Chapter 4 of 610% of exam

IP Services

IP services are the supporting protocols that make a network usable and manageable. This domain covers NAT and PAT for conserving public addresses, DHCP and DNS for automatic host configuration and name resolution, NTP for time synchronization, and the operational tools SNMP, Syslog, and QoS. It also covers secure device access with SSH. These features appear constantly in real networks and reliably on the 200-301 exam.

Network Address Translation

NAT (Network Address Translation) lets many hosts using private RFC 1918 addresses share public IPv4 space, which is exhausted. A NAT router rewrites the source (and sometimes destination) IP as packets cross between the inside and outside, and keeps a translation table so return traffic is delivered to the right internal host. Cisco terminology defines four address types: inside local (private address on the LAN), inside global (the public address the LAN host is translated to), outside global (the real public address of an Internet host), and outside local. There are three flavors. Static NAT maps one inside address to one public address permanently — useful for a server that must be reachable from the Internet. Dynamic NAT maps inside addresses to public addresses drawn from a pool, first come first served, but still one-to-one at a time, so it can run out. PAT (Port Address Translation), also called NAT overload, is by far the most common: it maps many inside hosts to a single public IP by also translating the source port, using the unique port number to tell the conversations apart in the table. A typical home or branch router uses PAT so an entire site shares one public address. Configuration marks each interface as "ip nat inside" or "ip nat outside," defines what to translate (usually an ACL of inside sources), and applies the translation. A common PAT line is "ip nat inside source list 1 interface Gig0/1 overload," where the "overload" keyword enables PAT. Verify with "show ip nat translations" to see active mappings and "show ip nat statistics." NAT conserves addresses and hides internal structure, but it also breaks end-to-end addressing and can complicate protocols that embed IPs in their payload. Remember that NAT is an IPv4 workaround; IPv6's vast address space is designed to remove the need for it. On the exam, the key discriminators are static vs dynamic vs PAT and identifying inside local vs inside global in a translation table.

Static NAT = permanent one-to-one; dynamic NAT = pool, one-to-one at a time; PAT/overload = many-to-one via port numbers.
PAT is the common form (whole site shares one public IP); enabled with the 'overload' keyword.
Address types: inside local (private LAN) vs inside global (translated public).
Mark interfaces ip nat inside / ip nat outside; verify with show ip nat translations.
NAT is an IPv4 address-conservation workaround; IPv6 largely removes the need.

DHCP and DNS

DHCP (Dynamic Host Configuration Protocol) automatically hands hosts an IP address, subnet mask, default gateway, DNS server, and often more, eliminating manual configuration. The exchange is DORA: Discover (client broadcasts looking for a server), Offer (server proposes an address), Request (client formally asks for the offered address), and Acknowledge (server confirms and records the lease). DHCP uses UDP ports 67 (server) and 68 (client), and addresses are leased for a limited time and then renewed. Because Discover is a broadcast and broadcasts do not cross routers, a client on a different subnet than the server needs a DHCP relay. Configure "ip helper-address <server-IP>" on the router interface facing the clients; the router then forwards the DHCP broadcasts as unicast to the central server, inserting the subnet information so the server picks the right pool. A Cisco router can also act as the DHCP server itself with an "ip dhcp pool" and an "ip dhcp excluded-address" range for statics. DNS (Domain Name System) resolves human-friendly names such as www.example.com into IP addresses using a distributed hierarchy of servers and record types — A records for IPv4, AAAA for IPv6, CNAME aliases, MX for mail, and PTR for reverse lookups. DNS uses UDP 53 for normal queries (and TCP 53 for zone transfers and large responses). Without DNS, users would have to remember raw IP addresses. Common failure signatures help on the exam and in practice: a host with a 169.254.x.x APIPA address never got a DHCP reply (relay missing or server down); a host that can ping IP addresses but not names has a DNS problem; and duplicate-address complaints often mean a static host sits inside the DHCP pool without being excluded. Verify with "show ip dhcp binding" on a router acting as server, and use ipconfig / ifconfig plus nslookup on the client to isolate DHCP versus DNS issues.

DHCP process = DORA (Discover, Offer, Request, Acknowledge) over UDP 67/68.
Cross-subnet DHCP needs ip helper-address on the client-side router interface (DHCP relay).
DNS resolves names to IPs on UDP 53; A=IPv4, AAAA=IPv6, CNAME=alias, MX=mail, PTR=reverse.
A 169.254.x.x (APIPA) address means no DHCP reply was received.
Can ping IPs but not names = DNS problem, not connectivity.

