Why does an IPv4 route name its next hop by IP address, and how does the router turn that into a sendable frame?
answer
- routes live at the IP layer
- adjacent means no router in between
- resolve the neighbour, not the destination
- frame addresses change, IP addresses stay
basics
~20 sRoutes are IP-layer knowledge that must work over any link, so the next hop is an IP address; the router then resolves it to a link-layer address (ARP on IPv4 Ethernet) and frames the unchanged packet to it.
solid answer
~50 sRFC 1812 defines the **next hop** as "the IP address of the adjacent host or router to which the packet should be sent next", where adjacent means reachable without crossing another router. If the destination is on a directly connected network, the next hop is the destination itself (**direct delivery**); otherwise it is a router on a connected network (**indirect delivery**). After the lookup, the router resolves that next-hop address to a link-layer address: ARP on IPv4 over Ethernet, Neighbor Discovery for IPv6. It builds a new frame with the neighbour's link-layer address as destination and its own interface's as source; the IP header still names the final destination. Keeping next hops as IP addresses means one resolution serves every destination routed through that neighbour, and a route survives the neighbour's network card being replaced.
go deeper
Recall that the next hop is a neighbour's IP address, ARP turns it into a link-layer address, and the packet's own IP addresses do not change.
Explain direct versus indirect delivery, trace one packet through lookup, resolution and re-framing, and say why one ARP entry serves every destination behind a neighbour.
Diagnose from the mechanism: a route that is present but traffic dying at the hop points to failed neighbour resolution, not to the lookup.
Discuss the layering choice: IP next hops keep routing independent of link technology, at the cost of a resolution step and its failure modes on every link.
## Two kinds of delivery Every IPv4 forwarding decision ends in one of two cases, which RFC 1812 section 5.2.4.2 calls the **local/remote decision**: - **Direct delivery.** The destination address falls inside a network prefix configured on one of the router's interfaces. The destination is **adjacent** (reachable without going through any IP router), so the next hop is the destination address itself. - **Indirect delivery.** The destination is elsewhere. The routing table supplies a **next-hop address**: the IP address of an adjacent router that is one hop closer. Either way the next hop is an **IP address on a directly connected network**. RFC 1812 defines it exactly so: "the IP address of the adjacent host or router to which the packet should be sent next". ## The resolution step, traced Take a router with this table: | Prefix | Next hop | Outgoing interface | |---|---|---| | `0.0.0.0/0` (default) | `203.0.113.1` | uplink | | `10.0.0.0/8` | `172.16.0.2` | link A | | `10.1.0.0/16` | `172.16.1.2` | link B | | `10.1.1.0/24` | `172.16.2.2` | link C | and a packet from `192.0.2.10` to `10.1.2.9`: 1. Longest match selects `10.1.0.0/16`: next hop `172.16.1.2`, interface link B. 2. The router decrements the `TTL` and recomputes the checksum. 3. It needs the **link-layer address** of `172.16.1.2`. On IPv4 over Ethernet it checks its ARP cache; if the entry is missing it broadcasts an ARP request on link B and waits for the unicast reply. 4. It builds a frame: destination = the link-layer address of `172.16.1.2`, source = its own link-B interface address. 5. The IP header inside still says source `192.0.2.10`, destination `10.1.2.9`. On the next link the frame addresses change again while the IP addresses still do not: every router on the path repeats the same resolution for its own next hop. RFC 1812's own step list puts it this way: "The forwarder determines the Link Layer address of the packet's next hop. The mechanisms for doing this are Link Layer-dependent." ## What each header carries | Field | Value on link B | |---|---| | Frame destination | link-layer address of `172.16.1.2` (the next hop) | | Frame source | link-layer address of the router's link-B interface | | IP source | `192.0.2.10` (unchanged) | | IP destination | `10.1.2.9` (unchanged) | ## Why an IP next hop, not a link-layer address - **Link independence.** The same table works over Ethernet, point-to-point links or tunnels; each link type supplies its own resolution method. - **One resolution, many destinations.** Thousands of prefixes can share next hop `172.16.1.2`; the router needs one ARP entry for that neighbour, not one per destination. - **Stable routes.** If the neighbour's network card is replaced, its link-layer address changes, the resolution cache refreshes, and no route has to change. - **Routing protocols speak IP.** Neighbours advertise reachability using their IP addresses, so routes naturally arrive with IP next hops. ## When resolution fails - If the next hop never answers, the frame cannot be addressed and the packet is eventually dropped. RFC 1812 (section 3.3.2) says a router's link layer must not report the destination unreachable merely because no ARP entry exists yet; it **SHOULD** queue a few packets briefly while resolving, and report unreachable only when resolution proves fruitless. - If the router is the **last hop** and finds no path to the destination host, RFC 1812 requires an ICMP Destination Unreachable with code 1 (**Host Unreachable**). - A **stale** resolution entry, holding a neighbour's old link-layer address after its hardware changed, sends frames to a link-layer address no station holds until the entry is refreshed or expires; how long entries live is an implementation choice. - The per-packet lookup itself does not test whether a neighbour is alive; a route stays in the table until whatever installed it removes it. - On IPv6 the router resolves next hops with **Neighbor Discovery** (RFC 4861): a Neighbor Solicitation to the target's solicited-node multicast address, answered by a Neighbor Advertisement, with Neighbor Unreachability Detection noticing a dead neighbour. ## A next hop that is not adjacent Some routes are configured or learned with a next hop several routers away. Many implementations resolve such a route by looking the next-hop address up again in the same table until they reach an adjacent neighbour. This is an implementation behaviour; the frame still always goes to an adjacent address, because a link-layer frame cannot cross a router.
- How many address resolutions does an IPv4 router need to forward traffic to 5,000 remote destinations that all share one next hop on Ethernet?One. Every packet routed via that next hop is framed to the same neighbour, so the router needs only that neighbour's link-layer address in its ARP cache. Entries for individual destinations appear only for hosts on the router's own connected networks, where the destination is itself the next hop.
- What does an IPv4 router do when its next hop never answers address resolution?It cannot address a frame, so the packet is dropped once resolution gives up. RFC 1812 says the router should queue a few packets briefly while resolving, rather than reporting failure just because no ARP entry exists yet. A last-hop router that concludes the destination host is unreachable must send ICMP Destination Unreachable, code 1 (Host Unreachable). The lookup itself keeps choosing the route until whatever installed it withdraws it.
saying these in an interview costs you the question
- The router puts the next hop's IP address into the packet's destination field.
- The router uses ARP to find the final destination even when it is several hops away.
- A router needs an ARP entry for every remote destination it forwards to.
- A router can send a frame straight to a next hop several routers away.
- Routes store MAC addresses, so no resolution happens at forwarding time.