The Network Layer & IP Routing

September 25, 2026 • 11 min read

The Network Layer & IP Routing
Table of contents

Part of the series:Networks Explained

The link layer post delivered a frame to the machine on the other end of one cable. That is a small promise for a world-sized problem: the destination is usually in another building, another city, another continent, on a network whose owner has never heard of you. This post opens the layer built for that: the one that gives every machine on earth an address, and that moves data one stranger at a time until it arrives.

What the network layer is for

Two jobs, both simple to state.

Addressing. Every host gets a globally unique address, so any machine anywhere can name any other. That is the layer’s whole reason to exist. A local link can get away with small numbers because it only ever has a dozen machines; the network layer needs an address space big enough for the planet, and it needs addresses that contain a bit of structure, because routers will need to group hosts together to forward at scale.

Routing. Data is not sent to the destination; it is sent one hop at a time to whichever neighbor is closer. Each machine decides, locally, “for each destination I care about, who is the next step?” No router knows the whole path. The path emerges from a chain of local decisions.

Layer two asks “who is next door?”. Layer three asks “who is next door in the direction of Japan”, and answers it with whatever the neighbour says.

The network layer also has to carry the previous post’s assumption into a world where the wire is unreliable. It does not fix anything. It forwards, counts hops, and reports errors.

IP addresses

The network layer’s protocol is the Internet Protocol (IP)1, and its address is the IP address2. Two versions exist in the world, and both are still in daily use.

IPv4 is 32 bits, written as four decimal numbers:

93.184.216.34
└ each octet: 0-255        2^32 ≈ 4.3 billion addresses

IPv6 is 128 bits, written as eight groups of hexadecimal digits:

2606:2800:220:1:248:1893:25c8:1946
└ 8 groups of 16 bits       2^128 addresses

The scale difference is the whole story. IPv4 was designed for a research network and ran out around the time smartphones arrived; IPv6 was created because of that shortage and is being deployed slowly, one network at a time, mostly because the two can coexist.

Not every address is public. Private address ranges3 are reserved for internal networks and are never routed on the internet:

10.0.0.0/8        192.168.0.0/16       172.16.0.0/12
(one big block)   (home networks)       (most offices)

That is why your laptop is 192.168.0.x at home and why your provider gives you an address no website can look up. Something must translate between the two, and that something is NAT, which the security post opens properly.

Real example: a public site cannot distinguish your laptop from a million other laptops behind a million routers by IP address alone. They all share one address. NAT is why “your IP address” is much weaker evidence than it sounds.

Subnets, prefixes, and CIDR

An address is not just an address. It is a prefix plus a host part, and that split is what makes routing possible at all.

The old scheme carved addresses into three fixed classes: class A for enormous networks, class B for large, class C for small. It was exhausted almost immediately, because “medium-sized network” was not a size anyone had.

CIDR4, classless inter-domain routing, replaced it with one idea: write the prefix length explicitly.

192.168.1.0/24

│            └── 24 bits of prefix = the network
└───────────────── 32 bits total

the /24 means the first 24 bits identify the network,
the last 8 bits identify hosts (up to 254 usable)

The prefix length is the only concept you need. And because a prefix describes a whole range, a router can advertise a million addresses as one line.

A subnet is not a special kind of address. It is an address plus a ruler saying how much of it is the network.

The IP packet header

The unit layer three moves is the packet5, and it is the first place we meet the idea from the representation post applied to real wire formats: a fixed layout of fields, each with a known offset.

 0                   1                   2                   3
 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
| version |  IHL  |    DSCP     |      total length            |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|           identification         | flags      |fragment offset|
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|      time to live      |  protocol |       header checksum      |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|                        source address                         |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|                      destination address                     |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|                    options (if IHL > 5)                      |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+

The fields you will actually reason about:

  • Source and destination address. The whole point of the packet.
  • Protocol. What is inside: 6 for TCP, 17 for UDP, 1 for ICMP. This is the pointer that lets the receiving host hand the payload to the right module.
  • Time to live. A counter that starts at some value, like 64, and is decremented by every router. This is the field that stops packets from circulating forever.
  • Header checksum. Only the header is checked, and it is recomputed at every hop, because the header changes at every hop.
  • Total length and IHL. How big the packet is, and how big the header is, since options make the header variable.

Note the asymmetry: the header changes at every hop, the payload does not. The payload survives the journey untouched; only the envelope is re-addressed.

TTL and why tracert works

The time to live6 field is a distance counter, not a timer. A router that receives a packet with TTL 1 decrements it to 0, sends back a message saying “I had to throw this away”, and drops the packet. Any packet with a TTL high enough to cross a continent still counts its hops.

That single field produces the best network tool most people know:

traceroute to a server in Amsterdam:

 1  192.168.0.1        0.9 ms   your router
 2  10.x.x.x           8.1 ms   your provider
 3  ...               14.2 ms   backbone
 ...
 7  ...              121.4 ms   the destination, or near it

Each line is one network refusing to carry the packet any further and saying so. The tool asks again with TTL 2, again with 3, and the sequence of refusals is the path.

