CSS334 – Network Layer Cheat Sheet (Lectures 7 & 8)
0. Big Picture: Where Does the Network Layer Live?
Application → HTTP, SMTP, DNS, FTP
Transport → TCP (reliable), UDP (fast, no guarantee)
Network (L3) → IP, ARP, ICMP, IGMP ← YOU ARE HERE
Data Link (L2)→ Ethernet, Wi-Fi
Physical (L1) → Cables, fiber, radio
Analogy: Sending a package internationally — App = you writing the letter, Transport = courier service, Network = postal routing system deciding which country/city, Link+Physical = actual roads and trucks.
When you type google.com in a browser, across layers:
| Layer | What Happens | Example Values |
|---|---|---|
| Application | Browser sends HTTP GET | GET / HTTP/1.1 |
| Transport | TCP wraps with ports | Src Port: 4546 → Dst Port: 80 |
| Network | IP wraps with addresses | Src: 192.168.0.1 → Dst: 203.159.10.11 |
| Data Link | MAC addresses added | Src MAC: B4:6B:FC:7F:7F:8C → Dst MAC: 8C:16:45:74:32:AA |
Routers only operate at L3 + L2 + L1 — they don't care about transport or application headers.
1. Network Devices (Hub, Switch, Router)
| Device | Layer | Identifier Used | Behaviour |
|---|---|---|---|
| Hub | L1 – Physical | None | Floods every packet to all ports (obsolete) |
| Switch | L2 – Data Link | MAC Address | Learns MAC → forwards to the correct port only |
| Router | L3 – Network | IP Address | Routes packets between different networks |
Analogy:
- Hub = shouting in a room (everyone hears — bad)
- Switch = whispering directly to the right person
- Router = a post office directing mail between cities
Key Rule: Different subnets MUST be connected through a Router. A switch alone cannot route between subnets.
Interface
- Interface = the connection point between a host/router and a physical link
- Routers have multiple interfaces (e.g.,
eth0,eth1,eth2), each with its own IP address - Hosts typically have 1–2 interfaces (wired
eth0, wirelesswlan0)
2. Network Layer: Two Key Functions
| Function | Plane | Scope | Analogy |
|---|---|---|---|
| Forwarding | Data Plane | Local, per-router | Getting through one highway interchange |
| Routing | Control Plane | Network-wide, end-to-end | Planning your entire road trip on a map |
Data Plane (Forwarding)
- Operates per-router in hardware → nanosecond speed
- Looks up the destination IP in the local forwarding table → picks an output port
Control Plane (Routing) — Two Approaches
1. Traditional Per-Router Routing
- Each router runs its own routing algorithm (e.g., OSPF, BGP)
- Routers talk to each other to build forwarding tables
- Think of each taxi driver independently knowing the city map
2. Software-Defined Networking (SDN)
- A remote controller (server) computes routes centrally
- Each router just has a Local Control Agent (CA) that talks to the controller
- The controller pushes a Flow Table (much richer than a plain forwarding table) to each router
- Think of separating the GPS app (control plane) from the car's engine (data plane)
3. IP Datagram Format (IPv4)
Every IP packet has a 20-byte minimum header (32 bits wide per row):
| ver(4) | head.len(4) | type of service(8) | total length(16) |
| identification(16) | flags(3) | fragment offset(13) |
| TTL(8) | upper layer protocol(8) | header checksum(16) |
| source IP address (32) |
| destination IP address (32) |
| options (if any) + data |
| Field | Size | Description |
|---|---|---|
ver | 4 bits | IP version (4 = IPv4) |
head.len | 4 bits | Header length in 32-bit words |
type of service | 8 bits | QoS hints (Diffserv/ECN) |
length | 16 bits | Total datagram length in bytes |
identification | 16 bits | Used for fragment reassembly |
flags | 3 bits | DF (don't fragment), MF (more fragments) |
fragment offset | 13 bits | Position of fragment in original datagram |
TTL | 8 bits | Decremented at each hop; drop at 0 |
upper layer protocol | 8 bits | 6=TCP, 17=UDP, 1=ICMP |
checksum | 16 bits | Integrity check of header only |
src/dst IP | 32 bits each | Source and destination addresses |
TTL = Time To Live: Prevents packets from looping forever. Each router decrements TTL by 1. If TTL = 0, the packet is dropped and an ICMP TTL Expired message is sent back to source.
