WEBVTT

00:00:00.000 --> 00:00:03.950
Welcome back to CSE 316 — Data Communication and Networking.

00:00:04.000 --> 00:00:07.780
This is the detailed video version of Session 7.

00:00:07.830 --> 00:00:16.260
Everything so far has been about the wire: what a signal is, what it can carry, and how long it takes.

00:00:16.310 --> 00:00:25.040
Today we climb one floor and meet the layer that decides what actually gets written on the front of the envelope.

00:00:25.090 --> 00:00:33.683
There is a checkpoint at the end of each section, so you can tell whether to go on or go back.

00:00:33.733 --> 00:00:36.713
Here is the question this session answers.

00:00:36.763 --> 00:00:42.323
Your laptop already knows the IP address of the server it wants to reach.

00:00:42.373 --> 00:00:45.923
It has the number. Nothing is missing.

00:00:45.973 --> 00:00:54.773
And yet, before it sends a single byte, it shouts a question at every machine in the room: WHO HAS 10.0.2.1?

00:00:54.823 --> 00:00:59.103
So write down two answers before we begin.

00:00:59.153 --> 00:01:02.873
First: why is knowing the IP address not enough?

00:01:02.923 --> 00:01:09.763
And second: why does the asking have to be a shout, rather than a question put quietly to the one machine that knows?

00:01:09.813 --> 00:01:18.503
Both answers are in today's session. And note the address now: ten dot zero dot two dot one is not the server.

00:01:18.553 --> 00:01:21.133
Section four says whose address it is.

00:01:21.183 --> 00:01:25.143
Today the datagram stops being the only thing on the wire.

00:01:25.193 --> 00:01:34.143
It starts travelling inside a frame — an envelope that is built, read, and thrown away at every single hop of the journey.

00:01:36.997 --> 00:01:38.277
Section one.

00:01:38.327 --> 00:01:40.807
One datagram, many frames.

00:01:40.857 --> 00:01:49.377
The vocabulary of chapter nine, and the single duty the data-link layer actually has.

00:01:49.427 --> 00:01:54.327
Four words, and I am going to use them exactly for the rest of the session.

00:01:54.377 --> 00:01:58.187
Nodes are the machines — hosts and routers.

00:01:58.237 --> 00:02:01.247
Every node has at least one link attached to it.

00:02:01.297 --> 00:02:06.247
A router has several, which is precisely why a router is interesting.

00:02:06.297 --> 00:02:09.807
Links are the networks between those nodes.

00:02:09.857 --> 00:02:15.577
Each link may run a completely different protocol, with a completely different frame format.

00:02:15.627 --> 00:02:22.037
Ethernet on this one, Wi-Fi on that one, something else entirely on the fibre in between.

00:02:22.087 --> 00:02:25.997
Now the duty, and this is the sentence of the day.

00:02:26.047 --> 00:02:31.187
The data-link layer delivers the datagram to the NEXT machine along the path.

00:02:31.237 --> 00:02:34.487
Never to the far end. Only to the next node.

00:02:34.537 --> 00:02:43.397
Say it out loud once — node to node — because the most expensive mistake in this chapter is answering "source to destination".

00:02:43.447 --> 00:02:47.067
And that duty has an immediate consequence.

00:02:47.117 --> 00:02:52.697
Alice sending to Bob across two routers is one datagram and three frames.

00:02:52.747 --> 00:02:56.597
Each frame is built at one node and destroyed at the next.

00:02:56.647 --> 00:03:03.979
Three links, three frames, and not one of them survives the journey.

00:03:04.029 --> 00:03:08.219
Two cards, and they are the two halves of everything that follows.

00:03:08.269 --> 00:03:10.479
On the left, the datagram.

00:03:10.529 --> 00:03:15.549
It is written once, at the source. Source IP, destination IP, payload.

00:03:15.599 --> 00:03:24.249
Those two addresses name the two ends of the whole journey, and they are sealed. No link on the way may rewrite them.

00:03:24.299 --> 00:03:27.009
And on the right, the frame.

00:03:27.059 --> 00:03:31.849
A header and a trailer, wrapped around that datagram, for ONE link.

00:03:31.899 --> 00:03:40.539
At the next node the wrapper is stripped off, read, and thrown away — and a completely fresh one is written for the next link.

00:03:40.589 --> 00:03:44.769
So here is the test to apply whenever you are unsure.

00:03:44.819 --> 00:03:46.669
Ask what changed at the router.

00:03:46.719 --> 00:03:53.479
The IP pair did not move. The MAC pair was rewritten, and the frame format may have changed entirely.

00:03:53.529 --> 00:04:01.279
If your answer has the IP addresses changing at a router, your answer is wrong.

00:04:01.329 --> 00:04:04.569
Sixty seconds, and three numbers.

00:04:04.619 --> 00:04:09.719
Alice sends one datagram to Bob, across two routers.

00:04:09.769 --> 00:04:12.609
How many datagrams exist on the journey?

00:04:12.659 --> 00:04:14.759
How many different frames carry it?

00:04:14.809 --> 00:04:17.709
And which devices actually build a frame?

00:04:17.759 --> 00:04:21.599
Pause the video and write three numbers down.

00:04:21.649 --> 00:04:28.859
They are worth one mark each in the kind of question this always becomes.

00:04:28.909 --> 00:04:34.079
Pause now.

00:04:34.129 --> 00:04:40.689
One datagram. Three frames. Built by Alice, R1 and R2.

00:04:40.739 --> 00:04:43.439
Bob builds none — he only strips.

00:04:43.489 --> 00:04:49.109
Every node that FORWARDS builds a frame; the node that finally receives it does not.

00:04:49.159 --> 00:04:58.109
And if you answered "one frame", you are still thinking end-to-end. The frame does not survive a router.

00:04:58.811 --> 00:05:04.811
So what does this layer actually sell you? Three services.

00:05:04.861 --> 00:05:05.821
Framing. Wrap it.

00:05:05.871 --> 00:05:12.001
Encapsulate the datagram in a frame before every link, and decapsulate it at the other end.

00:05:12.051 --> 00:05:15.601
New format, new addresses, once per hop.

00:05:15.651 --> 00:05:22.281
This is the first service and the unavoidable one — without it there is nothing to put on the wire.

00:05:22.331 --> 00:05:25.221
Flow control. Pace it.

00:05:25.271 --> 00:05:32.301
The producer and the consumer of frames sit at the two ends of one link, and the consumer's buffer is finite.

00:05:32.351 --> 00:05:36.051
So either you drop the excess, or you say "slow down".

00:05:36.101 --> 00:05:43.671
That is all it is here. It returns with real machinery at the transport layer.

00:05:43.721 --> 00:05:46.021
Error control. Check it.

00:05:46.071 --> 00:05:51.981
Signals corrupt — that is your Session 5 vocabulary — and therefore frames corrupt.

00:05:52.031 --> 00:05:58.701
Detect first. Then either correct it, or discard the frame and let the sender resend.

00:05:58.751 --> 00:06:07.701
Concept only this term. CSE 316 does no CRC arithmetic; error detection is chapter ten, which is not in your compiled book.

