Network Course

Now showing on GB3OO

An Introduction to Internet Networking and Routing

From “what’s a MAC address?” to designing your own segmented home or shack network — with the reason behind every decision. Four parts, no prior knowledge needed, and no seven-layer catechism.

4 partsAbout 1 hr 40 in totalBeginner to confidentBy G8YTZ

The course runs as auto-advancing slides on the repeater, so this page is your companion: the key ideas from each part, the reference tables worth keeping, and a subnet drill so you can practise the arithmetic yourself. Watching is good. Doing the sums is what makes it stick.

Part 1

The Wire

20 minutes · cable, Ethernet frames, MAC addresses, switching
▶ Watch Part 1

Key ideas

  • Every network has to answer two questions: who is next to me? and how do I reach everyone else? Ethernet answers the first. IP answers the second.
  • A MAC address is 48 bits: half says who made the interface, half is its serial number. It tells you who a device is, never where it is.
  • A switch learns which MAC address lives on which port just by watching traffic. No setup required.
  • A switch splits collision domains but not broadcast domains. Only a router or a VLAN does that — which is why subnets exist.

Buying advice in one breath

Install Cat 6a and forget about it. Leave auto-negotiation on at both ends. Buy a switch that can do VLANs, and check its total PoE budget, not just the per-port figure. Fibre between buildings, never copper.

Toolkit

Link lights · a £20 cable tester · arp -a · switch port error counters (CRC errors mean a bad cable; late collisions mean a duplex mismatch).

Part 2

The Address

26 minutes · IPv4 in binary, subnet masks, ARP, routing, NAT
▶ Watch Part 2

Key ideas

  • An IPv4 address is one 32-bit number wearing dots. Like a phone number, it has a network part (the area code) and a host part (the subscriber).
  • The subnet mask draws the line between them. Address AND mask = the network. That one operation is the whole of subnetting.
  • Every subnet loses two addresses: host bits all zero (the network) and all ones (the broadcast).
  • Before sending, a host asks: is the destination on my subnet? Yes — ARP for it and send direct. No — send it to the default gateway.
  • MAC addresses change at every router. IP addresses travel end to end — unless NAT rewrites them on the way out of your house.

The only nine numbers you need

Any octet of a subnet mask is one of these. Learn the list and you can subnet in your head.

DecimalBinaryMask bits in this octet
0000000000
128100000001
192110000002
224111000003
240111100004
248111110005
252111111006
254111111107
255111111118

How big is a subnet?

PrefixMaskAddressesUsable hostsSubnets start every…
/24255.255.255.0256254256
/25255.255.255.128128126128
/26255.255.255.192646264
/27255.255.255.224323032
/28255.255.255.240161416
/29255.255.255.248868
/30255.255.255.252424

Addresses you will meet

RangeWhat it isWhat it tells you
10.0.0.0/8PrivateLarger businesses, VPNs
172.16.0.0/12PrivateDocker, some routers
192.168.0.0/16PrivateAlmost every home
127.0.0.0/8LoopbackThis machine, talking to itself
169.254.0.0/16Link-localDHCP failed — a fault sign
100.64.0.0/10Carrier-grade NATYour ISP is sharing your address; port forwarding won’t work
Ready to try it? The subnet drill is just below.

Toolkit

ipconfig / ip addr · ping · arp -a · route print / ip route · tracert / traceroute

0 / 0

Subnet drill

A fresh question every time. Work it out on paper first — then check yourself, and look at the working if you’re stuck.

Part 3

The Network

27 minutes · DHCP, DNS, ports, firewalls, VLANs and a real IP plan
▶ Watch Part 3

Key ideas

  • DHCP hands out address, mask, gateway and DNS. Run one server per subnet, and prefer reservations to typing static addresses into devices.
  • DNS turns names into numbers. When websites won’t load but ping 8.8.8.8 works, it’s almost always DNS.
  • The IP address gets you to the machine; the port number gets you to the program. TCP for reliability, UDP for anything live.
  • VLANs split one switch into several separate networks. The router joins them, and the firewall on that router decides who may talk to whom.

The plan: make addresses mean something

Rule one: the VLAN number is the third octet, so VLAN 20 is 192.168.20.0/24. Rule two: lay out every subnet the same way.

