skip to content

IPv4

The 32-bit version most networks still run: dotted-decimal addresses, a 20-byte header with TTL and fragmentation fields, and routers that split big packets. Packet captures assume you can read it.

on this pageshow

questions

16

In IPv4, how is a 32-bit address written in dotted decimal, and how does the subnet mask split it into network and host parts?

level: juniorimportance: must knowfreq 78%

answer

  1. four octets, each with a ceiling
  2. the mask's ones versus zeros
  3. a bitwise operation on two values
  4. same result means same link

basics

~20 s

An IPv4 address is 32 bits written as four decimal octets, each 0-255, such as 198.51.100.37. The subnet mask's one-bits mark the network part and its zero-bits the host part; ANDing address and mask gives the network.

solid answer

~40 s

An IPv4 address is a 32-bit number. **Dotted decimal** writes it as four 8-bit octets in decimal, each 0-255: `198.51.100.37` is `11000110.00110011.01100100.00100101`. The address alone does not say where the network ends; the **subnet mask** does. Its leading one-bits mark the **network part** and the remaining zero-bits the **host part**, so with `255.255.255.0` the network is `198.51.100.0` and the host is `37`. A host uses this on every send: it ANDs the destination with its own mask, and if the result equals its own network it delivers directly on the link; otherwise it hands the datagram to a router. The mask is local configuration, never carried in the IPv4 header, and today it is always contiguous ones then zeros, which is why it can be written as a prefix length.

code

pseudocode · 12 lines
pseudocode
# on-link test a host runs before each send (RFC 950)
my_addr = 203.0.113.77
my_mask = 255.255.255.192
dest    = 203.0.113.130

my_net   = my_addr AND my_mask   # 203.0.113.64
dest_net = dest    AND my_mask   # 203.0.113.128

if dest_net == my_net:
    send_on_link(dest)            # not taken here
else:
    send_on_link(default_gateway) # taken: .128 differs from .64

go deeper

for a junior

Recall that an IPv4 address is 32 bits in four octets of 0 to 255, and that the mask's ones mark the network part and its zeros the host part.

for a middle

Explain the bitwise AND that extracts the network and how a host uses it to decide between delivering on the link and sending to its router. Note that the mask is configuration, not a header field.

for a senior

Diagnose symptoms of mismatched masks on one link, such as asymmetric paths through a router, and explain why an address without its mask is ambiguous since classless addressing.

for a principal

Weigh addressing plans by how hosts will apply masks: consistent masks per link, clear documentation of boundaries, and the operational cost when a boundary has to move later.

## An IPv4 address is a 32-bit number RFC 791 (September 1981) fixes every IPv4 address at **four octets, 32 bits**. That gives 2^32 = 4,294,967,296 possible values. Nothing inside those bits labels itself as "network" or "host"; the address is just a number. People do not read 32-bit binary comfortably, so the address is written in **dotted decimal**: each 8-bit octet is converted to a decimal number from 0 to 255, and the four numbers are joined with dots. | Octet | Binary | Decimal | |---|---|---| | 1st | `11000110` | 198 | | 2nd | `00110011` | 51 | | 3rd | `01100100` | 100 | | 4th | `00100101` | 37 | So `198.51.100.37` and `11000110.00110011.01100100.00100101` are the same address. No octet can exceed 255, because eight bits hold only 256 values, 0 through 255. ## What the subnet mask adds The **subnet mask** is a second 32-bit value, configured alongside the address, that says where the network part ends: - its **one-bits** mark the **network part** (the bits every host on that network shares); - its **zero-bits** mark the **host part** (the bits that tell hosts on the network apart); - the mask is configured on each host and router interface; it is **not** carried in the IPv4 header, so a packet on the wire never says what mask its sender uses. RFC 950 (1985) introduced the mask for subnetting, and RFC 1122 requires every host to support it: each local address has an address mask associated with it. Applying the mask is a **bitwise AND**. Take `203.0.113.77` with mask `255.255.255.192`: | | Last octet in binary | Decimal | |---|---|---| | Address `203.0.113.77` | `01001101` | 77 | | Mask `255.255.255.192` | `11000000` | 192 | | AND = network | `01000000` | 64 | The network is `203.0.113.64`, and the remaining six host bits (`001101`, 13) identify this host within it. The first three octets pass through unchanged because the mask is all ones there. ## How a host uses the split: on the link or via a router The split matters every time a host sends. RFC 950 spells out the test a host runs before each datagram: 1. AND the **destination** address with the host's own mask. 2. AND the host's **own** address with the same mask. 3. If the two results are equal, the destination is on the same network: deliver it **directly** on the link (on Ethernet, after resolving its hardware address). 4. If they differ, hand the datagram to a **router** (the default gateway), which forwards it on. From `203.0.113.77` with mask `255.255.255.192`, the destination `203.0.113.100` ANDs to `203.0.113.64` (same network, direct), while `203.0.113.130` ANDs to `203.0.113.128` (different network, via the router). A wrong mask therefore breaks connectivity in quiet ways: a host may try to reach a remote address directly, or send a neighbour's traffic to the router. ## Two host-part values that are not hosts RFC 1122 does not let a host part be all zeros or all ones except in special cases: - **All ones** in the host part is the **directed broadcast** for that network (`203.0.113.127` for the example above). It is a destination for every host on that network and must never be used as a source address. - **All zeros** in the host part is not assigned to a host; by convention it names the network itself, which is how RFC 4632 writes the legacy network `192.168.99.0`. RFC 3021 makes one exception: on a point-to-point link with a 31-bit mask, both remaining addresses are host addresses. Counting usable hosts in a block is subnet arithmetic, a separate subject. ## Public and private addresses Whether an address is **public** or **private** is a matter of allocation, not of format. A public address is globally unique and routed on the internet. RFC 1918 sets aside three blocks (`10.0.0.0`-`10.255.255.255`, `172.16.0.0`-`172.31.255.255`, `192.168.0.0`-`192.168.255.255`) that any organisation may reuse internally; they are unique only within an enterprise, and routes to them must not be propagated between enterprises. A private address has exactly the same 32-bit structure, and the mask works on it exactly the same way. ## Contiguous masks and prefix length RFC 950 allowed the mask's one-bits to be non-contiguous but recommended against it. RFC 1812 assumes every mask is a run of ones followed by zeros, which is why a mask can be written as a **prefix length**: `255.255.255.0` has 24 ones. Prefix notation itself is a separate subject. ## What interviewers listen for - The address alone does not reveal the network boundary; the mask does. - The mask is local configuration, not a header field. - The mask drives the on-link versus via-router decision on every send. - Private versus public is about allocation and routing, not a different address format.

