DevOps Hub/Networking Lab
All systems operational
Networking Lab/Packet path briefing
Online

Learn by tracing / build real instincts

Read the path a packet takes.

Build a working mental model from address space to traffic decisions. Practice subnetting, forwarding, policy, wireless, and diagnosis in the same order a real network reveals them.

Start with foundations23 modules / 4 stages
IPv4CIDRRoutingWi-FiContainers

Live topology

Packet path

Online / 23 labs
01CLIENTorigin
02SUBNETscope
03ROUTERnext hop
04SERVICEdestination
Focus

Scope → decision

Next signal

CIDR /24

23

interactive labs

04

learning stages

01

prerequisite path

Learning path / 04 stages

Move from address space to traffic decisions

Each stage narrows the distance between a prefix on paper and a packet making a production decision. Start at the left, or jump to the signal you need.

01 · Foundations7 Modules

Networking Foundations

Start with how hosts, bits, prefixes, and subnet boundaries work; then calculate and design IPv4 address space before moving on.

#basics

1. What is a Subnet?

A subnet (subnetwork) is a logical subdivision of an IP network. A prefix and mask define which addresses are on the local IP network and which destinations require a router. In common designs, each subnet is mapped to a VLAN or other Layer 2 segment, while routing and policy controls determine whether subnets can communicate.

⚡

Performance & Traffic Control

Switches and VLANs define the Layer 2 broadcast domain. Subnet boundaries give hosts an IP-level on-link scope, so ARP and DHCP broadcasts normally stay within the associated segment.

Broadcast ScopeNormally Local
🛡️

Enhanced Security Isolation

Subnetting provides an addressing boundary; it does not enforce security by itself. Firewalls, ACLs, routing policy, and identity controls must explicitly restrict access between sensitive and less-trusted networks.

Access ControlL3 ACL / Firewall
📐

Logical Addressing & Scale

A deliberate addressing hierarchy supports IPAM, route summarization, and predictable growth across buildings, sites, or cloud regions.

IP ArchitectureStructured Hierarchy
SIGNAL / WORKED EXAMPLE

Network Topology Example: 192.168.1.0/24 Subnet Partitioning

A single private /24 CIDR block divided into 3 functional subnets with a central Layer 3 gateway router.

Core Gateway Router
VLAN 10 gateway192.168.1.1/26
VLAN 20 gateway192.168.1.65/26
VLAN 30 gateway192.168.1.129/25
One routed gateway interface per VLAN
Subnet AVLAN 10

Management & Admin

192.168.1.0 / 26
Mask:255.255.255.192
Usable IPs:.1 — .62 (62 hosts)
Gateway:192.168.1.1
Admin Workstation (192.168.1.10)
Core Switch Mgmt (192.168.1.2)
NAS Backup Vault (192.168.1.15)
Subnet BVLAN 20

Staff Workstations

192.168.1.64 / 26
Mask:255.255.255.192
Usable IPs:.65 — .126 (62 hosts)
Gateway:192.168.1.65
Office PC-01 (192.168.1.70)
Dev Laptop-04 (192.168.1.85)
VoIP Desk Phone (192.168.1.90)
Subnet CVLAN 30

IoT & Guest Wi-Fi

192.168.1.128 / 25
Mask:255.255.255.128
Usable IPs:.129 — .254 (126 hosts)
Gateway:192.168.1.129
Smart TV (192.168.1.135)
Guest Phone (192.168.1.142)
IP Security Camera (192.168.1.200)
Total IPs: 256
#binary

2. IP Addresses & Binary

Every IPv4 address is a 32-bit binary number represented in 4 decimal octets separated by dots. Understanding bit values, positional binary weights (128, 64, 32, 16, 8, 4, 2, 1), and bitwise operations is fundamental to networking.

Live 4-Octet Decimal to Binary Converter

Enter values from 0 to 255 for each octet to visualize their 8-bit binary representation in real time.

192.168.1.100
Octet 1: 192
128
1
64
1
32
0
16
0
8
0
4
0
2
0
1
0
Octet 2: 168
128
1
64
0
32
1
16
0
8
1
4
0
2
0
1
0
Octet 3: 1
128
0
64
0
32
0
16
0
8
0
4
0
2
0
1
1
Octet 4: 100
128
0
64
1
32
1
16
0
8
0
4
1
2
0
1
0
Full 32-Bit Binary Representation:11000000 . 10101000 . 00000001 . 01100100

IPv4 Address Anatomy: Network ID vs Host ID

A subnet mask divides an IPv4 address into a network prefix and host portion. Hosts use this relationship to decide whether a destination is on-link; routers use destination prefixes during route lookup to choose a next hop.

Bit 1← Network Prefix Bits (1s in Mask) →← Host Suffix Bits (0s in Mask) →Bit 32
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
0
0
0
0
0
0
0
0
24 Network Bits (e.g. /24 Subnet)8 Host Bits (2 to the 8th power minus 2 equals 254 hosts)

RFC 1918 Private IPv4 Ranges

RFC 1918 designates three IPv4 blocks for private internets. The addresses may be reused by different organizations, and routing information for them should not cross inter-enterprise links.

ClassCIDR BlockIP Address RangeTotal AddressesTypical Application
10/8 block10.0.0.0 / 810.0.0.0 — 10.255.255.25516,777,216Enterprise networks and cloud VPCs
172.16/12 block172.16.0.0 / 12172.16.0.0 — 172.31.255.2551,048,576Enterprise networks and container bridges
192.168/16 block192.168.0.0 / 16192.168.0.0 — 192.168.255.25565,536Home, SOHO, and local networks

Classful vs CIDR Addressing

Historical Classful routing forced rigid network boundaries, leading to rapid IP address exhaustion. CIDR (Classless Inter-Domain Routing) introduced variable-length prefix masks.

FeatureLegacy Classful Routing (Historical)Modern CIDR (RFC 1519, obsoleted by RFC 4632)
Mask AllocationFixed class boundaries (/8, /16, /24)Any prefix from /0 to /32
Routing Protocol SupportRIPv1 and IGRP used classful updates (historical)OSPF, BGP4, RIPv2, and IS-IS carry prefix information
IP Utilization EfficiencyOften wasteful for networks smaller than a class boundaryVLSM enables subnet sizing to match requirements
Route Table AggregationLimited to classful boundariesSupports arbitrary aligned CIDR summaries
127.0.0.0 / 8

Loopback Address Space

Reserved for host-internal network stack testing (127.0.0.1 / localhost). Traffic sent to loopback is handled by the host and does not reach a physical interface or switch port.

ping 127.0.0.1 → Tests local TCP/IP protocol stack functionality
169.254.0.0 / 16

IPv4 Link-Local (APIPA)

A host may self-configure an IPv4 link-local address when no routable configuration is available. RFC 3927 limits communication to the same physical or logical link; it is not an Internet-routable fallback.

Usable selection space: 169.254.1.0 — 169.254.254.255 (excluding the first and last /24 portions)

Bitwise AND Operation: Calculating Network Address

A bitwise AND between an IPv4 address and its subnet mask produces the address of the containing subnet. Hosts and routing software use this calculation when determining local scope and route matches.

Host IP (192.168.1.100):11000000 . 10101000 . 00000001 . 01100100
Subnet Mask (255.255.255.0):11111111 . 11111111 . 11111111 . 00000000
AND OPERATOR (1 AND 1 = 1, ALL OTHER COMBINATIONS = 0)
Network ID (192.168.1.0):11000000 . 10101000 . 00000001 . 00000000
#cidr

3. CIDR & Subnet Masks — Interactive

CIDR (Classless Inter-Domain Routing) specifies how many leading bits in an IP address represent the network prefix. Adjust the slider or click any bit box below to interactively observe how changing prefix length affects subnet mask, bit allocation, total addresses, and usable host count.

Subnet Mask Bit Allocator

Selected Prefix: /24 (24 Network Bits, 8 Host Bits)

/0 (Default Route)/24 Prefix/32 (1 Host Route)
← 24 Blue Network Bits (1)8 Green Host Bits (0) →
Octet 1255
Octet 2255
Octet 3255
Octet 40
Subnet Mask
255.255.255.0
Equivalent to /24 CIDR prefix
Total IP Addresses
256
28 addresses (32 minus 24 network bits)
Usable Host IPs
254
Excludes network and broadcast addresses
Wildcard Mask (ACL)
0.0.0.255
Inverted subnet mask (255 minus each mask octet)
SIGNAL / WORKED EXAMPLE

Usable Hosts Calculation Formula: 2h - 2

For an IPv4 subnet, use Usable Hosts = 2h - 2, where h = 32 - CIDR is the number of host bits.

Why subtract 2 addresses?
1. Network Address (All Host Bits = 0)The first IP address in the range identifies the subnet block itself in routing tables and cannot be assigned to an interface.
2. Directed Broadcast (All Host Bits = 1)The last address in a conventional IPv4 subnet is the directed-broadcast address. Hosts and routers may filter directed broadcasts, so it is not a universal guarantee of delivery.
Step-by-Step for /24:
1. Host bits = 32 - 24 = 8
2. Total addresses = 28 = 256
3. Reserve the network and broadcast addresses:
256 - 2 = 254 usable hosts
#calculator

4. Subnet Calculator

Enter an IPv4 address and select a CIDR prefix length to calculate subnet or route boundaries, usable address ranges, and subnet masks in real time.

Network Address
192.168.1.0/24
Subnet identifier (all host bits = 0)
Broadcast Address
192.168.1.255
Subnet broadcast target (all host bits = 1)
First Usable Host
192.168.1.1
First assignable host IP in range
Last Usable Host
192.168.1.254
Last assignable host IP in range
Subnet Mask
255.255.255.0
Subnet mask in dotted-decimal format
Usable Hosts
254
Total assignable host IP addresses

Common Subnet Quick Reference

CIDRSubnet MaskUsable HostsTypical Use
/16255.255.0.065,534Large Enterprise / Cloud VPC
/24255.255.255.0254Standard Local Subnet (LAN / Office)
/25255.255.255.128126Medium Department (100+ devices)
/26255.255.255.19262Small Department / Server Rack
/27255.255.255.22430Branch Office / Small Workgroup
/28255.255.255.24014Management Network / DMZ Subnet
/30255.255.255.2522Point-to-Point Router Link
/31255.255.255.2542RFC 3021 Point-to-Point Link (both endpoints usable)
/32255.255.255.2551Host Route (one endpoint)
#create

5. Creating Subnets on Your Local Network

Building custom subnets on a local area network requires methodical planning and accurate configuration across your gateway router, managed switches, and endpoint operating systems. Follow this 4-step workflow to partition and verify your subnets.

