Every protocol in short: what it does and a real-life example.
CCNA
DNS
53 / UDP,TCPApplication
What it isName service: turns a name (dc01.corp.local) into an IP address. Without healthy DNS, Active Directory simply does not work.
Real-life exampleA PC looks up the SRV record _ldap._tcp.dc._msdcs.corp.local to find a Domain Controller before logging in.
Troubleshooting
Common symptomsName does not resolve / domain join fails / "DNS name does not exist". Check the client points at the DC as DNS server (not 8.8.8.8) and that SRV records exist.
What it isAutomatically hands out IP addresses on the network (the DORA process: Discover, Offer, Request, Ack).
Real-life exampleA laptop joins the office network and within a second gets an IP, gateway and DNS server with zero manual setup.
Troubleshooting
Common symptomsClient gets 169.254.x.x (APIPA) — no DHCP answer. Causes: exhausted scope, server in another VLAN without ip helper-address, or a rogue DHCP.
What it isThe browser protocol. HTTPS adds TLS encryption so nobody in the middle can read the content.
Real-life exampleYou open the company portal and see the padlock in the address bar — the traffic is HTTPS-encrypted.
Troubleshooting
Common symptoms404 = wrong path on the server; 403 = permissions; 502/504 = backend not answering; "Connection refused" = service down or port blocked.
What it isThe encryption layer that wraps other protocols (HTTPS, LDAPS, SMTPS) and proves the server's identity with a certificate.
Real-life exampleA server presents a certificate issued by the corporate CA and the client confirms: this really is the right server.
Troubleshooting
Common symptomsBrowser warning: expired certificate, name mismatch (CN/SAN), or CA not trusted by the client. A wrong clock also yields "certificate not yet valid".
Check commands
openssl s_client -connect web01:443
curl -vI https://web01
certutil -verify -urlfetch cert.cer
NTP
123 / UDPInfrastructure
What it isClock synchronisation. In AD, a gap of more than 5 minutes between a client and a DC breaks Kerberos entirely.
Real-life exampleA user can't log in after a holiday — the PC's clock drifted; syncing time fixes it.
Troubleshooting
Common symptomsClock drift breaks Kerberos and confuses logs. Sign: "unsynchronized" in the output, or stratum 16 on the router.
What it isThe network's service-message protocol — ping and traceroute are built on it.
Real-life exampleping dc01 shows whether the server is alive and how many milliseconds it takes to answer.
Troubleshooting
Common symptoms"Request timed out" does not always mean the host is dead — a firewall often blocks ICMP. "Destination host unreachable" = missing route/gateway.
What it isReliable connection: a 3-way handshake, then confirmation that every packet arrived in order. Slower but safe.
Real-life exampleDownloading a file — you can't lose a single byte, so TCP is used.
Troubleshooting
Common symptoms"Connection refused" = nothing listening on the port. Hang until timeout = firewall silently dropping. Many TIME_WAIT = the app leaks connections.
What it isA guard at the network jack: a device must authenticate before it gets any network access at all.
Real-life exampleA guest plugs a laptop into a wall port and gets nothing until they authenticate — or lands in a guest VLAN.
Troubleshooting
Common symptomsUser gets no network: no supplicant configured, RADIUS unreachable, or the device was moved to a Guest/Restricted VLAN after a failed auth.
Check commands
Switch# show dot1x all
Switch# show authentication sessions interface gi0/2
What it isA central authentication server for network access (Wi-Fi, VPN, 802.1X). In Microsoft land it's NPS, validating against AD.
Real-life exampleYou join corporate Wi-Fi with your domain account — NPS/RADIUS validates it against Active Directory.
Troubleshooting
Common symptomsAll authentications fail: shared secret mismatch between device and NPS, ports 1812/1813 blocked, or the NPS policy does not match the group.
What it isA fixed 1:1 mapping between an inside and a public address — required for servers reachable from outside.
Real-life exampleInternal web server 172.19.0.10 is mapped to 209.165.200.5 so external users can reach it.
