The IPv4 header is 20 bytes in front of every packet, holding twelve fields. Eight of those bytes are the source and destination addresses. Six fields come up in real work: TTL, protocol, the DF bit, total length, DSCP and the addresses. The rest is machinery you never touch.
- 20 bytes minimum, and 8 of them are the two addresses
- TTL is a hop count, not a time, despite the name
- The protocol field is why a tunnel rule names no port
- The checksum covers the header only, never the payload
- Every router recomputes it, because every router changes the TTL
On this page
The layoutThe header, laid out
Each row below is 32 bits, which is how the IPv4 header is always drawn and how the length field counts its size.
0 1 2 3
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
+-------+-------+---------------+-------------------------------+
| Ver | IHL | DSCP | ECN| Total length |
+-------+-------+---------------+---+---------------------------+
| Identification |Flg| Fragment offset |
+---------------+---------------+---+---------------------------+
| TTL | Protocol | Header checksum |
+---------------+---------------+-------------------------------+
| Source address |
+---------------------------------------------------------------+
| Destination address |
+---------------------------------------------------------------+
Five rows of four bytes each, which is the minimum size of an IPv4 header. Everything after that is the data, which is usually a TCP or UDP header followed by the payload.
The six that matterThe six fields you actually meet
Every guide to the IPv4 header lists all twelve fields. These are the ones that come up in a working week.
The TTL field, time to live. An 8 bit counter, decremented by one at every router. At zero the datagram is discarded and an ICMP time exceeded message goes back to the sender.
It exists to stop a packet circling forever in a routing loop, and it is the entire mechanism behind traceroute, which sends packets with deliberately small TTLs so each router in turn announces itself.
It is also a rough fingerprint. Common starting values are 64 on Linux and macOS, 128 on Windows, and 255 on network equipment. A reply arriving with TTL 57 probably started at 64 and crossed seven routers.
The protocol field. An 8 bit value naming what is inside the IPv4 packet. This is why a firewall rule for a tunnel names a protocol rather than a port: IPsec in transport form is protocol 50, which has no ports at all, so a rule written in terms of ports matches nothing.
| Number | Protocol |
|---|---|
| 1 | ICMP |
| 6 | TCP |
| 17 | UDP |
| 47 | GRE |
| 50 | ESP, the encrypted part of IPsec |
| 51 | AH, the authentication part of IPsec |
| 89 | OSPF |
The DF bit. One bit in the three bit flags field, meaning do not fragment. When it is set, a router that cannot fit the datagram on the next link must discard it and return an ICMP error rather than fragmenting it.
That is path MTU discovery in one bit, and the reason a VPN tunnel opens and then hangs when the error is blocked.
The total length field. 16 bits covering the IPv4 header plus the data, so the theoretical maximum size of a datagram is 65,535 bytes. In practice the link MTU decides, which is why almost every packet you will ever see is 1500 bytes or less.
The DSCP field. Six bits marking how the packet should be prioritized, used by quality of service policies to put voice ahead of a file transfer.
The important operational fact is that these bits are only meaningful inside a network that agrees to honor the value: most providers rewrite or ignore them at the edge, so marking a datagram for priority does not mean it gets any once it leaves.
The source and destination address fields. 32 bits each, and the only fields most people think about. Worth noting for the same reason as DSCP: the source address is written by the sender and nothing in the IPv4 header verifies it, which is what makes address spoofing possible and why reflection attacks work.
The other sixThe fields you will probably never touch
The other six fields of the IPv4 header exist and rarely matter outside a packet capture.
The version field. Four bits holding the value 4. It is how a receiver distinguishes an IPv4 datagram from IPv6 on the same wire.
The IHL field, header length. Four bits counting the IPv4 header in 32 bit words. The value is 5 for a normal 20 byte header, and larger only when options are present. The maximum value of 15 is what caps the header size at 60 bytes.
The ECN field. Two bits letting a congested router mark a datagram rather than dropping it, so the sender slows down without losing any data. A good idea that took a long time to be widely enabled.
Identification, flags and fragment offset. The three fields that make fragmentation work. Every fragment of one original datagram carries the same identification value; the more fragments flag says whether another fragment follows; the fragment offset says where this piece of data belongs. The destination uses all three fields to reassemble it.
The header checksum field. Sixteen bits covering the IPv4 header alone, not the data, because TCP and UDP carry their own checksums over their own payloads. Every router has to recompute the value, because every router changes the TTL. That per hop cost is one of the reasons IPv6 removed the field entirely.
The options field. Variable length, almost never used, and frequently dropped or deprioritized by routers when it is. Anything relying on IPv4 options should be assumed not to work across the internet.
Against IPv6What IPv6 changed, and why
The IPv6 header is a useful mirror, because every difference is a deliberate decision about what the IPv4 header got wrong.
