MAC Address vs IP Address: Hardware Identity vs Network Location

Overview A MAC address is a hardware identifier burned into a network interface card and used to move frames across a single local link. An IP address is a logical network address assigned to a device and used to route packets across interconnected networks, including the internet. They operate at different OSI layers, working together to get data from one physical wire to a destination anywhere in the world. Comparison Diagram Host AIP 10.0.0.5Routerrewrites MAC per hopHost BIP 10.0.0.9MAC AA:01 to MAC RR:01MAC RR:02 to MAC BB:01Layer 2 - MAC changes at every hopIP 10.0.0.5 to 10.0.0.9Layer 3 - IP stays constant end-to-endMAC = local hop identity; IP = end-to-end address Comparison Table Aspect MAC Address IP Address OSI layer Layer 2 (Data Link) Layer 3 (Network) Format 48-bit hex, e.g. 00:1A:2B:3C:4D:5E 32-bit (IPv4) or 128-bit (IPv6) dotted/colon notation Assignment Burned in by the NIC manufacturer at production Assigned by a network admin or DHCP server Structure Flat, no hierarchy — vendor prefix plus serial Hierarchical — network portion plus host portion for routing Persistence Fixed to the physical interface (though spoofable) Can change when a device moves to a different network Role in delivery Identifies the next-hop device on the local link Identifies source and destination across the whole path Behavior across hops Rewritten by every router at each hop Preserved end-to-end (barring NAT) Resolution mechanism Discovered via ARP (IPv4) or NDP (IPv6) Discovered via DNS for hostnames Key Differences MAC address operates at Layer 2 while IP address operates at Layer 3. MAC is burned into hardware by the manufacturer, whereas IP is assigned by the network. A frame’s MAC addresses are rewritten at every hop, but the packet’s IP addresses stay end-to-end constant. ARP maps an IP address to the MAC address needed for delivery on the local segment. MAC addresses are flat with no structure, while IP addresses are hierarchical to support routing. When to Use Each MAC Address ...

August 1, 2026 · 3 min · 440 words · jeonck

Ping vs Traceroute: Testing Reachability vs Mapping the Path

Overview Ping and Traceroute are both ICMP-based diagnostic tools, but they answer different questions: ping tests reachability between two hosts, while traceroute reveals the path packets take to get there. Ping reports simple round-trip latency and packet loss; traceroute manipulates TTL values to map every router hop along the route. Comparison Diagram PINGTRACEROUTEClientServerEcho RequestEcho ReplyOne round trip → RTT to destinationClientR1R2R3SrvTTL=1TTL=2TTL=3TTL=4Time Exceeded replyEach probe's TTL expires one hop further Comparison Table Aspect Ping Traceroute Primary purpose Tests whether a host is reachable and measures round-trip latency Maps the sequence of routers (hops) a packet crosses to reach a host Underlying mechanism Sends an ICMP Echo Request and waits for an ICMP Echo Reply Sends probes with incrementing TTL, capturing an ICMP Time Exceeded from each hop TTL handling Uses a fixed, generous TTL (OS default, e.g. 64 or 128) meant to survive the whole path Deliberately starts TTL at 1 and increments it per probe to force expiry at each hop Who responds Only the final destination host replies Every intermediate router along the path replies, plus the destination Output produced Single or repeated RTT values and a packet loss percentage Ordered list of hop addresses with per-hop RTT samples Interpreting failure No reply means unreachable or blocked, without saying where A missing hop reply pinpoints exactly where the path breaks or gets filtered Typical runtime Fast, usually sub-second to a few seconds for a handful of probes Slower, since it waits on timeouts at each hop before moving to the next Common blocking issues Firewalls dropping ICMP Echo hide the host entirely, showing total silence Firewalls dropping Time Exceeded or Echo hide specific hops, shown as * * * Key Differences Ping only confirms reachability to the final host and reports nothing about the path in between. Traceroute exploits TTL expiry to make each router along the route reveal itself. A ping reply comes from the destination alone; traceroute yields one reply per hop. Traceroute is inherently slower since it waits on timeouts at every intermediate router, not just the endpoint. When ICMP is filtered, ping just times out, while traceroute pinpoints the exact blackhole hop. When to Use Each Ping ...

