7-8

Updated 4 Oct 2026

CSS334 – Network Layer Cheat Sheet (Lectures 7 & 8)


0. Big Picture: Where Does the Network Layer Live?

Application   → HTTP, SMTP, DNS, FTP
Transport     → TCP (reliable), UDP (fast, no guarantee)
Network (L3)  → IP, ARP, ICMP, IGMP  ← YOU ARE HERE
Data Link (L2)→ Ethernet, Wi-Fi
Physical (L1) → Cables, fiber, radio

Analogy: Sending a package internationally — App = you writing the letter, Transport = courier service, Network = postal routing system deciding which country/city, Link+Physical = actual roads and trucks.

When you type google.com in a browser, across layers:

LayerWhat HappensExample Values
ApplicationBrowser sends HTTP GETGET / HTTP/1.1
TransportTCP wraps with portsSrc Port: 4546 → Dst Port: 80
NetworkIP wraps with addressesSrc: 192.168.0.1 → Dst: 203.159.10.11
Data LinkMAC addresses addedSrc MAC: B4:6B:FC:7F:7F:8C → Dst MAC: 8C:16:45:74:32:AA

Routers only operate at L3 + L2 + L1 — they don't care about transport or application headers.


1. Network Devices (Hub, Switch, Router)

DeviceLayerIdentifier UsedBehaviour
HubL1 – PhysicalNoneFloods every packet to all ports (obsolete)
SwitchL2 – Data LinkMAC AddressLearns MAC → forwards to the correct port only
RouterL3 – NetworkIP AddressRoutes packets between different networks

Analogy:

  • Hub = shouting in a room (everyone hears — bad)
  • Switch = whispering directly to the right person
  • Router = a post office directing mail between cities

Key Rule: Different subnets MUST be connected through a Router. A switch alone cannot route between subnets.

Interface

  • Interface = the connection point between a host/router and a physical link
  • Routers have multiple interfaces (e.g., eth0, eth1, eth2), each with its own IP address
  • Hosts typically have 1–2 interfaces (wired eth0, wireless wlan0)

2. Network Layer: Two Key Functions

FunctionPlaneScopeAnalogy
ForwardingData PlaneLocal, per-routerGetting through one highway interchange
RoutingControl PlaneNetwork-wide, end-to-endPlanning your entire road trip on a map

Data Plane (Forwarding)

  • Operates per-router in hardware → nanosecond speed
  • Looks up the destination IP in the local forwarding table → picks an output port

Control Plane (Routing) — Two Approaches

1. Traditional Per-Router Routing

  • Each router runs its own routing algorithm (e.g., OSPF, BGP)
  • Routers talk to each other to build forwarding tables
  • Think of each taxi driver independently knowing the city map

2. Software-Defined Networking (SDN)

  • A remote controller (server) computes routes centrally
  • Each router just has a Local Control Agent (CA) that talks to the controller
  • The controller pushes a Flow Table (much richer than a plain forwarding table) to each router
  • Think of separating the GPS app (control plane) from the car's engine (data plane)

3. IP Datagram Format (IPv4)

Every IP packet has a 20-byte minimum header (32 bits wide per row):

| ver(4) | head.len(4) | type of service(8) | total length(16)     |
| identification(16)              | flags(3) | fragment offset(13) |
| TTL(8)          | upper layer protocol(8) | header checksum(16) |
|                      source IP address (32)                      |
|                   destination IP address (32)                    |
|                   options (if any) + data                        |
FieldSizeDescription
ver4 bitsIP version (4 = IPv4)
head.len4 bitsHeader length in 32-bit words
type of service8 bitsQoS hints (Diffserv/ECN)
length16 bitsTotal datagram length in bytes
identification16 bitsUsed for fragment reassembly
flags3 bitsDF (don't fragment), MF (more fragments)
fragment offset13 bitsPosition of fragment in original datagram
TTL8 bitsDecremented at each hop; drop at 0
upper layer protocol8 bits6=TCP, 17=UDP, 1=ICMP
checksum16 bitsIntegrity check of header only
src/dst IP32 bits eachSource and destination addresses

TTL = Time To Live: Prevents packets from looping forever. Each router decrements TTL by 1. If TTL = 0, the packet is dropped and an ICMP TTL Expired message is sent back to source.

