Lab 8

Updated 4 Oct 2026

🌐 Lab 8 — Transport-Layer Protocols · Cheat Sheet

ITS352/DES352 · SIIT · Thammasat University


1 · Layer Address Summary

LayerAddressSizeIdentifies
Data LinkMAC Address48 bitsDevice within a LAN
NetworkIP Address32 bitsDevice across different networks
TransportPort Number16 bitsProcess/program on a host
  • Network layer → host-to-host (gets packet to the right machine)
  • Transport layer → process-to-process (gets packet to the right program)

IP = building address. Port = apartment number. MAC = local street directions.


2 · Port Numbers

Range: 0 – 65,535 (16-bit = 2^16 − 1)

GroupRangeUsed for
Well-Known0 – 1,023Common services (HTTP, FTP, DNS…)
Registered1,024 – 49,151Specific apps assigned by IANA
Dynamic / Private49,152 – 65,535Auto-assigned by OS to clients

Key Well-Known Ports (memorise these!)

PortProtocolTCPUDP
20FTP (data)✅
21FTP (control)✅
22SSH✅
23TELNET✅
25SMTP✅
53DNS✅✅
67DHCP✅
69TFTP✅✅
80HTTP✅
123NTP✅
161SNMP (server)✅

Port conflict rule:

  • Same IP, same protocol, same port → ❌ NOT OK (e.g. two apps on TCP 80)
  • Same IP, same port, different protocol → ✅ OK (TCP 80 + UDP 80 can coexist)
  • Same IP, same protocol, different port → ✅ OK (TCP 80 + TCP 8080)

Socket Address = IP Address + Port Number (e.g. 200.23.56.8:80)


3 · UDP vs TCP

FeatureUDPTCP
ConnectionConnectionlessConnection-oriented
ReliabilityUnreliableReliable (ACKs + retransmission)
OrderingUnorderedIn-order delivery
SpeedFasterSlower (overhead)
Header size8 bytes20+ bytes
Flow control❌✅
PhasesNoneEstablish → Transfer → Terminate
Use casesDNS, DHCP, streaming, gamingHTTP, FTP, SMTP, SSH

UDP = postcard (send & hope). TCP = phone call (dial, talk, hang up properly).


4 · TCP Three-Way Handshake

Connection Establishment

Client                        Server
  |---[SYN] Seq=0, Len=0------->|   Step 1: Client requests connection
  |<--[SYN,ACK] Seq=0, Ack=1----|   Step 2: Server acknowledges + its own SYN
  |---[ACK] Seq=1, Ack=1-------->|   Step 3: Client ACKs → connection OPEN

Connection Termination

Active closer                 Passive closer
  |---[FIN,ACK] Seq=x--------->|   Step 1: Initiate close
  |<--[FIN,ACK] Seq=y, Ack=x+1-|   Step 2: ACK + own FIN
  |---[ACK] Ack=y+1------------>|   Step 3: Final ACK → connection CLOSED

5 · Sequence Number Rules ⚠️ (exam favourite!)

SegmentConsumes Seq#Amount
SYN✅+1
SYN + ACK✅+1
FIN✅+1
FIN + ACK✅+1
ACK only (no data)❌0
Data segment✅+Len (bytes)

Formulas:

Next Seq after SYN or FIN  = Current Seq + 1
Next Seq after data        = Current Seq + Len
ACK sent back              = Seq received + Len  (or +1 for SYN/FIN)

Full TCP Exchange Example (Assignment 4 pcap)

Client 192.178.18.8:39668           Server 192.178.18.9:5000
  |---[SYN] Seq=0, Len=0------------>|
  |<--[SYN,ACK] Seq=0, Ack=1---------|  ← Establishment
  |---[ACK] Seq=1, Ack=1------------>|
  |                                   |
  |---Data="How are you?" Seq=1,Len=13->|
  |<--[ACK] Seq=1, Ack=14------------|  ← Data Transfer
  |                                   |
  |<--Data="I am fine." Seq=1,Len=11--|
  |---[ACK] Seq=14, Ack=12---------->|
  |                                   |
  |<--[FIN,ACK] Seq=12, Ack=14-------|
  |---[FIN,ACK] Seq=14, Ack=13------>|  ← Termination
  |<--[ACK] Seq=13, Ack=15-----------|

