SEMESTER 5 · COMPUTER NETWORKS
Computer Networks Study Notes
Exam-focused coverage of all 5 units — OSI/TCP/IP models, switching, subnetting, routing, transport protocols, and network security.
5 Units
1M + 5M + 15M
PYQs Marked
MAKAUT Pattern
- 1-Mark Qs
- 35+
Definitions & facts
- 5-Mark Qs
- 22+
Explanations & diagrams
- 15-Mark Qs
- 12+
Detailed answers
- PYQs
- 2021–24
Previous years
01
Introduction & Physical Layer
Introduction & Physical Layer
↻
Quick Revision
Quick Revision: Networks connect devices (hosts) via communication links (wired/wireless). Physical Layer defines electrical/mechanical specs. Topologies define layout. Transmission media carry signals. Multiplexing shares a link. Switching routes data.
1-Mark Questions — Definitions
1-Mark
1M
Define Computer Network.
A Computer Network is a collection of autonomous computers interconnected by a single technology (communication medium) for the purpose of sharing resources (files, printers) and information.
1M
What is a LAN?
A Local Area Network (LAN) is a network that connects computers within a limited area such as a home, office, or building, with typical speeds of 100 Mbps to 10 Gbps.
1M
What is a MAN?
A Metropolitan Area Network (MAN) spans a city or metropolitan area (e.g., cable TV network). It covers a larger geographic area than a LAN but smaller than a WAN.
1M
What is a WAN?
A Wide Area Network (WAN) spans countries/continents (e.g., the Internet). It uses leased lines or satellite links and is usually slower than LANs.
1M
What is a PAN?
A Personal Area Network (PAN) connects devices within a range of a few meters (e.g., Bluetooth, NFC, USB). Used for personal devices.
1M
What is a topology?
Network Topology is the physical or logical arrangement of computers, cables, and other components in a network. Common types: Bus, Star, Ring, Mesh, Tree, Hybrid.
1M
What is the OSI reference model?
The OSI (Open Systems Interconnection) model is a 7-layer framework (Physical, Data Link, Network, Transport, Session, Presentation, Application) for standardizing network communication.
1M
What is the TCP/IP model?
The TCP/IP model is a 4-layer model (Network Interface, Internet, Transport, Application) that forms the basis of the Internet.
1M
Define Simplex, Half-Duplex, and Full-Duplex transmission modes.
Simplex — one-way only (TV broadcast). Half-Duplex — both directions but not simultaneously (walkie-talkie). Full-Duplex — both directions simultaneously (telephone).
1M
What is guided transmission media?
Guided media uses physical cables/twisted pair, coaxial cable, optical fiber) to transmit signals in a directed path.
1M
What is unguided transmission media?
Unguided media (wireless) transmits signals through the atmosphere/space without cables. Examples: radio waves, microwaves, infrared.
1M
Define Multiplexing.
Multiplexing is the technique of combining multiple signals into one signal over a shared medium. Types: FDM, TDM, WDM.
1M
What is Switching?
Switching is the method of connecting devices for communication. Types: Circuit Switching, Message Switching, Packet Switching.
5-Mark Questions
5-Mark
5M
Explain different network topologies with advantages and disadvantages.
Bus Topology: Single cable backbone. All devices connect to it. Adv: Simple, cheap. Disadv: Single point of failure, difficult troubleshooting.
Star Topology: Each device connects to a central hub/switch. Adv: Easy to troubleshoot, one cable failure doesn't affect others. Disadv: Hub failure breaks entire network.
Ring Topology: Devices form a closed loop. Adv: orderly, no collisions. Disadv: One device failure breaks ring.
Mesh Topology: Every device connects to every other. Adv: High redundancy, reliable. Disadv: Very expensive.
Tree/Hybrid: Combination of star and bus. Used in large organizations.
5M
Compare OSI and TCP/IP reference models.
| Aspect | OSI Model | TCP/IP Model |
| Layers | 7 layers | 4 layers |
| Approach | Vertical (strict layer separation) | Horizontal (protocols developed first) |
| Network Layer | Network Layer | Internet Layer (IP) |
| Transport Layer | Transport Layer | Host-to-Host Layer |
| Session/Presentation | Separate layers | Merged with Application |
| Standards | Defined before protocols | Protocols defined before model |
| Usage | Theoretical/educational | Practical (Internet) |
Note: OSI layers → Physical, Data Link, Network, Transport, Session, Presentation, Application. TCP/IP layers → Network Interface, Internet, Transport, Application.
5M
Explain Frequency Division Multiplexing (FDM) and Time Division Multiplexing (TDM) with diagrams.
FDM: The total bandwidth is divided into multiple non-overlapping frequency bands. Each signal modulates a different carrier frequency. Used in radio/TV broadcasting. Guard bands prevent interference.
TDM: Time is divided into frames; each frame is subdivided into time slots. Each signal gets a specific time slot. Used in digital telephony (PCM).
FDM Concept
|───Signal A───|───Signal B───|───Signal C───|
(Frequency domain — each signal occupies different band)
5M
Describe guided transmission media (Twisted Pair, Coaxial Cable, Fiber Optic).
Twisted Pair: Two insulated copper wires twisted together. Categories: Cat-5 (100 Mbps), Cat-6 (1 Gbps). Advantages: cheap, easy installation. Disadvantages: attenuation, EMI.
Coaxial Cable: Central conductor surrounded by insulator, shield, and outer cover. Used in cable TV. Better shielding than twisted pair, higher bandwidth.
Optical Fiber: Glass/plastic core carries light pulses. Single-mode (long distance, narrow core) vs Multi-mode (short distance, wider core). Advantages: extremely high bandwidth, no EMI, low attenuation. Disadvantages: expensive, fragile.
5M
Explain Circuit Switching, Message Switching, and Packet Switching.
Circuit Switching: A dedicated path is established before data transfer (telephone network). Advantages: guaranteed bandwidth, low delay. Disadvantages: inefficient for bursty data.
Message Switching: Entire message is stored at each node (store-and-forward). Used in email. No dedicated path. Disadvantages: slow, requires large buffers.
Packet Switching: Message is divided into packets. Each packet routed independently. Two approaches: Datagram (each packet independent, may take different paths) and Virtual Circuit (path established before transfer like circuit, but packets follow same path). Used in the Internet.
