Detailed Ethernet Frame Format
From the ITCTA curriculum
TL;DR
An Ethernet frame is the basic unit of data transmission over an Ethernet network, packaging your data along with essential information for delivery. It's structured into several fields, each with a specific job like addressing, type identification, and error checking. Understanding this format is key to troubleshooting network issues and appreciating how data moves across your local network.
1. The Mental Model
Think of an Ethernet frame like a specialized envelope for your digital mail. It doesn't just contain your letter (the actual data), but also has spaces for the sender's and receiver's addresses, a stamp, and even a way to check if the envelope got damaged in transit.
2. The Core Material
The Ethernet frame format defines how data is organized before it's sent over an Ethernet network. It ensures that devices can understand where data comes from, where it's going, and what kind of data it is.
Preamble and Start Frame Delimiter (SFD)

Photo by Kindel Media on Pexels
These aren't technically part of the "frame" but precede it.
* Preamble (7 bytes): A sequence of alternating 1s and 0s (10101010...) that synchronizes the receiving device's clock with the incoming data stream.
* SFD (1 byte): The final 10101011 sequence that signals the actual start of the Ethernet frame.
MAC Addresses

Photo by Pixabay on Pexels
These are fundamental for identifying devices on a local network.
* Destination MAC Address (6 bytes): The physical address of the network interface card (NIC) intended to receive the frame. It tells the frame where to go on the local segment.
* Source MAC Address (6 bytes): The physical address of the NIC that sent the frame. This tells the receiver where the frame came from.
EtherType / Length Field

Photo by cottonbro studio on Pexels
This field has a dual purpose depending on its value.
* EtherType (2 bytes): If the value is greater than or equal to 1536 (0x0600 in hex), it indicates the protocol carried in the payload (e.g., IP, ARP).
* Length (2 bytes): If the value is less than or equal to 1500, it indicates the length of the data field in bytes. This is common in older Ethernet II frames or specific IEEE 802.3 implementations.
Data (Payload)

Photo by Rashed Paykary on Pexels
This is where your actual information lives.
* Data (46-1500 bytes): This carries the higher-layer protocol data (e.g., an IP packet, an ARP request). If the data is less than 46 bytes, padding bytes are added to meet the minimum frame size.
Frame Check Sequence (FCS)
This is for error detection.
* FCS (4 bytes): Contains a 32-bit Cyclic Redundancy Check (CRC). The sending device calculates this value based on the frame's contents (from Destination MAC to Data) and attaches it. The receiving device recalculates the CRC; if the calculated value doesn't match the FCS, it indicates corruption during transmission and the frame is usually dropped.
Here's a visual breakdown:
graph LR
A["Preamble (7 bytes)"] --> B["SFD (1 byte)"];
B --> C["Destination MAC (6 bytes)"];
C --> D["Source MAC (6 bytes)"];
D --> E["EtherType / Length (2 bytes)"];
E --> F["Data (46-1500 bytes)"];
F --> G["FCS (4 bytes)"];
3. Worked Example
Let's imagine a computer with MAC address AA:BB:CC:DD:EE:FF sending an IPv4 packet to another computer with MAC address 00:11:22:33:44:55. The IP packet itself is 1000 bytes long.
- Preamble & SFD: The NIC first sends the 7-byte Preamble then the 1-byte SFD for synchronization.
- Destination MAC:
00:11:22:33:44:55is inserted. - Source MAC:
AA:BB:CC:DD:EE:FFis inserted. - EtherType: Since it's an IPv4 packet, the EtherType
0x0800(hexadecimal for 2048) is inserted, indicating the payload is an IPv4 packet. - Data: The 1000-byte IPv4 packet is placed here. Since 1000 bytes is between 46 and 1500, no padding is needed.
- FCS: A CRC-32 checksum is calculated over the entire frame (from Destination MAC to Data) and appended as a 4-byte value.
The complete frame (excluding Preamble/SFD) would be:
6 (DMAC) + 6 (SMAC) + 2 (EtherType) + 1000 (Data) + 4 (FCS) = 1018 bytes.
4. Key Takeaways
- An Ethernet frame is the data unit at the Data Link Layer (Layer 2).
- It starts with Preamble/SFD for synchronization, followed by the frame's actual content.
- Destination and Source MAC addresses are crucial for local network delivery.
- The EtherType field identifies the protocol encapsulated within the frame's data.
- The Data field carries the actual payload, typically an IP packet or ARP message.
- The Frame Check Sequence (FCS) is used for error detection, ensuring data integrity.
- Minimum frame size for the data field is 46 bytes; padding is added if needed.
Common mistakes to avoid:
- Confusing MAC addresses (Layer 2) with IP addresses (Layer 3).
- Forgetting that the Preamble and SFD are before the frame, not in it.
- Overlooking the dual purpose of the EtherType/Length field.
- Thinking FCS corrects errors; it only detects them.
5. Now Try It
Using a network packet analyzer like Wireshark, capture some local network traffic (e.g., browse a website, ping another device on your network). Identify an Ethernet II frame in your capture. For that specific frame, locate and note down the values for: Destination MAC, Source MAC, and EtherType. Then, confirm the total length of the frame (excluding Preamble/SFD) and identify how many bytes are in the Data/Payload section.
Success looks like: You can consistently identify these fields in different captured frames and explain what their values represent.
Frequently asked about Detailed Ethernet Frame Format
More from ITCTA
Get the full ITCTA curriculum
Clone the complete plan to your dashboard for unlimited AI-generated notes, practice quizzes, and a personalised revision schedule.
Save this course free