1Session at a glance
Objectives
- Name the seven OSI layers and the four TCP/IP layers, and say what lives at each.
- Say what a MAC address is, what an IP address is, and which one changes at every hop.
- Place the common protocols and their ports at their layer: ARP, IP, TCP, UDP, DNS, DHCP, HTTP, HTTPS, RDP, SMB.
- Given a symptom, name the layer it most likely lives at and the first command to run.
- Open one packet in Wireshark and point at each layer's header in it.
Before the session
- The two stacks drawn on the whiteboard, with the right-hand "lives here" column left blank to fill in live.
- Wireshark open with
01-sample-capture.pcaploaded and nothing expanded. If the capture file does not exist yet, capture ten seconds of a browser loading an internal site and use that. - One recent Syncro ticket open that came down to a single layer. A "cannot reach the file server" that turned out to be DNS or a cable is ideal.
- The six ports written large somewhere visible: 53, 67 and 68, 80, 443, 3389, 445.
- Everyone with the Learner Guide open, and Wireshark installed on the machines they will use.
| Time | Block | What happens |
|---|---|---|
| 0:00 | Open | Name the layer before touching anything. |
| 0:05 | Concept | The devices, the two addresses, the seven OSI layers, the four TCP/IP layers, encapsulation, protocols and ports. |
| 0:28 | Show | Live in Wireshark: twelve packets, then one packet expanded to every layer. Then one real ticket diagnosed out loud by layer. |
| 0:38 | Do | Everyone on their own machine: ipconfig /all labeled by layer, then find the DNS query and the handshake in the capture. |
| 0:48 | Check | Seven questions. |
| 0:55 | Close | The work before session 02, and what that session covers. |
The concept block is 23 minutes across six ideas. The two that carry the session are the two addresses and the OSI layers, at four and six minutes. If the room is running behind, cut the device table to the three devices in the room and shorten the ports section to DNS, HTTPS and RDP. Never cut the two addresses, because encapsulation and the whole troubleshooting ladder rest on it.
2Open (0:00, 5 minutes)
A user calls and says the shared drive will not open. There are about six things it could be, and they are not equally likely, and they are not in random order. They are in a fixed order, from the cable at the bottom to the application at the top. If you test in that order, the first test that fails is the answer, and you are done. If you guess, you can spend forty minutes on the server and find out at the end that the switch port was on the wrong network. Today is the order you test in.
- Hand on the whiteboard stack while you say it. The two stacks are already drawn, and the right-hand column is blank because you fill it in as you go.
- Ask the room: last ticket you closed, what layer was it? Take two answers, no more. Most tickets turn out to sit at one layer, and hearing two examples from their own week makes the point faster than you can.
- Say what they will be able to do at the end: take a symptom, name the layer, and name the first command. That is the deliverable.
3Concept (0:05, 23 minutes)
The devices on a network (3 min)
Work the device table in section 2 of the Learner Guide. Point at the real hardware in the room or the rack if you can see any of it.
- Cable, patch panel and PoE carry the signal. PoE is power over Ethernet, electrical power down the same cable, which is why a phone or an access point needs no separate power supply.
- Switch connects devices inside one office and forwards by hardware address.
- Access point is a switch port delivered over radio.
- Router connects one network to another and forwards by network address.
- Firewall permits or blocks against a rule list, on addresses, on ports, and on many firewalls on the application itself.
- Say the part people find surprising: at most of our client sites one box is the firewall, the router and the wireless controller at once. It still does each job at its own layer, which is why one of those jobs can fail while the others keep working.
Two addresses for every device (4 min)
This is the section that decides whether the rest of the hour lands. Do not rush it.
Every machine has two addresses at the same time. The MAC address is 48 bits burned into the network card at the factory, six pairs of hex digits, and it never changes no matter where you carry the laptop. The IP address is handed to the machine by whatever network it is plugged into, four numbers separated by dots, and it changes the moment you plug it in somewhere else. One says what the device is. The other says where the device currently is.
- Then the reason both exist. Walk the hop-by-hop trace on the board: a workstation at 192.168.10.15 loads a site at 203.0.113.9. The message leaves with destination IP 203.0.113.9, which is fifteen hops away, and destination MAC of the office router, which is three feet away.
- The router strips the local addressing, writes new local addressing for the next device, and sends the same message on. Fifteen times.
- Land the line that makes it stick: the destination IP address does not change once on the whole journey. The destination MAC address changes at every single hop. IP is the address on the envelope, MAC is whose hands the envelope is in right now.
- Then ARP, because two addressing systems need something joining them. A device that knows an IP on its own network but not the MAC broadcasts "who has 192.168.10.10" and the owner answers. Nothing else happens until that answer arrives, which is why ARP is the first thing in almost every capture, and they are about to see exactly that.
Somebody usually asks whether the source address really stays the same. It does not: the firewall rewrites the private source address to its own public one on the way out, and remembers the swap so the reply comes back to the right machine. That is network address translation. Give that answer in one sentence and move on. It is a session of its own.
