What “traffic type” means
Every frame and packet has a destination address. That address does not only say where the data goes; it also says how many devices should receive it. There are three main types, plus a fourth special case:
📨 Unicast: one to one
Like a letter addressed to one person. Only that device processes it.
📢 Broadcast: one to all
Like an announcement over the office loudspeaker. Every device in the local network hears it.
📺 Multicast: one to a group
Like a TV channel. Only the devices that tuned in (joined the group) receive it.
📍 Anycast: one to the nearest
Like calling a national phone number that connects you to your nearest branch. Many servers share one address.
Why it matters
A unicast frame is cheap: only the device it is addressed to spends any effort on it, and other network cards discard it straight away. A broadcast must be read and processed by every device in the network, even those that do not need it. Choosing the right traffic type keeps networks efficient:
- Unicast for normal conversations, when the sender knows exactly which device it wants.
- Broadcast only when the sender does not yet know who to ask (“who has this IP address?”, “is there a DHCP server?”).
- Multicast when the same data is wanted by several devices at once.
Quick comparison
| Type | Who receives it | Layer 2 (MAC) | IPv4 | IPv6 | Crosses routers? | Examples |
|---|---|---|---|---|---|---|
| Unicast | One device | The receiver's own MAC, e.g. 02:00:00:00:00:bb | One host, e.g. 192.168.1.20 or 203.0.113.10 | One host, e.g. 2001:db8::20 | Yes | Web pages, email, SSH, most traffic |
| Broadcast | Every device in the broadcast domain | ff:ff:ff:ff:ff:ff | 255.255.255.255, or the subnet's last address (192.168.1.255) | Does not exist in IPv6 | No | ARP request, DHCP Discover |
| Multicast | Devices that joined a group | 01:00:5e:… (IPv4) or 33:33:… (IPv6) | 224.0.0.0 – 239.255.255.255 | ff00::/8, e.g. ff02::1 | Only if multicast routing is set up | IPTV, OSPF hellos, mDNS |
| Anycast | The nearest of several devices sharing one address | Normal unicast MAC | A normal-looking unicast address | A normal-looking unicast address | Yes (routing picks the nearest) | Public DNS resolvers, CDNs, DNS root servers |
Where it happens: Layer 2 and Layer 3
The traffic type is marked twice in every IP packet sent over Ethernet: once in the destination MAC of the Ethernet frame (Layer 2), and once in the destination IP of the packet inside (Layer 3). The two usually agree: an IPv4 broadcast travels in a frame sent to ff:ff:ff:ff:ff:ff.
- Switches act on the MAC address type: they forward unicast to one port, flood broadcasts, and flood multicast or deliver it only to group members.
- Network cards use the MAC type to decide whether to accept a frame.
- Routers act on the IP address type: they route unicast, do not forward broadcasts, and route multicast only if they are configured to.
ARP is a special case: its messages have no IP header at all, and an ARP request is a pure Layer 2 broadcast. With no IP address to route on, a router never forwards ARP, so it never leaves the local network.
Unicast: one to one
Unicast is the normal case: one sender, one receiver. The destination MAC address is the receiver's own address (or the router's, if the receiver is on another network), and the destination IP address is the receiver's.
- 1. One frame, one receiver: destination MAC 02:00:00:00:00:bb, destination IP 192.168.1.20. The switch has learned the server's port, so PC B and PC C never see the frame.
- 2. The reply is unicast too, straight back to PC A's MAC and IP.
Real examples: loading a web page, sending an email, an SSH session, a video call and a DNS query to your resolver. When you open https://routelearn.net, every packet of that connection is unicast. One small exception: if a switch has not yet learned where the receiver is, it floods that unicast frame out of every other port (this is called an “unknown unicast”).
Learn more: How a Switch Learns MAC Addresses
Broadcast: one to all
A broadcast is delivered to every device in the local network (the broadcast domain). It is used when the sender does not yet know which device to talk to. There are broadcast addresses at both Layer 2 and Layer 3:
| Layer | Address | Meaning |
|---|---|---|
| Layer 2 | ff:ff:ff:ff:ff:ff | Every device on this LAN (all 48 bits set to 1) |
| Layer 3 (IPv4) | 255.255.255.255 | Limited broadcast: every device on the local network |
| Layer 3 (IPv4) | 192.168.1.255 (in 192.168.1.0/24) | Directed broadcast: every device in that subnet; routers do not forward these by default |
- 1. PC A broadcasts: “Who has 192.168.1.1?” The switch floods the frame out of every other port. PC B, the printer and the router all receive and read it.
- 2. The router keeps it local. It answers, because it is 192.168.1.1, but it never forwards the broadcast to 10.0.20.0/24. The other network never sees it.
- 3. The answer is unicast: the router replies directly to PC A's MAC address. Only the question needed to be a broadcast.
Real broadcast example 1: ARP
A PC knows the IP address it wants to reach but not the matching MAC address. ARP sends a request to ff:ff:ff:ff:ff:ff. Every device reads it, but only the device that owns that IP address replies.
