0% found this document useful (0 votes)
44 views47 pages

Understanding Internetworking Concepts

Uploaded by

dhwanisaboo710
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
44 views47 pages

Understanding Internetworking Concepts

Uploaded by

dhwanisaboo710
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

UNIT 2 Internetworking

Internetworking is combined of 2 words, inter and networking which implies an association between
totally different nodes or segments. This connection area unit is established through intercessor
devices akin to routers or gateway. The first term for associate degree internetwork was catenet. This
interconnection is often among or between public, private, commercial, industrial, or governmental
networks. Thus, associate degree internetwork could be an assortment of individual networks,
connected by intermediate networking devices, that function as one giant network. Internetworking
refers to the trade, products, and procedures that meet the challenge of making and administering
internet works.
To enable communication, every individual network node or phase is designed with a similar protocol
or communication logic, that is Transfer Control Protocol (TCP) or Internet Protocol (IP). Once a
network communicates with another network having constant communication procedures, it’s called
Internetworking. Internetworking was designed to resolve the matter of delivering a packet of
information through many links.
There is a minute difference between extending the network and Internetworking. Merely exploitation
of either a switch or a hub to attach 2 local area networks is an extension of LAN whereas connecting them
via the router is an associate degree example of Internetworking. Internetworking is enforced in Layer three
(Network Layer) of the OSI-ISO model. The foremost notable example of internetworking is the Internet.
There is chiefly 3 units of Internetworking:
1. Extranet
2. Intranet
3. Internet
Intranets and extranets might or might not have connections to the net. If there is a connection to the
net, the computer network or extranet area unit is usually shielded from being accessed from the net
if it is not authorized. The net isn’t thought-about to be a section of the computer network or
extranet, though it should function as a portal for access to parts of the associate degree extranet.
1. Extranet – It’s a network of the internetwork that’s restricted in scope to one organization
or entity however that additionally has restricted connections to the networks of one or a lot of
different sometimes, however not essential. It’s the very lowest level of Internetworking, usually
enforced in an exceedingly personal area. Associate degree extranet may additionally be
classified as a Man, WAN, or different form of network however it cannot encompass one local
area network i.e. it should have a minimum of one reference to associate degree external network.
2. Intranet – This associate degree computer network could be a set of interconnected
networks, which exploits the Internet Protocol and uses IP-based tools akin to web browsers and
FTP tools, that are underneath the management of one body entity. That body entity closes the
computer network to the remainder of the planet and permits solely specific users. Most typically,
this network is the internal network of a corporation or different enterprise. An outsized
computer network can usually have its own internet server to supply users with browsable data.
3. Internet – A selected Internetworking, consisting of a worldwide interconnection of
governmental, academic, public, and personal networks based mostly upon the Advanced
analysis comes Agency Network (ARPANET) developed by ARPA of the U.S. Department of
Defense additionally home to the World Wide Web (WWW) and cited as the ‘Internet’ to
differentiate from all different generic Internetworks. Participants within the web, or their service
suppliers, use IP Addresses obtained from address registries that manage assignments.
Internetworking has evolved as an answer to a few key problems: isolated LANs, duplication of
resources, and an absence of network management. Isolated LANs created transmission problems
between totally different offices or departments. Duplication of resources meant that constant
hardware and code had to be provided to every workplace or department, as did a separate support
employee. This lack of network management meant that no centralized methodology of managing
and troubleshooting networks existed.
One more form of the interconnection of networks usually happens among enterprises at the Link
Layer of the networking model, i.e. at the hardware-centric layer below the amount of the TCP/IP
logical interfaces. Such interconnection is accomplished through network bridges and network
switches. This can be typically incorrectly termed internetworking, however, the ensuing system is
just a bigger, single subnetwork, and no internetworking protocol, akin to web Protocol, is needed
to traverse these devices.
However, one electronic network is also reborn into associate degree internetwork by dividing the
network into phases and logically dividing the segment traffic with routers. The Internet Protocol is
meant to supply an associate degree unreliable packet service across the network. The design avoids
intermediate network components maintaining any state of the network. Instead, this task is allotted
to the endpoints of every communication session. To transfer information correctly, applications
should utilize associate degree applicable Transport Layer protocol, akin to Transmission
management Protocol (TCP), that provides a reliable stream. Some applications use a less
complicated, connection-less transport protocol, User Datagram Protocol (UDP), for tasks that don’t
need reliable delivery of information or that need period of time service, akin to video streaming or
voice chat.

Internetwork Addressing –

Internetwork addresses establish devices severally or as members of a bunch. Addressing schemes


differ based on the protocol family and therefore the OSI layer. Three kinds of internetwork
addresses area units are ordinarily used: data-link layer addresses, Media Access control (MAC)
addresses, and network-layer addresses.

1. Data Link Layer addresses: A data-link layer address unambiguously identifies every
physical network association of a network device. Data-link addresses typically area units cited
as physical or hardware addresses. Data-link addresses sometimes exist among a flat address area
and have a pre-established and usually fastened relationship to a selected device. End systems
usually have just one physical network association, and therefore have just one data-link address.
Routers and different internetworking devices usually have multiple physical network
connections and so eventually have multiple data-link addresses.
2. MAC Addresses: Media Access management (MAC) addresses encompass a set of data-
link layer addresses. MAC addresses establish network entities in LANs that implement the
IEEE MAC addresses of the data-link layer. MAC addresses different area units distinctively for
every local area network interface. MAC addresses are forty-eight bits long and are expressed in
form of twelve hexadecimal digits. The primary half dozen hexadecimal digits, which are usually
administered by the IEEE, establish the manufacturer or merchant and therefore comprise the
Organizational Unique Identifier (OUI). The last half dozen positional notation digits comprise
the interface serial variety or another price administered by the particular merchant. MAC
addresses are typically area units referred to as burned-in addresses (BIAs) as a result of being
burned into read-only memory(ROM) and are traced into random-access memory (RAM) once
the interface card initializes.
3. Network-Layer Addresses: Network addresses sometimes exist among a gradable address
area and typically area units referred to as virtual or logical addresses. the connection between a
network address and a tool is logical and unfixed, it usually relies either on physical network
characteristics or on groupings that don’t have any physical basis. finish systems need one
network-layer address for every network-layer protocol they support. Routers and different
Internetworking devices need one network-layer address per physical network association for
every network-layer protocol supported.

Challenges to Internetworking

 Internetworking comes with several challenges due to its complexity and the diverse technologies
and systems involved. Some of the challenges include:
 Scalability:As the number of devices and users on a network increases, the network must be able
to handle growing traffic, data, and demands without incurring major performance degradation. It
is a continuing struggle to design networks that can scale effectivel
 Security:As networks become more connected, the potential attack surface for malicious actors
grows. Protecting networks from unauthorized access, data breaches, viruses, and other online
threats is an essential concern in internetworking
 Reliability and RedundancyNetworks need to be highly reliable, minimizing downtime and
disruptions. Implementing redundancy mechanisms and failover systems to ensure continuous
operation in the face of failures is complex but necessary.
 InteroperabilityDifferent networks and devices frequently employ a variety of protocols,
standards, and technologies. It can be difficult to ensure smooth communication and
compatibility among these disparate elements. Protocols such as TCP/IP have helped bridge these
gaps, although problems can still exist.
 Network Management:
 As networks grow in complexity, managing and monitoring them becomes increasingly
challenging. Efficiently diagnosing and troubleshooting issues, optimizing performance, and
ensuring proper resource allocation are ongoing tasks
 Resource Management:It can be difficult to manage network resources properly to ensure
optimal performance, especially in shared environments. This includes responsibilities such as
bandwidth allotment and congestion control.

Advantages and Disadvantages of Internetworking

 Global ConnectivityInternetworking provides worldwide connectivity, allowing users and


devices to communicate and exchange resources from all over the world.
 ScalabilityInternetworking allows networks to scale to accommodate growing numbers of users
and devices without needing to rebuild the entire infrastructure.
 Resource Sharing:

 Users can share resources such as files, printers, and databases across networks, increasing
efficiency and collaboration.
 Remote Access:Internetworking facilitates remote access to corporate networks, enabling
telecommuting and remote management.
 Redundancy and Failover:Redundant network connections and failover mechanisms improve
network reliability, mnimizing downtime and ensuring continuous operation.
 Disadvantages
 Security Risks:Internetworking exposes networks to additional security concerns such as
unauthorized access, data breaches, and cyberattacks.
 Network Congestion:Increased connectivity can cause network congestion and poor
performance, particularly during high usage times.
 Privacy Concerns:Internetworking raises concerns about user privacy and data protection,
particularly when sensitive information is transmitted across networks.
 Dependency on Infrastructure:Organizations that rely on interconnected networks are
vulnerable to outages or interruptions in the internet infrastructure.
 Complexity:Connecting multiple networks using different technologies and protocols creates
complexity in terms of configuration, management, and troubleshooting.

Tunneling

If they are two geographically separate networks, which want to communicate with each other, they
may deploy a dedicated line between or they have to pass their data through intermediate
[Link] is a mechanism by which two or more same networks communicate with each
other, by passing intermediate networking complexities. Tunneling is configured at both ends.

Figure2.1 : Tunneling

When the data enters from one end of Tunnel, it is tagged. This tagged data is then routed inside the
intermediate or transit network to reach the other end of Tunnel. When data exists the Tunnel its tag is
removed and delivered to the other part of the network.

Both ends seem as if they are directly connected and tagging makes data travel through transit
network without any [Link] the general case of making two different networks
interwork is exceedingly difficult. However, there is a common special case that is manageable even
for different network protocols. This case is where the source and destination hosts are on the same
type of network, but there is a different network in between. As an example, think of an international
bank with an IPv6 network in Paris, an IPv6 network in London and connectivity between the offices
via the IPv4 Internet. This situation is shown in Fig.

Figure2.2 : Tunneling a packet from Paris to London.

The solution to this problem is a technique called tunneling. To send an IP packet to a host in the
London office, a host in the Paris office constructs the packet containing an IPv6 address in London,
and sends it to the multiprotocol router that connects the Paris IPv6 network to the IPv4 Internet.
When this router gets the IPv6 packet, it encapsulates the packet with an IPv4 header addressed to
the IPv4 side of the multiprotocol router that connects to the London IPv6 net work. That is, the router
puts a (IPv6) packet inside a (IPv4) packet. When this wrapped packet arrives, the London router
removes the original IPv6 packet and sends it onward to the destination host. The path through the
IPv4 Internet can be seen as a big tunnel extending from one multiprotocol router to the other. The
IPv6 packet just travels from one end of the tunnel to the other, snug in its nice box. It does not have
to worry about dealing with IPv4 at all. Neither do the hosts in Paris or London. Only the multi
protocol routers have to understand both IPv4 and IPv6 packets. In effect, the en
tire trip from one multiprotocol router to the other is like a hop over a single link.
Tunneling is widely used to connect isolated hosts and networks using other networks. The network
that results is called an overlay since it has effectively been overlaid on the base network.
Deployment of a network protocol with a new feature is a common reason, as our ‘‘IPv6 over IPv4’’
example shows. The disadvantage of tunneling is that none of the hosts on the network that is
tunneled over can be reached because the packets cannot escape in the middle of the tunnel.
However, this limitation of tunnels is turned into an advantage with VPNs (Virtual Private
Networks). A VPN is simply an overlay that is used to provide a measure of security.

