Network Layer Protocols

Ka Kavitha V Updated 08 Oct 2026
15 min read ·Lesson 27 of 45

Network Layer Protocols

Whenever data leaves your device and has to cross more than one network to reach its destination, the Network Layer — Layer 3 of the OSI model — is the layer responsible for getting it there. It does not care what the data is; it only cares about addressing it correctly and choosing a path for it to travel. Everything from browsing a website to streaming video depends on a set of specialized protocols working together at this layer.

This lesson walks through the most important Network Layer protocols, grouped by what they actually do: resolving addresses, delivering and diagnosing packets, managing multicast groups, assigning addresses automatically, translating addresses, and routing packets across networks.

What Is the Network Layer?

The Network Layer's core job is logical addressing and routing: moving packets from a source device to a destination device, even when the two devices sit on completely different networks that have never communicated before.

Its main responsibilities are:

ResponsibilityDescription
Logical addressingAssigns every device a unique IP address, independent of the physical hardware
RoutingDetermines the best path a packet should take across multiple networks
Packet forwardingMoves packets from router to router until they reach the destination
Fragmentation and reassemblySplits packets that are too large for a network link and reassembles them at the destination
Error reportingReports problems such as unreachable hosts or expired packets
Multicast supportAllows one sender to efficiently deliver data to many receivers

A useful analogy is a courier service shipping a parcel from Chennai to Delhi:

Courier conceptNetwork Layer equivalent
Sender's addressSource IP address
Receiver's addressDestination IP address
Courier hubsRouters
Route planningRouting protocols

Just as a courier service picks the most efficient route between hubs rather than a single direct road, the Network Layer picks the best available path across routers — and that path can change if part of the network becomes unavailable.

No single protocol does all of this. Instead, a family of protocols divides the work: some resolve addresses, some carry and diagnose traffic, some assign addresses automatically, and some calculate routes. The rest of this lesson covers each one.

Address Resolution: ARP and RARP

Before two devices on the same local network (LAN) can actually exchange data, their network cards need to know each other's MAC address (the physical hardware address burned into a network interface). Applications and users, however, work with IP addresses. ARP and RARP exist to bridge that gap.

ARP (Address Resolution Protocol)

ARP finds the MAC address of a device when only its IP address is known. It is the mechanism that lets an IP-addressed packet actually be delivered on an Ethernet or Wi-Fi network, where delivery ultimately happens using MAC addresses.

How ARP works

Suppose Computer A wants to send data to Computer B on the same LAN:

  1. Check the ARP cache. Computer A first checks its local ARP cache — a small table mapping IP addresses to MAC addresses — to see if it already knows B's MAC address.

    arp -a

    This Windows/Linux command displays the current ARP cache.

  2. Broadcast an ARP request. If there's no cached entry, Computer A broadcasts a request to every device on the LAN:

    "Who has IP address 192.168.1.10?"

  3. Receive the ARP reply. Only the device that owns that IP address responds, directly to Computer A:

    "I am 192.168.1.10, and my MAC address is AA-BB-CC-DD-EE-FF."

  4. Cache the result. Computer A stores this mapping in its ARP cache so that future packets to that IP don't require another broadcast.

Dynamic vs. static ARP entries

Entry typeHow it's createdLifetime
DynamicLearned automatically through the request/reply process aboveTemporary — expires after a timeout and is relearned as needed
StaticAdded manually by a network administratorPermanent until manually removed

Static entries are occasionally used for security or stability (for example, pinning a server's MAC address to prevent ARP spoofing), but dynamic entries are the norm on ordinary networks.

RARP (Reverse Address Resolution Protocol)

RARP does the opposite of ARP: given a device's own MAC address, it asks the network for a corresponding IP address.

How RARP works

  1. A device knows only its own MAC address (it has no IP address configured yet).
  2. It broadcasts a RARP request containing that MAC address.
  3. A RARP server on the network looks up the MAC address and replies with the IP address assigned to it.

This was historically used by diskless workstations that had no local storage to remember a previously assigned IP address and had to ask for one every time they booted.