The seven OSI layers (6 min)
Fill in the "lives here" column on the whiteboard while you talk, and say the layer number out loud every time you say a layer name. Start at the bottom, because bottom to top is the order they will troubleshoot in.
- L1 Physical. The cable, the port, the light, PoE. Is it plugged in and lit. Unit: bits.
- L2 Data Link. The switch. MAC addresses. ARP. VLANs. Define VLAN here rather than assuming it: one physical switch split into separate networks by configuration, ports 1 to 12 staff and 13 to 24 guest, nothing physical marking the difference. Unit: frame.
- L3 Network. IP addresses. The router. The default gateway, which is the address a device sends anything not on its own network to. Unit: packet.
- L4 Transport. TCP against UDP. Ports. Unit: segment.
- L5 to L7. Where the application lives. Roll them together and say plainly that nobody separates them on a ticket. Unit: data.
- Give both memory hooks: bottom to top, Please Do Not Throw Sausage Pizza Away. Top to bottom, All People Seem To Need Data Processing.
The four TCP/IP layers (3 min)
- Draw the brackets joining the seven to the four: layers 5, 6 and 7 become Application; layer 4 stays Transport; layer 3 becomes Internet; layers 1 and 2 become Link.
- Say why both are taught. OSI is the vocabulary people speak in. TCP/IP is what the operating system is built on, so it is what the tools report in. The exam asks in OSI and Wireshark answers in TCP/IP.
- The figure in section 5 of the Learner Guide is the same mapping if the whiteboard gets crowded.
Encapsulation (4 min)
- Use the envelope image, then correct it immediately: each layer adds a header in front of what it was handed, and layer 2 also adds a trailer holding a checksum used to spot a damaged frame.
- Walk the figure in section 6 of the Learner Guide one row at a time, naming the unit as it changes: data, segment, packet, frame, bits.
- Say the payoff out loud, because it is what makes the demo readable: one captured frame contains every layer at once, in order, and reading it top to bottom on screen means reading the layers bottom to top.
- Give them the general term once, PDU, protocol data unit, and then go back to using the specific names.
Protocols and ports (3 min)
- Define the port before the table: a number from 0 to 65535 in the TCP or UDP header saying which program on the machine the data is for. One server at one address runs a web service and remote desktop at once, and the port is the only thing keeping them apart.
- Then the six: DNS 53, DHCP 67 and 68, HTTP 80, HTTPS 443, RDP 3389, SMB 445. Point at the numbers on the board.
- Explain the two DHCP ports rather than letting them look like a typo: the client sends from 68 to the server on 67, and the server answers back to 68. The device asking has no address yet, so the request goes to the whole local network.
- TCP against UDP in two sentences: TCP sets up a connection and confirms delivery, which is why web, files and RDP use it. UDP sends without setting up and without confirming, which is why name lookups, voice and video use it. In a capture, TCP opens with three packets and DNS over UDP has none.
4Show (0:28, 10 minutes)
Wireshark on the TV. Go slowly and name the layer out loud at every step. The capture is one thing happening: a workstation loads the intranet site, in twelve packets.
- Play the whole capture top to bottom first, narrating, expanding nothing. Packets 1 and 2 are ARP finding the DNS server's MAC address, layer 2. Packets 3 and 4 are the DNS question and answer, and there is no handshake because this is UDP. Packets 5 and 6 are ARP again for the web server, because it is a new destination and needs a new MAC address. Packets 7, 8 and 9 are the TCP handshake to port 80. Packet 10 is the request itself. Packets 11 and 12 are the acknowledgement and the 200 OK.
- Expand packet 4, the DNS answer. Show the nesting in the detail pane: Ethernet, then IP, then UDP with port 53, then the DNS answer. Say it: top down in Wireshark is bottom up in the stack.
- Expand packet 10, the GET. Point at the MAC addresses, then the IP addresses, then port 80, then the
GET / HTTP/1.1line. Every layer, one packet. That is encapsulation, on screen. - Count the ARP. Four of the twelve packets did nothing except pair an IP address with a MAC address. That is how much work the two addressing systems cost on every single conversation.
- Then the real ticket. Read the symptom out loud off the Syncro ticket, then diagnose it out loud, in order: link light, layer 1. Switch port and VLAN, layer 2. Address and gateway, layer 3. Port open, layer 4. Name resolves and the application answers, layer 7. Land on the layer it actually turned out to be, and say which test would have found it first.
Naming the layer picked the next test. Nothing else in the hour matters as much as that sentence, and it is worth saying twice: once on the capture and once on the ticket.
5Do (0:38, 10 minutes)
Everyone on their own machine. Circulate. This is the block where the two addresses either landed or did not, and you will find out by listening.
ipconfig /all, orip addrandip route. Write down the IP address, the MAC address, the default gateway and the DNS server, with the OSI layer number next to each. Answers: IP address L3, MAC address L2, default gateway L3, DNS server L7.arp -a. Find the gateway's IP address in the list and read off the MAC address beside it. This is the two addressing systems joined, on their own screen.- Open the capture. Find packet 3, the DNS query, and packet 10, the web request. In each, point at the MAC address, the IP address and the port, and say the layer for each.
