🏠 home · reset
⟨⟩ sidebar
Aa text size
▾ routing
▾ switching
▾ wan & sd-wan
▾ management
▾ calculators
▾ security & auth
▾ reference
▾ troubleshooting
▾ layer 1 & 2
▾ protocols
▾ tools & os
Built for network engineers who value straight to the point.
One bookmark. Every tool you reach for daily — subnetting, routing, wireless, security, and reference — all in one place.
STTP · Straight To The Point.
One bookmark. Every tool you reach for daily — subnetting, routing, wireless, security, and reference — all in one place.
STTP · Straight To The Point.
subnetting
subnetting
Subnet Calculator
Enter a CIDR block and get network address, broadcast, host range, wildcard mask, usable hosts, and binary breakdown.
subnetting
VLSM Planner
Variable Length Subnet Masking — allocate multiple subnets of different sizes from a single address block, sorted by host requirement.
subnetting
Subnet List
Divide a network into equal-size subnets. Lists all subnets with their network/broadcast addresses and host ranges.
subnetting
Cloud Subnet Calculator
Cloud-aware subnet planning for AWS, Azure, and GCP. Accounts for provider-reserved addresses and shows usable host counts.
subnetting
Overlap Checker
Paste a list of CIDR ranges and instantly detect overlapping or duplicate subnets — essential for route table audits.
subnetting
Subnet Cheatsheet
Quick-reference table for all /0–/32 prefix lengths: subnet mask, wildcard, host count, and common use cases at a glance.
route / switch
route/switch
Route Summarization
Enter a list of subnets and calculate the optimal summary route (supernet) that covers all of them with minimal waste.
route/switch
VLAN / Trunk Planner
Build VLAN tables, assign ports, visualize trunk/access port configurations, and parse Aruba AOS-CX running config to detect mismatches.
route/switch
PoE Planner
Plan switch PoE budgets. Reference for 802.3af/at/bt standards, per-device power draw for Aruba, Cisco, and Ruckus APs, cameras, and phones.
route/switch
STP Planner
Add switches and links to visualize the spanning tree topology. Calculates root bridge election, port roles (RP/DP/BLK), and root path costs. Includes STP/RSTP/MSTP reference.
route/switch
Switching Cheatsheet
Layer 2 forwarding, MAC table operation, 802.1Q VLAN/trunking, EtherChannel (LACP/PAgP), STP port states and roles, inter-VLAN routing, port security, BPDU guard, storm control, and switching troubleshooting quick reference.
route/switch
Circuit & WAN Planner
WAN bandwidth sizing with IPsec overhead, growth buffer, and SD-WAN path split recommendation. Circuit types reference (MPLS, DIA, broadband, LTE/5G) and SLA thresholds for latency, jitter, and packet loss by application type.
route/switch
Route Preference / AD
Administrative Distance quick reference across Cisco, Aruba, and Juniper. Interactive route conflict resolver — compare two routes, see which wins and why.
route/switch
OSPF Planner
Area type reference (stub/NSSA/totally-stub), OSPF cost calculator with reference bandwidth, DR/BDR election rules, and LSA type quick reference.
route/switch
BGP Cheatsheet
11-step path selection order with memory aid, well-known communities, FSM states, common techniques (prepending, LOCAL_PREF, MED, route reflectors, RTBH).
route/switch
SD-WAN Comparison
Side-by-side comparison of Cisco Viptela, Meraki, Aruba EdgeConnect, Fortinet, VeloCloud, and Versa. NSA vs SA 5G deployment modes and SASE component breakdown.
route/switch
Path Selection
How SD-WAN picks paths step by step, SLA metric thresholds for voice/video/data, path strategies (active/standby, app-aware, FEC, packet duplication), and BFD reference.
route/switch
IPv6 Cheatsheet
Address types (GUA/ULA/link-local/multicast), EUI-64 generation, NDP vs ARP, SLAAC vs DHCPv6, prefix sizing (/48/56/64/127), and well-known multicast addresses.
route/switch
Routing Cheatsheet
IP routing fundamentals, longest prefix match, CEF/FIB, administrative distance table, static route types, ECMP load balancing, OSPF neighbor states and area types, redistribution, route filtering (prefix-list/route-map), PBR, and troubleshooting quick reference.
route/switch
VPN Reference
IPsec IKEv2 phases, tunnel vs transport mode, ESP vs AH, DMVPN phases 1/2/3 with NHRP, GRE overhead and gotchas, WireGuard quick reference, and port/protocol table.
route/switch
SNMP / Syslog / NTP
SNMPv3 security levels, GET/TRAP/INFORM operations, useful OIDs, syslog severity levels 0–7, facility codes, NTP stratum hierarchy, and NTP best practices.
wireless
wireless
Wi-Fi Channel Visualizer
Visual map of 2.4 GHz, 5 GHz, and 6 GHz channels showing width, overlap, and non-overlapping channel sets.
wireless
MCS / RSSI Mapper
Maps RSSI signal levels to MCS index and PHY rates for 802.11n/ac/ax. Shows minimum SNR requirements per MCS.
wireless
802.11 Frame Calculator
Calculate frame overhead, payload efficiency, and throughput for 802.11 frames at different MCS rates and frame sizes.
wireless
Roam Threshold Advisor
Calculates recommended RSSI roaming thresholds based on environment, AP density, and application type (voice, video, data).
wireless
EIRP Calculator
Calculate Effective Isotropic Radiated Power: Tx power + antenna gain − cable loss. Check against regulatory EIRP limits.
wireless
Airtime Utilization
Calculate channel airtime consumed by your client mix. Shows how low-MCS clients starve high-MCS clients and estimates max clients before saturation.
wireless
WPA2 vs WPA3
Side-by-side comparison of WPA2 and WPA3 security modes, authentication methods, encryption, and use-case recommendations.
wireless
Power & dB Guide
Reference for dB, dBm, dBi, SNR. Includes dBm-to-mW table, the 3 dB / 10 dB rules, link budget walkthrough, and RF loss values for common building materials.
wireless
802.11 Amendments
Full timeline of 802.11 amendments from original to Wi-Fi 7 (be). Feature comparison table, key non-speed amendments (k/r/v/w), and MLO / 6 GHz notes.
wireless
802.11 Frame Cheatsheet
Frame types (management/control/data), MAC header fields, management subtype reference, association process step-by-step, reason codes, and status codes.
wireless
EAP / 802.1X Guide
802.1X architecture (supplicant, authenticator, RADIUS), EAP method comparison (PEAP, EAP-TLS, EAP-TTLS, EAP-FAST, EAP-SIM), certificate requirements, and step-by-step auth flow per method.
wireless
Wi-Fi Troubleshooting
Layer-by-layer troubleshooting flowchart — RF/signal, association, 802.1X authentication, DHCP, and routing/DNS. Expandable checks with pass/fail criteria and quick triage commands.
wireless
WLC CLI Comparison
Wireless controller CLI reference for Cisco 9800 (IOS-XE), Aruba Mobility Controller (AOS8), Ruckus SmartZone, and Juniper Mist. Covers clients, APs, SSIDs, RF, auth/AAA, management, and debug. Filter by category or search.
wireless
Antenna Cheatsheet
Antenna types (omni, sector, patch, yagi, panel), radiation pattern diagrams, gain vs coverage tradeoffs, polarization (single/dual/cross-pol), indoor vs outdoor use cases, connector types (RP-SMA, N-type, SMA), and Aruba/Cisco/Ruckus antenna model reference.
reference
reference
Ethernet Guide
Cable categories (Cat5e–Cat8), PoE support by cable, Ethernet speeds timeline (10BASE-T → 400GbE), and a quick cable selection guide by scenario.
reference
SFP / Transceiver Guide
Form factor comparison (SFP to QSFP-DD), common module types (SR/LR/ER/DAC/AOC/BiDi) with reach and connector info, plus breakout/fan-out guide.
reference
IP Ports & Protocols
IP protocol numbers (TCP/UDP/OSPF/GRE/ESP/VRRP) and common TCP/UDP port reference with network-engineer notes (RADIUS, SNMP, TFTP, Syslog, 802.1X).
reference
DSCP / QoS Reference
Full DSCP table with PHB class and drop precedence, WMM access categories (AC_VO/VI/BE/BK) with AIFS/CWmin, and DSCP ↔ 802.1p ↔ WMM mapping.
reference
Wireshark Cheatsheet
Display filter cheatsheet, common protocol filters (DHCP, ARP, EAPOL, RADIUS, STP), 802.11 wireless capture & monitor mode tips, built-in statistics tools, and follow stream / export / tshark workflow tips.
reference
OS Networking
Networking commands for Linux, macOS, and Windows — tabbed reference covering interface management, routing, DNS, packet capture, port testing, and firewall per OS.
reference
4G / 5G Guide
LTE and 5G architecture, radio access technologies (FDD/TDD), frequency bands, NR vs LTE feature comparison, 5G NR sub-6 GHz vs mmWave, network slicing, and carrier aggregation basics.
reference
Vendor CLI Comparison
Side-by-side CLI reference for Cisco IOS/IOS-XE, Aruba AOS-CX, Juniper JunOS, and Arista EOS. Covers interfaces, switching, routing, OSPF, BGP, show commands, and management. Filter by category or search.
reference
Download Time Calculator
How long to transfer a file over any circuit. Lookup table for common file sizes × circuit speeds from 1 Mbps to 100 Gbps. Interactive calculator with custom inputs and protocol overhead toggle (raw, TCP/IP, VPN/IPsec, HTTPS).
security
Firewall Cheatsheet
Stateless vs stateful vs NGFW comparison, zone-based design, NAT types (static/dynamic/PAT/DNAT/Twice NAT), firewall rule order and implicit deny, essential port reference, common attacks (SYN flood, spoofing, DNS tunnel, lateral movement) and mitigations, troubleshooting quick reference.
ip services
ip services
NAT Reference
Static, dynamic, and PAT translation mechanics with session table walkthrough. Interactive port forwarding rule builder with Cisco/Aruba CLI output. Hairpin/NAT loopback, ALG reference (SIP, FTP, H.323), and NAT troubleshooting guide.
ip services
DNS Deep Dive
Record type reference (A, AAAA, CNAME, MX, PTR, NS, SOA, TXT, SRV, CAA), TTL behavior and propagation, recursive vs iterative query flow, DNSSEC chain of trust, split-horizon DNS, and common failure modes (NXDOMAIN, SERVFAIL, DNS rebinding).
ip services
DHCP Cheatsheet
DORA exchange, message types, common options (1/3/6/43/50/51/82/121), lease timers, packet fields, DHCP snooping/DAI/IP Source Guard, and troubleshooting quick reference.
ip services
VoIP Cheatsheet
SIP methods and response codes, INVITE/ACK/BYE call flow, RTP/RTCP/SRTP transport, codec reference (G.711/G.722/G.729/Opus), DSCP/QoS markings, voice VLAN design, DHCP provisioning options, and troubleshooting quick reference.
security
security
802.1X / NAC Deep Dive
NAC posture workflow, MAB fallback, ClearPass and ISE policy flow, RADIUS VSA enforcement (VLAN, role, ACL), CoA/PoD mechanics, quarantine patterns, BYOD onboarding, and common failure modes with debug guidance.
security
ACL Builder
Build and test IPv4 ACLs interactively. Add permit/deny rules, generate CLI output for Cisco IOS, Aruba AOS-CX, and AOS8. Test source + destination + port against the ruleset to see which rule matches and what action is taken.
cidr · or ip + mask
$ calc
10.0.0.0/8
172.16.0.0/12
192.168.1.0/24
10.10.50.0/26
100.64.0.0/10 CGNAT
192.168.1.0 255.255.255.0
configuration
supernet
$ supernet
subnets needed
configuration
parent block
$ block
split into
/
192.168.0.0/22 → /24
10.0.0.0/20 → /26
configuration
cidr blocks to check
configuration
routes to summarize
configuration
cloud provider
AWS VPC
5 reserved
Azure VNet
5 reserved
GCP VPC
3 reserved
Standard
2 reserved
cidr block
$ cloud
/16
/24
/25
/26
/27
/28
configuration
region / country
FCC
frequency band
channel width
spectrum
DFS required
indoor only
overlap zone
channels
summary
overlap analysis
interactive channel planner · place APs & see overlap live
band
channel width
region
0
access points
6
clean channels
0
collisions
0
on DFS
spectrum · click a channel to drop an AP
channel overlap · frequency domain — red = overlapping spectrum
analysisno APs placed
configuration
standard
channel width
spatial streams
signal — RSSI / noise floor
RSSI
dBm
noise
dBm
-45 excellent
-60 good
-70 fair
-75 poor
-85 very poor
MCS index
—
data rate
—
—
SNR / signal quality
0 dB1020304050 dB
full MCS table
| MCS | modulation | coding | min SNR | min RSSI | rate | vs current |
|---|
configuration · parameters
std ?
MCS ?
width ?
streams ?
payload ?
bytes
64B
512B
1500B MTU
9000B jumbo
frame type ?
A-MPDU frames ?
subframes
results
frame breakdown
airtime breakdown
Each 802.11 transmission consumes airtime well beyond the data itself. DIFS (Distributed Inter-Frame Space) is the mandatory idle time before any station may transmit — 802.11ac = 34 µs. Backoff is a random additional wait (0–CWmin slots) to reduce collisions. Preamble (PLCP header) is the sync sequence every receiver must decode before the data — legacy rates make this expensive. MAC header is the 802.11 addressing overhead. Data is your actual payload. SIFS (Short IFS = 16 µs) is the gap before the ACK. ACK is the receiver’s acknowledgement frame. The ratio of Data to Total airtime is your frame efficiency — A-MPDU aggregation improves this dramatically by amortising DIFS + preamble + ACK across many subframes.
| component | duration (μs) | % of total |
|---|
Reading the airtime breakdown
DIFS (DCF Interframe Space) — mandatory quiet time before any station may attempt to transmit (~34 µs for 802.11ac). No one can transmit during DIFS.
Backoff — random wait slots added on top of DIFS to avoid collisions when multiple stations are ready. Each failed transmission doubles the contention window (binary exponential backoff).
Preamble — fixed training sequence at the start of every transmission. Lets the receiver synchronize timing, measure channel, and decode the SIGNAL field. 802.11ac HT preamble = 32+ µs depending on configuration.
SIGNAL / Header — PLCP header containing the data rate, length, and other PHY parameters — transmitted at the base rate so all stations can read it.
Data — the actual payload transmission time. This is the only part carrying user data. Notice how small this slice is relative to the total at low MCS or small payloads.
SIFS (Short Interframe Space) — mandatory gap between data frame and its ACK (~16 µs). Shorter than DIFS so the ACK gets priority over other stations.
ACK — the receiver's acknowledgement frame. If this is A-MPDU, a Block ACK bitmap (64-bit) acknowledges multiple subframes at once — this is why A-MPDU efficiency is so much higher than per-frame ACK.
Efficiency % = Data time ÷ Total airtime. At MCS 0 (BPSK 1/2) with 64-byte packets, efficiency can drop below 5% — 95% of the channel is spent on overhead. A-MPDU with 64 subframes at high MCS can push efficiency above 80%.
Backoff — random wait slots added on top of DIFS to avoid collisions when multiple stations are ready. Each failed transmission doubles the contention window (binary exponential backoff).
Preamble — fixed training sequence at the start of every transmission. Lets the receiver synchronize timing, measure channel, and decode the SIGNAL field. 802.11ac HT preamble = 32+ µs depending on configuration.
SIGNAL / Header — PLCP header containing the data rate, length, and other PHY parameters — transmitted at the base rate so all stations can read it.
Data — the actual payload transmission time. This is the only part carrying user data. Notice how small this slice is relative to the total at low MCS or small payloads.
SIFS (Short Interframe Space) — mandatory gap between data frame and its ACK (~16 µs). Shorter than DIFS so the ACK gets priority over other stations.
ACK — the receiver's acknowledgement frame. If this is A-MPDU, a Block ACK bitmap (64-bit) acknowledges multiple subframes at once — this is why A-MPDU efficiency is so much higher than per-frame ACK.
Efficiency % = Data time ÷ Total airtime. At MCS 0 (BPSK 1/2) with 64-byte packets, efficiency can drop below 5% — 95% of the channel is spent on overhead. A-MPDU with 64 subframes at high MCS can push efficiency above 80%.
throughput vs payload size
configuration
deployment type
client type
coverage overlap (AP cell edge SNR)
overlap RSSI at edge
noise floor
recommended thresholds
roaming timeline
-90 dBm-80-70-60-50 dBm
good coverage
roam candidate zone
sticky / kick zone
no coverage
aruba AOS settings
| parameter | value | location in AOS | status |
|---|
aruba CLI
inputs
country
frequency band
TX power (conducted)
dBm
antenna gain
dBi
cable / connector loss
dB
number of TX chains
EIRP
—
effective isotropic radiated power
EIRP vs regulatory limit
regulatory limits —
| band / sub-band | max EIRP | max mW | notes | status |
|---|
inputs
link / path MTU
bytes
IP version
encapsulation / tunnel
overhead (editable)
bytes
presets approximate — edit for exact
TCP options
adds 12 B, shrinks payload
TCP MSS
—
max TCP segment size
byte breakdown — effective MTU
mss clamp — vendor cli
Why this matters: the MSS is advertised in the TCP SYN; each side sends large segments and relies on Path MTU Discovery to learn it must fragment. When ICMP "fragmentation needed" is filtered (very common across firewalls/tunnels), large packets silently black-hole — connections hang on big transfers but small pings work. Clamping MSS on the tunnel interface forces both ends to negotiate a safe segment size up front. Jumbo frames (MTU 9000) require end-to-end support, including every switch in the path.
switch config
PoE budget (W)
port count
quick fill
utilization
0%
of PoE power budget used
power budget
0 W / 370 W used
370W
0 W
allocated
370 W
remaining
0
ports used
port #
device type
draw (W)
standard
port map — click to remove ■ af ■ at ■ bt ■ over budget
802.3 PoE standards
| standard | class | switch port output | device max | pairs used | min cable | common use |
|---|---|---|---|---|---|---|
| 802.3af (PoE) | 0–3 | 15.4W | 12.95W | 2-pair | Cat3+ | Basic APs, VoIP phones, cameras |
| 802.3at (PoE+) | 4 | 30W | 25.5W | 2-pair | Cat5e+ | Wi-Fi 6 APs, PTZ cameras, thin clients |
| 802.3bt Type 3 (PoE++) | 5–6 | 45–60W | 40–51W | 4-pair | Cat5e+ (Cat6a recommended) | Wi-Fi 6E/7 tri-radio APs, video phones |
| 802.3bt Type 4 (PoE++) | 7–8 | 71.3–90W | 62–71.3W | 4-pair | Cat6a required | High-end APs, digital displays, pan-tilt cameras |
| Cisco uPoE / HPE HPoE | vendor | 60W | ~51W | 4-pair | Cat6a recommended | Cisco pre-bt solution, Aruba 655/730 series |
⚡ Always plan with ~16% line loss between switch port and device. A 25.5W device requires ~30W switch port allocation. Cable length and quality affect actual delivery.
power requirements by device type — APs · cameras · VoIP phones
| model | Wi-Fi gen | radios | PoE standard | switch port W | device W | reduced functionality if underpowered |
|---|---|---|---|---|---|---|
| AP-305 | Wi-Fi 5 (ac) | 2.4+5 | 802.3af | 15.4W | 12.5W | Full functionality on af |
| AP-315 | Wi-Fi 5 (ac) | 2.4+5 | 802.3at | 30W | 14.4W | Runs on af with IPM |
| AP-325 | Wi-Fi 5 (ac) | 2.4+5 | 802.3at | 30W | 20W max | On af: 2.4GHz drops to 1x1:1. Dual E0/E1 PoE-in — two af sources can be combined. |
| AP-375 | Wi-Fi 5 (ac) | 2.4+5 | 802.3at | 30W | 23W max | Outdoor omni. 802.3at required — af insufficient for full operation. |
| AP-377 | Wi-Fi 5 (ac) | 2.4+5 | 802.3at | 30W | 23W max | Outdoor directional. Same power profile as AP-375. 802.3at required. |
| AP-387 | Wi-Fi 5 (ac) | 2.4+5 | 802.3at | 30W | 22W max | Outdoor IP67. PoE+ required. Cable run <80m recommended. |
| AP-505 | Wi-Fi 6 (ax) | 2.4+5 | 802.3af | 15.4W | 12.5W | Full functionality on af |
| AP-515 | Wi-Fi 6 (ax) | 2.4+5 | 802.3bt | ~36W | 25.5W typ / 30W max | On at: limited to 2x2 on 5GHz, USB disabled. On af: minimal operation. |
| AP-518 | Wi-Fi 6 (ax) | 2.4+5 | 802.3at / 802.3bt | 30W (at) / 60W (bt) | 26.1W (1 port) / 32W (2 port) | Hardened outdoor. Dual E0/E1 PoE-in. Combine two 802.3at ports for full power. IPM supported. |
| AP-535 | Wi-Fi 6 (ax) | 2.4+5 | 802.3at | 30W | 26.4W | On af: reduced spatial streams, 1Gbps eth only. |
| AP-555 | Wi-Fi 6 (ax) | 2.4+5+5 | 802.3bt | 45W | 30W+ | On at: operates as 4x4 single 5GHz only. |
| AP-575 | Wi-Fi 6 (ax) | 2.4+5 | 802.3at / 802.3bt | 30W (at) / 60W (bt) | 26.1W (1 port) / 32W (2 port) | Outdoor omni Wi-Fi 6. Dual E0/E1 PoE-in. Single 802.3at = full operation with IPM. |
| AP-577 | Wi-Fi 6 (ax) | 2.4+5 | 802.3at / 802.3bt | 30W (at) / 60W (bt) | 26.1W (1 port) / 32W (2 port) | Outdoor directional Wi-Fi 6. Same power profile as AP-575. Dual E0/E1 PoE-in. |
| AP-635 | Wi-Fi 6E (ax) | 2.4+5+6 | 802.3at | 30W | 23.8W | USB disabled on at. 802.3bt for USB + full power. |
| AP-655 | Wi-Fi 6E (ax) | 2.4+5+6 | 802.3bt | 45–60W | ~40W | On 802.3at: 6GHz radio disabled — operates as dual-band only. |
| AP-675 | Wi-Fi 6E (ax) | 2.4+5+6 | 802.3bt | 60W | 45.5W max | Outdoor tri-radio omni. 802.3bt required. Cat6a strongly recommended. |
| AP-677 | Wi-Fi 6E (ax) | 2.4+5+6 | 802.3bt | 60W | 45.5W max | Outdoor tri-radio directional. Same power profile as AP-675. 802.3bt required. Cat6a required. |
| AP-730 | Wi-Fi 7 (be) | 2.4+5+6 | 802.3bt | 60W | ~50W | Full 802.3bt required for tri-radio at full capability. |
Source: Aruba datasheets and Airheads community PoE quick reference. IPM = Intelligent Power Monitoring — Aruba APs negotiate power via LLDP and reduce functionality gracefully when underpowered.
| model | Wi-Fi gen | radios | PoE standard | switch port W | device W | reduced functionality if underpowered |
|---|---|---|---|---|---|---|
| C9105AX | Wi-Fi 6 (ax) | 2.4+5 | 802.3af | 15.4W | 13.8W | Full functionality on af |
| C9115AX | Wi-Fi 6 (ax) | 2.4+5 | 802.3at | 30W | 21.4W | On af: USB disabled, eth 1Gbps, radios 2x2 |
| C9120AX | Wi-Fi 6 (ax) | 2.4+5 | 802.3at | 30W | 25.5W | On af: USB disabled, eth 1Gbps, radios 1x1 |
| C9130AX | Wi-Fi 6 (ax) | 2.4+5 | 802.3at / uPoE | 30–60W | 30.5W | On af: eth 1Gbps, radios 1x1. USB requires uPoE/bt |
| C9162 | Wi-Fi 6E (ax) | 2.4+5+6 | 802.3bt | 60W | ~45W | On at: reduced spatial streams on 6GHz |
| C9164 | Wi-Fi 6E (ax) | 2.4+5+6 | 802.3bt | 60W | ~50W | On at: 6GHz radio degraded |
| C9166 | Wi-Fi 6E (ax) | 2.4+5+6 | 802.3bt | 60W | ~55W | Full bt required for beacon protection + GCMP-256 |
Source: Cisco AP Power Requirements Quick Reference (cisco.com). Note: Most Cisco switches require CDP or LLDP to be enabled to deliver more than 802.3af power — LLDP is disabled by default on many Cisco switches.
| model | Wi-Fi gen | radios | min PoE | switch port W (full) | device W | reduced functionality if underpowered |
|---|---|---|---|---|---|---|
| AP24 | Wi-Fi 6E (ax) | 2.4+5+6 2x2 | 802.3af | 15.4W | 13W | Full functionality on af |
| AP32 | Wi-Fi 6 (ax) | 2.4+5 2x2 | 802.3af | 15.4W | ~15W | On af: 5GHz 2x2, eth0 1Gbps, eth1 off |
| AP33 | Wi-Fi 6 (ax) | 2.4+5 4x4 | 802.3at | 30W | 19.5W | On af: 5GHz reduces to 2x2, eth1 disabled |
| AP34 | Wi-Fi 6E (ax) | 2.4+5+6 2x2 | 802.3at | 30W | 20.9W | On af: connects to cloud only to report low power |
| AP43 | Wi-Fi 6 (ax) | 2.4+5 4x4 | 802.3at | 30W | 25.5W | On af: 5GHz 2x2, eth1 disabled. Always use at. |
| AP45 | Wi-Fi 6E (ax) | 2.4+5+6 4x4 | 802.3bt | 45W | 29.3W | On at: 2x2 on 2.4+6GHz, 4x4 on 5GHz only |
| AP63 | Wi-Fi 6 (ax) | 2.4+5 outdoor | 802.3at | 30W | 25.2W | Always use at. Outdoor — check cable run length. |
| AP64 | Wi-Fi 6E (ax) | 2.4+5+6 outdoor | 802.3af | 15.4W | 13W | Full functionality on af |
Source: Juniper Mist official PoE requirements documentation (juniper.net). APs use LLDP to negotiate power — ensure LLDP is enabled on the upstream switch. Cisco switches may require manual LLDP enable.
| model | Wi-Fi gen | radios | min PoE | switch port W (full) | device W | reduced functionality if underpowered |
|---|---|---|---|---|---|---|
| R350 | Wi-Fi 6 (ax) | 2.4+5 2x2 | 802.3af | 15.4W | 12.5W | Full functionality on af |
| R550 | Wi-Fi 6 (ax) | 2.4+5 2x2+4x4 | 802.3at | 30W | 22W | On af: reduced 5GHz spatial streams |
| R650 | Wi-Fi 6 (ax) | 2.4+5 4x4 | 802.3at | 30W | 24W | On af: degraded performance |
| R750 | Wi-Fi 6 (ax) | 2.4+5 4x4+4x4 | 802.3at | 30W | 26W | On af: IoT radios may be disabled |
| R850 | Wi-Fi 6 (ax) | 2.4+5 2x2+8x8 | uPoE/PoH | 60W | ~35W+ | On at (Mode 1): 4x4 on 5GHz. On af: minimal |
| R560 | Wi-Fi 6E (ax) | 2.4+5+6 2x2 | 802.3at | 30W | 25.5W | Tri-radio requires 25.5W minimum. Auto-reboot if insufficient for 10+ min. |
| R760 | Wi-Fi 6E (ax) | 2.4+5+6 4x4 | 802.3at | 30W | 25.5W | Tri-radio requires 25.5W minimum. Auto-reboot if insufficient for 10+ min. |
| R770 | Wi-Fi 6E (ax) | 2.4+5+6 4x4 | 802.3bt | 45–60W | ~40W | On at: same 25.5W min restriction as R760 |
| T350 outdoor | Wi-Fi 6 (ax) | 2.4+5 2x2 | 802.3at | 30W | 25W | Outdoor rated. Keep cable run <80m. Surge protection recommended. |
| T750 outdoor | Wi-Fi 6 (ax) | 2.4+5 4x4 | uPoE/bt | 60W | ~40W | Requires bt or uPoE for full operation. Outdoor rated IP67. |
| T760 outdoor | Wi-Fi 6E (ax) | 2.4+5+6 4x4 | 802.3bt | 60W | ~45W | Tri-radio outdoor. bt required. Use Cat6a for runs over 60m. |
Source: Ruckus SmartZone release notes, Ruckus One AP power documentation. R560/R760/R770 will auto-reboot after 10 minutes if PoE supply is insufficient. R850 supports uPoE/PoH via 5Gbps Ethernet interface.
| model | type | resolution | PoE class | switch port W | typical W | max W | notes |
|---|---|---|---|---|---|---|---|
| M3106-L Mk II | Indoor fixed dome | 4MP | Class 2 | 8W | 4.5W | 7.5W | Basic indoor dome. af fully sufficient. |
| M4216-LV | Indoor varifocal dome | 4MP | Class 3 | 10W | 6W | 8.5W | IR + varifocal. af fully sufficient. |
| P3255-V | Indoor fixed dome | 2MP | Class 2 | 8W | 4.7W | 8.0W | Latest ARTPEC-8 SoC. Deep learning analytics. |
| P3265-V | Indoor varifocal dome | 2MP | Class 3 | 10W | 5.5W | 9.5W | ARTPEC-8, Lightfinder 2.0, Forensic WDR. |
| P3265-LV | Indoor IR varifocal | 2MP | Class 3 | 13W | 7.0W | 11.0W | IR illumination increases draw. af sufficient. |
| P3265-LVE | Outdoor IR varifocal | 2MP | Class 3 | 15.4W | 8.5W | 14.0W | Outdoor IP66/67. Heater in cold weather adds ~3W. |
| M3158-V | Indoor panoramic | 8MP | Class 3 | 12W | 6.5W | 9.0W | 180° panoramic. af sufficient for most deployments. |
| Q6135-LE | Outdoor PTZ 32x | 1080p | Class 4 | 30W | 18W | 30W | High-speed PTZ + OptimizedIR 250m. PoE+ required. |
| Q6100-E | Outdoor 360° PTZ | 4K | Class 4 | 30W | 20W | 30W | Multidirectional outdoor. PoE+ required. |
| P5676-LE | Outdoor PTZ | 4K | Class 4 | 30W | 22W | 30W | 4K outdoor PTZ. PoE+ required. |
Source: Axis Communications datasheets and Axis power consumption white paper. Typical values are measured with heaters and IR off at room temperature. Maximum includes heaters at full power, IR at 100%, and all motors running. Plan with maximum values for switch budget. Outdoor cameras with heaters draw significantly more in cold climates — add 3–5W buffer per outdoor camera.
| model | lines | PoE class | switch port W | typical W | notes |
|---|---|---|---|---|---|
| Cisco 7841 | 4-line | Class 1 | 5W | 4.5W | Basic af phone. Very low draw. |
| Cisco 8841 | 5-line | Class 2 | 8W | 6.5W | Mid-range. af sufficient. |
| Cisco 8851 | 5-line + USB | Class 3 | 12W | 9.5W | USB charging port adds draw. af sufficient. |
| Cisco 8861 | 5-line + Wi-Fi + BT | Class 4 | 15.4W | 13W | Wi-Fi + Bluetooth + 2 USB. Class 4 required for full feature set. |
| Cisco 8865 | 5-line + video + Wi-Fi | Class 4 | 15.4W | 15W | Video phone. Class 4 / PoE+ for KEM expansion modules. |
| Poly VVX 311 | 6-line | Class 1 | 5W | 4.5W | Entry level. Very low draw. af more than sufficient. |
| Poly VVX 411 | 12-line | Class 2 | 9W | 7.5W | Mid-range color. af sufficient. |
| Poly VVX 501 | 12-line color | Class 3 | 12W | 10W | Higher-end color display. af sufficient. |
| Poly VVX 601 | 16-line color | Class 3 | 12W | 10W | High-end. Optional USB camera adds ~2W. |
| Poly Edge E300 | 6-line | Class 2 | 8W | 6W | Modern replacement for VVX 311. af sufficient. |
| Poly Edge E500 | 12-line | Class 3 | 12W | 9W | Modern replacement for VVX 411/501. af sufficient. |
| Yealink T46U | 16-line | Class 1 | 6W | 5.5W | Very efficient. af more than sufficient. |
| Yealink T58W | 16-line + Wi-Fi | Class 3 | 11W | 9W | Wi-Fi + BT. af sufficient. |
Source: Cisco IP Phone 8800 series datasheet, Poly/Polycom product datasheets, Yealink datasheets. VoIP phones are generally very PoE-efficient — most run comfortably on 802.3af. Plan 7–12W per phone for budget calculations. Key expansion modules add 2–3W each.
