Routelearn.net
Course menu

Unit 13: Complete Packet FlowLesson 13.1 (1 of 3 in this unit)70 of 84 in the Network Fundamentals course

Same-Subnet Communication: Following One Packet

PC-A wants to send a packet to PC-B. Both are connected to the same switch and are in the same subnet. This lesson follows that packet through all eleven steps: the decision PC-A makes, the ARP exchange, the frame it builds, what the switch does and how PC-B unwraps it, with every MAC and IP address shown at each step.

Beginner · 15 min read · Before this: MAC Addresses, Subnet Mask Basics, ARP Fundamentals

Same-subnet communication is delivery between hosts in the same IP subnet. The sender uses ARP to learn the destination’s MAC address and sends the frame directly to it; switches forward the frame at Layer 2 and no router is involved.

In simple terms: When two devices are on the same local network, they talk directly. The sender finds the other device’s MAC address, and the switch carries the frame straight across.

This is the simplest journey a packet can make, and it is the foundation for everything else in this unit: two computers, one switch and one subnet. Even so, eleven separate things must happen before PC-B receives anything. Once you can explain each one, the different-subnet journey is just the same story with a router added.

What “same-subnet communication” means

Same-subnet communication happens when a device sends traffic to another device whose IP address is in its own subnet. A subnet is a group of addresses that share the same network part, as defined by the subnet mask. Devices in the same subnet can reach each other directly through switches, without a router in the middle.

This kind of traffic is everywhere: a laptop printing to an office printer, a PC opening a file share on a local server, or a phone casting video to a TV on your home Wi-Fi.

💡 In simple terms: it is like handing a note to a colleague in the same room. You don't need the post office (the router). You only need to know which desk they sit at (their MAC address).

The lab: who is who

The same small network is used throughout this lesson. PC-A is going to ping PC-B. A ping is an ICMP Echo Request, but the steps are the same for any data: a web request, a file copy or a print job.

DeviceIP address / maskMAC addressSwitch portRole
PC-A192.168.10.10/2402:00:00:00:00:aaGi0/1The sender
PC-B192.168.10.20/2402:00:00:00:00:bbGi0/2The receiver
SW1Not needed to forward framesHas its own, but it never appears in these frames-Layer 2 switch connecting both PCs
R1 (gateway)192.168.10.1/2402:00:00:00:00:01Gi0/3Present, but not used for local traffic
Gi0/1Gi0/2Gi0/3SW1MAC tablePC-A.10.10 · …:aaPC-B.10.20 · …:bbR1 (gateway).10.1 · …:01
  1. 1. PC-A decides. 192.168.10.20 is inside 192.168.10.0/24, so PC-B is local. No gateway is needed.
  2. 2. ARP request (broadcast). PC-A has no MAC address for .20, so it broadcasts to ff:ff:ff:ff:ff:ff. SW1 learns that …:aa is on Gi0/1.
  3. 3. SW1 floods the broadcast. Every other port gets a copy. R1 ignores it because .20 is not its address.
  4. 4. ARP reply (unicast). PC-B answers PC-A directly. SW1 learns that …:bb is on Gi0/2.
  5. 5. PC-A sends the real frame. Source …:aa → destination …:bb, carrying 192.168.10.10 → 192.168.10.20.
  6. 6. SW1 forwards out one port. …:bb is in the MAC address table on Gi0/2, so only PC-B gets the frame. R1 sees nothing.
  7. 7. PC-B replies. PC-B already knows PC-A's MAC address from the ARP request, so it replies straight away.
The whole conversation in seven animated steps. The router is connected, but it is never used for this traffic.

Where this happens in the network

Everything in this lesson stays inside one broadcast domain: the PCs, the cables and the switch. In OSI terms, PC-A makes a Layer 3 decision (is the destination IP address local?) and uses ARP to link Layer 3 to Layer 2. The switch works only at Layer 2. No device in the middle ever looks at the IP header.

