Routelearn.net
Course menu

Unit 10: Network Traffic TypesLesson 10.1 (1 of 2 in this unit)61 of 84 in the Network Fundamentals course

Unicast, Broadcast and Multicast

Every message on a network is sent to one device, to every device, or to a chosen group. Learn the three traffic types (plus anycast), the MAC and IP addresses each one uses, who receives what, and why routers stop broadcasts.

Beginner · 16 min read · Before this: MAC addresses, What is an IP address?, ARP fundamentals

Traffic types (unicast, broadcast and multicast) describe how many receivers a frame or packet is addressed to: unicast goes to one device, broadcast to every device in the broadcast domain, and multicast to the devices that have joined a particular group. Anycast sends to the nearest of several devices that share the same address.

In simple terms: A message can be meant for one device, for everyone on the local network or for a group that asked for it. It is like the difference between a phone call, a shout across a room and a radio station that people tune in to.

What “traffic type” means

Every frame and packet has a destination address. That address does not only say where the data goes; it also says how many devices should receive it. There are three main types, plus a fourth special case:

📨 Unicast: one to one

Like a letter addressed to one person. Only that device processes it.

📢 Broadcast: one to all

Like an announcement over the office loudspeaker. Every device in the local network hears it.

📺 Multicast: one to a group

Like a TV channel. Only the devices that tuned in (joined the group) receive it.

📍 Anycast: one to the nearest

Like calling a national phone number that connects you to your nearest branch. Many servers share one address.

Why it matters

A unicast frame is cheap: only the device it is addressed to spends any effort on it, and other network cards discard it straight away. A broadcast must be read and processed by every device in the network, even those that do not need it. Choosing the right traffic type keeps networks efficient:

  • Unicast for normal conversations, when the sender knows exactly which device it wants.
  • Broadcast only when the sender does not yet know who to ask (“who has this IP address?”, “is there a DHCP server?”).
  • Multicast when the same data is wanted by several devices at once.

Quick comparison

TypeWho receives itLayer 2 (MAC)IPv4IPv6Crosses routers?Examples
UnicastOne deviceThe receiver's own MAC, e.g. 02:00:00:00:00:bbOne host, e.g. 192.168.1.20 or 203.0.113.10One host, e.g. 2001:db8::20YesWeb pages, email, SSH, most traffic
BroadcastEvery device in the broadcast domainff:ff:ff:ff:ff:ff255.255.255.255, or the subnet's last address (192.168.1.255)Does not exist in IPv6NoARP request, DHCP Discover
MulticastDevices that joined a group01:00:5e:… (IPv4) or 33:33:… (IPv6)224.0.0.0 – 239.255.255.255ff00::/8, e.g. ff02::1Only if multicast routing is set upIPTV, OSPF hellos, mDNS
AnycastThe nearest of several devices sharing one addressNormal unicast MACA normal-looking unicast addressA normal-looking unicast addressYes (routing picks the nearest)Public DNS resolvers, CDNs, DNS root servers

Where it happens: Layer 2 and Layer 3

The traffic type is marked twice in every IP packet sent over Ethernet: once in the destination MAC of the Ethernet frame (Layer 2), and once in the destination IP of the packet inside (Layer 3). The two usually agree: an IPv4 broadcast travels in a frame sent to ff:ff:ff:ff:ff:ff.

  • Switches act on the MAC address type: they forward unicast to one port, flood broadcasts, and flood multicast or deliver it only to group members.
  • Network cards use the MAC type to decide whether to accept a frame.
  • Routers act on the IP address type: they route unicast, do not forward broadcasts, and route multicast only if they are configured to.

ARP is a special case: its messages have no IP header at all, and an ARP request is a pure Layer 2 broadcast. With no IP address to route on, a router never forwards ARP, so it never leaves the local network.

Unicast: one to one

Unicast is the normal case: one sender, one receiver. The destination MAC address is the receiver's own address (or the router's, if the receiver is on another network), and the destination IP address is the receiver's.

SwitchPC A192.168.1.10 · …:aaPC B192.168.1.11PC C192.168.1.12File server192.168.1.20 · …:bb
  1. 1. One frame, one receiver: destination MAC 02:00:00:00:00:bb, destination IP 192.168.1.20. The switch has learned the server's port, so PC B and PC C never see the frame.
  2. 2. The reply is unicast too, straight back to PC A's MAC and IP.