Overhead calculation: 20-byte IP header + 20-byte TCP header = 40 bytes of overhead for just 1 byte of data.


4. IP Addressing Fundamentals

Structure

  • IPv4 address: 32-bit, written in dotted-decimal notation (4 octets, 0–255 each)
  • Example: 192.168.32.152 = 11000000.10101000.00100000.10011000

Binary Reference Table

Bit position76543210
Value if bit=11286432168421

3 notations for the same address:

NotationExample
Binary10000000 00001011 00000011 00011111
Dotted Decimal128.11.3.31
Hexadecimal80 0B 03 1F

5. Subnet & Subnet Mask

Why subnet? Without subnets, a broadcast from one machine goes to ALL 4.3 billion addresses. Subnets isolate broadcast domains.

Analogy: Subnetting = dividing a city into neighbourhoods. Broadcasts only flood within your neighbourhood (subnet), not the whole city.

Subnet Mask

  • IP = Network Portion (prefix) + Host Portion (suffix)
  • Subnet mask: 1s for network bits, 0s for host bits

Example: 192.168.10.10/24

Octet 1Octet 2Octet 3Octet 4
IPv4 Address1921681010
Subnet Mask2552552550

3 Special Addresses in Every Subnet

TypeDescriptionExample (192.168.30.0/24)
Network AddressFirst IP — identifies the subnet192.168.30.0
Host AddressesUsable IPs for devices192.168.30.1 – 192.168.30.254
Broadcast AddressLast IP — floods to all hosts in subnet192.168.30.255

Usable Hosts=2host bits−2\boxed{\text{Usable Hosts} = 2^{\text{host bits}} - 2}

Subtract 2 because: 1 for Network Address + 1 for Broadcast Address.

Broadcast Domain

  • Broadcast packets (e.g., ARP requests, DHCP Discover, ping to broadcast) are scoped within the subnet
  • Routers do NOT forward broadcasts to other subnets
  • This is why you can separate traffic, improve security, and reduce congestion with subnetting

6. IP Address Classes (Classful Addressing)

4 main IP range splitting techniques: Classful, Public/Private, CIDR, VLSM

Class Table

ClassFirst OctetFixed Prefix BitsNet MaskPrefixNetworksHosts/Net
A1–1270xxxxxxx255.0.0.0/8128 (272^7)16,777,214
B128–19110xxxxxx255.255.0.0/1616,384 (2142^{14})65,534
C192–223110xxxxx255.255.255.0/242,097,152 (2212^{21})254
D224–239———Multicast only—
E240–254———Reserved/Experimental—

Analogy:

  • Class A = a country (few, but enormous networks — used by ISPs)
  • Class B = a state/province (medium — enterprises)
  • Class C = a neighbourhood (many small networks — most common)

Reserved Addresses

  • 127.0.0.1 → Loopback (refers to yourself — Class A reserved)
  • 169.254.0.0/16 → Link-local / APIPA (auto-assigned when no DHCP server found — Class B reserved)

Formulas

Total Networks (Class A)=27=128(7 net ID bits)\text{Total Networks (Class A)} = 2^7 = 128 \quad \text{(7 net ID bits)} Hosts per Network=2host bits−2\text{Hosts per Network} = 2^{\text{host bits}} - 2

Class B Detail (128–191):

  • Fixed prefix bits: 10 → range 128.x.x.x to 191.x.x.x
  • Networks = 214=16,3842^{14} = 16{,}384
  • Hosts per network = 216−2=65,5342^{16} - 2 = 65{,}534

7. Public vs Private IP Addresses

TypeDescriptionWho AssignsRoutable on Internet?
Public IPGlobally unique, one per device on the internetISP (you pay)✅ Yes
Private IPFree to use internally, not unique globallyNetwork Admin❌ No — needs NAT to reach internet

Private IP Ranges

RangePrefix
10.0.0.0 – 10.255.255.25510.0.0.0/8
172.16.0.0 – 172.31.255.255172.16.0.0/12
192.168.0.0 – 192.168.255.255192.168.0.0/16

Your home router's LAN uses 192.168.x.x (private). Your ISP assigns you one public IP. All devices in your home share that one public IP via NAT.


