tunnels across IPv4; translation for IPv6-only

Chapter 8: Network security

7 hours · about 11 marks a paper · in 26 of the 27 sittings

Network security and its properties TOP 11/27

Network security: the policies, practices and technologies that protect a network and its data from unauthorised access, misuse, modification and disruption

Attacks and the property broken

  • Interruptionavailability
  • Interceptionconfidentiality
  • Modificationintegrity
  • Fabricationauthenticity

Six properties

  • Confidentiality
  • Integrity
  • Authentication
  • Non-repudiation
  • Availability
  • Access control
  • Passive, active: interception; interruption, modification, fabrication, replay, denial of service
  • Maintained by: policy, access control, encryption, firewalls, VLANs, patching, anti-malware, IDS, backups, training

Cryptography: symmetric and public key HOT 8/27

Cryptography: securing messages by turning plaintext into ciphertext with a cipher and a key; only the right key turns it back

PointSymmetric keyPublic key
Keysone shared secret keypublic and private pair
Speedfast: bulk dataslow: keys, digests
Keys for n usersn(n−1)/22n
ExamplesDES, AES, RC4RSA, Diffie-Hellman, ECC
  • Hybrid: public key sends a session key; a symmetric cipher encrypts the data
  • Third tool: hash function (SHA-256): one-way, fixed-length digest

Classical ciphers

Two kinds

  • Substitutionletters replaced
  • Transpositionletters reordered
  • Substitution: Caesar, monoalphabetic, polyalphabetic (Vigenère)
C=(P+k)mod26

DES and AES PIN 4/27

DES and AES: symmetric block ciphers: DES, 64-bit block, 56-bit key, 16 Feistel rounds; AES, 128-bit block, 128, 192 or 256-bit key

DES

  1. Initial permutation
  2. 16 Feistel rounds
  3. 32-bit swap
  4. Final permutation

Function f

  1. Expand 32 to 48
  2. XOR round key
  3. 8 S-boxes, 6 to 4
  4. Permute P

AES round

  1. SubBytes
  2. ShiftRows
  3. MixColumns
  4. AddRoundKey
  • AES rounds: 10, 12, 14; last round without MixColumns
  • Structure: DES Feistel, broken by brute force; AES substitution-permutation, secure

RSA TOP 16/27

RSA: Rivest, Shamir and Adleman's public key algorithm: public key (e,n) encrypts, private key (d,n) decrypts; security from factoring n

Key generation

  1. Choose primes p, q
  2. n=pq
  3. ϕ(n)=(p−1)(q−1)
  4. Choose egcd(e,ϕ)=1
  5. Find dedmodϕ=1
C=MemodnM=Cdmodn
  • Example: p 7, q 11, n 77, e 13, d 37; E (5) encrypts to 26
  • Words: A = 1 to Z = 26; n above 26; each letter alone

Diffie-Hellman key exchange PIN 2/27

Diffie-Hellman: key agreement over an open channel: both ends compute the same secret K=GxymodN, never sending it

Steps

  1. Public prime N, generator G
  2. A sends R1=GxmodN
  3. B sends R2=GymodN
  4. Both compute K
  • Example: G 7, N 23, x 3, y 6 give R1 21, R2 4, K 18
  • Security: discrete logarithm; man in the middle unless authenticated

Digital signatures HOT 5/27

Digital signature: a digest of the message encrypted with the sender's private key, checked by anyone with the sender's public key

Sign at A

  1. Hash the message
  2. Encrypt digestA's private key
  3. Send message and signature

Verify at B

  1. Hash the message
  2. Decrypt signatureA's public key
  3. Compare the digests

Gives

  • Authentication
  • Integrity
  • Non-repudiation
  • Not given: confidentiality; a CA certificate binds the public key to its owner

PGP PIN 3/27

PGP: Pretty Good Privacy (Zimmermann, 1991): e-mail security from a signature, a one-time session key and the receiver's public key

At sender A

  1. Hash
  2. SignA's private key
  3. CompressZIP
  4. Encryptsession key
  5. Lock keyB's public key
  6. Base64

Services

  • Authentication
  • Confidentiality
  • Compression
  • E-mail compatibility
  • Segmentation
  • Trust: key rings, web of trust; S/MIME uses CA certificates

SSL and TLS PIN 3/27

SSL/TLS: a layer between TCP and the application that authenticates the server, agrees session keys, and encrypts and MACs the data

Handshake

  1. ClientHello
  2. ServerHello
  3. Certificate
  4. Key exchangepre-master secret
  5. Change cipher spec, Finished
  6. Encrypted data

Record protocol

  1. Fragment
  2. Compress
  3. Add MAC
  4. Encrypt
  5. Add header
  • Port: HTTPS on 443; sub-protocols handshake, change cipher spec, alert, record

IPsec PIN 3/27

IPsec: IETF protocols that secure IP packets at the network layer, with AH or ESP, in transport or tunnel mode

  • AH (protocol 51): authentication, integrity, anti-replay; no encryption
  • ESP (protocol 50): encryption plus authentication, integrity, anti-replay
  • Modes: transport: payload, host to host; tunnel: whole packet, gateway to gateway
  • SA: one-way; SPI, destination, protocol; set up by IKE

VPN HOT 5/27

VPN: a private network over the public Internet, built from encrypted, authenticated tunnels between its endpoints

Working

  1. Authenticate
  2. Agree keys
  3. Encrypt, encapsulate
  4. Cross the Internet
  5. Decrypt, deliver

Types

  • Remote accesshost to gateway
  • Site to siteintranet, extranet
  • Protocols: IPsec, SSL/TLS (OpenVPN), L2TP over IPsec, WireGuard
  • Example: Kathmandu head office to Pokhara branch through an IPsec tunnel

WEP and wireless security PIN 2/27

WEP: Wired Equivalent Privacy, the original 802.11 security: RC4 keyed by a 24-bit IV and a 40 or 104-bit key, with a CRC-32 check

Encrypt a frame

  1. IV + key seed RC4
  2. Append CRC-32 ICV
  3. XOR with keystream
  4. Send, IV in clear

Weaknesses

  • IV repeats
  • Weak RC4 keys
  • Linear CRC-32
  • One static key
  • Replaced by: WPA (TKIP), WPA2 (AES-CCMP, 802.11i), WPA3 (SAE)

Firewalls and router ACLs TOP 13/27

Firewall: a device or software at the boundary of a trusted network that permits or blocks traffic by a security policy

Types

  • Packet filter
  • Stateful inspection
  • Application gateway (proxy)
  • Circuit-level gateway
  • Next-generation firewall

Packet filter

  1. Read the header
  2. Compare rules, top down
  3. First matchpermit or deny
  4. No matchimplicit deny
  • Protects by: choke point, filtering, state table, NAT, content control, DMZ, logging
  • ACL: access-list 10 deny 202.70.91.0 0.0.0.255, access-list 10 permit any, ip access-group 10 in

Intrusion detection systems PIN 1/27

IDS: a device or software that monitors a network or hosts for malicious activity and raises alerts

Where

  • NIDSa network segment
  • HIDSone host

How

  • Signatureknown patterns
  • Anomalydeviation from baseline
  • IDS, IPS: IDS detects and alerts; IPS sits inline and blocks

All eight chaptersRecall sheet

Only what is hard to remember: the steps and phases in order, the types, the advantages and disadvantages, the numbers. No reasons and no explanations; each topic name opens its full card.

Chapter 1: Introduction to computer network

Computer network PIN 4/27

  • Definition: autonomous computers, links, protocols, exchange data, share resources
  • Parts: nodes, links, protocols, services
  • Business: resource sharing, reliability, saving money, scalability, e-commerce
  • Home: remote information, communication, entertainment, e-commerce, online education
  • Five instances: wallet payments, VoIP calls, online classes, streaming, ride booking

Network types PIN 1/27

  • By size: PAN 1 to 10 m, LAN campus, MAN city, WAN country
  • LAN: private, fast, Ethernet, Wi-Fi
  • WAN: hosts plus a subnet of routers, leased lines, store and forward
  • Other bases: broadcast or point to point; client/server or P2P

Topologies PIN 1/27

  • Types: bus, star, ring, mesh, tree, hybrid
  • Physical vs logical: cable layout, signal path
  • Mesh: n(n-1)/2 links, n-1 ports each
  • Weak points: bus backbone, star switch, ring break, tree root

Client/server and P2P TOP 10/27

  • Client/server: server listens, client requests, server processes, server replies
  • C/S features: central data, security, backup; tiers; single point of failure
  • P2P process: join, search, connect, exchange, leave
  • P2P kinds: pure (Gnutella), hybrid (Napster, BitTorrent), workgroup
  • Compare on: control, cost, security, scalability, failure, example

Active networking PIN 1/27

  • Idea: programmable nodes, computation on packets
  • Approaches: capsule (integrated), programmable switch (discrete)
  • Active node: NodeOS, execution environments, active applications, ANEP
  • Legacy network: store and forward, vendor firmware, slow new services
  • Successors: SDN, programmable switches

Protocols and standards HOT 5/27

  • Protocol: rules, format, order, meaning, actions
  • Elements: syntax, semantics, timing
  • Bodies: ISO, ITU-T (CCITT), IEEE, IETF, ANSI, EIA
  • Standards: de jure, de facto
  • Interface: boundary between adjacent layers, primitives, services

Layered architecture TOP 9/27

  • Reasons: complexity, modularity, standards, troubleshooting, reuse, flexibility
  • Hierarchy: peers, protocols, interfaces, virtual communication
  • Flow: M, H4, H3 with M1 and M2, H2 and T2, bits
  • Architecture: layers and protocols; TCP/IP, SNA
  • Design issues: addressing, direction, error control, flow control, multiplexing, routing, ordering, segmentation

Services and primitives PIN 1/27

  • Kinds: connection-oriented (phone), connectionless (post)
  • Primitives: LISTEN, CONNECT, RECEIVE, SEND, DISCONNECT; ACCEPT later
  • OSI classes: request, indication, response, confirm
  • Sockets: listen, connect, accept, send, recv, close

OSI model HOT 8/27

  • Layers up: physical, data link, network, transport, session, presentation, application
  • Units: bit, frame, packet, segment, SPDU, PPDU, APDU
  • Hop by hop: layers 1 to 3; end to end, 4 to 7
  • Which layer: voltage physical; framing, MAC, errors data link; IP network; sockets transport; dialog session; encryption presentation
  • Origin: ISO 7498, 1984; work began 1977

TCP/IP model PIN 4/27

  • Layers up: host-to-network, internet, transport, application
  • Internet: IP, ICMP, IGMP, ARP; connectionless
  • Transport: TCP reliable, UDP fast
  • Application: HTTP 80, HTTPS 443, SMTP 25, DNS 53, FTP 21, SSH 22
  • Origin: ARPANET, Cerf and Kahn 1974, switch on 1 January 1983

Encapsulation PIN 3/27

  • Units down: data, segment, packet, frame, bits
  • Header: addresses, sequence numbers, type, checksum
  • Trailer: FCS (CRC), data link only
  • Router: up to the IP header, new frame each hop

OSI vs TCP/IP TOP 9/27

  • Layers: 7 vs 4
  • Made: model first vs protocols first
  • Network layer: both services vs connectionless
  • Transport layer: connection-oriented vs TCP and UDP
  • Similar: layered, transport end to end, network layer, application
  • OSI lost on: timing, technology, implementations, politics

The Internet

  • History: ARPANET 1969, TCP/IP 1983, NSFNET 1986 to 1995, web 1989 to 1991
  • Structure: hosts, access networks, tiered ISPs, IXPs, NPIX
  • Governance: ICANN, IANA, APNIC, IETF RFCs, .np
  • Kinds: internet, Internet, intranet, extranet

X.25 HOT 7/27

  • Layers: physical X.21, link LAPB, packet PLP
  • Header: GFI (Q, D, modulo), LCGN 4, LCN 8, P(R), M, P(S), 0
  • Call: request, incoming, accepted, connected, data, clear request, indication, confirmation
  • Circuits: SVC, PVC; 4095 per line; window 2; 128-byte data
  • Type codes: call request 00001011, accepted 00001111, clear 00010011

Frame Relay HOT 5/27

  • Layers: physical and data link; errors detected, frames dropped
  • Address: DLCI 10 bits, C/R, EA, FECN, BECN, DE
  • Congestion: CIR, DE dropped first, FECN forward, BECN back
  • SVC states: setup, data transfer, idle, termination
  • Q.933 messages: SETUP, CALL PROCEEDING, CONNECT, DISCONNECT, RELEASE, RELEASE COMPLETE
  • Speeds: 56 kbps to 44.736 Mbps

ATM PIN 3/27

  • Cell: 53 bytes, 5 header, 48 payload
  • UNI header: GFC 4, VPI 8, VCI 16, PT 3, CLP 1, HEC 8
  • Layers: AAL (CS, SAR), ATM layer, physical (TC, PMD)
  • AAL types: AAL1 CBR, AAL2 timed VBR, AAL3/4 data, AAL5 IP
  • Services: CBR, rt-VBR, nrt-VBR, ABR, UBR

Ethernet

  • Standard: IEEE 802.3, Xerox PARC 1973, DIX
  • Speeds: 10 Mbps, 100 Mbps, 1 Gbps, 10 Gbps, 400 Gbps
  • Change: shared coaxial bus to switched full-duplex star

VoIP

  • Steps: SIP, codec, RTP over UDP, jitter buffer
  • Codecs: G.711 64 kbps, G.729 8 kbps, Opus
  • Quality: delay under 150 ms, jitter, loss
  • G.711 call: 80 kbps

NGN

  • Standard: ITU-T Y.2001, Y.2011
  • Ideas: IP core, convergence, service and transport strata, IMS, mobility
  • Layers: access, transport, control, service

MPLS

  • Label: 20 bits, TC 3, S 1, TTL 8
  • Routers: LER push, LSR swap, egress pop; FEC, LSP
  • Uses: traffic engineering, VPN, QoS, fast reroute

xDSL

  • Parts: splitter, modem, DSLAM, DMT
  • Variants: ADSL, ADSL2+, VDSL2, HDSL, SDSL
  • Against ISDN: same copper, far faster than 144 kbps

Chapter 2: Physical layer

Physical layer PIN 1/27

  • Definition: layer 1, raw bits as signals; mechanical, electrical, functional, procedural
  • Functions: physical characteristics, bit representation, data rate, synchronization, line configuration, topology, transmission mode
  • Modes: simplex, half-duplex, full-duplex
  • In TCP/IP: inside host-to-network (network access) layer
  • Devices: repeater, hub, modem, transceiver, cable

Delay and throughput PIN 3/27

  • Measures: bandwidth, throughput, latency, jitter
  • Four delays: processing, queuing, transmission L/R, propagation d/s
  • Throughput: data delivered / time; never above bandwidth
  • Products: bandwidth-delay product R x propagation delay; RTT two-way
  • Causes: congestion, slow links, distance, hops, retransmission, slow hosts
  • Example: 1,500 bytes at 10 Mbps 1.2 ms; GEO hop 238.6 ms

Channel capacity PIN 1/27

  • Nyquist: C = 2B log2 L, noiseless
  • Shannon: C = B log2 (1 + SNR), noisy
  • SNR dB: 10 log10 (S/N); 10 dB 10, 20 dB 100, 30 dB 1000
  • Impairments: attenuation, distortion, noise (thermal, induced, crosstalk, impulse)
  • Example: 3 kHz at 30 dB, 29.9 kbps; 2066 Bhadra 1.04 Gbps

Transmission media HOT 7/27

  • Definition: physical path carrying the signal, below the physical layer
  • Kinds: guided (twisted pair, coaxial, fiber); unguided (radio, microwave, infrared)
  • Factors: security, bandwidth, environment, noise, installation, mobility, cost, distance
  • Campus: UTP labs, multimode fiber backbone, microwave bridge, Wi-Fi, ISP fiber

Twisted pair and coaxial HOT 7/27

  • Twisted pair: two copper wires twisted, noise cancels; four pairs, RJ-45
  • Types: UTP, STP (F/UTP, U/FTP, S/FTP); straight-through, crossover, rollover
  • Categories: Cat 3 16 MHz, Cat 5e 100 MHz, Cat 6 250 MHz, Cat 6A 500 MHz, Cat 8 2000 MHz
  • Limits: Ethernet 100 m; amplifiers 5 to 6 km, repeaters 2 to 3 km
  • Coaxial: conductor, dielectric, braid, jacket; RG-6, RG-59 75 ohm; RG-58, RG-8 50 ohm
  • Compare: signal, bandwidth, distance, noise, attenuation, security, cost, installation

Optical fiber PIN 1/27

  • Structure: core, cladding 125 micrometres, buffer 250, Kevlar, jacket
  • Principle: total internal reflection; critical angle, numerical aperture
  • Modes: step index, graded index (50, 62.5 micrometres), single mode (8 to 10)
  • Parts: source LED or laser; detector PIN or APD; repeater or EDFA
  • Windows: 850, 1310, 1550 nm; 353, 229, 193 THz
  • Block diagram: source, transmitter, optical source, fiber, detector, receiver, destination

Unguided media HOT 5/27

  • Media: radio 3 kHz to 1 GHz; microwave 1 to 300 GHz; infrared 300 GHz to 400 THz
  • Antennas: omnidirectional, directional (dish, horn)
  • Propagation: ground below 2 MHz; sky 2 to 30 MHz; line of sight above 30 MHz
  • LOS: direct and ground-reflected waves; d = 3.57 root (Kh) km, K 4/3
  • Impairments: free-space loss, rain, multipath, refraction, obstacles

Satellite communication

  • Transponder: amplification, frequency translation; uplink above downlink
  • Orbits: LEO 500 to 2,000 km; MEO, GPS 20,200 km; GEO 35,786 km
  • Delay: GEO hop 0.24 s, reply 0.48 s; LEO 550 km 3.7 ms
  • Bands: L, S, C, X, Ku, K, Ka, V, W

Multiplexing HOT 6/27

  • Definition: many signals, one link; MUX and DEMUX
  • Importance: efficiency, cost, trunks and broadcasting, scalability
  • Types: FDM (guard bands), WDM, synchronous TDM, statistical TDM, CDM
  • TDM example: 4 x 64 kbps, 33-bit frame, 264 kbps
  • CDM: orthogonal chip codes; CDMA 3G, GPS

Switching TOP 13/27

  • Definition: sender to receiver through intermediate switches; mesh needs n(n-1)/2 links
  • Types: circuit, message, packet (datagram, virtual circuit)
  • Circuit phases: setup, data transfer, teardown
  • Compare: path, setup, bandwidth, store-and-forward, addressing, delay, order, congestion, charging
  • Real time: reserved bandwidth, constant delay, no jitter, in order, one setup
  • Versus multiplexing: path through network against sharing one link

Datagram and virtual circuit HOT 6/27

  • Datagram: connectionless, full address, independent routing, out of order; IP
  • Virtual circuit: setup, data transfer, teardown; short VCI swapped each hop
  • VC types: PVC, SVC
  • VCI names: X.25 LCN, Frame Relay DLCI, ATM VPI/VCI, MPLS label
  • Frame Relay: DLCI 10 bits, PVC, Q.933 SVC, FECN, BECN, DE

Telephone network and E1 PIN 2/27

  • Parts: telephone set, local loop, end office, tandem, toll office, trunks
  • Telephone set: transmitter, receiver, hook switch, DTMF dialler, ringer, hybrid
  • Call steps: off-hook, dial tone, dialling, switching, ringing, answer, hang up
  • T1: 24 channels, 193 bits, 1.544 Mbps; DS2 6.312, DS3 44.736
  • E1: 32 slots, TS0 sync, TS16 signalling, 2.048 Mbps; E2 8.448, E3 34.368, E4 139.264

Switching systems

  • Kinds: manual; Strowger, crossbar; electronic SPC
  • Electronic: space division, time division (analog, digital)
  • Space: crossbar N squared crosspoints; multistage
  • Time: time slot interchange; TST
  • Signalling: CAS (TS16), CCS (SS7)

ISDN HOT 5/27

  • Purpose: digital local loop, one network, out-of-band signalling, digital quality
  • Channels: B 64 kbps; D 16 or 64 kbps; H0 384, H11 1536, H12 1920
  • Interfaces: BRI 2B+D 144 (192) kbps; PRI 23B+D 1.544, 30B+D 2.048 Mbps
  • Groups: TE1, TE2, TA, NT2, NT1; points R, S, T, U
  • Signalling: D channel, LAPD (Q.921), Q.931; SS7 inside
  • Messages: SETUP, CALL PROCEEDING, ALERTING, CONNECT, DISCONNECT, RELEASE

Chapter 3: Data link layer

Data link layer HOT 8/27

  • Functions: framing, physical addressing, flow control, error control, access control
  • Services: unacknowledged connectionless (Ethernet), acknowledged connectionless (Wi-Fi), acknowledged connection-oriented (HDLC)
  • Design issues: service interface, framing, error control, flow control, medium access, addressing
  • Sublayers: LLC 802.2, DSAP and SSAP, types 1, 2, 3; MAC per LAN

Framing TOP 10/27

  • Methods: character count, byte stuffing, bit stuffing, coding violations
  • Count flaw: one garbled count, every later boundary lost
  • Byte stuffing: FLAG, ESC before FLAG or ESC; PPP 0x7E, 0x7D
  • Bit stuffing: flag 01111110, a 0 after five 1s; HDLC
  • Coding violations: Manchester high-high, low-low; 4B/5B J and K
  • Example: 01001111110111110 to 0100111110101111100

Errors, parity, checksum PIN 1/27

  • Types: single-bit, burst (first to last bad bit); content, flow integrity
  • Detection: discard and resend, ARQ, backward correction; parity, checksum, CRC
  • Correction: FEC, more redundancy; Hamming, Reed-Solomon; QR codes
  • Parity: odd counts only; 2D parity corrects one bit
  • Checksum: one's complement sum, complement sent; book example 11011010

CRC PIN 3/27

  • Sender: append r zeros, divide by G mod 2, remainder is the CRC
  • Receiver: divide by G; zero accept, nonzero reject
  • Detects: single-bit, odd counts with x + 1, bursts up to r
  • Generators: CRC-8 ATM, CRC-16-CCITT HDLC and PPP, CRC-32 Ethernet
  • Example: 1101 with 1011, remainder 001, sent 1101001

Hamming distance, Hamming code PIN 1/27

  • Distance: XOR, count the 1s; 10101 and 11110 give 3
  • Rules: detect s if d ≥ s + 1; correct t if d ≥ 2t + 1
  • Parity bits: positions 1, 2, 4; 2^r ≥ m + r + 1
  • Groups: P1 1, 3, 5, 7; P2 2, 3, 6, 7; P4 4, 5, 6, 7
  • Book example: 1110111, syndrome 100, bit 4, corrected 1111111

Flow control HOT 5/27

  • Stop and wait: one frame then ACK; U = 1/(1 + 2a)
  • Sliding window: W frames, seq modulo 2^k, ACK names next expected
  • Piggybacking: ack field in data frames, ack timer; HDLC N(R), TCP
  • Satellite example: a = 270, U 0.18 %; W = 7 gives 1.3 %

ARQ PIN 4/27

  • Tools: sequence numbers, ACK, NAK, timers, copies kept
  • Stop and wait: 1-bit seq; damaged frame, lost frame, lost ACK
  • Go-back-N: window 2^k - 1, receiver window 1, resend from the lost frame
  • Selective repeat: windows 2^(k-1), buffer, resend only the lost frame
  • Window limits: 3 bits, GBN 7, SR 4

HDLC PIN 2/27

  • Stations: primary, secondary, combined
  • Configurations: unbalanced, balanced, symmetric
  • Modes: NRM, ARM, ABM
  • Frame: flag, address, control, information, FCS, flag
  • Frame types: I with N(S), N(R); S with RR, RNR, REJ, SREJ; U with SNRM, SABM, DISC, UA
  • Family: LAPB, LAPD, LAPF; Cisco serial default

PPP

  • Parts: framing, LCP, NCPs (IPCP)
  • Frame: 0x7E, 0xFF, 0x03, protocol, payload 1500, FCS, 0x7E
  • Phases: dead, establish, authenticate, network, open, terminate
  • Authentication: PAP clear password, CHAP challenge and hash
  • Related: SLIP (RFC 1055), PPPoE

MAC sublayer HOT 7/27

  • Job: who sends next on a broadcast channel
  • Why essential: collisions, efficiency, fairness, delay, priority, cost
  • Static: FDM, TDM; delay N times; 200 µs against 2 ms
  • Dynamic: station model, one channel, collisions observed, slotted or continuous, carrier sense or not
  • Classes: random, controlled, channelization

ALOHA HOT 6/27

  • Origin: ALOHAnet, Hawaii, Abramson, 1971
  • Pure: any time, vulnerable 2T, S = G e^-2G, 18.4 % at G = 0.5
  • Slotted: slot starts, vulnerable T, S = G e^-G, 36.8 % at G = 1
  • No collision: none within T either side; none in the same slot
  • Example: 200 kbps, 200-bit frames; 135, 92, 38 frames/s

CSMA PIN 1/27

  • Rule: listen before talk
  • Vulnerable time: propagation time
  • Persistence: 1-persistent (Ethernet), non-persistent, p-persistent

CSMA/CD TOP 9/27

  • Steps: sense, transmit and listen, detect, jam 32 bits, back off, retry
  • Backoff: K from 0 to 2^min(n,10) - 1, slot 512 bit times, 16 attempts
  • Detection: higher signal level on coax; receive activity on twisted pair
  • Minimum frame: 2 T_prop B; 51.2 µs, 512 bits, 64 bytes
  • Collision: overlapping frames; propagation delay, waiting stations
  • Today: switches, full duplex, no collisions

Controlled access

  • Reservation: mini-slots before data
  • Polling: poll and select, primary station; Bluetooth, HDLC NRM
  • Token passing: logical ring; holding time, priority, lost token

Channelization

  • FDMA: bands, guard bands; first-generation mobile
  • TDMA: time slots, synchronisation; GSM 8 slots per 200 kHz carrier
  • CDMA: orthogonal Walsh codes, inner product; 3G

IEEE 802 family

  • Standards: 802.1 bridging, VLANs; 802.2 LLC; 802.3 Ethernet; 802.4 token bus; 802.5 token ring; 802.11 Wi-Fi; 802.15 Bluetooth; 802.16 WiMAX
  • Status: 802.4 and 802.5 withdrawn

Ethernet PIN 4/27

  • Frame: preamble 7, SFD 1, DA 6, SA 6, length/type 2, data 46 to 1500, FCS 4
  • Sizes: 64 to 1518 bytes; gap 96 bits; type 0x0800 IPv4
  • MAC address: 48 bits, OUI, I/G, U/L, broadcast FF:FF:FF:FF:FF:FF
  • Cabling: 10Base5, 10Base2, 10BaseT, 10BaseF, 100BaseTX, 100BaseFX, 1000BaseT
  • Fiber: 1000BaseSX 850 nm, 1000BaseLX 1310 nm, 10GBase-SR, LR, ER

Token bus HOT 5/27

  • Idea: physical bus, logical ring by descending address
  • Token ring name: token circles, lowest back to highest
  • Priority: classes 0, 2, 4, 6
  • Maintenance: claim token, solicit successor, who follows, set successor
  • Physical: broadband coax, 1, 5, 10 Mbps; MAP factories

Token ring PIN 4/27

  • Steps: wait, seize (T bit), circulate, copy (A, C), remove, release
  • Frame: SD, AC, FC, DA, SA, data, FCS, ED, FS; token SD, AC, ED
  • AC byte: PPPTMRRR
  • Monitor: lost token, orphan frames, ring delay
  • Physical: 4 or 16 Mbps, STP, differential Manchester, MAU, 10 ms

FDDI PIN 3/27

  • Basics: 100 Mbps fiber, dual counter-rotating rings, 4B/5B
  • Size: 1000 connections, 200 km, 2 km apart, 4500-byte frames
  • Timed token: synchronous and asynchronous traffic, early release
  • Stations: DAS, SAS, concentrators
  • Fault tolerance: wrap, optical bypass, dual homing

Wireless LAN PIN 3/27

  • Architecture: BSS ad hoc, infrastructure with AP; ESS, distribution system, SSID
  • No CSMA/CD: cannot listen while sending; hidden, exposed stations; fading
  • CSMA/CA: DIFS, contention window, SIFS, ACK, RTS, CTS, NAV
  • DSSS: Barker 10110111000, 11 chips, 22 MHz, 10.4 dB
  • Versions: 802.11b, a, g, n, ac, ax

VLAN PIN 3/27

  • Definition: one broadcast domain by configuration
  • Membership: port, MAC, IP, application
  • 802.1Q tag: TPID 0x8100, PCP 3, DEI 1, VID 12; VLANs 1 to 4094
  • Ports: access untagged, trunk tagged, native VLAN
  • Routing: router on a stick, layer 3 switch
  • Design: STUDENT 10, 192.168.10.0/24; DEPARTMENT 20, 192.168.20.0/24

Chapter 4: Network layer

Network layer PIN 1/27

  • Delivery: host to host across networks; data link hop to hop; transport process to process
  • Functions: logical addressing, routing, forwarding, packetizing, fragmentation, internetworking, ICMP error reporting, congestion control
  • Key layer: highest layer in every router, narrow waist, global addressing
  • Services: datagram (IP), virtual circuit (X.25, ATM, MPLS)

Internetworking devices PIN 4/27

  • Layer 1: repeater (regenerates, 2 ports, 5-4-3 rule), hub (active, passive), one collision domain
  • Layer 2: bridge, switch (MAC table, collision domain per port)
  • Switch modes: store-and-forward, cut-through, fragment-free (64 bytes)
  • Layer 3: router (IP, routing table, broadcast domain per interface, TTL, NAT)
  • Gateway: up to layer 7, protocol conversion; email, VoIP, IoT
  • Switch over hub: dedicated bandwidth, no collisions, full duplex, privacy, VLANs, cost

Bridges PIN 1/27

  • Steps: receive, record source MAC, filter, forward, flood, age (300 s)
  • Throughput: repeater C; bridge 2C/(1+f); 100 Mbps, f 0.2: 166.7 Mbps
  • Gains: two collision domains, longer LAN, bad frames dropped, mixed speeds
  • Loops: STP, IEEE 802.1D, root bridge lowest ID, priority 32768
  • Types: transparent, source routing, translational, remote

IPv4 addresses HOT 5/27

  • Format: 32 bits, dotted decimal, network part and host part
  • Classes: A 0 /8 0 to 127; B 10 /16 128 to 191; C 110 /24 192 to 223; D 1110 multicast; E 1111 reserved
  • Counts: A 126 networks, 16,777,214 hosts; B 16,384, 65,534; C 2,097,152, 254
  • Special: network, directed broadcast, 255.255.255.255, 0.0.0.0, 127.0.0.0/8, 169.254.0.0/16
  • Private: 10/8, 172.16/12, 192.168/16; CGNAT 100.64/10
  • Logical vs MAC: hierarchical, end to end, any link, assigned, location

Subnetting and VLSM TOP 24/27

  • Numbers: subnets 2^s, hosts 2^h minus 2, block 256 minus mask octet
  • Masks: /25 128, /26 64, /27 32, /28 16, /29 8, /30 4
  • VLSM steps: AND for block, size, sort largest first, allocate from start, links /30, network, range, broadcast
  • Waste: usable minus hosts per subnet; unused range after the last subnet
  • Contribution: less waste, smaller broadcast domains, security, management, summarization, growth
  • Traps: 2 extra addresses, aligned blocks, subnet zero (RFC 1878), /31 (RFC 3021)

CIDR and supernetting PIN 2/27

  • CIDR: RFC 1519 (1993), RFC 4632; a.b.c.d/n; aligned power-of-two blocks
  • Supernet rules: contiguous, power of two, aligned
  • Example: 192.168.4.0 to 7.0 /24s into 192.168.4.0/22, mask 255.255.252.0
  • Routing: aggregation, longest prefix match

NAT

  • Types: static, dynamic, PAT (NAPT, overload)
  • Table: private IP and port to public IP and port
  • Costs: breaks end to end, port forwarding, P2P and IPsec AH trouble

IPv4 datagram HOT 5/27

  • Header: version, IHL, TOS, total length, identification, flags, fragment offset, TTL, protocol, checksum, source, destination, options
  • Sizes: header 20 to 60 bytes; datagram 65,535; IHL 5 to 15
  • TTL and protocol: hop limit 64, 128, 255; 1 ICMP, 6 TCP, 17 UDP, 89 OSPF, 50 ESP, 51 AH
  • Fragmentation: MTU 1,500, same ID, offset in 8 bytes, MF, DF, destination reassembles
  • Max TCP payload: 65,495 = 65,535 minus 20 IP minus 20 TCP; UDP 65,507

ARP and RARP PIN 4/27

  • ARP steps: cache, broadcast request, unicast reply, cache, send
  • Packet: 28 bytes, EtherType 0x0806, operation 1 request, 2 reply
  • Variants: gratuitous ARP, proxy ARP, ARP spoofing
  • RARP: MAC to IP, RFC 903, diskless hosts; replaced by BOOTP, DHCP
  • NDP: RFC 4861, ICMPv6 133 to 137, solicited-node multicast, SLAAC, DAD, SEND

ICMP HOT 5/27

  • Format: type, code, checksum, rest of header; errors carry IP header plus 8 bytes
  • Errors: 3 unreachable, 4 source quench, 11 time exceeded, 12 parameter problem, 5 redirect
  • Queries: echo 8 and 0, timestamp 13 and 14, address mask 17 and 18, router 10 and 9
  • Uses: ping, traceroute, path MTU discovery, redirect, monitoring
  • No error for: ICMP errors, non-first fragments, broadcast, multicast

Routing TOP 13/27

  • Routing vs forwarding: builds tables vs per-packet lookup
  • Good algorithm: correctness, simplicity, robustness, stability, fairness, optimality
  • Static vs dynamic: manual, fixed, secure vs automatic, adaptive, overhead
  • Routed vs routing: IPv4, IPv6 vs RIP, OSPF, EIGRP, BGP
  • Optimality principle: I to K through J; r1, r2; sink tree, no loops
  • Autonomous system: one administration, ASN 16 or 32 bits; IGP inside, BGP between

Routing table

  • Fields: destination, mask, next hop, interface, metric, source
  • Classful: first octet, class, default mask, network lookup
  • Classless: longest prefix match; default route 0.0.0.0/0

Dijkstra's algorithm PIN 1/27

  • Steps: source 0 permanent, relabel neighbours, fix smallest tentative, repeat, trace back
  • Book graph: B 2, E 4, G 5, F 6, H 8, C 9, D 10
  • A to D: A, B, E, F, H, D; cost 10

Flooding

  • Rule: every line except the arrival line
  • Damping: hop counter, sequence numbers, selective flooding
  • Uses: robustness, LSPs, broadcast, benchmark

Distance vector TOP 10/27

  • Keys: whole network, neighbours only, regular intervals
  • Rule: Bellman-Ford, D x of y = min over v of c(x,v) + D v of y
  • Count to infinity: C 3, B 4, C 5, up to 16
  • Loop prevention: max hop count, split horizon, poison reverse, route poisoning, triggered updates, hold-down

Link state TOP 11/27

  • Keys: neighbourhood, to all routers, on change
  • Five steps: discover, measure, build LSP, flood, compute
  • Properties: full map, Dijkstra, fast convergence, cost metric, more memory, areas
  • DV vs LS: table vs own links, neighbours vs all, Bellman-Ford vs Dijkstra, slow vs fast, RIP vs OSPF

Hierarchical routing

  • Regions: 1A table 17 to 7 entries
  • 720 routers: 720 flat, 53 two-level, 25 three-level; levels ln N
  • Cost: longer paths; used in OSPF areas, AS hierarchy

Routing protocols PIN 4/27

  • Why: scale, discovery, adaptation, best loop-free paths, policy
  • IGP: RIP, OSPF, IS-IS, EIGRP; EGP: BGP
  • Classless: RIPv2, OSPF, EIGRP, IS-IS, BGP-4; classful: RIPv1, IGRP
  • IGRP: Cisco, bandwidth and delay, 90 s, 100 hops
  • EIGRP: DUAL, feasible successor, partial updates, 224.0.0.10

RIP PIN 2/27

  • Basics: distance vector, hop count, 15 max, 16 infinity, UDP 520
  • Timers: update 30, invalid 180, hold-down 180, flush 240 seconds
  • RFC timers: timeout 180, garbage collection 120
  • Versions: RIPv1 RFC 1058 broadcast, RIPv2 RFC 2453 224.0.0.9, RIPng UDP 521
  • Limits: 15 hops, slow, ignores bandwidth, full tables

OSPF HOT 5/27

  • Basics: link state, RFC 2328, protocol 89, 224.0.0.5 and 224.0.0.6
  • Packets: Hello, DBD, LSR, LSU, LSAck; hello 10 s, dead 40 s
  • DR election: priority 0 to 255, default 1; router ID; no pre-emption
  • States: Down, Init, 2-Way, ExStart, Exchange, Loading, Full
  • Areas: area 0 backbone, ABR, ASBR; cost 10^8 / bandwidth

BGP

  • Basics: BGP-4, RFC 4271, path vector, TCP 179
  • Messages: open, update, keepalive, notification
  • Terms: AS path, eBGP, iBGP, local preference, NPIX

Unicast and multicast PIN 3/27

  • Unicast: one to one; RIP, OSPF, IS-IS, EIGRP, BGP
  • Multicast: one to group, class D, one copy per link
  • Membership: IGMP v1, v2 leave, v3
  • Protocols: DVMRP, MOSPF, PIM-DM, PIM-SM, CBT
  • Trees: source-based, shared, rendezvous point, RPF

Network design PIN 2/27

  • Method: requirements, topology, devices, cabling, wireless, VLANs, servers, security
  • Layers: core, distribution, access
  • Campus: 500 PCs, 25 room switches, 5 distribution, core, OM3 fibre, Cat6
  • Hotel: dual ISP, UTM firewall, PoE+ switches, Wi-Fi 6, VLANs, PMS, IP PBX, NVR

Chapter 5: Transport layer

Transport service HOT 5/27

  • Definition: process-to-process delivery, end to end, only in hosts
  • Scopes: node to node (MAC), host to host (IP), process to process (port)
  • Services: addressing, segmentation, connection control, reliability, ordering, flow control, multiplexing, congestion control
  • In order: handshake, numbered bytes, checksum, cumulative ACK, RTO and three duplicate ACKs, reorder buffer, FIN
  • Example: 1001, 2001 lost, 3001 kept, duplicate ACK 2001, resend, ACK 4001

Services to upper layer

  • Two services: connection-oriented (TCP, phone call), connectionless (UDP, letter)
  • Primitives: LISTEN, CONNECT, SEND, RECEIVE, DISCONNECT; TPDU, segment, user datagram
  • Berkeley sockets: SOCKET, BIND, LISTEN, ACCEPT, CONNECT, SEND, RECEIVE, CLOSE
  • QoS: establishment delay, failure probability, throughput, transit delay, residual error ratio, protection, priority, resilience

UDP HOT 6/27

  • Standard: RFC 768, 1980; protocol 17
  • Header: source port, destination port, length (8 to 65,535), checksum; 8 bytes
  • Checksum: pseudo-header (source IP, destination IP, zero, 17, length); optional IPv4, mandatory IPv6
  • Features: connectionless, unreliable, unordered, message-oriented, stateless, multicast, no flow control
  • Why used: no setup, timeliness, low overhead, broadcast, own reliability (DNS, TFTP, QUIC)
  • Uses: DNS 53, DHCP 67/68, VoIP RTP, games, IPTV, SNMP 161, NTP 123, TFTP 69, RIP 520

TCP TOP 9/27

  • Standard: RFC 9293 (2022), RFC 793 (1981); protocol 6
  • Features: connection-oriented, reliable, ordered, byte stream, full duplex, point to point, piggybacking
  • Header: ports, sequence, acknowledgement, HLEN, reserved, flags, window, checksum, urgent pointer, options; 20 to 60 bytes
  • Flags: CWR, ECE, URG, ACK, PSH, RST, SYN, FIN
  • Reliability: handshake, sequence numbers, cumulative ACK, RTO = SRTT + 4 RTTVAR, fast retransmit, checksum, windows, FIN

TCP against UDP HOT 6/27

  • TCP: handshake, ACK, order, 20 to 60 bytes, windows, unicast, HTTP, SMTP, FTP, SSH
  • UDP: no setup, no ACK, 8 bytes, no control, multicast, DNS, DHCP, VoIP, games
  • Two transports: opposite needs, end hosts only, end-to-end principle
  • One IP: hourglass waist, every router, any link, costly to change (IPv6)
  • Others: SCTP, DCCP, QUIC over UDP

Ports and sockets PIN 4/27

  • Port: 16 bits, 0 to 65,535, names a process
  • Ranges: well-known 0 to 1023, registered 1024 to 49151, dynamic 49152 to 65535
  • Common: 20/21 FTP, 22 SSH, 23 Telnet, 25 SMTP, 53 DNS, 67/68 DHCP, 80 HTTP, 443 HTTPS
  • Standardize: meeting point, interoperability, URL default, firewall rules, root below 1024, no clashes
  • Port 8765: URL needs :8765, plain URL refused (RST), firewall may block
  • Socket: IP plus port; socket pair four-tuple; Berkeley API

Handshake and release HOT 7/27

  • Open: SYN seq 8000; SYN + ACK seq 15000 ack 8001; ACK seq 8001 ack 15001
  • Roles: server passive open (LISTEN) first, client active open; no listener gives RST
  • Why three: both ISNs confirmed, old duplicate SYN rejected, random ISN
  • Release: FIN, ACK (half-close), FIN, ACK; three segments if FIN+ACK combined
  • States: FIN-WAIT-1, FIN-WAIT-2, TIME-WAIT (2 MSL), CLOSE-WAIT, LAST-ACK, CLOSING
  • Attack: SYN flood, SYN cookies

Sliding window PIN 2/27

  • Window: rwnd advertised in every segment; in flight at most rwnd
  • Regions: acknowledged, in flight, usable, must wait
  • Example: ACK 3001 rwnd 4000 gives 3001 to 7000; ACK 5001 gives 5001 to 9000
  • Zero window: persist timer probes
  • Refinements: silly window, Clark, Nagle, window scale 2 to the 14, min(rwnd, cwnd)
  • Buffers: chained fixed-size, chained variable-size, circular per connection

Multiplexing

  • Multiplexing: sockets to one IP, port headers added
  • Demultiplexing: ports pick the socket
  • Keys: UDP destination IP and port; TCP four-tuple
  • Older sense: upward (many on one), downward (one on many, Multipath TCP, SCTP)

Congestion PIN 4/27

  • Definition: load above capacity; queues, delay, drops, collapse
  • Causes: arrival rate, buffer memory, bursts, slow processors, retransmissions, routing
  • Policies: retransmission, out-of-order caching, ACK, flow control, timeout; VC or datagram, queueing, discard, routing, lifetime
  • Open loop: retransmission, window, ACK, discard, admission, shaping
  • Closed loop: backpressure, choke packets, implicit, explicit (ECN), load shedding, RED
  • TCP: slow start, congestion avoidance (AIMD), fast retransmit, fast recovery

Leaky bucket HOT 5/27

  • Idea: finite queue, constant output rate, overflow discarded
  • Steps: arrive, full then discard, queue, one packet per tick
  • Byte counting: counter n per tick, send while fits, no carry over
  • Example: n 1000; 200 and 700, then 500 and 300
  • Limits: packet loss, no saved credit, rigid

Token bucket TOP 9/27

  • Idea: tokens at rate r up to C; packet takes token; bursts up to C
  • Steps: token every delta T, full discards token, no token waits, counter
  • Formula: C + rS = MS, S = C / (M minus r)
  • Example: C 6 Mb, M 10 Mbps, r 2 Mbps, S 0.75 s, 12 Mb in 3 s against 6 s
  • Against leaky: holds tokens, bursts, no packet loss, idle credit, fast response
  • Best shaping: token bucket, leaky for peak, edge policing, TCP and ECN

Chapter 6: Application layer

Application layer and ports

  • Job: messages between processes, carried by TCP or UDP
  • Models: client-server, peer-to-peer
  • TCP ports: HTTP 80, HTTPS 443, FTP 21 and 20, SSH 22, Telnet 23, SMTP 25 and 587, POP3 110, IMAP 143
  • UDP ports: DNS 53, DHCP 67 and 68, TFTP 69, SNMP 161 and 162

HTTP and HTTPS HOT 5/27

  • Nature: stateless request and response, TCP 80
  • Steps: DNS, TCP handshake, request, processing, response, render, close or keep
  • Messages: request line or status line, headers, blank line, body
  • Methods and codes: GET, POST, HEAD, PUT, DELETE; 1xx to 5xx, 200, 301, 304, 404, 500
  • Connections: non-persistent 2 RTT per object; persistent, pipelining; HTTP/1.0, 1.1, 2, 3
  • HTTPS: TLS, port 443, certificate, encryption, integrity; web servers Apache, Nginx, IIS

FTP and TFTP PIN 4/27

  • Connections: control port 21 for the session, data port 20 per file, out of band
  • Session: 220, USER, 331, PASS, 230, PORT or PASV, RETR or STOR, 150, 226, QUIT, 221
  • Modes: active (server opens from 20), passive (227, client opens)
  • Traits: stateful, plain-text password; types ASCII, image; FTPS, SFTP
  • TFTP: UDP 69, no login, RRQ, WRQ, DATA, ACK, ERROR, 512-byte blocks, stop and wait
  • File servers: SMB 445, NFS 2049

SSH, PuTTY, WinSCP

  • SSH: port 22, host key, password or key login, three layers
  • Copy: SCP, SFTP over SSH; FTPS is FTP over TLS
  • PuTTY: SSH, Telnet, rlogin, serial client; PuTTYgen, Pageant
  • WinSCP: SFTP, SCP, FTP, two-panel drag and drop
  • Insecure: Telnet 23, FTP 21

Electronic mail TOP 11/27

  • Components: user agent, mail server, MTA, MDA, MAA, mailbox, queue
  • Flow: UA, SMTP 587, sender's server, MX lookup, SMTP 25, mailbox, POP3 or IMAP
  • SMTP: 220, HELO, MAIL FROM, RCPT TO, DATA 354, body ending ".", 250, QUIT 221; 7-bit ASCII
  • POP3: port 110, authorization, transaction, update; delete or keep mode
  • IMAP: port 143, mail and folders on server, state kept, partial fetch, server search
  • MIME: Content-Type, Content-Transfer-Encoding; base64 3 bytes to 4 characters; quoted-printable; /9j/

DNS TOP 11/27

  • Basics: distributed hierarchical database, UDP 53, RFC 1034 and 1035, TTL caching
  • Servers: root (13, a to m), TLD, authoritative, local resolver
  • Queries: recursive (server does the work), iterative (referrals); inverse via PTR
  • Records: A, AAAA, CNAME, MX, NS, PTR, SOA, TXT; name, type, class, TTL, data
  • Delegation: NS records plus glue in the parent zone
  • Message: 12-byte header, ID, QR AA TC RD RA RCODE, four counts; question, answer, authority, additional

DHCP PIN 1/27

  • Basics: UDP 67 and 68, lease, mask, gateway, DNS
  • DORA: DISCOVER, OFFER, REQUEST, ACK; also NAK, RELEASE, DECLINE, INFORM
  • Timers: T1 50 percent unicast renew, T2 87.5 percent broadcast rebind, expiry back to INIT
  • States: INIT, SELECTING, REQUESTING, BOUND, RENEWING, REBINDING
  • Relay: ip helper-address, gateway field

P2P applications

  • Designs: central index, flooding, super peers, DHT
  • BitTorrent: torrent file, tracker, swarm, seeders, leechers, rarest first, tit for tat
  • DHT: Kademlia, Chord, about log N hops
  • Scaling: each peer adds upload capacity

Socket programming HOT 5/27

  • Types: stream TCP, datagram UDP, raw IP
  • Server: socket, bind, listen, accept, recv, send, close
  • Client: socket, connect, send, recv, close
  • Rules: accept returns a new socket; server first, else connection refused; htons
  • UDP: sendto, recvfrom

Proxy and web caching PIN 3/27

  • Cache: hit, miss, conditional GET, 304 Not Modified
  • Uses: speed, bandwidth, origin load, filtering, privacy, security, logging
  • Kinds: forward, reverse, transparent, anonymous, distorting, high anonymity
  • Formula: average time = h x hit time + (1 - h) x miss time

Server optimization

  • Web: caching, CDN, compression, HTTP/2, load balancing
  • Mail: backup MX, spam filtering, separate 587 and 25
  • DNS: TTL caching, secondary servers, anycast, rate limits
  • All: RAID, RAM, SSD, UPS, monitoring
  • Availability: 99.9 percent, 8.76 hours down a year

RAID PIN 1/27

  • Why: availability, performance, capacity; not a backup
  • RAID 0: striping, n disks, no fault tolerance
  • RAID 1: mirroring, one disk usable, survives one failure
  • RAID 5: distributed parity, n minus 1, at least 3, write penalty
  • Parity: XOR of the stripe

SNMP

  • Parts: manager, agent, MIB, SMI, OID
  • Messages: GetRequest, GetNextRequest, GetBulkRequest, SetRequest, Response, Trap, InformRequest
  • Ports: UDP 161 agent, 162 traps
  • Versions: v1, v2c community string, v3 security

MRTG and PRTG

  • MRTG: Tobias Oetiker, Perl, SNMP octet counters, 5 minutes, four graphs
  • PRTG: Paessler, Windows, sensors, alerts, free to 100 sensors

Wireshark and Packet Tracer

  • Wireshark: Ethereal 1998, capture and display filters, Follow TCP Stream, TShark
  • Packet Tracer: Cisco simulator, realtime and simulation modes, server services

Chapter 7: Introduction to IPv6

Why IPv6 TOP 13/27

  • Definition: IETF replacement for IPv4, RFC 8200 (2017); RFC 1883 (1995), RFC 2460 (1998); version 5 taken by ST
  • IPv4 problems: exhaustion, NAT, complex header, routing tables, no security, weak QoS, manual setup, broadcast, mobility
  • Numbers: 232 = 4,294,967,296; 2128≈3.4×1038; /64 holds 264
  • Dates: IANA pool empty 3 February 2011; APNIC last block 15 April 2011; World IPv6 Launch 6 June 2012
  • Advantages: address space, better header, extension, smaller tables, security, resource allocation, scoped multicast, SLAAC, no NAT, mobility
  • IPsec: mandatory in RFC 4294 (2006), "should" since RFC 6434 (2011)

The IPv6 datagram HOT 6/27

  • Fields (bits): version 4, traffic class 8, flow label 20, payload length 16, next header 8, hop limit 8, source 128, destination 128
  • Total: 320 bits, 40 bytes fixed; payload up to 65,535
  • Removed: IHL, identification, flags, fragment offset, header checksum, options
  • Renamed: TOS to traffic class, total length to payload length, TTL to hop limit, protocol to next header
  • Router work: hop limit minus 1; no checksum, no fragmenting; Packet Too Big; minimum MTU 1,280
  • Book slip: flow label printed 24 bits, really 20

Extension headers PIN 1/27

  • Order: hop-by-hop 0, destination options 60, routing 43, fragment 44, AH 51, ESP 50, destination options 60, upper layer
  • Upper layer: TCP 6, UDP 17, ICMPv6 58; none 59
  • Hop-by-hop options: Pad1, PadN, jumbo payload, router alert
  • Rules: once each, destination options twice; multiples of 8 bytes; source-only fragmentation, path MTU discovery

IPv6 addresses PIN 3/27

  • Notation: 8 groups of 4 hex digits; drop leading zeros; one double colon; prefix /64
  • Types: unicast, anycast, multicast; no broadcast
  • Unicast: global 2000::/3, link-local fe80::/10, unique local fc00::/7, loopback ::1, site-local fec0::/10 deprecated
  • IPv4 inside: mapped ::ffff:a.b.c.d, NAT64 64:ff9b::/96, 6to4 2002::/16
  • SLAAC: link-local, DAD, RS 133, RA 134, global address, DHCPv6 if M or O
  • Interface ID: EUI-64 (FF-FE, flip bit 7) or random (RFC 7217, RFC 8981)

IPv6 multicasting

  • Format: ff, flags 0RPT, scope 4 bits, group ID 112 bits
  • Scopes: 1 interface, 2 link, 4 admin, 5 site, 8 organization, e global
  • Groups: ff02::1 nodes, ff02::2 routers, ff02::5 OSPFv3, ff02::9 RIPng, ff02::1:2 DHCPv6
  • Solicited-node: ff02::1:ff + last 24 bits; MAC 33:33 + last 32 bits
  • MLD: v1 RFC 2710, v2 RFC 3810; query 130, report 131 or 143, done 132

Transition from IPv4 TOP 18/27

  • Coexistence: both protocols side by side, no flag day, incompatible headers
  • Dual stack: RFC 4213, two stacks, DNS A or AAAA, Happy Eyeballs, needs IPv4 addresses
  • Tunnels: protocol 41; configured, 6to4 RFC 3056, ISATAP RFC 5214, 6RD RFC 5969, Teredo RFC 4380
  • Formats: 6to4 2002 + IPv4; ISATAP 0000:5efe or 0200:5efe + IPv4; 6RD ISP prefix + IPv4 bits
  • Translation: SIIT RFC 7915, NAT-PT historic, NAT64 + DNS64, 464XLAT, DS-Lite, MAP
  • Choice: dual stack first (RFC 6180), tunnels across IPv4, translation for IPv6-only

Chapter 8: Network security

Network security and properties TOP 11/27

  • Attacks: interruption, interception, modification, fabrication; passive, active, replay, denial of service
  • Properties: confidentiality, integrity, authentication, non-repudiation, availability, access control
  • Maintaining: policy, access control, encryption, firewall, VLANs, patching, anti-malware, IDS, backups, physical security, training

Cryptography HOT 8/27

  • Terms: plaintext, ciphertext, key, cipher, cryptanalysis, Kerckhoffs
  • Symmetric: one shared key, fast, n(n-1)/2 keys; DES, AES, IDEA, RC4
  • Public key: key pair, slow, 2n keys; RSA, Diffie-Hellman, ElGamal, ECC
  • Others: block and stream ciphers, hash (SHA-256), hybrid session key

Classical ciphers

  • Substitution: Caesar, monoalphabetic, polyalphabetic, Vigenère
  • Transposition: columnar, rail fence
  • Book examples: k = 2 gives k co c uvwfgpv; attack gives muumbf

DES and AES PIN 4/27

  • DES: 64-bit block, 56-bit key, 16 Feistel rounds, IP, swap, IP inverse
  • Function f: expansion 32 to 48, XOR key, 8 S-boxes, permutation P
  • Key schedule: PC-1, 28 + 28, shift 1 or 2, PC-2
  • AES: 128-bit block; 10, 12, 14 rounds; Rijndael, 2001
  • AES round: SubBytes, ShiftRows, MixColumns, AddRoundKey

RSA TOP 16/27

  • Keys: p, q; n = pq; phi = (p-1)(q-1); gcd(e, phi) = 1; ed mod phi = 1
  • Formulas: C = M^e mod n; M = C^d mod n
  • Example: 7, 11, 77, 60, e 13, d 37; E 5 to 26
  • Security: factoring n; 2048-bit modulus

Diffie-Hellman PIN 2/27

  • Steps: N, G public; R1 = G^x; R2 = G^y; K = G^xy mod N
  • Example: G 7, N 23, x 3, y 6; R1 21, R2 4, K 18
  • Weakness: man in the middle; authenticated in TLS, IKE

Digital signatures HOT 5/27

  • Sign: hash, encrypt digest with private key
  • Verify: hash, decrypt with public key, compare
  • Gives: authentication, integrity, non-repudiation; no confidentiality
  • Trust: certificate, CA, PKI, X.509

PGP PIN 3/27

  • Origin: Phil Zimmermann, 1991; OpenPGP
  • Steps: hash, sign, compress, session key, B's public key, base64
  • Services: authentication, confidentiality, compression, compatibility, segmentation
  • Keys: key rings, web of trust; S/MIME

SSL and TLS PIN 3/27

  • Position: between TCP and application; HTTPS port 443
  • Protocols: handshake, change cipher spec, alert, record
  • Handshake: hellos, certificate, pre-master secret, master secret, finished
  • Record: fragment, compress, MAC, encrypt, header
  • Versions: SSL 2.0, 3.0; TLS 1.0, 1.1, 1.2, 1.3 (2018)

IPsec PIN 3/27

  • AH: protocol 51, authentication, integrity, no encryption
  • ESP: protocol 50, encryption plus authentication
  • Modes: transport host to host; tunnel gateway to gateway
  • SA: SPI, destination, protocol; SAD, SPD, IKE

VPN HOT 5/27

  • Idea: encrypted tunnel across the Internet
  • Types: remote access; site to site, intranet, extranet
  • Protocols: IPsec, SSL/TLS, OpenVPN, L2TP, WireGuard, PPTP old
  • Example: Kathmandu and Pokhara offices

WEP PIN 2/27

  • Design: RC4, 24-bit IV, 40 or 104-bit key, CRC-32 ICV
  • Weaknesses: IV reuse, weak keys (FMS), linear CRC, static key
  • Successors: WPA TKIP, WPA2 AES-CCMP, WPA3 SAE

Firewalls and ACLs TOP 13/27

  • Types: packet filter, stateful, application gateway, circuit-level, NGFW
  • Packet filter: header, rules top down, first match, implicit deny
  • Protection: choke point, filtering, NAT, proxy, DMZ, logs
  • ACL lines: deny 202.70.91.0 0.0.0.255, permit any, ip access-group in
  • ACL types: standard 1 to 99 source; extended 100 to 199

Intrusion detection PIN 1/27

  • Where: NIDS, HIDS
  • How: signature, anomaly
  • Related: IPS inline, SIEM, false positive, false negative
  • Examples: Snort, Suricata, Zeek, OSSEC, Tripwire

8 chapters · 127 topics · about 65100 words

Compact chapters

Each chapter with every definition, step, formula and example kept and the teaching prose taken out. The copy button on a chapter copies all of it, formulas as LaTeX, ready to paste into Claude as context before you ask about it.

Chapter 1: Introduction to computer network 10950 words

What a computer network is, and what it is used for

PIN 4/27 Open the full card

Computer network: a collection of autonomous computers and other devices (nodes) interconnected by communication links and following common protocols, so that they can exchange data and share resources. Links may be copper wire, optical fibre, radio, microwave, infrared or satellite.

Autonomous is the key word (Tanenbaum): each computer can work alone; the network only lets them talk. A mainframe with dumb terminals is not a network in this sense. Two computers are interconnected when they can exchange information.

Four parts of every network:

  • Nodes: end systems (hosts: laptops, phones, servers) and intermediate devices (switches, routers, access points).
  • Links: transmission media: twisted pair, coaxial cable, optical fibre, radio.
  • Protocols: the rules both ends follow.
  • Services: what users get: the web, mail, file sharing, voice and video calls.

Three criteria judge a network: performance (throughput, delay), reliability (how often it fails, how fast it recovers), security (protection against unauthorised access and damage).

WhoUseWhat the network makes possible
BusinessResource sharingmany PCs share one printer, scanner, database or internet line, wherever they are
BusinessHigh reliabilityfiles replicated on two or more machines; if one fails another copy is used
BusinessSaving moneycheap PCs as clients of a few servers replace one costly mainframe
BusinessScalabilityadd a server or PC as load grows instead of replacing the system
BusinessCommunication, e-commerceemail, video meetings, orders placed electronically
HomeRemote informationthe web, news, online banking, exam results
HomePerson to person communicationchat, voice and video calls, cheaper and faster than phone calls
HomeInteractive entertainmentvideo on demand, multiplayer games, social networking
HomeE-commerce, online educationpaying bills, sending money, shopping; online classes, notes, assignments
Mobile usersAnywhere accessphones and laptops on Wi-Fi or 4G: mail, web, maps, remote files, remote login
SocietyPublic services, new problemse-government; also privacy loss, misinformation, phishing fraud, copyright disputes

Five instances of networks in a student's day (2072 Chaitra asks exactly this):

  1. Paying by phone: fonepay QR at the canteen, eSewa or Khalti wallet: the app is a client of the bank's server over mobile data.
  2. Calling family: WhatsApp or Viber video call to a relative abroad, as IP packets (VoIP), for the price of data instead of an international call.
  3. Studying: online classes, notes in the class group, exam results on the exam board's website.
  4. Entertainment: YouTube streamed on demand; online multiplayer games whose moves must arrive within milliseconds.
  5. Daily services: a Pathao or inDrive ride (GPS position over mobile data); paying the NEA electricity bill online.

Memory example: a hostel kitchen: every student can cook alone (autonomous), but sharing one gas cylinder and fridge (resources) needs agreed rules (protocols); the hostel Wi-Fi shares one ISP fibre line among all rooms.

Networks by size and geography: PAN, LAN, MAN and WAN

PIN 1/27 Open the full card

Types of network by size: classified by the area covered: PAN around one person, LAN in a room, building or campus, MAN across a city, WAN across a country or continent; networks joined by routers form an internetwork, the Internet being the largest.

Distance decides the owner, speed, delay and error rate: a LAN is privately cabled, fast, nearly error free; a WAN uses links leased from carriers, costs more per bit and adds delay.

TypeSpanOwnerSpeed and delayTechnologyExample
PANabout 1 to 10 mone personlow data rate, tiny delayBluetooth, USB, NFCearbuds and smartwatch paired with a phone
LANroom, building or campus, up to a few kmone organisation (private)100 Mbps to 10 Gbps and more; very low delay and error rateEthernet (IEEE 802.3), Wi-Fi (IEEE 802.11)college lab, hostel Wi-Fi
MANa city, roughly 10 to 50 kmISP, cable operator, city bodyhigh, usually fibrefibre rings, Metro Ethernet, cable TV networks, WiMAX (IEEE 802.16)an ISP's fibre ring across the Kathmandu valley
WANcountry or continent, hundreds to thousands of kmtelecom carriers; users lease capacitylower speed for the money, higher delayleased lines, X.25, Frame Relay, ATM, MPLS, satellitea bank joining its head office and branches all over Nepal
Internetworkworldwidemany ownersvariesrouters joining unlike networks, TCP/IPthe Internet

WAN structure: hosts joined through a communication subnet of switching elements (routers) and transmission lines; packets travel store and forward (each router stores a whole packet, then forwards it). Hosts belong to users; the subnet usually to a carrier or ISP.

Other classifications:

  • By transmission technology: broadcast (one shared channel all machines hear: classic Ethernet, Wi-Fi; an address says whom a frame is for) or point-to-point (pairs of machines; a packet may cross intermediate nodes: most WANs).
  • By architecture and shape: client/server or peer to peer; bus, star, ring, mesh.

Memory example: one video call outwards: earbuds and phone (PAN), hostel Wi-Fi (LAN), ISP fibre ring across the valley (MAN), links across the border (WAN), all together (the Internet).

The 2070 Ashad question says "types of network topologies based on its size and geographical distributions": size and geography classify networks, so answer PAN, LAN, MAN, WAN (and internetwork); bus, star, ring belong to its first part.

Network topologies: bus, star, ring, mesh, tree and hybrid

PIN 1/27 Open the full card

Network topology: the arrangement of nodes and links. Physical topology: the actual layout of devices and cables. Logical topology: the path signals or data actually follow. They can differ: an Ethernet hub is a physical star but a logical bus (it repeats every frame out of every port); Token Ring is wired as a star into a central access unit but the token travels as a ring.

Figure: six sketches: bus with terminators, star round a switch, ring with one-way flow, five-node full mesh, tree under a root, hybrid star joined to a ring by a backbone

TopologyHow it is builtMeritsDemeritsExample
Busone backbone cable; drop lines; terminator at each end stops reflectionsleast cable, cheap, easy to add a nodebackbone break stops all; collisions; faults hard to find; limited length and nodesearly coaxial Ethernet (10BASE5, 10BASE2)
Stareach node has its own link to a central hub or switcha cut link loses one node; easy to add, remove, troubleshootcentral device is a single point of failure; more cable than busswitched Ethernet LAN, home Wi-Fi router
Ringeach node joined to the next, last to first; data one way round, each node repeats itno collisions (token gives turns); equal access; predictable delayone break or dead node stops it (dual ring, as FDDI, survives one); adding a node breaks the ringIEEE 802.5 Token Ring, FDDI
Meshevery node joined to every other by a dedicated linkrobust, no single point of failure; no shared traffic; private; easy fault isolationcables and ports grow with the square of n: costly, bulkycore router links (partial mesh)
Treestars in a hierarchy below a root (star of stars)grows easily; a branch can be isolatedroot or backbone failure cuts off branchescampus: core, building, floor switches
Hybridtwo or more topologies joinedeach part uses what suits itcomplex to design and managebuildings on a fibre ring, each a star

Full mesh of n nodes: one link per pair, n−1 ports a node:

L=n(n−1)2

Example: six office PCs: mesh 6×5/2=15 cables and 5 ports a PC; star 6 cables and one 8-port switch; bus one cable with six taps. So LANs are stars, and only core routers are (partially) meshed.

Memory example: village water: bus = one pipe along the road with every house tapped (cut it and the lane is dry); star = a tank with a pipe to each house; ring = a loop main; mesh = a pipe from every house to every other.

Client/server and peer to peer: the two networking models

TOP 10/27 Open the full card

Networking model: how work and resources are divided among the computers. Client/server: dedicated servers provide services, clients request them. Peer to peer (P2P): every computer is an equal peer, both client and server, sharing resources directly.

Figure: left, one server above three clients (laptop browser, phone app, ATM terminal) with request arrows up and reply arrows down; right, four peers fully interconnected

Client/server architecture: each computer or process is a client or a server. A server is a powerful, always-on machine or process holding data and programs (web, mail, file, database, print server); clients are users' machines asking for services. Every exchange involves two processes, one on each machine.

How it works (request and reply):

  1. Server waits: the server process starts first and listens on a known address and port (web server: 80 or 443).
  2. Client requests: the client process sends a request message and waits.
  3. Server processes: reads a file, queries a database, checks a password.
  4. Server replies: sends the reply message back.
  5. Client uses the reply: shows the result; the server goes on serving others.

Example: browser (client) and web server.

Features of the client/server architecture:

  • Asymmetric roles: clients start every exchange, servers only respond; many clients to one server.
  • Centralised resources and data: one up-to-date copy on the server.
  • Centralised administration and security: accounts, access rights, backups, updates in one place.
  • Dedicated, powerful server: server hardware, network OS (Windows Server, Linux), always on.
  • Scalability: clients added freely; capacity grows by upgrading or adding servers.
  • Location transparency: the client needs only the server's name or address.
  • Tiers: two-tier (client, database server) or three-tier (client, application server, database server), as in online banking.

Peer to peer: a P2P network forms when two or more PCs or devices connect and share resources without a separate server; each peer has equivalent capabilities and responsibilities, stores data on its own disk and shares it, so it is client and server at once.

P2P process (file sharing):

  1. Join: contact known peers, a tracker or a bootstrap node; in a small workgroup, announce itself on the LAN.
  2. Search: flood a query to neighbours, ask an index (hybrid P2P) or look up a distributed hash table.
  3. Connect directly to the peers holding the resource.
  4. Exchange: download pieces from many peers at once, upload pieces it has.
  5. Leave: its resources leave with it; the rest carry on.

Kinds: pure P2P (no central element: Gnutella), hybrid (central index or tracker only finds peers: Napster, BitTorrent with a tracker), the small office or home workgroup.

Examples: BitTorrent (file cut into pieces, every downloader also uploads); Windows workgroup of four PCs sharing folders and a printer; SHAREit and Nearby Share (direct Wi-Fi between phones); Bitcoin and other blockchains (every node keeps a copy of the ledger).

BasisClient/serverPeer to peer
Rolesfixed: servers serve, clients requestevery peer both
Central serverone or more dedicated serversnone (at most an index or tracker)
Datacentral, on the serverspread over peers' disks
Administration, securitycentral, strongeach user, weak and uneven
Backupcentral, simplemachine by machine, often skipped
Costhigh: server hardware, server OS, administratorlow: ordinary PCs
Scalabilitylimited by the serverself-scaling: each peer adds capacity and demand
Reliabilityserver is a single point of failurenone, but a peer that leaves takes its files
Performancefast and predictable until the server is the bottleneckdepends on peers; a popular file gets faster
Suited tolarge networks: banks, web, mail, online servicessmall networks (about ten PCs), file sharing
Examplebrowser and web server; ATM and bank serverBitTorrent; home workgroup
ModelAdvantagesDisadvantages
Client/servercentral control of data, users, security; easy backup and recovery; one consistent copy; grows by adding servers; cheap clientscostly server, software and administrator; single point of failure; bottleneck when overloaded; traffic piles up at the server
Peer to peercheap; easy setup; no single point of failure; capacity grows as peers joinweak security, no central control or backup; data scattered and duplicated; a peer that is off takes its files; slow when shared PCs are busy

Memory example: client/server is a restaurant (customers order, one kitchen cooks, kitchen closed means nobody eats); P2P is a class picnic where every friend brings a dish (more friends, more food, nobody in charge).

Active networking, compared with the traditional legacy network

PIN 1/27 Open the full card

Active network: a network whose nodes are programmable: besides carrying bits, routers and switches compute on the data flowing through them, running code supplied by users or by the packets themselves.

Legacy network is passive: a router stores and forwards (reads the header, looks up the route, sends the packet on) without touching the payload; functions fixed by the vendor; a new service (new multicast or QoS scheme) needs years of standardisation and a firmware upgrade of every router. Active networking (Tennenhouse and Wetherall, MIT, mid 1990s, funded by DARPA) puts new services into the network as programs.

Two approaches:

  • Discrete (programmable switch): programs loaded into nodes beforehand, out of band, by an operator or authorised user; packets carry a header naming the program.
  • Integrated (capsule): every packet (capsule) carries a small program and data; each node executes it, deciding the capsule's fate. MIT's ANTS toolkit worked this way.

Framework of an active node (DARPA active network architecture):

  1. NodeOS: node operating system; owns the resources (links, called channels; processor time; memory; storage), shares them among EEs, enforces security and isolation.
  2. Execution environments (EEs): like a virtual machine or interpreter (Java VM) running active code; several per node; a management EE lets the operator control the node.
  3. Active applications (AAs): user programs inside an EE giving a flow its custom service.

An arriving packet is matched to its EE by the ANEP header (Active Network Encapsulation Protocol), processed, and leaves forwarded, merged, shrunk, copied or dropped.

Figure: a legacy router (read header, look up route, forward; data never touched) beside an active node (AAs on EEs on NodeOS on hardware; a capsule with ANEP header, code and data goes up to its EE)

PointLegacy (passive) networkActive network
Node's jobstore and forward by headerforward and compute on contents
Processingsame for every packetcustomised per user, flow or packet
Programmed bythe vendor, in firmwareusers and applications, by injecting code
New serviceyears: standardise, upgrade every routerdays: load the program or send it in capsules
Packetheader and datacapsule: code and data (or a header naming a loaded program)
Intelligenceend systems only (end to end principle)end systems and inside the network
Data and algorithmsfixedmutable and fluid
Security, performancesimpler; fast hardware forwardingharder: foreign code must be isolated; running it costs time

Uses: shrink a video stream at the node nearest a slow link; cache content in the network; merge sensor readings on the way; deploy new multicast or congestion control without a standard; push firewall rules to the right node during an attack; network management by mobile agents.

Few active networks were deployed (security and performance problems of running others' code in routers); the programmable network idea lives on in SDN (a central controller programs switches) and programmable switch hardware.

The book says an active network "can be at least as secure as the legacy network" and "has faster hardware": read both as design goals; security was its hardest problem and executing code costs time.

Memory example: legacy network = postal service reading only the address; active network = a courier who obeys a note on the parcel ("if the village road is slow, send only the small photos").

Protocols, standards and interfaces

HOT 5/27 Open the full card

Protocol: a set of rules governing communication between two or more entities: the format and order of messages, their meaning, and the actions on sending or receiving; an agreement on how a link or conversation is established, maintained and released. Without one, the bits arrive but mean nothing.

Three key elements:

  • Syntax: structure or format of the data (in an IPv4 header the first 4 bits are the version, the next 4 the header length).
  • Semantics: meaning of each field and the action it calls for ("data" or "error, resend").
  • Timing: when data may be sent and how fast: speed matching, sequencing, timeouts (a 100 Mbps sender swamps a 1 Mbps receiver unless the protocol prevents it).

The book: a protocol explains how the physical network is built, how computers connect, how data is formatted, how it is sent, how errors are handled.

ProtocolLayerWhat it does
HTTP, HTTPSapplicationfetches web pages
SMTP, POP3, IMAPapplicationsends and reads email
DNSapplicationnames to IP addresses
TCPtransportreliable ordered byte stream between processes
UDPtransportfast connectionless datagrams
IPnetwork (internet)addresses and routes packets between networks
Ethernet (802.3), Wi-Fi (802.11)data link, physicalframes over one link

Human protocol: a phone call opens with "Hello" or "Namaste", turns are taken, a missed word gets "Hajur?" (resend), an agreed goodbye closes it: opening, turn taking, error recovery, release.

Standards: agreed published specifications letting different vendors' equipment work together. De jure: set by an official body. De facto: won in practice before or without approval (TCP/IP grew this way).

BodyFull nameKnown for
ISOInternational Organization for StandardizationOSI reference model (ISO 7498)
ITU-TInternational Telecommunication Union, Telecommunication Standardization Sector (CCITT until 1993)X.25, V series modems, ISDN, ADSL (G.992)
IEEEInstitute of Electrical and Electronics Engineers802 LAN standards: 802.3 Ethernet, 802.11 Wi-Fi
IETFInternet Engineering Task ForceInternet protocols as RFCs: IP (RFC 791), TCP (RFC 9293)
ANSIAmerican National Standards InstituteUS standards, US member of ISO; FDDI
EIA (standards now with TIA)Electronic Industries AllianceEIA-232 (RS-232) serial interface

Forums (Frame Relay Forum, ATM Forum) sped up standards; regulators license airwaves and telecom services (Nepal: Nepal Telecommunications Authority, NTA).

Protocol, service, interface:

  • Protocol: horizontal: rules between peers (same layer, two machines).
  • Service: vertical: what a layer offers the layer above, as primitive operations.
  • Interface: boundary between adjacent layers on one machine; tells the upper layer how to reach the lower layer's services (operations, parameters, results).
  • Protocol stack: list of protocols a system uses, one per layer.

Analogy: post office counter = interface; "registered delivery" = service; rules among post offices = protocol; the counter can stay while the rules change.

The book says ISO is the "International Standards Organization" and IEEE the "Institute of Electrical and Electrical Engineer"; the official names are International Organization for Standardization and Institute of Electrical and Electronics Engineers; CCITT is ITU-T since 1993.

Layered architecture: why network software is a hierarchy of layers

TOP 9/27 Open the full card

Layered architecture: network software as a stack of layers, each built on the one below, each offering services to the layer above while hiding how they are done; layer n on one machine talks to layer n on another by the layer n protocol.

Why: communication across different cables, radios, routers and operating systems is too big for one piece of design; layering splits it (bits on a wire, a reliable link, a route, a reliable path for programs...), each layer using only the services below.

Reasons for layering (asked in nine sittings):

  1. Reduces design complexity: small understandable parts, designed, built and tested separately.
  2. Modularity and independence: a layer changes without touching others if its service and interface stay the same (Wi-Fi to Ethernet cable, the browser never notices).
  3. Standardisation and interoperability: defined jobs and protocols per layer let vendors' products work together.
  4. Easier troubleshooting: faults located layer by layer (cable, link, route, port).
  5. Specialisation and reuse: teams per layer; one layer serves many users (IP carries every application over every link).
  6. Flexibility: new technology at one layer (fibre for copper, 5G for 4G).

Price: header overhead at every layer; repeated functions (error control at data link and transport); strict layering can cost performance.

Protocol hierarchy: networks are a series of layers; their number, names, contents and functions differ from network to network. Entities in corresponding layers on different machines are peers and talk by the layer's protocol, but no data goes directly from layer n to layer n: each layer passes data and control down until the physical medium carries it. Peer communication is virtual; only the medium carries real signals. Between adjacent layers is an interface defining the primitive operations and services offered upward.

Figure: five-layer source and destination machines; M, then H4 M, then H3 H4 M1 and H3 M2, then H2 H3 H4 M1 T2 and H2 H3 M2 T2, then bits on the medium; dashed peer arrows labelled layer 5 to layer 2 protocol

Information flow (Tanenbaum's five-layer example, in the book):

  1. Layer 5 produces message M and passes it to layer 4.
  2. Layer 4 adds header H4 (control information such as sequence numbers so the receiving layer 4 delivers pieces in order).
  3. Layer 3 has a packet size limit: splits M into M1 and M2, puts header H3 (addresses for routers) on each.
  4. Layer 2 adds header H2 and trailer T2 to each piece.
  5. Layer 1 transmits the bits; at the destination each layer removes its own header (and trailer) and passes the rest up; no lower header reaches layer n.

Network architecture: the set of layers and protocols; its specification gives an implementer enough detail to build each layer so it obeys the protocol; implementation details and internal interfaces are not part of it. TCP/IP and IBM's SNA are architectures; the OSI model alone is not (it names no protocols).

Design issues for the layers:

IssueProblemAnswer
Addressingmany machines, each with many processes: whom is the data for?MAC (data link), IP (network), port (transport) addresses
Direction of data transferone way, either way in turn, both at once; how many logical channels?simplex, half duplex, full duplex; separate data and control channels
Error controlphysical circuits are imperfectdetecting or correcting codes; acknowledgements
Ordering (sequencing)some channels reorder messagesnumber pieces, reorder at receiver
Flow controlfast sender swamps slow receiverreceiver feedback, windows, agreed rates
Segmentation (message size)processes or links cannot take arbitrarily long (or short) messagesbreak up and reassemble; gather small ones
Multiplexinga connection per pair of processes is costlymany conversations share one channel, separated at the far end
Routingseveral paths from source to destinationchoose the best route (network layer)

Later texts group these as reliability, resource allocation (congestion, QoS), evolution and security.

Memory example: momo delivery: order in the app (application), box packed with a slip naming the buyer (transport), rider's app picks the route to Pulchowk (network), the rider rides segment by segment (data link), on the road (physical); bike or scooter, the restaurant does not care.

The book's step 4 says layer 2 adds a header and trailer to each packet "obtained from layer 2": the packets come from layer 3.

Services: connection-oriented and connectionless, and the service primitives

PIN 1/27 Open the full card

Service: the operations (primitives) a layer offers the layer above. Connection-oriented: set up, use, release, like a telephone call; bits come out in order like a tube; parameters (maximum message size, QoS) may be negotiated at setup; TCP, X.25 virtual circuits. Connectionless: each message (datagram) carries the full destination address and is routed independently, possibly out of order, like the post; UDP, IP.

ServiceKindExample
Reliable message streamconnection-orientedsequence of pages
Reliable byte streamconnection-orientedmovie download, remote login
Unreliable connectionconnection-orienteddigitised voice
Unreliable datagramconnectionlesselectronic junk mail
Acknowledged datagramconnectionlessregistered mail
Request and replyconnectionlessdatabase query

Reliable = receiver acknowledges every message; acknowledgements cost delay, so voice and video often prefer unreliable service.

Service primitives: operations a user process calls to use a service (usually system calls). Five for a simple connection-oriented service:

PrimitiveMeaning
LISTENblock waiting for an incoming connection
CONNECTestablish a connection with a waiting peer
RECEIVEblock waiting for an incoming message
SENDsend a message to the peer
DISCONNECTterminate the connection

Client and server use (six packets):

  1. Server calls LISTEN, blocks.
  2. Client calls CONNECT: connection request packet (1); client suspended.
  3. Server OS unblocks the server, sends an acceptance (2); connection up.
  4. Server calls RECEIVE for the first request.
  5. Client SENDs the request (3), then RECEIVEs; server processes and SENDs the reply (4).
  6. Client DISCONNECTs (5); server answers DISCONNECT (6); released.

