🏠 home · reset
⟨⟩ sidebar
Aa text size
netslice Pro Toolkit
routing
switching
wan & sd-wan
management
calculators
security & auth
reference
troubleshooting
layer 1 & 2
protocols
tools & os
Built for network engineers who value straight to the point.
One bookmark. Every tool you reach for daily — subnetting, routing, wireless, security, and reference — all in one place.
STTP · Straight To The Point.
subnetting
Subnet Calculator
Enter a CIDR block and get network address, broadcast, host range, wildcard mask, usable hosts, and binary breakdown.
subnetting
VLSM Planner
Variable Length Subnet Masking — allocate multiple subnets of different sizes from a single address block, sorted by host requirement.
subnetting
Subnet List
Divide a network into equal-size subnets. Lists all subnets with their network/broadcast addresses and host ranges.
subnetting
Cloud Subnet Calculator
Cloud-aware subnet planning for AWS, Azure, and GCP. Accounts for provider-reserved addresses and shows usable host counts.
subnetting
Overlap Checker
Paste a list of CIDR ranges and instantly detect overlapping or duplicate subnets — essential for route table audits.
subnetting
Subnet Cheatsheet
Quick-reference table for all /0–/32 prefix lengths: subnet mask, wildcard, host count, and common use cases at a glance.

route/switch
Route Summarization
Enter a list of subnets and calculate the optimal summary route (supernet) that covers all of them with minimal waste.
route/switch
VLAN / Trunk Planner
Build VLAN tables, assign ports, visualize trunk/access port configurations, and parse Aruba AOS-CX running config to detect mismatches.
route/switch
PoE Planner
Plan switch PoE budgets. Reference for 802.3af/at/bt standards, per-device power draw for Aruba, Cisco, and Ruckus APs, cameras, and phones.
route/switch
STP Planner
Add switches and links to visualize the spanning tree topology. Calculates root bridge election, port roles (RP/DP/BLK), and root path costs. Includes STP/RSTP/MSTP reference.
route/switch
Switching Cheatsheet
Layer 2 forwarding, MAC table operation, 802.1Q VLAN/trunking, EtherChannel (LACP/PAgP), STP port states and roles, inter-VLAN routing, port security, BPDU guard, storm control, and switching troubleshooting quick reference.
route/switch
Circuit & WAN Planner
WAN bandwidth sizing with IPsec overhead, growth buffer, and SD-WAN path split recommendation. Circuit types reference (MPLS, DIA, broadband, LTE/5G) and SLA thresholds for latency, jitter, and packet loss by application type.
route/switch
Route Preference / AD
Administrative Distance quick reference across Cisco, Aruba, and Juniper. Interactive route conflict resolver — compare two routes, see which wins and why.
route/switch
OSPF Planner
Area type reference (stub/NSSA/totally-stub), OSPF cost calculator with reference bandwidth, DR/BDR election rules, and LSA type quick reference.
route/switch
BGP Cheatsheet
11-step path selection order with memory aid, well-known communities, FSM states, common techniques (prepending, LOCAL_PREF, MED, route reflectors, RTBH).
route/switch
SD-WAN Comparison
Side-by-side comparison of Cisco Viptela, Meraki, Aruba EdgeConnect, Fortinet, VeloCloud, and Versa. NSA vs SA 5G deployment modes and SASE component breakdown.
route/switch
Path Selection
How SD-WAN picks paths step by step, SLA metric thresholds for voice/video/data, path strategies (active/standby, app-aware, FEC, packet duplication), and BFD reference.
route/switch
IPv6 Cheatsheet
Address types (GUA/ULA/link-local/multicast), EUI-64 generation, NDP vs ARP, SLAAC vs DHCPv6, prefix sizing (/48/56/64/127), and well-known multicast addresses.
route/switch
Routing Cheatsheet
IP routing fundamentals, longest prefix match, CEF/FIB, administrative distance table, static route types, ECMP load balancing, OSPF neighbor states and area types, redistribution, route filtering (prefix-list/route-map), PBR, and troubleshooting quick reference.
route/switch
VPN Reference
IPsec IKEv2 phases, tunnel vs transport mode, ESP vs AH, DMVPN phases 1/2/3 with NHRP, GRE overhead and gotchas, WireGuard quick reference, and port/protocol table.
route/switch
SNMP / Syslog / NTP
SNMPv3 security levels, GET/TRAP/INFORM operations, useful OIDs, syslog severity levels 0–7, facility codes, NTP stratum hierarchy, and NTP best practices.

wireless
Wi-Fi Channel Visualizer
Visual map of 2.4 GHz, 5 GHz, and 6 GHz channels showing width, overlap, and non-overlapping channel sets.
wireless
MCS / RSSI Mapper
Maps RSSI signal levels to MCS index and PHY rates for 802.11n/ac/ax. Shows minimum SNR requirements per MCS.
wireless
802.11 Frame Calculator
Calculate frame overhead, payload efficiency, and throughput for 802.11 frames at different MCS rates and frame sizes.
wireless
Roam Threshold Advisor
Calculates recommended RSSI roaming thresholds based on environment, AP density, and application type (voice, video, data).
wireless
EIRP Calculator
Calculate Effective Isotropic Radiated Power: Tx power + antenna gain − cable loss. Check against regulatory EIRP limits.
wireless
Airtime Utilization
Calculate channel airtime consumed by your client mix. Shows how low-MCS clients starve high-MCS clients and estimates max clients before saturation.
wireless
WPA2 vs WPA3
Side-by-side comparison of WPA2 and WPA3 security modes, authentication methods, encryption, and use-case recommendations.
wireless
Power & dB Guide
Reference for dB, dBm, dBi, SNR. Includes dBm-to-mW table, the 3 dB / 10 dB rules, link budget walkthrough, and RF loss values for common building materials.
wireless
802.11 Amendments
Full timeline of 802.11 amendments from original to Wi-Fi 7 (be). Feature comparison table, key non-speed amendments (k/r/v/w), and MLO / 6 GHz notes.
wireless
802.11 Frame Cheatsheet
Frame types (management/control/data), MAC header fields, management subtype reference, association process step-by-step, reason codes, and status codes.
wireless
EAP / 802.1X Guide
802.1X architecture (supplicant, authenticator, RADIUS), EAP method comparison (PEAP, EAP-TLS, EAP-TTLS, EAP-FAST, EAP-SIM), certificate requirements, and step-by-step auth flow per method.
wireless
Wi-Fi Troubleshooting
Layer-by-layer troubleshooting flowchart — RF/signal, association, 802.1X authentication, DHCP, and routing/DNS. Expandable checks with pass/fail criteria and quick triage commands.
wireless
WLC CLI Comparison
Wireless controller CLI reference for Cisco 9800 (IOS-XE), Aruba Mobility Controller (AOS8), Ruckus SmartZone, and Juniper Mist. Covers clients, APs, SSIDs, RF, auth/AAA, management, and debug. Filter by category or search.
wireless
Antenna Cheatsheet
Antenna types (omni, sector, patch, yagi, panel), radiation pattern diagrams, gain vs coverage tradeoffs, polarization (single/dual/cross-pol), indoor vs outdoor use cases, connector types (RP-SMA, N-type, SMA), and Aruba/Cisco/Ruckus antenna model reference.

reference
Ethernet Guide
Cable categories (Cat5e–Cat8), PoE support by cable, Ethernet speeds timeline (10BASE-T → 400GbE), and a quick cable selection guide by scenario.
reference
SFP / Transceiver Guide
Form factor comparison (SFP to QSFP-DD), common module types (SR/LR/ER/DAC/AOC/BiDi) with reach and connector info, plus breakout/fan-out guide.
reference
IP Ports & Protocols
IP protocol numbers (TCP/UDP/OSPF/GRE/ESP/VRRP) and common TCP/UDP port reference with network-engineer notes (RADIUS, SNMP, TFTP, Syslog, 802.1X).
reference
DSCP / QoS Reference
Full DSCP table with PHB class and drop precedence, WMM access categories (AC_VO/VI/BE/BK) with AIFS/CWmin, and DSCP ↔ 802.1p ↔ WMM mapping.
reference
Wireshark Cheatsheet
Display filter cheatsheet, common protocol filters (DHCP, ARP, EAPOL, RADIUS, STP), 802.11 wireless capture & monitor mode tips, built-in statistics tools, and follow stream / export / tshark workflow tips.
reference
OS Networking
Networking commands for Linux, macOS, and Windows — tabbed reference covering interface management, routing, DNS, packet capture, port testing, and firewall per OS.
reference
4G / 5G Guide
LTE and 5G architecture, radio access technologies (FDD/TDD), frequency bands, NR vs LTE feature comparison, 5G NR sub-6 GHz vs mmWave, network slicing, and carrier aggregation basics.
reference
Vendor CLI Comparison
Side-by-side CLI reference for Cisco IOS/IOS-XE, Aruba AOS-CX, Juniper JunOS, and Arista EOS. Covers interfaces, switching, routing, OSPF, BGP, show commands, and management. Filter by category or search.
reference
Download Time Calculator
How long to transfer a file over any circuit. Lookup table for common file sizes × circuit speeds from 1 Mbps to 100 Gbps. Interactive calculator with custom inputs and protocol overhead toggle (raw, TCP/IP, VPN/IPsec, HTTPS).
security
Firewall Cheatsheet
Stateless vs stateful vs NGFW comparison, zone-based design, NAT types (static/dynamic/PAT/DNAT/Twice NAT), firewall rule order and implicit deny, essential port reference, common attacks (SYN flood, spoofing, DNS tunnel, lateral movement) and mitigations, troubleshooting quick reference.

ip services
NAT Reference
Static, dynamic, and PAT translation mechanics with session table walkthrough. Interactive port forwarding rule builder with Cisco/Aruba CLI output. Hairpin/NAT loopback, ALG reference (SIP, FTP, H.323), and NAT troubleshooting guide.
ip services
DNS Deep Dive
Record type reference (A, AAAA, CNAME, MX, PTR, NS, SOA, TXT, SRV, CAA), TTL behavior and propagation, recursive vs iterative query flow, DNSSEC chain of trust, split-horizon DNS, and common failure modes (NXDOMAIN, SERVFAIL, DNS rebinding).
ip services
DHCP Cheatsheet
DORA exchange, message types, common options (1/3/6/43/50/51/82/121), lease timers, packet fields, DHCP snooping/DAI/IP Source Guard, and troubleshooting quick reference.
ip services
VoIP Cheatsheet
SIP methods and response codes, INVITE/ACK/BYE call flow, RTP/RTCP/SRTP transport, codec reference (G.711/G.722/G.729/Opus), DSCP/QoS markings, voice VLAN design, DHCP provisioning options, and troubleshooting quick reference.

security
802.1X / NAC Deep Dive
NAC posture workflow, MAB fallback, ClearPass and ISE policy flow, RADIUS VSA enforcement (VLAN, role, ACL), CoA/PoD mechanics, quarantine patterns, BYOD onboarding, and common failure modes with debug guidance.
security
ACL Builder
Build and test IPv4 ACLs interactively. Add permit/deny rules, generate CLI output for Cisco IOS, Aruba AOS-CX, and AOS8. Test source + destination + port against the ruleset to see which rule matches and what action is taken.
cidr · or ip + mask
$ calc
10.0.0.0/8 172.16.0.0/12 192.168.1.0/24 10.10.50.0/26 100.64.0.0/10 CGNAT 192.168.1.0 255.255.255.0
configuration
supernet
$ supernet
subnets needed
configuration
parent block
$ block
split into
/ 192.168.0.0/22 → /24 10.0.0.0/20 → /26
configuration
cidr blocks to check
configuration
routes to summarize
configuration
cloud provider
AWS VPC
5 reserved
Azure VNet
5 reserved
GCP VPC
3 reserved
Standard
2 reserved
cidr block
$ cloud
/16 /24 /25 /26 /27 /28
configuration
region / country
FCC
frequency band
channel width
spectrum
DFS required
indoor only
overlap zone
channels
summary
overlap analysis
interactive channel planner  ·  place APs & see overlap live
band
channel width
region
0
access points
6
clean channels
0
collisions
0
on DFS
spectrum  ·  click a channel to drop an AP
channel overlap  ·  frequency domain — red = overlapping spectrum
auto-plan
3
APs
analysisno APs placed
configuration
standard
channel width
spatial streams
signal — RSSI / noise floor
RSSI dBm noise dBm
-45 excellent -60 good -70 fair -75 poor -85 very poor
MCS index
data rate
SNR / signal quality
0 dB1020304050 dB
full MCS table
MCS modulation coding min SNR min RSSI rate vs current
configuration · parameters
std ?
MCS ?
width ?
streams ?
payload ? bytes
64B 512B 1500B MTU 9000B jumbo
frame type ?
A-MPDU frames ? subframes
results
frame breakdown
airtime breakdown
Each 802.11 transmission consumes airtime well beyond the data itself. DIFS (Distributed Inter-Frame Space) is the mandatory idle time before any station may transmit — 802.11ac = 34 µs. Backoff is a random additional wait (0–CWmin slots) to reduce collisions. Preamble (PLCP header) is the sync sequence every receiver must decode before the data — legacy rates make this expensive. MAC header is the 802.11 addressing overhead. Data is your actual payload. SIFS (Short IFS = 16 µs) is the gap before the ACK. ACK is the receiver’s acknowledgement frame. The ratio of Data to Total airtime is your frame efficiency — A-MPDU aggregation improves this dramatically by amortising DIFS + preamble + ACK across many subframes.
component duration (μs) % of total
Reading the airtime breakdown DIFS (DCF Interframe Space) — mandatory quiet time before any station may attempt to transmit (~34 µs for 802.11ac). No one can transmit during DIFS.
Backoff — random wait slots added on top of DIFS to avoid collisions when multiple stations are ready. Each failed transmission doubles the contention window (binary exponential backoff).
Preamble — fixed training sequence at the start of every transmission. Lets the receiver synchronize timing, measure channel, and decode the SIGNAL field. 802.11ac HT preamble = 32+ µs depending on configuration.
SIGNAL / Header — PLCP header containing the data rate, length, and other PHY parameters — transmitted at the base rate so all stations can read it.
Data — the actual payload transmission time. This is the only part carrying user data. Notice how small this slice is relative to the total at low MCS or small payloads.
SIFS (Short Interframe Space) — mandatory gap between data frame and its ACK (~16 µs). Shorter than DIFS so the ACK gets priority over other stations.
ACK — the receiver's acknowledgement frame. If this is A-MPDU, a Block ACK bitmap (64-bit) acknowledges multiple subframes at once — this is why A-MPDU efficiency is so much higher than per-frame ACK.

Efficiency % = Data time ÷ Total airtime. At MCS 0 (BPSK 1/2) with 64-byte packets, efficiency can drop below 5% — 95% of the channel is spent on overhead. A-MPDU with 64 subframes at high MCS can push efficiency above 80%.
throughput vs payload size
configuration
deployment type
client type
coverage overlap (AP cell edge SNR)
overlap RSSI at edge
-67 dBm
noise floor
-95 dBm
recommended thresholds
roaming timeline
-90 dBm-80-70-60-50 dBm
good coverage
roam candidate zone
sticky / kick zone
no coverage
aruba AOS settings
parameter value location in AOS status
aruba CLI
inputs
country
frequency band
TX power (conducted)
dBm
antenna gain
dBi
cable / connector loss
dB
number of TX chains
EIRP
effective isotropic radiated power
EIRP vs regulatory limit
regulatory limits —
band / sub-band max EIRP max mW notes status
inputs
link / path MTU
bytes
IP version
encapsulation / tunnel
overhead (editable)
bytes
presets approximate — edit for exact
TCP options
adds 12 B, shrinks payload
TCP MSS
max TCP segment size
byte breakdown — effective MTU
mss clamp — vendor cli
Why this matters: the MSS is advertised in the TCP SYN; each side sends large segments and relies on Path MTU Discovery to learn it must fragment. When ICMP "fragmentation needed" is filtered (very common across firewalls/tunnels), large packets silently black-hole — connections hang on big transfers but small pings work. Clamping MSS on the tunnel interface forces both ends to negotiate a safe segment size up front. Jumbo frames (MTU 9000) require end-to-end support, including every switch in the path.
switch config
PoE budget (W)
port count
quick fill
utilization
0%
of PoE power budget used
power budget
0 W / 370 W used 370W
0 W
allocated
370 W
remaining
0
ports used
port #
device type
draw (W)
standard
port map — click to remove   af   at   bt   over budget
standardclassswitch port outputdevice maxpairs usedmin cablecommon use
802.3af (PoE)0–315.4W12.95W2-pairCat3+Basic APs, VoIP phones, cameras
802.3at (PoE+)430W25.5W2-pairCat5e+Wi-Fi 6 APs, PTZ cameras, thin clients
802.3bt Type 3 (PoE++)5–645–60W40–51W4-pairCat5e+ (Cat6a recommended)Wi-Fi 6E/7 tri-radio APs, video phones
802.3bt Type 4 (PoE++)7–871.3–90W62–71.3W4-pairCat6a requiredHigh-end APs, digital displays, pan-tilt cameras
Cisco uPoE / HPE HPoEvendor60W~51W4-pairCat6a recommendedCisco pre-bt solution, Aruba 655/730 series
⚡ Always plan with ~16% line loss between switch port and device. A 25.5W device requires ~30W switch port allocation. Cable length and quality affect actual delivery.
modelWi-Fi genradiosPoE standardswitch port Wdevice Wreduced functionality if underpowered
AP-305Wi-Fi 5 (ac)2.4+5802.3af15.4W12.5WFull functionality on af
AP-315Wi-Fi 5 (ac)2.4+5802.3at30W14.4WRuns on af with IPM
AP-325Wi-Fi 5 (ac)2.4+5802.3at30W20W maxOn af: 2.4GHz drops to 1x1:1. Dual E0/E1 PoE-in — two af sources can be combined.
AP-375Wi-Fi 5 (ac)2.4+5802.3at30W23W maxOutdoor omni. 802.3at required — af insufficient for full operation.
AP-377Wi-Fi 5 (ac)2.4+5802.3at30W23W maxOutdoor directional. Same power profile as AP-375. 802.3at required.
AP-387Wi-Fi 5 (ac)2.4+5802.3at30W22W maxOutdoor IP67. PoE+ required. Cable run <80m recommended.
AP-505Wi-Fi 6 (ax)2.4+5802.3af15.4W12.5WFull functionality on af
AP-515Wi-Fi 6 (ax)2.4+5802.3bt~36W25.5W typ / 30W maxOn at: limited to 2x2 on 5GHz, USB disabled. On af: minimal operation.
AP-518Wi-Fi 6 (ax)2.4+5802.3at / 802.3bt30W (at) / 60W (bt)26.1W (1 port) / 32W (2 port)Hardened outdoor. Dual E0/E1 PoE-in. Combine two 802.3at ports for full power. IPM supported.
AP-535Wi-Fi 6 (ax)2.4+5802.3at30W26.4WOn af: reduced spatial streams, 1Gbps eth only.
AP-555Wi-Fi 6 (ax)2.4+5+5802.3bt45W30W+On at: operates as 4x4 single 5GHz only.
AP-575Wi-Fi 6 (ax)2.4+5802.3at / 802.3bt30W (at) / 60W (bt)26.1W (1 port) / 32W (2 port)Outdoor omni Wi-Fi 6. Dual E0/E1 PoE-in. Single 802.3at = full operation with IPM.
AP-577Wi-Fi 6 (ax)2.4+5802.3at / 802.3bt30W (at) / 60W (bt)26.1W (1 port) / 32W (2 port)Outdoor directional Wi-Fi 6. Same power profile as AP-575. Dual E0/E1 PoE-in.
AP-635Wi-Fi 6E (ax)2.4+5+6802.3at30W23.8WUSB disabled on at. 802.3bt for USB + full power.
AP-655Wi-Fi 6E (ax)2.4+5+6802.3bt45–60W~40WOn 802.3at: 6GHz radio disabled — operates as dual-band only.
AP-675Wi-Fi 6E (ax)2.4+5+6802.3bt60W45.5W maxOutdoor tri-radio omni. 802.3bt required. Cat6a strongly recommended.
AP-677Wi-Fi 6E (ax)2.4+5+6802.3bt60W45.5W maxOutdoor tri-radio directional. Same power profile as AP-675. 802.3bt required. Cat6a required.
AP-730Wi-Fi 7 (be)2.4+5+6802.3bt60W~50WFull 802.3bt required for tri-radio at full capability.
Source: Aruba datasheets and Airheads community PoE quick reference. IPM = Intelligent Power Monitoring — Aruba APs negotiate power via LLDP and reduce functionality gracefully when underpowered.
modelWi-Fi genradiosPoE standardswitch port Wdevice Wreduced functionality if underpowered
C9105AXWi-Fi 6 (ax)2.4+5802.3af15.4W13.8WFull functionality on af
C9115AXWi-Fi 6 (ax)2.4+5802.3at30W21.4WOn af: USB disabled, eth 1Gbps, radios 2x2
C9120AXWi-Fi 6 (ax)2.4+5802.3at30W25.5WOn af: USB disabled, eth 1Gbps, radios 1x1
C9130AXWi-Fi 6 (ax)2.4+5802.3at / uPoE30–60W30.5WOn af: eth 1Gbps, radios 1x1. USB requires uPoE/bt
C9162Wi-Fi 6E (ax)2.4+5+6802.3bt60W~45WOn at: reduced spatial streams on 6GHz
C9164Wi-Fi 6E (ax)2.4+5+6802.3bt60W~50WOn at: 6GHz radio degraded
C9166Wi-Fi 6E (ax)2.4+5+6802.3bt60W~55WFull bt required for beacon protection + GCMP-256
Source: Cisco AP Power Requirements Quick Reference (cisco.com). Note: Most Cisco switches require CDP or LLDP to be enabled to deliver more than 802.3af power — LLDP is disabled by default on many Cisco switches.
modelWi-Fi genradiosmin PoEswitch port W (full)device Wreduced functionality if underpowered
AP24Wi-Fi 6E (ax)2.4+5+6 2x2802.3af15.4W13WFull functionality on af
AP32Wi-Fi 6 (ax)2.4+5 2x2802.3af15.4W~15WOn af: 5GHz 2x2, eth0 1Gbps, eth1 off
AP33Wi-Fi 6 (ax)2.4+5 4x4802.3at30W19.5WOn af: 5GHz reduces to 2x2, eth1 disabled
AP34Wi-Fi 6E (ax)2.4+5+6 2x2802.3at30W20.9WOn af: connects to cloud only to report low power
AP43Wi-Fi 6 (ax)2.4+5 4x4802.3at30W25.5WOn af: 5GHz 2x2, eth1 disabled. Always use at.
AP45Wi-Fi 6E (ax)2.4+5+6 4x4802.3bt45W29.3WOn at: 2x2 on 2.4+6GHz, 4x4 on 5GHz only
AP63Wi-Fi 6 (ax)2.4+5 outdoor802.3at30W25.2WAlways use at. Outdoor — check cable run length.
AP64Wi-Fi 6E (ax)2.4+5+6 outdoor802.3af15.4W13WFull functionality on af
Source: Juniper Mist official PoE requirements documentation (juniper.net). APs use LLDP to negotiate power — ensure LLDP is enabled on the upstream switch. Cisco switches may require manual LLDP enable.
modelWi-Fi genradiosmin PoEswitch port W (full)device Wreduced functionality if underpowered
R350Wi-Fi 6 (ax)2.4+5 2x2802.3af15.4W12.5WFull functionality on af
R550Wi-Fi 6 (ax)2.4+5 2x2+4x4802.3at30W22WOn af: reduced 5GHz spatial streams
R650Wi-Fi 6 (ax)2.4+5 4x4802.3at30W24WOn af: degraded performance
R750Wi-Fi 6 (ax)2.4+5 4x4+4x4802.3at30W26WOn af: IoT radios may be disabled
R850Wi-Fi 6 (ax)2.4+5 2x2+8x8uPoE/PoH60W~35W+On at (Mode 1): 4x4 on 5GHz. On af: minimal
R560Wi-Fi 6E (ax)2.4+5+6 2x2802.3at30W25.5WTri-radio requires 25.5W minimum. Auto-reboot if insufficient for 10+ min.
R760Wi-Fi 6E (ax)2.4+5+6 4x4802.3at30W25.5WTri-radio requires 25.5W minimum. Auto-reboot if insufficient for 10+ min.
R770Wi-Fi 6E (ax)2.4+5+6 4x4802.3bt45–60W~40WOn at: same 25.5W min restriction as R760
T350 outdoorWi-Fi 6 (ax)2.4+5 2x2802.3at30W25WOutdoor rated. Keep cable run <80m. Surge protection recommended.
T750 outdoorWi-Fi 6 (ax)2.4+5 4x4uPoE/bt60W~40WRequires bt or uPoE for full operation. Outdoor rated IP67.
T760 outdoorWi-Fi 6E (ax)2.4+5+6 4x4802.3bt60W~45WTri-radio outdoor. bt required. Use Cat6a for runs over 60m.
Source: Ruckus SmartZone release notes, Ruckus One AP power documentation. R560/R760/R770 will auto-reboot after 10 minutes if PoE supply is insufficient. R850 supports uPoE/PoH via 5Gbps Ethernet interface.
modeltyperesolutionPoE classswitch port Wtypical Wmax Wnotes
M3106-L Mk IIIndoor fixed dome4MPClass 28W4.5W7.5WBasic indoor dome. af fully sufficient.
M4216-LVIndoor varifocal dome4MPClass 310W6W8.5WIR + varifocal. af fully sufficient.
P3255-VIndoor fixed dome2MPClass 28W4.7W8.0WLatest ARTPEC-8 SoC. Deep learning analytics.
P3265-VIndoor varifocal dome2MPClass 310W5.5W9.5WARTPEC-8, Lightfinder 2.0, Forensic WDR.
P3265-LVIndoor IR varifocal2MPClass 313W7.0W11.0WIR illumination increases draw. af sufficient.
P3265-LVEOutdoor IR varifocal2MPClass 315.4W8.5W14.0WOutdoor IP66/67. Heater in cold weather adds ~3W.
M3158-VIndoor panoramic8MPClass 312W6.5W9.0W180° panoramic. af sufficient for most deployments.
Q6135-LEOutdoor PTZ 32x1080pClass 430W18W30WHigh-speed PTZ + OptimizedIR 250m. PoE+ required.
Q6100-EOutdoor 360° PTZ4KClass 430W20W30WMultidirectional outdoor. PoE+ required.
P5676-LEOutdoor PTZ4KClass 430W22W30W4K outdoor PTZ. PoE+ required.
Source: Axis Communications datasheets and Axis power consumption white paper. Typical values are measured with heaters and IR off at room temperature. Maximum includes heaters at full power, IR at 100%, and all motors running. Plan with maximum values for switch budget. Outdoor cameras with heaters draw significantly more in cold climates — add 3–5W buffer per outdoor camera.
modellinesPoE classswitch port Wtypical Wnotes
Cisco 78414-lineClass 15W4.5WBasic af phone. Very low draw.
Cisco 88415-lineClass 28W6.5WMid-range. af sufficient.
Cisco 88515-line + USBClass 312W9.5WUSB charging port adds draw. af sufficient.
Cisco 88615-line + Wi-Fi + BTClass 415.4W13WWi-Fi + Bluetooth + 2 USB. Class 4 required for full feature set.
Cisco 88655-line + video + Wi-FiClass 415.4W15WVideo phone. Class 4 / PoE+ for KEM expansion modules.
Poly VVX 3116-lineClass 15W4.5WEntry level. Very low draw. af more than sufficient.
Poly VVX 41112-lineClass 29W7.5WMid-range color. af sufficient.
Poly VVX 50112-line colorClass 312W10WHigher-end color display. af sufficient.
Poly VVX 60116-line colorClass 312W10WHigh-end. Optional USB camera adds ~2W.
Poly Edge E3006-lineClass 28W6WModern replacement for VVX 311. af sufficient.
Poly Edge E50012-lineClass 312W9WModern replacement for VVX 411/501. af sufficient.
Yealink T46U16-lineClass 16W5.5WVery efficient. af more than sufficient.
Yealink T58W16-line + Wi-FiClass 311W9WWi-Fi + BT. af sufficient.
Source: Cisco IP Phone 8800 series datasheet, Poly/Polycom product datasheets, Yealink datasheets. VoIP phones are generally very PoE-efficient — most run comfortably on 802.3af. Plan 7–12W per phone for budget calculations. Key expansion modules add 2–3W each.
tipdetail
16% line lossIEEE 802.3 allows up to 16% power loss in the cable. A 25.5W device needs ~30.4W allocated at the switch port. Use Cat5e or better — Cat5 degrades efficiency.
LLDP negotiationMost modern APs negotiate power via LLDP. Cisco switches have LLDP disabled by default — enable it or APs may only get 802.3af. Aruba and Juniper APs also fall back gracefully but with reduced features.
Cable length mattersMaximum PoE cable run is 100m (Cat5e+). Longer runs increase resistance and power loss — keep outdoor cable runs under 80m where possible for reliable PoE delivery.
Plan for 80% utilizationNever plan to use 100% of switch PoE budget. A 740W switch should only be loaded to ~592W. Power supplies degrade over time and emergency load spikes happen.
Tri-radio APs need PoE+/btWi-Fi 6E APs with 3 simultaneous radios (2.4+5+6GHz) typically require 802.3at (30W) minimum and often 802.3bt (45-60W) for full performance. Plan accordingly when upgrading infrastructure.
USB + IoT radio adds ~2–5WEnabling USB devices or IoT radios (BLE/Zigbee) adds 2–5W to AP power draw. Factor this in when using APs with IoT capabilities in dense deployments.
Outdoor cable runsKeep outdoor PoE cable runs under 80m (not 100m) to account for increased resistance in outdoor-rated cables and conduit. Always use Cat5e minimum — Cat6a for 802.3bt outdoor deployments. Add surge protection/lightning arrestors at both ends.
Midspan injectors as fallbackIf your switch cannot deliver sufficient PoE, midspan injectors (e.g. Aruba H1 or Cisco AIR-PWRINJ6) can deliver full power to individual APs without replacing switch infrastructure.
quick reference
SAE
WPA3 auth
AES-CCMP
cipher
PMF
mandatory (WPA3)
192-bit
WPA3-Ent
WPA3-Personal uses SAE (Dragonfly) to replace the WPA2 PSK 4-way-handshake weakness (offline cracking/KRACK). Protected Management Frames mandatory in WPA3. Transition mode runs WPA2+WPA3 together.
settingWPA2WPA3notes
Personal authPSKSAE (Dragonfly)SAE is resistant to offline dictionary attacks — captured handshake cannot be brute-forced
Enterprise auth802.1X + EAP802.1X + EAPSame EAP methods. WPA3-Ent 192-bit mode adds GCMP-256 + ECDH/ECDSA requirements
Forward secrecy✗ none✓ per-session PMKSAE generates a unique PMK each session — past sessions stay protected if PSK is later compromised
Open / unauthenticatedOpen (no encryption)OWE (encrypted, no auth)OWE encrypts traffic without a password. OWE-Transition keeps legacy clients working alongside
Transition / mixed modeSAE-TransitionBoth WPA3-SAE and WPA2-PSK on same SSID. Same passphrase. Requires controller support (see vendor table)
settingWPA2WPA3notes
Unicast cipher (Personal)CCMP-128 (AES)CCMP-128 or GCMP-128GCMP is faster on hardware with AES-GCM acceleration
Unicast cipher (Enterprise)CCMP-128GCMP-256 (192-bit mode)WPA3-Ent 192-bit mandates GCMP-256 — not supported on all AP hardware (see vendor notes)
TKIPallowed (deprecated)removed entirelyWPA3 removes TKIP. TKIP-only clients cannot connect to WPA3 SSIDs
Management frame cipherBIP-CMAC-128 (optional)BIP-CMAC-128 / BIP-GMAC-256Mgmt frame encryption is optional in WPA2, mandatory in WPA3
settingWPA2WPA3notes
PMF requirementoptionalrequiredWPA3 mandates PMF. SAE and OWE will not negotiate without it
Deauth / disassoc attack✗ vulnerable✓ protectedPMF encrypts deauth/disassoc — prevents forced roam and evil twin attacks
Legacy client impactnonemay break pre-2018 clientsSome older drivers reject pmf-required. Use transition mode with pmf-optional for mixed environments
featureAruba AOSCisco IOS-XE (C9800)Juniper MistRuckus SmartZone
WPA3-Personal (SAE) 8.6+ 16.12+ FW 0.8.x+ SZ 5.2+ (Wave2 APs)
SAE Transition (WPA2+WPA3) 8.11+ only 16.12+ FW 0.8.x+ SZ 5.2+
WPA3-Enterprise 8.7+ 16.12+ FW 0.8.x+ SZ 5.2+
WPA3-Enterprise 192-bit 8.7+ 17.1+ (not on 9105/9115/9120) FW 0.14.29091+ Limited AP support
OWE / OWE-Transition 8.11+ only 16.12+ FW 0.8.x+ SZ 5.2+
WPA3 default on new WLANs no no yes (Nov 2025) no
Known bugs / caveats Multicast bug 8.11.0–8.11.1 → min 8.11.2.1 Wave 1 APs not supported. GCMP-256 not on 9105/9110/9115/9120 No major known bugs R310 Wave1 is exception. WPA3+DPSK limited
Fast roaming (802.11r) + WPA3 FT-SAE supported FT-Adaptive not supported with SAE FT-SAE supported WPA3+DPSK limits 802.11r
platformWPA2WPA3-Personal (SAE)WPA3-Enterprise / OWE
Windows 11
Windows 10 (1903+)
Windows 10 (pre-1903)
macOS 10.15+ (Catalina+)
iOS 13+
Android 10+
Android 9 and below
Linux (wpa_supplicant 2.9+)
Chromebook (Chrome OS 79+)
IoT / embedded (most)✗ (rare support)
Legacy / pre-2018 devices
attackWPA2WPA3notes
Offline dictionary / brute-force✗ vulnerable✓ mitigated (SAE)SAE requires live exchange per attempt — offline cracking is not possible
KRACK (CVE-2017-13077)✗ vulnerable (patched)✓ not applicableSAE + PMF design prevents the nonce reuse that KRACK exploited
PMKID offline attack✗ vulnerable✓ mitigatedWPA2 PMKID can be captured without a client. SAE has no equivalent attack vector
Deauth / disassoc flood✗ vulnerable✓ protected (PMF)Unprotected mgmt frames in WPA2 allow forced disconnection attacks
Evil twin / rogue AP✗ partial✓ harderPMF prevents forced roam; SAE prevents credential capture at rogue AP
Dragonblood (SAE side-channel)N/Apatched in WPA3-R2 (2019)Early SAE had timing/cache side-channels. Fixed in Wi-Fi Alliance WPA3 R2 spec revision
Aruba AOS 8.11.2.1+ · WPA3-SAE Transition mode · Mobility Master CLI
! WPA3-SAE Transition — Aruba AOS 8.11.2.1+
! Minimum safe build: 8.11.2.1 (avoids multicast encryption bug)

