In IPv4, what does an ICMP Time Exceeded message (type 11) report, and which device sends each of its two codes?
answer
- a clock or counter ran out
- two codes, two different senders
- in transit versus at reassembly
- fragment zero must have arrived
basics
~20 sICMP type 11 reports a datagram discarded because a limit ran out. Code 0, TTL exceeded in transit, comes from a router that dropped a packet whose TTL reached zero; code 1, fragment reassembly time exceeded, comes from the destination host.
solid answer
~50 sTime Exceeded is ICMP type 11, defined in RFC 792. **Code 0 — time to live exceeded in transit** is sent by a *router*: when forwarding reduces a packet's `TTL` to zero, RFC 1812 says the router MUST discard it and MUST send code 0 back to the source (unless the destination was multicast). It signals a routing loop or a starting TTL too small for the path, and it is what traceroute relies on. **Code 1 — fragment reassembly time exceeded** is sent by the *destination host*: RFC 1122 requires a reassembly timeout (60-120 seconds recommended), and when it expires the partial datagram is discarded and code 1 is sent, but only if fragment zero arrived. Like every ICMP error it quotes the dropped datagram's IP header plus at least its first 8 payload bytes, so the sender can match it to a socket.
go deeper
Recall type 11 and its two codes: code 0 when a router drops a packet whose TTL hit zero, code 1 when a destination gives up reassembling fragments. Say who sends each.
Explain the rules behind each code: RFC 1812's MUST discard and MUST send for code 0, RFC 1122's reassembly timeout and the fragment-zero condition for code 1, and why the quoted 8 bytes let the sender match the error.
Show you know when the message does not arrive: rate limiting, the per-interface switch RFC 1812 allows, and the no-error-about-errors rules. Connect code 0 to routing loops and code 1 to lost fragments.
Weigh the policy angle: Time Exceeded is required because diagnostics depend on it, yet operators suppress or rate-limit it. Argue where suppressing it costs more troubleshooting time than it saves.
## What type 11 is for The **Internet Control Message Protocol** (ICMP, RFC 792) is how IPv4 nodes report problems with datagrams back to the sender. Each message carries a one-byte **type** naming the condition and a one-byte **code** refining it. **Type 11, Time Exceeded**, covers one family of problems: a datagram was thrown away because a limit on its lifetime ran out before it was delivered. There are two such limits in IPv4, and each has its own code and its own sender: | Code | Name in RFC 792 | Sent by | Trigger | |---|---|---|---| | 0 | time to live exceeded in transit | a router (RFC 792 says "gateway") | forwarding reduced the `TTL` to zero | | 1 | fragment reassembly time exceeded | the destination host | the fragments of one datagram did not all arrive before the reassembly timer expired | RFC 792 says it in one line: "Code 0 may be received from a gateway. Code 1 may be received from a host." ## Code 0 — TTL exceeded in transit Every IPv4 header carries an 8-bit **Time to Live** (`TTL`) field. The sender sets it, and every router that forwards the packet must reduce it by at least one. Its job is to stop a packet circling forever when routing is broken. When the TTL reaches zero, RFC 1812 (the IPv4 router requirements) is explicit: - the router **MUST discard** the packet; - if the destination is not a multicast address, the router **MUST send** an ICMP Time Exceeded, code 0, to the source; - a router **MAY** offer a per-interface option to stop originating these messages, but that option **MUST default** to sending them. RFC 1122 explains what a host should conclude on receiving one: there is "either a gateway routing loop or too small an initial TTL value." RFC 1812 adds why the message is mandatory at all: traceroute depends on it. A tracing tool deliberately sends packets with TTL 1, 2, 3 and so on, and each router that expires one reports itself with a code 0. ## Code 1 — fragment reassembly time exceeded When an IPv4 datagram is split into **fragments**, only the final destination puts them back together. It cannot wait forever for a missing piece, so RFC 1122 requires a **reassembly timeout**: 1. The timeout SHOULD be a fixed value, not taken from the remaining TTL (RFC 791's original suggestion, which fails because routers treat TTL as a hop count). 2. RFC 1122 recommends a value between **60 and 120 seconds**; the exact number is the implementation's choice. 3. When it expires, the partial datagram MUST be discarded and a Time Exceeded code 1 sent to the source — **if fragment zero has been received**. The fragment-zero condition matters. Fragment zero is the one that starts at offset 0, so it is the only fragment carrying the transport header with its port numbers. An error that quotes a later fragment could not be matched to any socket at the sender, and RFC 1122 separately forbids sending ICMP errors about non-initial fragments. RFC 792 puts it plainly: "If fragment zero is not available then no time exceeded need be sent at all." ## What the message carries The Time Exceeded layout in RFC 792 is the common ICMP error shape: - type `11`, code `0` or `1`, a 16-bit checksum; - 32 **unused** bits; - the **original datagram's IP header plus the first 64 bits (8 bytes) of its data**. Those 8 bytes cover the source and destination ports of a UDP or TCP header, which is how the sender's stack hands the error to the right process. RFC 1812 asks routers to quote as much more of the original as fits without the ICMP datagram exceeding 576 bytes, and RFC 4884 defines a length field and extension objects appended to the quote; one such extension (RFC 5837) lets a router say which interface the expired packet arrived on. RFC 1122 also requires a host to pass an incoming Time Exceeded up to the transport layer. TCP treats it as advisory: it tells the application and does not abort the connection, because a routing loop may be transient. ## When no Time Exceeded is sent ICMP errors are never sent about certain packets (RFC 1122 §3.2.2), and these rules override the requirements above: - another ICMP **error** message (an Echo request is a query, not an error, so an expiring Echo request does draw a Time Exceeded); - a datagram sent to an IP broadcast or multicast address, or as a link-layer broadcast; - a **non-initial fragment**; - a datagram whose source address does not identify a single host. Routers may also **rate-limit** the ICMP errors they originate (RFC 1812 §4.3.2.8), so a burst of expiring packets can draw fewer messages than packets. ## The IPv6 counterpart ICMPv6 (RFC 4443) carries the same two conditions as **type 3**, Time Exceeded: code 0 "hop limit exceeded in transit" and code 1 "fragment reassembly time exceeded". In IPv6 the field is called Hop Limit, and the type number differs from IPv4's 11, so the two numbering schemes must not be mixed.
- Why does an IPv4 destination send Time Exceeded code 1 only when fragment zero has arrived?Fragment zero is the only one that carries the transport header, with its port numbers, inside the first 8 bytes of payload. The ICMP error quotes the IP header plus those 8 bytes so the sender can find the socket. Without fragment zero there is nothing useful to quote, and RFC 1122 forbids ICMP errors about non-initial fragments anyway, so the host discards the partial datagram silently.
- An IPv4 host receives a Time Exceeded code 0 for one of its TCP segments. What should TCP do with it?Treat it as advisory. RFC 1122 requires IP to pass the message to the transport layer, and its TCP rules say to report Time Exceeded to the application without aborting the connection. Code 0 suggests a routing loop or too low a starting TTL; a loop may clear within seconds as routing converges, so killing the connection would turn a transient fault into a hard failure.
saying these in an interview costs you the question
- Time Exceeded code 0 comes from the destination when a packet arrives too late
- Code 1 comes from a router that waited too long to forward a fragment
- The router decrements TTL to zero and still delivers the packet to the next hop
- The reassembly timeout is taken from the remaining TTL of the first fragment
- Time Exceeded uses the same type number in ICMPv6 as in IPv4
- Routers may never suppress or rate-limit Time Exceeded because traceroute needs it