Hello Guest! Welcome to ep6network, Get all components from Basic Networking.
Something you might want to know about us.
Don't be hesitated to contact us if you have something to say.
Showing posts with label Features. Show all posts
Showing posts with label Features. Show all posts

Network Fundamental and its Components

| 1 responce(s) | Tuesday, July 28, 2009
|

Source : Microsoft Encyclopedia of Networking Second edition

What Is Networking?

In the simplest sense, networking means connecting computers so that they can share files, printers, applications, and other computer-related resources. The advantages of networking computers are fairly obvious:
● Users can save their important files and documents on a file server. This is more secure than storing them on workstations because a file server can be backed up in a single operation.
● Users can share a network printer, which costs much less than having a locally attached printer for each user’s computer.
● Users can share groupware applications running on application servers, which enables users to share documents, send messages, and collaborate directly.
● The job of administering and securing a company’s computer resources is simplified since they are concentrated on a few centralized servers. The above definition of networking focuses on the basic goals of networking computers together: increased manageability, security, cost-effectiveness, and efficiency over non-networked systems. However, we could also focus our discussion on the different types of networks, including
● Personal area networks (PANs), once the stuff of science fiction but rapidly becoming a reality as the mobile knowledge workers of today carry around an array of cell phones, Personal Digital Assistants (PDAs), pagers, and other small devices
● Local area networks (LANs), which can range from a few desktop workstations in a Small Office/Home Office (SOHO) to several thousand workstations and dozens of servers deployed throughout dozens of buildings on a university campus or in an industrial park
● Metropolitan area networks (MANs), which span an urban area and are generally run by telcos and other service providers to provide companies with high-speed connectivity between branch offices and with the Internet
● Wide area networks (WANs), which might take the form of a company’s head office linked to a few branch offices or an enterprise spanning several continents with hundreds of offices and subsidiaries
● The Internet, the world’s largest network and the “network of networks” On the other hand, we could also focus on the different networking architectures in which these various types of networks can be implemented, including
● Peer-to-peer networking, which might be implemented in a workgroup consisting of computers running Microsoft Windows 98 or Windows 2000 Professional
● Server-based networking, which might be based on the domain model of Windows NT, the domain trees and forests of Active Directory directory service in Windows 2000, or another architecture such as Novell Directory Services (NDS) for Novell NetWare
● Terminal-based networking, which might be the traditional host-based mainframe environment; the UNIX X Windows environment; the terminal services of Windows NT Server 4 Enterprise Edition; Windows 2000 Advanced Server; or Citrix MetaFrame Or we could look at the various networking technologies used to implement these architectures, including
● LAN technologies such as Ethernet, Token Ring, Fiber Distributed Data Interface (FDDI), Fast
Ethernet, Gigabit Ethernet (GbE), and the emerging 10G Ethernet (10GbE)
● WAN technologies such as Integrated Services Digital Network (ISDN), T-carrier leased lines, X.25, frame relay, Asynchronous Transfer Mode (ATM), Synchronous Optical Network (SONET), Digital Subscriber Line (DSL), and metropolitan Ethernet
● Wireless communication technologies such as the wireless LAN (WAN) standards 802.11a and
802.11b, and the consumer wireless technologies HomeRF and Bluetooth
● Cellular communication systems such as Time Division Multiple Access (TDMA), Code Division
Multiple Access (CDMA), Global System for Mobile Communications (GSM), and the emerging
3G cellular communication standards In addition, we could consider the hardware used to
implement these different networking technologies, including
● LAN devices such as repeaters, concentrators, bridges, hubs, Ethernet switches, and routers
● WAN devices such as modems, ISDN terminal adapters, Channel Service Units (CSUs), Data Service Units (DSUs), packet assembler/disassemblers (PADs), frame relay access devices (FRADs), multiplexers (MUXes), and inverse multiplexers (IMUXes)
● Equipment for organizing, protecting, and troubleshooting LAN and WAN hardware, such as racks, cabinets, surge protectors, line conditioners, uninterruptible power supplies (UPSs), KVM switches, and cable testers
● Cabling technologies such as coaxial cabling, twinax cabling, twisted-pair cabling, fiber-optic cabling, and associated equipment such as connectors, patch panels, wall plates, and splitters
● Unguided media technologies such as infrared communication, wireless cellular networking, and satellite networking, along with their associated hardware
● Data storage technologies such as redundant array of independent disks (RAID), network-attached storage (NAS), and storage area networks (SANs) along with their associated hardware, plus various enabling technologies, including Small Computer System Interface (SCSI) and Fibre Channel Or we could talk about various technologies that enhance the reliability, scalability, security, and manageability of computer networks, including
● Technologies for implementing network security, including firewalls, proxy servers, and virtual private networking (VPN), and such devices as smart cards and firewall appliances
● Technologies for increasing availability and reliability of access to network resources, such as clustering, caching, load balancing, Layer 7 switching, and terminal services
● Network management technologies such as Simple Network Management Protocol (SNMP), Remote Network Monitoring (RMON), Web-Based Enterprise Management (WBEM), Common Information Model (CIM), and Windows Management Instrumentation (WMI) Returning to a more general level, networking can also be thought of as the various standards that underlie the
different networking technologies and hardware mentioned above, including
● The Open Systems Interconnection (OSI) networking model from the International Organization for Standardization (ISO)
● The G-series, H-series, I-series, T-series, V-series, and X-series standards from the International Telecommunication Union (ITU)
● Project 802 of the Institute of Electrical and Electronics Engineers (IEEE)
● The Requests for Comment (RFC) series from the Internet Engineering Task Force (IETF)
● Various standards developed by the World Wide Web Consortium (W3C), the Frame Relay Forum, the ATM Forum, the Gigabit Ethernet Alliance, and other standards organizations Networking protocols deserve special attention in any definition of the word networking. These protocols include:
● LAN protocols such as NetBEUI, Internetwork Packet Exchange/Sequenced Packet Exchange
(IPX/SPX), Transmission Control Protocol/Internet Protocol (TCP/IP), and AppleTalk
● WAN protocols such as Serial Line Internet Protocol (SLIP), Point-to-Point Protocol (PPP), Point-to- Point Tunneling Protocol (PPTP), and Layer 2 Tunneling
Protocol (L2TP)
● Protocols developed within mainframe computing environments, such as Systems Network Architecture (SNA), Advanced Program-to-Program Communications (APPC), Synchronous Data Link Control (SDLC), and High-level Data Link Control (HDLC)
● Routing protocols such as the Routing Information Protocol (RIP), Interior Gateway Routing Protocol (IGRP), Open Shortest Path First (OSPF) Protocol, and Border Gateway Protocol (BGP)
● Internet protocols such as the Hypertext Transfer Protocol (HTTP), File Transfer Protocol (FTP), Network News Transfer Protocol (NNTP), and the Domain Name System (DNS)
● Electronic messaging protocols such as X.400, Simple Mail Transfer Protocol (SMTP), Post Office Protocol version 3 (POP3), and Internet Mail Access Protocol version 4 (IMAPv4)
● Directory protocols such as X.500’s Directory Access Protocol (DAP) and the Lightweight Directory Access Protocol (LDAP)
● Security protocols such as Password Authentication Protocol (PAP), Challenge Handshake Authentication Protocol (CHAP), Windows NT LAN Manager (NTLM) Authentication, Kerberos, IP Security Protocol (IPsec), Secure Sockets Layer (SSL), and public key cryptography standards and protocols
● Serial interface standards such as RS-232, RS-422/ 423, RS-485, V.35, and X.21
We could dig still deeper and discuss the fundamental engineering concepts that underlie the various networking technologies and services previously discussed, including
● Impedance, attenuation, shielding, near-end crosstalk (NEXT), and other characteristics of cabling and other transmission systems
● Signals and how they can be multiplexed using time-division, frequency-division, statistical, and other multiplexing techniques
● Transmission parameters including bandwidth, throughput, latency, jabber, jitter, backbone, handshaking, hop, dead spots, dark fiber, and late collisions
● Balanced vs. unbalanced signals, baseband vs. broadband transmission, data communications equipment (DCE) vs. data terminal equipment (DTE), circuit switching vs. packet switching, connection-oriented vs. connectionless communication, unicast vs. multicast and broadcast, pointto- point vs. multipoint links, direct sequencing vs. frequency hopping methods, and switched virtual circuit (SVC) vs. permanent virtual circuit (PVC) We could also talk about the different types of providers of networking services, including
● Internet service providers (ISPs), application service providers (ASPs), and integrated communications providers (ICPs)
● Telcos or local exchange carriers (LECs), including both Regional Bell Operating Companies (RBOCs) and competitive local exchange carriers (CLECs), that offer such popular broadband services as Asymmetric Digital Subscriber Line (ADSL) and High-bit-level Digital Subscriber Line (HDSL) through their central office (CO) and local loop connection
● Inter-exchange carriers (IXCs) that provide popular WAN services such as dedicated leased lines and frame relay for the enterprise (large companies)
● Local loop alternatives including cable modems, fixed wireless, and satellite networking companies We could also list the various software technologies vendors have developed that make computer networking both useful and possible, including
● Network operating systems such as Windows, Novell NetWare, UNIX, and Linux
● Specialized operating systems such as Cisco Systems’ Internetwork Operating System (IOS), which runs on Cisco routers, and the variant of IOS used on Cisco’s Catalyst line of Ethernet switches
● Directory systems such as Microsoft Corporation’s domain-based Active Directory, Novell Directory Services (NDS), and various implementations of X.500 and LDAP directory systems
● File systems such as NTFS file system (NTFS) on Windows platforms and distributed file systems such as the Network File System (NFS) developed by Sun Microsystems for the UNIX platform
● Programming languages and architectures for developing distributed computing applications, such as the C/C++ and Java languages, Microsoft’s ActiveX and Sun’s Jini technologies, component technologies such as Distributed Component Object Model (DCOM) and COM+, inter process communication (IPC) technologies such as Remote Procedure Calls (RPCs) and named pipes, and Internet standards such as the popular Hypertext Markup Language (HTML) and the Extensible Markup Language (XML) family of standards
● Tools for integrating networking technologies in heterogeneous environments, such as Gateway Services for NetWare (GSNW), Services for Macintosh, Services for UNIX on the Windows 2000 platforms, and Microsoft Host Integration Server, all of which provide connectivity with mainframe systems On an even deeper level, we could focus on the various administration tools for managing networking hardware, platforms, services and protocols, including
● The Microsoft Management Console (MMC) and its various snap-ins in the Windows 2000 and
Windows .NET Server platforms
● The various ways routers and network appliances can be administered using Telnet, terminal programs, and the universal Web browser interface
● Popular TCP/IP command-line utilities such as arp, ping, ipconfig, traceroute, netstat, nbtstat, finger, and nslookup
● Platform-specific command-line utilities such as various Windows commands used for automating common administration tasks
● Cross-platform scripting languages that can be used for system and network administration, including JavaScript, VBScript, and Perl We could also look at various enterprise applications widely used in networked environments, including
● Enterprise Resource Planning (ERP) and Customer Relationship Management (CRM) platforms
● Enterprise Information Portal (EIP) and Enterprise Knowledge Portal (EKP) platforms
● The Microsoft .NET Enterprise Server family of applications that includes Microsoft Application Center Server, BizTalk Server, Commerce Server,Exchange Server, Host Integration Server, Internet Security and Acceleration Server, Mobile Information Server, and SQL Server I think that you can see by now that we could go on and on, slowly unpeeling our answer to the question “What is networking?” like the many layers of an onion. And it is pretty obvious by now that there is more to networking than just hubs and cables! In fact, the field of computer networking today is almost overwhelming in its breadth and complexity, and one could spend a lifetime studying only one small aspect of the subject. This has not always been the case. Let’s take a look now at how the field of computer networking has reached the amazing point where it is today.


