IPv4

At the network layer, the Internet Protocol (IP) is responsible for moving packets between sending and receiving hosts.

IPv4 is the fourth version of IP.

IPv4 datagram format

IPv4 - Internet Protocol Version 4 (32 bits)
Offsets
(starting positions)
Octet 0 1 2 3
Octet Bit 4-7 0-3 8-15 16-18 19-23 24-31
0 0 Version Header Length Type of Service Total Length
4 32 16-bit Identifier 3-bit Flags 13-bit Fragment Offset
8 64 Time to Live Upper-layer protocol Header Checksum
12 96 32-bit Source IP Address
16 128 32-bit Destination IP Address
20 160 Options (if any)
24+ 192+ Data
Field Description

Version

Specify the IP protocol version.

Header length

An IPv4 datagram can contain a variable number of options.

These bits are used to determine where the payload actually begins.

Type of service (TOS)

Allows different types of IP datagrams to be distinguished from each other (e.g. real-time IP telephony traffic versus non-real-time FTP traffic).

The specific level of service is a policy issue determined and configured by the network administrator for that router.

Historically called the Type of Service (ToS) field. Modern networks interpret it as a DSCP field (6 bits) plus ECN (2 bits).

Total Length

Total length of the IP datagram (header plus data) in bytes.

Since this field is 16 bits long, the theoretical maximum size of an IP datagram is 65,535 bytes, although datagrams are rarely larger than 1,500 bytes.

Identifier, Flags, Fragmentation offset

Related to IP fragmentation.

IPv6 moved responsibility away from routers. Fragmentation may only be performed by the source host using the IPv6 Fragment extension header.

Time-to-live (TTL)

Ensures datagrams do not circulate forever (e.g. due to a routing loop).

The field is decremented by one at each router hop.

If the TTL reaches 0, the router must drop the datagram.

Upper-layer protocol

Used only when an IP datagram reaches its final destination.

Indicates the transport-layer protocol number to which the data portion should be passed. For example, 6 indicates TCP and 17 indicates UDP.

The protocol number plays a role analogous to the port number in a transport-layer segment: it binds the network layer to the transport layer, just as port numbers bind the transport layer to the application layer.

Header checksum

The checksum must be recomputed at every router because the TTL field is modified during forwarding.

IP checksums only the IP header, whereas TCP/UDP checksums cover the entire segment.

Error checking is performed at both the transport and network layers because IP can carry data that will not be passed to TCP/UDP.

Source and destination IP addresses

Contain the sender's and receiver's IP addresses.

Options

Optional field that allows the IP header to be extended.

It complicates processing because header lengths become variable, making it harder to determine where the data field begins.

Some datagrams require option processing while others do not, causing processing times to vary.

For these reasons, IPv6 does not include IP options in its header.

Data (payload)

The encapsulated data carried by the IP datagram.

Interfaces

A host:

A router:

IP addresses

IP requires each interface to have its own globally unique IP address (except behind NAT):

Subnet

A subnet is a group of interfaces that can communicate without passing through a router.

E.g., 1 router (with 3 interfaces) connects 7 hosts:

A router separates different subnets and acts as a boundary between them:

Three routers interconnecting six subnets

Different subnets can have very different addresses, but in practice their addresses often look similar because of how Internet addressing is structured.

The Internet's address assignment strategy

The Internet uses Classless Interdomain Routing (CIDR) (RFC 4632) to assign IP addresses:

An organization is given a block of consecutive IP addresses that all share the same prefix.

Routers outside the organization only look at the x prefix:

Inside the organization:

Before CIDR:

Broadcast address

IPv4 provides broadcast addresses that allow a packet to be delivered to all hosts on a subnet.

The special address 255.255.255.255 is the limited broadcast address (RFC 791):

Each subnet also has a directed broadcast address obtained by setting all host bits to 1:

Subnet Directed broadcast
192.168.1.0/24 192.168.1.255
10.1.0.0/16 10.1.255.255
172.16.4.0/22 172.16.7.255

Limited broadcast is used when you don't yet know the network structure; directed broadcast is used when you already know the subnet and want to reach all hosts in it.

