Lab 3 - NIC and ARP

Updated 4 Oct 2026

🖥️ Customized for Your VM Setup

Course: ITS352, DES352 - Networking Laboratory
Institution: School of ICT, Sirindhorn International Institute of Technology

Your VM Configuration:

  • Primary Interface: enp0s1 (192.168.64.7)
  • Docker Interfaces: docker0, br-0212e2f637a2 (ignore these for lab)
  • Loopback: lo (127.0.0.1)

🍎 Mac vs 🐧 Linux VM Comparison

AspectYour Linux VMYour Mac
Primary Interfaceenp0s1en0 (WiFi/Ethernet)
Secondary InterfaceWould be enp0s2, enp0s3en1, en2
Loopbacklolo0
IP Address192.168.64.7 (VM network)Different (your home/office network)
Commandifconfigifconfig (works the same!)
Sudo requiredYes for changesYes for changes
Docker interfacesYes (you have them)If Docker Desktop installed

Instructions

  • The attendance will be checked at the beginning of the Lab class
  • You must login to Ubuntu via:
    • Username: student
    • Password: Siit@1992
    • Your VM: Already logged in as npwitk
  • In this lab sheet, the ✔ sign identifies your exercise
    • Some exercises require a TA's signature to check your result
  • When finishing all exercises, show your Lab Sheet to a TA
  • You will have a 20-minute quiz around the end of the Lab class (or when appropriate)
  • You must submit the last page to a TA at the end of the class

Section 1: Network Interface Card (NIC)

What is a NIC?

  • A Network Interface Card/Controller (NIC) is a computer hardware component that allows a computer to connect to a network
  • NICs may be used for both wired and wireless connections
  • In our networking lab, each computer has 3 Ethernet NICs called:
    • Lab computers: eth0, eth1, eth2 OR eno1, enp4s0, etc.
    • Your VM: enp0s1 (and potentially enp0s2, enp0s3 if you add more)
    • Your Mac: en0 (WiFi), en1 (Thunderbolt), etc.
  • You connect a LAN cable to a NIC to connect this computer to a network

Analogy: Think of a NIC as a network "port" on your computer - just like USB ports allow you to connect USB devices, NICs allow you to connect to networks. Each NIC is like having a separate "phone line" that can connect to different networks.

Note: Appendix B in the Lab Manual shows the scheme of the network connection in the networking lab.

[Image of NIC hardware]

🔍 Your Current Setup:

Your Linux VM has these interfaces:

enp0s1          # Your main network interface (connected)
docker0         # Docker bridge network (can ignore)
br-0212e2f637a2 # Another Docker bridge (can ignore)
lo              # Loopback (localhost)

If you run ifconfig on your Mac, you'd see:

en0             # Your WiFi/Ethernet (main connection)
en1             # Thunderbolt/secondary
lo0             # Loopback
bridge0         # If you have VM software

Section 2: Computer Addresses

Each computer occupies three different kinds of addresses:

1. MAC Address (Media Access Control Address)

  • Also known as the hardware address
  • A unique identifier (ID) assigned to an NIC for communications at the data link layer of a network segment
  • Consists of 12 hexadecimal characters (6 bytes)
  • Example format: 02:0a:95:9d:68:16
  • The MAC address of a computer could be fixed (if not changing its NIC)

Your VM's MAC Address:

enp0s1: be:52:f6:c8:ab:1c

Analogy: A MAC address is like the serial number on your laptop - it's permanently assigned to the hardware and uniquely identifies that specific network card. Even if you move to a different building or country, the MAC address stays the same.

2. IP Address (Internet Protocol Address)

  • A logical address (at the network layer) used to uniquely identify every computer/device in the network
  • Because IP addresses are logical, they can change
  • IPv4 format: A series of four numbers separated by dots
  • Example: 192.168.5.11

Your VM's IP Address:

enp0s1: 192.168.64.7

On Mac, it might be:

en0: 192.168.1.XXX  (your home router's network)
# or
en0: 10.0.0.XXX     (common for some routers)

Types of IP Addresses:

Public IP:

  • Assigned by an Internet Service Provider (ISP)
  • Used by routers and computers connected directly to a modem without a router

Private IP:

  • Special IP addresses assigned by a router
  • Known only to a router and its home network
  • Common private IP ranges:
    • 192.168.x.x ← Your VM uses this!
    • 10.x.x.x
    • 172.16.x.x to 172.31.x.x ← Your Docker uses this!

Analogy: If MAC addresses are like permanent serial numbers, IP addresses are like your current mailing address - they can change when you move to a different network, just like your street address changes when you move houses.

Router IP Addresses:

  • Routers are special because they have two IP addresses
  • An IP address is assigned to each of the router's two interfaces:
  1. WAN (Wide Area Network) Interface:
    • The side of the router that faces the Internet
    • Has a public IP address
  2. LAN (Local Area Network) Interface:
    • The side of the router that faces the home network's computers
    • Has a private IP address
    • Your VM's gateway: Likely 192.168.64.1 or 192.168.64.254
    • Your Mac's gateway: Check with netstat -nr | grep default

[Image showing router with WAN and LAN interfaces]

3. Hostname

  • The computer name
  • Created/readable/understandable by people
  • Example: MyComp

Your VM's hostname:

npwitk-linux

Your Mac's hostname:

# Check with: hostname
# Probably something like: npwitk-MacBook-Pro.local

Analogy: A hostname is like a person's name - much easier for humans to remember than a string of numbers. Just as "John's Computer" is easier to remember than 192.168.1.105.


Section 3: Roles of MAC Addresses and IP Addresses

How Packets are Transferred

To transfer a packet from source (computer) to destination (computer), both destination MAC address and IP addressshould be known.

