MAC addresses are unique across the planet and yet unusable at large scale, because they say nothing about where the equipment is. The network layer solves the problem exactly as the postal service solved it two centuries ago: with a hierarchical address, from which the direction can be worked out without knowing the final destination.
1Recap5 min
- A MAC address has 48 bits, is unique across the planet, but is flat (no hierarchy) and local (visible only within the broadcast domain).
- A switch forwards by MAC address; a router works at layer 3 and separates broadcast domains.
- A VLAN is a broadcast domain. Communication between VLANs necessarily requires a layer 3 device.
- The binary ↔ decimal conversion from lecture 1 becomes, from today, a daily working tool.
Learning outcomes
- Explain why hierarchical addressing makes routing possible at Internet scale
- Read the IPv4 header and say what each important field is for
- Calculate the network address and the broadcast address through bitwise operations
- Subnet a block into equal subnets and then, optimally, with VLSM
- Distinguish public from private addresses and recognise the reserved blocks
- Describe a complete ARP exchange and explain what proxy ARP is
- Follow the four DHCP messages and say when a relay is needed
2Why we need a second set of addresses8 min
A MAC address uniquely identifies an interface in all the world. It looks like exactly what we need - and yet it is not enough. The reason is a single property: the scheme is flat.
From the address 00:FC:42:3E:34:99 absolutely nothing can be deduced about where that
network card is. It may be in the next room or in Australia. There is no rule saying "addresses
beginning with X are in Europe".
The consequence: a router forwarding traffic by MAC address would need a separate entry for every interface in the world - billions of rows, with no possibility of grouping. The table would fit nowhere, could be updated by nobody, and could not be searched fast enough.
Each level of decision uses only the prefix it needs. This is exactly the mechanism that makes IP routing possible at Internet scale.
3The three functions of the network layer5 min
| Function | What it means concretely |
|---|---|
| Global addressing | each device is uniquely identified by an IP address, organised hierarchically, so that nearby addresses can be grouped |
| End-to-end communication | the protocol is best-effort: it establishes no connections, guarantees no delivery, guarantees no ordering. The guarantees are layer 4's business |
| Routing | intermediate devices choose the path of each packet on the basis of the destination address |
IP promises one thing only: it will try to deliver the packet. It does not promise to succeed, does not promise ordering, and does not tell you if it failed. A packet may be discarded by any congested router along the way, with no ceremony whatever.
This looks like a weakness. It is the design decision that made the Internet possible: by staying simple and stateless, a router can process millions of packets per second without remembering anything about them. The complexity - retransmissions, ordering, acknowledgements - was moved to the endpoints, into TCP.
| Protocol | Role |
|---|---|
| IPv4 | the basic protocol; the subject of this lecture |
| IPv6 | the successor, with 128-bit addresses; lecture 9 |
| ICMP | control and error messages: ping, traceroute, "destination unreachable" |
| IGMP | management of multicast groups |
4The IPv4 header11 min
IPv4 is defined in RFC 791, published in 1981 - and, with minor exceptions, it has worked unchanged ever since. The data unit produced by IP encapsulation is called a packet.
You then send with TTL = 2, then 3, then 4… Each packet dies one hop further on and each router introduces itself. That is how the complete list of the path is built, using a field that had been conceived as protection against loops.
5The address, the mask and the two operations13 min
An IPv4 address has 32 bits, usually written in dotted decimal - four numbers between 0 and 255, one per byte.
10001101.01010101.11110001.10001011
The address divides into two parts: the network part and the host part. Devices that share the same network part are in the same network and can communicate directly, without a router.
The boundary between the two parts cannot be deduced from the address - it must be stated separately, through the network mask: a continuous run of 1s followed by a continuous run of 0s.
There is nothing mysterious about them. They apply bit by bit, on corresponding positions:
| A | B | A AND B | A OR B |
|---|---|---|---|
| 0 | 0 | 0 | 0 |
| 0 | 1 | 0 | 1 |
| 1 | 0 | 0 | 1 |
| 1 | 1 | 1 | 1 |
What to remember, practically: AND with 1 keeps the bit, AND with 0 clears it. OR with 1 sets the bit, OR with 0 leaves it alone. That is all you need for the rest of the course.
Broadcast address = the IP address OR the inverse of the mask. The inverse has 0s on the network part (changing nothing) and 1s on the host part (setting everything). The result: every host bit set to 1.
Neither of them can be assigned to a host.
