60 phút
Network Fundamentals
Network Fundamentals
OSI Model
7 Layers
7. Application - HTTP, FTP, SMTP, DNS
6. Presentation - Encryption, compression, format
5. Session - Session management
4. Transport - TCP, UDP (end-to-end)
3. Network - IP, ICMP, routing (logical addressing)
2. Data Link - Ethernet, MAC, switching (physical addressing)
1. Physical - Cables, signals, bits
Mnemonic
Layer 7 → 1:
"All People Seem To Need Data Processing"
Layer 1 → 7:
"Please Do Not Throw Sausage Pizza Away"
TCP/IP Model
4 Layers
Application = OSI 5-7
Transport = OSI 4
Internet = OSI 3
Network Access = OSI 1-2
Encapsulation
Data → Segment (TCP) → Packet (IP) → Frame (Ethernet) → Bits
TCP vs UDP
TCP (Transmission Control Protocol)
Connection-oriented
Reliable - có ACK
Ordered - đảm bảo thứ tự
Flow control - sliding window
Congestion control
3-way handshake: SYN → SYN/ACK → ACK
Applications: HTTP, HTTPS, FTP, SSH, SMTP, Telnet
UDP (User Datagram Protocol)
Connectionless
Unreliable - không ACK
Unordered
Fast - ít overhead
Best-effort delivery
Applications: DNS, DHCP, TFTP, SNMP, VoIP, video streaming
TCP Header
Source Port (16) Destination Port (16)
Sequence Number (32)
Acknowledgment Number (32)
Flags (9) Window Size (16)
Checksum (16) Urgent Pointer (16)
Options Data
TCP Flags
URG - Urgent
ACK - Acknowledgment
PSH - Push
RST - Reset
SYN - Synchronize
FIN - Finish
Ví dụ 3-way handshake:
Client → Server: SYN (seq=x)
Server → Client: SYN-ACK (seq=y, ack=x+1)
Client → Server: ACK (ack=y+1)
IP Addressing
IPv4
32 bits = 4 octets
Format: A.B.C.D
Example: 192.168.1.1
Classes:
Class A: 1-126 /8 (0.0.0.0 - 127.255.255.255)
Class B: 128-191 /16 (128.0.0.0 - 191.255.255.255)
Class C: 192-223 /24 (192.0.0.0 - 223.255.255.255)
Class D: 224-239 Multicast
Class E: 240-255 Experimental
Private IP (RFC 1918):
10.0.0.0/8 (10.0.0.0 - 10.255.255.255)
172.16.0.0/12 (172.16.0.0 - 172.31.255.255)
192.168.0.0/16 (192.168.0.0 - 192.168.255.255)
Special:
127.0.0.0/8 Loopback
169.254.0.0/16 APIPA (link-local)
0.0.0.0/0 Default route
Subnetting
Subnet Mask:
/24 = 255.255.255.0 256 addresses
/25 = 255.255.255.128 128 addresses
/26 = 255.255.255.192 64 addresses
/27 = 255.255.255.224 32 addresses
/28 = 255.255.255.240 16 addresses
/29 = 255.255.255.248 8 addresses
/30 = 255.255.255.252 4 addresses (point-to-point)
/31 = 255.255.255.254 2 addresses (RFC 3021)
/32 = 255.255.255.255 1 address (host route)
Công thức:
Số host = 2^(32 - prefix) - 2
Số subnet = 2^(prefix - original_prefix)
Ví dụ subnetting
Cho: 192.168.10.0/24
Chia thành 4 subnet bằng nhau:
Cần 2 bits → /26
Subnet mask: 255.255.255.192
Subnet 1: 192.168.10.0/26 (hosts .1-.62)
Subnet 2: 192.168.10.64/26 (hosts .65-.126)
Subnet 3: 192.168.10.128/26 (hosts .129-.190)
Subnet 4: 192.168.10.192/26 (hosts .193-.254)
Broadcast:
Subnet 1: 192.168.10.63
Subnet 2: 192.168.10.127
Subnet 3: 192.168.10.191
Subnet 4: 192.168.10.255
VLSM
Variable Length Subnet Mask
Sử dụng các subnet mask khác nhau cho các subnet khác nhau
Ví dụ: 10.0.0.0/24 cho 4 phòng:
Phòng A: 100 hosts → /25 (126 hosts)
Phòng B: 50 hosts → /26 (62 hosts)
Phòng C: 20 hosts → /27 (30 hosts)
Phòng D: 10 hosts → /28 (14 hosts)
IPv6
128 bits = 8 groups × 16 bits (hex)
Format: xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx
Ví dụ:
2001:0db8:85a3:0000:0000:8a2e:0370:7334
Viết tắt:
2001:db8:85a3::8a2e:370:7334
(Bỏ số 0 đầu, dùng :: cho nhóm 0 liên tiếp)
Prefix: /64 thông thường cho LAN
IPv6 Address Types
Global Unicast: 2000::/3 (public)
Link-Local: fe80::/10 (auto-config)
Unique Local: fc00::/7 (private, như RFC1918)
Multicast: ff00::/8
Loopback: ::1/128
Unspecified: ::/128
EUI-64
Tạo IPv6 từ MAC address:
1. Tách MAC: 00:1A:2B:3C:4D:5E
2. Chèn FFFE: 00:1A:2B:FF:FE:3C:4D:5E
3. Đảo bit 7: 02:1A:2B:FF:FE:3C:4D:5E
4. Thêm prefix: 2001:db8::21a:2bff:fe3c:4d5e
SLAAC (Stateless Address Autoconfiguration)
1. Host gửi Router Solicitation (RS)
2. Router trả Router Advertisement (RA)
3. Host tự cấu hình địa chỉ từ prefix trong RA
4. Host verify uniqueness (DAD)
Ethernet
Frame Format (Ethernet II)
Preamble (7) - 10101010...
