MAC Address and ARP
MAC Address and ARP
Why MAC address?
- 32-bit IP address:
- network-layer address for interface
- used for layer 3 (network layer) forwarding/routing
- MAC (or LAN or physical or Ethernet) address:
- function: used ‘locally” to get frame from one interface to another physically-connected interface (same network, in IP-addressing sense)
- 48 bit MAC address (for most LANs) burned in NIC ROM, also sometimes software settable
- e.g.: 1A-2F-BB-76-09-AD
- hexadecimal (base 16) notation (each “numeral” represents 4 bits)
Notes:
- Think of The OSI Model
- Today we could probably lived without the MAC addresses, and just live with addresses at the IP layer
- So in the end we have 2 addresses
- MAC address
- IP address
- MAC addresses are basically used to address computers on your LAN
MAC addresses (more)
- MAC address allocation administered by IEEE
- manufacturer buys portion of MAC address space (to assure uniqueness)
- analogy:
- MAC address: like Social Security Number
- IP address: like postal address
- MAC flat address ➜ portability
- can move LAN card from one LAN to another
- IP hierarchical address not portable
- address depends on IP subnet to which node is attached
Notes:
- MAC addresses are completely flat
- It shouldn't be the case that 2 devices have the same MAC address
- If IP addresses were like these, it would be almost impossible look up addresses
- MAC addresses are completely random distributed around the world
ARP: address resolution protocol
Question: how to determine interface’s MAC address, knowing its IP address?
ARP table: each IP node (host, router) on LAN has table
- IP/MAC address mappings for some LAN nodes:
< IP address; MAC address; TTL>
- TTL (Time To Live): time after which address mapping will be forgotten (typically 20 min)
- Good thing because the network might leave the network at some point and have a new IP address when it comes back on
/CSCE-465-63860/Lecture/05%20-%20Applications%20II/Visual%20Aids/image-4.png)
ARP: how it works
- A wants to send datagram to B
- B’s MAC address not in A’s ARP table.
- A broadcasts ARP query packet, containing B's IP address
- destination MAC address =
FF-FF-FF-FF-FF-FF - all nodes on LAN receive ARP query
- destination MAC address =
- B receives ARP packet, replies to A with its (B's) MAC address
- frame sent to A’s MAC address (unicast)
- A caches (saves) IP-to-MAC address pair in its ARP table until information becomes old (times out)
- soft state: information that times out (goes away) unless refreshed
- ARP is "plug-and-play":
- nodes create their ARP tables without intervention from net administrator
Notes:
- There is no security in this protocol
- There is no encryption or authentication of any kind
- Anyone can send a broadcast
- What might be an issue, is if it is the wrong device replying to the broadcast
- We can reply to a broadcast even though we are not the ones requested to reply
Ethernet, Switch and VLAN
Ethernet: physical topology
- bus: popular through mid 90s
- coaxial cable
- all nodes in same collision domain (can collide with each other)
- star: prevails today
- active switch in center
- each “spoke” runs a (separate) Ethernet protocol (nodes do not collide with each other)
Notes:
- With a bus, if the link was broken somewhere or one of the host was missing, then the whole network could be shut down
- With a star, if one of the hosts disconnects, it does not affect the connection of the other hosts to the switch, keeping your network up
- There could also be some configurations on a switch
Ethernet frame structure
sending adapter encapsulates IP datagram (or other network layer protocol packet) in Ethernet frame
/CSCE-465-63860/Lecture/05%20-%20Applications%20II/Visual%20Aids/image-5.png)
- preamble:
- 7 bytes with pattern
10101010followed by one byte with pattern10101011 - used to synchronize receiver, sender clock rate
- 7 bytes with pattern
- addresses: 6 byte source, destination MAC addresses
- if adapter receives frame with matching destination address, or with broadcast address (e.g. ARP packet), it passes data in frame to network layer protocol
- otherwise, adapter discards frame
- type: indicates higher layer protocol (mostly IP but others possible, e.g., Novell IPX, AppleTalk)
- CRC: cyclic redundancy check at receiver
- error detected: frame is dropped
802.3 Ethernet standards: link & physical layers
- many different Ethernet standards
- common MAC protocol and frame format
- different speeds: 2 Mbps, 10 Mbps, 100 Mbps, 1Gbps, 10 Gbps, 40 Gbps
- different physical layer media: fiber, cable
/CSCE-465-63860/Lecture/05%20-%20Applications%20II/Visual%20Aids/image-6.png)
Ethernet switch
- link-layer device: takes an active role
- store, forward Ethernet frames
- examine incoming frame’s MAC address, selectively forward frame to one-or-more outgoing links when frame is to be forwarded on segment, uses CSMA/CD to access segment
- transparent
- hosts are unaware of presence of switches
- plug-and-play, self-learning
- switches do not need to be configured
Switch: multiple simultaneous transmissions
- Hosts have dedicated, direct connection to switch
- switches buffer packets
- Ethernet protocol used on each incoming link, but no collisions; full duplex
- each link is its own collision domain
- switching: A-to-A’ and B-to-B’ can transmit simultaneously, without collisions
Switch: self-learning
- switch learns which hosts can be reached through which interfaces
- when frame received, switch “learns” location of sender: incoming LAN segment
- records sender/location pair in switch table
/CSCE-465-63860/Lecture/05%20-%20Applications%20II/Visual%20Aids/image-7.png)
Switch table (initially empty)
| MAC addr | interface | TTL |
|---|---|---|
| A | 1 | 60 |
Switch: frame filtering/forwarding
when frame received at switch:
- record incoming link, MAC address of sending host
- index switch table using MAC destination address
Pseudo:
if entry found for destination
then {
if destination on segment from which frame arrived
then drop frame
else forward frame on interface indicated by entry
}
else flood /* forward on all interfaces except arriving interface */
Self-learning, forwarding: example
- frame destination, A’, location unknown:
- destination A location known:
- selectively send on just one link
| MAC addr | interface | TTL |
|---|---|---|
| A | 1 | 60 |
| A' | 4 | 60 |
Interconnecting switches
self-learning switches can be connected together:
/CSCE-465-63860/Lecture/05%20-%20Applications%20II/Visual%20Aids/image-8.png)
Q: sending from A to G - how does S1 know to forward frame destined to G via S4 and S3?
