A fresh start.
Not from scratch.
You’ve done this before. Give yourself room to remember.
sessions completed
Follow a packet
Read it once. Try it yourself. Explain it without notes.
Start with the path you already know: application → transport → IP → Ethernet. IP addresses identify endpoints across networks; MAC addresses deliver frames on the local link. For a remote destination, your host sends a frame to its gateway. Each router replaces link-layer headers while forwarding the IP packet. NAT, when present, can change IP addresses and ports.
Example: your laptop is 192.168.1.20/24; its gateway is 192.168.1.1. To contact 93.184.215.14, the laptop keeps 93.184.215.14 as the destination IP but first looks up the gateway’s MAC. The Ethernet frame goes to that MAC. The router receives the frame, consults its route table, then puts the packet in a new link-layer frame for the next hop.
- 01
Write four boxes on paper: your laptop, default gateway, DNS resolver, website. Mark what each box knows before the request.
- 02
On Windows run
ipconfig /all,route print,arp -a; on Linux runip -br addr,ip route,ip neigh. Find your local IP/prefix and default gateway. Ifipis unavailable, useifconfigor your network settings. - 03
Run
nslookup example.comordig example.com. Record the resolver and returned address. DNS gives an address; it does not deliver the page. - 04
Open Wireshark on the active interface. Set display filter
dns or tcp.port == 443. Visithttps://example.comin a new tab. Find the DNS exchange, then a TCP SYN/SYN-ACK/ACK to one returned IP. - 05
Return to your diagram. For the first packet to a remote IP, label destination IP and destination MAC separately. Say aloud which one changes at each router and why.
You should find a default route via your gateway. The DNS response should contain at least one address (often IPv4 and/or IPv6). A normal TCP connection usually begins with SYN, SYN-ACK, ACK; HTTPS follows. DNS or browser caches can remove packets you expected.
Stuck or seeing something else?
No DNS packet? Flush only your lab/browser cache or query a new hostname, and confirm you captured the active interface. No SYN? The browser may reuse a connection, choose IPv6, use HTTP/3 over UDP 443, or use a proxy. Use `curl -vI https://example.com` for a separate request and widen the filter to `dns or tcp or udp.port == 443`. Do not guess from a blank capture.
Check all four steps when you have actually done them.