7 new

Updated 4 Oct 2026


1. Network Devices (Hub, Switch, Router)

DeviceLayerIdentifier UsedBehaviour
HubL1 – PhysicalNoneFloods every packet to all ports (obsolete)
SwitchL2 – Data LinkMAC AddressLearns MAC → forwards to the correct port only
RouterL3 – NetworkIP AddressRoutes packets between different networks/subnets

Analogy:

  • Hub = shouting in a room (everyone hears — bad, insecure)
  • Switch = whispering directly to the right person in the room
  • Router = a post office directing mail between cities

Key Rule: Different subnets MUST be connected through a Router. A switch alone cannot route between subnets.

Interface

  • Interface = the connection point between a host/router and a physical link
  • Routers have multiple interfaces (e.g., eth0, eth1, eth2), each with its own IP address
  • Hosts typically have 1–2 interfaces (wired eth0, wireless wlan0)
  • Analogy: Interface = a door of a building. Each door connects to a different street (network). A router has many doors; your MacBook usually just has one or two.

Network Architectures in Practice

Home Network:

Cable/Fiber Modem → Modem Router (Wi-Fi) → Devices (PC, Laptop, Phone, Printer)

Home Network (ADSL):

Phone Jack → Phone Cable → ADSL Splitter → Modem Router
(Phone can still share the same line)

Office Network:

Internet → Firewall → Router → Switches → PCs, IP Phones, Printers, Servers
                              → WiFi Router → Laptops, Smartphones

The Firewall is placed between the internet and the internal router in office setups — it filters traffic before it reaches the internal network.


2. Network Layer: Two Key Functions

FunctionPlaneScopeAnalogy
ForwardingData PlaneLocal, per-routerGetting through one highway interchange
RoutingControl PlaneNetwork-widePlanning your entire road trip on a map

Data Plane (Forwarding)

  • Operates per-router in hardware → nanosecond speed
  • Looks up the destination IP in the local forwarding table → picks an output port
  • Determined by: Arriving packet header field → match in local forwarding table → route to output port

Control Plane (Routing) — Two Approaches

1. Traditional Per-Router Routing

  • Individual routing algorithm runs on each router
  • Routers exchange info with each other (e.g., link states, distance vectors) to build their own forwarding tables
  • Protocols: OSPF (within AS), BGP (between AS)
  • Think of each taxi driver independently knowing the city map

2. Software-Defined Networking (SDN)

  • A remote controller (server) computes routes centrally and pushes them out
  • Each router runs a Local Control Agent (CA) that communicates with the remote controller
  • The controller installs a Flow Table (richer than a plain forwarding table — can match on ports, MACs, IPs) into each router
  • Think of separating the GPS app (control plane) from the car's engine (data plane)
  • More centralized, flexible, and programmable than per-router routing

3. IP Datagram Format

The structure of every IP packet — 32 bits wide per row.

 0                   1                   2                   3
 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|Version| IHL |Type of Service|          Total Length           |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|         Identification        |Flags|      Fragment Offset    |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|  Time to Live |    Protocol   |         Header Checksum       |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|                       Source Address                          |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|                    Destination Address                        |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|                    Options (if any)          |    Padding     |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|                          Data (Payload)                       |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
FieldDescription
ver (Version)IP version number — IPv4 = 4
head.len (IHL)Header length in 32-bit words (min = 5 → 20 bytes)
type of serviceDiffserv / ECN — quality of service hints (priority, congestion)
lengthTotal datagram length in bytes. Max: 64K bytes, typically ≤ 1500 bytes
16-bit identifierUsed to identify fragments of the same original datagram
flgs + fragment offsetFragmentation control — how to reassemble split packets
TTL (Time to Live)Remaining max hops — decremented by 1 at each router, dropped at 0
upper layer (Protocol)Protocol above IP: TCP = 6, UDP = 17, ICMP = 1
header checksumError detection for the header only (not payload)
source IP address32-bit source IP
destination IP address32-bit destination IP
optionsOptional: timestamp, record route, security — rarely used
payload dataUsually a TCP or UDP segment

TCP + IP overhead=20 bytes (TCP header)+20 bytes (IP header)=40 bytes minimum\boxed{\text{TCP + IP overhead} = 20 \text{ bytes (TCP header)} + 20 \text{ bytes (IP header)} = 40 \text{ bytes minimum}}

TTL in real life: When you do traceroute, it works by sending packets with TTL=1, TTL=2, TTL=3... Each router that drops the packet (TTL expired) sends back an ICMP "Time Exceeded" message — that's how you see each hop's IP.