- A: self learning! (works exactly the same as in single-switch case
Notes:
- At some point our switches will be able to learn the MAC addresses from all devices and therefore will be able to communicate only through that link instead of broadcasting to all hosts whenever we want to talk to that single host
VLAN (Virtual LAN): motivation
consider:
- CS user moves office to EE, but wants connect to CS switch?
- single broadcast domain:
- all layer-2 broadcast traffic (ARP, DHCP, unknown location of destination MAC address) must cross entire LAN
- security/privacy, efficiency issues
Notes:
- Sometimes we want this isolation of networks, VLANs gives us that
/CSCE-465-63860/Lecture/05%20-%20Applications%20II/Visual%20Aids/image-9.png)
VLANs
port-based VLAN: switch ports grouped (by switch management software) so that single physical switch
Virtual Local Area Network:
- switch(es) supporting VLAN capabilities can be configured to define multiple virtual LANS over single physical LAN infrastructure.
- operates as multiple virtual switches
/CSCE-465-63860/Lecture/05%20-%20Applications%20II/Visual%20Aids/image-10.png)
Notes:
- In order to communicate between the 2 VLANs we need to do that through the IP layer (connecting a router!)
Port-based VLAN
- traffic isolation: frames to/from ports 1-8 can only reach ports 1-8
- can also define VLAN based on MAC addresses of endpoints, rather than switch port
- dynamic membership: ports can be dynamically assigned among VLAN
- forwarding between VLANS: done via routing (just as with separate switches)
- in practice vendors sell combined switches plus routers
Notes:
- Switches containing several VLANs will usually also contain a router inside to be able to communicate within them
Getting IP Address by DHCP
IP addresses: how to get one?
Q: How does a host get IP address?
- hard-coded by system admin in a file
- Windows: control-panel->network->configuration->tcp/ip->properties
- UNIX: /etc/rc.config
- DHCP: Dynamic Host Configuration Protocol: dynamically get address from as server
- “plug-and-play”
DHCP: Dynamic Host Configuration Protocol
- goal: allow host to dynamically obtain its IP address from network server when it joins network
- can renew its lease on address in use
- allows reuse of addresses (only hold address while connected/“on”)
- support for mobile users who want to join network (more shortly)
- DHCP overview:
- host broadcasts “DHCP discover” msg
[optional] - DHCP server responds with “DHCP offer” msg
[optional] - host requests IP address: “DHCP request” msg
- DHCP server sends address: “DHCP ack” msg
- host broadcasts “DHCP discover” msg
DHCP client-server scenario
/CSCE-465-63860/Lecture/05%20-%20Applications%20II/Visual%20Aids/image-11.png)
/CSCE-465-63860/Lecture/05%20-%20Applications%20II/Visual%20Aids/image-12.png)
- Note all messages are done through Broadcasting since the client doe snot have an IP address until the end
- A lot of broadcasts
- No encryption, no authentication
- Seems attackable
- Q: Who decides if you get IPv4 or IPv6?
- If IPv6 is supported maybe you'll get one but not sure
- IPv6 is not really used that much but all modern equipment support it
DHCP: more than IP addresses
DHCP can return more than just allocated IP address on subnet:
- address of first-hop router for client
- name and IP address of DNS sever
- network mask (indicating network versus host portion of address)
DHCP: example
/CSCE-465-63860/Lecture/05%20-%20Applications%20II/Visual%20Aids/image-13.png)
- connecting laptop needs its IP address, addr of first-hop router, addr of DNS server: use DHCP
- DHCP request encapsulated in UDP, encapsulated in IP, encapsulated in 802.1 Ethernet
- Ethernet frame broadcast (dest:
FFFFFFFFFFFF) on LAN, received at router running DHCP server - Ethernet demuxed to IP demuxed, UDP demuxed to DHCP
- DCP server formulates DHCP ACK containing client’s IP address, IP address of first-hop router for client, name & IP address of DNS server
- encapsulation of DHCP server, frame forwarded to client, demuxing up to DHCP at client
- client now knows its IP address, name and IP address of DSN server, IP address of its first-hop router