🌐 Lab 8 — Transport-Layer Protocols · Cheat Sheet
ITS352/DES352 · SIIT · Thammasat University
1 · Layer Address Summary
| Layer | Address | Size | Identifies |
|---|---|---|---|
| Data Link | MAC Address | 48 bits | Device within a LAN |
| Network | IP Address | 32 bits | Device across different networks |
| Transport | Port Number | 16 bits | Process/program on a host |
- Network layer → host-to-host (gets packet to the right machine)
- Transport layer → process-to-process (gets packet to the right program)
IP = building address. Port = apartment number. MAC = local street directions.
2 · Port Numbers
Range: 0 – 65,535 (16-bit = 2^16 − 1)
| Group | Range | Used for |
|---|---|---|
| Well-Known | 0 – 1,023 | Common services (HTTP, FTP, DNS…) |
| Registered | 1,024 – 49,151 | Specific apps assigned by IANA |
| Dynamic / Private | 49,152 – 65,535 | Auto-assigned by OS to clients |
Key Well-Known Ports (memorise these!)
| Port | Protocol | TCP | UDP |
|---|---|---|---|
| 20 | FTP (data) | ✅ | |
| 21 | FTP (control) | ✅ | |
| 22 | SSH | ✅ | |
| 23 | TELNET | ✅ | |
| 25 | SMTP | ✅ | |
| 53 | DNS | ✅ | ✅ |
| 67 | DHCP | ✅ | |
| 69 | TFTP | ✅ | ✅ |
| 80 | HTTP | ✅ | |
| 123 | NTP | ✅ | |
| 161 | SNMP (server) | ✅ |
Port conflict rule:
- Same IP, same protocol, same port → ❌ NOT OK (e.g. two apps on TCP 80)
- Same IP, same port, different protocol → ✅ OK (TCP 80 + UDP 80 can coexist)
- Same IP, same protocol, different port → ✅ OK (TCP 80 + TCP 8080)
Socket Address = IP Address + Port Number (e.g. 200.23.56.8:80)
3 · UDP vs TCP
| Feature | UDP | TCP |
|---|---|---|
| Connection | Connectionless | Connection-oriented |
| Reliability | Unreliable | Reliable (ACKs + retransmission) |
| Ordering | Unordered | In-order delivery |
| Speed | Faster | Slower (overhead) |
| Header size | 8 bytes | 20+ bytes |
| Flow control | ❌ | ✅ |
| Phases | None | Establish → Transfer → Terminate |
| Use cases | DNS, DHCP, streaming, gaming | HTTP, FTP, SMTP, SSH |
UDP = postcard (send & hope). TCP = phone call (dial, talk, hang up properly).
4 · TCP Three-Way Handshake
Connection Establishment
Client Server
|---[SYN] Seq=0, Len=0------->| Step 1: Client requests connection
|<--[SYN,ACK] Seq=0, Ack=1----| Step 2: Server acknowledges + its own SYN
|---[ACK] Seq=1, Ack=1-------->| Step 3: Client ACKs → connection OPEN
Connection Termination
Active closer Passive closer
|---[FIN,ACK] Seq=x--------->| Step 1: Initiate close
|<--[FIN,ACK] Seq=y, Ack=x+1-| Step 2: ACK + own FIN
|---[ACK] Ack=y+1------------>| Step 3: Final ACK → connection CLOSED
5 · Sequence Number Rules ⚠️ (exam favourite!)
