How Computers Talk: Packets, Frames, and Addresses
Enterprise Network Engineer · Module 1: Networking Fundamentals
Lesson 2 of 8
Prerequisites: What Is a Network, Really?
What you'll be able to do: explain how messages are wrapped in layers, name the three addresses every device uses and what each is for, and read one line of a packet capture.
Write a birthday card and you face three addressing jobs. The card names your friend. The envelope names the street address the mail carrier needs. The courier's pouch names only the depot it goes to first — the courier never reads your card at all.
Every message your computer sends does the same triple-wrapping. The inner message names the faraway computer. A middle wrapper names the final destination for every network along the way. An outer wrapper names only the next device down the wire — rewritten at every stop, like the courier's pouch.
Get one wrapper wrong and the message goes to the wrong place, or nowhere. Most "the internet is broken" mysteries are just a wrong address on the wrong wrapper.
Here's the puzzle.
Scenario. Your friend Priya's video calls work fine, but her roommate's laptop can't see the shared folder on Priya's laptop. You're staring at a short list of captured messages from Priya's laptop, trying to learn which address does what — because the fix depends on knowing which wrapper is wrong.
Given artifacts. Four captured messages. Key: aa:aa:… = Priya's laptop · bb:bb:… = roommate's laptop · cc:cc:… = the home box that forwards messages between the apartment and the internet.
# | Time | Source hardware | Dest hardware | Source IP | Dest IP | Src port | Dst port | Info
1 | 0.000 | aa:aa:aa:aa:aa:aa | bb:bb:bb:bb:bb:bb | 192.168.1.10 | 192.168.1.20 | 52341 | 445 | File-share request
2 | 0.004 | bb:bb:bb:bb:bb:bb | aa:aa:aa:aa:aa:aa | 192.168.1.20 | 192.168.1.10 | 445 | 52341 | File-share reply
3 | 1.102 | aa:aa:aa:aa:aa:aa | cc:cc:cc:cc:cc:cc | 192.168.1.10 | 203.0.113.45 | 61200 | 443 | Video-call data
4 | 1.150 | cc:cc:cc:cc:cc:cc | aa:aa:aa:aa:aa:aa | 203.0.113.45 | 192.168.1.10 | 443 | 61200 | Video-call data
Your task: using only packet #3, answer three questions with the exact values from its row — (a) which machine on this wire should receive it (the destination hardware address), (b) which machine across the world is the true destination (the destination IP address), (c) which program on the far machine should get it (the destination port).
Workspace: analyze-and-answer — three text fields labeled (a), (b), (c). Copy the values exactly as they appear; nothing is graded.
Hint 1 — where to look
All three answers sit in packet #3's row — the other packets are only there for comparison. Find the three destination columns and copy them exactly. That's the whole mechanical job; the thinking is in why they're those values.Hint 2 — what to compare
Compare packet #1 with packet #3. In #1, the destination hardware address names the roommate's laptop — the true destination. In #3, the destination hardware address does not name the video server. Why would the "on this wire" address differ from the "across the world" address?Hint 3 — the mechanism
Hardware addresses only work on the local wire, so a message leaving for the internet is handed — at the hardware level — to the device that carries it off the wire: the home box. The worldwide address, meanwhile, names the true final destination and never changes along the way. One of the three destination columns in packet #3 names a machine that is not the video server — and that's correct behavior, not a bug.Commitment ritual: below the workspace sits a checkbox — "I've attempted this challenge and thought it through." Checking it (with or without typing an answer) reveals the worked answer in S7. Nothing is graded; the checkbox is a promise to yourself that you struggled first. (Honor system for now — real progress tracking arrives with accounts.)
Checking the box reveals the worked answer in S7 below. Returning learners stay unlocked.
Messages travel in small, addressed pieces
The smallest piece of information is a bit (a single 1 or 0 — eight of them make a byte, and everything you've ever seen on a screen is bits in bulk). Networks don't send your whole video call as one giant blob; they chop every message into small chunks called packets (a small piece of a larger message, carrying addresses so the network knows where it's going).
Why chop? Sharing. A wire is like a single-lane road: if one giant truck (your video call) blocked it end to end, everyone else's mail would wait. Small packets interleave — a slice of your call, a slice of your roommate's file transfer, a slice of someone's web page — so hundreds of conversations share the same wires fairly. Your devices quietly reassemble the slices at the far end.
Why this matters for the challenge: each row in the capture is one packet — one slice, with its addresses printed on the outside. Reading the row means reading the addresses.
