The CCNA tests whether you can reason about a network from the cable up to the routing table. Each idea below is one the quiz leans on, so if a question caught you out, the section for its topic explains why the answer is what it is.
The OSI model as a map
The OSI model splits networking into seven layers, each with one job and each relying on the layer below. You rarely configure 'the OSI model' directly, but it is how engineers say where a problem lives, and the CCNA uses it constantly.
| Layer | Name | What it deals with |
|---|---|---|
| 7-5 | Application, presentation, session | The data the app understands |
| 4 | Transport | End-to-end delivery: TCP, UDP |
| 3 | Network | IP addresses, routing |
| 2 | Data link | MAC addresses, frames, switches, VLANs |
| 1 | Physical | Cables, signals, bits |
The two layers that matter most day to day are 2 and 3. Layer 2 moves frames between devices on the same local network, using MAC addresses burned into each network card. Layer 3 moves packets between different networks, using IP addresses that you assign. A switch is a Layer 2 device: it learns which MAC address sits behind which port. A router is a Layer 3 device: it reads the destination IP address and decides which network to send the packet towards. Deciding the path between networks is routing, and routing is the network layer's job.
Cables and what they connect
Ethernet copper cables differ in how the wires are arranged at each end.
- A straight-through cable has the same wiring at both ends. It joins unlike devices, such as a PC to a switch or a switch to a router. The PC transmits on the pins the switch listens on, so no crossing is needed.
- A crossover cable swaps the transmit and receive pairs. It traditionally joins like devices: switch to switch, or PC to PC.
- A rollover (console) cable is not for data traffic at all. It connects your laptop to a router's or switch's console port, so you can configure it before it has an IP address.
- Coaxial cable belongs to older Ethernet and to cable broadband, not to modern LAN access ports.
Most modern switch ports support auto-MDIX, which detects the wiring and crosses the pairs itself, so the wrong cable often works anyway. The exam still expects you to know the rule, because it tells you how the pins are meant to line up.
TCP: a conversation with rules
TCP is connection-oriented: before any data flows, the two ends agree to talk with a three-way handshake. The client sends a SYN, the server answers with a SYN-ACK, and the client confirms with an ACK. From then on every segment is numbered and acknowledged, so TCP can resend what is lost, put segments back in order and slow down when the network is congested.
UDP, the other common Layer 4 protocol, skips all of that. It is connectionless: it sends datagrams and does not check they arrived. That sounds worse, but it suits traffic where a late packet is useless anyway, such as voice calls, games and DNS lookups.
A common mix-up is to think 'connection-oriented' means there is a physical circuit. It doesn't: it means both ends keep state about the conversation.
ARP: from IP address to MAC address
A PC knows the IP address it wants to reach, but a frame on the local network needs a destination MAC address. ARP, the Address Resolution Protocol, fills that gap.
Here is one lookup on a small network where PC A wants to reach 10.0.0.2:
An ARP request and reply on one switch
Step 1 of 7: PC A wants to reach 10.0.0.2, but its ARP cache has no MAC address for it.
The request is a broadcast because PC A doesn't yet know who to address it to; the reply is unicast because PC B now knows exactly who asked. The answer sits in the ARP cache for a while, so the next frame skips the lookup. You can see your own cache with arp -a on Windows, macOS or Linux.
ARP only works inside one local network. To reach a host on another network, the PC ARPs for its default gateway instead and lets the router carry the packet on. Don't confuse ARP with its neighbours: DNS turns names into IP addresses, DHCP hands out IP addresses, and ICMP carries error and diagnostic messages such as ping.
Subnet masks and prefix length
An IPv4 address is 32 bits, and the subnet mask marks which of those bits name the network and which name the host. Prefix notation, like /24, is just a count of the network bits.
So /24 means 24 ones followed by 8 zeros. Written as four octets, that is 255.255.255.0: three octets of all ones (255 each) and one of zeros. A /16 is 255.255.0.0 and a /8 is 255.0.0.0.