5M
Compare guided and unguided transmission media with examples.
| Feature | Guided Media | Unguided Media |
| Medium | Physical cables | Atmosphere/Space |
| Examples | Twisted pair, Coax, Fiber | Radio, Microwave, Infrared, Satellite |
| Security | High (hard to tap) | Low (easily intercepted) |
| Bandwidth | Very high (especially fiber) | Limited |
| Cost | Higher installation cost | Lower installation, high spectrum licensing |
15-Mark Questions
15-Mark
15M
Describe the OSI reference model in detail. Explain the functions of each layer and how data flows through the model. Also compare with TCP/IP model.
The OSI (Open Systems Interconnection) Reference Model has 7 layers organized from physical hardware to application software:
1. Physical Layer: Defines electrical, mechanical, procedural specs for activating/maintaining the physical link. Concerned with bits, data rate, physical topology, transmission mode. Devices: hubs, repeaters. Protocols: Ethernet physical, USB.
2. Data Link Layer: Responsible for node-to-node delivery, framing, physical addressing, error control, flow control. Sublayers: LLC (Logical Link Control) and MAC (Media Access Control). Devices: switches, bridges. Protocols: Ethernet, PPP, HDLC.
3. Network Layer: Responsible for source-to-destination delivery across multiple networks. Handles logical addressing, routing. Devices: routers. Protocols: IP, ICMP, ARP, OSPF, BGP.
4. Transport Layer: Provides end-to-end delivery, ensures complete data transfer. Services: TCP (reliable, connection-oriented), UDP (unreliable, connectionless). Port numbers used for process-to-process delivery.
5. Session Layer: Establishes, manages, and terminates sessions between applications. Handles dialog control (half/full duplex) and synchronization with checkpoints.
6. Presentation Layer: Handles data translation, encryption/decryption, compression/decompression. Ensures data from source is readable by destination application.
7. Application Layer: Closest to end user. Provides network services to applications. Protocols: HTTP, FTP, SMTP, DNS, Telnet.
Data Encapsulation Flow:
At sender: Application → Session adds header → Presentation → Transport adds TCP/UDP header → Network adds IP header → Data Link adds frame header/trailer → Physical converts to bits.
At receiver: reverse process — de-encapsulation layer by layer.
| OSI Layer | TCP/IP Layer | Key Protocols |
| Application | Application | HTTP, FTP, SMTP, DNS |
| Presentation | SSL/TLS, MIME |
| Session | NetBIOS, RPC |
| Transport | Transport | TCP, UDP, SCTP |
| Network | Internet | IP, ICMP, ARP, OSPF |
| Data Link + Physical | Network Interface | Ethernet, Wi-Fi, PPP |
Key Difference: TCP/IP is protocol-independent in design; OSI is model-first. TCP/IP has no separate Session/Presentation layers.
15M
Discuss transmission media in detail. Classify and explain guided and unguided media with their characteristics, advantages, and disadvantages. [2022]
GUIDED TRANSMISSION MEDIA
1. Twisted Pair Cable:
— Two insulated copper wires twisted to reduce crosstalk/EMI
— UTP (Unshielded) vs STP (Shielded)
— Categories: Cat-3 (10 Mbps), Cat-5 (100 Mbps), Cat-5e (1 Gbps), Cat-6 (10 Gbps)
— Used in: Ethernet LANs, telephone lines
— Advantages: Cheapest, easy to install, flexible
— Disadvantages: High attenuation, susceptible to EMI, low bandwidth compared to fiber
2. Coaxial Cable:
— Central copper conductor + dielectric insulator + metallic shield + plastic cover
— 50-ohm (baseband) and 75-ohm (broadband) variants
— Used in: Cable TV, broadband Internet
— Advantages: Higher bandwidth than twisted pair, better shielding
— Disadvantages: Thick, heavy, more expensive
3. Optical Fiber:
— Core (glass/plastic) + cladding (lower refractive index) + protective coating
— Total internal reflection carries light pulses
— Single-mode: 8-10 µm core, laser source, long distance (km), low attenuation
— Multi-mode: 50-62.5 µm core, LED source, short distance (<2 km)
— Used in: Backbone networks, undersea cables, high-speed LANs
— Advantages: Highest bandwidth (Tbps), no EMI, low loss, secure, lightweight
— Disadvantages: Expensive, requires skilled installation, fragile
UNGUIDED TRANSMISSION MEDIA
1. Radio Waves: 3 kHz – 1 GHz. Omni-directional. Penetrate walls. Used in AM/FM radio, Wi-Fi (2.4 GHz), cordless phones.
2. Microwaves: 1 GHz – 300 GHz. Directional (require line-of-sight). Parabolic dishes. Used in satellite communication, cellular backhaul.
3. Infrared: 300 GHz – 400 THz. Very short range, line-of-sight. Used in TV remotes, IrDA, IR data association.
4. Satellite Communication: Uses geostationary satellites (36,000 km). Covers large areas. Latency ~270 ms due to distance.
5M
Explain CRC error detection with a numerical example. Show encoding and decoding steps.
CRC Encoding Steps:
1. Choose a generator polynomial G(x). E.g., G(x) = x³ + x + 1 → binary 1011 (degree 3, so append 3 zero bits).
2. Multiply data by 2^r (append r zeros).
3. Divide by G(x) using binary modulo-2 division (XOR instead of subtraction).
4. Remainder = CRC bits. Append to original data.
Example: Data = 10110011, G(x) = 1011
5M
Explain Hamming Code for error correction with a numerical example.
Hamming Code can detect and correct single-bit errors. Redundant bits (r) are placed at positions 2^0, 2^1, 2^2, ... Each redundant bit checks specific data bits.
Formula: 2^r ≥ m + r + 1 (where m = data bits, r = redundant bits)
Example: Encode 1011 using Hamming Code
5M
Explain the Go-Back-N ARQ protocol with sequence diagram.
Go-Back-N ARQ allows the sender to have up to N unacknowledged frames (window size N). If a frame is lost or damaged, the receiver discards that frame and all subsequent frames (even if correctly received). The sender must retransmit from the errored frame onwards ("go back").
Go-Back-N Sequence Diagram
Sender: |Frame 0|Frame 1|Frame 2|Frame 3|Frame 2|Frame 3|
Receiver: |—ACK 0—|—ACK 1—|—Discard—|—Discard—|
(Frame 2 lost → ACK 2 never received → Sender times out → retransmits Frame 2 & 3)
5M
Explain CSMA/CD with its algorithm steps.
CSMA/CD (Carrier Sense Multiple Access with Collision Detection) is the MAC protocol for Ethernet LANs:
Algorithm:
1. Listen: Station checks if the channel is idle or busy.
2. Transmit if idle: If idle, station begins transmitting.
3. Monitor: While transmitting, station continues to listen for collisions.
4. Collision detected: If collision is detected, station immediately stops transmitting and sends a jam signal (48 bits) to ensure all stations detect the collision.
