skip to content

Networking Protocols

How a packet reaches another machine: IPv4 and IPv6 addressing, BGP and OSPF routing, TCP versus UDP, DNS lookups, and IPSec tunnels. Asked when a design turns into how traffic actually gets there.

on this pageshow

explore

questions

869 · 27 sections

In OSI terms, what does a hub, a switch and a router each read from incoming traffic, and what does each forward on?

level: juniorimportance: must knowfreq 78%
basics
~20 s

A hub reads no addresses and repeats bits out of every other port (layer 1). A switch forwards frames on the destination MAC address (layer 2). A router forwards packets on the destination IP address (layer 3).

open as a page

In the TCP/IP stack, what is encapsulation, and what is the data unit called at the transport, internet and link layers?

level: juniorimportance: must knowfreq 68%
basics
~20 s

Encapsulation is each layer wrapping what the layer above hands it in its own header (a link layer may add a trailer) on send, and removing it on receive. TCP sends segments, UDP and IP send datagrams, links send frames.

open as a page

In the OSI reference model, what are the seven layers from L1 to L7, and what is each one responsible for?

level: juniorimportance: must knowfreq 82%
basics
~20 s

The OSI model's seven layers, bottom up: Physical (bits on a medium), Data Link (frames between neighbours), Network (addressing and routing across networks), Transport (end-to-end delivery between processes), Session (dialogue control), Presentation (data representation), Application (network services to programs).

open as a page

In the OSI model, which layer do Ethernet, IP, TCP, UDP and HTTP each belong to, and what reasoning puts each one there?

level: juniorimportance: must knowfreq 72%
basics
~20 s

Ethernet and Wi-Fi sit at layer 2, IP at layer 3, TCP and UDP at layer 4, and HTTP at layer 7. Each sits where its job and address scope sit: one link, across networks, to a process, application meaning.

open as a page

What are the four layers of the TCP/IP model, and which OSI layers does each one correspond to?

level: juniorimportance: must knowfreq 72%
basics
~10 s

RFC 1122 names four TCP/IP layers: link (OSI L1-L2, one directly connected network), internet (L3, IP across networks), transport (L4, TCP and UDP between applications) and application (conventionally L5-L7).

open as a page

What is an Ethernet MAC address, and what do its OUI and the group and local bits of its first octet tell you?

level: juniorimportance: must knowfreq 60%
basics
~20 s

A MAC address is Ethernet's 48-bit interface identifier. A global one starts with an IEEE-assigned prefix, usually a 24-bit OUI; in the first octet, the lowest bit marks a group address and the next bit a locally administered one.

open as a page

In a rack cabling audit, how does LLDP tell you which switch and port a server's network interface is plugged into?

level: juniorimportance: must knowfreq 32%
basics
~20 s

LLDP devices periodically announce their identity and the port each frame left from, to a multicast address standard switches do not forward. A server that hears its switch's frame learns the switch name and port number at the other end of its cable.

open as a page

How does an Ethernet switch differ from a hub, and what are collision domains and broadcast domains?

level: juniorimportance: must knowfreq 68%
basics
~20 s

A hub repeats every bit out every port, so its hosts share one collision domain; a switch forwards whole frames by destination MAC, so each port is its own collision domain. Neither splits a VLAN's broadcast domain; a router does.

open as a page

In Ethernet switching, what is a VLAN, and how does an access port differ from a trunk port?

level: juniorimportance: must knowfreq 68%
basics
~20 s

A VLAN is a separate broadcast domain carved out of shared switches. An access port belongs to one VLAN and carries untagged frames for an unaware host; a trunk carries many VLANs between switches, marking each frame with an 802.1Q VLAN ID.

open as a page

What fields make up an Ethernet II frame, and why is an untagged frame between 64 and 1,518 bytes long?

level: middleimportance: must knowfreq 46%
basics
~20 s

An Ethernet II frame is destination MAC (6 bytes), source MAC (6), EtherType (2), payload (46-1,500) and a 4-byte CRC: 64 to 1,518 bytes. The preamble and start delimiter precede it on the wire and are not counted.

open as a page

In IPv4 over Ethernet, what is the ARP cache, what does each entry hold, and why does a host keep one?

level: juniorimportance: must knowfreq 55%
basics
~10 s

The ARP cache is a host's table of IPv4-address-to-MAC-address mappings for neighbours on the same link. Keeping resolved mappings lets the host build Ethernet frames without broadcasting an ARP request before every packet.

open as a page

In IPv4 ARP, what is a gratuitous ARP, what do its address fields contain, and why would a host send one?

level: juniorimportance: must knowfreq 38%
basics
~20 s

A gratuitous ARP is an unsolicited, broadcast ARP packet whose sender and target IP fields both hold the sender's own IPv4 address. It tells the link which MAC now owns that address, so peers overwrite stale cache entries.

open as a page

In IPv4, what is proxy ARP, and how does a router answering ARP for a remote host make that host appear on-link?

level: juniorimportance: must knowfreq 30%
basics
~20 s

Proxy ARP is a router answering an ARP request for a host on another network with its own MAC address. The asker caches that mapping and sends the frames to the router, which routes them onward.

open as a page

When an IPv4 host sends a packet to an address outside its own subnet, whose MAC address does its ARP request ask for, and why?

level: juniorimportance: must knowfreq 64%
basics
~10 s

The default gateway's. The mask marks the destination off-link, so the host ARPs for the gateway's IPv4 address; the frame goes to the gateway's MAC while the IPv4 header still names the remote destination.

open as a page

In IPv4 over Ethernet, how does ARP find a neighbour's MAC address, and why is the request broadcast but the reply unicast?

level: juniorimportance: must knowfreq 76%
basics
~20 s

ARP broadcasts a request naming the wanted IPv4 address; the owner answers with a unicast reply carrying its MAC, sent to the requester's MAC copied from the request. The requester caches the mapping, then sends the waiting frame.

open as a page

In IPv4 CIDR notation, what does the number after the slash mean, and how do you convert /20 to a dotted-decimal subnet mask and back?

level: juniorimportance: must knowfreq 78%
basics
~20 s

The number after the slash is the prefix length: how many leading bits of the 32-bit IPv4 address are network bits. /20 is twenty ones then twelve zeros, 255.255.240.0; counting the ones in 255.255.240.0 gives 20 back.

open as a page

Which IPv4 address blocks does RFC 1918 reserve for private networks, and why are they not routed on the public internet?

