Lab 3

Updated 4 Oct 2026

Linux Lab 3 - Network Interface Card (NIC) and ARP - Cheat Sheet

Network Fundamentals

What is a NIC?

  • Network Interface Card (NIC): Hardware component that allows a computer to connect to a network
  • Used for both wired (Ethernet) and wireless connections
  • Each NIC has a unique identifier (MAC address)

Interface Naming Conventions

SystemInterface NamesExample
Your VMenp0s1, enp0s2, enp0s3enp0s1 (primary)
Lab Computerseth0, eth1, eth2 OR eno1, enp4s0eth0, eth1
Macen0, en1, en2en0 (WiFi)
Loopbacklo (Linux), lo0 (Mac)127.0.0.1

Analogy: NICs are like "ports" on your computer - just as USB ports connect USB devices, NICs connect to networks.


Three Types of Computer Addresses

1. MAC Address (Media Access Control)

  • Hardware address at the data link layer
  • Permanently assigned to the NIC
  • Format: 12 hexadecimal characters (6 bytes)
  • Example: 02:0a:95:9d:68:16 or be:52:f6:c8:ab:1c
  • Fixed (doesn't change unless you change the NIC)

Structure: XX:XX:XX:XX:XX:XX

  • First 3 bytes: Manufacturer ID (OUI)
  • Last 3 bytes: Device serial number

Analogy: MAC address is like your laptop's serial number - permanently assigned to the hardware, never changes.

2. IP Address (Internet Protocol)

  • Logical address at the network layer
  • Can change (dynamically assigned)
  • IPv4 format: Four numbers separated by dots (0-255 each)
  • Example: 192.168.5.11 or 192.168.64.7

Types of IP Addresses:

Public IP:

  • Assigned by ISP (Internet Service Provider)
  • Used by routers connected directly to internet
  • Unique across the entire internet

Private IP (RFC 1918):

RangeFormatCommon Use
Class A10.0.0.0 - 10.255.255.255Large networks
Class B172.16.0.0 - 172.31.255.255Medium networks, Docker
Class C192.168.0.0 - 192.168.255.255Home networks, VMs

Your VM: 192.168.64.7 (Private IP)

Analogy: IP address is like your mailing address - changes when you move to a different network.

Router IP Addresses

Routers have TWO IP addresses:

  1. WAN Interface (Wide Area Network)

    • Faces the internet
    • Has public IP address
  2. LAN Interface (Local Area Network)

    • Faces home network
    • Has private IP address
    • Usually 192.168.1.1 or 192.168.64.1 (gateway)

3. Hostname

  • Computer name (human-readable)
  • Created and understood by people
  • Example: MyComp, npwitk-linux, student-pc

Analogy: Hostname is like a person's name - easier for humans than remembering numbers.


Roles of MAC and IP Addresses

How Packets Travel

Key Principle:

  • IP address = Global identifier (stays the same throughout journey)
  • MAC address = Local identifier (changes at every hop)

Packet Journey Example:

Source (195.15.16.11)
    ↓ [IP: same, MAC: changes]
Router 1
    ↓ [IP: same, MAC: changes]
Router 2
    ↓ [IP: same, MAC: changes]
Destination (2.17.169.198)

Why Both Are Needed:

  • IP addresses: Identify destination globally across the internet
  • MAC addresses: Relay packets locally from one router to the next (hop-by-hop)

Important Behaviors:

  • IP of destination is FIXED throughout the journey
  • MAC address CHANGES every hop
  • If destination is in same network, packet delivered directly using MAC address

Analogy: Sending a package across the country:

  • IP = Final destination address (never changes)
  • MAC = Delivery truck for each leg of journey (changes at each distribution center)

Packet Header Changes:

Hop 1: Source → Router 1

  • Source IP: 195.15.16.11 (unchanged)
  • Dest IP: 2.17.169.198 (unchanged)
  • Source MAC: 35:a0:b1:00:57:c2
  • Dest MAC: 01:53:aa:f9:d2:8c