wlan ssid-profile "Corp-WPA3-Trans"
  essid "Corp-WiFi"
  opmode wpa3-personal-transition
  wpa-passphrase <your-passphrase>
  pmf-optional
!
wlan virtual-ap "Corp-VAP"
  ssid-profile "Corp-WPA3-Trans"
  vlan <your-vlan>
!
ap-group "<your-ap-group>"
  virtual-ap "Corp-VAP"
⚠ AOS 8.10 and below: use opmode wpa2-personal only — transition mode not supported
Cisco Catalyst 9800 · IOS-XE 16.12+ · WPA3-SAE Transition mode
! WPA3-SAE Transition — Cisco IOS-XE 16.12+
! Note: Fast Transition Adaptive not supported with WPA3 SAE

configure terminal
 wlan Corp-WiFi 1 Corp-WiFi
  security wpa wpa3
  security wpa wpa2
  security wpa akm sae
  security wpa akm psk
  security wpa wpa3 ciphers aes
  security pmf optional
  no shutdown
 exit
!
! Apply to policy profile:
wireless profile policy Corp-Policy
  vlan <your-vlan>
  no shutdown
!
wireless tag policy Corp-Tag
  wlan Corp-WiFi policy Corp-Policy
⚠ WPA3 not supported on Wave 1 APs. GCMP-256 not available on C9105/9110/9115/9120.
Juniper Mist · Cloud GUI config (API equivalent shown) · FW 0.8.x+ required
// Juniper Mist — WPA3-SAE Transition via API (PATCH /api/v1/sites/{site_id}/wlans)
// GUI: Site > WLANs > Add WLAN > Security: WPA3/PSK (+WPA-2)

{
  "ssid": "Corp-WiFi",
  "auth": {
    "type": "psk",
    "psk": "<your-passphrase>",
    "multi_psk_only": false
  },
  "wpa3_enabled": true,          // enables SAE
  "wpa2_enabled": true,          // enables transition mode
  "pmf": "optional",
  "vlan_id": <your-vlan>,
  "enabled": true
}

// Note: As of Nov 2025, WPA3 is the DEFAULT security type for new WLANs in Mist.
// WPA3-Enterprise 192-bit requires FW 0.14.29091+ and EAP-TLS only.
✓ No major known WPA3 bugs in Mist. WPA3 is now default for new WLANs.
Ruckus SmartZone 5.2+ · WPA3-SAE Transition · GUI path shown
! Ruckus SmartZone 5.2+ — WPA3/WPA2 Mixed Mode
! GUI: Wireless LANs > Create > Security Options > WPA3/WPA2 Mixed

! SmartZone CLI equivalent:
no aaa wlan <wlan-id>

! Configure via SmartZone GUI:
! Wireless LANs > Add
!   SSID: Corp-WiFi
!   Authentication: WPA3/WPA2 Mixed (SAE + PSK)
!   Passphrase: <your-passphrase>
!   PMF: Optional
!   VLAN: <your-vlan>

! Ruckus One (R1) / Cloud — same options via cloud portal
! Navigate to: Configure > WLANs > Add WLAN > Security: WPA3+WPA2

! Caveats:
! - WPA3 requires 802.11ac Wave2 or newer APs (R310 Wave1 is the one exception)
! - WPA3 + DPSK combined not supported on SZ 6.1.x and below
! - WPA3 + 802.11r: supported in mixed mode; WPA3-Enterprise 192-bit has no fast roaming
⚠ WPA3+DPSK not supported on SZ 6.1.x and below. Most Wave2+ APs supported from SZ 5.2.
scenarioWPA2WPA3recommendation
Corporate — modern clients + 802.1XWPA2-EnterpriseWPA3-EnterpriseAll vendors support from their respective minimums above
Corporate — mixed clients + 802.1XWPA2-EnterpriseWPA3-Ent Transitionpmf-optional. Aruba needs 8.11.2.1+
PSK — modern clients onlyWPA2-PersonalWPA3-SAEPure SAE if all clients are 2019+
PSK — mixed legacy + modernWPA2-PersonalSAE-TransitionAruba: needs 8.11.2.1+. Others: 2020+ builds
Guest / captive portalOpenOWE-TransitionAruba 8.11+. Cisco 16.12+. Mist FW 0.8.x+
IoT / legacy onlyWPA2-Personalnot compatibleStay WPA2-PSK — isolate on dedicated VLAN
6 GHz / Wi-Fi 6E / Wi-Fi 7not permittedWPA3 mandatoryWi-Fi Alliance mandates WPA3 + OWE for 6 GHz operation
quick reference
1500 B
std MTU
9000 B
jumbo
64–1518 B
frame size
18 B
L2 overhead
Frame = 8 preamble + 12 MAC (dst+src) + 2 type + 46–1500 payload + 4 FCS. Min 64 B on the wire, MTU 1500. Speeds 10 M → 400 G; auto-MDIX removes crossover cables.
categorymax speedbandwidthmax lengthshieldingPoE supportbest for
Cat5 100 Mbps 100 MHz 100m UTP 802.3af only Legacy — avoid for new installs
Cat5e 1 Gbps 100 MHz 100m UTP / STP 802.3af / 802.3at Minimum standard for new deployments. Supports PoE+.
Cat6 1 Gbps (10G up to 55m) 250 MHz 100m (55m at 10G) UTP / STP 802.3af / 802.3at / 802.3bt Good general-purpose cable. 10G limited to short runs.
Cat6a 10 Gbps 500 MHz 100m UTP / STP / SFTP 802.3af / at / bt (Type 3 & 4) Recommended for Wi-Fi 6E/7 APs, 802.3bt deployments, future-proof installs.
Cat7 10 Gbps 600 MHz 100m SFTP (shielded required) bt capable (shielded) Proprietary connectors (GG45/TERA) — avoid unless required. Not a TIA standard.
Cat8 25 / 40 Gbps 2000 MHz 30m S/FTP (shielded required) Not designed for PoE Data center switch-to-switch and server connections only. Very short runs.
⚡ Cat6a is the recommended minimum for 802.3bt (PoE++) deployments. At high power loads, lower-grade cables generate more heat — bundled cable runs amplify this significantly. TIA-568-C.2 recommends derating PoE budgets for bundled cables.
cable802.3af (15.4W)802.3at / PoE+ (30W)802.3bt Type 3 (60W)802.3bt Type 4 (90W)notes
Cat5 ⚠ marginal Higher resistance — voltage drop on long runs. Replace for PoE+.
Cat5e ⚠ possible, not recommended Adequate for PoE+. For bt, use Cat6a to avoid heat buildup in bundles.
Cat6 ⚠ check bundle size Supports bt Type 3. Type 4 at full 90W requires careful bundle derating.
Cat6a Recommended for all PoE++ deployments. Lower resistance = less heat.
Cat7 / Cat8 ⚠ possible ✗ not designed for PoE Cat8 is optimized for short high-speed runs, not PoE delivery.
Bundle derating rule: IEEE 802.3bt recommends reducing per-port PoE budget when cables are bundled. A bundle of 24 Cat5e cables at full 802.3bt load should be derated by ~40%. Use Cat6a to minimize this effect.
standardspeedintroducedmediummax copper distancestatus
10BASE-T 10 Mbps 1990 Cat3+, UTP 100m legacy
100BASE-TX (Fast Ethernet) 100 Mbps 1995 Cat5+, UTP 100m legacy / IoT
1000BASE-T (GbE) 1 Gbps 1999 Cat5e+, 4-pair 100m ubiquitous
2.5GBASE-T 2.5 Gbps 2016 Cat5e+ 100m common — Wi-Fi 6/6E APs
5GBASE-T 5 Gbps 2016 Cat5e+ 100m growing — high-end APs
10GBASE-T 10 Gbps 2006 Cat6a+ (100m), Cat6 (55m) 100m (Cat6a) standard for uplinks / servers
25GBASE-T 25 Gbps 2018 Cat8 30m data center / ToR switches
40GBASE-T 40 Gbps 2016 Cat8 30m data center
100GbE 100 Gbps 2010 Fiber / DAC fiber only (copper DAC ~3m) data center / core
400GbE 400 Gbps 2018 Fiber / DAC fiber only data center spine
2.5G and 5G (NBASE-T / IEEE 802.3bz) were introduced specifically to bridge the gap between 1G and 10G over existing Cat5e/Cat6 cabling — crucial for Wi-Fi 6/6E AP deployments where replacing cabling is costly.
scenariorecommended cablereason
Wi-Fi 6 AP (802.3at)Cat5e minimum, Cat6 preferred1G or 2.5G uplink, PoE+ sufficient
Wi-Fi 6E / 7 AP (802.3bt)Cat6a required2.5G–5G uplink, bt PoE++ heat management
IP camera (indoor)Cat5e100M–1G, low PoE draw, af sufficient
IP camera (outdoor PTZ)Cat5e outdoor-rated, Cat6a preferredPoE+ required, UV/moisture rated jacket
VoIP phoneCat5e100M, very low PoE, af more than sufficient
Switch uplink (1–10G)Cat6a or fiber SFP+10G over Cat6a up to 100m; fiber for longer runs
Server / NIC (10G)Cat6a or fiber DAC10GBASE-T up to 100m, DAC for rack-to-rack
New building install (future-proof)Cat6a everywhereHandles 10G, full 802.3bt PoE++, Wi-Fi 7 ready

