12

Updated 4 Oct 2026

CSS334 — Link Layer (Part 2) Cheat Sheet

Exam-ready summary | Lecture 12 | All topics included


1. Ethernet

  • Dominant wired LAN technology — first widely used, simple, cheap
  • Speed range: 10 Mbps → 400 Gbps (same fundamental MAC protocol throughout)
  • All variants share the same MAC protocol and frame format — only speed and physical media differ
  • Single NIC chip can support multiple speeds (e.g., 10/100/1000 auto-negotiation)

Analogy: Ethernet is like a highway that keeps getting extra lanes added — the road rules stay the same, just more capacity.

⚠️ To run 10 Gbps Ethernet end-to-end, every component in the path must support it: NIC + Switch + Router.


2. Ethernet Frame Structure

┌──────────┬────────┬────────┬──────┬─────────────┬─────┐
│ Preamble │ Dst MAC│ Src MAC│ Type │ Data/Payload │ CRC │
│  8 bytes │ 6 bytes│ 6 bytes│2 byte│  46–1500 B  │ 4 B │
└──────────┴────────┴────────┴──────┴─────────────┴─────┘
FieldSizePurpose
Preamble8 bytes7 × 10101010 + 1 × 10101011 — synchronise sender/receiver clocks
Destination MAC6 bytesMAC of next-hop recipient (adjacent node)
Source MAC6 bytesMAC of sender
Type2 bytesUpper-layer protocol: IPv4 = 0x0800, IPv6 = 0x86DD, ARP = 0x0806
Data (Payload)46–1500 bytesIP datagram (min 46 to meet minimum frame size)
CRC4 bytesError check — frame is dropped if CRC fails

Frame Acceptance Rules (at the NIC)

ConditionAction
Dst MAC = my MAC✅ Pass up to network layer
Dst MAC = broadcast FF:FF:FF:FF:FF:FF✅ Pass up (e.g., ARP)
Dst MAC = other (not mine)❌ Discard
Promiscuous mode ON✅ Accept ALL frames (Wireshark, tcpdump)

Type Field — Upper Layer Demultiplexing

Type ValueProtocol
0x0800IPv4
0x86DDIPv6
0x0806ARP

3. Ethernet: Connectionless & Unreliable

PropertyDetail
ConnectionlessNo handshake before sending — just send
UnreliableNo ACK/NAK — dropped frames only recovered by TCP (upper layer)
MAC ProtocolCSMA/CD with binary exponential backoff

Analogy: Sending a letter without tracking — might arrive, might not. Only TCP (the sender) would notice if it's lost.


4. Ethernet Standards Reference

IEEE StandardShorthandInformal NameSpeedMedium
802.3i10BASE-TEthernet10 MbpsUTP
802.3u100BASE-TFast Ethernet100 MbpsUTP
802.3z1000BASE-XGigabit Ethernet1 GbpsFiber
802.3ab1000BASE-TGigabit Ethernet1 GbpsUTP
802.3ae10GBASE-X10 GigE10 GbpsFiber
802.3an10GBASE-T10 GigE10 GbpsUTP
802.3ba40GBASE-X40 GigE40 GbpsFiber
802.3ba100GBASE-X100 GigE100 GbpsFiber
802.11a/b/g/n/ac/ax—Wi-FivariesWireless

Naming pattern: [speed]BASE-[medium] — e.g., 1000BASE-T = 1 Gbps, baseband, twisted pair


5. UTP Cable (Unshielded Twisted Pair)

  • Most common physical medium for Ethernet
  • Uses RJ45 connector, T-568B standard wiring

T-568B Pin Order (Memorise!)

PinColour
1White/Orange
2Orange
3White/Green
4Blue
5White/Blue
6Green
7White/Brown
8Brown

Patch vs Crossover Cable

TypeWiringUsed to connect
Patch (Straight)Same both endsPC → Switch (most common)
CrossoverPins 1↔3, 2↔6 swappedPC → PC direct

Modern NICs support Auto-MDIX — auto-detect and adjust, so either cable type works.

UTP Categories

CategoryMax SpeedMax LengthApplication
CAT310 Mbps100m10BASE-T Ethernet
CAT5100 Mbps100mFast Ethernet
CAT5e1 Gbps100mGigabit Ethernet ← common
CAT610 Gbps55m10G Ethernet (short runs)
CAT6a10 Gbps100m10G Ethernet (full 100m)
CAT710 Gbps100m10G Ethernet (shielded)

Rule of thumb: CAT5e for Gigabit, CAT6a for 10 Gigabit at full 100m distance.