CIDR notation
Decimal notation of the mask - 255.255.255.0 - is cumbersome. The CIDR
shorthand was introduced: you write the number of 1 bits in the mask, preceded by a slash.
| Prefix | Decimal mask | Host bits | Total addresses | Usable addresses |
|---|---|---|---|---|
| /24 | 255.255.255.0 | 8 | 256 | 254 |
| /25 | 255.255.255.128 | 7 | 128 | 126 |
| /26 | 255.255.255.192 | 6 | 64 | 62 |
| /27 | 255.255.255.224 | 5 | 32 | 30 |
| /28 | 255.255.255.240 | 4 | 16 | 14 |
| /29 | 255.255.255.248 | 3 | 8 | 6 |
| /30 | 255.255.255.252 | 2 | 4 | 2 |
This table is worth learning - not by heart, but through its logic. Each row halves the number of addresses of the one above it, and "usable" is always "total minus 2" (network and broadcast).
- Change the prefix from /26 to /24 and watch the bits change colour. Moving the boundary by a single bit doubles the number of hosts and halves the number of subnets.
- Enter the address
192.168.10.64with prefix /26. Notice that the address you typed is itself the network address - so it cannot be given to a host. - Try /31 and /32. They are special cases: /31 is used on point-to-point links between routers, /32 for a single address (a loopback interface).
Three hosts are connected to the same switch: A with 192.168.17.64/26, B with
192.168.17.35/26, C with 192.168.17.31/27. Are there any problems?
See the solution
Yes, three distinct problems:
- A has been given a network address. 64 in binary is
01000000, and with /26 the last 6 bits are host bits and are all zero. A network address cannot be assigned to an interface. - C has been given a broadcast address. With /27, its network is
192.168.17.0/27, and the broadcast of that network is exactly.31. - C also has a different mask from the others. Even with correct addresses, A and B
would consider themselves in network
192.168.17.0/26and C in192.168.17.0/27- communication would work asymmetrically and confusingly.
Check each case in the calculator above. Enter the address and the prefix and compare with what it displays.
6Classes, private addresses, reserved addresses8 min
Historically, addresses were divided into five classes identified by their leading bits, each with its own fixed default mask.
| Class | Leading bits | Range | Default mask | Status today |
|---|---|---|---|---|
| A | 0… | 0.0.0.0 – 127.255.255.255 | /8 | historical |
| B | 10… | 128.0.0.0 – 191.255.255.255 | /16 | historical |
| C | 110… | 192.0.0.0 – 223.255.255.255 | /24 | historical |
| D | 1110… | 224.0.0.0 – 239.255.255.255 | - | multicast, in use |
| E | 1111… | 240.0.0.0 – 255.255.255.255 | - | reserved, experimental |
The replacement is called CIDR (Classless Inter-Domain Routing) and does one simple thing: the mask may be anything, not only /8, /16 or /24. For 300 addresses you receive a /23, with 510 usable addresses.
Classes have vanished from equipment but have remained in the vocabulary. When somebody says "a class C network", read "a /24" - and do not be puzzled.
Private addresses
RFC 1918 set aside three ranges for private use. They cannot be routed on the Internet, so they can be reused by anybody - and they are, in every home and every company in the world. Reaching the Internet is done through translation (NAT), the subject of lecture 9.
| Private block | Size | Where it usually appears |
|---|---|---|
10.0.0.0/8 | 16.7 million addresses | large enterprise networks |
172.16.0.0/12 | 1 million addresses | medium-sized networks |
192.168.0.0/16 | 65,536 addresses | small networks, home equipment |
Addresses with special meaning
| Block | What it means |
|---|---|
127.0.0.0/8 | Loopback. 127.0.0.1 refers to the computer itself. A ping here tests the local stack, not the network. |
169.254.0.0/16 | APIPA. The address a host gives itself when the DHCP server does not answer. |
0.0.0.0 | "this network" or "any network", depending on context. As the destination in a route, it means the default route. |
255.255.255.255 | Limited broadcast - it never passes a router. |
224.0.0.0/4 | Multicast. 224.0.0.5 = all OSPF routers, 224.0.0.6 = the DR and BDR. |
169.254.x.x, there is no point looking for the problem
anywhere else: the DHCP server did not answer. Either there is none, or the cable is in a
different VLAN, or the relay is not configured, or the address pool has run out.7Subnetting13 min
In a modern network a "subnet" is no different from a network; the term merely indicates that it is part of the address space of a larger network.
