This is the simplest journey a packet can make, and it is the foundation for everything else in this unit: two computers, one switch and one subnet. Even so, eleven separate things must happen before PC-B receives anything. Once you can explain each one, the different-subnet journey is just the same story with a router added.
What “same-subnet communication” means
Same-subnet communication happens when a device sends traffic to another device whose IP address is in its own subnet. A subnet is a group of addresses that share the same network part, as defined by the subnet mask. Devices in the same subnet can reach each other directly through switches, without a router in the middle.
This kind of traffic is everywhere: a laptop printing to an office printer, a PC opening a file share on a local server, or a phone casting video to a TV on your home Wi-Fi.
💡 In simple terms: it is like handing a note to a colleague in the same room. You don't need the post office (the router). You only need to know which desk they sit at (their MAC address).
The lab: who is who
The same small network is used throughout this lesson. PC-A is going to ping PC-B. A ping is an ICMP Echo Request, but the steps are the same for any data: a web request, a file copy or a print job.
| Device | IP address / mask | MAC address | Switch port | Role |
|---|---|---|---|---|
| PC-A | 192.168.10.10/24 | 02:00:00:00:00:aa | Gi0/1 | The sender |
| PC-B | 192.168.10.20/24 | 02:00:00:00:00:bb | Gi0/2 | The receiver |
| SW1 | Not needed to forward frames | Has its own, but it never appears in these frames | - | Layer 2 switch connecting both PCs |
| R1 (gateway) | 192.168.10.1/24 | 02:00:00:00:00:01 | Gi0/3 | Present, but not used for local traffic |
- 1. PC-A decides. 192.168.10.20 is inside 192.168.10.0/24, so PC-B is local. No gateway is needed.
- 2. ARP request (broadcast). PC-A has no MAC address for .20, so it broadcasts to ff:ff:ff:ff:ff:ff. SW1 learns that …:aa is on Gi0/1.
- 3. SW1 floods the broadcast. Every other port gets a copy. R1 ignores it because .20 is not its address.
- 4. ARP reply (unicast). PC-B answers PC-A directly. SW1 learns that …:bb is on Gi0/2.
- 5. PC-A sends the real frame. Source …:aa → destination …:bb, carrying 192.168.10.10 → 192.168.10.20.
- 6. SW1 forwards out one port. …:bb is in the MAC address table on Gi0/2, so only PC-B gets the frame. R1 sees nothing.
- 7. PC-B replies. PC-B already knows PC-A's MAC address from the ARP request, so it replies straight away.
Where this happens in the network
Everything in this lesson stays inside one broadcast domain: the PCs, the cables and the switch. In OSI terms, PC-A makes a Layer 3 decision (is the destination IP address local?) and uses ARP to link Layer 3 to Layer 2. The switch works only at Layer 2. No device in the middle ever looks at the IP header.
| Component | Layer | Job in this journey |
|---|---|---|
| IP address + subnet mask | 3 | Lets PC-A decide that PC-B is local |
| ARP cache | 2/3 | PC-A's memory of IP → MAC mappings |
| ARP request and reply | 2/3 | Finds PC-B's MAC address when it is not cached |
| Ethernet frame | 2 | The envelope that carries the packet across the cable |
| Switch MAC address table | 2 | Tells SW1 which port each MAC address is on |
| Network interface card (NIC) | 1/2 | Puts bits on the wire and accepts frames addressed to it |
Phase 1: PC-A decides where the packet goes (steps 1 to 3)
Before anything is sent, PC-A has to answer one question: is PC-B on my own subnet, or somewhere else? The answer decides whose MAC address goes in the frame.
Step 1: PC-A checks the destination IP address
The ping command (or any application) hands the operating system a destination: 192.168.10.20. PC-A already knows its own IP address and MAC address, so the source fields are easy to fill in. The destination MAC address is still unknown.