SONET NETWORKS

| 0 responce(s) | Thursday, April 30, 2009
|












SONET NETWORKS


Using SONET equipment, we can create a SONET network that can be used as a high-speed backbone carrying loads from other networks such as ATM (Chapter 18) or IP (Chapter 20). We can roughly divide SOlNET networks into three categories: linear, ting, and mesh networks.

Linear Networks

A linear SONET network can be point-to-point or multipoint. Point-to-Point Network. A point-to-point network is normally made of an STS multiplexer, an STS demultiplexer, and zero or more regenerators with no add/drop multiplexers, as shown in Figure 17.18. The signal flow can be unidirectional or bidirectional,

Multipoint Network

A multipoint network uses ADMs to allow the communications between several terminals. An ADM removes the signal belonging to the terminal connected to it and adds the signal transmitted from another terminal. Each terminal can send data to one or more downstream terminals. which each terminal can send data only to the downstream terminals, but the a multipoint network can be bidirectional, too.

Automatic Protection Switching

To create protection against failure in linear networks, SONET defines automatic protection switching (APS). APS in linear networks is defined at the line layer, which means the protection is between two ADMs or a pair of STS multiplexer/multiplexers. The idea is to provide redundancy; a redundant line (fiber) can be used in case of failure in the main one. The main line is referred to as the work line and the redundant line as the protection line. Three schemes are common for protection in linear channels:
one-plus-one, one-to-one, and one-to-many.

One-Plus-One APS In this scheme, there are normally two lines: one working line and one protection line. Both lines are active all the time. The sending multiplexer


sends the same data on both lines; the receiver multiplexer monitors the line and chooses the one with the better quality. If one of the lines fails, it loses its signal, and, of course, the other line is selected at the receiver. Although, the failure recovery for this scheme is instantaneous, the scheme is inefficient because two times the bandwidth is required. Note that one-plus-one switching is done at the path layer.

One-to-One APS In this scheme, which looks like the one-plus-one scheme, there is also one working line and one protection line. However, the data are normally sent on the working line until it fails. At this time, the receiver, using the reverse channel, informs the sender to use the protection line instead. Obviously, the failure recovery is slower than that of the one-plus-scheme, but this scheme is more efficient because the protection line can be used for data transfer when it is not used to replace the working line. Note that the one-to-one switching is done at the line layer.

One-to-Many APS This scheme is similar to the one-to-one scheme except that there is only one protection line for many working lines. When a failure occurs in one of the working lines, the protection line takes control until the failed line is repaired. It is not as secure as the one-to-one scheme because if more than one working line fails at the same time, the protection line can replace only one of them. Note that one-to-many APS is done at the line layer.


Ring Networks

ADMs make it possible to have SONET ring networks. SONET rings can be used in either a unidirectional or a bidirectional configuration. In each case, we can add extra rings to make the network self-healing, capable of self-recovery from line failure. Unidirectional Path Switching Ring

A unidirectional path switching ring (UPSR) is a unidirectional network with two rings: one ring used as the working ring and the other as the protection ring. The idea is similar to the one-plus-one APS scheme we discussed in a linear network. The same signal flows through both rings, one clockwise and the other counterclockwise. It is called UPSR because monitoring is done at the path layer. A node receives two copies of the electrical signals at the path layer, compares them, and chooses the one with the better quality. If part of a ring between two ADMs fails, the other ring still can guarantee the continuation of data flow. UPSR, like the one-plus-one scheme, has fast failure recovery, but it is not efficient because we need to have two rings that do the job of one. Half of the bandwidth is wasted.

Although we have chosen one sender and three receivers in the figure, there can be many other configurations. The sender uses a two-way connection to send data to both rings simultaneously; the receiver uses selecting switches to select the ring with better signal quality. We have used one STS multiplexer and three STS alemultiplexers to emphasize that nodes operate on the path layer.

