CSS334 — Network Layer (Part 2) Cheat Sheet
Exam-ready summary | Lecture 8 | All topics included
0. Quick Recap: 4 Techniques to Split IP Range
| Method | Prefix Length | When to Use |
|---|---|---|
| Classful (A/B/C) | Fixed (/8, /16, /24) | No constraint given — just use private ranges |
| Public/Private | Fixed | Separating LAN from internet |
| CIDR | Arbitrary, same for all subnets | Given a range, equal-split needed |
| VLSM | Arbitrary, different per subnet | Given a range, efficient split needed |
Rule of thumb:
- No condition → Classful private
- Given a range, easy equal split → CIDR
- Given a range, want efficient use → VLSM
⚠️ Always remember: Router-to-router WAN links count as a separate subnet! Don't forget to include them in your subnet count.
1. Why Classful Is Wasteful
Example: 5-subnet network (100, 300, 254 hosts + 2 WAN links)
| Subnet | Hosts Needed | Classful Allocation | IPs Given | Wasted |
|---|---|---|---|---|
| Network A | 100 | 192.168.0.0/24 | 254 | 154 |
| Network B | 300 | 172.16.0.0/16 | 65,534 | 65,234 ⚠️ |
| Network C | 254 | 192.168.1.0/24 | 254 | 0 |
| R1-R2 link | 2 | 192.168.2.0/24 | 254 | 252 |
| R2-R3 link | 2 | 192.168.3.0/24 | 254 | 252 |
Analogy: Classful is like renting an entire warehouse just to store a bicycle. Network B needs 300 IPs but gets 65,534.
2. CIDR — Classless Inter-Domain Routing
Pronounced "cider" 🍎
What is CIDR?
- Allocates IPs and routes with arbitrary prefix length (not locked to class boundaries)
- Address format: where = bits in the network portion
- Example:
200.23.16.0/23→ 23-bit network, 9-bit host - In classful, you'd be forced to /24 (Class C) or /16 (Class B) — no in between. CIDR lets you pick /23, /25, /20, etc.
Key Formulas
Borrowed bits = (new prefix) − (original prefix). Every bit you borrow doubles the number of subnets and halves the hosts per subnet.
CIDR Worked Examples
Example 1: 128.143.137.144/20
- Host bits = 32 − 20 = 12
- Usable hosts =
- Network address:
128.143.128.0/20- Why? Zero out the last 12 bits of
137.144: 137=10001001→ keep top 4 bits1000→10000000=128144=10010000→ zero out →00000000=0
- Why? Zero out the last 12 bits of
- First host:
128.143.128.1| Last host:128.143.143.254| Broadcast:128.143.143.255
Example 2: 192.168.10.0/25 (mask 255.255.255.128)
- Host bits = 32 − 25 = 7 → usable hosts per subnet
- Produces 2 subnets:
| Subnet | Network | Host Range | Broadcast |
|---|---|---|---|
| 1 | 192.168.10.0/25 | .1 – .126 | .127 |
| 2 | 192.168.10.128/25 | .129 – .254 | .255 |
CIDR Reference: Prefix → Subnet Mask
| CIDR | Subnet Mask | Host bits | Usable Hosts |
|---|---|---|---|
| /8 | 255.0.0.0 | 24 | 16,777,214 |
| /16 | 255.255.0.0 | 16 | 65,534 |
| /20 | 255.255.240.0 | 12 | 4,094 |
| /23 | 255.255.254.0 | 9 | 510 |
| /24 | 255.255.255.0 | 8 | 254 |
| /25 | 255.255.255.128 | 7 | 126 |
| /26 | 255.255.255.192 | 6 | 62 |
| /27 | 255.255.255.224 | 5 | 30 |
| /28 | 255.255.255.240 | 4 | 14 |
| /29 | 255.255.255.248 | 3 | 6 |
| /30 | 255.255.255.252 | 2 | 2 ← WAN links |
Memorise /30! It gives exactly 2 usable hosts — perfect for router-to-router WAN links.
