BGP Routing Protocol Practice Lab 01

 

BGP Routing Protocol Practice Lab 01



Lab 1: MED and AS-Path Prepend


Basic configuration

R1:

interface Loopback0

ip address 1.1.1.1 255.255.255.255

!

interface FastEthernet0/0 
ip address 150.1.1.1 255.255.255.0
 no shut

!

interface Serial0/0

ip address 10.0.0.1 255.255.255.252

no shut

R2:

interface Loopback0

ip address 2.2.2.2 255.255.255.255

!

interface Loopback192

ip address 192.1.1.1 255.255.255.0

!

interface Loopback193

ip address 193.1.1.1 255.255.255.0

!

interface Loopback194

ip address 194.1.1.1 255.255.255.0

!

interface Loopback195

ip address 195.1.1.1 255.255.255.0

!

interface Serial0/0

ip address 10.0.0.2 255.255.255.252

no shut !

interface Serial0/1

ip address 10.0.0.9 255.255.255.252

no shut



R3:

interface Loopback0

ip address 3.3.3.3 255.255.255.255

!

interface FastEthernet0/0 ip address 150.3.3.3 255.255.255.0 no shut

!

interface Serial0/1

ip address 10.0.0.10 255.255.255.252

no shut !

interface Serial0/2

ip address 10.0.0.13 255.255.255.252

no shut !

interface Serial0/3

ip address 10.0.0.17 255.255.255.252

no shut




R4:


interface Loopback0

ip address 4.4.4.4 255.255.255.255

!

interface FastEthernet0/0 ip address 150.1.1.4 255.255.255.0 no shut

!

interface Serial0/0

ip address 10.0.0.14 255.255.255.252

no shut !

interface Serial0/1

ip address 10.0.0.18 255.255.255.252

no shut




Configure BGP as illustrated in the topology. Use the Loopback 0 addresses for peering. Do NOT configure any IGPs. Instead, use static routes only. R1 should peer with R2 and R4. R2 should peer with R1 and R3. R3 should peer with R2 and R4. R4 should peer with R1 and R3.



R1(config)#ip route 2.2.2.2 255.255.255.255 serial 0/0

R1(config)#ip route 4.4.4.4 255.255.255.255 fastethernet 0/0 150.1.1.4

R1(config)#router bgp 1

R1(config-router)#neighbor 2.2.2.2 remote-as 2

R1(config-router)#neighbor 2.2.2.2 update-source loopback 0

R1(config-router)#neighbor 2.2.2.2 ebgp-multihop 3

R1(config-router)#neighbor 4.4.4.4 remote-as 4

R1(config-router)#neighbor 4.4.4.4 update-source loopback 0

R1(config-router)#neighbor 4.4.4.4 ebgp-multihop 3



R2(config)#ip route 1.1.1.1 255.255.255.255 serial 0/0

R2(config)#ip route 3.3.3.3 255.255.255.255 serial 0/1

R2(config)#router bgp 2

R2(config-router)#neighbor 1.1.1.1 remote-as 1

R2(config-router)#neighbor 1.1.1.1 update-source loopback 0

R2(config-router)#neighbor 1.1.1.1 ebgp-multihop 3

R2(config-router)#neighbor 3.3.3.3 remote-as 3

R2(config-router)#neighbor 3.3.3.3 update-source loopback 0

R2(config-router)#neighbor 3.3.3.3 ebgp-multihop 3




R3(config)#ip route 2.2.2.2 255.255.255.255 serial 1/1

R3(config)#ip route 4.4.4.4 255.255.255.255 serial 1/2

R3(config)#ip route 4.4.4.4 255.255.255.255 serial 1/3

R3(config)#router bgp 3

R3(config-router)#neighbor 2.2.2.2 remote-as 2

R3(config-router)#neighbor 2.2.2.2 update-source loopback 0

R3(config-router)#neighbor 2.2.2.2 ebgp-multihop 3

R3(config-router)#neighbor 4.4.4.4 remote-as 4

R3(config-router)#neighbor 4.4.4.4 update-source loopback 0

R3(config-router)#neighbor 4.4.4.4 ebgp-multihop 3




R4(config)#ip route 1.1.1.1 255.255.255.255 fastethernet 0/0 150.1.1.1

R4(config)#ip route 3.3.3.3 255.255.255.255 serial 0/0

R4(config)#ip route 3.3.3.3 255.255.255.255 serial 0/1

R4(config)#router bgp 4

R4(config-router)#neighbor 1.1.1.1 remote-as 1

R4(config-router)#neighbor 1.1.1.1 update-source loopback 0

R4(config-router)#neighbor 1.1.1.1 ebgp-multihop 3

R4(config-router)#neighbor 3.3.3.3 remote-as 3

R4(config-router)#neighbor 3.3.3.3 update-source loopback 0

R4(config-router)#neighbor 3.3.3.3 ebgp-multihop 3




In order to ensure that the ORIGIN code is INCOMPLETE, you need to redistribute the LAN subnets into BGP. However, you can also use the network statement in conjunction with a route map and set the ORIGIN code within the route map.



