sistemi-e-reti VLAN subnetting CIDR DHCP DNS NAT exam

Local Network Design — Part 2: Bandwidth, VLANs, IP and Services

Reference guide for the Networks & Systems written exam — part two. Covers bandwidth sizing, VLAN segmentation, IP addressing and core network services.


4. Bandwidth Sizing and ISP Connectivity

Throughput Calculation

Sizing the Internet (WAN) bandwidth is not simply the sum of all network card maximum speeds, but a statistical estimate based on real-world usage. The general formula is:

$$B_{tot} = (N \cdot B_{user}) \cdot C$$

Where:

  • N: Total number of users or devices.
  • B_user: Estimated average bandwidth per user (e.g. 2 Mbps for browsing, 0.1 Mbps for VoIP, 10 Mbps for 4K streaming).
  • C (Concurrency Factor): A value between 0 and 1 indicating the percentage of users simultaneously active at peak time. In a standard office it is often 0.3–0.5; in a call centre it can reach 0.8–1.0.

Worked Example — Sizing for a School

SegmentDevicesEstimated bandwidth/userSubtotal
Computer lab (cloud + video)30 PCs4 Mbps120 Mbps
Administrative offices10 PCs1 Mbps10 Mbps
Student Wi-Fi100 smartphones0.5 Mbps50 Mbps
Gross total180 Mbps

With concurrency factor C = 0.4:

B_total = 180 Mbps × 0.4 = 72 Mbps

Commercial choice: Since at least 72 Mbps are needed, a VDSL line (often limited on upload) is discarded in favour of a FTTH 1 Gbps connection or a dedicated FTTO line at 100 Mbps symmetrical guaranteed (MCR).

Failover and High Availability

For businesses, a redundancy strategy is implemented (e.g. primary FTTH line and FWA backup) via Floating Static Routes and link-state monitoring (IP SLA Tracking in Cisco environments). Upon failover, QoS (Quality of Service) is activated to prioritise critical traffic such as VoIP.


5. VLANs and Network Segmentation

VLANs (Virtual LANs) allow a single physical network to be logically split into multiple isolated networks, improving security and reducing broadcast domains. They are defined by the IEEE 802.1Q standard.

Why Use VLANs

Without VLANs, all devices share the same broadcast domain: a single broadcast packet (such as a DHCP request) is sent to every host on the network, wasting bandwidth and creating security risks.

With VLANs:

  • Traffic from different departments (e.g. Administration, Production, Guest) is isolated;
  • the attack surface is reduced: a compromised host in one VLAN cannot communicate directly with hosts in another;
  • management is centralised on the switches, without changing the physical cabling.

Access and Trunk Ports

TypeDescriptionTypical Use
AccessBelongs to a single VLAN. The 802.1Q tag is added/removed by the switch.End devices: PCs, printers, IP phones.
TrunkCarries tagged traffic for multiple VLANs. The Ethernet frame includes a 4-byte field with the VLAN ID (VID, 1 to 4094).Switch-to-switch and switch-to-router links.

Inter-VLAN Routing: Router-on-a-Stick

Hosts in different VLANs cannot communicate directly: a Layer 3 device is required. The most common solution in classroom environments is Router-on-a-Stick:

  1. The router is connected to the switch with a single physical cable on a trunk port.
  2. Virtual sub-interfaces are configured on the router interface (e.g. Gi0/0.10, Gi0/0.20), one per VLAN.
  3. Each sub-interface has an IP address acting as the default gateway for its VLAN.
  4. Inter-VLAN routing is handled in software by the router.

In enterprise environments, Layer 3 switches (with built-in routing capabilities) are used instead, handling Inter-VLAN Routing in hardware with far superior performance.

Exam tip: In a project with multiple departments, always assign a separate VLAN and IP subnet to each department. Don’t forget the Management VLAN (e.g. VLAN 99) for administrative access to the switches, kept separate from user traffic.


6. IP Addressing and Subnetting

Subnetting is the technique of dividing an IP address block into smaller subnets, optimising the use of the address space. The notation used is CIDR (Classless Inter-Domain Routing), which expresses the mask as /n where n is the number of bits reserved for the network portion.

