Networking Devices and Network Services
Chapter 5 — Networking Devices and Network Services
Networking devices are physical or virtual components that connect hosts and control the movement of data across a network. Network services are functions that support communication by automatically assigning addresses, resolving names, synchronizing time, controlling access, and managing network resources. Together, networking devices and network services form the operational foundation of modern networks.
The topics in this article are categorized according to their primary functions: endpoint connectivity, switching and routing, network security, wireless access, traffic and access management, addressing and name resolution, time synchronization, and specialized network systems. This article also explains how these components affect collision and broadcast domains and introduces supporting tools used to verify and troubleshoot their operation.
Device Decision Map
Start with the layer and the forwarding decision. A hub repeats signals, a switch reads MAC addresses, and a router reads IP addresses. Specialized appliances then add security, control, translation, or service delivery.
| Device family | Typical layer | Primary decision or action |
|---|---|---|
| Repeater / hub | Layer 1 | Regenerates and repeats signals; does not inspect frames. |
| NIC / bridge / switch / AP | Layer 2 | Uses frames and MAC addresses. |
| Router / multilayer switch | Layer 3 | Forwards packets using IP addresses and routes. |
| Firewall / proxy / load balancer | Multiple layers | Applies policy, mediates sessions, or distributes application traffic. |
Core Device Explorer
Select a device to see what it examines, what boundary it creates, and where it fits.
NICs, Bridges & Switches
Link before activity
The link LED indicates a physical carrier. The activity LED flashes when frames move. Speed colours vary by vendor.
Learn and forward
A bridge learns source MAC locations. Unknown destinations are flooded to eligible ports except the ingress port.
Multiport bridge
Each switch port is its own collision domain. All ports remain in the same broadcast domain unless VLANs divide them.
Managed Switching & Routing
| Feature | Unmanaged switch | Managed switch | Router interface |
|---|---|---|---|
| Configuration | Plug-and-play | VLANs, monitoring, security, port controls | IP network, routing, policy |
| Addressing | No per-port IP | Management IP; access ports normally no IP | IP required for connected network |
| Boundary | Collision per port | Collision per port; broadcast per VLAN | Collision and broadcast per interface |
| Typical use | Small simple LAN | Business or enterprise LAN | Connect subnets and VLANs |
Security Devices
Wireless Architecture
Autonomous AP
Each AP is configured independently. This suits a home, SOHO, or small site where centralized orchestration is unnecessary.
Lightweight AP + WLC
A wireless LAN controller centralizes policies, configuration, and visibility for many lightweight APs.
Range extender
Receives and retransmits an existing wireless signal. Plan overlap with the original AP coverage; the manual recommends at least 15%.
Traffic & Access Appliances
Load balancer
Presents a virtual IP, distributes connections, and uses health checks to remove failed servers. Methods include round robin, least connections, response time, and weights.
Packet shaper
Controls bandwidth and prioritizes latency-sensitive traffic so one application cannot consume disproportionate capacity.
Forward proxy
Represents internal clients and may cache, authenticate, log, or filter their external requests.
Reverse proxy
Hides back-end servers and may terminate encryption, cache responses, or distribute traffic.
NGFW
Adds application awareness and deeper inspection beyond basic address-and-port filtering.
VPN headend
Terminates many remote-access or site-to-site tunnels and centralizes authentication, encryption, and policy.
DHCP — DORA Simulator
DHCP automatically supplies IP configuration using UDP 67 on the server and UDP 68 on the client. Step through the four-message workflow.
DHCP Scope, Relay & IPAM
| Control | Purpose | Example |
|---|---|---|
| Scope | Pool and policy for one subnet | 192.168.10.0/24 client scope |
| Lease | Time a client may use an address | 8 hours |
| Reservation | Predictable lease tied to client identity | Printer always receives .50 |
| Exclusion | Addresses DHCP must not allocate | Router and server range |
| Option | Additional client configuration | Gateway, DNS, domain name |
DHCP relay / IP helper
Receives a local client broadcast and forwards it as unicast to a centralized DHCP server because routers do not forward broadcasts by default.
IPAM
Tracks blocks, subnets, assignments, reservations, utilization, and often DHCP/DNS data to prevent duplicates and exhausted pools.
DNS Resolution Path
DNS maps human-friendly names to records. Ordinary queries commonly use UDP 53; TCP 53 is used when reliable transport is required, including many zone transfers and large responses.
DNS Record Explorer
DNS Roles & Secure Resolution
| Technology | Protects | Does not inherently provide |
|---|---|---|
| DNSSEC | Authenticity and integrity of signed DNS data | Query confidentiality |
| DoH | Encrypted transport over HTTPS, typically TCP 443 | Proof that unsigned DNS data is correct |
| DoT | Encrypted transport over dedicated TLS, typically TCP 853 | Proof that unsigned DNS data is correct |
Time & Specialized Systems
NTP
Synchronizes clocks across packet networks and organizes time sources by stratum.
PTP
Supports much tighter, often sub-microsecond synchronization where the environment supports it.
NTS
Adds cryptographic security to NTP to authenticate time service and resist tampering.
Collision & Broadcast Domains
Count boundaries systematically: every switch-port connection is a separate collision domain; every VLAN or router interface is a separate broadcast domain. Hubs extend one shared collision domain.
| Pattern | Collision effect | Broadcast effect |
|---|---|---|
| Hosts on one hub | All share one | All share one |
| One host per switch port | Each port is separate | Together within the VLAN |
| Router between networks | Each interface is separate | Each interface is separate |
| Multiple VLANs | Ports already separate | Each VLAN is separate |
Domain-counting lab
Scenario: six PCs connect to six access ports on one switch. The switch has one uplink to a router. All switch ports belong to one VLAN.
Troubleshooting Ladder & PowerShell
Power, cabling, radio signal, LEDs, interface state.
VLAN, MAC learning, duplex, speed, wireless association.
Address, prefix, gateway, routes, subnet boundaries.
DHCP lease, DNS resolution, time, required ports.
Firewall, ACL, proxy, NAC, IDS/IPS, segmentation.
Test the actual service and inspect its logs.
Get-NetIPConfigurationAddresses, gateway, and DNSGet-NetIPAddressAssigned IPv4 and IPv6ipconfig /allAdapter and DHCP detailsipconfig /releaseRelease IPv4 leaseipconfig /renewRequest a new leaseResolve-DnsName example.comQuery DNS recordsGet-DnsClientServerAddressConfigured DNS serversipconfig /flushdnsClear resolver cacheExam Check
Choose one answer. Each question locks after selection and immediately explains the result.