WEBVTT

00:00:00.000 --> 00:00:03.700
Welcome back to CSE 316 — Data Communication and Networking.

00:00:03.750 --> 00:00:09.380
This is the detailed video version of Session twenty, and it finishes the addressing arc.

00:00:09.430 --> 00:00:18.380
Last session gave you a hundred and twenty-eight bits and two rules for writing them down. This session answers a question that sounds impossible: where does the address actually come from?

00:00:26.510 --> 00:00:35.460
A brand-new laptop joins a network. No IT department, no DHCP server, nobody typing anything. Thirty seconds later it has a working IPv6 address — correct, unique and routable.

00:00:38.960 --> 00:00:46.720
Three jobs. First, EUI-64: split, stuff, flip — three steps, one of which is a flip and not a set, including flipping downward.

00:00:46.770 --> 00:00:55.720
Second, the packet that got simpler. And third, the debt from last session — why twenty-five years, and why the villain turns out to be a word from Session seventeen.

00:01:02.089 --> 00:01:08.709
The question, and there are two half-answers worth having in your head first.

00:01:08.759 --> 00:01:15.099
Fresh laptop, fresh network. No IT department, no DHCP server, nobody typed anything.

00:01:15.149 --> 00:01:23.379
Thirty seconds later it has a working IPv6 address — correct, unique and routable. Where did that address come from?

00:01:23.429 --> 00:01:32.379
And keep the older debt in view: Session nineteen still owes you the reason this protocol has taken twenty-five years to conquer the world. Both bills get paid before the end of this video.

00:01:36.239 --> 00:01:40.299
Guess one, and it is worth saying out loud: it is random.

00:01:40.349 --> 00:01:49.299
Half right. Something in the machine really does invent part of the address without asking anybody. But it is not random — the part it invents has been sitting inside the hardware since the factory.

00:01:53.079 --> 00:01:56.709
Guess two: the router assigns it. Also half right.

00:01:56.759 --> 00:02:05.709
A router really is involved, and it really does supply half the answer. But it assigns nothing to anybody — it announces, and the host does the arithmetic itself.

00:02:07.559 --> 00:02:16.509
Two guesses, each exactly half of the truth. The address is a handshake between hardware and network.

00:02:17.489 --> 00:02:21.059
Section one. Where the right half comes from.

00:02:21.109 --> 00:02:30.059
An address needs two halves — and one of them the machine can manufacture out of a number it has owned since it left the factory.

00:02:33.185 --> 00:02:37.905
Four rows, and the whole session follows from the third one.

00:02:37.955 --> 00:02:46.025
Last session's structure. Sixty-four bits of prefix — site plus subnet — and sixty-four bits of interface ID.

00:02:46.075 --> 00:02:53.695
The left half says which network. The right half says which machine on that network.

00:02:53.745 --> 00:03:02.695
In IPv4, somebody had to give you everything: a network manager typing, or a DHCP server leasing. Either way, a second party had to be present and working.

00:03:06.145 --> 00:03:13.885
Now the observation. The right sixty-four bits must be unique on the LAN — and the machine already OWNS a globally unique number.

00:03:13.935 --> 00:03:20.665
It has been burned into its network card since the factory. Week four. The MAC address.

00:03:20.715 --> 00:03:29.585
And the left sixty-four bits only the local router knows — which site this is, which subnet. So that half has to arrive from the network.

00:03:29.635 --> 00:03:38.585
But arriving is not the same as being configured. Nobody touches the host. Split the problem in two, and only one half needs anybody else at all.

00:03:42.536 --> 00:03:45.676
Three rows on the raw material.

00:03:45.726 --> 00:03:53.526
The MAC address is unique everywhere and forty-eight bits long. Week four's address, burned in by the manufacturer.

00:03:53.576 --> 00:04:02.526
No two cards on Earth were ever meant to share one — and the first three bytes name the manufacturer, while the last three are that manufacturer's serial number.

00:04:04.386 --> 00:04:09.326
The interface ID must be unique on the LAN and sixty-four bits long.

00:04:09.376 --> 00:04:18.326
So the MAC supplies the uniqueness for free, and falls exactly sixteen bits short on length. The whole of EUI-64 is a recipe for those sixteen bits — plus one strange extra step.

00:04:23.906 --> 00:04:27.426
And that is a much smaller problem than inventing an identity.

00:04:27.476 --> 00:04:36.426
A machine cannot invent a unique number out of nothing without asking somebody. It can stretch one it already holds without asking anybody at all.

00:04:37.686 --> 00:04:46.636
EUI-64 stands for Extended Unique Identifier, sixty-four bits. The name is the specification: take a unique identifier, and extend it.

00:04:51.189 --> 00:05:00.139
Five rows, and this is the conversion you will be examined on. Write it down as we go — do not just watch it.

00:05:01.519 --> 00:05:10.469
The input: MAC F-five, A-nine, twenty-three, fourteen, seven-A, D-two. Forty-eight bits, six bytes.

00:05:10.629 --> 00:05:19.579
The target is sixty-four bits, eight bytes. Sixteen bits short, and every step below is about that gap.

00:05:21.689 --> 00:05:29.149
Step one, split. Cut the MAC dead centre: F5-A9-23 on the left, 14-7A-D2 on the right.

00:05:29.199 --> 00:05:38.149
Why the middle? So that both halves of the original MAC stay readable inside the finished identifier.

00:05:38.279 --> 00:05:43.719
Step two, stuff. Push F-F, F-E into the gap: F5-A9-23-FF-FE-14-7A-D2.

00:05:43.769 --> 00:05:52.719
Forty-eight plus sixteen is sixty-four. And F-F-F-E is a reserved marker meaning "this identifier grew out of a MAC address" — it is a signature, not padding.

00:05:55.539 --> 00:06:04.489
Step three, flip. Bit seven of the FIRST byte. F5 is one-one-one-one, zero-one-zero-one — so bit seven, counting from the left, is a zero.

00:06:06.579 --> 00:06:15.529
Flip it: one-one-one-one, zero-one-one-one, which is F7. One bit, in one byte, and the identifier is finished.

00:06:16.849 --> 00:06:24.149
The result in colon hex: F-seven-A-nine, twenty-three-F-F, F-E-fourteen, seven-A-D-two.

