Routelearn.net
Course menu

Unit 13: Complete Packet FlowLesson 13.2 (2 of 3 in this unit)71 of 84 in the Network Fundamentals course

Different-Subnet Communication: A Packet Through a Router

PC-A on 192.168.10.0/24 sends a packet to a server on 192.168.20.0/24, with one router between them. Follow the packet through all thirteen steps and watch one of the most important rules in networking in action: the MAC addresses are replaced at the router, while the IP addresses stay the same from end to end.

Beginner · 18 min read · Before this: Same-Subnet Communication, The Default Gateway, ARP for Local and Remote Destinations

Different-subnet communication is delivery between hosts in different IP subnets. The sender frames the packet to its default gateway’s MAC address; each router removes the frame, looks up the destination in its routing table, decrements the TTL and builds a new frame for the next hop, while the source and destination IP addresses stay the same (when no NAT is involved).

In simple terms: When the destination is on another network, your computer sends the packet to the router. The router sends it on in a new frame with new MAC addresses, but the IP addresses stay the same.

In Same-subnet communication, the packet went straight from PC-A to PC-B through a switch. Most real traffic is not like that: your printer may be local, but your file server, your email and every website are on other networks. To reach them, traffic must go through a router. This lesson shows exactly what that changes, one step at a time.

What different-subnet communication is

Different-subnet communication (also called inter-subnet or remote communication) is any traffic where the destination IP address is outside the sender's own subnet. A switch alone cannot deliver it, because switches only connect devices inside one network. A router connects networks and moves packets between them.

Networks are split up on purpose: to keep broadcast traffic small, to separate departments for security, and because the internet itself is made of millions of separate networks.

Learn more: Network Segmentation

💡 In simple terms: sending to another subnet is like posting a letter to another city. You don't walk it there. You hand it to the post office (your default gateway), and each sorting office passes it to the next. The address on the letter (the IP address) never changes, but the van carrying it (the frame) changes at every office.

The lab

This lab has two networks and one router. PC-A pings the server; the steps are the same for any traffic, such as opening a web page on that server.

Device / interfaceIP address / maskDefault gatewayMAC addressNotes
PC-A192.168.10.10/24192.168.10.102:00:00:00:00:aaLAN 10, on SW1
R1 G0/0 (LAN 10)192.168.10.1/24-02:00:00:00:00:01PC-A's default gateway
R1 G0/1 (LAN 20)192.168.20.1/24-02:00:00:00:00:02The server's default gateway
Server192.168.20.10/24192.168.20.102:00:00:00:00:ccLAN 20, on SW2

Notice that the router has two interfaces, one in each network, and each interface has its own IP address and its own MAC address. That detail is the key to the whole lesson.

G0/0 .10.1G0/1 .20.1PC-A.10.10 · …:aa192.168.10.0/24SW1R1…:01 | …:02192.168.20.0/24SW2Server.20.10 · …:cc
  1. 1. PC-A decides. 192.168.20.10 is not in 192.168.10.0/24, so the packet must go to the default gateway, 192.168.10.1.
  2. 2. ARP for the gateway. PC-A broadcasts an ARP request for R1's LAN 10 address, not for the server.
  3. 3. R1 replies. PC-A caches 192.168.10.1 → 02:00:00:00:00:01.
  4. 4. Frame to the router, packet to the server. The destination MAC address is R1's; the destination IP address is the server's. TTL 128.
  5. 5. R1 routes. R1 removes the frame, finds 192.168.20.0/24 directly connected on G0/1 and lowers the TTL to 127.
  6. 6. R1 uses ARP on the far side. R1 needs the server's MAC address on LAN 20, so it sends an ARP request from its G0/1 interface.
  7. 7. The server replies to R1. R1 caches 192.168.20.10 → 02:00:00:00:00:cc.
  8. 8. R1 sends a new frame. New MAC addresses, same IP addresses, TTL 127. The server receives and unwraps it.
  9. 9. The reply comes back the same way. The server uses its own gateway, 192.168.20.1. R1 builds a new frame for LAN 10.
Two links, two frames. The packet inside keeps its IP addresses the whole way.