- Source MAC
- 02:00:00:00:00:aa
- Destination MAC
- not known yet
- Source IP
- 192.168.10.10
- Destination IPchanged
- 192.168.10.20
Step 2: PC-A checks its subnet mask
PC-A applies its own mask, 255.255.255.0 (/24), to both addresses. The mask keeps the network part and removes the host part. In binary this is a bitwise AND, but with a /24 mask you can simply keep the first three numbers:
| Address | Mask | Network part | |
|---|---|---|---|
| PC-A (itself) | 192.168.10.10 | 255.255.255.0 | 192.168.10.0 |
| Destination | 192.168.10.20 | 255.255.255.0 | 192.168.10.0 |
- Source MAC
- 02:00:00:00:00:aa
- Destination MAC
- not known yet
- Source IP
- 192.168.10.10
- Destination IP
- 192.168.10.20
- Mask appliedchanged
- 255.255.255.0 (/24)
Step 3: PC-A decides the destination is local
Both network parts are 192.168.10.0, so they match. PC-B is on the same subnet. That means:
- PC-A will send the frame directly to PC-B.
- The default gateway (R1) is not used.
- The MAC address PC-A needs is PC-B's own MAC.
Important: PC-A uses its own mask for this check. It never knows PC-B's mask. If the two PCs are configured with different masks, they can disagree about whether they are on the same subnet (see “What happens when it fails” below).
- Source MAC
- 02:00:00:00:00:aa
- Destination MACchanged
- PC-B's own MAC (to be found)
- Source IP
- 192.168.10.10
- Destination IP
- 192.168.10.20
- Decisionchanged
- Local: send directly, no gateway
Phase 2: finding PC-B's MAC address (steps 4 to 6)
PC-A knows the destination IP address. To build an Ethernet frame, it also needs the destination MAC address. This is the job of ARP (Address Resolution Protocol).
Step 4: PC-A checks its ARP cache
The ARP cache is a small table in memory that maps IP addresses to the MAC addresses PC-A has learned recently. Entries expire after a short time (often within a few minutes on modern systems). If 192.168.10.20 were already in the cache, PC-A would skip straight to step 7. In this example, the cache has no entry for it, so PC-A must ask.
- Looking for
- 192.168.10.20
- Resultchanged
- No entry (cache miss)
Step 5: PC-A sends an ARP request (broadcast)
PC-A sends one frame to the broadcast MAC address ff:ff:ff:ff:ff:ff, so every device on the subnet receives it. The question inside is: “Who has 192.168.10.20? Tell 192.168.10.10.”
An ARP message is not an IP packet. Its EtherType is 0x0806 (ARP), not 0x0800 (IPv4). The IP addresses are carried inside the ARP message itself. SW1 floods the broadcast out of every port except Gi0/1, and it also learns that 02:00:00:00:00:aa is on Gi0/1.
- Source MAC
- 02:00:00:00:00:aa
- Destination MACchanged
- ff:ff:ff:ff:ff:ff (broadcast)
- ARP sender IP
- 192.168.10.10
- ARP target IP
- 192.168.10.20
Step 6: PC-B sends an ARP reply (unicast)
PC-B recognises its own IP address and answers: “192.168.10.20 is at 02:00:00:00:00:bb.” The reply is unicast: it goes only to PC-A, because PC-B learned PC-A's MAC address from the request. PC-B also saves PC-A's IP address and MAC address in its own ARP cache. R1 received the request too, but the target was not its address, so it did not reply.
SW1 learns that 02:00:00:00:00:bb is on Gi0/2. PC-A stores the answer in its ARP cache.
- Source MACchanged
- 02:00:00:00:00:bb
- Destination MACchanged
- 02:00:00:00:00:aa
- ARP sender IP
- 192.168.10.20
- ARP target IP
- 192.168.10.10
1. ARP request · Broadcast
Who has 192.168.10.20? Tell 192.168.10.10.
Tap this step's arrow for the details.
