In IPv4, what does the Time to Live field do, and what happens when a router decrements it to zero?
answer
- one byte, set by the sender
- seconds on paper, hops in practice
- every forwarder subtracts at least one
- zero at a router means discard
- the source is told why
basics
~20 sIPv4's Time to Live is an 8-bit counter each router decrements by at least one; a router that brings it to zero discards the datagram and, for unicast, returns ICMP Time Exceeded to the source, so looping packets cannot circulate forever.
solid answer
~50 s`Time to Live` is an 8-bit field (0-255) set by the sending host. RFC 791 defined it in seconds, but because every module that handles the datagram must decrement it by at least one, RFC 1812 calls it effectively a hop-count limit. When a router's decrement takes it to zero, the router MUST discard the datagram and, unless the destination is multicast, send an ICMP Time Exceeded (type 11, code 0) to the source. Its job is damage control: during a routing loop each packet burns at most its TTL in hops and then dies. TTL is a forwarding check only — RFC 1122 says a host must not discard a datagram just because it arrived with TTL below 2. And since TTL sits inside the checksummed header, every decrement also means a header checksum update.
go deeper
Recall that TTL is an 8-bit counter every router decrements, that reaching zero means the router discards the datagram and sends ICMP Time Exceeded to the source, and that its purpose is killing looping packets.
Explain the seconds-versus-hops history, that only forwarding checks TTL so a destination accepts TTL 1, and that each decrement forces a header checksum update.
Show that TTL bounds a loop's damage rather than ending it, and reason from it during an incident: bursts of Time Exceeded from two alternating routers point at a loop while routing converges.
Weigh the initial TTL: too low and long paths fail with Time Exceeded, too high and looping packets live longer; RFC 1812 asks for at least the internet's diameter and suggests twice it.
## What the field is The **Time to Live** (`TTL`) is the first byte of the IPv4 header's third 32-bit word. It is **8 bits wide**, so it holds 0 to 255. The **sending host** chooses the starting value: RFC 1122 requires the IP layer to let the transport set it, and requires any fixed default to be configurable. RFC 1812 argues that a default must exceed the internet's "diameter" (the longest path), ideally twice it, and notes that **64 is a common value** — a convention, not a protocol constant. RFC 791 defines the unit as **seconds**: the field is "the maximum time the datagram is allowed to remain in the internet system". But the same paragraph requires every module that processes a datagram to decrease the TTL **by at least one even if it processed the datagram in less than a second**. Forwarding takes far less than a second, so in practice each router subtracts exactly one. RFC 1812 draws the conclusion: TTL is "effectively a hop count limit". (IPv6 renamed its equivalent field Hop Limit, matching the name to the practice.) ## What a router does with it RFC 1812 (sections 4.2.2.9 and 5.3.1) sets the order of operations for a forwarding router: 1. **Validate the header** — checksum, version 4, sane header and total lengths — and decide whether the datagram is addressed to the router itself. A router **MUST NOT check the TTL except when forwarding**, so a datagram addressed to the router is received even if it arrives with TTL 0 or 1. 2. **Reduce the TTL by at least one.** A router that holds a packet for more than a second MAY subtract one per second held. 3. **If the result is zero, discard the datagram.** Unless the destination is a multicast address, the router MUST send an ICMP **Time Exceeded** message, type 11, code 0 ("time to live exceeded in transit"), to the datagram's **source**. 4. **Otherwise update the header checksum and forward.** TTL is inside the header the checksum covers, so a new TTL means a new checksum. Two boundary rules complete the picture: - A router **MUST NOT originate or forward** a datagram with TTL zero. - A router **MUST NOT discard** a unicast or broadcast packet with a non-zero TTL merely because it predicts a later router will exhaust it. ## What the destination host does TTL guards **forwarding**, not delivery. RFC 1122: "A host MUST NOT discard a datagram just because it was received with TTL less than 2." A datagram that arrives at its destination with TTL 1 is delivered normally. A host also MUST NOT *send* a datagram with TTL zero, and a host that forwards datagrams for others is acting as a router and follows the router rules. ## Why the field exists: loops and lifetimes RFC 1122 names two jobs: **bound the lifetime of TCP segments** and **terminate routing loops**. The loop case is the one interviewers want. Suppose a link fails and, while the routing protocol converges, router A points 198.51.100.0/24 at router B while B still points it back at A. Every packet for that prefix now bounces between them. Without TTL each packet would bounce forever and the link would fill with immortal traffic. With TTL, a packet that started at 64 crosses the A-B link at most 64 times — fewer, since earlier hops spent part of its budget — and dies, and each discard sends a Time Exceeded back to its source. What TTL does **not** do matters as much: - It does **not fix the loop**. The routing protocol has to converge; TTL only makes each trapped packet mortal. - It does **not prevent the damage** while the loop lasts. Every trapped packet still crosses the loop many times, so the link can saturate. - It is **not checked by the destination**, and it says nothing about who sent the datagram. - It is **not** the TTL of a DNS record, which is a cache lifetime in seconds. ## A side effect everyone uses The router that exhausts a TTL reports from its own address. A sender that deliberately sets TTL to 1, then 2, then 3 therefore hears from each router in turn — the classic traceroute technique. How those probes and replies are built belongs with ICMP; the header's part is only the counter and the rule that a router reports its exhaustion. ## Two TTLs that are easy to confuse | | IPv4 Time to Live | DNS record TTL | |---|---|---| | Where it lives | IPv4 header, one byte | each DNS resource record | | What it counts | hops in practice (seconds on paper) | seconds a cache may keep the record | | Who decrements it | every router that forwards the datagram | the resolver's cache clock | | What zero means | datagram discarded, ICMP Time Exceeded to the source | record expires and is fetched again |
- During a routing loop between two IPv4 routers, does the TTL field stop the loop?No. TTL bounds each datagram's life, not the loop. Every packet caught in it still crosses the looping link again and again until its TTL runs out, so the link can saturate while the loop lasts, and only routing convergence ends it. What TTL guarantees is that trapped packets eventually die and that each discarding router sends ICMP Time Exceeded to the source.
- An IPv4 router receives a datagram addressed to one of its own interfaces with TTL 1; does it drop it?No. RFC 1812 says a router MUST NOT check the TTL except when forwarding, and MUST NOT discard a datagram just because it arrived with TTL zero or one: if it is addressed to the router and otherwise valid, the router must try to receive it. TTL guards forwarding; delivery to the final recipient, router or host, ignores it.
- Why does a TTL decrement force an IPv4 router to touch a second header field?The Header Checksum covers the whole IPv4 header, TTL included, so the decrement invalidates it. RFC 791 says the checksum is recomputed and verified wherever the header is processed, and RFC 1812 lets a router adjust it incrementally when TTL is the only field that changed, instead of summing the header again.
A ride pass with a fixed number of punches: every conductor punches one, and the conductor who punches the last one takes the rider off the train and notifies the issuer. The station the rider is heading for never checks how many punches are left.
saying these in an interview costs you the question
- TTL counts seconds, so a fast path never exhausts it however many routers it crosses.
- The destination host drops a datagram that arrives with a TTL of 1.
- TTL breaks a routing loop by making the routers fix their tables.
- A router that exhausts TTL drops the datagram silently and tells nobody.
- The IPv4 TTL and a DNS record's TTL are the same kind of countdown.