01Architecture & Sizing

Step 1: Plan Address Space & CIDR Blocks

Select a private RFC 1918 base network (e.g. 192.168.0.0/16) and divide it into subnets based on required host capacity and isolation goals.

VLAN 10 (Staff):192.168.10.0/24 (254 hosts)
VLAN 20 (Guest):192.168.20.0/24 (254 hosts)
VLAN 30 (Servers):192.168.30.0/28 (14 hosts)
💡 In this example, .0 is the network address, .1 is chosen as a gateway convention, and .255 is the directed-broadcast address for a /24. Actual gateway selection and address reservations depend on the platform and design.
02Cisco IOS / Switch Config

Step 2: Configure Router/Switch Gateways

Configure 802.1Q sub-interfaces on your router (Router-on-a-Stick) or SVIs on a Layer 3 switch to act as default gateways.

! Step 2: Configure Router Sub-Interfaces (Router-on-a-Stick)
interface GigabitEthernet0/0.10
 description LAN_Subnet_Staff
 encapsulation dot1Q 10
 ip address 192.168.10.1 255.255.255.0
 no shutdown
!
interface GigabitEthernet0/0.20
 description LAN_Subnet_Guest
 encapsulation dot1Q 20
 ip address 192.168.20.1 255.255.255.0
 no shutdown
03

Step 3: Assign IP Addresses to Host Interfaces

Configure static IP address parameters, netmasks, and default gateways directly on host machines via OS CLI tools.

# Assign Static IP & Netmask on Windows via Netsh
netsh interface ip set address name="Ethernet" static 192.168.10.50 255.255.255.0 192.168.10.1

# Configure Primary DNS Server
netsh interface ip set dns name="Ethernet" static 1.1.1.1
04ICMP & Diagnostics

Step 4: Verify & Test Inter-Subnet Routing

Confirm local gateway reachability, test cross-subnet packet forwarding, and inspect hop pathways using standard diagnostic utilities.

# 1. Verify Gateway Reachability
ping 192.168.10.1

# 2. Test Inter-Subnet Routing to Guest Subnet
ping 192.168.20.50

# 3. Trace Route Path across Gateway (Windows / Linux)
tracert 192.168.20.50   # Windows
traceroute 192.168.20.50 # Linux / macOS
#vlsm

6. VLSM — Variable Length Subnet Masking

Variable Length Subnet Masking (VLSM) allows network engineers to subdivide an address block into non-uniform subnets sized for different host requirements. Longer prefixes such as /27 and /30 create smaller subnets; allocating the smallest suitable block avoids wasting addresses.

/30 Prefix255.255.255.252

Point-to-Point Router Links

Provides exactly 4 total IPv4 addresses (22), yielding 2 conventional host addresses. It is common for two-endpoint links, while RFC 3021 /31 can use both addresses on supported point-to-point interfaces.

Usable Efficiency:50% (2 of 4)
/27 Prefix255.255.255.224

Branch & Small Departments

Provides 32 total IP addresses (25), yielding 30 usable hosts. Perfect for small department teams, remote office locations, or server racks.

Usable Efficiency:93.75% (30 of 32)
/24 Prefix255.255.255.0

Standard Building / LAN

Provides 256 total IPv4 addresses (28), yielding 254 conventional host addresses. It is a common LAN example, not a universal allocation size.

Usable Efficiency:99.2% (254 of 256)
SIGNAL / WORKED EXAMPLE

Worked VLSM Example: Subnetting a 192.168.1.0/24 Block

Requirement: Allocate subnets for Engineering (50 hosts), Sales (25 hosts), Executive (10 hosts), and 2 Router Links.

DepartmentNeeded HostsAllocated CIDRSubnet MaskNetwork AddressUsable Host RangeBroadcast Address
Engineering50 hosts/26 (64 IPs)255.255.255.192192.168.1.0192.168.1.1 — 192.168.1.62192.168.1.63
Sales25 hosts/27 (32 IPs)255.255.255.224192.168.1.64192.168.1.65 — 192.168.1.94192.168.1.95
Executive10 hosts/28 (16 IPs)255.255.255.240192.168.1.96192.168.1.97 — 192.168.1.110192.168.1.111
Router Link 12 hosts/30 (4 IPs)255.255.255.252192.168.1.112192.168.1.113 — 192.168.1.114192.168.1.115
Router Link 22 hosts/30 (4 IPs)255.255.255.252192.168.1.116192.168.1.117 — 192.168.1.118192.168.1.119
Unassigned PoolFuture expansion136 IPs free/29 + /25192.168.1.120/29 + 192.168.1.128/25192.168.1.120–.127; .128–.255 (136 raw addresses)Free range, no broadcast assignment
Address Space Allocation Tree (192.168.1.0/24)
192.168.1.0/24 (256 Total IPs)
├── 192.168.1.0/26   [Engineering: 50 hosts required, 62 usable (.1-.62)]
├── 192.168.1.64/27  [Sales:       25 hosts required, 30 usable (.65-.94)]
├── 192.168.1.96/28  [Executive:   10 hosts required, 14 usable (.97-.110)]
├── 192.168.1.112/30 [Router Link 1: 2 hosts required, 2 usable (.113-.114)]
├── 192.168.1.116/30 [Router Link 2: 2 hosts required, 2 usable (.117-.118)]
└── 192.168.1.120/29 + 192.168.1.128/25 [Reserved Future Allocation Pool: 136 raw addresses (.120-.127 and .128-.255)]
Heuristic: allocate largest requirements first to simplify alignment
RFC 3021 Standard

/31 Subnet Prefixes on Point-to-Point Links

Under conventional IPv4 subnet rules, a /30 block uses 4 addresses to supply 2 host addresses. RFC 3021 defines a limited /31 interpretation for point-to-point links so both addresses can identify the two endpoints.

Standard /30 Link (4 IPs):
.0 (Network ID - Unusable)
.1 (Router A Interface)
.2 (Router B Interface)
.3 (Broadcast - Unusable)
RFC 3021 /31 Link (2 IPs - 100% Efficient):
.0 (Router A Interface)
.1 (Router B Interface)
Network and directed-broadcast semantics are not used for these two endpoints on the point-to-point link.
#supernetting

7. Supernetting & CIDR Aggregation

Supernetting (also called CIDR Route Aggregation or Route Summarization) is the process of combining multiple contiguous smaller networks into a single, shorter-prefix network route. This dramatically reduces core routing table sizes and conserves memory on enterprise network backbones.

❌ Before Aggregation (4 Individual Routes)

Bloated Routing Table

Routers must store, query, and advertise four separate routing table entries for adjacent subnets:

S 192.168.0.0/24via 10.1.1.1
S 192.168.1.0/24via 10.1.1.1
S 192.168.2.0/24via 10.1.1.1
S 192.168.3.0/24via 10.1.1.1

✅ After Aggregation (1 Supernet Route)

75% Table Reduction

All 4 subnets are consolidated into a single summary prefix with a shorter network mask:

S 192.168.0.0/22via 10.1.1.1
Covers range: 192.168.0.0 to 192.168.3.255 (Total 1,024 IP addresses in 1 route entry).
02 · Applied6 Modules

Connect & Operate Networks

Apply the addressing model to VLANs, DHCP, IPv6, NAT, cloud subnets, and wireless access.

#vlans

8. VLANs & Subnets — How They Connect

While both VLANs (Virtual LANs) and Subnets isolate network traffic, they operate at different layers of the OSI model. Understanding how Layer 2 physical switch isolation pairs with Layer 3 IP addressing is essential for modern enterprise network design.

OSI Layer 2 (Data Link)IEEE 802.1Q

VLAN (Virtual Local Area Network)

Partitioning at the physical switch level. Inserts a 4-byte 802.1Q tag into Ethernet frame headers to divide a single switch into multiple virtual broadcast domains.

Hardware Scope:Ethernet Switches & Trunks
Identifier:VLAN ID (1 — 4094)
Isolation Layer:MAC / Frame Broadcast Scope
OSI Layer 3 (Network)IPv4 / IPv6

IP Subnet (Subnetwork)

Logical IP address grouping defined by subnet masks (e.g., 255.255.255.0). Determines whether a packet stays local or must be routed through a gateway.

Hardware Scope:Routers & L3 Switches
Identifier:Network IP & CIDR Prefix
Isolation Layer:IP Packet Routing Boundaries
SIGNAL / WORKED EXAMPLE

Industry Standard: 1:1 Mapping & Inter-VLAN Routing

Best practice commonly maps one IP subnet to one VLAN. Communication between VLANs requires a Layer 3 router or Layer 3 switch.

Layer 3 Gateway (Router / L3 Switch)
Inter-VLAN Routing ("Router-on-a-Stick")
Evaluates Firewall ACLs before forwarding packets between subnets
VLAN 10Layer 2
Finance Dept
Subnet: 10.10.10.0 / 24
Gateway: 10.10.10.1
Switch Ports: FastEthernet 0/1 - 0/10
VLAN 20Layer 2
Engineering
Subnet: 10.10.20.0 / 24
Gateway: 10.10.20.1
Switch Ports: FastEthernet 0/11 - 0/20
VLAN 30Layer 2
Guest Wi-Fi
Subnet: 10.10.30.0 / 24
Gateway: 10.10.30.1
Switch Ports: Wireless AP Trunk
802.1Q Trunking

Access Ports (End Devices)

Switch ports configured as Access Ports belong to a single access VLAN (the port's PVID). They send and receive standard untagged Ethernet frames directly to workstations, printers, and IP phones. "Native VLAN" is trunk terminology and does not apply to an access port.

Trunk Ports (IEEE 802.1Q Inter-Switch Links)

Switch ports configured as Trunk Ports multiplex traffic from multiple VLANs over a single physical link by appending a 4-byte 802.1Q VLAN ID tag to each Ethernet frame header. The exception is the trunk's native (untagged) VLAN: frames in that VLAN are forwarded across the trunk without a tag, so both ends must agree on which VLAN it is.

#dhcp

9. DHCP & IP Address Management (IPAM)

Dynamic Host Configuration Protocol (DHCP) automates IPv4/IPv6 allocation across local networks. Explore the step-by-step DORA handshake, Layer 3 relay agent forwarding across subnets, core DHCP options, and enterprise IPAM pool sizing.

SIGNAL / WORKED EXAMPLE

The 4-Step DORA Handshake

Interactive four-step DHCP discovery, offer, request, and acknowledgement flow.