Phase 3: building and delivering the frame (steps 7 to 11)
Step 7: PC-A builds the Ethernet frame
Now that it has PC-B's MAC address, PC-A completes encapsulation. The ICMP message goes inside an IP packet, and the IP packet goes inside an Ethernet frame:
- IP header: source
192.168.10.10, destination192.168.10.20, protocol 1 (ICMP), TTL 128 (Windows default). - Ethernet header: destination
02:00:00:00:00:bb, source02:00:00:00:00:aa, EtherType0x0800(IPv4). - Trailer: a 4-byte FCS (frame check sequence) so the receiver can detect damaged frames.
- Source MAC
- 02:00:00:00:00:aa
- Destination MACchanged
- 02:00:00:00:00:bb
- Source IP
- 192.168.10.10
- Destination IP
- 192.168.10.20
The frame PC-A puts on the wire
Same subnet: the destination MAC and the destination IP belong to the same device
Step 8: SW1 receives the frame on Gi0/1
The frame arrives on port Gi0/1. SW1 (a store-and-forward switch) first checks the FCS. If the frame was damaged on the cable, it is silently dropped here. A switch does not read the IP header at all: to the switch, the IP addresses are just part of the payload.
- Source MAC
- 02:00:00:00:00:aa
- Destination MAC
- 02:00:00:00:00:bb
- Source IP
- 192.168.10.10
- Destination IP
- 192.168.10.20
Step 9: SW1 checks its MAC address table (and learns the source)
A switch does two things with every frame:
- Learn: it records the source MAC address against the port the frame arrived on:
02:00:00:00:00:aa→ Gi0/1. (It already learned this from the ARP request; this frame only refreshes the timer.) - Look up: it searches for the destination MAC address.
02:00:00:00:00:bbwas learned from the ARP reply, so it is in the table on Gi0/2.
If the destination were not in the table (an “unknown unicast”), SW1 would flood the frame out of every port except the one it arrived on, just as it did with the broadcast.
Learn more: How a Switch Learns MAC Addresses
- Learn: source
- …:aa → Gi0/1 (refreshed)
- Look up: destinationchanged
- …:bb → Gi0/2 (found)
Step 10: SW1 forwards the frame out of Gi0/2 only
Because the destination is known, the frame goes out of exactly one port. R1 and every other device see nothing. Look at the fields: nothing has changed. A switch never rewrites MAC or IP addresses; it only chooses the exit port.
- Source MAC
- 02:00:00:00:00:aa
- Destination MAC
- 02:00:00:00:00:bb
- Source IP
- 192.168.10.10
- Destination IP
- 192.168.10.20
Step 11: PC-B receives the frame and de-encapsulates it
PC-B unwraps the frame layer by layer (de-encapsulation), checking at each layer that it is the right recipient:
- Layer 1/2: the NIC sees destination MAC
02:00:00:00:00:bb, which is its own, and the FCS is correct. It keeps the frame. - Layer 2 → 3: EtherType
0x0800means “hand this to IPv4”. The Ethernet header and trailer are removed. - Layer 3: destination IP address
192.168.10.20is PC-B's own. Protocol 1 means “hand this to ICMP”. - ICMP: ICMP is a helper protocol carried inside IP, so there is no TCP or UDP header and no port. It sees an Echo Request and builds an Echo Reply, which goes back through steps 7 to 10 in the opposite direction.
- Source MAC
- 02:00:00:00:00:aa
- Destination MAC
- 02:00:00:00:00:bb
- Source IP
- 192.168.10.10
- Destination IP
- 192.168.10.20
All eleven steps in one table
Here is the whole journey at a glance. Once the real frame is built in step 7, not a single address changes until it is delivered.