00:06:10.409 --> 00:06:16.899
There is a fourth service the textbook mentions, and the exam offers it as a link duty.

00:06:16.949 --> 00:06:25.899
Forouzan names congestion control among the link layer's possible services — and then, in almost the same breath, says it is rarely used there.

00:06:27.679 --> 00:06:31.079
A link can only see its own two ends.

00:06:31.129 --> 00:06:39.049
Congestion is a property of a PATH — many links, many senders, queues building somewhere you cannot see from here.

00:06:39.099 --> 00:06:44.689
So the cure has to live where the path is visible, which is layers three and four.

00:06:44.739 --> 00:06:50.219
Three services. Framing, flow control, error control.

00:06:50.269 --> 00:06:54.999
If a multiple-choice list offers you a fourth, that is the distractor.

00:06:55.049 --> 00:06:59.359
Decline it politely.

00:06:59.599 --> 00:07:04.359
First checkpoint. Pause, paper, no scrolling back.

00:07:04.409 --> 00:07:05.999
One.

00:07:06.049 --> 00:07:13.149
A datagram crosses four links. How many frames carry it, and how many datagrams exist?

00:07:13.199 --> 00:07:14.739
Two.

00:07:14.789 --> 00:07:21.449
Name the three services of the data-link layer — and then name the one that is listed and then disclaimed.

00:07:21.499 --> 00:07:23.039
Three.

00:07:23.089 --> 00:07:31.829
A router rewrites the addresses on the frame. Does it also rewrite the addresses in the datagram?

00:07:31.879 --> 00:07:37.029
Pause now.

00:07:37.079 --> 00:07:38.899
Answers.

00:07:38.949 --> 00:07:45.849
The first is four frames and one datagram. One frame per link, each destroyed at the next node.

00:07:45.899 --> 00:07:54.849
The second is framing, flow control and error control — and congestion control is the one that is listed and then declined, because a link cannot see the path.

00:07:56.489 --> 00:08:05.439
And the third is no. Never. The IP pair is sealed at the source and survives end to end. Only the frame's MAC pair is rewritten.

00:08:09.046 --> 00:08:10.346
Section two.

00:08:10.396 --> 00:08:11.206
DLC and MAC.

00:08:11.256 --> 00:08:20.206
Splitting the job: the problems every link has, and the one problem only shared links have.

00:08:21.280 --> 00:08:28.660
The data-link layer is not one thing. It is two sublayers, and they solve two genuinely different problems.

00:08:28.710 --> 00:08:32.230
On the left, DLC — data link control.

00:08:32.280 --> 00:08:38.220
Framing, flow control and error control: the issues COMMON to every kind of link.

00:08:38.270 --> 00:08:45.670
Whatever the medium is — a dedicated fibre, a phone line, the air in this room — those three apply.

00:08:45.720 --> 00:08:50.170
And on the right, MAC — media access control.

00:08:50.220 --> 00:08:51.860
Who may transmit NOW.

00:08:51.910 --> 00:08:56.450
That is the sharing problem, and it exists ONLY on broadcast links.

00:08:56.500 --> 00:09:03.360
A referee for the medium: when several stations could talk at once, something has to decide who does.

00:09:03.410 --> 00:09:07.890
So the dividing question is simply: is the medium shared?

00:09:07.940 --> 00:09:14.990
If the link is a dedicated wire between exactly two devices, there is nobody to share with and no referee is needed.

00:09:15.040 --> 00:09:22.117
If the link is the air in this room, there is.

00:09:22.167 --> 00:09:26.167
Two cases, and they are the two you will be given in an exam.

00:09:26.217 --> 00:09:30.527
A point-to-point link. Dedicated, one device at each end.

00:09:30.577 --> 00:09:37.497
The capacity belongs to that pair. Nobody else can transmit on it, so the question "may I talk now?" never arises.

00:09:37.547 --> 00:09:39.107
It needs DLC only.

00:09:39.157 --> 00:09:44.357
A broadcast link. Shared — the Wi-Fi in this room.

00:09:44.407 --> 00:09:50.967
Every station hears every transmission, and two at once is a collision.

00:09:51.017 --> 00:09:56.037
It needs DLC and MAC, because someone must referee the medium.

00:09:56.087 --> 00:09:59.527
And now look at the diagram you are always given.

00:09:59.577 --> 00:10:04.957
The dedicated line between two routers is point-to-point: no MAC sublayer needed.

00:10:05.007 --> 00:10:09.217
The LAN full of hosts hanging off each router is broadcast: MAC needed.

00:10:09.267 --> 00:10:18.217
One diagram, both answers, and the question is only ever which link they are pointing at.

00:10:19.632 --> 00:10:24.592
MAC has two meanings in this chapter, and they have to be kept apart.

00:10:24.642 --> 00:10:29.272
Right now, in this section, MAC means a sublayer.

00:10:29.322 --> 00:10:37.892
Media access control — the referee that decides who may transmit on a shared medium. It is a piece of the data-link layer.

00:10:37.942 --> 00:10:42.102
In about ten minutes, MAC will mean an address.

00:10:42.152 --> 00:10:48.772
A forty-eight bit number burned into a network card. It is not a referee. It is a name.

00:10:48.822 --> 00:10:52.802
Same neighbourhood, two completely different things.

00:10:52.852 --> 00:10:54.912
So read the word that follows.

00:10:54.962 --> 00:11:01.212
When a question says "the MAC sublayer", it is asking you about access — who talks when.

00:11:01.262 --> 00:11:09.282
When it says "the MAC address", it is asking you about naming — who is who.

00:11:09.332 --> 00:11:11.262
Second checkpoint.

00:11:11.312 --> 00:11:12.902
One.

00:11:12.952 --> 00:11:20.152
A dedicated fibre joins two routers. Which sublayer or sublayers does that link need, and why?

00:11:20.202 --> 00:11:21.742
Two.

00:11:21.792 --> 00:11:26.242
Give the two meanings of "MAC" that live in this chapter.

00:11:26.292 --> 00:11:27.852
Three.

00:11:27.902 --> 00:11:34.212
Which sublayer owns framing — DLC or MAC?

00:11:34.262 --> 00:11:39.432
Pause now.

00:11:39.482 --> 00:11:41.302
Answers.

00:11:41.352 --> 00:11:49.592
The first is DLC only. It is point-to-point, so there is nobody to share the medium with and no referee is needed.

00:11:49.642 --> 00:11:58.392
The second is the media-access-control SUBLAYER — who may transmit now — and the MAC ADDRESS, forty-eight bits burned into a card.

00:11:58.442 --> 00:12:07.392
And the third is DLC. Framing, flow control and error control are common to every link. MAC only settles access on the shared ones.

00:12:11.580 --> 00:12:13.080
Section three.

00:12:13.130 --> 00:12:14.510
Forty-eight bits.

00:12:14.560 --> 00:12:19.310
We have said, twice now, that the frame carries its own addresses.

00:12:19.360 --> 00:12:25.620
We have not yet said what one of those addresses looks like, or who decides that a card should listen to it.

