This is the final lesson of the packet flow unit, and it brings the whole course together. If you have read Same-subnet communication and Different-subnet communication, you already know the core ideas: the PC decides whether the destination is local or remote, uses ARP to find the next hop's MAC address, and routers build a new frame at every hop. Now you add names (DNS), a home router doing NAT, the internet, and the protocols that make a web page secure and reliable.
All addresses in this lesson are examples from ranges reserved for documentation. The real IP address of routelearn.net, your public IP and your MAC addresses will be different, but the steps are the same.
The setup
A laptop on a typical home or small-office network opens https://routelearn.net. Here are all the devices involved:
| Device | Address(es) | MAC (on its link) | Job |
|---|---|---|---|
| Laptop | 192.168.1.50/24, gateway 192.168.1.1 | 02:00:00:00:00:aa | Runs the browser |
| Switch | None needed | Not used in frames | Joins the LAN (often built into the home router) |
| Home router (router + firewall + NAT) | LAN 192.168.1.1, WAN 203.0.113.25 | LAN …:01, WAN …:02 | Gateway to the internet; holds the home's one public IP address |
| ISP router | 203.0.113.1 | …:fe | The provider's first router |
| DNS resolver | 198.51.100.53 | - | Looks up names for the laptop (run by the ISP here) |
| Web server | 198.51.100.10, TCP port 443 | - | Serves routelearn.net |
- 1. URL and cache. The browser reads the URL and checks its caches. Nothing usable is cached, so it needs the network.
- 2. DNS query. A UDP query to port 53 asks the resolver for routelearn.net's IP address.
- 3. DNS answer. The resolver replies: routelearn.net is 198.51.100.10. The laptop caches it.
- 4. To the gateway. 198.51.100.10 is remote, so the frame goes to the router's MAC address (learned with ARP).
- 5. NAT and the internet. The router replaces the private source address with its public IP address and port, then internet routers forward the packet hop by hop.
- 6. TCP handshake. The laptop and the server agree to open a connection on port 443.
- 7. TLS handshake. They agree on encryption keys and the server proves it really is routelearn.net.
- 8. HTTPS request. The encrypted request for the home page travels to the server.
- 9. Response and reverse NAT. The page comes back, and the router maps port 40001 back to 192.168.1.50:51000.
- 10. Render. The browser decrypts, builds the page and fetches images, styles and scripts.
Why this matters
Opening a website touches almost every topic in this course. When a site won't load, the fault is in one of these steps. If you can list them in order, you can test them in order, which is the heart of a troubleshooting method. It is also a classic job-interview question.
The 21 steps at a glance
| Steps | Phase | What happens |
|---|---|---|
| 1–2 | In the browser | Understand the URL, check the cache |
| 3–4 | Find the server | DNS turns routelearn.net into an IP address |
| 5–8 | Leave the PC | Local or remote? ARP, frame, switch |
| 9–10 | The edge router | Routing, firewall and NAT |
| 11–13 | Cross the internet | ISP and internet routers, hop by hop |
| 14–15 | Open a secure connection | TCP handshake, then TLS |
| 16–18 | Ask and answer | HTTPS request, response, return trip |
| 19–21 | Back home | Reverse NAT, receive, render |
💡 A note on order: the steps are numbered in the order you learn them, not strictly in the order packets are sent. The DNS query from step 3 is the first packet to leave the laptop, and it takes the same path out to the resolver. The packet you follow through steps 5 to 13 is the TCP SYN from step 14. You follow that SYN out, then look at the connection it starts.
Phase 1: in the browser (steps 1 and 2)
Step 1: The user enters the URL
You type routelearn.net or https://routelearn.net and press Enter. The browser splits the URL (Uniform Resource Locator) into parts:
| Part | Value | What it tells the browser |
|---|---|---|
| Scheme | https | Use HTTP inside TLS encryption |
| Host | routelearn.net | The name to look up in DNS |
| Port | (not written) → 443 | The default port for HTTPS (HTTP uses 80) |
| Path | / | Which page: the home page |
If you typed only the name, the browser assumes HTTPS (or tries HTTP first and is redirected to HTTPS).
