CSS334 — Link Layer (Part 2) Cheat Sheet
Exam-ready summary | Lecture 12 | All topics included
1. Ethernet
- Dominant wired LAN technology — first widely used, simple, cheap
- Speed range: 10 Mbps → 400 Gbps (same fundamental MAC protocol throughout)
- All variants share the same MAC protocol and frame format — only speed and physical media differ
- Single NIC chip can support multiple speeds (e.g., 10/100/1000 auto-negotiation)
Analogy: Ethernet is like a highway that keeps getting extra lanes added — the road rules stay the same, just more capacity.
⚠️ To run 10 Gbps Ethernet end-to-end, every component in the path must support it: NIC + Switch + Router.
2. Ethernet Frame Structure
┌──────────┬────────┬────────┬──────┬─────────────┬─────┐
│ Preamble │ Dst MAC│ Src MAC│ Type │ Data/Payload │ CRC │
│ 8 bytes │ 6 bytes│ 6 bytes│2 byte│ 46–1500 B │ 4 B │
└──────────┴────────┴────────┴──────┴─────────────┴─────┘
| Field | Size | Purpose |
|---|---|---|
| Preamble | 8 bytes | 7 × 10101010 + 1 × 10101011 — synchronise sender/receiver clocks |
| Destination MAC | 6 bytes | MAC of next-hop recipient (adjacent node) |
| Source MAC | 6 bytes | MAC of sender |
| Type | 2 bytes | Upper-layer protocol: IPv4 = 0x0800, IPv6 = 0x86DD, ARP = 0x0806 |
| Data (Payload) | 46–1500 bytes | IP datagram (min 46 to meet minimum frame size) |
| CRC | 4 bytes | Error check — frame is dropped if CRC fails |
Frame Acceptance Rules (at the NIC)
| Condition | Action |
|---|---|
| Dst MAC = my MAC | ✅ Pass up to network layer |
Dst MAC = broadcast FF:FF:FF:FF:FF:FF | ✅ Pass up (e.g., ARP) |
| Dst MAC = other (not mine) | ❌ Discard |
| Promiscuous mode ON | ✅ Accept ALL frames (Wireshark, tcpdump) |
Type Field — Upper Layer Demultiplexing
| Type Value | Protocol |
|---|---|
0x0800 | IPv4 |
0x86DD | IPv6 |
0x0806 | ARP |
3. Ethernet: Connectionless & Unreliable
| Property | Detail |
|---|---|
| Connectionless | No handshake before sending — just send |
| Unreliable | No ACK/NAK — dropped frames only recovered by TCP (upper layer) |
| MAC Protocol | CSMA/CD with binary exponential backoff |
Analogy: Sending a letter without tracking — might arrive, might not. Only TCP (the sender) would notice if it's lost.
4. Ethernet Standards Reference
| IEEE Standard | Shorthand | Informal Name | Speed | Medium |
|---|---|---|---|---|
| 802.3i | 10BASE-T | Ethernet | 10 Mbps | UTP |
| 802.3u | 100BASE-T | Fast Ethernet | 100 Mbps | UTP |
| 802.3z | 1000BASE-X | Gigabit Ethernet | 1 Gbps | Fiber |
| 802.3ab | 1000BASE-T | Gigabit Ethernet | 1 Gbps | UTP |
| 802.3ae | 10GBASE-X | 10 GigE | 10 Gbps | Fiber |
| 802.3an | 10GBASE-T | 10 GigE | 10 Gbps | UTP |
| 802.3ba | 40GBASE-X | 40 GigE | 40 Gbps | Fiber |
| 802.3ba | 100GBASE-X | 100 GigE | 100 Gbps | Fiber |
| 802.11a/b/g/n/ac/ax | — | Wi-Fi | varies | Wireless |
Naming pattern:
[speed]BASE-[medium]— e.g., 1000BASE-T = 1 Gbps, baseband, twisted pair
5. UTP Cable (Unshielded Twisted Pair)
- Most common physical medium for Ethernet
- Uses RJ45 connector, T-568B standard wiring
T-568B Pin Order (Memorise!)
| Pin | Colour |
|---|---|
| 1 | White/Orange |
| 2 | Orange |
| 3 | White/Green |
| 4 | Blue |
| 5 | White/Blue |
| 6 | Green |
| 7 | White/Brown |
| 8 | Brown |
Patch vs Crossover Cable
| Type | Wiring | Used to connect |
|---|---|---|
| Patch (Straight) | Same both ends | PC → Switch (most common) |
| Crossover | Pins 1↔3, 2↔6 swapped | PC → PC direct |
Modern NICs support Auto-MDIX — auto-detect and adjust, so either cable type works.
