Retrospective: a day in the life of a web page request

Bob connects his laptop to his school's Ethernet switch and opens a Web page such as www.google.com.

Before the page can load, several networking protocols need to cooperate:

To keep things simple, we omit a number of additional protocols and considerations:

1. DHCP

Bob connects his laptop to the school's Ethernet switch.

The switch connects the laptop to the school's router, which connects the school network to the ISP. In this example, the ISP (comcast.net) also provides the school's DNS service.

The laptop does not yet have an IP address, so it initiates a DHCP exchange to request network information:

The laptop broadcasts a DHCP message placed inside:

Protocol Destination Source Layer
DHCP request DHCP server DHCP client Application
UDP segment Port 67 (DHCP server) Port 68 (DHCP client) Transport
IP datagram 255.255.255.255 (broadcast) 0.0.0.0 Network
Ethernet frame FF:FF:FF:FF:FF:FF (broadcast) 00:16:D3:23:68:8A (Bob's laptop) Link

Because the Ethernet frame is addressed to the broadcast MAC address, the switch floods it out all ports except the incoming one.

The router, which runs the DHCP server, receives the Ethernet frame:

The DHCP server assigns Bob:

It sends this information back (unicast) in a DHCP reply placed inside:

Protocol Destination Source Layer
DHCP reply DHCP client DHCP server Application
UDP segment Port 68 (DHCP client) Port 67 (DHCP server) Transport
IP datagram 68.85.2.101 (Bob's laptop) 68.85.2.1 (router) Network
Ethernet frame 00:16:D3:23:68:8A (Bob's laptop) 00:22:6B:45:1F:1B (router) Link

The Ethernet switch receives the Ethernet frame:

Bob's laptop receives the DHCP ACK and stores:

Now the laptop is ready to communicate.

2. DNS

When Bob types www.google.com into his browser.

The browser needs Google's IP address before it can create a TCP socket to connect.

So it needs to send a DNS query message encapsulated into an Ethernet frame.

However, the laptop knows only the router's IP address, not its MAC address.

3. ARP

Before it can send the Ethernet frame containing the DNS request, the laptop must find the router's MAC address.

It creates an ARP query request.

ARP operates at the link layer and does not use UDP or IP encapsulation, so ARP messages are carried directly inside Ethernet frames:

Protocol Destination Source Layer
ARP request All hosts on the LAN ARP client ("Who has IP address 68.85.2.1?") Link/Network
Ethernet frame FF:FF:FF:FF:FF:FF (broadcast) 00:16:D3:23:68:8A (Bob's laptop) Link

The switch broadcasts this message.

The router recognizes its own IP address and replies (unicast) with an ARP reply:

Protocol Destination Source Layer
ARP reply ARP client Owner of 68.85.2.1 ("I am 68.85.2.1 and my MAC address is 00:22:6B:45:1F:1B") Link/Network
Ethernet frame 00:16:D3:23:68:8A (Bob's laptop) 00:22:6B:45:1F:1B (router) Link

The frame is sent to the switch, which delivers the frame to Bob's laptop.

Now Bob's laptop knows how to send Ethernet frames to the router.

4. DNS (bis)

Bob's laptop is now able to send the Ethernet frame containing a DNS query to the gateway router's MAC address:

Protocol Destination Source Layer
DNS query DNS server (www.google.com lookup) DNS client Application
UDP segment Port 53 (DNS server) Ephemeral port (DNS client) Transport
IP datagram 68.87.71.226 (DNS server) 68.85.2.101 (Bob's laptop) Network
Ethernet frame 00:22:6B:45:1F:1B (router) 00:16:D3:23:68:8A (Bob's laptop) Link

The school's router receives the DNS request:

Routers along the way continue forwarding the packet until it reaches the DNS server.

The DNS server:

The DNS server returns a DNS reply containing the hostname-to-IP-address mapping placed inside:

Protocol Destination Source Layer
DNS reply DNS client DNS server Application
UDP segment Ephemeral port (DNS client) Port 53 (DNS server) Transport
IP datagram 68.85.2.101 (Bob's laptop) 68.87.71.226 (DNS server) Network
Ethernet frame 00:16:D3:23:68:8A (Bob's laptop) 00:22:6B:45:1F:1B (router) Link

This datagram is forwarded back through the Comcast network to the school's router and from there, via the Ethernet switch to Bob's laptop.

Bob's laptop extracts the IP address of the server www.google.com from the DNS message.

Bob's laptop now knows Google's IP address.

5. TCP

The browser can now contact Google's server.

The browser asks the operating system to create a TCP socket and initiate a connection to Google's server.

TCP must first perform a three-way handshake with www.google.com:

1. TCP SYN (Bob's laptop requests a connection):

Protocol Destination Source Layer
TCP SYN segment Port 80 (Google HTTP server) Ephemeral port (Bob's browser) Transport
IP datagram 64.233.169.105 (Google server) 68.85.2.101 (Bob's laptop) Network
Ethernet frame 00:22:6B:45:1F:1B (router) 00:16:D3:23:68:8A (Bob's laptop) Link

2. TCP SYN-ACK (Google's server accepts the request):

Protocol Destination Source Layer
TCP SYN-ACK segment Ephemeral port (Bob's browser) Port 80 (Google HTTP server) Transport
IP datagram 68.85.2.101 (Bob's laptop) 64.233.169.105 (Google server) Network
Ethernet frame Next-hop router (Google's gateway) Google server's MAC address Link

3. TCP ACK (Bob's laptop confirms the connection):

Protocol Destination Source Layer
TCP ACK segment Port 80 (Google HTTP server) Ephemeral port (Bob's browser) Transport
IP datagram 64.233.169.105 (Google server) 68.85.2.101 (Bob's laptop) Network
Ethernet frame 00:22:6B:45:1F:1B (router) 00:16:D3:23:68:8A (Bob's laptop) Link

The socket on Bob's laptop is now ready to send bytes to www.google.com.

6. HTTP

Bob's browser creates the HTTP GET message containing the URL to be fetched:

GET / HTTP/1.1
Host: www.google.com

The HTTP GET message is placed inside:

Protocol Destination Source Layer
HTTP GET request www.google.com Bob's browser Application
TCP segment Port 80 (Google HTTP server) Ephemeral port (Bob's browser) Transport
IP datagram 64.233.169.105 (Google server) 68.85.2.101 (Bob's laptop) Network
Ethernet frame 00:22:6B:45:1F:1B (router) 00:16:D3:23:68:8A (Bob's laptop) Link

The request travels through: Bob's laptop → school switch → school router → Comcast network → Google's network → Google server.

Google's web server receives the request, reads it and generates the response.

It sends the page data back through the TCP socket:

Protocol Destination Source Layer
HTTP response Bob's browser www.google.com Application
TCP segment Ephemeral port (Bob's browser) Port 80 (Google HTTP server) Transport
IP datagram 68.85.2.101 (Bob's laptop) 64.233.169.105 (Google server) Network
Ethernet frame Next-hop router (Google's gateway) Google server's MAC address Link

The response travels back: Google server → Google's network → Comcast network → school router → school switch → Bob's laptop.

The browser receives the HTML, processes it, and displays the web page.

Previous VLANs All ⏎ Next Introduction to wireless networks

A Kemar Joint