level: juniorimportance: must knowfreq 78%
basics
~10 s

RFC 1918 reserves 10.0.0.0/8, 172.16.0.0/12 (172.16.0.0 to 172.31.255.255) and 192.168.0.0/16. Anyone may reuse them without registration, so they are not unique, and routes and packets for them are kept off inter-network links.

open as a page

In IPv4, how do you work out the usable host count for a prefix length, and the smallest prefix fitting a host requirement?

level: juniorimportance: must knowfreq 76%
basics
~20 s

An IPv4 /n prefix leaves 32 - n host bits: 2^(32 - n) addresses, minus the all-zeros network and all-ones broadcast addresses. To size a subnet, pick the fewest host bits h whose 2^h - 2 covers the hosts needed.

open as a page

In IPv4 addressing, what is VLSM, and why use it instead of giving every subnet the same mask?

level: juniorimportance: must knowfreq 55%
basics
~20 s

VLSM (variable-length subnet masking) carves one IPv4 block into subnets with different prefix lengths, each sized to its segment. A single fixed mask must fit the largest segment, which wastes space on small ones and yields too few subnets.

open as a page

When an IPv4 host answers an ICMP echo request with an echo reply, what does that reply prove, and what does it not prove?

level: juniorimportance: must knowfreq 72%
basics
~20 s

An ICMP echo reply proves that something holding the target address has a running IP stack and that small ICMP datagrams can travel both ways right now. It proves nothing about TCP or UDP services, application health, or larger packets.

open as a page

In IPv4, how is an ICMP message carried, and what do the four parts of its 8-byte header do?

level: juniorimportance: must knowfreq 45%
basics
~20 s

ICMP rides inside an IPv4 datagram with protocol number 1. Its 8-byte header holds an 8-bit type (kind of message), an 8-bit code (specific condition), a 16-bit checksum over the whole ICMP message, and a type-dependent 32-bit word.

open as a page

Why do firewalls often block ICMP, and what breaks when an IPv4 network drops all of it?

level: juniorimportance: must knowfreq 58%
basics
~20 s

ICMP gets blocked because it has carried floods, Smurf amplification, forged redirects, covert tunnels and network mapping. Dropping all of it breaks path-MTU discovery, traceroute and fast error reporting, so large transfers stall and failed connections hang until timeout.

open as a page

In IPv4, what does an ICMP Destination Unreachable message tell the sender of a packet, and what does it not prove?

level: juniorimportance: must knowfreq 45%
basics
~10 s

An ICMP Destination Unreachable (type 3) says one IPv4 datagram was discarded before delivery and its code gives the reason. It does not prove the destination is down, and receiving none proves nothing either.

open as a page

When an IPv4 router or host sends an ICMP error, how much of the offending packet does it quote, and why that much?

level: middleimportance: must knowfreq 35%
basics
~20 s

An ICMPv4 error quotes the offending datagram's full IP header plus at least its first 8 payload bytes, enough to reach the TCP or UDP ports. RFC 1812 asks routers to quote as much as fits in 576 bytes.

open as a page

What is NAT hairpinning, and why does an inside host need it to reach a port-forwarded server by the network's public address?

level: juniorimportance: must knowfreq 40%
basics
~20 s

Hairpinning is a NAT relaying a packet from one inside host back inside to another host that was addressed by its public, translated endpoint. Without it, an inside client that resolves a service name to the public address cannot reach the server.

open as a page

How does Port Address Translation (NAPT) let many private hosts share one public IPv4 address, and how does a reply reach the right host?

level: juniorimportance: must knowfreq 68%
basics
~20 s

A NAPT rewrites each outbound packet's private source address and port to the public address plus a port it assigns, records that binding, and uses a reply's destination port to find the binding and restore the private address and port.

open as a page

On a NAT router, what is port forwarding, and what happens to a packet when a rule maps public port 8443 to 192.168.1.10:443?

level: juniorimportance: must knowfreq 62%
basics
~20 s

Port forwarding is a static inbound NAT mapping: packets for the router's public address on a chosen port get their destination rewritten to an internal host and port, and the replies get their source rewritten back.

open as a page

Why did NAT become standard on IPv4 networks, and what does it cost the Internet's end-to-end reachability between hosts?

level: juniorimportance: must knowfreq 62%
basics
~20 s

IPv4's 32-bit space (about 4.3 billion addresses) ran short, so NAT lets many privately addressed hosts share one public address. The cost: outside hosts cannot start connections to them, the translator holds critical per-flow state, and addresses inside payloads break.

open as a page

In network address translation, what is the difference between source NAT and destination NAT, and what happens to the reply packets in each case?

level: juniorimportance: must knowfreq 62%
basics
~20 s

Source NAT rewrites the source address of outbound packets so inside hosts appear as a public address; destination NAT rewrites the destination of inbound packets so a public address reaches an inside server. Replies get the mirror-image rewrite from the stored mapping.

open as a page

In TCP, what problem does congestion control solve, and why is the receiver's advertised window alone not enough to prevent it?

level: juniorimportance: must knowfreq 58%
basics
~20 s

TCP congestion control stops senders from overloading the network path between two hosts. The receiver's advertised window only protects the receiver's buffer, so the sender keeps its own congestion window and sends no more than the smaller of the two.

open as a page

In TCP, what problem does flow control solve, and how is it different from congestion control?

level: juniorimportance: must knowfreq 62%
basics
~20 s

TCP flow control keeps a fast sender from overrunning the receiver's buffer: the receiver advertises how many more bytes it can accept (rwnd). Congestion control protects the network through the sender's cwnd; the sender obeys the smaller.

open as a page

In TCP, what does each segment of the three-way handshake (SYN, SYN-ACK, ACK) carry, and why are three segments needed?

level: juniorimportance: must knowfreq 82%
basics
~20 s

The SYN carries the client's initial sequence number, the SYN-ACK carries the server's and acknowledges the client's, and the final ACK acknowledges the server's. Three segments let each side confirm the other's starting number and reject stale duplicate SYNs.

open as a page

How does a TCP sender detect that a segment was lost, and what are the two ways it decides to retransmit it?

level: juniorimportance: must knowfreq 55%
basics
~20 s

A TCP sender infers loss two ways: its retransmission timer (RTO) expires with data still unacknowledged, or a third duplicate ACK arrives and triggers fast retransmit. Fast retransmit usually fires first; the timer is the slower backstop.

open as a page

In a TCP header, what do the SYN, ACK, FIN, RST, PSH and URG control flags each signal?