Hop 2: Router 1 → Router 2

  • Source IP: 195.15.16.11 (unchanged)
  • Dest IP: 2.17.169.198 (unchanged)
  • Source MAC: 28:18:78:5a:f5:96 (changed)
  • Dest MAC: 35:a0:b1:72:01:19 (changed)

Hop 3: Router 2 → Destination

  • Source IP: 195.15.16.11 (unchanged)
  • Dest IP: 2.17.169.198 (unchanged)
  • Source MAC: 00:1f:19:ba:20:39 (changed)
  • Dest MAC: 28:18:78:5a:f4:c7 (changed)

ifconfig Command - View/Configure Network Interfaces

Basic Syntax

ifconfig [interface] [options]

Common Commands

CommandDescriptionUse Case
ifconfigView active interfacesCheck current network config
ifconfig -aView ALL interfaces (including inactive)See all NICs on system
ifconfig eth0View specific interfaceCheck one interface
sudo ifconfig eth0 upEnable interfaceTurn on network card
sudo ifconfig eth0 downDisable interfaceTurn off network card
sudo ifconfig eth0 [IP]Assign static IPSet custom IP address

⚠️ Note: Enabling/disabling interfaces requires sudo (superuser permissions)


View All Active Network Interfaces

ifconfig

Example Output:

enp0s1: flags=4163<UP,BROADCAST,RUNNING,MULTICAST>  mtu 1500
        inet 192.168.64.7  netmask 255.255.255.0  broadcast 192.168.64.255
        inet6 fd88:82c3:e85b:fd91:bc52:f6ff:fec8:ab1c  prefixlen 64
        ether be:52:f6:c8:ab:1c  txqueuelen 1000  (Ethernet)
        RX packets 143  bytes 65090 (65.0 KB)
        TX packets 133  bytes 20586 (20.5 KB)
 
lo: flags=73<UP,LOOPBACK,RUNNING>  mtu 65536
        inet 127.0.0.1  netmask 255.0.0.0
        loop  txqueuelen 1000  (Local Loopback)

Understanding the Output:

FieldValueMeaning
Interface nameenp0s1Network interface identifier
flagsUP,BROADCAST,RUNNING• UP: Interface is enabled
• BROADCAST: Can handle broadcast packets
• RUNNING: Operational and ready
• MULTICAST: Can handle multicast
mtu1500Maximum Transmission Unit (bytes)
inet192.168.64.7IPv4 address
netmask255.255.255.0Subnet mask
broadcast192.168.64.255Broadcast address
etherbe:52:f6:c8:ab:1cMAC address (hardware address)
inet6fd88:82c3:...IPv6 address
RX packets143Packets received
RX bytes65090Bytes received
TX packets133Packets transmitted
TX bytes20586Bytes transmitted
RX/TX errors0Damaged packets
dropped0Dropped packets
collisions0Packet collisions

View All Interfaces (Including Inactive)

ifconfig -a

Shows all network interfaces, even those that are not currently running.


View Specific Interface

ifconfig [interface_name]

Examples:

ifconfig eth0        # Lab computers
ifconfig enp0s1      # Your VM
ifconfig en0         # Mac

Disable an Interface

sudo ifconfig [interface] down

Examples:

sudo ifconfig eth0 down
sudo ifconfig enp0s1 down

⚠️ WARNING: This disconnects you from the network!

Effect: Interface stops all network communication (like unplugging the cable)


Enable an Interface

sudo ifconfig [interface] up

Examples:

sudo ifconfig eth0 up
sudo ifconfig enp0s1 up

Effect: Activates the interface for network communication


Assign Static IP Address

sudo ifconfig [interface] [IP_address]

With netmask:

sudo ifconfig [interface] [IP] netmask [mask]

Examples:

sudo ifconfig eth1 192.168.10.50
sudo ifconfig eth1 192.168.10.50 netmask 255.255.255.0
sudo ifconfig enp0s2 192.88.100.10

⚠️ WARNING: Don't change IP on your primary interface or you'll lose connection!


ping Command - Test Network Connectivity

What is ping?