Real examples: loading a web page, sending an email, an SSH session, a video call and a DNS query to your resolver. When you open https://routelearn.net, every packet of that connection is unicast. One small exception: if a switch has not yet learned where the receiver is, it floods that unicast frame out of every other port (this is called an “unknown unicast”).

Learn more: How a Switch Learns MAC Addresses

Broadcast: one to all

A broadcast is delivered to every device in the local network (the broadcast domain). It is used when the sender does not yet know which device to talk to. There are broadcast addresses at both Layer 2 and Layer 3:

LayerAddressMeaning
Layer 2ff:ff:ff:ff:ff:ffEvery device on this LAN (all 48 bits set to 1)
Layer 3 (IPv4)255.255.255.255Limited broadcast: every device on the local network
Layer 3 (IPv4)192.168.1.255 (in 192.168.1.0/24)Directed broadcast: every device in that subnet; routers do not forward these by default
SwitchPC A192.168.1.10PC BPrinterstops itRouter192.168.1.1Other network10.0.20.0/24
  1. 1. PC A broadcasts: “Who has 192.168.1.1?” The switch floods the frame out of every other port. PC B, the printer and the router all receive and read it.
  2. 2. The router keeps it local. It answers, because it is 192.168.1.1, but it never forwards the broadcast to 10.0.20.0/24. The other network never sees it.
  3. 3. The answer is unicast: the router replies directly to PC A's MAC address. Only the question needed to be a broadcast.

Real broadcast example 1: ARP

A PC knows the IP address it wants to reach but not the matching MAC address. ARP sends a request to ff:ff:ff:ff:ff:ff. Every device reads it, but only the device that owns that IP address replies.

Real broadcast example 2: DHCP Discover

A laptop that has just joined a network has no IP address and does not know where the DHCP server is. So it broadcasts at both layers:

Step 1 of 2 · DHCP Discover
New laptop
no IP yet · …:aa
LAN
192.168.1.0/24
DHCP server
192.168.1.1
Tap a message to see its addresses. The full four-message exchange is in the DHCP lesson.

Because broadcasts stop at routers, a DHCP server on another subnet cannot hear these requests on its own. The router needs a DHCP relay, which forwards them to the server as unicast.

Learn more: DHCP

Why routers stop broadcasts

If routers forwarded broadcasts, every ARP request from every PC in the world would reach every other device on the internet, and nothing else would fit on the links. So routers draw a line: a broadcast stays inside its own network. The area a broadcast can reach is called a broadcast domain. Each router interface (and each VLAN) is a separate broadcast domain. The next lesson explains this in detail.

Learn more: Broadcast Domains

Multicast: one to a group

Multicast sends one stream to a group. Devices that want the stream join the group; other devices ignore it. The sender sends each packet once, no matter how many receivers there are.

SwitchIGMP snooping onVideo sourceto 239.1.1.1joinedViewer 1Office PCjoinedViewer 2
  1. 1. Viewers join the group: each sends an IGMP message saying “I want 239.1.1.1”. The switch listens to these messages (IGMP snooping) and notes their ports.
  2. 2. One stream, copied only where needed: the source sends each packet once, and the switch copies it to the two joined ports. The office PC never receives it.

Multicast addresses

Range or addressUsed for
224.0.0.0/4 (224.0.0.0 – 239.255.255.255)All IPv4 multicast (the old “Class D”)
224.0.0.0/24Local network control traffic; never routed. 224.0.0.5 = all OSPF routers, 224.0.0.251 = mDNS
239.0.0.0/8Private multicast inside an organisation, for example IPTV or camera streams
ff02::1, ff02::2IPv6: all nodes and all routers on the local link

From multicast IP to multicast MAC

A multicast frame needs a destination MAC address too. There is no ARP for groups, so the MAC address is calculated from the IP address:

  1. Start with the fixed prefix 01:00:5e (the I/G bit is set, marking a group).
  2. Copy the last 23 bits of the IPv4 group address into the remaining bits.
Group IPMulticast MACWho uses it
224.0.0.501:00:5e:00:00:05OSPF hello messages between routers
224.0.0.25101:00:5e:00:00:fbmDNS: printers and smart speakers announcing themselves
239.1.1.101:00:5e:01:01:01The video stream in the example above
ff02::1 (IPv6)33:33:00:00:00:01All IPv6 nodes; IPv6 uses 33:33 plus the last 32 bits of the address

Going deeper
IPv4 multicast addresses have 28 variable bits, but only 23 of them fit in the MAC address. So 32 different group addresses share each MAC address: for example, 239.1.1.1 and 239.129.1.1 both map to 01:00:5e:01:01:01. A host may therefore receive a frame for a group it did not join; its IP software then discards it.

