🖥️ Customized for Your VM Setup
Course: ITS352, DES352 - Networking Laboratory
Institution: School of ICT, Sirindhorn International Institute of Technology
Your VM Configuration:
- Primary Interface:
enp0s1(192.168.64.7) - Docker Interfaces:
docker0,br-0212e2f637a2(ignore these for lab) - Loopback:
lo(127.0.0.1)
🍎 Mac vs 🐧 Linux VM Comparison
| Aspect | Your Linux VM | Your Mac |
|---|---|---|
| Primary Interface | enp0s1 | en0 (WiFi/Ethernet) |
| Secondary Interface | Would be enp0s2, enp0s3 | en1, en2 |
| Loopback | lo | lo0 |
| IP Address | 192.168.64.7 (VM network) | Different (your home/office network) |
| Command | ifconfig | ifconfig (works the same!) |
| Sudo required | Yes for changes | Yes for changes |
| Docker interfaces | Yes (you have them) | If Docker Desktop installed |
Instructions
- The attendance will be checked at the beginning of the Lab class
- You must login to Ubuntu via:
- Username:
student - Password:
Siit@1992 - Your VM: Already logged in as
npwitk
- Username:
- In this lab sheet, the ✔ sign identifies your exercise
- Some exercises require a TA's signature to check your result
- When finishing all exercises, show your Lab Sheet to a TA
- You will have a 20-minute quiz around the end of the Lab class (or when appropriate)
- You must submit the last page to a TA at the end of the class
Section 1: Network Interface Card (NIC)
What is a NIC?
- A Network Interface Card/Controller (NIC) is a computer hardware component that allows a computer to connect to a network
- NICs may be used for both wired and wireless connections
- In our networking lab, each computer has 3 Ethernet NICs called:
- Lab computers:
eth0,eth1,eth2OReno1,enp4s0, etc. - Your VM:
enp0s1(and potentiallyenp0s2,enp0s3if you add more) - Your Mac:
en0(WiFi),en1(Thunderbolt), etc.
- Lab computers:
- You connect a LAN cable to a NIC to connect this computer to a network
Analogy: Think of a NIC as a network "port" on your computer - just like USB ports allow you to connect USB devices, NICs allow you to connect to networks. Each NIC is like having a separate "phone line" that can connect to different networks.
Note: Appendix B in the Lab Manual shows the scheme of the network connection in the networking lab.
[Image of NIC hardware]
🔍 Your Current Setup:
Your Linux VM has these interfaces:
enp0s1 # Your main network interface (connected)
docker0 # Docker bridge network (can ignore)
br-0212e2f637a2 # Another Docker bridge (can ignore)
lo # Loopback (localhost)If you run ifconfig on your Mac, you'd see:
en0 # Your WiFi/Ethernet (main connection)
en1 # Thunderbolt/secondary
lo0 # Loopback
bridge0 # If you have VM softwareSection 2: Computer Addresses
Each computer occupies three different kinds of addresses:
1. MAC Address (Media Access Control Address)
- Also known as the hardware address
- A unique identifier (ID) assigned to an NIC for communications at the data link layer of a network segment
- Consists of 12 hexadecimal characters (6 bytes)
- Example format:
02:0a:95:9d:68:16 - The MAC address of a computer could be fixed (if not changing its NIC)
Your VM's MAC Address:
enp0s1: be:52:f6:c8:ab:1cAnalogy: A MAC address is like the serial number on your laptop - it's permanently assigned to the hardware and uniquely identifies that specific network card. Even if you move to a different building or country, the MAC address stays the same.
2. IP Address (Internet Protocol Address)
- A logical address (at the network layer) used to uniquely identify every computer/device in the network
- Because IP addresses are logical, they can change
- IPv4 format: A series of four numbers separated by dots
- Example:
192.168.5.11
Your VM's IP Address:
enp0s1: 192.168.64.7On Mac, it might be:
en0: 192.168.1.XXX (your home router's network)
# or
en0: 10.0.0.XXX (common for some routers)Types of IP Addresses:
Public IP:
- Assigned by an Internet Service Provider (ISP)
- Used by routers and computers connected directly to a modem without a router
Private IP:
- Special IP addresses assigned by a router
- Known only to a router and its home network
- Common private IP ranges:
192.168.x.x← Your VM uses this!10.x.x.x172.16.x.xto172.31.x.x← Your Docker uses this!
Analogy: If MAC addresses are like permanent serial numbers, IP addresses are like your current mailing address - they can change when you move to a different network, just like your street address changes when you move houses.
Router IP Addresses:
- Routers are special because they have two IP addresses
- An IP address is assigned to each of the router's two interfaces:
- WAN (Wide Area Network) Interface:
- The side of the router that faces the Internet
- Has a public IP address
- LAN (Local Area Network) Interface:
- The side of the router that faces the home network's computers
- Has a private IP address
- Your VM's gateway: Likely
192.168.64.1or192.168.64.254 - Your Mac's gateway: Check with
netstat -nr | grep default
[Image showing router with WAN and LAN interfaces]
3. Hostname
- The computer name
- Created/readable/understandable by people
- Example:
MyComp
Your VM's hostname:
npwitk-linuxYour Mac's hostname:
# Check with: hostname
# Probably something like: npwitk-MacBook-Pro.localAnalogy: A hostname is like a person's name - much easier for humans to remember than a string of numbers. Just as "John's Computer" is easier to remember than
192.168.1.105.
Section 3: Roles of MAC Addresses and IP Addresses
How Packets are Transferred
To transfer a packet from source (computer) to destination (computer), both destination MAC address and IP addressshould be known.
