0% found this document useful (0 votes)
2 views117 pages

COM 221 Basic Computer Networking

Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
2 views117 pages

COM 221 Basic Computer Networking

Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

COM 226 Basic Computer Networking Course Outline

Weeks Content
1-2 1.1 Define Computer Network
1.2 State the advantages and disadvantages of a Computer Networks.
1.3 Explain types of Networks: LAN, MAN and WAN
1.4 Explain Perimeter networks, addressing VLANs, Wired and Wireless LAN
1.5 Explain Leased lines, dial-up, ISDN, VPN, T1, T3, E1, E3, DSL, cable
modem etc, and their characteristics (speed, availability
1.6 Differentiate between Client and Server Computers
1.7 Differentiate between Wired and Wireless Networks
2-4 2.1 List the hardware components of Computer Network: Router, switches,
repeater, Gateway and cables.
2.2 Differentiate between Hub and Switch
2.3 Explain Repeaters and their functions
2.4 Explain bridges and their Functions
2.6 Explain Routers and their functions.
2.7 Describe Network Interface Card (NIC) and functions
5-6 3.1 Define Network Planning and Design
3.2 Outline the importance of network planning
3.3 Outline the steps involved in designing a network
3.4 Explain network topology and access methods
7-9 4.1 Describe Point-to-point, Peer-to-peer, Client/Server based networks
4.2 Explain types of Cable termination and suitable cables for each
4.3 State advantages and Disadvantages of each connection type in 2.1 above
4.4 Explain the types of Servers: print, mails etc.
4.5 Discuss Server reliability, availability and data integrity
10-11 5.1 Define OSI Model.
5.2. Explain TCP/IP Reference Model
5.3 Differentiate between TCP/IP and OSI Model.
5.4 State the functions of each layer of the OSI Model
12-13 6.1 Explain the concept of IP addressing. and types
6.2 Explain the term IPV 4. 6.3 State the classes of IP addresses.
6.4 Explain the range of IP address classes. 6.5 Describe VLSM/ Subnetting IPV4
6.6 Explain IPV6. 6.7 Explain Network functionality test
14-15 7.1 Differentiate between Internet and Extranet
7.2 Explain the various types of internet connectivity
7.3 Define Wireless Network and types of Access
7.4 Differentiate between Dial- up, wireless and Broad band Internet access.
7.5 Explain the Advantages of Broad band Over Dial-up and Wireless Access
Network
7.6 Explain wireless network standards
7.7 Explain types of Network Security
NATIONAL DIPLOMA IN COMPUTER SCIENCE

COURSE CODE: COM 221


Basic Computer Networking
Introduction
Computer Network
A computer network can be described as a system of interconnected devices that can communicate
using some common standards called the Internet protocol suite or TCP/IP. These devices
communicate to exchange network resources, such as files and printers, and network services.
Here is an example of a computer network consisting of two computers connected together:

The example above shows that the two computers are directly connected using a cable. This small
network can exchange data between just these two computers.

What if we want to expand our network? Then we can use network devices, such as routers,
switches, or hubs, to connect two or more computers together:

Advantages of Computer Network


Computer networks provide many benefits to individuals and organizations.
1. Resource Sharing: Network users can share resources such as:
Printers, Scanners, Storage devices, Internet connection.
Example: Twenty computers in a computer laboratory can share one printer instead of
purchasing twenty printers.
2. File Sharing: Users can easily exchange files and documents over the network.
Example: A lecturer can share lecture notes with students through the school's network.

3. Communication: Networks facilitate communication between users through:


Email, Instant messaging, Video conferencing, Voice calls
Example: Students can communicate with lecturers using email and online learning
platforms.

4. Centralized Data Management: Data can be stored on a central server for easy access
and management.
Example: Student records can be stored in a central database server.
5. Internet Sharing: Multiple users can share a single Internet connection.
Example: A Polytechnic can provide Internet access to all departments through one
network connection.
6. Improved Collaboration: Network users can work together on projects and share
information efficiently.
Example: Students working on a group assignment can access shared files simultaneously.

7. Increased Efficiency: Information can be transferred quickly between departments and


users.
Example: The Admissions Office can instantly send student information to the Academic
Affairs Unit.

8. Cost Reduction: Organizations save money by sharing hardware, software, and


communication resources.
Example: One licensed software package may be shared across multiple computers.
9. Remote Access: Authorized users can access network resources from different locations.
Example: A lecturer can access course materials from home using a VPN.

10. Data Backup and Recovery: Centralized storage makes data backup easier.
Example: Student results stored on a server can be backed up regularly.

Disadvantages of Computer Network

Despite their advantages, computer networks also have some drawbacks.

1. Security Risks: Hackers, viruses, and malware can spread through networks.
Example: A virus on one computer may infect other computers on the same network.
2. High Installation Cost: Setting up a network requires: Computers, Switches, Routers,
Cables, Servers
3. Maintenance Cost: Networks require continuous maintenance and monitoring.

4. Dependence on the Server: In client-server networks, server failure may disrupt services.
5. Network Failure: Hardware or software problems can affect the entire network.
6. Spread of Malware: Viruses and worms can spread rapidly through a network.
7. Privacy Issues: Unauthorized users may access confidential information if security
measures are weak.
8. Complexity: Large networks can be difficult to configure and manage.
9. Performance Issues: Network performance may decrease when many users access
resources simultaneously.
10. Dependence on Electricity: Networks require continuous power supply.

Advantages of Computer Networks Disadvantages of Computer Networks


Resource sharing Security risks
File sharing High installation cost
Internet sharing Maintenance cost
Improved communication Server dependence
Centralized data management Network failure
Better collaboration Spread of malware
Increased efficiency Privacy issues
Cost reduction Complexity
Remote access Performance issues
Easy backup and recovery Dependence on electricity

Concepts of the Internet, Intranet, and Extranet.


The Internet, Intranet, and Extranet are communication networks that enable the sharing of
information and resources among users. Although they are related concepts, they differ in terms
of accessibility, ownership, security, and scope.

INTERNET

The Internet is a worldwide network of interconnected computers and networks that communicate
using standard protocols such as TCP/IP. It is often called the "Network of Networks" because
it connects millions of networks and devices across the world.

Characteristics of the Internet


1. Global network.
2. Open to the public.
3. Uses TCP/IP protocols.
4. Supports communication and information sharing.
5. Accessible from anywhere with an Internet connection.
INTRANET
An Intranet is a private network that uses Internet technologies and protocols but is accessible only
to authorized users within an organization. It belongs to a specific organization and is not available
to the general public.
Characteristics of an Intranet
1. Private network.
2. Accessible only to authorized users.
3. Owned by a single organization.
4. Uses Internet technologies such as web browsers and TCP/IP.
5. Protected by security controls.

EXTRANET

An Extranet is an extension of an Intranet that allows authorized external users to access part of
an organization's private network. It enables secure information sharing between an organization
and external parties.

Characteristics of an Extranet
1. Controlled access.
2. Accessible to authorized outsiders.
3. Uses Internet technologies.
4. More secure than the public Internet.
5. Supports collaboration between organizations.

Differences Between Internet, Intranet, and Extranet


Feature Internet Intranet Extranet
Access Public Private Restricted External Access
Users Everyone Organization Members Organization + Authorized Outsiders
Ownership No Single Owner Single Organization Single Organization
Security Lowest High High
Coverage Worldwide Within Organization Organization and Partners
Example Public Websites Staff Portal Supplier Portal
NETWORK TYPES AND NETWORK SECURITY
TYPES OF NETWORKS

Computer networks are classified based on their size, coverage area, and geographical spread. The
three major types are:

1. PAN (Personal Area Network)


2. LAN (Local Area Network)
3. MAN (Metropolitan Area Network)
4. WAN (Wide Area Network)

Personal Area Network (PAN): A short-range network centred around a single user within a 10-
meter range.
Examples: Connecting a smartphone to a smartwatch, wireless headphones, or a fitness tracker
using Bluetooth
Local Area Network (LAN) is a network that connects computers within a small geographical
area such as a room, building, school, or office. A LAN, or Local Area Network, allows devices
to connect within a specific geographic area, such as a building, office, or home. This type of
network is commonly used to facilitate communication and data sharing between computers and
other devices. LANs are widely used to facilitate communication and resource sharing between
connected devices.

Diagram (LAN in a Computer Lab)

PC1 ───┐
PC2 ───┼── Switch ── Router ── Internet
PC3 ───┼
PC4 ───┘
Characteristics of LAN
• Limited geographical area: LANs cover a small physical area, typically within a building
or campus.
• High data transfer rates: LANs offer fast data transfer, enabling quick communication and
resource sharing.
• Localized administration: LANs manage and administer network resources locally,
enabling control.
• Shared infrastructure: LANs often use shared network infrastructure, such as Ethernet
switches and routers, to connect devices.
Purposes of LANs:
• Facilitating communication: LANs enable users to communicate through email, instant
messaging, and shared applications, improving collaboration within an organization.
• Resource sharing: LANs enable multiple users to access printers, scanners, and storage
devices, reducing costs and improving efficiency.
• Centralized data storage and backup: LANs provide a centralized location for storing and
backing up important data, making it easily accessible and protected.
• Access to shared applications and databases: LANs enable users to access shared
applications and databases, streamlining workflows and providing access to critical
information.
Types of LANs:
• Token Ring LAN: Token Ring LANs use a token-passing protocol in which a special
“token” is circulated among network devices. When a device possesses the token, it has
the right to transmit data. Token Ring LANs ensure fair access to the network and use a
ring topology.
• Token Bus LAN: Token Bus LANs use a token-passing mechanism but employ a bus
topology rather than a ring. Devices on the network contend for the token to transmit data.
Token Bus LANs were less commonly used than Token Ring LANs.
• Wireless LAN (WLAN): WLANs use wireless technology, such as Wi-Fi, to connect
devices without needing physical cables. They allow users to access the network and its
resources via wireless adapters or devices with built-in Wi-Fi capabilities. WLANs provide
flexibility, mobility, and ease of connectivity.
• Wired LAN: Wired LANs use physical cables, such as Ethernet or fiber-optic cables, to
connect devices within a limited area. They offer reliable, high-speed data transfer. Wired
LANs are commonly used in offices, homes, and data centers.
• Cloud Managed LAN: Cloud Managed LANs leverage cloud-based management and
control to centrally administer and monitor the LAN infrastructure. Network configuration,
monitoring, and troubleshooting can be done through a web-based interface, enabling
scalability, easier management, and simplified network deployment.
Advantages of LANs
• Resource Sharing: LANs allow devices to share resources such as printers, scanners,
and storage devices, reducing the need for individual devices for each user.
• File Sharing: LANs enable users to share files and documents easily, improving
collaboration and productivity.
• Centralized data management: By centralizing data storage on a LAN server, data
backup, security, and management become more efficient.
• Cost-effective: LANs are generally more cost-effective than wide area networks (WANs)
as they require less cabling and equipment.
• Fast data transfer: LANs provide high-speed data transfer rates, enabling quick access
to shared resources and improved communication.
Disadvantages of LANs
• Limited geographic range: LANs are confined to a limited area, typically a building or
campus, which restricts connectivity to devices within that range.
• Installation and maintenance costs: Setting up and maintaining a LAN can be costly,
requiring network equipment, cables, and skilled IT personnel.
• Network congestion: In heavily utilized LANs, increased traffic can lead to network
congestion and reduced performance.
• Security risks: LANs can be vulnerable to unauthorized access, data breaches, and
malicious activities if proper security measures are not implemented.
• Scalability limitations: The scalability of a LAN may be limited, making it
Examples

• Computer lab in a polytechnic


• Office network in a bank
• Campus building network

Metropolitan Area Network (MAN) is a network that covers a larger area than LAN, such as a
city or large campus. It connects multiple LANs together within a town or city. A Metropolitan
Area Network (MAN) is a computer network that spans a metropolitan area or a city. It connects
multiple local area networks (LANs) and efficiently transmits data, voice, and video between
different locations within the metropolitan region.

Diagram (City Network)


School LAN ───┐
Bank LAN ───┼── City Network Backbone ─── Internet
Hospital LAN ─┘
Examples of MAN:

• Cable Television Network: Cable TV providers often leverage MANs to deliver television
signals and internet services to subscribers within a city or metropolitan area.
• Educational Institutions: Universities and colleges often establish MANs to interconnect
various departments, libraries, and research facilities.
• Government Networks: Municipalities or government agencies may use MANs to
connect different government buildings, enabling efficient communication and data
sharing.
• Large Corporations: Multinational companies or corporations with multiple branches in
a city can employ a MAN to connect their various offices and facilities.

Types of MAN:
o Fiber Distributed Data Interface (FDDI): FDDI is a type of MAN that uses fiber optic
cables to transmit data over a ring network topology.
o Asynchronous Transfer Mode (ATM): MANs use ATM as a high-speed networking
technology to efficiently transmit voice, data, and video.
o Ethernet MAN (E-Man): E-Man utilizes Ethernet technology to connect multiple LANs
within a metropolitan area, providing a cost-effective solution for interconnecting local
networks.
o Wireless MAN (WMAN): WMANs use wireless technologies such as Wi-Fi and WiMAX
to establish networks within metropolitan areas.
Characteristics of MAN

• Covers a city or large campus


• High-speed connectivity
• More expensive than LAN
• Uses fiber optic cables or microwave links

Advantages of MANs
▪ Expanded Connectivity: MANs provide connectivity to a larger geographic area, enabling
communication and data sharing between multiple LANs.
▪ Higher Bandwidth: MANs typically offer higher bandwidth than individual LANs,
allowing faster data transfer rates and better performance.
▪ Centralized Management: A MAN allows centralized management and control of network
resources, making monitoring and maintaining the network infrastructure easier.
▪ Cost-Effective: Sharing network infrastructure among multiple organizations within a
metropolitan area can result in cost savings compared to individual LAN setups.
▪ Scalability: MANs can be easily expanded or upgraded to accommodate the growing needs
of businesses or institutions within the metropolitan area.
Disadvantages of MANs
▪ Complexity: Setting up and managing a MAN can be more complex and challenging than
managing a single LAN due to the larger scale and multiple locations involved.
▪ Dependency on Service Providers: MANs often require services from telecommunications
or network service providers, which can introduce dependencies and potential points of
failure.
▪ Security Concerns: Since a MAN covers a larger area and connects multiple organizations,
there is an increased risk of security breaches and unauthorized access to the network.
▪ Reliability: MANs may experience downtime or performance issues, particularly if there
are infrastructure or connectivity problems within the metropolitan area.
Wide Area Network (WAN) is a network that covers a very large geographical area such as a
country, continent, or the entire world. A Wide Area Network (WAN) is a computer network
spanning large geographical areas, such as cities, countries, or continents. It connects multiple
Local Area Networks (LANs) or other WANs, allowing data, voice, and video transmission over
long distances. Many organizations use WANs to connect their remote offices, branches, or data
centres, enabling communication and resource sharing.

