1. Network Devices (Hub, Switch, Router)
| Device | Layer | Identifier Used | Behaviour |
|---|---|---|---|
| Hub | L1 – Physical | None | Floods every packet to all ports (obsolete) |
| Switch | L2 – Data Link | MAC Address | Learns MAC → forwards to the correct port only |
| Router | L3 – Network | IP Address | Routes packets between different networks/subnets |
Analogy:
- Hub = shouting in a room (everyone hears — bad, insecure)
- Switch = whispering directly to the right person in the room
- Router = a post office directing mail between cities
Key Rule: Different subnets MUST be connected through a Router. A switch alone cannot route between subnets.
Interface
- Interface = the connection point between a host/router and a physical link
- Routers have multiple interfaces (e.g.,
eth0,eth1,eth2), each with its own IP address - Hosts typically have 1–2 interfaces (wired
eth0, wirelesswlan0) - Analogy: Interface = a door of a building. Each door connects to a different street (network). A router has many doors; your MacBook usually just has one or two.
Network Architectures in Practice
Home Network:
Cable/Fiber Modem → Modem Router (Wi-Fi) → Devices (PC, Laptop, Phone, Printer)
Home Network (ADSL):
Phone Jack → Phone Cable → ADSL Splitter → Modem Router
(Phone can still share the same line)
Office Network:
Internet → Firewall → Router → Switches → PCs, IP Phones, Printers, Servers
→ WiFi Router → Laptops, Smartphones
The Firewall is placed between the internet and the internal router in office setups — it filters traffic before it reaches the internal network.
2. Network Layer: Two Key Functions
| Function | Plane | Scope | Analogy |
|---|---|---|---|
| Forwarding | Data Plane | Local, per-router | Getting through one highway interchange |
| Routing | Control Plane | Network-wide | Planning your entire road trip on a map |
Data Plane (Forwarding)
- Operates per-router in hardware → nanosecond speed
- Looks up the destination IP in the local forwarding table → picks an output port
- Determined by: Arriving packet header field → match in local forwarding table → route to output port
Control Plane (Routing) — Two Approaches
1. Traditional Per-Router Routing
- Individual routing algorithm runs on each router
- Routers exchange info with each other (e.g., link states, distance vectors) to build their own forwarding tables
- Protocols: OSPF (within AS), BGP (between AS)
- Think of each taxi driver independently knowing the city map
2. Software-Defined Networking (SDN)
- A remote controller (server) computes routes centrally and pushes them out
- Each router runs a Local Control Agent (CA) that communicates with the remote controller
- The controller installs a Flow Table (richer than a plain forwarding table — can match on ports, MACs, IPs) into each router
- Think of separating the GPS app (control plane) from the car's engine (data plane)
- More centralized, flexible, and programmable than per-router routing
3. IP Datagram Format
The structure of every IP packet — 32 bits wide per row.
0 1 2 3
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|Version| IHL |Type of Service| Total Length |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
| Identification |Flags| Fragment Offset |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
| Time to Live | Protocol | Header Checksum |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
| Source Address |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
| Destination Address |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
| Options (if any) | Padding |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
| Data (Payload) |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
| Field | Description |
|---|---|
ver (Version) | IP version number — IPv4 = 4 |
head.len (IHL) | Header length in 32-bit words (min = 5 → 20 bytes) |
type of service | Diffserv / ECN — quality of service hints (priority, congestion) |
length | Total datagram length in bytes. Max: 64K bytes, typically ≤ 1500 bytes |
16-bit identifier | Used to identify fragments of the same original datagram |
flgs + fragment offset | Fragmentation control — how to reassemble split packets |
TTL (Time to Live) | Remaining max hops — decremented by 1 at each router, dropped at 0 |
upper layer (Protocol) | Protocol above IP: TCP = 6, UDP = 17, ICMP = 1 |
header checksum | Error detection for the header only (not payload) |
source IP address | 32-bit source IP |
destination IP address | 32-bit destination IP |
options | Optional: timestamp, record route, security — rarely used |
payload data | Usually a TCP or UDP segment |
TTL in real life: When you do
traceroute, it works by sending packets with TTL=1, TTL=2, TTL=3... Each router that drops the packet (TTL expired) sends back an ICMP "Time Exceeded" message — that's how you see each hop's IP.
