2 · How a packet gets from A to B Network
OSI vs TCP/IP, encapsulation, MAC vs IP, switch vs router, same-subnet vs gateway
Why it matters for NPE. Every troubleshooting question is a packet-path question. Interviewers test whether you can walk a frame hop by hop and say which header changes where.
Primer: two addresses, two jobs
Every packet on an IP network carries two destination addresses. The IP address says where the packet is going end to end. The MAC address says who should pick it up on this link. Switches read MACs. Routers read IPs. The IP addresses normally stay the same for the whole trip; the MAC addresses are rewritten at every router. If you can say that sentence and draw it, you can answer most "walk me through it" questions.
Watch
The walk-through to reproduce on a whiteboard: 1:03 the three tables (routing, ARP, MAC), 5:48 packet from host A to B hop by hop, 14:23 the reply, 17:28 a second flow, and at 23:59 the exact interview question ("tell me what happens when browsing to a website").
Same walk with explicit source/destination MAC and IP at every hop (3:59 PC1→R1, 7:45 R1→R2, 11:43 R4→PC4, 14:18 the reply). Confirms "MAC changes per hop, IP does not".
Only if the layer table below is new to you. Watch 3:23-21:02 (layers, PDUs, OSI vs TCP/IP).
The host's own decision: local or remote, what to ARP for, which headers to build.
What each device does with a frame; the MAC-table learning part is what interviewers ask.
Text version with the same diagrams: Practical Networking, Packet Traveling series.
The layers you actually talk about
| OSI | TCP/IP | Unit | Address / identifier | Device that reads it | Interview vocabulary |
|---|---|---|---|---|---|
| 7 Application | Application | data | URL, hostname | host | HTTP, DNS, DHCP, SSH, BGP (yes, BGP is an application over TCP) |
| 6 Presentation | TLS encryption, encoding | ||||
| 5 Session | rarely used in practice | ||||
| 4 Transport | Transport | segment (TCP) / datagram (UDP) | port | host, firewall, load balancer | TCP, UDP, ports, sockets, handshake, retransmission |
| 3 Network | Internet | packet | IP address | router, L3 switch | IP, ICMP, routing, TTL, fragmentation |
| 2 Data link | Link | frame | MAC address | switch, bridge, NIC | Ethernet, ARP, VLANs, STP, MAC table |
| 1 Physical | bits | none | cable, optic, hub | speed, duplex, light levels, errors |
Say "layer 2" and "layer 3" fluently. Interviewers say "L2 problem" meaning switching, VLANs, ARP, MAC tables, and "L3 problem" meaning IP addressing and routing.
Encapsulation
Each layer wraps the one above and adds the fields it needs. The Ethernet EtherType (0x0800 = IPv4, 0x86DD = IPv6, 0x0806 = ARP) and the IP protocol field (6 = TCP, 17 = UDP, 1 = ICMP) tell the receiver which parser to hand the payload to. Ethernet frames carry at most 1500 bytes of payload by default (the MTU), so a TCP segment usually carries 1460 bytes of data (the MSS) after the 20-byte IP and 20-byte TCP headers.
The host's decision: same subnet or not?
A host with address 10.1.1.10/24 wants to send to 10.1.1.20. It ANDs both addresses with the mask 255.255.255.0: both give 10.1.1.0, so the target is local. It needs the target's MAC, so it ARPs for 10.1.1.20 and sends the frame directly.
Now it wants to send to 8.8.8.8. The AND gives 8.8.8.0, which is not 10.1.1.0, so the target is remote. The host looks up its route table, finds the default route via gateway 10.1.1.1, ARPs for the gateway's IP, and sends the frame to the gateway's MAC while the IP destination stays 8.8.8.8.
A packet's journey, hop by hop
- Host A decides B is remote, ARPs for the gateway 10.1.1.1, builds the frame to MAC r1a, dst IP 10.2.2.30, TTL 64.
- Switch S1 looks up dst MAC r1a in its MAC address table (learned from source MACs of earlier frames). Known → forward out that one port. Unknown → flood out all ports in the VLAN except the one it came in. It never changes the frame.
- Router R1 accepts the frame because the dst MAC is its own, strips the Ethernet header, reads dst IP 10.2.2.30, finds the longest-prefix match in its route table (say 10.2.2.0/24 via 203.0.113.2), decrements TTL to 63, recomputes the IP checksum, ARPs (or already knows) the MAC of 203.0.113.2, and builds a new Ethernet header: src r1b, dst r2a.
- Router R2 does the same; 10.2.2.0/24 is directly connected, so it ARPs for 10.2.2.30 itself and delivers to MAC bb with TTL 62.
- Host B checks the dst MAC is its own, the dst IP is its own, hands the segment to TCP by protocol number, and TCP hands the data to the socket bound to the dst port.
- The reply follows the same logic in reverse, and the return path can be different from the forward path (asymmetric routing). Always ask "and does the reply path work?" in a troubleshooting answer.