R1(config)#route-map CONNECTED permit 10

R1(config-route-map)#match interface fastethernet 0/0

R1(config-route-map)#exit

R1(config)#route-map CONNECTED deny 20

R1(config-route-map)#exit

R1(config)#router bgp 1

R1(config-router)#redistribute connected route-map CONNECTED R1(config-router)#exit





You can verify the ORIGIN code by looking at the prefix entry in the BGP Tables. The ORIGIN code of INCOMPLETE is denoted by a question mark (?) in the output of the show ip bgp command. You can view additional detail on a per-prefix basis also when using this command



show ip bgp


show ip bgp


show ip bgp

show ip bgp




Configure BGP, so that R4 prefers the path via R3 to reach any subnet

In the output of the show ip bgp command on R4 we can see that the preferred route to reach 150.3.3.0 is via R3, however the preferred route to reach 150.2.2.0 is via R1 (the lowest routerid), also, to ensure that the subnet 150.1.1.0 will be reached via R3, configure BGP on R1 to advertise all prefixes with a longer AS-PATH to influence the path selection as follow:




R1(config)#route-map PREP permit 10

R1(config-route-map)#set as-path prepend 1 1 1 1 R1(config-route-map)#exit

R1(config)#router bgp 1

R1(config-router)#neighbor 4.4.4.4 route-map PREP out R1(config-router)#exit



Notice now the preferred path to reach both prefixes 150.3.3.0 and 150.2.2.0 is via R3 with the next-hop 3.3.3.3 because the shortest AS-PATH length:



do show ip bgp



Configure R4 so that it sends all updates to R3 with a MED of 4. Configure R2 so that it sends all updates to R3 with a MED of 2. Ensure that R3 prefers all routes with the better (lower) MED value.

Before configuring the MED let's verify the BGP RIBs on R3:

The preferred path to reach the prefix 150.1.1.0 is via R4, we should see all routes with the next-hop R2:





Let's configure MED




Let's configure MED on R3:

R4(config)#route-map MED permit 10

R4(config-route-map)#set metric 4

R4(config-route-map)#exit

R4(config)#router bgp 4

R4(config-router)#neighbor 3.3.3.3 route-map MED out

R4(config-router)#exit



R2(config)#route-map MED permit 10

R2(config-route-map)#set metric 2

R2(config-route-map)#exit

R2(config)#router bgp 2


R2(config-router)#neighbor 3.3.3.3 route-map MED out

R2(config-router)#exit





Let's verify the BGP RIBs of R3:

We have still the best path to reach 150.1.1.0 via R4 as shown by the show ip bgp command on R3 below, so the problem is not resolved even if R2 advertises the lowest MED comparing with R4.

The reason is: we met two issues in this case:

-the first issue is: by default, the MED is only compared for path received from the same AS ,in this case R3 receives two values of MED from two routers (R2 and R4) configured in different AS.

-The second issue: the MED is compared after the AS-PATH in the BGP decision process. In this case R3 will select the path via R4 as the best path to the 150.1.1.0/24 prefix because of the shorter AS-PATH length.



BGP MED




To override the two issues, configure the bgp always-compare-med command to avoid the first issue so always compare the MED even if MED is received from Different AS. And bgp bestpath as-path ignore command to avoid the second issue so that R3 override the BGP decision process by ignoring the step of the AS-PATH in the BGP Decision Process:

Let's configure these two commands:



R3(config)#router bgp 3

R3(config-router)#bgp bestpath as-path ignore R3(config-router)#bgp always-compare-med



We can see for the prefix 150.1.1.0 that the path with the longer AS-PATH length is preferred because the lowest MED even if the AS-PATH takes precedence over the MED in the order of the path selection in BGP:


BGP



Another way to verify all BGP RIBs with do show ip bgp, R3 prefers all routes from R2 because the lowest MED:





#BGP #LAB #CCNA #CCNP #CCIE #cisco #gns3 #solution

















Understanding the OSI model

 In this lesson, we explain what the OSI model is in an easy and understandable language. It is one of the most important concepts in networking, so we break it down into pieces to help you understand exactly what its purpose is.

What is data encapsulation?

To understand the OSI model, you must first understand what data encapsulation is. Let's explore the following example. Imagine you want to send a letter to a friend who lives in another city to invite him to your wedding. What if you send the letter without an envelope, with any information, such as the sender's and recipient's names, addresses, and postcodes? What if you simply write the letter and drop it in the mailbox at the post office? 





Most readers of this CCNA course are so young that they've never sent a physical letter in their lives. They live in the digital age and have grown up with emails and instant text messages. However, surprisingly, everyone understands the concept of the post service and sending mail.

Let's examine the following two examples: a letter without an envelope (on the left) and one placed inside an envelope with all required information written on top (on the right). If you put those two into your mailbox, which one will reach its intended recipient and which one won't?



#cisco #networking #OSI #model

It is pretty obvious, right? If you send a letter with no envelope and no additional information, such as sender and recipient details, the postal service won't know where to deliver it. The letter won't reach anyone. Your friend won't show up at your wedding.

To ensure that the information (the letter) is delivered to the correct recipient, we must include additional information alongside the letter, so that the postal service knows how to handle it (we encapsulate the data).



The envelope that encapsulates the letter contains the following information, which helps the postal service deliver the letter correctly:

  • Stamp and postcard
  • Sender's name
  • Sender's address
  • Sender's postcode
  • Recipient's name
  • Recipient's address
  • Recipient's postcode

Optionally, the envelope may include:

  • Return address (if different from the sender’s address)
  • Date and time stamp
  • Subject or reference line inside the letter (in formal letters)

The main idea is that sending letters equals sending information by utilizing the postal service as the medium. Sending emails is the same—it’s still a process of sending information, but through a computer network. The key point is that in both cases, you can’t send just the information alone; you need to include extra details that tell the transporting medium how to deliver the information.



Data Encapsulation in Networking

Computer networks function similarly to the postal service. The difference is that they move digital information instead of paper letters. However, you can’t just send raw data onto the network and expect it to reach the destination, just like you can’t drop a plain letter into a mailbox and expect it to be delivered. The data must be encapsulated with additional information first, as shown in the diagram below.







Imagine a device (like your laptop) wants to send data onto the network. Let's say you're sending a Facebook message to a friend. As you type the message and hit enter, the data goes from the web browser (where you have Facebook opened), to the Operating System (OS), to the NIC, and out to the network. Many processes add their own additional information called headers. These headers contain important details, like:

  • Who the data is for.
  • Where did it come from?
  • How it should be delivered.
  • What type of data is it?

In the end, the simple Facebook message "Hey! What's up?" looks like a network packet encapsulated with multiple headers, as shown in the diagram below.



At the destination, the data undergoes the reverse process of removing headers before the it is presented to the correct application.

