Section 1: Transport Layer
1.1 Process-to-Process Communications
- The transport layer is responsible for providing services to the application layer and receives services from the network layer
- The main duty of a transport-layer protocol is to provide process-to-process communication
- A process is an application-layer entity (running program) that uses the services of the transport layer
- The network layer handles host-to-host communication — it can deliver a message only to the destination computer, but NOT to the correct process
- The transport layer takes over from there: it is responsible for delivering the message to the appropriate process
Analogy: Think of it like a postal service vs. a building receptionist. The post office (network layer) gets the mail to the right building (host). The receptionist (transport layer) then delivers it to the right person (process) inside.
1.2 Addresses
There are three types of addresses used in networking, each operating at a different layer:
| Layer | Address Type | Representation | Size | Purpose |
|---|---|---|---|---|
| Data Link | Physical / Link Address | MAC Address | 48 bits | Finds destination host within a LAN |
| Network | Logical Address | IP Address | 32 bits | Finds destination host across different networks |
| Transport | Port Address | Port Number | 16 bits | Finds the destination program/process on the host |
Analogy: IP address = building address, port number = apartment number inside that building. MAC address = street directions used within the local neighborhood.
1.3 Port Numbers
- The client-server paradigm is a common model for process-to-process communication
- Client: a process on the local host that needs services
- Server: a process (usually on a remote host) that provides services
- Modern OSes are multiprogramming — many processes run concurrently on a host
- To distinguish between them, each process is identified by a port number
- In TCP/IP: port numbers are integers from 0 to 65,535 (16-bit)
Port Number Groups
| Group | Range | Description |
|---|---|---|
| Well-Known Ports | 0 – 1,023 | Reserved for common/popular services (HTTP, FTP, DNS, etc.) |
| Registered Ports | 1,024 – 49,151 | Assigned by IANA to specific applications (e.g., Cisco RADIUS = 1812) |
| Private / Dynamic Ports | 49,152 – 65,535 | Dynamically assigned by the OS when a client initiates a connection |
Well-Known Port Table
| Port | Protocol | UDP | TCP | Description |
|---|---|---|---|---|
| 7 | Echo | ✓ | ✓ | Echoes back a received datagram |
| 9 | Discard | ✓ | ✓ | Discards any datagram received |
| 11 | Users | ✓ | ✓ | Active users |
| 13 | Daytime | ✓ | ✓ | Returns the date and time |
| 17 | Quote | ✓ | ✓ | Returns a quote of the day |
| 19 | Chargen | ✓ | ✓ | Returns a string of characters |
| 20 | FTP-data | ✓ | File Transfer Protocol (data) | |
| 21 | FTP-21 | ✓ | File Transfer Protocol (control) | |
| 23 | TELNET | ✓ | Terminal Network | |
| 25 | SMTP | ✓ | Simple Mail Transfer Protocol | |
| 53 | DNS | ✓ | ✓ | Domain Name Service |
| 67 | DHCP | ✓ | ✓ | Dynamic Host Configuration Protocol |
| 69 | TFTP | ✓ | ✓ | Trivial File Transfer Protocol |
| 80 | HTTP | ✓ | HyperText Transfer Protocol | |
| 111 | RPC | ✓ | ✓ | Remote Procedure Call |
| 123 | NTP | ✓ | ✓ | Network Time Protocol |
| 161 | SNMP-server | ✓ | Simple Network Management Protocol | |
| 162 | SNMP-client | ✓ | Simple Network Management Protocol |
Important rule: One IP address cannot have two services on the same port number within the same transport protocol (TCP or UDP).
- HTTP (TCP 80) + NGINX (TCP 80) = ❌ NOT OK
- HTTP (TCP 80) + NGINX (TCP 8080) = ✅ OK
- HTTP (TCP 80) + App (UDP 80) = ✅ OK (different protocol)
1.4 Socket Addresses
- A transport-layer protocol needs both the IP address and the port number at each end to make a connection
- The combination of an IP address and a port number is called a socket address
Example:
200.23.56.8 : 69 → Socket address of a host at IP 200.23.56.8 using port 69
Analogy: Like a full mailing address — IP = city + street, Port = apartment number. Together they uniquely identify one process on one machine.