Key Concepts:

  • IP addresses are used to identify the destination globally

    • The destination might be located across the world
    • The packet must be sent across/through many routers
  • MAC addresses are used to identify the address locally

    • Used to relay packets from one router to another router (hop-by-hop)
    • The MAC address is used for local delivery (not the IP address)

Important Behavior:

  • The IP of the destination is fixed throughout the journey
  • The MAC address changes every hop
  • If the destination is in the same network as the source, the packet will be delivered directly to the destination using the MAC address

Analogy: Think of sending a package across the country:

  • The IP address is like the final destination address on the package (e.g., "123 Main St, New York, NY") - this never changes
  • The MAC address is like the delivery truck or plane that carries it for each leg of the journey - it changes at each distribution center, but the final destination stays the same

Example Packet Journey:

[Image showing packet traversal with changing MAC addresses]

Packet Details at Each Hop:

From Source to Router 1:

  • Source IP: 195.15.16.11
  • Destination IP: 2.17.169.198
  • Source MAC: 35:a0:b1:00:57:c2
  • Destination MAC: 01:53:aa:f9:d2:8c

From Router 1 to Router 2:

  • Source IP: 195.15.16.11 (unchanged)
  • Destination IP: 2.17.169.198 (unchanged)
  • Source MAC: 28:18:78:5a:f5:96 (changed)
  • Destination MAC: 35:a0:b1:72:01:19 (changed)

From Router 2 to Computer:

  • Source IP: 195.15.16.11 (unchanged)
  • Destination IP: 2.17.169.198 (unchanged)
  • Source MAC: 00:1f:19:ba:20:39 (changed)
  • Destination MAC: 28:18:78:5a:f4:c7 (changed)

Section 4: Linux Commands - ifconfig to Show/Change Details of Network Interface

What is ifconfig?

The command ifconfig (stands for interface configuration) is used to:

  • View the configuration of network interfaces
  • Change the configuration of network interfaces on your system

4.1) View All Active Network Interfaces

Command:

ifconfig

Purpose: To view information about all network interfaces currently in operation (running)

🖥️ Your VM Output:

npwitk@npwitk-linux:~$ ifconfig
enp0s1: flags=4163<UP,BROADCAST,RUNNING,MULTICAST>  mtu 1500
        inet 192.168.64.7  netmask 255.255.255.0  broadcast 192.168.64.255
        inet6 fd88:82c3:e85b:fd91:bc52:f6ff:fec8:ab1c  prefixlen 64  scopeid 0x0<global>
        inet6 fe80::bc52:f6ff:fec8:ab1c  prefixlen 64  scopeid 0x20<link>
        ether be:52:f6:c8:ab:1c  txqueuelen 1000  (Ethernet)
        RX packets 143  bytes 65090 (65.0 KB)
        RX errors 0  dropped 0  overruns 0  frame 0
        TX packets 133  bytes 20586 (20.5 KB)
        TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0
 
lo: flags=73<UP,LOOPBACK,RUNNING>  mtu 65536
        inet 127.0.0.1  netmask 255.0.0.0
        inet6 ::1  prefixlen 128  scopeid 0x10<host>
        loop  txqueuelen 1000  (Local Loopback)
        RX packets 414  bytes 33213 (33.2 KB)
        RX errors 0  dropped 0  overruns 0  frame 0
        TX packets 414  bytes 33213 (33.2 KB)
        TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0

🍎 Mac Output (for comparison):

# On Mac, you'd see:
en0: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
	options=6463<RXCSUM,TXCSUM,TSO4,TSO6,CHANNEL_IO,PARTIAL_CSUM,ZEROINVERT_CSUM>
	ether a4:83:e7:xx:xx:xx 
	inet6 fe80::1c2f:2aff:fe9b:xxxx%en0 prefixlen 64 secured scopeid 0x4 
	inet 192.168.1.123 netmask 0xffffff00 broadcast 192.168.1.255
	nd6 options=201<PERFORMNUD,DAD>
	media: autoselect
	status: active
 
lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> mtu 16384
	options=1203<RXCSUM,TXCSUM,TXSTATUS,SW_TIMESTAMP>
	inet 127.0.0.1 netmask 0xff000000 
	inet6 ::1 prefixlen 128 
	inet6 fe80::1%lo0 prefixlen 64 scopeid 0x1 
	nd6 options=201<PERFORMNUD,DAD>

Notice the differences:

  • Linux: enp0s1, Mac: en0
  • Linux: More human-readable format
  • Mac: More compact, different flag format
  • Both show: IP, MAC (ether), packets, bytes

Understanding the Output:

ColumnValue (Your VM)Meaning
Interface nameenp0s1Your network interface name
LinkEthernetEthernet frame type
ether (HWaddr)be:52:f6:c8:ab:1cNetwork Hardware address or MAC address
inet192.168.64.7Network Logical Address or IPv4 Address
inet6fd88:82c3:e85b:fd91:...Network Logical Address IPv6 Address (global)
inet6fe80::bc52:f6ff:...IPv6 Link-local Address
broadcast192.168.64.255Broadcast address for your subnet
netmask255.255.255.0Network mask associated with this interface
flagsUP,BROADCAST,RUNNING,MULTICAST• UP: Network interface enabled
• BROADCAST: Able to handle broadcast packet
• RUNNING: Operational and ready to accept and transmit data
• MULTICAST: Able to handle multicast packet
ColumnValueMeaning
MTU1500Maximum transmission unit (bytes)
RX packets143Packets received
RX bytes65090 (65.0 KB)Total bytes received
TX packets133Packets transmitted
TX bytes20586 (20.5 KB)Total bytes transmitted
RX/TX errors0Damaged packets
dropped0Dropped packets due to errors
overruns0Buffer overrun issues
collisions0Number of packet collisions