| # | Where | What happens | Src MAC | Dst MAC | Src IP | Dst IP |
|---|---|---|---|---|---|---|
| 1 | PC-A | Check destination IP | …:aa | ? | .10.10 | .10.20 |
| 2 | PC-A | Apply subnet mask | …:aa | ? | .10.10 | .10.20 |
| 3 | PC-A | Local: no gateway | …:aa | ? | .10.10 | .10.20 |
| 4 | PC-A | ARP cache miss | …:aa | ? | .10.10 | .10.20 |
| 5 | PC-A → all | ARP request | …:aa | ff:ff:…:ff | (ARP: no IP header) | |
| 6 | PC-B → PC-A | ARP reply | …:bb | …:aa | (ARP: no IP header) | |
| 7 | PC-A | Build frame | …:aa | …:bb | .10.10 | .10.20 |
| 8 | SW1 Gi0/1 | Frame arrives | …:aa | …:bb | .10.10 | .10.20 |
| 9 | SW1 | Learn source, look up destination | …:aa | …:bb | .10.10 | .10.20 |
| 10 | SW1 Gi0/2 | Forward one port | …:aa | …:bb | .10.10 | .10.20 |
| 11 | PC-B | De-encapsulate | …:aa | …:bb | .10.10 | .10.20 |
The reply: the journey back
PC-B's Echo Reply follows the same steps, but faster. PC-B makes the same local check (PC-A's address is in 192.168.10.0/24), finds PC-A's MAC address already in its ARP cache (learned from the request in step 5) and sends the reply straight away. SW1 already has both MAC addresses in its table, so no flooding happens at all.
Request: PC-A → PC-B
Reply: PC-B → PC-A
The source and destination addresses simply swap places. The first ping is sometimes a little slower than the rest because only the first one has to wait for ARP.
A real-world example
In a small office, Priya clicks “Print” on her laptop (192.168.10.10). The printer is 192.168.10.20 on the same switch. Her laptop follows steps 1 to 11 exactly. It decides that the printer is local, uses ARP to find the printer's MAC address (if it has not printed recently) and builds frames addressed to the printer. The switch delivers them out of the printer's port. The office router could be switched off and printing would still work, because local traffic never needs it.
What happens when it fails
| What breaks | Which step fails | What you see |
|---|---|---|
| PC-B is switched off or unplugged | 6: no ARP reply | “Destination host unreachable” from PC-A's own address. No entry for .20 in arp -a. |
| PC-B's firewall blocks ping | 11: PC-B drops the ICMP | “Request timed out”, but arp -a on PC-A does show PC-B's MAC address. ARP worked, so the Layer 2 path is fine. |
| Wrong subnet mask on PC-A (e.g. /28) | 3: wrong decision | PC-A thinks .20 is remote and sends the traffic to the gateway instead. It may still work through R1, or not at all. |
| PCs in different VLANs | 5: the broadcast never reaches PC-B | ARP fails, even though the IP addresses look like they are in the same subnet. |
| Bad cable or port | 8: frames dropped or never arrive | Link light off, or CRC/FCS errors counting up on the switch port. |
| Duplicate IP address | 6: two ARP replies | Connections work only some of the time, as the ARP cache flips between two MAC addresses. |
⚠️ The most useful clue is the ARP cache. If PC-A has a MAC address for PC-B, Layer 2 between them works, and the problem is higher up (for example, a firewall or a stopped service). If there is no MAC address, check the cabling, VLANs, power and IP settings.
Troubleshooting and useful commands
Work through the steps in order and check each one:
- Steps 1 to 3: check your own IP address and mask with
ipconfig(Windows) orip addr(Linux). - Steps 4 to 6: ping the target, then look at the ARP cache with
arp -aorip neigh. - Steps 8 to 10: on a managed switch, check which port each MAC address was learned on with
show mac address-table.
