skip to content

What does an IPv4 router do with each packet it forwards, from the moment it arrives until it leaves?

level: juniorimportance: must knowfreq 62%

answer

  1. check the header before anything
  2. the destination address drives the lookup
  3. most specific matching route
  4. TTL down, checksum redone
  5. new frame, same IP addresses

basics

~20 s

An IPv4 router validates the header, finds the longest matching prefix for the destination address, decrements the TTL, resolves the next hop's link-layer address, sends the packet in a new frame, and then forgets it.

solid answer

~50 s

For each packet the router first validates the IPv4 header (length, version, checksum) and checks whether the packet is addressed to the router itself. If it is to be forwarded, the router looks up the **destination address** in its forwarding table and takes the route with the **longest matching prefix**, which yields an outgoing interface and a next-hop IP address. It decrements the `TTL` by at least one, discarding the packet if that reaches zero, and recomputes the header checksum because the header changed. It then resolves the next hop's link-layer address (ARP on Ethernet), wraps the packet in a fresh frame and sends it. The source and destination IP addresses stay as they were (a NAT on the path is a separate function), and once the packet is gone the router keeps no record of it: the next packet of the same conversation gets a lookup of its own.

go deeper

for a junior

Recall the order: validate, lookup by longest prefix, decrement TTL, resolve the next hop, new frame, forget. Say clearly that the IP addresses stay the same.

for a middle

Explain why the checksum is recomputed, why local delivery is decided before the TTL check, and what happens when no route matches at all.

for a senior

Connect statelessness to operations: each packet is decided alone, so a table change moves traffic immediately, and any device that needs per-flow memory has to supply it itself.

for a principal

Frame the design tradeoff: keeping routers stateless buys scale and fast rerouting, and pushes reliability and ordering to the endpoints that need them.

## What a router is for An **IPv4 router** is a device that connects several networks and moves **packets** (IP datagrams) from one to another. It does not deliver data end to end by itself; it moves each packet **one hop** closer to its destination and hands it to the next device on the path. The whole Internet works by chaining these single hops, which is why the job is called **hop-by-hop forwarding**. RFC 791 sets the tone: the Internet Protocol "treats each internet datagram as an independent entity unrelated to any other internet datagram", with "no connections or logical circuits". RFC 1812 (Requirements for IP Version 4 Routers) then spells out what a router must do with each packet. Its section 5.2.1 says an implementation need not follow the steps literally, but must achieve the same effect in the same order. ## The per-packet steps For a unicast packet that is not addressed to the router itself, the work runs in this order: 1. **Receive and strip the frame.** The link layer (for example Ethernet) hands the IP packet up; the old frame header is discarded. 2. **Validate the header.** RFC 1812 section 5.2.2 requires the router to check that the packet is at least 20 bytes long, the version is 4, the header length and total length are sane, and the header **checksum** is correct. A packet that fails is silently discarded. 3. **Decide: for me, or to forward?** If the destination is one of the router's own addresses, the packet is delivered locally. This check comes **before** any `TTL` handling. 4. **Look up the destination.** The router compares the **destination address** with every route and keeps the one with the **longest matching prefix**. The winning route gives an outgoing interface and a **next-hop IP address**. If nothing matches, not even a default route, the packet is discarded and an ICMP Destination Unreachable (Network Unreachable) goes back to the source. 5. **Decrement the TTL.** The `TTL` drops by at least one. If it reaches zero, the packet is discarded and an ICMP Time Exceeded message goes to the source. 6. **Fragment if necessary.** If the outgoing link's maximum packet size is too small and the header allows it, the IPv4 router splits the packet. That is a subject of its own. 7. **Resolve the next hop.** The router finds the link-layer address of the next hop (on IPv4 Ethernet, through ARP). 8. **Re-encapsulate and send.** The packet goes into a new frame addressed to the next hop and leaves through the chosen interface. Because the `TTL` changed, the header checksum is **recomputed**; RFC 791 notes the checksum is "recomputed and verified at each point that the internet header is processed". ## A worked example A router holds this table: | Prefix | Next hop | Outgoing interface | |---|---|---| | `0.0.0.0/0` (default) | `203.0.113.1` | uplink | | `10.0.0.0/8` | `172.16.0.2` | link A | | `10.1.0.0/16` | `172.16.1.2` | link B | | `10.1.1.0/24` | `172.16.2.2` | link C | A packet from `192.0.2.10` to `10.1.2.9` arrives with `TTL` 57. The destination matches `0.0.0.0/0`, `10.0.0.0/8` and `10.1.0.0/16`, but not `10.1.1.0/24` (its third byte is 2, not 1). The longest match is the `/16`, so the next hop is `172.16.1.2` on link B. The `TTL` becomes 56, the checksum is redone, the router resolves `172.16.1.2` to a link-layer address, and the packet leaves in a frame addressed to that neighbour. ## What changes and what does not | Item | At each router hop | |---|---| | Source IP address | unchanged | | Destination IP address | unchanged | | `TTL` | decremented by at least one | | Header checksum | recomputed | | Link-layer frame | replaced: new source and destination addresses | Unchanged IP addresses are the rule for plain forwarding; a **NAT** device on the path rewrites addresses, but that is a separate function layered on top of forwarding. ## Why the router forgets everything After step 8 the router keeps **no per-packet or per-connection state**. The next packet of the same TCP connection goes through the same steps from scratch. This is what lets a router carry huge numbers of flows, and lets traffic shift to a new path as soon as the table changes. Implementations cache lookup results for speed, but a cache only reproduces what the table would answer; it is not a memory of connections. ## Common confusions - The router does **not** write the next hop's address into the IP header; the next hop appears only as the frame's destination. - The table is **not** read top to bottom; prefix length decides, not entry order. - `TTL` is not left alone on a fast router: RFC 1812 requires a decrement of at least one "even if the elapsed time was much less than a second".

  • What does an IPv4 router do with a packet whose destination matches no route, not even a default route?
    It discards the packet and, per RFC 1812, generates an ICMP Destination Unreachable with code 0 (Network Unreachable) for the source. A default route (`0.0.0.0/0`) matches every destination, so a router that has one never reaches this case: it sends traffic for unknown destinations to the default next hop instead of reporting it unreachable.
  • Why must an IPv4 router check whether a packet is addressed to itself before it decrements the TTL?
    RFC 1812 says a router must check the `TTL` only when forwarding, and must not discard a packet just because it arrived with `TTL` 0 or 1 if it is addressed to the router. A management or routing-protocol packet sent with `TTL` 1 to a neighbour has to be accepted, so the local-delivery decision comes first.
  • Does an IPv6 router run the same per-packet steps?
    Mostly. It takes the longest matching prefix and decrements the Hop Limit, discarding the packet when it reaches zero (RFC 8200). There is no header checksum to recompute, routers never fragment because IPv6 fragmentation is done only by the source, and next-hop resolution uses Neighbor Discovery (RFC 4861) instead of ARP.

saying these in an interview costs you the question

  • The router rewrites the destination IP address to the next router's address.
  • Routers remember each connection and send its later packets the same way.
  • The router uses the first matching route it finds, reading the table top to bottom.
  • TTL counts seconds, so a fast router can pass the packet on without changing it.
  • The router forwards the original Ethernet frame unchanged to the next hop.