Showing posts with label networking. Show all posts
Showing posts with label networking. Show all posts

Thursday, August 12, 2010

Troubleshooting DNS servers

There may be broadly 2 problems we face when dealing with DNS server:
  • The DNS server is not responding to clients.
  • The DNS server does not resolve names correctly.
Dealing with them 1 by 1.

The DNS server is not responding to clients

Cause 1: Network failure

Solution: Check if the hardware is fully ok, i.e. adapters are properly plugged or not. Then check network connectivity by pinging other computers or routers (such as its default gateway) that are used and available on the same network as the affected DNS servers.


Cause2: Network is o.k. but non-responsive to client's query

Solution: If the DNS client can ping the DNS server, verify that the DNS server is started or not and is able to listen to client's request. Try using the nslookup command to test whether the server can respond to DNS clients. In ubuntu, if you can't run nslookup you need to install a package called dnsutils - which provide clients such as nslookup, host and other tools. The Berkeley Internet Name Domain (BIND) implements an Internet domain name server. his package delivers various client programs related to DNS that are derived from the BIND source tree. In windows use nslookup on command prompt.


Cause: The DNS server has been configured to limit service to a specific list of its configured IP addresses. The IP address originally used in testing its responsiveness is not included in this list.

Solution: If the server was previously configured to restrict the IP addresses for which it responds to queries, it is possible that the IP address being used by clients to contact it is not in the list of restricted IP addresses permitted to provide service to clients.

Try testing the server for a response again, but specify a different IP address known to be in the restricted interfaces list for the server. If the DNS server responds for that address, add the missing server IP address to the list.


Cause: The DNS server has been configured to disable the use of its automatically created default reverse lookup zones.

Solution: Verify that automatically created reverse lookup zones have been created for the server or that advanced configuration changes have not been previously made to the server.

By default, DNS servers automatically create the following three standard reverse lookup zones based on Request for Comments (RFC) recommendations:

These zones are created with common IP addresses covered by these zones that are not useful in a reverse lookup search (0.0.0.0, 127.0.0.1, and 255.255.255.255). By being authoritative for the zones corresponding to these addresses, the DNS service avoids unnecessary recursion to root servers in order to perform reverse lookups on these types of IP addresses.

It is possible, although unlikely, that these automatic zones are not created. This is because disabling the creation of these zones involves advanced manual configuration of the server registry by a user.


Cause: The DNS server is configured to use a non-default service port, such as in an advanced security or firewall configuration.

Solution: Verify that the DNS server is not using a non-standard configuration.

This is a rare but possible cause. By default, the nslookup command sends queries to targeted DNS servers using User Datagram Protocol (UDP) port 53. If the DNS server is located on another network only reachable through an intermediate host (such as a packet-filtering router or proxy server), the DNS server might use a non-standard port to listen for and receive client requests.

If this situation applies, determine whether any intermediate firewall or proxy server configuration is intentionally used to block traffic on well-known service ports used for DNS. If not, you might be able to add such a packet filter onto these configurations to permit traffic to standard DNS ports.

Also, check the DNS server event log to see if Event ID 414 or other critical service-related events have occurred which might indicate why the DNS server is not responding.


The DNS server does not resolve names correctly

Cause: The DNS server provides incorrect data for queries it successfully answers.

Solution: Determine the cause of the incorrect data for the DNS server.

Some of the most likely causes include the following:

  • Resource records (RRs) were not dynamically updated in a zone.
  • An error was made when manually adding or modifying static resource records in the zone.
  • Stale resource records in the DNS server database, left from cached lookups or zone records not updated with current information or removed when they are no longer needed.

To help prevent the most common types of problems, be sure to first review best practices for tips and suggestions on deploying and managing your DNS servers. Also, follow and use the checklists appropriate for installing and configuring DNS servers and clients based on your deployment needs.

If you are deploying DNS for Active Directory, note new directory integration features. These features can cause some differences for DNS server defaults when the DNS database is directory-integrated, that differ from those used with traditional file-based storage.

Many DNS server problems start with failed queries at a client, so it is often good to start there and troubleshoot the DNS client first.


Cause: The DNS server does not resolve names for computers or services outside of your immediate network, such as those located on external networks or the Internet.

Solution: The server has a problem based on its ability to correctly perform recursion. Recursion is used in most DNS configurations to resolve names that are not located within the configured DNS domain name used by the DNS servers and clients.

If a DNS server fails to resolve a name for which it is not authoritative, the cause is usually a failed recursive query. Recursive queries are used frequently by DNS servers to resolve remote names delegated to other DNS zones and servers.

For recursion to work successfully, all DNS servers used in the path of a recursive query must be able to respond to and forward correct data. If not, a recursive query can fail for any of the following reasons:
  • The recursive query times out before it can be completed.
  • A remote DNS server fails to respond.
  • A remote DNS server provides incorrect data.

If a server fails a recursive query for a remote name, review the following possible causes to troubleshoot the problem. If you do not understand recursion or the DNS query process, review conceptual topics in Help to better understand the issues involved.



Cause: The DNS server is not configured to use other DNS servers to assist it in resolving queries.

Solution: Check whether the DNS server can use both forwarders and recursion.

By default, all DNS servers are enabled to use recursion, although the option to disable its use is configurable using the DNS console to modify advanced server options. The other possibility where recursion might be disabled is if the server is configured to use forwarders and recursion has been specifically disabled for that configuration.


Cause: Current root hints for the DNS server are not valid.

Solution: Check whether server root hints are valid.

If configured and used correctly, root hints always should point to DNS servers authoritative for the zone containing the domain root and top-level domains.

By default, DNS servers are configured to use root hints appropriate to your deployment, based on the following available choices when using the DNS console to configure a server:

1. If the DNS server is installed as the first DNS server for your network, it is configured as a root server.

For this configuration, root hints are disabled at the server because the server is authoritative for the root zone.

2. If the installed server is an additional DNS server for your network, you can direct the Configure DNS Server Wizard to update its root hints from an existing DNS server on the network.

3. If you do not have other DNS servers on your network but still need to resolve Internet DNS names, you can use the default root hints file which includes a list of Internet root servers authoritative for the Internet DNS namespace.

Cause: The DNS server does not have network connectivity to the root servers.

Solution: Test for connectivity to the root servers.

If root hints appear to be configured correctly, verify that the DNS server used in a failed query can ping its root servers by IP address.

If a ping attempt to one root server fails, it might indicate that an IP address for that root server has changed. Reconfiguration of root servers, however, is uncommon.

A more likely cause is a full loss of network connectivity or in some cases, poor network performance on the intermediate network links between the DNS server and its configured root servers. Follow basic TCP/IP network troubleshooting steps to diagnose connections and determine whether this is the problem.

By default, the DNS service uses a recursive time-out of 15 seconds before failing a recursive query. Under normal network conditions, this time-out does not need to be changed. If performance warrants it, however, you can increase this value.

To review additional performance related information on DNS queries, you can enable and use the DNS server debug log file, Dns.log, which can provide extensive information about some types of service-related events.


Cause: Other problems exist with updating DNS server data, such as an issue related to zones or dynamic updates.

Solution: Determine whether the problem is related to zones. As needed, Troubleshoot any issues in this area, such as possible failure of zone transfer.

Wednesday, August 4, 2010

Socket Programming In C

Today we will discuss about Sockets programming paradigm, elements of Sockets applications, and the Sockets API. The Sockets API allows to develop applications that communicate over a network. The network can be a local private network or the public Internet. An important item about Sockets programming is that it's neither operating system specific nor language specific. Sockets applications can be written in the Ruby scripting language on a GNU/Linux host or in C on an embedded controller. This freedom and flexibility are the reasons that the BSD4.4 Sockets API is so popular.


Layered Model of Networking



Sockets programming uses the layered model of packet communication as shown in the figure below. At the top is the application layer, which is where the applications exist (those that utilize Sockets for communication). Below is the application layer defines the Sockets layer. This isn't actually a layer, but it is shown to illustrate where the API is located. The Sockets layer sits on top of the transport layer. The transport layer provides the transport protocols. Next is the network layer, which provides among other things routing over the Internet. This layer is occupied by the Internet Protocol, or IP. Finally, is the physical layer driver, which provides the means to introduce packets onto the physical network.



Sockets API Summary



The networking API for C provides a mixed set of functions for the development of client and server applications. Some functions are used by only server-side sockets, whereas others are used solely by client-side sockets (most are available to both).