C:\>ping 192.168.10.20 Pinging 192.168.10.20 with 32 bytes of data: Reply from 192.168.10.20: bytes=32 time=1ms TTL=128 Reply from 192.168.10.20: bytes=32 time<1ms TTL=128 Reply from 192.168.10.20: bytes=32 time<1ms TTL=128 Reply from 192.168.10.20: bytes=32 time<1ms TTL=128 Ping statistics for 192.168.10.20: Packets: Sent = 4, Received = 4, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 0ms, Maximum = 1ms, Average = 0ms
C:\>arp -a Interface: 192.168.10.10 --- 0xb Internet Address Physical Address Type 192.168.10.1 02-00-00-00-00-01 dynamic 192.168.10.20 02-00-00-00-00-bb dynamic 192.168.10.255 ff-ff-ff-ff-ff-ff static 224.0.0.22 01-00-5e-00-00-16 static
192.168.10.20 line, with PC-B's MAC address and the type dynamic, is the result of steps 5 and 6. The gateway entry (192.168.10.1) is from earlier traffic to other networks. The static entries are the broadcast and multicast addresses. Windows writes MAC addresses with dashes.$ ip neigh show 192.168.10.20 dev eth0 lladdr 02:00:00:00:00:bb REACHABLE 192.168.10.1 dev eth0 lladdr 02:00:00:00:00:01 STALE
192.168.10.20 line shows PC-B's MAC address after lladdr. On Linux, the ARP cache is called the neighbour table. REACHABLE means the entry was confirmed recently; STALE means it will be checked again before it is trusted.SW1#show mac address-table dynamic Mac Address Table ------------------------------------------- Vlan Mac Address Type Ports ---- ----------- -------- ----- 1 0200.0000.0001 DYNAMIC Gi0/3 1 0200.0000.00aa DYNAMIC Gi0/1 1 0200.0000.00bb DYNAMIC Gi0/2 Total Mac Addresses for this criterion: 3
…00aa) on Gi0/1, PC-B (…00bb) on Gi0/2 and R1 (…0001) on Gi0/3. Cisco writes MAC addresses as three groups of four hex digits.Learn more: Essential Windows Network CommandsEssential Linux Network Commands
Common mistakes
- Thinking the router is involved. For same-subnet traffic, the default gateway is never used. Even if the gateway setting is wrong, local traffic still works.
- Thinking PC-A sends an ARP request before every packet. It only uses ARP when the address is not in its ARP cache. Most packets skip steps 5 and 6.
- Thinking the switch reads IP addresses. A Layer 2 switch forwards frames using MAC addresses only.
- Thinking the switch changes the frame. It forwards the frame unchanged. Only routers build new frames.
- Treating “Request timed out” as a network failure. If the ARP entry is there, Layer 2 works; the target may simply be blocking ping.
- Thinking the ARP reply is also a broadcast. The request is a broadcast, but the reply is unicast, sent only to the device that asked.
- The sender uses its own subnet mask to compare the destination with its own subnet. If they match, the destination is local.
- For a local destination, the frame carries the destination's own MAC address. No router is involved.
- ARP is only needed when the MAC address is not in the ARP cache. The request is a broadcast; the reply is unicast.
- The switch learns source MAC addresses, looks up destination MAC addresses and forwards out of one port (or floods if the destination is unknown).
- Between the sender and the receiver, no MAC or IP address changes, and the TTL stays the same.
Knowledge check
PC-A (192.168.10.10/24) pings PC-B (192.168.10.20/24) for the first time today. What is the very first frame PC-A sends?
SW1 has just been rebooted and its MAC address table is empty. PC-A's ARP cache still has PC-B's MAC, so PC-A sends the ping frame straight away. What does SW1 do?
The router R1 is switched off for maintenance. Can PC-A still ping PC-B?
Ping from PC-A to PC-B shows 'Request timed out', but arp -a on PC-A lists 192.168.10.20 with MAC 02-00-00-00-00-bb. What is the most likely cause?
Where to go next
You have followed a packet inside one subnet. Next, add a router and watch what changes in Different-subnet communication: the PC uses ARP to find the gateway instead, and the router builds a new frame. Then put everything together in What happens when you open a website?. To review the building blocks, read MAC addresses, ARP for local and remote destinations and Broadcast domains.