1. OSI Ref Model/TCP-IP Model
· Explanation of each layer
· Protocols at each layer
2. ARP
· Packet structure ARP, GARP
· Diff between ARP & GARP
3. Ethernet Frame
· Fields in Ethernet II frame
· Size of Ethernet Frame
· LLC & MAC Sublayer
4. IP
· Fields in IP header
· Importance of Identification field, Flags, Fragment Offset
· Fragmentation-Importance, Detailed understanding of how packet is reassembled
· Path MTU Discovery
5. TCP
· 3 way handshake
· Parameters Informed, negotiated in TCP
· Fields in TCP header
· Windowing in TCP
· Purpose of Sequence, Ack number
· Window Size , MSS, Windows Scale Factor, SACK
· Zero Window
· Diff between MSS & MTU
· Flags -SYN,ACK,FIN,RST,PSH,URG
· Diff between Push & Urg , Purpose of RST bit
· Segmentation
· 4 way close
· Flow Control –Sliding Window
· Error Control – TCP retransmissions
6. FTP
· How Active & Passive FTP works
· PORT & PASV command
· Troubleshooting FTP issues
7. Traceroute , ICMP, Ping
· How Traceroute, Tracert works
· ICMP message in traceroute
· ICMP Type & Code (Type 8, Type 0, Type 3, Type 11)
· Meaning of traceroute output
8. Switching & Routing Basics
· Working of a Layer 2 switch
· MAC Table, CAM Table , ARP Table
· Static & Default Route
9. Firewall
· Stateful vs stateless Firewall
· Parameters in a Session Table
· NAT , PAT
· TCP Packet through Firewall , SYN check, Sequence check
· FTP connection through Firewall, Troubleshooting
· Deep Packet Inspection / ALG
· Transparent Firewall
· High Availability – Active/Standby , Active/Active , How Standby knows if Active is down
· SYN Flood Attack & Mitigation
· IP spoofing & Mitigation
10. VPN
· Need for VPN
· Types of VPN
· Phase 1 & Phase 2 messages – Main mode, Aggressive Mode, Quick Mode
· Need for 2 Phases in IPsec
· Symmetric & Asymmetric keys, Hash & HMAC,DH group
· Troubleshooting if various messages not received in IPsec (Msg1,Msg2,Msg3,Msg4,Msg5,Msg6)
· Why Phase 1 is needed
· Reasons why VPN Phase 1 does not come up
· VPN Phase 1 up , Phase 2 down – Troubleshoot
· VPN Phase 1 up , Phase 2 up , Traffic not flowing – Troubleshoot
· Traffic Flowing but Latency Issue-Troubleshoot
· Tunnel Mode & Transport Mode
· Overlapping subnets
· NAT-T(NAT Discovery) –VPN msgs for NAT-T Negotiation & Discovery
· ESP,AH
· Replay Attack & Mitigation
· Ports to be allowed on Firewall for VPN