Section 2: Transport-Layer Protocols
Three protocols exist at the transport layer (this lab covers only UDP and TCP):
- UDP – User Datagram Protocol
- TCP – Transmission Control Protocol
- SCTP – Stream Control Transmission Protocol (not covered in this lab)
2.1 UDP – User Datagram Protocol
- Connectionless and unreliable transport protocol
- Does not add much beyond what IP provides, except enabling process-to-process communication
Key Characteristics
- Suitable for small messages where reliability is not critical
- Faster than TCP — much less handshaking between sender and receiver
- No connection establishment or termination phases
- Each UDP datagram is independent — no relationship between datagrams, even from the same source
- Datagrams are not numbered
Analogy: UDP is like dropping a postcard in a mailbox. You send it and hope it arrives — no tracking, no confirmation, no guarantee.
2.2 TCP – Transmission Control Protocol
- Connection-oriented and reliable protocol
- Requires three phases: connection establishment → data transfer → connection termination
Analogy: TCP is like a phone call — you dial (SYN), the other person picks up (SYN-ACK), you say hello (ACK), you talk (data transfer), then you both say goodbye before hanging up (FIN/ACK).
a) Connection Establishment — Three-Way Handshake
Important rules:
- A SYN segment cannot carry data, but consumes one sequence number
- A SYN + ACK segment cannot carry data, but consumes one sequence number
- An ACK segment (with no data) consumes no sequence number
b) Data Transfer
- After connection is established, bidirectional data transfer can occur
Seq= byte offset of the first byte in this segmentAck= next byte expected from the other sideLen= number of data bytes in this segment
c) Connection Termination — Three-Way Handshake (Teardown)
Important rules:
- A FIN segment consumes one sequence number if it carries no data
- A FIN + ACK segment consumes only one sequence number if it carries no data
- An ACK segment cannot carry data and consumes no sequence numbers
Quick Reference: Sequence Number Arithmetic
| Segment | Consumes Seq# |
|---|---|
| SYN | ✅ +1 |
| SYN + ACK | ✅ +1 |
| FIN | ✅ +1 |
| FIN + ACK | ✅ +1 |
| ACK (no data) | ❌ 0 |
| Data segment | ✅ +Len |
Quick Reference: TCP vs UDP
| Feature | TCP | UDP |
|---|---|---|
| Connection | Connection-oriented | Connectionless |
| Reliability | Reliable (ACKs, retransmission) | Unreliable |
| Ordering | In-order delivery | Unordered |
| Speed | Slower (overhead) | Faster |
| Use cases | HTTP, FTP, SMTP, SSH | DNS, DHCP, streaming, gaming |
| Header size | 20+ bytes | 8 bytes |
| Flow control | Yes | No |
| Congestion control | Yes | No |
🖥️ Linux Command Summary
nc (Netcat) — Option Reference
| Option | Meaning |
|---|---|
-l | Listen mode — act as a server |
-u | Use UDP (default is TCP if omitted) |
-v | Verbose — show more connection details |
-n | No DNS resolution (avoids "temporary failure in name resolution" error) |
Wireshark Filter Reference
sudo wireshark # launch Wireshark| Scenario | Filter String |
|---|---|
| All UDP from/to client IP | ip.addr==192.178.18.8 && udp |
| All UDP from/to server IP | ip.addr==192.178.18.9 && udp |
| All TCP from/to client IP | ip.addr==192.178.18.8 && tcp |
| All TCP from/to server IP | ip.addr==192.178.18.9 && tcp |
| Filter by specific port | tcp.port==5000 |
| Combine IP + port | ip.addr==192.178.18.8 && tcp.port==5000 |
Tip — Inspect payload: Click a packet → expand the protocol in the middle pane → click Data → the payload bytes are highlighted in the hex pane below.
📋 Step-by-Step Assignment Guides
✅ Assignment 1 — Investigating UDP Mechanisms
Goal: Send the message Test from Client to Server over UDP, capture with Wireshark, and draw the packet exchange diagram.