Note: RARP is now obsolete. DHCP (covered later in this lesson) replaced it because DHCP also provides the subnet mask, default gateway, and DNS server in a single exchange, instead of just an IP address.

ICMP (Internet Control Message Protocol)

ARP and RARP solve addressing. ICMP solves a different problem: what happens when something goes wrong while a packet is in transit? ICMP lets routers and hosts report network errors and diagnostic information back to the sender.

Important: ICMP only reports problems. It does not fix them, retransmit lost data, or guarantee delivery — that's left to other protocols or the application itself.

Ping: ICMP's most familiar use

The ping command uses two ICMP message types — Echo Request and Echo Reply — to test whether a destination is reachable:

ping google.com

If Google's server is reachable, it responds with Echo Reply messages, and ping reports the round-trip time. If there's no response, something along the path — the destination, a router, or a firewall — is blocking or failing to deliver ICMP traffic.

Common ICMP error messages

MessageWhen it's generatedExample
Destination UnreachableThe destination network or host cannot be reachedThe target web server is offline
Time ExceededA packet's TTL (Time to Live) counter reaches zero before arrivingA routing loop causes a packet to bounce between routers until it expires
Parameter ProblemThe IP header contains invalid or malformed dataA malformed or corrupted packet header
RedirectA router knows of a better next-hop router for a given destinationA host is told to use a more direct router for future packets

Source Quench, an older ICMP message that asked a sender to slow down during congestion, is now considered obsolete and has been deprecated in modern networks (RFC 6633) in favor of congestion control handled at the Transport Layer, such as TCP's own algorithms.

TTL deserves a quick explanation since it comes up in the Time Exceeded message: every IP packet carries a TTL value that a router decrements by one each time it forwards the packet. When TTL reaches zero, the packet is discarded and an ICMP Time Exceeded message is sent back to the source. This mechanism exists specifically to prevent packets from circulating forever if a routing loop occurs.

IGMP (Internet Group Management Protocol)

Most traffic on a network is unicast — one sender talking to one receiver, like sending an email. But some traffic needs to reach many receivers at once efficiently, such as live video streaming, online classes, or IPTV. Sending a separate copy of the stream to every viewer would waste enormous bandwidth. This is where multicast comes in: one sender transmits a single stream, and the network itself replicates it only where needed, to only the devices that asked for it.

IGMP is the protocol that manages multicast group membership between hosts and their local router.

IGMP messagePurpose
Membership QuerySent by a router to check which multicast groups are still active on the network
Membership ReportSent by a host to join a multicast group
Leave GroupSent by a host when it no longer wants to receive a multicast stream

For example, when thousands of users watch the same live sports broadcast, the network doesn't send thousands of identical copies of the video across every link — IGMP lets routers know exactly which network segments currently have interested viewers, and the stream is replicated only along those paths.

Internet Protocol (IP)

Every protocol discussed so far either supports IP or depends on it. IP (Internet Protocol) is the core protocol of the Network Layer — it defines how packets are addressed and handed off from one router to the next.

IP has three defining characteristics:

It's connectionless. No dedicated end-to-end connection is set up before data is sent. Every packet is addressed and forwarded independently, which also means packets can arrive out of order or take different paths to the same destination.

It offers best-effort delivery. IP tries to deliver every packet, but makes no guarantees about:

  • Successful delivery (a packet can be dropped)
  • Error correction (IP doesn't fix corrupted data)
  • Ordering (packets can arrive in a different sequence than they were sent)

These guarantees, when an application needs them, are provided by a Transport Layer protocol like TCP, not by IP itself.

It provides logical addressing. Every device on a network is given a unique IP address — for example, 192.168.1.1 (IPv4) or 2001:db8::1 (IPv6) — that identifies it independently of its physical hardware.

IP also handles fragmentation and reassembly: when a packet is larger than the maximum size a network link allows (its MTU, or Maximum Transmission Unit), IP splits it into smaller fragments for transmission and reassembles them in the correct order at the destination.