Why do we need the OSI model?

The process of data encapsulation is not simple. It involves many different protocols, headers, and steps. Each part of a network—like applications, network devices, and physical mediums—needs to know what to do with the data and how to handle it correctly.

In the early days of networking, different companies built their own systems, using their own encapsulation methods. These systems often couldn’t work together because they didn’t follow the same rules. For example, one vendor might add certain headers in a unique order that another vendor's device couldn't understand. This made it hard to send data between different networks or even between devices from the same company.

Additionally, to achieve the ultra-high speeds of today's networks, network devices must precisely locate the information they need, without examining headers that are irrelevant, as shown in the diagram below.

.

To fix this, engineers realized that the industry needed a standard framework. They needed a common way to describe how data should be prepared, sent, and received. That’s where the OSI model comes in.

The OSI model gives a step-by-step structure for how data encapsulation should work:

  • Each layer has a specific job, like adding source and destination addresses or checking for errors.
  • Each layer uses specific protocols that follow agreed-upon rules.
  • Each layer adds its own header (and sometimes trailer) to the message, so the receiving system knows how to process it.

In short, the OSI model helps manage the complexity of data encapsulation by providing a clear, standard method that everyone in networking can use. This ensures interoperability, consistency, and easier troubleshooting.

The OSI model helps us understand and explain how data is wrapped up layer by layer (encapsulation), and how it's unwrapped at the other end (de-encapsulation).

What is the OSI model?

The OSI model, or Open Systems Interconnection model, is a framework that breaks down the encapsulation process into seven layers. Each layer has a specific role and handles a part of the encapsulation, such as data formatting, logical addressing, routing, physical addressing, or error checking.

The following example shows how data moves through the OSI layers and gets wrapped at each step before being sent over the network to the next device. Notice that each layer adds its own specific header with relevant information for the network function.




The primary goal of the OSI model is to establish a standard and vendor-agnostic data encapsulation framework. It helps different devices and systems work together by following the same set of rules and standards. 

The following diagram illustrates each layer, with a brief description and the protocols that operate at that layer. Notice that in general, different network devices operate at different layers of the OSI model. This means that a network device cares only for the headers up to a particular layer and doesn't care about the rest of the headers in the message. For example, a switch only cares about the data link (layer 2) header, which consists of the source and destination MAC addresses. A router cares only about the layer 2 and layer 3 headers, and so on.







Note also that we refer to the data at each layer of the OSI model with a different term. For example, at layer 4, we refer to a TCP message as a segment. At layer 3, we refer to it as a packet. At layer 2, we refer to it as a frame.

The OSI model vs. TCP/IP model

The OSI model, with its seven layers, is a well-structured and useful way to understand how data encapsulation works. However, network engineers quickly notice that layers 5, 6, and 7 are not directly related to most networking tasks. These layers focus more on how software applications handle data, which is usually outside the scope of networking.

As a result, network professionals, through practice and real-world experience, began using a simpler model that focuses on the aspects that matter most to networking—Layers 1 through 4. This led to the development of the TCP/IP model, which has fewer layers and is more aligned with how networks actually operate.

The following diagram shows a comparison of the OSI model (with 7 layers), the first version of TCP/IP (which had 4 layers), and the modern version of the TCP/IP model (with 5 layers).


The modern 5-layer TCP/IP model uses the same names as the OSI model for the lower layers, and their jobs are very similar. So, when reading about networks or talking to others in the field, you can think of the lower four layers as being the same in both models- OSI and TCP/IP.

For this course, make sure you understand how the 5-layer TCP/IP model maps to the 7-layer OSI model (as shown in both ends of the diagram above). Also, remember that when people refer to “Layer 7,” they typically mean the top layer in both models, which handles applications.

For example, you will often hear one of the following phrases that you must understand:

  •  "Do you need a layer 2 or a layer 3 port?"
  •  "Is this a layer 2 or layer 3 switch?"
  •  "The problem is at layer 2."

Although networks today use TCP/IP, many people still refer to OSI layer numbers. For example, people call an application protocol a “Layer 7 protocol,” even though TCP/IP combines some of those OSI layers (application, presentation, and session) into just one.



Key Takeaways on the OSI Model

  • The OSI model is a theoretical framework that breaks down the data encapsulation process into seven layers
  • Each layer describes the information included in the message as a header.
  • The OSI model remains widely used to teach networking and explain how protocols function. 
  • However, while Cisco includes the OSI model in the CCNA/CCNP exams, knowing more than the basics isn’t very useful in real-world networking today. 
  • It’s essential to know the first four layers as they are the ones that concern network engineers the most.

How ARP Works: Understanding ARP Requests, Replies, and ARP Cache

 How ARP Works: Understanding ARP Requests, Replies, and ARP Cache


Address Resolution Protocol (ARP) is an essential protocol in the world of networking. It's responsible for mapping IP addresses to MAC addresses within a local area network (LAN).


🔄 How ARP Works

When a host wants to communicate with another device, it needs the MAC address associated with the destination IP. If the MAC address is unknown, the host sends out a broadcast ARP Request asking:
🗨️ “Who has IP address X.X.X.X? Tell me your MAC address.”

The device with the matching IP sends an ARP Reply with its MAC address, allowing communication to begin.


📨 ARP Messages

ARP uses two packet types:

  • ARP Request

    • Destination MAC: FF-FF-FF-FF-FF-FF (broadcast)

    • Target MAC: 00-00-00-00-00-00 (unknown)

  • ARP Reply

    • Uses unicast MAC addresses for both source and destination

Header Fields Include:

  • Source MAC and IP

  • Target MAC and IP


🧪 Real-World Examples

  1. Host-to-Host on Same Network
    PC2 wants to send data to PC3 (192.168.1.3), sends an ARP request, and receives PC3’s MAC address in reply.