Bidirectional Line Switching Ring

Another alternative in a SONET ring network is bidirectional line switching ring (BLSR). In this case, communication is bidirectional, which means that we need two rings for working lines. We also need two rings for protection lines. This means BLSR uses four rings. The operation, however, is similar to the one-to-one APS scheme. If a working ring in one direction between two nodes fails, the receiving node can use the reverse ring to inform the upstream node in the failed direction to use the protection ring. The network can recover in several different failure situations that we do not discuss here. Note that the discovery of a failure in BLSR is at the line layer, not the path layer. The ADMs find the failure and inform the adjacent nodes to use the protection rings.

Combination of Rings

SONET networks today use a combination of interconnected rings to create services in a wide area. For example, a SONET network may have a regional ring, several local rings, and many site rings to give services to a wide area. These rings can be UPSR, BLSR, or a combination of both.
Mesh Networks

One problem with ring networks is the lack of scalability. When the traffic in a ring increases, we need to upgrade not only the lines, but also the ADMs. In this situation, a mesh network with switches probably give better performance. A switch in a network mesh is called a cross-connect. A cross-connect, like other switches we have seen, has input and output ports. In an input port, the switch takes an OC-n signal, changes it to an STS-n signal, demultiplexes it into the corresponding STS-1 signals, and sends each STS-1 signal to the appropriate output port. An output port takes STS-1 signals coming from different input ports, multiplexes them into an STS-n signal, and makes an OC-n signal for transmission.


VIRTUAL TRIBUTARIES

SONET is designed to carry broadband payloads. Current digital hierarchy data rates (DS-1 to DS~3), however, are lower than STS-1. To make SONET backward-compatible with the current hierarchy, its frame design includes a system of virtual tributaries (VTs) . A virtual tributary is a partial payload that can be inserted into an STS-1 and combined with other partial payloads to fill out the frame. Instead of using all 86 payload columns of an STS-1 frame for data from one source, we can sub- divide the SPE and call each component a VT.

Types of VTs

Four types of VTs have been defined to accommodate existing digital hierarchies Notice that the number of columns allowed for each type of VT can be determined by doubling the type identification number

(VT1.5 gets three columns, VT2 gets four columns, etc.).
VT1.5 accommodates the U.S. DS-1 service (1.544 Mbps).
VT2 accommodates the European CEPT-1 service (2.048 Mbps).
VT3 accommodates the DS-1C service (fractional DS-l, 3.152 Mbps).
VT6 accommodates the DS-2 service (6.312 Mbps).


When two or more tributaries are inserted into a single STS-1 frame, they are interleaved column by column. SONET provides mechanisms for identifying each VT and separating them without demultiplexing the entire stream.


CDMA

| 0 responce(s) | Saturday, April 25, 2009
|














Code-Division Multiple Access (CDMA)

Code-division multiple access (CDMA) was conceived several decades ago. Recent advances in electronic technology have finally made its implementation possible. CDMA differs from FDMA because only one channel occupies the entire bandwidth of the link. It differs from TDMA because all stations can send data simultaneously; there is no timesharing.

Analogy

Let us first give an analogy. CDMA simply means communication with different codes. For example, in a large room with many people, two people can talk in English if nobody else understands English. Another two people can talk in Chinese if they are the only ones who understand Chinese, and so on. In other words, the common channel, the space of the room in this case, can easily allow communication between several couples, but in different languages (codes).

Idea

Let us assume we have four stations 1, 2, 3, and 4 connected to the same channel. The data from station 1 are d 1, from station 2 are d 2, and so on. The code assigned to the first station is cl, to the second is c2, and so on. We assume that the assigned codes have two properties.

1. If we multiply each code by another, we get 0.
2. If we multiply each code by itself, we get 4 (the number of stations).
With these two properties in mind, let us see how the above four stations can send data using the same common channel,

data that go on the channel are the sum of all these terms, as shown in the box. Any station that wants to receive data from one of the other three multiplies the data on the channel by the code of the sender. For example, suppose stations 1 and 2 are talking to each other. Station 2 wants to hear what station 1 is saying. It multiplies the data on the channel by c 1, the code of station 1.
Because (c 1 ?? Cl) is 4, but (c 2 ?? Cl), (c. Cl), and (c 4 - c 1) are all Os, station 2 divides
the result by 4 to get the data from station 1.
data = (d 1 - c t + d 2 ?? c 2 +d 3 - c 3 + d 4- c4) ?? c I
=d l.c 1.c l+d 2.c 2.c l+d 3-c 3.c l+d 4-c4.c l=4Xd

Chips

CDMA is based on coding theory. Each station is assigned a code, which is a sequence of numbers called chips.

Telephone networks

| 0 responce(s) | Sunday, April 19, 2009
|











TELEPHONE NETWORK
Telephone networks use circuit switching. The telephone network had its beginnings in the late 1800s. The entire network, which is referred to as the plain old telephone system (POTS), was originally an analog system using analog signals to transmit voice. With the advent of the computer era, the network, in the 1980s, began to carry data inaddition to voice. During the last decade, the telephone network has undergone many technical changes. The network is now digital as well as analog.

Major Components
there are three major components these are The telephone network, is made of three major components:

local loops, trunks, and switching offices. The telephone network has several levels of
switching offices such as end offices, tandem offices, and regional offices.

Local Loops
One component of the telephone network is the local loop, a twisted-pair cable that connects the subscriber telephone to the nearest end office or local central office. The local loop, when used for voice, has a bandwidth of 4000 Hz (4 kHz). It is interesting to examine the telephone number associated with each local loop. The first three digits of a local telephone number define the office, and the next four digits define the local loop number.

Trunks
Trunks are transmission media that handle the communication between offices. A trunk normally handles hundreds or thousands of connections through multiplexing. Transmission is usually through optical fibers or satellite links.

Switching Offices
To avoid having a permanent physical link between any two subscribers, the telephone company has switches located in a switching office. A switch connects several local loops or trunks and allows a connection between different subscribers.

LATAs
After the divestiture of 1984 (see Appendix E), the United States was divided into more than 200 local-access transport areas (LATAs). The number of LATAs has increased since then. A LATA can be a small or large metropolitan area. A small state may have one single LATA; a large state may have several LATAs. A LATA boundary may overlap the boundary of a state; part of a LATA can be in one state, part in another state.

Intra-LATA Services
The services offered 'by the common carriers (telephone companies) inside a LATA are called intra-LATA services. The carrier that handles these services is called a local exchange carrier (LEC). Before the Telecommunications Act of 1996 (see Appendix E), intra-LATA services were granted to one single carrier. This was a monopoly. After 1996, more than one carder could provide services inside a LATA. The carder that provided services before 1996 owns the cabling system (local loops) and is called the incumbent local exchange carrier (ILEC). The new carriers that can provide services are called competitive local exchange carriers (CLECs). To avoid the costs of new cabling, it was agreed that the ILECs would continue to provide the main services, and the CLECs would provide other services such as mobile telephone service, toll calls inside a LATA, and so on. Communication inside a LATA is handled by end switches and tandem switches. A call that can be completed by using only end offices is considered toll-free. A call that
has to go through a tandem office (intra-LATA toll office) is charged.Intra-LATA services are provided by local -exchange carriers. Since 1996, there are two types of LECs: incumbent local exchange carriers and competitive local exchange carriers.

Inter-LATA Services
The services between LATAs are handled by interexchange carriers (IXCs). These carders, sometimes called long-distance companies, provide communication services between two customers in different LATAs. After the act of 1996 (see Appendix E), these services can be provided by any carder, including those involved in intra-LATA services. The field is wide open. Carders providing inter-LATA services include AT&T, MCI, WorldCom, Sprint, and Verizon. The IXCs are long-distance carriers that provide general data communications services including telephone service. A telephone call going through an IXC is normally digitized, with the carders using several types of networks to provide service.