8. DHCP — Dynamic Host Configuration Protocol

Purpose: When you plug into a network, you get an IP automatically. No manual config needed ("plug-and-play").

DHCP lives in the router — co-located on most home/office routers.

4-Step Process (DORA)

StepMessageDirectionDescription
1DHCP DiscoverClient → Broadcast (255.255.255.255)"Is there a DHCP server?"
2DHCP OfferServer → Broadcast"I'm a server! Here's an IP for you"
3DHCP RequestClient → Broadcast"I accept that IP!"
4DHCP ACKServer → Broadcast"Confirmed! It's yours."

Why broadcast? The client has no IP yet, so it can't send unicast. All DHCP messages use broadcast until the IP is confirmed. Steps 1 & 2 can be skipped if the client remembers its old IP and wants to reuse it [RFC 2131].

Packet Details (Real Exam Values)

DHCP Discover:
  src: 0.0.0.0:68 → dst: 255.255.255.255:67
  yiaddr: 0.0.0.0, transaction ID: 654

DHCP Offer:
  src: 223.1.2.5:67 → dst: 255.255.255.255:68
  yiaddr: 223.1.2.4, transaction ID: 654, lifetime: 3600 sec

DHCP Request:
  src: 0.0.0.0:68 → dst: 255.255.255.255:67
  yiaddr: 223.1.2.4, transaction ID: 655, lifetime: 3600 sec

DHCP ACK:
  src: 223.1.2.5:67 → dst: 255.255.255.255:68
  yiaddr: 223.1.2.4, transaction ID: 655, lifetime: 3600 sec

Ports: Server listens on 67, client on 68. Always UDP.

DHCP Returns More Than Just an IP

DHCP also hands you:

  • Your IP address (e.g., 192.168.1.43)
  • Subnet mask (e.g., 255.255.255.0)
  • Default Gateway — address of your first-hop router (e.g., 192.168.1.1)
  • DNS Server — so you can resolve domain names (e.g., 8.8.8.8)

Encapsulation Path

DHCP message → UDP → IP → Ethernet (broadcast FF:FF:FF:FF:FF:FF)


9. CIDR — Classless Inter-Domain Routing

Classful addressing was wasteful — an org with 300 hosts gets a Class B (65,534 hosts). CIDR lets you use any prefix length.

Key Formulas

Host bits=32−prefix length\boxed{\text{Host bits} = 32 - \text{prefix length}} Usable IPs=2host bits−2\boxed{\text{Usable IPs} = 2^{\text{host bits}} - 2} Subnets created=2bits borrowed from host\boxed{\text{Subnets created} = 2^{\text{bits borrowed from host}}}

Pizza analogy: The prefix locks in slices as "network." The remaining bits are slices for hosts. Always lose 2 slices (network address + broadcast).

CIDR Subnet Mask Reference Table

PrefixSubnet MaskHost BitsUsable IPs
/8255.0.0.02416,777,214
/16255.255.0.01665,534
/20255.255.240.0124,094
/23255.255.254.09510
/24255.255.255.08254
/25255.255.255.1287126
/26255.255.255.192662
/27255.255.255.224530
/28255.255.255.240414
/29255.255.255.24836
/30255.255.255.25222
/32255.255.255.25501 specific host