  2. Host-to-Remote Host via Gateway
    PC2 needs to reach Google, checks its default gateway (192.168.1.1), sends ARP request for it, and receives Router1’s MAC address.

  3. Router-to-Host on Local Network
    Router receives data destined for a host on its connected LAN, sends ARP request to resolve the host's MAC.

  4. Router-to-Next-Hop in Another Network
    Router2 resolves next-hop IP address (e.g., 34.43.12.1) via ARP to forward the packet.


🧾 ARP Table (Cache)

Once a MAC is resolved, it's stored in the ARP table (cache) to prevent future broadcasts.

  • Default timeout: 240 minutes (can be configured)

  • Check ARP cache:

    • On Windows/Unix: arp -a in command prompt


💡 Final Thoughts

ARP quietly enables devices to communicate in every modern IP network. Understanding its role, message types, and cache behavior helps build a solid foundation for network troubleshooting and design.

Understanding Cisco SD-WAN Architecture: A Deep Dive into Control and Management Plane Functions

 Cisco SD-WAN revolutionizes network management by decoupling the control and management planes from WAN edge routers, centralizing them in software-based controllers. This architectural shift improves security, availability, and scalability, making Cisco SD-WAN a preferred choice for managing large and distributed networks.

In this blog post, we’ll explore the roles of vEdge routers and the SD-WAN controllers, namely vSmart, vManage, and vBond, each of which interacts with WAN edge devices in unique ways to ensure secure, streamlined, and reliable control connections.

Control Connections and Security Protocols

Each vEdge router establishes secure control connections to SD-WAN controllers using DTLS or TLS protocols. DTLS, which operates over UDP, is the default protocol due to its efficiency and speed, while TLS, running over TCP, provides slightly enhanced reliability. These protocols create secured tunnels that shield the control plane protocols (such as OMP, NETCONF, and SNMP) from security vulnerabilities by running them over encrypted channels.

Controller Roles Explained

  • vSmart acts as the central brain of the network, handling routing information and distributing policy-driven paths via the Overlay Management Protocol (OMP).
  • vManage is the configuration hub, interacting with vEdges through protocols like NETCONF, SNMP, and ICMP for configuration management and monitoring.
  • vBond serves as the orchestrator, assisting newly connected routers in finding their respective SD-WAN controllers and ensuring they securely join the network.

Deployment Options and Control Connections

For a new vEdge router, there are several options for connecting to the Cisco SD-WAN overlay, including Zero-Touch Provisioning (ZTP), Plug-and-Play (PnP), and manual CLI configuration. Once connected, each router establishes a DTLS/TLS tunnel to vSmart and vManage for ongoing management and control, ensuring a resilient network fabric.

Control Plane Overview and Data Plane Connections

Each WAN edge device in the SD-WAN fabric initiates IPsec tunnels across remote locations. Cisco SD-WAN’s overlay design uses these encrypted data plane tunnels for secure data transmission across the network. This approach allows organizations to achieve high performance and reliability across geographically distributed networks.

Whether you're working on a new Cisco SD-WAN deployment or seeking a better understanding of secure control plane connections, Cisco SD-WAN architecture provides the flexibility and security required in today’s dynamic network environments.

Stay tuned for more networking insights!





ipv4 subnetting

In this blog post, we dive deep into the art of subnetting IPv4 addresses, a crucial skill for network administrators and engineers. We start with the fundamentals of subnetting, explaining how IP addresses are divided into network and host portions. The post includes a variety of practice questions, each accompanied by detailed explanations to help you master the concepts. Whether you're preparing for certification exams or just brushing up on your skills, this guide will provide you with the knowledge and confidence you need to tackle subnetting challenges.


#Subnetting #IPv4 #Networking #IP Addressing #CCNA #Network Administration #IT_Certification #Practice Questions #NetworkEngineering #Subnetting #Explained


(Solutions Provided at End)

Question #1

What is the range of assignable IP addresses for a subnet containing an IP address of 172.16.1.10 /19?

a. 172.16.0.1 – 172.16.31.254

b. 172.16.0.1 – 172.16.63.254

c. 172.16.0.0 – 172.16.31.255

d. 172.16.0.1 – 172.16.31.255

e. 172.16.0.0 – 172.16.63.254

Question #2

You are assigning IP addresses to hosts in the 192.168.4.0 /26 subnet. Which two of the following IP addresses are assignable IP addresses that reside in that subnet?

a. 192.168.4.0

b. 192.168.4.63

c. 192.168.4.62

d. 192.168.4.32

e. 192.168.4.64

Question #3

A host in your network has been assigned an IP address of 192.168.181.182 /25. What is the subnet to which the host belongs?

a. 192.168.181.128 /25

b. 192.168.181.0 /25

c. 192.168.181.176 /25

d. 192.168.181.192 /25

e. 192.168.181.160 /25

Question #4

You are working with a Class B network with the private IP address of 172.16.0.0 /16. You need to maximize the number of broadcast domains, where each broadcast domain can accommodate 1000 hosts. What subnet mask should you use?

a. /22


b. /23

c. /24

d. /25

e. /26

Question #5

What is the directed broadcast address of a subnet containing an IP address of 172.16.1.10 /19?

a. 172.16.15.255

b. 172.16.31.255

c. 172.16.255.255

d. 172.16.95.255

e. 172.16.0.255

Question #6

A customer is using a Class C network of 192.168.10.0 subnetted with a 28-bit subnet mask. How many subnets can be created by using this subnet mask?

a. 32

b. 16

c. 30

d. 8

e. 14

Question #7

Given a subnet of 172.16.56.0 /21, identify which of the following IP addresses belong to this subnet. (Select 2.)

a. 172.16.54.129

b. 172.16.62.255

c. 172.16.61.0

d. 172.16.65.255

e. 172.16.64.1

Question #8

What is the subnet address of the IP address 192.168.5.55 with a subnet mask of 255.255.255.224?

a. 192.168.5.0 /27

b. 192.168.5.16 /27

c. 192.168.5.32 /27

d. 192.168.5.48 /27

e. 192.168.5.64 /27


Question #9

You are working for a company that will be using the 192.168.1.0 /24 private IP address space for IP addressing inside their organization.