00:12:25.670 --> 00:12:34.620
That is this section: why the envelope cannot carry an IP address, what it carries instead, and the single bit that decides who listens.

00:12:37.580 --> 00:12:39.930
Start with the obvious objection.

00:12:39.980 --> 00:12:45.710
The datagram already has two addresses on it. Why does the frame need two more?

00:12:45.760 --> 00:12:49.560
Because IP names the ends, not the road.

00:12:49.610 --> 00:12:54.300
The source and destination IP addresses say where the journey starts and where it finishes.

00:12:54.350 --> 00:12:59.800
They say nothing whatsoever about which links to cross to get there.

00:12:59.850 --> 00:13:08.800
And remember the rule from section one: the letter is sealed. Those two addresses must not change on the way.

00:13:10.740 --> 00:13:13.160
So every hop needs an address of its own.

00:13:13.210 --> 00:13:19.570
The frame carries link-layer addresses, and a link-layer address means something only on THIS link.

00:13:19.620 --> 00:13:28.570
You will see three names for the same thing, and they are interchangeable: link address, physical address, MAC address.

00:13:29.300 --> 00:13:34.150
I will say MAC address, because that is what the exam will say.

00:13:34.200 --> 00:13:37.740
Here it is. Forty-eight bits. Six bytes.

00:13:37.790 --> 00:13:43.010
Written as twelve hexadecimal digits in colon pairs: A2:34:45:11:92:F1.

00:13:43.060 --> 00:13:48.100
And it is fixed in the hardware when the card is manufactured.

00:13:48.150 --> 00:13:51.400
Now the sentence that catches people out.

00:13:51.450 --> 00:13:55.100
The MAC address belongs to the CARD, not to the machine.

00:13:55.150 --> 00:13:59.690
A router with three interfaces has three MAC addresses, not one.

00:13:59.740 --> 00:14:08.010
An address names a CONNECTION to a network. It does not name a box sitting on a desk.

00:14:08.060 --> 00:14:17.010
So if an exam question gives you a router and asks for "the router's MAC address", the correct first move is to ask back: on which interface?

00:14:20.942 --> 00:14:25.402
A MAC address does not only say WHO. It also says HOW MANY.

00:14:25.452 --> 00:14:30.412
There are three kinds, and Forouzan gives you one example of each.

00:14:30.462 --> 00:14:34.992
Unicast. Four-A colon thirty, and so on.

00:14:35.042 --> 00:14:37.232
One frame, one recipient.

00:14:37.282 --> 00:14:44.012
Every other card on the LAN sees that frame arrive, compares the address, and drops it — in hardware.

00:14:44.062 --> 00:14:49.702
The CPU on those machines never wakes up. It is never even told the frame existed.

00:14:49.752 --> 00:14:54.662
Notice the second hexadecimal digit. A. That is even.

00:14:54.712 --> 00:14:59.602
Multicast. Forty-seven colon twenty, and so on.

00:14:59.652 --> 00:15:02.202
One frame, a GROUP of listeners.

00:15:02.252 --> 00:15:10.622
The block beginning 01:00:5E is reserved for IPv4 multicast groups. Multicast routing itself is not in this course.

00:15:10.672 --> 00:15:14.142
Second hexadecimal digit: seven. That is odd.

00:15:14.192 --> 00:15:17.052
And broadcast. FF:FF:FF:FF:FF:FF.

00:15:17.102 --> 00:15:21.552
One frame, EVERYONE on the LAN.

00:15:21.602 --> 00:15:24.662
All forty-eight bits are one.

00:15:24.712 --> 00:15:33.662
Every station must accept it, and every station must process it — which is exactly why it is the expensive one.

00:15:34.612 --> 00:15:43.562
Broadcast is expensive: every station accepts the frame and interrupts its CPU. Section four shows that this cost is why ARP keeps a cache.

00:15:51.892 --> 00:15:56.912
And the second hex digit has run even, odd, even, odd.

00:15:56.962 --> 00:16:04.672
That shortcut is a shadow of one real bit, and the next slide is that bit.

00:16:04.722 --> 00:16:11.542
Here is the rule underneath the shortcut, and it fits in one line.

00:16:11.592 --> 00:16:17.802
Take the FIRST byte of the address. Write it in binary. Read its LAST bit.

00:16:17.852 --> 00:16:24.832
That bit is called the Individual slash Group bit — the I/G bit.

00:16:24.882 --> 00:16:29.972
Four-A. In binary: zero one zero zero, one zero one zero.

00:16:30.022 --> 00:16:35.772
Last bit: zero. Individual. One card. Unicast.

00:16:35.822 --> 00:16:40.482
Forty-seven. In binary: zero one zero zero, zero one one one.

00:16:40.532 --> 00:16:47.172
Last bit: one. Group. Many cards. Multicast.

00:16:47.222 --> 00:16:50.262
And FF. One one one one, one one one one.

00:16:50.312 --> 00:16:55.402
Last bit is one, so it is certainly a group — but this one goes further.

00:16:55.452 --> 00:17:04.402
All forty-eight bits are ones, across all six bytes. That is the broadcast address, the group that contains everybody.

00:17:06.342 --> 00:17:15.292
Three rows. One rule. Look at the middle column and say the last bit out loud before you move on.

00:17:16.655 --> 00:17:19.885
Now, a fair question. Why THAT bit?

00:17:19.935 --> 00:17:28.035
Of forty-eight bits, why should the last bit of the first byte be the one carrying the meaning?

00:17:28.085 --> 00:17:31.275
Because of the order things travel in.

00:17:31.325 --> 00:17:34.675
Ethernet transmits each byte least-significant-bit first.

00:17:34.725 --> 00:17:43.445
So the last bit of byte zero — the I/G bit — is the very first bit to arrive at the receiving card.

00:17:43.495 --> 00:17:46.015
And that buys something real.

00:17:46.065 --> 00:17:51.265
The card knows "is this frame for a group?" before anything else has landed.

00:17:51.315 --> 00:17:56.905
It can begin deciding whether to care before the rest of the address has even finished arriving.

00:17:56.955 --> 00:18:02.135
The bit is not there by accident. It is there so the decision can be early.

00:18:02.185 --> 00:18:05.175
Which brings us back to the shortcut.

00:18:05.225 --> 00:18:12.225
Second hex digit even means unicast, odd means multicast — and now you can see WHY that works.

00:18:12.275 --> 00:18:20.495
The second hex digit IS the low four bits of byte zero. And the I/G bit is the lowest of those four.

00:18:20.545 --> 00:18:27.305
The shortcut is not a rule. It is a consequence of a rule.

00:18:27.545 --> 00:18:33.915
Thirty seconds on study technique, because it applies to every topic, not just this one.

00:18:33.965 --> 00:18:37.675
The shortcut is fast, and it is correct.

00:18:37.725 --> 00:18:40.175
But it is a memorised surface fact.

00:18:40.225 --> 00:18:49.175
And memorised facts fail you at exactly the wrong moment — when a slide is wrong, or a printing is wrong, or you misremember which way round it went at eight in the morning.

00:18:51.255 --> 00:18:54.585
The derivation cannot fail like that.