You have been given the block 192.168.10.0/24 - 254 usable addresses. You have three
departments. You could put every computer into a single flat network, but then you are back to all
the problems of lecture 4: a single broadcast domain, no separation, no differentiated policy.
Subnetting gives you three separate networks, each with its own gateway, between which traffic passes in a controlled way, through a router.
The simple variant: equal subnets
You borrow as many bits as are needed for the desired number of subnets. For three subnets we need 2 bits, because 2² = 4 ≥ 3.
Example: 192.168.10.0/24 for three networks with 60, 30 and 15 hosts.
subnet 1 11000000.10101000.00001010.00000000 /26 → 192.168.10.0
subnet 2 11000000.10101000.00001010.01000000 /26 → 192.168.10.64
subnet 3 11000000.10101000.00001010.10000000 /26 → 192.168.10.128
(subnet 4) 11000000.10101000.00001010.11000000 /26 → 192.168.10.192
Each /26 offers 62 usable addresses, so all three requirements are met. The waste, however, is considerable:
| Requirement | Allocated | Usable | Wasted |
|---|---|---|---|
| 60 hosts | /26 | 62 | 2 |
| 30 hosts | /26 | 62 | 32 |
| 15 hosts | /26 | 62 | 47 |
| Total wasted | 81 addresses | ||
Why is a /28, which offers 14 usable addresses, not enough for 15 hosts?
See the answer
Because 14 < 15. You have to go to /27, which offers 30.
And more importantly: to the 15 hosts you must add the gateway, which also consumes a usable address. So the real requirement is 16, and a /28 is all the more insufficient.
This is mistake number one in the examination: the gateway is forgotten.
8VLSM: optimal subnetting12 min
VLSM (Variable Length Subnet Mask) abandons the constraint that every subnet must have the same mask. Each subnet receives exactly what it needs.
The reason: a block of size 2n must start at an address aligned to 2n. If you allocate several small blocks first, the alignment is lost, and the next large block can only start much further on - the space between them becomes unusable.
The same requirements as above, solved with VLSM. Computing the host bits needed:
- 60 hosts + gateway = 61 → 26 − 2 = 62 ≥ 61 → 6 host bits → /26
- 30 hosts + gateway = 31 → 25 − 2 = 30 < 31 → not enough; 26 − 2 = 62 → /26. If the requirement is strictly 30 including the gateway, /27 suffices.
- 15 hosts + gateway = 16 → 25 − 2 = 30 ≥ 16 → 5 bits → /27
| Requirement | Subnet allocated | Usable addresses | Waste |
|---|---|---|---|
| 60 hosts | 192.168.10.0/26 | 62 | 2 |
| 30 hosts | 192.168.10.64/27 | 30 | 0 |
| 15 hosts | 192.168.10.96/27 | 30 | 15 |
| Total wasted | 17 instead of 81 | ||
On top of that, the whole block from 192.168.10.128 upward stays free - 128 addresses
for future expansion, against none in the equal-subnet variant.
Optimally subnet 172.18.240.0/23 for: one network with 200 hosts, one with 90, two
with 20, one with 6 and three with 4 hosts.
See the step-by-step solution
Step 1 - sort in descending order: 200, 90, 20, 20, 6, 4, 4, 4.
Step 2 - compute the host bits for each:
| Requirement | Needed with gateway | Host bits | Prefix | Subnet | Broadcast |
|---|---|---|---|---|---|
| 200 | 201 | 8 → 254 usable | /24 | 172.18.240.0 | 172.18.240.255 |
| 90 | 91 | 7 → 126 | /25 | 172.18.241.0 | 172.18.241.127 |
| 20 | 21 | 5 → 30 | /27 | 172.18.241.128 | 172.18.241.159 |
| 20 | 21 | 5 → 30 | /27 | 172.18.241.160 | 172.18.241.191 |
| 6 | 7 | 3 → 6 | /29 | 172.18.241.192 | 172.18.241.199 |
| 4 | 5 | 3 → 6 | /29 | 172.18.241.200 | 172.18.241.207 |
| 4 | 5 | 3 → 6 | /29 | 172.18.241.208 | 172.18.241.215 |
| 4 | 5 | 3 → 6 | /29 | 172.18.241.216 | 172.18.241.223 |
Step 3 - the check: each subnet begins exactly where the previous one ended (broadcast + 1). If there is a gap or an overlap anywhere, the calculation is wrong.