Learn more: HTTP: How the Web TalksCommon Ports to Know
Step 2: The browser checks its cache
Fetching from the network is slow compared with reading from memory, so the browser first looks for things it already has:
- Page cache: a saved copy of the page or its files (images, stylesheets). If a copy is still marked fresh, it can be used without asking the server at all.
- DNS cache: a stored IP address for
routelearn.net, kept by the browser and the operating system. - Open connections: an existing TCP and TLS connection to the same server that can be reused.
On this first visit, nothing is cached, so the browser must go to the network for everything.
Phase 2: finding the server (steps 3 and 4)
Step 3: DNS lookup
Computers connect to IP addresses, not names. DNS (Domain Name System) works like the internet's phone book. The operating system sends a small query to its configured DNS resolver (learned from DHCP) asking for the A record (IPv4 address) of routelearn.net.
The query normally travels over UDP to port 53, from a random high source port. The resolver is on another network, so this query itself goes through steps 5 to 12 below. If the resolver doesn't already know the answer, it asks the root servers, then the .net servers, then the domain's own authoritative servers.
- Source IP : port
- 192.168.1.50:60123
- Destination IP : port
- 198.51.100.53:53
- Transport
- UDP
- Question
- routelearn.net, type A
Step 4: The IP address is learned
The operating system stores the answer in its DNS cache for the record's TTL and passes 198.51.100.10 to the browser. From now on, the network only uses this IP address. The name appears again only inside TLS and HTTP. If DNS fails here, none of the later steps can happen.
Learn more: DNS Problems
- routelearn.netchanged
- 198.51.100.10
- Cached for
- 300 seconds
C:\>nslookup routelearn.net Server: resolver1.isp.example Address: 198.51.100.53 Non-authoritative answer: Name: routelearn.net Address: 198.51.100.10
198.51.100.53). The Address under Name is the answer: 198.51.100.10. "Non-authoritative" means the answer came from the resolver's cache or lookup, not directly from the domain's own name server. Try it yourself with the Website to IP tool.Phase 3: leaving the laptop (steps 5 to 8)
Step 5: Local or remote?
The laptop applies its subnet mask to 198.51.100.10. It is not in 192.168.1.0/24, so the server is remote and the packet must go to the default gateway. This is exactly the decision described in Different-subnet communication. (For a website on the internet, the server is practically always remote.)
- My network
- 192.168.1.0/24
- Destination network
- 198.51.100.x: not mine
- Decisionchanged
- Remote → default gateway 192.168.1.1
Step 6: ARP for the gateway's MAC address
To put the packet in a frame, the laptop needs the router's MAC address. It checks its ARP cache; if the entry is missing, it broadcasts an ARP request for 192.168.1.1. In practice, the entry is almost always cached already, because the DNS query in step 3 needed the same gateway. The laptop never sends an ARP request for 198.51.100.10, because the server is not on its local network.
Learn more: ARP for Local and Remote Destinations
- Request
- Who has 192.168.1.1?
- Sent to
- ff:ff:ff:ff:ff:ff
- Replychanged
- 192.168.1.1 is at 02:00:00:00:00:01
Step 7: The Ethernet frame is created
The laptop encapsulates the first packet, a TCP SYN (step 14), layer by layer:
- TCP header: source port
51000(a temporary "ephemeral" port the operating system picks for this connection), destination port443. - IP header: source
192.168.1.50, destination198.51.100.10, TTL 128. - Ethernet header: source
02:00:00:00:00:aa, destination02:00:00:00:00:01(the gateway), plus an FCS (frame check sequence) trailer.
Learn more: Port Numbers and SocketsThe Ethernet Frame
- Source MAC
- 02:00:00:00:00:aa
- Destination MACchanged
- 02:00:00:00:00:01
- Source IP : port
- 192.168.1.50:51000
- Destination IP : port
- 198.51.100.10:443
- TTL
- 128
- TCP flags
- SYN (first packet)
Data: The application produces data, such as an HTTPS request.A complete Ethernet frame
- Data · application
- Segment · transport
- Packet · network
- Frame · data link
Data: The application produces data, such as an HTTPS request. Segment: TCP adds a header with the source and destination ports. Packet: IP adds a header with the source and destination IP addresses. Frame: Ethernet adds MAC addresses in front and an error check (FCS) at the end.
