Networking Protocols
How a packet reaches another machine: IPv4 and IPv6 addressing, BGP and OSPF routing, TCP versus UDP, DNS lookups, and IPSec tunnels. Asked when a design turns into how traffic actually gets there.
on this pageshowhide
explore
- OSI23 questions
- Seven Layers4 questions
- Encapsulation and PDUs5 questions
- OSI vs TCP/IP Mapping4 questions
- Protocol Placement per Layer6 questions
- Network Devices and Layers4 questions
- Ethernet20 questions
- Frames and MAC Addresses5 questions
- MAC Learning and Switching5 questions
- VLANs and Trunking5 questions
- LLDP Neighbor Discovery5 questions
- ARP23 questions
- IP-to-MAC Resolution5 questions
- ARP Cache5 questions
- Gratuitous ARP4 questions
- ARP Spoofing & Poisoning5 questions
- Proxy ARP4 questions
- IP81 questions
- IPv416 questions
- IPv630 questions
- CIDR24 questions
- Hop-by-Hop Forwarding5 questions
- Choosing Between Route Sources6 questions
- ICMP30 questions
- Message Format5 questions
- Echo and Ping4 questions
- Destination Unreachable5 questions
- Time Exceeded and Traceroute5 questions
- ICMPv65 questions
- Security and Filtering6 questions
- NAT31 questions
- SNAT and DNAT5 questions
- PAT and Port Mapping5 questions
- Port Forwarding5 questions
- Hairpinning4 questions
- NAT Traversal6 questions
- Security and Limitations6 questions
- TCP46 questions
- Segment Header and Options5 questions
- Connection Establishment6 questions
- Sequencing and Acknowledgment5 questions
- Flow Control4 questions
- Congestion Control5 questions
- Retransmission and Timeouts5 questions
- Nagle, Delayed ACK & Keepalive5 questions
- Connection Teardown5 questions
- Sockets & Ports6 questions
- UDP14 questions
- Datagram Model6 questions
- Header Structure4 questions
- UDP vs TCP Tradeoffs4 questions
- DNS37 questions
- Record Types6 questions
- Resolution Flow6 questions
- Header, Rcodes and Transport4 questions
- Caching and TTL5 questions
- Zones and Delegation6 questions
- Answer Steering and Failover5 questions
- Resolver Privacy and Attacks5 questions
- DHCP37 questions
- DORA Exchange6 questions
- Leases and Renewal5 questions
- Scopes and Reservations5 questions
- DHCP Options4 questions
- Relay Agents5 questions
- DHCPv66 questions
- Rogue Servers and Snooping6 questions
- NTP30 questions
- Strata and Association Modes4 questions
- Offset and Delay Calculation4 questions
- Source Selection and Polling6 questions
- Clock Drift and Discipline5 questions
- Securing Time Sources6 questions
- SNTP and PTP Alternatives5 questions
- STP30 questions
- Loop Prevention Mechanics4 questions
- Root Bridge Election5 questions
- Port States and Roles5 questions
- BPDUs and Timers6 questions
- RSTP and MSTP5 questions
- Convergence and Port Guards5 questions
- VXLAN31 questions
- Encapsulation Format5 questions
- VTEPs and Tunneling5 questions
- Flood-and-Learn5 questions
- EVPN Control Plane6 questions
- Multitenancy and VNIs5 questions
- MTU and Underlay Design5 questions
- RIP16 questions
- Distance-Vector Mechanics5 questions
- Loop Prevention6 questions
- RIPv1, RIPv2 and RIPng5 questions
- OSPF32 questions
- Link-State Model5 questions
- Areas and LSA Types6 questions
- Adjacency and DR/BDR6 questions
- SPF Computation4 questions
- Metrics and Convergence5 questions
- OSPFv36 questions
- EIGRP30 questions
- Neighbor Discovery and Adjacency5 questions
- DUAL Algorithm6 questions
- Composite Metric and K-Values5 questions
- Topology and Route Tables4 questions
- Partial and Bounded Updates5 questions
- EIGRP vs OSPF5 questions
- BGP38 questions
- Autonomous Systems5 questions
- Peering Session States6 questions
- eBGP and iBGP Sessions6 questions
- Path Attributes4 questions
- Best-Path Selection6 questions
- Route Policy and Filtering6 questions
- Route Leaks and Hijacks5 questions
- Network Design & High Availability49 questions
- Campus and Data Center Topologies6 questions
- First-Hop Redundancy (HSRP/VRRP/GLBP)6 questions
- Link Aggregation and MLAG5 questions
- Bidirectional Forwarding Detection5 questions
- QoS and Traffic Shaping6 questions
- MPLS and L3VPN5 questions
- SD-WAN5 questions
- VRFs and Network Segmentation5 questions
- Capacity Planning and Availability6 questions
- SNMP35 questions
- Manager/Agent Architecture5 questions
- MIBs and OIDs5 questions
- PDU Operations5 questions
- Traps and Informs5 questions
- Protocol Versions5 questions
- SNMPv3 Security Model5 questions
- Interface Counters5 questions
- Network Telemetry23 questions
- Syslog6 questions
- Flow Record Export5 questions
- Port Mirroring and TAPs6 questions
- Model-Driven Streaming6 questions
- YANG31 questions
- Modules and Submodules5 questions
- Schema Node Types6 questions
- Types and Typedefs5 questions
- Constraints and Conditions5 questions
- Augmentation and RPCs5 questions
- Deviations and Conformance5 questions
- NETCONF32 questions
- SSH Transport Layer5 questions
- Datastores5 questions
- RPC Operations6 questions
- Locking and Transactions6 questions
- Model Discovery and Filtering5 questions
- NETCONF vs SNMP5 questions
- RESTCONF28 questions
- YANG Resource Mapping5 questions
- Datastores and Root Resources4 questions
- CRUD Operations and Methods5 questions
- JSON and XML Encoding5 questions
- Query Parameters5 questions
- RESTCONF vs NETCONF4 questions
- VPN31 questions
- Tunneling Models5 questions
- GRE and Multipoint Tunnels5 questions
- WireGuard6 questions
- TLS Control Channel Tunnels5 questions
- Split Tunneling5 questions
- NAT Survival Strategies5 questions
- IPsec32 questions
- AH vs ESP Headers6 questions
- Security Associations5 questions
- Transport vs Tunnel Mode5 questions
- IKE Key Exchange6 questions
- ESP NAT Traversal4 questions
- Policy vs Route-Based VPNs6 questions
- DNSSEC33 questions
- Signature and Key Records6 questions
- Chain of Trust5 questions
- Zone Signing & Key Roles5 questions
- Validation & Resolution5 questions
- Authenticated Denial6 questions
- Key Rollover & Deployment6 questions
- SRTP26 questions
- RTP Baseline and Threats5 questions
- Protection Profiles5 questions
- Keying and Key Derivation6 questions
- Replay and Integrity Protection5 questions
- WebRTC and VoIP Deployment5 questions
questions
869 · 27 sectionsIn OSI terms, what does a hub, a switch and a router each read from incoming traffic, and what does each forward on?
basics
~20 sA hub reads no addresses and repeats bits out of every other port (layer 1). A switch forwards frames on the destination MAC address (layer 2). A router forwards packets on the destination IP address (layer 3).