PoE planning tips
| tip | detail |
|---|---|
| 16% line loss | IEEE 802.3 allows up to 16% power loss in the cable. A 25.5W device needs ~30.4W allocated at the switch port. Use Cat5e or better — Cat5 degrades efficiency. |
| LLDP negotiation | Most modern APs negotiate power via LLDP. Cisco switches have LLDP disabled by default — enable it or APs may only get 802.3af. Aruba and Juniper APs also fall back gracefully but with reduced features. |
| Cable length matters | Maximum PoE cable run is 100m (Cat5e+). Longer runs increase resistance and power loss — keep outdoor cable runs under 80m where possible for reliable PoE delivery. |
| Plan for 80% utilization | Never plan to use 100% of switch PoE budget. A 740W switch should only be loaded to ~592W. Power supplies degrade over time and emergency load spikes happen. |
| Tri-radio APs need PoE+/bt | Wi-Fi 6E APs with 3 simultaneous radios (2.4+5+6GHz) typically require 802.3at (30W) minimum and often 802.3bt (45-60W) for full performance. Plan accordingly when upgrading infrastructure. |
| USB + IoT radio adds ~2–5W | Enabling USB devices or IoT radios (BLE/Zigbee) adds 2–5W to AP power draw. Factor this in when using APs with IoT capabilities in dense deployments. |
| Outdoor cable runs | Keep outdoor PoE cable runs under 80m (not 100m) to account for increased resistance in outdoor-rated cables and conduit. Always use Cat5e minimum — Cat6a for 802.3bt outdoor deployments. Add surge protection/lightning arrestors at both ends. |
| Midspan injectors as fallback | If your switch cannot deliver sufficient PoE, midspan injectors (e.g. Aruba H1 or Cisco AIR-PWRINJ6) can deliver full power to individual APs without replacing switch infrastructure. |
quick reference
SAE
WPA3 auth
AES-CCMP
cipher
PMF
mandatory (WPA3)
192-bit
WPA3-Ent
WPA3-Personal uses SAE (Dragonfly) to replace the WPA2 PSK 4-way-handshake weakness (offline cracking/KRACK). Protected Management Frames mandatory in WPA3. Transition mode runs WPA2+WPA3 together.
authentication
| setting | WPA2 | WPA3 | notes |
|---|---|---|---|
| Personal auth | PSK | SAE (Dragonfly) | SAE is resistant to offline dictionary attacks — captured handshake cannot be brute-forced |
| Enterprise auth | 802.1X + EAP | 802.1X + EAP | Same EAP methods. WPA3-Ent 192-bit mode adds GCMP-256 + ECDH/ECDSA requirements |
| Forward secrecy | ✗ none | ✓ per-session PMK | SAE generates a unique PMK each session — past sessions stay protected if PSK is later compromised |
| Open / unauthenticated | Open (no encryption) | OWE (encrypted, no auth) | OWE encrypts traffic without a password. OWE-Transition keeps legacy clients working alongside |
| Transition / mixed mode | — | SAE-Transition | Both WPA3-SAE and WPA2-PSK on same SSID. Same passphrase. Requires controller support (see vendor table) |
encryption
| setting | WPA2 | WPA3 | notes |
|---|---|---|---|
| Unicast cipher (Personal) | CCMP-128 (AES) | CCMP-128 or GCMP-128 | GCMP is faster on hardware with AES-GCM acceleration |
| Unicast cipher (Enterprise) | CCMP-128 | GCMP-256 (192-bit mode) | WPA3-Ent 192-bit mandates GCMP-256 — not supported on all AP hardware (see vendor notes) |
| TKIP | allowed (deprecated) | removed entirely | WPA3 removes TKIP. TKIP-only clients cannot connect to WPA3 SSIDs |
| Management frame cipher | BIP-CMAC-128 (optional) | BIP-CMAC-128 / BIP-GMAC-256 | Mgmt frame encryption is optional in WPA2, mandatory in WPA3 |
protected management frames (802.11w / PMF)
| setting | WPA2 | WPA3 | notes |
|---|---|---|---|
| PMF requirement | optional | required | WPA3 mandates PMF. SAE and OWE will not negotiate without it |
| Deauth / disassoc attack | ✗ vulnerable | ✓ protected | PMF encrypts deauth/disassoc — prevents forced roam and evil twin attacks |
| Legacy client impact | none | may break pre-2018 clients | Some older drivers reject pmf-required. Use transition mode with pmf-optional for mixed environments |
vendor version requirements
| feature | Aruba AOS | Cisco IOS-XE (C9800) | Juniper Mist | Ruckus SmartZone |
|---|---|---|---|---|
| WPA3-Personal (SAE) | 8.6+ | 16.12+ | FW 0.8.x+ | SZ 5.2+ (Wave2 APs) |
| SAE Transition (WPA2+WPA3) | 8.11+ only | 16.12+ | FW 0.8.x+ | SZ 5.2+ |
| WPA3-Enterprise | 8.7+ | 16.12+ | FW 0.8.x+ | SZ 5.2+ |
| WPA3-Enterprise 192-bit | 8.7+ | 17.1+ (not on 9105/9115/9120) | FW 0.14.29091+ | Limited AP support |
| OWE / OWE-Transition | 8.11+ only | 16.12+ | FW 0.8.x+ | SZ 5.2+ |
| WPA3 default on new WLANs | no | no | yes (Nov 2025) | no |
| Known bugs / caveats | Multicast bug 8.11.0–8.11.1 → min 8.11.2.1 | Wave 1 APs not supported. GCMP-256 not on 9105/9110/9115/9120 | No major known bugs | R310 Wave1 is exception. WPA3+DPSK limited |
| Fast roaming (802.11r) + WPA3 | FT-SAE supported | FT-Adaptive not supported with SAE | FT-SAE supported | WPA3+DPSK limits 802.11r |
client device compatibility
| platform | WPA2 | WPA3-Personal (SAE) | WPA3-Enterprise / OWE |
|---|---|---|---|
| Windows 11 | ✓ | ✓ | ✓ |
| Windows 10 (1903+) | ✓ | ✓ | ✓ |
| Windows 10 (pre-1903) | ✓ | ✗ | ✗ |
| macOS 10.15+ (Catalina+) | ✓ | ✓ | ✓ |
| iOS 13+ | ✓ | ✓ | ✓ |
| Android 10+ | ✓ | ✓ | ✓ |
| Android 9 and below | ✓ | ✗ | ✗ |
| Linux (wpa_supplicant 2.9+) | ✓ | ✓ | ✓ |
| Chromebook (Chrome OS 79+) | ✓ | ✓ | ✓ |
| IoT / embedded (most) | ✓ | ✗ (rare support) | ✗ |
| Legacy / pre-2018 devices | ✓ | ✗ | ✗ |
vulnerability / attack surface
| attack | WPA2 | WPA3 | notes |
|---|---|---|---|
| Offline dictionary / brute-force | ✗ vulnerable | ✓ mitigated (SAE) | SAE requires live exchange per attempt — offline cracking is not possible |
| KRACK (CVE-2017-13077) | ✗ vulnerable (patched) | ✓ not applicable | SAE + PMF design prevents the nonce reuse that KRACK exploited |
| PMKID offline attack | ✗ vulnerable | ✓ mitigated | WPA2 PMKID can be captured without a client. SAE has no equivalent attack vector |
| Deauth / disassoc flood | ✗ vulnerable | ✓ protected (PMF) | Unprotected mgmt frames in WPA2 allow forced disconnection attacks |
| Evil twin / rogue AP | ✗ partial | ✓ harder | PMF prevents forced roam; SAE prevents credential capture at rogue AP |
| Dragonblood (SAE side-channel) | N/A | patched in WPA3-R2 (2019) | Early SAE had timing/cache side-channels. Fixed in Wi-Fi Alliance WPA3 R2 spec revision |
vendor cli — wpa3-personal (sae transition mode)
Aruba AOS 8.11.2.1+ · WPA3-SAE Transition mode · Mobility Master CLI
! WPA3-SAE Transition — Aruba AOS 8.11.2.1+ ! Minimum safe build: 8.11.2.1 (avoids multicast encryption bug) wlan ssid-profile "Corp-WPA3-Trans" essid "Corp-WiFi" opmode wpa3-personal-transition wpa-passphrase <your-passphrase> pmf-optional ! wlan virtual-ap "Corp-VAP" ssid-profile "Corp-WPA3-Trans" vlan <your-vlan> ! ap-group "<your-ap-group>" virtual-ap "Corp-VAP"
⚠ AOS 8.10 and below: use opmode wpa2-personal only — transition mode not supported
Cisco Catalyst 9800 · IOS-XE 16.12+ · WPA3-SAE Transition mode
! WPA3-SAE Transition — Cisco IOS-XE 16.12+ ! Note: Fast Transition Adaptive not supported with WPA3 SAE configure terminal wlan Corp-WiFi 1 Corp-WiFi security wpa wpa3 security wpa wpa2 security wpa akm sae security wpa akm psk security wpa wpa3 ciphers aes security pmf optional no shutdown exit ! ! Apply to policy profile: wireless profile policy Corp-Policy vlan <your-vlan> no shutdown ! wireless tag policy Corp-Tag wlan Corp-WiFi policy Corp-Policy
⚠ WPA3 not supported on Wave 1 APs. GCMP-256 not available on C9105/9110/9115/9120.
Juniper Mist · Cloud GUI config (API equivalent shown) · FW 0.8.x+ required
// Juniper Mist — WPA3-SAE Transition via API (PATCH /api/v1/sites/{site_id}/wlans)
// GUI: Site > WLANs > Add WLAN > Security: WPA3/PSK (+WPA-2)
{
"ssid": "Corp-WiFi",
"auth": {
"type": "psk",
"psk": "<your-passphrase>",
"multi_psk_only": false
},
"wpa3_enabled": true, // enables SAE
"wpa2_enabled": true, // enables transition mode
"pmf": "optional",
"vlan_id": <your-vlan>,
"enabled": true
}
// Note: As of Nov 2025, WPA3 is the DEFAULT security type for new WLANs in Mist.
// WPA3-Enterprise 192-bit requires FW 0.14.29091+ and EAP-TLS only.
✓ No major known WPA3 bugs in Mist. WPA3 is now default for new WLANs.
Ruckus SmartZone 5.2+ · WPA3-SAE Transition · GUI path shown
! Ruckus SmartZone 5.2+ — WPA3/WPA2 Mixed Mode ! GUI: Wireless LANs > Create > Security Options > WPA3/WPA2 Mixed ! SmartZone CLI equivalent: no aaa wlan <wlan-id> ! Configure via SmartZone GUI: ! Wireless LANs > Add ! SSID: Corp-WiFi ! Authentication: WPA3/WPA2 Mixed (SAE + PSK) ! Passphrase: <your-passphrase> ! PMF: Optional ! VLAN: <your-vlan> ! Ruckus One (R1) / Cloud — same options via cloud portal ! Navigate to: Configure > WLANs > Add WLAN > Security: WPA3+WPA2 ! Caveats: ! - WPA3 requires 802.11ac Wave2 or newer APs (R310 Wave1 is the one exception) ! - WPA3 + DPSK combined not supported on SZ 6.1.x and below ! - WPA3 + 802.11r: supported in mixed mode; WPA3-Enterprise 192-bit has no fast roaming
⚠ WPA3+DPSK not supported on SZ 6.1.x and below. Most Wave2+ APs supported from SZ 5.2.
quick decision reference
| scenario | WPA2 | WPA3 | recommendation |
|---|---|---|---|
| Corporate — modern clients + 802.1X | WPA2-Enterprise | WPA3-Enterprise | All vendors support from their respective minimums above |
| Corporate — mixed clients + 802.1X | WPA2-Enterprise | WPA3-Ent Transition | pmf-optional. Aruba needs 8.11.2.1+ |
| PSK — modern clients only | WPA2-Personal | WPA3-SAE | Pure SAE if all clients are 2019+ |
| PSK — mixed legacy + modern | WPA2-Personal | SAE-Transition | Aruba: needs 8.11.2.1+. Others: 2020+ builds |
| Guest / captive portal | Open | OWE-Transition | Aruba 8.11+. Cisco 16.12+. Mist FW 0.8.x+ |
| IoT / legacy only | WPA2-Personal | not compatible | Stay WPA2-PSK — isolate on dedicated VLAN |
| 6 GHz / Wi-Fi 6E / Wi-Fi 7 | not permitted | WPA3 mandatory | Wi-Fi Alliance mandates WPA3 + OWE for 6 GHz operation |
quick reference
1500 B
std MTU
9000 B
jumbo
64–1518 B
frame size
18 B
L2 overhead
Frame = 8 preamble + 12 MAC (dst+src) + 2 type + 46–1500 payload + 4 FCS. Min 64 B on the wire, MTU 1500. Speeds 10 M → 400 G; auto-MDIX removes crossover cables.
ethernet cable categories
| category | max speed | bandwidth | max length | shielding | PoE support | best for |
|---|---|---|---|---|---|---|
| Cat5 | 100 Mbps | 100 MHz | 100m | UTP | 802.3af only | Legacy — avoid for new installs |
| Cat5e | 1 Gbps | 100 MHz | 100m | UTP / STP | 802.3af / 802.3at | Minimum standard for new deployments. Supports PoE+. |
| Cat6 | 1 Gbps (10G up to 55m) | 250 MHz | 100m (55m at 10G) | UTP / STP | 802.3af / 802.3at / 802.3bt | Good general-purpose cable. 10G limited to short runs. |
| Cat6a | 10 Gbps | 500 MHz | 100m | UTP / STP / SFTP | 802.3af / at / bt (Type 3 & 4) | Recommended for Wi-Fi 6E/7 APs, 802.3bt deployments, future-proof installs. |
| Cat7 | 10 Gbps | 600 MHz | 100m | SFTP (shielded required) | bt capable (shielded) | Proprietary connectors (GG45/TERA) — avoid unless required. Not a TIA standard. |
| Cat8 | 25 / 40 Gbps | 2000 MHz | 30m | S/FTP (shielded required) | Not designed for PoE | Data center switch-to-switch and server connections only. Very short runs. |
⚡ Cat6a is the recommended minimum for 802.3bt (PoE++) deployments. At high power loads, lower-grade cables generate more heat — bundled cable runs amplify this significantly. TIA-568-C.2 recommends derating PoE budgets for bundled cables.
PoE support by cable type
| cable | 802.3af (15.4W) | 802.3at / PoE+ (30W) | 802.3bt Type 3 (60W) | 802.3bt Type 4 (90W) | notes |
|---|---|---|---|---|---|
| Cat5 | ✓ | ⚠ marginal | ✗ | ✗ | Higher resistance — voltage drop on long runs. Replace for PoE+. |
| Cat5e | ✓ | ✓ | ⚠ possible, not recommended | ✗ | Adequate for PoE+. For bt, use Cat6a to avoid heat buildup in bundles. |
| Cat6 | ✓ | ✓ | ✓ | ⚠ check bundle size | Supports bt Type 3. Type 4 at full 90W requires careful bundle derating. |
| Cat6a | ✓ | ✓ | ✓ | ✓ | Recommended for all PoE++ deployments. Lower resistance = less heat. |
| Cat7 / Cat8 | ✓ | ✓ | ⚠ possible | ✗ not designed for PoE | Cat8 is optimized for short high-speed runs, not PoE delivery. |
Bundle derating rule: IEEE 802.3bt recommends reducing per-port PoE budget when cables are bundled. A bundle of 24 Cat5e cables at full 802.3bt load should be derated by ~40%. Use Cat6a to minimize this effect.
ethernet speeds timeline
| standard | speed | introduced | medium | max copper distance | status |
|---|---|---|---|---|---|
| 10BASE-T | 10 Mbps | 1990 | Cat3+, UTP | 100m | legacy |
| 100BASE-TX (Fast Ethernet) | 100 Mbps | 1995 | Cat5+, UTP | 100m | legacy / IoT |
| 1000BASE-T (GbE) | 1 Gbps | 1999 | Cat5e+, 4-pair | 100m | ubiquitous |
| 2.5GBASE-T | 2.5 Gbps | 2016 | Cat5e+ | 100m | common — Wi-Fi 6/6E APs |
| 5GBASE-T | 5 Gbps | 2016 | Cat5e+ | 100m | growing — high-end APs |
| 10GBASE-T | 10 Gbps | 2006 | Cat6a+ (100m), Cat6 (55m) | 100m (Cat6a) | standard for uplinks / servers |
| 25GBASE-T | 25 Gbps | 2018 | Cat8 | 30m | data center / ToR switches |
| 40GBASE-T | 40 Gbps | 2016 | Cat8 | 30m | data center |
| 100GbE | 100 Gbps | 2010 | Fiber / DAC | fiber only (copper DAC ~3m) | data center / core |
| 400GbE | 400 Gbps | 2018 | Fiber / DAC | fiber only | data center spine |
2.5G and 5G (NBASE-T / IEEE 802.3bz) were introduced specifically to bridge the gap between 1G and 10G over existing Cat5e/Cat6 cabling — crucial for Wi-Fi 6/6E AP deployments where replacing cabling is costly.
quick selection guide
| scenario | recommended cable | reason |
|---|---|---|
| Wi-Fi 6 AP (802.3at) | Cat5e minimum, Cat6 preferred | 1G or 2.5G uplink, PoE+ sufficient |
| Wi-Fi 6E / 7 AP (802.3bt) | Cat6a required | 2.5G–5G uplink, bt PoE++ heat management |
| IP camera (indoor) | Cat5e | 100M–1G, low PoE draw, af sufficient |
| IP camera (outdoor PTZ) | Cat5e outdoor-rated, Cat6a preferred | PoE+ required, UV/moisture rated jacket |
| VoIP phone | Cat5e | 100M, very low PoE, af more than sufficient |
| Switch uplink (1–10G) | Cat6a or fiber SFP+ | 10G over Cat6a up to 100m; fiber for longer runs |
| Server / NIC (10G) | Cat6a or fiber DAC | 10GBASE-T up to 100m, DAC for rack-to-rack |
| New building install (future-proof) | Cat6a everywhere | Handles 10G, full 802.3bt PoE++, Wi-Fi 7 ready |
VLAN / Trunk Planner
configurationvlans
quick add
ports
| port | mode | native VLAN | tagged VLANs | untagged VLANs |
|---|
paste aruba AOS-CX config
Supports:
vlan X, interface 1/1/X, vlan trunk allowed, vlan access, vlan trunk nativequick reference
1 G
SFP
10 G
SFP+
25 G
SFP28
100 G
QSFP28
SR = multimode (OM3/OM4, ~300–400 m), LR = single-mode (~10 km), ER (~40 km). DOM/DDM exposes optical Tx/Rx power & temperature. Match wavelength + fiber type both ends.
transceiver form factors
| form factor | max speed | lanes | hot-swap | typical use |
|---|---|---|---|---|
| SFP | 1 Gbps | 1 | ✓ | GbE uplinks, access switches |
| SFP+ | 10 Gbps | 1 | ✓ | 10G uplinks, server connections, distribution |
| SFP28 | 25 Gbps | 1 | ✓ | 25G server NIC uplinks, leaf-spine fabric |
| SFP56 | 50 Gbps | 1 (PAM4) | ✓ | 50G high-density data center |
| QSFP+ | 40 Gbps | 4 × 10G | ✓ | 40G uplinks, spine switches, breakout to 4×10G |
| QSFP28 | 100 Gbps | 4 × 25G | ✓ | 100G spine/core, breakout to 4×25G or 2×50G |
| QSFP56 | 200 Gbps | 4 × 50G (PAM4) | ✓ | 200G high-density spine |
| QSFP-DD | 400 Gbps | 8 × 50G (PAM4) | ✓ | 400G data center core, AI/ML fabric |
| OSFP | 400 / 800 Gbps | 8 × 50/100G | ✓ | 800G next-gen data center (competing with QSFP-DD) |
| CFP / CFP2 / CFP4 | 100–400 Gbps | varies | ✓ | Long-haul DWDM, service provider edge |
common SFP / SFP+ module types
| module | speed | fiber type | wavelength | max reach | connector |
|---|---|---|---|---|---|
| SX | 1G | MMF OM1/OM2 | 850nm | 550m | LC duplex |
| LX / LX10 | 1G | SMF | 1310nm | 10km | LC duplex |
| ZX | 1G | SMF | 1550nm | 80km | LC duplex |
| SR (10G) | 10G | MMF OM3/OM4 | 850nm | 300m (OM3) / 400m (OM4) | LC duplex |
| LR (10G) | 10G | SMF | 1310nm | 10km | LC duplex |
| ER (10G) | 10G | SMF | 1550nm | 40km | LC duplex |
| ZR (10G) | 10G | SMF | 1550nm | 80km | LC duplex |
| DAC (passive) | 10 / 25 / 40 / 100G | Copper twinax | — | 1–5m | SFP+/QSFP integral |
| AOC (active) | 10 / 25 / 40 / 100G | MMF fiber | 850nm | up to 100m | SFP+/QSFP integral |
| BiDi (WDM) | 1G / 10G | SMF single strand | TX 1310 / RX 1490nm | 10–20km | LC simplex |
⚡ DAC cables are the most cost-effective for rack-to-rack within the same row. AOC for longer inter-rack runs. Use SMF for anything over 550m. BiDi halves fiber strand usage — great for patching efficiency.
breakout / fan-out guide
| source port | breakout to | cable / module | notes |
|---|---|---|---|
| QSFP+ (40G) | 4 × 10G SFP+ | QSFP+ to 4× LC or 4× SFP+ DAC | Most common breakout. Supported on most data center switches. |
| QSFP28 (100G) | 4 × 25G SFP28 | QSFP28 to 4× LC or 4× SFP28 DAC | Leaf-spine breakout for 25G server connections. |
| QSFP28 (100G) | 2 × 50G SFP56 | QSFP28 to 2× SFP56 | Less common. Check switch support. |
| QSFP-DD (400G) | 8 × 50G SFP56 | QSFP-DD to 8× SFP56 DAC | High-density 400G breakout for AI/ML GPU fabric. |
| QSFP-DD (400G) | 4 × 100G QSFP28 | QSFP-DD breakout cable | Spine to 100G leaf switches. |
quick reference
a/n/ac
5 GHz
b/g/n
2.4 GHz
ax
Wi-Fi 6/6E
be
Wi-Fi 7
n = Wi-Fi 4, ac = Wi-Fi 5, ax = Wi-Fi 6 (6E adds 6 GHz), be = Wi-Fi 7. MIMO (n) → MU-MIMO (ac) → OFDMA + MU-MIMO (ax) → MLO + 320 MHz (be).
802.11 amendment timeline
| amendment | wi-fi gen | year | bands | max PHY rate | key tech | status |
|---|---|---|---|---|---|---|
| 802.11 | — | 1997 | 2.4 GHz | 2 Mbps | DSSS / FHSS | obsolete |
| 802.11b | Wi-Fi 1 | 1999 | 2.4 GHz | 11 Mbps | DSSS, CCK | obsolete |
| 802.11a | Wi-Fi 2 | 1999 | 5 GHz | 54 Mbps | OFDM, 52 subcarriers | obsolete |
| 802.11g | Wi-Fi 3 | 2003 | 2.4 GHz | 54 Mbps | OFDM (backward compat b) | legacy |
| 802.11n | Wi-Fi 4 | 2009 | 2.4 / 5 GHz | 600 Mbps | MIMO (4×4), 40 MHz ch, A-MPDU | legacy / IoT |
| 802.11ac | Wi-Fi 5 | 2013 | 5 GHz only | 6.9 Gbps | MU-MIMO DL, 160 MHz, 256-QAM, beamforming | widely deployed |
| 802.11ax | Wi-Fi 6 / 6E | 2021 | 2.4 / 5 / 6 GHz | 9.6 Gbps | OFDMA, MU-MIMO UL+DL, BSS Color, TWT, 1024-QAM | current standard |
| 802.11be | Wi-Fi 7 | 2024 | 2.4 / 5 / 6 GHz | 46 Gbps | MLO, 320 MHz ch, 4K-QAM, 16×16 MU-MIMO, Multi-RU | emerging |
key feature comparison
| feature | Wi-Fi 4 (n) | Wi-Fi 5 (ac) | Wi-Fi 6/6E (ax) | Wi-Fi 7 (be) |
|---|---|---|---|---|
| Modulation | 64-QAM | 256-QAM | 1024-QAM | 4096-QAM |
| Max channel width | 40 MHz | 160 MHz | 160 MHz | 320 MHz |
| Max spatial streams | 4 | 8 | 8 | 16 |
| MU-MIMO (DL) | ✗ | ✓ (4 users) | ✓ (8 users) | ✓ (16 users) |
| MU-MIMO (UL) | ✗ | ✗ | ✓ | ✓ |
| OFDMA | ✗ | ✗ | ✓ | ✓ + Multi-RU |
| Target Wake Time (TWT) | ✗ | ✗ | ✓ | ✓ |
| BSS Coloring | ✗ | ✗ | ✓ | ✓ |
| Multi-Link Operation | ✗ | ✗ | ✗ | ✓ (MLO) |
| 6 GHz band | ✗ | ✗ | ✓ (6E only) | ✓ |
| Security minimum | WPA2 | WPA2 | WPA3 (6E mandatory) | WPA3 mandatory |
📡 Wi-Fi 6E = 802.11ax extended to 6 GHz. Adds up to 1200 MHz of clean spectrum (channels 1–233) with no legacy device interference. Wi-Fi 7's MLO lets clients bond channels across 2.4/5/6 GHz simultaneously for lower latency and higher throughput.
notable amendments (non-speed)
| amendment | year | purpose |
|---|---|---|
| 802.11e | 2005 | QoS / WMM — voice and video priority queues (EDCA) |
| 802.11i | 2004 | Security — basis for WPA2 (CCMP/AES) |
| 802.11r | 2008 | Fast BSS Transition (FT) — faster roaming handoffs |
| 802.11k | 2008 | Radio Resource Measurement — neighbor reports for assisted roaming |
| 802.11v | 2011 | BSS Transition Management — AP can suggest clients roam |
| 802.11w | 2009 | Management Frame Protection (MFP) — protects deauth/disassoc frames |
| 802.11u | 2011 | Interworking — basis for Hotspot 2.0 / Passpoint |
| 802.11s | 2011 | Mesh networking standard |
| 802.11p | 2010 | WAVE — vehicular / V2X communications (DSRC) |
| 802.11ai | 2016 | Fast Initial Link Setup (FILS) — sub-100ms association |
quick reference
22
SSH
443
HTTPS
53
DNS
<1024
well-known
Well-known 0–1023, registered 1024–49151, dynamic/ephemeral 49152–65535. TCP for reliable streams, UDP for low-latency/stateless (DNS, DHCP, VoIP).
IP protocol numbers
| number | protocol | description | common use |
|---|---|---|---|
| 1 | ICMP | Internet Control Message Protocol | ping, traceroute, unreachable messages |
| 2 | IGMP | Internet Group Management Protocol | multicast group membership |
| 6 | TCP | Transmission Control Protocol | reliable, connection-oriented transport |
| 17 | UDP | User Datagram Protocol | low-latency, connectionless transport |
| 41 | IPv6 | IPv6 encapsulation | IPv6-in-IPv4 tunnels (6in4) |
| 47 | GRE | Generic Routing Encapsulation | VPN tunnels, PPTP, ERSPAN |
| 50 | ESP | Encapsulating Security Payload | IPsec encrypted payload |
| 51 | AH | Authentication Header | IPsec integrity / authentication |
| 58 | ICMPv6 | ICMP for IPv6 | NDP, router discovery, ping6 |
| 89 | OSPF | Open Shortest Path First | link-state routing protocol |
| 112 | VRRP | Virtual Router Redundancy Protocol | gateway redundancy |
| 132 | SCTP | Stream Control Transmission Protocol | telecom / signaling (SS7, Diameter) |
common TCP / UDP ports
| port | proto | service | notes |
|---|---|---|---|
| 20 / 21 | TCP | FTP | Data / control. Unencrypted — avoid on production |
| 22 | TCP | SSH | Secure remote shell, SCP, SFTP |
| 23 | TCP | Telnet | unencrypted — legacy only |
| 25 | TCP | SMTP | Email delivery between servers |
| 53 | TCP/UDP | DNS | UDP for queries, TCP for zone transfers / large responses |
| 67 / 68 | UDP | DHCP | Server:67, Client:68 |
| 69 | UDP | TFTP | Firmware upgrades, PXE boot, config backups |
| 80 | TCP | HTTP | Web — unencrypted. Redirect to 443 in production. |
| 123 | UDP | NTP | Time sync — critical for certificates, logs, Kerberos |
| 161 / 162 | UDP | SNMP | Poll:161, Trap:162. Use v3 with auth+priv in production. |
| 389 | TCP/UDP | LDAP | Directory services. Use 636 (LDAPS) in production. |
| 443 | TCP | HTTPS | TLS web traffic, REST APIs, WebSockets |
| 445 | TCP | SMB | Windows file sharing, Active Directory |
| 514 | UDP | Syslog | Network device logging. Use 6514 (TLS syslog) for secure. |
| 636 | TCP | LDAPS | LDAP over TLS — use instead of 389 |
| 1812 / 1813 | UDP | RADIUS | Auth:1812, Accounting:1813. Used by 802.1X / WPA2/3-Ent |
| 3389 | TCP | RDP | Windows Remote Desktop Protocol |
| 4500 | UDP | IKE NAT-T | IPsec NAT traversal (alongside UDP 500) |
| 8080 / 8443 | TCP | Alt HTTP/HTTPS | Dev/proxy web traffic. Common on Aruba Central, NMS tools. |
quick reference
46 / EF
voice
34 / AF41
video
48 / CS6
net-control
0 / BE
best-effort
DSCP = top 6 bits of the IP ToS byte (64 values). EF (46) for real-time voice, AF4x for video, CS6/CS7 for routing/control. Maps to 802.1p CoS at L2.
DSCP values & per-hop behaviors
| DSCP name | decimal | binary (6-bit) | IP Prec | PHB class | traffic type | drop precedence |
|---|---|---|---|---|---|---|
| CS0 / BE | 0 | 000000 | 0 | Default | Best effort — unclassified traffic | — |
| EF | 46 | 101110 | 5 | Expedited Forwarding | VoIP RTP, real-time video, latency-sensitive | Low (prioritized queue) |
| CS6 | 48 | 110000 | 6 | Network Control | Routing protocols (OSPF, BGP, EIGRP) | — |
| CS7 | 56 | 111000 | 7 | Network Control | Reserved — rarely used in practice | — |
| AF11 | 10 | 001010 | 1 | AF Class 1 | Bulk data, low-priority transfers | Low |
| AF12 | 12 | 001100 | 1 | AF Class 1 | Bulk data | Medium |
| AF13 | 14 | 001110 | 1 | AF Class 1 | Bulk data | High |
| AF21 | 18 | 010010 | 2 | AF Class 2 | Transactional / interactive data | Low |
| AF22 | 20 | 010100 | 2 | AF Class 2 | Transactional data | Medium |
| AF23 | 22 | 010110 | 2 | AF Class 2 | Transactional data | High |
| AF31 | 26 | 011010 | 3 | AF Class 3 | Streaming / mission-critical apps | Low |
| AF32 | 28 | 011100 | 3 | AF Class 3 | Streaming apps | Medium |
| AF33 | 30 | 011110 | 3 | AF Class 3 | Streaming apps | High |
| AF41 | 34 | 100010 | 4 | AF Class 4 | Video conferencing, interactive video | Low |
| AF42 | 36 | 100100 | 4 | AF Class 4 | Video conferencing | Medium |
| AF43 | 38 | 100110 | 4 | AF Class 4 | Video conferencing | High |
| CS1 | 8 | 001000 | 1 | Scavenger | Low-priority / scavenger class (P2P, backup) | — |
| CS2–CS5 | 16/24/32/40 | varies | 2–5 | Class Selector | Legacy IP precedence mapping | — |
DSCP = 6 most significant bits of the IP ToS byte (DSCP value × 4 = ToS byte value). AF drop precedence: within the same AF class, higher precedence = dropped first under congestion. EF at DSCP 46 is the standard for VoIP — it gets a dedicated low-latency queue.
802.11e / WMM access categories
| WMM AC | priority | 802.1p | DSCP | traffic type | AIFS | CWmin |
|---|---|---|---|---|---|---|
| AC_VO | Highest | 6–7 | EF (46), CS6/7 | VoIP, voice calls | 2 | 3 |
| AC_VI | High | 4–5 | AF41 (34) | Video streaming, conferencing | 2 | 7 |
| AC_BE | Normal | 0, 3 | CS0 (0), AF21 | Best effort — web, email, data | 3 | 15 |
| AC_BK | Low | 1–2 | CS1 (8) | Background — backup, P2P, print | 7 | 15 |
AIFS = Arbitration InterFrame Space. Lower AIFS = less wait before transmitting = higher priority. CWmin = minimum contention window — smaller window = fewer backoff slots = faster access. WMM maps wired DSCP/802.1p markings to wireless access categories at the AP.