Step 8: The switch forwards the frame
The switch learns the laptop's MAC address on the port it arrived on, finds the router's MAC address …:01 in its MAC address table, and forwards the frame out of that one port, unchanged. On Wi-Fi, the access point does a similar job, then passes the frame onto the wired network.
Learn more: How a Switch Learns MAC Addresses
- Source MAC
- 02:00:00:00:00:aa
- Destination MAC
- 02:00:00:00:00:01
- Source IP : port
- 192.168.1.50:51000
- Destination IP : port
- 198.51.100.10:443
Phase 4: the edge router, firewall and NAT (steps 9 and 10)
Step 9: The router and firewall process the packet
The home router is several devices in one box. In order:
- Router, Layer 2: the destination MAC address is its own, so it accepts the frame and removes the Ethernet header.
- Router, Layer 3: it looks up
198.51.100.10in its routing table. The only match is the default route (0.0.0.0/0, "everything else"), pointing to the ISP router203.0.113.1. The TTL drops to 127. - Firewall: a stateful firewall checks its rules. Connections started from inside are normally allowed. It records this connection in its state table, so the reply will be let back in while uninvited traffic from outside is blocked.
Learn more: RoutersFirewall Basics
- Frame
- Dst MAC 02:00:00:00:00:01 = mine → accept
- Routechanged
- 0.0.0.0/0 → 203.0.113.1 (ISP)
- Firewallchanged
- Outbound HTTPS allowed; state recorded
- TTLchanged
- 128 → 127
Step 10: NAT translates the private address
192.168.1.50 is a private address. Private addresses are not routed on the internet, so the server could never reply to it. The router therefore performs PAT (Port Address Translation, the common form of NAT):
- It replaces the source IP
192.168.1.50with its own public IP203.0.113.25. - It may replace the source port too (here
51000→40001). Many routers keep the original port when it is free; either way, the port is what tells the conversations apart. - It writes the mapping into its NAT table so it can reverse it later (step 19).
- It builds a new frame for the ISP link, from its WAN MAC to the ISP router's MAC.
Every device in the home shares that one public IP address.
Learn more: Why NAT Exists
- Source MACchanged
- 02:00:00:00:00:02
- Destination MACchanged
- 02:00:00:00:00:fe
- Source IP : portchanged
- 203.0.113.25:40001
- Destination IP : port
- 198.51.100.10:443
- TTLchanged
- 127
- Source MAC
- …:aa
- Destination MAC
- …:01
- Source IP:port
- 192.168.1.50:51000
- Destination IP:port
- 198.51.100.10:443
- TTL
- 128
- Source MAC
- …:02 (rewritten)
- Destination MAC
- …:fe (rewritten)
- Source IP:port
- 203.0.113.25:40001 (rewritten)
- Destination IP:port
- 198.51.100.10:443
- TTL
- 127 (rewritten)
Highlighted fields were rewritten by the router.
| Protocol | Inside (private) | Outside (public) | Remote server |
|---|---|---|---|
| TCP | 192.168.1.50:51000 | 203.0.113.25:40001 | 198.51.100.10:443 |
| UDP | 192.168.1.50:60123 | 203.0.113.25:40000 | 198.51.100.53:53 (the DNS query) |
Phase 5: across the internet (steps 11 to 13)
Step 11: The packet reaches the ISP
The frame crosses the access link (DSL, cable, fibre or mobile, usually through a modem or fibre terminal) to the ISP's first router. That link may not use Ethernet at all, but the idea is the same: a Layer 2 header for this one link, wrapped around the unchanged IP packet. The ISP router removes that header, looks up 198.51.100.10 and sends the packet on.
- Source MAC
- 02:00:00:00:00:02
- Destination MAC
- 02:00:00:00:00:fe
- Source IP : port
- 203.0.113.25:40001
- Destination IP : port
- 198.51.100.10:443
- TTLchanged
- 127 → 126 as the ISP router forwards it
Step 12: Internet routers forward it hop by hop
The internet is made of thousands of separate networks, run by different companies and connected together. Each router on the way does exactly what R1 did in Different-subnet communication: remove the frame, look up the destination, lower the TTL by one and build a new frame for the next link. A typical path crosses 8 to 20 routers.