5. Backoff: Station waits for a random time using Binary Exponential Backoff — K = min(N, 10) attempts, random delay from 0 to 2^K-1 × 2τ.
6. Retry: After backoff, go back to step 1. After 16 failed attempts, give up.
Minimum Frame Size: Frame must be long enough to detect collision. Minimum frame transmission time ≥ 2τ (round-trip propagation delay). For 10 Mbps Ethernet: minimum frame = 512 bits (64 bytes).
15-Mark Questions
15-Mark
15M
Describe the Ethernet standards and MAC sublayer in detail. Explain CSMA/CD, frame format, and Gigabit Ethernet. [2023]
ETHERNET OVERVIEW: Ethernet (IEEE 802.3) is the most widely used LAN technology. It uses CSMA/CD for half-duplex and full-duplex switching for modern networks.
EVOLUTION OF ETHERNET STANDARDS:
| Standard | Speed | Cable | Max Distance | Topology |
| 10BASE-T | 10 Mbps | UTP Cat-3/5 | 100 m | Star (hub) |
| 10BASE-F | 10 Mbps | Fiber | 2 km | Star |
| 100BASE-TX | 100 Mbps | UTP Cat-5 | 100 m | Star (switch) |
| 100BASE-FX | 100 Mbps | Fiber | 2 km | Star |
| 1000BASE-T | 1 Gbps | UTP Cat-5e/6 | 100 m | Star |
| 1000BASE-SX | 1 Gbps | Fiber (MMF) | 550 m | Star |
| 10GBASE-T | 10 Gbps | UTP Cat-6a/7 | 100 m | Star |
MAC SUBLAYER:
The MAC sublayer (Media Access Control) is the lower sublayer of the Data Link Layer. It provides:
— Addressing (6-byte MAC addresses)
— Media access control (who can transmit)
— Frame delimiting and synchronization
— Error detection (CRC in trailer)
ETHERNET FRAME FORMAT (IEEE 802.3):
| Field | Size | Purpose |
| Preamble | 7 bytes | 10101010 pattern for clock sync |
| SFD (Start Frame Delimiter) | 1 byte | 10101011 — marks frame start |
| Destination MAC | 6 bytes | Receiver's MAC address |
| Source MAC | 6 bytes | Sender's MAC address |
| Length/Type | 2 bytes | Payload length or EtherType |
| Payload (Data) | 46–1500 bytes | Upper layer data |
| Padding | 0–46 bytes | Fills to minimum 64-byte frame |
| FCS (CRC) | 4 bytes | Error detection checksum |
CSMA/CD Detailed Operation:
1. Carrier Sense: Check channel before transmitting
2. Multiple Access: Multiple stations share same medium
3. Collision Detection: If two stations transmit simultaneously, signals collide and both detect it
4. Jam Signal: 48-bit jam signal ensures all stations detect collision
5. Binary Exponential Backoff: Random wait time doubles with each collision
GIGABIT ETHERNET (1000BASE-T):
— Uses all four twisted pairs simultaneously (full-duplex)
— Encoding: 5-level PAM (Pulse Amplitude Modulation) at 125 MBd → 1 Gbps
— Uses 4D-PAM5 encoding
— No CSMA/CD needed in full-duplex mode (switched networks)
— Minimum frame size still 64 bytes (with carrier extension in half-duplex)
15M
Compare Go-Back-N and Selective Repeat ARQ protocols. Explain sliding window concept with diagrams.
| Feature | Go-Back-N ARQ | Selective Repeat ARQ |
| Sender Window | 2^(m-1) frames | 2^(m-1) frames |
| Receiver Window | 1 frame | 2^(m-1) frames |
| On Error | Retransmit from errored frame onwards | Retransmit only errored frame |
| Receiver Buffering | None — discards out-of-order frames | Buffers out-of-order frames |
| Efficiency | Lower (wastes bandwidth) | Higher (selective retransmit) |
| Complexity | Simpler | More complex (needs buffering) |
| ACK Type | Cumulative ACK | Individual ACK per frame |
| Suitability | Low error rate channels | High error rate channels |
Sliding Window Concept:
The sliding window protocol allows multiple frames to be "in flight" simultaneously. The sender maintains a window of sequence numbers. As each ACK arrives, the window slides forward, allowing the next frame to be sent.
Selective Repeat — Sender & Receiver Windows
Sender Window (size 4): [0, 1, 2, 3] → slides right on each ACK
Receiver Window (size 4): [0, 1, 2, 3] → accepts frames within window
If Frame 2 is lost: Receiver buffers 3, 4. Sender retransmits only 2.
After 2 received: receiver delivers 2, 3, 4 in order to network layer.
↻
Quick Revision
Quick Revision: Network Layer handles routing and forwarding of packets across multiple networks. Key topics: IPv4 addressing & subnetting, IPv6, routing algorithms (distance vector, link state, path vector), ARP/RARP, ICMP, NAT, DHCP, and network devices.
1-Mark Questions
1-Mark
1M
What is IPv4? How many bits is an IPv4 address?
IPv4 (Internet Protocol version 4) uses 32-bit addresses written in dotted decimal notation (e.g., 192.168.1.1). It provides ~4.3 billion unique addresses.
1M
What are the IPv4 address classes?
Class A: 0xxxxxxx (1.0.0.0 – 126.255.255.255) /8, 16.7M hosts
Class B: 10xxxxxx (128.0.0.0 – 191.255.255.255) /16, 65K hosts
Class C: 110xxxxx (192.0.0.0 – 223.255.255.255) /24, 254 hosts
Class D: 1110xxxx (224.0.0.0 – 239.255.255.255) — Multicast
Class E: 1111xxxx (240.0.0.0 – 255.255.255.255) — Reserved
1M
What is Subnetting?
Subnetting divides a large network into smaller logical sub-networks (subnets) by borrowing bits from the host portion of the IP address. Benefits: reduced traffic, easier management, improved security.
1M
What is CIDR?
CIDR (Classless Inter-Domain Routing) represents IP addresses as a prefix (e.g., 192.168.1.0/24). It eliminates class boundaries and allows flexible allocation of address blocks. Notation: IP address / prefix length.
1M
What is VLSM?
VLSM (Variable Length Subnet Mask) allows different subnets to use different subnet masks within the same network. Enables efficient IP address allocation by using smaller subnets where fewer hosts are needed.