4.2) View All Network Interfaces (Including Inactive)

Command:

$ ifconfig -a

Purpose: To view the configuration of all network interfaces on the system (not just the ones that are currently active)

Your VM shows:

  • enp0s1 (active)
  • docker0 (inactive but configured)
  • br-0212e2f637a2 (inactive but configured)
  • lo (active loopback)

On Mac, you might see:

  • en0 (WiFi - active)
  • en1 (Thunderbolt - may be inactive)
  • en2 (USB Ethernet - if you have adapter)
  • awdl0 (Apple Wireless Direct Link - for AirDrop)
  • bridge0 (if running VMs)
  • lo0 (loopback)

4.3) View Information of a Specific Network Interface

Command:

$ ifconfig [NICname]

For Your VM:

$ ifconfig enp0s1

For Mac (to compare):

$ ifconfig en0

Lab manual examples (for reference):

$ ifconfig eth0     # Lab computers
$ ifconfig eno1     # Some lab computers

4.4) Disable an Active Interface

Command:

$ sudo ifconfig [NICname] down

For Your VM:

$ sudo ifconfig enp0s1 down

⚠️ WARNING: This will disconnect your VM from the network! You won't be able to browse the internet or ssh until you bring it back up!

For Mac:

$ sudo ifconfig en0 down

⚠️ WARNING: This will disconnect your Mac from WiFi/network!

Note: Enabling or disabling a device requires superuser permissions, so you will either have to be logged in as root or prefix your command with sudo to run it with superuser privileges.

Important: When you disable an interface, it stops all network communication through that NIC. It's like unplugging the network cable.

✔ Activity 4.4:

Step 1: Check current status:

$ ifconfig

Step 2: Look for enp0s1 in the output with UP and RUNNING flags

Question: In the list, do you see the NIC enp0s1 with UP and RUNNING flags?

Answer: YES (you should see it since it's currently active)

For comparison on Mac:

$ ifconfig en0
# Look for: flags=8863<UP,BROADCAST,SMART,RUNNING...>

4.5) Enable an Inactive Interface

Command:

$ sudo ifconfig [NICname] up

For Your VM:

$ sudo ifconfig enp0s1 up

For Mac:

$ sudo ifconfig en0 up

✔ Activity 4.5:

Step 1: After bringing the interface up:

$ ifconfig

Step 2: Verify enp0s1 appears with UP and RUNNING flags

Question: In the list, do you see the NIC enp0s1?

Answer: YES (after running the up command)

4.6) Assign a Static IP Address to an Interface

Command:

$ sudo ifconfig [NICname] [IPaddress]

Lab manual example:

$ sudo ifconfig eth1 192.168.10.50

For Your VM (if you had a second interface):

# If you add a second network adapter, it would be:
$ sudo ifconfig enp0s2 192.168.10.50

For Mac:

$ sudo ifconfig en1 192.168.10.50

⚠️ WARNING: Don't run this on your primary interface (enp0s1 or en0) as it will change your IP and likely disconnect you!

To verify the change:

$ ifconfig enp0s2     # For VM
$ ifconfig en1        # For Mac

✔ Activity 4.6:

NOTE: Since your VM currently only has one active network interface (enp0s1), you have two options:

Option 1 - Add a second network adapter to your VM:

  1. Shut down your VM
  2. In your VM settings, add a second network adapter
  3. Start the VM
  4. The new interface will appear as enp0s2
  5. Then run: sudo ifconfig enp0s2 192.168.10.50

Option 2 - Just record the command you would use:

sudo ifconfig enp0s2 192.168.10.50

Record the IP address assigned:

Answer: 192.168.10.50 (or write that you need to add second adapter first)


Section 5: Testing Network Connectivity by Using the Command ping

What is ping?

  • The command ping (Packet Internet Groper) is a network administration utility used to:
    • Check the connectivity status/quality between a source and destination computer/device over an IP network
    • Assess the time it takes to send and receive a response from the network

How ping Works:

  • Uses the Internet Control Message Protocol (ICMP) to send and receive echo messages
  • Process:
    1. An ICMP request message is sent to the destination computer
    2. If the destination IP address is available, it sends an ICMP response message back to the host computer
    3. This tells us about the connectivity status/quality of the network such as round-trip time (RTT) - the time taken to send and receive a packet

Analogy: Using ping is like shouting "Hello!" in a canyon and waiting for the echo. The echo tells you there's something there, and how long it takes for the echo to return tells you how far away it is. In networking, the "echo" is the response from the destination computer.

5.1) Basic Ping Command

Command:

$ ping [HostName/IPaddress]

To stop: Press CTRL-C

🖥️ Try These on Your VM:

Test 1: Ping yourself (loopback)

$ ping 127.0.0.1
# or
$ ping localhost

Test 2: Ping your VM's gateway (likely the host Mac)

$ ping 192.168.64.1

Test 3: Ping Google's DNS

$ ping 8.8.8.8

Test 4: Ping a website

$ ping google.com

🍎 Same Commands Work on Mac!