Creating and Destroying Sockets

The first step of any Sockets-based application is to create a socket.The socket function provides the following prototype:

Code:
int socket( int domain, int type, int protocol );
The socket object is represented as a simple integer and is returned by the socket function. Three parameters must be passed to define the type of socket to be created. Right now, you are interested primarily in stream (TCP) and datagram (UDP) sockets, but many other types of sockets can be created. In addition to stream and datagram, a raw socket is also illustrated by the following code snippets:

Code:
myStreamSocket = socket( AF_INET, SOCK_STREAM, 0 );
myDgramSocket = socket( AF_INET, SOCK_DGRAM, 0 );
myRawSocket = socket( AF_INET, SOCK_RAW, IPPROTO_RAW );
The AF_INET symbolic constant indicates that we are using the IPv4 Internet protocol. After this, the second parameter (type) defines the semantics of communication. For stream communication (using TCP), you use the SOCK_STREAM type, and for datagram communication (using UDP), you specify SOCK_DGRAM. The third parameter can define a particular protocol to use, but only the types exist for stream and datagram, so this third parameter is left as zero in those cases.

When we've finished with a socket, we must close it. The close prototype is defined as follows:

Code:
int close( sock );
After close is called, no further data can be received through the socket. Any data queued for transmission is given some amount of time to be sent before the connection physically closes.

Socket Addresses

For socket communication over the Internet (domain AF_INET), we use the sock-addr_in structure for naming purposes.

Code:
struct sockaddr_in 
{
int16_t sin_family;
uint16_t sin_port;
struct in_addr sin_addr;
char sin_zero[8];
};
struct in_addr
{
uint32_t s_addr;
};
For Internet communication, we use AF_INET solely for sin_family. Field sin_port defines your specified port number in network byte order. Therefore, we must use htons to load the port and ntohs to read it from this structure. Field sin_addr is, through s_addr, a 32-bit field that represents an IPv4 Internet address.IPv4 addresses are 4-byte addresses. Often the sin_addr is set to INADDR_ANY, which is the wildcard. When you're accepting connections (server socket), this wildcard accepts connections from any available interface on the host. For client sockets, this is commonly left blank. For a client, sin_addr is set to the IP address of a local interface, this restricts outgoing connections to that interface.

Now let us take look at a quick example of addressing for both a client and a server. First, in this example we create the socket address (later to be bound to your server socket) that permits incoming connections on any interface and port 48000.
Code:
int servsock;
struct sockaddr_in servaddr;
servsock = socket( AF_INET, SOCK_STREAM, 0);
memset( &servaddr, 0, sizeof(servaddr) );
servaddr.sin_family = AF_INET;
servaddr.sin_port = htons( 48000 );
servaddr.sin_addr.s_addr = inet_addr( INADDR_ANY );
Next, we create a socket address that permits a client socket to connect to your previously created server socket.

Code:
int clisock;
struct sockaddr_in servaddr;
clisock = socket(AF_INET, SOCK_STREAM, 0);
memset(&servaddr, 0, sizeof(servaddr));
servaddr.sin_family = AF_INET;
servaddr.sin_port = htons(48000);
servaddr.sin_addr.s_addr = inet_addr("192.168.1.1");
Note the similarities between these two code segments. The difference,is that the server uses the address to bind to itself as an advertisement. The client uses this information to define to whom it wants to connect.

Socket Primitives



Now I will look at a number of other important server-side socket control primitives.

bind

The bind function provides a local naming capability to a socket. This can be used to name either client or server sockets, but it is used most often in the server case.

The bind function is provided by the following prototype:

Code:
int bind( int sock, struct sockaddr *addr, int addrLen );
The socket to be named is provided by the sock argument, and the address structure previously defined is defined by addr. Note that the structure here differs from the address structure discussed previously. The bind function can be used with a variety of different protocols, but when we are using a socket created with AF_INET, we must use the sockaddr_in. Therefore, as shown in the following example, we cast our sockaddr_in structure as sockaddr.

Code:
err = bind( servsock, (struct sockaddr *)&servaddr,sizeof(servaddr));
Using the address structure created in the server example in the previous address section, we bind the name defined by servaddr to our server socket servsock.

Recall that a client application can also call bind to name the client socket. This isn't used often, because the Sockets API dynamically assigns a port to us.

listen

Before a server socket can accept incoming client connections, it must call the listen function to declare this willingness. The listen function is provided by the following function prototype:

Code:
int listen( int sock, int backlog );
The sock argument represents the previously created server socket, and the backlog argument represents the number of outstanding client connections that might be queued. Within GNU/Linux, the backlog parameter (post 2.2 kernel version) represents the number of established connections pending on accept for the application layer protocol. Other operating systems might treat this differently.

accept

The accept call is the final call made by servers to accept incoming client connections. Before accept can be called, the server socket must be created, a name must be bound to it, and listen must be called. The accept function returns a socket descriptor for a client connection and is provided by the following function prototype:

Code:
int accept( int sock, struct sockaddr *addr, int *addrLen );
In practice, two examples of accept are commonly seen. The first represents the case in which we need to know who connected to us. This requires the creation of an address structure that is not initialized.
Code:
struct sockaddr_in cliaddr;
int cliLen;
cliLen = sizeof( struct sockaddr_in );
clisock = accept( servsock, (struct sockaddr *)cliaddr, &cliLen );
The call to accept blocks until a client connection is available. Upon return, the clisock return value contains the value of the new client socket, and cliaddr represents the address for the client peer (host address and port number).

The alternate example is commonly found when the server application isn't interested in the client information. This one typically appears as follows:

Code:
cliSock = accept( servsock, (struct sockaddr *)NULL, NULL );
In this case, NULL is passed for the address structure and length. The accept function then ignores these parameters.

connect

The connect function is used by client Sockets applications to connect to a server. Clients must have created a socket and then defined an address structure containing the host and port number to which they want to connect. The connect function is provided by the following function prototype:

Code:
int connect( int sock, (struct sockaddr *)servaddr, int addrLen );
The sock argument represents the client socket, created previously with the Sockets API function. The servaddr structure is the server peer to which you want to connect . Finally, we must pass in the length of your servaddr structure so that connect knows we are passing in a sockaddr_in structure.

The following code shows a complete example of connect:

Code:
int clisock;
struct sockaddr_in servaddr;
clisock = socket( AF_INET, SOCK_STREAM, 0);
memset( &servaddr, 0, sizeof(servaddr) );
servaddr.sin_family = AF_INET;
servaddr.sin_port = htons( 48000 );
servaddr.sin_addr.s_addr = inet_addr( "192.168.1.1" );
connect( clisock, (struct sockaddr_in *)&servaddr, sizeof(servaddr) );
The connect function blocks until either an error occurs or the three-way handshake with the server finishes. Any error is returned by the connect function.

Sockets I/O



A variety of API functions exist to read data from a socket or write data to a socket. Two of the API functions (recv, send) are used exclusively by sockets that are connected (such as stream sockets), whereas an alternative pair (recvfrom, sendto) is used exclusively by sockets that are unconnected (such as datagram sockets).

Connected Socket Functions

The send and recv functions are used to send a message to the peer socket endpoint and to receive a message from the peer socket endpoint. These functions have the following prototypes:

Code:
int send( int sock, const void *msg, int len, unsigned int flags );
int recv( int sock, void *buf, int len, unsigned int flags );
The send function takes as its first argument the socket descriptor from which to send the msg. The msg is defined as a (const void *) because the object referenced by msg is not altered by the send function. The number of bytes to be sent in msg is contained by the len argument. Finally, a flags argument can alter the behavior of the send call. An example of sending a string through a previously created stream socket is shown as follows:

Code:
strcpy( buf, "Hello\n");
send( sock, (void *)buf, strlen(buf), 0);
In this example, our character array is initialized by the strcpy function. This buffer is then sent through sock to the peer endpoint, with a length defined by the string length function, strlen. To see flags use let us take a look at one side effect of the send call. When send is called, it can block until all of the data contained within buf has been placed on the socket's send queue. If not enough space is available to do this, the send function blocks until space is available. If we want to avoid this blocking behavior and instead want the send call to simply return if sufficient space is available, we can set the MSG_DONTWAIT flag, such as follows:

Code:
send( sock, (void *)buf, strlen(buf), MSG_DONTWAIT);
The return value from send represents either an error (less than 0) or the number of bytes that were queued to be sent. Completion of the send function does not imply that the data was actually transmitted to the host, only that it is queued on the socket's send queue waiting to be transferred.
The recv function mirrors the send function in terms of an argument list. Instead of sending the data pointed to be msg, the recv function fills the buf argument with the bytes read from the socket. We must define the size of the buffer so that the network protocol stack doesn't overwrite the buffer, which is defined by the len argument. Finally, we can alter the behavior of the read call using the flags argument. The value returned by the recv function is the number of bytes now contained in the msg buffer, or -1 on error. An example of the recv function is as follows:

Code:
#define MAX_BUFFER_SIZE        50
char buffer[MAX_BUFFER_SIZE+1];
...
numBytes = recv( sock, buffer, MAX_BUFFER_SIZE, 0);
At completion of this example, numBytes contains the number of bytes that are contained within the buffer argument.
We can peek at the data that's available to read by using the MSG_PEEK flag. This performs a read, but it doesn't consume the data at the socket. This requires another recv to actually consume the available data. An example of this type of read is illustrated as follows:

Code:
numBytes = recv( sock, buffer, MAX_BUFFER_SIZE, MSG_PEEK);
This call requires an extra copy (the first to peek at the data, and the second to actually read and consume it). More often than not, this behavior is handled instead at the application layer by actually reading the data and then determining what action to take.