00:06:24.199 --> 00:06:32.759
And with F-E-eight-zero double-colon in front of it, the machine has a working link-local address — before it has spoken to anyone at all.

00:06:32.809 --> 00:06:41.759
Forouzan Example twenty-two point three. Say it until it is automatic: split, stuff, flip.

00:06:42.877 --> 00:06:48.607
Step three is the one that needs explaining, so here is why it exists.

00:06:48.657 --> 00:06:52.317
Bit seven of the first byte is the universal-local bit.

00:06:52.367 --> 00:07:01.317
In a MAC address, zero means universal — burned in at the factory. One means locally administered — made up by a human, or by a hypervisor handing out addresses to virtual machines.

00:07:06.757 --> 00:07:14.327
EUI-64 inverts that meaning. In an interface ID, a factory-burned address shows up as one instead.

00:07:14.377 --> 00:07:23.327
Local, hand-made identifiers keep their zero — so double-colon-one and double-colon-one-two stay short and honest.

00:07:23.427 --> 00:07:32.377
Which means the rule is flip, not "set to one". A locally administered MAC, whose bit is already one, flips DOWN to zero. A MAC beginning zero-two becomes zero-zero.

00:07:35.387 --> 00:07:42.207
Every published worked example flips upward, so the downward case is the one to practise.

00:07:42.257 --> 00:07:50.057
And that is the test of whether you learned the rule or the example. If your method cannot flip downward, you memorised the example.

00:07:50.107 --> 00:07:59.057
The inversion itself is a deliberate economy: it makes the cheap, short, hand-made identifiers cheap to write. One bit, paying for itself.

00:08:03.110 --> 00:08:06.100
And now the counting ambush.

00:08:06.150 --> 00:08:11.580
Some cards report an eight-byte EUI-64 directly. That input is already sixty-four bits.

00:08:11.630 --> 00:08:20.510
Push F-F-F-E into it and you have built an eighty-bit monster that is not an address at all.

00:08:20.560 --> 00:08:26.420
For an eight-byte input, only the flip applies. Forouzan Example twenty-two point two.

00:08:26.470 --> 00:08:35.420
The recipe is "make it sixty-four bits, then flip" — and if it is already sixty-four bits, the first half of the recipe has nothing to do.

00:08:36.710 --> 00:08:42.380
Bit seven of the FIRST byte. Not bit seven of the whole address, and not of some other byte.

00:08:42.430 --> 00:08:51.380
Write that one byte in binary, count seven places from the left, and change what you land on. It takes four seconds and it is never wrong.

00:08:52.090 --> 00:08:57.900
And the marker is F-F then F-E, in that order. It is a specific reserved pattern.

00:08:57.950 --> 00:09:04.960
Getting the two bytes the wrong way round produces a legal-looking identifier that means something else entirely.

00:09:05.010 --> 00:09:13.960
Count the bytes in the input before you touch anything. Six means split, stuff and flip. Eight means flip alone. That one habit removes two whole classes of error.

00:09:19.830 --> 00:09:28.780
Forty-two seconds. The whole conversion, both traps, the bootstrap and the worked example — and you have already done half of it by hand.

00:09:30.720 --> 00:09:39.670
The two columns: the left half only the router knows, the right half the machine already owns. And underneath, the change — in IPv4 a second party had to supply everything.

00:09:42.970 --> 00:09:51.920
The MAC, six bytes, forty-eight bits — and the counter underneath saying we need sixty-four. That gap is the entire problem.

00:09:52.560 --> 00:10:01.510
Three bytes, a gap, three bytes — and the two orange bytes sliding in. Eight bytes now, sixty-four bits, and the shortfall is gone.

00:10:03.270 --> 00:10:11.140
The binary strip, with the seventh cell picked out. Watch it change from zero to one, and the byte above it change from F5 to F7.

00:10:11.190 --> 00:10:16.520
Then the finished identifier, and F-E-eight-zero glued in front of it.

00:10:16.570 --> 00:10:25.520
The three traps, in red. Zero-two flipping down to zero-zero on the top row; the eighty-bit monster on the second.

00:10:25.570 --> 00:10:34.520
The four moves, which is the next section of this video. Notice the source address on move two — the unspecified address, all zeros.

00:10:35.590 --> 00:10:44.540
And the finished global address, colour-coded: orange from the router, green from the MAC. The address was in the hardware all along.

00:10:47.394 --> 00:10:51.444
Five errors, and not one of them is conceptual.

00:10:51.494 --> 00:10:56.754
Setting bit seven to one, so a MAC beginning zero-two would stay zero-two.

00:10:56.804 --> 00:11:05.754
Flip it. Zero-two flips down to zero-zero, and F5 flips up to F7. The direction depends on what is already there.

00:11:06.484 --> 00:11:09.684
Stuffing F-F-F-E into an eight-byte input, producing eighty bits.

00:11:09.734 --> 00:11:15.974
Count first. Six bytes in means split, stuff and flip. Eight bytes in means flip only.

00:11:16.024 --> 00:11:21.384
Flipping bit seven of the wrong byte, or of the whole address.

00:11:21.434 --> 00:11:28.494
The first byte only. Write it in binary and count seven from the left.

00:11:28.544 --> 00:11:33.564
Splitting the MAC somewhere other than the centre — two bytes and four, say.

00:11:33.614 --> 00:11:40.704
Three and three. The manufacturer half and the serial half, with the marker sitting between them.

00:11:40.754 --> 00:11:47.284
And writing the marker as F-F-F-F, or F-E-F-F. It looks close enough, and it is not.

00:11:47.334 --> 00:11:56.284
F-F then F-E, in that order — a specific reserved pattern, and the reason a reader can tell a derived identifier from a native one.

00:11:56.854 --> 00:12:05.804
Five errors, and every single one is counting. Which is why the fix is always the same: write it down and count.

00:12:06.873 --> 00:12:11.063
Checkpoint one. Pause the video and do these on paper — the conversion does not stick until your own hand has done it.

00:12:11.113 --> 00:12:13.793
One: convert MAC forty-eight, B-D, three-E, eleven, zero-zero, C-five into a sixty-four-bit interface ID.

00:12:13.843 --> 00:12:18.433
Two: a MAC begins with the byte zero-two. What does that byte become, and why?

00:12:18.483 --> 00:12:19.133
Three: a card reports the eight-byte identifier thirty-four, twelve, F-F, F-E, nine-A, B-C, D-E, F-zero. What do you do with it?