level: juniorimportance: must knowfreq 58%
basics
~20 s

SYN synchronizes sequence numbers to open a connection, ACK says the acknowledgment field is valid, FIN means the sender has no more data, RST aborts the connection, PSH asks for prompt delivery, and URG marks the urgent pointer as significant.

open as a page

UDP preserves message boundaries and TCP does not; if a sender makes three 100-byte sends, what does the receiver get with each?

level: juniorimportance: must knowfreq 58%
basics
~20 s

With UDP the receiver gets up to three separate 100-byte datagrams, each read returning exactly one, in any order or not at all. With TCP it gets 300 ordered bytes split arbitrarily across reads, so the application must mark message edges itself.

open as a page

What does UDP leave out that TCP provides, and what does an application actually see when a datagram is lost, duplicated or reordered?

level: juniorimportance: must knowfreq 74%
basics
~20 s

UDP adds only port multiplexing and a checksum to IP: no delivery guarantee, retransmission, ordering, duplicate suppression, flow control or congestion control. A lost datagram simply never arrives; duplicates and reordered datagrams reach the application as they come.

open as a page

What four fields make up the UDP header, and why is it only 8 bytes when a TCP header is at least 20?

level: juniorimportance: must knowfreq 58%
basics
~20 s

A UDP header is four 16-bit fields: source port, destination port, length and checksum, 8 bytes in all. It is that small because UDP adds only port addressing and an integrity check; it carries no sequence numbers, acknowledgements, window or control flags.

open as a page

What are the core differences between TCP and UDP, and which kinds of workload call for each one?

level: juniorimportance: must knowfreq 82%
basics
~20 s

TCP is a connection-oriented, reliable, ordered byte stream with flow and congestion control; UDP sends independent datagrams with no handshake, retransmission or ordering. Choose TCP when every byte must arrive in order, UDP when latency or statelessness matters more.

open as a page

Why is the UDP checksum optional over IPv4 but mandatory over IPv6, and what does its pseudo-header protect against?

level: middleimportance: must knowfreq 40%
basics
~20 s

Over IPv4, RFC 768 lets a sender put zero for no checksum, and the IPv4 header checksum still guards the addresses. IPv6 has no header checksum, so UDP's checksum over a pseudo-header of the addresses is mandatory to catch corrupted or misdelivered packets.

open as a page

In DNS, what does a record's TTL control, and why can clients keep getting the old address after you change the record?

level: juniorimportance: must knowfreq 68%
basics
~20 s

A DNS TTL is the number of seconds a cache may keep a record before consulting the authoritative source again. Resolvers that cached the old record can keep serving it until their copy's remaining TTL runs out.

open as a page

Does DNS use UDP or TCP, and when does a DNS query move from UDP port 53 to TCP?

level: juniorimportance: must knowfreq 62%
basics
~20 s

DNS uses both. Queries normally travel over UDP port 53; a response too large for UDP (512 bytes without EDNS0) comes back with the TC bit set, and the client repeats the query over TCP port 53, which RFC 7766 makes mandatory.

open as a page

Which DNS record types does example.com need to serve a web app and receive email, and what does each one answer?

level: juniorimportance: must knowfreq 74%
basics
~20 s

A and AAAA map a name to IPv4 and IPv6 addresses, CNAME makes one name an alias of another, MX names the mail servers with a preference (lower first), and TXT carries free-form strings such as verification tokens.

open as a page

With every DNS cache empty, which servers take part in resolving www.example.com, and in what order is each one asked?

level: juniorimportance: must knowfreq 78%
basics
~20 s

The stub resolver asks a recursive resolver; that resolver asks a root server, then a com server, then example.com's authoritative server. The first two refer it onward, the last answers, and the recursive resolver returns the address to the stub.

open as a page

What is DNS cache poisoning, and why does one forged answer accepted by a recursive resolver affect many users?

level: juniorimportance: must knowfreq 52%
basics
~20 s

DNS cache poisoning is getting a recursive resolver to accept and store a forged answer. Because the resolver serves its cache to every client, one accepted forgery misdirects all of them until the record's TTL runs out.

open as a page

In DHCPv4, what are the four messages of the DORA exchange, and who sends each one to which address?

level: juniorimportance: must knowfreq 55%
basics
~20 s

DORA is Discover, Offer, Request, Acknowledge. The client broadcasts a DHCPDISCOVER, each willing server answers with a DHCPOFFER, the client broadcasts a DHCPREQUEST naming the server it chose, and that server commits the lease and sends a DHCPACK.

open as a page

A laptop's DHCPv4 offer carries options 1, 3, 6, 15 and 51; what does each give it, and what breaks without 3 or 6?

level: juniorimportance: must knowfreq 55%
basics
~20 s

A DHCPv4 reply carries the address in yiaddr; option 1 is the subnet mask, 3 the routers, 6 the DNS servers, 15 the domain name, 51 the lease in seconds. Without 3 the host stays on its subnet; without 6 names fail.

open as a page

Why can a DHCPv4 client not reach a server on another subnet by itself, and what does a relay agent do about it?

level: juniorimportance: must knowfreq 42%
basics
~20 s

A DHCPv4 client with no address broadcasts to 255.255.255.255, which routers must not forward. A relay agent on the subnet's gateway catches that broadcast, writes its own interface address into giaddr and unicasts the message to the configured DHCP server.

open as a page

In DHCPv4, how does a printer reservation differ from a static address set on the printer, and which should be the source of truth?

level: juniorimportance: must knowfreq 48%
basics
~20 s

A reservation keeps the printer on DHCP: the server always gives its identifier the same address, with current options. A static address lives only on the printer, invisible to the server, so it must stay out of the pool.

open as a page

When a test DHCPv4 server is plugged into a production access switch, what do clients on that VLAN get, and why is it possible?

level: juniorimportance: must knowfreq 45%
basics
~20 s

Clients that accept the test server's offer take its address, default router and DNS servers, and keep renewing with it. DHCPv4 allows this because RFC 2131 gives a client no way to authenticate a server.

open as a page

In plain NTP, why can an on-path attacker who shifts a client's clock make expired certificates and replayed tokens valid again?

level: juniorimportance: must knowfreq 32%
basics
~20 s

Certificate lifetimes, time-based one-time codes and replay windows all compare against the local clock. Plain NTP replies are unauthenticated UDP, so an attacker on the path can rewrite them and move the clock back until expired credentials pass again.

open as a page

Why does a computer clock left without NTP drift, and how far does a 50 PPM oscillator error move it in a day?