Interactive Protocol Flow
UDP Ports: Server 67 | Client 68
💻
Client Workstation
MAC: 00:1A:2B:3C:4D:5E
IP: 0.0.0.0
Direction: Client Workstation ➔ DHCP Server / Broadcast
0.0.0.0:68
D
255.255.255.255:67
Type: BroadcastDst MAC: FF:FF:FF:FF:FF:FF
🖥️
DHCP Server
IP: 192.168.10.1
Listening UDP 67

DHCP DISCOVER Summary

When an unconfigured device connects to a network, it commonly sends a UDP broadcast from 0.0.0.0:68 to 255.255.255.255:67. A DHCP relay can forward the request to servers on another network.

Packet Header Payload
Source MAC: 00:1A:2B:3C:4D:5E
Dest MAC: FF:FF:FF:FF:FF:FF
Source IP: 0.0.0.0
Dest IP: 255.255.255.255

Payload Parameters & Options

Option 53DHCP Message Type = Discover (1)Identifies the packet type
Option 55Parameter Request List (1, 3, 6, 15, 121)Options client is asking for
Option 61Client IdentifierIdentifier supplied by the client
Option 12Host Name = 'MacBook-Pro'Optional client hostname
Step 1 of 4
SIGNAL / WORKED EXAMPLE

DHCP Relay Agent (ip helper-address)

A relay agent forwards client broadcasts across routed subnets.

Cross-Subnet Forwarding
VLAN 10 Subnet (192.168.10.0/24)
💻
Client Host
Sends L3 Broadcast:
255.255.255.255:67
L3 Router (Gateway 192.168.10.1)
🛣️
Interface G0/0.10
✓ Converts Broadcast to Unicast to 10.0.0.100 (GIADDR: 192.168.10.1)
Central Management Subnet
🖥️
Central DHCP Server
IP: 10.0.0.100
Receives Unicast & Allocates from Pool 192.168.10.0/24
Why DHCP Relay is Required: Routers do not forward the limited broadcast 255.255.255.255 beyond the local link, so a DISCOVER stays inside the client's subnet. When clients reside on separate VLANs from the central DHCP server, the router's interface acts as a DHCP Relay Agent. It intercepts the local broadcast, sets the GIADDR (Gateway IP Address) field to 192.168.10.1, and forwards a unicast packet across subnets directly to 10.0.0.100.
Cisco IOS Relay Agent Configuration
! Cisco IOS DHCP Relay Agent Configuration
! 1. Enter Gateway Subnet Interface (VLAN 10)
interface GigabitEthernet0/0.10
 description LAN-VLAN10-GATEWAY
 ip address 192.168.10.1 255.255.255.0

! 2. Configure Primary & Secondary DHCP Server Relays
! Helper-address converts L2/L3 Broadcasts into Unicast to target IP
 ip helper-address 10.0.0.100
 ip helper-address 10.0.0.101

! 3. (Optional) Fine-tune Relay Security & Option 82 Insertion
 ip dhcp relay information option
 ip dhcp relay information trust-all
Network Configuration Parameters

Essential DHCP Options

Option 1Subnet Mask
0x01

Specifies the subnet mask of the client's subnet according to dotted decimal notation.

Sample Payload: 255.255.255.0
Data Length: 4 bytes | RFC 2132 Section 3.3
Enterprise Use Case: Defines network vs host portion boundary for routing decisions.
Option 3Router (Default Gateway)
0x03

List of IP addresses for routers on the client's subnet. Routers should be listed in order of preference.

Sample Payload: 192.168.10.1
Data Length: 4 * n bytes | RFC 2132 Section 3.5
Enterprise Use Case: Allows hosts to route traffic destined for external networks and the Internet.
Option 6Domain Name Server (DNS)
0x06

List of DNS recursive name servers available to the client.

Sample Payload: 10.0.0.10, 1.1.1.1
Data Length: 4 * n bytes | RFC 2132 Section 3.8
Enterprise Use Case: Directs client domain name lookups to internal Active Directory DNS and public fallbacks.
Option 12Host Name
0x0C

Specifies the name of the client host, often populated automatically into Dynamic DNS (DDNS).

Sample Payload: 'FINANCE-PC-042'
Data Length: Variable | RFC 2132 Section 3.14
Enterprise Use Case: Enables corporate DNS servers to auto-register hostnames for internal resolution.
Option 15Domain Name
0x0F

Specifies the domain name that client should use when resolving unqualified hostnames.

Sample Payload: 'corp.internal.example.com'
Data Length: Variable | RFC 2132 Section 3.17
Enterprise Use Case: Allows staff to type 'server01' and automatically expand to 'server01.corp.internal'.
Option 66TFTP Server Name (PXE)
0x42

Identifies TFTP boot server used for PXE network operating system deployment.

Sample Payload: '10.0.0.50' / 'tftp.corp.net'
Data Length: Variable | RFC 2132 Section 9.4
Enterprise Use Case: Used by WDS / SCCM / iPXE to automate OS installation over bare-metal network boot.
Option 67Bootfile Name (PXE)
0x43

Specifies the executable filename location on the TFTP server to initiate PXE boot.

Sample Payload: 'pxelinux.0' / 'boot\x64\wdsmgfw.efi'
Data Length: Variable | RFC 2132 Section 9.5
Enterprise Use Case: Instructs UEFI / BIOS firmware which NBP (Network Boot Program) binary to load.
Option 121Classless Static Routes
0x79

Injects specific static routing table entries directly into client operating systems.

Sample Payload: Dst: 10.50.0.0/16 -> Gateway: 192.168.10.254
Data Length: Variable | RFC 3442
Enterprise Use Case: Directs internal VPN / MPLS traffic to dedicated security gateways without overriding default Internet gateway.
Capacity & Planning

Enterprise IPAM & Pool Exhaustion Calculator

HIGH UTILIZATION WARNING
Pool Allocation Distribution80.4% Utilization
Static Reserved: 30
Active Leases: 180
Free Available: 44
Total Usable Pool Size
224 IPs
Excluding network & broadcast address
Available Free Pool
44 IPs
Unallocated available leases
Est. Time to Pool Exhaustion
23.5 Hours
Illustrative: free IPs ÷ (daily churn ÷ 24). Assumes churn continues and no lease is released, so lease duration is not modelled here.
💡 IPAM Health Recommendation

WARNING: High pool usage. High churn during peak hours may trigger address depletion.

Best Practice Tip: For guest Wi-Fi networks with high turnover, set lease duration to 2 to 4 hours. For enterprise office desktops, set lease duration to 8 days.
#ipv6

10. IPv6 — The Next Generation

IPv6 replaces IPv4's 32-bit address space with a 128-bit address space (about 3.4 × 10 to the 38th power total addresses). Its architecture supports hierarchical routing, SLAAC, and a simplified base header; IPsec support is recommended for IPv6 nodes (RFC 8504), but IPv6 itself does not provide confidentiality or access control.

IPv6 Address Anatomy: 8 Hextets (128 Bits)

Written as 8 groups of 4 hexadecimal digits (called hextets), separated by colons. Each hextet represents 16 bits (8 × 16 = 128 bits).

Hextet 1
2001
16 bits
Hextet 2
0db8
16 bits
Hextet 3
85a3
16 bits
Hextet 4
0000
16 bits
Hextet 5
0000
16 bits
Hextet 6
8a2e
16 bits
Hextet 7
0370
16 bits
Hextet 8
7334
16 bits
← First 64 Bits (with a /64 prefix): Network / Subnet Prefix →← Last 64 Bits: Interface ID (Host) →

Zero Compression Rules

RFC 5952 recommends a canonical text representation for IPv6 addresses. Other valid RFC 4291 representations remain valid input.

Step 1: Original Uncompressed IPv6 Address
2001:0db8:0000:0000:0000:0000:1428:57ab
Rule 1: Omit Leading Zeros

In any hextet, leading zeros can be dropped. For example, 0db8 becomes db8, and 0000 becomes 0.

Rule 2: Double Colon (::) Compression

A single contiguous sequence of all-zero hextets can be replaced with ::.Critical Constraint: :: can only be used ONCE per address to prevent ambiguity when parsing.

IPv4 vs IPv6 Feature Matrix

Architectural comparison between legacy IPv4 protocols and modern IPv6 standards.

FeatureIPv4 StandardIPv6 Standard
Address Size32 Bits (4 Bytes)128 Bits (16 Bytes)
Total Address Count~4.3 Billion (4.3 × 10 to the 9th power)~340 Undecillion (3.4 × 10 to the 38th power)
Format NotationDotted Decimal (e.g. 192.168.1.1)Hexadecimal Colons (e.g. 2001:db8::1)
Prefix LengthVariable prefixes (/0 to /32)/64 is common for SLAAC subnets; other prefixes exist
Address Auto-ConfigurationStatic configuration or DHCPv4 are common optionsSLAAC can configure addresses; DHCPv6 can supply other parameters or addresses
NAT UseCommonly used to conserve public IPv4 space, but not required by IPv4Usually unnecessary for address conservation; filtering is still required
SIGNAL / WORKED EXAMPLE

Why IPv6 LANs Commonly Use /64

Many IPv6 LANs use /64 subnets because SLAAC is designed around a 64-bit interface identifier. Point-to-point links, loopbacks, and infrastructure-specific designs may use other prefix lengths, so /64 is a convention rather than a universal rule.

/64 Common Subnet
Addresses per /64
2⁶⁴
18.4 quintillion addresses; a few interface identifiers are reserved (Subnet-Router anycast, RFC 4291 Section 2.6.1; reserved IIDs, RFC 5453)
IPv6 /64 Subnet Structure:Addresses per /64 = 18.4 Quintillion (2 to the 64th power), minus a few reserved interface IDs
Global Routing Prefix (48 Bits)
First 32 bits are the RFC 3849 documentation prefix 2001:db8::/32; the rest is site space
2001:0db8:85a3
Subnet ID (16 Bits)
Internal Subnet Allocation
:0001:
Interface ID (64 Bits)
Host address (SLAAC, stable, or temporary)
:0000:0000:0000:0001
#ips

11. Public vs Private IPs & NAT

IPv4 addresses may be publicly routable or drawn from private-use ranges. Because public IPv4 space is limited, Network Address Translation (NAT), especially port translation, lets many private hosts share one public address for outbound connections. NAT changes address/port reachability; it is not a replacement for firewall policy.

Public IP AddressesGlobally Routable

Internet-Facing Infrastructure

Public addresses are allocated through the Internet number registry system and advertised by networks that have routing connectivity. A public address can still be blocked by firewalls or service policy; public does not mean universally reachable.

Routability:Global Public Internet
Uniqueness:Worldwide Unique
Examples:8.8.8.8 (Google), 1.1.1.1 (Cloudflare)
Private IP AddressesRFC 1918 Local LAN

Internal LAN & Cloud VPCs

RFC 1918 reserves these ranges for private internets. They are not meant to be advertised across inter-enterprise links; whether an upstream router filters them is a policy and implementation matter, not a guaranteed behavior of every ISP.