Later editions of Tanenbaum add a sixth primitive, ACCEPT, for step 3. Berkeley sockets: listen(), connect(), accept(), send(), recv(), close().

OSI primitive classes: request (user asks, as CONNECT.request), indication (peer told of the event), response (peer answers), confirm (first user told the result); confirmed service uses all four, unconfirmed only request and indication.

Service against protocol: service = what a layer does for the layer above (vertical; the operations, not how); protocol = rules peers on different machines use to implement it (horizontal; format and meaning of packets). The protocol can change while the service stays, like rewriting a function's code without changing its calls.

Memory example: phone call = connection-oriented (dial, talk, hang up; words in order); letter = connectionless (full address on each envelope; two letters may arrive on different days).

The OSI reference model: seven layers and what each does

HOT 8/27 Open the full card

OSI reference model: ISO's seven-layer framework (ISO 7498, 1984) for communication between open systems (systems open to communication with others, whatever the vendor), physical at the bottom to application at the top; a reference model saying what each layer should do, not which protocols. Work began 1977; published 1984. Not a network architecture (no exact services or protocols specified); ISO's OSI protocols never caught on, the model survived as the vocabulary of networking.

Tanenbaum's five principles: a layer where a different abstraction is needed; a well-defined function per layer; functions chosen with international standard protocols in mind; boundaries that minimise information flow across interfaces; enough layers to keep distinct functions apart, few enough not to be unwieldy.

Figure: hosts A and B with seven layers each, dashed end to end peer protocols for layers 7 to 4, and two routers in the communication subnet with only layers 3 to 1, hop by hop; units APDU, PPDU, SPDU, TPDU, packet, frame, bit

Two groups: layers 1 to 3 (physical, data link, network) are network support layers, working hop by hop (host to router, router to router), run by every router; layers 5 to 7 are user support; transport joins them, and from transport up layers work end to end, only in the two hosts. The book: top three define how applications communicate; bottom four define how data travels end to end.

LayerMain functionsUnitExample protocols and devices
7 Applicationwindow to the network for users and programs: file transfer and access, mail, directory services, remote login, network virtual terminalmessage (APDU)HTTP, FTP, SMTP, POP3, IMAP, DNS, Telnet, SSH, SNMP, DHCP
6 Presentationsyntax and semantics: code translation (ASCII, EBCDIC, Unicode) and machine formats; encryption, decryption; compressionPPDUTLS encryption, JPEG, MPEG, ASN.1 with BER, XDR, MIME
5 Sessiondialog control (who talks when; half or full duplex; token management); synchronisation by checkpoints (resume after a crash); open, maintain, close sessionsSPDUNetBIOS, RPC, OSI session protocol (ISO 8327)
4 Transportprocess to process delivery of the whole message: port addressing; segmentation and reassembly with sequence numbers; connection control; end to end flow and error control; multiplexingsegment (TPDU)TCP, UDP, SCTP
3 Networksource to destination delivery across networks: logical (IP) addressing, routing and forwarding, fragmentation, congestion control, internetworkingpacketIP (v4, v6), ICMP, IPsec, X.25 packet layer; router
2 Data linknode to node delivery of frames: framing, physical (MAC) addressing, error control (CRC, retransmission), flow control, medium access control; sublayers LLC and MACframeEthernet (802.3), Wi-Fi (802.11), HDLC, PPP, Frame Relay; switch, bridge, NIC
1 Physicalraw bits over the medium: mechanical and electrical specs (connectors, pins, voltage for 0 and 1), bit timing, data rate, encoding, modulation, bit synchronisation, line configuration, topology, transmission modebitRS-232, V.35, 10BASE-T, 1000BASE-T, DSL, SONET/SDH; hub, repeater, modem, cable

Which layer does it:

TaskLayerReason
Timing and voltage of the received signalPhysicalvoltage levels, bit duration, bit synchronisation
Data framingData linkgroups bits into frames with header and trailer
Physical identification (MAC address)Data linkMAC addresses in the frame header
Error detection and correctionData linkCRC on every link (transport also checks end to end)
Access to a shared channelData link (MAC sublayer)decides who transmits
Logical identification (IP address)NetworkIP addresses identify hosts across networks
RoutingNetworkrouters forward by destination address
Point to point connection of socketsTransportsocket = IP address + port; transport joins two ports end to end
Segmentation, port addressingTransportnumbers segments, delivers to the right process
Dialog control, synchronisationSessionwho talks when, where to resume
Encryption, compression, code translationPresentationrepresentation of data
File transfer, email, remote loginApplicationservices to users

Significance of OSI: common vocabulary ("layer 2 switch", "layer 3 problem"); separates services, interfaces, protocols so a layer can change alone; reference for designing and comparing stacks and for multi-vendor interoperability; layer by layer troubleshooting; the standard way networking is taught.

Example, one web request from hostel Wi-Fi: HTTP request (application); TLS encryption, UTF-8 text (presentation); logged-in session kept (session); TCP segments to port 443, lost ones resent (transport); IP packets with the server's address, routed through the ISP (network); Wi-Fi frames with laptop and access point MAC addresses and CRC (data link); radio at 2.4 or 5 GHz (physical).

The book says ISO developed the model "in 1977": that is when work began; ISO 7498 was published in 1984.

The TCP/IP model: four layers and their protocols

PIN 4/27 Open the full card

TCP/IP model: the layered model of the Internet protocol suite, named after TCP and IP; four layers: host-to-network (network access), internet, transport, application; many texts split the lowest into data link and physical (five layers).

Origin: the ARPANET, funded by the US DoD's Advanced Research Projects Agency (ARPA); Cerf and Kahn described TCP in 1974; the ARPANET switched to TCP/IP on 1 January 1983. Goals: interconnect many different networks with universal services; connections survive the loss of intermediate routers and lines while the ends work; carry applications from file transfer to real-time speech. Protocols came first, the model was written later.

Figure: the four layers as an hourglass: application protocols on top, TCP and UDP, IP alone at the narrow waist with ICMP, IGMP, ARP, and many link technologies below

  1. Host-to-network (network access, link): the original model only says the host connects with some protocol so it can send IP packets; in practice framing, MAC addressing, bits on the medium (OSI data link + physical). Ethernet (802.3), Wi-Fi (802.11), PPP, DSL, Frame Relay, ATM.
  2. Internet: the linchpin; hosts inject packets into any network, packets travel independently, possibly by different routes and out of order (connectionless, best effort, like letters); defines the packet format and protocol IP; logical addressing and routing. IP (IPv4 RFC 791, IPv6 RFC 8200), ICMP (errors, control), IGMP (multicast groups), ARP (MAC lookup, at the boundary with the layer below).
  3. Transport: peer processes on the two hosts converse, as in OSI; segments and reassembles; ports name processes. TCP: reliable, connection-oriented byte stream, error free, in order, flow control (web, mail, file transfer). UDP: unreliable, connectionless, no sequencing or flow control, prompt delivery (DNS lookups, voice and video calls, games).
  4. Application: all higher-level protocols; no session or presentation layer (applications do that themselves). HTTP and HTTPS, SMTP, POP3, IMAP, FTP, DNS, DHCP, SNMP, Telnet, SSH.
LayerProtocols (well known ports)Unit
ApplicationHTTP 80, HTTPS 443, FTP 20 and 21, SSH 22, Telnet 23, SMTP 25, DNS 53, DHCP 67 and 68, POP3 110, IMAP 143, SNMP 161message
TransportTCP, UDP (SCTP)segment (TCP), datagram (UDP)
InternetIPv4, IPv6, ICMP, IGMP, ARP, RARP, IPsecpacket (IP datagram)
Host-to-networkEthernet, Wi-Fi, PPP, DSL, Frame Relay, ATMframe, bits

Hourglass: many applications over two transport protocols over one internet protocol over every kind of link; IP is the narrow waist: anything carrying IP joins the Internet; any IP application runs over any link (same browser on hostel Wi-Fi, home fibre, 4G).

Four or five layers: Tanenbaum's TCP/IP model and the book use four; Kurose and Ross, and Tanenbaum's hybrid teaching model, use five (application, transport, network, data link, physical); state which one is drawn.

Memory example: a Messenger video call: app (application) to UDP (transport) to IP with the server's address (internet) to Wi-Fi frames and the ISP's fibre (host-to-network): four handovers.

The book calls UDP "an unreliable connection protocol": it is unreliable and connectionless. It expands ARPANET as "Advanced Research Project Agency": ARPA (Advanced Research Projects Agency) was the agency, ARPANET its network.

Data encapsulation: how headers and trailers are added and removed

PIN 3/27 Open the full card

Data encapsulation: each layer at the sender wraps the data from the layer above with its own control information, a header (and at the data link layer a trailer), forming its PDU. Decapsulation: the reverse at the receiver; each layer reads and removes its own header and trailer.

Header: control information in front of the data: addresses (MAC, IP, port), sequence and acknowledgement numbers, length, type, time to live, checksum. Trailer: after the data: the data link layer's FCS (frame check sequence, a CRC over the frame), sometimes an end marker; at the end because the CRC is computed while the frame is sent and appended last.

SDU and PDU: what a layer receives from above is its service data unit; SDU plus the layer's header (and trailer) is its protocol data unit, which is the SDU of the layer below.

Figure: sender going down (Data; TCP header + data = segment; IP header + segment = packet; frame header + packet + FCS = frame; bits) and the receiver going up removing them

Sender, five steps (the book's OSI count):

  1. Data: application, presentation and session layers create data from user input.
  2. Segment: transport adds a TCP or UDP header (source and destination ports, sequence number, checksum).
  3. Packet: network adds an IP header (source and destination IP addresses, time to live, protocol number).
  4. Frame: data link adds a frame header (destination and source MAC addresses, type) and the trailer (FCS).
  5. Bits: physical sends the frame as electrical, light or radio signals.

Receiver: physical turns signals into bits; data link checks the FCS (bad frame discarded), checks the destination MAC, strips header and trailer; network checks the destination IP, removes the IP header; transport uses the port to find the process, orders segments, removes its header; the application gets the original data. Each layer reads only its peer's header (headers are how peers talk).

At a router: decapsulated only up to the network layer; IP header read, next hop chosen, packet wrapped in a new frame with new MAC addresses. IP addresses stay end to end; MAC addresses change every hop.

Example: 1460-byte file chunks over Ethernet: TCP 20 bytes + IP 20 bytes = 1500 (Ethernet's maximum packet), + 14-byte Ethernet header + 4-byte FCS = 1518-byte frame; 1460/1518=96.2% is file data.

Memory example: posting a letter: letter (data), envelope with the friend's name (transport), bag tagged with the district (network), truck with a trip sheet in front and a seal behind checked on arrival (data link header and trailer), the road (physical); each office opens only its own wrapping.

OSI and TCP/IP compared: similarities and differences

TOP 9/27 Open the full card

OSI against TCP/IP: OSI is a seven-layer reference model defined by ISO before its protocols existed; TCP/IP is the four-layer model of the protocols the Internet uses, described after they were built; both are layered with an end to end transport layer.

Figure: the OSI layers 7 to 1 (with OSI protocols FTAM, X.400, X.500; ISO 8823, ASN.1; ISO 8327; TP0 to TP4 (ISO 8073); CLNP, X.25 packet layer; HDLC, LAPB, LLC; X.21, RS-232, V.35) mapped by dashed lines to TCP/IP application (7, 6, 5), transport (4), internet (3), host-to-network (2, 1), with TCP/IP protocols HTTP, HTTPS, FTP, SMTP, POP3, IMAP, DNS, DHCP, SNMP, SSH, Telnet; TCP, UDP; IP, ICMP, IGMP, ARP; Ethernet, Wi-Fi, PPP, DSL, Frame Relay

Mapping: TCP/IP application = OSI application + presentation + session; transport = transport; internet = network; host-to-network = data link + physical.

Similarities:

  1. Both layered: stacks of independent protocols, each layer serving the one above, peers talking by protocols.
  2. Both have an end to end transport layer: layers up to transport give processes an end to end, network-independent transport service.
  3. Both have an application layer on top.
  4. Both have a network (internet) layer routing between networks; both use packet switching.
  5. Both use encapsulation.
  6. Both describe real networks; their layer numbers are the engineers' everyday language.
BasisOSI modelTCP/IP model
Stands forOpen Systems InterconnectionTransmission Control Protocol / Internet Protocol
Developed byISO (ISO 7498, 1984)US DoD's ARPA for the ARPANET, 1970s; maintained by the IETF
Layers74 (5 when the lowest is split)
How mademodel first, protocols later: generalprotocols first, model later: fits only its own protocols
Service, interface, protocolclearly distinguished (central idea)not clearly distinguished
Network layer serviceconnection-oriented and connectionlessconnectionless only (IP)
Transport layer serviceconnection-oriented onlyboth: TCP connection-oriented, UDP connectionless
Session, presentationseparate layersnone: left to the application
Data link, physicalseparate layersone host-to-network layer, barely specified
Replacing protocolswell hidden, replaceablenot easily replaced
Internetworkingnot considered at first (one network per country expected)main goal from the start
Use todayreference and teaching model; own protocols hardly usedthe protocol suite the Internet runs on

Why OSI's protocols lost (Tanenbaum): bad timing (arrived when TCP/IP was spreading free with Berkeley UNIX); bad technology (session and presentation nearly empty, data link and network overfull; addressing, flow and error control repeated in several layers; huge complex standards); bad implementations (large, slow, unwieldy); bad politics (seen as pushed by European telecom ministries and governments).

TCP/IP's weaknesses: service, interface and protocol not clearly separated; not general (cannot describe other stacks); host-to-network is an interface rather than a layer and does not separate physical from data link; ad hoc early protocols (Telnet) became entrenched. Modern habit: OSI model to talk about networks, TCP/IP protocols to build them.

Memory example: OSI = a syllabus a committee wrote before any class (complete, tidy, never followed to the letter); TCP/IP = the seniors' notes written after passing (shorter, messier, what everyone uses).

The book's table says internetworking "is not supported" in OSI: Tanenbaum's point is that the OSI committee did not think of internetworking at first (one network per country), and an internetworking sublayer was added to its network layer later; TCP/IP was designed for internetworking.

The Internet: a network of networks

Open the full card

The Internet: the worldwide network of networks interconnecting billions of devices with the TCP/IP protocol suite; nobody owns it; thousands of independently run networks agree to exchange traffic using common protocols.

History:

  • 1969, ARPANET: four US nodes (UCLA, SRI, UC Santa Barbara, University of Utah), funded by ARPA; the first large packet switched network.
  • 1974 to 1983, TCP/IP: Cerf and Kahn's internetworking protocol; the ARPANET adopted it on 1 January 1983.
  • 1986 to 1995, NSFNET: the US National Science Foundation backbone joined universities; retired in 1995 as commercial ISPs took over.
  • 1989 to 1991, the World Wide Web: Tim Berners-Lee at CERN (HTTP, HTML, URLs) brought the Internet to the public.

Structure: end systems (hosts); access networks (DSL, cable, fibre to the home, Wi-Fi, 4G, 5G); ISPs in tiers (local access ISPs buy transit from national and international ISPs, which connect to global tier 1 backbones; similar ISPs peer free); internet exchange points (IXPs) where many ISPs swap traffic directly (the Nepal Internet Exchange, NPIX, in Kathmandu keeps Nepali traffic local instead of going abroad and back); content providers' own networks with caches inside ISPs.

Governance: no central government; each network sets its own policy; only the name spaces are coordinated: IP addresses (IANA under ICANN to five regional registries; APNIC serves the Asia Pacific, Nepal included) and the DNS root (ICANN), under which .np is Nepal's country code domain; standards from the IETF as RFCs, supported by the Internet Society (ISOC).

Internet (capital I, the global one) against internet (any routed set of networks), intranet (private TCP/IP network inside one organisation, such as a campus-only portal) and extranet (part of an intranet opened to partners, such as suppliers on an order system).

Memory example: tracert (Windows) or traceroute (Linux) to a foreign website shows the hops: Wi-Fi router, ISP, across the border, the server's network: a dozen independently owned networks passing the packets.

X.25: the reliable, slow packet switched WAN

HOT 7/27 Open the full card

X.25: an ITU-T standard (CCITT, 1976) for the interface between a user's DTE (data terminal equipment) and the DCE (data circuit-terminating equipment) of a public packet switched network; connection-oriented, packets over virtual circuits, errors checked and corrected at every hop.

Designed for the noisy analog lines and simple terminals of the 1970s: every link and switch checks, acknowledges and retransmits; packets arrive error free and in order; price: speed (access lines typically up to 64 kbps) and per-hop delay.

Parts (the book's figure 1.9): DTE (user's terminal, computer, router); DCE (device joining the DTE to the network, usually a modem or access port); PSE (packet switching exchange: carrier switches joined by trunks; X.25 defines only the DTE to DCE interface, the PSEs talk as the carrier likes); PAD (packet assembler and disassembler for character terminals: X.3, X.28, X.29).

Figure: DTE and DCE each with packet layer (PLP), link layer (LAPB) and physical (X.21, V.24), exchanging packets, frames and bits; the modulo 8 data packet bit by bit; the packet inside a LAPB frame (flag, address, control, X.25 header, user data, FCS, flag)

LayerOSIJob
Physical1DTE to DCE electrical interface: X.21 (digital), X.21bis and V.24 on analog modems
Link access (frame)2LAPB (Link Access Procedure, Balanced), a subset of HDLC: sequence numbers, CRC error detection, acknowledgement and retransmission, flow control on the DTE to DCE link
Packet (PLP)3sets up and clears virtual circuits, multiplexes up to 4095 on a link, numbers packets and controls flow per circuit, recovers by reset and restart

Virtual circuits: SVC (switched) set up per call and cleared, like a phone call; PVC (permanent) set up by the carrier at subscription, always present, like a leased line, no call setup. A circuit is known on a link by a 12-bit number: 4-bit LCGN (logical channel group number) + 8-bit LCN (logical channel number): 212=4096 values, 0 reserved, up to 4095 circuits on one line.

Data packet, modulo 8:

OctetFieldBitsMeaning
1Q bit1qualifier: 1 control information for a device such as a PAD, 0 user data
1D bit1delivery confirmation: 1 end to end acknowledgement, 0 local
1Modulo201 modulo 8, 10 modulo 128; Q, D and these form the GFI
1LCGN4logical channel group number
2LCN8logical channel number; with LCGN the 12-bit circuit number
3P(R)3receive sequence number: next packet expected, acknowledging those before
3M bit1more data follows in the next packet
3P(S)3send sequence number
3Type10 = data packet (control packets end in 1, whole octet is a type code)
4 onUser datavariableup to 128 bytes by default (other sizes negotiable)

Control packets keep octets 1 and 2; octet 3 is the type; a call request adds calling and called DTE addresses (X.121) and facilities.

Packet (DTE to DCE / DCE to DTE)Type octet
Call request / Incoming call0000 1011
Call accepted / Call connected0000 1111
Clear request / Clear indication0001 0011
Clear confirmation0001 0111
Receive ready (RR)xxx0 0001 (xxx = P(R))
Receive not ready (RNR)xxx0 0101
Reset request / Reset indication0001 1011
Restart request / Restart indication1111 1011

Figure: sequence DTE A, DCE A, network (PSEs), DCE B, DTE B: call request, incoming call, call accepted, call connected; data P(S)=0 and RR P(R)=1 on each side; clear request, clear indication, clear confirmation on both sides

Virtual circuit connection, three phases:

  1. Call setup: DTE A picks a free channel, sends Call request with B's address; the network routes it once through the PSEs, each recording the circuit in a table; B gets Incoming call on a free channel; B answers Call accepted; A gets Call connected.
  2. Data transfer: data packets carry only the channel number; each PSE switches by table lookup (link 1 channel 5 to link 3 channel 9, say); P(S), P(R) number and acknowledge; window (default 2) limits outstanding packets; RR and RNR start and stop flow; in-order delivery.
  3. Clearing: a DTE sends Clear request; the other gets Clear indication, answers Clear confirmation; the first DTE gets Clear confirmation; channel numbers freed.

Also: interrupt (a few urgent bytes outside flow control), reset (reinitialise one circuit, sequence numbers to 0), restart (clear every circuit on the interface).

Advantages: reliable, error free, in-order delivery over poor lines; many circuits multiplexed on one line; per-circuit flow control; SVCs and PVCs; worldwide international standard; pay per data sent instead of renting a line. Disadvantages: slow (low line rates, every node stores, checks and acknowledges), high overhead and delay, unsuited to voice and video; once fibre made lines nearly error free the hop by hop checking was wasted; replaced by Frame Relay, ATM, IP and MPLS, though it ran card payment and airline reservation networks for decades.

X.25 against Frame Relay: compared on the Frame Relay card (Frame Relay keeps the virtual circuits, drops the packet layer and the error correction).

Memory example: a careful old postman checking every letter at every post office and going back for torn ones: nothing lost, slow post.

Frame Relay: fast virtual circuits at the data link layer

HOT 5/27 Open the full card

Frame Relay: a connection-oriented, packet switched WAN technology carrying variable-length frames over virtual circuits identified by a DLCI, using only the physical and data link layers; detects errors but does not correct them (bad frames dropped, end systems recover).

Why it replaced X.25: by the late 1980s digital and fibre lines made errors rare and end hosts ran TCP; per-hop checking was wasted; Frame Relay keeps virtual circuits, removes the packet layer and per-hop acknowledgements; a switch relays a frame once it has read the address. Standards: ITU-T I.122, Q.922; ANSI T1.618; Frame Relay Forum. Access speeds 56 or 64 kbps through 1.544 Mbps (T1) and 2.048 Mbps (E1) to 44.736 Mbps (T3).

Devices: DTEs (customer's routers, bridges, terminals, on the customer's premises) and DCEs (carrier's packet switches providing clocking and switching, moving data through the WAN).

Virtual circuits: PVC configured by the carrier, always present, steady traffic, only two states (data transfer, idle); SVC set up on demand by Q.933 signalling and cleared, occasional traffic. Many circuits share one access line (a head office needs one line, not one per branch).

DLCI (data link connection identifier): names a circuit on one link; local significance (same circuit DLCI 102 at the head office, DLCI 201 at the branch; every switch changes it); DLCI 0 carries signalling; user circuits usually 16 to 1007.

Figure: the frame (flag 8, address 16, information variable, FCS 16, flag 8); the address bits (DLCI high 6, C/R, EA 0; DLCI low 4, FECN, BECN, DE, EA 1); a carrier network of three switches joining Kathmandu HQ (DLCI 102 to Pokhara, 103 to Biratnagar), Pokhara (DLCI 201) and Biratnagar (DLCI 301)

FieldSizeContents
Flag8 bits01111110, start and end; bit stuffing keeps it unique
Address16 bits (extendable to 24 or 32)DLCI (10 bits, split 6 and 4), C/R (command or response, for end systems), EA (0 = another octet follows, 1 = last), FECN, BECN, DE
Informationvariableuser data such as an IP packet; no control field (no sequencing, no acknowledgement)
FCS16 bitsCRC over address and information; bad frame discarded
Flag8 bits01111110

Congestion control without flow control:

  • CIR (committed information rate): rate promised on a circuit (256 kbps on a 2 Mbps line, say); bursts above it allowed when there is room.
  • DE (discard eligibility): frames above the CIR get DE = 1; dropped first under congestion.
  • FECN (forward explicit congestion notification): set on frames going towards the receiver through a congested switch.
  • BECN (backward explicit congestion notification): set on frames going back to the sender: slow down.
  • LMI (local management interface): status messages on the access line (DLCI 0 or 1023): which PVCs are active, link alive.

Operation (Kathmandu head office to Pokhara branch over a PVC):

  1. Encapsulate: HQ router (DTE) puts the IP packet in a frame with DLCI 102, sends it to the carrier switch (DCE).
  2. Check: switch checks the FCS; damaged frame discarded silently.
  3. Look up and relay: (incoming port, DLCI 102) to (outgoing port 3, DLCI 310), DLCI rewritten, frame relayed; every switch repeats; no acknowledgement.
  4. Congestion: busy switch sets FECN forward, BECN backward, drops DE frames first.
  5. Deliver: the last switch delivers to the Pokhara router with DLCI 201; TCP in the hosts resends any lost data.

SVC established, maintained and torn down: four operational states, Q.933 messages on DLCI 0:

Figure: calling DTE, Frame Relay network, called DTE: SETUP (called address, CIR), CALL PROCEEDING, SETUP, CONNECT, CONNECT; data frames both ways on the assigned DLCI; idle with an idle timer; DISCONNECT, RELEASE, RELEASE COMPLETE on each side

  1. Call setup: caller sends SETUP (called address, traffic parameters such as CIR); network answers CALL PROCEEDING and passes SETUP to the called DTE; called DTE answers CONNECT, passed back to the caller; the network tells each end its DLCI; circuit established.
  2. Data transfer: frames both ways on the assigned DLCI, relayed as on a PVC.
  3. Idle: connection active, no data; maintained (STATUS ENQUIRY and STATUS check the link); idle too long and the call can be terminated.
  4. Call termination: a DTE sends DISCONNECT; the network answers RELEASE; the DTE confirms RELEASE COMPLETE; the other DTE gets the same three; DLCI freed.

Advantages: higher rates than X.25; low overhead and delay; suits bursty LAN traffic (burst above CIR); many circuits on one access line (cheaper than a leased line per pair); protocol independent. Disadvantages: no error correction or guaranteed delivery; frames dropped under congestion; variable delay, poor for voice and video; now largely replaced by MPLS and Ethernet services.

BasisX.25Frame Relay
Layers usedphysical, link (LAPB), network (packet)physical, data link only
Error controldetects and corrects at every hopdetects only; bad frames dropped; ends recover
Flow controlhop by hop, per circuit (windows, RR/RNR)none; FECN, BECN, DE instead
Acknowledgementsevery hopnone
Speedtypically up to 64 kbps56 kbps to 44.736 Mbps
Delay, overheadhigh: every node processes every packetlow: relayed once the address is read
Circuit number12-bit LCGN + LCN10-bit DLCI (default)
Multiplexingnetwork (packet) layerdata link layer
Signallingin band (call request packets)out of band (DLCI 0, Q.933)
Lines suitednoisy analogclean digital and fibre
Trafficterminal to host, low volumeLAN to LAN, bursty
BasisFrame RelayATM
Unitvariable-length framefixed 53-byte cell (5 header, 48 payload)
Speed56 kbps to 44.736 Mbpstypically 155.52 or 622.08 Mbps (SONET/SDH), also T1 to T3 for access
Circuit identifierDLCIVPI and VCI
Designed fordata, bursty LAN trafficvoice, video and data together
Delayvariable: long frames hold up short oneslow, predictable: small fixed cells, hardware switching
Quality of serviceCIR and DE onlyCBR, VBR, ABR, UBR
Error checkFCS over the whole frameHEC over the header; payload checked by the AAL
Overheadabout 6 bytes per frame of any size5 of 53 bytes (9.4%), the cell tax
CongestionFECN, BECN, DECLP bit, congestion bit in PT, traffic contracts
Cost, complexitylow, simplehigh, complex
Typical useenterprise branch LANscarrier backbones, broadband ISDN, DSL aggregation

Memory example: X.25 the careful postman; Frame Relay the express courier reading only the label, throwing away soaked parcels, leaving the sender to post again: faster because checking moved to the ends.

The book says "1.544 Mbps to 44.376 Mbps" (pages 18 and 19): T3 is 44.736 Mbps (digits swapped); access also ran below T1, at 56 or 64 kbps.

ATM: fixed 53-byte cells, virtual paths and the adaptation layers

PIN 3/27 Open the full card

ATM (Asynchronous Transfer Mode): a connection-oriented cell switching technology (ITU-T, ATM Forum) carrying voice, video and data in fixed 53-byte cells (5-byte header, 48-byte payload) over virtual circuits named by VPI and VCI; the transfer mode chosen for broadband ISDN.

Asynchronous: a source sends a cell whenever it has data, not in a fixed own slot as in synchronous TDM; no slot wasted on idle sources. Cells not frames: small fixed cells switched in hardware at high speed; a voice cell never waits behind a 1500-byte frame: low, predictable delay.

48 bytes: compromise between the US (64 bytes, efficiency) and Europe (32 bytes, low voice delay). Filling 48 bytes with 64 kbps voice: 48×8/64000=6 ms.

Figure: the 53-byte cell; the UNI header bit by bit (GFC, VPI; VPI, VCI; VCI; VCI, PT, CLP; HEC); the ATM reference model (AAL with CS and SAR, ATM layer, physical with TC and PMD); a transmission path carrying two virtual paths of three channels each

Field (UNI)BitsJob
GFC (generic flow control)4local user to network flow control (UNI only)
VPI (virtual path identifier)8which virtual path
VCI (virtual channel identifier)16which channel in the path
PT (payload type)3user or OAM cell; congestion experienced bit; AAL5 end of message
CLP (cell loss priority)11 = may be dropped first
HEC (header error control)8CRC-8 over the first four header bytes: corrects single-bit, detects most others; finds cell boundaries

NNI (between switches): no GFC; VPI 12 bits.

Virtual paths and channels: a link (transmission path) carries virtual paths, each bundling virtual channels; VPI/VCI names a connection on each link (local, like a DLCI). VP switch (cross-connect) changes only the VPI (thousands of channels rerouted by one entry); VC switch changes both. PVCs and SVCs (Q.2931 signalling).

Reference model (planes: user, control, management):

LayerSublayersJob
AAL (ATM adaptation layer)CS (convergence), SAR (segmentation and reassembly)CS adds what the service needs (timing, sequence numbers, CRC); SAR cuts into 48-byte payloads and rebuilds
ATM layernoneadds and removes the header, multiplexes cells, translates VPI/VCI, generic flow control, traffic management
PhysicalTC (transmission convergence), PMD (physical medium dependent)TC: HEC, cell boundaries, idle cells, SONET/SDH framing; PMD: bits on fibre or copper (155.52 Mbps OC-3/STM-1, 622.08 Mbps OC-12/STM-4)
AALClassUsed forHow it adapts
AAL1A: constant bit rate, timing, connection-orienteduncompressed voice, T1/E1 emulation1-byte SAR header (sequence number and protection), 47 data bytes per cell
AAL2B: variable bit rate with timingcompressed voice and video, mobile voicepacks short packets of several users into one cell, each with a channel ID
AAL3/4C and D: variable rate data, no timing, connection-oriented or connectionlessdata, old SMDS4 bytes SAR header and trailer per cell (segment type, sequence number, multiplexing ID, length, CRC-10), 44 data bytes
AAL5C and D, simple and efficientIP over ATM, LAN emulation, signallingno per-cell overhead: 8-byte trailer (length, CRC-32) and padding per message, 48 data bytes per cell, last cell flagged in PT

Service categories (ATM Forum): CBR (constant: voice, video), rt-VBR (real-time variable: compressed video), nrt-VBR (non real-time variable), ABR (available bit rate: adapts), UBR (unspecified: best effort).

Example (cell tax): 1500-byte IP packet over AAL5: + 8-byte trailer = 1508, padded to 32 cells of 48 (1536, 28 bytes padding); wire: 32×53=1696 bytes; 1500/1696=88.4% is the packet.

Advantages: very high speed; voice, video, data on one network with real QoS; low predictable delay; desktop to backbone. Disadvantages: 9.4% cell tax, complexity, cost; lost to switched Ethernet and IP over MPLS for data. Ran 1990s telephone and Internet backbones; carried ADSL traffic between home modems and the exchange.

Memory example: a supermarket shipping everything in identical 53-litre crates on a conveyor: fast, never jams, much crate per egg.

Ethernet as an example network

Open the full card

Ethernet: the family of wired LAN technologies standardised as IEEE 802.3, describing how devices on one segment format data into frames and put them on the medium; the most used LAN technology, now also on metropolitan and wide area links.

Invented at Xerox PARC by Robert Metcalfe and David Boggs, 1973; DIX (DEC, Intel, Xerox) Ethernet 10 Mbps, 1980, Ethernet II 1982; IEEE 802.3 in 1983. First a shared coaxial bus with CSMA/CD turn taking; now each station has its own full-duplex link to a switch (a star with no collisions; CSMA/CD no longer needed).

GenerationIEEE standard (year)SpeedCommon media
Ethernet802.3 (1983)10 Mbpsthick and thin coax (10BASE5, 10BASE2), later twisted pair (10BASE-T, 1990)
Fast Ethernet802.3u (1995)100 MbpsCategory 5 (100BASE-TX), fibre
Gigabit802.3z (1998), 802.3ab (1999)1 Gbpsfibre; Category 5e (1000BASE-T)
10 Gigabit802.3ae (2002), 802.3an (2006)10 Gbpsfibre; Category 6a (10GBASE-T)
40 and 100 Gigabit802.3ba (2010)40, 100 Gbpsfibre, data centres, backbones
400 Gigabit802.3bs (2017)400 Gbpsfibre, data centre and carrier links

Name code: speed, signalling, medium: 10BASE-T (10 Mbps, baseband, twisted pair); 100BASE-TX (two pairs of Category 5); 1000BASE-T (four pairs); 10GBASE-SR (short-reach multimode fibre).

Every version keeps the frame (preamble, 48-bit destination and source MAC, type or length, 46 to 1500 data bytes, 32-bit CRC): an old card's frame is understood by a new switch. Frame, MAC addressing and access rules: chapter 3.

Why it won: cheap, simple, backward compatible, speed multiplied by ten repeatedly, switch replaced the bus without changing the frame. Metro Ethernet and Carrier Ethernet are sold as MAN and WAN services (the book: "used in LANs and MANs").

Memory example: the blue cable from the hostel router to a desktop: 1000BASE-T on Category 5e or 6, a star point to the router's switch, the same frame format since the 1980s.

VoIP: voice calls as IP packets

Open the full card

VoIP (voice over Internet Protocol): technologies carrying voice calls and multimedia sessions as packets over IP networks such as the Internet instead of the circuit switched PSTN; also IP telephony, Internet telephony, broadband phone.

Circuit against packet: a PSTN call reserves a 64 kbps circuit for the whole call, silences included; VoIP sends packets that share the network, avoiding PSTN tolls and costing only data.

How a call works:

  1. Signalling: SIP (RFC 3261: INVITE, ringing, 200 OK, ACK, BYE) or the older ITU-T H.323 finds the party and sets up the call.
  2. Digitise and compress: sampled 8000 times a second (telephone quality); codec G.711 (64 kbps, the PSTN's coding), G.729 (8 kbps), Opus (adaptive).
  3. Packetise: each 20 ms of speech in one packet with an RTP header (sequence number, timestamp), inside UDP, inside IP; UDP since a late voice packet is useless.
  4. Carry: like any packets; QoS routers send them first.
  5. Play out: jitter buffer holds packets a few tens of milliseconds to even delay, reorders by sequence number, conceals loss, decodes, plays; RTCP reports loss and delay.

Example: one G.711 call: 20 ms at 64 kbps = 160 bytes; + RTP 12 + UDP 8 + IP 20 = 200-byte packets, 50 a second: 200×8×50=80 kbps each way, before the link header.

Quality: one-way delay under about 150 ms (ITU-T G.114), jitter (smoothed by the buffer), packet loss (a few percent sounds broken).

Kinds: app to app (WhatsApp, Viber, Messenger, Zoom); IP phones on an office IP-PBX; analog telephone adapter; gateways to the PSTN under a softswitch; VoLTE (VoIP inside the 4G operator network).

Advantages: cheap (international calls), one network for voice, video, data, features (video, conferencing, voicemail by email, number anywhere). Disadvantages: depends on internet and power; emergency calls hard to locate; eavesdropping, spam calls, toll fraud unless secured (SRTP, TLS).

Memory example: a Viber call to a parent working in Qatar costs a few megabytes: fifty packets a second, reassembled on the other side.

NGN: the next generation network

Open the full card

NGN (next generation network): a packet-based network (ITU-T Y.2001, 2004) able to provide telecommunication services using multiple broadband, QoS-enabled transport technologies, in which service functions are independent of the underlying transport; unrestricted user access to competing providers; generalised mobility.

Problem solved: an operator ran separate networks per service (circuit switches for fixed phones, a mobile core, a data network, television), each with its own equipment, staff, billing; NGN replaces them with one IP packet core for voice, video and data: convergence.

Key ideas:

  • Packet transport: everything as IP packets over one core, often with MPLS for traffic engineering and QoS.
  • Service separated from transport: ITU-T Y.2011's transport stratum (access and core, moving packets) and service stratum (call and session control, applications); add services without touching transport and the reverse.
  • Software call control: softswitch, or IMS (IP Multimedia Subsystem, 3GPP) using SIP; media gateways to the PSTN.
  • QoS-enabled broadband access: DSL, FTTH, cable, 4G, 5G into one core.
  • Open interfaces: third-party services; access to competing providers.
  • Generalised mobility: same services on any fixed or mobile access (fixed mobile convergence).

Four layers often drawn: access, transport (core IP/MPLS), control (softswitch, IMS), service or application.

Benefits: cheaper single network, faster new services. Challenges: telephone-grade quality and reliability over shared IP, security of an open network, working with the old network.

Memory example: a city replacing separate pipes for water, gas and drainage with one service tunnel: dig once, maintain once, add a service by laying a line in the same tunnel.

MPLS: forwarding by short labels

Open the full card

MPLS (Multiprotocol Label Switching): IETF technique (RFC 3031) forwarding packets along pre-established paths by short fixed-length labels instead of a destination IP lookup at every router; carries many protocols over many link types; between layers 2 and 3: "layer 2.5".

Why: an IP router does a longest-prefix match against perhaps a million routes at every hop; MPLS classifies once at the edge; inside, routers look up the label in a small exact-match table, swap it and forward; labels identify virtual paths between distant nodes (like a DLCI or VPI/VCI).

Label (shim) header, 32 bits between the layer 2 header and the IP header:

FieldBitsJob
Label20value routers look up
TC (traffic class, once EXP)3QoS class
S (bottom of stack)11 on the last label (labels stack)
TTL8time to live, loops cannot run forever

Parts: ingress LER (label edge router) classifies packets into an FEC (forwarding equivalence class: packets treated alike, such as one prefix and class) and pushes a label; LSRs (label switching routers) swap; egress LER pops and forwards by IP; the path is an LSP (label switched path, one way). Labels agreed by LDP, RSVP-TE or BGP.

  1. OSPF or IS-IS learns the topology; LDP or RSVP-TE builds LSPs and label tables.
  2. Ingress LER classifies into an FEC, pushes label 17 (say).
  3. Each LSR reads only the label: 17 in, 42 out on port 2.
  4. Egress LER (or the router before it) pops the label, delivers the IP packet.

Uses: traffic engineering (load onto lightly used links), MPLS VPNs joining a company's branches across a carrier's shared network (replaced Frame Relay and ATM circuits), QoS by traffic class, fast reroute in tens of milliseconds. Carries IP, Ethernet, ATM, Frame Relay over T1/E1, ATM, Frame Relay, DSL or Ethernet: multiprotocol.

Memory example: a hospital token: reception reads the whole case once and gives token 17; every counter after reads only the token.

xDSL: broadband over the telephone line

Open the full card

DSL (digital subscriber line, originally digital subscriber loop): family of technologies (xDSL) carrying high-speed digital data over the existing copper telephone line between customer and exchange, in frequencies above the voice band, so phone and internet work at the same time.

Last mile: the local loop was built for voice (about 4 kHz), but the copper carries a few megahertz over short distances; DSL uses those for data; only the exchange to home link, never between exchanges.

How it works:

  • Splitter or microfilter at home separates voice band (phone) and data band (modem).
  • DSL modem at home puts data on the line.
  • DSLAM (DSL access multiplexer) at the exchange ends hundreds of lines, passes traffic to the ISP.
  • DMT (discrete multitone): band split into 4.3125 kHz subchannels (256 in ADSL, up to 1.104 MHz); each carries as many bits as its signal to noise ratio allows.
  • Asymmetric: more bandwidth downstream (to the customer) than upstream.
VariantSymmetryTypical top speedStandard
ADSLasymmetricabout 8 Mbps down, 1 Mbps upITU-T G.992.1 (1999)
ADSL2+asymmetricabout 24 Mbps down, 1 Mbps upITU-T G.992.5 (2003)
VDSL2asymmetric or symmetricabout 100 Mbps on loops of a few hundred metresITU-T G.993.2 (2006)
HDSLsymmetric1.544 or 2.048 Mbps over two or three pairsreplaced leased T1/E1
SDSLsymmetricabout 2 Mbps on one pairbusiness lines

Distance: speed falls as the loop lengthens (high frequencies fade in copper); ADSL to about 5 km; VDSL2's top speeds within a few hundred metres.

DSL and ISDN: both on existing copper, both need the customer near the exchange (the book: usually under 20,000 feet); DSL far faster (ISDN basic rate 144 kbps, 2B+D; DSL megabits). ADSL traffic between modem and exchange usually carried in ATM cells. FTTH has overtaken both.

Nepal: Nepal Telecom sold ADSL over its landline copper for years; most homes have moved to fibre to the home from ISPs such as Nepal Telecom, WorldLink and Vianet.

Memory example: grandfather's landline copper: voice in the bottom 4 kHz, internet in the megahertz above, split by a small box at the socket.

The book says xDSL offers "up to 32 Mbps for upstream traffic, and from 32 Kbps to over 1 Mbps for downstream traffic": directions swapped; in asymmetric DSL the large rate is downstream.

Chapter 2: Physical layer 6100 words

The physical layer: moving raw bits as signals

PIN 1/27 Open the full card

Physical layer: the lowest layer (layer 1) of the OSI model. It transmits a raw stream of bits over a physical medium and defines the mechanical, electrical, functional and procedural characteristics needed to activate, maintain and deactivate the physical link between two devices. It moves bits, not meaning: every frame, packet and segment finally travels as its signals.

Four kinds of rule describe a physical interface (EIA-232, ITU-T X.21):

  • Mechanical: connector shape, size, pin count (RJ-45 has 8 pins).
  • Electrical: voltage levels, bit duration, longest cable.
  • Functional: what each pin or circuit does (transmit, receive, clock, ground).
  • Procedural: the order of events to bring the link up, use it, take it down.
FunctionWhat it decidesExample
Physical characteristicscable, connector, mediumCat 6 UTP with RJ-45
Representation of bitsencoding of 0s and 1sManchester code on 10 Mbps Ethernet
Data ratebits per second, bit duration100 Mbps: a bit lasts 10 ns
Synchronization of bitssender and receiver clocks agree7-byte Ethernet preamble
Line configurationpoint-to-point or multipointleased line; old coaxial bus
Physical topologyhow devices are wiredstar, bus, ring, mesh, hybrid
Transmission modedirection of flowsimplex, half-duplex, full-duplex
ModeDirectionExample
Simplexone waykeyboard to computer, TV broadcast
Half-duplexboth ways, one at a timewalkie-talkie, Ethernet on a hub
Full-duplexboth ways at oncetelephone call, switched Ethernet
  • Bit rate vs baud rate: bit rate = baud rate x bits per symbol; 2,400 symbols a second at 4 bits a symbol (16 levels) gives 9,600 bps. Bandwidth limits the baud rate; noise limits the number of levels.
  • In TCP/IP: no separate physical layer; the lowest layer (host-to-network, network access or link) covers physical and data link functions; TCP/IP defines no protocol there and runs over IEEE 802.3, 802.11, DSL. Forouzan's five-layer TCP/IP draws a separate physical layer. Same functions, different place.
  • Devices: repeaters (regenerate), hubs (multiport repeaters), modems, transceivers, cables and connectors; none reads an address.
  • Memory example: a laptop's network card turns each bit into voltages on the four pairs of a Cat 6 cable; on Wi-Fi the same bits leave as 2.4 or 5 GHz radio waves.

Delay, latency and throughput: measuring a network

PIN 3/27 Open the full card

Network monitoring: measuring how well a network carries traffic by its bandwidth, throughput, latency (delay) and jitter. Delay at every hop is the sum of processing, queuing, transmission and propagation delay.

MeasureMeaningUnit
Bandwidthcapacity: most data per second (for a signal, range of frequencies)bps (Hz)
Throughputdata actually delivered successfully per second over a periodbps
Latencytime for data to reach the destinations, ms
Jittervariation in delay between packets of one flowms
  • Throughput =data delivered/time, never above bandwidth; reduced by headers, retransmissions, collisions, congestion, slow hosts, the bottleneck link. Board calculations (2080 Bhadra, 2078 Bhadra) are in the Numericals panel: watch bytes to bits (x 8) and minutes to seconds (divide by 60).

Figure: a packet crossing router A towards router B, with processing, queuing, transmission and propagation delay marked.

DelayCauseFormulaSize
Processingheader check, bit errors, output link lookuproutermicroseconds
Queuingwaiting in the output bufferload0 to ms, varies
Transmissionpushing L bits onto a link of rate RL/Rµs to ms
Propagationone bit crossing length d at speed sd/s5 µs per km of cable
dnodal=dproc+dqueue+dtrans+dprop
  • Signal speed: about 2×108 m/s in copper and fiber, 3×108 m/s in air and space.
  • Transmission vs propagation: transmission depends on packet size and link rate, not distance; propagation on distance and medium, not packet size (boarding the bus vs driving to Pokhara).
  • Traffic intensity La/R (a = packets per second): near 0 short queues; near 1 queuing delay grows sharply; above 1 queue grows without limit, packets dropped. Congestion appears here.
  • Latency = propagation + transmission + queuing + processing, over every hop. RTT: there and back, as ping reports.
  • Bandwidth-delay product =R×dprop: bits in flight on the link; sizes sliding windows.
  • Worked example: 1,500-byte packet (12,000 bits) at 10 Mbps. Over 2 km of fiber: dtrans = 1.2 ms, dprop = 10 µs (transmission dominates). Over a GEO hop (35,786 km up and down, 3×108 m/s): dprop about 238.6 ms (propagation dominates); bandwidth-delay product about 2.39 million bits, about 199 packets in flight.
  • Causes of packet delay: router processing; congestion (queues, loss); slow links and big packets; distance and medium; number of hops (store-and-forward); retransmissions after errors or loss, flow and congestion control; slow end systems.
  • Jitter: packets sent 20 ms apart arriving 15, 30, 18 ms apart; evened out by a jitter (playout) buffer.
  • The book: defines total latency as one-way there plus one-way back, which is the RTT; latency usually means one-way (Forouzan: propagation + transmission + queuing + processing).

Bandwidth and channel capacity: Nyquist and Shannon

PIN 1/27 Open the full card

Channel capacity: the highest data rate a channel can carry; Nyquist limit for a noiseless channel, Shannon limit for a noisy one.

  • Bandwidth: for a signal, the width of the frequency range in hertz (voice channel 300 to 3,400 Hz, about 3.1 kHz, 4 kHz with guard bands); for a link, the bit rate in bps.
  • Nyquist (1924), noiseless channel, L signal levels: at most 2B signal changes a second.
C=2Blog2L
  • Nyquist example: 3 kHz channel: 2 levels give 6 kbps; 16 levels give 24 kbps.
  • Shannon (1948), noisy channel, SNR as a plain power ratio:
C=Blog2(1+SNR)
  • Decibels: SNRdB=10log10(S/N); 10 dB = 10, 20 dB = 100, 30 dB = 1000. Convert dB to a ratio before Shannon.
  • Shannon example: telephone line, B = 3,000 Hz, SNR 30 dB: C=3000log21001, about 29.9 kbps; dial-up modems stopped near 33.6 kbps.
  • Both together: B = 2 MHz, SNR = 255: Shannon 16 Mbps; choose 12 Mbps; Nyquist gives log2L=3, L = 8 levels.
ImpairmentWhat happensExample
Attenuationpower lost with distance, in dBamplifiers or repeaters every few km
Distortionfrequency components travel at different speedspulses spreading
Noisethermal, induced, crosstalk, impulsehiss on a phone line
  • Loss in dB: 10log10(Pout/Pin); half the power is about 3 dB.
  • 2066 Bhadra: 2 mW and 200 µW: SNR = 10 (10 dB); C=300×106log211, about 1.04 Gbps (Numericals panel).
  • Calculator: log2x=log10x/log102.

Transmission media: the kinds, and how to choose one

HOT 7/27 Open the full card

Transmission medium: the physical path between a transmitter and a receiver that carries the signal (electric current, light, electromagnetic waves); below the physical layer, controlled by it; guided (wired) or unguided (wireless).

Figure: tree of transmission media: guided (twisted pair UTP and STP, coaxial, optical fiber) and unguided (radio 3 kHz to 1 GHz, microwave 1 to 300 GHz terrestrial and satellite, infrared 300 GHz to 400 THz).

PointGuidedUnguided
Signal pathalong a cablefrom an antenna through air or space
Examplestwisted pair, coaxial, fiberradio, microwave, infrared
Data ratehigh, terabits on fiberlower, shared
Securitymust be tapped physicallyanyone in range can receive
Interferencelow; none on fiberweather, obstacles, transmitters
Mobilitynonefree
Installationcable laid; costly over hills and riverstowers and antennas
Cost with distancegrows with lengthalmost independent (satellite)
FactorQuestionWho wins
Bandwidth, data ratebits per second now and laterfiber, coaxial, twisted pair
Distance, attenuationhow far before a repeatersingle mode fiber (tens of km); UTP Ethernet 100 m
Costcable, equipment, labour, upkeepUTP cheapest; fiber optics and satellite dearest
Noise immunitymotors, power lines, lightningfiber immune; STP and coaxial beat UTP
Securitytapped unnoticed?fiber hardest; radio easiest
Installationflexibility, weight, skillsUTP easy; fiber needs splicing
Environment, terrainoutdoor, river, ridgemicrowave or satellite
Mobilityusers move?only wireless
  • Also: reliability, scalability, regulation (spectrum licence).
  • Campus example: labs within 90 m: Cat 6 UTP; 400 m library link: multimode fiber (1000BASE-SX 550 m on OM2; avoids lightning on copper); hostel across a river: microwave or Wi-Fi bridge; canteen: Wi-Fi; ISP: single mode fiber.
  • One line each: twisted pair cheap, noisy, short; coaxial better shielding, bulky; fiber huge bandwidth, EMI immune, costly; radio through walls, low rate; microwave high rate, line of sight, rain fade; infrared private to a room, blocked by walls.

Twisted pair and coaxial cable, compared with fiber

HOT 7/27 Open the full card

Guided media: cables carrying the signal on a solid path: twisted pair and coaxial carry current in copper, optical fiber carries light in glass.

Figure: cross sections of a four pair UTP cable, a coaxial cable (conductor, insulation, braid, jacket) and an optical fiber (core, cladding, buffer, jacket).

  • Twisted pair: two insulated copper conductors, about half a millimetre (22 to 26 AWG), twisted; four pairs per LAN cable, one or two per telephone drop; cheapest, most used.
  • Why twist: noise induces nearly equal voltages in both wires; the receiver reads the difference, so noise cancels; different twist rates cut crosstalk.
TypeConstructionMeritsDemeritsUse
UTPno shieldcheap, thin, flexibleEMI, crosstalkoffice LANs, phone lines
STPgrounded foil or braidless EMI, higher ratescostly, stiff, needs groundfactories, near power cables
  • Shield names (ISO/IEC 11801): U/UTP, F/UTP (foil around all pairs), U/FTP (foil per pair), S/FTP (braid plus foil per pair).
CategoryBandwidthUse
Cat 316 MHztelephone, 10BASE-T
Cat 5100 MHz100BASE-TX
Cat 5e100 MHz1000BASE-T
Cat 6250 MHz1 Gbps; 10 Gbps to about 55 m
Cat 6A500 MHz10GBASE-T to 100 m
Cat 7 (class F)600 MHzshielded 10 Gbps
Cat 82000 MHz25 and 40 Gbps to 30 m
  • Wiring (T568A, T568B): straight-through (same order both ends: PC to switch); crossover (A one end, B the other: PC to PC, switch to switch; auto-MDIX does it automatically); rollover (fully reversed: PC to router console).
  • Characteristics (book): analog amplifiers every 5 to 6 km, digital repeaters every 2 to 3 km; Ethernet over UTP 100 m (90 m fixed plus patch cords).
  • Uses: local loop, DSL, Ethernet LANs, Power over Ethernet. Merits: cheapest, flexible, easy. Demerits: noise, crosstalk, short range, less bandwidth, easy to tap.
  • Coaxial cable: central copper conductor, insulation (dielectric), braided or foil outer conductor (return path and shield), plastic jacket; one shared axis; up to about 1 GHz. 5 to 7 mm (RG-58, RG-6); trunk cables 1 to 2.5 cm (book).
  • Grades: RG-59, RG-6 (75 ohm) cable TV, CCTV; RG-58 (50 ohm) thin Ethernet 10BASE2; RG-8 (50 ohm) thick Ethernet 10BASE5. Connectors BNC, F-type, N-type.
  • Coaxial uses: cable TV and internet, CCTV, antenna leads; once trunks and early Ethernet. Merits: bandwidth, noise immunity, longer runs. Demerits: thick, stiff, dearer; one fault downs a shared bus; amplifiers every few km.
PointTwisted pairCoaxialOptical fiber
Signalelectricalelectricallight
Bandwidth16 MHz to 2 GHz by categoryup to about 1 GHzterahertz range
Data rate10 Mbps to 10 Gbps (40 on Cat 8)10 Mbps to a few Gbps10 Gbps a wavelength, terabits with WDM
Distance100 m Ethernethundreds of m to a few kmkm (multimode), tens of km (single mode)
Noise immunitylowgoodcomplete
Attenuationhighmoderateabout 0.2 dB/km at 1550 nm
Power loss (book)conduction, radiationconductionabsorption, scattering, dispersion, bending
Securityeasy to taphardervery hard
Costcheapestmoderatehighest
Installationeasiestmoderateskilled splicing
UseLANs, phone loopscable TV, CCTVbackbones, FTTH, submarine
  • Memory example: one hostel: Cat 6 UTP to the floor switch, coaxial from the rooftop dish, fiber from the ISP; a lab 160 m away needs a switch half way or fiber.

Optical fiber: light in glass

PIN 1/27 Open the full card

Optical fiber: a thin strand of pure glass (or plastic) carrying information as pulses of light, kept in by total internal reflection at the boundary between a higher-index core and a lower-index cladding.

  • Structure: core (8 to 10 µm single mode; 50 or 62.5 µm multimode), cladding (125 µm, lower index), buffer coating (250 µm), strength members (Kevlar), jacket.
  • Total internal reflection: light from denser core (n1) to rarer cladding (n2) bends away from the normal; beyond the critical angle it is reflected back, at every bounce.
θc=sin−1(n2/n1),NA=n12−n22
  • Example: n1 = 1.48, n2 = 1.46: critical angle about 80.6 degrees; NA about 0.243; acceptance about 14 degrees from the axis.

Figure: three fibers with a sharp input pulse: step index spreads it most, graded index less, single mode keeps its shape.

ModeCoreLight pathSourceReach, use
Multimode step index50 µm or more, uniform indexmany bounce angles; modal dispersionLEDshortest; old LANs, plastic fiber
Multimode graded index50 or 62.5 µm, index falls outwardcurved rays, arrivals bunchLED or VCSELabout 550 m at 1 Gbps; building backbones
Single mode8 to 10 µmone ray on the axis, no modal dispersionlaser diodetens of km; backbones, FTTH, submarine
  • Sources: LED (cheap, long life, wide temperature range, incoherent, low power, short multimode); injection laser diode (coherent, narrow spectrum, high power, fast, long single mode).
  • Detectors: PIN photodiode (simple, cheap); avalanche photodiode APD (gain, sensitive, long links).
  • Windows: 850 nm (multimode), 1310 nm (least dispersion), 1550 nm (lowest loss, about 0.2 dB/km; EDFA, DWDM). f=c/λ: about 353, 229, 193 THz; near infrared, 190 to 355 THz, 650 to 1,200 times the top of the RF range (300 GHz). Radio-over-fiber carries RF signals to antenna sites.

Figure: generic optical fiber system as a U: message source, electrical transmitter, optical source (LED, laser), fiber with repeater or optical amplifier, optical detector (PIN, APD), electrical receiver, destination.

  1. Message source: electrical signal.
  2. Electrical transmitter: code, modulate, drive.
  3. Optical source: current to light.
  4. Fiber cable: connectors, splices; repeaters or EDFAs on long links.
  5. Optical detector: light to current.
  6. Electrical receiver: amplify, equalize, regenerate, decode.
  7. Destination.
  • Advantages: very high bandwidth; low attenuation (repeaters tens of km apart); immune to EMI and lightning; no crosstalk; hard to tap; thin, light; no sparks or shock; no corrosion; long life.
  • Disadvantages: costly install, termination, test; fragile, bend radius; splicing skill; one way, so two fibers or wavelengths for duplex; no power to devices.
  • FTTH example: single mode fiber from the ISP to a passive splitter shared by many houses; the ONT in each house is detector and receiver (WorldLink, Vianet).
  • The book: 2 to 5 km multimode, 25 km single mode; reach depends on rate and optics: 1 Gbps multimode about 550 m; single mode 10 km, 40 to 80 km with long-reach optics.

Unguided media: radio, microwave, infrared and how waves travel

HOT 5/27 Open the full card

Unguided (wireless) media: carry electromagnetic waves through air, water or space without a conductor; an antenna radiates, another collects.

  • Antennas: omnidirectional (radio mast, Wi-Fi access point) or directional (parabolic dish, horn).
MediumFrequencyDirectionPropertiesUses
Radio waves3 kHz to 1 GHzomnidirectionalfar, through walls; low rate; crowded, licensedAM, FM, TV, cordless phones, paging
Microwaves1 to 300 GHzdirectional, line of sighthigh rate; aligned antennas; rain fade above about 10 GHzterrestrial links, satellite, cellular, Wi-Fi 2.4, 5, 6 GHz
Infrared300 GHz to 400 THzline of sight, shortcannot pass walls; sunlight interferesremotes, short device links
  • Terrestrial microwave (book): 4 to 6 GHz and 21 to 23 GHz between dishes on towers or hills; repeaters farther apart than coaxial; across rivers and mountains.

Figure: three panels: ground wave hugging the earth, sky wave bent back by the ionosphere, line of sight between two towers.

MethodFrequencyHowUses
Ground wavebelow 2 MHzfollows the earth's curvature; range by powerAM medium wave, navigation beacons
Sky wave2 to 30 MHzbent back by the ionosphere; long range, low power; day and night differshortwave, amateur radio
Line of sightabove 30 MHzstraight line; antennas must see each otherFM, TV, microwave, mobile, satellite
  • LOS paths: direct wave; ground-reflected wave (with the direct wave forms the space wave; can add or cancel: multipath fading).
  • Radio vs optical horizon (K = 4/3, h in metres):
doptical=3.57h,dradio=3.57Kh≈4.12h km
  • Two antennas: 3.57(Kh1+Kh2) km; two 50 m towers: 29.2 km each, about 58 km apart; towers stand on hilltops.
  • LOS impairments: free-space loss, rain and water vapour absorption (above about 10 GHz), multipath, refraction, obstacles.
  • Wi-Fi, Bluetooth, mobile: microwave ISM bands 2.4 and 5 GHz (MAC in chapter 3, security in chapter 8).
  • Memory example: AM heard beyond hills, farther at night; FM fades behind a ridge; TV remote blocked by a person.

Satellite communication

Open the full card

Communication satellite: a microwave relay station in orbit; earth station uplink, transponder amplifies and shifts frequency, downlink to earth stations.

  • Transponder: receiver and transmitter; amplification and frequency translation; many per satellite.
  • Uplink above downlink: C band about 6 GHz up, 4 GHz down; Ku band about 14 GHz up, 11 to 12 GHz down; separate frequencies keep the strong outgoing signal off the weak incoming one; the earth station affords more power for the fading higher frequency.
OrbitAltitudePeriodFeaturesExample
LEOabout 500 to 2,000 kmabout 90 to 120 minfew ms delay, small footprint, many satellitesStarlink, Iridium
MEOabout 2,000 km to GEO heighthours (GPS about 12 h)navigationGPS at about 20,200 km
GEO35,786 km over the equator23 h 56 min 4 sfixed in the sky; three cover the earth but the poles; long delayDTH TV, VSAT
  • GEO delay: 2 x 35,786 = 71,572 km at 3×108 m/s, about 0.239 s; a reply about 0.48 s. LEO at 550 km: about 3.7 ms.
  • Bands (IEEE, book Table 2.2): L 1 to 2, S 2 to 4, C 4 to 8, X 8 to 12, Ku 12 to 18, K 18 to 27, Ka 27 to 40, V 40 to 75, W 75 to 110 GHz. L: GPS, satellite phones; C: TV distribution, least rain fade; Ku: DTH, VSAT; Ka: broadband.
  • Merits: huge coverage, cost independent of distance, broadcast, remote reach. Demerits: GEO delay, build and launch cost, life about 12 to 15 years (book), rain fade in Ku and Ka, station keeping.
  • Other kinds (book): astronomical, biosatellites, communication, earth observation, navigation, killer satellites.
  • Memory example: DTH dishes in Kathmandu point south and never move.
  • The book: LEO 500 to 1,500 km, MEO 5,000 to 15,000 km, yet names GPS (about 20,200 km) as MEO; usual bounds: LEO to about 2,000 km, MEO up to GEO height.

Multiplexing: many signals on one link

HOT 6/27 Open the full card

Multiplexing: techniques that let several signals share one link at the same time; a MUX combines n inputs into one link, a DEMUX separates them onto n outputs.

  • Importance: efficiency (one fiber carries thousands of calls); lower cost (one cable, less installation and upkeep); makes trunks, broadcasting, cable TV, mobile networks and backbones possible; scalability. Like one bus instead of forty taxis.

Figure: three senders A, B, C sharing a link four ways: FDM bands with guard bands, synchronous TDM frames with empty slots, statistical TDM frames with addressed slots, CDM with codes.

  • FDM: analog; bandwidth split into bands, one carrier each, guard bands between, all at once. Uses: AM 530 to 1700 kHz, FM 88 to 108 MHz, TV, 1G mobile, cable TV; old analog telephony put 12 voice channels of 4 kHz in a 48 kHz group.
  • WDM: FDM for light; one wavelength per signal; prism or grating; DWDM: dozens of wavelengths 0.8 nm (100 GHz) apart near 1550 nm, 10 to 100 Gbps each.
  • TDM: digital; time slots used in turn, a round of slots is a frame with framing bits; link rate n times an input's rate.
  • Synchronous TDM: fixed slot per input every frame, idle slots wasted (T1, E1).
  • Statistical TDM: slots only to inputs with data, fewer slots than inputs, each slot carries an address, buffers absorb bursts; for bursty data.
  • Worked example: four 64 kbps inputs, one byte per slot, one framing bit: 8,000 frames a second (125 µs); frame 33 bits; 264 kbps; slot about 30.3 µs. With 24 inputs: T1, 193 bits, 1.544 Mbps.
  • CDM (CDMA): all send at once over the whole band; data times an orthogonal chip code (inner product of different codes zero); receiver multiplies by one code. 3G (CDMA2000, W-CDMA), GPS.
  • CDMA example: a = (+1, +1), b = (+1, -1); A sends 1 (+1), B sends 0 (-1); channel (0, +2); A recovers (0 + 2)/2 = +1, B recovers (0 - 2)/2 = -1.
PointFDMWDMTDMCDM
Sharesfrequencywavelengthtimecodes
Signalanalogopticaldigitaldigital
Kept apart byguard bandswavelength spacingframing, slot positionorthogonal codes
ExampleFM, cable TVfiber backbonesT1, E1, GSM3G CDMA, GPS
  • Versus switching: multiplexing shares one link; switching chooses the path.
  • Memory example: Kathmandu FM stations each on their own frequency between 88 and 108 MHz (FDM); a call in one 64 kbps slot of an E1 trunk (TDM).

Switching: circuit, message and packet

TOP 13/27 Open the full card

Switching: connecting a sender to a receiver through intermediate nodes (switches) instead of a link between every pair; a switch forwards from an input port (ingress) to the output port (egress) towards the destination.

  • Why: a mesh of n devices needs n(n−1)/2 links; 1,000 phones would need 499,500 lines.
  • Techniques (book Fig 2.18): circuit, message, packet (datagram, virtual circuit); inside a switch, circuits are made by space or time division.

Figure: one message from A to D through B and C, time downward: circuit (request, accept, one stream, release), message (stored whole at each node, arrives last), packet (three packets pipelined, arrives first).

  • Circuit switching: a dedicated end-to-end path reserved before data and held for the session; one channel (FDM band or TDM slot) per link. Phases: setup (request hop by hop, reserve, accept), data transfer (continuous, no addresses, no store-and-forward, no queuing), teardown (release frees channels). Example: PSTN call.
  • Message switching: no setup or reserved path; whole message with destination address stored at each node (on disk) and forwarded when the link is free; store-and-forward network. Drawbacks (book): storage for the largest message, delays add hop by hop, useless for real time. Telegraph, telex; replaced by packet switching.
  • Packet switching: message cut into limited-size packets with headers (addresses, sequence number); store and forward per packet; links shared, capacity used only with data (statistical multiplexing); pipelining makes it faster than message switching. Forms: datagram and virtual circuit. Example: the internet.
  • Worked example: 1 Mbit over 3 links of 1 Mbps: message switching 3 s; 1,000 packets of 1 kbit: 1 + 2 x 0.001 = 1.002 s. In general message NL/R, packet L/R+(N−1)P/R.
PointCircuit switchingPacket switching
Pathdedicated for the sessionnone; links shared
Setupneedednone (datagram)
Bandwidthfixed, reserveddynamic, on demand
Idle capacitywastedused by others
Transfercontinuous, no store-and-forwardstore-and-forward per node
Addressingonly at setupheader on every packet
Delaysetup, then constantno setup; variable queuing
Orderin ordermay be out of order
Congestionat setup (busy tone)per packet (queuing, loss)
Switch failscall cutpackets rerouted
Chargingtime and distancedata volume
Suitsreal-time voicebursty data
ExamplePSTNthe internet
  • Circuit switching suits real time: guaranteed reserved bandwidth (no competition, no congestion once up); constant low delay, no jitter (no queuing, no store-and-forward; ITU-T G.114: one-way delay under 150 ms); in-order delivery on one path; no per-packet overhead or buffer loss; setup paid once. VoIP needs priorities, jitter buffers and spare capacity to approach this.
PointSwitchingMultiplexing
Purposeconnects sender to receivershares one link among signals
Wherenodes inside the networktwo ends of a link
Deviceswitch, router, exchangeMUX, DEMUX
Kindscircuit, message, packetFDM, WDM, TDM, CDM
Exampleexchange connecting a call to PokharaE1 trunk with 30 calls
  • Together: a circuit-switched call is one time slot of a multiplexed trunk on every link.
  • Modern networks: packet switching: IP routers (datagrams by destination address); MPLS in ISP backbones (virtual circuits with labels); Ethernet switches by MAC address, store-and-forward or cut-through. Circuit switching only in legacy telephony; voice now VoIP, VoLTE.
  • Memory example: landline call to Pokhara holds a path (circuit); Viber voice message shares links (packet); festival morning busy tone: no free circuit.

Datagram and virtual circuit: two ways to switch packets

HOT 6/27 Open the full card

Datagram and virtual circuit: the two forms of packet switching. Datagram (connectionless): each packet carries the full destination address and is routed on its own. Virtual circuit (connection-oriented): a path set up first, every packet follows it with a short VCI.

Figure: two networks of routers R1 to R4 between hosts A and B: datagram packets 1 and 3 on the upper path, 2 and 4 on the lower, arriving 2, 1, 4, 3, header with destination, source, sequence; virtual circuit path A, R1, R2, R4, B with VCIs 12, 25, 7, 31 and R2's table (from R1, 25 to R4, 7).

  • Datagram (book Fig 2.21): header with full source and destination address plus payload; routing table lookup per packet; no connection state; packets may take different paths, arrive out of order, be lost or duplicated; TCP reorders. IP.
  • Virtual circuit (book Figs 2.22, 2.23): circuit's phases, datagram's packets.
  1. Setup: request with full destination address; each switch picks the next hop and writes in port, in VCI, out port, out VCI; acknowledgment returns; resources can be reserved.
  2. Data transfer: packets carry only the VCI; lookup (in port, in VCI), replace VCI (label swapping), send out; one path, in order.
  3. Teardown: release removes the entries.
  • VCI: local meaning on one link only; small; reused.
NetworkVCI nameSize
X.25logical channel number12 bits
Frame RelayDLCI10 bits (default)
ATMVPI and VCI8 or 12 bits, and 16 bits
MPLSlabel20 bits
  • PVC: set up in advance by the operator, like a leased line. SVC: set up on demand by signalling, torn down after, like a phone call.
IssueDatagramVirtual circuit
Setupnot neededneeded
Addressingfull source and destinationshort VC number
Statenone per connectiontable space per VC in every switch
Routingeach packet independentlyat setup; all packets follow
Router failureonly packets in it lostall VCs through it terminated
Ordermay be out of orderin order
QoSdifficulteasy with reserved resources
Congestion controldifficulteasy with reserved resources
Header overheadlargesmall
ExamplesIPX.25, Frame Relay, ATM, MPLS
  • Frame Relay (2081 Bhadra): a virtual circuit network; 10-bit DLCI in the address field; switches look up (in port, DLCI) and swap it; mostly PVCs by the carrier, SVCs by Q.933; frames in order; only CRC check and discard, recovery left to end systems; congestion bits FECN, BECN, DE. A datagram network (IP) would route each packet by full address with no setup or per-circuit state.
  • 2078 Bhadra "packet switching vs virtual circuit": packet switching means datagram. 2070 Ashad prints "virus circuit switching": virtual circuit switching.
  • Memory example: datagrams are taxis (full address, own road, either order); a virtual circuit is a bus route (fixed first, short route number).

The telephone network, and the T1 and E1 hierarchy

PIN 2/27 Open the full card

Telephone: an instrument turning speech into an electrical signal and back. PSTN: the worldwide circuit-switched network of telephones, local loops, exchanges and trunks.

PartJob
Transmitter (microphone)sound to varying current
Receiver (earpiece)current to sound
Hook switchoff-hook asks for service; on-hook ends the call
Diallerpulses (rotary) or DTMF: one tone from 697 to 941 Hz, one from 1209 to 1477 Hz
Ringerrings on ringing current
Hybrid (induction coil)two-wire line to four-wire handset; sidetone
  • Bell's patent: 1876. Line power: about 48 V DC from the exchange; works without house electricity.

Figure: telephone network hierarchy: phones on local loops to end offices, end offices to toll offices, toll offices to a regional office; a call from Kathmandu (01) to Pokhara (061) through two toll offices.

  • Local loop: twisted pair from subscriber to end office (local exchange), 300 to 3,400 Hz, the last analog part.
  • Switching offices: end offices (own subscribers), tandem offices (end offices of one area), toll offices (long distance); AT&T classes: regional centre (1), sectional (2), primary (3), toll (4), end office (5).
  • Trunks: multiplexed high-capacity links; once FDM, now TDM (E1, T1) over fiber.
  • Numbering: country code, area code, subscriber number; Nepal +977, Kathmandu 01, Pokhara 061.
  1. Off-hook: loop closes, end office detects current.
  2. Dial tone: exchange ready.
  3. Dialling: DTMF tones or pulses stored.
  4. Switching: local call inside the end office; otherwise a trunk to tandem or toll office; SS7 sets up the circuit hop by hop.
  5. Ringing: free line rings, caller hears ringback; else busy tone.
  6. Answer and conversation: analog on loops, 64 kbps PCM in a time slot on each trunk.
  7. Hang up: channels released, call recorded for billing (time and distance).
  • Basic channel: voice sampled 8,000 times a second (Nyquist for 4 kHz) x 8 bits = 64 kbps (DS0, E0).
  • T1 (North America, Japan): 24 channels; frame 24 x 8 + 1 = 193 bits; 193 x 8,000 = 1.544 Mbps (1,536 kbps voice + 8 kbps framing).
ServiceLineRateVoice channels
DS-1T-11.544 Mbps24
DS-2T-26.312 Mbps96
DS-3T-344.736 Mbps672
DS-4T-4274.176 Mbps4032

Figure: E1 frame of 32 slots (TS0 alignment, TS16 signalling, 30 voice) and the ladder E0 64 kbps, E1 2.048, E2 8.448, E3 34.368, E4 139.264 Mbps.

  • E1 (ITU-T; Europe, most of the world, Nepal and India): 32 slots TS0 to TS31 of 8 bits = 256 bits, 8,000 frames a second (125 µs). TS0: frame alignment, alarms, messages (fixed pattern in alternate frames). TS16: signalling (setup, teardown) or data. TS1 to TS15 and TS17 to TS31: 30 voice channels of 64 kbps. 32 x 8 x 8,000 = 2.048 Mbps.
LevelRateVoice channelsMade of
E064 kbps1one channel
E12.048 Mbps3032 slots
E28.448 Mbps1204 x E1 + 256 kbps
E334.368 Mbps4804 x E2 + 576 kbps
E4139.264 Mbps19204 x E3 + 1.792 Mbps
  • Justification bits: lower streams on slightly different clocks: plesiochronous digital hierarchy (PDH); replaced by SDH (STM-1 155.52 Mbps).
  • T1 vs E1: T1 24 channels, robbed-bit signalling; E1 30 channels, separate TS0 and TS16. ISDN PRI: 23B + D on T1, 30B + D on E1.
  • Memory example: an E1 is a train of 32 compartments passing 8,000 times a second: engine TS0, guard's van TS16, 30 calls.

Telecommunication switching systems: from operators to digital exchanges

Open the full card

Telecommunication switching system: exchange equipment that connects any incoming line to any outgoing line or trunk on demand, holds the connection for the call, and releases it.

  • Manual: operators with cords and jacks; slow, operator-dependent, replaced.
  • Electromechanical, step-by-step (Strowger, Almon B. Strowger, 1891): dialled pulses step selector switches; control spread over the switches.
  • Electromechanical, crossbar: bars crossing, contacts closed by relays and latches; hard-wired control, hard to change.
  • Electronic SPC (stored program control): a computer runs the exchange from a stored program; new services by software (Bell No. 1 ESS, 1965). Space division (separate path per call) or time division (shared path, samples at fixed intervals; analog or digital; digital from space switches, time switches and combinations).
  • Space division: an N x N crossbar has N2 crosspoints, only N in use (1,000 lines: 1,000,000); multistage switches need fewer but can block.
  • Time division: time slot interchange (TSI): write the incoming frame to memory in order, read out in the outgoing order; digital exchanges switch the 64 kbps slots of E1 lines; large ones combine stages (time-space-time, TST).
  • TSI example: incoming A, B, C, D in slots 1 to 4; control: out 1 takes in 3, out 2 takes in 1, out 3 takes in 4, out 4 takes in 2; outgoing C, A, D, B.
  • Networking of exchanges: trunks join local, tandem and toll exchanges; signalling first channel associated (CAS, in the channel or E1 TS16), now common channel (CCS) over a separate network, SS7: faster setup, voice channels free.
  • Memory example: a Strowger exchange clatters with each digit; a digital exchange is silent memory.

ISDN: one digital network for voice and data

HOT 5/27 Open the full card

ISDN (Integrated Services Digital Network): ITU-T I-series standards (1980s) for a fully digital, circuit-switched telephone network carrying voice, data, fax and video end to end over the existing copper line, through standard channels (64 kbps B, signalling D) and interfaces (BRI, PRI).

  • Why developed: (1) the local loop was the last analog link (300 to 3,400 Hz, slow modems) while trunks and exchanges were digital; (2) separate networks for voice, telex and X.25 data, now one network, line, number, bill; (3) out-of-band D channel signalling: faster setup, caller identification, call waiting, several numbers; (4) end-to-end digital quality; (5) standard interfaces for any vendor.
  • Contribution to data communication: 64 or 128 kbps on an ordinary line (modems gave 28.8 to 56 kbps), 1.5 or 2 Mbps on PRI; voice and data together; fast dial-up for internet and office links; router backup (dial on demand); videoconferencing (H.320); PRI trunks for PBXs; broadband ISDN led to ATM. Replaced by DSL, cable, fiber.
ChannelRateCarries
B (bearer)64 kbpsuser voice, data, video; circuit switched
D (delta, data)16 kbps (BRI), 64 kbps (PRI)signalling; low-rate packet data
H (hybrid)H0 384, H11 1,536, H12 1,920 kbpsvideo, fast data
  • BRI: 2B + D = 2 x 64 + 16 = 144 kbps; with 48 kbps framing and sync, 192 kbps on the S/T interface; homes, small offices, one twisted pair.
  • PRI: 23B + D = 23 x 64 + 64 + 8 = 1,544 kbps (T1; North America, Japan); 30B + D = 30 x 64 + 64 + 64 = 2,048 kbps (E1; B in TS1 to 15 and 17 to 31, D in TS16, framing TS0); PBXs, ISPs.

Figure: ISDN reference point diagram: TE1 at S to NT2; TE2 at R to TA, TA at S to NT2; NT2 at T to NT1; NT1 at U to the exchange, which reaches circuit, packet, leased line and SS7 networks; customer premises up to NT1.

GroupWhatExample
TE1ISDN terminal, at SISDN phone, PC with ISDN card
TE2non-ISDN terminal, at R, needs TAanalog phone, RS-232 PC
TAterminal adapter, R in, S outISDN adapter box
NT2customer switching, layers 2 and 3PBX, router, LAN
NT1line end, layer 1; four-wire S/T to two-wire loop, monitoring, timingNT1 box
LT, ETline and exchange terminationcarrier's switch
  • Reference points: R (TE2 to TA), S (TE1 or TA to NT2), T (NT2 to NT1), U (NT1 to exchange); alphabetical outward; no NT2: S/T; up to 8 terminals on a BRI S bus.
  • Layers: I.430 (BRI), I.431 (PRI); LAPD (Q.921) on D, HDLC-type, address with SAPI and TEI; Q.931 call control; B channels carry anything.
  • Working: SETUP on D; exchange routes with SS7; B channel assigned at each end and joined; 64 kbps end to end; D free for more signalling; release by three D messages.

Figure: Q.931 sequence: SETUP, CALL PROCEEDING, SETUP to called, ALERTING, ALERTING, CONNECT, CONNECT ACK, CONNECT, CONNECT ACK; B channel; DISCONNECT, RELEASE, RELEASE COMPLETE on each side; SS7 inside.

  • Signalling: out-of-band, common channel, on D only. User to network: Q.931 in LAPD frames; setup SETUP (called number, bearer), CALL PROCEEDING, ALERTING, CONNECT, CONNECT ACKNOWLEDGE; release DISCONNECT, RELEASE, RELEASE COMPLETE. Network: SS7 ISUP: IAM, ACM, ANM, REL, RLC. User to user signalling through the network. Benefits: B channel free throughout, fast setup, one channel for many calls.
  • Broadband ISDN: narrowband stops near 2 Mbps; B-ISDN at 155.52 and 622.08 Mbps over fiber with ATM.
  • Memory example: small office BRI: ISDN phone (TE1) and old fax through a TA on the S bus; a call on one B, 64 kbps internet on the other; D set up both; NT1 on the wall.
  • The book: labels the D channel "(Bearer Channel)"; a slip: B is the bearer, D the signalling channel.

Chapter 3: Data link layer 8750 words

The data link layer: functions, services and design issues

HOT 8/27 Open the full card

Data link layer: layer 2 of the OSI model. It packs the network layer's packets into frames and moves them reliably from one node to the next over a single link, hiding noise and medium sharing from the layers above.

Hop to hop, not end to end: a packet from a hostel laptop to a server abroad crosses laptop to Wi-Fi AP, AP to switch, switch to router, router to ISP; the network layer picks the route, the data link layer works each hop, with a fresh header (that link's addresses) and a fresh bit check on every hop. Memory example: a relay race; route planned once, each runner carries the baton one leg and checks it at the hand-over.

