Linux Lab 3 - Network Interface Card (NIC) and ARP - Cheat Sheet
Network Fundamentals
What is a NIC?
- Network Interface Card (NIC): Hardware component that allows a computer to connect to a network
- Used for both wired (Ethernet) and wireless connections
- Each NIC has a unique identifier (MAC address)
Interface Naming Conventions
| System | Interface Names | Example |
|---|---|---|
| Your VM | enp0s1, enp0s2, enp0s3 | enp0s1 (primary) |
| Lab Computers | eth0, eth1, eth2 OR eno1, enp4s0 | eth0, eth1 |
| Mac | en0, en1, en2 | en0 (WiFi) |
| Loopback | lo (Linux), lo0 (Mac) | 127.0.0.1 |
Analogy: NICs are like "ports" on your computer - just as USB ports connect USB devices, NICs connect to networks.
Three Types of Computer Addresses
1. MAC Address (Media Access Control)
- Hardware address at the data link layer
- Permanently assigned to the NIC
- Format: 12 hexadecimal characters (6 bytes)
- Example:
02:0a:95:9d:68:16orbe:52:f6:c8:ab:1c - Fixed (doesn't change unless you change the NIC)
Structure: XX:XX:XX:XX:XX:XX
- First 3 bytes: Manufacturer ID (OUI)
- Last 3 bytes: Device serial number
Analogy: MAC address is like your laptop's serial number - permanently assigned to the hardware, never changes.
2. IP Address (Internet Protocol)
- Logical address at the network layer
- Can change (dynamically assigned)
- IPv4 format: Four numbers separated by dots (0-255 each)
- Example:
192.168.5.11or192.168.64.7
Types of IP Addresses:
Public IP:
- Assigned by ISP (Internet Service Provider)
- Used by routers connected directly to internet
- Unique across the entire internet
Private IP (RFC 1918):
| Range | Format | Common Use |
|---|---|---|
| Class A | 10.0.0.0 - 10.255.255.255 | Large networks |
| Class B | 172.16.0.0 - 172.31.255.255 | Medium networks, Docker |
| Class C | 192.168.0.0 - 192.168.255.255 | Home networks, VMs |
Your VM: 192.168.64.7 (Private IP)
Analogy: IP address is like your mailing address - changes when you move to a different network.
Router IP Addresses
Routers have TWO IP addresses:
-
WAN Interface (Wide Area Network)
- Faces the internet
- Has public IP address
-
LAN Interface (Local Area Network)
- Faces home network
- Has private IP address
- Usually
192.168.1.1or192.168.64.1(gateway)
3. Hostname
- Computer name (human-readable)
- Created and understood by people
- Example:
MyComp,npwitk-linux,student-pc
Analogy: Hostname is like a person's name - easier for humans than remembering numbers.
Roles of MAC and IP Addresses
How Packets Travel
Key Principle:
- IP address = Global identifier (stays the same throughout journey)
- MAC address = Local identifier (changes at every hop)
Packet Journey Example:
Source (195.15.16.11)
↓ [IP: same, MAC: changes]
Router 1
↓ [IP: same, MAC: changes]
Router 2
↓ [IP: same, MAC: changes]
Destination (2.17.169.198)
Why Both Are Needed:
- IP addresses: Identify destination globally across the internet
- MAC addresses: Relay packets locally from one router to the next (hop-by-hop)
Important Behaviors:
- IP of destination is FIXED throughout the journey
- MAC address CHANGES every hop
- If destination is in same network, packet delivered directly using MAC address
Analogy: Sending a package across the country:
- IP = Final destination address (never changes)
- MAC = Delivery truck for each leg of journey (changes at each distribution center)
Packet Header Changes:
Hop 1: Source → Router 1
- Source IP:
195.15.16.11(unchanged) - Dest IP:
2.17.169.198(unchanged) - Source MAC:
35:a0:b1:00:57:c2 - Dest MAC:
01:53:aa:f9:d2:8c
Hop 2: Router 1 → Router 2
- Source IP:
195.15.16.11(unchanged) - Dest IP:
2.17.169.198(unchanged) - Source MAC:
28:18:78:5a:f5:96(changed) - Dest MAC:
35:a0:b1:72:01:19(changed)
Hop 3: Router 2 → Destination
- Source IP:
195.15.16.11(unchanged) - Dest IP:
2.17.169.198(unchanged) - Source MAC:
00:1f:19:ba:20:39(changed) - Dest MAC:
28:18:78:5a:f4:c7(changed)
ifconfig Command - View/Configure Network Interfaces
Basic Syntax
ifconfig [interface] [options]Common Commands
| Command | Description | Use Case |
|---|---|---|
ifconfig | View active interfaces | Check current network config |
ifconfig -a | View ALL interfaces (including inactive) | See all NICs on system |
ifconfig eth0 | View specific interface | Check one interface |
sudo ifconfig eth0 up | Enable interface | Turn on network card |
sudo ifconfig eth0 down | Disable interface | Turn off network card |
sudo ifconfig eth0 [IP] | Assign static IP | Set custom IP address |
⚠️ Note: Enabling/disabling interfaces requires sudo (superuser permissions)
View All Active Network Interfaces
ifconfigExample Output:
enp0s1: flags=4163<UP,BROADCAST,RUNNING,MULTICAST> mtu 1500
inet 192.168.64.7 netmask 255.255.255.0 broadcast 192.168.64.255
inet6 fd88:82c3:e85b:fd91:bc52:f6ff:fec8:ab1c prefixlen 64
ether be:52:f6:c8:ab:1c txqueuelen 1000 (Ethernet)
RX packets 143 bytes 65090 (65.0 KB)
TX packets 133 bytes 20586 (20.5 KB)
lo: flags=73<UP,LOOPBACK,RUNNING> mtu 65536
inet 127.0.0.1 netmask 255.0.0.0
loop txqueuelen 1000 (Local Loopback)Understanding the Output:
| Field | Value | Meaning |
|---|---|---|
| Interface name | enp0s1 | Network interface identifier |
| flags | UP,BROADCAST,RUNNING | • UP: Interface is enabled • BROADCAST: Can handle broadcast packets • RUNNING: Operational and ready • MULTICAST: Can handle multicast |
| mtu | 1500 | Maximum Transmission Unit (bytes) |
| inet | 192.168.64.7 | IPv4 address |
| netmask | 255.255.255.0 | Subnet mask |
| broadcast | 192.168.64.255 | Broadcast address |
| ether | be:52:f6:c8:ab:1c | MAC address (hardware address) |
| inet6 | fd88:82c3:... | IPv6 address |
| RX packets | 143 | Packets received |
| RX bytes | 65090 | Bytes received |
| TX packets | 133 | Packets transmitted |
| TX bytes | 20586 | Bytes transmitted |
| RX/TX errors | 0 | Damaged packets |
| dropped | 0 | Dropped packets |
| collisions | 0 | Packet collisions |
View All Interfaces (Including Inactive)
ifconfig -aShows all network interfaces, even those that are not currently running.
View Specific Interface
ifconfig [interface_name]Examples:
ifconfig eth0 # Lab computers
ifconfig enp0s1 # Your VM
ifconfig en0 # MacDisable an Interface
sudo ifconfig [interface] downExamples:
sudo ifconfig eth0 down
sudo ifconfig enp0s1 down⚠️ WARNING: This disconnects you from the network!
Effect: Interface stops all network communication (like unplugging the cable)
Enable an Interface
sudo ifconfig [interface] upExamples:
sudo ifconfig eth0 up
sudo ifconfig enp0s1 upEffect: Activates the interface for network communication
Assign Static IP Address
sudo ifconfig [interface] [IP_address]With netmask:
sudo ifconfig [interface] [IP] netmask [mask]Examples:
sudo ifconfig eth1 192.168.10.50
sudo ifconfig eth1 192.168.10.50 netmask 255.255.255.0
sudo ifconfig enp0s2 192.88.100.10⚠️ WARNING: Don't change IP on your primary interface or you'll lose connection!
ping Command - Test Network Connectivity
What is ping?