Packet Fragmentation

Most Ethernet segments have their maximum transmission unit (MTU) fixed to 1500 bytes. A data
packet can have more or less packet length depending upon the application. Devices in the transit path
also have their hardware and software capabilities which tell what amount of data that device can
handle and what size of packet it can process.

If the data packet size is less than or equal to the size of packet the transit network can handle, it is
processed neutrally. If the packet is larger, it is broken into smaller pieces and then forwarded. This is
called packet fragmentation. Each fragment contains the same destination and source address and
routed through transit path easily. At the receiving end it is assembled again.

If a packet with DF (don’t fragment) bit set to 1 comes to a router which can not handle the packet
because of its length, the packet is [Link] a packet is received by a router has its MF (more
fragments) bit set to 1, the router then knows that it is a fragmented packet and parts of the original
packet is on the [Link] packet is fragmented too small, the overhead is increases. If the packet is
fragmented too large, intermediate router may not be able to process it and it might get dropped.

Internet Protocol (IP)


The Internet Protocol (IP) is the network layer communications protocol in the Internet protocol
suite for relaying datagrams across network boundaries. Its routing function enables internetworking,
and essentially establishes the Internet.

IP has the task of delivering packets from the source host to the destination host solely based on the IP
addresses in the packet headers. For this purpose, IP defines packet structures that encapsulate the
data to be delivered. It also defines addressing methods that are used to label the datagram with source
and destination information.

IP was the connectionless datagram service in the original Transmission Control Program introduced
by Vint Cerf and Bob Kahn in 1974, which was complemented by a connection-oriented service that
became the basis for the Transmission Control Protocol (TCP). The Internet protocol suite is therefore
often referred to as TCP/IP.

The first major version of IP, Internet Protocol version 4 (IPv4), is the dominant protocol of the
Internet. Its successor is Internet Protocol version 6 (IPv6), which has been in
increasing deployment on the public Internet since around 2006.
The Internet Protocol is responsible for addressing host interfaces, encapsulating data into datagrams
(including fragmentation and reassembly) and routing datagrams from a source host interface to a
destination host interface across one or more IP [Link] these purposes, the Internet Protocol
defines the format of packets and provides an addressing system.

Each datagram has two components: a header and a payload. The IP header includes a source IP
address, a destination IP address, and other metadata needed to route and deliver the datagram. The
payload is the data that is transported. This method of nesting the data payload in a packet with a
header is called encapsulation.

IP addressing entails the assignment of IP addresses and associated parameters to host interfaces. The
address space is divided into subnets, involving the designation of network prefixes. IP routing is
performed by all hosts, as well as routers, whose main function is to transport packets across network
boundaries. Routers communicate with one another via specially designed routing protocols,
either interior gateway protocols or exterior gateway protocols, as needed for the topology of the
network.

Figure2.3 :Encapsulation of application data

Addressing methods
There are four principal addressing methods in the Internet Protocol:

 Unicast delivers a message to a single specific node using a one-to-one association between a
sender and destination: each destination address uniquely identifies a single receiver endpoint.
 Broadcast delivers a message to all nodes in the network using a one-to-all association; a
single datagram (or packet) from one sender is routed to all of the possibly multiple endpoints
associated with the broadcast address. The network automatically replicates datagrams as needed
to reach all the recipients within the scope of the broadcast, which is generally an entire
network subnet.
 Multicast delivers a message to a group of nodes that have expressed interest in receiving the
message using a one-to-many-of-many or many-to-many-of-many association; datagrams are
routed simultaneously in a single transmission to many recipients. Multicast differs from broadcast
in that the destination address designates a subset, not necessarily all, of the accessible nodes.
 Anycast delivers a message to any one out of a group of nodes, typically the one nearest to the
source using a one-to-one-of-many[4] association where datagrams are routed to any single
member of a group of potential receivers that are all identified by the same destination address.
The routing algorithm selects the single receiver from the group based on which is the nearest
according to some distance or cost measure.
Routing schemes
Unicast

Broadcast

Multicast

Anycast

The IP Version 4 Protocol


An appropriate place to start our study of the network layer in the Internet is with the format of the IP
datagrams themselves. An IPv4 datagram consists of a header part and a body or payload part. The
header has a 20-byte fixed part and a variable-length optional part. The header format is shown in Fig.
5-46. The bits are transmitted from left to right and top to bottom, with the high-order bit of the
1. Version field going first. (This is a ‘‘big-endian’’ network byte order. On littleendian machines,
such as Intel x86 computers, a software conversion is required on both transmission and
reception.) In retrospect, little endian would have been a better choice, but at the time IP was
designed, no one knew it would come to dominate computing.
Figure2.4: IPv4 header

The Version field keeps track of which version of the protocol the datagram belongs to. Version 4
dominates the Internet today, and that is where we have started our discussion. By including the
version at the start of each datagram, it becomes possible to have a transition between versions over a
long period of time.
In fact, IPv6, the next version of IP, was defined more than a decade ago, yet is only just beginning to
be deployed. We will describe it later in this section. Its use will eventually be forced when each of
China’s almost 231 people has a desktop PC, a laptop, and an IP phone. As an aside on numbering,
IPv5 was an experimental real-time stream protocol that was never widely used.
2. Since the header length is not constant, a field in the header, IHL, is provided to tell how long
the header is, in 32-bit words. The minimum value is 5, which applies when no options are
present. The maximum value of this 4-bit field is 15, which limits the header to 60 bytes, and thus
the Options field to 40 bytes. For some options, such as one that records the route a packet has
taken, 40 bytes is far too small, making those options useless.
3. The Differentiated services field is one of the few fields that has changed its meaning (slightly)
over the years. Originally, it was called the Type of service field. It was and still is intended to
distinguish between different classes of ser vice. Various combinations of reliability and speed
are possible. For digitized voice, fast delivery beats accurate delivery. For file transfer, error-free
transmission is more important than fast transmission. The Type of service field provided 3 bits to
signal priority and 3 bits to signal whether a host cared more about delay, throughput, or
reliability. However, no one really knew what to do with these bits at routers, so they were left
unused for many years. When differentiated services were designed, IETF threw in the towel and
reused this field. Now, the top 6 bits are used to mark the packet with its service class; we
described the expedited and assured services earlier in this chapter. The bottom 2 bits are used to
carry explicit congestion notification information, such as whether the packet has experienced
congestion; we described explicit congestion notification as part of congestion control earlier in
this chapter.
4. The Total length includes everything in the datagram—both header and data. The maximum
length is 65,535 bytes. At present, this upper limit is tolerable, but with future networks, larger
datagrams may be needed.
5. The Identification field is needed to allow the destination host to determine which packet a
newly arrived fragment belongs to. All the fragments of a packet contain the same Identification
value. Next comes an unused bit, which is surprising, as available real estate in the IP header is
extremely scarce.

6. Then come two 1-bit fields related to fragmentation. DF stands for Don’t Fragment. It is an
order to the routers not to fragment the packet. Originally, it was intended to support hosts
incapable of putting the pieces back together again. Now it is used as part of the process to
discover the path MTU, which is the largest packet that can travel along a path without being
fragmented. By marking the datagram with the DF bit, the sender knows it will either arrive in
one piece, or an error message will be returned to the sender. MF stands for More Fragments. All
fragments except the last one have this bit set. It is needed to know when all fragments of a
datagram have arrived.
7. The Fragment offset tells where in the current packet this fragment belongs. All fragments
except the last one in a datagram must be a multiple of 8 bytes, the elementary fragment unit.
Since 13 bits are provided, there is a maximum of 8192 fragments per datagram, supporting a
maximum packet length up to the limit of the Total length field. Working together, the
Identification, MF, and Fragment offset fields are used to implement fragmentation.
8. The TtL (Time to live) field is a counter used to limit packet lifetimes. It was originally supposed
to count time in seconds, allowing a maximum lifetime of 255 sec. It must be decremented on
each hop and is supposed to be decremented multiple times when a packet is queued for a long
time in a router. In practice, it just counts hops. When it hits zero, the packet is discarded and a
warning packet is sent back to the source host. This feature prevents packets from wandering
around forever, something that otherwise might happen if the routing tables ever become
corrupted. When the network layer has assembled a complete packet, it needs to know what to
do with it.
9. The Protocol field tells it which transport process to give the packet to. TCP is one possibility,
but so are UDP and some others. The numbering of protocols is global across the entire Internet.
Protocols and other assigned numbers were formerly listed in RFC 1700, but nowadays they are
contained in an online database located at [Link].
10. Since the header carries vital information such as addresses, it rates its own checksum for
protection, the Header checksum. The algorithm is to add up all the 16-bit halfwords of the
header as they arrive, using one’s complement arithmetic, and then take the one’s complement of
the result. For purposes of this algorithm, the Header checksum is assumed to be zero upon
arrival. Such a checksum is useful for detecting errors while the packet travels through the
network. Note that it must be recomputed at each hop because at least one field always changes
(the Time to live field), but tricks can be used to speed up the computation.
11. The Source address and Destination address indicate the IP address of the source and
destination network interfaces. We will discuss Internet addresses in the next section. The field
was designed to provide an escape to allow subsequent versions of the protocol to include
information not present in the original design, to permit experimenters to try out new ideas, and
to avoid allocating header bits to information that is rarely needed. The options are of variable
length. Each begins with a 1-byte code identifying the option. Some options are followed by a 1-
byte option length field, and then one ormore data bytes.
12. The Options field is padded out to a multiple of 4 bytes. Originally, the five options listed in Fig.
were defined.
13. The Security option tells how secret the information is. In theory, a military router might use this
field to specify not to route packets through certain countries the military considers to be ‘‘bad
guys.’’ In practice, all routers ignore it, so its only practical function is to help spies find the good
stuff more easily.
Figure2.5 : Some IP Option

The Strict source routing option gives the complete path from source to destination as a sequence of
IP addresses. The datagram is required to follow thatexact route. It is most useful for system managers
who need to send emergency packets when the routing tables have been corrupted, or for making
timing meas
urements.
The Loose source routing option requires the packet to traverse the list of routers specified, in the
order specified, but it is allowed to pass through other routers on the way. Normally, this option will
provide only a few routers, to force a particular path. For example, to force a packet from London to
Sydney to gowest instead of east, this option might specify routers in New York, Los Angeles, and
Honolulu. This option is most useful when political or economic considerations dictate passing
through or avoiding certain countries.
The Record route option tells each router along the path to append its IP adress to the Options field.
This allows system managers to track down bugs in the routing algorithms (‘‘Why are packets from
Houston to Dallas visiting Tokyo first?’’). When the ARPANET was first set up, no packet ever
passed through more than nine routers, so 40 bytes of options was plenty. As mentioned above, now it
is too small.
Finally, the Timestamp option is like the Record route option, except that in addition to recording its
32-bit IP address, each router also records a 32-bit timestamp. This option, too, is mostly useful for
network measurement.

IP address

An IP address represents a unique address that distinguishes any device on the


internet or any network from another. IP or Internet Protocol defines the set of
commands directing the setup of data transferred through the internet or any other
local network.