Directed broadcast is now rarely used and often disabled due to security concerns, with multicast preferred instead.

Obtaining a host address: DHCP

When an organization receives a block of IP addresses, it assigns them to its devices interfaces:

DHCP automatically provides network settings to a device when it connects to a network:

Because DHCP handles these settings automatically, it is often called a plug-and-play protocol.

DHCP is a client-server protocol:

If there is no DHCP server on a subnet, a DHCP relay agent (usually a router) forwards requests to a DHCP server located elsewhere on the network.

When a device joins a network, DHCP assigns it an IP address through a four-step process:

Step Description

1. DHCP server discovery

The client needs to find a DHCP server:

  • it sends a DHCP Discover message within a UDP packet (destination port 67)
  • since the client does not yet know the IP address of the network to which it is attaching, it broadcasts the message:
    • Source IP = 0.0.0.0
    • Destination IP = 255.255.255.255 (broadcast)
  • the link layer then broadcasts this frame to all nodes attached to the subnet

2. DHCP server offer(s)

Several DHCP servers can be present on the subnet:

  • each server receives the DHCP Discover message
  • each server replies with a DHCP Offer message broadcast to all nodes on the subnet using 255.255.255.255
  • each offer message contains:
    • the transaction ID from the Discover message
    • a proposed IP address for the client (yiaddr = "your Internet address")
    • the subnet mask
    • an IP address lease time (the amount of time for which the IP address will be valid)

3. DHCP request

The client chooses one of the offers:

  • it sends a DHCP Request message indicating which offer it accepts
  • the request identifies the selected offer and requested IP address

4. DHCP ACK

The selected server responds with a DHCP ACK (Acknowledgment) message:

  • this confirms the IP address and configuration

DHCP also provides a mechanism that allows a client to renew its lease on an IP address.

A major limitation of DHCP is that a device receives a new IP address whenever it moves to a new subnet:

Network address translation (NAT)

When a small office or home office (SOHO) sets up a local area network (LAN), all devices need IP addresses.

A common solution is Network Address Translation (NAT) (RFC 2663, RFC 3022).

A NAT-enabled router makes the entire home network appear as a single device to the Internet:

Private IPs

The devices on the local network use private IP addresses:

The router gets its public IP address from the ISP's DHCP server.

The router then acts as a DHCP server and assigns private IP addresses to the computers and devices on the home network.

NAT translation table

How does a NAT router know which internal host should receive an incoming packet?

A NAT router uses a NAT translation table that maps internal IP addresses and port numbers to external port numbers.

Suppose host 10.0.0.1 requests a web page from 128.119.40.186 on port 80:

Step Details

1. The host sends the datagram into the LAN

  • source IP: 10.0.0.1
  • source port: 3345 (chosen by the host)

2. The NAT router modifies the datagram

  • replaces the source IP with its WAN-side public IP, e.g., 138.76.29.7
  • replaces source port 3345 with a new port, e.g., 5001
  • adds an entry to its NAT table:
    | Public IP   | Public Port | Private IP | Private Port |
    | ----------- | ----------- | ---------- | ------------ |
    | 138.76.29.7 | 5001        | 10.0.0.1   | 3345         |
    
  • since port numbers are 16 bits long, the NAT protocol can support at least 60,000+ simultaneous connections for a single IP address of a router
  • by using a 5-tuple flow identifier that includes the transport protocol (e.g. TCP or UDP), NAT can support many more simultaneous connections

3. The web server sends a reply

  • destination IP: 138.76.29.7
  • destination port: 5001

4. The NAT router receives the reply

  • looks up 138.76.29.7, 5001 in its NAT table
  • finds the matching internal host 10.0.0.1, 3345
  • rewrites the destination IP and port accordingly
  • forwards the datagram to 10.0.0.1

NAT critics

Some argue that:

More philosophical arguments:

Previous Router All ⏎ Next IPv6

A Kemar Joint