Real multicast examples

  • Video and IPTV: a hotel or company sends TV channels as multicast groups, and each TV joins the group for the channel being watched.
  • OSPF hellos: on Ethernet, routers running OSPF send “hello” messages every 10 seconds by default to 224.0.0.5, so all OSPF routers on the link hear them without needing to know each other's addresses.
  • mDNS / Bonjour: your phone finds a printer or a smart speaker by asking the 224.0.0.251 group.
  • IPv6 basics: Neighbor Discovery messages, including router advertisements, use multicast instead of broadcast.

Joining groups: IGMP and IGMP snooping

Hosts tell the network which groups they want with IGMP (Internet Group Management Protocol; MLD in IPv6). A switch without snooping treats multicast like broadcast and floods it out of every port in the VLAN. A switch with IGMP snooping listens to those join messages and sends each group only to the ports that asked for it. On networks with heavy multicast, such as IPTV or security cameras, snooping is what stops the streams from overloading every PC.

A note on anycast

Anycast is not a special address range. It is a routing technique: the same unicast IP address is given to servers in many places, and every location advertises it to the internet. Normal routing then delivers each user's packets to the nearest server, measured by routing (usually, but not always, the closest one geographically).

User in LondonUser in SydneyInternetDNS server, Europe192.0.2.53DNS server, Asia-Pacific192.0.2.53
  1. 1. London's query is routed to the nearest server that uses 192.0.2.53: the one in Europe.
  2. 2. Sydney's query to the same address reaches the Asia-Pacific server. Each user simply gets fast answers.

Large public DNS resolvers, the DNS root servers and content delivery networks (CDNs) all use anycast. To the user, and on the local LAN, it looks exactly like unicast.

How a switch treats each type

Destination MACWhat the switch does
Known unicastForwards it out of the one port where that MAC address was learned
Unknown unicastFloods out of every port in the VLAN except the incoming one
BroadcastFloods out of every port in the VLAN except the incoming one
MulticastFloods like a broadcast, or (with IGMP snooping) sends only to ports that joined the group

Seeing each type in a capture

Example output from a Linux PC, written for this lesson (trimmed)
$ sudo tcpdump -e -n -i eth0
09:30:11.402118 02:00:00:00:00:aa > ff:ff:ff:ff:ff:ff, ethertype ARP (0x0806), length 42: Request who-has 192.168.1.1 tell 192.168.1.10, length 28
09:30:11.402650 02:00:00:00:00:01 > 02:00:00:00:00:aa, ethertype ARP (0x0806), length 60: Reply 192.168.1.1 is-at 02:00:00:00:00:01, length 46
09:30:11.402711 02:00:00:00:00:aa > 02:00:00:00:00:01, ethertype IPv4 (0x0800), length 74: 192.168.1.10.40112 > 203.0.113.10.443: Flags [S], seq 2085160123, win 64240, options [mss 1460,sackOK,TS val 401922 ecr 0,nop,wscale 7], length 0
09:30:12.118044 02:00:00:00:00:cc > 01:00:5e:00:00:fb, ethertype IPv4 (0x0800), length 87: 192.168.1.30.5353 > 224.0.0.251.5353: 0 PTR (QM)? _ipp._tcp.local. (45)
What to look for: the -e option prints the source and destination MAC addresses at the start of each line. Line 1 is a broadcast: an ARP request to ff:ff:ff:ff:ff:ff. Line 2 is the unicast ARP reply. Line 3 is unicast: a TCP SYN to start an HTTPS connection, sent to the router's MAC address because 203.0.113.10 is on another network. Line 4 is multicast: mDNS, a device looking for printers (01:00:5e:00:00:fb / 224.0.0.251).