Overhead calculation: 20-byte IP header + 20-byte TCP header = 40 bytes of overhead for just 1 byte of data.
4. IP Addressing Fundamentals
Structure
- IPv4 address: 32-bit, written in dotted-decimal notation (4 octets, 0–255 each)
- Example:
192.168.32.152=11000000.10101000.00100000.10011000
Binary Reference Table
| Bit position | 7 | 6 | 5 | 4 | 3 | 2 | 1 | 0 |
|---|---|---|---|---|---|---|---|---|
| Value if bit=1 | 128 | 64 | 32 | 16 | 8 | 4 | 2 | 1 |
3 notations for the same address:
| Notation | Example |
|---|---|
| Binary | 10000000 00001011 00000011 00011111 |
| Dotted Decimal | 128.11.3.31 |
| Hexadecimal | 80 0B 03 1F |
5. Subnet & Subnet Mask
Why subnet? Without subnets, a broadcast from one machine goes to ALL 4.3 billion addresses. Subnets isolate broadcast domains.
Analogy: Subnetting = dividing a city into neighbourhoods. Broadcasts only flood within your neighbourhood (subnet), not the whole city.
Subnet Mask
- IP = Network Portion (prefix) + Host Portion (suffix)
- Subnet mask:
1sfor network bits,0sfor host bits
Example: 192.168.10.10/24
| Octet 1 | Octet 2 | Octet 3 | Octet 4 | |
|---|---|---|---|---|
| IPv4 Address | 192 | 168 | 10 | 10 |
| Subnet Mask | 255 | 255 | 255 | 0 |
3 Special Addresses in Every Subnet
| Type | Description | Example (192.168.30.0/24) |
|---|---|---|
| Network Address | First IP — identifies the subnet | 192.168.30.0 |
| Host Addresses | Usable IPs for devices | 192.168.30.1 – 192.168.30.254 |
| Broadcast Address | Last IP — floods to all hosts in subnet | 192.168.30.255 |
Subtract 2 because: 1 for Network Address + 1 for Broadcast Address.
Broadcast Domain
- Broadcast packets (e.g., ARP requests, DHCP Discover, ping to broadcast) are scoped within the subnet
- Routers do NOT forward broadcasts to other subnets
- This is why you can separate traffic, improve security, and reduce congestion with subnetting
6. IP Address Classes (Classful Addressing)
4 main IP range splitting techniques: Classful, Public/Private, CIDR, VLSM
Class Table
| Class | First Octet | Fixed Prefix Bits | Net Mask | Prefix | Networks | Hosts/Net |
|---|---|---|---|---|---|---|
| A | 1–127 | 0xxxxxxx | 255.0.0.0 | /8 | 128 () | 16,777,214 |
| B | 128–191 | 10xxxxxx | 255.255.0.0 | /16 | 16,384 () | 65,534 |
| C | 192–223 | 110xxxxx | 255.255.255.0 | /24 | 2,097,152 () | 254 |
| D | 224–239 | — | — | — | Multicast only | — |
| E | 240–254 | — | — | — | Reserved/Experimental | — |
Analogy:
- Class A = a country (few, but enormous networks — used by ISPs)
- Class B = a state/province (medium — enterprises)
- Class C = a neighbourhood (many small networks — most common)
Reserved Addresses
127.0.0.1→ Loopback (refers to yourself — Class A reserved)169.254.0.0/16→ Link-local / APIPA (auto-assigned when no DHCP server found — Class B reserved)
Formulas
Class B Detail (128–191):
- Fixed prefix bits:
10→ range128.x.x.xto191.x.x.x - Networks =
- Hosts per network =
7. Public vs Private IP Addresses
| Type | Description | Who Assigns | Routable on Internet? |
|---|---|---|---|
| Public IP | Globally unique, one per device on the internet | ISP (you pay) | ✅ Yes |
| Private IP | Free to use internally, not unique globally | Network Admin | ❌ No — needs NAT to reach internet |
Private IP Ranges
| Range | Prefix |
|---|---|
10.0.0.0 – 10.255.255.255 | 10.0.0.0/8 |
172.16.0.0 – 172.31.255.255 | 172.16.0.0/12 |
192.168.0.0 – 192.168.255.255 | 192.168.0.0/16 |
Your home router's LAN uses
192.168.x.x(private). Your ISP assigns you one public IP. All devices in your home share that one public IP via NAT.