Diagram (Global WAN – Internet)


Nigeria LAN ───┐
USA LAN ───┼── Internet (WAN) ─── UK LAN
India LAN ───┘
Examples of WAN:
Virtual Private Network (VPN): VPNs create secure tunnels over public networks, such as
the internet, to connect remote locations and enable secure communication and resource
sharing.
Internet-based WAN: Many organizations leverage the internet as WAN infrastructure,
using technologies such as IPsec, MPLS, or software-defined WAN (SD-WAN) to connect
their remote sites.
Leased Lines: Leased lines, such as T1/E1 or T3/E3 lines, provide dedicated point-to-point
connections between locations, ensuring reliable and secure data transmission.
Satellite Networks: In remote areas or regions with limited terrestrial infrastructure, WANs
can be established using satellite communication technology to connect sites over long
distances
Characteristics of WAN:
❖ Large Geographic Coverage: WANs span a significant geographic area, from regional to
national to international.
❖ Diverse Connectivity Technologies: WANs use various technologies, including leased
lines, fiber-optic links, satellite links, microwave links, and internet-based networks, to
connect sites.
❖ Reliance on Public or Private Infrastructure: WANs can utilize public networks, such as
the internet, or private leased lines to transmit data, depending on the organization’s
requirements and security considerations.
❖ Network Protocols and Routing: WANs employ routing protocols, such as Border Gateway
Protocol (BGP), to efficiently direct data packets across multiple interconnected networks
and determine the best path.
❖ Quality of Service (QoS): WANs often implement QoS mechanisms to prioritize certain
types of traffic, such as voice or video, to ensure optimal performance and minimize
latency for critical applications.

Types of WAN:
1. Packet switching: Two main types of packet switching are used in wide area networks
(WANs): circuit-switched and packet-switched. Let’s explore both types:
i. Circuit-Switched WAN: In a circuit-switched network, a dedicated communication
path is established between two endpoints for the duration of the communication
session. This path remains dedicated to the specific session, even without data
transmission. Traditional telephone networks are an example of circuit-switched
networks. Circuit-switched networks provide guaranteed bandwidth but are less
efficient for data transmission than packet-switched networks.
ii. Packet-Switched WAN: A packet-switched network divides data into packets and
transmits them independently. The packets can take different routes and reassemble
at the destination. Packet-switched networks are more efficient for data
transmission as they allow multiple sessions to share the same network resources.
The Internet is an example of a packet-switched network.
2. TCP/IP protocol suite: The TCP/IP protocol suite is the foundation for communication
on the Internet and many private networks. It consists of two main protocols:
Transmission Control Protocol (TCP): TCP provides reliable, connection-oriented
communication between devices. It ensures the delivery of data packets in order
and without errors, and incorporates flow-control mechanisms to prevent
congestion. TCP breaks data into packets, reassembles them at the destination, and
ensures error recovery in the event of any lost packets.
Internet Protocol (IP): IP addresses and routes packets across networks. It
establishes the logical addressing scheme used for identifying devices on a network
and enables the routing of packets to their destinations. IP handles packet
fragmentation and reassembly and ensures their proper delivery.
3. Packet over SONET/SDH (PoS): Packet over SONET/SDH is a technology that allows
the transmission of packet-switched data over synchronous optical networks (SONET) or
synchronous digital hierarchy (SDH) networks. Standardized protocols for transmitting
digital signals over optical fiber networks include SONET and SDH. PoS encapsulates IP
packets into SONET/SDH frames, efficiently utilizing high-speed optical networks for IP-
based data transmission.
4. Multiprotocol Label Switching (MPLS): MPLS is a packet-forwarding technology in
high-performance networks. It combines the benefits of circuit-switching and packet-
switching to efficiently route IP packets. MPLS uses labels to identify paths through the
network, allowing routers to make forwarding decisions based on these labels rather than
examining the entire packet’s IP header. This improves routing speed and efficiency,
enhances quality of service (QoS) features, and enables the creation of virtual private
networks (VPNs) and traffic engineering in complex networks.
Advantages of WANs
➢ Geographical Coverage: WANs allow communication and connectivity across large
distances, enabling organizations to connect remote offices or branches in different cities
or countries.
➢ Resource Sharing: WANs facilitate the sharing of resources, such as servers, databases,
and applications, among different locations, enabling efficient collaboration and data
access.
➢ Centralized Management: WANs can be centrally managed, making monitoring and
controlling the network infrastructure easier, ensuring consistent connectivity and
performance across the entire network.
➢ Scalability: WANs can be easily scaled up to accommodate the growing needs of
organizations, allowing for adding new sites or locations to the network.
➢ Wide Range of Services: WANs provide access to many services, including internet
connectivity, cloud services, Voice over IP (VoIP), video conferencing, and virtual private
networks (VPNs).
Disadvantages of WANs
➢ Cost: Setting up and maintaining a WAN can be costly, requiring dedicated network
equipment, high-speed connectivity, and potentially recurring fees for leased lines or
service providers.
➢ Complexity: WANs can be complex to design, implement, and manage, especially when
dealing with multiple technologies, protocols, and connectivity options.
➢ Dependency on Service Providers: Organizations relying on WANs often depend on third-
party service providers for connectivity and service reliability, which can introduce
potential points of failure.
➢ Security Risks: WANs extend the network beyond the organization's physical boundaries,
increasing the risk of security breaches and unauthorized access to sensitive data.
To build a secure network infrastructure, whether it's for a global enterprise or a local setup, you
need tools that control traffic, segment sensitive data, and secure remote connections.

VIRTUAL PRIVATE NETWORK (VPN)

Virtual Private Network (VPN) is a secure connection that allows users to access a private
network over a public network (Internet) using encryption. A VPN creates a secure tunnel through
the Internet so that data cannot be easily intercepted. When a user connects to a VPN, it establishes
a secure and private connection between their device and the network they are accessing. This
tunnel encrypts and protects data transmitted between the user and the network, helping prevent
potential threats. It encrypts the data traffic passing through the tunnel, ensuring confidentiality
and protecting it from eavesdropping or unauthorized access.

Purposes of VPN:
• Secure Remote Access: Allowing remote users to connect to a private network from
anywhere securely.
• Privacy and Anonymity: Concealing the user’s IP address and online activities from
potential surveillance or monitoring.
• Bypassing Geo-restrictions: Enabling access to geographically restricted content or
services by masking the user’s location.

Types of VPN Protocols and Technologies: VPNs utilize various protocols and technologies to
establish secure connections. Some common types include:
 IPsec (Internet Protocol Security): IPsec provides a suite of protocols for securing IP
communication. It provides strong encryption and authentication and is usable in both
remote access and site-to-site VPN configurations.
 SSL/TLS (Secure Sockets Layer/Transport Layer Security): SSL and its successor TLS are
widely used protocols for securing web communication. Users often use SSL/TLS VPNs
to securely access web-based applications or services from remote locations.
 OpenVPN: An open-source VPN protocol that uses SSL/TLS for encryption and provides
secure remote access. It is known for its flexibility and cross-platform compatibility.
 L2TP/IPsec (Layer 2 Tunneling Protocol/IPsec): L2TP combines the best features of PPTP
(Point-to-Point Tunneling Protocol) and Cisco’s L2F (Layer 2 Forwarding). It commonly
uses IPsec for secure remote access and provides strong encryption.
 PPTP (Point-to-Point Tunneling Protocol): PPTP is an older VPN protocol that offers basic
encryption and authentication. While widely supported, it is considered less secure than
other options.

Two Common Types of VPNs


▪ Remote-Access VPN: Allows individual users (like remote workers) to securely connect
to a corporate network from anywhere. The user logs in via a client application, giving
them secure access to internal resources just as if their computer were physically plugged
into the office LAN.
▪ Site-to-Site VPN: Connects entire networks together—for example, connecting a branch
office network to a main headquarters network. It uses dedicated gateway devices on both
sides to handle the encryption and decryption automatically.
VPN Diagram
User (Home)

Encrypted Tunnel

Internet

Company Server

Characteristics of VPN

• Uses encryption for security


• Works over public Internet
• Provides remote access
• Masks user identity (IP address)

Advantages of VPN

• Secure communication
• Protects data from hackers
• Allows remote access (work from home)
• Reduces cost of private leased lines

Disadvantages of VPN

• May reduce internet speed


• Requires configuration
• Depends on Internet quality

Example Uses

• Lecturers accessing school database from home


• Employees working remotely
• Secure online banking
SECURITY ZONES

A Security Zone is a logical grouping of network assets (like servers, computers, and databases)
based on their risk profile and who needs access to them. Instead of treating an entire network as
one giant room where everyone can talk to everyone, firewalls divide the network into distinct
"rooms" or zones. A security zone is a defined, segmented area where specific policies and
restrictions are enforced to regulate access, prevent unauthorized entry, or isolate risks. Depending
on the context, security zones can be physical territories or logical network boundaries.

A firewall sits at the boundary of these zones to enforce strict rules on how traffic flows between
them.

Typical Security Zones


✓ Inside / Trusted Zone (LAN): Your private local network. This contains internal corporate
assets, employee workstations, and sensitive internal data. It is highly protected.
✓ Outside / Untrusted Zone (WAN): Usually the public Internet. It is completely outside your
control and assumed to be entirely hostile.
✓ Demilitarized Zone (DMZ): A semi-trusted buffer zone between the inside and outside
network. It hosts public-facing servers (like web servers or email servers). If a hacker
compromises a web server in the DMZ, the firewall still prevents them from easily jumping
into the internal Trusted Zone.

Security Zone Diagram


Internet (Untrusted)

Firewall

DMZ
(Web Server, Email)

Firewall

Internal Network
(Student Records, Database)

Characteristics of Security Zones

• Network is divided into sections


• Each zone has different security level
• Controlled by firewalls
• Reduces attack risk

Advantages

• Improves security
• Limits hacker access
• Organizes network traffic
• Protects sensitive data

In the following example below, you can see the 4 zones (red, yellow, green, white). The red zone
represents our server room. This is where the internet access, the router/firewall and 3 servers are
located. The yellow zone would be the entrance area where our reception is located. There may be
a workstation there and a television with the latest news. Suppliers, postmen, customers and other
visitors occasionally enter this area. Our green zone represents the office area where no public
traffic takes place. This is where most employees work on their networked desktops or laptops.
This is where software is developed or customer inquiries are handled over the phone. The human
resources department or purchasing department may be located here.

In the following example we see a security concept that represents the security zones like onion
rings or tree rings. Anyone in the yellow zone cannot simply get into the green zone. In the green
zone the workplaces are located on 4 floors. Only those who get in here can request entry into the
red zone.
Firewalls: The Gatekeepers
A firewall is a network security device that monitors and filters incoming and outgoing network
traffic based on an organization’s previously established security policies. Think of it as a security
guard standing at the entrance of a building, checking IDs and deciding who gets to enter or leave.

Types of Firewalls

✓ Packet Filtering Firewalls: The oldest and most basic type. They inspect small chunks of
data (packets) and block them based on source/destination IP addresses, protocols, or ports.
Checks data packets.
✓ Stateful Inspection Firewalls: These track the operating state of network connections
(e.g., whether a connection is new or part of an existing, trusted conversation) to make
smarter filtering decisions. Tracks connection status.

✓ Proxy Firewall is a network security system that protects network resources by filtering
messages at the Application Layer (Layer 7) of the OSI model. Unlike packet-filtering
firewalls that just look at IP addresses and port numbers (Layers 3 and 4), a proxy firewall
completely breaks the network connection between the source device and the destination
device. Act as middleman.
✓ Next-Generation Firewalls (NGFW): Modern firewalls that go beyond simple packet
filtering. They feature Deep Packet Inspection (DPI), intrusion prevention systems (IPS),
and application awareness (e.g., blocking specific apps like torrents while allowing
standard web browsing).

Firewall Diagram

Internet ─── Firewall ─── Internal Network

How Firewall Works

1. Checks incoming data


2. Compares with security rules
3. Allows or blocks traffic
Characteristics of Firewalls

• Monitors traffic
• Blocks unauthorized access
• Enforces security rules
• Protects internal network

Advantages of Firewalls

• Prevents hacking
• Protects sensitive data
• Controls network traffic
• Enhances security

Limitations

• Cannot stop internal threats


• Needs regular updates
• Misconfiguration can cause issues

Summary: How They Work Together


• Imagine an organization with a main headquarters and remote workers:
• A remote employee connects to the corporate network via a VPN, safely passing through
the hostile Internet.
• The traffic arrives at the corporate boundary, where a Firewall inspects the traffic to ensure
it matches security policies.
• Once cleared, the firewall routes the user strictly into the specific Security Zone they are
authorized to access (such as the general LAN, while keeping them out of the highly
sensitive Data Centre zone).
RELATIONSHIP BETWEEN VPN, SECURITY ZONES, AND FIREWALL
Internet

VPN (Secure Tunnel)

Firewall

DMZ Zone

Internal Network

• VPN provides secure remote access


• Firewall controls traffic
• Security zones organize and protect network areas

Perimeter Networks, Addressing VLANs, Wired LAN and Wireless LAN.

Introduction
Computer networks are designed to allow devices to communicate efficiently and securely. To
achieve this, network administrators use various techniques such as perimeter networks, IP
addressing, VLANs, and different LAN technologies. Understanding these concepts is essential
for managing modern computer networks.
Perimeter Networks

A perimeter network, also called a DMZ (Demilitarized Zone), is a security zone that sits between
an organisation's internal private network and the public internet. It provides an extra layer of
protection by placing publicly accessible servers in a separate zone away from sensitive internal
systems. It serves as the front line of defence, preventing unauthorized access and cyber threats
from reaching sensitive corporate data. A perimeter network (also called a DMZ Demilitarized
Zone) is a subnetwork that sits between an organization's internal (trusted) network and an external
(untrusted) network, typically the internet.
A Demilitarized Zone (DMZ), often synonymous with a perimeter network, is a segregated
subnetwork positioned between the trusted LAN and the untrusted internet. It hosts public-facing
services (like web servers or email gateways) so external users can access them without exposing
the critical internal systems to direct attacks.

Purpose of a Perimeter Network


1. Protect internal network resources.
2. Allow public access to selected services.
3. Reduce the risk of cyber attacks.
4. Improve network security.

How a Perimeter Network Works


A perimeter network uses TWO firewalls:
• Outer firewall (Firewall 1): Filters traffic coming from the internet into the DMZ. It allows
only specific traffic such as HTTP (port 80) and HTTPS (port 443).
• Inner firewall (Firewall 2): Filters traffic from the DMZ into the internal network. It is
much more restrictive and blocks most traffic.
• Even if an attacker breaks into a server in the DMZ, they still face the inner firewall before
reaching the internal network.
Servers Placed in the DMZ

Server Type Purpose

Web server Hosts the organisation's website accessible to


the public

Email server Handles incoming and outgoing emails from


the internet

DNS server Resolves domain names for external users

FTP server Allows controlled file uploads/downloads


from outside

VPN gateway Entry point for remote workers connecting


from home

Advantages of a Perimeter Network


• Protects internal systems even if a public server is compromised.
• Reduces the attack surface on critical internal data.
• Allows public services to run without exposing internal systems.
• Provides clear monitoring points between zones.
Real-World Nigerian Example
A bank's internet banking web server sits in the DMZ. Customers can access it online, but the core
banking database (account balances, transaction records) remains in the internal network, protected
by the inner firewall.