Key Concepts:
-
IP addresses are used to identify the destination globally
- The destination might be located across the world
- The packet must be sent across/through many routers
-
MAC addresses are used to identify the address locally
- Used to relay packets from one router to another router (hop-by-hop)
- The MAC address is used for local delivery (not the IP address)
Important Behavior:
- The IP of the destination is fixed throughout the journey
- The MAC address changes every hop
- If the destination is in the same network as the source, the packet will be delivered directly to the destination using the MAC address
Analogy: Think of sending a package across the country:
- The IP address is like the final destination address on the package (e.g., "123 Main St, New York, NY") - this never changes
- The MAC address is like the delivery truck or plane that carries it for each leg of the journey - it changes at each distribution center, but the final destination stays the same
Example Packet Journey:
[Image showing packet traversal with changing MAC addresses]
Packet Details at Each Hop:
From Source to Router 1:
- Source IP:
195.15.16.11 - Destination IP:
2.17.169.198 - Source MAC:
35:a0:b1:00:57:c2 - Destination MAC:
01:53:aa:f9:d2:8c
From Router 1 to Router 2:
- Source IP:
195.15.16.11(unchanged) - Destination IP:
2.17.169.198(unchanged) - Source MAC:
28:18:78:5a:f5:96(changed) - Destination MAC:
35:a0:b1:72:01:19(changed)
From Router 2 to Computer:
- Source IP:
195.15.16.11(unchanged) - Destination IP:
2.17.169.198(unchanged) - Source MAC:
00:1f:19:ba:20:39(changed) - Destination MAC:
28:18:78:5a:f4:c7(changed)
Section 4: Linux Commands - ifconfig to Show/Change Details of Network Interface
What is ifconfig?
The command ifconfig (stands for interface configuration) is used to:
- View the configuration of network interfaces
- Change the configuration of network interfaces on your system
4.1) View All Active Network Interfaces
Command:
ifconfigPurpose: To view information about all network interfaces currently in operation (running)
🖥️ Your VM Output:
npwitk@npwitk-linux:~$ ifconfig
enp0s1: flags=4163<UP,BROADCAST,RUNNING,MULTICAST> mtu 1500
inet 192.168.64.7 netmask 255.255.255.0 broadcast 192.168.64.255
inet6 fd88:82c3:e85b:fd91:bc52:f6ff:fec8:ab1c prefixlen 64 scopeid 0x0<global>
inet6 fe80::bc52:f6ff:fec8:ab1c prefixlen 64 scopeid 0x20<link>
ether be:52:f6:c8:ab:1c txqueuelen 1000 (Ethernet)
RX packets 143 bytes 65090 (65.0 KB)
RX errors 0 dropped 0 overruns 0 frame 0
TX packets 133 bytes 20586 (20.5 KB)
TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0
lo: flags=73<UP,LOOPBACK,RUNNING> mtu 65536
inet 127.0.0.1 netmask 255.0.0.0
inet6 ::1 prefixlen 128 scopeid 0x10<host>
loop txqueuelen 1000 (Local Loopback)
RX packets 414 bytes 33213 (33.2 KB)
RX errors 0 dropped 0 overruns 0 frame 0
TX packets 414 bytes 33213 (33.2 KB)
TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0🍎 Mac Output (for comparison):
# On Mac, you'd see:
en0: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
options=6463<RXCSUM,TXCSUM,TSO4,TSO6,CHANNEL_IO,PARTIAL_CSUM,ZEROINVERT_CSUM>
ether a4:83:e7:xx:xx:xx
inet6 fe80::1c2f:2aff:fe9b:xxxx%en0 prefixlen 64 secured scopeid 0x4
inet 192.168.1.123 netmask 0xffffff00 broadcast 192.168.1.255
nd6 options=201<PERFORMNUD,DAD>
media: autoselect
status: active
lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> mtu 16384
options=1203<RXCSUM,TXCSUM,TXSTATUS,SW_TIMESTAMP>
inet 127.0.0.1 netmask 0xff000000
inet6 ::1 prefixlen 128
inet6 fe80::1%lo0 prefixlen 64 scopeid 0x1
nd6 options=201<PERFORMNUD,DAD>Notice the differences:
- Linux:
enp0s1, Mac:en0 - Linux: More human-readable format
- Mac: More compact, different flag format
- Both show: IP, MAC (ether), packets, bytes
Understanding the Output:
| Column | Value (Your VM) | Meaning |
|---|---|---|
| Interface name | enp0s1 | Your network interface name |
| Link | Ethernet | Ethernet frame type |
| ether (HWaddr) | be:52:f6:c8:ab:1c | Network Hardware address or MAC address |
| inet | 192.168.64.7 | Network Logical Address or IPv4 Address |
| inet6 | fd88:82c3:e85b:fd91:... | Network Logical Address IPv6 Address (global) |
| inet6 | fe80::bc52:f6ff:... | IPv6 Link-local Address |
| broadcast | 192.168.64.255 | Broadcast address for your subnet |
| netmask | 255.255.255.0 | Network mask associated with this interface |
| flags | UP,BROADCAST,RUNNING,MULTICAST | • UP: Network interface enabled • BROADCAST: Able to handle broadcast packet • RUNNING: Operational and ready to accept and transmit data • MULTICAST: Able to handle multicast packet |
| Column | Value | Meaning |
|---|---|---|
| MTU | 1500 | Maximum transmission unit (bytes) |
| RX packets | 143 | Packets received |
| RX bytes | 65090 (65.0 KB) | Total bytes received |
| TX packets | 133 | Packets transmitted |
| TX bytes | 20586 (20.5 KB) | Total bytes transmitted |
| RX/TX errors | 0 | Damaged packets |
| dropped | 0 | Dropped packets due to errors |
| overruns | 0 | Buffer overrun issues |
| collisions | 0 | Number of packet collisions |
4.2) View All Network Interfaces (Including Inactive)
Command:
$ ifconfig -aPurpose: To view the configuration of all network interfaces on the system (not just the ones that are currently active)
Your VM shows:
enp0s1(active)docker0(inactive but configured)br-0212e2f637a2(inactive but configured)lo(active loopback)
On Mac, you might see:
en0(WiFi - active)en1(Thunderbolt - may be inactive)en2(USB Ethernet - if you have adapter)awdl0(Apple Wireless Direct Link - for AirDrop)bridge0(if running VMs)lo0(loopback)
4.3) View Information of a Specific Network Interface
Command:
$ ifconfig [NICname]For Your VM:
$ ifconfig enp0s1For Mac (to compare):
$ ifconfig en0Lab manual examples (for reference):
$ ifconfig eth0 # Lab computers
$ ifconfig eno1 # Some lab computers4.4) Disable an Active Interface
Command:
$ sudo ifconfig [NICname] downFor Your VM:
$ sudo ifconfig enp0s1 down⚠️ WARNING: This will disconnect your VM from the network! You won't be able to browse the internet or ssh until you bring it back up!
