What is an IP packet?¶
An IP packet is a labelled unit of network traffic. Its header helps networks forward it; its payload carries the data.
Header and payload¶
The header contains delivery information such as source and destination addresses, version and processing fields. The payload may contain part of a web request, message, image or other higher-layer data.
One communication normally uses many packets. They may be lost, retransmitted, reordered or take different routes. IP provides addressing and forwarding; it does not guarantee a completed user action.
Read the layers¶
TCP or UDP information sits inside the IP payload. A local network may carry the packet using Ethernet or Wi-Fi. This is why one record can contain addresses, ports, protocol and a local interface identifier without those fields meaning the same thing.
NAT, VPNs and proxies can change the source address visible at different observation points. A captured packet therefore needs its capture location and surrounding traffic to be interpreted.
What it cannot prove alone¶
A packet does not by itself establish who operated the source device, that the address was local to that device, that the payload represents a completed action or that it reached its final destination.
The point to remember
A packet is one unit in a larger communication. Its fields describe traffic at an observation point, not automatically the person behind it.