8. DHCP — Dynamic Host Configuration Protocol
Purpose: When you plug into a network, you get an IP automatically. No manual config needed ("plug-and-play").
DHCP lives in the router — co-located on most home/office routers.
4-Step Process (DORA)
| Step | Message | Direction | Description |
|---|---|---|---|
| 1 | DHCP Discover | Client → Broadcast (255.255.255.255) | "Is there a DHCP server?" |
| 2 | DHCP Offer | Server → Broadcast | "I'm a server! Here's an IP for you" |
| 3 | DHCP Request | Client → Broadcast | "I accept that IP!" |
| 4 | DHCP ACK | Server → Broadcast | "Confirmed! It's yours." |
Why broadcast? The client has no IP yet, so it can't send unicast. All DHCP messages use broadcast until the IP is confirmed. Steps 1 & 2 can be skipped if the client remembers its old IP and wants to reuse it [RFC 2131].
Packet Details (Real Exam Values)
DHCP Discover:
src: 0.0.0.0:68 → dst: 255.255.255.255:67
yiaddr: 0.0.0.0, transaction ID: 654
DHCP Offer:
src: 223.1.2.5:67 → dst: 255.255.255.255:68
yiaddr: 223.1.2.4, transaction ID: 654, lifetime: 3600 sec
DHCP Request:
src: 0.0.0.0:68 → dst: 255.255.255.255:67
yiaddr: 223.1.2.4, transaction ID: 655, lifetime: 3600 sec
DHCP ACK:
src: 223.1.2.5:67 → dst: 255.255.255.255:68
yiaddr: 223.1.2.4, transaction ID: 655, lifetime: 3600 sec
Ports: Server listens on 67, client on 68. Always UDP.
DHCP Returns More Than Just an IP
DHCP also hands you:
- Your IP address (e.g.,
192.168.1.43) - Subnet mask (e.g.,
255.255.255.0) - Default Gateway — address of your first-hop router (e.g.,
192.168.1.1) - DNS Server — so you can resolve domain names (e.g.,
8.8.8.8)
Encapsulation Path
DHCP message → UDP → IP → Ethernet (broadcast FF:FF:FF:FF:FF:FF)
9. CIDR — Classless Inter-Domain Routing
Classful addressing was wasteful — an org with 300 hosts gets a Class B (65,534 hosts). CIDR lets you use any prefix length.
Key Formulas
Pizza analogy: The prefix locks in slices as "network." The remaining bits are slices for hosts. Always lose 2 slices (network address + broadcast).
CIDR Subnet Mask Reference Table
| Prefix | Subnet Mask | Host Bits | Usable IPs |
|---|---|---|---|
| /8 | 255.0.0.0 | 24 | 16,777,214 |
| /16 | 255.255.0.0 | 16 | 65,534 |
| /20 | 255.255.240.0 | 12 | 4,094 |
| /23 | 255.255.254.0 | 9 | 510 |
| /24 | 255.255.255.0 | 8 | 254 |
| /25 | 255.255.255.128 | 7 | 126 |
| /26 | 255.255.255.192 | 6 | 62 |
| /27 | 255.255.255.224 | 5 | 30 |
| /28 | 255.255.255.240 | 4 | 14 |
| /29 | 255.255.255.248 | 3 | 6 |
| /30 | 255.255.255.252 | 2 | 2 |
| /32 | 255.255.255.255 | 0 | 1 specific host |
CIDR Example 1: 128.143.137.144/20
- Host bits = 32 − 20 = 12
- Total IPs =
- Network Address =
128.143.128.0 - First Host =
128.143.128.1 - Last Host =
128.143.143.254 - Broadcast =
128.143.143.255
CIDR Example 2: Split 192.168.10.0/24 into 2 subnets → /25
- Borrow 1 bit → subnets
- Each subnet has usable hosts
| Subnet | Network | Broadcast | Host Range |
|---|---|---|---|
| 1 | 192.168.10.0/25 | .127 | .1 – .126 |
| 2 | 192.168.10.128/25 | .255 | .129 – .254 |
Key Questions for Any Subnet (exam checklist)
- How many subnets does the mask produce?