In the TCP/IP stack, what is encapsulation, and what is the data unit called at the transport, internet and link layers?
basics
~20 sEncapsulation is each layer wrapping what the layer above hands it in its own header (a link layer may add a trailer) on send, and removing it on receive. TCP sends segments, UDP and IP send datagrams, links send frames.
In the OSI reference model, what are the seven layers from L1 to L7, and what is each one responsible for?
basics
~20 sThe OSI model's seven layers, bottom up: Physical (bits on a medium), Data Link (frames between neighbours), Network (addressing and routing across networks), Transport (end-to-end delivery between processes), Session (dialogue control), Presentation (data representation), Application (network services to programs).
In the OSI model, which layer do Ethernet, IP, TCP, UDP and HTTP each belong to, and what reasoning puts each one there?
basics
~20 sEthernet and Wi-Fi sit at layer 2, IP at layer 3, TCP and UDP at layer 4, and HTTP at layer 7. Each sits where its job and address scope sit: one link, across networks, to a process, application meaning.
What are the four layers of the TCP/IP model, and which OSI layers does each one correspond to?
basics
~10 sRFC 1122 names four TCP/IP layers: link (OSI L1-L2, one directly connected network), internet (L3, IP across networks), transport (L4, TCP and UDP between applications) and application (conventionally L5-L7).
What is an Ethernet MAC address, and what do its OUI and the group and local bits of its first octet tell you?
basics
~20 sA MAC address is Ethernet's 48-bit interface identifier. A global one starts with an IEEE-assigned prefix, usually a 24-bit OUI; in the first octet, the lowest bit marks a group address and the next bit a locally administered one.
In a rack cabling audit, how does LLDP tell you which switch and port a server's network interface is plugged into?
basics
~20 sLLDP devices periodically announce their identity and the port each frame left from, to a multicast address standard switches do not forward. A server that hears its switch's frame learns the switch name and port number at the other end of its cable.
How does an Ethernet switch differ from a hub, and what are collision domains and broadcast domains?
basics
~20 sA hub repeats every bit out every port, so its hosts share one collision domain; a switch forwards whole frames by destination MAC, so each port is its own collision domain. Neither splits a VLAN's broadcast domain; a router does.
In Ethernet switching, what is a VLAN, and how does an access port differ from a trunk port?
basics
~20 sA VLAN is a separate broadcast domain carved out of shared switches. An access port belongs to one VLAN and carries untagged frames for an unaware host; a trunk carries many VLANs between switches, marking each frame with an 802.1Q VLAN ID.
What fields make up an Ethernet II frame, and why is an untagged frame between 64 and 1,518 bytes long?
basics
~20 sAn Ethernet II frame is destination MAC (6 bytes), source MAC (6), EtherType (2), payload (46-1,500) and a 4-byte CRC: 64 to 1,518 bytes. The preamble and start delimiter precede it on the wire and are not counted.
In IPv4 over Ethernet, what is the ARP cache, what does each entry hold, and why does a host keep one?
basics
~10 sThe ARP cache is a host's table of IPv4-address-to-MAC-address mappings for neighbours on the same link. Keeping resolved mappings lets the host build Ethernet frames without broadcasting an ARP request before every packet.
In IPv4 ARP, what is a gratuitous ARP, what do its address fields contain, and why would a host send one?
basics
~20 sA gratuitous ARP is an unsolicited, broadcast ARP packet whose sender and target IP fields both hold the sender's own IPv4 address. It tells the link which MAC now owns that address, so peers overwrite stale cache entries.
In IPv4, what is proxy ARP, and how does a router answering ARP for a remote host make that host appear on-link?
basics
~20 sProxy ARP is a router answering an ARP request for a host on another network with its own MAC address. The asker caches that mapping and sends the frames to the router, which routes them onward.
When an IPv4 host sends a packet to an address outside its own subnet, whose MAC address does its ARP request ask for, and why?
basics
~10 sThe default gateway's. The mask marks the destination off-link, so the host ARPs for the gateway's IPv4 address; the frame goes to the gateway's MAC while the IPv4 header still names the remote destination.
In IPv4 over Ethernet, how does ARP find a neighbour's MAC address, and why is the request broadcast but the reply unicast?
basics
~20 sARP broadcasts a request naming the wanted IPv4 address; the owner answers with a unicast reply carrying its MAC, sent to the requester's MAC copied from the request. The requester caches the mapping, then sends the waiting frame.
In IPv4 CIDR notation, what does the number after the slash mean, and how do you convert /20 to a dotted-decimal subnet mask and back?
basics
~20 sThe number after the slash is the prefix length: how many leading bits of the 32-bit IPv4 address are network bits. /20 is twenty ones then twelve zeros, 255.255.240.0; counting the ones in 255.255.240.0 gives 20 back.
An IPv4 host's interface shows 169.254.37.12/16 instead of its usual address; what does that address signal, and how did the host choose it?
basics
~20 sIt is an RFC 3927 IPv4 link-local address: the host obtained no address from DHCP or manual configuration and assigned itself one. It picked a pseudo-random address, confirmed it was free with ARP probes, and can reach only hosts on its own link.
Which IPv4 address blocks does RFC 1918 reserve for private networks, and why are they not routed on the public internet?
basics
~10 sRFC 1918 reserves 10.0.0.0/8, 172.16.0.0/12 (172.16.0.0 to 172.31.255.255) and 192.168.0.0/16. Anyone may reuse them without registration, so they are not unique, and routes and packets for them are kept off inter-network links.