IPv4

IPv4 addresses are 32 bits long, usually written in dotted-decimal form:

192.168.1.1

With 32 bits, IPv4 supports roughly 4.3 billion unique addresses. That sounded like more than enough in the early days of the Internet, but the explosive growth of connected devices — phones, laptops, servers, IoT devices — led to IPv4 address exhaustion, the depletion of the pool of available public addresses. This shortage is one of the main reasons both NAT (below) and IPv6 exist.

IPv6

IPv6 was designed to solve IPv4's exhaustion problem. Its addresses are 128 bits long, written as eight groups of hexadecimal digits:

2001:0db8:85a3:0000:0000:8a2e:0370:7334

128 bits provides an address space large enough to assign unique addresses to a virtually unlimited number of devices — far more than IPv4's 32 bits could ever offer. Beyond the larger address space, IPv6 also brings:

  • More efficient routing, since its header is simpler and more consistently structured than IPv4's
  • Built-in support for devices to self-configure an address without a DHCP server (stateless address autoconfiguration)
  • Security features designed in from the start, rather than added on later as with IPv4 and IPsec

Despite being defined since the late 1990s, IPv6 adoption has been gradual, and most networks today run IPv4 and IPv6 side by side.

DHCP (Dynamic Host Configuration Protocol)

Manually assigning an IP address, subnet mask, default gateway, and DNS server to every device on a network simply doesn't scale. DHCP automates this: when a device joins a network, DHCP assigns it all the configuration it needs to communicate.

DHCP typically provides:

  • An IP address
  • The subnet mask
  • The default gateway
  • One or more DNS server addresses

The DHCP DORA process

DHCP assigns an address through a four-step exchange, usually remembered by the acronym DORA:

StepNameWhat happens
DDiscoverThe client broadcasts a request looking for any DHCP server on the network
OOfferA DHCP server responds, offering an available IP address and configuration
RRequestThe client formally requests the offered address (this also handles the case where more than one server made an offer)
AAcknowledgmentThe server confirms the assignment, and the client begins using the address

Because DHCP automates configuration, it reduces manual errors, eliminates duplicate IP address conflicts, and makes it practical to manage networks with hundreds or thousands of devices.

NAT (Network Address Translation)

Because public IPv4 addresses are limited, most home and office networks use private IP addresses internally (such as the 192.168.x.x range) and rely on a router to translate them to a single public address when talking to the Internet. That translation is done by NAT.

For example, a home network might have:

  • Laptop — 192.168.1.2
  • Phone — 192.168.1.3
  • Smart TV — 192.168.1.4

All three devices share a single public IP address assigned by the ISP. NAT keeps track of which internal device each outgoing connection belongs to, so replies are routed back to the correct device.

Types of NAT

TypeMapping
Static NATOne private IP address is permanently mapped to one public IP address
Dynamic NATMany private IP addresses share a pool of public IP addresses, assigned as needed
PAT (Port Address Translation), also called NAT OverloadMany private IP addresses share a single public IP address, distinguished by different port numbers

PAT is by far the most common form in home and small-office routers, since it allows an entire household's worth of devices to share one public IP address at the same time.

Routing Protocols: OSPF, RIP, and BGP

IP gets a packet addressed correctly, but something still has to decide which path that packet takes across a network of routers. That's the job of routing protocols. They fall into two broad categories: protocols used within an organization's own network (interior routing) and the protocol used between independent networks on the Internet (exterior routing).

OSPF (Open Shortest Path First)

OSPF is a link-state routing protocol commonly used inside medium to large organizations. Rather than just trusting what neighboring routers tell it, every OSPF router builds a complete map of the network's topology and independently calculates the shortest path to every destination using Dijkstra's shortest-path algorithm.

Key characteristics:

  • Link-state design — every router maintains detailed knowledge of the full network topology, not just what its direct neighbors report
  • Hierarchical structure — large networks are divided into areas to limit how much topology information each router needs to track, improving scalability
  • Fast convergence — when the topology changes (a link fails, for example), OSPF routers recalculate routes quickly
  • Authentication support — routing updates can be authenticated to prevent a rogue device from injecting false routes

RIP (Routing Information Protocol)

RIP is one of the oldest routing protocols still in use and uses a simpler, distance-vector approach: each router periodically shares its entire routing table with its direct neighbors, and routes are chosen based on the hop count (the number of routers a packet must pass through).

