Skip to main content
AD Academy

Protocols and key terms

Every protocol in short: what it does and a real-life example.

CCNA

DNS

53 / UDP,TCPApplication

What it isName service: turns a name (dc01.corp.local) into an IP address. Without healthy DNS, Active Directory simply does not work.

Real-life exampleA PC looks up the SRV record _ldap._tcp.dc._msdcs.corp.local to find a Domain Controller before logging in.

Troubleshooting

Common symptomsName does not resolve / domain join fails / "DNS name does not exist". Check the client points at the DC as DNS server (not 8.8.8.8) and that SRV records exist.

Check commands
  • nslookup dc01.corp.local
  • nslookup -type=SRV _ldap._tcp.dc._msdcs.corp.local
  • ipconfig /flushdns | ipconfig /registerdns
  • dcdiag /test:DNS
  • Router# show ip name-server
Go to the topic

DHCP

67, 68 / UDPApplication

What it isAutomatically hands out IP addresses on the network (the DORA process: Discover, Offer, Request, Ack).

Real-life exampleA laptop joins the office network and within a second gets an IP, gateway and DNS server with zero manual setup.

Troubleshooting

Common symptomsClient gets 169.254.x.x (APIPA) — no DHCP answer. Causes: exhausted scope, server in another VLAN without ip helper-address, or a rogue DHCP.

Check commands
  • ipconfig /all | ipconfig /release | ipconfig /renew
  • Get-DhcpServerv4Scope | Get-DhcpServerv4Lease -ScopeId 10.0.10.0
  • Router# show ip dhcp binding
  • Router# show ip dhcp pool
  • Router# debug ip dhcp server events
Go to the topic

HTTP / HTTPS

80 / 443 / TCPWeb

What it isThe browser protocol. HTTPS adds TLS encryption so nobody in the middle can read the content.

Real-life exampleYou open the company portal and see the padlock in the address bar — the traffic is HTTPS-encrypted.

Troubleshooting

Common symptoms404 = wrong path on the server; 403 = permissions; 502/504 = backend not answering; "Connection refused" = service down or port blocked.

Check commands
  • curl -I https://intranet.corp.local
  • Test-NetConnection web01 -Port 443
  • nslookup intranet.corp.local
Go to the diagram

TLS / SSL

נלווה לפרוטוקולים אחריםSecurity

What it isThe encryption layer that wraps other protocols (HTTPS, LDAPS, SMTPS) and proves the server's identity with a certificate.

Real-life exampleA server presents a certificate issued by the corporate CA and the client confirms: this really is the right server.

Troubleshooting

Common symptomsBrowser warning: expired certificate, name mismatch (CN/SAN), or CA not trusted by the client. A wrong clock also yields "certificate not yet valid".

Check commands
  • openssl s_client -connect web01:443
  • curl -vI https://web01
  • certutil -verify -urlfetch cert.cer

NTP

123 / UDPInfrastructure

What it isClock synchronisation. In AD, a gap of more than 5 minutes between a client and a DC breaks Kerberos entirely.

Real-life exampleA user can't log in after a holiday — the PC's clock drifted; syncing time fixes it.

Troubleshooting

Common symptomsClock drift breaks Kerberos and confuses logs. Sign: "unsynchronized" in the output, or stratum 16 on the router.

Check commands
  • w32tm /query /status | w32tm /resync
  • w32tm /monitor
  • Router# show ntp status | show ntp associations
  • Router# debug ntp packets
Go to the topic

SNMP

161, 162 / UDPMonitoring

What it isNetwork device monitoring: poll a switch or router for status, or receive an alert (Trap) from it.

Real-life exampleA monitoring system reports a switch port went down — that alert arrived as an SNMP Trap.

Troubleshooting

Common symptomsMonitoring shows no data: wrong community string, version mismatch (v2c vs v3), or an ACL blocking the monitoring server.

Check commands
  • snmpwalk -v2c -c public 10.0.0.1
  • Router# show snmp
  • Router# show snmp community
Go to the topic

Syslog

514 / UDPMonitoring

What it isA standard for shipping logs from devices to a central server / SIEM.

Real-life exampleAll switches send logs to one server, so you can see failed login attempts in a single place.