Characteristics of Perimeter Network


1. Intermediate Buffer Zone
o Acts as a neutral area between trusted internal networks and untrusted external
networks
o Provides an additional layer of security isolation
o Prevents direct access from external users to internal resources
2. Controlled Access Points
▪ Traffic is filtered through at least two firewalls:
Front-end (external) firewall — filters traffic between internet and DMZ
Back-end (internal) firewall — filters traffic between DMZ and internal
network
▪ Strict access control policies govern traffic flow
3. Hosts Public-Facing Services
Commonly hosted services include:
• Web servers (HTTP/HTTPS)
• Email servers (SMTP)
• DNS servers
• FTP servers
• Proxy servers
• VPN gateways
4. Limited Trust Level
▪ DMZ systems are considered semi-trusted
▪ They have restricted access to internal network resources
▪ Compromised DMZ hosts cannot easily pivot to the internal network
Perimeter networks, addressing VLANs, Wired and Wireless LAN
Perimeter Networks and VLANs (Logical Segmentation)
A VLAN (Virtual Local Area Network) is a logical subdivision of a physical network. In modern
networking, perimeter networks are rarely built using entirely separate physical hardware; instead,
they are created using VLANs.
▪ Creating the DMZ Logically: A network administrator can configure a single physical
switch to host multiple VLANs. For example:
• VLAN 10: Internal Corporate LAN (Highly Trusted)
• VLAN 20: Perimeter Network / DMZ (Semi-Trusted)
• VLAN 30: Guest Network (Untrusted)
▪ Traffic Isolation: By default, devices on VLAN 20 (the DMZ) cannot communicate with
devices on VLAN 10 (the Internal LAN). The VLAN tags (using the 802.1Q standard)
ensure that broadcast traffic and data packets are kept strictly separate at Layer 2 of the
OSI model.
▪ Inter-VLAN Routing via Firewalls: To allow the DMZ to communicate with the internet
or the internal network, traffic must be routed. In a secure perimeter architecture, this
routing is handled by a firewall, not a standard router. The firewall inspects the traffic
moving between VLANs, applying strict Access Control Lists (ACLs) to ensure only
authorized traffic (e.g., a DMZ web server querying an internal database on a specific port)
is permitted.
▪ Cost and Flexibility: Using VLANs to create a perimeter network is highly cost-effective.
If a new public-facing service is needed, an administrator can simply assign its switch port
to the DMZ VLAN, rather than running new physical cables to a dedicated DMZ switch.
Perimeter Networks and Wired LANs (Protecting the Core)
The Wired LAN consists of the physical cables, switches, and endpoints (desktops, physical
servers, printers) that make up the core internal network. The primary purpose of a perimeter
network is to protect the Wired LAN from external threats.
o Physical vs. Logical Separation: Historically, the DMZ was physically separated from the
Wired LAN (using different switches and cables). Today, while they may share physical
switches (via VLANs), the security perimeters are strictly enforced.
o Protecting Internal Assets: The Wired LAN contains highly sensitive data (Active
Directory controllers, financial databases, HR files). The perimeter network acts as a
shield. If an external attacker compromises a public-facing web server located in the DMZ,
the back-end firewall prevents them from using that compromised server as a launching
pad to pivot into the internal Wired LAN.
o Port Security: On the physical switches, ports connected to DMZ servers are configured
with strict security policies. For instance, if a DMZ server is compromised and attempts to
scan the internal Wired LAN, switch-level security (like MAC address filtering or 802.1X
authentication) and firewall rules will drop the malicious traffic.
o Inbound Traffic Flow: External internet traffic destined for a company resource never hits
the internal Wired LAN directly. It hits the front-end firewall, is routed to a proxy or web
server in the DMZ, and only specific, sanitized requests are forwarded to the Wired LAN.
Perimeter Networks and Wireless LANs (Securing the Edge)
A Wireless LAN (WLAN) uses radio waves to connect devices to the network. Because the
transmission medium (the air) cannot be physically contained, WLANs are inherently more
vulnerable than Wired LANs. The perimeter network concept is crucial for securing wireless
access.
Guest Wi-Fi as a Wireless DMZ: The most common application of a perimeter network in
a WLAN is the "Guest Network." When a visitor connects to Guest Wi-Fi, they are placed
into a wireless DMZ.
o They are granted access to the internet.
o They are completely blocked from accessing the internal Wired LAN (printers, file
shares, internal servers).
o Client isolation is often enabled, meaning guest devices cannot even communicate
with other guest devices.
BYOD (Bring Your Own Device) Networks: Employees using personal smartphones or
laptops may be connected to a specific WLAN SSID that drops them into a perimeter
network. This allows them to access the internet and perhaps specific cloud applications,
but keeps unmanaged, potentially infected personal devices off the trusted internal Wired
LAN.
Captive Portals: When users connect to a public or guest WLAN, they are often redirected
to a login page (Captive Portal). The servers hosting these portals, as well as the
authentication databases (like RADIUS servers handling guest credentials), are typically
hosted inside the DMZ to prevent external users from reaching the internal network during
the authentication process.
Wireless Controllers: In large enterprises, Access Points (APs) are managed by centralized
Wireless LAN Controllers (WLCs). The management interfaces of these controllers are
often placed in a secure perimeter network so they can be monitored and updated without
exposing the core management network to the general wireless user base.
Leased lines, dial-up, ISDN, VPN, T1, T3, E1, E3, DSL, cable modem and their
characteristics

These are communication technologies used to connect computers and networks to exchange data.

Leased Line
A Leased Line is a dedicated communication link rented from a telecommunication provider for
exclusive use by an organization. A leased line, sometimes called a dedicated line, is a dedicated
point-to-point link and fixed-bandwidth data connection. A leased line is not a dedicated cable. It
is a reserved dedicated leased line circuit (either a copper or a fiber optic cable) between two
points. Unlike normal Internet connections, it is not shared with other users.
A leased line is a dedicated, permanent connection rented from a telecom company (MTN, Glo,
IPNX in Nigeria). It is always on no dialling needed. It is not shared with anyone else. The same
speed is guaranteed 24 hours a day. Nigerian banks, government offices, universities, and large
corporations use leased lines.
Characteristics
Feature Description
Speed 64 Kbps to several Gbps
Availability Available 24 hours a day, 7 days a week
Security Very high
Reliability Very reliable

Lease Line Advantages and Disadvantages


Most leased lines have a Service Level of Agreement (SLA) to the ISP, which guarantees a reliable
and stable internet connection. Because the leased line is a dedicated communication channel, your
network will have reliable internet access, continuous data flow, higher bandwidth can be achieved
and controlled. You can implement a leased line when you want a completely secured and superior
quality of service for your network.
On the other hand, leased lines can be expensive because they need a dedicated cable and switching
circuitry. Not only that, the leased line is not scalable as it is a permanent physical connection.
✦ Practical Exercise — Leased Line vs Dial-Up Comparison

1. In Packet Tracer, set up two networks — Lagos HQ and Abuja branch


2. Connect them with a serial WAN link (simulates leased line) using routers
3. Configure the serial interface with a clock rate of 64000 (64 Kbps)
4. Use ping and traceroute between both ends
5. Observe: connection is always available — no dialling, instant response
6. Change clock rate to 1544000 (T1 speed) and compare ping times.
Dial-up

A dial-up connection is an older, legacy method of accessing the internet that uses a standard
telephone line and a modem. It functions like a regular phone call, temporarily connecting your
computer to an Internet Service Provider (ISP) network at speeds typically ranging between 40
kbps and 56 kbps. Dial-up uses an ordinary telephone line to connect to the internet. Your modem
converts digital computer data into analogy signals (sounds) to travel over the phone line, then
converts it back at the other end. While connected, nobody can call you on that line.

Dial-up Characteristics
• Low Speeds & High Latency: Maximum speeds typically top out at 56 kbps for
downloads and 33.6 kbps for uploads. This makes it unsuitable for modern, bandwidth-
heavy tasks like video streaming or gaming.
• Manual Connection & Handshake: Users must initiate a connection by instructing the
modem to dial a specific Internet Service Provider (ISP) access number. The process
creates a distinct, audible sequence of tones commonly known as a "handshake".
• Exclusive Line Usage: Because it uses the same frequencies as human voice, you cannot
talk on the telephone and use the internet at the same time. If someone picks up a phone
elsewhere in the house, the internet connection will disconnect or experience severe
disruptions.
• Pay-per-Call or Usage-Based: Unlike modern "always-on" broadband, dial-up access
traditionally charges based on connection time, making prolonged usage prohibitively
expensive.
• Hardware Requirements: It requires an active landline wall jack, a dial-up modem
(internal or external), and Point-to-Point Protocol (PPP) software
Advantages
• Widespread Availability: Because it relies on existing copper telephone networks, it is
accessible almost anywhere.
• Cost-Effective: It requires no additional infrastructure or expensive installation, resulting
in cheaper setup and lower monthly costs.
• High Security: Due to the direct, point-to-point nature of the connection, it is generally
less susceptible to broad network hacks or vulnerabilities compared to always-on
broadband.
• Portability: Users can connect from different locations just by plugging the modem into
any standard active phone wall jack
Disadvantages
• Extremely Slow Speeds: Dial-up caps out around 56 Kbps, making it practically
incompatible with modern websites, media, and video streaming.
• Ties up the Telephone Line: You cannot access the internet and use your landline for
voice calls simultaneously; incoming calls will receive a busy signal.
• No "Always-On" Access: You must actively dial a phone number and wait for the modem
to authenticate and connect every time you need the internet.
• High Latency: The slow data transfer rates result in high latency, rendering real-time
online activities like gaming or video conferencing nearly impossible.

✦ Practical Exercise — Dial-Up Simulation

1. Open Cisco Packet Tracer


2. Place a PC and connect it to a modem device
3. Connect the modem to a cloud (representing PSTN)
4. On the other side of the cloud, add an ISP router
5. Configure the PC to use PPP (Point-to-Point Protocol)
6. Use ping command to test connectivity
7. Observe: only ONE connection possible at a time — no simultaneous voice
ISDN
ISDN stands for Integrated Services Digital Network. It is a set of telecommunication standards
that allows traditional copper telephone lines to carry digital signals, enabling the simultaneous
transmission of voice, video, and data.
Integrated Services Digital Network (ISDN) is a set of communication standards that transmits
voice, video, and data digitally over traditional telephone lines. Its core characteristics include end-
to-end digital transmission, simultaneous service integration, and the use of dedicated channels for
data and signalling.
Developed in the 1980s, ISDN was designed to replace older analogy systems. Because it transmits
digital data directly, it offered faster, clearer, and more reliable connections than standard dial-up
internet or analogy landlines.
How ISDN Works
An ISDN line divides a single physical telephone wire into distinct digital channels:
• B-Channels (Bearer Channels): These carry the actual data—such as voice calls, faxes,
or internet traffic. Each B-channel typically operates at 64 kbps.
• D-Channels (Delta Channels): These manage call setup, routing, and control information.
Common Service Levels
• Basic Rate Interface (BRI): Designed for homes and small businesses. It typically
provides two B-channels and one D-channel, allowing you to use a phone and connect to
the internet simultaneously.
• Primary Rate Interface (PRI): Designed for larger businesses and corporations requiring
heavier usage. In North America, it offers 23 B-channels and one D-channel; in Europe, it
offers 30 B-channels.
Characteristics of ISDN include:
• End-to-End Digital Transmission: Replaces older analogy systems to provide cleaner
voice quality, lower latency, and faster connection speeds.
• Simultaneous Service Integration: Allows users to run multiple services (voice, data, fax,
and video) concurrently over a single line without needing separate analogy connections
for each.
• Channel Structure: Operates using dedicated communication channels:
o B-Channels (Bearer): Carries actual user data, voice, and video. Typically
operates at 64 Kbps.
o D-Channels (Delta): Carries signalling and control information to manage the
connection.
• Main Interface Types:
• Basic Rate Interface (BRI): Designed for home or small business use, offering two 64
Kbps B-channels and one 16 Kbps D-channel.
• Primary Rate Interface (PRI): Designed for larger organizations, commonly offering 23
B-channels and one D-channel in the US/Japan, and 30 B-channels and one D-channel in
Europe.
ISDN Advantages
• Faster Transmissions

Compared to its predecessors, ISDN has a much faster data transmission rate. ISDN’s digital
phone lines being able to carry 128 kbps over the same phone circuits left normal phones
transmission rates of only 2.4kbps in the dust.

• Better Quality Signal

The lines that ISDN runs through also transmit better quality signal compared to its predecessors.
Voice calls are of a higher quality and suffer from less static during the call, and the internet
connection itself is also a lot more stable with less interruptions.

• Multi-Purpose Cables

ISDN lines can transmit voice, video, fax information and data all on the same cable
simultaneously, so you can browse the web and take a phone call at the same time. ISDN allows
for more productivity in the workplace as its more efficient.

• Various Call Management Functions

ISDN features a range of useful phone call features such as call forwarding, directed call pickup,
message waiting indicator and more.
ISDN Disadvantage
• Little Flexibility

As traditional ISDN requires the physical cables to connect, it’s difficult for businesses to
implement remote working and company expansions as ISDN is less flexible. In fact, more and
more businesses are moving to cloud-based systems which are more flexible in their scalability.

• Physical Cables

As ISDN requires the physical connection through telephone lines, the installation and set up of
this can be time-consuming and frustrating for businesses. The system is also more likely to fail
compared to newer technologies.

• Geographical Limitations

ISDN connections are bound to a specific geographical area code, and making changes to this
can take up to several weeks to implement. Businesses are therefore limited on phone numbers
as they’re tied to the geographical location.

• Cost Ineffective

The installation and set up of ISDN cables can be expensive itself, but having to pay for both the
service and the price of leasing the cables all adds up. It’s also costly to make calls with bearer
channels.

• Somewhat Outdated

ISDN has been around since the 1980’s, so compared to newer technologies, such as VoIP (Voice
Over Internet Protocol), it can seem a little outdated. Interested in learning more? Give our blog
a read: 5 Strategic Advantages of IP Voice vs. ISDN. While ISDN offers faster and more reliable
transmission rates than it’s predecessors, compared to broadband internet connection speeds, it
just isn’t as good.
ISDN has been a reliable technology for businesses since the 1980’s, but with more advanced
technology now developed it just doesn’t hold up as well as before anymore. In fact, ISDN has
a confirmed end-of-life date for 2025, as there are new technologies that keep up with society’s
demands more efficiently. If you’re looking for the right service for your company, contact
us today to discuss technological solutions to your business needs.

✦ Practical Exercise — ISDN Channels

1. Open a blank document and draw a table with 3 columns: Channel, Speed, Purpose
2. Fill in: B1 (64 Kbps, Data), B2 (64 Kbps, Voice), D (16 Kbps, Signalling)
3. Calculate total BRI bandwidth: 64 + 64 = 128 Kbps
4. Calculate total PRI bandwidth: 30 × 64 Kbps = 1.920 Mbps + 64 Kbps D = 1.984 Mbps ≈
2 Mbps
5. Discussion: Why can ISDN carry voice and data at the same time but dial-up cannot?
VPN

A VPN (Virtual Private Network) is a cybersecurity tool that creates a secure, encrypted tunnel
between your device and the internet. It hides your real IP address and virtual location, making it
difficult for hackers, advertisers, and Internet Service Providers (ISPs) to monitor your online
activity or track your identity
T1 Line

A T1 line is a dedicated, physical telecommunications connection that transmits data at 1.544


Mbps. Primarily used by businesses, it provides symmetrical speeds (equal upload and download)
and guaranteed bandwidth that is not shared with other users. A T1 line is a dedicated digital
communication line widely used in North America.