Routability:Not globally routed
Uniqueness:Local Network Only
RFC 1918 Blocks:10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16
Examples:192.168.1.1, 10.0.0.1, 172.16.0.1
SIGNAL / WORKED EXAMPLE

Interactive NAT / PAT (Port Address Translation) Flow

Step-by-step walkthrough showing how a NAT Gateway translates private sockets to public sockets.

Step 1 of 4

Outbound Request Sent by Private Host

Client (192.168.1.50) sends a packet to Web Server (93.184.216.34:80) via ephemeral port 51234.

This walkthrough illustrates NAPT (RFC 3022) with endpoint-independent mapping; actual mapping and filtering behavior is implementation-defined (RFC 4787 §4.1 / §5), so another NAT may reuse or refuse this state differently.
Private LAN Client
192.168.1.50
Private Network (RFC 1918)
NAT Gateway Router
LAN: 192.168.1.1
WAN Public: 203.0.113.5
Rewrites Packet Headers
Public Web Server
93.184.216.34:80
Global Public Internet
Active Packet Header State:
Source Socket:192.168.1.50 : 51234
Destination Socket:93.184.216.34 : 80
Router NAT Translation Table:
Private SocketPublic NAT Socket
Creating translation state...
#cloud

12. Subnets in the Cloud

Cloud hyperscalers (AWS, Azure, GCP) use Software-Defined Networking (SDN) to deliver virtual private clouds. While cloud subnets share traditional CIDR math, cloud vendors enforce vendor-specific IP reservations, availability zone scopes, and routing rules.

AWS VPC (Virtual Private Cloud)

Cloud SDN Subnet Architecture
Subnet Scope & Availability
Each IPv4 subnet resides in a single Availability Zone, or in a single Local Zone, Wavelength Zone, or Outpost. A VPC spans the Region.
Provider subnet scope and availability model
Reserved Addresses
AWS reserves 5 IPv4 addresses per subnet: .0 network, .1 VPC router, .2 AWS DNS, .3 future use, and the last address (.255 in a /24).
Provider-specific reserved addresses
Infrastructure-as-Code Configuration (Terraform)
# AWS VPC & Subnet Terraform Example
resource "aws_vpc" "main" {
  cidr_block = "10.0.0.0/16"
}

resource "aws_subnet" "public_az1" {
  vpc_id            = aws_vpc.main.id
  cidr_block        = "10.0.1.0/24"
  availability_zone = "us-east-1a"
}

📋 Cloud Subnetting Architecture Checklist & Tips

Plan for growth and non-overlap

Choose an address range that leaves room for growth and does not overlap networks you must connect over VPN or Direct Connect. The required size depends on the design; /16 is not a universal default.

Treat public/private as a routing design

A common pattern places internet-facing resources in public subnets and application or database workloads in private subnets. Route tables, gateways, load balancers, and policy determine the actual exposure.

Check provider address reservations

Account for each provider's reservations when sizing IPv4 subnets. For example, AWS and Azure reserve five addresses in each subnet; in a /28, that leaves 11 addresses available for provider resources. Minimum prefix lengths and other limits vary by provider.

Design for the availability model

Use separate subnets in multiple zones when the workload and provider support zone redundancy; the number of zones is an availability decision, not a universal requirement.

Verify the platform's controls

Use the controls provided by the platform: security groups are commonly stateful, while network ACLs are commonly stateless and evaluated at a subnet boundary. Verify the provider's rule direction and default behavior before relying on a policy.

#wireless

13. Wireless & WLAN Integration

Modern enterprise wireless LANs bridge 802.11 radio networks to wired Ethernet through access points and, in many designs, a wireless LAN controller. This section explores SSID-to-VLAN mapping, WLC topologies, 2.4GHz, 5GHz, and 6GHz bands, RF planning, and Wi-Fi 6/6E/7 behavior.

Part 1 ArchitectureCAPWAP & 802.1Q Trunking

SSID-to-VLAN Mapping & WLC Topology

Live Frame Flow for SSID: Corp-Enterprise

CAPWAP Data Tunneling (UDP 5247)
Step 1: Client
Wi-Fi Device
802.11 Radio Frame
SSID: Corp-Enterprise
Step 2: Access Point
Enterprise AP
Encapsulate CAPWAP
CAPWAP Payload
Step 3: WLC
Wireless Controller
Strip CAPWAP & Tag 802.1Q
Dot1Q Tag: VLAN 10
Step 4: L3 Gateway
Core Switch / Router
Default Gateway SVI
10.10.0.1
Authentication:
802.1X RADIUS (EAP-TLS)
Subnet CIDR:
10.10.0.0/24
QoS & Priority:
High (DSCP EF / Voice & Video)
ACL Policy:
Full Access to Internal LAN & ERP

Centralized WLC (Split MAC Architecture)

CAPWAP Tunnel

The AP handles time-sensitive 802.11 radio work. In a centralized forwarding design, user traffic commonly travels in CAPWAP data (UDP 5247) to the WLC, while authentication and policy placement depend on the controller design.

FlexConnect (Local Switching Architecture)

Branch & Remote APs

In local-switching designs, CAPWAP control traffic (UDP 5246) reaches the WLC while user payload is switched onto local VLANs. Continued branch service during a WAN outage depends on the AP, authentication, and site configuration.

Part 2 Spectrum Analysis2.4 GHz vs 5 GHz vs 6 GHz (Wi-Fi 6E/7)

Wi-Fi Frequency Bands & Technical Comparison

2.4 GHz Band (Legacy & IoT)

2.400 - 2.4835 GHz (regulatory-domain dependent channel use)
Max Channel Width:
20 MHz is common; 40 MHz may be available but is often avoided in dense deployments
Max PHY Speed:
PHY rate depends on Wi-Fi generation, channel width, streams, and modulation
Range & Wall Penetration:
Often less attenuated than higher frequencies, but building materials vary
Interference Risk:
Unlicensed users, microwaves, Bluetooth, Zigbee, and neighboring WLANs
Non-Overlapping Channels:
Channels 1, 6, and 11 are a common non-overlapping 20 MHz plan in North America
Key Technologies:
DSSS / CCK (802.11b), OFDM (802.11g), OFDM/OFDMA (802.11n/ax)
Advantages
  • • Often better reach through typical indoor obstacles
  • • Broad client compatibility
Disadvantages & Limitations
  • • Fewer clean 20 MHz planning choices
  • • Often congested in homes and dense deployments
Specification / Metric2.4 GHz Band5 GHz Band6 GHz Band (Wi-Fi 6E/7)
Frequency Range2.400 - 2.4835 GHz (region-dependent use)5 GHz ranges vary by regulatory domain5.925 - 7.125 GHz where the region permits the full band
Available SpectrumAbout 83.5 MHz of band spaceVaries by region and permitted channelsUp to about 1,200 MHz in regions with the full allocation
20 MHz Planning Choices1, 6, and 11 are a common North American planCount varies by region, DFS, and channel availabilityCount varies by region and power class
Channel Width20 MHz common; 40 MHz may be supported20 / 40 / 80 / 160 MHz where permittedUp to 320 MHz with supported Wi-Fi 7 devices and rules
CoverageOften longer reach in the same environmentOften shorter reach than 2.4 GHz at the same conditionsOften shorter reach than 5 GHz at the same conditions
Interference SourcesNeighboring WLANs, microwaves, Bluetooth, and ZigbeeNeighboring WLANs and radar rules on DFS channelsNo legacy 2.4/5 GHz clients; other 6 GHz users still contend
Theoretical PHY RateDepends on Wi-Fi generation, width, streams, and modulationDepends on Wi-Fi generation, width, streams, and modulationWi-Fi 7 advertises multi-gigabit rates; actual throughput varies
Part 3 Channel PlanningChannels 1, 6, 11 & Bonding Tree

2.4 GHz Channel Planner & 5/6 GHz Bonding

2.4 GHz Channel Overlap Calculator (Channels 1 to 11)20 MHz Width / 5 MHz Spacing

Ch 1 (2412MHz)Ch 6 (2437MHz)Ch 11 (2462MHz)
Ch 1 (2412MHz)Ch 6 (2437MHz)Ch 11 (2462MHz)
Calculated Interaction:Separated in This Simplified Model (Lower Overlap Risk)

The selected channels are separated by at least five channel numbers in this 20 MHz model. Validate the result against the actual regulatory channel plan and width.

Ch 1Ch 2Ch 3Ch 4Ch 5Ch 6Ch 7Ch 8Ch 9Ch 10Ch 11
AP1
AP2
Green shaded zones indicate standard non-overlapping channels (1, 6, 11).

5 GHz & 6 GHz Channel Bonding Hierarchy

Combines contiguous 20MHz channels to multiply throughput at the expense of spectrum density and SNR.

Base 20 MHz Channels:
Ch 36
Ch 40
Ch 44
Ch 48
Ch 52 (DFS)
Ch 56 (DFS)
Ch 60 (DFS)
Ch 64 (DFS)
Bonded 40 MHz Channels:
Ch 38 (36+40)
Ch 46 (44+48)
Ch 54 (52+56 DFS)
Ch 62 (60+64 DFS)
Bonded 80 MHz Channels:
Ch 42 (36+40+44+48)
Ch 58 (52+56+60+64 DFS)
Thermal Noise Penalty: Doubling channel width doubles noise floor (+3 dB noise).
+6 dB Noise
Part 4 SimulatorRSSI, Noise Floor, SNR & Spectrum Mask

Interactive Wi-Fi Signal & Spectrum Overlap Visualizer

1. Transmitter & Environment

TX Power:20 dBm (100 mW)
Distance:15 meters

2. AP Channels & Noise

3. Derived Signal Quality

Free-space + obstacle estimate:-74 dB
RSSI (Signal):-54 dBm
Signal-to-Noise (SNR):36 dB
Est. MCS Index:MCS 11 (Wi-Fi 6) (1024-QAM)
Illustrative PHY Estimate:1201 Mbps
Excellent (Pristine Link)

Real-Time RF Spectrum Mask & Signal Shape

Overlapping at 80 MHz (gap 4, needs 16)
Noise Floor (-90 dBm)AP1 (Ch 36)AP2 (Ch 40)
Lower channel numbersChannel index (ordinal) - not to frequency scaleHigher channel numbers
03 · Operations7 Modules

Understand, Forward & Diagnose Traffic

Read packet structure first, then learn forwarding, filtering, encrypted overlays, diagnostics, and container-networking tradeoffs.

#packets

14. Packet Encapsulation & Analysis

Every interaction on the internet depends on Packet Encapsulation—the process where raw application data is wrapped layer-by-layer with Transport headers, IP headers, and Ethernet frames before physical transmission over the wire. Understanding header bit fields, stateful TCP handshakes, and PCAP analysis tools like Wireshark is essential for network engineering and security analysis.