Troubleshooting

Common symptomsNo messages on the server: logging host not set, severity level too high, or wrong time (without NTP the logs are useless).

Check commands
  • Router# show logging
  • Router# logging host 10.0.20.50
  • Router# debug ip packet (בזהירות!)
  • tail -f /var/log/syslog
Go to the topic

SMTP

25 / 587 / TCPMail

What it isThe protocol for sending email between servers and from client to server.

Real-life exampleA monitoring system emails an alert to the IT team — that was SMTP.

Troubleshooting

Common symptomsMail stuck in queue: port 25 blocked by the ISP, wrong MX record, or the server is blacklisted / relay denied.

Check commands
  • Test-NetConnection mail01 -Port 25
  • nslookup -type=MX corp.com
  • telnet mail01 25

IMAP / POP3

143/993, 110/995Mail

What it isReceiving mail: IMAP keeps messages on the server and syncs devices, POP3 downloads and deletes.

Real-life exampleThe same email shows on phone and PC — that's IMAP. It vanishes after download — that's POP3.

Troubleshooting

Common symptomsClient cannot fetch mail: wrong port/encryption (993 vs 143), bad password, or a full mailbox.

Check commands
  • Test-NetConnection mail01 -Port 993
  • openssl s_client -connect mail01:993

FTP / SFTP

21 / 22File transfer

What it isFile transfer. FTP sends username and password in clear text — always prefer SFTP over SSH.

Real-life exampleYou upload a backup to a remote server via SFTP so nobody on the network sees the password.

Troubleshooting

Common symptomsLogin works but the file listing hangs — a passive/active mode issue with the firewall. "Permission denied" = folder permissions.

Check commands
  • ftp 10.0.0.5 | sftp user@10.0.0.5
  • Test-NetConnection 10.0.0.5 -Port 21
  • openssl s_client -connect host:990

SSH

22 / TCPRemote access

What it isEncrypted command-line access to servers and network gear (Linux, switches, routers).

Real-life exampleAn admin connects to a switch with ssh admin@10.0.0.1 and configures a VLAN remotely.

Troubleshooting

Common symptoms"Connection refused" = SSH disabled or no RSA key. "No matching key exchange" = version mismatch. vty lines need transport input ssh.

Check commands
  • ssh -v admin@10.0.0.1
  • Switch# show ip ssh | show users
  • Switch# debug ip ssh
  • Switch(config)# crypto key generate rsa modulus 2048
Go to the topic

Telnet

23 / TCPRemote access

What it isAn ancient, unencrypted ancestor of SSH. Everything, including the password, travels in clear text — disable it.

Real-life exampleAnyone sniffing the network sees the switch admin password in plain view — that's why SSH replaced it.

Troubleshooting

Common symptoms"Password required, but none set" = no vty password. Remember Telnet is clear text — lab use only.

Check commands
  • telnet 10.0.0.1
  • Switch# show line | show running-config | section line vty
Go to the topic

ARP

שכבה 2Networking

What it isFinds the MAC address that belongs to an IP address on the same local network.

Real-life exampleYour PC asks "who has 192.168.1.1?" and the router replies with its MAC. An attacker answering instead is ARP spoofing.

Troubleshooting

Common symptomsDuplicate IP or conflicting ARP replies = ARP poisoning (MitM). MAC missing = port down or wrong VLAN.

Check commands
  • arp -a | arp -d *
  • Router# show ip arp
  • Switch# show mac address-table
  • Router# debug arp
Go to the diagram

ICMP

שכבה 3Networking

What it isThe network's service-message protocol — ping and traceroute are built on it.

Real-life exampleping dc01 shows whether the server is alive and how many milliseconds it takes to answer.

Troubleshooting

Common symptoms"Request timed out" does not always mean the host is dead — a firewall often blocks ICMP. "Destination host unreachable" = missing route/gateway.

Check commands
  • ping -t 8.8.8.8 | ping -l 1472 -f (MTU)
  • Router# show ip route
  • Router# debug ip icmp
Go to the diagram

TCP

שכבה 4Transport

What it isReliable connection: a 3-way handshake, then confirmation that every packet arrived in order. Slower but safe.

Real-life exampleDownloading a file — you can't lose a single byte, so TCP is used.