Unconnected Socket Functions

The sendto and recvfrom functions are used to send a message to the peer socket endpoint and receive a message from the peer socket endpoint. These functions have the following prototypes:

Code:
int sendto( int sock, const void *msg, int len,unsigned int flags,const struct sockaddr *to, int tolen );
int recvfrom( int sock, void *buf, int len,unsigned int flags,struct sockaddr *from, int *fromlen );
The sendto function is used by an unconnected socket to send a datagram to a destination defined by an initialized address structure. The sendto function is similar to the previously discussed send function, except that the recipient is defined by the to structure. An example of the sendto function is shown in the following code:

Code:
struct sockaddr_in destaddr;
int sock;
char *buf;
...
memset( &destaddr, 0, sizeof(destaddr) );
destaddr.sin_family = AF_INET;
destaddr.sin_port = htons(581);
destaddr.sin_addr.s_addr = inet_addr("192.168.1.1");
sendto( sock, buf, strlen(buf), 0,(struct sockaddr *)&destaddr, sizeof(destaddr) );
In this example, the datagram (contained with buf) is sent to an application on host 192.168.1.1, port number 581. The destaddr structure defines the intended recipient for the datagram.
As with the send function, the number of characters queued for transmission is returned, or -1 if an error occurs.

The recvfrom function provides the ability for an unconnected socket to receive datagrams. The recvfrom function is again similar to the recv function, but an address structure and length are provided. The address structure is used to return the sender of the datagram to the function caller. This information can be used with the sendto function to return a response datagram to the original sender.

An example of the recvfrom function is shown in the following code:

Code:
#define MAX_LEN 100
struct sockaddr_in fromaddr;
int sock, len, fromlen;
char buf[MAX_LEN+1];
...
fromlen = sizeof(fromaddr);
len = recvfrom( sock, buf, MAX_LEN, 0,(struct sockaddr *)&fromaddr, &fromlen );
This blocking call returns when either an error occurs (represented by a -1 return) or a datagram is received (return value of 0 or greater). The datagram is contained within buf and has a length of len. The fromaddr contains the datagram sender, specifically the host address and port number of the originating application.

Socket Options

Socket options permit an application to change some of the modifiable behaviors of sockets and the functions that manipulate them. For example, an application can modify the sizes of the send or receive socket buffers or the size of the maximum segment used by the TCP layer for a given socket.

The functions for setting or retrieving options for a given socket are provided by the following function prototypes:

Code:
int getsockopt( int sock, int level, int optname,void *optval, socklen_t *optlen );
int setsockopt( int sock, int level, int optname,const void *optval, socklen_t optlen );
First, we define the socket of interest using the sock argument. Next, we must define the level of the socket option that is being applied.

The level argument can be :
  • SOL_SOCKET for socket-layer options,
  • IPPROTO_IP for IP layer options, and
  • IPPROTO_TCP for TCP layer options.
The specific option within the level is applied using the optname argument. Arguments optval and optlen define the specifics of the value of the option. optval is used to get or set the option value, and optlen defines the length of the option. This slightly complicated structure is used because structures can be used to define options.

Now let us take a look at an example for both setting and retrieving an option. In the first example, we retrieve the size of the send buffer for a socket.

Code:
int sock, size, len;
...
getsockopt( sock, SOL_SOCKET, SO_SNDBUF, (void *)&size,
(socklen_t *)&len );
printf( "Send buffer size is &d\n", size );
Now let us take a look at a slightly more complicated example. In this case, we're going to set the [b]Socket linger option[b]. Socket linger allows you to change the behavior of a stream socket when the socket is closed and data is remaining to be sent. After close is called, any data remaining attempts to be sent for some amount of time. If after some duration the data cannot be sent, then the data to be sent is abandoned. The time after the close when the data is removed from the send queue is defined as the linger time. This can be set using a special structure called linger, as shown in the following example:

Code:
struct linger ling;
int sock;
...
ling.l_onoff = 1; /* Enable */
ling.l_linger = 10; /* 10 seconds */
setsockopt( sock, SOL_SOCKET, SO_LINGER,(void *)&ling, sizeof(struct linger) );
After this call is performed, the socket waits 10 seconds after the socket close before aborting the send.

Other Miscellaneous Functions

Now it's time to look at a few miscellaneous functions from the Sockets API and the capabilities they provide. The three function prototypes discussed in this section are shown in the following code:

Code:
struct hostent *gethostbyname( const char *name );
int getsockname( int sock, struct sockaddr *name, socklen_t*namelen );
int getpeername( int sock, struct sockaddr *name, socklen_t*namelen );
Function gethostbyname provides the means to resolve a host and domain name (otherwise known as a fully qualified domain name, or FQDN) to an IP address. For example, the FQDN of www.microsoft.com might resolve to the IP address 64.4.31.252. Converting an FQDN to an IP address is important because all of the Sockets API functions work with number IP addresses (32-bit addresses) rather than FQDNs.

An example of the gethostbyname function is shown below:

Code:
struct hostent *hptr;
hptr = gethostbyname( "www.microsoft.com");
if (hptr == NULL) // can't resolve...
else
{
printf("Binary address is %x\n", hptr-> h_addr_list[0]);
}
Function gethostbyname returns a pointer to a structure that represents the numeric IP address for the FQDN (hptr->h_addr_list[0]). Otherwise, gethostbyname returns a NULL, which means that the FQDN could not be resolved by the local resolver. This call blocks while the local resolver communicates with the configured DNS servers.

Function getsockname permits an application to retrieve information about the local socket endpoint. This function, for example, can identify the dynamically assigned ephemeral port number for the local socket.

An example of its use is shown in the following code:

Code:
int sock;
struct sockaddr localaddr;
int laddrlen;
// Socket for sock created and connected.
...
getsockname( sock, (struct sockaddr_in *)&localaddr, &laddrlen );
printf( "local port is %d\n", ntohs(localaddr.sin_port) );
The reciprocal function of getsockname is getpeername. This permits you to gather addressing information about the connected peer socket. An example, similar to the getsockname example, is shown in the following code:

Code:
int sock;
struct sockaddr remaddr;
int raddrlen;
// Socket for sock created and connected.
...
getpeername( sock, (struct sockaddr_in *)&remaddr, &raddrlen );
printf( "remote port is %d\n", ntohs(remaddr.sin_port) );
In both examples, the address can also be extracted using the sin_addr field of the sockaddr structure.

The osi model

"What is The OSI model? Is this related to any of the atom models done in old school ? Huh!" No, my friend the OSI model [OPEN SYSTEM INTERCONNECTION ] is a way of subdividing a system into smaller or simpler parts [ with respect to the communications ] called layers.

Things to remember
  1. A layer is a collection of services/functions .
  2. Each layer provides services to the layer above it and receive services from the layer below it.
  3. It have 7 layers coming to that in a minute.
Layers of the OSI model:-
  1. Application
  2. Presentation
  3. Session
  4. Transport
  5. Network
  6. Data-Link
  7. Physical layer
How to remember all these layers....

Yeah! I know that you guyz would be thinking how do I remember these stuff..

As usual I'll make it easy:-

Here comes the acronym to remember these layers with their orders . I came to know about this from a youtube video...
Code:
All        : application
People : presentation
Seem : session
to : transport
need : network
Data : data-link
processing : physical
What are these layers man What do they do..

Lets start explaining them 1 by 1 :-
  1. Application layer



    This layer is basically there so that you can interact with any application on the WWW or the world wide web or on your own network. Protocols in there are : HTTP , FTP , SMTP etc etc.........
  2. Presentation Layer



    This layer is the easiest one it deals with the ANCII code means it deals with the relationship between binary and letters.. We'll be doing the byte-ordering and conversion topics few pages down. Then you'll be able to properly understand this..
  3. Session Layer



    This one's easy too.. The dictionary meaning of session is : A period of time spend on a particular activity. What a session in OSI model means that it finds the destination PC on the network .

    Ask about can they initiate a connection between our comp's and theirs.

    In easy language it just there to establish a connection between the source computer to the destination.

    I'll make it easy :-

    Imagine you make a chat server program and decide to establish a connection between you and your friend so in that ,the role of this layer will be to carry the request from your computer to your friend's computer "knock knock" and ask him "Sir can we initiate a connection between each other and do some chat,if you dont mind"

    So that was the session layer.
  4. Transport



    In our case this is the most Important stuff . It contains the two most important protocols for us :- TCP and UDP .. I'll explain these two in a healthy 2 pages topic .. Which is coming next in the next tutorial.