UTP Categories
| Category | Max Speed | Max Length | Application |
|---|---|---|---|
| CAT3 | 10 Mbps | 100m | 10BASE-T Ethernet |
| CAT5 | 100 Mbps | 100m | Fast Ethernet |
| CAT5e | 1 Gbps | 100m | Gigabit Ethernet ← common |
| CAT6 | 10 Gbps | 55m | 10G Ethernet (short runs) |
| CAT6a | 10 Gbps | 100m | 10G Ethernet (full 100m) |
| CAT7 | 10 Gbps | 100m | 10G Ethernet (shielded) |
Rule of thumb: CAT5e for Gigabit, CAT6a for 10 Gigabit at full 100m distance.
6. Switches
Network Device Comparison
| Device | Layer | Address Used | Behaviour |
|---|---|---|---|
| Hub | L1 | None | Floods all frames to all ports |
| Switch | L2 | MAC | Selectively forwards to correct port |
| Router | L3 | IP | Routes between different networks/subnets |
Switch Key Properties
- Link-layer device (L2) — reads MAC addresses
- Store-and-forward: receives entire frame, checks CRC, then forwards
- Transparent: hosts are completely unaware the switch exists
- Plug-and-play, self-learning: no manual configuration needed
- Each port = its own collision domain → full-duplex, zero collisions
Analogy: Smart post office — reads the address on each envelope (MAC) and delivers only to the right mailbox. A hub just dumps all mail on every desk.
Simultaneous Transmissions
- A→A' and B→B' simultaneously → ✅ allowed (different destination ports)
- A→A' and C→A' simultaneously → ❌ blocked (same destination port — can't write to same port at once)
7. Switch Self-Learning & Forwarding
Switch Forwarding Table Entry Format
Self-Learning Algorithm (Step-by-Step)
Frame arrives at switch on interface X:
1. Record (src MAC → interface X) in table ← always learn the SOURCE
2. Look up DESTINATION MAC in table:
Found → forward to that interface only ← selective forward
Not found → FLOOD (send to all except X) ← unknown destination
Dst is on same interface X → DROP ← no need to resend
Self-Learning Example (A sends to A')
| Event | Switch Table | Action |
|---|---|---|
| Frame arrives from A, port 1 | Add: A → port 1 | Flood (A' unknown) |
| A' receives frame, replies | Add: A' → port 4 | — |
| A sends to A' again | A' → port 4 (found!) | Forward to port 4 only |
First time: flood to all ports (except source). Every subsequent time: selective forward.
⚠️ Other nodes that received the flooded frame check the destination MAC — if it's not theirs, they discardit.
Multi-Switch Self-Learning
- Works identically across interconnected switches
- Each switch learns from traffic it sees — no central coordination needed
- Frame from C to I (across S1 → S4 → S3): first time floods through all switches; each switch learns the path; future frames selectively forwarded
8. Switch Types
L2 vs L3 Switch vs Router
| Device | What it does |
|---|---|
| L2 Switch | MAC-based forwarding only — no IP awareness |
| L3 Switch | Switching + basic IP routing + VLAN support (MLS) |
| Router | Full L3 routing, WAN support, advanced features |
Managed vs Unmanaged Switch
| Feature | Unmanaged | Managed |
|---|---|---|
| Config | Plug and play — no config | Web UI / CLI / SNMP configuration |
| Application | Home, small networks | Enterprise, datacentre |
| Features | Basic switching only | VLAN, SNMP, QoS, 802.1X, Spanning Tree |
| Hardware | Entry-level ASIC | Advanced ASIC + CPU + Flash + RAM |
Need VLANs, routing, 802.1X auth, SNMP monitoring → must use managed switch
Power over Ethernet (PoE)
- Delivers power + data over a single UTP cable (up to 100m)
- Devices powered: IP Phones, Wireless APs, IP Cameras — no separate power cable
- If switch doesn't support PoE natively → use a PoE injector inline
Switch vs Router (Detailed)
| Feature | Switch (L2) | Router (L3) |
|---|---|---|
| Layer | Data Link | Network |
| Address | MAC | IP |
| Table built by | Flood + self-learning | Routing algorithms (OSPF, BGP) |
| Store-and-forward | ✅ | ✅ |
| Separates broadcast domains | ❌ (same broadcast domain) | ✅ |
| Connects subnets | ❌ | ✅ |
9. VLANs — Virtual Local Area Networks
Why VLANs?