3. CIDR: Splitting a /24 into Equal Subnets
Base network: 192.168.10.0/24
Split into 2 subnets → borrow 1 bit → /25
- subnets | hosts each
- Block size = 256 / 2 = 128 (jump between subnets)
| Subnet | Network | Host Range | Broadcast |
|---|---|---|---|
| 1 | 192.168.10.0/25 | .1 – .126 | .127 |
| 2 | 192.168.10.128/25 | .129 – .254 | .255 |
Split into 4 subnets → borrow 2 bits → /26
- subnets | hosts each
- Block size = 256 / 4 = 64
| Subnet | Network | Host Range | Broadcast |
|---|---|---|---|
| 1 | 192.168.10.0/26 | .1 – .62 | .63 |
| 2 | 192.168.10.64/26 | .65 – .126 | .127 |
| 3 | 192.168.10.128/26 | .129 – .190 | .191 |
| 4 | 192.168.10.192/26 | .193 – .254 | .255 |
Split into 5 subnets → round up to → borrow 3 bits → /27
- Need 5 subnets → is not enough → round up to
- hosts each | Block size = 256 / 8 = 32
| Subnet | Network | Host Range | Broadcast |
|---|---|---|---|
| 1 | 192.168.10.0/27 | .1 – .30 | .31 |
| 2 | 192.168.10.32/27 | .33 – .62 | .63 |
| 3 | 192.168.10.64/27 | .65 – .94 | .95 |
| 4 | 192.168.10.96/27 | .97 – .126 | .127 |
| 5 | 192.168.10.128/27 | .129 – .158 | .159 |
| … | … | … | … |
| 8 | 192.168.10.224/27 | .225 – .254 | .255 |
Exam tip: For "split into 5 subnets" questions, you still get 8 subnets (3 spare). You can use any 5 of the 8 — typically the first 5.
⚠️ Exam: Identify an IP's Role in a Subnet
Given an IP and prefix, determine if it is: Network Address, Broadcast Address, Valid Host, or Invalid/Reserved
Method:
- Calculate network address (zero out host bits)
- Calculate broadcast (set all host bits to 1)
- Everything in between = valid host
- First and last in range = not usable
4. CIDR: Equal-Subnet Network Design Example
Given: 192.168.0.0/20, split using CIDR → pick /23
Why /23? Largest subnet needs 300 hosts → ✓ (next smaller /24 only gives 254 ✗)
- Total subnets available from /20 using /23:
| Subnet | Hosts Needed | Allocated | Address |
|---|---|---|---|
| Network B | 300 | 510 | 192.168.0.0/23 |
| Network C | 254 | 510 | 192.168.2.0/23 |
| Network A | 100 | 510 | 192.168.4.0/23 |
| R1-R2 link | 2 | 510 | 192.168.6.0/23 |
| R2-R3 link | 2 | 510 | 192.168.8.0/23 |
⚠️ Problem: All 5 subnets use /23 (510 hosts), even the WAN links that only need 2 IPs. This is where VLSM is needed.
5. VLSM — Variable Length Subnet Mask
What is VLSM?
- An extension of CIDR that allows each subnet to have a different prefix length
- Each subnet gets exactly (or tightly) what it needs
- Key rule: Always assign the LARGEST subnet first
Analogy: Cutting a rope into pieces of different sizes for different purposes — instead of equal chunks where most get wasted.