1. Interactive OSI vs TCP/IP Layer Stack Inspector

Select any layer to inspect protocol mapping, PDU names, headers attached, and addressing units.

Encapsulation Step:Data
📦
PDU Encapsulation State
1. Application Data (HTTP GET /index.html)
Payload: GET /index.html
OSI 7-Layer ModelTCP/IP 4-Layer Equivalent
OSI Layer 4

Transport Layer

Transport Layer

Provides end-to-end process-to-process data delivery, flow control, error recovery, and multiplexing.

Protocol Data Unit (PDU)
Segment (TCP) / Datagram (UDP)
Addressing Scheme
Port Numbers (e.g. Src: 54321, Dst: 443)
Encapsulation Header / Trailer Action
Transport Header (Src/Dst Ports, Seq/Ack, Flags, Checksum)
Key Protocols & Standards
TCPUDPSCTPQUIC
Encapsulation Direction: Top-Down (L7 → L1)Decapsulation: Bottom-Up (L1 → L7)

2. Frame, Packet & Segment Header Anatomy

RFC Bit/Byte layout visualizer for Ethernet II Frames (Layer 2), IPv4 Packets (Layer 3), and TCP Segments (Layer 4).

Bit Offset: 0Bit 15Bit 31 (32-Bit Width Word)

Data Offset (4b) + Reserved (4b) + Flags (8b)

Offset: 12-13 (2 Bytes) (16 bits)

Data Offset defines header size in 32-bit words. The next 4 bits are reserved, followed by the 8 control flags defined in RFC 9293: CWR, ECE, URG, ACK, PSH, RST, SYN, FIN (the 9th 'NS' bit from RFC 3540 was reclassified as Historic by RFC 8311).

Sample Hex Raw Bytes:80 02
Decoded / Value:Header Len: 32B | Flags: SYN=1
SIGNAL / WORKED EXAMPLE

3. TCP 3-Way Handshake & Connection Teardown

Step-by-step TCP sequence number arithmetic, flag bitmask inspection, and TCP socket state transitions.

💻
Client Host
192.168.1.50 : 54321
State: SYN_SENT
🌐
Web Server
93.184.216.34 : 443
State: LISTEN → SYN_RCVD
TCP SYN Segment
Direction: Client ➔ Server
TCP Control Flags BitmaskHeader Field
URG
0
ACK
0
PSH
0
RST
0
SYN
1
FIN
0
Sequence Num (Seq):1000
Ack Num (Ack):0

Step Explanation: Client picks an Initial Sequence Number (ISN=1000), sets SYN=1 flag, and sends connection request to Server port 443.

4. Interactive Wireshark PCAP Packet Viewer Simulator

Inspect real network trace packets, expand nested protocol headers, and analyze byte hex dumps.

Wireshark Packet Capture Trace - capture_01.pcap
Apply a display filter:
No.Time (s)SourceDestinationProtocolLengthInfo
10.000000192.168.1.5093.184.216.34TCP7454321 → 80 [SYN] Seq=0 Win=64240 Len=0 MSS=1460 SACK_PERM=1
20.02411593.184.216.34192.168.1.50TCP7480 → 54321 [SYN, ACK] Seq=0 Ack=1 Win=29200 Len=0 MSS=1460
30.024210192.168.1.5093.184.216.34TCP6654321 → 80 [ACK] Seq=1 Ack=1 Win=64240 Len=0
40.025102192.168.1.5093.184.216.34HTTP162GET /index.html HTTP/1.1
50.026401192.168.1.501.1.1.1DNS75Standard query 0x1a2b A api.example.com
60.038920192.168.1.508.8.8.8ICMP68Echo (ping) request id=0x1234, seq=1, ttl=64
Packet Details Tree (Packet #1)
• Encapsulation type: Ethernet (1)
• Arrival Time: Aug 8, 2026 14:22:01.000000000 UTC
• Frame Length: 74 bytes (592 bits)
• Capture Length: 74 bytes (592 bits)
• Destination: Router_70:3a:0e (70:3a:0e:99:88:77)
• Source: Apple_00:1a:2b (00:1a:2b:3c:4d:5e)
• Type: IPv4 (0x0800)
• 0100 .... = Version: 4
• .... 0101 = Header Length: 20 bytes (5)
• Total Length: 60 bytes
• Identification: 0x1c46 (7238)
• Flags: 0x4000, Don't fragment
• Time to Live: 64
• Protocol: TCP (6)
• Header Checksum: 0x7c2d [validation disabled]
• Source Address: 192.168.1.50
• Destination Address: 93.184.216.34
• Source Port: 54321
• Destination Port: 80
• Sequence Number: 0 (raw: 983503360)
• Acknowledgment Number: 0
• 1010 .... = Header Length: 40 bytes (10)
• Flags: 0x002 (SYN)
• Window: 64240
• Checksum: 0xe2a1 [validation disabled]
• TCP Options: (20 bytes) MSS=1460, SACK_PERM=1, TSval=0 TSecr=0, WS=128
Packet Bytes (Hex Dump)Selected Range: 34 - 74 Bytes
000070 3A 0E 99 88 77 00 1A 2B 3C 4D 5E 08 00 45 00p:...w..+<M^..E.
001000 3C 1C 46 40 00 40 06 7C 2D C0 A8 01 32 5D B8.<.F@.@.|-...2].
0020D8 22 D4 31 00 50 3A 9F 12 00 00 00 00 00 A0 02.".1.P:.........
0030FA F0 E2 A1 00 00 02 04 05 B4 04 02 08 0A 00 00................
004000 00 00 00 00 00 01 03 03 07..........
Packets: 6 • Displayed: 6Profile: Default Wireshark Decoders Active
#routing

15. Routing & Gateway Protocols

Routers build forwarding decisions by evaluating destination addresses against local routing tables. Explore dynamic IGP & EGP protocols, configured first-hop redundancy with HSRP/VRRP, policy-controlled BGP aggregation, and longest-prefix matching.

Part 1

Static vs. Dynamic Routing Protocols

Code: OLink-State IGP

OSPF (Open Shortest Path First)

Admin Distance (Cisco IOS default)110
Multicast IP / Transport224.0.0.5 (All OSPF) / 224.0.0.6 (DR/BDR)
Administrative Distance (Cisco IOS default)
110
Cisco IOS default distance for OSPF routes; RFC 2328 does not define administrative distance.

Medium to large enterprise networks requiring fast convergence and hierarchical area design (Backbone Area 0).

AlgorithmDijkstra's Shortest Path First (SPF)
Metric CalculationCisco default: reference bandwidth (100 Mbps) / interface bandwidth (configurable)
Convergence SpeedCan be fast; BFD is optional and timer-dependent
Deployment ScopeInterior Gateway Protocol (IGP) / Enterprise LAN/WAN
Key Technical Highlights
✓Hierarchical structuring via Area 0 (Backbone) and stub areas.
✓Floods topology changes and periodically refreshes link-state information.
✓Open IETF standard protocol (RFC 2328).

Cisco IOS Default Administrative Distance (Lower = Better)Believability Score (0 - 255)

0
Connected
1
Static
20
eBGP
90
EIGRP (internal)
110
OSPF
120
RIP
200
iBGP

Administrative distance is a Cisco IOS route-selection construct, not a protocol field: these are the platform defaults and every one of them is configurable. External EIGRP is 170 and an EIGRP summary route is 5.

Part 2

Gateway Redundancy (HSRP & VRRP Virtual IP Failover)

Shared First-Hop Gateway (HSRP)
VIP: 192.168.1.1(VMAC: 0000.0C07.AC01 (HSRPv1; HSRPv2 uses 0000.0C9F.Fxxx))
Router A (R1)ACTIVE
Phys IP: 192.168.1.2
Priority: 110
Hello: Every 3s (IOS default)
Forwarding LAN Traffic
Router B (R2)STANDBY
Phys IP: 192.168.1.3
Priority: 100
Hold Timer: 10s (IOS default)
Listening for R1 Heartbeats
LAN Client HostIP: 192.168.1.50
Configured Default Gateway: 192.168.1.1 (Unaware of physical router swap!)

Interactive Failover Controls

Primary Router A StatusLink UP & Healthy
Preemption ModeForces highest priority router back to Active upon recovery
Protocol Event Console Log
12:00:00 - Initial state: Router A is ACTIVE (Priority 110). Router B is STANDBY (Priority 100).
12:00:00 - Virtual IP 192.168.1.1 is served by the selected FHRP group. Serving LAN Host 192.168.1.50.
Part 3

BGP Route Summarization & Aggregation

BGP aggregate-address

Reducing Global Routing Table Bloat

The global routing table is large and changes over time. Autonomous systems can summarize contiguous, aligned prefixes before advertising to peers, reducing routing state when policy allows.

Original Routes:4 prefixes
Aggregated Block:198.51.100.0/22
Table Reduction:-75% route entries

Bitwise Matching Breakdown (22 Common Bits)Green = Identical Network Bits

198.51.100.0/24
11000110001100110110010000000000
198.51.101.0/24
11000110001100110110010100000000
198.51.102.0/24
11000110001100110110011000000000
198.51.103.0/24
11000110001100110110011100000000
! Cisco IOS BGP Aggregation Configuration
router bgp 65001
network 198.51.100.0 mask 255.255.255.0
network 198.51.101.0 mask 255.255.255.0
network 198.51.102.0 mask 255.255.255.0
network 198.51.103.0 mask 255.255.255.0
aggregate-address 198.51.100.0 255.255.252.0 summary-only as-set
Part 4

Interactive Routing Table Lookup Simulator (Longest Prefix Match)

Quick Test IPs
🎯Selected Route: 10.0.1.48/29 via 10.0.1.49 (Eth1.20)
Longest Prefix: /29

Matched 6 route entries. Subnet mask /29 won because it has the highest number of contiguous matching network bits (Longest Prefix Match Rule).

Active Router Forwarding Information Base (FIB)

Total Entries: 8
StatusProtocolNetwork CIDRNext Hop IPInterfaceAD / MetricAction
★ SELECTEDEIGRP10.0.1.48/2910.0.1.49Eth1.2090 / 15
MATCHED (/27)Static10.0.1.32/2710.0.1.1Eth1.101 / 1
MATCHED (/24)Connected10.0.1.0/2410.0.1.1Eth10 / 0
MATCHED (/16)OSPF10.0.0.0/1610.255.1.1Eth0110 / 10
MATCHED (/8)OSPF10.0.0.0/810.255.0.1Eth0110 / 20
NO MATCHConnected192.168.1.0/24192.168.1.1Eth20 / 0
NO MATCHBGP172.16.0.0/12172.16.0.1Eth320 / 100
MATCHED (/0)Static0.0.0.0/0203.0.113.1WAN01 / 1

Add Custom Route Entry to Table

#firewall

16. Firewall Rules Between Subnets

Subnets define addressing and broadcast boundaries, but inter-subnet communication also depends on routing. A router or Layer 3 switch may forward traffic when a route exists; firewalls and ACLs then apply the platform's configured policy to permit, deny, or log packets.