For Mac:
$ sudo ifconfig en0 down⚠️ WARNING: This will disconnect your Mac from WiFi/network!
Note: Enabling or disabling a device requires superuser permissions, so you will either have to be logged in as root or prefix your command with sudo to run it with superuser privileges.
Important: When you disable an interface, it stops all network communication through that NIC. It's like unplugging the network cable.
✔ Activity 4.4:
Step 1: Check current status:
$ ifconfigStep 2: Look for enp0s1 in the output with UP and RUNNING flags
Question: In the list, do you see the NIC enp0s1 with UP and RUNNING flags?
Answer: YES (you should see it since it's currently active)
For comparison on Mac:
$ ifconfig en0
# Look for: flags=8863<UP,BROADCAST,SMART,RUNNING...>4.5) Enable an Inactive Interface
Command:
$ sudo ifconfig [NICname] upFor Your VM:
$ sudo ifconfig enp0s1 upFor Mac:
$ sudo ifconfig en0 up✔ Activity 4.5:
Step 1: After bringing the interface up:
$ ifconfigStep 2: Verify enp0s1 appears with UP and RUNNING flags
Question: In the list, do you see the NIC enp0s1?
Answer: YES (after running the up command)
4.6) Assign a Static IP Address to an Interface
Command:
$ sudo ifconfig [NICname] [IPaddress]Lab manual example:
$ sudo ifconfig eth1 192.168.10.50For Your VM (if you had a second interface):
# If you add a second network adapter, it would be:
$ sudo ifconfig enp0s2 192.168.10.50For Mac:
$ sudo ifconfig en1 192.168.10.50⚠️ WARNING: Don't run this on your primary interface (enp0s1 or en0) as it will change your IP and likely disconnect you!
To verify the change:
$ ifconfig enp0s2 # For VM
$ ifconfig en1 # For Mac✔ Activity 4.6:
NOTE: Since your VM currently only has one active network interface (enp0s1), you have two options:
Option 1 - Add a second network adapter to your VM:
- Shut down your VM
- In your VM settings, add a second network adapter
- Start the VM
- The new interface will appear as
enp0s2 - Then run:
sudo ifconfig enp0s2 192.168.10.50
Option 2 - Just record the command you would use:
sudo ifconfig enp0s2 192.168.10.50Record the IP address assigned:
Answer: 192.168.10.50 (or write that you need to add second adapter first)
Section 5: Testing Network Connectivity by Using the Command ping
What is ping?
- The command
ping(Packet Internet Groper) is a network administration utility used to:- Check the connectivity status/quality between a source and destination computer/device over an IP network
- Assess the time it takes to send and receive a response from the network
How ping Works:
- Uses the Internet Control Message Protocol (ICMP) to send and receive echo messages
- Process:
- An ICMP request message is sent to the destination computer
- If the destination IP address is available, it sends an ICMP response message back to the host computer
- This tells us about the connectivity status/quality of the network such as round-trip time (RTT) - the time taken to send and receive a packet
Analogy: Using
pingis like shouting "Hello!" in a canyon and waiting for the echo. The echo tells you there's something there, and how long it takes for the echo to return tells you how far away it is. In networking, the "echo" is the response from the destination computer.
5.1) Basic Ping Command
Command:
$ ping [HostName/IPaddress]To stop: Press CTRL-C
🖥️ Try These on Your VM:
Test 1: Ping yourself (loopback)
$ ping 127.0.0.1
# or
$ ping localhostTest 2: Ping your VM's gateway (likely the host Mac)
$ ping 192.168.64.1Test 3: Ping Google's DNS
$ ping 8.8.8.8Test 4: Ping a website
$ ping google.com🍎 Same Commands Work on Mac!
$ ping 127.0.0.1 # Ping yourself
$ ping 192.168.1.1 # Ping your router (IP may differ)
$ ping 8.8.8.8 # Ping Google DNS
$ ping google.com # Ping websiteExample Output from Your VM:
npwitk@npwitk-linux:~$ ping 8.8.8.8
PING 8.8.8.8 (8.8.8.8) 56(84) bytes of data.