Figure: the network layer above, the data link layer split into one LLC (802.2) and a MAC per LAN (802.3, 802.4, 802.5, 802.11), each over its own physical layer

Functions (Forouzan's five):

  • Framing: divide the bit stream into frames, delimit start and end.
  • Physical addressing: sender and receiver MAC addresses in the header (48-bit Ethernet addresses).
  • Flow control: stop a fast sender overrunning a slow receiver.
  • Error control: detect damaged frames (CRC or checksum in the trailer); recover damaged, lost and duplicate frames by retransmission (ARQ).
  • Access control: on a shared medium, decide which station transmits now.
  • Also (Tanenbaum): a well-defined service interface to the network layer; link management (set up, maintain, release connections).
ServiceHow it worksSuitsExample
Unacknowledged connectionlessno connection, no ACK; lost frame not recovered herelow-error links, real-time trafficEthernet
Acknowledged connectionlessno connection; every frame ACKed, resent on timeoutunreliable links, radioIEEE 802.11
Acknowledged connection-orientedconnection set up; numbered frames, each exactly once, in order; establish, transfer, releaselong or noisy links, WAN serial, satelliteHDLC, LLC type 2

Design issues: service to the network layer; framing; error control (detection, ACKs, timers, sequence numbers); flow control; on broadcast links, medium access and addressing.

SublayerStandardFunctions
LLC (upper)IEEE 802.2, same for all LANsnetwork layer interface; multiplexes protocols with service access points (DSAP, SSAP); optional flow and error control; type 1 unacknowledged connectionless, type 2 connection-oriented, type 3 acknowledged connectionless
MAC (lower)one per LAN: 802.3, 802.4, 802.5, 802.11frame for its LAN; MAC addresses and FCS; medium access (CSMA/CD, token passing, CSMA/CA); error detection

Framing: character count, byte stuffing and bit stuffing

TOP 10/27 Open the full card

Framing: dividing the physical layer's bit stream into frames and delimiting each frame's start and end, so the receiver finds boundaries, checks each frame and asks again for only the damaged one.

Why: one flipped bit in a whole-file block means resending everything; in frames of a few hundred bytes only the damaged frame is resent. Frame = header (addresses, control) + payload + trailer (error check). Fixed-size frames (ATM's 53-byte cells) need no delimiters; variable-size frames need a method; protocols often combine two.

Figure: character count (frames of 5, 5, 8, 8 bytes; one count garbled from 5 to 7 breaks every later boundary), byte stuffing (FLAG ends, ESC added before FLAG or ESC in data), bit stuffing (flag 01111110, stuffed 0s)

  1. Character count: a header field gives the frame's byte count. Flaw: a garbled count loses the receiver's step for good; the CRC says the frame is bad but not where the next one starts, and the sender cannot tell how much to resend. Never used alone.
  2. Flag bytes with byte (character) stuffing: FLAG byte at start and end; a lost receiver searches for the next FLAG. A FLAG in the data is sent as ESC FLAG, an ESC as ESC ESC; the receiver removes each escape. PPP: FLAG 0x7E, ESC 0x7D. Drawbacks: tied to 8-bit bytes; a frame full of FLAGs can double.
  3. Flag bits with bit stuffing: flag 01111110 at both ends; after five consecutive 1s in the data the sender stuffs a 0, so six 1s never occur inside. Receiver: after five 1s, a 0 is stuffed (delete it); a 1 then 0 is the flag. Any number of bits, not only bytes. HDLC; USB stuffs after six 1s.
  4. Physical layer coding violations: line codes with unused signal patterns. Manchester: each bit high-low or low-high, so high-high and low-low delimit frames. 4B/5B: 16 of 32 code groups carry data; 100BASE-X and FDDI start frames with J and K. Only where the line code has spare patterns.

Memory example: byte stuffing is a quote inside a C string, "He said \"namaste\"": backslash = ESC; a real backslash is written as two (ESC ESC).

Example (the book's, checked): data 01001111110111110 (17 bits):

data      0100 11111 1 0 11111 0
stuffed   0100 11111 0 1 0 11111 0 0
sent      01111110 0100111110101111100 01111110

Two bits stuffed, 19 bits between the flags.

MethodFrame delimited byWeaknessUsed in
Character countlength field in headerone bad count loses every later boundaryonly with another method
Byte stuffingFLAG bytes; ESC before FLAG or ESCneeds 8-bit bytes; frames growPPP
Bit stuffingflag 01111110; 0 after five 1sup to one extra bit per fiveHDLC family
Coding violationspatterns data never usesneeds a redundant line code100BASE-X, FDDI

Errors, detection against correction, parity and the checksum

PIN 1/27 Open the full card

Error: a change in a frame's bits between sender and receiver (noise, interference, attenuation, faulty device), caught with redundant bits computed from the data and recomputed by the receiver.

  • Single-bit error: one bit changes; rare on serial links (noise outlasts one bit).
  • Burst error: two or more bits change; length from the first wrong bit to the last, bits between may be right. A 1 ms noise burst hits about 10 bits at 10 kbps, about 10,000 at 10 Mbps.
  • The book adds: content error (message bits change) and flow integrity error (frame lost, duplicated or misdelivered).

Detection asks did an error happen; the frame is discarded and resent (ARQ, backward error correction). Correction asks which bits and fixes them at the receiver (forward error correction, FEC); it needs many more redundant bits, so it pays where retransmission is slow or impossible.

PointError detectionError correction
Goalfind that the frame has an errorfind which bits and fix them
Redundancysmall: 1 parity bit, 16 or 32-bit CRClarge: 3 check bits per 4 data bits, Hamming (7,4)
After an errordiscard; sender retransmits (ARQ)receiver repairs at once (FEC)
Hamming distancedmin≥s+1 detects sdmin≥2t+1 corrects t
Suitswired LANs, links with a return channelnoisy or long-delay links, no return: satellite, mobile, Wi-Fi, CDs, QR codes
Codesparity, checksum, CRCHamming, Reed-Solomon, convolutional, LDPC

Memory example: a shop's payment QR sticker (Fonepay, eSewa) scans with a torn corner: Reed-Solomon correction rebuilds up to 30 percent of the code at the highest level.

  • Simple parity: one bit makes the count of 1s even (or odd). Book example: 1001101 (four 1s) sent with even parity as 01001101; 00001101 arrives: odd count, detected; 00001001 (two flips): even, missed. Detects every odd number of errors, no even number; corrects nothing.
  • Two-dimensional parity: rows with a row parity bit (VRC), columns with a column parity bit (LRC); detects all 1, 2 and 3-bit errors, misses some 4-bit patterns; corrects a single bit at the failing row and column.
  • Checksum: upper layers (IP, UDP, TCP use the 16-bit Internet checksum). Sender: k segments of m bits, added in one's complement (carry out of the top wrapped to the bottom); checksum = complement of the sum. Receiver: adds all segments and the checksum; complement all 0s means accept.

Book example (checked), k=4, m=8:

  10011001
+ 11100010  = 1 01111011  wrap: 01111100
+ 00100100  =   10100000
+ 10000100  = 1 00100100  wrap: 00100101
sum 00100101, checksum 11011010
receiver: 00100101 + 11011010 = 11111111, complement 00000000: accept

Checksum weakness: errors that cancel (one word +1, another -1) and swapped words pass, so the link uses CRC.

CRC: the cyclic redundancy check

PIN 3/27 Open the full card

CRC: error detection by binary polynomial division: the sender appends r check bits, the remainder of dividing the data (with r zeros added) by a generator of degree r in modulo-2 arithmetic, so the whole frame divides exactly; the receiver divides again and a nonzero remainder means an error.

  • Bits as polynomials: 1101 is x3+x2+1; a degree-r generator has r+1 bits, first and last 1.
  • Modulo-2 arithmetic: no carries or borrows; addition = subtraction = XOR (1+1=0); subtract the generator where the leading bit is 1, zeros where it is 0.

Figure: sender appends r zeros, divides, appends the remainder; receiver divides by the same generator; remainder 000 accept, otherwise reject (example data 1101, generator 1011)

Sender: 1. append r zeros (xrM(x)); 2. divide by G(x) mod 2; 3. remainder R (r bits, leading zeros kept) is the CRC; 4. send M then R, T(x)=xrM(x)+R(x). Receiver: divide by the same G(x); zero remainder accept, else discard (ARQ resends).

Example: message 1101, generator 1011 (x3+x+1, r=3):

          1111        quotient
1011 ) 1101000
       1011
       ----
        1100
        1011
        ----
         1110
         1011
         ----
          1010
          1011
          ----
           001        remainder = CRC

Sent 1101001; at the receiver 1101001 / 1011 leaves 000: accepted.

Why it works: T(x) is a multiple of G(x) (adding the remainder = subtracting it mod 2); with an error pattern E(x) the remainder is that of E(x) alone, missed only if G(x) divides E(x). Detects:

  • all single-bit errors, when G(x) has at least two terms;
  • all double-bit errors, when G(x) divides no xt+1 for t up to the frame length;
  • every odd number of errors, when x+1 is a factor;
  • every burst of length r or less; a burst of r+1 with probability 1−2−(r−1); longer ones with probability 1−2−r.

Generators: CRC-8 x8+x2+x+1 (ATM header), CRC-16-CCITT x16+x12+x5+1 (HDLC, PPP), CRC-32 (Ethernet and Wi-Fi 4-byte FCS). Hardware: a shift register with an XOR per generator term, computed as bits go out; the book: CRC described by modulo-2 arithmetic, polynomials or digital logic. Memory example: a teacher checking a long sum by its remainder on division by 9: a wrong remainder shows a copying error but not where.

Method in the exam: generator as bits; append r zeros (r = bits minus one); full division layout; remainder with r bits; transmitted frame. To show detection: flip the bit, divide the received frame, show the nonzero remainder.

Hamming distance and the Hamming code

PIN 1/27 Open the full card

Hamming distance: the number of bit positions in which two equal-length codewords differ, found by XOR and counting the 1s. The minimum Hamming distance dmin of a code is the smallest distance between any two valid codewords; it fixes how many errors the code detects and corrects.

Example: 10101 XOR 11110 = 01011: distance 3. Memory example: SITA and GITA differ in one letter (distance 1): one wrong letter makes another valid name, unnoticed; names at least three letters apart would turn a typo into a non-name closest to exactly one real name.

dmin≥s+1 to detect s,dmin≥2t+1 to correct t
CodedminDetectsCorrects
Even parity21 errornone
Repetition 000, 11132 errors1
Hamming (7,4)32 (if not correcting)1
Extended Hamming (8,4), SECDED421 (ECC memory)

Use in error control: pick a code whose dmin fits the link; detecting code (CRC) plus retransmission (ARQ) where there is a return channel, correcting code (Hamming, FEC) where retransmission is costly. A received word that is not a codeword shows an error; correction = the nearest codeword.

Hamming code: r parity bits for m data bits with 2r≥m+r+1 (4 data bits need 3: the (7,4) code). Parity bits at positions 1, 2, 4, 8, ...; each checks the positions whose binary number contains its bit: P1 checks 1, 3, 5, 7 (check 1, skip 1); P2 checks 2, 3, 6, 7 (check 2, skip 2); P4 checks 4, 5, 6, 7 (check 4, skip 4). Word layout D7 D6 D5 P4 D3 P2 P1, even parity.

Example, encode data 1011 (D7 D6 D5 D3 = 1 0 1 1), then correct:

P1 = D3 xor D5 xor D7 = 1 xor 1 xor 1 = 1
P2 = D3 xor D6 xor D7 = 1 xor 0 xor 1 = 0
P4 = D5 xor D6 xor D7 = 1 xor 0 xor 1 = 0
codeword = 1 0 1 0 1 0 1
bit 6 flips: 1110101 arrives
C1 = P1 D3 D5 D7 = 1 1 1 1  even: 0
C2 = P2 D3 D6 D7 = 0 1 1 1  odd:  1
C4 = P4 D5 D6 D7 = 0 1 1 1  odd:  1
syndrome C4 C2 C1 = 110 = 6: flip bit 6, 1010101

Syndrome 000 means no error. The book's example: 1110111 arrives, syndrome 100 = 4, "the 4th bit is incorrect", but the book never writes the corrected code: flipping bit 4 gives 1111111 (data 1111).

Flow control: stop and wait, the sliding window and piggybacking

HOT 5/27 Open the full card

Flow control: procedures telling the sender how much data it may send before it must wait for an acknowledgement, so a fast sender does not overrun a slow receiver's buffer and processing speed.

Without it the buffer fills, frames are dropped and resent: wasted time. Memory example: a teacher dictating; stop and wait reads one line and waits for "OK"; the sliding window reads up to seven lines ahead while the student calls out "done up to line 5".

Stop and wait: send one frame, wait for its ACK, then the next. Simple, never overruns, but the link idles a round trip per frame. With a=Tprop/Tframe:

Ustop and wait=11+2a

Example: 1000-bit frames at 1 Mbps (Tframe = 1 ms), satellite Tprop = 270 ms: a=270, U=1/541, about 0.18 percent.

Figure: stop and wait timing; normal (frame 0, ACK 1, frame 1, ACK 0) and errors (frame 0 lost, timeout, resent; ACK 1 lost, timeout, duplicate frame 0 discarded and re-acknowledged)

Sliding window: up to W frames before an ACK; k-bit sequence numbers modulo 2k (0 to 7 for 3 bits). Send window = sent but unacknowledged plus may-send-now; receive window = frames the receiver will accept. An ACK carries the next frame expected, acknowledging all before it, and slides the window right.

U=1 if W≥1+2a,U=W1+2a otherwise

Same satellite link, W=7: U=7/541, about 1.3 percent; filling the pipe needs W≥541, so 10-bit sequence numbers. TCP grows its window for the same reason.

Figure: send window of 7 over 3-bit sequence numbers: 0, 1 acknowledged; 2 to 4 sent, waiting; 5, 6, 7, 0 may be sent; receive window 1 for go-back-N, up to 4 for selective repeat

Piggybacking: with two-way data the ACK rides in a header field of the receiver's next data frame instead of a separate ACK frame; each data frame carries seq (its own number) and ack (next frame expected from the other side).

  • Advantages: fewer frames (no separate ACK frames, headers, trailers), better bandwidth use; less processing, fewer interrupts; window still slides.
  • Cost: an ACK may wait for outgoing data; an ack timer sends a separate ACK if no data frame leaves in time (before the sender's timer resends needlessly).
  • Where: HDLC N(R) in every I-frame; TCP's ACK flag on data segments.

Memory example: in a phone call, "yes, got it" said at the start of your own next sentence.

Error control by ARQ: stop and wait, go-back-N and selective repeat

PIN 4/27 Open the full card

ARQ (automatic repeat request): error control by retransmission, also called backward error correction; the receiver detects damaged frames (CRC) and the sender resends any frame damaged or lost, prompted by a timeout or a NAK.

Tools: sequence numbers (gaps, duplicates), ACKs, NAKs, a timer per outstanding frame, a copy of every unacknowledged frame at the sender. The three ARQs are the ways of backward error correction.

  1. Stop and wait ARQ: stop and wait flow control plus a timer and 1-bit sequence numbers (0, 1, 0, 1). Damaged frame: receiver discards (or NAKs), timer expires, resend. Lost frame: timeout, resend. Lost ACK: timeout, resend; receiver sees a duplicate by sequence number, discards it, re-ACKs (without sequence numbers it would accept it twice).
  2. Go-back-N ARQ: sliding window; up to 2k−1 outstanding; receiver window 1 (in order only, discards frames after a gap); cumulative ACKs; on a NAK or timeout for frame n, resend n and every frame after it, even those that arrived.
  3. Selective repeat ARQ: receiver buffers frames after a gap and NAKs only the missing one; sender resends just that frame; receiver delivers in order once the gap fills. Both windows at most 2k−1. Costs (the book): sorting logic and a buffer at the receiver for frames held after a NAK; a search at the sender for the frame asked.

Figure: go-back-N and selective repeat with frames 0 to 4 and frame 2 lost; go-back-N discards 3 and 4 and resends 2, 3, 4; selective repeat buffers 3 and 4 and resends only 2, then ACK 5

PointStop and waitGo-back-NSelective repeat
Frames outstanding1up to 2k−1up to 2k−1
Receiver window11 (in order)up to 2k−1
On an error resendthat framethat frame and all afterthat frame only
Receiver bufferone frameone framea window
Efficiencylowgood on clean linksbest on noisy links
Complexityleastmoderatemost

Window limits: with 3-bit numbers, a go-back-N window of 8 and every ACK lost, the old frame 0 resent would be taken as the new frame 0; window 7 avoids it; selective repeat must stay at 4 so old and new receive windows never overlap. Memory example: a student misses line 3 of a dictation; go-back-N re-reads from line 3 to the end, selective repeat re-reads only line 3.

HDLC: stations, modes, the frame and its three frame types

PIN 2/27 Open the full card

HDLC (High-level Data Link Control): a bit-oriented ISO data link protocol (ISO 3309 and 4335, now ISO/IEC 13239) for point-to-point and multipoint links; flag 01111110 with bit stuffing; sliding window and ARQ for flow and error control.

  • Stations: primary (controls the link, sends commands); secondary (under a primary, sends responses); combined (both).
  • Configurations: unbalanced (one primary, one or more secondaries, point to point or multipoint); balanced (two combined stations, point to point, equal responsibility); symmetric (book: each physical station two logical ones, primary and secondary).
ModeConfigurationWho may send
NRM, normal response modeunbalancedprimary starts every exchange; secondary only when polled
ARM, asynchronous response modeunbalancedsecondary sends without permission; primary owns the line (start-up, error recovery, disconnection)
ABM, asynchronous balanced modebalancedeither combined station any time; the usual mode today

Figure: the HDLC frame (flag 8, address 8 or more, control 8 or 16, information variable, FCS 16 or 32, flag 8 bits) and the control field of I (0, N(S), P/F, N(R)), S (1 0, S S, P/F, N(R)) and U frames (1 1, M M, P/F, M M M)

  • Flag (8 bits, 01111110): both ends; bit stuffing keeps it out of the data.
  • Address (8 bits, extendable): the secondary; receiver in a command, sender in a response.
  • Control (8 or 16 bits): frame type and sequence numbers; 16 bits gives 7-bit numbers (modulo 128) instead of 3-bit (modulo 8).
  • Information (variable): network layer data, or management information in a U-frame.
  • FCS (16 or 32 bits): CRC over the frame between the flags.

Frame types:

  • I-frame: user data with N(S) (own number) and N(R) (next expected from the other side, a piggybacked ACK).
  • S-frame: flow and error control, no data: RR (00, receive ready, an ACK), REJ (01, reject, go back to N(R)), RNR (10, receive not ready, stop), SREJ (11, selective reject, resend N(R) only).
  • U-frame: link management: SNRM, SABM (set a mode), DISC (disconnect), UA (unnumbered acknowledgement), FRMR (frame reject).
  • P/F: poll bit in a command (reply wanted), final bit in a response.

Family: LAPB (X.25), LAPD (ISDN D channel), LAPF (frame relay) and PPP's framing come from HDLC. Memory example: the default encapsulation of a Cisco router's serial port (a bank branch's leased line) is HDLC, Cisco's own variant.

PPP: the Point-to-Point Protocol

Open the full card

PPP (Point-to-Point Protocol): the standard data link protocol for a point-to-point link (dial-up, DSL, leased line), RFC 1661; byte-oriented with HDLC-like framing (RFC 1662), plus LCP to manage the link and an NCP per network protocol.

  • Framing: an unambiguous frame with error detection, byte stuffing.
  • LCP (Link Control Protocol): brings the line up, tests it, negotiates options (maximum frame size, authentication, compression), takes it down.
  • NCPs: one per network protocol; IPCP configures IPv4 (gives each end its address).

Figure: PPP frame (flag 0x7E, address 0xFF, control 0x03, protocol 1 or 2 bytes, payload up to 1500 by default, FCS 2 or 4, flag 0x7E) and the phases Dead, Establish, Authenticate, Network, Open, Terminate

Frame: flag 0x7E; address 0xFF (all stations, only two exist); control 0x03 (unnumbered, PPP numbers nothing); protocol 2 bytes (1 if LCP compresses it): 0x0021 IPv4, 0x0057 IPv6, 0xC021 LCP, 0x8021 IPCP, 0xC023 PAP, 0xC223 CHAP; payload up to 1500 bytes by default; FCS 2 bytes (4 if negotiated); flag. Inside: 0x7E sent as 0x7D 0x5E, 0x7D as 0x7D 0x5D.

Phases: Dead (no carrier), Establish (LCP options), Authenticate (optional; PAP clear password, CHAP challenge and hashed reply), Network (NCP, IPCP), Open (data), Terminate (LCP closes), back to Dead; a failed option or login also ends the link.

PointHDLCPPP
Orientationbit-oriented, bit stuffingbyte-oriented, byte stuffing
Addressingstation addressnone (always 0xFF)
Flow and error controlsliding window, ACKs, ARQnone by default; errors only detected
Extrasnoneoption negotiation, authentication, several network protocols

SLIP (Serial Line IP, RFC 1055) came first: wraps IP packets between END bytes; no error detection, no address negotiation, no authentication, no protocol field; replaced by PPP. Memory example: a home fibre router asking for a PPPoE username and password runs PPP over Ethernet (RFC 2516) to log in to the ISP.

The MAC sublayer and the channel allocation problem

HOT 7/27 Open the full card

MAC (medium access control) sublayer: the lower data link sublayer that decides which station may transmit next when many share one broadcast channel (cable, ring, radio band), using a multiple access protocol.

Point-to-point links join two stations (no question who talks); a broadcast link is shared and every station hears every frame; who gets the channel under contention is the MAC sublayer's job.

Why channel access control is essential (its significance):

  • Collisions: two stations sending at once garble both frames; bandwidth wasted, both resent.
  • Efficiency: channel busy with useful frames, few collisions, little idle time.
  • Fairness: every station gets a chance; none hogs the channel.
  • Delay and priority: token passing guarantees worst-case delay and priorities (real-time, factory traffic).
  • Cost: many cheap stations share one medium.

Memory example: a class discussion with no moderator (everyone at once, nothing heard) against a rule (raise a hand, pass a microphone).

The channel allocation problem: how to allocate one broadcast channel among competing users.

Static allocation: fixed portions, 1/N of the bandwidth each (FDM) or one slot in N (TDM). Suits few users with steady traffic (radio, TV, telephone trunks); wastes capacity on bursty data (idle shares lost, busy users cannot borrow). Capacity C bps, frames of mean length 1/μ bits, λ frames per second:

T=1μC−λ,TN=1μ(C/N)−(λ/N)=NT

Example (Tanenbaum's numbers): 100 Mbps, 10,000-bit frames (μC = 10,000 frames/s), 5000 frames/s: T = 200 µs; ten static 10 Mbps channels with a tenth of the traffic: T = 2 ms, ten times worse.

Dynamic allocation: on demand. Tanenbaum's five assumptions: independent stations generating frames at random (station model); one shared channel; collisions observable; continuous or slotted time; carrier sense or not.

Figure: tree of multiple access protocols: random access (ALOHA, CSMA, CSMA/CD, CSMA/CA; Ethernet, Wi-Fi), controlled access (reservation, polling, token passing; token bus, token ring, FDDI), channelization (FDMA, TDMA, CDMA; GSM, 3G)

  • Random access (contention): no station controls another; send when ready, collisions resolved by retrying: ALOHA, CSMA, CSMA/CD, CSMA/CA.
  • Controlled access: turns by agreement, no collisions: reservation, polling, token passing.
  • Channelization: the channel divided by frequency, time or code: FDMA, TDMA, CDMA.

ALOHA: pure and slotted

HOT 6/27 Open the full card

ALOHA: the first random access protocol (ALOHAnet, University of Hawaii, Norman Abramson, 1971): a station transmits whenever it has data; overlapping frames collide and are lost; each sender retries after a random time.

Pure ALOHA: send at once, wait for an ACK (time-out about twice the longest propagation delay); no ACK means a collision: wait a random backoff (Forouzan: R from 0 to 2K−1 frame or propagation times after the Kth attempt, give up after about 15) and resend. Random, or the same two frames collide forever.

Figure: vulnerable time; pure ALOHA, frames starting in (t - T, t + T) overlap the frame sent at t (2T); slotted ALOHA, only a frame in the same slot collides (T)

Vulnerable time: frame time T; a frame sent at t survives only if no other starts in (t−T,t+T) (an earlier one overlaps its head, a later one its tail): 2T. Even a first bit overlapping a last bit destroys both.

Slotted ALOHA (Roberts, 1972): slots of length T; start only at a slot boundary (a station missing it waits for the next); collision only with a frame in the same slot: vulnerable time T. Needs synchronised clocks.

Throughput: G = offered load (frames tried per frame time, new and retried, Poisson); S = successful frames per frame time; probability of no other frame in k frame times e−kG:

Spure=Ge−2G,Smax=12e=0.184 at G=0.5
Sslotted=Ge−G,Smax=1e=0.368 at G=1

Figure: throughput S against G from 0 to 3; slotted peaks at 0.368 at G = 1, pure at 0.184 at G = 0.5; at G = 1 slotted leaves 37 percent of slots empty and 26 percent in collision

PointPure ALOHASlotted ALOHA
Sendsany timestart of a slot only
Timecontinuous, no clockslotted, synchronised
Vulnerable time2TT
No collision whenno other frame starts within T before or after its startno other station sends in the same slot
Success probabilitye−2Ge−G
ThroughputGe−2GGe−G
Maximum18.4 % at G=0.536.8 % at G=1

Example (Forouzan's numbers, checked): 200 kbps, 200-bit frames, T = 1 ms. Pure at 1000 frames/s (G=1): S=e−2 = 0.135, about 135 frames/s; at 500 (G=0.5): 0.184, about 92; at 250 (G=0.25): 0.152, about 38. Slotted at 1000 frames/s: e−1 = 0.368, about 368. Memory example: students shouting answers any time (pure) against only right after the teacher's bell (slotted).

The book's Table 3.1 (p. 82) labels Ge−2G and Ge−G "probability of successful transmission"; they are throughputs; the success probabilities are e−2G and e−G. Efficiency of slotted ALOHA derived in the Numericals panel.

CSMA: listen before talking

PIN 1/27 Open the full card

CSMA (carrier sense multiple access): random access in which a station first listens to the medium and transmits only if it is idle: listen before talk.

Beats ALOHA: never starts during another transmission; at light load throughput approaches 1. Collisions remain through propagation delay: A starts, its signal needs Tp to reach B; B sensing within that time hears nothing and sends too. Vulnerable time = propagation time Tp.

MethodMedium idleMedium busyResult
1-persistentsend at once (probability 1)keep sensing, send the moment it is idleno idle time; waiting stations collide together; Ethernet
Non-persistentsend at oncewait a random time, sense againfewer collisions; idle medium while all wait
p-persistent(slotted) send with probability p; with 1−p wait a slot and repeatwait until idle, then as for idlebalance set by p

Memory example: in a group call, the 1-persistent friend talks the instant there is silence, the non-persistent one checks again later, the p-persistent one tosses a coin at each pause. Limit: plain CSMA does not notice a collision; both send whole frames, wasting a frame time; collision detection fixes it (CSMA/CD).

CSMA/CD: carrier sense with collision detection

TOP 9/27 Open the full card

CSMA/CD: the access method of classic half-duplex Ethernet (IEEE 802.3): sense the carrier, send when idle, keep listening while sending, and on a collision stop at once, send a jam signal and retry after a random binary exponential backoff.

Collision: two or more frames on a shared medium at overlapping times; signals add, both garbled. Cause: stations transmit almost together, each sensing idle before the other's signal arrived (propagation delay), or several waiting for one busy period start together when it ends.

  1. Sense: listen; while busy keep listening (1-persistent).
  2. Transmit: when idle (after the 96-bit interframe gap), send and monitor the medium.
  3. Success: whole frame out with no collision.
  4. Collision: abort at once; send a 32-bit jam signal so every station knows.
  5. Count: attempt counter n + 1; after 16 attempts, give up and report an error.
  6. Back off: K at random from 0 to 2m−1, m=min(n,10); wait K slot times of 512 bit times; back to step 1.

Figure: CSMA/CD flowchart: start (n = 0), sense, idle?, transmit and listen, collision?, whole frame sent? success; on collision jam, n = n + 1, n > 15? abort, else pick K, wait K slots, sense again

Detection: compare what is sent with what is heard; on coax a signal level (voltage, energy) higher than its own; on twisted pair (10BASE-T) activity on the receive pair while transmitting. Must happen while still sending, so a frame lasts at least one round trip:

Tframe≥2Tprop⇒Lmin=2Tprop×B

10 Mbps Ethernet: round-trip budget (2500 m, four repeaters) 51.2 µs, Lmin = 512 bits = 64 bytes; 512 bit times is the slot time.

Binary exponential backoff: K∈{0,1} after the 1st collision; 0 to 3 after the 2nd; 0 to 7 after the 3rd; 0 to 1023 from the 10th on; the range doubles as contention grows.

PointCSMACSMA/CD
Listensbefore sendingbefore and while sending
On a collisionsends the whole damaged framestops at once, short jam
Time wasteda whole frame timeabout 2Tprop plus the jam
Retrypersistence methodbinary exponential backoff, 16 attempts
Needscarrier sensinghearing while sending, a minimum frame
Throughputlowerhigher, less delay

Today: each switch port is a two-station full-duplex link, no collisions, CSMA/CD off; it runs only in half duplex (hubs); Ethernet from 10 Gbps up dropped half duplex. Memory example: a polite argument: speak when quiet, listen as you speak, both stop and say "sorry" (jam), wait a random moment, longer after each clash.

Controlled access: reservation, polling and token passing

Open the full card

Controlled access: stations consult one another, or a controller, to decide who may send; only the station with the right transmits, so no collisions.

  • Reservation: time in intervals; a reservation frame of N mini-slots (one per station) opens each; a station sets its mini-slot; reserved stations send in order. Example: booking a futsal slot in advance.
  • Polling: one primary; every exchange through it. Poll: asks each secondary in turn if it has data; select: asks if a secondary is ready to receive, waits for its ACK, then sends. Weak: polling overhead; the link stops if the primary fails. Examples: HDLC normal response mode, a Bluetooth piconet master, a teacher's roll call.
  • Token passing: a token circulates round a logical ring; only its holder sends, for a limited time, then passes it on. Token management: holding-time limit, priorities, recovery of a lost or duplicate token. Ring: physical (token ring), dual (FDDI) or a bus (token bus). Example: the talking stick in a circle.
PointRandom accessControlled access
Collisionspossiblenone
Delay at light loadvery lowwait for a turn
Heavy loadthroughput falls, delay unpredictablefair, delay bounded
Weak pointcontentionoverhead; failed primary, lost token

Channelization: FDMA, TDMA and CDMA

Open the full card

Channelization: multiple access by sharing out the channel's bandwidth by frequency (FDMA), time (TDMA) or code (CDMA); each station has its own share and does not contend.

  • FDMA: own frequency band with guard bands, used all the time; first-generation analog mobiles. FDM is the same idea in one multiplexer at the physical layer; FDMA is an access method for many stations.
  • TDMA: one band, own time slot, guard times, tight synchronisation. GSM (2G of NTC and Ncell) uses both: each 200 kHz carrier (FDMA) shared by 8 time slots (TDMA).
  • CDMA: all send at once on one band; each multiplies its data by its own chip sequence; codes orthogonal (inner product of two different codes 0, of a code with itself = number of chips); the receiver multiplies the sum by a station's code. 3G.

Example, Walsh codes c1=(+1,+1,+1,+1), c2=(+1,−1,+1,−1), c3=(+1,+1,−1,−1), c4=(+1,−1,−1,+1); bit 1 as +1, 0 as -1, silence 0. Station 1 sends 1, station 2 sends 0: channel carries (0,+2,0,+2). Receiver for station 1: (0+2+0+2)/4=+1 (a 1); station 2: (0−2+0−2)/4=−1 (a 0); station 3: 0 (silent).

Memory example: at a wedding party, FDMA is couples in separate rooms, TDMA turns at one microphone, CDMA pairs talking at once in Nepali, Newari, Maithili and English, each listener following one language.

The IEEE 802 family of LAN standards

Open the full card

IEEE 802: the IEEE's standards for local and metropolitan networks, splitting the data link layer into one LLC sublayer (802.2) and a MAC sublayer plus physical layer per LAN.

StandardCoversStatus
802.1bridging and spanning tree (802.1D), VLAN tagging (802.1Q), port authentication (802.1X), managementactive
802.2logical link controlstable
802.3Ethernet, CSMA/CD, now switched, 10 Mbps to 400 Gbpsdominant wired LAN
802.4token buswithdrawn
802.5token ringwithdrawn
802.11wireless LAN (Wi-Fi), CSMA/CAdominant wireless LAN
802.15personal area networks: Bluetooth (802.15.1), low-rate (802.15.4, under Zigbee)active
802.16broadband wireless access (WiMAX)little used now

Why the split: the network layer sees one LLC interface on any LAN (IP runs unchanged over Ethernet, Wi-Fi, token ring); each LAN keeps the access method suited to its medium. Memory example: a lab laptop uses three at once: Ethernet port 802.3, Wi-Fi card 802.11, the switch's 802.1Q VLANs.

Ethernet (IEEE 802.3): the frame, MAC addresses, data transfer and cabling

PIN 4/27 Open the full card

Ethernet (IEEE 802.3): the dominant wired LAN: frames with 48-bit MAC addresses and a CRC-32, 10 Mbps to 400 Gbps over coax, twisted pair or fiber; shared Ethernet uses 1-persistent CSMA/CD; switched full-duplex Ethernet needs no access method.

History: Xerox PARC, Robert Metcalfe and David Boggs, 1973, about 3 Mbps; DEC, Intel and Xerox made it 10 Mbps (Ethernet II); IEEE 802.3 in 1983. Generations: Standard (10 Mbps), Fast (100 Mbps, 802.3u, 1995), Gigabit (802.3z, 802.3ab), 10 Gigabit (802.3ae, 2002), then 40, 100 and 400 Gbps.

Figure: Ethernet frame (preamble 7, SFD 1, destination 6, source 6, length/type 2, data and pad 46 to 1500, FCS 4 bytes) and a MAC address split into OUI and NIC-specific halves

FieldBytesFunction
Preamble710101010 seven times; wakes the receiver, locks its clock
SFD (start frame delimiter)110101011; the last two 1s say the frame starts
Destination address6receiver MAC: unicast, multicast or broadcast; first, so stations decide early
Source address6sender MAC, always unicast
Length/Type2up to 1500: data length (802.3, LLC follows); 1536 (0x0600) or more: EtherType, 0x0800 IPv4, 0x0806 ARP, 0x86DD IPv6
Data and pad46 to 1500the packet, padded to 46
FCS4CRC-32 over addresses, length/type, data; bad frame dropped

Frame (destination to FCS) 64 to 1518 bytes (1522 with an 802.1Q tag); the 64-byte minimum lets CSMA/CD detect a collision while sending; interframe gap 96 bit times.

MAC address: 48 bits, six hex bytes; first 24 bits the OUI (IEEE number for the maker), last 24 the maker's serial; lowest bit of the first byte (I/G) 0 unicast, 1 multicast; next bit (U/L) global or locally set; all 1s (FF:FF:FF:FF:FF:FF) broadcast; bytes left to right, least significant bit first, so I/G goes first. Examples use 00:00:5E:00:53:01 (documentation block, RFC 7042). Memory example: ipconfig /all shows a laptop card's MAC as "Physical Address".

Data transfer:

  1. Address: ARP finds the receiver's MAC from its IP address.
  2. Encapsulate: the NIC builds the frame and computes the CRC-32 FCS.
  3. Access: half duplex (shared segment, hub): 1-persistent CSMA/CD; full-duplex switch port: just send.
  4. Signal: preamble and SFD for synchronisation, then the line-coded frame (Manchester at 10 Mbps).
  5. Deliver: on a bus every station hears it; a switch looks up the destination in its MAC table (from source addresses) and forwards to that port, or floods if unknown.
  6. Receive: keep only frames for its own, the broadcast or a joined multicast address; check the FCS; drop bad frames and frames under 64 or over 1518 bytes; hand the data up by type.

Connectionless, unacknowledged: a dropped frame is recovered, if at all, by TCP.

Cabling: speed in Mbps, Base = baseband, then medium or segment length in hundreds of metres (10Base5: 10 Mbps baseband, 500 m).

StandardMediumMax segmentNotes
10Base5 (thick)thick coax500 mbus, 1983
10Base2 (thin)thin coax, BNC T-connectors185 mbus
10BaseT2 pairs UTP, Cat 3 or better100 mstar, hub
10BaseF (10Base-FL)multimode fiber pair2000 mstar
100BaseTX2 pairs Cat 5 UTP100 mFast Ethernet, 4B/5B
100BaseFXmultimode fiber pair2000 m (full duplex)Fast Ethernet
1000BaseT4 pairs Cat 5e UTP100 m802.3ab
1000BaseSXmultimode, 850 nm short-wave laser220 to 550 m802.3z
1000BaseLX1310 nm long-wave laser, multimode or single-mode550 m or 5 km802.3z
10GBase-SR, LR, ER850 nm multimode; 1310, 1550 nm single-mode300 m, 10 km, 40 km802.3ae

Fiber standards with examples: fiber beyond copper's 100 m and against electrical noise and lightning, between buildings and up risers. 850 nm multimode, cheap, hundreds of metres: 1000BaseSX between floors or close blocks. 1310 nm single-mode, kilometres: 1000BaseLX or 10GBase-LR to distant buildings (a library 2 km from the data centre). 100BaseFX and 10BaseF are the older 100 and 10 Mbps versions.

The book's Figure 3.34 (p. 89) prints data and padding as "0-46" bytes (it is 46 to 1500) and describes Length as naming the upper-layer protocol (the EtherType meaning; up to 1500 is a length, 1536 or more a type).

Token bus (IEEE 802.4): a physical bus, a logical ring

HOT 5/27 Open the full card

Token bus (IEEE 802.4): stations on a physical bus (linear or tree cable) pass a token in a logical ring ordered by address; only the token holder transmits, for a limited time, then passes the token to its successor.

Figure: five stations (90, 45, 112, 70, 20) on one bus cable, and the same stations as a logical ring 112, 90, 70, 45, 20 and back to 112

Why also called a token ring: physically a bus (every frame reaches all at once), but access follows a ring: each station knows its predecessor and successor; the token goes in descending order of address; the lowest passes it back to the highest. The ring is only in the stations' tables: a logical ring.

  • Sending: the token holder sends until its token holding time runs out, then sends the token to its successor.
  • Priorities: four access classes, 0, 2, 4, 6 (highest), each with a timer.
  • Ring maintenance: claim token (start the ring, replace a lost token); solicit successor (new stations join); who follows and set successor (close the gap when a station leaves or fails).
  • Physical: 75-ohm broadband coax (cable TV type), 1, 5 or 10 Mbps.
  • Frame: preamble, start delimiter, frame control, destination and source addresses (2 or 6 bytes each), data up to 8182 bytes, 4-byte FCS, end delimiter.
  • Use: factory automation (General Motors' MAP): a robot arm needs its command within a known time, which Ethernet's random backoff cannot promise.
Point802.3 Ethernet802.4 Token bus802.5 Token ring
Topologybus, now a switched starphysical bus, logical ringphysical ring, star-wired
AccessCSMA/CDtoken by addresstoken to next station downstream
Collisionsyesnonenone
Worst-case delayunboundedboundedbounded
Prioritiesnone in the MAC0, 2, 4, 68 levels with reservation
Medium, speedcoax, UTP, fiber; 10 Mbps upbroadband coax; 1, 5, 10 MbpsSTP; 4, 16 Mbps
Frame removed bynobody (ends on the bus)nobody (ends on the bus)the sender
Ring upkeepnonedistributedactive monitor
Light loadvery short delaywaits for tokenwaits for token

Memory example: pass the parcel by roll number, not seat: children scattered (bus), parcel in a fixed circle (logical ring).

Token ring (IEEE 802.5): operation and frame format

PIN 4/27 Open the full card

Token ring (IEEE 802.5): IBM's LAN (4 or 16 Mbps): stations in a physical ring of point-to-point links round which a 3-byte token circulates; a station sends only after seizing the free token; its frame goes round, the destination copies it, the sender removes it and releases a new token.

Figure: ring of four stations with a circulating token, the five steps, the data frame (SD 1, AC 1, FC 1, DA 2 or 6, SA 2 or 6, data, FCS 4, ED 1, FS 1), the token (SD, AC, ED) and the AC byte (P P P T M R R R)

Multiple access: one token, so one transmitter at a time, no collisions.

  1. Wait: for the free token (SD, AC, ED).
  2. Seize: set the token bit T in AC to 1 (the token becomes a frame header); append the rest of the frame.
  3. Circulate: each station repeats the bits on (one-bit delay); the destination copies the frame and sets A (address recognised) and C (frame copied) in frame status.
  4. Remove: back at the sender, it strips the frame and reads A, C: 1, 1 delivered; 1, 0 present but not copied; 0, no such station.
  5. Release: a new free token; token holding time at most 10 ms by default; at 16 Mbps early token release right after the frame.
FieldBytesFunction
SD, start delimiter1announces token or frame; deliberate coding violations
AC, access control1PPPTMRRR: 3 priority bits, token bit (0 token, 1 frame), monitor bit, 3 reservation bits
FC, frame control1data or ring management frame
DA, SA2 or 6 eachdestination, source
Datano fixed limitlimited by token holding time
FCS4CRC-32
ED, end delimiter1ends token or frame; flags an error seen on the way
FS, frame status1A and C bits, written twice (outside the FCS)

Priority and reservation: a waiting station with an urgent frame writes its priority into the reservation bits of a passing frame; the next released token carries that priority; only equal or higher priority frames seize it; the raiser lowers it afterwards.

Active monitor (elected): new token when none seen too long (lost token); removes an orphan frame whose sender died (recognised by the monitor bit it set on the first pass); adds delay so the ring holds the 24-bit token.

Physical: 4 or 16 Mbps over shielded twisted pair, differential Manchester; star-wired to wiring centres (MAU) whose relays bypass a switched-off station. Memory example: the talking stick at a circle meeting; a message goes all the way round, so the speaker knows everyone heard it.

FDDI: dual counter-rotating rings and fault tolerance

PIN 3/27 Open the full card

FDDI (Fiber Distributed Data Interface): a 100 Mbps token-passing LAN or backbone on optical fiber (ANSI X3T9.5, ISO 9314), built as two counter-rotating rings: the primary carries data, the secondary stands by, surviving a cut cable or a failed station.

Figure: four dual attachment stations on two counter-rotating rings; after a fiber cut between A and B, both wrap and the rings become one ring of twice the length

Features:

  • 100 Mbps over multimode fiber, later copper (CDDI); 4B/5B coding, line at 125 Mbaud.
  • Dual counter-rotating rings: opposite directions; secondary idle until a fault.
  • Large: up to 1000 physical connections (about 500 dual attachment stations; Tanenbaum rounds it to 1000 stations) on up to 200 km of fiber, stations up to 2 km apart: campus or city backbone.
  • Timed token protocol: a target token rotation time agreed at start-up; guaranteed share for synchronous traffic, the rest for asynchronous; early token release.
  • Frames up to 4500 bytes, CRC-32.
  • Stations: dual attachment station (DAS) on both rings; single attachment station (SAS, such as a PC) on the primary through a concentrator.
  • Fault tolerance: wrapping, optical bypass, dual homing.

Fault tolerance mechanism:

  1. Cable cut: the two stations beside the break detect loss of signal and wrap (join primary to secondary inside themselves); the dual ring becomes one ring of twice the length, every station still reached.
  2. Failed station: its neighbours wrap, cutting it out; or an optical bypass switch passes the light through a switched-off station, no wrap needed.
  3. Failed SAS: its concentrator cuts it off; the ring never notices.
  4. Dual homing: a critical server or router on two concentrators; the backup takes over.

Limit: two faults at once split the network into two separate rings. Memory example: Kathmandu's Ring Road with lanes both ways; a blocked stretch, traffic turns back and goes round the other way, every chowk still reached. The book (p. 93) expands FDDI as "Fiber Distribution Data Interface"; the name is Fiber Distributed Data Interface.

Wireless LAN (IEEE 802.11): architecture, CSMA/CA and the physical layer

PIN 3/27 Open the full card

IEEE 802.11 (Wi-Fi): the wireless LAN standard; physical layer (radio in 2.4, 5, 6 GHz) and MAC sublayer, whose access method is CSMA/CA (collision avoidance), optionally with RTS and CTS.

Architecture: basic service set (BSS), stations sharing one channel; ad hoc (independent BSS) stations talk directly; infrastructure BSS, every frame through an access point (AP); BSSs joined by a distribution system (usually wired Ethernet) form an extended service set (ESS) with one SSID; stations roam between APs.

Figure: ad hoc BSS, infrastructure BSS around an AP, and an ESS of two BSSs whose APs hang off a distribution system, a station roaming between them

Why CSMA/CD is not applicable:

  • A radio cannot listen while sending: its own signal is millions of times stronger; detection needs costly full-duplex radios.
  • Hidden station: A and C both reach B but not each other; while A sends to B, C senses idle and sends; collision at B, neither sender knows.
  • Collisions happen at the receiver; a sender senses only where it is, and signals fade with distance.
  • Exposed station: C hears B sending to A and holds back, though its frame to D could not disturb A.

Figure: hidden station (A and C out of each other's range, frames collide at B) and exposed station (C defers to B's transmission though its frame to D would not reach A)

CSMA/CA, the distributed coordination function:

  1. Sense: wait until the channel has been idle for a DIFS.
  2. Back off: random number of slots from the contention window, counted down only while idle, frozen while busy.
  3. Send when the count reaches zero.
  4. Acknowledge: receiver waits a SIFS and sends an ACK; no ACK means likely collision: double the contention window and retry.
  5. RTS and CTS (large frames): short RTS carrying the exchange's duration; receiver's CTS with the same time; every station hearing either sets its NAV (network allocation vector) and stays quiet: virtual carrier sensing. A hidden station misses the RTS but hears the CTS.

Figure: timing of DIFS, backoff, RTS, SIFS, CTS, SIFS, DATA, SIFS, ACK; station C's NAV from the RTS, hidden station D's NAV from the CTS; then DIFS and a new backoff

Interframe spaces: SIFS < PIFS < DIFS; ACK and CTS wait only a SIFS, so they always win the channel. The optional point coordination function lets the AP poll stations.

PointIEEE 802.3 EthernetIEEE 802.11 Wi-Fi
Access methodCSMA/CDCSMA/CA
Strategydetect fast and stopavoid beforehand
Before sendingsense, send when idle (1-persistent)sense, DIFS, random backoff
During sendinglisten; on a collision jam and back offcannot listen; relies on the ACK
Extra tools64-byte minimum frame, binary exponential backoff; switches remove collisionsRTS/CTS with NAV, ACK for every frame, contention window doubling

Physical layer: original 802.11 (1997), 1 and 2 Mbps in 2.4 GHz, FHSS or DSSS (and infrared).

  • FHSS: carrier hops among 79 channels of 1 MHz in a pseudo-random order known to both ends, at most 400 ms per hop; narrowband interference spoils a hop or two. Bluetooth hops too.
  • DSSS: each bit replaced by the 11-chip Barker sequence (10110111000 for 1, its inverse 01001000111 for 0) at 11 Mchips/s; spread over a 22 MHz channel; the receiver correlates with the same sequence; the wanted signal adds up, narrowband interference and echoes are spread out and suppressed (processing gain about 10.4 dB, 10log1011). 802.11b kept the 22 MHz channel and reached 11 Mbps with CCK coding.
  • OFDM: many narrow subcarriers at once; every later version.
VersionYearBandTop rateTechnique
802.11b19992.4 GHz11 MbpsDSSS (CCK)
802.11a19995 GHz54 MbpsOFDM
802.11g20032.4 GHz54 MbpsOFDM
802.11n (Wi-Fi 4)20092.4 and 5 GHz600 MbpsOFDM, MIMO
802.11ac (Wi-Fi 5)20135 GHzabout 6.9 Gbpswide channels, multi-user MIMO
802.11ax (Wi-Fi 6, 6E)20212.4, 5, 6 GHzabout 9.6 GbpsOFDMA

Frame (book Figure 3.41): frame control (2: version, type, subtype, To DS, From DS, more fragments, retry, power management, more data, protected (WEP), order), duration (2, the NAV value), up to four addresses (6 each), sequence control (2), body (0 to 2312), CRC (4). Security (WEP, WPA) is chapter 8's. The book (p. 92) lists 802.11a, b, g and calls 802.11n the latest; 802.11ac and 802.11ax have come since. Memory example: two students shouting answers from opposite ends of a big hall, unheard by each other, clash at the teacher in the middle; RTS/CTS is raising a hand and waiting for the teacher's "yes, you", which everyone hears.

Virtual LANs and IEEE 802.1Q, with a two-VLAN design

PIN 3/27 Open the full card

VLAN (virtual LAN): a logical group of stations on one or more switches behaving as a separate LAN, one broadcast domain, defined by configuration (port, MAC address, IP address, application), not wiring.

Problem solved: all ports of a plain switch share one broadcast domain (ARP, DHCP broadcasts reach every PC); per-department switches would need rewiring on every move; a VLAN switch does it in software.

  • Smaller broadcast domains: broadcasts stay inside their VLAN.
  • Security: students cannot reach the department's servers at layer 2; inter-VLAN traffic passes a router that can filter.
  • Flexibility: grouping by function, not location; a move is a port's VLAN change, not cabling.
  • Cost and performance: one switch serves several groups; easier management.

Membership (the book's four): switch port (static, most common), MAC address, IP address, application. The book separates single-switch VLANs from multi-switch VLANs (which need a trunk).

IEEE 802.1Q: a trunk carries frames of many VLANs; a 4-byte tag after the source address: TPID (16 bits) 0x8100; PCP (3 bits) priority (802.1p); DEI (1 bit) drop first under congestion; VID (12 bits) VLAN ID, 4096 values, 0 and 4095 reserved, so 1 to 4094. An access port belongs to one VLAN and carries untagged frames; the switch tags on entering a trunk and untags at the access port; untagged trunk frames belong to the native VLAN.

Routing between VLANs (two subnets): router or layer 3 switch; router on a stick: one router port, one subinterface per VLAN, one trunk.

Figure: router R1 (G0/0.10 192.168.10.1/24, G0/0.20 192.168.20.1/24) on an 802.1Q trunk to switch S1; Fa0/1 to 0/12 VLAN 10 STUDENT, Fa0/13 to 0/24 VLAN 20 DEPARTMENT; the 802.1Q tag fields

VLANPortsSubnetGatewayHosts
10 STUDENTFa0/1 to Fa0/12192.168.10.0/24192.168.10.1192.168.10.11, .12
20 DEPARTMENTFa0/13 to Fa0/24192.168.20.0/24192.168.20.1192.168.20.11, .12
S1(config)# vlan 10
S1(config-vlan)# name STUDENT
S1(config-vlan)# vlan 20
S1(config-vlan)# name DEPARTMENT
S1(config-vlan)# exit
S1(config)# interface range fastEthernet 0/1 - 12
S1(config-if-range)# switchport mode access
S1(config-if-range)# switchport access vlan 10
S1(config-if-range)# interface range fastEthernet 0/13 - 24
S1(config-if-range)# switchport mode access
S1(config-if-range)# switchport access vlan 20
S1(config-if-range)# interface gigabitEthernet 0/1
S1(config-if)# switchport mode trunk
R1(config)# interface gigabitEthernet 0/0
R1(config-if)# no shutdown
R1(config-if)# interface gigabitEthernet 0/0.10
R1(config-subif)# encapsulation dot1Q 10
R1(config-subif)# ip address 192.168.10.1 255.255.255.0
R1(config-subif)# interface gigabitEthernet 0/0.20
R1(config-subif)# encapsulation dot1Q 20
R1(config-subif)# ip address 192.168.20.1 255.255.255.0

Each PC uses its VLAN's subnet and gateway; show vlan brief lists the ports per VLAN; a student-to-department ping succeeds only through R1. Layer 3 switch alternative: interface vlan 10 and interface vlan 20 with the gateway addresses, and ip routing. Memory example: two WhatsApp groups on one phone: same hardware (the switch), separate conversations; passing something between them takes a deliberate forward (the router).

Chapter 4: Network layer 11900 words

The network layer: what it does, and why it is the key layer

PIN 1/27 Open the full card

Network layer: layer 3 of the OSI model. Delivers a packet from the source host to the destination host, possibly across many networks, by giving every interface a logical address and having routers choose the path one hop at a time.

Three scopes of delivery: the data link layer moves a frame across one link, node to node (hop to hop); the network layer moves a packet from source host to destination host across all links between (host to host); the transport layer moves a message between two processes in those hosts (process to process, by port).

Figure: two hosts running all five layers and two routers running only network, data link and physical; the packet's source and destination IP stay the same end to end, while each link carries a new frame with new MAC addresses.

At every router the frame is opened, the packet read, and a new frame built for the next link with new MAC addresses; the IP addresses never change (only TTL does).

Functions
  • Logical addressing: every host and router interface gets an IP address unique across the internetwork; each packet header carries source and destination address. A MAC address works only inside one link.
  • Routing: routers run routing algorithms and protocols to learn the networks and build routing tables.
  • Forwarding: for each arriving packet, look up the destination in the table and send it out of the matching interface.
  • Packetizing: wrap the transport segment in a packet with its own header at the source, unwrap at the destination (encapsulation).
  • Fragmentation and reassembly: a packet bigger than the next link's MTU is split; the destination rebuilds it.
  • Internetworking: one packet format and one address space hide different link technologies (Ethernet, Wi-Fi, fibre, leased WAN lines).
  • Error reporting and diagnostics: ICMP tells the source why delivery failed; ping and traceroute.
  • Congestion control and QoS: routers queue, drop or prioritise packets (type of service field); end-to-end control belongs to the transport layer.

Two kinds of service: datagram (connectionless): each packet carries the full destination address and is routed on its own (IP); virtual circuit (connection-oriented): a path is set up first and packets carry a short circuit number (X.25, ATM, MPLS).

LayerDeliversUnitAddressDevice
Data link (2)node to node, one linkframeMAC, 48 bitsswitch, bridge
Network (3)host to host, across networkspacket (datagram)IP, 32 bitsrouter
Transport (4)process to processsegmentport, 16 bitsend hosts only
Why it is the key layer
  • Highest layer on the path: routers implement layers 1 to 3, so layer 3 is the top layer every node between the hosts understands; the path is decided here.
  • Narrow waist: many applications and two transport protocols above, many link technologies below, one network protocol in the middle (IP over everything, everything over IP); replacing Wi-Fi with fibre changes no application.
  • Global addressing that scales: hierarchical addresses let a router keep one route per network, not per host.
  • Without it a frame could never leave its own LAN.

Example: a parcel from Pulchowk to Pokhara: the address (district, municipality, ward, name) is the IP address; each post office is a router looking only at the district; the bus between two offices is the data link and changes at every office; the address never does.

Internetworking devices, layer by layer

PIN 4/27 Open the full card

Internetworking device: hardware joining network segments or whole networks. Each works at one OSI layer, and the layer fixes what it can read (bits, frames, packets, whole messages) and so how much it can decide. A repeater sees only a signal, so it copies it; a switch reads MAC addresses, so it picks one port; a router reads IP addresses, so it picks a path between networks; a gateway reads whole messages, so it translates protocols.

Figure: the seven OSI layers as rows, with repeater and hub at layer 1, bridge and switch at layer 2, router at layer 3 and the gateway spanning layers 4 to 7.

  • Repeater (physical): receives a weakened, noisy signal and regenerates it at full strength on its other port; restores bits without reading them; extends a cable beyond its limit (500 m for a thick coaxial 10BASE5 segment). Two ports, no intelligence; every bit, collisions included, is copied, so both sides stay one collision domain. 10 Mbps Ethernet's 5-4-3 rule: at most five segments, four repeaters, stations on only three segments. Not an amplifier: an amplifier boosts noise too, a repeater rebuilds a clean digital signal.
  • Hub (physical): multiport repeater; a signal on one port is copied to every other port; all ports share one bandwidth and one collision domain; half duplex. Active hub: powered, regenerates. Passive hub: only joins the wires.
  • Bridge (data link): joins two LAN segments, reads MAC addresses, records which station is on which side, forwards a frame only when its destination is on the other side; each side its own collision domain; broadcasts still cross.
  • Switch (data link): multiport bridge with a MAC address table; sends each frame only to the destination's port; floods unknown and broadcast frames; each port its own collision domain, and full-duplex ports have no collisions. Modes: store-and-forward (whole frame received, FCS checked: reliable, usual default), cut-through (forwards once the destination MAC is read: fastest, passes bad frames), fragment-free (waits for the first 64 bytes, where collision fragments show). Managed switches add VLANs, port security, monitoring; a layer 3 switch also routes between VLANs.
  • Router (network): joins different networks (subnet to subnet, LAN to WAN); forwards packets by destination IP using a routing table configured by hand or built by routing protocols; each interface is its own network and broadcast domain (no broadcasts forwarded); decrements TTL, fragments, often does NAT and filtering.
  • Gateway (up to application): protocol converter joining networks with different protocol stacks: email gateway, VoIP to telephone gateway, IoT (Zigbee to IP) gateway. In TCP/IP the "default gateway" of a host is the router for off-subnet packets.
  • NIC: layers 1 and 2, carries the MAC address. Modem (or a fibre ONT): converts the digital signal to the line's analogue or optical signal, layer 1.
DeviceLayerReadsUnicast sent toCollision domainsBroadcast domains
Repeater1signalother portone, sharedone
Hub1signalevery other portone for allone
Bridge2MACdestination's sideone per portone
Switch2MACdestination's portone per portone (one per VLAN)
Router3IPnext hop on best pathone per interfaceone per interface
Gatewayup to 7whole messageother network, translatedseparateseparate
Switch instead of hub
  1. Dedicated bandwidth: a 24-port 100 Mbps hub shares 100 Mbps among 24 PCs; a switch gives each port 100 Mbps and carries many conversations at once.
  2. No collisions: each port its own collision domain; with full duplex CSMA/CD never fires; a hub's one collision domain collapses under load.
  3. Full duplex: send and receive together; hub half duplex.
  4. Privacy and security: unicast frames reach only their owner; on a hub every PC receives every frame (sniffing).
  5. Features: VLANs, port security, QoS, link aggregation, monitoring.
  6. Cost: the gap has closed; hubs are no longer made.
Router against gateway
PointRouterGateway
Jobforwards packets between networkstranslates between networks with different protocols
Layer3any, usually 4 to 7
Protocols on its sidessame (IP)different stacks
Decides bydestination IP and routing tablethe message's protocol and content
Changesonly header fields (TTL, checksum)the format (protocol conversion)
ExamplesISP core router, home Wi-Fi routeremail, VoIP, IoT gateways

The book places the gateway at "the session layer and above"; most texts allow any layer up to application.

Example: hostel letters: hub, a warden reading every letter aloud in the corridor; switch, a warden sliding each letter under the right door; router, the post office sending letters to other cities; gateway, a translator rewriting a Japanese letter in Nepali.

Bridges: learning, filtering and forwarding

PIN 1/27 Open the full card

Bridge: a data link layer device that joins LAN segments and forwards each frame by its destination MAC address: it records which station lives on which port, filters frames that stay local and forwards only those meant for another segment.

Transparent bridge (IEEE 802.1D): stations do not know it exists; no setup; it hears every frame on every port and builds its MAC table (forwarding database) from source addresses. A switch works the same way with more ports.

Figure: segment 1 (A, B) and segment 2 (C, D) joined by a two-port bridge with its MAC table; a frame A to B filtered, A to C forwarded, A to an unknown address flooded.

Handling one frame
  1. Receive the frame on a port.
  2. Learn: record source MAC against arrival port, with the time.
  3. Look up the destination: filter (drop) if on the arrival port; forward out of that port only if elsewhere; flood to all ports except the arrival port if unknown, broadcast or multicast.
  4. Age: entries not refreshed within 300 seconds (default) are deleted, so a moved station is found again.

Example, empty table, A and B on port 1, C and D on port 2:

FrameLearnsDestinationActionTable after
A to CA on 1C unknownflood to port 2A-1
C to AC on 2A on 1forward to port 1A-1, C-2
B to AB on 1A on 1 (arrival port)filterA-1, C-2, B-1
D broadcastD on 2broadcastflood to port 1A-1, C-2, B-1, D-2
Throughput against a repeater
  • Repeater: copies every bit, so the segments stay one collision domain sharing one channel: total throughput at most one segment's capacity C; more stations, more collisions.
  • Bridge: local frames stay local; both segments carry traffic at once; only crossing frames load both. Each segment offers load L, fraction f crosses: L+fL≤C, so
total throughput=2L=2C1+f
  • With 100 Mbps segments and f = 0.2: 166.7 Mbps against 100 Mbps; all traffic local: 200 Mbps.
  • Collisions stay on their own segment; store-and-forward gives each side its own CSMA/CD distance limit, so the LAN can be longer.
  • Bad frames (FCS errors, collision fragments) dropped; segments of different speeds can be joined.
  • Limits: broadcasts still cross; store-and-forward adds delay.

Loops and the Spanning Tree Protocol: two bridges between the same LANs make a loop: a broadcast circulates for ever (broadcast storm) and MAC tables flap. STP (IEEE 802.1D, Radia Perlman, 1985): bridges exchange BPDUs, elect a root bridge (lowest bridge ID: priority, default 32768, then MAC), block redundant ports to leave a tree; a blocked port opens if an active link fails. Rapid STP (802.1w) converges in seconds.

TypeHow it worksWhere
Transparent (learning)builds its own table; stations unawareEthernet (802.1D)
Source routingsender writes the route of bridges into the frametoken ring (802.5)
Translationalconverts frame formatsEthernet to token ring or FDDI
Remotea pair joins two LANs over a WANtwo offices

The book calls source routing bridges "routing bridges" and the bridge "a two port switch".

Example: the guard at the gate between two hostel blocks notes who lives where; a letter within one block never passes the gate.

IPv4 addresses: classes, special and private addresses

HOT 5/27 Open the full card

IPv4 address: a 32-bit logical address of an interface, written in dotted decimal as four octets (192.168.10.37), split into a network part (which network) and a host part (which interface on it).

  • Notation: four bytes 0 to 255; 192.168.10.37 = 11000000.10101000.00001010.00100101.
  • Address space: 232 = 4,294,967,296 addresses; IANA gave out its last blocks in February 2011; APNIC (serving Nepal and Asia-Pacific) reached its final block in April 2011.
  • Network and host part: like a phone number's area code and line number; routers look only at the network part.
Logical against physical address
PointPhysical (MAC)Logical (IP)
Layerdata linknetwork
Size48 bits, 12 hex digits32 bits (IPv4), 128 (IPv6)
Assigned bymanufacturer, in the NICadministrator or DHCP
Structureflat: OUI and serial, no locationhierarchical: network and host
Scopeone link, replaced at every hopend to end (unless NAT)
Changes whencard replacedhost moves to another network
Used byswitches, within a LANrouters, between networks

Why IP although MAC exists:

  1. A MAC address says who, not where; flat, so routers would need an entry per device; IP's network part lets one route cover a network, and routes can be summarised.
  2. A MAC address works on one link only; frames are re-addressed each hop; the IP address stays end to end.
  3. Links differ: Ethernet and Wi-Fi have MACs, serial, PPP and cellular use other schemes or none; IP is uniform over all.
  4. Hardware changes: a new card changes the MAC, not the IP; a moved laptop's new IP shows its new location.
  5. Planning: IP addresses can be laid out by department and subnetted. ARP joins the two at the last hop.

Example: a citizenship certificate number (identity, no location) against a postal address (district, municipality, ward, which changes when you move).

Classful addressing

Figure: the five class formats as 32-bit bars with their first bits and network and host octets.

ClassFirst bitsRangeDefault maskNetworksHosts each
A00.0.0.0 to 127.255.255.255255.0.0.0 (/8)27 = 128 (126 usable)224−2 = 16,777,214
B10128.0.0.0 to 191.255.255.255255.255.0.0 (/16)214 = 16,384216−2 = 65,534
C110192.0.0.0 to 223.255.255.255255.255.255.0 (/24)221 = 2,097,15228−2 = 254
D1110224.0.0.0 to 239.255.255.255nonemulticast groupsnone
E1111240.0.0.0 to 255.255.255.255nonereserved, experimentalnone
  • Minus two: host part all 0s is the network address, all 1s the directed broadcast.
  • Finding the class: first octet; 172.20.5.9 is class B, network 172.20.0.0, host 5.9.
  • The book counts 27 class A networks; 0.0.0.0/8 and 127.0.0.0/8 are reserved, so 126 are usable. Its notation example prints the first octet of 128.11.3.31 with nine bits; it is 10000000.
Special addressMeaning
host part all 0sthe network itself
host part all 1sdirected broadcast
255.255.255.255limited broadcast, never routed
0.0.0.0this host (before it has an address); 0.0.0.0/0 is the default route
127.0.0.0/8loopback
169.254.0.0/16link-local, self-assigned when DHCP fails

Private addresses (RFC 1918): 10.0.0.0/8 (one class A, 16,777,216), 172.16.0.0/12 (172.16 to 172.31, sixteen class B, 1,048,576), 192.168.0.0/16 (256 class C, 65,536); never routed on the Internet; reach it through NAT. Carrier-grade NAT uses 100.64.0.0/10 (RFC 6598).

Why classful failed: waste (a company of 2,000 hosts took a class B, 63,534 unused); too few class B networks (16,384); a route per class C network; rigid sizes; D and E unusable for hosts. Fixes: subnetting (1985), CIDR (1993), NAT, IPv6.

Subnetting and VLSM: dividing a block with the least waste

TOP 24/27 Open the full card

Subnetting: dividing one network into smaller subnetworks by borrowing bits from the host part; each subnet has its own network address, broadcast address and host range, and a longer subnet mask shows where its network part ends.

Subnet mask: 32 bits, 1s over network and subnet bits, 0s over host bits; written 255.255.255.192 or /26. ANDing an address with its mask gives the network address:

Address  130.45.32.56   10000010.00101101.00100000.00111000
Mask     255.255.0.0    11111111.11111111.00000000.00000000
AND      130.45.0.0     10000010.00101101.00000000.00000000

Inside an octet: 192.168.10.150/26: 150 AND 192 = 10010110 AND 11000000 = 10000000 = 128: subnet 192.168.10.128/26, broadcast .191, hosts .129 to .190.

Contribution to address management
  • Less waste: the block is cut to fit departments.
  • Smaller broadcast domains: ARP and other broadcasts stay in one subnet.
  • Security and policy: traffic between subnets passes a router or firewall with access rules.
  • Easier management: an address tells the department or floor; faults stay in one subnet.
  • Hierarchy: the outside world sees one route for the whole block.
  • Room to grow: each department gets its own range.
The numbers

For s borrowed bits and h host bits left, with m the last non-255 mask octet:

subnets=2shosts=2h−2block size=2h=256−m

Network addresses are multiples of the block size; each broadcast is one less than the next network; usable hosts lie between.

PrefixMaskBlockUsable hosts
/24255.255.255.0256254
/25255.255.255.128128126
/26255.255.255.1926462
/27255.255.255.2243230
/28255.255.255.2401614
/29255.255.255.24886
/30255.255.255.25242

Above /24 the same in the third octet: /23 = 512 (2 in the third octet), /22 = 1,024 (4), /21 = 2,048, /20 = 4,096.

FLSM (one mask for all): four equal subnets of 192.168.10.0/24 borrow 2 bits: /26 at .0, .64, .128, .192, 62 hosts each. N equal parts: smallest s with 2s≥N; five departments need 3 bits, 8 subnets, 3 spare.

VLSM

VLSM (variable length subnet mask): each subnet gets its own mask. Used when subnets need different numbers of hosts (unequal departments; point-to-point links needing 2 addresses). With one mask all subnets must fit the largest: 100 and 10 hosts in two /25s waste 26 + 116 = 142 usable addresses; VLSM's /25 and /28 waste 26 + 4 = 30. Keeps the plan hierarchical and summarisable. Needs classless routing protocols (RIPv2, OSPF, EIGRP, IS-IS, BGP; not RIPv1 or IGRP).

Method:

  1. Find the block: if host bits are set, AND with the mask (202.83.54.91/25 gives block 202.83.54.0/25, .0 to .127).
  2. Size each demand: smallest h with 2h−2≥ hosts; prefix 32 minus h; block 2h. Point-to-point link: /30 (block 4).
  3. Sort largest first: keeps every subnet aligned on a multiple of its own size.
  4. Allocate from the start of the block: each subnet begins where the last ended; links last.
  5. Each row: network, mask, first usable (network + 1), last usable (broadcast minus 1), broadcast (next network minus 1).
  6. Waste: per subnet, wasted = (2h−2) minus hosts; unused range = from the end of the last subnet to the end of the block.
  7. Check: blocks add up to no more than the given block.

Figure: 192.168.10.0/24 drawn to scale with the /26, /27, /28 and two /30 subnets and the unused range, with a zoom on .96 to .127.

Example: 192.168.10.0/24 for Accounts 60, Library 25, Hostel office 10 and two router links:

SubnetHostsBlockNetworkMaskUsableBroadcastWasted
Accounts6064192.168.10.0/26255.255.255.192.1 to .62.632
Library2532192.168.10.64/27255.255.255.224.65 to .94.955
Hostel office1016192.168.10.96/28255.255.255.240.97 to .110.1114
Link R1 to R224192.168.10.112/30255.255.255.252.113 to .114.1150
Link R2 to R324192.168.10.116/30255.255.255.252.117 to .118.1190

Unused range: 192.168.10.120 to 192.168.10.255 (136 addresses); 11 usable addresses wasted inside the subnets.

Points that cost marks
  • Hosts need two extra addresses: 30 hosts fit a /27, 31 need a /26.
  • A block starts on a multiple of its size: a /27 at .0, .32, .64, never .40.
  • Point-to-point links take a /30 each; RFC 3021 allows /31 but papers expect /30.
  • Subnet zero: RFC 950 dropped the first and last subnets (2s−2); since RFC 1878 all 2s are used, as the book does.
  • Each LAN's default gateway takes one usable address; host counts include it unless stated.
  • The book's worked problems print some ranges wrongly: the first usable host of 202.83.54.64/27 as .64 (it is .65), a range ending at the broadcast .127 (should be .126), a /22's block of 4 without saying it is in the third octet (1,024 addresses), and a "class C" pool written 190.16.0.0 (class B). Some answers count wasted as block minus hosts (including network and broadcast): state the count used.

Example: departments seated in a 256-seat hall in power-of-two blocks, biggest first; first and last seat of each block empty (network, broadcast).

Classless addressing: CIDR and supernetting

PIN 2/27 Open the full card

Supernetting: combining several contiguous networks (typically class C /24s) into one larger block with a shorter prefix, so a single route covers them all; also called route aggregation or summarisation.

CIDR (classless inter-domain routing): RFC 1519 (1993), now RFC 4632. Drops the classes: a block is any power-of-two run of addresses written a.b.c.d/n, n = prefix length (leading network bits). ISPs hand out blocks that fit (a /22 for 1,000 hosts) and routing tables shrink.

  • CIDR block rules: 232−n addresses; first address divisible by the size (aligned); first address = network, last = broadcast.
  • Supernetting rules: networks contiguous; number a power of two; first network on a boundary of the combined size.

Figure: the third octets of four /24 networks in binary, the first six bits equal, merging into 192.168.4.0/22.

Example: 192.168.4.0/24 to 192.168.7.0/24: third octets 00000100, 00000101, 00000110, 00000111; first six bits agree, last two take all values; common prefix 16 + 6 = 22 bits: supernet 192.168.4.0/22, mask 255.255.252.0, 1,024 addresses (192.168.4.0 to 192.168.7.255); one route replaces four.

Trap: 192.168.5.0 to 192.168.8.0 are contiguous but 5 is not a multiple of 4: no single /22; best is 192.168.5.0/24, 192.168.6.0/23, 192.168.8.0/24.

Use: an ISP advertises only its large block for many customer blocks. Overlapping routes are chosen by longest prefix match (most specific wins).

PointClassfulClassless (CIDR)
Network partfixed by class: 8, 16 or 24 bitsany length /n
Block sizes16,777,216, 65,536 or 256any power of two
Maskimplied by first bitscarried with the address
Wastelargesmall
Routing tableone route per classful networkaggregated, longest prefix match
Example192.168.1.0 is class C, /24192.168.1.0/26 is a block of 64
PointSubnettingSupernetting
Doesdivides one networkjoins several networks
Masklonger (bits borrowed from host part)shorter (bits given back)
Purposeorganise and conserve addresses inside an organisationshrink routing tables
Used bynetwork administratorsISPs, backbone routers

Example: a bus stops once at the mouth of a lane instead of at each of four houses on it, only if the houses are adjacent on the same lane.

NAT: many private hosts behind one public address

Open the full card

NAT (network address translation, RFC 3022): a router function that rewrites the private source address (and port) of outgoing packets to a public address, records the pair, and reverses it for replies, so a private network can use the Internet.

  • Why: private RFC 1918 addresses are free but never routed; public IPv4 addresses ran out.
  • Static NAT: one private address always to one public address (publishing a server).
  • Dynamic NAT: private addresses take public ones from a pool while needed.
  • PAT (NAPT, overload): many private hosts share one public address, told apart by port; every home and hostel router does this.

PAT steps: outgoing: replace source 192.168.1.10:51000 with 203.0.113.5:62001 and record it; incoming reply to 203.0.113.5:62001 rewritten to 192.168.1.10:51000; entry removed when the connection ends or idles.

Inside (private)        Outside (public)       Remote server
192.168.1.10:51000  ->  203.0.113.5:62001  ->  198.51.100.20:443
192.168.1.11:49200  ->  203.0.113.5:62002  ->  198.51.100.20:443
  • Gains: saves public addresses; hides the inside layout; ISP can change without renumbering.
  • Costs: breaks end to end (inbound connections need port forwarding); trouble for peer-to-peer, games, VoIP; protocols carrying addresses in their data (FTP) need help; rewriting the header defeats IPsec AH. ISPs also run carrier-grade NAT on 100.64.0.0/10, so a customer may sit behind two NATs.
  • DHCP: the same router usually hands each device its private address, mask, gateway and DNS server.

Example: a hostel with one postal address; the office notes the room number of each sender and hands replies to the right room.

The IPv4 datagram: the header, fragmentation, and why 65,495

HOT 5/27 Open the full card

IP (Internet Protocol, version 4, RFC 791): the Internet's network layer protocol: a connectionless, best-effort datagram service. Each datagram has a 20 to 60 byte header with source and destination addresses and is routed on its own; no promise it arrives, arrives once, or in order.

  • Best effort: no acknowledgements, no connection, no retransmission; datagrams can be lost, duplicated, delayed, reordered; only the header is error-checked; TCP adds reliability, ICMP reports problems. Like ordinary (unregistered) post.
  • What IP does: addresses each datagram, forwards hop by hop, fragments for small MTUs, limits lifetime with TTL, names the upper-layer protocol.

Figure: the IPv4 header as rows of 32 bits: version, IHL, type of service, total length; identification, flags, fragment offset; TTL, protocol, header checksum; source address; destination address; options and padding.

FieldBitsJob
Version44 for IPv4
IHL4header length in 32-bit words: 5 (20 bytes) to 15 (60 bytes)
Type of service8treatment; now 6 bits DSCP (QoS) and 2 bits ECN (congestion)
Total length16header plus data in bytes, at most 216−1 = 65,535
Identification16same on every fragment of one datagram
Flags3reserved 0, DF (do not fragment), MF (more fragments)
Fragment offset13position of the fragment's data, in 8-byte units
Time to live8hop limit: each router subtracts 1, drops at 0
Protocol81 ICMP, 2 IGMP, 6 TCP, 17 UDP, 89 OSPF
Header checksum16over the header only; recomputed every hop (TTL changes)
Source address32sender
Destination address32final receiver
Options and padding0 to 320record route, timestamp, source route; padded to 32 bits
TTL and the protocol field
  • TTL: limits lifetime so a datagram in a routing loop dies; each router subtracts 1; at 0 the router discards it and sends ICMP time exceeded to the source; initial values 64 (Linux), 128 (Windows), 255 (many routers); at most 255 hops; traceroute uses it.
  • Protocol: the network layer's demultiplexing number (as a port is for transport): 6 TCP, 17 UDP, 1 ICMP; IPsec 50 (ESP), 51 (AH).
  • The book says TTL is time in seconds: RFC 791 defined seconds but required each router to subtract at least 1, and no router counts seconds, so it is a hop count (IPv6: hop limit). The book also prints the maximum length as 65,635 on one page; it is 65,535.
Fragmentation and reassembly

MTU: largest datagram a link's frame carries (Ethernet 1,500 bytes); a datagram may be up to 65,535.

  1. Check DF: if set, drop and send ICMP "fragmentation needed" with the link MTU (path MTU discovery).
  2. Split the data to fit the MTU after the header; every piece but the last a multiple of 8 bytes.
  3. Copy the header onto each piece: same Identification, own Total length, MF = 1 except the last, Fragment offset = first byte position / 8.
  4. Send fragments as independent datagrams; later routers may fragment again.
  5. Reassemble at the destination host only: fragments with the same source, destination, protocol and Identification, ordered by offset, last one known by MF = 0, under a reassembly timer; a missing fragment at timeout discards the whole datagram.

Figure: a 4,000 byte datagram split into fragments carrying bytes 0 to 1,479, 1,480 to 2,959 and 2,960 to 3,979 with offsets 0, 185 and 370.

Example: total 4,000 bytes (20 header, 3,980 data), Identification 4321, MTU 1,500: data per fragment 1,500 minus 20 = 1,480 (185 x 8).

FragmentData bytesOriginal bytesOffsetMFTotal length
11,4800 to 1,479011,500
21,4801,480 to 2,95918511,500
31,0202,960 to 3,97937001,040

Check: 1,480 + 1,480 + 1,020 = 3,980. Reassembly only at the destination since fragments may take different paths; IPv6 routers never fragment, only the source.

Why 65,495

A TCP segment travels inside one IP datagram; the 16-bit Total length caps a datagram at 65,535 bytes including the header; minus the smallest IPv4 header (20) and the smallest TCP header (20):

65535−20−20=65495 bytes of TCP data

UDP (8-byte header): 65,535 minus 20 minus 8 = 65,507. On Ethernet, MTU 1,500 minus 40 = 1,460 bytes of data per segment (the usual MSS).

ARP and RARP: from IP address to MAC address and back

PIN 4/27 Open the full card

ARP (Address Resolution Protocol, RFC 826): finds the MAC address belonging to a known IPv4 address on the same link: broadcast request, unicast reply, answer cached.

Why: frames are delivered to MAC addresses, but software knows the next hop's IP. Same subnet: ask for the destination's MAC; otherwise for the default gateway's MAC, never the distant host's.

Figure: a sequence: laptop A broadcasts "who has 192.168.1.20?", host C drops it, printer B replies unicast with 3c:52:82:10:aa:07, A caches it and sends the packet.

  1. Check the cache: laptop 192.168.1.10 finds no entry for printer 192.168.1.20; the IP packet waits.
  2. Broadcast a request to ff:ff:ff:ff:ff:ff (EtherType 0x0806): "who has 192.168.1.20? Tell 192.168.1.10", with its own IP and MAC.
  3. Only the owner answers: others drop the request; the printer keeps the laptop's mapping.
  4. Unicast reply: "192.168.1.20 is at 3c:52:82:10:aa:07".
  5. Cache and send: the laptop stores the pair with a timeout and sends the frame; later packets skip the request.
ARP fieldSizeIPv4 over Ethernet
Hardware type2 bytes1 (Ethernet)
Protocol type2 bytes0x0800 (IPv4)
Address lengths1 byte each6 and 4
Operation2 bytes1 request, 2 reply
Sender MAC, IP6 + 4 bytesasker's addresses
Target MAC, IP6 + 4 bytesMAC zeros in a request; the IP asked about

ARP packet: 28 bytes, carried directly in Ethernet, not in IP; arp -a shows the cache.

