Subscribe by Email


Showing posts with label IP. Show all posts
Showing posts with label IP. Show all posts

Thursday, September 19, 2013

What is fragmentation?

- The fragmentation technique is implemented in the IP (internet protocol) for breaking down the datagrams into smaller pieces. 
- This is done so that it becomes easy for the data packets to be passed through the link with a datagram size smaller than that of the original MTU or the maximum transmission unit. 
- The procedure for the IP fragmentation along with the procedures for reassembling and transmitting the datagrams is given in the RFC 791. 
- For determining the optimal MTU path, the IPv6 hosts are needed so that the packets can be sent. 
- If in case the PDU i.e., the protocol data unit received by the router is larger than the MTU of the next hop, then there are two options are available if IPv4 transport is being used:
Ø Dropping the PDU and sending an ICMP (internet control message protocol) message indicating that the condition packet is quite big.
Ø  Fragmenting the IP packet and then transmitting it over the link whose MTU is smaller. Any IPv6 packet with a size less than or equal to 1280 bytes can be delivered without having the need for using the IPv6 fragmentation.

- If a fragmented IP packet is received by the recipient host, its job is to reassemble the datagram and then send it over to the protocols at the higher layers. 
- The purpose of reassembling is expected to take place at the recipient’s host side but for some practical reasons it might be done by some intermediate router. 
- For example, the fragments might be reassembled by the NAT (network address translation) for translating the data streams. 
- Excessive re-transmission can result as a consequence of the IP fragmentation whenever packet loss might be encountered by the fragments. 
- It is required for all the reliable protocols (example, TCP) for re-transmitting the fragments in their correct order for recovering from the single fragment loss. 
Thus, typically two approaches are used by the senders for determining datagrams of what size should be transmitted over the network:
  1. First approach: The sender must transmit an IP datagram of size as same as that of the first hop’s MTU.
  2. Second approach: Running the path MTU discovery algorithm.

- Fragmentation does leave an impact on the network forwarding. 
- When there are multiple parallel paths for the internet router the traffic is split by the technologies such as the CEF and LAG throughout the links via some hash algorithms. 
- The major goal of this algorithm is to make sure that all the packets with the same flow are transmitted out on the same path for the minimization of the not so required packet reordering. 
- If the TCP or UDP port numbers are used by the hash algorithm, the fragmented packets might be forwarded through different paths. 
- This is so because the layer 4 information is contained only in the first fragment of the packet. 
- As a result of this, usually the initial fragment arrives after the non-initial fragments. 
- This condition is often treated as an error by most of the security devices in the hosts.  
- Therefore, they drop these packets.
- The fragmentation mechanism differs in IPv4 and IPv6. 
- In the former, the fragmentation is performed by the router. 
- On the other hand, in IPv6 fragments that are larger than MTU are dropped by the routers.
- Also, in both the cases there is a variation in the header format. 
- Since fragmentation is carried out using analogous fields, therefore the algorithm can be used again and again for the purpose of fragmentation and reassembling. 
- A best effort should be made by the IPv4 hosts for reassembling the datagram fragments. 


Saturday, August 24, 2013

Explain multicast routing?

- Multicast routing is also known as the IP multicast. 
- For sending the IP (internet protocol) data-grams to a group of receivers who are interested in receiving the data-grams, multicast routing is used.
- The data-grams are sent to all the receivers in just one transmission. 
- Multicast routing has got a special use in the applications that require media streaming on private networks as well as internet. 
- Multicast routing is IP specific version. 
- A more general version is the multicast networking.
- Here, the multicast address blocks are especially reserved in IPv6 and IPv4. 
- Broadcast addressing has been replaced by multicast addressing in IPv6. 
- Broadcast addressing was used in IPv4. 
- RFC 1112 describes the multicast routing and in 1986 it was standardized. 

