I’m going to turn our attention to a popular and sometimes confusing exam topic, and let Tuesday’s discussion and polls regarding one possible value of certifications for Cisco customers percolate for a few more days. Specifically, we’ll spend a few posts (at least) considering the issues related to what numbers sit inside the frames/packets/segments that flow in a network, specifically data link addresses, IP addreses, and TCP/UDP port numbers. This topic was one of the most requested from a survey a few weeks back, where I asked where you wanted to go with the technical topics in this blog.
The concepts related to addressing and port numbers deserves some attention both for exam prep and for real life. First, the CCNA exam topics include two direct references to these concepts. Second, several other important exam topics require this same knowledge as background information. For example, you have to understand what port numbers are used, for packets in each direction between two hosts, before you can correctly configure an access-list to match those packets. And probably more importantly, for real life, most problem analysis that happens in a network requires the knowledge of which addresses/port numbers should be in a packet. These concepts really should become second nature once you’ve worked in a network engineering job for a while.
While the discussions of the why’s and wherefore’s are probably more important, I’ll get us started with a sample question, which hopefully gives some of you a little practice, and it’ll give me some context in which to describe the important parts in the coming posts. I also think that it would be useful to take a survey of how long it’s taking you to come up with your answer, so I’ll put in a survey about that as well:
OK, start your timer if you plan to answer the survey. Here’s the question:
Question: The user of PC1 opens a web browser and successfully connects to the web server at the bottom of the figure. An engineer uses a network analysis tool to capture packets as they cross the cables labeled “2” and “4”. The engineer looks at a single packet, sent by the server to PC1, at both points in the network. Which of the following is true regarding this one packet, as viewed at these two points in the network? (Note that unless otherwise labeled, the links do not use LAN trunking.)
A) At “2”, the source MAC address is the web server’s MAC address.
B) At “2”, the source port number is well-known port 80.
C) At “4”, the destination IP address is one of R1’s IP addresses.
D) At “4”, the destination MAC address is PC1’s MAC address.
E) At “4”, the destination MAC address is one of R1’s MAC addresses.

As usual, feel free to comment and inquire, but try to avoid giving away the answer in the title of your post, so others won’t accidentally get a hint. Thanks…