Where the router sits and what it needs

ComponentWho has itUsed in step
Subnet maskPC-A2: is the destination local or remote?
Default gateway settingPC-A (and the server, for the reply)3: where to send remote traffic
ARP cachePC-A and R1, each for its own link4 and 12
Routing tableR110 and 11: which way to the destination
Two interfaces, two MAC addressesR18 (receives on G0/0) and 12 (sends on G0/1)

Phase 1: PC-A decides the destination is remote (steps 1 to 3)

Step 1: PC-A checks the destination IP address

On PC-A

The application asks to reach 192.168.20.10. PC-A fills in what it already knows: its own MAC address, its own IP address and the destination IP address. The TTL starts at 128, the Windows default.

Addresses at this step
Source MAC
02:00:00:00:00:aa
Destination MAC
not known yet
Source IP
192.168.10.10
Destination IP
192.168.20.10
TTL
128

Step 2: PC-A compares networks and finds the destination is remote

On PC-A

PC-A applies its own subnet mask (/24) to both addresses:

AddressNetwork part (/24)
PC-A192.168.10.10192.168.10.0
Destination192.168.20.10192.168.20.0

The network parts differ (10 vs 20 in the third number). The server is remote, so PC-A cannot deliver the packet directly.

Addresses at this step
Source MAC
02:00:00:00:00:aa
Destination MAC
not known yet
Source IP
192.168.10.10
Destination IP
192.168.20.10
TTL
128
Decisionchanged
Remote: 192.168.20.0 ≠ 192.168.10.0

Step 3: PC-A selects its default gateway

On PC-A

For remote destinations, PC-A uses its default gateway: 192.168.10.1, R1's LAN 10 interface. The gateway becomes the next hop: the device this frame is handed to. The final destination is still the server.

The gateway must be in PC-A's own subnet. PC-A can only send frames to devices on its own link, so a gateway address on another network would be useless.

Addresses at this step
Source MAC
02:00:00:00:00:aa
Destination MACchanged
gateway's MAC (to be found)
Source IP
192.168.10.10
Destination IP
192.168.20.10
TTL
128
Next hopchanged
192.168.10.1 (default gateway)

Phase 2: getting the packet to the router (steps 4 to 7)

Step 4: PC-A uses ARP to find the gateway's MAC address (not the server's)

PC-A → SW1 → R1

PC-A checks its ARP cache for 192.168.10.1. If it is not there, it broadcasts: “Who has 192.168.10.1?” R1 answers with the MAC address of its G0/0 interface, 02:00:00:00:00:01. In practice, this entry is almost always already cached, because every remote packet uses the gateway.

⚠️ PC-A never sends an ARP request for 192.168.20.10. ARP broadcasts do not cross routers, so no device on LAN 10 could answer anyway.

Learn more: ARP for Local and Remote Destinations

ARP request and reply
Request dst MAC
ff:ff:ff:ff:ff:ff
Asks forchanged
192.168.10.1
Reply src MAC
02:00:00:00:00:01
PC-A caches
192.168.10.1 → …:01

Step 5: PC-A builds the frame

On PC-A

Now PC-A has everything it needs to encapsulate: the ICMP message goes into an IP packet, and the IP packet goes into an Ethernet frame with EtherType 0x0800.

Addresses at this step
Source MAC
02:00:00:00:00:aa
Destination MACchanged
02:00:00:00:00:01
Source IP
192.168.10.10
Destination IP
192.168.20.10
TTL
128

Step 6: Destination MAC address = the gateway's MAC address

Ethernet header (Layer 2)

The Ethernet header is addressed to the next hop, R1. It answers the question “which device on this link should accept this frame?”

The key Layer 2 field
Destination MACchanged
02:00:00:00:00:01 (R1 G0/0)

Step 7: Destination IP address = the server's IP address

IP header (Layer 3)

The IP header is addressed to the final destination, the server. It answers the question “where is this packet finally going?” This mismatch (the MAC address of one device, the IP address of another) is completely normal for remote traffic.