4. Network-Layer Service Model

ArchitectureService ModelBandwidth GuaranteeLossOrderTiming
InternetBest EffortNoneNoNoNo
ATMConstant Bit Rate (CBR)Constant rateYesYesYes
ATMAvailable Bit Rate (ABR)Guaranteed minNoYesNo
InternetIntserv Guaranteed (RFC 1633)YesYesYesYes
InternetDiffserv (RFC 2475)PossiblePossiblyPossiblyNo

Internet "Best Effort"

  • No guarantees on:
    1. Successful delivery to destination
    2. Timing or order of delivery
    3. Bandwidth available to the flow

Analogy: Internet is like dropping a letter in a public mailbox with no tracking — it usually arrives, but there's no promise of when or in what order.
Why does the Internet still work well? TCP (transport layer) adds reliability on top of best-effort IP.


5. IP Address

Structure

  • 32-bit identifier, one per interface (not per host — a router has many)
  • Written in dotted-decimal notation: 4 octets (0–255) separated by dots

192.168.32.152=11000000⏟192.10101000⏟168.00100000⏟32.10011000⏟152\boxed{192.168.32.152 = \underbrace{11000000}_{192}.\underbrace{10101000}_{168}.\underbrace{00100000}_{32}.\underbrace{10011000}_{152}}

Three Notations for IPv4

NotationExample
Binary10000000 00001011 00000011 00011111
Dotted Decimal128.11.3.31
Hexadecimal80 0B 03 1F

Bit Value Reference (each octet = 8 bits)

Bit position76543210
Value if 11286432168421

Quick tip: Octet range is always 0–255. Sum the values wherever the bit is 1.
Example: 11000000 = 128 + 64 = 192 ✓

IP Address Analogy to Physical Address

Physical WorldNetwork World
Apartment 1, Building 1, ABC RdTCP Port 80, IP 192.168.100.10
Street/NeighbourhoodSubnet 192.168.10.0/24
ISP (like a regional post HQ)ISP AIS Fiber / CAT Telecom

6. Subnet & Subnet Mask

Why Subnets?

  • Total IPv4 space: 232≈4.32^{32} \approx 4.3 billion IPs
  • One flat range causes: broadcast floods, management nightmare, security issues
  • Solution: Split IP range into multiple subnets
  • Broadcasts are scoped within a subnet — they do NOT pass through routers

Analogy: Subnetting = dividing a city into neighbourhoods. ARP broadcast only floods your neighbourhood (subnet), not the whole city.

IP Address = Network Portion + Host Portion

IP Address=Network Portion (n bits)⏟Prefix+Host Portion (32-n bits)⏟Suffix\boxed{\text{IP Address} = \underbrace{\text{Network Portion (n bits)}}_{\text{Prefix}} + \underbrace{\text{Host Portion (32-n bits)}}_{\text{Suffix}}}

Subnet Mask: A 32-bit number — 1s for the network part, 0s for the host part.

Example: 192.168.10.10/24

Octet 1Octet 2Octet 3Octet 4
IP Address1921681010
Binary11000000101010000000101000001010
Subnet Mask2552552550
Mask Binary11111111111111111111111100000000
  • /24 → 24 bits network, 8 bits host → 28=2562^8 = 256 total IPs

3 Special Addresses in Every Subnet

PartDescriptionExample (192.168.30.0/24)
Network AddressFirst IP — identifies the subnet itself192.168.30.0
Host AddressesAll IPs excluding first and last192.168.30.1 – 192.168.30.254
Broadcast AddressLast IP — sends to ALL hosts in subnet192.168.30.255

Usable Hosts=2host bits−2\boxed{\text{Usable Hosts} = 2^{\text{host bits}} - 2}

Subtract 2: one for Network Address + one for Broadcast Address.