6. Switches

Network Device Comparison

DeviceLayerAddress UsedBehaviour
HubL1NoneFloods all frames to all ports
SwitchL2MACSelectively forwards to correct port
RouterL3IPRoutes between different networks/subnets

Switch Key Properties

  • Link-layer device (L2) — reads MAC addresses
  • Store-and-forward: receives entire frame, checks CRC, then forwards
  • Transparent: hosts are completely unaware the switch exists
  • Plug-and-play, self-learning: no manual configuration needed
  • Each port = its own collision domain → full-duplex, zero collisions

Analogy: Smart post office — reads the address on each envelope (MAC) and delivers only to the right mailbox. A hub just dumps all mail on every desk.

Simultaneous Transmissions

  • A→A' and B→B' simultaneously → ✅ allowed (different destination ports)
  • A→A' and C→A' simultaneously → ❌ blocked (same destination port — can't write to same port at once)

7. Switch Self-Learning & Forwarding

Switch Forwarding Table Entry Format

(MAC Address, Interface/Port, TTL)\boxed{(\text{MAC Address},\ \text{Interface/Port},\ \text{TTL})}

Self-Learning Algorithm (Step-by-Step)

Frame arrives at switch on interface X:
  1. Record (src MAC → interface X) in table   ← always learn the SOURCE
  2. Look up DESTINATION MAC in table:
       Found → forward to that interface only    ← selective forward
       Not found → FLOOD (send to all except X)  ← unknown destination
       Dst is on same interface X → DROP          ← no need to resend

Self-Learning Example (A sends to A')

EventSwitch TableAction
Frame arrives from A, port 1Add: A → port 1Flood (A' unknown)
A' receives frame, repliesAdd: A' → port 4—
A sends to A' againA' → port 4 (found!)Forward to port 4 only

First time: flood to all ports (except source). Every subsequent time: selective forward.

⚠️ Other nodes that received the flooded frame check the destination MAC — if it's not theirs, they discardit.

Multi-Switch Self-Learning

  • Works identically across interconnected switches
  • Each switch learns from traffic it sees — no central coordination needed
  • Frame from C to I (across S1 → S4 → S3): first time floods through all switches; each switch learns the path; future frames selectively forwarded

8. Switch Types

L2 vs L3 Switch vs Router

DeviceWhat it does
L2 SwitchMAC-based forwarding only — no IP awareness
L3 SwitchSwitching + basic IP routing + VLAN support (MLS)
RouterFull L3 routing, WAN support, advanced features

Managed vs Unmanaged Switch

FeatureUnmanagedManaged
ConfigPlug and play — no configWeb UI / CLI / SNMP configuration
ApplicationHome, small networksEnterprise, datacentre
FeaturesBasic switching onlyVLAN, SNMP, QoS, 802.1X, Spanning Tree
HardwareEntry-level ASICAdvanced ASIC + CPU + Flash + RAM

Need VLANs, routing, 802.1X auth, SNMP monitoring → must use managed switch

Power over Ethernet (PoE)

  • Delivers power + data over a single UTP cable (up to 100m)
  • Devices powered: IP Phones, Wireless APs, IP Cameras — no separate power cable
  • If switch doesn't support PoE natively → use a PoE injector inline

Switch vs Router (Detailed)

FeatureSwitch (L2)Router (L3)
LayerData LinkNetwork
AddressMACIP
Table built byFlood + self-learningRouting algorithms (OSPF, BGP)
Store-and-forward✅✅
Separates broadcast domains❌ (same broadcast domain)✅
Connects subnets❌✅

9. VLANs — Virtual Local Area Networks

Why VLANs?

Problem with a single large LAN (one big broadcast domain):

  • Every ARP, DHCP, and unknown-MAC frame floods the entire network — scales badly
  • Security: all traffic visible to all nodes
  • Privacy: department A can see department B's broadcasts
  • Administrative: user physically moves but logically should stay in same group

Solution: VLANs — divide one physical switch into multiple logically isolated virtual switches

Analogy: Soundproof walls between departments in an open-plan office — Finance and Engineering can't hear each other's internal announcements.