Characteristics
• Symmetrical Bandwidth: Both upload and download speeds are locked at 1.544 Mbps.
• Dedicated Connection: Unlike shared consumer networks (like cable), you do not share
your bandwidth with neighbours. This prevents slowdowns during peak hours.
• Reliability (SLAs): T1 lines are highly stable and generally backed by a Service Level
Agreement (SLA) that guarantees maximum uptime.
• Dual Functionality: They can transmit both data and up to 24 digitized voice channels
simultaneously.
How It Works
• A T1 line is physically delivered over traditional twisted-pair copper wiring (similar to a
standard telephone line) or sometimes coaxial or fiber optic cables. It terminates at the
customer's premises using a "smart jack," which connects to a CSU/DSU (Channel Service
Unit/Data Service Unit) before plugging into the business
E1 and E3 Lines - Nigerian Standard

E-carrier lines are the ITU-T European standard used throughout Africa, Europe, and Nigeria. E1
is the backbone of Nigerian telecoms - MTN, Airtel, Glo, and 9mobile all use E1 circuits to
connect their base stations (BTS) to the core network. Nigerian banks use E1 for ATM and
branch connectivity. E3 is a higher-capacity version of E1.
✦ Practical Exercise — E1 Channel Calculation

1. Calculate total E1 capacity: 32 channels × 64 Kbps = 2,048 Kbps = 2.048 Mbps


2. Calculate usable capacity: 30 channels × 64 Kbps = 1.920 Mbps
3. Calculate E3 capacity: 16 × 2.048 Mbps = 32.768 Mbps (plus overhead = 34.368 Mbps)
4. Research exercise: Visit any Nigerian bank ATM. The network connecting that ATM to
the bank's core uses E1 leased line. How many ATM transactions per second can one E1
handle if each transaction uses 1 channel?
T1 and T3 Lines
T-carrier lines are the North American standard for digital transmission. They use Time Division
Multiplexing (TDM) to combine many channels into one physical line. Note: Nigeria uses E-
carrier (E1/E3), not T-carrier, but T1/T3 appears in textbooks.
DSL - Digital Subscriber Line
DSL sends broadband internet over ordinary copper telephone wire but at higher frequencies than
voice, so both can be used simultaneously. A splitter at your home separates the voice signal (low
frequency) from the internet signal (high frequency). The DSLAM at the telephone exchange
collects DSL connections from the whole area. DSL provides Internet access using existing
telephone lines.

✦ Practical Exercise — DSL Speed vs Distance

1. Open a spreadsheet (Excel or LibreOffice)


2. Create a table: Distance from exchange (km) | ADSL speed (Mbps)
3. Enter values: 1km=24Mbps, 2km=18Mbps, 3km=12Mbps, 4km=6Mbps, 5km=2Mbps
4. Create a line chart — observe how speed decreases with distance.
5. Discussion: Why does speed drop with distance? (Answer: signal attenuation in copper
wire)
Cable Modem
Cable modem uses the same coaxial cable as cable TV to deliver broadband internet. It is much
faster than DSL. However, the key difference is that bandwidth is shared among all neighbours on
the same cable segment — speed drops during peak hours when everyone is online.

✦ Practical Exercise — Cable vs DSL Comparison

1. Create a comparison table: Feature | Cable Modem | DSL


2. Fill in: Medium, Speed, Shared? Distance limit, Cost
3. Discussion question: You live 6km from a telephone exchange but close to a cable TV
headend. Which is better for you and why?
4. Speed test exercise: At 8am and 8pm, if you had cable internet, predict which would be
faster and explain why
Addressing; reserved address ranges for local use (including local loopback ip), VLANs;
wired LAN and wireless LAN
Network Addressing is the process of assigning unique addresses to devices on a network. IP
addressing is a logical method of assigning unique identifiers to devices on a network.
Type of IP Adress
IPv4 (Internet Protocol version 4)

Class Practical IP Range Subnet Mask Number of Networks Practical Use


Class A [Link] – [Link] [Link] 1 Large enterprises
Class B [Link] – [Link] [Link] 16 Medium
organizations
Class C [Link] – [Link] [Link] 256 Home/small
office networks
▪ Format: Four octets (e.g., [Link])
▪ Range: [Link] to [Link]
▪ Total Addresses: ~4.3 billion
IPv6 (Internet Protocol version 6)
o Format: Eight groups of hexadecimal (e.g., 2001:0db8:85a3::8a2e:0370:7334)
o Total Addresses: 340 undecillion (virtually unlimited)
Components of an IP Address:
• Network Portion: Identifies the network
• Host Portion: Identifies the specific device
• Subnet Mask: Divides IP into network and host portions (e.g., [Link])
Example:
IP Address: [Link]
Subnet Mask: [Link]
Network ID: [Link]
Host ID: 25

Reserved Address Ranges for Local Use

These addresses are reserved for private networks.

Practical Private IP Ranges (RFC 1918):


Advantages:
Address Conservation: Saves public IPv4 addresses
Security: Not directly accessible from internet
Reusability: Same ranges can be used in different private networks
Practical Example:
Your home Wi-Fi router typically uses 192.168.1.x or 192.168.0.x range.
Loopback IP Address
A loopback address allows a computer to communicate with itself. A special IP address used by
a computer to refer to itself.
Address:
[Link] – also known as localhost
Loopback Details:
 IPv4 Loopback: [Link] (most common)
 IPv4 Loopback Range: [Link] – [Link]
 IPv6 Loopback: ::1
 Hostname: localhost
Practical Uses:
❖ Testing TCP/IP Stack: Check if network software is working
❖ Local Development: Run web servers locally ([Link]
❖ Troubleshooting: Verify network configuration.

Commands Example:

ping [Link] # Test local network stack


ping localhost # Same as above
[Link] # Access local web server
A web developer tests a website on their computer using localhost before deploying to a live
server.
VLANs (Virtual Local Area Networks)
A VLAN is a logical subdivision of a network that groups devices together, regardless of their
physical location.
How it Works:
 Uses managed switches with VLAN support
 Devices are assigned to VLANs by port or MAC address
 Each VLAN acts as a separate broadcast domain
Advantages:
Improved Security: Isolates sensitive data (e.g., HR from Sales)

Better Performance: Reduces broadcast traffic


Easier Management: Logical grouping instead of physical rewiring

Cost-Effective: Uses existing infrastructure


Configuration Example:
VLAN ID Department IP Range
VLAN 10 HR [Link]/24
VLAN 20 IT [Link]/24
VLAN 30 Sales [Link]/24
VLAN 99 Management [Link]/24

Practical Scenario:
In a school, separate VLANs for students, teachers, and administration prevent students from
accessing administrative resources.
Wired LAN (Local Area Network)
A network where devices are connected using physical cables (Ethernet).
Characteristics:
Feature Details
Cable Types Cat5e, Cat6, Cat6a, Cat7, Fiber Optic
Speed 100 Mbps – 100 Gbps
Standard IEEE 802.3 (Ethernet)
Topology Star (most common), Bus, Ring
Hardware Switch, Router, NIC, Cables

Advantages:
High Speed: Faster than wireless
Stable Connection: No interference

Secure: Hard to intercept


Reliable: Less prone to drops
Disadvantages:
Limited Mobility: Devices must stay connected

Installation Cost: Requires cabling infrastructure


Maintenance: Physical wear and tear
Use Cases:
o Office desktops
o Data centres
o Gaming setups
o CCTV systems
Wireless LAN (WLAN)
A network where devices connect using radio waves (Wi-Fi) instead of cables.
Characteristics:
Feature Details
Standard IEEE 802.11 (a/b/g/n/ac/ax)
Speed 11 Mbps (802.11b) to 9.6 Gbps (Wi-Fi 6E)
Frequency 2.4 GHz, 5 GHz, 6 GHz (Wi-Fi 6E)
Range 30-100 meters indoors
Hardware Wireless Router/Access Point, Wireless NIC

Wi-Fi Standards:
Standard Name Max Speed Frequency
802.11b Wi-Fi 1 11 Mbps 2.4 GHz
802.11g Wi-Fi 3 54 Mbps 2.4 GHz
802.11n Wi-Fi 4 600 Mbps 2.4/5 GHz
802.11ac Wi-Fi 5 3.5 Gbps 5 GHz
802.11ax Wi-Fi 6 9.6 Gbps 2.4/5/6 GHz

Advantages:
Mobility: Connect from anywhere in range
Easy Setup: No cabling required

Scalability: Easy to add devices


Cost-Effective: Lower installation cost
Disadvantages:
Security Risks: Vulnerable to eavesdropping

Interference: Walls, devices affect signal


Slower: Generally slower than wired

Limited Range: Needs repeaters for large areas


Security Standards:
▪ WEP (Weak - obsolete)
▪ WPA (Better)
▪ WPA2 (Good)
▪ WPA3 (Best - current standard)
Use Cases:
➢ Home networks
➢ Coffee shops, airports (public hotspots)
➢ Mobile devices (smartphones, tablets)
➢ IoT devices
Comparison: Wired vs Wireless LAN
Factor Wired LAN Wireless LAN
Speed Higher (up to 100 Gbps) Lower (up to 9.6 Gbps)
Security More secure Less secure
Mobility Limited High
Installation Complex (cabling) Simple
Cost Higher initial cost Lower initial cost
Reliability Very reliable Can be affected by interference
Practical Use Offices, data centres Homes, cafes, mobile users
SUMMARY
Key Speeds:
Dial-Up = 56 Kbps
ISDN = 128 Kbps
T1 = 1.544 Mbps
E1 = 2.048 Mbps
E3 = 34.368 Mbps
T3 = 44.736 Mbps
Private Address Ranges:
[Link] – [Link]
[Link] – [Link]
[Link] – [Link]
Loopback Address:
[Link]
Difference Between Client and Server Computers
Introduction

In a computer network, communication often follows the client-server model. In this model, one
computer requests services or resources, while another computer provides those services or
resources. The computer requesting services is called a Client, while the computer providing
services is called a Server.

Client Computer

A Client Computer is a computer that requests data, resources, or services from another computer
(server) on a network. A client depends on a server to access information or resources.
Examples of Client Computers

• Desktop computers
• Laptops
• Smartphones
• Tablets

Functions of a Client

1. Sends requests to the server.


2. Accesses shared files and resources.
3. Receives services from the server.
4. Displays information to users.

Example

When a student opens a web browser and visits a website, the student's computer acts as a client
because it requests web pages from a web server.

Server Computer

A Server Computer is a powerful computer that provides resources, services, or data to client
computers over a network. A server waits for requests from clients and responds accordingly.

Examples of Servers

• File Server
• Database Server
• Web Server
• Mail Server
• Print Server

Functions of a Server
1. Stores data and files.
2. Processes client requests.
3. Provides network resources.
4. Controls access to information.
5. Manages network services.

Example

When a student accesses the Polytechnic result portal, the server stores and provides the result
information requested by the student's computer.

Client-Server Relationship

Explanation

• The clients send requests.


• The server processes the requests.
• The server sends responses back to the clients.

Differences Between Client and Server Computers


Client Computer Server Computer
Requests services from a server Provides services to clients
Initiates communication Responds to requests
Usually less powerful Usually more powerful
Used directly by end users Usually managed by administrators
Requires server resources Provides resources
Stores limited data Stores large amounts of data
Examples: Laptop, Desktop, Examples: Web Server, Database Server, File
Smartphone Server

Practical Example in a Polytechnic


Client Computers

• Students' laptops
• Lecturers' desktops
• Library computers

Server Computers

• Student records server


• School website server
• E-learning server
• Examination database server

Scenario

A student logs into the Polytechnic portal to check results.

1. The student's laptop sends a request.


2. The result server receives the request.
3. The server searches its database.
4. The server sends the result back to the student's laptop.

In this case:

• Student's laptop = Client


• Result database system = Server

Characteristics of a Client Computer

1. Used by end users.


2. Requests network services.
3. Usually has lower processing power than servers.
4. Depends on servers for shared resources.

Characteristics of a Server Computer

1. Provides services continuously.


2. Operates 24/7 in many organizations.
3. Has high processing power.
4. Has large storage capacity.
5. Supports multiple users simultaneously.

Advantages of Client-Server Networks

1. Centralized data management.


2. Better security.
3. Easier backup and recovery.
4. Efficient resource sharing.
5. Supports many users.

Disadvantages of Client-Server Networks

1. High setup cost.


2. Requires skilled administrators.
3. Server failure may affect many users.
4. Maintenance costs can be high.

Easy Memory Tip

Client = Requests Services

Server = Serves Services

Think of a restaurant:
• Customer → Client (requests food)
• Kitchen/Chef → Server (provides food)

Similarly, in networking:

• Client requests data.


• Server provides data.

Other Comparison Between Client and Server


Hardware Requirements
Client Computer:
i. Standard consumer-grade components
ii. Focus on user experience (graphics, display quality)
iii. Single hard drive is sufficient
iv. Practical Example: Dell laptop with Intel i5, 8GB RAM, 512GB SSD

Server Computer:
i. Enterprise-grade components
ii. Focus on reliability and performance
iii. RAID storage for data redundancy
iv. Redundant power supplies
v. ECC (Error-Correcting Code) RAM
vi. Practical Example: Dell PowerEdge server with dual Xeon processors, 128GB ECC RAM,
10TB RAID storage

Operating Systems
Client Computer:
1. Windows: Windows 10, Windows 11
2. macOS: For Apple computers
3. Linux: Ubuntu, Fedora (desktop versions)
4. Focus on user-friendly GUI

Server Computer:
1. Windows Server: 2016, 2019, 2022
2. Linux Server: Ubuntu Server, CentOS, Red Hat Enterprise Linux
3. Unix: FreeBSD, Solaris
4. Often runs without GUI (command-line interface)

Performance
Client Computer:
▪ Handles individual user tasks
▪ Performance measured in user experience
▪ Can idle or sleep when not in use
▪ Practical Example: Running Microsoft Word, browsing websites

Server Computer:
• Handles multiple simultaneous connections
• Performance measured in throughput and response time
• Must maintain consistent performance 24/7
• Practical Example: Processing 10,000 database queries per second

Availability & Reliability


Client Computer:
Can be shut down daily
Occasional downtime is acceptable
Basic backup solutions
Practical Uptime: 8-16 hours/day

Server Computer:
❖ Must be always available (99.9%+ uptime)
❖ Downtime can cost thousands per minute
❖ Advanced backup and disaster recovery
❖ Hot-swappable components
❖ Practical Uptime: 24/7/365 (99.99% or higher)

Security
Client Computer:
➢ User-level security
➢ Antivirus software
➢ Personal firewall
➢ Protects individual user data
➢ Practical Measures: Windows Defender, password protection

Server Computer:
✓ Enterprise-level security
✓ Multiple layers of protection
✓ Access control lists (ACLs)
✓ Intrusion detection systems
✓ Regular security audits
✓ Practical Measures: Firewalls, DMZ, encryption, authentication servers

Maintenance
Client Computer:
o User performs basic maintenance
o Occasional updates and patches
o Individual troubleshooting
o Practical Tasks: Update software, virus scans, disk cleanup

Server Computer:
• Requires professional IT staff
• Scheduled maintenance windows
• Continuous monitoring
• Automated updates and patches
• Practical Tasks: Performance monitoring, log analysis, security patches, hardware
monitoring

Differentiating Between Wired and Wireless Networks


A computer network allows computers and other devices to communicate and share resources.
Based on the transmission medium used, networks can be classified into:
1. Wired Network
2. Wireless Network
The major difference is that a wired network uses physical cables for communication, while a
wireless network uses radio waves.
Wired Network
A Wired Network is a network in which computers and devices are connected using physical
cables such as Ethernet cables or fiber-optic cables.
Wireless Network
A Wireless Network is a network in which devices communicate using radio waves without the
use of physical cables. The most common wireless technology is Wi-Fi.
Difference Between Wired and Wireless Networks
Feature Wired Network Wireless Network
Definition A network that uses physical A network that uses radio waves to
cables to connect devices. connect devices without cables.
Transmission Ethernet cables, fiber-optic Radio waves, Wi-Fi signals, infrared
Medium cables, coaxial cables. signals.
Speed Generally faster and more stable. Generally slower than wired networks.
Security More secure because physical Less secure because signals can be
access is required. intercepted.
Reliability Highly reliable with minimal Can be affected by interference from
interference. walls, weather, and electronic devices.
Mobility Limited mobility; devices must High mobility; users can move around
remain connected by cables. while connected.
Installation More difficult and expensive due Easier and quicker to install.
to cabling requirements.
Maintenance Cable faults may require physical Easier to maintain but may require
repairs. signal troubleshooting.
Cost Higher installation cost because Lower installation cost due to reduced
of cables and network cabling.
equipment.
Network Adding new devices may require New devices can be added easily
Expansion additional cabling. within signal coverage.
Performance Consistent performance even Performance may decrease when
with many users. many users are connected.
Examples Computer laboratories, banks, Campus Wi-Fi, home Wi-Fi, mobile
offices, data centres. hotspots.