00:12:19.183 --> 00:12:20.883
One: split to 48-BD-3E and 11-00-C5, stuff to 48-BD-3E-FF-FE-11-00-C5, then flip bit seven of forty-eight.

00:12:20.933 --> 00:12:21.733
Forty-eight is zero-one-zero-zero, one-zero-zero-zero, so bit seven is a zero; flipped it is zero-one-zero-zero, one-zero-one-zero, which is four-A. The identifier is four-A-B-D, three-E-F-F, F-E-one-one, zero-zero-C-five.

00:12:21.783 --> 00:12:22.683
Two: it becomes zero-zero. Zero-two is zero-zero-zero-zero, zero-zero-one-zero, so bit seven is already one — a locally administered MAC — and flipping it gives all zeros. This is the case that separates "flip" from "set to one".

00:12:22.733 --> 00:12:31.683
Three: only the flip. It is already sixty-four bits, so stuffing would make it eighty. Thirty-four is zero-zero-one-one, zero-one-zero-zero; bit seven is zero, so it becomes zero-zero-one-one, zero-one-one-zero, which is thirty-six — giving three-six-one-two, F-F-F-E, nine-A-B-C, D-E-F-zero.

00:13:59.942 --> 00:14:02.262
Section two. The bootstrap.

00:14:02.312 --> 00:14:11.262
The machine has half an address. Watch it acquire the other half, check its work, and start using the result — without anybody being asked for anything.

00:14:14.201 --> 00:14:19.431
Four moves. Keep it as a story rather than a protocol trace.

00:14:19.481 --> 00:14:25.781
Move one: the host glues F-E-eight-zero double-colon onto its fresh interface ID.

00:14:25.831 --> 00:14:34.781
That is a link-local address, and it is legal on this LAN immediately. Last session's F-E-eight-zero slash ten block, finally explained.

00:14:36.061 --> 00:14:42.601
Move two: duplicate address detection. It asks the LAN, "is anyone already using this?"

00:14:42.651 --> 00:14:50.021
And look carefully at the source address on that question — it is the whole of the next slide.

00:14:50.071 --> 00:14:59.021
Move three: a router solicitation goes out, and a router advertisement comes back carrying the sixty-four-bit prefix — site plus subnet.

00:15:00.331 --> 00:15:07.421
Move four: glue. Prefix plus interface ID, and the machine has a complete, unique, global address.

00:15:07.471 --> 00:15:11.671
No server stored a byte of state, and no human typed anything.

00:15:11.721 --> 00:15:20.671
The router announces rather than assigns. It broadcasts what the prefix is, and every host on the link does its own arithmetic.

00:15:22.501 --> 00:15:29.231
This is the slide where two pieces of last session's trivia turn out to have been prerequisites.

00:15:29.281 --> 00:15:38.231
The host has to ask before it may use the address. That is what duplicate address detection is — a question to the LAN, asked before the candidate address is trusted.

00:15:39.541 --> 00:15:47.381
But a question needs a source address, and the only candidate the host has is the one currently under suspicion.

00:15:47.431 --> 00:15:52.031
So the source is the double colon. All one hundred and twenty-eight bits zero.

00:15:52.081 --> 00:16:01.031
Last session's unspecified address — and now it has a job rather than a definition. It says exactly one thing: I have no address yet.

00:16:02.071 --> 00:16:11.021
And that is why the block exists at all. Two of last session's reserved blocks — the double colon, and F-E-eight-zero slash ten — turn out to be the first two moves of this bootstrap.

00:16:13.801 --> 00:16:21.151
They were not trivia. They were the prerequisites, and you learned them a week early without being told why.

00:16:21.201 --> 00:16:30.151
If the LAN answers, the address is abandoned and the host tries again. If nobody answers, silence is consent, and the address is now real.

00:16:32.557 --> 00:16:35.817
And now the left half of the address.

00:16:35.867 --> 00:16:39.797
A router solicitation is a host saying "is there a router here?"

00:16:39.847 --> 00:16:48.657
And routers also advertise periodically on their own, so a patient host would eventually hear one without asking at all.

00:16:48.707 --> 00:16:55.807
The advertisement carries the sixty-four-bit prefix — site plus subnet, the left half of the address.

00:16:55.857 --> 00:17:01.217
The router is describing the link, not handing out addresses one at a time.

00:17:01.267 --> 00:17:07.097
Which is why no state is stored anywhere. One advertisement serves every host on the link.

00:17:07.147 --> 00:17:15.847
A DHCP server must remember every lease it has granted. A router advertisement remembers nothing at all.

00:17:15.897 --> 00:17:21.617
And DHCPv6 still exists — for networks that WANT central control, for logging, for policy.

00:17:21.667 --> 00:17:30.307
It is now a choice rather than a necessity. That is the real change: the default stopped requiring a server.

00:17:30.357 --> 00:17:39.307
Write down the phrase "announced, not assigned". It is the whole difference between this and DHCP, and it is where the state disappears.

00:17:43.517 --> 00:17:52.467
The address factory. It runs the conversion one step at a time, and it shows its working — which is exactly what you have to do on paper.

00:17:53.977 --> 00:18:02.927
State one: the six bytes, the first three labelled manufacturer and the last three serial — and the counter underneath, forty-eight in, sixty-four needed.

00:18:05.607 --> 00:18:14.557
State two: the dashed red cut, exactly between bytes three and four. Three bytes each side, and the labels change to left half and right half.

00:18:16.977 --> 00:18:25.927
State three: the two orange bytes have arrived, and there are now eight cells. Read the line underneath — forty-eight plus sixteen equals sixty-four, with a tick.

00:18:30.617 --> 00:18:39.567
State four is the one to watch twice. The first byte is picked out in orange, and underneath it the eight bits with the seventh highlighted.

00:18:40.817 --> 00:18:49.767
Count along with the demo. One, two, three, four, five, six, seven — and there is the zero that changes.

00:18:50.347 --> 00:18:58.367
State five: the bit has gone green and become a one, the byte above has become F7, and the finished identifier appears.

00:18:58.417 --> 00:19:06.557
Then F-E-eight-zero double-colon in front of it. That is a working link-local address, and nothing has been asked of anybody.

00:19:06.607 --> 00:19:13.467
State six puts both traps side by side. Zero-two flipping down to zero-zero on the left; the eighty-bit monster on the right.