  • Packet Internet Groper: Network utility to test connectivity
  • Uses ICMP (Internet Control Message Protocol)
  • Measures round-trip time (RTT) between source and destination

How ping Works:

  1. Sends ICMP echo request to destination
  2. Destination replies with ICMP echo response
  3. Measures time taken for round trip

Analogy: Like shouting "Hello!" in a canyon - the echo tells you something is there, and the delay tells you how far away.


Basic Ping Syntax

ping [options] [hostname/IP]

Stop ping: Press CTRL+C


Common Ping Commands

CommandDescriptionExample
ping 8.8.8.8Basic ping (runs forever)Test internet connectivity
ping -c [n] [host]Send n packetsping -c 10 google.com
ping -s [size] [host]Set packet sizeping -s 100 8.8.8.8
ping -i [interval] [host]Set interval (seconds)ping -i 2 8.8.8.8
ping localhostPing yourselfping 127.0.0.1

Understanding Ping Output

$ ping 8.8.8.8
PING 8.8.8.8 (8.8.8.8) 56(84) bytes of data.
64 bytes from 8.8.8.8: icmp_seq=1 ttl=117 time=12.4 ms
64 bytes from 8.8.8.8: icmp_seq=2 ttl=117 time=11.8 ms
64 bytes from 8.8.8.8: icmp_seq=3 ttl=117 time=13.2 ms
^C
--- 8.8.8.8 ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 2004ms
rtt min/avg/max/mdev = 11.812/12.466/13.201/0.586 ms

Field Explanations:

FieldValueMeaning
56(84)Data(Total) bytes56 bytes data + 28 bytes headers (8 ICMP + 20 IP)
64 bytes fromResponse size56 data + 8 ICMP header
icmp_seqSequence numberPacket sequence number
ttl=117Time To LiveHops remaining (started at 128 or 64)
time=12.4 msRound Trip TimeTime for request + response
0% packet lossReliabilityAll packets received successfully

TTL (Time To Live):

  • Windows: Starts at 128
  • Linux: Starts at 64
  • Each router decreases by 1
  • ttl=117 means packet went through ~11 routers (128-117)

RTT (Round Trip Time) Quality:

RTT RangeQualityDescription
< 1 msExcellentSame local network
1-30 msVery GoodLocal servers, nearby
30-50 msGoodMost websites
50-100 msAcceptableInternational connections
100-300 msSlowFar away servers
> 300 msVery SlowSatellite, poor connection

Ping Packet Size Calculation

ICMP Packet Structure:

Total Size = IP Header (20 bytes) + ICMP Header (8 bytes) + Data

Default Ping:

84 bytes = 20 (IP) + 8 (ICMP) + 56 (data)

Custom Size Example (ping -s 100):

128 bytes = 20 (IP) + 8 (ICMP) + 100 (data)

Response Size: Data + ICMP header only

  • Request sends: 128 bytes (100 data + 28 headers)
  • Response shows: 108 bytes (100 data + 8 ICMP)

Ping Command Options

1. Send Specific Number of Packets

ping -c [count] [host]

Examples:

ping -c 4 8.8.8.8         # Send 4 packets
ping -c 10 google.com     # Send 10 packets

Output: Stops automatically after sending specified number


2. Change Packet Size

ping -s [size] [host]

Examples:

ping -s 100 8.8.8.8       # 100 bytes of data
ping -s 1000 google.com   # 1000 bytes of data

Output Example:

PING 8.8.8.8 (8.8.8.8) 100(128) bytes of data.
108 bytes from 8.8.8.8: icmp_seq=1 ttl=117 time=12.3 ms
  • 100(128): 100 data + 28 headers
  • 108 bytes: 100 data + 8 ICMP header (IP header stripped in response)

3. Change Interval Between Packets

ping -i [interval] [host]

Default interval: 1 second

Examples:

ping -i 2 8.8.8.8         # Send every 2 seconds
ping -i 0.5 google.com    # Send every 0.5 seconds
ping -i 5 192.168.1.1     # Send every 5 seconds

⚠️ Note: Intervals < 0.2 seconds require root privileges:

sudo ping -i 0.1 8.8.8.8

Combining Ping Options

ping -c [count] -s [size] -i [interval] [host]

