Why addressing matters
Every device that talks across the internet needs an address that routers can use to find it. That is the job of the IP address, the network-layer (layer 3) address carried in every IP packet. Unlike a MAC address, which only matters on one link, an IP address stays the same from source to destination and is hierarchical: part of it names a network, the rest names a host on that network. That split is what lets a router keep one table entry for a whole network of thousands of hosts.
Subnetting is the single most calculation-heavy topic in networking interviews and service-company aptitude rounds. You will be given an address like 172.16.45.200/20 and asked for the network address, broadcast address, usable range and host count, or asked to carve a block into subnets for departments of given sizes. This lesson teaches a method you can do on paper in under a minute, with seven worked problems checked using Python's ipaddress module.
The second half covers what surrounds addressing: NAT (how a whole home shares one public IP), the IPv4 header, fragmentation, ICMP (ping and traceroute), DHCP (how your laptop gets an address) and IPv6.
IPv4 address format
An IPv4 address is 32 bits, written in dotted decimal: four 8-bit groups (octets), each 0 to 255.
192 . 168 . 10 . 77
11000000 10101000 00001010 01001101
There are 2^32, about 4.3 billion, IPv4 addresses. That sounds like a lot but ran out at the global registry level in 2011, which is why NAT and IPv6 exist.
Binary refresher
You need to convert octets quickly. Memorise the place values of one octet:
bit: 128 64 32 16 8 4 2 1
77 = 64 + 8 + 4 + 1 = 01001101. 200 = 128 + 64 + 8 = 11001000.
The subnet mask values that appear in masks are runs of 1s from the left. Memorise this table; it does most of the work:
| Bits of 1s in octet | Binary | Decimal | Block size (256 - value) |
|---|---|---|---|
| 0 | 00000000 | 0 | 256 |
| 1 | 10000000 | 128 | 128 |
| 2 | 11000000 | 192 | 64 |
| 3 | 11100000 | 224 | 32 |
| 4 | 11110000 | 240 | 16 |
| 5 | 11111000 | 248 | 8 |
| 6 | 11111100 | 252 | 4 |
| 7 | 11111110 | 254 | 2 |
| 8 | 11111111 | 255 | 1 |
Network part, host part and the mask
An IP address splits into a network prefix (which network) and a host part (which device on it). The subnet mask says where the split is: 1 bits cover the network part, 0 bits the host part.
address 192.168.10.77 11000000.10101000.00001010.01001101
mask 255.255.255.224 11111111.11111111.11111111.11100000
|<------- network: 27 bits ------>|host
CIDR notation (Classless Inter-Domain Routing) writes the mask as a slash and the count of 1 bits: 192.168.10.77/27.
Two addresses in every subnet are reserved:
- Network address: host bits all 0. Names the subnet itself. Find it with
address AND mask. - Broadcast address: host bits all 1. Reaches every host on the subnet.
So a subnet with h host bits has 2^h addresses and 2^h - 2 usable hosts. (The exceptions are /31, used for point-to-point links with 2 usable addresses per RFC 3021, and /32, a single host route.)
Classful addressing (historical)
Before 1993, the first bits of an address fixed the size of its network. You still need to know this for interviews and for reading old material, but routing on the internet no longer uses classes.
| Class | First bits | First octet | Default mask | Networks | Hosts per network |
|---|---|---|---|---|---|
| A | 0 | 1 to 126 | /8 (255.0.0.0) | 126 | 16,777,214 |
| B | 10 | 128 to 191 | /16 (255.255.0.0) | 16,384 | 65,534 |
| C | 110 | 192 to 223 | /24 (255.255.255.0) | 2,097,152 | 254 |
| D | 1110 | 224 to 239 | none | multicast | - |
| E | 1111 | 240 to 255 | none | reserved | - |
127.0.0.0/8 is loopback (127.0.0.1 is "this host"), which is why class A usable networks stop at 126. 0.0.0.0/8 means "this network".
The problem with classes was waste. A company with 2,000 hosts was too big for a class C (254) and got a class B (65,534), wasting over 63,000 addresses. Routing tables also exploded because many small class C networks each needed an entry.