00:19:13.517 --> 00:19:22.307
The paragraph underneath is the "why" — EUI-64 inverts the convention so that short hand-made identifiers stay short.

00:19:22.357 --> 00:19:30.237
And state seven assembles the lot: orange from the router, green from the MAC, and the subnet ID in grey between them.

00:19:30.287 --> 00:19:39.237
Open it yourself and type in your own machine's MAC. If what your operating system reports does not match, that is not the demo failing — it is your OS choosing a random identifier instead, for privacy. Work out why that is a good idea.

00:19:48.271 --> 00:19:54.691
Forouzan's Example twenty-two point four. Try to call each line before the reveal.

00:19:54.741 --> 00:20:02.231
An organisation holds the block two-thousand colon one-four-five-six colon two-four-seven-four, slash forty-eight.

00:20:02.281 --> 00:20:08.201
A computer with MAC F5-A9-23-14-7A-D2 joins the THIRD subnet. What is its global unicast address?

00:20:08.251 --> 00:20:17.201
Step one, the interface ID. Split, stuff, flip on that MAC gives F-seven-A-nine, twenty-three-F-F, F-E-fourteen, seven-A-D-two.

00:20:19.471 --> 00:20:25.481
That came from hardware the machine has owned since the factory. Nobody was consulted.

00:20:25.531 --> 00:20:34.481
Step two, the subnet ID. Third subnet means zero-zero-zero-two — because the counting starts at zero-zero-zero-zero.

00:20:36.431 --> 00:20:43.501
Session twelve's off-by-one, and slide eighteen's audit is built to catch it.

00:20:43.551 --> 00:20:52.501
Step three, the prefix: site plus subnet, two-thousand colon one-four-five-six colon two-four-seven-four colon zero-zero-zero-two. Sixty-four bits.

00:20:53.231 --> 00:21:01.001
And that came from the router's advertisement. Overheard — not requested, and not granted.

00:21:01.051 --> 00:21:10.001
The answer: two-thousand colon one-four-five-six colon two-four-seven-four colon zero-zero-zero-two colon F-seven-A-nine colon twenty-three-F-F colon F-E-fourteen colon seven-A-D-two.

00:21:12.921 --> 00:21:21.871
Audit it: forty-eight plus sixteen plus sixty-four is a hundred and twenty-eight. Every bit accounted for, and not one of them typed by a person.

00:21:22.011 --> 00:21:30.888
The MAC on the card and the interface ID in the address are the same number in a different format.

00:21:30.938 --> 00:21:39.338
Three checks, ten seconds, and they catch almost every mistake this question can produce.

00:21:39.388 --> 00:21:48.278
Count the groups. The site is three groups, the subnet is one, and the interface ID is four. Eight groups.

00:21:48.328 --> 00:21:56.038
If your answer has seven or nine, something upstream went wrong and the audit has just caught it for free.

00:21:56.088 --> 00:22:05.038
The third subnet is zero-zero-zero-two, not zero-zero-zero-three. Counting starts at zero-zero-zero-zero, exactly as blocks have counted since Session eleven.

00:22:08.068 --> 00:22:17.018
This is the single most common arithmetic slip on the whole question, and it costs exactly as much as getting EUI-64 wrong.

00:22:18.798 --> 00:22:24.798
And the interface ID is four groups, not three. Sixty-four bits is four colon-hex groups.

00:22:24.848 --> 00:22:33.798
Writing F7A9:23FF:FE14 and stopping is the same class of error as leaving a group unpadded in Session nineteen — a complete answer thrown away at the last step.

00:22:37.729 --> 00:22:43.469
Checkpoint two, and the third question is the whole section in one go.

00:22:43.519 --> 00:22:49.419
One: name the four moves of stateless autoconfiguration, in order.

00:22:49.469 --> 00:22:56.349
Two: what source address does a host use for duplicate address detection, and why?

00:22:56.399 --> 00:23:05.349
Three: MAC 48-BD-3E-11-00-C5 joins the FOURTH subnet of two-thousand colon one-four-five-six colon two-four-seven-four slash forty-eight. Give its global address.

00:23:06.359 --> 00:23:15.309
One: make a link-local address, F-E-eight-zero double-colon plus the interface ID; run duplicate address detection; send a router solicitation and receive an advertisement carrying the prefix; glue prefix and interface ID together.

00:23:22.209 --> 00:23:31.159
Two: the unspecified address, double colon, all one hundred and twenty-eight bits zero. It has no address yet — that is the entire point of the question it is asking — and the double colon is the standard way of saying so. It can never be a destination.

00:23:39.609 --> 00:23:48.559
Three: the interface ID is four-A-B-D, three-E-F-F, F-E-one-one, zero-zero-C-five. The fourth subnet is zero-zero-zero-three.

00:23:50.209 --> 00:23:59.159
So the address is two-thousand colon one-four-five-six colon two-four-seven-four colon zero-zero-zero-three colon four-A-B-D colon three-E-F-F colon F-E-one-one colon zero-zero-C-five. Audit: forty-eight plus sixteen plus sixty-four is a hundred and twenty-eight.

00:24:12.419 --> 00:24:15.369
Section three. The packet got a haircut.

00:24:15.419 --> 00:24:24.369
A new address forced a new packet format — and the designers used the opportunity to fix twenty years of regrets.

00:24:26.019 --> 00:24:27.209
Eight fields, forty bytes, and the whole header fits into four rows of thirty-two bits. Here it is, before the next slide says what it dropped.

00:24:27.259 --> 00:24:28.179
The first thirty-two bits hold three fields. Version is four bits, and for IPv6 the value is six. Traffic class is eight bits, and it replaces IPv4's type-of-service field. Flow label is twenty bits, and it is the one field with no IPv4 ancestor — it lets a router treat a stream of packets as a flow. Four plus eight plus twenty is thirty-two.

00:24:28.229 --> 00:24:32.109
The second thirty-two bits hold three more. Payload length is sixteen bits and measures the datagram excluding the header — IPv4 needed two length fields, IPv6 needs one, because the header length is fixed and never has to be stated. Next header is eight bits. Hop limit is eight bits, and it is IPv4's TTL under an honest name. Sixteen plus eight plus eight is thirty-two.