DSCP to 802.1p mapping (common)
| traffic class | DSCP | decimal | 802.1p (CoS) | WMM AC |
|---|---|---|---|---|
| VoIP / voice | EF | 46 | 5 or 6 | AC_VO |
| Call signaling (SIP) | CS3 | 24 | 3 | AC_VI |
| Video conferencing | AF41 | 34 | 4 | AC_VI |
| Streaming video | AF31 | 26 | 4 | AC_VI |
| Routing protocols | CS6 | 48 | 6 | AC_VO |
| Transactional / ERP | AF21 | 18 | 2 | AC_BE |
| Best effort / web | CS0 | 0 | 0 | AC_BE |
| Scavenger / P2P | CS1 | 8 | 1 | AC_BK |
dB & dBm — what the numbers actually mean
| unit | definition | reference point | used for | example |
|---|---|---|---|---|
| dB | Decibel — a ratio between two values on a logarithmic scale. Not an absolute value. | Relative — compares two power levels | Gain, loss, difference between two signals | Antenna gain: +6 dB (4× more power than reference) |
| dBm | Decibels relative to 1 milliwatt. An absolute power measurement. | 0 dBm = 1 mW | Tx power, RSSI, received signal strength | AP Tx power: 20 dBm = 100 mW |
| dBi | Decibels relative to an isotropic antenna (theoretical perfect radiator). | 0 dBi = isotropic radiator | Antenna gain specification | Dipole antenna: 2.14 dBi gain over isotropic |
| dBd | Decibels relative to a dipole antenna. Add 2.14 to convert to dBi. | 0 dBd = dipole antenna | Antenna gain (older spec sheets) | 3 dBd = 5.14 dBi |
Key insight: dB is always a ratio (gain or loss). dBm is an absolute power level. You can add dB to dBm to get dBm — e.g. 20 dBm Tx + 6 dBi antenna = 26 dBm EIRP. You cannot add dBm to dBm.
dBm ↔ milliwatt conversion
| dBm | milliwatts (mW) | watts | typical meaning |
|---|---|---|---|
| 30 dBm | 1000 mW | 1 W | Maximum allowed EIRP in many regions (FCC outdoor) |
| 27 dBm | 500 mW | 0.5 W | High-power outdoor AP Tx power |
| 23 dBm | 200 mW | 0.2 W | High indoor AP Tx — typically reduced to avoid co-channel |
| 20 dBm | 100 mW | 0.1 W | Common indoor AP Tx power on 5 GHz |
| 17 dBm | 50 mW | 0.05 W | Moderate AP Tx power — good for dense deployments |
| 14 dBm | 25 mW | 0.025 W | Reduced power for high-density / co-channel control |
| 10 dBm | 10 mW | 0.01 W | Low Tx — short range, IoT devices |
| 0 dBm | 1 mW | 0.001 W | Reference point — 0 dBm by definition |
| −10 dBm | 0.1 mW | 100 µW | Very low power |
| −30 dBm | 0.001 mW | 1 µW | Excellent received signal (very close to AP) |
| −70 dBm | 0.0000001 mW | 100 pW | Marginal received signal — near edge of coverage |
Formula: dBm = 10 × log₁₀(mW). Reverse: mW = 10^(dBm/10). A useful anchor: 0 dBm = 1 mW, 10 dBm = 10 mW, 20 dBm = 100 mW, 30 dBm = 1000 mW (1 W).
the 3 dB & 10 dB rules of thumb
| rule | effect on power | direction | real-world example |
|---|---|---|---|
| +3 dB | 2× power | increase | 20 dBm → 23 dBm doubles radiated power (100 mW → 200 mW) |
| −3 dB | ½ power | decrease | 20 dBm → 17 dBm halves power (100 mW → 50 mW). Lossy cable, splitter. |
| +10 dB | 10× power | increase | 20 dBm → 30 dBm = 10× more power (100 mW → 1000 mW) |
| −10 dB | ÷10 power | decrease | 20 dBm → 10 dBm = 10× less power. Each wall adds ~3–15 dB of loss. |
| +6 dB | 4× power | increase | High-gain directional antenna vs omni. Doubles range in open space. |
| −6 dB | ¼ power | decrease | Doubling distance in free space loses ~6 dB (inverse square law). |
| +20 dB | 100× power | increase | High-gain dish vs dipole. −50 dBm vs −70 dBm RSSI = 100× stronger signal. |
| −20 dB | ÷100 power | decrease | Typical loss through a concrete wall + floor in a multi-story building. |
Memory trick: 3 dB = double/half, 10 dB = ×10/÷10. Chain them: +13 dB = +10 dB + +3 dB = ×10 × ×2 = ×20 power. −7 dB = −10 dB + +3 dB = ÷10 × ×2 = ÷5 power.
common dB math — worked examples
| scenario | calculation | result | takeaway |
|---|---|---|---|
| AP link budget | 20 dBm Tx + 3 dBi antenna − 2 dB cable loss | = 21 dBm EIRP | Just add and subtract — dB math is arithmetic on the log scale |
| Client receives −65 dBm, noise floor −95 dBm | −65 − (−95) = 30 dB | = 30 dB SNR | Good SNR — supports MCS 9+ (256-QAM) |
| Doubling Tx power from 100 mW to 200 mW | +3 dB | = +3 dBm | Barely noticeable to a client — human perception threshold ~6 dB |
| Client moves from −55 dBm to −61 dBm | 6 dB drop = ÷4 power | = 4× weaker signal | May trigger MCS rate drop — watch for throughput impact |
| Wall penetration loss (drywall) | ~3 dB loss | = ½ signal power | Concrete: 10–15 dB. Brick: 8–12 dB. Glass: 2–3 dB. Metal: 20–30 dB. |
| Free space path loss (doubling distance) | ~6 dB additional loss | = ¼ signal power | Every time you double the distance, you lose 6 dB (inverse square law) |
| Co-channel interference threshold | Desired signal − interference > 20 dB | = 100:1 ratio | 802.11 needs ~20 dB SIR to decode reliably at higher MCS rates |
quick reference — dB multiplier table
| dB change | power multiplier | signal stronger/weaker |
|---|---|---|
| +1 dB | ×1.26 | 26% more power |
| +3 dB | ×2 | double |
| +6 dB | ×4 | 4× — doubles usable range in free space |
| +10 dB | ×10 | 10× |
| +13 dB | ×20 | 20× (10 + 3) |
| +20 dB | ×100 | 100× |
| +30 dB | ×1000 | 1000× |
| −1 dB | ×0.79 | 21% less power |
| −3 dB | ×0.5 | half |
| −6 dB | ×0.25 | quarter |
| −10 dB | ×0.1 | tenth |
| −20 dB | ×0.01 | hundredth |
dB & dBm — what the numbers actually mean
| unit | definition | reference point | used for | example |
|---|---|---|---|---|
| dB | Decibel — a ratio between two values on a logarithmic scale. Not an absolute value. | Relative — compares two power levels | Gain, loss, difference between two signals | Antenna gain: +6 dB (4× more power than reference) |
| dBm | Decibels relative to 1 milliwatt. An absolute power measurement. | 0 dBm = 1 mW | Tx power, RSSI, received signal strength | AP Tx power: 20 dBm = 100 mW |
| dBi | Decibels relative to an isotropic antenna (theoretical perfect radiator). | 0 dBi = isotropic radiator | Antenna gain specification | Dipole antenna: 2.14 dBi gain over isotropic |
| dBd | Decibels relative to a dipole antenna. Add 2.14 to convert to dBi. | 0 dBd = dipole antenna | Antenna gain (older spec sheets) | 3 dBd = 5.14 dBi |
Key insight: dB is always a ratio (gain or loss). dBm is an absolute power level. You can add dB to dBm to get dBm — e.g. 20 dBm Tx + 6 dBi antenna = 26 dBm EIRP. You cannot add dBm to dBm.
dBm ↔ milliwatt conversion
| dBm | milliwatts (mW) | watts | typical meaning |
|---|---|---|---|
| 30 dBm | 1000 mW | 1 W | Maximum allowed EIRP in many regions (FCC outdoor) |
| 27 dBm | 500 mW | 0.5 W | High-power outdoor AP Tx power |
| 23 dBm | 200 mW | 0.2 W | High indoor AP Tx — typically reduced to avoid co-channel |
| 20 dBm | 100 mW | 0.1 W | Common indoor AP Tx power on 5 GHz |
| 17 dBm | 50 mW | 0.05 W | Moderate AP Tx power — good for dense deployments |
| 14 dBm | 25 mW | 0.025 W | Reduced power for high-density / co-channel control |
| 10 dBm | 10 mW | 0.01 W | Low Tx — short range, IoT devices |
| 0 dBm | 1 mW | 0.001 W | Reference point — 0 dBm by definition |
| −10 dBm | 0.1 mW | 100 µW | Very low power |
| −30 dBm | 0.001 mW | 1 µW | Excellent received signal (very close to AP) |
| −70 dBm | 0.0000001 mW | 100 pW | Marginal received signal — near edge of coverage |
Formula: dBm = 10 × log₁₀(mW). Reverse: mW = 10^(dBm/10). A useful anchor: 0 dBm = 1 mW, 10 dBm = 10 mW, 20 dBm = 100 mW, 30 dBm = 1000 mW (1 W).
the 3 dB & 10 dB rules of thumb
| rule | effect on power | direction | real-world example |
|---|---|---|---|
| +3 dB | 2× power | increase | 20 dBm → 23 dBm doubles radiated power (100 mW → 200 mW) |
| −3 dB | ½ power | decrease | 20 dBm → 17 dBm halves power (100 mW → 50 mW). Lossy cable, splitter. |
| +10 dB | 10× power | increase | 20 dBm → 30 dBm = 10× more power (100 mW → 1000 mW) |
| −10 dB | ÷10 power | decrease | 20 dBm → 10 dBm = 10× less power. Each wall adds ~3–15 dB of loss. |
| +6 dB | 4× power | increase | High-gain directional antenna vs omni. Doubles range in open space. |
| −6 dB | ¼ power | decrease | Doubling distance in free space loses ~6 dB (inverse square law). |
| +20 dB | 100× power | increase | High-gain dish vs dipole. −50 dBm vs −70 dBm RSSI = 100× stronger signal. |
| −20 dB | ÷100 power | decrease | Typical loss through a concrete wall + floor in a multi-story building. |
Memory trick: 3 dB = double/half, 10 dB = ×10/÷10. Chain them: +13 dB = +10 dB + +3 dB = ×10 × ×2 = ×20 power. −7 dB = −10 dB + +3 dB = ÷10 × ×2 = ÷5 power.
common dB math — worked examples
| scenario | calculation | result | takeaway |
|---|---|---|---|
| AP link budget | 20 dBm Tx + 3 dBi antenna − 2 dB cable loss | = 21 dBm EIRP | Just add and subtract — dB math is arithmetic on the log scale |
| Client receives −65 dBm, noise floor −95 dBm | −65 − (−95) = 30 dB | = 30 dB SNR | Good SNR — supports MCS 9+ (256-QAM) |
| Doubling Tx power from 100 mW to 200 mW | +3 dB | = +3 dBm | Barely noticeable to a client — human perception threshold ~6 dB |
| Client moves from −55 dBm to −61 dBm | 6 dB drop = ÷4 power | = 4× weaker signal | May trigger MCS rate drop — watch for throughput impact |
| Wall penetration loss (drywall) | ~3 dB loss | = ½ signal power | Concrete: 10–15 dB. Brick: 8–12 dB. Glass: 2–3 dB. Metal: 20–30 dB. |
| Free space path loss (doubling distance) | ~6 dB additional loss | = ¼ signal power | Every time you double the distance, you lose 6 dB (inverse square law) |
| Co-channel interference threshold | Desired signal − interference > 20 dB | = 100:1 ratio | 802.11 needs ~20 dB SIR to decode reliably at higher MCS rates |
quick reference — dB multiplier table
| dB change | power multiplier | signal stronger/weaker |
|---|---|---|
| +1 dB | ×1.26 | 26% more power |
| +3 dB | ×2 | double |
| +6 dB | ×4 | 4× — doubles usable range in free space |
| +10 dB | ×10 | 10× |
| +13 dB | ×20 | 20× (10 + 3) |
| +20 dB | ×100 | 100× |
| +30 dB | ×1000 | 1000× |
| −1 dB | ×0.79 | 21% less power |
| −3 dB | ×0.5 | half |
| −6 dB | ×0.25 | quarter |
| −10 dB | ×0.1 | tenth |
| −20 dB | ×0.01 | hundredth |
quick reference
0 dBm
= 1 mW
+3 dB
= 2×
+10 dB
= 10×
+20 dBm
= 100 mW
dBm is absolute power; dB is a ratio. +3 dB doubles, −3 dB halves, +10 dB is 10×. EIRP = Tx power − cable loss + antenna gain. Free-space path loss(dB) = 20·log₁₀(d) + 20·log₁₀(f) + 32.44.
dB & dBm — what the numbers mean
| term | definition | formula | key point |
|---|---|---|---|
| dB | Decibel — a ratio between two power levels. Not an absolute unit. | dB = 10 × log₁₀(P₂ / P₁) | Always relative. "3 dB gain" means 2× the power of a reference — but what reference? |
| dBm | Decibels relative to 1 milliwatt. An absolute power level. | dBm = 10 × log₁₀(mW / 1mW) | 0 dBm = 1 mW. Every +10 dBm = 10× more power. Every +3 dBm ≈ 2× more power. |
| dBi | Antenna gain relative to an isotropic (perfect omnidirectional) radiator. | dBi = gain vs theoretical point | An antenna with 6 dBi gain focuses power 4× more than a perfect sphere radiator. |
| dBd | Antenna gain relative to a dipole antenna. | dBd = dBi − 2.15 | Dipole ≈ 2.15 dBi. Always clarify which reference an antenna spec uses. |
| RSSI | Received Signal Strength Indicator — vendor-specific scale, often maps to dBm. | unitless (0–255 or 0–100) | Not standardized. Most Wi-Fi tools display RSSI as dBm for clarity. Always verify units. |
| SNR | Signal-to-Noise Ratio — how far signal is above the noise floor. | SNR (dB) = RSSI − noise floor | Noise floor is typically −95 to −100 dBm. SNR >25 dB is needed for high MCS rates. |
💡 The key insight: dB is a ratio (dimensionless), dBm is an absolute level. You add dB gains and subtract dB losses. You cannot add two dBm values together — that would be like adding two temperatures to get a combined temperature.
dBm to milliwatt conversion table
| dBm | milliwatts | description | typical context |
|---|---|---|---|
| 30 dBm | 1000 mW (1W) | Maximum legal EIRP in some bands | Outdoor bridge / high-power AP |
| 27 dBm | 500 mW | High-power outdoor AP | Point-to-multipoint deployments |
| 24 dBm | 250 mW | High indoor / outdoor AP Tx | Common max for enterprise indoor APs |
| 23 dBm | 200 mW | Common enterprise AP Tx power | Aruba, Cisco, Extreme at full power |
| 20 dBm | 100 mW | Typical indoor AP, medium power | Most enterprise APs at reduced power |
| 17 dBm | 50 mW | Moderate power — high density | Typical in high-density deployments |
| 14 dBm | 25 mW | Low power — dense AP placement | Stadium / conference room deployments |
| 10 dBm | 10 mW | Very low power | IoT devices, BLE beacons |
| 0 dBm | 1 mW | Reference point | Definition of 0 dBm |
| −10 dBm | 0.1 mW | Very weak transmit / strong receive | Near-AP client RSSI |
| −30 dBm | 0.001 mW | Excellent RSSI | Client 1–2m from AP |
| −67 dBm | 0.0000002 mW | Good RSSI threshold | Minimum for voice / video |
| −70 dBm | 0.0000001 mW | Acceptable data RSSI | Typical roaming trigger point |
| −80 dBm | 0.00000001 mW | Weak — low MCS only | Edge of coverage, MCS 0–1 |
| −90 dBm | 0.000000001 mW | Near noise floor | Unusable for data |
💡 The mW values get tiny fast because the dB scale is logarithmic. A -67 dBm signal is 200 picowatts — your AP is detecting signals 50 billion times weaker than its own transmit power. This is why antenna placement and avoiding interference sources matters so much.
the 3 dB and 10 dB rules
| rule | power effect | example | practical meaning |
|---|---|---|---|
| +3 dB | ≈ 2× more power | 20 dBm → 23 dBm | 100 mW → ~200 mW. Doubling Tx power only adds 3 dB — often not worth the interference increase. |
| −3 dB | ≈ half the power | 23 dBm → 20 dBm | A 3 dB cable loss cuts your signal in half before it reaches the antenna. |
| +10 dB | 10× more power | 20 dBm → 30 dBm | 100 mW → 1000 mW. Huge jump. Regulatory EIRP limits exist to prevent this being abused. |
| −10 dB | 1/10th the power | −60 dBm → −70 dBm | RSSI dropping 10 dB is a massive degradation. Client drops 2–3 MCS tiers. |
| +6 dB | 4× more power | Antenna upgrade: 0 → 6 dBi | A 6 dBi directional antenna quadruples effective radiated power vs an isotropic source. |
| −6 dB | 1/4 the power | Distance doubles (free space) | In free space, every time distance doubles, signal drops ~6 dB. Indoors is much worse. |
🧮 Quick mental math: memorize +3 dB = ×2 and +10 dB = ×10. Everything else follows. +6 dB = ×4, +7 dB ≈ ×5, +13 dB = ×20, +20 dB = ×100. For negative values, flip it: −20 dB = 1/100th the power.
link budget example — adding dB in practice
| element | dB value | running total | notes |
|---|---|---|---|
| AP Tx power | +20 dBm | 20 dBm | 100 mW transmit power |
| Cable / connector loss | −1 dB | 19 dBm | Short pigtail cable |
| Antenna gain | +5 dBi | 24 dBm EIRP | Directional antenna — EIRP is the number that matters for regulatory limits |
| Free-space path loss (50m, 5GHz) | −88 dB | −64 dBm | Signal received at the client |
| Wall penetration loss (×2 walls) | −14 dB | −78 dBm | ~7 dB per drywall partition |
| Client antenna gain | +2 dBi | −76 dBm RSSI | Typical laptop internal antenna |
📐 EIRP (Effective Isotropic Radiated Power) = Tx Power (dBm) + Antenna Gain (dBi) − Cable Loss (dB). This is the number regulators care about. In the US, max EIRP on 5 GHz UNII-1 is 23 dBm (200 mW). You can use a high-gain antenna as long as you reduce Tx power to stay within the EIRP limit.
common RF loss values — quick reference
| material / obstacle | typical loss (dB) | notes |
|---|---|---|
| Free space (distance doubles) | −6 dB | Theoretical. Real-world is worse due to reflections. |
| Drywall / partition | 3–5 dB | Most common office obstacle |
| Wooden door | 3–5 dB | Similar to drywall |
| Brick / concrete block wall | 8–15 dB | Significant loss — one wall can kill coverage |
| Reinforced concrete | 15–25 dB | Parking garages, bunkers — plan extra APs |
| Metal door / filing cabinet | 20–30 dB | Near-complete block. Creates RF dead zones. |
| Glass window (standard) | 2–3 dB | Low loss — but reflections cause multipath |
| Low-E glass (energy efficient) | 20–30 dB | Metallic coating blocks RF almost entirely |
| Human body | 3–5 dB | Crowds absorb RF — factor in for high-density |
| Floor / ceiling (concrete) | 10–15 dB | Between floors in a multi-storey building |
| LMR-400 coax (per metre) | ~0.23 dB/m @ 2.4GHz | Low-loss cable — use the shortest run possible |
| LMR-400 coax (per metre) | ~0.44 dB/m @ 5GHz | Loss doubles at 5 GHz vs 2.4 GHz |
⚠ Low-E glass is the most commonly overlooked RF blocker in modern buildings. A floor-to-ceiling energy-efficient window can cause 20–30 dB loss — equivalent to a concrete wall. Always ask about glazing spec during site surveys.
airtime utilization calculator
presets:
configuration
ap configuration
Wi-Fi standard
Channel width
Spatial streams (AP)
Overhead factor
client mix
Enter number of clients per signal quality tier. Each tier maps to a typical MCS index.
Excellent (MCS 9–11, >-65 dBm)
clients
Good (MCS 5–8, -65 to -70 dBm)
clients
Fair (MCS 2–4, -70 to -75 dBm)
clients
Poor (MCS 0–1, <-75 dBm)
clients
Avg traffic per client
Mbps
Add switches with their bridge priority and MAC address. Add links between them with path cost. The tool calculates root bridge election, port roles, and visualizes the spanning tree topology.
configuration
switches
name
bridge priority
MAC address
links
from switch
to switch
path cost
STP / RSTP / MSTP comparison
| feature | STP (802.1D) | RSTP (802.1w) | MSTP (802.1s) |
|---|---|---|---|
| Standard | IEEE 802.1D-1998 | IEEE 802.1w → merged into 802.1D-2004 | IEEE 802.1s → merged into 802.1Q |
| Convergence time | 30–50 seconds | < 1 second | < 1 second per instance |
| Port states | Blocking, Listening, Learning, Forwarding, Disabled | Discarding, Learning, Forwarding | Discarding, Learning, Forwarding (per instance) |
| Port roles | Root, Designated, Blocked | Root, Designated, Alternate, Backup | Root, Designated, Alternate, Backup, Master |
| VLAN support | Single instance (all VLANs) | Single instance (all VLANs) | Multiple instances — per VLAN group |
| BPDU handling | Relays BPDUs from root | Each switch generates BPDUs | Each switch generates BPDUs per instance |
| Topology change | TCN floods entire network, 30s+ to reconverge | Rapid transition, port-by-port handshake | Per-instance topology change |
| Cisco proprietary variants | PVST+ (per-VLAN STP) | Rapid PVST+ | — |
| Use today | Legacy only | Default on most modern switches | Enterprise multi-VLAN environments |
STP timers & bridge ID
| parameter | default value | range | description |
|---|---|---|---|
| Hello time | 2 seconds | 1–10s | Interval between BPDUs sent by root bridge |
| Forward delay | 15 seconds | 4–30s | Time spent in Listening and Learning states each |
| Max age | 20 seconds | 6–40s | Time before a BPDU is considered stale |
| Convergence (STP) | 30–50 seconds | — | Max age + 2× forward delay = 50s worst case |
| Convergence (RSTP) | < 1 second | — | Proposal/agreement handshake replaces timers |
| Bridge priority | 32768 | 0–61440 (steps of 4096) | Lower = more likely to become root bridge |
| Bridge ID | priority + MAC | — | 8-byte value: 2 bytes priority + 6 bytes MAC. Lower Bridge ID wins root election. |
| Path cost (10G) | 2 | — | IEEE 802.1D-2004 long path cost |
| Path cost (1G) | 4 | — | IEEE 802.1D-2004 long path cost |
| Path cost (100M) | 19 | — | IEEE 802.1D-1998 short path cost (still widely used) |
| Path cost (10M) | 100 | — | IEEE 802.1D-1998 short path cost |
Root bridge election: lowest Bridge Priority wins. Tie → lowest MAC address wins. To influence election: set priority to 0 or 4096 on the desired root. Use
spanning-tree vlan X priority 0 on Cisco or spanning-tree priority 0 on Aruba AOS-CX.
port roles explained
| role | per switch | state | description |
|---|---|---|---|
| Root Port (RP) | One per non-root switch | Forwarding | Port with the lowest root path cost on a non-root switch. Best path toward root bridge. |
| Designated Port (DP) | One per segment | Forwarding | Forwards frames on a given segment. All root bridge ports are designated. One per link. |
| Blocked / Alternate (BLK) | Remaining ports | Blocking | Discards frames to prevent loops. In RSTP called Alternate port — takes over if root port fails. |
| Backup Port | RSTP only | Discarding | RSTP only. Redundant path to a segment where this switch already has a designated port (hub scenario). |
quick reference
1–4094
VLAN range
4 B
802.1Q tag
300 s
CAM aging
802.1D/w/s
STP
Access ports carry one untagged VLAN; trunks carry many 802.1Q-tagged + one untagged native VLAN. CAM/MAC table maps MAC→port. RSTP (802.1w) converges in <1 s vs classic STP 30–50 s.
Layer 2 forwarding — how a switch decides
| action | when | detail |
|---|---|---|
| Learn | Any frame received | Source MAC + ingress port recorded in the MAC address table (CAM table). Entry ages out after inactivity timeout (default 300s on most platforms). |
| Forward (unicast) | Destination MAC known in table | Frame sent out the single port associated with the destination MAC. No flooding, no copies. |
| Flood | Destination MAC unknown (unknown unicast) | Frame sent out all ports in the same VLAN except the ingress port. Unknown unicast + broadcast + multicast all flood. |
| Drop | Source = destination port, or port security violation | Frame discarded. Also dropped if VLAN mismatch, port in blocking state, or storm control threshold exceeded. |
💡 CAM vs TCAM: MAC table uses CAM (Content Addressable Memory) — exact-match lookup in O(1). ACLs/routing use TCAM (Ternary CAM) — supports wildcard/prefix matching. CAM exhaustion causes all unicast to flood (like an unknown MAC). TCAM exhaustion causes route/ACL drops.
MAC address table — types & aging
| entry type | how added | removed by | notes |
|---|---|---|---|
| Dynamic | Learned from incoming frames automatically | Age-out timer (default 300s) or MAC flush | Most entries. Refreshed on each frame from that MAC. Cleared by clear mac address-table dynamic. |
| Static | Manually configured by admin | Manual removal or reboot (unless saved) | Persistent. Used to pin a known MAC to a port. Overrides dynamic learning for that MAC. |
| Secure | Port security — learned or manually added | Port security violation action | Sticky secure — learned dynamically but saved to running config. Persists across reboot if config saved. |
| VLAN-mapped | Each entry scoped to a VLAN | — | Same MAC can exist in multiple VLANs (e.g. a router sub-interface). Table key = MAC + VLAN. |
802.1Q VLANs & trunking
| concept | detail |
|---|---|
| 802.1Q Tag | |
| Tag location | 4-byte tag inserted into Ethernet frame between src MAC and EtherType. Fields: TPID (0x8100) + PCP (3-bit CoS) + DEI (drop eligible) + VID (12-bit VLAN ID, 0–4095). |
| Valid VLAN range | 1–4094. VLAN 0 = priority tagging only (no VLAN). VLAN 4095 reserved. VLAN 1 = default, exists on all ports unless pruned. VLANs 1002–1005 reserved on Cisco for FDDI/Token Ring. |
| Extended VLANs | 1006–4094. Require VTP v3 or transparent mode on Cisco. Supported natively on Aruba AOS-CX and Juniper without VTP dependency. |
| Port Types | |
| Access port | Carries one VLAN. Frames arrive untagged, switch tags internally. Frames leave untagged. End devices (PCs, APs, servers) connect here. Port is a member of exactly one VLAN. |
| Trunk port | Carries multiple VLANs. Frames tagged with 802.1Q (except native VLAN). Used for switch-to-switch, switch-to-router, switch-to-AP uplinks. Allowed VLAN list restricts which VLANs traverse. |
| Native VLAN | VLAN whose frames traverse a trunk untagged. Default = VLAN 1. Must match on both ends — mismatch causes VLAN hopping risk and CDP/LLDP native VLAN mismatch warnings. Best practice: set native VLAN to an unused VLAN. |
| Voice VLAN | Access port carries data VLAN (untagged) + voice VLAN (tagged via CDP/LLDP-MED). Phone's embedded switch passes PC traffic untagged. Switch port appears as both access + tagged for voice. |
| VLAN Pruning & VTP | |
| Pruning | Prevents unnecessary VLAN flooding across trunks that have no members in that VLAN. VTP pruning (Cisco) or manual allowed-VLAN list. Reduces broadcast domain footprint. |
| VTP modes | Server — creates/modifies/deletes VLANs, propagates. Client — receives only, can't modify. Transparent — local only, forwards VTP frames but doesn't sync. Off — VTPv3, doesn't forward. Use transparent/off for safety. |
⚠️ VLAN hopping attack: Two vectors — (1) switch spoofing: attacker sends DTP frames to negotiate a trunk, gaining access to all VLANs; (2) double tagging: attacker on native VLAN sends double-tagged frame, outer tag stripped at first switch, inner tag delivers to target VLAN. Mitigate: disable DTP (
switchport nonegotiate), set native VLAN to unused VLAN, tag native VLAN explicitly.
EtherChannel — LACP · PAgP · static
| protocol | standard | modes | negotiation |
|---|---|---|---|
| LACP | IEEE 802.3ad / 802.1AX | active — initiates. passive — responds only. active+active or active+passive forms channel. | Preferred. Vendor-neutral. Supports fast timers (1s PDU vs 30s slow). Max 16 members, 8 active. |
| PAgP | Cisco proprietary | desirable — initiates. auto — responds only. desirable+desirable or desirable+auto. | Cisco-only. Avoid for multi-vendor. Max 8 members. |
| Static (on) | No protocol | on — forces channel, no negotiation. Both ends must be on. | No protection against misconfiguration. If one side is on+other is LACP, channel won't form. Use with caution. |
| load balancing method | hashes on | best for |
|---|---|---|
src-mac | Source MAC only | Many clients, one uplink. Poor for routed traffic (all same src MAC). |
dst-mac | Destination MAC only | One server, many clients. |
src-dst-mac | XOR of src+dst MAC | General L2 — good default for access-layer bundles. |
src-dst-ip | XOR of src+dst IP | Best for routed/uplink bundles — distributes across varied IP pairs. |
src-dst-port | IP + L4 port | Best overall when available — most entropy for mixed traffic flows. |
⚡ EtherChannel requirements — all member ports must match: speed, duplex, VLAN config (access VLAN or trunk allowed list), STP settings, and port type (all access or all trunk). Mismatch = channel won't form or will flap. Check with
show etherchannel summary — look for (D) = down, (P) = in port-channel, (I) = standalone (not in channel).
STP port states & roles (802.1D / RSTP)
| 802.1D state | RSTP state | forwards data? | learns MACs? | duration |
|---|---|---|---|---|
| Blocking | Discarding | No | No | Until STP converges. Receives BPDUs. |
| Listening | Discarding | No | No | 15s (Forward Delay). Participates in STP election. |
| Learning | Learning | No | Yes | 15s (Forward Delay). Builds MAC table before forwarding. |
| Forwarding | Forwarding | Yes | Yes | Normal operation. |
| Disabled | Discarding | No | No | Admin shutdown or no cable. |
| port role | per switch? | description |
|---|---|---|
| Root Port (RP) | One per non-root switch | Best path toward the root bridge. Lowest root path cost. Tie-breaks: lowest upstream bridge ID → lowest port ID. |
| Designated Port (DP) | One per segment | Forwards traffic on that segment. Root bridge has all designated ports. Non-root switch wins DP on a segment if it has lower root path cost to root. |
| Blocked / Alternate (BLK/ALT) | Any remaining ports | Discards frames to prevent loops. RSTP Alternate port is the backup root port — transitions to forwarding instantly if RP fails (no 30s delay). |
| Backup (BKP) | RSTP only | Backup designated port on the same shared segment (hub scenario). Rarely seen in modern networks. |
⏱ Convergence times: 802.1D STP = up to 50s (20s max-age + 15s listen + 15s learn). RSTP = 1–2s via rapid transition and proposal/agreement. MSTP = RSTP convergence per instance. PortFast / Edge port: skips listening+learning, goes straight to forwarding — only use on access ports connected to end devices, never on switch-to-switch links.
inter-VLAN routing
| method | how it works | pros | cons |
|---|---|---|---|
| Router-on-a-Stick | Router with sub-interfaces on a trunk port. Each sub-interface = one VLAN with 802.1Q encapsulation and a default gateway IP. | Simple, one physical port. Works with any router. | Single physical uplink = bottleneck. Router CPU handles all routing. Latency slightly higher. |
| L3 Switch (SVI) | Layer 3 switch with Switch Virtual Interfaces (SVIs) — interface vlan X with IP address per VLAN. Routing happens in hardware (ASIC/TCAM). | Wire-speed routing. No external router needed. Lower latency. | Requires L3 license on some platforms. More complex config. |
| Separate physical router | Dedicated router with a physical port in each VLAN — each port in a different subnet. | Full isolation, dedicated hardware. | Requires one router port per VLAN. Expensive and inflexible at scale. |
📌 SVI gotcha: An SVI only comes up if at least one port in that VLAN is active and in forwarding state. An SVI with no active ports stays down even if the VLAN exists. Add
no autostate (Cisco) to keep the SVI up regardless of member port states — useful for management VLANs.
port security & L2 protection features
| feature | what it does | violation actions / notes |
|---|---|---|
| Port Security | ||
| Max MACs | Limits number of MAC addresses allowed on a port. Default = 1. | Shutdown — err-disables port, sends SNMP trap (default). Restrict — drops violating frames, increments counter. Protect — drops silently, no log. |
| Sticky MAC | Dynamically learns MACs and saves to running config. Survives reboot if config saved. Useful for locking known devices without pre-configuring MACs. | Configured via switchport port-security mac-address sticky. Review learned MACs with show port-security address. |
| Storm Control | ||
| Storm control | Rate-limits broadcast, multicast, or unknown-unicast traffic per port. Threshold set as % of bandwidth or pps. Prevents broadcast storms from overwhelming the network. | Actions: shutdown (err-disable) or trap (SNMP only). Typical threshold: 20% for broadcast, 10% for unknown unicast. |
| BPDU Guard & Root Guard | ||
| BPDU Guard | Err-disables a PortFast/edge port if a BPDU is received. Prevents rogue switches from connecting to access ports and influencing STP topology. | Enable globally: spanning-tree portfast bpduguard default. Enable per-port: spanning-tree bpduguard enable. Recovery: errdisable recovery cause bpduguard. |
| Root Guard | Prevents a port from becoming a root port — if a superior BPDU arrives, port goes to root-inconsistent (blocking) state. Protects root bridge placement. | Applied on ports facing untrusted switches or downstream switches that should never become root. Does not err-disable — recovers automatically when superior BPDUs stop. |
| Loop Guard | Prevents unidirectional link failures from causing a non-designated port to incorrectly transition to forwarding (if BPDUs stop being received). | Moves port to loop-inconsistent (blocking) instead of forwarding when BPDUs are lost. Recovers automatically. Complement to Root Guard — use on root and alternate ports. |
switching troubleshooting quick reference
| symptom | likely cause | check / fix |
|---|---|---|
| Port stuck err-disabled | BPDU guard, port-security, storm control, UDLD, or loopback detected | show interfaces status err-disabled — reason column tells you why. Fix root cause, then shutdown / no shutdown or configure errdisable recovery. |
| Hosts in same VLAN can't communicate | VLAN not active, STP blocking, port mismatch | Verify VLAN exists and is active: show vlan brief. Check STP state: show spanning-tree vlan X. Verify both ports are in same VLAN: show interfaces trunk / show interfaces switchport. |
| Trunk not passing a VLAN | VLAN pruned, not allowed, or not active on both sides | show interfaces trunk — check "VLANs allowed and active in management domain" column. VLAN must be created, active, and in allowed list on both ends. |
| EtherChannel won't form | Mode mismatch, config mismatch on member ports | show etherchannel summary — look for (D) standalone. Check speed/duplex, VLAN config, STP settings all match. LACP requires at least one side active. |
| STP topology keeps changing | TC (Topology Change) storm, flapping port | show spanning-tree detail — look for "topology changes" counter and "last change occurred". Enable BPDU guard on access ports. Check for flapping uplinks or rogue switches. |
| High CPU on switch | Broadcast storm, STP instability, CAM overflow, process-switched traffic | Check show processes cpu sorted. Enable storm control. Verify STP stable. Check CAM table size: show mac address-table count. Identify flooded VLANs. |
| Native VLAN mismatch warning | Native VLAN differs on trunk endpoints | CDP/LLDP logs: "Native VLAN mismatch discovered on X." Match native VLAN on both sides or set native VLAN to a dedicated unused VLAN on all trunks. |
| MAC flapping log messages | Loop in the network, dual-homed device, NIC teaming issue | MAC seen on multiple ports = loop or bonding misconfiguration. show mac address-table — if a MAC appears on 2+ ports, trace from each port. Check EtherChannel consistency and STP topology. |
🔍 Essential show commands:
show vlan brief · show interfaces trunk · show interfaces switchport · show mac address-table · show spanning-tree [vlan X] · show etherchannel summary · show interfaces status · show interfaces status err-disabledquick reference
254
/24 hosts
2
/30 hosts
65,534
/16 hosts
1
/32 host
Usable hosts = 2^(32 − prefix) − 2 (network + broadcast reserved); /31 = 2 (point-to-point, RFC 3021), /32 = single host. Block size = 256 − mask octet.
CIDR subnet mask reference — /0 to /32
| prefix | subnet mask | wildcard | total hosts | usable hosts | binary mask ■ network ■ host | common use |
|---|---|---|---|---|---|---|
| /0 | 0.0.0.0 | 255.255.255.255 | 4295.0M | 4295.0M | 00000000.00000000.00000000.00000000 | entire internet |
| /1 | 128.0.0.0 | 127.255.255.255 | 2147.5M | 2147.5M | 10000000.00000000.00000000.00000000 | |
| /2 | 192.0.0.0 | 63.255.255.255 | 1073.7M | 1073.7M | 11000000.00000000.00000000.00000000 | |
| /3 | 224.0.0.0 | 31.255.255.255 | 536.9M | 536.9M | 11100000.00000000.00000000.00000000 | |
| /4 | 240.0.0.0 | 15.255.255.255 | 268.4M | 268.4M | 11110000.00000000.00000000.00000000 | |
| /5 | 248.0.0.0 | 7.255.255.255 | 134.2M | 134.2M | 11111000.00000000.00000000.00000000 | |
| /6 | 252.0.0.0 | 3.255.255.255 | 67.1M | 67.1M | 11111100.00000000.00000000.00000000 | |
| /7 | 254.0.0.0 | 1.255.255.255 | 33.6M | 33.6M | 11111110.00000000.00000000.00000000 | |
| /8 | 255.0.0.0 | 0.255.255.255 | 16.8M | 16.8M | 11111111.00000000.00000000.00000000 | class A |
| /9 | 255.128.0.0 | 0.127.255.255 | 8.4M | 8.4M | 11111111.10000000.00000000.00000000 | |
| /10 | 255.192.0.0 | 0.63.255.255 | 4.2M | 4.2M | 11111111.11000000.00000000.00000000 | |
| /11 | 255.224.0.0 | 0.31.255.255 | 2.1M | 2.1M | 11111111.11100000.00000000.00000000 | |
| /12 | 255.240.0.0 | 0.15.255.255 | 1.0M | 1.0M | 11111111.11110000.00000000.00000000 | |
| /13 | 255.248.0.0 | 0.7.255.255 | 524.3K | 524.3K | 11111111.11111000.00000000.00000000 | |
| /14 | 255.252.0.0 | 0.3.255.255 | 262.1K | 262.1K | 11111111.11111100.00000000.00000000 | |
| /15 | 255.254.0.0 | 0.1.255.255 | 131.1K | 131.1K | 11111111.11111110.00000000.00000000 | |
| /16 | 255.255.0.0 | 0.0.255.255 | 65.5K | 65.5K | 11111111.11111111.00000000.00000000 | class B (65K hosts) |
| /17 | 255.255.128.0 | 0.0.127.255 | 32.8K | 32.8K | 11111111.11111111.10000000.00000000 | |
| /18 | 255.255.192.0 | 0.0.63.255 | 16.4K | 16.4K | 11111111.11111111.11000000.00000000 | |
| /19 | 255.255.224.0 | 0.0.31.255 | 8.2K | 8.2K | 11111111.11111111.11100000.00000000 | |
| /20 | 255.255.240.0 | 0.0.15.255 | 4.1K | 4.1K | 11111111.11111111.11110000.00000000 | 4K hosts |
| /21 | 255.255.248.0 | 0.0.7.255 | 2.0K | 2.0K | 11111111.11111111.11111000.00000000 | 2K hosts |
| /22 | 255.255.252.0 | 0.0.3.255 | 1.0K | 1.0K | 11111111.11111111.11111100.00000000 | 1K hosts |
| /23 | 255.255.254.0 | 0.0.1.255 | 512 | 510 | 11111111.11111111.11111110.00000000 | 512 hosts (2 x /24) |
| /24 | 255.255.255.0 | 0.0.0.255 | 256 | 254 | 11111111.11111111.11111111.00000000 | class C — most common |
| /25 | 255.255.255.128 | 0.0.0.127 | 128 | 126 | 11111111.11111111.11111111.10000000 | 2 x /25 from /24 |
| /26 | 255.255.255.192 | 0.0.0.63 | 64 | 62 | 11111111.11111111.11111111.11000000 | 4 x /26 from /24 |
| /27 | 255.255.255.224 | 0.0.0.31 | 32 | 30 | 11111111.11111111.11111111.11100000 | 8 x /27 (30 hosts) |
| /28 | 255.255.255.240 | 0.0.0.15 | 16 | 14 | 11111111.11111111.11111111.11110000 | 16 x /28 (14 hosts) |
| /29 | 255.255.255.248 | 0.0.0.7 | 8 | 6 | 11111111.11111111.11111111.11111000 | 8 hosts — point-to-point+ |
| /30 | 255.255.255.252 | 0.0.0.3 | 4 | 2 | 11111111.11111111.11111111.11111100 | 4 hosts — p2p links |
| /31 | 255.255.255.254 | 0.0.0.1 | 2 | — | 11111111.11111111.11111111.11111110 | 2 hosts — RFC3021 p2p |
| /32 | 255.255.255.255 | 0.0.0.0 | 1 | — | 11111111.11111111.11111111.11111111 | single host / loopback |
💡 Usable hosts = total − 2 (network address + broadcast). /31 is a special case per RFC 3021 — used for point-to-point links with no network/broadcast waste. /32 is a host route (single IP). /24 = 255.255.255.0 is the most common subnet in enterprise networks.
quick reference
EAP-TLS
cert/cert
PEAP
tunnelled
1812 / 1813
RADIUS
EAPOL
transport
802.1X port-based access control: supplicant → authenticator → RADIUS server. EAP-TLS = mutual certs (strongest); PEAP/EAP-TTLS tunnel an inner method (MSCHAPv2). Success → dynamic VLAN/role.