CIDR and private ranges
CIDR removed fixed classes. A prefix can be any length from /0 to /32, so a 2,000-host company gets a /21 (2,046 hosts). Registries hand out blocks of the right size, and ISPs can aggregate many customer blocks into one route.
Special and private ranges
Private addresses (RFC 1918) can be used freely inside any organisation but are never routed on the public internet. Routers on the internet drop them; NAT translates them to public addresses at the edge.
| Range | CIDR | Typical use |
|---|---|---|
| 10.0.0.0 to 10.255.255.255 | 10.0.0.0/8 | Large enterprises, cloud VPCs |
| 172.16.0.0 to 172.31.255.255 | 172.16.0.0/12 | Medium networks, Docker defaults |
| 192.168.0.0 to 192.168.255.255 | 192.168.0.0/16 | Home and small office routers |
Other special blocks worth knowing:
127.0.0.0/8: loopback.169.254.0.0/16: link-local (APIPA). A host gives itself one of these when DHCP fails, which is a classic troubleshooting clue.100.64.0.0/10: carrier-grade NAT shared space, used between ISPs and customers. Not RFC 1918 private.224.0.0.0/4: multicast.255.255.255.255: limited broadcast.
Common mistake
Thinking 172.0.0.0/8 is private. Only 172.16.0.0 to 172.31.255.255 is. So 172.31.255.1 is private but 172.32.1.1 is a public address.
The subnetting method
For any address and prefix, use the block size (also called the magic number):
- Find the interesting octet: the octet where the mask is neither 255 nor 0.
- Block size = 256 minus the mask value in that octet.
- The network address is the largest multiple of the block size that is less than or equal to the address's value in that octet. Octets to the right become 0.
- The broadcast address is network + block size - 1 in that octet; octets to the right become 255.
- Usable range: network + 1 to broadcast - 1.
- Usable hosts: 2^(host bits) - 2, where host bits = 32 - prefix.
Worked problems
Each answer below was verified with Python's ipaddress module; the script is at the end of this section.
Problem 1: 192.168.10.77/27
- /27 means 24 + 3 bits: the mask is
255.255.255.224. Interesting octet: the 4th. - Block size = 256 - 224 = 32. Subnets start at 0, 32, 64, 96, 128...
- 77 lies between 64 and 96, so the network is 192.168.10.64.
- Broadcast: 64 + 32 - 1 = 95, so 192.168.10.95.
- Usable range: 192.168.10.65 to 192.168.10.94.
- Host bits = 5, so 2^5 - 2 = 30 usable hosts.
77 = 010 | 01101 mask 224 = 111 | 00000
network = 010 | 00000 = 64
broadcast = 010 | 11111 = 95
Problem 2: 172.16.45.200/20
- /20 = 16 + 4: mask
255.255.240.0. Interesting octet: the 3rd. - Block size = 256 - 240 = 16. Third-octet subnets: 0, 16, 32, 48...
- 45 lies in 32 to 47. Network = 172.16.32.0 (4th octet becomes 0).
- Broadcast: third octet 32 + 16 - 1 = 47, fourth octet 255: 172.16.47.255.
- Usable range: 172.16.32.1 to 172.16.47.254.
- Host bits = 12, so 2^12 - 2 = 4,094 hosts.
Note how the 4th octet (200) is irrelevant to finding the network; it is all host bits.
Problem 3: 10.1.130.5 with mask 255.255.192.0
- 255.255.192.0 is /18 (8 + 8 + 2). Interesting octet: the 3rd.
- Block size = 256 - 192 = 64. Subnets: 0, 64, 128, 192.
- 130 lies in 128 to 191. Network = 10.1.128.0.
- Broadcast = 10.1.191.255.
- Usable range: 10.1.128.1 to 10.1.191.254.
- Host bits = 14, so 2^14 - 2 = 16,382 hosts.
Problem 4: are two hosts on the same subnet?
Hosts 10.0.5.130/25 and 10.0.5.100/25. Can they talk directly without a router?
- /25: mask 255.255.255.128, block size 128 in the 4th octet. Subnets start at 0 and 128.
- 130 is in the subnet starting at 128: network
10.0.5.128. - 100 is in the subnet starting at 0: network
10.0.5.0. - Different networks, so no: traffic between them must go through a router. Each host would send the frame to its default gateway rather than ARPing for the other host.
