Networking Devices and Network Services

Chapter 5 — Networking Devices | Network+ Study Map
CompTIA Network+ · N10-009 · Domains 2.3 & 3.4

Chapter 5 — Networking Devices and Network Services

Networking devices are physical or virtual components that connect hosts and control the movement of data across a network. Network services are functions that support communication by automatically assigning addresses, resolving names, synchronizing time, controlling access, and managing network resources. Together, networking devices and network services form the operational foundation of modern networks.
The topics in this article are categorized according to their primary functions: endpoint connectivity, switching and routing, network security, wireless access, traffic and access management, addressing and name resolution, time synchronization, and specialized network systems. This article also explains how these components affect collision and broadcast domains and introduces supporting tools used to verify and troubleshoot their operation.

16 sectionsDevice explorerDORA simulatorDNS pathDomain-counting lab15-question exam check
CLIENTSWITCHROUTERSERVICESDNS
01

Device Decision Map

Start with the layer and the forwarding decision. A hub repeats signals, a switch reads MAC addresses, and a router reads IP addresses. Specialized appliances then add security, control, translation, or service delivery.

Device familyTypical layerPrimary decision or action
Repeater / hubLayer 1Regenerates and repeats signals; does not inspect frames.
NIC / bridge / switch / APLayer 2Uses frames and MAC addresses.
Router / multilayer switchLayer 3Forwards packets using IP addresses and routes.
Firewall / proxy / load balancerMultiple layersApplies policy, mediates sessions, or distributes application traffic.
Memory hookHub = signal. Switch = frame and MAC. Router = packet and IP.
02

Core Device Explorer

Select a device to see what it examines, what boundary it creates, and where it fits.

03

NICs, Bridges & Switches

NIC indicators

Link before activity

The link LED indicates a physical carrier. The activity LED flashes when frames move. Speed colours vary by vendor.

Transparent bridge

Learn and forward

A bridge learns source MAC locations. Unknown destinations are flooded to eligible ports except the ingress port.

Modern switch

Multiport bridge

Each switch port is its own collision domain. All ports remain in the same broadcast domain unless VLANs divide them.

Troubleshooting orderCheck power, cable, interface state, and the link LED first. Higher-layer tests are meaningless without a working physical connection.
04

Managed Switching & Routing

FeatureUnmanaged switchManaged switchRouter interface
ConfigurationPlug-and-playVLANs, monitoring, security, port controlsIP network, routing, policy
AddressingNo per-port IPManagement IP; access ports normally no IPIP required for connected network
BoundaryCollision per portCollision per port; broadcast per VLANCollision and broadcast per interface
Typical useSmall simple LANBusiness or enterprise LANConnect subnets and VLANs
Performance clueA duplex mismatch can produce errors and poor throughput even when the link is up. Check speed and duplex at both endpoints.
05

Security Devices

CompareIDS tells you. IPS tries to stop it. HIDS watches one host. A firewall enforces policy at a boundary.
06

Wireless Architecture

Small deployment

Autonomous AP

Each AP is configured independently. This suits a home, SOHO, or small site where centralized orchestration is unnecessary.

Enterprise deployment

Lightweight AP + WLC

A wireless LAN controller centralizes policies, configuration, and visibility for many lightweight APs.

Coverage extension

Range extender

Receives and retransmits an existing wireless signal. Plan overlap with the original AP coverage; the manual recommends at least 15%.

Exam angleAn AP bridges wireless clients to the wired LAN at Layer 2. Wireless users share airtime, unlike dedicated switched full-duplex Ethernet links.
07

Traffic & Access Appliances

Availability

Load balancer

Presents a virtual IP, distributes connections, and uses health checks to remove failed servers. Methods include round robin, least connections, response time, and weights.

Performance

Packet shaper

Controls bandwidth and prioritizes latency-sensitive traffic so one application cannot consume disproportionate capacity.

Client representative

Forward proxy

Represents internal clients and may cache, authenticate, log, or filter their external requests.

Server representative

Reverse proxy

Hides back-end servers and may terminate encryption, cache responses, or distribute traffic.

Deep policy

NGFW

Adds application awareness and deeper inspection beyond basic address-and-port filtering.

Encrypted access

VPN headend

Terminates many remote-access or site-to-site tunnels and centralizes authentication, encryption, and policy.