00:18:54.635 --> 00:18:58.255
Byte zero, in binary, read the last bit.

00:18:58.305 --> 00:19:07.255
Zero means individual: one card. One means group: many cards. All ones, across all six bytes, means everyone.

00:19:08.175 --> 00:19:10.885
So here is the exam habit.

00:19:10.935 --> 00:19:13.175
Write the eight bits in the margin.

00:19:13.225 --> 00:19:21.815
It costs you four seconds, and it turns an answer you remembered into an answer you can CHECK.

00:19:21.865 --> 00:19:29.002
If you can draw the row, a misprint cannot hurt you.

00:19:29.052 --> 00:19:34.942
Checkpoint three. Same routine — paper, pen, and stop the video.

00:19:34.992 --> 00:19:36.582
One.

00:19:36.632 --> 00:19:45.582
Is 4A:30:10:21:10:1A unicast or multicast? And show me the bit you used, not just the answer.

00:19:47.872 --> 00:19:49.402
Two.

00:19:49.452 --> 00:19:56.182
A router has three interfaces. How many MAC addresses does it have?

00:19:56.232 --> 00:19:56.572
Three.

00:19:56.622 --> 00:20:04.252
Why is the I/G bit the LAST bit of byte zero, rather than the first?

00:20:04.302 --> 00:20:09.462
Pause now.

00:20:09.512 --> 00:20:11.332
Answers.

00:20:11.382 --> 00:20:20.332
One. Unicast. 4A is zero-one-zero-zero one-zero-one-zero; the last bit is zero, so Individual. The second hex digit A is even, which is the same fact.

00:20:22.552 --> 00:20:30.012
Two. Three. An address names a connection to a network, not the box. One per interface.

00:20:30.062 --> 00:20:39.012
Three. Because Ethernet transmits each byte least-significant-bit first — so that bit arrives first, and the card can decide early.

00:20:43.598 --> 00:20:45.088
Section four. ARP.

00:20:45.138 --> 00:20:49.718
We now have two facts that do not fit together.

00:20:49.768 --> 00:20:57.788
Layer three hands down an IP address for the next node. And layer two can only write a MAC address on the envelope.

00:20:57.838 --> 00:21:06.788
Something has to translate. That something is ARP — and this is the section where the question from minute one finally gets its answer.

00:21:10.396 --> 00:21:15.586
The problem, stated precisely, because the whole section turns on it.

00:21:15.636 --> 00:21:18.716
Layer three has already done its work.

00:21:18.766 --> 00:21:27.206
It has looked at the destination, consulted its forwarding table, and decided: the next node is ten dot zero dot two dot one.

00:21:27.256 --> 00:21:30.776
That is what it hands down. An IP address.

00:21:30.826 --> 00:21:33.636
And layer two cannot use it.

00:21:33.686 --> 00:21:38.126
The frame cannot carry an IP address in its destination field. It needs forty-eight bits.

00:21:38.176 --> 00:21:46.206
So we have a number, and we need a different number, and nothing on this machine knows the mapping.

00:21:46.256 --> 00:21:51.766
ARP is that translation. The Address Resolution Protocol.

00:21:51.816 --> 00:21:57.486
Give it the IP address of a machine on THIS link, and it returns that machine's MAC address.

00:21:57.536 --> 00:22:00.206
The words "on this link" are load-bearing.

00:22:00.256 --> 00:22:09.206
ARP runs on this network only. It has no reach beyond the first router, and that limit is why case two exists.

00:22:10.863 --> 00:22:15.613
So how does a machine find something out from a stranger it cannot yet address?

00:22:15.663 --> 00:22:17.853
It does it in two moves.

00:22:17.903 --> 00:22:21.743
Move one. The request goes to everyone.

00:22:21.793 --> 00:22:29.243
Destination FF:FF:FF:FF:FF:FF — broadcast. The address we called expensive.

00:22:29.293 --> 00:22:36.203
And the content of the request is: who has IP address N3? Tell N1. My MAC address is L1.

00:22:36.253 --> 00:22:43.473
The asker includes its own MAC address in the question. That is what lets the reply be a unicast.

00:22:43.523 --> 00:22:51.773
Move one, continued. Every station on the LAN receives it, because that is what broadcast means.

00:22:51.823 --> 00:22:57.803
B and D compare the requested IP with their own, find no match, and drop it.

00:22:57.853 --> 00:23:06.083
That is the cost we talked about: four machines were interrupted so that one of them could answer.

00:23:06.133 --> 00:23:10.363
Move two. C compares, and matches. C is N3.

00:23:10.413 --> 00:23:15.273
And C replies — but the reply is a UNICAST, straight back to L1.

00:23:15.323 --> 00:23:20.873
Why can the reply be a whisper when the question had to be a shout?

00:23:20.923 --> 00:23:29.873
Because C already knows where to send it. It read A's MAC address out of the request. A had no such luxury; that is the asymmetry.

00:23:30.393 --> 00:23:34.323
And move three, which is not really a move at all.

00:23:34.373 --> 00:23:38.243
A writes the pair down. N3 maps to L3, into the ARP cache.

00:23:38.293 --> 00:23:44.463
Every later frame for N3 is addressed directly. No shouting. Not once more.

00:23:44.513 --> 00:23:51.793
Shout once. Whisper after. That is the whole protocol.

00:23:51.843 --> 00:23:58.904
Let me show you it running.

00:23:58.954 --> 00:24:01.414
You have seen what ARP does. Here is what it sends. Figure nine point eight, and the packet is small: eight fixed bytes, then four address fields whose sizes the packet declares for itself.

00:24:01.464 --> 00:24:03.034
Hardware type. Sixteen bits, first on the wire. It names the link-layer protocol that the hardware addresses in this packet belong to, and Ethernet is type one. Change the kind of link and this number changes, and the address lengths further down change with it.

00:24:03.084 --> 00:24:04.654
Protocol type. Sixteen bits, in the same first word. It names the network-layer protocol being resolved, and IPv4 is oh-eight-oh-oh in hexadecimal. So the first four bytes of every ARP packet answer one question each: which kind of hardware address, and which kind of protocol address.

00:24:04.704 --> 00:24:06.434
Hardware length and protocol length, one byte each. They are byte counts for the four address fields below. On Ethernet with IPv4 they read six and four: a MAC address is six bytes, an IPv4 address is four. The packet states the length of its own addresses instead of assuming them.

00:24:06.484 --> 00:24:07.864
Operation. Sixteen bits, and it decides what the packet is. Request is one, reply is two. The book prints it on the figure itself. A request and a reply carry the same fields in the same order; this one number is the whole difference between them.

00:24:07.914 --> 00:24:16.864
Then the addresses, in this order: source hardware, source protocol, destination hardware, destination protocol. Variable length — that is what the two length fields were for. Here they are six, four, six and four bytes, so twenty bytes of addresses on top of the eight fixed bytes above them. One of those four is left empty in a request, and the next slide says which.

00:26:01.543 --> 00:26:03.513
Example nine point four, and it uses the book's own labels. Host A has IP address N-one and MAC address L-one. Host B has IP address N-two and a MAC address A does not know. Same network. Four address fields, filled in twice.