This technique is used for the following types of real – time communication over the IP infrastructure of the network:
Ø  Many – to – many
Ø  One – to – many

- It scales up to receiving population that is large enough and it does not require either knowledge regarding the receivers and the identity of the receivers. 
- Network infrastructure is used efficiently by the multicast efficiently and requires source sending packet to a large number of receivers only once. 
- The responsibility of the replication of the packet is of the nodes which are nothing but the routers and the network switches.
- The packet has to be replicated till it reaches the multiple receivers. 
- Also, it is important that the message is sent only once over the link.   
- UDP or the user data gram protocol is the mostly used protocol of low level. 
- Even though if this protocol does not guarantees reliability i.e., the packets might get delivered or get lost. 
- There are other multicast protocols available that are reliable such as the PGM or the pragmatic general multicast. 

It has been developed for adding the following two things a top the IP multicast:
Ø  Retransmission and
Ø  Loss detection
The following 3 things are key elements of an IP multicast:
  1. Receiver driven tree creation
  2. Multicast distribution tree
  3. IP multicast group address
- The receivers and the sources use the last for sending as well as receiving the multicast messages. 
- The group address serves as the destination address of the data packets for the sources whereas it is used for informing the network whether or not the receivers want those packets.
- Receivers need a protocol for joining a group. 
- One most commonly used protocol for this purpose is the IGMP i.e., the internet group management protocol. 
- The multicast distribution trees are set up using this protocol. 
- Once a group has been joined by the receiver, the PIM (protocol independent multicast) protocol is used for constructing a multicast distribution tree for this group. 
- The multicast distribution trees set up with the help of this protocol are used for sending the multicast packets to the members of the multicast group. 

PIM can be implemented in any of the following variations:
  1. SM or sparse mode
  2. DM or dense mode
  3. SSM or source specified mode
  4. SDM or sparse – dense mode or bidirectional mode (bidir)

- Since 2006, the sparse mode is the most commonly used mode. 
- The last two variations are more scalable and simpler variations of PIM and are also popular. 
- An active source is not required for carrying out an IP multicast operation and knowing about the group’s receivers. 
- The receiver drives the construction of the IP multicast tree. 
- The network nodes which lie closer to receiver are responsible for initiating this construction.
- This multicast then scales to a receiver population that is large enough. 
- It is important for a multicast router to know which all multicast trees can be reached in the network. 
- Rather, it only requires knowledge of its downstream receivers. 
- This is how the multicast – addressed services can be scaled up. 


Saturday, August 17, 2013

What is reverse path forwarding?

- RPF or reverse path forwarding is a common technique used for ensuring that the multicast packets are forwarded without any loops in the modern routers in multicast routing. 
- This technique is also used for the prevention of the IP address spoofing during the unicast routing.
- Multicast RPF or just RPF is not used alone. 
- Rather, it is used along with some multicast routing protocol. 
- There are various multicast routing protocols such as the PIM – SM, PIM – DM, MSDP and so on. 
- This is for ensuring that no loops are formed in forwarding the multicast packets. 
- Source address is used for deciding whether the traffic has to be forwarded or not in multicast routing. 
- On the other hand in unicast routing, this depends up on the destination address instead of source address. 
- This it achieves either through utilization of either the unicast routing table of the router or a multicast routing table that has been dedicated to the purpose. 
- As and when a packet comes to the interface of the router, it searches in the networks list for the networks that can be reached through this interface. 
- This is nothing but the reverse path checking of the multicast packet.  
- If the appropriate routing entry is found for the multicast packet’s source IP address, it is said to pass the RPF check. 
- After this the packet is sent to all the participating interfaces in that particular multicast group.  
- If the packet fails at this RPF check, the packet is simply dropped. 
- Because of this, the packet forwarding has to be decided depending up on its reverse path. 
- Otherwise, the forward path can be used as usual. 
- Only those packets are forwarded by the RPF routers which pass this RPF check. 
- Passing this RPF check means breaking any loop that might otherwise exist. 
- This is of critical importance in the multicast topologies that are redundant. 
- This is so because it is possible for the same packet to come again and again to the same router through a number of multiple interfaces. 
- The RPF check is an integral part of the decision concerning forwarding of the packets. 
- Consider a router forwarding a packet from first interface to the second interface and also from second interface to the first one. 
- Thus, the same packet is received by the two packets, thus creating a common routing loop. 
- This loop will keep on forwarding the packets until the expiry of their TTLs. 
- Even if the TTL expiry is considered, the best thing to do is to avoid the routing loops because they are a main cause of the temporary network degradation.