Left free: the block from 172.18.241.224 upward - 32 addresses.
A /24 allocated to a link between two routers wastes 252 addresses on absolutely nothing. It is the classic waste in a beginner's design.
9ARP: from IP address to MAC address11 min
Here is a practical problem we have not yet solved. A host wants to send a packet and knows the destination's IP address. But the Ethernet frame the packet must be encapsulated in requires a MAC address - and that it does not have.
The protocol that performs the translation is called ARP (Address Resolution Protocol).
What happens when the destination is in another network
This is the part that causes the most confusion at first.
- The source checks whether the destination is in the same network, applying its own mask to both addresses.
- If yes - it sends an ARP request for the destination's IP address, as above.
- If no - it sends an ARP request for the IP address of its own default gateway. Because that is where the frame has to go, physically.
The source and destination MAC addresses are rewritten on every Ethernet segment traversed.
Practical consequence: if in a capture you see a packet with a source IP address from another network and the source MAC address of the local router, everything is perfectly normal. If you see the source IP address rewritten, then NAT is being done there - the subject of lecture 9.
The mechanism rescues faulty configurations - a host with no gateway configured, for instance - but it masks real problems and is therefore disabled by default on much modern equipment.
How many ARP tables does a router have? One per active multi-access interface. A switch, by contrast, has none: it does not look at IP addresses, so it has nothing to translate. The exception is the switch's management IP address, which belongs to the virtual interface rather than to the switching function.
10DHCP: addresses without manual configuration11 min
Configuring addresses by hand is realistic for routers and servers. For the hundreds of laptops and telephones that come and go from a network every day, it is impossible.
DHCP (Dynamic Host Configuration Protocol) automates the process through four messages, easily remembered by the acronym DORA.
DHCP relay
The Discover message is a broadcast to 255.255.255.255, and routers do not
propagate broadcasts - that is their job. In a network with several VLANs and a single central
DHCP server, the request would never reach it.
The solution is to configure a DHCP relay on the router in the local network: it takes the broadcast, turns it into a unicast towards the server's address and attaches information about the network it came from - so that the server knows which pool to allocate from.
R1(config)# interface gigabitEthernet 0/0.20 R1(config-subif)# ip helper-address 10.0.100.5
11Common mistakes4 min
- "I forgot the gateway in the address calculation" The gateway consumes a usable address too. For 30 hosts plus a gateway you need a /26, not a /27. The real requirement = the number of hosts + 1.
- "I allocated the VLSM subnets in the order given in the question" The order must be descending by size. Otherwise the alignment is lost and the large blocks no longer fit. Always sort before allocating.
- "The masks may differ between hosts on the same segment" They produce no visible error at configuration time, but they produce asymmetric behaviour: one host believes the destination is local, the other believes it is remote. The same mask on every host of a segment, without exception.
- "The host sends an ARP request for the IP address of the final destination" Only if the destination is in the same network. Otherwise it sends an ARP request for the gateway, because that is where the frame must physically go. First apply the mask, then decide whom to ask.
- "169.254.x.x is a valid address, so the network works" It is the clear sign that DHCP did not answer. Two hosts with such addresses can even see each other, which adds to the confusion. See 169.254 → look for the DHCP server or the relay, nothing else.
12Summary and glossary5 min
- The IP address is hierarchical, and that is what makes routing possible on a global scale - unlike the MAC address, which is flat.
- The mask separates the network part from the host part. AND with the mask gives the network address; OR with the inverse gives the broadcast.
- VLSM allocates each subnet exactly what it needs, in descending order.
- ARP translates IP → MAC within a segment. IP addresses stay constant, MAC addresses are rewritten at every hop.
- DHCP hands out addresses automatically, in four messages. Across broadcast boundaries a relay is needed.
13Self-check questions7 min
14Further reading and bibliography2 min
We have hierarchical addresses and the mechanisms that tie them to the physical world. The next lecture shows how the hierarchy is used: how a router decides, for each individual packet, where to send it next.
In laboratory 4 you design the complete addressing plan of a company, with real figures, and automate it with DHCP.
- RFC 791 - Internet Protocol
- RFC 826 - Address Resolution Protocol
- RFC 1918 - address allocation for private internets
- RFC 2131 - Dynamic Host Configuration Protocol
- RFC 4632 - CIDR: the address assignment and aggregation architecture
- RFC 3927 - link-local addressing (APIPA)