- How many valid hosts per subnet?
- What are the valid subnet addresses?
- What is the broadcast address of each subnet?
- What are the valid host IPs in each subnet?
10. VLSM — Variable Length Subnet Mask
VLSM = different subnets get different-sized masks. Assign mask based on how many hosts each subnet needs. Far more efficient than CIDR (fixed-size for all).
Rule: Sort subnets largest first, allocate, then work down.
VLSM vs CIDR Comparison
| Method | Mask | Flexibility | Wasted IPs |
|---|---|---|---|
| CIDR | Same /xx for all subnets | Low | High |
| VLSM | Different /xx per subnet | High | Low (most efficient) |
Step-by-Step VLSM Procedure
Given: 204.15.5.0/24
Requirements: netA=14, netB=28, netC=2, netD=7, netE=28
Step 1 — Pick mask for each subnet
| Subnet | Hosts Needed | Mask Needed | Prefix | Usable |
|---|---|---|---|---|
| netB | 28 | 255.255.255.224 | /27 | |
| netE | 28 | 255.255.255.224 | /27 | 30 |
| netA | 14 | 255.255.255.240 | /28 | |
| netD | 7 | 255.255.255.240 | /28 | 14 |
| netC | 2 | 255.255.255.252 | /30 |
Step 2 — Assign largest first (allocate sequentially)
204.15.5.0/24 → /27 (8 blocks: 0,32,64,96,128,160,192,224)
| Subnet | Allocated | Network Address | Mask | Host Range | Broadcast |
|---|---|---|---|---|---|
| B (28) | /27 | 204.15.5.0 | 255.255.255.224 | .1–.30 | .31 |
| E (28) | /27 | 204.15.5.32 | 255.255.255.224 | .33–.62 | .63 |
| A (14) | /28 | 204.15.5.64 | 255.255.255.240 | .65–.78 | .79 |
| D (7) | /28 | 204.15.5.80 | 255.255.255.240 | .81–.94 | .95 |
| C (2) | /30 | 204.15.5.96 | 255.255.255.252 | .97–.98 | .99 |
VLSM Worked Example 2 — 192.168.0.0/20
Requirements: Net A=100, Net B=300, Net C=254, R1-R2=2, R2-R3=2
| Subnet | Hosts | Prefix | Network | Host Range | Broadcast |
|---|---|---|---|---|---|
| B (300) | 510 avail | /23 | 192.168.0.0/23 | .0.1–.1.254 | 192.168.1.255 |
| C (254) | 254 avail | /24 | 192.168.2.0/24 | .2.1–.2.254 | 192.168.2.255 |
| A (100) | 126 avail | /25 | 192.168.3.0/25 | .3.1–.3.126 | 192.168.3.127 |
| R1-R2 (2) | 2 avail | /30 | 192.168.3.128/30 | .3.129–.3.130 | 192.168.3.131 |
| R2-R3 (2) | 2 avail | /30 | 192.168.3.132/30 | .3.133–.3.134 | 192.168.3.135 |
11. IP Addressing: How Does a Network Get Its Block?
- A network gets its subnet part from its ISP's address space
Route Aggregation (Hierarchical Addressing)
- ISP block:
200.23.16.0/20 - ISP splits it into 8 ×
/23blocks for 8 organizations:
| Org | Address |
|---|---|
| 0 | 200.23.16.0/23 |
| 1 | 200.23.18.0/23 |
| … | … |
| 7 | 200.23.30.0/23 |
- The ISP advertises just one prefix (
200.23.16.0/20) to the entire internet — this covers all 8 orgs - ISPs also have Autonomous System (AS) Numbers — unique identifiers per ISP
12. NAT — Network Address Translation
Problem: IPv4 only has ~4.3 billion addresses — not enough for every device on Earth.