- Packet Internet Groper: Network utility to test connectivity
- Uses ICMP (Internet Control Message Protocol)
- Measures round-trip time (RTT) between source and destination
How ping Works:
- Sends ICMP echo request to destination
- Destination replies with ICMP echo response
- Measures time taken for round trip
Analogy: Like shouting "Hello!" in a canyon - the echo tells you something is there, and the delay tells you how far away.
Basic Ping Syntax
ping [options] [hostname/IP]Stop ping: Press CTRL+C
Common Ping Commands
| Command | Description | Example |
|---|---|---|
ping 8.8.8.8 | Basic ping (runs forever) | Test internet connectivity |
ping -c [n] [host] | Send n packets | ping -c 10 google.com |
ping -s [size] [host] | Set packet size | ping -s 100 8.8.8.8 |
ping -i [interval] [host] | Set interval (seconds) | ping -i 2 8.8.8.8 |
ping localhost | Ping yourself | ping 127.0.0.1 |
Understanding Ping Output
$ ping 8.8.8.8
PING 8.8.8.8 (8.8.8.8) 56(84) bytes of data.
64 bytes from 8.8.8.8: icmp_seq=1 ttl=117 time=12.4 ms
64 bytes from 8.8.8.8: icmp_seq=2 ttl=117 time=11.8 ms
64 bytes from 8.8.8.8: icmp_seq=3 ttl=117 time=13.2 ms
^C
--- 8.8.8.8 ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 2004ms
rtt min/avg/max/mdev = 11.812/12.466/13.201/0.586 msField Explanations:
| Field | Value | Meaning |
|---|---|---|
56(84) | Data(Total) bytes | 56 bytes data + 28 bytes headers (8 ICMP + 20 IP) |
64 bytes from | Response size | 56 data + 8 ICMP header |
icmp_seq | Sequence number | Packet sequence number |
ttl=117 | Time To Live | Hops remaining (started at 128 or 64) |
time=12.4 ms | Round Trip Time | Time for request + response |
0% packet loss | Reliability | All packets received successfully |
TTL (Time To Live):
- Windows: Starts at 128
- Linux: Starts at 64
- Each router decreases by 1
ttl=117means packet went through ~11 routers (128-117)
RTT (Round Trip Time) Quality:
| RTT Range | Quality | Description |
|---|---|---|
| < 1 ms | Excellent | Same local network |
| 1-30 ms | Very Good | Local servers, nearby |
| 30-50 ms | Good | Most websites |
| 50-100 ms | Acceptable | International connections |
| 100-300 ms | Slow | Far away servers |
| > 300 ms | Very Slow | Satellite, poor connection |
Ping Packet Size Calculation
ICMP Packet Structure:
Total Size = IP Header (20 bytes) + ICMP Header (8 bytes) + Data
Default Ping:
84 bytes = 20 (IP) + 8 (ICMP) + 56 (data)
Custom Size Example (ping -s 100):
128 bytes = 20 (IP) + 8 (ICMP) + 100 (data)
Response Size: Data + ICMP header only
- Request sends:
128 bytes (100 data + 28 headers) - Response shows:
108 bytes (100 data + 8 ICMP)
Ping Command Options
1. Send Specific Number of Packets
ping -c [count] [host]Examples:
ping -c 4 8.8.8.8 # Send 4 packets
ping -c 10 google.com # Send 10 packetsOutput: Stops automatically after sending specified number
2. Change Packet Size
ping -s [size] [host]Examples:
ping -s 100 8.8.8.8 # 100 bytes of data
ping -s 1000 google.com # 1000 bytes of dataOutput Example:
PING 8.8.8.8 (8.8.8.8) 100(128) bytes of data.
108 bytes from 8.8.8.8: icmp_seq=1 ttl=117 time=12.3 ms100(128): 100 data + 28 headers108 bytes: 100 data + 8 ICMP header (IP header stripped in response)
3. Change Interval Between Packets
ping -i [interval] [host]Default interval: 1 second
Examples:
ping -i 2 8.8.8.8 # Send every 2 seconds
ping -i 0.5 google.com # Send every 0.5 seconds
ping -i 5 192.168.1.1 # Send every 5 seconds⚠️ Note: Intervals < 0.2 seconds require root privileges:
sudo ping -i 0.1 8.8.8.8Combining Ping Options
ping -c [count] -s [size] -i [interval] [host]Example: Send 8 packets with 60-byte data every 3 seconds
ping -c 8 -s 60 -i 3 8.8.8.8Output:
PING 8.8.8.8 (8.8.8.8) 60(88) bytes of data.