64 bytes from 8.8.8.8: icmp_seq=1 ttl=117 time=12.4 ms
64 bytes from 8.8.8.8: icmp_seq=2 ttl=117 time=11.8 ms
64 bytes from 8.8.8.8: icmp_seq=3 ttl=117 time=13.2 ms
64 bytes from 8.8.8.8: icmp_seq=4 ttl=117 time=12.1 ms
^C
--- 8.8.8.8 ping statistics ---
4 packets transmitted, 4 received, 0% packet loss, time 3004ms
rtt min/avg/max/mdev = 11.812/12.375/13.201/0.534 msUnderstanding the Output:
56: Default data length (bytes)84: Message length (bytes) = Header (8 bytes ICMP + 20 bytes IP) + Data64 bytes: Message length = Default data length (56 bytes) + ICMP header (8 bytes) sent back from destinationicmp_seq: Sequence number of the ICMP response messagettl=117: Time To Live - this packet can go through 117 more routers- Started at 128 (Windows) or 64 (Linux)
- Each router decreases it by 1
ttl=117means it went through ~11 routers (128-117=11)
time=12.4 ms: Round trip time - took 12.4 milliseconds
Key Point: A lower RTT means faster network connection. If you see timeouts or high RTT values, it indicates network problems.
What good RTT values look like:
< 1ms- Same network (e.g., your VM to host Mac)1-30ms- Excellent (local servers, nearby websites)30-50ms- Good (most websites)50-100ms- Acceptable (international connections)> 100ms- Slow (far away servers, network issues)> 300ms- Very slow (satellite, poor connection)
5.2) Increase/Decrease Interval Between Ping Packets
The default time interval between sending each packet is 1 second in Linux.
Command:
$ ping -i [TimeGap] [HostName/IPaddress]- You can increase the time interval by setting a value greater than 1
- You can decrease it by setting a value less than 1
Example: Send ping every 2 seconds
$ ping -i 2 8.8.8.8Example: Send ping every 0.5 seconds (faster)
$ ping -i 0.5 8.8.8.8⚠️ Note: Values less than 0.2 seconds require root privileges:
$ sudo ping -i 0.1 8.8.8.8Works the same on Mac!
5.3) Changing Ping Packet (Data) Size
You can change the packet (data) size through the following command:
Command:
$ ping -s [PacketSize] [HostName/IPaddress]Example: Send 100-byte data packets
$ ping -s 100 8.8.8.8Example: Send large packets (1000 bytes)
$ ping -s 1000 8.8.8.8Output will show:
PING 8.8.8.8 (8.8.8.8) 100(128) bytes of data.
# 100 = data size
# 128 = total size (100 + 8 ICMP + 20 IP headers)Works the same on Mac!
5.4) Sending a Specific Number of Ping Packets
You can specify the number of ping packets sent to the destination:
Command:
$ ping -c [Number] [HostName/IPaddress]Example: Send exactly 10 ping packets
$ ping -c 10 8.8.8.8Example: Send just 4 packets for quick test
$ ping -c 4 google.comAfter sending the specified number, ping will automatically stop and show statistics.
Works the same on Mac!
✔ Activity 5.4:
Task: Write a ping command to send 8 ping packets with 60-byte data, every 3 seconds
Solution:
Step 1: Identify the required options:
-c 8: Send 8 packets-s 60: 60-byte data size-i 3: 3-second interval
Step 2: Combine the options:
$ ping -c 8 -s 60 -i 3 [IPaddress]Step 3: Choose a target to ping:
For Your VM - Try these:
# Option 1: Ping Google DNS
$ ping -c 8 -s 60 -i 3 8.8.8.8
# Option 2: Ping your gateway
$ ping -c 8 -s 60 -i 3 192.168.64.1
# Option 3: Ping a website
$ ping -c 8 -s 60 -i 3 google.comComplete command:
$ ping -c 8 -s 60 -i 3 8.8.8.8Expected output:
PING 8.8.8.8 (8.8.8.8) 60(88) bytes of data.
68 bytes from 8.8.8.8: icmp_seq=1 ttl=117 time=12.3 ms
68 bytes from 8.8.8.8: icmp_seq=2 ttl=117 time=11.9 ms
68 bytes from 8.8.8.8: icmp_seq=3 ttl=117 time=12.5 ms
68 bytes from 8.8.8.8: icmp_seq=4 ttl=117 time=12.1 ms
68 bytes from 8.8.8.8: icmp_seq=5 ttl=117 time=13.0 ms
68 bytes from 8.8.8.8: icmp_seq=6 ttl=117 time=12.4 ms
68 bytes from 8.8.8.8: icmp_seq=7 ttl=117 time=11.8 ms
68 bytes from 8.8.8.8: icmp_seq=8 ttl=117 time=12.6 ms
--- 8.8.8.8 ping statistics ---
8 packets transmitted, 8 received, 0% packet loss, time 21047ms
rtt min/avg/max/mdev = 11.834/12.325/13.021/0.385 msNotice:
- Takes 24 seconds total (8 packets × 3 seconds = 24 seconds)
60(88)means 60 bytes data + 28 bytes headers68 bytesreceived = 60 data + 8 ICMP header
Your Answer:
ping -c 8 -s 60 -i 3 8.8.8.8Step 4: Execute the command and show the result to a TA
TA's Signature: ________________________
Section 6: Address Resolution Protocol (ARP)
What is ARP?