How do they know the way? Large networks tell each other which addresses they can reach using a routing protocol called BGP (Border Gateway Protocol). You don't need the details here; the CCNA course covers it. You can watch the hops yourself with traceroute.
Learn more: Where BGP Fits
- MAC addresseschanged
- Replaced (new frame)
- Source IP : port
- 203.0.113.25:40001
- Destination IP : port
- 198.51.100.10:443
- TTLchanged
- Minus 1 per router
Step 13: The server receives the packet
The last router delivers a frame to the server's MAC address. The server de-encapsulates it: its own MAC address, its own IP address, and TCP destination port 443, where the web server software is listening. Note that the server sees the home's public address 203.0.113.25, never 192.168.1.50.
Large sites rarely run on a single server. The address usually belongs to a load balancer or a content delivery network (CDN) edge server close to you, which passes the request to one of many servers behind it. The steps from your side look the same.
- Destination MAC
- Server's own MAC
- Source IP : port
- 203.0.113.25:40001
- Destination IP : port
- 198.51.100.10:443
- TTL
- e.g. 115 (13 routers later)
Phase 6: opening a secure connection (steps 14 and 15)
Step 14: The TCP three-way handshake
The packet you just followed was a SYN, the first of three messages that open a TCP connection. TCP makes the connection reliable: it numbers every byte, resends anything lost and puts the data back in order. Each side picks a random starting sequence number.
Step 15: TLS negotiation
TLS (Transport Layer Security) is what puts the "S" in HTTPS. Before any web content is sent, the browser and the server use TLS to:
- Agree on encryption keys without ever sending the keys themselves across the network.
- Prove the server's identity: the server sends a certificate for
routelearn.net, signed by a certificate authority the browser trusts. The browser checks that the name matches, the signature is valid and the certificate has not expired. - Agree on the application protocol, for example HTTP/2.
With TLS 1.3, this takes one round trip. You can check any site's certificate with the SSL Checker.
Learn more: HTTPS and TLS
Phase 7: request and response (steps 16 to 18)
Step 16: The HTTPS request is sent
The browser sends an HTTP request through the encrypted TLS channel. Decrypted, it looks roughly like this:
GET / HTTP/2 :authority: routelearn.net user-agent: Mozilla/5.0 (...) accept: text/html accept-language: en-GB
On the wire, routers see only the IP addresses, the ports and encrypted bytes. The URL path and the HTTP headers are hidden. The packet follows the same route as the SYN: steps 7 to 13 again, including NAT.
- Source MAC
- 02:00:00:00:00:aa
- Destination MAC
- 02:00:00:00:00:01
- Source IP : port
- 192.168.1.50:51000
- Destination IP : port
- 198.51.100.10:443
Step 17: The server responds
The web server finds (or generates) the home page and replies with a status code and the content:
HTTP/2 200 content-type: text/html; charset=utf-8 cache-control: public, max-age=0, must-revalidate <!DOCTYPE html><html> ... the page ... </html>
200 means OK. Other common codes are 301 (moved), 404 (not found) and 500 (server error). A page larger than one packet is split across many TCP segments, which the laptop acknowledges as they arrive.
- Source IP : portchanged
- 198.51.100.10:443
- Destination IP : portchanged
- 203.0.113.25:40001
- Content
- HTTP 200 + HTML (encrypted by TLS)
- TTL
- 64 (a common server default)
Step 18: Return traffic crosses the internet
The reply simply swaps the source and destination. It is addressed to the public address 203.0.113.25:40001, because that is the only address the server ever saw. Internet routers forward it hop by hop, as in step 12. The return path doesn't have to use the same routers as the outgoing path, and often doesn't.
- Source IP : portchanged
- 198.51.100.10:443
- Destination IP : portchanged
- 203.0.113.25:40001
- MAC addresses
- New at every hop
- TTL
- Starts at e.g. 64, minus 1 per hop
Phase 8: back home (steps 19 to 21)
Step 19: NAT is reversed
The home router receives a packet for 203.0.113.25:40001. It looks in its NAT table and finds that port 40001 belongs to 192.168.1.50:51000, and the firewall confirms that the packet belongs to a connection started from inside. The router rewrites the destination, routes the packet onto the LAN and builds a new frame from …:01 to the laptop's …:aa (using its own ARP cache for 192.168.1.50).