Troubleshooting

Common symptoms"Connection refused" = nothing listening on the port. Hang until timeout = firewall silently dropping. Many TIME_WAIT = the app leaks connections.

Check commands
  • netstat -ano | findstr :445
  • Test-NetConnection srv01 -Port 445
  • Get-NetTCPConnection -State Established
Go to the diagram

UDP

שכבה 4Transport

What it isFast, fire-and-forget delivery with no acknowledgements. Quick, but packets can be lost.

Real-life exampleA video call: a glitchy frame beats a one-second delay — hence UDP.

Troubleshooting

Common symptomsThere is no error — just no answer. Check on the server whether the packet arrived at all; loss directly hurts DNS and VoIP.

Check commands
  • netstat -ano -p udp
  • nslookup (בדיקת DNS/UDP)
  • Router# debug ip udp
Go to the diagram

VLAN (802.1Q)

שכבה 2Networking

What it isLogically splits one physical switch into several isolated networks.

Real-life exampleAccounting sits in VLAN 10 and guests in VLAN 20 — a guest can't reach the finance server.

Troubleshooting

Common symptomsPC gets no IP or cannot see the network: port in the wrong VLAN, VLAN missing from the trunk allowed list, or mismatched native VLAN.

Check commands
  • Switch# show vlan brief
  • Switch# show interfaces trunk
  • Switch# show interfaces gi0/1 switchport
  • Switch# show interfaces status
Go to the diagram

STP

שכבה 2Networking

What it isPrevents switching loops by temporarily blocking redundant links.

Real-life exampleTwo cables were accidentally patched between the same switches — STP blocks one and the network survives.

Troubleshooting

Common symptomsNetwork dead or very slow with blinking ports = a loop or the wrong Root Bridge elected. A Blocking port is usually intentional.

Check commands
  • Switch# show spanning-tree
  • Switch# show spanning-tree root
  • Switch# show spanning-tree interface gi0/1
  • Switch# show spanning-tree blockedports
Go to the diagram

802.1X

שכבה 2 / NACSecurity

What it isA guard at the network jack: a device must authenticate before it gets any network access at all.

Real-life exampleA guest plugs a laptop into a wall port and gets nothing until they authenticate — or lands in a guest VLAN.

Troubleshooting

Common symptomsUser gets no network: no supplicant configured, RADIUS unreachable, or the device was moved to a Guest/Restricted VLAN after a failed auth.

Check commands
  • Switch# show dot1x all
  • Switch# show authentication sessions interface gi0/2
  • Switch# debug dot1x events
  • Get-WinEvent -LogName Security (NPS)
Go to the topic

RADIUS

1812, 1813 / UDPSecurity

What it isA central authentication server for network access (Wi-Fi, VPN, 802.1X). In Microsoft land it's NPS, validating against AD.

Real-life exampleYou join corporate Wi-Fi with your domain account — NPS/RADIUS validates it against Active Directory.

Troubleshooting

Common symptomsAll authentications fail: shared secret mismatch between device and NPS, ports 1812/1813 blocked, or the NPS policy does not match the group.

Check commands
  • Router# show radius statistics
  • Router# test aaa group radius user pass new-code
  • Router# debug radius authentication
  • Get-NetEventSession (NPS logs)
Go to the topic

NAT / PAT

—Routing

What it isNAT translates a private address to a public one. PAT (NAT Overload) sends the whole network out through one address, using port numbers.

Real-life exampleThe whole office (172.31.0.0/16) reaches the internet via one public IP; the router tracks which port belongs to which host.

Troubleshooting

Common symptomsNo internet from inside: missing ip nat inside/outside on the interfaces, the network is not in the ACL, or no default route.

Check commands
  • Router# show ip nat translations
  • Router# show ip nat statistics
  • Router# clear ip nat translation *
  • Router# debug ip nat
Go to the topic

Static NAT

—Routing

What it isA fixed 1:1 mapping between an inside and a public address — required for servers reachable from outside.

Real-life exampleInternal web server 172.19.0.10 is mapped to 209.165.200.5 so external users can reach it.

Troubleshooting

Common symptomsServer unreachable from outside: mapping points at the wrong address, an ACL blocks the port, or the server's gateway is not this router.