The key Layer 3 field
Destination IP
192.168.20.10 (the server)

Frame 1: on LAN 10, between PC-A and R1

The MAC address points to the next hop; the IP address points to the final destination

Layer 2 · Ethernet header (this hop)
Destination MAC
02:00:00:00:00:01
R1 G0/0, the gateway
Source MAC
02:00:00:00:00:aa
PC-A
EtherType
0x0800
IPv4
Layer 3 · IP header (end to end)
Source IP
192.168.10.10
PC-A
Destination IP
192.168.20.10
The server
TTL 128 · protocol 1 (ICMP) · ICMP Echo Request

SW1 forwards this frame exactly as in the same-subnet lesson: it learns PC-A's MAC address on its port and sends the frame out of the port where it learned R1's MAC address. To SW1, the router is just another MAC address.

Phase 3: inside the router (steps 8 to 11)

Step 8: R1 receives the frame on G0/0

On R1, interface G0/0

R1's G0/0 sees a frame whose destination MAC address is its own, 02:00:00:00:00:01, so it accepts it. It checks the FCS and reads EtherType 0x0800: this is an IPv4 packet for the routing process.

Addresses at this step
Source MAC
02:00:00:00:00:aa
Destination MAC
02:00:00:00:00:01
Source IP
192.168.10.10
Destination IP
192.168.20.10
TTL
128

Step 9: R1 removes the Layer 2 header

On R1

The Ethernet header and trailer have done their job: they carried the packet across LAN 10. R1 discards them. What remains is the IP packet, which is what the router uses to make its decision. This is de-encapsulation up to Layer 3, and it is why a router is called a Layer 3 device.

What is left: the bare IP packet
Source MACchanged
(discarded)
Destination MACchanged
(discarded)
Source IP
192.168.10.10
Destination IP
192.168.20.10

Step 10: R1 checks its routing table

On R1

A routing table is the router's list of known networks and how to reach each one. R1 compares the destination IP address with the entries and chooses the most specific match (the longest prefix match):

NetworkHow R1 knows itExit interfaceMatches 192.168.20.10?
192.168.10.0/24Directly connectedG0/0No
192.168.20.0/24Directly connectedG0/1Yes

R1 also lowers the TTL (Time To Live) by one, from 128 to 127, and recalculates the IP header checksum. If the TTL had reached 0, R1 would drop the packet and send an ICMP Time Exceeded message back to PC-A instead.

If no route matched at all (and there was no default route), R1 would drop the packet and send back an ICMP Destination Unreachable message.

Routing table lookup
Looking for
192.168.20.10
Best matchchanged
192.168.20.0/24 (connected)
TTLchanged
128 → 127

Step 11: R1 chooses the next hop and the exit interface

On R1

Because 192.168.20.0/24 is directly connected, the destination is on R1's own G0/1 link, so the next hop is the server itself. If the server were further away, the route would point to another router's IP address as the next hop, and R1 would send the frame to that router instead. The same process would then repeat on that router.

Forwarding decision
Exit interfacechanged
G0/1 (192.168.20.1)
Next hop
192.168.20.10 (the server itself)

Phase 4: a new frame on the far side (steps 12 and 13)

Step 12: R1 uses ARP on the far side and builds a new frame

On R1, interface G0/1

R1 checks its own ARP cache for 192.168.20.10. If the entry is missing, R1 broadcasts an ARP request out of G0/1 (from 02:00:00:00:00:02) and the server replies with 02:00:00:00:00:cc. Then R1 builds a new Ethernet frame:

  • Source MAC: 02:00:00:00:00:02, R1's G0/1 (the interface it is sending from).
  • Destination MAC: 02:00:00:00:00:cc, the next hop on this link.
  • Inside: the same IP packet, with the same source and destination IP addresses, and TTL 127.

Many routers, including Cisco routers, drop the packet that triggered the ARP request while they wait for the reply. That is why the first ping across a router sometimes shows “Request timed out” while the rest succeed.

Addresses at this step
Source MACchanged
02:00:00:00:00:02
Destination MACchanged
02:00:00:00:00:cc
Source IP
192.168.10.10
Destination IP
192.168.20.10
TTLchanged
127

Step 13: The packet is delivered

SW2 → Server

SW2 forwards the frame to the server's port. The server sees its own MAC address, removes the Ethernet header, sees its own IP address and passes the ICMP Echo Request to ICMP, which builds a reply. This is exactly what PC-B did in the same-subnet lesson.