4. Network-Layer Service Model
| Architecture | Service Model | Bandwidth Guarantee | Loss | Order | Timing |
|---|---|---|---|---|---|
| Internet | Best Effort | None | No | No | No |
| ATM | Constant Bit Rate (CBR) | Constant rate | Yes | Yes | Yes |
| ATM | Available Bit Rate (ABR) | Guaranteed min | No | Yes | No |
| Internet | Intserv Guaranteed (RFC 1633) | Yes | Yes | Yes | Yes |
| Internet | Diffserv (RFC 2475) | Possible | Possibly | Possibly | No |
Internet "Best Effort"
- No guarantees on:
- Successful delivery to destination
- Timing or order of delivery
- Bandwidth available to the flow
Analogy: Internet is like dropping a letter in a public mailbox with no tracking — it usually arrives, but there's no promise of when or in what order.
Why does the Internet still work well? TCP (transport layer) adds reliability on top of best-effort IP.
5. IP Address
Structure
- 32-bit identifier, one per interface (not per host — a router has many)
- Written in dotted-decimal notation: 4 octets (0–255) separated by dots
Three Notations for IPv4
| Notation | Example |
|---|---|
| Binary | 10000000 00001011 00000011 00011111 |
| Dotted Decimal | 128.11.3.31 |
| Hexadecimal | 80 0B 03 1F |
Bit Value Reference (each octet = 8 bits)
| Bit position | 7 | 6 | 5 | 4 | 3 | 2 | 1 | 0 |
|---|---|---|---|---|---|---|---|---|
| Value if 1 | 128 | 64 | 32 | 16 | 8 | 4 | 2 | 1 |
Quick tip: Octet range is always 0–255. Sum the values wherever the bit is 1.
Example:11000000= 128 + 64 = 192 ✓
IP Address Analogy to Physical Address
| Physical World | Network World |
|---|---|
| Apartment 1, Building 1, ABC Rd | TCP Port 80, IP 192.168.100.10 |
| Street/Neighbourhood | Subnet 192.168.10.0/24 |
| ISP (like a regional post HQ) | ISP AIS Fiber / CAT Telecom |
6. Subnet & Subnet Mask
Why Subnets?
- Total IPv4 space: billion IPs
- One flat range causes: broadcast floods, management nightmare, security issues
- Solution: Split IP range into multiple subnets
- Broadcasts are scoped within a subnet — they do NOT pass through routers
Analogy: Subnetting = dividing a city into neighbourhoods. ARP broadcast only floods your neighbourhood (subnet), not the whole city.
IP Address = Network Portion + Host Portion
Subnet Mask: A 32-bit number — 1s for the network part, 0s for the host part.
Example: 192.168.10.10/24
| Octet 1 | Octet 2 | Octet 3 | Octet 4 | |
|---|---|---|---|---|
| IP Address | 192 | 168 | 10 | 10 |
| Binary | 11000000 | 10101000 | 00001010 | 00001010 |
| Subnet Mask | 255 | 255 | 255 | 0 |
| Mask Binary | 11111111 | 11111111 | 11111111 | 00000000 |
/24→ 24 bits network, 8 bits host → total IPs
3 Special Addresses in Every Subnet
| Part | Description | Example (192.168.30.0/24) |
|---|---|---|
| Network Address | First IP — identifies the subnet itself | 192.168.30.0 |
| Host Addresses | All IPs excluding first and last | 192.168.30.1 – 192.168.30.254 |
| Broadcast Address | Last IP — sends to ALL hosts in subnet | 192.168.30.255 |
Subtract 2: one for Network Address + one for Broadcast Address.