00:24:32.159 --> 00:24:32.969
Source address: sixteen bytes, one hundred and twenty-eight bits. That is Session nineteen's colon-hexadecimal address, in the header exactly as you learned to write it. And notice the proportion: the two addresses together are thirty-two of the forty bytes. Four fifths of an IPv6 header is addresses, and everything a router needs to forward the packet rides in the other eight.

00:24:33.019 --> 00:24:36.419
Destination address: sixteen bytes again, and that is the eighth and last field. Thirty-two plus thirty-two plus one hundred and twenty-eight plus one hundred and twenty-eight is three hundred and twenty bits, which is forty bytes. Fixed. Every IPv6 base header is that size, which is why a router finds the next field by addition rather than by reading a length.

00:24:36.469 --> 00:24:38.349
Next header is the field that builds the chain. Its code names whatever comes after the base header: zero-zero hop-by-hop option, zero-two ICMPv6, zero-six TCP, seventeen UDP, forty-three source-routing option, forty-four fragmentation option, fifty encrypted security payload, fifty-one authentication header, fifty-nine null, sixty destination option. Each extension header carries a next-header field of its own plus a length, so the headers hang off one another in a chain, and the last code names the protocol the datagram is actually carrying.

00:24:38.399 --> 00:24:47.349
Forty bytes of base header, then extension headers only when something uses one. That is the design, and the next slide is what it removed to get there.

00:27:11.988 --> 00:27:16.508
Five verbs, and they carry the whole comparison table.

00:27:16.558 --> 00:27:25.118
Header size: forty bytes, fixed. IPv4's was twenty to sixty bytes, and you had to read a length field to know which.

00:27:25.168 --> 00:27:34.118
A fixed offset is addition. A variable one is a read, a branch and a second read — and hardware is very good at addition.

00:27:34.758 --> 00:27:41.368
The checksum: gone. It was recomputed at EVERY hop, because the hop limit changes at every hop.

00:27:41.418 --> 00:27:50.368
And the link layer and the transport layer were both already checking the same bytes. It was the third check, and the expensive one.

00:27:51.728 --> 00:27:58.668
Fragmentation: routers never fragment. The source learns the path's smallest MTU and sizes its packets to fit.

00:27:58.718 --> 00:28:07.668
A router that cannot forward one replies "packet too big" and drops it. Mid-path fragmentation was slow, fragile, and it made routers hold state.

00:28:09.958 --> 00:28:18.908
Options became extension headers, chained after the base header. A packet that uses no options carries none, and a router that does not need to look does not look.

00:28:20.188 --> 00:28:27.978
And TTL was renamed hop limit, because that is what it always was — it never counted seconds; it counted routers.

00:28:28.028 --> 00:28:36.978
Every change either removes work from the router or moves it somewhere that only pays when it is used.

00:28:37.355 --> 00:28:45.025
The same six changes as a table. Read the right-hand column downwards as a sentence.

00:28:45.075 --> 00:28:51.845
Header size. IPv4: twenty to sixty bytes, variable, with a length field to interpret first.

00:28:51.895 --> 00:29:00.295
IPv6: forty bytes, FIXED — so a router parses every packet identically, at full speed.

00:29:00.345 --> 00:29:05.775
Checksum. IPv4: yes, and recomputed at every single hop.

00:29:05.825 --> 00:29:14.775
IPv6: GONE. The frame is checked below and the segment is checked above. Two checks were always enough.

00:29:15.915 --> 00:29:21.725
Fragmentation. IPv4: any router along the path may fragment a packet.

00:29:21.775 --> 00:29:28.935
IPv6: NEVER. Only the source may, and it sizes to the path MTU instead.

00:29:28.985 --> 00:29:33.695
Options. IPv4: an options field living inside the header itself.

00:29:33.745 --> 00:29:42.165
IPv6: CHAINED after the base — extension headers, present only when something actually uses one.

00:29:42.215 --> 00:29:51.165
And the last two. TTL becomes hop limit — honest at last, since it never counted seconds. Type of service becomes traffic class, plus a new flow label.

00:29:53.495 --> 00:30:02.445
Fixed, gone, never, chained, renamed. Five verbs, and the table is recoverable from them.

00:30:03.947 --> 00:30:09.767
Why any of that matters is a Week four argument rather than a Week eleven one.

00:30:09.817 --> 00:30:17.717
Processing and queuing delay dominate at every hop. That was Week four's delay lecture, and this is where it gets cashed in.

00:30:17.767 --> 00:30:26.717
A change that removes per-hop work from a router does not save microseconds in one place. It saves them at every hop of every packet, forever.

00:30:28.097 --> 00:30:35.707
The checksum was pure per-hop work — recomputed at every router because one field in the header changes at every router.

00:30:35.757 --> 00:30:41.847
Deleting it deletes an arithmetic operation from every hop on the Internet.

00:30:41.897 --> 00:30:48.187
And mid-path fragmentation made routers hold state. A fragmenting router has to track pieces.

00:30:48.237 --> 00:30:57.057
Pushing that job out to the source makes the middle of the network simpler — which is exactly the same instinct that produced the datagram in Session eighteen.

00:30:57.107 --> 00:31:06.057
None of this made IPv6 faster than IPv4 on a fast link. It made the ROUTER's job smaller, which is where the time was actually going.

00:31:10.630 --> 00:31:19.580
Forty-two seconds covering the header, the three transition strategies, and both of the open questions. The last half of it is the next section of this video.

00:31:23.730 --> 00:31:32.680
The two packet diagrams stacked: IPv4's variable options in red, IPv6's fixed forty bytes in green with the extension headers hanging off the back.

00:31:33.850 --> 00:31:42.800
The comparison table. Read only the green column and you get: fixed, gone, never, chained, renamed, split in two.

00:31:44.490 --> 00:31:53.440
The four reasons. The checksum as the third check; fragmentation as a trap; options that only cost when used; and TTL finally called what it is.

00:31:56.130 --> 00:32:05.080
Now the transition. Dual stack: one host, two stacks, and a choice made per destination on what DNS returns.

00:32:05.940 --> 00:32:14.890
Tunnelling. Watch the packet diagram: an outer IPv4 header added by R1, the IPv6 header untouched inside it, and R2 stripping the outer one off.

00:32:16.450 --> 00:32:23.270
And the middle row of the caption — the ocean routers saw an ordinary IPv4 packet.