This is exactly the check a host does before every send.
Problem 5: split a /24 into equal subnets
Divide 192.168.1.0/24 into at least 6 equal subnets. Give the new mask, hosts per subnet and the subnet list.
- Subnets needed = 6. Borrow
nhost bits so that 2^n is at least 6: n = 3 gives 8 subnets. - New prefix = 24 + 3 = /27, mask 255.255.255.224.
- Host bits = 5, so 30 usable hosts per subnet.
- Block size 32. Subnets:
| # | Network | Usable range | Broadcast |
|---|---|---|---|
| 1 | 192.168.1.0/27 | .1 to .30 | .31 |
| 2 | 192.168.1.32/27 | .33 to .62 | .63 |
| 3 | 192.168.1.64/27 | .65 to .94 | .95 |
| 4 | 192.168.1.96/27 | .97 to .126 | .127 |
| 5 | 192.168.1.128/27 | .129 to .158 | .159 |
| 6 | 192.168.1.160/27 | .161 to .190 | .191 |
| 7 | 192.168.1.192/27 | .193 to .222 | .223 |
| 8 | 192.168.1.224/27 | .225 to .254 | .255 |
Two subnets are spare for growth. (Very old equipment did not allow the first, "subnet zero", or the last subnet; modern devices do, and interview answers should assume they are usable unless told otherwise.)
Problem 6: choose a mask for a host count
An organisation needs subnets of up to 500 hosts each from 10.0.0.0/8. What prefix should it use?
- Find the smallest
hwith 2^h - 2 at least 500. 2^8 - 2 = 254 is too small; 2^9 - 2 = 510 fits. So h = 9. - Prefix = 32 - 9 = /23, mask 255.255.254.0.
- Each subnet has 510 usable hosts. The /8 provides 2^(23 - 8) = 2^15 = 32,768 such subnets.
Problem 7: VLSM for departments
VLSM (variable-length subnet masking) gives each subnet a mask sized to its own needs instead of using one size for all. It saves addresses.
You are given 192.168.50.0/24. Allocate subnets for:
- Sales: 100 hosts
- Engineering: 50 hosts
- HR: 25 hosts
- Admin: 10 hosts
- Two point-to-point router links: 2 hosts each
Rule: sort by size, largest first, and allocate from the start of the block. Allocating large blocks first keeps every block aligned on its own boundary.
For each requirement, find the smallest block with 2^h - 2 at least the host count:
| Department | Hosts | Host bits | Block size | Prefix |
|---|---|---|---|---|
| Sales | 100 | 7 (126 usable) | 128 | /25 |
| Engineering | 50 | 6 (62 usable) | 64 | /26 |
| HR | 25 | 5 (30 usable) | 32 | /27 |
| Admin | 10 | 4 (14 usable) | 16 | /28 |
| Link A | 2 | 2 (2 usable) | 4 | /30 |
| Link B | 2 | 2 (2 usable) | 4 | /30 |
Now allocate in order, each block starting right after the previous one:
| Department | Network | Mask | Usable range | Broadcast |
|---|---|---|---|---|
| Sales | 192.168.50.0/25 | 255.255.255.128 | .1 to .126 | .127 |
| Engineering | 192.168.50.128/26 | 255.255.255.192 | .129 to .190 | .191 |
| HR | 192.168.50.192/27 | 255.255.255.224 | .193 to .222 | .223 |
| Admin | 192.168.50.224/28 | 255.255.255.240 | .225 to .238 | .239 |
| Link A | 192.168.50.240/30 | 255.255.255.252 | .241 to .242 | .243 |
| Link B | 192.168.50.244/30 | 255.255.255.252 | .245 to .246 | .247 |
Free for later: 192.168.50.248/29 (8 addresses, .248 to .255).
0 128 192 224 240 244 248 256
| Sales | Eng | HR | Ad |A |B | free |
/25 /26 /27 /28 /30/30 /29
With fixed-size /25 subnets, the same /24 could hold only two subnets. VLSM fits six.