NAT Solution: All devices on a LAN share one public IP as seen from the internet.
Analogy: NAT is like an apartment building — many residents (private IPs) share one street address (public IP). The lobby receptionist (NAT router) knows which apartment each parcel goes to via a mapping table.
How NAT Works
Outgoing (LAN → Internet):
- Replace (private IP, src port) → (public IP, new NAT port)
- Record this mapping in the NAT translation table
Incoming (Internet → LAN):
- Look up (public IP, port) in NAT table
- Replace with (original private IP, original port)
- Forward to correct internal host
NAT Example (Step-by-Step)
Host 10.0.0.1:3345 → 128.119.40.186:80
Step 1: Host sends datagram
Src: 10.0.0.1:3345 Dst: 128.119.40.186:80
Step 2: NAT router rewrites source
Src: 138.76.29.7:5001 Dst: 128.119.40.186:80
[NAT table: 138.76.29.7:5001 ↔ 10.0.0.1:3345]
Step 3: Reply arrives
Src: 128.119.40.186:80 Dst: 138.76.29.7:5001
Step 4: NAT rewrites destination
Src: 128.119.40.186:80 Dst: 10.0.0.1:3345
The NAT table maps using IP + Port (not just IP) — 16-bit port = up to 65,536 simultaneous connections per public IP.
NAT Advantages
- Only one public IP needed from ISP for all internal devices
- Can change internal IPs without notifying the internet
- Security: internal devices are not directly reachable from outside
NAT Controversies
- ⚠️ Routers should only operate up to L3, but NAT touches L4 port numbers
- ⚠️ Violates the end-to-end argument (network device modifies port info)
- ⚠️ NAT traversal problem: hard for external clients to reach servers behind NAT
- Solutions: Port Forwarding (manual NAT table entry), DDNS (for dynamic public IPs), ngrok (tunnel service)
- ✅ Still widely used everywhere (home, offices, cellular networks)
13. IPv4 Address Exhaustion & IPv6
IPv4 Exhaustion
- ICANN allocated the last chunk of IPv4 in 2011
- IPv4 = 32-bit = ~4.3 billion addresses (not enough!)
- Short-term workaround: NAT
- Long-term solution: IPv6
IPv6
| Feature | IPv4 | IPv6 |
|---|---|---|
| Address size | 32-bit | 128-bit |
| Header size | Variable (20+ bytes) | Fixed 40 bytes |
| Checksum | Yes | No (speeds up routers) |
| Fragmentation | Yes (at routers) | No (endpoints only) |
| Options | In header | As next-header extensions |
| TTL | TTL field | Hop Limit field |
IPv6 Datagram Format:
| ver(4) | priority(8) | flow label(20) |
| payload length(16) | next header(8) | hop limit(8) |
| source address (128 bits) |
| destination address (128 bits) |
| payload |
- flow label: identify datagrams in the same "flow" (for QoS)
- next hdr: identifies upper-layer protocol (replaces options)
- hop limit: replaces TTL
IPv6 is like a streamlined express lane — removed all the overhead IPv4 had at every router to make forwarding blazing fast.
IPv4 → IPv6 Transition: Tunneling
Challenge: Can't flip all routers overnight ("no flag day"). Must coexist.
Solution: Tunneling — carry IPv6 datagram as payload inside an IPv4 datagram between IPv4-only routers.
IPv4 datagram (B → E):
+--- IPv4 header (src=B, dst=E) ---+
| IPv6 datagram (src=A, dst=F): |
| +-- IPv6 header |
| | payload (data) |
| +---------------------------- |
+----------------------------------+
Flow through nodes A → B → C → D → E → F:
- A→B: Native IPv6
- B→C→D→E: IPv6 tunneled inside IPv4 (B wraps, E unwraps)
- E→F: Native IPv6
Tunneling = like putting an international package (IPv6) inside a domestic shipping box (IPv4) — the outer box travels through the local postal system, but the real destination is international.