Computer Network Hardware Components


Introduction
Network hardware components are physical devices used to connect computers and other devices
in a network. They facilitate communication, data transmission, and resource sharing among
connected devices.

The major network hardware components include:

1. Router
2. Switch
3. Repeater
4. Gateway
5. Network Cables

1. Router
A router is a device that connects two or more different networks together and routes data
packets between them using IP addresses. It operates at Layer 3 (Network layer) of the OSI
model. Every home that has internet service has a router, it connects your local home
network to your ISP's network. In Nigeria, routers are used in every bank branch, office,
and polytechnic to connect the local network to the internet. A router reads the destination
IP address of each packet and decides the best path for it to travel. It maintains a routing
table a map of known networks and how to reach them.
Functions of a Router

• Connects different networks.


• Directs data packets to their destinations.
• Connects a LAN to the Internet.
• Performs Network Address Translation (NAT).
• Provides security through firewall features.

Characteristics

• Operates at the Network Layer (Layer 3) of the OSI Model.


• Uses IP addresses.
• Connects multiple networks.

Key router facts: works at OSI Layer 3 (Network layer), uses IP addresses for forwarding
decisions, connects different networks (not just different devices), supports both wired and
wireless connections, and performs NAT (Network Address Translation) to allow many private IP
addresses to share one public IP.
2. Switch
A switch connects multiple devices within the same network (LAN). It operates at Layer 2
(Data Link layer) using MAC addresses to forward frames only to the correct destination
port unlike a hub which sends data to every port. Every computer lab in a Nigerian
polytechnic uses a switch to connect all the computers together. A switch builds a MAC
address table by learning which device is connected to which port. When a frame arrives,
the switch looks up the destination MAC address and sends it only to that port.
Functions of a Switch
• Connects devices within a LAN.
• Reduces network traffic.
• Improves network performance.
• Forwards data using MAC addresses.
Characteristics

• Operates at the Data Link Layer (Layer 2).


• Uses MAC addresses.
• Intelligent device.
• Faster than a hub.
Key switch facts: works at OSI Layer 2 (Data Link layer), uses MAC addresses, creates separate
collision domains per port, reduces network congestion, supports full-duplex communication (send
and receive at the same time), and is the foundation of every modern wired LAN.

3. Repeater
A repeater is the simplest network device. Its only job is to receive a weak or degraded
signal and retransmit it at full strength. As data travels along a cable, the signal gets weaker
over distance (this is called attenuation). The repeater boosts the signal so it can travel
further. It operates at Layer 1 (Physical layer) it does not read addresses or make any
decisions; it simply regenerates the signal.
Functions of a Repeater

• Receives weak signals.


• Amplifies and retransmits signals.
• Extends network coverage.

Characteristics

• Operates at the Physical Layer (Layer 1).


• Does not understand data content.
• Simply boosts signals.
Key repeater facts: works at OSI Layer 1 (Physical layer) only, has no intelligence — cannot filter
or direct traffic, extends the maximum cable distance of a network, commonly used with fibre
optic or long Ethernet cable runs, and does not reduce collisions or improve network performance
beyond distance extension.
4. Gateway
A gateway is the most intelligent network device. It translates between two completely
different network protocols or architectures. While a router connects networks that use the
same protocol (TCP/IP to TCP/IP), a gateway translates between networks that speak
different languages entirely — for example, connecting a TCP/IP network to an older IBM
SNA mainframe network, or converting email formats between different systems. A
gateway operates at all layers of the OSI model (Layer 1 through Layer 7) when full
protocol translation is needed.
Functions of a Gateway
• Connects different networks.
• Converts data formats and protocols.
• Controls network access.
• Enables communication between incompatible systems.

Characteristics

• Can operate at multiple OSI layers.


• Acts as a protocol converter.
• More complex than routers and switches.

Key gateway facts: works at all 7 OSI layers, performs full protocol translation (not just routing),
is the most complex and expensive network device, commonly used to connect modern IP
networks to older legacy systems, and in simple home networks the word "gateway" is
sometimes used loosely to mean the router/modem combination.
5. Network Cables
Cables are the physical medium that carry data signals between devices in a wired
network. Different cable types suit different speeds, distances, and environments.
Types of network cables:

1. Coaxial Cable
Coaxial cable (or "coax") was the backbone of early Ethernet networks and is still used for
cable TV, DSTV dish connections, and some broadband internet. It has a central copper
conductor surrounded by insulation, then a metallic braid or foil shield, then an outer plastic
jacket. The shield protects the signal from electromagnetic interference (EMI). The name
"coaxial" means both the inner conductor and the outer shield share the same axis.
Sub-Types:
RG-6 – Standard coax for cable TV/internet
RG-59 – Older CCTV and video
RG-11 – Long-distance, thicker
Examples / Use Cases:
• Cable internet (ISP connections)
• Antenna/satellite connections
• CCTV surveillance systems
• Old Ethernet 10BASE2
Real-world examples of coaxial cable use: connecting a DSTV decoder to a satellite dish, the old
10BASE2 (Thinnet) and 10BASE5 (Thicknet) Ethernet networks, cable TV distribution in housing
estates, and some broadband cable internet connections. Two common types are RG-58 (thin coax,
used in old computer networks) and RG-6 (thick coax, used for TV and broadband).

2. UTP — Unshielded Twisted Pair (Cat5e)


UTP is the most widely used network cable in the world today. It contains 8 copper wires
organised into 4 twisted pairs. The twisting is deliberate; it causes interference from each
wire in a pair to cancel out the interference from its partner (this is called cancellation).
UTP has no metal shield, which makes it lighter and cheaper than STP. Cat5e is the
standard cable in virtually every Nigerian polytechnic lab, office, and home network.
Twisted Pair cables consist of pairs of copper wires twisted together. Twisting reduces
electromagnetic interference (EMI) between pairs. It is the most widely used cable in local
area networks (LANs).
Sub-Types:
▪ UTP – Unshielded Twisted Pair (common in offices)
▪ STP – Shielded Twisted Pair (industrial environments)
Examples / Use Cases:
• Cat5e – 1 Gbps, up to 100m
• Cat6 – 10 Gbps, up to 55m
• Cat6a – 10 Gbps, up to 100m
• Cat7 – 10+ Gbps, heavily shielded
The T568B colour wiring order for a Cat5e/Cat6 straight-through cable (used in Nigerian
polytechnic practicals): White/Orange → Orange → White/Green → Blue → White/Blue →
Green → White/Brown → Brown.
3. Fiber Optic Cable
Fiber Optic cables transmit data as pulses of light through glass or plastic strands. They
offer the highest speed, longest distance, and complete immunity to EMI. Used by ISPs,
telecoms, and data centres.
Sub-Types:
• Single-Mode (SMF) – Very long distances, laser light
• Multi-Mode (MMF) – Shorter distances, LED light
Examples / Use Cases:
• OS1/OS2 – Single-mode telecom fiber
• OM3/OM4 – Multi-mode data centre fiber
• Internet backbone between cities
• Hospital/university campus networks.

Summary of Network Hardware Components


Device Function
Router Connects different networks and routes data
Switch Connects devices within a LAN
Repeater Regenerates weak signals
Gateway Connects networks using different protocols
Network Cable Provides physical connection for data transmission

Hub vs Switch — Full Comparison

This is one of the most common exam questions. Both devices connect multiple computers in a
LAN, but they work in completely different ways.

• A hub is a "dumb" device — it has no intelligence. When it receives a frame on any port,
it immediately broadcasts (sends) that frame out through every other port, even if only one
device is the intended recipient. Every device must check whether the frame was meant for
them, and most of the time it was not.
• A switch is an "intelligent" device. It learns which MAC address is connected to which
port and stores this in a MAC address table. When a frame arrives, it looks up the
destination MAC address and sends the frame only to that specific port. All other devices
never see the frame at all.

Difference Between Hub and Switch


Feature Hub Switch
Definition A hub connects devices and A switch connects devices and sends
broadcasts data to all devices. data only to the intended device.
Intelligence Not intelligent. Intelligent device.
Data Sends data to all connected Sends data to the specific destination
Transmission devices. device.
Performance Slower. Faster.
Traffic Creates more network traffic. Reduces network traffic.
Management
Collision One collision domain. Separate collision domain for each
Domain port.
Security Less secure. More secure.
Operating Layer Physical Layer (Layer 1). Data Link Layer (Layer 2).
MAC Address Does not use MAC addresses. Uses MAC addresses to forward data.
Usage
Cost Cheaper. More expensive.

Functions of Network Hardware Components with respect to routing data, traffic, remote
connections, switching types and MAC table.
Routing Data and Traffic: Routing is the process of selecting the best path for data to travel
from a source to a destination.
Remote Connections: Routers enable remote communication between geographically separated
networks.
SWITCHING: Switching is the process of directing data from one device to another within a
network. A switch forwards data only to the intended recipient.
Types of Switching
Circuit Switching A dedicated path is reserved for the entire duration of communication
Dedicated Path Connection-Oriented Traditional Telephony
In Circuit Switching, a dedicated physical path (circuit) is established between sender and
receiver before any data is sent. This path is reserved exclusively for the duration of the
communication no other user can use those links. Once the session ends, the circuit is torn down
and resources are released. This is how the traditional telephone network (PSTN) works.
How It Works. Step by Step
Step 1 — Circuit Setup: A dedicated end-to-end path is established through the network (call setup
signaling).
Step 2 — Data Transfer: Data flows continuously along the reserved path with fixed bandwidth.
Step 3 — Circuit Teardown: When done, the circuit is released and resources freed for others.
Advantages
• Guaranteed, constant bandwidth throughout session
• Predictable, fixed latency ideal for real-time voice
• No congestion once circuit is established
• Simple receiver no reassembly needed
Disadvantages
• Wastes bandwidth when no data is flowing (e.g., silence)
• Setup delay before communication begins
• Expensive resources locked even if idle
• Not scalable for bursty data like internet traffic
Key Properties

Attribute Detail

How path is set Dedicated circuit reserved before data flows

OSI Layer Layer 1 (Physical Circuit)

Connection type Connection-Oriented (setup required)

Bandwidth Fixed, guaranteed, reserved

Latency Predictable and constant (no queuing)

Wasted bandwidth? Yes — idle time still holds the circuit

Error handling None — relies on physical link quality


Real-world example PSTN telephone, ISDN, old dial-up modems

Modern use Legacy voice networks, some leased lines

Packet Switching: Data is split into packets; each routes independently across the network
Connectionless Most Efficient Basis of Internet
In Packet Switching, data is broken into small chunks called packets. Each packet contains
a header (with source IP, destination IP, sequence number) and a payload. Packets are
sent independently each one may take a different route through the network, and they
are reassembled in the correct order at the destination. This is the foundation of the modern
internet.
How It Works — Step by Step
Step 1 — Segmentation: Message is divided into numbered packets at the source.
Step 2 — Independent Routing: Each packet is routed separately — may take different paths.
Step 3 — Store-and-Forward: Routers receive, inspect, and forward each packet toward
destination.
Step 4 — Reassembly: Destination collects all packets and reassembles in order using sequence
numbers.
Advantages
• Highly efficient bandwidth shared dynamically
• Resilient packets reroute around failures
• Scales to billions of devices (the internet)
• Bursty traffic handled well no wasted reserved capacity
Disadvantages
• Variable latency (packets queue at routers)
• Packets can arrive out-of-order (need reassembly)
• Overhead per packet (headers on every packet)
• No guaranteed bandwidth congestion possible
Key Properties

Attribute Detail

How path is set No fixed path — each packet routed independently

OSI Layer Layer 3 (Network — IP)

Connection type Connectionless (UDP) or Connection-Oriented (TCP)

Bandwidth Shared dynamically — no reservation

Latency Variable (depends on congestion, queue depth)

Wasted bandwidth? No — idle links used by other traffic

Error handling TCP: retransmit lost packets | UDP: none


Message Switching: Whole message stored at each node, then forwarded — no path reserved
Store-and-Forward No Dedicated Path Pre-Internet Era
In Message Switching, the entire message (not broken into packets) is transmitted to an
intermediate node, which stores the complete message and then forwards it to the next node when
a link becomes available. This is the "store-and-forward" model at the message level. Think of it
like a postal relay system the letter travels whole from post office to post office. It was used in
early telegraph networks and email systems before packet switching.
How It Works Step by Step
Step 1 — Send Full Message: The entire message is transmitted to the first intermediate node.
Step 2 — Store: The node stores the complete message in memory/disk.
Step 3 — Forward: When the next link is free, the node forwards the entire message to the next
node.
Step 4 — Repeat: Each hop stores and forwards the whole message until it reaches the destination.

Advantages
• No dedicated circuit needed links shared
• Message delivered even if destination temporarily unavailable
• Simple routing no packet reassembly needed
• Reliable delivery through store-and-forward hops
Disadvantages
• High latency entire message stored at every hop
• Requires large storage at every intermediate node
• A large message blocks the link until fully forwarded
• Not suitable for real-time communication at all
Key Properties
Attribute Detail

How path is set No fixed path message forwarded hop by hop

OSI Layer Application / Data Link concept (pre-OSI)

Connection type Connectionless no circuit setup

Bandwidth Shared, but a large message monopolizes a link

Latency Very high delays at each node

Wasted bandwidth? No but links blocked by large messages

Error handling Retransmit whole message if error detected

Real-world example Telegraph relay, Email (SMTP), telex systems

Modern use Email (descendant), SMS store-and-forward, MMS

All Three Types Full Comparison

Criteria Circuit Switching Packet Switching Message Switching

Path Dedicated fixed No fixed path (per No fixed path (per


circuit packet) message)

Data unit Continuous bit Small packets Entire message


stream (chunks)

Bandwidth Reserved, wasted if Shared dynamically Shared (but can


idle block)

Latency Fixed, low (after Variable (congestion) Very high (stored


setup) each hop)
Storage needed None Small (buffer per Large (whole
packet) message)

Real-time Excellent Good (with QoS) Poor


suitability

Fault tolerance Circuit breaks = Packets reroute Message re-sent


fail

Scalability Poor Excellent Limited

Example PSTN phone call Internet / TCP/IP Email (SMTP),


Telegraph

Virtual Switch (vSwitch) Software-Defined Switching


A Virtual Switch (vSwitch) is a software Layer 2 switch running inside a hypervisor. It connects
Virtual Machines (VMs) to each other and to the physical network, using the same MAC learning
and VLAN logic as a physical switch but entirely in software.
Functions
• Connects virtual machines.
• Manages virtual network traffic.
• Provides network isolation.
Example
Used in:
• VMware
• Hyper-V
• VirtualBox
vSwitch vs Physical Switch

Feature Physical Switch Virtual Switch (vSwitch)

Location Dedicated hardware Software in hypervisor

MAC Learning Hardware ASIC Software

VLANs Full 802.1Q Port Groups per VLAN

Performance Line-rate (very fast) Limited by CPU/RAM

Examples Cisco Catalyst, HP Aruba VMware vDS, Hyper-V vSwitch, OVS

Management CLI / Web UI Hypervisor management tool

MAC Address Table: A MAC Address Table is a database maintained by a switch that maps
MAC addresses to switch ports.
Example:
MAC Address Port
AA:11:22:33 Port 1
BB:44:55:66 Port 2
Function
Allows switches to send data only to the correct destination.
Repeater Function & Role (OSI Layer 1: Physical)
A Repeater works at the Physical Layer. Its sole job is to receive a degraded electrical/optical
signal, clean it, amplify it, and retransmit it so data can travel beyond the cable's normal distance
limit. It has zero intelligence it cannot read MAC addresses or IP addresses.