August 1, 2026 · 3 min · 459 words · jeonck

Static Routing vs Dynamic Routing: Manual Paths vs Self-Adapting Networks

Overview Static routing means an administrator manually enters every route into a router’s table, while dynamic routing lets routers automatically discover and adjust paths using a routing protocol. The choice comes down to a tradeoff between precise manual control and automatic adaptation to network changes. Comparison Diagram Static RoutingDynamic RoutingAdmin sets a fixed pathRouters exchange updatesABABCLink A-B failsLink A-B failsABTraffic still sent - blackholedABCAuto-reroutes via C Comparison Table Aspect Static Routing Dynamic Routing Configuration Manually entered by an administrator on each router Learned automatically through a routing protocol (OSPF, EIGRP, BGP, etc.) Path determination Fixed path defined once by the admin; never recalculated Computed algorithmically from real-time topology and link metrics Reaction to link/topology change No detection; route stays configured even if the path is down Protocol detects the failure and recalculates automatically Convergence time Instant to apply, but requires manual intervention to correct Seconds to minutes depending on protocol, then self-healing Resource overhead None - no CPU or bandwidth spent on updates Ongoing CPU for computation and bandwidth for update messages Scalability Impractical beyond a small, stable topology Scales to large, frequently changing networks Administrative control Exact, fully predictable path enforced by the admin Path chosen by the protocol based on metrics and policy, less predictable Key Differences Static routes are entered by hand; dynamic routes are learned via a routing protocol. Static routing has zero ongoing CPU and bandwidth cost; dynamic routing continuously spends both on updates. Only dynamic routing performs automatic failover when a link goes down. Static routing gives exact predictable paths; dynamic routing adapts them based on live metrics. Static doesn’t scale past a handful of routers; dynamic routing is required for large networks. When to Use Each Static Routing ...

August 1, 2026 · 3 min · 444 words · jeonck

OSI Model vs TCP/IP Model: 7 Conceptual Layers vs 4 Practical Layers

Overview The OSI Model is a conceptual seven-layer framework that ISO designed to standardize how network communication should be described, while the TCP/IP Model is the four-layer protocol suite that actually powers the internet. Real devices implement TCP/IP directly, but engineers still borrow OSI’s vocabulary to reason about and troubleshoot problems layer by layer. Comparison Diagram OSI ModelTCP/IP Model7. Application6. Presentation5. Session4. Transport3. Network2. Data Link1. PhysicalApplicationTransportInternetNetwork Access Comparison Table Aspect OSI Model TCP/IP Model Purpose Theoretical reference model for describing how network communication should work Practical protocol suite that actually runs the internet Layer count 7 layers 4 layers (sometimes taught as 5) Layer structure Application, Presentation, Session, Transport, Network, Data Link, Physical Application, Transport, Internet, Network Access Development origin Designed by ISO in the late 1970s/80s before matching protocols existed Grew out of DARPA’s ARPANET; protocols came first, the model was described afterward Protocol coupling Layers defined independently of any specific protocol Layers map directly onto real protocols like IP, TCP, and HTTP Encapsulation granularity Splits presentation and session concerns into their own distinct layers Folds presentation and session functions into the single Application layer Real-world adoption Rarely implemented exactly as specified; used mainly as a teaching and reference framework Implemented in essentially every networked device and across the internet Troubleshooting use Provides layer-by-layer vocabulary for isolating where a problem occurs Maps directly to the tools and protocols engineers actually configure and debug Key Differences OSI has seven layers while TCP/IP condenses the same concerns into four layers OSI is a theoretical reference model; TCP/IP is the actual protocol suite running the internet OSI separates Session and Presentation into distinct layers; TCP/IP merges them into one Application layer TCP/IP’s protocols were built first and the model described them afterward, while OSI’s layers were designed before implementation When to Use Each OSI Model ...

August 1, 2026 · 2 min · 415 words · jeonck

Unicast vs Multicast: One-to-One vs One-to-Many Delivery

Overview Unicast and multicast are IP transmission models that differ in how a sender’s data reaches its destinations. Unicast sends a dedicated copy to each individual recipient, while multicast sends a single stream that network devices replicate only where delivery paths actually diverge. The choice shapes bandwidth usage, routing complexity, and how receivers subscribe to traffic. Comparison Diagram UnicastMulticastSenderR1R2R33 separate packet copiessent end-to-endSenderR1R2R3single stream, replicatedonly at the branch point Comparison Table Aspect Unicast Multicast Addressing model One-to-one; packet is addressed to a single destination IP One-to-many; packet is addressed to a shared multicast group IP Sender behavior Sends a separate copy of the data for each recipient Sends one copy regardless of how many receivers exist Network replication No replication; each copy travels its own end-to-end path Routers/switches replicate the packet only at points where paths diverge Receiver participation Implicit; determined solely by the destination address Explicit; hosts must join the group (IGMP/MLD membership) Bandwidth scaling Grows linearly with the number of receivers Stays roughly constant on the sender’s link as receivers grow Routing requirements Standard unicast routing (OSPF, BGP, static routes) Requires multicast-aware routing (PIM-SM/DM plus IGMP) Delivery reliability Can run over TCP for guaranteed, ordered delivery Almost always UDP-based, with no built-in delivery guarantee Typical use cases Web browsing, file transfer, email, SSH Live video/audio streaming, market data feeds, routing protocol updates Key Differences Unicast requires a separate packet copy per receiver; multicast needs only one. Multicast pushes replication into the network fabric instead of the sender. Multicast receivers must explicitly join a group via IGMP before traffic arrives. Unicast bandwidth scales linearly with recipients; multicast stays flat. Multicast typically rides over UDP, sacrificing delivery guarantees for efficiency. When to Use Each Unicast ...