Example: Send 8 packets with 60-byte data every 3 seconds

ping -c 8 -s 60 -i 3 8.8.8.8

Output:

PING 8.8.8.8 (8.8.8.8) 60(88) bytes of data.
68 bytes from 8.8.8.8: icmp_seq=1 ttl=117 time=12.3 ms
68 bytes from 8.8.8.8: icmp_seq=2 ttl=117 time=11.9 ms
...
--- 8.8.8.8 ping statistics ---
8 packets transmitted, 8 received, 0% packet loss, time 21047ms

Time calculation: 8 packets × 3 seconds = ~24 seconds total


Common Ping Targets

ping 127.0.0.1            # Ping yourself (loopback)
ping localhost            # Same as 127.0.0.1
ping 8.8.8.8              # Google DNS (test internet)
ping 1.1.1.1              # Cloudflare DNS
ping google.com           # Ping website by name
ping 192.168.1.1          # Ping your router (common gateway)

Address Resolution Protocol (ARP)

What is ARP?

  • Address Resolution Protocol: Network protocol to find MAC address from IP address
  • Used on local networks only
  • Maps IP addresses (Layer 3) to MAC addresses (Layer 2)

Why ARP is Needed:

  • To send packets on local network, you need the destination's MAC address
  • You usually only know the IP address
  • ARP translates IP → MAC

Analogy: ARP is like looking up someone's phone number:

  • You know their name (IP address)
  • You need their phone number (MAC address) to call them
  • You check your contacts (ARP cache) first
  • If not there, ask everyone "Who has this name?" (broadcast)

How ARP Works

Process:

  1. Check ARP Cache: Source looks in its ARP table

    • If MAC address found → Use it
    • If not found → Continue to step 2
  2. ARP Request (Broadcast):

    • Source sends broadcast: "Who has IP 192.168.1.50?"
    • All devices on local network receive this
    • Each device checks if it has that IP
  3. ARP Reply (Unicast):

    • Only the device with matching IP responds
    • Replies with: "I have 192.168.1.50, my MAC is XX:XX:XX:XX:XX:XX"
  4. Cache Update:

    • Source adds MAC-IP mapping to ARP cache
    • Future packets use cached MAC address
  5. Send Packets:

    • Now source can send packets using destination MAC

Visual Flow:

Host A wants to reach Host B (192.168.1.50)
    ↓
Check ARP cache for 192.168.1.50
    ↓
Not found → Broadcast ARP request
    ↓
"Who has 192.168.1.50?"
    ↓
Host B replies: "I do! My MAC is aa:bb:cc:dd:ee:ff"
    ↓
Host A adds to cache: 192.168.1.50 → aa:bb:cc:dd:ee:ff
    ↓
Host A sends packets to Host B using MAC address

arp Command - View/Modify ARP Cache

Basic Syntax

arp [options] [IP_address]

Common ARP Commands

CommandDescriptionUse Case
arp -aShow complete ARP cache with hostnamesView all MAC-IP mappings
arp -nShow ARP cache without hostnamesFaster, no DNS lookup
arp -a [IP]Show specific IP in cacheFind MAC of specific device
arp -i [interface]Show cache for specific NICFilter by interface
arp -d [IP]Delete entry from cacheRemove specific mapping

View Complete ARP Cache

arp -a

Example Output:

? (192.168.64.1) at 52:54:00:12:35:02 [ether] on enp0s1
_gateway (192.168.64.1) at 52:54:00:12:35:02 [ether] on enp0s1
? (192.168.1.5) at dc:a6:32:xx:xx:xx [ether] on eth0

Fields:

  • ? or hostname: Device name (if resolvable)
  • (IP): IP address
  • at MAC: MAC address
  • [ether]: Ethernet type
  • on interface: Network interface

View ARP Cache (No Hostnames)

arp -n

Example Output:

Address           HWtype  HWaddress           Flags Mask  Iface
192.168.64.1     ether   52:54:00:12:35:02   C           enp0s1
192.168.1.5      ether   dc:a6:32:aa:bb:cc   C           eth0

Flags:

  • C = Complete (entry is complete and valid)
  • M = Permanent (manually added, won't expire)
  • P = Published (proxy ARP)