Real broadcast example 2: DHCP Discover
A laptop that has just joined a network has no IP address and does not know where the DHCP server is. So it broadcasts at both layers:
Because broadcasts stop at routers, a DHCP server on another subnet cannot hear these requests on its own. The router needs a DHCP relay, which forwards them to the server as unicast.
Learn more: DHCP
Why routers stop broadcasts
If routers forwarded broadcasts, every ARP request from every PC in the world would reach every other device on the internet, and nothing else would fit on the links. So routers draw a line: a broadcast stays inside its own network. The area a broadcast can reach is called a broadcast domain. Each router interface (and each VLAN) is a separate broadcast domain. The next lesson explains this in detail.
Learn more: Broadcast Domains
Multicast: one to a group
Multicast sends one stream to a group. Devices that want the stream join the group; other devices ignore it. The sender sends each packet once, no matter how many receivers there are.
- 1. Viewers join the group: each sends an IGMP message saying “I want 239.1.1.1”. The switch listens to these messages (IGMP snooping) and notes their ports.
- 2. One stream, copied only where needed: the source sends each packet once, and the switch copies it to the two joined ports. The office PC never receives it.
Multicast addresses
| Range or address | Used for |
|---|---|
224.0.0.0/4 (224.0.0.0 – 239.255.255.255) | All IPv4 multicast (the old “Class D”) |
224.0.0.0/24 | Local network control traffic; never routed. 224.0.0.5 = all OSPF routers, 224.0.0.251 = mDNS |
239.0.0.0/8 | Private multicast inside an organisation, for example IPTV or camera streams |
ff02::1, ff02::2 | IPv6: all nodes and all routers on the local link |
From multicast IP to multicast MAC
A multicast frame needs a destination MAC address too. There is no ARP for groups, so the MAC address is calculated from the IP address:
- Start with the fixed prefix
01:00:5e(the I/G bit is set, marking a group). - Copy the last 23 bits of the IPv4 group address into the remaining bits.
| Group IP | Multicast MAC | Who uses it |
|---|---|---|
224.0.0.5 | 01:00:5e:00:00:05 | OSPF hello messages between routers |
224.0.0.251 | 01:00:5e:00:00:fb | mDNS: printers and smart speakers announcing themselves |
239.1.1.1 | 01:00:5e:01:01:01 | The video stream in the example above |
ff02::1 (IPv6) | 33:33:00:00:00:01 | All IPv6 nodes; IPv6 uses 33:33 plus the last 32 bits of the address |
Going deeper
IPv4 multicast addresses have 28 variable bits, but only 23 of them fit in the MAC address. So 32 different group addresses share each MAC address: for example, 239.1.1.1 and 239.129.1.1 both map to 01:00:5e:01:01:01. A host may therefore receive a frame for a group it did not join; its IP software then discards it.
Real multicast examples
- Video and IPTV: a hotel or company sends TV channels as multicast groups, and each TV joins the group for the channel being watched.
- OSPF hellos: on Ethernet, routers running OSPF send “hello” messages every 10 seconds by default to
224.0.0.5, so all OSPF routers on the link hear them without needing to know each other's addresses. - mDNS / Bonjour: your phone finds a printer or a smart speaker by asking the
224.0.0.251group. - IPv6 basics: Neighbor Discovery messages, including router advertisements, use multicast instead of broadcast.
Joining groups: IGMP and IGMP snooping
Hosts tell the network which groups they want with IGMP (Internet Group Management Protocol; MLD in IPv6). A switch without snooping treats multicast like broadcast and floods it out of every port in the VLAN. A switch with IGMP snooping listens to those join messages and sends each group only to the ports that asked for it. On networks with heavy multicast, such as IPTV or security cameras, snooping is what stops the streams from overloading every PC.
A note on anycast
Anycast is not a special address range. It is a routing technique: the same unicast IP address is given to servers in many places, and every location advertises it to the internet. Normal routing then delivers each user's packets to the nearest server, measured by routing (usually, but not always, the closest one geographically).
- 1. London's query is routed to the nearest server that uses 192.0.2.53: the one in Europe.
- 2. Sydney's query to the same address reaches the Asia-Pacific server. Each user simply gets fast answers.
Large public DNS resolvers, the DNS root servers and content delivery networks (CDNs) all use anycast. To the user, and on the local LAN, it looks exactly like unicast.