Common mistake
Forgetting the two reserved addresses. 25 hosts do not fit in a /27 "because 2^5 = 32 is enough"; they fit because 2^5 - 2 = 30 is at least 25. A department of 31 hosts would need a /26. And a department of 30 hosts plus its router interface needs 31 addresses, so ask whether the gateway counts.
Verify with Python
import ipaddress as ip
import math
for s in ["192.168.10.77/27", "172.16.45.200/20", "10.1.130.5/18"]:
n = ip.ip_interface(s).network
print(s, n, n.broadcast_address, n.num_addresses - 2)
print(ip.ip_interface("10.0.5.130/25").network,
ip.ip_interface("10.0.5.100/25").network)
subs = list(ip.ip_network("192.168.1.0/24").subnets(new_prefix=27))
print(len(subs), subs[0], subs[-1])
cur = int(ip.ip_address("192.168.50.0"))
for name, hosts in [("Sales", 100), ("Engineering", 50), ("HR", 25),
("Admin", 10), ("LinkA", 2), ("LinkB", 2)]:
prefix = 32 - math.ceil(math.log2(hosts + 2))
net = ip.ip_network((cur, prefix))
print(name, net, net.broadcast_address)
cur += net.num_addresses
Output:
192.168.10.77/27 192.168.10.64/27 192.168.10.95 30
172.16.45.200/20 172.16.32.0/20 172.16.47.255 4094
10.1.130.5/18 10.1.128.0/18 10.1.191.255 16382
10.0.5.128/25 10.0.5.0/25
8 192.168.1.0/27 192.168.1.224/27
Sales 192.168.50.0/25 192.168.50.127
Engineering 192.168.50.128/26 192.168.50.191
HR 192.168.50.192/27 192.168.50.223
Admin 192.168.50.224/28 192.168.50.239
LinkA 192.168.50.240/30 192.168.50.243
LinkB 192.168.50.244/30 192.168.50.247
Interview tip
Talk through the block-size method out loud: "/20 means the third octet mask is 240, block size 16, 45 falls in 32 to 47, so the network is .32.0 and broadcast .47.255." Interviewers care that your method is reliable and fast, not that you converted every bit to binary.
Supernetting (route aggregation)
Supernetting is the reverse of subnetting: combining several contiguous networks into one larger prefix so a router advertises one route instead of many. It is also called route summarisation or aggregation.
Worked example
An ISP has 200.10.0.0/24, 200.10.1.0/24, 200.10.2.0/24 and 200.10.3.0/24. Find the summary route.
- Write the third octets in binary: 0 =
000000 00, 1 =000000 01, 2 =000000 10, 3 =000000 11. - The first 6 bits of the third octet are identical; the last 2 vary.
- Common prefix = 8 + 8 + 6 = 22 bits. Summary: 200.10.0.0/22, mask 255.255.252.0.
Conditions for a clean summary:
- The networks must be contiguous.
- Their count must be a power of two.
- The first network must be aligned: its third octet must be a multiple of the count (here 0 is a multiple of 4).
Counter-example: 200.10.1.0/24 through 200.10.4.0/24 is also four networks, but 1 is not a multiple of 4. The smallest exact cover is three routes: 200.10.1.0/24, 200.10.2.0/23 and 200.10.4.0/24. A single /21 would cover them but also claim addresses the ISP does not own.
NAT and PAT
NAT (network address translation) lets hosts with private addresses reach the internet by rewriting addresses at the edge router. It was the main reason IPv4 survived its address shortage.
Types
- Static NAT: one private address permanently maps to one public address. Used to make an internal server reachable.
- Dynamic NAT: private addresses take a public address from a pool as needed. The pool size limits how many hosts can be online at once.
- PAT (port address translation), also called NAPT or NAT overload: many private hosts share one public IP, distinguished by port numbers. This is what every home router does.
Worked example: PAT
A home router has public IP 203.0.113.5. Two laptops open connections to the same web server 93.184.216.34:443.
- Laptop A (
192.168.1.10) sends from source port 51000. The router rewrites the source to203.0.113.5:40001and records the mapping. - Laptop B (
192.168.1.11) also happens to use source port 51000. The router rewrites it to203.0.113.5:40002. - Replies come back to
203.0.113.5:40001and:40002. The router looks them up and rewrites the destinations back.
| Inside address:port | Outside address:port | Remote |
|---|---|---|
| 192.168.1.10:51000 | 203.0.113.5:40001 | 93.184.216.34:443 |
| 192.168.1.11:51000 | 203.0.113.5:40002 | 93.184.216.34:443 |
The router must also fix IP and TCP/UDP checksums because addresses and ports changed.