Columns:

  • Address: IP address
  • HWtype: Hardware type (ethernet)
  • HWaddress: MAC address
  • Flags: Entry status
  • Iface: Network interface name

Add Entry to ARP Cache (By Pinging)

Method: Ping a device to automatically add it to ARP cache

ping -c 2 [IP_address]

Example:

# Before ping
$ arp -n
(empty or minimal entries)
 
# Ping the device
$ ping -c 2 192.168.1.50
 
# After ping
$ arp -n
Address           HWtype  HWaddress           Flags  Iface
192.168.1.50     ether   aa:bb:cc:dd:ee:ff   C      eth0

Why this works: When you ping, your computer automatically performs ARP to find the MAC address!


View Specific IP in ARP Cache

arp -a [IP_address]

Example:

$ arp -a 192.168.64.1
? (192.168.64.1) at 52:54:00:12:35:02 [ether] on enp0s1

Use case: Useful when ARP cache has hundreds of entries


View ARP Entries for Specific Interface

arp -i [interface]

Examples:

arp -i eth0          # Show only eth0 ARP entries
arp -i enp0s1        # Show only enp0s1 entries

Use case: When you have multiple NICs on different networks


Delete Entry from ARP Cache

sudo arp -d [IP_address]

Example:

sudo arp -d 192.168.1.50

Effect: Removes MAC-IP mapping from cache. Next packet to that IP will trigger new ARP request.


Quiz Key Topics & Answers

Multiple Choice Questions

Q1: What protocol does ping command use?

  • ✅ Internet Control Message Protocol (ICMP)
  • ❌ Transmission Control Protocol (TCP)
  • ❌ Address Resolution Protocol (ARP)
  • ❌ User Datagram Protocol (UDP)

Q2: IP and MAC address used in which layer in TCP/IP model?

  • ✅ Network and Data link layer
  • ❌ Presentation and Application layer
  • ❌ Network and Application layer
  • ❌ Presentation and Data link layer

Q3: Correct format of assigning IP address "192.168.1.55" to network interface "eth1"?

  • ✅ ifconfig eth1 192.168.1.55
  • ❌ ifconfig -o eth1 192.168.1.55
  • ❌ ifconfig -o eth0 192.168.1.55
  • ❌ ifconfig eth0 192.168.1.55

Q4: Command to view MAC address of devices without hostnames?

  • ✅ arp -n
  • ❌ arp -i eth0
  • ❌ arp -a 192.168.1.55
  • ❌ arp -a

Q5: What is the size of the Internet control message protocol header?

  • ✅ 8 bytes
  • ❌ 20 bytes
  • ❌ 16 bytes
  • ❌ 10 bytes

Q6: Command to view and configure a network interface?

  • ✅ ifconfig
  • ❌ ping
  • ❌ arp
  • ❌ pwd

Short Answer Questions

Q1: Give a command to assign static IP address to interface "eth1" to 192.88.100.10

Answer:

sudo ifconfig eth1 192.88.100.10

Alternative with netmask:

sudo ifconfig eth1 192.88.100.10 netmask 255.255.255.0

Q2: Write command to ping 10 packets to 10.1.1.1 with interval of 5 seconds

Answer:

ping -c 10 -i 5 10.1.1.1

Breakdown:

  • -c 10: Send 10 packets
  • -i 5: 5-second interval between packets
  • 10.1.1.1: Destination IP

Long Answer Questions

Q1: Write commands to activate Ethernet card 2 and assign IP address 192.168.0.10

Answer:

sudo ifconfig eth2 up
sudo ifconfig eth2 192.168.0.10

Or in one line:

sudo ifconfig eth2 up && sudo ifconfig eth2 192.168.0.10

Or with netmask:

sudo ifconfig eth2 192.168.0.10 netmask 255.255.255.0
sudo ifconfig eth2 up

Q2: Write ping command to get the following output:

Required Output:

PING 127.0.0.1 (127.0.0.1) 100(128) bytes of data.
108 bytes from 127.0.0.1: icmp_seq=1 ttl=64 time=0.028 ms
...
6 packets transmitted, 6 received, 0% packet loss, time 5126ms