Example: 192.168.5.10/24
- Network:
192.168.5.0| HostMin:192.168.5.1| HostMax:192.168.5.254| Broadcast:192.168.5.255 - Usable hosts:
7. Classful IP Addressing
4 main techniques to split IP range: (1) Classful A/B/C ← this lecture, (2) Public/Private, (3) CIDR, (4) VLSM
IP Address Classes
| Class | First Octet Range | Prefix Bits | Network Mask | Prefix | # of Networks | Hosts/Network |
|---|---|---|---|---|---|---|
| A | 1 – 127 | Fixed 0 | 255.0.0.0 | /8 | 16,777,214 | |
| B | 128 – 191 | Fixed 10 | 255.255.0.0 | /16 | 65,534 | |
| C | 192 – 223 | Fixed 110 | 255.255.255.0 | /24 | 254 | |
| D | 224 – 239 | — | — | — | Multicast only | — |
| E | 240 – 254 | — | — | — | Restricted/Experimental | — |
How to identify class from first octet:
- A: Starts with
0_______→ 0–127 → but 1–126 usable (127 = loopback) - B: Starts with
10______→ 128–191 - C: Starts with
110_____→ 192–223
Analogy: Class A = countries (few, enormous). Class B = states/provinces. Class C = neighbourhoods (many, small). Class D = group chat (multicast). Class E = reserved for lab experiments.
Class-by-Class Detail
Class A (/8):
- Example:
10.2.1.1/8→ Network:10.0.0.0| Broadcast:10.255.255.255| Mask:255.0.0.0
Class B (/16):
- Example:
172.16.1.5/16→ Network:172.16.0.0| Broadcast:172.16.255.255| Mask:255.255.0.0 - Example:
128.2.0.0/16→ HostMin:128.2.0.1| HostMax:128.2.255.254| Broadcast:128.2.255.255
Class C (/24):
- Example:
192.168.1.1/24→ Network:192.168.1.0| Broadcast:192.168.1.255| Mask:255.255.255.0
Reserved / Special Addresses
| Address | Class | Meaning |
|---|---|---|
127.0.0.1 | A | Loopback — refers to yourself (your own machine) |
169.254.0.0/16 | B | Link-local / APIPA — auto-assigned when no DHCP found |
0.0.0.0 | — | Default route (match anything — used in routing tables) |
255.255.255.255 | — | Limited broadcast (to all on local network) |
8. Public vs Private IP Addresses
| Feature | Public IP | Private IP (Intranet) |
|---|---|---|
| Usage | WAN / Internet | LAN only |
| Recognized on Internet | ✅ Yes | ❌ No (not routable on internet) |
| Uniqueness | Globally unique | Unique only within the network |
| Cost | Paid (from ISP / IANA via ICANN) | Free |
| Assigned by | ISP / IANA (under ICANN) | Network Administrator |
Private IP Ranges (RFC 1918 — memorise these!)
| Class | Private Range | Subnet Mask |
|---|---|---|
| A | 10.0.0.0 – 10.255.255.255 | 255.0.0.0 /8 |
| B | 172.16.0.0 – 172.31.255.255 | 255.255.0.0 /16 |
| C | 192.168.0.0 – 192.168.255.255 | 255.255.255.0 /24 |
Analogy: Private IPs are like apartment numbers — the same number (e.g.,
192.168.1.1) can exist in different buildings. But each building's public IP is globally unique on the internet.
Class B Private Range Detail
Valid private Class B subnets: 172.16.X.X through 172.31.X.X
Example: 172.18.0.0/16 → Usable: 172.18.0.1 – 172.18.255.254 | Broadcast: 172.18.255.255
NAT (Network Address Translation)
- NAT converts between Public IP ↔ Private IP
- Your home router does NAT — all devices share one public IP, but have unique private IPs inside
- Example: Your phone (
192.168.1.5) → Router NAT →49.228.234.12(public) → Internet
9. How to Design a Network (Subnetting Steps)
Design Process
Step 1 — Determine number of required Network IDs:
- One per subnet (each department, area, or segment)
- One per WAN link (router-to-router connection counts as a network too!)
- Ask: How many departments? How many router links?