CIDR vs VLSM Comparison
| Feature | CIDR | VLSM |
|---|---|---|
| Prefix lengths | Same for all subnets | Different per subnet |
| Efficiency | Better than classful | Best — near-zero waste |
| Complexity | Moderate | Higher — must plan carefully |
| WAN links | Wasteful (e.g., /23 for 2 hosts) | Efficient (/30 for WAN links) |
6. VLSM Step-by-Step Method
Full Example: 204.15.5.0/24
Requirements: netA=14, netB=28, netC=2, netD=7, netE=28
Step 1 — Sort by size (largest first):
| Subnet | Hosts Needed | Prefix | Mask | Usable |
|---|---|---|---|---|
| netB | 28 | /27 | 255.255.255.224 | |
| netE | 28 | /27 | 255.255.255.224 | |
| netA | 14 | /28 | 255.255.255.240 | |
| netD | 7 | /28 | 255.255.255.240 | |
| netC | 2 | /30 | 255.255.255.252 |
How to pick prefix: Find the smallest such that
- 28 hosts → → /27 ✓
- 14 hosts → → /28 ✓
- 2 hosts → → /30 ✓
Step 2 — Assign from the start of the block:
204.15.5.0/24 (256 IPs)
├── netB: 204.15.5.0/27 [.0 – .31 ] 32 IPs
├── netE: 204.15.5.32/27 [.32 – .63 ] 32 IPs
├── Remaining: 204.15.5.64/26 (64 IPs) → split for /28s
│ ├── netA: 204.15.5.64/28 [.64 – .79 ] 16 IPs
│ └── netD: 204.15.5.80/28 [.80 – .95 ] 16 IPs
├── Remaining: 204.15.5.96/27 (32 IPs) → split for /30
│ └── netC: 204.15.5.96/30 [.96 – .99 ] 4 IPs
└── Unused: 204.15.5.100 onward
Step 3 — Final Assignment Table:
| Subnet | Needed | Mask | Network Address | Host Range | Broadcast |
|---|---|---|---|---|---|
| B | 28 | 255.255.255.224 | 204.15.5.0/27 | .1 – .30 | .31 |
| E | 28 | 255.255.255.224 | 204.15.5.32/27 | .33 – .62 | .63 |
| A | 14 | 255.255.255.240 | 204.15.5.64/28 | .65 – .78 | .79 |
| D | 7 | 255.255.255.240 | 204.15.5.80/28 | .81 – .94 | .95 |
| C | 2 | 255.255.255.252 | 204.15.5.96/30 | .97 – .98 | .99 |
VLSM Network Design: 192.168.0.0/20
Requirements: B=300 hosts, C=254 hosts, A=100 hosts, R1-R2=2, R2-R3=2
| Subnet | Needed | Prefix | Network Address | Host Range | Broadcast |
|---|---|---|---|---|---|
| B | 300 | /23 | 192.168.0.0/23 | .0.1 – .1.254 | 192.168.1.255 |
| C | 254 | /24 | 192.168.2.0/24 | .2.1 – .2.254 | 192.168.2.255 |
| A | 100 | /25 | 192.168.3.0/25 | .3.1 – .3.126 | 192.168.3.127 |
| R1-R2 | 2 | /30 | 192.168.3.128/30 | .3.129 – .3.130 | 192.168.3.131 |
| R2-R3 | 2 | /30 | 192.168.3.132/30 | .3.133 – .3.134 | 192.168.3.135 |
How each split works:
192.168.0.0/20 → /23: block size=2 → subnets at .0, .2, .4, .6, .8 …
192.168.2.0/23 → /24: block size=1 → subnets at .2, .3
192.168.3.0/24 → /25: block size=128 → subnets at .0, .128
192.168.3.128/25 → /30: block size=4 → subnets at .128, .132, .136 …
7. ISP Address Allocation & Route Aggregation
How Networks Get Their IP Block
- ISPs are allocated large blocks from IANA (Internet Assigned Numbers Authority) via ICANN
- ISPs subdivide and distribute to organisations
Example: ISP block 200.23.16.0/20 split into 8 × /23:
| Org | Address |
|---|---|
| 0 | 200.23.16.0/23 |
| 1 | 200.23.18.0/23 |
| 2 | 200.23.20.0/23 |
| … | … |
| 7 | 200.23.30.0/23 |
Route Aggregation (Supernetting)
- The ISP advertises one summary route (
200.23.16.0/20) to the whole internet - Covers all 8 customer /23 blocks in one routing entry
- Hierarchical addressing = efficient routing table advertisement
- Each ISP has a unique AS Number (Autonomous System Number) as a global identifier
8. IPv4 Address Exhaustion
- ICANN allocated the last IPv4 chunk in 2011
- IPv4 = 32-bit = ~4.3 billion addresses — not enough for the modern internet
- Two solutions:
| Solution | Type | How |
|---|---|---|
| NAT | Short-term workaround | Many private IPs share one public IP |
| IPv6 | Long-term fix | 128-bit address space = addresses |
9. IPv6
Why IPv6?
- 128-bit addresses = addresses (practically unlimited)
- Fixed 40-byte header for faster processing and forwarding at routers
- Enables per-flow treatment ("flow label")
IPv4 and IPv6 must coexist — there's no "flag day" where everything switches at once. Hardware constraints mean migration is gradual.