Port-Based VLANs

  • Switch ports grouped by admin into different VLANs
  • One physical switch behaves like multiple independent virtual switches
Physical Switch:
  Ports 1–8  → VLAN 10 (Engineering)
  Ports 9–15 → VLAN 20 (Finance)
  Port 16    → Trunk port (to router / another switch)

VLAN Properties

PropertyDetail
Traffic isolationFrames from VLAN 10 cannot reach VLAN 20 ports (at L2)
Dynamic membershipPorts can be reassigned between VLANs via management software
Inter-VLAN routingRequires L3 device (router or L3 switch) — VLANs can't talk at L2
Alternative membershipCan also assign by MAC address instead of port number
RequiresManaged switch — unmanaged switches cannot do VLANs

The Problem

  • Two switches on different floors, each with VLAN 10 and VLAN 20
  • Naïve solution: run one cable per VLAN between switches → 2 cables, scales badly
  • Better solution: Trunk port — one cable carries all VLANs

Trunk Port

  • Carries frames from multiple VLANs over a single link between switches
  • Uses IEEE 802.1Q (Dot1q) to tag frames with their VLAN ID
  • Switch adds tag on ingress to trunk, removes tag on egress to access port

802.1Q Frame Format

┌──────────┬────────┬────────┬────────────┬──────┬─────────────┬────────────┬─────┐
│ Preamble │ Dst MAC│ Src MAC│ 802.1Q Tag │ Type │ Data/Payload │ (new) CRC  │     │
│  8 bytes │ 6 bytes│ 6 bytes│  4 bytes   │ 2 B  │  46–1500 B  │  4 bytes   │     │
└──────────┴────────┴────────┴────────────┴──────┴─────────────┴────────────┴─────┘

The 4-byte 802.1Q tag (inserted after Src MAC):

Sub-fieldSizeValue / Purpose
Tag Protocol ID (TPID)2 bytesAlways 0x8100 — marks this as 802.1Q frame
Tag Control Info (TCI)2 bytesContains VLAN ID + Priority
— Priority (PCP)3 bitsQoS priority (like IP ToS)
— VLAN ID (VID)12 bitsWhich VLAN this frame belongs to

Max VLAN ID=212−2=4094 usable VLANs (0 and 4095 reserved)\boxed{\text{Max VLAN ID} = 2^{12} - 2 = 4094 \text{ usable VLANs (0 and 4095 reserved)}}

CRC is recomputed after adding the tag — tag changes the frame size so old CRC is invalid.

802.1Q Key Details

DetailValue / Rule
VLAN 1Default VLAN / Management VLAN
TPIDAlways 0x8100
VLAN ID bits12 bits → 4096 values → 4094 usable
Inter-VLAN routingMust go through L3 device (router or L3 switch)
Multi-VLAN DHCPEach VLAN needs its own DHCP address pool

Port Types (Exam Important ⚠️)

Port TypeVLANs CarriedUsed For
Access port1 VLAN onlyEnd devices (PC, printer, phone)
Trunk portMultiple VLANs (all)Switch↔Switch, Switch↔Router
General portConfigurableFlexible — either mode

11. VLAN vs Subnet (Key Distinction)

DimensionVLANSubnet
LayerL2 — Data LinkL3 — Network
SeparationLogical isolation of broadcast domainsIP address range division
RelationEach VLAN typically maps to one subnetEach subnet typically lives in one VLAN
ScopeWithin switch infrastructureIP addressing scheme

Rule of thumb: one VLAN = one subnet. VLANs enforce L2 isolation; subnets enforce L3 addressing. Inter-VLAN = inter-subnet = needs a router.


12. A Day in the Life of a Web Request

Scenario: Laptop connects to school network, opens browser → types www.google.com

Every protocol that fires, in order:

Step 1 — DHCP: Get an IP Address

Laptop has no IP → broadcasts DHCP Discover

DHCP Discover → DHCP Offer → DHCP Request → DHCP ACK

DHCP→UDP (ports 68→67)→IP (0.0.0.0→255.255.255.255)→Ethernet (broadcast FF:FF:FF:FF:FF:FF)\boxed{\text{DHCP} \rightarrow \text{UDP (ports 68→67)} \rightarrow \text{IP (0.0.0.0→255.255.255.255)} \rightarrow \text{Ethernet (broadcast FF:FF:FF:FF:FF:FF)}}

After DHCP ACK, laptop knows:

  • Its own IP address
  • Default gateway IP (first-hop router)
  • DNS server IP + name

Step 2 — ARP: Find the Router's MAC

Laptop knows the router's IP (from DHCP) but needs its MAC to build an Ethernet frame.

ARP Request (broadcast) → "Who has 192.168.1.1?"
ARP Reply (unicast)     → "That's me. My MAC is E6:E9:00:17:BB:4B"

ARP broadcast→router replies with its MAC→cached in ARP table\boxed{\text{ARP broadcast} \rightarrow \text{router replies with its MAC} \rightarrow \text{cached in ARP table}}

Laptop can now address Ethernet frames to the router.