Step 2 — Determine hosts per subnet:
- One per TCP/IP host (PC, printer, phone, server)
- One per router interface (each interface takes one IP)
Step 3 — Create:
- One subnet mask for the entire network
- A unique subnet ID for each physical segment
- A range of host IDs for each subnet
⚠️ Don't forget the WAN link! The link between two routers is itself a network (usually a /30 — only 2 usable hosts). This is a very common exam mistake.
Subnetting Examples
Example 1: 4 Subnets from Class C
- Network:
192.168.100.0/24| Need: 4 subnets (100 users, 60 users, 200 users + WAN)
| Area | Subnet | Max Hosts |
|---|---|---|
| Area 1 | 192.168.1.0/24 | |
| Area 2 | 192.168.2.0/24 | 254 |
| Area 3 | 192.168.3.0/24 | 254 |
| WAN | (separate /24) | 254 (เปลืองนะ) |
Example 2: Mixed Class B and C
- Areas: 5000 users, 1000 users, 200 users (+1 WAN link = 4 networks total)
| Area | Subnet | Class | Max Hosts |
|---|---|---|---|
| Area 1 (5000 users) | 172.17.0.0/16 | B | 65,534 |
| Area 2 (1000 users) | 172.16.0.0/16 | B | 65,534 |
| Area 3 (200 users) | 192.168.3.0/24 | C | 254 |
| WAN link (between routers) | (point-to-point) | — | 254 |
Always count the router-to-router WAN link as a separate network!
10. Network Diagram: Logical vs Physical
Instructor note: This is almost certain on the final exam. The MOST COMMON mistake is not labeling interface names on physical diagrams.
Two Types
| Type | Shows | Uses |
|---|---|---|
| Logical | How information flows | Subnets (cloud shapes), routing protocols, IP addresses on links |
| Physical | Actual topology of all devices | All devices, cable connections, interface names (eth0, eth1...) AND their IPs |
Key Difference (EXAM CRITICAL ⚠️)
- Logical diagram: Label the IP addresses on the links/clouds between devices
- Physical diagram: Label the interface name (e.g.,
eth0) AND the IP address on each interface of each device
Physical Diagram Example:
Host A
|
(Network A: 192.168.1.0/24)
|
Router R1
eth0: 192.168.1.1 ← label BOTH interface name AND IP
eth1: 10.0.0.1
|
(Network B: 10.0.0.0/30) ← WAN link between routers
|
Router R2
eth0: 10.0.0.2
eth1: 192.168.2.1
|
(Network C: 192.168.2.0/24)
|
Host B
11. How Does a Host Get an IP Address?
Two Methods
| Method | How | Use Case |
|---|---|---|
| Static | Sysadmin manually sets IP in config | Servers, printers, router interfaces |
| DHCP | Host auto-gets IP from DHCP server | PCs, phones, laptops (plug-and-play) |
Always write IP with CIDR prefix (e.g.,
192.168.1.5/24) — without it, you don't know which network it belongs to!
How Does a Network Get Its IP Block?
- Private network: Allocated by Network Admin from RFC 1918 private ranges (free)
- Public IP block: Purchased from ISP (ISP gets ranges from IANA/ICANN)
12. DHCP — Dynamic Host Configuration Protocol
Every home router has DHCP enabled by default!
Purpose
- Host dynamically obtains an IP address when it joins the network
- Supports address reuse — IP is leased, returned when device leaves
- Supports mobile users (join/leave dynamically)
- Ensures no IP conflicts — DHCP tracks who has what
- Can renew lease before it expires
DHCP 4-Step Process (DORA)
| Step | Message | Direction | Meaning |
|---|---|---|---|
| 1 | DHCP Discover | Client → Broadcast | "Is there a DHCP server out there?" |
| 2 | DHCP Offer | Server → Broadcast | "I'm here! Here's an IP you can use" |
| 3 | DHCP Request | Client → Broadcast | "OK, I'd like to use that IP!" |
| 4 | DHCP ACK | Server → Broadcast | "Confirmed! That IP is yours." |
Mnemonic: DORA — Discover, Offer, Request, ACK
Why are steps 1 & 2 sometimes skipped? If a client already has a previously allocated IP and wants to reuse it, it can skip straight to Request → ACK [RFC 2131].
