An Introduction to Internet Networking and Routing
From “what’s a MAC address?” to designing your own segmented home or shack network — with the reason behind every decision. Four parts, no prior knowledge needed, and no seven-layer catechism.
The course runs as auto-advancing slides on the repeater, so this page is your companion: the key ideas from each part, the reference tables worth keeping, and a subnet drill so you can practise the arithmetic yourself. Watching is good. Doing the sums is what makes it stick.
The Wire
Key ideas
- Every network has to answer two questions: who is next to me? and how do I reach everyone else? Ethernet answers the first. IP answers the second.
- A MAC address is 48 bits: half says who made the interface, half is its serial number. It tells you who a device is, never where it is.
- A switch learns which MAC address lives on which port just by watching traffic. No setup required.
- A switch splits collision domains but not broadcast domains. Only a router or a VLAN does that — which is why subnets exist.
Buying advice in one breath
Install Cat 6a and forget about it. Leave auto-negotiation on at both ends. Buy a switch that can do VLANs, and check its total PoE budget, not just the per-port figure. Fibre between buildings, never copper.
Toolkit
Link lights · a £20 cable tester · arp -a · switch port error counters (CRC errors mean a bad cable; late collisions mean a duplex mismatch).
The Address
Key ideas
- An IPv4 address is one 32-bit number wearing dots. Like a phone number, it has a network part (the area code) and a host part (the subscriber).
- The subnet mask draws the line between them. Address AND mask = the network. That one operation is the whole of subnetting.
- Every subnet loses two addresses: host bits all zero (the network) and all ones (the broadcast).
- Before sending, a host asks: is the destination on my subnet? Yes — ARP for it and send direct. No — send it to the default gateway.
- MAC addresses change at every router. IP addresses travel end to end — unless NAT rewrites them on the way out of your house.
The only nine numbers you need
Any octet of a subnet mask is one of these. Learn the list and you can subnet in your head.
| Decimal | Binary | Mask bits in this octet |
|---|---|---|
| 0 | 00000000 | 0 |
| 128 | 10000000 | 1 |
| 192 | 11000000 | 2 |
| 224 | 11100000 | 3 |
| 240 | 11110000 | 4 |
| 248 | 11111000 | 5 |
| 252 | 11111100 | 6 |
| 254 | 11111110 | 7 |
| 255 | 11111111 | 8 |
How big is a subnet?
| Prefix | Mask | Addresses | Usable hosts | Subnets start every… |
|---|---|---|---|---|
| /24 | 255.255.255.0 | 256 | 254 | 256 |
| /25 | 255.255.255.128 | 128 | 126 | 128 |
| /26 | 255.255.255.192 | 64 | 62 | 64 |
| /27 | 255.255.255.224 | 32 | 30 | 32 |
| /28 | 255.255.255.240 | 16 | 14 | 16 |
| /29 | 255.255.255.248 | 8 | 6 | 8 |
| /30 | 255.255.255.252 | 4 | 2 | 4 |
Addresses you will meet
| Range | What it is | What it tells you |
|---|---|---|
| 10.0.0.0/8 | Private | Larger businesses, VPNs |
| 172.16.0.0/12 | Private | Docker, some routers |
| 192.168.0.0/16 | Private | Almost every home |
| 127.0.0.0/8 | Loopback | This machine, talking to itself |
| 169.254.0.0/16 | Link-local | DHCP failed — a fault sign |
| 100.64.0.0/10 | Carrier-grade NAT | Your ISP is sharing your address; port forwarding won’t work |
Toolkit
ipconfig / ip addr · ping · arp -a · route print / ip route · tracert / traceroute
Subnet drill
A fresh question every time. Work it out on paper first — then check yourself, and look at the working if you’re stuck.
The Network
Key ideas
- DHCP hands out address, mask, gateway and DNS. Run one server per subnet, and prefer reservations to typing static addresses into devices.
- DNS turns names into numbers. When websites won’t load but
ping 8.8.8.8works, it’s almost always DNS. - The IP address gets you to the machine; the port number gets you to the program. TCP for reliability, UDP for anything live.
- VLANs split one switch into several separate networks. The router joins them, and the firewall on that router decides who may talk to whom.