Two-message TCP Example (Assignment 3: "Test1" + "Test2", each = 6 bytes incl. \n)

Client                              Server :5000
  |---[SYN] Seq=0 ----------------->|
  |<--[SYN,ACK] Seq=0, Ack=1--------|  Establishment
  |---[ACK] Seq=1, Ack=1 ----------->|
  |---Data=Test1 Seq=1, Len=6------->|
  |<--[ACK] Seq=1, Ack=7 -----------|  Data Transfer
  |---Data=Test2 Seq=7, Len=6------->|
  |<--[ACK] Seq=1, Ack=13 ----------|
  |---[FIN,ACK] Seq=13, Ack=1------->|
  |<--[FIN,ACK] Seq=1, Ack=14--------|  Termination
  |---[ACK] Seq=14, Ack=2----------->|

Quiz Q: Seq/Ack for arrows A and B (from quiz screenshot)

Given Wireshark shows packets 8–15 between client 10.0.0.20 and server 10.0.0.21:

  • A (packet 12→13, client→server): Seq=12, Ack=1
  • B (packet 13→14, server→client): Seq=1, Ack=20

6 · nc (Netcat) Commands

OptionMeaning
-lListen mode (server)
-uUse UDP (omit for TCP)
-vVerbose output
-nNo DNS resolution (use if you get "name resolution" error)

Server commands

# TCP server (listen on port 5000)
nc -lv 5000
# Output: Listening on [0.0.0.0] (family 0, port 5000)
# When client connects: Connection from [192.178.18.8] port 5000 accepted
 
# UDP server
nc -luv 5000
# Output: Listening on [0.0.0.0] (family 0, port 5000)
# When message arrives: XXXXXTest   ← 5 auto X packets then your message
 
# If DNS error on either:
nc -lvn 5000    # TCP
nc -luvn 5000   # UDP

Client commands

# TCP client (connect to server)
nc -v 192.178.18.9 5000
# Output: Connection to 192.178.18.9 5000 port [tcp/*] succeeded!
 
# UDP client
nc -uv 192.178.18.9 5000
# Output: Connection to 192.178.18.9 5000 port [udp/*] succeeded!
 
# Send to specific IP:port (one-liner, no interactive)
nc -uv 10.0.0.5 1234    # quiz answer for UDP to 10.0.0.5:1234
 
# If DNS error:
nc -vn 192.178.18.9 5000   # TCP
nc -uvn 192.178.18.9 5000  # UDP

⚠️ TCP server = nc -lv (no -u). Quiz asked "make computer a server for TCP" → nc -luv is wrong (that's UDP). Answer: nc -lv (but quiz showed -luv selected — note: -luv = UDP server).


7 · Wireshark

Launch

sudo wireshark

Display Filters

GoalFilter
All UDP from/to an IPip.addr==192.178.18.8 && udp
All TCP from/to an IPip.addr==192.178.18.8 && tcp
Only UDP from specific IPudp && ip.src==192.178.18.8
Only UDP packets from IP (quiz format)udp && (ip.src == 172.16.0.1 | ip.dst == 172.16.0.1)
Filter by porttcp.port==5000
IP + port combinedip.addr==192.178.18.8 && tcp.port==5000

Identify TCP Phases in Wireshark

PhaseFlags to look for
Connection Establishment[SYN] → [SYN, ACK] → [ACK]
Data Transfer[ACK] with Len > 0 (or protocol label)
Connection Termination[FIN, ACK] → [FIN, ACK] → [ACK]

Inspect Packet Payload

Click packet → middle pane → expand protocol → click Data → payload highlighted in hex pane below.