For 192.168.1.0/24, the first three octets are the network and the last octet is for hosts. Eight host bits give 256 addresses, minus the network address and the broadcast address, which leaves 254 usable hosts. Every extra prefix bit halves that: a /25 has 126 usable hosts.
VLANs: several networks on one switch
A VLAN splits one physical switch into several separate broadcast domains. Ports in VLAN 10 and ports in VLAN 20 behave as if they were on different switches: a broadcast in one never reaches the other.
VLANs are a Layer 2 feature. The switch tags frames with a VLAN number and keeps them apart by that tag, without looking at IP addresses. The confusion comes from the fact that each VLAN usually gets its own IP subnet, and traffic between VLANs needs a router or a Layer 3 switch. That routing step is Layer 3; the VLAN itself is not. On a Cisco switch, show vlan brief lists each VLAN and the ports in it.
Reading the routing table
A router forwards packets by looking up the destination in its routing table. On a Cisco router, show ip route prints it. Each line shows a network, how the router learned it (a code such as C for connected, S for static, O for OSPF, D for EIGRP) and the next hop or exit interface. The other show commands answer different questions: show mac address-table is the switch's Layer 2 view, show interfaces shows port status and errors, and show vlan brief lists VLANs.
Administrative distance
When two routing sources offer a route to the same network, the router trusts the one with the lower administrative distance (AD). It is a measure of how believable the source is, not of how good the path is.
| Source | Default AD |
|---|---|
| Directly connected | 0 |
| Static route | 1 |
| EIGRP (internal) | 90 |
| OSPF | 110 |
| RIP | 120 |
So if OSPF and RIP both know a route, the OSPF route goes in the table. Metrics, such as OSPF cost or RIP hop count, only compare routes from the same protocol.
How routing protocols differ
Routing protocols fall into families by how they share what they know.
- Distance-vector protocols, like RIP, tell their neighbours 'this network is this far away'. Each router trusts its neighbours' view.
- Link-state protocols, like OSPF, share a map of every link, and each router works out the best paths itself.
- EIGRP is Cisco's advanced distance-vector protocol, with faster convergence than RIP.
- BGP is a path-vector protocol. Each route carries the list of autonomous systems it has passed through.
An autonomous system (AS) is a network run under one routing policy, such as an ISP or a large company, identified by an AS number. BGP routes between them, which is why it runs the internet. The AS path lets BGP spot loops (a route that already lists your own AS is rejected) and apply policy about which networks to prefer. EIGRP also uses an AS number in its configuration, but only to group routers in one domain; it is not a path-vector protocol.
Spanning Tree Protocol
Switches are often linked in a loop for redundancy, but Ethernet frames have no time-to-live. A broadcast on a loop would circle forever and multiply, which is a broadcast storm. The Spanning Tree Protocol (STP) prevents that by choosing one path and blocking the redundant ones.
Switches exchange BPDUs (bridge protocol data units) to elect a root bridge and decide which ports forward. In classic STP a port moves through these states:
- Blocking: discards data frames, but keeps listening to BPDUs so it can take over if the active path fails.
- Listening: taking part in the election, still not forwarding.
- Learning: filling the MAC address table, still not forwarding. Like listening, it is a short stop on the way to forwarding.
- Forwarding: sending and receiving data normally.
- Disabled: shut down by an administrator, taking no part in STP.
Blocking is what breaks the loop, and listening to BPDUs is what lets the network recover by itself when a link goes down. Rapid STP merges some of these states, but the idea is the same.
Key takeaways
- Layer 2 moves frames by MAC address within a network; Layer 3 routes packets by IP address between networks. VLANs are Layer 2.
- Straight-through joins unlike devices, crossover joins like ones, and rollover is for the console.
- TCP sets up a connection and guarantees delivery; ARP finds the MAC address for a local IP address.
- A
/24is255.255.255.0, and lower administrative distance wins: OSPF is 110. - BGP is the path-vector protocol between autonomous systems, and STP's blocking state stops loops while still listening for BPDUs.