Core Formulas

Given a network prefix /n:

  • Usable hosts: 2^(32−n) − 2 (the network and broadcast addresses are subtracted)
  • Block size (subnet increment): 2^(32−n)
  • Broadcast address: last address in the block (all host bits set to 1)
  • Gateway: conventionally the first or last usable host address

Quick Reference Table

PrefixMaskUsable HostsBlock SizeTypical Use
/24255.255.255.0254256Medium-sized LAN
/25255.255.255.128126128Small LAN, /24 subdivision
/26255.255.255.1926264Department with a few dozen hosts
/27255.255.255.2243032Small department or server farm
/28255.255.255.2401416Segment with very few devices
/30255.255.255.25224Point-to-point link (WAN)

Practical IP Plan Example

Scenario: a company has the block 192.168.10.0/24 and needs to accommodate three departments and a DMZ.

VLANDepartmentNetworkMaskGatewayMax Hosts
10Administration192.168.10.0/26.162
20Production192.168.10.64/26.6562
30Guest Wi-Fi192.168.10.128/26.12962
40DMZ (Servers)192.168.10.192/28.19314
99Management192.168.10.208/28.20914

The five subnets do not overlap and together consume only 240 out of the 256 addresses available in the original /24.

Exam tip: Always state explicitly: network address, CIDR mask, broadcast address, gateway and host range. Use a table — it is clear, fast to fill in and easy for examiners to assess.


7. Network Services: DHCP, DNS and NAT

DHCP — Automatic Address Assignment

The Dynamic Host Configuration Protocol (DHCP) automatically assigns clients: an IP address, subnet mask, default gateway and DNS server. It works through a 4-message exchange (acronym DORA):

  1. Discover: the client broadcasts looking for a DHCP server.
  2. Offer: the server responds offering an available address.
  3. Request: the client formally accepts the offer.
  4. Acknowledge: the server confirms the assignment and communicates the lease duration.

In networks with multiple VLANs, separate DHCP pools are configured (one per VLAN). If the DHCP server is centralised, switches must be configured as DHCP Relay Agents (ip helper-address) to forward broadcast requests across routers.

DNS — Name Resolution

The Domain Name System (DNS) translates domain names (e.g. www.school.edu) into IP addresses. It operates on port UDP 53 (or TCP for zone transfers). In an enterprise network:

  • The Internal DNS resolves names of local resources (servers, network printers).
  • The DNS Forwarder redirects external requests to public servers (e.g. Google’s 8.8.8.8 or Cloudflare’s 1.1.1.1).
  • DNS Zones divide the namespace: the forward zone maps names→IP, the reverse zone maps IP→names (PTR records).

NAT and PAT — Address Translation

Network Address Translation (NAT) allows all hosts on a private network to access the Internet by sharing a single public IP address assigned by the ISP.

  • PAT (Port Address Translation), also called NAT Overload or Masquerading: the most common form. The router distinguishes sessions from different users by assigning different source ports (e.g. PC1 → port 10234, PC2 → port 10235). Transparent to users.
  • Static NAT (DNAT): an internal private address (e.g. a web server in the DMZ at 192.168.10.194) is always mapped to the same public address or port. Allows external clients to reach internal servers. Example: traffic arriving at public_IP:443 is redirected to 192.168.10.194:443.

8. Technical Report Structure

The technical report summarises design choices. In an exam context it must be clear, concise and well-structured. Essential sections:

  • Requirements Analysis: Brief description of the scenario, structural constraints (historic building, multiple floors) and user needs (number of hosts, required services).
  • Physical and Logical Topology:
    • Physical: Cabinet placement, fibre/copper backbones, AP positions.
    • Logical: Block diagram with Router, Firewall, DMZ and Switches.
  • IP Addressing Plan: Table with subnets (Subnetting), masks (CIDR), gateways and associated VLANs.
  • Equipment Selection: Hardware list (Router, Switch, AP) with technical justification (e.g. “PoE+ Switch to power the APs”).
  • Service Configuration: Notes on DHCP, DNS, NAT/PAT and Routing (Static or Dynamic).
  • Security: Adopted strategies (Firewall, ACL, VPN for remote access, VLAN segmentation).

Exam tip: Don’t just produce a shopping list. Always write the “why” behind a choice. Example: “Multimode optical fibre was chosen for the vertical backbone because the distance between floors is less than 300 m and it guarantees 10 Gbps.”