68 bytes from 8.8.8.8: icmp_seq=1 ttl=117 time=12.3 ms
68 bytes from 8.8.8.8: icmp_seq=2 ttl=117 time=11.9 ms
...
--- 8.8.8.8 ping statistics ---
8 packets transmitted, 8 received, 0% packet loss, time 21047msTime calculation: 8 packets × 3 seconds = ~24 seconds total
Common Ping Targets
ping 127.0.0.1 # Ping yourself (loopback)
ping localhost # Same as 127.0.0.1
ping 8.8.8.8 # Google DNS (test internet)
ping 1.1.1.1 # Cloudflare DNS
ping google.com # Ping website by name
ping 192.168.1.1 # Ping your router (common gateway)Address Resolution Protocol (ARP)
What is ARP?
- Address Resolution Protocol: Network protocol to find MAC address from IP address
- Used on local networks only
- Maps IP addresses (Layer 3) to MAC addresses (Layer 2)
Why ARP is Needed:
- To send packets on local network, you need the destination's MAC address
- You usually only know the IP address
- ARP translates IP → MAC
Analogy: ARP is like looking up someone's phone number:
- You know their name (IP address)
- You need their phone number (MAC address) to call them
- You check your contacts (ARP cache) first
- If not there, ask everyone "Who has this name?" (broadcast)
How ARP Works
Process:
-
Check ARP Cache: Source looks in its ARP table
- If MAC address found → Use it
- If not found → Continue to step 2
-
ARP Request (Broadcast):
- Source sends broadcast: "Who has IP 192.168.1.50?"
- All devices on local network receive this
- Each device checks if it has that IP
-
ARP Reply (Unicast):
- Only the device with matching IP responds
- Replies with: "I have 192.168.1.50, my MAC is XX:XX:XX:XX:XX:XX"
-
Cache Update:
- Source adds MAC-IP mapping to ARP cache
- Future packets use cached MAC address
-
Send Packets:
- Now source can send packets using destination MAC
Visual Flow:
Host A wants to reach Host B (192.168.1.50)
↓
Check ARP cache for 192.168.1.50
↓
Not found → Broadcast ARP request
↓
"Who has 192.168.1.50?"
↓
Host B replies: "I do! My MAC is aa:bb:cc:dd:ee:ff"
↓
Host A adds to cache: 192.168.1.50 → aa:bb:cc:dd:ee:ff
↓
Host A sends packets to Host B using MAC address
arp Command - View/Modify ARP Cache
Basic Syntax
arp [options] [IP_address]Common ARP Commands
| Command | Description | Use Case |
|---|---|---|
arp -a | Show complete ARP cache with hostnames | View all MAC-IP mappings |
arp -n | Show ARP cache without hostnames | Faster, no DNS lookup |
arp -a [IP] | Show specific IP in cache | Find MAC of specific device |
arp -i [interface] | Show cache for specific NIC | Filter by interface |
arp -d [IP] | Delete entry from cache | Remove specific mapping |
View Complete ARP Cache
arp -aExample Output:
? (192.168.64.1) at 52:54:00:12:35:02 [ether] on enp0s1
_gateway (192.168.64.1) at 52:54:00:12:35:02 [ether] on enp0s1
? (192.168.1.5) at dc:a6:32:xx:xx:xx [ether] on eth0Fields:
?or hostname: Device name (if resolvable)(IP): IP addressat MAC: MAC address[ether]: Ethernet typeon interface: Network interface
View ARP Cache (No Hostnames)
arp -nExample Output:
Address HWtype HWaddress Flags Mask Iface
192.168.64.1 ether 52:54:00:12:35:02 C enp0s1
192.168.1.5 ether dc:a6:32:aa:bb:cc C eth0Flags:
C= Complete (entry is complete and valid)M= Permanent (manually added, won't expire)P= Published (proxy ARP)
Columns:
- Address: IP address
- HWtype: Hardware type (ethernet)
- HWaddress: MAC address
- Flags: Entry status
- Iface: Network interface name
Add Entry to ARP Cache (By Pinging)
Method: Ping a device to automatically add it to ARP cache
ping -c 2 [IP_address]Example:
# Before ping
$ arp -n
(empty or minimal entries)
# Ping the device
$ ping -c 2 192.168.1.50
# After ping
$ arp -n
Address HWtype HWaddress Flags Iface
192.168.1.50 ether aa:bb:cc:dd:ee:ff C eth0Why this works: When you ping, your computer automatically performs ARP to find the MAC address!