ComponentLayerJob in this journey
IP address + subnet mask3Lets PC-A decide that PC-B is local
ARP cache2/3PC-A's memory of IP → MAC mappings
ARP request and reply2/3Finds PC-B's MAC address when it is not cached
Ethernet frame2The envelope that carries the packet across the cable
Switch MAC address table2Tells SW1 which port each MAC address is on
Network interface card (NIC)1/2Puts bits on the wire and accepts frames addressed to it

Phase 1: PC-A decides where the packet goes (steps 1 to 3)

Before anything is sent, PC-A has to answer one question: is PC-B on my own subnet, or somewhere else? The answer decides whose MAC address goes in the frame.

Step 1: PC-A checks the destination IP address

On PC-A

The ping command (or any application) hands the operating system a destination: 192.168.10.20. PC-A already knows its own IP address and MAC address, so the source fields are easy to fill in. The destination MAC address is still unknown.

Addresses at this step
Source MAC
02:00:00:00:00:aa
Destination MAC
not known yet
Source IP
192.168.10.10
Destination IPchanged
192.168.10.20

Step 2: PC-A checks its subnet mask

On PC-A

PC-A applies its own mask, 255.255.255.0 (/24), to both addresses. The mask keeps the network part and removes the host part. In binary this is a bitwise AND, but with a /24 mask you can simply keep the first three numbers:

AddressMaskNetwork part
PC-A (itself)192.168.10.10255.255.255.0192.168.10.0
Destination192.168.10.20255.255.255.0192.168.10.0
Addresses at this step
Source MAC
02:00:00:00:00:aa
Destination MAC
not known yet
Source IP
192.168.10.10
Destination IP
192.168.10.20
Mask appliedchanged
255.255.255.0 (/24)

Step 3: PC-A decides the destination is local

On PC-A

Both network parts are 192.168.10.0, so they match. PC-B is on the same subnet. That means:

  • PC-A will send the frame directly to PC-B.
  • The default gateway (R1) is not used.
  • The MAC address PC-A needs is PC-B's own MAC.

Important: PC-A uses its own mask for this check. It never knows PC-B's mask. If the two PCs are configured with different masks, they can disagree about whether they are on the same subnet (see “What happens when it fails” below).

Addresses at this step
Source MAC
02:00:00:00:00:aa
Destination MACchanged
PC-B's own MAC (to be found)
Source IP
192.168.10.10
Destination IP
192.168.10.20
Decisionchanged
Local: send directly, no gateway

Phase 2: finding PC-B's MAC address (steps 4 to 6)

PC-A knows the destination IP address. To build an Ethernet frame, it also needs the destination MAC address. This is the job of ARP (Address Resolution Protocol).

Step 4: PC-A checks its ARP cache

On PC-A

The ARP cache is a small table in memory that maps IP addresses to the MAC addresses PC-A has learned recently. Entries expire after a short time (often within a few minutes on modern systems). If 192.168.10.20 were already in the cache, PC-A would skip straight to step 7. In this example, the cache has no entry for it, so PC-A must ask.

ARP cache lookup
Looking for
192.168.10.20
Resultchanged
No entry (cache miss)

Step 5: PC-A sends an ARP request (broadcast)

PC-A → SW1 → every port

PC-A sends one frame to the broadcast MAC address ff:ff:ff:ff:ff:ff, so every device on the subnet receives it. The question inside is: “Who has 192.168.10.20? Tell 192.168.10.10.”

An ARP message is not an IP packet. Its EtherType is 0x0806 (ARP), not 0x0800 (IPv4). The IP addresses are carried inside the ARP message itself. SW1 floods the broadcast out of every port except Gi0/1, and it also learns that 02:00:00:00:00:aa is on Gi0/1.