Three tables you must keep straight
| Table | Lives on | Maps | Filled by | Linux command |
|---|---|---|---|---|
| ARP cache / neighbor table | hosts and routers | IP on the local link → MAC | ARP request/reply (IPv6: NDP) | ip neigh |
| MAC address table (CAM) | switches | MAC → port (+ VLAN) | learning from source MACs; ages out (default 300 s on many switches) | bridge fdb show |
| Route table (RIB/FIB) | hosts and routers | destination prefix → next hop + interface | connected, static, dynamic (OSPF/IS-IS/BGP) | ip route |
What changes where (the summary table interviewers love)
| Field | Across a switch | Across a router | Across NAT |
|---|---|---|---|
| Source / dest MAC | unchanged | rewritten | rewritten (it's a router too) |
| Source / dest IP | unchanged | unchanged | source IP (and port) rewritten outbound |
| TTL | unchanged | −1 | −1 |
| Ports | unchanged | unchanged | source port may be rewritten (PAT) |
| VLAN tag | added/removed on trunk vs access ports | removed (router sees the packet) | n/a |
Interview questions
1. What is the difference between a switch and a router?
A switch forwards frames inside one broadcast domain using MAC addresses it learned from source addresses; it floods unknown destinations. A router forwards packets between networks using IP prefixes in a route table, rewrites the layer-2 header on each hop and decrements TTL. Follow-up: a layer-3 switch is a switch ASIC that can also route between VLANs.2. Which addresses change as a packet crosses three routers?
The source and destination MAC change at every router (each hop is a new frame). The IP addresses stay the same unless NAT is involved. TTL goes down by one per router.3. How does a host know whether to use ARP for the destination or for the gateway?
It ANDs its own IP and the destination with its subnet mask. Same result means local: ARP for the destination. Different means remote: look up the route table, usually the default route, and ARP for the next-hop IP.4. How does a switch build its MAC table, and what does it do with a frame to an unknown MAC?
It records the source MAC and ingress port of every frame it sees. An unknown unicast destination is flooded out every other port in that VLAN; the reply teaches the switch where that MAC lives. Broadcasts (like ARP requests) are always flooded.5. What is a broadcast domain and what bounds it?
The set of hosts that receive a layer-2 broadcast (dst MAC ff:ff:ff:ff:ff:ff). A router (or a VLAN boundary) bounds it. Switches extend it.6. What is TTL for, and what sends the message when it hits zero?
It prevents packets from looping forever. Each router decrements it; at zero the router drops the packet and sends an ICMP Time Exceeded back to the source. traceroute exploits this by sending probes with TTL 1, 2, 3…7. What is encapsulation?
Each layer adds its own header around the data from the layer above: HTTP data inside a TCP segment inside an IP packet inside an Ethernet frame. The receiver strips them in reverse, using the type/protocol/port fields to pick the next parser.8. What is the MTU and why does it matter?
The maximum payload a link can carry in one frame, 1500 bytes for standard Ethernet, often 9000 in data centers (jumbo frames). Packets bigger than the path MTU must be fragmented or, with the Don't Fragment bit set, dropped with an ICMP "fragmentation needed" message. If that ICMP is blocked, large transfers hang while small ones work.9. Why do we have both MAC and IP addresses?
MACs are flat, burned-in identifiers that only need to be unique on a link; they have no hierarchy, so you cannot route on them at Internet scale. IP addresses are hierarchical (prefixes) so routers can summarise millions of hosts into a few routes. The two layers can evolve independently: IP runs over Ethernet, Wi-Fi, and fiber alike.10. Describe what a router does with a packet in the order it does it.
Check the frame's dst MAC is mine and the FCS is valid; strip the L2 header; validate the IP header and check TTL > 1; longest-prefix-match the dst IP in the FIB; decrement TTL and fix the checksum; resolve the next hop's MAC via the neighbor table; build the new frame; queue it on the egress interface. Mention that this is the data plane, programmed by the control plane (routing protocols).Traps
- Saying the switch "routes" or that it looks at IP addresses. A plain switch never reads the IP header.
- Saying the destination MAC is the final server's MAC for a remote destination. It is the gateway's MAC.
- Forgetting that ARP is not an IP protocol: it sits directly on Ethernet (EtherType 0x0806) and does not cross routers.
- Confusing the ARP cache (IP → MAC, on hosts/routers) with the switch's MAC table (MAC → port).
- Claiming TTL is a time in seconds. It is a hop count in practice.
- Forgetting the return path. The reply needs its own route and its own ARP resolution at each hop.
- Memorising OSI layer names without being able to name the unit, the address and the device at each one.
Scenario
Host A (10.1.1.10/24, gateway 10.1.1.1) can ping 10.1.1.20 but not 10.2.2.30. Walk through what you check.
Expected reasoning
- Local works, so the NIC, cable, VLAN and ARP on the local link are fine. The problem starts at the gateway or beyond.
ip routeon A: is there a default route via 10.1.1.1?ip neigh: does 10.1.1.1 resolve to a MAC?ping 10.1.1.1.- If the gateway answers,
traceroute 10.2.2.30to see where replies stop. A stop after R1 means R1 has no route to 10.2.2.0/24, or R2 has no route back to 10.1.1.0/24 (check the return path!), or an ACL drops it. - On R1:
show ip route 10.2.2.30(orip route get 10.2.2.30on Linux). On R2: a route back to 10.1.1.0/24. - If both routes exist, suspect a filter: ACL or firewall between the sites, or host B's own firewall. Confirm with a capture on B: do the echo requests arrive? Do the replies leave?
← 1 · Python fluency for interviews · all topics · 3 · Hash maps, sets, counting and grouping →