VLAN / Trunk Planner

vlans
quick add
ports
portmodenative VLANtagged VLANsuntagged VLANs
paste aruba AOS-CX config
Supports: vlan X, interface 1/1/X, vlan trunk allowed, vlan access, vlan trunk native
quick reference
1 G
SFP
10 G
SFP+
25 G
SFP28
100 G
QSFP28
SR = multimode (OM3/OM4, ~300–400 m), LR = single-mode (~10 km), ER (~40 km). DOM/DDM exposes optical Tx/Rx power & temperature. Match wavelength + fiber type both ends.
form factormax speedlaneshot-swaptypical use
SFP1 Gbps1GbE uplinks, access switches
SFP+10 Gbps110G uplinks, server connections, distribution
SFP2825 Gbps125G server NIC uplinks, leaf-spine fabric
SFP5650 Gbps1 (PAM4)50G high-density data center
QSFP+40 Gbps4 × 10G40G uplinks, spine switches, breakout to 4×10G
QSFP28100 Gbps4 × 25G100G spine/core, breakout to 4×25G or 2×50G
QSFP56200 Gbps4 × 50G (PAM4)200G high-density spine
QSFP-DD400 Gbps8 × 50G (PAM4)400G data center core, AI/ML fabric
OSFP400 / 800 Gbps8 × 50/100G800G next-gen data center (competing with QSFP-DD)
CFP / CFP2 / CFP4100–400 GbpsvariesLong-haul DWDM, service provider edge
modulespeedfiber typewavelengthmax reachconnector
SX1GMMF OM1/OM2850nm550mLC duplex
LX / LX101GSMF1310nm10kmLC duplex
ZX1GSMF1550nm80kmLC duplex
SR (10G)10GMMF OM3/OM4850nm300m (OM3) / 400m (OM4)LC duplex
LR (10G)10GSMF1310nm10kmLC duplex
ER (10G)10GSMF1550nm40kmLC duplex
ZR (10G)10GSMF1550nm80kmLC duplex
DAC (passive)10 / 25 / 40 / 100GCopper twinax1–5mSFP+/QSFP integral
AOC (active)10 / 25 / 40 / 100GMMF fiber850nmup to 100mSFP+/QSFP integral
BiDi (WDM)1G / 10GSMF single strandTX 1310 / RX 1490nm10–20kmLC simplex
⚡ DAC cables are the most cost-effective for rack-to-rack within the same row. AOC for longer inter-rack runs. Use SMF for anything over 550m. BiDi halves fiber strand usage — great for patching efficiency.
source portbreakout tocable / modulenotes
QSFP+ (40G)4 × 10G SFP+QSFP+ to 4× LC or 4× SFP+ DACMost common breakout. Supported on most data center switches.
QSFP28 (100G)4 × 25G SFP28QSFP28 to 4× LC or 4× SFP28 DACLeaf-spine breakout for 25G server connections.
QSFP28 (100G)2 × 50G SFP56QSFP28 to 2× SFP56Less common. Check switch support.
QSFP-DD (400G)8 × 50G SFP56QSFP-DD to 8× SFP56 DACHigh-density 400G breakout for AI/ML GPU fabric.
QSFP-DD (400G)4 × 100G QSFP28QSFP-DD breakout cableSpine to 100G leaf switches.
quick reference
a/n/ac
5 GHz
b/g/n
2.4 GHz
ax
Wi-Fi 6/6E
be
Wi-Fi 7
n = Wi-Fi 4, ac = Wi-Fi 5, ax = Wi-Fi 6 (6E adds 6 GHz), be = Wi-Fi 7. MIMO (n) → MU-MIMO (ac) → OFDMA + MU-MIMO (ax) → MLO + 320 MHz (be).
amendmentwi-fi genyearbandsmax PHY ratekey techstatus
802.1119972.4 GHz2 MbpsDSSS / FHSSobsolete
802.11bWi-Fi 119992.4 GHz11 MbpsDSSS, CCKobsolete
802.11aWi-Fi 219995 GHz54 MbpsOFDM, 52 subcarriersobsolete
802.11gWi-Fi 320032.4 GHz54 MbpsOFDM (backward compat b)legacy
802.11nWi-Fi 420092.4 / 5 GHz600 MbpsMIMO (4×4), 40 MHz ch, A-MPDUlegacy / IoT
802.11acWi-Fi 520135 GHz only6.9 GbpsMU-MIMO DL, 160 MHz, 256-QAM, beamformingwidely deployed
802.11axWi-Fi 6 / 6E20212.4 / 5 / 6 GHz9.6 GbpsOFDMA, MU-MIMO UL+DL, BSS Color, TWT, 1024-QAMcurrent standard
802.11beWi-Fi 720242.4 / 5 / 6 GHz46 GbpsMLO, 320 MHz ch, 4K-QAM, 16×16 MU-MIMO, Multi-RUemerging
featureWi-Fi 4 (n)Wi-Fi 5 (ac)Wi-Fi 6/6E (ax)Wi-Fi 7 (be)
Modulation64-QAM256-QAM1024-QAM4096-QAM
Max channel width40 MHz160 MHz160 MHz320 MHz
Max spatial streams48816
MU-MIMO (DL)✓ (4 users)✓ (8 users)✓ (16 users)
MU-MIMO (UL)
OFDMA✓ + Multi-RU
Target Wake Time (TWT)
BSS Coloring
Multi-Link Operation✓ (MLO)
6 GHz band✓ (6E only)
Security minimumWPA2WPA2WPA3 (6E mandatory)WPA3 mandatory
📡 Wi-Fi 6E = 802.11ax extended to 6 GHz. Adds up to 1200 MHz of clean spectrum (channels 1–233) with no legacy device interference. Wi-Fi 7's MLO lets clients bond channels across 2.4/5/6 GHz simultaneously for lower latency and higher throughput.
amendmentyearpurpose
802.11e2005QoS / WMM — voice and video priority queues (EDCA)
802.11i2004Security — basis for WPA2 (CCMP/AES)
802.11r2008Fast BSS Transition (FT) — faster roaming handoffs
802.11k2008Radio Resource Measurement — neighbor reports for assisted roaming
802.11v2011BSS Transition Management — AP can suggest clients roam
802.11w2009Management Frame Protection (MFP) — protects deauth/disassoc frames
802.11u2011Interworking — basis for Hotspot 2.0 / Passpoint
802.11s2011Mesh networking standard
802.11p2010WAVE — vehicular / V2X communications (DSRC)
802.11ai2016Fast Initial Link Setup (FILS) — sub-100ms association
quick reference
22
SSH
443
HTTPS
53
DNS
<1024
well-known
Well-known 0–1023, registered 1024–49151, dynamic/ephemeral 49152–65535. TCP for reliable streams, UDP for low-latency/stateless (DNS, DHCP, VoIP).
numberprotocoldescriptioncommon use
1ICMPInternet Control Message Protocolping, traceroute, unreachable messages
2IGMPInternet Group Management Protocolmulticast group membership
6TCPTransmission Control Protocolreliable, connection-oriented transport
17UDPUser Datagram Protocollow-latency, connectionless transport
41IPv6IPv6 encapsulationIPv6-in-IPv4 tunnels (6in4)
47GREGeneric Routing EncapsulationVPN tunnels, PPTP, ERSPAN
50ESPEncapsulating Security PayloadIPsec encrypted payload
51AHAuthentication HeaderIPsec integrity / authentication
58ICMPv6ICMP for IPv6NDP, router discovery, ping6
89OSPFOpen Shortest Path Firstlink-state routing protocol
112VRRPVirtual Router Redundancy Protocolgateway redundancy
132SCTPStream Control Transmission Protocoltelecom / signaling (SS7, Diameter)
portprotoservicenotes
20 / 21TCPFTPData / control. Unencrypted — avoid on production
22TCPSSHSecure remote shell, SCP, SFTP
23TCPTelnetunencrypted — legacy only
25TCPSMTPEmail delivery between servers
53TCP/UDPDNSUDP for queries, TCP for zone transfers / large responses
67 / 68UDPDHCPServer:67, Client:68
69UDPTFTPFirmware upgrades, PXE boot, config backups
80TCPHTTPWeb — unencrypted. Redirect to 443 in production.
123UDPNTPTime sync — critical for certificates, logs, Kerberos
161 / 162UDPSNMPPoll:161, Trap:162. Use v3 with auth+priv in production.
389TCP/UDPLDAPDirectory services. Use 636 (LDAPS) in production.
443TCPHTTPSTLS web traffic, REST APIs, WebSockets
445TCPSMBWindows file sharing, Active Directory
514UDPSyslogNetwork device logging. Use 6514 (TLS syslog) for secure.
636TCPLDAPSLDAP over TLS — use instead of 389
1812 / 1813UDPRADIUSAuth:1812, Accounting:1813. Used by 802.1X / WPA2/3-Ent
3389TCPRDPWindows Remote Desktop Protocol
4500UDPIKE NAT-TIPsec NAT traversal (alongside UDP 500)
8080 / 8443TCPAlt HTTP/HTTPSDev/proxy web traffic. Common on Aruba Central, NMS tools.
quick reference
46 / EF
voice
34 / AF41
video
48 / CS6
net-control
0 / BE
best-effort
DSCP = top 6 bits of the IP ToS byte (64 values). EF (46) for real-time voice, AF4x for video, CS6/CS7 for routing/control. Maps to 802.1p CoS at L2.
DSCP namedecimalbinary (6-bit)IP PrecPHB classtraffic typedrop precedence
CS0 / BE00000000DefaultBest effort — unclassified traffic
EF461011105Expedited ForwardingVoIP RTP, real-time video, latency-sensitiveLow (prioritized queue)
CS6481100006Network ControlRouting protocols (OSPF, BGP, EIGRP)
CS7561110007Network ControlReserved — rarely used in practice
AF11100010101AF Class 1Bulk data, low-priority transfersLow
AF12120011001AF Class 1Bulk dataMedium
AF13140011101AF Class 1Bulk dataHigh
AF21180100102AF Class 2Transactional / interactive dataLow
AF22200101002AF Class 2Transactional dataMedium
AF23220101102AF Class 2Transactional dataHigh
AF31260110103AF Class 3Streaming / mission-critical appsLow
AF32280111003AF Class 3Streaming appsMedium
AF33300111103AF Class 3Streaming appsHigh
AF41341000104AF Class 4Video conferencing, interactive videoLow
AF42361001004AF Class 4Video conferencingMedium
AF43381001104AF Class 4Video conferencingHigh
CS180010001ScavengerLow-priority / scavenger class (P2P, backup)
CS2–CS516/24/32/40varies2–5Class SelectorLegacy IP precedence mapping
DSCP = 6 most significant bits of the IP ToS byte (DSCP value × 4 = ToS byte value). AF drop precedence: within the same AF class, higher precedence = dropped first under congestion. EF at DSCP 46 is the standard for VoIP — it gets a dedicated low-latency queue.
WMM ACpriority802.1pDSCPtraffic typeAIFSCWmin
AC_VOHighest6–7EF (46), CS6/7VoIP, voice calls23
AC_VIHigh4–5AF41 (34)Video streaming, conferencing27
AC_BENormal0, 3CS0 (0), AF21Best effort — web, email, data315
AC_BKLow1–2CS1 (8)Background — backup, P2P, print715
AIFS = Arbitration InterFrame Space. Lower AIFS = less wait before transmitting = higher priority. CWmin = minimum contention window — smaller window = fewer backoff slots = faster access. WMM maps wired DSCP/802.1p markings to wireless access categories at the AP.
traffic classDSCPdecimal802.1p (CoS)WMM AC
VoIP / voiceEF465 or 6AC_VO
Call signaling (SIP)CS3243AC_VI
Video conferencingAF41344AC_VI
Streaming videoAF31264AC_VI
Routing protocolsCS6486AC_VO
Transactional / ERPAF21182AC_BE
Best effort / webCS000AC_BE
Scavenger / P2PCS181AC_BK
unitdefinitionreference pointused forexample
dB Decibel — a ratio between two values on a logarithmic scale. Not an absolute value. Relative — compares two power levels Gain, loss, difference between two signals Antenna gain: +6 dB (4× more power than reference)
dBm Decibels relative to 1 milliwatt. An absolute power measurement. 0 dBm = 1 mW Tx power, RSSI, received signal strength AP Tx power: 20 dBm = 100 mW
dBi Decibels relative to an isotropic antenna (theoretical perfect radiator). 0 dBi = isotropic radiator Antenna gain specification Dipole antenna: 2.14 dBi gain over isotropic
dBd Decibels relative to a dipole antenna. Add 2.14 to convert to dBi. 0 dBd = dipole antenna Antenna gain (older spec sheets) 3 dBd = 5.14 dBi
Key insight: dB is always a ratio (gain or loss). dBm is an absolute power level. You can add dB to dBm to get dBm — e.g. 20 dBm Tx + 6 dBi antenna = 26 dBm EIRP. You cannot add dBm to dBm.
dBmmilliwatts (mW)wattstypical meaning
30 dBm1000 mW1 WMaximum allowed EIRP in many regions (FCC outdoor)
27 dBm500 mW0.5 WHigh-power outdoor AP Tx power
23 dBm200 mW0.2 WHigh indoor AP Tx — typically reduced to avoid co-channel
20 dBm100 mW0.1 WCommon indoor AP Tx power on 5 GHz
17 dBm50 mW0.05 WModerate AP Tx power — good for dense deployments
14 dBm25 mW0.025 WReduced power for high-density / co-channel control
10 dBm10 mW0.01 WLow Tx — short range, IoT devices
0 dBm1 mW0.001 WReference point — 0 dBm by definition
−10 dBm0.1 mW100 µWVery low power
−30 dBm0.001 mW1 µWExcellent received signal (very close to AP)
−70 dBm0.0000001 mW100 pWMarginal received signal — near edge of coverage
Formula: dBm = 10 × log₁₀(mW). Reverse: mW = 10^(dBm/10). A useful anchor: 0 dBm = 1 mW, 10 dBm = 10 mW, 20 dBm = 100 mW, 30 dBm = 1000 mW (1 W).
ruleeffect on powerdirectionreal-world example
+3 dB 2× power increase 20 dBm → 23 dBm doubles radiated power (100 mW → 200 mW)
−3 dB ½ power decrease 20 dBm → 17 dBm halves power (100 mW → 50 mW). Lossy cable, splitter.
+10 dB 10× power increase 20 dBm → 30 dBm = 10× more power (100 mW → 1000 mW)
−10 dB ÷10 power decrease 20 dBm → 10 dBm = 10× less power. Each wall adds ~3–15 dB of loss.
+6 dB 4× power increase High-gain directional antenna vs omni. Doubles range in open space.
−6 dB ¼ power decrease Doubling distance in free space loses ~6 dB (inverse square law).
+20 dB 100× power increase High-gain dish vs dipole. −50 dBm vs −70 dBm RSSI = 100× stronger signal.
−20 dB ÷100 power decrease Typical loss through a concrete wall + floor in a multi-story building.
Memory trick: 3 dB = double/half, 10 dB = ×10/÷10. Chain them: +13 dB = +10 dB + +3 dB = ×10 × ×2 = ×20 power. −7 dB = −10 dB + +3 dB = ÷10 × ×2 = ÷5 power.
scenariocalculationresulttakeaway
AP link budget 20 dBm Tx + 3 dBi antenna − 2 dB cable loss = 21 dBm EIRP Just add and subtract — dB math is arithmetic on the log scale
Client receives −65 dBm, noise floor −95 dBm −65 − (−95) = 30 dB = 30 dB SNR Good SNR — supports MCS 9+ (256-QAM)
Doubling Tx power from 100 mW to 200 mW +3 dB = +3 dBm Barely noticeable to a client — human perception threshold ~6 dB
Client moves from −55 dBm to −61 dBm 6 dB drop = ÷4 power = 4× weaker signal May trigger MCS rate drop — watch for throughput impact
Wall penetration loss (drywall) ~3 dB loss = ½ signal power Concrete: 10–15 dB. Brick: 8–12 dB. Glass: 2–3 dB. Metal: 20–30 dB.
Free space path loss (doubling distance) ~6 dB additional loss = ¼ signal power Every time you double the distance, you lose 6 dB (inverse square law)
Co-channel interference threshold Desired signal − interference > 20 dB = 100:1 ratio 802.11 needs ~20 dB SIR to decode reliably at higher MCS rates
dB changepower multipliersignal stronger/weaker
+1 dB×1.2626% more power
+3 dB×2double
+6 dB×44× — doubles usable range in free space
+10 dB×1010×
+13 dB×2020× (10 + 3)
+20 dB×100100×
+30 dB×10001000×
−1 dB×0.7921% less power
−3 dB×0.5half
−6 dB×0.25quarter
−10 dB×0.1tenth
−20 dB×0.01hundredth
unitdefinitionreference pointused forexample
dB Decibel — a ratio between two values on a logarithmic scale. Not an absolute value. Relative — compares two power levels Gain, loss, difference between two signals Antenna gain: +6 dB (4× more power than reference)
dBm Decibels relative to 1 milliwatt. An absolute power measurement. 0 dBm = 1 mW Tx power, RSSI, received signal strength AP Tx power: 20 dBm = 100 mW
dBi Decibels relative to an isotropic antenna (theoretical perfect radiator). 0 dBi = isotropic radiator Antenna gain specification Dipole antenna: 2.14 dBi gain over isotropic
dBd Decibels relative to a dipole antenna. Add 2.14 to convert to dBi. 0 dBd = dipole antenna Antenna gain (older spec sheets) 3 dBd = 5.14 dBi
Key insight: dB is always a ratio (gain or loss). dBm is an absolute power level. You can add dB to dBm to get dBm — e.g. 20 dBm Tx + 6 dBi antenna = 26 dBm EIRP. You cannot add dBm to dBm.
dBmmilliwatts (mW)wattstypical meaning
30 dBm1000 mW1 WMaximum allowed EIRP in many regions (FCC outdoor)
27 dBm500 mW0.5 WHigh-power outdoor AP Tx power
23 dBm200 mW0.2 WHigh indoor AP Tx — typically reduced to avoid co-channel
20 dBm100 mW0.1 WCommon indoor AP Tx power on 5 GHz
17 dBm50 mW0.05 WModerate AP Tx power — good for dense deployments
14 dBm25 mW0.025 WReduced power for high-density / co-channel control
10 dBm10 mW0.01 WLow Tx — short range, IoT devices
0 dBm1 mW0.001 WReference point — 0 dBm by definition
−10 dBm0.1 mW100 µWVery low power
−30 dBm0.001 mW1 µWExcellent received signal (very close to AP)
−70 dBm0.0000001 mW100 pWMarginal received signal — near edge of coverage
Formula: dBm = 10 × log₁₀(mW). Reverse: mW = 10^(dBm/10). A useful anchor: 0 dBm = 1 mW, 10 dBm = 10 mW, 20 dBm = 100 mW, 30 dBm = 1000 mW (1 W).
ruleeffect on powerdirectionreal-world example
+3 dB 2× power increase 20 dBm → 23 dBm doubles radiated power (100 mW → 200 mW)
−3 dB ½ power decrease 20 dBm → 17 dBm halves power (100 mW → 50 mW). Lossy cable, splitter.
+10 dB 10× power increase 20 dBm → 30 dBm = 10× more power (100 mW → 1000 mW)
−10 dB ÷10 power decrease 20 dBm → 10 dBm = 10× less power. Each wall adds ~3–15 dB of loss.
+6 dB 4× power increase High-gain directional antenna vs omni. Doubles range in open space.
−6 dB ¼ power decrease Doubling distance in free space loses ~6 dB (inverse square law).
+20 dB 100× power increase High-gain dish vs dipole. −50 dBm vs −70 dBm RSSI = 100× stronger signal.
−20 dB ÷100 power decrease Typical loss through a concrete wall + floor in a multi-story building.
Memory trick: 3 dB = double/half, 10 dB = ×10/÷10. Chain them: +13 dB = +10 dB + +3 dB = ×10 × ×2 = ×20 power. −7 dB = −10 dB + +3 dB = ÷10 × ×2 = ÷5 power.
scenariocalculationresulttakeaway
AP link budget 20 dBm Tx + 3 dBi antenna − 2 dB cable loss = 21 dBm EIRP Just add and subtract — dB math is arithmetic on the log scale
Client receives −65 dBm, noise floor −95 dBm −65 − (−95) = 30 dB = 30 dB SNR Good SNR — supports MCS 9+ (256-QAM)
Doubling Tx power from 100 mW to 200 mW +3 dB = +3 dBm Barely noticeable to a client — human perception threshold ~6 dB
Client moves from −55 dBm to −61 dBm 6 dB drop = ÷4 power = 4× weaker signal May trigger MCS rate drop — watch for throughput impact
Wall penetration loss (drywall) ~3 dB loss = ½ signal power Concrete: 10–15 dB. Brick: 8–12 dB. Glass: 2–3 dB. Metal: 20–30 dB.
Free space path loss (doubling distance) ~6 dB additional loss = ¼ signal power Every time you double the distance, you lose 6 dB (inverse square law)
Co-channel interference threshold Desired signal − interference > 20 dB = 100:1 ratio 802.11 needs ~20 dB SIR to decode reliably at higher MCS rates
dB changepower multipliersignal stronger/weaker
+1 dB×1.2626% more power
+3 dB×2double
+6 dB×44× — doubles usable range in free space
+10 dB×1010×
+13 dB×2020× (10 + 3)
+20 dB×100100×
+30 dB×10001000×
−1 dB×0.7921% less power
−3 dB×0.5half
−6 dB×0.25quarter
−10 dB×0.1tenth
−20 dB×0.01hundredth
quick reference
0 dBm
= 1 mW
+3 dB
= 2×
+10 dB
= 10×
+20 dBm
= 100 mW
dBm is absolute power; dB is a ratio. +3 dB doubles, −3 dB halves, +10 dB is 10×. EIRP = Tx power − cable loss + antenna gain. Free-space path loss(dB) = 20·log₁₀(d) + 20·log₁₀(f) + 32.44.
termdefinitionformulakey point
dB Decibel — a ratio between two power levels. Not an absolute unit. dB = 10 × log₁₀(P₂ / P₁) Always relative. "3 dB gain" means 2× the power of a reference — but what reference?
dBm Decibels relative to 1 milliwatt. An absolute power level. dBm = 10 × log₁₀(mW / 1mW) 0 dBm = 1 mW. Every +10 dBm = 10× more power. Every +3 dBm ≈ 2× more power.
dBi Antenna gain relative to an isotropic (perfect omnidirectional) radiator. dBi = gain vs theoretical point An antenna with 6 dBi gain focuses power 4× more than a perfect sphere radiator.
dBd Antenna gain relative to a dipole antenna. dBd = dBi − 2.15 Dipole ≈ 2.15 dBi. Always clarify which reference an antenna spec uses.
RSSI Received Signal Strength Indicator — vendor-specific scale, often maps to dBm. unitless (0–255 or 0–100) Not standardized. Most Wi-Fi tools display RSSI as dBm for clarity. Always verify units.
SNR Signal-to-Noise Ratio — how far signal is above the noise floor. SNR (dB) = RSSI − noise floor Noise floor is typically −95 to −100 dBm. SNR >25 dB is needed for high MCS rates.
💡 The key insight: dB is a ratio (dimensionless), dBm is an absolute level. You add dB gains and subtract dB losses. You cannot add two dBm values together — that would be like adding two temperatures to get a combined temperature.
dBmmilliwattsdescriptiontypical context
30 dBm1000 mW (1W)Maximum legal EIRP in some bandsOutdoor bridge / high-power AP
27 dBm500 mWHigh-power outdoor APPoint-to-multipoint deployments
24 dBm250 mWHigh indoor / outdoor AP TxCommon max for enterprise indoor APs
23 dBm200 mWCommon enterprise AP Tx powerAruba, Cisco, Extreme at full power
20 dBm100 mWTypical indoor AP, medium powerMost enterprise APs at reduced power
17 dBm50 mWModerate power — high densityTypical in high-density deployments
14 dBm25 mWLow power — dense AP placementStadium / conference room deployments
10 dBm10 mWVery low powerIoT devices, BLE beacons
0 dBm1 mWReference pointDefinition of 0 dBm
−10 dBm0.1 mWVery weak transmit / strong receiveNear-AP client RSSI
−30 dBm0.001 mWExcellent RSSIClient 1–2m from AP
−67 dBm0.0000002 mWGood RSSI thresholdMinimum for voice / video
−70 dBm0.0000001 mWAcceptable data RSSITypical roaming trigger point
−80 dBm0.00000001 mWWeak — low MCS onlyEdge of coverage, MCS 0–1
−90 dBm0.000000001 mWNear noise floorUnusable for data
💡 The mW values get tiny fast because the dB scale is logarithmic. A -67 dBm signal is 200 picowatts — your AP is detecting signals 50 billion times weaker than its own transmit power. This is why antenna placement and avoiding interference sources matters so much.
rulepower effectexamplepractical meaning
+3 dB ≈ 2× more power 20 dBm → 23 dBm 100 mW → ~200 mW. Doubling Tx power only adds 3 dB — often not worth the interference increase.
−3 dB ≈ half the power 23 dBm → 20 dBm A 3 dB cable loss cuts your signal in half before it reaches the antenna.
+10 dB 10× more power 20 dBm → 30 dBm 100 mW → 1000 mW. Huge jump. Regulatory EIRP limits exist to prevent this being abused.
−10 dB 1/10th the power −60 dBm → −70 dBm RSSI dropping 10 dB is a massive degradation. Client drops 2–3 MCS tiers.
+6 dB 4× more power Antenna upgrade: 0 → 6 dBi A 6 dBi directional antenna quadruples effective radiated power vs an isotropic source.
−6 dB 1/4 the power Distance doubles (free space) In free space, every time distance doubles, signal drops ~6 dB. Indoors is much worse.
🧮 Quick mental math: memorize +3 dB = ×2 and +10 dB = ×10. Everything else follows. +6 dB = ×4, +7 dB ≈ ×5, +13 dB = ×20, +20 dB = ×100. For negative values, flip it: −20 dB = 1/100th the power.
elementdB valuerunning totalnotes
AP Tx power+20 dBm20 dBm100 mW transmit power
Cable / connector loss−1 dB19 dBmShort pigtail cable
Antenna gain+5 dBi24 dBm EIRPDirectional antenna — EIRP is the number that matters for regulatory limits
Free-space path loss (50m, 5GHz)−88 dB−64 dBmSignal received at the client
Wall penetration loss (×2 walls)−14 dB−78 dBm~7 dB per drywall partition
Client antenna gain+2 dBi−76 dBm RSSITypical laptop internal antenna
📐 EIRP (Effective Isotropic Radiated Power) = Tx Power (dBm) + Antenna Gain (dBi) − Cable Loss (dB). This is the number regulators care about. In the US, max EIRP on 5 GHz UNII-1 is 23 dBm (200 mW). You can use a high-gain antenna as long as you reduce Tx power to stay within the EIRP limit.
material / obstacletypical loss (dB)notes
Free space (distance doubles)−6 dBTheoretical. Real-world is worse due to reflections.
Drywall / partition3–5 dBMost common office obstacle
Wooden door3–5 dBSimilar to drywall
Brick / concrete block wall8–15 dBSignificant loss — one wall can kill coverage
Reinforced concrete15–25 dBParking garages, bunkers — plan extra APs
Metal door / filing cabinet20–30 dBNear-complete block. Creates RF dead zones.
Glass window (standard)2–3 dBLow loss — but reflections cause multipath
Low-E glass (energy efficient)20–30 dBMetallic coating blocks RF almost entirely
Human body3–5 dBCrowds absorb RF — factor in for high-density
Floor / ceiling (concrete)10–15 dBBetween floors in a multi-storey building
LMR-400 coax (per metre)~0.23 dB/m @ 2.4GHzLow-loss cable — use the shortest run possible
LMR-400 coax (per metre)~0.44 dB/m @ 5GHzLoss doubles at 5 GHz vs 2.4 GHz
⚠ Low-E glass is the most commonly overlooked RF blocker in modern buildings. A floor-to-ceiling energy-efficient window can cause 20–30 dB loss — equivalent to a concrete wall. Always ask about glazing spec during site surveys.
airtime utilization calculator
presets:
configuration
ap configuration
Wi-Fi standard
Channel width
Spatial streams (AP)
Overhead factor
client mix
Enter number of clients per signal quality tier. Each tier maps to a typical MCS index.
Excellent (MCS 9–11, >-65 dBm) clients
Good (MCS 5–8, -65 to -70 dBm) clients
Fair (MCS 2–4, -70 to -75 dBm) clients
Poor (MCS 0–1, <-75 dBm) clients
Avg traffic per client Mbps
Add switches with their bridge priority and MAC address. Add links between them with path cost. The tool calculates root bridge election, port roles, and visualizes the spanning tree topology.
switches
name
bridge priority
MAC address
links
from switch
to switch
path cost
featureSTP (802.1D)RSTP (802.1w)MSTP (802.1s)
StandardIEEE 802.1D-1998IEEE 802.1w → merged into 802.1D-2004IEEE 802.1s → merged into 802.1Q
Convergence time30–50 seconds< 1 second< 1 second per instance
Port statesBlocking, Listening, Learning, Forwarding, DisabledDiscarding, Learning, ForwardingDiscarding, Learning, Forwarding (per instance)
Port rolesRoot, Designated, BlockedRoot, Designated, Alternate, BackupRoot, Designated, Alternate, Backup, Master
VLAN supportSingle instance (all VLANs)Single instance (all VLANs)Multiple instances — per VLAN group
BPDU handlingRelays BPDUs from rootEach switch generates BPDUsEach switch generates BPDUs per instance
Topology changeTCN floods entire network, 30s+ to reconvergeRapid transition, port-by-port handshakePer-instance topology change
Cisco proprietary variantsPVST+ (per-VLAN STP)Rapid PVST+
Use todayLegacy onlyDefault on most modern switchesEnterprise multi-VLAN environments
parameterdefault valuerangedescription
Hello time2 seconds1–10sInterval between BPDUs sent by root bridge
Forward delay15 seconds4–30sTime spent in Listening and Learning states each
Max age20 seconds6–40sTime before a BPDU is considered stale
Convergence (STP)30–50 secondsMax age + 2× forward delay = 50s worst case
Convergence (RSTP)< 1 secondProposal/agreement handshake replaces timers
Bridge priority327680–61440 (steps of 4096)Lower = more likely to become root bridge
Bridge IDpriority + MAC8-byte value: 2 bytes priority + 6 bytes MAC. Lower Bridge ID wins root election.
Path cost (10G)2IEEE 802.1D-2004 long path cost
Path cost (1G)4IEEE 802.1D-2004 long path cost
Path cost (100M)19IEEE 802.1D-1998 short path cost (still widely used)
Path cost (10M)100IEEE 802.1D-1998 short path cost
Root bridge election: lowest Bridge Priority wins. Tie → lowest MAC address wins. To influence election: set priority to 0 or 4096 on the desired root. Use spanning-tree vlan X priority 0 on Cisco or spanning-tree priority 0 on Aruba AOS-CX.
roleper switchstatedescription
Root Port (RP)One per non-root switchForwardingPort with the lowest root path cost on a non-root switch. Best path toward root bridge.
Designated Port (DP)One per segmentForwardingForwards frames on a given segment. All root bridge ports are designated. One per link.
Blocked / Alternate (BLK)Remaining portsBlockingDiscards frames to prevent loops. In RSTP called Alternate port — takes over if root port fails.
Backup PortRSTP onlyDiscardingRSTP only. Redundant path to a segment where this switch already has a designated port (hub scenario).
quick reference
1–4094
VLAN range
4 B
802.1Q tag
300 s
CAM aging
802.1D/w/s
STP
Access ports carry one untagged VLAN; trunks carry many 802.1Q-tagged + one untagged native VLAN. CAM/MAC table maps MAC→port. RSTP (802.1w) converges in <1 s vs classic STP 30–50 s.
actionwhendetail
LearnAny frame receivedSource MAC + ingress port recorded in the MAC address table (CAM table). Entry ages out after inactivity timeout (default 300s on most platforms).
Forward (unicast)Destination MAC known in tableFrame sent out the single port associated with the destination MAC. No flooding, no copies.
FloodDestination MAC unknown (unknown unicast)Frame sent out all ports in the same VLAN except the ingress port. Unknown unicast + broadcast + multicast all flood.
DropSource = destination port, or port security violationFrame discarded. Also dropped if VLAN mismatch, port in blocking state, or storm control threshold exceeded.
💡 CAM vs TCAM: MAC table uses CAM (Content Addressable Memory) — exact-match lookup in O(1). ACLs/routing use TCAM (Ternary CAM) — supports wildcard/prefix matching. CAM exhaustion causes all unicast to flood (like an unknown MAC). TCAM exhaustion causes route/ACL drops.
entry typehow addedremoved bynotes
DynamicLearned from incoming frames automaticallyAge-out timer (default 300s) or MAC flushMost entries. Refreshed on each frame from that MAC. Cleared by clear mac address-table dynamic.
StaticManually configured by adminManual removal or reboot (unless saved)Persistent. Used to pin a known MAC to a port. Overrides dynamic learning for that MAC.
SecurePort security — learned or manually addedPort security violation actionSticky secure — learned dynamically but saved to running config. Persists across reboot if config saved.
VLAN-mappedEach entry scoped to a VLANSame MAC can exist in multiple VLANs (e.g. a router sub-interface). Table key = MAC + VLAN.
conceptdetail
802.1Q Tag
Tag location4-byte tag inserted into Ethernet frame between src MAC and EtherType. Fields: TPID (0x8100) + PCP (3-bit CoS) + DEI (drop eligible) + VID (12-bit VLAN ID, 0–4095).
Valid VLAN range1–4094. VLAN 0 = priority tagging only (no VLAN). VLAN 4095 reserved. VLAN 1 = default, exists on all ports unless pruned. VLANs 1002–1005 reserved on Cisco for FDDI/Token Ring.
Extended VLANs1006–4094. Require VTP v3 or transparent mode on Cisco. Supported natively on Aruba AOS-CX and Juniper without VTP dependency.
Port Types
Access portCarries one VLAN. Frames arrive untagged, switch tags internally. Frames leave untagged. End devices (PCs, APs, servers) connect here. Port is a member of exactly one VLAN.
Trunk portCarries multiple VLANs. Frames tagged with 802.1Q (except native VLAN). Used for switch-to-switch, switch-to-router, switch-to-AP uplinks. Allowed VLAN list restricts which VLANs traverse.
Native VLANVLAN whose frames traverse a trunk untagged. Default = VLAN 1. Must match on both ends — mismatch causes VLAN hopping risk and CDP/LLDP native VLAN mismatch warnings. Best practice: set native VLAN to an unused VLAN.
Voice VLANAccess port carries data VLAN (untagged) + voice VLAN (tagged via CDP/LLDP-MED). Phone's embedded switch passes PC traffic untagged. Switch port appears as both access + tagged for voice.
VLAN Pruning & VTP
PruningPrevents unnecessary VLAN flooding across trunks that have no members in that VLAN. VTP pruning (Cisco) or manual allowed-VLAN list. Reduces broadcast domain footprint.
VTP modesServer — creates/modifies/deletes VLANs, propagates. Client — receives only, can't modify. Transparent — local only, forwards VTP frames but doesn't sync. Off — VTPv3, doesn't forward. Use transparent/off for safety.
⚠️ VLAN hopping attack: Two vectors — (1) switch spoofing: attacker sends DTP frames to negotiate a trunk, gaining access to all VLANs; (2) double tagging: attacker on native VLAN sends double-tagged frame, outer tag stripped at first switch, inner tag delivers to target VLAN. Mitigate: disable DTP (switchport nonegotiate), set native VLAN to unused VLAN, tag native VLAN explicitly.
protocolstandardmodesnegotiation
LACPIEEE 802.3ad / 802.1AXactive — initiates. passive — responds only. active+active or active+passive forms channel.Preferred. Vendor-neutral. Supports fast timers (1s PDU vs 30s slow). Max 16 members, 8 active.
PAgPCisco proprietarydesirable — initiates. auto — responds only. desirable+desirable or desirable+auto.Cisco-only. Avoid for multi-vendor. Max 8 members.
Static (on)No protocolon — forces channel, no negotiation. Both ends must be on.No protection against misconfiguration. If one side is on+other is LACP, channel won't form. Use with caution.
load balancing methodhashes onbest for
src-macSource MAC onlyMany clients, one uplink. Poor for routed traffic (all same src MAC).
dst-macDestination MAC onlyOne server, many clients.
src-dst-macXOR of src+dst MACGeneral L2 — good default for access-layer bundles.
src-dst-ipXOR of src+dst IPBest for routed/uplink bundles — distributes across varied IP pairs.
src-dst-portIP + L4 portBest overall when available — most entropy for mixed traffic flows.
EtherChannel requirements — all member ports must match: speed, duplex, VLAN config (access VLAN or trunk allowed list), STP settings, and port type (all access or all trunk). Mismatch = channel won't form or will flap. Check with show etherchannel summary — look for (D) = down, (P) = in port-channel, (I) = standalone (not in channel).
802.1D stateRSTP stateforwards data?learns MACs?duration
BlockingDiscardingNoNoUntil STP converges. Receives BPDUs.
ListeningDiscardingNoNo15s (Forward Delay). Participates in STP election.
LearningLearningNoYes15s (Forward Delay). Builds MAC table before forwarding.
ForwardingForwardingYesYesNormal operation.
DisabledDiscardingNoNoAdmin shutdown or no cable.
port roleper switch?description
Root Port (RP)One per non-root switchBest path toward the root bridge. Lowest root path cost. Tie-breaks: lowest upstream bridge ID → lowest port ID.
Designated Port (DP)One per segmentForwards traffic on that segment. Root bridge has all designated ports. Non-root switch wins DP on a segment if it has lower root path cost to root.
Blocked / Alternate (BLK/ALT)Any remaining portsDiscards frames to prevent loops. RSTP Alternate port is the backup root port — transitions to forwarding instantly if RP fails (no 30s delay).
Backup (BKP)RSTP onlyBackup designated port on the same shared segment (hub scenario). Rarely seen in modern networks.
Convergence times: 802.1D STP = up to 50s (20s max-age + 15s listen + 15s learn). RSTP = 1–2s via rapid transition and proposal/agreement. MSTP = RSTP convergence per instance. PortFast / Edge port: skips listening+learning, goes straight to forwarding — only use on access ports connected to end devices, never on switch-to-switch links.
methodhow it worksproscons
Router-on-a-StickRouter with sub-interfaces on a trunk port. Each sub-interface = one VLAN with 802.1Q encapsulation and a default gateway IP.Simple, one physical port. Works with any router.Single physical uplink = bottleneck. Router CPU handles all routing. Latency slightly higher.
L3 Switch (SVI)Layer 3 switch with Switch Virtual Interfaces (SVIs) — interface vlan X with IP address per VLAN. Routing happens in hardware (ASIC/TCAM).Wire-speed routing. No external router needed. Lower latency.Requires L3 license on some platforms. More complex config.
Separate physical routerDedicated router with a physical port in each VLAN — each port in a different subnet.Full isolation, dedicated hardware.Requires one router port per VLAN. Expensive and inflexible at scale.
📌 SVI gotcha: An SVI only comes up if at least one port in that VLAN is active and in forwarding state. An SVI with no active ports stays down even if the VLAN exists. Add no autostate (Cisco) to keep the SVI up regardless of member port states — useful for management VLANs.
featurewhat it doesviolation actions / notes
Port Security
Max MACsLimits number of MAC addresses allowed on a port. Default = 1.Shutdown — err-disables port, sends SNMP trap (default). Restrict — drops violating frames, increments counter. Protect — drops silently, no log.
Sticky MACDynamically learns MACs and saves to running config. Survives reboot if config saved. Useful for locking known devices without pre-configuring MACs.Configured via switchport port-security mac-address sticky. Review learned MACs with show port-security address.
Storm Control
Storm controlRate-limits broadcast, multicast, or unknown-unicast traffic per port. Threshold set as % of bandwidth or pps. Prevents broadcast storms from overwhelming the network.Actions: shutdown (err-disable) or trap (SNMP only). Typical threshold: 20% for broadcast, 10% for unknown unicast.
BPDU Guard & Root Guard
BPDU GuardErr-disables a PortFast/edge port if a BPDU is received. Prevents rogue switches from connecting to access ports and influencing STP topology.Enable globally: spanning-tree portfast bpduguard default. Enable per-port: spanning-tree bpduguard enable. Recovery: errdisable recovery cause bpduguard.
Root GuardPrevents a port from becoming a root port — if a superior BPDU arrives, port goes to root-inconsistent (blocking) state. Protects root bridge placement.Applied on ports facing untrusted switches or downstream switches that should never become root. Does not err-disable — recovers automatically when superior BPDUs stop.
Loop GuardPrevents unidirectional link failures from causing a non-designated port to incorrectly transition to forwarding (if BPDUs stop being received).Moves port to loop-inconsistent (blocking) instead of forwarding when BPDUs are lost. Recovers automatically. Complement to Root Guard — use on root and alternate ports.
symptomlikely causecheck / fix
Port stuck err-disabledBPDU guard, port-security, storm control, UDLD, or loopback detectedshow interfaces status err-disabled — reason column tells you why. Fix root cause, then shutdown / no shutdown or configure errdisable recovery.
Hosts in same VLAN can't communicateVLAN not active, STP blocking, port mismatchVerify VLAN exists and is active: show vlan brief. Check STP state: show spanning-tree vlan X. Verify both ports are in same VLAN: show interfaces trunk / show interfaces switchport.
Trunk not passing a VLANVLAN pruned, not allowed, or not active on both sidesshow interfaces trunk — check "VLANs allowed and active in management domain" column. VLAN must be created, active, and in allowed list on both ends.
EtherChannel won't formMode mismatch, config mismatch on member portsshow etherchannel summary — look for (D) standalone. Check speed/duplex, VLAN config, STP settings all match. LACP requires at least one side active.
STP topology keeps changingTC (Topology Change) storm, flapping portshow spanning-tree detail — look for "topology changes" counter and "last change occurred". Enable BPDU guard on access ports. Check for flapping uplinks or rogue switches.
High CPU on switchBroadcast storm, STP instability, CAM overflow, process-switched trafficCheck show processes cpu sorted. Enable storm control. Verify STP stable. Check CAM table size: show mac address-table count. Identify flooded VLANs.
Native VLAN mismatch warningNative VLAN differs on trunk endpointsCDP/LLDP logs: "Native VLAN mismatch discovered on X." Match native VLAN on both sides or set native VLAN to a dedicated unused VLAN on all trunks.
MAC flapping log messagesLoop in the network, dual-homed device, NIC teaming issueMAC seen on multiple ports = loop or bonding misconfiguration. show mac address-table — if a MAC appears on 2+ ports, trace from each port. Check EtherChannel consistency and STP topology.
🔍 Essential show commands: show vlan brief · show interfaces trunk · show interfaces switchport · show mac address-table · show spanning-tree [vlan X] · show etherchannel summary · show interfaces status · show interfaces status err-disabled
quick reference
254
/24 hosts
2
/30 hosts
65,534
/16 hosts
1
/32 host
Usable hosts = 2^(32 − prefix) − 2 (network + broadcast reserved); /31 = 2 (point-to-point, RFC 3021), /32 = single host. Block size = 256 − mask octet.
prefix subnet mask wildcard total hosts usable hosts binary mask network host common use
/0 0.0.0.0 255.255.255.255 4295.0M 4295.0M 00000000.00000000.00000000.00000000 entire internet
/1 128.0.0.0 127.255.255.255 2147.5M 2147.5M 10000000.00000000.00000000.00000000
/2 192.0.0.0 63.255.255.255 1073.7M 1073.7M 11000000.00000000.00000000.00000000
/3 224.0.0.0 31.255.255.255 536.9M 536.9M 11100000.00000000.00000000.00000000
/4 240.0.0.0 15.255.255.255 268.4M 268.4M 11110000.00000000.00000000.00000000
/5 248.0.0.0 7.255.255.255 134.2M 134.2M 11111000.00000000.00000000.00000000
/6 252.0.0.0 3.255.255.255 67.1M 67.1M 11111100.00000000.00000000.00000000
/7 254.0.0.0 1.255.255.255 33.6M 33.6M 11111110.00000000.00000000.00000000
/8 255.0.0.0 0.255.255.255 16.8M 16.8M 11111111.00000000.00000000.00000000 class A
/9 255.128.0.0 0.127.255.255 8.4M 8.4M 11111111.10000000.00000000.00000000
/10 255.192.0.0 0.63.255.255 4.2M 4.2M 11111111.11000000.00000000.00000000
/11 255.224.0.0 0.31.255.255 2.1M 2.1M 11111111.11100000.00000000.00000000
/12 255.240.0.0 0.15.255.255 1.0M 1.0M 11111111.11110000.00000000.00000000
/13 255.248.0.0 0.7.255.255 524.3K 524.3K 11111111.11111000.00000000.00000000
/14 255.252.0.0 0.3.255.255 262.1K 262.1K 11111111.11111100.00000000.00000000
/15 255.254.0.0 0.1.255.255 131.1K 131.1K 11111111.11111110.00000000.00000000
/16 255.255.0.0 0.0.255.255 65.5K 65.5K 11111111.11111111.00000000.00000000 class B (65K hosts)
/17 255.255.128.0 0.0.127.255 32.8K 32.8K 11111111.11111111.10000000.00000000
/18 255.255.192.0 0.0.63.255 16.4K 16.4K 11111111.11111111.11000000.00000000
/19 255.255.224.0 0.0.31.255 8.2K 8.2K 11111111.11111111.11100000.00000000
/20 255.255.240.0 0.0.15.255 4.1K 4.1K 11111111.11111111.11110000.00000000 4K hosts
/21 255.255.248.0 0.0.7.255 2.0K 2.0K 11111111.11111111.11111000.00000000 2K hosts
/22 255.255.252.0 0.0.3.255 1.0K 1.0K 11111111.11111111.11111100.00000000 1K hosts
/23 255.255.254.0 0.0.1.255 512 510 11111111.11111111.11111110.00000000 512 hosts (2 x /24)
/24 255.255.255.0 0.0.0.255 256 254 11111111.11111111.11111111.00000000 class C — most common
/25 255.255.255.128 0.0.0.127 128 126 11111111.11111111.11111111.10000000 2 x /25 from /24
/26 255.255.255.192 0.0.0.63 64 62 11111111.11111111.11111111.11000000 4 x /26 from /24
/27 255.255.255.224 0.0.0.31 32 30 11111111.11111111.11111111.11100000 8 x /27 (30 hosts)
/28 255.255.255.240 0.0.0.15 16 14 11111111.11111111.11111111.11110000 16 x /28 (14 hosts)
/29 255.255.255.248 0.0.0.7 8 6 11111111.11111111.11111111.11111000 8 hosts — point-to-point+
/30 255.255.255.252 0.0.0.3 4 2 11111111.11111111.11111111.11111100 4 hosts — p2p links
/31 255.255.255.254 0.0.0.1 2 11111111.11111111.11111111.11111110 2 hosts — RFC3021 p2p
/32 255.255.255.255 0.0.0.0 1 11111111.11111111.11111111.11111111 single host / loopback
💡 Usable hosts = total − 2 (network address + broadcast). /31 is a special case per RFC 3021 — used for point-to-point links with no network/broadcast waste. /32 is a host route (single IP). /24 = 255.255.255.0 is the most common subnet in enterprise networks.
quick reference
EAP-TLS
cert/cert
PEAP
tunnelled
1812 / 1813
RADIUS
EAPOL
transport
802.1X port-based access control: supplicant → authenticator → RADIUS server. EAP-TLS = mutual certs (strongest); PEAP/EAP-TTLS tunnel an inner method (MSCHAPv2). Success → dynamic VLAN/role.
supplicant
Client Device
The end device requesting network access. Runs an EAP supplicant (built into Windows, macOS, iOS, Android). Presents credentials or certificates to the authenticator.