Inside the ARP request frame
Source MAC
02:00:00:00:00:aa
Destination MACchanged
ff:ff:ff:ff:ff:ff (broadcast)
ARP sender IP
192.168.10.10
ARP target IP
192.168.10.20

Step 6: PC-B sends an ARP reply (unicast)

PC-B → SW1 → PC-A

PC-B recognises its own IP address and answers: “192.168.10.20 is at 02:00:00:00:00:bb.” The reply is unicast: it goes only to PC-A, because PC-B learned PC-A's MAC address from the request. PC-B also saves PC-A's IP address and MAC address in its own ARP cache. R1 received the request too, but the target was not its address, so it did not reply.

SW1 learns that 02:00:00:00:00:bb is on Gi0/2. PC-A stores the answer in its ARP cache.

Inside the ARP reply frame
Source MACchanged
02:00:00:00:00:bb
Destination MACchanged
02:00:00:00:00:aa
ARP sender IP
192.168.10.20
ARP target IP
192.168.10.10
Step 1 of 7 · ARP request
One subnet · 192.168.10.0/24
PC-A
192.168.10.10
SW1
Layer 2 only
PC-B
192.168.10.20

1. ARP request · Broadcast

Who has 192.168.10.20? Tell 192.168.10.10.

Tap this step's arrow for the details.

The full exchange: ARP first (only if the cache is empty), then the data itself, then the reply.

Phase 3: building and delivering the frame (steps 7 to 11)

Step 7: PC-A builds the Ethernet frame

On PC-A

Now that it has PC-B's MAC address, PC-A completes encapsulation. The ICMP message goes inside an IP packet, and the IP packet goes inside an Ethernet frame:

  • IP header: source 192.168.10.10, destination 192.168.10.20, protocol 1 (ICMP), TTL 128 (Windows default).
  • Ethernet header: destination 02:00:00:00:00:bb, source 02:00:00:00:00:aa, EtherType 0x0800 (IPv4).
  • Trailer: a 4-byte FCS (frame check sequence) so the receiver can detect damaged frames.
Addresses at this step
Source MAC
02:00:00:00:00:aa
Destination MACchanged
02:00:00:00:00:bb
Source IP
192.168.10.10
Destination IP
192.168.10.20

The frame PC-A puts on the wire

Same subnet: the destination MAC and the destination IP belong to the same device

Layer 2 · Ethernet header (this hop)
Destination MAC
02:00:00:00:00:bb
PC-B
Source MAC
02:00:00:00:00:aa
PC-A
EtherType
0x0800
IPv4
Layer 3 · IP header (end to end)
Source IP
192.168.10.10
PC-A
Destination IP
192.168.10.20
PC-B
ICMP Echo Request (the ping) · then the FCS trailer

Step 8: SW1 receives the frame on Gi0/1

On SW1

The frame arrives on port Gi0/1. SW1 (a store-and-forward switch) first checks the FCS. If the frame was damaged on the cable, it is silently dropped here. A switch does not read the IP header at all: to the switch, the IP addresses are just part of the payload.

Addresses at this step
Source MAC
02:00:00:00:00:aa
Destination MAC
02:00:00:00:00:bb
Source IP
192.168.10.10
Destination IP
192.168.10.20

Step 9: SW1 checks its MAC address table (and learns the source)

On SW1

A switch does two things with every frame:

  1. Learn: it records the source MAC address against the port the frame arrived on: 02:00:00:00:00:aa → Gi0/1. (It already learned this from the ARP request; this frame only refreshes the timer.)
  2. Look up: it searches for the destination MAC address. 02:00:00:00:00:bb was learned from the ARP reply, so it is in the table on Gi0/2.

If the destination were not in the table (an “unknown unicast”), SW1 would flood the frame out of every port except the one it arrived on, just as it did with the broadcast.

