skip to content

Header Format

Every IPv4 header field and who reads it in flight: routers read TTL and destination, endpoints read protocol, and DF and MF matter only when a packet is split. Interviewers pick fields at random.

on this pageshow

questions

6

In IPv4, what does the Time to Live field do, and what happens when a router decrements it to zero?

level: juniorimportance: must knowfreq 60%

answer

  1. one byte, set by the sender
  2. seconds on paper, hops in practice
  3. every forwarder subtracts at least one
  4. zero at a router means discard
  5. the source is told why

basics

~20 s

IPv4's Time to Live is an 8-bit counter each router decrements by at least one; a router that brings it to zero discards the datagram and, for unicast, returns ICMP Time Exceeded to the source, so looping packets cannot circulate forever.

solid answer

~50 s

`Time to Live` is an 8-bit field (0-255) set by the sending host. RFC 791 defined it in seconds, but because every module that handles the datagram must decrement it by at least one, RFC 1812 calls it effectively a hop-count limit. When a router's decrement takes it to zero, the router MUST discard the datagram and, unless the destination is multicast, send an ICMP Time Exceeded (type 11, code 0) to the source. Its job is damage control: during a routing loop each packet burns at most its TTL in hops and then dies. TTL is a forwarding check only — RFC 1122 says a host must not discard a datagram just because it arrived with TTL below 2. And since TTL sits inside the checksummed header, every decrement also means a header checksum update.

go deeper

for a junior

Recall that TTL is an 8-bit counter every router decrements, that reaching zero means the router discards the datagram and sends ICMP Time Exceeded to the source, and that its purpose is killing looping packets.

for a middle

Explain the seconds-versus-hops history, that only forwarding checks TTL so a destination accepts TTL 1, and that each decrement forces a header checksum update.

for a senior

Show that TTL bounds a loop's damage rather than ending it, and reason from it during an incident: bursts of Time Exceeded from two alternating routers point at a loop while routing converges.

for a principal

Weigh the initial TTL: too low and long paths fail with Time Exceeded, too high and looping packets live longer; RFC 1812 asks for at least the internet's diameter and suggests twice it.

## What the field is The **Time to Live** (`TTL`) is the first byte of the IPv4 header's third 32-bit word. It is **8 bits wide**, so it holds 0 to 255. The **sending host** chooses the starting value: RFC 1122 requires the IP layer to let the transport set it, and requires any fixed default to be configurable. RFC 1812 argues that a default must exceed the internet's "diameter" (the longest path), ideally twice it, and notes that **64 is a common value** — a convention, not a protocol constant. RFC 791 defines the unit as **seconds**: the field is "the maximum time the datagram is allowed to remain in the internet system". But the same paragraph requires every module that processes a datagram to decrease the TTL **by at least one even if it processed the datagram in less than a second**. Forwarding takes far less than a second, so in practice each router subtracts exactly one. RFC 1812 draws the conclusion: TTL is "effectively a hop count limit". (IPv6 renamed its equivalent field Hop Limit, matching the name to the practice.) ## What a router does with it RFC 1812 (sections 4.2.2.9 and 5.3.1) sets the order of operations for a forwarding router: 1. **Validate the header** — checksum, version 4, sane header and total lengths — and decide whether the datagram is addressed to the router itself. A router **MUST NOT check the TTL except when forwarding**, so a datagram addressed to the router is received even if it arrives with TTL 0 or 1. 2. **Reduce the TTL by at least one.** A router that holds a packet for more than a second MAY subtract one per second held. 3. **If the result is zero, discard the datagram.** Unless the destination is a multicast address, the router MUST send an ICMP **Time Exceeded** message, type 11, code 0 ("time to live exceeded in transit"), to the datagram's **source**. 4. **Otherwise update the header checksum and forward.** TTL is inside the header the checksum covers, so a new TTL means a new checksum. Two boundary rules complete the picture: - A router **MUST NOT originate or forward** a datagram with TTL zero. - A router **MUST NOT discard** a unicast or broadcast packet with a non-zero TTL merely because it predicts a later router will exhaust it. ## What the destination host does TTL guards **forwarding**, not delivery. RFC 1122: "A host MUST NOT discard a datagram just because it was received with TTL less than 2." A datagram that arrives at its destination with TTL 1 is delivered normally. A host also MUST NOT *send* a datagram with TTL zero, and a host that forwards datagrams for others is acting as a router and follows the router rules. ## Why the field exists: loops and lifetimes RFC 1122 names two jobs: **bound the lifetime of TCP segments** and **terminate routing loops**. The loop case is the one interviewers want. Suppose a link fails and, while the routing protocol converges, router A points 198.51.100.0/24 at router B while B still points it back at A. Every packet for that prefix now bounces between them. Without TTL each packet would bounce forever and the link would fill with immortal traffic. With TTL, a packet that started at 64 crosses the A-B link at most 64 times — fewer, since earlier hops spent part of its budget — and dies, and each discard sends a Time Exceeded back to its source. What TTL does **not** do matters as much: - It does **not fix the loop**. The routing protocol has to converge; TTL only makes each trapped packet mortal. - It does **not prevent the damage** while the loop lasts. Every trapped packet still crosses the loop many times, so the link can saturate. - It is **not checked by the destination**, and it says nothing about who sent the datagram. - It is **not** the TTL of a DNS record, which is a cache lifetime in seconds. ## A side effect everyone uses The router that exhausts a TTL reports from its own address. A sender that deliberately sets TTL to 1, then 2, then 3 therefore hears from each router in turn — the classic traceroute technique. How those probes and replies are built belongs with ICMP; the header's part is only the counter and the rule that a router reports its exhaustion. ## Two TTLs that are easy to confuse | | IPv4 Time to Live | DNS record TTL | |---|---|---| | Where it lives | IPv4 header, one byte | each DNS resource record | | What it counts | hops in practice (seconds on paper) | seconds a cache may keep the record | | Who decrements it | every router that forwards the datagram | the resolver's cache clock | | What zero means | datagram discarded, ICMP Time Exceeded to the source | record expires and is fetched again |

