1.2 TCP/IP Protocol Suite and IP Headers
Key Takeaways
The TCP/IP model condenses network architecture into four functional layers (Application, Transport, Internet, Network Access), matching real-world IP network deployments.
TCP provides reliable, ordered, byte-stream transmission using a three-way handshake (SYN, SYN-ACK, ACK) and sliding-window flow control, whereas UDP provides low-overhead, connectionless datagram transport.
The IPv4 header contains a 20-byte base header with critical fields including Time-to-Live (TTL) for loop mitigation, Protocol to identify Layer 4 payloads (TCP: 6, UDP: 17, OSPF: 89, ICMP: 1), and DSCP for QoS classification.
Enterprise management and security protocols rely on specific transport assignments, notably TACACS+ operating over reliable TCP port 49, while RADIUS operates over UDP ports 1812 (authentication) and 1813 (accounting).
TCP/IP Protocol Suite and IP Headers
Quick Summary: The TCP/IP protocol suite forms the operational foundation of modern enterprise networks. While the OSI model serves as a conceptual reference, production campus networks run TCP/IP protocols. At Layer 4, TCP delivers connection-oriented, reliable transmission with sliding-window flow control, while UDP provides lightweight, connectionless delivery ideal for real-time traffic like voice and video. At Layer 3, the IPv4 header provides logical addressing, loop prevention via Time-to-Live (TTL), and protocol multiplexing to direct payloads to the correct upper-layer protocol.
The TCP/IP Architecture vs. OSI Reference Model
Originally developed by DARPA, the TCP/IP model (RFC 1122) focuses on practical protocol implementation rather than theoretical boundaries. Modern network engineering compares the classic 4-layer DoD model, the practical 5-layer model, and the 7-layer OSI model:
| OSI 7-Layer Model | TCP/IP Practical 5-Layer Model | Original DoD 4-Layer Model | Representative Protocols & Standards |
|---|---|---|---|
| Layer 7: Application | Layer 5: Application | Layer 4: Application (Process) | HTTP, HTTPS, SSH, DNS, DHCP, NTP, SNMP, RADIUS |
| Layer 6: Presentation | ^ | ^ | TLS, SSL, Base64, JSON |
| Layer 5: Session | ^ | ^ | RPC, Sockets, Session API |
| Layer 4: Transport | Layer 4: Transport | Layer 3: Host-to-Host (Transport) | TCP, UDP |
| Layer 3: Network | Layer 3: Network (Internet) | Layer 2: Internet | IPv4, IPv6, ICMP, ARP, OSPF |
| Layer 2: Data Link | Layer 2: Data Link | Layer 1: Network Access (Link) | Ethernet (802.3), Wi-Fi (802.11), 802.1Q VLAN |
| Layer 1: Physical | Layer 1: Physical | ^ | 1000BASE-T, 10GBASE-SR, DAC cables, SFP+ |
In the TCP/IP suite, application developers integrate data presentation and session logic directly into user applications and shared cryptographic libraries (such as OpenSSL), eliminating the need for standalone Presentation and Session layers.
Layer 4 Transport Protocols: TCP vs. UDP
The Transport Layer establishes logical communication channels between host application processes. Two primary protocols operate at Layer 4:
Transmission Control Protocol (TCP - RFC 793)
TCP provides connection-oriented, reliable, sequenced data delivery:
- Reliability: Every transmitted segment requires an acknowledgment (ACK). Missing segments trigger timer expiration and automatic retransmission.
- Sequencing: TCP assigns a 32-bit sequence number to each byte, allowing the receiver to reorder out-of-order packets into a seamless byte stream.
- Flow Control (Sliding Window): The receiver advertises an available Window Size in its header, preventing high-speed senders from overflowing receiving buffers.
- Congestion Control: Senders monitor round-trip latency and packet loss, dynamically adjusting transmission rates to prevent campus link congestion.