You need two computers: one as Server (
192.178.18.9), one as Client (192.178.18.8). Do both sides in parallel (coordinate with your partner).
🖥️ SERVER Side — Step by Step
Step 1 — Open Terminal 1: Start Wireshark
sudo wireshark- Wireshark will open a GUI
- Select your network interface (e.g.,
eth0) and click Start capturing
Step 2 — Open Terminal 2: Start the UDP server
nc -luv 5000- You should see:
Listening on [0.0.0.0] (family 0, port 5000) - If you see "temporary failure in name resolution", use instead:
nc -luvn 5000- Leave this terminal open and wait for the client to connect
Step 3 — Wait for message
- When the client sends
Test, your terminal will display:XXXXXTest - The
XXXXXare 5 automatic packets sent byncbefore the actual message
Step 4 — Stop the server
Ctrl+CStep 5 — Analyze Wireshark (Server side)
- In the Wireshark filter bar, type:
ip.addr==192.178.18.8 && udp
- Press Enter or click Apply
- You will see a list of UDP packets coming from the client
- Click on any packet → in the middle pane click Data → see the message content highlighted in the hex pane
- You should see 6 packets total: 5 with
X, 1 withTest
Step 6 — Show to TA and get signature
💻 CLIENT Side — Step by Step
Step 1 — Open Terminal 1: Start Wireshark
sudo wireshark- Select your network interface and start capturing
Step 2 — Open Terminal 2: Connect to the server via UDP
nc -uv 192.178.18.9 5000- You should see:
Connection to 192.178.18.9 5000 port [udp/*] succeeded! - If DNS error: use
nc -uvn 192.178.18.9 5000
Step 3 — Send the message
- Type:
Test
- Press Enter
Step 4 — Stop the client
Ctrl+CStep 5 — Analyze Wireshark (Client side)
- In the Wireshark filter bar, type:
ip.addr==192.178.18.9 && udp
- You will see the same UDP packets as on the server side
Step 6 — Draw the UDP packet exchange diagram
192.178.18.8 : [client_port] 192.178.18.9 : 5000
|----X----------------------->|
|----X----------------------->|
|----X----------------------->|
|----X----------------------->|
|----X----------------------->|
|----Test------------------->|
(Fill in the actual client port number you see in Wireshark)
Step 7 — Show to TA and get signature ✅
sed
✅ Assignment 2 — Investigating TCP Mechanisms
Goal: Send the message Test from Client to Server over TCP, capture with Wireshark, and draw the full TCP packet exchange diagram including 3-way handshake and termination.
🖥️ SERVER Side — Step by Step
Step 1 — Open Terminal 1: Start Wireshark
sudo wireshark- Select interface and start capturing
Step 2 — Open Terminal 2: Start the TCP server
nc -lv 5000- You should see:
Listening on [0.0.0.0] (family 0, port 5000) - If DNS error:
nc -lvn 5000Step 3 — Wait for the client to connect
- When the client connects, you will see:
Connection from [192.178.18.8] port 5000 [tcp/*] accepted (family 2, sport XXXXX) - When the client sends
Test, it appears in your terminal
Step 4 — Stop the server
Ctrl+CStep 5 — Analyze Wireshark (Server side)
- Apply filter:
ip.addr==192.178.18.8 && tcp
- You should see 8 packets:
- Packets 1–3: 3-way handshake (
SYN→SYN,ACK→ACK) - Packet 4: Data from Client (
Test) — labeled as IPA protocol in Wireshark since port 5000 is unrecognized - Packet 5: ACK from Server
- Packets 6–8: Connection termination (
FIN,ACK→FIN,ACK→ACK)
- Packets 1–3: 3-way handshake (
Step 6 — Show to TA and get signature
💻 CLIENT Side — Step by Step
Step 1 — Open Terminal 1: Start Wireshark
sudo wireshark- Select interface and start capturing
