Afrikaans
Akan
Albanian
Amharic
Arabic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranî)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
So what happens if A now wants to ping a remote device in a separate subnet?
So now for example, A with IP address 10.1.1.1
Wants to ping device B with IP address 10.1.2.1
In these examples I�m discussing ICMP or ping traffic
but something similar would happen
if you were sending HTTP, FTP or other traffic.
what�s important to note here is that these devices are in separate subnets
we are using a /24 mask in this topology.
So host A is not in the same subnet as host B. 10
now the first thing the PC will do is to check whether the IP address 11
it's trying to communicate with is in a separate subnet 12
or in the same subnet as itself. 13
It does this by doing a logical end using the network mask. 14
So in this case we�ve got /24 mask 15
the IP address of PC A is 10.1.1.1 16
and it�s trying to ping an IP address 10.1.2.1/24 17
in dotted decimal notation looks like this 255.255.255.0 18
Which means the network portion is the first 3 octets of the address. 19
So the local PC 10.1.1.1 compares the network portion with the device that 20
it's trying to communicate with to check if the device is local or remote. 21
In this case the network portion of the address is different. 22
So the local PC knows that the remote device is in a different subnet 23
to itself and it will therefore send the traffic to its default gateway 24
to get to the remote subnet on which the device resides. 25
Now in this example we are assuming that device A 26
has a default gateway configured. 27
So device A has been configured with the default gateway of the router 28
10.1.1.100 so the PC will firstly check if it has the router's MAC address 29
in its local ARP cache 30
It does this because its need to send the traffic 31
to the router to get to the remote device. 32
And because this is an Ethernet segment a layer 2 33
Mac address is required for communication. 34
Ethernet once again requires that MAC address is be use at 35
layer 2 for transmission across an Ethernet network. 36
So at layer 2 a Mac address is required by the PC 37
the PC would have been configured with the default gateway of 10.1.1.100 38
which is an IP address at layer 3 39
but the MAC address of the default gateway wouldn�t have been 40
configured on the PC, so there�s no entry on the local PC 41
for the MAC address of its default gateway 42
and thus it will need to send out a broadcast unto the segment 43
asking who has IP address 10.1.1.100 in other words 44
this is an ARP request looking for the MAC address 45
associated with the IP address of the default gateway. 46
When the broadcast is received by the hub, it will flood it out of all ports 47
except the ports on which they arrived 48
PC C will receive the broadcast at layer 2 49
but when reading the layer 3 information it will see that 50
this is an ARP for 10.1.1.100 which is not its IP address. 51
So PC C will therefore drop the ARP request. 52
The router however will process the ARP request. 53
Firstly it will receive the traffic at layer 2 54
because this is a broadcast and when it reads the layer 3 information 55
it will see that this is an ARP request for its IP address. 56
So the router will reply with an ARP reply to PC A ARP request. 57
The ARP reply is a unicast address so source MAC address is G 58
the router's MAC address, destination MAC address is A 59
source IP address is the router's IP address 60
destination IP address is A IP address. 61
The hub will once again flood the traffic out of all ports 62
except the port on which it arrived. 63
C will drop the frame because it's not destined to itself. 64
Notice in the frame the destination MAC address is A 65
but the PCs MAC address is C, so it will drop the frame. 66
And what�s important to note is that it�s the Network Interface Card 67
that drops the frame and not the central CPU of the PC. 68
A will receive the frame and upon a receipt will process the frame 69
because the destination MAC address is itself. 70
So at layer 2 the frame is accepted by the NIC or Network Interface Card . 71
The layer 2 information is strip and forward it to high layer protocols. 72
Because this is an ARP reply its process by high layer protocols 73
and the ARP cache is updated with the MAC address of the router, so PC A 74
now has a mapping saying that IP address 10.1.1.100 uses MAC address G 75
so this is the important, PC A knows that the IP address 76
10.1.1.100 is associated with MAC address G. 77
So the PC can send traffic to the network destined for the remote PC 10.1.2.1 78
with the source IP address set to 10.1.1.1 itself 79
but notice please that the source MAC address is the local PC 80
and the destination MAC address is the router. 81
The layer 2 frame goes to the router and hence the layer 2 82
information contains the local segment MAC addresses. 83
Source MAC address the PC, destination MAC address the router. 84
The layer 3 information contains the destination IP address 85
of the remote host and the local PCs IP address. 86
The hub will flood the frame to both c and G, C will drop the frame 87
because the destination MAC address is not itself 88
the router will receive the frame at layer 2 89
because its destined to its MAC address of G. 90
It will then strip the layer 2 information 91
and read the layer 3 information in the packet. 92
So now let�s look at a practical example 93
I�m going to capture traffic in Wireshark, so I'll start the capture 94
I�m gonna clear my ARP cache, so arp-a shows that no entries 95
are in the ARP cache at the moment and then I�m gonna ping hp.com 96
notice the DNS resolution has taking place, ICMP message has timing out 97
because a firewall is blocking the ICMP messages to that server. 98
So here�s another example, lets ping Google com. 99
Notice pings are succeeding, so I�ll stop the capture. 100
HP was using an IP address in the 15 range. 101
So let�s have a look for that ICMP traffic 102
so notice there�s an ICMP message to hp.com 103
and you can see that because the address is 15. 104
And HP own the 15 IP address range. 105
We didn�t get a reply from the server but the echo request was sent. 106
What I�d like you to see please is that at layer 2 107
the source MAC address is my local pc 108
but the destination MAC address is my local router. 109
Notice I can see that this is a Cisco device because the MAC address 110
is shown as Cisco for the OUI or vendor portion of the address. 111
We can see that by typing arp-a 112
notice this MAC address is the MAC address associated with IP address 113
10.0.0.254 IP config shows us that 114
that is the IP address of the default gateway. 115
So the traffic is going from my local PC to hp.com 116
but it�s being routed by my local router. 117
At layer 3 we have the local PC's IP address 118
the destination IP address is hp but at layer 2 119
the source MAC address is my PC 120
and the destination MAC address is the local router. 121
And once again sending the traffic to my local default gateway at layer 2. 122
I can filter the Wireshark capture to show only ICMP traffic again. 123
Here�s traffic going to Google so source IP address is my local machine 124
destination IP address is Google but notice at layer 2 125
the source MAC address is my local PC 126
and the destination MAC address is once again the local router.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.