- The Address Resolution Protocol (ARP) is a network protocol used to find out the hardware/MAC address of a device from an IP address
- Used when a device wants to send packets to another device on a local network (e.g., on an Ethernet network that requires physical addresses to be known before sending packets)
How ARP Works:
Process:
-
Before sending packets, the source device looks in its ARP cache (ARP table that stores a mapping list of MAC and IP addresses) to see if there is a MAC address and corresponding IP address for the destination device
-
If there is no entry:
- The source device sends a broadcast message to every device on the network
- Each device compares the IP address to its own
- Only the device with the matching IP address replies to the sending device with a packet containing its MAC address (called unicast)
-
The source device adds the destination device MAC address to its ARP cache for future reference
-
Now it is able to send the packets to the destination device
Analogy: ARP is like looking up someone's phone number in a directory:
- You know their name (IP address) but need their phone number (MAC address) to call them
- You first check your contacts (ARP cache)
- If not there, you ask everyone in the room "Who has this name?" (broadcast)
- Only the person with that name responds with their number (unicast reply)
- You save it in your contacts for next time (add to ARP cache)
[Image showing ARP request/reply process with Host A, B, C, and D]
Using the arp Command
The arp command allows you to display and modify the ARP cache.
6.1) Show Complete ARP Cache (Including Hostname)
Command:
$ arp -aPurpose: Display all MAC-IP address mappings with hostnames
🖥️ Example Output from Your VM:
npwitk@npwitk-linux:~$ arp -a
? (192.168.64.1) at 52:54:00:12:35:02 [ether] on enp0s1
_gateway (192.168.64.1) at 52:54:00:12:35:02 [ether] on enp0s1What this shows:
192.168.64.1- Your gateway (probably your Mac host)52:54:00:12:35:02- Gateway's MAC address[ether]- Ethernet typeon enp0s1- Connected via your network interface
🍎 Example Output on Mac:
$ arp -a
? (192.168.1.1) at b8:27:eb:xx:xx:xx on en0 ifscope [ethernet]
? (192.168.1.5) at dc:a6:32:xx:xx:xx on en0 ifscope [ethernet]
? (192.168.64.7) at be:52:f6:c8:ab:1c on bridge100 ifscope [ethernet]What this shows:
192.168.1.1- Router192.168.1.5- Another device (phone, computer, etc.)192.168.64.7- That's YOUR VM! (Mac sees it through bridge)
6.2) Show ARP Cache (Excluding Hostname)
Command:
$ arp -nPurpose: Display all MAC-IP address mappings without resolving hostnames (faster)
🖥️ Example Output from Your VM:
npwitk@npwitk-linux:~$ arp -n
Address HWtype HWaddress Flags Mask Iface
192.168.64.1 ether 52:54:00:12:35:02 C enp0s1Columns explained:
- Address: IP address
- HWtype: Hardware type (ethernet)
- HWaddress: MAC address
- Flags:
C= Complete (entry is complete)M= Permanent (manually added)P= Published (proxy ARP)
- Iface: Interface name
6.3) Add ARP Entry to ARP Cache
How to add an entry when you know the IP address but not the MAC address:
✔ Activity 6.3:
For Your VM Setup:
Since your VM is in a virtualized network (192.168.64.x), you'll be pinging devices in your VM's network.
Step 1: Identify targets to ping (that are NOT in your ARP cache yet)
Targets you can try:
a) Your Mac host (gateway):
192.168.64.1b) Google DNS:
8.8.8.8⚠️ Note: External IPs like 8.8.8.8 won't appear in ARP cache because they're not on your local network!
c) If you have other VMs running:
192.168.64.2, 192.168.64.3, etc.Step 2: Check your current ARP cache (before pinging):
$ arp -nWrite down what you see: _________________
Step 3: Choose an IP to ping (let's use your gateway):
$ ping -c 4 192.168.64.1Step 4: Check your ARP cache again:
$ arp -nWhy this works: When you ping a device on your local network, your computer automatically performs an ARP request to find the MAC address, which then gets stored in your ARP cache.
Step 5: Verify the MAC address is now in your cache
You should see:
Address HWtype HWaddress Flags Mask Iface
192.168.64.1 ether 52:54:00:12:35:02 C enp0s1Show the TA that you have the MAC address corresponding to the IP address
TA's Signature: ________________________
🍎 What This Looks Like on Mac:
Before ping:
$ arp -n
? (192.168.1.1) at b8:27:eb:xx:xx:xx on en0Ping a new device:
$ ping -c 2 192.168.1.50After ping:
$ arp -n
? (192.168.1.1) at b8:27:eb:xx:xx:xx on en0
? (192.168.1.50) at a4:83:e7:xx:xx:xx on en0 ← NEW ENTRY!6.4) Find MAC Address of a Particular IP in ARP Cache
Command:
$ arp -a [IPaddress]Purpose: When your ARP cache might list hundreds of IP addresses, this command filters to show only the specific IP you're looking for
For Your VM:
$ arp -a 192.168.64.1Output:
? (192.168.64.1) at 52:54:00:12:35:02 [ether] on enp0s1On Mac:
$ arp -a 192.168.1.1
? (192.168.1.1) at b8:27:eb:xx:xx:xx on en0 ifscope [ethernet]6.5) Find MAC Addresses Connected to a Particular NIC
Command:
$ arp -i [NICname]Purpose: Show only the ARP entries for devices connected through a specific network interface
For Your VM:
$ arp -i enp0s1Output:
Address HWtype HWaddress Flags Mask Iface
192.168.64.1 ether 52:54:00:12:35:02 C enp0s1On Mac:
$ arp -i en0Use case: This is useful when your computer has multiple NICs connected to different networks, and you want to see which devices are on each specific network.
For your VM: Since you only have enp0s1 active, this will show the same result as arp -a. But if you had multiple network adapters (enp0s1, enp0s2), you could filter by each one.