NAT trade-offs
- Pros: saves public addresses; hides internal addressing; changing ISP does not renumber the inside.
- Cons: breaks end-to-end connectivity, because outside hosts cannot start a connection to an inside host unless you configure port forwarding. This complicates peer-to-peer apps, VoIP and games, which use techniques like STUN and TURN. Some protocols that embed IP addresses in their payload (old FTP active mode, SIP) need special helpers. NAT state also costs router memory.
- NAT is not a firewall, although the "no unsolicited inbound" side effect resembles one.
The IPv4 header
The IPv4 header is 20 bytes without options (up to 60 bytes with them).
0 4 8 16 19 31
+-------+-------+---------------+------------------------+
|Version| IHL | DSCP | ECN | Total length |
+-------+-------+---------------+------+-----------------+
| Identification |Flags | Fragment offset |
+---------------+---------------+------+-----------------+
| TTL | Protocol | Header checksum |
+---------------+---------------+------------------------+
| Source address |
+--------------------------------------------------------+
| Destination address |
+--------------------------------------------------------+
| Options (if IHL > 5) |
+--------------------------------------------------------+
| Field | Bits | Meaning |
|---|---|---|
| Version | 4 | 4 for IPv4 |
| IHL | 4 | Header length in 32-bit words; minimum 5 (20 bytes), maximum 15 (60 bytes) |
| DSCP / ECN | 6 + 2 | Quality of service class; explicit congestion notification |
| Total length | 16 | Header + data in bytes; maximum 65,535 |
| Identification | 16 | Same value on all fragments of one datagram |
| Flags | 3 | Reserved, DF (don't fragment), MF (more fragments) |
| Fragment offset | 13 | Position of this fragment's data, in units of 8 bytes |
| TTL | 8 | Hop limit, decremented by each router; at 0 the packet is dropped and ICMP sent |
| Protocol | 8 | Payload type: 1 ICMP, 6 TCP, 17 UDP, 89 OSPF |
| Header checksum | 16 | Covers the header only; recomputed at every hop because TTL changes |
| Source / destination | 32 each | IPv4 addresses |
Fragmentation
Every link has an MTU, the largest IP packet it can carry (1,500 bytes on Ethernet). If a router must send a packet larger than the next link's MTU, IPv4 can split it into fragments. Each fragment is a full IP packet with its own header. Only the destination reassembles them.
Rules:
- Each fragment's data length, except the last, must be a multiple of 8 bytes, because the offset field counts 8-byte units.
- Offset = position of the fragment's first data byte in the original data, divided by 8.
- MF (more fragments) = 1 on every fragment except the last.
- All fragments keep the original Identification value.
Worked example
A 4,000-byte IPv4 datagram (20-byte header + 3,980 bytes data) must cross a link with MTU 1,500.
- Maximum data per fragment = 1,500 - 20 = 1,480 bytes. 1,480 / 8 = 185, a whole number, so 1,480 is usable.
- Split 3,980 bytes of data: 1,480 + 1,480 + 1,020.
- Offsets: 0 / 8 = 0; 1,480 / 8 = 185; 2,960 / 8 = 370.
| Fragment | Total length | Data bytes | Data range | Offset | MF |
|---|---|---|---|---|---|
| 1 | 1,500 | 1,480 | 0 to 1,479 | 0 | 1 |
| 2 | 1,500 | 1,480 | 1,480 to 2,959 | 185 | 1 |
| 3 | 1,040 | 1,020 | 2,960 to 3,979 | 370 | 0 |
Check: 1,480 + 1,480 + 1,020 = 3,980. Three headers mean 40 extra bytes on the wire (4,040 total versus 4,000).
Why fragmentation is avoided
If any fragment is lost, the whole datagram is lost. Fragments also burden the receiver with reassembly and confuse firewalls (only the first fragment has port numbers). Modern hosts use Path MTU Discovery: they set the DF bit; a router that cannot forward replies with ICMP "fragmentation needed" including the next-hop MTU; the sender shrinks its packets. IPv6 routers never fragment at all.
