Recently I’ve been doing some operations on IP packets. When packets pass through switches, they are mirrored and then sent to an analysis server. These mirrored packets actually represent the path they traveled; they can be used to judge whether a loop or packet loss occurred.
Today’s group meeting discussed the ordering problem of these packets. Even though the mirroring times have an order, when the packets reach the analysis server the order becomes different, so the path cannot be reconstructed. Packet loss and loops can be detected, but only at a coarse granularity — we can only learn whether there is packet loss somewhere on the path.
Afterwards I proposed a partially feasible solution: sort by the TTL of different packets, because a packet’s
TTL decreases by one after passing through a switch. Below is an IPv4 header structure, in which Time to Live is the commonly mentioned
TTL; IPv6 has a similar field called Hop Limit. For details see TCP/IP protocol headers
and IPv4 and IPv6 packet formats.
1 | 0 1 2 3 |
Why only partially feasible? Because layer-2 switches do not modify the TTL.
Layer-2 switching, routing and layer-3 switching introduces the related issues.
A packet’s TTL only changes when it passes through a layer-3 switch with routing functionality. The article also explains the differences among the three.
For a layer-2 switch, MAC addresses are mapped to its hardware ports. If a packet’s destination MAC address is a MAC address in the address table, it will be sent to the corresponding port. See the learning process of layer-2 switches.