Assignments
Assignment 1 – Record Your NIC Information
Task: Fill in the details of your NIC names, IP addresses, MAC addresses, and manufacturers
🖥️ For Your VM:
Step 1: List all network interfaces:
$ ifconfig -aStep 2: Extract information for each interface:
Your VM's Network Interfaces:
| NIC Name | IP Address | MAC Address | Manufacturer |
|---|---|---|---|
| enp0s1 | 192.168.64.7 | be:52:f6:c8:ab:1c | Red Hat (QEMU/KVM) |
| docker0 | 172.17.0.1 | 62:8e:2a:2c:c8:94 | (locally administered) |
| br-0212e2f637a2 | 172.18.0.1 | 7a:da:b7:c2:0d:a9 | (locally administered) |
| lo | 127.0.0.1 | N/A (loopback) | N/A |
Step 3: Check manufacturers using macvendors.com
How to identify:
enp0s1MAC starting withbe:52:f6- Likely QEMU virtual NICdocker0and bridge MACs - Locally administered (virtual)
Step 4: Show your completed table to a TA
TA's Signature: ________________________
🍎 If You Did This on Mac (for comparison):
$ ifconfig | grep -E "^[a-z]|ether|inet "Mac's Network Interfaces:
| NIC Name | IP Address | MAC Address | Manufacturer |
|---|---|---|---|
| en0 | 192.168.1.123 | a4:83:e7:xx:xx:xx | Apple Inc. |
| en1 | N/A | 82:91:c7:xx:xx:xx | (not active) |
| lo0 | 127.0.0.1 | N/A (loopback) | N/A |
| bridge100 | 192.168.64.1 | 52:54:00:12:35:02 | QEMU (for VMs) |
Assignment 2 – Add More Entities (MAC–IP Addresses) to Your ARP Cache
Task: Add approximately 10 MAC-IP addresses to your ARP cache
🖥️ For Your VM:
Challenge: Your VM is in an isolated network (192.168.64.x), so you might not have 10 devices to ping!
Here's what you can do:
Step 1: Check your current ARP cache:
$ arp -aStep 2: Ping various targets:
Local Network Targets (will appear in ARP):
# Your gateway
$ ping -c 2 192.168.64.1
# Try other possible VMs (if they exist)
$ ping -c 2 192.168.64.2
$ ping -c 2 192.168.64.3
# ... up to .10External Targets (for completeness, but won't appear in ARP):
# These test connectivity but won't add to ARP cache
$ ping -c 2 8.8.8.8 # Google DNS
$ ping -c 2 1.1.1.1 # Cloudflare DNS
$ ping -c 2 google.com # Google
$ ping -c 2 facebook.com # Facebook
$ ping -c 2 youtube.com # YouTubeStep 3: Check your ARP cache:
$ arp -nExpected Result: You might only see 1-3 entries (your gateway and any other VMs), because:
- External IPs (8.8.8.8, google.com) don't appear in ARP - they're not on your local network
- Your VM is in an isolated virtual network
For the Assignment:
- Show your TA what you have in your ARP cache
- Explain that your VM is in a virtual network with limited local devices
- The important thing is understanding the ARP process!
Step 4: Show your ARP cache to a TA
TA's Signature: ________________________
🍎 If You Did This on Mac (much easier):
# Mac is on a real network with more devices!
$ ping -c 1 192.168.1.1 # Router
$ ping -c 1 192.168.1.2 # Device 1
$ ping -c 1 192.168.1.3 # Device 2
# ... continue
$ ping -c 1 192.168.1.10 # Device 9
# Or scan a range:
for i in {1..20}; do ping -c 1 -W 1 192.168.1.$i & done; wait
$ arp -a # Now you'll see many more entries!Tip for Mac: You can ping common network devices like:
- Your router (usually .1 or .254)
- Smart TVs
- Phones
- IoT devices
- Other computers
- Printers
- Game consoles
Assignment 3 – Peer to Peer Connection
Task: Create a direct connection between two computers and test communication
⚠️ Challenge for VM Users:
This assignment is designed for physical lab computers with multiple Ethernet ports. Your VM currently has only one virtual network adapter.
🖥️ Options for VM Setup:
Option A: Add a Second Network Adapter (Recommended for Practice)
Step 1: Shut down your VM:
$ sudo shutdown -h nowStep 2: In your VM software (UTM, VMware, VirtualBox, Parallels):
- Go to VM Settings → Network
- Add a second network adapter
- Set it to "Host-only" or "Internal Network" mode
- Save settings
Step 3: Start your VM
Step 4: Check for the new interface:
$ ifconfig -aYou should now see enp0s2 (or similar)
Step 5: Continue with the assignment below using enp0s2
Option B: Simulate with Your Current Setup
You can practice the commands without a second adapter by using your existing interface, but you won't get a TA signature for this part.
Step 3.1: Physical/Virtual Connection
Action: Work with a partner (or prepare for lab day)
For Lab Computers:
- Connect LAN cable from Computer 1's
eth1to Computer 2'seth1
For Your VM (if you added second adapter):
- Both VMs should have their second adapter (
enp0s2) on the same "Host-only" or "Internal" network
Step 3.2: Configure IP Addresses
Action: Set up IP addresses for direct communication
Computer 1 / VM 1:
$ sudo ifconfig enp0s2 192.168.10.1 netmask 255.255.255.0Computer 2 / VM 2:
$ sudo ifconfig enp0s2 192.168.10.2 netmask 255.255.255.0Verify the configuration:
$ ifconfig enp0s2You should see:
enp0s2: flags=4163<UP,BROADCAST,RUNNING,MULTICAST> mtu 1500
inet 192.168.10.1 netmask 255.255.255.0 broadcast 192.168.10.255
ether xx:xx:xx:xx:xx:xx txqueuelen 1000 (Ethernet)Record the command used:
Command:
sudo ifconfig enp0s2 192.168.10.1 netmask 255.255.255.0Why these IPs?