Common mistake
Writing the offset in bytes (1,480) instead of 8-byte units (185). Also, if the MTU minus header is not a multiple of 8, round the per-fragment data down to one (for MTU 1,006 with a 20-byte header, use 984 bytes, not 986).
ICMP: ping and traceroute
ICMP (Internet Control Message Protocol) carries error reports and diagnostics for IP. It is carried inside IP with protocol number 1. Each message has a type and code.
| Type | Meaning | Typical cause |
|---|---|---|
| 0 | Echo reply | Answer to ping |
| 3 | Destination unreachable | Code 0 net, 1 host, 3 port unreachable, 4 fragmentation needed |
| 5 | Redirect | Better next-hop exists on this LAN |
| 8 | Echo request | Ping |
| 11 | Time exceeded | Code 0: TTL reached 0 in transit |
ICMP errors are never sent about other ICMP error messages (to avoid storms), nor about broadcast packets or non-first fragments.
How ping works
ping sends ICMP echo requests (type 8) and waits for echo replies (type 0). It reports RTT for each, packet loss, and min/avg/max. If ping fails, the host may simply block ICMP, so a failed ping does not prove a host is down.
How traceroute works
traceroute discovers each router on the path by exploiting TTL:
- Send a probe with TTL = 1. The first router decrements it to 0, drops the packet and returns ICMP Time Exceeded (type 11). That reply's source address reveals router 1, and the time gives its RTT.
- Send probes with TTL = 2, 3, 4... each revealing the next router.
- When a probe reaches the destination, the destination replies differently: on Linux and macOS the default probe is UDP to a high, unlikely port, so the destination answers Port Unreachable (type 3, code 3). Windows
tracertuses ICMP echo, so the destination answers with an echo reply. Either way, the trace stops.
TTL=1 you ---> R1 (TTL->0) R1 sends Time Exceeded
TTL=2 you ---> R1 ---> R2 R2 sends Time Exceeded
TTL=3 you ---> R1 ---> R2 ---> Dest Port Unreachable / Echo Reply
Each hop is usually probed three times, so you see three RTTs per line. A * means no reply arrived in time (the router may rate-limit or block ICMP). Reading traceroute output is covered in the routing lesson.
DHCP: getting an address automatically
DHCP (Dynamic Host Configuration Protocol) gives a host its IP address, subnet mask, default gateway, DNS servers and a lease time without manual setup. It runs over UDP: the server listens on port 67, the client on port 68.
The exchange is called DORA:
Client (no IP yet) DHCP server
|-- 1. DISCOVER src 0.0.0.0 dst 255.255.255.255 -->|
|<-- 2. OFFER "you may use 192.168.1.23" ---------|
|-- 3. REQUEST "I accept 192.168.1.23" (bcast) --->|
|<-- 4. ACK lease 24 h, mask, gateway, DNS -----|
- Discover: the client has no address, so it sends from
0.0.0.0to the broadcast address255.255.255.255, including its MAC. - Offer: each server that hears it offers an available address and settings.
- Request: the client picks one offer and broadcasts a request naming that server, so the other servers know their offers were declined.
- Acknowledge: the chosen server confirms. The client may first check the address is not in use (often with an ARP probe), then configures itself.
Lease renewal: at 50% of the lease (T1) the client unicasts a REQUEST to its server to renew; if that fails, at 87.5% (T2) it broadcasts to any server. If the lease expires, it must stop using the address.
DHCP relay: broadcasts do not cross routers, so a router configured as a relay agent forwards DHCP messages to a central server on another subnet.
Other messages: DECLINE (address already in use), RELEASE (client gives it up), NAK (server refuses, for example after the client moved networks). If no server answers, many operating systems self-assign a 169.254.x.x address.
IPv6
IPv6 uses 128-bit addresses, giving 2^128 (about 3.4 × 10^38) addresses. Beyond size, it simplifies the header and removes some IPv4 baggage.