| Segment | Consumes Seq# | Amount |
|---|---|---|
| SYN | ✅ | +1 |
| SYN + ACK | ✅ | +1 |
| FIN | ✅ | +1 |
| FIN + ACK | ✅ | +1 |
| ACK only (no data) | ❌ | 0 |
| Data segment | ✅ | +Len (bytes) |
Formulas:
Next Seq after SYN or FIN = Current Seq + 1
Next Seq after data = Current Seq + Len
ACK sent back = Seq received + Len (or +1 for SYN/FIN)
Full TCP Exchange Example (Assignment 4 pcap)
Client 192.178.18.8:39668 Server 192.178.18.9:5000
|---[SYN] Seq=0, Len=0------------>|
|<--[SYN,ACK] Seq=0, Ack=1---------| ← Establishment
|---[ACK] Seq=1, Ack=1------------>|
| |
|---Data="How are you?" Seq=1,Len=13->|
|<--[ACK] Seq=1, Ack=14------------| ← Data Transfer
| |
|<--Data="I am fine." Seq=1,Len=11--|
|---[ACK] Seq=14, Ack=12---------->|
| |
|<--[FIN,ACK] Seq=12, Ack=14-------|
|---[FIN,ACK] Seq=14, Ack=13------>| ← Termination
|<--[ACK] Seq=13, Ack=15-----------|
Two-message TCP Example (Assignment 3: "Test1" + "Test2", each = 6 bytes incl. \n)
Client Server :5000
|---[SYN] Seq=0 ----------------->|
|<--[SYN,ACK] Seq=0, Ack=1--------| Establishment
|---[ACK] Seq=1, Ack=1 ----------->|
|---Data=Test1 Seq=1, Len=6------->|
|<--[ACK] Seq=1, Ack=7 -----------| Data Transfer
|---Data=Test2 Seq=7, Len=6------->|
|<--[ACK] Seq=1, Ack=13 ----------|
|---[FIN,ACK] Seq=13, Ack=1------->|
|<--[FIN,ACK] Seq=1, Ack=14--------| Termination
|---[ACK] Seq=14, Ack=2----------->|
Quiz Q: Seq/Ack for arrows A and B (from quiz screenshot)
Given Wireshark shows packets 8–15 between client 10.0.0.20 and server 10.0.0.21:
- A (packet 12→13, client→server):
Seq=12, Ack=1 - B (packet 13→14, server→client):
Seq=1, Ack=20
6 · nc (Netcat) Commands
| Option | Meaning |
|---|---|
-l | Listen mode (server) |
-u | Use UDP (omit for TCP) |
-v | Verbose output |
-n | No DNS resolution (use if you get "name resolution" error) |
Server commands
# TCP server (listen on port 5000)
nc -lv 5000
# Output: Listening on [0.0.0.0] (family 0, port 5000)
# When client connects: Connection from [192.178.18.8] port 5000 accepted
# UDP server
nc -luv 5000
# Output: Listening on [0.0.0.0] (family 0, port 5000)
# When message arrives: XXXXXTest ← 5 auto X packets then your message
# If DNS error on either:
nc -lvn 5000 # TCP
nc -luvn 5000 # UDPClient commands
# TCP client (connect to server)
nc -v 192.178.18.9 5000
# Output: Connection to 192.178.18.9 5000 port [tcp/*] succeeded!
# UDP client
nc -uv 192.178.18.9 5000
# Output: Connection to 192.178.18.9 5000 port [udp/*] succeeded!
# Send to specific IP:port (one-liner, no interactive)
nc -uv 10.0.0.5 1234 # quiz answer for UDP to 10.0.0.5:1234
# If DNS error:
nc -vn 192.178.18.9 5000 # TCP
nc -uvn 192.178.18.9 5000 # UDP⚠️ TCP server =
nc -lv(no-u). Quiz asked "make computer a server for TCP" →nc -luvis wrong (that's UDP). Answer:nc -lv(but quiz showed-luvselected — note:-luv= UDP server).
7 · Wireshark
Launch
sudo wiresharkDisplay Filters
| Goal | Filter |
|---|---|
| All UDP from/to an IP | ip.addr==192.178.18.8 && udp |
| All TCP from/to an IP | ip.addr==192.178.18.8 && tcp |
| Only UDP from specific IP | udp && ip.src==192.178.18.8 |
| Only UDP packets from IP (quiz format) | udp && (ip.src == 172.16.0.1 | ip.dst == 172.16.0.1) |
| Filter by port | tcp.port==5000 |
| IP + port combined | ip.addr==192.178.18.8 && tcp.port==5000 |
Identify TCP Phases in Wireshark
| Phase | Flags to look for |
|---|---|
| Connection Establishment | [SYN] → [SYN, ACK] → [ACK] |
| Data Transfer | [ACK] with Len > 0 (or protocol label) |
| Connection Termination | [FIN, ACK] → [FIN, ACK] → [ACK] |
Inspect Packet Payload
Click packet → middle pane → expand protocol → click Data → payload highlighted in hex pane below.
