Network Fundamentals
Network fundamentals establish the vocabulary and models used throughout the CCNA 200-301 exam. This domain covers the roles of network devices, the OSI and TCP/IP models, physical media, and both IPv4 and IPv6 addressing. Subnetting is the single most tested skill in this section, so this chapter works through address math step by step. Master the address types and block-size method here and every later topic — routing, ACLs, VLANs — becomes much easier.
OSI and TCP/IP Models
The OSI model divides communication into seven layers: Physical (1), Data Link (2), Network (3), Transport (4), Session (5), Presentation (6), and Application (7). A common memory aid is "Please Do Not Throw Sausage Pizza Away." Each layer has one job. Layer 1 moves raw bits over copper, fiber, or radio. Layer 2 groups bits into frames and uses 48-bit MAC addresses to deliver them across a single link; switches live here. Layer 3 wraps data in packets and uses IPv4 or IPv6 logical addresses to route between networks; routers live here. Layer 4 provides end-to-end transport with TCP or UDP and uses port numbers to identify applications. Layers 5 to 7 handle sessions, data formatting, and the actual application data. The TCP/IP model condenses these into four layers: Network Access (OSI 1-2), Internet (OSI 3), Transport (OSI 4), and Application (OSI 5-7). On the 200-301 exam you should map protocols to layers quickly: Ethernet and ARP at Layer 2, IP and ICMP at Layer 3, TCP and UDP at Layer 4, and HTTP, DNS, and DHCP at the Application layer. The most important concept to internalize is encapsulation. As data moves down the stack on the sending host, each layer adds its own header (and Layer 2 also adds a trailer with a frame check sequence). The result is called by a different name at each layer — the "PDU" (protocol data unit): segment at Layer 4, packet at Layer 3, frame at Layer 2, and bits at Layer 1. On the receiving host the process reverses in de-encapsulation, stripping each header as it moves up. Understanding which addresses change and which stay the same during this journey is the foundation of troubleshooting: the source and destination IP addresses stay constant end to end, while the source and destination MAC addresses are rewritten at every router hop.
Network Components and Media
A network is built from devices with distinct roles. Routers connect different IP networks and forward packets between them at Layer 3, applying the routing table to choose a path. Switches forward frames within a LAN at Layer 2, learning MAC addresses to avoid needless flooding. Endpoints (PCs, phones, servers) originate and consume traffic. Access points bridge Wi-Fi clients onto the wired LAN. Firewalls enforce security policy between zones, and wireless LAN controllers (WLCs) centrally manage lightweight access points. PoE (Power over Ethernet) lets a switch deliver power and data over one cable to phones, APs, and cameras. Physical media determine speed and distance. Copper twisted-pair (Cat5e, Cat6) is cheap and common but is limited to about 100 meters per run and is vulnerable to electromagnetic interference. Fiber-optic cable carries light instead of electricity, supporting far longer distances and higher speeds with immunity to EMI; single-mode fiber reaches the longest distances, while multimode fiber is used for shorter campus runs. Coax survives in some cable-modem and older deployments. Copper Ethernet uses specific pinouts. A straight-through cable connects unlike devices — for example a PC to a switch or a switch to a router. A crossover cable connects like devices — switch to switch or PC to PC — though modern ports with Auto-MDIX detect and adjust automatically. A rollover (console) cable connects a PC's serial or USB port to a router or switch console port for out-of-band management. Two duplex settings matter. Full duplex allows simultaneous send and receive with no collisions and is standard on switched links. Half duplex shares the medium and can suffer collisions. A duplex mismatch — one side full, the other half — is a classic fault that produces late collisions, CRC errors, and slow throughput while the link still shows "up." Always verify speed and duplex match on both ends of a link before blaming higher layers.
IPv4 Addressing and Subnetting
An IPv4 address is 32 bits, written as four dotted-decimal octets (each 0-255). A subnet mask splits the address into a network portion (the 1 bits) and a host portion (the 0 bits). CIDR notation writes the mask as a prefix length: /24 equals 255.255.255.0. In any subnet, the first address (all host bits 0) is the network ID and the last address (all host bits 1) is the broadcast; usable host addresses are the ones in between. Usable hosts = 2^(host bits) − 2. The fastest exam technique is the block-size (magic-number) method. The block size in the "interesting" octet = 256 − mask value for that octet. Subnets increment by that block size, and each subnet's broadcast is the next network minus one. Worked example 1: 172.16.45.10 /20. A /20 mask is 255.255.240.0, so the interesting octet is the third and block size = 256 − 240 = 16. Third-octet subnets are 0, 16, 32, 48… The value 45 falls in the 32 block, so the network is 172.16.32.0, the broadcast is 172.16.47.255, and the usable range is 172.16.32.1 through 172.16.47.254 (4,094 hosts). Worked example 2: 192.168.1.100 /26. A /26 mask is 255.255.255.192, block size = 256 − 192 = 64. Subnets are .0, .64, .128, .192. Host .100 sits in the .64 subnet: network 192.168.1.64, broadcast 192.168.1.127, usable .65 to .126 (62 hosts). VLSM (Variable Length Subnet Masking) sizes each subnet to its need instead of wasting addresses. To serve a link with exactly two hosts (a router-to-router point-to-point), use a /30 (four addresses, two usable); a /31 is a special case that allows two usable addresses on point-to-point links. Always allocate the largest subnets first when subnetting a block with VLSM. Remember the private (RFC 1918) ranges: 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16, which are not routable on the public Internet and must be translated by NAT.