Points of Presence
As we discussed, intra-LATA services can be provided by several LECs (one ILEC and possibly more than one CLEC). We also said that inter-LATA services can be provided by several IXCs. How do these carriers interact with one another? The answer is, via a switching office called a point of presence (POP). Each IXC that wants to provide interLATA services in a LATA must have a POP in that LATA. The LECs that provide services inside the LATA must provide connections so that every subscriber can have access to all POPs. Figure 9.3 illustrates the concept. A subscriber who needs to make a connection with another subscriber is connected first to an end switch and then, either directly or through a tandem switch, to a POP. The call now goes from the POP of an IXC (the one the subscriber has chosen) in the source LATA to the POP of the same IXC in the destination LATA. The call is passed through the toll office of the IXC and is carried through the network provided by the IXC.

Signaling
The telephone network, at its beginning, used a circuit-switched network with dedicated links (multiplexing had not yet been invented) to transfer voice communication. As we saw in Chapter 8, a circuit-switched network needs the setup and teardown phases to establish and terminate paths between the two communicating parties. In the beginning, this task was performed by human operators. The operator room was a center to which all subscribers were connected. A subscriber who wished to talk to another subscriber picked up the receiver (off-hook) and rang the operaton The operator, after listening to the caller and getting the identifier of the called party, connected the two by using a wire with two plugs inserted into the corresponding two jacks. A dedicated circuit was created in this way. One of the parties, after the conversation ended, informed the operator to disconnect the circuit. This type of signaling is called in-band signaling because the same circuit can be used for both signaling and voice communication. Later, the signaling system became automatic. Rotary telephones were invented that sent a digital signal defining each digit in a multidigit telephone number. The switches in the telephone companies used the digital signals to create a connection between the caller and the called parties. Both in-band and out-of-band signaling were used. In in-band signaling, the 4-kHz voice channel was also used to provide signaling. In out-of-band signaling, a portion of the voice channel bandwidth was used for signaling; the voice bandwidth and the signaling bandwidth were separate. As telephone networks evolved into a complex network, the functionality of the signaling system increased. The signaling system was required to perform other tasks such as

1. Providing dial tone, ring tone, and busy tone
2. Transferring telephone numbers between offices
3. Maintaining and monitoring the call
4. Keeping billing information
5. Maintaining and monitoring the status of the telephone network equipment
6. Providing other functions such as caller ID, voice mail, and so on These complex tasks resulted in the provision of a separate network for signaling. This means that a telephone network today can be thought of as two networks: a signaling network and a data transfer network. The tasks of data transfer and signaling are separated in modern telephone networks: data transfer is done by one network, signaling by another.

However, we need to emphasize a point here. Although the two networks are separate, this does not mean that there are separate physical links everywhere; the two networks may use separate channels of the same link in parts of the system. Data Transfer Network The data transfer network that can carry multimedia information today is, for the most part, a circuit-switched network, although it can also be a packet-switched network. This network follows the same type of protocols and model as other networks discussed in this book.

Signaling Network
The signaling network, which is our main concern in this section, is a packet-switched network involving the layers similar to those in the OSI model or Internet model, nature of signaling makes it more suited to a packet-switching network with different layers. For example, the information needed to convey a telephone address can easily be encapsulated in a packet with all the error control and addressing information.

Signaling System Seven (SS7)
The protocol that is used in the signaling network is called Signaling System Seven (SS7). It is very similar to the five-layer Internet model

Physical Layer: MTP Level 1 The physical layer in SS7 called message transport part (MTP) level 1 uses several physical layer specifications such as T-1 (1.544 Mbps) and DC0 (64 kbps).

Data Link Layer: MTP Level 2 The MTP level 2 layer provides typical data link layer services such as packetizing, using source and destination address in the packet header, and CRC for error checking.

Network Layer: MTP Level 3 The MTP level 3 layer provides end-to-end connectivity by using the datagram approach to switching. Routers and switches route the signal packets from the source to the destination.

Transport Layer: SCCP The signaling connection control point (SCCP) is used for special services such as 800-call processing.

Upper Layers: TUP, TCAP, and ISUP There are three protocols at the upper layers. Telephone user port (TUP) is responsible for setting up voice calls. It receives the dialed digits and routes the calls. Transaction capabilities application port (TCAP) provides remote calls that let an application program on a computer invoke a procedure on another computer. ISDN user port (ISUP) can replace TUP to provide services similar to those of an ISDN network.

Services Provided by Telephone Networks
Telephone companies provide two types of services: analog and digital. Analog Services In the beginning, telephone companies provided their subscribers with analog services. These services still continue today. We can categorize these services as either analog switched services or analog leased services. Analog Switched Services This is the familiar dial-up service most often encountered when a home telephone is used. The signal on a local loop is analog, and the bandwidth is usually between 0 and 4000 Hz. A local call service is normally provided for a flat monthly rate, although in some LATAs, the carder charges for each call or a set of calls. The rationale for a non flat-rate charge is to provide cheaper service for those customers who do not make many calls. A toll call can be intra-LATA or inter-LATA. If the LATA is geographically large, a call may go through a tandem office (toll office) and the subscriber will pay a fee for the call. The inter-LATA calls are long-distance calls and are charged as such. Another service is called 800 service. If a subscriber (normally an organization) needs to provide free connections for other subscribers (normally customers), it can request the 800 service. In this case, the call is free for the caller, but it is paid by the callee. An organization uses this service to encourage customers to call. The rate is less expensive than that for a normal long-distance call. The wide-area telephone service (WATS) is the opposite of the 800 service. The latter are inbound calls paid by the organization; the former are outbound calls paid by the organization. This service is a less expensive alternative to regular toll calls; charges are based on the number of calls. The service can be specified as outbound calls to the same state, to several states, or to the whole country, with rates charged accordingly. The 900 services are like the 800 service, in that they are inbound calls to a sub- scriber. However, unlike the 800 service, the call is paid by the caller and is normally much more expensive than a normal long-distance call. The reason is that the carrier charges two fees: the first is the long-distance toll, and the second is the fee paid to the callee for each call.

Analog Leased Service
An analog leased service offers customers the opportunity to lease a line, sometimes called a dedicated line, that is permanently connected toanother customer. Although the connection still passes through the switches in the telephone network, subscribers experience it as a single line because the switch is always closed; no dialing is needed.

Digital Services
Recently telephone companies began offering digital services to their subscribers. Digital services are less sensitive than analog services to noise and other forms of interference. The two most common digital services axe switched/56 service and digital data service (DDS). Switched/56 Service Switched/56 service is the digital version of an analog switched line. It is a switched digital service that allows data rates of up to 56 kbps. To communivative through this service, both parties must subscribe. A caller with normal telephone service cannot connect to a telephone or computer with switched/56 service even if the caller is using a modem. On the whole, digital and analog services represent two completely different domains for the telephone companies. Because the line in a switched/ 56 service is already digital, subscribers do not need modems to transmit digital data. However, they do need another device called a digital service unit (DSU). Digital Data Service Digital data service (DDS) is the digital version of an analog
leased line; it is a digital leased line with a maximum data rate of 64 kbps.




Cryptography

| 0 responce(s) | Wednesday, April 15, 2009
|







Cryptography comes from the Greek words for ''secret writing.'' It has a long and colorful history going back thousands of years. In this section we will just sketch some of the highlights, as background information for what follows. For a complete history of cryptography, Kahn's (1995) book is recommended reading. For a comprehensive treatment of the current state-of-the-art in security and cryptographic algorithms, protocols, and applications, see (Kaufman et al., 2002). For a more mathematical approach, see (Stinson, 2002). For a less mathematical approach, see (Burnett and Paine, 2001).