Example: 192.168.5.10/24

  • Network: 192.168.5.0 | HostMin: 192.168.5.1 | HostMax: 192.168.5.254 | Broadcast: 192.168.5.255
  • Usable hosts: 28−2=2542^8 - 2 = \mathbf{254}

7. Classful IP Addressing

4 main techniques to split IP range: (1) Classful A/B/C ← this lecture, (2) Public/Private, (3) CIDR, (4) VLSM

IP Address Classes

ClassFirst Octet RangePrefix BitsNetwork MaskPrefix# of NetworksHosts/Network
A1 – 127Fixed 0255.0.0.0/827=1282^7 = 12816,777,214
B128 – 191Fixed 10255.255.0.0/16214=16,3842^{14} = 16{,}38465,534
C192 – 223Fixed 110255.255.255.0/24221=2,097,1522^{21} = 2{,}097{,}152254
D224 – 239———Multicast only—
E240 – 254———Restricted/Experimental—

Total Hosts per Network=2host bits−2\boxed{\text{Total Hosts per Network} = 2^{\text{host bits}} - 2}

How to identify class from first octet:

  • A: Starts with 0_______ → 0–127 → but 1–126 usable (127 = loopback)
  • B: Starts with 10______ → 128–191
  • C: Starts with 110_____ → 192–223

Analogy: Class A = countries (few, enormous). Class B = states/provinces. Class C = neighbourhoods (many, small). Class D = group chat (multicast). Class E = reserved for lab experiments.

Class-by-Class Detail

Class A (/8): Host bits=24⇒224−2=16,777,214 hosts\text{Host bits} = 24 \Rightarrow 2^{24} - 2 = 16{,}777{,}214 \text{ hosts}

  • Example: 10.2.1.1/8 → Network: 10.0.0.0 | Broadcast: 10.255.255.255 | Mask: 255.0.0.0

Class B (/16): Prefix: 10xxxxxx⇒128 to 191;216−2=65,534 hosts\text{Prefix: }10xxxxxx \Rightarrow 128 \text{ to } 191 \quad ; \quad 2^{16} - 2 = 65{,}534 \text{ hosts}

  • Example: 172.16.1.5/16 → Network: 172.16.0.0 | Broadcast: 172.16.255.255 | Mask: 255.255.0.0
  • Example: 128.2.0.0/16 → HostMin: 128.2.0.1 | HostMax: 128.2.255.254 | Broadcast: 128.2.255.255

Class C (/24): 28−2=254 hosts2^8 - 2 = 254 \text{ hosts}

  • Example: 192.168.1.1/24 → Network: 192.168.1.0 | Broadcast: 192.168.1.255 | Mask: 255.255.255.0

Reserved / Special Addresses

AddressClassMeaning
127.0.0.1ALoopback — refers to yourself (your own machine)
169.254.0.0/16BLink-local / APIPA — auto-assigned when no DHCP found
0.0.0.0—Default route (match anything — used in routing tables)
255.255.255.255—Limited broadcast (to all on local network)

8. Public vs Private IP Addresses

FeaturePublic IPPrivate IP (Intranet)
UsageWAN / InternetLAN only
Recognized on Internet✅ Yes❌ No (not routable on internet)
UniquenessGlobally uniqueUnique only within the network
CostPaid (from ISP / IANA via ICANN)Free
Assigned byISP / IANA (under ICANN)Network Administrator

Private IP Ranges (RFC 1918 — memorise these!)

ClassPrivate RangeSubnet Mask
A10.0.0.0 – 10.255.255.255255.0.0.0 /8
B172.16.0.0 – 172.31.255.255255.255.0.0 /16
C192.168.0.0 – 192.168.255.255255.255.255.0 /24

Analogy: Private IPs are like apartment numbers — the same number (e.g., 192.168.1.1) can exist in different buildings. But each building's public IP is globally unique on the internet.