Problem with a single large LAN (one big broadcast domain):
- Every ARP, DHCP, and unknown-MAC frame floods the entire network — scales badly
- Security: all traffic visible to all nodes
- Privacy: department A can see department B's broadcasts
- Administrative: user physically moves but logically should stay in same group
Solution: VLANs — divide one physical switch into multiple logically isolated virtual switches
Analogy: Soundproof walls between departments in an open-plan office — Finance and Engineering can't hear each other's internal announcements.
Port-Based VLANs
- Switch ports grouped by admin into different VLANs
- One physical switch behaves like multiple independent virtual switches
Physical Switch:
Ports 1–8 → VLAN 10 (Engineering)
Ports 9–15 → VLAN 20 (Finance)
Port 16 → Trunk port (to router / another switch)
VLAN Properties
| Property | Detail |
|---|---|
| Traffic isolation | Frames from VLAN 10 cannot reach VLAN 20 ports (at L2) |
| Dynamic membership | Ports can be reassigned between VLANs via management software |
| Inter-VLAN routing | Requires L3 device (router or L3 switch) — VLANs can't talk at L2 |
| Alternative membership | Can also assign by MAC address instead of port number |
| Requires | Managed switch — unmanaged switches cannot do VLANs |
10. VLANs Across Multiple Switches — Trunk Links
The Problem
- Two switches on different floors, each with VLAN 10 and VLAN 20
- Naïve solution: run one cable per VLAN between switches → 2 cables, scales badly
- Better solution: Trunk port — one cable carries all VLANs
Trunk Port
- Carries frames from multiple VLANs over a single link between switches
- Uses IEEE 802.1Q (Dot1q) to tag frames with their VLAN ID
- Switch adds tag on ingress to trunk, removes tag on egress to access port
802.1Q Frame Format
┌──────────┬────────┬────────┬────────────┬──────┬─────────────┬────────────┬─────┐
│ Preamble │ Dst MAC│ Src MAC│ 802.1Q Tag │ Type │ Data/Payload │ (new) CRC │ │
│ 8 bytes │ 6 bytes│ 6 bytes│ 4 bytes │ 2 B │ 46–1500 B │ 4 bytes │ │
└──────────┴────────┴────────┴────────────┴──────┴─────────────┴────────────┴─────┘
The 4-byte 802.1Q tag (inserted after Src MAC):
| Sub-field | Size | Value / Purpose |
|---|---|---|
| Tag Protocol ID (TPID) | 2 bytes | Always 0x8100 — marks this as 802.1Q frame |
| Tag Control Info (TCI) | 2 bytes | Contains VLAN ID + Priority |
| — Priority (PCP) | 3 bits | QoS priority (like IP ToS) |
| — VLAN ID (VID) | 12 bits | Which VLAN this frame belongs to |
CRC is recomputed after adding the tag — tag changes the frame size so old CRC is invalid.
802.1Q Key Details
| Detail | Value / Rule |
|---|---|
| VLAN 1 | Default VLAN / Management VLAN |
| TPID | Always 0x8100 |
| VLAN ID bits | 12 bits → 4096 values → 4094 usable |
| Inter-VLAN routing | Must go through L3 device (router or L3 switch) |
| Multi-VLAN DHCP | Each VLAN needs its own DHCP address pool |
Port Types (Exam Important ⚠️)
| Port Type | VLANs Carried | Used For |
|---|---|---|
| Access port | 1 VLAN only | End devices (PC, printer, phone) |
| Trunk port | Multiple VLANs (all) | Switch↔Switch, Switch↔Router |
| General port | Configurable | Flexible — either mode |
11. VLAN vs Subnet (Key Distinction)
| Dimension | VLAN | Subnet |
|---|---|---|
| Layer | L2 — Data Link | L3 — Network |
| Separation | Logical isolation of broadcast domains | IP address range division |
| Relation | Each VLAN typically maps to one subnet | Each subnet typically lives in one VLAN |
| Scope | Within switch infrastructure | IP addressing scheme |
Rule of thumb: one VLAN = one subnet. VLANs enforce L2 isolation; subnets enforce L3 addressing. Inter-VLAN = inter-subnet = needs a router.