1M
What is IPv6?
IPv6 uses 128-bit addresses (written in hexadecimal groups, e.g., 2001:0db8:85a3::8a2e:370:7334). Provides ~3.4 × 10^38 addresses. Built-in IPSec, simplified header, no broadcast (uses multicast/anycast).
1M
What is ARP?
ARP (Address Resolution Protocol) maps a known IPv4 address to its MAC address. When a host needs to send a packet, it broadcasts an ARP request asking "Who has IP X.X.X.X? Tell Y.Y.Y.Y". The owner replies with its MAC address.
1M
What is RARP?
RARP (Reverse ARP) maps a known MAC address to its IP address. Used by diskless workstations at boot time to discover their own IP address. Largely replaced by BOOTP and DHCP.
1M
What is ICMP?
ICMP (Internet Control Message Protocol) is used for diagnostic and error-reporting in IP networks. Tools: ping (ICMP Echo Request/Reply), traceroute (ICMP Time Exceeded). ICMP messages include Destination Unreachable, Time Exceeded, Redirect, etc.
1M
What is NAT?
NAT (Network Address Translation) translates private IP addresses to public IP addresses (and vice versa) at the router. Types: Static NAT (1:1 mapping), Dynamic NAT (pool of public IPs), PAT (Port Address Translation / NAT Overload — multiple private IPs share one public IP using different port numbers).
1M
What is DHCP?
DHCP (Dynamic Host Configuration Protocol) automatically assigns IP addresses and network configuration to hosts. Uses DORA process: Discover → Offer → Request → Acknowledge. Port 67 (server), Port 68 (client).
1M
Name the network devices at each layer.
Physical Layer: Repeater, Hub (regenerate signals, broadcast to all ports)
Data Link Layer: Bridge, Switch (filter by MAC address, forward to correct port)
Network Layer: Router (forward packets based on IP address, connect different networks)
Application Layer: Gateway (protocol conversion between different network architectures)
1M
What is a default gateway?
The Default Gateway is the IP address of the router that a host uses to send packets to destinations outside its local network. It is the next hop for all packets not destined for the local subnet.
5-Mark Questions
5-Mark
5M
Explain Classful addressing and the need for CIDR with numerical examples.
Classful Addressing: IP addresses divided into 5 classes (A-E) with fixed boundaries. Problems:
— Class A wastes millions of addresses for small organizations
— Class C limited to 254 hosts
— No flexibility for medium-sized networks needing, say, 1000 hosts
CIDR Solution: Classless addressing using prefix notation. E.g., 200.10.5.0/23 gives 2^(32-23) = 512 addresses (510 usable).
CIDR Block Allocation Example:
5M
Perform subnetting for the network 200.10.5.0/24 to create 4 equal subnets. Show subnet masks, network addresses, and usable host ranges.
Given: Network = 200.10.5.0/24. Need 4 subnets.
Step 1: Borrow 2 bits from host portion (2^2 = 4 subnets).
Step 2: New prefix = /24 + 2 =
/26. Subnet mask = 255.255.255.192
Step 3: Calculate subnets (block size = 2^(32-26) = 64):
| Subnet | Network Address | First Usable | Last Usable | Broadcast |
| Subnet 0 | 200.10.5.0 | 200.10.5.1 | 200.10.5.62 | 200.10.5.63 |
| Subnet 1 | 200.10.5.64 | 200.10.5.65 | 200.10.5.126 | 200.10.5.127 |
| Subnet 2 | 200.10.5.128 | 200.10.5.129 | 200.10.5.190 | 200.10.5.191 |
| Subnet 3 | 200.10.5.192 | 200.10.5.193 | 200.10.5.254 | 200.10.5.255 |
Each subnet has 62 usable hosts (2^6 - 2 = 62).
5M
Describe the DHCP DORA process with a sequence diagram.
DHCP (Dynamic Host Configuration Protocol) automatically assigns IP addresses to hosts. The process is called
DORA:
1. Discover: Client broadcasts DHCPDISCOVER packet (src IP = 0.0.0.0, dest IP = 255.255.255.255) to find available DHCP servers.
2. Offer: DHCP server responds with DHCPOFFER containing available IP address, subnet mask, lease time, and other configuration.
3. Request: Client broadcasts DHCPREQUEST accepting the offered IP address. If multiple servers responded, this selects one.
4. Acknowledge: Server sends DHCPACK confirming the lease. Client now has a valid IP address and can communicate.
DHCP DORA Process
Client → Broadcast: DHCPDISCOVER
Server → Client: DHCPOFFER (IP: 192.168.1.100)
Client → Broadcast: DHCPREQUEST
Server → Client: DHCPACK (Lease confirmed, time: 86400s)
Lease renewal at T1 (50% of lease time) and T2 (87.5%)
Release: Client sends DHCPRELEASE when disconnecting.
5M
Explain IPv4 vs IPv6 — key differences and IPv6 address types.
| Feature | IPv4 | IPv6 |
| Address Length | 32 bits | 128 bits |
| Notation | Dotted decimal (192.168.1.1) | Hexadecimal groups (2001:db8::1) |
| Address Space | ~4.3 billion | ~3.4 × 10^38 |
| Header | 20-60 bytes (variable) | 40 bytes (fixed, simplified) |
| Fragmentation | Router & sender | Sender only |
| Checksum | Yes | No (removed) |
| Broadcast | Yes | No (uses multicast) |
| NAT | Required (address shortage) | Not needed |
| Security | Optional (IPSec) | Built-in IPSec |
| Configuration | Manual or DHCP | Auto-configuration (SLAAC) |
IPv6 Address Types:
—
Unicast: One-to-one communication (2001:db8::1)
—
Multicast: One-to-many (ff02::1 — all nodes on link)
—
Anycast: One-to-nearest (multiple interfaces share same address, nearest one responds)
—
Link-local: fe80::/10 (auto-assigned on each interface, not routable)
—
Global unicast: 2000::/3 (routable on the Internet)
15-Mark Questions
15-Mark
15M
Explain subnetting in detail with worked numerical examples for Class A, B, and C networks. Include CIDR and VLSM. [2023]
SUBNETTING — COMPLETE THEORY
Subnetting divides a large IP network into smaller subnets by borrowing bits from the host portion. It improves efficiency, security, and manageability.