  • During a routing loop between two IPv4 routers, does the TTL field stop the loop?
    No. TTL bounds each datagram's life, not the loop. Every packet caught in it still crosses the looping link again and again until its TTL runs out, so the link can saturate while the loop lasts, and only routing convergence ends it. What TTL guarantees is that trapped packets eventually die and that each discarding router sends ICMP Time Exceeded to the source.
  • An IPv4 router receives a datagram addressed to one of its own interfaces with TTL 1; does it drop it?
    No. RFC 1812 says a router MUST NOT check the TTL except when forwarding, and MUST NOT discard a datagram just because it arrived with TTL zero or one: if it is addressed to the router and otherwise valid, the router must try to receive it. TTL guards forwarding; delivery to the final recipient, router or host, ignores it.
  • Why does a TTL decrement force an IPv4 router to touch a second header field?
    The Header Checksum covers the whole IPv4 header, TTL included, so the decrement invalidates it. RFC 791 says the checksum is recomputed and verified wherever the header is processed, and RFC 1812 lets a router adjust it incrementally when TTL is the only field that changed, instead of summing the header again.

A ride pass with a fixed number of punches: every conductor punches one, and the conductor who punches the last one takes the rider off the train and notifies the issuer. The station the rider is heading for never checks how many punches are left.

saying these in an interview costs you the question

  • TTL counts seconds, so a fast path never exhausts it however many routers it crosses.
  • The destination host drops a datagram that arrives with a TTL of 1.
  • TTL breaks a routing loop by making the routers fix their tables.
  • A router that exhausts TTL drops the datagram silently and tells nobody.
  • The IPv4 TTL and a DNS record's TTL are the same kind of countdown.
open as a page

What fields make up the 20-byte IPv4 header, and which does a router read in flight versus only the destination host?

level: middleimportance: must knowfreq 48%

basics

~20 s

The IPv4 header holds Version, IHL, DSCP/ECN, Total Length, Identification, Flags, Fragment Offset, TTL, Protocol, Header Checksum, source and destination addresses, then optional options. Routers chiefly read destination, TTL and checksum; the destination host uses Protocol and reassembly fields.

open as a page

What became of the IPv4 header's Type of Service byte, and what do its DSCP and ECN fields carry today?

level: middleimportance: should knowfreq 20%

basics

~20 s

RFC 2474 superseded the IPv4 Type of Service byte with a 6-bit DSCP that selects a per-hop forwarding behaviour, and RFC 3168 made the last 2 bits the ECN field, where a congested router can mark CE instead of dropping.

open as a page

An IPv4 header begins with the byte 0x46 and its Total Length reads 1,500; how long are the header, its options and the payload?

level: middleimportance: should knowfreq 28%

basics

~20 s

The high nibble 4 is the version and the low nibble 6 is IHL in 32-bit words, so the header is 24 bytes, 4 of them options. Total Length includes the header, so the payload is 1,500 minus 24: 1,476 bytes.

open as a page

When an IPv4 router forwards a datagram, which header fields does it change, and why must it update the header checksum at every hop?

level: middleimportance: should knowfreq 35%

basics

~20 s

An IPv4 router always decrements TTL, and because the Header Checksum covers the whole header, it must update the checksum too. A plain forwarding hop leaves addresses, Protocol and Identification alone; fragmenting, option processing or DSCP/ECN marking change more.

open as a page

IPv4's Loose Source and Record Route option is still required of routers by RFC 1812, yet networks commonly discard source-routed packets; why, and what does the option let an attacker do?

level: seniorimportance: nice to knowfreq 12%

basics

~20 s

LSRR lets a sender list routers a datagram must visit, overriding normal routing, and the receiver reverses that list for replies. An attacker can bypass routing-based separation or spoof a trusted address and still receive replies, so many operators discard it.

open as a page