Routing Technologies
- Static routing
- Manually configured routing tables. The administrator explicitly defines next-hop addresses for each destination network.
- Must be manually updated when topology changes.
- Dynamic routing
- Networks automatically share route information, propagating knowledge of topology changes.
- Border Gateway Protocol (BGP)
- Port 179 (TCP)
- Exterior gateway protocol (used between autonomous systems (AS))
- Path-vector protocol (instead of distance/link-state)
- Scales to handle the entire internet routing table.
- Enhanced Interior Gateway Routing Protocol (EIGRP)
- Cisco proprietary distance-vector protocol.
- Uses Diffusing Update Algorithm (DUAL) to calculate best paths.
- Fast convergence with minimal network traffic.
- Supports VLSM and CIDR.
- Open Shortest Path First (OSPF)
- Link-state routing protocol.
- Creates topology map through link-state advertisements (LSAs).
- Uses Djikstra's algorithm to find shortest path.
- Organises networks into areas for scalability.
- Faster convergence than distance-vector protocols.
- Route Selection
- Administrative distance
- Indicates how trustworthy a routing source is (lower numbers are better)
- E.g. directly connected networks are more trustworthy than OSPF.
- Prefix length
- Indicates how specific a route is. More specific routes are prefered.
- E.g. a route to
192.168.1.0/24is more specific than192.168.0.0/16
- Metric
- Value used by routing protocols to determine best path. Different for each protocol.
- Cost, bandwidth, delay, reliability, load, hop count
- Administrative distance
- Address translation
- Network Address Translation (NAT)
- Maps one IP address to another.
- Static 1-1 mapping between public and private addresses or dynamic mapping from a pool of public addresses.
- Helps conserve public IP addresses by allowing many devices to connect to the internet through one address.
- Port Address Translation (PAT)
- aka. NAT overload or many-to-one NAT.
- Common in home or small business networks.
- Port numbers are used to track different connections through a single IP address.
- Network Address Translation (NAT)
- First Hop Redundancy Protocol (FHRP)
- FHRPs provide high availability for default gateways through redundacy.
- Virtual IP (VIP)
- Shared IP address used by multiple physical routers
- Client devices use the VIP as their default gateway.
- If the VIP fails, another takes over.
- Sub-interfaces
- Allows one physical network port to act as several virtual ports.
- Each virtual port can connect to a different network.
Switching Technologies
- Virtual Local Area Network (VLAN)
- Using a VLAN-capable switch, devices on the same logical network are separated into isolated logical virtual LANs.
- Its like a logical, rather than physical, subnet.
- Each port on the switch designates a separate VLAN.
- VLANs alleviate excessive broadcast traffic.
- VLAN1 is the default VLAN on most switches.
- VLAN database
- Storage area for VLAN configuration information (vlan.dat)
- Stores VLAN numbers, names and associated ports.
- Switch Virtual Interface (SVI)
- Allows a switch to have an IP address within that VLAN.
- Enables remote management of the switch.
- Acts as a gateway for inter-VLAN routing on Layer 3 switches.
- Interface Configuration
- Native VLAN
- The default VLAN assigned to frames arriving on a trunk port without VLAN tags.
- Defaults to VLAN1 on most switches.
- Best practice to change the native VLAN from VLAN1 immediately.
- Voice VLAN
- Dedicated VLAN for VoIP.
- Improved performance using QoS to reduce jitter and packet loss.
- Tagged traffic on a trunk port.
- 802.1Q tagging
- Standard used to insert VLAN tags into Ethernet frames.
- The tag is a 4-byte field between the source MAC address and the EtherType/Length field
- A VLAN ID (VID) is a 12-bit value used to identify the target VLAN.
- Trunk ports carry tagged traffic from multiple VLANs, adding a tag to each frame.
- Access ports carry untagged traffic for a single VLAN.
- Link Aggregation
- The practice of combining multiple physical network links into a single logical link.
- Provides failover redundancy and load balancing.
- Typically used with trunk ports, and Link Aggregation Control Protocol (LACP).
- Speed
- ???
- Duplex
- Refers to the mode in which data can be transmitted over a network.
- Half-duplex or one-way, like walkie-talkies and older 10BASE-T cables
- Full-duplex or two-way, like telephones and modern 100BASE-TX
- Collisions are more likely in half duplex.
- Native VLAN
- Spanning Tree Protocol (STP)
- Protocol to ensure there are no loops in a switched Ethernet network, which might use loops for redundancy.
- Ensures that only path exists between any two devices by dynamically blocking redundant paths.
- A central root bridge is used as a reference point.
- When topology changes, STP opens up blocked ports to create new paths.
- Rapid STP is a version with faster convergence.
- Multiple STP enables spanning trees across multiple VLANs.
- Maximum Transmission Unit (MTU)
- The largest size of a packet in bytes that can be transmitted over a network without being fragmented.
- Larger MTU size increases throughput, but it must match the network capability otherwise fragmentation occurs.
- Ethernet is typically 1500 bytes.
- Jumbo frames
- Can increase MTU to 9000 bytes or more.
Wireless Technologies
- Channels
- Specific frequency ranges within the radio spectrum. They allow devices to transmit and receive signals without interference.
- Each channel is centred around a base frequency: i.e. Channel 1 is 20Mhz either side of 2.412Ghz
- Channel width
- How much of a frequency range is used for communication.