Assignment 2 Wireshark — Expected 8 packets (TCP + "Test")

#DirectionFlagsPhase
1C→SSYNEstablishment
2S→CSYN, ACKEstablishment
3C→SACKEstablishment
4C→SACK + Data "Test" Len=5Data Transfer
5S→CACKData ACK
6C→SFIN, ACKTermination
7S→CFIN, ACKTermination
8C→SACKTermination

8 · Assignment Quick Reference

Assignment 1 — UDP

SideCommand
Servernc -luv 5000 (then wait)
Clientnc -uv <server_ip> 5000 → type Test → Enter → Ctrl+C

Server receives: XXXXXTest (5 auto X packets before actual message)
UDP diagram: 6 one-way arrows Client→Server (no ACKs — connectionless!)

Assignment 2 — TCP (1 message: "Test")

SideCommand
Servernc -lv 5000
Clientnc -v <server_ip> 5000 → type Test → Enter → Ctrl+C

Expected: 8 packets in Wireshark (3 handshake + 1 data + 1 ACK + 3 termination)

Assignment 3 — TCP (2 messages: "Test1" + "Test2")

SideCommand
Servernc -lv 5000
Clientnc -v <server_ip> 5000 → Test1 Enter → Test2 Enter → Ctrl+C

Expected: 10 packets (3 handshake + 2 data + 2 ACK + 3 termination)
Note: TCP may merge both messages into 1 segment (Len=12) if sent fast enough.

Assignment 4 — Analyze pcap file

sudo wireshark   # File → Open → Lab8_Assign4.pcap

Filter: ip.addr==192.178.18.8 && tcp

  • Client port: 39668 | Server port: 5000
  • Message C→S: "How are you?" (Len=13)
  • Message S→C: "I am fine." (Len=11)

9 · Quiz Question Patterns

QuestionAnswer
Which layer uses IP address?Network layer
Which layer uses port number?Transport layer
Which layer uses MAC address?Data Link layer
TCP server command (TCP)?nc -lv <port>
TCP server verbose (quiz showed)?nc -luv = UDP server ⚠️
UDP client to 10.0.0.5:1234?nc -uv 10.0.0.5 1234
Correct TCP termination sequence?ACK / FIN+ACK / FIN (passive side gets ACK first, then sends FIN+ACK, then gets FIN+ACK — quiz answer was ACK/FIN+ACK/FIN)
NOT true about UDP?"UDP provides more reliability" — UDP is less reliable than TCP
SSH port?22
HTTP port?80 (TCP)
DNS port?53 (UDP + TCP)
DHCP port?67 (UDP)
FTP control port?21 (TCP)
Wireshark filter: UDP only from 172.16.0.1?udp && (ip.src == 172.16.0.1 | ip.dst == 172.16.0.1)
SYN Seq=1000 → ACK back?1001 (SYN consumes +1)
Data Seq=1, Len=5 → ACK back?6 (1+5)
Does ACK-only consume seq#?No
Does SYN consume seq#?Yes (+1)
Does FIN consume seq#?Yes (+1)
Port range well-known?0 – 1,023
Port range dynamic?49,152 – 65,535
UDP sends X's before message?5 X packets automatically sent by nc before actual data

10 · Termination Order Clarification (tricky!)

The quiz answer was ACK / FIN+ACK / FIN — this describes what the passive closer sees:

Active closer   →  [FIN,ACK]  →  Passive closer
Active closer   ←  [FIN,ACK]  ←  Passive closer   (combined ACK+FIN)
Active closer   →  [ACK]      →  Passive closer

From passive closer's perspective of received/sent: receives FIN → sends FIN+ACK → receives ACK.
From active closer's perspective: sends FIN+ACK → receives FIN+ACK → sends ACK.

ITS352/DES352 · SIIT · Thammasat University