00:26:03.563 --> 00:26:05.883
The request A sends. Operation one. Source hardware address L-one, source protocol address N-one, destination protocol address N-two — the address A is asking about. A writes its own pair into the source fields, and that is not politeness: it is the reason B can answer with a unicast instead of shouting back.

00:26:05.933 --> 00:26:10.493
One field is left empty, and it is the obvious one. The destination hardware address — B's MAC — is the single thing A does not know, and the whole reason the packet exists. Figure nine point eight labels that row in brackets: empty in request. Figure nine point nine shows what travels there instead: all zeros.

00:26:10.543 --> 00:26:15.223
B's reply. Operation two. B is now the sender, so the source fields carry B's own pair: hardware L-two, protocol N-two. The destination fields carry A's: L-one and N-one. B looked nothing up to fill those in — it read both of A's addresses straight out of the request.

00:26:15.273 --> 00:26:16.583
The rule underneath this is a naming rule, not a swapping trick. Source and destination are always relative to the packet in your hand, so whoever sends a packet writes its own hardware and protocol addresses into the source pair. The book states the consequence plainly: the response contains the recipient's IP and link-layer addresses, and it is unicast to the node that sent the request.

00:26:16.633 --> 00:26:25.583
One correction to the printed figure. In the reply, the last address reads N-two. It has to be N-one, A's own IP address. Everything else in Figure nine point nine is exactly as drawn.

00:28:12.163 --> 00:28:19.613
Four stations on one LAN. A wants to send to N3, and A's ARP cache is empty.

00:28:19.663 --> 00:28:26.533
Watch the frame leave A. Destination all-Fs, so it goes everywhere at once.

00:28:26.583 --> 00:28:33.543
It reaches all three. Every card accepts it. Every CPU is interrupted.

00:28:33.593 --> 00:28:42.543
B and D compare, find no match, and drop it. Two machines just did work for nothing. That is the price of a broadcast.

00:28:45.213 --> 00:28:54.163
C matched. And look at the reply — one path, not four. A unicast, straight to A, because C read A's address out of the question.

00:28:57.453 --> 00:29:03.703
A writes the pair into its cache. N3 maps to L3.

00:29:03.753 --> 00:29:12.003
And now the data. Straight to C. No shout, no interruptions, nobody else disturbed.

00:29:12.053 --> 00:29:21.003
Everything after this is a whisper — until that cache entry expires, and the shout happens once more.

00:29:22.435 --> 00:29:27.485
Now the cache: what a shout costs, and why the answer is kept.

00:29:27.535 --> 00:29:31.615
A broadcast costs every station on the LAN.

00:29:31.665 --> 00:29:40.615
Every card accepts it. Every CPU is interrupted. Every machine does a comparison, and all but one of them throws the frame away.

00:29:41.155 --> 00:29:47.445
On a LAN with two hundred machines, one question wastes one hundred and ninety-nine comparisons.

00:29:47.495 --> 00:29:51.065
Now imagine doing that for every single frame.

00:29:51.115 --> 00:29:58.615
So the answer is kept — for minutes, not hours; the exact timeout is set by the operating system.

00:29:58.665 --> 00:30:01.505
And the entry EXPIRES, deliberately.

00:30:01.555 --> 00:30:09.735
Cards get replaced. Machines move to a different network. An address that was true this morning may be a lie this afternoon.

00:30:09.785 --> 00:30:14.115
A cache that never expired would be worse than no cache at all.

00:30:14.165 --> 00:30:18.305
Here is tonight's homework, and it takes ten seconds.

00:30:18.355 --> 00:30:23.515
Open a terminal on your own machine and run: a-r-p space minus a.

00:30:23.565 --> 00:30:26.975
You will find your default gateway sitting in that list.

00:30:27.025 --> 00:30:35.975
And by the end of this session you will be able to say exactly why your laptop bothered to learn that particular MAC address.

00:30:37.368 --> 00:30:43.348
Now the table. Four cases. This is Forouzan's example of communication.

00:30:43.398 --> 00:30:51.088
The question in every row is the same: who is asking ARP, and what IP address are they handing it?

00:30:51.138 --> 00:30:55.298
Case one. Host to host, same network.

00:30:55.348 --> 00:31:02.338
The source host asks for the destination host's IP address, and gets the destination host's MAC address back.

00:31:02.388 --> 00:31:07.608
This is the easy row. The machine you want IS the machine you ask about.

00:31:07.658 --> 00:31:11.308
Case two. Host to somewhere far away.

00:31:11.358 --> 00:31:17.528
The source host asks for the DEFAULT ROUTER's IP address, and gets the router's MAC address back.

00:31:17.578 --> 00:31:21.588
It is asking about the router. Not about the destination.

00:31:21.638 --> 00:31:25.348
Case three. Router to the next router.

00:31:25.398 --> 00:31:33.158
R1 asks for the next router's IP address — which it takes from its own forwarding table — and gets that router's MAC address.

00:31:33.208 --> 00:31:37.188
Same shape as case two, one floor along the path.

00:31:37.238 --> 00:31:41.548
Case four. The last router to the destination.

00:31:41.598 --> 00:31:50.548
R2 asks for the destination host's IP address, and finally gets the destination's MAC address.

00:31:50.628 --> 00:31:53.158
Look at the whole table now.

00:31:53.208 --> 00:32:02.158
Only in cases one and four does anybody ask about the final destination. In the middle of the journey, nobody is asking about Bob at all.

00:32:02.498 --> 00:32:11.318
Every row is asking the same question in different clothes: what is the MAC address of the NEXT NODE?

00:32:11.368 --> 00:32:16.048
Case two gets its own slide, because it is where the marks leak.

00:32:16.098 --> 00:32:21.908
The intuition is: I am sending to the server, so I ask for the server.

00:32:21.958 --> 00:32:23.638
It is the natural answer.

00:32:23.688 --> 00:32:25.258
And it is wrong.

00:32:25.308 --> 00:32:27.988
What actually happens is this.

00:32:28.038 --> 00:32:36.398
The forwarding decision already said "next node: the default router". ARP is only ever given the NEXT NODE.

00:32:36.448 --> 00:32:42.178
So the laptop asks for the gateway's MAC address, and the frame is addressed to the gateway.

00:32:42.228 --> 00:32:51.178
The server's IP address is still sealed inside the datagram, untouched. But the server's MAC address is not on that envelope, and never will be — the laptop has no way to learn it, and no use for it.

00:32:55.618 --> 00:33:00.388
And here is the test to apply in an exam, in one question.

00:33:00.438 --> 00:33:03.688
Is the destination on THIS network?

00:33:03.738 --> 00:33:08.938
If yes, ARP asks for the destination. If no, ARP asks for the router.

00:33:08.988 --> 00:33:15.468
That is the entire decision, and it takes you two seconds.

00:33:15.518 --> 00:33:24.468
The next slide lets you change the destination and watch which IP address ARP is handed.

00:33:25.581 --> 00:33:29.621
This is the same LAN, but now you drive it.

00:33:29.671 --> 00:33:36.631
On the left you choose the destination. On the right you watch what ARP is actually asked.