Check commands
  • Router# show ip nat translations
  • Router# show run | include ip nat inside source static
  • Router# debug ip nat
Go to the topic

OSPF

AD 110Routing

What it isDynamic routing protocol: routers exchange information and build the routing table themselves using Cost. Each has a Router-ID and an Area.

Real-life exampleAdd a new LAN3 network and every router learns it within seconds, with no manual entry.

Troubleshooting

Common symptomsNeighbor stuck in INIT/EXSTART: mismatched Area, Hello/Dead timers, MTU, or a wrong wildcard mask in the network command.

Check commands
  • Router# show ip ospf neighbor
  • Router# show ip ospf interface brief
  • Router# show ip route ospf
  • Router# debug ip ospf adj
Go to the diagram

Static Route

AD 1Routing

What it isA manually configured route: "for network X, go via neighbour Y". Simple and stable but never updates itself. 0.0.0.0/0 is the default route.

Real-life exampleBetween two routers in LAN3 you add one static route instead of running a whole routing protocol.

Troubleshooting

Common symptomsRoute missing from the table = next-hop unreachable or interface down. Traffic flows one way only = no return route on the other side.

Check commands
  • Router# show ip route
  • Router# show ip route 10.20.0.0
  • Router# ping 10.20.0.1
  • Router# traceroute 10.20.0.5
Go to the diagram

HSRP / VRRP

—Routing

What it isTwo routers share one virtual gateway address: one Active, one Standby. If the active one dies, the other takes over.

Real-life exampleUnplug Router3 and PC6 keeps browsing because Router4 became Active within seconds (failover).

Troubleshooting

Common symptomsBoth routers Active = they cannot see each other (VLAN/ACL blocking multicast 224.0.0.2). No failover = priority/preempt misconfigured.

Check commands
  • Router# show standby brief
  • Router# show standby
  • Router# debug standby events
  • ping -t <virtual IP> בזמן failover
Go to the diagram

EtherChannel (LACP / PAgP)

—Switching

What it isBundling several physical cables into one logical link: more bandwidth plus automatic redundancy. LACP is the standard, PAgP is Cisco's.

Real-life exampleThree cables between Switch5 and Switch7 become a single channel; losing one does not drop the link.

Troubleshooting

Common symptomsOutput shows (I)/(s) instead of (P): channel modes mismatch (active vs desirable), or ports differ in speed/duplex/VLAN.

Check commands
  • Switch# show etherchannel summary
  • Switch# show etherchannel port-channel
  • Switch# show interfaces etherchannel
  • Switch# debug etherchannel
Go to the diagram

SVI / Inter-VLAN Routing

—Switching

What it isA VLAN's virtual interface on an L3 switch (interface vlan 10) acting as its gateway. Without it VLANs cannot talk.

Real-life exampleVLAN10 (users) and VLAN20 (printers) each get an SVI, so a PC can finally print.

Troubleshooting

Common symptomsSVI down/down = no active port in that VLAN. No inter-VLAN routing = ip routing missing on the L3 switch, or wrong client gateway.

Check commands
  • Switch# show ip interface brief
  • Switch# show vlan brief
  • Switch# show ip route
  • Switch(config)# ip routing
Go to the diagram

DHCP Relay (ip helper-address)

67 / UDPInfrastructure

What it isTurns a broadcast DHCP request into a unicast toward a server in another VLAN. Without it remote clients get no address.

Real-life examplePCs in VLAN20 receive IPs from a DHCP server living in the LAN2 server farm.

Troubleshooting

Common symptomsRemote-VLAN clients get APIPA: helper-address missing or pointing to the wrong IP, or the server has no scope for that subnet.

Check commands
  • Router# show run interface vlan 20
  • Router# show ip dhcp binding
  • Router# debug ip dhcp server packet
  • ipconfig /renew בלקוח
Go to the topic

Port Security

—Security

What it isLimits which and how many MAC addresses are allowed on a switch port. In restrict mode a violation is dropped and logged.

Real-life exampleSomeone plugs a personal switch into an office jack — the port sees an extra MAC and blocks it instantly.

Troubleshooting

Common symptomsPort went err-disabled after an extra device was plugged in. In restrict mode the counter rises and syslog fires; recover with shut/no shut or errdisable recovery.

