Posts

Showing posts with the label CCNA

Autonomous Systems and BGP: How the Internet Routes Between Networks

An autonomous system is a network under one administrative authority with a single, consistent routing policy, identified by a globally unique AS number. The internet is roughly a hundred thousand of them exchanging reachability information, and BGP is the protocol they use to do it. Interior and exterior routing The distinction organizes the whole topic. Interior gateway protocols — OSPF, IS-IS, EIGRP, RIP — run inside one autonomous system. Their job is to find the best path by a technical metric such as cost or hop count, and they converge quickly because everyone inside the AS is cooperating. Exterior gateway protocols — BGP in practice — run between autonomous systems. Their job is to enforce policy , not to find the technically shortest path. A network may prefer a longer route because it is cheaper, or refuse to carry traffic between two neighbours because it has no contract to do so. That is why BGP is described as a path vector protocol rather th...

VLSM Explained: Variable Length Subnet Masking for Network+

Variable Length Subnet Masking is the practice of using different subnet mask lengths within the same address block , sizing each subnet to the hosts it actually needs. It is the difference between cutting every board to the same length and cutting each one to fit. On the Network+ exam it appears both as a concept question and as a subnetting problem you have to work by hand. The waste VLSM eliminates Suppose you are given 192.168.10.0/24 and you need four networks: a user LAN with 100 hosts, a server segment with 25, a management segment with 10, and a point-to-point WAN link with exactly 2. With fixed-length subnetting you must size every subnet for the largest requirement. Four subnets of /26 give you 62 usable addresses each — which fails immediately, because the user LAN needs 100. Go to /25 and you get 126 usable addresses per subnet, but a /24 only yields two /25s, so you cannot make four networks at all. Fixed-length subnetting has boxed you in while three of your four...

FHRP Explained: HSRP, VRRP and GLBP for Gateway Redundancy

A host knows exactly one default gateway. If that router fails, the host does not look for another — it simply cannot reach anything off its own subnet. First Hop Redundancy Protocols solve this by letting two or more routers share a single virtual gateway address, so the host's configuration never has to change and failover happens without the host knowing. The problem Redundant links, redundant switches, and redundant uplinks all count for nothing if every host on the segment points at one router's address. That address is a single point of failure sitting in the configuration of every device. Changing it on failure is not an option: hosts learn it from DHCP and hold it for the lease duration, and statically configured devices never change it at all. The gateway address has to stay constant while the router behind it changes. How the virtual gateway works Two or more routers share a virtual IP address and a virtual MAC address. Hosts are configured — usually via DH...

VTP: Centralised VLAN Management and the Revision Number Trap

VLAN Trunking Protocol propagates VLAN definitions between switches so a VLAN created on one appears on all of them. It saves configuration effort and it carries a failure mode severe enough that many organizations disable it entirely. Understanding why is more valuable than understanding the protocol. What it does Switches in the same VTP domain exchange advertisements over trunk links. Create a VLAN on one switch and the definition propagates, so every switch in the domain learns it without being configured individually. The three modes define behaviour. Server switches can create, modify and delete VLANs and propagate those changes. Client switches accept changes and cannot make them locally. Transparent switches maintain their own VLAN database independently, ignoring advertisements for their own purposes while still forwarding them to others. Note what VTP does not do: it propagates VLAN definitions , not port assignments. Which ports belong to which VLAN is always config...

VXLAN in Practice: EVPN Control Plane, VTEP Design and Fabric Operations

This article assumes you know what VXLAN is — the encapsulation, the 24-bit VNI, the VTEP endpoints. If those are unfamiliar, start with VXLAN fundamentals . What follows is the operational layer: how the fabric learns where things are, where the tunnel endpoints should live, and what breaks in practice. Flood-and-learn, and why it was replaced The original VXLAN specification had no control plane. A VTEP learned remote MAC addresses the way a switch always has — by flooding unknown traffic and observing the replies — with multicast in the underlay used to deliver broadcast, unknown unicast, and multicast traffic to every VTEP in the segment. Two problems followed. Multicast in the underlay is operationally unpopular, requiring rendezvous points and a level of multicast expertise many teams do not have. And flooding scales badly: as tenants and endpoints grow, broadcast traffic replicated to every VTEP consumes an increasing share of the fabric. Head-end replicati...