In IPv4, how do you work out the usable host count for a prefix length, and the smallest prefix fitting a host requirement?
basics
~20 sAn IPv4 /n prefix leaves 32 - n host bits: 2^(32 - n) addresses, minus the all-zeros network and all-ones broadcast addresses. To size a subnet, pick the fewest host bits h whose 2^h - 2 covers the hosts needed.
In IPv4 addressing, what is VLSM, and why use it instead of giving every subnet the same mask?
basics
~20 sVLSM (variable-length subnet masking) carves one IPv4 block into subnets with different prefix lengths, each sized to its segment. A single fixed mask must fit the largest segment, which wastes space on small ones and yields too few subnets.
When an IPv4 host answers an ICMP echo request with an echo reply, what does that reply prove, and what does it not prove?
basics
~20 sAn ICMP echo reply proves that something holding the target address has a running IP stack and that small ICMP datagrams can travel both ways right now. It proves nothing about TCP or UDP services, application health, or larger packets.
In IPv4, how is an ICMP message carried, and what do the four parts of its 8-byte header do?
basics
~20 sICMP rides inside an IPv4 datagram with protocol number 1. Its 8-byte header holds an 8-bit type (kind of message), an 8-bit code (specific condition), a 16-bit checksum over the whole ICMP message, and a type-dependent 32-bit word.
Why do firewalls often block ICMP, and what breaks when an IPv4 network drops all of it?
basics
~20 sICMP gets blocked because it has carried floods, Smurf amplification, forged redirects, covert tunnels and network mapping. Dropping all of it breaks path-MTU discovery, traceroute and fast error reporting, so large transfers stall and failed connections hang until timeout.
In IPv4, what does an ICMP Destination Unreachable message tell the sender of a packet, and what does it not prove?
basics
~10 sAn ICMP Destination Unreachable (type 3) says one IPv4 datagram was discarded before delivery and its code gives the reason. It does not prove the destination is down, and receiving none proves nothing either.
When an IPv4 router or host sends an ICMP error, how much of the offending packet does it quote, and why that much?
basics
~20 sAn ICMPv4 error quotes the offending datagram's full IP header plus at least its first 8 payload bytes, enough to reach the TCP or UDP ports. RFC 1812 asks routers to quote as much as fits in 576 bytes.
What is NAT hairpinning, and why does an inside host need it to reach a port-forwarded server by the network's public address?
basics
~20 sHairpinning is a NAT relaying a packet from one inside host back inside to another host that was addressed by its public, translated endpoint. Without it, an inside client that resolves a service name to the public address cannot reach the server.
How does Port Address Translation (NAPT) let many private hosts share one public IPv4 address, and how does a reply reach the right host?
basics
~20 sA NAPT rewrites each outbound packet's private source address and port to the public address plus a port it assigns, records that binding, and uses a reply's destination port to find the binding and restore the private address and port.
On a NAT router, what is port forwarding, and what happens to a packet when a rule maps public port 8443 to 192.168.1.10:443?
basics
~20 sPort forwarding is a static inbound NAT mapping: packets for the router's public address on a chosen port get their destination rewritten to an internal host and port, and the replies get their source rewritten back.
Why did NAT become standard on IPv4 networks, and what does it cost the Internet's end-to-end reachability between hosts?
basics
~20 sIPv4's 32-bit space (about 4.3 billion addresses) ran short, so NAT lets many privately addressed hosts share one public address. The cost: outside hosts cannot start connections to them, the translator holds critical per-flow state, and addresses inside payloads break.
In network address translation, what is the difference between source NAT and destination NAT, and what happens to the reply packets in each case?
basics
~20 sSource NAT rewrites the source address of outbound packets so inside hosts appear as a public address; destination NAT rewrites the destination of inbound packets so a public address reaches an inside server. Replies get the mirror-image rewrite from the stored mapping.
In TCP, what problem does congestion control solve, and why is the receiver's advertised window alone not enough to prevent it?
basics
~20 sTCP congestion control stops senders from overloading the network path between two hosts. The receiver's advertised window only protects the receiver's buffer, so the sender keeps its own congestion window and sends no more than the smaller of the two.
In TCP, what problem does flow control solve, and how is it different from congestion control?
basics
~20 sTCP flow control keeps a fast sender from overrunning the receiver's buffer: the receiver advertises how many more bytes it can accept (rwnd). Congestion control protects the network through the sender's cwnd; the sender obeys the smaller.
In TCP, what does each segment of the three-way handshake (SYN, SYN-ACK, ACK) carry, and why are three segments needed?
basics
~20 sThe SYN carries the client's initial sequence number, the SYN-ACK carries the server's and acknowledges the client's, and the final ACK acknowledges the server's. Three segments let each side confirm the other's starting number and reject stale duplicate SYNs.
How does a TCP sender detect that a segment was lost, and what are the two ways it decides to retransmit it?
basics
~20 sA TCP sender infers loss two ways: its retransmission timer (RTO) expires with data still unacknowledged, or a third duplicate ACK arrives and triggers fast retransmit. Fast retransmit usually fires first; the timer is the slower backstop.
In a TCP header, what do the SYN, ACK, FIN, RST, PSH and URG control flags each signal?
basics
~20 sSYN synchronizes sequence numbers to open a connection, ACK says the acknowledgment field is valid, FIN means the sender has no more data, RST aborts the connection, PSH asks for prompt delivery, and URG marks the urgent pointer as significant.
UDP preserves message boundaries and TCP does not; if a sender makes three 100-byte sends, what does the receiver get with each?
basics
~20 sWith UDP the receiver gets up to three separate 100-byte datagrams, each read returning exactly one, in any order or not at all. With TCP it gets 300 ordered bytes split arbitrarily across reads, so the application must mark message edges itself.
What does UDP leave out that TCP provides, and what does an application actually see when a datagram is lost, duplicated or reordered?
basics
~20 sUDP adds only port multiplexing and a checksum to IP: no delivery guarantee, retransmission, ordering, duplicate suppression, flow control or congestion control. A lost datagram simply never arrives; duplicates and reordered datagrams reach the application as they come.
What four fields make up the UDP header, and why is it only 8 bytes when a TCP header is at least 20?
basics
~20 sA UDP header is four 16-bit fields: source port, destination port, length and checksum, 8 bytes in all. It is that small because UDP adds only port addressing and an integrity check; it carries no sequence numbers, acknowledgements, window or control flags.