802.1X architecture — supplicant · authenticator · RADIUS
supplicant
Client Device
The end device requesting network access. Runs an EAP supplicant (built into Windows, macOS, iOS, Android). Presents credentials or certificates to the authenticator.
Examples: Windows native supplicant, Cisco AnyConnect NAM, SecureW2, Jamf Connect
Examples: Windows native supplicant, Cisco AnyConnect NAM, SecureW2, Jamf Connect
authenticator
AP or Switch
The network access device that enforces 802.1X. It does NOT validate credentials itself — it acts as a relay between supplicant and RADIUS. Controls port access via PAE (Port Access Entity).
Examples: Aruba AP/switch, Cisco WLC/switch, Ruckus AP, Juniper EX
Examples: Aruba AP/switch, Cisco WLC/switch, Ruckus AP, Juniper EX
authentication server
RADIUS Server
Validates credentials, certificates, or SIM. Returns Access-Accept or Access-Reject. Can return VLAN, ACL, and role assignments via RADIUS attributes (VSAs).
Examples: Aruba ClearPass, Cisco ISE, Microsoft NPS, FreeRADIUS, Jumpcloud
Examples: Aruba ClearPass, Cisco ISE, Microsoft NPS, FreeRADIUS, Jumpcloud
802.1X AUTHENTICATION FLOW
Supplicant ──────────────────────────────── Authenticator (AP/Switch) ────────────────── RADIUS Server
──── EAPOL-Start ────────────────────────────►
◄─── EAP-Request/Identity ────────
──── EAP-Response/Identity ─────────────────► ─── RADIUS Access-Request ──────────────────────►
◄─── RADIUS Access-Challenge ─
◄─── EAP-Request (method) ────────
... EAP method exchange (TLS tunnel / challenge-response) ...
──── EAP-Response ───────────────────────────► ─── RADIUS Access-Request ──────────────────────►
──── RADIUS Access-Accept ────►
◄─── EAP-Success ───────────────── (+ optional: VLAN, ACL, role via VSAs)
◄─── 802.1X port opens / network access granted ────────────────────
The authenticator uses RADIUS (UDP 1812 for auth, 1813 for accounting) to communicate with the RADIUS server. It never sees the actual credentials — it only relays EAP messages. This separation is what makes 802.1X secure even on untrusted network equipment.
EAP method comparison
| method | inner auth | outer tunnel | client cert req? | server cert req? | identity protection | complexity | common use |
|---|---|---|---|---|---|---|---|
| PEAP Protected EAP |
MSCHAPv2 (usually) | TLS tunnel | ✗ not required | ✓ required | ✓ outer identity anonymous | Low | Most common enterprise Wi-Fi. Username/password via AD/LDAP. Windows native. |
| EAP-TLS TLS mutual auth |
Certificate (no inner) | TLS mutual auth | ✓ required (client PKI) | ✓ required | ✓ strongest protection | High | Highest security. Requires PKI for every device. Passwordless. MDM/SCEP typically used. |
| EAP-TTLS Tunneled TLS |
PAP, CHAP, MSCHAPv2, or others | TLS tunnel | ✗ not required | ✓ required | ✓ outer identity anonymous | Medium | More flexible inner auth than PEAP. Common on Linux/Android. Less Windows-native support. |
| EAP-FAST Flexible Auth via Secure Tunneling |
MSCHAPv2, GTC, or TLS | PAC (Protected Access Credential) | ✗ not required | ✓ optional (PAC provisioning) | ✓ PAC-based tunnel | Medium | Cisco proprietary alternative to PEAP. Used where cert infrastructure isn't available. Less common. |
| EAP-SIM SIM card auth |
SIM GSM challenge-response | None (SIM provides security) | ✗ uses SIM instead | ✗ not required | ⚠ limited (IMSI exposed) | Low (for carrier) | Carrier Wi-Fi offload. Hotspot 2.0 / Passpoint. Seamless auth using SIM credentials. |
| EAP-AKA Auth & Key Agreement |
USIM AKA challenge-response (3G/4G) | None | ✗ uses USIM | ✗ not required | ✓ improved vs EAP-SIM | Low (for carrier) | Evolved SIM auth for UMTS/LTE. More secure than EAP-SIM. Used in carrier Wi-Fi offload. |
PEAP-MSCHAPv2 is the most deployed enterprise EAP method due to its low client-side complexity (no client cert needed). EAP-TLS is the gold standard for security but requires a full PKI with certificate enrollment for every device — typically via SCEP/ACME through an MDM like Jamf, Intune, or ClearPass Onboard.
certificate requirements by EAP method
| EAP method | RADIUS server cert | client cert | CA cert (on client) | deployment complexity | notes |
|---|---|---|---|---|---|
| PEAP-MSCHAPv2 | ✓ required | ✗ not needed | ⚠ should validate | Low — creds only | Clients MUST validate server cert to prevent MITM. Many deployments skip this — a critical security gap. |
| EAP-TLS | ✓ required | ✓ required (per device) | ✓ required | High — full PKI needed | Every device needs a unique cert. Use MDM + SCEP/ACME for automated enrollment. Revocation via OCSP/CRL. |
| EAP-TTLS | ✓ required | ✗ not needed | ⚠ should validate | Medium | Same cert risks as PEAP if server cert not validated. Better inner auth flexibility. |
| EAP-FAST | ⚠ optional | ✗ not needed | ⚠ depends on provisioning | Medium | Anonymous PAC provisioning (phase 0) can be vulnerable. Use authenticated PAC provisioning where possible. |
| EAP-SIM / EAP-AKA | ✗ not used | ✗ not used | ✗ not used | Low (carrier managed) | Auth is handled by SIM / USIM cryptography. No certificates involved — carrier PKI handles security. |
⚠ PEAP without server cert validation is one of the most common Wi-Fi security misconfigurations. Without it, any rogue AP with a self-signed cert can perform a man-in-the-middle attack and capture MSCHAPv2 hashes (which can be cracked offline). Always configure trusted CA and server name validation on supplicants.
auth flow — how each method works
| method | phase 1 (outer) | phase 2 (inner) | what's protected | credential type |
|---|---|---|---|---|
| PEAP | TLS tunnel established using server cert. Outer identity = anonymous@domain | MSCHAPv2 challenge-response with AD username/password inside the tunnel | Inner identity + credentials hidden | Username + password (AD/LDAP) |
| EAP-TLS | Mutual TLS handshake — both client and server present certificates | No phase 2 — certificate IS the credential | Full mutual auth, no password ever sent | X.509 client certificate (device or user) |
| EAP-TTLS | TLS tunnel using server cert. Anonymous outer identity. | Any inner method: PAP, CHAP, MSCHAPv2, or even another EAP | Inner identity + credentials hidden | Username + password (flexible inner methods) |
| EAP-FAST | Phase 0: PAC (Protected Access Credential) provisioning. Phase 1: PAC establishes tunnel | MSCHAPv2, GTC (token), or EAP-TLS inside tunnel | Depends on PAC provisioning security | PAC file + inner credentials |
| EAP-SIM | No tunnel. RADIUS sends GSM triplets (RAND, SRES, Kc) from HLR/HSS | No phase 2 — SIM card performs RAND challenge-response | IMSI can be exposed in early exchanges | SIM card (GSM A3/A8 algorithm) |
PEAP and EAP-TTLS both use a TLS tunnel to protect inner credentials — the key difference is PEAP is primarily designed for MSCHAPv2 while EAP-TTLS supports any inner method including PAP (plaintext over the encrypted tunnel). EAP-TLS has no inner phase — the mutual certificate exchange is the entire authentication.
AAA — authentication · authorization · accounting
authentication
Who are you?
Verifies the identity of a user or device before granting any access. The supplicant presents credentials — password, certificate, SIM, or token — and the authentication server validates them.
Methods: Password (MSCHAPv2), Certificate (EAP-TLS), SIM (EAP-SIM), Token (OTP/GTC)
Protocols: RADIUS (UDP 1812), TACACS+ (TCP 49), Diameter (SCTP/TCP 3868)
Methods: Password (MSCHAPv2), Certificate (EAP-TLS), SIM (EAP-SIM), Token (OTP/GTC)
Protocols: RADIUS (UDP 1812), TACACS+ (TCP 49), Diameter (SCTP/TCP 3868)
authorization
What can you do?
Determines what network resources and permissions a successfully authenticated identity receives. Applied after auth succeeds, before network access is granted.
Outputs: VLAN assignment, ACL/dACL, downloadable policy, QoS profile, role/group, session timeout, bandwidth limit
Mechanisms: RADIUS attributes (VSAs), ClearPass roles, ISE authorization profiles, CoA (Change of Authorization)
Outputs: VLAN assignment, ACL/dACL, downloadable policy, QoS profile, role/group, session timeout, bandwidth limit
Mechanisms: RADIUS attributes (VSAs), ClearPass roles, ISE authorization profiles, CoA (Change of Authorization)
accounting
What did you do?
Records session activity — when a user connected, disconnected, how much data was transferred, which device/port was used. Used for auditing, billing, and troubleshooting.
Records: Session start/stop, bytes in/out, session duration, NAS IP, calling-station-ID (MAC), framed-IP
Protocol: RADIUS Accounting (UDP 1813), TACACS+ accounting (TCP 49)
Records: Session start/stop, bytes in/out, session duration, NAS IP, calling-station-ID (MAC), framed-IP
Protocol: RADIUS Accounting (UDP 1813), TACACS+ accounting (TCP 49)
AAA protocols comparison — RADIUS · TACACS+ · Diameter
| feature | RADIUS | TACACS+ | Diameter |
|---|---|---|---|
| Transport | UDP 1812 (auth) / 1813 (acct) | TCP 49 (reliable) | TCP / SCTP 3868 |
| Encryption | Password only (MD5) | Full packet body encrypted | TLS / DTLS |
| AAA separation | Auth + Authz combined | Auth / Authz / Acct fully separate | Fully modular |
| Protocol origin | Open standard (RFC 2865/2866) | Cisco proprietary (extended) | IETF RFC 6733 (RADIUS successor) |
| Primary use | Network access (802.1X, VPN, Wi-Fi) | Device administration (CLI, SSH, enable) | Mobile/carrier (LTE, IMS, Hotspot 2.0) |
| Command authorization | ✗ not supported | ✓ per-command authorization | ✗ not applicable |
| Attribute extensibility | VSAs (vendor-specific attributes) | Flexible — any attribute | AVPs (attribute-value pairs) — fully extensible |
| Change of Authorization | ✓ RFC 5176 (CoA / Disconnect) | ✗ not standard | ✓ native re-auth |
| Failover | Client retries to backup server | Client retries to backup server | Native peer failover |
| Common servers | ClearPass, ISE, NPS, FreeRADIUS | ClearPass, ISE, ACS (legacy), TACACS Pro | Diameter base on carrier gear |
RADIUS vs TACACS+: Use RADIUS for network access control (802.1X, VPN, Wi-Fi auth). Use TACACS+ for device administration — it encrypts the entire packet and supports per-command authorization, making it significantly better for auditing SSH/CLI access to switches and routers. Many enterprises run both: RADIUS for user/device NAC, TACACS+ for admin access.
common RADIUS attributes for network access
| attribute | type # | direction | value / example | use |
|---|---|---|---|---|
| User-Name | 1 | Request | [email protected] | Identity sent to RADIUS. For 802.1X, outer identity is often anonymous@domain. |
| Framed-IP-Address | 8 | Accept | 192.168.10.50 | Assign specific IP to user (used with some VPN/PPP scenarios). |
| Framed-MTU | 12 | Accept | 1400 | Set MTU for the session. |
| Session-Timeout | 27 | Accept | 28800 (seconds) | Force re-authentication after N seconds. Common: 8h = 28800. |
| Idle-Timeout | 28 | Accept | 600 | Disconnect idle sessions after N seconds. |
| Calling-Station-Id | 31 | Request | AA-BB-CC-DD-EE-FF | Client MAC address. Used by ClearPass/ISE for device profiling and policy lookup. |
| NAS-IP-Address | 4 | Request | 10.0.0.1 | IP of the AP or switch sending the RADIUS request. |
| NAS-Port-Type | 61 | Request | 19 = Wireless-802.11 | Access method. 15 = Ethernet, 19 = Wireless. |
| Tunnel-Type | 64 | Accept | 13 = VLAN | Used with VLAN assignment. Must be set to 13 (VLAN) for dynamic VLAN. |
| Tunnel-Medium-Type | 65 | Accept | 6 = 802 | Always 6 (IEEE 802) for VLAN assignment. |
| Tunnel-Private-Group-Id | 81 | Accept | "100" (VLAN ID) | The VLAN ID to assign. All three Tunnel-* attributes must be present for dynamic VLAN to work. |
| Reply-Message | 18 | Reject/Challenge | "Invalid credentials" | Human-readable message returned on failure. Useful in RADIUS logs. |
Dynamic VLAN assignment requires three RADIUS attributes returned in Access-Accept:
Tunnel-Type = VLAN(13), Tunnel-Medium-Type = IEEE-802(6), and Tunnel-Private-Group-Id = "VLAN_ID". Missing any one of these will cause the AP/switch to ignore the VLAN assignment and fall back to the default VLAN.
change of authorization (CoA) — RFC 5176
| CoA type | RADIUS code | direction | what it does | common use case |
|---|---|---|---|---|
| CoA-Request | 43 | RADIUS server → NAS | Changes session attributes mid-session without disconnect | Push new VLAN/ACL/role after posture check completes |
| CoA-ACK | 44 | NAS → RADIUS server | CoA accepted and applied | Confirms the NAS applied the new policy |
| CoA-NAK | 45 | NAS → RADIUS server | CoA rejected | Session not found, attribute unsupported, or NAS error |
| Disconnect-Request (PoD) | 40 | RADIUS server → NAS | Forcibly disconnects a session (Packet of Death) | Quarantine a compromised device, force re-auth after password change |
| Disconnect-ACK | 41 | NAS → RADIUS server | Session disconnected successfully | Device will need to re-authenticate to regain access |
| Disconnect-NAK | 42 | NAS → RADIUS server | Disconnect failed | Session not found or NAS doesn't support PoD |
CoA is initiated by the RADIUS server (ClearPass/ISE) toward the NAS (AP/switch) on UDP port 3799. The NAS must have CoA enabled and the RADIUS server IP whitelisted. CoA is used in posture-based NAC workflows — device connects to a quarantine VLAN, passes health check, CoA pushes the production VLAN without disconnecting the session.
quick reference
1812
RADIUS auth
1813
accounting
3799
CoA
802.1X / MAB
methods
Enforcement order typically 802.1X → MAC-auth-bypass → web-auth. CoA (Change of Authorization, UDP 3799) lets the server re-authorize or bounce a session live. Result = dynamic VLAN / dACL / role.
NAC authentication decision flow
CLIENT CONNECTS TO PORT / SSID
▶Device connects — authenticator sends EAP-Request/Identity
│
◆│
802.1X supplicant present?
YES → EAP exchange begins → RADIUS validates → Access-Accept / Reject
NO → EAP timeout → MAB triggered (if configured)
NO → EAP timeout → MAB triggered (if configured)
│ (MAB path)
◆
RADIUS receives MAB request (MAC as username/password)
MAC known → Access-Accept + policy (VLAN/role/ACL)
MAC unknown → Reject or redirect to guest/onboarding VLAN
MAC unknown → Reject or redirect to guest/onboarding VLAN
│ (posture path)
◆
Posture check required? (ClearPass OnGuard / ISE agent)
PASS → CoA pushes production VLAN/role — no disconnect
FAIL → Stays in quarantine VLAN / remediation redirect
NO AGENT → Policy decision: trust level, profiling, or quarantine
FAIL → Stays in quarantine VLAN / remediation redirect
NO AGENT → Policy decision: trust level, profiling, or quarantine
802.1X
EAP Authentication
Strongest method. Supplicant required on device. Identity verified by RADIUS via EAP-TLS, PEAP, or EAP-TTLS. Supports per-user/device policy enforcement via VSAs.
Best for: Corp-managed endpoints, BYOD with MDM enrollment
Best for: Corp-managed endpoints, BYOD with MDM enrollment
MAB
MAC Auth Bypass
Fallback for devices without 802.1X (IoT, printers, cameras). MAC address sent as RADIUS username AND password. Inherently weak — MAC can be spoofed.
Best for: IoT/OT devices, printers, IP phones with no supplicant
Best for: IoT/OT devices, printers, IP phones with no supplicant
Captive Portal
Web Auth
Browser-based credential entry. No supplicant needed. Used for guest access, BYOD onboarding, or as fallback after MAB. Credentials typically validated against LDAP or a sponsor portal.
Best for: Guest Wi-Fi, contractor access, BYOD first-time enrollment
Best for: Guest Wi-Fi, contractor access, BYOD first-time enrollment
MAC auth bypass (MAB) — mechanics & risks
| aspect | detail | notes |
|---|---|---|
| RADIUS request format | Username = MAC (no colons, lowercase) Password = same MAC string | Format varies by vendor — Aruba uses lowercase no-delimiter. Cisco uses lowercase colon-separated. Verify format matches RADIUS policy. |
| Trigger condition | EAP timeout (typically 3 retries × ~30s) or explicit port config | On Aruba: aaa authentication mac-auth. On Cisco: mab under interface. |
| Security risk | MAC spoofing trivial | Attacker clones a known-good MAC and bypasses NAC. Mitigate with profiling (DHCP fingerprint, HTTP UA, CDP/LLDP) to verify device type matches expected MAC OUI. |
| Profiling integration | ClearPass/ISE correlates DHCP, HTTP, SNMP, NMAP data | Profile confirms "this MAC claims to be a Cisco IP phone, fingerprint matches." Adds confidence to MAB decisions. |
| Typical policy outcome | Restricted VLAN, limited ACL, or quarantine until profiled | Start least-privilege, CoA to production VLAN after profiling confirms device type. |
RADIUS VSA enforcement — VLAN, role, ACL assignment
| attribute | RADIUS attrs | Aruba (ClearPass) | Cisco (ISE) | what it controls |
|---|---|---|---|---|
| VLAN Assignment | Tunnel-Type=VLAN(13) Tunnel-Medium-Type=802(6) Tunnel-Private-Group-ID=<VLAN-ID> |
Standard RFC 3580 attrs | Standard RFC 3580 attrs | Dynamically assigns client to a VLAN without static port config. Most common NAC outcome. |
| User Role (Aruba) | VSA 1 — Aruba-User-Role | Aruba-User-Role = "employee" |
N/A (ISE uses SGT) | Assigns a named firewall role on Aruba APs/switches. Role defines per-user ACL, bandwidth limits, and captive portal policy. |
| Downloadable ACL | Filter-Id or Cisco-AVPairip:inacl#N=... |
Aruba-User-Role maps to named ACL | DACL (downloadable ACL) pushed via Cisco-AVPair | Per-session ACL pushed to the NAS. More granular than VLAN alone — permit/deny specific traffic for this session. |
| Security Group Tag (Cisco) | Cisco-AVPair: cts:security-group-tag=<N> |
N/A | ISE → TrustSec SGT | Tags the session with a scalable group ID. SXP or inline tagging propagates the SGT through the network for policy enforcement at egress. |
| Session Timeout | Session-Timeout (attr 27) Termination-Action (attr 29) |
Standard | Standard | Forces re-authentication after N seconds. Termination-Action=RADIUS-Request re-auths silently; =Default disconnects. |
| Bandwidth Limit | VSA — vendor specific | Aruba-User-Role maps to bandwidth contract | Cisco-AVPair: ip:sub-qos-policy-in= |
Per-user bandwidth shaping. Common for guest portals — limit guests to 5 Mbps down/up regardless of SSID capacity. |
VSAs are vendor-specific — always load the correct RADIUS dictionary on your RADIUS server. Aruba VSAs use PEN 14823. Cisco VSAs use PEN 9. Mismatched dictionary = attributes silently ignored = no VLAN/role applied = client gets default (often no access or unrestricted).
CoA / posture workflow — quarantine → production
POSTURE-BASED NAC FLOW (ClearPass / ISE)
1. Device authenticates → Access-Accept with quarantine VLAN + redirect ACL → HTTP redirected to posture agent download URL
2. OnGuard/ISE agent runs → checks AV status, OS patch level, disk encryption, corp cert presence
3a. PASS → agent reports to RADIUS → CoA-Request sent to NAS → new VLAN/role pushed → session updated without disconnect
3b. FAIL → stays in quarantine → remediation page shown (patch link, AV download) → agent re-checks on fix
3c. NO AGENT → timeout → policy decision: limited trust, restrict to quarantine, or CoA to guest role
CoA port: UDP 3799 (NAS must have RADIUS server IP whitelisted + CoA enabled)
Common posture checks
✓ Antivirus — installed, running, definitions current
✓ OS patch level — Windows Update / macOS patch
✓ Disk encryption — BitLocker / FileVault enabled
✓ Corporate cert — machine cert from internal CA present
✓ MDM enrollment — device registered in Intune/Jamf
✓ Firewall — host firewall enabled
✓ Prohibited apps — no unauthorized VPN or P2P software
Aruba ClearPass policy model
Service — matches inbound RADIUS request (by NAS IP, SSID, called-station)
Auth Source — AD, LDAP, local DB, cert, or MAC cache
Auth Method — PEAP, EAP-TLS, MAB, WebAuth
Role Mapping — maps identity attributes → ClearPass role
Enforcement — role + posture → RADIUS response (VLAN, role, ACL)
Profiler — DHCP, HTTP, SNMP, NMAP → device fingerprint
common NAC failure modes & debug
| symptom | likely cause | where to look | fix |
|---|---|---|---|
| Access-Reject (error 9002) | EAP method mismatch, wrong inner auth, or user not found in auth source | ClearPass Access Tracker → Auth details tab → error code | Check service matched, auth source reachable, credentials correct. Verify supplicant EAP method matches server policy. |
| Client stuck in quarantine VLAN | CoA not reaching NAS, NAS CoA port blocked, or wrong NAS secret | ClearPass → CoA log; NAS debug radius CoA | Verify UDP 3799 open from RADIUS to NAS. NAS must list RADIUS server as CoA source. Check RADIUS shared secret matches. |
| VLAN not assigned (gets default VLAN) | Tunnel attributes missing or wrong format; NAS ignoring VSAs | ClearPass → Enforcement tab → verify profile sends Tunnel attrs; packet capture RADIUS response | Confirm Tunnel-Type=13, Tunnel-Medium-Type=6, Tunnel-Private-Group-ID=VLAN-ID. Check NAS is configured to honour dynamic VLAN. |
| MAB fails for known device | MAC format mismatch between NAS and RADIUS policy | ClearPass Access Tracker → Request username field | Check MAC format sent (Aruba: aabbccddeeff, Cisco: aa:bb:cc:dd:ee:ff or aa-bb-cc-dd-ee-ff). Match RADIUS policy to NAS format. |
| Server cert validation fails (PEAP) | Client doesn't trust RADIUS server cert CA; wrong CA pushed via MDM | Supplicant event log; Wireshark — TLS alert handshake_failure | Push correct CA cert via MDM profile. Or configure supplicant to trust specific server cert CN. Never disable cert validation in production. |
| Intermittent re-auth disconnects | Session-Timeout too short; PMK caching not enabled on wireless | AP event log; RADIUS accounting log for session duration | Increase Session-Timeout (3600–86400s for corp devices). Enable PMK/OKC caching on APs to allow silent re-auth without disassociation. |
guest & BYOD onboarding patterns
Guest — Self-Service Portal
1. Guest associates to open/OWE SSID → MAB → captive redirect
2. Guest enters name/email or receives SMS OTP
3. Sponsor approval (optional) — email link to sponsor
4. CoA → restricted guest VLAN (internet only, no internal access)
5. Session expires after defined guest duration (4h / 24h)
Aruba: ClearPass Guest portal. Cisco: ISE Guest portal or Meraki splash.
BYOD — Certificate Enrollment
1. BYOD user connects → PEAP with AD creds → limited VLAN
2. Redirect to onboarding portal (ClearPass Onboard / ISE)
3. Device cert issued via SCEP/ACME from internal CA
4. MDM profile pushed (Wi-Fi config, cert, VPN)
5. Disconnect → reconnect → EAP-TLS with device cert → full access
Aruba: ClearPass Onboard. Cisco: ISE BYOD portal. SecureW2 / Jamf also common.
Dual-SSID BYOD (separate onboarding SSID) is cleaner than single-SSID redirect — avoids captive portal issues with HSTS and modern OS captive detection. The onboarding SSID is open/OWE; post-enrollment clients move to the WPA2/3-Enterprise SSID with their device cert.
configuration
ACL settings
ACL name
vendor
add rule
quick patterns:
permit HTTPS
permit SSH
permit DNS
permit ICMP
deny all
permit RADIUS
block Telnet
RFC1918 →any
test a packet
rules (7)
⟳ sample
✕ clear all
permittcp10.0.0.0/8 → any:443HTTPS outbound✕
permittcp10.0.0.0/8 → any:22SSH to jumphost✕
permitudp10.0.0.0/8 → 192.168.1.10:53DNS to resolver✕
permitudp10.0.0.0/8 → 10.10.10.1:1812RADIUS auth✕
permiticmp10.0.0.0/8 → anyICMP ping✕
denytcpany → any:23block Telnet✕
denyipany → anyexplicit deny all✕
▼ implicit deny ip any any — always applied, not shown in CLI unless added explicitly
generated CLI
⎘ copy
ip access-list extended CORP_ACL
remark HTTPS outbound
permit tcp 10.0.0.0 0.255.255.255 any eq 443
remark SSH to jumphost
permit tcp 10.0.0.0 0.255.255.255 any eq 22
remark DNS to resolver
permit udp 10.0.0.0 0.255.255.255 host 192.168.1.10 eq 53
remark RADIUS auth
permit udp 10.0.0.0 0.255.255.255 host 10.10.10.1 eq 1812
remark ICMP ping
permit icmp 10.0.0.0 0.255.255.255 any
remark block Telnet
deny tcp any any eq 23
remark explicit deny all
deny ip any any
! implicit: deny ip any any
ACL reference — wildcard masks & syntax
wildcard mask quick reference
| prefix | subnet mask | wildcard | hosts |
|---|---|---|---|
| /32 | 255.255.255.255 | 0.0.0.0 | 1 (host) |
| /30 | 255.255.255.252 | 0.0.0.3 | 2 |
| /29 | 255.255.255.248 | 0.0.0.7 | 6 |
| /28 | 255.255.255.240 | 0.0.0.15 | 14 |
| /27 | 255.255.255.224 | 0.0.0.31 | 30 |
| /24 | 255.255.255.0 | 0.0.0.255 | 254 |
| /23 | 255.255.254.0 | 0.0.1.255 | 510 |
| /22 | 255.255.252.0 | 0.0.3.255 | 1022 |
| /16 | 255.255.0.0 | 0.0.255.255 | 65534 |
| /8 | 255.0.0.0 | 0.255.255.255 | 16M |
| any | 0.0.0.0 | 255.255.255.255 | all |
common ACL patterns
Permit established TCP —
permit tcp any any established — allows return traffic without full stateful firewallBlock RFC1918 from WAN — deny private ranges inbound on internet-facing interface
RADIUS traffic — permit UDP 1812/1813 from NAS to RADIUS server only
Management ACL — permit SSH/HTTPS from jump host only, deny any any at end
Guest isolation — deny ip guest-subnet internal-subnets, permit ip any any (internet only)
CoA — permit UDP 3799 from RADIUS server to NAS (often forgotten)
quick reference
default-deny
base rule
stateful
conn tracking
zones
trust model
L7 / NGFW
app-aware
Stateful firewalls track connections and auto-allow established/related return traffic. Rules evaluate top-down — first match wins, implicit deny at the end. NGFW adds L7 app-ID, IPS, and TLS inspection.
firewall types — stateless · stateful · NGFW · proxy
| type | inspects | state tracking | use case |
|---|---|---|---|
| Packet filter (stateless) | L3/L4 headers only — src/dst IP, protocol, port, flags | None | Router ACLs, simple perimeter filtering. Fast, low overhead. No return traffic tracking — must explicitly permit return flows. Easily spoofed. |
| Stateful inspection | L3/L4 + connection state table (TCP FSM, UDP pseudo-state, ICMP) | Connection table | Traditional firewalls (ASA, iptables, pfSense). Permits return traffic automatically by tracking established connections. Blocks unsolicited inbound. |
| Application layer (proxy) | L7 — full payload inspection, protocol compliance | Full session proxy | Web proxies, SMTP gateways. Terminates and re-originates connections. High latency, high CPU. Can strip malicious content at protocol level. |
| NGFW | L3–L7 — DPI, app-ID (even encrypted via JA3/fingerprint), user identity, URL categories, IPS/IDS | Connection + app state | Palo Alto, Fortinet, Check Point, Cisco FTD. App-aware policy — block Dropbox without blocking HTTPS. SSL/TLS inspection (decrypt → inspect → re-encrypt). |
| WAF (Web Application Firewall) | HTTP/HTTPS — request/response bodies, headers, cookies, SQL/XSS patterns | HTTP session | Protects web apps — OWASP Top 10. ModSecurity, AWS WAF, Cloudflare. Sits in front of web server. Complements NGFW, not a replacement. |
zone-based firewall design
| zone | trust level | typical contents | policy notes |
|---|---|---|---|
| Outside / Untrusted | 0 — No trust | Internet, untrusted WAN, partner connections | Default deny all inbound. Only permit explicitly needed inbound (DNAT targets, VPN endpoints). Aggressive rate limiting, no ICMP echo reply by default. |
| DMZ / Semi-trusted | 1 — Low trust | Public-facing servers — web, mail, DNS, VPN concentrators | Internet → DMZ: permit specific services only. DMZ → Inside: deny all (servers in DMZ should never initiate connections to internal). DMZ → Outside: permit outbound for updates etc. |
| Inside / Trusted | 3 — High trust | Corporate LAN, user workstations, printers | Inside → Outside: permit with inspection. Inside → DMZ: permit as needed. Outbound filtering for data loss prevention and malware C2 blocking. |
| Management / OOB | 4 — Highest trust | Network devices management plane, IPMI/iDRAC, OOB switches | Strictly limited access. Jump host / bastion required. No direct access from user VLANs. Log all connections. Consider separate physical network. |
| Guest / IoT | 0.5 — Untrusted internal | Guest WiFi, BYOD, IoT sensors, building systems | Internet-only. Block all lateral movement to corporate subnets. DNS filtering, limited port access. Treat as hostile — assume compromise. |
📐 Design principle: Traffic between zones is denied by default — policy must explicitly permit. Traffic within a zone is typically permitted (same-zone traffic doesn't cross the firewall). Always create a dedicated management zone — never manage firewalls from the same zone they protect.
