Lab 8 - Transport-Layer Protocols

Updated 4 Oct 2026

Section 1: Transport Layer

1.1 Process-to-Process Communications

  • The transport layer is responsible for providing services to the application layer and receives services from the network layer
  • The main duty of a transport-layer protocol is to provide process-to-process communication
  • A process is an application-layer entity (running program) that uses the services of the transport layer
  • The network layer handles host-to-host communication — it can deliver a message only to the destination computer, but NOT to the correct process
  • The transport layer takes over from there: it is responsible for delivering the message to the appropriate process

Analogy: Think of it like a postal service vs. a building receptionist. The post office (network layer) gets the mail to the right building (host). The receptionist (transport layer) then delivers it to the right person (process) inside.


1.2 Addresses

There are three types of addresses used in networking, each operating at a different layer:

LayerAddress TypeRepresentationSizePurpose
Data LinkPhysical / Link AddressMAC Address48 bitsFinds destination host within a LAN
NetworkLogical AddressIP Address32 bitsFinds destination host across different networks
TransportPort AddressPort Number16 bitsFinds the destination program/process on the host

Analogy: IP address = building address, port number = apartment number inside that building. MAC address = street directions used within the local neighborhood.


1.3 Port Numbers

  • The client-server paradigm is a common model for process-to-process communication
    • Client: a process on the local host that needs services
    • Server: a process (usually on a remote host) that provides services
  • Modern OSes are multiprogramming — many processes run concurrently on a host
  • To distinguish between them, each process is identified by a port number
  • In TCP/IP: port numbers are integers from 0 to 65,535 (16-bit)

Port Number Range=0 to 65,535(216−1)\boxed{\text{Port Number Range} = 0 \text{ to } 65{,}535 \quad (2^{16} - 1)}

Port Number Groups

GroupRangeDescription
Well-Known Ports0 – 1,023Reserved for common/popular services (HTTP, FTP, DNS, etc.)
Registered Ports1,024 – 49,151Assigned by IANA to specific applications (e.g., Cisco RADIUS = 1812)
Private / Dynamic Ports49,152 – 65,535Dynamically assigned by the OS when a client initiates a connection

Well-Known Port Table

PortProtocolUDPTCPDescription
7Echo✓✓Echoes back a received datagram
9Discard✓✓Discards any datagram received
11Users✓✓Active users
13Daytime✓✓Returns the date and time
17Quote✓✓Returns a quote of the day
19Chargen✓✓Returns a string of characters
20FTP-data✓File Transfer Protocol (data)
21FTP-21✓File Transfer Protocol (control)
23TELNET✓Terminal Network
25SMTP✓Simple Mail Transfer Protocol
53DNS✓✓Domain Name Service
67DHCP✓✓Dynamic Host Configuration Protocol
69TFTP✓✓Trivial File Transfer Protocol
80HTTP✓HyperText Transfer Protocol
111RPC✓✓Remote Procedure Call
123NTP✓✓Network Time Protocol
161SNMP-server✓Simple Network Management Protocol
162SNMP-client✓Simple Network Management Protocol

Important rule: One IP address cannot have two services on the same port number within the same transport protocol (TCP or UDP).

  • HTTP (TCP 80) + NGINX (TCP 80) = ❌ NOT OK
  • HTTP (TCP 80) + NGINX (TCP 8080) = ✅ OK
  • HTTP (TCP 80) + App (UDP 80) = ✅ OK (different protocol)

1.4 Socket Addresses

  • A transport-layer protocol needs both the IP address and the port number at each end to make a connection
  • The combination of an IP address and a port number is called a socket address

Socket Address=IP Address+Port Number\boxed{\text{Socket Address} = \text{IP Address} + \text{Port Number}}

Example:
200.23.56.8 : 69 → Socket address of a host at IP 200.23.56.8 using port 69

Analogy: Like a full mailing address — IP = city + street, Port = apartment number. Together they uniquely identify one process on one machine.