RPF check has the following underlying assumptions:
  1. The given unicast routing table is converged as well as correct.
  2. There is symmetry between the path that goes from sender to router and the path that comes back from the router to the sender.
- RPF check uses the unicast routing table as the fallback. 
- Therefore, if the first assumption is not satisfied, the check will fail. 
- But in case the second assumption is false, the multicast traffic is rejected by the RPF check save the traffic on the shortest path that exists between the sender and the router. 
- This results in a multicast tree that is non–optimal.
- The reverse path forwarding will not work if there are uni-directional links present in the network.


Unicast RPF: 
- This type of the reverse path forwarding is based up on the concept that the interface which does not originate traffic must not accept it. 
- It is good for the organizations to not allow private address propagation on their network until and unless they are continuously using it. 


Monday, August 12, 2013

What are different methods of broadcasting a packet?

Without broadcasting, our information theory and telecommunications does not mean anything. 
- It is broadcasting that actually makes the transfer of data possible from one point to another. 
- Broadcasting can be defined as the method of transfer of a message to a number of recipients, all at the same time. 
- Broadcasting is often considered to be a sort of high – level operation in some programs while low level operation in some other programs. 
- For example, in message passing interface, broadcasting is a high level operation whereas in broadcasting on Ethernet, it is considered to be a low level operation in networking. 

We have many kinds of routing schemes suiting for various kinds of broadcasting requirements:
  1. Anycast
  2. Broadcast
  3. Multicast
  4. Unicast
  5. Geocast
- Broadcasting is transmission of a packet to each and every device that is attached to the network. 
- However, the broadcasting is limited to transmission in the broadcast domain in practical applications. 
- Broadcasting can be contrasted with uni cast routing scheme in the sense that in uni cast, the datagrams are transmitted by one host and are received by another single host only. 
- This receiving host is identified with an IP address on the network that is unique to it. 
- All the technologies used in networking are not capable of supporting broadcasting. 

For example, the following do not have this capability:
Ø  X.25 relay
Ø  Frame relay

- The broadcast method cannot be implement with IPv6 i.e., the successor of the IPv4 (internet protocol version 4).
- This is for the avoidance of the disturbance to the nodes. 
- Also, there does not exist anything such as the internet wide broadcast. 
- Therefore, this limits the scope of the broadcasting to the LAN technologies such as token ring and Ethernet since here the impact of the broadcasting performance is small.

Categories of Broadcasting Methods

The broadcasting methods can be classified in to 4 major categories as per the IEEE 802.11 standard:

1. Simple flooding method: 
- In this method the packets are rebroadcast-ed by each of the nodes.
- A message is disseminated to all the neighboring nodes by a source node in the MANET. 
- If the neighboring nodes would have received this message already, then this time the message will be dropped.
- If not, they will re-disseminate the message to their neighbors simultaneously. 
- This process continues until all the nodes have received this message. 
- Only for a MANET this method proves to be reliable that too only if the nodes have low density as well as high mobility. 
- This method has a good potential for harming the network and make it unproductive. 
- This happens so because it will cause congestion in the network thereby exhausting the power of the battery.

2. Area based broadcasting method: 
- Here, we assume a transmission distance.
- Only if sufficient coverage area is detected, the node can rebroadcast otherwise not. 
- This method can be of two types namely location based scheme and the distance based scheme.