NAT types
| type | mapping | use case | notes |
|---|---|---|---|
| Static NAT | 1-to-1 — one private IP ↔ one public IP, permanent | Inbound to public-facing servers (web, mail). Server always reachable at same public IP. | Bidirectional — both inbound and outbound work. Consumes one public IP per server. Also called DNAT when applied inbound only. |
| Dynamic NAT | 1-to-1 — private IP mapped to available pool address for session duration | Outbound for small groups of hosts with a pool of public IPs. Less common now. | Pool exhaustion = no new sessions. No port translation — each host needs unique IP. Returns IP to pool after session ends. |
| PAT / NAT Overload | Many-to-1 — many private IPs share one public IP, differentiated by port number | Standard outbound NAT for homes and enterprises. Entire network shares one public IP. | ~65,535 ports available per public IP — practical limit ~4,000–6,000 concurrent sessions. Breaks some protocols (FTP active mode, SIP, IPsec AH). ALG required. |
| Port forwarding (DNAT) | Inbound — public IP:port → private IP:port | Expose internal service through PAT — e.g. public 203.0.113.1:443 → 10.0.0.10:443 | Also called destination NAT. Only specific port/protocol forwarded — host remains otherwise unreachable. Common for home lab / small office hosting. |
| Twice NAT / Bi-directional | Both src and dst IP translated in same policy | Overlapping IP space between sites. Translates both ends to avoid conflicts. | Used in mergers/acquisitions when two networks share the same RFC 1918 range. Complex to troubleshoot — capture both pre- and post-NAT traffic. |
| NAT64 | IPv6 → IPv4 translation at network boundary | IPv6-only hosts accessing IPv4-only resources. Common in mobile carrier networks. | Works with DNS64 — synthesizes AAAA records with embedded IPv4 address. Requires stateful NAT64 gateway. Not the same as IPv6 tunneling. |
⚠️ NAT breaks end-to-end connectivity — IPsec (AH mode), some VoIP, FTP active mode, and peer-to-peer protocols require Application Layer Gateways (ALG) or use NAT traversal techniques (NAT-T for IPsec via UDP 4500, STUN/TURN for WebRTC). Disable SIP ALG on consumer/SMB routers — it often corrupts SIP headers rather than fixing them.
rule order, implicit deny & ACL logic
| concept | detail |
|---|---|
| First match wins | Rules evaluated top-to-bottom. First matching rule is applied — evaluation stops. Order is critical: place most specific rules before general ones. A broad permit before a specific deny will always match first, making the deny unreachable. |
| Implicit deny all | Every ACL and firewall policy ends with an invisible "deny any any." Traffic not matched by any explicit rule is dropped. On Cisco IOS ACLs, applying an ACL to an interface that has no permit statements blocks all traffic on that interface. |
| Stateful return traffic | Stateful firewalls automatically permit return traffic for established sessions — you don't need an explicit permit for TCP ACK, UDP responses, etc. Stateless ACLs (router ACLs) require a matching return rule or use established keyword for TCP. |
| TCP established | permit tcp any any established — permits TCP packets with ACK or RST bit set (return traffic for outbound sessions). Does not permit initial SYN. Only works for TCP, not UDP/ICMP. |
| Rule shadowing | A rule that can never be matched because a broader rule above it already handles all the same traffic. Common mistake: permit ip any any followed by deny tcp any any eq 23 — the deny is shadowed, Telnet is allowed. Audit regularly. |
| Cleanup rule | Explicit deny ip any any log at the end of every ACL/policy. Functionally same as implicit deny but generates log entries for blocked traffic — essential for troubleshooting and audit trails. |
essential port & protocol reference for firewall rules
| port / proto | service | notes for firewall policy |
|---|---|---|
| Infrastructure — almost always needed | ||
UDP 53 | DNS | Permit to internal DNS servers. Block direct external DNS from workstations — forces use of internal resolvers for logging and filtering. TCP 53 for zone transfers and large responses (DNSSEC). |
UDP/TCP 67/68 | DHCP | Permit broadcast on access VLANs. Permit UDP 67 to DHCP server for relay. Block DHCP server port from untrusted zones to prevent rogue servers. |
UDP 123 | NTP | Permit to internal NTP servers. All devices must sync to common time source for log correlation. Block inbound NTP from internet — NTP amplification DDoS vector. |
UDP 161/162 | SNMP | 161 = polling (inbound to devices), 162 = traps (outbound to NMS). Restrict to management zone only. SNMPv1/v2c community strings are cleartext — never permit from untrusted zones. |
| Management | ||
TCP 22 | SSH | Permit from management zone / jump host only. Block from all other zones. Disable Telnet (TCP 23) everywhere — cleartext credentials. |
TCP 443 | HTTPS / management GUI | Restrict management GUIs to management zone. Separate from user HTTPS if possible — different interfaces or ACLs. Enforce TLS 1.2+. |
TCP 3389 | RDP | Never expose directly to internet. Jump host / VPN required. Restrict source to management subnet. High-value target — enforce MFA. |
| Common Services | ||
TCP 80 / 443 | HTTP / HTTPS | Permit outbound from inside. For NGFW: enforce HTTPS inspection, block HTTP-only sites or force redirect. Block outbound to known malicious IPs via threat intelligence feeds. |
TCP 25 / 587 / 465 | SMTP / submission | Block outbound TCP 25 from workstations — prevents direct spam sending. Permit only from mail relay servers. 587/465 = authenticated submission, permit from clients to mail relay. |
UDP 500 / 4500 | IKE / IPsec NAT-T | Required for IPsec VPN. 500 = IKEv1/v2 initial exchange. 4500 = NAT traversal (encapsulates ESP in UDP when NAT detected). Also permit IP protocol 50 (ESP) if no NAT. |
TCP/UDP 1194 | OpenVPN | Default OpenVPN port. Can be changed to TCP 443 to bypass restrictive firewalls. Permit inbound to VPN server only. |
UDP 51820 | WireGuard | Default WireGuard port. Stateless — firewall must permit inbound UDP to WG interface. Responds only to valid authenticated peers (stealth mode for others). |
ICMP type 8/0 | Ping (echo/reply) | Permit ICMP echo (type 8) outbound and echo-reply (type 0) inbound from internet for troubleshooting. Block inbound echo from internet to hide topology. Always permit ICMP unreachable (type 3) and time-exceeded (type 11) for path MTU discovery and traceroute. |
common attack patterns & firewall mitigations
| attack | how it works | mitigation |
|---|---|---|
| SYN flood | Attacker sends massive volume of TCP SYN packets with spoofed source IPs. Server allocates half-open connection state for each, exhausting connection table. | SYN cookies (server-side), SYN rate limiting per source, connection table limits, upstream scrubbing. Firewalls: max half-open connection threshold, SYN proxy. |
| IP spoofing | Attacker sends packets with forged source IP to bypass ACLs, hide identity, or exploit trust relationships. | uRPF (Unicast Reverse Path Forwarding) — drops packets whose source IP is not reachable via the ingress interface. Enable on internet-facing interfaces. Ingress/egress filtering (BCP38). |
| Port scanning | Attacker probes ports to discover open services and OS fingerprint before launching targeted exploit. | Block ICMP echo from internet. Rate limit SYN to minimize scan speed. Log and alert on port scan patterns. NGFW can identify and block automated scanners via IPS signatures. |
| Firewall rule bypass via fragmentation | Attacker fragments packets so L4 header (port numbers) appears in second fragment — stateless ACL only checks first fragment, permits all fragments from same flow. | Stateful firewall tracks fragment state and reassembles before inspection. Never use stateless ACLs as primary perimeter defense against internet traffic. |
| DNS tunneling | Attacker exfiltrates data or establishes C2 channel by encoding data in DNS queries/responses. Bypasses firewalls that permit UDP 53 outbound. | Restrict outbound DNS to internal resolvers only (block direct UDP 53 from workstations to internet). DNS inspection/RPZ on resolvers. Monitor for high-entropy domain names and excessive TXT/NULL queries. |
| HTTPS C2 / beacon | Malware communicates with C2 server over TCP 443 to blend in with normal traffic. Traditional firewalls can't inspect encrypted payload. | TLS/SSL inspection (decrypt → NGFW DPI → re-encrypt). Threat intelligence IP/domain blocking. DNS filtering (blocks C2 domain before TLS even established). JA3 fingerprinting for suspicious TLS clients. |
| Lateral movement | Once inside, attacker pivots between hosts using RDP, SMB, WMI, SSH. Relies on flat internal network with no east-west controls. | Micro-segmentation — firewall between VLANs, not just perimeter. Zero-trust: authenticate and authorize every connection. Block SMB (445) and RDP (3389) between user workstations. Monitor for unusual internal port scans. |
firewall troubleshooting quick reference
| symptom | likely cause | check / fix |
|---|---|---|
| Traffic dropped, no log entry | Implicit deny (no log), interface ACL before firewall, or routing issue | Add explicit deny any any log at end of policy. Verify packet is actually reaching the firewall — check routing, ARP, L2 forwarding first. Interface ACLs on the router may be dropping before the firewall sees the packet. |
| One-way traffic / asymmetric routing | Return path goes through different firewall — stateful table miss | Stateful firewalls require both directions to traverse the same device. Asymmetric routing breaks stateful inspection — SYN on FW-A, SYN-ACK on FW-B = dropped. Fix routing to be symmetric, or use stateful failover / session sync between HA pair. |
| Connection works then drops after ~1 min | Idle timeout expiring on firewall | Firewall removed connection state due to inactivity. Increase timeout for that application, or ensure keepalives are configured on the application/TCP stack. Common with SSH, database connections, VoIP. |
| NAT not working | Rule order, wrong interface direction, missing return route | Verify NAT rule matches the traffic (src, dst, port). Check direction — NAT applied on correct interface (inbound vs outbound). Confirm return route exists for translated address. Check NAT translation table: show xlate (ASA) / show ip nat translations (IOS). |
| VPN up but no traffic | Interesting traffic ACL mismatch, routing, or split tunneling | Check crypto ACL / traffic selectors match on both ends (must be mirror image). Verify routing — is traffic actually sent to VPN interface? Check NAT exemption rule (no-nat for VPN traffic must come before PAT rule). Confirm firewall permits ESP/UDP 4500 inbound. |
| NGFW blocking valid app traffic | App-ID misidentifying traffic, SSL inspection cert error, IPS false positive | Check application logs — what app-ID is being assigned? For SSL inspection: verify CA cert is trusted on client, check for cert pinning (some apps break with inspection). IPS: tune signatures, add exception for specific host/app. Temporarily bypass inspection to confirm. |
| MTU / fragmentation issues through firewall | Firewall blocking ICMP type 3 (fragmentation needed), IPsec overhead | Ping with DF bit set to test: ping -M do -s 1400 X.X.X.X. Ensure ICMP unreachable (type 3 code 4) is permitted through firewall — required for PMTUD. For VPN: set TCP MSS clamping (ip tcp adjust-mss 1350) on tunnel interface. |
🔍 Packet capture is your best friend: Capture on both sides of the firewall simultaneously. If packet arrives on ingress interface but never leaves egress — firewall is dropping it. If packet never arrives — upstream routing/switching issue. On ASA:
capture CAP interface inside match ip host X host Y. On Linux/iptables: tcpdump -ni eth0 host X with iptables -j LOG rules.quick reference
ip.addr ==
host filter
tcp.port ==
port filter
tcp.flags
flags
Follow Stream
reassemble
Display filters run post-capture (ip.addr, tcp.port, http, dns, !arp); capture/BPF filters run pre-capture (host, port, net). tcp.analysis.flags surfaces retransmits/dup-ACKs/zero-window. Right-click → Follow → TCP Stream.
display filter cheatsheet
| filter | description | example |
|---|---|---|
| IP / ADDRESS | ||
ip.addr == x.x.x.x | Any packet to or from IP | ip.addr == 192.168.1.10 |
ip.src == x.x.x.x | Source IP only | ip.src == 10.0.0.1 |
ip.dst == x.x.x.x | Destination IP only | ip.dst == 8.8.8.8 |
ip.addr == x.x.x.x/24 | Entire subnet | ip.addr == 192.168.1.0/24 |
eth.addr == xx:xx:xx:xx:xx:xx | MAC address (src or dst) | eth.addr == aa:bb:cc:dd:ee:ff |
eth.src == xx:xx:xx:xx:xx:xx | Source MAC | eth.src == 00:11:22:33:44:55 |
| TCP / UDP / PORTS | ||
tcp.port == 443 | TCP src or dst port | tcp.port == 443 |
tcp.dstport == 80 | TCP destination port only | tcp.dstport == 80 |
udp.port == 53 | UDP port | udp.port == 53 |
tcp.flags.syn == 1 | TCP SYN packets only | tcp.flags.syn==1 && tcp.flags.ack==0 |
tcp.flags.reset == 1 | TCP RST — connection resets | tcp.flags.reset == 1 |
tcp.analysis.retransmission | TCP retransmissions | tcp.analysis.retransmission |
tcp.analysis.zero_window | Zero window — receiver buffer full | tcp.analysis.zero_window |
| APPLICATION PROTOCOLS | ||
dns | All DNS traffic | dns.qry.name contains "google" |
dns.flags.response == 0 | DNS queries only | dns.flags.response == 0 |
http | All HTTP traffic | http.request.method == "GET" |
tls | TLS/SSL traffic | tls.handshake.type == 1 |
icmp | Ping / ICMP | icmp.type == 8 (echo request) |
| OPERATORS & COMBINING | ||
&& or and | Both conditions must match | ip.src==10.0.0.1 && tcp.port==443 |
|| or or | Either condition matches | dns || dhcp |
! or not | Exclude matches | !arp && !icmp |
contains | Field contains string | http.host contains "example" |
matches | Regex match | dns.qry.name matches "\.local$" |
in {} | Match any value in set | tcp.port in {80 443 8080} |
💡 Display filters use field names (ip.addr, tcp.port) — not BPF syntax. Use Ctrl+Space in the filter bar for autocomplete. Right-click any field in a packet → Apply as Filter to build filters interactively.
common protocol filters — DHCP · ARP · ICMP · STP · EAPOL · RADIUS
| protocol | display filter | what to look for | notes |
|---|---|---|---|
| DHCP | dhcp or bootp |
Discover → Offer → Request → ACK sequence. NAK = address conflict. | Filter by MAC: dhcp.hw.mac_addr == xx:xx:xx:xx:xx:xx |
| ARP | arp |
Gratuitous ARP, duplicate IP (ARP probes with no reply), ARP storms. | arp.duplicate-address-detected flags IP conflicts automatically |
| ICMP | icmp |
Echo req/reply (ping), unreachable, TTL exceeded, redirect messages. | Type 3 = unreachable, Type 11 = TTL exceeded (traceroute), Type 5 = redirect |
| ICMPv6 | icmpv6 |
NDP (neighbor discovery), router advertisements, DAD (duplicate address detection). | icmpv6.type == 135 = Neighbor Solicitation, 136 = Neighbor Advertisement |
| DNS | dns |
Failed lookups (NXDOMAIN), slow response times, unexpected resolvers. | dns.flags.rcode != 0 = DNS errors. dns.time > 0.5 = slow DNS |
| STP / RSTP | stp |
BPDUs, topology change notifications (TCN), root bridge changes. | TCN floods cause MAC table flushes — look for stp.flags.tc == 1 |
| EAPOL | eapol |
802.1X auth frames — EAPOL-Start, EAP-Request/Response, EAP-Success/Failure. | eap shows inner EAP. Look for EAP-Failure to debug auth issues. |
| RADIUS | radius |
Access-Request, Access-Accept, Access-Reject, Access-Challenge, Accounting. | radius.code == 3 = Access-Reject. Capture on RADIUS server or authenticator uplink. |
| LLDP / CDP | lldp / cdp |
Neighbor discovery, VLAN IDs advertised, port descriptions, system capabilities. | Useful for verifying what VLAN an AP or phone is advertising via LLDP-MED |
| OSPF | ospf |
Hello packets, LSAs, neighbor state changes, DR/BDR election. | ospf.msg == 1 = Hello. Watch for neighbor drops and LSA flooding storms. |
| VRRP | vrrp |
Virtual router advertisements, master/backup transitions. | Multiple masters on same VRIDs = split-brain. Check advertisement intervals match. |
802.11 wireless capture — monitor mode & filters
| topic | detail |
|---|---|
| Monitor mode (Linux) | sudo ip link set wlan0 down && sudo iw wlan0 set monitor none && sudo ip link set wlan0 upOr: sudo airmon-ng start wlan0 → creates wlan0mon |
| Monitor mode (macOS) | Hold Option → click Wi-Fi icon → Open Wireless Diagnostics → Window menu → Sniffer. Or use tcpdump -I -i en0 |
| Lock to channel | sudo iwconfig wlan0mon channel 6 (2.4GHz) or sudo iw dev wlan0mon set channel 36 HT40+ (5GHz) |
| Filter by BSSID | wlan.bssid == aa:bb:cc:dd:ee:ff |
| Filter by SSID | wlan.ssid == "MyNetwork" or wlan.ssid contains "Corp" |
| Management frames only | wlan.fc.type == 0 — beacons, probes, auth, assoc, deauth, disassoc |
| Beacon frames | wlan.fc.type_subtype == 8 |
| Probe requests | wlan.fc.type_subtype == 4 — shows clients probing for networks |
| Authentication frames | wlan.fc.type_subtype == 11 |
| Deauth / Disassoc frames | wlan.fc.type_subtype == 12 || wlan.fc.type_subtype == 10 — rogue deauth attacks or roaming events |
| 4-way handshake (WPA) | eapol && wlan.bssid == xx:xx:xx:xx:xx:xx — capture all 4 EAPOL frames to crack offline (educational) |
| Signal strength (RSSI) | wlan_radio.signal_dbm — filter weak clients: wlan_radio.signal_dbm < -75 |
| Data frames only | wlan.fc.type == 2 |
| Retry frames | wlan.fc.retry == 1 — high retries = RF interference or poor signal |
📡 On Wi-Fi 6 (HE) captures, use
wlan_radio.phy == he to isolate 802.11ax frames. For encrypted captures you need the PSK or PMK to decrypt — add via Edit → Preferences → Protocols → IEEE 802.11 → Decryption keys.
built-in statistics tools
| tool | menu path | what it shows | best for |
|---|---|---|---|
| Protocol Hierarchy | Statistics → Protocol Hierarchy | Breakdown of all protocols in capture by packet count and bytes % | Quickly identify unexpected protocols or traffic composition |
| Conversations | Statistics → Conversations | All TCP/UDP/IP conversations with bytes transferred, duration | Find top talkers, high-volume flows, unexpected connections |
| Endpoints | Statistics → Endpoints | All unique IPs/MACs with tx/rx bytes | Identify noisy devices, rogue hosts, broadcast sources |
| IO Graph | Statistics → IO Graph | Throughput over time graph. Can overlay multiple filters. | Visualize traffic bursts, retransmission spikes, utilization over time |
| TCP Stream Graph | Statistics → TCP Stream Graphs | Time-sequence, round trip time, window scaling, throughput graphs | TCP performance analysis, identify slow-start, window issues |
| DNS | Statistics → DNS | DNS query types, response codes, response times | Identify DNS failures, slow lookups, unusual query types |
| HTTP | Statistics → HTTP | HTTP request/response counters, load distribution | Web traffic analysis, response code distribution |
| WLAN Traffic | Wireless → WLAN Traffic | Per-SSID/BSSID stats, retry rates, data rates in 802.11 captures | Wi-Fi performance analysis, retry rate per AP/client |
| Expert Information | Analyze → Expert Information | Auto-detected issues: retransmissions, resets, out-of-order, malformed | Fast triage — start here on any capture to spot anomalies |
| Capture File Properties | Statistics → Capture File Properties | Duration, packet count, avg packet rate, avg packet size | High-level summary before deep analysis |
follow stream · export objects · IO graphs · workflow tips
| action | how to | use case |
|---|---|---|
| Follow TCP Stream | Right-click packet → Follow → TCP Stream. Or: Analyze → Follow → TCP Stream |
Reconstruct full conversation (HTTP requests, SMTP, Telnet). Shows client bytes in red, server in blue. |
| Follow UDP Stream | Right-click → Follow → UDP Stream | DNS, TFTP, SNMP conversations. Less common than TCP but useful for TFTP debugging. |
| Export HTTP Objects | File → Export Objects → HTTP |
Save files downloaded over HTTP (images, scripts, configs). Essential for malware analysis. |
| Export SMB Objects | File → Export Objects → SMB |
Extract files transferred over SMB file shares. |
| IO Graph — overlay filters | Statistics → IO Graph → click + to add lines → set display filter per line | Compare retransmissions vs total traffic: line 1 = all, line 2 = tcp.analysis.retransmission |
| Mark / Ignore packets | Ctrl+M to mark, Ctrl+D to ignore |
Highlight key packets for reference or remove noise from analysis. |
| Time reference | Ctrl+T on a packet — sets it as time zero |
Measure relative timing from a specific event (e.g., DHCP Discover as T=0). |
| Coloring rules | View → Coloring Rules |
Add custom colors for protocols or filters. Default rules already color TCP errors red. |
| tshark (CLI) | tshark -i eth0 -Y "dns" -T fields -e dns.qry.name |
Command-line Wireshark. Pipe output to grep/awk. Ideal for remote captures via SSH. |
| Remote capture (rpcapd) | File → Capture Options → Manage Interfaces → Remote |
Capture on a remote host and view locally. Or use ssh user@host tcpdump -w - | wireshark -k -i - |
| Decrypt TLS (with key log) | Edit → Preferences → Protocols → TLS → Pre-Master-Secret log file |
Set SSLKEYLOGFILE=~/tls.log env var in Chrome/Firefox, then load the file in Wireshark to decrypt HTTPS. |
🔧 Keyboard shortcuts:
Ctrl+F find, Ctrl+G go to packet, Ctrl+E collapse all details, Space scroll, Ctrl+Shift+X expert info. Use Analyze → Expert Information as your first stop on any unknown capture — it surfaces retransmissions, resets, and malformed packets automatically.quick reference
DORA
exchange
UDP 67
server
UDP 68
client
Opt 53
msg type
Discover → Offer → Request → Ack. Option 53 message types 1–8. Across subnets a relay agent sets giaddr (Cisco
ip helper-address).
DORA exchange — how DHCP works
| step | message | src → dst | what happens |
|---|---|---|---|
| 1 | DISCOVER | 0.0.0.0:68 → 255.255.255.255:67 | Client broadcasts — "I need an IP." No IP yet, src=0.0.0.0. Includes client MAC in chaddr field and requested options list (Option 55). |
| 2 | OFFER | server:67 → 255.255.255.255:68 | Server responds with a proposed IP, subnet mask, gateway, lease time. May be unicast if relay present. Client not yet configured — may receive multiple offers. |
| 3 | REQUEST | 0.0.0.0:68 → 255.255.255.255:67 | Client broadcasts its acceptance of an offer, identifying the chosen server via Option 54. Still broadcast so other servers know their offer was declined. |
| 4 | ACK | server:67 → 255.255.255.255:68 | Server confirms. Client configures interface. Lease clock starts. Server records binding in its database. Client performs ARP probe for conflict detection before using IP. |
💡 Also used for renewals: at T1 (50% lease) client unicasts REQUEST to the original server. At T2 (87.5%) it broadcasts REQUEST to any server. At expiry it restarts DORA. A NAK at any point forces the client to restart from DISCOVER.
DHCP message types — Option 53 values
| type value | name | direction | purpose |
|---|---|---|---|
1 | DHCPDISCOVER | Client → broadcast | Initial lease request. Client has no IP. |
2 | DHCPOFFER | Server → client | Server proposes IP + parameters. |
3 | DHCPREQUEST | Client → broadcast | Accept offer, renew lease, or verify address at boot (INIT-REBOOT). |
4 | DHCPDECLINE | Client → server | Client detected IP conflict via ARP probe — address is in use. Server marks address as declined. |
5 | DHCPACK | Server → client | Confirms lease. Client applies configuration. |
6 | DHCPNAK | Server → client | Rejects request — wrong subnet, lease expired, address unavailable. Client must restart DORA. |
7 | DHCPRELEASE | Client → server | Client relinquishes lease. Server returns address to pool. Unicast to server. |
8 | DHCPINFORM | Client → server | Client already has IP (static) but wants config options (DNS, NTP, etc). Server responds with ACK but no address assignment. |
common DHCP options
| option | name | value type | notes |
|---|---|---|---|
| Core Network Config | |||
1 | Subnet Mask | 4 bytes | Network mask for assigned IP. e.g. 255.255.255.0 |
3 | Router (Gateway) | IP list | Default gateway(s). Multiple IPs in preference order. |
6 | DNS Servers | IP list | Up to 8 DNS resolvers in preference order. |
15 | Domain Name | string | DNS domain for hostname resolution. e.g. corp.example.com |
28 | Broadcast Address | IP | Broadcast address for the subnet. |
| Lease Timing | |||
51 | Lease Time | uint32 (seconds) | Total lease duration. Common: 86400 (1 day), 3600 (1 hr for guests). |
58 | Renewal Time (T1) | uint32 (seconds) | When client unicasts REQUEST to renew. Default = 50% of lease time. |
59 | Rebinding Time (T2) | uint32 (seconds) | When client broadcasts REQUEST if no renewal. Default = 87.5% of lease time. |
| Client / Server Identity | |||
50 | Requested IP | IP | Client requests a specific IP (e.g. previously held lease). In DISCOVER or INIT-REBOOT REQUEST. |
52 | Option Overload | 1 byte | Options overflow into sname or file fields. 1=file, 2=sname, 3=both. |
53 | Message Type | 1 byte | DISCOVER/OFFER/REQUEST/ACK etc. Always present. See message type table above. |
54 | Server Identifier | IP | Server IP. Included in OFFER and ACK. Client echoes it in REQUEST to identify chosen server. |
55 | Parameter Request List | byte list | Client lists which options it wants in the reply. e.g. [1,3,6,15,28,43,51,58,59]. |
60 | Vendor Class ID | string | Client identifies itself — e.g. MSFT 5.0 (Windows), udhcp 1.x. Used for class-based assignment. |
61 | Client Identifier | type + value | Overrides MAC for identifying client. Type 0x01 = MAC. Windows may use GUID instead of MAC. |
| Enterprise / Relay Options | |||
43 | Vendor-Specific Info | vendor-defined | Used for vendor provisioning — Aruba AP bootstrap, Cisco phone config server, WLC discovery (Option 43 sub-option 3). |
82 | Relay Agent Info | sub-options | Added by relay agent (switch/router). Sub-opt 1 = Circuit ID (port), Sub-opt 2 = Remote ID (switch MAC). Used for policy/logging. |
121 | Classless Static Routes | route list | Push specific routes to client (RFC 3442). Overrides Option 3 on compliant clients. Format: prefix-len, subnet octets, gateway. |
⚠️ Option 43 is vendor-specific and interpreted differently per vendor. For Aruba APs: sub-option 3 carries the Mobility Controller IP. Always set alongside Option 60 (Vendor Class ID =
ArubaAP) to scope delivery to APs only.
DHCP packet field reference (BOOTP header)
| field | size | description |
|---|---|---|
op | 1 byte | 1 = BOOTREQUEST (client→server), 2 = BOOTREPLY (server→client) |
htype | 1 byte | Hardware type. 1 = Ethernet. |
hlen | 1 byte | Hardware address length. 6 for MAC addresses. |
hops | 1 byte | Relay agent hop count. Incremented by each relay. Max 16. |
xid | 4 bytes | Transaction ID — random value chosen by client, echoed in all DORA messages to correlate exchange. |
secs | 2 bytes | Seconds elapsed since client started attempting to acquire a lease. |
flags | 2 bytes | Bit 0 = broadcast flag. Set by clients that can't receive unicast before IP is assigned. |
ciaddr | 4 bytes | Client IP — populated only when client has valid lease (RENEWING/REBINDING). |
yiaddr | 4 bytes | "Your" IP — the address the server is offering or confirming. |
siaddr | 4 bytes | Server IP for next bootstrap step (e.g. TFTP server for PXE). |
giaddr | 4 bytes | Gateway IP — relay agent sets this to its own IP. Server uses it to select scope and route reply. |
chaddr | 16 bytes | Client hardware (MAC) address. First 6 bytes used for Ethernet. |
sname | 64 bytes | Optional server hostname. Can be overloaded with options (Option 52). |
file | 128 bytes | Boot filename for PXE/TFTP. Can be overloaded with options. |
magic cookie | 4 bytes | Fixed: 0x63825363 — marks start of DHCP options. Required by RFC 2131. |
options | variable | TLV-encoded options. Ends with 0xFF (Option 255 = End). Option 0 = pad byte. |
lease timers & client state machine
| state | trigger | action |
|---|---|---|
| BOUND | ACK received | Client has valid lease. T1 and T2 timers start. |
| RENEWING | T1 expires (default 50% of lease) | Client unicasts REQUEST to original server. If ACK received → back to BOUND with new timers. |
| REBINDING | T2 expires (default 87.5% of lease) | Client broadcasts REQUEST — any server can respond. Original server unreachable. |
| EXPIRED | Lease time expires, no ACK | Client must stop using IP and restart DORA from INIT state. |
| INIT-REBOOT | Client reboots with cached lease | Client broadcasts REQUEST with previously held IP (Option 50). Skips DISCOVER if server confirms. |
| DECLINED | ARP probe detects conflict | Client sends DECLINE, server marks address as declined/bad. Client waits 10s then restarts DORA. |
📐 Timer defaults: T1 = lease × 0.5 | T2 = lease × 0.875 | lease expiry = T. Can be explicitly set via Options 58 and 59. Shorter leases = more DHCP traffic but faster reclamation of stale addresses (good for guest/IoT pools).
DHCP snooping · DAI · IP Source Guard
| feature | what it does | trusted vs untrusted | protects against |
|---|---|---|---|
| DHCP Snooping | Intercepts DHCP messages on access ports. Builds a binding table: MAC → IP → VLAN → port → lease time. | Trusted: uplinks to real DHCP servers. Untrusted: all access/edge ports. OFFER/ACK on untrusted port = dropped. | Rogue DHCP servers, DHCP starvation (exhausting pool with fake MACs), DHCP spoofing. |
| Dynamic ARP Inspection (DAI) | Validates ARP packets against the DHCP snooping binding table. ARP with IP/MAC not in binding = dropped. | Same trusted/untrusted model as snooping. Trusted ports bypass DAI inspection. | ARP poisoning / ARP spoofing / MITM attacks. Depends on DHCP snooping table being populated. |
| IP Source Guard (IPSG) | Filters IP packets on untrusted ports — only allows traffic where src IP + MAC matches snooping binding table. | Applied per-port. Static IPSG bindings can be added manually for static-IP devices. | IP spoofing attacks. Client using an IP it didn't receive via DHCP is silently dropped. |
⚡ Deployment order matters: Enable DHCP Snooping first to build the binding table, then enable DAI (depends on snooping table), then IPSG. Mark uplink/trunk ports as trusted. On Aruba AOS-CX:
ip dhcp snooping globally + ip dhcp snooping trust on uplinks. DHCP snooping + DAI + IPSG together form a strong Layer 2 security triad.
DHCP troubleshooting quick reference
| symptom | likely cause | check / fix |
|---|---|---|
| 169.254.x.x (APIPA) | No DHCP response received within timeout | DISCOVER sent but no OFFER. Check relay agent (giaddr), DHCP server reachability, scope exhaustion, snooping trusted ports. |
| Wrong subnet / wrong pool | Relay agent misconfigured or missing | Verify giaddr in capture — should match server-facing IP of relay. Check ip helper-address / DHCP relay config on SVI. |
| DHCP NAK received | Client requesting expired/wrong-subnet IP | Client INIT-REBOOT with stale lease from different subnet. Server rejects it. Client should restart DORA — check OS / force release+renew. |
| Pool exhausted | Scope out of addresses | Short lease time + many devices, stale leases, DHCP starvation attack. Check server lease table, enable snooping, expand pool or reduce lease time. |
| IP conflict detected | Static device using DHCP pool address | Client sends DECLINE after ARP probe conflict. Exclude static IPs from pool. Check for duplicate statics. |
| OFFER never arrives | Firewall blocking UDP 67/68, snooping drop | Capture at client — see DISCOVER? Capture at server — DISCOVER arriving? Check snooping trusted port config. Check ACLs on VLAN SVI. |
| Slow lease acquisition | Multiple servers, delayed offers, DAD | DISCOVER → OFFER delay? Check relay latency. ARP probe/DAD adds ~1-2s. Multiple server offers — client waits for all before choosing. |
| Option 43 not delivered to APs | Missing Option 60 scope filter | Option 43 is delivered to all clients unless scoped by Option 60 (Vendor Class ID = ArubaAP). Add vendor class condition to DHCP policy. |
🔍 Wireshark filter:
dhcp or bootp — look for the DORA sequence via matching xid values. dhcp.hw.mac_addr == xx:xx:xx:xx:xx:xx to isolate a specific client. On Aruba AOS-CX: show dhcp-snooping binding, show ip dhcp-relay statistics. On Windows: ipconfig /release && ipconfig /renew. On Linux: dhclient -r && dhclient eth0.quick reference
5060 / 5061
SIP / SIPS
RTP
media (UDP)
G.711 / G.729
64 / 8 kbps
EF / 46
voice DSCP
SIP signals call setup; RTP carries the media over UDP (RTCP for stats). Mark voice EF (DSCP 46), call-signaling CS3. Budget <150 ms one-way latency, <30 ms jitter, <1 % loss.
SIP methods
| method | purpose | notes |
|---|---|---|
| Core Call Control | ||
INVITE | Initiate or modify a session | Contains SDP offer in body. Re-INVITE used to change media (hold, codec change, add video). |
ACK | Confirm INVITE transaction | Sent after receiving 200 OK to INVITE. Completes the 3-way handshake. Contains SDP answer if not in 200 OK. |
BYE | Terminate an established session | Either party can send. Triggers RTP teardown. Must receive 200 OK response. |
CANCEL | Cancel a pending INVITE | Sent before receiving final response (1xx only). Used when caller hangs up before answer. |
| Registration & Discovery | ||
REGISTER | Bind a SIP URI to a contact address | Phone registers its IP with the SIP registrar. Expires header sets registration lifetime (typically 3600s). Re-REGISTER before expiry. |
OPTIONS | Query capabilities / keepalive | Used to discover supported methods, codecs. Also used as a NAT keepalive ping — server responds 200 OK if reachable. |
| Supplementary Services | ||
SUBSCRIBE | Request event notifications | Used for presence, BLF (busy lamp field), MWI (message waiting indicator). Paired with NOTIFY. |
NOTIFY | Send event notification to subscriber | Server pushes state changes (line busy, voicemail waiting) to subscribed phones. |
REFER | Transfer a call | Attended or blind transfer. Refer-To header contains target URI. Phone receiving REFER sends INVITE to the transfer target. |
INFO | Mid-session signaling | DTMF tones (application/dtmf-relay), FAX negotiation. Not for session modification — use Re-INVITE for that. |
MESSAGE | Instant message transport | Simple pager-mode IM. Body contains text/plain or text/html message. |
UPDATE | Modify session before answer | Like Re-INVITE but can be used in early dialog (before 200 OK). Codec renegotiation during ringback. |
PRACK | Reliable provisional response ACK | ACKs 1xx responses (like 180 Ringing) when 100rel extension is used. Ensures no provisional response is lost. |
SIP response codes
| code | meaning | common cause |
|---|---|---|
| 1xx — Provisional | ||
100 | Trying | Request received, processing. Hop-by-hop only — not forwarded end-to-end. |
180 | Ringing | Destination phone is alerting. Early media may start here (ringback tone). |
183 | Session Progress | Early media in progress — SDP in body. Used for ringback, announcements before answer. |
| 2xx — Success | ||
200 | OK | Call answered, registration confirmed, OPTIONS replied. Contains SDP answer for INVITE. |
| 3xx — Redirection | ||
302 | Moved Temporarily | Try alternate URI in Contact header. Used for call forwarding, failover. |
| 4xx — Client Error | ||
400 | Bad Request | Malformed SIP message. Check headers, SDP syntax. |
401 | Unauthorized | Authentication required (WWW-Authenticate header). Phone must resend with credentials. |
403 | Forbidden | Server refuses — wrong credentials, call not permitted, number blocked. |
404 | Not Found | SIP URI doesn't exist on this server. Wrong extension, unregistered user. |
408 | Request Timeout | No response within timer. Network issue, phone unreachable. |
480 | Temporarily Unavailable | Phone registered but not answering (DND, away). Also used when all agents busy. |
486 | Busy Here | Called party is on another call. Phone-level busy — UCM may still try other lines. |
487 | Request Terminated | INVITE cancelled by CANCEL request. Normal when caller hangs up before answer. |
488 | Not Acceptable Here | No codec match in SDP offer — codec mismatch between endpoints. |
| 5xx — Server Error | ||
500 | Server Internal Error | UCM/PBX fault. Check server logs. |
503 | Service Unavailable | Server overloaded or in maintenance. May include Retry-After header. |
| 6xx — Global Failure | ||
600 | Busy Everywhere | Called party busy on all endpoints — don't retry elsewhere. |
603 | Decline | Called party explicitly rejected the call (pressed reject button). |
basic SIP call flow — INVITE · 180 · 200 · ACK · BYE
| caller (A) | →/← | callee (B) | notes |
|---|---|---|---|
INVITE (SDP offer) | → | — | A proposes codecs/ports in SDP. Via/Contact headers track routing path. |
| — | ← | 100 Trying | Server/proxy acknowledges receipt. Not forwarded end-to-end. |
| — | ← | 180 Ringing | B's phone is alerting. Caller hears ringback (generated locally or via 183 early media). |
| — | ← | 200 OK (SDP answer) | B answers. SDP answer contains B's chosen codec, RTP port, IP. Both sides now have enough to start media. |
ACK | → | — | A confirms. Completes INVITE transaction. RTP can flow both directions. |
| ↔ RTP media flows directly between A and B (peer-to-peer, bypasses SIP proxy) ↔ | |||
BYE | → | — | Either party ends call. RTP stops. Dialog terminated. |
| — | ← | 200 OK | Confirms BYE. Session fully torn down. |
💡 SIP vs RTP: SIP is signaling only — it sets up, modifies, and tears down sessions. RTP carries the actual voice and flows directly between endpoints, bypassing the SIP proxy. This means media problems (one-way audio, choppy voice) are usually a network/NAT/QoS issue, not a SIP issue.