Section 2: Transport-Layer Protocols

Three protocols exist at the transport layer (this lab covers only UDP and TCP):

  • UDP – User Datagram Protocol
  • TCP – Transmission Control Protocol
  • SCTP – Stream Control Transmission Protocol (not covered in this lab)

2.1 UDP – User Datagram Protocol

  • Connectionless and unreliable transport protocol
  • Does not add much beyond what IP provides, except enabling process-to-process communication

Key Characteristics

  • Suitable for small messages where reliability is not critical
  • Faster than TCP — much less handshaking between sender and receiver
  • No connection establishment or termination phases
  • Each UDP datagram is independent — no relationship between datagrams, even from the same source
  • Datagrams are not numbered

Analogy: UDP is like dropping a postcard in a mailbox. You send it and hope it arrives — no tracking, no confirmation, no guarantee.


2.2 TCP – Transmission Control Protocol

  • Connection-oriented and reliable protocol
  • Requires three phases: connection establishment → data transfer → connection termination

Analogy: TCP is like a phone call — you dial (SYN), the other person picks up (SYN-ACK), you say hello (ACK), you talk (data transfer), then you both say goodbye before hanging up (FIN/ACK).

a) Connection Establishment — Three-Way Handshake

Important rules:

  • A SYN segment cannot carry data, but consumes one sequence number
  • A SYN + ACK segment cannot carry data, but consumes one sequence number
  • An ACK segment (with no data) consumes no sequence number

b) Data Transfer

  • After connection is established, bidirectional data transfer can occur
  • Seq = byte offset of the first byte in this segment
  • Ack = next byte expected from the other side
  • Len = number of data bytes in this segment

c) Connection Termination — Three-Way Handshake (Teardown)

Important rules:

  • A FIN segment consumes one sequence number if it carries no data
  • A FIN + ACK segment consumes only one sequence number if it carries no data
  • An ACK segment cannot carry data and consumes no sequence numbers

Quick Reference: Sequence Number Arithmetic

SegmentConsumes Seq#
SYN✅ +1
SYN + ACK✅ +1
FIN✅ +1
FIN + ACK✅ +1
ACK (no data)❌ 0
Data segment✅ +Len

Next Seq (after SYN or FIN)=Current Seq+1\boxed{\text{Next Seq (after SYN or FIN)} = \text{Current Seq} + 1}

Next Seq (after data)=Current Seq+Len\boxed{\text{Next Seq (after data)} = \text{Current Seq} + \text{Len}}

ACK number sent back=Seq received+Len received(or +1 for SYN/FIN)\boxed{\text{ACK number sent back} = \text{Seq received} + \text{Len received} \quad (\text{or } +1 \text{ for SYN/FIN})}


Quick Reference: TCP vs UDP

FeatureTCPUDP
ConnectionConnection-orientedConnectionless
ReliabilityReliable (ACKs, retransmission)Unreliable
OrderingIn-order deliveryUnordered
SpeedSlower (overhead)Faster
Use casesHTTP, FTP, SMTP, SSHDNS, DHCP, streaming, gaming
Header size20+ bytes8 bytes
Flow controlYesNo
Congestion controlYesNo

🖥️ Linux Command Summary

nc (Netcat) — Option Reference

OptionMeaning
-lListen mode — act as a server
-uUse UDP (default is TCP if omitted)
-vVerbose — show more connection details
-nNo DNS resolution (avoids "temporary failure in name resolution" error)

Wireshark Filter Reference

sudo wireshark    # launch Wireshark
ScenarioFilter String
All UDP from/to client IPip.addr==192.178.18.8 && udp
All UDP from/to server IPip.addr==192.178.18.9 && udp
All TCP from/to client IPip.addr==192.178.18.8 && tcp
All TCP from/to server IPip.addr==192.178.18.9 && tcp
Filter by specific porttcp.port==5000
Combine IP + portip.addr==192.178.18.8 && tcp.port==5000

Tip — Inspect payload: Click a packet → expand the protocol in the middle pane → click Data → the payload bytes are highlighted in the hex pane below.


📋 Step-by-Step Assignment Guides


✅ Assignment 1 — Investigating UDP Mechanisms

Goal: Send the message Test from Client to Server over UDP, capture with Wireshark, and draw the packet exchange diagram.

You need two computers: one as Server (192.178.18.9), one as Client (192.178.18.8). Do both sides in parallel (coordinate with your partner).