Routing Data Through Repeater


A repeater does NOT route data. It blindly regenerates every bit of signal on the wire. It cannot
distinguish between traffic types all bits are treated equally. Data routing is handled by Layer 3
(Router).

Feature Repeater

Reads IP address No

Reads MAC address No

Filters traffic No

Direction of data Both ways (bi-directional)

Broadcasts Yes, amplifies everything


amplified

Repeater Traffic & Collision Domain


Because a repeater blindly retransmits all signals, every device connected through a repeater shares
a single collision domain. When two devices transmit simultaneously the signals collide and both
must retransmit using CSMA/CD (Carrier Sense Multiple Access with Collision Detection).
CSMA/CD Process (Collision Handling)

Step Action

1. Sense Device listens is the channel free?

2. Transmit If free, start sending data frame

3. Detect Collision Detects if another device transmitted at same time

4. Jam Signal Send 32-bit jam signal to alert all devices

5. Back Off All devices wait a random time (exponential backoff)

6. Retry Retransmit after backoff period

Bridge Function (OSI Layer 2: Data Link)


A Bridge connects two or more network segments and uses MAC addresses to intelligently filter
and forward frames. It learns which MAC addresses exist on which segment by reading source
MACs from incoming frames and builds a MAC Address Table dynamically.
MAC Address Table. How Bridge Learns
Every time a frame arrives, the bridge reads the source MAC and records which port it came from.
This is called MAC learning. The table ages out entries (default 300 seconds) to handle device
moves.

Learned
MAC Address Port Age Action
From

AA:BB:CC:11:22:33 Port PC-A1 frame 12s Frames to AA:BB stay on Port 1


1

DD:EE:FF:44:55:66 Port PC-A2 frame 45s Frames to DD:EE stay on Port 1


1

11:22:33:AA:BB:CC Port PC-B1 frame 5s Frames to 11:22 go to Port 2


2

Unknown / New — Not yet seen — FLOOD: Send to all ports except
source

Bridge Traffic & Segmentation


The key value of a bridge is traffic segmentation. It breaks a large network into smaller collision
domains. Intra-segment traffic (within same side) stays local and never crosses the bridge, reducing
overall traffic and improving performance.
Without Bridge (One Collision Domain):
• All traffic seen by all devices
• Collisions affect entire network
• Bandwidth shared by all
• Broadcast storms propagate everywhere
With Bridge (Two Collision Domains):
• Local traffic stays local
• Collisions isolated per segment
• Only inter-segment traffic crosses
• Broadcasts still cross (limitation)
Bridge Limitations vs Switch

Feature Bridge Switch

Number of ports 2–4 ports 8–48+ ports

MAC table size Small Very large (thousands)

Speed Software-based Hardware ASICs (fast)

VLAN support Limited Full VLAN support

Spanning Tree Basic STP RSTP, MSTP

Use today Rare Standard everywhere

Router Routing Data & Traffic (OSI Layer 3: Network)


A Router is the most intelligent forwarding device. It operates at Layer 3 (Network Layer) using IP
addresses to make forwarding decisions. It maintains a Routing Table a database of all known
networks and the best path to reach each one.
Routing Table. How Router Forwards Packets
The router looks at the destination IP in each packet and matches it against its routing table
using Longest Prefix Match the most specific route wins.

Destination Subnet
Next Hop Interface Route Type Metric
Network Mask

[Link] /24 Directly Eth0 Connected 0


Connected (C)

[Link] /24 [Link] Eth1 Static (S) 1

[Link] /16 [Link] Eth1 OSPF (O) 110

[Link] /0 [Link] Eth2 Default (S*) 1

Default route [Link]/0 = "send anything unknown to the internet"


Router. Remote Connections & WAN
Routers are the gateway between private local networks and the outside world. They support
multiple types of WAN/remote connection technologies to link branch offices, remote workers,
and cloud services.
Remote Connection Technologies

Technology How It Works Use Case Speed

IPSec VPN Encrypts IP packets, tunneled Site-to-site office Up to 1Gbps


over internet links

SSL/TLS VPN Encrypted browser-based Remote workers, Up to


tunnel (port 443) HTTPS 500Mbps

MPLS Label-switched private network Enterprise WAN, Up to


through ISP QoS 10Gbps

SD-WAN Software-defined WAN across Cloud-first Variable


multiple links enterprises

Leased Line Dedicated physical circuit from Guaranteed 1.5–45Mbps


(T1/T3) ISP bandwidth

Serial/Console Direct RS-232 or USB Router 9600 baud


management link configuration

HUB VS SWITCH Capabilities


HUB Capabilities (Layer 1) SWITCH Capabilities (Layer 1)
A Hub is simply a multiport repeater. It A Switch uses MAC address table to send
rebroadcasts every incoming signal to ALL frames only to the correct destination port.
ports. It has no intelligence no MAC table, Each port is its own collision domain. Full-
no filtering, no full-duplex. Every port share duplex, dedicated bandwidth per port,
one collision domain supports VLANs, QoS, Port Security.

Feature Hub

OSI Layer Layer 1

MAC Table None

Collision Domains 1 (shared by all)

Broadcast Domains 1

Duplex Half-duplex only

Bandwidth Shared by all ports

VLAN No

Feature Switch
OSI Layer Layer 2 (L3 for managed)

MAC Table Dynamic learning

Collision Domains 1 per port (isolated)

Broadcast Domains 1 (unless VLANs used)

Duplex Full-duplex

Bandwidth Dedicated per port

VLAN Full support

Switch MAC Address Table Dynamic Learning


When a frame enters a switch port, the switch reads the source MAC → logs port + MAC. When
forwarding, it looks up the destination MAC. If found → send to that port only. If unknown →
flood.

MAC Address Port VLAN TTL (Age) Status

AA:BB:CC:11:22:33 Fa0/1 10 280s Active

DD:EE:FF:44:55:66 Fa0/3 10 45s Active

11:22:33:AA:BB:CC Fa0/7 20 12s Active

FF:FF:FF:FF:FF:FF ALL ALL — Broadcast →


Flood

Unknown destination ALL except same VLAN — Unicast Flood


source

Static Routing
Routes are manually typed by the network admin. The router does not learn or adapt. If a link goes
down, traffic stops unless admin manually updates the route.
ip route [Link] [Link] [Link]
ip route [Link] [Link] [Link]

Attribute Value

Configuration Manual (admin types


each route)

Adaptability None fixed

CPU Usage Very Low

Scalability Poor small networks


only

Security No routing update


exposure

Best For Stub networks, default


routes

Dynamic Routing
Routers automatically discover and share routes using a routing protocol. They update routing
tables in real-time when the network topology changes.
router ospf 1
network [Link] [Link] area 0
network [Link] [Link] area 0

Attribute Value

Configuration Protocol-driven auto-


discovery

Adaptability Auto-reroutes on failure

CPU Usage Medium-High (updates)


Scalability Scales to thousands of
routers

Security Routing updates can be


spoofed

Best For Enterprise, ISP, campus


networks

Routing Protocol Categories

Category Protocols Shares Algorithm

Distance Vector RIP, EIGRP Full routing table to neighbours Bellman-Ford

Link State OSPF, IS-IS LSAs (topology maps) Dijkstra (SPF)

Path Vector BGP Full paths (AS paths) Policy-based

Hybrid EIGRP Partial updates on change DUAL

RIP Routing Information Protocol


Distance Vector Bellman-Ford
Each router sends its entire routing table to neighbours every 30 seconds, regardless of changes.
Routes are chosen by hop count only maximum 15 hops (16 = unreachable).

Attribute RIP v1 RIP v2

Metric Hop Count (max 15)

Update interval Every 30 seconds


Convergence Slow (minutes)

Admin Distance 120

VLSM/CIDR No Yes

Authentication MD5

Multicast Broadcast [Link]


updates

OSPF — Open Shortest Path First


Link State Dijkstra SPF
Each router builds a complete map of the network topology (LSDB) and runs Dijkstra's Shortest
Path First algorithm to calculate the best route. Updates sent only when topology changes (LSA
flooding).

Attribute OSPF

Metric Cost (100Mbps/link


BW)

Update trigger On topology change


(LSA)

Convergence Fast (seconds)

Admin Distance 110

VLSM/CIDR Full support


Authentication MD5 / SHA

Areas Hierarchical (Area


0=backbone)

Max network Unlimited (area


size design)

RIP vs OSPF Side by Side

Criteria RIP OSPF Winner

Speed of Slow (30s+ updates) Fast (LSA on change) OSPF


convergence

Scalability Max 15 hops Unlimited with areas OSPF

Metric accuracy Hop count only Bandwidth-based cost OSPF

Complexity Very simple Complex (areas, RIP (simpler)


DR/BDR)

Bandwidth usage High (full table every Low (only on change) OSPF
30s)

Use case Small/lab networks Enterprise/ISP Depends on


size

NAT - Network Address Translation


NAT allows an entire private network (with private IPs like 192.168.x.x) to share a single public
IP address when accessing the internet. The router maintains a NAT Translation Table to track
which internal device made each connection, so return traffic is delivered correctly.
NAT Translation Table Example

Private IP : Port Public IP : Port Protocol Destination

[Link]:1050 [Link]:5001 TCP [Link]:80

[Link]:1051 [Link]:5002 TCP [Link]:443

[Link]:1052 [Link]:5003 UDP [Link]:53

Return traffic arrives at [Link] → router checks port → sends to correct private IP
Types of NAT

NAT Type Mapping How It Works Common Use

Static NAT 1 private ↔ 1 Fixed permanent mapping Web servers, mail


public same public IP always servers needing fixed
assigned IP

Dynamic Many private → Router assigns from a pool Organizations with


NAT pool of public of public IPs on demand multiple public IPs

PAT (NAT Many private → 1 Tracks connections using Home routers, small
Overload) public (port- port numbers most offices (default)
based) common type

NAT64 IPv6 → IPv4 Translates between IPv6 IPv6-only networks


and IPv4 addresses reaching IPv4 internet
QoS - Quality of Service
QoS is a set of network techniques that prioritize certain types of traffic over others. When
bandwidth is limited, QoS ensures critical real-time traffic (VoIP calls, video conferencing) gets
through first while less urgent traffic (file downloads, backups) waits.

QoS Mechanisms - Detailed

Mechanism What It Does Example

Classification Identify traffic type by IP, port, Port 5060 = SIP/VoIP;


protocol, or DSCP value Port 80 = HTTP

Marking (DSCP) Stamp packets with a priority value EF=VoIP, AF41=Video,


in IP header TOS field CS0=Best Effort

Queuing (CBWFQ) Assign traffic to separate queues VoIP=30%, Video=40%,


with guaranteed bandwidth % Data=30%

Scheduling (LLQ) Always serve the priority queue VoIP queue served every
first before others cycle

Shaping Smooth bursty traffic — buffer Limit video to 2Mbps


excess to stay within rate average

Policing Drop or re-mark packets that Drop excess if backup >


exceed agreed rate 5Mbps
Congestion Selectively drop low-priority Drop best-effort before
Avoidance (WRED) packets early before queue fills VoIP

DSCP Marking Values (Common)

DSCP Class Decimal Traffic Type Drop Priority

EF (Expedited Forwarding) 46 VoIP, real-time Never dropped

AF41 34 Video conferencing Low

AF21 18 Business data Medium

CS0 / BE 0 Default / Best Effort Dropped first

Network Interface Card (NIC)


Hardware Component OSI Layer 1 & 2 Physical + Data Link Built-in or Add-on Card
A Network Interface Card (NIC) also called a network adapter, LAN card, or network card
is a hardware component that provides a device (computer, server, printer, etc.) with the ability
to connect to a network. It serves as the physical interface between the device and the
transmission medium (cable or wireless signal).
Every NIC has a globally unique MAC address (Media Access Control address) burned into its
firmware at manufacture a 48-bit hardware address used to identify the device at the Data Link
layer.
Physical Components of a NIC
NIC Controller Chip: The brain of the NIC. Processes data going in and out, handles protocols,
manages the MAC layer, and communicates with the CPU via the system bus (PCIe).
ROM Chip (MAC Address): Read-Only Memory that permanently stores the 48-bit MAC
address burned in at the factory. Unique worldwide. Format: XX:XX:XX:XX:XX:XX
TX/RX Buffer (RAM): Temporary memory that holds outgoing (TX) and incoming (RX) data
packets before they are processed. Prevents data loss during bursts.
Network Port: Physical connector RJ-45 for Ethernet, SFP for fiber, or an integrated antenna for
Wi-Fi. The point where data enters/leaves as a signal.
Status LEDs: Link light (solid = connected) and activity light (blinking = data flowing).
Diagnostic indicators for troubleshooting.
Edge Connector / Bus: PCIe, PCI, or USB interface that connects the NIC to the motherboard,
enabling data transfer between NIC and system memory/CPU.

Functions of a NIC
The NIC performs multiple critical functions spanning both the Physical and Data Link layers of
the OSI model. Click any function below to learn more.
1. Data Encoding & Signal Conversion
The NIC converts digital data (binary bits: 0s and 1s) from the computer into electrical
signals (copper Ethernet), light pulses (fiber optic), or radio waves (Wi-Fi) for
transmission. On reception, it does the reverse — converting incoming signals back into
digital bits the computer can process. This is called serialization/deserialization (SerDes).
▪ Digital → Electrical signal (Copper/Ethernet)
▪ Digital → Light pulses (Fiber Optic NIC)
▪ Digital → Radio waves (Wireless NIC)
▪ Incoming signal → Digital bits (deserialization)
2. MAC Addressing
Every NIC has a unique 48-bit MAC address (e.g., A4:C3:F0:85:AC:2D) permanently
stored in its ROM. The NIC uses this address to identify itself on the local network. The
first 3 bytes (OUI) identify the manufacturer; the last 3 bytes are a unique serial. The NIC
stamps every outgoing frame with this source MAC and reads incoming frames addressed
to its MAC.
▪ 48-bit globally unique hardware address
▪ First 3 bytes = OUI (manufacturer ID)
▪ Last 3 bytes = device serial
▪ Used for Layer 2 (frame) addressing
▪ Can be spoofed in software (MAC spoofing)
3. Frame Assembly & Disassembly
When sending, the NIC encapsulates data from the OS into Ethernet frames — adding the
destination MAC, source MAC, EtherType field, data payload, and a CRC checksum at the
end. When receiving, it strips the frame headers and trailers, verifies the CRC, and passes
the payload up to the OS/network stack.
Outgoing: wraps data in Ethernet frame
▪ Adds: Dest MAC, Src MAC, EtherType, CRC
▪ Incoming: strips headers, checks CRC
▪ Discards corrupt frames (CRC mismatch)
▪ Passes clean payload to OS network stack
4. Flow Control & Error Detection
The NIC uses CRC (Cyclic Redundancy Check) to detect corrupted frames and silently
discard them. It also implements flow control using IEEE 802.3x PAUSE frames — when
the receive buffer is nearly full, the NIC signals the sender to slow down, preventing buffer
overflow and dropped packets.
▪ CRC error detection on every received frame
▪ Corrupt frames discarded silently
▪ IEEE 802.3x PAUSE frames for flow control
▪ Prevents buffer overflow
▪ Works at Layer 2 before TCP/IP
5. Parallel-to-Serial Conversion (DMA)
Inside the computer, data moves in parallel (multiple bits at once across a wide bus). The
NIC must serialize this into a single stream of bits for the network cable. It uses DMA
(Direct Memory Access) to transfer data between system RAM and the NIC buffer without
burdening the CPU greatly improving performance.
▪ Converts parallel bus data → serial bit stream
▪ DMA transfers data without CPU involvement
▪ Reduces CPU overhead significantly
▪ Enables high-speed NICs (10GbE, 25GbE, 100GbE)
▪ DMA rings managed by NIC driver
6. Media Access Control (CSMA/CD & CSMA/CA)
The NIC controls when the device can transmit to avoid collisions on a shared medium.
Wired NICs use CSMA/CD (Carrier Sense Multiple Access / Collision Detection) — listen
before sending, detect if a collision occurred, then back off and retry. Wireless NICs
use CSMA/CA (Collision Avoidance) — announce before sending to reserve the medium.
▪ CSMA/CD for wired Ethernet (half-duplex)
▪ CSMA/CA for Wi-Fi (wireless NICs)
▪ Carrier Sense: listen before transmitting
▪ Collision Detection: detect & back off
▪ Random backoff timer before retransmit