RTP · RTCP · SRTP — media transport
| protocol | ports | purpose | notes |
|---|---|---|---|
| RTP | UDP — even ports, negotiated via SDP (typically 10000–20000) | Carries encoded voice/video frames. Each packet = one audio frame (20ms typical). No retransmission — lost packets cause dropouts. | Payload type in header identifies codec. Sequence number and timestamp used for jitter buffer and RTCP stats. |
| RTCP | UDP — RTP port + 1 (odd) | Control channel for RTP. Reports packet loss %, jitter, round-trip delay. Sender Report (SR) and Receiver Report (RR) every ~5 seconds. | Use RTCP stats to distinguish network issues (loss/jitter) from codec/endpoint issues. MOS score can be derived from RTCP-XR. |
| SRTP | Same ports as RTP | Encrypted RTP — AES-128/256. Required for security-conscious deployments. Keys exchanged via SDES in SDP or DTLS-SRTP. | SRTCP = encrypted RTCP. If capturing, SRTP traffic is opaque without keys. Wireshark can decrypt if you provide key material. |
📐 RTP port range: Each call uses 2 UDP ports (RTP + RTCP). A system handling 100 concurrent calls needs 200 ports open. Default ranges: Cisco CUCM 16384–32767, Asterisk 10000–20000, generic RFC suggestion 49152–65535. Ensure firewall/NAT rules cover your configured range.
codec reference
| codec | bitrate | bandwidth w/ headers | MOS | use case |
|---|---|---|---|---|
| G.711 µ-law (PCMU) | 64 Kbps | ~87 Kbps (20ms frames, IPv4/UDP/RTP) | 4.1 | North America PSTN standard. Excellent quality, high bandwidth. No complexity. PT=0. |
| G.711 a-law (PCMA) | 64 Kbps | ~87 Kbps | 4.1 | Europe/international PSTN standard. Functionally identical to µ-law. PT=8. |
| G.722 | 64 Kbps | ~87 Kbps | 4.5 | Wideband HD voice (50Hz–7kHz vs 300Hz–3.4kHz for G.711). Same bandwidth, much better quality. Modern phones only. PT=9. |
| G.729 | 8 Kbps | ~32 Kbps | 3.9 | Low-bandwidth WAN/remote sites. CPU-intensive compression. Sensitive to packet loss. Historically required licensing. PT=18. |
| G.729a | 8 Kbps | ~32 Kbps | 3.7 | Reduced complexity variant of G.729. Slightly lower quality, interoperable with G.729. |
| Opus | 6–510 Kbps (adaptive) | ~30–80 Kbps typical | 4.5+ | WebRTC standard. Adaptive bitrate, handles loss/jitter well. Narrowband + wideband + fullband. Best choice for modern UCaaS/WebRTC. PT=dynamic. |
| G.726 | 16–40 Kbps | ~30–55 Kbps | 3.8 | ADPCM — legacy DECT/analog trunks. Rarely used in modern IP telephony. |
| iLBC | 13.3 / 15.2 Kbps | ~27–30 Kbps | 4.1 | Tolerates packet loss well — designed for lossy networks. Used in some WebRTC deployments before Opus dominated. |
📊 Bandwidth math: G.711 with 20ms packetization = 160 bytes payload + 40 bytes IP/UDP/RTP headers = 200 bytes × 50 pps = 80,000 bytes/s = ~640 Kbps per call... wait — that's bits: 80,000 × 8 = 640,000 bps. G.729 = 10 bytes payload + 40 headers = 50 bytes × 50 pps = 20,000 bytes/s = ~160 Kbps per call. Add 20% overhead for good measure.
VoIP QoS — DSCP markings & queuing
| traffic type | DSCP name | DSCP value | hex | CoS (802.1p) | queue |
|---|---|---|---|---|---|
| Voice (RTP) | EF — Expedited Forwarding | 46 (101110) | 0x2E | 5 | Priority queue — strict priority. Maximum 33% of link bandwidth to avoid starvation of other traffic. |
| SIP Signaling | CS3 — Class Selector 3 | 24 (011000) | 0x18 | 3 | Medium-priority queue. Signaling is low bandwidth but latency-sensitive — delayed INVITE = delayed call setup. |
| Video (RTP) | AF41 — Assured Forwarding | 34 (100010) | 0x22 | 4 | High priority but below voice. Drop preference = low. Use for video conferencing streams. |
| Call Control / SCCP | CS3 | 24 | 0x18 | 3 | Same class as SIP signaling. Cisco SCCP skinny protocol for CUCM-registered phones. |
| Best Effort (data) | CS0 / DF | 0 (000000) | 0x00 | 0 | Default. All unclassified traffic. Never use for voice. |
⚡ Voice quality thresholds (one-way): Latency <150ms good / 150–400ms acceptable / >400ms unacceptable | Jitter <30ms | Packet loss <1% (G.711) / <0.5% (G.729). Mark RTP at DSCP EF (46) and trust/re-mark at the access layer. Phones typically self-mark if trusted — configure
trust dscp on the voice VLAN access port.
voice VLAN design & DHCP provisioning
| topic | detail |
|---|---|
| Voice VLAN Architecture | |
| Separate voice VLAN | Always isolate voice traffic from data. Separate IP subnet, separate QoS policy, separate DHCP scope. Prevents data storms from impacting voice, simplifies QoS trust boundaries. |
| Access port config | Port carries data VLAN (untagged) + voice VLAN (tagged via CDP/LLDP-MED). Phone's built-in switch passes PC traffic untagged. Port = access + voice VLAN on Cisco; on Aruba AOS-CX use voice-vlan command. |
| LLDP-MED | Link Layer Discovery Protocol - Media Endpoint Discovery. Vendor-neutral alternative to CDP for voice VLAN assignment. Carries Network Policy TLV (VLAN ID, DSCP, CoS) to phones. Enable on access ports serving IP phones. |
| CDP voice VLAN | Cisco Discovery Protocol sends voice VLAN ID to Cisco phones. Phone moves to voice VLAN automatically. Aruba switches support CDP passthrough but not origination — use LLDP-MED for non-Cisco phones. |
| DHCP Provisioning Options | |
| Option 150 (TFTP) | Cisco proprietary — carries TFTP server IP for phone config download. Used by SCCP/Cisco SIP phones. Cisco-specific alternative to Option 66. |
| Option 66 (TFTP server) | Standard BOOTP option — TFTP server hostname or IP. Used by many vendors for config file download. String format. |
| Option 160 / 176 | Avaya/Nortel provisioning — HTTP provisioning server URL (Option 160) or script parameters (Option 176). Avaya IP phones use these to find the call server and download firmware/config. |
| Option 43 (vendor-specific) | Universal vendor provisioning. Cisco phones: sub-option 150 (TFTP). Polycom: URL of provisioning server. Yealink: config server address. Always pair with Option 60 to scope delivery to phones only. |
| Short lease for voice | Use shorter DHCP leases (1–4 hours) on voice VLANs. Phones move desks frequently — shorter leases reclaim addresses faster and ensure phones re-provision promptly after moves. |
VoIP troubleshooting quick reference
| symptom | layer | likely cause & check |
|---|---|---|
| One-way audio | RTP / NAT | RTP flowing one direction only. Almost always NAT or firewall blocking return path. Check SDP — is the IP in the c= line reachable from both sides? Asymmetric routing. Media pinned to wrong IP behind NAT. |
| No audio (both ways) | RTP / VLAN | SIP connected (200 OK / ACK seen) but no RTP. Firewall blocking UDP port range. Wrong VLAN — RTP sourced from data VLAN, firewall rule only permits voice VLAN. Check SDP port negotiation. |
| Choppy / robotic voice | QoS / network | Packet loss or high jitter. Check RTCP receiver reports for loss %. Run ping with large count. Verify DSCP EF marking survives end-to-end — may be re-marked to 0 at a hop. Jitter buffer overflow. |
| Echo | Acoustic / PSTN | Acoustic echo = mic picking up speaker (headset/speakerphone). Electrical echo = impedance mismatch on analog PSTN trunk. Check echo cancellation settings on gateway. High latency >50ms makes echo perceptible. |
| Call drops after ~30s | SIP / NAT | Classic SIP ALG / NAT timer issue. NAT state times out, BYE can't route back. Firewall UDP timeout shorter than call duration. Disable SIP ALG on NAT device. Enable SIP OPTIONS keepalives. |
| Calls drop after ~11 min | SIP timers | SIP session timer (RFC 4028) — re-INVITE sent at session-expires/2, no response = BYE. Usually a proxy timeout at ~11 min (660s). Check Session-Expires and Min-SE headers. |
| Phone won't register | SIP / DHCP / network | Check DHCP — did phone get IP + provisioning options? Can phone reach SIP registrar (ping/traceroute)? 401 = auth failure (wrong password). 403 = not authorized. 404 = wrong domain/realm. Firewall blocking UDP 5060. |
| 488 Not Acceptable Here | SDP codec | No codec overlap between INVITE SDP offer and server/endpoint capabilities. Check codecs configured on both endpoints. G.729 license issue on Cisco gateway. Transcoding required but not available. |
| Calls fail over WiFi only | Wireless / QoS | WMM (Wi-Fi Multimedia) not enabled — voice traffic not prioritized over air. DSCP-to-WMM-AC mapping: EF → AC_VO. Roaming interruption during call — check FT (802.11r) / OKC. Hidden node, high retry rates causing jitter. |
🔍 Wireshark for VoIP:
sip — all SIP. rtp — RTP streams. Use Telephony → VoIP Calls to visualize call flows and play back audio. Telephony → RTP → RTP Streams shows jitter, packet loss, max delta per stream. Filter a full call: sip.Call-ID == "your-call-id". Check DSCP: ip.dsfield.dscp == 46 to verify EF marking on RTP packets.
WAN / SD-WAN bandwidth sizing calculator
Enter your branch traffic profile to calculate required WAN capacity, with SD-WAN path recommendations.
configuration
branch profile
Mbps/user
Mbps/user
Mbps/user
Mbps/user
Mbps total
SD-WAN factors
recommended circuit
Raw demand—
After concurrency—
After IPsec overhead—
With growth buffer—
Recommended per-link circuit—
Total provisioned (with redundancy)—
SD-WAN path recommendation
common circuit types and characteristics
| type | typical speed | latency | SLA | best for |
|---|---|---|---|---|
| MPLS (L3VPN) | 10–10,000 Mbps | 5–30 ms | Yes — carrier SLA | Voice, video, ERP — mission-critical, predictable performance |
| Business Broadband (cable/fibre) | 100–10,000 Mbps | 10–50 ms | Best-effort | Internet, cloud apps — low cost, high bandwidth |
| DIA (Dedicated Internet Access) | 100–10,000 Mbps | 5–20 ms | Yes — symmetrical | Hybrid WAN primary — guaranteed symmetrical, SLA-backed internet |
| 4G LTE | 10–150 Mbps | 20–60 ms | Best-effort | Failover, temporary sites, pop-up branches |
| 5G (sub-6 GHz) | 100–1,000 Mbps | 10–30 ms | Improving | Primary WAN for branches without fibre, replacing LTE failover |
| SD-WAN over internet | Aggregated | Varies | App-level SLA | Replacing MPLS for non-latency-sensitive apps — 60–80% cost reduction |
quick reference
110
OSPF AD
IP 89
protocol
Area 0
backbone
ref / BW
cost
Link-state, Dijkstra SPF. DR/BDR elected on multi-access by highest priority then highest RID. Reference bandwidth default 100 Mbps (raise to match 10G+ links). LSA types 1–7.
OSPF area types reference
| area type | LSA types allowed | external routes | default route | use case |
|---|---|---|---|---|
| Backbone (Area 0) | 1,2,3,4,5 | Yes (Type 5) | Optional | Required hub — all other areas must connect to Area 0 directly or via virtual link |
| Normal area | 1,2,3,4,5 | Yes (Type 5) | Optional | Standard non-backbone area — full LSA database |
| Stub | 1,2,3 | No — blocked | Injected by ABR | Leaf areas with no ASBR — reduces LSA database size significantly |
| Totally Stub | 1,2 | No | Injected by ABR | Most aggressive size reduction — only intra-area routes + default. Cisco-proprietary. |
| NSSA | 1,2,3,7 | Type 7 (internal) | Optional | Stub area that also has an ASBR redistributing external routes (e.g. connected to internet) |
| Totally NSSA | 1,2,7 | Type 7 (internal) | Injected by ABR | NSSA with default route injection — Cisco-proprietary |
OSPF cost calculator
OSPF cost = reference bandwidth / interface bandwidth. Default reference = 100 Mbps (Cisco). Adjust reference to differentiate modern link speeds.
| interface type | bandwidth | cost @ selected ref BW |
|---|
* Cost floors at 1 — IOS cannot represent fractional costs. Set auto-cost reference-bandwidth 10000 (or higher) to differentiate GE from 10GE. Always set the same reference bandwidth on ALL OSPF routers in the domain.
DR / BDR election reference
| step | criterion | notes |
|---|---|---|
| 1 | OSPF priority | Highest priority wins (0–255). Default 1. Priority 0 = never elected DR/BDR. Set on interface: ip ospf priority X |
| 2 | Router ID | Tiebreaker — highest Router ID wins. Router ID = highest loopback IP, else highest interface IP, or manually configured. |
DR/BDR election only occurs on multi-access networks (Ethernet broadcast segments). Point-to-point links skip election entirely. DR reduces LSA flooding — instead of n(n-1)/2 adjacencies, all routers form adjacency only with DR and BDR. Election is non-preemptive — changing priority does not force re-election without clearing the OSPF process.
OSPF LSA types quick reference
| LSA type | name | generated by | scope | carries |
|---|---|---|---|---|
1 | Router LSA | Every router | Single area | Links and states of the originating router |
2 | Network LSA | DR | Single area | List of routers on a broadcast segment |
3 | Summary LSA | ABR | Other areas | Inter-area routes — blocked in stub/totally-stub areas |
4 | ASBR Summary LSA | ABR | Other areas | Location of ASBR — blocked in stub areas |
5 | External LSA | ASBR | Entire OSPF domain | External routes (E1/E2) — blocked in all stub types |
7 | NSSA External LSA | ASBR in NSSA | NSSA area only | External routes within NSSA — converted to Type 5 by ABR |
quick reference
128-bit
address
fe80::/10
link-local
2000::/3
global (GUA)
fc00::/7
ULA
No broadcast — uses multicast (ff00::/8) and NDP instead of ARP. SLAAC builds addresses from Router Advertisements + interface ID (EUI-64). Loopback ::1, unspecified ::.
IPv6 address structure
| component | detail |
|---|---|
| Length | 128 bits — written as 8 groups of 4 hex digits separated by colons. Example: 2001:0db8:85a3:0000:0000:8a2e:0370:7334 |
| Compression rules | Leading zeros in each group may be omitted. One contiguous sequence of all-zero groups may be replaced with :: (only once per address). |
| Prefix notation | CIDR-style: 2001:db8::/32. Prefix length replaces subnet mask. |
| Interface ID | Typically the lower 64 bits. Can be EUI-64 derived, random (RFC 4941 privacy), or manually assigned. |
address types
| type | prefix | scope | notes |
|---|---|---|---|
| Global Unicast (GUA) | 2000::/3 | Internet-routable | Equivalent to public IPv4. IANA allocates from 2001::/32 upward. Your ISP gives you a /48 or /56. |
| Link-Local | fe80::/10 | Single link | Auto-configured on every IPv6 interface. Never routed. Used for NDP, DHCPv6, routing protocol adjacencies. Required even if no GUA assigned. |
| Unique Local (ULA) | fc00::/7 | Organization | Roughly equivalent to RFC 1918. Not routable on internet. fd00::/8 is locally assigned (randomly generated 40-bit prefix). Use for internal services. |
| Loopback | ::1/128 | Host | Equivalent to 127.0.0.1. Single address. |
| Unspecified | ::/128 | — | Source address used before interface has an address (DHCPv6 solicit, DAD). Never destination. |
| Multicast | ff00::/8 | Varies | No IPv6 broadcast — multicast replaces it. See table below for well-known groups. |
| Anycast | From unicast space | Nearest node | Same address assigned to multiple nodes — routed to closest. Used for DNS root servers, CDN, load balancing. |
| Documentation | 2001:db8::/32 | Examples only | Reserved for documentation and examples (RFC 3849). Never routed. |
well-known multicast addresses
| address | group | notes |
|---|---|---|
ff02::1 | All nodes (link-local) | Equivalent to 224.0.0.1. Reaches all IPv6 nodes on the link. |
ff02::2 | All routers (link-local) | Used by hosts to find routers for SLAAC (RS messages). |
ff02::5 | OSPFv3 all routers | OSPFv3 hello messages. |
ff02::6 | OSPFv3 DR/BDR | OSPFv3 designated router. |
ff02::9 | RIPng | RIPng routing updates. |
ff02::a | EIGRP | EIGRP hellos and updates. |
ff02::1:2 | All DHCPv6 relay/servers | DHCPv6 client sends Solicit to this address. |
ff02::1:ffxx:xxxx | Solicited-node multicast | Derived from last 24 bits of unicast address. Used for NDP neighbor solicitation (replaces ARP). |
EUI-64 interface ID generation
| step | detail |
|---|---|
| 1 | Take the 48-bit MAC address: 00:1A:2B:3C:4D:5E |
| 2 | Split in half and insert FF:FE in the middle: 00:1A:2B:FF:FE:3C:4D:5E |
| 3 | Flip bit 7 of the first byte (Universal/Local bit): 00 → 02 |
| 4 | Result: 021a:2bff:fe3c:4d5e — append to /64 prefix for full address. |
Privacy concern: EUI-64 embeds your MAC address in the IPv6 address, making you trackable across networks. RFC 4941 (privacy extensions) generates random Interface IDs instead and is default on most modern OS.
NDP — Neighbor Discovery Protocol (replaces ARP)
| message type | ICMPv6 type | purpose | IPv4 equivalent |
|---|---|---|---|
| Router Solicitation (RS) | 133 | Host asks routers to send RA immediately | — |
| Router Advertisement (RA) | 134 | Router announces prefix, default gateway, M/O flags | DHCP offer (partial) |
| Neighbor Solicitation (NS) | 135 | Resolve IPv6 address to MAC (like ARP request), also used for DAD | ARP request |
| Neighbor Advertisement (NA) | 136 | Reply with MAC address | ARP reply |
| Redirect | 137 | Router tells host of better next-hop | ICMP Redirect |
address configuration methods
| method | M flag | O flag | how it works | best for |
|---|---|---|---|---|
| SLAAC | 0 | 0 | Host combines /64 prefix from RA with self-generated Interface ID (EUI-64 or random). No server needed. | Simple networks, IoT, home |
| SLAAC + Stateless DHCPv6 | 0 | 1 | SLAAC for address, DHCPv6 for other options (DNS, NTP). Server assigns no address. | Enterprise where DNS control needed |
| Stateful DHCPv6 | 1 | 1 | DHCPv6 server assigns full address + options. Like DHCPv4. Requires relay on routed segments. | Enterprise requiring address control |
| Static | — | — | Manually configured. Always needed for router interfaces and servers. | Servers, routers, infrastructure |
DAD (Duplicate Address Detection) runs automatically before any unicast address is used — sends NS to the solicited-node multicast address; if NA received, address is a duplicate and not assigned.
common IPv6 prefixes reference
| prefix | allocation | notes |
|---|---|---|
/32 | ISP allocation | Typical block assigned to an ISP from RIR |
/48 | Site / customer | Typical allocation to an end-site. Allows 65,536 subnets of /64. |
/56 | Residential / small site | Common ISP allocation for home/SOHO — 256 subnets of /64. |
/64 | Single subnet | Standard subnet size. Required for SLAAC and EUI-64. 18.4 quintillion host addresses. |
/127 | Point-to-point links | RFC 6164. Use instead of /64 on router-to-router links to prevent subnet-router anycast issues. |
/128 | Host / loopback | Single address — used for loopbacks, anycast, and host routes. |
quick reference
ESP 50
protocol
UDP 500
IKE
UDP 4500
NAT-T
AH 51
auth-only
IKE Phase 1 builds the secure IKE SA; Phase 2 builds the IPsec SAs. ESP encrypts+authenticates (AH authenticates only). Tunnel mode for site-to-site, transport for host-to-host.
VPN types overview
| type | layer | common use | key protocols |
|---|---|---|---|
| IPsec (tunnel mode) | L3 | Site-to-site, remote access | IKEv1/v2, ESP, AH |
| IPsec (transport mode) | L3 | Host-to-host encryption | ESP, AH |
| GRE | L3 | Tunnel multicast/routing protocols | GRE (IP proto 47) |
| GRE over IPsec | L3 | Site-to-site with routing protocol support | GRE + ESP |
| DMVPN | L3 | Hub-spoke with dynamic spoke-to-spoke | mGRE, NHRP, IPsec |
| FlexVPN | L3 | Modern Cisco VPN framework | IKEv2, VTI |
| SSL/TLS VPN | L4-L7 | Remote access, clientless | TLS, DTLS |
| WireGuard | L3 | Modern simple VPN | UDP, Curve25519, ChaCha20 |
| L2TP/IPsec | L2 in L3 | Legacy remote access (Windows built-in) | L2TP + IPsec ESP |
| MPLS L3VPN | L2.5 | Service provider enterprise VPN | MPLS, MP-BGP, VRF |
IPsec — IKEv2 negotiation phases
| phase | name | what happens | output |
|---|---|---|---|
| Phase 1 | IKE_SA_INIT | Exchange DH public keys, nonces, SA proposals (encryption, integrity, PRF, DH group). Establishes a secure authenticated channel. | IKE SA — encrypted management channel |
| Phase 2 | IKE_AUTH | Authenticate peers (pre-shared key or certificates), negotiate first Child SA (IPsec tunnel parameters). | Child SA — the actual data tunnel (ESP/AH) |
| Rekey | CREATE_CHILD_SA | Renew Child SAs before lifetime expires without dropping traffic. Can also add new tunnels. | New Child SA, old removed |
IKEv2 is faster (2 exchanges vs IKEv1's 6–9), supports MOBIKE (mobility), EAP authentication, and asymmetric authentication. Always prefer IKEv2 for new deployments.
IPsec modes — tunnel vs transport
| Tunnel mode | Transport mode | |
|---|---|---|
| What's encrypted | Entire original IP packet (header + payload) encapsulated in new IP packet | Only the IP payload (TCP/UDP data); original IP header preserved |
| New IP header | Added — outer header uses tunnel endpoints (gateway IPs) | None — original header used |
| Use case | Site-to-site VPN, remote access (gateway encrypts on behalf of hosts) | Host-to-host encryption (both endpoints run IPsec stack) |
| Overhead | Higher — extra IP header + ESP header (~50–60 bytes) | Lower — no extra IP header (~30–40 bytes) |
IPsec — ESP vs AH
| ESP (Encapsulating Security Payload) | AH (Authentication Header) | |
|---|---|---|
| IP protocol | 50 | 51 |
| Encryption | Yes — AES-GCM, AES-CBC, ChaCha20-Poly1305 | No |
| Authentication | Yes (of payload) | Yes (of entire packet including IP header) |
| NAT traversal | Yes — ESP-in-UDP (port 4500) for NAT-T | No — AH covers IP header, broken by NAT |
| Used in practice | Always — ESP is the standard | Rare — AH is mostly legacy |
DMVPN — Dynamic Multipoint VPN
| component | role | notes |
|---|---|---|
| Hub | Central site | Runs mGRE and NHRP server. All spokes register their NBMA (real) address here on boot. |
| Spoke | Branch site | Registers with hub. Can dynamically build direct spoke-to-spoke tunnels without hub forwarding. |
| mGRE | Multipoint GRE | Single GRE interface on hub that terminates tunnels from all spokes. Eliminates hub config scaling problem. |
| NHRP | Next Hop Resolution Protocol | Spoke queries hub for another spoke's real IP. Hub responds so spokes can build direct tunnel. Like ARP for DMVPN. |
| Phase 1 | Hub-and-spoke only | All traffic flows through hub. Simple. No direct spoke-to-spoke. |
| Phase 2 | Spoke-to-spoke (same subnet) | Spokes learn each other's IPs via NHRP and build direct tunnels. Hub in same subnet as spokes. |
| Phase 3 | Spoke-to-spoke (hierarchical) | Uses NHRP redirect/shortcut. Spokes can be in different subnets. Most scalable. |
GRE — Generic Routing Encapsulation
| attribute | detail |
|---|---|
| IP protocol | 47 |
| Overhead | 24 bytes (20 outer IP + 4 GRE header). MTU considerations: reduce inner MTU to 1476 (1500 − 24) or enable PMTUD. |
| Supports multicast | Yes — can carry OSPF, EIGRP, PIM hellos. IPsec alone cannot carry multicast. |
| Encryption | None — GRE is an encapsulation protocol only. Combine with IPsec for security. |
| Keepalives | Supported (Cisco). Send GRE keepalives to detect far-end tunnel failure even if routing still up. |
| Recursive routing | Common misconfiguration — tunnel destination reachable only via the tunnel itself. Fix: use a static route for the tunnel destination via the physical interface. |
WireGuard quick reference
| attribute | detail |
|---|---|
| Transport | UDP — port 51820 default (configurable) |
| Crypto | Curve25519 (key exchange), ChaCha20-Poly1305 (encryption + auth), BLAKE2s (hash), SipHash24 (hashtable) |
| Authentication | Public/private key pairs — no certificates, no PKI, no CA needed |
| Handshake | 1-RTT — much faster than IKEv2's 2-RTT. Initiator sends first packet, responder replies, tunnel up. |
| Roaming | Built-in — IP address changes handled transparently. Endpoint updates on valid packet receipt. |
| Stealth | No response to unauthenticated packets — appears as closed port to scanners. |
| vs IPsec | Far simpler config, smaller attack surface (~4K LoC vs ~400K), faster, but fewer enterprise features (no IKEv2 EAP, no RADIUS integration). |
common IPsec port / protocol reference
| protocol/port | purpose | notes |
|---|---|---|
UDP 500 | IKE (Internet Key Exchange) | Phase 1 and Phase 2 negotiation. Used when no NAT detected. |
UDP 4500 | IKE NAT-Traversal + ESP-in-UDP | Used when NAT detected between peers. ESP packets wrapped in UDP for NAT compatibility. |
IP proto 50 | ESP | The actual encrypted data. Used directly when no NAT. Becomes UDP 4500 with NAT-T. |
IP proto 51 | AH | Authentication only. Rarely used. Incompatible with NAT. |
IP proto 47 | GRE | GRE tunnel encapsulation. Often combined with IPsec. |
quick reference
UDP 161
SNMP get
UDP 162
traps
UDP 514
syslog
UDP 123
NTP
Prefer SNMPv3 (auth + priv) over v2c community strings. Syslog severities 0 (emerg) → 7 (debug). NTP stratum 0 = reference clock, 1 = directly attached.
SNMP versions comparison
| SNMPv1 | SNMPv2c | SNMPv3 | |
|---|---|---|---|
| Authentication | Community string (cleartext) | Community string (cleartext) | Username + MD5/SHA hash |
| Encryption | None | None | DES / AES-128/256 |
| Bulk operations | No | Yes — GetBulk | Yes — GetBulk |
| 64-bit counters | No | Yes (Counter64) | Yes |
| Use today | Legacy only | Common (monitoring) | Required for security |
Use SNMPv3 with authPriv security level for any device accessible beyond your management VLAN. Community strings in v1/v2c are transmitted in cleartext and visible in packet captures.
SNMPv3 security levels
| level | authentication | encryption | use case |
|---|---|---|---|
| noAuthNoPriv | Username only | None | Avoid — no real security |
| authNoPriv | MD5 or SHA | None | Verifies source but data is cleartext |
| authPriv | MD5 or SHA | DES or AES | Recommended — full security |
SNMP operations
| operation | direction | port | purpose |
|---|---|---|---|
| GET | Manager → Agent | UDP 161 | Retrieve a specific OID value |
| GET-NEXT | Manager → Agent | UDP 161 | Walk the MIB tree — get next OID in sequence |
| GET-BULK | Manager → Agent | UDP 161 | v2c/v3 — retrieve multiple OIDs in one request. Efficient for tables. |
| SET | Manager → Agent | UDP 161 | Write a value to the agent. Requires read-write community / access. |
| TRAP | Agent → Manager | UDP 162 | Unsolicited alert from agent (link down, threshold exceeded). No acknowledgement. |
| INFORM | Agent → Manager | UDP 162 | Like TRAP but manager acknowledges. Reliable delivery. v2c/v3 only. |
useful OIDs — quick reference
| OID | name | description |
|---|---|---|
1.3.6.1.2.1.1.1.0 | sysDescr | Device description string (OS version, model) |
1.3.6.1.2.1.1.3.0 | sysUpTime | Time since last reboot (in hundredths of a second) |
1.3.6.1.2.1.1.5.0 | sysName | Configured hostname |
1.3.6.1.2.1.2.2.1.8 | ifOperStatus | Interface operational status (1=up, 2=down) |
1.3.6.1.2.1.2.2.1.10 | ifInOctets | Inbound octets on interface (32-bit, wraps on high-speed links) |
1.3.6.1.2.1.2.2.1.16 | ifOutOctets | Outbound octets on interface |
1.3.6.1.2.1.31.1.1.1.6 | ifHCInOctets | 64-bit inbound octet counter — use this for interfaces above 100 Mbps |
1.3.6.1.2.1.4.21 | ipRouteTable | IP routing table |
1.3.6.1.4.1.9 | Cisco enterprise MIB | Cisco-specific OIDs (CPU, memory, temperature) |
Syslog severity levels
| level | name | meaning | examples |
|---|---|---|---|
| 0 | Emergency | System unusable | Kernel panic, total hardware failure |
| 1 | Alert | Immediate action required | Database corruption, all redundancy lost |
| 2 | Critical | Critical conditions | Dual PSU failure, hardware error |
| 3 | Error | Error conditions | Interface error, BGP session down, config apply fail |
| 4 | Warning | Warning conditions | High CPU, link flap, interface error rate |
| 5 | Notice | Normal but significant | Config change, user login, interface up/down |
| 6 | Informational | Informational messages | STP topology change, OSPF adjacency up |
| 7 | Debug | Debug-level messages | Per-packet detail — never send to syslog server in production |
Cisco IOS default logging: severity 6 (informational) to console and buffer. Recommended syslog server level: 5 (notice) or 6 (informational) to capture events without flooding. logging trap <level> on Cisco sets the threshold sent to the syslog server.
Syslog — facility codes (common)
| facility | code | typical source |
|---|---|---|
| kern | 0 | Kernel messages |
| user | 1 | User-level messages |
| 2 | Mail system | |
| daemon | 3 | System daemons |
| auth | 4 | Security/authentication (login, sudo) |
| syslog | 5 | Syslog daemon itself |
| local0–local7 | 16–23 | Custom use — network devices commonly use local6 or local7 |
NTP — Network Time Protocol
| concept | detail |
|---|---|
| Port | UDP 123 |
| Stratum 0 | Reference clock (atomic, GPS, radio). Not directly accessible on network. |
| Stratum 1 | Directly connected to stratum 0. Public NTP servers (time.cloudflare.com, pool.ntp.org). Most accurate on internet. |
| Stratum 2 | Syncs from stratum 1. Your internal NTP server should be stratum 2. |
| Stratum 3–15 | Each level adds ~1ms jitter. Avoid deep chains. |
| Stratum 16 | Unsynchronized — device does not have a valid time source. |
| NTPv4 | Current version. Supports IPv6, improved security, up to nanosecond precision. |
| PTP (IEEE 1588) | Precision Time Protocol — sub-microsecond accuracy for financial, telecom, 5G. Hardware timestamping required. |
Why NTP matters for networks: syslog timestamps across devices must match to correlate events during incidents. Certificate validation requires accurate time. Kerberos authentication fails if clocks are skewed >5 minutes. OSPF/BGP can be affected by timestamp issues in some implementations.
NTP best practices
| practice | detail |
|---|---|
| Minimum sources | Configure at least 3 NTP servers so NTP can use majority voting to detect a bad time source. 4+ preferred. |
| Internal hierarchy | Point all network devices to 2–3 internal NTP servers (your core routers or dedicated appliances). Internal servers sync to 2+ public stratum 1/2 sources. |
| Authentication | Use NTP MD5 authentication between internal servers and clients to prevent rogue NTP server attacks. |
| Restrict access | NTP ACL — only allow queries from your management network. Prevents NTP amplification DDoS abuse. |
| Cisco quick config | ntp server <IP> prefer / ntp source <interface> / show ntp status / show ntp associations |
quick reference
≥ −67 dBm
good RSSI
≥ 25 dB
target SNR
< 10 %
retry rate
< 40 %
ch. util
−67 dBm / SNR 25 dB supports voice and high MCS. High retries or airtime utilization points to interference or client overload. Check co-channel interference, DFS radar events, sticky clients, and band steering.
← click a node to see troubleshooting tips
quick reference
conf t
IOS config
configure
Junos config
show run
running cfg
commit
Junos apply
Cisco IOS / Aruba AOS-CX apply changes immediately; Juniper Junos stages a candidate config and applies on commit. show running-config (IOS) ≈ show configuration (Junos). Use the search box to filter commands.
| task | 🟦 Cisco IOS / IOS-XE | 🟩 Aruba AOS-CX | 🟧 Juniper JunOS | 🟥 Arista EOS |
|---|
quick reference
AireOS
legacy WLC
IOS-XE
Catalyst 9800
show ap summary
APs
show wlan
SSIDs
Cisco controllers moved from AireOS (5520/8540) to Catalyst 9800 IOS-XE; Mobility Express embeds the WLC in an AP. Common checks: show ap summary, show wlan summary, show client summary. Filter with the search box.
| task | 🟦 Cisco 9800 (IOS-XE) | 🟩 Aruba MC (AOS8) | 🟧 Ruckus SmartZone | 🟣 Juniper Mist |
|---|
configuration
file size
quick file presets
circuit speed
quick speed presets
protocol overhead
the formula
TRANSFER TIME
time (s) = file_size_bits ÷ throughput_bps
where throughput = circuit_speed × (1 − overhead_fraction)
file_size_bits = file_bytes × 8
⚠ bits vs bytes — circuits are rated in bits/s (Mbps). File sizes are in bytes. Multiply bytes × 8 before dividing. Forgetting this gives results 8× too fast.
⚠ overhead is cumulative — a VPN over HTTPS adds ~15% total, not 10+5 as separate numbers. Use the closest preset or calculate custom.
⚠ half-duplex — on half-duplex links (old hubs, some Wi-Fi scenarios), effective throughput can be 40–60% of rated speed due to collision/backoff.