    After this.
  5. Network layer



    This layer is also a very important layer. This is where IP : INETERNET PROTOCOL is found …

    We all know that net is like a matrix it is the most complex network so it has lots and lots of webs of wires so what the IP and other protocols here does that they find or actually they know the shortest and the most reliable way to connect host and the destination . I'll explain you this topic more clearly through the following "kind of picture"
    Code:
    ******                  Route 2nd                         ****** 
    * C1 *-------->------>------------>---------------------->* C2 *
    ****** ******
    | |
    | 1st route |
    | |
    ****** |
    * C3 *---------<---------------<--------------<----------<------
    ******
    In the above diagram there is a network of 3 computers C1,C2 and C3.

    We want to initiate a connection between C1 and C3. There are 2 routes :-

    The straight and the shorter route is "route 1st"

    The coiled , complex and the longer route is "route 2nd".

    You'll have a better understanding of this topic while in the next section. "When I'll talk about TCP/IP in more detail".
  6. Data-Link layer



    According to me it is the most confusing layer . It contains two sub-layers MAC and LLC:-

    MAC :- The id given to every network card manufactured.

    Is known as MAC address.

    Don't be confused between logical address and physical address .

    They both are different logical addresses are what we call IP addresses and physical addresses are one associated with this layer.
  7. Physical layer



    This is the most easy layer according to me It only deals with zeroes and ones yeah! Binary.. The ethernet cable , hub , switch , modem , etc etc all come in this layer....

Where he is getting us with all this stuff!!!" Sorry guyz but it is important if you want to be a good and a successful socket programmer you have to know about all this stuff so Fix in your seat and bear it with me....

Ip versions:-



Till date there are two IP VERSIONS :-

1.IPv4 [The old one but still the dominant one]
2.IPv6 [The new and the complex one]

The reason why we needed to get this new ip versions is that we were getting short of it "what" yes we were getting short of it..
Day by day the net was spreading more and more faster which lead to creation of new Ip version that is Ipv6...

What are thes Ipv4 and Ipv6 :-

See before getting what are these different versions and differentiate them i'd like you to introduce about.

What is an IP?

IP is known as Internet protocol it is the primary protocol in the Internet layer. It have many uses like incapsulation [ explained above ] , addressing , etc , etc....

But I'll only cover the basics:-

TCP/IP in terms of Addressing

Before talking in terms of the biggy big net I'll talk this topic with respect to a smaller network let call it "The tutorial network" .

What I did is that I connected 3 of my computers with each other . Ok . You are sitting at comp no.1 I'm at comp no.2 and my uncle "Mr Sachin Sharma " is sitting on the third . I requested to download a file name "blah blah blah.jpg " on the Sachin's computer [3rd computer] . Now suppose that you are the [3rd computer ] how will you find who wanted to download that file.

Here when the ip's comes in work .. You can actually suppose IP's as the names of computer.

Now when I'll make a request to read a file on comp 3rd The computer will respond back to my ip address .

The exact definition of IP address :-

It is a numeric address given to every device including/participating in a computer network.

That was IP in terms on Addressing.

More about ip :- http://en.wikipedia.org/wiki/Internet_Protocol

IPV4 and IPV6:-

As I explained above that IP is a numeric address given to every device participating in a computer network .whether its a mobile phone , a PSP etc etc..

IPV4 : It is a 32 bit ip version and the old one.

Eg:- 127.0.0.1

Yeah I'll explain you what is 32 bit.

Actually its a 4 byte address.

As there are 8 bits in each byte . And 8*4=32 . Got it …

Wait a sec I'll make it easy.

234.44.55.22

here:-

234 = 11101010 ? 8 bits
44 = 00101100 ? 8 bits
55 = 00110111 ? 8 bits
22 = 00010110 ? 8 bits

IPV6 :

See as, I said above we needed IPV6 as we were getting short of IPV4 addresses .

IPV6 are a 128 bit IP version . And they were invented in 1995 …

"Whats so cool about that" I was born in the same year... Yupiii!!!

LOL...

eg:-

1001:0bb8:65a3:08c1:1339:9b2d:1370:5434
You can also see a IP like this :-
0000:0000:0000:0000:1339:9b2d:1370:5434

in the form of this:-

::::1339:9b2d:1370:5434
or:-
::1339:9b2d:1370:5434

This is because the zeros in the IPV6 can be omitted.

Sunday, August 1, 2010

Troubleshooting DNS servers

There may be 3 problems we face when dealing with DNS server:
  • The DNS server is not responding to clients.
  • The DNS server does not resolve names correctly.
  • The DNS server appears to be affected by a problem for reasons not described above.
Dealing with this 1 by 1.
1. The DNS server is not responding to clients

Cause 1: Network failure

Solution: Check if the hardware is fully ok, i.e. adapters are properly plugged or not. Then check network connectivity by pinging other computers or routers (such as its default gateway) that are used and available on the same network as the affected DNS servers.


Cause2: Network is o.k. but non-responsive to client's query

Solution: If the DNS client can ping the DNS server, verify that the DNS server is started or not and is able to listen to client's request. Try using the nslookup command to test whether the server can respond to DNS clients. You need to install a package called dnsutils - which provide clients such as nslookup, host and other tools. The Berkeley Internet Name Domain (BIND) implements an Internet domain name server. his package delivers various client programs related to DNS that are derived from the BIND source tree.


Cause: The DNS server has restricted some IP addresses to which it will respond.
Solution: If above is the case, it is possible that the IP address being used by clients to contact it is not in the list of restricted IP addresses permitted to provide service to clients.   
Try testing the server for a response again, but specify a different IP address known to be in the restricted interfaces list for the server. If the DNS server responds for that address, add the missing server IP address to the list.

Cause: The DNS server has been configured to disable the use of its automatically created default reverse lookup zones.
Solution: Verify that automatically created reverse lookup zones have been created for the server or that advanced configuration changes have not been previously made to the server.

By default, DNS servers automatically create the following three standard reverse lookup zones based on Request for Comments (RFC) recommendations:

These zones are created with common IP addresses covered by these zones that are not useful in a reverse lookup search (0.0.0.0, 127.0.0.1, and 255.255.255.255). By being authoritative for the zones corresponding to these addresses, the DNS service avoids unnecessary recursion to root servers in order to perform reverse lookups on these types of IP addresses.

It is possible, although unlikely, that these automatic zones are not created. This is because disabling the creation of these zones involves advanced manual configuration of the server registry by a user.

To verify that these zones have been created, do the following:

1. Open the DNS console.

2. From the View menu, click Advanced.

3. In the console tree, click Reverse Lookup Zones.

Where?

* DNS/applicable DNS server/Reverse Lookup Zones

4. In the details pane, verify that the following reverse lookup zones are present:

* 0.in-addr.arpa

* 127.in-addr.arpa

* 255.in-addr.arpa

See also: Open the DNS console; DNS RFCs.

Cause: The DNS server is configured to use a non-default service port, such as in an advanced security or firewall configuration.
Solution: Verify that the DNS server is not using a non-standard configuration.

This is a rare but possible cause. By default, the nslookup command sends queries to targeted DNS servers using User Datagram Protocol (UDP) port 53. If the DNS server is located on another network only reachable through an intermediate host (such as a packet-filtering router or proxy server), the DNS server might use a non-standard port to listen for and receive client requests.

If this situation applies, determine whether any intermediate firewall or proxy server configuration is intentionally used to block traffic on well-known service ports used for DNS. If not, you might be able to add such a packet filter onto these configurations to permit traffic to standard DNS ports.

Also, check the DNS server event log to see if Event ID 414 or other critical service-related events have occurred which might indicate why the DNS server is not responding.

See also: DNS server log reference; View the DNS server system event log; Microsoft Windows Deployment and Resource Kits.
The DNS server does not resolve names correctly.

Cause: The DNS server provides incorrect data for queries it successfully answers.

Solution: Determine the cause of the incorrect data for the DNS server.

Some of the most likely causes include the following:

* Resource records (RRs) were not dynamically updated in a zone.

* An error was made when manually adding or modifying static resource records in the zone.

* Stale resource records in the DNS server database, left from cached lookups or zone records not updated with current information or removed when they are no longer needed.

To help prevent the most common types of problems, be sure to first review best practices for tips and suggestions on deploying and managing your DNS servers. Also, follow and use the checklists appropriate for installing and configuring DNS servers and clients based on your deployment needs.

If you are deploying DNS for Active Directory, note new directory integration features. These features can cause some differences for DNS server defaults when the DNS database is directory-integrated, that differ from those used with traditional file-based storage.

Many DNS server problems start with failed queries at a client, so it is often good to start there and troubleshoot the DNS client first.

See also: DNS best practices; DNS Checklists; Troubleshooting DNS clients; Modify an existing resource record in a zone; Clear the server names cache; Modifying server defaults.