Professionals make a distinction between ciphers and codes. A cipher is a character-for-character or bit-for-bit transformation, without regard to the linguistic structure of the message. In contrast, a code replaces one word with another word or symbol. Codes are not used any more, although they have a glorious history. The most successful code ever devised was used by the U.S. armed forces during World War II in the Pacific. They simply had Navajo Indians talking to each other using specific Navajo words for military terms, for example chay-dagahi-nail-tsaidi (literally: tortoise killer) for antitank weapon. The Navajo language is highly tonal, exceedingly complex, and has no written form. And not a single person in Japan knew anything about it.

In September 1945, the San Diego Union described the code by saying ''For three years, wherever the Marines landed, the Japanese got an earful of strange gurgling noises interspersed with other sounds resembling the call of a Tibetan monk and the sound of a hot water bottle being emptied.'' The Japanese never broke the code and many Navajo code talkers were awarded high military honors for extraordinary service and bravery. The fact that the U.S. broke the Japanese code but the Japanese never broke the Navajo code played a crucial role in the American victories in the Pacific.

Introduction to Cryptography

Historically, four groups of people have used and contributed to the art of cryptography: the military, the diplomatic corps, diarists, and lovers. Of these, the military has had the most important role and has shaped the field over the centuries. Within military organizations, the messages to be encrypted have traditionally been given to poorly-paid, low-level code clerks for encryption and transmission. The sheer volume of messages prevented this work from being done by a few elite specialists.

Until the advent of computers, one of the main constraints on cryptography had been the ability of the code clerk to perform the necessary transformations, often on a battlefield with little equipment. An additional constraint has been the difficulty in switching over quickly from one cryptographic method to another one, since this entails retraining a large number of people. However, the danger of a code clerk being captured by the enemy has made it essential to be able to change the cryptographic method instantly if need be.

The nonsecrecy of the algorithm cannot be emphasized enough. Trying to keep the algorithm secret, known in the trade as security by obscurity, never works. Also, by publicizing the algorithm, the cryptographer gets free consulting from a large number of academic cryptologists eager to break the system so they can publish papers demonstrating how smart they are. If many experts have tried to break the algorithm for 5 years after its publication and no one has succeeded, it is probably pretty solid.

Since the real secrecy is in the key, its length is a major design issue. Consider a simple combination lock. The general principle is that you enter digits in sequence. Everyone knows this, but the key is secret. A key length of two digits means that there are 100 possibilities. A key length of three digits means 1000 possibilities, and a key length of six digits means a million. The longer the key, the higher the work factor the cryptanalyst has to deal with. The work factor for breaking the system by exhaustive search of the key space is exponential in the key length. Secrecy comes from having a strong (but public) algorithm and a long key. To prevent your kid brother from reading your e-mail, 64-bit keys will do. For routine commercial use, at least 128 bits should be used. To keep major governments at bay, keys of at least 256 bits, preferably more, are needed.

From the cryptanalyst's point of view, the cryptanalysis problem has three principal variations. When he has a quantity of ciphertext and no plaintext, he is confronted with the ciphertext-only problem. The cryptograms that appear in the puzzle section of newspapers pose this kind of problem. When the cryptanalyst has some matched ciphertext and plaintext, the problem is called the known plaintext problem. Finally, when the cryptanalyst has the ability to encrypt pieces of plaintext of his own choosing, we have the chosen plaintext problem. Newspaper cryptograms could be broken trivially if the cryptanalyst were allowed to ask such questions as: What is the encryption of ABCDEFGHIJKL?

Novices in the cryptography business often assume that if a cipher can withstand a ciphertext-only attack, it is secure. This assumption is very naive. In many cases the cryptanalyst can make a good guess at parts of the plaintext. For example, the first thing many computers say when you call them up is login: . Equipped with some matched plaintext-ciphertext pairs, the cryptanalyst's job becomes much easier. To achieve security, the cryptographer should be conservative and make sure that the system is unbreakable even if his opponent can encrypt arbitrary amounts of chosen plaintext.

Encryption methods have historically been divided into two categories: substitution ciphers and transposition ciphers. We will now deal with each of these briefly as background information for modern cryptography.

Substitution Ciphers

In a substitution cipher each letter or group of letters is replaced by another letter or group of letters to disguise it. One of the oldest known ciphers is the Caesar cipher, attributed to Julius Caesar. In this method, a becomes D, b becomes E, c becomes F, ... , and z becomes C. For example, attack becomes DWWDFN. In examples, plaintext will be given in lower case letters, and ciphertext in upper case letters.

A slight generalization of the Caesar cipher allows the ciphertext alphabet to be shifted by k letters, instead of always 3. In this case k becomes a key to the general method of circularly shifted alphabets. The Caesar cipher may have fooled Pompey, but it has not fooled anyone since.

The next improvement is to have each of the symbols in the plaintext, say, the 26 letters for simplicity, map onto some other letter. For example,

plaintext: a b c d e f g h i j k l m n o p q r s t u v w x y z

ciphertext: Q W E R T Y U I O P A S D F G H J K L Z X C V B N M

The general system of symbol-for-symbol substitution is called a monoalphabetic substitution, with the key being the 26-letter string corresponding to the full alphabet. For the key above, the plaintext attack would be transformed into the ciphertext QZZQEA.

At first glance this might appear to be a safe system because although the cryptanalyst knows the general system (letter-for-letter substitution), he does not know which of the 26! 4 x 1026 possible keys is in use. In contrast with the Caesar cipher, trying all of them is not a promising approach. Even at 1 nsec per solution, a computer would take 1010 years to try all the keys.

Nevertheless, given a surprisingly small amount of ciphertext, the cipher can be broken easily. The basic attack takes advantage of the statistical properties of natural languages. In English, for example, e is the most common letter, followed by t, o, a, n, i, etc. The most common two-letter combinations, or digrams, are th, in, er, re, and an. The most common three-letter combinations, or trigrams, are the, ing, and, and ion.

A cryptanalyst trying to break a monoalphabetic cipher would start out by counting the relative frequencies of all letters in the ciphertext. Then he might tentatively assign the most common one to e and the next most common one to t. He would then look at trigrams to find a common one of the form tXe, which strongly suggests that X is h. Similarly, if the pattern thYt occurs frequently, the Y probably stands for a. With this information, he can look for a frequently occurring trigram of the form aZW, which is most likely and. By making guesses at common letters, digrams, and trigrams and knowing about likely patterns of vowels and consonants, the cryptanalyst builds up a tentative plaintext, letter by letter.

Another approach is to guess a probable word or phrase. For example, consider the following ciphertext from an accounting firm (blocked into groups of five characters):

CTBMN BYCTC BTJDS QXBNS GSTJC BTSWX CTQTZ CQVUJ
QJSGS TJQZZ MNQJS VLNSX VSZJU JDSTS JQUUS JUBXJ
DSKSU JSNTK BGAQJ ZBGYQ TLCTZ BNYBN QJSW

A likely word in a message from an accounting firm is financial. Using our knowledge that financial has a repeated letter (i), with four other letters between their occurrences, we look for repeated letters in the ciphertext at this spacing. We find 12 hits, at positions 6, 15, 27, 31, 42, 48, 56, 66, 70, 71, 76, and 82. However, only two of these, 31 and 42, have the next letter (corresponding to n in the plaintext) repeated in the proper place. Of these two, only 31 also has the a correctly positioned, so we know that financial begins at position 30. From this point on, deducing the key is easy by using the frequency statistics for English text.


Quantum Cryptography

Interestingly, there may be a solution to the problem of how to transmit the one-time pad over the network, and it comes from a very unlikely source: quantum mechanics. This area is still experimental, but initial tests are promising. If it can be perfected and be made efficient, virtually all cryptography will eventually be done using one-time pads since they are provably secure. Below we will briefly explain how this method, quantum cryptography, works. In particular, we will describe a protocol called BB84 after its authors and publication year (Bennet and Brassard, 1984).