802.1Q VLAN Tagging: Trunks, Native VLANs and VLAN Hopping

A VLAN divides one physical switch into several logical broadcast domains. 802.1Q is the standard that lets those domains span multiple switches, by inserting a four-byte tag into the Ethernet frame that says which VLAN it belongs to. Almost everything interesting about VLAN security comes from the details of that tag and from one unfortunate exception to it. The tag The 802.1Q tag sits between the source MAC address and the EtherType field. Four bytes: a two-byte tag protocol identifier marking the frame as tagged, then three bits of priority for quality of service, one drop-eligible bit, and twelve bits of VLAN identifier. Twelve bits gives 4096 values, with 0 and 4095 reserved, so 4094 usable VLANs. That ceiling is the reason large multi-tenant data centers moved to overlays — the 24-bit identifier in VXLAN exists precisely because 4094 segments is not enough for a cloud provider. Because four bytes are added, the maximum frame grows to 1522 bytes. Switches handle this tr...

Spanning Tree Priority and Root Bridge Election: Controlling the Topology

Spanning tree prevents loops by electing one switch as the root bridge and blocking any port that would create a second path to it. Which switch wins that election determines the shape of the entire forwarding topology — and left to defaults, it is decided by an arbitrary tiebreaker that has nothing to do with your network design. The bridge ID Every switch advertises a bridge ID made of two parts: a 16-bit bridge priority and the switch's MAC address . The lowest bridge ID wins the election, priority compared first and MAC address used only as a tiebreaker. The default priority is 32768 on essentially every switch. When every switch shares that default, the priority comparison is a tie and the election falls entirely to the MAC address — meaning the oldest switch in the network usually wins, because manufacturers assign addresses roughly in sequence. That is frequently a small access switch in a closet rather than a core switch, and the resulting topology routes traffi...

SVIs and Inter-VLAN Routing: From Router-on-a-Stick to Layer 3 Switching

VLANs separate broadcast domains, and traffic between them has to be routed. A switch virtual interface is a logical layer 3 interface on the switch itself, giving a VLAN a gateway address without any external router in the path. It is how nearly every campus network does inter-VLAN routing. The three ways to route between VLANs A router per VLAN — a physical router interface in each VLAN. Obviously correct, obviously unscalable: twenty VLANs needs twenty interfaces. Router-on-a-stick — one router interface carrying a trunk, divided into subinterfaces, one per VLAN, each with an address and a VLAN tag. It works, and every packet crossing between VLANs travels up the trunk to the router and back down, so the trunk carries the traffic twice and becomes the bottleneck. Fine for a small site, poor above that. Switch virtual interfaces — the switch itself holds a layer 3 interface per VLAN and routes between them in hardware, at line rate, with no packet leaving the...

Split Horizon, Route Poisoning and Hold-Down Timers: Loop Prevention

Distance vector routing protocols learn routes from their neighbours and pass them on. That works until a network goes down and a router learns about the dead destination from a neighbour it originally told — at which point two routers can point at each other indefinitely, incrementing the hop count and forwarding packets in a circle. Split horizon and its companions exist to stop exactly that. Counting to infinity The failure works like this. Router A is connected to network X. A tells B about X at one hop; B tells C at two hops. Network X fails and A removes the route. Before A can inform B, B advertises its own route to X back toward A. A now believes it can reach X through B at three hops, and tells B so. B updates to four, A to five, and the count climbs while packets for X loop between them. The base defence is a maximum metric — sixteen hops is unreachable in RIP — which caps the damage but does not prevent it. The loop still forms and still wastes time con...