It is fixed at 40 bytes. Longer, because the addresses are four times the size, and fixed, because a variable header costs a router work on every packet.
There is no checksum field. Removed entirely. The layer below catches corruption and the layer above has its own checksum, so recomputing a header value at every hop bought very little.
The fragment fields moved out of the base header. IPv6 routers never fragment, and a sender that needs to uses an extension header, which keeps the common case simple.
Options became extension headers. Chained after the base header rather than embedded in it, so a router that does not care about them skips straight past.
PitfallsWhere people go wrong
Reading the TTL field as a time. It is a hop count, despite the name. Nothing about the value is measured in seconds on any modern network.
Writing a firewall rule with ports for a tunnel. ESP is protocol 50 and GRE is protocol 47, and neither has ports. A rule naming a port matches nothing at all.
Expecting DSCP markings to survive. They are honored inside networks configured to honor them and commonly rewritten at any boundary you do not control.
Trusting the source address. Nothing in the header authenticates it. Every reflection and amplification attack starts with a forged source address.
Assuming the checksum protects the data. It covers the IPv4 header only. Corrupted data in the payload is caught by TCP or UDP, or not at all.
Chasing IPv4 options. The field exists in the specification and is unreliable in practice, so any design that depends on it will work in the lab and fail on the internet.
Ignoring the DF bit while debugging a hang. A connection that opens and then stops on the first large transfer is that one bit meeting a smaller link, with the error blocked on the way back.
ComparisonThe two headers, and what every difference removes from a router
| Criterion | IPv4 | IPv6 |
|---|---|---|
| Base header size | 20 bytes, variable to 60 | 40 bytes, fixed |
| Address size | 32 bits | 128 bits |
| Header checksum | Yes, recomputed per hop | None |
| Routers may fragment | Yes | No |
| Options | Inside the header | Chained after it |
| Hop counter | TTL | Hop limit, same idea |
FAQFrequently asked questions
How big is the IPv4 header?
20 bytes without options, which is almost always the case, and up to 60 bytes with them. The IHL field counts the size in 32 bit words.
What is the TTL field in the IPv4 header?
An 8 bit hop counter, decremented at every router. At zero the datagram is discarded and an ICMP time exceeded message is returned, which is what makes traceroute work.
What are the common TTL starting values?
64 on Linux and macOS, 128 on Windows, and 255 on much network equipment. A received TTL of 57 suggests a start of 64 and seven hops.
What is the protocol field for?
It names what is inside the IPv4 packet, so the receiver knows which handler to pass the data to. 6 is TCP, 17 is UDP, 1 is ICMP, 47 is GRE and 50 is ESP.
Why does an IPsec firewall rule not use a port?
Because ESP is protocol 50 and has no ports. Ports belong to TCP and UDP, so a rule for a protocol that is not one of those has to name the protocol number.
What is the DF bit?
Do not fragment. When it is set, a router that cannot fit the packet must discard it and return an ICMP error naming the size that would fit, rather than splitting it.
What does the header checksum cover?
The IPv4 header only. TCP and UDP have their own checksums over their own data, so this field never protects the payload.
Why is the checksum recomputed at every hop?
Because every router decrements the TTL, which changes the header, which changes the checksum. IPv6 removed the field partly to avoid that cost.
What is DSCP?
Six bits marking the priority a packet should receive. It works inside networks configured to honor it and is routinely rewritten or ignored at a boundary you do not control.
What is the maximum size of an IPv4 datagram?
65,535 bytes, from the 16 bit total length field. In practice the link MTU limits the size to 1500 bytes on Ethernet, which is why larger packets are rare.
How does fragmentation use the IPv4 header?
Three fields together: identification ties the fragments to one original datagram, the more fragments flag says whether another follows, and the fragment offset says where this piece belongs.
How is the IPv6 header different?
Fixed at 40 bytes, no checksum, no fragmentation fields in the base header, and options chained after it rather than embedded. Every difference removes per hop work from routers.
Where do I see the IPv4 header in practice?
In a packet capture, where the middle pane decodes every field with its value labeled.
What are the IP header fields?
The IP header fields in IPv4 are version, header length, DSCP and ECN, total length, identification, flags, fragment offset, time to live, protocol, header checksum, source address, destination address and optional options. Without options the header is 20 bytes.
Keep readingRelated concepts
Read next · Protocols What Is ICMP? A TTL that reaches zero produces an ICMP time exceeded message, which is the whole of how traceroute works. Open this next11 min- Diagnostics · 12 min Reading a Wireshark Capture Without Drowning in Packets The details pane decodes every one of these fields with its value labeled, which is the fastest way to learn them.
- Diagnostics · 12 min MTU and Fragmentation, and the Numbers Worth Memorizing The DF bit and the three fragment fields are one topic, and that page is where it is worked through.
- Protocols · 10 min The TCP Header, Field by Field, and What to Read in a Capture The other header in every packet, field by field.