Time Synchronization with NTP

NTP (Network Time Protocol) keeps every device's clock aligned to a common, accurate reference. This matters more than it sounds: log timestamps only correlate across devices if their clocks agree, certificates and Kerberos depend on time, and troubleshooting a fault across ten routers is nearly impossible if each has a different time. NTP uses UDP port 123. NTP organizes sources into a stratum hierarchy that measures distance from the authoritative clock. Stratum 0 is a reference clock such as an atomic or GPS clock; a server directly attached to it is stratum 1; a device syncing to a stratum 1 becomes stratum 2, and so on, up to stratum 15 (stratum 16 means unsynchronized). Lower stratum is more authoritative, and devices prefer the lowest reachable stratum. On a Cisco router you point to a time source with "ntp server <ip>," and the router can simultaneously serve time to other devices, so a common design has border routers sync to an Internet or GPS source and internal devices sync to those routers. You can also set the local clock manually, but that does not scale. For accuracy across a campus, choose a small number of trusted internal NTP servers and have everything else point at them. Security-conscious deployments use NTP authentication (keys) so a device only accepts time from trusted servers, preventing an attacker from skewing clocks to break logging or certificates. Configure with "ntp authenticate," an "ntp authentication-key," and "ntp trusted-key." Verify NTP with "show ntp status" (look for "Clock is synchronized" and the stratum) and "show ntp associations" (the "*" marks the currently selected master). Always set the time zone and daylight-saving rules with "clock timezone" so displayed times make sense locally even though NTP itself works in UTC. Accurate, synchronized time is a quiet prerequisite for almost every other operational and security feature.

NTP synchronizes clocks over UDP 123 — essential for correlated logs, certificates, and troubleshooting.
Stratum measures distance from the reference clock: stratum 1 is closest, lower is better (16 = unsynchronized).
'ntp server <ip>' sets a source; a router can be both client and server.
NTP authentication (keys) prevents accepting time from untrusted sources.
Verify with show ntp status (synchronized?) and show ntp associations (* = selected master).

Network Management: SNMP, Syslog, QoS, and SSH

SNMP (Simple Network Management Protocol) lets a Network Management System monitor and manage devices. The manager polls an agent's values (organized in a MIB and identified by OIDs) with GET requests, can change values with SET, and the agent can send unsolicited traps or informs to report events like an interface going down. SNMP uses UDP 161 (queries) and 162 (traps). Versions matter for the exam: v1 and v2c authenticate only with a plaintext community string, while v3 adds authentication and encryption and is the secure choice. Syslog centralizes log messages so you can see what devices are doing over time. Messages carry a severity level from 0 to 7 — 0 Emergency, 1 Alert, 2 Critical, 3 Error, 4 Warning, 5 Notification, 6 Informational, 7 Debugging (mnemonic: "Every Awesome Cisco Engineer Will Need Ice-cream Daily"). Lower numbers are more severe, and configuring a logging level captures that level and everything more severe. Send logs off-box with "logging host <ip>"; Syslog uses UDP 514. Correct timestamps from NTP make these logs far more useful. QoS (Quality of Service) manages congestion so latency-sensitive traffic is not starved by bulk data. Traffic is classified and marked — commonly with DSCP values in the IP header, such as EF (Expedited Forwarding) for voice — then queued and scheduled so voice and video get priority, while policing or shaping limits other flows. Voice needs low latency, low jitter, and low loss, so it is typically placed in a priority queue. Marking should be done as close to the source as possible and trusted only at controlled boundaries. SSH secures device management. Unlike Telnet, which sends usernames, passwords, and commands in clear text, SSH encrypts the whole session, so it is the required method for CLI access. Enable it by setting a hostname and domain name, generating an RSA key ("crypto key generate rsa" with at least a 1024-bit modulus), creating a local user, and applying "transport input ssh" plus "login local" on the VTY lines. SSHv2 is preferred.

SNMP monitors devices over UDP 161/162; use v3 for authentication and encryption (v1/v2c use plaintext community strings).
Syslog severities 0-7: 0 Emergency (most severe) to 7 Debugging; Syslog uses UDP 514.
QoS classifies/marks (e.g. DSCP EF for voice) then queues so voice/video get priority during congestion.
Voice requires low latency, low jitter, low loss — typically a priority queue.
Use SSH (encrypted), never Telnet (cleartext); requires hostname, domain name, and an RSA key.

Keep going: the full Cisco CCNA 200-301 guide covers every section of the exam. Cisco CCNA 200-301 — Complete Study Guide (2026) — PDF + EPUB, $14.99 · 14-day refund →

Studying in order?

Practice stays free. The full Cisco CCNA 200-301 study guide is the material itself, taught start to finish — a downloadable PDF + EPUB you keep.

Get the book — $14.99
Report