Class B Private Range Detail

Valid private Class B subnets: 172.16.X.X through 172.31.X.X

Number of private Class B subnets=216−12=16 subnets\text{Number of private Class B subnets} = 2^{16-12} = 16 \text{ subnets}

Example: 172.18.0.0/16 → Usable: 172.18.0.1 – 172.18.255.254 | Broadcast: 172.18.255.255

NAT (Network Address Translation)

  • NAT converts between Public IP ↔ Private IP
  • Your home router does NAT — all devices share one public IP, but have unique private IPs inside
  • Example: Your phone (192.168.1.5) → Router NAT → 49.228.234.12 (public) → Internet

9. How to Design a Network (Subnetting Steps)

Design Process

Step 1 — Determine number of required Network IDs:

  • One per subnet (each department, area, or segment)
  • One per WAN link (router-to-router connection counts as a network too!)
  • Ask: How many departments? How many router links?

Step 2 — Determine hosts per subnet:

  • One per TCP/IP host (PC, printer, phone, server)
  • One per router interface (each interface takes one IP)

Step 3 — Create:

  • One subnet mask for the entire network
  • A unique subnet ID for each physical segment
  • A range of host IDs for each subnet

⚠️ Don't forget the WAN link! The link between two routers is itself a network (usually a /30 — only 2 usable hosts). This is a very common exam mistake.

Subnetting Examples

Example 1: 4 Subnets from Class C

  • Network: 192.168.100.0/24 | Need: 4 subnets (100 users, 60 users, 200 users + WAN)
AreaSubnetMax Hosts
Area 1192.168.1.0/2428−2=2542^8-2 = 254
Area 2192.168.2.0/24254
Area 3192.168.3.0/24254
WAN(separate /24)254 (เปลืองนะ)

Example 2: Mixed Class B and C

  • Areas: 5000 users, 1000 users, 200 users (+1 WAN link = 4 networks total)
AreaSubnetClassMax Hosts
Area 1 (5000 users)172.17.0.0/16B65,534
Area 2 (1000 users)172.16.0.0/16B65,534
Area 3 (200 users)192.168.3.0/24C254
WAN link (between routers)(point-to-point)—254

Always count the router-to-router WAN link as a separate network!


10. Network Diagram: Logical vs Physical

Instructor note: This is almost certain on the final exam. The MOST COMMON mistake is not labeling interface names on physical diagrams.

Two Types

TypeShowsUses
LogicalHow information flowsSubnets (cloud shapes), routing protocols, IP addresses on links
PhysicalActual topology of all devicesAll devices, cable connections, interface names (eth0, eth1...) AND their IPs

Key Difference (EXAM CRITICAL ⚠️)

  • Logical diagram: Label the IP addresses on the links/clouds between devices
  • Physical diagram: Label the interface name (e.g., eth0) AND the IP address on each interface of each device

Physical Diagram Example:

Host A
  |
 (Network A: 192.168.1.0/24)
  |
Router R1
  eth0: 192.168.1.1       ← label BOTH interface name AND IP
  eth1: 10.0.0.1
  |
 (Network B: 10.0.0.0/30) ← WAN link between routers
  |
Router R2
  eth0: 10.0.0.2
  eth1: 192.168.2.1
  |
 (Network C: 192.168.2.0/24)
  |
Host B

11. How Does a Host Get an IP Address?

Two Methods

MethodHowUse Case
StaticSysadmin manually sets IP in configServers, printers, router interfaces
DHCPHost auto-gets IP from DHCP serverPCs, phones, laptops (plug-and-play)

Always write IP with CIDR prefix (e.g., 192.168.1.5/24) — without it, you don't know which network it belongs to!

How Does a Network Get Its IP Block?

  • Private network: Allocated by Network Admin from RFC 1918 private ranges (free)
  • Public IP block: Purchased from ISP (ISP gets ranges from IANA/ICANN)

12. DHCP — Dynamic Host Configuration Protocol

Every home router has DHCP enabled by default!

Purpose

  • Host dynamically obtains an IP address when it joins the network
  • Supports address reuse — IP is leased, returned when device leaves
  • Supports mobile users (join/leave dynamically)
  • Ensures no IP conflicts — DHCP tracks who has what
  • Can renew lease before it expires

DHCP 4-Step Process (DORA)

StepMessageDirectionMeaning
1DHCP DiscoverClient → Broadcast"Is there a DHCP server out there?"
2DHCP OfferServer → Broadcast"I'm here! Here's an IP you can use"
3DHCP RequestClient → Broadcast"OK, I'd like to use that IP!"
4DHCP ACKServer → Broadcast"Confirmed! That IP is yours."