$ ping 127.0.0.1      # Ping yourself
$ ping 192.168.1.1    # Ping your router (IP may differ)
$ ping 8.8.8.8        # Ping Google DNS
$ ping google.com     # Ping website

Example Output from Your VM:

npwitk@npwitk-linux:~$ ping 8.8.8.8
PING 8.8.8.8 (8.8.8.8) 56(84) bytes of data.
64 bytes from 8.8.8.8: icmp_seq=1 ttl=117 time=12.4 ms
64 bytes from 8.8.8.8: icmp_seq=2 ttl=117 time=11.8 ms
64 bytes from 8.8.8.8: icmp_seq=3 ttl=117 time=13.2 ms
64 bytes from 8.8.8.8: icmp_seq=4 ttl=117 time=12.1 ms
^C
--- 8.8.8.8 ping statistics ---
4 packets transmitted, 4 received, 0% packet loss, time 3004ms
rtt min/avg/max/mdev = 11.812/12.375/13.201/0.534 ms

Understanding the Output:

  • 56: Default data length (bytes)
  • 84: Message length (bytes) = Header (8 bytes ICMP + 20 bytes IP) + Data
  • 64 bytes: Message length = Default data length (56 bytes) + ICMP header (8 bytes) sent back from destination
  • icmp_seq: Sequence number of the ICMP response message
  • ttl=117: Time To Live - this packet can go through 117 more routers
    • Started at 128 (Windows) or 64 (Linux)
    • Each router decreases it by 1
    • ttl=117 means it went through ~11 routers (128-117=11)
  • time=12.4 ms: Round trip time - took 12.4 milliseconds

Key Point: A lower RTT means faster network connection. If you see timeouts or high RTT values, it indicates network problems.

What good RTT values look like:

  • < 1ms - Same network (e.g., your VM to host Mac)
  • 1-30ms - Excellent (local servers, nearby websites)
  • 30-50ms - Good (most websites)
  • 50-100ms - Acceptable (international connections)
  • > 100ms - Slow (far away servers, network issues)
  • > 300ms - Very slow (satellite, poor connection)

5.2) Increase/Decrease Interval Between Ping Packets

The default time interval between sending each packet is 1 second in Linux.

Command:

$ ping -i [TimeGap] [HostName/IPaddress]
  • You can increase the time interval by setting a value greater than 1
  • You can decrease it by setting a value less than 1

Example: Send ping every 2 seconds

$ ping -i 2 8.8.8.8

Example: Send ping every 0.5 seconds (faster)

$ ping -i 0.5 8.8.8.8

⚠️ Note: Values less than 0.2 seconds require root privileges:

$ sudo ping -i 0.1 8.8.8.8

Works the same on Mac!

5.3) Changing Ping Packet (Data) Size

You can change the packet (data) size through the following command:

Command:

$ ping -s [PacketSize] [HostName/IPaddress]

Example: Send 100-byte data packets

$ ping -s 100 8.8.8.8

Example: Send large packets (1000 bytes)

$ ping -s 1000 8.8.8.8

Output will show:

PING 8.8.8.8 (8.8.8.8) 100(128) bytes of data.
# 100 = data size
# 128 = total size (100 + 8 ICMP + 20 IP headers)

Works the same on Mac!

5.4) Sending a Specific Number of Ping Packets

You can specify the number of ping packets sent to the destination:

Command:

$ ping -c [Number] [HostName/IPaddress]

Example: Send exactly 10 ping packets

$ ping -c 10 8.8.8.8

Example: Send just 4 packets for quick test

$ ping -c 4 google.com

After sending the specified number, ping will automatically stop and show statistics.

Works the same on Mac!

✔ Activity 5.4:

Task: Write a ping command to send 8 ping packets with 60-byte data, every 3 seconds

Solution:

Step 1: Identify the required options:

  • -c 8: Send 8 packets
  • -s 60: 60-byte data size
  • -i 3: 3-second interval

Step 2: Combine the options:

$ ping -c 8 -s 60 -i 3 [IPaddress]

Step 3: Choose a target to ping:

For Your VM - Try these:

# Option 1: Ping Google DNS
$ ping -c 8 -s 60 -i 3 8.8.8.8
 
# Option 2: Ping your gateway
$ ping -c 8 -s 60 -i 3 192.168.64.1
 
# Option 3: Ping a website
$ ping -c 8 -s 60 -i 3 google.com

Complete command:

$ ping -c 8 -s 60 -i 3 8.8.8.8

Expected output:

PING 8.8.8.8 (8.8.8.8) 60(88) bytes of data.
68 bytes from 8.8.8.8: icmp_seq=1 ttl=117 time=12.3 ms
68 bytes from 8.8.8.8: icmp_seq=2 ttl=117 time=11.9 ms
68 bytes from 8.8.8.8: icmp_seq=3 ttl=117 time=12.5 ms
68 bytes from 8.8.8.8: icmp_seq=4 ttl=117 time=12.1 ms
68 bytes from 8.8.8.8: icmp_seq=5 ttl=117 time=13.0 ms
68 bytes from 8.8.8.8: icmp_seq=6 ttl=117 time=12.4 ms
68 bytes from 8.8.8.8: icmp_seq=7 ttl=117 time=11.8 ms
68 bytes from 8.8.8.8: icmp_seq=8 ttl=117 time=12.6 ms
 
--- 8.8.8.8 ping statistics ---
8 packets transmitted, 8 received, 0% packet loss, time 21047ms
rtt min/avg/max/mdev = 11.834/12.325/13.021/0.385 ms

Notice:

  • Takes 24 seconds total (8 packets × 3 seconds = 24 seconds)
  • 60(88) means 60 bytes data + 28 bytes headers
  • 68 bytes received = 60 data + 8 ICMP header

Your Answer:

ping -c 8 -s 60 -i 3 8.8.8.8

Step 4: Execute the command and show the result to a TA

TA's Signature: ________________________


Section 6: Address Resolution Protocol (ARP)

What is ARP?