Formulas:
— Number of subnets = 2^s (s = borrowed bits)
— Hosts per subnet = 2^h - 2 (h = remaining host bits; -2 for network & broadcast)
— Subnet mask: add 2^s to the default classful mask
Example 1: Class C Subnetting (206.100.10.0/24)
Need 4 subnets → s = 2 → new prefix = /26 → mask = 255.255.255.192
Block size = 2^(32-26) = 64
Subnets: 206.100.10.0/26, .64/26, .128/26, .192/26 → each has 62 usable hosts
Example 2: Class B Subnetting (172.16.0.0/16)
Need 8 subnets → s = 3 → new prefix = /19 → mask = 255.255.224.0
Block size = 2^(32-19) = 2048
Subnets: 172.16.0.0/19, .32.0/19, .64.0/19, … .224.0/19
Each has 2^(32-19) - 2 = 2046 usable hosts
Example 3: Class A Subnetting (10.0.0.0/8)
Need 512 subnets → s = 9 → new prefix = /17 → mask = 255.255.128.0
Block size = 2^(32-17) = 32768
Each subnet has 32766 usable hosts
VLSM (Variable Length Subnet Mask):
Different subnets use different mask lengths within the same network. Allows efficient address allocation.
VLSM Example: Network 200.10.0.0/24
15M
Describe routing algorithms in detail — Distance Vector (Bellman-Ford), Link State (Dijkstra/OSPF), and Path Vector (BGP). Compare them. [2022]
1. DISTANCE VECTOR ROUTING (Bellman-Ford / RIP)
— Each router maintains a routing table (destination, next hop, distance)
— Periodically exchanges entire routing table with neighbors
— Uses Bellman-Ford equation: D_x(y) = min{ C(x,v) + D_v(y) } for all neighbors v
— RIP (Routing Information Protocol): max hop count = 15 (16 = unreachable), update every 30s
—
Advantages: Simple, low overhead
—
Disadvantages: Slow convergence, count-to-infinity problem, routing loops, periodic updates waste bandwidth
2. LINK STATE ROUTING (Dijkstra / OSPF)
— Each router discovers neighbors, measures link costs (delay, bandwidth)
— Floods Link State Packets (LSP) to ALL routers in the area
— Each router builds complete topology map and runs Dijkstra's algorithm to compute shortest paths
— OSPF (Open Shortest Path First): uses areas, fast convergence, hierarchical
— Dijkstra: Finds shortest path tree from source to all destinations
—
Advantages: Fast convergence, no loops, scalable with areas
—
Disadvantages: Memory intensive (stores full map), CPU intensive (Dijkstra per update)
3. PATH VECTOR ROUTING (BGP)
— BGP (Border Gateway Protocol) is used between Autonomous Systems (ISPs)
— Each AS advertises reachable networks along with the path (AS sequence)
— Policies determine which paths to accept (not just shortest path)
— eBGP (between ASes) and iBGP (within an AS)
—
Advantages: Handles policy-based routing, scales to Internet size
—
Disadvantages: Slow convergence, complex configuration
| Feature | Distance Vector | Link State | Path Vector |
| Algorithm | Bellman-Ford | Dijkstra | BGP (policy-based) |
| Knowledge | Only neighbor info | Full topology map | Path info (AS sequence) |
| Updates | Periodic (whole table) | Triggered (LSP floods) | Incremental (path vectors) |
| Convergence | Slow (count-to-infinity) | Fast | Moderate |
| Memory | Low (one table) | High (topology map) | Moderate |
| Loops | Possible (split horizon helps) | No | Prevented by AS path |
| Scale | Small networks | Medium to large | Internet-scale (ASes) |
| Protocol | RIP | OSPF, IS-IS | BGP |
Port Numbers Reference Table
Port
| Protocol | Port | Protocol | Port |
| HTTP | 80 | HTTPS | 443 |
| FTP (control) | 21 | FTP (data) | 20 |
| SSH | 22 | Telnet | 23 |
| SMTP | 25 | DNS | 53 |
| DHCP (server) | 67 | DHCP (client) | 68 |
| TFTP | 69 | HTTP Alt | 8080 |
| POP3 | 110 | IMAP | 143 |
| SNMP | 161 | SNMP Trap | 162 |
| LDAP | 389 | SMTPS | 465 |
↻
Quick Revision
Quick Revision: Transport Layer provides end-to-end reliable data delivery between processes using port numbers. TCP is reliable/connection-oriented; UDP is unreliable/fast. Congestion control prevents network overload. QoS ensures adequate service for critical applications.
1-Mark Questions
1-Mark
1M
What is the role of the Transport Layer?
The Transport Layer provides process-to-process delivery (end-to-end) using port numbers. It handles segmentation, flow control, error control, and congestion control. Two main protocols: TCP and UDP.
1M
What is a port number?
A Port Number is a 16-bit identifier (0–65535) used by the Transport Layer to identify specific processes/applications. Range: 0–1023 (well-known), 1024–49151 (registered), 49152–65535 (dynamic/private).
1M
What is a socket?
A Socket is the combination of an IP address and a port number (e.g., 192.168.1.10:80). It uniquely identifies a process on a host: Socket = IP Address : Port Number.
1M
What is TCP?
TCP (Transmission Control Protocol) is a connection-oriented, reliable transport protocol. Provides: guaranteed delivery, sequencing, flow control, congestion control. Used by HTTP, FTP, SMTP, SSH.
1M
What is UDP?
UDP (User Datagram Protocol) is a connectionless, unreliable transport protocol. No connection setup, no guaranteed delivery, no sequencing. Used by DNS, VoIP, video streaming, online gaming — where speed matters more than reliability.
1M
What is the Three-Way Handshake?
The Three-Way Handshake establishes a TCP connection: (1) Client → SYN, (2) Server → SYN-ACK, (3) Client → ACK. Both sides agree on initial sequence numbers.
1M
What is Congestion Control?
Congestion Control prevents overwhelming the network with too much traffic. TCP uses: Slow Start, Congestion Avoidance, Fast Retransmit, and Fast Recovery. Monitors congestion window (cwnd) and slow start threshold (ssthresh).
1M
What is QoS?
QoS (Quality of Service) ensures adequate network performance for critical applications. Mechanisms: Traffic shaping (leaky bucket, token bucket), prioritization, resource reservation. Important for VoIP, video conferencing, and real-time systems.
1M
What is Flow Control?
Flow Control prevents a fast sender from overwhelming a slow receiver. TCP uses Sliding Window (receiver advertises its window size). Stop-and-Wait is the simplest flow control method.
1M
What is MSS?
MSS (Maximum Segment Size) is the maximum amount of data (in bytes) that TCP can deliver to the receiving TCP in one segment. MSS = MTU - 40 (TCP header 20 bytes + IP header 20 bytes). Default MSS = 536 bytes.