- Wider channels have higher bandwidth but more interference.
- 2.4GHz width is typically 20Mhz and its channels do not overlap.
- 5GHz offers different channel widths at 20, 40, 80, 120MHz.
- Non-overlapping channels
- Channels that do overlap frequency and thus do not interfere.
- In 2.4Ghz its channels 1, 6 and 11.
- In 5Ghz there are numerous which might overlap.
- As channel width increases, overlapping is more likely to occur.
- Regulatory impacts
- 802.11h
- Dynamic Frequency Selection (DSF)
- Ensures all devices automatically detect and avoid ranges used by radar systems.
- Transmit Power Control (TPU)
- Devices must detect and limit transmit power in regulated environments.
- Higher transmit power increases potential for interference.
- Dynamic Frequency Selection (DSF)
- 802.11h
- Frequency Options
- 2.4GHz
- Longest range. Can penetrate obstacles like walls.
- Lower speed due to more interference (crowded) and lower channel width (20mhz).
- 3 non-overlapping channels shared between many devices like microwaves, bluetooth, cordless phones.
- 5.6GHz
- Shorter range. Less effective at penetration.
- Wider channels widths (20, 40, 60, 120) and less interference.
- Many more available channels (up to 25 non-overlapping)
- 6GHz
- Shortest range.
- Wide channels up to 160mhz.
- Less congested as recently opened.
- Band steering
- Used in dual and tri-band wifi to automatically direct devices to the appropriate frequency based on device capability, signal strength and network congestion.
- 2.4GHz
- Service Set Identifier (SSID)
- Basic Service Set Identifier (BSSID)
- The primary identifier for a wireless network. It is the name broadcast by the access point.
- E.g.
HomeNetwork
- Extended Service Set Identifier (ESSID)
- Used when there are multiple access points broadcasting for the same network.
- E.g.
HomeNetwork_1
- Basic Service Set Identifier (BSSID)
- Network Types
- Mesh networks
- Where each node is connected to multiple other nodes.
- Mesh networks are self-healing when nodes fail.
- Devices roam seamless within the mesh as it reconnects to closest nodes.
- One internet gateway router with many satellite node / access points.
- Nodes communicate to optimise data pathways, for example to alleviate congestion.
- Ad hoc
- Devices in an ad hoc network communicate without a centralised access point.
- Typically temporary. Each node acts as both client and server. No internet access.
- Point to point
- Two directly connected devices.
- ISP backbones are typically point-to-point networks.
- Infrastructure
- Networks that use a router??
- Mesh networks
- Encryption
- Wi-Fi Protected Access 2 (WPA2)
- Uses Advanced Encryption Standard (AES) and a password (pre-shared key (PEK)).
- WPA3
- Uses AES-GCM and SHA-384 encryption standards.
- More resistant to brute force and MITM attacks using Simultaneous Authentication of Equals (SAE).
- Protection against offline dictionary attacks.
- Wi-Fi Protected Access 2 (WPA2)
- Guest Networks
- A method providing a separate, isolated network guests, so that do not have to connect to the main network.
- Typically only provides internet access, and have their own SSID and password.
- Captive Portals
- A special network that requires users to interact with a landing page before access.
- They can be vulnerable to MITM attacks.
- Authentication
- Pre-shared Key (PSK) vs Enterprise
- Pre-shared keys are basically just a password.
- Enterprise authentication often involves things like RADIUS servers, 802.1X authentication, Extensible Authentication Protocol (EAP).
- Pre-shared Key (PSK) vs Enterprise
- Antennas
- Omnidirectional
- Radiates signals in all directions on a horizontal plane.
- Little vertical coverage. Typical in WiFi.
- Directional
- Focuses signals on a specific direction.
- Better for long range.
- Omnidirectional
- Access Points
- Autonomous
- An access point that manages its own configuration, without a central authority.
- Typical in SOHO networks.
- Lightweight
- Access point managed by a controller.
- Relies on a central wireless LAN controller (WLC).
- Autonomous
Physical Installations
- Important Implications
- Locations
- Intermediate Distribution Frame (IDF)
- Equipment used to connect and manage network cabling in a building
- Connects to the MDF.
- Main Distribution Frame (MDF)
- Primary connection point to external links.
- Intermediate Distribution Frame (IDF)
- Rack size
- Based on a standard rack unit (U) of 1.75 inches (44.45mm) of vertical space.
- Most common are:
- 19-inch (482.6mm) width racks of various U height, up 42U (full-size).
- 23-inch racks used in telecoms.
- Port-side exhaust intake
- Refers to the direction that air moves through a device. Cooling systems move air through the system by pulling it in via the intake (usually the front) and pushing it out via the outake (exhaust), at the back.
- Cabling
- Patch panel
- A central point for connecting multiple devices in a structured cabling system. Incoming cables are plugged into the back of the patch panel. Short patch cords can be used at the front of the panel to configure different connections.
- Fibre distribution panel
- A central point for terminating, connecting and routing fibre cables.
- Patch panel
- Lockable
- You can lock it!
- Locations
- Power
- Uninterrupted power supply (UPS)
- Power distribution unit (PDU)
- Power load
- Voltage
- Environmental Factors
- Humidity
- Fire suppression
- Temperature