Check commands
  • Switch# show port-security
  • Switch# show port-security interface gi0/2
  • Switch# show port-security address
  • Switch(config-if)# shutdown / no shutdown (שחזור)
Go to the topic

ACL

—Security

What it isA filtering rule list: who is allowed or denied, by address, protocol and port. Read top-down with an implicit deny at the end.

Real-life exampleAn ACL blocks VLAN10↔VLAN20 traffic but still allows HTTP and DNS toward the LAN2 servers.

Troubleshooting

Common symptomsTraffic blocked "for no reason": every ACL ends with an implicit deny any, rules are in the wrong order, or it is applied in the wrong direction (in vs out).

Check commands
  • Router# show access-lists
  • Router# show ip interface gi0/0 | include access list
  • Router# debug ip packet <acl> (בזהירות)
  • Router# clear access-list counters
Go to the topic

CAPWAP (WLC + AP)

5246, 5247 / UDPWireless

What it isA wireless controller (WLC) manages all access points centrally; CAPWAP is the tunnel between AP and WLC.

Real-life exampleDefine one SSID on the WLC and every AP in the building broadcasts it, mapped to VLAN10.

Troubleshooting

Common symptomsAP does not join the WLC: no DHCP address, missing Option 43 / CISCO-CAPWAP-CONTROLLER DNS record, or a firmware version mismatch.

Check commands
  • WLC> show ap summary
  • WLC> show capwap client rcb
  • AP# show capwap client mm
  • Router# show ip dhcp binding (כתובת ל־AP)

Traceroute / Ping

ICMPTroubleshooting

What it isThe first diagnostic tools: ping checks whether the target answers, traceroute shows the path and where it stops.

Real-life exampleAn internal site fails: ping to the server works but traceroute stalls at a router — the problem is routing, not the server.

Troubleshooting

Common symptomsStars (*) at a hop = that router blocks ICMP or traffic stops there. Ping by IP works but by name fails = a DNS problem, not a network one.

Check commands
  • ping 8.8.8.8 | ping dc01
  • tracert 10.20.0.5 | traceroute 10.20.0.5
  • pathping 10.20.0.5
  • Router# show ip route
Go to the diagram

Microsoft / Active Directory

LDAP / LDAPS

389 / 636 (TLS)Application

What it isThe query language of the corporate directory: how you ask AD who users are and which groups they belong to. LDAPS is the same thing over TLS.

Real-life exampleA business app asks AD: "is user dani in the HR group?" and gets a yes/no answer.

Troubleshooting

Common symptomsQueries hang or fail with "Can't contact LDAP server": port 389/636 blocked, expired LDAPS certificate, or a wrong bind account.

Check commands
  • ldp.exe (חיבור ל־389/636)
  • Test-NetConnection dc01 -Port 389
  • nltest /dsgetdc:corp.local
  • Get-ADUser -Filter * -Server dc01

Kerberos

88 / UDP,TCPAuthentication

What it isTicket-based authentication: sign in once, get a ticket (TGT), then reach services without resending your password.

Real-life exampleYou log in in the morning, then open a file share later and are never prompted — the ticket did the work.

Troubleshooting

Common symptomsKRB_AP_ERR_SKEW = clock skew over 5 minutes. Fallback to NTLM or an SPN error = missing or duplicate SPN. Repeated "bad password" = account lockout.

Check commands
  • klist | klist purge
  • w32tm /query /status
  • setspn -L svc_sql | setspn -X (כפילויות)
  • nltest /sc_verify:corp.local

NTLM

עובד מעל SMB/445Authentication

What it isMicrosoft's legacy authentication protocol. Kept for compatibility but vulnerable to Pass-the-Hash — prefer Kerberos.

Real-life exampleYou connect to a server by IP instead of by name — Kerberos can't be used, so the system falls back to NTLM.

Troubleshooting

Common symptomsAuth falls back to NTLM instead of Kerberos (NTLM visible in event 4624) — usually access by IP instead of name, or a missing SPN. Also a relay risk.

Check commands
  • Get-WinEvent -LogName Security -FilterXPath "*[System/EventID=4624]"
  • klist (לוודא שאין כרטיס Kerberos)
  • nltest /dsgetdc:corp.local

SMB / CIFS

445 / TCPFile sharing

What it isWindows file and printer sharing protocol. Group Policies also reach machines through the SYSVOL share over SMB.