August 1, 2026 · 2 min · 390 words · jeonck

Subnet vs VLAN: Layer 3 IP Segmentation vs Layer 2 Port Segmentation

Overview A subnet and a VLAN both carve a large network into smaller, more manageable pieces, but they operate at different layers and are configured in different places. A subnet divides IP address space at Layer 3 based on address range and mask, independent of physical wiring, while a VLAN divides switch ports at Layer 2, creating separate broadcast domains on shared physical hardware. In most enterprise designs the two are paired one-to-one, but knowing which layer each governs matters for troubleshooting, security, and scaling. ...

August 1, 2026 · 3 min · 465 words · jeonck

Switch vs Router: Layer 2 Switching vs Layer 3 Routing

Overview A switch connects devices within a single network by forwarding traffic based on MAC addresses, while a router connects separate networks together by forwarding traffic based on IP addresses. Plugging a device into the wrong one is a common source of confusion — one expands a LAN, the other bridges LANs to each other or to the internet. Comparison Diagram SwitchRouterSingle broadcast domainSwitchPC1PC2PC3Forwards by MAC address10.0.1.0/24PCPCInternetWANRouterForwards by IP address, links networks Comparison Table Aspect Switch Router OSI layer Layer 2 (Data Link) Layer 3 (Network) Addressing used MAC addresses IP addresses Forwarding table MAC address table (CAM table), learned automatically Routing table, built via static routes or routing protocols Broadcast domain Devices share one broadcast domain (unless VLANs are configured) Separates traffic into distinct broadcast domains per interface Typical placement Connects devices within a single LAN segment Connects different networks together, e.g. LAN to LAN or LAN to WAN Unknown-destination handling Floods frame to all ports in the VLAN when MAC is unknown Drops or rejects packets with no matching route Built-in services Basic switching only, plus optional VLANs/QoS on managed models Often includes NAT, DHCP, firewall, and VPN functions Typical device Cisco Catalyst switch in a wiring closet Home router or edge router linking a LAN to an ISP Key Differences Switches forward traffic using MAC addresses at Layer 2, while routers forward using IP addresses at Layer 3. A switch keeps connected devices in one broadcast domain; a router splits traffic into separate domains. Switches flood frames to unknown destinations within a VLAN; routers simply drop packets they can’t route. Routers commonly bundle NAT and firewall features that switches don’t provide. Switches scale port count for a single network; routers scale the number of distinct networks a device can reach. When to Use Each Switch ...

August 1, 2026 · 2 min · 406 words · jeonck

DNS vs DHCP: Naming the Network vs Configuring It

Overview DHCP and DNS are both foundational network services, but they solve different problems in a device’s journey onto the network. DHCP automatically assigns a device its IP address and network configuration when it joins a subnet, while DNS translates human-readable domain names into the IP addresses needed to actually reach other hosts. Comparison Diagram DHCP DNS Client (no IP) DHCP Server DHCPDISCOVER leased IP + gateway local subnet, broadcast Client (has IP) DNS Resolver example.com? 93.184.216.34 global, hierarchical gives device an address gives a name an address Comparison Table Aspect DHCP DNS Primary purpose Assigns an IP address and network configuration to a device Translates a domain name into an IP address Triggered by A device connecting or booting onto the network An application needing to resolve a hostname Transport protocol UDP, ports 67 (server) and 68 (client) UDP or TCP, port 53 Discovery mechanism Client broadcasts DHCPDISCOVER on the local subnet Client sends a unicast query to a configured resolver address Data returned IP address, subnet mask, default gateway, DNS server list IP address (A/AAAA record) or other record types like MX, CNAME, TXT State and validity Lease with an expiration time that must be renewed Record with a TTL, cached locally then re-queried after expiry Scope Local network segment or subnet Global, hierarchical, distributed across the internet Key Differences DHCP assigns IP addresses to devices; DNS resolves domain names to those addresses. DHCP requests use broadcast discovery on the local subnet; DNS clients send unicast queries to a configured resolver. DHCP assignments are leases that expire and renew; DNS answers are cached per record TTL. DHCP typically hands out the DNS server addresses a client should use, linking the two protocols at boot time. When to Use Each DHCP ...