00:33:36.681 --> 00:33:45.631
Send to C, which is on this network. The forwarding decision says "next node: C". ARP is handed C's IP address, and C's MAC comes back. The frame's four addresses are all on screen — read them.

00:33:51.741 --> 00:34:00.691
The pair is in the cache. Press Send again and there is no broadcast at all. Shout once, whisper after.

00:34:01.761 --> 00:34:08.651
Clear the cache and it shouts again — which is exactly what happens when an entry expires.

00:34:08.701 --> 00:34:14.591
Now change the destination to the server in another country, and watch the middle panel.

00:34:14.641 --> 00:34:21.511
The IP handed to ARP CHANGES. It is not the server's. It is the gateway's.

00:34:21.561 --> 00:34:30.511
And look at the four addresses now. The destination IP is still the server, sealed. The destination MAC is the router.

00:34:30.691 --> 00:34:34.611
That is case two.

00:34:34.661 --> 00:34:43.611
Pause the video and open the demo yourself — the link is on the course site. Send to both destinations and read the wire log line by line.

00:34:50.673 --> 00:34:59.623
Two minutes of work. This is the question that ties section one to section three, and it is the shape of a question you will meet in the exam.

00:35:01.723 --> 00:35:02.423
The setup.

00:35:02.473 --> 00:35:09.433
Alice, with IP address N-A and MAC address L-A, is sending to Bob, with IP N-B and MAC L-B.

00:35:09.483 --> 00:35:13.123
Between them, two routers: R1 and R2. Three links.

00:35:13.173 --> 00:35:14.703
The moment.

00:35:14.753 --> 00:35:21.273
I freeze the frame in mid-flight on link two — the link between R1 and R2.

00:35:21.323 --> 00:35:28.093
Nothing has arrived yet. Nothing has been stripped. It is simply in the air.

00:35:28.143 --> 00:35:30.933
Write down its four addresses.

00:35:30.983 --> 00:35:34.793
Source IP, destination IP, source MAC, destination MAC.

00:35:34.843 --> 00:35:43.793
All four. Pause the video now and write them before you go on.

00:35:47.643 --> 00:35:49.463
The answer.

00:35:49.513 --> 00:35:58.343
The IP pair: N-A to N-B. Exactly as Alice sealed them. They have not moved and they never will.

00:35:58.393 --> 00:36:02.463
The MAC pair: R1's exit interface, to R2's entry interface.

00:36:02.513 --> 00:36:11.463
And notice something about those two MAC addresses. Neither of them existed on link one. Alice has never heard of either. They were resolved by R1, on this link, by ARP — case three.

00:36:18.493 --> 00:36:21.153
Now mark yourself honestly.

00:36:21.203 --> 00:36:25.533
If your IP pair changed, go back and re-read section one.

00:36:25.583 --> 00:36:33.179
If your MAC pair did NOT change, go back and re-read section three.

00:36:33.229 --> 00:36:39.979
Checkpoint four. The last one before we go back to the opening question.

00:36:40.029 --> 00:36:40.239
One.

00:36:40.289 --> 00:36:45.989
Why must the ARP request be a broadcast, when the reply can be a unicast?

00:36:46.039 --> 00:36:47.569
Two.

00:36:47.619 --> 00:36:53.859
Your laptop sends to a server in another country. Whose MAC address does ARP return?

00:36:53.909 --> 00:36:55.469
Three.

00:36:55.519 --> 00:37:02.449
Does an ARP request cross a router to reach the next network?

00:37:02.499 --> 00:37:07.669
Pause now.

00:37:07.719 --> 00:37:09.529
Answers.

00:37:09.579 --> 00:37:18.529
One. Because the one machine that can answer is the machine you cannot yet address. The replier has no such problem — it read your MAC address out of the request.

00:37:20.909 --> 00:37:29.859
Two. Your default router's. The server is not on this network, and ARP only ever resolves the next node, which is the gateway. That is case two.

00:37:31.589 --> 00:37:40.539
Three. No. A broadcast is bounded by the network. And that is precisely why case two has to exist.

00:37:41.486 --> 00:37:42.886
Section five.

00:37:42.936 --> 00:37:45.216
A to B, one hop at a time.

00:37:45.266 --> 00:37:54.216
Everything you have met so far — the frame, the MAC address, the broadcast, the cache — now runs once, end to end, on a network with real numbers on it.

00:37:56.896 --> 00:38:05.846
Two networks, two switches, one router. Watch two things as we go: what each box has to ask before it can send anything, and what each box quietly writes down while nobody is looking.

00:38:11.886 --> 00:38:20.296
Five boxes. Take thirty seconds and copy the addresses down, because every slide in this section names them.

00:38:20.346 --> 00:38:27.636
A, the client. IP one-ninety-two dot one-six-eight dot ten dot ten, on network ten.

00:38:27.686 --> 00:38:33.996
Its MAC address ends in zero-A, and its default gateway is one-ninety-two dot one-six-eight dot ten dot one.

00:38:34.046 --> 00:38:35.936
Then the two switches.

00:38:35.986 --> 00:38:44.936
A switch has no IP address in this story, and it never puts an address of its own into any frame. It is not a station on the network; it is the wire, with a memory.

00:38:48.016 --> 00:38:56.966
It forwards on the MAC address table alone — and it builds that table by reading the source address of whatever happens to pass through it.

00:38:57.736 --> 00:39:01.986
R1, the router, and it has two faces.

00:39:02.036 --> 00:39:10.986
Interface e-zero sits on network ten, at one-ninety-two dot one-six-eight dot ten dot one, with its own MAC address. Interface e-one sits on network twenty, at one-ninety-two dot one-six-eight dot twenty dot one, with a different MAC address.

00:39:19.196 --> 00:39:27.426
One box. Two addresses of each kind — because an address names a connection to a network, not a machine.

00:39:27.476 --> 00:39:36.426
And B, the server, on the far side: one-ninety-two dot one-six-eight dot twenty dot twenty, MAC ending in zero-B.

00:39:40.076 --> 00:39:47.736
One fact before we start. Nothing A does in the next two minutes will ever put B's MAC address on a frame.

00:39:47.786 --> 00:39:55.434
A will never learn it, and never needs to. The next slide is the reason why.

00:39:55.484 --> 00:40:02.024
A has a datagram for B, and before anything reaches the wire, A asks one question.

00:40:02.074 --> 00:40:07.244
The test. Take the destination and AND it with my own mask.

00:40:07.294 --> 00:40:15.984
Twenty dot twenty ANDed with two-fifty-five, two-fifty-five, two-fifty-five, zero gives network twenty dot zero.

00:40:16.034 --> 00:40:21.034
My own address ANDed with the same mask gives network ten dot zero.

00:40:21.084 --> 00:40:24.604
They do not match. B is not on this wire.

00:40:24.654 --> 00:40:31.014
So the answer is the default gateway. The next node is one-ninety-two dot one-six-eight dot ten dot one.

00:40:31.064 --> 00:40:36.254
That is what layer three hands down — not B's address, the gateway's.

00:40:36.304 --> 00:40:42.994
And notice exactly what has been decided: where to send it. Nothing else.