  • Gratuitous ARP: a host announces its own mapping (boot, card change) to refresh caches and detect duplicate addresses.
  • Proxy ARP: a router answers for hosts on another network.
  • ARP spoofing: no authentication; an attacker answers with its own MAC to intercept traffic; defences: dynamic ARP inspection, static entries.

RARP (Reverse ARP, RFC 903): a diskless workstation knowing only its MAC broadcasts "what is my IP?"; a RARP server on the same LAN replies. Needs a server per network (broadcast cannot cross routers), gives only an IP (no mask, gateway); replaced by BOOTP and DHCP.

NDP (Neighbour Discovery Protocol, RFC 4861): ARP's IPv6 replacement, using ICMPv6:

PointARP (IPv4)NDP (IPv6)
DefinedRFC 826, 1982RFC 4861, 2007
Carried inown Ethernet type 0x0806ICMPv6 in IPv6
Request tobroadcastsolicited-node multicast (same last 24 bits)
Messagesrequest, replyNS 135, NA 136, RS 133, RA 134, redirect 137
Jobsresolution onlyresolution, router and prefix discovery, SLAAC, duplicate address detection, unreachability detection, redirect
SecuritynoneSEND (RFC 3971)

Example: a teacher calling "who is roll 20?" (broadcast); only roll 20 stands (reply); the teacher remembers the face (cache). RARP: a student asking the class for his own roll number.

ICMP: the network layer's error reports and queries

HOT 5/27 Open the full card

ICMP (Internet Control Message Protocol, RFC 792): IP's companion protocol that reports errors in delivering datagrams back to their source and answers diagnostic queries such as echo (ping); carried inside IP (protocol 1); reports problems, does not correct them.

Why: IP is best effort with no feedback of its own; without ICMP undeliverable datagrams vanish silently. It is the internet layer protocol giving hosts and routers feedback about network problems.

Figure: an Ethernet frame holding an IP header with protocol 1 and the ICMP message, expanded into type, code, checksum, the rest of the header, and data.

Format: type (8 bits, which message), code (8 bits, the reason), checksum (16 bits, whole message), 32 bits depending on type (identifier and sequence number for echo); error messages then carry the offending datagram's IP header and first 8 bytes of data (enough for the TCP or UDP ports).

Error-reporting messages
TypeMessageSent whenCodes
3Destination unreachablenetwork or host unreachable, or no process on the port0 network, 1 host, 2 protocol, 3 port, 4 fragmentation needed with DF, 13 blocked by policy
4Source quenchcongested router asks the source to slow down (withdrawn, RFC 6633, 2012)0
11Time exceededTTL reached 0, or reassembly timer ran out0 TTL, 1 reassembly
12Parameter problembad header field or missing optionpointer to the bad byte
5Redirecta host on the same network should use another routernetwork or host
Query (informational) messages
TypesPairUse
8 and 0echo request and replyping: alive, round-trip time
13 and 14timestamp request and replyround-trip time, clock difference
17 and 18address mask request and replysubnet mask (now DHCP)
10 and 9router solicitation and advertisementfinding routers

No ICMP error is sent about an ICMP error, a non-first fragment, a broadcast or multicast datagram, or a special source address (0.0.0.0, 127.0.0.1): prevents message storms.

Importance and uses in TCP/IP
  • Error feedback to transport: unreachable messages let applications report "port unreachable" or "host unreachable" instead of waiting; RFC 1122 makes TCP abort on protocol or port unreachable.
  • ping: echo request and reply test reachability and round-trip time.
  • traceroute: probes with TTL 1, 2, 3 ...; each router where TTL runs out answers time exceeded; Windows tracert uses echo requests, Unix traceroute UDP probes ending at the destination's port unreachable.
  • Path MTU discovery: TCP sets DF; "fragmentation needed" messages give the largest size, so no fragmentation is needed.
  • Better routes: redirect; router solicitation and advertisement.
  • Network management: monitoring tools ping devices.
C:\> tracert -d 203.0.113.10
  1     1 ms     1 ms     1 ms  192.168.1.1
  2     5 ms     6 ms     5 ms  198.51.100.1
  3    17 ms    18 ms    17 ms  198.51.100.77
  4    20 ms    21 ms    20 ms  203.0.113.10

TTL 1 dies at the home router (line 1), TTL 2 at the ISP router (line 2), TTL 3 one router further; the fourth probes reach the server, which answers with echo reply.

Security: firewalls often block echo requests, but blocking all ICMP breaks path MTU discovery; let error messages through. ICMPv6 (RFC 4443) also carries neighbour discovery and multicast group management.

Example: the post office's returned-letter slip: it delivers nothing, it says why the letter came back.

Routing: what it is, what a good algorithm needs, static against dynamic

TOP 13/27 Open the full card

Routing: the process by which routers find paths through an internetwork and build the tables forwarding uses. Routing algorithm: the part of the network layer software that decides which output line an incoming packet is sent on.

Routing against forwarding: forwarding handles each packet (table lookup, out of the right interface, microseconds); routing fills and updates the table (runs the algorithm, talks to other routers, reacts to failures, seconds to minutes).

Why routing is essential
  • Delivery beyond one network: every router on the way must know the next hop.
  • Many paths: networks are meshes; routing picks the best by the metric (hops, delay, bandwidth, cost).
  • Survival: dynamic routing reroutes around failures without anyone touching the routers.
  • Efficiency: spreads load, cuts delay, avoids congestion.
  • Scale and policy: aggregated routes keep tables small; between organisations routing carries policies.
Properties of a good routing algorithm
  • Correctness: delivers every packet to the right destination.
  • Simplicity: little computation, few messages.
  • Robustness: works through failures and topology and load changes for years without a network-wide reboot.
  • Stability: converges quickly to fixed routes, no oscillation, no loops.
  • Fairness: every source and destination pair served reasonably.
  • Optimality (efficiency): minimises mean delay or maximises throughput; fairness and optimality conflict, so a balance is struck.

The book's list also has "cleverness" (detouring around congestion).

Adaptive and non-adaptive routing
PointNon-adaptive (static)Adaptive (dynamic)
Routes chosenin advance, offline, by the administratorcontinuously by routers from current topology and load
On a failurenothing changes until editedreroutes itself
Methodsstatic and default routes; floodingdistance vector, link state: RIP, OSPF, EIGRP, BGP
Overheadnonebandwidth, CPU, memory
Securityhigher, nothing advertisedlower, messages can be forged unless authenticated
Suitssmall, stable networks; branch with one linklarge networks with many paths

Adaptive algorithms differ in where they get information (locally, neighbours, all routers), when they change routes (timer, topology or load change) and the metric (distance, hops, delay). A single link to an ISP is best served by a static default route.

Routed and routing protocols
PointRouted protocolRouting protocol
Whatnetwork protocol whose packets carry user data and are routedprotocol routers use to swap route information and build tables
Providesaddresses and packet formatpaths: which networks, how far
Used byhosts and routersrouters only
ExamplesIPv4, IPv6 (once IPX, AppleTalk)RIP, OSPF, EIGRP, IS-IS, BGP

RIP messages themselves travel in routed IP datagrams.

Optimality principle

If router J is on the optimal path from I to K, the optimal path from J to K falls along the same route. Proof: call I to J r1 and the rest r2; a better route than r2 from J to K joined to r1 would beat r1r2, contradicting its optimality.

Figure: I, J and K with r1 and r2 and a dashed shorter r2 prime, beside a sink tree of routers A, C, D, E and F towards destination B.

Sink tree: the optimal routes from every router to one destination form a tree rooted at the destination; no loops, so delivery in finite hops; routing algorithms find and use the sink trees. Example: if the shortest bus route Kalanki to Pulchowk passes Balkhu, the shortest Balkhu to Pulchowk route is the rest of it.

Autonomous system

Autonomous system (AS): networks and routers under one administration with one routing policy, identified by an AS number (16 bits, 1 to 65,535; 32 bits since 2007, RFC 4893, now RFC 6793): an ISP, university, large bank. Inside: an interior gateway protocol chosen by the AS (RIP, OSPF, EIGRP, IS-IS); between ASes: BGP. Stub AS (one link out), multihomed (several providers), transit (an ISP carrying others' traffic). Nepal's larger ISPs each run an AS and exchange local traffic at the Nepal Internet Exchange (NPIX) over BGP.

Example: a microbus route is static routing (same stops even when a road is blocked); a traffic officer at Kalanki waving cars to the ring road when the main road jams is adaptive routing.

The routing table, and forwarding with classful addresses

Open the full card

Routing table: what a router consults for every packet: per destination network, its mask, the next hop, the outgoing interface, a metric, and how the route was learned.

  • Destination and mask: routes name networks, not hosts (network-specific, next-hop routing), keeping tables small.
  • Next hop: neighbouring router's IP; empty for a directly connected network.
  • Interface: port to send out of.
  • Metric: route cost (RIP hops, OSPF cost).
  • Source: connected, static, or learned by a protocol (dynamic entries time out).
  • Default route 0.0.0.0 mask 0.0.0.0: route of last resort.

Classful forwarding: class from the first octet, apply the default mask, look up the network.

Router R1
Destination    Mask             Next hop       Interface   Source
10.0.0.0       255.0.0.0        (direct)       Gi0/0       connected
172.16.0.0     255.255.0.0      (direct)       Gi0/1       connected
192.168.1.0    255.255.255.0    (direct)       Se0/0/0     connected
192.168.2.0    255.255.255.0    192.168.1.2    Se0/0/0     RIP, 1 hop
0.0.0.0        0.0.0.0          192.168.1.2    Se0/0/0     static default
  1. To 172.16.40.9: 172 in 128 to 191, class B, network 172.16.0.0, connected on Gi0/1: delivered directly (after ARP).
  2. To 192.168.2.77: class C, 192.168.2.0: next hop 192.168.1.2 via Se0/0/0.
  3. To 203.0.113.50: class C, 203.0.113.0: no entry, default route to 192.168.1.2.

Classless tables carry a mask per route; overlaps resolved by longest prefix match: routes 10.0.0.0/8 via A, 10.1.0.0/16 via B, 10.1.2.0/24 via C: 10.1.2.5 to C, 10.1.9.9 to B, 10.200.0.1 to A; /0 loses to anything longer.

Static routes in Cisco syntax: ip route 192.168.2.0 255.255.255.0 192.168.1.2; default ip route 0.0.0.0 0.0.0.0 192.168.1.2. Hosts: route print (Windows), ip route (Linux).

Example: the board at a bus park saying which counter sells tickets for which district; "everything else, counter 1" is the default route.

Dijkstra's shortest path algorithm, worked on a graph

PIN 1/27 Open the full card

Dijkstra's algorithm (Edsger Dijkstra, 1959): finds the least-cost path from one node to every other node of a graph with non-negative link costs, making one node permanent at a time, always the nearest one not yet fixed.

In routing: in link state routing every router holds the whole graph and runs Dijkstra with itself as source; the shortest path tree gives the first hop to each destination; OSPF and IS-IS call it SPF (shortest path first).

Steps, with a label (distance, previous node) on each node:

  1. Start: source (0, none), permanent; all others (infinity, none).
  2. Relax: for each neighbour of the newest permanent node, distance + link cost; if smaller, relabel (new distance, via this node), tentative.
  3. Fix the nearest: the tentative node with the smallest distance becomes permanent and the new working node.
  4. Repeat 2 and 3 until the destination (or all) is permanent.
  5. Read the path backwards through the "via" fields.

Figure: the book's Figure 4.12 graph of eight routers with link costs, each node labelled with its final distance and predecessor, the path A, B, E, F, H, D in colour.

Example (book Figure 4.12): A-B 2, A-G 6, B-C 7, B-E 2, E-F 2, E-G 1, F-C 3, F-H 2, G-H 4, C-D 3, H-D 2; from A to D:

StepMade permanentTentative after the step
1A (0)B (2, A), G (6, A)
2B (2, A)G (6, A), E (4, B), C (9, B)
3E (4, B)G (5, E), F (6, E), C (9, B)
4G (5, E)F (6, E), C (9, B), H (9, G)
5F (6, E)C (9, B), H (8, F)
6H (8, F)C (9, B), D (10, H)
7C (9, B)D (10, H)
8D (10, H)none

Shortest path A, B, E, F, H, D, cost 2 + 2 + 2 + 2 + 2 = 10. In step 3 G drops from (6, A) to (5, E) (A-B-E-G = 5); in step 5 F offers C at 9, a tie, so C stays (9, B); C's route to D costs 12. The book's figure is right; it omits the cost, 10.

Cost: about N2 steps simply, about ElogN with a priority queue; costs must be non-negative. Distance vector uses Bellman-Ford instead, computing the same shortest paths piece by piece across routers.

Example: a fire spreading from A along the links at one metre per second per unit cost: the order nodes catch fire is Dijkstra's order.

Flooding: send every packet out of every line

Open the full card

Flooding: a non-adaptive routing algorithm in which a router sends every incoming packet out on every line except the one it arrived on.

Problem: duplicates multiply without end on networks with loops. Damping:

  • Hop counter: set at the source to the path length (or network diameter); each router subtracts 1, drops at 0. The book floods with a hop count of 3 (first, second, third hops).
  • Sequence numbers: source numbers each packet; routers keep the numbers seen per source and drop repeats (how link state packets are flooded).
  • Selective flooding: send only on lines going roughly the right way.

Uses: delivery almost certain if any path exists (military robustness, early ARPANET idea); always finds the shortest path (the first copy took it), so a benchmark; needs no knowledge of the network, so used to spread link state packets and broadcasts. Cost: bandwidth for copies, so never for ordinary traffic.

Example: a village rumour, each person telling everyone met except the teller, and repeating it only once.

Distance vector routing, count to infinity, and loop prevention

TOP 10/27 Open the full card

Distance vector routing: each router keeps a vector of the best known distance to every destination and the line to use, and periodically shares the whole table with its neighbours only, updating by Bellman-Ford.

Three keys: knowledge about the whole network; shared only with neighbours; at regular intervals (RIP every 30 s). "Routing by rumour".

Update rule: router x's distance to y is the minimum over neighbours v of the link cost to v plus v's distance to y:

Dx(y)=minv{c(x,v)+Dv(y)}

On receiving a neighbour's table: add the link cost to every entry; keep a route if shorter, or if it comes from the current next hop (its news is always believed).

Example (book Figures 4.14 and 4.15): A on networks 14, 78, 23; neighbours B (14, 55), E (08, 23), F (78, 92); each router starts with its own networks at distance 1; A adds one hop to each received entry:

NetworkA oldFrom B +1From E +1From F +1A new
08nonenone2, Enone2 via E
141 direct2, Bnonenone1 direct
231 directnone2, Enone1 direct
55none2, Bnonenone2 via B
781 directnonenone2, F1 direct
92nonenonenone2, F2 via F

Network 66 arrives next round at 3 hops (through B or E); a few rounds later no table changes (converged).

Count to infinity

Good news spreads fast, bad news slowly. Line A, B, C, network N on C: C at 1, B at 2 via C, A at 3 via B. C's link to N fails:

  • C loses N, but B's regular update "N, 2 hops" arrives first; C records 3 via B (not knowing B's route runs through C).
  • B hears 3 from its next hop C and accepts 4; C goes to 5, B to 6: a routing loop, packets bounce between them.
  • Ends only at infinity: RIP's 16; about 14 exchanges.

Figure: routers A, B and C in a line with network N cut off from C, and boxes showing C and B counting 3, 4, 5, 6 up to 16.

Loop prevention
  • Maximum hop count: infinity defined as 16 (RIP); counting stops; network limited to 15 hops.
  • Split horizon: never advertise a route back out of the interface it was learned from; B never tells C about N.
  • Split horizon with poison reverse: B advertises N back to C with metric 16; kills the loop at once; larger updates.
  • Route poisoning: C advertises N with metric 16 as soon as it fails.
  • Triggered updates: send at once on a change, not after 30 s.
  • Hold-down timer: once a route goes bad, ignore news of a worse route to it for a while (RIP 180 s); only better news or the timer's end accepted.

Split horizon fails in loops of three or more routers (Tanenbaum's example); hold-down and triggered updates cover it; link state avoids it.

Strengths and weaknesses: simple, little memory and CPU; slow convergence, loops while converging, usually hop count regardless of speed, whole tables even when nothing changes. ARPANET used it until 1979, then link state. RIP and IGRP are distance vector; EIGRP advanced distance vector.

Example: villagers passing directions by rumour; the fallen bridge's news spreads slowly while the old "two hours from here" goes round the hills.

Link state routing: properties, five steps, and distance vector compared

TOP 11/27 Open the full card

Link state routing: each router floods the state of its own links (neighbours and costs) to every router, so every router holds a map of the whole network and computes its own shortest paths with Dijkstra.

Three keys: knowledge of its neighbourhood only (not its table); sent to every router (flooding); sent when there is a change (plus a slow refresh).

Properties
  • Full topology: same link state database (whole graph of the area) in every router.
  • Independent computation: each runs Dijkstra itself; errors do not spread as rumour.
  • Fast convergence, no count to infinity: changes flooded at once; loops rare.
  • Real costs: metric from bandwidth or delay.
  • Low traffic when stable; more memory (database) and CPU (Dijkstra).
  • Scales with hierarchy: areas (OSPF, IS-IS).
Five steps
  1. Discover neighbours: HELLO on each link; neighbours reply with router IDs.
  2. Measure cost: ECHO round-trip delay, or a cost from bandwidth.
  3. Build a link state packet (LSP): own ID, sequence number, age, neighbours with link costs.
  4. Flood the LSP: each router forwards a new LSP on all other links; sequence number drops duplicates and old copies; age expires stale LSPs.
  5. Compute: with all LSPs, run Dijkstra from itself; the first hop of each path goes in the table.

Figure: five routers A to E with link costs and the link state packet of each router; A's shortest path tree in colour.

Example: A-B 2, A-C 1, B-C 2, B-D 3, C-E 4, D-E 1:

LSP ofABCDE
Neighbours, costsB 2, C 1A 2, C 2, D 3A 1, B 2, E 4B 3, E 1C 4, D 1

Flooding gives every router all five LSPs; A's Dijkstra makes C (1), B (2), D (5 via B), E (5 via C) permanent:

DestinationCostPathNext hop
B2A, BB
C1A, CC
D5A, B, DB
E5A, C, EC

If D-E fails, D and E flood new LSPs and every router reruns Dijkstra; no count to infinity.

Distance vector against link state
PointDistance vectorLink state
Knowsdistances and next hops as neighbours reportwhole topology of its area
Sendswhole routing tablestate of its own links (LSP)
To whomneighbours onlyevery router, flooding
Whenperiodically (RIP 30 s) plus triggeredon change, slow refresh (OSPF 30 min)
AlgorithmBellman-Ford, shared across routersDijkstra, each router on its own copy
Convergenceslow, count to infinityfast, none
Loopspossible; split horizon, hold-downrare
Metricusually hop countcost from bandwidth or delay
Memory and CPUlittlemore
Bandwidth when stablewasted on periodic tableslittle
Scale, setupsmall (RIP 15 hops); simplelarge, areas; more complex
ExamplesRIP, IGRP (EIGRP advanced DV)OSPF, IS-IS

Examples: a small office of four routers runs RIP, configured in minutes; an ISP or large campus runs OSPF or IS-IS, rerouting around a cut fibre in under a second where RIP could take minutes. The 2072 Kartik paper's "static link routing" means link state routing.

Example: distance vector is directions by word of mouth; link state is every village sending its sketch of nearby roads to all, each holding the full district map.

Hierarchical routing: regions instead of every router

Open the full card

Hierarchical routing: routers grouped into regions; each knows every router of its own region in detail but treats each other region as one destination, so tables shrink.

Why: flat tables, update traffic and computation grow with the number of routers; past some size no router can keep a route to every other.

Example (Tanenbaum's, in the book): 17 routers in five regions; router 1A's flat table has 17 entries, its hierarchical table 7:

Router 1A, hierarchical table
Destination   Line   Hops
1A            -      -
1B            1B     1
1C            1C     1
Region 2      1B     2
Region 3      1C     2
Region 4      1C     3
Region 5      1C     4

Savings grow: 720 routers: flat 720 entries; 24 regions of 30: 30 + 23 = 53; three levels (8 clusters of 9 regions of 10): 10 + 8 + 7 = 25. Kamoun and Kleinrock: best number of levels about lnN, about elnN entries per router (720 routers: about 18).

Price: longer paths (everything for a region goes through one entry point). Used in: OSPF areas and the Internet's hierarchy of autonomous systems joined by BGP.

Example: a parcel from Kathmandu to a Jhapa village is sent "to Jhapa"; only the Jhapa office knows the village.

Routing protocols: why they are needed, IGP and EGP, and the main five

PIN 4/27 Open the full card

Routing protocol: the rules and messages by which routers tell each other which networks they can reach and at what cost, so each builds and updates its table automatically; a routing algorithm put to work between real routers.

Why necessary
  • Static routes do not scale: every router needs a route to every network, typed by hand; one new subnet means editing every router.
  • Discovery: routers find networks themselves.
  • Adaptation: reroute by themselves in seconds on a failure.
  • Best loop-free paths: a metric chooses; rules keep routes loop free while routers converge on a consistent view.
  • Policy: between autonomous systems, BGP carries who may use whose links.
Classification
  • By scope: IGP (intra-AS): RIP, OSPF, IS-IS, EIGRP; EGP (inter-AS): BGP.
  • By algorithm: distance vector (RIP, IGRP), link state (OSPF, IS-IS), advanced distance vector (EIGRP), path vector (BGP).
  • By masks: classful, no mask in updates (RIPv1, IGRP); classless, mask carried, VLSM and CIDR (RIPv2, OSPF, EIGRP, IS-IS, BGP-4).

Figure: two autonomous systems, one running OSPF and one RIP inside, their border routers joined by eBGP over TCP 179.

PointIntra-AS (IGP)Inter-AS (EGP)
Scopeinside one ASbetween ASes
Goalperformance, shortest pathpolicy and reachability
Chosen byeach ASeveryone uses BGP-4
Sizehundreds to thousands of routeswhole Internet
ExamplesRIP, OSPF, IS-IS, EIGRPBGP
ProtocolTypeAlgorithmMetricUpdatesOrigin
RIPIGPdistance vectorhop count, 15 mostwhole table every 30 sRFC 1058, 2453
OSPFIGPlink state (Dijkstra)cost from bandwidthon change; refresh 30 minRFC 2328
IGRPIGPdistance vectorbandwidth and delaywhole table every 90 sCisco, 1980s, obsolete
EIGRPIGPadvanced distance vector (DUAL)bandwidth and delaypartial, on changeCisco; RFC 7868
BGPEGPpath vectorpolicy, AS path lengthincremental, TCP 179RFC 4271
  • RIP: oldest, simplest; hop count, 16 infinity, whole table every 30 s; small networks; slow.
  • OSPF: open link state IGP; floods within areas, DR and BDR on LANs, Dijkstra; fast, VLSM, authentication.
  • IGRP: Cisco's 1980s answer to RIP's limits; distance vector, composite metric (bandwidth and delay by default, load and reliability optional), hop limit 100 by default (up to 255), updates every 90 s; classful; replaced by EIGRP.
  • EIGRP: Cisco's advanced distance vector ("hybrid"); neighbour and topology tables like link state but exchanges distances; DUAL keeps a backup route (feasible successor) so it switches almost at once, loop free; small updates only on change; VLSM, unequal-cost load balancing; multicast 224.0.0.10.
  • BGP: the Internet's EGP; path vector; each route with its list of ASes; chooses by policy over TCP.
  • IS-IS: ISO link state IGP like OSPF, used by many large ISPs.

Intra-AS in practice: a campus or ISP runs one IGP, usually OSPF; it reaches the Internet by a static default route, or BGP if it owns an AS number and has more than one provider.

Example: inside a city the traffic office picks the fastest roads (IGP); between countries border agreements decide which highways carry whose goods (EGP).

RIP: hop counts, 30 second updates, and its timers

PIN 2/27 Open the full card

RIP (Routing Information Protocol): distance vector interior protocol (RFC 1058; version 2 RFC 2453); metric = hop count, 15 the most, 16 unreachable; whole table to neighbours every 30 s over UDP port 520.

Operation
  1. Start up: knows only connected networks; sends a request on each RIP interface.
  2. Respond: neighbours answer with response messages (their tables); sent again every 30 s by the update timer, changed or not.
  3. Update: add one hop to each received route; add new networks; replace by shorter routes; always believe the current next hop; metric 16 = unreachable.
  4. Triggered update: send at once when a route changes.
  5. Age out by the timers.
  6. Loop control: split horizon, poison reverse, hold-down.

Figure: a time line from 0 to 360 seconds: updates due every 30 s, the route invalid at 180 s, hold-down from 180 s, and the route flushed at 240 s.

Timers (Cisco defaults)
TimerDefaultWhat happens
Update30 swhole table sent out of every RIP interface
Invalid180 sno refresh for 180 s (six missed updates): route invalid, metric 16, advertised unreachable
Hold-down180 safter invalid, news of another route to that network refused unless clearly better
Flush240 s240 s after the last update the route is removed

Flush counts from the last update, so it fires 60 s after invalid, before hold-down would end (360 s). RFC 2453 names two timers: timeout 180 s and garbage collection 120 s after it (route deleted at 300 s); hold-down is Cisco's; the RFC adds a random offset to the 30 s.

Example: R1, R2, R3 in a line (RIPv2)

R1 LAN 10.1.0.0/16; R1 to R2 link 10.2.0.0/16; R2 to R3 link 10.3.0.0/16; R3 LAN 10.4.0.0/16.

  • First update (about 30 s): R1 adds 10.3.0.0 at 1 hop via R2; R2 adds 10.1.0.0 (via R1) and 10.4.0.0 (via R3) at 1 hop.
  • Second update (about 60 s): R1 adds 10.4.0.0 at 2 hops via R2; R3 adds 10.1.0.0; converged.
R1# show ip route
C    10.1.0.0/16 is directly connected, GigabitEthernet0/0
C    10.2.0.0/16 is directly connected, Serial0/0/0
R    10.3.0.0/16 [120/1] via 10.2.0.2, 00:00:12, Serial0/0/0
R    10.4.0.0/16 [120/2] via 10.2.0.2, 00:00:12, Serial0/0/0

C connected, R by RIP; [120/2] = administrative distance 120 and 2 hops; 00:00:12 = time since last update. If R3 dies: 10.4.0.0 invalid at 180 s, flushed at 240 s.

Message: 4-byte header (command 1 request, 2 response; version) and up to 25 entries of 20 bytes (address family, IP address, metric; v2 adds route tag, subnet mask, next hop): at most 504 bytes, in UDP.

PointRIPv1RIPv2RIPng
DefinedRFC 1058, 1988RFC 2453, 1998RFC 2080, 1997
Addressingclassful, no maskclassless, mask and next hopIPv6 prefixes
Sent tobroadcast 255.255.255.255multicast 224.0.0.9multicast ff02::9
Authenticationnoneplain text or MD5IPsec
TransportUDP 520UDP 520UDP 521

Limits: 15-hop diameter; slow convergence and count to infinity; hop count ignores bandwidth (one hop over 2 Mbps beats two over gigabit fibre); whole table every 30 s. Suits small networks; larger use OSPF.

Counting hops: Cisco and most texts count routers to cross (a neighbour's network is 1 hop); the book's distance vector figure counts a directly connected network as 1, so its values are one higher; either, consistently.

Example: RIP counts bus stops, not minutes; one stop through the Kalanki jam beats two along the empty ring road. Timers: half a minute, three, three and four minutes.

OSPF: areas, DR and BDR, and the road to full adjacency

HOT 5/27 Open the full card

OSPF (Open Shortest Path First): open-standard link state interior protocol (OSPFv2, RFC 2328): each router floods LSAs through its area, builds the same link state database, and runs Dijkstra. "Open": public standard (unlike Cisco's EIGRP); "shortest path first": Dijkstra. Messages straight in IP (protocol 89) to 224.0.0.5 (all OSPF routers) or 224.0.0.6 (DR and BDR).

Metric: cost from bandwidth:

cost=108 bit/sbandwidth

Cisco default reference 100 Mbps: 10 Mbps link costs 10, 100 Mbps costs 1 (gigabit too unless the reference is raised); path cost = sum of link costs.

The OSPF process
  1. Find neighbours: Hello every 10 s on each interface; matching area, subnet, timers and authentication make neighbours; silent 40 s (dead interval) means down.
  2. Elect DR and BDR on multi-access networks.
  3. Form adjacencies and synchronise: database descriptions, requests, updates until databases match (Full).
  4. Flood LSAs: each router's own links through the area; the DR adds one for the LAN; flooded on change, refreshed every 30 minutes.
  5. Run SPF: Dijkstra with itself as root.
  6. Install routes: best path to each network; changes flood new LSAs and SPF reruns.
TypePacketJob
1Hellofind neighbours, keep alive, DR election
2Database description (DBD)list LSA headers held
3Link state request (LSR)ask for missing or old LSAs
4Link state update (LSU)carry full LSAs
5Link state acknowledgement (LSAck)confirm each LSA

Areas: all attached to the backbone, area 0; routers keep detailed databases only of their own area (quick SPF, faults not flooded everywhere); ABR joins an area to the backbone and summarises; ASBR brings in outside routes (BGP, static). Hierarchical routing.

Figure: an AS with backbone area 0, areas 1 and 2 behind ABR1 and ABR2, and an ASBR to another AS; beside it five routers on one Ethernet with R1 as DR, R2 as BDR, and three DROthers adjacent only to them.

DR and BDR

On a multi-access network n routers fully meshed need n(n−1)/2 adjacencies (ten routers: 45) and flood each LSA repeatedly. So a designated router (DR) is elected: every router forms full adjacency only with the DR and a backup DR (BDR): 2(n−2)+1 adjacencies (ten routers: 17; five: 7 against 10). Routers send updates to the DR (224.0.0.6); the DR floods to all (224.0.0.5) and originates one network LSA for the segment; the BDR listens and takes over at once if the DR fails. Others are DROthers.

Election:

  1. Highest interface priority (0 to 255, default 1) becomes DR, next highest BDR.
  2. Tie: highest router ID (set by hand, else highest loopback address, else highest active interface address).
  3. Priority 0: never DR or BDR.
  4. Timing: a new interface waits one dead interval (40 s) before electing.
  5. No pre-emption: a better router joining later does not take over; only on DR failure does the BDR become DR and a new BDR is elected.
Neighbour states to full adjacency (RFC 2328)

Figure: the seven OSPF neighbour states left to right, Down to Full, with what happens in each; DROthers stop at 2-Way.

  1. Down: no Hello heard (or dead interval ran out).
  2. Init: Hello received, not yet listing this router (one-way).
  3. 2-Way: each sees its own router ID in the other's Hello; DR and BDR elected here; two DROthers stay here.
  4. ExStart: master and slave chosen (higher router ID is master), first sequence number.
  5. Exchange: DBD packets with LSA headers swapped.
  6. Loading: LSRs for missing or older LSAs, received in LSUs, acknowledged.
  7. Full: databases identical; fully adjacent; each lists the other in its router LSA.

(Attempt: on NBMA networks, Hellos sent to a configured neighbour.)

Why the usual IGP: converges in seconds, no count to infinity, no hop limit, VLSM and CIDR, authentication, equal-cost load balancing, little traffic when stable. Costs: more memory and CPU than RIP; harder setup (areas, router IDs, priorities). The book says OSPF "doesn't need a high memory and high-speed processor": it needs more than RIP (whole database, Dijkstra); areas exist to keep that down.

Example: a class elects a CR (DR) and an assistant CR (BDR); everyone tells the CR, the CR tells everyone; the assistant steps in without a new election.

BGP: routing between autonomous systems

Open the full card

BGP (Border Gateway Protocol, version 4, RFC 4271): the Internet's exterior gateway protocol: a path vector protocol by which autonomous systems advertise the networks they reach, each route carrying the list of ASes it passes through, chosen by policy.

Why not RIP or OSPF between ASes: the goal is the permitted path, not the fastest (an ISP carries customers' traffic, not a competitor's); each AS hides its inside; internal metrics are not comparable; the Internet's table is too large to flood.

Path vector: a route = prefix + AS_PATH, e.g. 203.0.113.0/24 with path 64501 64502; passing it on, an AS adds its own number in front; an AS seeing its own number in a path rejects the route, which prevents loops without count to infinity.

  • Sessions over TCP port 179: peers exchange the full table once, then only changes.
  • eBGP and iBGP: external between different ASes (usually directly connected); internal carries outside routes among the border routers of one AS.
  • Policy: each AS chooses what it accepts and advertises; ranks routes by attributes such as local preference, then the shortest AS_PATH.
MessageJob
OPENstarts a session: AS number, hold time, router ID
UPDATEadvertises routes with path attributes, withdraws dead ones
KEEPALIVE"still here", every third of the hold time (commonly 60 s with 180 s hold)
NOTIFICATIONreports an error and closes the session

Internet exchange point: many ASes exchange traffic directly over BGP sessions instead of paying an upstream provider; Nepali ISPs peer at the Nepal Internet Exchange (NPIX), so traffic between member networks stays in the country.

Example: a travel itinerary "Kathmandu, Delhi, Dubai, London" lists every stop, so no city appears twice and an agent can refuse any route through a country it does not deal with.

Unicast and multicast routing, and their protocols

PIN 3/27 Open the full card

Unicast: one source to one destination. Multicast: one packet from a source to a group of receivers that joined; the network copies it only where the paths to members split, one copy per link.

Figure: the same network drawn twice: unicast sends three copies from the source (9 link transmissions), multicast one copy per link (6), to receivers that joined group 239.1.1.1 with IGMP.

PointUnicastMulticastBroadcast
Receiversonea group that joinedall on the network
Addressone host'sgroup, class D 224.0.0.0 to 239.255.255.255host part all 1s
Copies for N receiversN from the sourceone per link, by routersone, to all
Crosses routersyesyes, with multicast routingno
Examplea web pagelive lecture, IPTVARP request

Unicast routing: look up one destination, one copy to one next hop. Unicast routing protocols: RIP and IGRP (distance vector), OSPF and IS-IS (link state), EIGRP (advanced distance vector) inside an AS; BGP between ASes.

Multicast routing

Two questions: which hosts want a group, and along which tree to copy.

  • Group membership (host to router): IGMP (IP protocol 2; v1 RFC 1112, v2 RFC 2236, v3 RFC 3376): a host sends a membership report to join; the router queries periodically (224.0.0.1); v2 added a leave message.
  • Distribution trees (router to router): source-based tree (shortest path tree per source: best paths, one tree per source); shared tree (one per group rooted at a core or rendezvous point: fewer trees, longer paths).
  • Reverse path forwarding (RPF): accept a multicast packet only if it arrived on the interface used to send unicast traffic back to the source; stops loops and duplicates.
ProtocolBuilt onTree
DVMRP (RFC 1075)distance vectorflood and prune by RPF; source-based trees
MOSPF (RFC 1584)OSPFgroup-membership LSAs; source tree by Dijkstra
PIM-DM (dense mode)any unicast protocolflood and prune; members everywhere
PIM-SM (sparse mode, RFC 7761)any unicast protocolexplicit joins to a rendezvous point (shared tree), then source trees for heavy flows; scattered members; most used
CBT (RFC 2201)any unicast protocolone shared tree per group, rooted at a core

"Protocol independent": PIM uses the existing unicast routing table for RPF checks instead of its own algorithm.

Example: unicast is a teacher phoning 200 students with the same notice; multicast is reading it once over the speakers only in the halls whose students signed up; broadcast is the siren everyone hears.

Designing a network for a real site: a hotel, a campus

PIN 2/27 Open the full card

Network design: choosing the topology, devices, cabling, wireless, addressing, servers and security that meet a site's needs, with a reason for each, from stated or written-down assumed requirements.

Method
  1. Requirements and assumptions: users, devices, rooms, floors, buildings; services (Internet, Wi-Fi, phones, CCTV, servers); growth; budget; write assumptions down.
  2. Topology: hierarchical star (core, distribution, access): isolates faults, grows by branches.
  3. Devices: managed switches (PoE where APs, phones, cameras plug in), router and firewall at the edge, access points with a controller.
  4. Cabling: Cat6 UTP up to 100 m; fibre between buildings, up risers, for long runs: multimode (OM3 or OM4, 10 Gbps up to 300 to 400 m) inside a campus, single-mode beyond; fibre ignores lightning and electrical noise.
  5. Wireless: enough APs for coverage and device count; 802.11ax (Wi-Fi 6) or 802.11ac; separate staff and guest SSIDs; WPA2 or WPA3.
  6. Addressing: private RFC 1918 addresses, one VLAN and subnet per department or function, DHCP, NAT to the public address.
  7. Servers and services: DHCP and DNS, file and print, web and mail, site applications, camera recorder.
  8. Security and reliability: firewall rules between VLANs, guest isolation, antivirus, backups; two ISPs, UPS, redundant core links.
  9. Management: SNMP monitoring, labelled cables and ports, a written plan.
LayerJobDevice
Corefast backbone joining distribution blocks and server roomlayer 3 core switch, fibre
Distributionjoins a building's or department's access switches; routes between VLANs; policylayer 3 switch
Accessconnects end deviceslayer 2 PoE switches, APs
Campus LAN: five departments of Pulchowk Campus

Given: 5 departments, each 100 computers in 5 rooms of 20: 500 computers. Assumed: separate buildings within a few hundred metres of a central server room; rooms within 100 m of their closet; one ISP link, room for another.

Figure: ISP, router and firewall, core switch and server room above five department distribution switches, each with five 24-port room switches over Cat6, joined to the core by fibre.

ItemQuantityWhy
Access switch, managed, 24 gigabit ports25, one per room20 PCs, uplink, spares; collision-free gigabit per PC
Distribution switch, layer 3, SFP fibre ports5, one per departmentjoins 5 room switches, routes the VLAN, contains broadcasts
Core switch, layer 3, 10 Gbps fibre1 (2 for redundancy)joins departments and server room
Router and firewall1ISP link, NAT, security policy
Wi-Fi 6 access points, PoE2 or 3 per departmentlaptops, phones
Cat6 UTP drops500under 100 m, gigabit
Multimode fibre (OM3, OM4)5 department links10 Gbps over hundreds of metres, lightning immune
Racks, patch panels, UPSevery closet and the coretidy cabling, runs through power cuts
ServersDHCP, DNS, file, web, mail, authenticationcentral server room

Accessories: RJ45 connectors, keystone jacks, faceplates, cable trays and conduit, SFP modules, labels, crimping tool, LAN tester. Addressing: one VLAN and private subnet per department (100 hosts plus growth), DHCP, NAT at the firewall; the address ranges for this campus are worked in the Numericals panel.

3-star hotel

Assumed: 60 rooms on 4 floors; lobby, restaurant and bar, conference hall, back offices (front desk, accounts, kitchen, store); about 30 staff PCs and POS terminals; 40 CCTV cameras; an IP phone in every room.

Figure: two ISP links into a dual-WAN firewall, a layer 3 core switch with the server room, a PoE+ switch on each of four floors by fibre, and five VLANs.

  • Internet: two ISP links (fibre plus a backup from another ISP) on a firewall with two WAN ports: failover and load balancing; guests judge a hotel by its Wi-Fi.
  • Firewall (UTM): NAT, VLAN rules, content filtering, VPN for remote management, captive portal (guest login by room number).
  • Core: stackable layer 3 switch in the server room, routing between VLANs.
  • Access: one 48-port PoE+ switch per floor (powers APs, phones, cameras over the data cable), fibre uplink up the riser.
  • Wireless: Wi-Fi 6 APs, about one per three or four rooms plus lobby, restaurant, conference hall, under one controller for roaming; WPA3 for staff; isolated guest SSID with per-device speed limit.
  • Voice and video: IP PBX with a gateway to the telephone network, IP phones, network video recorder.
  • Software: property management system (reservations, check-in, billing, linked to keycard locks and restaurant POS), accounting, hotspot manager, antivirus, backup, SNMP monitoring.
VLANWhoExample subnetRule
10 Staffoffice PCs, front desk, POS10.10.10.0/24PMS and Internet
20 Guestsguests' devices10.10.20.0/22Internet only, isolated
30 VoiceIP phones10.10.30.0/24QoS priority
40 CCTVcameras, recorder10.10.40.0/24no Internet
50 ServersPMS, file, DHCP, DNS10.10.50.0/24staff only

Why: VLANs keep guests away from billing and card systems; PoE saves sockets; managed switches allow VLANs and monitoring; two ISPs and a UPS keep the hotel online; Cat6 gigabit to rooms, fibre floor uplinks.

Example: planning a wedding venue: count guests (requirements), lay out halls (topology), hire tables and chairs (devices), lay carpets (cabling), seat families together (VLANs), guards at the doors (security).

Chapter 5: Transport layer 6960 words

The transport layer: process-to-process delivery and its services

HOT 5/27 Open the full card

Transport layer: provides logical communication between processes running on different hosts. It takes a message from an application, cuts it into segments, hands them to IP, and at the far end reassembles the data and gives it to the right process. It runs only in the end hosts, never in routers: an end-to-end layer.

Three scopes of delivery: data link layer, node to node (one hop, MAC addresses); network layer, host to host (IP addresses); transport layer, process to process (port numbers). An IP address names only a machine; a laptop running a browser, a video call and an update at once needs the port to pick the program.

Figure: one path from host A (198.51.100.10, browser on port 52344) through routers R1 and R2 to host B (203.0.113.5, web server on port 80), with the three scopes marked: three hops, host to host, process to process.

Memory example: a letter to a hostel. The postal address brings it to the gate (IP, host to host); the warden reads the room number and puts it in the right box (port, process to process); the postal van between sorting offices is the data link layer, one hop at a time.

Services, functions or major tasks (the same list):

ServiceWhat it doesTCP and UDP
Process-to-process delivery (addressing)delivers to a process, not just a host16-bit source and destination ports in both headers
Segmentation and reassemblycuts a long message into pieces and rebuilds itTCP numbers every byte, sizes segments to the MSS; UDP sends each message as one datagram
Connection controlsets up, uses, releases a logical connection, or noneTCP: three-way handshake, FIN release; UDP: connectionless
Reliability (error control)detects and recovers corrupt, lost, duplicate dataTCP: checksum, ACK, timer, retransmission; UDP: checksum only, bad datagram dropped
Ordered deliveryhands data up in the order sentTCP: reorders by sequence number; UDP: none
Flow control and bufferingprotects a slow receiver's bufferTCP: receive window; UDP: none
Multiplexing and demultiplexingmany processes share one IP addressports in every header
Congestion controlkeeps all senders from flooding the networkTCP: slow start, AIMD; shaping with leaky and token buckets

Why a separate layer: the network layer is run by the carrier; users do not own the routers and cannot fix their losses. The transport layer runs in the users' hosts, so it can improve on the network's service (recover losses, restore order) and give applications one standard interface whatever the networks in between. In OSI terms layers 1 to 4 are the transport service provider, layers 5 to 7 its user.

How the complete message arrives in order (TCP):

  1. Synchronize: the three-way handshake agrees both initial sequence numbers.
  2. Number every byte: each segment carries the number of its first byte; gaps, duplicates and misordering show at once.
  3. Check: the checksum catches a corrupted segment, which is dropped and so becomes a loss.
  4. Acknowledge: cumulative ACK, the number of the next byte expected.
  5. Retransmit: on retransmission timeout (RTO) or three duplicate ACKs.
  6. Reorder and drop duplicates: the receive buffer keeps early segments; data goes up only when no gap precedes it.
  7. Flow control: the advertised window prevents receiver overflow.
  8. Close cleanly: FIN after the data, carrying the next sequence number, so the receiver knows where the stream ends.

Worked example (3,000-byte message, first data byte 1001): segments seq 1001, 2001, 3001 of 1,000 bytes; 2001 is lost. Segment 1001 arrives: bytes 1001 to 2000 go up, ACK 2001. Segment 3001 arrives early: buffered, duplicate ACK 2001. Timer for 2001 runs out: sender resends 2001 from its copy. Gap filled: bytes 2001 to 4000 go up, all 3,000 bytes delivered in order, ACK 4001.

Figure: sequence diagram of that loss and recovery, with the RTO timer on the sender side; three duplicate ACKs would trigger fast retransmit sooner, and a corrupt segment fails its checksum and is treated as lost.

UDP does none of this beyond the checksum: right port, nothing more.

Services to the upper layer: connection-oriented, connectionless, and the primitives

Open the full card

Transport service: what the transport layer offers the application layer: a connection-oriented service (establish, transfer, release; a reliable stream, TCP) or a connectionless service (independent datagrams, each fully addressed, no guarantees, UDP), used through service primitives.

PointConnection-orientedConnectionless
Phasesestablish, transfer, releasesend only
Addressingfull address once, at setupfull address in every datagram
Reliabilityacknowledged, retransmitted, in ordernone: loss, repeats, reordering possible
Delay before dataa setup round tripnone
Stateboth ends keep connection statenone
Picturea phone calla letter or postcard
ProtocolTCPUDP

Memory example: calling home from the hostel (ring, answer, hello, talk, bye) against posting letters (full address on each, may arrive in any order or not at all).

Service primitives (general idea in chapter 1). Unit exchanged: TPDU (transport protocol data unit), called a segment in TCP, a user datagram in UDP.

PrimitiveTPDU sentMeaning
LISTENnoneblock until a process tries to connect
CONNECTCONNECTION REQUESTactively set up a connection
SENDDATAsend information
RECEIVEnoneblock until a DATA TPDU arrives
DISCONNECTDISCONNECTION REQUESTrelease the connection

Berkeley sockets (4.2BSD, 1983): SOCKET (create endpoint), BIND (attach local address and port), LISTEN (be ready, with a queue), ACCEPT (take next incoming connection), CONNECT (active open), SEND, RECEIVE, CLOSE. Server: SOCKET, BIND, LISTEN, ACCEPT; client: SOCKET, CONNECT. Code is chapter 6.

Why harder than the data link layer: the destination must be addressed explicitly; connection setup must cope with the network storing and delivering old duplicates late; a host holds hundreds of connections, so buffering cannot be one fixed buffer per line.

Classic OSI quality of service parameters: connection establishment delay, connection establishment failure probability, throughput, transit delay, residual error ratio, protection, priority, resilience. The internet's protocols promise none as numbers.

UDP: the 8-byte header, its features, and why an unreliable protocol is used

HOT 6/27 Open the full card

UDP (User Datagram Protocol, RFC 768, 1980): connectionless, unreliable transport that adds to IP only port numbers, a length and a checksum, in an 8-byte header. Each message is one independent datagram: no handshake, no acknowledgement, no retransmission, no ordering, no flow or congestion control.

Figure: the UDP header as a 32-bit grid (source port, destination port; length, checksum), the 12-byte IPv4 pseudo-header below it, and the datagram inside an IP datagram with protocol 17.

FieldBitsCarries
Source port16sender's port for replies; optional, 0 when no reply wanted
Destination port16receiving process; always present
Length16header plus data in bytes: at least 8, at most 65,535; at most 65,507 data bytes over IPv4 (65,535 minus 20 minus 8)
Checksum16one's complement over pseudo-header, header, data; optional in IPv4 (0 = not computed, a computed 0 sent as all ones), mandatory in IPv6

Pseudo-header (12 bytes, IPv4, never sent): source IP, destination IP, zero byte, protocol 17, UDP length. Including the addresses makes a misdelivered datagram fail the check.

Worked example: DNS query for ioe.edu.np. DNS message 28 bytes (12-byte header plus 16-byte question: name coded 3ioe3edu2np0, 12 bytes, plus 2 type, 2 class). Ephemeral source port 50000.

Source port        50000          = 0xC350
Destination port   53 (DNS)       = 0x0035
Length             8 + 28 = 36    = 0x0024
Checksum           over the pseudo-header, the header and the 28 bytes
On the wire:  C3 50  00 35  00 24  (checksum)  then 28 bytes of DNS

IP datagram: protocol 17, total length 20 + 36 = 56 bytes. One datagram out, one back; the resolver retries if no answer.

Features:

  • Connectionless: first datagram carries data.
  • Unreliable (best effort): no ACK, no retransmission.
  • No ordering.
  • Message-oriented: boundaries kept (TCP is a byte stream).
  • No flow or congestion control: sends at the application's rate.
  • Small overhead: 8 bytes against TCP's 20 to 60.
  • Stateless: nothing kept per client; one server serves very many.
  • Broadcast and multicast supported (TCP unicast only).
  • Error detection only: a failed datagram is silently dropped.

Why used though unreliable (unreliable means promises nothing, not usually fails):

  1. Speed: no handshake; a DNS lookup is one round trip.
  2. Timeliness over completeness: in calls and games a late packet is useless; TCP would hold back newer data until the lost piece is resent (head-of-line blocking).
  3. Small and stateless: suits busy servers and small devices.
  4. Broadcast and multicast: DHCP before the host has an address; IPTV.
  5. Application adds only the reliability it needs: DNS retries, TFTP block acknowledgements, QUIC (HTTP/3) builds reliable encrypted streams over UDP.

Memory example: live cricket commentary on the radio; a crackled second is not replayed, the next ball matters more (UDP). A downloaded highlights file must arrive whole (TCP).

ApplicationPortWhy UDP
DNS53one small question and answer; client retries
DHCP67 server, 68 clientclient has no IP address yet, must broadcast
VoIP, video calls (RTP)chosen per calllate audio useless; small losses barely heard
Online gamesgame's ownonly the newest position matters
IPTVmulticastone stream to many viewers
SNMP, NTP, TFTP, RIP, syslog161, 123, 69, 520, 514short messages, simple devices
QUIC (HTTP/3)443own reliability and encryption, no TCP handshake or head-of-line blocking

Recorded on-demand video usually goes over TCP (or QUIC) with a large playback buffer.

The book's Table 5.1 calls UDP "unsecured" for lacking flow control; unreliable is meant. Neither TCP nor UDP encrypts; that is TLS (chapter 8).

TCP: the reliable byte stream, its segment header, and how reliability is provided

TOP 9/27 Open the full card

TCP (Transmission Control Protocol, RFC 9293, 2022, replacing RFC 793 of 1981): connection-oriented, reliable, full-duplex byte-stream transport. Numbers every byte, acknowledges, retransmits, reorders, controls flow and congestion: the receiver gets exactly the bytes sent, in order.

TCP connection: a logical, full-duplex, point-to-point association between two sockets, named by (source IP, source port, destination IP, destination port). State (sequence numbers, windows, buffers, timers, in a transmission control block, TCB) lives only in the two end hosts; routers know nothing of it: a virtual connection, not a reserved circuit.

Features: connection-oriented (handshake, graceful release); reliable and ordered; byte stream with no message boundaries (100 bytes written three times may be read as 300 at once or 150 and 150); full duplex, point to point, piggybacked ACKs, no broadcast or multicast; flow control (receive window) and congestion control (congestion window); mandatory checksum over pseudo-header (protocol 6), header and data.

Figure: the TCP header as a 32-bit grid: source and destination port; sequence number; acknowledgement number; HLEN, reserved, eight flags, window; checksum, urgent pointer; options and padding; data.

FieldBitsCarries
Source port16sending process
Destination port16receiving process
Sequence number32number of the first data byte; on a SYN, the ISN
Acknowledgement number32next byte expected; valid when ACK = 1
Header length (HLEN, data offset)4in 32-bit words, 5 to 15, so 20 to 60 bytes
Reserved4 (6 in RFC 793)zero
Flags8 (6 in RFC 793)CWR, ECE, URG, ACK, PSH, RST, SYN, FIN
Window size16receive window: bytes the segment's sender can still accept
Checksum16pseudo-header, header, data; mandatory
Urgent pointer16valid when URG = 1: offset from the sequence number to the end of urgent data
Options and padding0 to 3200 to 40 bytes: MSS, window scale, SACK permitted, SACK, timestamps; padded to 32 bits

Flags:

  • SYN: synchronize sequence numbers; first segment from each side.
  • ACK: acknowledgement field valid; every segment after the first SYN.
  • FIN: sender has finished; closes its direction.
  • RST: abort at once, or refuse a SYN to a port with no listener.
  • PSH: deliver to the application now (a keystroke in SSH).
  • URG: urgent pointer valid (an interrupt key).
  • CWR, ECE: explicit congestion notification (RFC 3168).

Options (mostly in the SYNs): MSS, maximum data per segment, 1460 bytes on Ethernet (1500 minus 20 IP minus 20 TCP), 536 assumed for IPv4 if absent; window scale, multiplies the window by up to 2 to the 14 (windows up to about 1 GB); SACK, selective acknowledgement of out-of-order blocks; timestamps, for round-trip measurement. Sequence space 32 bits, 4,294,967,296 bytes, wraps round; ISN random.

Worked example, first 20 bytes of a SYN:

C3 50 00 50 | 00 00 1F 40 | 00 00 00 00 | A0 02 FA F0 | (checksum) 00 00
C3 50        source port        50000 (client's free port)
00 50        destination port   80 (HTTP)
00 00 1F 40  sequence number    8000, the client's ISN
00 00 00 00  ack number         0, not valid (ACK flag off)
A            header length      10 words = 40 bytes, 20 bytes of options
0            reserved           0000
02           flags              0000 0010: only SYN
FA F0        window             64,240 bytes
00 00        urgent pointer     0

Why reliable: over IP, which may lose, corrupt, duplicate or reorder, TCP delivers every byte once, in order, or reports an error. Mechanisms:

  1. Connection establishment: both ready, starting numbers agreed.
  2. Sequence numbers on every byte: detect gaps, reorder, discard duplicates.
  3. Positive cumulative acknowledgements: each ACK names the next byte expected.
  4. Retransmission on timeout: sender keeps a copy and a timer; resends after RTO and doubles the timeout.
  5. Fast retransmit: three duplicate ACKs, resend at once.
  6. Checksum: damaged segment discarded, recovered like a loss.
  7. Flow control: receive window prevents receiver overflow.
  8. Congestion control: slow start and congestion window prevent router overflow.
  9. Graceful release: FIN and ACK each way.

Timer (RFC 6298), R the measured round-trip time; RTTVAR is updated first, with the old SRTT:

RTTVAR←34RTTVAR+14|SRTT−R|,SRTT←78SRTT+18R
RTO=SRTT+4×RTTVAR

The timeout follows the path: short and steady gives a short RTO, long and jittery a longer one.

Memory example: exam forms sent by courier; pages numbered, the office phones "got 1 to 20, send 21" (cumulative ACK), unconfirmed pages resent, torn page treated as missing.

The book's Figure 5.4 shows 6 flags with unlabelled reserved bits (RFC 793, 6 reserved bits); RFC 9293 has 4 reserved bits and 8 flags (CWR, ECE from RFC 3168, 2001); either drawing is right if each row adds to 32 bits. The book calls the window "the window size of the sending TCP": precisely, the receive window the segment's sender advertises. It says options give "congestion control": options are MSS, window scale, SACK, timestamps; congestion control works through the window.

TCP against UDP, and why the transport layer has two protocols

HOT 6/27 Open the full card

TCP and UDP: the two transport protocols of TCP/IP, a trade between reliability and speed: TCP buys a reliable, ordered, connection-oriented byte stream with a handshake, a bigger header and waiting; UDP drops every guarantee for no setup, 8 bytes of header, no waiting.

PointTCPUDP
Connectionconnection-oriented: handshake, releaseconnectionless
ReliabilityACK and retransmissionnone
Orderin order (sequence numbers)none
Data unitsegment; byte streamuser datagram; message kept whole
Header20 to 60 bytes8 bytes
Flow, congestion controlreceive and congestion windowsnone
Error checkingmandatory checksum; repaired by retransmissionchecksum (optional in IPv4); bad datagram dropped
Speedslower: setup round trip, waits for lossesfaster: sends at once
Castingunicast onlyunicast, broadcast, multicast
Server stateTCB and buffers per connectionnone
IP protocol number617
Used byHTTP/HTTPS 80, 443; SMTP 25; FTP 20, 21; SSH 22; Telnet 23DNS 53; DHCP 67, 68; SNMP 161; TFTP 69; NTP 123; calls; games; QUIC

Memory example: TCP is a phone call home ("hello", "hajur, bhannus" before talking; "feri bhannu ta?" for a lost word). UDP is shouting the cricket score down the hostel corridor: no setup, no answer, the next shout carries the new score.

Why two transport protocols but one internet protocol:

Figure: the hourglass: many applications on top, TCP and UDP below them (end hosts only), IP alone at the waist (every router), many link technologies at the bottom (Ethernet, WiFi, 4G and 5G, fibre, DSL).

  1. Opposite needs: files and web pages must arrive complete and in order; a voice call must arrive on time. Recovering a loss means waiting, which real-time traffic cannot afford: one protocol cannot give both.
  2. End-to-end principle: transport runs only in the end hosts; two choices cost routers nothing.
  3. IP is the common meeting point: every router and every link technology must handle it; one minimal best-effort protocol any network can offer gives universal reach: the narrow waist.
  4. Changing the waist is costly: a new transport needs only hosts to change; a new network protocol needs every router changed (IPv6 still not complete after decades).
  5. UDP keeps the door open: IP's raw service plus ports, so applications build their own reliability (QUIC) without touching the network.

Strictly: the transport layer also has SCTP (RFC 9260) and DCCP (RFC 4340), QUIC (RFC 9000) runs over UDP, and the internet layer has IPv4 and IPv6 plus helpers such as ICMP; TCP and UDP still carry nearly all application data over one routed IP.

Ports and sockets: how a segment finds its process

PIN 4/27 Open the full card

Port number (port address): a 16-bit number, 0 to 65,535, in every TCP and UDP header, naming a process on a host. Socket (socket address): IP address plus port, such as 203.0.113.5:80; one TCP connection is named by a pair of sockets.

Why ports: IP brings data to a host that runs many processes at once; each process needs its own label. Four levels of address in TCP/IP:

AddressLayerSizeNamesExample
Physical (MAC)data link48 bitsa network card; changes hop to hop00:1A:2B:3C:4D:5E
Logical (IP)network32 bits (IPv4)a host; same end to end203.0.113.5
Porttransport16 bitsa process80
Application-specificapplicationvariesuser or document, converted to the othersan e-mail address, a URL

Memory example: a college with one phone number (IP) and extensions (ports) printed on the notice board (well-known); a caller is given a line for the call (ephemeral port).

Figure: the three IANA ranges, and three client sockets (198.51.100.10:52344, 198.51.100.10:52345, 198.51.100.20:49200) connected to one server socket 203.0.113.5:80, told apart by their four-tuples.

RangeNumbersWho sets themExamples
Well-known (system)0 to 1023assigned by IANA; on Unix only root may open22 SSH, 25 SMTP, 53 DNS, 80 HTTP, 443 HTTPS
Registered (user)1024 to 49151registered with IANA by vendors, not controlled3306 MySQL, 3389 Remote Desktop, 8080 HTTP alternate
Dynamic (private, ephemeral)49152 to 65535never assigneda client's temporary port

Common ports: FTP 20 (data), 21 (control) TCP; SSH 22 TCP; Telnet 23 TCP; SMTP 25 TCP; DNS 53 UDP and TCP; DHCP 67 server, 68 client UDP; TFTP 69 UDP; HTTP 80 TCP; POP3 110 TCP; NTP 123 UDP; IMAP 143 TCP; SNMP 161, trap 162 UDP; BGP 179 TCP; HTTPS 443 TCP (and UDP for QUIC); RIP 520 UDP.

Ephemeral ports: the operating system gives a client a free port per connection (Windows: IANA range 49152 to 65535; Linux default 32768 to 60999). No standard needed: the server reads the client's port from the SYN.

Why well-known ports are standardized:

  1. Meeting point known in advance: the client must know where to knock; DNS gives the IP address but not the port.
  2. Interoperability: any client reaches any server with no configuration or lookup.
  3. Defaults: http://ioe.edu.np/ carries no port; 80 is implied.
  4. Administration and security: firewall, NAT and IDS rules written per port (allow 443, block 23); only root opens ports below 1024, so a system service is behind them.
  5. No clashes: one registry, no two services on one number.

Web service on port 8765 instead of 80: TCP works the same. The port must be written in the URL (http://www.example.com:8765/); without it the browser tries 80, and if nothing listens there the server's TCP sends RST (connection refused), or another service on 80 answers. Every link, bookmark and search result must carry the port. Firewalls that allow only 80 and 443 may block it. Hiding on an odd port is security through obscurity; a scanner finds it. Convenience: above 1023, an ordinary user can run it (python -m http.server 8765, then http://localhost:8765/).

Socket, two meanings:

  • Address: IP : port with the protocol; a connection is the socket pair (four-tuple), so one server socket 203.0.113.5:80 holds thousands of connections, each client socket differing in IP or port.
  • Programming interface: the door between an application and the transport layer (Berkeley sockets API); the application controls its side, and on the transport side chooses only the protocol and a few settings (buffer sizes, MSS).
  • Importance: identifies a process uniquely across the internet, lets many connections share one server port, separates each connection's traffic, and is the interface every network application is written on.

The book's Table 5.2 lists ICMP 1, IPv6 41, OSPF 89 and "17/6" for IP beside real ports: those are IP protocol numbers (the IPv4 protocol field); ICMP, IPv6-in-IPv4 and OSPF run directly on IP with no port, and 17 and 6 are UDP and TCP. Its socket example writes port 96 in the text while Figure 5.7 shows 69 (the TFTP port).

Opening and closing a TCP connection: the three-way handshake and the graceful release

HOT 7/27 Open the full card

Three-way handshake: TCP connection setup in three segments: SYN (client ISN x), SYN + ACK (server ISN y, ack x + 1), ACK (ack y + 1); synchronizes both sequence numbers and proves both sides ready. Release is graceful: each direction closed by its own FIN and ACK, four segments.

Passive and active open: the server creates a socket, binds its well-known port, listens and waits in LISTEN (passive open); the client calls connect, which sends the SYN (active open).

Why the server program runs first: only a socket in LISTEN accepts a SYN. With no listener on the port, the server host's TCP replies RST and the client's connect fails ("connection refused"); TCP does not queue a SYN until a server appears. UDP: a datagram to a port with no socket is dropped and the host returns ICMP port unreachable. A shop must open its shutter before customers can enter.

Handshake with the book's numbers (client ISN 8000, server ISN 15000):

  1. SYN (client to server): SYN = 1, seq = 8000, no data; CLOSED to SYN-SENT. A SYN consumes one sequence number; carries options (MSS, window scale).
  2. SYN + ACK (server to client): SYN = 1, ACK = 1, seq = 15000, ack = 8001; server allocates buffers and record; LISTEN to SYN-RECEIVED.
  3. ACK (client to server): ACK = 1, seq = 8001, ack = 15001; client ESTABLISHED on sending, server on receiving; may carry data.

Figure: sequence diagram of the handshake with states, then data: client seq 8001 (1000 bytes) ack 15001; server seq 15001 (500 bytes) ack 9001.

Why three, not two:

  • Both ISNs confirmed: SYN + ACK confirms the client's, the final ACK the server's.
  • Old duplicates: a delayed SYN from an earlier attempt would open an unwanted connection with two segments; with three, the client receives a SYN + ACK it never asked for and answers RST, so the server drops it (book Figure 5.9).
  • Random ISN: old segments on the same ports are not mistaken for new ones, and attackers cannot guess numbers to inject data.

Memory example: phone call home: "Hello Aama, can you hear me?" (SYN); "Yes, can you hear me?" (SYN + ACK); "Yes!" (ACK); then the real talk.

SYN flood: floods of SYNs from forged addresses, third ACK never sent; half-open connections exhaust the server's queue. Defences: SYN cookies (state encoded in the ISN, none kept until the ACK), shorter timeouts, firewall filtering.

Release, continuing after client sent 1,000 bytes (8001 to 9000) and server 500 (15001 to 15500):

  1. FIN (client): seq = 9001, ack = 15501; FIN-WAIT-1. A FIN consumes one sequence number.
  2. ACK (server): seq = 15501, ack = 9002; server CLOSE-WAIT (tells its application); client FIN-WAIT-2. Half-closed: the server may still send.
  3. FIN (server): seq = 15501, ack = 9002, when its application closes; LAST-ACK.
  4. ACK (client): seq = 9002, ack = 15502; server CLOSED on receipt; client TIME-WAIT for 2 MSL, then CLOSED.

Figure: sequence diagram of the four-segment release with states and the TIME-WAIT bracket.

Why four segments: full duplex, each direction closed on its own. If the server has nothing left to send it can combine ACK and FIN: a three-segment release.

Why TIME-WAIT: a lost final ACK makes the server resend FIN, which the client must re-acknowledge; delayed segments of the connection die out before the same port pair is reused. RFC 793 suggested MSL 2 minutes (TIME-WAIT 4 minutes); Linux waits 60 seconds.

Abrupt release: RST ends the connection at once, data in flight lost (a crashed program, or a segment matching no connection).

StateMeaning
CLOSEDno connection
LISTENserver waiting for SYN
SYN-SENTclient sent SYN, waiting for SYN + ACK
SYN-RECEIVEDserver got SYN, sent SYN + ACK, waiting for ACK
ESTABLISHEDopen, data both ways
FIN-WAIT-1sent FIN, waiting for its ACK
FIN-WAIT-2FIN acknowledged, waiting for the other FIN
CLOSE-WAITgot FIN, waiting for the local application to close
LAST-ACKsent own FIN after CLOSE-WAIT, waiting for last ACK
CLOSINGboth sent FIN at once
TIME-WAITwaiting 2 MSL after the final ACK

The book's Figure 5.11 labels the third segment "seq: 8000, ack: 15001" and Figure 5.8 "Data (seq = x, ACK = y + 1)"; the SYN used up x, so the third segment carries seq = x + 1 (8001), as in RFC 9293's example. The acknowledgement numbers are right.

Flow control and buffering: TCP's sliding window

PIN 2/27 Open the full card

Transport flow control: end-to-end control that stops a fast sender overflowing a slow receiver's buffer. TCP uses a byte-oriented sliding window: every segment advertises the receive window (rwnd), the free space in the receiver's buffer; the sender keeps at most rwnd bytes sent but unacknowledged.

Why: a slow application leaves data piling up in TCP's receive buffer; overflow would lose data, so the receiver states in each segment's window field how much more it can take.

Four regions of the sender's bytes: sent and acknowledged; in flight (sent, not acknowledged); usable window (allowed, not sent); not allowed until the window moves. Left edge = last ACK; right edge = last ACK + rwnd.

Figure: byte blocks 1001 to 9001; before, ACK 3001 and rwnd 4000 give the window 3001 to 7000 (3001 to 6000 in flight, 6001 to 7000 usable); after ACK 5001 with rwnd 4000 the window is 5001 to 9000 (5001 to 6000 in flight, 6001 to 9000 usable).

Worked example:

  1. Start: last ACK 3001, rwnd 4000: 3001 to 7000 may be outstanding; sent up to 6000, so 3,000 in flight and 6001 to 7000 may go.
  2. ACK 5001, window 4000: window 5001 to 9000; 1,000 in flight, 3,000 may be sent; slid 2,000 bytes right.
  3. Slow reader: ACK 5001 with window 2000 keeps the right edge at 7000: only 1,000 bytes may go.
  4. Buffer full: window 0 stops the sender; a persist timer sends small window probes until space is advertised, so a lost window update cannot deadlock both sides.

Memory example: a water tanker filling a household tank asks how much room is left and pumps no more; as water is used, the room grows.

Refinements:

  • Silly window syndrome: one-byte windows lead to one-byte segments with 40 bytes of headers. Clark: the receiver advertises only when it can take a full segment or half its buffer. Nagle (RFC 896): a sender with small data sends one piece and holds the rest until it is acknowledged or a full segment gathers.
  • Window scaling: the 16-bit field allows 65,535 bytes; at most one window per round trip, so with a 100 ms round trip a connection is capped at 65,535 times 8 / 0.1, about 5.24 Mbps. A 100 Mbps, 100 ms path needs 100,000,000 times 0.1 / 8 = 1,250,000 bytes in flight (bandwidth-delay product); the window scale option multiplies the field by up to 2 to the 14.

With congestion control the sender's limit is min(rwnd, cwnd).

Buffering: hundreds of connections per host, so not one fixed buffer set per line; buffer space shared, size agreed at setup and adjusted by the receiver's advertisements.

SchemeHowGood forWeakness
Chained fixed-size bufferspool of identical buffers, one TPDU eachsegments of similar sizesmall segment wastes a buffer; big one needs several
Chained variable-size bufferseach buffer cut to fitsizes from a few bytes to thousandsharder memory management
One large circular buffer per connectiona ring the data flows roundbusy connectionswastes memory on light connections

Where to buffer: low-rate bursty traffic (an interactive terminal): buffer at the sender, receiver grabs buffers as data arrives; bulk transfer (file download): receiver sets aside a full window of buffers.

PointLink-level window (chapter 3)TCP's window
Countsframesbytes
Sequence numberssmall, such as 3 bits (0 to 7)32 bits
Window sizefixedadvertised in every segment
Scopeone link, hop by hopend to end
Recoverygo-back-N or selective repeatcumulative ACKs like go-back-N; early segments kept and SACK resends only gaps, like selective repeat

Multiplexing and demultiplexing: many processes, one IP address

Open the full card

Multiplexing (sender): gather data from many sockets, add a header with source and destination ports to each chunk, pass all segments to the one network layer. Demultiplexing (receiver): read the ports in each arriving segment and deliver its data to the right socket.

Figure: a laptop 198.51.100.10 with browser tab 1 (TCP 52344), browser tab 2 (TCP 52345) and a DNS resolver (UDP 50000); three segments arrive at the one IP (TCP from 203.0.113.5:80 to 52344, TCP from 203.0.113.5:80 to 52345, UDP from 198.51.100.53:53 to 50000) and are sorted by port.

  • UDP demultiplexes by two values: destination IP and destination port; datagrams from any senders to one port share one socket.
  • TCP demultiplexes by four values: source IP, source port, destination IP, destination port; a web server on port 80 has one socket per client connection.

Memory example: one postbag for the whole hostel sorted by room number into residents' boxes (demultiplexing); outgoing letters dropped in one bag, each with its room number as return address (multiplexing).

Older sense (also in the book): upward multiplexing, several transport connections share one network connection or address (saves cost where network connections are scarce or charged, like old virtual circuits; works while the shared bandwidth covers all needs); downward (inverse) multiplexing, one transport connection spread over several paths for bandwidth or resilience (Multipath TCP, RFC 8684; SCTP with several addresses).

Not the physical layer's multiplexing (FDM, TDM share a cable among signals, chapter 2): here one IP address is shared by processes and the port is the channel number.

Congestion: causes, the parameters that affect it, prevention and control

PIN 4/27 Open the full card

Congestion: the load offered to a network, or part of it, exceeds its capacity: router queues fill, delay climbs, packets are dropped and resent, useful throughput falls; at worst congestion collapse, the network busy with retransmissions and delivering almost nothing.

Congestion control is not flow control: flow control protects one receiver from one sender; congestion control protects the network's links and router buffers from all senders together. A fast laptop and a slow phone need flow control; a hostel uploading through one link needs congestion control.

Memory example: results day; thousands open the same results page at once; same links and server, only more load; pages time out, every refresh adds load (the collapse).

Causes (factors), in a WAN or any packet-switched network:

  • Arrival rate above outgoing capacity: several inputs feeding one output line; its queue grows without limit.
  • Too little buffer memory: drops when queues fill; more memory is no cure, packets wait until they time out and are resent as duplicates (Nagle, 1987).
  • Bursty traffic: sources bursting together exceed capacity briefly.
  • Slow processors and slow lines: a router that cannot queue, route and forward fast enough, or a low-bandwidth link.
  • Retransmissions: congestion feeds itself.
  • Poor routing, long packet lifetimes: one path overloaded while others idle; old packets wandering.

Parameters (policies) and their effect:

LayerPolicyEffect on congestion
Transportretransmission policyhasty timer or go-back-N resends more
Transportout-of-order caching policydiscarding early segments forces resends
Transportacknowledgement policyACK per segment adds traffic; delayed, piggybacked ACKs cut it
Transportflow control policysmall window keeps the rate down
Transporttimeout determinationtoo short: duplicates; too long: slow recovery
Networkvirtual circuits against datagramscircuits allow admission control, reserved resources
Networkpacket queueing and service policyone queue or one per line; FIFO or fair turns
Networkpacket discard policywhich packet is dropped when a queue is full
Networkrouting algorithmspreading traffic relieves hot spots
Networkpacket lifetime managementtoo long: old packets clog; too short: packets die, resent
Data linkretransmission, out-of-order caching, acknowledgement, flow controlsame effects on each link

Load and delay (M/M/1 queue, service rate μ packets per second, random arrivals λ per second):

T=1μ−λ

With μ = 1,000: λ = 500 gives 2 ms, 900 gives 10 ms, 990 gives 100 ms; the last 10% of load costs ten times the delay.

Prevention policies (open loop):

  • Retransmission policy: good timers, no resending of merely late packets.
  • Window policy: selective repeat instead of go-back-N.
  • Acknowledgement policy: cumulative, delayed, piggybacked ACKs.
  • Discard policy: routers drop least important packets first (some audio packets).
  • Admission policy: a virtual circuit network refuses a flow that would congest it.
  • Traffic shaping: agreed rate and burst size, smoothed before entry (leaky and token buckets).
FamilyIdeaTechniques
Open loop (prevention)good design, no feedbackthe policies, admission control, traffic shaping, resource reservation
Closed loop (removal)monitor, feed back, adjustbackpressure (congested router asks the router before it to slow), choke packets to the source, implicit signalling (loss or delay, as TCP), explicit signalling (ECN bits), load shedding, random early detection (RED: drop a few early)

Closed loop in three steps: detect congestion (queue lengths, drops, delay); send the information where action can be taken; adjust (slow the sources).

TCP's congestion control (RFC 5681): congestion window cwnd beside rwnd. Slow start: cwnd starts small, doubles each round trip up to a threshold. Congestion avoidance: plus one segment per round trip (additive increase). Three duplicate ACKs: halve cwnd (multiplicative decrease) with fast retransmit and fast recovery. Timeout: cwnd back to one segment, slow start again.

Traffic shaping regulates the average rate and burstiness of a flow before it enters the network, holding packets back to conform; policing only monitors and drops (or tags) packets that break the agreed profile. Both use the buckets.

The leaky bucket: bursty in, steady out

HOT 5/27 Open the full card

Leaky bucket algorithm: traffic shaping in which each host's interface holds a finite queue (the bucket) that accepts packets at any rate but releases them into the network at a constant rate; a packet arriving when the bucket is full is discarded.

Picture: a bucket with a hole; water in at any rate, out at a steady rate while any remains, none when empty; overflow spills and is lost. Packets for water, the interface queue for the bucket.

Figure: (a) water from a tap into a full bucket, overflow lost, steady drops below; (b) host, "full?" test (yes: discard; no: queue), packets removed at a constant rate into the network.

Fixed-size packets:

  1. Packet arrives; if the bucket is full, discard.
  2. Otherwise it joins the queue.
  3. Each clock tick one packet leaves; none if empty.
  4. Output: smooth, at most one packet per tick, however bursty the input.

Variable-size packets (byte counting, the book's version):

  1. At each tick set a counter to n bytes.
  2. While the head packet fits (size not more than the counter), send it and subtract its size.
  3. When the next packet does not fit, stop until the next tick.
  4. Reset the counter at the next tick; leftover count not carried forward, so no tick sends more than n bytes.

Worked example, n = 1,000 bytes a tick, packets 200, 700, 500, 300: tick 1 sends 200 (800 left) and 700 (100 left), 500 does not fit, 900 bytes sent, 100 not saved; tick 2 sends 500 (500 left) and 300 (200 left), queue empty. Fixed-size: a bucket of 6 packets draining 1 per millisecond, hit by 10 at once, keeps 6, discards 4, sends the 6 one per millisecond.

Memory example: the ceramic water filter in many Nepali kitchens; pour a whole jug in, clean water still drips at the same slow rate; overfill and it overflows.

  • Good: removes burstiness completely; predictable constant-rate flow; simple (a queue and a clock).
  • Rigid: same rate even when the network is idle; idle host saves nothing.
  • Lossy: bursts bigger than the bucket lose packets.
  • Slow to respond: urgent bursts still drained at the fixed rate.

The book captions the implementation figure on page 185 "Figure 4.15" in a chapter numbered 5.x.

The token bucket: saving up permission to burst

TOP 9/27 Open the full card

Token bucket algorithm: traffic shaping in which tokens drop into a bucket at constant rate r, up to capacity C, and a packet (or byte) leaves only by taking a token; an idle host saves tokens and may later burst up to C at the full line rate, while its long-run average stays r.

The bucket holds permission, not data; packets wait in the host's queue and go as fast as the line allows while tokens last.

Figure: (a) host with 5 packets waiting, bucket of capacity 3 holding 3 tokens, one token added every delta T, a new token discarded when full; (b) after: 3 packets sent at once, bucket empty, 2 waiting for tokens.

  1. Every delta T a token is added (r = 1/delta T per second); a full bucket (C tokens) discards the new token.
  2. A packet is sent only if a token is available, removing one (byte version: one token per byte).
  3. No token: the packet waits; the bucket throws away tokens, never packets.
  4. Implementation: one counter, plus 1 every delta T up to C, minus 1 per packet sent; at 0 nothing is sent.

Book example: 5 packets waiting, 3 tokens saved: 3 sent at once (a burst), 2 wait for the next tokens; a leaky bucket would release the 5 one tick apart.

Burst length: C capacity, r token rate, M maximum line rate, S burst length in seconds. During the burst the host sends MS, paid by the C saved plus rS arriving:

C+rS=MS⟹S=CM−r

Worked example: a router shapes a hostel's upload; M = 10 Mbps, r = 2 Mbps, bucket full with C = 6 Mb (750 KB); a 12 Mb file sent at full speed.

S=610−2=0.75 s
  1. Burst: 0.75 s at 10 Mbps, 7.5 Mb (check: 6 saved plus 2 times 0.75 = 1.5 arriving = 7.5).
  2. Then 12 minus 7.5 = 4.5 Mb at 2 Mbps, 2.25 s; done at 3.0 s.
  3. A 2 Mbps leaky bucket takes 12 / 2 = 6 s; holding only 6 Mb it would lose 3.6 Mb of the burst.

Same average rate and long-run load; the token bucket finishes in half the time and loses nothing.

Figure: rate against time for the same 12 Mb burst: input 10 Mbps for 1.2 s; leaky bucket 2 Mbps for 6 s; token bucket 10 Mbps for 0.75 s then 2 Mbps until 3.0 s; equal areas (12 Mb).

Memory example: hostel meal coupons; one a day, unused ones pile up to three; after two light days eat three meals at once (burst), never more than one a day on average (rate). The leaky bucket is a mess serving exactly one plate a day, hungry or not.

PointLeaky bucketToken bucket
Bucket holdspacketstokens (permission)
Outputconstant raverage r, bursts up to C at line rate
Idle hostsaves nothingsaves tokens up to C
Bucket fullarriving packets discardedarriving tokens discarded; packets wait
Burstinessremovedallowed, bounded by C
Sudden burstdrained slowly at rsent at once while tokens last
Idle networkwastedused by the saved burst
Parametersqueue size, output ratetoken rate r, bucket size C
Implementationqueue and clock (or byte counter reset each tick)token counter and queue

Why the token bucket controls congestion better: both hold the long-run rate at r, so the average load is bounded as before; but a quiet host can use the capacity it left unused, bursts go at once, no data is lost when the bucket fills (only tokens), and the worst-case burst is capped at C, so the network knows the most it must absorb.

Both together: a leaky bucket of rate p (r below p below M) after the token bucket caps the peak rate, while the token bucket keeps the average at r.

Proposed traffic shaping approach for a packet-switched network:

  1. Agree a profile with each source at the edge: average r, burst C, peak p if needed.
  2. Shape at the source: token bucket (r, C), then a leaky bucket at p.
  3. Police at the edge router: in-profile packets pass; excess dropped or tagged low priority.
  4. Closed-loop backing: TCP's congestion window at hosts, early dropping or ECN at routers.