12. A Day in the Life of a Web Request
Scenario: Laptop connects to school network, opens browser → types www.google.com
Every protocol that fires, in order:
Step 1 — DHCP: Get an IP Address
Laptop has no IP → broadcasts DHCP Discover
DHCP Discover → DHCP Offer → DHCP Request → DHCP ACK
After DHCP ACK, laptop knows:
- Its own IP address
- Default gateway IP (first-hop router)
- DNS server IP + name
Step 2 — ARP: Find the Router's MAC
Laptop knows the router's IP (from DHCP) but needs its MAC to build an Ethernet frame.
ARP Request (broadcast) → "Who has 192.168.1.1?"
ARP Reply (unicast) → "That's me. My MAC is E6:E9:00:17:BB:4B"
Laptop can now address Ethernet frames to the router.
Step 3 — DNS: Resolve www.google.com
Laptop needs the IP address of www.google.com.
DNS Query → UDP → IP (dst: DNS server) → Ethernet (dst MAC: router) → forwarded by router
DNS Reply ← "www.google.com = 64.233.169.105"
Step 4 — TCP: 3-Way Handshake
Before HTTP, establish a reliable connection to Google's web server.
SYN → laptop to 64.233.169.105 (I want to connect)
SYNACK ← Google server (OK, I'm ready)
ACK → laptop to Google (Great, let's go)
Step 5 — HTTP: The Actual Web Request
HTTP GET / HTTP/1.1
Host: www.google.com
→ routed to 64.233.169.105
← HTTP 200 OK + HTML content
→ browser renders page
Full Summary: All Protocols for One Web Request
| Step | Protocol | Why | Encapsulation |
|---|---|---|---|
| 1 | DHCP | Get IP, gateway, DNS server | DHCP → UDP → IP → Ethernet (bcast) |
| 2 | ARP | Get router's MAC address | ARP → Ethernet (broadcast) |
| 3 | DNS | Resolve hostname → IP | DNS → UDP → IP → Ethernet |
| 4 | TCP | Establish reliable connection | TCP → IP → Ethernet |
| 5 | HTTP | Request and receive the web page | HTTP → TCP → IP → Ethernet |
Analogy: Ordering delivery from a new restaurant — look up their address (DNS), call a taxi (ARP/routing), taxi takes you there (TCP connection), you order and food arrives (HTTP). Even "just typing a URL" triggers all 5 protocols across all 4 layers.
Quick Reference Summary
| Topic | Key Facts |
|---|---|
| Ethernet | Connectionless, unreliable, CSMA/CD; 10 Mbps–400 Gbps; same frame format always |
| Frame fields | Preamble(8B) + DstMAC(6B) + SrcMAC(6B) + Type(2B) + Data(46–1500B) + CRC(4B) |
| Preamble | 7×10101010 + 1×10101011 — clock sync between sender and receiver |
| Type field | 0x0800=IPv4, 0x86DD=IPv6, 0x0806=ARP |
| CRC on Ethernet | Frame dropped if CRC fails — no retransmit at L2 (TCP handles it) |
| T-568B | W/O, O, W/G, B, W/B, G, W/Br, Br (pins 1–8) |
| Patch cable | PC→Switch (same wiring both ends) |
| Crossover cable | PC→PC direct (pins 1↔3, 2↔6 swapped) |
| CAT5e | 1 Gbps / 100m; CAT6a = 10 Gbps / 100m |
| Switch | L2, MAC-based, self-learning, store-and-forward, full-duplex, no collisions |
| Self-learning | Learn src MAC on arrival; flood if dst unknown; selective forward if dst known |
| Flood vs forward | Unknown dst → flood all (except src port); known dst → forward to that port only |
| Managed switch | Required for VLANs, SNMP, QoS, 802.1X, Spanning Tree |
| PoE | Power + data over single UTP cable; for IP phones, APs, cameras |
| VLAN | L2 isolation; one physical switch = multiple virtual switches; needs managed switch |
| Inter-VLAN | Must go through L3 device (router or L3 switch) |
| Trunk port | Carries multiple VLANs on one cable (switch↔switch); tagged with 802.1Q |
| Access port | One VLAN only; for end devices |
| 802.1Q tag | 4 bytes after Src MAC: TPID 0x8100 + TCI (3-bit priority + 12-bit VLAN ID) |
| Max VLAN ID | usable (0 and 4095 reserved; VLAN 1 = management) |
| CRC recomputed | 802.1Q adds 4 bytes → old CRC invalid → must recalculate |
| DHCP→ARP→DNS→TCP→HTTP | The exact order every web request fires; DHCP first (no IP yet), ARP second (need router MAC) |