Addresses at this step
Source MAC
02:00:00:00:00:02
Destination MAC
02:00:00:00:00:cc
Source IP
192.168.10.10
Destination IP
192.168.20.10
TTL
127

Before and after the router: what changed?

This is the most important comparison in the unit. Put the frame on LAN 10 next to the frame on LAN 20:

Before R1 (LAN 10)

PC-A → R1

Layer 2 · Ethernet header (this hop)
Destination MAC
02:00:00:00:00:01
R1 G0/0
Source MAC
02:00:00:00:00:aa
PC-A
EtherType
0x0800
Layer 3 · IP header (end to end)
Source IP
192.168.10.10
PC-A
Destination IP
192.168.20.10
Server
TTL 128 · ICMP Echo Request

After R1 (LAN 20)

R1 → Server

Layer 2 · Ethernet header (this hop)
Destination MAC
02:00:00:00:00:cc
Server
Source MAC
02:00:00:00:00:02
R1 G0/1
EtherType
0x0800
Layer 3 · IP header (end to end)
Source IP
192.168.10.10
unchanged
Destination IP
192.168.20.10
unchanged
TTL 127 · ICMP Echo Request (same data)
Frame 1
LAN 10 · PC-A → R1
Source MAC
…:aa
Destination MAC
…:01
Source IP
192.168.10.10
Destination IP
192.168.20.10
TTL
128
Frame 2
LAN 20 · R1 → Server
Source MAC
…:02 (rewritten)
Destination MAC
…:cc (rewritten)
Source IP
192.168.10.10
Destination IP
192.168.20.10
TTL
127 (rewritten)

Highlighted fields were rewritten by the router.

Highlighted fields were rewritten by R1. Everything else crossed the router untouched.
FieldBefore R1After R1Changed?Why
Source MAC…:aa (PC-A)…:02 (R1 G0/1)YesThe sender on the new link is R1
Destination MAC…:01 (R1 G0/0)…:cc (server)YesThe next hop on the new link is the server
Source IP192.168.10.10192.168.10.10NoThe packet still comes from PC-A
Destination IP192.168.20.10192.168.20.10NoThe packet is still going to the server
TTL128127Yes, minus 1Each router lowers it, to prevent endless loops
Data (ICMP)Echo RequestEcho RequestNoRouters do not change the payload
✅ The golden rule of routing
  • MAC addresses change at every router. They only describe one link: “from this interface to that interface on this link”.
  • Source and destination IP addresses stay the same from end to end, unless NAT changes them (for example, on a home router sending traffic to the internet).
  • The TTL decreases by one at every router.
  • Switches change nothing. Only routers build new frames.

Learn more: How NAT and PAT Work

Step 1 of 8 · ARP request
Two subnets, one router · 192.168.10.0/24 ↔ 192.168.20.0/24
PC-A
192.168.10.10
R1
.10.1 | .20.1
Server
192.168.20.10

1. ARP request · Broadcast on LAN 10

Who has 192.168.10.1?

Two ARP exchanges (one per link), then the packet crosses R1 twice: once each way.

The reply journey

The server runs the same logic in reverse. It sees that 192.168.10.10 is not in 192.168.20.0/24, so it sends the reply to its default gateway, 192.168.20.1 (MAC address 02:00:00:00:00:02). R1 removes that frame, finds 192.168.10.0/24 on G0/0, lowers the TTL and builds a new frame from 02:00:00:00:00:01 to 02:00:00:00:00:aa.

⚠️ This means both ends need a correct default gateway. If the server's gateway is missing or wrong, PC-A's request arrives but the reply never leaves LAN 20, and PC-A sees “Request timed out”.

A real-world example

A company puts staff laptops in 192.168.10.0/24 and its servers in 192.168.20.0/24, so it can control what reaches the servers. When Sam opens the intranet site at 192.168.20.10, his laptop sends every frame to the gateway's MAC address. The core router (in an office, often a Layer 3 switch) routes each packet and builds new frames on the server network. Traffic to the internet works the same way, with more routers and with NAT at the edge.

Learn more: What Happens When You Open a Website?