Why best: fixed average load per source (plannable), bounded bursts, no loss while the source keeps its profile, idle capacity used. ISPs enforce plan speeds this way; the Internet's quality of service schemes describe a flow by a token bucket rate and depth.

On "never discards packets" (the book, like Tanenbaum): true of the bucket itself; a shaper's packet queue is finite and can overflow, and a policer built on a token bucket drops or tags packets that find no token. The point: a full bucket of tokens costs no data.

Chapter 6: Application layer 8240 words

The application layer: what it does, and the ports its protocols use

Open the full card

Application layer: the top layer of the TCP/IP model, home of network applications and their protocols. An application layer protocol defines the messages two application processes exchange: their types (request, reply), syntax (fields), meaning, and the rules for when a process sends what. It hands its messages to TCP or UDP to carry.

  • Only end systems run it: routers and switches work at the network layer and below; only the browser and the web server read the HTTP messages. New applications spread without changing routers.
  • Client-server: an always-on server with a fixed address and a well-known port serves many clients that never talk to each other directly (web, mail, FTP, DNS).
  • Peer-to-peer (P2P): ordinary hosts both ask and serve, with little or no central server (BitTorrent).
  • Sockets: a process hands its message to its socket, the door between the application and the transport layer; the message is addressed by the destination IP address and port. Servers wait on well-known ports (0 to 1023); the client's port is a temporary one picked by its operating system.
  • Transport needs: reliability, throughput, low delay, security. TCP for the web, mail and file transfer; UDP (no connection setup) for DNS queries, DHCP, SNMP, TFTP and live voice.
ProtocolJobTransportServer port
HTTPfetch web pages and objectsTCP80
HTTPSHTTP inside TLSTCP443
FTPfile transfer with a loginTCP21 control, 20 data (active mode)
SSH, SCP, SFTPencrypted remote login and copyTCP22
Telnetplain-text remote loginTCP23
SMTPsend and relay mailTCP25 between servers, 587 from a user agent
DNSnames to addressesUDP; TCP for zone transfers and long replies53
DHCPgive a host its IP settingsUDP67 server, 68 client
TFTPsimple file transfer, no loginUDP69
POP3download mail from a mailboxTCP110 (995 with TLS)
IMAPmanage mail kept on the serverTCP143 (993 with TLS)
SNMPmonitor and manage devicesUDP161 agent, 162 traps

Memory example: the IP address is the ward office building, the port the counter number inside; counter 25 takes letters, 53 answers "where is this name?", 80 hands out pages.

HTTP and HTTPS: how a browser's request is served

HOT 5/27 Open the full card

HTTP (HyperText Transfer Protocol): the web's application layer protocol, a stateless request and response protocol: the client (browser) sends a request naming an object by its URL; the web server returns it in a response; both over a TCP connection to port 80. HTTPS: HTTP inside an encrypted TLS connection, port 443.

  • Web page: a base HTML file plus referenced objects (images, style sheets, scripts), each named by a URL. In https://www.example.com:443/notes/ch6.html?lang=np: scheme https, host www.example.com, port 443 (omitted when default), path /notes/ch6.html, query lang=np. A page with ten images costs eleven requests.

How a request is served:

  1. Name to address: DNS lookup of the host name.
  2. Connection: TCP three-way handshake to port 80 (443 plus the TLS handshake for HTTPS).
  3. Request: request message, for example GET /index.html HTTP/1.1 and header lines.
  4. Processing: the server parses it, maps the path to a file under its document root, or runs a program (PHP) for a dynamic page, and builds the response.
  5. Response: status line (HTTP/1.1 200 OK), header lines, the object as body.
  6. Render and repeat: the browser parses the HTML, requests each referenced object, draws the page.
  7. Close or keep: close, or keep the connection for the next request (persistent HTTP).

Figure: a time sequence of SYN, SYN+ACK, ACK with GET, 200 OK with the page, a second GET on the same connection, and FIN; one RTT for the handshake, one RTT plus transfer for the page; the request and response messages beside it.

GET /notes/ch6.html HTTP/1.1
Host: www.example.com
User-Agent: Mozilla/5.0
Accept: text/html
Accept-Language: en, ne
Connection: keep-alive

HTTP/1.1 200 OK
Date: Sun, 04 Oct 2026 09:00:00 GMT
Server: Apache
Last-Modified: Fri, 02 Oct 2026 16:30:00 GMT
Content-Type: text/html; charset=UTF-8
Content-Length: 5120

<!DOCTYPE html><html> ... the page ... </html>

Request message: request line (method, path, version), header lines Name: value, blank line, optional body (form data with POST). Response: status line (version, code, phrase), headers, blank line, body.

MethodWhat it asks
GETsend the object at this URL
HEADthe headers GET would send, no body
POSTprocess this data (login form, upload)
PUTstore this body at this URL
DELETEremove the object
PATCH, OPTIONS, CONNECT, TRACEpartial change; allowed methods; tunnel through a proxy (HTTPS); echo
ClassMeaningCommon codes
1xxinformational100 Continue, 101 Switching Protocols
2xxsuccess200 OK, 201 Created, 204 No Content
3xxredirection301 Moved Permanently, 302 Found, 304 Not Modified
4xxclient error400 Bad Request, 401 Unauthorized, 403 Forbidden, 404 Not Found
5xxserver error500 Internal Server Error, 502 Bad Gateway, 503 Service Unavailable
  • Stateless: the server keeps no memory of earlier requests; simple, easy to multiply. Cookies add memory: Set-Cookie: session=8f2a in a response, Cookie: session=8f2a in every later request; the server looks the number up in its database (a canteen token).
  • Non-persistent (HTTP/1.0 default): one TCP connection per object, 2 RTT each plus transmission time. Persistent (HTTP/1.1 default, Connection: keep-alive): one RTT per later object, less with pipelining.
Tobject=2RTT+Ttransmit

Example: one HTML file and 10 images, RTT 50 ms: non-persistent 11 x 2 RTT = 22 RTT = 1,100 ms; persistent 2 + 10 = 12 RTT = 600 ms; persistent with pipelining 3 RTT = 150 ms.

VersionYearWhat it brought
HTTP/1.01996, RFC 1945one object per connection
HTTP/1.11997, now RFC 9112persistent connections, pipelining, Host header, chunked transfer
HTTP/22015, now RFC 9113binary frames, multiplexed requests, header compression
HTTP/32022, RFC 9114over QUIC on UDP with TLS 1.3; faster start, no stall of all streams on one loss

HTTPS: TCP to port 443, then the TLS handshake: the server's certificate (signed by a trusted certificate authority) and agreed session keys; then every message encrypted and integrity-checked. It gives server authentication (defeats a fake site, man in the middle), confidentiality, integrity. It does not hide the server's IP, usually the site name (sent in the handshake), or traffic size and timing. Browsers label plain HTTP pages "Not secure"; search engines give HTTPS a small ranking boost.

PointHTTPHTTPS
Full nameHyperText Transfer ProtocolHTTP Secure: HTTP over TLS (formerly SSL)
Default port80443
URLhttp://https://
LayeringHTTP over TCPHTTP over TLS over TCP
On the wireplain text, readable and changeableencrypted, integrity-checked
Server identitynot provedcertificate from a CA
Setup costTCP handshakeTCP plus TLS handshake (one round trip in TLS 1.3)
Used forredirects, local testslogins, payments (eSewa), every modern site
  • Web server: Apache httpd, Nginx, Microsoft IIS. Listens on 80 and 443; per request: parse, check access, map the path to a file under the document root (GET /index.html gives /var/www/html/index.html) or hand it to a program (PHP, Python, Node.js), respond with status and headers, log it. Concurrency: process or thread per connection (Apache) or an event loop (Nginx). Virtual hosting: many sites on one IP, chosen by the Host: header.
  • Web server communication: DNS (UDP 53) for the address, TCP for the connection (80 or 443), TLS for HTTPS, HTTP for request and response, IP for routing.
  • The book's claim that HTTPS is slower: only a new connection pays for TLS (one round trip in TLS 1.3); with persistent connections and HTTP/2 rarely slower.

Memory example: HTTP is a postcard every post office can read and rewrite; HTTPS a sealed, verified envelope, only the address visible.

FTP and TFTP: copying files across the network

PIN 4/27 Open the full card

FTP (File Transfer Protocol, RFC 959): the standard TCP/IP protocol for copying files between client and server after a login, over two TCP connections: a control connection to server port 21, open for the whole session (commands and replies), and a data connection, server port 20 in active mode, opened for each file or listing and closed after it.

  • Out of band: commands never mix with file bytes; ABOR can stop a transfer; the control channel is one text command, one reply. HTTP is in band.
  • Model: each side has a control process (protocol interpreter) and a data transfer process; the client adds the user interface.

How a client connects:

  1. Control connection: TCP to port 21; 220 Service ready.
  2. Login: USER anuj, 331 Password required; PASS, 230 User logged in (530 if wrong). Public archives accept user anonymous.
  3. Settings: TYPE I binary, TYPE A text; 200.
  4. Data connection: active: PORT 192,168,1,10,195,80 (port 195 x 256 + 80 = 50000), the server connects from port 20; passive: PASV, 227 Entering Passive Mode with a high port, the client connects.
  5. Transfer: RETR download, STOR upload, LIST listing; 150, bytes on the data connection, data connection closes, 226 Transfer complete.
  6. Repeat, then quit: a new data connection per file; QUIT, 221 Goodbye.

Figure: an FTP session in active mode: control messages to port 21 and back, then the data connection from port 20 to client port 50000, then 226 and QUIT; notes on control, data and passive mode.

PointActive (PORT)Passive (PASV)
Opens the data connectionserver, from port 20client
Toclient's port in PORTserver's high port in the 227 reply
NAT and firewallsoften blockedpasses: both connections outward from the client
Todayraredefault in most clients (FileZilla, WinSCP)
CommandMeaningTypical reply
USER, PASSlog in331, then 230 (530 on failure)
CWD, PWDchange, print directory250, 257
LISTlisting on a data connection150, then 226
RETR, STORdownload, upload150, then 226
TYPE A, TYPE IASCII or binary image200
PORT, PASVactive or passive data connection200, 227
QUITend the session221
  • Reply codes: first digit 1 started (wait), 2 done, 3 send the next part, 4 temporary failure, 5 permanent failure.
  • Data types: ASCII, EBCDIC, image (binary). Modes: stream (default), block, compressed. A photo in ASCII mode is damaged by line-ending conversion.
  • Stateful: the server remembers user, directory and type for the session (HTTP is stateless).
  • Not secure: password in plain text (visible in Wireshark); FTPS (FTP over TLS) or SFTP instead.

Memory example: a shop counter (control connection) for the whole visit; a back door opened for each parcel (data connection); active, the shopkeeper delivers to the customer's gate (locked by NAT); passive, he names a door and the customer collects.

TFTP (Trivial File Transfer Protocol, RFC 1350): UDP port 69, no login, no listing, only read and write.

  • Packets: RRQ (opcode 1), WRQ (2), DATA (3), ACK (4), ERROR (5).
  • Lock step: numbered 512-byte blocks, each ACKed before the next (stop and wait); resent after a timeout; a block under 512 bytes ends the file: 2,000 bytes go as 512, 512, 512, 464; exactly 1,024 bytes needs a final empty block.
  • Ports: request to 69; the server answers from a fresh port that carries the transfer.
  • Uses: booting diskless machines (PXE), loading firmware and configuration onto routers, switches and IP phones (copy tftp); small enough for a boot ROM.
PointFTPTFTP
TransportTCPUDP
Ports21 control, 20 data69, then a fresh port
Loginuser name, passwordnone
Commandsdozensread or write only
ReliabilityTCP'seach 512-byte block ACKed
Usegeneral file transferbooting, device images
  • File servers in a LAN: SMB (Windows file sharing, TCP 445), NFS (Unix, port 2049): mount a remote folder.
  • The book gives port 20 for data without saying it holds only in active mode; in passive mode the server names a high port in its 227 reply.

Remote login and secure transfer: Telnet, SSH, PuTTY and WinSCP

Open the full card

SSH (Secure Shell): encrypted remote login and command execution over TCP port 22; the same channel carries file transfer (SCP, SFTP) and forwarded ports.

  • Telnet (RFC 854, TCP 23): remote terminal in plain text, password included; replaced by SSH.
  • SSH versions: SSH-1 1995; SSH-2 standardised 2006 (RFC 4251 to 4254).
  • Transport layer: server's host key, key agreement, encryption and integrity; fingerprint prompt on first connection.
  • User authentication: password, or a key pair (public key in ~/.ssh/authorized_keys, private key stays on the laptop).
  • Connection layer: many channels: shell, file transfer, forwarded ports.
Tool or protocolDoesPortEncrypted
Telnetremote terminal23no
SSHremote terminal and commands22yes
SCPcopy files over SSH22yes
SFTPSSH File Transfer Protocol: list, rename, delete, resume22yes
FTPSFTP inside TLS (not SFTP)21 (990 implicit)yes
  • PuTTY: free, open-source Windows terminal emulator by Simon Tatham; client for SSH, Telnet, rlogin, raw TCP, serial; log in to a Linux server or a router console. PuTTYgen makes key pairs (.ppk), Pageant holds keys, pscp and psftp copy files.
  • WinSCP: free, open-source Windows client for SFTP, SCP and FTP (FTPS) with two panels and drag and drop; SSH code from PuTTY, FTP code from FileZilla.

Memory example: a final-year team logs in to the college Linux server with PuTTY and drags the build folder over with WinSCP, both on port 22; Telnet and FTP would expose the password on the hostel Wi-Fi.

Electronic mail: user agents, mail servers, SMTP, POP3, IMAP and MIME

TOP 11/27 Open the full card

Electronic mail: an asynchronous message service of user agents (write, read), mail servers (a mailbox per user, a queue of outgoing mail) and protocols: SMTP pushes mail to and between servers (TCP 25); POP3 or IMAP pulls it from the mailbox to the reader.

  • Asynchronous: sender and receiver need not be online together (Sita in Pokhara at night, Ram in Kathmandu next morning). Addresses here are defanged: ram@example[.]org.
ComponentWhat it isExamples
User agent (UA)compose, read, reply, forward, file mailOutlook, Thunderbird, Gmail app, browser (webmail)
Mail servermailbox per user, outgoing queue, runs the agentsa college's or company's server, Gmail's servers
MTA (message transfer agent)SMTP software moving mail between serversPostfix, Sendmail, Exim, Microsoft Exchange
MDA (message delivery agent)places arriving mail in the right mailbox, often after a spam filterprocmail, Dovecot's delivery agent
MAA (message access agent)the POP3 or IMAP server the reader pulls fromDovecot, Courier
  • Email server: a host running these programs; accepts mail for its domain (the DNS MX record points other servers to it), stores it, lets users fetch it, relays their outgoing mail.

How one mail travels:

  1. Compose: Sita writes to ram@example[.]org and presses Send.
  2. Submit: her agent hands it to her mail server with SMTP (port 587, after login); it waits in the queue.
  3. Find the server: her server looks up the MX record of example.org.
  4. Transfer: TCP to that server's port 25, SMTP push; if it is down, the mail stays queued and is retried for days before a bounce.
  5. Deliver: the receiving MDA puts it in Ram's mailbox.
  6. Read: Ram's agent pulls it with POP3 or IMAP; webmail uses HTTPS in a browser.

Figure: the mail system: Sita's agent, SMTP 587, sender's server, DNS MX lookup, SMTP 25, receiver's server with Ram's mailbox, POP3 or IMAP (110 or 143), Ram's agent; push on the left, pull on the right.

  • Push, then pull: SMTP is push (the holder of the mail starts); it cannot fetch from a mailbox and the reader's computer is not always on, so the last hop is pull (POP3, IMAP). Mail goes to an always-on server, not to the laptop.

SMTP (Simple Mail Transfer Protocol, RFC 821 of 1982, now RFC 5321): text commands, three-digit replies; every mail server is an SMTP client when sending and a server when receiving. Three phases:

  1. Connection setup: TCP to 25; 220 greeting; HELO (or EHLO, which asks for extensions); 250.
  2. Mail transfer: MAIL FROM: sender (250); RCPT TO: per recipient (250, or 550 no such mailbox); DATA (354); header lines, blank line, body, a line holding only "."; 250.
  3. Termination: QUIT; 221; TCP closes. Several messages may go before QUIT.

Figure: an SMTP session as a sequence diagram, grouped into connection setup, mail transfer and termination.

S: 220 mail.example.org ESMTP ready
C: HELO mail.example.com
S: 250 mail.example.org
C: MAIL FROM:<sita@example[.]com>
S: 250 OK
C: RCPT TO:<ram@example[.]org>
S: 250 OK
C: DATA
S: 354 End data with <CR><LF>.<CR><LF>
C: From: Sita <sita@example[.]com>
C: To: Ram <ram@example[.]org>
C: Subject: Lab report
C:
C: Ram, the lab report is attached.
C: .
S: 250 OK: queued
C: QUIT
S: 221 Bye
CommandMeaningUsual reply
HELO, EHLOclient names itself (after 220)250
MAIL FROM:sender, where a bounce goes250 OK
RCPT TO:one recipient, repeated250 OK, or 550
DATAthe message follows354; 250 after the "."
QUITend221
RSET, VRFY, NOOPabort mail; check user; nothing250
  • Reply codes: 2xx done, 3xx send the rest, 4xx temporary (421 service not available, 450 mailbox busy), 5xx permanent (550).
  • Rules: 7-bit ASCII (0 to 127) in commands, headers and body; lines at most 1,000 characters with CR LF; a body line starting with "." gets an extra dot (dot stuffing).
  • Envelope and header: MAIL FROM and RCPT TO are the envelope for servers; From: and To: inside DATA are the letter's header for the reader.
  • Security: SMTP checks no sender (spam, forgery); SPF, DKIM, DMARC records in DNS let receivers check; STARTTLS encrypts each hop; PGP or S/MIME for end to end.

POP3 (RFC 1939, TCP 110, 995 with TLS): log in, download, usually delete. States: authorization (USER, PASS), transaction (STAT, LIST, RETR, DELE), update (deletions applied after QUIT). Modes: download-and-delete (one computer), download-and-keep.

S: +OK POP3 server ready
C: USER ram
S: +OK
C: PASS ********
S: +OK 2 messages (6800 octets)
C: LIST
S: 1 1200
S: 2 5600
S: .
C: RETR 1
S: +OK 1200 octets ... (the whole message) ... .
C: DELE 1
S: +OK message 1 deleted
C: QUIT
S: +OK bye

IMAP (IMAP4rev1 RFC 3501, IMAP4rev2 RFC 9051; TCP 143, 993 with TLS): mail and folders stay on the server; state (read, answered, flagged, deleted) kept across sessions; many devices see one mailbox; fetch headers only or one part; search on the server; tagged commands.

C: a1 LOGIN ram ********
S: a1 OK LOGIN completed
C: a2 SELECT INBOX
S: * 2 EXISTS
S: a2 OK [READ-WRITE] SELECT completed
C: a3 FETCH 1 (BODY.PEEK[HEADER.FIELDS (FROM SUBJECT)])
S: * 1 FETCH (... From: Sita ... Subject: Lab report ...)
S: a3 OK FETCH completed
C: a4 LOGOUT
PointPOP3IMAP
Where mail livesdownloaded, usually deleted from serveron the server until deleted
Foldersonly INBOX on the servercreated, renamed, deleted on the server
Several devicesmail scatterssame mailbox everywhere
Statenone between sessionsread, answered, flagged kept
Partial downloadwhole messagesheaders or one part
Searchlocal copyon the server
Offlineeasyneeds a local cache
Server storagesmalllarge
Complexitysimplecomplex
Port110 (995)143 (993)

MIME (Multipurpose Internet Mail Extensions, RFC 2045 to 2049): SMTP carries 7-bit ASCII; photos, PDFs and Nepali text have bytes 128 to 255 and long unbroken runs. MIME adds headers describing each part and encodes any bytes as 7-bit text; the receiving agent decodes.

HeaderSaysExample
MIME-VersionMIME is used1.0
Content-Typemedia typetext/plain, text/html, image/jpeg, application/pdf, multipart/mixed
Content-Transfer-Encodinghow made 7-bit safe7bit, quoted-printable, base64
Content-Dispositioninline or attachmentattachment; filename="phewa.jpg"
Content-ID, Content-Descriptiona label; a descriptionan image inside an HTML mail
  • Base64: 3 bytes (24 bits) at a time, four 6-bit groups, each one of 64 characters: A to Z (0 to 25), a to z (26 to 51), 0 to 9 (52 to 61), + (62), / (63); = pads the end; lines every 76 characters; size grows by a third (a 3 MB photo travels as about 4 MB).
  • Example "Ram": 52 61 6D = 01010010 01100001 01101101, regrouped 010100 100110 000101 101101 = 20, 38, 5, 45 = UmFt.
  • Example JPEG: every JPEG starts FF D8 FF = 11111111 11011000 11111111 = 63, 61, 35, 63 = /9j/.
  • Quoted-printable: for mostly ASCII text; other bytes become = and two hex digits: Nepali न (UTF-8 E0 A4 A8) is =E0=A4=A8. A Nepali subject नमस्ते becomes the encoded word =?UTF-8?B?4KSo4KSu4KS44KWN4KSk4KWH?=.

Figure: base64 of FF D8 FF: 24 bits, four 6-bit groups, values 63, 61, 35, 63, characters /9j/, the alphabet and the MIME headers.

From: Sita <sita@example[.]com>
To: Ram <ram@example[.]org>
Subject: Photo from Phewa Lake
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="XyZ42"

--XyZ42
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 7bit

Here is the photo from the boat.
--XyZ42
Content-Type: image/jpeg; name="phewa.jpg"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="phewa.jpg"

/9j/4AAQSkZJRgAB ... (about 4 MB of base64 text) ...
--XyZ42--
  • The book's table slips: POP3's one folder is the INBOX (the book prints "index folder"); "IMAP storage limited to 2 GB" is a provider's quota, not an IMAP limit.

Memory example: the postal service: UA the letter writer, her mail server the local post office, SMTP the van between post offices (delivers, never collects), the mailbox a PO box; POP3 empties the PO box and takes everything home, IMAP reads at the counter with letters kept in labelled folders.

DNS: the Internet's distributed directory of names

TOP 11/27 Open the full card

DNS (Domain Name System, RFC 1034 and 1035): a distributed, hierarchical database of names and the application layer protocol to query it; maps host names such as www.ioe.edu.np to IP addresses (and back); mostly UDP port 53.

Why it is used:

  • Names for people, numbers for machines: people remember youtube.com; routers forward on 32-bit or 128-bit addresses.
  • Freedom to move: a site changes server and address; only the record changes.
  • One name, many servers: load spreading; a CDN gives each user its nearest copy.
  • More than addresses: MX (mail server), CNAME (alias), PTR (name of an address).
  • Distributed: before DNS (designed 1983) every host copied one HOSTS.TXT from the SRI Network Information Center; one table would be a single point of failure, a traffic jam, impossible to keep current; DNS splits it among countless servers, each run by the owner of its part.

Memory example: the phone's contact list: dial "Aama", not her number; a new SIM changes only the entry.

  • Name space: an inverted tree; each node a label of up to 63 characters; the root's label empty. A domain name is the labels read upward, joined by dots: www.youtube.com., the final dot the root. With the dot: FQDN (fully qualified); without (www inside a campus): PQDN, completed by the resolver. A full name is at most 255 bytes.
  • Root: one, unnamed; 13 root server identities a.root-servers.net to m.root-servers.net, run by 12 organizations, copied worldwide by anycast.
  • TLDs: generic (com, org, net, edu, gov, info, newer ones), country codes (np, in, uk, jp), arpa for reverse lookups. Verisign runs com and net; np is run by Mercantile Communications.
  • Below: com.np, edu.np, gov.np, org.np under np; ioe.edu.np, pcampus.edu.np under edu.np; owners create names below their own.

Figure: the name space tree: root; com, org, net, edu, np; youtube and example under com, wikipedia under org, mit under edu, edu and gov under np; www under youtube; ioe and pcampus under edu.np; the path www.youtube.com highlighted; zones youtube.com and ioe.edu.np outlined.

Name serverWhat it holds or doesExample
Rootservers of every TLD; answers with referralsa to m.root-servers.net
TLDauthoritative servers of every domain under its TLDa.gtld-servers.net for com
Authoritativea zone's records from its zone file; primary plus secondaries by zone transferns1.google.com for youtube.com
Local (resolver)outside the tree; the server a host asks (set by DHCP); resolves for hosts, cachesISP resolver (NTC, WorldLink), public 8.8.8.8 or 1.1.1.1
  • Caching: every answer has a TTL in seconds; the resolver keeps it that long; after the first hostel student looks up youtube.com, the next hundred are answered from the ISP's resolver; TLD server addresses are cached too, so the root is rarely asked; failed lookups are cached too (negative caching).
  • Recursive query: the server asked must return the answer or an error, asking other servers itself.
  • Iterative query: the server asked replies at once: the answer, or a referral (servers closer to the answer); the asker continues. The RD (recursion desired) flag states the wish.

Figure: iterative resolution of www.youtube.com in eight numbered steps among host, local server, root, .com TLD and authoritative server.

Iterative lookup of www.youtube.com:

  1. Host to local server: query for www.youtube.com, type A, RD set, to the ISP's resolver (nothing cached).
  2. Local server to root.
  3. Root's referral: NS records of com (a.gtld-servers.net and siblings) in the authority section, their addresses (glue) in the additional section.
  4. Local server to a com server.
  5. TLD's referral: ns1.google.com and siblings, with addresses.
  6. Local server to ns1.google.com.
  7. Answer: the A record, AA set (a CNAME is looked up again the same way).
  8. Back to the host: every record cached for its TTL; the address returned; the browser connects.

The host sent one query; the local server three.

Figure: recursive resolution of www.youtube.com: host to local, local to root, root to TLD, TLD to authoritative, and the answer back along the chain in steps 5 to 8.

  • Fully recursive: root asks TLD, TLD asks authoritative, answer climbs back; loads servers up the tree, which would hold state for millions of queries; root and TLD servers refuse (RA clear). In practice: host to local server recursive, local server's queries iterative.
PointRecursiveIterative
Who worksthe server askedthe asker
Replyanswer or erroranswer or referral
Loadheavy: waits, keeps statelight: answers at once
Messages for askerone query, one replyone per server visited
Cachingthe server cachesthe asker caches the chain
FlagsRD set, RA setRD clear, or no recursion offered
Typical usehost to local serverlocal to root, TLD, authoritative
  • Inverse query (older texts): the name for an address; now an ordinary PTR query: 192.0.2.80 becomes 80.2.0.192.in-addr.arpa (bytes reversed); the inverse opcode is obsolete.
  • Resource record fields: NAME (owner), TYPE, CLASS (IN), TTL (seconds cacheable), data (RDATA; RDLENGTH on the wire).
TypeCodeDataExample (zone example.com)
A1IPv4 addresswww A 192.0.2.80
AAAA28IPv6 addresswww AAAA 2001:db8::80
CNAME5canonical name of an aliasftp CNAME www.example.com.
MX15mail server, preference (lower first)example.com. MX 10 mail.example.com.
NS2authoritative name serverexample.com. NS ns1.example.com.
PTR12name for an address80.2.0.192.in-addr.arpa. PTR www.example.com.
SOA6primary server, admin mailbox, serial, timersone per zone
TXT16free text: SPF, DKIM, ownership proofsexample.com. TXT "v=spf1 mx -all"
$TTL 3600
example.com.   IN SOA   ns1.example.com. admin.example.com. (
                        2026100401 ; serial: raised on every change
                        7200       ; refresh: secondaries check every 2 hours
                        900        ; retry
                        1209600    ; expire: 14 days
                        300 )      ; TTL for "no such name" answers
example.com.   IN NS    ns1.example.com.
example.com.   IN NS    ns2.example.com.
example.com.   IN MX 10 mail.example.com.
ns1            IN A     192.0.2.53
www            IN A     192.0.2.80
www            IN AAAA  2001:db8::80
mail           IN A     192.0.2.25
ftp            IN CNAME www.example.com.
example.com.   IN TXT   "v=spf1 mx -all"
  • Delegation: a zone is the part of the tree one set of authoritative servers answers for; a parent delegates a subtree by NS records for the child in its own zone, plus glue A records when the child's servers are named inside the child; then the child's owner changes names without asking. Root delegates np; np delegates edu.np; edu.np delegates ioe.edu.np to IOE's name servers. A referral is the parent reading out its delegation. Glue example: pcampus.edu.np is served by dns1.pcampus.edu.np and dns2.pcampus.edu.np, inside the child, so the edu.np zone also holds their addresses.
; inside the com zone, run by Verisign
youtube.com.       NS  ns1.google.com.    ; delegation to Google's servers
example.com.       NS  ns1.example.com.   ; delegation
ns1.example.com.   A   192.0.2.53         ; glue: the server sits inside the child
  • Message: one format for query and response: a 12-byte header (identification copied by the reply; flags QR, Opcode, AA, TC, RD, RA, Z, RCODE with 0 no error and 3 no such name; QDCOUNT, ANCOUNT, NSCOUNT, ARCOUNT), then question (name, type, class), answer (records), authority (NS records, referrals), additional (extras such as glue).

Figure: the DNS header 16 bits wide (ID; QR, Opcode, AA, TC, RD, RA, Z, RCODE; four counts), the four sections, and a resource record's fields (NAME, TYPE 16, CLASS 16, TTL 32, RDLENGTH 16, RDATA).

Example: query ID 0x1A2B (6699), QR 0, Opcode 0, RD 1, QDCOUNT 1; question www.example.com A IN; name on the wire 3 www 7 example 3 com 0, 17 bytes; 12 + 17 + 4 = 33 bytes in one UDP datagram to port 53. Response: same ID, QR 1, RD 1, RA 1, AA 0 from a cache, RCODE 0, ANCOUNT 1; answer www.example.com 3600 IN A 192.0.2.80, its name a 2-byte pointer to the question (compression); 33 + 16 = 49 bytes.

dig www.example.com A
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 6699
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0
;; QUESTION SECTION:
;www.example.com.            IN   A
;; ANSWER SECTION:
www.example.com.     3600    IN   A    192.0.2.80
  • UDP and TCP: one datagram each way, no handshake, lost queries simply repeated; TCP 53 for zone transfers and replies over the UDP limit (512 bytes originally, raised by EDNS): the server sets TC, the resolver retries over TCP.
  • The book's four components: name space, name servers, resolvers, cache. Forged replies can poison a cache; DNSSEC signs records.
  • The book's slips: "it is easier to remember an IP address" (names are easier); Network Solutions managing the root and com (1990s); today IANA (ICANN) manages the root zone and Verisign, which bought Network Solutions, runs com.

DHCP: how a host gets its address, and how the lease is renewed

PIN 1/27 Open the full card

DHCP (Dynamic Host Configuration Protocol, RFC 2131): client-server over UDP (server 67, client 68); leases a host an IP address for a limited time, with subnet mask, default gateway and DNS servers; no manual configuration.

  • Why: devices work at once on a new network; a limited pool is shared (addresses return when leases end); settings changed in one place; no duplicate addresses. Reserved (fixed) addresses by MAC for printers and servers. Grew out of BOOTP, keeps its message format.

DORA:

  1. DHCPDISCOVER: broadcast from 0.0.0.0:68 to 255.255.255.255:67.
  2. DHCPOFFER: each server offers an address (192.168.1.23), mask, gateway, DNS, lease time.
  3. DHCPREQUEST: broadcast, naming the chosen server; others withdraw their offers.
  4. DHCPACK: the lease starts; the client checks the address with ARP (DHCPDECLINE if in use).

Figure: DORA between a laptop with no address and the DHCP server at 192.168.1.1, with the addresses and ports of each message.

  • Other messages: DHCPNAK (refuse), DHCPRELEASE (give back), DHCPDECLINE (in use), DHCPINFORM (fixed address, other settings only).
T1=0.5×lease,T2=0.875×lease
  1. Bound (0 to T1): use the address.
  2. Renewing (from T1): unicast DHCPREQUEST to the granting server; DHCPACK renews (fresh full lease) and restarts the timers; DHCPNAK: stop, DISCOVER again; no reply: keep asking.
  3. Rebinding (from T2): broadcast DHCPREQUEST to any server; any ACK renews.
  4. Expiry: no ACK by the end: stop using the address at once; INIT, then DISCOVER.

Figure: the 24-hour lease on a time line: bound to 12 h, renewing to 21 h, rebinding to 24 h, an arrow back to the start for an ACK, and the action at T1, T2 and expiry.

Example: a phone joins hostel Wi-Fi at 07:00 with a 24-hour lease; T1 = 12 h, renewal at 19:00 (normally answered, held until 19:00 next day); if the router is down, T2 = 21 h, broadcast at 04:00; no answer by 07:00 next day: drop the address, DORA again. An 8-day lease gives T1 = 4 days, T2 = 7 days.

  • Client states: INIT, SELECTING, REQUESTING, BOUND, RENEWING, REBINDING.
  • Relay agent: broadcasts stop at routers; a relay on each router interface (Cisco ip helper-address) forwards by unicast to the server and writes its address in the gateway field, so the server picks the right subnet's pool.

Memory example: a library book: borrowing is DORA; renew at the same desk halfway (T1); any desk near the due date (T2); return on the due date.

Peer-to-peer applications: BitTorrent and distributed hash tables

Open the full card

P2P application: end hosts (peers) talk directly, each both client and server, with little or no always-on server.

  • Central index: one server knows who has what; files peer to peer (Napster, 1999); single point of failure.
  • Query flooding: searches passed neighbour to neighbour (Gnutella); floods the network.
  • Super peers: well-connected peers index their neighbours (KaZaA).
  • Structured DHT: each key has one home, found in a few hops (Chord, Kademlia).
  • Scaling: each peer that receives a part also uploads it; newcomers add capacity.
Dcs≥max(NFus,Fdmin),Dp2p≥max(Fus,Fdmin,NFus+∑ui)

Example: F = 800 Mbit (100 MB), N = 100, server upload 100 Mbit/s, peers upload 10 and download 50 Mbit/s: client-server max(800 s, 16 s) = 800 s; P2P max(8 s, 16 s, 80,000 / 1,100 = 72.7 s) = about 73 s, eleven times faster.

  • BitTorrent (Bram Cohen, 2001): .torrent file or magnet link (name, piece size, a hash per piece, tracker address); tracker lists the swarm; seeders (whole file) and leechers (downloading, uploading what they have); equal pieces, rarest first; each piece checked against its hash; tit for tat: upload to the 4 fastest uploaders, re-chosen every 10 s, plus one optimistic unchoke every 30 s.
  • DHT: peers and keys share an ID space (for example 160 bits); a key is stored at the closest peer ID; each lookup hop halves the distance: about log2 N hops (about 20 for a million peers). BitTorrent's trackerless mode: Kademlia, key = info-hash, value = peer list.
  • Good and bad: no single point of failure, grows with users; heavy upload use, NAT trouble, hard to control, piracy, malware risk. Others: early Skype, Bitcoin, WebRTC calls.

Memory example: classmates sharing notes the night before an exam: each copies one chapter and swaps instead of queueing at the one photocopy shop.

Socket programming: the calls, and a TCP server and client

HOT 5/27 Open the full card

Socket programming: writing network applications against the socket API, the interface between an application process and the transport layer; a socket is an endpoint named by an IP address and a port; programs create, connect, read, write and close sockets with system calls.

  • Berkeley (BSD) sockets: 4.2BSD Unix, 1983; copied by Linux, Windows (Winsock), Java, Python; a connection treated like a file.
TypeTransportGivesUsed by
Stream (SOCK_STREAM)TCPreliable ordered byte streamHTTP, FTP, SSH, SMTP
Datagram (SOCK_DGRAM)UDPseparate messages, no connectionDNS, DHCP, TFTP, SNMP
Raw (SOCK_RAW)IP itselfIP and ICMP packets, admin rightsping, traceroute
CallWhoDoes
socket()bothcreate an endpoint (family, type); returns a descriptor
bind()serverattach a local IP address and port
listen()servermake the socket passive, with a queue length
accept()serverblock until a client connects; return a new socket
connect()clientconnect to the server; TCP three-way handshake
send(), recv()bothwrite, read (sendto(), recvfrom() for UDP)
close()bothrelease; TCP sends FIN
  • Order: server socket, bind, listen, accept (blocks); client socket, connect (no bind: a temporary port); accept returns when the handshake completes; data; close.

Figure: the server's calls and the client's calls in two columns, with the handshake between connect and accept, request and reply data, and FIN at close.

/* server.c: a TCP server on port 5000 (BSD sockets, Linux) */
#include <stdio.h>
#include <string.h>
#include <unistd.h>
#include <sys/socket.h>
#include <arpa/inet.h>

int main(void) {
    int lfd = socket(AF_INET, SOCK_STREAM, 0);       /* 1. a TCP socket          */
    struct sockaddr_in me;
    memset(&me, 0, sizeof me);
    me.sin_family = AF_INET;
    me.sin_port = htons(5000);                       /* port, network byte order */
    me.sin_addr.s_addr = htonl(INADDR_ANY);          /* every local address      */
    bind(lfd, (struct sockaddr *)&me, sizeof me);    /* 2. name it: IP + port    */
    listen(lfd, 5);                                  /* 3. passive, queue of 5   */
    for (;;) {
        int cfd = accept(lfd, NULL, NULL);           /* 4. wait for a client     */
        char buf[100];
        int n = recv(cfd, buf, sizeof buf - 1, 0);   /* 5. read its request      */
        if (n > 0) {
            buf[n] = '\0';
            printf("client says: %s\n", buf);
            send(cfd, "Namaste from server\n", 20, 0);   /* 6. reply             */
        }
        close(cfd);                                  /* 7. end this client only  */
    }
}
/* client.c: talks to the server above */
#include <stdio.h>
#include <string.h>
#include <unistd.h>
#include <sys/socket.h>
#include <arpa/inet.h>

int main(void) {
    int fd = socket(AF_INET, SOCK_STREAM, 0);              /* 1. a TCP socket    */
    struct sockaddr_in srv;
    memset(&srv, 0, sizeof srv);
    srv.sin_family = AF_INET;
    srv.sin_port = htons(5000);                            /* the server's port  */
    inet_pton(AF_INET, "192.168.1.10", &srv.sin_addr);     /* the server's IP    */
    if (connect(fd, (struct sockaddr *)&srv, sizeof srv) < 0) {  /* 2. handshake */
        perror("connect");               /* no server listening: refused         */
        return 1;
    }
    send(fd, "Hello", 5, 0);                               /* 3. the request     */
    char buf[100];
    int n = recv(fd, buf, sizeof buf - 1, 0);              /* 4. the reply       */
    if (n > 0) { buf[n] = '\0'; printf("%s", buf); }
    close(fd);                                             /* 5. FIN             */
    return 0;
}
  • Reading it: htons, htonl give network byte order (big-endian); INADDR_ANY accepts on every interface; the listening socket lfd never carries data, each client gets cfd; real code checks every return value; busy servers use fork or threads per client. Compile gcc server.c -o server, run the server, then the client in a second terminal.
  • Server first: connect() sends a SYN; with no listening socket, the server's TCP answers RST and connect fails, "connection refused" (ECONNREFUSED).
  • UDP: no listen, accept or connect; the server binds and loops on recvfrom() (which gives the sender's address) and replies with sendto().
  • The book's slips: a datagram socket sends "with having logical connection" (it means without: UDP is connectionless); SOCK-RAW for SOCK_RAW.
  • Other languages: Java new ServerSocket(5000) (socket, bind, listen), accept() returns a Socket, client new Socket("192.168.1.10", 5000) (the book's version); Python keeps the C names.

Memory example: a hostel landline: bind is getting a number, listen switching the ringer on, accept picking up, connect a friend dialling; a number not yet connected gives "does not exist", connection refused.

Proxy servers and web caching

PIN 3/27 Open the full card

Proxy server: an intermediary that receives clients' requests and makes them to the destination on their behalf. A caching proxy (web cache) keeps copies of recently fetched objects and answers repeat requests from them.

  1. Every request to the proxy: browsers configured, or traffic redirected (transparent proxy).
  2. Cache check for the URL.
  3. Fresh hit: copy returned from the LAN (within Cache-Control: max-age or Expires).
  4. Possibly stale hit: conditional GET with If-Modified-Since; 304 Not Modified (no body, copy served) or 200 OK with the new version.
  5. Miss: the proxy fetches from the origin, stores a copy, forwards it.

Figure: a campus LAN with two clients and the proxy; client A's request is a hit (steps 1, 2); client B's a miss (steps 1, 3, 4, 5) across the access link to the origin server.

  • Uses: faster pages (LAN hits); less access-link traffic (the slow, paid part); less origin load; filtering and access control (sites, hours); logging and monitoring; privacy (origin sees the proxy's address) and security (malware scanning, single exit, an application gateway); sharing one connection.
Tavg=h×Thit+(1−h)×Tmiss

Example: h = 0.4, hit 10 ms, miss 2 s: 0.4 x 0.01 + 0.6 x 2 = 1.204 s against 2 s; the access link carries only 60 percent of requests.

KindWhere, for whomExample
Forwardnear clients, for themcampus or office proxy (Squid)
Reversein front of web servers: caching, load balancing, TLSNginx, a CDN
Transparentintercepts with no browser setting; passes client IP; says it is a proxyISP or school interception cache
Anonymoushides client IP; says it is a proxyprivacy proxy
Distortingfalse client IP; says it is a proxyprivacy proxy
High anonymityhides IP; does not say it is a proxy"elite" proxy
  • CDN: caching at world scale, reverse-proxy caches near users.

Memory example: the hostel copy of a popular book: the first student waits while it is fetched (miss), the next forty borrow it at once (hits), the warden checks weekly for a new edition (conditional GET).

Web, mail and DNS server optimization

Open the full card

Server optimization: tuning a server's hardware, software and placement to answer more clients, faster, without interruption: caching, load balancing, replication, efficient protocols, reliable storage.

ServerBottleneckOptimization
Webmany connections, disk reads, database-built pagescaching in memory, reverse proxy, CDN; gzip, Brotli; persistent connections, HTTP/2; event-driven server (Nginx) for static files; load balancer over a farm; cached database results; expiry headers
Mailqueues, spam volume, storagetwo or more MX records with preferences (backup); edge spam filtering (blocklists, SPF, DKIM, DMARC); submission 587 apart from relay 25; tuned queue and retry times; mailboxes on RAID; quotas; IMAP search indexes
DNSquery volume, delay, attackscaching with sensible TTLs; at least two authoritative servers on different networks (zone transfer); anycast; separate authoritative and recursive servers; rate limits against amplification; resolvers near users
  • Shared: RAID, enough memory, SSDs, redundant power (UPS and generator, needed through Nepal's load-shedding years), two network links, monitoring (SNMP, MRTG, PRTG).
  • Measures: throughput (requests per second), response time, availability: 99.9 percent allows 8.76 hours down a year, 99.99 percent 52.6 minutes.

Memory example: a results website on result day: cached page, several servers behind a load balancer, two DNS servers, mirrored disks.

RAID 0, RAID 1 and RAID 5: why servers need them

PIN 1/27 Open the full card

RAID (Redundant Array of Independent, originally Inexpensive, Disks; Patterson, Gibson and Katz, 1988): several physical disks as one logical volume for speed (striping), protection against disk failure (mirroring, parity), or both.

  • Availability: shared servers (web, mail, DNS, file, database); a dead disk would stop the service and lose data; RAID 1 or 5 keeps running while the disk is hot-swapped and rebuilt.
  • Performance: striping spreads I/O over disks in parallel.
  • Capacity: one large volume.
  • Not a backup: deletion, viruses and ransomware hit every disk.

Figure: RAID 0 (A1, A3, A5, A7 on disk 1; A2, A4, A6, A8 on disk 2), RAID 1 (A1 to A4 on both disks), RAID 5 over three disks (A1, A2, Ap; B1, Bp, B2; Cp, C1, C2; D1, D2, Dp) with capacity, speed and fault tolerance for each.

  • RAID 0, striping: blocks round-robin over n disks; all capacity; up to n times faster; no redundancy: one failure destroys the volume (less reliable than one disk); scratch space, easily recreated data; at least 2 disks.
  • RAID 1, mirroring: every block on two disks; one disk's capacity; reads from either (faster); writes at one disk's speed; survives either disk failing; rebuild is a copy; OS disks, small critical servers (DNS, mail); at least 2 disks.
  • RAID 5, distributed parity: data and parity striped over n disks (at least 3), the parity block rotating; parity = XOR of the stripe's data; capacity n minus 1 disks; fast reads; small writes read old data and parity and write both (four operations, the write penalty); survives any one disk; a second failure during a long rebuild loses everything (RAID 6 keeps two parities); file and web servers that mostly read.

Example: D1 = 1011, D2 = 0110, D3 = 1100; P = D1 XOR D2 XOR D3 = 0001; disk 2 fails; D1 XOR D3 XOR P = 0110 = D2.

PointRAID 0RAID 1RAID 5
Techniquestripingmirroringstriping, distributed parity
Minimum disks223
Usable capacityn x SS(n minus 1) x S
Example2 x 2 TB: 4 TB2 x 2 TB: 2 TB4 x 2 TB: 6 TB
Disks that may failnoneone of the pairany one
Read speedfastestfastfast
Write speedfastestone disk'sslower (parity)
Best fortemporary datasystem disks, small serversfile, web servers
  • Also: RAID 10 (stripe of mirrors, half capacity); hardware controller or software RAID; a hot spare starts the rebuild at once.

Memory example: friends and the semester's notes: RAID 0 two split the chapters (fast, but one lost notebook loses half); RAID 1 each writes everything; RAID 5 three split them and keep a check sheet that rebuilds any one lost notebook.

SNMP: managing network devices

Open the full card

SNMP (Simple Network Management Protocol): an application layer protocol over UDP by which a manager reads and changes variables held by agents on routers, switches, servers and printers, and agents report events unasked.

  • Manager (network management station): polls, stores, graphs, alerts (MRTG, PRTG, Zabbix).
  • Agent: a process on each managed device.
  • MIB (Management Information Base): the objects an agent exposes, as a tree; MIB-II (RFC 1213) the standard set.
  • SMI (Structure of Management Information): naming rules, data types (integer, counter, gauge, string), encoding.
  • OID: an object's address in the tree: 1.3.6.1.2.1.1.3.0 sysUpTime; 1.3.6.1.2.1.2.2.1.10 ifInOctets (bytes received on an interface).

Figure: the manager sends GetRequest, GetNextRequest or SetRequest to the agent's UDP port 161, the agent answers with a Response, and sends Traps to the manager's port 162; the agent holds the MIB.

MessageDirectionDoes
GetRequestmanager to agent (UDP 161)read variables
GetNextRequestmanager to agentread the next variable: walk a table
GetBulkRequest (v2)manager to agentread a large block
SetRequestmanager to agentchange a variable
Responseagent to managervalues or an error
Trapagent to manager (UDP 162)unasked event report
InformRequest (v2)agent to manageracknowledged trap
  • Versions: SNMPv1 (RFC 1157, 1990) and v2c: community string in plain text (default read-only "public", a risk); SNMPv3 (RFC 3411 to 3418): authentication and encryption.

Example: ifInOctets read 300 s apart: 1,200,000,000 then 1,575,000,000 bytes; (375,000,000 x 8) / 300 = 10,000,000 bit/s = 10 Mbit/s, which MRTG does every five minutes.

Memory example: a hostel warden (manager) reads each room's meter on a five-minute round (Get), switches a room off from the office (Set), and a room with a short circuit calls him at once (trap).

Traffic graphers: MRTG and PRTG

Open the full card

Traffic grapher: a monitoring tool that polls devices at regular intervals, mostly over SNMP, stores the counters and draws graphs of link load and device health over time.

  • MRTG (Multi Router Traffic Grapher): free, open source, Tobias Oetiker, 1995, Perl with a C helper; every 5 minutes by default reads ifInOctets and ifOutOctets, computes rates from the difference, redraws four graphs on a web page: daily (5-minute averages), weekly (30-minute), monthly (2-hour), yearly (1-day). Succeeded by RRDtool (same author) and tools on it such as Cacti.
  • PRTG Network Monitor (Paessler Router Traffic Grapher): Paessler (Germany), commercial, Windows, free up to 100 sensors; auto-discovery; sensors (ping, SNMP traffic, CPU, disk, HTTP response, NetFlow, sniffed packets); history, dashboards, maps, email or SMS alerts.
PointMRTGPRTG
Licencefree, open sourcecommercial (free to 100 sensors)
PlatformUnix, Windows; text configurationWindows server, web interface
DataSNMP counters, mainly trafficSNMP, ping, NetFlow, sniffing, WMI
OutputPNG graphs on HTML pagesdashboards, maps, reports, alerts
Best forper-link traffic historywhole-network monitoring with alarms
  • Questions answered: how full a link is and when, rising errors and discards, overloaded devices, when to upgrade. Throughput and delay themselves are chapter 2's.

Memory example: an electricity meter with a chart; suppose a hostel's 100 Mbit/s link peaks near 90 Mbit/s from 8 to 11 pm and idles at 4 am: full only in the streaming hours.

Wireshark and Packet Tracer: real packets, simulated networks

Open the full card

Wireshark: a free, open-source packet analyser that captures frames on a real interface and decodes every layer. Packet Tracer: Cisco's network simulator: virtual routers, switches and PCs built, configured and watched packet by packet, no hardware.

  • Wireshark history: Ethereal by Gerald Combs, 1998; renamed 2006; captures through libpcap (Npcap on Windows), usually in promiscuous mode.
  • Panes: packet list, packet details (layer tree: Ethernet, IP, TCP, HTTP), packet bytes (hex).
  • Capture filters (BPF): port 53, host 192.168.1.10. Display filters: dns, http.request, ip.addr == 192.168.1.10, tcp.port == 80, tcp.flags.syn == 1.
  • Tools: Follow TCP Stream; Statistics (conversations, protocol shares, graphs); TShark command line.
  • What it shows students: the three-way handshake, DNS query and reply with the same ID, DHCP's DORA, an FTP password in plain text, HTTP readable against HTTPS as TLS records. Capture only with permission.
  • Packet Tracer: free with a Cisco Networking Academy account; devices dragged, cabled, configured with real IOS commands; servers run DHCP, DNS, HTTP, FTP, TFTP, email; realtime mode, and simulation mode (time stops, packets as envelopes, each opened layer by layer).
  • The book says Wireshark uses GTK+; it moved to Qt in 2015 and dropped the GTK version in 2019.
PointWiresharkPacket Tracer
Works onreal traffic, a real interfacea simulated network
Purposetroubleshooting, security analysis, learning protocolsdesigning, configuring, learning networks
Showsevery field of every captured packetpackets moving through devices
Made byopen-source community (free)Cisco (free with Networking Academy)
Limitonly traffic reaching the interfacea subset of device features

Memory example: Packet Tracer is the flight simulator, Wireshark the black box of a real flight; build DHCP and DNS in Packet Tracer and watch DORA, then capture dhcp or dns with Wireshark on a real laptop.

Chapter 7: Introduction to IPv6 4490 words

Why IPv6: the problems of IPv4 and what IPv6 fixes

TOP 13/27 Open the full card

IPv6 (Internet Protocol version 6): the network layer protocol designed by the IETF to replace IPv4. Same job (connectionless, best-effort datagram delivery across many networks), but 128-bit addresses, a simpler fixed 40-byte header, options moved into extension headers, and built-in autoconfiguration, multicast and IPsec support (RFC 8200). TCP, UDP and applications run over it unchanged.

  • IPng: in the early 1990s the IETF saw 32-bit addresses would run out and began "IP next generation".
  • Standards: RFC 1883 (1995), RFC 2460 (1998), full Internet Standard RFC 8200 (2017).
  • Why "6": version 5 had gone to the experimental Internet Stream Protocol (ST).

IPv4 (RFC 791, 1981) was designed for a research network; it now carries billions of devices.

IPv4 problemWhat goes wrongWhat IPv6 does
Address exhaustion232 = 4,294,967,296 addresses, fewer after private, multicast and reserved blocks; classful waste. IANA's last free blocks 3 February 2011; APNIC (serves Nepal) last block 15 April 2011128 bits: 2128≈3.4×1038; one /64 holds 264≈1.8×1019, 232 times the whole IPv4 Internet
NAT everywhereoutside hosts cannot reach inside ones; peer-to-peer, VoIP, games, IPsec struggle; carrier-grade NAT puts many customers behind one addressa global address per device; end-to-end restored; a firewall, not NAT, filters
Slow, complex header20 to 60 bytes, options, checksum recomputed per hop, router fragmentationfixed 40 bytes, no checksum, no router fragmentation, extension headers
Routing table growthclassful history, scattered allocations aggregate poorlyhierarchical allocation: registry, ISP, site /48, subnet /64
No IP-layer securityIPsec added later as an optionAH and ESP as extension headers
Weak real-time supportTOS used inconsistently; no flow markingtraffic class plus a 20-bit flow label
Configurationmanual or DHCPSLAAC (plug and play, easy renumbering); DHCPv6 optional
BroadcastARP and others interrupt every hostno broadcast: scoped multicast, anycast
MobilityMobile IPv4 triangle routing via home agentMobile IPv6 (RFC 6275) routes straight to the moving host

Advantages of IPv6 over IPv4 (the book's first seven):

  1. Larger address space: 2128 addresses.
  2. Better header format: fixed 40 bytes, options separated, no checksum, faster processing.
  3. Possibility of extension: new features as new extension headers or options.
  4. Smaller routing tables: hierarchical prefixes instead of classes.
  5. Security: authentication (AH) and encryption (ESP) at the IP layer.
  6. Resource allocation: traffic class and flow label for real-time audio and video.
  7. Multicast with scopes; anycast reaches the nearest server.
  8. Autoconfiguration (SLAAC).
  9. End-to-end connectivity: no NAT; suits peer-to-peer, VoIP, IoT.
  10. Mobility and jumbograms: Mobile IPv6; payloads over 64 KiB with the jumbo payload option.

Factors behind its development and adoption: growth of the Internet (pools forecast to empty in the early 1990s, emptied from 2011); new devices (smartphones, always-on broadband, IoT; developing countries coming online); the cost of NAT; real-time multimedia; security; simpler routing and configuration; deployment pushes: World IPv6 Day (8 June 2011) and World IPv6 Launch (6 June 2012), and IPv6-only mobile networks.

Memory example: IPv4 is a hostel with about four billion rooms for eight billion people; NAT puts a whole floor behind one room number; IPv6 gives every device its own number, and one floor of the new hostel has more rooms than the whole old building.

IPsec caveat: the book calls IPsec built in. RFC 4294 (2006) made IPsec support mandatory for IPv6 nodes; RFC 6434 (2011) relaxed it to "should"; IPsec also runs over IPv4.

The IPv6 datagram: a fixed 40-byte header, compared with IPv4

HOT 6/27 Open the full card

IPv6 datagram: a fixed 40-byte base header followed by the payload: zero or more extension headers, then upper-layer data (TCP segment, UDP datagram or ICMPv6 message); payload length allows up to 65,535 bytes after the base header.

Figure: the 40-byte base header as a 32-bit-wide grid, with the whole packet (base header, extension headers, upper-layer data) under it

FieldBitsWhat it does
Version46 (0110); same position as IPv4's
Traffic class86-bit DSCP plus 2 ECN bits; the job of IPv4's TOS
Flow label20set by the source to identify one flow so routers treat its packets alike without reading the transport header; 0 when unused (RFC 6437)
Payload length16bytes after the base header, extension headers included, up to 65,535; base header never counted
Next header8extension header (0, 43, 44, 50, 51, 60) or upper layer (6 TCP, 17 UDP, 58 ICMPv6); same numbers as IPv4's protocol field
Hop limit8minus 1 per router; at 0 dropped, ICMPv6 Time Exceeded sent; IPv4's TTL renamed
Source address128sender
Destination address128receiver, or next node when a routing header is present
4+8+20+16+8+8+128+128=320 bits=40 bytes

Memory example: a courier slip with fixed printed boxes; the office in Butwal (a router) reads only the "to" box and stamps the hop counter; extra sheets behind the slip are extension headers, read by the receiver, except one marked for every office (hop-by-hop).

Against the IPv4 header

Six IPv4 fields gone, four renamed, three kept, one added.

Figure: the IPv4 and IPv6 headers side by side at the same scale, every field coloured kept, renamed, removed or added

IPv4 field (bits)In IPv6Why
Version (4)kept, value 6tells the versions apart
IHL (4)removedheader always 40 bytes
Type of service (8)renamed traffic classsame DSCP and ECN bits
Total length (16)renamed payload lengthcounts only what follows the header
Identification (16), flags (3), fragment offset (13)removed, into the fragment extension headeronly the source fragments
Time to live (8)renamed hop limitit always counted hops
Protocol (8)renamed next headermay point to an extension header
Header checksum (16)removedEthernet CRC and transport checksums catch errors; no recomputation per hop
Source, destination (32 each)kept, 128 bits eachlarger space
Options and padding (up to 320)removedextension headers
noneadded: flow label (20)flow identification

The UDP checksum, optional over IPv4, is mandatory over IPv6 (RFC 8200); TCP, UDP and ICMPv6 checksums cover a pseudo-header with both 128-bit addresses.

PointIPv4IPv6
Address32 bits, dotted decimal, 192.168.1.20128 bits, hex with colons, 2001:db8:acad:1::20
Header20 to 60 bytes, 12 fields and options40 bytes, 8 fields
Checksumyesnone
Fragmentationsender and routerssender only; routers send Packet Too Big
Smallest link MTU68 bytes (hosts accept 576)1,280 bytes
Optionsin the headerextension headers
Configurationmanual or DHCPSLAAC, DHCPv6, manual
Deliveryunicast, multicast, broadcastunicast, multicast, anycast, no broadcast
Neighbour's MACARP, broadcastneighbour discovery (ICMPv6), multicast
SecurityIPsec optional, laterAH, ESP extension headers
QoSTOStraffic class, flow label
NATcommonnot needed
DNS recordAAAAA
Loopback127.0.0.1::1
Routing and header manipulation
At each routerIPv4IPv6
Find the fieldsread IHL firstfixed offsets
Checksumverify, recompute after TTL changenone
LifetimeTTL minus 1hop limit minus 1, the only change
Optionsexamine, often in slow softwareskip extension headers except hop-by-hop
Too bigfragment unless DFdrop, ICMPv6 Packet Too Big; source resends smaller
Address rewritingNAT rewrites addresses, ports, checksumsnone
Flow recognitionports, deep in the packetflow label
Lookuplongest prefix match, 32 bitslongest prefix match, 128 bits
Routing protocolsRIP, OSPFv2, BGPRIPng, OSPFv3, MP-BGP, IS-IS

Critical points: 128-bit lookups need more TCAM per route; dual-stack routers keep two tables and two protocol sets; extension headers (hop-by-hop above all) leave the fast path and are often dropped (RFC 7872); filtering ICMPv6 breaks path MTU discovery; tables stay small only if providers announce whole blocks.

Worked example: a 1,500-byte packet meets a 1,280-byte MTU link. IPv4 router: read IHL 5 (20 bytes), check checksum, TTL 64 to 63, recompute checksum, split the 1,480 data bytes into fragments of 1,276 and 244 bytes, each with its own header and checksum. IPv6 router: hop limit 64 to 63, too big, drop, return Packet Too Big (MTU 1,280); the PC sends later packets at most 1,280 bytes (TCP uses smaller segments).

Book slip: the book gives the flow label 24 bits (first row would be 36 bits); it is 20 bits (RFC 2460, RFC 8200); 24 bits belonged to the 1995 header (RFC 1883) with a 4-bit priority field. The book counts TOS as removed and traffic class as added; most comparisons call it renamed.

Extension headers: the options moved out of the base header

PIN 1/27 Open the full card

Extension headers: optional headers between the base header and the upper-layer data, each naming the next in its next header field; they carry what IPv4 kept in options and fragmentation fields, and except hop-by-hop options are examined only where the packet is addressed.

Why: IPv4 options sit in the header, so every router checks for them; IPv6 keeps the base header fixed and adds extension headers only where needed: a compromise between generality and efficiency, and extensible (a new feature is a new header type).

Figure: a packet whose base header says next header 0, then hop-by-hop (43), routing (44), fragment (6), TCP; and the eight places of the recommended order with their codes

Chain: base header's next header gives the first extension header; each extension header's next header gives the following one; the chain ends at the upper layer (6 TCP, 17 UDP, 58 ICMPv6) or 59 (no next header).

Format: each starts with an 8-bit next header and (except the fixed 8-byte fragment header) an 8-bit length in 8-byte units not counting the first 8; each padded to a multiple of 8 bytes.

OrderHeaderCodeRead byWhat it does
1Hop-by-hop options0every node on the pathfirst, right after the base header; Pad1, PadN, Jumbo Payload (over 65,535, up to 232−1), Router Alert (MLD)
2Destination options60destination and nodes the routing header listsoptions for those nodes
3Routing43listed nodesaddresses to visit; IPv4's loose and strict source routing
4Fragment44final destination13-bit offset, more-fragments flag, 32-bit identification; source-only
5Authentication header (AH)51final destinationsender and integrity (IPsec)
6Encapsulating security payload (ESP)50final destinationencryption and integrity
7Destination options60final destination onlyoptions for the receiver
8Upper-layer header6, 17, 58TCP, UDP, ICMPv6the data

Rules (RFC 8200): each at most once, except destination options (at most twice); hop-by-hop must follow the base header directly and, since RFC 8200, is processed by a router only if configured to; no router inserts or deletes extension headers.

Memory example: a parcel from Kathmandu to Pokhara with stickers in order: "fragile" read by every handler (hop-by-hop), "via the Mugling office" (routing), "box 2 of 3" (fragment), wax seal (AH), locked inner box (ESP).

Fragmentation only at the source: path MTU discovery (RFC 8201) sends at the link MTU; a router that cannot forward drops and returns ICMPv6 Packet Too Big with the next link's MTU; the source sends smaller, using a fragment header only when it must. Every IPv6 link carries at least 1,280 bytes.

Book slips: the next header table gives ICMP as 2; ICMPv6 is 58 (2 is IGMP in IPv4; IPv4 ICMP is 1). "Only three hop-by-hop options": Router Alert is a fourth. The "source routing" header is the routing header; type 0 deprecated in 2007 (RFC 5095), as attackers bounced traffic between routers with it. "Up to six extension headers" counts the six types a full implementation supports; destination options may appear twice.

IPv6 addresses: notation, types and autoconfiguration

PIN 3/27 Open the full card

IPv6 address: a 128-bit identifier for an interface (unicast, anycast) or a set of interfaces (multicast), written as eight groups of four hexadecimal digits separated by colons, with a prefix length after a slash: 2001:db8:acad:1::/64 (RFC 4291).

Shortening 2001:0db8:0000:0000:0000:ff00:0042:8329:

  1. Drop leading zeros in each group: 0db8 to db8, 0042 to 42, 0000 to 0.
  2. Replace one run of zero groups by ::, once only: 2001:db8:0:0:0:ff00:42:8329 becomes 2001:db8::ff00:42:8329.
  • Expanding: :: stands for 8 minus the number of groups shown.
  • Only once: 2001:db8::1::1 could be 2001:db8:0:1:0:0:0:1 or 2001:db8:0:0:1:0:0:1.
  • Canonical form (RFC 5952): lower case, longest zero run shortened (the first if equal), never :: for a single zero group.

Prefixes as in CIDR: /64 leaves 64 bits of interface ID; an ISP holds a /32, a site gets a /48 (a home a /56), subnets are /64; a /48 holds 216 = 65,536 subnets. In a URL: http://[2001:db8::1]:8080/.

TypeDelivered toRanges and examples
Unicastone interfaceglobal 2000::/3 (2001:db8:acad:1::20), link-local fe80::/10, unique local fc00::/7, loopback ::1, unspecified ::
Anycastthe nearest of a set, by routingfrom unicast space; subnet-router anycast = prefix with all-zero interface ID, 2001:db8:acad:1::
Multicastevery group memberff00::/8: ff02::1 all nodes, ff02::2 all routers

No broadcast in IPv6.

Figure: five 128-bit layouts: global unicast, link-local, unique local, multicast, IPv4-mapped

  • Global unicast (2000::/3): routable; global routing prefix (48 bits for a typical site), 16-bit subnet ID, 64-bit interface ID.
  • Link-local (fe80::/10): every interface makes one; its own link only, never forwarded; used by neighbour discovery and routing protocols; the default gateway is the router's link-local address.
  • Unique local (fc00::/7, in practice fd00::/8 with a random 40-bit global ID, RFC 4193): private, like 10.0.0.0/8.
  • Site-local (fec0::/10): deprecated 2004 (RFC 3879), replaced by unique local.

IPv4 inside IPv6: write each IPv4 byte as two hex digits: 192.0.2.33 is c0, 00, 02, 21, so c000:0221.

FormLayout192.0.2.33 becomesUsed for
IPv4-mapped80 zero bits, 16 one bits, IPv4::ffff:192.0.2.33 = ::ffff:c000:221an IPv4 peer seen by an IPv6 socket on a dual-stack host; SIIT
IPv4-compatible96 zero bits, IPv4::192.0.2.33deprecated (RFC 4291)
NAT64 well-known prefix64:ff9b::/96, IPv464:ff9b::c000:221IPv6-only hosts reaching IPv4 servers
6to4 site prefix2002, IPv4, subnet, interface2002:c000:221::/48automatic tunnels
Getting an address automatically

Three ways, chosen by router advertisement flags: SLAAC (RFC 4862, the host builds its own address, no server record); stateless DHCPv6 (SLAAC address, DHCPv6 for DNS and settings); stateful DHCPv6 (RFC 8415, a server leases addresses). SLAAC runs on neighbour discovery (RFC 4861), ICMPv6 messages that also replace ARP: router solicitation 133, router advertisement 134, neighbour solicitation 135, neighbour advertisement 136, redirect 137.

Figure: SLAAC as a message sequence between the new host, the other nodes and the router, with the EUI-64 interface ID derivation

  1. Link-local address: fe80::/64 plus a 64-bit interface ID: fe80::200:5eff:fe00:5301.
  2. DAD: from ::, a neighbour solicitation for the new address to its solicited-node group ff02::1:ff00:5301; a neighbour advertisement means duplicate; silence for about a second means the address is the host's.
  3. Router solicitation to ff02::2 (all routers).
  4. Router advertisement to ff02::1 (all nodes): prefix 2001:db8:acad:1::/64, valid and preferred lifetimes, hop limit, MTU, M (managed) and O (other) flags, often DNS servers (RDNSS, RFC 8106); the router's link-local address becomes the default gateway.
  5. Global address: 2001:db8:acad:1:200:5eff:fe00:5301, checked by DAD.
  6. DHCPv6 if flagged: M set, address from DHCPv6 (UDP 546 and 547); O set, only DNS and settings.

Modified EUI-64: split the MAC, insert FF-FE, flip bit 7 of the first byte (universal/local): 00-00-5E-00-53-01 gives 02-00-5E-FF-FE-00-53-01, interface ID 0200:5eff:fe00:5301. Privacy: a MAC-based ID lets sites track a device across networks; current systems use random IDs, stable per network (RFC 7217) or temporary (RFC 8981). Renumbering: the router advertises the new prefix, the old preferred lifetime runs out, hosts move by themselves.

Memory example: a hostel room with no warden: the corridor notice gives block and floor (prefix), you add your roll number (interface ID), shout once "anyone using this number?" (DAD), and with no answer the room is yours; no register: stateless.

Book slips: its example FE80:0000:0000:0001:0800:23E7:F5DB has only seven groups (112 bits); its shortened FE80::1:0800:23E7:F5DB is valid but means fe80:0:0:0:1:800:23e7:f5db (three zero groups) and keeps the leading zero of 0800. It lists site-local as a unicast type (deprecated 2004).

IPv6 multicasting: groups, scopes and MLD

Open the full card

IPv6 multicasting: delivery of one packet to every member of a group named by an address in ff00::/8; no broadcast exists, so broadcast jobs use multicast groups; every multicast address carries a scope; routers find listeners with MLD.

Any node may join or leave at any time; a sender needs no member list; a group address is only a destination, never a source nor a routing-header stop; one copy reaches each member, by hardware multicast on each link.

Figure: the multicast address (ff, flags, scope, group ID), the scope values, and the solicited-node group derived from a unicast address

  • Prefix: first 8 bits 1111 1111, so ff.
  • Flags (4 bits, 0RPT): T = 0 permanent (IANA), T = 1 temporary; P = 1 prefix-based (RFC 3306); R = 1 rendezvous point embedded (RFC 3956).
  • Scope (4 bits): a router never forwards beyond it; IPv4 marked scope only by convention (239.0.0.0/8, TTL limits).
  • Group ID (112 bits).
ScopeReach
1interface-local (loopback)
2link-local, never routed
4admin-local, set by configuration
5site-local
8organization-local
eglobal
AddressGroup
ff02::1all nodes (nearest thing to broadcast)
ff02::2all routers
ff02::5, ff02::6OSPFv3 routers, OSPFv3 designated routers
ff02::9RIPng routers
ff02::aEIGRP routers
ff02::16MLDv2-capable routers
ff02::1:2all DHCPv6 relay agents and servers
ff05::1:3all DHCPv6 servers in the site

Solicited-node group: every unicast address joins ff02::1:ff plus its last 24 bits: 2001:db8:acad:1:200:5eff:fe00:5301 joins ff02::1:ff00:5301; neighbour solicitations (address resolution, DAD) go there, not to everyone. On Ethernet the MAC is 33:33 plus the last 32 bits (RFC 2464): 33:33:ff:00:53:01; ff02::1 maps to 33:33:00:00:00:01. The card filters in hardware, so only hosts sharing the last 24 bits (usually one) are disturbed.

MLD (Multicast Listener Discovery), part of ICMPv6: MLDv1 (RFC 2710) like IGMPv2, MLDv2 (RFC 3810) like IGMPv3 with source filtering. Query 130; report 131 (v1) or 143 (v2); done 132. Link-local source, hop limit 1, Router Alert option; switches snoop MLD. Between routers, PIM-SM and PIM-SSM.

Memory example: the warden shouting "room 301!" down every corridor is broadcast; calling only rooms ending in 301 is the solicited-node group; "second-year students, this block only" is a scoped group.

From IPv4 to IPv6: coexistence, dual stack, tunneling and translation

TOP 18/27 Open the full card

Transition from IPv4 to IPv6: the gradual migration of hosts, routers and applications from IPv4 to IPv6 while both keep working, by dual stack, tunneling and header (address family) translation.

No switch-over day: IPv6 is not backward compatible (an IPv4-only host cannot read an IPv6 header); billions of devices cannot change at once, unlike the ARPANET's switch to TCP/IP on 1 January 1983.

Coexistence: IPv4 and IPv6 running side by side on the same Internet, often on the same hosts, links and routers, through the migration; nodes are IPv4-only, IPv6-only or dual stack, and the mechanisms let any two communicate until IPv4 is switched off.

SituationMechanism
a node must talk to IPv4 and IPv6 hostsdual stack
IPv6 networks separated by IPv4tunneling (configured, 6to4, ISATAP, 6RD, Teredo)
IPv6-only host to IPv4-only hostheader translation (SIIT, NAT64 with DNS64)
IPv4 customers on IPv6-only provider networksDS-Lite, 464XLAT, MAP

Figure: the three strategies in rows: a dual-stack host between IPv4-only and IPv6-only hosts; an IPv6 packet inside an IPv4 packet (protocol 41) between R1 and R2; a NAT64 translator rewriting an IPv6 header as IPv4

Memory example: an English letter crossing a Nepali-only post office: a clerk reading both scripts is dual stack; the letter sealed in a Nepali-addressed envelope is tunneling; an interpreter rewriting it in Nepali is translation (some meaning may be lost).

1. Dual stack (RFC 4213)

Every node runs both stacks: one application and TCP/UDP layer over IPv4 and IPv6 network layers on the same link; each interface has an IPv4 and an IPv6 address; routers keep two routing tables and run both protocol sets (OSPFv2 and OSPFv3).

Figure: a dual-stack host's layers, with IPv4 reaching an IPv4-only server (A record) and IPv6 an IPv6 server (AAAA record)

  • Choosing: DNS A and AAAA records; AAAA means IPv6, preferred by default address selection (RFC 6724); only A means IPv4.
  • Happy Eyeballs (RFC 8305): if IPv6 has not answered within about 250 ms (recommended default), try IPv4 too and keep the first to connect.
  • For: simplest, native speed, nothing encapsulated or translated, services move when ready; recommended wherever possible (RFC 6180).
  • Against: every node still needs an IPv4 address (no help with exhaustion); two sets of addresses, firewall rules and routing tables.

Example: a laptop on college Wi-Fi with 192.168.1.20 (DHCP) and 2001:db8:acad:1::20 (SLAAC) fetches AAAA sites over IPv6 and A-only sites over IPv4 through NAT.

2. Tunneling

IPv6 nodes separated by an IPv4-only region: the entry router (dual stack) encapsulates the whole IPv6 packet behind an IPv4 header with protocol 41 addressed to the tunnel exit; IPv4 routers forward it as ordinary IPv4; the exit router decapsulates and forwards the IPv6 packet. The IPv4 region looks like one hop.

Figure: IPv6 host A, router R1 (192.0.2.1), an IPv4-only network, router R2 (198.51.100.1), IPv6 host B, with the packet on each stretch

Costs: 20 extra bytes (smaller MTU), harder troubleshooting (one hop in traceroute), firewalls bypassed if protocol 41 is not inspected.

TunnelConnectsFar end fromAddressStatus
Configured (RFC 4213)two routers, or host and tunnel brokerset by handanycommon for router links
6to4 (RFC 3056)IPv6 sites across the IPv4 InternetIPv4 inside the 6to4 prefix2002:WWXX:YYZZ::/48relays deprecated 2015 (RFC 7526)
ISATAP (RFC 5214)dual-stack hosts in one IPv4 siteIPv4 in the interface IDprefix + 0:5efe:a.b.c.dlittle used now
6RD (RFC 5969)ISP customers over its IPv4 networkIPv4 bits in the ISP's 6rd prefixISP prefix + IPv4 bitsISP deployments
Teredo (RFC 4380)hosts behind IPv4 NAT, UDP 3544Teredo servers and relays2001::/32last resort, little used now

Figure: the address formats of 6to4, ISATAP, 6RD and Teredo as 128-bit bars

6to4: prefix 2002 plus the site router's public IPv4 in hex (48 bits), then 16-bit subnet ID and 64-bit interface ID. Router 192.0.2.4 gives 2002:c000:204::/48. Between 6to4 sites the router copies bits 17 to 48 of the destination (the far router's IPv4) and tunnels straight there; to native IPv6, through a 6to4 relay (once anycast 192.88.99.1). Weakness: needs public IPv4 (fails behind NAT); unowned public relays gave slow, one-sided or broken paths; anycast relay prefix deprecated 2015 (RFC 7526).

ISATAP (Intra-Site Automatic Tunnel Addressing Protocol): IPv6 for dual-stack hosts inside an IPv4-only organization network, treated as one link. Interface ID 0000:5efe + host IPv4 (0200:5efe if the IPv4 address is globally unique, the universal/local bit). Host 10.1.1.5 gets fe80::5efe:a01:105 (fe80::5efe:10.1.1.5). The host finds the ISATAP router (Windows looked up the DNS name isatap), sends a router solicitation inside IPv4, receives the prefix 2001:db8:acad:5::/64, forms 2001:db8:acad:5:0:5efe:a01:105. To ISATAP hosts: tunnel straight to the IPv4 in the last 32 bits; elsewhere: via the ISATAP router.

6RD (IPv6 rapid deployment): 6to4 rebuilt inside one ISP; first used by the French ISP Free in 2007 (described in RFC 5569, 2010), standardised in RFC 5969 (2010).

  • Importance: IPv6 over an IPv4-only access network without upgrading it; the ISP's own prefix and relays (reliable, under its control); stateless, scales; stable delegated prefix per customer.
  • Parts: customer edge (CE) router; border relay (BR) routers.
  • Configuration: usually DHCPv4 option 212: 6rd prefix, its length, the number of shared leading IPv4 bits left out, BR IPv4 address.
  • Delegated prefix: 6rd prefix + remaining IPv4 bits. 2001:db8::/32, no shared bits, CE 203.0.113.5 (cb00:7105) gives 2001:db8:cb00:7105::/64. With all customers in 198.51.100.0/24 (24 bits left out), 2001:db8:ab00::/40 gives CE 198.51.100.7 the /48 2001:db8:ab07::/48.
  • Forwarding: CE wraps IPv6 in IPv4 (protocol 41) to the BR or another CE; the BR unwraps and forwards natively, and for replies reads the CE's IPv4 out of the destination prefix.

Teredo (RFC 4380): for hosts behind IPv4 NAT, IPv6 inside UDP (port 3544) inside IPv4; address in 2001::/32 with the Teredo server's IPv4 and the client's obscured public port and IPv4.

3. Header translation (address family translation)

One end IPv6-only, the other IPv4-only: a translator rewrites each header in the other version and maps addresses between the address families. The book's case: a mostly IPv6 Internet with IPv4 stragglers; today usually IPv6-only networks (mobile operators) reaching IPv4-only servers.

Figure: an IPv6-only host, DNS64, a NAT64 translator and an IPv4-only server, with the field mapping table

Procedure, IPv6 to IPv4 (SIIT rules, RFC 7915):

  1. Addresses: IPv4 destination from the low 32 bits (64:ff9b::c000:221 gives 192.0.2.33); IPv6 source to an IPv4 address by a fixed mapping or, in NAT64, a shared pool address and port.
  2. Version 6 to 4; 20-byte header (IHL 5, no options).
  3. Traffic class copied into TOS (or replaced by a configured value).
  4. Flow label dropped.
  5. Payload length plus 20 becomes total length.
  6. Next header to protocol (ICMPv6 58 to ICMP 1); hop-by-hop, routing and destination options dropped; a fragment header becomes identification, flags, fragment offset.
  7. Hop limit to TTL, lowered by one (the translator is a router).
  8. Header checksum computed; TCP and UDP checksums adjusted; ICMPv6 messages rewritten as ICMP.

Replies: the same in reverse.

TranslatorHow it worksStatus
SIIT (RFC 7915)stateless, one packet at a time, fixed one-to-one address mappingcurrent; base of the others
NAT-PT (RFC 2766, 2000)stateful with a built-in DNS gatewayHistoric since 2007 (RFC 4966)
NAT64 (RFC 6146, 2011)stateful; IPv6 clients share IPv4 addresses by portcurrent, with DNS64
DNS64 (RFC 6147)synthesizes AAAA from A: 192.0.2.33 to 64:ff9b::c000:221current
464XLAT (RFC 6877, 2013)CLAT on the device (stateless, IPv4 to IPv6) plus PLAT (NAT64) in the networkIPv6-only mobile networks

Limits: applications carrying addresses in their data (FTP, SIP) break without an ALG; end-to-end IPsec fails; the flow label and extension headers are lost; a stateful translator holds every flow's state.

The latest methods and which to choose

IPv6-only provider networks carrying IPv4 as a service: NAT64 with DNS64 and 464XLAT on mobile networks; DS-Lite (RFC 6333: home router tunnels IPv4 in IPv6 to the ISP's carrier-grade NAT, the AFTR); MAP-E and MAP-T (RFC 7597, RFC 7599: stateless IPv4 sharing by port range). RFC 9313 (2022) compares five: 464XLAT, DS-Lite, lightweight 4over6, MAP-E, MAP-T.

SituationChooseWhy
both protocols possible, IPv4 addresses to handdual stacknative, simplest; IETF's first choice (RFC 6180)
IPv6 islands across an IPv4-only networkconfigured tunnel, or 6RD from the ISPreuses IPv4 until upgraded
IPv6-only network reaching IPv4-only contentNAT64 with DNS64; 464XLAT on phonesno IPv4 needed inside
ISP short of IPv4 addressesDS-Lite, MAP, 464XLATIPv4 as a service over IPv6

For a campus or company: dual stack, a tunnel only as a stop-gap, translation where part of the network goes IPv6-only.