Examples: Windows native supplicant, Cisco AnyConnect NAM, SecureW2, Jamf Connect
authenticator
AP or Switch
The network access device that enforces 802.1X. It does NOT validate credentials itself — it acts as a relay between supplicant and RADIUS. Controls port access via PAE (Port Access Entity).

Examples: Aruba AP/switch, Cisco WLC/switch, Ruckus AP, Juniper EX
authentication server
RADIUS Server
Validates credentials, certificates, or SIM. Returns Access-Accept or Access-Reject. Can return VLAN, ACL, and role assignments via RADIUS attributes (VSAs).

Examples: Aruba ClearPass, Cisco ISE, Microsoft NPS, FreeRADIUS, Jumpcloud
802.1X AUTHENTICATION FLOW
Supplicant ──────────────────────────────── Authenticator (AP/Switch) ────────────────── RADIUS Server
──── EAPOL-Start ────────────────────────────►
◄─── EAP-Request/Identity ────────
──── EAP-Response/Identity ─────────────────► ─── RADIUS Access-Request ──────────────────────►
◄─── RADIUS Access-Challenge ─
◄─── EAP-Request (method) ────────
... EAP method exchange (TLS tunnel / challenge-response) ...
──── EAP-Response ───────────────────────────► ─── RADIUS Access-Request ──────────────────────►
──── RADIUS Access-Accept ────►
◄─── EAP-Success ───────────────── (+ optional: VLAN, ACL, role via VSAs)
◄─── 802.1X port opens / network access granted ────────────────────
The authenticator uses RADIUS (UDP 1812 for auth, 1813 for accounting) to communicate with the RADIUS server. It never sees the actual credentials — it only relays EAP messages. This separation is what makes 802.1X secure even on untrusted network equipment.
method inner auth outer tunnel client cert req? server cert req? identity protection complexity common use
PEAP
Protected EAP
MSCHAPv2 (usually) TLS tunnel ✗ not required ✓ required ✓ outer identity anonymous Low Most common enterprise Wi-Fi. Username/password via AD/LDAP. Windows native.
EAP-TLS
TLS mutual auth
Certificate (no inner) TLS mutual auth ✓ required (client PKI) ✓ required ✓ strongest protection High Highest security. Requires PKI for every device. Passwordless. MDM/SCEP typically used.
EAP-TTLS
Tunneled TLS
PAP, CHAP, MSCHAPv2, or others TLS tunnel ✗ not required ✓ required ✓ outer identity anonymous Medium More flexible inner auth than PEAP. Common on Linux/Android. Less Windows-native support.
EAP-FAST
Flexible Auth via Secure Tunneling
MSCHAPv2, GTC, or TLS PAC (Protected Access Credential) ✗ not required ✓ optional (PAC provisioning) ✓ PAC-based tunnel Medium Cisco proprietary alternative to PEAP. Used where cert infrastructure isn't available. Less common.
EAP-SIM
SIM card auth
SIM GSM challenge-response None (SIM provides security) ✗ uses SIM instead ✗ not required ⚠ limited (IMSI exposed) Low (for carrier) Carrier Wi-Fi offload. Hotspot 2.0 / Passpoint. Seamless auth using SIM credentials.
EAP-AKA
Auth & Key Agreement
USIM AKA challenge-response (3G/4G) None ✗ uses USIM ✗ not required ✓ improved vs EAP-SIM Low (for carrier) Evolved SIM auth for UMTS/LTE. More secure than EAP-SIM. Used in carrier Wi-Fi offload.
PEAP-MSCHAPv2 is the most deployed enterprise EAP method due to its low client-side complexity (no client cert needed). EAP-TLS is the gold standard for security but requires a full PKI with certificate enrollment for every device — typically via SCEP/ACME through an MDM like Jamf, Intune, or ClearPass Onboard.
EAP method RADIUS server cert client cert CA cert (on client) deployment complexity notes
PEAP-MSCHAPv2 ✓ required ✗ not needed ⚠ should validate Low — creds only Clients MUST validate server cert to prevent MITM. Many deployments skip this — a critical security gap.
EAP-TLS ✓ required ✓ required (per device) ✓ required High — full PKI needed Every device needs a unique cert. Use MDM + SCEP/ACME for automated enrollment. Revocation via OCSP/CRL.
EAP-TTLS ✓ required ✗ not needed ⚠ should validate Medium Same cert risks as PEAP if server cert not validated. Better inner auth flexibility.
EAP-FAST ⚠ optional ✗ not needed ⚠ depends on provisioning Medium Anonymous PAC provisioning (phase 0) can be vulnerable. Use authenticated PAC provisioning where possible.
EAP-SIM / EAP-AKA ✗ not used ✗ not used ✗ not used Low (carrier managed) Auth is handled by SIM / USIM cryptography. No certificates involved — carrier PKI handles security.
⚠ PEAP without server cert validation is one of the most common Wi-Fi security misconfigurations. Without it, any rogue AP with a self-signed cert can perform a man-in-the-middle attack and capture MSCHAPv2 hashes (which can be cracked offline). Always configure trusted CA and server name validation on supplicants.
methodphase 1 (outer)phase 2 (inner)what's protectedcredential type
PEAP TLS tunnel established using server cert. Outer identity = anonymous@domain MSCHAPv2 challenge-response with AD username/password inside the tunnel Inner identity + credentials hidden Username + password (AD/LDAP)
EAP-TLS Mutual TLS handshake — both client and server present certificates No phase 2 — certificate IS the credential Full mutual auth, no password ever sent X.509 client certificate (device or user)
EAP-TTLS TLS tunnel using server cert. Anonymous outer identity. Any inner method: PAP, CHAP, MSCHAPv2, or even another EAP Inner identity + credentials hidden Username + password (flexible inner methods)
EAP-FAST Phase 0: PAC (Protected Access Credential) provisioning. Phase 1: PAC establishes tunnel MSCHAPv2, GTC (token), or EAP-TLS inside tunnel Depends on PAC provisioning security PAC file + inner credentials
EAP-SIM No tunnel. RADIUS sends GSM triplets (RAND, SRES, Kc) from HLR/HSS No phase 2 — SIM card performs RAND challenge-response IMSI can be exposed in early exchanges SIM card (GSM A3/A8 algorithm)
PEAP and EAP-TTLS both use a TLS tunnel to protect inner credentials — the key difference is PEAP is primarily designed for MSCHAPv2 while EAP-TTLS supports any inner method including PAP (plaintext over the encrypted tunnel). EAP-TLS has no inner phase — the mutual certificate exchange is the entire authentication.
authentication
Who are you?
Verifies the identity of a user or device before granting any access. The supplicant presents credentials — password, certificate, SIM, or token — and the authentication server validates them.

Methods: Password (MSCHAPv2), Certificate (EAP-TLS), SIM (EAP-SIM), Token (OTP/GTC)

Protocols: RADIUS (UDP 1812), TACACS+ (TCP 49), Diameter (SCTP/TCP 3868)
authorization
What can you do?
Determines what network resources and permissions a successfully authenticated identity receives. Applied after auth succeeds, before network access is granted.

Outputs: VLAN assignment, ACL/dACL, downloadable policy, QoS profile, role/group, session timeout, bandwidth limit

Mechanisms: RADIUS attributes (VSAs), ClearPass roles, ISE authorization profiles, CoA (Change of Authorization)
accounting
What did you do?
Records session activity — when a user connected, disconnected, how much data was transferred, which device/port was used. Used for auditing, billing, and troubleshooting.

Records: Session start/stop, bytes in/out, session duration, NAS IP, calling-station-ID (MAC), framed-IP

Protocol: RADIUS Accounting (UDP 1813), TACACS+ accounting (TCP 49)
featureRADIUSTACACS+Diameter
TransportUDP 1812 (auth) / 1813 (acct)TCP 49 (reliable)TCP / SCTP 3868
EncryptionPassword only (MD5)Full packet body encryptedTLS / DTLS
AAA separationAuth + Authz combinedAuth / Authz / Acct fully separateFully modular
Protocol originOpen standard (RFC 2865/2866)Cisco proprietary (extended)IETF RFC 6733 (RADIUS successor)
Primary useNetwork access (802.1X, VPN, Wi-Fi)Device administration (CLI, SSH, enable)Mobile/carrier (LTE, IMS, Hotspot 2.0)
Command authorization✗ not supported✓ per-command authorization✗ not applicable
Attribute extensibilityVSAs (vendor-specific attributes)Flexible — any attributeAVPs (attribute-value pairs) — fully extensible
Change of Authorization✓ RFC 5176 (CoA / Disconnect)✗ not standard✓ native re-auth
FailoverClient retries to backup serverClient retries to backup serverNative peer failover
Common serversClearPass, ISE, NPS, FreeRADIUSClearPass, ISE, ACS (legacy), TACACS ProDiameter base on carrier gear
RADIUS vs TACACS+: Use RADIUS for network access control (802.1X, VPN, Wi-Fi auth). Use TACACS+ for device administration — it encrypts the entire packet and supports per-command authorization, making it significantly better for auditing SSH/CLI access to switches and routers. Many enterprises run both: RADIUS for user/device NAC, TACACS+ for admin access.
attributetype #directionvalue / exampleuse
User-Name1Request[email protected]Identity sent to RADIUS. For 802.1X, outer identity is often anonymous@domain.
Framed-IP-Address8Accept192.168.10.50Assign specific IP to user (used with some VPN/PPP scenarios).
Framed-MTU12Accept1400Set MTU for the session.
Session-Timeout27Accept28800 (seconds)Force re-authentication after N seconds. Common: 8h = 28800.
Idle-Timeout28Accept600Disconnect idle sessions after N seconds.
Calling-Station-Id31RequestAA-BB-CC-DD-EE-FFClient MAC address. Used by ClearPass/ISE for device profiling and policy lookup.
NAS-IP-Address4Request10.0.0.1IP of the AP or switch sending the RADIUS request.
NAS-Port-Type61Request19 = Wireless-802.11Access method. 15 = Ethernet, 19 = Wireless.
Tunnel-Type64Accept13 = VLANUsed with VLAN assignment. Must be set to 13 (VLAN) for dynamic VLAN.
Tunnel-Medium-Type65Accept6 = 802Always 6 (IEEE 802) for VLAN assignment.
Tunnel-Private-Group-Id81Accept"100" (VLAN ID)The VLAN ID to assign. All three Tunnel-* attributes must be present for dynamic VLAN to work.
Reply-Message18Reject/Challenge"Invalid credentials"Human-readable message returned on failure. Useful in RADIUS logs.
Dynamic VLAN assignment requires three RADIUS attributes returned in Access-Accept: Tunnel-Type = VLAN(13), Tunnel-Medium-Type = IEEE-802(6), and Tunnel-Private-Group-Id = "VLAN_ID". Missing any one of these will cause the AP/switch to ignore the VLAN assignment and fall back to the default VLAN.
CoA typeRADIUS codedirectionwhat it doescommon use case
CoA-Request43RADIUS server → NASChanges session attributes mid-session without disconnectPush new VLAN/ACL/role after posture check completes
CoA-ACK44NAS → RADIUS serverCoA accepted and appliedConfirms the NAS applied the new policy
CoA-NAK45NAS → RADIUS serverCoA rejectedSession not found, attribute unsupported, or NAS error
Disconnect-Request (PoD)40RADIUS server → NASForcibly disconnects a session (Packet of Death)Quarantine a compromised device, force re-auth after password change
Disconnect-ACK41NAS → RADIUS serverSession disconnected successfullyDevice will need to re-authenticate to regain access
Disconnect-NAK42NAS → RADIUS serverDisconnect failedSession not found or NAS doesn't support PoD
CoA is initiated by the RADIUS server (ClearPass/ISE) toward the NAS (AP/switch) on UDP port 3799. The NAS must have CoA enabled and the RADIUS server IP whitelisted. CoA is used in posture-based NAC workflows — device connects to a quarantine VLAN, passes health check, CoA pushes the production VLAN without disconnecting the session.
quick reference
1812
RADIUS auth
1813
accounting
3799
CoA
802.1X / MAB
methods
Enforcement order typically 802.1X → MAC-auth-bypass → web-auth. CoA (Change of Authorization, UDP 3799) lets the server re-authorize or bounce a session live. Result = dynamic VLAN / dACL / role.
CLIENT CONNECTS TO PORT / SSID
Device connects — authenticator sends EAP-Request/Identity
802.1X supplicant present?
YES → EAP exchange begins → RADIUS validates → Access-Accept / Reject
NO → EAP timeout → MAB triggered (if configured)
│ (MAB path)
RADIUS receives MAB request (MAC as username/password)
MAC known → Access-Accept + policy (VLAN/role/ACL)
MAC unknown → Reject or redirect to guest/onboarding VLAN
│ (posture path)
Posture check required? (ClearPass OnGuard / ISE agent)
PASS → CoA pushes production VLAN/role — no disconnect
FAIL → Stays in quarantine VLAN / remediation redirect
NO AGENT → Policy decision: trust level, profiling, or quarantine
802.1X
EAP Authentication
Strongest method. Supplicant required on device. Identity verified by RADIUS via EAP-TLS, PEAP, or EAP-TTLS. Supports per-user/device policy enforcement via VSAs.

Best for: Corp-managed endpoints, BYOD with MDM enrollment
MAB
MAC Auth Bypass
Fallback for devices without 802.1X (IoT, printers, cameras). MAC address sent as RADIUS username AND password. Inherently weak — MAC can be spoofed.

Best for: IoT/OT devices, printers, IP phones with no supplicant
Captive Portal
Web Auth
Browser-based credential entry. No supplicant needed. Used for guest access, BYOD onboarding, or as fallback after MAB. Credentials typically validated against LDAP or a sponsor portal.