Address notation
Eight groups of four hex digits separated by colons:
2001:0db8:0000:0000:0000:ff00:0042:8329
Two shortening rules:
- Drop leading zeros in each group:
0db8becomesdb8,0042becomes42. - Replace one run of consecutive all-zero groups with
::. Only once per address, or the length would be ambiguous.
Result: 2001:db8::ff00:42:8329.
Address types
| Type | Prefix | Purpose |
|---|---|---|
| Global unicast | 2000::/3 | Public, routable (like public IPv4) |
| Link-local | fe80::/10 | Valid only on one link; every interface has one |
| Unique local | fc00::/7 (fd00::/8 in practice) | Private, like RFC 1918 |
| Multicast | ff00::/8 | Groups; replaces broadcast |
| Loopback | ::1/128 | Like 127.0.0.1 |
| Unspecified | ::/128 | Like 0.0.0.0 |
There is no broadcast in IPv6, and anycast addresses look like ordinary unicast ones.
A typical global address is split into a routing prefix from the ISP, a subnet ID and a 64-bit interface ID. LANs are almost always /64, giving each subnet 2^64 addresses. Hosts can configure themselves with SLAAC (stateless address autoconfiguration): the router advertises the /64 prefix and the host chooses its own interface ID (randomised for privacy on modern systems). DHCPv6 is the stateful alternative.
The IPv6 header
The base header is a fixed 40 bytes, simpler than IPv4's:
+-------+---------------+--------------------------------+
|Version| Traffic class | Flow label |
+-------+---------------+-------------+------------------+
| Payload length | Next hdr | Hop lim|
+-------------------------------------+----------+-------+
| Source address (128 bits) |
+--------------------------------------------------------+
| Destination address (128 bits) |
+--------------------------------------------------------+
| Change from IPv4 | Why |
|---|---|
| No header checksum | Link and transport layers already check; routers save work every hop |
| No fragmentation by routers | Only the source fragments (via an extension header); path MTU discovery is mandatory; minimum MTU 1,280 |
| Options moved to extension headers, chained by Next Header | Fixed base header is fast to process |
| TTL renamed Hop Limit | Same meaning |
| New Flow Label | Lets routers identify packets of the same flow |
Transition from IPv4 to IPv6
The two protocols are not compatible on the wire, so the internet runs both during a long transition.
- Dual stack: hosts and routers run IPv4 and IPv6 side by side and use IPv6 when the destination supports it (DNS returns AAAA records for IPv6, A records for IPv4). Browsers use "Happy Eyeballs", racing both and picking the faster. This is the most common approach.
- Tunnelling: IPv6 packets are wrapped inside IPv4 packets (IP protocol 41) to cross an IPv4-only network, then unwrapped. Examples are manual 6in4 tunnels and historical automatic schemes (6to4, Teredo).
- Translation: NAT64 with DNS64 lets IPv6-only clients reach IPv4-only servers: DNS64 synthesises an IPv6 address that embeds the IPv4 one, and a NAT64 gateway translates packets. Mobile networks commonly use this.
Tunnelling:
[v6 host]--v6--[R1]==== IPv4 network ====[R2]--v6--[v6 host]
| IPv4 hdr | IPv6 hdr | data |
wrapped at R1, unwrapped at R2
Interview questions
Q1. Find the network, broadcast and host range of 172.16.45.200/20.
The /20 mask has 240 in the third octet, so block size is 16 and 45 falls in 32 to 47. Network 172.16.32.0, broadcast 172.16.47.255, usable 172.16.32.1 to 172.16.47.254, which is 2^12 - 2 = 4,094 hosts.
Q2. Why do we subtract 2 when counting hosts?
The all-zeros host address names the network and the all-ones host address is the subnet broadcast, so neither can be assigned to a host. The exceptions are /31 point-to-point links, which use both addresses, and /32, which identifies a single host.
Q3. What problem did CIDR solve?
Classful addressing allocated only /8, /16 or /24 networks, wasting addresses (a 2,000-host company got 65,534 addresses) and bloating routing tables with many class C routes. CIDR allows any prefix length, so allocations fit needs, and contiguous blocks can be aggregated into one route.
Q4. What is VLSM and why allocate the largest subnet first?
VLSM uses different prefix lengths within one block so each subnet matches its size. Allocating the largest first keeps every subnet aligned to a multiple of its block size and avoids gaps that cannot be used. For example, a /24 can hold a /25, /26, /27, /28 and two /30s.