Cause: The DNS server does not resolve names for computers or services outside of your immediate network, such as those located on external networks or the Internet.

Solution: The server has a problem based on its ability to correctly perform recursion. Recursion is used in most DNS configurations to resolve names that are not located within the configured DNS domain name used by the DNS servers and clients.

If a DNS server fails to resolve a name for which it is not authoritative, the cause is usually a failed recursive query. Recursive queries are used frequently by DNS servers to resolve remote names delegated to other DNS zones and servers.

For recursion to work successfully, all DNS servers used in the path of a recursive query must be able to respond to and forward correct data. If not, a recursive query can fail for any of the following reasons:

* The recursive query times out before it can be completed.

* A remote DNS server fails to respond.

* A remote DNS server provides incorrect data.

If a server fails a recursive query for a remote name, review the following possible causes to troubleshoot the problem. If you do not understand recursion or the DNS query process, review conceptual topics in Help to better understand the issues involved.

See also: How DNS query works.

Cause: The DNS server is not configured to use other DNS servers to assist it in resolving queries.

Solution: Check whether the DNS server can use both forwarders and recursion.

By default, all DNS servers are enabled to use recursion, although the option to disable its use is configurable using the DNS console to modify advanced server options. The other possibility where recursion might be disabled is if the server is configured to use forwarders and recursion has been specifically disabled for that configuration.

Note

* If you disable recursion on the DNS server, you will not be able to use forwarders on the same server.

See also: Disable recursion on the DNS server; Configure a DNS server to use forwarders.

Cause: Current root hints for the DNS server are not valid.
Solution: Check whether server root hints are valid.

If configured and used correctly, root hints always should point to DNS servers authoritative for the zone containing the domain root and top-level domains.

By default, DNS servers are configured to use root hints appropriate to your deployment, based on the following available choices when using the DNS console to configure a server:

1. If the DNS server is installed as the first DNS server for your network, it is configured as a root server.

For this configuration, root hints are disabled at the server because the server is authoritative for the root zone.

2. If the installed server is an additional DNS server for your network, you can direct the Configure DNS Server Wizard to update its root hints from an existing DNS server on the network.

3. If you do not have other DNS servers on your network but still need to resolve Internet DNS names, you can use the default root hints file which includes a list of Internet root servers authoritative for the Internet DNS namespace.

See also: Update root hints on the DNS server; Updating root hints.

Cause: The DNS server does not have network connectivity to the root servers.
Solution: Test for connectivity to the root servers.

If root hints appear to be configured correctly, verify that the DNS server used in a failed query can ping its root servers by IP address.

If a ping attempt to one root server fails, it might indicate that an IP address for that root server has changed. Reconfiguration of root servers, however, is uncommon.

A more likely cause is a full loss of network connectivity or in some cases, poor network performance on the intermediate network links between the DNS server and its configured root servers. Follow basic TCP/IP network troubleshooting steps to diagnose connections and determine whether this is the problem.

By default, the DNS service uses a recursive time-out of 15 seconds before failing a recursive query. Under normal network conditions, this time-out does not need to be changed. If performance warrants it, however, you can increase this value.

To review additional performance related information on DNS queries, you can enable and use the DNS server debug log file, Dns.log, which can provide extensive information about some types of service-related events.

See also: Test a TCP/IP configuration by using the ping command; Using server debug logging options; View a DNS server debug log file; Tuning advanced server parameters.

Cause: Other problems exist with updating DNS server data, such as an issue related to zones or dynamic updates.
Solution: Determine whether the problem is related to zones. As needed, Troubleshoot any issues in this area, such as possible failure of zone transfer.

Namespaces in internet

The Internet maintains two principal namespaces, the domain name hierarchy and the Internet Protocol (IP) address system.The Domain Name System maintains the domain namespace and provides translation services between these two namespaces. Internet name servers and a communications protocol implement the Domain Name System A DNS name server is a server that stores the DNS records, such as address (A) records, name server (NS) records, and mail exchanger (MX) records for a domain name (see also List of DNS record types) and responds with answers to queries against its database.

Namespaces in internet

The Internet maintains two principal namespaces, the domain name hierarchy and the Internet Protocol (IP) address system. The Domain Name System maintains the domain namespace and provides translation services between these two namespaces. Internet name servers and a communications protocol implement the Domain Name System. A DNS name server is a server that stores the DNS records, such as address (A) records, name server (NS) records, and mail exchanger (MX) records for a domain name (see also List of DNS record types) and responds with answers to queries against its database.

Saturday, March 27, 2010

Simplified IP Addressing

Basics
The first question concerns what constitutes a Class A, or a Class B, etc. network. Novices have trouble remembering where each class begins and ends. Table 3 shows a schema to help with this. First, let's discuss some basics of binary numbers.
A byte is a grouping of eight binary bits. Since a binary bit is either a 0 or a 1, a byte consists of eight 0s and/or 1s. No mystery here. So 10010101 is one byte and 11100000 is another. How do we convert these to decimal numbers? It turns out that the right-most bit has a weight of 1 (2<+>0<+>). The next bit to its left has a weight of 2 (2<+>1<+>), the next has a weight of 4 (2<+>2<+>), i.e., two raised to the second power and so on:
2
or equivalently:
128  64  32  16  8  4  2  1     : decimal weights
Thus, the binary number 10101001 has a decimal equivalent of
1x1 + 1x8 + 1x32 + 1x128 = 169
If you assign contiguous 1s starting from the right, the above diagram can be used as a kind of calculator. Let's say you have 00001111 binary bits. To get the decimal equivalent, you could do the calculations the hard way, that is:
1x1 + 1x2 + 1x4 + 1x8 = 15
or you could note the following (taking our number):
128  64  32  16  8  4  2  1     :decimal weights
0 0 0 0 1 1 1 1 :binary number
If you have all ones starting at the right side, you can simply take the weight of the first 0 bit (16 in this case), subtract 1, and you have 15—the decimal equivalent—without having to use a calculator. Thus, if all the bits on the right are 1s, you can determine the decimal value by using the above diagram as a kind of calculator. Note that the bits go up in powers of 2, so the ninth bit has a decimal weight of 256. So if you have a byte with all ones, i.e., 11111111, then it has a decimal value of 255 (256 -1). 255 appears many times in IP addressing.

Table 1. Decimal Equivalents for Netmasking

128 64 32 16 8 4 2 1 decimal
1 0 0 0 0 0 0 0 128
1 1 0 0 0 0 0 0 192
1 1 1 0 0 0 0 0 224
1 1 1 1 0 0 0 0 240
1 1 1 1 1 0 0 0 248
1 1 1 1 1 1 0 0 252
1 1 1 1 1 1 1 0 254
1 1 1 1 1 1 1 1 255
Now we need to construct another calculator for handy reference (see Table 1). There is a thing called netmasking, which I will discuss later on. Standard procedure says to start the masking from the left and work down. So, if you make the eighth, or high-order bit, 1 and the rest equal to 0, the decimal equivalent is 128; if you made the first three bits 1 and the rest 0, the decimal equivalent is 224, etc.

Table 2. Shortened Netmask Table

128 64 32 16 8 4 2 1 Binary
128 192 224 240 248 252 254 255 Decimal

This table works fine, but is a bit unwieldy. Table 2 shows a short version. It says that if your byte is 11100000, then the decimal equivalent value is 224. If this bothers you, just use Table 1.
IP Addresses
We have set the groundwork for IP addressing, and I will now discuss the standard IPv4 addresses. The IP addresses are sometimes called “dotted quad” numbers. There are five classes of IP addresses, i.e., A, B, C, D and E. Classes D and E are reserved so you can work with classes A, B and C. However, I will show all five here. The class is determined from the first byte. Thus, an IP address of 205.140.187.31 is a class C address, since the first byte is 205. How do I know that? Well, let's look at Table 3.

Table 3. Classes of IP Addresses


High-Ordered Byte
Class Binary Decimal Decimal

Starting Starting Ending

Point Point Point
A 0 0 126



127 (loop-back)
B 10 128 191
C 110 192 223
D 1110 224 239
E 11110 240 247

How did I get Table 3? I had to remember only a couple of pieces of information, then I constructed the rest. I know there are five classes of IP addresses, and the first byte of the IP address tells you to which class it belongs. I also know the schema for the binary starting value of the first byte, i.e., 0, 10, 110, etc. Because of the way it follows a schema, the second column is easy to construct. Now, using Table 2, it was easy to construct the third column.
Next, note that the fourth column (ending point) follows naturally by simply subtracting one from the beginning of the next class. A class C begins at 192, while a class D begins at 224. Hence, a class C must end at 223. Now you have no excuses about forgetting the beginning and ending points of each class; merely remember the binary schema, and take a minute to construct the table. On a side note, you don't have to worry about Classes D and E, except that the beginning of Class D tells you where Class C ends by subtracting 1.
Bitwise AND
We need to discuss netmasking, but first, let's digress for a moment. A Boolean AND is just like an “and” in English. You tell Johnny you will buy him an ice cream cone if he puts out the trash “and” makes his bed. If he does neither or only one of them, he doesn't get an ice cream cone. If he does both, he gets the cone.