View Specific IP in ARP Cache
arp -a [IP_address]Example:
$ arp -a 192.168.64.1
? (192.168.64.1) at 52:54:00:12:35:02 [ether] on enp0s1Use case: Useful when ARP cache has hundreds of entries
View ARP Entries for Specific Interface
arp -i [interface]Examples:
arp -i eth0 # Show only eth0 ARP entries
arp -i enp0s1 # Show only enp0s1 entriesUse case: When you have multiple NICs on different networks
Delete Entry from ARP Cache
sudo arp -d [IP_address]Example:
sudo arp -d 192.168.1.50Effect: Removes MAC-IP mapping from cache. Next packet to that IP will trigger new ARP request.
Quiz Key Topics & Answers
Multiple Choice Questions
Q1: What protocol does ping command use?
- ✅ Internet Control Message Protocol (ICMP)
- ❌ Transmission Control Protocol (TCP)
- ❌ Address Resolution Protocol (ARP)
- ❌ User Datagram Protocol (UDP)
Q2: IP and MAC address used in which layer in TCP/IP model?
- ✅ Network and Data link layer
- ❌ Presentation and Application layer
- ❌ Network and Application layer
- ❌ Presentation and Data link layer
Q3: Correct format of assigning IP address "192.168.1.55" to network interface "eth1"?
- ✅ ifconfig eth1 192.168.1.55
- ❌ ifconfig -o eth1 192.168.1.55
- ❌ ifconfig -o eth0 192.168.1.55
- ❌ ifconfig eth0 192.168.1.55
Q4: Command to view MAC address of devices without hostnames?
- ✅ arp -n
- ❌ arp -i eth0
- ❌ arp -a 192.168.1.55
- ❌ arp -a
Q5: What is the size of the Internet control message protocol header?
- ✅ 8 bytes
- ❌ 20 bytes
- ❌ 16 bytes
- ❌ 10 bytes
Q6: Command to view and configure a network interface?
- ✅ ifconfig
- ❌ ping
- ❌ arp
- ❌ pwd
Short Answer Questions
Q1: Give a command to assign static IP address to interface "eth1" to 192.88.100.10
Answer:
sudo ifconfig eth1 192.88.100.10Alternative with netmask:
sudo ifconfig eth1 192.88.100.10 netmask 255.255.255.0Q2: Write command to ping 10 packets to 10.1.1.1 with interval of 5 seconds
Answer:
ping -c 10 -i 5 10.1.1.1Breakdown:
-c 10: Send 10 packets-i 5: 5-second interval between packets10.1.1.1: Destination IP
Long Answer Questions
Q1: Write commands to activate Ethernet card 2 and assign IP address 192.168.0.10
Answer:
sudo ifconfig eth2 up
sudo ifconfig eth2 192.168.0.10Or in one line:
sudo ifconfig eth2 up && sudo ifconfig eth2 192.168.0.10Or with netmask:
sudo ifconfig eth2 192.168.0.10 netmask 255.255.255.0
sudo ifconfig eth2 upQ2: Write ping command to get the following output:
Required Output:
PING 127.0.0.1 (127.0.0.1) 100(128) bytes of data.
108 bytes from 127.0.0.1: icmp_seq=1 ttl=64 time=0.028 ms
...