Wrappers inside wrappers: encapsulation
Every packet wears layers, and the layering has a name: encapsulation (wrapping data in successive layers, each layer adding its own addressing — the card, the envelope, and the courier's pouch from the hook). The order matters and never changes:
- Your program hands down its message with the worldwide addresses attached — this is the packet, addressed from the true sender to the true receiver.
- Then the local wire addresses are attached outside it — now it's a frame (a packet plus its outermost wrapper, the envelope used for one trip along one wire).
Inner wrapper: who in the world. Outer wrapper: who's next on this wire. At every stop along the way, the outer wrapper is peeled off and replaced with a fresh one naming the next device — while the inner addresses ride through untouched, all the way to the far end.
Why this matters for the challenge: packet #3 wears both wrappers. The puzzle is noticing that its two destination addresses name two different machines — and realizing that's exactly how the system is designed.
Three addresses, three jobs
Every connected device juggles three kinds of address, each answering one question:
| Question | Address | Scope |
|---|---|---|
| Which device is next on this wire? | hardware address (also called a MAC address — a permanent label built into a device's network plug; it only has meaning on the local wire) | one wire |
| Which device, anywhere in the world? | IP address (the worldwide device address, like 192.168.1.10 — it names the true sender and receiver and stays the same for the whole trip) | everywhere |
| Which program on that device? | port (a number naming which program should send or receive — the apartment number inside the building; your video app and your browser each get their own) | one device |
A useful memory hook: the hardware address is the courier's depot, the IP address is the street address, and the port is the name on the mailbox. Miss the depot and the pouch never leaves town; miss the street and it crosses the world to the wrong house; miss the name and it arrives at the right house but nobody claims it.
Why this matters for the challenge: questions (a), (b), and (c) map one-to-one onto these three rows. You'll apply the mapping to packet #3 in the worked answer.
How to read one line of a capture
A capture is just a list of packets, one per row, in the order they flew past. The columns are always the same story: # (the packet's number in the list), Time (seconds since the capture started), Source → Destination (who sent it, who should receive it), Protocol (what kind of message), Length (how big), and Info (a one-line human summary).
Two reading habits that pay off forever. First, read source and destination as a pair — packets 1 and 2 in the challenge are mirror images, the request and its reply. Second, when two addresses on one row disagree, ask which wrapper each belongs to — the challenge's packet #3 disagrees with itself on purpose, and the disagreement is the lesson.
In the challenge excerpt we laid every address out flat so you can compare them side by side. Real tools nest them — hardware addresses inside the frame section, IP addresses inside the packet section, ports inside the program section — and Section 5 walks you through that real view.
Why this matters for the challenge: (a), (b), and (c) are all visible in packet #3's row right now. The theory gave you the map; the row is the territory.
- Step 1 of 5: Your program hands down its message — just the content, no addresses yet.
- Step 2 of 5: The worldwide addresses are attached (green wrapper): from 192.168.1.10 to 203.0.113.45. This is now a packet — it names the true sender and receiver.
- Step 3 of 5: The local wire addresses are attached outside (amber wrapper): to the home box, the next device on this wire. This is now a frame — ready for one trip along one wire.
- Step 4 of 5: The frame travels the wire to the home box.
- Step 5 of 5: The home box peels off the amber wrapper and will write a fresh one for the next wire — but the green worldwide addresses ride through untouched, all the way to the far server.
First capture reading — a laptop opens a web page and shares a file
green = healthy/expected · red = problem packet(s) · amber = noteworthy, not faulty · untinted = context
| No | Time | Source | Destination | Protocol | Length | Info |
|---|---|---|---|---|---|---|
| 1 | 0.000 | 192.168.1.10 | 203.0.113.45 | TCP | 66 | Web request — laptop to far server |
| 2 | 0.048 | 203.0.113.45 | 192.168.1.10 | TCP | 66 | Web reply — server answers |
| 3 | 1.200 | 192.168.1.10 | 192.168.1.20 | TCP | 62 | File-share request — laptop to roommate |
| 4 | 1.204 | 192.168.1.20 | 192.168.1.10 | TCP | 62 | File-share reply |
| 5 | 2.310 | 192.168.1.10 | 203.0.113.77 | TCP | 66 | Second web request — new conversation |
Step 1 of 4 · packets 1, 2: Read the list like a story: packet 1 is the request, packet 2 is its mirror-image reply. Source and destination swap — that pairing is the first thing to check in any capture.
Step 2 of 4 · packets 1: Open packet 1 and look at its two destination addresses. The frame names the home box; the packet inside names the far web server. Same row, two different machines — the outer wrapper vs the inner one.