Real-life exampleYou open \\fileserver\Shared in Explorer — that's SMB working under the hood.

Troubleshooting

Common symptoms"Access denied" despite permissions = Share vs NTFS conflict. No connection at all = port 445 blocked. SMB Signing warning = mismatched settings.

Check commands
  • net use \\\\fs01\\share
  • Test-NetConnection fs01 -Port 445
  • Get-SmbConnection | Get-SmbShare
  • gpresult /r (הרשאות/מדיניות)

RDP

3389 / TCPRemote access

What it isRemote Desktop: graphical control of another machine. A favourite attacker target — never expose it to the internet.

Real-life exampleAn admin connects from home to an office server and sees its screen as if sitting in front of it.

Troubleshooting

Common symptoms"Can't connect" = service off or port 3389 blocked. Session drops instantly = session limit or user not in Remote Desktop Users.

Check commands
  • Test-NetConnection srv01 -Port 3389
  • qwinsta /server:srv01 | rwinsta <id>
  • Get-WinEvent -LogName Security -FilterXPath "*[System/EventID=4625]"

WinRM / PowerShell Remoting

5985 / 5986 (HTTPS)Remote access

What it isCommand-line remote management: run PowerShell commands on another machine without a GUI.

Real-life exampleEnter-PSSession -ComputerName SRV01 and you're running commands on the server from your own PC.

Troubleshooting

Common symptoms"WinRM cannot complete the operation" = service down, port 5985/5986 blocked, or the host is non-domain and not in TrustedHosts.

Check commands
  • Test-WSMan srv01
  • winrm quickconfig
  • Enter-PSSession srv01
  • Get-Item WSMan:\localhost\Client\TrustedHosts

MSRPC / DCERPC

135 + פורטים דינמייםAD internals

What it isWindows' remote procedure call machinery. DC-to-DC replication, admin tools and DCSync all ride on it.

Real-life exampleWhen you open Active Directory Users and Computers, the console talks to the DC over RPC.

Troubleshooting

Common symptomsManagement tools fail with "RPC server is unavailable": port 135 or the dynamic range (49152-65535) is blocked.

Check commands
  • Test-NetConnection dc01 -Port 135
  • netstat -ano | findstr 135
  • dcdiag /test:Replications
  • repadmin /replsummary

Global Catalog

3268 / 3269 (TLS)AD internals

What it isA partial replica of every object in the forest — enables fast cross-domain lookups.

Real-life exampleOutlook finds a contact from another domain in the organisation instantly, thanks to the Global Catalog.

Troubleshooting

Common symptomsCross-domain user lookups fail or logon is slow: no GC available in the site, or port 3268 blocked.

Check commands
  • nltest /dsgetdc:corp.local /gc
  • Test-NetConnection dc01 -Port 3268
  • dcdiag /test:advertising
  • repadmin /showrepl

LLMNR / NBT-NS

5355 / 137Legacy

What it isLegacy name-resolution protocols used when DNS fails. An attacker answers instead of the real server and steals hashes — disable them.

Real-life exampleYou mistype a server name; the PC asks the whole network and an attacker running Responder replies "that's me" and harvests credentials.

Troubleshooting

Common symptomsWhen DNS fails, Windows broadcasts the question — and an attacker answers instead (Responder) and steals the hash. Fix: disable LLMNR/NBT-NS and fix DNS.

Check commands
  • Get-DnsClientGlobalSetting
  • nbtstat -n
  • Get-WinEvent -LogName Security (4624 NTLM)

SAML / OAuth 2.0 / OIDC

מעל HTTPSModern identity

What it isModern cloud identity protocols: sign in once (SSO) and reach many apps without further passwords.

Real-life exampleYou sign in to Microsoft 365 and then enter Zoom or Jira without typing a password again.

Troubleshooting

Common symptomsEndless login loop or "Invalid signature": clock skew, expired signing certificate, or mismatched Reply URL / Entity ID.

Check commands
  • בדיקת שעון: w32tm /query /status
  • כלי דפדפן: SAML-tracer / Network tab
  • openssl s_client -connect idp:443