  • Looking only at an IPv4 address such as 10.1.2.3, can you tell which part is the network?
    No. Since classless addressing replaced the classes in 1993, the network boundary is whatever the configured mask says: `10.1.2.3` could sit in a network with mask `255.0.0.0`, `255.255.0.0`, `255.255.255.0` or many others. Under the old classful scheme the first bits implied the boundary, which is exactly the assumption that no longer holds.
  • Two IPv4 hosts share a link: A is 203.0.113.77 with mask 255.255.255.0, B is 203.0.113.130 with mask 255.255.255.192. What happens when they talk?
    Each makes its own on-link decision. A ANDs B's address to `203.0.113.0`, its own network, so it delivers directly. B ANDs A's address to `203.0.113.64`, not its own `203.0.113.128`, so it sends replies to its router. The conversation works only if that router sends them back onto the same link: a classic cause of one-way or intermittent connectivity.

saying these in an interview costs you the question

  • The address itself shows which bits are the network part.
  • A dotted-decimal octet can go up to 256.
  • The subnet mask travels in every IPv4 header.
  • A host sends everything to the router, even neighbours on its own network.
  • Private addresses have a different format from public ones.
open as a page

In IPv4, how do unicast, limited broadcast, directed broadcast and multicast differ in who receives a datagram and which addresses signal them?

level: juniorimportance: must knowfreq 60%

basics

~20 s

Unicast reaches one interface. Limited broadcast, 255.255.255.255, reaches every host on the sender's link and is never routed. A directed broadcast (a network's all-ones host address) reaches every host on that remote network. Multicast, 224.0.0.0-239.255.255.255, reaches joined group members.

open as a page

In IPv4, what is the MTU, and what happens to a datagram that is larger than the next link's MTU?

level: juniorimportance: must knowfreq 52%

basics

~20 s

The MTU is the largest IP datagram, header included, that a link carries in one frame: 1,500 bytes on Ethernet. An IPv4 router fragments a bigger datagram and only the destination reassembles it; with Don't Fragment set, the router drops it instead.

open as a page

In IPv4, what does the Time to Live field do, and what happens when a router decrements it to zero?

level: juniorimportance: must knowfreq 60%

basics

~20 s

IPv4's Time to Live is an 8-bit counter each router decrements by at least one; a router that brings it to zero discards the datagram and, for unicast, returns ICMP Time Exceeded to the source, so looping packets cannot circulate forever.

open as a page

How does IPv4 Path MTU Discovery use the Don't Fragment flag to find the largest datagram a path can carry?

level: middleimportance: must knowfreq 42%

basics

~20 s

The source assumes the path MTU equals its first link's MTU and sets DF on every datagram. A router that cannot forward one drops it and returns an ICMP error carrying the next hop's MTU; the source lowers its estimate and sends smaller.