Learn more: How a Switch Learns MAC Addresses

MAC address table
Learn: source
…:aa → Gi0/1 (refreshed)
Look up: destinationchanged
…:bb → Gi0/2 (found)

Step 10: SW1 forwards the frame out of Gi0/2 only

SW1 → PC-B

Because the destination is known, the frame goes out of exactly one port. R1 and every other device see nothing. Look at the fields: nothing has changed. A switch never rewrites MAC or IP addresses; it only chooses the exit port.

Addresses at this step
Source MAC
02:00:00:00:00:aa
Destination MAC
02:00:00:00:00:bb
Source IP
192.168.10.10
Destination IP
192.168.10.20

Step 11: PC-B receives the frame and de-encapsulates it

On PC-B

PC-B unwraps the frame layer by layer (de-encapsulation), checking at each layer that it is the right recipient:

  1. Layer 1/2: the NIC sees destination MAC 02:00:00:00:00:bb, which is its own, and the FCS is correct. It keeps the frame.
  2. Layer 2 → 3: EtherType 0x0800 means “hand this to IPv4”. The Ethernet header and trailer are removed.
  3. Layer 3: destination IP address 192.168.10.20 is PC-B's own. Protocol 1 means “hand this to ICMP”.
  4. ICMP: ICMP is a helper protocol carried inside IP, so there is no TCP or UDP header and no port. It sees an Echo Request and builds an Echo Reply, which goes back through steps 7 to 10 in the opposite direction.
Addresses at this step
Source MAC
02:00:00:00:00:aa
Destination MAC
02:00:00:00:00:bb
Source IP
192.168.10.10
Destination IP
192.168.10.20

All eleven steps in one table

Here is the whole journey at a glance. Once the real frame is built in step 7, not a single address changes until it is delivered.

#WhereWhat happensSrc MACDst MACSrc IPDst IP
1PC-ACheck destination IP…:aa?.10.10.10.20
2PC-AApply subnet mask…:aa?.10.10.10.20
3PC-ALocal: no gateway…:aa?.10.10.10.20
4PC-AARP cache miss…:aa?.10.10.10.20
5PC-A → allARP request…:aaff:ff:…:ff(ARP: no IP header)
6PC-B → PC-AARP reply…:bb…:aa(ARP: no IP header)
7PC-ABuild frame…:aa…:bb.10.10.10.20
8SW1 Gi0/1Frame arrives…:aa…:bb.10.10.10.20
9SW1Learn source, look up destination…:aa…:bb.10.10.10.20
10SW1 Gi0/2Forward one port…:aa…:bb.10.10.10.20
11PC-BDe-encapsulate…:aa…:bb.10.10.10.20

The reply: the journey back

PC-B's Echo Reply follows the same steps, but faster. PC-B makes the same local check (PC-A's address is in 192.168.10.0/24), finds PC-A's MAC address already in its ARP cache (learned from the request in step 5) and sends the reply straight away. SW1 already has both MAC addresses in its table, so no flooding happens at all.

Request: PC-A → PC-B

Layer 2 · Ethernet header (this hop)
Destination MAC
02:00:00:00:00:bb
PC-B
Source MAC
02:00:00:00:00:aa
PC-A
EtherType
0x0800
Layer 3 · IP header (end to end)
Source IP
192.168.10.10
Destination IP
192.168.10.20
ICMP Echo Request

Reply: PC-B → PC-A

Layer 2 · Ethernet header (this hop)
Destination MAC
02:00:00:00:00:aa
PC-A
Source MAC
02:00:00:00:00:bb
PC-B
EtherType
0x0800
Layer 3 · IP header (end to end)
Source IP
192.168.10.20
Destination IP
192.168.10.10
ICMP Echo Reply

The source and destination addresses simply swap places. The first ping is sometimes a little slower than the rest because only the first one has to wait for ARP.

A real-world example

In a small office, Priya clicks “Print” on her laptop (192.168.10.10). The printer is 192.168.10.20 on the same switch. Her laptop follows steps 1 to 11 exactly. It decides that the printer is local, uses ARP to find the printer's MAC address (if it has not printed recently) and builds frames addressed to the printer. The switch delivers them out of the printer's port. The office router could be switched off and printing would still work, because local traffic never needs it.

