Routelearn.net
Course menu

Network Protocols

Learn the application-layer protocols behind everyday network use: the web, remote access, file transfer, email, time and monitoring. For each one, you will learn what it does, which port it uses and how to check it on a Cisco device.

Beginner · 7 lessons + test · Before this: TCP & UDP

Application-layer protocols are the rules that applications follow to exchange data over a network, such as HTTP for the web, SSH for remote access, SMTP for email and NTP for time. Each one defines its own message formats and normally uses a well-known TCP or UDP port.

In simple terms: Each everyday network job has its own set of rules. Your browser, your email app and your remote login tool each use their own protocol, usually on a well-known port number.

Every time you open a website, send an email or log in to a router, an application-layer protocol does the real work. A protocol is a set of rules that both sides agree on, like a shared language. These protocols run on top of TCP or UDP, and each server listens on a well-known port number, so a device knows which application a packet belongs to.

LaptopR1edge routerInternetWeb serverMail serverMonitoringSNMP / Syslog
  1. 1. The web: the laptop asks the web server for a page over HTTPS (TCP 443).
  2. 2. Email: the email app sends a message to the mail server with SMTP (TCP 587).
  3. 3. Remote access: an engineer logs in to R1 with SSH (TCP 22) to change its settings.
  4. 4. Monitoring: R1 reports an event to the monitoring server with Syslog (UDP 514).

What you'll learn

How the web works

HTTP requests and responses, status codes and how TLS turns HTTP into HTTPS.

Reach and manage devices

Log in with SSH instead of Telnet, and move files and IOS images with FTP, SFTP and TFTP.

Follow an email

How SMTP carries a message between servers, and how POP3 and IMAP let you read it.

Run a healthy network

Keep device clocks in sync with NTP, and monitor devices with SNMP and Syslog.

Skills you'll gain

  • HTTP
  • HTTPS & TLS
  • SSH
  • Telnet
  • FTP & TFTP
  • SMTP
  • POP3 & IMAP
  • NTP
  • SNMP
  • Syslog
  • Port numbers

Who is this for?

This course is for CCNA students and anyone new to networking. You should already know what an IP address is and the difference between TCP and UDP. If not, start with the TCP & UDP course.

Start the first lesson →

Related protocols

Two more protocols you meet every day have their own lessons, because they need a little more space:

  • DNS turns names like example.com into IP addresses. Almost every protocol in this course starts with a DNS lookup.
  • DHCP automatically gives a device its IP address, subnet mask, default gateway and DNS server when it joins the network.

Quick reference: ports

ProtocolPortTransportPurpose
HTTP80TCPWeb pages, no encryption
HTTPS443TCPWeb pages over TLS
SSH / SFTP22TCPEncrypted remote login and file transfer
Telnet23TCPRemote login in clear text (legacy)
FTP21 (control), 20 (active data)TCPFile transfer
TFTP69UDPSimple file transfer, no login
SMTP25 / 587 / 465TCPSending and relaying email
POP3110 / 995TCPDownloading email to one device
IMAP143 / 993TCPReading email kept on the server
NTP123UDPTime synchronisation
SNMP161 (polls), 162 (traps)UDPMonitoring devices
Syslog514UDPSending log messages
DNS53UDP / TCPNames to IP addresses
DHCP67 / 68UDPAutomatic IP settings

FAQ

Why do some protocols use TCP and others UDP?
It depends on what the protocol needs. HTTP, SSH, FTP and the email protocols need every byte to arrive correctly and in order, so they run on TCP. Others, such as NTP, SNMP, Syslog, TFTP and most DNS lookups, send small messages where speed and low overhead matter more, so they use UDP. The TCP & UDP course explains the full trade-off.
What is the difference between HTTP and HTTPS?
HTTPS is HTTP running inside a TLS-encrypted connection. The requests and responses are the same. The difference is that everything is encrypted in transit and the server proves its identity with a certificate. Anyone who captures the traffic sees only encrypted data.
Is Telnet still used anywhere?
Rarely for real work, because it sends everything, including passwords, in clear text. You may still see it in old labs, or used to test whether a TCP port is open. For remote access, SSH replaced it a long time ago.