- Source MACchanged
- 02:00:00:00:00:01
- Destination MACchanged
- 02:00:00:00:00:aa
- Source IP : port
- 198.51.100.10:443
- Destination IP : portchanged
- 192.168.1.50:51000
- Source IP:port
- 198.51.100.10:443
- Destination IP:port
- 203.0.113.25:40001
- Source IP:port
- 198.51.100.10:443
- Destination IP:port
- 192.168.1.50:51000 (rewritten)
Highlighted fields were rewritten by the router.
Step 20: The browser receives the data
The frame goes through the switch to the laptop, which unwraps it from the bottom up:
- Ethernet: the destination MAC address is mine and the FCS is good → pass up to IP.
- IP: the destination
192.168.1.50is mine → pass up to TCP. - TCP: port 51000 belongs to the browser's connection. TCP acknowledges the data and puts the segments back in order.
- TLS: decrypts the bytes and checks that they were not changed on the way.
- HTTP: passes the status code, headers and HTML to the browser.
- Source MAC
- 02:00:00:00:00:01
- Destination MAC
- 02:00:00:00:00:aa
- Source IP : port
- 198.51.100.10:443
- Destination IP : port
- 192.168.1.50:51000
Step 21: The page is rendered
The browser reads the HTML and builds the page structure. The HTML refers to more files (stylesheets, scripts, fonts, images), so the browser requests those too. Files from routelearn.net reuse the existing TCP and TLS connection; files from other domains need their own DNS lookup and connection (steps 3 to 20 again). Finally, the browser lays out the page and draws it on the screen, usually in well under a second.
The running address table
Here is the same TCP connection seen at each point on the path. Notice what changes: the MAC addresses at every router, the source IP address and port at NAT (the destination on the way back), and nothing else.
| Where | Src MAC | Dst MAC | Source IP : port | Destination IP : port | TTL |
|---|---|---|---|---|---|
| Laptop → router (LAN) | …:aa | …:01 | 192.168.1.50:51000 | 198.51.100.10:443 | 128 |
| Router → ISP (after NAT) | …:02 | …:fe | 203.0.113.25:40001 | 198.51.100.10:443 | 127 |
| Across the internet | New at every hop | 203.0.113.25:40001 | 198.51.100.10:443 | −1 per hop | |
| Arriving at server | last router | server | 203.0.113.25:40001 | 198.51.100.10:443 | e.g. 115 |
| Server reply (internet) | New at every hop | 198.51.100.10:443 | 203.0.113.25:40001 | 64, −1 per hop | |
| Router → laptop (NAT reversed) | …:01 | …:aa | 198.51.100.10:443 | 192.168.1.50:51000 | e.g. 51 |
- MAC addresses change at every router, because they only describe the current link.
- IP addresses and ports stay the same end to end, except where NAT rewrites them (source on the way out, destination on the way back).
- TTL goes down by one at every router.
What happens when a step fails
| Step that fails | Typical cause | What you see |
|---|---|---|
| 3–4 DNS | Resolver down, wrong DNS server, typo in the name | "This site can't be reached… DNS_PROBE_FINISHED_NXDOMAIN" or "server not found". Pinging an IP still works. |
| 5–6 Gateway / ARP | Wrong or missing gateway, router off | Nothing outside the LAN works. A ping to 192.168.1.1 fails. |
| 8 Switch / Wi-Fi | Cable, port, Wi-Fi association | No link, or an APIPA address (169.254.x.x) because DHCP also failed. |
| 9–11 Router / ISP | Internet connection down, firewall rule | The LAN works, but the internet doesn't. Traceroute stops after hop 1 or 2. |
| 12–13 Internet / server | Routing problem, server down | Timeouts. Traceroute stops partway. Other sites load normally. |
| 14 TCP | Nothing listening on 443, firewall blocking | "Connection refused" (a reset came back) or "timed out" (nothing came back). |
| 15 TLS | Expired or wrong certificate, wrong clock on the PC | A full-page browser warning such as "Your connection is not private". |
| 16–17 HTTP | Missing page, application error | A 404 or 500 error page. The network is fine! |
💡 The error message tells you which step failed. A DNS error means you never got past step 4. A certificate warning means steps 1 to 14 all worked. A 404 page means the network did its job.