What are the core differences between TCP and UDP, and which kinds of workload call for each one?
basics
~20 sTCP is a connection-oriented, reliable, ordered byte stream with flow and congestion control; UDP sends independent datagrams with no handshake, retransmission or ordering. Choose TCP when every byte must arrive in order, UDP when latency or statelessness matters more.
Why is the UDP checksum optional over IPv4 but mandatory over IPv6, and what does its pseudo-header protect against?
basics
~20 sOver IPv4, RFC 768 lets a sender put zero for no checksum, and the IPv4 header checksum still guards the addresses. IPv6 has no header checksum, so UDP's checksum over a pseudo-header of the addresses is mandatory to catch corrupted or misdelivered packets.
In DNS, what does a record's TTL control, and why can clients keep getting the old address after you change the record?
basics
~20 sA DNS TTL is the number of seconds a cache may keep a record before consulting the authoritative source again. Resolvers that cached the old record can keep serving it until their copy's remaining TTL runs out.
Does DNS use UDP or TCP, and when does a DNS query move from UDP port 53 to TCP?
basics
~20 sDNS uses both. Queries normally travel over UDP port 53; a response too large for UDP (512 bytes without EDNS0) comes back with the TC bit set, and the client repeats the query over TCP port 53, which RFC 7766 makes mandatory.
Which DNS record types does example.com need to serve a web app and receive email, and what does each one answer?
basics
~20 sA and AAAA map a name to IPv4 and IPv6 addresses, CNAME makes one name an alias of another, MX names the mail servers with a preference (lower first), and TXT carries free-form strings such as verification tokens.
With every DNS cache empty, which servers take part in resolving www.example.com, and in what order is each one asked?
basics
~20 sThe stub resolver asks a recursive resolver; that resolver asks a root server, then a com server, then example.com's authoritative server. The first two refer it onward, the last answers, and the recursive resolver returns the address to the stub.
What is DNS cache poisoning, and why does one forged answer accepted by a recursive resolver affect many users?
basics
~20 sDNS cache poisoning is getting a recursive resolver to accept and store a forged answer. Because the resolver serves its cache to every client, one accepted forgery misdirects all of them until the record's TTL runs out.
In DHCPv4, what are the four messages of the DORA exchange, and who sends each one to which address?
basics
~20 sDORA is Discover, Offer, Request, Acknowledge. The client broadcasts a DHCPDISCOVER, each willing server answers with a DHCPOFFER, the client broadcasts a DHCPREQUEST naming the server it chose, and that server commits the lease and sends a DHCPACK.
A laptop's DHCPv4 offer carries options 1, 3, 6, 15 and 51; what does each give it, and what breaks without 3 or 6?
basics
~20 sA DHCPv4 reply carries the address in yiaddr; option 1 is the subnet mask, 3 the routers, 6 the DNS servers, 15 the domain name, 51 the lease in seconds. Without 3 the host stays on its subnet; without 6 names fail.
Why can a DHCPv4 client not reach a server on another subnet by itself, and what does a relay agent do about it?
basics
~20 sA DHCPv4 client with no address broadcasts to 255.255.255.255, which routers must not forward. A relay agent on the subnet's gateway catches that broadcast, writes its own interface address into giaddr and unicasts the message to the configured DHCP server.
In DHCPv4, how does a printer reservation differ from a static address set on the printer, and which should be the source of truth?
basics
~20 sA reservation keeps the printer on DHCP: the server always gives its identifier the same address, with current options. A static address lives only on the printer, invisible to the server, so it must stay out of the pool.
When a test DHCPv4 server is plugged into a production access switch, what do clients on that VLAN get, and why is it possible?
basics
~20 sClients that accept the test server's offer take its address, default router and DNS servers, and keep renewing with it. DHCPv4 allows this because RFC 2131 gives a client no way to authenticate a server.
In plain NTP, why can an on-path attacker who shifts a client's clock make expired certificates and replayed tokens valid again?
basics
~20 sCertificate lifetimes, time-based one-time codes and replay windows all compare against the local clock. Plain NTP replies are unauthenticated UDP, so an attacker on the path can rewrite them and move the clock back until expired credentials pass again.
Why does a computer clock left without NTP drift, and how far does a 50 PPM oscillator error move it in a day?
basics
~20 sA clock counts oscillator ticks, and no oscillator runs at exactly its nominal frequency, so the error accumulates. 50 PPM is 50 microseconds per second: 50 x 10^-6 x 86,400 s is about 4.3 seconds a day.
What does an NTP server's stratum number tell you, and why is a lower stratum not the same as better time?
basics
~20 sStratum counts how many NTP hops a server sits from a reference clock: 1 is a primary server, 2-15 are secondary servers, 16 means unsynchronized. It measures distance in the tree, not the size of the clock's error.
In Network Time Security, how does NTS-KE give a client its keys and cookies, and why can the NTP server keep no per-client state?
basics
~20 sNTS-KE runs TLS 1.3 on TCP 4460, exports two AEAD keys and hands the client cookies: those keys sealed under a server secret. Each NTP request carries one cookie, so the server recovers the keys from it and stores no per-client state.
An NTP client records T1 = 1000, T2 = 1045, T3 = 1050 and T4 = 1055 ms; what are the delay and offset?
basics
~10 sDelay is (T4-T1)-(T3-T2) = 55 - 5 = 50 ms. Offset is ((T2-T1)+(T3-T4))/2 = (45 - 5)/2 = +20 ms: the server is 20 ms ahead, assuming each leg took 25 ms.
Why do switched Ethernet networks need spanning tree, and why is a Layer 2 loop more destructive than a Layer 3 routing loop?
basics
~20 sEthernet frames carry no TTL or hop count, so a broadcast that enters a loop of switches circulates indefinitely and keeps reaching every host. Spanning tree blocks redundant ports so one active path remains, and reopens one if that path fails.
In spanning tree, which switch becomes the root bridge, and why does an untuned network often end up with an old switch as root?
basics
~20 sThe switch with the lowest bridge ID becomes root. The bridge ID is a priority followed by a MAC address, and every switch ships with the same default priority, so the lowest MAC decides, which is frequently an older device.
What does Rapid Spanning Tree Protocol (RSTP, IEEE 802.1w) change compared with classic 802.1D spanning tree?
basics
~20 sRSTP keeps 802.1D's root election and path costs but adds alternate and backup port roles, merges disabled, blocking and listening into one discarding state, and moves ports to forwarding by an explicit neighbour handshake instead of waiting out timers.
