EMZETT.
Login

Broadcast

In short: A transmission from one sender to all devices in a network segment at the same time, without addressing individual recipients.

In more detail: ARP requests are a classic broadcast example: “Who has this IP?” is sent to everyone in the local network because it isn’t yet known who will answer. Broadcast traffic causes noticeable load in large networks, which is why networks are often divided into smaller segments to keep broadcast domains small.

In Depth

Addressing: subnet broadcast vs. limited broadcast

Technically, a broadcast in the local network addresses a special broadcast address — with IPv4 there are two variants. The “directed” (subnet-directed) broadcast uses the highest address of a subnet (e.g. 192.168.1.255 in a /24 network) and can theoretically even be addressed across router boundaries to a specific remote subnet. The “limited” broadcast, on the other hand, uses the fixed address 255.255.255.255, which ALWAYS reaches only the local segment and is never forwarded by routers. At the MAC address level (layer 2), both correspond to the address FF:FF:FF:FF:FF:FF. Every device in the segment is obliged to process frames addressed to this address, in contrast to normal unicast frames, which only the actual target device passes on to the higher network layers at all.

Typical broadcast applications

Besides ARP, DHCP requests also use broadcast, for example: a new device without an IP address can’t address anyone specifically yet, so it shouts “I need an IP address!” into the network via broadcast, and a DHCP server answers. Wake-on-LAN (waking a shut-down computer over the network) also classically works via broadcast: the “magic packet” is sent to the broadcast address so that it arrives even if the target computer’s exact current IP address isn’t known.

Broadcast storms

This very principle — every device has to process every broadcast message, even if it doesn’t concern it — is why broadcast traffic can become a real problem in large, flat networks (“broadcast storm”): every additional device increases the base load for all others, and certain misconfigurations (e.g. an accidental network loop without a working Spanning Tree Protocol, see Bridge) can cause broadcast frames to multiply in a self-reinforcing loop until the entire network segment is practically incapacitated within seconds. In practice, a sudden, inexplicable total failure of a network segment without any recognisable cause is often an indication of exactly this phenomenon.

Security risk: the Smurf attack

The directed broadcast was historically also the basis of the “Smurf attack”: an attacker sends ICMP echo requests (see Ping) with a forged sender address (that of the actual victim) to the broadcast address of another network — all devices in that network then reply simultaneously to the supposed victim, which is flooded with replies (denial of service through amplification). For exactly this reason, modern routers and firewalls block incoming directed broadcasts from outside by default.

Containment and replacement in IPv6

Modern networks therefore actively limit broadcast domains through VLANs and routing boundaries — a router basically doesn’t forward broadcast traffic between different networks, so each VLAN forms its own smaller broadcast domain and problems stay contained locally. IPv6 abolished broadcast as a concept completely and replaced it with more targeted multicast — a deliberate design decision to avoid exactly these scaling and security problems of large networks from the outset, since multicast messages only reach devices that have actively registered interest in the respective multicast group.

See also: Unicast, Multicast, ARP, DHCP, VLAN