They have multiple geographical locations and want to carve up the 192.168.1.0 /24 address space into subnets. Their largest subnet will need 13 hosts.

What subnet mask should you use to accommodate at least 13 hosts per subnet, while maximizing the number of subnets that can be created?

a. 255.255.255.248

b. 255.255.255.224

c. 255.255.255.252

d. 255.255.255.192

e. 255.255.255.240

Question #10

A customer is using a Class C network of 192.168.10.0 subnetted with a 28-bit subnet mask. How many assignable addresses are available in each of the subnets?

a. 32

b. 16

c. 30

d. 8

e. 14

Question #11

An IP address of 192.168.0.100 /27 belongs to which of the following subnets?

a. 192.168.0.92

b. 192.168.0.128

c. 192.168.0.64

d. 192.168.0.96

e. 192.168.0.32

Question #12

What subnet mask should be used to subnet the 192.168.10.0 network to support the number of subnets and IP addresses per subnet shown in the following topology?


a. 255.255.255.0

b. 255.255.255.128

c. 255.255.255.192

d. 255.255.255.224

e. 255.255.255.240


Solutions

Question #1

What is the range of assignable IP addresses for a subnet containing an IP address of 172.16.1.10 /19?

a. 172.16.0.1 – 172.16.31.254

b. 172.16.0.1 – 172.16.63.254

c. 172.16.0.0 – 172.16.31.255

d. 172.16.0.1 – 172.16.31.255

e. 172.16.0.0 – 172.16.63.254

Answer: a

To determine the subnets, assignable IP address ranges, and directed broadcast addresses created by the 19-bit subnet mask we perform the following steps:

Step #1: Identify the interesting octet (i.e. the octet that contains the first zero in the binary subnet mask).

In this question, we have a 19-bit subnet mask, which is written in binary as:

11111111 11111111 11100000 00000000

The interesting octet is the third octet, because the third octet (i.e. 11100000) is the first octet to contain a 0 in the binary.

Step #2: Identify the decimal value in the interesting octet of the subnet mask.

A 19-bit subnet mask can be written in dotted decimal notation as: 255.255.224.0

Since the third octet is the interesting octet, the decimal value in the interesting octet is 224.

Step #3: Determine the block size by subtracting the decimal value of the interesting octet from 256.

Block Size = 256 – 224 = 32

Step #4: Determine the subnets by counting by the block size in the interesting octet, starting at 0.

Placing a zero in the first interesting octet identifies the first subnet as:

172.16.0.0 /19


We then count by the block size (of 32) in the interesting octet (the third octet in this question) to determine the remaining subnets:

172.16.32.0 /19

172.16.64.0 /19

172.16.96.0 /19

172.16.128.0 /19

172.16.160.0 /19

172.16.192.0 /19

172.16.224.0 /19

Step #5: Identify the subnet address, the directed broadcast address, and the usable range of addresses.

Looking through the subnets created by the 19-bit subnet mask reveals that the IP address of 172.16.1.10 resides in the 172.16.0.0 /19 subnet.

The directed broadcast address, where all host bits are set to a 1, is 1 less than the next subnet address.

The next subnet address is 172.16.32.0. So, the directed broadcast address for the 172.16.0.0 /19 subnet is 1 less than 172.16.32.0, which is:

172.16.31.255

The usable IP addresses are all the IP addresses between the subnet address and the directed broadcast address. Therefore, in this example, the assignable IP address range for the 172.16.0.0 /19 network is:

172.16.0.1 – 172.16.31.254

Question #2

You are assigning IP addresses to hosts in the 192.168.4.0 /26 subnet. Which two of the following IP addresses are assignable IP addresses that reside in that subnet?

a. 192.168.4.0

b. 192.168.4.63

c. 192.168.4.62

d. 192.168.4.32

e. 192.168.4.64

Answer: c and d

To determine subnets and usable address ranges created by the 26-bit subnet mask we perform the following steps:


Step #1: Identify the interesting octet (i.e. the octet that contains the first zero in the binary subnet mask).

In this question, we have a 26-bit subnet mask, which is written in binary as:

11111111 11111111 11111111 11000000

The interesting octet is the forth octet, because the forth octet (i.e. 11000000) is the first octet to contain a 0 in the binary.

Step #2: Identify the decimal value in the interesting octet of the subnet mask.

A 26-bit subnet mask can be written in dotted decimal notation as: 255.255.255.192

Since the forth octet is the interesting octet, the decimal value in the interesting octet is 192.

Step #3: Determine the block size by subtracting the decimal value of the interesting octet from 256.

Block Size = 256 – 192 = 64

Step #4: Determine the subnets by counting by the block size in the interesting octet, starting at 0.

Placing a zero in the first interesting octet identifies the first subnet as:

192.168.4.0 /26

We then count by the block size (of 64) in the interesting octet (the forth octet in this question) to determine the remaining subnets:

192.168.4.64 /26

192.168.4.128 /26

192.168.4.192 /26

Step #5:

This question is asking about the 192.168.4.0 /26 subnet. From the above list of subnets, we can determine that the assignable range of IP addresses for this subnet is 192.168.4.1 – 192.168.4.62. We can also determine that 192.168.4.0 is the network address, and 192.168.4.63 is the directed broadcast address.

From the assignable range of IP addresses we have calculated, we can determine that the two assignable IP addresses given as options in this question are:
192.168.4.62 and 192.168.4.32.


Question #3

A host in your network has been assigned an IP address of 192.168.181.182 /25. What is the subnet to which the host belongs?

a. 192.168.181.128 /25

b. 192.168.181.0 /25

c. 192.168.181.176 /25

d. 192.168.181.192 /25

e. 192.168.181.160 /25

Answer: a

To determine subnets and usable address ranges created by the 25-bit subnet mask we perform the following steps:

Step #1: Identify the interesting octet (i.e. the octet that contains the first zero in the binary subnet mask).