Troubleshooting: test the steps in order
- Steps 5–6:
ipconfig, thenping 192.168.1.1. Is my address right, and can I reach the gateway? - Steps 9–12:
pinga well-known public IP. Does the internet path work without DNS? - Steps 3–4:
nslookup routelearn.net. Does DNS answer? - Step 14:
Test-NetConnection routelearn.net -Port 443(PowerShell). Can a TCP connection be opened? - Steps 15–17:
curl -I https://routelearn.net. Does TLS succeed, and what status code comes back?
C:\>tracert -d routelearn.net Tracing route to routelearn.net [198.51.100.10] over a maximum of 30 hops: 1 1 ms 1 ms 1 ms 192.168.1.1 2 8 ms 7 ms 8 ms 203.0.113.1 3 10 ms 9 ms 10 ms 192.0.2.17 4 * * * Request timed out. 5 14 ms 13 ms 14 ms 192.0.2.130 6 15 ms 15 ms 15 ms 198.51.100.10 Trace complete.
198.51.100.10. A single row of stars in the middle, followed by later hops that answer, usually just means that router doesn't reply to traceroute. It is still forwarding traffic.PS C:\> Test-NetConnection routelearn.net -Port 443 ComputerName : routelearn.net RemoteAddress : 198.51.100.10 RemotePort : 443 InterfaceAlias : Wi-Fi SourceAddress : 192.168.1.50 TcpTestSucceeded : True
C:\>netstat -n | findstr :443 TCP 192.168.1.50:51000 198.51.100.10:443 ESTABLISHED
192.168.1.50:51000. The remote side is the server on port 443, and ESTABLISHED means the TCP connection is open.Learn more: Viewing Connections on Your Computer
$ curl -sI https://routelearn.net HTTP/2 200 content-type: text/html; charset=utf-8 cache-control: public, max-age=0, must-revalidate
Learn more: A Troubleshooting MethodEssential Windows Network Commands
Common mistakes
- Thinking the laptop sends the frame to the web server's MAC address. It sends the frame to the gateway's MAC address. On this path, only the last router needs to know the server's MAC address.
- Thinking the web server sees your 192.168.x.x address. It sees the home router's public address after NAT.
- Thinking HTTPS hides which site you visit. It hides the page and its content, but the IP addresses, and usually the site name, are still visible on the path.
- Thinking DNS happens on every request. Answers are cached for their TTL, so repeat visits usually skip step 3.
- Assuming a site is down because ping fails. Many servers ignore ping but serve HTTPS normally. Test port 443 instead.
- Forgetting the return trip. Half of the journey is the reply, and it depends on the NAT table and the firewall's state table.
- The browser checks caches first, then uses DNS to turn the name into an IP address.
- The server is remote, so the laptop uses ARP to find the gateway's MAC address and sends the frame there.
- The home router routes, filters (firewall) and translates (NAT) before handing the packet to the ISP.
- Internet routers forward the packet hop by hop: new MAC addresses, the same IP addresses, and the TTL minus one.
- TCP opens a reliable connection, TLS secures it, and only then is the HTTP request sent.
- The reply comes back to the public IP, NAT reverses it, and the browser unwraps and renders the page.
Knowledge check
The laptop sends the TCP SYN for routelearn.net. What destination MAC address is in the frame as it leaves the laptop?
The SYN from 192.168.1.50:51000 passes through the home router and reaches the web server. What source IP address and port does the server see?
A user can open websites by IP address, but every site by name fails with 'server not found'. Which step is failing?
The browser shows 'Your connection is not private' because the certificate has expired. Which steps definitely worked?
After the home router, the SYN passes through 12 more routers (the ISP router included) before reaching the server. Assuming every link is Ethernet, how many different frames carry it from the laptop to the server?
Related lessons
Each step above has its own full lesson elsewhere in the course. Revisit DNS, ARP fundamentals, The default gateway, How NAT and PAT work, Firewall basics, The three-way handshake, HTTPS and TLS and HTTP: how the web talks. For a shorter overview of the same journey, see the summary in What is a computer network?. Next up is the troubleshooting unit, where you will use this step-by-step picture to find faults.