1M
What is the leaky bucket algorithm?
The Leaky Bucket algorithm shapes traffic by allowing data to enter at variable rates but exit at a fixed constant rate. If the bucket overflows, packets are discarded. Analogous to water leaking from a bucket at a steady rate.
5-Mark Questions
5-Mark
5M
Compare TCP and UDP in detail with a comparison table and suitable application examples for each.
| Feature | TCP | UDP |
| Connection | Connection-oriented (3-way handshake) | Connectionless |
| Reliability | Reliable (ACK, retransmission) | Unreliable (no ACK) |
| Flow Control | Yes (sliding window) | No |
| Congestion Control | Yes | No |
| Ordering | Guaranteed (sequencing) | Not guaranteed |
| Header Size | 20-60 bytes (complex) | 8 bytes (simple) |
| Speed | Slower (overhead) | Faster (minimal overhead) |
| Data Boundaries | Stream-oriented (no boundaries) | Message-oriented (preserves boundaries) |
| Retransmission | Yes (automatic) | No |
| Applications | Web (HTTP), Email (SMTP), File Transfer (FTP), SSH | DNS, VoIP, Video Streaming, Online Games, DHCP |
When to use TCP: When data integrity and delivery guarantee are critical (file transfers, email, web pages).
When to use UDP: When speed/latency is critical and some data loss is acceptable (live video, VoIP, gaming, DNS queries).
5M
Explain TCP congestion control mechanisms: Slow Start, Congestion Avoidance, Fast Retransmit, and Fast Recovery.
TCP Congestion Control prevents the sender from overwhelming the network. It uses two variables:
cwnd (congestion window — sender's estimate of available network capacity) and
ssthresh (slow start threshold).
1. SLOW START:
— Initially cwnd = 1 MSS
— For each ACK received, cwnd increases by 1 MSS (exponential growth)
— cwnd doubles each RTT: 1 → 2 → 4 → 8 → 16 …
— When cwnd ≥ ssthresh, transition to Congestion Avoidance
2. CONGESTION AVOIDANCE:
— cwnd grows slowly (additive): cwnd = cwnd + 1/cwnd per ACK
— Effectively cwnd increases by ~1 MSS per RTT (linear growth)
— Continues until congestion detected (timeout or 3 duplicate ACKs)
3. FAST RETRANSMIT:
— If sender receives 3 duplicate ACKs, it assumes a packet is lost
— Retransmits the missing segment WITHOUT waiting for timeout
— Sets ssthresh = cwnd / 2, cwnd = ssthresh + 3 (enters Fast Recovery)
4. FAST RECOVERY:
— For each additional duplicate ACK, cwnd += 1 MSS (inflate window)
— When new ACK arrives (indicating some data got through), set cwnd = ssthresh
— If timeout occurs: more severe — ssthresh = cwnd/2, cwnd = 1, restart Slow Start
TCP Congestion Control — cwnd Growth Pattern
Slow Start (exponential): cwnd: 1 → 2 → 4 → 8 → 16 → 32 → 64
Congestion Avoidance (linear): 64 → 65 → 66 → 67 → 68 → 69 …
On 3 dupACKs: ssthresh = cwnd/2, cwnd = ssthresh + 3
On Timeout: ssthresh = cwnd/2, cwnd = 1 (restart Slow Start)
5M
Explain the TCP Three-Way Handshake and Four-Way Termination with sequence diagrams.
THREE-WAY HANDSHAKE (Connection Establishment):
Client → Server: SYN (seq = x, ISN_x)
Server → Client: SYN-ACK (seq = y, ISN_y; ack = x+1)
Client → Server: ACK (seq = x+1; ack = y+1)
Connection ESTABLISHED — data transfer begins
Both sides exchange Initial Sequence Numbers (ISNs). ISN should be random for security (prevents TCP sequence prediction attacks).
FOUR-WAY TERMINATION (Connection Release):
Since TCP is full-duplex, each direction must be closed independently:
Client → Server: FIN (seq = u) — "I'm done sending"
Server → Client: ACK (ack = u+1) — "Got your FIN"
[Server can still send data to Client — half-closed state]
Server → Client: FIN (seq = v) — "I'm done too"
Client → Server: ACK (ack = v+1) — "Got your FIN"
Connection CLOSED after TIME_WAIT (2MSL)
TIME_WAIT (2MSL): After sending final ACK, client waits 2 × Maximum Segment Lifetime (typically 2 minutes) to ensure the last ACK was received. Prevents delayed duplicates from confusing a new connection.
5M
Explain Leaky Bucket and Token Bucket algorithms for traffic shaping.
1. LEAKY BUCKET:
— Fixed output rate (like water leaking from a hole at constant rate)
— Input can be bursty, but output is uniform
— If bucket overflows, packets are discarded
— Used for: enforcing constant bit rate, smoothing traffic
—
Limitation: Cannot handle bursty traffic efficiently (drops bursts)
2. TOKEN BUCKET:
— Tokens accumulate at a fixed rate (r tokens/second) in a bucket of size b
— To send a packet, must consume 1 token per byte/packet
— If no tokens available, packet must wait or be discarded
— Allows bursts up to b tokens/packets
— More flexible than leaky bucket
Token Bucket — Burst Handling Example
Rate r = 1 token/ms, Bucket size b = 10 tokens
After 10ms of silence: 10 tokens accumulated
Can now send 10 packets instantly (burst of 10)
Then limited to 1 packet per ms (steady rate)
15-Mark Questions
15-Mark
15M
Describe the TCP header format in detail. Explain each field with its purpose and the Three-Way Handshake process with a timing diagram. [2023]
TCP HEADER FORMAT (20-60 bytes minimum):
| Field | Size | Purpose |
| Source Port | 16 bits | Sender's port number |
| Destination Port | 16 bits | Receiver's port number |
| Sequence Number | 32 bits | Byte number of first data byte in segment |
| Acknowledgment Number | 32 bits | Next expected byte (ACK = last received + 1) |
| Data Offset | 4 bits | Header length in 32-bit words (5 = 20 bytes) |
| Reserved | 3 bits | Reserved for future use (set to 0) |
| Flags (URG/ACK/PSH/RST/SYN/FIN) | 6 bits | Control flags (1 bit each) |
| Window Size | 16 bits | Receiver's available buffer (flow control) |
| Checksum | 16 bits | Error detection over pseudo-header + TCP segment |
| Urgent Pointer | 16 bits | Offset to urgent data (if URG flag set) |
| Options | 0-40 bytes | MSS, Window Scale, SACK, Timestamps |
TCP Flags Explained:
— SYN: Synchronize sequence numbers (connection request)
— ACK: Acknowledgment field is valid
— FIN: No more data from sender (close connection)
— RST: Reset the connection
— PSH: Push function — deliver data immediately
— URG: Urgent pointer is valid
THREE-WAY HANDSHAKE (Detailed):
TCP Connection Establishment (Three-Way Handshake)
Client (A) Server (B)
| |
|── SYN (seq=x) ──────────────→|
| | SYN_SENT → SYN_RCVD
|←── SYN-ACK (seq=y, ack=x+1) ─|
| |
|── ACK (seq=x+1, ack=y+1) ───→|
| | ESTABLISHED
|==== DATA TRANSFER ===========|
↻
Quick Revision
Quick Revision: Application Layer provides network services to end-user applications. Key protocols: HTTP/HTTPS (web), DNS (name resolution), SMTP/POP3/IMAP (email), FTP (file transfer), Telnet/SSH (remote login), SNMP (network management). Security: encryption, firewalls, SSL/TLS.