Step 2 — Open Terminal 2: Connect to the server via TCP
nc -v 192.178.18.9 5000- You should see:
Connection to 192.178.18.9 5000 port [tcp/*] succeeded! - If DNS error:
nc -vn 192.178.18.9 5000
Step 3 — Send the message
Test
Press Enter
Step 4 — Stop the client
Ctrl+CStep 5 — Analyze Wireshark (Client side)
- Apply filter:
ip.addr==192.178.18.9 && tcp
- You will see the same 8 packets
Step 6 — Draw the TCP packet exchange diagram
192.178.18.8 : 39664 192.178.18.9 : 5000
| |
|---[SYN], Seq=0, Len=0-------->| ← Connection
|<--[SYN,ACK], Seq=0, Ack=1----| Establishment
|---[ACK], Seq=1, Ack=1-------->|
| |
|---Data=Test, Seq=1, Len=5---->| ← Data Transfer
|<--[ACK], Seq=1, Ack=6---------|
| |
|---[FIN,ACK], Seq=6, Ack=1---->| ← Connection
|<--[FIN,ACK], Seq=1, Ack=7-----| Termination
|---[ACK], Seq=7, Ack=2-------->|
(Use the actual Seq/Ack values from your Wireshark capture)
Step 7 — Show to TA and get signature ✅
✅ Assignment 3 — TCP Mechanisms for Sending Two Packets
Goal: Same as Assignment 2, but send two messages (Test1 and Test2) and draw the updated TCP exchange diagram showing both data segments.
🖥️ SERVER Side — Step by Step
Step 1 — Open Terminal 1: Start Wireshark
sudo wireshark- Select interface and start capturing
Step 2 — Open Terminal 2: Start the TCP server
nc -lv 5000Step 3 — Wait for both messages
- When the client sends both messages, your terminal will show:
Test1
Test2
Step 4 — Stop the server
Ctrl+CStep 5 — Analyze Wireshark
- Apply filter:
ip.addr==192.178.18.8 && tcp
- You will see up to 10 packets depending on whether TCP batches the two messages:
- Packets 1–3: 3-way handshake
- Packet 4:
Test1data (Len=6, becauseTest1\n= 6 bytes) - Packet 5: ACK
- Packet 6:
Test2data (Len=6) - Packet 7: ACK
- Packets 8–10: Connection termination
Note: TCP may sometimes combine
Test1andTest2into a single segment if they are sent fast enough. In that case you will see one data packet with Len=12 instead of two separate ones.
Step 6 — Show to TA and get signature
💻 CLIENT Side — Step by Step
Step 1 — Open Terminal 1: Start Wireshark
sudo wiresharkStep 2 — Open Terminal 2: Connect to the server
nc -v 192.178.18.9 5000Step 3 — Send two messages (one at a time)
- Type
Test1→ press Enter - Type
Test2→ press Enter
Step 4 — Stop the client
Ctrl+CStep 5 — Draw the TCP packet exchange diagram
192.178.18.8 : [port] 192.178.18.9 : 5000
| |
|---[SYN], Seq=0, Len=0-------->| ← Connection
|<--[SYN,ACK], Seq=0, Ack=1----| Establishment
|---[ACK], Seq=1, Ack=1-------->|
| |
|---Data=Test1, Seq=1, Len=6--->| ← Data Transfer
|<--[ACK], Seq=1, Ack=7---------| (message 1)
| |
|---Data=Test2, Seq=7, Len=6--->| ← Data Transfer
|<--[ACK], Seq=1, Ack=13--------| (message 2)
| |
|---[FIN,ACK], Seq=13, Ack=1--->| ← Connection
|<--[FIN,ACK], Seq=1, Ack=14----| Termination
|---[ACK], Seq=14, Ack=2------->|
(Fill in actual values from your Wireshark — Seq numbers are shown in the Info column)
Step 6 — Show to TA and get signature ✅
✅ Assignment 4 — Analyzing a Given Wireshark File
Goal: Open the provided .pcap file, answer the 3 questions, and draw the TCP packet exchange diagram.
Step-by-Step Guide
Step 1 — Open the pcap file
- Open Wireshark:
sudo wireshark- Go to File → Open
- Navigate to the file
Lab8_Assign4.pcap(provided by the instructor) - Click Open
Step 2 — Apply a TCP filter to see only relevant packets
ip.addr==192.178.18.8 && tcp
- Press Enter / click Apply
Step 3 — Answer Question 4.1: What is the port number of the Client?