A user, Alice, wants to establish a one-time pad with a second user, Bob. Alice and Bob are called principals, the main characters in our story. For example, Bob is a banker with whom Alice would like to do business. The names ''Alice'' and ''Bob'' have been used for the principals in virtually every paper and book on cryptography in the past decade. Cryptographers love tradition. If we were to use ''Andy'' and ''Barbara'' as the principals, no one would believe anything in this chapter. So be it.

If Alice and Bob could establish a one-time pad, they could use it to communicate securely. The question is: How can they establish it without previously exchanging DVDs? We can assume that Alice and Bob are at opposite ends of an optical fiber over which they can send and receive light pulses. However, an intrepid intruder, Trudy, can cut the fiber to splice in an active tap. Trudy can read all the bits in both directions. She can also send false messages in both directions. The situation might seem hopeless for Alice and Bob, but quantum cryptography can shed some new light on the subject.

Quantum cryptography is based on the fact that light comes in little packets called photons, which have some peculiar properties. Furthermore, light can be polarized by being passed through a polarizing filter, a fact well known to both sunglasses wearers and photographers. If a beam of light (i.e., a stream of photons) is passed through a polarizing filter, all the photons emerging from it will be polarized in the direction of the filter's axis (e.g., vertical). If the beam is now passed through a second polarizing filter, the intensity of the light emerging from the second filter is proportional to the square of the cosine of the angle between the axes. If the two axes are perpendicular, no photons get through. The absolute orientation of the two filters does not matter; only the angle between their axes counts.

To generate a one-time pad, Alice needs two sets of polarizing filters. Set one consists of a vertical filter and a horizontal filter. This choice is called a rectilinear basis. A basis (plural: bases) is just a coordinate system. The second set of filters is the same, except rotated 45 degrees, so one filter runs from the lower left to the upper right and the other filter runs from the upper left to the lower right. This choice is called a diagonal basis. Thus, Alice has two bases, which she can rapidly insert into her beam at will. In reality, Alice does not have four separate filters, but a crystal whose polarization can be switched electrically to any of the four allowed directions at great speed. Bob has the same equipment as Alice. The fact that Alice and Bob each have two bases available is essential to quantum cryptography.

For each basis, Alice now assigns one direction as 0 and the other as 1. In the example presented below, we assume she chooses vertical to be 0 and horizontal to be 1. Independently, she also chooses lower left to upper right as 0 and upper left to lower right as 1. She sends these choices to Bob as plaintext.

Now Alice picks a one-time pad, for example based on a random number generator (a complex subject all by itself). She transfers it bit by bit to Bob, choosing one of her two bases at random for each bit. To send a bit, her photon gun emits one photon polarized appropriately for the basis she is using for that bit. For example, she might choose bases of diagonal, rectilinear, rectilinear, diagonal, rectilinear, etc. To send her one-time pad of 1001110010100110 with these bases.

Two Fundamental Cryptographic Principles

Although we will study many different cryptographic systems in the pages ahead, two principles underlying all of them are important to understand.

Redundancy

The first principle is that all encrypted messages must contain some redundancy, that is, information not needed to understand the message. An example may make it clear why this is needed. Consider a mail-order company, The Couch Potato (TCP), with 60,000 products. Thinking they are being very efficient, TCP's programmers decide that ordering messages should consist of a 16-byte customer name followed by a 3-byte data field (1 byte for the quantity and 2 bytes for the product number). The last 3 bytes are to be encrypted using a very long key known only by the customer and TCP.

At first this might seem secure, and in a sense it is because passive intruders cannot decrypt the messages. Unfortunately, it also has a fatal flaw that renders it useless. Suppose that a recently-fired employee wants to punish TCP for firing her. Just before leaving, she takes the customer list with her. She works through the night writing a program to generate fictitious orders using real customer names. Since she does not have the list of keys, she just puts random numbers in the last 3 bytes, and sends hundreds of orders off to TCP.

When these messages arrive, TCP's computer uses the customer's name to locate the key and decrypt the message. Unfortunately for TCP, almost every 3-byte message is valid, so the computer begins printing out shipping instructions. While it might seem odd for a customer to order 837 sets of children's swings or 540 sandboxes, for all the computer knows, the customer might be planning to open a chain of franchised playgrounds. In this way an active intruder (the ex-employee) can cause a massive amount of trouble, even though she cannot understand the messages her computer is generating.

This problem can be solved by the addition of redundancy to all messages. For example, if order messages are extended to 12 bytes, the first 9 of which must be zeros, then this attack no longer works because the ex-employee can no longer generate a large stream of valid messages. The moral of the story is that all messages must contain considerable redundancy so that active intruders cannot send random junk and have it be interpreted as a valid message.

However, adding redundancy also makes it easier for cryptanalysts to break messages. Suppose that the mail order business is highly competitive, and The Couch Potato's main competitor, The Sofa Tuber, would dearly love to know how many sandboxes TCP is selling. Consequently, they have tapped TCP's telephone line. In the original scheme with 3-byte messages, cryptanalysis was nearly impossible, because after guessing a key, the cryptanalyst had no way of telling whether the guess was right. After all, almost every message is technically legal. With the new 12-byte scheme, it is easy for the cryptanalyst to tell a valid message from an invalid one. Thus, we have

Cryptographic principle 1: Messages must contain some redundancy

In other words, upon decrypting a message, the recipient must be able to tell whether it is valid by simply inspecting it and perhaps performing a simple computation. This redundancy is needed to prevent active intruders from sending garbage and tricking the receiver into decrypting the garbage and acting on the ''plaintext.'' However, this same redundancy makes it much easier for passive intruders to break the system, so there is some tension here. Furthermore, the redundancy should never be in the form of n zeros at the start or end of a message, since running such messages through some cryptographic algorithms gives more predictable results, making the cryptanalysts' job easier. A CRC polynomial is much better than a run of 0s since the receiver can easily verify it, but it generates more work for the cryptanalyst. Even better is to use a cryptographic hash, a concept we will explore later.

Getting back to quantum cryptography for a moment, we can also see how redundancy plays a role there. Due to Trudy's interception of the photons, some bits in Bob's one-time pad will be wrong. Bob needs some redundancy in the incoming messages to determine that errors are present. One very crude form of redundancy is repeating the message two times. If the two copies are not identical, Bob knows that either the fiber is very noisy or someone is tampering with the transmission. Of course, sending everything twice is overkill; a Hamming or Reed-Solomon code is a more efficient way to do error detection and correction. But it should be clear that some redundancy is needed to distinguish a valid message from an invalid message, especially in the face of an active intruder.

Freshness

The second cryptographic principle is that some measures must be taken to ensure that each message received can be verified as being fresh, that is, sent very recently. This measure is needed to prevent active intruders from playing back old messages. If no such measures were taken, our ex-employee could tap TCP's phone line and just keep repeating previously sent valid messages. Restating this idea we get.

Cryptographic principle 2: Some method is needed to foil replay attacks

One such measure is including in every message a timestamp valid only for, say, 10 seconds. The receiver can then just keep messages around for 10 seconds, to compare newly arrived messages to previous ones to filter out duplicates. Messages older than 10 seconds can be thrown out, since any replays sent more than 10 seconds later will be rejected as too old.



Subnet Masks

| 1 responce(s) |
|











Introduction to Subnet Masks

Subnet masks are one of the most interesting aspects of TCP/IP. Subnet masks point out to IP which bits of the 32-bit IP address refer to the network. A good network administrator understands how to determine and use subnet masks.


What Is a Subnet Mask?