🚫

Default-DENY (Block)

A default-deny policy drops traffic that does not match an explicit permit rule. The exact default depends on the device and rule direction, so verify it rather than assuming it.

Action: DROP / REJECTDefault Guard
✅

Granular PERMIT (Allow)

Allows specific protocol, source CIDR, destination CIDR, and port combinations (e.g. Web Subnet to DB Subnet on TCP 5432).

Action: ACCEPTPort Specific
📊

Stateful Audit & LOG

Captures dropped connection attempts, port scans, and unauthorized inter-subnet packets to SIEM monitoring tools for incident analysis.

Action: AUDIT / SIEMTraffic Analytics
SIGNAL / WORKED EXAMPLE

Cisco IOS Inter-Subnet Access Control List (ACL 100)

Extended ACLs filter based on source/destination IPs and TCP/UDP ports. Apply inbound on the router sub-interface closest to the source:

Extended ACL Logic
! Cisco Extended Access Control List (ACL 100)
! 1. Allow Web Subnet (VLAN 10) to access Database Subnet (VLAN 20) on PostgreSQL port 5432
access-list 100 remark --- Permit Web to DB Postgres ---
access-list 100 permit tcp 192.168.10.0 0.0.0.255 192.168.20.0 0.0.0.255 eq 5432

! 2. Allow Web Subnet (VLAN 10) to access Shared HTTPS Services (VLAN 30)
access-list 100 remark --- Permit Web to Shared HTTPS ---
access-list 100 permit tcp 192.168.10.0 0.0.0.255 192.168.30.0 0.0.0.255 eq 443

! 3. Explicitly DENY remaining Web-to-DB traffic and log attempts
access-list 100 remark --- Deny other Web to DB packets ---
access-list 100 deny ip 192.168.10.0 0.0.0.255 192.168.20.0 0.0.0.255 log

! NOTE: Every IOS ACL ends with an implicit 'deny ip any any'. With only the permits
! above, VLAN 10 loses all other egress (including Internet) once this ACL is applied.
! A real deployment adds the further permits it needs, or a trailing 'permit ip any any'.
access-list 100 remark --- Implicit deny ip any any follows: add required permits ---

! 4. Apply ACL inbound on VLAN 10 Interface
interface GigabitEthernet0/0.10
 ip access-group 100 in

🛡️ Home & Small Network Firewall Rule Best Practices

Isolate Guest Wi-Fi Subnet

If the platform supports guest isolation, enable it and apply policy so guests (e.g. 192.168.2.0/24) cannot reach private NAS drives, PCs, or printers on 192.168.1.0/24.

Segregate Smart Home IoT Devices

Place smart TVs, cameras, smart plugs, and voice assistants on an isolated IoT subnet (e.g. 192.168.50.0/24). Explicitly block or restrict traffic from that subnet to the main LAN.

Review UPnP Across Trust Boundaries

Avoid allowing Universal Plug and Play (UPnP) port-mapping requests from less-trusted IoT or guest networks to create exposure into protected subnets; exact controls depend on the router.

Use Stateful Firewall Engines Carefully

When policy and defaults allow outbound sessions, stateful firewall engines can permit matching return traffic without static inbound ports. Verify the product's defaults and rule direction.

#security

17. Network Security & Access Control

Defense in depth combines routing, filtering, identity, encryption, and monitoring. The NACL and security-group comparison below uses AWS-style semantics as a concrete example; other providers and appliances expose different boundaries and defaults.

Policy Model
Stateless NACL
Current control view
Simulation Step
1 / 3
Return traffic inspection
Rule Entries
6
Active inspector rules
Layer 3/4 Filtering

1. Network ACLs vs. Security Groups

Concrete AWS-style comparison: subnet-level stateless filters versus instance or interface-level stateful rules.

Architectural FeatureNetwork ACL (NACL)Security Group (SG)
Operating BoundarySubnet Boundary (VPC Router Level)Instance / ENI Level (Hypervisor)
State TrackingStateless

In this AWS-style NACL model, return traffic must match an outbound rule because the filter is stateless.

Stateful

In this AWS-style security-group model, response traffic for an allowed flow is tracked automatically.

Rule Actions SupportedALLOW and DENY rules (AWS network ACL)ALLOW rules only in AWS security groups (implicit deny)
Evaluation OrderSequential by rule number; lowest matching number winsRules are aggregated; there is no user-visible order
Ephemeral Return PortsMust allow the matching return traffic in the outbound direction; a broad ephemeral range is only one possible policy.AWS tracks response traffic for an allowed flow

Return Traffic Flow Breakdown — NACL (Stateless)Step 1 of 3

[PACKET INBOUND]Src: 203.0.113.50:52134 → Dst: 10.0.1.10:80

External client sends HTTP request to web server on port 80 using client ephemeral port 52134.

NACL Check: Inbound Rule 100 permits TCP Port 80 → Packet allowed into Subnet.
Site-to-Site & Remote Access

VPN Tunnels

WireGuard — Modern Lightweight Crypto Tunnel

Designed as a small, simple encrypted tunnel; it can run in the Linux kernel and also has user-space implementations. Performance and overhead depend on platform and configuration.

Crypto Primitive:ChaCha20-Poly1305 & Curve25519
Handshake Protocol:Noise Protocol Framework (1 RTT)
Transport Layer:UDP Port 51820 (common default)
Key Exchange:Static Public Keys (Cryptokey Routing)
Roaming:Endpoint roaming across changing networks
Overlay Network (L2 over L3)

VXLAN Encapsulation

UDP 4789 (common default)

Virtual Extensible LAN (VXLAN) encapsulates Layer 2 Ethernet frames inside UDP packets. It is used in data-center overlays and some Kubernetes CNI implementations to expand beyond the 4,096 VLAN-ID space up to 16.7 million VNI values.

Click Packet Header Layer to Inspect Encapsulation:
4. VXLAN HeaderHeader Size: 8 Bytes
Flags (I=1) | Reserved (24b) | VNI: 5001 (24-bit) | Reserved (8b)

Contains the 24-bit VXLAN Network Identifier (VNI) providing up to 16,777,216 isolated virtual Layer 2 subnets over a shared L3 fabric.

SIGNAL / WORKED EXAMPLE

3. Network Address Translation (NAT) Variants

Understanding SNAT, DNAT, and PAT (NAPT) packet header transformations at boundary gateways.

Address Translation Architecture
Many-to-One Overload NAT

PAT — Port Address Translation

Maps thousands of internal private host IP addresses onto a single shared public IP address by assigning unique public source ports for each session.

Primary Use Case: Home Routers, Corporate Egress Gateways, IPv4 Address Preservation.
PAT Translation Table Mapping (Multiple Internal Hosts → 1 Public IP):
Host A (10.0.1.15:5000)➔203.0.113.1:10001
Host B (10.0.1.16:5000)➔203.0.113.1:10002
Host C (10.0.1.17:5000)➔203.0.113.1:10003

Both source IP and source port are translated to prevent socket collisions on public internet responses.

Interactive Testing Suite

4. Interactive Security Rule Inspector

Test arbitrary packet parameters (Source IP, Destination Port, Protocol) against custom firewall ACLs.

Testing packet: TCP packet to port 80 from 203.0.113.50.

✓ PACKET PERMITTED (ALLOWED)Mode: NACL

Matched enabled Rule #100 (Allow inbound HTTP from internet). Evaluation halted (First Match Wins).

Rule Engine Evaluation Trace:
›Rule #100 MATCHED: [Protocol: TCP, Port: 80, Source: 0.0.0.0/0] → Action: ALLOW

Active NACL Rule ConfigurationClick rule checkbox to enable/disable

ActiveRule #ProtocolPort RangeSource CIDRActionDescription
#100TCP800.0.0.0/0ALLOWAllow inbound HTTP from internet
#110TCP4430.0.0.0/0ALLOWAllow inbound HTTPS from internet
#200TCP22192.168.1.0/24ALLOWAllow SSH only from Admin Subnet
#210TCP220.0.0.0/0DENYDeny SSH from everywhere else
#300TCP330610.0.1.0/24ALLOWAllow MySQL from Web Subnet
*ALLALL0.0.0.0/0DENYCatch-all '*' rule: denies anything no numbered rule matched
Add Custom Rule to NACL Table:
#diagnostics

18. Network Diagnostics & CLI Sandbox

Master essential network troubleshooting CLI utilities (ping, traceroute, mtr, iperf3, dig, nmap). Test commands interactively in the simulated bash terminal sandbox, execute instant command presets, and reference the diagnostic cheat sheet.

guest@net-sandbox: ~ (bash)
========================================================================
NETWORK DIAGNOSTICS & CLI SANDBOX v2.4 (Simulated Bash Kernel)
Supported commands: ping, traceroute, mtr, iperf3, dig, nmap, clear, help
Tip: Type commands directly or click preset buttons below!
========================================================================
guest@net-sandbox:~$

Instant Execution Presets (Click to Run):

Structured Troubleshooting Workflow Matrix

Step 01Reachability

Layer 3 ICMP Ping Test

Verify IP layer connectivity and physical/link layer reachability.

Step 02Path Analysis

Hop Path & Delay Pinpoint

Identify exact router hop or provider link dropping packets.

Step 03DNS Audit

DNS Resolution Audit

Confirm whether issue is IP routing or domain name resolution failure.

Step 04Port Security

Firewall & Port Check

Detect blocked TCP/UDP ports, stateful firewall drops, or down services.

Step 05Throughput

Bandwidth & Throughput

Measure maximum transmission rate, TCP window size, and UDP packet loss.

SIGNAL / WORKED EXAMPLE

Diagnostic Tools Command Cheat Sheet

Comprehensive reference of syntax, flags, OSI layers, and practical use-cases.

ping (Packet InterNet Groper)ICMP / Layer 3

Sends ICMP Echo Requests to test IP-layer reachability and measure replies, RTT, and loss when the destination and path permit ICMP.