CIDR Example 1: 128.143.137.144/20

  • Host bits = 32 − 20 = 12
  • Total IPs = 212−2=4,0942^{12} - 2 = 4{,}094
  • Network Address = 128.143.128.0
  • First Host = 128.143.128.1
  • Last Host = 128.143.143.254
  • Broadcast = 128.143.143.255

CIDR Example 2: Split 192.168.10.0/24 into 2 subnets → /25

  • Borrow 1 bit → 21=22^1 = 2 subnets
  • Each subnet has 27−2=1262^7 - 2 = 126 usable hosts
SubnetNetworkBroadcastHost Range
1192.168.10.0/25.127.1 – .126
2192.168.10.128/25.255.129 – .254

Key Questions for Any Subnet (exam checklist)

  1. How many subnets does the mask produce?
  2. How many valid hosts per subnet?
  3. What are the valid subnet addresses?
  4. What is the broadcast address of each subnet?
  5. What are the valid host IPs in each subnet?

10. VLSM — Variable Length Subnet Mask

VLSM = different subnets get different-sized masks. Assign mask based on how many hosts each subnet needs. Far more efficient than CIDR (fixed-size for all).

Rule: Sort subnets largest first, allocate, then work down.

VLSM vs CIDR Comparison

MethodMaskFlexibilityWasted IPs
CIDRSame /xx for all subnetsLowHigh
VLSMDifferent /xx per subnetHighLow (most efficient)

Step-by-Step VLSM Procedure

Given: 204.15.5.0/24
Requirements: netA=14, netB=28, netC=2, netD=7, netE=28

Step 1 — Pick mask for each subnet

SubnetHosts NeededMask NeededPrefixUsable
netB28255.255.255.224/2725−2=302^5-2=30
netE28255.255.255.224/2730
netA14255.255.255.240/2824−2=142^4-2=14
netD7255.255.255.240/2814
netC2255.255.255.252/3022−2=22^2-2=2

Step 2 — Assign largest first (allocate sequentially)

204.15.5.0/24 → /27 (8 blocks: 0,32,64,96,128,160,192,224)

SubnetAllocatedNetwork AddressMaskHost RangeBroadcast
B (28)/27204.15.5.0255.255.255.224.1–.30.31
E (28)/27204.15.5.32255.255.255.224.33–.62.63
A (14)/28204.15.5.64255.255.255.240.65–.78.79
D (7)/28204.15.5.80255.255.255.240.81–.94.95
C (2)/30204.15.5.96255.255.255.252.97–.98.99

VLSM Worked Example 2 — 192.168.0.0/20

Requirements: Net A=100, Net B=300, Net C=254, R1-R2=2, R2-R3=2

SubnetHostsPrefixNetworkHost RangeBroadcast
B (300)510 avail/23192.168.0.0/23.0.1–.1.254192.168.1.255
C (254)254 avail/24192.168.2.0/24.2.1–.2.254192.168.2.255
A (100)126 avail/25192.168.3.0/25.3.1–.3.126192.168.3.127
R1-R2 (2)2 avail/30192.168.3.128/30.3.129–.3.130192.168.3.131
R2-R3 (2)2 avail/30192.168.3.132/30.3.133–.3.134192.168.3.135

11. IP Addressing: How Does a Network Get Its Block?

  • A network gets its subnet part from its ISP's address space

Route Aggregation (Hierarchical Addressing)

  • ISP block: 200.23.16.0/20
  • ISP splits it into 8 × /23 blocks for 8 organizations:
OrgAddress
0200.23.16.0/23
1200.23.18.0/23
……
7200.23.30.0/23
  • The ISP advertises just one prefix (200.23.16.0/20) to the entire internet — this covers all 8 orgs
  • ISPs also have Autonomous System (AS) Numbers — unique identifiers per ISP

12. NAT — Network Address Translation

Problem: IPv4 only has ~4.3 billion addresses — not enough for every device on Earth.
NAT Solution: All devices on a LAN share one public IP as seen from the internet.

Analogy: NAT is like an apartment building — many residents (private IPs) share one street address (public IP). The lobby receptionist (NAT router) knows which apartment each parcel goes to via a mapping table.