00:32:23.320 --> 00:32:32.270
Header translation. The IPv6 header becomes an IPv4 header, and the flow label in red is simply dropped. Wrapping is lossless; rewriting is not.

00:32:33.140 --> 00:32:42.090
And both answers: the laptop makes half and receives half; no flag day is possible; and NAT worked too well. We will do all three properly in a moment.

00:32:49.468 --> 00:32:53.538
Checkpoint three, on the header.

00:32:53.588 --> 00:33:00.078
One: give three things the IPv6 header removed, and one it renamed.

00:33:00.128 --> 00:33:06.388
Two: an IPv6 packet is too large for the next link. What happens?

00:33:06.438 --> 00:33:11.558
Three: why was deleting the header checksum safe?

00:33:11.608 --> 00:33:20.558
One: removed — the header checksum; the router's ability to fragment; and the variable-length options field, which moved out into chained extension headers. Renamed: TTL became hop limit.

00:33:25.658 --> 00:33:34.608
Two: the router does NOT fragment it. It drops the packet and sends back an ICMPv6 "packet too big" message naming the MTU, and the source then re-sends smaller. Only the source may fragment in IPv6.

00:33:38.338 --> 00:33:47.288
Three: because it was the third check on the same bytes — the link layer checks the frame and the transport layer checks the segment. It was also the most expensive, since the changing hop limit forced a recomputation at every hop.

00:33:55.735 --> 00:33:58.995
Section four. Two Internets, one wire.

00:33:59.045 --> 00:34:07.995
Nobody can reboot the Internet. So IPv4 and IPv6 have to share the world — and there are exactly three ways to manage that.

00:34:11.701 --> 00:34:18.691
Three strategies, and one sentence each — then the discriminating questions.

00:34:18.741 --> 00:34:27.691
Dual stack: the host runs the IPv4 and IPv6 stacks side by side. Ask DNS what the far end has, try version six, fall back to version four.

00:34:29.381 --> 00:34:35.541
It is what your laptop is doing right now, every time you open a page.

00:34:35.591 --> 00:34:42.351
Tunnelling: the version six packet is swallowed whole inside a version four packet at one end and unwrapped at the other.

00:34:42.401 --> 00:34:48.251
Session three's encapsulation, pointed sideways instead of downwards.

00:34:48.301 --> 00:34:55.431
Header translation: a router converts the version six header into a version four header, field by field.

00:34:55.481 --> 00:35:04.431
Not wrapped — transformed. And it is lossy: the flow label has no IPv4 equivalent, so it is dropped.

00:35:04.551 --> 00:35:10.921
And one, two or all three may be running at once. Forouzan twenty-two point four.

00:35:10.971 --> 00:35:17.561
The path your packet takes this afternoon probably uses more than one of them, and no host involved needs to know.

00:35:17.611 --> 00:35:26.561
The exam does not ask you to list the three. It gives you a scenario and asks which one applies — so the verb matters more than the name.

00:35:28.729 --> 00:35:32.979
Five scenarios. Answer each one before I do.

00:35:33.029 --> 00:35:38.849
Two IPv6 campuses linked by an ISP that still runs IPv4 only. Both campuses speak version six.

00:35:38.899 --> 00:35:47.849
Tunnelling. Wrap at one edge, unwrap at the other, and the middle carries an ordinary version four packet.

00:35:49.379 --> 00:35:55.839
A new IPv6-only sensor that must reach a legacy server which will never be upgraded. One end never will speak version six.

00:35:55.889 --> 00:36:02.839
Header translation. There is nothing to unwrap at the far side, so the header has to be rewritten.

00:36:02.889 --> 00:36:11.819
Your laptop, on a network where some sites are version six and some are version four. One host, a mixed world.

00:36:11.869 --> 00:36:20.729
Dual stack. The question is about a host rather than a path, and the host simply picks per destination.

00:36:20.779 --> 00:36:27.269
A router that rebuilds the header field by field — addresses mapped, hop limit into TTL.

00:36:27.319 --> 00:36:35.959
Translation, and something is lost: the flow label has no IPv4 equivalent, so it is simply dropped.

00:36:36.009 --> 00:36:42.089
And a packet that arrives at the far end bit for bit as it left, with nothing inside touched.

00:36:42.139 --> 00:36:47.669
Tunnelling. The inner packet was payload. Wrapping is lossless; rewriting is not.

00:36:47.719 --> 00:36:56.669
Read the scenario for what the FAR END speaks before you choose the verb. That one habit answers the whole question, every time it is asked.

00:36:59.399 --> 00:37:05.779
One question, and it is the one that checks whether encapsulation landed.

00:37:05.829 --> 00:37:09.169
An ordinary IPv4 packet. That is all they ever saw.

00:37:09.219 --> 00:37:18.169
They read an IPv4 header addressed from one tunnel end to the other, forwarded it by longest prefix match exactly as in Session seventeen, and never looked any deeper.

00:37:19.069 --> 00:37:27.839
To them, the entire IPv6 packet was payload. An opaque blob of bytes, no different from a chunk of a file.

00:37:27.889 --> 00:37:32.959
They did not know IPv6 existed, and nothing about their job required them to.

00:37:33.009 --> 00:37:40.049
Which is exactly why tunnelling works over equipment nobody is willing to upgrade.

00:37:40.099 --> 00:37:49.049
You do not need the middle of the network to learn anything. You need two boxes at the edges that agree — and that is a much cheaper thing to arrange.

00:37:50.349 --> 00:37:59.299
Be able to answer that question in one sentence. A definition of tunnelling without it is only half an answer.

00:38:00.399 --> 00:38:05.789
Five contrasts, and between them they are the whole of section four.

00:38:05.839 --> 00:38:10.809
Tunnelling adds a header — the original packet survives underneath, untouched.

00:38:10.859 --> 00:38:18.379
Translation replaces one — the original header is gone, and a new one stands in its place.

00:38:18.429 --> 00:38:23.379
Tunnelling needs IPv6 at both ends, because somebody has to unwrap it.

00:38:23.429 --> 00:38:32.379
Translation needs IPv6 at one end only — the other end never speaks it, which is the whole reason for translating.

00:38:33.049 --> 00:38:38.279
Tunnelling is lossless: what comes out is bit for bit what went in.

00:38:38.329 --> 00:38:45.489
Translation is lossy: the flow label has no IPv4 home, so it is dropped in transit.