Mnemonic: DORA — Discover, Offer, Request, ACK

Why are steps 1 & 2 sometimes skipped? If a client already has a previously allocated IP and wants to reuse it, it can skip straight to Request → ACK [RFC 2131].

Why broadcast (not unicast)? The client has no IP yet — it can't address a unicast packet. The server's reply is also broadcast because the client isn't officially on the network yet.

Packet Details (Exam-Level Detail)

DHCP Discover (Client → Network):

src: 0.0.0.0, port 68  →  dest: 255.255.255.255, port 67
yiaddr: 0.0.0.0  |  transaction ID: 654

DHCP Offer (Server → Network):

src: 223.1.2.5, port 67  →  dest: 255.255.255.255, port 68
yiaddr: 223.1.2.4  |  transaction ID: 654  |  lifetime: 3600 sec

DHCP Request (Client → Network):

src: 0.0.0.0, port 68  →  dest: 255.255.255.255, port 67
yiaddr: 223.1.2.4  |  transaction ID: 655  |  lifetime: 3600 sec

DHCP ACK (Server → Network):

src: 223.1.2.5, port 67  →  dest: 255.255.255.255, port 68
yiaddr: 223.1.2.4  |  transaction ID: 655  |  lifetime: 3600 sec

yiaddr = "your IP address" — the field where the server tells the client its assigned IP.
Port 67 = DHCP server, Port 68 = DHCP client — always.

DHCP Returns More Than Just an IP

When DHCP ACK is received, the client gets:

WhatExamplePurpose
IP Address223.1.2.4Client's assigned IP
Subnet Mask255.255.255.0To know network vs host portion
Default Gateway192.168.1.1Address of first-hop router
DNS Server8.8.8.8For domain name → IP lookup
Lease Time3600 sec (1 hour)How long the IP is valid

DHCP Encapsulation Stack

DHCP message
  → encapsulated in UDP
    → encapsulated in IP (dest: 255.255.255.255)
      → encapsulated in Ethernet (dest MAC: FF:FF:FF:FF:FF:FF — broadcast)

DHCP in Practice (Home Network)

ISP Modem (10.10.10.26)
       ↓
  Router (192.168.1.1) ← DHCP server lives here
       ↓
  Switch (192.168.1.2)
   ↙       ↓        ↘
Desktop  Game       Network Printer
(DHCP)  Console     (static: 192.168.1.100)
         (DHCP)
         Mobile Phone (DHCP)
         Laptop (DHCP)

The DHCP server is typically co-located in the router, serving all subnets the router is attached to.

Pro tip: You can reserve a fixed IP for a specific MAC address in the router — the device always gets the same IP via DHCP (useful for printers, cameras).


Quick Reference Summary

TopicKey Facts
Hub / Switch / RouterL1 broadcast / L2 MAC forwarding / L3 IP routing
Forwarding vs RoutingLocal data plane / Network-wide control plane
SDNRemote controller + Local CA agent per router; installs Flow Tables
IP DatagramTTL decrements at each hop; Protocol field: TCP=6, UDP=17
Best EffortNo guarantees on delivery, order, timing, bandwidth
IP Address32-bit, dotted-decimal, per interface not per host
Class A/8, 1–126, up to 16M hosts, 255.0.0.0
Class B/16, 128–191, up to 65K hosts, 255.255.0.0
Class C/24, 192–223, up to 254 hosts, 255.255.255.0
Class D / E224–239 Multicast / 240–254 Experimental
Loopback127.0.0.1 — refers to yourself
APIPA169.254.x.x — auto-assigned when no DHCP server
Private Ranges10.x.x.x / 172.16–31.x.x / 192.168.x.x — free, LAN-only, NAT to internet
NATConverts private ↔ public IP at the router
Usable Hosts2host bits−22^{\text{host bits}} - 2 (minus network addr + broadcast addr)
Physical DiagramMUST label interface name (eth0, eth1...) AND its IP — most common mistake
DHCP DORADiscover → Offer → Request → ACK, all on UDP 67/68, all broadcast
DHCP givesIP, Subnet Mask, Default Gateway, DNS Server, Lease Time
WAN linkAlways counts as a separate network when designing subnets!