🖥️ SERVER Side — Step by Step

Step 1 — Open Terminal 1: Start Wireshark

sudo wireshark
  • Wireshark will open a GUI
  • Select your network interface (e.g., eth0) and click Start capturing

Step 2 — Open Terminal 2: Start the UDP server

nc -luv 5000
  • You should see: Listening on [0.0.0.0] (family 0, port 5000)
  • If you see "temporary failure in name resolution", use instead:
nc -luvn 5000
  • Leave this terminal open and wait for the client to connect

Step 3 — Wait for message

  • When the client sends Test, your terminal will display: XXXXXTest
  • The XXXXX are 5 automatic packets sent by nc before the actual message

Step 4 — Stop the server

Ctrl+C

Step 5 — Analyze Wireshark (Server side)

  • In the Wireshark filter bar, type:
ip.addr==192.178.18.8 && udp
  • Press Enter or click Apply
  • You will see a list of UDP packets coming from the client
  • Click on any packet → in the middle pane click Data → see the message content highlighted in the hex pane
  • You should see 6 packets total: 5 with X, 1 with Test

Step 6 — Show to TA and get signature


💻 CLIENT Side — Step by Step

Step 1 — Open Terminal 1: Start Wireshark

sudo wireshark
  • Select your network interface and start capturing

Step 2 — Open Terminal 2: Connect to the server via UDP

nc -uv 192.178.18.9 5000
  • You should see: Connection to 192.178.18.9 5000 port [udp/*] succeeded!
  • If DNS error: use nc -uvn 192.178.18.9 5000

Step 3 — Send the message

  • Type:
Test
  • Press Enter

Step 4 — Stop the client

Ctrl+C

Step 5 — Analyze Wireshark (Client side)

  • In the Wireshark filter bar, type:
ip.addr==192.178.18.9 && udp
  • You will see the same UDP packets as on the server side

Step 6 — Draw the UDP packet exchange diagram

192.178.18.8 : [client_port]     192.178.18.9 : 5000
      |----X----------------------->|
      |----X----------------------->|
      |----X----------------------->|
      |----X----------------------->|
      |----X----------------------->|
      |----Test------------------->|

(Fill in the actual client port number you see in Wireshark)

Step 7 — Show to TA and get signature ✅

sed


✅ Assignment 2 — Investigating TCP Mechanisms

Goal: Send the message Test from Client to Server over TCP, capture with Wireshark, and draw the full TCP packet exchange diagram including 3-way handshake and termination.


🖥️ SERVER Side — Step by Step

Step 1 — Open Terminal 1: Start Wireshark

sudo wireshark
  • Select interface and start capturing

Step 2 — Open Terminal 2: Start the TCP server

nc -lv 5000
  • You should see: Listening on [0.0.0.0] (family 0, port 5000)
  • If DNS error:
nc -lvn 5000

Step 3 — Wait for the client to connect

  • When the client connects, you will see: Connection from [192.178.18.8] port 5000 [tcp/*] accepted (family 2, sport XXXXX)
  • When the client sends Test, it appears in your terminal

Step 4 — Stop the server

Ctrl+C

Step 5 — Analyze Wireshark (Server side)

  • Apply filter:
ip.addr==192.178.18.8 && tcp
  • You should see 8 packets:
    • Packets 1–3: 3-way handshake (SYN → SYN,ACK → ACK)
    • Packet 4: Data from Client (Test) — labeled as IPA protocol in Wireshark since port 5000 is unrecognized
    • Packet 5: ACK from Server
    • Packets 6–8: Connection termination (FIN,ACK → FIN,ACK → ACK)

Step 6 — Show to TA and get signature


💻 CLIENT Side — Step by Step

Step 1 — Open Terminal 1: Start Wireshark

sudo wireshark
  • Select interface and start capturing

Step 2 — Open Terminal 2: Connect to the server via TCP

nc -v 192.178.18.9 5000
  • You should see: Connection to 192.178.18.9 5000 port [tcp/*] succeeded!
  • If DNS error: nc -vn 192.178.18.9 5000