Hint: Default data length, ICMP header size, customized data size

Analysis:

  • Total: 100(128) → 100 bytes data + 28 bytes headers
  • Response: 108 bytes → 100 data + 8 ICMP
  • Packets: 6 packets sent
  • Target: 127.0.0.1 (loopback)

Answer:

ping -s 100 -c 6 127.0.0.1

Breakdown:

  • -s 100: 100 bytes of data
  • -c 6: Send 6 packets
  • 127.0.0.1: Loopback address

Practical Assignments

Assignment 1: Record Your NIC Information

Task: Fill in details for each network interface

Steps:

  1. List all interfaces:
ifconfig -a
  1. For each interface, record:
    • NIC Name
    • IP Address
    • MAC Address
    • Manufacturer (check at macvendors.com)

Example Table:

NIC NameIP AddressMAC AddressManufacturer
enp0s1192.168.64.7be:52:f6:c8:ab:1cQEMU/KVM
eth0192.168.1.100a4:83:e7:xx:xx:xxIntel
docker0172.17.0.162:8e:2a:2c:c8:94(virtual)
lo127.0.0.1N/AN/A

Assignment 2: Add 10 MAC-IP Addresses to ARP Cache

Task: Build ARP cache by pinging devices

Method:

# Check current ARP cache
arp -n
 
# Ping various devices (they'll be added to cache)
ping -c 2 192.168.1.1      # Router
ping -c 2 192.168.1.2      # Device 1
ping -c 2 192.168.1.3      # Device 2
ping -c 2 192.168.1.10     # Device 3
# ... continue up to 10 devices
 
# View updated ARP cache
arp -n

Targets to ping:

  • Your gateway/router (usually .1 or .254)
  • Other computers on network
  • Smart TVs, phones, printers
  • IoT devices

Verification:

arp -a    # View all entries with hostnames
arp -n    # View all entries (numeric only)

Assignment 3: Peer-to-Peer Connection

Task: Create direct connection between two computers

Requirements:

  • Two computers with multiple NICs
  • LAN cable connecting their second NICs (eth1)

Steps:

Computer 1:

# Step 1: Configure IP on second interface
sudo ifconfig eth1 192.168.10.1 netmask 255.255.255.0
 
# Step 2: Verify configuration
ifconfig eth1
 
# Step 3: Check ARP cache before
arp -i eth1
 
# Step 4: Ping Computer 2
ping -c 4 192.168.10.2
 
# Step 5: Verify ARP entry added
arp -i eth1
# Should show: 192.168.10.2 at [MAC] on eth1

Computer 2:

# Step 1: Configure IP on second interface
sudo ifconfig eth1 192.168.10.2 netmask 255.255.255.0
 
# Step 2: Verify configuration
ifconfig eth1
 
# Step 3: Wait for Computer 1 to ping
 
# Step 4: Check ARP cache
arp -i eth1
# Should show: 192.168.10.1 at [MAC] on eth1

Expected ping output:

PING 192.168.10.2 (192.168.10.2) 56(84) bytes of data.
64 bytes from 192.168.10.2: icmp_seq=1 ttl=64 time=0.234 ms
64 bytes from 192.168.10.2: icmp_seq=2 ttl=64 time=0.189 ms
...
--- 192.168.10.2 ping statistics ---
4 packets transmitted, 4 received, 0% packet loss
rtt min/avg/max = 0.189/0.204/0.234 ms

Why these IPs?

  • Both in same subnet: 192.168.10.0/24
  • Can communicate directly without router
  • .1 and .2 are just conventions

Network Layer Model

TCP/IP Model (4 Layers)

LayerNameProtocolsAddresses Used
4ApplicationHTTP, FTP, DNS, SMTPDomain names
3TransportTCP, UDPPort numbers
2Internet/NetworkIP, ICMPIP addresses
1Network Access/Data LinkEthernet, ARPMAC addresses

Key Points:

  • IP (Layer 2): Uses IP addresses for routing
  • Ethernet/ARP (Layer 1): Uses MAC addresses for local delivery
  • ICMP (Layer 2): Used by ping command