- We use
192.168.10.xfrom the private IP range- Both computers must be in the same subnet (192.168.10.0/24) to communicate directly
.1and.2are just conventions - you could use any numbers from 2-254
🍎 On Mac (for comparison):
Computer 1:
$ sudo ifconfig en1 192.168.10.1 netmask 255.255.255.0Computer 2:
$ sudo ifconfig en1 192.168.10.2 netmask 255.255.255.0Step 3.3: Check ARP Cache
Action: On each computer, check the ARP cache
$ arp -nYou should see: Only entries from your primary network (enp0s1), NOT the peer-to-peer network yet
If there is no MAC address of the partner computer:
From Computer 1/VM 1:
$ ping -c 4 192.168.10.2From Computer 2/VM 2:
$ ping -c 4 192.168.10.1Expected output:
PING 192.168.10.2 (192.168.10.2) 56(84) bytes of data.
64 bytes from 192.168.10.2: icmp_seq=1 ttl=64 time=0.234 ms
64 bytes from 192.168.10.2: icmp_seq=2 ttl=64 time=0.189 ms
64 bytes from 192.168.10.2: icmp_seq=3 ttl=64 time=0.201 ms
64 bytes from 192.168.10.2: icmp_seq=4 ttl=64 time=0.195 ms
--- 192.168.10.2 ping statistics ---
4 packets transmitted, 4 received, 0% packet loss, time 3056ms
rtt min/avg/max/mdev = 0.189/0.204/0.234/0.025 msNotice:
- Very low latency (< 1ms) because it's a direct connection!
ttl=64means Linux system- 0% packet loss = perfect connection
Step 3.4: Verify and Show to TA
Action: Verify the partner computer's MAC address is now in your ARP cache
$ arp -nYou should see:
Address HWtype HWaddress Flags Mask Iface
192.168.10.2 ether xx:xx:xx:xx:xx:xx C enp0s2Or with more details:
$ arp -i enp0s2Alternative verification:
$ arp -a 192.168.10.2Show your ARP cache to a TA
TA's Signature: ________________________
What you learned: This demonstrates how ARP works in practice. When you pinged the other computer:
- Your computer sent an ARP broadcast: "Who has 192.168.10.2?"
- The other computer replied: "I have 192.168.10.2, my MAC is xx:xx:xx:xx:xx:xx"
- Your computer stored this mapping in the ARP cache
- Your computer used the MAC address to send the actual ping packets
- All of this happened in milliseconds before the first ping!
🖥️ Complete Walkthrough for VM Users:
If you have two VMs running:
Terminal 1 (VM 1):
# Configure IP
$ sudo ifconfig enp0s2 192.168.10.1 netmask 255.255.255.0
# Verify
$ ifconfig enp0s2
# Check ARP before
$ arp -i enp0s2
# Ping VM 2
$ ping -c 4 192.168.10.2
# Check ARP after
$ arp -i enp0s2
# Should see: 192.168.10.2 at [MAC] on enp0s2Terminal 2 (VM 2):
# Configure IP
$ sudo ifconfig enp0s2 192.168.10.2 netmask 255.255.255.0
# Verify
$ ifconfig enp0s2
# Check ARP before
$ arp -i enp0s2
# Wait for VM 1 to ping, then check ARP
$ arp -i enp0s2
# Should see: 192.168.10.1 at [MAC] on enp0s2🍎 Summary: VM vs Mac Command Reference
Quick Command Comparison:
| Task | Your VM (Linux) | Your Mac |
|---|---|---|
| View interfaces | ifconfig | ifconfig |
| Primary interface | enp0s1 | en0 |
| Your IP | 192.168.64.7 | 192.168.1.XXX (varies) |
| Disable interface | sudo ifconfig enp0s1 down | sudo ifconfig en0 down |
| Enable interface | sudo ifconfig enp0s1 up | sudo ifconfig en0 up |
| Set IP | sudo ifconfig enp0s1 [IP] | sudo ifconfig en0 [IP] |
| Ping test | ping 8.8.8.8 | ping 8.8.8.8 |
| View ARP cache | arp -a | arp -a |
| View ARP (numeric) | arp -n | arp -n |
What's Different:
Linux VM:
- Interface names:
enp0s1,enp0s2, etc. - Virtual network: 192.168.64.x
- Docker interfaces present
- Part of VM's isolated network
Mac:
- Interface names:
en0,en1, etc. - Real network: varies (home/office)
- No Docker interfaces (unless installed)
- Part of your actual WiFi/Ethernet network
- Can see more devices in ARP cache
Quiz Answer Sheet
Name and ID: npwitk (Your Student ID)
Part 1: Lab Exercise Completion
When you complete all exercises, show your Lab Sheet to a TA to check this box and sign:
☐ The student has finished all exercises.