✓ real-world note — TCP throughput over WAN is also limited by the bandwidth-delay product. On a 100 Mbps link with 200ms RTT, a single TCP flow tops out at ~6 Mbps without window scaling (BDP = 100M × 0.2s = 2.5 MB, default window 64 KB).
overhead reference
| protocol | overhead | what it covers |
|---|---|---|
| Raw / Layer 1 | 0% | Pure bit rate. No framing, no protocol. Theoretical max. |
| Ethernet + IP + TCP | ~3% | Standard TCP/IP framing (Ethernet 18B + IP 20B + TCP 20B per ~1500B frame = ~3.8%). |
| HTTPS / TLS 1.3 | ~5% | TLS record overhead (~5B per record) + TCP + IP. TLS 1.3 is more efficient than 1.2. |
| IPsec ESP (tunnel) | ~10% | New outer IP header (20B) + ESP header (8B) + IV (16B) + padding + ICV (12B) per packet. |
| GRE tunnel | ~8% | GRE adds 4B header + outer IP 20B. Over 1500B payload = ~1.6%. MTU fragmentation adds more. |
| MPLS + IPsec VPN | ~20% | MPLS shim labels (4B each, often 2 labels) + IPsec overhead. Typical MPLS WAN with encryption. |
| Wi-Fi 802.11 (managed) | 15–40% | DIFS, backoff, preamble, MAC header, ACK, SIFS. Efficiency highly dependent on MCS rate and aggregation. A-MPDU reduces overhead significantly. |
transfer time
—
transfer time lookup table — raw throughput
green <10s · amber 10s–5min · red >5min
Table uses raw throughput (0% overhead). Time = (file_bytes × 8) ÷ circuit_bps. Click "protocol overhead" buttons above the calculator to see adjusted times.
port forwarding builder
outside interface
public IP
public port
inside server IP
inside port
protocol
vendor
quick service presets:
HTTP
HTTPS
SSH
RDP
DNS
SMTP
SIP
PPTP
OpenVPN
generated CLI
⎘ copy
NAT types — static · dynamic · PAT
static NAT 1:1
One-to-One Mapping
A single private IP maps permanently to a single public IP. The mapping is bidirectional — inbound and outbound both work without additional config.
Translation table:
✓ Predictable — same outside IP always
✓ Inbound connections work without port forwarding
✗ Requires one public IP per host
✗ Wastes public address space
Use for: Servers, DMZ hosts, anything that must be reached inbound by full IP.
Translation table:
10.0.0.10 ↔ 203.0.113.10✓ Predictable — same outside IP always
✓ Inbound connections work without port forwarding
✗ Requires one public IP per host
✗ Wastes public address space
Use for: Servers, DMZ hosts, anything that must be reached inbound by full IP.
dynamic NAT pool
Pool-Based Mapping
Private IPs map to a pool of public IPs — first-come, first-served. The mapping is temporary and released when the session ends. Inbound connections are not possible unless a mapping exists.
Translation table:
✓ Better address utilization than static
✗ If pool exhausted, new sessions fail
✗ No inbound without static entry
Use for: Rarely used today — PAT is more efficient.
Translation table:
10.0.0.10 → 203.0.113.10 (active)10.0.0.11 → 203.0.113.11 (active)10.0.0.12 → (waiting — pool exhausted)✓ Better address utilization than static
✗ If pool exhausted, new sessions fail
✗ No inbound without static entry
Use for: Rarely used today — PAT is more efficient.
PAT / NAT overload many:1
Port Address Translation
Many private IPs share a single (or small pool of) public IP(s). The router tracks sessions by adding a unique source port to each translation. Up to ~65,535 simultaneous sessions per public IP.
Translation table:
✓ Massive address conservation
✓ Most common NAT type in production
✗ Inbound requires explicit port forwarding
✗ Breaks protocols that embed IP in payload (ALG needed)
Use for: Home routers, branch offices, any outbound-primary environment.
Translation table:
10.0.0.10:5000 → 203.0.113.1:102410.0.0.11:3200 → 203.0.113.1:102510.0.0.10:5001 → 203.0.113.1:1026✓ Massive address conservation
✓ Most common NAT type in production
✗ Inbound requires explicit port forwarding
✗ Breaks protocols that embed IP in payload (ALG needed)
Use for: Home routers, branch offices, any outbound-primary environment.
PAT session table — how translation works
OUTBOUND PACKET FLOW (PAT)
1. Client sends: src=10.0.0.10:54321 dst=8.8.8.8:53 proto=UDP
2. NAT router: creates entry → src rewritten to 203.0.113.1:1024
3. Packet sent: src=203.0.113.1:1024 dst=8.8.8.8:53
─────────────────────────── response arrives ───────────────────────────
4. Reply arrives: src=8.8.8.8:53 dst=203.0.113.1:1024
5. NAT lookup: port 1024 → maps to 10.0.0.10:54321
6. Delivered: src=8.8.8.8:53 dst=10.0.0.10:54321
| field | inside local | inside global | outside global | notes |
|---|---|---|---|---|
| Source IP | 10.0.0.10 | 203.0.113.1 | 8.8.8.8 | Private → public rewrite on egress |
| Source Port | 54321 | 1024 | — | Port remapped to track session uniquely |
| Dest IP | 8.8.8.8 | unchanged | 8.8.8.8 | Destination not modified for outbound |
| Session timer | UDP: 30s idle timeout · TCP: 86400s (24h) established · TCP FIN/RST: 60s | Entry removed after timeout | ||
The NAT table is stateful — the router must see the SYN (TCP) or first packet (UDP) to create the entry. Asymmetric routing breaks NAT because the return packet hits a different router that has no table entry.
hairpin NAT / NAT loopback
PROBLEM — internal client hits public IP
Client 10.0.0.50 → DNS resolves server.example.com → 203.0.113.1:443
│ packet hits router outside interface
Without hairpin: router drops — src is inside, dst is its own outside IP
With hairpin: router translates → forwards to 10.0.0.100:443
Note: return traffic src IP = router outside IP, not server IP — client sees connection from public IP
When it matters: Internal clients using public DNS names for internal servers. Without hairpin, split-horizon DNS (internal DNS returns private IP) is the cleaner fix.
Cisco IOS:
ip nat inside source static ... no-alias + ip nat hairpin or simply ensure NAT inside/outside on same VRFBetter fix: Split-horizon DNS — internal DNS returns 10.0.0.100 for server.example.com, external DNS returns 203.0.113.1
ALG — application layer gateway
Some protocols embed IP addresses or ports in their payload — not just headers. NAT rewrites headers but not payload, breaking the protocol. ALGs inspect and rewrite payload too.
| protocol | port | ALG needed? | why |
|---|---|---|---|
| SIP (VoIP) | 5060/5061 | yes | SDP body contains private IP for RTP media stream. Without ALG, audio one-way or fails. |
| FTP (active) | 21 | yes | PORT command sends private IP:port in ASCII payload. Server tries to connect back — fails through NAT. FTP passive avoids this. |
| FTP (passive) | 21 | no | Client initiates data connection. No ALG needed — standard outbound NAT handles it. |
| H.323 | 1720 | yes | Legacy VoIP. Embeds addresses in Q.931/H.245 signaling. Modern deployments use SIP instead. |
| TFTP | 69 | yes | UDP — server replies from random high port. NAT may not track the session return. |
| HTTPS / TLS | 443 | no | Encrypted — ALG cannot inspect payload anyway. Standard PAT works. |
| IPsec ESP | — | NAT-T | ESP has no port — can't PAT. NAT-T (RFC 3947) encapsulates ESP in UDP/4500 to add ports. |
ALGs can cause problems when the protocol is encrypted (TLS-SIP) or when the ALG misidentifies traffic. Many enterprise firewalls allow disabling specific ALGs per interface.
NAT troubleshooting
| symptom | likely cause | Cisco debug / show | fix |
|---|---|---|---|
| Outbound connections fail | ACL not matching traffic for NAT, or inside/outside interfaces misconfigured | debug ip natshow ip nat translations |
Verify ip nat inside on LAN int, ip nat outside on WAN. Check ACL permits correct source range. |
| Port forward not working (inbound) | Static NAT entry missing, firewall ACL blocking, or wrong inside IP | show ip nat translations verbosedebug ip nat detailed |
Confirm static entry exists. Check inbound ACL on outside interface permits the port. Verify server is actually listening on that port. |
| Asymmetric routing / session drops | Traffic ingress/egress via different routers — return hits router with no NAT table entry | show ip nat translations — entry missing for return |
Ensure symmetric routing through single NAT device. Use ECMP-aware NAT or stateful NAT failover (HSRP + NAT). |
| NAT table exhaustion (PAT) | >65535 concurrent sessions per public IP | show ip nat translations totalshow ip nat statistics |
Add public IPs to PAT pool. Reduce session timeouts (UDP: 30s, TCP established: 3600s). Investigate session leak. |
| Overlapping RFC1918 (VPN/merger) | Both sides use 10.0.0.0/8 — routing ambiguous after tunnel | Routing table shows conflict | Use twice-NAT (NAT on both source and destination). Translate one side's range to unique address before VPN. Cisco: ip nat inside source static network. |
| VoIP one-way audio | SIP ALG not rewriting SDP media IP, or ALG rewriting incorrectly | Wireshark — check SDP c=IN IP4 line in INVITE |
Enable SIP ALG if disabled. Or disable SIP ALG entirely and use a SBC (Session Border Controller) to handle media NAT properly. |
| IPsec VPN fails through NAT | ESP (protocol 50) has no port — can't PAT. IKE on UDP/500 blocked. | debug crypto isakmpshow crypto isakmp sa |
Enable NAT-T (UDP/4500) on both endpoints. Cisco: crypto isakmp nat-traversal. Ensure UDP 500 and 4500 permitted inbound. |
quick reference
UDP 53
queries
A / AAAA
v4 / v6
CNAME / MX
alias / mail
TCP 53
zone xfer
Recursive resolver walks root → TLD → authoritative, caching by TTL. UDP 53 for normal queries; TCP 53 for zone transfers and responses >512 B. PTR = reverse, TXT = SPF/DKIM/verification, NS = delegation.
DNS record types
| type | full name | what it stores | example | notes |
|---|---|---|---|---|
| address records | ||||
| A | Address | IPv4 address (32-bit) | example.com. → 93.184.216.34 |
Most common record. One name can have multiple A records (round-robin load balancing). |
| AAAA | IPv6 Address | IPv6 address (128-bit) | example.com. → 2606:2800:220:1:248:1893:25c8:1946 |
Quad-A. Resolver queries both A and AAAA — client uses whichever it has connectivity for (Happy Eyeballs). |
| PTR | Pointer | Reverse DNS — IP → hostname | 34.216.184.93.in-addr.arpa. → example.com. |
Stored in in-addr.arpa (IPv4) or ip6.arpa (IPv6) zones. Octets reversed. Required by many mail servers for spam checks. |
| name & alias records | ||||
| CNAME | Canonical Name | Alias → another hostname | www.example.com. → example.com. |
Resolver follows the chain until it hits an A/AAAA. Cannot coexist with other records at same name. Can't use at zone apex (root domain). |
| NS | Name Server | Authoritative NS for zone | example.com. → ns1.registrar.net. |
Delegation record. TLD nameservers hold NS records pointing to your authoritative servers. Always fully-qualified (trailing dot). |
| mail records | ||||
| MX | Mail Exchange | Mail server + priority | example.com. MX 10 mail.example.com. |
Lower priority number = preferred. Multiple MX records = redundancy. Value must point to A/AAAA — not a CNAME. |
| zone & service records | ||||
| SOA | Start of Authority | Zone metadata | ns1.example.com. admin.example.com. serial refresh retry expire min-ttl |
One per zone. Serial increments on every change (triggers zone transfers). Minimum TTL = negative cache TTL (NXDOMAIN caching time). |
| SRV | Service | Service location (host + port) | _sip._tcp.example.com. 10 20 5060 sipserver.example.com. |
Format: priority weight port target. Used by SIP, XMPP, Teams, Active Directory. Allows service discovery without hardcoding ports. |
| text & security records | ||||
| TXT | Text | Arbitrary text (up to 255 chars per string) | example.com. TXT "v=spf1 include:_spf.google.com ~all" |
Used for SPF, DKIM, DMARC, domain verification (Google, Azure, Let's Encrypt). Multiple TXT records at same name are valid — resolvers return all. |
| CAA | Certification Authority Authorization | Which CAs may issue certs | example.com. CAA 0 issue "letsencrypt.org" |
Prevents unauthorized CAs from issuing certs for your domain. CAs must check before issuing. Tags: issue, issuewild, iodef. |
| DNSKEY | DNS Key | DNSSEC public key | ZSK or KSK public key for zone signing | Used by DNSSEC. Zone Signing Key (ZSK) signs RRsets. Key Signing Key (KSK) signs the DNSKEY RRset itself. |
| DS | Delegation Signer | Hash of child zone KSK | Stored in parent zone to establish chain of trust | Links parent to child zone in DNSSEC. DS record in .com zone points to your domain's KSK hash. |
DNS query flow — recursive vs iterative
recursive query (client → resolver)
Client → Recursive Resolver: "What is the IP of www.example.com?"
Resolver handles all further lookups on behalf of client
Resolver → Root NS: "Who handles .com?"
Root NS → Resolver: "Try a.gtld-servers.net"
Resolver → .com TLD NS: "Who handles example.com?"
.com TLD NS → Resolver: "Try ns1.example.com"
Resolver → example.com NS: "What is www.example.com?"
Auth NS → Resolver: "93.184.216.34 (TTL 3600)"
Resolver → Client: "93.184.216.34" (cached)
resolver hierarchy
1. Browser cache — shortest lived, respects TTL
2. OS resolver cache — nscd, systemd-resolved, Windows DNS Client service
3. Local recursive resolver — DHCP-assigned (ISP, corporate DNS, 8.8.8.8)
4. Root nameservers — 13 root server identities (A–M), anycast, operated by ICANN, Verisign, etc.
5. TLD nameservers — .com, .net, .org, country codes
6. Authoritative NS — your DNS provider (Route53, Cloudflare, your on-prem DNS)
iterative vs recursive
Recursive — client asks resolver once; resolver does all the work. Used by clients to resolvers.
Iterative — resolver asks each NS in turn, gets a referral, queries the next. Used by resolvers to authoritative servers.
Authoritative — final answer, not from cache. Flag set in DNS response (AA bit).
Iterative — resolver asks each NS in turn, gets a referral, queries the next. Used by resolvers to authoritative servers.
Authoritative — final answer, not from cache. Flag set in DNS response (AA bit).
TTL — time to live behavior
| TTL value | duration | use case |
|---|---|---|
| 60 | 1 minute | During active migrations, failover prep — minimizes propagation lag |
| 300 | 5 minutes | Pre-migration: lower here 24–48h before cutover |
| 900 | 15 minutes | Services that change occasionally |
| 3600 | 1 hour | Common default — good balance |
| 86400 | 24 hours | Stable records (MX, NS) — reduces resolver load |
| 604800 | 7 days | Very stable (root hints, static infra) |
| 0 | No caching | Never cache — every query hits authoritative. High load. |
TTL behavior rules
Propagation time = old TTL at time of change. If A record had TTL 86400, every resolver that cached it holds the old value for up to 24h. Lower TTL before making changes, not after.
Negative TTL — NXDOMAIN responses are cached for the SOA minimum TTL. If you delete a record, resolvers cache the "not found" answer for that duration.
Resolver vs client TTL — resolvers decrement TTL as they hold the cache entry. Client receives remaining TTL. Client TTL often clamped to 0–300s by OS regardless of DNS response.
Migration best practice:
1. Lower TTL to 300s, wait old-TTL duration for propagation
2. Make DNS change
3. Wait 300s for new value to propagate
4. Raise TTL back to normal after cutover confirmed
DNSSEC — chain of trust
DNSSEC VALIDATION CHAIN
Root zone → signed with Root KSK (ICANN managed, ceremony every ~3mo)
│ DS record in root points to .com KSK hash
.com TLD zone → signed with .com KSK/ZSK
│ DS record in .com points to example.com KSK hash
example.com zone → all RRsets signed with ZSK
│ RRSIG record accompanies each signed RRset
Validator → verifies RRSIG with DNSKEY, checks DS hash matches parent
Validation fails → SERVFAIL returned to client (not the spoofed answer)
| record | purpose |
|---|---|
| DNSKEY | Public key used to verify signatures. KSK signs DNSKEY RRset; ZSK signs all others. |
| RRSIG | Cryptographic signature over an RRset. Includes expiry timestamp — must be renewed before expiry. |
| DS | Delegation Signer — hash of child KSK stored in parent zone. Links the chain. |
| NSEC / NSEC3 | Proves a name does NOT exist (authenticated denial of existence). NSEC3 hashes names to prevent zone enumeration. |
what DNSSEC does and doesn't do
PROTECTS AGAINST
✓ Cache poisoning (Kaminsky attack) — forged responses rejected
✓ On-path response modification
✓ NXDOMAIN injection
DOES NOT PROTECT AGAINST
✗ DDoS / DNS amplification — still possible
✗ Privacy — queries still visible on wire (use DoH/DoT)
✗ Typosquatting — validates the record, not if it's the right domain
✗ Expired signatures — if RRSIG expires and isn't renewed, zone appears broken
⚠ RRSIG expiry is the #1 operational DNSSEC failure. Set key rollover reminders. Broken DNSSEC = SERVFAIL for all clients with validation enabled.
split-horizon DNS
Different DNS answers returned based on where the query comes from. Internal clients get private IPs; external get public IPs. Same domain, different views.
EXAMPLE — server.example.com
Internal client → internal DNS → 10.0.0.100 (private IP, direct)
External client → public DNS → 203.0.113.1 (public IP, firewall)
Why it matters: Avoids hairpin NAT. Internal clients reach servers directly. Required when internal IP scheme differs from public-facing.
Cisco IOS:
ip dns view + ip dns view-listWindows DNS: Two zones with same name — one internal, one external, different records
BIND:
view "internal" { match-clients { 10.0.0.0/8; }; };⚠ Split-horizon breaks DNSSEC — the two zones have different RRsets so signatures won't match across views. Choose one or the other.
common DNS failure modes
| response / symptom | meaning | common cause |
|---|---|---|
NXDOMAIN |
Name does not exist | Typo in hostname, record deleted, wrong zone. Negative-cached for SOA min TTL. |
SERVFAIL |
Server failed to complete query | DNSSEC validation failure, authoritative NS unreachable, resolver misconfigured, zone transfer failed. |
REFUSED |
Server refused the query | Resolver ACL blocking client IP, recursive queries disabled on authoritative NS, RPZ (response policy zone) block. |
NOERROR + empty answer |
Name exists but no record of requested type | Queried wrong record type (A vs AAAA), CNAME loop, or record type mismatch. |
Slow resolution |
High latency to resolver or auth NS | Cache miss on cold resolver, distant auth NS, DNSSEC signature verification overhead. |
Stale record after change |
Old IP still returned | TTL not lowered before change. Cache holding old answer. Check remaining TTL: dig +nocmd example.com A +noall +answer |
DNS rebinding |
Malicious external domain resolves to internal IP | Attacker controls DNS for their domain, returns 192.168.x.x. Browser same-origin policy bypassed. Mitigate with DNS rebinding protection on resolver (block private IP responses for external names). |
CNAME at apex |
CNAME on root domain fails | RFC 1034 prohibits CNAME coexisting with SOA/NS at zone apex. Use ALIAS/ANAME records (Cloudflare CNAME flattening) instead. |
DNS troubleshooting — dig & nslookup reference
dig commands
| command | what it does |
|---|---|
dig example.com A | Query A record, uses system resolver |
dig @8.8.8.8 example.com A | Query specific resolver (8.8.8.8) |
dig example.com ANY | All record types (many servers block ANY) |
dig -x 93.184.216.34 | Reverse lookup (PTR) |
dig example.com +trace | Full iterative trace from root |
dig example.com +short | Answer only, no header |
dig example.com +dnssec | Include RRSIG records in response |
dig example.com +cd | Disable DNSSEC checking (checking disabled) |
dig example.com TTL | Check remaining TTL in answer section |
dig example.com MX +noall +answer | Clean answer section only |
Wireshark DNS filters
| filter | catches |
|---|---|
dns | All DNS traffic |
dns.flags.response == 0 | Queries only |
dns.flags.response == 1 | Responses only |
dns.flags.rcode != 0 | All error responses (NXDOMAIN, SERVFAIL, REFUSED) |
dns.flags.rcode == 3 | NXDOMAIN only |
dns.flags.rcode == 2 | SERVFAIL only |
dns.qry.name contains "example" | Queries for specific domain |
dns.time > 0.5 | Slow DNS responses (>500ms) |
dns.flags.aa == 1 | Authoritative answers only (AA bit set) |
dns && udp.port == 5353 | mDNS (Bonjour/Avahi) traffic |
DoH (DNS over HTTPS) — port 443, encrypted. Wireshark can't filter as DNS. Disable DoH on browser/OS to inspect.
DoT (DNS over TLS) — port 853. TCP, encrypted. Same limitation — need decryption keys to inspect.
When comparing resolver vs authoritative answers, always use
dig @<auth-ns> example.com to bypass resolver cache. If authoritative returns correct answer but resolver doesn't, it's a caching or negative-TTL issue.quick reference
dBi
gain unit
360°
omni
EIRP
effective power
3 dB
beamwidth
Higher gain antennas trade coverage angle for range — a narrower beamwidth focuses energy. EIRP = Tx power − cable loss + antenna gain. Match polarization (V/H) between link ends.
antenna types — pattern · gain · use case
omnidirectional
Omni / Dipole
gain2–6 dBi
H-plane360° (uniform)
E-plane±60–75°
use Open offices, lobbies
indooroutdoor
Radiates equally in all horizontal directions. Higher gain = flatter donut = less vertical coverage. Standard AP internal antenna. Watch: high-gain omnis (>6 dBi) compress vertical beam — bad for multi-floor coverage.
directional
Sector Antenna
gain10–17 dBi
H-plane60°, 90°, or 120°
E-plane6–15°
use Stadiums, warehouses, outdoor cells
outdoorindoor large
3 × 120° sectors cover a full cell. Higher gain than omni in-sector. Used on AP mounts at ceiling perimeter or on towers. Watch: strong nulls behind — never assume back coverage.
directional
Patch / Panel
gain6–14 dBi
H-plane30–90°
E-plane30–90°
use Hallways, point-to-multipoint, outdoor coverage
indoor/outdoor
Flat panel with moderate directivity. Wall-mounted for corridor coverage or aimed at client clusters. Low profile. Used in Aruba ANT-2x2-2714 series, Cisco AIR-ANT series.
highly directional
Yagi-Uda
gain10–20 dBi
H-plane10–30°
E-plane10–30°
use Point-to-point links, long-range outdoor bridges
outdoor
Parasitic array — driven element + reflector + directors. Very narrow beam, very high gain. Must be precisely aimed. Used for long-distance point-to-point bridging. Not suitable for client Wi-Fi.
highly directional
Parabolic Dish
gain20–35+ dBi
H-plane3–10°
E-plane3–10°
use Long-range P2P links, backhaul
outdoor
Maximum gain, minimum beamwidth. Reflective dish focuses energy at the feed point. Used for campus or building-to-building backhaul links. Extremely sensitive to alignment — 1° off can lose 3+ dB.
integrated
Internal AP Antenna
gain3–5 dBi typical
H-planeNear-omnidirectional
E-planeVaries by AP model
use Standard office, ceiling mount
indoor
PIFA or patch arrays built into the AP chassis. Aruba, Cisco, and Ruckus publish radiation pattern PDFs for each AP model. Ceiling mount = best omni coverage; wall mount = tilted pattern toward floor.
gain vs coverage — the tradeoff
GAIN ↑ = RANGE ↑ but BEAMWIDTH ↓ (energy is redistributed, not created)
2 dBi
wide
→
6 dBi
medium
→
10 dBi
narrow
→
15 dBi
very narrow
| gain range | beamwidth (approx) | range increase vs dipole | best for | watch out for |
|---|---|---|---|---|
| 2–3 dBi | Nearly spherical | baseline | Dense indoor AP, ceiling mount, high client density | Limited range in large open spaces |
| 4–6 dBi | ~75° E-plane | +2–4 dB (~40–60% more range) | Standard office omni, outdoor APs, general purpose | Starts losing vertical — avoid in multi-story open atriums |
| 8–10 dBi | ~40–60° E-plane | +6–8 dB (~2× range) | Warehouses, outdoor sectors, hallway panels | Very flat donut — poor coverage directly above/below AP |
| 12–16 dBi | ~15–30° | +10–14 dB (~3–5× range) | Outdoor point-to-multipoint, stadium sectors | Must be precisely aimed — clients outside beam get nothing |
| 20+ dBi | <10° | +18+ dB (>8× range) | Point-to-point backhaul only | No client use. Requires precise alignment. Regulatory limits may restrict EIRP. |
Every 3 dB of gain doubles the effective radiated power in the beam direction — but halves it in others. Gain is redistribution of a fixed power budget, not amplification. EIRP = TX power + antenna gain − cable loss.
polarization — single · dual · cross-pol
single polarization
│
One orientation — vertical (most common) or horizontal. Simple, lower cost. Used on older APs and basic outdoor bridges. MIMO not possible with a single polarization antenna. Client must match orientation for best sensitivity.
dual polarization
│ ─
Two orthogonal feeds (V + H) in the same physical antenna. Required for 2×2 MIMO and above. Both feeds share the same radiation pattern shape. Used on virtually all modern 802.11n/ac/ax APs.
cross-pol (±45°)
╱ ╲
Feeds tilted ±45° instead of V/H. Better isolation between ports (~30 dB vs ~20 dB for V/H). Preferred for high-density deployments — reduces cross-polarization interference. Standard on most enterprise APs (Aruba, Cisco, Ruckus internal antennas are cross-pol).
Cross-pol (±45°) has become the de facto standard for enterprise Wi-Fi. It provides better port isolation, which directly improves MIMO spatial stream separation and throughput in high-density environments. If you see "dual-band dual-pol" on an AP datasheet, it's almost certainly ±45°.
connector types
RP-SMA (Reverse Polarity SMA)
thread: 3.5mm, same as SMA
center pin: Female on plug (reversed vs SMA)
use: Consumer/SMB APs, home routers, low-power devices
vendors: Cisco older SMB, Linksys, Netgear, some Ubiquiti
⚠ FCC-mandated reversed pin prevents use of high-gain antennas on consumer devices
N-Type
thread: 7/16" hex, weatherproof
frequency: DC–18 GHz
impedance: 50Ω (standard) or 75Ω (cable TV)
use: Enterprise outdoor APs, external antennas, cable runs
vendors: Aruba outdoor APs (ANT-xx series), Cisco AIR-ANT outdoor
✓ Best choice for outdoor — weatherproof, low loss at 5 GHz
SMA (SubMiniature version A)
thread: 3.5mm
frequency: DC–18 GHz
use: Test equipment, cables, some enterprise APs
note: Male has center pin; female has socket — opposite of RP-SMA
⚠ Easy to confuse with RP-SMA — check center pin carefully
MMCX (Micro-Miniature Coax)
size: 3mm diameter, snap-on lock
frequency: DC–6 GHz
use: Internal AP pigtails, IoT devices, compact hardware
note: Used inside AP chassis to connect PCB to external connector
4.3-10 (newer outdoor standard)
size: Between N-type and 7/16 DIN
frequency: DC–6 GHz+
use: 5G small cells, newer outdoor enterprise APs
vendors: Some newer Aruba and Cisco outdoor units
✓ PIM-resistant, compact, replacing N-type in some deployments
Cable loss reference
LMR-100 @ 2.4 GHz~0.8 dB/ft
LMR-200 @ 2.4 GHz~0.35 dB/ft
LMR-400 @ 2.4 GHz~0.13 dB/ft
LMR-400 @ 5 GHz~0.22 dB/ft
⚠ Keep cable runs <3 ft when possible. Each connector adds ~0.3 dB. Loss subtracts from EIRP budget.
vendor antenna reference — Aruba · Cisco · Ruckus
| model | vendor | type | bands | gain | connector | use case |
|---|---|---|---|---|---|---|
| aruba | ||||||
| ANT-2x2-2714 | Aruba | Dual-pol omni | 2.4 + 5 GHz | 4/7 dBi | RP-SMA | Ceiling mount indoor, standard office |
| ANT-2x2-5714 | Aruba | Dual-pol omni | 5 GHz only | 7 dBi | RP-SMA | 5 GHz-only environments, high-density |
| ANT-2x2-2410 | Aruba | Dual-pol patch | 2.4 + 5 GHz | 4/10 dBi | RP-SMA | Wall/ceiling directional, hallways |
| ANT-3x3-5706 | Aruba | Tri-pol omni | 5 GHz | 6 dBi | RP-SMA | 3×3 MIMO APs, high-density |
| ANT-2x2-D-OUT | Aruba | Dual-pol omni | 2.4 + 5 GHz | 5/7 dBi | N-type | Outdoor omni — AP-374/377/387 |
| ANT-2x2-D-OUT-SEC | Aruba | Dual-pol sector | 2.4 + 5 GHz | 9/11 dBi · 90° | N-type | Outdoor sector — stadiums, campuses |
| cisco | ||||||
| AIR-ANT2422DW-R | Cisco | Dual-pol omni | 2.4 GHz | 2.2 dBi | RP-SMA | Desktop/wall omni for older Aironet |
| AIR-ANT2513P4M-N | Cisco | Dual-pol patch | 2.4 + 5 GHz | 13 dBi | N-type | Outdoor directional, warehouse walls |
| AIR-ANT2566P4W-R | Cisco | Dual-pol patch | 2.4 + 5 GHz | 6/6 dBi | RP-SMA | Indoor wall mount, open office |
| AIR-ANT2524V4C-R | Cisco | 4-element omni | 2.4 + 5 GHz | 2/4 dBi | RP-SMA | Ceiling mount, Catalyst 9100 series |
| AIR-ANT2547VG-N | Cisco | Dual-pol omni | 2.4 + 5 GHz | 4/7 dBi | N-type | Outdoor omni — AIR-AP18xx, 28xx series |
| ruckus | ||||||
| ANT-P25-0200 | Ruckus | BeamFlex patch | 2.4 + 5 GHz | 2 dBi | Integrated | BeamFlex+ internal — H510, R750 |
| 902-0169-0000 | Ruckus | Dual-pol omni | 2.4 + 5 GHz | 3/5 dBi | RP-SMA | Indoor omni for T310/T610 series |
| 902-0119-0000 | Ruckus | Dual-pol sector | 2.4 + 5 GHz | 8/8 dBi · 120° | RP-SMA | Outdoor sector — T710 series |
Always verify antenna compatibility with your specific AP model — connector type, port count (2×2 vs 4×4), and supported frequency bands must match. Aruba publishes antenna datasheets at arubanetworks.com/resource/antenna-guide. Check your EIRP budget before selecting external antenna gain — high-gain + max TX power may exceed regulatory limits.
quick reference
Management
beacon/assoc
Control
RTS/CTS/ACK
Data
payload
2.4 / 5 / 6
bands
Three frame types. Management: beacon, probe req/resp, auth, (re)association. Control: RTS/CTS, ACK, Block-ACK, PS-Poll. Data carries the actual L3 payload; QoS-Data adds the TID/priority.
frame types — management · control · data
| type | type bits | common subtypes | purpose |
|---|---|---|---|
| Management | 00 | Beacon, Probe Req/Resp, Auth, Assoc Req/Resp, Deauth, Disassoc, Action | BSS management — discovery, joining, leaving. Not encrypted unless PMF (802.11w) enabled. |
| Control | 01 | RTS, CTS, ACK, Block ACK, PS-Poll, CF-End | Medium access control — channel reservation, acknowledgement, power save. Never encrypted. |
| Data | 10 | Data, Null, QoS Data, QoS Null, A-MSDU | Carries actual payload. Encrypted in infrastructure mode. QoS variants carry TID for WMM. |
| Extension | 11 | DMG Beacon (802.11ad) | Reserved / 60 GHz WiGig. Rarely seen in enterprise deployments. |
802.11 MAC header fields
| field | size | purpose | notes |
|---|---|---|---|
| Frame Control | 2 bytes | Protocol version, type, subtype, To DS, From DS, More Frag, Retry, Power Mgmt, More Data, Protected, Order | Most important field — contains all frame classification bits |
| Duration/ID | 2 bytes | NAV (Network Allocation Vector) — how long the medium will be occupied in μs | Used by other stations to defer transmission (virtual carrier sense) |
| Address 1 | 6 bytes | Receiver address (RA) — immediate recipient | Always present. May be broadcast (FF:FF:FF:FF:FF:FF) |
| Address 2 | 6 bytes | Transmitter address (TA) — immediate sender | Present in most frames except ACK/CTS |
| Address 3 | 6 bytes | BSSID, SA, or DA depending on To DS/From DS bits | Omitted in control frames |
| Sequence Control | 2 bytes | Fragment number (4 bits) + Sequence number (12 bits) | Used for duplicate detection and fragmentation reassembly |
| Address 4 | 6 bytes | SA when To DS=1 AND From DS=1 (WDS/mesh) | Only present in WDS/mesh frames |
| QoS Control | 2 bytes | TID (Traffic Identifier), AMSDU flag, TXOP | Present only in QoS Data frames (802.11e/WMM) |
| Frame Body | 0–7951 bytes | Payload — varies by frame type | Encrypted in data frames when RSN/CCMP/GCMP in use |
| FCS | 4 bytes | CRC-32 over entire frame | Checked by receiver — corrupted frames silently dropped |
To DS / From DS bit combinations: 00 = IBSS/management, 01 = client→AP (To DS), 10 = AP→client (From DS), 11 = WDS/mesh. These bits determine which address field maps to SA/DA/BSSID.
association process — step by step
CLIENT ──────────────────────────────────────── AP
1. AP continuously sends Beacon (every 102.4ms default) — BSSID, SSID, rates, capabilities
2. Probe Request ──────────────────────────────► client scans — broadcast or directed
3. ◄────────────────────────────── Probe Response AP replies with capabilities
4. Authentication Request ────────────────────────► Open System (seq 1)
5. ◄──────────────────────── Authentication Response status 0 = success (seq 2)
6. Association Request ──────────────────────────────► client sends supported rates, RSN IE
7. ◄────────────────────────────── Association Response AID assigned, status 0
8. 4-Way Handshake ◄────────────────────────────────► PTK/GTK derivation (WPA2/3)
9. Data frames begin — port open, traffic flows
reason codes — deauth / disassoc
| code | meaning |
|---|---|
| 1 | Unspecified reason |
| 2 | Previous auth no longer valid |
| 3 | Deauth — station leaving BSS |
| 4 | Disassoc — inactivity |
| 5 | AP capacity exceeded |
| 6 | Class 2 frame from non-auth station |
| 7 | Class 3 frame from non-assoc station |
| 8 | Disassoc — station leaving BSS |
| 15 | 4-Way Handshake timeout |
| 23 | 802.1X auth failed |
| 36 | Requested by BSS Transition (802.11v) |
status codes — assoc response
| code | meaning |
|---|---|
| 0 | Success |
| 1 | Unspecified failure |
| 10 | Cannot support all requested capabilities |
| 12 | Association denied — unspecified |
| 13 | Auth algorithm not supported |
| 16 | Association denied — too many STAs |
| 17 | Station requesting assoc not auth'd |
| 23 | Assoc denied — RSSI below threshold |
| 37 | RSNA IE missing or invalid |
| 72 | Invalid PMKID |
quick reference
ip a / ip r
addr / routes
ss -tlnp
sockets
tcpdump
capture
nft
firewall
iproute2 (ip, ss) replaces the legacy net-tools (ifconfig, route, netstat). ss -tlnp = listening TCP + PID; ip -s link for counters; nftables replaces iptables. Resolver config in /etc/resolv.conf.
interfaces
| task | command |
|---|---|
| Show all interfaces | ip link show or ip a |
| Show IP addresses | ip addr show |
| Bring interface up/down | ip link set eth0 up / down |
| Set IP address | ip addr add 192.168.1.10/24 dev eth0 |
| Show interface stats | ip -s link show eth0 |
| Show MAC address | ip link show eth0 | grep ether |
routing
| task | command |
|---|---|
| Show routing table | ip route show or ip r |
| Add static route | ip route add 10.0.0.0/8 via 192.168.1.1 |
| Add default gateway | ip route add default via 192.168.1.1 |
| Delete route | ip route del 10.0.0.0/8 |
| Traceroute | traceroute 8.8.8.8 or mtr 8.8.8.8 |
| Show ARP table | ip neigh show or arp -n |
dns & connectivity
| task | command |
|---|---|
| DNS lookup | dig example.com or nslookup example.com |
| Reverse DNS | dig -x 8.8.8.8 |
| Ping | ping -c 4 8.8.8.8 |
| Test port connectivity | nc -zv 192.168.1.1 443 or telnet host port |
| Show listening ports | ss -tlnp or netstat -tlnp |
| Show established connections | ss -tnp |
capture & firewall
| task | command |
|---|---|
| Capture traffic | tcpdump -i eth0 -n |
| Capture to file | tcpdump -i eth0 -w capture.pcap |
| Filter by host | tcpdump -i eth0 host 192.168.1.1 |
| Show iptables rules | iptables -L -n -v |
| Show nftables rules | nft list ruleset |
| Allow port (ufw) | ufw allow 443/tcp |
interfaces
| task | command |
|---|---|
| Show all interfaces | ifconfig or networksetup -listallhardwareports |
| Show IP address | ipconfig getifaddr en0 |
| Renew DHCP | ipconfig set en0 DHCP |
| Set static IP | networksetup -setmanual Wi-Fi 192.168.1.10 255.255.255.0 192.168.1.1 |
| Flush ARP cache | arp -ad |
| Show Wi-Fi info | /System/Library/PrivateFrameworks/Apple80211.framework/Versions/Current/Resources/airport -I |
routing & dns
| task | command |
|---|---|
| Show routing table | netstat -rn or route -n get default |
| Add static route | sudo route add -net 10.0.0.0/8 192.168.1.1 |
| Flush DNS cache | sudo dscacheutil -flushcache && sudo killall -HUP mDNSResponder |
| DNS lookup | dig example.com or nslookup example.com |
| Traceroute | traceroute 8.8.8.8 |
| Show listening ports | lsof -i -P -n | grep LISTEN |
capture & testing
| task | command |
|---|---|
| Capture traffic | tcpdump -i en0 -n |
| Capture to file | tcpdump -i en0 -w capture.pcap |
| Test port | nc -zv host 443 |
| Ping | ping -c 4 8.8.8.8 |
| Show firewall status | sudo /usr/libexec/ApplicationFirewall/socketfilterfw --getglobalstate |
| Wi-Fi packet capture | sudo tcpdump -I -i en0 (monitor mode) |
interfaces
| task | command |
|---|---|
| Show all interfaces | ipconfig /all |
| Show brief IP info | ipconfig |
| Release DHCP lease | ipconfig /release |
| Renew DHCP lease | ipconfig /renew |
| Flush DNS cache | ipconfig /flushdns |
| Show ARP table | arp -a |
routing & dns
| task | command |
|---|---|
| Show routing table | route print or netstat -r |
| Add static route | route add 10.0.0.0 mask 255.0.0.0 192.168.1.1 |
| Persistent route | route -p add 10.0.0.0 mask 255.0.0.0 192.168.1.1 |
| DNS lookup | nslookup example.com or Resolve-DnsName example.com |
| Traceroute | tracert 8.8.8.8 |
| Show listening ports | netstat -ano | findstr LISTENING |
testing & firewall
| task | command |
|---|---|
| Ping | ping 8.8.8.8 or ping -n 4 8.8.8.8 |
| Test port (PowerShell) | Test-NetConnection -ComputerName host -Port 443 |
| Test port (telnet) | telnet host 443 (enable telnet client first) |
| Show firewall rules | netsh advfirewall firewall show rule name=all |
| Capture traffic (netsh) | netsh trace start capture=yes tracefile=c:\trace.etl |
| Show Wi-Fi profiles | netsh wlan show profiles |
quick reference
LTE
4G
NR
5G
sub-6 GHz
coverage
mmWave
capacity
5G NR runs Non-Standalone (NSA, anchored to LTE core) or Standalone (SA, 5G core). Sub-6 GHz = range/penetration; mmWave (24 GHz+) = huge throughput, short range. Target latency <10 ms (URLLC <1 ms).