An IP address is the identifier that enables your device to send or receive data packets across the
internet. It holds information related to your location and therefore making devices available for two-
way communication. The internet requires a process to distinguish between different networks,
routers, and websites. Therefore, IP addresses provide the mechanism of doing so, and it forms an
indispensable part in the working of the internet. You will notice that most of the IP addresses are
essentially numerical. Still, as the world is witnessing a colossal growth of network users, the network
developers had to add letters and some addresses as internet usage grows.
An IP address is represented by a series of numbers segregated by periods(.). They are expressed in
the form of four pairs - an example address might be [Link] wherein each set can range
from 0 to 255.

IP addresses are not produced randomly. They are generated mathematically and are further assigned
by the IANA (Internet Assigned Numbers Authority), a department of the ICANN. ICANN stands for
Internet Corporation for Assigned Names and Numbers. It is a non-profit corporation founded in the
US back in 1998 with an aim to manage Internet security and enable it to be available by all.

IP addresses working
Sometimes your device doesn't connect to your network the way you expect it to be, or you wish to
troubleshoot why your network is not operating correctly. To answer the above questions, it is vital to
learn the process with which IP addresses work.

Internet Protocol or IP runs the same manner as other languages, i.e., applying the set guidelines to
communicate the information. All devices obtain, send, and pass information with other associated
devices with the help of this protocol only. By using the same language, the computers placed
anywhere can communicate with one another.

The process of IP address works in the following way:

1. Your computer, smartphone, or any other Wi-Fi-enabled device firstly connects to a network
that is further connected to the internet. The network is responsible for giving your device
access to the internet.
2. While working from home, your device would be probably using that network provided by
your Internet Service Provider (ISP). In a professional environment, your device uses your
company network.
3. Your ISP is responsible to generate the IP address for your device.
4. Your internet request penetrates through the ISP, and they place the requested data back to
your device using your IP address. Since they provide you access to the internet, ISP's are
responsible for allocating an IP address to your computer or respective device.
5. Your IP address is never consistent and can change if there occurs any changes in its internal
environment. For instance, if you turn your modem or router on or off, it will change your IP
address. Or the user can also connect the ISP to change their IP address.
6. When you are out of your home or office, mainly if you travel and carry your device with you,
your computer won't be accessing your home IP address anymore. This is because you will be
accessing the different networks (your phone hotspot, Wi-Fi at a cafe, resort, or airport, etc.) to
connect the device with the internet. Therefore, your device will be allocated a different
(temporary) IP address by the ISP of the hotel or cafe.
Figure2.6 : Types of IP Address

Classes of IPv4 Address: There are around 4.3 billion IPv4 addresses and managing all those
addresses without any scheme is next to impossible. Let’s understand it with a simple example. If
you have to find a word from a language dictionary, how long will it take? Usually, you will take
less than 5 minutes to find that word. You are able to do this because words in the dictionary are
organized in alphabetical order. If you have to find out the same word from a dictionary that doesn’t
use any sequence or order to organize the words, it will take an eternity to find the word. If a
dictionary with one billion words without order can be so disastrous, then you can imagine the pain
behind finding an address from 4.3 billion addresses.

Prefixes
IP addresses are hierarchical, unlike Ethernet addresses. Each 32-bit address is comprised of a
variable-length network portion in the top bits and a host portion in the bottom bits. The network
portion has the same value for all hosts on a single network, such as an Ethernet LAN. This means
that a network corresponds to a contiguous block of IP address space. This block is called a prefix.
IP addresses are written in dotted decimal notation. In this format, each of the 4 bytes is written in
decimal, from 0 to 255. For example, the 32-bit hexadecimal address 80D00297 is written as
[Link]. Prefixes are written by giving the lowest IP address in the block and the size of the
block. The size is determined by the number of bits in the network portion; the remaining bits in the
host portion can vary. This means that the size must be a power of two. By convention, it is written
after the prefix IP address as a slash followed by the length in bits of the network portion. In our
example, if the prefix contains 28 addresses and so leaves 24 bits for the network portion, it is written
as [Link]/24.
Since the prefix length cannot be inferred from the IP address alone, routing protocols must carry the
prefixes to routers. Sometimes prefixes are simply described by their length, as in a ‘‘/16’’ which is
pronounced ‘‘slash 16.’’ The length of the prefix corresponds to a binary mask of 1s in the network
portion. When written out this way, it is called a subnet mask. It can be ANDed with the IP address
to extract only the network portion. For our example, the subnet mask is [Link]. Fig. 5-48
shows a prefix and a subnet mask.

For easier management and assignment IP addresses are organized in numeric order and divided
into the following 5 classes :
Figure2.7 :- Five classes of IP addresses

Figure2.8 : IP Address Format

Class A

IP addresses belonging to class A are assigned to the networks that contain a large number of hosts.
 The network ID is 8 bits long.
 The host ID is 24 bits long.
The higher-order bit of the first octet in class A is always set to 0. The remaining 7 bits in the first
octet are used to determine network ID. The 24 bits of host ID are used to determine the host in any
network. The default subnet mask for Class A is 255.x.x.x. Therefore, class A has a total of:
 2^24 – 2 = 16,777,214 host ID
IP addresses belonging to class A ranges from [Link] – [Link].
Class B

IP address belonging to class B is assigned to networks that range from medium-sized to large-sized
networks.
 The network ID is 14 bits long.
 The host ID is 16 bits long.
The higher-order bits of the first octet of IP addresses of class B are always set to 10. The remaining
14 bits are used to determine the network ID. The 16 bits of host ID are used to determine the host
in any network. The default subnet mask for class B is 255.255.x.x. Class B has a total of:
 2^14 = 16384 network address
 2^16 – 2 = 65534 host address
IP addresses belonging to class B ranges from [Link] – [Link].

Class C

IP addresses belonging to class C are assigned to small-sized networks.


 The network ID is 24 bits long.
 The host ID is 8 bits long.
The higher-order bits of the first octet of IP addresses of class C is always set to 110. The remaining
21 bits are used to determine the network ID. The 8 bits of host ID are used to determine the host in
any network. The default subnet mask for class C is 255.255.255.x. Class C has a total of:
 2^21 = 2097152 network address
 2^8 – 2 = 254 host address
IP addresses belonging to class C range from [Link] – [Link].

Class D

IP address belonging to class D is reserved for multi-casting. The higher-order bits of the first octet
of IP addresses belonging to class D is always set to 1110. The remaining bits are for the address
that interested hosts recognize.
Class D does not possess any subnet mask. IP addresses belonging to class D range from [Link]
– [Link].
Class E

IP addresses belonging to class E are reserved for experimental and research purposes. IP addresses
of class E range from [Link] – [Link]. This class doesn’t have any subnet mask. The
higher-order bits of the first octet of class E are always set to 1111.

Range of Special IP Addresses


[Link] – [Link] : Link-local addresses
[Link] – [Link] : Loop-back addresses
[Link] – [Link]: used to communicate within the current network.

Rules for Assigning Host ID


Host IDs are used to identify a host within a network. The host ID is assigned based on the
following rules:
 Within any network, the host ID must be unique to that network.
 A host ID in which all bits are set to 0 cannot be assigned because this host ID is used to
represent the network ID of the IP address.
 Host ID in which all bits are set to 1 cannot be assigned because this host ID is reserved as a
broadcast address to send packets to all the hosts present on that particular network.
Rules for Assigning Network ID
Hosts that are located on the same physical network are identified by the network ID, as all host on
the same physical network is assigned the same network ID. The network ID is assigned based on
the following rules:
 The network ID cannot start with 127 because 127 belongs to the class A address and is
reserved for internal loopback functions.
 All bits of network ID set to 1 are reserved for use as an IP broadcast address and therefore,
cannot be used.
 All bits of network ID set to 0 are used to denote a specific host on the local network and are
not routed and therefore, aren’t used.
Summary of Classful Addressing

Figure2.9: IP Address Range


Subnetting
Subnets
Network numbers are managed by a nonprofit corporation called ICANN (Internet Corporation for
Assigned Names and Numbers), to avoid conflicts. In turn, ICANN has delegated parts of the
address space to various regional authorities, which dole out IP addresses to ISPs and other companies.
This is the process by which a company is allocated a block of IP addresses. However, this process is
only the start of the story, as IP address assignment is ongoing as companies grow. We have said that
routing by prefix requires all the hosts in a network to have the same network number. This property
can cause problems as networks grow. For example, consider a university that started out with our
example /16 prefix for use by the Computer Science Dept. for the computers on its Ethernet. A year
later, the Electrical Engineering Dept. wants to get on the Internet. The Art Dept. soon follows suit.
What IP addresses should these departments use? Getting further blocks requires going outside the
university and may be expensive or inconvenient. Moreover, the /16 already allocated has enough
addresses for over 60,000 hosts. It might be intended to allow for signifi cant growth, but until that
happens, it is wasteful to allocate further blocks of IP addresses to the same university. A different
organization is required. The solution is to allow the block of addresses to be split into several parts
for internal use as multiple networks, while still acting like a single network to the outside world.
This is called subnetting and the networks (such as Ethernet LANs) that result from dividing up a
larger network are called subnets. As we mentioned we should be aware that this new usage of the
term conflicts with older usage of ‘‘subnet’’ to mean the set of all routers and communication lines in
a network.

Figure 2.10: Subnetting

Subnetting enables the network administrator to further divide the host part of the address into
two or more subnets. In this case, a

part of the host address is reserved to identify the particular subnet. This is easier to see if we
show the IP address in binary format.
Figure 2.11: Subnetting without and with

Subnet masks are frequently expressed in dotted decimal notation Subnet mask is not an IP
address. Each host on a TCP/IP network requires a subnet mask even on a single segment
network.

Address Class Bits for Subnet Mask Subnet Mask


Class A 11111111 00000000 00000000 00000000 [Link]
Class B 11111111 11111111 00000000 00000000 [Link]
Class C 11111111 11111111 11111111 00000000 [Link]

Supernetting
Supernetting is the opposite of Subnetting. In subnetting, a single big network is divided into
multiple smaller subnetworks. In Supernetting, multiple networks are combined into a bigger
network termed a Supernetwork or Supernet.
Supernetting is the process of aggregating routes to multiple smaller networks. Thus saving storage
space in the routing table, simplifying routing decisions, and reducing route advertisements to
neighboring gateways. Supernetting has helped address the increasing size of routing tables as the
Internet has expanded. Supernetting is mainly used in Route Summarization, where routes to
multiple networks with similar network prefixes are combined into a single routing entry, with the
routing entry pointing to a Super network, encompassing all the networks. This in turn significantly
reduces the size of routing tables and also the size of routing updates exchanged by routing
protocols.
More specifically,
 When multiple networks are combined to form a bigger network, it is termed super-netting
 Super netting is used in route aggregation to reduce the size of routing tables and routing
table updates
Important Points for Supernetting
 All the Networks should be contiguous.
 The block size of every network should be equal and must be in form of 2n.
 First Network id should be exactly divisible by whole size of supernet.

Example: Suppose 4 small networks of class C:

[Link],
[Link],
[Link],
[Link]

Build a bigger network that has a single Network Id.