6 packets transmitted, 6 received, 0% packet loss, time 5126ms
Hint: Default data length, ICMP header size, customized data size
Analysis:
- Total:
100(128)→ 100 bytes data + 28 bytes headers - Response:
108 bytes→ 100 data + 8 ICMP - Packets: 6 packets sent
- Target: 127.0.0.1 (loopback)
Answer:
ping -s 100 -c 6 127.0.0.1Breakdown:
-s 100: 100 bytes of data-c 6: Send 6 packets127.0.0.1: Loopback address
Practical Assignments
Assignment 1: Record Your NIC Information
Task: Fill in details for each network interface
Steps:
- List all interfaces:
ifconfig -a- For each interface, record:
- NIC Name
- IP Address
- MAC Address
- Manufacturer (check at macvendors.com)
Example Table:
| NIC Name | IP Address | MAC Address | Manufacturer |
|---|---|---|---|
| enp0s1 | 192.168.64.7 | be:52:f6:c8:ab:1c | QEMU/KVM |
| eth0 | 192.168.1.100 | a4:83:e7:xx:xx:xx | Intel |
| docker0 | 172.17.0.1 | 62:8e:2a:2c:c8:94 | (virtual) |
| lo | 127.0.0.1 | N/A | N/A |
Assignment 2: Add 10 MAC-IP Addresses to ARP Cache
Task: Build ARP cache by pinging devices
Method:
# Check current ARP cache
arp -n
# Ping various devices (they'll be added to cache)
ping -c 2 192.168.1.1 # Router
ping -c 2 192.168.1.2 # Device 1
ping -c 2 192.168.1.3 # Device 2
ping -c 2 192.168.1.10 # Device 3
# ... continue up to 10 devices
# View updated ARP cache
arp -nTargets to ping:
- Your gateway/router (usually .1 or .254)
- Other computers on network
- Smart TVs, phones, printers
- IoT devices
Verification:
arp -a # View all entries with hostnames
arp -n # View all entries (numeric only)Assignment 3: Peer-to-Peer Connection
Task: Create direct connection between two computers
Requirements:
- Two computers with multiple NICs
- LAN cable connecting their second NICs (eth1)
Steps:
Computer 1:
# Step 1: Configure IP on second interface
sudo ifconfig eth1 192.168.10.1 netmask 255.255.255.0
# Step 2: Verify configuration
ifconfig eth1
# Step 3: Check ARP cache before
arp -i eth1
# Step 4: Ping Computer 2
ping -c 4 192.168.10.2
# Step 5: Verify ARP entry added
arp -i eth1
# Should show: 192.168.10.2 at [MAC] on eth1Computer 2:
# Step 1: Configure IP on second interface
sudo ifconfig eth1 192.168.10.2 netmask 255.255.255.0
# Step 2: Verify configuration
ifconfig eth1
# Step 3: Wait for Computer 1 to ping
# Step 4: Check ARP cache
arp -i eth1
# Should show: 192.168.10.1 at [MAC] on eth1Expected ping output:
PING 192.168.10.2 (192.168.10.2) 56(84) bytes of data.
64 bytes from 192.168.10.2: icmp_seq=1 ttl=64 time=0.234 ms
64 bytes from 192.168.10.2: icmp_seq=2 ttl=64 time=0.189 ms
...
--- 192.168.10.2 ping statistics ---
4 packets transmitted, 4 received, 0% packet loss
rtt min/avg/max = 0.189/0.204/0.234 msWhy these IPs?