00:38:45.539 --> 00:38:52.789
Tunnelling costs bytes — a whole extra header on every packet, and a smaller usable MTU underneath it.

00:38:52.839 --> 00:39:00.379
Translation costs fidelity, and it must sit in the path of every packet of the conversation.

00:39:00.429 --> 00:39:09.379
And dual stack is neither. Nothing is added and nothing is replaced; the host just speaks both and chooses, destination by destination.

00:39:09.929 --> 00:39:18.879
Wrap, rewrite, or speak both. If you can attach the right verb to the right scenario, the transition questions are finished.

00:39:22.014 --> 00:39:30.944
This one shows the packet as a stack of headers, which is the only way the difference between wrapping and rewriting becomes obvious.

00:39:30.994 --> 00:39:36.804
State one: two IPv6 islands and an IPv4 ocean between them, drawn as a dashed box because nothing in it has ever heard of IPv6.

00:39:36.854 --> 00:39:45.804
State two: one host with two stacks, DNS in the middle, and two possible destinations. The packet underneath has one header and nothing added.

00:39:47.474 --> 00:39:56.424
State three: watch the packet. An outer IPv4 header in blue, added by R1; the IPv6 header in green underneath it, untouched; and the payload behind that.

00:39:59.034 --> 00:40:04.474
R2 removes the blue one and what falls out is the original, bit for bit.

00:40:04.524 --> 00:40:13.474
State four is the checking question, made visual. The same stack, but now the labels say what they read and what they never looked at.

00:40:14.534 --> 00:40:20.414
The IPv6 header has gone grey — to those routers it was just more payload.

00:40:20.464 --> 00:40:29.414
State five: now the green header BECOMES an orange one, and the flow label appears in red and struck out.

00:40:30.134 --> 00:40:34.954
Nothing is nested here. There is one header, and it has been replaced.

00:40:35.004 --> 00:40:43.704
State six is the three scenarios with their answers. Cover the right-hand column and try them before you look.

00:40:43.754 --> 00:40:48.804
The discriminating detail is always the same: what does the far end speak?

00:40:48.854 --> 00:40:57.804
And state seven puts the two packet shapes side by side — v4 wrapping v6 wrapping data, against v4 wrapping data alone.

00:40:58.584 --> 00:41:07.534
Then the paragraph that answers last session's open question. Read it, and then come back for the next slide.

00:41:10.885 --> 00:41:13.375
Today's hook first.

00:41:13.425 --> 00:41:17.975
Where does the address come from? The laptop makes half and receives half.

00:41:18.025 --> 00:41:26.975
The right sixty-four bits it manufactures from its own MAC — split, stuff, flip. The left sixty-four it overhears from a router advertisement. Glue, check for twins, done.

00:41:31.495 --> 00:41:37.595
So "it is random" was half right. Something really is invented locally, with nobody's permission.

00:41:37.645 --> 00:41:46.165
It is just not random — it was sitting in the hardware the whole time, and it had been unique since before the machine was unboxed.

00:41:46.215 --> 00:41:51.185
And "the router assigns it" was half right too. A router really does supply half.

00:41:51.235 --> 00:42:00.185
But it announces a prefix to the whole link rather than assigning an address to anyone, and the host does the arithmetic itself.

00:42:00.435 --> 00:42:07.505
The truth is a handshake — between hardware the machine has always owned, and a network it has only just met.

00:42:07.555 --> 00:42:16.505
Neither half is enough on its own, and neither half required a server. That is why both classic guesses feel right and neither one is.

00:42:19.269 --> 00:42:22.699
And now last session's open question.

00:42:22.749 --> 00:42:30.849
First: no flag day is possible. Nobody can take the Internet down for an afternoon and bring it back speaking a new protocol.

00:42:30.899 --> 00:42:39.849
So both Internets must run side by side, indefinitely — and the transition machinery you just learned exists precisely BECAUSE the switch cannot be finished.

00:42:42.509 --> 00:42:46.429
Second, and this is the villain: NAT worked too well.

00:42:46.479 --> 00:42:55.429
Session seventeen's trick made a whole building comfortable behind one scarce IPv4 address. It removed the pain that would have forced migration — and it removed it cheaply.

00:42:58.639 --> 00:43:03.459
IPv6 solved address scarcity. NAT made scarcity survivable.

00:43:03.509 --> 00:43:08.839
And people do not pay to replace what survives. Good enough is the enemy of better.

00:43:08.889 --> 00:43:17.839
The answer is economic rather than technical. Nothing about IPv6 was too hard, and everything about IPv4 was just bearable enough. That is a lesson about engineering history, not about addressing.

00:43:24.769 --> 00:43:28.739
Checkpoint four, the last one.

00:43:28.789 --> 00:43:37.739
One: two IPv6 sites are separated by an IPv4-only carrier. Which strategy, and what does the carrier see?

00:43:37.919 --> 00:43:45.099
Two: give the two reasons the IPv4-to-IPv6 switch is not finished.

00:43:45.149 --> 00:43:53.159
Three: in one sentence each — what does tunnelling do, and what does translation do?

00:43:53.209 --> 00:44:02.159
One: tunnelling. The carrier's routers see an ordinary IPv4 packet addressed from one tunnel endpoint to the other, and forward it by longest prefix match. The entire IPv6 packet is payload to them.

00:44:06.209 --> 00:44:15.159
Two: no flag day is possible, so version four and version six must coexist indefinitely; and NAT removed the pain of address scarcity, so nobody was forced to migrate. Technical necessity and economic incentive, pulling the same way.

00:44:22.829 --> 00:44:31.779
Three: tunnelling WRAPS — it puts a version four header in front of an untouched version six packet, and both ends speak version six. Translation REWRITES — it replaces the version six header with a version four one, because the far end never speaks version six.

00:44:43.714 --> 00:44:50.384
Five mistakes, ten seconds each — and the first three are all one skill.

00:44:50.434 --> 00:44:58.434
"Set bit seven to one", so zero-two stays zero-two. The most common EUI-64 error there is.

00:44:58.484 --> 00:45:07.434
Flip bit seven. Zero-two goes down to zero-zero; F5 goes up to F7. A locally administered MAC flips DOWN.

00:45:08.314 --> 00:45:13.194
Inserting F-F-F-E into an eight-byte EUI-64, producing an eighty-bit result.