Table 4. Bit-Wise Logical AND Truth Table

First Second Result
Bit Bit
0 0 0
0 1 0
1 0 0
1 1 1

Bitwise ANDs work bit by bit. So, if you AND a 1 with a 1, you get a 1. If you AND two 0s, a 1 and a 0, or a 0 and a 1, however, you get a 0. Table 4 illustrates this operation.
Now let's take a whole byte and do a Logical AND with another byte. Suppose the first byte is 10110010 and the second byte is 01100111. Working from the right, note that the first byte has a decimal value of
0*1 + 1*2 + 0*4 + 0*8 + 1*16 + 1*32 + 0*64 + 1*128 = 178
while the second byte has a decimal value of
1*1 + 1*2 + 1*4 + 0*8 + 0*16 + 1*32 + 1*64 + 0*128 = 103.
Now, AND the two bytes:
1 0 1 1 0 0 1 0         178 decimal, ANDed with
0 1 1 0 0 1 1 1 103 decimal
--------------- gives
0 0 1 0 0 0 1 0 34 decimal
As a second example, let's AND 178 with 255.
1 0 1 1 0 0 1 0         178 decimal, ANDed with
1 1 1 1 1 1 1 1 255 decimal
--------------- gives
1 0 1 1 0 0 1 0 178 decimal
We know, then, that when you bit-wise AND any byte (number) with 255, you get the number dropping through, i.e., the result is merely the number again.
Netmasking
The default netmasks for the various classes are shown in Table 5 with some sample host IP addresses. Simply put, a host is anything that has an IP address. This includes servers, workstations, routers, etc.

Table 5. Default Netmasks, etc.

Class Default Meaning of Sample Sample

Net-Mask IP (Host) Host Network


Address Address Address
A 255.0.0.0 N.H.H.H 10.0.1.23 10.0.0.0
B 255.255.0.0 N.N.H.H 146.87.12.250 146.87.0.0
C 255.255.255.0 N.N.N.H 200.150.189.31 200.150.189.0

So, what does this mean and what do we do with it? Let's work through Table 5. If we take the sample Class A address, 10.0.1.23 and bit-wise AND it with its default netmask, we obtain 10.0.0.0. What is 10.0.0.0? It's the network address—look at the last column.
Notice that the first byte gives the network address when ANDing a Class A network with its default netmask, while the first two bytes give the network address when ANDing a Class B IP address with the default Class B netmask. Hence, we say that the first byte of a Class A IP address gives the network address, and the three remaining bytes give the host addresses, i.e., a Class A address has the form N.H.H.H where N stands for Network and H stands for Host. Likewise, the first two bytes of a Class B IP address pertain to the network, and the last two bytes pertain to the host address, i.e., N.N.H.H. Finally, the first three bytes of a Class C IP address pertain to the network, while the last byte pertains to the host, i.e., N.N.N.H.
Subnetting
Let's illustrate this with a Class B IP address such as 142.168.25.100. From Table 5, we know that the default netmask for a Class B network is 255.255.0.0. Hence, ANDing the default mask with the IP address yields the address of the network that particular host is on, i.e., 142.168.0.0. So, a host with an IP address of 142.168.25.100 finds itself on a network with an IP address of 142.168.0.0 if a default Class B net-mask is used.
If you are granted a full Class B suite of addresses with a network address of 142.168.0.0, what do you do with them? Remember, a Class B network has the form of N.N.H.H, i.e., the last two bytes can be used for assigning host IP addresses. This yields a network with 2<+>16<+> - 2 host addresses. The -2 comes from the fact that 142.168.0.0 is the network address, so it can't be assigned to a host; the last address on the network, 142.168.255.255, is used for broadcasts, so it also can't be assigned to a host.
This would be a very big network (65,534 host addresses), far too big to be practical. A very simple approach is to “borrow” one byte's worth of host addresses and assign them as network addresses. That would yield 2<+>8<+> = 256 networks with 254 hosts on each. Even here, these are large networks. This process of borrowing host addresses and using them for networks is called subnetting. We accomplish this by using a sub-netmask (SNM). In this case, we would use a sub-netmask of 255.255.255.0, which is the default Class C netmask. Hence, we have taken one Class B network and turned it into 256 Class C networks.
If we AND 142.168.25.100 with 255.255.255.0, we get a network address of 142.168.25.0 with the first available host address of 142.168.25.1 and the last of 142.168.25.254, since 142.168.25.255 is reserved for broadcasts. Another way of doing this is to start with the network address (142.168.25.0 in this case), turn all host bits into 1s, and obtain the broadcast address. Here, the last byte is used for host addresses, so turning them to ones gives 142.168.25.255. This type of broadcast is called a directed broadcast, meaning that it jumps routers while a local broadcast (which doesn't jump routers) has the form 255.255.255.255 no matter which class of network is involved.
If you're not too stunned at this point, you may wonder if you can subnet only on byte boundaries or if you can subnet a Class C network. The answers are “no” and “yes”, respectively; i.e., you can work in the middle of a byte.
Subnetting on Non-Byte Boundaries
Let's say you are granted a full Class C suite of addresses, e.g., 210.168.94.0 as your network address. You are allowed to assign the host addresses (the last byte) as you please. If you use the default Class C netmask of 255.255.255.0 (see Table 5), you can assign host addresses of 210.168.94.1 through 210.168.94.254 on a single network. That's feasible of course, but you may want to break this up into multiple networks of perhaps 25 hosts each.
Let's do some mathematics. If we have 4 bits for hosts, will it be enough? 2<+>4<+>-2 = 14 and is not enough. So, let's use 5 bits for hosts: 2<+>5<+>-2 = 30 which will work. However, we have 8 bits in the last byte for hosts, so let's borrow three bits for subnetworks; then we still have the requisite 5 bits for hosts. Great, but how many subnets do we have? How about 2<+>3<+> = 8? We have, then, eight subnetworks with 30 host addresses on each. If you are doing the math, you are probably saying, “but 8x30 is only 240 addresses; what happened to the others?” Valid question! Oops, don't get sore, but it's time to construct another table. Note that each address will have the form of 210.168.94.last byte, and the SNM (sub-netmask) will have the form 255.255.255.last byte. Let's just work with the last byte.

Table 6. Subnetworks for Class C Network (shows the last byte)

Binary Decimal
Number Equivalent
00000000 0
00100000 32
01000000 64
01100000 96
10000000 128
10100000 160
11000000 192
11100000 224

From Table 2 (or Table 1), we see the SNM will be 255.255.255.224. The 224 comes from the last byte being 11100000. So what are the subnets? Table 6 shows them (last byte only).
Let's detail a few. First, take the smallest. The full subnetwork address of the smallest is 210.168.94.0. The next one up is 210.168.94.32, and so on. Remember that with three bits to work with, we get 2<+>3<+> = 8 subnets, and looking at Table 6, you see them.

Table 7. Analysis of 256 Values of Last Byte

Last Byte What Why
Addresses Happens  
  to Them  
0 invalid first subnet address
1-30 valid hosts on first subnet
31 invalid broadcast address of first subnet
32 invalid second subnet address
33-62 valid hosts for second subnet
63 invalid broadcast address of second subnet
64 invalid third subnet address
65-94 valid hosts for third subnet
95 invalid broadcast address of third subnet
96 invalid fourth subnet address
97-126 valid hosts for fourth subnet
127 invalid broadcast address of fourth subnet
128 invalid fifth subnet address
129-158 valid hosts for fifth subnet
159 invalid broadcast address of fifth subnet
160 invalid sixth subnet address
161-190 valid hosts for sixth subnet
191 invalid broadcast address of sixth subnet
192 invalid seventh subnet address
193-222 valid hosts for seventh subnet
223 invalid broadcast address of seventh subnet
224 invalid eighth subnet address
225-254 valid hosts for eighth subnet
255 invalid broadcast for eighth subnet

Back to the question of why we get only 240 host addresses. “(Gasp)—another table!” Looking at the last byte, we get Table 7.
Now let's answer the question of what happened to the other addresses. To do this, tally all the “invalid addresses”, i.e., those that can't be used for host addresses.
First, we have eight subnets, each with a subnetwork address and a broadcast address. So we lose 8*2 = 16 addresses here. Now if we subtract these 16 from 256, we get 240 available host addresses.
Doing it the other way is much easier. We have eight subnetworks, each with 30 valid IP addresses; this gives us 8*30=240 valid IP addresses total, the magic number.
For fun, let's do one more thing: analyze the sixth subnetwork in a little more detail. The last byte is 10100000 binary or 160 decimal. The full subnet address is 210.168.94.160 decimal, and we use an SNM of 255.255.255.224. Remember, I said to take the subnet address, set all the host bits to 1s and add them to get the broadcast address. If we do this correctly, it should give the same result as Table 7.
We use five bits for host addresses, so the decimal value of the sixth bit is 32. Subtracting 1 gives 31. Thus, setting the five host bits to 1s, i.e., 00011111, gives a value of 31 decimal. Adding this to the last byte of the subnet address (160) gives 191 for the broadcast address, agreeing with Table 7. Here is the “whole Megillah”:
210.168.94.160 The Sub-Network address210.168.94.161-190 Valid host addresses210.168.94.191 Directed Broadcast address
One final point. Some authors use the term “sub-netmask” even when referring to the default netmasks—they are being just a tad loose with their terms. Happy IP addressing, and remember, Linux is inevitable.