IPv6 Addressing
IPv6 uses 128-bit addresses written as eight groups (hextets) of four hex digits separated by colons, e.g. 2001:0db8:0000:0000:0000:ff00:0042:8329. Two compression rules shorten them: drop leading zeros within a hextet, and replace one single run of all-zero hextets with a double colon (::). The example compresses to 2001:db8::ff00:42:8329. The :: may appear only once in an address, because otherwise the length of the zero run would be ambiguous. Key address types: Global unicast (2000::/3) are the public, routable addresses. Link-local (FE80::/10) are auto-generated on every IPv6 interface and are valid only on the local link — routers never forward them; they are used for neighbor discovery and as the next hop in routing. Unique local (FC00::/7, in practice FD00::/8) are the private equivalent of RFC 1918. Multicast (FF00::/8) replaces IPv4 broadcast for one-to-many delivery; important groups include FF02::1 (all nodes) and FF02::2 (all routers). IPv6 has no broadcast address. Hosts can obtain addresses several ways. SLAAC (Stateless Address Autoconfiguration) lets a host build its own global address from the /64 prefix advertised in a Router Advertisement (RA), generating the interface ID with EUI-64 (which inserts FFFE in the middle of the MAC and flips the seventh bit) or a random value. Stateful DHCPv6 hands out full addresses from a server, while stateless DHCPv6 supplies extra options such as DNS while SLAAC provides the address. Neighbor Discovery Protocol (NDP) replaces ARP, using ICMPv6 messages: Router Solicitation/Advertisement and Neighbor Solicitation/Advertisement, plus Duplicate Address Detection. Dual stack, in which a device runs IPv4 and IPv6 simultaneously, is the most common migration approach and is the model assumed on the 200-301 exam. Note that a standard IPv6 prefix for a LAN is /64, which is required for SLAAC and EUI-64 to work correctly.
Transport Layer Protocols
The Transport layer (OSI Layer 4) delivers data between applications and offers two very different protocols. TCP (Transmission Control Protocol) is connection-oriented and reliable. Before sending data it performs the three-way handshake: SYN, SYN-ACK, ACK. It then numbers every byte with sequence numbers, acknowledges received data, retransmits anything lost, reorders segments that arrive out of order, and uses a sliding window for flow control so a fast sender does not overwhelm a slow receiver. This overhead makes TCP ideal for file transfer, email, and web pages where completeness matters more than speed. UDP (User Datagram Protocol) is connectionless and best-effort. It has an 8-byte header, no handshake, no acknowledgments, no retransmission, and no ordering. That low latency makes it the right choice for real-time voice and video, DNS lookups, and other traffic where a late packet is worthless and speed is everything. If reliability is needed for UDP-based apps, the application layer must provide it. Both protocols use 16-bit port numbers to identify the application on each host, forming a socket when combined with the IP address. Ports fall into ranges: well-known (0-1023), registered (1024-49151), and dynamic/ephemeral (49152-65535) used for client source ports. Memorize common well-known ports for the exam: FTP 20/21, SSH 22, Telnet 23, DNS 53 (TCP and UDP), HTTP 80, HTTPS 443, SMTP 25, and DHCP 67/68 (UDP). SNMP uses 161/162 and Syslog uses 514, both over UDP. A useful troubleshooting mindset: if a connection "hangs" or half-opens, think TCP handshake and windowing; if data simply disappears with no error, think UDP best-effort. Recognizing whether an application rides on TCP or UDP tells you what behavior to expect and where to look when something breaks.
Keep going: the full Cisco CCNA 200-301 guide covers every section of the exam. Cisco CCNA 200-301 — Complete Study Guide (2026) — PDF + EPUB, $14.99 · 14-day refund →

Practice stays free. The full Cisco CCNA 200-301 study guide is the material itself, taught start to finish — a downloadable PDF + EPUB you keep.