What happens when it fails

What breaksWhich step failsWhat you see
PC-B is switched off or unplugged6: no ARP reply“Destination host unreachable” from PC-A's own address. No entry for .20 in arp -a.
PC-B's firewall blocks ping11: PC-B drops the ICMP“Request timed out”, but arp -a on PC-A does show PC-B's MAC address. ARP worked, so the Layer 2 path is fine.
Wrong subnet mask on PC-A (e.g. /28)3: wrong decisionPC-A thinks .20 is remote and sends the traffic to the gateway instead. It may still work through R1, or not at all.
PCs in different VLANs5: the broadcast never reaches PC-BARP fails, even though the IP addresses look like they are in the same subnet.
Bad cable or port8: frames dropped or never arriveLink light off, or CRC/FCS errors counting up on the switch port.
Duplicate IP address6: two ARP repliesConnections work only some of the time, as the ARP cache flips between two MAC addresses.

⚠️ The most useful clue is the ARP cache. If PC-A has a MAC address for PC-B, Layer 2 between them works, and the problem is higher up (for example, a firewall or a stopped service). If there is no MAC address, check the cabling, VLANs, power and IP settings.

Troubleshooting and useful commands

Work through the steps in order and check each one:

  1. Steps 1 to 3: check your own IP address and mask with ipconfig (Windows) or ip addr (Linux).
  2. Steps 4 to 6: ping the target, then look at the ARP cache with arp -a or ip neigh.
  3. Steps 8 to 10: on a managed switch, check which port each MAC address was learned on with show mac address-table.
Example output from a Windows PC, written for this lesson
C:\>ping 192.168.10.20
Pinging 192.168.10.20 with 32 bytes of data:
Reply from 192.168.10.20: bytes=32 time=1ms TTL=128
Reply from 192.168.10.20: bytes=32 time<1ms TTL=128
Reply from 192.168.10.20: bytes=32 time<1ms TTL=128
Reply from 192.168.10.20: bytes=32 time<1ms TTL=128

Ping statistics for 192.168.10.20:
    Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 0ms, Maximum = 1ms, Average = 0ms
What to look for: four Reply from 192.168.10.20 lines and 0% loss mean PC-B answered every ping. TTL=128 is PC-B's starting value (the Windows default), and it arrived unchanged. No router decreased it, which confirms that the traffic stayed on the local subnet. A time of 1 ms or less is normal on a LAN.
Example output from a Windows PC, written for this lesson
C:\>arp -a
Interface: 192.168.10.10 --- 0xb
  Internet Address      Physical Address      Type
  192.168.10.1          02-00-00-00-00-01     dynamic
  192.168.10.20         02-00-00-00-00-bb     dynamic
  192.168.10.255        ff-ff-ff-ff-ff-ff     static
  224.0.0.22            01-00-5e-00-00-16     static
What to look for: the 192.168.10.20 line, with PC-B's MAC address and the type dynamic, is the result of steps 5 and 6. The gateway entry (192.168.10.1) is from earlier traffic to other networks. The static entries are the broadcast and multicast addresses. Windows writes MAC addresses with dashes.
Example output from a Linux PC, written for this lesson
$ ip neigh show
192.168.10.20 dev eth0 lladdr 02:00:00:00:00:bb REACHABLE
192.168.10.1 dev eth0 lladdr 02:00:00:00:00:01 STALE
What to look for: the 192.168.10.20 line shows PC-B's MAC address after lladdr. On Linux, the ARP cache is called the neighbour table. REACHABLE means the entry was confirmed recently; STALE means it will be checked again before it is trusted.
Example output · based on Cisco documentation; exact format varies by platform and software version
SW1#show mac address-table dynamic
          Mac Address Table
-------------------------------------------