Best for: Guest Wi-Fi, contractor access, BYOD first-time enrollment
aspectdetailnotes
RADIUS request formatUsername = MAC (no colons, lowercase)
Password = same MAC string
Format varies by vendor — Aruba uses lowercase no-delimiter. Cisco uses lowercase colon-separated. Verify format matches RADIUS policy.
Trigger conditionEAP timeout (typically 3 retries × ~30s) or explicit port configOn Aruba: aaa authentication mac-auth. On Cisco: mab under interface.
Security riskMAC spoofing trivialAttacker clones a known-good MAC and bypasses NAC. Mitigate with profiling (DHCP fingerprint, HTTP UA, CDP/LLDP) to verify device type matches expected MAC OUI.
Profiling integrationClearPass/ISE correlates DHCP, HTTP, SNMP, NMAP dataProfile confirms "this MAC claims to be a Cisco IP phone, fingerprint matches." Adds confidence to MAB decisions.
Typical policy outcomeRestricted VLAN, limited ACL, or quarantine until profiledStart least-privilege, CoA to production VLAN after profiling confirms device type.
attributeRADIUS attrsAruba (ClearPass)Cisco (ISE)what it controls
VLAN Assignment Tunnel-Type=VLAN(13)
Tunnel-Medium-Type=802(6)
Tunnel-Private-Group-ID=<VLAN-ID>
Standard RFC 3580 attrs Standard RFC 3580 attrs Dynamically assigns client to a VLAN without static port config. Most common NAC outcome.
User Role (Aruba) VSA 1 — Aruba-User-Role Aruba-User-Role = "employee" N/A (ISE uses SGT) Assigns a named firewall role on Aruba APs/switches. Role defines per-user ACL, bandwidth limits, and captive portal policy.
Downloadable ACL Filter-Id or Cisco-AVPair
ip:inacl#N=...
Aruba-User-Role maps to named ACL DACL (downloadable ACL) pushed via Cisco-AVPair Per-session ACL pushed to the NAS. More granular than VLAN alone — permit/deny specific traffic for this session.
Security Group Tag (Cisco) Cisco-AVPair: cts:security-group-tag=<N> N/A ISE → TrustSec SGT Tags the session with a scalable group ID. SXP or inline tagging propagates the SGT through the network for policy enforcement at egress.
Session Timeout Session-Timeout (attr 27)
Termination-Action (attr 29)
Standard Standard Forces re-authentication after N seconds. Termination-Action=RADIUS-Request re-auths silently; =Default disconnects.
Bandwidth Limit VSA — vendor specific Aruba-User-Role maps to bandwidth contract Cisco-AVPair: ip:sub-qos-policy-in= Per-user bandwidth shaping. Common for guest portals — limit guests to 5 Mbps down/up regardless of SSID capacity.
VSAs are vendor-specific — always load the correct RADIUS dictionary on your RADIUS server. Aruba VSAs use PEN 14823. Cisco VSAs use PEN 9. Mismatched dictionary = attributes silently ignored = no VLAN/role applied = client gets default (often no access or unrestricted).
POSTURE-BASED NAC FLOW (ClearPass / ISE)
1. Device authenticates → Access-Accept with quarantine VLAN + redirect ACL → HTTP redirected to posture agent download URL
2. OnGuard/ISE agent runs → checks AV status, OS patch level, disk encryption, corp cert presence
3a. PASS → agent reports to RADIUS → CoA-Request sent to NAS → new VLAN/role pushed → session updated without disconnect
3b. FAIL → stays in quarantine → remediation page shown (patch link, AV download) → agent re-checks on fix
3c. NO AGENT → timeout → policy decision: limited trust, restrict to quarantine, or CoA to guest role
CoA port: UDP 3799 (NAS must have RADIUS server IP whitelisted + CoA enabled)
Common posture checks
Antivirus — installed, running, definitions current
OS patch level — Windows Update / macOS patch
Disk encryption — BitLocker / FileVault enabled
Corporate cert — machine cert from internal CA present
MDM enrollment — device registered in Intune/Jamf
Firewall — host firewall enabled
Prohibited apps — no unauthorized VPN or P2P software
Aruba ClearPass policy model
Service — matches inbound RADIUS request (by NAS IP, SSID, called-station)
Auth Source — AD, LDAP, local DB, cert, or MAC cache
Auth Method — PEAP, EAP-TLS, MAB, WebAuth
Role Mapping — maps identity attributes → ClearPass role
Enforcement — role + posture → RADIUS response (VLAN, role, ACL)
Profiler — DHCP, HTTP, SNMP, NMAP → device fingerprint
symptomlikely causewhere to lookfix
Access-Reject (error 9002)EAP method mismatch, wrong inner auth, or user not found in auth sourceClearPass Access Tracker → Auth details tab → error codeCheck service matched, auth source reachable, credentials correct. Verify supplicant EAP method matches server policy.
Client stuck in quarantine VLANCoA not reaching NAS, NAS CoA port blocked, or wrong NAS secretClearPass → CoA log; NAS debug radius CoAVerify UDP 3799 open from RADIUS to NAS. NAS must list RADIUS server as CoA source. Check RADIUS shared secret matches.
VLAN not assigned (gets default VLAN)Tunnel attributes missing or wrong format; NAS ignoring VSAsClearPass → Enforcement tab → verify profile sends Tunnel attrs; packet capture RADIUS responseConfirm Tunnel-Type=13, Tunnel-Medium-Type=6, Tunnel-Private-Group-ID=VLAN-ID. Check NAS is configured to honour dynamic VLAN.
MAB fails for known deviceMAC format mismatch between NAS and RADIUS policyClearPass Access Tracker → Request username fieldCheck MAC format sent (Aruba: aabbccddeeff, Cisco: aa:bb:cc:dd:ee:ff or aa-bb-cc-dd-ee-ff). Match RADIUS policy to NAS format.
Server cert validation fails (PEAP)Client doesn't trust RADIUS server cert CA; wrong CA pushed via MDMSupplicant event log; Wireshark — TLS alert handshake_failurePush correct CA cert via MDM profile. Or configure supplicant to trust specific server cert CN. Never disable cert validation in production.
Intermittent re-auth disconnectsSession-Timeout too short; PMK caching not enabled on wirelessAP event log; RADIUS accounting log for session durationIncrease Session-Timeout (3600–86400s for corp devices). Enable PMK/OKC caching on APs to allow silent re-auth without disassociation.
Guest — Self-Service Portal
1. Guest associates to open/OWE SSID → MAB → captive redirect
2. Guest enters name/email or receives SMS OTP
3. Sponsor approval (optional) — email link to sponsor
4. CoA → restricted guest VLAN (internet only, no internal access)
5. Session expires after defined guest duration (4h / 24h)
Aruba: ClearPass Guest portal. Cisco: ISE Guest portal or Meraki splash.
BYOD — Certificate Enrollment
1. BYOD user connects → PEAP with AD creds → limited VLAN
2. Redirect to onboarding portal (ClearPass Onboard / ISE)
3. Device cert issued via SCEP/ACME from internal CA
4. MDM profile pushed (Wi-Fi config, cert, VPN)
5. Disconnect → reconnect → EAP-TLS with device cert → full access
Aruba: ClearPass Onboard. Cisco: ISE BYOD portal. SecureW2 / Jamf also common.
Dual-SSID BYOD (separate onboarding SSID) is cleaner than single-SSID redirect — avoids captive portal issues with HSTS and modern OS captive detection. The onboarding SSID is open/OWE; post-enrollment clients move to the WPA2/3-Enterprise SSID with their device cert.
configuration
ACL name
vendor
quick patterns:
permit HTTPS permit SSH permit DNS permit ICMP deny all permit RADIUS block Telnet RFC1918 →any
permittcp10.0.0.0/8 → any:443HTTPS outbound
permittcp10.0.0.0/8 → any:22SSH to jumphost
permitudp10.0.0.0/8 → 192.168.1.10:53DNS to resolver
permitudp10.0.0.0/8 → 10.10.10.1:1812RADIUS auth
permiticmp10.0.0.0/8 → anyICMP ping
denytcpany → any:23block Telnet
denyipany → anyexplicit deny all
▼ implicit deny ip any any — always applied, not shown in CLI unless added explicitly
ip access-list extended CORP_ACL remark HTTPS outbound permit tcp 10.0.0.0 0.255.255.255 any eq 443 remark SSH to jumphost permit tcp 10.0.0.0 0.255.255.255 any eq 22 remark DNS to resolver permit udp 10.0.0.0 0.255.255.255 host 192.168.1.10 eq 53 remark RADIUS auth permit udp 10.0.0.0 0.255.255.255 host 10.10.10.1 eq 1812 remark ICMP ping permit icmp 10.0.0.0 0.255.255.255 any remark block Telnet deny tcp any any eq 23 remark explicit deny all deny ip any any ! implicit: deny ip any any
wildcard mask quick reference
prefixsubnet maskwildcardhosts
/32255.255.255.2550.0.0.01 (host)
/30255.255.255.2520.0.0.32
/29255.255.255.2480.0.0.76
/28255.255.255.2400.0.0.1514
/27255.255.255.2240.0.0.3130
/24255.255.255.00.0.0.255254
/23255.255.254.00.0.1.255510
/22255.255.252.00.0.3.2551022
/16255.255.0.00.0.255.25565534
/8255.0.0.00.255.255.25516M
any0.0.0.0255.255.255.255all
common ACL patterns
Permit established TCPpermit tcp any any established — allows return traffic without full stateful firewall
Block RFC1918 from WAN — deny private ranges inbound on internet-facing interface
RADIUS traffic — permit UDP 1812/1813 from NAS to RADIUS server only
Management ACL — permit SSH/HTTPS from jump host only, deny any any at end
Guest isolation — deny ip guest-subnet internal-subnets, permit ip any any (internet only)
CoA — permit UDP 3799 from RADIUS server to NAS (often forgotten)
quick reference
default-deny
base rule
stateful
conn tracking
zones
trust model
L7 / NGFW
app-aware
Stateful firewalls track connections and auto-allow established/related return traffic. Rules evaluate top-down — first match wins, implicit deny at the end. NGFW adds L7 app-ID, IPS, and TLS inspection.
typeinspectsstate trackinguse case
Packet filter (stateless)L3/L4 headers only — src/dst IP, protocol, port, flagsNoneRouter ACLs, simple perimeter filtering. Fast, low overhead. No return traffic tracking — must explicitly permit return flows. Easily spoofed.
Stateful inspectionL3/L4 + connection state table (TCP FSM, UDP pseudo-state, ICMP)Connection tableTraditional firewalls (ASA, iptables, pfSense). Permits return traffic automatically by tracking established connections. Blocks unsolicited inbound.
Application layer (proxy)L7 — full payload inspection, protocol complianceFull session proxyWeb proxies, SMTP gateways. Terminates and re-originates connections. High latency, high CPU. Can strip malicious content at protocol level.
NGFWL3–L7 — DPI, app-ID (even encrypted via JA3/fingerprint), user identity, URL categories, IPS/IDSConnection + app statePalo Alto, Fortinet, Check Point, Cisco FTD. App-aware policy — block Dropbox without blocking HTTPS. SSL/TLS inspection (decrypt → inspect → re-encrypt).
WAF (Web Application Firewall)HTTP/HTTPS — request/response bodies, headers, cookies, SQL/XSS patternsHTTP sessionProtects web apps — OWASP Top 10. ModSecurity, AWS WAF, Cloudflare. Sits in front of web server. Complements NGFW, not a replacement.
zonetrust leveltypical contentspolicy notes
Outside / Untrusted0 — No trustInternet, untrusted WAN, partner connectionsDefault deny all inbound. Only permit explicitly needed inbound (DNAT targets, VPN endpoints). Aggressive rate limiting, no ICMP echo reply by default.
DMZ / Semi-trusted1 — Low trustPublic-facing servers — web, mail, DNS, VPN concentratorsInternet → DMZ: permit specific services only. DMZ → Inside: deny all (servers in DMZ should never initiate connections to internal). DMZ → Outside: permit outbound for updates etc.
Inside / Trusted3 — High trustCorporate LAN, user workstations, printersInside → Outside: permit with inspection. Inside → DMZ: permit as needed. Outbound filtering for data loss prevention and malware C2 blocking.
Management / OOB4 — Highest trustNetwork devices management plane, IPMI/iDRAC, OOB switchesStrictly limited access. Jump host / bastion required. No direct access from user VLANs. Log all connections. Consider separate physical network.
Guest / IoT0.5 — Untrusted internalGuest WiFi, BYOD, IoT sensors, building systemsInternet-only. Block all lateral movement to corporate subnets. DNS filtering, limited port access. Treat as hostile — assume compromise.
📐 Design principle: Traffic between zones is denied by default — policy must explicitly permit. Traffic within a zone is typically permitted (same-zone traffic doesn't cross the firewall). Always create a dedicated management zone — never manage firewalls from the same zone they protect.
typemappinguse casenotes
Static NAT1-to-1 — one private IP ↔ one public IP, permanentInbound to public-facing servers (web, mail). Server always reachable at same public IP.Bidirectional — both inbound and outbound work. Consumes one public IP per server. Also called DNAT when applied inbound only.
Dynamic NAT1-to-1 — private IP mapped to available pool address for session durationOutbound for small groups of hosts with a pool of public IPs. Less common now.Pool exhaustion = no new sessions. No port translation — each host needs unique IP. Returns IP to pool after session ends.
PAT / NAT OverloadMany-to-1 — many private IPs share one public IP, differentiated by port numberStandard outbound NAT for homes and enterprises. Entire network shares one public IP.~65,535 ports available per public IP — practical limit ~4,000–6,000 concurrent sessions. Breaks some protocols (FTP active mode, SIP, IPsec AH). ALG required.
Port forwarding (DNAT)Inbound — public IP:port → private IP:portExpose internal service through PAT — e.g. public 203.0.113.1:443 → 10.0.0.10:443Also called destination NAT. Only specific port/protocol forwarded — host remains otherwise unreachable. Common for home lab / small office hosting.
Twice NAT / Bi-directionalBoth src and dst IP translated in same policyOverlapping IP space between sites. Translates both ends to avoid conflicts.Used in mergers/acquisitions when two networks share the same RFC 1918 range. Complex to troubleshoot — capture both pre- and post-NAT traffic.
NAT64IPv6 → IPv4 translation at network boundaryIPv6-only hosts accessing IPv4-only resources. Common in mobile carrier networks.Works with DNS64 — synthesizes AAAA records with embedded IPv4 address. Requires stateful NAT64 gateway. Not the same as IPv6 tunneling.
⚠️ NAT breaks end-to-end connectivity — IPsec (AH mode), some VoIP, FTP active mode, and peer-to-peer protocols require Application Layer Gateways (ALG) or use NAT traversal techniques (NAT-T for IPsec via UDP 4500, STUN/TURN for WebRTC). Disable SIP ALG on consumer/SMB routers — it often corrupts SIP headers rather than fixing them.
conceptdetail
First match winsRules evaluated top-to-bottom. First matching rule is applied — evaluation stops. Order is critical: place most specific rules before general ones. A broad permit before a specific deny will always match first, making the deny unreachable.
Implicit deny allEvery ACL and firewall policy ends with an invisible "deny any any." Traffic not matched by any explicit rule is dropped. On Cisco IOS ACLs, applying an ACL to an interface that has no permit statements blocks all traffic on that interface.
Stateful return trafficStateful firewalls automatically permit return traffic for established sessions — you don't need an explicit permit for TCP ACK, UDP responses, etc. Stateless ACLs (router ACLs) require a matching return rule or use established keyword for TCP.
TCP establishedpermit tcp any any established — permits TCP packets with ACK or RST bit set (return traffic for outbound sessions). Does not permit initial SYN. Only works for TCP, not UDP/ICMP.
Rule shadowingA rule that can never be matched because a broader rule above it already handles all the same traffic. Common mistake: permit ip any any followed by deny tcp any any eq 23 — the deny is shadowed, Telnet is allowed. Audit regularly.
Cleanup ruleExplicit deny ip any any log at the end of every ACL/policy. Functionally same as implicit deny but generates log entries for blocked traffic — essential for troubleshooting and audit trails.
port / protoservicenotes for firewall policy
Infrastructure — almost always needed
UDP 53DNSPermit to internal DNS servers. Block direct external DNS from workstations — forces use of internal resolvers for logging and filtering. TCP 53 for zone transfers and large responses (DNSSEC).
UDP/TCP 67/68DHCPPermit broadcast on access VLANs. Permit UDP 67 to DHCP server for relay. Block DHCP server port from untrusted zones to prevent rogue servers.
UDP 123NTPPermit to internal NTP servers. All devices must sync to common time source for log correlation. Block inbound NTP from internet — NTP amplification DDoS vector.
UDP 161/162SNMP161 = polling (inbound to devices), 162 = traps (outbound to NMS). Restrict to management zone only. SNMPv1/v2c community strings are cleartext — never permit from untrusted zones.
Management
TCP 22SSHPermit from management zone / jump host only. Block from all other zones. Disable Telnet (TCP 23) everywhere — cleartext credentials.
TCP 443HTTPS / management GUIRestrict management GUIs to management zone. Separate from user HTTPS if possible — different interfaces or ACLs. Enforce TLS 1.2+.
TCP 3389RDPNever expose directly to internet. Jump host / VPN required. Restrict source to management subnet. High-value target — enforce MFA.
Common Services
TCP 80 / 443HTTP / HTTPSPermit outbound from inside. For NGFW: enforce HTTPS inspection, block HTTP-only sites or force redirect. Block outbound to known malicious IPs via threat intelligence feeds.
TCP 25 / 587 / 465SMTP / submissionBlock outbound TCP 25 from workstations — prevents direct spam sending. Permit only from mail relay servers. 587/465 = authenticated submission, permit from clients to mail relay.
UDP 500 / 4500IKE / IPsec NAT-TRequired for IPsec VPN. 500 = IKEv1/v2 initial exchange. 4500 = NAT traversal (encapsulates ESP in UDP when NAT detected). Also permit IP protocol 50 (ESP) if no NAT.
TCP/UDP 1194OpenVPNDefault OpenVPN port. Can be changed to TCP 443 to bypass restrictive firewalls. Permit inbound to VPN server only.
UDP 51820WireGuardDefault WireGuard port. Stateless — firewall must permit inbound UDP to WG interface. Responds only to valid authenticated peers (stealth mode for others).
ICMP type 8/0Ping (echo/reply)Permit ICMP echo (type 8) outbound and echo-reply (type 0) inbound from internet for troubleshooting. Block inbound echo from internet to hide topology. Always permit ICMP unreachable (type 3) and time-exceeded (type 11) for path MTU discovery and traceroute.
attackhow it worksmitigation
SYN floodAttacker sends massive volume of TCP SYN packets with spoofed source IPs. Server allocates half-open connection state for each, exhausting connection table.SYN cookies (server-side), SYN rate limiting per source, connection table limits, upstream scrubbing. Firewalls: max half-open connection threshold, SYN proxy.
IP spoofingAttacker sends packets with forged source IP to bypass ACLs, hide identity, or exploit trust relationships.uRPF (Unicast Reverse Path Forwarding) — drops packets whose source IP is not reachable via the ingress interface. Enable on internet-facing interfaces. Ingress/egress filtering (BCP38).
Port scanningAttacker probes ports to discover open services and OS fingerprint before launching targeted exploit.Block ICMP echo from internet. Rate limit SYN to minimize scan speed. Log and alert on port scan patterns. NGFW can identify and block automated scanners via IPS signatures.
Firewall rule bypass via fragmentationAttacker fragments packets so L4 header (port numbers) appears in second fragment — stateless ACL only checks first fragment, permits all fragments from same flow.Stateful firewall tracks fragment state and reassembles before inspection. Never use stateless ACLs as primary perimeter defense against internet traffic.
DNS tunnelingAttacker exfiltrates data or establishes C2 channel by encoding data in DNS queries/responses. Bypasses firewalls that permit UDP 53 outbound.Restrict outbound DNS to internal resolvers only (block direct UDP 53 from workstations to internet). DNS inspection/RPZ on resolvers. Monitor for high-entropy domain names and excessive TXT/NULL queries.
HTTPS C2 / beaconMalware communicates with C2 server over TCP 443 to blend in with normal traffic. Traditional firewalls can't inspect encrypted payload.TLS/SSL inspection (decrypt → NGFW DPI → re-encrypt). Threat intelligence IP/domain blocking. DNS filtering (blocks C2 domain before TLS even established). JA3 fingerprinting for suspicious TLS clients.
Lateral movementOnce inside, attacker pivots between hosts using RDP, SMB, WMI, SSH. Relies on flat internal network with no east-west controls.Micro-segmentation — firewall between VLANs, not just perimeter. Zero-trust: authenticate and authorize every connection. Block SMB (445) and RDP (3389) between user workstations. Monitor for unusual internal port scans.
symptomlikely causecheck / fix
Traffic dropped, no log entryImplicit deny (no log), interface ACL before firewall, or routing issueAdd explicit deny any any log at end of policy. Verify packet is actually reaching the firewall — check routing, ARP, L2 forwarding first. Interface ACLs on the router may be dropping before the firewall sees the packet.
One-way traffic / asymmetric routingReturn path goes through different firewall — stateful table missStateful firewalls require both directions to traverse the same device. Asymmetric routing breaks stateful inspection — SYN on FW-A, SYN-ACK on FW-B = dropped. Fix routing to be symmetric, or use stateful failover / session sync between HA pair.
Connection works then drops after ~1 minIdle timeout expiring on firewallFirewall removed connection state due to inactivity. Increase timeout for that application, or ensure keepalives are configured on the application/TCP stack. Common with SSH, database connections, VoIP.
NAT not workingRule order, wrong interface direction, missing return routeVerify NAT rule matches the traffic (src, dst, port). Check direction — NAT applied on correct interface (inbound vs outbound). Confirm return route exists for translated address. Check NAT translation table: show xlate (ASA) / show ip nat translations (IOS).
VPN up but no trafficInteresting traffic ACL mismatch, routing, or split tunnelingCheck crypto ACL / traffic selectors match on both ends (must be mirror image). Verify routing — is traffic actually sent to VPN interface? Check NAT exemption rule (no-nat for VPN traffic must come before PAT rule). Confirm firewall permits ESP/UDP 4500 inbound.
NGFW blocking valid app trafficApp-ID misidentifying traffic, SSL inspection cert error, IPS false positiveCheck application logs — what app-ID is being assigned? For SSL inspection: verify CA cert is trusted on client, check for cert pinning (some apps break with inspection). IPS: tune signatures, add exception for specific host/app. Temporarily bypass inspection to confirm.
MTU / fragmentation issues through firewallFirewall blocking ICMP type 3 (fragmentation needed), IPsec overheadPing with DF bit set to test: ping -M do -s 1400 X.X.X.X. Ensure ICMP unreachable (type 3 code 4) is permitted through firewall — required for PMTUD. For VPN: set TCP MSS clamping (ip tcp adjust-mss 1350) on tunnel interface.
🔍 Packet capture is your best friend: Capture on both sides of the firewall simultaneously. If packet arrives on ingress interface but never leaves egress — firewall is dropping it. If packet never arrives — upstream routing/switching issue. On ASA: capture CAP interface inside match ip host X host Y. On Linux/iptables: tcpdump -ni eth0 host X with iptables -j LOG rules.
quick reference
ip.addr ==
host filter
tcp.port ==
port filter
tcp.flags
flags
Follow Stream
reassemble
Display filters run post-capture (ip.addr, tcp.port, http, dns, !arp); capture/BPF filters run pre-capture (host, port, net). tcp.analysis.flags surfaces retransmits/dup-ACKs/zero-window. Right-click → Follow → TCP Stream.
filterdescriptionexample
IP / ADDRESS
ip.addr == x.x.x.xAny packet to or from IPip.addr == 192.168.1.10
ip.src == x.x.x.xSource IP onlyip.src == 10.0.0.1
ip.dst == x.x.x.xDestination IP onlyip.dst == 8.8.8.8
ip.addr == x.x.x.x/24Entire subnetip.addr == 192.168.1.0/24
eth.addr == xx:xx:xx:xx:xx:xxMAC address (src or dst)eth.addr == aa:bb:cc:dd:ee:ff
eth.src == xx:xx:xx:xx:xx:xxSource MACeth.src == 00:11:22:33:44:55
TCP / UDP / PORTS
tcp.port == 443TCP src or dst porttcp.port == 443
tcp.dstport == 80TCP destination port onlytcp.dstport == 80
udp.port == 53UDP portudp.port == 53
tcp.flags.syn == 1TCP SYN packets onlytcp.flags.syn==1 && tcp.flags.ack==0
tcp.flags.reset == 1TCP RST — connection resetstcp.flags.reset == 1
tcp.analysis.retransmissionTCP retransmissionstcp.analysis.retransmission
tcp.analysis.zero_windowZero window — receiver buffer fulltcp.analysis.zero_window
APPLICATION PROTOCOLS
dnsAll DNS trafficdns.qry.name contains "google"
dns.flags.response == 0DNS queries onlydns.flags.response == 0
httpAll HTTP traffichttp.request.method == "GET"
tlsTLS/SSL traffictls.handshake.type == 1
icmpPing / ICMPicmp.type == 8 (echo request)
OPERATORS & COMBINING
&& or andBoth conditions must matchip.src==10.0.0.1 && tcp.port==443
|| or orEither condition matchesdns || dhcp
! or notExclude matches!arp && !icmp
containsField contains stringhttp.host contains "example"
matchesRegex matchdns.qry.name matches "\.local$"
in {}Match any value in settcp.port in {80 443 8080}
💡 Display filters use field names (ip.addr, tcp.port) — not BPF syntax. Use Ctrl+Space in the filter bar for autocomplete. Right-click any field in a packet → Apply as Filter to build filters interactively.
protocoldisplay filterwhat to look fornotes
DHCP dhcp or bootp Discover → Offer → Request → ACK sequence. NAK = address conflict. Filter by MAC: dhcp.hw.mac_addr == xx:xx:xx:xx:xx:xx
ARP arp Gratuitous ARP, duplicate IP (ARP probes with no reply), ARP storms. arp.duplicate-address-detected flags IP conflicts automatically
ICMP icmp Echo req/reply (ping), unreachable, TTL exceeded, redirect messages. Type 3 = unreachable, Type 11 = TTL exceeded (traceroute), Type 5 = redirect
ICMPv6 icmpv6 NDP (neighbor discovery), router advertisements, DAD (duplicate address detection). icmpv6.type == 135 = Neighbor Solicitation, 136 = Neighbor Advertisement
DNS dns Failed lookups (NXDOMAIN), slow response times, unexpected resolvers. dns.flags.rcode != 0 = DNS errors. dns.time > 0.5 = slow DNS
STP / RSTP stp BPDUs, topology change notifications (TCN), root bridge changes. TCN floods cause MAC table flushes — look for stp.flags.tc == 1
EAPOL eapol 802.1X auth frames — EAPOL-Start, EAP-Request/Response, EAP-Success/Failure. eap shows inner EAP. Look for EAP-Failure to debug auth issues.
RADIUS radius Access-Request, Access-Accept, Access-Reject, Access-Challenge, Accounting. radius.code == 3 = Access-Reject. Capture on RADIUS server or authenticator uplink.
LLDP / CDP lldp / cdp Neighbor discovery, VLAN IDs advertised, port descriptions, system capabilities. Useful for verifying what VLAN an AP or phone is advertising via LLDP-MED
OSPF ospf Hello packets, LSAs, neighbor state changes, DR/BDR election. ospf.msg == 1 = Hello. Watch for neighbor drops and LSA flooding storms.
VRRP vrrp Virtual router advertisements, master/backup transitions. Multiple masters on same VRIDs = split-brain. Check advertisement intervals match.
topicdetail
Monitor mode (Linux) sudo ip link set wlan0 down && sudo iw wlan0 set monitor none && sudo ip link set wlan0 up
Or: sudo airmon-ng start wlan0 → creates wlan0mon
Monitor mode (macOS) Hold Option → click Wi-Fi icon → Open Wireless Diagnostics → Window menu → Sniffer. Or use tcpdump -I -i en0
Lock to channel sudo iwconfig wlan0mon channel 6 (2.4GHz) or sudo iw dev wlan0mon set channel 36 HT40+ (5GHz)
Filter by BSSID wlan.bssid == aa:bb:cc:dd:ee:ff
Filter by SSID wlan.ssid == "MyNetwork" or wlan.ssid contains "Corp"
Management frames only wlan.fc.type == 0 — beacons, probes, auth, assoc, deauth, disassoc
Beacon frames wlan.fc.type_subtype == 8
Probe requests wlan.fc.type_subtype == 4 — shows clients probing for networks
Authentication frames wlan.fc.type_subtype == 11
Deauth / Disassoc frames wlan.fc.type_subtype == 12 || wlan.fc.type_subtype == 10 — rogue deauth attacks or roaming events
4-way handshake (WPA) eapol && wlan.bssid == xx:xx:xx:xx:xx:xx — capture all 4 EAPOL frames to crack offline (educational)
Signal strength (RSSI) wlan_radio.signal_dbm — filter weak clients: wlan_radio.signal_dbm < -75
Data frames only wlan.fc.type == 2
Retry frames wlan.fc.retry == 1 — high retries = RF interference or poor signal
📡 On Wi-Fi 6 (HE) captures, use wlan_radio.phy == he to isolate 802.11ax frames. For encrypted captures you need the PSK or PMK to decrypt — add via Edit → Preferences → Protocols → IEEE 802.11 → Decryption keys.
toolmenu pathwhat it showsbest for
Protocol HierarchyStatistics → Protocol HierarchyBreakdown of all protocols in capture by packet count and bytes %Quickly identify unexpected protocols or traffic composition
ConversationsStatistics → ConversationsAll TCP/UDP/IP conversations with bytes transferred, durationFind top talkers, high-volume flows, unexpected connections
EndpointsStatistics → EndpointsAll unique IPs/MACs with tx/rx bytesIdentify noisy devices, rogue hosts, broadcast sources
IO GraphStatistics → IO GraphThroughput over time graph. Can overlay multiple filters.Visualize traffic bursts, retransmission spikes, utilization over time
TCP Stream GraphStatistics → TCP Stream GraphsTime-sequence, round trip time, window scaling, throughput graphsTCP performance analysis, identify slow-start, window issues
DNSStatistics → DNSDNS query types, response codes, response timesIdentify DNS failures, slow lookups, unusual query types
HTTPStatistics → HTTPHTTP request/response counters, load distributionWeb traffic analysis, response code distribution
WLAN TrafficWireless → WLAN TrafficPer-SSID/BSSID stats, retry rates, data rates in 802.11 capturesWi-Fi performance analysis, retry rate per AP/client
Expert InformationAnalyze → Expert InformationAuto-detected issues: retransmissions, resets, out-of-order, malformedFast triage — start here on any capture to spot anomalies
Capture File PropertiesStatistics → Capture File PropertiesDuration, packet count, avg packet rate, avg packet sizeHigh-level summary before deep analysis
actionhow touse case
Follow TCP Stream Right-click packet → Follow → TCP Stream. Or: Analyze → Follow → TCP Stream Reconstruct full conversation (HTTP requests, SMTP, Telnet). Shows client bytes in red, server in blue.
Follow UDP Stream Right-click → Follow → UDP Stream DNS, TFTP, SNMP conversations. Less common than TCP but useful for TFTP debugging.
Export HTTP Objects File → Export Objects → HTTP Save files downloaded over HTTP (images, scripts, configs). Essential for malware analysis.
Export SMB Objects File → Export Objects → SMB Extract files transferred over SMB file shares.
IO Graph — overlay filters Statistics → IO Graph → click + to add lines → set display filter per line Compare retransmissions vs total traffic: line 1 = all, line 2 = tcp.analysis.retransmission
Mark / Ignore packets Ctrl+M to mark, Ctrl+D to ignore Highlight key packets for reference or remove noise from analysis.
Time reference Ctrl+T on a packet — sets it as time zero Measure relative timing from a specific event (e.g., DHCP Discover as T=0).
Coloring rules View → Coloring Rules Add custom colors for protocols or filters. Default rules already color TCP errors red.
tshark (CLI) tshark -i eth0 -Y "dns" -T fields -e dns.qry.name Command-line Wireshark. Pipe output to grep/awk. Ideal for remote captures via SSH.
Remote capture (rpcapd) File → Capture Options → Manage Interfaces → Remote Capture on a remote host and view locally. Or use ssh user@host tcpdump -w - | wireshark -k -i -
Decrypt TLS (with key log) Edit → Preferences → Protocols → TLS → Pre-Master-Secret log file Set SSLKEYLOGFILE=~/tls.log env var in Chrome/Firefox, then load the file in Wireshark to decrypt HTTPS.
🔧 Keyboard shortcuts: Ctrl+F find, Ctrl+G go to packet, Ctrl+E collapse all details, Space scroll, Ctrl+Shift+X expert info. Use Analyze → Expert Information as your first stop on any unknown capture — it surfaces retransmissions, resets, and malformed packets automatically.
quick reference
DORA
exchange
UDP 67
server
UDP 68
client
Opt 53
msg type
Discover → Offer → Request → Ack. Option 53 message types 1–8. Across subnets a relay agent sets giaddr (Cisco ip helper-address).
stepmessagesrc → dstwhat happens
1DISCOVER0.0.0.0:68 → 255.255.255.255:67Client broadcasts — "I need an IP." No IP yet, src=0.0.0.0. Includes client MAC in chaddr field and requested options list (Option 55).
2OFFERserver:67 → 255.255.255.255:68Server responds with a proposed IP, subnet mask, gateway, lease time. May be unicast if relay present. Client not yet configured — may receive multiple offers.
3REQUEST0.0.0.0:68 → 255.255.255.255:67Client broadcasts its acceptance of an offer, identifying the chosen server via Option 54. Still broadcast so other servers know their offer was declined.
4ACKserver:67 → 255.255.255.255:68Server confirms. Client configures interface. Lease clock starts. Server records binding in its database. Client performs ARP probe for conflict detection before using IP.
💡 Also used for renewals: at T1 (50% lease) client unicasts REQUEST to the original server. At T2 (87.5%) it broadcasts REQUEST to any server. At expiry it restarts DORA. A NAK at any point forces the client to restart from DISCOVER.
type valuenamedirectionpurpose
1DHCPDISCOVERClient → broadcastInitial lease request. Client has no IP.
2DHCPOFFERServer → clientServer proposes IP + parameters.
3DHCPREQUESTClient → broadcastAccept offer, renew lease, or verify address at boot (INIT-REBOOT).
4DHCPDECLINEClient → serverClient detected IP conflict via ARP probe — address is in use. Server marks address as declined.
5DHCPACKServer → clientConfirms lease. Client applies configuration.
6DHCPNAKServer → clientRejects request — wrong subnet, lease expired, address unavailable. Client must restart DORA.
7DHCPRELEASEClient → serverClient relinquishes lease. Server returns address to pool. Unicast to server.
8DHCPINFORMClient → serverClient already has IP (static) but wants config options (DNS, NTP, etc). Server responds with ACK but no address assignment.
optionnamevalue typenotes
Core Network Config
1Subnet Mask4 bytesNetwork mask for assigned IP. e.g. 255.255.255.0
3Router (Gateway)IP listDefault gateway(s). Multiple IPs in preference order.
6DNS ServersIP listUp to 8 DNS resolvers in preference order.
15Domain NamestringDNS domain for hostname resolution. e.g. corp.example.com
28Broadcast AddressIPBroadcast address for the subnet.
Lease Timing
51Lease Timeuint32 (seconds)Total lease duration. Common: 86400 (1 day), 3600 (1 hr for guests).
58Renewal Time (T1)uint32 (seconds)When client unicasts REQUEST to renew. Default = 50% of lease time.
59Rebinding Time (T2)uint32 (seconds)When client broadcasts REQUEST if no renewal. Default = 87.5% of lease time.
Client / Server Identity
50Requested IPIPClient requests a specific IP (e.g. previously held lease). In DISCOVER or INIT-REBOOT REQUEST.
52Option Overload1 byteOptions overflow into sname or file fields. 1=file, 2=sname, 3=both.
53Message Type1 byteDISCOVER/OFFER/REQUEST/ACK etc. Always present. See message type table above.
54Server IdentifierIPServer IP. Included in OFFER and ACK. Client echoes it in REQUEST to identify chosen server.
55Parameter Request Listbyte listClient lists which options it wants in the reply. e.g. [1,3,6,15,28,43,51,58,59].
60Vendor Class IDstringClient identifies itself — e.g. MSFT 5.0 (Windows), udhcp 1.x. Used for class-based assignment.
61Client Identifiertype + valueOverrides MAC for identifying client. Type 0x01 = MAC. Windows may use GUID instead of MAC.
Enterprise / Relay Options
43Vendor-Specific Infovendor-definedUsed for vendor provisioning — Aruba AP bootstrap, Cisco phone config server, WLC discovery (Option 43 sub-option 3).
82Relay Agent Infosub-optionsAdded by relay agent (switch/router). Sub-opt 1 = Circuit ID (port), Sub-opt 2 = Remote ID (switch MAC). Used for policy/logging.
121Classless Static Routesroute listPush specific routes to client (RFC 3442). Overrides Option 3 on compliant clients. Format: prefix-len, subnet octets, gateway.
⚠️ Option 43 is vendor-specific and interpreted differently per vendor. For Aruba APs: sub-option 3 carries the Mobility Controller IP. Always set alongside Option 60 (Vendor Class ID = ArubaAP) to scope delivery to APs only.
fieldsizedescription
op1 byte1 = BOOTREQUEST (client→server), 2 = BOOTREPLY (server→client)
htype1 byteHardware type. 1 = Ethernet.
hlen1 byteHardware address length. 6 for MAC addresses.
hops1 byteRelay agent hop count. Incremented by each relay. Max 16.
xid4 bytesTransaction ID — random value chosen by client, echoed in all DORA messages to correlate exchange.
secs2 bytesSeconds elapsed since client started attempting to acquire a lease.
flags2 bytesBit 0 = broadcast flag. Set by clients that can't receive unicast before IP is assigned.
ciaddr4 bytesClient IP — populated only when client has valid lease (RENEWING/REBINDING).
yiaddr4 bytes"Your" IP — the address the server is offering or confirming.
siaddr4 bytesServer IP for next bootstrap step (e.g. TFTP server for PXE).
giaddr4 bytesGateway IP — relay agent sets this to its own IP. Server uses it to select scope and route reply.
chaddr16 bytesClient hardware (MAC) address. First 6 bytes used for Ethernet.
sname64 bytesOptional server hostname. Can be overloaded with options (Option 52).
file128 bytesBoot filename for PXE/TFTP. Can be overloaded with options.
magic cookie4 bytesFixed: 0x63825363 — marks start of DHCP options. Required by RFC 2131.
optionsvariableTLV-encoded options. Ends with 0xFF (Option 255 = End). Option 0 = pad byte.
statetriggeraction
BOUNDACK receivedClient has valid lease. T1 and T2 timers start.
RENEWINGT1 expires (default 50% of lease)Client unicasts REQUEST to original server. If ACK received → back to BOUND with new timers.
REBINDINGT2 expires (default 87.5% of lease)Client broadcasts REQUEST — any server can respond. Original server unreachable.
EXPIREDLease time expires, no ACKClient must stop using IP and restart DORA from INIT state.
INIT-REBOOTClient reboots with cached leaseClient broadcasts REQUEST with previously held IP (Option 50). Skips DISCOVER if server confirms.
DECLINEDARP probe detects conflictClient sends DECLINE, server marks address as declined/bad. Client waits 10s then restarts DORA.
📐 Timer defaults: T1 = lease × 0.5  |  T2 = lease × 0.875  |  lease expiry = T. Can be explicitly set via Options 58 and 59. Shorter leases = more DHCP traffic but faster reclamation of stale addresses (good for guest/IoT pools).
featurewhat it doestrusted vs untrustedprotects against
DHCP Snooping Intercepts DHCP messages on access ports. Builds a binding table: MAC → IP → VLAN → port → lease time. Trusted: uplinks to real DHCP servers. Untrusted: all access/edge ports. OFFER/ACK on untrusted port = dropped. Rogue DHCP servers, DHCP starvation (exhausting pool with fake MACs), DHCP spoofing.
Dynamic ARP Inspection (DAI) Validates ARP packets against the DHCP snooping binding table. ARP with IP/MAC not in binding = dropped. Same trusted/untrusted model as snooping. Trusted ports bypass DAI inspection. ARP poisoning / ARP spoofing / MITM attacks. Depends on DHCP snooping table being populated.
IP Source Guard (IPSG) Filters IP packets on untrusted ports — only allows traffic where src IP + MAC matches snooping binding table. Applied per-port. Static IPSG bindings can be added manually for static-IP devices. IP spoofing attacks. Client using an IP it didn't receive via DHCP is silently dropped.
Deployment order matters: Enable DHCP Snooping first to build the binding table, then enable DAI (depends on snooping table), then IPSG. Mark uplink/trunk ports as trusted. On Aruba AOS-CX: ip dhcp snooping globally + ip dhcp snooping trust on uplinks. DHCP snooping + DAI + IPSG together form a strong Layer 2 security triad.
symptomlikely causecheck / fix
169.254.x.x (APIPA)No DHCP response received within timeoutDISCOVER sent but no OFFER. Check relay agent (giaddr), DHCP server reachability, scope exhaustion, snooping trusted ports.
Wrong subnet / wrong poolRelay agent misconfigured or missingVerify giaddr in capture — should match server-facing IP of relay. Check ip helper-address / DHCP relay config on SVI.
DHCP NAK receivedClient requesting expired/wrong-subnet IPClient INIT-REBOOT with stale lease from different subnet. Server rejects it. Client should restart DORA — check OS / force release+renew.
Pool exhaustedScope out of addressesShort lease time + many devices, stale leases, DHCP starvation attack. Check server lease table, enable snooping, expand pool or reduce lease time.
IP conflict detectedStatic device using DHCP pool addressClient sends DECLINE after ARP probe conflict. Exclude static IPs from pool. Check for duplicate statics.
OFFER never arrivesFirewall blocking UDP 67/68, snooping dropCapture at client — see DISCOVER? Capture at server — DISCOVER arriving? Check snooping trusted port config. Check ACLs on VLAN SVI.
Slow lease acquisitionMultiple servers, delayed offers, DADDISCOVER → OFFER delay? Check relay latency. ARP probe/DAD adds ~1-2s. Multiple server offers — client waits for all before choosing.
Option 43 not delivered to APsMissing Option 60 scope filterOption 43 is delivered to all clients unless scoped by Option 60 (Vendor Class ID = ArubaAP). Add vendor class condition to DHCP policy.
🔍 Wireshark filter: dhcp or bootp — look for the DORA sequence via matching xid values. dhcp.hw.mac_addr == xx:xx:xx:xx:xx:xx to isolate a specific client. On Aruba AOS-CX: show dhcp-snooping binding, show ip dhcp-relay statistics. On Windows: ipconfig /release && ipconfig /renew. On Linux: dhclient -r && dhclient eth0.
quick reference
5060 / 5061
SIP / SIPS
RTP
media (UDP)
G.711 / G.729
64 / 8 kbps
EF / 46
voice DSCP
SIP signals call setup; RTP carries the media over UDP (RTCP for stats). Mark voice EF (DSCP 46), call-signaling CS3. Budget <150 ms one-way latency, <30 ms jitter, <1 % loss.
methodpurposenotes
Core Call Control
INVITEInitiate or modify a sessionContains SDP offer in body. Re-INVITE used to change media (hold, codec change, add video).
ACKConfirm INVITE transactionSent after receiving 200 OK to INVITE. Completes the 3-way handshake. Contains SDP answer if not in 200 OK.
BYETerminate an established sessionEither party can send. Triggers RTP teardown. Must receive 200 OK response.
CANCELCancel a pending INVITESent before receiving final response (1xx only). Used when caller hangs up before answer.
Registration & Discovery
REGISTERBind a SIP URI to a contact addressPhone registers its IP with the SIP registrar. Expires header sets registration lifetime (typically 3600s). Re-REGISTER before expiry.
OPTIONSQuery capabilities / keepaliveUsed to discover supported methods, codecs. Also used as a NAT keepalive ping — server responds 200 OK if reachable.
Supplementary Services
SUBSCRIBERequest event notificationsUsed for presence, BLF (busy lamp field), MWI (message waiting indicator). Paired with NOTIFY.
NOTIFYSend event notification to subscriberServer pushes state changes (line busy, voicemail waiting) to subscribed phones.
REFERTransfer a callAttended or blind transfer. Refer-To header contains target URI. Phone receiving REFER sends INVITE to the transfer target.
INFOMid-session signalingDTMF tones (application/dtmf-relay), FAX negotiation. Not for session modification — use Re-INVITE for that.
MESSAGEInstant message transportSimple pager-mode IM. Body contains text/plain or text/html message.
UPDATEModify session before answerLike Re-INVITE but can be used in early dialog (before 200 OK). Codec renegotiation during ringback.
PRACKReliable provisional response ACKACKs 1xx responses (like 180 Ringing) when 100rel extension is used. Ensures no provisional response is lost.
codemeaningcommon cause
1xx — Provisional
100TryingRequest received, processing. Hop-by-hop only — not forwarded end-to-end.
180RingingDestination phone is alerting. Early media may start here (ringback tone).
183Session ProgressEarly media in progress — SDP in body. Used for ringback, announcements before answer.
2xx — Success
200OKCall answered, registration confirmed, OPTIONS replied. Contains SDP answer for INVITE.
3xx — Redirection
302Moved TemporarilyTry alternate URI in Contact header. Used for call forwarding, failover.
4xx — Client Error
400Bad RequestMalformed SIP message. Check headers, SDP syntax.
401UnauthorizedAuthentication required (WWW-Authenticate header). Phone must resend with credentials.
403ForbiddenServer refuses — wrong credentials, call not permitted, number blocked.
404Not FoundSIP URI doesn't exist on this server. Wrong extension, unregistered user.
408Request TimeoutNo response within timer. Network issue, phone unreachable.
480Temporarily UnavailablePhone registered but not answering (DND, away). Also used when all agents busy.
486Busy HereCalled party is on another call. Phone-level busy — UCM may still try other lines.
487Request TerminatedINVITE cancelled by CANCEL request. Normal when caller hangs up before answer.
488Not Acceptable HereNo codec match in SDP offer — codec mismatch between endpoints.
5xx — Server Error
500Server Internal ErrorUCM/PBX fault. Check server logs.
503Service UnavailableServer overloaded or in maintenance. May include Retry-After header.
6xx — Global Failure
600Busy EverywhereCalled party busy on all endpoints — don't retry elsewhere.
603DeclineCalled party explicitly rejected the call (pressed reject button).
caller (A)→/←callee (B)notes
INVITE (SDP offer)A proposes codecs/ports in SDP. Via/Contact headers track routing path.
100 TryingServer/proxy acknowledges receipt. Not forwarded end-to-end.
180 RingingB's phone is alerting. Caller hears ringback (generated locally or via 183 early media).
200 OK (SDP answer)B answers. SDP answer contains B's chosen codec, RTP port, IP. Both sides now have enough to start media.
ACKA confirms. Completes INVITE transaction. RTP can flow both directions.
↔ RTP media flows directly between A and B (peer-to-peer, bypasses SIP proxy) ↔
BYEEither party ends call. RTP stops. Dialog terminated.
200 OKConfirms BYE. Session fully torn down.
💡 SIP vs RTP: SIP is signaling only — it sets up, modifies, and tears down sessions. RTP carries the actual voice and flows directly between endpoints, bypassing the SIP proxy. This means media problems (one-way audio, choppy voice) are usually a network/NAT/QoS issue, not a SIP issue.
protocolportspurposenotes
RTPUDP — even ports, negotiated via SDP (typically 10000–20000)Carries encoded voice/video frames. Each packet = one audio frame (20ms typical). No retransmission — lost packets cause dropouts.Payload type in header identifies codec. Sequence number and timestamp used for jitter buffer and RTCP stats.
RTCPUDP — RTP port + 1 (odd)Control channel for RTP. Reports packet loss %, jitter, round-trip delay. Sender Report (SR) and Receiver Report (RR) every ~5 seconds.Use RTCP stats to distinguish network issues (loss/jitter) from codec/endpoint issues. MOS score can be derived from RTCP-XR.
SRTPSame ports as RTPEncrypted RTP — AES-128/256. Required for security-conscious deployments. Keys exchanged via SDES in SDP or DTLS-SRTP.SRTCP = encrypted RTCP. If capturing, SRTP traffic is opaque without keys. Wireshark can decrypt if you provide key material.
📐 RTP port range: Each call uses 2 UDP ports (RTP + RTCP). A system handling 100 concurrent calls needs 200 ports open. Default ranges: Cisco CUCM 16384–32767, Asterisk 10000–20000, generic RFC suggestion 49152–65535. Ensure firewall/NAT rules cover your configured range.
codecbitratebandwidth w/ headersMOSuse case
G.711 µ-law (PCMU)64 Kbps~87 Kbps (20ms frames, IPv4/UDP/RTP)4.1North America PSTN standard. Excellent quality, high bandwidth. No complexity. PT=0.
G.711 a-law (PCMA)64 Kbps~87 Kbps4.1Europe/international PSTN standard. Functionally identical to µ-law. PT=8.
G.72264 Kbps~87 Kbps4.5Wideband HD voice (50Hz–7kHz vs 300Hz–3.4kHz for G.711). Same bandwidth, much better quality. Modern phones only. PT=9.
G.7298 Kbps~32 Kbps3.9Low-bandwidth WAN/remote sites. CPU-intensive compression. Sensitive to packet loss. Historically required licensing. PT=18.
G.729a8 Kbps~32 Kbps3.7Reduced complexity variant of G.729. Slightly lower quality, interoperable with G.729.
Opus6–510 Kbps (adaptive)~30–80 Kbps typical4.5+WebRTC standard. Adaptive bitrate, handles loss/jitter well. Narrowband + wideband + fullband. Best choice for modern UCaaS/WebRTC. PT=dynamic.
G.72616–40 Kbps~30–55 Kbps3.8ADPCM — legacy DECT/analog trunks. Rarely used in modern IP telephony.
iLBC13.3 / 15.2 Kbps~27–30 Kbps4.1Tolerates packet loss well — designed for lossy networks. Used in some WebRTC deployments before Opus dominated.
📊 Bandwidth math: G.711 with 20ms packetization = 160 bytes payload + 40 bytes IP/UDP/RTP headers = 200 bytes × 50 pps = 80,000 bytes/s = ~640 Kbps per call... wait — that's bits: 80,000 × 8 = 640,000 bps. G.729 = 10 bytes payload + 40 headers = 50 bytes × 50 pps = 20,000 bytes/s = ~160 Kbps per call. Add 20% overhead for good measure.
traffic typeDSCP nameDSCP valuehexCoS (802.1p)queue
Voice (RTP)EF — Expedited Forwarding46 (101110)0x2E5Priority queue — strict priority. Maximum 33% of link bandwidth to avoid starvation of other traffic.
SIP SignalingCS3 — Class Selector 324 (011000)0x183Medium-priority queue. Signaling is low bandwidth but latency-sensitive — delayed INVITE = delayed call setup.
Video (RTP)AF41 — Assured Forwarding34 (100010)0x224High priority but below voice. Drop preference = low. Use for video conferencing streams.
Call Control / SCCPCS3240x183Same class as SIP signaling. Cisco SCCP skinny protocol for CUCM-registered phones.
Best Effort (data)CS0 / DF0 (000000)0x000Default. All unclassified traffic. Never use for voice.
Voice quality thresholds (one-way): Latency <150ms good / 150–400ms acceptable / >400ms unacceptable  |  Jitter <30ms  |  Packet loss <1% (G.711) / <0.5% (G.729). Mark RTP at DSCP EF (46) and trust/re-mark at the access layer. Phones typically self-mark if trusted — configure trust dscp on the voice VLAN access port.
topicdetail
Voice VLAN Architecture
Separate voice VLANAlways isolate voice traffic from data. Separate IP subnet, separate QoS policy, separate DHCP scope. Prevents data storms from impacting voice, simplifies QoS trust boundaries.
Access port configPort carries data VLAN (untagged) + voice VLAN (tagged via CDP/LLDP-MED). Phone's built-in switch passes PC traffic untagged. Port = access + voice VLAN on Cisco; on Aruba AOS-CX use voice-vlan command.
LLDP-MEDLink Layer Discovery Protocol - Media Endpoint Discovery. Vendor-neutral alternative to CDP for voice VLAN assignment. Carries Network Policy TLV (VLAN ID, DSCP, CoS) to phones. Enable on access ports serving IP phones.
CDP voice VLANCisco Discovery Protocol sends voice VLAN ID to Cisco phones. Phone moves to voice VLAN automatically. Aruba switches support CDP passthrough but not origination — use LLDP-MED for non-Cisco phones.
DHCP Provisioning Options
Option 150 (TFTP)Cisco proprietary — carries TFTP server IP for phone config download. Used by SCCP/Cisco SIP phones. Cisco-specific alternative to Option 66.
Option 66 (TFTP server)Standard BOOTP option — TFTP server hostname or IP. Used by many vendors for config file download. String format.
Option 160 / 176Avaya/Nortel provisioning — HTTP provisioning server URL (Option 160) or script parameters (Option 176). Avaya IP phones use these to find the call server and download firmware/config.
Option 43 (vendor-specific)Universal vendor provisioning. Cisco phones: sub-option 150 (TFTP). Polycom: URL of provisioning server. Yealink: config server address. Always pair with Option 60 to scope delivery to phones only.
Short lease for voiceUse shorter DHCP leases (1–4 hours) on voice VLANs. Phones move desks frequently — shorter leases reclaim addresses faster and ensure phones re-provision promptly after moves.
symptomlayerlikely cause & check
One-way audioRTP / NATRTP flowing one direction only. Almost always NAT or firewall blocking return path. Check SDP — is the IP in the c= line reachable from both sides? Asymmetric routing. Media pinned to wrong IP behind NAT.
No audio (both ways)RTP / VLANSIP connected (200 OK / ACK seen) but no RTP. Firewall blocking UDP port range. Wrong VLAN — RTP sourced from data VLAN, firewall rule only permits voice VLAN. Check SDP port negotiation.
Choppy / robotic voiceQoS / networkPacket loss or high jitter. Check RTCP receiver reports for loss %. Run ping with large count. Verify DSCP EF marking survives end-to-end — may be re-marked to 0 at a hop. Jitter buffer overflow.
EchoAcoustic / PSTNAcoustic echo = mic picking up speaker (headset/speakerphone). Electrical echo = impedance mismatch on analog PSTN trunk. Check echo cancellation settings on gateway. High latency >50ms makes echo perceptible.
Call drops after ~30sSIP / NATClassic SIP ALG / NAT timer issue. NAT state times out, BYE can't route back. Firewall UDP timeout shorter than call duration. Disable SIP ALG on NAT device. Enable SIP OPTIONS keepalives.
Calls drop after ~11 minSIP timersSIP session timer (RFC 4028) — re-INVITE sent at session-expires/2, no response = BYE. Usually a proxy timeout at ~11 min (660s). Check Session-Expires and Min-SE headers.
Phone won't registerSIP / DHCP / networkCheck DHCP — did phone get IP + provisioning options? Can phone reach SIP registrar (ping/traceroute)? 401 = auth failure (wrong password). 403 = not authorized. 404 = wrong domain/realm. Firewall blocking UDP 5060.
488 Not Acceptable HereSDP codecNo codec overlap between INVITE SDP offer and server/endpoint capabilities. Check codecs configured on both endpoints. G.729 license issue on Cisco gateway. Transcoding required but not available.
Calls fail over WiFi onlyWireless / QoSWMM (Wi-Fi Multimedia) not enabled — voice traffic not prioritized over air. DSCP-to-WMM-AC mapping: EF → AC_VO. Roaming interruption during call — check FT (802.11r) / OKC. Hidden node, high retry rates causing jitter.
🔍 Wireshark for VoIP: sip — all SIP. rtp — RTP streams. Use Telephony → VoIP Calls to visualize call flows and play back audio. Telephony → RTP → RTP Streams shows jitter, packet loss, max delta per stream. Filter a full call: sip.Call-ID == "your-call-id". Check DSCP: ip.dsfield.dscp == 46 to verify EF marking on RTP packets.