Step 3 — DNS: Resolve www.google.com

Laptop needs the IP address of www.google.com.

DNS Query → UDP → IP (dst: DNS server) → Ethernet (dst MAC: router) → forwarded by router
DNS Reply ← "www.google.com = 64.233.169.105"

DNS→UDP (port 53)→IP→Ethernet→routed via OSPF/BGP to DNS server\boxed{\text{DNS} \rightarrow \text{UDP (port 53)} \rightarrow \text{IP} \rightarrow \text{Ethernet} \rightarrow \text{routed via OSPF/BGP to DNS server}}


Step 4 — TCP: 3-Way Handshake

Before HTTP, establish a reliable connection to Google's web server.

SYN     → laptop to 64.233.169.105   (I want to connect)
SYNACK  ← Google server              (OK, I'm ready)
ACK     → laptop to Google           (Great, let's go)

SYN→SYNACK→ACK(TCP connection established)\boxed{\text{SYN} \rightarrow \text{SYNACK} \rightarrow \text{ACK} \quad (\text{TCP connection established})}


Step 5 — HTTP: The Actual Web Request

HTTP GET / HTTP/1.1
Host: www.google.com
→ routed to 64.233.169.105
← HTTP 200 OK + HTML content
→ browser renders page

HTTP→TCP→IP→Ethernet→routed to Google\boxed{\text{HTTP} \rightarrow \text{TCP} \rightarrow \text{IP} \rightarrow \text{Ethernet} \rightarrow \text{routed to Google}}


Full Summary: All Protocols for One Web Request

StepProtocolWhyEncapsulation
1DHCPGet IP, gateway, DNS serverDHCP → UDP → IP → Ethernet (bcast)
2ARPGet router's MAC addressARP → Ethernet (broadcast)
3DNSResolve hostname → IPDNS → UDP → IP → Ethernet
4TCPEstablish reliable connectionTCP → IP → Ethernet
5HTTPRequest and receive the web pageHTTP → TCP → IP → Ethernet

Analogy: Ordering delivery from a new restaurant — look up their address (DNS), call a taxi (ARP/routing), taxi takes you there (TCP connection), you order and food arrives (HTTP). Even "just typing a URL" triggers all 5 protocols across all 4 layers.


Quick Reference Summary

TopicKey Facts
EthernetConnectionless, unreliable, CSMA/CD; 10 Mbps–400 Gbps; same frame format always
Frame fieldsPreamble(8B) + DstMAC(6B) + SrcMAC(6B) + Type(2B) + Data(46–1500B) + CRC(4B)
Preamble7×10101010 + 1×10101011 — clock sync between sender and receiver
Type field0x0800=IPv4, 0x86DD=IPv6, 0x0806=ARP
CRC on EthernetFrame dropped if CRC fails — no retransmit at L2 (TCP handles it)
T-568BW/O, O, W/G, B, W/B, G, W/Br, Br (pins 1–8)
Patch cablePC→Switch (same wiring both ends)
Crossover cablePC→PC direct (pins 1↔3, 2↔6 swapped)
CAT5e1 Gbps / 100m; CAT6a = 10 Gbps / 100m
SwitchL2, MAC-based, self-learning, store-and-forward, full-duplex, no collisions
Self-learningLearn src MAC on arrival; flood if dst unknown; selective forward if dst known
Flood vs forwardUnknown dst → flood all (except src port); known dst → forward to that port only
Managed switchRequired for VLANs, SNMP, QoS, 802.1X, Spanning Tree
PoEPower + data over single UTP cable; for IP phones, APs, cameras
VLANL2 isolation; one physical switch = multiple virtual switches; needs managed switch
Inter-VLANMust go through L3 device (router or L3 switch)
Trunk portCarries multiple VLANs on one cable (switch↔switch); tagged with 802.1Q
Access portOne VLAN only; for end devices
802.1Q tag4 bytes after Src MAC: TPID 0x8100 + TCI (3-bit priority + 12-bit VLAN ID)
Max VLAN ID212−2=40942^{12} - 2 = \mathbf{4094} usable (0 and 4095 reserved; VLAN 1 = management)
CRC recomputed802.1Q adds 4 bytes → old CRC invalid → must recalculate
DHCP→ARP→DNS→TCP→HTTPThe exact order every web request fires; DHCP first (no IP yet), ARP second (need router MAC)