August 1, 2026 · 2 min · 412 words · jeonck

IPv4 vs IPv6: 32-bit vs 128-bit Addressing

Overview IPv4 and IPv6 are the two versions of the Internet Protocol responsible for addressing and routing packets across networks. IPv4 relies on 32-bit addresses that ran out of unique combinations, while IPv6 was designed around 128-bit addresses to give every device a globally unique, non-NAT’d address. The distinction matters because it affects address exhaustion, header processing overhead, and whether NAT traversal is required for peer-to-peer connectivity. Comparison Diagram IPv4IPv61921681132 bits · dotted-decimal20010db885a3000000008a2e03707334128 bits · hex colon-notation~4.3 billion addresses~340 undecillion addressesRelative address length32 bits (IPv4)128 bits (IPv6) — 4x longerNAT dependencyIPv4: needs NAT (scarce space)IPv6: end-to-end, no NAT needed Comparison Table Aspect IPv4 IPv6 Address length & notation 32-bit, dotted-decimal (e.g. 192.168.1.1) 128-bit, hexadecimal colon-separated (e.g. 2001:0db8::7334) Address space size ~4.3 billion addresses ~340 undecillion addresses Address assignment Manual configuration or DHCP Stateless Address Autoconfiguration (SLAAC) or DHCPv6 Header structure Variable-length header with options field and checksum Fixed 40-byte header, no checksum, optional extension headers NAT requirement Commonly required due to address scarcity Not needed; supports true end-to-end addressing Broadcast/discovery Uses broadcast (e.g. ARP) for local discovery Broadcast eliminated; uses multicast Neighbor Discovery Built-in security IPsec is an optional add-on IPsec support is part of the core protocol spec Adoption & compatibility Universally supported, legacy infrastructure Growing adoption, requires dual-stack or tunneling for legacy interop Key Differences IPv6 addresses are 128-bit, four times longer than IPv4’s 32-bit addresses, resolving address exhaustion IPv6 removes the need for NAT, restoring true end-to-end connectivity between hosts IPv6 uses a simplified, fixed-length header that speeds up router processing compared to IPv4’s variable header IPv6 replaces ARP broadcasts with Neighbor Discovery multicast for local address resolution When to Use Each IPv4 ...

August 1, 2026 · 2 min · 391 words · jeonck

HTTP/2 vs HTTP/3: Multiplexing Over TCP vs QUIC

Overview HTTP/2 and HTTP/3 both let a browser send many requests over one logical connection, but they diverge at the transport layer. HTTP/2 rides on TCP, inheriting its single ordered byte stream and its packet-loss stalls; HTTP/3 replaces that with QUIC over UDP, giving each stream independent loss recovery and letting connections survive network changes. Comparison Diagram HTTP/2 (TCP)HTTP/3 (QUIC/UDP)Stream AStream BStream CStream AStream BStream CSingle TCP connectionOne lost packet stalls every streamIndependent QUIC streamsLoss stalls only its own streamX = lost packet dashed = blocked/waiting Comparison Table Aspect HTTP/2 HTTP/3 Transport protocol Runs over TCP Runs over QUIC (built on UDP) Connection handshake Separate TCP handshake, then TLS handshake (1-2 RTT) TLS 1.3 is integrated into the QUIC handshake, often 1-RTT or 0-RTT on resumption Stream multiplexing Multiple streams share one ordered TCP byte stream Each stream is a distinct, independently-sequenced QUIC stream Head-of-line blocking A single lost TCP segment stalls delivery of every stream until it’s retransmitted Loss on one stream only stalls that stream; others keep flowing Header compression HPACK QPACK Connection identity and migration Bound to the source/destination IP and port 4-tuple; changing networks breaks it Bound to a connection ID; survives IP or network changes, e.g. Wi-Fi to cellular Congestion control and loss recovery Implemented in the OS kernel’s TCP stack Implemented in user-space by the QUIC library, easier to iterate on Network and middlebox support Ubiquitous; TCP port 443 is rarely blocked UDP is sometimes blocked or throttled by firewalls, requiring a TCP fallback Key Differences HTTP/2 multiplexes streams inside a single TCP connection, while HTTP/3 gives each stream its own loss-recovery in QUIC TCP’s in-order delivery means one dropped packet causes head-of-line blocking across all HTTP/2 streams; HTTP/3 avoids this by design HTTP/3 folds the transport and TLS handshakes together for faster 0-RTT setup on reconnection QUIC’s connection ID lets HTTP/3 sessions survive a client’s IP or network change without reconnecting HTTP/3 depends on UDP reaching the server, so restrictive middleboxes can force a fallback to HTTP/2 When to Use Each HTTP/2 ...

August 1, 2026 · 3 min · 445 words · jeonck