LACP and Link Aggregation: Why Four Links Are Not Four Times the Speed

Link aggregation combines several physical links into one logical link, adding bandwidth and redundancy at the same time. LACP is the standard protocol that negotiates it. The single most important thing to understand is what aggregation does not give you: a single conversation does not get faster. Why a flow cannot be split TCP requires packets to arrive in order, or close enough that reordering does not trigger retransmission. If a switch sprayed one session's packets across four links with different queue depths, they would arrive out of order and performance would collapse. So the switch hashes some combination of header fields — source and destination MAC addresses, IP addresses, and often port numbers — and uses the result to pick one link. All packets in a given flow take the same link , arriving in order. The consequence: four bundled 1 Gbps links give 4 Gbps of aggregate capacity across many flows, and any single transfer is still capped at 1 Gbps. A question ...

LLDP and CDP: Neighbour Discovery, and What It Tells an Attacker

Link Layer Discovery Protocol lets a device tell its directly connected neighbours what it is. Switches, routers, phones and access points advertise their identity, capabilities and port details, and each builds a picture of what is on the other end of every cable. It is genuinely useful and it is an information disclosure waiting to happen on the wrong port. What gets advertised LLDP frames are sent periodically to a reserved multicast address and are not forwarded by switches, so they reach only the directly connected device. Each frame carries a set of typed fields. Mandatory: the chassis identifier, the port identifier, and a time-to-live after which the neighbour entry expires. Optional and commonly enabled: the system name, a system description including the software version, the port description, the device's capabilities and which are enabled, the management address, and the VLAN identifier. That optional set is the security problem. A device advertising its model, it...

Administrative Distance: How a Router Picks Between Two Sources for One Route

A router may learn the same destination from several places at once — a static route, OSPF, and BGP all offering a path to the same network. Their metrics are not comparable, since a hop count and an OSPF cost measure different things. Administrative distance is the tiebreaker: a number expressing how much the router trusts each source , with lower being more trusted . The values to know Directly connected interface: 0 . Static route: 1 . External BGP: 20 . Internal EIGRP: 90 . OSPF: 110 . IS-IS: 115 . RIP: 120 . External EIGRP: 170 . Internal BGP: 200 . Unknown or untrusted: 255 , which means the route is never installed. The ordering encodes a judgement about reliability. A directly connected interface is fact. A static route was configured deliberately by an administrator, so it is trusted next. Among dynamic protocols, those carrying richer information rank above simpler ones, which is why OSPF beats RIP. Two values reward attention. External BGP at 20 is more trusted tha...

NHRP and DMVPN: How Spoke-to-Spoke Tunnels Build Themselves

Next Hop Resolution Protocol solves one problem: on a network where every site has a dynamic or unknown public address, how does one spoke learn how to reach another directly instead of routing everything through headquarters? NHRP is the lookup service that answers that, and DMVPN is the architecture built on top of it. The problem with hub-and-spoke A traditional site-to-site VPN builds a tunnel between two known endpoints. With twenty branch sites, connecting every site to every other requires 190 tunnels, each configured by hand, and every new site multiplies the work. So most deployments settle for hub-and-spoke: every branch tunnels to headquarters, and traffic between two branches goes branch to hub to branch. That is simple to configure and wasteful in practice — it doubles latency for site-to-site traffic, consumes hub bandwidth twice for every flow, and makes the hub a bottleneck for voice and video between offices that may be physically close together. What NHRP d...

BPDU Guard, Root Guard and Loop Guard: Hardening Switch Access Ports

Spanning tree keeps a switched network loop-free by trusting the information switches exchange. The guard features exist because that trust extends to any device on any port, including a consumer switch a user plugged in and a laptop running attack tooling. Each guard defends a different assumption, and applying the right one to the right port type is what the exam tests. BPDU Guard An access port connects an end host. An end host has no business participating in spanning tree, so a bridge protocol data unit arriving on such a port means something other than a host is attached. BPDU Guard shuts the port down immediately — into err-disabled state — the moment any BPDU is received. Not a lower priority BPDU, not a superior one: any. It pairs with PortFast, which skips the listening and learning states so a host gets a working link in a second rather than thirty. PortFast alone is dangerous, because a port that forwards immediately will forward a loop immediately if someon...