Syntax:ping [options] <destination_ip_or_hostname>
Key Command Options & Flags:
-c <count>Stop after sending specified number of ECHO_REQUEST packets.
-i <interval>Wait specified seconds between sending each packet (default: 1s).
-s <bytes>Specify number of payload data bytes to send (useful for MTU test).
-t <ttl>Linux/iputils: set IP Time To Live (TTL) hop count limit. Platform-specific: on macOS/BSD -t is a timeout in seconds (-m sets TTL), and on Windows -t pings continuously.
Practical Use-Case: Quick sanity check for gateway reachability; payload-size tests can help investigate MTU issues, but results depend on fragmentation and filtering.
traceroute / tracertICMP & UDP / Layer 3

Sends probes with increasing IP TTL values and reports routers that return errors. Missing replies, filtering, load balancing, and asymmetric paths can leave gaps or make the result incomplete.

Syntax:traceroute [options] <destination_host>
Key Command Options & Flags:
-nPrint hop addresses numerically without executing slow DNS reverse lookups.
-m <max_ttl>Set maximum number of hops (Linux default: 30).
-IOn Linux traceroute, use ICMP Echo requests instead of the default UDP probes.
-p <port>Specify destination base port for UDP probes.
Practical Use-Case: Comparing observed hop responses while isolating a possible routing or latency change; it cannot guarantee a complete map of the path.
mtr (My TraceRoute)ICMP & UDP / Layer 3

Combines the functionality of ping and traceroute into a single continuous real-time network diagnostic tool.

Syntax:mtr [options] <target_host>
Key Command Options & Flags:
-rReport mode: output continuous stats after running set packet count.
-c <count>Set number of pings sent per hop before generating final report.
-wWide report mode: print full hostnames without truncating.
-nNo DNS resolution on hop IP addresses.
Practical Use-Case: Generating repeatable diagnostic reports for an authorized network investigation; interpret intermediate-hop loss carefully because routers may rate-limit probes.
iperf3 (Bandwidth Benchmark)TCP & UDP / Layer 4

Measures observed TCP or UDP throughput between two hosts; UDP mode can report jitter and datagram loss.

Syntax:iperf3 -c <server_ip> [options] | iperf3 -s
Key Command Options & Flags:
-c <host>Run in client mode, connecting to specified iperf3 server host.
-sRun in server daemon mode listening for incoming benchmark connections.
-p <port>Set server port to listen/connect on (default 5201).
-uUse UDP packets instead of default TCP streams for jitter/loss test.
-b <rate>Set target UDP bandwidth constraint (e.g. 1G, 100M).
Practical Use-Case: Verifying actual throughput capacity across VPN tunnels, 10GbE links, or Wi-Fi subnets.
dig (Domain Information Groper)DNS / Layer 7

Flexible DNS lookup utility that queries Domain Name System servers directly and prints exact response records.

Syntax:dig [@server] <domain> [type] [options]
Key Command Options & Flags:
+shortPrint clean, concise answer records only without header noise.
+traceFollow authoritative DNS delegation path from root servers down.
@serverQuery specific DNS resolver IP instead of default system DNS.
ANY / A / MXSpecify query record type (A, AAAA, MX, NS, TXT, CNAME, SOA).
Practical Use-Case: Troubleshooting email routing failures, verifying DNS propagation, and auditing SPF/TXT records.
nmap (Network Mapper)TCP & UDP / Layer 4 & 7

A port scanner and service-enumeration tool for authorized assessments; results depend on scan type, filtering, and target responses.

Syntax:nmap [scan_type] [options] <target>
Key Command Options & Flags:
-sSTCP SYN Stealth Scan (half-open scan, does not complete 3-way handshake).
-sVProbe open ports to determine service name and software version info.
-p <ports>Scan target ports only (e.g. -p 22,80,443 or -p 1-1024).
-OEnable remote operating system fingerprint detection.
Practical Use-Case: Auditing firewall rules or inventorying services on systems you own or are authorized to assess.
#troubleshooting

19. Troubleshooting Subnet Issues

Subnetting issues can lead to subtle network failures, including host isolation, asymmetric routing, IP conflicts, and cross-subnet packet drops. Master these 6 diagnostic scenarios and follow the 6-step troubleshooting workflow.

6 Common Subnet Misconfigurations & Solutions

1. Misconfigured Subnet Mask (Off-by-One CIDR)

Mask Mismatch
⚠️ Symptom / Impact

Host A (192.168.1.50/24) cannot reach Host B (192.168.1.200/25). Host B incorrectly treats Host A as external and sends packets to Gateway.

💡 Resolution Strategy

Verify netmask uniformity across all hosts in the subnet block.

Diagnostic CLI Commands
# Windows: Inspect IPv4 Subnet Mask
ipconfig /all

# Linux: Verify assigned IP & Prefix length
ip -4 addr show dev eth0

🩺 6-Step Subnet Diagnostic Workflow

Step 1ipconfig /all | ip addr

Verify Local IP Address & Subnet Mask

Ensure host has a valid IP address (not 0.0.0.0 or APIPA 169.254.x.x) and correct netmask matching network plan.

Step 2ping 127.0.0.1

Test Local Loopback & Interface

Ping 127.0.0.1 and local host IP to verify local TCP/IP protocol stack and NIC driver functionality.

Step 3ping 192.168.10.1

Ping Default Gateway IP

Test ICMP reachability to local subnet router interface (e.g. 192.168.10.1) to confirm Layer 2 switch connectivity.

Step 4tracert 192.168.20.50

Trace Route Path to Target Destination

Execute traceroute to locate exact router hop where inter-subnet packet forwarding fails or times out.

Step 5nslookup domain.com | nc -zv IP PORT

Test DNS & Targeted TCP/UDP Ports

Verify whether issue is pure IP layer routing or higher-layer DNS resolution / firewall port blocking.

Step 6show vlan brief | show access-lists

Audit Switch VLANs & Firewall ACL Rules

Check switchport VLAN assignments, 802.1Q trunk tags, stateful firewall rules, and router ACL drop counters.

#containers

20. Cloud-Native & Container Networking

Modern cloud-native systems rely on virtualized network namespaces (netns), virtual ethernet pairs (veth), overlay tunnels, and kernel-level packet manipulation. Discover how Kubernetes CNI plugins, Docker isolation modes, and Layer 4/7 load balancers route microservice traffic at scale.

1. Kubernetes Networking Architecture & CIDR Ranges

Kubernetes defines a Pod networking model: each Pod is assigned an IP by the cluster network plugin, and the plugin is expected to provide Pod-to-Pod connectivity without NAT. Exact routing, encapsulation, and policy behavior depend on the CNI implementation.

Pod CIDR Range: 10.244.0.0/16Allocated per Node (/24 per Worker)

Pods receive IP addresses from the cluster network plugin and expose them on the Pod's network interface. Addresses are usually ephemeral: recreating or rescheduling a Pod may change its IP, so Services provide stable discovery.

Worker Node 1 Subnet
10.244.1.0/24
Pods: 10.244.1.2 - 10.244.1.254
Worker Node 2 Subnet
10.244.2.0/24
Pods: 10.244.2.2 - 10.244.2.254
Worker Node 3 Subnet
10.244.3.0/24
Pods: 10.244.3.2 - 10.244.3.254

🔌 CNI (Container Network Interface) Plugins Comparison

Cilium CNI (eBPF)

Project Maintainer: Isovalent / CNCF
eBPF (Extended Berkeley Packet Filter)
NetworkPolicy Enforcement:L3/L4 + L7 API-Aware (HTTP, gRPC, Kafka)
Performance Profile:Can reduce per-packet overhead in supported datapaths; results depend on kernel, mode, and workload.

Cilium uses eBPF programs at selected kernel hooks for networking, policy, and observability. It can integrate with or replace kube-proxy in supported modes; Hubble and WireGuard encryption are optional features.

# Cilium L7 HTTP NetworkPolicy Example
apiVersion: "cilium.io/v2"
kind: CiliumNetworkPolicy
metadata:
  name: secure-api-access
spec:
  endpointSelector:
    matchLabels:
      app: payment-service
  ingress:
  - fromEndpoints:
    - matchLabels:
        app: checkout
    toPorts:
    - ports:
      - port: "8080"
        protocol: TCP
      rules:
        http:
        - method: "POST"
          path: "/v1/charge"

2. Docker Networking Drivers & Modes

Docker uses container network drivers to manipulate Linux network namespaces, iptables NAT tables, and virtual interfaces. Select a mode below to analyze host binding, performance, and packet paths.

Bridge Mode (Default)

docker run --net=bridge
Subnet Scope: 172.17.0.0/16 (docker0)

Containers connect to a virtual software bridge (docker0) via virtual ethernet (veth) pairs. Outbound traffic commonly uses IP masquerading. User-defined bridges provide automatic container-name DNS lookup.

✓ Architectural Advantages
  • •Isolated container network namespace
  • •Automatic container DNS on custom bridges
  • •Useful default for standalone single-host containers
⚠ Technical Limitations
  • •Port publishing may add NAT and filtering work
  • •Multi-host communication needs an overlay or other routing design
Docker CLI Execution Example:
docker run -d --name web -p 8080:80 nginx:alpine

3. Layer 4 (L4) vs Layer 7 (L7) Load Balancing & Ingress

Load balancers operate at different OSI layers to distribute traffic across container replicas. Compare transport-level packet routing (L4) with application-level HTTP routing (L7).

🌐 L7 Ingress Controller Mechanics

  • ✓Inspection Depth: Terminates the TLS session and decrypts the record stream using the server private key, then parses HTTP methods, URI paths (/v1/users), Host headers (api.domain.com), and cookies.
  • ✓Advanced Traffic Controls: Supports Canary deployment traffic splits (90/10 weighted routing), rate-limiting, CORS injection, and Web Application Firewall (WAF) rule sets.
  • Endpoint selection: An Ingress controller may watch Service endpoints and proxy to Pod addresses; the exact path depends on the controller and Service configuration.
Kubernetes Ingress Manifest (networking.k8s.io/v1)
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: production-ingress
  annotations:
    nginx.ingress.kubernetes.io/rewrite-target: /
    nginx.ingress.kubernetes.io/ssl-redirect: "true"
spec:
  ingressClassName: nginx
  rules:
  - host: api.company.com
    http:
      paths:
      - path: /v1/users
        pathType: Prefix
        backend:
          service:
            name: user-service
            port:
              number: 8080
      - path: /v1/orders
        pathType: Prefix
        backend:
          service:
            name: order-service
            port:
              number: 9090

4. Interactive K8s Service IP Routing Simulator

Illustrative Packet Path Simulation

Test how incoming client packets travel through Kubernetes abstractions (ClusterIP, NodePort, LoadBalancer, Headless, and Ingress) using either an iptables-based or an eBPF-based data path!