1-Mark Questions
1-Mark
1M
What is HTTP?
HTTP (HyperText Transfer Protocol) is the application layer protocol for the World Wide Web. Uses port 80 (HTTP) or 443 (HTTPS). It is stateless — each request is independent.
1M
What is HTTPS?
HTTPS (HTTP Secure) is HTTP over SSL/TLS. Uses port 443. Provides encryption, server authentication, and data integrity. Prevents eavesdropping and tampering.
1M
What is DNS?
DNS (Domain Name System) translates human-readable domain names (www.google.com) to IP addresses (142.250.185.14). Uses a hierarchical distributed database. Port 53 (TCP for zone transfers, UDP for queries).
1M
What is SMTP?
SMTP (Simple Mail Transfer Protocol) is used for sending emails between mail servers. Port 25 (plain), 465 (SMTPS/SSL), 587 (STARTTLS). Uses TCP (reliable delivery required).
1M
What is POP3?
POP3 (Post Office Protocol v3) is used by email clients to retrieve emails from a mail server. Downloads and typically deletes from server. Port 110 (plain), 995 (POP3S). Simple, offline access.
1M
What is IMAP?
IMAP (Internet Message Access Protocol) is a more advanced email retrieval protocol. Keeps emails on the server, allows multiple device access, supports folders. Port 143 (plain), 993 (IMAPS).
1M
What is FTP?
FTP (File Transfer Protocol) transfers files between client and server using two connections: Control (port 21, TCP) and Data (port 20, TCP). Modes: Active (server connects to client) and Passive (client connects to server).
1M
What is the difference between FTP Active and Passive modes?
Active FTP: Server connects to client's data port (problematic with firewalls/NAT). Passive FTP: Client connects to server's data port (better for firewalls/NAT — client initiates all connections).
1M
What is Telnet?
Telnet is a remote login protocol (port 23) that allows a user to log into a remote host and execute commands. It is unencrypted — all data including passwords is sent in plaintext. Replaced by SSH for security.
1M
What is SSH?
SSH (Secure Shell) is a secure remote login protocol (port 22). Provides encrypted communication, strong authentication (password + public key), and secure file transfer (SCP, SFTP). Replaces insecure Telnet and FTP.
1M
What is SNMP?
SNMP (Simple Network Management Protocol) is used for monitoring and managing network devices. Uses a manager-agent model. Port 161 (queries), 162 (traps). Versions: SNMPv1, SNMPv2c, SNMPv3 (with security).
1M
What is a Firewall?
A Firewall is a network security device that monitors and filters incoming/outgoing traffic based on predetermined security rules. Types: Packet Filter, Stateful Inspection, Application Proxy, Next-Generation Firewall (NGFW).
1M
What is SSL/TLS?
SSL (Secure Sockets Layer) and TLS (Transport Layer Security) are cryptographic protocols that provide secure communication over a network. TLS is the modern successor to SSL. They use asymmetric encryption for key exchange and symmetric encryption for data transfer.
5-Mark Questions
5-Mark
5M
Explain the DNS resolution process with a step-by-step example. Include recursive and iterative queries.
DNS Resolution Process: Converting www.example.com → IP address involves a hierarchical lookup through DNS servers.
DNS Resolution — Step by Step
1. Client queries Local DNS Server (recursive query)
2. Local DNS queries Root Server (iterative) → ".com" TLD servers
3. Local DNS queries .com TLD server (iterative) → "example.com" authoritative server
4. Local DNS queries example.com authoritative server → gets IP (93.184.216.34)
5. Local DNS returns IP to Client
6. Client connects to 93.184.216.34:80
5M
Compare POP3 and IMAP. Also explain SMTP mail delivery process.
| Feature | POP3 | IMAP |
| Port (plain) | 110 | 143 |
| Port (SSL) | 995 | 993 |
| Message Storage | Downloads to client, deletes from server | Keeps on server, syncs with client |
| Multi-device | No (email on one device) | Yes (sync across devices) |
| Folders | Limited (local only) | Full folder support on server |
| Offline Access | Yes (all mail downloaded) | Limited (needs connection for search) |
| Bandwidth | Less (downloads once) | More (syncs headers/body) |
SMTP Mail Delivery Process:
1. Sender's email client connects to sender's SMTP server (port 25/587)
2. Client sends MAIL FROM command (sender address)
3. Server responds 250 OK
4. Client sends RCPT TO (recipient addresses) — one per recipient
5. Server responds for each recipient
6. Client sends DATA command → server responds 354
7. Client sends email content → ends with <CRLF>.<CRLF>
8. Server queues email for delivery
9. Sender's server connects to recipient's SMTP server and transfers email
10. Recipient's server stores email in mailbox (user's inbox)
11. Recipient's email client uses POP3/IMAP to retrieve email
5M
Explain network security basics: encryption types, firewall types, and SSL/TLS handshake process.
ENCRYPTION TYPES:
1. Symmetric Encryption: Same key for encryption and decryption. Fast. Examples: AES (Advanced Encryption Standard, 128/256-bit), DES, 3DES, RC4.
2. Asymmetric Encryption: Public key + private key pair. Slower but solves key distribution problem. Examples: RSA (used in TLS), Diffie-Hellman (key exchange), ECC (Elliptic Curve).
3. Hashing: One-way function producing fixed-size digest. Used for integrity verification. Examples: MD5 (broken), SHA-1 (deprecated), SHA-256, SHA-3.