Explanation: Before Supernetting routing table will look like as:

Network Id Subnet Mask Interface

[Link] [Link] A

[Link] [Link] B

[Link] [Link] C

[Link] [Link] D
First, let’s check whether three conditions are satisfied or not:
 Contiguous: You can easily see that all networks are contiguous all having size 256 IP
Addresses( or 254 Hosts )..
Range of first Network from [Link] to [Link]. If you add 1 in last IP address of first
network that is [Link] + [Link], you will get the next network id which is [Link].
Similarly, check that all network are contiguous.
 Equal size of all network: As all networks are of class C, so all of them have a size of 256
which is in turn equal to 28.
 First IP address exactly divisible by total size: When a binary number is divided by
2n then last n bits are the remainder. Hence in order to prove that first IP address is exactly
divisible by while size of Supernet Network. You can check that if last n (n here refers to the
number of bits required to represent the Total Size of the Supernet) bits are 0 or not.
In the given example first IP is [Link] and whole size of supernet is 4*28 = 210. If last 10 bits of
first IP address are zero then IP will be divisible.

Last 10 bits of first IP address are zero (highlighted by green color). So 3rd condition is also
satisfied.
Advantages of Supernetting
 Control and reduce network traffic
 Helpful to solve the problem of lacking IP addresses
 Minimizes the routing table i.e, it cannot cover a different area of the network when
combined and all the networks should be in the same class and all IP should be contiguous
Classless Inter Domain Routing (CIDR)
Classless Inter-Domain Routing (CIDR) is a method of IP address allocation and IP routing that
allows for more efficient use of IP addresses. CIDR is based on the idea that IP addresses can be
allocated and routed based on their network prefix rather than their class, which was the traditional
way of IP address allocation.
Representation: It is as also a 32-bit address, which includes a special number that represents the
number of bits that are present in the Block Id.
a.b.c.d/n
Where n is the number of bits that are present in Block Id / Network Id.
Example:
[Link]/20

CIDR addresses are represented using a slash notation, which specifies the number of bits in the
network prefix. For example, an IP address of [Link] with a prefix length of 24 would be
represented as [Link]/24. This notation indicates that the first 24 bits of the IP address are the
network prefix and the remaining 8 bits are the host identifier.
Several Advantages of the Traditional Class-Based Addressing System of CIDR
 Efficient use of IP addresses: CIDR allows for more efficient use of IP addresses by allowing
the allocation of IP addresses based on their network prefix rather than their class.
 Flexibility: CIDR allows for more flexible IP address allocation, as it allows for the allocation
of arbitrary-sized blocks of IP addresses.
Better routing: CIDR allows for better routing of IP traffic, as it allows routers to aggregate IP
addresses based on their network prefix, reducing the size of routing tables.
 Reduced administrative overhead: CIDR reduces administrative overhead by allowing for the
allocation and routing of IP addresses in a more efficient and flexible way.
 In summary, CIDR is a method of IP address allocation and routing that allows for more
efficient use of IP addresses and better routing of IP traffic. It has several advantages over the
traditional class-based addressing system, including greater flexibility, better routing, and reduced
administrative overhead.
As with any technology or system, there are advantages and disadvantages of using CIDR:
Advantages of CIDR
 Efficient use of IP addresses: CIDR allows for more efficient use of IP addresses, which is
important as the pool of available IPv4 addresses continues to shrink.
 Flexibility: CIDR allows for more flexible allocation of IP addresses, which can be important
for organizations with complex network requirements.
 Better routing: CIDR allows for more efficient routing of IP traffic, which can lead to better
network performance. Reduced administrative overhead: CIDR reduces administrative overhead
by allowing for easier management of IP addresses and routing.
Disadvantages of CIDR
 Complexity: CIDR can be more complex to implement and manage than traditional class-
based addressing, which can require additional training and expertise.
 Compatibility issues: Some older network devices may not be compatible with CIDR, which
can make it difficult to transition to a CIDR-based network.
 Security concerns: CIDR can make it more difficult to implement security measures such as
firewall rules and access control lists, which can increase security risks.
 Overall, CIDR is a useful and efficient method of IP address allocation and routing, but it may
not be suitable for all organizations or networks. It is important to weigh the advantages and
disadvantages of CIDR and consider the specific needs and requirements of your network before
implementing CIDR.
As we have already learned about Classful Addressing, so in this article, we are going to learn about
Classless Inter-Domain Routing. which is also known as Classless addressing. In Classful addressing
the no of Hosts within a network always remains the same depending upon the class of the Network.
Class A network contains 224(IP addresses) or 224 - 2 Hosts,
Class B network contains 216(IP addresses) or 216 - 2 Hosts,
Class C network contains 28(IP addresses) or 28 - 2 Hosts
Rules for forming CIDR Blocks:
All IP addresses must be contiguous.
Block size must be the power of 2 (2^n). If the size of the block is the power of 2, then it will be
easy to divide the Network. Finding out the Block Id is very easy if the block size is of the power of
2.
Example: If the Block size is 2^5 then, Host Id will contain 5 bits and Network will contain 32 – 5
= 27 bits.

First IP address of the Block must be evenly divisible by the size of the block. in simple words, the
least significant part should always start with zeroes in Host Id. Since all the least significant bits of
Host Id is zero, then we can use it as Block Id part.
Example: Check whether [Link] to [Link] is a valid IP address block or not?
 All the IP addresses are contiguous.
 Total number of IP addresses in the Block = 16 = 2^4.
 1st IP address: 100.1.2.00100000 Since, Host Id will contains last 4 bits and all the least
significant 4 bits are zero. Hence, first IP address is evenly divisible by the size of the block.
All three rules are followed by this Block. Hence, it is a valid IP address block.

ICMP
IMCP—The Internet Control Message Protocol
The operation of the Internet is monitored closely by the routers. When something unexpected occurs
during packet processing at a router, the event is reported to the sender by the ICMP (Internet
Control Message Protocol). ICMP is also used to test the Internet. About a dozen types of ICMP
messages are defined.
Each ICMP message type is carried encapsulated in an IP packet. The most important ones are listed
in Figure.
The DESTINATION UNREACHABLE message is used when the router cannot locate the destination
or when a packet with the DF bit cannot be delivered because a ‘‘small-packet’’ network stands in the
way.
Figure2.11: Principle of ICMP message type

The TIME EXCEEDED message is sent when a packet is dropped because its TtL (Time to live)
counter has reached zero. This event is a symptom that packets are looping, or that the counter values
are being set too low. One clever use of this error message is the traceroute utility that was
developed by Van Jacobson in 1987. Traceroute finds the routers along the path from the host to a
destination IP address. It finds this information without any kind of privileged network support. The
method is simply to send a sequence of packets to the destination, first with a TtL of 1, then a TtL of 2,
3, and so on. The counters on these packets will reach zero at successive routers along the path. These
routers will each obediently send a TIME EXCEEDED message back to the host. From those
messages, the host can determine the IP addresses of the routers along the path, as well as keep
statistics and timings on parts of the path. It is not what the TIME EXCEEDED message was intended
for, but it is perhaps the most useful network debugging tool of all time. \

The PARAMETER PROBLEM message indicates that an illegal value has been detected in a header
field. This problem indicates a bug in the sending host’s IP software or possibly in the software of a
router transited.
The SOURCE QUENCH message was long ago used to throttle hosts that were sending too many
packets. When a host received this message, it was expected to slow down. It is rarely used anymore
because when congestion occurs, these packets tend to add more fuel to the fire and it is unclear how
to respond to them. Congestion control in the Internet is now done largely by taking action in the
transport layer, using packet losses as a congestion signal.
The REDIRECT message is used when a router notices that a packet seems to be routed incorrectly. It
is used by the router to tell the sending host to update to a better route.
The ECHO and ECHO REPLY messages are sent by hosts to see if a given destination is reachable
and currently alive. Upon receiving the ECHO message,the destination is expected to send back an
ECHO REPLY message. These messages are used in the ping utility that checks if a host is up and on
the Internet.
The TIMESTAMP REQUEST and TIMESTAMP REPLY messages are similar, except that the
arrival time of the message and the departure time of the reply are recorded in the reply. This facility
can be used to measure network performance.
The ROUTER ADVERTISEMENT and ROUTER SOLICITATION messages are used to let hosts
find nearby routers. A host needs to learn the IP address of at least one router to be able to send
packets off the local network. In addition to these messages, others have been defined.
ARP—The Address Resolution Protocol
Although every machine on the Internet has one or more IP addresses, these addresses are not
sufficient for sending packets. Data link layer NICs (Network \Interface Cards) such as Ethernet cards
do not understand Internet addresses. In the case of Ethernet, every NIC ever manufactured comes
equipped with a unique 48-bit Ethernet address. Manufacturers of Ethernet NICs request a block of
Ethernet addresses from IEEE to ensure that no two NICs have the same address (to avoid conflicts
should the two NICs ever appear on the same LAN). The NICs send and receive frames based on 48-
bit Ethernet addresses. They know nothing at all about 32-bit IP addresses.
The question now arises, how do IP addresses get mapped onto data link layer addresses, such as
Ethernet? To explain how this works, let us use the example of Figure, in which a small university
with two /24 networks is illustrated. One network (CS) is a switched Ethernet in the Computer
Science Dept. It has the prefix [Link]/24. The other LAN (EE), also switched Ethernet, is in
Electrical Engineering and has the prefix [Link]/24. The two LANs are connected by an IProuter.
Each machine on an Ethernet and each interface on the router has a unique Ethernet address, labeled
E1 through E6, and a unique IP address on the CS or EE network. Let us start out by seeing how a
user on host 1 sends a packet to a user on host 2 on the CS network. Let us assume the sender knows
the name of the intended receiver, possibly something like [Link]. For the moment, we will
just assume that DNS returns the IP address for host 2 ([Link]). The upper layer software on host
1 now builds a packet with [Link] in the Destination address field and gives it to the IP software
to transmit. The IP software can look at the address and see that the destination is on the CS network,
(i.e., its own network). However, it still needs some way to find the destination’s Ethernet address to
send the frame. One solution is to have a configuration file somewhere in the system that maps IP
addresses onto Ethernet addresses. While this solution is certainly possible, for organizations with
thousands of machines keeping all these files up to date is an error-prone, time-consuming job.
A better solution is for host 1 to output a broadcast packet onto the Ethernet asking who owns IP
address [Link]. The broadcast will arrive at every machine on the CS Ethernet, and each one will
check its IP address. Host 2 alone will respond with its Ethernet address (E2). In this way host 1
learns that IP address [Link] is on the host with Ethernet address E2. The protocol used for
asking this question and getting the reply is called ARP (Address Resolution Protocol). Almost
every machine on the Internet runs it. ARP is defined in RFC 826.
The advantage of using ARP over configuration files is the simplicity. The system manager does not
have to do much except assign each machine an IP address and decide about subnet masks. ARP does
the rest. At this point, the IP software on host 1 builds an Ethernet frame addressed to E2, puts the
IPpacket (addressed to [Link]) in the payload field, and dumps it onto the Ethernet. The IP and
Ethernet addresses of this packet are given in Figure.. The Ethernet NIC of host 2 detects this frame,
recognizes it as a frame for itself, scoops it up, and causes an interrupt. The Ehernet driver extracts the
IP packet from the payload and passes it to the IP software, which sees that it is cor
recently addressed and processes it. Various optimizations are possible to make ARP work more
efficiently. To start with, once a machine has run ARP, it caches the result in case it needs to contact
the same machine shortly. Next time it will find the mapping in its own cache, thus eliminating the
need for a second broadcast. In many cases, host 2will need to send back a reply, forcing it, too, to run
ARP to determine the sender’s Ethernet address. This ARP broadcast can be avoided by having host 1
include its IP-to-Ethernet mapping in the ARP packet. When the ARP broadcast arrives at host 2, the
pair ([Link], E1) is entered into host 2’s ARP cache. In fact, all machines on the Ethernet can
enter this mapping into their ARP caches. To allow mappings to change, for example, when a host is
configured to use a new IP address (but keeps its old Ethernet address), entries in the ARP cache
should time out after a few minutes. A clever way to help keep the cached information current and to
optimize performance is to have every machine broadcast its mapping when it is configured. This
broadcast is generally done in the form of an ARP looking for its own IP address. There should not be
a response, but a side effect of the broadcast is to make or update an entry in everyone’s ARP cache.
This is known as a gratuitous ARP. If a response does (unexpectedly) arrive, two machines have
been assigned the same IP address. The error must be resolved by the network manager before both
machines can use the network.