open as a page

What fields make up the 20-byte IPv4 header, and which does a router read in flight versus only the destination host?

level: middleimportance: must knowfreq 48%

basics

~20 s

The IPv4 header holds Version, IHL, DSCP/ECN, Total Length, Identification, Flags, Fragment Offset, TTL, Protocol, Header Checksum, source and destination addresses, then optional options. Routers chiefly read destination, TTL and checksum; the destination host uses Protocol and reassembly fields.

open as a page

An old network document calls an IPv4 subnet 'a class C network'; what did that originally mean, and why was classful addressing abandoned?

level: middleimportance: should knowfreq 46%

basics

~20 s

Originally a class C network had an address starting with bits 110 (first octet 192-223), a fixed 24-bit network and 254 hosts. Classes died from class B exhaustion and routing-table growth; CIDR replaced them in 1993.

open as a page

An IPv4 router must forward a 4,000-byte datagram with a 20-byte header onto a 1,500-byte MTU link; which fragments does it send?

level: middleimportance: should knowfreq 32%

basics

~20 s

Three fragments: 1,480 data bytes at offset 0 with MF set, 1,480 at offset 185 with MF set, and the last 1,020 at offset 370 with MF clear, all sharing one Identification. Only the destination reassembles; losing any fragment loses the datagram.

open as a page

What became of the IPv4 header's Type of Service byte, and what do its DSCP and ECN fields carry today?

level: middleimportance: should knowfreq 20%

basics

~20 s

RFC 2474 superseded the IPv4 Type of Service byte with a 6-bit DSCP that selects a per-hop forwarding behaviour, and RFC 3168 made the last 2 bits the ECN field, where a congested router can mark CE instead of dropping.

open as a page

An IPv4 header begins with the byte 0x46 and its Total Length reads 1,500; how long are the header, its options and the payload?

level: middleimportance: should knowfreq 28%

basics

~20 s

The high nibble 4 is the version and the low nibble 6 is IHL in 32-bit words, so the header is 24 bytes, 4 of them options. Total Length includes the header, so the payload is 1,500 minus 24: 1,476 bytes.

open as a page

When an IPv4 router forwards a datagram, which header fields does it change, and why must it update the header checksum at every hop?

level: middleimportance: should knowfreq 35%

basics

~20 s

An IPv4 router always decrements TTL, and because the Header Checksum covers the whole header, it must update the checksum too. A plain forwarding hop leaves addresses, Protocol and Identification alone; fragmenting, option processing or DSCP/ECN marking change more.

open as a page

An edge router forwards IPv4 directed broadcasts that arrive from the internet; why is that dangerous, and what does RFC 2644 require of routers?

level: seniorimportance: should knowfreq 24%

basics

~20 s

Forwarding outside directed broadcasts makes the network an amplifier: one forged echo request to its broadcast address draws replies from every answering host, all aimed at the victim. RFC 2644 updates RFC 1812 so routers block them by default.

open as a page

An IPv4 TCP connection completes its handshake and small requests, but large responses never arrive; how can Path MTU Discovery cause this, and what fixes it?

level: seniorimportance: should knowfreq 40%

basics

~20 s

The server sends full-size DF datagrams; a router before a narrower link drops them, but its fragmentation-needed ICMP error is filtered or never sent, so the server never shrinks. Fix the ICMP path, or use packetization-layer PMTUD (RFC 4821, RFC 8899).

open as a page

Why does RFC 8900 call IP fragmentation fragile, and what should a protocol that sends large IPv4 datagrams do instead?

level: seniorimportance: should knowfreq 24%

basics

~20 s

Fragments lack ports, which confuses firewalls, NAT and load balancers; one lost fragment loses the datagram; IPv4's 16-bit Identification wraps at high rates and splices data. RFC 8900 says new protocols should size to the path MTU instead.

open as a page

How do tiny-fragment and overlapping-fragment attacks use IPv4 fragmentation to slip past packet filters, and how are they blocked?

level: seniorimportance: nice to knowfreq 17%

basics

~20 s

A stateless filter judges only the first fragment. A tiny first fragment pushes TCP's flags into the second; an overlapping later fragment rewrites the header at reassembly. Filters drop TCP fragments at offset 1 and too-short first fragments (RFC 1858, RFC 3128).

open as a page

IPv4's Loose Source and Record Route option is still required of routers by RFC 1812, yet networks commonly discard source-routed packets; why, and what does the option let an attacker do?

level: seniorimportance: nice to knowfreq 12%

basics

~20 s

LSRR lets a sender list routers a datagram must visit, overriding normal routing, and the receiver reverses that list for replies. An attacker can bypass routing-based separation or spoof a trusted address and still receive replies, so many operators discard it.

open as a page