The plan: make addresses mean something
Rule one: the VLAN number is the third octet, so VLAN 20 is 192.168.20.0/24. Rule two: lay out every subnet the same way.
| Range | Use |
|---|---|
| .1 | Gateway — the router |
| .2 – .49 | Fixed kit: switches, access points, servers |
| .50 – .199 | DHCP pool |
| .200 – .254 | DHCP reservations: printers, cameras, Pis |
A worked plan for home, shack or small office
| VLAN | Name | Subnet | What lives there |
|---|---|---|---|
| 1 | Management | 192.168.1.0/24 | Switches, access points |
| 10 | Trusted | 192.168.10.0/24 | Laptops, phones, desktops |
| 20 | IoT | 192.168.20.0/24 | Smart plugs, TV, heating |
| 30 | Guest | 192.168.30.0/24 | Visitors — internet only |
| 40 | Cameras | 192.168.40.0/24 | CCTV and the recorder |
| 50 | Shack | 192.168.50.0/24 | SDRs, Pis, stream encoders |
Who may talk to whom
Read across: from the zone on the left, to the zone at the top. “Drop” still lets replies back to conversations the other side started — so a laptop can open a camera, but a camera can’t open anything.
| From \ To | Trusted | IoT | Guest | Cameras | Shack | Internet |
|---|---|---|---|---|---|---|
| Trusted | — | Allow | Drop | Allow | Allow | Allow |
| IoT | Drop | — | Drop | Drop | Drop | Allow |
| Guest | Drop | Drop | — | Drop | Drop | Allow |
| Cameras | Drop | Drop | Drop | — | Drop | Drop |
| Shack | Drop | Drop | Drop | Drop | — | Allow |
Fault-finding: climb the ladder
Start at rung 1. The first rung that fails tells you where the problem is.
- 1
link lightNothing? Cable, port or power. - 2
ipconfig / ip addr169.254 or the wrong subnet? DHCP, or the wrong switch port or VLAN. - 3
ping the gatewayFails? VLAN, mask or cable. - 4
ping 8.8.8.8Fails? NAT, the ISP, or a firewall rule. - 5
ping a nameFails when rung 4 works? DNS.
Wi-Fi
Key ideas
- Wi-Fi is Ethernet over a shared, half-duplex radio channel. Airtime, not megabits, is the scarce resource — and one slow old device drags everyone down.
- The signal bars only tell you how well your device hears the access point, not how well the AP hears you. It’s the talk-in problem every repeater user knows.
- Several modest access points, wired back and powered by PoE, beat one loud one — and beat plug-in extenders every time.
- Each Wi-Fi name maps onto a VLAN from Part 3. Three names cover almost every house: Home, Things, Guest.
Quick reference
| Setting | Recommendation |
|---|---|
| 2.4 GHz channels | 1, 6 or 11 only — anything else overlaps two of them |
| 5 GHz width | 80 MHz at home. Random one-minute drops? Suspect a DFS radar hit |
| Target signal | −67 dBm or better in every room that matters |
| Transmit power | Moderate, not maximum — loud APs make lopsided links and sticky clients |
| Security | WPA2/WPA3 mixed, long passphrase (four random words), WPS off |
| Guest network | Own VLAN, internet only, client isolation on |
| Casting to the TV on the IoT network | Turn on the router’s mDNS reflector, and allow Trusted → IoT in the firewall |
En français — Introduction aux réseaux Internet et au routage
Une série en quatre parties (environ 1 h 40 au total), diffusée sur GB3OO, pour passer de « c’est quoi une adresse MAC ? » à la conception de votre propre réseau domestique segmenté.
- Partie 1 — Le câble : Ethernet, adresses MAC, commutateurs, et pourquoi un commutateur ne bloque pas les diffusions.
- Partie 2 — L’adresse : IPv4 en binaire, masques de sous-réseau, ARP, passerelle par défaut, routage et NAT.
- Partie 3 — Le réseau : DHCP, DNS, ports, pare-feu, VLAN, et un plan d’adressage complet.
- Partie 4 — Le Wi-Fi : bandes, canaux, couverture, sécurité, et un nom de réseau par VLAN.
Les diapositives sont en anglais, mais les tableaux et l’exercice de sous-réseaux se passent de traduction : les chiffres sont les mêmes dans toutes les langues ! Un conseil de radioamateur : si vous émettez vers QO-100 en DATV, éloignez votre Wi-Fi du canal 1.
Questions et remarques : admin@gb3oo.co.uk — 73 de G8YTZ