Wednesday, December 9, 2009

Some basic networking interview questions

1. What are 10Base2, 10Base5 and 10BaseT Ethernet LANs
10Base2—An Ethernet term meaning a maximum transfer rate of 10 Megabits per second that uses
baseband
signaling, with a contiguous cable segment length of 100
meters and a maximum of 2 segments.
10Base5—An Ethernet term meaning a maximum transfer rate of 10 Megabits per second that uses
baseband
signaling, with 5 continuous segments not exceeding 100
meters per segment.
10BaseT—An Ethernet term meaning a maximum transfer rate of 10 Megabits per second that uses
baseband
signaling and twisted pair cabling.
2. Explain the difference between an unspecified passive open and a fully specified passive open
An unspecified passive open has the server waiting for a connection request from a client. A fully
specified passive
open has the server waiting for a connection from a
specific client.
3. Explain the function of Transmission Control Block
A TCB is a complex data structure that contains a considerable amount of information about each
connection.
4. Explain a Management Information Base (MIB)
A Management Information Base is part of every SNMP-managed device. Each SNMP agent has the
MIB database that
contains information about the device's status, its
performance, connections, and configuration. The MIB is queried by SNMP.
5. Explain anonymous FTP and why would you use it
Anonymous FTP enables users to connect to a host without using a valid login and password. Usually,
anonymous FTP
uses a login called anonymous or guest, with the
password usually requesting the user's ID for tracking purposes only. Anonymous FTP is used to
enable a large number
of users to access files on the host without having
to go to the trouble of setting up logins for them all. Anonymous FTP systems usually have strict
controls over the areas
an anonymous user can access.
6. Explain a pseudo tty
A pseudo tty or false terminal enables external machines to connect through Telnet or rlogin. Without
a pseudo tty, no
connection can take place.
7. Explain REX
What advantage does REX offer other similar utilities
8. What does the Mount protocol do
The Mount protocol returns a file handle and the name of the file system in which a requested file
resides. The message
is sent to the client from the server after reception
of a client's request.
9. Explain External Data Representation
External Data Representation is a method of encoding data within an RPC message, used to ensure
that the data is not
system-dependent.
10. Explain the Network Time Protocol ?
11. BOOTP helps a diskless workstation boot. How does it get a message to the network looking for
its IP address and the location of its operating system boot files
BOOTP sends a UDP message with a subnetwork broadcast address and waits for a reply from a
server that gives it the IP address. The same message might contain the name of the machine that has
the boot files on it. If the boot image location is not specified, the workstation sends another UDP
message to query the server.
12. Explain a DNS resource record
A resource record is an entry in a name server's database. There are several types of resource records
used, including name-to-address resolution information. Resource records are maintained as ASCII
files.
13. What protocol is used by DNS name servers
DNS uses UDP for communication between servers. It is a better choice than TCP because of the
improved speed a connectionless protocol offers. Of course, transmission reliability suffers with UDP.
14. Explain the difference between interior and exterior neighbor gateways
Interior gateways connect LANs of one organization, whereas exterior gateways connect the
organization to the outside world.
15. Explain the HELLO protocol used for
The HELLO protocol uses time instead of distance to determine optimal routing. It is an alternative to
the Routing Information Protocol.
16. What are the advantages and disadvantages of the three types of routing tables
The three types of routing tables are fixed, dynamic, and fixed central. The fixed table must be
manually modified every time there is a change. A dynamic table changes its information based on
network traffic, reducing the amount of manual maintenance. A fixed central table lets a manager
modify only one table, which is then read by other devices. The fixed central table reduces the need to
update each machine's table, as with the fixed table. Usually a dynamic table causes the fewest
problems for a network
administrator, although the table's contents can change without the administrator being aware of the
change.
17. Explain a TCP connection table
18. Explain source route
It is a sequence of IP addresses identifying the route a datagram must follow. A source route may
optionally be included in an IP datagram header.
19. Explain RIP (Routing Information Protocol)
It is a simple protocol used to exchange information between the routers.
20. Explain SLIP (Serial Line Interface Protocol)
It is a very simple protocol used for transmission of IP datagrams across a serial line.
21. Explain Proxy ARP
It is using a router to answer ARP requests. This will be done when the originating host believes that a
destination is local, when in fact is lies beyond router.
22. Explain OSPF
It is an Internet routing protocol that scales well, can route traffic along multiple paths, and uses
knowledge of an Internet's topology to make accurate routing decisions.
23. Explain Kerberos
It is an authentication service developed at the Massachusetts Institute of Technology. Kerberos uses
encryption to prevent intruders from discovering passwords and gaining unauthorized access to files.
24. Explain a Multi-homed Host
It is a host that has a multiple network interfaces and that requires multiple IP addresses is called as a
Multi-homed Host.
25. Explain NVT (Network Virtual Terminal)
It is a set of rules defining a very simple virtual terminal interaction. The NVT is used in the start of a
Telnet session.
26. Explain Gateway-to-Gateway protocol
It is a protocol formerly used to exchange routing information between Internet core routers.
27. Explain BGP (Border Gateway Protocol)
It is a protocol used to advertise the set of networks that can be reached with in an autonomous
system. BGP enables this information to be shared with the autonomous system. This is newer than
EGP (Exterior Gateway Protocol).
28. Explain autonomous system
It is a collection of routers under the control of a single administrative authority and that uses a
common Interior Gateway Protocol.
29. Explain EGP (Exterior Gateway Protocol)
It is the protocol the routers in neighboring autonomous systems use to identify the set of networks
that can be reached
within or via each autonomous system.
30. Explain IGP (Interior Gateway Protocol)
It is any routing protocol used within an autonomous system.
31. Explain Mail Gateway
It is a system that performs a protocol translation between different electronic mail delivery protocols.
32. Explain wide-mouth frog
Wide-mouth frog is the simplest known key distribution center (KDC) authentication protocol.
33. What are Digrams and Trigrams
The most common two letter combinations are called as digrams. e.g. th, in, er, re and an. The most
common three letter combinations are called as trigrams. e.g. the, ing, and, and ion.
34. Explain silly window syndrome
It is a problem that can ruin TCP performance. This problem occurs when data are passed to the
sending TCP entity in large blocks, but an interactive application on the receiving side reads 1 byte at
a time.
35. Explain region
When hierarchical routing is used, the routers are divided into what we call regions, with each router
knowing all the details about how to route packets to destinations within its own region, but knowing
nothing about the internal structure of other regions.
36. Explain multicast routing
Sending a message to a group is called multicasting, and its routing algorithm is called multicast
routing.
37. Explain traffic shaping
One of the main causes of congestion is that traffic is often busy. If hosts could be made to transmit at
a uniform rate, congestion would be less common. Another open loop method to help manage
congestion is forcing the packet to be transmitted at a more predictable rate. This is called traffic
shaping.
38. Explain packet filter
Packet filter is a standard router equipped with some extra functionality. The extra functionality allows
every incoming or outgoing packet to be inspected. Packets meeting some criterion are forwarded
normally. Those that fail the test are dropped.
39. Explain virtual path
Along any transmission path from a given source to a given destination, a group of virtual circuits can
be grouped together into what is called path.
40. Explain virtual channel
Virtual channel is normally a connection from one source to one destination, although multicast
connections are also permitted. The other name for virtual channel is virtual circuit.
41. Explain logical link control
One of two sublayers of the data link layer of OSI reference model, as defined by the IEEE 802
standard. This sublayer is responsible for maintaining the link between computers when they are
sending data across the physical network connection.
42. Why should you care about the OSI Reference Model
It provides a framework for discussing network operations and design.
43. Explain the difference between routable and non- routable protocols
Routable protocols can work with a router and can be used to build large networks. Non-Routable
protocols are designed to work on small, local networks and cannot be used with a router
44. Explain MAU
In token Ring , hub is called Multistation Access Unit(MAU).
45. Explain 5-4-3 rule
In a Ethernet network, between any two points on the network, there can be no more than five network
segments or four repeaters, and of those five segments only three of segments can be populated.
46. Explain the difference between TFTP and FTP application layer protocols
The Trivial File Transfer Protocol (TFTP) allows a local host to obtain files from a remote host but
does not provide reliability or security. It uses the fundamental packet delivery services offered by
UDP.
The File Transfer Protocol (FTP) is the standard mechanism provided by TCP / IP for copying a file
from one host to another. It uses the services offered by TCP and so is reliable and secure. It
establishes two connections (virtual circuits) between the hosts, one for data transfer and another for