Assignment 2 Wireshark — Expected 8 packets (TCP + "Test")
| # | Direction | Flags | Phase |
|---|---|---|---|
| 1 | C→S | SYN | Establishment |
| 2 | S→C | SYN, ACK | Establishment |
| 3 | C→S | ACK | Establishment |
| 4 | C→S | ACK + Data "Test" Len=5 | Data Transfer |
| 5 | S→C | ACK | Data ACK |
| 6 | C→S | FIN, ACK | Termination |
| 7 | S→C | FIN, ACK | Termination |
| 8 | C→S | ACK | Termination |
8 · Assignment Quick Reference
Assignment 1 — UDP
| Side | Command |
|---|---|
| Server | nc -luv 5000 (then wait) |
| Client | nc -uv <server_ip> 5000 → type Test → Enter → Ctrl+C |
Server receives: XXXXXTest (5 auto X packets before actual message)
UDP diagram: 6 one-way arrows Client→Server (no ACKs — connectionless!)
Assignment 2 — TCP (1 message: "Test")
| Side | Command |
|---|---|
| Server | nc -lv 5000 |
| Client | nc -v <server_ip> 5000 → type Test → Enter → Ctrl+C |
Expected: 8 packets in Wireshark (3 handshake + 1 data + 1 ACK + 3 termination)
Assignment 3 — TCP (2 messages: "Test1" + "Test2")
| Side | Command |
|---|---|
| Server | nc -lv 5000 |
| Client | nc -v <server_ip> 5000 → Test1 Enter → Test2 Enter → Ctrl+C |
Expected: 10 packets (3 handshake + 2 data + 2 ACK + 3 termination)
Note: TCP may merge both messages into 1 segment (Len=12) if sent fast enough.
Assignment 4 — Analyze pcap file
sudo wireshark # File → Open → Lab8_Assign4.pcapFilter: ip.addr==192.178.18.8 && tcp
- Client port: 39668 | Server port: 5000
- Message C→S:
"How are you?"(Len=13) - Message S→C:
"I am fine."(Len=11)
9 · Quiz Question Patterns
| Question | Answer |
|---|---|
| Which layer uses IP address? | Network layer |
| Which layer uses port number? | Transport layer |
| Which layer uses MAC address? | Data Link layer |
| TCP server command (TCP)? | nc -lv <port> |
| TCP server verbose (quiz showed)? | nc -luv = UDP server ⚠️ |
| UDP client to 10.0.0.5:1234? | nc -uv 10.0.0.5 1234 |
| Correct TCP termination sequence? | ACK / FIN+ACK / FIN (passive side gets ACK first, then sends FIN+ACK, then gets FIN+ACK — quiz answer was ACK/FIN+ACK/FIN) |
| NOT true about UDP? | "UDP provides more reliability" — UDP is less reliable than TCP |
| SSH port? | 22 |
| HTTP port? | 80 (TCP) |
| DNS port? | 53 (UDP + TCP) |
| DHCP port? | 67 (UDP) |
| FTP control port? | 21 (TCP) |
| Wireshark filter: UDP only from 172.16.0.1? | udp && (ip.src == 172.16.0.1 | ip.dst == 172.16.0.1) |
| SYN Seq=1000 → ACK back? | 1001 (SYN consumes +1) |
| Data Seq=1, Len=5 → ACK back? | 6 (1+5) |
| Does ACK-only consume seq#? | No |
| Does SYN consume seq#? | Yes (+1) |
| Does FIN consume seq#? | Yes (+1) |
| Port range well-known? | 0 – 1,023 |
| Port range dynamic? | 49,152 – 65,535 |
| UDP sends X's before message? | 5 X packets automatically sent by nc before actual data |
10 · Termination Order Clarification (tricky!)
The quiz answer was ACK / FIN+ACK / FIN — this describes what the passive closer sees:
Active closer → [FIN,ACK] → Passive closer
Active closer ← [FIN,ACK] ← Passive closer (combined ACK+FIN)
Active closer → [ACK] → Passive closer
From passive closer's perspective of received/sent: receives FIN → sends FIN+ACK → receives ACK.
From active closer's perspective: sends FIN+ACK → receives FIN+ACK → sends ACK.
ITS352/DES352 · SIIT · Thammasat University