level: juniorimportance: must knowfreq 38%
basics
~20 s

A clock counts oscillator ticks, and no oscillator runs at exactly its nominal frequency, so the error accumulates. 50 PPM is 50 microseconds per second: 50 x 10^-6 x 86,400 s is about 4.3 seconds a day.

open as a page

What does an NTP server's stratum number tell you, and why is a lower stratum not the same as better time?

level: juniorimportance: must knowfreq 45%
basics
~20 s

Stratum counts how many NTP hops a server sits from a reference clock: 1 is a primary server, 2-15 are secondary servers, 16 means unsynchronized. It measures distance in the tree, not the size of the clock's error.

open as a page

In Network Time Security, how does NTS-KE give a client its keys and cookies, and why can the NTP server keep no per-client state?

level: middleimportance: must knowfreq 22%
basics
~20 s

NTS-KE runs TLS 1.3 on TCP 4460, exports two AEAD keys and hands the client cookies: those keys sealed under a server secret. Each NTP request carries one cookie, so the server recovers the keys from it and stores no per-client state.

open as a page

An NTP client records T1 = 1000, T2 = 1045, T3 = 1050 and T4 = 1055 ms; what are the delay and offset?

level: middleimportance: must knowfreq 38%
basics
~10 s

Delay is (T4-T1)-(T3-T2) = 55 - 5 = 50 ms. Offset is ((T2-T1)+(T3-T4))/2 = (45 - 5)/2 = +20 ms: the server is 20 ms ahead, assuming each leg took 25 ms.

open as a page

Why do switched Ethernet networks need spanning tree, and why is a Layer 2 loop more destructive than a Layer 3 routing loop?

level: juniorimportance: must knowfreq 65%
basics
~20 s

Ethernet frames carry no TTL or hop count, so a broadcast that enters a loop of switches circulates indefinitely and keeps reaching every host. Spanning tree blocks redundant ports so one active path remains, and reopens one if that path fails.

open as a page

In spanning tree, which switch becomes the root bridge, and why does an untuned network often end up with an old switch as root?

level: juniorimportance: must knowfreq 50%
basics
~20 s

The switch with the lowest bridge ID becomes root. The bridge ID is a priority followed by a MAC address, and every switch ships with the same default priority, so the lowest MAC decides, which is frequently an older device.

open as a page

What does Rapid Spanning Tree Protocol (RSTP, IEEE 802.1w) change compared with classic 802.1D spanning tree?

level: juniorimportance: must knowfreq 45%
basics
~20 s

RSTP keeps 802.1D's root election and path costs but adds alternate and backup port roles, merges disabled, blocking and listening into one discarding state, and moves ports to forwarding by an explicit neighbour handshake instead of waiting out timers.

open as a page

In 802.1D spanning tree, what do the Hello, Max Age and Forward Delay timers control, and whose values do bridges actually use?

level: middleimportance: must knowfreq 40%
basics
~20 s

Hello Time (IEEE default 2 s) paces the root's Configuration BPDUs, Max Age (20 s) is how long stored BPDU information lives, and Forward Delay (15 s) is each listening and learning period. Every bridge uses the root's values, carried in its BPDUs.

open as a page

Under 802.1D spanning tree, why does a direct uplink failure take about 30 seconds to recover while an indirect failure takes about 50?

level: middleimportance: must knowfreq 40%
basics
~20 s

A direct failure shows up at once as link loss, leaving only listening and learning: about 30 s at IEEE defaults. An indirect failure is learned through BPDUs, so stored information must first reach Max Age (20 s): about 50 s.

open as a page

Why does VXLAN identify segments with a 24-bit VNI rather than VLAN IDs, and how many segments does that allow?

level: juniorimportance: must knowfreq 42%
basics
~20 s

VXLAN carries a 24-bit VXLAN Network Identifier in its own header, giving 2^24 = 16,777,216 segment IDs against 4,094 usable 12-bit VLAN IDs, so a shared data centre can give every tenant many isolated layer 2 segments.

open as a page

What is a VXLAN Tunnel Endpoint (VTEP), and what does it do to an Ethernet frame entering and leaving the tunnel?

level: juniorimportance: must knowfreq 42%
basics
~20 s

A VTEP originates and terminates VXLAN tunnels: it wraps a host's Ethernet frame in a VXLAN header carrying the segment's VNI, plus UDP and an outer IP header addressed VTEP to VTEP, and the far VTEP strips them and delivers the original frame.

open as a page

How many bytes does VXLAN encapsulation add to an Ethernet frame over IPv4, and how does that change with IPv6 or an outer 802.1Q tag?

level: middleimportance: must knowfreq 36%
basics
~20 s

Over IPv4, VXLAN adds 50 bytes: outer Ethernet 14, outer IPv4 20, UDP 8 and the VXLAN header 8. An outer 802.1Q tag makes it 54; an outer IPv6 header, 40 bytes, makes it 70, or 74 tagged.

open as a page

Why do VXLAN fabrics adopt BGP EVPN as a control plane, and what does it advertise that flood-and-learn must discover by flooding?

level: middleimportance: must knowfreq 30%
basics
~20 s

BGP EVPN lets each VTEP announce the MAC and IP addresses it learned locally as BGP routes, so remote VTEPs know where hosts live before traffic flows, instead of learning them by flooding unknown and ARP traffic across the fabric.

open as a page

In a VXLAN segment using data-plane learning, what does each VTEP learn as two hosts complete their first ARP exchange?

level: middleimportance: must knowfreq 32%
basics
~20 s

Host A's ARP broadcast is flooded to every VTEP in the VNI, so each learns A's MAC behind A's VTEP. B's unicast reply goes to A's VTEP alone, which learns B's MAC behind B's VTEP; afterwards both directions are known unicast.

open as a page

How does a RIP router choose its route to a network, and how does the hop count change as a route travels one router further?

level: juniorimportance: must knowfreq 40%
basics
~20 s

A RIP router adds the cost of the network an update arrived on, normally 1, to each metric a neighbour advertises and keeps the lowest result, with that neighbour as next hop; metric 16 means unreachable.

open as a page

When a RIP neighbour dies silently, when do its routes leave service and the table under RFC 2453, and how does the 180/180/240 set differ?

level: middleimportance: must knowfreq 30%
basics
~20 s

Under RFC 2453 a RIP route expires 180 seconds after its last refresh, is advertised at metric 16 while a 120-second garbage-collection timer runs, then is deleted: 300 seconds in all. The invalid/holddown/flush set of 180/180/240 is an implementation's.