In 802.1D spanning tree, what do the Hello, Max Age and Forward Delay timers control, and whose values do bridges actually use?
basics
~20 sHello Time (IEEE default 2 s) paces the root's Configuration BPDUs, Max Age (20 s) is how long stored BPDU information lives, and Forward Delay (15 s) is each listening and learning period. Every bridge uses the root's values, carried in its BPDUs.
Under 802.1D spanning tree, why does a direct uplink failure take about 30 seconds to recover while an indirect failure takes about 50?
basics
~20 sA direct failure shows up at once as link loss, leaving only listening and learning: about 30 s at IEEE defaults. An indirect failure is learned through BPDUs, so stored information must first reach Max Age (20 s): about 50 s.
Why does VXLAN identify segments with a 24-bit VNI rather than VLAN IDs, and how many segments does that allow?
basics
~20 sVXLAN carries a 24-bit VXLAN Network Identifier in its own header, giving 2^24 = 16,777,216 segment IDs against 4,094 usable 12-bit VLAN IDs, so a shared data centre can give every tenant many isolated layer 2 segments.
What is a VXLAN Tunnel Endpoint (VTEP), and what does it do to an Ethernet frame entering and leaving the tunnel?
basics
~20 sA VTEP originates and terminates VXLAN tunnels: it wraps a host's Ethernet frame in a VXLAN header carrying the segment's VNI, plus UDP and an outer IP header addressed VTEP to VTEP, and the far VTEP strips them and delivers the original frame.
How many bytes does VXLAN encapsulation add to an Ethernet frame over IPv4, and how does that change with IPv6 or an outer 802.1Q tag?
basics
~20 sOver IPv4, VXLAN adds 50 bytes: outer Ethernet 14, outer IPv4 20, UDP 8 and the VXLAN header 8. An outer 802.1Q tag makes it 54; an outer IPv6 header, 40 bytes, makes it 70, or 74 tagged.
Why do VXLAN fabrics adopt BGP EVPN as a control plane, and what does it advertise that flood-and-learn must discover by flooding?
basics
~20 sBGP EVPN lets each VTEP announce the MAC and IP addresses it learned locally as BGP routes, so remote VTEPs know where hosts live before traffic flows, instead of learning them by flooding unknown and ARP traffic across the fabric.
In a VXLAN segment using data-plane learning, what does each VTEP learn as two hosts complete their first ARP exchange?
basics
~20 sHost A's ARP broadcast is flooded to every VTEP in the VNI, so each learns A's MAC behind A's VTEP. B's unicast reply goes to A's VTEP alone, which learns B's MAC behind B's VTEP; afterwards both directions are known unicast.
How does a RIP router choose its route to a network, and how does the hop count change as a route travels one router further?
basics
~20 sA RIP router adds the cost of the network an update arrived on, normally 1, to each metric a neighbour advertises and keeps the lowest result, with that neighbour as next hop; metric 16 means unreachable.
When a RIP neighbour dies silently, when do its routes leave service and the table under RFC 2453, and how does the 180/180/240 set differ?
basics
~20 sUnder RFC 2453 a RIP route expires 180 seconds after its last refresh, is advertised at metric 16 while a 120-second garbage-collection timer runs, then is deleted: 300 seconds in all. The invalid/holddown/flush set of 180/180/240 is an implementation's.
In RIP, what is count-to-infinity, and how does it unfold when a router's connected network fails while a neighbour still advertises it?
basics
~20 sCount-to-infinity is RIP's slow failure mode: after a network vanishes, routers keep re-learning it from each other's stale advertisements, raising the metric one hop per exchange until it reaches 16, RIP's infinity, and the route is finally declared unreachable.
In RIP, how does simple split horizon differ from split horizon with poisoned reverse, and why is poisoned reverse considered safer?
basics
~20 sSimple split horizon leaves a route out of updates sent where it was learned; poisoned reverse sends it there with metric 16. That explicit 16 breaks a two-router loop at once rather than after a timeout, but enlarges updates.
What does a RIPv2 route entry carry that a RIPv1 entry does not, and why did the missing subnet mask make RIPv1 classful?
basics
~20 sRIPv1 route entries carry no subnet mask, so a receiver infers each mask from its own interface or the address class, which makes RIPv1 classful. RIPv2 reuses unused fields for a subnet mask, a route tag and a next hop.
In OSPF, why is a large network split into areas, and what job do backbone area 0, ABRs and ASBRs each do?
basics
~20 sOSPF areas bound LSA flooding and SPF runs, so a change in one area does not ripple through every router. Area 0 is the hub every area attaches to; ABRs join areas to it, and ASBRs inject routes learned outside OSPF.
In OSPF, what does a router's SPF calculation take as input, and what does it produce?
basics
~20 sAn OSPF router runs Dijkstra's shortest-path-first algorithm over its area's link-state database with itself as the root. The result is a shortest-path tree giving the lowest total cost and next hops to every destination, which becomes its routing table.
How does OSPF elect a Designated Router and Backup Designated Router on a LAN, and why doesn't a higher-priority newcomer take over?
basics
~20 sOn broadcast and NBMA networks, OSPF elects a BDR, then a DR, from routers in 2-Way or above: highest Router Priority wins, highest Router ID breaks ties, priority 0 never qualifies. A better newcomer never preempts a working DR.
In OSPF, which states does a neighbour pass through from the first Hello to Full, and what happens in each?
basics
~20 sAn OSPF neighbour goes Down, Init (its Hello heard), 2-Way (each sees itself in the other's Hello), ExStart (master and slave chosen), Exchange (database summaries traded), Loading (missing LSAs requested) and Full (databases synchronised). NBMA adds Attempt.
What does an EIGRP router's composite metric measure along a path by default, and which carried values does it leave out?
basics
~20 sBy default the EIGRP composite metric adds two terms: the inverse of the slowest link's bandwidth on the path and the sum of the outgoing interfaces' delays. Load, reliability, MTU and hop count travel with the route but are not weighed.
In EIGRP, what makes routing updates partial and bounded, and how does that differ from RIP's periodic full-table updates?
basics
~20 sEIGRP sends an UPDATE only when a route is added or its metric changes, carries only those prefixes, and the change stops spreading where no router's best path changes; RIP resends its whole table every 30 seconds.