Step 3 — Send the message

Test

Press Enter

Step 4 — Stop the client

Ctrl+C

Step 5 — Analyze Wireshark (Client side)

  • Apply filter:
ip.addr==192.178.18.9 && tcp
  • You will see the same 8 packets

Step 6 — Draw the TCP packet exchange diagram

192.178.18.8 : 39664          192.178.18.9 : 5000
      |                               |
      |---[SYN], Seq=0, Len=0-------->|  ← Connection
      |<--[SYN,ACK], Seq=0, Ack=1----|    Establishment
      |---[ACK], Seq=1, Ack=1-------->|
      |                               |
      |---Data=Test, Seq=1, Len=5---->|  ← Data Transfer
      |<--[ACK], Seq=1, Ack=6---------|
      |                               |
      |---[FIN,ACK], Seq=6, Ack=1---->|  ← Connection
      |<--[FIN,ACK], Seq=1, Ack=7-----|    Termination
      |---[ACK], Seq=7, Ack=2-------->|

(Use the actual Seq/Ack values from your Wireshark capture)

Step 7 — Show to TA and get signature ✅


✅ Assignment 3 — TCP Mechanisms for Sending Two Packets

Goal: Same as Assignment 2, but send two messages (Test1 and Test2) and draw the updated TCP exchange diagram showing both data segments.


🖥️ SERVER Side — Step by Step

Step 1 — Open Terminal 1: Start Wireshark

sudo wireshark
  • Select interface and start capturing

Step 2 — Open Terminal 2: Start the TCP server

nc -lv 5000

Step 3 — Wait for both messages

  • When the client sends both messages, your terminal will show:
Test1
Test2

Step 4 — Stop the server

Ctrl+C

Step 5 — Analyze Wireshark

  • Apply filter:
ip.addr==192.178.18.8 && tcp
  • You will see up to 10 packets depending on whether TCP batches the two messages:
    • Packets 1–3: 3-way handshake
    • Packet 4: Test1 data (Len=6, because Test1\n = 6 bytes)
    • Packet 5: ACK
    • Packet 6: Test2 data (Len=6)
    • Packet 7: ACK
    • Packets 8–10: Connection termination

Note: TCP may sometimes combine Test1 and Test2 into a single segment if they are sent fast enough. In that case you will see one data packet with Len=12 instead of two separate ones.

Step 6 — Show to TA and get signature


💻 CLIENT Side — Step by Step

Step 1 — Open Terminal 1: Start Wireshark

sudo wireshark

Step 2 — Open Terminal 2: Connect to the server

nc -v 192.178.18.9 5000

Step 3 — Send two messages (one at a time)

  • Type Test1 → press Enter
  • Type Test2 → press Enter

Step 4 — Stop the client

Ctrl+C

Step 5 — Draw the TCP packet exchange diagram

192.178.18.8 : [port]           192.178.18.9 : 5000
      |                               |
      |---[SYN], Seq=0, Len=0-------->|  ← Connection
      |<--[SYN,ACK], Seq=0, Ack=1----|    Establishment
      |---[ACK], Seq=1, Ack=1-------->|
      |                               |
      |---Data=Test1, Seq=1, Len=6--->|  ← Data Transfer
      |<--[ACK], Seq=1, Ack=7---------|    (message 1)
      |                               |
      |---Data=Test2, Seq=7, Len=6--->|  ← Data Transfer
      |<--[ACK], Seq=1, Ack=13--------|    (message 2)
      |                               |
      |---[FIN,ACK], Seq=13, Ack=1--->|  ← Connection
      |<--[FIN,ACK], Seq=1, Ack=14----|    Termination
      |---[ACK], Seq=14, Ack=2------->|

(Fill in actual values from your Wireshark — Seq numbers are shown in the Info column)

Step 6 — Show to TA and get signature ✅


✅ Assignment 4 — Analyzing a Given Wireshark File

Goal: Open the provided .pcap file, answer the 3 questions, and draw the TCP packet exchange diagram.