Book slip: its eight translation steps (from older textbooks) set TOS to zero, discard a "priority" field and convert extension headers to IPv4 options; RFC 7915 copies the traffic class into TOS by default, drops hop-by-hop, routing and destination options headers, and maps only the fragment header; "priority" was the 4-bit field of the 1995 header (RFC 1883).

Chapter 8: Network security 7690 words

Network security and the properties of secure communication

TOP 11/27 Open the full card

Network security: the policies, practices and technologies that protect a network and the data crossing it from unauthorised access, misuse, modification and disruption, so that a sender and a receiver can communicate securely over an insecure medium. The setting: a sender (Alice) and a receiver (Bob) exchange messages over a medium they do not control (the Internet, a radio link), where an intruder (Trudy) may intercept, read, change, delete or inject messages. The book: the basic objective is to communicate securely over an insecure medium.

Figure: four panels, A sending to B with intruder T: interruption, interception, modification, fabrication, each with the property it violates

The four classic attacks:

  • Interruption: the message is destroyed or blocked (cut cable, jammed radio, flooded server); attacks availability.
  • Interception: an unauthorised party reads it (sniffing open Wi-Fi); attacks confidentiality.
  • Modification: the message is changed in transit; attacks integrity.
  • Fabrication: a false message inserted as if from a genuine sender; attacks authenticity.

Passive attacks (interception, traffic analysis) change nothing, are hard to detect, and are defeated by prevention (encryption). Active attacks (interruption, modification, fabrication, replay of a captured valid message such as a login, denial of service) alter the stream; the aim is to detect them and recover.

PropertyMeaningAttack it answersProvided by
Confidentialityonly sender and intended receiver understand the contentinterception, eavesdroppingencryption (AES, TLS, WPA2)
Integritycontent arrives exactly as sent, not altered by accident or on purposemodificationhash with a MAC, digital signature
Authenticationeach end confirms the other is who it claims, and a message came from its claimed senderfabrication, masqueradepasswords, certificates, signatures
Non-repudiationsender cannot later deny sending (nor receiver deny receiving)repudiationdigital signature
Availabilitynetwork and services usable by authorised users when neededinterruption, denial of serviceredundancy, filtering, backups
Access controlonly authorised users reach a resource, only with their rightsunauthorised accessfirewalls, ACLs, permissions

CIA triad: confidentiality, integrity, availability, the core; authentication, non-repudiation and access control complete it for two communicating parties.

Memory example, a cheque paid into a bank: nobody else reads the account number (confidentiality); Rs 500 does not become Rs 5,000 (integrity); the bank checks the signature (authentication); the writer cannot deny it (non-repudiation); the bank is open (availability); only the cashier opens the drawer (access control).

Maintaining security: defense in depth

No single device gives all six properties; protect in layers, so one failure leaves the next control standing. Procedures, in order:

  1. Policy and risk assessment: assets (servers, data, links), threats, rules of use.
  2. Access control: individual accounts, strong passwords or multi-factor login, least privilege, accounts removed when people leave.
  3. Encryption: TLS for web and mail, VPN for remote and branch links, WPA2 or WPA3 on Wi-Fi, encrypted disks and backups.
  4. Perimeter control: firewall and router ACLs at every boundary; public servers in a DMZ.
  5. Segmentation: VLANs keep hostel, office and server networks apart; separate guest Wi-Fi.
  6. Hardening and patching: updates for routers, servers, PCs; unused services and ports off; default passwords changed.
  7. Malware protection: antivirus or endpoint protection, filtering of e-mail attachments and links.
  8. Monitoring: IDS or IPS, logs collected and reviewed, alerts acted on.
  9. Availability measures: offline backups, redundant links and power, flood protection.
  10. Physical security and people: locked racks and wiring closets, phishing training, an incident response plan.

Example, a campus hostel network: WPA2 with a password per block and a separate guest network; router ACL drops Telnet and remote desktop from outside; warden's office PCs on their own VLAN; router firmware updated each semester; rack in a locked room; students told never to share the result-portal password.

The book gives five headings: confidentiality, authentication, non-repudiation, message integrity, and access control with availability as one; heading 4 is printed "Message Integrity and Non-reliability" (the text means integrity and non-repudiation). It offers checksums for integrity, but a checksum or CRC stops only accidents (an attacker recomputes it); integrity against an attacker needs a keyed MAC or a signature. Kurose and Ross name four: confidentiality, message integrity, end-point authentication, operational security.

Cryptography: symmetric key and public key

HOT 8/27 Open the full card

Cryptography: the science of keeping messages secure by transforming them into an unreadable form (encryption) that only the holder of the right key can turn back (decryption). Two families: symmetric key (one shared secret key) and public key or asymmetric (a key pair, one public, one private).

  • Plaintext (P): the original readable message.
  • Ciphertext (C): the scrambled message that travels, C=EK(P); decryption gives P=DK(C).
  • Cipher: the encryption and decryption algorithms together.
  • Key (K): the secret value the algorithm uses; another key gives another ciphertext.
  • Cryptanalysis: breaking a cipher without the key; cryptology covers making and breaking.

Kerckhoffs's principle: the algorithm is public, only the key is secret (DES, AES, RSA are published standards); security comes from a key space too large to try every key (brute force).

Figure: two rows; symmetric: plaintext, encrypt with shared key K, ciphertext, decrypt with the same K; public key: encrypt with B's public key, decrypt with B's private key

Symmetric key (secret key, conventional): one shared key encrypts and decrypts; fast enough for bulk data (disk encryption, TLS records, VPN tunnels, Wi-Fi). Weakness: key distribution, the key must reach the other side secretly before the first message, and every pair needs its own key: n(n−1)/2 keys for n users (100 users: 4,950 keys).

  • Block ciphers: a fixed block at a time: DES (64-bit blocks), 3DES, AES (128-bit blocks), IDEA, Blowfish.
  • Stream ciphers: XOR the data with a keystream, bit or byte at a time: RC4 (WEP), ChaCha20.

Public key (asymmetric): each user has a key pair, a public key published to everyone and a private key that never leaves its owner; what one encrypts, only the other decrypts. To send a secret to B, encrypt with B's public key; only B's private key decrypts. To sign, B encrypts a digest with its private key; anyone checks with B's public key. Solves key distribution (2n keys for n users, nothing secret shared) but slow (numbers hundreds of digits long). Examples: RSA, Diffie-Hellman, ElGamal, ECC, DSA. Diffie and Hellman published the idea in 1976.

Memory example, padlocks: symmetric is one lock with two identical keys, one of which must reach a friend in Dharan uncopied; public key is open padlocks handed to anyone, which anyone can snap shut, but only one key opens.

PointSymmetric keyPublic key (asymmetric)
Keysone shared secret keya public key and a private key
Who holds themboth parties, secretlypublic: anyone; private: owner only
Encrypt, decryptthe same keyone key of the pair each
Speedfast: long messages, bulk dataslow: short data, keys, digests
Key distributionhard: shared secretly firsteasy: publish, with a certificate
Keys for n usersn(n−1)/22n
Equal strength128 bits (AES-128)3072 bits (RSA-3072), NIST SP 800-57
Servicesconfidentialityconfidentiality, authentication, non-repudiation, key exchange
ExamplesDES, 3DES, AES, IDEA, RC4RSA, Diffie-Hellman, ElGamal, ECC, DSA

Hybrid use: public key cryptography only agrees or protects a fresh random session key; a fast symmetric cipher encrypts the data under it (PGP, TLS, IPsec).

Types of encryption used in security: symmetric key and asymmetric (public key) encryption; beside them the hash function (MD5, SHA-1, SHA-256), a keyless one-way transformation of any message to a fixed-length digest, which cannot be decrypted and so gives integrity, not secrecy. The oldest ciphers, substitution and transposition, are the classical ciphers.

Classical ciphers: substitution and transposition

Open the full card

Classical ciphers: traditional pre-computer ciphers on letters. Substitution replaces each letter and keeps the order; transposition keeps the letters and changes their order. Every modern symmetric cipher repeats both under a key: DES S-boxes substitute and P-boxes transpose; AES SubBytes substitutes, ShiftRows transposes.

Caesar (shift) cipher: each letter moves k places, wrapping z to a.

C=(P+k)mod26,P=(C−k)mod26

Book's example, k=2: i am a student becomes k co c uvwfgpv. Only 25 useful keys: brute force.

Monoalphabetic: any rearrangement of the alphabet is the key: 26!≈4×1026 keys, but frequency analysis (e, t, a commonest in English) breaks it. Kurose and Ross's key:

plaintext:  abcdefghijklmnopqrstuvwxyz
ciphertext: mnbvcxzasdfghjklpoiuytrewq
attack  becomes  muumbf

Polyalphabetic: several substitutions in turn, so one plaintext letter maps to different letters and frequencies blur. Book: C1 (k=2), C2 (k=5), pattern C1, C2, C1: i am a student becomes k fo c xvwigpy (the two a's become f and c). Vigenère: a key word gives the shifts.

Transposition (columnar): write in rows under a numbered key, read columns in key order.

key:    3 1 4 2
        M E E T
        A T R A
        T N A P
        A R K X      (X pads)
read columns 1, 2, 3, 4 of the key:  ETNR TAPX MATA ERAK  =  ETNRTAPXMATAERAK

The receiver writes the groups back into columns and reads the rows: MEET AT RATNAPARK.

PointSubstitutionTransposition
Changesthe letterstheir order
Letter frequencieshidden only by polyalphabetic formsunchanged
ExamplesCaesar, monoalphabetic, Vigenèrecolumnar, rail fence
In modern ciphersS-boxes, SubBytesP-boxes, ShiftRows

Memory example: a class note with each letter written two on (Caesar), or written in a grid and read down the columns (transposition).

Book's slips: its Caesar answer "k co c UV FG PV" drops the w (correct: k co c uvwfgpv); its monoalphabetic key repeats i (the 16th letter should be l, as in Kurose and Ross); its answer QZZQEA comes from the keyboard key qwerty... (a to q, t to z, c to e, k to a); the printed key gives muumbf.

DES and AES: the symmetric block ciphers

PIN 4/27 Open the full card

DES (Data Encryption Standard, FIPS 46, 1977): 64-bit blocks, 56-bit key, 16 Feistel rounds. AES (Advanced Encryption Standard, FIPS 197, 2001): 128-bit blocks, 128, 192 or 256-bit key, 10, 12 or 14 rounds; has replaced DES.

Block cipher: a fixed-size block plus a key gives a ciphertext block of the same size; built from P-boxes (permute bits), S-boxes (non-linear substitution) and XOR with a round key, repeated in rounds. Shannon's goals: confusion (ciphertext depends on the key in a complicated way) and diffusion (each plaintext bit affects many ciphertext bits).

DES in numbers: designed at IBM from Lucifer, adopted by the US National Bureau of Standards (now NIST) in 1977. 64-bit plaintext block, 64-bit key with 8 parity bits (56-bit effective key), 16 rounds each with a 48-bit round key, 64-bit ciphertext; the same algorithm decrypts.

Figure: DES structure (IP, rounds 1 to 16 fed K1 to K16 by the key schedule, 32-bit swap, final permutation), one Feistel round, and the f function

The operation of DES:

  1. Initial permutation (IP): the 64 bits rearranged by a fixed table (bit 58 to position 1, bit 50 to position 2, and so on).
  2. Split: left half L0, right half R0, 32 bits each.
  3. Sixteen Feistel rounds: Li=Ri−1, Ri=Li−1⊕f(Ri−1,Ki).
  4. 32-bit swap of the halves after round 16.
  5. Final permutation IP−1 gives the 64-bit ciphertext.

Round function f (32-bit half, 48-bit key):

  • Expansion E: 32 bits to 48 by repeating 16 of them.
  • XOR with the round key Ki.
  • Eight S-boxes: eight 6-bit groups, each to 4 bits; outer two bits pick one of 4 rows, inner four one of 16 columns; 48 to 32 bits; the only non-linear step, the heart of DES security.
  • Permutation P: straight permutation of 32 bits.

S-box example: input 011011 to S1: row 01 = 1, column 1101 = 13; row 1 of S1 is 0 15 7 4 14 2 13 1 10 6 12 11 9 5 3 8; column 13 (from 0) is 5; output 0101.

Key schedule: PC-1 drops the 8 parity bits and permutes 56; two 28-bit halves, each rotated left 1 bit (rounds 1, 2, 9, 16) or 2 bits (others); PC-2 picks 48 bits as Ki.

Decryption: the same steps, round keys reversed (K16 first); a Feistel structure never needs the inverse of f. Test vector: key 133457799BBCDFF1 encrypts 0123456789ABCDEF to 85E813540F0AB405.

Retired: only 256≈7.2×1016 keys; in 1998 the EFF DES Cracker found a key by brute force in under three days. Triple DES (3DES): encrypt, decrypt, encrypt with two or three keys (112 or 168 bits); strong but a third the speed; being retired for AES.

AES: NIST open competition 1997 to 2000, fifteen candidates; winner Rijndael by the Belgian cryptographers Joan Daemen and Vincent Rijmen; FIPS 197 in 2001; used in WPA2, TLS, VPNs, disk encryption.

  • Block: 128 bits as a 4 x 4 state of 16 bytes, filled column by column.
  • Key, rounds: 128-bit key 10 rounds; 192-bit 12; 256-bit 14.
  • Structure: substitution-permutation network, not Feistel; every round changes all 16 bytes.

Figure: AES-128 flow: round 0 AddRoundKey with K0, rounds 1 to 9 with all four steps, round 10 without MixColumns; key expansion to K0 to K10; the state grid before and after ShiftRows

One AES round:

  1. SubBytes: each byte through a fixed 16 x 16 S-box (inverse in GF(28), then an affine map): 00 to 63, 53 to ED; the non-linear step.
  2. ShiftRows: row 0 stays; rows 1, 2, 3 rotate 1, 2, 3 bytes left.
  3. MixColumns: each column multiplied by a fixed matrix over GF(28); each output byte depends on its whole column.
  4. AddRoundKey: XOR with the 128-bit round key.

Whole cipher: initial AddRoundKey with K0; rounds 1 to 9 all four steps; round 10 without MixColumns. Key expansion: 128-bit key to 44 words of 32 bits (11 round keys, K0 to K10). Decryption: InvShiftRows, InvSubBytes, AddRoundKey, InvMixColumns, round keys reversed.

A word in AES: ASCII bytes, NEPAL = 4E 45 50 41 4C, padded to 16 (PKCS#7: 11 bytes of value 0B) and filled column by column. With the FIPS 197 example key 2B 7E 15 16 ...: 4E XOR 2B = 65; SubBytes gives 4D. FIPS 197 Appendix B: plaintext 32 43 F6 A8 88 5A 30 8D 31 31 98 A2 E0 37 07 34 gives ciphertext 39 25 84 1D 02 DC 09 FB DC 11 85 97 19 6A 0B 32.

PointDESAES
StandardFIPS 46, 1977FIPS 197, 2001
DesignerIBM (from Lucifer)Daemen and Rijmen (Rijndael)
Block64 bits128 bits
Key56 bits (64 with parity)128, 192 or 256 bits
Rounds1610, 12 or 14
StructureFeistel: half the block per roundsubstitution-permutation: whole block per round
Round stepsexpansion, XOR key, 8 S-boxes, permutationSubBytes, ShiftRows, MixColumns, AddRoundKey
Decryptionsame steps, keys reversedinverse steps, reverse order
Securitybroken by brute force (256 keys)no practical attack; current standard
Speedslow in software (bit permutations)fast, processor instructions for it

By hand: ten AES rounds do not fit the time; "encrypt the word using any suitable AES technique" is answered with the structure and the first round on the state, or with simplified AES (S-AES: 16-bit block, 16-bit key, two rounds). The Numericals panel works both papers' words.

Memory example: the hostel Wi-Fi encrypts every frame with AES-128 under WPA2; DES survives mostly in old systems and exam questions.

Book's slip: its DES operation says "a 6-bit block of ciphertext comes out"; the ciphertext block is 64 bits.

RSA: the public key algorithm, step by step

TOP 16/27 Open the full card

RSA (Rivest, Shamir, Adleman, MIT, 1977): public key (e,n) encrypts, private key (d,n) decrypts; C=Memodn, M=Cdmodn; security rests on factoring n, the product of two large primes. Idea: multiplying two primes is easy, recovering them from a product hundreds of digits long is practically impossible.

Figure: key generation steps with p 7, q 11 (n 77, phi 60, e 13, d 37), public key (13, 77), private key (37, 77); A encrypts E = 5 to 26, B decrypts 26 to 5

Key generation, once, by the receiver:

  1. Choose two primes p, q, large and distinct.
  2. Modulus n=p×q; its bit length is the key size (2048 bits today).
  3. ϕ(n)=(p−1)(q−1), Euler's totient (the book's z).
  4. Public exponent e: 1<e<ϕ(n), gcd(e,ϕ(n))=1; in practice e=65537.
  5. Private exponent d: inverse of e modulo ϕ(n), (e×d)modϕ(n)=1.
  6. Publish (e,n); keep (d,n), p, q, ϕ(n) secret.

For every message M with 0≤M<n:

C=MemodnM=Cdmodn

Why it works: e·d=1+kϕ(n) and Euler's theorem Mϕ(n)≡1(modn), so Cd=Med≡M(modn).

Why it is secure: d from (e,n) needs ϕ(n), which needs the factors p, q of n; a 2048-bit n has 617 decimal digits and no known method factors it in useful time. Exam-sized numbers only show the method.

The book's letter E, finished

p=7, q=11: n=77, ϕ(n)=60; e=13 (gcd(13,60)=1); d: smallest k with (1+60k)/13 whole is k=8, 481/13=37, so d=37 (13×37=481=8×60+1). Public (13, 77), private (37, 77). E is the 5th letter, M=5.

5^2 = 25
5^4 = 625 mod 77 = 9
5^8 = 81 mod 77 = 4
5^13 = 5^8 x 5^4 x 5 = 4 x 9 x 5 = 180 mod 77 = 26        C = 26

26^2  = 676 mod 77 = 60
26^4  = 3600 mod 77 = 58
26^8  = 3364 mod 77 = 53
26^16 = 2809 mod 77 = 37
26^32 = 1369 mod 77 = 60
26^37 = 60 x 58 x 26: 3480 mod 77 = 15; 15 x 26 = 390 mod 77 = 5     M = 5 = E

Repeated squaring: write the exponent as powers of two (37 = 32 + 4 + 1), square repeatedly mod n, multiply the needed squares, reducing after each product; no number exceeds (n−1)2.

Finding d: trial, d=(1+kϕ(n))/e for k=1,2,3,…; or the extended Euclidean algorithm (60 = 4 x 13 + 8, 13 = 1 x 8 + 5, 8 = 1 x 5 + 3, 5 = 1 x 3 + 2, 3 = 1 x 2 + 1, back-substituted to 37).

Encrypting a word: number the letters (A = 1 to Z = 26 common, A = 0 to Z = 25 if stated); choose p, q with n above the largest value (n=77>26); encrypt and decrypt each letter alone. Book example 2, SUZANNE with p=3, q=11, n=33, e=3, d=7: ciphertext 28 21 20 1 5 5 26. The papers' words are worked in the Numericals panel.

Weakness of letter-by-letter RSA: the two N's of SUZANNE both give 5; a substitution cipher open to frequency analysis. Real RSA encrypts one large padded number (OAEP), and in practice only a session key or a digest.

Signing: S=Mdmodn, checked as Semodn=M; with the keys above, M=5 signs to S=47 and 4713mod77=5.

Memory example: 7 x 11 = 77 is instant both ways, but a 617-digit number defeats every computer on Earth: easy one way, hopeless back.

Book's slips: example 1 sets up m=2637mod77 and stops (it is 5, the letter E); example 2 says e may be any value other than the factors 1, 2, 4, 5, 10 of z=20, but the rule is gcd(e,z)=1 (6 is no factor of 20 yet shares the factor 2, and has no d).

Diffie-Hellman key exchange

PIN 2/27 Open the full card

Diffie-Hellman (Whitfield Diffie and Martin Hellman, 1976): key agreement by which two parties sharing no secret exchange public values over an open channel and each computes the same secret key K=GxymodN, which an eavesdropper cannot compute. It creates a symmetric session key; it neither encrypts nor signs. Problem solved: a shared key appears at both ends without ever being sent.

Figure: public N = 23, G = 7; A's secret x = 3, R1 = 21; B's secret y = 6, R2 = 4; both reach K = 18; the eavesdropper sees 23, 7, 21, 4

Steps (public: large prime N, generator G, a primitive root of N):

  1. A chooses a large random secret x, computes R1=GxmodN.
  2. A sends R1 to B, never x.
  3. B chooses a large random secret y, computes R2=GymodN.
  4. B sends R2 to A, never y.
  5. A computes K=R2xmodN; B computes K=R1ymodN.

Equal because (Gy)x=(Gx)y=Gxy, all mod N.

Book's example (correct): G=7, N=23; x=3: R1=73mod23 = 343mod23=21; y=6: R2=76mod23 = 117649mod23=4; A: K=43mod23 = 64mod23=18; B: K=216mod23=18 (21≡−2, (−2)6=64≡18); K=718mod23=18.

Eavesdropper: sees N, G, R1, R2; needs x from R1=GxmodN, the discrete logarithm problem, infeasible for a 2048-bit prime (for 23, only x=3 gives 21).

Man in the middle: plain DH authenticates nobody; Trudy runs one exchange with A and one with B, then decrypts, reads and re-encrypts everything. Cure: authenticate the exchanged values with signatures and certificates (TLS, IKE for IPsec). TLS 1.3, IKE and SSH use ephemeral DH (fresh x, y per session): forward secrecy, a stolen long-term key cannot unlock past sessions.

Memory example, paint: common public yellow; each adds a secret colour, sends the mixture, adds the secret colour again to what arrives; both get the same brown; a watcher cannot un-mix the secrets.

The book: N a large prime with (N−1)/2 also prime (a safe prime: 23 = 2 x 11 + 1) and G "also a prime number"; the real requirement is that G is a primitive root of N (its powers run through 1 to N−1); 7 is a primitive root of 23 (first returns to 1 at 722).

Digital signatures: how they work

HOT 5/27 Open the full card

Digital signature: a value computed from a message and the signer's private key that anyone with the signer's public key can check; proves who sent it (authentication), that it was not changed (integrity), and that the sender cannot deny it (non-repudiation). Needed because an electronic document can be copied and edited without a trace, so its signature must depend on the exact content and a secret only the signer holds.

Figure: signing at A (hash, encrypt the digest with A's private key, send M with S); verifying at B (hash M to H1, decrypt S with A's public key to H2, compare)

Signing at A:

  1. Hash the message M (SHA-256): a short fixed-length digest H(M).
  2. Encrypt the digest with A's private key: the signature S (RSA: S=Hdmodn).
  3. Send M with S, usually with A's certificate.

Verifying at B:

  1. Hash the received message: H1.
  2. Decrypt the signature with A's public key: H2.
  3. Compare: H1=H2 means valid (only A's private key could make it, message unchanged); different means altered or forged, reject.

Why sign the hash: RSA on a long document is slow; the digest is small (256 bits for SHA-256) whatever the size; one changed bit changes about half the digest's bits. A good hash is one-way and collision resistant; MD5 and SHA-1 have known collisions and are no longer used for signatures; SHA-256 is.

Properties (book): verifiable, non-forgeable, non-repudiable. Different for every document, so it cannot be cut from one and pasted on another. No confidentiality: the message travels in the clear unless also encrypted (as PGP does).

Where the public key comes from: a certificate (X.509) binds a name to a public key and is signed by a certification authority (CA) the receiver trusts; browsers and operating systems ship trusted root CAs; this is the public key infrastructure (PKI). Nepal's Electronic Transactions Act, 2063 gives digital signatures legal force, with certifying authorities licensed under the Office of the Controller of Certification.

PointMACDigital signature
Keyone shared secret keysigner's private key; checked with its public key
Who can verifyholders of the shared keyanyone
Non-repudiationno: either end could make ityes: only the signer could
Speedfast (HMAC)slower (RSA, ECDSA)
Used inTLS records, IPsec packetscertificates, PGP mail, software updates

Example with the RSA card's keys (n=77, e=13, d=37): digest H=5; A signs S=537mod77=47; B checks 4713mod77=5, equal to its own hash; a tampered message's digest (say 6) would not match.

Memory example: Windows checks Microsoft's signature on an update before installing it; a file changed by one byte, or signed by anyone else, is refused. Algorithms: RSA signatures, DSA, ECDSA, EdDSA.

Book's slip: it says signing generates a hash "through a complex mathematical computation that generates a large prime number"; a hash gives a fixed-length digest, not a prime; primes belong to the RSA key pair.

PGP: how an e-mail is secured

PIN 3/27 Open the full card

PGP (Pretty Good Privacy, Phil Zimmermann, 1991): e-mail security program giving confidentiality, authentication, integrity and compression by combining a hash, a digital signature, a one-time symmetric session key and the receiver's public key; message format standardised as OpenPGP (RFC 4880). Mail needs it because SMTP carries messages in plain text through several servers, readable by anyone with access, and a forged sender costs nothing; PGP protects the message end to end.

Figure: six sending steps at A (hash, sign, compress, encrypt, lock the key, base64) with the services they give, and five receiving steps at B

Securing one mail from A to B:

  1. Hash the message (SHA-256 now; MD5 or SHA-1 in early versions).
  2. Sign: encrypt the digest with A's private key (RSA or DSA), attach it.
  3. Compress message and signature (ZIP).
  4. Encrypt the bundle with a fresh random session key, for this message only (IDEA, 3DES, CAST-128, AES).
  5. Lock the key: encrypt the session key with B's public key (RSA or ElGamal), attach it.
  6. Convert to radix-64 (base64) text and send.

At B, backwards: decode base64; decrypt the session key with B's private key; decrypt the bundle; decompress; hash the message and compare with the digest recovered from the signature with A's public key.

Order: sign before compressing (the signature covers the message as written, checkable without recompressing); compress before encrypting (less redundancy for cryptanalysis, less to encrypt); session key (public key encryption is slow: only the short key goes through RSA).

Services: authentication and integrity (signature); confidentiality (session key, symmetric encryption); compression (ZIP); e-mail compatibility (radix-64, mail carries 7-bit text); segmentation (long messages split and rejoined).

Keys: installing PGP makes a key pair; the private key stored encrypted under a passphrase typed at each use; public keys on websites or key servers; public key ring (others' keys) and private key ring (own pairs); web of trust: users sign each other's keys, no central authority.

S/MIME: the alternative in mail programs; same ingredients, but public keys from X.509 certificates issued by CAs.

Memory example: posting an answer sheet: sign it, fold it small, lock it in a box with a new padlock, put the padlock's only key in an envelope only the exam office can open, and write the address in plain letters.

Book's slips: it dates PGP to 1995 (released 1991); it says "MD5 or SHA for calculating the message digest such as CAST, Triple-DES or IDEA" (MD5 and SHA make the digest; CAST, 3DES, IDEA encrypt).

SSL and TLS: securing a TCP connection

PIN 3/27 Open the full card

SSL (Secure Sockets Layer, Netscape, 1995) and successor TLS (Transport Layer Security, IETF; 1.3 is RFC 8446): a layer between TCP and the application that authenticates the server (optionally the client), agrees session keys, and gives the application's data confidentiality and integrity. Needs TCP below for reliable in-order delivery. HTTPS is HTTP over TLS on port 443; SMTPS 465, IMAPS 993, or STARTTLS.

Figure: the stack (application, SSL/TLS with handshake, alert and change cipher spec over the record protocol, TCP port 443, IP) and the eight-step handshake between a browser and a bank site

Four protocols: handshake (authenticates, agrees keys); change cipher spec (switch to the new keys now); alert (warnings, fatal errors such as a bad certificate); record (carries everything).

Handshake, classic RSA form (SSL 3.0, TLS 1.2):

  1. ClientHello: supported versions, cipher suites, a client random.
  2. ServerHello: chosen version and suite, a server random.
  3. Certificate: server's public key signed by a CA; the client checks it against trusted CAs and the site name.
  4. ServerHelloDone.
  5. ClientKeyExchange: a random pre-master secret encrypted with the server's public key (only the real server decrypts it).
  6. Key derivation: master secret from the pre-master secret and both randoms; from it the session keys (encryption and MAC key each way).
  7. ChangeCipherSpec and Finished from each side; Finished is a MAC over the whole handshake, catching tampering.
  8. Application data, encrypted and authenticated by the record protocol.

Record protocol: fragment (up to 214 = 16,384 bytes); compress (optional, dropped in TLS 1.3); add a MAC (HMAC); encrypt (AES, ChaCha20); add a 5-byte header (content type, version, length). The book: fragmentation, compression, message integrity, confidentiality, framing.

Services: server authentication by certificate, optional client authentication, confidentiality (symmetric), integrity (MAC), key exchange (public key): the hybrid scheme.

VersionYearStatus
SSL 2.0, 3.01995, 1996 (Netscape)broken; prohibited (RFC 6176, RFC 7568)
TLS 1.0, 1.11999 (RFC 2246), 2006 (RFC 4346)deprecated (RFC 8996)
TLS 1.22008 (RFC 5246)in use
TLS 1.32018 (RFC 8446)current: one round trip, ephemeral DH only, no RSA key transport

Uses (book's advantages): online card payments, logins, webmail, secure file transfer (HTTPS, FTPS), SSL VPNs for remote access through a browser.

Memory example: paying an exam form fee through a digital wallet in the browser: https and a padlock; the browser checked the certificate and agreed session keys; the NTC or WorldLink line carries only ciphertext.

IPsec: AH and ESP, transport and tunnel mode

PIN 3/27 Open the full card

IPsec (IETF, RFC 4301): protocols securing the IP packets themselves, between two hosts, two routers, or a host and a router; two protocols (AH: authentication and integrity; ESP: also confidentiality), two modes (transport, tunnel), security associations set up by IKE. At the network layer it protects TCP, UDP, ICMP and routing updates without changing applications; works with IPv4 and IPv6 (AH and ESP are IPv6 extension headers).

Figure: packet layouts: original, transport with AH, transport with ESP, tunnel with ESP, tunnel with AH; shaded fields encrypted, brackets authenticated

Modes:

  • Transport mode: IPsec header between the original IP header and the transport header; protects only the payload; the original header (real addresses) travels as is; end to end, host to host.
  • Tunnel mode: the whole original packet becomes the payload of a new IP packet with a new header, usually gateway to gateway; inner addresses hidden; builds VPNs.

AH (Authentication Header), IP protocol 51: source authentication, integrity, anti-replay; no confidentiality. Fields: next header (8 bits, e.g. 6 for TCP); payload length (8, the AH's own length); reserved (16); SPI (32, names the SA like a virtual circuit number); sequence number (32, up by one per packet, against replay); authentication data (variable: integrity check value, a keyed hash over the packet with fields that change in transit, TTL and header checksum, counted as zero).

ESP (Encapsulating Security Payload), IP protocol 50: confidentiality by encryption plus authentication, integrity, anti-replay. ESP header (SPI and sequence number, 32 bits each); encrypted payload; ESP trailer (padding 0 to 255 bytes, 8-bit pad length, 8-bit next header); ESP authentication data at the end (computed in one pass on the way out). Payload and trailer encrypted; header to trailer authenticated.

PointAHESP
IP protocol number5150
Confidentialitynoyes, encryption (AES)
Integrity, source authenticationyesyes (optional)
Anti-replayyes, sequence numberyes, sequence number
Covers outer IP headeryes, fixed fieldsno
Through NATfails (NAT changes authenticated addresses)works, with UDP encapsulation
Use todayrarealmost every IPsec VPN

Security association (SA): a one-way agreement holding protocol, mode, algorithms, keys, sequence counter, replay window, lifetime; identified by SPI, destination address and protocol; two SAs for two-way traffic; stored in the security association database (SAD); the security policy database (SPD) decides per packet: protect, pass or drop.

IKE (Internet Key Exchange, IKEv2 RFC 7296): authenticates the ends (certificates or pre-shared key) and agrees fresh keys with Diffie-Hellman.

Memory example: Pokhara branch and Kathmandu head office routers in tunnel mode with ESP; packets cross the ISP as gibberish addressed router to router; staff notice nothing.

The book says AH's authentication data covers "the entire IP datagram"; fields changing in transit (TTL, header checksum) are set to zero for the calculation, and the hash is keyed (a MAC).

VPN: a private network over a public one

HOT 5/27 Open the full card

Virtual private network: a private network built over a public one (the Internet) by tunnelling: each packet encrypted and authenticated, then carried inside another packet between the VPN endpoints, so distant sites and users communicate as if on one private LAN. A leased line is secure but expensive, the Internet cheap but public; a VPN gives the privacy of the first at the price of the second (virtual: no private wires; private: no outsider reads or joins).

Figure: Kathmandu head office LAN (192.168.1.0/24) and Pokhara branch LAN (192.168.2.0/24) behind VPN gateways joined by a site-to-site IPsec tunnel across the Internet; a remote user's laptop with its own tunnel to the head office; inside a tunnel, a new IP header, ESP, the encrypted original packet

How it works:

  1. Authenticate: client or gateway proves its identity (certificate, pre-shared key, username and password with a one-time code).
  2. Agree keys: IKE for IPsec, a TLS handshake for an SSL VPN.
  3. Encapsulate: a packet for the private network is encrypted, authenticated and wrapped in a new packet addressed to the far endpoint.
  4. Cross the Internet: routers see only public endpoint addresses and ciphertext.
  5. Decapsulate: the far endpoint checks, decrypts and delivers inside its LAN; replies return the same way.
TypeJoinsExample
Remote access (host to gateway)a user's device to the organisation, via client softwarestaff at home reaching the office file server
Site to site, intranet (gateway to gateway)one organisation's sites, permanentlyhead office and branches
Site to site, extranetan organisation to a partner, limited accessa company and its supplier's ordering system

Protocols: IPsec tunnel mode with ESP (usual site to site); SSL/TLS VPNs (OpenVPN, browser portal; common for remote access); L2TP over IPsec; WireGuard (modern, small); PPTP (old, insecure).

  • Advantages: far cheaper than leased lines; confidentiality, integrity, authentication over a public network; remote users join from anywhere; sites added in software.
  • Disadvantages: encryption and extra headers cost speed and bandwidth; performance depends on the Internet; setup and keys to manage; a stolen or infected laptop with VPN access is an attacker inside.

Example: head office in Kathmandu (192.168.1.0/24) and branch in Pokhara (192.168.2.0/24), each on an ordinary ISP connection; their routers run a site-to-site IPsec VPN; a branch PC opens the accounts server at 192.168.1.10 as if down the corridor; an accountant at home in Bhaktapur uses a remote-access VPN client.

Memory example: a sealed pipe inside a public road. Consumer "VPN apps" that make a phone appear in another country use the same tunnel, from one user to the provider's server.

Securing wireless LANs: WEP, and why WPA2 replaced it

PIN 2/27 Open the full card

WEP (Wired Equivalent Privacy): security protocol of the original IEEE 802.11 (1997), meant to make a wireless LAN as private as a wired one; encrypts each frame with the RC4 stream cipher keyed by a 24-bit IV plus a shared 40 or 104-bit key, and appends a CRC-32 integrity check; broken, replaced by WPA2. Radio passes through walls, so anyone in range can capture frames. Goals: confidentiality, access control, integrity.

Figure: IV (24 bits) and shared key (40 or 104) seed RC4; the keystream is XORed with the data plus its CRC-32 ICV; the frame carries the IV in the clear, a key ID and the ciphertext; the book's example 0101 XOR 1100 = 1001

Encrypting a frame:

  1. Integrity value: CRC-32 of the data, the 32-bit ICV, appended.
  2. Seed: the 24-bit IV (meant to change per frame) in front of the shared key: 24 + 40 = 64 or 24 + 104 = 128 bits.
  3. Keystream: RC4 keyed with the seed, as long as the frame.
  4. Encrypt: data and ICV XORed with the keystream.
  5. Send: IV in the clear, a key ID, the ciphertext.

Decryption: IV from the frame plus the receiver's key, RC4, same keystream, XOR, check the CRC. Book's example: keystream 0101 XOR plaintext 1100 = 1001; XOR with 0101 again gives 1100.

Key sizes: 10 hexadecimal digits = 40 bits, with the IV "64-bit WEP"; 26 hexadecimal digits = 104 bits, "128-bit WEP". Authentication: open system (none) or shared key (a challenge encrypted with WEP, which hands an eavesdropper keystream).

Weaknesses:

  • IV too short: 24 bits, 16,777,216 keystreams; a busy access point (1500-byte frames at 11 Mbps) uses all in about 5 hours; by the birthday effect a repeat is likely after about 4,800 frames; same IV and key, same keystream: C1⊕C2=P1⊕P2.
  • Weak RC4 keys: the IV, sent in the clear and placed before the key, leaks key bytes for certain values (Fluhrer, Mantin and Shamir attack, 2001); free tools recover the key in minutes.
  • CRC-32 no integrity against an attacker: linear and keyless; flipped ciphertext bits matched by fixing the ICV; no replay protection.
  • One static key: shared by every user, rarely changed, no key management; one leak exposes everyone.
PointWEPWPAWPA2WPA3
Year, basis1997, 802.112003, Wi-Fi Alliance interim2004, IEEE 802.11i2018, Wi-Fi Alliance
CipherRC4RC4 with TKIPAES (CCMP)AES (CCMP or GCMP)
Keysstatic shared key, 24-bit IVnew key per packet, 48-bit sequence counterfresh session keys, 4-way handshakeSAE handshake, forward secrecy
Integrity, statusCRC-32; brokenMichael MIC; deprecatedCBC-MAC in CCMP; usual minimumCCMP or GCMP; current

Personal (one passphrase: pre-shared key in WPA2, SAE against offline guessing in WPA3) and Enterprise (each user logs in through IEEE 802.1X and EAP to a RADIUS server).

Memory example: a hostel router still on WEP is a locked door with the key taped to it; the fix is one setting, WPA2-AES or WPA3.

Firewalls: what they are, how they protect, their types, and router ACLs

TOP 13/27 Open the full card

Firewall: a device or program at the boundary between a trusted internal network and an untrusted one (the Internet) that examines traffic crossing it and passes or blocks each packet or connection by a security policy, its rule set. Design goals (Cheswick and Bellovin): all traffic between inside and outside passes through it; only policy-authorised traffic passes; the firewall resists penetration. Book's picture: a wall between the corporate LAN and the outside world; a valid web request passes, an invalid Telnet request bounces off.

How a firewall protects a network:

  • Single choke point: every connection crosses one place; policy enforced, attempts logged and audited.
  • Filtering by rule: blocks unwanted source addresses, ports, protocols (Telnet, file sharing, remote desktop from outside); default deny.
  • Only expected replies: stateful firewalls admit inbound packets only for connections started inside.
  • Hiding the inside: NAT shows one public address, not internal hosts and layout.
  • Content control: a proxy blocks malware, banned sites, file types, dangerous commands; can require login.
  • Containment and alerting: separates zones (DMZ), slows worms between segments, resists floods (SYN floods), alerts the administrator.

Book's reasons: stop intruders interfering with daily running (denial of service, SYN and FIN attacks), deleting or modifying information, obtaining secrets; allow only authorised access; stop illegal changes (replacing the official homepage).

Figure: layers (application, session, transport, network, data link) with the type that inspects each: application gateway, circuit-level gateway, stateful inspection, packet filter

Types, by layer inspected:

  1. Packet filtering (first generation, stateless): router or host checks each packet alone against a rule table using IP and TCP/UDP headers: source and destination IP, protocol, source and destination port, TCP flags, interface and direction; permit or deny; first match decides. Fast, cheap, invisible; but no state (a forged "reply" looks valid), no content, cannot tell spoofed sources, rule lists error-prone.
  2. Stateful inspection (dynamic packet filter): also keeps a state table of open connections (addresses, ports, TCP state); admits inbound packets only for open connections or explicit rules; an out-of-the-blue ACK is dropped; most firewalls today.
  3. Application-level gateway (proxy): application layer; the client connects to the proxy, which checks the request (URL, FTP command, mail and attachments, user) and opens a second connection to the server, relaying the reply; one proxy per service (HTTP, SMTP, FTP, DNS); most secure, full logs; slower (each connection handled twice), new applications need new proxies.
  4. Circuit-level gateway: session layer; checks the TCP handshake (and user), then relays bytes without reading them; SOCKS is the standard example; often for outgoing connections from trusted insiders.
  5. Next-generation firewall (NGFW): stateful plus deep packet inspection, application recognition whatever the port, intrusion prevention, TLS inspection, user identity.

Network firewall guards a whole network at its edge; host-based firewall (Windows Defender Firewall, Linux nftables) one machine; a home Wi-Fi router has a small stateful one.

PointPacket filterStateful inspectionApplication gateway
Layernetwork, transportnetwork, transport, with stateapplication
Decides oneach packet's headerheader plus connection statecontent and user
Speedfastestfastslowest
Securitylowestgoodhighest
Examplerouter ACLhome router, perimeter firewallfiltering HTTP proxy

Memory example, the hostel gate's chowkidar: checking each name against a list (packet filter); remembering who went out so only they come back (stateful); walking each visitor to the room and checking the bag (application gateway); checking the visitors' book once and then not watching (circuit-level).

Figure: packet filter flowchart (packet arrives, read header, rule k matches?, permit or deny, more rules?, implicit deny) with a hostel router's five rules and three traced packets

How a packet filter works:

  1. Receive a packet on an interface, inbound or outbound.
  2. Read the header: source and destination IP, protocol (TCP, UDP, ICMP), source and destination port, TCP flags.
  3. Compare with the rules, top down: each rule gives values (or "any") and an action.
  4. First match decides: forward (permit) or drop (deny); the rest is not read.
  5. No match: the implicit deny drops it.
  6. Log the denied packets.

Hostel router's rules (example): 1 deny anything from 203.0.113.0/24; 2 deny TCP 23 (Telnet) to 192.168.10.0/24; 3 permit TCP 443 to the web server 192.168.10.5; 4 permit 192.168.10.0/24 out on TCP 80 and 443; 5 deny everything else. Traces: 198.51.100.7 to 192.168.10.5:443, rules 1 and 2 miss, rule 3 permits; 203.0.113.9 to the same server, rule 1 denies first; 198.51.100.7 to 192.168.10.20:23, rule 2 denies.

Book's filter table blocks: incoming from network 121.34.0.0; incoming to any internal Telnet server (port 23); incoming to internal host 192.168.0.8; outgoing to web servers (port 80), so staff cannot browse.

Router ACLs

Access control list (ACL): ordered permit and deny statements applied to one router interface in one direction (in or out); compared top down; first match decides; every list ends in an implicit "deny any". Turns a router into a packet filtering firewall.

PointStandard ACLExtended ACL
Cisco numbers1 to 99, 1300 to 1999100 to 199, 2000 to 2699
Matchessource address onlysource, destination, protocol, ports
Placednear the destinationnear the source

Wildcard mask: the subnet mask inverted, 0 must match, 1 ignore; /24 (255.255.255.0) gives 0.0.0.255.

Blocking the paper's network 202.70.91.0/24 coming in on FastEthernet 0/0, all else passing:

Router(config)# access-list 10 deny 202.70.91.0 0.0.0.255
Router(config)# access-list 10 permit any
Router(config)# interface FastEthernet0/0
Router(config-if)# ip access-group 10 in

Extended equivalent: access-list 110 deny ip 202.70.91.0 0.0.0.255 any, access-list 110 permit ip any any, then ip access-group 110 in on FastEthernet0/0. Line 1 denies sources 202.70.91.0 to 202.70.91.255; line 2 is essential (otherwise the implicit deny drops all traffic on the interface); lines 3 and 4 apply it inbound, so packets are dropped on arrival, before routing. Check with show access-lists (match counters) and show ip interface FastEthernet0/0.

Placement: screened subnet: border router filters first, firewall second, public servers (web, mail) in a DMZ (demilitarised zone), so a hacked web server is still outside the trusted LAN; simpler set-ups: a single screening router, or a dual-homed host.

Figure: Internet, border router (ACL), firewall (stateful or NGFW), a DMZ with web and mail servers, the trusted LAN with PCs and a database server, a NIDS sensor on a mirror port, HIDS on the servers

Limits: cannot stop traffic going around it (a phone's mobile hotspot, an infected USB drive), insiders, malware in allowed or encrypted traffic without deeper inspection, or phishing; an IDS watches behind it.

The book's table is captioned "Figure 2.26" in chapter 8 (between figures 8.25 and 8.27).

Intrusion detection systems

PIN 1/27 Open the full card

Intrusion detection system (IDS): a device or program that monitors a network or its hosts for malicious activity or policy violations and raises an alert, to an administrator or a SIEM (security information and event management) system. An IDS detects and reports; an intrusion prevention system (IPS) sits in the traffic's path and also blocks. A firewall decides at the gate by rules; attacks inside allowed traffic (an exploit to the web server's port 443), insiders and unforeseen attacks pass, and the IDS watches what gets past.

PointNetwork IDS (NIDS)Host IDS (HIDS)
Placedkey points (behind the firewall, in the DMZ), fed by a mirror (SPAN) port or tapon each protected host, as an agent
Watchespackets of a whole segmentthe host's traffic, logs, processes, system files
Catchesscans, floods, exploits on the wirechanged or deleted system files, logins, malware
Missesencrypted payloads, other segmentsother hosts; disabled by an attacker owning the host
ExamplesSnort, Suricata, ZeekOSSEC, Wazuh, Tripwire
  • Signature-based (misuse): matches known attack patterns like antivirus signatures; few false alarms, clear explanation; blind to new (zero-day) attacks until a signature exists; constant updates.
  • Anomaly-based: a baseline of normal behaviour (volumes, ports, login times), deviations flagged; can catch new attacks; more false alarms; needs a training period.

Example signature (Snort): alert tcp any any -> 192.168.10.0/24 23 (msg:"Telnet attempt"; sid:1000001; rev:1;).

The book splits NIDS by timing: on-line (real time) and off-line (stored data afterwards); a HIDS snapshots critical system files and alerts when a later snapshot shows a change or deletion.

Alerts: true positive (real attack flagged); false positive (alarm on harmless activity; too many and staff stop reading); false negative (attack missed, the worst case).

PointFirewallIDSIPS
Joballow or block by policydetect and alertdetect and block
Positioninline, at the boundarybeside the traffic (a copy)inline
Effect on trafficpasses or dropsnonedrops attack packets

Figure: the network placement drawing again: NIDS on the LAN switch's mirror port, HIDS on the servers

Memory example: the firewall is the hostel gate's chowkidar; the IDS is the corridor CCTV, which records and alerts the warden but stops no one; the IPS is a guard who also steps in when the camera spots trouble.

49 calculations from 25 of the 27 sittings · 19 more the Insights book works · grouped by method

Numericals

Every calculation the board papers have set, worked in full and grouped by the method it needs, with the method once at the top of each group; then the examples the Insights book works that no paper has set yet. Every number is recomputed when the page is built, so none of them is typed.

How to use this page

  • Learn the method, then the numbers do not matter: the same methods come back with new values.
  • Write the given values first, then the formula, then the substitution, then the answer in bold with its unit. The working is what earns the marks.
  • Where a paper is misprinted, the reading used is stated above the solution rather than assumed.

Throughput: the data actually delivered per second PIN 2/27

Ch 2 · Physical layer2 from 2 of the 27 sittings

The method
  1. Find the amount of data actually delivered, in bits (1 byte = 8 bits).
  2. Find the time it took, in seconds (1 minute = 60 s).
  3. Divide the data delivered by the time taken: T=Dt, in bits per second.
  4. Compare with the bandwidth: utilization = throughput / bandwidth, never above 100 %.
2080 Bhadra · Q22 marksIf a file of 1000 bytes was sent over a network in 2 seconds, calculate throughput.

Given: data delivered = 1,000 bytes; time taken t = 2 s.

In bits: 1,000 bytes × 8 = 8,000 bits.

Throughput=data deliveredtime=8,000 bits2 s=4,000 bps

In bytes the same rate is 1,000 / 2 = 500 bytes per second.

Answer: throughput = 4,000 bps = 4 kbps (500 bytes per second).

2078 Bhadra · Q23 marksA network with bandwidth of 20 Mbps can pass only an average of 18,000 frames per minute with each frame carrying an average of 20,000 bits. Calculate the throughput of this network.

Given: bandwidth = 20 Mbps; 18,000 frames per minute; 20,000 bits per frame.

Bits delivered in one minute: 18,000 × 20,000 = 360,000,000 bits.

Per second (1 minute = 60 s):

Throughput=18,000×20,00060=360,000,00060=6,000,000 bps=6 Mbps

Compared with the bandwidth: 6 / 20 = 0.3, so the network delivers only 30 % of its 20 Mbps capacity.

Answer: throughput = 6 Mbps, 30 % of the bandwidth.

Channel capacity: SNR and the Shannon limit PIN 1/27

Ch 2 · Physical layer1 from 1 of the 27 sittings

The method
  1. Put the signal and noise powers in the same unit, then SNR=S/N, a plain ratio.
  2. In decibels: SNRdB=10log10(S/N).
  3. Shannon capacity: C=Blog2(1+SNR), with B in hertz and SNR as a ratio, never in dB.
  4. On a calculator, log2x=log10x/log102.
2066 Bhadra · Q2b4+4 marksCalculate SNR and maximum channel capacity of a cat6 channel having bandwidth 300 MHz with 2mW and 200 μW as signal and noise power respectively.

How this is readCat 6 cable is specified up to 250 MHz (Cat 6A to 500 MHz); the 300 MHz given is used as set.

Given: bandwidth B = 300 MHz = 3×108 Hz; signal power S = 2 mW; noise power N = 200 µW = 0.2 mW.

1. SNR, with both powers in milliwatts:

SNR=SN=2 mW0.2 mW=10
SNRdB=10log1010=10 dB

2. Maximum channel capacity (Shannon), with SNR as a ratio:

C=Blog2(1+SNR)=3×108×log211
log211=log1011log102=1.04140.301=3.4594
C=3×108×3.4594=1,037,829,486 bps≈1.04 Gbps

Answer: SNR = 10 (10 dB); maximum channel capacity = 1.04 Gbps (about 1,037.8 Mbps).

CRC by modulo-2 division PIN 3/27

Ch 3 · Data link layer3 from 3 of the 27 sittings

The method
  1. Write the generator G(x) as bits (a coefficient for every power, 0s included); its degree r is one less than its number of bits.
  2. Append r zeros to the message M.
  3. Divide by the generator in modulo 2: wherever the leading bit is 1, XOR the generator under it; where it is 0, XOR zeros; bring down the next bit each time.
  4. The last r bits are the remainder R, the CRC (keep its leading 0s).
  5. Transmit M followed by R; it divides by G(x) with remainder 0.
  6. At the receiver, divide what arrived by the same G(x): remainder 0 means accept; any other remainder means an error is detected.
2082 Baishakh · Q35 marksCalculate the CRC for a 8 bit sequence 11001101. The generator polynomial is x⁴ + x² + 1. Also find the transmitted bit frame.

Given: message 11001101 (8 bits), generator G(x)=x4+x2+1.

Generator as bits: 1·x4+0·x3 +1·x2+0·x+1 = 10101, degree r=4, so 4 zeros are appended: dividend 110011010000.

Modulo-2 division:

            11111101   quotient
10101 ) 110011010000
        10101
        -----
         11001
         10101
         -----
          11000
          10101
          -----
           11011
           10101
           -----
            11100
            10101
            -----
             10010
             10101
             -----
              01110
              00000
              -----
               11100
               10101
               -----
                1001   remainder

CRC (remainder, 4 bits) = 1001.

Check at the receiver: 110011011001 divided by 10101:

            11111101   quotient
10101 ) 110011011001
        10101
        -----
         11001
         10101
         -----
          11000
          10101
          -----
           11011
           10101
           -----
            11101
            10101
            -----
             10000
             10101
             -----
              01010
              00000
              -----
               10101
               10101
               -----
                0000   remainder

The remainder is 0000, so the frame is accepted.

Answer: CRC = 1001; transmitted frame = 110011011001 (the message followed by the CRC).

2081 Bhadra · Q35 marksCalculate the CRC for a 10 bit sequence 1010001101. The generator polynomial is x⁵ + x⁴ + x² + 1. Also find the transmitted bit frame.

Given: message 1010001101 (10 bits), generator G(x)=x5+x4+x2+1.

Generator as bits: x5+x4+0·x3 +x2+0·x+1 = 110101, degree r=5; append 5 zeros: dividend 101000110100000.

Modulo-2 division:

              1101010110   quotient
110101 ) 101000110100000
         110101
         ------
          111011
          110101
          ------
           011101
           000000
           ------
            111010
            110101
            ------
             011111
             000000
             ------
              111110
              110101
              ------
               010110
               000000
               ------
                101100
                110101
                ------
                 110010
                 110101
                 ------
                  001110
                  000000
                  ------
                   01110   remainder

CRC (remainder, 5 bits, the leading 0 kept) = 01110.

Check at the receiver: 101000110101110 divided by 110101:

              1101010110   quotient
110101 ) 101000110101110
         110101
         ------
          111011
          110101
          ------
           011101
           000000
           ------
            111010
            110101
            ------
             011111
             000000
             ------
              111110
              110101
              ------
               010111
               000000
               ------
                101111
                110101
                ------
                 110101
                 110101
                 ------
                  000000
                  000000
                  ------
                   00000   remainder

The remainder is 00000: no error, the frame is accepted.

Answer: CRC = 01110; transmitted frame = 101000110101110.

2080 Bhadra · Q35 marksGiven message is M (x) = x7 + x4 +x3 +x2 + 1 and the generator is G (x) = x3 + 1. Show the actual bit string transmitted, suppose the third bit from the left is inverted during the transmission. Show how the error is detected at the receiver's end.

How this is readThe powers are printed on the line (x7, x4, x3, x2, x3); they are read as x7,x4,x3,x2 and x3.

Given: M(x)=x7+x4 +x3+x2+1, G(x)=x3+1.

As bits: M(x) has the powers 7, 4, 3, 2 and 0, so 10011101; G(x) = 1001, degree r=3. Append 3 zeros: dividend 10011101000.

Modulo-2 division at the sender:

          10001100   quotient
1001 ) 10011101000
       1001
       ----
        0001
        0000
        ----
         0011
         0000
         ----
          0110
          0000
          ----
           1101
           1001
           ----
            1000
            1001
            ----
             0010
             0000
             ----
              0100
              0000
              ----
               100   remainder

CRC = 100, so the bit string transmitted is 10011101100.

The error: the third bit from the left is inverted (0 becomes 1), so the receiver gets 10111101100.

Detection at the receiver: it divides the received string by the same generator:

          10101000   quotient
1001 ) 10111101100
       1001
       ----
        0101
        0000
        ----
         1011
         1001
         ----
          0100
          0000
          ----
           1001
           1001
           ----
            0001
            0000
            ----
             0010
             0000
             ----
              0100
              0000
              ----
               100   remainder, not zero

The remainder is 100, not zero, so the receiver knows the frame is damaged, discards it and the frame is retransmitted. (Without the error the remainder would be 000.)

Answer: transmitted 10011101100; received 10111101100; remainder 100 ≠ 0, so the error is detected.

Bit stuffing PIN 3/27

Ch 3 · Data link layer3 from 3 of the 27 sittings, 1 from the book

The method
  1. Scan the data from the left, counting consecutive 1s.
  2. After every run of five 1s, insert (stuff) a 0 and start counting again; a 0 in the data also resets the count.
  3. The flag 01111110 is added at both ends of the frame, if the question asks for the frame.
  4. Check: the receiver deletes the 0 after every five 1s and must get the data back.
2075 Ashwin · Q32 marksA bit string 01111011111101111110 needs to be transmitted at the data link layer. What is the string actually transmitted after bit stuffing?

Given: the bit string 01111011111101111110 (20 bits). Rule: after every five consecutive 1s, the sender stuffs a 0.

Working: split the string into runs; every run of five 1s gets a stuffed 0 after it (shown as [0]):

data            01111011111101111110
runs            0 1111 0 111111 0 111111 0
stuffed ([0])   0 1111 0 11111[0]1 0 11111[0]1 0
sent            0111101111101011111010

2 bits are stuffed, so 22 bits are sent. Check: the receiver deletes the 0 after each run of five 1s and gets 01111011111101111110 back; six 1s in a row now occur only in the flag.

Answer: the string actually transmitted is 0111101111101011111010.

2070 Chaitra · Q33 marksA bit string 01111011111011111110 needs to be transmitted at the data link layer what is string actually transmitted after bit stuffing, if flag patterns is 01111110.

Given: the bit string 01111011111011111110 (20 bits), flag 01111110. Rule: after every five consecutive 1s, the sender stuffs a 0.

Working: split the string into runs; every run of five 1s gets a stuffed 0 after it (shown as [0]):

data            01111011111011111110
runs            0 1111 0 11111 0 1111111 0
stuffed ([0])   0 1111 0 11111[0] 0 11111[0]11 0
sent            0111101111100111110110
frame           01111110 0111101111100111110110 01111110

2 bits are stuffed, so 22 bits are sent. Check: the receiver deletes the 0 after each run of five 1s and gets 01111011111011111110 back; six 1s in a row now occur only in the flag.

Answer: the string actually transmitted is 0111101111100111110110, and the whole frame with its flags is 01111110 0111101111100111110110 01111110.

2068 Baishakh · Q102 marksA bit string 0111101111101111110 needs to be transmitted at the data link layer. What is the string actually transmitted after bit stuffing?

Given: the bit string 0111101111101111110 (19 bits). Rule: after every five consecutive 1s, the sender stuffs a 0.

Working: split the string into runs; every run of five 1s gets a stuffed 0 after it (shown as [0]):

data            0111101111101111110
runs            0 1111 0 11111 0 111111 0
stuffed ([0])   0 1111 0 11111[0] 0 11111[0]1 0
sent            011110111110011111010

2 bits are stuffed, so 21 bits are sent. Check: the receiver deletes the 0 after each run of five 1s and gets 0111101111101111110 back; six 1s in a row now occur only in the flag.

Answer: the string actually transmitted is 011110111110011111010.

Insights on Computer Networks, p. 59Find the data stream sent after framing with the flag 01111110 and bit stuffing, for the data 01001111110111110.

Given: the bit string 01001111110111110 (17 bits), flag 01111110. Rule: after every five consecutive 1s, the sender stuffs a 0.

Working: split the string into runs; every run of five 1s gets a stuffed 0 after it (shown as [0]):

data            01001111110111110
runs            0 1 00 111111 0 11111 0
stuffed ([0])   0 1 00 11111[0]1 0 11111[0] 0
sent            0100111110101111100
frame           01111110 0100111110101111100 01111110

2 bits are stuffed, so 19 bits are sent. Check: the receiver deletes the 0 after each run of five 1s and gets 01001111110111110 back; six 1s in a row now occur only in the flag.

Answer: the string actually transmitted is 0100111110101111100, and the whole frame with its flags is 01111110 0100111110101111100 01111110.

ALOHA throughput and its maximum PIN 1/27

Ch 3 · Data link layer1 from 1 of the 27 sittings

The method
  1. Take G as the mean number of frames offered per frame time, Poisson-distributed: P(k)=Gke−G/k!.
  2. A frame succeeds only if no other frame starts in its vulnerable time: one frame time (one slot) for slotted ALOHA, two for pure ALOHA.
  3. Throughput S = G times that probability: S=Ge−G (slotted), S=Ge−2G (pure).
  4. Set dS/dG=0 for the best load, and substitute it back for the maximum.
2068 Baishakh · Q24 marksCalculate the efficiency of slotted Aloha.

Given: slotted ALOHA: time is divided into slots of one frame time T, and frames are sent only at the start of a slot. Let G be the mean number of frames (new and retransmitted) offered per slot, Poisson-distributed:

P(k frames in a slot)=Gke−Gk!

Success: a frame gets through only if no other frame is sent in the same slot (the vulnerable time is one slot):

P(success)=P(0 other frames)=e−G

Throughput (successful frames per slot, the efficiency):

S=GP(success)=Ge−G

Maximum: differentiate and set to zero:

dSdG=e−G−Ge−G=e−G(1−G)=0⇒G=1

(The second derivative e−G(G−2) is negative at G=1, so this is a maximum.)

Smax=1×e−1=1e=0.3679

For contrast, pure ALOHA: the vulnerable time is two frame times, so S=Ge−2G; dS/dG=e−2G(1−2G)=0 gives G=0.5 and Smax=1/(2e) = 0.1839, about 18.4 %.

At G=1 in slotted ALOHA, 36.8 % of the slots carry a good frame, 36.8 % are empty (e−1) and 26.4 % hold collisions.

Answer: the maximum efficiency of slotted ALOHA is 1/e = 0.3679, about 36.8 %, reached when G=1 frame per slot: twice that of pure ALOHA (18.4 %).

The one's complement checksum BOOK

Ch 3 · Data link layernot set by a paper yet, 1 from the book

The method
  1. Divide the data into k segments of m bits.
  2. Add the segments in one's complement arithmetic: a carry out of the top bit is wrapped round and added to the bottom bit.
  3. The checksum is the complement (every bit inverted) of the sum; send it with the data.
  4. The receiver adds all the segments and the checksum the same way; if the complement of that sum is all 0s, it accepts the data.
Insights on Computer Networks, p. 65Compute the checksum of the data 10011001 11100010 00100100 10000100 (k = 4 segments of m = 8 bits), and check it at the receiver.

Given: data 10011001 11100010 00100100 10000100, k=4 segments of m=8 bits.

Sender: add the segments in one's complement arithmetic (a carry out of the 8th bit is added back at the bottom):

  10011001
+ 11100010  = 101111011  wrap: 01111100
+ 00100100  = 10100000
+ 10000100  = 100100100  wrap: 00100101

Sum = 00100101; checksum = its complement = 11011010.

Receiver: add the four segments and the checksum: 00100101 + 11011010 = 11111111; complement = 00000000, all zeros, so the data is accepted.

Answer: checksum 11011010; at the receiver the complemented sum is 00000000: accept.

The Hamming (7,4) code: finding and correcting one wrong bit BOOK

Ch 3 · Data link layernot set by a paper yet, 1 from the book

The method
  1. Write the 7 received bits as D7 D6 D5 P4 D3 P2 P1.
  2. Check each parity group (even parity): C1 over positions 1, 3, 5, 7; C2 over 2, 3, 6, 7; C4 over 4, 5, 6, 7. An even number of 1s gives 0, an odd number gives 1.
  3. Read the syndrome C4C2C1 as a binary number: 0 means no error; otherwise it is the position of the wrong bit.
  4. Flip that bit to get the corrected codeword; the data bits are D7 D6 D5 D3.
Insights on Computer Networks, pp. 69 and 70A seven-bit Hamming code is received as 1110111. Find the correct code.

How this is readInsights finds the syndrome 100 = 4 and stops at "the 4th bit in the codeword is incorrect"; it never writes the corrected code the example asks for. It is 1111111.

Given: received 7-bit Hamming code 1110111, even parity, laid out as:

D7 D6 D5 P4 D3 P2 P1
1  1  1  0  1  1  1

Parity checks (P1 checks 1, skips 1; P2 checks 2, skips 2; P4 checks 4, skips 4):

C1: D7 D5 D3 P1 = 1111  4 ones, even: 0
C2: D7 D6 D3 P2 = 1111  4 ones, even: 0
C4: D7 D6 D5 P4 = 1110  3 ones, odd: 1

Syndrome C4C2C1 = 100 = 4, so bit 4 (P4) is wrong. Flip it: 0 becomes 1.

Answer: the correct code is 1111111, carrying the data bits D7 D6 D5 D3 = 1111. All three checks on 1111111 give 0.

VLSM: a subnet sized to each department, minimum wastage TOP 21/27

Ch 4 · Network layer21 from 21 of the 27 sittings, 7 from the book

The method
  1. Find the block: AND the given address with its mask; an address with host bits set stands for its network. A /p block holds 232−p addresses.
  2. Size each subnet: for H hosts take the smallest block of 2h addresses with 2h≥H+2 (the network and broadcast addresses carry no host); its prefix is /(32−h). A point-to-point link has 2 hosts, so it takes a /30.
  3. Check the fit: the block sizes must add up to no more than the given block; if they do not, state it and name the smallest block that does fit.
  4. Allocate largest first (equal host counts keep the order given) from the start of the block, each subnet starting where the previous one ends; a block of 2h then always starts on a multiple of 2h.
  5. Fill each row: network = its first address; broadcast = network + 2h−1; usable hosts from network + 1 to broadcast - 1; mask from the prefix; wasted = 2h−2−H.
  6. State what is left: the unused range after the last subnet, kept for growth.
2082 Bhadra · Q58 marksSuppose a company XYZ has an IP address of 160.24.96.0/21 and it has 6 departments containing 1024, 750, 254, 500, 151 and 45 users and also include point-point links. List out the CIDR, network address, broadcast address, usable host range and wasted IP address in each subnet.

How this is readAs printed the design cannot fit. The 1,024-user department needs 1,024 + 2 = 1,026 addresses, so it needs a /21 (2,048) and fills 160.24.96.0/21 by itself; the other five departments and their links need 2,132 more. All of it needs 4,180 addresses, more than even a /20 (4,096). The block is therefore read as 160.24.96.0/19 (8,192 addresses; 96 is a multiple of 32, so it is a valid /19 network), whose first /21 is exactly the printed block. The number of point-to-point links is not printed: 5 are taken, the fewest that join 6 department routers, and each further link takes the next /30 from the unused range.

Given: block 160.24.96.0/21 (2,048 addresses, 160.24.96.0 to 160.24.103.255); users: Dept 1 1,024, Dept 2 750, Dept 3 254, Dept 4 500, Dept 5 151, Dept 6 45; 5 point-to-point links (Link 1, Link 2, Link 3, Link 4, Link 5), 2 hosts each.

Step 1, size each subnet (largest first; a block of 2h addresses holds 2h−2 hosts):

SubnetHosts HH + 2hBlock 2hPrefixMask
Dept 11,0241,026112,048/21255.255.248.0
Dept 2750752101,024/22255.255.252.0
Dept 45005029512/23255.255.254.0
Dept 32542568256/24255.255.255.0
Dept 51511538256/24255.255.255.0
Dept 64547664/26255.255.255.192
Link 12424/30255.255.255.252
Link 22424/30255.255.255.252
Link 32424/30255.255.255.252
Link 42424/30255.255.255.252
Link 52424/30255.255.255.252

Step 2, check the fit: 2,048 + 1,024 + 512 + 256 + 256 + 64 + 4 + 4 + 4 + 4 + 4 = 4,180 addresses are needed. The printed /21 holds only 2,048, and the 1,024 users alone fill it (a /22 holds only 1,022 hosts); a /20 holds 4,096, still 84 short. The smallest block that holds the design is a /19 of 8,192 addresses, 160.24.96.0/19 (160.24.96.0 to 160.24.127.255), which leaves 4,012 to spare.

Step 3, allocate from 160.24.96.0, each subnet starting where the previous one ends:

SubnetHostsNetwork (CIDR)Subnet maskUsable host rangeBroadcastWasted
Dept 11,024160.24.96.0/21255.255.248.0160.24.96.1 to 160.24.103.254160.24.103.2551,022
Dept 2750160.24.104.0/22255.255.252.0160.24.104.1 to 160.24.107.254160.24.107.255272
Dept 4500160.24.108.0/23255.255.254.0160.24.108.1 to 160.24.109.254160.24.109.25510
Dept 3254160.24.110.0/24255.255.255.0160.24.110.1 to 160.24.110.254160.24.110.2550
Dept 5151160.24.111.0/24255.255.255.0160.24.111.1 to 160.24.111.254160.24.111.255103
Dept 645160.24.112.0/26255.255.255.192160.24.112.1 to 160.24.112.62160.24.112.6317
Link 12160.24.112.64/30255.255.255.252160.24.112.65 to 160.24.112.66160.24.112.670
Link 22160.24.112.68/30255.255.255.252160.24.112.69 to 160.24.112.70160.24.112.710
Link 32160.24.112.72/30255.255.255.252160.24.112.73 to 160.24.112.74160.24.112.750
Link 42160.24.112.76/30255.255.255.252160.24.112.77 to 160.24.112.78160.24.112.790
Link 52160.24.112.80/30255.255.255.252160.24.112.81 to 160.24.112.82160.24.112.830

Unused range: 160.24.112.84 to 160.24.127.255 (4,012 addresses), kept for growth.

Wasted in all: 1,424 addresses inside the subnets, most of it in the 1,024-user /21 (1,022).

Answer: Dept 1 160.24.96.0/21, Dept 2 160.24.104.0/22, Dept 4 160.24.108.0/23, Dept 3 160.24.110.0/24, Dept 5 160.24.111.0/24, Dept 6 160.24.112.0/26, Link 1 160.24.112.64/30, Link 2 160.24.112.68/30, Link 3 160.24.112.72/30, Link 4 160.24.112.76/30, Link 5 160.24.112.80/30; the CIDR, network, broadcast, usable range and wasted count of each are in the table.

2082 Baishakh · Q57 marksYou have to assign addresses to four departmental LANs with following hosts 14, 55, 10 and 29 addresses respectively from the given IP address block: 202.97.43.0/25. Perform the subnetting and find out subnet mask, network address, broadcast address and usable host IP ranges.

Given: block 202.97.43.0/25 (128 addresses, 202.97.43.0 to 202.97.43.127); hosts: LAN 1 14, LAN 2 55, LAN 3 10, LAN 4 29.

Step 1, size each subnet (largest first; a block of 2h addresses holds 2h−2 hosts):

SubnetHosts HH + 2hBlock 2hPrefixMask
LAN 25557664/26255.255.255.192
LAN 42931532/27255.255.255.224
LAN 11416416/28255.255.255.240
LAN 31012416/28255.255.255.240

Step 2, check the fit: 64 + 32 + 16 + 16 = 128 addresses are needed and the /25 holds 128, so it fits exactly.

Step 3, allocate from 202.97.43.0, each subnet starting where the previous one ends:

SubnetHostsNetwork (CIDR)Subnet maskUsable host rangeBroadcastWasted
LAN 255202.97.43.0/26255.255.255.192202.97.43.1 to 202.97.43.62202.97.43.637
LAN 429202.97.43.64/27255.255.255.224202.97.43.65 to 202.97.43.94202.97.43.951
LAN 114202.97.43.96/28255.255.255.240202.97.43.97 to 202.97.43.110202.97.43.1110
LAN 310202.97.43.112/28255.255.255.240202.97.43.113 to 202.97.43.126202.97.43.1274

Unused range: none; the block is used exactly.

Answer: LAN 2 202.97.43.0/26, LAN 4 202.97.43.64/27, LAN 1 202.97.43.96/28, LAN 3 202.97.43.112/28; masks, broadcasts and usable ranges as in the table.

2081 Bhadra · Q57 marksPerform the subnetting of IPv4 address block 200.74.20.0/24 for five different departments having 4, 54, 120, 12 and 30 hosts. List out the network address, broadcast address, usable host range and wasted IP address in each subnet.

Given: block 200.74.20.0/24 (256 addresses, 200.74.20.0 to 200.74.20.255); hosts: Dept 1 4, Dept 2 54, Dept 3 120, Dept 4 12, Dept 5 30.

Step 1, size each subnet (largest first; a block of 2h addresses holds 2h−2 hosts):

SubnetHosts HH + 2hBlock 2hPrefixMask
Dept 31201227128/25255.255.255.128
Dept 25456664/26255.255.255.192
Dept 53032532/27255.255.255.224
Dept 41214416/28255.255.255.240
Dept 14638/29255.255.255.248

Step 2, check the fit: 128 + 64 + 32 + 16 + 8 = 248 addresses are needed and the /24 holds 256, so it fits, with 8 addresses to spare.

Step 3, allocate from 200.74.20.0, each subnet starting where the previous one ends:

SubnetHostsNetwork (CIDR)Subnet maskUsable host rangeBroadcastWasted
Dept 3120200.74.20.0/25255.255.255.128200.74.20.1 to 200.74.20.126200.74.20.1276
Dept 254200.74.20.128/26255.255.255.192200.74.20.129 to 200.74.20.190200.74.20.1918
Dept 530200.74.20.192/27255.255.255.224200.74.20.193 to 200.74.20.222200.74.20.2230
Dept 412200.74.20.224/28255.255.255.240200.74.20.225 to 200.74.20.238200.74.20.2392
Dept 14200.74.20.240/29255.255.255.248200.74.20.241 to 200.74.20.246200.74.20.2472

Unused range: 200.74.20.248 to 200.74.20.255 (8 addresses), kept for growth.

Answer: Dept 3 200.74.20.0/25, Dept 2 200.74.20.128/26, Dept 5 200.74.20.192/27, Dept 4 200.74.20.224/28, Dept 1 200.74.20.240/29; wasted 18 addresses in all inside the subnets.

2080 Bhadra · Q48 marksSuppose a company has IP address of 10.20.30.0/24 and it has 4 LANs containing 4,64,24,18 number of hosts. Also, there are 4 WAN links to connect LAN1 - LAN2, LAN2 - LAN3, LAN3 - LAN4 and LAN1 - LAN3. List out the subnet wasted IP addresses for each LAN.

How this is read"List out the subnet wasted IP addresses" is read as: list each subnet and its wasted addresses. LAN1 to LAN4 are the LANs in the order given; each WAN link joins two LAN routers and takes a /30.

Given: block 10.20.30.0/24 (256 addresses, 10.20.30.0 to 10.20.30.255); hosts: LAN1 4, LAN2 64, LAN3 24, LAN4 18; 4 point-to-point links (LAN1-LAN2, LAN2-LAN3, LAN3-LAN4, LAN1-LAN3), 2 hosts each.

The trap: 64 hosts need 64 + 2 = 66 addresses, but a /26 holds only 62 hosts, so LAN2 needs a /25 and wastes 62.

Step 1, size each subnet (largest first; a block of 2h addresses holds 2h−2 hosts):

SubnetHosts HH + 2hBlock 2hPrefixMask
LAN264667128/25255.255.255.128
LAN32426532/27255.255.255.224
LAN41820532/27255.255.255.224
LAN14638/29255.255.255.248
LAN1-LAN22424/30255.255.255.252
LAN2-LAN32424/30255.255.255.252
LAN3-LAN42424/30255.255.255.252
LAN1-LAN32424/30255.255.255.252

Step 2, check the fit: 128 + 32 + 32 + 8 + 4 + 4 + 4 + 4 = 216 addresses are needed and the /24 holds 256, so it fits, with 40 addresses to spare.

Step 3, allocate from 10.20.30.0, each subnet starting where the previous one ends:

SubnetHostsNetwork (CIDR)Subnet maskUsable host rangeBroadcastWasted
LAN26410.20.30.0/25255.255.255.12810.20.30.1 to 10.20.30.12610.20.30.12762
LAN32410.20.30.128/27255.255.255.22410.20.30.129 to 10.20.30.15810.20.30.1596
LAN41810.20.30.160/27255.255.255.22410.20.30.161 to 10.20.30.19010.20.30.19112
LAN1410.20.30.192/29255.255.255.24810.20.30.193 to 10.20.30.19810.20.30.1992
LAN1-LAN2210.20.30.200/30255.255.255.25210.20.30.201 to 10.20.30.20210.20.30.2030
LAN2-LAN3210.20.30.204/30255.255.255.25210.20.30.205 to 10.20.30.20610.20.30.2070
LAN3-LAN4210.20.30.208/30255.255.255.25210.20.30.209 to 10.20.30.21010.20.30.2110
LAN1-LAN3210.20.30.212/30255.255.255.25210.20.30.213 to 10.20.30.21410.20.30.2150

Unused range: 10.20.30.216 to 10.20.30.255 (40 addresses), kept for growth.

Answer: LAN2 10.20.30.0/25, LAN3 10.20.30.128/27, LAN4 10.20.30.160/27, LAN1 10.20.30.192/29, LAN1-LAN2 10.20.30.200/30, LAN2-LAN3 10.20.30.204/30, LAN3-LAN4 10.20.30.208/30, LAN1-LAN3 10.20.30.212/30; wasted per LAN: LAN2 62, LAN3 6, LAN4 12, LAN1 2.

2080 Baishakh · Q58 marksSuppose a company has IP address of 200.80.40.0/24 with 5 departments containing 29, 5, 16, 43, 14, number of hosts. Also there are point to point links between the departments. List out the subnet mask, network address, broadcast address, usable host IP ranges and no. of wasted IP addresses for each subnet.

How this is readThe number of point-to-point links is not printed: 4 are taken, the fewest that join 5 department routers (a chain or a tree); each further link takes the next /30 from the unused range.

Given: block 200.80.40.0/24 (256 addresses, 200.80.40.0 to 200.80.40.255); hosts: Dept 1 29, Dept 2 5, Dept 3 16, Dept 4 43, Dept 5 14; 4 point-to-point links (Link 1, Link 2, Link 3, Link 4), 2 hosts each.

Step 1, size each subnet (largest first; a block of 2h addresses holds 2h−2 hosts):

SubnetHosts HH + 2hBlock 2hPrefixMask
Dept 44345664/26255.255.255.192
Dept 12931532/27255.255.255.224
Dept 31618532/27255.255.255.224
Dept 51416416/28255.255.255.240
Dept 25738/29255.255.255.248
Link 12424/30255.255.255.252
Link 22424/30255.255.255.252
Link 32424/30255.255.255.252
Link 42424/30255.255.255.252

Step 2, check the fit: 64 + 32 + 32 + 16 + 8 + 4 + 4 + 4 + 4 = 168 addresses are needed and the /24 holds 256, so it fits, with 88 addresses to spare.

Step 3, allocate from 200.80.40.0, each subnet starting where the previous one ends:

SubnetHostsNetwork (CIDR)Subnet maskUsable host rangeBroadcastWasted
Dept 443200.80.40.0/26255.255.255.192200.80.40.1 to 200.80.40.62200.80.40.6319
Dept 129200.80.40.64/27255.255.255.224200.80.40.65 to 200.80.40.94200.80.40.951
Dept 316200.80.40.96/27255.255.255.224200.80.40.97 to 200.80.40.126200.80.40.12714
Dept 514200.80.40.128/28255.255.255.240200.80.40.129 to 200.80.40.142200.80.40.1430
Dept 25200.80.40.144/29255.255.255.248200.80.40.145 to 200.80.40.150200.80.40.1511
Link 12200.80.40.152/30255.255.255.252200.80.40.153 to 200.80.40.154200.80.40.1550
Link 22200.80.40.156/30255.255.255.252200.80.40.157 to 200.80.40.158200.80.40.1590
Link 32200.80.40.160/30255.255.255.252200.80.40.161 to 200.80.40.162200.80.40.1630
Link 42200.80.40.164/30255.255.255.252200.80.40.165 to 200.80.40.166200.80.40.1670

Unused range: 200.80.40.168 to 200.80.40.255 (88 addresses), kept for growth.

Answer: Dept 4 200.80.40.0/26, Dept 1 200.80.40.64/27, Dept 3 200.80.40.96/27, Dept 5 200.80.40.128/28, Dept 2 200.80.40.144/29, Link 1 200.80.40.152/30, Link 2 200.80.40.156/30, Link 3 200.80.40.160/30, Link 4 200.80.40.164/30; masks, ranges, broadcasts and wasted counts as in the table.

2079 Bhadra · Q58 marksAn ISP provided you an IP address block of 172.24.96.0/21. Suppose you need to divide this for four different departments A, B, C and D having 750, 200, 500 and 45 hosts respectively with minimum wastage of IP addresses. Also allocate IP addresses for three point-to-point links in the network. Find out the network address, broadcast address, subnet mash and usable host range of IP addresses for each subnet.

How this is read"subnet mash" is read as subnet mask.

Given: block 172.24.96.0/21 (2,048 addresses, 172.24.96.0 to 172.24.103.255); hosts: A 750, B 200, C 500, D 45; 3 point-to-point links (Link 1, Link 2, Link 3), 2 hosts each.