How do you compute an EIGRP path's classic composite metric by hand, and why can a longer path beat a shorter one?
basics
~20 sWith default K-values, the EIGRP classic metric is 256 × (10^7 / slowest bandwidth in kb/s + summed delay in tens of microseconds). Only the slowest link sets the bandwidth term, so a longer path with a faster bottleneck can win.
In EIGRP, what is the feasibility condition, and how does it decide which neighbours become feasible successors for a prefix?
basics
~20 sA neighbour meets EIGRP's feasibility condition when its reported distance to a prefix is strictly below this router's feasible distance, its best distance since the route last went passive; that neighbour is a feasible successor, a guaranteed loop-free backup.
Two EIGRP routers on the same link can ping each other but never become neighbours; what do you check, and why?
basics
~20 sFirst check that hellos cross the link: EIGRP enabled, IP protocol 88 and 224.0.0.10 not filtered. Then the three things RFC 7868 makes neighbours agree on: the AS number, the K-values and authentication. Hello and hold timers need not match.
In BGP, what is an autonomous system, and what does its AS number do in the routes BGP exchanges?
basics
~20 sAn autonomous system is a network, or group of IP prefixes, run under one clearly defined routing policy. Its AS number identifies it to BGP peers and is prepended to AS_PATH, which BGP uses to compare paths and reject loops.
How does a BGP speaker use the AS_PATH attribute to keep routes from looping between autonomous systems?
basics
~20 sEach AS adds its own number to AS_PATH when advertising a route to an external peer. A BGP speaker that finds its own AS number in a received AS_PATH treats the route as a loop and does not use it.
Why does BGP run its sessions over TCP port 179, and what are the four message types a BGP-4 session exchanges?
basics
~20 sBGP runs over TCP port 179 so TCP supplies retransmission, ordering and sequencing for it. A BGP-4 session uses four messages: OPEN starts it, UPDATE advertises and withdraws routes, NOTIFICATION reports an error and closes it, KEEPALIVE shows the peer is alive.
In BGP, what distinguishes an eBGP session from an iBGP session, and how does each one treat the routes it passes on?
basics
~20 seBGP joins speakers in different autonomous systems, iBGP speakers in the same one. eBGP prepends the sender's AS number and normally rewrites NEXT_HOP; iBGP changes neither and, outside route reflection, does not relay one iBGP peer's routes to another.
What makes a BGP autonomous system stub, multihomed or transit, and when does an enterprise need an AS number of its own?
basics
~20 sA stub AS has one neighbouring AS; a multihomed AS has several but, as an enterprise, carries only its own traffic; a transit AS carries traffic between other ASes. An enterprise mainly needs its own ASN to multihome.
What is Bidirectional Forwarding Detection (BFD), and why do routers run it beside BGP or OSPF instead of relying on their own keepalives?
basics
~20 sBFD (RFC 5880) is a lightweight hello protocol that only checks, in milliseconds, whether the forwarding path to a neighbour works; it carries no routes and tells clients such as BGP, OSPF or a static route to react.
In network design, what does an availability of 99.99% mean in downtime per year, and how is availability derived from MTBF and MTTR?
basics
~20 sAvailability is the fraction of time a system is in service: MTBF / (MTBF + MTTR). At 99.99% the allowed downtime is 0.01% of a year, about 52.6 minutes; 99.9% allows about 8.76 hours and 99.999% about 5.26 minutes.
How does a first-hop redundancy protocol such as VRRP keep a LAN's static default gateway working when one router fails?
basics
~20 sRouters share one virtual gateway IP and one virtual MAC; an election makes one Active, which answers ARP and forwards. If its advertisements stop, a Backup claims the same addresses, so hosts keep their configured gateway unchanged.
What is Ethernet link aggregation, and what does bundling four 10G links into one logical port give that four separate links do not?
basics
~20 sLink aggregation joins parallel Ethernet links into one logical link: spanning tree and routing see one port, every member forwards, and a failed member only costs capacity. Four 10G links give 40G in total, yet each flow rides one member.
In SD-WAN, what is the difference between the overlay and the underlay, and why does that split let a branch use almost any transport?
basics
~20 sThe underlay is the rented transports, such as MPLS, broadband or LTE, that only carry packets between edge addresses; the overlay is the encrypted tunnels, routes and policy built over them, so sites see one private network whatever the transport.
In SNMP, what do the manager and the agent each do, and which UDP ports carry requests and notifications?
basics
~20 sAn SNMP manager sends requests to agents and receives their notifications; the agent on each managed device answers from its managed objects and sends notifications on events. Requests go to the agent on UDP 161, notifications to the manager on UDP 162.
In SNMP, what is an object identifier, and how does the numeric OID 1.3.6.1.2.1.1.3.0 map to a named MIB object?
basics
~10 sAn OID is a path of numbered arcs through a global registration tree. 1.3.6.1.2.1.1.3.0 reads iso.org.dod.internet.mgmt.mib-2.system.sysUpTime plus .0, the single instance of that scalar; a MIB module supplies the name, type and meaning.
What do the SNMP GetRequest, GetNextRequest, GetBulkRequest and SetRequest PDUs each ask an agent to do, and what comes back?
basics
~20 sGetRequest reads exactly the named instances; GetNextRequest returns each name's successor in OID order; GetBulkRequest returns many successors at once; SetRequest writes values all or nothing. Each is answered by a Response-PDU with the same request-id, an error-status and an error-index.
Why are SNMPv1 and SNMPv2c community strings considered insecure, and what does SNMPv3 put in their place?
basics
~20 sAn SNMPv1 or SNMPv2c community string is a shared password sent unencrypted in every message, so one captured packet lets anyone reuse it, and nothing protects integrity or freshness. SNMPv3 replaces it with per-user authentication, optional encryption and view-based access control.
How do you compute a link's utilisation from SNMP IF-MIB octet counters polled twice, and which speed object do you divide by?
basics
~10 sDifference two readings of ifHCInOctets (or ifHCOutOctets), multiply by 8, divide by the seconds between the polls, then divide by the interface speed, ifHighSpeed x 1,000,000 bit/s. Each direction is computed separately.
In NetFlow and IPFIX flow export, what is a flow key, and how does an exporter turn packets into flow records?
basics
~20 sA flow key is the set of fields, classically the five-tuple, that packets must share to count as one flow. The exporter keeps a cache entry per key, adds each matching packet to it, and exports it as a record on expiry.