NIC and the OSI Model


The NIC operates primarily at Layer 1 (Physical) and Layer 2 (Data Link) of the OSI model,
bridging the computer's software world with the physical network medium.
Layer 1 — Physical Layer
❖ Converts bits into signals (electrical/light/radio)
❖ Manages cable/medium timing and bit rate
❖ Handles the physical connector (RJ-45, SFP, antenna)
❖ Detects cable presence, link speed negotiation
❖ Auto-negotiation (10/100/1000 Mbps, full/half duplex)
Layer 2 — Data Link Layer
❖ Assigns/uses MAC address for device identification
❖ Assembles Ethernet fra mes (header + payload + CRC)
❖ Performs CRC error detection on received frames
❖ Implements CSMA/CD (wired) or CSMA/CA (wireless)
❖ Manages flow control with PAUSE frames (802.3x)

Types of NICs
NICs come in many forms depending on connection type, form factor, and interface. Here are the
main categories:
Ethernet NIC (Wired)
 Most common type for LANs
 Uses RJ-45 port with Cat5e/Cat6/Cat7 cable
 Speeds: 10/100/1000 Mbps (Fast Ethernet, Gigabit)
 High-end: 10GbE, 25GbE, 40GbE, 100GbE
 Built into virtually all modern motherboards
 Add-on cards for extra ports or higher speeds
Wireless NIC (Wi-Fi)
 Connects via radio waves (no cable)
 Standards: 802.11a/b/g/n/ac/ax (Wi-Fi 6/6E)
 Has antenna (built-in or external)
 Uses CSMA/CA instead of CSMA/CD
 Common in laptops, phones, tablets
 PCIe or USB form factor for desktops
Fiber Optic NIC
 Uses light instead of electrical signals
 Very high speeds (1GbE to 400GbE+)
 Long-distance (up to 80km for single-mode)
 Uses SFP / SFP+ / QSFP transceivers
 Immune to electromagnetic interference
 Common in data centres, ISP backbones
Virtual NIC (vNIC)
 Software-only NIC — no physical hardware
 Used in virtual machines (VMs)
 Provided by hypervisor (VMware, H yper-V, KVM)
 Has a virtual MAC address
 Multiple vNICs can share one physical NIC
 Connects to Virtual Switch (vSwitch)
USB NIC (Dongle)
 External NIC connected via USB port
 Portable — plug-and-play
 Lower performance than PCIe NICs
 Speeds typically 100Mbps to 1Gbps
 Wi-Fi USB dongles very common
 Good for laptops missing Ethernet port
Converged / Smart NIC (SmartNIC)
 Advanced NIC with onboard processor
 Offloads network tasks from main CPU
 Features: RDMA, iSCSI, FCoE offload
 Used in high-performance servers, cloud
 Examples: Mellanox ConnectX, NVIDIA BlueField
 Reduces CPU overhead by up to 30%
Key Facts & Quick Reference

Property Details

Full Name Network Interface Card (also: Network Adapter, LAN Card,
Network Card)

OSI Layers Layer 1 (Physical) + Layer 2 (Data Link)

MAC Address 48-bit (6 bytes), e.g., A4:C3:F0:85:AC:2D — globally unique,


stored in ROM

MAC Format First 3 bytes = OUI (manufacturer) | Last 3 bytes = device serial
number

Common Speeds 100 Mbps (Fast Ethernet), 1 Gbps, 10 Gbps, 25/40/100 Gbps
(data centres)

Interface to PCIe (most common), USB, PCI (legacy)


Motherboard

Wired Protocol IEEE 802.3 (Ethernet)

Wireless Protocol IEEE 802.11 (Wi-Fi)

Error Detection CRC (Cyclic Redundancy Check) — detects corrupt frames

Flow Control IEEE 802.3x PAUSE frames

Media Access CSMA/CD (wired) | CSMA/CA (wireless)

Drivers Software driver required for OS to communicate with NIC


hardware
Built-in vs Add-on Modern motherboards have built-in NICs; add-on PCIe cards for
extra ports/speed

Network Planning and Design


Network Planning is the systematic process of analysing requirements, defining goals, and
creating a strategy for building or expanding a network infrastructure. It involves understanding
the organization's needs, budget, and constraints before any equipment is purchased or cable is
laid.
Network Design is the technical process of translating those plans into a detailed blueprint —
specifying the topology, hardware, protocols, IP addressing scheme, security measures, and
physical layout of the network.
Together, they form the foundation of any successful network deployment. A poorly planned
network leads to bottlenecks, security vulnerabilities, high costs, and downtime — while a well-
planned network scales gracefully and meets business needs reliably.
Network Planning
1. Identifies what the network must do
2. Gathers user, business, and technical requirements
3. Estimates budget and resources needed
4. Assesses current infrastructure (if upgrading)
5. Defines performance, availability, and security goals
6. Produces a Network Requirements Document
Network Design
1. Determines how the network will be built
2. Selects topology, protocols, hardware, media
3. Creates logical and physical network diagrams
4. Defines IP addressing and subnetting schemes
5. Plans security zones, VLANs, routing policies
6. Produces a Network Design Document (NDD)

Importance Of Network Planning


Proper network planning prevents costly mistakes, ensures the network meets real needs, and
creates a foundation for future growth. Below are the key reasons why network planning is critical:
1. Cost Efficiency: Planning identifies exact hardware and infrastructure needs
upfront, preventing overspending on unnecessary equipment or underspending
leading to future upgrades. It is far cheaper to redesign on paper than to rewire
physical infrastructure.
➢ Avoids purchasing wrong or oversized equipment
➢ Prevents expensive mid-project scope changes
➢ Enables accurate budgeting and cost forecasting
➢ Reduces total cost of ownership (TCO) long-term
2. Scalability & Future Growth: A well-planned network anticipates future growth
in users, devices, and bandwidth demands. Designing for scalability from the start
means you can expand without rebuilding the entire network from scratch.
➢ Supports adding users, sites, and services easily
➢ Hierarchical design (Core-Distribution-Access) enables modular growth
➢ IP addressing plan leaves room for expansion
➢ Infrastructure supports higher speeds later (e.g., 1GbE → 10GbE)
3. Performance & Reliability: Planning ensures the network is sized correctly for
current and future traffic loads, with appropriate redundancy and QoS policies. This
prevents bottlenecks, packet loss, and downtime.
➢ Bandwidth planning prevents congestion
➢ Redundant links and devices ensure high availability
➢ QoS policies prioritize critical traffic (VoIP, video)
➢ SLAs (Service Level Agreements) can be defined and met
4. Security: Network planning integrates security from the ground up (security by
design) rather than bolting it on later. This includes defining security zones, firewall
placement, access control policies, and encryption strategies.
➢ DMZ and security zones defined at design stage
➢ Firewall and IDS/IPS placement planned early
➢ VLANs segment sensitive traffic (HR, Finance, Guest)
➢ Access control lists (ACLs) and authentication policies baked in
5. Simplified Management & Maintenance: A planned network has logical,
documented structure making it far easier for administrators to troubleshoot,
reconfigure, and maintain. Ad-hoc networks become chaotic "spaghetti" that
nobody fully understands.
➢ Consistent IP addressing scheme aids troubleshooting
➢ Network diagrams guide administrators
➢ Naming conventions make device identification easy
➢ Monitoring and management tools can be planned in advance
6. Business Continuity: Network planning ensures business-critical systems remain
available even during failures. Redundancy, failover design, and disaster recovery
are incorporated at the planning stage.
➢ Single points of failure identified and eliminated
➢ Backup links and redundant ISP connections planned
➢ Disaster recovery and failover strategies defined
➢ RTO (Recovery Time Objective) and RPO goals are met
Steps in Designing a Network
Network design follows a structured lifecycle from gathering requirements to ongoing monitoring.
Each step builds on the previous one. Skipping steps leads to costly rework.
Network design follows a structured series of steps. These steps are sometimes called the Network
Design Life Cycle (NDLC). Each step builds on the previous one.
Step 1 — Requirements gathering and analysis
This is the first and most important step. The network designer meets with the organisation's
management, staff, and IT team to understand what is needed. Questions asked include: how many
users will connect? What applications will they use (email, web browsing, video conferencing,
large file transfers)? Which departments need to be separated? What is the budget? What are the
security requirements? The answers to these questions drive every decision that follows.
The foundation of every successful network design. Before drawing a single cable or choosing any
equipment, you must fully understand what the network needs to achieve, who will use it, and
what constraints exist.
Tasks & Activities
Identify stakeholders: IT staff, management, department heads, end users
Define business goals: what does the network need to support? (e.g., VoIP, cloud apps,
CCTV, remote work)
Determine number of users and devices: now and in 3–5 years (scalability planning)
Identify locations: single site, multiple buildings, remote branches, data centre
Define performance requirements: bandwidth needs, latency thresholds, uptime SLAs
Identify compliance/regulatory needs: GDPR, HIPAA, PCI-DSS, ISO 27001
Establish budget constraints: CAPEX (hardware) and OPEX (licensing, support)
Identify existing infrastructure: what can be reused or upgraded?
Deliverables / Outputs
Business requirements document
Technical requirements list
Stakeholder sign-off
Budget envelope
Compliance checklist
Note: Skipping this step is the #1 cause of failed network projects. A network designed without
requirements will require expensive redesign later.
Example: For a Nigerian polytechnic, the designer finds out there are 1,200 students, 200 staff, 6
departments (CS, Engineering, Business, Science, Law, Admin), 3 labs, a library, and a rector's
office. All departments need internet access. The bursary must be isolated from students for
security.
Step 2 Site survey
The designer physically visits the location and inspects the buildings, rooms, corridors, and
distances between buildings. They note where power outlets are, where cable ducts can run, where
the server room will be located, the thickness of walls (important for wireless signal planning),
and any obstacles. A site survey prevents nasty surprises like discovering a cable must travel 120
metres when Cat5e only supports 100 metres. Analyse the current environment both physical and
logical. A site survey captures the existing infrastructure, physical layout, interference sources,
and any legacy systems that the new design must accommodate or replace.
Tasks & Activities
 Physical site survey: walk every floor, building, room; measure cable runs; find MDF/IDF
locations
 Wireless survey: identify RF interference, walls, signal obstacles; plan AP placement
 Inventory existing hardware: document all current switches, routers, firewalls, servers
 Map existing cabling: identify cable types (Cat5e, Cat6, fibre), lengths, condition
 Document existing addressing: current IP scheme, VLANs, subnets, DNS, DHCP
 Identify pain points: what problems does the current network have? (congestion, outages,
security gaps)
 Traffic analysis: use tools (Wireshark, SNMP, NetFlow) to understand current traffic
patterns
 Assess power availability: UPS, PDU, PoE budget per switch location
Deliverables / Outputs
 Site survey report
 Physical floor plan with device locations
 Current network topology diagram
 Traffic baseline report
 Hardware inventory list

Step 3 Network topology selection (Logical Design)


Based on the requirements and site survey, the designer chooses the physical topology (how
devices are physically connected star, bus, ring, mesh, or hybrid) and the logical topology (how
data flows). For most modern networks, a hierarchical star topology is chosen with three layers:
core layer (backbone switches), distribution layer (floor switches), and access layer (switches
connecting end devices). This is called the three-tier model. Design how the network will function
logically independent of physical hardware. This includes the IP addressing scheme, VLAN
structure, routing design, redundancy model, and network topology. This is the most intellectually
demanding phase.
Tasks & Activities

• Choose network topology — Three-tier hierarchical (Core/Distribution/Access) or Two-


tier (collapsed core) for smaller networks
• Design VLAN structure — one VLAN per department/function (Data, Voice,
Management, IoT, Guest)
• Design IP addressing scheme — choose private address ranges (RFC 1918); subnet each
VLAN; plan for growth
• Design routing — static routes vs dynamic (OSPF/EIGRP); route summarization at
distribution
• Plan redundancy — HSRP/VRRP for gateway redundancy; redundant uplinks; dual ISP
for WAN
• Design DNS and DHCP — centralized or distributed; scope per VLAN; lease times
• Plan QoS — classify voice, video, critical data; define queuing policies
• Design WAN connectivity — MPLS, SD-WAN, Internet VPN, leased line; bandwidth per
site
Deliverables / Outputs

• Logical network diagram


• IP addressing plan (spreadsheet)
• VLAN table
• Routing design document
• Redundancy plan
Step 4 Physical Design
Translate the logical design into a real-world physical plan what hardware to buy, where to place
it, how to cable it, and what the physical environment must support. This phase produces the bill
of materials and physical topology diagrams.
Tasks & Activities

• Select hardware — core switches, distribution switches, access switches, routers,


firewalls, APs
• Plan device placement — MDF (Main Distribution Frame), IDF (Intermediate
Distribution Frame) locations per floor/building
• Design cabling plant — structured cabling standard (TIA-568); Cat6/Cat6A for copper;
OM4 or OS2 fibre for backbone
• Plan rack layout — rack units (U) per device; power distribution; cable management;
airflow (hot/cold aisle)
• Power planning — UPS sizing; PoE budget per switch (total PoE watts needed vs switch
PoE budget)
• Physical security — server room locks, cage racks, camera coverage of network rooms
• Environmental controls — cooling (CRAC units), temperature monitoring, humidity
sensors
• Label everything — patch panel ports, cable runs, switches, routers — use consistent
naming convention
Deliverables / Outputs

• Physical network diagram


• Bill of materials (BOM)
• Rack elevation diagrams
• Cabling plan / patch panel schedule
• Room/floor layout with device positions
Always add 20–30% port capacity headroom at Access layer. Running out of switch ports after
installation is an expensive mistake.
Step 5 Security Design

Security is not an afterthought it must be built into the design from the ground up. Every layer of
the network needs security controls. A defence-in-depth strategy applies multiple overlapping
layers of protection. The designer plans all security measures including firewall placement and
rules, VLAN segmentation, VPN configuration for remote access, wireless security protocols
(WPA2/WPA3), access control lists (ACLs) on routers, password policies, DMZ setup for any
public-facing servers, and physical security for the server room. Security must be designed in from
the start, not added as an afterthought.

Tasks & Activities

• Firewall placement — perimeter firewall between Internet and internal network; internal
firewall between zones
• DMZ design — isolate public-facing servers (web, mail, DNS) from internal LAN using
a DMZ
• Network segmentation — separate VLANs for users, servers, IoT, guest; inter-VLAN
ACLs at distribution
• Access control — 802.1X NAC for wired ports; WPA3-Enterprise for Wi-Fi;
RADIUS/TACACS+ authentication
• Port security — limit MAC addresses per access port; DHCP snooping; Dynamic ARP
Inspection
• VPN design — site-to-site IPSec VPN for branches; SSL/TLS VPN or ZTNA for remote
users
• IDS/IPS — intrusion detection/prevention at perimeter and critical internal segments
• Network monitoring — SIEM integration; syslog collection; SNMP traps; NetFlow for
traffic visibility
Deliverables / Outputs

• Security architecture diagram


• Firewall rule baseline
• ACL policy document
• DMZ design
• Incident response plan
Follow the principle of least privilege — every device, user, and VLAN should only have access
to exactly what it needs and nothing more.