- Look at any packet sent from
192.178.18.8(the client) - In the Info column or the packet details, find the Source Port
Step 4 — Answer Question 4.2: What is the port number of the Server?
- Look at any packet sent from
192.178.18.9(the server) - Find the Source Port from the server side (or Destination Port from the client packets)
Step 5 — Identify the phases from the packet list
| Packet # | Direction | Flags | Seq | Ack | Len | Phase |
|---|---|---|---|---|---|---|
| 1 | C → S | SYN | 0 | — | 0 | Establishment |
| 2 | S → C | SYN, ACK | 0 | 1 | 0 | Establishment |
| 3 | C → S | ACK | 1 | 1 | 0 | Establishment |
| 4 | C → S | ACK | 1 | 1 | 13 | Data (C→S) |
| 5 | S → C | ACK | 1 | 14 | 0 | Data ACK |
| 6 | S → C | ACK | 1 | 14 | 11 | Data (S→C) |
| 7 | C → S | ACK | 14 | 12 | 0 | Data ACK |
| 8 | S → C | FIN, ACK | 12 | 14 | 0 | Termination |
| 9 | C → S | FIN, ACK | 14 | 13 | 0 | Termination |
| 10 | S → C | ACK | 13 | 15 | 0 | Termination |
Step 6 — Find the messages inside the data packets
- Click on packet 4 (first data packet, C → S, Len=13)
- In the middle pane, expand the TCP layer → click Data
- In the hex pane at the bottom, you will see the text:
How are you? - Click on packet 6 (data packet, S → C, Len=11)
- Repeat the same → you will see:
I am fine.
Step 7 — Answer Question 4.3: Draw the TCP packet exchange diagram
192.178.18.8 : 39668 192.178.18.9 : 5000
| |
|---[SYN], Seq=0, Len=0------------->|
|<--[SYN,ACK], Seq=0, Ack=1----------| Connection
|---[ACK], Seq=1, Ack=1------------->| Establishment
| |
|---Data="How are you?", |
| Seq=1, Ack=1, Len=13------------>| Data Transfer (C→S)
|<--[ACK], Seq=1, Ack=14-------------|
| |
|<--Data="I am fine.", |
| Seq=1, Ack=14, Len=11------------| Data Transfer (S→C)
|---[ACK], Seq=14, Ack=12----------->|
| |
|<--[FIN,ACK], Seq=12, Ack=14--------|
|---[FIN,ACK], Seq=14, Ack=13------->| Connection
|<--[ACK], Seq=13, Ack=15------------| Termination
Step 8 — Show to TA and get signature ✅
🧪 Quiz Prep — Questions & Answers
Conceptual Questions
Q1. What is the difference between host-to-host and process-to-process communication? Which layer handles each?
- Host-to-host → handled by the Network Layer (IP) — delivers a packet to the correct destination machine using IP addresses
- Process-to-process → handled by the Transport Layer (TCP/UDP) — delivers the message to the correct running program using port numbers
Q2. What are the three types of addresses in networking? What layer does each belong to, and what is its size?
| Address | Layer | Size |
|---|---|---|
| MAC Address | Data Link | 48 bits |
| IP Address | Network | 32 bits |
| Port Number | Transport | 16 bits |
Q3. What is a socket address? Give an example.
- The combination of an IP address + a port number
- Uniquely identifies one specific process on one specific machine
- Example:
200.23.56.8:80— IP200.23.56.8, port80(HTTP) - A TCP connection requires a socket address on both ends (client socket + server socket)
Q4. What is the port number range for well-known, registered, and dynamic ports?
- Well-known: 0 – 1,023
- Registered: 1,024 – 49,151
- Dynamic / Private: 49,152 – 65,535
Q5. Can two services share the same port on the same IP? Under what conditions?
- No — if both use the same transport protocol (both TCP, or both UDP)
- Yes — if they use different protocols (TCP port 80 and UDP port 80 can coexist on the same IP, as they are completely separate port spaces)
UDP Questions
Q6. What does it mean that UDP is connectionless? How does it differ from TCP?