TA's Signature: _____________________________
Part 2: Quiz Questions
Instructions:
- Questions 1–4 are multiple-choice questions (1 point each)
- Questions 5–6 are short-answer questions (1 point each)
- Questions 7–8 are explanation questions (2 points each)
| Question | Answer |
|---|---|
| 1 | A B C D |
| 2 | A B C D |
| 3 | A B C D |
| 4 | A B C D |
| 5 | |
| 6 | |
| 7 | |
| 8 | |
| Total Score |
Key Formulas and Concepts Summary
Packet Sizes:
ICMP Packet Structure:
Default ping packet:
Address Formats:
MAC Address:
IPv4 Address:
Your Network Configuration:
VM Network:
Important Commands Summary:
| Command | Purpose | Your VM Example |
|---|---|---|
ifconfig | View active network interfaces | Shows enp0s1, lo |
ifconfig -a | View all network interfaces | Shows all including Docker |
ifconfig enp0s1 | View specific interface | Shows your main adapter |
sudo ifconfig enp0s1 down | Disable interface | ⚠️ Disconnects network |
sudo ifconfig enp0s1 up | Enable interface | Reconnects network |
sudo ifconfig enp0s2 [IP] | Assign IP address | For second adapter |
ping 8.8.8.8 | Test connectivity | Tests internet |
ping -c 4 [IP] | Send 4 packets | ping -c 4 192.168.64.1 |
ping -s [size] [IP] | Set packet size | ping -s 100 8.8.8.8 |
ping -i [interval] [IP] | Set interval | ping -i 2 8.8.8.8 |
arp -a | Show ARP cache with hostnames | Shows 192.168.64.1 |
arp -n | Show ARP cache (numeric) | Faster, no DNS lookup |
arp -a [IP] | Show specific IP | arp -a 192.168.64.1 |
arp -i enp0s1 | Show cache for interface | Only enp0s1 entries |
Quick Reference Cards
ARP Process Flow:
1. Source checks ARP cache for destination IP
↓
2. If NOT found → Send ARP broadcast: "Who has this IP?"
↓
3. All devices on local network receive broadcast
↓
4. Only matching device replies with its MAC (unicast)
↓
5. Source adds MAC-IP mapping to cache
↓
6. Source can now send packets using MAC address
Your VM's Network Flow:
Your VM (192.168.64.7)
↓
├─ enp0s1 (be:52:f6:c8:ab:1c)
↓
VM's Gateway (192.168.64.1)
↓
├─ Mac Host (52:54:00:12:35:02)
↓
Mac's Network Interface
↓
Home Router
↓
Internet
Packet Journey Example:
Source Computer (195.15.16.11)
↓ [MAC changes, IP stays same]
Router 1
↓ [MAC changes, IP stays same]
Router 2
↓ [MAC changes, IP stays same]
Destination Computer (2.17.169.198)
Key Principles:
- IP address = Global identifier (never changes during transmission)
- MAC address = Local identifier (changes at each router/hop)
Study Tips
-
Practice the commands in your actual VM - muscle memory helps!
-
Compare VM and Mac: Run the same command on both and observe differences:
# On VM: $ ifconfig # On Mac (in Terminal): $ ifconfig -
Understand the "why" behind each protocol:
- Why do we need both MAC and IP addresses?
- Why does MAC change but IP doesn't during routing?
-
Draw diagrams of the ARP process to visualize the broadcast/unicast mechanism
-
Memorize key byte sizes:
- MAC address: 6 bytes (48 bits)
- IPv4 address: 4 bytes (32 bits)
- ICMP header: 8 bytes
- IP header: 20 bytes
-
Test yourself: Can you explain to someone else how ARP works without looking at notes?
-
Common mistakes to avoid:
- Using
eth0instead ofenp0s1(wrong interface name for your VM) - Forgetting
sudofor interface configuration commands - Not pressing
CTRL-Cto stop ping (it runs forever!) - Expecting external IPs (8.8.8.8) to appear in ARP cache (they won't!)
- Using
-
Understand your VM's limitations:
- Your VM is in an isolated network (192.168.64.x)
- You won't have as many ARP entries as a real network
- Some assignments may require adding virtual network adapters
-
For lab day preparation:
- Lab computers use
eth0,eth1,eth2OReno1,enp4s0, etc. - Always check interface names with
ifconfigfirst! - Practice on your VM, perform on lab computers
- Lab computers use
Troubleshooting Guide
Problem: Can't ping anything
Solution:
# Check if interface is up
$ ifconfig enp0s1
# If not shown, bring it up
$ sudo ifconfig enp0s1 up
# Check if you have an IP
$ ifconfig enp0s1 | grep inet
# Test connectivity
$ ping 192.168.64.1 # Your gateway
$ ping 8.8.8.8 # Google DNSProblem: No ARP entries showing up
Solution:
# You can only see devices on your LOCAL network
# External IPs (8.8.8.8, google.com) won't appear
# Ping your gateway (this WILL appear in ARP)
$ ping -c 2 192.168.64.1
# Check ARP cache
$ arp -aProblem: "Operation not permitted" when changing interface
Solution:
# You forgot sudo!
$ sudo ifconfig enp0s1 192.168.10.1Problem: Lost network connection after running commands
Solution:
# You probably disabled your main interface
# Bring it back up:
$ sudo ifconfig enp0s1 up
# Or restart networking:
$ sudo systemctl restart networking
# Or restart the VM
$ sudo rebootReferences
- L. Limwiwatkul, ITS352 Lecture/Lab Note, Academic Year 2/2017
- https://www.lmi.net/support/common/dsl-support/ip-addresses
- http://www.homenethowto.com/switching/mac-addresses
- https://vitux.com/linux-ping-command
- https://study-ccna.com/arp
- Cisco ARP Configuration Guide
Good luck with your lab! 🚀
Remember:
- Your VM uses
enp0s1, noteth0 - Your network is
192.168.64.x - Commands are the same on Mac and Linux!
- Practice makes perfect! 💪