Networking · Concept · 10 min read

The IPv4 Header, Field by Field and in Order of Usefulness

Every guide to this header lists all twelve fields as though they were equally interesting. Six of them turn up in a working week, and those six explain traceroute, MTU failures and tunnel firewall rules.

Written by Marko Ristic, Editor Updated Sep 17, 2026
20 BThe header without options, which is almost always the case
8 BOf those twenty taken by the two addresses
255The maximum TTL, decremented once at every router
0Bytes of payload the header checksum protects
Short answer

The IPv4 header is 20 bytes in front of every packet, holding twelve fields. Eight of those bytes are the source and destination addresses. Six fields come up in real work: TTL, protocol, the DF bit, total length, DSCP and the addresses. The rest is machinery you never touch.

  • 20 bytes minimum, and 8 of them are the two addresses
  • TTL is a hop count, not a time, despite the name
  • The protocol field is why a tunnel rule names no port
  • The checksum covers the header only, never the payload
  • Every router recomputes it, because every router changes the TTL
On this page

The layoutThe header, laid out

Each row below is 32 bits, which is how the IPv4 header is always drawn and how the length field counts its size.

0                   1                   2                   3
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
+-------+-------+---------------+-------------------------------+
| Ver   | IHL   | DSCP     | ECN|          Total length         |
+-------+-------+---------------+---+---------------------------+
|         Identification        |Flg|      Fragment offset      |
+---------------+---------------+---+---------------------------+
|      TTL      |   Protocol    |        Header checksum        |
+---------------+---------------+-------------------------------+
|                        Source address                         |
+---------------------------------------------------------------+
|                      Destination address                      |
+---------------------------------------------------------------+

Five rows of four bytes each, which is the minimum size of an IPv4 header. Everything after that is the data, which is usually a TCP or UDP header followed by the payload.

The six that matterThe six fields you actually meet

Every guide to the IPv4 header lists all twelve fields. These are the ones that come up in a working week.

The TTL field, time to live. An 8 bit counter, decremented by one at every router. At zero the datagram is discarded and an ICMP time exceeded message goes back to the sender.

It exists to stop a packet circling forever in a routing loop, and it is the entire mechanism behind traceroute, which sends packets with deliberately small TTLs so each router in turn announces itself.

It is also a rough fingerprint. Common starting values are 64 on Linux and macOS, 128 on Windows, and 255 on network equipment. A reply arriving with TTL 57 probably started at 64 and crossed seven routers.

The protocol field. An 8 bit value naming what is inside the IPv4 packet. This is why a firewall rule for a tunnel names a protocol rather than a port: IPsec in transport form is protocol 50, which has no ports at all, so a rule written in terms of ports matches nothing.

NumberProtocol
1ICMP
6TCP
17UDP
47GRE
50ESP, the encrypted part of IPsec
51AH, the authentication part of IPsec
89OSPF

The DF bit. One bit in the three bit flags field, meaning do not fragment. When it is set, a router that cannot fit the datagram on the next link must discard it and return an ICMP error rather than fragmenting it.

That is path MTU discovery in one bit, and the reason a VPN tunnel opens and then hangs when the error is blocked.

The total length field. 16 bits covering the IPv4 header plus the data, so the theoretical maximum size of a datagram is 65,535 bytes. In practice the link MTU decides, which is why almost every packet you will ever see is 1500 bytes or less.

The DSCP field. Six bits marking how the packet should be prioritized, used by quality of service policies to put voice ahead of a file transfer.

The important operational fact is that these bits are only meaningful inside a network that agrees to honor the value: most providers rewrite or ignore them at the edge, so marking a datagram for priority does not mean it gets any once it leaves.

The source and destination address fields. 32 bits each, and the only fields most people think about. Worth noting for the same reason as DSCP: the source address is written by the sender and nothing in the IPv4 header verifies it, which is what makes address spoofing possible and why reflection attacks work.

The other sixThe fields you will probably never touch

The other six fields of the IPv4 header exist and rarely matter outside a packet capture.

The version field. Four bits holding the value 4. It is how a receiver distinguishes an IPv4 datagram from IPv6 on the same wire.

The IHL field, header length. Four bits counting the IPv4 header in 32 bit words. The value is 5 for a normal 20 byte header, and larger only when options are present. The maximum value of 15 is what caps the header size at 60 bytes.

The ECN field. Two bits letting a congested router mark a datagram rather than dropping it, so the sender slows down without losing any data. A good idea that took a long time to be widely enabled.

Identification, flags and fragment offset. The three fields that make fragmentation work. Every fragment of one original datagram carries the same identification value; the more fragments flag says whether another fragment follows; the fragment offset says where this piece of data belongs. The destination uses all three fields to reassemble it.

The header checksum field. Sixteen bits covering the IPv4 header alone, not the data, because TCP and UDP carry their own checksums over their own payloads. Every router has to recompute the value, because every router changes the TTL. That per hop cost is one of the reasons IPv6 removed the field entirely.

The options field. Variable length, almost never used, and frequently dropped or deprioritized by routers when it is. Anything relying on IPv4 options should be assumed not to work across the internet.

Against IPv6What IPv6 changed, and why

The IPv6 header is a useful mirror, because every difference is a deliberate decision about what the IPv4 header got wrong.