Service Type
loadbalancer
Current Kubernetes virtual endpoint
Data Path
eBPF
Selected kernel forwarding engine
Requests Sent
0
Live simulator request count
Backend Pod Target Replicas (Total Requests: 0)
pod-10 Hits (0%)
Pod IP: 10.244.1.14:8080
Worker-1 (192.168.10.101)
pod-20 Hits (0%)
Pod IP: 10.244.2.88:8080
Worker-2 (192.168.10.102)
pod-30 Hits (0%)
Pod IP: 10.244.3.42:8080
Worker-3 (192.168.10.103)
📡 Simulated Packet Translation Trace (illustrative)Engine: eBPF socket LB (cgroup/connect)
Click "Send Packet / Trigger Request" above to trace kernel packet routing...
04 · Evaluation3 Modules

Practice & Review

Reinforce the track with guided practice, fast-reference formulas, and a final knowledge check.

#practice

21. Practice Problems

Master subnetting with real-world scenarios and certification-style drill questions. Test your calculations for network boundaries, host ranges, broadcast addresses, and VLSM allocations, then toggle answers to verify your steps.

Easy172.16.5.0/24

Problem 1: Basic Subnetting

You are given the network address 172.16.5.0/24. Calculate the Network ID, Subnet Mask, First Usable Host IP, Last Usable Host IP, Broadcast Address, and Total Usable Hosts.

Medium10.1.1.0/24 into 4 Subnets

Problem 2: Subnet Division

Divide the network 10.1.1.0/24 into 4 equal subnets. Determine the new CIDR prefix length, Subnet Mask, Block Size, and list each created subnet with its Network ID, Usable Range, and Broadcast Address.

Medium192.168.10.150/27

Problem 3: Find the Network

An engineer discovers a workstation configured with IP address 192.168.10.150/27. Determine the Network ID, Subnet Mask, First & Last Usable Host IPs, and Broadcast Address for the subnet block it belongs to. Is 192.168.10.150 a valid host address?

Hard192.168.1.0/24 (WAN, Mkt, Fin)

Problem 4: VLSM Challenge

Given the single base network block 192.168.1.0/24, design a Variable Length Subnet Masking (VLSM) allocation for three subnets: Finance (25 hosts needed), Marketing (12 hosts needed), and WAN Link (2 hosts needed). Allocate from the largest requirement to the smallest so each block stays aligned on its own boundary and the remaining space stays contiguous.

Real-World10.0.5.100/28 vs 10.0.5.113

Problem 5: Real-World Scenario

A database server is configured with IP 10.0.5.100/28 and default gateway 10.0.5.113. The server cannot reach anything outside its own subnet. Determine the exact subnet boundary for 10.0.5.100/28 and decide whether 10.0.5.113 can act as this server's default gateway.

#cheatsheet

22. Subnetting Cheat Sheet

Quick-reference hub containing essential subnet formulas, comprehensive CIDR prefix lookup tables (/8 through /32), and mental math shortcuts for rapid network calculations in exams and production deployments.

📐Core Subnetting Formulas

Total IP Addresses

2^(32 - CIDR) = 2^H

Calculates total raw IP addresses in block including network & broadcast.

Ex: For /24: 32 - 24 = 8 host bits => 2^8 = 256 IPs

Usable Host Count

2^H - 2 (conventional IPv4 subnet, H >= 2)

Subtracts the conventional network and directed-broadcast addresses; /31 point-to-point and /32 host routes use special semantics.

Ex: For /24: 256 - 2 = 254 conventional usable host addresses

Block Size (Magic Number)

256 - Mask Octet OR 2^H (in target octet)

Determines the exact step size between adjacent network boundaries.

Ex: Mask 255.255.255.224 => 256 - 224 = 32 increment step

Wildcard Mask (Inverse)

255.255.255.255 - Subnet Mask

Used in Cisco Access Control Lists (ACLs) and OSPF network commands.

Ex: 255.255.255.255 - 255.255.255.240 = 0.0.0.15

Network Address

IP Address AND Subnet Mask

Performs bitwise AND matching between IP address and subnet mask.

Ex: 192.168.10.150 AND 255.255.255.224 = 192.168.10.128

Broadcast Address

Network Address + (Block Size - 1)

Last address in the subnet block where all host bits equal binary 1.

Ex: 192.168.10.128 + (32 - 1) = 192.168.10.159

First Usable Host

Network Address + 1

First assignable IP address for network interfaces/endpoints.

Ex: 192.168.10.128 + 1 = 192.168.10.129

Last Usable Host

Broadcast Address - 1

Final assignable IP address before the broadcast boundary.

Ex: 192.168.10.159 - 1 = 192.168.10.158

Subnets Created

2^(Borrowed Bits)

Calculates total equal subnets created when extending network prefix.

Ex: Borrow 3 bits from /24 => 2^3 = 8 subnets (/27)

📊Prefix Quick Reference Table (/8 to /32)

Complete CIDR lookup listing netmasks, host counts, magic numbers, and practical RFC use-cases.

SIGNAL / WORKED EXAMPLE

⚡ /31 Prefix Note RFC 3021

RFC 3021 enables 2 usable IP addresses on point-to-point links with zero overhead (no reserved network or broadcast addresses), doubling IPv4 address efficiency on WAN links compared to traditional /30. RFC 3021 scopes this to point-to-point links only (it does not consider the effects on other interface types), and using a /31 requires platform support for 31-bit prefixes.

SIGNAL / WORKED EXAMPLE

📌 /32 Prefix Note Single Host Route

A /32 prefix represents a single host route (mask 255.255.255.255). Used for router loopback interfaces (Router IDs in OSPF/BGP) and explicit single-IP host firewall rules.

CIDRSubnet MaskTotal IPsUsable HostsBlock Size (Increment)Primary RFC / Production Use Case
/8Historic Class A
255.0.0.016,777,21616,777,2141 (Octet 1) / 256 (Octet 2)Historic classful /8 boundary; modern networks use CIDR
/9
255.128.0.08,388,6088,388,606128 (Octet 2)Telco Backbones & Regional Supernets
/10
255.192.0.04,194,3044,194,30264 (Octet 2)Carrier-Grade NAT (CGNAT 100.64.0.0/10)
/11
255.224.0.02,097,1522,097,15032 (Octet 2)Large Enterprise Data Centers
/12
255.240.0.01,048,5761,048,57416 (Octet 2)Cloud VPC Private Allocations (RFC 1918 172.16.0.0/12)
/13
255.248.0.0524,288524,2868 (Octet 2)Multi-Region Cloud Supernets
/14
255.252.0.0262,144262,1424 (Octet 2)Large Service Provider Blocks
/15
255.254.0.0131,072131,0702 (Octet 2)Regional Metro Networks
/16Historic Class B
255.255.0.065,53665,5341 (Octet 2) / 256 (Octet 3)Historic classful /16 boundary; a /16 can still be chosen by design
/17
255.255.128.032,76832,766128 (Octet 3)University & Large Campus LANs
/18
255.255.192.016,38416,38264 (Octet 3)Enterprise Office Hubs
/19
255.255.224.08,1928,19032 (Octet 3)Regional Corporate Buildings
/20
255.255.240.04,0964,09416 (Octet 3)Example cloud or campus allocation; provider limits vary
/21
255.255.248.02,0482,0468 (Octet 3)Large Office Campus Subnets
/22
255.255.252.01,0241,0224 (Octet 3)Example Kubernetes node or Pod allocation; CNI and cluster sizing vary
/23
255.255.254.05125102 (Octet 3)Medium Branch Office Networks
/24Historic Class C
255.255.255.02562541 (Octet 3) / 256 (Octet 4)Historic classful /24 boundary; common LAN example today
/25
255.255.255.128128126128 (Octet 4)Half /24 Subnet / Office Department
/26
255.255.255.192646264 (Octet 4)Standard Corporate Department Subnet
/27Popular
255.255.255.224323032 (Octet 4)Small Team Subnet / Wireless Segment
/28
255.255.255.240161416 (Octet 4)Server Rack / Database Cluster
/29
255.255.255.248868 (Octet 4)Small infrastructure segment or virtual-router example
/30Legacy P2P
255.255.255.252424 (Octet 4)Traditional Point-to-Point Router Link (2 Usable / 2 Reserved)
/31RFC 3021
255.255.255.254222 (Octet 4)Point-to-Point Link (RFC 3021 - 0 Network/Broadcast Overhead)
/32Host Route
255.255.255.255111 (Octet 4)Host route, loopback interface, or single-address policy object

🧠Mental Math Tricks Grid (4 Cards)

🪄

1. The Magic 256 Rule

Step Size

Instant Subnet Increment Step

Subtract the non-255 subnet mask octet from 256 to calculate the exact block size (subnet increment) in seconds.

Block Size = 256 - (Interesting Octet Mask)
Example: Mask 255.255.255.224 => 256 - 224 = 32 step size. Subnets: .0, .32, .64, .96, .128, .160, .192, .224.
🖐️

2. Finger-Counting Bit Borrowing

Subnet Doubling

Double Subnets, Halve Host Capacity

Every bit borrowed doubles the created subnets (2^n) and halves host capacity per subnet. Count on fingers from 1 to 6 bits.

1 bit=2 | 2 bits=4 | 3 bits=8 | 4 bits=16 | 5 bits=32 | 6 bits=64
Example: Starting at /24: Borrowing 3 bits yields /27 prefix (2^3 = 8 subnets with 32 IPs each).
🎯

3. Octet Jump Shortcuts

Target Octet

Locate the 'Interesting Octet' Instantly

Quickly map CIDR prefixes to their active working octet without converting binary digits:

/8 to /15 => Octet 2 | /16 to /23 => Octet 3 | /24 to /32 => Octet 4
Example: CIDR /20 falls in Octet 3 (255.255.240.0). Octet 1 & 2 are 255, Octet 4 is 0.
⚡

4. Quick Wildcard Mask Inversion

ACL & OSPF

Subtract Subnet Mask from 255.255.255.255

Derive Cisco ACL wildcard masks instantly by subtracting each mask octet from 255.

Wildcard = (255 - Mask Octet) for each of 4 octets
Example: Subnet Mask 255.255.255.240 (/28) => (255-255).(255-255).(255-255).(255-240) = 0.0.0.15.
#quiz

23. Test Your Knowledge

Click an answer to check it. Your score is tracked at the bottom.

Q1 — How many usable hosts does a /26 subnet have?

Q2 — What is the broadcast address of 192.168.1.64/26?

Q3 — Which subnet mask matches /27?

Q4 — In VLSM, why is it conventional to allocate subnets from largest to smallest?

Q5 — What does NAT stand for?

Q6 — How many subnets do you get by borrowing 3 bits from a /24?

Q7 — Which address is outside the conventional host range of 192.168.1.0/30?

Q8 — What is the primary purpose of a VLAN?

Your Score
0 / 8

Keep practicing! Review the sections above and try again.