Step-by-Step Guide

Step 1 — Open the pcap file

  • Open Wireshark:
sudo wireshark
  • Go to File → Open
  • Navigate to the file Lab8_Assign4.pcap (provided by the instructor)
  • Click Open

Step 2 — Apply a TCP filter to see only relevant packets

ip.addr==192.178.18.8 && tcp
  • Press Enter / click Apply

Step 3 — Answer Question 4.1: What is the port number of the Client?

  • Look at any packet sent from 192.178.18.8 (the client)
  • In the Info column or the packet details, find the Source Port

Client port=39668\boxed{\text{Client port} = 39668}

Step 4 — Answer Question 4.2: What is the port number of the Server?

  • Look at any packet sent from 192.178.18.9 (the server)
  • Find the Source Port from the server side (or Destination Port from the client packets)

Server port=5000\boxed{\text{Server port} = 5000}

Step 5 — Identify the phases from the packet list

Packet #DirectionFlagsSeqAckLenPhase
1C → SSYN0—0Establishment
2S → CSYN, ACK010Establishment
3C → SACK110Establishment
4C → SACK1113Data (C→S)
5S → CACK1140Data ACK
6S → CACK11411Data (S→C)
7C → SACK14120Data ACK
8S → CFIN, ACK12140Termination
9C → SFIN, ACK14130Termination
10S → CACK13150Termination

Step 6 — Find the messages inside the data packets

  • Click on packet 4 (first data packet, C → S, Len=13)
  • In the middle pane, expand the TCP layer → click Data
  • In the hex pane at the bottom, you will see the text: How are you?
  • Click on packet 6 (data packet, S → C, Len=11)
  • Repeat the same → you will see: I am fine.

Step 7 — Answer Question 4.3: Draw the TCP packet exchange diagram

192.178.18.8 : 39668                192.178.18.9 : 5000
       |                                     |
       |---[SYN], Seq=0, Len=0------------->|
       |<--[SYN,ACK], Seq=0, Ack=1----------|  Connection
       |---[ACK], Seq=1, Ack=1------------->|  Establishment
       |                                     |
       |---Data="How are you?",              |
       |   Seq=1, Ack=1, Len=13------------>|  Data Transfer (C→S)
       |<--[ACK], Seq=1, Ack=14-------------|
       |                                     |
       |<--Data="I am fine.",                |
       |   Seq=1, Ack=14, Len=11------------|  Data Transfer (S→C)
       |---[ACK], Seq=14, Ack=12----------->|
       |                                     |
       |<--[FIN,ACK], Seq=12, Ack=14--------|
       |---[FIN,ACK], Seq=14, Ack=13------->|  Connection
       |<--[ACK], Seq=13, Ack=15------------|  Termination

Step 8 — Show to TA and get signature ✅


🧪 Quiz Prep — Questions & Answers

Conceptual Questions

Q1. What is the difference between host-to-host and process-to-process communication? Which layer handles each?

  • Host-to-host → handled by the Network Layer (IP) — delivers a packet to the correct destination machine using IP addresses
  • Process-to-process → handled by the Transport Layer (TCP/UDP) — delivers the message to the correct running program using port numbers

Q2. What are the three types of addresses in networking? What layer does each belong to, and what is its size?

AddressLayerSize
MAC AddressData Link48 bits
IP AddressNetwork32 bits
Port NumberTransport16 bits

Q3. What is a socket address? Give an example.

  • The combination of an IP address + a port number
  • Uniquely identifies one specific process on one specific machine
  • Example: 200.23.56.8:80 — IP 200.23.56.8, port 80 (HTTP)
  • A TCP connection requires a socket address on both ends (client socket + server socket)

Q4. What is the port number range for well-known, registered, and dynamic ports?

  • Well-known: 0 – 1,023
  • Registered: 1,024 – 49,151
  • Dynamic / Private: 49,152 – 65,535

Q5. Can two services share the same port on the same IP? Under what conditions?

  • No — if both use the same transport protocol (both TCP, or both UDP)
  • Yes — if they use different protocols (TCP port 80 and UDP port 80 can coexist on the same IP, as they are completely separate port spaces)

UDP Questions

Q6. What does it mean that UDP is connectionless? How does it differ from TCP?