The TCP Three-Way Handshake
Before transferring application payload, TCP establishes state via a three-way exchange:
- SYN (Synchronize): The client transmits a segment with the
SYNflag set and an Initial Sequence Number (ISN) . - SYN-ACK: The server acknowledges with
ACK(), setsSYN, and supplies its own ISN . - ACK: The client acknowledges with
ACK(). The session reaches theESTABLISHEDstate, and data transfer begins.
Graceful session termination uses FIN and ACK handshakes, while abrupt resets use the RST flag.
User Datagram Protocol (UDP - RFC 768)
UDP provides connectionless, lightweight, best-effort transmission. It omits connection handshakes, sequence tracking, acknowledgments, and retransmissions:
- Minimal Overhead: Fixed 8-byte header (versus TCP's 20-byte minimum).
- Zero Connection Delay: Applications transmit immediately without handshake round trips.
- Target Workloads: Real-time delay-sensitive traffic (VoIP, streaming video) and lightweight request-response services (DNS queries, DHCP, NTP, syslog).
| Feature | TCP | UDP |
|---|---|---|
| Connection State | Connection-oriented (Handshake required) | Connectionless (No handshake) |
| Reliability | Guaranteed (Acknowledgments & retransmissions) | Best-effort (No retransmissions) |
| Header Size | 20 to 60 bytes (20 bytes standard) | 8 bytes fixed |
| Ordering | Enforced via 32-bit sequence numbers | Datagrams delivered as received |
| Flow Control | Yes (Sliding window and congestion avoidance) | None |
| Campus Workloads | Web (HTTPS), SSH, TACACS+, File Transfer (SFTP) | Voice (RTP), Video, DNS, DHCP, RADIUS, Syslog |
Port Addressing and Service Multiplexing
Transport layer headers feature 16-bit Source Port and Destination Port fields (0 to 65,535), enabling service multiplexing across a single IP address.
IANA organizes ports into three standardized tiers:
- Well-Known Ports (0-1023): Standardized core infrastructure services.
- Registered Ports (1024-49151): Vendor applications and specific network protocols.
- Dynamic / Ephemeral Ports (49152-65535): Client-assigned temporary source ports.
Essential Campus Network Ports
| Protocol | Port Number | Transport Protocol | Role in Campus Network |
|---|---|---|---|
| SSH | 22 | TCP | Secure encrypted CLI management for switches and APs |
| Telnet | 23 | TCP | Insecure legacy CLI access (disabled by default on AOS-CX) |
| DNS | 53 | UDP / TCP | Name resolution (UDP queries, TCP zone transfers) |
| DHCP Server | 67 | UDP | Server port receiving client discovers and requests |
| DHCP Client | 68 | UDP | Client port receiving server offers and acknowledgments |
| HTTP / HTTPS | 80 / 443 | TCP | Web GUI, Aruba Central cloud uplink, Captive Portal |
| NTP | 123 | UDP | Network Time Protocol clock synchronization |
| Syslog | 514 | UDP | System event logging to central monitoring servers |
| SNMP | 161 / 162 | UDP | Port 161 for device polling; Port 162 for traps |
| RADIUS Auth / Acct | 1812 / 1813 | UDP | 802.1X authentication (1812) and accounting (1813) |
| RADIUS CoA | 3799 | UDP | Change of Authorization (CoA) dynamic policy disconnects |
| TACACS+ | 49 | TCP | Administrative AAA authentication and command authorization |
Critical Exam Distinction: TACACS+ uses TCP port 49, ensuring reliable command authorization and accounting logs. In contrast, RADIUS uses UDP ports 1812 and 1813, relying on application-level timeouts and retransmissions.
IPv4 Header Deep-Dive
The IPv4 header provides Layer 3 addressing, routing loop prevention, and protocol demultiplexing across enterprise subnets. A standard header without options is 20 bytes long.
IPv4 Header Field Breakdown
- Version (4 bits): Set to binary
0100(4) for IPv4. - Internet Header Length (IHL - 4 bits): Measures header length in 32-bit words (minimum
5, meaning ). With options, it expands up to 60 bytes. - Type of Service / DSCP (8 bits): Differentiated Services Code Point (6 bits) classifies traffic for campus Quality of Service (QoS), alongside Explicit Congestion Notification (2 bits).