08

DHCP — DORA Simulator

DHCP automatically supplies IP configuration using UDP 67 on the server and UDP 68 on the client. Step through the four-message workflow.

Client has no lease. Begin with DHCPDISCOVER.
Memory hookDiscover → Offer → Request → Acknowledge = DORA.
09

DHCP Scope, Relay & IPAM

ControlPurposeExample
ScopePool and policy for one subnet192.168.10.0/24 client scope
LeaseTime a client may use an address8 hours
ReservationPredictable lease tied to client identityPrinter always receives .50
ExclusionAddresses DHCP must not allocateRouter and server range
OptionAdditional client configurationGateway, DNS, domain name
Across subnets

DHCP relay / IP helper

Receives a local client broadcast and forwards it as unicast to a centralized DHCP server because routers do not forward broadcasts by default.

Source of truth

IPAM

Tracks blocks, subnets, assignments, reservations, utilization, and often DHCP/DNS data to prevent duplicates and exhausted pools.

APIPA clueA 169.254.x.x address means the client did not receive a valid DHCP response. Check link, VLAN, relay, server reachability, and available leases.
10

DNS Resolution Path

DNS maps human-friendly names to records. Ordinary queries commonly use UDP 53; TCP 53 is used when reliable transport is required, including many zone transfers and large responses.

1 · CLIENTCache and hosts file
→
2 · RESOLVERCache or recurse
→
3 · HIERARCHYFollow referrals
→
4 · AUTHORITYReturn zone answer
Diagnostic clueIf an IP address works but the equivalent hostname fails, investigate DNS before routing or the destination application.
11

DNS Record Explorer

12

DNS Roles & Secure Resolution

TechnologyProtectsDoes not inherently provide
DNSSECAuthenticity and integrity of signed DNS dataQuery confidentiality
DoHEncrypted transport over HTTPS, typically TCP 443Proof that unsigned DNS data is correct
DoTEncrypted transport over dedicated TLS, typically TCP 853Proof that unsigned DNS data is correct
Exam trapDNSSEC signs DNS data. DoH and DoT encrypt DNS transport. They solve different problems.
13

Time & Specialized Systems

UDP 123

NTP

Synchronizes clocks across packet networks and organizes time sources by stratum.

High precision

PTP

Supports much tighter, often sub-microsecond synchronization where the environment supports it.

Secure time

NTS

Adds cryptographic security to NTP to authenticate time service and resist tampering.

Why time mattersAccurate clocks support log correlation, authentication, certificate validation, monitoring, incident response, and distributed applications.
14

Collision & Broadcast Domains

Count boundaries systematically: every switch-port connection is a separate collision domain; every VLAN or router interface is a separate broadcast domain. Hubs extend one shared collision domain.

PatternCollision effectBroadcast effect
Hosts on one hubAll share oneAll share one
One host per switch portEach port is separateTogether within the VLAN
Router between networksEach interface is separateEach interface is separate
Multiple VLANsPorts already separateEach VLAN is separate

Domain-counting lab

Scenario: six PCs connect to six access ports on one switch. The switch has one uplink to a router. All switch ports belong to one VLAN.

15

Troubleshooting Ladder & PowerShell

01 · Physical

Power, cabling, radio signal, LEDs, interface state.

02 · Data Link

VLAN, MAC learning, duplex, speed, wireless association.

03 · Network

Address, prefix, gateway, routes, subnet boundaries.

04 · Services

DHCP lease, DNS resolution, time, required ports.

05 · Security

Firewall, ACL, proxy, NAC, IDS/IPS, segmentation.

06 · Application

Test the actual service and inspect its logs.

Get-NetIPConfigurationAddresses, gateway, and DNS
Get-NetIPAddressAssigned IPv4 and IPv6
ipconfig /allAdapter and DHCP details
ipconfig /releaseRelease IPv4 lease
ipconfig /renewRequest a new lease
Resolve-DnsName example.comQuery DNS records
Get-DnsClientServerAddressConfigured DNS servers
ipconfig /flushdnsClear resolver cache
16

Exam Check

Choose one answer. Each question locks after selection and immediately explains the result.

Score: 0 / 0
NETWORK+ STUDY MAP · CHAPTER 5 · NETWORKING DEVICES & SERVICES