Important Formulas & Calculations

Packet Size Calculations

ICMP Packet Structure:

Total Size = IP Header + ICMP Header + Data
           = 20 bytes + 8 bytes + Data size

Default ping:

84 bytes = 20 (IP) + 8 (ICMP) + 56 (data)

Custom data size (-s option):

Total = 28 (IP+ICMP) + Data size

Examples:

CommandDataTotalResponse
ping host568464 bytes
ping -s 100 host100128108 bytes
ping -s 1000 host100010281008 bytes

Response size = Data + ICMP header (8 bytes)


TTL Calculations

Starting TTL values:

  • Windows: 128
  • Linux/Mac: 64

Calculation:

Hops = Starting TTL - Current TTL

Examples:

  • ttl=117 → 128 - 117 = 11 hops (Windows source)
  • ttl=52 → 64 - 52 = 12 hops (Linux source)
  • ttl=64 → 64 - 64 = 0 hops (same network)

Netmask Calculations

Common Netmasks:

CIDRNetmaskUsable IPsUse Case
/8255.0.0.016,777,214Class A (10.x.x.x)
/16255.255.0.065,534Class B (172.16-31.x.x)
/24255.255.255.0254Class C (192.168.x.x)
/30255.255.255.2522Point-to-point

Example: 192.168.10.0/24

  • Network: 192.168.10.0
  • First usable: 192.168.10.1
  • Last usable: 192.168.10.254
  • Broadcast: 192.168.10.255
  • Total IPs: 256 (254 usable)

Common Command Patterns

Interface Configuration Workflow

# 1. View current interfaces
ifconfig
 
# 2. View all interfaces (including down)
ifconfig -a
 
# 3. Bring up interface
sudo ifconfig eth1 up
 
# 4. Assign IP address
sudo ifconfig eth1 192.168.10.1 netmask 255.255.255.0
 
# 5. Verify configuration
ifconfig eth1
 
# 6. Test connectivity
ping -c 4 192.168.10.2

ARP Troubleshooting Workflow

# 1. Check current ARP cache
arp -n
 
# 2. Ping device to trigger ARP
ping -c 2 192.168.1.50
 
# 3. Verify ARP entry added
arp -n
# or
arp -a 192.168.1.50
 
# 4. Check specific interface
arp -i eth0
 
# 5. Delete stale entry if needed
sudo arp -d 192.168.1.50

Network Connectivity Testing

# Test loopback (yourself)
ping -c 4 127.0.0.1
 
# Test gateway (local router)
ping -c 4 192.168.1.1
 
# Test internet (Google DNS)
ping -c 4 8.8.8.8
 
# Test with custom packet size
ping -c 10 -s 500 google.com
 
# Test with longer interval
ping -c 5 -i 2 192.168.1.1
 
# Combined test
ping -c 8 -s 100 -i 3 8.8.8.8

Troubleshooting Guide

Problem: Can't ping anything

Solution:

# Check if interface is up
ifconfig
 
# If interface not shown, bring it up
sudo ifconfig eth0 up
 
# Check if you have IP address
ifconfig eth0 | grep inet
 
# Check default gateway
route -n
# or
ip route show
 
# Test loopback first
ping 127.0.0.1
 
# Then test gateway
ping [gateway_IP]
 
# Finally test internet
ping 8.8.8.8

Problem: No ARP entries showing

Cause: ARP only shows devices on local network

Solution:

# External IPs (8.8.8.8) won't appear in ARP
# Only local network devices will appear
 
# Ping your gateway (will appear in ARP)
ping -c 2 192.168.1.1
 
# Ping other local devices
ping -c 2 192.168.1.5
 
# Check ARP cache
arp -n

Problem: "Operation not permitted"

Cause: Forgot sudo for administrative tasks

Solution:

# Wrong:
ifconfig eth0 192.168.1.100
 
# Correct:
sudo ifconfig eth0 192.168.1.100

Problem: Lost network connection

Solution:

# Bring interface back up
sudo ifconfig eth0 up
 
# Restart networking service
sudo systemctl restart networking
 
# Or restart the computer
sudo reboot

Problem: Can't find interface name

Solution:

# List all interfaces
ifconfig -a
 
# Or use ip command
ip link show
 
# Or check dmesg for hardware
dmesg | grep -i eth

Quick Reference Card

Essential Commands Summary

# Interface Management
ifconfig                              # View active interfaces
ifconfig -a                           # View all interfaces
ifconfig eth0                         # View specific interface
sudo ifconfig eth0 up                 # Enable interface
sudo ifconfig eth0 down               # Disable interface
sudo ifconfig eth0 192.168.1.100     # Assign IP
 
# Connectivity Testing
ping 8.8.8.8                          # Basic ping
ping -c 4 host                        # Send 4 packets
ping -s 100 host                      # 100-byte data
ping -i 2 host                        # 2-second interval
ping -c 10 -s 60 -i 3 host           # Combined options
 
# ARP Management
arp -a                                # View cache with hostnames
arp -n                                # View cache (numeric)
arp -a 192.168.1.50                  # View specific IP
arp -i eth0                           # View cache for interface
sudo arp -d IP                        # Delete entry

Key Differences Between Systems

AspectLab ComputersYour VMMac
Interfaceeth0, eth1, eno1enp0s1, enp0s2en0, en1
Loopbacklololo0
CommandsSameSameSame
IP RangeLab network192.168.64.xHome network

Memory Aids & Tips

Remember Interface Names

  • eth0 = ethernet 0 (traditional Linux)
  • enp0s1 = ethernet nIC PCI bus 0 slot 1 (modern Linux)
  • en0 = ethernet nIC 0 (Mac)

Remember Packet Sizes

  • MAC: 6 bytes (like 6 pairs of hex digits)
  • ICMP header: 8 bytes (always!)
  • IP header: 20 bytes (standard)
  • Default ping: 56 + 8 + 20 = 84 bytes

Remember ARP Process

Acronym: CBC-RS

  • Check cache
  • Broadcast request
  • Compare IP
  • Reply unicast
  • Store in cache

Remember ping Options

  • -c: Count (number of packets)
  • -s: Size (data size in bytes)
  • -i: Interval (time between packets)

Common Mistakes to Avoid

❌ WRONG: ifconfig eth0 192.168.1.100 (without sudo) ✓ CORRECT: sudo ifconfig eth0 192.168.1.100

❌ WRONG: Using eth0 on modern systems ✓ CORRECT: Check with ifconfig first, use actual interface name

❌ WRONG: Expecting external IPs in ARP cache ✓ CORRECT: ARP only shows local network devices

❌ WRONG: ping host (runs forever) ✓ CORRECT: ping -c 4 host (stops after 4 packets)

❌ WRONG: Thinking MAC addresses change ✓ CORRECT: MAC is permanent, IP addresses change

❌ WRONG: Thinking IP addresses stay same during routing ✓ CORRECT: IP stays same, MAC changes at each hop


Final Exam Tips

  1. Know your interface names: Check with ifconfig first!
  2. Remember packet size formula: Total = 20 (IP) + 8 (ICMP) + Data
  3. ARP only works locally: External IPs won't show in cache
  4. Always use sudo for interface configuration
  5. Practice combining ping options: -c, -s, -i together
  6. Understand the difference: IP (global) vs MAC (local)
  7. Know TTL calculation: Starting value - Current value = Hops
  8. Remember layer model: IP at Layer 3, MAC at Layer 2
  9. Ping to add ARP entries: It happens automatically!
  10. Stop ping with CTRL+C: Don't let it run forever

Study Strategy

Week Before Exam:

  • Practice all commands on actual VM/computer
  • Create your own network with peer-to-peer setup
  • Build ARP cache by pinging various devices
  • Time yourself doing assignments

Day Before Exam:

  • Review quiz questions and answers
  • Practice packet size calculations
  • Draw ARP process from memory
  • Review common mistakes section

Exam Day:

  • Bring this cheat sheet!
  • Check interface names first (ifconfig)
  • Read questions carefully (especially units: bytes vs bits)
  • Show your work for calculations

Good luck! 🚀