Step 3 of 4 · packets 3, 4: Now the local baseline: laptop to roommate's laptop. Here the frame and the packet agree — both name the roommate. On one wire with no forwarding box, the wrappers line up.
Step 4 of 4 · packets 5: A second web request, but the source port changed (61201, not 61200). New port, new conversation — ports are how one laptop holds many talks at once.
| No | Time | Source | Destination | Protocol | Length | Info |
|---|---|---|---|---|---|---|
| 1 | 0.000 | 192.168.1.10 | 203.0.113.45 | TCP | 66 | Web request — laptop to far server |
| 2 | 0.048 | 203.0.113.45 | 192.168.1.10 | TCP | 66 | Web reply — server answers |
| 3 | 1.200 | 192.168.1.10 | 192.168.1.20 | TCP | 62 | File-share request — laptop to roommate |
| 4 | 1.204 | 192.168.1.20 | 192.168.1.10 | TCP | 62 | File-share reply |
| 5 | 2.310 | 192.168.1.10 | 203.0.113.77 | TCP | 66 | Second web request — new conversation |
Fixture: hand-authored to teach capture reading: nested address layers, the local-vs-worldwide split, and ports; no production data
🔒 Revealed after the commitment ritual in S2 — attempt the challenge first. (Honor system: the page hides this until you check the box.)
Step 1 — Isolate packet #3's row. Ignore the other three for a moment; every answer you need is in row 3: aa:aa:aa:aa:aa:aa → cc:cc:cc:cc:cc:cc · 192.168.1.10 → 203.0.113.45 · 61200 → 443.
Step 2 — Read the three destination columns. (a) The destination hardware address is cc:cc:cc:cc:cc:cc — the home box. (b) The destination IP address is 203.0.113.45 — the far video server. (c) The destination port is 443 — the video service's program number on that server.
Step 3 — Understand why (a) and (b) name different machines. This is the whole lesson in one row. The video server is not on Priya's wire — the home box is the thing that carries messages off the wire toward the internet. So the outer wrapper (the frame) is addressed to the home box: "you're next, take this." The inner wrapper (the packet) is addressed to the true destination, 203.0.113.45, and the home box will write a new outer wrapper for the next wire without touching it. The port, 443, rides inside all the way to the far program.
Wrong turns, named: "The destination hardware address should be the video server's" — the most instructive wrong answer. The server's hardware address doesn't appear anywhere in the capture because the server isn't on this wire; hardware addresses can't cross wires. "The answers are aa:aa:… / 192.168.1.10 / 61200" — those are the source columns (Priya's side), not the destinations the question asked for. "(c) is 61200, the video app" — 61200 is Priya's laptop's return number; the question asked which program on the far machine, which is 443.
The exact answer: (a) cc:cc:cc:cc:cc:cc · (b) 203.0.113.45 · (c) 443.
Verify it worked: now read packet #4 — the reply — and predict before looking: every source/destination pair should be mirror-swapped. Expected: hardware cc:cc:… → aa:aa:…, IP 203.0.113.45 → 192.168.1.10, ports 443 → 61200. If all three flip cleanly, you read the addresses right — and you now know why Priya's video calls work (their wrappers are correct) while the file-share problem must live in a different wrapper.
Check yourself — nothing here is graded. Wrong answers are the useful ones; each explains why.
Question 1. A message is being prepared for sending. Which wrapping happens first?
Question 2. Which address picks the program — for example, the web browser versus the video app on the same machine?
Question 3. You capture traffic from your laptop to a faraway server. The destination hardware address names your home box, not the server. Is something broken?
Question 4. Two laptops on the same wifi exchange files. In the capture, the destination hardware address and the destination IP address both name the receiving laptop. What does that tell you?
Question 5. A capture line reads: 192.168.1.10 → 203.0.113.45, Src port 61200, Dst port 443. Which program on the far machine is being contacted?
- Big messages are split into small addressed packets so many conversations can share the same wires fairly.
- Encapsulation wraps twice: worldwide addresses make it a packet, local wire addresses make it a frame — always in that order.
- Three addresses, three jobs: hardware names the next device on this wire, IP names the device anywhere in the world, port names the program on the device.
- For internet traffic the destination hardware address is your forwarding box, not the far server — the outer wrapper is rewritten at every stop while the IP addresses ride through unchanged.
- Read a capture line by matching each address to its job: wire, world, or program — and read source/destination as mirror-image pairs.
Next: IP Addresses and Subnets Without Tears — you can now read the addresses on a packet; next you'll learn to read the addresses themselves: what the four numbers mean, and how to tell whether two devices are neighbors or strangers.