- Total Length (16 bits): Entire packet size in bytes (header plus payload, up to 65,535 bytes).
- Identification, Flags, Fragment Offset (32 bits total): Manage packet fragmentation. Flags include Don't Fragment (DF) and More Fragments (MF).
- Time-to-Live (TTL - 8 bits): Hop counter preventing routing loops. Routers decrement TTL by 1 at each hop. If TTL reaches 0, the router discards the packet and returns an ICMP Type 11 Code 0 (Time Exceeded in Transit) error.
- Protocol (8 bits): Identifies the encapsulated Layer 4 payload:
1for ICMP,6for TCP,17for UDP, and89for OSPF. - Header Checksum (16 bits): Verifies IPv4 header integrity. Because routers decrement TTL at each hop, they must recalculate this checksum at every routing hop.
- Source and Destination IP Addresses (32 bits each): Logical origin and target endpoints.
Contrast with IPv6 Header Architecture
IPv6 streamlines Layer 3 processing with a fixed 40-byte base header. Key differences include:
- Hop Limit: Replaces IPv4's TTL field with identical decrement behavior.
- Next Header: Replaces IPv4's Protocol field, identifying Layer 4 protocols or chained extension headers.
- No Header Checksum: Eliminates hop-by-hop checksum recalculation, delegating integrity checks to Layer 2 and Layer 4.
Diagnostic Verification on Aruba CX Switches
Network administrators utilize built-in AOS-CX diagnostic tools that leverage these header fields:
- Ping: Sends ICMP Type 8 (Echo Request) packets and evaluates ICMP Type 0 (Echo Reply) returns to verify Layer 3 reachability.
- Traceroute: Systematically increments the IPv4 TTL (1, 2, 3...) to elicit ICMP Time Exceeded responses, mapping every router hop along the path.
Common Exam Traps
- Transport Confusion for Security Protocols: Memorize that TACACS+ = TCP 49 (reliable administrative session) while RADIUS = UDP 1812/1813 (connectionless network access).
- Header Location of TTL: TTL resides in the Layer 3 IPv4 header, never in Layer 4 TCP/UDP headers.
- Layer 2 Switches and TTL: Layer 2 switches do not decrement the TTL. Only Layer 3 forwarding hops decrement TTL.
During a TCP connection establishment between an administrative management workstation and an Aruba CX 6300 switch via SSH, which sequence of control flags is exchanged during the three-way handshake?
Workstation sends RST -> Switch replies SYN -> Workstation sends ACK
Workstation sends SYN -> Switch replies ACK -> Workstation sends SYN-ACK
Workstation sends ACK -> Switch replies SYN -> Workstation sends FIN
Workstation sends SYN -> Switch replies SYN-ACK -> Workstation sends ACK
When configuring administrative authentication and network access control in an Aruba enterprise campus, what is a primary transport layer difference between the TACACS+ and RADIUS protocols?
TACACS+ relies on TCP port 49 to provide reliable transport, whereas RADIUS uses UDP ports 1812 and 1813
TACACS+ uses connectionless UDP port 49 for lower latency, while RADIUS uses connection-oriented TCP port 1812 for guaranteed delivery
TACACS+ and RADIUS both use UDP to avoid transport-layer connection overhead during authentication
TACACS+ uses TCP port 1812, while RADIUS uses UDP port 49
A network engineer issues a traceroute command from a core Aruba CX 8325 switch to a remote campus branch router. What IPv4 header field is intentionally manipulated to identify intermediate routers, and what ICMP message is generated when this value reaches zero?
Differentiated Services Code Point (DSCP); intermediate routers return ICMP Type 8 (Echo Request)
Time-to-Live (TTL); intermediate routers drop the packet and return ICMP Type 11 (Time Exceeded)
Protocol field; intermediate routers return ICMP Type 3 (Destination Unreachable)
Identification field; intermediate routers return ICMP Type 0 (Echo Reply)
Sections you finish are checked off in the contents.