00:45:13.244 --> 00:45:20.344
F-F-F-E is only for forty-eight-bit MACs. An EUI-64 input needs the flip alone — count the bytes first.

00:45:20.394 --> 00:45:29.344
Flipping bit seven of the whole address, or of the wrong byte. It is an easy slip under time pressure.

00:45:29.904 --> 00:45:38.854
The first byte, seventh from the left. Write the byte in binary and count to seven.

00:45:38.954 --> 00:45:43.764
"IPv6 routers fragment large packets." They did in IPv4, so it feels true.

00:45:43.814 --> 00:45:52.764
Never. Only the source fragments; a router replies "packet too big". And there is no header checksum either — those two go together in the same answer.

00:45:56.294 --> 00:46:03.274
And using tunnelling and translation interchangeably. They sound like synonyms and they are not.

00:46:03.324 --> 00:46:09.584
Tunnelling wraps; translation rewrites. And the giveaway is whether the FAR END speaks IPv6.

00:46:09.634 --> 00:46:18.584
Three of those five are one skill. If the EUI-64 conversion is automatic, more than half of this session's risk disappears.

00:46:21.891 --> 00:46:27.331
Three things, and the third one opens the final act of the course.

00:46:27.381 --> 00:46:34.501
The addressing arc is finished. Eleven sessions, from "what is an address" to a machine that builds its own.

00:46:34.551 --> 00:46:40.761
Every remaining question about getting a packet to the right computer has now been answered.

00:46:40.811 --> 00:46:49.761
But your laptop has one address and about forty conversations. A browser, a mail client, a chat app, three background updaters.

00:46:49.841 --> 00:46:57.081
The packet arrives at the right machine — and then what? Nothing you have learned so far can tell those forty apart.

00:46:57.131 --> 00:47:04.551
So the last hop is inside the machine. That is the transport layer, and it starts the final act of the course.

00:47:04.601 --> 00:47:08.371
Ports, sockets, and forty conversations that never collide.

00:47:08.421 --> 00:47:17.371
Read Forouzan twenty-three point one to twenty-three point two before next session, and run netstat dash n tonight to count the connections your own machine is holding open.

00:47:21.838 --> 00:47:27.928
Four skills, and between them they are almost every mark this session is worth.

00:47:27.978 --> 00:47:34.788
Convert any MAC to an interface ID, in both directions of the flip. Split, stuff, flip.

00:47:34.838 --> 00:47:43.788
And be as fluent on zero-two to zero-zero as on F5 to F7. This is the highest-frequency question in the session.

00:47:44.778 --> 00:47:51.818
Assemble a full global address from a prefix and a MAC. Example twenty-two point four is the model.

00:47:51.868 --> 00:48:00.568
Watch the subnet counting from zero-zero-zero-zero, and audit forty-eight plus sixteen plus sixty-four before you stop.

00:48:00.618 --> 00:48:09.348
Name the four moves of autoconfiguration in order: link-local, duplicate address detection, router advertisement, glue.

00:48:09.398 --> 00:48:13.918
And know which source address move two uses, and why.

00:48:13.968 --> 00:48:19.708
And match a transition scenario to its strategy: wrap, rewrite, or speak both.

00:48:19.758 --> 00:48:27.639
Decided by what the far end speaks — not by what sounds most sophisticated.

00:48:27.689 --> 00:48:33.169
And three phrasings that lose marks while you know the material perfectly.

00:48:33.219 --> 00:48:37.999
"Convert this MAC" wants the whole chain, not just the interface ID.

00:48:38.049 --> 00:48:46.999
If the question mentions a prefix or a subnet, it wants the global address. Stopping at the interface ID answers a question that was not asked.

00:48:48.709 --> 00:48:54.249
"How does a host get an address with no server?" is not "what is DHCP?"

00:48:54.299 --> 00:49:03.249
The expected answer is the four moves of stateless autoconfiguration. DHCPv6 is worth one sentence at the end, as the option for networks that want central control.

00:49:07.399 --> 00:49:10.809
And "explain tunnelling" wants the ocean routers' view.

00:49:10.859 --> 00:49:19.809
Say what is added, say who removes it, and say what the routers in between saw. A definition without that last clause is only half the answer.

00:49:19.989 --> 00:49:27.847
Read the question twice. The second read is where the verb becomes visible.

00:49:27.897 --> 00:49:31.157
Three wordings, one session.

00:49:31.207 --> 00:49:36.567
"Convert this MAC", or "give the address". Pure mechanics, and one flip.

00:49:36.617 --> 00:49:45.567
Split, stuff F-F-F-E, flip bit seven of the first byte — then prefix plus interface ID, audited to a hundred and twenty-eight.

00:49:47.217 --> 00:49:52.607
"How does a host get an address with no server?" wants the four moves, in order.

00:49:52.657 --> 00:49:59.797
Link-local, duplicate address detection from the double colon, router advertisement, glue.

00:49:59.847 --> 00:50:08.657
And "which transition strategy, and why?" wants one question answered first: what does the far end speak?

00:50:08.707 --> 00:50:17.657
Both ends version six, tunnel — wrap. Far end never version six, translate — rewrite. One host in a mixed world, dual stack.

00:50:19.897 --> 00:50:23.377
That is Session twenty, and that is the addressing arc.

00:50:23.427 --> 00:50:32.377
The address was in the hardware all along. Split, stuff, flip — and flip means flip: zero-two goes down to zero-zero, and an eight-byte input is never stuffed.

00:50:35.087 --> 00:50:43.337
Four moves and no server: link-local, duplicate address detection from the unspecified address, router advertisement, glue.

00:50:43.387 --> 00:50:52.337
The packet got a haircut — forty bytes fixed, no checksum, no router fragmentation — and every deletion is per-hop work that a router never has to do again.

00:50:54.267 --> 00:51:03.037
Tunnelling wraps, translation rewrites, dual stack speaks both. And NAT is why your ISP still has not finished the switch.

00:51:03.087 --> 00:51:12.037
Eleven sessions ago an address was a number on a slide. It is now something a machine assembles for itself out of a serial number and an overheard announcement.

00:51:12.827 --> 00:51:21.777
Next session, the last act begins: your laptop has one IP address and forty conversations, and none of them ever collide. The last hop is inside the machine.

00:51:23.177 --> 00:51:27.880
I will see you there.