  • The Address Resolution Protocol (ARP) is a network protocol used to find out the hardware/MAC address of a device from an IP address
  • Used when a device wants to send packets to another device on a local network (e.g., on an Ethernet network that requires physical addresses to be known before sending packets)

How ARP Works:

Process:

  1. Before sending packets, the source device looks in its ARP cache (ARP table that stores a mapping list of MAC and IP addresses) to see if there is a MAC address and corresponding IP address for the destination device

  2. If there is no entry:

    • The source device sends a broadcast message to every device on the network
    • Each device compares the IP address to its own
    • Only the device with the matching IP address replies to the sending device with a packet containing its MAC address (called unicast)
  3. The source device adds the destination device MAC address to its ARP cache for future reference

  4. Now it is able to send the packets to the destination device

Analogy: ARP is like looking up someone's phone number in a directory:

  • You know their name (IP address) but need their phone number (MAC address) to call them
  • You first check your contacts (ARP cache)
  • If not there, you ask everyone in the room "Who has this name?" (broadcast)
  • Only the person with that name responds with their number (unicast reply)
  • You save it in your contacts for next time (add to ARP cache)

[Image showing ARP request/reply process with Host A, B, C, and D]

Using the arp Command

The arp command allows you to display and modify the ARP cache.

6.1) Show Complete ARP Cache (Including Hostname)

Command:

$ arp -a

Purpose: Display all MAC-IP address mappings with hostnames

🖥️ Example Output from Your VM:

npwitk@npwitk-linux:~$ arp -a
? (192.168.64.1) at 52:54:00:12:35:02 [ether] on enp0s1
_gateway (192.168.64.1) at 52:54:00:12:35:02 [ether] on enp0s1

What this shows:

  • 192.168.64.1 - Your gateway (probably your Mac host)
  • 52:54:00:12:35:02 - Gateway's MAC address
  • [ether] - Ethernet type
  • on enp0s1 - Connected via your network interface

🍎 Example Output on Mac:

$ arp -a
? (192.168.1.1) at b8:27:eb:xx:xx:xx on en0 ifscope [ethernet]
? (192.168.1.5) at dc:a6:32:xx:xx:xx on en0 ifscope [ethernet]
? (192.168.64.7) at be:52:f6:c8:ab:1c on bridge100 ifscope [ethernet]

What this shows:

  • 192.168.1.1 - Router
  • 192.168.1.5 - Another device (phone, computer, etc.)
  • 192.168.64.7 - That's YOUR VM! (Mac sees it through bridge)

6.2) Show ARP Cache (Excluding Hostname)

Command:

$ arp -n

Purpose: Display all MAC-IP address mappings without resolving hostnames (faster)

🖥️ Example Output from Your VM:

npwitk@npwitk-linux:~$ arp -n
Address                  HWtype  HWaddress           Flags Mask            Iface
192.168.64.1            ether   52:54:00:12:35:02   C                     enp0s1

Columns explained:

  • Address: IP address
  • HWtype: Hardware type (ethernet)
  • HWaddress: MAC address
  • Flags:
    • C = Complete (entry is complete)
    • M = Permanent (manually added)
    • P = Published (proxy ARP)
  • Iface: Interface name

6.3) Add ARP Entry to ARP Cache

How to add an entry when you know the IP address but not the MAC address:

✔ Activity 6.3:

For Your VM Setup:

Since your VM is in a virtualized network (192.168.64.x), you'll be pinging devices in your VM's network.

Step 1: Identify targets to ping (that are NOT in your ARP cache yet)

Targets you can try:

a) Your Mac host (gateway):

192.168.64.1

b) Google DNS:

8.8.8.8

⚠️ Note: External IPs like 8.8.8.8 won't appear in ARP cache because they're not on your local network!

c) If you have other VMs running:

192.168.64.2, 192.168.64.3, etc.

Step 2: Check your current ARP cache (before pinging):

$ arp -n

Write down what you see: _________________

Step 3: Choose an IP to ping (let's use your gateway):

$ ping -c 4 192.168.64.1

Step 4: Check your ARP cache again:

$ arp -n

Why this works: When you ping a device on your local network, your computer automatically performs an ARP request to find the MAC address, which then gets stored in your ARP cache.

Step 5: Verify the MAC address is now in your cache

You should see:

Address           HWtype  HWaddress           Flags Mask  Iface
192.168.64.1     ether   52:54:00:12:35:02   C           enp0s1

Show the TA that you have the MAC address corresponding to the IP address

TA's Signature: ________________________

🍎 What This Looks Like on Mac:

Before ping:

$ arp -n
? (192.168.1.1) at b8:27:eb:xx:xx:xx on en0

Ping a new device:

$ ping -c 2 192.168.1.50

After ping:

$ arp -n
? (192.168.1.1) at b8:27:eb:xx:xx:xx on en0
? (192.168.1.50) at a4:83:e7:xx:xx:xx on en0  ← NEW ENTRY!

6.4) Find MAC Address of a Particular IP in ARP Cache

Command:

$ arp -a [IPaddress]

Purpose: When your ARP cache might list hundreds of IP addresses, this command filters to show only the specific IP you're looking for

For Your VM:

$ arp -a 192.168.64.1

Output:

? (192.168.64.1) at 52:54:00:12:35:02 [ether] on enp0s1

On Mac:

$ arp -a 192.168.1.1
? (192.168.1.1) at b8:27:eb:xx:xx:xx on en0 ifscope [ethernet]

6.5) Find MAC Addresses Connected to a Particular NIC

Command:

$ arp -i [NICname]

Purpose: Show only the ARP entries for devices connected through a specific network interface

For Your VM:

$ arp -i enp0s1

Output:

Address                  HWtype  HWaddress           Flags Mask            Iface
192.168.64.1            ether   52:54:00:12:35:02   C                     enp0s1

On Mac:

$ arp -i en0

Use case: This is useful when your computer has multiple NICs connected to different networks, and you want to see which devices are on each specific network.

For your VM: Since you only have enp0s1 active, this will show the same result as arp -a. But if you had multiple network adapters (enp0s1, enp0s2), you could filter by each one.


