Stage 2: Packets & IP Addressing¶
Key takeaways
- Data is chopped into packets so many flows can share a link fairly and recover from loss cheaply
- Every packet has a header (control info) and a payload (actual data)
- IPv4 = 32-bit (~4.3B addresses, exhausted); IPv6 = 128-bit (practically inexhaustible)
- Routers move packets between networks by consulting a routing table
Why packets, not one continuous stream?¶
If you sent a whole file as one unbroken transmission, one bit error partway through would mean resending the entire thing, and no other device could use the link until you finished. Breaking data into packets means:
- Loss/corruption only costs you one small packet, not the whole transfer
- Multiple flows can interleave on the same physical link (fairness)
- Packets can take different paths and arrive out of order — the transport layer (TCP) reassembles them correctly
Packet anatomy¶
+------------------+------------------------+
| Header | Payload |
+------------------+------------------------+
source/dest IP, the actual data
protocol, TTL, etc.
The header is what routers and switches actually read to decide what to do with the packet — they generally never look at the payload (that's also a security/privacy boundary: a router doesn't need to know what you're sending, only where).
IP addressing¶
An IP address identifies a device's interface on a network — not the device itself (a device with two network interfaces has two IPs).
IPv4¶
- 32-bit, written as 4 decimal octets:
192.168.1.10 - Total space: ~4.3 billion addresses
- Exhausted as a public-address space years ago — this is the reason NAT and private IP ranges exist
IPv6¶
- 128-bit, written in hex groups:
2001:0db8:85a3:0000:0000:8a2e:0370:7334 - Address space so large that NAT is no longer functionally necessary (though it's sometimes still used for other reasons)
- Adoption has been slow because IPv4 and IPv6 aren't directly interoperable — this is a common "why hasn't the internet just switched" interview tangent
Subnet Mask and CIDR Notation¶
An IPv4 address consists of 32 bits divided into four 8-bit blocks called octets.
A subnet mask is also a 32-bit number that runs parallel to an IP address. Subnet masks tells about the network & host
portion of the IP Address
* Binary 1s in the subnet mask represent the Network Portion.
* Binary 0s in the subnet mask represent the Host Portion.
When a router or computer evaluates an IP address against its subnet mask, it performs a bitwise logical AND operation to determine the network ID.
Example 1: 192.168.1.0 with Subnet Mask 255.255.255.0 (/24)¶
This configuration is common in home networks and small office environments (traditionally associated with Class C networks).
Decimal Notation¶
- IP Address:
192.168.1.0 - Subnet Mask:
255.255.255.0
Binary Alignment¶
- IP Address:
11000000.10101000.00000001.00000000 - Subnet Mask:
11111111.11111111.11111111.00000000
Structure Analysis¶
- Network Portion (first 3 octets):
192.168.1(represented by 24 contiguous binary 1s) - Host Portion (last octet):
.0(represented by 8 binary 0s)
In this subnet, every device on the local network shares the prefix 192.168.1.x, allowing up to 254 unique assignable
host addresses (excluding network and broadcast addresses).
Summary Comparison¶
| IP Address | Subnet Mask | CIDR Prefix | Network Portion | Host Portion | Typical Use Case |
|---|---|---|---|---|---|
192.168.1.0 |
255.255.255.0 |
/24 |
192.168.1 |
.0 |
Small networks / Home routers |
172.16.1.0 |
255.255.0.0 |
/16 |
172.16 |
.1.0 |
Medium-to-large business networks |
10.0.1.0 |
255.0.0.0 |
/8 |
10 |
.0.1.0 |
Large enterprises / Datacenters |
Routers and routing tables¶
A router's job: look at a packet's destination IP, consult its routing table, and forward the packet out the correct interface toward that destination — one hop at a time.
A simplified routing table entry looks like:
| Destination network | Next hop | Interface |
|---|---|---|
| 192.168.2.0/24 | directly connected | Gig0/1 |
| 0.0.0.0/0 (default route) | 203.0.113.2 | Gig0/0 |
The 0.0.0.0/0 entry is the default route — "anything I don't have
a more specific match for, send here." This is how your home router
gets any packet destined for the internet to your ISP without needing
a table entry for every possible destination on Earth.
TTL (Time To Live)¶
Every IP packet carries a TTL field that decrements by 1 at each router
hop. When it hits 0, the packet is dropped and an error is sent back.
This exists purely to prevent packets from looping forever if a routing
loop occurs — it's also exactly what traceroute exploits to map a
path (it sends packets with deliberately increasing TTLs to force each
router along the way to respond).
Cloud connection
Cloud designs must reserve non-overlapping CIDRs for VPC subnets and, where applicable, Kubernetes Pods and Services. A load balancer, node, Pod, and Service may each use a different address because they are separate network endpoints or forwarding stages.
Practice in Packet Tracer¶
- Lab 02 — Router & Subnets: apply masks, gateways, and routed packet forwarding.
- Lab 07 — OSPF & eBGP: observe packets crossing several routed prefixes.