- Both in same subnet:
192.168.10.0/24 - Can communicate directly without router
.1and.2are just conventions
Network Layer Model
TCP/IP Model (4 Layers)
| Layer | Name | Protocols | Addresses Used |
|---|---|---|---|
| 4 | Application | HTTP, FTP, DNS, SMTP | Domain names |
| 3 | Transport | TCP, UDP | Port numbers |
| 2 | Internet/Network | IP, ICMP | IP addresses |
| 1 | Network Access/Data Link | Ethernet, ARP | MAC addresses |
Key Points:
- IP (Layer 2): Uses IP addresses for routing
- Ethernet/ARP (Layer 1): Uses MAC addresses for local delivery
- ICMP (Layer 2): Used by
pingcommand
Important Formulas & Calculations
Packet Size Calculations
ICMP Packet Structure:
Total Size = IP Header + ICMP Header + Data
= 20 bytes + 8 bytes + Data size
Default ping:
84 bytes = 20 (IP) + 8 (ICMP) + 56 (data)
Custom data size (-s option):
Total = 28 (IP+ICMP) + Data size
Examples:
| Command | Data | Total | Response |
|---|---|---|---|
ping host | 56 | 84 | 64 bytes |
ping -s 100 host | 100 | 128 | 108 bytes |
ping -s 1000 host | 1000 | 1028 | 1008 bytes |
Response size = Data + ICMP header (8 bytes)
TTL Calculations
Starting TTL values:
- Windows: 128
- Linux/Mac: 64
Calculation:
Hops = Starting TTL - Current TTL
Examples:
ttl=117→128 - 117 = 11 hops(Windows source)ttl=52→64 - 52 = 12 hops(Linux source)ttl=64→64 - 64 = 0 hops(same network)
Netmask Calculations
Common Netmasks:
| CIDR | Netmask | Usable IPs | Use Case |
|---|---|---|---|
| /8 | 255.0.0.0 | 16,777,214 | Class A (10.x.x.x) |
| /16 | 255.255.0.0 | 65,534 | Class B (172.16-31.x.x) |
| /24 | 255.255.255.0 | 254 | Class C (192.168.x.x) |
| /30 | 255.255.255.252 | 2 | Point-to-point |
Example: 192.168.10.0/24
- Network:
192.168.10.0 - First usable:
192.168.10.1 - Last usable:
192.168.10.254 - Broadcast:
192.168.10.255 - Total IPs: 256 (254 usable)
Common Command Patterns
Interface Configuration Workflow
# 1. View current interfaces
ifconfig
# 2. View all interfaces (including down)
ifconfig -a
# 3. Bring up interface
sudo ifconfig eth1 up
# 4. Assign IP address
sudo ifconfig eth1 192.168.10.1 netmask 255.255.255.0
# 5. Verify configuration
ifconfig eth1
# 6. Test connectivity
ping -c 4 192.168.10.2ARP Troubleshooting Workflow
# 1. Check current ARP cache
arp -n
# 2. Ping device to trigger ARP
ping -c 2 192.168.1.50
# 3. Verify ARP entry added
arp -n
# or
arp -a 192.168.1.50
# 4. Check specific interface
arp -i eth0
# 5. Delete stale entry if needed
sudo arp -d 192.168.1.50Network Connectivity Testing
# Test loopback (yourself)
ping -c 4 127.0.0.1
# Test gateway (local router)
ping -c 4 192.168.1.1
# Test internet (Google DNS)
ping -c 4 8.8.8.8
# Test with custom packet size
ping -c 10 -s 500 google.com
# Test with longer interval
ping -c 5 -i 2 192.168.1.1
# Combined test
ping -c 8 -s 100 -i 3 8.8.8.8Troubleshooting Guide
Problem: Can't ping anything
Solution:
# Check if interface is up
ifconfig
# If interface not shown, bring it up
sudo ifconfig eth0 up
# Check if you have IP address
ifconfig eth0 | grep inet
# Check default gateway
route -n
# or
ip route show
# Test loopback first
ping 127.0.0.1
# Then test gateway
ping [gateway_IP]
# Finally test internet
ping 8.8.8.8Problem: No ARP entries showing
Cause: ARP only shows devices on local network
Solution:
# External IPs (8.8.8.8) won't appear in ARP
# Only local network devices will appear
# Ping your gateway (will appear in ARP)
ping -c 2 192.168.1.1
# Ping other local devices
ping -c 2 192.168.1.5
# Check ARP cache
arp -nProblem: "Operation not permitted"
Cause: Forgot sudo for administrative tasks
Solution:
# Wrong:
ifconfig eth0 192.168.1.100