A subnet mask is a number that looks like an IP address. It shows TCP/IP how many bits are used for the network portion of the IP address by covering up, or “masking,” the IP address’s network portion. As you learned in Chapter 6, an IP address is made up of two parts: the network portion and the host portion. For every outgoing packet, IP has to determine whether the destination host is on the same local network or on a remote network . If the destination is local, then IP uses an ARP broadcast to find out the hardware address of the destination host. If the destination host is not on the local network, then ARP broadcastsa request for the hardware address of the router. Therefore, IP sends packets that are bound for a remote network directly to the router, which is also known as the default gateway. The router then sends the packet to the next network on its journey to the correct destination network.Just as the telephone system uses an area code to determine whether a number is local or long distance, TCP/IP uses the subnet mask to determine whether the destination of a packet is a host on the local network or a host on a remote network. In the same way that every U.S. telephone number must have an area code, every IP address must have a subnet mask. If, for example, your telephone number is (619) 555-1212, and you call someone whose telephone number is (619) 345-1111, it is a local call. You know that because you can look at the numbers between the parentheses and see that they have the same value. If, on the other hand, your number is (619) 555-1212, and you call someone whose number is (213) 888-8146, it’s a long distance call. You know that because the numbers inside of the parentheses are different. You can think of the subnet mask as the area code in the parentheses of a telephone number. Just as an area code determines a phone call’s destination, a subnet mask tells IP how many bits to look at when determining if the destination IP address is local or remote.The following graphic shows Harry calling Amber. Since Amber has a different area code, the phone call will have to go through the router. When Harry calls Sally, however, it is a local call and does not need to go through the router. When determining if the packet is bound for the local network or a remote network, IP compares the network portion of the sender’s IP address with the same number of bits from the destination’s IP address. If the bit values are exactly the same, the packet’s destination is determined to be local. If there are
any differences in the bit values, the packet’s destination is determined to be remote. To know how many bits to compare, IP evaluates the subnet mask of the sending host. In the subnet mask, there is a series of 1s, and then the rest of the bits are set to 0. When IP evaluates the subnet mask, it is looking specifically for the answer to the question, “How many bits are set to 1?” Once IP determines how many bits are set to 1, it knows how many bits of the source host’s IP address and the destination host’s IP address will be compared.You can think of the number of bits that are set to 1 in the subnet mask as the number of digits inside the parentheses in a telephone number—if that number could change (in other words, if it’s variable). If, for example, a telephone number has 10 digits, imagine if the parentheses include 4, 5, or 6 digits. You would
then evaluate the number to be local or long distance based on the digits that are in the arentheses. If there are 8 bits set to 1 in the subnet mask, IP will compare the first 8 bits of the host with the first 8 bits of the destination. If there are 16 bits in the subnet mask that are set to 1, IP will compare the first 16 bits of host and destination. A subnet mask is a required element of every IP address. When you want to type in the IP address for a host, the only two required elements are the IP address itself and the subnet mask. Likewise, when you want to call someone, it is required that you know the correct area code for the phone number. You then
compare the first three characters of your phone number (your area code) with the first three characters of their phone number (their area code). If the area codes are the same, you don’t need to dial the area code, nor do you have to pay for a long distance call, because it is a local call. If the area code is not the same, however, you’ll have to dial their area code so that the telephone system can route your call to their city. You’ll see over the next several pages that IP looks at everything in binary. Subnet masks and routing will become clearer if you think about the IP addresses and subnet masks in binary, so begin now to think of IP addresses and subnet
masks as 32 bits. When thinking in binary, do not pay attention to the periods
that we use in the decimal representation. IP does not pay attention to the periods;
neither should we. Just consider the addresses as 32 1s and 0s.


Network and Host

subnet goggles
A fictional set of goggles that IP wears
when looking at an IP address to determine
whether an address is local or
remote. The goggles “light up” the network
and subnet bits with 1s as the bit
values in the subnet mask.
Applying a subnet mask is like looking through a set of “
subnet goggles
.” Imagine
wearing a set of goggles as you look at an IP address; you see all 32 bits, each
in its own slot. When you ask the question, “How many bits are used for the network
portion of this IP address?” the subnet mask lights up the slots that are in
the network portion of the address.
Through subnet goggles, 255.0.0.0 looks like this:
NNNN NNNN.
HHHH HHHH.HHHH HHHH.HHHH HHHH
The goggles light up the first 8 bits as the network portion (
N
), and the
remaining 24 bits are used for the host portion (H).
Through subnet goggles, 255.255.0.0 looks like this:
NNNN NNNN.NNNN NNNN.
HHHH HHHH.HHHH HHHH
The goggles light up the first 16 bits as the network portion.
The subnet mask simply provides a means to light up the correct slots so that
IP can figure out the number of bits used for the network portion of the address.
After IP figures this out, it can compare the address to that of another host to
determine whether that host is local or remote. Using our telephone number and
area code example, we can say that the subnet goggles are illuminating the area



Identifying a Local or Remote Network

With every packet that is sent across a network, the big question is: Is the destination
address local or remote? The destination is local if the network portion of the source’s IP address is the same as that of the destination’s IP address. If any bits of the network portions differ from each other, then the destination
is remote. This is similar to figuring out whether someone lives on the same street as you do. If you look at the person’s street name and it is the same as yours, the person lives on the same street as you do. If any part of the street name is different, the person is remote to your street. But, as stated earlier, before IP can figure out whether the destination address is remote, IP has to determine how many bits are in the network portion of the source IP address. IP uses the subnet mask to determine which bits of the IP address represent the network portion of the address.The subnet mask is 32 bits long, but you use dotted decimal notation to represent
it, just as you do with an IP address. A subnet mask, in binary, is made up of several contiguous 1s, which represent the network portion of the address, and then the rest of the bits are 0s. When determining how many of the 32 bits are in the network portion of an IP address, IP looks at the subnet mask for the contiguous 1s. When you look at a subnet mask in binary, imagine that the 1s represent the beginning and end of an area code. The number of bits set to 1 in the subnet mask is the number of bits that will be compared to determine if the destination is local or remote. This is similar to evaluating two telephone numbers by comparing the values that are inside the parentheses. The 1s in the subnet mask will act like the number of digits within the parentheses in an area code; these are the only values that are compared to determine if the destination is local or remote. When someone gives you their telephone number, you can tell if it is a long distance number just by looking at the digits in the parentheses. Likewise, the subnet mask’s only purpose is to determine how many bits are used to identify if the destination host of every packet is local or remote. For example, if the first 16 bits are set to 1, then IP compares the first 16 bits of the source IP address with the first 16 bits of the destination IP address. If these 16 bits are exactly the same, the destination host is local; if any of the bits are different,the destination host is remote. If the first 24 bits are set to 1, then IP compares the first 24 bits of the source IP address with the first 24 bits of the destination IP address. If these 24 bits are exactly the same, the destination host is local; if any of the bits are different, the destination host is remote. It is called a subnet “mask” for a good reason: it indicates or “masks” the network bits. Think of it as a shadow covering up some of the bits.


Standard Subnet Masks

In Chapter 6, you looked at the five classes of IP addresses. For each class of address, there is a standard, or default, subnet mask. Each is discussed in the following sections.

Class A Addresses

The standard subnet mask for a Class A address is 255.0.0.0. This tells IP that the first 8 bits are used for the network portion of the IP address, and the remaining 24 bits are used for the host portion. IP looks at the 32 bits and uses the subnet mask to mask out the network portion of the address: NNNN NNNN.HHHH HHHH.HHHH HHHH.HHHH HHHH

Because 24 bits are left for the host portion of the address, there are almost 17 million unique host IP addresses for each Class A network address.


Class B Addresses

A Class B address has a standard subnet mask of 255.255.0.0. This mask tells IP that the first 16 bits are used for the network portion of the address, and the remaining 16 bits are used for the host portion: NNNN NNNN.NNNN NNNN.HHHH HHHH.HHHH HHHH The 16 bits that are used for the host portion of the address can uniquely address more than 16,000 hosts on each Class B network.