When the Ethernet NIC of the router gets this frame, it gives the packet to the IP software. It knows
from the network masks that the packet should be sent onto the EE network where it will reach host 4.
If the router does not know the Ethernet address for host 4, then it will use ARP again. The table in
Figure lists the source and destination Ethernet and IP addresses that are present in the frames as
observed on the CS and EE networks. Observe that the Ethernet addresses change with the frame on
each network while the IP addresses remain constant (because they indicate the endpoints across all of
the interconnected networks).
It is also possible to send a packet from host 1 to host 4 without host 1 knowing that host 4 is on a
different network. The solution is to have the router answer ARPs on the CS network for host 4 and
give its Ethernet address, E3, as the response. It is not possible to have host 4 reply directly because it
will not see the ARP request (as routers do not forward Ethernet-level broadcasts). The router will
then receive frames sent to [Link] and forward them onto the EE network. This solution is called
proxy ARP. It is used in special cases in which a host wants to appear on a network even though it
actually resides on another network. A common situation, for example, is a mobile computer that
wants some other node to pick up packets for it when it is not on its home network

Bootstrap Protocol (BOOTP)


Bootstrap Protocol (BOOTP) is a networking protocol which is used by networking administration ,It
is set of rules which assigns the IP (Internet Protocol) address to each node/member which
participates in the network to communicate with others or to the central server.
The Bootstrap Protocol (BOOTP) is an internet protocol that helps a network user automatically get
an IP address and boot an operating system. Here's some information about BOOTP address
allocation, configuration, and packet format:

Important Features of Bootstrap Protocol :


 Bootstrap Protocol (BOOTP) is a basic protocol that automatically provides each participant
in a network connection with a unique IP address for identification and authentication as
soon as it connects to the network. This helps the server to speed up data transfers and
connection requests.
 BOOTP uses a unique IP address algorithm to provide each system on the network with a
completely different IP address in a fraction of a second.
 This shortens the connection time between the server and the client. It starts the process of
downloading and updating the source code even with very little information.
 BOOTP uses a combination of TFTP (Trivial File Transfer Protocol) and UDP (User
Datagram Protocol) to request and receive requests from various network-connected
participants and to handle their responses.
 In a BOOTP connection, the server and client just need an IP address and a gateway address
to establish a successful connection. Typically, in a BOOTP network, the server and client
share the same LAN, and the routers used in the network must support BOOTP bridging.
 A great example of a network with a TCP / IP configuration is the Bootstrap Protocol
network. Whenever a computer on the network asks for a specific request to the server,
BOOTP uses its unique IP address to quickly resolve them.

Bootstrap Protocol differs from DHCP :



DHCP network servers have much broader use than a BOOTP network server. It may be
used for the purpose when a user gives request to the server for a particular IP address and it
gives the response of that particular IP address only, hence, time is not wasted for monitoring
other addresses, saving time from having to monitor additional addresses.
 Each network user is identified and authenticated by BOOTP using the UDP (User Datagram
Protocol) over an IPv4 address connection. Additionally, a BOOTP connection contains a
reliable static database of IP addresses that provides the client with the needed IP address right
away.

Working of Bootstrap Protocol :

 At the very beginning, each network participant does not have an IP address. The network
administrator then provides each host on the network with a unique IP address using the IPv4
protocol.
 The client installs the BOOTP network protocol using TCP / IP Intervention on its computer
system to ensure compatibility with all network protocols when connected to this network.
 The BOOTP network administrator then sends a message that contains a valid unicast address.
This unicast address is then forwarded to the BOOTP client by the master server.
Uses of Bootstrap Protocol :

1. Bootstrap (BOOTP) is primarily required to check the system on a network the first time
you start your computer. Records the BIOS cycle of each computer on the network to allow the
computer’s motherboard and network manager to efficiently organize the data transfer on the
computer as soon as it boots up.
2. BOOTP is mainly used in a diskless environment and requires no media as all data is stored
in the network cloud for efficient use.
3. BOOTP is the transfer of a data between a client and a server to send and receive requests
and corresponding responses by the networking server.
4. BOOTP supports the use of motherboards and network managers, so no external storage
outside of the cloud network is required.

Address allocation
BOOTP assigns an IP address from a pool of addresses to a client computer that requests one. The
administrator preconfigures the pool of addresses.

Configuration
The client computer uses the IP address and other settings, like the default gateway and DNS servers,
to configure its network interface card (NIC).

Packet format
The BOOTP packet format includes fields for the following:

 Operation code
 Transaction ID
 Time elapsed
 Client/server IP addresses
 Boot file name
 Options

Advantages of BOOTP

 Automatic IP Addressing: BOOTP allows devices to automatically obtain an IP address


and other pertinent network configurations without administrative intervention.
 Central Management: A network administrator can manage the assignment of IP addresses
and their configurations from one central server, thereby making the management of a network
easier.
 Stable IP Addresses: Most BOOTP implementations allot the same IP address for any
given machine whenever it boots, which provides the same configuration for the network.
 Legacy Support: BOOTP is backward compatible; that is, it functions with older network
devices and systems that may not support more modern protocols, such as DHCP.

Disadvantages of BOOTP

 No Flexibility: BOOTP does not provide any dynamic IP address leasing, hence is
inefficient for IP address allocation in environments where devices are changing often.
 Static Configuration: BOOTP configurations are static and need to be updated manually on
the server in case of any changes in the network settings; hence, it is not much adapted to
dynamic network settings.
 Slower Initialization: BOOTP requires a more complex setup process compared to DHCP
that can slow down the initialization of devices on a network.
 Obsolescence: BOOTP has been overridden by DHCP, which is much more functional and
better suited to modern network configurations.
DHCP—The Dynamic Host Configuration Protocol
ARP (as well as other Internet protocols) makes the assumption that hosts are configured with some
basic information, such as their own IP addresses. How do hosts get this information? It is possible to
manually configure each computer, but that is tedious and error-prone. There is a better way, and it is
called DHCP
DHCP (Dynamic Host Configuration Protocol) works at the Application layer of the TCP/IP model.
This protocol is responsible for automatically assigning IP addresses, subnet masks, and other
network configuration settings to devices on a network. The Application layer is the topmost layer of
the TCP/IP model and is responsible for providing network services to applications. DHCP operates
at this layer as it provides a service that allows devices to obtain the necessary network configuration
information to communicate on the network.
DHCP (Dynamic Host Configuration Protocol) is an extension of BOOTP (Bootstrap Protocol).
BOOTP was the predecessor of DHCP and provided a way for a computer to obtain its IP address,
subnet mask, and other network configuration information from a central server. DHCP builds upon
this functionality by adding more features, such as dynamic allocation of IP addresses and automatic
configuration of additional network parameters like DNS servers and default gateways. Therefore,
DHCP is an extension of BOOTP.

(Dynamic Host Configuration Protocol). With DHCP, every network must have a DHCP server that is
responsible for configuration. When a computer is started, it has a built-in Ethernet or other link layer
address embedded in the NIC, but no IP address. Much like ARP, the computer broadcasts a request
for an IP address on its network. It does this by using a DHCP DISCOVER packet. This packet must
reach the DHCP server. If that server is not directly attached to the network, the router will be
configured to receive DHCP broadcasts and relay them to the DHCP server, wherever it is located.
When the server receives the request, it allocates a free IP address and sends it to the host in a DHCP
OFFER packet (which again may be relayed via the router). To be able to do this work even when
hosts do not have IP addresses, the server identifies a host using its Ethernet address (which is carried
in the DHCP DISCOVER packet)
An issue that arises with automatic assignment of IP addresses from a pool is for how long an IP
address should be allocated. If a host leaves the network and does not return its IP address to the
DHCP server, that address will be permanently lost. After a period of time, many addresses may be
lost. To prevent that from happening, IP address assignment may be for a fixed period of time, a
technique called leasing. Just before the lease expires, the host must ask for a DHCP renewal. If it
fails to make a request or the request is denied, the host may no longer use the IP address it was given
earlier. DHCP is described in RFCs 2131 and 2132. It is widely used in the Internet to configure all
sorts of parameters in addition to providing hosts with IP addresses. As well as in business and home
networks, DHCP is used by ISPs to set the parameters of devices over the Internet access link, so that
customers do not
need to phone their ISPs to get this information. Common examples of the information that is
configured include the network mask, the IP address of the default gateway, and the IP addresses of
DNS and time servers. DHCP has largely replaced earlier protocols (called RARP and BOOTP) with
more limited functionality.

Advantages of DHCP
 Auto-IP Assignment: DHCP clients reserve or get auto-assignment of the IP address to a
system, which decreases the manual configuration of the IP address and avoids address conflicts.
 Centralized Management: Network settings and IP address assignments are configured on
a central DHCP server managed by the network administrators.
 Dynamic IP Allocation: DHCP can dynamically allocate and reclaim IP addresses
depending on demand, optimizing IP address usage and accommodates devices which frequently
join and leave the network.
 Configuration Flexibility: It configures various options on the network; DHCP supports a
whole series of configuration options for the network, for example, subnet masks, default
gateways, DNS servers, many more. Hence, the protocol is adaptable to different network
configurations.

Disadvantages of DHCP

 Dependency Upon the DHCP Server: If the DHCP server goes down or is unavailable, the
devices might not obtain the IP addresses, hence not connecting over the network.
 Security Issues: The DHCP, when not configured and secured properly, is prone to attacks,
like DHCP spoofing. Here, unauthorized servers start issuing incorrect configuration information.
 Leasing of IP Address: IP addresses provided by DHCP are leased for some time. This may
result in temporary shortages or inefficiency of address allocation, especially when devices are
frequently added and removed from the network.
 Complexity in Large Networks: In large networks, handling a large number of DHCP
servers or complex configuration takes a lot of time and needs a good planning and monitoring
process.
Components of DHCP
The main components of DHCP include:
 DHCP Server: DHCP Server is a server that holds IP Addresses and other information
related to configuration.
 DHCP Client: It is a device that receives configuration information from the server. It can
be a mobile, laptop, computer, or any other electronic device that requires a connection.
 DHCP Relay: DHCP relays basically work as a communication channel between DHCP
Client and Server.
 IP Address Pool: It is the pool or container of IP Addresses possessed by the DHCP Server.
It has a range of addresses that can be allocated to devices.
 Subnets: Subnets are smaller portions of the IP network partitioned to keep networks under
control.
 Lease: It is simply the time that how long the information received from the server is valid,
in case of expiration of the lease, the tenant must have to re-assign the lease.
 DNS Servers: DHCP servers can also provide DNS (Domain Name System) server
information to DHCP clients, allowing them to resolve domain names to IP addresses.
 Default Gateway: DHCP servers can also provide information about the default gateway,
which is the device that packets are sent to when the destination is outside the local network.
 Options: DHCP servers can provide additional configuration options to clients, such as the
subnet mask, domain name, and time server information.
 Renewal: DHCP clients can request to renew their lease before it expires to ensure that they
continue to have a valid IP address and configuration information.
 Failover: DHCP servers can be configured for failover, where two servers work together to
provide redundancy and ensure that clients can always obtain an IP address and configuration
information, even if one server goes down.
 Dynamic Updates: DHCP servers can also be configured to dynamically update DNS
records with the IP address of DHCP clients, allowing for easier management of network
resources.
 Audit Logging: DHCP servers can keep audit logs of all DHCP transactions, providing
administrators with visibility into which devices are using which IP addresses and when leases
are being assigned or renewed.