Why does streaming telemetry from network devices beat five-minute SNMP polling when you monitor 2,000 routers and switches?
basics
~20 sSNMP polling makes a manager ask every device for every value each cycle, so data arrives late, averaged and lost under stress. Streaming telemetry subscribes once; each device then pushes YANG-modelled values on a timer or on change.
What are syslog's eight severity levels, and what does a filter for 'Warning and more urgent' actually select?
basics
~10 sSyslog severities run from 0 Emergency to 7 Debug, and a lower number means a more urgent message. 'Warning and more urgent' therefore selects 0 to 4: Emergency, Alert, Critical, Error and Warning.
How do a NetFlow or IPFIX exporter's active and inactive timeouts decide when flow records are sent, and what do they do to per-minute graphs?
basics
~20 sThe inactive timeout expires a flow that has gone quiet; the active timeout exports a long-lived flow in slices. Collectors see traffic only when records arrive, so a long active timeout piles a long transfer into one graph spike.
How does a network TAP differ from a SPAN port as a packet source, and what happens to the monitored link when each loses power?
basics
~20 sA SPAN port is switch configuration copying frames best effort; a TAP sits in the cable and copies the signal. A passive optical TAP needs no power, so a power cut is harmless; an active copper TAP typically drops the link briefly.
In a YANG module, what do the namespace and prefix statements each do, and which one identifies the module's data on the wire?
basics
~20 sA YANG namespace is a globally unique URI that qualifies the module's definitions and never changes; the prefix is a short local handle an importer may rename. Encoded data uses the namespace in XML and the module name in JSON, never the prefix.
In YANG, what is the difference between a container, a list, a leaf and a leaf-list when modelling a router's interfaces?
basics
~20 sA YANG leaf holds one typed value and a leaf-list a set of values of one type; a container groups child nodes and occurs at most once under its parent, while a list holds many entries, each identified by its key leafs.
In YANG, how does a vendor module use augment to add a QoS leaf to the standard ietf-interfaces list without editing that module?
basics
~10 sThe vendor module imports ietf-interfaces and declares augment "/if:interfaces/if:interface" with the new leaf inside. The leaf appears in every interface entry but belongs to the vendor module's namespace, so the standard module stays untouched.
In YANG, how does a must statement differ from a when statement, and what happens to the data when each evaluates to false?
basics
~20 sA false YANG must is a validation error: the edit is refused with the must's error-message and error-app-tag. A false when means its node does not apply: writes to it fail, and an existing instance is silently deleted.
In YANG, how do feature and if-feature make part of a module optional, and what happens when a client configures an unsupported part?
basics
~20 sA feature statement names an optional capability and if-feature ties schema nodes to it. Where a server does not support the feature those nodes are absent from its schema, and a NETCONF server must reject data for them with unknown-element.
In NETCONF, what do the running, candidate and startup configuration datastores each hold, and which one must every device have?
basics
~20 sRunning holds the configuration in use now and is the only datastore every NETCONF device has. Candidate is an optional full working copy you edit and then commit; startup is an optional copy loaded at boot.
How does a NETCONF client open a session over SSH, and why does NETCONF run as an SSH subsystem rather than through a shell?
basics
~20 sA NETCONF client connects to TCP port 830, authenticates over SSH, opens an SSH session channel and requests the subsystem named "netconf". The subsystem hands the channel straight to the NETCONF server, so no shell prompt or login banner corrupts the XML stream.
Why is SNMP mostly used to monitor network devices, while NETCONF is the protocol usually chosen to configure them?
basics
~20 sSNMP was designed for cheap polling of counters and status, and standard MIB modules rarely expose writable configuration; NETCONF was designed for configuration, with full-configuration retrieval, staged and validated edits, an all-or-nothing commit and a YANG schema.
In NETCONF, how does the candidate workflow of edit, <validate>, then <commit> or <discard-changes> change the running datastore?
basics
~10 sEdits to the candidate change nothing on the device. <validate> checks the candidate, <commit> sets running to the candidate's entire contents, and <discard-changes> throws the edits away by resetting the candidate to running.
In NETCONF, what does a <lock> on a configuration datastore prevent, how long does it last, and what does a competing session get back?
basics
~20 sA NETCONF <lock> gives one session exclusive write access to a whole datastore until it unlocks or its session ends; other sessions, SNMP and CLI cannot change it, and a competing <lock> fails with lock-denied naming the holder's session-id.
On a RESTCONF server, what does each HTTP method — GET, POST, PUT, PATCH and DELETE — do to YANG-modelled configuration data?
basics
~20 sRESTCONF (RFC 8040) maps HTTP methods onto YANG data: GET reads a subtree, POST creates a child or invokes an operation, PUT creates or replaces the target, plain PATCH merges into it, and DELETE removes an existing node.
In RESTCONF, what does each child of the API root resource — data, operations and yang-library-version — give a client?
basics
~20 sUnder the RESTCONF API root, data is the one combined datastore of configuration and state that clients read and edit, operations lists and invokes the server's YANG RPCs, and yang-library-version gives the ietf-yang-library revision the server implements.
How does RESTCONF differ from NETCONF in transport, message encoding and the way a client converses with a device?
basics
~20 sRESTCONF carries YANG-modelled data over HTTPS as XML or JSON, one self-contained HTTP request per operation. NETCONF sends XML RPCs over a long-lived SSH or TLS session, which can hold locks and stage edits before committing them.
In RESTCONF, how do YANG containers, lists and leaves become the URI path of a data resource under {+restconf}/data?
basics
~20 sEvery data node from the top of the YANG tree down to the target becomes one path segment under {+restconf}/data: containers and leaves by name, list entries as name=key, and the top-level node prefixed with its module name.
Why does a RESTCONF server reject a JSON body whose member names are unqualified, and where does RFC 7951 require module prefixes?
basics
~20 sRFC 7951 requires every top-level JSON member to be named module:node, and a child to be qualified again only when its module differs from its parent's, as with augmented nodes; without those names the server cannot map the body to its schema.
In a remote-access VPN, what is the difference between a full tunnel and a split tunnel, and what does each cost?
basics
~20 sA full tunnel sends all the client's traffic through the VPN gateway; a split tunnel sends only corporate destinations there and lets the rest go direct. Split saves gateway capacity and latency; full keeps central visibility and control.