It is fixed at 40 bytes. Longer, because the addresses are four times the size, and fixed, because a variable header costs a router work on every packet.

There is no checksum field. Removed entirely. The layer below catches corruption and the layer above has its own checksum, so recomputing a header value at every hop bought very little.

The fragment fields moved out of the base header. IPv6 routers never fragment, and a sender that needs to uses an extension header, which keeps the common case simple.

Options became extension headers. Chained after the base header rather than embedded in it, so a router that does not care about them skips straight past.

PitfallsWhere people go wrong

Reading the TTL field as a time. It is a hop count, despite the name. Nothing about the value is measured in seconds on any modern network.

Writing a firewall rule with ports for a tunnel. ESP is protocol 50 and GRE is protocol 47, and neither has ports. A rule naming a port matches nothing at all.

Expecting DSCP markings to survive. They are honored inside networks configured to honor them and commonly rewritten at any boundary you do not control.

Trusting the source address. Nothing in the header authenticates it. Every reflection and amplification attack starts with a forged source address.

Assuming the checksum protects the data. It covers the IPv4 header only. Corrupted data in the payload is caught by TCP or UDP, or not at all.

Chasing IPv4 options. The field exists in the specification and is unreliable in practice, so any design that depends on it will work in the lab and fail on the internet.

Ignoring the DF bit while debugging a hang. A connection that opens and then stops on the first large transfer is that one bit meeting a smaller link, with the error blocked on the way back.

FIVE ROWS OF FOUR BYTES, AND THE SIX FIELDS YOU MEET IN PRACTICEVersion | IHL | DSCP + ECN | Total lengthtotal length is one of the sixIdentification | Flags, with DF | Fragment offsetthe DF bit is one of the sixTTL | Protocol | Header checksumTTL and protocol are two moreSource addressfour bytesDestination addressfour bytes, and that is eight of twentyThe checksum covers the header alone, never the payload, and every router recomputes it.Those six fields explain traceroute, MTU failures, and why a tunnel rule names a protocol.The other six are real, specified, and almost never something you touch.
The header to scale. Most guides give all twelve fields equal weight, and the six highlighted here are the ones that come up in a working week.

ComparisonThe two headers, and what every difference removes from a router

CriterionIPv4IPv6
Base header size20 bytes, variable to 6040 bytes, fixed
Address size32 bits128 bits
Header checksumYes, recomputed per hopNone
Routers may fragmentYesNo
OptionsInside the headerChained after it
Hop counterTTLHop limit, same idea

FAQFrequently asked questions

How big is the IPv4 header?

20 bytes without options, which is almost always the case, and up to 60 bytes with them. The IHL field counts the size in 32 bit words.

What is the TTL field in the IPv4 header?

An 8 bit hop counter, decremented at every router. At zero the datagram is discarded and an ICMP time exceeded message is returned, which is what makes traceroute work.

What are the common TTL starting values?

64 on Linux and macOS, 128 on Windows, and 255 on much network equipment. A received TTL of 57 suggests a start of 64 and seven hops.

What is the protocol field for?

It names what is inside the IPv4 packet, so the receiver knows which handler to pass the data to. 6 is TCP, 17 is UDP, 1 is ICMP, 47 is GRE and 50 is ESP.

Why does an IPsec firewall rule not use a port?

Because ESP is protocol 50 and has no ports. Ports belong to TCP and UDP, so a rule for a protocol that is not one of those has to name the protocol number.

What is the DF bit?

Do not fragment. When it is set, a router that cannot fit the packet must discard it and return an ICMP error naming the size that would fit, rather than splitting it.

What does the header checksum cover?

The IPv4 header only. TCP and UDP have their own checksums over their own data, so this field never protects the payload.

Why is the checksum recomputed at every hop?

Because every router decrements the TTL, which changes the header, which changes the checksum. IPv6 removed the field partly to avoid that cost.

What is DSCP?

Six bits marking the priority a packet should receive. It works inside networks configured to honor it and is routinely rewritten or ignored at a boundary you do not control.

What is the maximum size of an IPv4 datagram?

65,535 bytes, from the 16 bit total length field. In practice the link MTU limits the size to 1500 bytes on Ethernet, which is why larger packets are rare.

How does fragmentation use the IPv4 header?

Three fields together: identification ties the fragments to one original datagram, the more fragments flag says whether another follows, and the fragment offset says where this piece belongs.

How is the IPv6 header different?

Fixed at 40 bytes, no checksum, no fragmentation fields in the base header, and options chained after it rather than embedded. Every difference removes per hop work from routers.

Where do I see the IPv4 header in practice?

In a packet capture, where the middle pane decodes every field with its value labeled.

What are the IP header fields?

The IP header fields in IPv4 are version, header length, DSCP and ECN, total length, identification, flags, fragment offset, time to live, protocol, header checksum, source address, destination address and optional options. Without options the header is 20 bytes.

Read next · Protocols What Is ICMP? A TTL that reaches zero produces an ICMP time exceeded message, which is the whole of how traceroute works. Open this next11 min
Also worth reading
One packet a weekA short, illustrated explainer every Tuesday. No vendor pitches, unsubscribe in one click.