Step 1, size each subnet (largest first; a block of 2h addresses holds 2h−2 hosts):

SubnetHosts HH + 2hBlock 2hPrefixMask
A750752101,024/22255.255.252.0
C5005029512/23255.255.254.0
B2002028256/24255.255.255.0
D4547664/26255.255.255.192
Link 12424/30255.255.255.252
Link 22424/30255.255.255.252
Link 32424/30255.255.255.252

Step 2, check the fit: 1,024 + 512 + 256 + 64 + 4 + 4 + 4 = 1,868 addresses are needed and the /21 holds 2,048, so it fits, with 180 addresses to spare.

Step 3, allocate from 172.24.96.0, each subnet starting where the previous one ends:

SubnetHostsNetwork (CIDR)Subnet maskUsable host rangeBroadcastWasted
A750172.24.96.0/22255.255.252.0172.24.96.1 to 172.24.99.254172.24.99.255272
C500172.24.100.0/23255.255.254.0172.24.100.1 to 172.24.101.254172.24.101.25510
B200172.24.102.0/24255.255.255.0172.24.102.1 to 172.24.102.254172.24.102.25554
D45172.24.103.0/26255.255.255.192172.24.103.1 to 172.24.103.62172.24.103.6317
Link 12172.24.103.64/30255.255.255.252172.24.103.65 to 172.24.103.66172.24.103.670
Link 22172.24.103.68/30255.255.255.252172.24.103.69 to 172.24.103.70172.24.103.710
Link 32172.24.103.72/30255.255.255.252172.24.103.73 to 172.24.103.74172.24.103.750

Unused range: 172.24.103.76 to 172.24.103.255 (180 addresses), kept for growth.

Answer: A 172.24.96.0/22, C 172.24.100.0/23, B 172.24.102.0/24, D 172.24.103.0/26, Link 1 172.24.103.64/30, Link 2 172.24.103.68/30, Link 3 172.24.103.72/30; masks, ranges and broadcasts as in the table.

2078 Bhadra · Q48 marksConsider IP block of 202.50.0.0/24 and six departments with 125, 59, 27, 14, 4 and 2 hosts respectively. Perform the subnetting so that wastage of IP addresses is minimum and find out the subnet mask, network address, broadcast address, wasted IP addresses and usable host ranges in each network.

Given: block 202.50.0.0/24 (256 addresses, 202.50.0.0 to 202.50.0.255); hosts: Dept 1 125, Dept 2 59, Dept 3 27, Dept 4 14, Dept 5 4, Dept 6 2.

Step 1, size each subnet (largest first; a block of 2h addresses holds 2h−2 hosts):

SubnetHosts HH + 2hBlock 2hPrefixMask
Dept 11251277128/25255.255.255.128
Dept 25961664/26255.255.255.192
Dept 32729532/27255.255.255.224
Dept 41416416/28255.255.255.240
Dept 54638/29255.255.255.248
Dept 62424/30255.255.255.252

Step 2, check the fit: 128 + 64 + 32 + 16 + 8 + 4 = 252 addresses are needed and the /24 holds 256, so it fits, with 4 addresses to spare.

Step 3, allocate from 202.50.0.0, each subnet starting where the previous one ends:

SubnetHostsNetwork (CIDR)Subnet maskUsable host rangeBroadcastWasted
Dept 1125202.50.0.0/25255.255.255.128202.50.0.1 to 202.50.0.126202.50.0.1271
Dept 259202.50.0.128/26255.255.255.192202.50.0.129 to 202.50.0.190202.50.0.1913
Dept 327202.50.0.192/27255.255.255.224202.50.0.193 to 202.50.0.222202.50.0.2233
Dept 414202.50.0.224/28255.255.255.240202.50.0.225 to 202.50.0.238202.50.0.2390
Dept 54202.50.0.240/29255.255.255.248202.50.0.241 to 202.50.0.246202.50.0.2472
Dept 62202.50.0.248/30255.255.255.252202.50.0.249 to 202.50.0.250202.50.0.2510

Unused range: 202.50.0.252 to 202.50.0.255 (4 addresses), kept for growth.

Answer: Dept 1 202.50.0.0/25, Dept 2 202.50.0.128/26, Dept 3 202.50.0.192/27, Dept 4 202.50.0.224/28, Dept 5 202.50.0.240/29, Dept 6 202.50.0.248/30; 9 addresses wasted in all inside the subnets.

2076 Chaitra · Q48 marksSuppose your company has leased the IP address of 222.70.94.0/24 from your ISP. Divide it far five different departments containing 50, 30, 25, 12, 10 no of hosts. There are also two points to point links far interconnection between routers. List out the network address, broadcast address, usable IP address range and subnet mask for each subnet. Also mention the unused range of IP addresses.

How this is read"far" is read as "for" (printed twice). "Unused range" is answered both ways: the addresses each subnet leaves unused after its hosts (hosts numbered from the first usable address), and the part of the block no subnet takes. Insights works this as Problem 15 (p. 163 to 166) with the same subnets, but it opens with "given mask is /25" (the block is a /24); it sizes the 30 hosts as "32 = 2^n - 2" and prints their range as 202.10.10.65 to 202.10.10.94 (it is 222.70.94.65 to 222.70.94.94); its table gives the 12-host department .129 to .141 and calls .142 to .143 unused, though .143 is the broadcast (hosts .129 to .140, unused .141 to .142); and it never gives the unused range of the block, 222.70.94.168 to 222.70.94.255.

Given: block 222.70.94.0/24 (256 addresses, 222.70.94.0 to 222.70.94.255); hosts: Dept 1 50, Dept 2 30, Dept 3 25, Dept 4 12, Dept 5 10; 2 point-to-point links (Link 1, Link 2), 2 hosts each.

Step 1, size each subnet (largest first; a block of 2h addresses holds 2h−2 hosts):

SubnetHosts HH + 2hBlock 2hPrefixMask
Dept 15052664/26255.255.255.192
Dept 23032532/27255.255.255.224
Dept 32527532/27255.255.255.224
Dept 41214416/28255.255.255.240
Dept 51012416/28255.255.255.240
Link 12424/30255.255.255.252
Link 22424/30255.255.255.252

Step 2, check the fit: 64 + 32 + 32 + 16 + 16 + 4 + 4 = 168 addresses are needed and the /24 holds 256, so it fits, with 88 addresses to spare.

Step 3, allocate from 222.70.94.0, each subnet starting where the previous one ends:

SubnetHostsNetwork (CIDR)Subnet maskUsable host rangeAssigned to the hostsUnassigned (count)Broadcast
Dept 150222.70.94.0/26255.255.255.192222.70.94.1 to 222.70.94.62222.70.94.1 to 222.70.94.50222.70.94.51 to 222.70.94.62 (12)222.70.94.63
Dept 230222.70.94.64/27255.255.255.224222.70.94.65 to 222.70.94.94222.70.94.65 to 222.70.94.94none222.70.94.95
Dept 325222.70.94.96/27255.255.255.224222.70.94.97 to 222.70.94.126222.70.94.97 to 222.70.94.121222.70.94.122 to 222.70.94.126 (5)222.70.94.127
Dept 412222.70.94.128/28255.255.255.240222.70.94.129 to 222.70.94.142222.70.94.129 to 222.70.94.140222.70.94.141 to 222.70.94.142 (2)222.70.94.143
Dept 510222.70.94.144/28255.255.255.240222.70.94.145 to 222.70.94.158222.70.94.145 to 222.70.94.154222.70.94.155 to 222.70.94.158 (4)222.70.94.159
Link 12222.70.94.160/30255.255.255.252222.70.94.161 to 222.70.94.162222.70.94.161 to 222.70.94.162none222.70.94.163
Link 22222.70.94.164/30255.255.255.252222.70.94.165 to 222.70.94.166222.70.94.165 to 222.70.94.166none222.70.94.167

Unused range of the block: 222.70.94.168 to 222.70.94.255 (88 addresses), kept for growth.

Answer: Dept 1 222.70.94.0/26, Dept 2 222.70.94.64/27, Dept 3 222.70.94.96/27, Dept 4 222.70.94.128/28, Dept 5 222.70.94.144/28, Link 1 222.70.94.160/30, Link 2 222.70.94.164/30; unused inside the subnets as in the table, and 222.70.94.168 to 222.70.94.255 of the block unused.

2076 Ashwin · Q48 marksInstitute of Engineering has six departments having 16, 32, 61, 8, 6 and 24 computers. Use 192.168.1.0/24 to distribute the network. Find the network address, broadcast address, usable IP range and subnet mask in each department.

Given: block 192.168.1.0/24 (256 addresses, 192.168.1.0 to 192.168.1.255); computers: Dept 1 16, Dept 2 32, Dept 3 61, Dept 4 8, Dept 5 6, Dept 6 24.

The trap: 32 computers need 32 + 2 = 34 addresses, but a /27 holds only 30 hosts, so Dept 2 needs a /26 and wastes 30.

Step 1, size each subnet (largest first; a block of 2h addresses holds 2h−2 hosts):

SubnetHosts HH + 2hBlock 2hPrefixMask
Dept 36163664/26255.255.255.192
Dept 23234664/26255.255.255.192
Dept 62426532/27255.255.255.224
Dept 11618532/27255.255.255.224
Dept 4810416/28255.255.255.240
Dept 56838/29255.255.255.248

Step 2, check the fit: 64 + 64 + 32 + 32 + 16 + 8 = 216 addresses are needed and the /24 holds 256, so it fits, with 40 addresses to spare.

Step 3, allocate from 192.168.1.0, each subnet starting where the previous one ends:

SubnetHostsNetwork (CIDR)Subnet maskUsable host rangeBroadcastWasted
Dept 361192.168.1.0/26255.255.255.192192.168.1.1 to 192.168.1.62192.168.1.631
Dept 232192.168.1.64/26255.255.255.192192.168.1.65 to 192.168.1.126192.168.1.12730
Dept 624192.168.1.128/27255.255.255.224192.168.1.129 to 192.168.1.158192.168.1.1596
Dept 116192.168.1.160/27255.255.255.224192.168.1.161 to 192.168.1.190192.168.1.19114
Dept 48192.168.1.192/28255.255.255.240192.168.1.193 to 192.168.1.206192.168.1.2076
Dept 56192.168.1.208/29255.255.255.248192.168.1.209 to 192.168.1.214192.168.1.2150

Unused range: 192.168.1.216 to 192.168.1.255 (40 addresses), kept for growth.

Answer: Dept 3 192.168.1.0/26, Dept 2 192.168.1.64/26, Dept 6 192.168.1.128/27, Dept 1 192.168.1.160/27, Dept 4 192.168.1.192/28, Dept 5 192.168.1.208/29; masks, ranges and broadcasts as in the table.

2075 Chaitra · Q48 marksSuppose you are a private consultant hired by the large company to setup the network for their enterprise and you are given a large number of consecutive. IP address starting at 120.89.96.0/19. Suppose that four departments A, B, C and D request 100, 500, 800 and 400 addresses respectively, how the subnetting can be performed so, that address wastage will be minimum?

How this is readThe same four requests are set on 120.89.96.0/19 again in 2074 Ashwin Q5 and on 202.70.64.0/19 in 2073 Shrawan Q4.

Given: block 120.89.96.0/19 (8,192 addresses, 120.89.96.0 to 120.89.127.255); addresses requested: A 100, B 500, C 800, D 400.

Step 1, size each subnet (largest first; a block of 2h addresses holds 2h−2 hosts):

SubnetHosts HH + 2hBlock 2hPrefixMask
C800802101,024/22255.255.252.0
B5005029512/23255.255.254.0
D4004029512/23255.255.254.0
A1001027128/25255.255.255.128

Step 2, check the fit: 1,024 + 512 + 512 + 128 = 2,176 addresses are needed and the /19 holds 8,192, so it fits, with 6,016 addresses to spare.

Step 3, allocate from 120.89.96.0, each subnet starting where the previous one ends:

SubnetHostsNetwork (CIDR)Subnet maskUsable host rangeBroadcastWasted
C800120.89.96.0/22255.255.252.0120.89.96.1 to 120.89.99.254120.89.99.255222
B500120.89.100.0/23255.255.254.0120.89.100.1 to 120.89.101.254120.89.101.25510
D400120.89.102.0/23255.255.254.0120.89.102.1 to 120.89.103.254120.89.103.255110
A100120.89.104.0/25255.255.255.128120.89.104.1 to 120.89.104.126120.89.104.12726

Unused range: 120.89.104.128 to 120.89.127.255 (6,016 addresses), kept for growth.

How it is performed: each request gets the smallest power-of-two block that holds it plus its network and broadcast addresses; placing the biggest block first keeps every later block on its own boundary, so no addresses are lost between blocks. The four take 2,176 of the 8,192 addresses and leave 6,016 free in one piece.

Answer: C 120.89.96.0/22, B 120.89.100.0/23, D 120.89.102.0/23, A 120.89.104.0/25; masks, ranges and broadcasts as in the table.

2075 Ashwin · Q58 marksDesign a network for 5 departments containing 29, 14, 15, 23 and 5 computers. Take a network example IP 202.83.54.91/25.

How this is read202.83.54.91 has host bits set under /25 (91 is below 128), so the block is its network, 202.83.54.0/25. Insights works this twice, as Problem 1 (p. 134 to 136) and Problem 13 (p. 159 to 161), with the same subnets; both tables start the 15-computer range at 202.83.54.64, its network address (the first host is 202.83.54.65); Problem 13's table gives the masks as 255.255.255.192 for the three /27 rows and 255.255.255.224 for the /28 and /29 rows (they are 255.255.255.224, 255.255.255.240 and 255.255.255.248); both workings call the /28 step a "difference of 32" (it is 16); and neither gives the unused 202.83.54.120 to 202.83.54.127.

Given: block 202.83.54.91/25; computers: Dept 1 29, Dept 2 14, Dept 3 15, Dept 4 23, Dept 5 5.

Find the block: the /25 mask is 255.255.255.128; in octet 4, 91 = 01011011 AND 10000000 = 00000000 = 0, so the block is the network 202.83.54.0/25 (202.83.54.0 to 202.83.54.127).

Step 1, size each subnet (largest first; a block of 2h addresses holds 2h−2 hosts):

SubnetHosts HH + 2hBlock 2hPrefixMask
Dept 12931532/27255.255.255.224
Dept 42325532/27255.255.255.224
Dept 31517532/27255.255.255.224
Dept 21416416/28255.255.255.240
Dept 55738/29255.255.255.248

Step 2, check the fit: 32 + 32 + 32 + 16 + 8 = 120 addresses are needed and the /25 holds 128, so it fits, with 8 addresses to spare.

Step 3, allocate from 202.83.54.0, each subnet starting where the previous one ends:

SubnetHostsNetwork (CIDR)Subnet maskUsable host rangeBroadcastWasted
Dept 129202.83.54.0/27255.255.255.224202.83.54.1 to 202.83.54.30202.83.54.311
Dept 423202.83.54.32/27255.255.255.224202.83.54.33 to 202.83.54.62202.83.54.637
Dept 315202.83.54.64/27255.255.255.224202.83.54.65 to 202.83.54.94202.83.54.9515
Dept 214202.83.54.96/28255.255.255.240202.83.54.97 to 202.83.54.110202.83.54.1110
Dept 55202.83.54.112/29255.255.255.248202.83.54.113 to 202.83.54.118202.83.54.1191

Unused range: 202.83.54.120 to 202.83.54.127 (8 addresses), kept for growth.

Answer: Dept 1 202.83.54.0/27, Dept 4 202.83.54.32/27, Dept 3 202.83.54.64/27, Dept 2 202.83.54.96/28, Dept 5 202.83.54.112/29; masks, ranges and broadcasts as in the table.

2074 Chaitra · Q58 marksHow can you dedicate 32, 65, 10, 21, 9 public IP address to the departments A, B, C, D and E respectively form the pool of class C IP addresses with minimum loss. Explain.

How this is readNo address is given. 192.0.2.0/24, a class C block reserved for documentation (RFC 5737), stands for "the pool of class C"; with a real allocation only the first three octets change. "form" is read as "from".

Given: block 192.0.2.0/24, standing for the class C pool (256 addresses, 192.0.2.0 to 192.0.2.255); addresses: A 32, B 65, C 10, D 21, E 9.

Step 1, size each subnet (largest first; a block of 2h addresses holds 2h−2 hosts):

SubnetHosts HH + 2hBlock 2hPrefixMask
B65677128/25255.255.255.128
A3234664/26255.255.255.192
D2123532/27255.255.255.224
C1012416/28255.255.255.240
E911416/28255.255.255.240

Step 2, check the fit: 128 + 64 + 32 + 16 + 16 = 256 addresses are needed and the /24 holds 256, so it fits exactly.

Step 3, allocate from 192.0.2.0, each subnet starting where the previous one ends:

SubnetHostsNetwork (CIDR)Subnet maskUsable host rangeBroadcastWasted
B65192.0.2.0/25255.255.255.128192.0.2.1 to 192.0.2.126192.0.2.12761
A32192.0.2.128/26255.255.255.192192.0.2.129 to 192.0.2.190192.0.2.19130
D21192.0.2.192/27255.255.255.224192.0.2.193 to 192.0.2.222192.0.2.2239
C10192.0.2.224/28255.255.255.240192.0.2.225 to 192.0.2.238192.0.2.2394
E9192.0.2.240/28255.255.255.240192.0.2.241 to 192.0.2.254192.0.2.2555

Unused range: none; the block is used exactly.

Why the loss is least: each department gets the smallest block that holds it, and the blocks are packed largest first, so nothing is lost between blocks. The 109 wasted addresses are forced by the counts: B's 65 just misses a /26 (62 hosts) and A's 32 just misses a /27 (30 hosts), so each needs a block twice as big.

Answer: B 192.0.2.0/25, A 192.0.2.128/26, D 192.0.2.192/27, C 192.0.2.224/28, E 192.0.2.240/28; the five fill the class C network exactly.

2074 Ashwin · Q58 marksSuppose you are a private consultant hired by a company to setup the network for their enterprise and you are given a large number of consecutive IP address starting at 120.89.96.0/19. Suppose that four departments A, B, C and D request 100, 500, 800 and 400 addresses respectively, how the subnetting can be performed so that address wastage will be minimum?

Given: block 120.89.96.0/19 (8,192 addresses, 120.89.96.0 to 120.89.127.255); addresses requested: A 100, B 500, C 800, D 400.

Step 1, size each subnet (largest first; a block of 2h addresses holds 2h−2 hosts):

SubnetHosts HH + 2hBlock 2hPrefixMask
C800802101,024/22255.255.252.0
B5005029512/23255.255.254.0
D4004029512/23255.255.254.0
A1001027128/25255.255.255.128

Step 2, check the fit: 1,024 + 512 + 512 + 128 = 2,176 addresses are needed and the /19 holds 8,192, so it fits, with 6,016 addresses to spare.

Step 3, allocate from 120.89.96.0, each subnet starting where the previous one ends:

SubnetHostsNetwork (CIDR)Subnet maskUsable host rangeBroadcastWasted
C800120.89.96.0/22255.255.252.0120.89.96.1 to 120.89.99.254120.89.99.255222
B500120.89.100.0/23255.255.254.0120.89.100.1 to 120.89.101.254120.89.101.25510
D400120.89.102.0/23255.255.254.0120.89.102.1 to 120.89.103.254120.89.103.255110
A100120.89.104.0/25255.255.255.128120.89.104.1 to 120.89.104.126120.89.104.12726

Unused range: 120.89.104.128 to 120.89.127.255 (6,016 addresses), kept for growth.

How it is performed: each request gets the smallest power-of-two block that holds it plus its network and broadcast addresses; placing the biggest block first keeps every later block on its own boundary, so no addresses are lost between blocks. The four take 2,176 of the 8,192 addresses and leave 6,016 free in one piece.

Answer: C 120.89.96.0/22, B 120.89.100.0/23, D 120.89.102.0/23, A 120.89.104.0/25; masks, ranges and broadcasts as in the table.

2073 Shrawan · Q48 marksYou are a private contractor hired by the large company to setup the network for their enterprise and you are given a large number of consecutive IP address starting at 202.70.64.0/19. Suppose that four department A, B, C and D request 100, 500, 800 and 400 addresses respectively, how the subnetting can be performed so, that address wastage will be minimum?

How this is readInsights works this as Problem 3 (p. 138 to 140) and tags it 2070 Magh and 2073 Shrawan; 2070 Magh is not among the 27 papers on record. Its subnets agree with these, but its working prints the usable range of A as 202.70.72.1 to 202.70.72.127, and .127 is the broadcast (its table rightly ends at .126); it gives no unused range.

Given: block 202.70.64.0/19 (8,192 addresses, 202.70.64.0 to 202.70.95.255); addresses requested: A 100, B 500, C 800, D 400.

Step 1, size each subnet (largest first; a block of 2h addresses holds 2h−2 hosts):

SubnetHosts HH + 2hBlock 2hPrefixMask
C800802101,024/22255.255.252.0
B5005029512/23255.255.254.0
D4004029512/23255.255.254.0
A1001027128/25255.255.255.128

Step 2, check the fit: 1,024 + 512 + 512 + 128 = 2,176 addresses are needed and the /19 holds 8,192, so it fits, with 6,016 addresses to spare.

Step 3, allocate from 202.70.64.0, each subnet starting where the previous one ends:

SubnetHostsNetwork (CIDR)Subnet maskUsable host rangeBroadcastWasted
C800202.70.64.0/22255.255.252.0202.70.64.1 to 202.70.67.254202.70.67.255222
B500202.70.68.0/23255.255.254.0202.70.68.1 to 202.70.69.254202.70.69.25510
D400202.70.70.0/23255.255.254.0202.70.70.1 to 202.70.71.254202.70.71.255110
A100202.70.72.0/25255.255.255.128202.70.72.1 to 202.70.72.126202.70.72.12726

Unused range: 202.70.72.128 to 202.70.95.255 (6,016 addresses), kept for growth.

How it is performed: each request gets the smallest power-of-two block that holds it plus its network and broadcast addresses; placing the biggest block first keeps every later block on its own boundary, so no addresses are lost between blocks. The four take 2,176 of the 8,192 addresses and leave 6,016 free in one piece.

Answer: C 202.70.64.0/22, B 202.70.68.0/23, D 202.70.70.0/23, A 202.70.72.0/25; masks, ranges and broadcasts as in the table.

2072 Chaitra · Q48 marksExplain how can you allocate 30, 24, 25 and 20 IP addresses to the four different department of ABC company with minimum wastage. Specify the range of IP addresses, Broadcast Address, Network Address and Subnet mask for each department form the given address pool 202.77.19.0/24.

How this is read"form" is read as "from". Insights works this as Problem 10 (p. 154 to 155) and gets the same subnets.

Given: block 202.77.19.0/24 (256 addresses, 202.77.19.0 to 202.77.19.255); addresses: Dept 1 30, Dept 2 24, Dept 3 25, Dept 4 20.

Step 1, size each subnet (largest first; a block of 2h addresses holds 2h−2 hosts):

SubnetHosts HH + 2hBlock 2hPrefixMask
Dept 13032532/27255.255.255.224
Dept 32527532/27255.255.255.224
Dept 22426532/27255.255.255.224
Dept 42022532/27255.255.255.224

Step 2, check the fit: 32 + 32 + 32 + 32 = 128 addresses are needed and the /24 holds 256, so it fits, with 128 addresses to spare.

Step 3, allocate from 202.77.19.0, each subnet starting where the previous one ends:

SubnetHostsNetwork (CIDR)Subnet maskUsable host rangeBroadcastWasted
Dept 130202.77.19.0/27255.255.255.224202.77.19.1 to 202.77.19.30202.77.19.310
Dept 325202.77.19.32/27255.255.255.224202.77.19.33 to 202.77.19.62202.77.19.635
Dept 224202.77.19.64/27255.255.255.224202.77.19.65 to 202.77.19.94202.77.19.956
Dept 420202.77.19.96/27255.255.255.224202.77.19.97 to 202.77.19.126202.77.19.12710

Unused range: 202.77.19.128 to 202.77.19.255 (128 addresses), kept for growth.

How: all four counts lie between 15 and 30 hosts, so each department gets a /27 (mask 255.255.255.224, 30 hosts); four /27s take the first half of the pool and leave 202.77.19.128 to 202.77.19.255 free in one piece.

Answer: Dept 1 202.77.19.0/27, Dept 3 202.77.19.32/27, Dept 2 202.77.19.64/27, Dept 4 202.77.19.96/27; ranges, broadcasts and masks as in the table.

2071 Chaitra · Q510 marksYou are given the following address space 10.10.10.0/24. You have to assign addresses to 4 departments with the following hosts 5, 16, 23 and 27 respectively. Perform the subnetting in such a way that the IP address wastage in each department are minimum. Also find out the subnet mask, network address, broadcast address and unassigned range in each department.

How this is read"Unassigned range in each department" is answered both ways: the addresses each subnet leaves unassigned after its hosts (hosts numbered from the first usable address), and the part of the address space no department takes. Insights works this as Problem 7 (p. 147 to 149) with the same subnets but never gives either unassigned range.

Given: block 10.10.10.0/24 (256 addresses, 10.10.10.0 to 10.10.10.255); hosts: Dept 1 5, Dept 2 16, Dept 3 23, Dept 4 27.

Step 1, size each subnet (largest first; a block of 2h addresses holds 2h−2 hosts):

SubnetHosts HH + 2hBlock 2hPrefixMask
Dept 42729532/27255.255.255.224
Dept 32325532/27255.255.255.224
Dept 21618532/27255.255.255.224
Dept 15738/29255.255.255.248

Step 2, check the fit: 32 + 32 + 32 + 8 = 104 addresses are needed and the /24 holds 256, so it fits, with 152 addresses to spare.

Step 3, allocate from 10.10.10.0, each subnet starting where the previous one ends:

SubnetHostsNetwork (CIDR)Subnet maskUsable host rangeAssigned to the hostsUnassigned (count)Broadcast
Dept 42710.10.10.0/27255.255.255.22410.10.10.1 to 10.10.10.3010.10.10.1 to 10.10.10.2710.10.10.28 to 10.10.10.30 (3)10.10.10.31
Dept 32310.10.10.32/27255.255.255.22410.10.10.33 to 10.10.10.6210.10.10.33 to 10.10.10.5510.10.10.56 to 10.10.10.62 (7)10.10.10.63
Dept 21610.10.10.64/27255.255.255.22410.10.10.65 to 10.10.10.9410.10.10.65 to 10.10.10.8010.10.10.81 to 10.10.10.94 (14)10.10.10.95
Dept 1510.10.10.96/29255.255.255.24810.10.10.97 to 10.10.10.10210.10.10.97 to 10.10.10.10110.10.10.102 (1)10.10.10.103

Unassigned range of the address space: 10.10.10.104 to 10.10.10.255 (152 addresses), kept for growth.

Answer: Dept 4 10.10.10.0/27, Dept 3 10.10.10.32/27, Dept 2 10.10.10.64/27, Dept 1 10.10.10.96/29; unassigned inside each department as in the table, and 10.10.10.104 to 10.10.10.255 of the space unassigned.

2070 Chaitra · Q58 marksHow can you dedicate 10, 12, 8, 14 public IP addresses to department A, B, C and D respectively from the pool of class C with minimum losses of IP? Explain.

How this is readNo address is given; 192.0.2.0/24, a class C documentation block (RFC 5737), stands for the pool. Insights works this as Problem 5 (p. 142 to 144) on 190.16.0.0/24, which is a class B address (first octet 128 to 191), not class C; it calls the /28 step a "difference of 4" (it is 16), labels the rows of its table D(14), B(12), C(10), D(8) (they are D, B, A and C) and prints one range as "190.16.33-190.16.0.46" (190.16.0.33 to 190.16.0.46). Its /28 layout is right.

Given: block 192.0.2.0/24, standing for the class C pool (256 addresses, 192.0.2.0 to 192.0.2.255); addresses: A 10, B 12, C 8, D 14.

Step 1, size each subnet (largest first; a block of 2h addresses holds 2h−2 hosts):

SubnetHosts HH + 2hBlock 2hPrefixMask
D1416416/28255.255.255.240
B1214416/28255.255.255.240
A1012416/28255.255.255.240
C810416/28255.255.255.240

Step 2, check the fit: 16 + 16 + 16 + 16 = 64 addresses are needed and the /24 holds 256, so it fits, with 192 addresses to spare.

Step 3, allocate from 192.0.2.0, each subnet starting where the previous one ends:

SubnetHostsNetwork (CIDR)Subnet maskUsable host rangeBroadcastWasted
D14192.0.2.0/28255.255.255.240192.0.2.1 to 192.0.2.14192.0.2.150
B12192.0.2.16/28255.255.255.240192.0.2.17 to 192.0.2.30192.0.2.312
A10192.0.2.32/28255.255.255.240192.0.2.33 to 192.0.2.46192.0.2.474
C8192.0.2.48/28255.255.255.240192.0.2.49 to 192.0.2.62192.0.2.636

Unused range: 192.0.2.64 to 192.0.2.255 (192 addresses), kept for growth.

Why the loss is least: every count fits a /28 (14 hosts), the smallest block that holds 14; a /29 holds only 6. The four /28s lose 12 addresses inside the subnets and leave 192.0.2.64 to 192.0.2.255 free in one piece.

Answer: D 192.0.2.0/28, B 192.0.2.16/28, A 192.0.2.32/28, C 192.0.2.48/28; masks, ranges and broadcasts as in the table.

2069 Chaitra · Q48 marksShow the importance in this case. Banijya bank need to allocate 15 IPs in HR department, 30 in finance department, 24 in customer care unit and 25 in ATM machines. If you have one network of class C range public IP address. Describe how you will manage it.

How this is readNo address is given; 192.0.2.0/24, a class C documentation block (RFC 5737), stands for the public class C network. Insights works this as Problem 2 (p. 136 to 138) on an assumed 200.10.10.0/24 with the same layout.

Given: block 192.0.2.0/24, standing for the public class C network (256 addresses, 192.0.2.0 to 192.0.2.255); addresses: HR 15, Finance 30, Customer care 24, ATM machines 25.

The importance here: without subnetting all 94 hosts of the four units share one network: one broadcast domain, and nothing between the ATM machines and the staff PCs. Subnetting gives each unit its own network, so the ATM subnet can be fenced off by router rules, broadcasts stay inside a unit, and the four subnets use only 128 of the 256 addresses, leaving 192.0.2.128/25 for new units.

Step 1, size each subnet (largest first; a block of 2h addresses holds 2h−2 hosts):

SubnetHosts HH + 2hBlock 2hPrefixMask
Finance3032532/27255.255.255.224
ATM machines2527532/27255.255.255.224
Customer care2426532/27255.255.255.224
HR1517532/27255.255.255.224

Step 2, check the fit: 32 + 32 + 32 + 32 = 128 addresses are needed and the /24 holds 256, so it fits, with 128 addresses to spare.

Step 3, allocate from 192.0.2.0, each subnet starting where the previous one ends:

SubnetHostsNetwork (CIDR)Subnet maskUsable host rangeBroadcastWasted
Finance30192.0.2.0/27255.255.255.224192.0.2.1 to 192.0.2.30192.0.2.310
ATM machines25192.0.2.32/27255.255.255.224192.0.2.33 to 192.0.2.62192.0.2.635
Customer care24192.0.2.64/27255.255.255.224192.0.2.65 to 192.0.2.94192.0.2.956
HR15192.0.2.96/27255.255.255.224192.0.2.97 to 192.0.2.126192.0.2.12715

Unused range: 192.0.2.128 to 192.0.2.255 (128 addresses), kept for growth.

Answer: Finance 192.0.2.0/27, ATM machines 192.0.2.32/27, Customer care 192.0.2.64/27, HR 192.0.2.96/27; all four with mask 255.255.255.224, and 192.0.2.128/25 left for growth.

2068 Chaitra · Q810 marksSuppose there are 4 departments A, B, C and D. The department A has 23 hosts, B has 16, C has 28 and D has 13 hosts. You are given a networks 202.70.64.0/24. Perform the subnetting in such a way that the IP address wastage in each department are minimum and also find out the sunbet mask, network address, broadcast, and unable host range in each department.

How this is read"sunbet mask" is read as subnet mask, "unable host range" as usable host range and "a networks" as a network.

Given: block 202.70.64.0/24 (256 addresses, 202.70.64.0 to 202.70.64.255); hosts: A 23, B 16, C 28, D 13.

Step 1, size each subnet (largest first; a block of 2h addresses holds 2h−2 hosts):

SubnetHosts HH + 2hBlock 2hPrefixMask
C2830532/27255.255.255.224
A2325532/27255.255.255.224
B1618532/27255.255.255.224
D1315416/28255.255.255.240

Step 2, check the fit: 32 + 32 + 32 + 16 = 112 addresses are needed and the /24 holds 256, so it fits, with 144 addresses to spare.

Step 3, allocate from 202.70.64.0, each subnet starting where the previous one ends:

SubnetHostsNetwork (CIDR)Subnet maskUsable host rangeBroadcastWasted
C28202.70.64.0/27255.255.255.224202.70.64.1 to 202.70.64.30202.70.64.312
A23202.70.64.32/27255.255.255.224202.70.64.33 to 202.70.64.62202.70.64.637
B16202.70.64.64/27255.255.255.224202.70.64.65 to 202.70.64.94202.70.64.9514
D13202.70.64.96/28255.255.255.240202.70.64.97 to 202.70.64.110202.70.64.1111

Unused range: 202.70.64.112 to 202.70.64.255 (144 addresses), kept for growth.

Answer: C 202.70.64.0/27, A 202.70.64.32/27, B 202.70.64.64/27, D 202.70.64.96/28; masks, broadcasts and usable ranges as in the table.

2068 Baishakh · Q46 marksYou are given the IP address block 200.10.80.32/25. If there are five departments which require 5, 40, 28, 12, 6 hosts respectively. Design the subnet.

How this is read200.10.80.32 has host bits set under /25 (32 is below 128), so the block is its network, 200.10.80.0/25. Starting at .32 instead would leave only 96 addresses (.32 to .127), too few for the 128 the five subnets need.

Given: block 200.10.80.32/25; hosts: Dept 1 5, Dept 2 40, Dept 3 28, Dept 4 12, Dept 5 6.

Find the block: the /25 mask is 255.255.255.128; in octet 4, 32 = 00100000 AND 10000000 = 00000000 = 0, so the block is the network 200.10.80.0/25 (200.10.80.0 to 200.10.80.127).

Step 1, size each subnet (largest first; a block of 2h addresses holds 2h−2 hosts):

SubnetHosts HH + 2hBlock 2hPrefixMask
Dept 24042664/26255.255.255.192
Dept 32830532/27255.255.255.224
Dept 41214416/28255.255.255.240
Dept 56838/29255.255.255.248
Dept 15738/29255.255.255.248

Step 2, check the fit: 64 + 32 + 16 + 8 + 8 = 128 addresses are needed and the /25 holds 128, so it fits exactly.

Step 3, allocate from 200.10.80.0, each subnet starting where the previous one ends:

SubnetHostsNetwork (CIDR)Subnet maskUsable host rangeBroadcastWasted
Dept 240200.10.80.0/26255.255.255.192200.10.80.1 to 200.10.80.62200.10.80.6322
Dept 328200.10.80.64/27255.255.255.224200.10.80.65 to 200.10.80.94200.10.80.952
Dept 412200.10.80.96/28255.255.255.240200.10.80.97 to 200.10.80.110200.10.80.1112
Dept 56200.10.80.112/29255.255.255.248200.10.80.113 to 200.10.80.118200.10.80.1190
Dept 15200.10.80.120/29255.255.255.248200.10.80.121 to 200.10.80.126200.10.80.1271

Unused range: none; the block is used exactly.

Answer: Dept 2 200.10.80.0/26, Dept 3 200.10.80.64/27, Dept 4 200.10.80.96/28, Dept 5 200.10.80.112/29, Dept 1 200.10.80.120/29; masks, ranges and broadcasts as in the table.

2066 Bhadra · Q5a6 marksYou are given the IPv4 address block 203.71.53.0/26; assign the IP subnet for the following network. [Figure, as text: Net A: 6 Hosts (LAN on router R1); Net B: 2 Hosts (link R1 to R2); Net C: 12 Hosts (LAN on router R2); Net E: 2 Hosts (link R2 to R3); Net F: 29 Hosts (LAN on router R3). The routers are unlabelled in the print and no Net D is drawn.]

How this is readThe host counts are taken to include the router interfaces, as the 2 hosts of Nets B and E are the two router ends of each link; on that reading the five nets fill the /26 exactly. (With one more address on each LAN for its router, Net A would need a /28 and the nets would need 72 addresses, more than the 64 of the /26.)

Given: block 203.71.53.0/26 (64 addresses, 203.71.53.0 to 203.71.53.63); hosts: Net A 6, Net B 2, Net C 12, Net E 2, Net F 29.

Step 1, size each subnet (largest first; a block of 2h addresses holds 2h−2 hosts):

SubnetHosts HH + 2hBlock 2hPrefixMask
Net F (LAN on R3)2931532/27255.255.255.224
Net C (LAN on R2)1214416/28255.255.255.240
Net A (LAN on R1)6838/29255.255.255.248
Net B (link R1 to R2)2424/30255.255.255.252
Net E (link R2 to R3)2424/30255.255.255.252

Step 2, check the fit: 32 + 16 + 8 + 4 + 4 = 64 addresses are needed and the /26 holds 64, so it fits exactly.

Step 3, allocate from 203.71.53.0, each subnet starting where the previous one ends:

SubnetHostsNetwork (CIDR)Subnet maskUsable host rangeBroadcastWasted
Net F (LAN on R3)29203.71.53.0/27255.255.255.224203.71.53.1 to 203.71.53.30203.71.53.311
Net C (LAN on R2)12203.71.53.32/28255.255.255.240203.71.53.33 to 203.71.53.46203.71.53.472
Net A (LAN on R1)6203.71.53.48/29255.255.255.248203.71.53.49 to 203.71.53.54203.71.53.550
Net B (link R1 to R2)2203.71.53.56/30255.255.255.252203.71.53.57 to 203.71.53.58203.71.53.590
Net E (link R2 to R3)2203.71.53.60/30255.255.255.252203.71.53.61 to 203.71.53.62203.71.53.630

Unused range: none; the block is used exactly.

Answer: Net F (LAN on R3) 203.71.53.0/27, Net C (LAN on R2) 203.71.53.32/28, Net A (LAN on R1) 203.71.53.48/29, Net B (link R1 to R2) 203.71.53.56/30, Net E (link R2 to R3) 203.71.53.60/30; the two router links take the two /30s.

Insights on Computer Networks, p. 156 to 157From 201.40.58.0/24 design subnets for groups of 49, 27, 11 and 45 hosts with minimum wastage; give the mask, network, broadcast, assigned and unassigned range of each.

How this is readInsights tags this 2073 Magh, a sitting not among the 27 papers on record. Its subnets agree, but it never gives the assigned and unassigned ranges the question asks for; they are in the table below, and 201.40.58.176 to 201.40.58.255 of the block is unassigned.

Given: block 201.40.58.0/24 (256 addresses, 201.40.58.0 to 201.40.58.255); hosts: Group 1 49, Group 2 27, Group 3 11, Group 4 45.

Step 1, size each subnet (largest first; a block of 2h addresses holds 2h−2 hosts):

SubnetHosts HH + 2hBlock 2hPrefixMask
Group 14951664/26255.255.255.192
Group 44547664/26255.255.255.192
Group 22729532/27255.255.255.224
Group 31113416/28255.255.255.240

Step 2, check the fit: 64 + 64 + 32 + 16 = 176 addresses are needed and the /24 holds 256, so it fits, with 80 addresses to spare.

Step 3, allocate from 201.40.58.0, each subnet starting where the previous one ends:

SubnetHostsNetwork (CIDR)Subnet maskUsable host rangeAssigned to the hostsUnassigned (count)Broadcast
Group 149201.40.58.0/26255.255.255.192201.40.58.1 to 201.40.58.62201.40.58.1 to 201.40.58.49201.40.58.50 to 201.40.58.62 (13)201.40.58.63
Group 445201.40.58.64/26255.255.255.192201.40.58.65 to 201.40.58.126201.40.58.65 to 201.40.58.109201.40.58.110 to 201.40.58.126 (17)201.40.58.127
Group 227201.40.58.128/27255.255.255.224201.40.58.129 to 201.40.58.158201.40.58.129 to 201.40.58.155201.40.58.156 to 201.40.58.158 (3)201.40.58.159
Group 311201.40.58.160/28255.255.255.240201.40.58.161 to 201.40.58.174201.40.58.161 to 201.40.58.171201.40.58.172 to 201.40.58.174 (3)201.40.58.175

Unassigned range of the block: 201.40.58.176 to 201.40.58.255 (80 addresses), kept for growth.

Answer: Group 1 201.40.58.0/26, Group 4 201.40.58.64/26, Group 2 201.40.58.128/27, Group 3 201.40.58.160/28; assigned and unassigned ranges as in the table.

Insights on Computer Networks, p. 157 to 159Departments A, B, C and D have 25, 16, 29 and 11 hosts. From 202.70.91.0/24 design subnets with minimum wastage and give the mask, network, broadcast and usable host range of each.

How this is readInsights tags this 2073 Chaitra, a sitting not among the 27 papers on record. Its subnets agree; its table prints the broadcast of A (25 hosts) as 202.70.91.94.63, which is 202.70.91.63.

Given: block 202.70.91.0/24 (256 addresses, 202.70.91.0 to 202.70.91.255); hosts: A 25, B 16, C 29, D 11.

Step 1, size each subnet (largest first; a block of 2h addresses holds 2h−2 hosts):

SubnetHosts HH + 2hBlock 2hPrefixMask
C2931532/27255.255.255.224
A2527532/27255.255.255.224
B1618532/27255.255.255.224
D1113416/28255.255.255.240

Step 2, check the fit: 32 + 32 + 32 + 16 = 112 addresses are needed and the /24 holds 256, so it fits, with 144 addresses to spare.

Step 3, allocate from 202.70.91.0, each subnet starting where the previous one ends:

SubnetHostsNetwork (CIDR)Subnet maskUsable host rangeBroadcastWasted
C29202.70.91.0/27255.255.255.224202.70.91.1 to 202.70.91.30202.70.91.311
A25202.70.91.32/27255.255.255.224202.70.91.33 to 202.70.91.62202.70.91.635
B16202.70.91.64/27255.255.255.224202.70.91.65 to 202.70.91.94202.70.91.9514
D11202.70.91.96/28255.255.255.240202.70.91.97 to 202.70.91.110202.70.91.1113

Unused range: 202.70.91.112 to 202.70.91.255 (144 addresses), kept for growth.

Answer: C 202.70.91.0/27, A 202.70.91.32/27, B 202.70.91.64/27, D 202.70.91.96/28; masks, broadcasts and usable ranges as in the table.

Insights on Computer Networks, p. 162 to 163A company has departments of 20, 32, 60 and 24 computers. Assume a class C public network and design VLSM blocks with the network, broadcast, usable range and mask of each.

How this is readInsights tags this 2076 Bhadra, a sitting not among the 27 papers on record. No block is given; 192.0.2.0/24, a class C documentation block (RFC 5737), stands for it. Insights says it assumes 200.10.10.0/24 and then computes every row with 202.10.10.x; its layout is right.

Given: block 192.0.2.0/24, standing for the public class C network (256 addresses, 192.0.2.0 to 192.0.2.255); computers: Dept 1 20, Dept 2 32, Dept 3 60, Dept 4 24.

The trap: 32 computers need 32 + 2 = 34 addresses, but a /27 holds only 30 hosts, so Dept 2 needs a /26 and wastes 30.

Step 1, size each subnet (largest first; a block of 2h addresses holds 2h−2 hosts):

SubnetHosts HH + 2hBlock 2hPrefixMask
Dept 36062664/26255.255.255.192
Dept 23234664/26255.255.255.192
Dept 42426532/27255.255.255.224
Dept 12022532/27255.255.255.224

Step 2, check the fit: 64 + 64 + 32 + 32 = 192 addresses are needed and the /24 holds 256, so it fits, with 64 addresses to spare.

Step 3, allocate from 192.0.2.0, each subnet starting where the previous one ends:

SubnetHostsNetwork (CIDR)Subnet maskUsable host rangeBroadcastWasted
Dept 360192.0.2.0/26255.255.255.192192.0.2.1 to 192.0.2.62192.0.2.632
Dept 232192.0.2.64/26255.255.255.192192.0.2.65 to 192.0.2.126192.0.2.12730
Dept 424192.0.2.128/27255.255.255.224192.0.2.129 to 192.0.2.158192.0.2.1596
Dept 120192.0.2.160/27255.255.255.224192.0.2.161 to 192.0.2.190192.0.2.19110

Unused range: 192.0.2.192 to 192.0.2.255 (64 addresses), kept for growth.

Answer: Dept 3 192.0.2.0/26, Dept 2 192.0.2.64/26, Dept 4 192.0.2.128/27, Dept 1 192.0.2.160/27; masks, ranges and broadcasts as in the table.

Insights on Computer Networks, p. 140 to 142Consecutive addresses are available starting at 192.122.2.1. Four organisations, Pulchowk, Thapathali, WRC and ERC, request 6000, 2000, 4000 and 2500 addresses. Design the blocks and give the first and last address and the mask, in x.y.z.w/s notation, for each.

How this is readInsights tags this 2070 Bhadra, a sitting not among the 27 papers on record. The start, 192.122.2.1, is no block boundary, so the blocks begin at the first /19 boundary inside the pool. Insights instead gives Pulchowk 192.122.0.0/19, which takes in 192.122.0.0 to 192.122.2.0, addresses before the pool starts; from WRC onwards, and in its whole table, it writes 192.221 for 192.122; and it starts the ERC range at .49.1, though its own ERC block starts at .48.0 (first host .48.1).

Given: a pool starting at 192.122.2.1; requests: Pulchowk 6,000, Thapathali 2,000, WRC 4,000, ERC 2,500.

Step 1, size each block (largest first):

SubnetHosts HH + 2hBlock 2hPrefixMask
Pulchowk6,0006,002138,192/19255.255.224.0
WRC4,0004,002124,096/20255.255.240.0
ERC2,5002,502124,096/20255.255.240.0
Thapathali2,0002,002112,048/21255.255.248.0

Step 2, place the blocks: a /19 must start where the third octet is a multiple of 32; the pool starts inside 192.122.0.0/19, so the first /19 wholly inside the pool is 192.122.32.0/19. Each later block starts where the previous one ends, already on its own boundary.

OrganisationRequestedBlock (x.y.z.w/s)First to last addressFirst to last valid hostMask
Pulchowk6,000192.122.32.0/19192.122.32.0 to 192.122.63.255192.122.32.1 to 192.122.63.254255.255.224.0
WRC4,000192.122.64.0/20192.122.64.0 to 192.122.79.255192.122.64.1 to 192.122.79.254255.255.240.0
ERC2,500192.122.80.0/20192.122.80.0 to 192.122.95.255192.122.80.1 to 192.122.95.254255.255.240.0
Thapathali2,000192.122.96.0/21192.122.96.0 to 192.122.103.255192.122.96.1 to 192.122.103.254255.255.248.0

Left free: 192.122.2.1 to 192.122.31.255 (7,679 addresses) before the first block, for smaller blocks later; its biggest whole blocks are 192.122.16.0/20 and 192.122.8.0/21.

Answer: Pulchowk 192.122.32.0/19, WRC 192.122.64.0/20, ERC 192.122.80.0/20, Thapathali 192.122.96.0/21; first and last valid hosts and masks as in the table.

Insights on Computer Networks, p. 144 to 147What is subnet masking? Five departments need 27, 28, 7, 12 and 8 hosts. Design the subnets with minimum loss of addresses and write the starting and ending address of each.

How this is readInsights tags this 2071 Magh, a sitting not among the 27 papers on record. Its subnets are right, but after assuming 192.168.0.0/24 it writes "Given mask: 255.255.224.0 (/19)", sizes 7 hosts as "8 = 2^n - 2", and its table drops an octet from four broadcasts (192.168.31 for 192.168.0.31, and likewise .63, .79, .95).

Given: block 192.168.0.0/24, the block Insights assumes (256 addresses, 192.168.0.0 to 192.168.0.255); hosts: Dept 1 27, Dept 2 28, Dept 3 7, Dept 4 12, Dept 5 8.

Subnet masking: ANDing an address with its mask keeps the network bits and clears the host bits, giving the (sub)network address a router forwards on. For example 130.45.34.56 = 10000010.00101101.00100010.00111000 AND 255.255.0.0 gives 130.45.0.0.

Step 1, size each subnet (largest first):

SubnetHosts HH + 2hBlock 2hPrefixMask
Dept 22830532/27255.255.255.224
Dept 12729532/27255.255.255.224
Dept 41214416/28255.255.255.240
Dept 5810416/28255.255.255.240
Dept 379416/28255.255.255.240

Step 2, check the fit: 32 + 32 + 16 + 16 + 16 = 112 addresses are needed and the /24 holds 256, so it fits, with 144 addresses to spare.

Step 3, allocate from 192.168.0.0:

SubnetHostsNetwork (CIDR)Starting addressEnding addressUsable host range
Dept 228192.168.0.0/27192.168.0.0192.168.0.31192.168.0.1 to 192.168.0.30
Dept 127192.168.0.32/27192.168.0.32192.168.0.63192.168.0.33 to 192.168.0.62
Dept 412192.168.0.64/28192.168.0.64192.168.0.79192.168.0.65 to 192.168.0.78
Dept 58192.168.0.80/28192.168.0.80192.168.0.95192.168.0.81 to 192.168.0.94
Dept 37192.168.0.96/28192.168.0.96192.168.0.111192.168.0.97 to 192.168.0.110

Unused range: 192.168.0.112 to 192.168.0.255 (144 addresses), kept for growth.

Answer: Dept 2 192.168.0.0/27, Dept 1 192.168.0.32/27, Dept 4 192.168.0.64/28, Dept 5 192.168.0.80/28, Dept 3 192.168.0.96/28; each subnet starts at its network address and ends at its broadcast.

Insights on Computer Networks, p. 149 to 151Design IPv4 subnets from 192.168.5.0/24 for departments of 16, 48, 61, 32 and 24 computers.

How this is readInsights tags this 2072 Magh, a sitting not among the 27 papers on record. Its subnets agree; its table prints the 61-computer range as 192.168.5.1 to 192.168.5.63, which is the broadcast (its working rightly ends at 192.168.5.62).

Given: block 192.168.5.0/24 (256 addresses, 192.168.5.0 to 192.168.5.255); computers: Dept 1 16, Dept 2 48, Dept 3 61, Dept 4 32, Dept 5 24.

The trap: 32 computers need 32 + 2 = 34 addresses, but a /27 holds only 30 hosts, so Dept 4 needs a /26 and wastes 30.

Step 1, size each subnet (largest first; a block of 2h addresses holds 2h−2 hosts):

SubnetHosts HH + 2hBlock 2hPrefixMask
Dept 36163664/26255.255.255.192
Dept 24850664/26255.255.255.192
Dept 43234664/26255.255.255.192
Dept 52426532/27255.255.255.224
Dept 11618532/27255.255.255.224

Step 2, check the fit: 64 + 64 + 64 + 32 + 32 = 256 addresses are needed and the /24 holds 256, so it fits exactly.

Step 3, allocate from 192.168.5.0, each subnet starting where the previous one ends:

SubnetHostsNetwork (CIDR)Subnet maskUsable host rangeBroadcastWasted
Dept 361192.168.5.0/26255.255.255.192192.168.5.1 to 192.168.5.62192.168.5.631
Dept 248192.168.5.64/26255.255.255.192192.168.5.65 to 192.168.5.126192.168.5.12714
Dept 432192.168.5.128/26255.255.255.192192.168.5.129 to 192.168.5.190192.168.5.19130
Dept 524192.168.5.192/27255.255.255.224192.168.5.193 to 192.168.5.222192.168.5.2236
Dept 116192.168.5.224/27255.255.255.224192.168.5.225 to 192.168.5.254192.168.5.25514

Unused range: none; the block is used exactly.

Answer: Dept 3 192.168.5.0/26, Dept 2 192.168.5.64/26, Dept 4 192.168.5.128/26, Dept 5 192.168.5.192/27, Dept 1 192.168.5.224/27; the five fill the /24 exactly.

Insights on Computer Networks, p. 151 to 153Design a network with public addresses for five departments of IOE Pulchowk Campus with 45, 35, 40, 23 and 30 computers, with minimum loss; assume the address block.

How this is readInsights tags this 2072 Ashwin, a sitting not among the 27 papers on record. No block is given; 192.0.2.0/24, a class C documentation block (RFC 5737), stands for the public network. Insights assumes 200.10.10.0/24 and gets the same layout; it is right.

Given: block 192.0.2.0/24, standing for the public class C network (256 addresses, 192.0.2.0 to 192.0.2.255); computers: Dept 1 45, Dept 2 35, Dept 3 40, Dept 4 23, Dept 5 30.

Step 1, size each subnet (largest first; a block of 2h addresses holds 2h−2 hosts):

SubnetHosts HH + 2hBlock 2hPrefixMask
Dept 14547664/26255.255.255.192
Dept 34042664/26255.255.255.192
Dept 23537664/26255.255.255.192
Dept 53032532/27255.255.255.224
Dept 42325532/27255.255.255.224

Step 2, check the fit: 64 + 64 + 64 + 32 + 32 = 256 addresses are needed and the /24 holds 256, so it fits exactly.

Step 3, allocate from 192.0.2.0, each subnet starting where the previous one ends:

SubnetHostsNetwork (CIDR)Subnet maskUsable host rangeBroadcastWasted
Dept 145192.0.2.0/26255.255.255.192192.0.2.1 to 192.0.2.62192.0.2.6317
Dept 340192.0.2.64/26255.255.255.192192.0.2.65 to 192.0.2.126192.0.2.12722
Dept 235192.0.2.128/26255.255.255.192192.0.2.129 to 192.0.2.190192.0.2.19127
Dept 530192.0.2.192/27255.255.255.224192.0.2.193 to 192.0.2.222192.0.2.2230
Dept 423192.0.2.224/27255.255.255.224192.0.2.225 to 192.0.2.254192.0.2.2557

Unused range: none; the block is used exactly.

Answer: Dept 1 192.0.2.0/26, Dept 3 192.0.2.64/26, Dept 2 192.0.2.128/26, Dept 5 192.0.2.192/27, Dept 4 192.0.2.224/27; the five fill the class C network exactly.

Fixed length subnetting: equal subnets PIN 3/27

Ch 4 · Network layer3 from 3 of the 27 sittings

The method
  1. Borrow bits: for n equal subnets borrow s bits with 2s≥n; where a host count H sets the size instead, keep h host bits with 2h−2≥H.
  2. New prefix and mask: /p becomes /(p + s); each subnet holds 232−(p+s) addresses, and the mask octet where the boundary falls is 256 minus the block size in that octet.
  3. List the subnets: subnet k starts at network + k × block size; its broadcast is one below the next start; the usable hosts lie in between.
  4. Assign: the first n subnets go to the departments; the other 2s−n stay spare.
2081 Baishakh · Q45 marksSuppose your company has IP address block of 16.16.16.0/21. Divide this IP address for five different departments of the company equally. List out the network address, broadcast address, subnet mask and usable IP address range for each subnet.

How this is read"Divide equally" asks for fixed length subnetting, not VLSM: equal subnets come in powers of two, so five departments take 5 of 8 equal /24 subnets and the other 3 stay spare.

Given: block 16.16.16.0/21 (2,048 addresses, 16.16.16.0 to 16.16.23.255); 5 departments, equal subnets.

Step 1, borrow bits: 2s≥5 gives s = 3 (22=4 is too few), so the /21 splits into 23 = 8 subnets.

Step 2, new prefix and mask: /21 + 3 = /24, mask 255.255.255.0; each subnet holds 232−24 = 256 addresses, 254 usable hosts.

Step 3, list the subnets (each starts 256 addresses, one step of the third octet, after the last):

DepartmentNetwork (CIDR)Subnet maskUsable host rangeBroadcast
Dept 116.16.16.0/24255.255.255.016.16.16.1 to 16.16.16.25416.16.16.255
Dept 216.16.17.0/24255.255.255.016.16.17.1 to 16.16.17.25416.16.17.255
Dept 316.16.18.0/24255.255.255.016.16.18.1 to 16.16.18.25416.16.18.255
Dept 416.16.19.0/24255.255.255.016.16.19.1 to 16.16.19.25416.16.19.255
Dept 516.16.20.0/24255.255.255.016.16.20.1 to 16.16.20.25416.16.20.255
Spare16.16.21.0/24255.255.255.016.16.21.1 to 16.16.21.25416.16.21.255
Spare16.16.22.0/24255.255.255.016.16.22.1 to 16.16.22.25416.16.22.255
Spare16.16.23.0/24255.255.255.016.16.23.1 to 16.16.23.25416.16.23.255

Answer: departments 1 to 5 get 16.16.16.0/24 to 16.16.20.0/24, each with mask 255.255.255.0 and 254 usable hosts; 16.16.21.0/24, 16.16.22.0/24, 16.16.23.0/24 stay spare for new departments.

2070 Ashad · Q94 markssub-netting with example

How this is readThe question asks for an example and gives no numbers, so one clean example of subnetting is chosen: a private (RFC 1918) campus block cut into four equal subnets.

Example: a campus network 192.168.10.0/24 (256 addresses) is cut into 4 equal subnets, one per department, so that each department is its own network behind one router interface.

Step 1, borrow bits: 2s≥4 gives s = 2.

Step 2, new prefix and mask: /24 + 2 = /26; mask 255.255.255.192 (last octet 11000000); each subnet holds 232−26 = 64 addresses, 62 usable hosts.

Step 3, list the subnets (each starts 64 after the last):

DepartmentNetwork (CIDR)Subnet maskUsable host rangeBroadcast
Dept 1192.168.10.0/26255.255.255.192192.168.10.1 to 192.168.10.62192.168.10.63
Dept 2192.168.10.64/26255.255.255.192192.168.10.65 to 192.168.10.126192.168.10.127
Dept 3192.168.10.128/26255.255.255.192192.168.10.129 to 192.168.10.190192.168.10.191
Dept 4192.168.10.192/26255.255.255.192192.168.10.193 to 192.168.10.254192.168.10.255

Finding the subnet of a host: AND its address with the mask. For 192.168.10.75, the last octet 75 = 01001011 AND 11000000 = 01000000 = 64, so the host is on 192.168.10.64/26 (Dept 2), whose broadcast is 192.168.10.127.

Answer: 192.168.10.0/24 with 2 bits borrowed gives 4 subnets of 62 hosts: 192.168.10.0/26, 192.168.10.64/26, 192.168.10.128/26, 192.168.10.192/26, all with mask 255.255.255.192.

2067 Ashad · Q98 marksIf you need to assign IP addresses to all computers of question no. 2 making each department as network. What will be your approach? Explain with IP address ranges you are suggesting.

How this is readQuestion 2 of 2067 Ashad sets the campus: 5 departments of 100 computers each, in 5 rooms of 20. No block is given; the computers sit inside a campus LAN, so a private block is chosen, and 192.168.0.0/22 is the smallest one that holds 5 department /25 networks.

Given (question 2 of the same sitting): Pulchowk Campus, 5 departments, each with 100 computers in 5 rooms of 20; each department is to be one network.

Approach: one subnet per department, sized from its host count, cut from a private block (RFC 1918): campus PCs need no public addresses and reach the Internet through NAT on the campus router, which also routes between the department subnets.

Step 1, size a department subnet: 100 computers + 1 router interface (the department gateway) = 101 hosts; 2h−2≥101 gives h = 7, a /25 of 128 addresses (126 hosts, mask 255.255.255.128), leaving 25 spare in each department for printers, access points and growth.

Step 2, size the block: 5 departments × 128 = 640 addresses; the smallest power of two that holds them is 1,024, a /22. Chosen: 192.168.0.0/22 (192.168.0.0 to 192.168.3.255).

Step 3, cut the /22 into /25 subnets (3 bits borrowed, 8 subnets):

DepartmentNetwork (CIDR)Subnet maskUsable host rangeGateway (router)Broadcast
Dept 1192.168.0.0/25255.255.255.128192.168.0.1 to 192.168.0.126192.168.0.1192.168.0.127
Dept 2192.168.0.128/25255.255.255.128192.168.0.129 to 192.168.0.254192.168.0.129192.168.0.255
Dept 3192.168.1.0/25255.255.255.128192.168.1.1 to 192.168.1.126192.168.1.1192.168.1.127
Dept 4192.168.1.128/25255.255.255.128192.168.1.129 to 192.168.1.254192.168.1.129192.168.1.255
Dept 5192.168.2.0/25255.255.255.128192.168.2.1 to 192.168.2.126192.168.2.1192.168.2.127
Spare192.168.2.128/25255.255.255.128192.168.2.129 to 192.168.2.254192.168.2.255
Spare192.168.3.0/25255.255.255.128192.168.3.1 to 192.168.3.126192.168.3.127
Spare192.168.3.128/25255.255.255.128192.168.3.129 to 192.168.3.254192.168.3.255

Rooms: the 20 computers of each room hang off one 24-port switch, and the room switches uplink to the department switch, all on the department subnet; a room needs no subnet of its own.

Trade-off: private space is not scarce, so one /24 per department (192.168.1.0/24 to 192.168.5.0/24, 254 hosts each) is an equally valid plan, simpler to read and with more room to grow; the /25 plan above wastes less.

Answer: departments 1 to 5 get 192.168.0.0/25, 192.168.0.128/25, 192.168.1.0/25, 192.168.1.128/25, 192.168.2.0/25, each with mask 255.255.255.128 and its first host as gateway; 192.168.2.128/25, 192.168.3.0/25, 192.168.3.128/25 stay spare.

Dijkstra's shortest path BOOK

Ch 4 · Network layernot set by a paper yet, 1 from the book

The method
  1. Start: make the source permanent with cost 0; every other node is tentative, labelled (∞, -).
  2. Relabel: for each neighbour of the node made permanent last, if its cost plus the link cost is less than the neighbour's label, relabel the neighbour (new cost, via that node).
  3. Pick: make the tentative node with the smallest cost permanent.
  4. Repeat steps 2 and 3 until the destination is permanent; read the path backwards through the "via" labels.
Insights on Computer Networks, p. 118 to 119Find the shortest path from A to D by Dijkstra's algorithm on the graph of Figure 4.12: links A-B 2, A-G 6, B-C 7, B-E 2, E-F 2, E-G 1, F-C 3, F-H 2, C-D 3, H-D 2 and G-H 4.

How this is readInsights draws the steps as Figure 4.12 (b) to (f) and stops with H at (8, F) and D still unlabelled: the last steps (C permanent at 9, then D at 10 via H) and the cost 10 are not shown, and panel (d) labels D (∞, 1) where it should read (∞, -). Its path, ABEFHD, is right.

Given: the graph of Figure 4.12, links A-B 2, A-G 6, B-C 7, B-E 2, E-F 2, E-G 1, F-C 3, F-H 2, C-D 3, H-D 2, G-H 4; source A, destination D.

Working: each row makes one node permanent and relabels its tentative neighbours; a label is (cost from A, via node), permanent labels in bold.

StepMade permanentBCDEFGH
1A (0)(2, A)∞∞∞∞(6, A)∞
2B (2)(2, A)(9, B)∞(4, B)∞(6, A)∞
3E (4)(2, A)(9, B)∞(4, B)(6, E)(5, E)∞
4G (5)(2, A)(9, B)∞(4, B)(6, E)(5, E)(9, G)
5F (6)(2, A)(9, B)∞(4, B)(6, E)(5, E)(8, F)
6H (8)(2, A)(9, B)(10, H)(4, B)(6, E)(5, E)(8, F)
7C (9)(2, A)(9, B)(10, H)(4, B)(6, E)(5, E)(8, F)
8D (10)(2, A)(9, B)(10, H)(4, B)(6, E)(5, E)(8, F)

Path: back from D through the via labels: D from H, H from F, F from E, E from B, B from A. Cost: 2 + 2 + 2 + 2 + 2 = 10.

Answer: the shortest path from A to D is A B E F H D, cost 10.

Distance vector routing: updating a routing table BOOK

Ch 4 · Network layernot set by a paper yet, 1 from the book

The method
  1. Receive: each router gets its neighbours' tables (destination, cost, next hop) at regular intervals.
  2. Adjust: add the cost of reaching that neighbour (1 hop) to every cost it sent, and make that neighbour the next hop.
  3. Combine: put the router's own table and the adjusted tables together.
  4. Keep the best: for each destination keep the entry with the least cost (on a tie the existing entry stays). The result is the new table, sent out at the next interval; the tables settle when an exchange changes nothing.
Insights on Computer Networks, p. 121 to 122In the network of Figure 4.14 (routers A to F joined by networks 08, 14, 23, 55, 66, 78 and 92) every router starts knowing only its own networks at 1 hop. Update router A's table from the tables of its neighbours B, E and F, and give the tables once they settle.

How this is readRecomputed, Figures 4.15 and 4.16 are right. Where two neighbours give the same cost, Figure 4.16 shows one of them (A to 66 via E; via B is as short); the last table lists both.

Given: routers A to F joined through networks 08, 14, 23, 55, 66, 78, 92 (Figure 4.14): A on 14, 23, 78; B on 14, 55; C on 55, 66; D on 08, 66; E on 08, 23; F on 78, 92. Each router starts knowing only its own networks, at cost 1 (one hop). A's neighbours are B (on net 14), E (on net 23), F (on net 78).

Step 1, A's own table (network, cost, next hop):

NetworkCost, next hop
141, direct
231, direct
781, direct

Step 2, add one hop to each table received, the sender becoming the next hop:

FromNetworkCostNext hop
B141 + 1 = 2B
B551 + 1 = 2B
E081 + 1 = 2E
E231 + 1 = 2E
F781 + 1 = 2F
F921 + 1 = 2F

Step 3, combine and keep the least cost for each network:

NetworkCandidates (cost, next hop)Kept
082, E2, E
141, direct; 2, B1, direct
231, direct; 2, E1, direct
552, B2, B
781, direct; 2, F1, direct
922, F2, F

Answer, A's new table:

NetworkCostNext hop
082E
141direct
231direct
552B
781direct
922F

Network 66 is still missing: none of A's neighbours knew it yet.

The tables settle after 3 exchanges (each router repeats the three steps every interval); a cell is cost, next hop, with both next hops where two give the same cost:

NetworkABCDEF
082, E3, A or C2, D1, direct1, direct3, A
141, direct1, direct2, B3, C or E2, A2, A
231, direct2, A3, B or D2, E1, direct2, A
552, B1, direct1, direct2, C3, A or D3, A
663, B or E2, C1, direct1, direct2, D4, A
781, direct2, A3, B3, E2, A1, direct
922, F3, A4, B4, E3, A1, direct

A reaches 66 at 3 hops via B (which goes on through C) or via E (which goes on through D), at equal cost; Figure 4.16 keeps E.

IPv6 address shortening: leading zeros, then one double colon BOOK

Ch 7 · Introduction to IPv6not set by a paper yet, 2 from the book

The method
  1. Write the address as eight groups of four hexadecimal digits; any other number of groups means the address is incomplete.
  2. Drop the leading zeros of every group: 0db8 becomes db8, 0000 becomes 0.
  3. Replace the longest run of consecutive all-zero groups by :: (the first run, if two are equally long); use :: only once, and never for a single zero group.
  4. To expand, count the groups shown: :: stands for 8 minus that count, each 0000.
Insights on Computer Networks, p. 219Shorten the IPv6 address FE80:0000:0000:0001:0800:23E7:F5DB: drop the leading zeros, then replace the zero groups by a double colon.

How this is readAs printed the address has seven groups, 112 bits, one short of the 128 an IPv6 address needs, so as it stands it cannot be shortened, or even read. It is read here as FE80:0000:0000:0000:0001:0800:23E7:F5DB, the eight groups that the printed answer FE80::1:0800:23E7:F5DB stands for. The printed middle step, FE80:0:0:1:0800:23E7:F5DB, also keeps the leading zero of 0800, which the first rule drops.

Given: FE80:0000:0000:0000:0001:0800:23E7:F5DB, eight groups.

Step 1, drop the leading zeros of each group (0000 to 0, 0001 to 1, 0800 to 800):

FE80:0000:0000:0000:0001:0800:23E7:F5DB
FE80:0:0:0:1:800:23E7:F5DB

Step 2, replace the run of zero groups by :: Groups 2, 3 and 4 are zero, one run of three, so they become :::

FE80:0:0:0:1:800:23E7:F5DB
FE80::1:800:23E7:F5DB

Check by expanding: 5 groups are written out, so :: stands for 8−5=3 zero groups, which gives back the eight groups above.

Answer: FE80::1:800:23E7:F5DB, or in the canonical lower case fe80::1:800:23e7:f5db.

Insights on Computer Networks, p. 219Shorten the IPv6 address 0000:0000:1212:2341:0000:0000:1212:251E, using the double colon only once.

How this is readThe printed answers, ::1212:2341:0000:0000:1212:251E and 0000:0000:1212:2341::1212:251E, are valid, but each keeps the leading zeros of the run that was not replaced; dropping them as well gives the shortest forms below.

Given: 0000:0000:1212:2341:0000:0000:1212:251E, eight groups, with two runs of two zero groups (groups 1 and 2, groups 5 and 6).

Step 1, drop the leading zeros:

0000:0000:1212:2341:0000:0000:1212:251E
0:0:1212:2341:0:0:1212:251E

Step 2, replace ONE run by :: Either run may go:

first run replaced:   ::1212:2341:0:0:1212:251E
second run replaced:  0:0:1212:2341::1212:251E

Why not both: ::1212:2341::1212:251E writes out 4 groups, so 4 are missing, and nothing says how they divide between the two gaps (1 + 3, 2 + 2, 3 + 1): the address would be ambiguous.

Answer: ::1212:2341:0:0:1212:251E or 0:0:1212:2341::1212:251E; the canonical form (RFC 5952: the first of two equal runs, lower case) is ::1212:2341:0:0:1212:251e.

RSA on a word, letter by letter TOP 13/27

Ch 8 · Network security13 from 13 of the 27 sittings, 1 from the book

The method
  1. Number the letters A = 1, B = 2, ..., Z = 26 (lower case takes the same numbers); each letter is one block M.
  2. Choose two primes p≠q, small enough for hand arithmetic, with n=p×q>26, so that every M is below n and no two letters collide.
  3. Compute n=pq and φ(n)=(p−1)(q−1).
  4. Choose e with 1<e<φ(n) and gcd(e,φ(n))=1. Any shared factor fails, even when e does not divide φ(n): e = 6 shares the factor 2 with 20.
  5. Find d =e−1modφ(n) by the extended Euclidean algorithm: start r1=φ(n), r2=e, t1=0, t2=1; in each row q=⌊r1/r2⌋, r=r1−qr2, t=t1−qt2, then r2,r move up to r1,r2 and t2,t to t1,t2. When r2=0, r1=1 and d=t1 (plus φ(n) if negative). Check e×dmodφ(n)=1.
  6. Keys: public (e,n), private (d,n).
  7. Encrypt each letter, C=Memodn; decrypt, M=Cdmodn. For a large power use repeated squaring: write the exponent as a sum of powers of 2, square and reduce mod n, then multiply the powers needed, reducing after each product.
  8. Write the ciphertext as numbers (a value above 26 has no letter) and check that every letter comes back. A letter may encrypt to itself (A = 1 always does, as 1e=1): a property of small RSA keys, not a slip.
2082 Bhadra · Q94+2 marksEncrypt and decrypt the “attack” using RSA.

Given: the word attack, in lower case. Lower-case letters take the same numbers as capitals: a = 1, b = 2, ..., z = 26. Each letter is one block M.

Step 1: key generation. Choose the primes p=3 and q=11.

n=p×q=3×11=33φ(n)=(p−1)(q−1)=2×10=20

Choose e=3: 1<3<20 and gcd(3,20)=1. The data works: p and q are distinct primes, n=33>26 keeps every letter number below n (so no two letters can share a ciphertext), and e shares no factor with φ(n), so d exists.

Step 2: private exponent d=e−1modφ(n), by the extended Euclidean algorithm. Start r1=20, r2=3, t1=0, t2=1; each row q=⌊r1/r2⌋, r=r1−qr2, t=t1−qt2; stop when r2=0.

qr1r2rt1t2t
6203201−6
13211−67
2210−67−20
107−20

r1=1 confirms gcd(3,20)=1, and d=t1=7. Check: 3×7=21=1×20+1.

Public key (e,n)=(3,33); private key (d,n)=(7,33).

Step 3: encryption, C=M3mod33, and step 4: decryption, M=C7mod33, letter by letter:

LetterMM3C=M3mod33C7mod33Letter
a1111a
t2080001420t
t2080001420t
a1111a
c327273c
k1113311111k

Decryption of one letter in full by repeated squaring, with d written as a sum of powers of 2:

Decrypt C = 14: M = 147 mod 33
d = 7 = 4 + 2 + 1
141 = 14
142 = 196 mod 33 = 31
144 = 312 = 961 mod 33 = 4
147 = 144 × 142 × 141 = 4 × 31 × 14
    4 × 31 = 124 mod 33 = 25
    25 × 14 = 350 mod 33 = 20
so M = 20 = t

The letters a and k encrypt to their own numbers (1, 11): 13=1 for any key, and 113=1331 = 40×33+11. Every RSA key has a few such fixed values; decryption still returns them, so this is no slip.

Answer: with the public key (3, 33), attack encrypts to the ciphertext 1, 14, 14, 1, 27, 11; decryption with the private key (7, 33) gives 1, 20, 20, 1, 3, 11, the plaintext attack.

2081 Baishakh · Q97 marksEncrypt the word "security" using the RSA algorithm. Also show the decryption to obtain the plaintext.

Given: the word security, in lower case. Lower-case letters take the same numbers as capitals: a = 1, b = 2, ..., z = 26. Each letter is one block M.

Step 1: key generation. Choose the primes p=3 and q=23.

n=p×q=3×23=69φ(n)=(p−1)(q−1)=2×22=44

Choose e=5: 1<5<44 and gcd(5,44)=1. The data works: p and q are distinct primes, n=69>26 keeps every letter number below n (so no two letters can share a ciphertext), and e shares no factor with φ(n), so d exists.

Step 2: private exponent d=e−1modφ(n), by the extended Euclidean algorithm. Start r1=44, r2=5, t1=0, t2=1; each row q=⌊r1/r2⌋, r=r1−qr2, t=t1−qt2; stop when r2=0.

qr1r2rt1t2t
8445401−8
15411−89
4410−89−44
109−44

r1=1 confirms gcd(5,44)=1, and d=t1=9. Check: 5×9=45=1×44+1.

Public key (e,n)=(5,69); private key (d,n)=(9,69).

Step 3: encryption, C=M5mod69, and step 4: decryption, M=C9mod69, letter by letter:

LetterMC=M5mod69C9mod69Letter
s193419s
e5205e
c3363c
u216021u
r18318r
i9549i
t205620t
y255525y

Encryption in full by repeated squaring (write e as a sum of powers of 2, square and reduce mod 69, then multiply the powers needed):

Encrypt s: C = 195 mod 69
e = 5 = 4 + 1
191 = 19
192 = 361 mod 69 = 16
194 = 162 = 256 mod 69 = 49
195 = 194 × 191 = 49 × 19
    49 × 19 = 931 mod 69 = 34
so C = 34

Decryption of two letters in full by repeated squaring:

Decrypt C = 34: M = 349 mod 69
d = 9 = 8 + 1
341 = 34
342 = 1156 mod 69 = 52
344 = 522 = 2704 mod 69 = 13
348 = 132 = 169 mod 69 = 31
349 = 348 × 341 = 31 × 34
    31 × 34 = 1054 mod 69 = 19
so M = 19 = s

Decrypt C = 20: M = 209 mod 69
d = 9 = 8 + 1
201 = 20
202 = 400 mod 69 = 55
204 = 552 = 3025 mod 69 = 58
208 = 582 = 3364 mod 69 = 52
209 = 208 × 201 = 52 × 20
    52 × 20 = 1040 mod 69 = 5
so M = 5 = e

Answer: with the public key (5, 69), security encrypts to the ciphertext 34, 20, 36, 60, 3, 54, 56, 55; decryption with the private key (9, 69) gives 19, 5, 3, 21, 18, 9, 20, 25, the plaintext security.

2080 Bhadra · Q96 marksUse RSA algorithm to encrypt and decrypt the message "network".

Given: the word network, in lower case. Lower-case letters take the same numbers as capitals: a = 1, b = 2, ..., z = 26. Each letter is one block M.

Step 1: key generation. Choose the primes p=3 and q=17.

n=p×q=3×17=51φ(n)=(p−1)(q−1)=2×16=32

Choose e=3: 1<3<32 and gcd(3,32)=1. The data works: p and q are distinct primes, n=51>26 keeps every letter number below n (so no two letters can share a ciphertext), and e shares no factor with φ(n), so d exists.

Step 2: private exponent d=e−1modφ(n), by the extended Euclidean algorithm. Start r1=32, r2=3, t1=0, t2=1; each row q=⌊r1/r2⌋, r=r1−qr2, t=t1−qt2; stop when r2=0.

qr1r2rt1t2t
10323201−10
13211−1011
2210−1011−32
1011−32

r1=1 confirms gcd(3,32)=1, and d=t1=11. Check: 3×11=33=1×32+1.

Public key (e,n)=(3,51); private key (d,n)=(11,51).

Step 3: encryption, C=M3mod51, and step 4: decryption, M=C11mod51, letter by letter:

LetterMM3C=M3mod51C11mod51Letter
n1427444114n
e5125235e
t2080004420t
w23121672923w
o153375915o
r1858321818r
k111331511k

Decryption of one letter in full by repeated squaring, with d written as a sum of powers of 2:

Decrypt C = 41: M = 4111 mod 51
d = 11 = 8 + 2 + 1
411 = 41
412 = 1681 mod 51 = 49
414 = 492 = 2401 mod 51 = 4
418 = 42 = 16
4111 = 418 × 412 × 411 = 16 × 49 × 41
    16 × 49 = 784 mod 51 = 19
    19 × 41 = 779 mod 51 = 14
so M = 14 = n

The letter r encrypts to its own number (18): 183=5832 = 114×51+18. Every RSA key has a few such fixed values; decryption still returns them, so this is no slip.

Answer: with the public key (3, 51), network encrypts to the ciphertext 41, 23, 44, 29, 9, 18, 5; decryption with the private key (11, 51) gives 14, 5, 20, 23, 15, 18, 11, the plaintext network.

2080 Baishakh · Q95 marksUse RSA algorithm to encrypt/decrypt the word COW.

Given: the word COW. Letters are numbered A = 1, B = 2, ..., Z = 26. Each letter is one block M.

Step 1: key generation. Choose the primes p=3 and q=17.

n=p×q=3×17=51φ(n)=(p−1)(q−1)=2×16=32

Choose e=3: 1<3<32 and gcd(3,32)=1. The data works: p and q are distinct primes, n=51>26 keeps every letter number below n (so no two letters can share a ciphertext), and e shares no factor with φ(n), so d exists.

Step 2: private exponent d=e−1modφ(n), by the extended Euclidean algorithm. Start r1=32, r2=3, t1=0, t2=1; each row q=⌊r1/r2⌋, r=r1−qr2, t=t1−qt2; stop when r2=0.

qr1r2rt1t2t
10323201−10
13211−1011
2210−1011−32
1011−32

r1=1 confirms gcd(3,32)=1, and d=t1=11. Check: 3×11=33=1×32+1.

Public key (e,n)=(3,51); private key (d,n)=(11,51).