Assignments

Assignment 1 – Record Your NIC Information

Task: Fill in the details of your NIC names, IP addresses, MAC addresses, and manufacturers

🖥️ For Your VM:

Step 1: List all network interfaces:

$ ifconfig -a

Step 2: Extract information for each interface:

Your VM's Network Interfaces:

NIC NameIP AddressMAC AddressManufacturer
enp0s1192.168.64.7be:52:f6:c8:ab:1cRed Hat (QEMU/KVM)
docker0172.17.0.162:8e:2a:2c:c8:94(locally administered)
br-0212e2f637a2172.18.0.17a:da:b7:c2:0d:a9(locally administered)
lo127.0.0.1N/A (loopback)N/A

Step 3: Check manufacturers using macvendors.com

How to identify:

  • enp0s1 MAC starting with be:52:f6 - Likely QEMU virtual NIC
  • docker0 and bridge MACs - Locally administered (virtual)

Step 4: Show your completed table to a TA

TA's Signature: ________________________

🍎 If You Did This on Mac (for comparison):

$ ifconfig | grep -E "^[a-z]|ether|inet "

Mac's Network Interfaces:

NIC NameIP AddressMAC AddressManufacturer
en0192.168.1.123a4:83:e7:xx:xx:xxApple Inc.
en1N/A82:91:c7:xx:xx:xx(not active)
lo0127.0.0.1N/A (loopback)N/A
bridge100192.168.64.152:54:00:12:35:02QEMU (for VMs)

Assignment 2 – Add More Entities (MAC–IP Addresses) to Your ARP Cache

Task: Add approximately 10 MAC-IP addresses to your ARP cache

🖥️ For Your VM:

Challenge: Your VM is in an isolated network (192.168.64.x), so you might not have 10 devices to ping!

Here's what you can do:

Step 1: Check your current ARP cache:

$ arp -a

Step 2: Ping various targets:

Local Network Targets (will appear in ARP):

# Your gateway
$ ping -c 2 192.168.64.1
 
# Try other possible VMs (if they exist)
$ ping -c 2 192.168.64.2
$ ping -c 2 192.168.64.3
# ... up to .10

External Targets (for completeness, but won't appear in ARP):

# These test connectivity but won't add to ARP cache
$ ping -c 2 8.8.8.8          # Google DNS
$ ping -c 2 1.1.1.1          # Cloudflare DNS
$ ping -c 2 google.com       # Google
$ ping -c 2 facebook.com     # Facebook
$ ping -c 2 youtube.com      # YouTube

Step 3: Check your ARP cache:

$ arp -n

Expected Result: You might only see 1-3 entries (your gateway and any other VMs), because:

  • External IPs (8.8.8.8, google.com) don't appear in ARP - they're not on your local network
  • Your VM is in an isolated virtual network

For the Assignment:

  • Show your TA what you have in your ARP cache
  • Explain that your VM is in a virtual network with limited local devices
  • The important thing is understanding the ARP process!

Step 4: Show your ARP cache to a TA

TA's Signature: ________________________

🍎 If You Did This on Mac (much easier):

# Mac is on a real network with more devices!
 
$ ping -c 1 192.168.1.1      # Router
$ ping -c 1 192.168.1.2      # Device 1
$ ping -c 1 192.168.1.3      # Device 2
# ... continue
$ ping -c 1 192.168.1.10     # Device 9
 
# Or scan a range:
for i in {1..20}; do ping -c 1 -W 1 192.168.1.$i & done; wait
 
$ arp -a   # Now you'll see many more entries!

Tip for Mac: You can ping common network devices like:

  • Your router (usually .1 or .254)
  • Smart TVs
  • Phones
  • IoT devices
  • Other computers
  • Printers
  • Game consoles

Assignment 3 – Peer to Peer Connection

Task: Create a direct connection between two computers and test communication

⚠️ Challenge for VM Users:

This assignment is designed for physical lab computers with multiple Ethernet ports. Your VM currently has only one virtual network adapter.

🖥️ Options for VM Setup:

Option A: Add a Second Network Adapter (Recommended for Practice)

Step 1: Shut down your VM:

$ sudo shutdown -h now

Step 2: In your VM software (UTM, VMware, VirtualBox, Parallels):

  • Go to VM Settings → Network
  • Add a second network adapter
  • Set it to "Host-only" or "Internal Network" mode
  • Save settings

Step 3: Start your VM

Step 4: Check for the new interface:

$ ifconfig -a

You should now see enp0s2 (or similar)

Step 5: Continue with the assignment below using enp0s2

Option B: Simulate with Your Current Setup

You can practice the commands without a second adapter by using your existing interface, but you won't get a TA signature for this part.


Step 3.1: Physical/Virtual Connection

Action: Work with a partner (or prepare for lab day)

For Lab Computers:

  • Connect LAN cable from Computer 1's eth1 to Computer 2's eth1

For Your VM (if you added second adapter):

  • Both VMs should have their second adapter (enp0s2) on the same "Host-only" or "Internal" network

Step 3.2: Configure IP Addresses

Action: Set up IP addresses for direct communication

Computer 1 / VM 1:

$ sudo ifconfig enp0s2 192.168.10.1 netmask 255.255.255.0

Computer 2 / VM 2:

$ sudo ifconfig enp0s2 192.168.10.2 netmask 255.255.255.0

Verify the configuration:

$ ifconfig enp0s2

You should see:

enp0s2: flags=4163<UP,BROADCAST,RUNNING,MULTICAST>  mtu 1500
        inet 192.168.10.1  netmask 255.255.255.0  broadcast 192.168.10.255
        ether xx:xx:xx:xx:xx:xx  txqueuelen 1000  (Ethernet)

Record the command used:

Command:

sudo ifconfig enp0s2 192.168.10.1 netmask 255.255.255.0

Why these IPs?