SFD (1) - 10101011
Destination MAC (6)
Source MAC (6)
Type/Length (2)
Data (46-1500)
FCS (4) - CRC
MAC Address
48 bits = 6 bytes (hex)
Format: 00:1A:2B:3C:4D:5E
OUI (24 bits) - Organizationally Unique Identifier
NIC (24 bits) - Network Interface Controller
Ví dụ:
00:1A:2B = OUI (nhà sản xuất)
3C:4D:5E = NIC (serial number)
Special MAC:
FF:FF:FF:FF:FF:FF = Broadcast
01:00:5E:xx:xx:xx = Multicast IPv4
33:33:xx:xx:xx:xx = Multicast IPv6
Ethernet Types
10Base-T 10 Mbps Category 3
100Base-TX 100 Mbps Category 5
1000Base-T 1 Gbps Category 5e/6
10GBase-T 10 Gbps Category 6a/7
Cabling
Twisted Pair
UTP - Unshielded Twisted Pair
STP - Shielded Twisted Pair
Category:
Cat 3: 10 Mbps
Cat 5: 100 Mbps
Cat 5e: 1 Gbps
Cat 6: 10 Gbps (55m)
Cat 6a: 10 Gbps (100m)
Cat 7: 10 Gbps shielded
Cable Types
Straight-through:
- Host to Switch
- Host to Router
- Router to Switch
- Both ends same standard (T568A or T568B)
Crossover:
- Switch to Switch
- Host to Host
- Router to Router
- Different standards on each end
Rollover:
- Console connection
- Cisco proprietary
T568A vs T568B:
Colors khác nhau ở cặp 2 & 3
Fiber Optic
Single-mode:
- Core 9 micron
- Long distance (km)
- Laser
- Yellow jacket
Multi-mode:
- Core 50/62.5 micron
- Short distance (m)
- LED/VCSEL
- Orange/Aqua jacket
Connectors:
- ST, SC, LC, MTRJ
ARP
ARP Process
1. Host cần MAC của 192.168.1.1
2. Check ARP cache
3. Nếu không có → gửi ARP Request (broadcast)
4. Target reply ARP Reply (unicast)
5. Cache MAC address
Commands:
arp -a # Windows
show arp # Cisco
show ip arp # Cisco
arp -d * # Clear (Windows)
ARP Table
Windows:
C:\> arp -a
Interface: 192.168.1.100
Internet Address Physical Address Type
192.168.1.1 00-11-22-33-44-55 dynamic
192.168.1.10 66-77-88-99-aa-bb dynamic
ICMP
Message Types
Type 0 - Echo Reply (ping response)
Type 3 - Destination Unreachable
Type 5 - Redirect
Type 8 - Echo Request (ping)
Type 11 - Time Exceeded (traceroute)
Tools
ping - ICMP Echo Request/Reply
traceroute/tracert - Trace route
pathping - Windows
mtr - Linux
Network Topologies
Physical
Bus - All on one cable
Star - All to central switch
Ring - Circular
Mesh - Full/Partial
Hybrid - Combination
Logical
Broadcast domain - Tất cả devices nhận broadcast
Collision domain - Trong hub/repeater (legacy)
Network Devices
Hub
Layer 1
1 collision domain
1 broadcast domain
Shared bandwidth
Legacy, obsolete
Switch
Layer 2
1 collision domain per port
1 broadcast domain (default)
Full-duplex
MAC address table
Router
Layer 3
Separate collision domains
Separate broadcast domains
Routing between networks
Firewall
Layer 3-7
Filter traffic
Stateful inspection
NAT
VPN
Bài tập thực hành
Hãy subnetting và troubleshoot mạng!