open as a page

In RIP, what is count-to-infinity, and how does it unfold when a router's connected network fails while a neighbour still advertises it?

level: middleimportance: must knowfreq 32%
basics
~20 s

Count-to-infinity is RIP's slow failure mode: after a network vanishes, routers keep re-learning it from each other's stale advertisements, raising the metric one hop per exchange until it reaches 16, RIP's infinity, and the route is finally declared unreachable.

open as a page

In RIP, how does simple split horizon differ from split horizon with poisoned reverse, and why is poisoned reverse considered safer?

level: middleimportance: must knowfreq 30%
basics
~20 s

Simple split horizon leaves a route out of updates sent where it was learned; poisoned reverse sends it there with metric 16. That explicit 16 breaks a two-router loop at once rather than after a timeout, but enlarges updates.

open as a page

What does a RIPv2 route entry carry that a RIPv1 entry does not, and why did the missing subnet mask make RIPv1 classful?

level: middleimportance: must knowfreq 32%
basics
~20 s

RIPv1 route entries carry no subnet mask, so a receiver infers each mask from its own interface or the address class, which makes RIPv1 classful. RIPv2 reuses unused fields for a subnet mask, a route tag and a next hop.

open as a page

In OSPF, why is a large network split into areas, and what job do backbone area 0, ABRs and ASBRs each do?

level: juniorimportance: must knowfreq 55%
basics
~20 s

OSPF areas bound LSA flooding and SPF runs, so a change in one area does not ripple through every router. Area 0 is the hub every area attaches to; ABRs join areas to it, and ASBRs inject routes learned outside OSPF.

open as a page

In OSPF, what does a router's SPF calculation take as input, and what does it produce?

level: juniorimportance: must knowfreq 45%
basics
~20 s

An OSPF router runs Dijkstra's shortest-path-first algorithm over its area's link-state database with itself as the root. The result is a shortest-path tree giving the lowest total cost and next hops to every destination, which becomes its routing table.

open as a page

How does OSPF elect a Designated Router and Backup Designated Router on a LAN, and why doesn't a higher-priority newcomer take over?

level: middleimportance: must knowfreq 45%
basics
~20 s

On broadcast and NBMA networks, OSPF elects a BDR, then a DR, from routers in 2-Way or above: highest Router Priority wins, highest Router ID breaks ties, priority 0 never qualifies. A better newcomer never preempts a working DR.

open as a page

In OSPF, which states does a neighbour pass through from the first Hello to Full, and what happens in each?

level: middleimportance: must knowfreq 48%
basics
~20 s

An OSPF neighbour goes Down, Init (its Hello heard), 2-Way (each sees itself in the other's Hello), ExStart (master and slave chosen), Exchange (database summaries traded), Loading (missing LSAs requested) and Full (databases synchronised). NBMA adds Attempt.

open as a page

What does an EIGRP router's composite metric measure along a path by default, and which carried values does it leave out?

level: juniorimportance: must knowfreq 34%
basics
~20 s

By default the EIGRP composite metric adds two terms: the inverse of the slowest link's bandwidth on the path and the sum of the outgoing interfaces' delays. Load, reliability, MTU and hop count travel with the route but are not weighed.

open as a page

In EIGRP, what makes routing updates partial and bounded, and how does that differ from RIP's periodic full-table updates?

level: juniorimportance: must knowfreq 42%
basics
~20 s

EIGRP sends an UPDATE only when a route is added or its metric changes, carries only those prefixes, and the change stops spreading where no router's best path changes; RIP resends its whole table every 30 seconds.

open as a page

How do you compute an EIGRP path's classic composite metric by hand, and why can a longer path beat a shorter one?

level: middleimportance: must knowfreq 27%
basics
~20 s

With default K-values, the EIGRP classic metric is 256 × (10^7 / slowest bandwidth in kb/s + summed delay in tens of microseconds). Only the slowest link sets the bandwidth term, so a longer path with a faster bottleneck can win.

open as a page

In EIGRP, what is the feasibility condition, and how does it decide which neighbours become feasible successors for a prefix?

level: middleimportance: must knowfreq 30%
basics
~20 s

A neighbour meets EIGRP's feasibility condition when its reported distance to a prefix is strictly below this router's feasible distance, its best distance since the route last went passive; that neighbour is a feasible successor, a guaranteed loop-free backup.

open as a page

Two EIGRP routers on the same link can ping each other but never become neighbours; what do you check, and why?

level: middleimportance: must knowfreq 38%
basics
~20 s

First check that hellos cross the link: EIGRP enabled, IP protocol 88 and 224.0.0.10 not filtered. Then the three things RFC 7868 makes neighbours agree on: the AS number, the K-values and authentication. Hello and hold timers need not match.

open as a page

In BGP, what is an autonomous system, and what does its AS number do in the routes BGP exchanges?

level: juniorimportance: must knowfreq 55%
basics
~20 s

An autonomous system is a network, or group of IP prefixes, run under one clearly defined routing policy. Its AS number identifies it to BGP peers and is prepended to AS_PATH, which BGP uses to compare paths and reject loops.

open as a page

How does a BGP speaker use the AS_PATH attribute to keep routes from looping between autonomous systems?

level: juniorimportance: must knowfreq 45%
basics
~20 s

Each AS adds its own number to AS_PATH when advertising a route to an external peer. A BGP speaker that finds its own AS number in a received AS_PATH treats the route as a loop and does not use it.

open as a page

Why does BGP run its sessions over TCP port 179, and what are the four message types a BGP-4 session exchanges?

level: juniorimportance: must knowfreq 46%
basics
~20 s

BGP runs over TCP port 179 so TCP supplies retransmission, ordering and sequencing for it. A BGP-4 session uses four messages: OPEN starts it, UPDATE advertises and withdraws routes, NOTIFICATION reports an error and closes it, KEEPALIVE shows the peer is alive.

open as a page

In BGP, what distinguishes an eBGP session from an iBGP session, and how does each one treat the routes it passes on?

level: juniorimportance: must knowfreq 55%
basics
~20 s

eBGP joins speakers in different autonomous systems, iBGP speakers in the same one. eBGP prepends the sender's AS number and normally rewrites NEXT_HOP; iBGP changes neither and, outside route reflection, does not relay one iBGP peer's routes to another.

open as a page

What makes a BGP autonomous system stub, multihomed or transit, and when does an enterprise need an AS number of its own?