Step 6 IP Addressing & Naming Plan


A well-structured IP addressing plan is critical for manageability, troubleshooting, and
scalability. Addresses should be assigned logically making it easy to identify a device's location
and role just from its IP address. The designer plans the IP address allocation for the entire network.
This includes choosing the right private address range (Class A: 10.x.x.x, Class B: 172.16–31.x.x,
or Class C: 192.168.x.x), dividing it into subnets for each department, assigning static IPs to
servers and network devices, and planning DHCP ranges for end-user devices. Good IP planning
makes the network easy to manage and troubleshoot.

Example IP plan for a polytechnic:

Department Network Range VLAN


CS lab [Link]/24 .10 – .200 VLAN 10
Bursary [Link]/24 .10 – .50 VLAN 20
Admin [Link]/24 .10 – .80 VLAN 30
Servers [Link]/24 .10 – .30 VLAN 100

Tasks & Activities

• Choose address space — typically [Link]/8 for large orgs; [Link]/12 or


[Link]/16 for smaller
• Allocate subnets per VLAN — e.g., VLAN 10 = [Link]/24; VLAN 20 =
[Link]/24
• Reserve address ranges — network devices (routers, switches) in low range (.1–.20);
servers (.50–.100); DHCP pool (.101–.254)
• Plan point-to-point links — use /30 or /31 subnets for router-to-router links
• Define naming convention — consistent hostnames: BLDGA-SW-ACC-01, BLDGA-
SW-DIST-01, CORE-SW-01
• Plan DNS zones — internal DNS domain ([Link]); forward and reverse
zones
• DHCP scopes — one scope per VLAN; exclusions for static devices; correct default
gateway, DNS, lease time
• Document everything — IP address management (IPAM) tool or detailed spreadsheet
Deliverables / Outputs

• IP addressing spreadsheet / IPAM database


• Subnet allocation table
• DHCP scope configuration
• DNS zone plan
• Device naming standard document

💡 Use IPAM tools like phpIPAM, NetBox, or Infoblox to manage your address space. Never
manage IPs on sticky not

Step 7 Prototype & Lab Testing


Never deploy directly to production. Build a lab prototype of the design either physical or virtual
(GNS3, Cisco Packet Tracer, EVE-NG) to validate that the design works as intended before a
single cable is run in the live environment.
Tasks & Activities

• Build lab topology — simulate the core design in GNS3/EVE-NG/Packet Tracer or a


physical lab
• Test routing — verify OSPF/EIGRP convergence; route summarization; failover paths
• Test VLAN routing — confirm inter-VLAN routing works; verify ACLs block/permit
correctly
• Test redundancy — disconnect links/switches; verify HSRP failover; measure
convergence time
• Test security policies — attempt to breach ACLs; verify 802.1X rejects unauthorized
devices
• Test QoS — generate voice and data traffic simultaneously; verify voice priority
• Performance testing — use iPerf or similar to measure throughput across all paths
• Document findings — record any design flaws discovered and update the design before
production
Deliverables / Outputs

• Lab test report


• Updated design (post-testing)
• Configuration templates
• Failover test results
• Performance baseline

💡 A 1-week lab test that catches a VLAN routing mistake saves weeks of production downtime.
The lab phase is never time wasted

Step 8 Implementation & Deployment


With a tested design and proven configurations, it is time to deploy the physical network.
Implementation should follow a structured plan phased rollout, change management process, and
rollback procedures ready at every step.
Tasks & Activities

• Prepare change management — schedule maintenance windows; notify users; have


rollback plan ready
• Install physical infrastructure — run cables, install patch panels, mount racks, install
switches and routers
• Configure devices — apply tested configurations from lab (hostname, VLANs, IPs,
routing, security)
• Phase the rollout — deploy Core first, then Distribution, then Access switches; test each
layer before proceeding
• Connect end devices — patch cables from wall ports to switch ports; assign VLANs;
verify DHCP
• Configure management systems — SNMP, syslog, NTP synchronization across all
devices
• Test connectivity — ping tests, traceroute, application testing, VoIP call quality
• Handover — brief operations team; transfer documentation; confirm SLA metrics are met
Deliverables / Outputs

• Deployed and functional network


• As-built network diagrams
• Configuration backup of all devices
• Handover checklist
• Acceptance sign-off

⚠️ Always deploy in phases. Never replace the entire network in one weekend. Phase 1: Core.
Phase 2: Distribution. Phase 3: Access. Test after each phase.
Step 9 Testing & Verification
After deployment, systematically verify every design requirement is working correctly in the
live production environment. This is different from lab testing — real traffic, real users, and real
conditions reveal issues that labs cannot simulate.
Tasks & Activities

• Connectivity testing — verify all VLANs can reach their default gateway; test cross-
VLAN routing
• Internet / WAN testing — verify all branches reach HQ and Internet; test VPN tunnels
• Failover testing — unplug uplinks one at a time; verify HSRP/OSPF failover within SLA
• Security testing — attempt unauthorized VLAN access; verify firewall blocks; test
802.1X rejection
• Performance testing — run bandwidth tests (iPerf); measure latency; verify QoS
prioritizes voice
• Application testing — test all business applications: email, VoIP, file shares, cloud apps,
ERP
• Wireless testing — roaming between APs; coverage verification; throughput testing per
area
• Document results — record all test results against original requirements; sign off on each
requirement
📄 Deliverables / Outputs

• Test report against requirements


• Approved acceptance document
• Outstanding issues list
• Performance baseline (for future comparison)

💡 Use the original requirements document as your checklist. Every requirement gathered in Step
1 should have a corresponding test result showing it was met.
Step 10 Monitoring, Optimization & Documentation
A network design is never truly finished. Once live, it must be continuously monitored, optimized
as usage patterns evolve, and kept fully documented. This ongoing phase ensures the network
remains aligned with business needs throughout its lifetime.
Tasks & Activities

• Deploy monitoring tools — SNMP-based (SolarWinds, PRTG, Zabbix); NetFlow for


traffic visibility; Syslog for logs
• Set up alerting — alerts for link down, high CPU, interface errors, low bandwidth, failed
auth attempts
• Establish baselines — record normal traffic volumes, CPU usage, error rates; deviations
trigger investigation
• Capacity planning — review utilization monthly; upgrade links or hardware before they
hit 70% sustained use
• Regular audits — quarterly review of ACLs, firewall rules, unused ports, rogue devices,
security patches
• Keep documentation current — update network diagrams, IP plans, and config backups
after every change
• Change management process — all changes must go through a formal change request
and approval process
• Disaster recovery testing — annually test full failover scenarios; verify backup configs
restore correctly
Deliverables / Outputs

• Live monitoring dashboard


• Incident and change log
• Updated as-built documentation
• Capacity trend reports
• Annual DR test results

💡 Treat documentation like code — it must be version-controlled and updated with every change.
Outdated network diagrams are worse than no diagrams.

The 10-Step Network Design Process at a Glance

S/N Step Key Output


01 Requirements Analysis Business & technical requirements doc

02 Site Survey & Network Analysis Physical floor plans, traffic baseline
03 Logical Design IP plan, VLAN table, routing design

04 Physical Design Bill of materials, cabling plan, rack layout

05 Security Design Firewall rules, DMZ, ACL policy

06 IP Addressing & Naming Plan Subnet table, DHCP scopes, DNS zones

07 Prototype & Lab Testing Lab test report, validated configs

08 Implementation & Deployment Live production network, as-built diagrams

09 Testing & Verification Acceptance sign-off, test report

10 Monitoring & Documentation Live dashboards, updated docs, change log

Network Topology

Network topology is the arrangement or layout of computers, cables, switches, and other devices
in a network. It describes how devices are physically connected to each other (physical topology)
and how data flows between them (logical topology). Network topology refers to
the arrangement or layout of devices (nodes), links, and connections that make up a computer
network. It defines how different network elements computers, switches, routers, hubs are
interconnected and how data flows between them.
Topology is studied in two distinct forms: Physical Topology (how devices are physically wired
and placed) and Logical Topology (how data actually flows through the network regardless of
physical layout).

Physical topology refers to the actual layout of cables and hardware you can see and touch.
Logical topology refers to how data travels through the network regardless of the physical layout.
For example, a network can be physically wired in a star but operate logically like a bus.

Physical Topology

The actual physical layout of cables, devices, and infrastructure. It is what you see when you look
at a network map where devices are placed and how cables connect them.
• Describes cable routing and device placement
• Visible and tangible you can trace the cables
• Affects installation cost, scalability, and maintenance
• Examples: Star, Bus, Ring, Mesh, Tree, Hybrid
Logical Topology

The path data actually travels through the network — which may differ completely from the
physical layout. It describes how signals flow, not where wires are.
• Describes how data is transmitted between nodes
• Determined by protocols and device behaviour
•A physically star-wired network can be logically a bus
• Examples: Broadcast, Token Ring, Point-to-Point
Types of Network Topologies

Bus Topology
In bus topology, all devices are connected to a single central cable called the backbone or bus.
Data sent by any device travels along the entire cable and every device receives it, but only the
intended recipient accepts it. A terminator is placed at each end of the bus cable to prevent signal
bouncing.
Bus topology was used in early Ethernet networks (10BASE2 using coaxial cable). Advantages:
cheap to install, uses less cable than other topologies, easy to extend by adding more devices.
Disadvantages: a break anywhere on the backbone cable stops the entire network, all devices share
bandwidth so performance drops as more devices are added, difficult to troubleshoot, and
terminators must be fitted at both ends or the signal bounces and causes errors.
Star Topology
In star topology, every device connects directly to a central device — usually a switch or hub. No
device connects directly to another. All data passes through the central switch. This is the most
widely used topology in modern networks including every Nigerian polytechnic lab, office, and
bank.

Advantages of star topology: easy to install and manage, a fault in one cable only affects that one
device (the rest continue working), easy to add or remove devices without disrupting the network,
and easy to diagnose faults. Disadvantages: if the central switch fails the entire network goes down
(single point of failure), requires more cable than bus topology, and the switch adds cost.
Ring Topology
In ring topology, devices are connected in a closed loop — each device connects to exactly two
others forming a circle. Data travels in one direction around the ring passing through each device
until it reaches its destination. Each device acts as a repeater, boosting the signal before passing it
on.
Ring topology was used in IBM Token Ring networks. Advantages: data travels in one direction
so there are no collisions, performs well under heavy load, each device acts as a repeater.
Disadvantages: a break in the ring or a failed device can bring down the entire network (unless
dual-ring is used), adding or removing a device disrupts the network, and it is slower than star
topology. Rarely used in modern networks.
Mesh Topology
In mesh topology, every device connects directly to every other device. This provides maximum
redundancy — if any link fails, data can take an alternative path. There are two types: full mesh
(every device connects to every other) and partial mesh (only some devices have multiple
connections).
Advantages: extremely reliable (multiple paths exist), no single point of failure, high performance
as data takes the fastest available path. Disadvantages: very expensive — too many cables and
ports needed, complex to install and manage. Used mainly in the internet backbone, core routers
of large organisations, and military networks.
Tree (Hierarchical) Topology
Tree topology combines bus and star topologies. Devices connect in a hierarchical structure like
the branches of a tree. There is a root node (usually a core switch or router), then distribution
switches connected to it, then access switches connected to those, and finally end devices.
Advantages: easy to manage and expand, fault in one branch does not affect other branches,
supports large networks. Disadvantages: depends on the root node if it fails the whole network is
affected, requires more cabling than bus topology.

Hybrid Topology
Hybrid topology combines two or more different topologies. For example, a Nigerian bank may
use star topology in each branch (connecting ATMs and teller computers), but connect all branches
to the head office in a partial mesh for redundancy. The result is a hybrid star-mesh topology. Most
real-world enterprise networks are hybrid topologies because no single topology perfectly suits
every part of a large organisation.

Topology comparison:
Topology Central Cable Best For Single point Used today
device used of failure
Bus None Least Legacy/small Yes No obsolete
networks (backbone)
Star Switch/Hub Moderate Most LANs, Yes (switch) Yes most common
offices
Ring None Moderate Industrial, fiber Yes (any No obsolete
rings device)
Mesh (full) None Most WANs, critical No Backbone only
backbones
Tree Core switch Moderate Enterprise, Yes (root) Yes campus
campus, data networks
centre
Hybrid Multiple Varies Most real-world Depends Yes large
networks enterprises

Network Access Methods

A network access method is the set of rules that controls how devices share the network medium
and take turns transmitting data. Without access control, two devices transmitting at the same time
would cause a collision and corrupt both signals. Three main access methods exist.

Access Method 1 CSMA/CD (Carrier Sense Multiple Access with Collision Detection)

CSMA/CD is used in wired Ethernet networks (IEEE 802.3). Here is exactly how it works:

A device that wants to transmit first listens to the cable (Carrier Sense) to check if another device
is already transmitting. If the cable is free, it transmits. If two devices happen to transmit at exactly
the same time, a collision occurs. Both devices detect the collision (Collision Detection),
immediately stop transmitting, and each waits a random amount of time before trying again. This
random wait (called backoff) ensures they do not collide again immediately.

The process step by step: Listen to medium → If busy, wait → If free, transmit → If collision
detected, stop → Send jam signal → Wait random backoff time → Try again.
CSMA/CD is rarely needed in modern networks because switches create separate collision
domains — each port on a switch is its own domain so collisions between devices on different
ports cannot occur. Full-duplex Ethernet (send and receive at the same time) also eliminates
collisions entirely.

Access Method 2 CSMA/CA (Carrier Sense Multiple Access with Collision Avoidance)

CSMA/CA is used in wireless networks (IEEE 802.11 Wi-Fi). Wireless networks cannot use
CSMA/CD because a transmitting device cannot simultaneously listen for collisions on a wireless
medium the transmitted signal would drown out any incoming signal.

Instead, CSMA/CA tries to avoid collisions before they happen. Before transmitting, a device
waits for the medium to be free, then waits an additional random backoff period before
transmitting. It can also send a short Request to Send (RTS) frame and wait for a Clear to Send
(CTS) reply from the access point before transmitting its data. This handshake reserves the medium
and prevents other devices from transmitting during that time.

The steps: Sense the medium → If busy, wait → If free, wait additional random backoff →
Optionally send RTS → Wait for CTS → Transmit data → Wait for acknowledgement.

Access Method 3 Token Passing

Token passing was used in Token Ring (IEEE 802.5) and FDDI (Fibre Distributed Data Interface)
networks. A small special data frame called a token is continuously passed around the network.
Only the device that holds the token is allowed to transmit. After transmitting, the device releases
the token and it moves to the next device.

Advantages: no collisions possible (only one device transmits at a time), fair access (every device
gets a turn), predictable performance even under heavy load. Disadvantages: a lost or corrupted
token can halt the entire network, more complex to manage than CSMA. Token passing networks
are rare today — replaced by switched Ethernet.

Access method comparison:


Access method Standard Network type Collision handling
CSMA/CD IEEE 802.3 Wired Ethernet Detected and retried
CSMA/CA IEEE 802.11 Wireless Wi-Fi Avoided before transmitting
Token passing IEEE 802.5 Token Ring / FDDI Prevented by token

Key points: Star topology is the most common in modern networks used in every polytechnic lab
and office. The switch is the central device in star topology; the hub is old and obsolete. CSMA/CD
is for wired Ethernet; CSMA/CA is for wireless Wi-Fi. Token passing prevents collisions entirely
but is rarely used today. Mesh topology has n(n-1)/2 links for n devices. Tree topology =
hierarchical star used in large campus networks.

You might also like