What is the difference between a site-to-site VPN and a remote-access VPN, and who terminates each tunnel?
basics
~20 sA site-to-site VPN joins two networks through gateways, so hosts need no VPN software; a remote-access VPN joins one device, running a client, to a gateway that authenticates the user and assigns an inner address.
In WireGuard, what identifies a peer, and why do two WireGuard peers never negotiate a cipher suite?
basics
~20 sA WireGuard peer is identified only by its static Curve25519 public key, exchanged out of band. The cryptography is fixed by the protocol (Curve25519, ChaCha20-Poly1305, BLAKE2s), so there is nothing to negotiate and nothing to downgrade.
Why do two branch routers pair GRE with IPsec to run OSPF over the internet, instead of using a policy-based IPsec tunnel alone?
basics
~20 sGRE gives the routers a point-to-point link that carries OSPF's multicast hellos and any routed subnet; IPsec encrypts and authenticates that single GRE flow. Policy-based IPsec alone matches unicast subnet pairs and gives OSPF no interface to run on.
How do IPsec, WireGuard and TLS-based VPNs each get through a NAT, and which of them still connects when a hotel network blocks UDP?
basics
~20 sTunnels answer a NAT three ways: ride UDP (IPsec wraps ESP in UDP 4500; WireGuard is UDP already), send keepalives so the mapping stays, or hide inside TCP or TLS on 443. Only the TCP rung survives dropped UDP.
In IPsec, what does the Authentication Header (AH) protect, what does ESP protect, and why is ESP the one deployed?
basics
~20 sAH (IP protocol 51) authenticates the payload plus the IP header fields that do not change in transit, and encrypts nothing. ESP (protocol 50) encrypts and normally authenticates its own contents, not the outer header, and meets almost every need.
In IPsec, what job does IKE do before any protected packet flows, and how did IKEv1's two phases divide that job?
basics
~20 sIKE authenticates the peers, negotiates algorithms and derives keys for ESP or AH. IKEv1 split this into Phase 1 (Main or Aggressive Mode, building a protected IKE SA) and Phase 2 (Quick Mode, negotiating IPsec SAs under it); RFC 9395 deprecates IKEv1.
In IPsec, what is the difference between transport mode and tunnel mode, and where does the ESP header sit in each?
basics
~20 sIPsec transport mode keeps the original IP header and inserts ESP between it and the payload, protecting only that payload; tunnel mode puts the whole original packet, header included, behind ESP and a new outer IP header.
Why does plain IPsec ESP often fail through a home router's port-translating NAT, and what does NAT traversal change on the wire?
basics
~20 sESP is IP protocol 50 with no port numbers, so a port-translating NAT cannot tell which inside host an inbound packet is for. NAT traversal puts a UDP header on port 4500 in front of ESP, giving the NAT ports to map.
In IPsec, what is a Security Association, and why does protecting two-way traffic between two gateways take a pair of them?
basics
~20 sAn IPsec Security Association is one-way state: the keys, algorithms, counters and selectors protecting traffic in a single direction with AH or ESP. Two-way traffic therefore needs two SAs, one per direction, each with its own SPI.
What does a DNSSEC RRSIG record returned alongside an answer prove about that answer, and what does it leave unprotected?
basics
~20 sA DNSSEC RRSIG proves one RRset was signed with the private key behind a zone's DNSKEY and is unchanged, within its inception-to-expiration window. It adds no secrecy, no freshness inside that window and no DoS protection.
When a DNSSEC-validating resolver cannot verify an answer's signatures, what does the client receive, and why does it look like an outage?
basics
~20 sThe client gets SERVFAIL (RCODE 2) and no records: the resolver withholds bogus data rather than pass on a possible forgery. SERVFAIL also reports unreachable or broken servers, so to users the domain simply seems down.
How does a DNSSEC-validating resolver build a chain of trust from the root trust anchor down to the A record of www.example.com?
basics
~20 sFrom the root anchor down, at every zone cut the parent's signed DS must match a digest of a child DNSKEY, and that key must sign the child's DNSKEY RRset. A key of the last zone then verifies the RRSIG over the A record.
In a DNSSEC-signed zone, how does an NSEC record prove that a queried name or record type does not exist?
basics
~20 sAn NSEC record names the next existing name in canonical order and lists the types at its owner. A signed NSEC spanning the queried name proves the name absent; one at that name, lacking the type, proves no data.
Why does DNSSEC's NSEC record let anyone list every name in a signed zone, and what does NSEC3 change about it?
basics
~20 sEach NSEC names the next existing name, so following the chain from the apex lists the whole zone. NSEC3 hashes owner names with SHA-1, so the chain shows hashes, not names, though guessable names still fall to offline dictionary attacks.
In SRTP, why does encrypting the RTP payload not stop an attacker from replaying recorded video packets or flipping bits in them?
basics
~20 sEncryption hides content but never fails: flipped bits in SRTP counter-mode ciphertext decrypt to the same flipped plaintext bits, and a recorded packet decrypts fine when re-sent. SRTP adds an authentication tag and a replay list to catch both.
Why is a SIP call's media sent as plain RTP over UDP unsafe on a shared office LAN, and what does SRTP add?
basics
~20 sPlain RTP carries no encryption, integrity check or replay protection: anyone seeing the packets can decode the audio, and anyone reaching the port can inject or replay media. SRTP adds payload encryption, whole-packet authentication and replay protection.
In SRTP's default protection profile, AES_CM_128_HMAC_SHA1_80, what does each part of the name select, and why is there a 112-bit salt?
basics
~20 sAES_CM_128_HMAC_SHA1_80 is AES counter mode under a 128-bit master key for confidentiality, plus HMAC-SHA1 truncated to an 80-bit tag for integrity. The 112-bit salt, beside a 16-bit block counter, fills each counter block and blunts precomputation.
Why is keying SRTP with SDES a=crypto lines considered unsafe, and how does DTLS-SRTP avoid the same weakness?
basics
~20 sSDES puts each sender's SRTP master key in the SDP, so every proxy, log or trace that reads the signalling can decrypt the media. DTLS-SRTP derives keys in a handshake on the media path; signalling carries only a certificate fingerprint.
How does an SRTP receiver's sliding replay window decide whether an arriving packet's 48-bit index is accepted or discarded?
basics
~20 sAn SRTP receiver accepts an index ahead of its highest authenticated index, or inside the window and unseen; it discards one already marked or too far behind. The window, at least 64 packets, is marked only after the tag verifies.