  • There is no connection establishment or termination — no handshake before sending, no goodbye after
  • Each UDP datagram is completely independent; even datagrams from the same source to the same destination have no relationship and are not numbered
  • TCP, by contrast, requires a 3-way handshake before any data is sent, tracks every byte with sequence numbers, and performs a teardown handshake when done

Q7. Why would you use UDP instead of TCP? Give two real-world examples.

  • Use UDP when speed matters more than reliability, or when the application handles its own error recovery
  • Example 1: DNS — small one-shot query/response; retrying at the application level is fast and TCP overhead is unnecessary
  • Example 2: Video/audio streaming — a dropped frame is better tolerated than the delay caused by TCP retransmission

Q8. When using nc to send UDP, what does the client automatically send before your actual message?

  • The nc command automatically sends 5 UDP packets containing the character 'X' before the actual message
  • This is why the server displays XXXXXTest — five X's arrive first, then the word Test

TCP Questions

Q9. Describe the TCP 3-way handshake for connection establishment (step by step with flags).

  1. Client → Server: [SYN], Seq=x — requests connection
  2. Server → Client: [SYN, ACK], Seq=y, Ack=x+1 — acknowledges client SYN and sends own SYN
  3. Client → Server: [ACK], Seq=x+1, Ack=y+1 — acknowledges server SYN; connection is now open

Q10. Describe the TCP 3-way handshake for connection termination.

  1. Active closer → Passive closer: [FIN, ACK], Seq=x — initiates close
  2. Passive closer → Active closer: [FIN, ACK], Seq=y, Ack=x+1 — acknowledges FIN and sends own FIN
  3. Active closer → Passive closer: [ACK], Ack=y+1 — final acknowledgement; connection is now closed

Q11. A SYN segment has Seq=1000. What ACK number should the receiver send back?

ACK=1000+1=1001\boxed{\text{ACK} = 1000 + 1 = 1001}

SYN consumes one sequence number, so the receiver expects the next byte at position 1001.


Q12. Given a data segment with Seq=1, Len=5, what will the receiver's ACK number be?

ACK=1+5=6\boxed{\text{ACK} = 1 + 5 = 6}

The receiver got bytes 1–5, so it expects byte 6 next.


Q13. Does a SYN segment consume a sequence number? What about an ACK-only segment?

  • SYN: ✅ Yes — consumes 1 sequence number (even though it carries no data)
  • SYN+ACK: ✅ Yes — consumes 1 sequence number
  • ACK (no data): ❌ No — consumes 0 sequence numbers

Q14. During connection termination, which side performs the active close and which the passive close?

  • Active close: the side that initiates termination by sending the first [FIN]
  • Passive close: the side that receives the FIN first and responds
  • Either the client or server can be the active closer — whoever sends FIN first

Wireshark / Practical Questions

Q15. What Wireshark filter would you use to see only TCP packets from/to IP 192.178.18.8?

ip.addr==192.178.18.8 && tcp

Q16. In Assignment 4's pcap, what messages were exchanged?

  • Client (192.178.18.8) sent: "How are you?"
  • Server (192.178.18.9) replied: "I am fine."

Q17. In Assignment 4, what port did the client use? What port did the server use?

Client port=39668Server port=5000\boxed{\text{Client port} = 39668 \qquad \text{Server port} = 5000}


Q18. Looking at Wireshark, how do you identify which packets belong to each TCP phase?

PhaseFlags to look for
Connection Establishment[SYN] → [SYN, ACK] → [ACK]
Data Transfer[ACK] with Len > 0, or application-protocol label
Connection Termination[FIN, ACK] → [FIN, ACK] → [ACK]

Port Number Questions

Q19. What port does HTTP, DNS, FTP (control), SMTP, and DHCP use?

ProtocolPortTransport
HTTP80TCP
DNS53UDP + TCP
FTP (control)21TCP
SMTP25TCP
DHCP67UDP

Q20. If a server runs HTTP on TCP port 80, can another app use UDP port 80 on the same IP? Why?

  • Yes — TCP and UDP maintain completely separate port namespaces
  • TCP port 80 and UDP port 80 are different sockets and do not conflict with each other
  • A port number alone does not uniquely identify a socket — it must be combined with the transport protocol (TCP or UDP) and the IP address