# Correct:
sudo ifconfig eth0 192.168.1.100Problem: Lost network connection
Solution:
# Bring interface back up
sudo ifconfig eth0 up
# Restart networking service
sudo systemctl restart networking
# Or restart the computer
sudo rebootProblem: Can't find interface name
Solution:
# List all interfaces
ifconfig -a
# Or use ip command
ip link show
# Or check dmesg for hardware
dmesg | grep -i ethQuick Reference Card
Essential Commands Summary
# Interface Management
ifconfig # View active interfaces
ifconfig -a # View all interfaces
ifconfig eth0 # View specific interface
sudo ifconfig eth0 up # Enable interface
sudo ifconfig eth0 down # Disable interface
sudo ifconfig eth0 192.168.1.100 # Assign IP
# Connectivity Testing
ping 8.8.8.8 # Basic ping
ping -c 4 host # Send 4 packets
ping -s 100 host # 100-byte data
ping -i 2 host # 2-second interval
ping -c 10 -s 60 -i 3 host # Combined options
# ARP Management
arp -a # View cache with hostnames
arp -n # View cache (numeric)
arp -a 192.168.1.50 # View specific IP
arp -i eth0 # View cache for interface
sudo arp -d IP # Delete entryKey Differences Between Systems
| Aspect | Lab Computers | Your VM | Mac |
|---|---|---|---|
| Interface | eth0, eth1, eno1 | enp0s1, enp0s2 | en0, en1 |
| Loopback | lo | lo | lo0 |
| Commands | Same | Same | Same |
| IP Range | Lab network | 192.168.64.x | Home network |
Memory Aids & Tips
Remember Interface Names
- eth0 = ethernet 0 (traditional Linux)
- enp0s1 = ethernet nIC PCI bus 0 slot 1 (modern Linux)
- en0 = ethernet nIC 0 (Mac)
Remember Packet Sizes
- MAC: 6 bytes (like 6 pairs of hex digits)
- ICMP header: 8 bytes (always!)
- IP header: 20 bytes (standard)
- Default ping: 56 + 8 + 20 = 84 bytes
Remember ARP Process
Acronym: CBC-RS
- Check cache
- Broadcast request
- Compare IP
- Reply unicast
- Store in cache
Remember ping Options
- -c: Count (number of packets)
- -s: Size (data size in bytes)
- -i: Interval (time between packets)
Common Mistakes to Avoid
❌ WRONG: ifconfig eth0 192.168.1.100 (without sudo) ✓ CORRECT: sudo ifconfig eth0 192.168.1.100
❌ WRONG: Using eth0 on modern systems ✓ CORRECT: Check with ifconfig first, use actual interface name
❌ WRONG: Expecting external IPs in ARP cache ✓ CORRECT: ARP only shows local network devices
❌ WRONG: ping host (runs forever) ✓ CORRECT: ping -c 4 host (stops after 4 packets)
❌ WRONG: Thinking MAC addresses change ✓ CORRECT: MAC is permanent, IP addresses change
❌ WRONG: Thinking IP addresses stay same during routing ✓ CORRECT: IP stays same, MAC changes at each hop
Final Exam Tips
- Know your interface names: Check with
ifconfigfirst! - Remember packet size formula: Total = 20 (IP) + 8 (ICMP) + Data
- ARP only works locally: External IPs won't show in cache
- Always use sudo for interface configuration
- Practice combining ping options:
-c,-s,-itogether - Understand the difference: IP (global) vs MAC (local)
- Know TTL calculation: Starting value - Current value = Hops
- Remember layer model: IP at Layer 3, MAC at Layer 2
- Ping to add ARP entries: It happens automatically!
- Stop ping with CTRL+C: Don't let it run forever
Study Strategy
Week Before Exam:
- Practice all commands on actual VM/computer
- Create your own network with peer-to-peer setup
- Build ARP cache by pinging various devices
- Time yourself doing assignments
Day Before Exam:
- Review quiz questions and answers
- Practice packet size calculations
- Draw ARP process from memory
- Review common mistakes section
Exam Day:
- Bring this cheat sheet!
- Check interface names first (
ifconfig) - Read questions carefully (especially units: bytes vs bits)
- Show your work for calculations
Good luck! 🚀