IPv6 Datagram Format
|<——————————— 32 bits ——————————————>|
| ver (4) | priority (8) | flow label (20) |
| payload length (16) | next hdr (8) | hop limit (8) |
| |
| source address (128 bits) |
| |
| destination address (128 bits) |
| |
| payload / data |
| Field | Description |
|---|---|
ver | IP version = 6 |
priority | Identifies priority among datagrams in the same flow |
flow label | Identifies datagrams belonging to the same "flow" (QoS hint) |
payload length | Length of data following the fixed header |
next hdr | Identifies the upper-layer protocol (like IPv4's "Protocol" field) |
hop limit | Replaces IPv4 TTL — decremented at each router, dropped at 0 |
What IPv6 Removed vs IPv4 (and Why)
| Removed Field | Why Removed |
|---|---|
| Checksum | Speeds up router processing — L2 and L4 already do error checking |
| Fragmentation | IPv6 routers don't fragment — only endpoints fragment/reassemble |
| Options | Replaced by "next header" extension headers — keeps fixed 40-byte header |
IPv6 = express lane — removed all in-flight checks IPv4 did at every router. Result: much faster per-hop forwarding.
10. IPv4 → IPv6 Transition: Tunneling
The Challenge
- Cannot upgrade all routers simultaneously
- No "flag day" — IPv4 and IPv6 routers must coexist indefinitely
- Some routers understand IPv6, some only IPv4
Solution: Tunneling (Packet-within-a-Packet)
- IPv6 datagram is carried as the payload of an IPv4 datagram through IPv4-only regions
- The IPv4 "tunnel" wraps the IPv6 packet between two IPv6-capable routers
- Used in 4G/5G networks too
IPv4 datagram:
┌─────────────────────────────────────────────┐
│ IPv4 Header (src: B, dst: E) │
│ ┌───────────────────────────────────────┐ │
│ │ IPv6 Header (src: A, dst: F) │ │
│ │ Payload (actual data) │ │
│ └───────────────────────────────────────┘ │
└─────────────────────────────────────────────┘
Tunneling Flow (A → B → C → D → E → F)
| Segment | Type | Who Acts |
|---|---|---|
| A → B | Native IPv6 | — |
| B → C → D → E | IPv6 inside IPv4 tunnel | B wraps, E unwraps |
| E → F | Native IPv6 | — |
Analogy: Like putting an international package inside a domestic shipping box. The outer box travels through the local system; inside is the real package destined internationally.
11. NAT — Network Address Translation
What is NAT?
- All devices in a LAN share one public IPv4 address as seen by the internet
- Inside uses private IPs; router maps private ↔ public using a NAT translation table
- The table stores (Private IP : Private Port) ↔ (Public IP : Public Port) mappings
Analogy: Apartment building — many residents (private IPs) share one street address (public IP). The lobby receptionist (NAT router) knows which apartment each parcel goes to via a mapping table.
Private IP Ranges (RFC 1918)
| Class | Range | Prefix |
|---|---|---|
| A | 10.0.0.0 – 10.255.255.255 | 10/8 |
| B | 172.16.0.0 – 172.31.255.255 | 172.16/12 |
| C | 192.168.0.0 – 192.168.255.255 | 192.168/16 |
Why Port Numbers in NAT Table?
- The public IP is one address — it alone can't distinguish which internal host a reply goes to
- Port numbers (16-bit = up to 65,535 mappings) are included to uniquely identify each internal connection
- So the full mapping is: (private IP, private port) ↔ (public IP, assigned port)
NAT Operation: Outbound (LAN → Internet)
Step 1: Internal host sends packet
src: 10.0.0.1:3345 → dst: 128.119.40.186:80
Step 2: NAT router rewrites source IP+port
src: 138.76.29.7:5001 → dst: 128.119.40.186:80
NAT table entry: 138.76.29.7:5001 ↔ 10.0.0.1:3345
NAT Operation: Inbound (Internet → LAN)
Step 3: Reply arrives at NAT router
src: 128.119.40.186:80 → dst: 138.76.29.7:5001
Step 4: NAT router looks up table, rewrites destination
src: 128.119.40.186:80 → dst: 10.0.0.1:3345
→ forwarded to correct internal host
NAT Advantages
| Advantage | Detail |
|---|---|
| IP conservation | Only one public IP needed for all internal devices |
| Internal flexibility | Change internal IPs without notifying outside world |
| ISP independence | Change ISP without reconfiguring internal devices |
| Security | Internal devices not directly addressable from outside |
NAT Controversies (Know These!)