Troubleshooting
Common symptomsServer unreachable from outside: mapping points at the wrong address, an ACL blocks the port, or the server's gateway is not this router.
Check commands
Router# show ip nat translations
Router# show run | include ip nat inside source static
What it isA manually configured route: "for network X, go via neighbour Y". Simple and stable but never updates itself. 0.0.0.0/0 is the default route.
Real-life exampleBetween two routers in LAN3 you add one static route instead of running a whole routing protocol.
Troubleshooting
Common symptomsRoute missing from the table = next-hop unreachable or interface down. Traffic flows one way only = no return route on the other side.
What it isLimits which and how many MAC addresses are allowed on a switch port. In restrict mode a violation is dropped and logged.
Real-life exampleSomeone plugs a personal switch into an office jack — the port sees an extra MAC and blocks it instantly.
Troubleshooting
Common symptomsPort went err-disabled after an extra device was plugged in. In restrict mode the counter rises and syslog fires; recover with shut/no shut or errdisable recovery.
What it isA filtering rule list: who is allowed or denied, by address, protocol and port. Read top-down with an implicit deny at the end.
Real-life exampleAn ACL blocks VLAN10↔VLAN20 traffic but still allows HTTP and DNS toward the LAN2 servers.
Troubleshooting
Common symptomsTraffic blocked "for no reason": every ACL ends with an implicit deny any, rules are in the wrong order, or it is applied in the wrong direction (in vs out).
Check commands
Router# show access-lists
Router# show ip interface gi0/0 | include access list
What it isA wireless controller (WLC) manages all access points centrally; CAPWAP is the tunnel between AP and WLC.
Real-life exampleDefine one SSID on the WLC and every AP in the building broadcasts it, mapped to VLAN10.
Troubleshooting
Common symptomsAP does not join the WLC: no DHCP address, missing Option 43 / CISCO-CAPWAP-CONTROLLER DNS record, or a firmware version mismatch.
Check commands
WLC> show ap summary
WLC> show capwap client rcb
AP# show capwap client mm
Router# show ip dhcp binding (כתובת ל־AP)
Traceroute / Ping
ICMPTroubleshooting
What it isThe first diagnostic tools: ping checks whether the target answers, traceroute shows the path and where it stops.
Real-life exampleAn internal site fails: ping to the server works but traceroute stalls at a router — the problem is routing, not the server.
Troubleshooting
Common symptomsStars (*) at a hop = that router blocks ICMP or traffic stops there. Ping by IP works but by name fails = a DNS problem, not a network one.
What it isThe query language of the corporate directory: how you ask AD who users are and which groups they belong to. LDAPS is the same thing over TLS.
Real-life exampleA business app asks AD: "is user dani in the HR group?" and gets a yes/no answer.
Troubleshooting
Common symptomsQueries hang or fail with "Can't contact LDAP server": port 389/636 blocked, expired LDAPS certificate, or a wrong bind account.
Check commands
ldp.exe (חיבור ל־389/636)
Test-NetConnection dc01 -Port 389
nltest /dsgetdc:corp.local
Get-ADUser -Filter * -Server dc01
Kerberos
88 / UDP,TCPAuthentication
What it isTicket-based authentication: sign in once, get a ticket (TGT), then reach services without resending your password.
Real-life exampleYou log in in the morning, then open a file share later and are never prompted — the ticket did the work.
Troubleshooting
Common symptomsKRB_AP_ERR_SKEW = clock skew over 5 minutes. Fallback to NTLM or an SPN error = missing or duplicate SPN. Repeated "bad password" = account lockout.
Check commands
klist | klist purge
w32tm /query /status
setspn -L svc_sql | setspn -X (כפילויות)
nltest /sc_verify:corp.local
NTLM
עובד מעל SMB/445Authentication
What it isMicrosoft's legacy authentication protocol. Kept for compatibility but vulnerable to Pass-the-Hash — prefer Kerberos.