This also retires a myth from the physical layer post. People often blame satellite latency on light being slow. It is: the count of hops is what distance means on a network, and the light is not the villain. The number of intermediate machines is.

Routing, hop by hop

Every host and every router has a routing table7: a list of destinations and next hops. When a packet arrives, the router looks at the destination and picks a row. The match is not exact, and this is the elegant part: the router picks the longest matching prefix.

routing table:

192.168.1.0/24      →  port 3          (my own network)
10.0.0.0/8          →  port 5
172.16.5.0/24       →  router A       (someone else's network)
0.0.0.0/0           →  default route  (everything else)

packet to 172.16.5.9   →  longest match is 172.16.5.0/24 → router A
packet to 8.8.8.8      →  only the /0 matches           → default route

The default route8, written 0.0.0.0/0, is the catch-all that lets a small network reach the internet with one entry. It is the same trick as a phone’s “call anywhere” entry, and it is why routers do not need an entry for every host on earth.

Longest prefix match is what makes prefixes useful rather than decorative. A host can have one entry for its own street and still inherit everything else from the default route, and a big provider can announce one line covering a million addresses and let every router downstream pick the most specific one that applies.

Who builds these tables

Two machines disagreeing about routes is the normal state of the internet, and fixing it is a whole field. The dividing line is ownership.

Inside one organization’s network, machines run an interior gateway protocol to compute routes automatically. OSPF9 is the common one: routers describe their links to each other, everyone builds a full map of that network, and the shortest path wins. Here, topology is shared data, and everyone can know everything.

Between organizations, that is impossible and undesirable. A provider has no interest in a competitor knowing its internal topology, and the shortest path is often the wrong path for policy reasons: peering agreements, transit fees, and who you are willing to carry traffic for. So the border protocol is different in kind. BGP10 is how networks, called autonomous systems11, announce to each other which prefixes they can reach.

inside one network:      OSPF — "here are my links, compute the best paths"
between networks:        BGP  — "I can reach these prefixes", plus policy

BGP does not compute shortest paths.
It decides who to tell what, in an order operators agree on.

Two properties of BGP explain a lot of the internet’s behavior. It does not tell anyone about everything, so some traffic takes odd detours. And because it runs in logical time, seconds or minutes, a misconfigured announcement can misdirect traffic for real stretches of time. BGP is a set of agreements between strangers, maintained by trust and contracts, not by mathematics.

ICMP: the network layer talking back

Routing is one thing; telling someone their packet failed is another. That is ICMP12, the protocol next to IP.

  • Echo request and echo reply are what ping sends: a tiny packet asking “are you there?”, answered with “yes, and here is the time”. That is how ping measures the latency from the physical layer post, because it measures a round trip through the whole chain.
  • Destination unreachable is how a router refuses to deliver. When you see “no route to host”, that message is why.
  • Time exceeded is how a router reports “your TTL ran out”, which is what traceroute reads.
  • Fragmentation needed tells the sender its packet was too large.

ICMP is the network’s error reporting, and it is genuinely useful, which is also why attackers love it: forged ICMP messages can be used to discover hosts, redirect traffic, or amplify traffic into a flood. Good networks answer ICMP carefully rather than blocking it, and that is why “blocked ping” is not the security win it sounds like.

The big picture

Layer three gives every host a globally meaningful address, carves it into a prefix plus host part so billions of addresses can be advertised in single lines, and moves packets one hop at a time by longest prefix match, default route in hand. It never fixes anything: it forwards, decrements a TTL that doubles as tracert, and reports trouble through ICMP. Inside a network, OSPF computes paths from a full picture. Between networks, BGP exchanges which prefixes are reachable under policy, because strangers do not share maps. And every packet’s header is rewritten at every hop while its payload survives untouched.

"send this to 93.184.216.34"

your machine:  not mine → default route
your router:   not mine → provider's router
provider:      not mine → transit backbone
... nineteen hops of "not mine, but I know who" ...
destination:   that is mine → hand to the host

Nobody knows the whole route. Everybody knows enough. The next post adds the layer that finally asks for something: not “how do I get there” but “did it arrive, and in what order”.

Footnotes

  1. Internet Protocol - Wikipedia

  2. IP address - Wikipedia

  3. Private IP address - Wikipedia

  4. Classless inter-domain routing - Wikipedia

  5. IP packet - Wikipedia

  6. Time to live - Wikipedia

  7. Routing table - Wikipedia

  8. Default route - Wikipedia

  9. Open Shortest Path First - Wikipedia

  10. Border Gateway Protocol - Wikipedia

  11. Autonomous system (Internet) - Wikipedia

  12. Internet Control Message Protocol - Wikipedia