| Issue | Explanation |
|---|---|
| ⚠️ Violates layer model | Routers should only process up to L3; NAT touches L4 port numbers |
| ⚠️ End-to-end violation | Network device manipulates transport-layer info |
| ⚠️ Hides the real problem | IPv4 exhaustion should be solved by IPv6, not NAT workarounds |
| ⚠️ NAT traversal problem | Hard for external clients to reach servers behind NAT |
| Widely used anyway | Home, enterprise, and cellular networks all use NAT |
Port Forwarding (Accessing a Server Behind NAT)
- Problem: Server
10.0.0.3has no public IP — how does the internet reach it? - Solution: Port Forwarding — manually add a static entry in the NAT table
- e.g., all traffic to
138.76.29.7:80→ forward to10.0.0.3:80
- e.g., all traffic to
- Tool for dynamic tunneling: ngrok — creates a public URL pointing to a local server
- If the server's private IP changes: use DDNS (Dynamic DNS) to keep a consistent domain name
12. ICMP — Internet Control Message Protocol
What is ICMP?
- Used by hosts and routers to communicate network-level information
- Sits above IP in the stack — carried inside IP datagrams (Protocol = 1)
- Handles two things:
- Error reporting — unreachable host/network/port/protocol
- Diagnostics —
ping(echo request/reply),traceroute(TTL expired)
ICMP Message Format
Type (8-bit) | Code (8-bit) | Checksum (16-bit)
First 8 bytes of offending IP datagram header
Common ICMP Messages (Exam-Level — Know Type + Code)
| Type | Code | Message | Triggered by |
|---|---|---|---|
| 0 | 0 | Echo Reply | Response to ping |
| 3 | 0 | Destination network unreachable | Router can't find network |
| 3 | 1 | Destination host unreachable | Router can't find host |
| 3 | 2 | Destination protocol unreachable | Protocol not supported |
| 3 | 3 | Destination port unreachable | Port closed — used by traceroute to stop |
| 3 | 6 | Destination network unknown | — |
| 3 | 7 | Destination host unknown | — |
| 4 | 0 | Source quench (deprecated) | Old congestion signal |
| 8 | 0 | Echo Request | ping sends this |
| 9 | 0 | Router advertisement | — |
| 10 | 0 | Router discovery | — |
| 11 | 0 | TTL Expired | Used by traceroute at each hop |
| 12 | 0 | Bad IP header | — |
13. Traceroute & ICMP
How traceroute Works (Step by Step)
- Source sends 3 UDP probes to destination with TTL = 1
- First router decrements TTL → 0 → drops datagram → sends back ICMP Type 11 Code 0 (TTL Expired)
- Source records RTT and the router's IP from the ICMP reply
- Repeat with TTL = 2 → second router replies, and so on
- Eventually the UDP probe reaches the destination host
- Destination has no process listening on that UDP port → sends ICMP Type 3 Code 3 (Port Unreachable)
- Source sees Type 3 Code 3 → stops
Source ──TTL=1──► Router1 → ICMP TTL Expired → Source (records hop 1)
Source ──TTL=2──► Router1 → Router2 → ICMP TTL Expired → Source (hop 2)
Source ──TTL=n──► … → Destination → ICMP Port Unreachable → Source (STOP)
Analogy: Like shouting "Marco Polo!" with a reset counter at each wall. Each router shouts "Polo!" when the counter hits zero, telling you exactly how far away it is.
ping vs traceroute Summary
| Tool | ICMP Used | Purpose |
|---|---|---|
ping | Type 8 (request) / Type 0 (reply) | Test if host is reachable, measure RTT |
traceroute | Type 11 (TTL expired) + Type 3 Code 3 (stop) | Discover each hop along the path |