Real-life exampleYou connect to a server by IP instead of by name — Kerberos can't be used, so the system falls back to NTLM.
Troubleshooting
Common symptomsAuth falls back to NTLM instead of Kerberos (NTLM visible in event 4624) — usually access by IP instead of name, or a missing SPN. Also a relay risk.
What it isWindows file and printer sharing protocol. Group Policies also reach machines through the SYSVOL share over SMB.
Real-life exampleYou open \\fileserver\Shared in Explorer — that's SMB working under the hood.
Troubleshooting
Common symptoms"Access denied" despite permissions = Share vs NTFS conflict. No connection at all = port 445 blocked. SMB Signing warning = mismatched settings.
Check commands
net use \\\\fs01\\share
Test-NetConnection fs01 -Port 445
Get-SmbConnection | Get-SmbShare
gpresult /r (הרשאות/מדיניות)
RDP
3389 / TCPRemote access
What it isRemote Desktop: graphical control of another machine. A favourite attacker target — never expose it to the internet.
Real-life exampleAn admin connects from home to an office server and sees its screen as if sitting in front of it.
Troubleshooting
Common symptoms"Can't connect" = service off or port 3389 blocked. Session drops instantly = session limit or user not in Remote Desktop Users.
What it isCommand-line remote management: run PowerShell commands on another machine without a GUI.
Real-life exampleEnter-PSSession -ComputerName SRV01 and you're running commands on the server from your own PC.
Troubleshooting
Common symptoms"WinRM cannot complete the operation" = service down, port 5985/5986 blocked, or the host is non-domain and not in TrustedHosts.
Check commands
Test-WSMan srv01
winrm quickconfig
Enter-PSSession srv01
Get-Item WSMan:\localhost\Client\TrustedHosts
MSRPC / DCERPC
135 + פורטים דינמייםAD internals
What it isWindows' remote procedure call machinery. DC-to-DC replication, admin tools and DCSync all ride on it.
Real-life exampleWhen you open Active Directory Users and Computers, the console talks to the DC over RPC.
Troubleshooting
Common symptomsManagement tools fail with "RPC server is unavailable": port 135 or the dynamic range (49152-65535) is blocked.
Check commands
Test-NetConnection dc01 -Port 135
netstat -ano | findstr 135
dcdiag /test:Replications
repadmin /replsummary
Global Catalog
3268 / 3269 (TLS)AD internals
What it isA partial replica of every object in the forest — enables fast cross-domain lookups.
Real-life exampleOutlook finds a contact from another domain in the organisation instantly, thanks to the Global Catalog.
Troubleshooting
Common symptomsCross-domain user lookups fail or logon is slow: no GC available in the site, or port 3268 blocked.
Check commands
nltest /dsgetdc:corp.local /gc
Test-NetConnection dc01 -Port 3268
dcdiag /test:advertising
repadmin /showrepl
LLMNR / NBT-NS
5355 / 137Legacy
What it isLegacy name-resolution protocols used when DNS fails. An attacker answers instead of the real server and steals hashes — disable them.
Real-life exampleYou mistype a server name; the PC asks the whole network and an attacker running Responder replies "that's me" and harvests credentials.
Troubleshooting
Common symptomsWhen DNS fails, Windows broadcasts the question — and an attacker answers instead (Responder) and steals the hash. Fix: disable LLMNR/NBT-NS and fix DNS.
Check commands
Get-DnsClientGlobalSetting
nbtstat -n
Get-WinEvent -LogName Security (4624 NTLM)
SAML / OAuth 2.0 / OIDC
מעל HTTPSModern identity
What it isModern cloud identity protocols: sign in once (SSO) and reach many apps without further passwords.
Real-life exampleYou sign in to Microsoft 365 and then enter Zoom or Jira without typing a password again.
Troubleshooting
Common symptomsEndless login loop or "Invalid signature": clock skew, expired signing certificate, or mismatched Reply URL / Entity ID.