control information.
47. Explain the range of addresses in the classes of internet addresses
Class A 0.0.0.0 - 127.255.255.255
Class B 128.0.0.0 - 191.255.255.255
Class C 192.0.0.0 - 223.255.255.255
Class D 224.0.0.0 - 239.255.255.255
Class E 240.0.0.0 - 247.255.255.255
48. Explain the minimum and maximum length of the header in the TCP segment and IP datagram
The header should have a minimum length of 20 bytes and can have a maximum length of 60 bytes.
49. Explain difference between ARP and RARP
The address resolution protocol (ARP) is used to associate the 32 bit IP address with the 48 bit
physical address, used by a host or a router to find the physical address of another host on its network
by sending a ARP query packet that includes the IP address of the receiver. The reverse address
resolution protocol (RARP) allows a host to discover its Internet address when it knows only its
physical address.
50. Explain ICMP
ICMP is Internet Control Message Protocol, a network layer protocol of the TCP/IP suite used by
hosts and gateways to send notification of datagram problems back to the sender. It uses the echo test /
reply to test whether a destination is reachable and responding. It also handles both control and error
messages.
51. What are the data units at different layers of the TCP / IP protocol suite
The data unit created at the application layer is called a message, at the transport layer the data unit
created is called either a segment or an user datagram, at the network layer the data unit created is
called the datagram, at the data link layer the datagram is encapsulated in to a frame and
finally transmitted as signals along the transmission media.
52. Explain Project 802
It is a project started by IEEE to set standards that enable intercommunication between equipment
from a variety of manufacturers. It is a way for specifying functions of the physical layer, the data link
layer and to some extent the network layer to allow for interconnectivity of major LAN protocols.
It consists of the following:
802.1 is an internetworking standard for compatibility of different LANs and MANs across protocols.
802.2 Logical link control (LLC) is the upper sublayer of the data link layer which is non-architecturespecific,
that is remains the same for all IEEE-defined LANs.
Media access control (MAC) is the lower sublayer of the data link layer that contains some distinct
modules each carrying proprietary information specific to the LAN product being used. The modules
are Ethernet LAN (802.3), Token ring LAN (802.4), Token bus LAN (802.5).
802.6 is distributed queue dual bus (DQDB) designed to be used in MANs.
53. Explain Bandwidth
Every line has an upper limit and a lower limit on the frequency of signals it can carry. This limited
range is called the bandwidth.
54. Difference between bit rate and baud rate.
Bit rate is the number of bits transmitted during one second whereas baud rate refers to the number of
signal units per second that are required to represent those bits. baud rate = bit rate / N where N is noof-
bits represented by each signal shift.
55. Explain MAC address
The address for a device as it is identified at the Media Access Control (MAC) layer in the network
architecture. MAC address is usually stored in ROM on the network adapter card and is unique.
56. Explain attenuation
The degeneration of a signal over distance on a network cable is called attenuation.
57. Explain cladding
A layer of a glass surrounding the center fiber of glass inside a fiber-optic cable.
58. Explain RAID
A method for providing fault tolerance by using multiple hard disk drives.
59. Explain NETBIOS and NETBEUI
NETBIOS is a programming interface that allows I/O requests to be sent to and received from a
remote computer and it hides the networking hardware from applications. NETBEUI is NetBIOS
extended user interface. A transport protocol designed by microsoft and IBM for the use on small
subnets.
60. Explain redirector
Redirector is software that intercepts file or prints I/O requests and translates them into network
requests. This comes under presentation layer.
61. Explain Beaconing
The process that allows a network to self-repair networks problems. The stations on the network
notify the other stations on the ring when they are not receiving the transmissions. Beaconing is used
in Token ring and FDDI networks.
62. Explain terminal emulation, in which layer it comes
Telnet is also called as terminal emulation. It belongs to application layer.
63. Explain frame relay, in which layer it comes
Frame relay is a packet switching technology. It will operate in the data link layer.
64. What do you meant by "triple X" in Networks
The function of PAD (Packet Assembler Disassembler) is described in a document known as X.3. The
standard protocol has been defined between the terminal and the PAD, called X.28; another standard
protocol exists between hte PAD and the network, called X.29. Together, these three recommendations
are often called "triple X"
65. Explain SAP
Series of interface points that allow other computers to communicate with the other layers of network
protocol stack.
66. Explain subnet
A generic term for section of a large networks usually separated by a bridge or router.
67. Explain Brouter
Hybrid devices that combine the features of both bridges and routers.
68. How Gateway is different from Routers
A gateway operates at the upper levels of the OSI model and translates information between two
completely different network architectures or data formats.
69. What are the different type of networking / internetworking devices
Repeater: Also called a regenerator, it is an electronic device that operates only at physical layer. It
receives the signal in the network before it becomes weak, regenerates the original bit pattern and puts
the refreshed copy back in to the link.
Bridges: These operate both in the physical and data link layers of LANs of same type. They divide a
larger network in to smaller segments. They contain logic that allow them to keep the traffic for each
segment separate and thus are repeaters that relay a frame only the side of the segment containing the
intended recipent and control congestion.
Routers: They relay packets among multiple interconnected networks (i.e. LANs of different type).
They operate in the physical, data link and network layers. They contain software that enable them to
determine which of the several possible paths is the best for a particular transmission.
Gateways:
They relay packets among networks that have different protocols (e.g. between a LAN and a WAN).
They accept a packet formatted for one protocol and convert it to a packet formatted for another
protocol before forwarding it. They operate in all seven layers of the OSI model.
70. Explain mesh network
A network in which there are multiple network links between computers to provide multiple paths for
data to travel.
71. Explain passive topology
When the computers on the network simply listen and receive the signal, they are referred to as
passive because they don’t amplify the signal in any way. Example for passive topology - linear bus.
72. What are the important topologies for networks
BUS topology:
In this each computer is directly connected to primary network cable in a single line.
Advantages:
Inexpensive, easy to install, simple to understand, easy to extend.
STAR topology:
In this all computers are connected using a central hub.
Advantages:
Can be inexpensive, easy to install and reconfigure and easy to trouble shoot physical problems.
RING topology:
In this all computers are connected in loop.
Advantages:
All computers have equal access to network media, installation can be simple, and signal does not
degrade as much as
in other topologies because each computer
regenerates it.
73. What are major types of networks and explain
Server-based network
Peer-to-peer network
Peer-to-peer network, computers can act as both servers sharing resources and as clients using the
resources.
Server-based networks provide centralized control of network resources and rely on server computers
to provide security and network administration
74. Explain Protocol Data Unit
The data unit in the LLC level is called the protocol data unit (PDU). The PDU contains of four fields
a destination service access point (DSAP), a source service access point (SSAP), a control field and an
information field. DSAP, SSAP are addresses used by the LLC to identify the protocol stacks on the
receiving and sending machines that are generating and using the data. The control field specifies
whether the PDU frame is a information frame (I - frame) or a supervisory frame (S - frame) or a
unnumbered frame (U - frame).
75. Explain difference between baseband and broadband transmission
In a baseband transmission, the entire bandwidth of the cable is consumed by a single signal. In
broadband transmission, signals are sent on multiple frequencies, allowing multiple signals to be sent
simultaneously.
76. What are the possible ways of data exchange
(i) Simplex (ii) Half-duplex (iii) Full-duplex.
77. What are the types of Transmission media
Signals are usually transmitted over some transmission media that are broadly classified in to two
categories.
Guided Media:
These are those that provide a conduit from one device to another that include twisted-pair, coaxial
cable and fiber-optic cable. A signal traveling along any of these media is directed and is contained by
the physical limits of the medium. Twisted-pair and coaxial cable use metallic that accept
and transport signals in the form of electrical current. Optical fiber is a glass or plastic cable that
accepts and transports signals in the form of light.
Unguided Media:
This is the wireless media that transport electromagnetic waves without using a physical conductor.
Signals are broadcast either through air. This is done through radio communication, satellite
communication and cellular telephony.
78. Explain point-to-point protocol
A communications protocol used to connect computers to remote networking services including
Internet service providers.
79. What are the two types of transmission technology available
(i) Broadcast and (ii) point-to-point
80. Difference between the communication and transmission.
Transmission is a physical movement of information and concern issues like bit polarity,
synchronization, clock etc. Communication means the meaning full exchange of information between
two communication media.