FIREWALL TYPES:
— Packet Filter: Examines IP headers and port numbers. Fast but stateless. Rules: Allow/Deny based on IP, port, protocol.
— Stateful Inspection: Tracks connection state (connection table). More secure — knows if packet belongs to an established connection.
— Application Proxy: Inspects application layer data. Acts as intermediary. Very secure but slow.
— NGFW: Combines stateful inspection with deep packet inspection, IDS/IPS, application awareness.
SSL/TLS HANDSHAKE (Simplified):
1. Client sends Client Hello (supported cipher suites, random nonce)
2. Server sends Server Hello (chosen cipher, certificate with public key, random nonce)
3. Client verifies certificate, generates pre-master secret, encrypts with server's public key → sends to server
4. Both sides derive session keys from pre-master secret + nonces
5. Encrypted communication begins (Finished messages confirm handshake)
15-Mark Questions
15-Mark
15M
Describe HTTP/HTTPS, DNS, and Email protocols (SMTP, POP3, IMAP) in detail. Explain how a web page is loaded step-by-step. [2023]
HTTP (HyperText Transfer Protocol):
— Application layer protocol (port 80), stateless, request-response model
— Request methods: GET, POST, PUT, DELETE, HEAD, OPTIONS, PATCH
— Response codes: 1xx (Info), 2xx (Success: 200 OK), 3xx (Redirect: 301, 302), 4xx (Client Error: 404 Not Found, 403 Forbidden), 5xx (Server Error: 500, 503)
— HTTP/1.1: persistent connections (keep-alive), pipelining
— HTTP/2: multiplexing, header compression, server push
— HTTP/3: QUIC over UDP (faster, lower latency)
HTTPS:
— HTTP over TLS/SSL. Port 443. Provides confidentiality, integrity, authentication.
— TLS Handshake: Negotiate cipher suite → Exchange certificates → Key exchange (ECDHE) → Derive session keys → Encrypted communication
DNS (Domain Name System):
— Hierarchical, distributed database for name-to-IP mapping
— Hierarchy: Root → TLD (.com, .org, .in) → Second-level (google.com) → Subdomain (mail.google.com)
— DNS uses UDP (port 53) for queries, TCP for zone transfers (large responses)
— Record types: A, AAAA, MX, CNAME, NS, PTR, TXT, SOA
EMAIL PROTOCOLS:
— SMTP (port 25/587): Push protocol for sending mail between servers
— POP3 (port 110/995): Pull protocol, downloads mail, removes from server
— IMAP (port 143/993): Pull protocol, syncs mail across devices, keeps on server
HOW A WEB PAGE LOADS (Step-by-Step):
1. User types https://www.example.com in browser
2. Browser checks DNS cache → if miss, queries OS resolver
3. OS sends DNS query to configured DNS server
4. DNS server returns IP (e.g., 93.184.216.34)
5. Browser opens TCP connection to port 443 (HTTPS)
6. TLS Handshake: certificate exchange, key agreement
7. Browser sends HTTP GET request (encrypted)
8. Server processes request, sends HTTP 200 OK + HTML content
9. Browser parses HTML, discovers CSS/JS/image URLs
10. Browser sends additional HTTP requests for each resource (parallel, HTTP/2 multiplexed)
11. Server responds with CSS, JS, images
12. Browser renders complete page
15M
Explain FTP and its modes (Active vs Passive). Describe Telnet, SSH, and SNMP. Also discuss network security fundamentals including encryption, firewalls, and the SSL/TLS handshake. [2022]
FTP (File Transfer Protocol):
— Application layer protocol (RFC 959) for transferring files
— Uses TWO connections:
• Control Connection: TCP port 21 (commands/responses throughout session)
• Data Connection: TCP port 20 (actual file transfer)
— Modes:
• Active Mode: Client sends PORT command telling server its listening port. Server connects to client on that port for data. Problem: Client behind firewall blocks incoming connections from server.
• Passive Mode (PASV): Server sends PASV response with its port number. Client initiates data connection to server's port. Solution: Works through firewalls since client initiates all connections.
— Anonymous FTP: Login with username "anonymous" and email as password.
— Commands: USER, PASS, LIST, RETR, STOR, DELE, QUIT
TELNET:
— Remote terminal protocol (port 23, TCP)
— Provides character-based terminal emulation
— Completely unencrypted — passwords and data sent in plaintext
— Replaced by SSH for all secure remote access
SSH (Secure Shell):
— Secure remote login and command execution (port 22, TCP)
— Provides: encrypted communication, host authentication, user authentication
— Authentication methods: password, public key (RSA/ECDSA), keyboard-interactive
— Features: X11 forwarding, port forwarding/tunneling, SFTP
— SSH-1 (obsolete), SSH-2 (current standard)
SNMP (Simple Network Management Protocol):
— Used for monitoring and managing network devices (routers, switches, servers)
— Three components: Manager (NMS), Agent (software on device), Management Information Base (MIB — database of managed objects)
— Port 161 (Get/Set requests), Port 162 (Traps — unsolicited alerts)
— Versions: SNMPv1 (basic, no security), SNMPv2c (community-based, bulk retrieval), SNMPv3 (user-based authentication, encryption, integrity)
— Operations: GET, GETNEXT, SET, GETBULK, INFORM, TRAP
NETWORK SECURITY FUNDAMENTALS:
Encryption:
— Symmetric (AES-256): Fast, same key for encrypt/decrypt. Problem: key distribution.
— Asymmetric (RSA-2048, ECC): Public key encrypts, private key decrypts. Solves key distribution. Slower.
— Hash Functions (SHA-256): One-way, verify integrity. Digital signatures combine hashing + asymmetric encryption.
Firewalls:
— Packet Filter: Simple rules (IP, port, protocol). Stateless. Fast but limited security.
— Stateful Inspection: Tracks connections. Knows if packet is part of established connection.
— Application Proxy: Inspects payload at application layer. Very secure, acts as intermediary.
— NGFW: Next-gen with deep packet inspection, IDS/IPS, application control, sandboxing.
SSL/TLS Handshake (Full Process):
1. Client Hello: TLS version, cipher suites, random number
2. Server Hello: Selected cipher, server certificate (X.509), random number
3. Client verifies certificate against CA trust store
4. Client generates pre-master secret, encrypts with server's public key → sends
5. Server decrypts with private key → both now have pre-master secret
6. Both derive session keys (encryption + MAC keys) from pre-master + nonces
7. Client sends Finished (encrypted with session key)
8. Server sends Finished (encrypted with session key)
9. Encrypted application data transfer begins