DHCP Packet Format

Figure DHCP Packet Format


 Hardware Length: This is an 8-bit field defining the length of the physical address in bytes.
e.g for Ethernet the value is 6.
 Hop count: This is an 8-bit field defining the maximum number of hops the packet can
travel.
 Transaction ID: This is a 4-byte field carrying an integer. The transcation identification
is set by the client and is used to match a reply with the request. The server returns the same
value in its reply.
 Number of Seconds: This is a 16-bit field that indicates the number of seconds elapsed
since the time the client started to boot.
 Flag: This is a 16-bit field in which only the leftmost bit is used and the rest of the bit
should be set to os. A leftmost bit specifies a forced broadcast reply from the server. If the reply
were to be unicast to the client, the destination. IP address of the IP packet is the address
assigned to the client.
 Client IP Address: This is a 4-byte field that contains the client IP address . If the client
does not have this information this field has a value of 0.
 Your IP Address: This is a 4-byte field that contains the client IP address. It is filled by the
server at the request of the client.
 Server IP Address: This is a 4-byte field containing the server IP address. It is filled by the
server in a reply message.
 Gateway IP Address: This is a 4-byte field containing the IP address of a routers. IT is
filled by the server in a reply message.
 Client Hardware Address: This is the physical address of the client .Although the server
can retrieve this address from the frame sent by the client it is more efficient if the address is
supplied explicity by the client in the request message.
 Server Name: This is a 64-byte field that is optionally filled by the server in a reply packet.
It contains a null-terminated string consisting of the domain name of the server. If the server
does not want to fill this filed with data, the server must fill it with all 0s.
 Boot Filename: This is a 128-byte field that can be optionally filled by the server in a reply
packet. It contains a null- terminated string consisting of the full pathname of the boot file. The
client can use this path to retrieve other booting information. If the server does not want to fill
this field with data, the server must fill it with all 0s.
 Options: This is a 64-byte field with a dual purpose. IT can carry either additional
information or some specific vendor information. The field is used only in a reply message. The
server uses a number, called a magic cookie, in the format of an IP address with the value of
[Link]. When the client finishes reading the message, it looks for this magic cookie. If
present the next 60 bytes are options.

Working of DHCP
DHCP works on the Application layer of the UDP Protocol. The main task of DHCP is to
dynamically assigns IP Addresses to the Clients and allocate information on TCP/IP configuration
to Clients. For more, you can refer to the Article Working of DHCP.
The DHCP port number for the server is 67 and for the client is 68. It is a client-server protocol
that uses UDP services. An IP address is assigned from a pool of addresses. In DHCP, the client and
the server exchange mainly 4 DHCP messages in order to make a connection, also called
the DORA process, but there are 8 DHCP messages in the process.
Figure:- Working of DHCP

The 8 DHCP Messages


1. DHCP Discover Message: This is the first message generated in the communication process
between the server and the client. This message is generated by the Client host in order to discover
if there is any DHCP server/servers are present in a network or not. This message is broadcasted to
all devices present in a network to find the DHCP server. This message is 342 or 576 bytes long.

Figure DHCP Discover Message


As shown in the figure, the source MAC address (client PC) is 08002B2EAF2A, the destination
MAC address(server) is FFFFFFFFFFFF, the source IP address is [Link](because the PC has had
no IP address till now) and the destination IP address is [Link] (IP address used for
broadcasting). As they discover message is broadcast to find out the DHCP server or servers in the
network therefore broadcast IP address and MAC address is used.
2. DHCP Offers A Message: The server will respond to the host in this message specifying the
unleased IP address and other TCP configuration information. This message is broadcasted by the
server. The size of the message is 342 bytes. If there is more than one DHCP server present in the
network then the client host will accept the first DHCP OFFER message it receives. Also, a server
ID is specified in the packet in order to identify the server.
Figure:-DHCP Offer Message

Now, for the offer message, the source IP address is [Link] (server’s IP address in the
example), the destination IP address is [Link] (broadcast IP address), the source MAC
address is 00AA00123456, the destination MAC address is 00:11:22:33:44:55 (client’s MAC
address). Here, the offer message is broadcast by the DHCP server therefore destination IP address
is the broadcast IP address and destination MAC address is 00:11:22:33:44:55 (client’s MAC
address)and the source IP address is the server IP address and the MAC address is the server MAC
address.
Also, the server has provided the offered IP address [Link] and a lease time of 72 hours(after
this time the entry of the host will be erased from the server automatically). Also, the client
identifier is the PC MAC address (08002B2EAF2A) for all the messages.
3. DHCP Request Message: When a client receives an offer message, it responds by broadcasting
a DHCP request message. The client will produce a gratuitous ARP in order to find if there is any
other host present in the network with the same IP address. If there is no reply from another host,
then there is no host with the same TCP configuration in the network and the message is
broadcasted to the server showing the acceptance of the IP address. A Client ID is also added to this
message.
Figure:- DHCP Request Message

Now, the request message is broadcast by the client PC therefore source IP address is [Link](as the
client has no IP right now) and destination IP address is [Link] (the broadcast IP address)
and the source MAC address is 08002B2EAF2A (PC MAC address) and destination MAC address
is FFFFFFFFFFFF.
Note – This message is broadcast after the ARP request broadcast by the PC to find out whether any
other host is not using that offered IP. If there is no reply, then the client host broadcast the DHCP
request message for the server showing the acceptance of the IP address and Other TCP/IP
Configuration.
4. DHCP Acknowledgment Message: In response to the request message received, the server will
make an entry with a specified client ID and bind the IP address offered with lease time. Now, the
client will have the IP address provided by the server.

Now the server will make an entry of the client host with the offered IP address and lease time. This
IP address will not be provided by the server to any other host. The destination MAC address is
00:11:22:33:44:55 (client’s MAC address) and the destination IP address is
[Link] and the source IP address is [Link] and the source MAC address is
00AA00123456 (server MAC address).
5. DHCP Negative Acknowledgment Message: Whenever a DHCP server receives a request for
an IP address that is invalid according to the scopes that are configured, it sends a DHCP Nak
message to the client. Eg-when the server has no IP address unused or the pool is empty, then this
message is sent by the server to the client.
6. DHCP Decline: If the DHCP client determines the offered configuration parameters are different
or invalid, it sends a DHCP decline message to the server. When there is a reply to the
gratuitous ARP by any host to the client, the client sends a DHCP decline message to the server
showing the offered IP address is already in use.
7. DHCP Release: A DHCP client sends a DHCP release packet to the server to release the IP
address and cancel any remaining lease time.
8. DHCP Inform: If a client address has obtained an IP address manually then the client uses
DHCP information to obtain other local configuration parameters, such as domain name. In reply to
the DHCP inform message, the DHCP server generates a DHCP ack message with a local
configuration suitable for the client without allocating a new IP address. This DHCP ack message is
unicast to the client.
Note – All the messages can be unicast also by the DHCP relay agent if the server is present in a
different network.
Security Considerations for Using DHCP
To make sure your DHCP servers are safe, consider these DHCP security issues:
 Limited IP Addresses: A DHCP server can only offer a set number of IP addresses. This
means attackers could flood the server with requests, causing essential devices to lose their
connection.
 Fake DHCP Servers: Attackers might set up fake DHCP servers to give out fake IP
addresses to devices on your network.
 DNS Access: When users get an IP address from DHCP, they also get DNS server details.
This could potentially allow them to access more data than they should. It’s important to restrict
network access, use firewalls, and secure connections with VPNs to protect against this.
OSPF—An Interior Gateway Routing Protocol
As we mentioned earlier, the Internet is made up of a large number of independent networks or ASes
(Autonomous Systems) that are operated by different organizations, usually a company, university,
or ISP. Inside of its own network, an organization can use its own algorithm for internal routing, or
intradomain routing, as it is more commonly known. Nevertheless, there are only a handful of
standard protocols that are popular. In this section, we will study the problem of intradomain routing
and look at the OSPF protocol that is widely used in practice. An intradomain routing protocol is also
called an interior gateway protocol. In the next section, we will study the problem of routing
between independently operated networks, or inter domain routing. For that case, all networks must
use the same interdomain routing protocol or exterior gateway protocol. The protocol that is used in
the Internet is BGP (Border Gateway Protocol).
Early intradomain routing protocols used a distance vector design, based on the distributed Bellman-
Ford algorithm inherited from the ARPANET. RIP (Routing Information Protocol) is the main
example that is used to this day. It works well in small systems, but less well as networks get larger. It
also suffers from the count-to-infinity problem and generally slow convergence. The ARPANET
switched over to a link state protocol in May 1979 because of these problems, and in 1988 IETF
began work on a link state protocol for intradomain routing. That protocol, called OSPF (Open
Shortest Path First), became a standard in 1990. It drew on a protocol called IS-IS (Intermediate-
System to Intermediate-System), which became an ISO standard. Because of their shared heritage,
the two protocols are much more alike than different. For the complete story, see RFC 2328. They are
the dominant intradomain routing protocols, and most router vendors now support both of them.
OSPF is more widely used in company networks, and IS-IS is more widely used in ISP networks. Of
the two, we will give a sketch of how OSPF works. Given the long experience with other routing
protocols, the group designing OSPF had a long list of requirements that had to be met. First, the
algorithm had to be published in the open literature, hence the ‘‘O’’ in OSPF.
A proprietary solution owned by one company would not do. \
Second, the new protocol had to support a variety of distance metrics, including physical distance,
delay, and so on.
Third, it had to be a dynamic algorithm, one that adapted to changes in the topology automatically and
quickly.
fourth, and new for OSPF, it had to support routing based on type of service.
The new protocol had to be able to route real-time traffic one way and other traffic a different way. At
the time, IP had a Type of service field, but no existing routing protocol used it. This field was
included in OSPF but still nobody used it, and it was eventually removed. Perhaps this requirement
was ahead of its time, as it preceded IETF’s work on differentiated services, which has rejuvenated
classes of service.
Fifth, and related to the above, OSPF had to do load balancing, splitting the load over multiple lines.
Most previous protocols sent all packets over a single best route, even if there were two routes that
were equally good. The other route was not used at all. In many cases, splitting the load over multiple
routes gives better performance.
Sixth, support for hierarchical systems was needed. By 1988, some networks had grown so large that
no router could be expected to know the entire topology. OSPF had to be designed so that no router
would have to.
Seventh, some modicum of security was required to prevent fun-loving students from spoofing routers
by sending them false routing information.
Finally, provision was needed for dealing with routers that were connected to the Internet
via a tunnel. Previous protocols did not handle this well.
OSPF supports both point-to-point links (e.g., SONET) and broadcast networks (e.g., most LANs).
Actually, it is able to support networks with multiple routers, each of which can communicate directly
with the others (called multiaccess networks) even if they do not have broadcast capability. Earlier
protocols did not handle this case well.
An example of an autonomous system network is given in Figure Hosts are omitted because they do
not generally play a role in OSPF, while routers and networks (which may contain hosts) do. Most of
the routers in Figures are connected to other routers by point-to-point links, and to networks to reach
the hosts on those networks. However, routers R3, R4, and R5 are connected by a broadcast LAN such
as switched Ethernet. OSPF operates by abstracting the collection of actual networks, routers, and
links into a directed graph in which each arc is assigned a weight (distance, delay, etc.). A point-to-
point connection between two routers is represented by a pair of arcs, one in each direction. Their
weights may be different. A broadcast network is represented by a node for the network itself, plus a
node for each router. The arcs from that network node to the routers have weight 0. They are
important nonetheless, as without them there is no path through the network. Other networks, which
have only hosts, have only an arc reaching them and not one returning. This structure gives routes to
hosts, but not through them.