What happens when it fails

ProblemStep that failsSymptom
No default gateway on PC-A3Local pings work; anything remote fails at once (“General failure” on Windows or “Network is unreachable” on Linux).
Wrong gateway IP on PC-A4ARP for the gateway gets no reply. “Destination host unreachable” from PC-A's own address.
Wrong subnet mask on PC-A2PC-A may think a remote host is local and send an ARP request for it directly. No device answers (unless the router uses proxy ARP).
R1 has no route to the destination10“Destination net unreachable” sent back from R1's address.
Router interface G0/1 down10/11The connected route disappears, and R1 replies with an “unreachable” message.
Server is off12R1's ARP request for .20.10 gets no reply. Usually “Request timed out” or “Destination host unreachable” from R1.
Wrong default gateway on the serverReply pathThe request arrives, but the reply is never routed back. “Request timed out”.
A routing loop10, repeatedlyThe TTL runs out: “TTL expired in transit”.

Troubleshooting and useful commands

Follow the packet and test each hop in order:

  1. Check PC-A's IP address, subnet mask and default gateway (ipconfig).
  2. Ping the gateway, 192.168.10.1. If this fails, the problem is on LAN 10.
  3. Ping R1's far-side interface, 192.168.20.1. A reply shows that PC-A's traffic reaches R1 and R1 can answer.
  4. Ping the server. Then run tracert to see where it stops.
  5. On the router, check the routing table and the ARP table.
Example output from a Windows PC, written for this lesson
C:\>ipconfig
Windows IP Configuration


Ethernet adapter Ethernet:

   Connection-specific DNS Suffix  . :
   IPv4 Address. . . . . . . . . . . : 192.168.10.10
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Default Gateway . . . . . . . . . : 192.168.10.1
What to look for: steps 2 and 3 depend on exactly these three lines. The IPv4 Address and Subnet Mask put PC-A in 192.168.10.0/24, and the Default Gateway 192.168.10.1 is where PC-A sends traffic for any other network.
Example output from a Windows PC, written for this lesson
C:\>ping 192.168.20.10
Pinging 192.168.20.10 with 32 bytes of data:
Request timed out.
Reply from 192.168.20.10: bytes=32 time=1ms TTL=63
Reply from 192.168.20.10: bytes=32 time<1ms TTL=63
Reply from 192.168.20.10: bytes=32 time<1ms TTL=63

Ping statistics for 192.168.20.10:
    Packets: Sent = 4, Received = 3, Lost = 1 (25% loss),
Approximate round trip times in milli-seconds:
    Minimum = 0ms, Maximum = 1ms, Average = 0ms
What to look for: the first Request timed out was lost while R1 used ARP to find the server's MAC address (step 12). The next three replies show the path works. TTL=63 tells you more: the server (running Linux) started its reply at 64, and one router lowered it by one on the way back.
Example output from a Windows PC, written for this lesson
C:\>tracert -d 192.168.20.10
Tracing route to 192.168.20.10 over a maximum of 30 hops

  1    <1 ms    <1 ms    <1 ms  192.168.10.1
  2     1 ms    <1 ms    <1 ms  192.168.20.10

Trace complete.
What to look for: hop 1 is the default gateway, 192.168.10.1, and hop 2 is the destination. If the trace stopped after hop 1 with * timeouts, the problem would be beyond R1. The -d option skips DNS name lookups, so the trace runs faster.

Learn more: Traceroute

Example output from a Linux PC, written for this lesson
$ ip route get 192.168.20.10
192.168.20.10 via 192.168.10.1 dev eth0 src 192.168.10.10 uid 1000
    cache
What to look for: via 192.168.10.1 is Linux confirming steps 2 and 3: the destination is remote, so it goes to the gateway. dev eth0 is the interface used, and src 192.168.10.10 is the source IP address.
Example output · based on Cisco documentation; exact format varies by platform and software version
R1#show ip route connected
      192.168.10.0/24 is variably subnetted, 2 subnets, 2 masks
C        192.168.10.0/24 is directly connected, GigabitEthernet0/0
L        192.168.10.1/32 is directly connected, GigabitEthernet0/0
      192.168.20.0/24 is variably subnetted, 2 subnets, 2 masks
C        192.168.20.0/24 is directly connected, GigabitEthernet0/1
L        192.168.20.1/32 is directly connected, GigabitEthernet0/1
What to look for: the C (connected) line for 192.168.20.0/24 on GigabitEthernet0/1 is the match used in step 10. The L (local) lines are R1's own interface addresses.

