An IPv4 header begins with the byte 0x46 and its Total Length reads 1,500; how long are the header, its options and the payload?
answer
- two nibbles in the first byte
- IHL counts 32-bit words
- Total Length counts bytes, header included
- subtract the header, not 20
basics
~20 sThe high nibble 4 is the version and the low nibble 6 is IHL in 32-bit words, so the header is 24 bytes, 4 of them options. Total Length includes the header, so the payload is 1,500 minus 24: 1,476 bytes.
solid answer
~40 sThe first byte packs two 4-bit fields: `Version` = 4 and `IHL` = 6. `IHL` counts 32-bit words, so the header is 6 × 4 = 24 bytes — the 20-byte fixed part plus 4 bytes of options, padded to a word boundary. `Total Length` counts bytes and covers header plus data, so the payload is 1,500 − 24 = 1,476 bytes. The limits follow from the widths: a 4-bit `IHL` tops out at 15 words, 60 bytes, so options never exceed 40 bytes, and the minimum legal value is 5; a 16-bit `Total Length` caps a datagram at 65,535 bytes. A header with no options starts with `0x45`, which is why that byte is so familiar in captures.
go deeper
Recall that the first byte holds version and IHL, that IHL counts 32-bit words, and that 0x45 means a 20-byte header with no options.
Do the arithmetic aloud: header is IHL × 4, options are header minus 20, payload is Total Length minus header, and name the three different units in the header.
Use the length rules when a capture looks wrong: link padding past Total Length, a header longer than 20 bytes, or lengths a router must discard under RFC 1812.
Explain how the field widths fixed hard ceilings — 40 bytes of options, 65,535-byte datagrams — that later designs had to work around rather than extend.
## Decoding the first byte The first byte of every IPv4 header holds two **4-bit fields** (nibbles). Reading `0x46`: 1. **High nibble = `Version`.** `0x4` is 4: this is an IPv4 header (RFC 791). 2. **Low nibble = `IHL`.** `0x6` is 6. 3. **Convert IHL to bytes.** RFC 791: "Internet Header Length is the length of the internet header in 32 bit words". Six words × 4 bytes = **24 bytes**. 4. **Find the options.** The fixed header is 20 bytes, so 24 − 20 = **4 bytes of options** (including any padding). 5. **Find the payload.** `Total Length` is "the length of the datagram, measured in octets, including internet header and data". So the payload is 1,500 − 24 = **1,476 bytes**. | Quantity | Formula | Value | |---|---|---| | Header | IHL × 4 | 6 × 4 = 24 bytes | | Options and padding | header − 20 | 4 bytes | | Payload | Total Length − header | 1,500 − 24 = 1,476 bytes | The classic slip is subtracting 20 instead of the real header length, which would give 1,480 bytes and put the first four option bytes into the payload. ## Three units in one header The IPv4 header counts in three different units, and mixing them up is the commonest arithmetic mistake: | Field | Width | Unit | Range | |---|---|---|---| | `IHL` | 4 bits | 32-bit words | 5-15, so 20-60 bytes | | `Total Length` | 16 bits | bytes | up to 65,535 | | `Fragment Offset` | 13 bits | 8-byte blocks | position of a fragment's data | Each unit was chosen to fit its field. Four bits counted in bytes could not even describe the fixed 20-byte header, so `IHL` counts words, and RFC 791 pads options so the header always ends on a 32-bit boundary. `Total Length` has 16 bits and can afford bytes. `Fragment Offset` has 13 bits and must span a datagram of up to 65,535 bytes, so it counts 8-byte blocks; the arithmetic of fragments is its own subject. ## Limits that fall out of the widths - **Smallest header:** `IHL` = 5, 20 bytes. RFC 791 calls 5 "the minimum value for a correct header". - **Largest header:** `IHL` = 15, 60 bytes. RFC 791 notes that "the maximal internet header is 60 octets". - **Most option space:** 60 − 20 = **40 bytes**. That ceiling is why options such as Record Route can hold only a handful of addresses. - **Largest datagram:** 65,535 bytes, the 16-bit maximum of `Total Length`, header included. - **What every host must accept:** a 576-byte datagram, whole or in fragments (RFC 791, restated in RFC 1122). - **Familiar first bytes:** `0x45` is "IPv4, no options"; anything from `0x46` to `0x4F` means options are present. ## Validity checks a router applies RFC 1812 section 5.2.2 turns the arithmetic into rules. Before processing a packet a router must check that: 1. the link layer delivered at least 20 bytes; 2. the checksum is correct; 3. the version is 4; 4. `IHL` is at least 5; 5. `Total Length` is at least as large as the header length `IHL` implies. A packet failing any test **MUST be silently discarded**. If it passes the checksum and version tests and meets some minimal size conditions, the router MAY also send ICMP Parameter Problem pointing at the bad length field — but it still discards the packet. ## Where the datagram actually ends `Total Length`, not the frame, marks the end of the datagram. Links can carry extra bytes: an Ethernet data field must be at least **46 bytes**, so a small datagram — a 40-byte one, say — travels with 6 bytes of zero padding. RFC 894 states that this padding "is not part of the IP packet and is not included in the total length field". A receiver that trusted the frame length would hand those zeros to the transport as data. ## A worked second example A header starting `0x45` with `Total Length` 60: - `IHL` 5 → 20-byte header, no options. - Payload 60 − 20 = 40 bytes. - If the payload is a TCP segment, its own header length comes from TCP's data offset field, not from anything in the IP header.
- Why does the IPv4 IHL field count 32-bit words instead of bytes?It has only 4 bits, so counted in bytes it could describe at most 15 bytes — less than the fixed 20-byte header. Counted in 32-bit words it reaches 15 × 4 = 60 bytes, and because RFC 791 pads options so the header ends on a 32-bit boundary, a word count is always exact.
- An IPv4 datagram's IHL reads 5 but its Total Length reads 16; what does a router do with it?RFC 1812 requires Total Length to be at least the header length IHL implies, here 20 bytes, so the router MUST silently discard it and should log the error. If the checksum and version are good, it MAY also send ICMP Parameter Problem pointing at Total Length, but the datagram is never forwarded.
- An IPv4 datagram with Total Length 40 arrives in an Ethernet frame with a 46-byte data field; what are the other 6 bytes?Padding. An Ethernet data field must be at least 46 bytes, so the sender pads a short datagram with zeros. RFC 894 says that padding is not part of the IP packet and is not counted in Total Length, so the receiver uses Total Length to trim it before handing the payload up.
saying these in an interview costs you the question
- IHL counts bytes, so an IHL of 5 means a 5-byte header.
- Total Length is the payload's length and excludes the IPv4 header.
- Payload length is always Total Length minus 20, whatever IHL says.
- IPv4 options can add up to 60 bytes to the 20-byte header.
- Fragment Offset counts bytes, the same unit as Total Length.