- Round the room. Each person names one symptom off the top of their head and the layer they would check first. No wrong answers, just repetitions.
The thing to push back on, gently and every time, is jumping to layer 7. Somebody will say the application is broken before anything below it has been tested. Send them back to the bottom of the stack and make them say what proves each layer is healthy.
6Check (0:48, 7 minutes)
Whole room, out loud, fast. Questions 6 and 7 are the ones worth slowing down for, because the obvious answer to each is wrong.
Put each of these at its layer: ARP, HTTPS, an IP address, a switch, a MAC address.
AnswerARP layer 2, HTTPS layer 7, IP address layer 3, switch layer 2, MAC address layer 2.
Which layer does the default gateway belong to, and what does it do?
AnswerLayer 3. It is the router address a device sends anything not on its own network to. Without it the device reaches only its own local network.
Name one thing that uses TCP and one that uses UDP, and say why each one fits its job.
AnswerTCP: web, file shares, remote desktop, anything that has to arrive complete and in order. UDP: DNS lookups, voice, video, anything where speed matters more than guaranteed delivery, or where a resent piece would arrive too late to be useful anyway.
A user cannot open a website by name, but pinging the web server's IP address works. Which layer is the fault at, and what proves the layers below it are healthy?
AnswerLayer 7, name resolution. The ping succeeding proves layers 1 through 3: the cable, the local network and the addressing all carried a packet to that server and back. It does not prove layer 4, because ping carries no port number, so a proper layer 4 test would be
Test-NetConnection <address> -Port 443. If other users load the same site by name, that also proves the service itself is up, which puts the fault on this one machine's DNS configuration.Name the port for HTTPS, RDP and DNS.
AnswerHTTPS 443, RDP 3389, DNS 53.
A laptop has an IP address of
169.254.14.9and reaches nothing. Name the layer the symptom appears at, the layer the cause lives at, and the first command you run.AnswerThe symptom is at layer 3, an unusable address. The cause is at layer 7: 169.254 is the address Windows assigns itself when it asked for a DHCP address and nothing answered. First command
ipconfig /all, then check the DHCP scope on the server and whether the machine is on the VLAN that can reach it.The obvious answer is to treat it as a layer 3 addressing problem and set a static address. That does make the machine work, and it hides a DHCP fault that is about to hit everybody else, and it breaks the machine again the moment it moves to another site.
A packet leaves a workstation in the office for a web server on the internet, fifteen hops away. How many times does its destination IP address change on the way, and how many times does its destination MAC address change?
AnswerThe destination IP address does not change at all. The destination MAC address changes at every hop, so fifteen times. The IP address names the endpoint for the whole journey; the MAC address names only the next device to hand it to.
The common wrong answers are that both change together, or that neither does. Either one means the two addresses have been collapsed into one idea, and it is worth reworking the hop-by-hop trace on the board if more than one person says it.
7Close (0:55, 5 minutes)
Work before the next session
- Memorize the six ports: 53, 67 and 68, 80, 443, 3389, 445. Session 02 opens by running through them.
- Do the practice steps in section 10 of the Learner Guide, and bring the four values written down with their layer numbers.
- Read the Network+ companion, chapter 2, the OSI and TCP/IP sections and "Common Protocols and Ports". About twenty minutes. Anyone sitting the exam also works the chapter 2 review questions and Exam Tips 4, 5 and 6.
Next session
02 - IP Addressing and Subnetting. Tell them to bring a laptop, because it is worked on paper and on screen.
Open items to settle
- Whether
01-sample-capture.pcapexists in the technicians folder, or is captured live at the start of the session. - Which recent Syncro ticket is used for the live diagnosis, picked the day before so it is fresh.
8Sources
- International Organization for Standardization, ISO/IEC 7498-1, Information technology, Open Systems Interconnection, Basic Reference Model, for the seven layers and what each one is defined to do.
- Internet Engineering Task Force, RFC 1122, Requirements for Internet Hosts, Communication Layers, for the four-layer TCP/IP model.
- Internet Engineering Task Force, RFC 791 (IP), RFC 9293 (TCP), RFC 768 (UDP) and RFC 826 (ARP), for the header fields and the three-way handshake.
- Internet Assigned Numbers Authority, Service Name and Transport Protocol Port Number Registry, for the port numbers.
- Internet Engineering Task Force, RFC 3927, Dynamic Configuration of IPv4 Link-Local Addresses, for the 169.254 range.
- Kodi A. Cochran, CompTIA Network+ (N10-009) Certification Companion (Apress, 2026), chapter 2, Networking Fundamentals, and Exam Tips 4, 5 and 6.
- Wireshark Foundation, Wireshark User's Guide, for the capture and packet detail panes.
9After the session
| Delivered on | |
| Attendance | |
| What landed | |
| What did not | |
| Changes for next time | |
| Backlog items created |