level: middleimportance: must knowfreq 45%
basics
~20 s

A stub AS has one neighbouring AS; a multihomed AS has several but, as an enterprise, carries only its own traffic; a transit AS carries traffic between other ASes. An enterprise mainly needs its own ASN to multihome.

open as a page

What is Bidirectional Forwarding Detection (BFD), and why do routers run it beside BGP or OSPF instead of relying on their own keepalives?

level: juniorimportance: must knowfreq 34%
basics
~20 s

BFD (RFC 5880) is a lightweight hello protocol that only checks, in milliseconds, whether the forwarding path to a neighbour works; it carries no routes and tells clients such as BGP, OSPF or a static route to react.

open as a page

In network design, what does an availability of 99.99% mean in downtime per year, and how is availability derived from MTBF and MTTR?

level: juniorimportance: must knowfreq 60%
basics
~20 s

Availability is the fraction of time a system is in service: MTBF / (MTBF + MTTR). At 99.99% the allowed downtime is 0.01% of a year, about 52.6 minutes; 99.9% allows about 8.76 hours and 99.999% about 5.26 minutes.

open as a page

How does a first-hop redundancy protocol such as VRRP keep a LAN's static default gateway working when one router fails?

level: juniorimportance: must knowfreq 58%
basics
~20 s

Routers share one virtual gateway IP and one virtual MAC; an election makes one Active, which answers ARP and forwards. If its advertisements stop, a Backup claims the same addresses, so hosts keep their configured gateway unchanged.

open as a page

In SD-WAN, what is the difference between the overlay and the underlay, and why does that split let a branch use almost any transport?

level: juniorimportance: must knowfreq 40%
basics
~20 s

The underlay is the rented transports, such as MPLS, broadband or LTE, that only carry packets between edge addresses; the overlay is the encrypted tunnels, routes and policy built over them, so sites see one private network whatever the transport.

open as a page

In SNMP, what do the manager and the agent each do, and which UDP ports carry requests and notifications?

level: juniorimportance: must knowfreq 55%
basics
~20 s

An SNMP manager sends requests to agents and receives their notifications; the agent on each managed device answers from its managed objects and sends notifications on events. Requests go to the agent on UDP 161, notifications to the manager on UDP 162.

open as a page

In SNMP, what is an object identifier, and how does the numeric OID 1.3.6.1.2.1.1.3.0 map to a named MIB object?

level: juniorimportance: must knowfreq 45%
basics
~10 s

An OID is a path of numbered arcs through a global registration tree. 1.3.6.1.2.1.1.3.0 reads iso.org.dod.internet.mgmt.mib-2.system.sysUpTime plus .0, the single instance of that scalar; a MIB module supplies the name, type and meaning.

open as a page

What do the SNMP GetRequest, GetNextRequest, GetBulkRequest and SetRequest PDUs each ask an agent to do, and what comes back?

level: juniorimportance: must knowfreq 42%
basics
~20 s

GetRequest reads exactly the named instances; GetNextRequest returns each name's successor in OID order; GetBulkRequest returns many successors at once; SetRequest writes values all or nothing. Each is answered by a Response-PDU with the same request-id, an error-status and an error-index.

open as a page

Why are SNMPv1 and SNMPv2c community strings considered insecure, and what does SNMPv3 put in their place?

level: juniorimportance: must knowfreq 58%
basics
~20 s

An SNMPv1 or SNMPv2c community string is a shared password sent unencrypted in every message, so one captured packet lets anyone reuse it, and nothing protects integrity or freshness. SNMPv3 replaces it with per-user authentication, optional encryption and view-based access control.

open as a page

How do you compute a link's utilisation from SNMP IF-MIB octet counters polled twice, and which speed object do you divide by?

level: middleimportance: must knowfreq 42%
basics
~10 s

Difference two readings of ifHCInOctets (or ifHCOutOctets), multiply by 8, divide by the seconds between the polls, then divide by the interface speed, ifHighSpeed x 1,000,000 bit/s. Each direction is computed separately.

open as a page

In NetFlow and IPFIX flow export, what is a flow key, and how does an exporter turn packets into flow records?

level: juniorimportance: must knowfreq 35%
basics
~20 s

A flow key is the set of fields, classically the five-tuple, that packets must share to count as one flow. The exporter keeps a cache entry per key, adds each matching packet to it, and exports it as a record on expiry.

open as a page

Why does streaming telemetry from network devices beat five-minute SNMP polling when you monitor 2,000 routers and switches?

level: juniorimportance: must knowfreq 40%
basics
~20 s

SNMP polling makes a manager ask every device for every value each cycle, so data arrives late, averaged and lost under stress. Streaming telemetry subscribes once; each device then pushes YANG-modelled values on a timer or on change.

open as a page

What are syslog's eight severity levels, and what does a filter for 'Warning and more urgent' actually select?

level: juniorimportance: must knowfreq 45%
basics
~10 s

Syslog severities run from 0 Emergency to 7 Debug, and a lower number means a more urgent message. 'Warning and more urgent' therefore selects 0 to 4: Emergency, Alert, Critical, Error and Warning.

open as a page

How do a NetFlow or IPFIX exporter's active and inactive timeouts decide when flow records are sent, and what do they do to per-minute graphs?

level: middleimportance: must knowfreq 25%
basics
~20 s

The inactive timeout expires a flow that has gone quiet; the active timeout exports a long-lived flow in slices. Collectors see traffic only when records arrive, so a long active timeout piles a long transfer into one graph spike.

open as a page

How does a network TAP differ from a SPAN port as a packet source, and what happens to the monitored link when each loses power?

level: middleimportance: must knowfreq 30%
basics
~20 s

A SPAN port is switch configuration copying frames best effort; a TAP sits in the cable and copies the signal. A passive optical TAP needs no power, so a power cut is harmless; an active copper TAP typically drops the link briefly.

open as a page

In a YANG module, what do the namespace and prefix statements each do, and which one identifies the module's data on the wire?

level: juniorimportance: must knowfreq 20%
basics
~20 s

A YANG namespace is a globally unique URI that qualifies the module's definitions and never changes; the prefix is a short local handle an importer may rename. Encoded data uses the namespace in XML and the module name in JSON, never the prefix.

open as a page

In YANG, what is the difference between a container, a list, a leaf and a leaf-list when modelling a router's interfaces?

level: juniorimportance: must knowfreq 30%
basics
~20 s

A YANG leaf holds one typed value and a leaf-list a set of values of one type; a container groups child nodes and occurs at most once under its parent, while a list holds many entries, each identified by its key leafs.

