Routelearn.net
Course menu

Unit 7: TCP, UDP and PortsLesson 7.1.7 (7 of 20 in this unit)40 of 84 in the Network Fundamentals course

How UDP works

The 8-byte UDP header, and why voice, video, DNS and DHCP choose it.

Beginner · 6 min read

UDP (User Datagram Protocol) is a connectionless transport layer protocol that sends each datagram with a small 8-byte header holding the source and destination ports, a length and a checksum. It sets up no connection and does not acknowledge, reorder or resend data, leaving that to the application if it needs it.

In simple terms: UDP sends the data without setting up a connection or checking that it arrived. That keeps it fast and simple, which suits live voice and video, and quick questions such as DNS lookups.

A situation

You are on a video call, and a few packets are lost on your Wi-Fi link. The picture blurs for a moment, then carries on. Nothing freezes, and nobody waits. That is UDP doing its job. If the call used TCP, it would stop and wait for the lost data to be sent again, and by then that moment of the call would already be over.

What it is

UDP (User Datagram Protocol) is the simpler of the two main transport protocols. It is connectionless: there is no handshake, no connection state and no closing exchange. Each message, called a datagram, is sent on its own. UDP does not number datagrams, confirm them or resend them. This is called best-effort delivery.

Source port16 bits
Destination port16 bits
Length16 bitsheader + data, in bytes
Checksum16 bits
The whole UDP header: four fields, 8 bytes. The TCP header is at least 20 bytes.
FieldJob
Source portThe sending application; replies are sent back to this port
Destination portThe receiving application, for example 53 for DNS
LengthSize of the header plus data, in bytes; at least 8
ChecksumDetects damaged datagrams; optional in IPv4, required in IPv6

So UDP keeps only one job of the transport layer: port numbers, so that the data reaches the right application. Everything else is left to the application, if it needs it at all.

IP phone A10.10.1.21R1R2IP phone B10.20.1.35
  1. 1. Every 20 ms phone A sends a small UDP datagram containing a slice of sound.
  2. 2. One is lost on the WAN. UDP does not notice that it is missing, and nothing asks for it again.
  3. 3. The next one plays. Phone B hides the 20 ms gap and keeps playing. A late resend would be worse than a tiny gap.

Why applications choose UDP

ApplicationWhy UDP suits it
Voice and video callsLate data is useless; skipping is better than waiting
Online gamesOnly the newest position matters
DNSOne small question, one small answer; the client simply asks again if it is lost
DHCPThe client has no IP address yet and must send broadcasts
NTP, SNMP, syslogSmall, regular messages; one lost message does little harm
Streaming to many receiversMulticast needs UDP, because TCP cannot hold a handshake with every receiver

Some applications want reliability but not TCP's exact rules, so they build their own on top of UDP. QUIC, used by HTTP/3 on UDP port 443, is the best-known example: it provides its own encryption, retransmission and ordering.

Why it works this way

Less work means less delay. There is no handshake, so the first datagram already carries real data. There is no waiting for ACKs, and no stall when one datagram is lost. The small header also saves bandwidth: a voice packet may carry only 20 to 160 bytes of sound, so saving 12 bytes on every packet adds up. The cost is that the application must deal with loss, duplicates and out-of-order data itself.

How to verify it

show ip traffic includes UDP counters for traffic sent to and from the router itself. The output below is based on Cisco documentation, not captured from a lab device, and shows only the UDP part.

Example output · based on Cisco documentation; exact format varies by platform and software version
R1#show ip traffic | section UDP
UDP statistics:
  Rcvd: 4093 total, 0 checksum errors, 312 no port, 0 finput
  Sent: 2240 total, 0 forwarded broadcasts
What to look for: checksum errors counts damaged datagrams, which are discarded. no port counts datagrams sent to a UDP port where nothing was listening. UDP has no RST, so the router normally replies to these with an ICMP “port unreachable” message instead.

Check yourself

Predict · scenario 1

You compare a DNS query in a packet capture with a TCP segment. How big is the UDP header in the DNS query?

Predict · scenario 2

A UDP datagram carrying part of a voice call is lost on a WAN link. What does UDP do?

Predict · scenario 3

You are writing a firewall rule that allows only UDP traffic to a web server. Which of these services would still work?