- There is no connection establishment or termination — no handshake before sending, no goodbye after
- Each UDP datagram is completely independent; even datagrams from the same source to the same destination have no relationship and are not numbered
- TCP, by contrast, requires a 3-way handshake before any data is sent, tracks every byte with sequence numbers, and performs a teardown handshake when done
Q7. Why would you use UDP instead of TCP? Give two real-world examples.
- Use UDP when speed matters more than reliability, or when the application handles its own error recovery
- Example 1: DNS — small one-shot query/response; retrying at the application level is fast and TCP overhead is unnecessary
- Example 2: Video/audio streaming — a dropped frame is better tolerated than the delay caused by TCP retransmission
Q8. When using nc to send UDP, what does the client automatically send before your actual message?
- The
nccommand automatically sends 5 UDP packets containing the character 'X' before the actual message - This is why the server displays
XXXXXTest— five X's arrive first, then the wordTest
TCP Questions
Q9. Describe the TCP 3-way handshake for connection establishment (step by step with flags).
- Client → Server:
[SYN], Seq=x — requests connection - Server → Client:
[SYN, ACK], Seq=y, Ack=x+1 — acknowledges client SYN and sends own SYN - Client → Server:
[ACK], Seq=x+1, Ack=y+1 — acknowledges server SYN; connection is now open
Q10. Describe the TCP 3-way handshake for connection termination.
- Active closer → Passive closer:
[FIN, ACK], Seq=x — initiates close - Passive closer → Active closer:
[FIN, ACK], Seq=y, Ack=x+1 — acknowledges FIN and sends own FIN - Active closer → Passive closer:
[ACK], Ack=y+1 — final acknowledgement; connection is now closed
Q11. A SYN segment has Seq=1000. What ACK number should the receiver send back?
SYN consumes one sequence number, so the receiver expects the next byte at position 1001.
Q12. Given a data segment with Seq=1, Len=5, what will the receiver's ACK number be?
The receiver got bytes 1–5, so it expects byte 6 next.
Q13. Does a SYN segment consume a sequence number? What about an ACK-only segment?
- SYN: ✅ Yes — consumes 1 sequence number (even though it carries no data)
- SYN+ACK: ✅ Yes — consumes 1 sequence number
- ACK (no data): ❌ No — consumes 0 sequence numbers
Q14. During connection termination, which side performs the active close and which the passive close?
- Active close: the side that initiates termination by sending the first
[FIN] - Passive close: the side that receives the FIN first and responds
- Either the client or server can be the active closer — whoever sends FIN first
Wireshark / Practical Questions
Q15. What Wireshark filter would you use to see only TCP packets from/to IP 192.178.18.8?
ip.addr==192.178.18.8 && tcp
Q16. In Assignment 4's pcap, what messages were exchanged?
- Client (
192.178.18.8) sent:"How are you?" - Server (
192.178.18.9) replied:"I am fine."
Q17. In Assignment 4, what port did the client use? What port did the server use?
Q18. Looking at Wireshark, how do you identify which packets belong to each TCP phase?
| Phase | Flags to look for |
|---|---|
| Connection Establishment | [SYN] → [SYN, ACK] → [ACK] |
| Data Transfer | [ACK] with Len > 0, or application-protocol label |
| Connection Termination | [FIN, ACK] → [FIN, ACK] → [ACK] |
Port Number Questions
Q19. What port does HTTP, DNS, FTP (control), SMTP, and DHCP use?
| Protocol | Port | Transport |
|---|---|---|
| HTTP | 80 | TCP |
| DNS | 53 | UDP + TCP |
| FTP (control) | 21 | TCP |
| SMTP | 25 | TCP |
| DHCP | 67 | UDP |
Q20. If a server runs HTTP on TCP port 80, can another app use UDP port 80 on the same IP? Why?
- Yes — TCP and UDP maintain completely separate port namespaces
- TCP port 80 and UDP port 80 are different sockets and do not conflict with each other
- A port number alone does not uniquely identify a socket — it must be combined with the transport protocol (TCP or UDP) and the IP address