In this question, we have a 25-bit subnet mask, which is written in binary as:

11111111 11111111 11111111 10000000

The interesting octet is the forth octet, because the forth octet (i.e. 10000000) is the first octet to contain a 0 in the binary.

Step #2: Identify the decimal value in the interesting octet of the subnet mask.

A 25-bit subnet mask can be written in dotted decimal notation as: 255.255.255.128

Since the forth octet is the interesting octet, the decimal value in the interesting octet is 128.

Step #3: Determine the block size by subtracting the decimal value of the interesting octet from 256.

Block Size = 256 – 128 = 128

Step #4: Determine the subnets by counting by the block size in the interesting octet, starting at 0.

Placing a zero in the first interesting octet identifies the first subnet as:

192.168.181.0 /25

We then count by the block size (of 128) in the interesting octet (the forth octet in this question) to determine the remaining subnets, or in this case just a single additional subnet.


192.168.181.128 /25

Now that we have our two subnets identified, we can determine the subnet in which the IP address of 192.168.181.182 resides.

Since the usable range of IP addresses for the 192.168.181.128 /25 network is 192.168.181.129 – 192.168.181.254 (because 192.168.181.128 is the network address, and 192.168.181.255 is the directed broadcast address), and since 192.168.181.182 is in that range, the subnet to which 192.168.181.182 /25 belongs is:

192.168.181.128 /25

Question #4

You are working with a Class B network with the private IP address of 172.16.0.0 /16. You need to maximize the number of broadcast domains, where each broadcast domain can accommodate 1000 hosts. What subnet mask should you use?

a. /22

b. /23

c. /24

d. /25

e. /26

Answer: a

In addition to testing your knowledge of subnetting, this question is also making sure you understand that a subnet is a broadcast domain. This should not be confused with a collision domain (i.e. each port on a switch is in its own collision domain).

To determine how many host bits are required to support 1000 hosts, we can create a table from the following formula:

Number of Hosts = 2h – 2, where h is the number of host bits

From this formula, we can create the following table:

1 Host Bit => 0 Hosts

2 Host Bits => 2 Hosts

3 Host Bits => 6 Hosts

4 Host Bits => 14 Hosts

5 Host Bits => 30 Hosts

6 Host Bits => 62 Hosts


7 Host Bits => 126 Hosts

8 Host Bits => 254 Hosts

9 Host Bits => 510 Hosts

10 Host Bits => 1022 Hosts

This table tells us that a subnet with 10 host bits will accommodate the requirement of 1000 hosts. If we have 10 host bits, then we have a
22-bit subnet mask (i.e. 32 – 10 = 22). Also, by not using more host bits than we need, we are maximizing the number of subnets that can be created.

Question #5

What is the directed broadcast address of a subnet containing an IP address of 172.16.1.10 /19?

a. 172.16.15.255

b. 172.16.31.255

c. 172.16.255.255

d. 172.16.95.255

e. 172.16.0.255

Answer: b

To determine the subnets, assignable IP address ranges, and directed broadcast addresses created by the 19-bit subnet mask we perform the following steps:

Step #1: Identify the interesting octet (i.e. the octet that contains the first zero in the binary subnet mask).

In this question, we have a 19-bit subnet mask, which is written in binary as:

11111111 11111111 11100000 00000000

The interesting octet is the third octet, because the third octet (i.e. 11100000) is the first octet to contain a 0 in the binary.

Step #2: Identify the decimal value in the interesting octet of the subnet mask.

A 19-bit subnet mask can be written in dotted decimal notation as: 255.255.224.0

Since the third octet is the interesting octet, the decimal value in the interesting octet is 224.

Step #3: Determine the block size by subtracting the decimal value of the interesting octet from 256.


Block Size = 256 – 224 = 32

Step #4: Determine the subnets by counting by the block size in the interesting octet, starting at 0.

Placing a zero in the first interesting octet identifies the first subnet as:

172.16.0.0 /19

We then count by the block size (of 32) in the interesting octet (the third octet in this question) to determine the remaining subnets:

172.16.32.0 /19

172.16.64.0 /19

172.16.96.0 /19

172.16.128.0 /19

172.16.160.0 /19

172.16.192.0 /19

172.16.224.0 /19

Step #5: Identify the subnet address, the directed broadcast address, and the usable range of addresses.

Looking through the subnets created by the 19-bit subnet mask reveals that the IP address of 172.16.1.10 resides in the 172.16.0.0 /19 subnet.

The directed broadcast address, where all host bits are set to a 1, is 1 less than the next subnet address.

The next subnet address is 172.16.32.0. So, the directed broadcast address for the 172.16.0.0 /19 subnet is 1 less than 172.16.32.0, which is:

172.16.31.255

The usable IP addresses are all the IP addresses between the subnet address and the directed broadcast address. Therefore, in this example, the assignable IP address range for the 172.16.0.0 /19 network is:

172.16.0.1 – 172.16.31.254

Question #6

A customer is using a Class C network of 192.168.10.0 subnetted with a 28-bit subnet mask. How many subnets can be created by using this subnet mask?

a. 32

b. 16

c. 30

d. 8


e. 14

Answer: b

The subnet in this question is a Class C network, because there is a 192 in the first octet. A class C network has a
natural mask of 24 bits. However, this network has a 28-bit subnet mask. Therefore, we have 4 borrowed bits, which are network bits added to a network’s natural mask (i.e. 28 – 24 = 4). The number of subnets can be calculated as follows:

Number of Subnets = 2s, where s is the number of borrowed bits.