Useful filters to see only one type:

Show only…tcpdumpWireshark display filter
Broadcaststcpdump -e -n broadcasteth.dst == ff:ff:ff:ff:ff:ff
Multicaststcpdump -e -n "multicast and not broadcast"eth.dst.ig == 1 && !(eth.dst == ff:ff:ff:ff:ff:ff)
Traffic to/from one hosttcpdump -n host 192.168.1.20ip.addr == 192.168.1.20

When traffic types cause trouble

ProblemWhat you noticeCause
Broadcast stormThe whole LAN freezes, switch lights flash constantly and CPU use spikes on every deviceA switching loop (for example, two links between switches with Spanning Tree disabled) makes broadcasts circulate endlessly
A broadcast domain that is too largeSlower devices, battery drain on phones, a sluggish networkThousands of devices in one network, all receiving each other's ARP and DHCP broadcasts
Multicast floodingEvery PC receives heavy video traffic it never asked forIGMP snooping is off or not working
DHCP fails on a remote subnetClients get 169.254.x.x addressesThe broadcast Discover cannot cross the router, and no DHCP relay is configured
A printer or speaker cannot be found from another networkIt is found from the same subnet, but not from a different one (for example, guest Wi-Fi and the office LAN)mDNS uses 224.0.0.251, which is link-local and not routed

💡 Quick health check: run a capture with the broadcast filter for one minute. A few ARP and DHCP messages per second is normal. Hundreds or thousands per second point to a loop or a faulty device.

Common mistakes

  • Thinking switches stop broadcasts. Switches flood broadcasts out of every port in the VLAN. Only routers (and VLAN boundaries) stop them.
  • Calling multicast “a kind of broadcast”. Multicast is meant only for devices that joined the group. With IGMP snooping, switches deliver it only to those devices.
  • Looking for broadcasts in IPv6. IPv6 has no broadcast; it uses multicast groups such as ff02::1 instead.
  • Assuming an ARP reply is a broadcast. Only the request is a broadcast. The reply goes straight back to the asker as unicast.
  • Thinking anycast needs special addresses. It uses ordinary unicast addresses; routing decides which server each user reaches.
✅ Key takeaways
  • Unicast = one receiver; broadcast = everyone in the local network; multicast = a group that joined; anycast = the nearest of many.
  • Broadcast addresses: ff:ff:ff:ff:ff:ff at Layer 2, 255.255.255.255 (or the subnet's last address) at Layer 3.
  • Multicast: 224.0.0.0/4 in IPv4, with MAC addresses starting 01:00:5e; IPv6 uses ff00::/8 and 33:33.
  • ARP requests and DHCP Discovers are broadcasts; their replies are unicast.
  • Switches flood broadcasts; routers stop them, which defines a broadcast domain.
  • IGMP snooping keeps multicast away from ports that did not ask for it.

Check yourself

Predict · scenario 1

In a capture, you see a frame with the destination MAC address 01:00:5e:00:00:05. What kind of traffic is it?

Predict · scenario 2

PC A sends an ARP request. Its LAN has a switch and a router to another network. Who receives the request?

Predict · scenario 3

A camera sends a video stream to 239.1.1.1. The office switch does not have IGMP snooping enabled. What does the switch do with the stream?

Predict · scenario 4

You capture traffic on an IPv6-only network to find out how devices locate each other. What do you expect to see?

Predict · scenario 5

Two users in different countries send DNS queries to the same IP address, and each gets a reply from a different server. What is this?

Where to go next

Continue with Broadcast domains to see exactly where broadcasts stop. To review how broadcasts are used, see ARP fundamentals and DHCP. To review how addresses are built, see MAC addresses.

FAQ

Does a switch forward broadcasts?
Yes. A switch sends a broadcast frame out of every port in the same VLAN except the one it arrived on. Only a router (or a Layer 3 switch routing between VLANs) stops a broadcast, which is why a router interface marks the edge of a broadcast domain.
Why doesn't IPv6 have broadcast?
Broadcasts disturb every device, even those that do not need the message. IPv6 replaced them with multicast. For example, instead of an ARP broadcast, IPv6 Neighbor Discovery sends to a “solicited-node” multicast group that usually contains only the device being looked for.
Is multicast the same as sending many unicast copies?
No. With unicast, a server sending a video to 100 viewers sends 100 copies. With multicast, it sends one stream to a group address, and the network makes copies only where the paths split. That saves a lot of work for the server and the links near it.
How can I tell what type of traffic a frame is?
Look at the destination MAC address. ff:ff:ff:ff:ff:ff is broadcast. If the first byte is odd (such as 01 or 33), it is multicast. Anything else is unicast. The destination IP address tells the same story at Layer 3.