When a laptop sends an IPv4 packet to a server through two routers, which addresses change at each hop and which stay the same?
answer
- a frame lives for one link
- router strips and rebuilds
- next hop vs final destination
- TTL is the IP field that moves
basics
~20 sThe MAC addresses change on every link, because each router strips the incoming frame and builds a new one. The IP addresses and ports stay the same end to end (NAT aside), while the TTL drops at each router.
solid answer
~40 sA frame only lives on one link. The laptop sees the server is off-link, so it addresses the frame to its default gateway's MAC while the IP destination stays the server's address. The first router strips that frame, decrements the IPv4 TTL (and so updates the header checksum), picks the next hop and builds a **new** frame with its own outgoing MAC as source and the second router's MAC as destination. The second router does the same toward the server. So the MAC pair is rewritten on every link, while the IP source and destination and the TCP or UDP ports arrive unchanged, unless a NAT device rewrites them on purpose. Switches along the way forward frames without changing either MAC.
go deeper
Remember the one-liner: MAC addresses change on every link, IP addresses stay end to end, and the laptop's first frame goes to the default gateway's MAC.
Walk the hops: the router strips the frame, decrements TTL, updates the IPv4 checksum, and builds a new frame with its own outgoing MAC and the next hop's MAC.
Use the model to read captures and incidents: whose MAC appears on each segment, why a TTL shows the hop count, and where NAT or a tunnel breaks the simple picture.
Expect the discussion to move to design: where address rewriting (NAT, overlays, tunnels) belongs, and what it costs in debuggability and in transport checksums.
## The setup A laptop `L` at `192.0.2.10` on LAN A sends a TCP segment to a server `S` at `203.0.113.20` on LAN C. Between them are two routers: `R1` joins LAN A to a transit link B, and `R2` joins link B to LAN C. Each router interface has its own **MAC address** (`R1a` on LAN A, `R1b` on link B, and so on). There is no NAT on the path. The key rule: **a frame is scoped to one link; an IP datagram is scoped to the whole path.** The link-layer header answers "which interface on *this* wire gets it next?"; the IP header answers "which host is it ultimately for?". ## Hop by hop | Link | Source MAC | Destination MAC | Source IP | Destination IP | IPv4 TTL | |---|---|---|---|---|---| | LAN A (L → R1) | `L` | `R1a` | 192.0.2.10 | 203.0.113.20 | t | | Link B (R1 → R2) | `R1b` | `R2b` | 192.0.2.10 | 203.0.113.20 | t − 1 | | LAN C (R2 → S) | `R2c` | `S` | 192.0.2.10 | 203.0.113.20 | t − 2 | The TCP ports inside never change either. `t` is whatever initial TTL the laptop's stack chose: RFC 1122 requires a host to set it and to make a fixed value configurable, and the common starting values are implementation choices. ## What each device actually does 1. **The laptop** compares the destination with its own address and mask (RFC 1122 §3.3.1.1). The server is not on a connected network, so the datagram must go to a gateway on a connected network (§3.3.1). The laptop resolves the **gateway's** IP address to a MAC address with ARP (§2.3.3 makes ARP the mechanism on Ethernet) and puts `R1a` in the destination MAC. The gateway's IP address never appears in the packet. 2. **R1** accepts the frame because it is addressed to `R1a`, checks it, and **discards the whole link header and trailer**. It looks up the IP destination, decrements the TTL, updates the IPv4 header checksum (the TTL is part of the checksummed header), and hands the datagram to its outgoing interface on link B, which builds a brand-new frame: source `R1b`, destination `R2b`. 3. **R2** repeats the process and builds a frame from `R2c` to `S`. 4. **The server** accepts the frame, strips it, sees its own IP address, and passes the segment to TCP, which sees the laptop's address and port as the peer. Because the frame is rebuilt from scratch, the link technology can differ per hop — Ethernet on LAN A, a point-to-point link on B, Wi-Fi on LAN C — and the IP datagram rides through all of them. ## What stays the same, and why - **Source and destination IP addresses** are the end-to-end identifiers. The server answers to the source address it received; if routers rewrote them, the reply could not find its way back. - **Transport ports** sit inside the IP payload. A plain router forwards on the IP header and never needs to open the transport header. - **The payload** is untouched. ## What does change besides the MACs - **TTL / Hop Limit.** Each IPv4 gateway reduces the TTL by at least one (RFC 1122 §3.2.1.7); IPv6 names the field Hop Limit and decrements it by 1 per forwarding node (RFC 8200 §3). A packet that reaches zero in transit is discarded, which is what breaks routing loops. - **The IPv4 header checksum**, because the TTL it covers just changed. IPv6 has no header checksum, so an IPv6 router only decrements the Hop Limit. - **Fragmentation**, if an IPv4 router must split the datagram for a smaller next-hop MTU, changes length and offset fields; that mechanism belongs to the fragmentation topic. ## The exceptions to name in an interview - **NAT** deliberately rewrites IP addresses (and usually ports) at the boundary, which is why "the IP pair stays" is qualified with "NAT aside". - **Switches** are link-layer relays: they forward a frame toward the right port on the same link and do **not** replace the MAC addresses. A capture on the server's LAN shows the last router's MAC, not the switch's. - **Tunnels** add an outer IP header whose addresses are the tunnel endpoints; the inner header still carries the original pair. ## Common mistakes - Putting the server's MAC in the laptop's first frame: the laptop cannot know it, and it is not on the laptop's link. - Saying routers rewrite the destination IP to the next router's address: next-hop choice is expressed only in the link header. - Saying nothing in the IP header changes: the TTL always does.
- How does the laptop learn which MAC address to put in its first IPv4 frame to a remote server?It decides the destination is off-link by comparing addresses under its mask, so the next hop is its default gateway. It resolves the gateway's IPv4 address to a MAC with ARP and uses that MAC as the frame destination, while the IP destination stays the server. IPv6 does the same job with Neighbor Discovery.
- When do the IP addresses change on the way from the laptop to the server?Only when a device rewrites them on purpose, which is NAT: a translator changes the private source address (and usually the port) to a public one and must fix the transport checksum too. A tunnel does not change them; it wraps the original datagram in an outer IP header with the endpoints' addresses.
- Why must an IPv4 router update the header checksum at each hop while an IPv6 router does not?The IPv4 header checksum covers the whole header, including the TTL that every router decrements, so it must be updated each hop. IPv6 dropped the header checksum and relies on link-layer and transport checksums, so an IPv6 router only decrements the Hop Limit.
saying these in an interview costs you the question
- The laptop puts the server's MAC address in its first frame.
- Each router rewrites the destination IP address to the next router's address.
- The IP addresses change at every hop, just like the MAC addresses.
- A switch on the path replaces the source MAC with its own.
- Nothing in the IPv4 header changes while the packet crosses routers.