Class C Addresses

A Class C address has a standard subnet mask of 255.255.255.0, which masks out the first 24 bits as the network portion and leaves the remaining 8 bits for the host portion:
NNNN NNNN.NNNN NNNN.NNNN NNNN. HHHH HHHH The 8 bits used for the host portion can uniquely address 254 hosts on each of the Class C networks.

In Summary

Class Subnet Masks(decimal) Standard Masks (Binary)


A 255.0.0.0 1111 1111.0000 0000.0000 0000.0000 0000

B 255.255.0.0 1111 1111.1111 1111.0000 0000.0000 0000


C 255.255.255.0 1111 1111.1111 1111.1111 1111.0000 0000

You can remember the standard masks this way:
1 octet = Class A (1st letter in the alphabet)
2 octets = Class B (2nd letter in the alphabet)
3 octets = Class C (3rd letter in the alphabet)
In most cases, however, using the standard subnet mask is not the optimal
solution for designing a TCP/IP addressing plan. Most implementations use a
variation of the standard subnet mask called a custom subnet mask, which is
explained in Chapter 9, “Using Custom Subnet Masks.”
The following screen capture shows a custom subnet mask being used.
Because the IP address has “10” in the first octet, this is a Class A address, and
the standard subnet mask is 255.0.0.0. However, the administrator has defined
a custom subnet mask of 255.255.255.240, which enables him to create more
networks with fewer hosts on each network.


Custom Subnet Mask will be posted later. (Regards - Utsav)


Broadband

| 1 responce(s) | Tuesday, April 14, 2009
|












Always-on Access

Before the late 1990s, people connected remotely to their offices or the Internet using dial up connections. An always-on remote network connection was not possible for a reasonable price. To connect to the corporate network, the user ran a program that dialed a phone number. Unless the user had a second phone line, being online prohibited incoming or outgoing phone calls. The user entered a user ID and password to gain access to the system. The fastest speed available over phone lines was 56 kbps, which was fine until the web became popular in the 1990s. Downloading large pictures, documents, applications, and audio files took what seemed like forever. Then, along came broadband. Broadband networking offered a reasonable high-speed alternative to traditional dialup networking. Using existing service connections to houses (such as phone wiring, cable TV coaxial cable, or even satellite), service providers offered Internet services at many times the speed of dialup. Downloading large files became palatable with broadband. Broadband technologies allow service providers to offer always-on connectivity similar to what people use in a corporate network. Computers on the broadband network always have access to the network; there is no intermediate dialup step. Sit down, load the browser, and off you go. High-speed Internet access to homes offers new levels of productivity and entertainment not possible before the commercialization of the Internet and the web. Aside from apparent uses such as online shopping and video streaming, corporations can accommodate road warriors and work-from-home folks in a way not previously possible. Using encryption technologies, an employee with a laptop computer can securely access her corporate network from any Internet access point in the world. Additionally, employees can attach IP phones, allowing them to work on their computers and make calls from their office-phone extensions as if they were sitting at their desks.

Broadband Technology Evolution

Integrated Services Digital Network (ISDN) was the first commercially viable broadband option available. Using existing phone lines, home users commonly subscribed to a Basic Rate Interface (BRI), which had a throughput maximum of 128 kbps. ISDN had some significant adoption in Europe, but in the U.S., ISDN was eclipsed by more cost-effective broadband technologies before it had a chance to become commonplace. Cable modem and digital subscriber line (DSL) services became the premier broadband technologies. Although other broadband technologies existed, the primary determination of a technology’s viability was access to “last mile” wiring to houses. Anything that required new wiring probably wouldn’t make it. Other technologies that take advantage of other media exist, such as satellite television dishes, but they did not become widely adopted. For those requiring even higher throughput, some providers now offer fiber links to homes as a premier service. This is already popular throughout major cities in Asia and is being installed in several cities in the U.S. as well.

Cable Modem

Cable modems provide high-speed data communication using existing cable television coaxial cabling. Current implementations of cable-modem technologies offer speeds as fast as Ethernet (greater than 10 Mbps). This means that a file that takes 2 minutes to transfer over ISDN takes 2 seconds over a cable modem. Cable modem can provide higher speeds than traditional leased lines, with lower cost and easier installation. Because a cable-modem connection is permanently established, it cannot dial multiple locations directly. As a result, cable-modem access must be to the Internet. This restriction means that employees can connect to their company’s network only if the company provides access through the Internet. Usually, this is done through a secure VPN connection.

DSL

Like cable modems, DSL provides high-speed Internet access for reasonable cost using existing cabling to houses and businesses. DSL carves off a portion of the telephone line to use for data transmission without interfering with existing phone service. Because of the multiple flavors of DSL services, DSL is generically referred to as xDSL. The two popular forms of xDSL service currently available are Asymmetric DSL (ADSL) and Symmetric DSL (SDSL). ADSL provides faster download speeds because traffic toward the user is given more bandwidth than traffic from the user. SDSL assigns equal bandwidth in both directions. ADSL is most often used for residential service, and SDSL is most often used in commercial settings, because of their different usage models.

Which One Is Better?

Both DSL and cable modems provide high-speed Internet access at a relatively low cost. Both provide always-on connectivity. Both have technical advantages and disadvantages. Either technology makes a good to-the-home or small office solution for Internet connectivity. Because both technologies are always on, a firewall must protect the local network from Internet-based attacks. Some practical issues affect how widespread the technologies become. Virtually all businesses and homes have telephone lines, which means that DSL is possible, but fewer homes and businesses have cable TV connections. In general, neither is “better,” and both types of service offer very high-speed connectivity for relatively low cost.

Digital Subscriber Line (DSL)

DSL uses the existing phone wires connected to virtually every home in most countries. The twisted-pair wires that provide phone service are ideal, because the available frequency ranges on the wires far exceed those required to carry a voice conversation. Human speech occupies frequencies of roughly 4000 hertz (4 kHz) or less. The copper wires that provide phone service can carry in the range of 1 to 2 million hertz (1 to 2 MHz). DSL provides more downstream data (from the Internet to you) than upstream data (from you to the Internet) based on user profiles, but this can be changed for businesses or those running web servers.

DSL Equipment

DSL requires some specialized equipment to ensure that the voice and data are kept separate and are routed to the right place. • Low-pass filters (LPF) are placed on all phone jacks not used by a computer to prevent interference from high-frequency data signals. DSL modems are the interface from the phone line to the computer. • DSL access multiplexers (DSLAM) aggregate hundreds of signals from homes and are the access point to the Internet.

Limitations and Advantages

DSL signals are distance-sensitive, which means that the available throughput decreases the farther your house is from the service provider. The maximum distance is about 18,000 feet. DSL signals cannot be amplified, nor can they be converted from one medium to another between the DSL modem and the DSLAM. (For example, opticalfiber extensions are not possible.) Typically the DSL company performs a line test to ensure that the service can be supported at a particular residence. The good news for DSL is that throughput is unaffected by the number of users so long as the phone company continues to add DSLAMs to support
new users.

Cable

Cable uses the same basic principle as DSL in that the bandwidth needed to accomplish the primary function is only a fraction of the available bandwidth on the wire or, in this case, cable. Cable is a slightly different concept in how it divides the available frequencies. The cable spectrum is already divided up into several hundred 6-MHz blocks to account for the various cable channels. Your cable-ready TV simply tunes its receiver to the frequency that corresponds
to the channel you have chosen. To add Internet capabilities, each user is assigned one or more blocks for downstream data (each 6-MHz block is good for about 30 Mbps of data). For the upstream piece, the lower end of the spectrum is divided into 2-MHz blocks, because most people download more information than they upload. Each subscriber is assigned one or more 2-MHz blocks.

 

Enter your email address:

Delivered by FeedBurner