LTE vs 5G NR — feature comparison
| feature | LTE (4G) | 5G NR (sub-6 GHz) | 5G NR (mmWave) |
|---|---|---|---|
| Peak downlink | ~1 Gbps (Cat 20) | ~4 Gbps | ~20 Gbps |
| Typical downlink | 10–100 Mbps | 100–500 Mbps | 1–3 Gbps (short range) |
| Latency (user plane) | 30–50 ms | 10–20 ms | <5 ms (URLLC) |
| Frequency range | 600 MHz – 2.6 GHz | 600 MHz – 6 GHz (FR1) | 24–100 GHz (FR2) |
| Channel width | 1.4–20 MHz | 5–100 MHz | 50–400 MHz |
| MIMO | 4×4 DL / 2×2 UL | Massive MIMO (up to 64T64R) | Beamforming arrays |
| Carrier aggregation | Up to 32 CC | Up to 16 CC (+ LTE CA) | Wideband — less CA needed |
| Duplexing | FDD or TDD | FDD or TDD (dynamic TDD) | TDD |
| Coverage range | Up to 100 km (rural) | Up to 10 km | 100–500 m |
| Network slicing | Limited (QCI) | ✓ Native (S-NSSAI) | ✓ Native |
key LTE frequency bands
| band | freq | duplex | common use | expected speeds |
|---|---|---|---|---|
| B2 | 1900 MHz | FDD | AT&T, T-Mobile US | 10–50 Mbps DL |
| B3 | 1800 MHz | FDD | Global mid-band | 15–75 Mbps DL |
| B4/B66 | 1700/2100 MHz | FDD | AWS — T-Mobile, AT&T | 20–75 Mbps DL |
| B7 | 2600 MHz | FDD | Europe/APAC capacity | 40–150 Mbps DL |
| B12/B17 | 700 MHz | FDD | Low-band — rural coverage | 5–25 Mbps DL |
| B13 | 700 MHz | FDD | Verizon low-band | 5–25 Mbps DL |
| B14 | 758/788 MHz | FDD | FirstNet (AT&T) — public safety priority | 10–40 Mbps DL |
| B20 | 800 MHz | FDD | Europe low-band | 5–30 Mbps DL |
| B41 | 2500 MHz | TDD | T-Mobile mid-band capacity | 50–150 Mbps DL |
key 5G NR bands
| band | freq | type | notes | expected speeds |
|---|---|---|---|---|
| n28 | 700 MHz | Sub-6 / FDD | APAC/Europe low-band 5G | 30–150 Mbps DL |
| n41 | 2.5 GHz | Sub-6 / TDD | T-Mobile mid-band 5G | 150–600 Mbps DL |
| n71 | 600 MHz | Sub-6 / FDD | T-Mobile nationwide coverage | 30–100 Mbps DL |
| n77/n78 | 3.5 GHz | Sub-6 / TDD | C-band — primary 5G globally | 200–900 Mbps DL |
| n79 | 4.9 GHz | Sub-6 / TDD | Japan / China capacity | 300–800 Mbps DL |
| n258 | 26 GHz | mmWave / TDD | Europe mmWave | 1–3 Gbps DL (line-of-sight) |
| n260/n261 | 39/28 GHz | mmWave / TDD | Ultra-high speed, short range | 1–4 Gbps DL (line-of-sight) |
5G deployment modes — NSA vs SA
| mode | control plane | user plane | core | status |
|---|---|---|---|---|
| Option 3 (NSA) | LTE (eNB anchor) | LTE + NR | EPC (4G core) | Most common initial 5G deployment — reuses 4G core |
| Option 7 (NSA) | NR + LTE | NR + LTE | 5GC (5G core) | Transition mode — 5G core with LTE fallback |
| Option 2 (SA) | NR only | NR only | 5GC (5G core) | Full standalone — enables slicing, URLLC, edge compute |
NSA (Non-Standalone) uses LTE as the anchor for signaling — faster to deploy but limited to eMBB use cases. SA (Standalone) with a 5G core unlocks network slicing, ultra-low latency URLLC, and massive IoT (mMTC). Most enterprise 5G private networks deploy SA.
enterprise 5G use cases
| use case | slice type | key requirement | example |
|---|---|---|---|
| Enhanced Mobile Broadband | eMBB | High throughput | HD video streaming, campus Wi-Fi offload, fixed wireless access |
| Ultra-Reliable Low Latency | URLLC | <1ms latency, 99.999% reliability | Industrial automation, remote surgery, autonomous vehicles |
| Massive IoT | mMTC | Low power, high device density | Smart meters, asset tracking, sensor networks |
| Private 5G | SA + slicing | Dedicated spectrum, low latency | Factory floors, ports, stadiums, hospital campuses |
| WAN failover / backup | eMBB | Fast failover, SD-WAN integration | Branch office 5G backup replacing LTE failover |
quick reference
0
connected
1
static
110
OSPF
120
RIP
Route selection: longest-prefix match first, then lowest AD (which protocol to trust), then lowest metric (best path within it). eBGP 20 · EIGRP 90 · iBGP 200.
IP routing fundamentals
| concept | detail |
|---|---|
| Forwarding Decision | |
| Longest prefix match | Router always picks the most specific (longest) matching prefix in the routing table. 10.1.1.0/24 wins over 10.0.0.0/8 for destination 10.1.1.5. A /32 host route always wins over any summary. Default route (0.0.0.0/0) is the last resort — matches everything but loses to any more specific prefix. |
| CEF / FIB | Cisco Express Forwarding — hardware-speed routing using pre-built FIB (Forwarding Information Base) and adjacency table (ARP cache). RIB (routing table) = control plane. FIB = data plane copy. Packets forwarded via FIB without CPU involvement. show ip cef to view. |
| Recursive lookup | When a route's next-hop is not directly connected, the router does a second lookup in the RIB to resolve the next-hop to an interface. Multiple levels of recursion possible (BGP next-hop → IGP route → connected). CEF flattens this at FIB build time. |
| Route Sources | |
| Connected (C) | Interface is up/up with an IP assigned. Automatically installed. AD = 0. The subnet of the interface IP is directly reachable. |
| Local (L) | /32 host route for the router's own interface IP. AD = 0. Used for traffic destined to the router itself. Present since IOS 15/IOS-XE. |
| Static (S) | Manually configured. AD = 1 by default (beats all dynamic protocols). Persistent until removed. Use floating statics (higher AD) for backup paths. |
| OSPF (O) | Open Shortest Path First. Link-state. AD = 110 (intra-area), 110 (inter-area O IA), 110 (E1/E2 external). SPF algorithm, area-based hierarchy. |
| EIGRP (D) | Enhanced IGRP. Cisco proprietary (now partially open). AD = 90 (internal), 170 (external). DUAL algorithm. Fast convergence, feasibility condition prevents routing loops. |
| BGP (B) | Border Gateway Protocol. Path-vector. AD = 20 (eBGP), 200 (iBGP). Policy-driven, not metric-driven. Internet routing protocol. Slow convergence by design. |
| RIP (R) | Routing Information Protocol. Distance-vector. AD = 120. Max 15 hops. Slow convergence. Legacy — avoid in new designs. |
administrative distance quick reference
| source | Cisco AD | Aruba AOS-CX AD | Juniper preference |
|---|---|---|---|
| Connected | 0 | 0 | 0 |
| Static | 1 | 1 | 5 |
| EIGRP summary | 5 | N/A | N/A |
| eBGP | 20 | 20 | 170 |
| EIGRP internal | 90 | N/A | N/A |
| IGRP | 100 | N/A | N/A |
| OSPF | 110 | 110 | 10 |
| IS-IS | 115 | 115 | 15 |
| RIP | 120 | 120 | 100 |
| EIGRP external | 170 | N/A | N/A |
| iBGP | 200 | 200 | 170 |
| Unknown / untrusted | 255 | 255 | — |
💡 AD is local significance only — it's not exchanged between routers. It only determines which source wins when multiple protocols know a route to the same prefix. Lower AD wins. AD 255 = route never used. Juniper calls this "preference" and lower is also better, but the default values differ significantly.
static routes — types & use cases
| type | example | behavior / use case |
|---|---|---|
| Standard static | ip route 10.1.0.0 255.255.0.0 192.168.1.1 | Next-hop IP. Route installed when next-hop is reachable. Removed if next-hop disappears (recursive lookup fails). |
| Directly attached static | ip route 10.1.0.0 255.255.0.0 GigE0/1 | Exit interface specified. Route always installed while interface is up. On multi-access (Ethernet) links, causes proxy ARP for every destination — use next-hop IP instead on LAN interfaces. |
| Fully specified static | ip route 10.1.0.0 255.255.0.0 GigE0/1 192.168.1.1 | Both interface and next-hop. Best practice for Ethernet — no proxy ARP, route tied to interface state. Preferred form for most static routes. |
| Floating static | ip route 0.0.0.0 0.0.0.0 203.0.113.2 254 | Higher AD than primary route. Installed only when primary route is gone. Used for backup ISP, OOB management fallback. AD must be higher than the primary protocol's AD. |
| Null route (black hole) | ip route 10.0.0.0 255.0.0.0 Null0 | Drops traffic matching the prefix. Used to prevent routing loops with summary routes, or to discard traffic to unused address space. Null0 never goes down. |
| Default route | ip route 0.0.0.0 0.0.0.0 203.0.113.1 | Gateway of last resort. Matches any destination not found in the table. Redistributed into IGP with default-information originate (OSPF) or redistribute static. |
ECMP & load balancing
| concept | detail |
|---|---|
| ECMP | Equal-Cost Multi-Path — when multiple routes to same destination have equal metric and AD, router installs all in RIB and load-balances across them. Cisco default: 4 paths (up to 32 with maximum-paths). OSPF, EIGRP, BGP (with maximum-paths) all support ECMP. |
| Per-destination LB | CEF default. Each flow (src/dst IP pair) consistently uses the same path. Avoids packet reordering. Works well for many flows. May cause uneven distribution if traffic is dominated by a few large flows. |
| Per-packet LB | Each packet round-robins across paths. Maximum bandwidth utilization but causes packet reordering — bad for TCP. Not recommended for most traffic. Use per-destination or flow-based. |
| Unequal-cost LB | EIGRP only via variance multiplier. Routes within variance × best metric are included. Distributes traffic proportionally to metric. OSPF and BGP do not support unequal-cost LB natively. |
OSPF quick reference
| topic | detail |
|---|---|
| Neighbor States | |
| Down → Init → 2-Way | Down: no hellos received. Init: hello received, my RID not in neighbor's hello yet. 2-Way: bidirectional communication established — DR/BDR election happens here on broadcast/NBMA. DROther routers stop here with each other. |
| ExStart → Exchange → Loading → Full | ExStart: master/slave negotiation by RID. Exchange: DBD (database description) packets exchanged. Loading: LSR/LSU to fill gaps. Full: LSDBs synchronized. Adjacency complete. Only DR/BDR form Full with all neighbors on broadcast segments. |
| Timers & Requirements | |
| Hello / Dead interval | Broadcast/point-to-point: hello=10s, dead=40s. NBMA: hello=30s, dead=120s. Must match between neighbors. Configurable per-interface. Fast hellos possible (sub-second with BFD preferred). |
| Adjacency requirements | Must match: area ID, hello/dead timers, subnet mask (point-to-point exempt), MTU (can disable check), stub/NSSA flags, authentication. RID must be unique in domain. |
| Area Types | |
| Backbone (Area 0) | All areas must connect to Area 0. Inter-area traffic must transit Area 0. Virtual links used if physical connection to Area 0 is not possible. |
| Stub | No external (Type 5) LSAs. ABR injects default route. Reduces LSDB size. All routers in area must agree. Cannot have ASBR or virtual link. |
| Totally Stubby | Cisco extension. No Type 3 (inter-area) or Type 5 LSAs. Only default route from ABR. Smallest LSDB. Best for spoke sites with single ABR. |
| NSSA | Not-So-Stubby Area. Blocks Type 5 but allows Type 7 (NSSA external) LSAs from a local ASBR. ABR translates Type 7 → Type 5 at area boundary. Use when stub site needs to redistribute local routes. |
| Cost & DR/BDR | |
| Cost calculation | Cost = reference bandwidth ÷ interface bandwidth. Default ref BW = 100 Mbps → GigE = cost 1, FastE = cost 1 (same!). Always set auto-cost reference-bandwidth 10000 (10G) or higher to differentiate modern interfaces. Lower cost = preferred path. |
| DR/BDR election | On broadcast (Ethernet) and NBMA segments only. Highest OSPF priority wins (default 1, range 0–255). Tie: highest RID. Priority 0 = never DR/BDR. Election is non-preemptive — existing DR keeps role until it fails. Set priority on ABRs/core switches to control placement. |
redistribution & route filtering
| tool | function | applies to |
|---|---|---|
| Redistribution | ||
| redistribute | Injects routes from one protocol into another. Redistributed routes become external routes in the destination protocol (OSPF E2 by default, EIGRP external AD=170). Always use route-maps or prefix-lists to filter — never redistribute everything blindly. | OSPF, EIGRP, BGP, RIP, static, connected |
| Seed metric | Redistributed routes need a metric in the target protocol. OSPF defaults to 20 (E2). EIGRP requires explicit metric or default-metric — without it routes won't be redistributed. RIP defaults to 1. | EIGRP, RIP |
| Mutual redistribution | Redistributing between two IGPs in both directions risks routing loops and suboptimal paths. Use route-tags to mark redistributed routes and filter them from being re-redistributed back. Design carefully. | OSPF ↔ EIGRP, OSPF ↔ RIP |
| Filtering Tools | ||
| Prefix-list | Match routes by prefix and prefix length range. More flexible and readable than ACLs for route filtering. Processed in sequence order, implicit deny at end. Use le/ge for length ranges. | BGP, OSPF distribute-list, redistribution |
| Route-map | Match + set logic. Matches on prefix, AS-path, community, metric, tag, etc. Sets attributes (metric, next-hop, community, local-pref, weight). Used for redistribution, BGP policy, PBR. Implicit deny at end. | BGP, redistribution, PBR |
| distribute-list | Filters routes going into or out of a routing process. In = filters received updates (affects RIB). Out = filters what this router advertises. Can reference ACL or prefix-list. | OSPF, EIGRP, RIP |
| Summarization | Advertise one aggregate prefix instead of many specifics. Reduces routing table size, hides topology instability, limits LSA/update flooding. OSPF: area X range (ABR) or summary-address (ASBR). EIGRP: ip summary-address eigrp per interface. | OSPF, EIGRP, BGP |
⚠️ Redistribution gotcha: When redistributing into OSPF, routes become E2 (external type 2) by default — metric doesn't accumulate as traffic crosses routers. E1 routes add internal cost to external metric, giving more accurate path selection across the OSPF domain. Use E1 when the ASBR is not close to all destinations.
policy-based routing (PBR)
| concept | detail |
|---|---|
| What PBR does | Overrides normal destination-based routing (FIB lookup) to forward packets based on source IP, protocol, port, packet size, or DSCP marking. Applied inbound on an interface via a route-map. |
| Use cases | Dual ISP — route voice traffic via low-latency ISP, bulk data via cheaper ISP. Route traffic from a specific VLAN/subnet to a specific next-hop. Force management traffic out OOB interface. QoS-aware forwarding. |
| set ip next-hop | Forward to specified next-hop if reachable — if next-hop is unreachable, falls back to normal routing. Use set ip next-hop verify-availability with IP SLA for tracked failover. |
| set ip default next-hop | Only applies if no more specific route exists in routing table. Normal routing takes precedence. Good for defaulting traffic without overriding specific routes. |
| Local PBR | Applied to traffic originated by the router itself (not transit). Uses ip local policy route-map. Useful for routing control-plane traffic out specific interfaces. |
routing troubleshooting quick reference
| symptom | likely cause | check / fix |
|---|---|---|
| Route missing from table | AD conflict, protocol not redistributing, neighbor down, filtered out | show ip route X.X.X.X — is it in RIB? show ip protocols — check sources. Verify neighbor adjacency. Check distribute-list / prefix-list / route-map for filtering. Check AD — higher AD source loses. |
| OSPF stuck in ExStart/Exchange | MTU mismatch | Most common cause. ip ospf mtu-ignore on both sides to bypass, or fix MTU to match. Also check duplicate RIDs: show ip ospf neighbor — same RID on two routers = instability. |
| OSPF stuck in 2-Way (not Full) | DROther-to-DROther on broadcast segment — expected | Normal behavior. DROther routers only form Full adjacency with DR and BDR, not each other. Check DR/BDR election: show ip ospf neighbor — verify DR/BDR are correct routers. |
| Route flapping | Interface instability, BFD false positives, timer mismatch | show ip route X.X.X.X repeatedly. Check interface counters for errors. Verify hello/dead timers match. Check BFD thresholds. debug ip routing to see install/remove events. |
| Routing loop | Mutual redistribution without tags, split horizon disabled, bad summary | Traceroute shows packet bouncing. Check TTL expiry. Verify redistribution uses route-tags to prevent re-redistribution. Check null route covering summary is present. |
| Traffic taking wrong path | Unexpected AD winner, ECMP hash, PBR override, wrong metric | show ip route X.X.X.X — which source won? show ip cef X.X.X.X detail — which adjacency? Check for PBR: show ip policy. Verify OSPF cost or EIGRP metric on relevant interfaces. |
| Redistribution not working | Missing seed metric (EIGRP), route filtered, protocol not running on interface | EIGRP: check default-metric or metric in redistribute command. OSPF: verify redistribute ... subnets (missing subnets keyword = classful only). Check route-map permit/deny logic — implicit deny at end catches everything not matched. |
| Default route not propagating | Missing originate command, conditional not met | OSPF: default-information originate — by default only advertises if default route exists in RIB. Add always keyword to advertise unconditionally. EIGRP: redistribute static with default route present. |
🔍 Essential show commands:
show ip route · show ip route X.X.X.X · show ip protocols · show ip ospf neighbor · show ip ospf interface brief · show ip cef X.X.X.X detail · show ip policy · show ip prefix-list · debug ip routing (use carefully in production)quick reference
0
connected
1
static
20
eBGP
110 / 120
OSPF / RIP
Lower administrative distance wins when multiple protocols offer the same prefix. EIGRP 90 (internal) / 170 (external), iBGP 200, unreachable 255. Floating static = AD set above the IGP so it only installs on failover.
administrative distance — Cisco IOS / IOS-XE
| source | AD | notes |
|---|---|---|
| Connected | 0 | Directly connected interface — always preferred |
| Static | 1 | Manually configured. Use AD > 1 for floating statics |
| EIGRP Summary | 5 | Auto-summary routes generated by EIGRP |
| eBGP | 20 | External BGP — routes learned from external AS |
| EIGRP Internal | 90 | Routes within the same EIGRP AS |
| IGRP | 100 | Legacy — not used in modern networks |
| OSPF | 110 | All OSPF route types (intra, inter, external) |
| IS-IS | 115 | Intermediate System to Intermediate System |
| RIP | 120 | Routing Information Protocol — 15 hop max |
| EIGRP External | 170 | Routes redistributed into EIGRP from another protocol |
| iBGP | 200 | Internal BGP — routes from same AS |
| Unknown / Unreachable | 255 | Never installed in routing table |
AD is used to select between routes learned from different protocols to the same destination. Once the best source is selected, metric determines the best path within that protocol. AD is local to the router — it is never advertised.
Aruba AOS-CX preference values
| source | preference |
|---|---|
| Connected | 0 |
| Static | 1 |
| OSPF Intra-area | 110 |
| OSPF Inter-area | 110 |
| OSPF External Type 1 | 110 |
| OSPF External Type 2 | 110 |
| iBGP | 200 |
| eBGP | 20 |
Juniper JunOS preference values
| source | preference |
|---|---|
| Direct (connected) | 0 |
| Local | 0 |
| Static | 5 |
| OSPF Internal | 10 |
| IS-IS L1 | 15 |
| IS-IS L2 | 18 |
| RIP | 100 |
| iBGP | 170 |
| eBGP | 170 |
JunOS uses same preference for iBGP/eBGP — BGP local-preference and MED attributes differentiate paths instead.
floating static routes & route selection logic
| scenario | config | behavior |
|---|---|---|
| Primary static, OSPF backup | ip route 0.0.0.0/0 via 1.1.1.1 | Static (AD 1) wins over OSPF default (AD 110). Remove static to fall back to OSPF. |
| Floating static (OSPF primary) | ip route 0.0.0.0/0 via 2.2.2.1 200 | AD 200 loses to OSPF 110. Only installs if OSPF default disappears — classic backup route. |
| ECMP (equal-cost paths) | max-paths 4 | Same AD + same metric from same protocol = load balance across all paths. Per-flow or per-packet depending on config. |
| Redistribution AD conflict | OSPF redistributes BGP | Redistributed route enters OSPF as External — AD 110. Original eBGP route AD 20 still wins on that router. |
quick reference
20
eBGP AD
200
iBGP AD
TCP 179
BGP port
16 / 32-bit
AS number
Best-path order: Weight → Local-Pref → locally-originated → shortest AS-path → lowest origin → lowest MED → eBGP>iBGP → lowest IGP metric → oldest → lowest RID. Path-vector protocol; neighbors are manually configured.
iBGP vs eBGP
| property | iBGP | eBGP |
|---|---|---|
| AS relationship | Same AS | Different AS |
| Admin Distance | 200 | 20 |
| TTL (default) | 255 (multihop) | 1 (direct link) |
| Next-hop behavior | Unchanged | Set to self |
| Split horizon | Yes — no readvertise to iBGP | No restriction |
| Full mesh required? | Yes (or RR/confederation) | No |
| AS_PATH prepend | Not prepended | Prepends own AS on send |
BGP neighbor states
| state | meaning |
|---|---|
| Idle | Initial state — waiting to start TCP connection |
| Connect | TCP SYN sent — waiting for completion |
| Active | TCP failed — retrying. Often means no route to peer or ACL blocking port 179 |
| OpenSent | TCP up — OPEN message sent, waiting for peer OPEN |
| OpenConfirm | OPEN received — waiting for KEEPALIVE |
| Established | Session up — exchanging UPDATE messages |
best-path selection — in order
| # | attribute | prefer | notes |
|---|---|---|---|
| 1 | Weight | Highest | Cisco-proprietary, local to router. Not advertised. Default 0 (32768 for local origination) |
| 2 | Local Preference | Highest | Shared within AS via iBGP. Default 100. Use to prefer exit points from AS |
| 3 | Locally originated | Local wins | network/aggregate/redistribute originating on this router wins |
| 4 | AS_PATH length | Shortest | Count of AS numbers traversed. Prepend to make paths less preferred |
| 5 | Origin | IGP > EGP > ? | IGP (i) = network statement. EGP (e) = legacy. ? = redistributed |
| 6 | MED | Lowest | Multi-Exit Discriminator — hint to external AS which entry point to use. Compared only between same AS paths |
| 7 | eBGP over iBGP | eBGP wins | External routes preferred over internal |
| 8 | IGP metric to next-hop | Lowest | Cost to reach the BGP next-hop via IGP |
| 9 | Router ID | Lowest | Tiebreaker — prefer path from peer with lowest Router ID |
Remember: W-L-L-A-O-M-E-I-R — Weight, Local-pref, Locally-originated, AS-path, Origin, MED, eBGP, IGP metric, Router-ID. Or: "We Love Oranges As Oranges Mean Pure Refreshment."
BGP communities (well-known)
| community | value | effect |
|---|---|---|
| NO_EXPORT | 0xFFFFFF01 | Do not advertise beyond AS boundary (ok to iBGP) |
| NO_ADVERTISE | 0xFFFFFF02 | Do not advertise to any BGP peer |
| LOCAL_AS | 0xFFFFFF03 | Do not advertise outside local confederation sub-AS |
| BLACKHOLE | 65535:666 | RFC 7999 — signal upstream to blackhole traffic to prefix |
common BGP troubleshooting
| symptom | likely cause |
|---|---|
| Stuck in Active | No TCP to peer — check route to peer IP, ACL on port 179, MD5 auth mismatch |
| Session flapping | Keepalive/hold timer mismatch, unstable link, MTU issues on TCP session |
| Routes not received | Missing network statement, no redistribute, outbound route-map filtering |
| Routes not installed | Next-hop unreachable (iBGP — use next-hop-self), not best path, AD too high |
| Route not advertised | Inbound/outbound prefix-list or route-map blocking, community NO_EXPORT set |
quick reference
longest-prefix
1st
lowest AD
2nd
lowest metric
3rd
ECMP
equal cost
Route selection order: most-specific prefix always wins (regardless of AD) → lowest administrative distance picks the protocol → lowest metric picks the path within it → equal cost load-balances (ECMP).
path selection order — how the RIB picks a route
1. Longest prefix match — most specific route always wins regardless of source. /32 beats /24 beats /0
2. Administrative Distance — if same prefix from multiple protocols, lowest AD wins (connected=0, static=1, eBGP=20, OSPF=110...)
3. Metric — within same protocol, lowest metric wins (OSPF cost, EIGRP composite, RIP hop count)
4. ECMP — if same prefix, same AD, same metric → load balance across all equal-cost paths
5. Policy (PBR) — policy-based routing bypasses RIB lookup entirely based on ACL match
OSPF cost calculation
| interface speed | default cost |
|---|---|
| 100 Mbps | 1 |
| 1 Gbps | 1 |
| 10 Gbps | 1 |
| 10 Mbps | 10 |
| 1.544 Mbps (T1) | 64 |
| 768 Kbps | 133 |
Formula: Cost = Reference BW / Interface BW. Default reference = 100 Mbps — everything ≥100M gets cost 1. Set
auto-cost reference-bandwidth 10000 on all routers to differentiate GE/10GE/100GE.
ECMP & load balancing
| method | behavior |
|---|---|
| Per-destination | Hash on src+dst IP — same flow always takes same path. Default on most platforms. |
| Per-packet | Alternate packets across paths. Can cause out-of-order delivery — avoid for TCP. |
| Per-flow (5-tuple) | Hash on src IP, dst IP, protocol, src port, dst port. Best distribution, no reordering. |
| Unequal (EIGRP) | variance command — install paths up to N× the best metric. Distributes based on metric ratio. |
policy-based routing (PBR)
| use case | match | action | example |
|---|---|---|---|
| Traffic steering by source | Source IP ACL | Set next-hop | Send 10.10.0.0/24 users out ISP-A, others out ISP-B |
| QoS marking | DSCP / ACL | Set IP precedence / DSCP | Mark VoIP traffic before entering WAN |
| Application steering | Port / protocol | Set next-hop | Send TCP/443 to direct internet, TCP/1433 via MPLS |
| SD-WAN path override | App-ID / DSCP | Path preference | Force real-time traffic to lowest-latency path regardless of routing table |
PBR is applied inbound on the interface and evaluated before the routing table lookup. It's powerful but adds complexity — use route-maps with permit/deny carefully. Always include a
set ip default next-hop fallback to avoid black-holing traffic if the PBR next-hop goes down.quick reference
overlay
transport-agnostic
app-aware
routing
ZTP
zero-touch
SLA
path select
SD-WAN builds an encrypted overlay across any underlay (MPLS + broadband + LTE/5G), steering apps by real-time SLA (loss/latency/jitter). A central controller pushes policy; zero-touch provisioning onboards branches.
SD-WAN architecture — key components
Edge Device (CPE)
Branch router/appliance. Terminates overlay tunnels, applies SLA policies, performs app-aware routing. Cisco vEdge/cEdge, Aruba EdgeConnect, VMware SD-WAN Edge, Fortinet FortiGate.
Controller (vSmart)
Centralized control plane. Distributes routing policy, SLA policies, and crypto keys to all edges. OMP (Overlay Management Protocol) on Cisco. Runs in cloud or on-prem.
Orchestrator (vBond)
Initial authentication and NAT traversal. Helps edges discover controllers and each other. Must be reachable from all sites — typically cloud-hosted.
Management (vManage)
GUI + REST API for config, monitoring, and templates. Zero-touch provisioning (ZTP). Dashboard for SLA compliance, circuit health, and app performance.
vendor comparison
| vendor / platform | control plane | overlay | app identification | cloud integration | best for |
|---|---|---|---|---|---|
| Cisco Catalyst SD-WAN (formerly Viptela) |
OMP / vSmart | IPsec / DTLS | NBAR2 + DPI | AWS, Azure, GCP via Cloud OnRamp | Cisco-heavy WAN replacement, service provider managed SD-WAN |
| Aruba EdgeConnect (Silver Peak) |
Orchestrator SaaS | IPsec | First-packet iQ DPI | Direct cloud breakout + Aruba Central | Application-first WAN, existing Aruba campus networks |
| VMware VeloCloud (Broadcom) |
VCO (cloud) | VCMP (UDP) | DPI + Cloud Intelligence | VeloCloud Gateways as PoPs | Multi-tenant MSP deployments, VMware environments |
| Fortinet Secure SD-WAN | FortiManager / FortiOS | IPsec | FortiGuard ISDB | FortiSASE, direct breakout | Security-first WAN, NGFW consolidation at branch |
| Palo Alto Prisma SD-WAN (CloudGenix) |
Prisma Cloud controller | IPsec | App-ID (Palo Alto) | Prisma Access SASE | SASE-first strategy, Palo Alto security stack |
SLA policy — path steering logic
| step | action |
|---|---|
| 1 | Continuous BFD/probe measurements per transport path (latency, jitter, loss) |
| 2 | Application identified via DPI (first packet or session) |
| 3 | SLA policy matched — e.g. VoIP requires <150ms latency, <1% loss |
| 4 | Paths scored against SLA thresholds — compliant paths eligible |
| 5 | Best path selected (lowest latency, or ECMP across compliant paths) |
| 6 | If no path meets SLA — use best available or drop (configurable) |
MPLS vs SD-WAN tradeoffs
| factor | MPLS | SD-WAN over internet |
|---|---|---|
| Cost | High (carrier-managed) | 60–80% lower |
| Latency | Guaranteed, predictable | Variable — SLA policies compensate |
| Bandwidth | Limited, expensive to scale | Easy to scale with broadband/LTE/5G |
| Security | L3 isolation (not encrypted) | IPsec encryption on all paths |
| Cloud access | Hairpin via HQ or co-lo | Direct internet breakout per branch |
| Provisioning | Weeks (carrier lead time) | Hours (ZTP + broadband) |
| Visibility | Limited (carrier managed) | Per-app, per-path, real-time |
© 2026 netslice.net · v2.2.0
built for network engineers and the curious