Therefore, in this question, the number of created subnets is 16:

Number of Subnets = 24 = 16

Question #7

Given a subnet of 172.16.56.0 /21, identify which of the following IP addresses belong to this subnet. (Select 2.)

a. 172.16.54.129

b. 172.16.62.255

c. 172.16.61.0

d. 172.16.65.255

e. 172.16.64.1

Answer: b, c

To determine subnets and usable address ranges created by the 21-bit subnet mask we perform the following steps:

Step #1: Identify the interesting octet (i.e. the octet that contains the first zero in the binary subnet mask).

In this question, we have a 21-bit subnet mask, which is written in binary as:

11111111 11111111 11111000 00000000

The interesting octet is the third octet, because the third octet (i.e. 11111000) is the first octet to contain a 0 in the binary subnet mask.

Step #2: Identify the decimal value in the interesting octet of the subnet mask. A 21-bit subnet mask can be written in dotted decimal notation as: 255.255.248.0


Since the third octet is the interesting octet, the decimal value in the interesting octet is 248.

Step #3: Determine the block size by subtracting the decimal value of the interesting octet from 256.

Block Size = 256 – 248 = 8

Step #4: Determine the subnets by counting by the block size in the interesting octet, starting at 0.

Placing a zero in the first interesting octet identifies the first subnet as:

172.16.0.0 /21

We then count by the block size (of 8) in the interesting octet (the third octet in this question) to determine the remaining subnets:

172.16.8.0 /21 172.16.16.0 /21 172.16.24.0 /21 172.16.32.0 /21 172.16.40.0 /21 172.16.48.0 /21 172.16.56.0 /21 172.16.64.0 /21 ... SUBNETS OMITTED ...

We can stop counting after we pass the subnet we are being asked about. Specifically, in this question, we’re being asked about 172.16.56.0 /21.

Step #5: Identify the subnet address, the directed broadcast address, and the usable range of addresses.

The subnet address, where all host bits are set to a 0, is given:

172.16.56.0 /24

The directed broadcast address, where all host bits are set to a 1, is 1 less than the next subnet address.

The next subnet address is 172.16.64.0. So, the directed broadcast address for the 172.16.54.0 /21 subnet is 1 less than 172.16.64.0, which is: 172.16.63.255

The usable IP addresses are all the IP addresses between the subnet address and the directed broadcast address. Therefore, in this example, the usable IP address range for the 172.16.56.0 /21 network is:


172.16.56.1 – 172.16.63.254

The only IP addresses in this question that reside in this range are:

172.16.62.255 172.16.61.0

WARNING:
Many CCNA R&S candidates look at IP addresses like these and immediately assume they are not usable IP addresses, because they have a 0 or a 255 in the forth octet. They argue that 172.16.61.0 is a subnet address and that 172.16.62.255 is a directed broadcast address.

While that would only be true of the subnet mask were 24-bits, remember that, by definition, a subnet address has all of its host bits set to a 0, and a directed broadcast address has all of its host bits set to a 1. In this question, we have 11 host bits (i.e. 32 – 21 = 11), not 8 host bits. So, 172.16.62.255 and 172.16.61.0 are actually usable IP addresses.

Question #8

What is the subnet address of the IP address 192.168.5.55 with a subnet mask of 255.255.255.224?

a. 192.168.5.0 /27

b. 192.168.5.16 /27

c. 192.168.5.32 /27

d. 192.168.5.48 /27

e. 192.168.5.64 /27

Answer: c

To determine subnets and usable address ranges created by the 27-bit subnet mask we perform the following steps:

Step #1: Identify the interesting octet (i.e. the octet that contains the first zero in the binary subnet mask).

In this question, we have a 27-bit subnet mask, which is written in binary as:

11111111 11111111 11111111 11100000

The interesting octet is the forth octet, because the forth octet (i.e. 11100000) is the first octet to contain a 0 in the binary.

Step #2: Identify the decimal value in the interesting octet of the subnet mask.

A 27-bit subnet mask can be written in dotted decimal notation as: 255.255.255.224


Since the forth octet is the interesting octet, the decimal value in the interesting octet is 224.

Step #3: Determine the block size by subtracting the decimal value of the interesting octet from 256.

Block Size = 256 – 224 = 32

Step #4: Determine the subnets by counting by the block size in the interesting octet, starting at 0.

Placing a zero in the first interesting octet identifies the first subnet as:

192.168.5.0 /27

We then count by the block size (of 32) in the interesting octet (the forth octet in this question) to determine the remaining subnets:

192.168.5.32 /27

192.168.5.64 /27

192.168.5.96 /27

192.168.5.128 /27

192.168.5.160 /27

192.168.5.192 /27

192.168.5.224 /27

Now that we have all of our subnets identified, we can determine the subnet in which the IP address of 192.168.5.55 resides.

Since the usable range of IP addresses for the 192.168.5.32 /27 network is 192.168.5.33 – 192.168.5.62 (because 192.168.5.32 is the network address, and 192.168.5.63 is the directed broadcast address), and since 192.168.5.55 is in that range, the subnet to which 192.168.5.55 /27 belongs is:

192.168.5.32 /27

Question #9

You are working for a company that will be using the 192.168.1.0 /24 private IP address space for IP addressing inside their organization.

They have multiple geographical locations and want to carve up the 192.168.1.0 /24 address space into subnets. Their largest subnet will need 13 hosts.

What subnet mask should you use to accommodate at least 13 hosts per subnet, while maximizing the number of subnets that can be created?

a. 255.255.255.248


b. 255.255.255.224

c. 255.255.255.252

d. 255.255.255.192

e. 255.255.255.240

Answer: e

We can determine the maximum number of hosts allowed in a subnet by raising the number 2 to the power of the number of host bits and then subtracting 2. So, the formula looks like this:

Maximum Number of Hosts per Subnet = 2h – 2, where h is the number of host bits.

Why are we subtracting two? Well, there are two IP addresses in the subnet that cannot be assigned. These addresses are: (1) the network address, where all of the host bits are set to a 0 and (2) the directed broadcast address, where all of the host bits are set to a 1.

