skip to content

Why must every IPv4 router decrement a packet's TTL, and how does that end a packet caught in a transient routing loop?

level: juniorimportance: should knowfreq 46%

answer

  1. named for time, used as hops
  2. at least one per router
  3. zero means discard and report
  4. bounds the packet, not the loop

basics

~20 s

Each router must lower the 8-bit IPv4 TTL by at least one; at zero it discards the packet and sends ICMP Time Exceeded to the source, so a looping packet dies after a bounded number of hops.

solid answer

~50 s

RFC 791 defined `TTL` as a lifetime in seconds, but RFC 1812 requires every router to decrement it by **at least one** even when it held the packet for far less than a second, so in practice it is a **hop limit**. When a decrement reaches zero, the router must discard the packet and, for a non-multicast destination, send ICMP Time Exceeded (code 0, TTL exceeded in transit) to the source. During a **transient routing loop**, say two routers each pointing a prefix at the other while routing converges, a packet bounces between them losing one per hop until it reaches zero. A packet sent with TTL *N* can be forwarded at most *N*−1 times. TTL does not repair the loop: every new packet loops too until the routing is fixed. IPv6 keeps the same role in its **Hop Limit** field (RFC 8200).

go deeper

for a junior

Recall that every router lowers the TTL by at least one, and at zero the packet is dropped and the source gets ICMP Time Exceeded.

for a middle

Trace a loop hop by hop with real TTL values, get the off-by-one right, and explain why local delivery is checked before the TTL.

for a senior

Read the symptoms of a transient loop: Time Exceeded for traffic that should arrive, extra load on one link, and the problem ending only when routing converges.

for a principal

Discuss TTL as damage containment rather than a cure, and what initial values trade between surviving long paths and limiting loop cost.

## What the TTL field is The **Time to Live** (`TTL`) is an **8-bit** field in the IPv4 header, so it holds 0 to 255. The **sender** chooses the initial value. RFC 791 defined it in **seconds**, as an upper bound on how long a datagram may exist. RFC 1812 then required every router that forwards a packet to reduce it by **at least one**, "even if the elapsed time was much less than a second", and made the time-based decrement optional (a router *may* subtract one per second it holds a packet). Since nearly every hop takes far less than a second, the `TTL` behaves as a **hop count limit**. RFC 1812's discussion says why this matters: the hop-count function "is critical to ensuring that routing problems can't melt down the network by causing packets to loop infinitely". IPv6 kept the idea and renamed the field **Hop Limit** (RFC 8200), because IPv6 nodes are not required to enforce a lifetime in seconds. ## The rule at each router 1. Check whether the packet is addressed to the router itself. RFC 1812 says a router must check the `TTL` only when **forwarding**, and must accept a valid packet addressed to it even if it arrived with `TTL` 0 or 1. 2. When forwarding, decrement the `TTL` by at least one. 3. If the result is zero, **discard** the packet and, unless the destination is multicast, send an ICMP **Time Exceeded** message, code 0 ("time to live exceeded in transit"), to the **source**. The details of that message, and how path-tracing tools exploit it, are a subject of their own. 4. Otherwise recompute the header checksum, since a header field changed, and continue forwarding. RFC 1812 allows the router to update the checksum incrementally when the `TTL` is the only field that changed, instead of recomputing it from scratch. Two further RFC 1812 rules: a router must never originate or forward a packet with `TTL` 0, and must not discard a unicast packet early just because it predicts a later router will drop it. ## A transient routing loop, traced Routers R1 and R2 share a link. A link failure makes R1 point `10.1.1.0/24` at R2, while R2, not yet updated, still points that prefix at R1. A packet from `192.0.2.10` to `10.1.1.7` reaches R1 with `TTL` 6: | Step | Router | TTL received | Action | |---|---|---|---| | 1 | R1 | 6 | forward to R2 with 5 | | 2 | R2 | 5 | forward to R1 with 4 | | 3 | R1 | 4 | forward to R2 with 3 | | 4 | R2 | 3 | forward to R1 with 2 | | 5 | R1 | 2 | forward to R2 with 1 | | 6 | R2 | 1 | decrements to 0: discard, Time Exceeded to `192.0.2.10` | The packet was forwarded five times, and the sixth router to receive it dropped it. In general a packet sent with `TTL` *N* can be forwarded at most *N*−1 times; the *N*th router to receive it discards it if it has not been delivered. ## What TTL does and does not do - It **bounds each packet's damage**: a looping packet consumes a limited number of link crossings instead of circling forever and piling up with every new packet. - It does **not fix the loop**. Each new packet for `10.1.1.0/24` loops too, until the routing process converges and one router points the prefix elsewhere. - It **limits reach by design**: a packet that arrives at a router with `TTL` 1 and must be forwarded dies there, so the sender's initial value caps how many routers the packet can cross. - It **cannot tell a loop from a long path**. A sender that chooses too small an initial value will see its packets die on a legitimate long route. - While a loop lasts, the looping links carry several copies' worth of traffic and the source receives Time Exceeded messages for packets it expected to be delivered. ## Common confusions - Thinking routers leave `TTL` alone when they are fast, because it is "in seconds". - Sending the Time Exceeded error to the destination: it goes to the packet's **source**, the party that chose the initial value and can act on it. - Confusing the IP `TTL` with a DNS record's TTL, which is a cache lifetime in seconds and unrelated to forwarding.

  • Does the IPv4 TTL stop a routing loop?
    No. It limits how long each packet survives, so no single packet circles forever, but the loop persists until routing converges. Meanwhile every new packet for the affected prefix circles the loop until its TTL runs out and is then discarded, the looping links carry extra load, and the senders get ICMP Time Exceeded messages instead of delivery.
  • If the IPv4 TTL is named for time, does any router actually count seconds?
    RFC 791 defined it in seconds, but RFC 1812 made the per-hop decrement of at least one mandatory and the per-second decrement optional: a router may subtract one for each second it holds a packet. Most treat it as a pure hop count. RFC 8200 renamed the IPv6 field Hop Limit because IPv6 nodes are not required to enforce a packet lifetime.

saying these in an interview costs you the question

  • TTL counts seconds, so a fast network never decrements it.
  • The router that drops a packet at TTL zero notifies the destination.
  • TTL fixes a routing loop by itself once packets start expiring.
  • A router drops any packet arriving with TTL 1, even one addressed to itself.
  • IPv6 dropped the hop limit idea entirely.