00:40:43.044 --> 00:40:45.414
Because here is the wall.

00:40:45.464 --> 00:40:54.414
The destination field of a frame is forty-eight bits of MAC address. One-ninety-two dot one-six-eight dot ten dot one will not fit in it — and even if you could force it in, the switch would not read it, because a switch never opens the datagram.

00:41:00.734 --> 00:41:07.574
The next-hop IP address says WHERE. It cannot say WHO.

00:41:07.624 --> 00:41:16.574
That gap — between knowing where and being able to write it down — is the entire reason ARP exists. Now watch it close.

00:41:21.091 --> 00:41:30.041
Forty-eight seconds. Nothing to write down — just watch two things: the tables filling, and the two IP addresses never moving.

00:41:31.051 --> 00:41:38.961
Everything starts empty. No MAC tables, no ARP caches, nothing learned by anybody.

00:41:39.011 --> 00:41:47.961
A makes the decision you just saw: off-network, so the next node is the gateway. And there it stops, because it cannot write the envelope.

00:41:51.341 --> 00:42:00.291
So A shouts. Watch the left-hand table the moment that frame enters the switch — SW1 writes down A's address, taken from the SOURCE field of the very frame that is asking the question.

00:42:03.721 --> 00:42:09.291
Then it floods it, because the destination is all-Fs and all-Fs is in nobody's table.

00:42:09.341 --> 00:42:18.291
R1 answers, quietly, straight back to A. And the switch learns again — R1's address this time, from the source of the reply.

00:42:19.131 --> 00:42:23.251
Two entries now, and nobody configured either one.

00:42:23.301 --> 00:42:32.251
Now the data. Read the four addresses: IP is A to B, the two ends of the whole journey. MAC is A to R1, the two ends of this one wire.

00:42:35.481 --> 00:42:44.431
R1 strips the frame and throws it away. It reads the datagram, matches the route, and finds the destination is directly connected on e-one — so here the next node IS B.

00:42:48.581 --> 00:42:56.151
And now watch the same wall appear one floor down. R1 has the next-hop IP and no MAC address to write with.

00:42:56.201 --> 00:43:02.711
So the whole thing happens again on the other side, and SW2 fills the same way.

00:43:02.761 --> 00:43:11.711
Notice what did not happen: that broadcast never crossed the router. Which is why A could never have asked B directly, no matter how patient it was.

00:43:14.381 --> 00:43:23.331
And frame two. Compare it with frame one: the two IP addresses are identical, untouched since A sealed them. Both MAC addresses are new. Neither existed anywhere on link one.

00:43:27.891 --> 00:43:36.841
One datagram. Two frames. Two ARP exchanges. Four MAC entries, learned from nothing but the traffic itself.

00:43:38.379 --> 00:43:44.339
Four tables came out of that run, and not one of them was typed in by an administrator.

00:43:44.389 --> 00:43:47.069
SW1 has two entries.

00:43:47.119 --> 00:43:52.589
A's address on port one — learned from the source field of A's broadcast request.

00:43:52.639 --> 00:43:58.899
R1's address on port twenty-four — learned from the source field of R1's unicast reply.

00:43:58.949 --> 00:44:02.779
The question taught it one; the answer taught it the other.

00:44:02.829 --> 00:44:09.179
SW2 has two entries, filled exactly the same way on the other network.

00:44:09.229 --> 00:44:18.179
And this is the mechanism worth naming: a switch never asks anything. It reads the source address of every frame it forwards, and writes down which port that frame came in on.

00:44:20.879 --> 00:44:25.509
A's cache has one entry: the gateway. Not B.

00:44:25.559 --> 00:44:32.179
A finished a conversation with a server on another continent and never learned that server's MAC address.

00:44:32.229 --> 00:44:34.419
And R1's cache has one entry: B.

00:44:34.469 --> 00:44:43.419
R1 had to ask for that separately, on network twenty, because the first ARP exchange happened on network ten and told it precisely nothing about link two.

00:44:48.439 --> 00:44:57.389
And flooding only happens once per unknown destination. After that, the tables do the work — which is the entire difference between a switch and the hub it replaced.

00:45:03.058 --> 00:45:11.158
Same journey, but now you hold the step button — and you can stop on any one of the nine states for as long as you like.

00:45:11.208 --> 00:45:19.598
Step one is the network at rest. Every table empty, and A holding a datagram it cannot yet address.

00:45:19.648 --> 00:45:28.598
Step two is the AND, done for you on screen. Watch the red panel underneath it — that is the sentence this whole section exists to teach.

00:45:30.618 --> 00:45:39.568
Step three, and the left-hand MAC table gains its first row the moment the request arrives. Hover on it: the entry came from the source address, not the destination.

00:45:44.228 --> 00:45:51.938
Step four. The reply is a unicast, the second row appears, and from here SW1 forwards instead of flooding.

00:45:51.988 --> 00:46:00.938
Step five puts the four addresses side by side. Read the IP row and the MAC row out loud — they are answering two completely different questions.

00:46:02.808 --> 00:46:11.758
Step six is the one to linger on. The matched route is highlighted, the next node is spelled out underneath it, and R1's ARP cache sits right below, empty.

00:46:14.158 --> 00:46:19.128
Everything R1 needs, except the one thing it can write on an envelope.

00:46:19.178 --> 00:46:26.498
Step seven repeats the whole exchange on the far side, and SW2's table fills.

00:46:26.548 --> 00:46:35.498
Step eight is the comparison the exam is built on. Flip between step five and step eight a few times and watch which row changes and which row does not.

00:46:37.898 --> 00:46:40.868
And step nine is the tally.

00:46:40.918 --> 00:46:49.868
Open it yourself after the lecture, and set yourself one exercise: predict every table before you press step, then check.

00:46:52.095 --> 00:46:57.095
Checkpoint five. Paper, pen, and no scrolling back.

00:46:57.145 --> 00:46:58.755
One.

00:46:58.805 --> 00:47:04.415
How many ARP exchanges happen between A and B, and on which networks?

00:47:04.465 --> 00:47:05.995
Two.

00:47:06.045 --> 00:47:11.405
SW1 learned two MAC addresses. Which frame taught it each one?

00:47:11.455 --> 00:47:13.005
Three.

00:47:13.055 --> 00:47:22.005
R1's route to network twenty is directly connected. What is the next-hop IP address, and why?

00:47:22.385 --> 00:47:27.555
Pause now.

00:47:27.605 --> 00:47:29.415
Answers.

00:47:29.465 --> 00:47:38.415
One. Two exchanges. One on network ten, where A asks for the gateway; one on network twenty, where R1 asks for B. Neither request crossed the router.

00:47:41.655 --> 00:47:50.605
Two. A's address came from the source field of A's broadcast request; R1's came from the source field of R1's unicast reply. Both learned from traffic, neither configured.

00:47:53.485 --> 00:48:02.435
Three. The next hop is one-ninety-two dot one-six-eight dot twenty dot twenty — B itself. A directly connected route means there is no intermediate router left, so the next node and the final destination are the same machine.