Why broadcast (not unicast)? The client has no IP yet — it can't address a unicast packet. The server's reply is also broadcast because the client isn't officially on the network yet.
Packet Details (Exam-Level Detail)
DHCP Discover (Client → Network):
src: 0.0.0.0, port 68 → dest: 255.255.255.255, port 67
yiaddr: 0.0.0.0 | transaction ID: 654
DHCP Offer (Server → Network):
src: 223.1.2.5, port 67 → dest: 255.255.255.255, port 68
yiaddr: 223.1.2.4 | transaction ID: 654 | lifetime: 3600 sec
DHCP Request (Client → Network):
src: 0.0.0.0, port 68 → dest: 255.255.255.255, port 67
yiaddr: 223.1.2.4 | transaction ID: 655 | lifetime: 3600 sec
DHCP ACK (Server → Network):
src: 223.1.2.5, port 67 → dest: 255.255.255.255, port 68
yiaddr: 223.1.2.4 | transaction ID: 655 | lifetime: 3600 sec
yiaddr= "your IP address" — the field where the server tells the client its assigned IP.
Port 67 = DHCP server, Port 68 = DHCP client — always.
DHCP Returns More Than Just an IP
When DHCP ACK is received, the client gets:
| What | Example | Purpose |
|---|---|---|
| IP Address | 223.1.2.4 | Client's assigned IP |
| Subnet Mask | 255.255.255.0 | To know network vs host portion |
| Default Gateway | 192.168.1.1 | Address of first-hop router |
| DNS Server | 8.8.8.8 | For domain name → IP lookup |
| Lease Time | 3600 sec (1 hour) | How long the IP is valid |
DHCP Encapsulation Stack
DHCP message
→ encapsulated in UDP
→ encapsulated in IP (dest: 255.255.255.255)
→ encapsulated in Ethernet (dest MAC: FF:FF:FF:FF:FF:FF — broadcast)
DHCP in Practice (Home Network)
ISP Modem (10.10.10.26)
↓
Router (192.168.1.1) ← DHCP server lives here
↓
Switch (192.168.1.2)
↙ ↓ ↘
Desktop Game Network Printer
(DHCP) Console (static: 192.168.1.100)
(DHCP)
Mobile Phone (DHCP)
Laptop (DHCP)
The DHCP server is typically co-located in the router, serving all subnets the router is attached to.
Pro tip: You can reserve a fixed IP for a specific MAC address in the router — the device always gets the same IP via DHCP (useful for printers, cameras).
Quick Reference Summary
| Topic | Key Facts |
|---|---|
| Hub / Switch / Router | L1 broadcast / L2 MAC forwarding / L3 IP routing |
| Forwarding vs Routing | Local data plane / Network-wide control plane |
| SDN | Remote controller + Local CA agent per router; installs Flow Tables |
| IP Datagram | TTL decrements at each hop; Protocol field: TCP=6, UDP=17 |
| Best Effort | No guarantees on delivery, order, timing, bandwidth |
| IP Address | 32-bit, dotted-decimal, per interface not per host |
| Class A | /8, 1–126, up to 16M hosts, 255.0.0.0 |
| Class B | /16, 128–191, up to 65K hosts, 255.255.0.0 |
| Class C | /24, 192–223, up to 254 hosts, 255.255.255.0 |
| Class D / E | 224–239 Multicast / 240–254 Experimental |
| Loopback | 127.0.0.1 — refers to yourself |
| APIPA | 169.254.x.x — auto-assigned when no DHCP server |
| Private Ranges | 10.x.x.x / 172.16–31.x.x / 192.168.x.x — free, LAN-only, NAT to internet |
| NAT | Converts private ↔ public IP at the router |
| Usable Hosts | (minus network addr + broadcast addr) |
| Physical Diagram | MUST label interface name (eth0, eth1...) AND its IP — most common mistake |
| DHCP DORA | Discover → Offer → Request → ACK, all on UDP 67/68, all broadcast |
| DHCP gives | IP, Subnet Mask, Default Gateway, DNS Server, Lease Time |
| WAN link | Always counts as a separate network when designing subnets! |