
ARP and Neighbor Discovery: resolving the next hop, not the destination
Why IPv4 ARP and IPv6 Neighbor Discovery map a layer-3 address to a layer-2 address on the local link, what each protocol actually does, and where their trust model breaks.

Why IPv4 ARP and IPv6 Neighbor Discovery map a layer-3 address to a layer-2 address on the local link, what each protocol actually does, and where their trust model breaks.

What each basic network tool really answers, how to read its result, and the conclusions it does not support.

What an Ethernet frame carries, what a MAC address identifies, and how a switch builds the table it forwards from.

What ICMP does inside IP, how TCP and UDP differ, and why a port identifies a process rather than a trusted service.

How an address splits into a prefix and a host part, why a prefix boundary can fall inside an octet, and what the default gateway actually does in IPv4 and IPv6.

Four devices, four different decisions: the information each one uses, the scope it applies in, and why "which layer it is" is the wrong question.

Why the layered models exist, what each layer adds to a packet, and where OSI and TCP/IP differ.

How unicast, broadcast and multicast address traffic, why IPv6 dropped broadcast, and why the size of a broadcast domain is an operational problem.