00:48:11.334 --> 00:48:13.144
Section six.

00:48:13.194 --> 00:48:16.524
Everything you need is now on the table.

00:48:16.574 --> 00:48:25.524
Let us go back to the question I put in front of you in minute one, and answer it properly — now that every piece of the answer has a name.

00:48:29.354 --> 00:48:37.624
The question was: your laptop already knows the server's IP address. So why does it shout WHO HAS ten dot zero dot two dot one?

00:48:37.674 --> 00:48:44.284
There are four parts to the answer, and you can now supply all four yourself.

00:48:44.334 --> 00:48:46.234
One. Frames do not speak IP.

00:48:46.284 --> 00:48:52.784
To put that datagram on this LAN, the laptop must write a forty-eight-bit MAC address on the envelope.

00:48:52.834 --> 00:48:57.764
Knowing the server's IP address buys it precisely nothing at layer two.

00:48:57.814 --> 00:49:01.124
Two. Now the address itself.

00:49:01.174 --> 00:49:04.904
Ten dot zero dot two dot one is not the server.

00:49:04.954 --> 00:49:13.904
The server is somewhere else entirely, beyond this network. The forwarding decision said: next node, the default router, ten dot zero dot two dot one.

00:49:15.684 --> 00:49:23.264
The laptop is asking for the GATEWAY's MAC address. This is case two, and you have now seen it three times.

00:49:23.314 --> 00:49:27.234
Three. Only a shout reaches a stranger.

00:49:27.284 --> 00:49:32.054
The one machine that could answer is the machine the laptop cannot yet address.

00:49:32.104 --> 00:49:41.054
So the request has to go to FF:FF:FF:FF:FF:FF. Everyone hears it. Exactly one answers — and answers quietly.

00:49:42.344 --> 00:49:46.204
And four. It shouts only once.

00:49:46.254 --> 00:49:54.724
The answer lands in the ARP cache. Every frame after that is a whisper straight to the gateway.

00:49:54.774 --> 00:50:02.994
Until the entry expires — and then the whole thing happens again, exactly once.

00:50:03.044 --> 00:50:06.884
Ask everyone once. Remember the answer.

00:50:06.934 --> 00:50:15.038
That is the entire protocol, and it is why your Wi-Fi is not drowning in noise.

00:50:15.278 --> 00:50:18.308
Five ways to lose marks in this chapter.

00:50:18.358 --> 00:50:23.478
Wrong: "the data-link layer delivers the frame from source to destination."

00:50:23.528 --> 00:50:32.478
Right: node to node only. The FRAME lives and dies on one link. The DATAGRAM goes end to end. Three links means three frames.

00:50:35.768 --> 00:50:39.528
Wrong: "ARP finds the MAC address of the final destination."

00:50:39.578 --> 00:50:48.528
Right: ARP resolves the NEXT NODE's IP address — very often the default router. It never reaches past this network.

00:50:49.448 --> 00:50:56.748
Wrong: memorising "odd second digit means multicast" from a slide that might be misprinted.

00:50:56.798 --> 00:51:05.748
Right: derive it. Byte zero in binary, last bit is I/G. Zero is unicast, one is multicast, all ones is broadcast.

00:51:05.828 --> 00:51:14.448
Wrong: "the MAC addresses changed at the router, so the IP addresses must have changed too."

00:51:14.498 --> 00:51:23.448
Right: never. Source and destination IP survive end to end. Only the frame's MAC pair is rewritten, once per link.

00:51:24.708 --> 00:51:32.718
And wrong: listing congestion control as a data-link service, because the textbook mentions it.

00:51:32.768 --> 00:51:41.718
Right: framing, flow control, error control. Congestion is a property of a PATH, and paths belong to layers three and four.

00:51:44.198 --> 00:51:51.304
These five pairs are the fastest revision for this chapter.

00:51:51.354 --> 00:51:56.344
So: what should you be able to DO now, that you could not do an hour ago?

00:51:56.394 --> 00:51:57.854
Four things.

00:51:57.904 --> 00:52:03.434
One. Say what the data-link layer's duty is, in one sentence.

00:52:03.484 --> 00:52:08.254
Node to node. Deliver to the next machine, never to the far end.

00:52:08.304 --> 00:52:12.424
And explain why that one sentence means one frame per link.

00:52:12.474 --> 00:52:17.274
Two. Name the three services, and decline the fourth.

00:52:17.324 --> 00:52:20.504
Framing, flow control, error control.

00:52:20.554 --> 00:52:27.874
Congestion control is listed by the textbook, and then disclaimed by the textbook.

00:52:27.924 --> 00:52:31.374
Three. Classify any MAC address from its first byte.

00:52:31.424 --> 00:52:36.884
Write byte zero in binary, read the last bit — the I/G bit.

00:52:36.934 --> 00:52:40.054
And recognise all-Fs on sight.

00:52:40.104 --> 00:52:45.624
Four. Trace ARP through all four of Forouzan's cases.

00:52:45.674 --> 00:52:54.624
And know, without hesitating, which IP address is handed to ARP when the destination is not on this network.

00:52:56.134 --> 00:53:05.084
If any one of those four is shaky, the section dividers tell you exactly where to go back to.

00:53:05.927 --> 00:53:11.807
Five final questions. No answers on the slide this time — these are yours to work out.

00:53:11.857 --> 00:53:16.677
Paper, pen, and the pause button.

00:53:16.727 --> 00:53:24.897
One. A datagram crosses three links. How many frames, how many datagrams, and which nodes build a frame?

00:53:24.947 --> 00:53:33.897
Two. Which sublayers does a dedicated point-to-point link need, and which does a Wi-Fi cell need?

00:53:34.307 --> 00:53:41.077
Three. Is 47:20:1B:2E:08:EE unicast, multicast or broadcast? Show me the bit.

00:53:41.127 --> 00:53:50.077
Four. A host sends to a machine on another network. Which IP address is handed to ARP?

00:53:50.167 --> 00:53:59.057
Five. A frame is caught on the middle link of a three-link path. Which of its four addresses are the original ones?

00:53:59.107 --> 00:54:07.627
Pause here and work through all five.

00:54:07.677 --> 00:54:16.627
Every one of them is answerable from a single slide in this session, and if you can do all five you are ready for the chapter nine questions.

00:54:22.257 --> 00:54:24.057
That is Session 7.

00:54:24.107 --> 00:54:26.377
One letter, many envelopes.

00:54:26.427 --> 00:54:30.297
IP names the ends. MAC drives one link at a time.

00:54:30.347 --> 00:54:39.297
Before the next session, read Forouzan sections eighteen point one to eighteen point three: the network layer, best-effort delivery, the four delays, and congestion.

00:54:41.187 --> 00:54:50.137
And one question to sleep on. Run a-r-p minus a on your own machine tonight, find your default gateway in that list, and be able to say why your laptop bothered to learn that particular MAC address.

00:54:53.447 --> 00:55:01.737
Weekly Online Quiz A3 is live on the course website — twenty minutes, one attempt, closes Saturday midnight.

00:55:01.787 --> 00:55:09.641
Next class we climb one more floor, to the network layer. See you there.