RangeUse
.1Gateway — the router
.2 – .49Fixed kit: switches, access points, servers
.50 – .199DHCP pool
.200 – .254DHCP reservations: printers, cameras, Pis

A worked plan for home, shack or small office

VLANNameSubnetWhat lives there
1Management192.168.1.0/24Switches, access points
10Trusted192.168.10.0/24Laptops, phones, desktops
20IoT192.168.20.0/24Smart plugs, TV, heating
30Guest192.168.30.0/24Visitors — internet only
40Cameras192.168.40.0/24CCTV and the recorder
50Shack192.168.50.0/24SDRs, Pis, stream encoders

Who may talk to whom

Read across: from the zone on the left, to the zone at the top. “Drop” still lets replies back to conversations the other side started — so a laptop can open a camera, but a camera can’t open anything.

From \ ToTrustedIoTGuestCamerasShackInternet
Trusted—AllowDropAllowAllowAllow
IoTDrop—DropDropDropAllow
GuestDropDrop—DropDropAllow
CamerasDropDropDrop—DropDrop
ShackDropDropDropDrop—Allow
Cameras get no internet at all. They record to the recorder on their own VLAN, and can’t phone home to anyone.

Fault-finding: climb the ladder

Start at rung 1. The first rung that fails tells you where the problem is.

  • 1link lightNothing? Cable, port or power.
  • 2ipconfig / ip addr169.254 or the wrong subnet? DHCP, or the wrong switch port or VLAN.
  • 3ping the gatewayFails? VLAN, mask or cable.
  • 4ping 8.8.8.8Fails? NAT, the ISP, or a firewall rule.
  • 5ping a nameFails when rung 4 works? DNS.
Part 4

Wi-Fi

26 minutes · bands, channels, coverage, security, SSIDs onto VLANs
▶ Watch Part 4

Key ideas

  • Wi-Fi is Ethernet over a shared, half-duplex radio channel. Airtime, not megabits, is the scarce resource — and one slow old device drags everyone down.
  • The signal bars only tell you how well your device hears the access point, not how well the AP hears you. It’s the talk-in problem every repeater user knows.
  • Several modest access points, wired back and powered by PoE, beat one loud one — and beat plug-in extenders every time.
  • Each Wi-Fi name maps onto a VLAN from Part 3. Three names cover almost every house: Home, Things, Guest.

Quick reference

SettingRecommendation
2.4 GHz channels1, 6 or 11 only — anything else overlaps two of them
5 GHz width80 MHz at home. Random one-minute drops? Suspect a DFS radar hit
Target signal−67 dBm or better in every room that matters
Transmit powerModerate, not maximum — loud APs make lopsided links and sticky clients
SecurityWPA2/WPA3 mixed, long passphrase (four random words), WPS off
Guest networkOwn VLAN, internet only, client isolation on
Casting to the TV on the IoT networkTurn on the router’s mDNS reflector, and allow Trusted → IoT in the firewall
For the shack: 2.4 GHz Wi-Fi sits inside the 13 cm band, and channel 1 lands right on the QO-100 uplink. If you run QO-100 DATV, keep your own Wi-Fi off channel 1 and the access point away from the dish.

En français — Introduction aux réseaux Internet et au routage

Une série en quatre parties (environ 1 h 40 au total), diffusée sur GB3OO, pour passer de « c’est quoi une adresse MAC ? » à la conception de votre propre réseau domestique segmenté.

  • Partie 1 — Le câble : Ethernet, adresses MAC, commutateurs, et pourquoi un commutateur ne bloque pas les diffusions.
  • Partie 2 — L’adresse : IPv4 en binaire, masques de sous-réseau, ARP, passerelle par défaut, routage et NAT.
  • Partie 3 — Le réseau : DHCP, DNS, ports, pare-feu, VLAN, et un plan d’adressage complet.
  • Partie 4 — Le Wi-Fi : bandes, canaux, couverture, sécurité, et un nom de réseau par VLAN.

Les diapositives sont en anglais, mais les tableaux et l’exercice de sous-réseaux se passent de traduction : les chiffres sont les mêmes dans toutes les langues ! Un conseil de radioamateur : si vous émettez vers QO-100 en DATV, éloignez votre Wi-Fi du canal 1.

Questions et remarques : admin@gb3oo.co.uk — 73 de G8YTZ

Questions, corrections or ideas for another course: admin@gb3oo.co.uk · 73 de G8YTZ