open as a page

In YANG, how does a vendor module use augment to add a QoS leaf to the standard ietf-interfaces list without editing that module?

level: middleimportance: must knowfreq 16%
basics
~10 s

The vendor module imports ietf-interfaces and declares augment "/if:interfaces/if:interface" with the new leaf inside. The leaf appears in every interface entry but belongs to the vendor module's namespace, so the standard module stays untouched.

open as a page

In YANG, how does a must statement differ from a when statement, and what happens to the data when each evaluates to false?

level: middleimportance: must knowfreq 22%
basics
~20 s

A false YANG must is a validation error: the edit is refused with the must's error-message and error-app-tag. A false when means its node does not apply: writes to it fail, and an existing instance is silently deleted.

open as a page

In YANG, how do feature and if-feature make part of a module optional, and what happens when a client configures an unsupported part?

level: middleimportance: must knowfreq 15%
basics
~20 s

A feature statement names an optional capability and if-feature ties schema nodes to it. Where a server does not support the feature those nodes are absent from its schema, and a NETCONF server must reject data for them with unknown-element.

open as a page

In NETCONF, what do the running, candidate and startup configuration datastores each hold, and which one must every device have?

level: juniorimportance: must knowfreq 28%
basics
~20 s

Running holds the configuration in use now and is the only datastore every NETCONF device has. Candidate is an optional full working copy you edit and then commit; startup is an optional copy loaded at boot.

open as a page

How does a NETCONF client open a session over SSH, and why does NETCONF run as an SSH subsystem rather than through a shell?

level: juniorimportance: must knowfreq 28%
basics
~20 s

A NETCONF client connects to TCP port 830, authenticates over SSH, opens an SSH session channel and requests the subsystem named "netconf". The subsystem hands the channel straight to the NETCONF server, so no shell prompt or login banner corrupts the XML stream.

open as a page

Why is SNMP mostly used to monitor network devices, while NETCONF is the protocol usually chosen to configure them?

level: juniorimportance: must knowfreq 28%
basics
~20 s

SNMP was designed for cheap polling of counters and status, and standard MIB modules rarely expose writable configuration; NETCONF was designed for configuration, with full-configuration retrieval, staged and validated edits, an all-or-nothing commit and a YANG schema.

open as a page

In NETCONF, how does the candidate workflow of edit, <validate>, then <commit> or <discard-changes> change the running datastore?

level: middleimportance: must knowfreq 22%
basics
~10 s

Edits to the candidate change nothing on the device. <validate> checks the candidate, <commit> sets running to the candidate's entire contents, and <discard-changes> throws the edits away by resetting the candidate to running.

open as a page

In NETCONF, what does a <lock> on a configuration datastore prevent, how long does it last, and what does a competing session get back?

level: middleimportance: must knowfreq 22%
basics
~20 s

A NETCONF <lock> gives one session exclusive write access to a whole datastore until it unlocks or its session ends; other sessions, SNMP and CLI cannot change it, and a competing <lock> fails with lock-denied naming the holder's session-id.

open as a page

On a RESTCONF server, what does each HTTP method — GET, POST, PUT, PATCH and DELETE — do to YANG-modelled configuration data?

level: juniorimportance: must knowfreq 22%
basics
~20 s

RESTCONF (RFC 8040) maps HTTP methods onto YANG data: GET reads a subtree, POST creates a child or invokes an operation, PUT creates or replaces the target, plain PATCH merges into it, and DELETE removes an existing node.

open as a page

In RESTCONF, what does each child of the API root resource — data, operations and yang-library-version — give a client?

level: juniorimportance: must knowfreq 16%
basics
~20 s

Under the RESTCONF API root, data is the one combined datastore of configuration and state that clients read and edit, operations lists and invokes the server's YANG RPCs, and yang-library-version gives the ietf-yang-library revision the server implements.

open as a page

How does RESTCONF differ from NETCONF in transport, message encoding and the way a client converses with a device?

level: juniorimportance: must knowfreq 24%
basics
~20 s

RESTCONF carries YANG-modelled data over HTTPS as XML or JSON, one self-contained HTTP request per operation. NETCONF sends XML RPCs over a long-lived SSH or TLS session, which can hold locks and stage edits before committing them.

open as a page

In RESTCONF, how do YANG containers, lists and leaves become the URI path of a data resource under {+restconf}/data?

level: juniorimportance: must knowfreq 20%
basics
~20 s

Every data node from the top of the YANG tree down to the target becomes one path segment under {+restconf}/data: containers and leaves by name, list entries as name=key, and the top-level node prefixed with its module name.

open as a page

Why does a RESTCONF server reject a JSON body whose member names are unqualified, and where does RFC 7951 require module prefixes?

level: middleimportance: must knowfreq 18%
basics
~20 s

RFC 7951 requires every top-level JSON member to be named module:node, and a child to be qualified again only when its module differs from its parent's, as with augmented nodes; without those names the server cannot map the body to its schema.

open as a page

In a remote-access VPN, what is the difference between a full tunnel and a split tunnel, and what does each cost?

level: juniorimportance: must knowfreq 55%
basics
~20 s

A full tunnel sends all the client's traffic through the VPN gateway; a split tunnel sends only corporate destinations there and lets the rest go direct. Split saves gateway capacity and latency; full keeps central visibility and control.

open as a page

What is the difference between a site-to-site VPN and a remote-access VPN, and who terminates each tunnel?

level: juniorimportance: must knowfreq 58%
basics
~20 s

A site-to-site VPN joins two networks through gateways, so hosts need no VPN software; a remote-access VPN joins one device, running a client, to a gateway that authenticates the user and assigns an inner address.

open as a page

In WireGuard, what identifies a peer, and why do two WireGuard peers never negotiate a cipher suite?

level: juniorimportance: must knowfreq 42%
basics
~20 s

A WireGuard peer is identified only by its static Curve25519 public key, exchanged out of band. The cryptography is fixed by the protocol (Curve25519, ChaCha20-Poly1305, BLAKE2s), so there is nothing to negotiate and nothing to downgrade.

open as a page

Why do two branch routers pair GRE with IPsec to run OSPF over the internet, instead of using a policy-based IPsec tunnel alone?

level: middleimportance: must knowfreq 35%
basics
~20 s

GRE gives the routers a point-to-point link that carries OSPF's multicast hellos and any routed subnet; IPsec encrypts and authenticates that single GRE flow. Policy-based IPsec alone matches unicast subnet pairs and gives OSPF no interface to run on.