3. Probability tested: 
- Rebroadcasting is done by the nodes depending up on the network’s topology and probabilities assigned to them. 
- This somewhat resembles the flooding algorithm with the only exception that a predetermined probability is used for rebroadcasting by the nodes.
- The transmission coverage might be shared by the multiple nodes where the network is too dense.

4. Neighborhood based broadcasting method: 
- Neighborhood method is used for maintaining a state in the neighborhood and rebroadcasting is done with the help of the info obtained from the nodes in this neighboring area. 
- There are two types of this method namely self-pruning approach and ad hoc broadcasting approach.      


Saturday, March 9, 2013

What is meant by Dynamic Virtual Private Network?


Dynamic virtual private network or DVPN is a network used for interconnecting various virtual application networks. 
- These networks reduce the need for manual configuration by a large percentage (almost by 93 %). 
- Dynamic virtual private networks help a great deal in the simplification of the wide area connectivity spread across a virtual application network.
- These networks have a great complexity when compared to the other networks.
- Further, they prove useful in establishing interconnections between various campuses, data centers, and offices and so on via IPsec VPN encryption. 
- The solution offered by the DVPNs is quite scalable, simple and secure. 
- The dynamic virtual private networks are highly automated and therefore provide a simple management solution. 
- A DVPN can scale up to 1000 – 3000 sites on a single router. 
- All these sites together constitute the domain of the DVPN. 
- So it is obvious that a very large network can be scaled via multiple DVPNs. 
- The best thing about these DVPNs is that they support all the WAN technologies and therefore can be implemented up on all.
- Furthermore, they offer flexibility in reducing the cost when compared to the lower cost broadband access.
- All the network operations are simplified since DVPN has automated VPN setup plus provisioning.
- DVPNs offer high resilience without adding to the complexity of the network. 
- Another characteristic feature of a dynamic virtual private network is its carrier agnostic connectivity.
- One solution to DVPN is offered by HP that has got the following features:
  1. Full mesh or hub – spoke configuration
  2. Encryption based up on IPsec standards.
  3. The control plane and the data plane have been separated to ensure scalability.
  4. Up to 30,000 clients are supportable by the VAM (VPN address management) server.
  5. Offers zero touch configuration.
- Another solution is offered by the Juniper networks. 
- Juniper’s DVPN is more of a client-less solution and has been designed for ‘remote access’ IPsec VPN. 
- The delivery of the client to the end users is made dynamically from SRX. 
- The remote access is simplified by DVPN since it provides the users the facility to secure the IPsec VPN tunnels without any need for configuring the VPN settings on their systems. 
- This whole process comes in to when the users login to the server’s web site. - Juniper’s DVPN solution can be licensed to 5, 10, 25 or 50 concurrent users. 
- It supports windows xp and above versions (both 32 and 64 bit).
- However, there are certain limitations for this solution:
  1. It requires an external RADIUS server for providing an IP address and for XAUTH.
  2. Does not support shared IKE id.
  3. Mandatory PFS (perfect forward secretary).
  4. Requires custom IKE/ IPsec security proposals.
  5. Only IKE – id supported is the FQDN.
- Configuration for DVPN is required only on the SRX gateway.
- Dynamic virtual private network is more of an intranet enabler whose purpose is to complement the regular services offered by the internet by adding more services as well as resources to it. 
- One major feature of these networks is that they have an excellent ability of loading balance on – the – fly allocation of the resources. 
- These networks are more popular in businesses since they offer more security by means of packet encryption protocols. 
- Self – modification is possible for the DVPNs and so they are able to recognize the added nodes without help from routers.
- Encryption and authentication are two technologies used by DVPNs for securing packing data and delivering across the networks. 
- Until the data reaches it destination it remains unpacked or encapsulated. 
- For reaching the remote networks tunneling is used. 


Facebook activity