How NAT Works

Outgoing (LAN → Internet):

  1. Replace (private IP, src port) → (public IP, new NAT port)
  2. Record this mapping in the NAT translation table

Incoming (Internet → LAN):

  1. Look up (public IP, port) in NAT table
  2. Replace with (original private IP, original port)
  3. Forward to correct internal host

NAT Example (Step-by-Step)

Host 10.0.0.1:3345 → 128.119.40.186:80

Step 1: Host sends datagram
  Src: 10.0.0.1:3345   Dst: 128.119.40.186:80

Step 2: NAT router rewrites source
  Src: 138.76.29.7:5001  Dst: 128.119.40.186:80
  [NAT table: 138.76.29.7:5001 ↔ 10.0.0.1:3345]

Step 3: Reply arrives
  Src: 128.119.40.186:80  Dst: 138.76.29.7:5001

Step 4: NAT rewrites destination
  Src: 128.119.40.186:80  Dst: 10.0.0.1:3345

The NAT table maps using IP + Port (not just IP) — 16-bit port = up to 65,536 simultaneous connections per public IP.

NAT Advantages

  • Only one public IP needed from ISP for all internal devices
  • Can change internal IPs without notifying the internet
  • Security: internal devices are not directly reachable from outside

NAT Controversies

  • ⚠️ Routers should only operate up to L3, but NAT touches L4 port numbers
  • ⚠️ Violates the end-to-end argument (network device modifies port info)
  • ⚠️ NAT traversal problem: hard for external clients to reach servers behind NAT
    • Solutions: Port Forwarding (manual NAT table entry), DDNS (for dynamic public IPs), ngrok (tunnel service)
  • ✅ Still widely used everywhere (home, offices, cellular networks)

13. IPv4 Address Exhaustion & IPv6

IPv4 Exhaustion

  • ICANN allocated the last chunk of IPv4 in 2011
  • IPv4 = 32-bit = ~4.3 billion addresses (not enough!)
  • Short-term workaround: NAT
  • Long-term solution: IPv6

IPv6

FeatureIPv4IPv6
Address size32-bit128-bit
Header sizeVariable (20+ bytes)Fixed 40 bytes
ChecksumYesNo (speeds up routers)
FragmentationYes (at routers)No (endpoints only)
OptionsIn headerAs next-header extensions
TTLTTL fieldHop Limit field

IPv6 Datagram Format:

| ver(4) | priority(8) |    flow label(20)            |
| payload length(16)  | next header(8) | hop limit(8) |
|              source address (128 bits)               |
|           destination address (128 bits)             |
|                     payload                          |
  • flow label: identify datagrams in the same "flow" (for QoS)
  • next hdr: identifies upper-layer protocol (replaces options)
  • hop limit: replaces TTL

IPv6 is like a streamlined express lane — removed all the overhead IPv4 had at every router to make forwarding blazing fast.

IPv4 → IPv6 Transition: Tunneling

Challenge: Can't flip all routers overnight ("no flag day"). Must coexist.

Solution: Tunneling — carry IPv6 datagram as payload inside an IPv4 datagram between IPv4-only routers.

IPv4 datagram (B → E):
+--- IPv4 header (src=B, dst=E) ---+
|  IPv6 datagram (src=A, dst=F):  |
|  +-- IPv6 header                |
|  |   payload (data)             |
|  +----------------------------  |
+----------------------------------+

Flow through nodes A → B → C → D → E → F:

  • A→B: Native IPv6
  • B→C→D→E: IPv6 tunneled inside IPv4 (B wraps, E unwraps)
  • E→F: Native IPv6

Tunneling = like putting an international package (IPv6) inside a domestic shipping box (IPv4) — the outer box travels through the local postal system, but the real destination is international.


14. ICMP — Internet Control Message Protocol

Purpose: Error reporting and network diagnostics. Carried inside IP datagrams (sits above IP logically).