In the actual exam, if you are given scratch paper or access to a note taking application, you might want to write out a table such as the following for your reference:

1 Host Bit: 2
1 – 2 = 0

2 Host Bits: 22 – 2 = 2

3 Host Bits: 23 – 2 = 6

4 Host Bits: 24 – 2 = 14

5 Host Bits: 25 – 2 = 30

6 Host Bits: 26 – 2 = 62

7 Host Bits: 27 – 2 = 126

8 Host Bits: 28 – 2 = 254

In this question, we’re asked to determine a subnet mask that accommodates at least 13 hosts per subnet. By looking at the reference table we created, we can see that 4 host bits (which support 14 hosts) would work, while 3 host bits (which supports only 6 hosts) would not be enough.

So, we need a subnet with 4 host bits, which are enough host bits to meet the design goal, but not more than we need. Using more host bits than we need would violate the requirement to maximize the number of subnets.

A subnet mask with 4 host bits has 28 network bits (i.e. 32 – 4 = 28), and therefore a 28-bit subnet mask. A 28-bit subnet mask can be written as:

255.255.255.240


Question #10

A customer is using a Class C network of 192.168.10.0 subnetted with a 28-bit subnet mask. How many assignable addresses are available in each of the subnets?

a. 32

b. 16

c. 30

d. 8

e. 14

Answer: e

An IPv4 address contains a total of 32 bits. Since, in this question, we have 28 subnet bits, the number of host bits is 4 (i.e. 32 – 28 = 4). The number of assignable IP addresses in a subnet can be calculated as follows:

Number of Assignable IP Addresses = 2h – 2, where h is the number of host bits.

Therefore, in this question, each subnet has 14 assignable IP addresses:

Number of Assignable IP Addresses = 24 – 2 = 16 – 2 = 14

Question #11

An IP address of 192.168.0.100 /27 belongs to which of the following subnets?

a. 192.168.0.92

b. 192.168.0.128

c. 192.168.0.64

d. 192.168.0.96

e. 192.168.0.32

Answer: d

To determine the subnets created by the 27-bit subnet mask we perform the following steps:

Step #1: Identify the interesting octet (i.e. the octet that contains the first zero in the binary subnet mask).

In this question, we have a 19-bit subnet mask, which is written in binary as:

11111111 11111111 11111111 11100000


The interesting octet is the forth octet, because the forth octet (i.e. 11100000) is the first octet to contain a 0 in the binary.

Step #2: Identify the decimal value in the interesting octet of the subnet mask.

A 27-bit subnet mask can be written in dotted decimal notation as: 255.255.255.224

Since the forth octet is the interesting octet, the decimal value in the interesting octet is 224.

Step #3: Determine the block size by subtracting the decimal value of the interesting octet from 256.

Block Size = 256 – 224 = 32

Step #4: Determine the subnets by counting by the block size in the interesting octet, starting at 0.

Placing a zero in the first interesting octet identifies the first subnet as:

192.168.0.0 /27

We then count by the block size (of 32) in the interesting octet (the forth octet in this question) to determine the remaining subnets:

192.168.0.32 /27

192.168.0.64 /27

192.168.0.96 /27

192.168.0.128 /27

192.168.0.160 /27

192.168.0.192 /27

192.168.0.224 /27

Step #5: Identify the subnet address of the IP address 192.168.0.100 /27.

Looking through the subnets created by the 27-bit subnet mask reveals that the IP address of 192.168.0.100 resides in the
192.168.0.96 subnet.

Question #12

What subnet mask should be used to subnet the 192.168.10.0 network to support the number of subnets and IP addresses per subnet shown in the following topology?


a. 255.255.255.0

b. 255.255.255.128

c. 255.255.255.192

d. 255.255.255.224

e. 255.255.255.240

Answer: c

To meet the design requirements, four subnets must be created, and each subnet must accommodate a maximum of 50 IP addresses.

We can begin by creating a listing of how many subnets are created from different numbers of borrowed bits, using the formula:

Number of Subnets Created = 2n, where n is the number of borrowed bits

1 borrowed bits => 2 subnets

2 borrowed bits => 4 subnets

3 borrowed bits => 8 subnets

4 borrowed bits => 16 subnets

5 borrowed bits => 32 subnets

6 borrowed bits => 64 subnets

7 borrowed bits => 128 subnets

From this, we can see we need at least 2 borrowed bits to accommodate 4 subnets. However, we need to make sure the subnet will accommodate 50 IP addresses. To determine this, we can use the formula:

Number of IP Addresses = 2h – 2, where h is the number of host bits


If we have 2 borrowed bits (i.e. the minimum number of borrowed bits required for 4 subnets), we have 6 host bits (i.e. 8 – 2 = 6). From the above formula, we can determine the number of IP addresses supported by 6 host bits.

Number of IP Addresses = 26 – 2 = 62

Since 6 host bits meet our requirement of at least 50 IP addresses per subnet, we can use a 26-bit subnet mask (i.e. 2 bits added to the Class C default mask (also known as the natural mask) of 24 bits). A 26-bit subnet mask can be written as:

255.255.255.192

Featured Post

Day 41 — BGP Confederations: Sub-AS Design, External View and Migration

1. Opening Confederations are another way to scale BGP inside a large administrative domain. They divide the domain into member autonomous systems while presenting a single confederation identifier to external peers. They are powerful, but their operational model is more complex than simply 'using private ASNs inside.' The engineering goal is not to memorize another BGP command. It is to understand what information each speaker is allowed to propagate, what path information can be hidden, and what failure domain is created by the chosen control-plane architecture . 2. Concept and standards behavior RFC 5065 defines AS_CONFED_SEQUENCE and AS_CONFED_SET and how member-AS relationships are represented. Confederation external sessions have eBGP-like properties inside the confederation, while the confederation is presented externally as one AS. Modern guidance must also account for the fact that RFC 9774 prohibits new origination of AS_SET/AS_CONFED_SET in ordinary aggregation c...