Figure (b) shows the graph representation of the network of Fig. (a).

What OSPF fundamentally does is represent the actual network as a graph like this and then use the
link state method to have every router compute the shortest path from itself to all other nodes.
Multiple paths may be found that are equally short. In this case, OSPF remembers the set of shortest
paths and during packet forwarding, traffic is split across them. This helps to balance load. It is called
ECMP (Equal Cost MultiPath). Many of the ASes in the Internet are themselves large and
nontrivial to manage. To work at this scale, OSPF allows an AS to be divided into numbered areas,
where an area is a network or a set of contiguous networks. Areas do notoverlap but need not be
exhaustive, that is, some routers may belong to no area.
Routers that lie wholly within an area are called internal routers. An area is a generalization of an
individual network. Outside an area, its destinations are visible but not its topology. This
characteristic helps routing to scale. Every AS has a backbone area, called area 0. The routers in this
area are called backbone routers. All areas are connected to the backbone, possibly by tunnels, so it
is possible to go from any area in the AS to any other area in the AS via the backbone. A tunnel is
represented in the graph as just another arc with a cost. As with other areas, the topology of the
backbone is not visible outside the backbone.
Each router that is connected to two or more areas is called an area border router. It must also be
part of the backbone. The job of an area border router is to summarize the destinations in one area
and to inject this summary into the other areas to which it is connected. This summary includes cost
information but not all the details of the topology within an area. Passing cost information allows
hosts in other areas to find the best area border router to use to enter an area. Not passing topology
information reduces traffic and simplifies the shortest-path computations of routers in other areas.
However, if there is only one border router out of an area, even the summary does not need to be
passed. Routes to destinations out of the area always start with the instruction ‘‘Go to the border
router.’’ This kind of area is called a stub area.
The last kind of router is the AS boundary router. It injects routes to external destinations on other
ASes into the area. The external routes then appear as destinations that can be reached via the AS
boundary router with some cost. An external route can be injected at one or more AS boundary
routers. The relationship between ASes, areas, and the various kinds of routers is shown in Figure
One router may play multiple roles, for example, a border router is also a backbone router.

Figure :The relation ship between ASes, areas, and the various kinds of routers

Messages Types in OSPF

When a router boots, it sends HELLO messages on all of its point-to-point lines and multicasts them
on LANs to the group consisting of all the other routers. From the responses, each router learns who
its neighbors are. Routers on the same LAN are all neighbors. OSPF works by exchanging
information between adjacent routers, which is not the same as between neighboring routers. In
particular, it is inefficient to have every router on a LAN talk to every other router on the LAN.
Toavoid this situation, one router is elected as the designated router. It is said to be adjacent to
all the other routers on its LAN, and exchanges information with them. In effect, it is acting as
thesingle node that represents the LAN. Neighboring routers that are not adjacent do not exchange
information with each other. A backup designated router is always kept up to date to ease the
transition should the primary designated router crash and need to be replaced immediately.
During normal operation, each router periodically floods LINK STATE UPDATE messages to each
of its adjacent routers. These messages gives its state and provide the costs used in the topological
database. The flooding messages are
acknowledged, to make them reliable. Each message has a sequence number, so a router can see
whether an incoming LINK STATE UPDATE is older or newer than what it currently has. Routers
also send these messages when a link goes up or down or its cost changes. DATABASE
DESCRIPTION messages give the sequence numbers of all the link state entries currently held by the
sender. By comparing its own values with those of the sender, the receiver can determine who has the
most recent values. These messages are used when a link is brought up. Either partner can request link
state information from the other one by using LINK STATE REQUEST messages. The result of this
algorithm is that each pair of adjacent routers checks to see who has the most recent data, and new
information is spread throughout the area this way

Open Shortest Path First (OSPF) is a link-state routing protocol that is used to find the best path
between the source and the destination router using its own Shortest Path First). OSPF is developed
by Internet Engineering Task Force (IETF) as one of the Interior Gateway Protocol (IGP), i.e, the
protocol which aims at moving the packet within a large autonomous system or routing domain. It
is a network layer protocol which works on protocol number 89 and uses AD value 110. OSPF uses
multicast address [Link] for normal communication and [Link] for update to designated
router(DR)/Backup Designated Router (BDR).

OSPF Terms

1. Router Id – It is the highest active IP address present on the router. First, the highest
loopback address is considered. If no loopback is configured then the highest active IP address
on the interface of the router is considered.
2. Router priority – It is an 8-bit value assigned to a router operating OSPF, used to elect DR
and BDR in a broadcast network.
3. Designated Router (DR) – It is elected to minimize the number of adjacencies formed. DR
distributes the LSAs to all the other routers. DR is elected in a broadcast network to which all the
other routers share their DBD. In a broadcast network, the router requests for an update to DR,
and DR will respond to that request with an update.
4. Backup Designated Router (BDR) – BDR is a backup to DR in a broadcast network. When
DR goes down, BDR becomes DR and performs its functions.
5. DR and BDR election – DR and BDR election takes place in the broadcast network or
multi-access network. Here are the criteria for the election:
 The router having the highest router priority will be declared as DR.
 If there is a tie in router priority then the highest router I’d be considered. First, the
highest loopback address is considered. If no loopback is configured then the highest active IP
address on the interface of the router is considered.

Criteria –
To form a neighborship in OSPF, there is a criterion for both routers:
1. It should be present in the same area.
2. The router I’d be unique.
3. The subnet mask should be the same.
4. Hello, and the dead timer should be the same.
5. The stub flag must match.
6. Authentication must match.

OSPF supports NULL, plain text, MD5 authentication.


Note – Both the routers (neighbors) should have some type of authentication enabled. e.g- if one
neighbor has MD5 authentication enabled then others should also have MD5 authentication
enabled.
OSPF messages –
OSPF uses certain messages for the communication between the routers operating OSPF.
 Hello message –
These are keep-alive messages used for neighbor discovery /recovery. These are exchanged
every 10 seconds. This includes the following information: Router I’d, Hello/dead interval, Area
I’d, Router priority, DR and BDR IP address, authentication data.
 Database Description (DBD) –
It is the OSPF route of the router. This contains the topology of an AS or an area (routing
domain).
 Link state request (LSR) –
When a router receives DBD, it compares it with its own DBD. If the DBD received has some
more updates than its own DBD then LSR is being sent to its neighbor.
 Link state update (LSU) –
When a router receives LSR, it responds with an LSU message containing the details requested.
 Link state acknowledgement –
This provides reliability to the link-state exchange process. It is sent as the acknowledgement of
LSU.
 Link state advertisement (LSA) –
It is an OSPF data packet that contains link-state routing information, shared only with the
routers to which adjacency has been formed.
Note – Link State Advertisement and Link State Acknowledgement both are different messages.
Timers –
 Hello timer –
The interval in which the OSPF router sends a hello message on an interface. It is 10 seconds by
default.
 Dead timer –
The interval in which the neighbor will be declared dead if it is not able to send the hello packet.
It is 40 seconds by default. It is usually 4 times the hello interval but can be configured manually
according to need.

Figure 25: OSPF packet header


Major fields of the OSPF packet header are as follows:
Version—OSPF version number, which is 2 for OSPFv2.
Type—OSPF packet type from 1 to 5, corresponding to hello, DD, LSR, LSU, and LSAck,
respectively.
Packet length—Total length of the OSPF packet in bytes, including the header.
Router ID—ID of the advertising router.
Area ID—ID of the area where the advertising router resides.
Checksum—Checksum of the message.
AuType—Authentication type, ranging from 0 to 2, corresponding to non-authentication, simple
(plaintext) authentication, and MD5 authentication, respectively.
Authentication—Information determined by authentication type. It is not defined for
authentication type 0. It is defined as password information for authentication type 1, and defined
as Key ID, MD5 authentication data length, and sequence number for authentication type 2.

OSPF Message Format


The following are the fields in an OSPF message format:

There are five different types of packets in OSPF:

o Hello
o Database Description
o Link state request
o Link state update
o Link state Acknowledgment

BGP—The Exterior Gateway Routing Protocol


Within a single AS, OSPF and IS-IS are the protocols that are commonly used. Between ASes, a
different protocol, called BGP (Border Gateway Protocol), is used. A different protocol is needed
because the goals of an intradomain protocol and an interdomain protocol are not the same. All an
intradomain protocol has to do is move packets as efficiently as possible from the source to the
destination. It does not have to worry about politics. In contrast, interdomain routing protocols have to
worry about politics a great deal (Metz, 2001). For example, a corporate AS might want the ability
tosend packets to any Internet site and receive packets from any Internet site. However,
it might be unwilling to carry transit packets originating in a foreign AS and ending in a different
foreign AS, even if its own AS is on the shortest path between the two foreign ASes (‘‘That’s their
problem, not ours’’). On the other hand, it might be willing to carry transit traffic for its neighbors, or
even for specific other ASes that paid it for this service. Telephone companies, for example, might be
happy to act as carriers for their customers, but not for others. Exterior gateway protocols in general,
and BGP in particular, have been designed to allow many kinds of routing policies to be enforced in
the interAS traffic. Typical policies involve political, security, or economic considerations. A few
examples of possible routing constraints are:
1. Do not carry commercial traffic on the educational network.
2. Never send traffic from the Pentagon on a route through Iraq.
3. Use TeliaSonera instead of Verizon because it is cheaper.
4. Don’t use AT&T in Australia because performance is poor.
5. Traffic starting or ending at Apple should not transit Google.
As you might imagine from this list, routing policies can be highly individual. They are often
proprietary because they contain sensitive business informationHowever, we can describe some
patterns that capture the reasoning of the company above and that are often used as a starting point.
A routing policy is implemented by deciding what traffic can flow over which of the links between
ASes. One common policy is that a customer ISP pays another provider ISP to deliver packets to any
other destination on the Internet and receive packets sent from any other destination. The customer
ISP is said to buy transit service from the provider ISP. This is just like a customer at home buying
Internet access service from an ISP. To make it work, the provider should advertise routes to all
destinations on the Internet to the customer over the link that connects them. In this way, the customer
will have a route to use to send packets anywhere. Conversely, the customer should advertise routes
only to the destinations on its network to the provider. This will let the provider send traffic to the
customer only for those addresses; the customer does not want to handle traffic intended for other
destinations. We can see an example

figure :Routing Policy between 4 AS

There are four ASes that are connected. The connection is often made with a link at IXPs (Internet
eXchange Points), facilities to which many ISPs have a link for the purpose of connecting with other
ISPs. AS2, AS3, and AS4 are customers of AS1. They buy transit service from it. Thus, when source A
sends to destination C, the packets travel from AS2 to AS1 and finally to AS4. The routing
advertisements travel in the opposite direction to the packets. AS4 advertises C as a destination to its
transit provider, AS1, to let sources reach C via AS1. Later, AS1 advertises a route to C to its other
customers, including AS2, to let the customers know that they can send traffic to C via AS1.