Real-world tools that use ICMP: ping, traceroute

Common ICMP Messages

TypeCodeDescriptionTriggered By
00Echo Replyping response
30Destination Network UnreachableRouting failure
31Destination Host UnreachableHost down
32Destination Protocol UnreachableProtocol not supported
33Destination Port UnreachableUsed by traceroute to STOP
36Destination Network Unknown—
37Destination Host Unknown—
40Source Quench (congestion)Deprecated
80Echo Requestping sent
90Router Advertisement—
100Router Discovery—
110TTL ExpiredUsed by traceroute to MAP hops
120Bad IP Header—

How traceroute Works (Step-by-Step)

Mechanism: Sends UDP segments with increasing TTL values. Each router that drops a packet sends back an ICMP TTL Expired message, revealing its identity.

1st set: TTL=1  → 1st router drops it → sends ICMP Type 11 back → source records RTT
2nd set: TTL=2  → 2nd router drops it → sends ICMP Type 11 back → source records RTT
...
nth set: TTL=n  → reaches destination → destination sends ICMP Type 3, Code 3 (Port Unreachable)

Stopping criteria: UDP segment reaches destination → destination returns ICMP Port Unreachable (Type 3, Code 3)→ traceroute stops.

Traceroute = "Marco Polo" with a timer that resets at each pool wall. Each router shouts back "Polo!" when its turn runs out, telling you how far it is.


15. Network Diagrams

Logical Network Diagram

  • Shows how information flows: subnets (cloud shapes), routing protocols, IP addresses on interfaces
  • Used to understand routing logic

Physical Network Diagram

  • Shows actual physical topology: all devices, cable connections, interface names
  • ⚠️ EXAM NOTE: Must label interface names (eth0, eth1, eth2) and their IP addresses — this is the most common mistake!

Example physical layout:

A — (Network A) — [R1: eth0=.1, eth1=.2] — (Network B) — [R2: eth0=.3, eth1=.4] — (Network C) — B

16. Summary Comparison Table

TopicKey Name / ValueRemember
ClassfulA=/8, B=/16, C=/24Fixed, wasteful
CIDRAny prefix length /xxFlexible splitting, same size per subnet
VLSMDifferent /xx per subnetMost efficient, largest-first allocation
DHCPDiscover→Offer→Request→ACKPorts: server 67, client 68, all broadcast
NATPrivate↔Public via IP+Port table16-bit port = 65k sessions per public IP
ICMPType 11=TTL Expired, Type 3 Code 3=Port UnreachableUsed by traceroute
IPv6128-bit, 40-byte fixed header, no checksum, no fragmentationTunneling for transition
ForwardingData plane, local, per-router, nanosecondsLookup in forwarding table
RoutingControl plane, network-wide, millisecondsOSPF (per-router), SDN (centralized)
Loopback127.0.0.1Refers to yourself
APIPA169.254.0.0/16Auto-assigned when no DHCP found

17. Quick Formula Sheet

Usable Hosts=2host bits−2\text{Usable Hosts} = 2^{\text{host bits}} - 2 Host bits=32−prefix\text{Host bits} = 32 - \text{prefix} Subnets=2bits borrowed\text{Subnets} = 2^{\text{bits borrowed}} Subnet increment (block size)=256−last non-zero octet of subnet mask\text{Subnet increment (block size)} = 256 - \text{last non-zero octet of subnet mask}

Example — block size for /27 (mask 255.255.255.224):

  • Last octet of mask = 224
  • Block size = 256 − 224 = 32
  • Subnets start at: 0, 32, 64, 96, 128, 160, 192, 224

Example — block size for /28 (mask 255.255.255.240):

  • Block size = 256 − 240 = 16
  • Subnets start at: 0, 16, 32, 48, 64, 80, 96, …

Example — block size for /30 (mask 255.255.255.252):

  • Block size = 256 − 252 = 4
  • Subnets start at: 0, 4, 8, 12, 96, 100, …