Ethernet II
The frame that carries everything on a local network: MACs, a type, a payload.
The header
A real frame from a laptop to its router, carrying an IPv4 packet.
Whole frame
Fourteen bytes of header and the frame can cross a switch: where it goes, who sent it, and what is inside. Everything else is payload.
| Field | Offset | Example value | Meaning |
|---|---|---|---|
| Destination MAC | Byte 0–5 | 00:1A:2B:3C:4D:5E (router) | Who should pick this frame up on the local network. Here it is the router. A MAC address is 6 bytes. The first three identify the manufacturer (OUI); the lowest bit of the first byte means 'group address' (multicast/broadcast); the next bit means 'locally administered'. |
| Source MAC | Byte 6–11 | 3C:22:FB:AA:01:20 (laptop) | The sender's own hardware address. Switches learn from this field which port each MAC lives on. |
| EtherType | Byte 12–13 | 0x0800 = IPv4 | What the payload contains, so the receiver knows which protocol to hand it to. 0x0800 IPv4, 0x0806 ARP, 0x86DD IPv6, 0x8100 a VLAN tag follows. Values below 0x0600 are lengths in the older 802.3 format. |
| Payload (start) | Byte 14–19 | 45 00 00 2C 1C 46 ... | Here an IPv4 packet starts: 0x45 means version 4, header length 5 words. The payload runs 46 to 1500 bytes, then a 4-byte checksum (FCS) follows. |
Overview
Ethernet is the link layer of almost every wired LAN. A frame has a 14-byte header (destination MAC, source MAC, EtherType), a payload of 46–1500 bytes, and a 4-byte checksum. Addresses are only meaningful on the local segment: routers rewrite them at every hop.
The 1500-byte payload limit is the famous MTU. IP packets larger than that must be split (fragmented) or never sent in the first place.
Key facts
- Address
- 48-bit MAC
- Header
- 14 bytes
- Payload
- 46 – 1500 bytes (MTU)
- Checksum
- FCS, CRC-32
- Max frame
- 1518 bytes (1522 with VLAN)
- Byte order
- Big-endian fields; bits LSB first
Everything on the wire
The same layer with its lead-in, padding and a computed FCS. The payload is an ARP request.
Whole frame
8 bytes of lead-in, 14 of header, 46 of (padded) payload and 4 of checksum: 72 byte times, about 5.8 microseconds at 100 Mbit/s.
| Field | Offset | Example value | Meaning |
|---|---|---|---|
| Preamble | Byte 0–6 | 55 55 55 55 55 55 55 | Seven bytes of 0x55 (alternating 1 0 1 0 on the wire, since bits go out LSB first). It gives the receiver's clock something to lock onto. Your capture software never sees it: the network card strips it. |
| SFD | Byte 7 | 0xD5 | Start Frame Delimiter 0xD5 (10101011 on the wire): the final 11 says 'the frame starts now'. |
| Destination MAC | Byte 8–13 | FF:FF:FF:FF:FF:FF (broadcast) | All ones: the broadcast address. Every host on the segment must accept it. An ARP request has to be broadcast because the sender does not yet know the target's MAC. |
| Source MAC | Byte 14–19 | 3C:22:FB:AA:01:20 | The asking host. |
| EtherType | Byte 20–21 | 0x0806 = ARP | 0x0806 = ARP. |
| ARP payload | Byte 22–49 | ARP request | The 28-byte ARP request (see the ARP page for every field). |
| Padding | Byte 50–67 | 00 × 18 | Ethernet frames must be at least 64 bytes including FCS, so the 28-byte payload is padded with zeros up to the 46-byte minimum. |
| FCS (CRC-32) | Byte 68–71 | 0x2E453236 | A CRC-32 over destination MAC through padding, computed here for real: 0x2E453236. It is sent low byte first (36 32 45 2E). A switch or NIC that finds a mismatch drops the frame silently. |
Where you meet it
- Every wired LAN, from home routers to data centres
- The base of Wi-Fi's frame format (802.11 reuses the idea) and of Power over Ethernet
- Industrial Ethernet: EtherCAT, PROFINET, EtherNet/IP
Watch out for
- The FCS is checked by hardware and usually stripped before you see the frame, so packet captures normally have no FCS and no preamble.
- MACs identify a hop, not a host across the internet. The destination MAC of a packet going to the internet is your router's, not the server's.
- A mismatched MTU (for example with a VPN or PPPoE) makes large packets disappear while small ones work.
Standards
- IEEE 802.3 (Ethernet)
- DIX Ethernet II