Step 3: encryption, C=M3mod51, and step 4: decryption, M=C11mod51, letter by letter:

LetterMM3C=M3mod51C11mod51Letter
C327273C
O153375915O
W23121672923W

Decryption of one letter in full by repeated squaring, with d written as a sum of powers of 2:

Decrypt C = 29: M = 2911 mod 51
d = 11 = 8 + 2 + 1
291 = 29
292 = 841 mod 51 = 25
294 = 252 = 625 mod 51 = 13
298 = 132 = 169 mod 51 = 16
2911 = 298 × 292 × 291 = 16 × 25 × 29
    16 × 25 = 400 mod 51 = 43
    43 × 29 = 1247 mod 51 = 23
so M = 23 = W

Answer: with the public key (3, 51), COW encrypts to the ciphertext 27, 9, 29; decryption with the private key (11, 51) gives 3, 15, 23, the plaintext COW.

2079 Bhadra · Q97 marksEncrypt the message "PANDEMIC" using RSA algorithm. Also obtain the plaintext from the ciphertext.

Given: the word PANDEMIC. Letters are numbered A = 1, B = 2, ..., Z = 26. Each letter is one block M.

Step 1: key generation. Choose the primes p=3 and q=11.

n=p×q=3×11=33φ(n)=(p−1)(q−1)=2×10=20

Choose e=3: 1<3<20 and gcd(3,20)=1. The data works: p and q are distinct primes, n=33>26 keeps every letter number below n (so no two letters can share a ciphertext), and e shares no factor with φ(n), so d exists.

Step 2: private exponent d=e−1modφ(n), by the extended Euclidean algorithm. Start r1=20, r2=3, t1=0, t2=1; each row q=⌊r1/r2⌋, r=r1−qr2, t=t1−qt2; stop when r2=0.

qr1r2rt1t2t
6203201−6
13211−67
2210−67−20
107−20

r1=1 confirms gcd(3,20)=1, and d=t1=7. Check: 3×7=21=1×20+1.

Public key (e,n)=(3,33); private key (d,n)=(7,33).

Step 3: encryption, C=M3mod33, and step 4: decryption, M=C7mod33, letter by letter:

LetterMM3C=M3mod33C7mod33Letter
P164096416P
A1111A
N142744514N
D464314D
E5125265E
M1321971913M
I972939I
C327273C

Decryption of two letters in full by repeated squaring, with d written as a sum of powers of 2:

Decrypt C = 4: M = 47 mod 33
d = 7 = 4 + 2 + 1
41 = 4
42 = 16
44 = 162 = 256 mod 33 = 25
47 = 44 × 42 × 41 = 25 × 16 × 4
    25 × 16 = 400 mod 33 = 4
    4 × 4 = 16
so M = 16 = P

Decrypt C = 31: M = 317 mod 33
d = 7 = 4 + 2 + 1
311 = 31
312 = 961 mod 33 = 4
314 = 42 = 16
317 = 314 × 312 × 311 = 16 × 4 × 31
    16 × 4 = 64 mod 33 = 31
    31 × 31 = 961 mod 33 = 4
so M = 4 = D

The letter A encrypts to its own number (1): 13=1 for any key. Every RSA key has a few such fixed values; decryption still returns them, so this is no slip.

Answer: with the public key (3, 33), PANDEMIC encrypts to the ciphertext 4, 1, 5, 31, 26, 19, 3, 27; decryption with the private key (7, 33) gives 16, 1, 14, 4, 5, 13, 9, 3, the plaintext PANDEMIC.

2078 Bhadra · Q98 marksEncrypt the word "Computer" using RSA algorithm.

Given: the word Computer. Letters are numbered A = 1, B = 2, ..., Z = 26, capital and lower case alike. Each letter is one block M.

Step 1: key generation. Choose the primes p=3 and q=23.

n=p×q=3×23=69φ(n)=(p−1)(q−1)=2×22=44

Choose e=5: 1<5<44 and gcd(5,44)=1. The data works: p and q are distinct primes, n=69>26 keeps every letter number below n (so no two letters can share a ciphertext), and e shares no factor with φ(n), so d exists.

Step 2: private exponent d=e−1modφ(n), by the extended Euclidean algorithm. Start r1=44, r2=5, t1=0, t2=1; each row q=⌊r1/r2⌋, r=r1−qr2, t=t1−qt2; stop when r2=0.

qr1r2rt1t2t
8445401−8
15411−89
4410−89−44
109−44

r1=1 confirms gcd(5,44)=1, and d=t1=9. Check: 5×9=45=1×44+1.

Public key (e,n)=(5,69); private key (d,n)=(9,69).

Step 3: encryption, C=M5mod69, and step 4: check by decryption, M=C9mod69, letter by letter:

LetterMC=M5mod69C9mod69Letter
C3363C
o153015o
m13413m
p165216p
u216021u
t205620t
e5205e
r18318r

Encryption in full by repeated squaring (write e as a sum of powers of 2, square and reduce mod 69, then multiply the powers needed):

Encrypt C: C = 35 mod 69
e = 5 = 4 + 1
31 = 3
32 = 9
34 = 92 = 81 mod 69 = 12
35 = 34 × 31 = 12 × 3
    12 × 3 = 36
so C = 36

Decryption of one letter in full by repeated squaring:

Decrypt C = 36: M = 369 mod 69
d = 9 = 8 + 1
361 = 36
362 = 1296 mod 69 = 54
364 = 542 = 2916 mod 69 = 18
368 = 182 = 324 mod 69 = 48
369 = 368 × 361 = 48 × 36
    48 × 36 = 1728 mod 69 = 3
so M = 3 = C

Answer: with the public key (5, 69), Computer encrypts to the ciphertext 36, 30, 4, 52, 60, 56, 20, 3 (written as numbers: a value above 26 has no letter). The private key (9, 69) decrypts it back to Computer.

2076 Chaitra · Q96 marksEncrypt the world HELLO using RSA algorithm. Also decrypt it by showing steps.

How this is readRead as “Encrypt the word HELLO”: the printed “world” is a slip for “word”.

Given: the word HELLO. Letters are numbered A = 1, B = 2, ..., Z = 26. Each letter is one block M.

Step 1: key generation. Choose the primes p=3 and q=23.

n=p×q=3×23=69φ(n)=(p−1)(q−1)=2×22=44

Choose e=5: 1<5<44 and gcd(5,44)=1. The data works: p and q are distinct primes, n=69>26 keeps every letter number below n (so no two letters can share a ciphertext), and e shares no factor with φ(n), so d exists.

Step 2: private exponent d=e−1modφ(n), by the extended Euclidean algorithm. Start r1=44, r2=5, t1=0, t2=1; each row q=⌊r1/r2⌋, r=r1−qr2, t=t1−qt2; stop when r2=0.

qr1r2rt1t2t
8445401−8
15411−89
4410−89−44
109−44

r1=1 confirms gcd(5,44)=1, and d=t1=9. Check: 5×9=45=1×44+1.

Public key (e,n)=(5,69); private key (d,n)=(9,69).

Step 3: encryption, C=M5mod69, and step 4: decryption, M=C9mod69, letter by letter:

LetterMC=M5mod69C9mod69Letter
H8628H
E5205E
L121812L
L121812L
O153015O

Encryption in full by repeated squaring (write e as a sum of powers of 2, square and reduce mod 69, then multiply the powers needed):

Encrypt H: C = 85 mod 69
e = 5 = 4 + 1
81 = 8
82 = 64
84 = 642 = 4096 mod 69 = 25
85 = 84 × 81 = 25 × 8
    25 × 8 = 200 mod 69 = 62
so C = 62

Decryption of every letter, step by step, by repeated squaring:

Decrypt C = 62: M = 629 mod 69
d = 9 = 8 + 1
621 = 62
622 = 3844 mod 69 = 49
624 = 492 = 2401 mod 69 = 55
628 = 552 = 3025 mod 69 = 58
629 = 628 × 621 = 58 × 62
    58 × 62 = 3596 mod 69 = 8
so M = 8 = H

Decrypt C = 20: M = 209 mod 69
d = 9 = 8 + 1
201 = 20
202 = 400 mod 69 = 55
204 = 552 = 3025 mod 69 = 58
208 = 582 = 3364 mod 69 = 52
209 = 208 × 201 = 52 × 20
    52 × 20 = 1040 mod 69 = 5
so M = 5 = E

Decrypt C = 18: M = 189 mod 69
d = 9 = 8 + 1
181 = 18
182 = 324 mod 69 = 48
184 = 482 = 2304 mod 69 = 27
188 = 272 = 729 mod 69 = 39
189 = 188 × 181 = 39 × 18
    39 × 18 = 702 mod 69 = 12
so M = 12 = L

Decrypt C = 30: M = 309 mod 69
d = 9 = 8 + 1
301 = 30
302 = 900 mod 69 = 3
304 = 32 = 9
308 = 92 = 81 mod 69 = 12
309 = 308 × 301 = 12 × 30
    12 × 30 = 360 mod 69 = 15
so M = 15 = O

Answer: with the public key (5, 69), HELLO encrypts to the ciphertext 62, 20, 18, 18, 30; decryption with the private key (9, 69) gives 8, 5, 12, 12, 15, the plaintext HELLO.

2076 Ashwin · Q96 marksEncrypt and decrypt “ROSE” using RSA algorithm.

Given: the word ROSE. Letters are numbered A = 1, B = 2, ..., Z = 26. Each letter is one block M.

Step 1: key generation. Choose the primes p=3 and q=11.

n=p×q=3×11=33φ(n)=(p−1)(q−1)=2×10=20

Choose e=7: 1<7<20 and gcd(7,20)=1. The data works: p and q are distinct primes, n=33>26 keeps every letter number below n (so no two letters can share a ciphertext), and e shares no factor with φ(n), so d exists.

Step 2: private exponent d=e−1modφ(n), by the extended Euclidean algorithm. Start r1=20, r2=7, t1=0, t2=1; each row q=⌊r1/r2⌋, r=r1−qr2, t=t1−qt2; stop when r2=0.

qr1r2rt1t2t
2207601−2
17611−23
6610−23−20
103−20

r1=1 confirms gcd(7,20)=1, and d=t1=3. Check: 7×3=21=1×20+1.

Public key (e,n)=(7,33); private key (d,n)=(3,33).

Step 3: encryption, C=M7mod33, and step 4: decryption, M=C3mod33, letter by letter:

LetterMC=M7mod33C3C3mod33Letter
R18621618R
O15271968315O
S1913219719S
E51427445E

Encryption in full by repeated squaring (write e as a sum of powers of 2, square and reduce mod 33, then multiply the powers needed):

Encrypt R: C = 187 mod 33
e = 7 = 4 + 2 + 1
181 = 18
182 = 324 mod 33 = 27
184 = 272 = 729 mod 33 = 3
187 = 184 × 182 × 181 = 3 × 27 × 18
    3 × 27 = 81 mod 33 = 15
    15 × 18 = 270 mod 33 = 6
so C = 6

Decryption of one letter in full by repeated squaring:

Decrypt C = 6: M = 63 mod 33
d = 3 = 2 + 1
61 = 6
62 = 36 mod 33 = 3
63 = 62 × 61 = 3 × 6
    3 × 6 = 18
so M = 18 = R

Answer: with the public key (7, 33), ROSE encrypts to the ciphertext 6, 27, 13, 14; decryption with the private key (3, 33) gives 18, 15, 19, 5, the plaintext ROSE.

2075 Ashwin · Q96 marksEncrypt a message "network" using RSA algorithm.

Given: the word network, in lower case. Lower-case letters take the same numbers as capitals: a = 1, b = 2, ..., z = 26. Each letter is one block M.

Step 1: key generation. Choose the primes p=3 and q=11.

n=p×q=3×11=33φ(n)=(p−1)(q−1)=2×10=20

Choose e=3: 1<3<20 and gcd(3,20)=1. The data works: p and q are distinct primes, n=33>26 keeps every letter number below n (so no two letters can share a ciphertext), and e shares no factor with φ(n), so d exists.

Step 2: private exponent d=e−1modφ(n), by the extended Euclidean algorithm. Start r1=20, r2=3, t1=0, t2=1; each row q=⌊r1/r2⌋, r=r1−qr2, t=t1−qt2; stop when r2=0.

qr1r2rt1t2t
6203201−6
13211−67
2210−67−20
107−20

r1=1 confirms gcd(3,20)=1, and d=t1=7. Check: 3×7=21=1×20+1.

Public key (e,n)=(3,33); private key (d,n)=(7,33).

Step 3: encryption, C=M3mod33, and step 4: check by decryption, M=C7mod33, letter by letter:

LetterMM3C=M3mod33C7mod33Letter
n142744514n
e5125265e
t2080001420t
w23121672323w
o153375915o
r1858322418r
k1113311111k

Decryption of one letter in full by repeated squaring, with d written as a sum of powers of 2:

Decrypt C = 5: M = 57 mod 33
d = 7 = 4 + 2 + 1
51 = 5
52 = 25
54 = 252 = 625 mod 33 = 31
57 = 54 × 52 × 51 = 31 × 25 × 5
    31 × 25 = 775 mod 33 = 16
    16 × 5 = 80 mod 33 = 14
so M = 14 = n

The letters w and k encrypt to their own numbers (23, 11): 233=12167 = 368×33+23, and 113=1331 = 40×33+11. Every RSA key has a few such fixed values; decryption still returns them, so this is no slip.

Answer: with the public key (3, 33), network encrypts to the ciphertext 5, 26, 14, 23, 9, 24, 11 (written as numbers: a value above 26 has no letter). The private key (7, 33) decrypts it back to network.

2073 Shrawan · Q85 marksExplain RSA algorithm with example.

Example: the word IOE. Letters are numbered A = 1, B = 2, ..., Z = 26. Each letter is one block M.

IOE, for the Institute of Engineering, is encrypted and decrypted with the smallest comfortable key, p=3 and q=11, through the four steps of RSA in order: key generation, the private exponent d, encryption, decryption.

Step 1: key generation. Choose the primes p=3 and q=11.

n=p×q=3×11=33φ(n)=(p−1)(q−1)=2×10=20

Choose e=3: 1<3<20 and gcd(3,20)=1. The data works: p and q are distinct primes, n=33>26 keeps every letter number below n (so no two letters can share a ciphertext), and e shares no factor with φ(n), so d exists.

Step 2: private exponent d=e−1modφ(n), by the extended Euclidean algorithm. Start r1=20, r2=3, t1=0, t2=1; each row q=⌊r1/r2⌋, r=r1−qr2, t=t1−qt2; stop when r2=0.

qr1r2rt1t2t
6203201−6
13211−67
2210−67−20
107−20

r1=1 confirms gcd(3,20)=1, and d=t1=7. Check: 3×7=21=1×20+1.

Public key (e,n)=(3,33); private key (d,n)=(7,33).

Step 3: encryption, C=M3mod33, and step 4: decryption, M=C7mod33, letter by letter:

LetterMM3C=M3mod33C7mod33Letter
I972939I
O153375915O
E5125265E

Decryption of one letter in full by repeated squaring, with d written as a sum of powers of 2:

Decrypt C = 3: M = 37 mod 33
d = 7 = 4 + 2 + 1
31 = 3
32 = 9
34 = 92 = 81 mod 33 = 15
37 = 34 × 32 × 31 = 15 × 9 × 3
    15 × 9 = 135 mod 33 = 3
    3 × 3 = 9
so M = 9 = I

Answer: with the public key (3, 33), IOE encrypts to the ciphertext 3, 9, 26; decryption with the private key (7, 33) gives 9, 15, 5, the plaintext IOE.

2072 Chaitra · Q98 marksEncrypt the word CAT using RSA algorithm, choose the suitable data for encryption by yourself according to RSA algorithm.

Given: the word CAT. Letters are numbered A = 1, B = 2, ..., Z = 26. Each letter is one block M.

Data chosen, and why it is suitable:

  • p = 3, q = 11: two different primes, small enough to work by hand.
  • n = 33: above 26, so the 26 letter numbers are 26 different values below n. A smaller n fails: p = 3, q = 7 gives n = 21, and V = 22 would act as 22 − 21 = 1, the same block as A.
  • e = 3: e must share no factor with φ(n) = 20, so 2, 4, 5, 6, 8 and 10 all fail (6 is not a factor of 20, yet shares the factor 2); 3 is the smallest e that works.
  • d = 7: follows from e by the extended Euclidean algorithm below.

Step 1: key generation. Choose the primes p=3 and q=11.

n=p×q=3×11=33φ(n)=(p−1)(q−1)=2×10=20

Choose e=3: 1<3<20 and gcd(3,20)=1. The data works: p and q are distinct primes, n=33>26 keeps every letter number below n (so no two letters can share a ciphertext), and e shares no factor with φ(n), so d exists.

Step 2: private exponent d=e−1modφ(n), by the extended Euclidean algorithm. Start r1=20, r2=3, t1=0, t2=1; each row q=⌊r1/r2⌋, r=r1−qr2, t=t1−qt2; stop when r2=0.

qr1r2rt1t2t
6203201−6
13211−67
2210−67−20
107−20

r1=1 confirms gcd(3,20)=1, and d=t1=7. Check: 3×7=21=1×20+1.

Public key (e,n)=(3,33); private key (d,n)=(7,33).

Step 3: encryption, C=M3mod33, and step 4: check by decryption, M=C7mod33, letter by letter:

LetterMM3C=M3mod33C7mod33Letter
C327273C
A1111A
T2080001420T

Decryption of one letter in full by repeated squaring, with d written as a sum of powers of 2:

Decrypt C = 27: M = 277 mod 33
d = 7 = 4 + 2 + 1
271 = 27
272 = 729 mod 33 = 3
274 = 32 = 9
277 = 274 × 272 × 271 = 9 × 3 × 27
    9 × 3 = 27
    27 × 27 = 729 mod 33 = 3
so M = 3 = C

The letter A encrypts to its own number (1): 13=1 for any key. Every RSA key has a few such fixed values; decryption still returns them, so this is no slip.

Answer: with the public key (3, 33), CAT encrypts to the ciphertext 27, 1, 14 (written as numbers: a value above 26 has no letter). The private key (7, 33) decrypts it back to CAT.

2072 Kartik · Q96 marksEncrypt and decrypt "OVEL" message using RSA algorithm.

Given: the word OVEL. Letters are numbered A = 1, B = 2, ..., Z = 26. Each letter is one block M.

Step 1: key generation. Choose the primes p=3 and q=17.

n=p×q=3×17=51φ(n)=(p−1)(q−1)=2×16=32

Choose e=3: 1<3<32 and gcd(3,32)=1. The data works: p and q are distinct primes, n=51>26 keeps every letter number below n (so no two letters can share a ciphertext), and e shares no factor with φ(n), so d exists.

Step 2: private exponent d=e−1modφ(n), by the extended Euclidean algorithm. Start r1=32, r2=3, t1=0, t2=1; each row q=⌊r1/r2⌋, r=r1−qr2, t=t1−qt2; stop when r2=0.

qr1r2rt1t2t
10323201−10
13211−1011
2210−1011−32
1011−32

r1=1 confirms gcd(3,32)=1, and d=t1=11. Check: 3×11=33=1×32+1.

Public key (e,n)=(3,51); private key (d,n)=(11,51).

Step 3: encryption, C=M3mod51, and step 4: decryption, M=C11mod51, letter by letter:

LetterMM3C=M3mod51C11mod51Letter
O153375915O
V22106484022V
E5125235E
L1217284512L

Decryption of one letter in full by repeated squaring, with d written as a sum of powers of 2:

Decrypt C = 40: M = 4011 mod 51
d = 11 = 8 + 2 + 1
401 = 40
402 = 1600 mod 51 = 19
404 = 192 = 361 mod 51 = 4
408 = 42 = 16
4011 = 408 × 402 × 401 = 16 × 19 × 40
    16 × 19 = 304 mod 51 = 49
    49 × 40 = 1960 mod 51 = 22
so M = 22 = V

Answer: with the public key (3, 51), OVEL encrypts to the ciphertext 9, 40, 23, 45; decryption with the private key (11, 51) gives 15, 22, 5, 12, the plaintext OVEL.

2068 Baishakh · Q96 marksEncrypt the message “DANGER” using RSA algorithm.

Given: the word DANGER. Letters are numbered A = 1, B = 2, ..., Z = 26. Each letter is one block M.

Step 1: key generation. Choose the primes p=3 and q=11.

n=p×q=3×11=33φ(n)=(p−1)(q−1)=2×10=20

Choose e=3: 1<3<20 and gcd(3,20)=1. The data works: p and q are distinct primes, n=33>26 keeps every letter number below n (so no two letters can share a ciphertext), and e shares no factor with φ(n), so d exists.

Step 2: private exponent d=e−1modφ(n), by the extended Euclidean algorithm. Start r1=20, r2=3, t1=0, t2=1; each row q=⌊r1/r2⌋, r=r1−qr2, t=t1−qt2; stop when r2=0.

qr1r2rt1t2t
6203201−6
13211−67
2210−67−20
107−20

r1=1 confirms gcd(3,20)=1, and d=t1=7. Check: 3×7=21=1×20+1.

Public key (e,n)=(3,33); private key (d,n)=(7,33).

Step 3: encryption, C=M3mod33, and step 4: check by decryption, M=C7mod33, letter by letter:

LetterMM3C=M3mod33C7mod33Letter
D464314D
A1111A
N142744514N
G7343137G
E5125265E
R1858322418R

Decryption of one letter in full by repeated squaring, with d written as a sum of powers of 2:

Decrypt C = 31: M = 317 mod 33
d = 7 = 4 + 2 + 1
311 = 31
312 = 961 mod 33 = 4
314 = 42 = 16
317 = 314 × 312 × 311 = 16 × 4 × 31
    16 × 4 = 64 mod 33 = 31
    31 × 31 = 961 mod 33 = 4
so M = 4 = D

The letter A encrypts to its own number (1): 13=1 for any key. Every RSA key has a few such fixed values; decryption still returns them, so this is no slip.

Answer: with the public key (3, 33), DANGER encrypts to the ciphertext 31, 1, 5, 13, 26, 24 (written as numbers: a value above 26 has no letter). The private key (7, 33) decrypts it back to DANGER.

Insights on Computer Networks, p. 238Encrypt the plaintext “E” with RSA, taking p = 7, q = 11 and e = 13, and decrypt the result.

How this is readInsights (p. 238) sets the decryption up as m = 2637 mod 77 and stops there; evaluated below, it gives 5, the letter E. Its other numbers (n = 77, z = 60, its name for φ(n), e = 13, C = 26, d = 37) are right.

Given: the letter E. Letters are numbered A = 1, B = 2, ..., Z = 26. Each letter is one block M.

Step 1: key generation. Given the primes p=7, q=11 and e=13.

n=p×q=7×11=77φ(n)=(p−1)(q−1)=6×10=60

Take e=13: 1<13<60 and gcd(13,60)=1. The data works: p and q are distinct primes, n=77>26 keeps every letter number below n (so no two letters can share a ciphertext), and e shares no factor with φ(n), so d exists.

Step 2: private exponent d=e−1modφ(n), by the extended Euclidean algorithm. Start r1=60, r2=13, t1=0, t2=1; each row q=⌊r1/r2⌋, r=r1−qr2, t=t1−qt2; stop when r2=0.

qr1r2rt1t2t
46013801−4
113851−45
1853−45−9
15325−914
1321−914−23
221014−2360
10−2360

r1=1 confirms gcd(13,60)=1, and d=t1+φ(n) = −23+60=37. Check: 13×37=481=8×60+1.

Public key (e,n)=(13,77); private key (d,n)=(37,77).

Step 3: encryption, C=M13mod77, and step 4: decryption, M=C37mod77, letter by letter:

LetterMC=M13mod77C37mod77Letter
E5265E

Encryption in full by repeated squaring (write e as a sum of powers of 2, square and reduce mod 77, then multiply the powers needed):

Encrypt E: C = 513 mod 77
e = 13 = 8 + 4 + 1
51 = 5
52 = 25
54 = 252 = 625 mod 77 = 9
58 = 92 = 81 mod 77 = 4
513 = 58 × 54 × 51 = 4 × 9 × 5
    4 × 9 = 36
    36 × 5 = 180 mod 77 = 26
so C = 26

Decryption of one letter in full by repeated squaring:

Decrypt C = 26: M = 2637 mod 77
d = 37 = 32 + 4 + 1
261 = 26
262 = 676 mod 77 = 60
264 = 602 = 3600 mod 77 = 58
268 = 582 = 3364 mod 77 = 53
2616 = 532 = 2809 mod 77 = 37
2632 = 372 = 1369 mod 77 = 60
2637 = 2632 × 264 × 261 = 60 × 58 × 26
    60 × 58 = 3480 mod 77 = 15
    15 × 26 = 390 mod 77 = 5
so M = 5 = E

Answer: with the public key (13, 77), E encrypts to the ciphertext 26; decryption with the private key (37, 77) gives 5, the plaintext E.

AES-128 on a word: one block, ten rounds PIN 2/27

Ch 8 · Network security2 from 2 of the 27 sittings

The method
  1. Bytes: write the word in ASCII (hex) and pad it to one 16-byte block by PKCS#7: when k bytes are missing, append k bytes, each of value k.
  2. State: fill a 4 × 4 byte matrix column by column (bytes 0 to 3 form column 0); the 16-byte key the same way.
  3. Key expansion: the key gives the words w0 to w3; then wi=wi−4⊕wi−1, except that for every fourth word wi−1 first goes through g: RotWord (one byte left), SubWord (S-box on each byte), XOR Rcon (01, 02, 04, 08, 10, 20, 40, 80, 1b, 36 in the first byte). Words w4r to w4r+3 are round key Kr: 11 keys.
  4. Round 0: AddRoundKey, the state XOR K0.
  5. Rounds 1 to 9, four steps each: SubBytes (each byte from the S-box: row = first hex digit, column = second); ShiftRows (row r rotated r bytes left); MixColumns (each column times the matrix 02 03 01 01 / 01 02 03 01 / 01 01 02 03 / 03 01 01 02 in GF(28), adding by XOR; 02·x is a left shift, XOR 1b when a 1 falls off the top; 03·x = 02·x XOR x); AddRoundKey with Kr.
  6. Round 10: SubBytes, ShiftRows, AddRoundKey with K10; no MixColumns.
  7. Ciphertext: the final state read column by column, 16 bytes (32 hex digits). Decryption runs the inverse steps in reverse order with the same key.
2082 Baishakh · Q96 marksEncrypt the word “ISPNet” using anyone suitable AES technique.

How this is read“Anyone suitable AES technique” is read as AES-128 (16-byte key, 10 rounds) in ECB mode on one 16-byte block, with a chosen key (any 16-character key serves).

Given: the word ISPNet, 6 characters. Technique: AES-128 (128-bit key, 10 rounds) on one 16-byte block, ECB mode.

Step 1: plaintext block. ASCII codes in hex: I = 49, S = 53, P = 50, N = 4e, e = 65, t = 74. PKCS#7 padding fills the block with 16 − 6 = 10 bytes, each of value 10 = 0a:

49 53 50 4e 65 74 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a

Step 2: key (chosen): the 16 characters Pulchowk Campus!, in hex:

50 75 6c 63 68 6f 77 6b 20 43 61 6d 70 75 73 21

Step 3: state matrices. The 16 bytes fill a 4 × 4 matrix column by column (bytes 0 to 3 are column 0); the key the same way, as round key K0:

Plaintext     Key = K0
49 65 0a 0a   50 68 20 70
53 74 0a 0a   75 6f 43 75
50 0a 0a 0a   6c 77 61 73
4e 0a 0a 0a   63 6b 6d 21

Step 4: key expansion. The key columns are the words w0 to w3. Every fourth word is wi=wi−4⊕g(wi−1), g = RotWord, SubWord, XOR Rcon; the others are wi=wi−4⊕wi−1. Round key K1 (w4 to w7):

w3               70 75 73 21
RotWord(w3)      75 73 21 70
SubWord          9d 8f fd 51
Rcon(1)          01 00 00 00
g(w3)            9c 8f fd 51
w0               50 75 6c 63
w4 = w0 XOR g    cc fa 91 32
w5 = w4 XOR w1   a4 95 e6 59
w6 = w5 XOR w2   84 d6 87 34
w7 = w6 XOR w3   f4 a3 f4 15

All eleven round keys, computed the same way (four words each):

K0   50756c63 686f776b 2043616d 70757321
K1   ccfa9132 a495e659 84d68734 f4a3f415
K2   c445c88d 60d02ed4 e406a9e0 10a55df5
K3   c6092e47 a6d90093 42dfa973 527af486
K4   14b66a47 b26f6ad4 f0b0c3a7 a2ca3721
K5   702c977d c243fda9 32f33e0e 9039092f
K6   422d821d 806e7fb4 b29d41ba 22a44895
K7   4b7fa88e cb11d73a 798c9680 5b28de15
K8   ff62f1b7 3473268d 4dffb00d 16d76e18
K9   eafd5cf0 de8e7a7d 9371ca70 85a6a468
K10  f8b41967 263a631a b54ba96a 30ed0d02

Step 5: round 0, AddRoundKey: the state XOR K0, byte by byte (first byte: 49 XOR 50 = 0100 1001 XOR 0101 0000 = 0001 1001 = 19):

Plaintext     K0            After round 0
49 65 0a 0a   50 68 20 70   19 0d 2a 7a
53 74 0a 0a   75 6f 43 75   26 1b 49 7f
50 0a 0a 0a   6c 77 61 73   3c 7d 6b 79
4e 0a 0a 0a   63 6b 6d 21   2d 61 67 2b

Step 6: round 1. SubBytes replaces every byte from the S-box (row = first hex digit, column = second; S(19) = d4). ShiftRows rotates row r by r bytes to the left (row 0 stays):

After round 0   SubBytes      ShiftRows
19 0d 2a 7a     d4 d7 e5 da   d4 d7 e5 da
26 1b 49 7f     f7 af 3b d2   af 3b d2 f7
3c 7d 6b 79     eb ff 7f b6   7f b6 eb ff
2d 61 67 2b     d8 ef 85 f1   f1 d8 ef 85

MixColumns multiplies each column by the fixed matrix (rows 02 03 01 01, 01 02 03 01, 01 01 02 03, 03 01 01 02) in GF(28), adding by XOR. 02·x shifts x one bit left and XORs 1b when a 1 falls off the top (02·d4: 1101 0100 becomes 1010 1000 = a8, XOR 1b = b3); 03·x = 02·x XOR x. Column 0 in full:

byte  a    02·a  03·a
a0    d4   b3    67
a1    af   45    ea
a2    7f   fe    81
a3    f1   f9    08

b0 = 02·a0 XOR 03·a1 XOR a2 XOR a3
   = b3 XOR ea XOR 7f XOR f1 = d7
b1 = a0 XOR 02·a1 XOR 03·a2 XOR a3
   = d4 XOR 45 XOR 81 XOR f1 = e1
b2 = a0 XOR a1 XOR 02·a2 XOR 03·a3
   = d4 XOR af XOR fe XOR 08 = 8d
b3 = 03·a0 XOR a1 XOR a2 XOR 02·a3
   = 67 XOR af XOR 7f XOR f9 = 4e

The other three columns the same way; then AddRoundKey with K1:

MixColumns    K1            After round 1
d7 96 b8 d7   cc a4 84 f4   1b 32 3c 23
e1 b8 93 b0   fa 95 d6 a3   1b 2d 45 13
8d e8 d0 5c   91 e6 87 f4   1c 0e 57 a8
4e 44 c8 6c   32 59 34 15   7c 1d fc 79

Step 7: rounds 2 to 10. Rounds 2 to 9 repeat the same four steps (SubBytes, ShiftRows, MixColumns, AddRoundKey with K2 to K9); round 10 leaves out MixColumns and adds K10. Computed, the state at the end of each round (read column by column) is:

Round 0   19263c2d 0d1b7d61 2a496b67 7a7f792b
Round 1   1b1b1c7c 322d0e1d 3c4557fc 2313a879
Round 2   1f1ac893 4662cc3d 960ceb74 ad9052e0
Round 3   b047b586 d7b8db20 168bfb1e 47fff8f4
Round 4   c5272573 ec9c1732 2608e1d8 c993c827
Round 5   6af24b29 7241423d a4c50ea9 ef0d40ad
Round 6   e641ea02 5dc77f8a d688cb4b f8d528f7
Round 7   6a2f660e 47e5aef0 7290f4f9 26aa6dfa
Round 8   193e388d 58fc7867 9d25b551 a1a4efc2
Round 9   6213e6b8 c9bd6d99 763147cd 41e52f89
Round 10  52ceb9c0 fbfd7676 8d922784 b39031bf

Answer: with the key Pulchowk Campus!, ISPNet (padded to 16 bytes) encrypts under AES-128 to the ciphertext 52ceb9c0fbfd76768d922784b39031bf (hex). Decryption with the same key (InvShiftRows, InvSubBytes, AddRoundKey, InvMixColumns, rounds in reverse) returns the padded block, and so the word ISPNet.

2081 Bhadra · Q96 marksEncrypt the word “ComNet” using anyone suitable AES technique.

How this is read“Anyone suitable AES technique” is read as AES-128 (16-byte key, 10 rounds) in ECB mode on one 16-byte block, with a chosen key (any 16-character key serves).

Given: the word ComNet, 6 characters. Technique: AES-128 (128-bit key, 10 rounds) on one 16-byte block, ECB mode.

Step 1: plaintext block. ASCII codes in hex: C = 43, o = 6f, m = 6d, N = 4e, e = 65, t = 74. PKCS#7 padding fills the block with 16 − 6 = 10 bytes, each of value 10 = 0a:

43 6f 6d 4e 65 74 0a 0a 0a 0a 0a 0a 0a 0a 0a 0a

Step 2: key (chosen): the 16 characters Pulchowk Campus!, in hex:

50 75 6c 63 68 6f 77 6b 20 43 61 6d 70 75 73 21

Step 3: state matrices. The 16 bytes fill a 4 × 4 matrix column by column (bytes 0 to 3 are column 0); the key the same way, as round key K0:

Plaintext     Key = K0
43 65 0a 0a   50 68 20 70
6f 74 0a 0a   75 6f 43 75
6d 0a 0a 0a   6c 77 61 73
4e 0a 0a 0a   63 6b 6d 21

Step 4: key expansion. The key columns are the words w0 to w3. Every fourth word is wi=wi−4⊕g(wi−1), g = RotWord, SubWord, XOR Rcon; the others are wi=wi−4⊕wi−1. Round key K1 (w4 to w7):

w3               70 75 73 21
RotWord(w3)      75 73 21 70
SubWord          9d 8f fd 51
Rcon(1)          01 00 00 00
g(w3)            9c 8f fd 51
w0               50 75 6c 63
w4 = w0 XOR g    cc fa 91 32
w5 = w4 XOR w1   a4 95 e6 59
w6 = w5 XOR w2   84 d6 87 34
w7 = w6 XOR w3   f4 a3 f4 15

All eleven round keys, computed the same way (four words each):

K0   50756c63 686f776b 2043616d 70757321
K1   ccfa9132 a495e659 84d68734 f4a3f415
K2   c445c88d 60d02ed4 e406a9e0 10a55df5
K3   c6092e47 a6d90093 42dfa973 527af486
K4   14b66a47 b26f6ad4 f0b0c3a7 a2ca3721
K5   702c977d c243fda9 32f33e0e 9039092f
K6   422d821d 806e7fb4 b29d41ba 22a44895
K7   4b7fa88e cb11d73a 798c9680 5b28de15
K8   ff62f1b7 3473268d 4dffb00d 16d76e18
K9   eafd5cf0 de8e7a7d 9371ca70 85a6a468
K10  f8b41967 263a631a b54ba96a 30ed0d02

Step 5: round 0, AddRoundKey: the state XOR K0, byte by byte (first byte: 43 XOR 50 = 0100 0011 XOR 0101 0000 = 0001 0011 = 13):

Plaintext     K0            After round 0
43 65 0a 0a   50 68 20 70   13 0d 2a 7a
6f 74 0a 0a   75 6f 43 75   1a 1b 49 7f
6d 0a 0a 0a   6c 77 61 73   01 7d 6b 79
4e 0a 0a 0a   63 6b 6d 21   2d 61 67 2b

Step 6: round 1. SubBytes replaces every byte from the S-box (row = first hex digit, column = second; S(13) = 7d). ShiftRows rotates row r by r bytes to the left (row 0 stays):

After round 0   SubBytes      ShiftRows
13 0d 2a 7a     7d d7 e5 da   7d d7 e5 da
1a 1b 49 7f     a2 af 3b d2   af 3b d2 a2
01 7d 6b 79     7c ff 7f b6   7f b6 7c ff
2d 61 67 2b     d8 ef 85 f1   f1 d8 ef 85

MixColumns multiplies each column by the fixed matrix (rows 02 03 01 01, 01 02 03 01, 01 01 02 03, 03 01 01 02) in GF(28), adding by XOR. 02·x shifts x one bit left and XORs 1b when a 1 falls off the top (02·af: 1010 1111 becomes 0101 1110 = 5e, XOR 1b = 45); 03·x = 02·x XOR x. Column 0 in full:

byte  a    02·a  03·a
a0    7d   fa    87
a1    af   45    ea
a2    7f   fe    81
a3    f1   f9    08

b0 = 02·a0 XOR 03·a1 XOR a2 XOR a3
   = fa XOR ea XOR 7f XOR f1 = 9e
b1 = a0 XOR 02·a1 XOR 03·a2 XOR a3
   = 7d XOR 45 XOR 81 XOR f1 = 48
b2 = a0 XOR a1 XOR 02·a2 XOR 03·a3
   = 7d XOR af XOR fe XOR 08 = 24
b3 = 03·a0 XOR a1 XOR a2 XOR 02·a3
   = 87 XOR af XOR 7f XOR f9 = ae

The other three columns the same way; then AddRoundKey with K1:

MixColumns    K1            After round 1
9e 96 2f 28   cc a4 84 f4   52 32 ab dc
48 b8 31 1a   fa 95 d6 a3   b2 2d e7 b9
24 e8 e5 09   91 e6 87 f4   b5 0e 62 fd
ae 44 5f 39   32 59 34 15   9c 1d 6b 2c

Step 7: rounds 2 to 10. Rounds 2 to 9 repeat the same four steps (SubBytes, ShiftRows, MixColumns, AddRoundKey with K2 to K9); round 10 leaves out MixColumns and adds K10. Computed, the state at the end of each round (read column by column) is:

Round 0   131a012d 0d1b7d61 2a496b67 7a7f792b
Round 1   52b2b59c 322d0e1d abe7626b dcb9fd2c
Round 2   6c7acc1d 0be248d6 ab08db96 8ad42006
Round 3   03cd3e48 b3f4993a e3061421 19cd5fb7
Round 4   6b14a1c6 44c41b67 3c8d8b80 deab85f4
Round 5   289354b8 30f4493d ee0f4769 ddece7dc
Round 6   d601c349 ea4d8a82 ac758e62 067233c3
Round 7   b551fd29 9ad21d80 bdfc2e60 d597d4e9
Round 8   a58bd16b 79cd4af7 a3bfa6de 0c4a84d3
Round 9   789005af 91b6fb15 b0e6d256 ee5ef7a0
Round 10  44faac87 a7b40b63 5213c233 188d02b3

Answer: with the key Pulchowk Campus!, ComNet (padded to 16 bytes) encrypts under AES-128 to the ciphertext 44faac87a7b40b635213c233188d02b3 (hex). Decryption with the same key (InvShiftRows, InvSubBytes, AddRoundKey, InvMixColumns, rounds in reverse) returns the padded block, and so the word ComNet.

Classical ciphers: Caesar, monoalphabetic, polyalphabetic BOOK

Ch 8 · Network securitynot set by a paper yet, 3 from the book

The method
  1. Caesar: number the letters a = 0 to z = 25 and move each one k places on, wrapping z round to a: C=(P+k)mod26; decryption P=(C−k)mod26. There are only 25 useful keys, so trying them all breaks it.
  2. Monoalphabetic: a fixed table gives every plaintext letter its own ciphertext letter (any rearrangement of the alphabet, 26! keys). Encrypt by looking each letter up, decrypt by the reverse lookup; letter frequencies still show through.
  3. Polyalphabetic: several Caesar (or monoalphabetic) ciphers used in turn by the position of the letter, for example C1, C2, C1 repeating, so one plaintext letter encrypts to different letters at different places.
  4. Spaces are kept and are not counted as positions; capital and lower case are treated alike.
Insights on Computer Networks, p. 231Using the Caesar cipher with key k = 2, encrypt the plaintext “I am a student”.

How this is readInsights (p. 231) prints the answer as “k co c UV FG PV”: the w that u becomes is missing. The full ciphertext is k co c uvwfgpv. Its rule says k places “behind” the letter; the shift runs forward (i to k), as its own example shows.

Given: plaintext I am a student, Caesar cipher with key k = 2: each letter moves 2 places on in the alphabet (y becomes a and z becomes b); spaces stay, and case is ignored.

Encryption, C=(P+2)mod26, letter by letter:

Plaintextiamastudent
Number (a = 0)80120181920341319
+ 2, mod 26102142202122561521
Ciphertextkcocuvwfgpv

Decryption moves every letter 2 places back, P=(C−2)mod26, and returns i am a student. Only 25 useful keys exist, so trying each one breaks the cipher at once.

Answer: k co c uvwfgpv.

Insights on Computer Networks, p. 231Encrypt the plaintext “attack” with the monoalphabetic key as printed: plaintext abcdefghijklmnopqrstuvwxyz, ciphertext mnbvcxzasdfghjkipoiuytrewq.

How this is readInsights (p. 231) prints the answer QZZQEA. That is what the keyboard key qwertyuiopasdfghjklzxcvbnm gives (a to q, t to z, c to e, k to a), not the key printed above it, which gives muumbf. The printed key also has i twice (16th and 19th places) and no l, so two letters would decrypt alike; with l in the 16th place it is a true key, and attack still gives muumbf.

Given: the monoalphabetic key (each plaintext letter above its ciphertext letter, with l in the 16th place) and the plaintext attack:

plain   a b c d e f g h i j k l m
cipher  m n b v c x z a s d f g h

plain   n o p q r s t u v w x y z
cipher  j k l p o i u y t r e w q

Encryption looks each letter up: a → m, t → u, t → u, a → m, c → b, k → f.

Decryption is the reverse lookup: m → a, u → t, b → c, f → k. There are 26! ≈4.03×1026 keys, far too many to try, yet letter frequencies (e is the commonest letter in English) still break it.

Answer: muumbf.

Insights on Computer Networks, p. 231Encrypt “I am a student” with two Caesar ciphers, C1 (k = 2) and C2 (k = 5), used in the repeating pattern C1, C2, C1.

Given: plaintext I am a student; C1 is a Caesar cipher with k = 2, C2 one with k = 5, used in the repeating pattern C1, C2, C1 over the letters (spaces skipped).

Plaintextiamastudent
Position1234567891011
CipherC1C2C1C1C2C1C1C2C1C1C2
Shift+2+5+2+2+5+2+2+5+2+2+5
Ciphertextkfocxvwigpy

The two a’s encrypt differently (f at position 2, c at position 4), which is what defeats simple letter counting. Decryption needs both keys and the pattern.

Answer: k fo c xvwigpy, as Insights gives it.

Diffie-Hellman key exchange BOOK

Ch 8 · Network securitynot set by a paper yet, 1 from the book

The method
  1. Public values: a large prime N (ideally with (N−1)/2 also prime) and a base G that is a primitive root modulo N: its powers G1,G2,…,GN−1 take every value 1 to N−1.
  2. A picks a secret x and sends R1=GxmodN.
  3. B picks a secret y and sends R2=GymodN.
  4. A computes K=R2xmodN; B computes K=R1ymodN.
  5. Both now hold K=GxymodN, the shared symmetric key. An eavesdropper sees N, G, R1 and R2, but finding x or y from them is the discrete logarithm problem.
Insights on Computer Networks, p. 240Diffie-Hellman with N = 23 and G = 7: A chooses x = 3 and B chooses y = 6. Find R1, R2 and the shared key K.

How this is readInsights (p. 239) asks for G to be a prime number. The condition is that G is a primitive root modulo N: 7 is one for N = 23, while the prime 2 is not (211 mod 23 = 1, so its powers take only 11 values). The arithmetic of the example is right.

Given: N = 23 (a prime, and (N−1)/2=11 is prime too), G = 7; A's secret x = 3, B's secret y = 6.

Step 1, A: R1=GxmodN = 73mod23 = 343mod23=21. A sends 21 to B.

Step 2, B: R2=GymodN=76mod23 by repeated squaring:

y = 6 = 4 + 2
71 = 7
72 = 49 mod 23 = 3
74 = 32 = 9
76 = 74 × 72 = 9 × 3
    9 × 3 = 27 mod 23 = 4

So R2=4. B sends 4 to A.

Step 3, A: K=R2xmodN = 43mod23 = 64mod23=18.

Step 4, B: K=R1ymodN = 216mod23:

y = 6 = 4 + 2
211 = 21
212 = 441 mod 23 = 4
214 = 42 = 16
216 = 214 × 212 = 16 × 4
    16 × 4 = 64 mod 23 = 18

Check: K=GxymodN = 718mod23=18. The base is sound: 7 is a primitive root modulo 23, since 72mod23=3 and 711mod23=22, neither 1, so its powers run through all 22 values.

Answer: R1=21, R2=4, and both sides compute the same shared key K = 18.

Every question the papers asked · 27 sittings · 2066 Bhadra to 2082 Bhadra

The complete question bank

All 269 questions of the 27 sittings, reproduced verbatim: only what a paper has actually asked. Read them by paper, newest first, or by chapter, where repeats are merged and counted. Every question links to its written answer and to the card that teaches it.

How to use the bank

  • By paper: sit a paper from the top, then open each answer. The board papers, 2081 and 2082 Bhadra, are the best guide to the next one.
  • By chapter: revise a chapter, then answer its questions. A question set in several sittings appears once, with how many times and when, and every other wording under it.
  • Answer links open the exact answer to write; Study links open the card that teaches the topic. A question with two answer links has two parts.

Regular2082 Bhadra

2082 Bhadra · Regular · BCT · 10 questions

Ch 24+2

Q2. Explain line of sight (LOS) propagation modes. Draw block diagram generic optical fiber (OF) communication system and its RF range.

Ch 34+4

Q3. Write different ways to correct backward error correction. Compare pure Aloha and slotted Aloha mentioning the condition for no collision.

Ch 4Numerical8

Q5. Suppose a company XYZ has an IP address of 160.24.96.0/21 and it has 6 departments containing 1024, 750, 254, 500, 151 and 45 users and also include point-point links. List out the CIDR, network address, broadcast address, usable host range and wasted IP address in each subnet.

Ch 52+3+3

Q6. Write UDP header field and functions. Explain TCP 3-way hand shaking for connection establishment and release.

Ch 62+6

Q7. Compare DNS recursive query vs. iterative query. Explain iterative query for browsing www.youtube.com

Ch 72+6

Q8. List the IPv6 extension headers in order. Explain ISATAP and 6 to 4 tunneling with their address format for IPv4 to IPv6 transition.

Ch 8Numerical2+4+2

Q9. What do you mean by firewall? Encrypt and decrypt the “attack” using RSA.

Back2082 Baishakh

2082 Baishakh · Back · BCT · 10 questions

Ch 14+4

Q1. Explain client/server and P2P network model with their advantages and disadvantages. Discuss the layer of TCP/IP model with suitable diagram.

Ch 32+3+3

Q2. What are the functions of data link layer? How to detect signal collision in CSMA/CD? List the ethernet cable specification standards for 802.3 ethernet standards.

Ch 3Numerical1+2+5

Q3. What is hamming distance? How do you apply it in data link layer error control mechanism? Calculate the CRC for a 8 bit sequence 11001101. The generator polynomial is x⁴ + x² + 1. Also find the transmitted bit frame.

Ch 4Numerical1+7

Q5. List the range of IPv4 address classes. You have to assign addresses to four departmental LANs with following hosts 14, 55, 10 and 29 addresses respectively from the given IP address block: 202.97.43.0/25. Perform the subnetting and find out subnet mask, network address, broadcast address and usable host IP ranges.

Ch 62+6

Q7. How does a DNS recursive query work? Discuss DHCP lease renew process with example diagram.

Ch 72+2+4

Q8. Map IPv4 addresses with its IPv6 equivalent. What are the latest best IPv6 transition methodologies? Explain anyone of them.

Ch 8Numerical2+6

Q9. What is router ACL? How do you apply ACL to block the IP network 202.70.91.0/24 incoming to interface Fast Ethernet of a router? Encrypt the word “ISPNet” using anyone suitable AES technique.

Regular2081 Bhadra

2081 Bhadra · Regular · BCT · 10 questions

Ch 22+6

Q2. What are the factors to be considered while selecting media for communication? Differentiate between datagram and virtual circuit switching approach with respect to Frame Relay Network.

Ch 3Numerical1+2+5

Q3. What is piggy-backing? How do you apply it in data link layer flow control mechanism? Calculate the CRC for a 10 bit sequence 1010001101. The generator polynomial is x⁵ + x⁴ + x² + 1. Also find the transmitted bit frame.

Ch 42+2+4

Q4. What is adaptive and non-adaptive routing? List the properties of link state routing and mention the method that how Designated Router (DR) is elected in OSPF routing.

Ch 4Numerical1+7

Q5. What is super-netting? Perform the subnetting of IPv4 address block 200.74.20.0/24 for five different departments having 4, 54, 120, 12 and 30 hosts. List out the network address, broadcast address, usable host range and wasted IP address in each subnet.

Ch 52+2+4

Q6. Why TCP is known as reliable protocol? What are the congestion control techniques applied in network communication? Discuss Token Bucket approach and compare it with leaky bucket.

Ch 62+6

Q7. What do you mean by DNS delegation? List the step-by-step working principle of SMTP.

Ch 74+4

Q8. Critically compare IPv4 and IPv6 in terms of routing and head manipulation. Explain the importance and implementation approach of 6RD for IPv6 based services on the existing IPv4 networking.

Ch 8Numerical2+6

Q9. What are the fundamental difference between AES and DES? Encrypt the word “ComNet” using anyone suitable AES technique.

Back2081 Baishakh

2081 Baishakh · Back · BCT · 10 questions

Ch 23+5

Q2. List out the most common guided and unguided transmission media used in computer networks now a days. Explain any one of the guided transmission media with examples.

Ch 32+2+4

Q3. What is CSMA/CD? Why is it not applicable in wireless LAN? What are the techniques used to avoid the possible collisions in WLAN? Explain.

Ch 4Numerical3+5

Q4. In which case VLSM is used while dividing the given block of IP addresses for different subnets and why? Suppose your company has IP address block of 16.16.16.0/21. Divide this IP address for five different departments of the company equally. List out the network address, broadcast address, subnet mask and usable IP address range for each subnet.

Ch 48

Q5. What is ICMP? Explain the importance and uses of ICMP in TCP/IP protocol suit.

Ch 53+5

Q6. Though UDP is said to be unreliable protocol, it is used in Internet. Why? Explain the three way handshake principle of a TCP connection between client and server.

Ch 64+4

Q7. What is a proxy server? Why is it used? Discuss briefly on HTTP and HTTPS services.

Ch 74+4

Q8. Compare the IPv4 header with IPv6 header. Explain the dual stack strategy to transit from IPv4 to IPv6.

Ch 8Numerical1+7

Q9. What is public key cryptography? Encrypt the word "security" using the RSA algorithm. Also show the decryption to obtain the plaintext.

Regular2080 Bhadra

2080 Bhadra · Regular · BCT · 10 questions

Ch 13+5

Q1. Differentiate between Client Server and Peer to Peer architecture. Discuss the functions of each layer of Open System Interconnection (OSI) model.

Ch 2Numerical3+3+2

Q2. a) Discuss about the different factors of choosing the transmission media." Circuit switching is suitable for real-time communication", give your reasons. If a file of 1000 bytes was sent over a network in 2 seconds, calculate throughput.

Ch 3Numerical3+5

Q3. Explain how does CRC detect the errors. Given message is M (x) = x7 + x4 +x3 +x2 + 1 and the generator is G (x) = x3 + 1. Show the actual bit string transmitted, suppose the third bit from the left is inverted during the transmission. Show how the error is detected at the receiver's end.

Ch 4Numerical8

Q4. Suppose a company has IP address of 10.20.30.0/24 and it has 4 LANs containing 4,64,24,18 number of hosts. Also, there are 4 WAN links to connect LAN1 - LAN2, LAN2 - LAN3, LAN3 - LAN4 and LAN1 - LAN3. List out the subnet wasted IP addresses for each LAN.

Ch 43+5

Q5. What is DR and BDR in OSPF? How do OSPF routers come into fully adacency states? Explain.

Ch 54+4

Q6. How does the transport layer ensure that the complete message arrive at the destination and in the proper order? How does Token Bucket control the congestion over the Leaky Bucket algorithm?

Ch 73+5

Q8. Explain the three address types in IPv6 with the IP notations. How does on IPv6 machine acquire IPv6 address automatically?

Ch 8Numerical2+6

Q9. What are the properties of secure communication? Use RSA algorithm to encrypt and decrypt the message "network".

Back2080 Baishakh

2080 Baishakh · Back · BCT · 10 questions

Ch 13+5

Q1. Why do we need layered architecture in computer network? Discuss the function of each layer of TCP/IP networking model.

Ch 21+2+5

Q2. What is multiplexing? What is its importance in communication? Explain different types of multiplexing techniques.

Ch 48

Q3. What is a bridge? How does it work? How can a bridge increase the throughout as compared with a repeater while extending a LAN? Explain with suitable diagrams.

Ch 4Numerical8

Q5. Suppose a company has IP address of 200.80.40.0/24 with 5 departments containing 29, 5, 16, 43, 14, number of hosts. Also there are point to point links between the departments. List out the subnet mask, network address, broadcast address, usable host IP ranges and no. of wasted IP addresses for each subnet.

Ch 52+4+2

Q6. What is port number? Why is it necessary to standardize the port numbers for well-known servers? What happens when a web service is hosted at some different port such as 8765 instead of 80? Explain.

Ch 8Numerical3+5

Q9. What is PGP? Use RSA algorithm to encrypt/decrypt the word COW.

Regular2079 Bhadra

2079 Bhadra · Regular · BCT · 10 questions

Ch 18

Q1. Compare the OSI reference model and TCP/IP reference model mentioning their similarities and differences.

Ch 24+4

Q2. What is switching and multiplexing? Explain switching technique used in modern computer networks.

Ch 34+4

Q3. How CSMA/CD works? Describe Ethernet (IEEE 802.3) frame structure with function of each field.

Ch 44+4

Q4. Why do we prefer a switch as networking device instead of Hub for LAN connection? Give reasons. Discuss the characteristics of a good routing algorithm.

Ch 4Numerical8

Q5. An ISP provided you an IP address block of 172.24.96.0/21. Suppose you need to divide this for four different departments A, B, C and D having 750, 200, 500 and 45 hosts respectively with minimum wastage of IP addresses. Also allocate IP addresses for three point-to-point links in the network. Find out the network address, broadcast address, subnet mash and usable host range of IP addresses for each subnet.

Ch 54+4

Q6. What are the features of UDP protocol? In which case is UDP preferred as a transport layer protocol? Discuss with practical examples.

Ch 62+2+4

Q7. What is DNS? Why is it used? How is the DNS request from a client computer resolved from the authoritative server? Explain with necessary diagrams.

Ch 72+2+4

Q8. What are the problems of IPV4? How can IPV6 reduce these problems? Explain header translation mechanism for transition from IPV4 to IPV6.

Ch 8Numerical1+7

Q9. What is a digital signature? Encrypt the message "PANDEMIC" using RSA algorithm. Also obtain the plaintext from the ciphertext.

Regular2078 Bhadra

2078 Bhadra · Regular · BCT · 10 questions

Ch 13+5

Q1. How does the client-server model work? Differentiate it with peer-to-peer network with advantages and disadvantages.

Ch 2Numerical1+3+4

Q2. Define Throughput. A network with bandwidth of 20 Mbps can pass only an average of 18,000 frames per minute with each frame carrying an average of 20,000 bits. Calculate the throughput of this network. Differentiate between Packet switching and Virtual Circuit switching.

Ch 34+4

Q3. Explain Go-back-N ARQ and selective Repeat ARQ with example. How carrier sense multiple access with collision detection (CSMA/CD) is better than CSMA?

Ch 4Numerical8

Q4. Consider IP block of 202.50.0.0/24 and six departments with 125, 59, 27, 14, 4 and 2 hosts respectively. Perform the subnetting so that wastage of IP addresses is minimum and find out the subnet mask, network address, broadcast address, wasted IP addresses and usable host ranges in each network.

Ch 43+5

Q5. Define routing algorithm. List out the properties/goals of routing algorithm. What is link state routing algorithm? Show how routing tables is populated in LSR with example.

Ch 53+5

Q6. What are services provided by Transport layer? Explain about Leaky-Bucket algorithm for congestion control?

Ch 63+5

Q7. What are resource records in DNS? Explain the types of DNS queries with example.

Ch 72+6

Q8. List advantages of IPv6 over IPv4. Explain any two suitable transition strategies for IPv4 to IPv6.

Ch 8Numerical8

Q9. Write down the steps involved in RSA encryption algorithm. Encrypt the word "Computer" using RSA algorithm.

Regular2076 Chaitra

2076 Chaitra · Regular · BCT · 10 questions

Ch 31+1+6

Q3. What is collision? How is it occured? How the possibility of collision is reduced in IEEE 802.3 and IEEE 802.11? Explain.

Ch 4Numerical8

Q4. Suppose your company has leased the IP address of 222.70.94.0/24 from your ISP. Divide it far five different departments containing 50, 30, 25, 12, 10 no of hosts. There are also two points to point links far interconnection between routers. List out the network address, broadcast address, usable IP address range and subnet mask for each subnet. Also mention the unused range of IP addresses.

Ch 44+1+3

Q5. What is the purpose of Time to live (TTL) and protocol field in header of IPv4 datagram. Which protocol is used in internet layer to provide feedback to hosts/routers about the problems in the network environment? What is ARP and how does it work?

Ch 73+5

Q8. "IPv4 and IPv6 coexistence" what does this mean? Explain Dual stack approach with an appropriate figure.

Ch 8Numerical2+6

Q9. How does a Digital Signature work? Encrypt the world HELLO using RSA algorithm. Also decrypt it by showing steps.

Ch 84+4

Q10. Explain briefly the desirable properties of secure communication. Explain how packet filtering firewall works.

Back2076 Ashwin

2076 Ashwin · Back · BCT · 10 questions

Ch 14+4

Q1. What are the features of Client/Server Architecture? What are headers and trailers and how do they get added and removed?

Ch 22+6

Q2. Why the telephone companies developed ISDN? Explain the working principle of ISDN with its interface and functional group.

Ch 38

Q3. Explain the working principle of CSMA/CD with appropriate figure.

Ch 4Numerical8

Q4. Institute of Engineering has six departments having 16, 32, 61, 8, 6 and 24 computers. Use 192.168.1.0/24 to distribute the network. Find the network address, broadcast address, usable IP range and subnet mask in each department.

Ch 54+4

Q6. Explain the TCP segment structure. Why TCP is known as reliable protocol and also describe how reliability is provided by TCP?

Ch 62+6

Q7. What is TFTP? Explain working principle of FTP with data transfer process including proper port connection. Use proper diagram to justify your answer.

Ch 72+6

Q8. List the advantages of IPv6 over IPv4. Explain any two transition strategies for IPv4 to IPv6.

Ch 8Numerical2+6

Q9. List the properties of secure communication. Encrypt and decrypt “ROSE” using RSA algorithm.

Regular / Back2075 Chaitra

2075 Chaitra · Regular / Back · BCT · 10 questions

Ch 12+6

Q1. Draw the architecture for Client/Server network model. Explain in details about P2P network model with supportive examples.

Ch 21+2+5

Q2. What is switching? What are the various switching techniques? Elaborate packet switching with a proper diagram.

Ch 32+6

Q3. What are multiple access protocols? Describe the various framing techniques at data link layer.

Ch 4Numerical8

Q4. Suppose you are a private consultant hired by the large company to setup the network for their enterprise and you are given a large number of consecutive. IP address starting at 120.89.96.0/19. Suppose that four departments A, B, C and D request 100, 500, 800 and 400 addresses respectively, how the subnetting can be performed so, that address wastage will be minimum?

Ch 42+6

Q5. What do you mean by autonomous system? Explain how routing loops are prevented in Distance Vector Routing with examples.

Ch 54+4

Q6. Explain connection establishment and termination in TCP. Explain briefly about Leaky-Bucket algorithm for congestion control?

Ch 73+5

Q8. “IPv4 and IPv6 coexistence” what does this mean? Explain what you mean by address family translation in IPv4/IPv6 migration process with an appropriate figure.

Ch 84+4

Q9. Explain briefly the desirable properties of secure communication. Explain how Packet filtering firewall Works.

Back2075 Ashwin

2075 Ashwin · Back · BCT · 10 questions

Ch 12+4+2

Q1. Why layering is important? Explain design issues for layers in detail. Mention service primitives for implementing connection oriented service.

Ch 3Numerical3+3+2

Q3. State the various design issues for the data link layer. What is piggybacking? A bit string 01111011111101111110 needs to be transmitted at the data link layer. What is the string actually transmitted after bit stuffing?

Ch 4Numerical8

Q5. Design a network for 5 departments containing 29, 14, 15, 23 and 5 computers. Take a network example IP 202.83.54.91/25.

Ch 53+5

Q6. What are the differences between TCP and UDP services? Explain the TCP datagram format in detail.

Ch 66+2

Q7. Define socket programming. How web server communication and file server communication are possible in network. Explain with used protocols.

Ch 8Numerical2+6

Q9. What is VPN? Encrypt a message "network" using RSA algorithm.

Regular2074 Chaitra

2074 Chaitra · Regular · BCT · 10 questions

Ch 13+5

Q1. Distinguish between Client-Server network and Peer-Peer network. Explain Open System Interconnection (OSI) model.

Ch 3, 24+4

Q3. What is the main functionality of data link layer? Differentiate between circuit switching and packet switching.

Ch 4Numerical8

Q5. How can you dedicate 32, 65, 10, 21, 9 public IP address to the departments A, B, C, D and E respectively form the pool of class C IP addresses with minimum loss. Explain.

Ch 65+3

Q7. Which protocols are used in sending and receiving an email? Illustrate with necessary figure. Give a comparison of POP3 and IMAP.

Ch 74+4

Q8. What are the factors that lead to the speedy development of IPv6? Define the process of transition from IPv4 to IPv6.

Ch 85+3

Q9. Define type of Encryption used in security. How PGP can secure email communication?

Back2074 Ashwin

2074 Ashwin · Back · BCT · 10 questions

Ch 12+6

Q1. What is the significance of OSI layer? Explain different layers of OSI with its functionalities.

Ch 22+6

Q3. What are the causes of packet delay in computer networks? What are the differences between circuit switching and packet switching?

Ch 4Numerical8

Q5. Suppose you are a private consultant hired by a company to setup the network for their enterprise and you are given a large number of consecutive IP address starting at 120.89.96.0/19. Suppose that four departments A, B, C and D request 100, 500, 800 and 400 addresses respectively, how the subnetting can be performed so that address wastage will be minimum?

Ch 55+3

Q6. Explain the TCP protocol with its Header. What do you understand by socket? Explain with its importance.

Ch 66+2

Q7. What is recursive and iterative query? Explain with suitable diagram. Discuss the DNS records.

Ch 74+4

Q8. List the advantages of IPv6 over IPv4. Explain header translation and tunneling approach used for migrating IPv4 to IPv6.

Ch 84+4

Q9. Explain briefly the desirable properties of secure communication. Explain how Packet filtering firewall Works.

New Back (2066 & Later Batch)2073 Shrawan

2073 Shrawan · New Back (2066 & Later Batch) · BCT · 10 questions

Ch 22+2+4

Q2. What do you mean by switching in communication? Compare switching with multiplexing. Explain the E1 Telephone hierarchy system.

Ch 32+2+4

Q3. What do you understand by Media Access Control? What is its significance in data link layer? Explain why token bus is also called as the token ring.

Ch 4Numerical8

Q4. You are a private contractor hired by the large company to setup the network for their enterprise and you are given a large number of consecutive IP address starting at 202.70.64.0/19. Suppose that four department A, B, C and D request 100, 500, 800 and 400 addresses respectively, how the subnetting can be performed so, that address wastage will be minimum?

Ch 5, 42+2+4

Q5. Discuss about the network congestion? Explain how different network parameters effect the congestion. Compare operation of link state routing with the distance vector routing.

Ch 66+2

Q6. How web server communication and file server communication are possible in network, explain with used protocols. Define socket programming.

Ch 74+4

Q7. What are the factors that lead to the development of IPv6? Define the process of transition from IPv4 to IPv6.

Ch 82+6

Q9. What do you mean by firewall? Explain different types of firewall.

Regular2072 Chaitra

2072 Chaitra · Regular · BCT · 10 questions

Ch 15+3

Q1. Compare OSI layer with TCP/IP Layer? Explain in which level of OSI layer following tasks are done. i) Error detection and correction ii) Encryption and Decryption of data iii) Logical identification of computer iv) Point-to-point connection of socket v) Dialogue control vi) Physical identification of computer

Ch 1, 45+3

Q2. Explain five instances of how networks are a part of your life today. Through we have MAC address, why do we use IP address to represent the host in networks? Explain your answer.

Ch 38

Q3. Briefly explain different types of Data Link Layer framing mechanisms. List the features of FDDI.

Ch 4Numerical8

Q4. Explain how can you allocate 30, 24, 25 and 20 IP addresses to the four different department of ABC company with minimum wastage. Specify the range of IP addresses, Broadcast Address, Network Address and Subnet mask for each department form the given address pool 202.77.19.0/24.

Ch 4, 54+4

Q5. What is routed and routing protocol? Give examples. Explain Token Bucket algorithm.

Ch 53+5

Q6. For the client-server application over TCP, why must the server program be executed before the client program? TCP is known as reliable process how, describe reliability is provided by TCP.

Ch 74+4

Q7. Compare the header fields of IPV6 and IPV4. Which method do you suggest for the migration of IPv6 and why?

Ch 88

Q8. Explain briefly how firewalls protect network and also explain different types of Firewall. Illustrate your answer with appropriate figures.

Ch 8Numerical8

Q9. Write down the steps involved in RSA encryption algorithm. Encrypt the word CAT using RSA algorithm, choose the suitable data for encryption by yourself according to RSA algorithm.

New Back (2066 & Later Batch)2072 Kartik

2072 Kartik · New Back (2066 & Later Batch) · BCT · 10 questions

Ch 48

Q1. You are assigned to design a network infrastructure for a 3-star hotel. Recommend a network solution with hardwares and softwares in current trend that can be used in the hotel. Make necessary assumptions and justify your recommadation with logical arguments where possible.

Ch 22+6

Q2. List out the functions of physical layer in TCP/IP reference model. Explain different types of transmission media.

Ch 33+5

Q3. What are the functions of data-link layer? Explain the channel allocation problem with example.

Ch 42+6

Q4. What are the functions of network layer? Explain briefly about multicast routing protocols and unicast routing protocols.

Ch 62+6

Q7. What are the different components of email server? Explain different types of electronic mail sending and accessing protocol.

Ch 72+6

Q8. What is IPV6? What methods are used so that IPV6 and IPV4 networks are interoperable?

Ch 8Numerical1+1+6

Q9. What is firewall? What are their types? Encrypt and decrypt "OVEL" message using RSA algorithm.

Ch 84×2

Q10. Write short notes on: a) Digital signature b) IPSec

Regular2071 Chaitra

2071 Chaitra · Regular · BCT · 10 questions

Ch 22+6

Q2. What is ISDN? Explain about the ISDN architecture in detail with example.

Ch 4Numerical10

Q5. You are given the following address space 10.10.10.0/24. You have to assign addresses to 4 departments with the following hosts 5, 16, 23 and 27 respectively. Perform the subnetting in such a way that the IP address wastage in each department are minimum. Also find out the subnet mask, network address, broadcast address and unassigned range in each department.

Ch 62+6

Q7. What is DNS? Explain the structure of DNS request and response with practical example.

Ch 72+2+4

Q8. What are the problems of IPv4? How IPv6 reduce these problems? Explain different strategies to transit from IPv4 and IPv6.

New Back (2066 & Later Batch)2071 Shrawan

2071 Shrawan · New Back (2066 & Later Batch) · BCT · 10 questions

Ch 68

Q7. SMTP is a text based protocol and uses 7 bit ascii. How can this be used to transmit sometimes like images? Explain.

Ch 72+6

Q8. What are the drawbacks in IPV4? Which of these drawbacks do IPV6 solve? Explain.

Ch 82+6

Q9. What is cryptography? Differentiate between symmetric key and public key cryptography.

Regular2070 Chaitra

2070 Chaitra · Regular · BCT · 10 questions

Ch 14+4

Q1. What are the features of Client/Server Architecture? What are headers and trailers and how do they get added and removed? Explain.

Ch 28

Q2. What do you mean by data switching? Explain about various types of switching with practical implementation example.

Ch 3Numerical5+3

Q3. What is the difference between Error Correcting and Error detection process? A bit string 01111011111011111110 needs to be transmitted at the data link layer what is string actually transmitted after bit stuffing, if flag patterns is 01111110.

Ch 48

Q4. Explain the working principle of different types of network devices Repeater, HUB, Bridge, Switch and Router.

Ch 4Numerical8

Q5. How can you dedicate 10, 12, 8, 14 public IP addresses to department A, B, C and D respectively from the pool of class C with minimum losses of IP? Explain.

Ch 58

Q6. Explain the UDP segment structure. Illustrate your answer with appropriate figures.

Ch 62+6

Q7. What do you mean by email server? What are the protocols used on it?

Ch 78

Q8. Explain the IPv6 datagram format with appropriate figures.

Ch 88

Q9. Explain briefly how firewalls protect network and also explain different types of Firewall. Illustrate your answer with appropriate figures.

Ch 83+5

Q10. What do you mean by Network security? Explain the operation of Data Encryption Standard Algorithm?

Old Back (2065 & Earlier Batch)2070 Ashad

2070 Ashad · Old Back (2065 & Earlier Batch) · BCT · 10 questions

Ch 14+4

Q1. What do you mean by protocol and interfaces? Write the protocols used in each layer of ICP/IP model.

Ch 13+5

Q2. How do you define network topology? Discuss the types of network topologies based on its size and geographical distributions.

Ch 32+2+6

Q3. What are the functions of LLC and MAC sub-layer? Discuss different farming approaches used in data link layer.

Ch 36

Q4. How data transfer occurs in Ethernet network? Explain.

Ch 32+2+4

Q5. Discuss how CSMA works? Differentiate it with CSMA-CD. Explain the optical fiber cabling standards with examples.

Ch 43+5

Q7. Differentiate between adaptive and non-adaptive routing. Explain shortest path finding algorithm in link state routing.

Ch 53+5

Q8. Compare between leaky bucket and token bucket algorithm with the operation how token bucket works.

Ch 3, 54+4

Q10. Write short notes on: a) ALOHA system b) TCP header

Regular2069 Chaitra

2069 Chaitra · Regular · BCT · 10 questions

Ch 16+2

Q1. Explain the need of Networking Software in the form of Hierarchy? Mention in which level layer of OSI reference model following tasks are done. i) Timing and voltage of received signal ii) Encryption and decryption of data iii) Data framing iv) Point-to-point connection of socket.

Ch 24+4

Q2. Define switching and multiplexing. Differentiate between circuit switching and packet switching.

Ch 38

Q3. Explain different types of Data link layer framing mechanisms.

Ch 4Numerical8

Q4. What is the contribution of sub-netting in IP address management? Show the importance in this case. Banijya bank need to allocate 15 IPs in HR department, 30 in finance department, 24 in customer care unit and 25 in ATM machines. If you have one network of class C range public IP address. Describe how you will manage it.

Ch 43+5

Q5. Why is routing protocol necessary? Explain the working process of Routing Information protocol (RIP) with example.

Ch 55+3

Q6. Why do you think that there exist two protocols in transport layer where as there exists only one protocol in Internet layer in TCP/IP reference model. Explain token bucket algorithm for congestion control.

Ch 62+6

Q7. What is HTTP protocol? With an example explain how a request initiated by a HTTP client is served by a HTTP server.

Ch 78

Q8. Explain the IPv6 datagram format and the function of each field with necessary figure.

Ch 84+4

Q9. Compare symmetric key encryption method with asymmetric key encryption. Describe the operation of RSA algorithm.

Ch 82+2+4

Q10. What is network security? How can firewalls enhance network security? Explain how firewalls can protect a system.

Regular / Back2068 Chaitra

2068 Chaitra · Regular / Back · BCT · 9 questions

Ch 12+6

Q1. Why are the network softwares defined with distinct layers stacked on top of one another? What are the factors to be considered when designing these layers?

Ch 62+6

Q2. Why do we need RAID in the computer networks? Define and discuss the differences between RAID 0, RAID 1 and RAID 5.

Ch 22+6

Q3. What is a telephone? With a simple diagram of a telephone network explain how the system works.

Ch 33+7

Q4. Why channel access mechanism is important in computer networking? Explain the operation of IEEE 802.5 with its frame format.

Ch 13+5

Q6. What is X.25? Explain the format of X.25 packet in detail.

Ch 53+5

Q7. What are the differences between TCP and UDP services? Explain the TCP datagram format in detail.

Ch 4Numerical10

Q8. Suppose there are 4 departments A, B, C and D. The department A has 23 hosts, B has 16, C has 28 and D has 13 hosts. You are given a networks 202.70.64.0/24. Perform the subnetting in such a way that the IP address wastage in each department are minimum and also find out the sunbet mask, network address, broadcast, and unable host range in each department.

Ch 8, 42×5

Q9. Write short notes on: a) Network Security b) Router and Gateway

Regular / Back2068 Baishakh

2068 Baishakh · Regular / Back · BCT · 10 questions

Ch 22+6

Q1. What is a switching? Differentiate between packet switching and circuit switching.

Ch 2, 3Numerical4+4

Q2. What are types of twisted pair cable? Calculate the efficiency of slotted Aloha.

Ch 32+6

Q3. What is a virtual LAN? Design a network which consists of two VLAN named student and department. Explain with necessary diagram, IP addresses and configurations.

Ch 4Numerical2+6

Q4. What is a logical address? You are given the IP address block 200.10.80.32/25. If there are five departments which require 5, 40, 28, 12, 6 hosts respectively. Design the subnet.

Ch 43+5

Q6. What is a fragmentation and re-assembly? Explain about any intra-AS routing protocol.

Ch 7, 44+4

Q7. What are the advantages of IPV6? The maximum payload segment is 65495 byte. Why was such strange number chosen?

Ch 8Numerical2+6

Q9. What is a secure socket layer? Encrypt the message “DANGER” using RSA algorithm.

Ch 1, 3Numerical6+2

Q10. Compare x.25 and frame relay network. A bit string 0111101111101111110 needs to be transmitted at the data link layer. What is the string actually transmitted after bit stuffing?

Regular / Back2067 Ashad

2067 Ashad · Regular / Back · BCT · 10 questions

Ch 46+2

Q2. If you are assigned to design a LAN for Pulchowk Campus having 5 departments. Each department will have 100 computers locating in 5 rooms each equipped with 20 computers. Make your own justification while selecting connecting devices and accessories.

Ch 23+5

Q3. What do you mean by ISDN and what is it contribution in the field of data communication? Explain various types of multiplexing mechanism used in communication.

Ch 2, 34+4

Q4. Describe what do you understand by switching along with various types of switching mechanism. Explain the fault tolerance mechanism of FDDI.

Ch 14+4

Q6. Explain along with the packet format about the virtual circuit connection of X.25.

Ch 48

Q8. Explain in detail about IP frame format.

Ch 4Numerical8

Q9. If you need to assign IP addresses to all computers of question no. 2 making each department as network. What will be your approach? Explain with IP address ranges you are suggesting.

Back2066 Poush

2066 Poush · Back · BCT · 10 questions

Ch 28

Q2. Describe guided and unguided media used in computer network with their advantages.

Ch 34+4

Q3. Explain the operation of pure ALOHA system. How CSMA/CD works?

Ch 54+6

Q5. Describe the policies that help in preventing the congestions within the network? Differentiate between leaky bucket and token bucket algorithm with their operation and working of token bucket.

Ch 2, 12+6

Q6. What do you understand by virtual circuit switching? Explain the X.25 virtual circuit switching.

Ch 18

Q7. Explain the seven layers of OSI model with their example protocols.

Ch 48

Q8. Briefly describe ICMP error and informational message types in IPv4 network infrastructure.

Regular / Back2066 Bhadra

2066 Bhadra · Regular / Back · BCT · 10 questions

Ch 12+2+4

Q1a. Why do communication process within computer network is divided into layers? How the process of data encapsulation occurs in transmission mode described by seven layers of OSI model. Compare OSI model with TCP/IP model.

Ch 13+5

Q1b. What is client/server networking? Explain Active Networking model framework comparing with traditional legacy network.

Ch 2Numerical4+4

Q2b. Calculate SNR and maximum channel capacity of a cat6 channel having bandwidth 300 MHz with 2mW and 200 μW as signal and noise power respectively.

Ch 35+3

Q3a. Describe the 802.3 Ethernet standard for CSMA/CD and compare it with 802.4 token bus technology. Explain how DSSS technique is applied in wireless transmission.

Ch 2, 12+6

Q3b. Differentiate between circuit switching and packet switching technology. Explain the operation how switched virtual circuit in frame relay network is established, maintained and teardown.

Ch 42+6

Q4a. What is unicast and multicast routing? Describe the concept of optimality principle. Describe how the routers in its link state routing come into fully adjacency state.

Ch 52+6

Q4b. What are the factors that cause congestion within WAN? Propose your best traffic shaping approach to manage congestion in packet switched network.

Ch 7, 4Numerical2+2+6

Q5a. Give the reason why the current world is moving to IPv6 addressing mechanism. Describe the IPv6 address types with its representation format. You are given the IPv4 address block 203.71.53.0/26; assign the IP subnet for the following network. [Figure, as text: Net A: 6 Hosts (LAN on router R1); Net B: 2 Hosts (link R1 to R2); Net C: 12 Hosts (LAN on router R2); Net E: 2 Hosts (link R2 to R3); Net F: 29 Hosts (LAN on router R3). The routers are unlabelled in the print and no Net D is drawn.]

392 cards · 127 definitions and 265 exam questions · what you miss comes back sooner

Flashcards

The definitions and every question the papers have asked, one at a time. Mark yourself honestly: a card you knew moves up a box and waits twice as long, a card you did not drops to box one and comes back before you leave the page. Your boxes are saved in this browser, and nothing leaves the device.

How this works

  • Five boxes. A new card starts in box one. Knowing it moves it up; missing it sends it back to box one.
  • The box sets the wait: one day, two, four, eight, then sixteen.
  • A theory card shows the opening of the answer, the line to start with; its link opens the full answer.
  • Saved in this browser only. Clearing site data resets it.

8 maps · 127 topics · 486 lists · 1729 items

Every chapter as one map

This is a theory paper, and theory marks are lost on “name the types”: you can explain a term and still go blank on the list. Each map opens whole: the chapter, its topics, every list and every member, with the size of each list beside its name. Press Close all and the items go while the names and counts stay, so “7 Stages of the Cyber Kill Chain” becomes a question. The canvas pans, zooms and goes full screen. Every map is built from the chapter cards themselves, so it always matches them.

How to use the maps

  • Press anything to have it explained. A topic, a list or a single item opens a note beside the map; the arrow beside a topic opens its card.
  • Close all turns the map into a test. Name the members of each list before you open it. Answering before you look is what moves a list into memory.
  • The count is half the memory. Knowing there are six criteria tells you to keep going when you have named four.
  • Drag to move, zoom with the buttons or ctrl and the wheel; Fit puts the whole chapter back on screen.
100%

Drag to move · ctrl and wheel to zoom

Chapter 1Introduction to computer network 21 topics · 62 lists · 238 items
  • ↗
  • ↗
  • ↗
  • ↗
  • ↗
  • ↗
  • ↗
  • ↗
  • ↗
  • ↗
  • ↗
  • ↗
  • ↗
  • ↗
  • ↗
  • ↗
  • ↗
  • ↗
  • ↗
  • ↗
  • ↗