open as a page

How do IPsec, WireGuard and TLS-based VPNs each get through a NAT, and which of them still connects when a hotel network blocks UDP?

level: middleimportance: must knowfreq 35%
basics
~20 s

Tunnels answer a NAT three ways: ride UDP (IPsec wraps ESP in UDP 4500; WireGuard is UDP already), send keepalives so the mapping stays, or hide inside TCP or TLS on 443. Only the TCP rung survives dropped UDP.

open as a page

In IPsec, what does the Authentication Header (AH) protect, what does ESP protect, and why is ESP the one deployed?

level: juniorimportance: must knowfreq 45%
basics
~20 s

AH (IP protocol 51) authenticates the payload plus the IP header fields that do not change in transit, and encrypts nothing. ESP (protocol 50) encrypts and normally authenticates its own contents, not the outer header, and meets almost every need.

open as a page

In IPsec, what job does IKE do before any protected packet flows, and how did IKEv1's two phases divide that job?

level: juniorimportance: must knowfreq 45%
basics
~20 s

IKE authenticates the peers, negotiates algorithms and derives keys for ESP or AH. IKEv1 split this into Phase 1 (Main or Aggressive Mode, building a protected IKE SA) and Phase 2 (Quick Mode, negotiating IPsec SAs under it); RFC 9395 deprecates IKEv1.

open as a page

In IPsec, what is the difference between transport mode and tunnel mode, and where does the ESP header sit in each?

level: juniorimportance: must knowfreq 50%
basics
~20 s

IPsec transport mode keeps the original IP header and inserts ESP between it and the payload, protecting only that payload; tunnel mode puts the whole original packet, header included, behind ESP and a new outer IP header.

open as a page

Why does plain IPsec ESP often fail through a home router's port-translating NAT, and what does NAT traversal change on the wire?

level: juniorimportance: must knowfreq 40%
basics
~20 s

ESP is IP protocol 50 with no port numbers, so a port-translating NAT cannot tell which inside host an inbound packet is for. NAT traversal puts a UDP header on port 4500 in front of ESP, giving the NAT ports to map.

open as a page

In IPsec, what is a Security Association, and why does protecting two-way traffic between two gateways take a pair of them?

level: juniorimportance: must knowfreq 42%
basics
~20 s

An IPsec Security Association is one-way state: the keys, algorithms, counters and selectors protecting traffic in a single direction with AH or ESP. Two-way traffic therefore needs two SAs, one per direction, each with its own SPI.

open as a page

What does a DNSSEC RRSIG record returned alongside an answer prove about that answer, and what does it leave unprotected?

level: juniorimportance: must knowfreq 45%
basics
~20 s

A DNSSEC RRSIG proves one RRset was signed with the private key behind a zone's DNSKEY and is unchanged, within its inception-to-expiration window. It adds no secrecy, no freshness inside that window and no DoS protection.

open as a page

When a DNSSEC-validating resolver cannot verify an answer's signatures, what does the client receive, and why does it look like an outage?

level: juniorimportance: must knowfreq 35%
basics
~20 s

The client gets SERVFAIL (RCODE 2) and no records: the resolver withholds bogus data rather than pass on a possible forgery. SERVFAIL also reports unreachable or broken servers, so to users the domain simply seems down.

open as a page

How does a DNSSEC-validating resolver build a chain of trust from the root trust anchor down to the A record of www.example.com?

level: middleimportance: must knowfreq 40%
basics
~20 s

From the root anchor down, at every zone cut the parent's signed DS must match a digest of a child DNSKEY, and that key must sign the child's DNSKEY RRset. A key of the last zone then verifies the RRSIG over the A record.

open as a page

In a DNSSEC-signed zone, how does an NSEC record prove that a queried name or record type does not exist?

level: middleimportance: must knowfreq 30%
basics
~20 s

An NSEC record names the next existing name in canonical order and lists the types at its owner. A signed NSEC spanning the queried name proves the name absent; one at that name, lacking the type, proves no data.

open as a page

Why does DNSSEC's NSEC record let anyone list every name in a signed zone, and what does NSEC3 change about it?

level: middleimportance: must knowfreq 25%
basics
~20 s

Each NSEC names the next existing name, so following the chain from the apex lists the whole zone. NSEC3 hashes owner names with SHA-1, so the chain shows hashes, not names, though guessable names still fall to offline dictionary attacks.

open as a page

In SRTP, why does encrypting the RTP payload not stop an attacker from replaying recorded video packets or flipping bits in them?

level: juniorimportance: must knowfreq 42%
basics
~20 s

Encryption hides content but never fails: flipped bits in SRTP counter-mode ciphertext decrypt to the same flipped plaintext bits, and a recorded packet decrypts fine when re-sent. SRTP adds an authentication tag and a replay list to catch both.

open as a page

Why is a SIP call's media sent as plain RTP over UDP unsafe on a shared office LAN, and what does SRTP add?

level: juniorimportance: must knowfreq 45%
basics
~20 s

Plain RTP carries no encryption, integrity check or replay protection: anyone seeing the packets can decode the audio, and anyone reaching the port can inject or replay media. SRTP adds payload encryption, whole-packet authentication and replay protection.

open as a page

In SRTP's default protection profile, AES_CM_128_HMAC_SHA1_80, what does each part of the name select, and why is there a 112-bit salt?

level: middleimportance: must knowfreq 30%
basics
~20 s

AES_CM_128_HMAC_SHA1_80 is AES counter mode under a 128-bit master key for confidentiality, plus HMAC-SHA1 truncated to an 80-bit tag for integrity. The 112-bit salt, beside a 16-bit block counter, fills each counter block and blunts precomputation.

open as a page

Why is keying SRTP with SDES a=crypto lines considered unsafe, and how does DTLS-SRTP avoid the same weakness?

level: middleimportance: must knowfreq 28%
basics
~20 s

SDES puts each sender's SRTP master key in the SDP, so every proxy, log or trace that reads the signalling can decrypt the media. DTLS-SRTP derives keys in a handshake on the media path; signalling carries only a certificate fingerprint.

open as a page

How does an SRTP receiver's sliding replay window decide whether an arriving packet's 48-bit index is accepted or discarded?

level: middleimportance: must knowfreq 30%
basics
~20 s

An SRTP receiver accepts an index ahead of its highest authenticated index, or inside the window and unseen; it discards one already marked or too far behind. The window, at least 64 packets, is marked only after the tag verifies.

open as a page