Learn more: Reading the Routing Table

Example output · based on Cisco documentation; exact format varies by platform and software version
R1#show ip arp
Protocol  Address          Age (min)  Hardware Addr   Type   Interface
Internet  192.168.10.1            -   0200.0000.0001  ARPA   GigabitEthernet0/0
Internet  192.168.10.10           0   0200.0000.00aa  ARPA   GigabitEthernet0/0
Internet  192.168.20.1            -   0200.0000.0002  ARPA   GigabitEthernet0/1
Internet  192.168.20.10           0   0200.0000.00cc  ARPA   GigabitEthernet0/1
What to look for: R1 keeps one ARP table for both links. The 192.168.10.10 entry (PC-A) is on GigabitEthernet0/0, and the 192.168.20.10 entry (the server) is on GigabitEthernet0/1. The entries with the age “-” are R1's own interfaces.

Common mistakes

  • Thinking PC-A sends an ARP request for the server. It sends one for the gateway. Only R1 ever learns the server's MAC address.
  • Thinking the destination MAC address is the server's from start to finish. MAC addresses are only used on one link. On LAN 10, the destination MAC address is R1's.
  • Thinking routers change the IP addresses. Normal routing never does. Only NAT rewrites IP addresses.
  • Thinking the router forwards the same frame. It forwards the same packet inside a new frame.
  • Forgetting the return path. The server needs a correct default gateway too, and R1 needs a route back.
  • Putting the default gateway in another subnet. The gateway must be reachable on the local link.
✅ Key takeaways
  • A destination outside your subnet is sent to your default gateway.
  • The sender uses ARP to find the gateway's MAC address, never the remote host's.
  • Frame 1: destination MAC address = gateway, destination IP address = final destination.
  • The router removes the frame, checks its routing table, lowers the TTL by one and builds a new frame for the next link.
  • MAC addresses change at every router; IP addresses stay the same unless NAT changes them.

Knowledge check

Predict · scenario 1

PC-A (192.168.10.10/24) sends a packet to 192.168.20.10. What destination MAC address does PC-A put in the frame?

Predict · scenario 2

The frame leaves R1 on G0/1 towards the server. What is its source IP address?

Predict · scenario 3

PC-A can ping 192.168.10.1 and 192.168.20.1, but pinging the server 192.168.20.10 times out. The server can ping 192.168.20.1. What is the most likely problem?

Predict · scenario 4

A Windows PC pings a Linux server three routers away. What TTL will the PC most likely see in the reply?

Where to go next

You now know the two patterns every packet follows: local delivery and routed delivery. The final lesson of this unit, What happens when you open a website?, combines them with DNS, NAT, TCP and TLS into one journey across the internet. To learn more about the individual pieces, read The default gateway, Routers, ICMP and IP and gateway problems. For how routers learn routes (static routes, OSPF), go further with the CCNA-level Routing course.

FAQ

Why does the destination MAC address change at every router?
A MAC address only has meaning on one link (one Ethernet segment). When a router forwards a packet onto a new link, it discards the old frame and builds a new one. It uses the MAC address of its outgoing interface as the source and the next device's MAC address as the destination.
Does the destination IP address ever change on the way?
Not during normal routing. The source and destination IP addresses stay the same from end to end. The common exception is NAT (Network Address Translation), where a router deliberately rewrites addresses, as a home router does for internet traffic.
Does PC-A ever learn the server's MAC address?
No. PC-A only uses ARP to find its default gateway's MAC address. The router learns the server's MAC address on the far-side link. PC-A never needs it and never sees it.
What is TTL and why does it go down by one?
TTL (Time to Live) is a counter in the IP header. Every router that forwards the packet subtracts one. If it reaches zero, the router drops the packet and sends back an ICMP Time Exceeded message. This stops packets from looping forever if routing is broken, and it is also how traceroute discovers each hop.