An example of how BGP routes are advertised is shown in Figure There are three ASes and the
middle one is providing transit to the left and right ISPs. A route advertisement to prefix C starts in
AS3. When it is propagated across the link to R2c at the top of the figure, it has the AS path of simply
AS3 and the next hop router of R3a. At the bottom, it has the same AS path but a different next hop
because it came across a different link. This advertisement continues to propagate and crosses the
boundary into AS1. At router R1a, at the top of the figure, the AS path is AS2, AS3 and the next hop is
R2a.

Giving a list of ASes is a very coarse way to specify a path. An AS might be a small company, or an
international backbone network. There is no way of telling from the route. BGP does not even try
because different ASes may use different intradomain protocols whose costs cannot be compared.
Even if they could be compared, an AS may not want to reveal its internal metrics. This is one of the
ways that interdomain routing protocols differ from intradomain [Link] far we have seen how a
route advertisement is sent across the link between two ISPs. We still need some way to propagate
BGP routes from one side of the ISP to the other, so they can be sent on to the next ISP. This task
could be handled by the intradomain protocol, but because BGP is very good at scaling to large
networks, a variant of BGP is often used. It is called iBGP (internal BGP) to distinguish it from the
regular use of BGP as eBGP (external BGP)
Figure : Propogation of BGP route Advertisment

o
Border Gateway Protocol
BGP is an interdomain routing protocol, and it uses the path-vector routing. It is a gateway protocol
that is used to exchange routing information among the autonomous system on the [Link] we
know that Border Gateway Protocol works on different autonomous systems, so we should know the
history of BGP, types of autonomous systems, etc.

Border Gateway Protocol (BGP) is a routing protocol, that works on an application level. BGP
chooses the most efficient routes to deliver Internet traffic.
Characteristics of Border Gateway Protocol (BGP)
 Inter-Autonomous System Configuration: The main role of BGP is to provide
communication between two autonomous systems.
 BGP supports the Next-Hop Paradigm.
 Coordination among multiple BGP speakers within the AS (Autonomous System).
 Path Information: BGP advertisements also include path information, along with the
reachable destination and next destination pair.
 Policy Support: BGP can implement policies that can be configured by the administrator.
For ex:- a router running BGP can be configured to distinguish between the routes that are
known within the AS and that which are known from outside the AS.
 Runs Over TCP.
 BGP conserves network Bandwidth.
 BGP supports CIDR.
 BGP also supports Security.

How BGP works


BGP can be called an Internet delivery service. When you send something to someone, the fastest and
most efficient route is chosen to send your parcel. BGP works in a very similar way, when someone
sends data over the Internet, BGP checks all the available paths that the data can travel and chooses
the best route. For example, when a user in Cork loads a website with source servers somewhere in
Texas, BGP provides the fastest and most efficient interaction.

BGP Neighbors
BGP neighbors are peer-to-peer nodes that are manually installed between routers. To maintain the
BGP connection, the speaker sends keepalive messages every 60 seconds. The main difference
between BGP and other routing protocols is that it uses TCP as the transport protocol.
There are two types of BGP: internal or iBGP and external eBGP. It is called internal when it works
in one autonomous system (AS), and external when it works in different autonomous systems.
iBGP and eBGP also differ in how routes received from one neighbor propagate to other neighbors.
For example, new routes received from eBGP are usually redistributed between all iBGP nodes and
all other eBGP neighbors. However, if new routes are advertised on an iBGP peer, they are only re-
advertised to all BGP peers. This means that all iBGP neighbors must be connected to the same
network.

BGP Message Format


A header and a data part are two essential parts of a BGP message. BGP is triggered by sending the
four message types: open, update, notification and keepalive. The header format is the same for all
types. Messages are transferred based on TCP (port 179). The length can be from 19 to 4096 octets.
The header of each BGP message consists of three fields and is 19 octets.

BGP Message Types


BGP starts its work with four message types:
. OPEN - Sets and configures BGP adjacency.
The OPEN message is used to set the BGP adjacency. Both parties agree on the session probabilities
before the peering is set up. The OPEN message contains the BGP version number, the ASN of the
source router, the hold time, the BGP ID, and other additional parameters that determine the session
capabilities.
. UPDATE - Announces, updates, or cancels routes.
The UPDATE message declares any possible routes, cancels previously declared routes, or can do
both. The UPDATE message includes Network Layer Reachability Information (NLRI) that
combines the prefix and its associated BGP PA when announcing prefixes. The withdrawn NLRIs
include only the prefix. The UPDATE message can act to reduce irrelevant traffic.
. NOTIFICATION - Indicates the error status to the BGP neighbor.
A NOTIFICATION message is sent when an error is detected in a BGP session, such as a hold timer
expiration, a change in neighbor capabilities, or a request to reset the BGP session. This message
closes the BGP connection.
. KEEPALIVE - Ensures the serviceability of BGP neighbors.
BGP does not rely on the state of the TCP connection to ensure that the neighbors are still working.
KEEPALIVE messages are returned every third of the hold timer agreed between the two BGP
routers. If the hold time is set to zero, Keepalive messages between BGP neighbors are not sent.

1. Marker: It is a 32-bit field which is used for the authentication purpose.


2. Length: It is a 16-bit field that defines the total length of the message, including the header.
3. Type: It is an 8-bit field that defines the type of the packet.
BGP Neighbor States
BGP forms a TCP session with neighboring routers, known as local peers. BGP uses a Finite State
Machine (FSM) to maintain a table of all BGP peers and their serviceability status. A BGP session
can report the following states
 Idle:
This is the first stage of BGP FSM. BGP detects the start event, attempts to initiate a TCP connection
to the peer, and waits for a new connection from the peer router.
 Connect:
In this state, BGP starts a TCP connection. If the three-way TCP confirmation is successful, the set
BGP session process resets the ConnectRetryTimer and sends an OPEN message to the neighbor, and
then switches to the OpenSent state.
 Active:
In this state, BGP starts a new three-way TCP confirmation. If the connection is set, then an OPEN
message is sent and the timer is set to 4 minutes, and the state switches to OpenSent. If a further TCP
connection attempts fail, the state returns to the CONNECT state and resets the ConnectRetryTimer.
 OpenSent:
In this state, the source router sends an OPEN message and is waiting for an OPEN message from the
other router. After the source router receives the OPEN message from the other router both messages
are verified for errors.
 OpenConfirm:
In this state, BGP expects a KEEPALIVE or NOTIFICATION message. After receiving the
KEEPALIVE message from a neighbor, the state changes to Established. If the hold timer expires, a
stop event occurs or a NOTIFICATION message is received, and BGP switches to the IDLE state.
 Established:
In this state, the BGP session is established. BGP neighbors exchange routes via UPDATE messages.
When the UPDATE and KEEPALIVE messages are received, the hold timer is reset. If the hold timer
expires, an error is detected, and BGP puts the neighbor back in the IDLE state.
IPV4 and IPV6

Common questions

Powered by AI

Routers use OSPF to manage large autonomous systems by representing the network as a graph and employing link state routing to compute the shortest paths to all nodes. OSPF supports routing scalability by dividing an AS into numbered areas, where each area can be separately managed and is connected to a backbone area for inter-area communication. This structure allows effective distribution of routing tasks and efficient handling of complex network topologies .

DHCP uses an IP address leasing method to prevent permanent loss, whereby IP addresses are allocated for a fixed period. This ensures that addresses can be reclaimed and reused if a host leaves the network without returning its IP address. However, this can introduce inefficiencies such as temporary shortages or address allocation issues, particularly in environments where devices are frequently added or removed from the network .

ARP (Address Resolution Protocol) is crucial in Ethernet networks for mapping IP addresses to MAC (Media Access Control) addresses. Every NIC (Network Interface Card) on Ethernet understands only MAC addresses, not IP addresses. ARP allows an Ethernet device to find the MAC address associated with an IP address, enabling data link layer communication of frames based on MAC addresses, thus allowing IP packets to be properly routed within the local network .

BGP differs from OSPF in its ability to apply varied routing policies between autonomous systems, addressing concerns beyond simple path efficiency, such as political and economic considerations. BGP enables the enforcement of complex routing policies based on business interests and external agreements, unlike OSPF, which focuses solely on efficient packet routing within a single AS .

Centralized DHCP management offers advantages like reduced manual configuration, prevention of address conflicts, and consistent network policy implementation. However, its limitations include reliance on the DHCP server's availability and potential security vulnerabilities such as spoofing attacks. In large networks, managing multiple DHCP servers and configurations can also become complex and require meticulous planning .

Routers in broadcast and non-broadcast multi-access networks can face issues with handling multiple simultaneous communications. OSPF addresses these challenges by abstracting the network into a directed graph and using the link state method to compute the shortest paths. In OSPF, a broadcast network is represented by a node for the network itself and nodes for each router, with arcs from the network node to routers having a weight of 0, allowing for efficient traffic distribution and load balancing through Equal Cost MultiPath (ECMP).

The DHCP DORA process, consisting of Discovery, Offer, Request, and Acknowledgment messages, is essential for dynamically assigning IP addresses to network devices. It ensures that clients locate DHCP servers, receive an IP address offer, request the offer, and finally obtain a confirmation acknowledgment. This process supports efficient network management and minimizes configuration errors, facilitating seamless device integration into networks .

The main components of a DHCP server include the DHCP server itself, which holds IP addresses and network configuration information, and DHCP clients, which are devices that receive this configuration. These components ensure efficient network management by centralizing control of IP allocations and configuration settings, reducing manual intervention, and supporting dynamic network environments where devices frequently enter and leave the network .

DHCP is susceptible to security vulnerabilities such as DHCP spoofing, where unauthorized servers issue incorrect configuration information to clients. This can lead to network integrity issues, such as clients being unable to connect due to receiving incorrect IP addresses or configuration settings. Proper configuration and securing of DHCP servers are critical to mitigating these attacks .

The backbone area in OSPF, known as area 0, is necessary for facilitating inter-area communication within an autonomous system. It ensures that all areas are connected, either directly or through tunnels, allowing data to traverse through any area across the AS. The backbone area supports the scalability of OSPF by abstracting inter-area routes, thus simplifying the overall routing structure .

You might also like