How a switch treats each type
| Destination MAC | What the switch does |
|---|---|
| Known unicast | Forwards it out of the one port where that MAC address was learned |
| Unknown unicast | Floods out of every port in the VLAN except the incoming one |
| Broadcast | Floods out of every port in the VLAN except the incoming one |
| Multicast | Floods like a broadcast, or (with IGMP snooping) sends only to ports that joined the group |
Seeing each type in a capture
$ sudo tcpdump -e -n -i eth0 09:30:11.402118 02:00:00:00:00:aa > ff:ff:ff:ff:ff:ff, ethertype ARP (0x0806), length 42: Request who-has 192.168.1.1 tell 192.168.1.10, length 28 09:30:11.402650 02:00:00:00:00:01 > 02:00:00:00:00:aa, ethertype ARP (0x0806), length 60: Reply 192.168.1.1 is-at 02:00:00:00:00:01, length 46 09:30:11.402711 02:00:00:00:00:aa > 02:00:00:00:00:01, ethertype IPv4 (0x0800), length 74: 192.168.1.10.40112 > 203.0.113.10.443: Flags [S], seq 2085160123, win 64240, options [mss 1460,sackOK,TS val 401922 ecr 0,nop,wscale 7], length 0 09:30:12.118044 02:00:00:00:00:cc > 01:00:5e:00:00:fb, ethertype IPv4 (0x0800), length 87: 192.168.1.30.5353 > 224.0.0.251.5353: 0 PTR (QM)? _ipp._tcp.local. (45)
-e option prints the source and destination MAC addresses at the start of each line. Line 1 is a broadcast: an ARP request to ff:ff:ff:ff:ff:ff. Line 2 is the unicast ARP reply. Line 3 is unicast: a TCP SYN to start an HTTPS connection, sent to the router's MAC address because 203.0.113.10 is on another network. Line 4 is multicast: mDNS, a device looking for printers (01:00:5e:00:00:fb / 224.0.0.251).Useful filters to see only one type:
| Show only… | tcpdump | Wireshark display filter |
|---|---|---|
| Broadcasts | tcpdump -e -n broadcast | eth.dst == ff:ff:ff:ff:ff:ff |
| Multicasts | tcpdump -e -n "multicast and not broadcast" | eth.dst.ig == 1 && !(eth.dst == ff:ff:ff:ff:ff:ff) |
| Traffic to/from one host | tcpdump -n host 192.168.1.20 | ip.addr == 192.168.1.20 |
When traffic types cause trouble
| Problem | What you notice | Cause |
|---|---|---|
| Broadcast storm | The whole LAN freezes, switch lights flash constantly and CPU use spikes on every device | A switching loop (for example, two links between switches with Spanning Tree disabled) makes broadcasts circulate endlessly |
| A broadcast domain that is too large | Slower devices, battery drain on phones, a sluggish network | Thousands of devices in one network, all receiving each other's ARP and DHCP broadcasts |
| Multicast flooding | Every PC receives heavy video traffic it never asked for | IGMP snooping is off or not working |
| DHCP fails on a remote subnet | Clients get 169.254.x.x addresses | The broadcast Discover cannot cross the router, and no DHCP relay is configured |
| A printer or speaker cannot be found from another network | It is found from the same subnet, but not from a different one (for example, guest Wi-Fi and the office LAN) | mDNS uses 224.0.0.251, which is link-local and not routed |
💡 Quick health check: run a capture with the broadcast filter for one minute. A few ARP and DHCP messages per second is normal. Hundreds or thousands per second point to a loop or a faulty device.
Common mistakes
- Thinking switches stop broadcasts. Switches flood broadcasts out of every port in the VLAN. Only routers (and VLAN boundaries) stop them.
- Calling multicast “a kind of broadcast”. Multicast is meant only for devices that joined the group. With IGMP snooping, switches deliver it only to those devices.
- Looking for broadcasts in IPv6. IPv6 has no broadcast; it uses multicast groups such as
ff02::1instead. - Assuming an ARP reply is a broadcast. Only the request is a broadcast. The reply goes straight back to the asker as unicast.
- Thinking anycast needs special addresses. It uses ordinary unicast addresses; routing decides which server each user reaches.
- Unicast = one receiver; broadcast = everyone in the local network; multicast = a group that joined; anycast = the nearest of many.
- Broadcast addresses:
ff:ff:ff:ff:ff:ffat Layer 2,255.255.255.255(or the subnet's last address) at Layer 3. - Multicast:
224.0.0.0/4in IPv4, with MAC addresses starting01:00:5e; IPv6 usesff00::/8and33:33. - ARP requests and DHCP Discovers are broadcasts; their replies are unicast.
- Switches flood broadcasts; routers stop them, which defines a broadcast domain.
- IGMP snooping keeps multicast away from ports that did not ask for it.
Check yourself
In a capture, you see a frame with the destination MAC address 01:00:5e:00:00:05. What kind of traffic is it?
PC A sends an ARP request. Its LAN has a switch and a router to another network. Who receives the request?
A camera sends a video stream to 239.1.1.1. The office switch does not have IGMP snooping enabled. What does the switch do with the stream?
You capture traffic on an IPv6-only network to find out how devices locate each other. What do you expect to see?
Two users in different countries send DNS queries to the same IP address, and each gets a reply from a different server. What is this?
Where to go next
Continue with Broadcast domains to see exactly where broadcasts stop. To review how broadcasts are used, see ARP fundamentals and DHCP. To review how addresses are built, see MAC addresses.