  • We use 192.168.10.x from the private IP range
  • Both computers must be in the same subnet (192.168.10.0/24) to communicate directly
  • .1 and .2 are just conventions - you could use any numbers from 2-254

🍎 On Mac (for comparison):

Computer 1:

$ sudo ifconfig en1 192.168.10.1 netmask 255.255.255.0

Computer 2:

$ sudo ifconfig en1 192.168.10.2 netmask 255.255.255.0

Step 3.3: Check ARP Cache

Action: On each computer, check the ARP cache

$ arp -n

You should see: Only entries from your primary network (enp0s1), NOT the peer-to-peer network yet

If there is no MAC address of the partner computer:

From Computer 1/VM 1:

$ ping -c 4 192.168.10.2

From Computer 2/VM 2:

$ ping -c 4 192.168.10.1

Expected output:

PING 192.168.10.2 (192.168.10.2) 56(84) bytes of data.
64 bytes from 192.168.10.2: icmp_seq=1 ttl=64 time=0.234 ms
64 bytes from 192.168.10.2: icmp_seq=2 ttl=64 time=0.189 ms
64 bytes from 192.168.10.2: icmp_seq=3 ttl=64 time=0.201 ms
64 bytes from 192.168.10.2: icmp_seq=4 ttl=64 time=0.195 ms
 
--- 192.168.10.2 ping statistics ---
4 packets transmitted, 4 received, 0% packet loss, time 3056ms
rtt min/avg/max/mdev = 0.189/0.204/0.234/0.025 ms

Notice:

  • Very low latency (< 1ms) because it's a direct connection!
  • ttl=64 means Linux system
  • 0% packet loss = perfect connection

Step 3.4: Verify and Show to TA

Action: Verify the partner computer's MAC address is now in your ARP cache

$ arp -n

You should see:

Address           HWtype  HWaddress           Flags Mask  Iface
192.168.10.2     ether   xx:xx:xx:xx:xx:xx   C           enp0s2

Or with more details:

$ arp -i enp0s2

Alternative verification:

$ arp -a 192.168.10.2

Show your ARP cache to a TA

TA's Signature: ________________________

What you learned: This demonstrates how ARP works in practice. When you pinged the other computer:

  1. Your computer sent an ARP broadcast: "Who has 192.168.10.2?"
  2. The other computer replied: "I have 192.168.10.2, my MAC is xx:xx:xx:xx:xx:xx"
  3. Your computer stored this mapping in the ARP cache
  4. Your computer used the MAC address to send the actual ping packets
  5. All of this happened in milliseconds before the first ping!

🖥️ Complete Walkthrough for VM Users:

If you have two VMs running:

Terminal 1 (VM 1):

# Configure IP
$ sudo ifconfig enp0s2 192.168.10.1 netmask 255.255.255.0
 
# Verify
$ ifconfig enp0s2
 
# Check ARP before
$ arp -i enp0s2
 
# Ping VM 2
$ ping -c 4 192.168.10.2
 
# Check ARP after
$ arp -i enp0s2
# Should see: 192.168.10.2 at [MAC] on enp0s2

Terminal 2 (VM 2):

# Configure IP
$ sudo ifconfig enp0s2 192.168.10.2 netmask 255.255.255.0
 
# Verify
$ ifconfig enp0s2
 
# Check ARP before
$ arp -i enp0s2
 
# Wait for VM 1 to ping, then check ARP
$ arp -i enp0s2
# Should see: 192.168.10.1 at [MAC] on enp0s2

🍎 Summary: VM vs Mac Command Reference

Quick Command Comparison:

TaskYour VM (Linux)Your Mac
View interfacesifconfigifconfig
Primary interfaceenp0s1en0
Your IP192.168.64.7192.168.1.XXX (varies)
Disable interfacesudo ifconfig enp0s1 downsudo ifconfig en0 down
Enable interfacesudo ifconfig enp0s1 upsudo ifconfig en0 up
Set IPsudo ifconfig enp0s1 [IP]sudo ifconfig en0 [IP]
Ping testping 8.8.8.8ping 8.8.8.8
View ARP cachearp -aarp -a
View ARP (numeric)arp -narp -n

What's Different:

Linux VM:

  • Interface names: enp0s1, enp0s2, etc.
  • Virtual network: 192.168.64.x
  • Docker interfaces present
  • Part of VM's isolated network

Mac:

  • Interface names: en0, en1, etc.
  • Real network: varies (home/office)
  • No Docker interfaces (unless installed)
  • Part of your actual WiFi/Ethernet network
  • Can see more devices in ARP cache

Quiz Answer Sheet

Name and ID: npwitk (Your Student ID)

Part 1: Lab Exercise Completion

When you complete all exercises, show your Lab Sheet to a TA to check this box and sign:

☐ The student has finished all exercises.