Enter your branch traffic profile to calculate required WAN capacity, with SD-WAN path recommendations.

configuration
branch profile
Mbps/user
Mbps/user
Mbps/user
Mbps/user
Mbps total
SD-WAN factors
recommended circuit
Raw demand
After concurrency
After IPsec overhead
With growth buffer
Recommended per-link circuit
Total provisioned (with redundancy)
SD-WAN path recommendation
typetypical speedlatencySLAbest for
MPLS (L3VPN)10–10,000 Mbps5–30 msYes — carrier SLAVoice, video, ERP — mission-critical, predictable performance
Business Broadband (cable/fibre)100–10,000 Mbps10–50 msBest-effortInternet, cloud apps — low cost, high bandwidth
DIA (Dedicated Internet Access)100–10,000 Mbps5–20 msYes — symmetricalHybrid WAN primary — guaranteed symmetrical, SLA-backed internet
4G LTE10–150 Mbps20–60 msBest-effortFailover, temporary sites, pop-up branches
5G (sub-6 GHz)100–1,000 Mbps10–30 msImprovingPrimary WAN for branches without fibre, replacing LTE failover
SD-WAN over internetAggregatedVariesApp-level SLAReplacing MPLS for non-latency-sensitive apps — 60–80% cost reduction
quick reference
110
OSPF AD
IP 89
protocol
Area 0
backbone
ref / BW
cost
Link-state, Dijkstra SPF. DR/BDR elected on multi-access by highest priority then highest RID. Reference bandwidth default 100 Mbps (raise to match 10G+ links). LSA types 1–7.
area typeLSA types allowedexternal routesdefault routeuse case
Backbone (Area 0)1,2,3,4,5Yes (Type 5)OptionalRequired hub — all other areas must connect to Area 0 directly or via virtual link
Normal area1,2,3,4,5Yes (Type 5)OptionalStandard non-backbone area — full LSA database
Stub1,2,3No — blockedInjected by ABRLeaf areas with no ASBR — reduces LSA database size significantly
Totally Stub1,2NoInjected by ABRMost aggressive size reduction — only intra-area routes + default. Cisco-proprietary.
NSSA1,2,3,7Type 7 (internal)OptionalStub area that also has an ASBR redistributing external routes (e.g. connected to internet)
Totally NSSA1,2,7Type 7 (internal)Injected by ABRNSSA with default route injection — Cisco-proprietary

OSPF cost = reference bandwidth / interface bandwidth. Default reference = 100 Mbps (Cisco). Adjust reference to differentiate modern link speeds.

interface typebandwidthcost @ selected ref BW
* Cost floors at 1 — IOS cannot represent fractional costs. Set auto-cost reference-bandwidth 10000 (or higher) to differentiate GE from 10GE. Always set the same reference bandwidth on ALL OSPF routers in the domain.
stepcriterionnotes
1OSPF priorityHighest priority wins (0–255). Default 1. Priority 0 = never elected DR/BDR. Set on interface: ip ospf priority X
2Router IDTiebreaker — highest Router ID wins. Router ID = highest loopback IP, else highest interface IP, or manually configured.
DR/BDR election only occurs on multi-access networks (Ethernet broadcast segments). Point-to-point links skip election entirely. DR reduces LSA flooding — instead of n(n-1)/2 adjacencies, all routers form adjacency only with DR and BDR. Election is non-preemptive — changing priority does not force re-election without clearing the OSPF process.
LSA typenamegenerated byscopecarries
1Router LSAEvery routerSingle areaLinks and states of the originating router
2Network LSADRSingle areaList of routers on a broadcast segment
3Summary LSAABROther areasInter-area routes — blocked in stub/totally-stub areas
4ASBR Summary LSAABROther areasLocation of ASBR — blocked in stub areas
5External LSAASBREntire OSPF domainExternal routes (E1/E2) — blocked in all stub types
7NSSA External LSAASBR in NSSANSSA area onlyExternal routes within NSSA — converted to Type 5 by ABR
quick reference
128-bit
address
fe80::/10
link-local
2000::/3
global (GUA)
fc00::/7
ULA
No broadcast — uses multicast (ff00::/8) and NDP instead of ARP. SLAAC builds addresses from Router Advertisements + interface ID (EUI-64). Loopback ::1, unspecified ::.
componentdetail
Length128 bits — written as 8 groups of 4 hex digits separated by colons. Example: 2001:0db8:85a3:0000:0000:8a2e:0370:7334
Compression rulesLeading zeros in each group may be omitted. One contiguous sequence of all-zero groups may be replaced with :: (only once per address).
Prefix notationCIDR-style: 2001:db8::/32. Prefix length replaces subnet mask.
Interface IDTypically the lower 64 bits. Can be EUI-64 derived, random (RFC 4941 privacy), or manually assigned.
typeprefixscopenotes
Global Unicast (GUA)2000::/3Internet-routableEquivalent to public IPv4. IANA allocates from 2001::/32 upward. Your ISP gives you a /48 or /56.
Link-Localfe80::/10Single linkAuto-configured on every IPv6 interface. Never routed. Used for NDP, DHCPv6, routing protocol adjacencies. Required even if no GUA assigned.
Unique Local (ULA)fc00::/7OrganizationRoughly equivalent to RFC 1918. Not routable on internet. fd00::/8 is locally assigned (randomly generated 40-bit prefix). Use for internal services.
Loopback::1/128HostEquivalent to 127.0.0.1. Single address.
Unspecified::/128Source address used before interface has an address (DHCPv6 solicit, DAD). Never destination.
Multicastff00::/8VariesNo IPv6 broadcast — multicast replaces it. See table below for well-known groups.
AnycastFrom unicast spaceNearest nodeSame address assigned to multiple nodes — routed to closest. Used for DNS root servers, CDN, load balancing.
Documentation2001:db8::/32Examples onlyReserved for documentation and examples (RFC 3849). Never routed.
addressgroupnotes
ff02::1All nodes (link-local)Equivalent to 224.0.0.1. Reaches all IPv6 nodes on the link.
ff02::2All routers (link-local)Used by hosts to find routers for SLAAC (RS messages).
ff02::5OSPFv3 all routersOSPFv3 hello messages.
ff02::6OSPFv3 DR/BDROSPFv3 designated router.
ff02::9RIPngRIPng routing updates.
ff02::aEIGRPEIGRP hellos and updates.
ff02::1:2All DHCPv6 relay/serversDHCPv6 client sends Solicit to this address.
ff02::1:ffxx:xxxxSolicited-node multicastDerived from last 24 bits of unicast address. Used for NDP neighbor solicitation (replaces ARP).
stepdetail
1Take the 48-bit MAC address: 00:1A:2B:3C:4D:5E
2Split in half and insert FF:FE in the middle: 00:1A:2B:FF:FE:3C:4D:5E
3Flip bit 7 of the first byte (Universal/Local bit): 0002
4Result: 021a:2bff:fe3c:4d5e — append to /64 prefix for full address.
Privacy concern: EUI-64 embeds your MAC address in the IPv6 address, making you trackable across networks. RFC 4941 (privacy extensions) generates random Interface IDs instead and is default on most modern OS.
message typeICMPv6 typepurposeIPv4 equivalent
Router Solicitation (RS)133Host asks routers to send RA immediately
Router Advertisement (RA)134Router announces prefix, default gateway, M/O flagsDHCP offer (partial)
Neighbor Solicitation (NS)135Resolve IPv6 address to MAC (like ARP request), also used for DADARP request
Neighbor Advertisement (NA)136Reply with MAC addressARP reply
Redirect137Router tells host of better next-hopICMP Redirect
methodM flagO flaghow it worksbest for
SLAAC00Host combines /64 prefix from RA with self-generated Interface ID (EUI-64 or random). No server needed.Simple networks, IoT, home
SLAAC + Stateless DHCPv601SLAAC for address, DHCPv6 for other options (DNS, NTP). Server assigns no address.Enterprise where DNS control needed
Stateful DHCPv611DHCPv6 server assigns full address + options. Like DHCPv4. Requires relay on routed segments.Enterprise requiring address control
StaticManually configured. Always needed for router interfaces and servers.Servers, routers, infrastructure
DAD (Duplicate Address Detection) runs automatically before any unicast address is used — sends NS to the solicited-node multicast address; if NA received, address is a duplicate and not assigned.
prefixallocationnotes
/32ISP allocationTypical block assigned to an ISP from RIR
/48Site / customerTypical allocation to an end-site. Allows 65,536 subnets of /64.
/56Residential / small siteCommon ISP allocation for home/SOHO — 256 subnets of /64.
/64Single subnetStandard subnet size. Required for SLAAC and EUI-64. 18.4 quintillion host addresses.
/127Point-to-point linksRFC 6164. Use instead of /64 on router-to-router links to prevent subnet-router anycast issues.
/128Host / loopbackSingle address — used for loopbacks, anycast, and host routes.
quick reference
ESP 50
protocol
UDP 500
IKE
UDP 4500
NAT-T
AH 51
auth-only
IKE Phase 1 builds the secure IKE SA; Phase 2 builds the IPsec SAs. ESP encrypts+authenticates (AH authenticates only). Tunnel mode for site-to-site, transport for host-to-host.
typelayercommon usekey protocols
IPsec (tunnel mode)L3Site-to-site, remote accessIKEv1/v2, ESP, AH
IPsec (transport mode)L3Host-to-host encryptionESP, AH
GREL3Tunnel multicast/routing protocolsGRE (IP proto 47)
GRE over IPsecL3Site-to-site with routing protocol supportGRE + ESP
DMVPNL3Hub-spoke with dynamic spoke-to-spokemGRE, NHRP, IPsec
FlexVPNL3Modern Cisco VPN frameworkIKEv2, VTI
SSL/TLS VPNL4-L7Remote access, clientlessTLS, DTLS
WireGuardL3Modern simple VPNUDP, Curve25519, ChaCha20
L2TP/IPsecL2 in L3Legacy remote access (Windows built-in)L2TP + IPsec ESP
MPLS L3VPNL2.5Service provider enterprise VPNMPLS, MP-BGP, VRF
phasenamewhat happensoutput
Phase 1IKE_SA_INITExchange DH public keys, nonces, SA proposals (encryption, integrity, PRF, DH group). Establishes a secure authenticated channel.IKE SA — encrypted management channel
Phase 2IKE_AUTHAuthenticate peers (pre-shared key or certificates), negotiate first Child SA (IPsec tunnel parameters).Child SA — the actual data tunnel (ESP/AH)
RekeyCREATE_CHILD_SARenew Child SAs before lifetime expires without dropping traffic. Can also add new tunnels.New Child SA, old removed
IKEv2 is faster (2 exchanges vs IKEv1's 6–9), supports MOBIKE (mobility), EAP authentication, and asymmetric authentication. Always prefer IKEv2 for new deployments.
Tunnel modeTransport mode
What's encryptedEntire original IP packet (header + payload) encapsulated in new IP packetOnly the IP payload (TCP/UDP data); original IP header preserved
New IP headerAdded — outer header uses tunnel endpoints (gateway IPs)None — original header used
Use caseSite-to-site VPN, remote access (gateway encrypts on behalf of hosts)Host-to-host encryption (both endpoints run IPsec stack)
OverheadHigher — extra IP header + ESP header (~50–60 bytes)Lower — no extra IP header (~30–40 bytes)
ESP (Encapsulating Security Payload)AH (Authentication Header)
IP protocol5051
EncryptionYes — AES-GCM, AES-CBC, ChaCha20-Poly1305No
AuthenticationYes (of payload)Yes (of entire packet including IP header)
NAT traversalYes — ESP-in-UDP (port 4500) for NAT-TNo — AH covers IP header, broken by NAT
Used in practiceAlways — ESP is the standardRare — AH is mostly legacy
componentrolenotes
HubCentral siteRuns mGRE and NHRP server. All spokes register their NBMA (real) address here on boot.
SpokeBranch siteRegisters with hub. Can dynamically build direct spoke-to-spoke tunnels without hub forwarding.
mGREMultipoint GRESingle GRE interface on hub that terminates tunnels from all spokes. Eliminates hub config scaling problem.
NHRPNext Hop Resolution ProtocolSpoke queries hub for another spoke's real IP. Hub responds so spokes can build direct tunnel. Like ARP for DMVPN.
Phase 1Hub-and-spoke onlyAll traffic flows through hub. Simple. No direct spoke-to-spoke.
Phase 2Spoke-to-spoke (same subnet)Spokes learn each other's IPs via NHRP and build direct tunnels. Hub in same subnet as spokes.
Phase 3Spoke-to-spoke (hierarchical)Uses NHRP redirect/shortcut. Spokes can be in different subnets. Most scalable.
attributedetail
IP protocol47
Overhead24 bytes (20 outer IP + 4 GRE header). MTU considerations: reduce inner MTU to 1476 (1500 − 24) or enable PMTUD.
Supports multicastYes — can carry OSPF, EIGRP, PIM hellos. IPsec alone cannot carry multicast.
EncryptionNone — GRE is an encapsulation protocol only. Combine with IPsec for security.
KeepalivesSupported (Cisco). Send GRE keepalives to detect far-end tunnel failure even if routing still up.
Recursive routingCommon misconfiguration — tunnel destination reachable only via the tunnel itself. Fix: use a static route for the tunnel destination via the physical interface.
attributedetail
TransportUDP — port 51820 default (configurable)
CryptoCurve25519 (key exchange), ChaCha20-Poly1305 (encryption + auth), BLAKE2s (hash), SipHash24 (hashtable)
AuthenticationPublic/private key pairs — no certificates, no PKI, no CA needed
Handshake1-RTT — much faster than IKEv2's 2-RTT. Initiator sends first packet, responder replies, tunnel up.
RoamingBuilt-in — IP address changes handled transparently. Endpoint updates on valid packet receipt.
StealthNo response to unauthenticated packets — appears as closed port to scanners.
vs IPsecFar simpler config, smaller attack surface (~4K LoC vs ~400K), faster, but fewer enterprise features (no IKEv2 EAP, no RADIUS integration).
protocol/portpurposenotes
UDP 500IKE (Internet Key Exchange)Phase 1 and Phase 2 negotiation. Used when no NAT detected.
UDP 4500IKE NAT-Traversal + ESP-in-UDPUsed when NAT detected between peers. ESP packets wrapped in UDP for NAT compatibility.
IP proto 50ESPThe actual encrypted data. Used directly when no NAT. Becomes UDP 4500 with NAT-T.
IP proto 51AHAuthentication only. Rarely used. Incompatible with NAT.
IP proto 47GREGRE tunnel encapsulation. Often combined with IPsec.
quick reference
UDP 161
SNMP get
UDP 162
traps
UDP 514
syslog
UDP 123
NTP
Prefer SNMPv3 (auth + priv) over v2c community strings. Syslog severities 0 (emerg) → 7 (debug). NTP stratum 0 = reference clock, 1 = directly attached.
SNMPv1SNMPv2cSNMPv3
AuthenticationCommunity string (cleartext)Community string (cleartext)Username + MD5/SHA hash
EncryptionNoneNoneDES / AES-128/256
Bulk operationsNoYes — GetBulkYes — GetBulk
64-bit countersNoYes (Counter64)Yes
Use todayLegacy onlyCommon (monitoring)Required for security
Use SNMPv3 with authPriv security level for any device accessible beyond your management VLAN. Community strings in v1/v2c are transmitted in cleartext and visible in packet captures.
levelauthenticationencryptionuse case
noAuthNoPrivUsername onlyNoneAvoid — no real security
authNoPrivMD5 or SHANoneVerifies source but data is cleartext
authPrivMD5 or SHADES or AESRecommended — full security
operationdirectionportpurpose
GETManager → AgentUDP 161Retrieve a specific OID value
GET-NEXTManager → AgentUDP 161Walk the MIB tree — get next OID in sequence
GET-BULKManager → AgentUDP 161v2c/v3 — retrieve multiple OIDs in one request. Efficient for tables.
SETManager → AgentUDP 161Write a value to the agent. Requires read-write community / access.
TRAPAgent → ManagerUDP 162Unsolicited alert from agent (link down, threshold exceeded). No acknowledgement.
INFORMAgent → ManagerUDP 162Like TRAP but manager acknowledges. Reliable delivery. v2c/v3 only.
OIDnamedescription
1.3.6.1.2.1.1.1.0sysDescrDevice description string (OS version, model)
1.3.6.1.2.1.1.3.0sysUpTimeTime since last reboot (in hundredths of a second)
1.3.6.1.2.1.1.5.0sysNameConfigured hostname
1.3.6.1.2.1.2.2.1.8ifOperStatusInterface operational status (1=up, 2=down)
1.3.6.1.2.1.2.2.1.10ifInOctetsInbound octets on interface (32-bit, wraps on high-speed links)
1.3.6.1.2.1.2.2.1.16ifOutOctetsOutbound octets on interface
1.3.6.1.2.1.31.1.1.1.6ifHCInOctets64-bit inbound octet counter — use this for interfaces above 100 Mbps
1.3.6.1.2.1.4.21ipRouteTableIP routing table
1.3.6.1.4.1.9Cisco enterprise MIBCisco-specific OIDs (CPU, memory, temperature)
levelnamemeaningexamples
0EmergencySystem unusableKernel panic, total hardware failure
1AlertImmediate action requiredDatabase corruption, all redundancy lost
2CriticalCritical conditionsDual PSU failure, hardware error
3ErrorError conditionsInterface error, BGP session down, config apply fail
4WarningWarning conditionsHigh CPU, link flap, interface error rate
5NoticeNormal but significantConfig change, user login, interface up/down
6InformationalInformational messagesSTP topology change, OSPF adjacency up
7DebugDebug-level messagesPer-packet detail — never send to syslog server in production
Cisco IOS default logging: severity 6 (informational) to console and buffer. Recommended syslog server level: 5 (notice) or 6 (informational) to capture events without flooding. logging trap <level> on Cisco sets the threshold sent to the syslog server.
facilitycodetypical source
kern0Kernel messages
user1User-level messages
mail2Mail system
daemon3System daemons
auth4Security/authentication (login, sudo)
syslog5Syslog daemon itself
local0–local716–23Custom use — network devices commonly use local6 or local7
conceptdetail
PortUDP 123
Stratum 0Reference clock (atomic, GPS, radio). Not directly accessible on network.
Stratum 1Directly connected to stratum 0. Public NTP servers (time.cloudflare.com, pool.ntp.org). Most accurate on internet.
Stratum 2Syncs from stratum 1. Your internal NTP server should be stratum 2.
Stratum 3–15Each level adds ~1ms jitter. Avoid deep chains.
Stratum 16Unsynchronized — device does not have a valid time source.
NTPv4Current version. Supports IPv6, improved security, up to nanosecond precision.
PTP (IEEE 1588)Precision Time Protocol — sub-microsecond accuracy for financial, telecom, 5G. Hardware timestamping required.
Why NTP matters for networks: syslog timestamps across devices must match to correlate events during incidents. Certificate validation requires accurate time. Kerberos authentication fails if clocks are skewed >5 minutes. OSPF/BGP can be affected by timestamp issues in some implementations.
practicedetail
Minimum sourcesConfigure at least 3 NTP servers so NTP can use majority voting to detect a bad time source. 4+ preferred.
Internal hierarchyPoint all network devices to 2–3 internal NTP servers (your core routers or dedicated appliances). Internal servers sync to 2+ public stratum 1/2 sources.
AuthenticationUse NTP MD5 authentication between internal servers and clients to prevent rogue NTP server attacks.
Restrict accessNTP ACL — only allow queries from your management network. Prevents NTP amplification DDoS abuse.
Cisco quick configntp server <IP> prefer / ntp source <interface> / show ntp status / show ntp associations
quick reference
≥ −67 dBm
good RSSI
≥ 25 dB
target SNR
< 10 %
retry rate
< 40 %
ch. util
−67 dBm / SNR 25 dB supports voice and high MCS. High retries or airtime utilization points to interference or client overload. Check co-channel interference, DFS radar events, sticky clients, and band steering.
← click a node to see troubleshooting tips
quick reference
conf t
IOS config
configure
Junos config
show run
running cfg
commit
Junos apply
Cisco IOS / Aruba AOS-CX apply changes immediately; Juniper Junos stages a candidate config and applies on commit. show running-config (IOS) ≈ show configuration (Junos). Use the search box to filter commands.
task 🟦 Cisco IOS / IOS-XE 🟩 Aruba AOS-CX 🟧 Juniper JunOS 🟥 Arista EOS
quick reference
AireOS
legacy WLC
IOS-XE
Catalyst 9800
show ap summary
APs
show wlan
SSIDs
Cisco controllers moved from AireOS (5520/8540) to Catalyst 9800 IOS-XE; Mobility Express embeds the WLC in an AP. Common checks: show ap summary, show wlan summary, show client summary. Filter with the search box.
task 🟦 Cisco 9800 (IOS-XE) 🟩 Aruba MC (AOS8) 🟧 Ruckus SmartZone 🟣 Juniper Mist
configuration
file size
quick file presets
circuit speed
quick speed presets
protocol overhead
TRANSFER TIME
time (s) = file_size_bits ÷ throughput_bps
where throughput = circuit_speed × (1 − overhead_fraction)
file_size_bits = file_bytes × 8
⚠ bits vs bytes — circuits are rated in bits/s (Mbps). File sizes are in bytes. Multiply bytes × 8 before dividing. Forgetting this gives results 8× too fast.
⚠ overhead is cumulative — a VPN over HTTPS adds ~15% total, not 10+5 as separate numbers. Use the closest preset or calculate custom.
⚠ half-duplex — on half-duplex links (old hubs, some Wi-Fi scenarios), effective throughput can be 40–60% of rated speed due to collision/backoff.
✓ real-world note — TCP throughput over WAN is also limited by the bandwidth-delay product. On a 100 Mbps link with 200ms RTT, a single TCP flow tops out at ~6 Mbps without window scaling (BDP = 100M × 0.2s = 2.5 MB, default window 64 KB).
protocoloverheadwhat it covers
Raw / Layer 10%Pure bit rate. No framing, no protocol. Theoretical max.
Ethernet + IP + TCP~3%Standard TCP/IP framing (Ethernet 18B + IP 20B + TCP 20B per ~1500B frame = ~3.8%).
HTTPS / TLS 1.3~5%TLS record overhead (~5B per record) + TCP + IP. TLS 1.3 is more efficient than 1.2.
IPsec ESP (tunnel)~10%New outer IP header (20B) + ESP header (8B) + IV (16B) + padding + ICV (12B) per packet.
GRE tunnel~8%GRE adds 4B header + outer IP 20B. Over 1500B payload = ~1.6%. MTU fragmentation adds more.
MPLS + IPsec VPN~20%MPLS shim labels (4B each, often 2 labels) + IPsec overhead. Typical MPLS WAN with encryption.
Wi-Fi 802.11 (managed)15–40%DIFS, backoff, preamble, MAC header, ACK, SIFS. Efficiency highly dependent on MCS rate and aggregation. A-MPDU reduces overhead significantly.
transfer time
Table uses raw throughput (0% overhead). Time = (file_bytes × 8) ÷ circuit_bps. Click "protocol overhead" buttons above the calculator to see adjusted times.
outside interface
public IP
public port
inside server IP
inside port
protocol
vendor
quick service presets:
HTTP HTTPS SSH RDP DNS SMTP SIP PPTP OpenVPN
generated CLI
⎘ copy
static NAT 1:1
One-to-One Mapping
A single private IP maps permanently to a single public IP. The mapping is bidirectional — inbound and outbound both work without additional config.