Vlan    Mac Address       Type        Ports
----    -----------       --------    -----
   1    0200.0000.0001    DYNAMIC     Gi0/3
   1    0200.0000.00aa    DYNAMIC     Gi0/1
   1    0200.0000.00bb    DYNAMIC     Gi0/2
Total Mac Addresses for this criterion: 3
What to look for: this is step 9 made visible. Each line shows a MAC address and the port SW1 learned it on: PC-A (…00aa) on Gi0/1, PC-B (…00bb) on Gi0/2 and R1 (…0001) on Gi0/3. Cisco writes MAC addresses as three groups of four hex digits.

Learn more: Essential Windows Network CommandsEssential Linux Network Commands

Common mistakes

  • Thinking the router is involved. For same-subnet traffic, the default gateway is never used. Even if the gateway setting is wrong, local traffic still works.
  • Thinking PC-A sends an ARP request before every packet. It only uses ARP when the address is not in its ARP cache. Most packets skip steps 5 and 6.
  • Thinking the switch reads IP addresses. A Layer 2 switch forwards frames using MAC addresses only.
  • Thinking the switch changes the frame. It forwards the frame unchanged. Only routers build new frames.
  • Treating “Request timed out” as a network failure. If the ARP entry is there, Layer 2 works; the target may simply be blocking ping.
  • Thinking the ARP reply is also a broadcast. The request is a broadcast, but the reply is unicast, sent only to the device that asked.
✅ Key takeaways
  • The sender uses its own subnet mask to compare the destination with its own subnet. If they match, the destination is local.
  • For a local destination, the frame carries the destination's own MAC address. No router is involved.
  • ARP is only needed when the MAC address is not in the ARP cache. The request is a broadcast; the reply is unicast.
  • The switch learns source MAC addresses, looks up destination MAC addresses and forwards out of one port (or floods if the destination is unknown).
  • Between the sender and the receiver, no MAC or IP address changes, and the TTL stays the same.

Knowledge check

Predict · scenario 1

PC-A (192.168.10.10/24) pings PC-B (192.168.10.20/24) for the first time today. What is the very first frame PC-A sends?

Predict · scenario 2

SW1 has just been rebooted and its MAC address table is empty. PC-A's ARP cache still has PC-B's MAC, so PC-A sends the ping frame straight away. What does SW1 do?

Predict · scenario 3

The router R1 is switched off for maintenance. Can PC-A still ping PC-B?

Predict · scenario 4

Ping from PC-A to PC-B shows 'Request timed out', but arp -a on PC-A lists 192.168.10.20 with MAC 02-00-00-00-00-bb. What is the most likely cause?

Where to go next

You have followed a packet inside one subnet. Next, add a router and watch what changes in Different-subnet communication: the PC uses ARP to find the gateway instead, and the router builds a new frame. Then put everything together in What happens when you open a website?. To review the building blocks, read MAC addresses, ARP for local and remote destinations and Broadcast domains.

FAQ

Does a router take part when two PCs on the same subnet talk?
No. When the destination is in the same subnet, the sender puts the destination's own MAC address in the frame, and the switch delivers it directly. If an ARP request is sent, the router receives the broadcast too, sees that it is not the target and ignores it.
Why does PC-A need PC-B's MAC address if it already knows its IP address?
On Ethernet, the network card and the switch deliver frames by MAC address, not IP address. The IP address says which host the packet is for; the MAC address says which network card on this link should pick the frame up. ARP connects the two.
Does the switch change the frame when it forwards it?
No. A switch forwards the frame exactly as it arrived: the same source and destination MAC addresses, the same IP header and the same data. It only reads the frame to learn the source MAC and decide which port to send it out of.
Does PC-B have to send its own ARP request to reply?
Usually not. PC-A's ARP request contained PC-A's IP address and MAC address, and PC-B saved them in its own ARP cache when it answered. So PC-B can send its reply straight away.