  • Maximum hop count is 15 — a destination 16 hops away is considered unreachable
  • Simple to configure and understand
  • Not suitable for large networks, because it converges slowly after a topology change and its 15-hop limit caps how large a network it can route for

BGP (Border Gateway Protocol)

While OSPF and RIP operate inside a single organization's network, BGP is the protocol that connects those networks to each other — it is the routing protocol that holds the Internet together. BGP exchanges routing information between Autonomous Systems (AS) — independently administered networks, typically run by ISPs, large enterprises, or cloud providers.

  • Path-vector protocol — routes are chosen based on the sequence (path) of Autonomous Systems a packet would cross, not just a simple metric like hop count
  • Inter-domain routing — it is specifically designed to connect separate organizations and ISPs, unlike OSPF or RIP which route within one
  • Policy-based decisions — an AS can choose routes based on business agreements and policy, not purely on "shortest" path, since different providers have different peering and transit arrangements

When your traffic crosses from your ISP to another network on the way to a distant server, BGP is what decided that path.

Comparing the three

ProtocolScopeAlgorithm typeTypical use
RIPInteriorDistance-vector (hop count)Small, simple networks
OSPFInteriorLink-state (Dijkstra)Medium to large organizational networks
BGPExteriorPath-vectorRouting between ISPs and organizations across the Internet

MPLS (Multiprotocol Label Switching)

Traditional IP routing requires every router along a path to examine a packet's destination IP address and look up the best next hop — on every single hop. MPLS speeds this up by attaching a short label to each packet at the edge of the network. Interior routers then forward the packet by reading this label instead of re-examining the full IP header at every hop, following a predetermined Label Switched Path (LSP).

Because MPLS sits between the Data Link Layer and the Network Layer, performing label-based forwarding rather than full IP routing at each hop, it's often described as operating at "Layer 2.5."

MPLS is widely used by ISPs and large enterprises for:

  • Faster forwarding — label lookups are simpler and faster than full routing-table lookups
  • Quality of Service (QoS) — latency-sensitive traffic such as voice calls and video conferencing can be prioritized over a predefined path
  • Traffic engineering — network operators can control exactly which paths specific traffic takes, improving overall bandwidth utilization
  • VPN support — MPLS underlies many enterprise-grade VPN services that need predictable performance

IPsec (Internet Protocol Security)

Everything covered so far addresses getting packets from one place to another — none of it, by default, protects the contents of those packets. IPsec is a suite of protocols that adds security directly at the Network Layer, protecting IP traffic regardless of which application generated it.

IPsec provides:

  • Authentication — verifying that a packet really came from the sender it claims to be from
  • Encryption — scrambling packet contents so they can't be read if intercepted
  • Data integrity — detecting if a packet was altered in transit

Because it operates at the IP layer rather than within a specific application, IPsec is widely used to build VPNs (Virtual Private Networks), allowing two sites or a remote user to exchange traffic over the public Internet with the confidentiality, integrity, and authentication of a private link.

Putting It Together

A single web request on an ordinary home network might touch nearly every protocol in this lesson: DHCP assigned your device its IP configuration when it joined the Wi-Fi; ARP resolved your router's MAC address; NAT translated your private IP to your ISP's public IP; IP addressed and routed the packet; RIP, OSPF, or BGP determined the path it took across networks; and ICMP would report back if something along the way failed. Multicast and MPLS come into play for specific use cases like live streaming or carrier-grade networks, while IPsec adds protection when the traffic needs to stay confidential.

Understanding each protocol's specific job — rather than treating "the Network Layer" as one single thing — is what makes it possible to diagnose real networking problems: a failed ping points you toward ICMP and routing, a misconfigured address points you toward DHCP or NAT, and a security requirement points you toward IPsec.

0 Comments

Reviewed before they appear

No comments yet.

Computer-Network
Ask about this post
AI Ask about this post

Ask questions about Network Layer Protocols and get answers drawn from it.

Signed-in readers only.