Translation table:
10.0.0.10 ↔ 203.0.113.10

Predictable — same outside IP always
Inbound connections work without port forwarding
Requires one public IP per host
Wastes public address space

Use for: Servers, DMZ hosts, anything that must be reached inbound by full IP.
dynamic NAT pool
Pool-Based Mapping
Private IPs map to a pool of public IPs — first-come, first-served. The mapping is temporary and released when the session ends. Inbound connections are not possible unless a mapping exists.

Translation table:
10.0.0.10 → 203.0.113.10 (active)
10.0.0.11 → 203.0.113.11 (active)
10.0.0.12 → (waiting — pool exhausted)

Better address utilization than static
If pool exhausted, new sessions fail
No inbound without static entry

Use for: Rarely used today — PAT is more efficient.
PAT / NAT overload many:1
Port Address Translation
Many private IPs share a single (or small pool of) public IP(s). The router tracks sessions by adding a unique source port to each translation. Up to ~65,535 simultaneous sessions per public IP.

Translation table:
10.0.0.10:5000 → 203.0.113.1:1024
10.0.0.11:3200 → 203.0.113.1:1025
10.0.0.10:5001 → 203.0.113.1:1026

Massive address conservation
Most common NAT type in production
Inbound requires explicit port forwarding
Breaks protocols that embed IP in payload (ALG needed)

Use for: Home routers, branch offices, any outbound-primary environment.
OUTBOUND PACKET FLOW (PAT)
1. Client sends: src=10.0.0.10:54321 dst=8.8.8.8:53 proto=UDP
2. NAT router: creates entry → src rewritten to 203.0.113.1:1024
3. Packet sent: src=203.0.113.1:1024 dst=8.8.8.8:53
─────────────────────────── response arrives ───────────────────────────
4. Reply arrives: src=8.8.8.8:53 dst=203.0.113.1:1024
5. NAT lookup: port 1024 → maps to 10.0.0.10:54321
6. Delivered: src=8.8.8.8:53 dst=10.0.0.10:54321
fieldinside localinside globaloutside globalnotes
Source IP10.0.0.10203.0.113.18.8.8.8Private → public rewrite on egress
Source Port543211024Port remapped to track session uniquely
Dest IP8.8.8.8unchanged8.8.8.8Destination not modified for outbound
Session timerUDP: 30s idle timeout · TCP: 86400s (24h) established · TCP FIN/RST: 60sEntry removed after timeout
The NAT table is stateful — the router must see the SYN (TCP) or first packet (UDP) to create the entry. Asymmetric routing breaks NAT because the return packet hits a different router that has no table entry.
PROBLEM — internal client hits public IP
Client 10.0.0.50 → DNS resolves server.example.com → 203.0.113.1:443
│ packet hits router outside interface
Without hairpin: router drops — src is inside, dst is its own outside IP
With hairpin: router translates → forwards to 10.0.0.100:443
Note: return traffic src IP = router outside IP, not server IP — client sees connection from public IP
When it matters: Internal clients using public DNS names for internal servers. Without hairpin, split-horizon DNS (internal DNS returns private IP) is the cleaner fix.
Cisco IOS: ip nat inside source static ... no-alias + ip nat hairpin or simply ensure NAT inside/outside on same VRF
Better fix: Split-horizon DNS — internal DNS returns 10.0.0.100 for server.example.com, external DNS returns 203.0.113.1
Some protocols embed IP addresses or ports in their payload — not just headers. NAT rewrites headers but not payload, breaking the protocol. ALGs inspect and rewrite payload too.
protocolportALG needed?why
SIP (VoIP)5060/5061yesSDP body contains private IP for RTP media stream. Without ALG, audio one-way or fails.
FTP (active)21yesPORT command sends private IP:port in ASCII payload. Server tries to connect back — fails through NAT. FTP passive avoids this.
FTP (passive)21noClient initiates data connection. No ALG needed — standard outbound NAT handles it.
H.3231720yesLegacy VoIP. Embeds addresses in Q.931/H.245 signaling. Modern deployments use SIP instead.
TFTP69yesUDP — server replies from random high port. NAT may not track the session return.
HTTPS / TLS443noEncrypted — ALG cannot inspect payload anyway. Standard PAT works.
IPsec ESPNAT-TESP has no port — can't PAT. NAT-T (RFC 3947) encapsulates ESP in UDP/4500 to add ports.
ALGs can cause problems when the protocol is encrypted (TLS-SIP) or when the ALG misidentifies traffic. Many enterprise firewalls allow disabling specific ALGs per interface.
symptomlikely causeCisco debug / showfix
Outbound connections fail ACL not matching traffic for NAT, or inside/outside interfaces misconfigured debug ip nat
show ip nat translations
Verify ip nat inside on LAN int, ip nat outside on WAN. Check ACL permits correct source range.
Port forward not working (inbound) Static NAT entry missing, firewall ACL blocking, or wrong inside IP show ip nat translations verbose
debug ip nat detailed
Confirm static entry exists. Check inbound ACL on outside interface permits the port. Verify server is actually listening on that port.
Asymmetric routing / session drops Traffic ingress/egress via different routers — return hits router with no NAT table entry show ip nat translations — entry missing for return Ensure symmetric routing through single NAT device. Use ECMP-aware NAT or stateful NAT failover (HSRP + NAT).
NAT table exhaustion (PAT) >65535 concurrent sessions per public IP show ip nat translations total
show ip nat statistics
Add public IPs to PAT pool. Reduce session timeouts (UDP: 30s, TCP established: 3600s). Investigate session leak.
Overlapping RFC1918 (VPN/merger) Both sides use 10.0.0.0/8 — routing ambiguous after tunnel Routing table shows conflict Use twice-NAT (NAT on both source and destination). Translate one side's range to unique address before VPN. Cisco: ip nat inside source static network.
VoIP one-way audio SIP ALG not rewriting SDP media IP, or ALG rewriting incorrectly Wireshark — check SDP c=IN IP4 line in INVITE Enable SIP ALG if disabled. Or disable SIP ALG entirely and use a SBC (Session Border Controller) to handle media NAT properly.
IPsec VPN fails through NAT ESP (protocol 50) has no port — can't PAT. IKE on UDP/500 blocked. debug crypto isakmp
show crypto isakmp sa
Enable NAT-T (UDP/4500) on both endpoints. Cisco: crypto isakmp nat-traversal. Ensure UDP 500 and 4500 permitted inbound.
quick reference
UDP 53
queries
A / AAAA
v4 / v6
CNAME / MX
alias / mail
TCP 53
zone xfer
Recursive resolver walks root → TLD → authoritative, caching by TTL. UDP 53 for normal queries; TCP 53 for zone transfers and responses >512 B. PTR = reverse, TXT = SPF/DKIM/verification, NS = delegation.
typefull namewhat it storesexamplenotes
address records
A Address IPv4 address (32-bit) example.com. → 93.184.216.34 Most common record. One name can have multiple A records (round-robin load balancing).
AAAA IPv6 Address IPv6 address (128-bit) example.com. → 2606:2800:220:1:248:1893:25c8:1946 Quad-A. Resolver queries both A and AAAA — client uses whichever it has connectivity for (Happy Eyeballs).
PTR Pointer Reverse DNS — IP → hostname 34.216.184.93.in-addr.arpa. → example.com. Stored in in-addr.arpa (IPv4) or ip6.arpa (IPv6) zones. Octets reversed. Required by many mail servers for spam checks.
name & alias records
CNAME Canonical Name Alias → another hostname www.example.com. → example.com. Resolver follows the chain until it hits an A/AAAA. Cannot coexist with other records at same name. Can't use at zone apex (root domain).
NS Name Server Authoritative NS for zone example.com. → ns1.registrar.net. Delegation record. TLD nameservers hold NS records pointing to your authoritative servers. Always fully-qualified (trailing dot).
mail records
MX Mail Exchange Mail server + priority example.com. MX 10 mail.example.com. Lower priority number = preferred. Multiple MX records = redundancy. Value must point to A/AAAA — not a CNAME.
zone & service records
SOA Start of Authority Zone metadata ns1.example.com. admin.example.com. serial refresh retry expire min-ttl One per zone. Serial increments on every change (triggers zone transfers). Minimum TTL = negative cache TTL (NXDOMAIN caching time).
SRV Service Service location (host + port) _sip._tcp.example.com. 10 20 5060 sipserver.example.com. Format: priority weight port target. Used by SIP, XMPP, Teams, Active Directory. Allows service discovery without hardcoding ports.
text & security records
TXT Text Arbitrary text (up to 255 chars per string) example.com. TXT "v=spf1 include:_spf.google.com ~all" Used for SPF, DKIM, DMARC, domain verification (Google, Azure, Let's Encrypt). Multiple TXT records at same name are valid — resolvers return all.
CAA Certification Authority Authorization Which CAs may issue certs example.com. CAA 0 issue "letsencrypt.org" Prevents unauthorized CAs from issuing certs for your domain. CAs must check before issuing. Tags: issue, issuewild, iodef.
DNSKEY DNS Key DNSSEC public key ZSK or KSK public key for zone signing Used by DNSSEC. Zone Signing Key (ZSK) signs RRsets. Key Signing Key (KSK) signs the DNSKEY RRset itself.
DS Delegation Signer Hash of child zone KSK Stored in parent zone to establish chain of trust Links parent to child zone in DNSSEC. DS record in .com zone points to your domain's KSK hash.
recursive query (client → resolver)
ClientRecursive Resolver: "What is the IP of www.example.com?"
Resolver handles all further lookups on behalf of client
ResolverRoot NS: "Who handles .com?"
Root NSResolver: "Try a.gtld-servers.net"
Resolver.com TLD NS: "Who handles example.com?"
.com TLD NSResolver: "Try ns1.example.com"
Resolverexample.com NS: "What is www.example.com?"
Auth NSResolver: "93.184.216.34 (TTL 3600)"
ResolverClient: "93.184.216.34" (cached)
resolver hierarchy
1. Browser cache — shortest lived, respects TTL
2. OS resolver cache — nscd, systemd-resolved, Windows DNS Client service
3. Local recursive resolver — DHCP-assigned (ISP, corporate DNS, 8.8.8.8)
4. Root nameservers — 13 root server identities (A–M), anycast, operated by ICANN, Verisign, etc.
5. TLD nameservers — .com, .net, .org, country codes
6. Authoritative NS — your DNS provider (Route53, Cloudflare, your on-prem DNS)
iterative vs recursive
Recursive — client asks resolver once; resolver does all the work. Used by clients to resolvers.

Iterative — resolver asks each NS in turn, gets a referral, queries the next. Used by resolvers to authoritative servers.