Q5. Explain PAT.
Port address translation lets many private hosts share one public IP. The router rewrites each outgoing connection's source IP and port to the public IP and a unique port, keeps a translation table, and reverses the mapping on replies. It breaks unsolicited inbound connections unless ports are forwarded.
Q6. Summarise 200.10.0.0/24 to 200.10.3.0/24.
The third octets 0 to 3 share their first 6 bits, so the common prefix is 22 bits: 200.10.0.0/22. This works because the four networks are contiguous and the first is aligned on a multiple of four.
Q7. A 4,000-byte datagram crosses a link with MTU 1,500. Describe the fragments.
Each fragment carries up to 1,480 data bytes (a multiple of 8). The 3,980 data bytes become 1,480, 1,480 and 1,020, with offsets 0, 185 and 370 and MF bits 1, 1 and 0. Total lengths are 1,500, 1,500 and 1,040.
Q8. How does traceroute work?
It sends probes with increasing TTL. Each router that decrements TTL to zero discards the probe and returns ICMP Time Exceeded, revealing its address and RTT. The final destination answers with ICMP Port Unreachable (for UDP probes) or an Echo Reply (for ICMP probes), which ends the trace.
Q9. Walk through DHCP.
DORA: the client broadcasts Discover from 0.0.0.0, servers reply with Offers, the client broadcasts a Request for one offer, and the chosen server sends an Ack with the lease, mask, gateway and DNS. The client renews at half the lease time. A relay agent forwards these broadcasts across routers.
Q10. Your laptop shows an IP of 169.254.12.7. What happened?
That is a link-local (APIPA) address the OS assigns itself when DHCP fails. The laptop can only talk to other link-local hosts on the same link. Check the DHCP server, the cable or Wi-Fi association, and any relay configuration.
Q11. What are the key differences between IPv4 and IPv6 headers?
IPv6 has a fixed 40-byte header with 128-bit addresses, no header checksum, no router fragmentation, a Flow Label, and options moved into chained extension headers. TTL is renamed Hop Limit. IPv4's header is 20 to 60 bytes and is recomputed at every hop because of its checksum.
Q12. How does the internet move from IPv4 to IPv6?
Mainly through dual stack, where devices run both and prefer IPv6 when DNS offers it. Tunnelling carries IPv6 over IPv4-only networks, and NAT64/DNS64 lets IPv6-only clients reach IPv4-only servers.
Q13. Are 10.0.5.130/25 and 10.0.5.100/25 on the same subnet?
No. With a /25 the block size is 128, so .130 is in 10.0.5.128/25 and .100 is in 10.0.5.0/25. Traffic between them must go through a router.
Q14. Why does the IPv4 header checksum need recomputing at every router?
Because each router decrements TTL, which changes the header, so the checksum must be updated. IPv6 removed the header checksum partly to avoid this per-hop work, relying on link-layer CRC and transport checksums.
Q15. Which mask gives at least 500 hosts per subnet?
We need 2^h - 2 to be at least 500, which needs h = 9 (510 hosts). So the prefix is /23, mask 255.255.254.0.
Key takeaways
- An IPv4 address is 32 bits split into network and host parts by the mask; CIDR writes the mask as /n.
- Network = address AND mask; broadcast = all host bits 1; usable hosts = 2^h - 2.
- The block-size method: 256 minus the mask's interesting octet, find the multiple that contains the address.
- Private ranges are 10/8, 172.16/12 and 192.168/16; 169.254/16 means DHCP failed.
- VLSM allocates largest first; supernetting merges aligned, contiguous, power-of-two groups.
- PAT shares one public IP using ports; it breaks unsolicited inbound connections.
- Fragment offsets are in 8-byte units; MF is set on all but the last fragment; modern hosts use path MTU discovery instead.
- traceroute uses increasing TTL and ICMP Time Exceeded; DHCP is Discover, Offer, Request, Ack.
- IPv6: 128-bit addresses,
::compression once, no broadcast, fixed 40-byte header, no router fragmentation; transition by dual stack, tunnelling and NAT64.
Next lesson
Continue with routing.