TA's Signature: _____________________________

Part 2: Quiz Questions

Instructions:

  • Questions 1–4 are multiple-choice questions (1 point each)
  • Questions 5–6 are short-answer questions (1 point each)
  • Questions 7–8 are explanation questions (2 points each)
QuestionAnswer
1A B C D
2A B C D
3A B C D
4A B C D
5
6
7
8
Total Score

Key Formulas and Concepts Summary

Packet Sizes:

ICMP Packet Structure: Total Size=IP Header (20 bytes)+ICMP Header (8 bytes)+Data\boxed{\text{Total Size} = \text{IP Header (20 bytes)} + \text{ICMP Header (8 bytes)} + \text{Data}}

Default ping packet: 84 bytes=20+8+56\boxed{84 \text{ bytes} = 20 + 8 + 56}

Address Formats:

MAC Address: Format: XX:XX:XX:XX:XX:XX (12 hex digits = 6 bytes)\boxed{\text{Format: } XX:XX:XX:XX:XX:XX \text{ (12 hex digits = 6 bytes)}}

IPv4 Address: Format: X.X.X.X (4 decimal numbers, 0-255)\boxed{\text{Format: } X.X.X.X \text{ (4 decimal numbers, 0-255)}}

Your Network Configuration:

VM Network: VM IP: 192.168.64.7/24\boxed{\text{VM IP: } 192.168.64.7 / 24} Gateway: 192.168.64.1\boxed{\text{Gateway: } 192.168.64.1} Interface: enp0s1\boxed{\text{Interface: } \texttt{enp0s1}}

Important Commands Summary:

CommandPurposeYour VM Example
ifconfigView active network interfacesShows enp0s1, lo
ifconfig -aView all network interfacesShows all including Docker
ifconfig enp0s1View specific interfaceShows your main adapter
sudo ifconfig enp0s1 downDisable interface⚠️ Disconnects network
sudo ifconfig enp0s1 upEnable interfaceReconnects network
sudo ifconfig enp0s2 [IP]Assign IP addressFor second adapter
ping 8.8.8.8Test connectivityTests internet
ping -c 4 [IP]Send 4 packetsping -c 4 192.168.64.1
ping -s [size] [IP]Set packet sizeping -s 100 8.8.8.8
ping -i [interval] [IP]Set intervalping -i 2 8.8.8.8
arp -aShow ARP cache with hostnamesShows 192.168.64.1
arp -nShow ARP cache (numeric)Faster, no DNS lookup
arp -a [IP]Show specific IParp -a 192.168.64.1
arp -i enp0s1Show cache for interfaceOnly enp0s1 entries

Quick Reference Cards

ARP Process Flow:

1. Source checks ARP cache for destination IP
   ↓
2. If NOT found → Send ARP broadcast: "Who has this IP?"
   ↓
3. All devices on local network receive broadcast
   ↓
4. Only matching device replies with its MAC (unicast)
   ↓
5. Source adds MAC-IP mapping to cache
   ↓
6. Source can now send packets using MAC address

Your VM's Network Flow:

Your VM (192.168.64.7)
    ↓
    ├─ enp0s1 (be:52:f6:c8:ab:1c)
    ↓
VM's Gateway (192.168.64.1)
    ↓
    ├─ Mac Host (52:54:00:12:35:02)
    ↓
Mac's Network Interface
    ↓
Home Router
    ↓
Internet

Packet Journey Example:

Source Computer (195.15.16.11)
    ↓ [MAC changes, IP stays same]
Router 1
    ↓ [MAC changes, IP stays same]
Router 2
    ↓ [MAC changes, IP stays same]
Destination Computer (2.17.169.198)

Key Principles:

  • IP address = Global identifier (never changes during transmission)
  • MAC address = Local identifier (changes at each router/hop)

Study Tips

  1. Practice the commands in your actual VM - muscle memory helps!

  2. Compare VM and Mac: Run the same command on both and observe differences:

    # On VM:
    $ ifconfig
     
    # On Mac (in Terminal):
    $ ifconfig
  3. Understand the "why" behind each protocol:

    • Why do we need both MAC and IP addresses?
    • Why does MAC change but IP doesn't during routing?
  4. Draw diagrams of the ARP process to visualize the broadcast/unicast mechanism

  5. Memorize key byte sizes:

    • MAC address: 6 bytes (48 bits)
    • IPv4 address: 4 bytes (32 bits)
    • ICMP header: 8 bytes
    • IP header: 20 bytes
  6. Test yourself: Can you explain to someone else how ARP works without looking at notes?

  7. Common mistakes to avoid:

    • Using eth0 instead of enp0s1 (wrong interface name for your VM)
    • Forgetting sudo for interface configuration commands
    • Not pressing CTRL-C to stop ping (it runs forever!)
    • Expecting external IPs (8.8.8.8) to appear in ARP cache (they won't!)
  8. Understand your VM's limitations:

    • Your VM is in an isolated network (192.168.64.x)
    • You won't have as many ARP entries as a real network
    • Some assignments may require adding virtual network adapters
  9. For lab day preparation:

    • Lab computers use eth0, eth1, eth2 OR eno1, enp4s0, etc.
    • Always check interface names with ifconfig first!
    • Practice on your VM, perform on lab computers

Troubleshooting Guide

Problem: Can't ping anything

Solution:

# Check if interface is up
$ ifconfig enp0s1
 
# If not shown, bring it up
$ sudo ifconfig enp0s1 up
 
# Check if you have an IP
$ ifconfig enp0s1 | grep inet
 
# Test connectivity
$ ping 192.168.64.1  # Your gateway
$ ping 8.8.8.8       # Google DNS

Problem: No ARP entries showing up

Solution:

# You can only see devices on your LOCAL network
# External IPs (8.8.8.8, google.com) won't appear
 
# Ping your gateway (this WILL appear in ARP)
$ ping -c 2 192.168.64.1
 
# Check ARP cache
$ arp -a

Problem: "Operation not permitted" when changing interface

Solution:

# You forgot sudo!
$ sudo ifconfig enp0s1 192.168.10.1

Problem: Lost network connection after running commands

Solution:

# You probably disabled your main interface
# Bring it back up:
$ sudo ifconfig enp0s1 up
 
# Or restart networking:
$ sudo systemctl restart networking
 
# Or restart the VM
$ sudo reboot

References


Good luck with your lab! 🚀

Remember:

  • Your VM uses enp0s1, not eth0
  • Your network is 192.168.64.x
  • Commands are the same on Mac and Linux!
  • Practice makes perfect! 💪