Authoritative — final answer, not from cache. Flag set in DNS response (AA bit).
TTL valuedurationuse case
601 minuteDuring active migrations, failover prep — minimizes propagation lag
3005 minutesPre-migration: lower here 24–48h before cutover
90015 minutesServices that change occasionally
36001 hourCommon default — good balance
8640024 hoursStable records (MX, NS) — reduces resolver load
6048007 daysVery stable (root hints, static infra)
0No cachingNever cache — every query hits authoritative. High load.
TTL behavior rules
Propagation time = old TTL at time of change. If A record had TTL 86400, every resolver that cached it holds the old value for up to 24h. Lower TTL before making changes, not after.
Negative TTL — NXDOMAIN responses are cached for the SOA minimum TTL. If you delete a record, resolvers cache the "not found" answer for that duration.
Resolver vs client TTL — resolvers decrement TTL as they hold the cache entry. Client receives remaining TTL. Client TTL often clamped to 0–300s by OS regardless of DNS response.
Migration best practice:
1. Lower TTL to 300s, wait old-TTL duration for propagation
2. Make DNS change
3. Wait 300s for new value to propagate
4. Raise TTL back to normal after cutover confirmed
DNSSEC VALIDATION CHAIN
Root zone → signed with Root KSK (ICANN managed, ceremony every ~3mo)
│ DS record in root points to .com KSK hash
.com TLD zone → signed with .com KSK/ZSK
│ DS record in .com points to example.com KSK hash
example.com zone → all RRsets signed with ZSK
│ RRSIG record accompanies each signed RRset
Validator → verifies RRSIG with DNSKEY, checks DS hash matches parent
Validation fails → SERVFAIL returned to client (not the spoofed answer)
recordpurpose
DNSKEYPublic key used to verify signatures. KSK signs DNSKEY RRset; ZSK signs all others.
RRSIGCryptographic signature over an RRset. Includes expiry timestamp — must be renewed before expiry.
DSDelegation Signer — hash of child KSK stored in parent zone. Links the chain.
NSEC / NSEC3Proves a name does NOT exist (authenticated denial of existence). NSEC3 hashes names to prevent zone enumeration.
what DNSSEC does and doesn't do
PROTECTS AGAINST
Cache poisoning (Kaminsky attack) — forged responses rejected
On-path response modification
NXDOMAIN injection
DOES NOT PROTECT AGAINST
DDoS / DNS amplification — still possible
Privacy — queries still visible on wire (use DoH/DoT)
Typosquatting — validates the record, not if it's the right domain
Expired signatures — if RRSIG expires and isn't renewed, zone appears broken
RRSIG expiry is the #1 operational DNSSEC failure. Set key rollover reminders. Broken DNSSEC = SERVFAIL for all clients with validation enabled.
Different DNS answers returned based on where the query comes from. Internal clients get private IPs; external get public IPs. Same domain, different views.
EXAMPLE — server.example.com
Internal client → internal DNS → 10.0.0.100 (private IP, direct)
External client → public DNS → 203.0.113.1 (public IP, firewall)
Why it matters: Avoids hairpin NAT. Internal clients reach servers directly. Required when internal IP scheme differs from public-facing.
Cisco IOS: ip dns view + ip dns view-list
Windows DNS: Two zones with same name — one internal, one external, different records
BIND: view "internal" { match-clients { 10.0.0.0/8; }; };
Split-horizon breaks DNSSEC — the two zones have different RRsets so signatures won't match across views. Choose one or the other.
response / symptommeaningcommon cause
NXDOMAIN Name does not exist Typo in hostname, record deleted, wrong zone. Negative-cached for SOA min TTL.
SERVFAIL Server failed to complete query DNSSEC validation failure, authoritative NS unreachable, resolver misconfigured, zone transfer failed.
REFUSED Server refused the query Resolver ACL blocking client IP, recursive queries disabled on authoritative NS, RPZ (response policy zone) block.
NOERROR + empty answer Name exists but no record of requested type Queried wrong record type (A vs AAAA), CNAME loop, or record type mismatch.
Slow resolution High latency to resolver or auth NS Cache miss on cold resolver, distant auth NS, DNSSEC signature verification overhead.
Stale record after change Old IP still returned TTL not lowered before change. Cache holding old answer. Check remaining TTL: dig +nocmd example.com A +noall +answer
DNS rebinding Malicious external domain resolves to internal IP Attacker controls DNS for their domain, returns 192.168.x.x. Browser same-origin policy bypassed. Mitigate with DNS rebinding protection on resolver (block private IP responses for external names).
CNAME at apex CNAME on root domain fails RFC 1034 prohibits CNAME coexisting with SOA/NS at zone apex. Use ALIAS/ANAME records (Cloudflare CNAME flattening) instead.
dig commands
commandwhat it does
dig example.com AQuery A record, uses system resolver
dig @8.8.8.8 example.com AQuery specific resolver (8.8.8.8)
dig example.com ANYAll record types (many servers block ANY)
dig -x 93.184.216.34Reverse lookup (PTR)
dig example.com +traceFull iterative trace from root
dig example.com +shortAnswer only, no header
dig example.com +dnssecInclude RRSIG records in response
dig example.com +cdDisable DNSSEC checking (checking disabled)
dig example.com TTLCheck remaining TTL in answer section
dig example.com MX +noall +answerClean answer section only
Wireshark DNS filters
filtercatches
dnsAll DNS traffic
dns.flags.response == 0Queries only
dns.flags.response == 1Responses only
dns.flags.rcode != 0All error responses (NXDOMAIN, SERVFAIL, REFUSED)
dns.flags.rcode == 3NXDOMAIN only
dns.flags.rcode == 2SERVFAIL only
dns.qry.name contains "example"Queries for specific domain
dns.time > 0.5Slow DNS responses (>500ms)
dns.flags.aa == 1Authoritative answers only (AA bit set)
dns && udp.port == 5353mDNS (Bonjour/Avahi) traffic
DoH (DNS over HTTPS) — port 443, encrypted. Wireshark can't filter as DNS. Disable DoH on browser/OS to inspect.
DoT (DNS over TLS) — port 853. TCP, encrypted. Same limitation — need decryption keys to inspect.
When comparing resolver vs authoritative answers, always use dig @<auth-ns> example.com to bypass resolver cache. If authoritative returns correct answer but resolver doesn't, it's a caching or negative-TTL issue.
quick reference
dBi
gain unit
360°
omni
EIRP
effective power
3 dB
beamwidth
Higher gain antennas trade coverage angle for range — a narrower beamwidth focuses energy. EIRP = Tx power − cable loss + antenna gain. Match polarization (V/H) between link ends.
omnidirectional
Omni / Dipole
↑ vertical 360°
gain2–6 dBi
H-plane360° (uniform)
E-plane±60–75°
use Open offices, lobbies
indooroutdoor
Radiates equally in all horizontal directions. Higher gain = flatter donut = less vertical coverage. Standard AP internal antenna. Watch: high-gain omnis (>6 dBi) compress vertical beam — bad for multi-floor coverage.
directional
Sector Antenna
60° null
gain10–17 dBi
H-plane60°, 90°, or 120°
E-plane6–15°
use Stadiums, warehouses, outdoor cells
outdoorindoor large
3 × 120° sectors cover a full cell. Higher gain than omni in-sector. Used on AP mounts at ceiling perimeter or on towers. Watch: strong nulls behind — never assume back coverage.
directional
Patch / Panel
30°
gain6–14 dBi
H-plane30–90°
E-plane30–90°
use Hallways, point-to-multipoint, outdoor coverage
indoor/outdoor
Flat panel with moderate directivity. Wall-mounted for corridor coverage or aimed at client clusters. Low profile. Used in Aruba ANT-2x2-2714 series, Cisco AIR-ANT series.
highly directional
Yagi-Uda
12°
gain10–20 dBi
H-plane10–30°
E-plane10–30°
use Point-to-point links, long-range outdoor bridges
outdoor
Parasitic array — driven element + reflector + directors. Very narrow beam, very high gain. Must be precisely aimed. Used for long-distance point-to-point bridging. Not suitable for client Wi-Fi.
highly directional
Parabolic Dish
gain20–35+ dBi
H-plane3–10°
E-plane3–10°
use Long-range P2P links, backhaul
outdoor
Maximum gain, minimum beamwidth. Reflective dish focuses energy at the feed point. Used for campus or building-to-building backhaul links. Extremely sensitive to alignment — 1° off can lose 3+ dB.
integrated
Internal AP Antenna
AP
gain3–5 dBi typical
H-planeNear-omnidirectional
E-planeVaries by AP model
use Standard office, ceiling mount
indoor
PIFA or patch arrays built into the AP chassis. Aruba, Cisco, and Ruckus publish radiation pattern PDFs for each AP model. Ceiling mount = best omni coverage; wall mount = tilted pattern toward floor.
GAIN ↑ = RANGE ↑ but BEAMWIDTH ↓ (energy is redistributed, not created)
2 dBi
wide
6 dBi
medium
10 dBi
narrow
15 dBi
very narrow
gain rangebeamwidth (approx)range increase vs dipolebest forwatch out for
2–3 dBiNearly sphericalbaselineDense indoor AP, ceiling mount, high client densityLimited range in large open spaces
4–6 dBi~75° E-plane+2–4 dB (~40–60% more range)Standard office omni, outdoor APs, general purposeStarts losing vertical — avoid in multi-story open atriums
8–10 dBi~40–60° E-plane+6–8 dB (~2× range)Warehouses, outdoor sectors, hallway panelsVery flat donut — poor coverage directly above/below AP
12–16 dBi~15–30°+10–14 dB (~3–5× range)Outdoor point-to-multipoint, stadium sectorsMust be precisely aimed — clients outside beam get nothing
20+ dBi<10°+18+ dB (>8× range)Point-to-point backhaul onlyNo client use. Requires precise alignment. Regulatory limits may restrict EIRP.
Every 3 dB of gain doubles the effective radiated power in the beam direction — but halves it in others. Gain is redistribution of a fixed power budget, not amplification. EIRP = TX power + antenna gain − cable loss.
single polarization
One orientation — vertical (most common) or horizontal. Simple, lower cost. Used on older APs and basic outdoor bridges. MIMO not possible with a single polarization antenna. Client must match orientation for best sensitivity.
dual polarization
│ ─
Two orthogonal feeds (V + H) in the same physical antenna. Required for 2×2 MIMO and above. Both feeds share the same radiation pattern shape. Used on virtually all modern 802.11n/ac/ax APs.
cross-pol (±45°)
╱ ╲
Feeds tilted ±45° instead of V/H. Better isolation between ports (~30 dB vs ~20 dB for V/H). Preferred for high-density deployments — reduces cross-polarization interference. Standard on most enterprise APs (Aruba, Cisco, Ruckus internal antennas are cross-pol).
Cross-pol (±45°) has become the de facto standard for enterprise Wi-Fi. It provides better port isolation, which directly improves MIMO spatial stream separation and throughput in high-density environments. If you see "dual-band dual-pol" on an AP datasheet, it's almost certainly ±45°.
RP-SMA (Reverse Polarity SMA)
thread: 3.5mm, same as SMA
center pin: Female on plug (reversed vs SMA)
use: Consumer/SMB APs, home routers, low-power devices
vendors: Cisco older SMB, Linksys, Netgear, some Ubiquiti
⚠ FCC-mandated reversed pin prevents use of high-gain antennas on consumer devices
N-Type
thread: 7/16" hex, weatherproof
frequency: DC–18 GHz
impedance: 50Ω (standard) or 75Ω (cable TV)
use: Enterprise outdoor APs, external antennas, cable runs
vendors: Aruba outdoor APs (ANT-xx series), Cisco AIR-ANT outdoor
✓ Best choice for outdoor — weatherproof, low loss at 5 GHz
SMA (SubMiniature version A)
thread: 3.5mm
frequency: DC–18 GHz
use: Test equipment, cables, some enterprise APs
note: Male has center pin; female has socket — opposite of RP-SMA
⚠ Easy to confuse with RP-SMA — check center pin carefully
MMCX (Micro-Miniature Coax)
size: 3mm diameter, snap-on lock
frequency: DC–6 GHz
use: Internal AP pigtails, IoT devices, compact hardware
note: Used inside AP chassis to connect PCB to external connector
4.3-10 (newer outdoor standard)
size: Between N-type and 7/16 DIN
frequency: DC–6 GHz+
use: 5G small cells, newer outdoor enterprise APs
vendors: Some newer Aruba and Cisco outdoor units
✓ PIM-resistant, compact, replacing N-type in some deployments
Cable loss reference
LMR-100 @ 2.4 GHz~0.8 dB/ft
LMR-200 @ 2.4 GHz~0.35 dB/ft
LMR-400 @ 2.4 GHz~0.13 dB/ft
LMR-400 @ 5 GHz~0.22 dB/ft
⚠ Keep cable runs <3 ft when possible. Each connector adds ~0.3 dB. Loss subtracts from EIRP budget.
modelvendortypebandsgainconnectoruse case
aruba
ANT-2x2-2714ArubaDual-pol omni2.4 + 5 GHz4/7 dBiRP-SMACeiling mount indoor, standard office
ANT-2x2-5714ArubaDual-pol omni5 GHz only7 dBiRP-SMA5 GHz-only environments, high-density
ANT-2x2-2410ArubaDual-pol patch2.4 + 5 GHz4/10 dBiRP-SMAWall/ceiling directional, hallways
ANT-3x3-5706ArubaTri-pol omni5 GHz6 dBiRP-SMA3×3 MIMO APs, high-density
ANT-2x2-D-OUTArubaDual-pol omni2.4 + 5 GHz5/7 dBiN-typeOutdoor omni — AP-374/377/387
ANT-2x2-D-OUT-SECArubaDual-pol sector2.4 + 5 GHz9/11 dBi · 90°N-typeOutdoor sector — stadiums, campuses
cisco
AIR-ANT2422DW-RCiscoDual-pol omni2.4 GHz2.2 dBiRP-SMADesktop/wall omni for older Aironet
AIR-ANT2513P4M-NCiscoDual-pol patch2.4 + 5 GHz13 dBiN-typeOutdoor directional, warehouse walls
AIR-ANT2566P4W-RCiscoDual-pol patch2.4 + 5 GHz6/6 dBiRP-SMAIndoor wall mount, open office
AIR-ANT2524V4C-RCisco4-element omni2.4 + 5 GHz2/4 dBiRP-SMACeiling mount, Catalyst 9100 series
AIR-ANT2547VG-NCiscoDual-pol omni2.4 + 5 GHz4/7 dBiN-typeOutdoor omni — AIR-AP18xx, 28xx series
ruckus
ANT-P25-0200RuckusBeamFlex patch2.4 + 5 GHz2 dBiIntegratedBeamFlex+ internal — H510, R750
902-0169-0000RuckusDual-pol omni2.4 + 5 GHz3/5 dBiRP-SMAIndoor omni for T310/T610 series
902-0119-0000RuckusDual-pol sector2.4 + 5 GHz8/8 dBi · 120°RP-SMAOutdoor sector — T710 series
Always verify antenna compatibility with your specific AP model — connector type, port count (2×2 vs 4×4), and supported frequency bands must match. Aruba publishes antenna datasheets at arubanetworks.com/resource/antenna-guide. Check your EIRP budget before selecting external antenna gain — high-gain + max TX power may exceed regulatory limits.
quick reference
Management
beacon/assoc
Control
RTS/CTS/ACK
Data
payload
2.4 / 5 / 6
bands
Three frame types. Management: beacon, probe req/resp, auth, (re)association. Control: RTS/CTS, ACK, Block-ACK, PS-Poll. Data carries the actual L3 payload; QoS-Data adds the TID/priority.
typetype bitscommon subtypespurpose
Management00Beacon, Probe Req/Resp, Auth, Assoc Req/Resp, Deauth, Disassoc, ActionBSS management — discovery, joining, leaving. Not encrypted unless PMF (802.11w) enabled.
Control01RTS, CTS, ACK, Block ACK, PS-Poll, CF-EndMedium access control — channel reservation, acknowledgement, power save. Never encrypted.
Data10Data, Null, QoS Data, QoS Null, A-MSDUCarries actual payload. Encrypted in infrastructure mode. QoS variants carry TID for WMM.
Extension11DMG Beacon (802.11ad)Reserved / 60 GHz WiGig. Rarely seen in enterprise deployments.
fieldsizepurposenotes
Frame Control2 bytesProtocol version, type, subtype, To DS, From DS, More Frag, Retry, Power Mgmt, More Data, Protected, OrderMost important field — contains all frame classification bits
Duration/ID2 bytesNAV (Network Allocation Vector) — how long the medium will be occupied in μsUsed by other stations to defer transmission (virtual carrier sense)
Address 16 bytesReceiver address (RA) — immediate recipientAlways present. May be broadcast (FF:FF:FF:FF:FF:FF)
Address 26 bytesTransmitter address (TA) — immediate senderPresent in most frames except ACK/CTS
Address 36 bytesBSSID, SA, or DA depending on To DS/From DS bitsOmitted in control frames
Sequence Control2 bytesFragment number (4 bits) + Sequence number (12 bits)Used for duplicate detection and fragmentation reassembly
Address 46 bytesSA when To DS=1 AND From DS=1 (WDS/mesh)Only present in WDS/mesh frames
QoS Control2 bytesTID (Traffic Identifier), AMSDU flag, TXOPPresent only in QoS Data frames (802.11e/WMM)
Frame Body0–7951 bytesPayload — varies by frame typeEncrypted in data frames when RSN/CCMP/GCMP in use
FCS4 bytesCRC-32 over entire frameChecked by receiver — corrupted frames silently dropped
To DS / From DS bit combinations: 00 = IBSS/management, 01 = client→AP (To DS), 10 = AP→client (From DS), 11 = WDS/mesh. These bits determine which address field maps to SA/DA/BSSID.
CLIENT ──────────────────────────────────────── AP
1. AP continuously sends Beacon (every 102.4ms default) — BSSID, SSID, rates, capabilities
2. Probe Request ──────────────────────────────► client scans — broadcast or directed
3. ◄────────────────────────────── Probe Response AP replies with capabilities
4. Authentication Request ────────────────────────► Open System (seq 1)
5. ◄──────────────────────── Authentication Response status 0 = success (seq 2)
6. Association Request ──────────────────────────────► client sends supported rates, RSN IE
7. ◄────────────────────────────── Association Response AID assigned, status 0
8. 4-Way Handshake ◄────────────────────────────────► PTK/GTK derivation (WPA2/3)
9. Data frames begin — port open, traffic flows
codemeaning
1Unspecified reason
2Previous auth no longer valid
3Deauth — station leaving BSS
4Disassoc — inactivity
5AP capacity exceeded
6Class 2 frame from non-auth station
7Class 3 frame from non-assoc station
8Disassoc — station leaving BSS
154-Way Handshake timeout
23802.1X auth failed
36Requested by BSS Transition (802.11v)
codemeaning
0Success
1Unspecified failure
10Cannot support all requested capabilities
12Association denied — unspecified
13Auth algorithm not supported
16Association denied — too many STAs
17Station requesting assoc not auth'd
23Assoc denied — RSSI below threshold
37RSNA IE missing or invalid
72Invalid PMKID
quick reference
ip a / ip r
addr / routes
ss -tlnp
sockets
tcpdump
capture
nft
firewall
iproute2 (ip, ss) replaces the legacy net-tools (ifconfig, route, netstat). ss -tlnp = listening TCP + PID; ip -s link for counters; nftables replaces iptables. Resolver config in /etc/resolv.conf.
taskcommand
Show all interfacesip link show or ip a
Show IP addressesip addr show
Bring interface up/downip link set eth0 up / down
Set IP addressip addr add 192.168.1.10/24 dev eth0
Show interface statsip -s link show eth0
Show MAC addressip link show eth0 | grep ether
taskcommand
Show routing tableip route show or ip r
Add static routeip route add 10.0.0.0/8 via 192.168.1.1
Add default gatewayip route add default via 192.168.1.1
Delete routeip route del 10.0.0.0/8
Traceroutetraceroute 8.8.8.8 or mtr 8.8.8.8
Show ARP tableip neigh show or arp -n
taskcommand
DNS lookupdig example.com or nslookup example.com
Reverse DNSdig -x 8.8.8.8
Pingping -c 4 8.8.8.8
Test port connectivitync -zv 192.168.1.1 443 or telnet host port
Show listening portsss -tlnp or netstat -tlnp
Show established connectionsss -tnp
taskcommand
Capture traffictcpdump -i eth0 -n
Capture to filetcpdump -i eth0 -w capture.pcap
Filter by hosttcpdump -i eth0 host 192.168.1.1
Show iptables rulesiptables -L -n -v
Show nftables rulesnft list ruleset
Allow port (ufw)ufw allow 443/tcp
taskcommand
Show all interfacesifconfig or networksetup -listallhardwareports
Show IP addressipconfig getifaddr en0
Renew DHCPipconfig set en0 DHCP
Set static IPnetworksetup -setmanual Wi-Fi 192.168.1.10 255.255.255.0 192.168.1.1
Flush ARP cachearp -ad
Show Wi-Fi info/System/Library/PrivateFrameworks/Apple80211.framework/Versions/Current/Resources/airport -I
taskcommand
Show routing tablenetstat -rn or route -n get default
Add static routesudo route add -net 10.0.0.0/8 192.168.1.1
Flush DNS cachesudo dscacheutil -flushcache && sudo killall -HUP mDNSResponder
DNS lookupdig example.com or nslookup example.com
Traceroutetraceroute 8.8.8.8
Show listening portslsof -i -P -n | grep LISTEN
taskcommand
Capture traffictcpdump -i en0 -n
Capture to filetcpdump -i en0 -w capture.pcap
Test portnc -zv host 443
Pingping -c 4 8.8.8.8
Show firewall statussudo /usr/libexec/ApplicationFirewall/socketfilterfw --getglobalstate
Wi-Fi packet capturesudo tcpdump -I -i en0 (monitor mode)
taskcommand
Show all interfacesipconfig /all
Show brief IP infoipconfig
Release DHCP leaseipconfig /release
Renew DHCP leaseipconfig /renew
Flush DNS cacheipconfig /flushdns
Show ARP tablearp -a
taskcommand
Show routing tableroute print or netstat -r
Add static routeroute add 10.0.0.0 mask 255.0.0.0 192.168.1.1
Persistent routeroute -p add 10.0.0.0 mask 255.0.0.0 192.168.1.1
DNS lookupnslookup example.com or Resolve-DnsName example.com
Traceroutetracert 8.8.8.8
Show listening portsnetstat -ano | findstr LISTENING
taskcommand
Pingping 8.8.8.8 or ping -n 4 8.8.8.8
Test port (PowerShell)Test-NetConnection -ComputerName host -Port 443
Test port (telnet)telnet host 443 (enable telnet client first)
Show firewall rulesnetsh advfirewall firewall show rule name=all
Capture traffic (netsh)netsh trace start capture=yes tracefile=c:\trace.etl
Show Wi-Fi profilesnetsh wlan show profiles
quick reference
LTE
4G
NR
5G
sub-6 GHz
coverage
mmWave
capacity
5G NR runs Non-Standalone (NSA, anchored to LTE core) or Standalone (SA, 5G core). Sub-6 GHz = range/penetration; mmWave (24 GHz+) = huge throughput, short range. Target latency <10 ms (URLLC <1 ms).
featureLTE (4G)5G NR (sub-6 GHz)5G NR (mmWave)
Peak downlink~1 Gbps (Cat 20)~4 Gbps~20 Gbps
Typical downlink10–100 Mbps100–500 Mbps1–3 Gbps (short range)
Latency (user plane)30–50 ms10–20 ms<5 ms (URLLC)
Frequency range600 MHz – 2.6 GHz600 MHz – 6 GHz (FR1)24–100 GHz (FR2)
Channel width1.4–20 MHz5–100 MHz50–400 MHz
MIMO4×4 DL / 2×2 ULMassive MIMO (up to 64T64R)Beamforming arrays
Carrier aggregationUp to 32 CCUp to 16 CC (+ LTE CA)Wideband — less CA needed
DuplexingFDD or TDDFDD or TDD (dynamic TDD)TDD
Coverage rangeUp to 100 km (rural)Up to 10 km100–500 m
Network slicingLimited (QCI)✓ Native (S-NSSAI)✓ Native
bandfreqduplexcommon useexpected speeds
B21900 MHzFDDAT&T, T-Mobile US10–50 Mbps DL
B31800 MHzFDDGlobal mid-band15–75 Mbps DL
B4/B661700/2100 MHzFDDAWS — T-Mobile, AT&T20–75 Mbps DL
B72600 MHzFDDEurope/APAC capacity40–150 Mbps DL
B12/B17700 MHzFDDLow-band — rural coverage5–25 Mbps DL
B13700 MHzFDDVerizon low-band5–25 Mbps DL
B14758/788 MHzFDDFirstNet (AT&T) — public safety priority10–40 Mbps DL
B20800 MHzFDDEurope low-band5–30 Mbps DL
B412500 MHzTDDT-Mobile mid-band capacity50–150 Mbps DL
bandfreqtypenotesexpected speeds
n28700 MHzSub-6 / FDDAPAC/Europe low-band 5G30–150 Mbps DL
n412.5 GHzSub-6 / TDDT-Mobile mid-band 5G150–600 Mbps DL
n71600 MHzSub-6 / FDDT-Mobile nationwide coverage30–100 Mbps DL
n77/n783.5 GHzSub-6 / TDDC-band — primary 5G globally200–900 Mbps DL
n794.9 GHzSub-6 / TDDJapan / China capacity300–800 Mbps DL
n25826 GHzmmWave / TDDEurope mmWave1–3 Gbps DL (line-of-sight)
n260/n26139/28 GHzmmWave / TDDUltra-high speed, short range1–4 Gbps DL (line-of-sight)
modecontrol planeuser planecorestatus
Option 3 (NSA)LTE (eNB anchor)LTE + NREPC (4G core)Most common initial 5G deployment — reuses 4G core
Option 7 (NSA)NR + LTENR + LTE5GC (5G core)Transition mode — 5G core with LTE fallback
Option 2 (SA)NR onlyNR only5GC (5G core)Full standalone — enables slicing, URLLC, edge compute
NSA (Non-Standalone) uses LTE as the anchor for signaling — faster to deploy but limited to eMBB use cases. SA (Standalone) with a 5G core unlocks network slicing, ultra-low latency URLLC, and massive IoT (mMTC). Most enterprise 5G private networks deploy SA.
use caseslice typekey requirementexample
Enhanced Mobile BroadbandeMBBHigh throughputHD video streaming, campus Wi-Fi offload, fixed wireless access
Ultra-Reliable Low LatencyURLLC<1ms latency, 99.999% reliabilityIndustrial automation, remote surgery, autonomous vehicles
Massive IoTmMTCLow power, high device densitySmart meters, asset tracking, sensor networks
Private 5GSA + slicingDedicated spectrum, low latencyFactory floors, ports, stadiums, hospital campuses
WAN failover / backupeMBBFast failover, SD-WAN integrationBranch office 5G backup replacing LTE failover
quick reference
0
connected
1
static
110
OSPF
120
RIP
Route selection: longest-prefix match first, then lowest AD (which protocol to trust), then lowest metric (best path within it). eBGP 20 · EIGRP 90 · iBGP 200.
conceptdetail
Forwarding Decision
Longest prefix matchRouter always picks the most specific (longest) matching prefix in the routing table. 10.1.1.0/24 wins over 10.0.0.0/8 for destination 10.1.1.5. A /32 host route always wins over any summary. Default route (0.0.0.0/0) is the last resort — matches everything but loses to any more specific prefix.
CEF / FIBCisco Express Forwarding — hardware-speed routing using pre-built FIB (Forwarding Information Base) and adjacency table (ARP cache). RIB (routing table) = control plane. FIB = data plane copy. Packets forwarded via FIB without CPU involvement. show ip cef to view.
Recursive lookupWhen a route's next-hop is not directly connected, the router does a second lookup in the RIB to resolve the next-hop to an interface. Multiple levels of recursion possible (BGP next-hop → IGP route → connected). CEF flattens this at FIB build time.
Route Sources
Connected (C)Interface is up/up with an IP assigned. Automatically installed. AD = 0. The subnet of the interface IP is directly reachable.
Local (L)/32 host route for the router's own interface IP. AD = 0. Used for traffic destined to the router itself. Present since IOS 15/IOS-XE.
Static (S)Manually configured. AD = 1 by default (beats all dynamic protocols). Persistent until removed. Use floating statics (higher AD) for backup paths.
OSPF (O)Open Shortest Path First. Link-state. AD = 110 (intra-area), 110 (inter-area O IA), 110 (E1/E2 external). SPF algorithm, area-based hierarchy.
EIGRP (D)Enhanced IGRP. Cisco proprietary (now partially open). AD = 90 (internal), 170 (external). DUAL algorithm. Fast convergence, feasibility condition prevents routing loops.
BGP (B)Border Gateway Protocol. Path-vector. AD = 20 (eBGP), 200 (iBGP). Policy-driven, not metric-driven. Internet routing protocol. Slow convergence by design.
RIP (R)Routing Information Protocol. Distance-vector. AD = 120. Max 15 hops. Slow convergence. Legacy — avoid in new designs.
sourceCisco ADAruba AOS-CX ADJuniper preference
Connected000
Static115
EIGRP summary5N/AN/A
eBGP2020170
EIGRP internal90N/AN/A
IGRP100N/AN/A
OSPF11011010
IS-IS11511515
RIP120120100
EIGRP external170N/AN/A
iBGP200200170
Unknown / untrusted255255
💡 AD is local significance only — it's not exchanged between routers. It only determines which source wins when multiple protocols know a route to the same prefix. Lower AD wins. AD 255 = route never used. Juniper calls this "preference" and lower is also better, but the default values differ significantly.
typeexamplebehavior / use case
Standard staticip route 10.1.0.0 255.255.0.0 192.168.1.1Next-hop IP. Route installed when next-hop is reachable. Removed if next-hop disappears (recursive lookup fails).
Directly attached staticip route 10.1.0.0 255.255.0.0 GigE0/1Exit interface specified. Route always installed while interface is up. On multi-access (Ethernet) links, causes proxy ARP for every destination — use next-hop IP instead on LAN interfaces.
Fully specified staticip route 10.1.0.0 255.255.0.0 GigE0/1 192.168.1.1Both interface and next-hop. Best practice for Ethernet — no proxy ARP, route tied to interface state. Preferred form for most static routes.
Floating staticip route 0.0.0.0 0.0.0.0 203.0.113.2 254Higher AD than primary route. Installed only when primary route is gone. Used for backup ISP, OOB management fallback. AD must be higher than the primary protocol's AD.
Null route (black hole)ip route 10.0.0.0 255.0.0.0 Null0Drops traffic matching the prefix. Used to prevent routing loops with summary routes, or to discard traffic to unused address space. Null0 never goes down.
Default routeip route 0.0.0.0 0.0.0.0 203.0.113.1Gateway of last resort. Matches any destination not found in the table. Redistributed into IGP with default-information originate (OSPF) or redistribute static.
conceptdetail
ECMPEqual-Cost Multi-Path — when multiple routes to same destination have equal metric and AD, router installs all in RIB and load-balances across them. Cisco default: 4 paths (up to 32 with maximum-paths). OSPF, EIGRP, BGP (with maximum-paths) all support ECMP.
Per-destination LBCEF default. Each flow (src/dst IP pair) consistently uses the same path. Avoids packet reordering. Works well for many flows. May cause uneven distribution if traffic is dominated by a few large flows.
Per-packet LBEach packet round-robins across paths. Maximum bandwidth utilization but causes packet reordering — bad for TCP. Not recommended for most traffic. Use per-destination or flow-based.
Unequal-cost LBEIGRP only via variance multiplier. Routes within variance × best metric are included. Distributes traffic proportionally to metric. OSPF and BGP do not support unequal-cost LB natively.
topicdetail
Neighbor States
Down → Init → 2-WayDown: no hellos received. Init: hello received, my RID not in neighbor's hello yet. 2-Way: bidirectional communication established — DR/BDR election happens here on broadcast/NBMA. DROther routers stop here with each other.
ExStart → Exchange → Loading → FullExStart: master/slave negotiation by RID. Exchange: DBD (database description) packets exchanged. Loading: LSR/LSU to fill gaps. Full: LSDBs synchronized. Adjacency complete. Only DR/BDR form Full with all neighbors on broadcast segments.
Timers & Requirements
Hello / Dead intervalBroadcast/point-to-point: hello=10s, dead=40s. NBMA: hello=30s, dead=120s. Must match between neighbors. Configurable per-interface. Fast hellos possible (sub-second with BFD preferred).
Adjacency requirementsMust match: area ID, hello/dead timers, subnet mask (point-to-point exempt), MTU (can disable check), stub/NSSA flags, authentication. RID must be unique in domain.
Area Types
Backbone (Area 0)All areas must connect to Area 0. Inter-area traffic must transit Area 0. Virtual links used if physical connection to Area 0 is not possible.
StubNo external (Type 5) LSAs. ABR injects default route. Reduces LSDB size. All routers in area must agree. Cannot have ASBR or virtual link.
Totally StubbyCisco extension. No Type 3 (inter-area) or Type 5 LSAs. Only default route from ABR. Smallest LSDB. Best for spoke sites with single ABR.
NSSANot-So-Stubby Area. Blocks Type 5 but allows Type 7 (NSSA external) LSAs from a local ASBR. ABR translates Type 7 → Type 5 at area boundary. Use when stub site needs to redistribute local routes.
Cost & DR/BDR
Cost calculationCost = reference bandwidth ÷ interface bandwidth. Default ref BW = 100 Mbps → GigE = cost 1, FastE = cost 1 (same!). Always set auto-cost reference-bandwidth 10000 (10G) or higher to differentiate modern interfaces. Lower cost = preferred path.
DR/BDR electionOn broadcast (Ethernet) and NBMA segments only. Highest OSPF priority wins (default 1, range 0–255). Tie: highest RID. Priority 0 = never DR/BDR. Election is non-preemptive — existing DR keeps role until it fails. Set priority on ABRs/core switches to control placement.
toolfunctionapplies to
Redistribution
redistributeInjects routes from one protocol into another. Redistributed routes become external routes in the destination protocol (OSPF E2 by default, EIGRP external AD=170). Always use route-maps or prefix-lists to filter — never redistribute everything blindly.OSPF, EIGRP, BGP, RIP, static, connected
Seed metricRedistributed routes need a metric in the target protocol. OSPF defaults to 20 (E2). EIGRP requires explicit metric or default-metric — without it routes won't be redistributed. RIP defaults to 1.EIGRP, RIP
Mutual redistributionRedistributing between two IGPs in both directions risks routing loops and suboptimal paths. Use route-tags to mark redistributed routes and filter them from being re-redistributed back. Design carefully.OSPF ↔ EIGRP, OSPF ↔ RIP
Filtering Tools
Prefix-listMatch routes by prefix and prefix length range. More flexible and readable than ACLs for route filtering. Processed in sequence order, implicit deny at end. Use le/ge for length ranges.BGP, OSPF distribute-list, redistribution
Route-mapMatch + set logic. Matches on prefix, AS-path, community, metric, tag, etc. Sets attributes (metric, next-hop, community, local-pref, weight). Used for redistribution, BGP policy, PBR. Implicit deny at end.BGP, redistribution, PBR
distribute-listFilters routes going into or out of a routing process. In = filters received updates (affects RIB). Out = filters what this router advertises. Can reference ACL or prefix-list.OSPF, EIGRP, RIP
SummarizationAdvertise one aggregate prefix instead of many specifics. Reduces routing table size, hides topology instability, limits LSA/update flooding. OSPF: area X range (ABR) or summary-address (ASBR). EIGRP: ip summary-address eigrp per interface.OSPF, EIGRP, BGP
⚠️ Redistribution gotcha: When redistributing into OSPF, routes become E2 (external type 2) by default — metric doesn't accumulate as traffic crosses routers. E1 routes add internal cost to external metric, giving more accurate path selection across the OSPF domain. Use E1 when the ASBR is not close to all destinations.
conceptdetail
What PBR doesOverrides normal destination-based routing (FIB lookup) to forward packets based on source IP, protocol, port, packet size, or DSCP marking. Applied inbound on an interface via a route-map.
Use casesDual ISP — route voice traffic via low-latency ISP, bulk data via cheaper ISP. Route traffic from a specific VLAN/subnet to a specific next-hop. Force management traffic out OOB interface. QoS-aware forwarding.
set ip next-hopForward to specified next-hop if reachable — if next-hop is unreachable, falls back to normal routing. Use set ip next-hop verify-availability with IP SLA for tracked failover.
set ip default next-hopOnly applies if no more specific route exists in routing table. Normal routing takes precedence. Good for defaulting traffic without overriding specific routes.
Local PBRApplied to traffic originated by the router itself (not transit). Uses ip local policy route-map. Useful for routing control-plane traffic out specific interfaces.
symptomlikely causecheck / fix
Route missing from tableAD conflict, protocol not redistributing, neighbor down, filtered outshow ip route X.X.X.X — is it in RIB? show ip protocols — check sources. Verify neighbor adjacency. Check distribute-list / prefix-list / route-map for filtering. Check AD — higher AD source loses.
OSPF stuck in ExStart/ExchangeMTU mismatchMost common cause. ip ospf mtu-ignore on both sides to bypass, or fix MTU to match. Also check duplicate RIDs: show ip ospf neighbor — same RID on two routers = instability.
OSPF stuck in 2-Way (not Full)DROther-to-DROther on broadcast segment — expectedNormal behavior. DROther routers only form Full adjacency with DR and BDR, not each other. Check DR/BDR election: show ip ospf neighbor — verify DR/BDR are correct routers.
Route flappingInterface instability, BFD false positives, timer mismatchshow ip route X.X.X.X repeatedly. Check interface counters for errors. Verify hello/dead timers match. Check BFD thresholds. debug ip routing to see install/remove events.
Routing loopMutual redistribution without tags, split horizon disabled, bad summaryTraceroute shows packet bouncing. Check TTL expiry. Verify redistribution uses route-tags to prevent re-redistribution. Check null route covering summary is present.
Traffic taking wrong pathUnexpected AD winner, ECMP hash, PBR override, wrong metricshow ip route X.X.X.X — which source won? show ip cef X.X.X.X detail — which adjacency? Check for PBR: show ip policy. Verify OSPF cost or EIGRP metric on relevant interfaces.
Redistribution not workingMissing seed metric (EIGRP), route filtered, protocol not running on interfaceEIGRP: check default-metric or metric in redistribute command. OSPF: verify redistribute ... subnets (missing subnets keyword = classful only). Check route-map permit/deny logic — implicit deny at end catches everything not matched.
Default route not propagatingMissing originate command, conditional not metOSPF: default-information originate — by default only advertises if default route exists in RIB. Add always keyword to advertise unconditionally. EIGRP: redistribute static with default route present.
🔍 Essential show commands: show ip route · show ip route X.X.X.X · show ip protocols · show ip ospf neighbor · show ip ospf interface brief · show ip cef X.X.X.X detail · show ip policy · show ip prefix-list · debug ip routing (use carefully in production)
quick reference
0
connected
1
static
20
eBGP
110 / 120
OSPF / RIP
Lower administrative distance wins when multiple protocols offer the same prefix. EIGRP 90 (internal) / 170 (external), iBGP 200, unreachable 255. Floating static = AD set above the IGP so it only installs on failover.
sourceADnotes
Connected0Directly connected interface — always preferred
Static1Manually configured. Use AD > 1 for floating statics
EIGRP Summary5Auto-summary routes generated by EIGRP
eBGP20External BGP — routes learned from external AS
EIGRP Internal90Routes within the same EIGRP AS
IGRP100Legacy — not used in modern networks
OSPF110All OSPF route types (intra, inter, external)
IS-IS115Intermediate System to Intermediate System
RIP120Routing Information Protocol — 15 hop max
EIGRP External170Routes redistributed into EIGRP from another protocol
iBGP200Internal BGP — routes from same AS
Unknown / Unreachable255Never installed in routing table
AD is used to select between routes learned from different protocols to the same destination. Once the best source is selected, metric determines the best path within that protocol. AD is local to the router — it is never advertised.
sourcepreference
Connected0
Static1
OSPF Intra-area110
OSPF Inter-area110
OSPF External Type 1110
OSPF External Type 2110
iBGP200
eBGP20
sourcepreference
Direct (connected)0
Local0
Static5
OSPF Internal10
IS-IS L115
IS-IS L218
RIP100
iBGP170
eBGP170
JunOS uses same preference for iBGP/eBGP — BGP local-preference and MED attributes differentiate paths instead.
scenarioconfigbehavior
Primary static, OSPF backupip route 0.0.0.0/0 via 1.1.1.1Static (AD 1) wins over OSPF default (AD 110). Remove static to fall back to OSPF.
Floating static (OSPF primary)ip route 0.0.0.0/0 via 2.2.2.1 200AD 200 loses to OSPF 110. Only installs if OSPF default disappears — classic backup route.
ECMP (equal-cost paths)max-paths 4Same AD + same metric from same protocol = load balance across all paths. Per-flow or per-packet depending on config.
Redistribution AD conflictOSPF redistributes BGPRedistributed route enters OSPF as External — AD 110. Original eBGP route AD 20 still wins on that router.
quick reference
20
eBGP AD
200
iBGP AD
TCP 179
BGP port
16 / 32-bit
AS number
Best-path order: Weight → Local-Pref → locally-originated → shortest AS-path → lowest origin → lowest MED → eBGP>iBGP → lowest IGP metric → oldest → lowest RID. Path-vector protocol; neighbors are manually configured.
propertyiBGPeBGP
AS relationshipSame ASDifferent AS
Admin Distance20020
TTL (default)255 (multihop)1 (direct link)
Next-hop behaviorUnchangedSet to self
Split horizonYes — no readvertise to iBGPNo restriction
Full mesh required?Yes (or RR/confederation)No
AS_PATH prependNot prependedPrepends own AS on send
statemeaning
IdleInitial state — waiting to start TCP connection
ConnectTCP SYN sent — waiting for completion
ActiveTCP failed — retrying. Often means no route to peer or ACL blocking port 179
OpenSentTCP up — OPEN message sent, waiting for peer OPEN
OpenConfirmOPEN received — waiting for KEEPALIVE
EstablishedSession up — exchanging UPDATE messages
#attributeprefernotes
1WeightHighestCisco-proprietary, local to router. Not advertised. Default 0 (32768 for local origination)
2Local PreferenceHighestShared within AS via iBGP. Default 100. Use to prefer exit points from AS
3Locally originatedLocal winsnetwork/aggregate/redistribute originating on this router wins
4AS_PATH lengthShortestCount of AS numbers traversed. Prepend to make paths less preferred
5OriginIGP > EGP > ?IGP (i) = network statement. EGP (e) = legacy. ? = redistributed
6MEDLowestMulti-Exit Discriminator — hint to external AS which entry point to use. Compared only between same AS paths
7eBGP over iBGPeBGP winsExternal routes preferred over internal
8IGP metric to next-hopLowestCost to reach the BGP next-hop via IGP
9Router IDLowestTiebreaker — prefer path from peer with lowest Router ID
Remember: W-L-L-A-O-M-E-I-R — Weight, Local-pref, Locally-originated, AS-path, Origin, MED, eBGP, IGP metric, Router-ID. Or: "We Love Oranges As Oranges Mean Pure Refreshment."
communityvalueeffect
NO_EXPORT0xFFFFFF01Do not advertise beyond AS boundary (ok to iBGP)
NO_ADVERTISE0xFFFFFF02Do not advertise to any BGP peer
LOCAL_AS0xFFFFFF03Do not advertise outside local confederation sub-AS
BLACKHOLE65535:666RFC 7999 — signal upstream to blackhole traffic to prefix
symptomlikely cause
Stuck in ActiveNo TCP to peer — check route to peer IP, ACL on port 179, MD5 auth mismatch
Session flappingKeepalive/hold timer mismatch, unstable link, MTU issues on TCP session
Routes not receivedMissing network statement, no redistribute, outbound route-map filtering
Routes not installedNext-hop unreachable (iBGP — use next-hop-self), not best path, AD too high
Route not advertisedInbound/outbound prefix-list or route-map blocking, community NO_EXPORT set
quick reference
longest-prefix
1st
lowest AD
2nd
lowest metric
3rd
ECMP
equal cost
Route selection order: most-specific prefix always wins (regardless of AD) → lowest administrative distance picks the protocol → lowest metric picks the path within it → equal cost load-balances (ECMP).
1. Longest prefix match — most specific route always wins regardless of source. /32 beats /24 beats /0
2. Administrative Distance — if same prefix from multiple protocols, lowest AD wins (connected=0, static=1, eBGP=20, OSPF=110...)
3. Metric — within same protocol, lowest metric wins (OSPF cost, EIGRP composite, RIP hop count)
4. ECMP — if same prefix, same AD, same metric → load balance across all equal-cost paths
5. Policy (PBR) — policy-based routing bypasses RIB lookup entirely based on ACL match
interface speeddefault cost
100 Mbps1
1 Gbps1
10 Gbps1
10 Mbps10
1.544 Mbps (T1)64
768 Kbps133
Formula: Cost = Reference BW / Interface BW. Default reference = 100 Mbps — everything ≥100M gets cost 1. Set auto-cost reference-bandwidth 10000 on all routers to differentiate GE/10GE/100GE.
methodbehavior
Per-destinationHash on src+dst IP — same flow always takes same path. Default on most platforms.
Per-packetAlternate packets across paths. Can cause out-of-order delivery — avoid for TCP.
Per-flow (5-tuple)Hash on src IP, dst IP, protocol, src port, dst port. Best distribution, no reordering.
Unequal (EIGRP)variance command — install paths up to N× the best metric. Distributes based on metric ratio.
use casematchactionexample
Traffic steering by sourceSource IP ACLSet next-hopSend 10.10.0.0/24 users out ISP-A, others out ISP-B
QoS markingDSCP / ACLSet IP precedence / DSCPMark VoIP traffic before entering WAN
Application steeringPort / protocolSet next-hopSend TCP/443 to direct internet, TCP/1433 via MPLS
SD-WAN path overrideApp-ID / DSCPPath preferenceForce real-time traffic to lowest-latency path regardless of routing table
PBR is applied inbound on the interface and evaluated before the routing table lookup. It's powerful but adds complexity — use route-maps with permit/deny carefully. Always include a set ip default next-hop fallback to avoid black-holing traffic if the PBR next-hop goes down.
quick reference
overlay
transport-agnostic
app-aware
routing
ZTP
zero-touch
SLA
path select
SD-WAN builds an encrypted overlay across any underlay (MPLS + broadband + LTE/5G), steering apps by real-time SLA (loss/latency/jitter). A central controller pushes policy; zero-touch provisioning onboards branches.
Edge Device (CPE)
Branch router/appliance. Terminates overlay tunnels, applies SLA policies, performs app-aware routing. Cisco vEdge/cEdge, Aruba EdgeConnect, VMware SD-WAN Edge, Fortinet FortiGate.
Controller (vSmart)
Centralized control plane. Distributes routing policy, SLA policies, and crypto keys to all edges. OMP (Overlay Management Protocol) on Cisco. Runs in cloud or on-prem.
Orchestrator (vBond)
Initial authentication and NAT traversal. Helps edges discover controllers and each other. Must be reachable from all sites — typically cloud-hosted.
Management (vManage)
GUI + REST API for config, monitoring, and templates. Zero-touch provisioning (ZTP). Dashboard for SLA compliance, circuit health, and app performance.
vendor / platformcontrol planeoverlayapp identificationcloud integrationbest for
Cisco Catalyst SD-WAN
(formerly Viptela)
OMP / vSmart IPsec / DTLS NBAR2 + DPI AWS, Azure, GCP via Cloud OnRamp Cisco-heavy WAN replacement, service provider managed SD-WAN
Aruba EdgeConnect
(Silver Peak)
Orchestrator SaaS IPsec First-packet iQ DPI Direct cloud breakout + Aruba Central Application-first WAN, existing Aruba campus networks
VMware VeloCloud
(Broadcom)
VCO (cloud) VCMP (UDP) DPI + Cloud Intelligence VeloCloud Gateways as PoPs Multi-tenant MSP deployments, VMware environments
Fortinet Secure SD-WAN FortiManager / FortiOS IPsec FortiGuard ISDB FortiSASE, direct breakout Security-first WAN, NGFW consolidation at branch
Palo Alto Prisma SD-WAN
(CloudGenix)
Prisma Cloud controller IPsec App-ID (Palo Alto) Prisma Access SASE SASE-first strategy, Palo Alto security stack
stepaction
1Continuous BFD/probe measurements per transport path (latency, jitter, loss)
2Application identified via DPI (first packet or session)
3SLA policy matched — e.g. VoIP requires <150ms latency, <1% loss
4Paths scored against SLA thresholds — compliant paths eligible
5Best path selected (lowest latency, or ECMP across compliant paths)
6If no path meets SLA — use best available or drop (configurable)
factorMPLSSD-WAN over internet
CostHigh (carrier-managed)60–80% lower
LatencyGuaranteed, predictableVariable — SLA policies compensate
BandwidthLimited, expensive to scaleEasy to scale with broadband/LTE/5G
SecurityL3 isolation (not encrypted)IPsec encryption on all paths
Cloud accessHairpin via HQ or co-loDirect internet breakout per branch
ProvisioningWeeks (carrier lead time)Hours (ZTP + broadband)
VisibilityLimited (carrier managed)Per-app, per-path, real-time
© 2026 netslice.net · v2.2.0 built for network engineers and the curious