14. ICMP — Internet Control Message Protocol
Purpose: Error reporting and network diagnostics. Carried inside IP datagrams (sits above IP logically).
Real-world tools that use ICMP: ping, traceroute
Common ICMP Messages
| Type | Code | Description | Triggered By |
|---|---|---|---|
| 0 | 0 | Echo Reply | ping response |
| 3 | 0 | Destination Network Unreachable | Routing failure |
| 3 | 1 | Destination Host Unreachable | Host down |
| 3 | 2 | Destination Protocol Unreachable | Protocol not supported |
| 3 | 3 | Destination Port Unreachable | Used by traceroute to STOP |
| 3 | 6 | Destination Network Unknown | — |
| 3 | 7 | Destination Host Unknown | — |
| 4 | 0 | Source Quench (congestion) | Deprecated |
| 8 | 0 | Echo Request | ping sent |
| 9 | 0 | Router Advertisement | — |
| 10 | 0 | Router Discovery | — |
| 11 | 0 | TTL Expired | Used by traceroute to MAP hops |
| 12 | 0 | Bad IP Header | — |
How traceroute Works (Step-by-Step)
Mechanism: Sends UDP segments with increasing TTL values. Each router that drops a packet sends back an ICMP TTL Expired message, revealing its identity.
1st set: TTL=1 → 1st router drops it → sends ICMP Type 11 back → source records RTT
2nd set: TTL=2 → 2nd router drops it → sends ICMP Type 11 back → source records RTT
...
nth set: TTL=n → reaches destination → destination sends ICMP Type 3, Code 3 (Port Unreachable)
Stopping criteria: UDP segment reaches destination → destination returns ICMP Port Unreachable (Type 3, Code 3)→ traceroute stops.
Traceroute = "Marco Polo" with a timer that resets at each pool wall. Each router shouts back "Polo!" when its turn runs out, telling you how far it is.
15. Network Diagrams
Logical Network Diagram
- Shows how information flows: subnets (cloud shapes), routing protocols, IP addresses on interfaces
- Used to understand routing logic
Physical Network Diagram
- Shows actual physical topology: all devices, cable connections, interface names
- ⚠️ EXAM NOTE: Must label interface names (
eth0,eth1,eth2) and their IP addresses — this is the most common mistake!
Example physical layout:
A — (Network A) — [R1: eth0=.1, eth1=.2] — (Network B) — [R2: eth0=.3, eth1=.4] — (Network C) — B
16. Summary Comparison Table
| Topic | Key Name / Value | Remember |
|---|---|---|
| Classful | A=/8, B=/16, C=/24 | Fixed, wasteful |
| CIDR | Any prefix length /xx | Flexible splitting, same size per subnet |
| VLSM | Different /xx per subnet | Most efficient, largest-first allocation |
| DHCP | Discover→Offer→Request→ACK | Ports: server 67, client 68, all broadcast |
| NAT | Private↔Public via IP+Port table | 16-bit port = 65k sessions per public IP |
| ICMP | Type 11=TTL Expired, Type 3 Code 3=Port Unreachable | Used by traceroute |
| IPv6 | 128-bit, 40-byte fixed header, no checksum, no fragmentation | Tunneling for transition |
| Forwarding | Data plane, local, per-router, nanoseconds | Lookup in forwarding table |
| Routing | Control plane, network-wide, milliseconds | OSPF (per-router), SDN (centralized) |
| Loopback | 127.0.0.1 | Refers to yourself |
| APIPA | 169.254.0.0/16 | Auto-assigned when no DHCP found |
17. Quick Formula Sheet
Example — block size for /27 (mask 255.255.255.224):
- Last octet of mask = 224
- Block size = 256 − 224 = 32
- Subnets start at: 0, 32, 64, 96, 128, 160, 192, 224
Example — block size for /28 (mask 255.255.255.240):
- Block size = 256 − 240 = 16
- Subnets start at: 0, 16, 32, 48, 64, 80, 96, …
Example — block size for /30 (mask 255.255.255.252):
- Block size = 256 − 252 = 4
- Subnets start at: 0, 4, 8, 12, 96, 100, …