A router hop decrements TTL and therefore changes the header bytes.

highlighted = computed this step

One hop subtracts one

At this toy router hop, TTL drops from 64 to 63.

641=6364 - 1=63
One hop changes TTLThe before and after IPv4 headers are shown as exact field strips.Before header160 bits / 20 bytes0x4500003c1c4640004006b1e6ac100a63ac100a0cbyte 0byte 1byte 2byte 301000101000000000000000000111100byte 4byte 5byte 6byte 700011100010001100100000000000000byte 8byte 9byte 10byte 1101000000000001101011000111100110byte 12byte 13byte 14byte 1510101100000100000000101001100011byte 16byte 17byte 18byte 1910101100000100000000101000001100version4ihl5dscp-ecn0x00total-length60identification0x1c46fragment-offset0ttl64protocol6->TCPheader-checksum0xb1e6source172.16.10.99destination172.16.10.12reserved: clear df: set mf: clearAfter header160 bits / 20 bytes0x4500003c1c4640003f06b2e6ac100a63ac100a0cbyte 0byte 1byte 2byte 301000101000000000000000000111100byte 4byte 5byte 6byte 700011100010001100100000000000000byte 8byte 9byte 10byte 1100111111000001101011001011100110byte 12byte 13byte 14byte 1510101100000100000000101001100011byte 16byte 17byte 18byte 1910101100000100000000101000001100version4ihl5dscp-ecn0x00total-length60identification0x1c46fragment-offset0ttl63protocol6->TCPheader-checksum0xb2e6source172.16.10.99destination172.16.10.12reserved: clear df: set mf: clear

After header

The after header has TTL 63. The helper recomputes the whole after header from the before header.

after TTL=63\text{after TTL}=63
One hop changes TTLThe before and after IPv4 headers are shown as exact field strips.Before header160 bits / 20 bytes0x4500003c1c4640004006b1e6ac100a63ac100a0cbyte 0byte 1byte 2byte 301000101000000000000000000111100byte 4byte 5byte 6byte 700011100010001100100000000000000byte 8byte 9byte 10byte 1101000000000001101011000111100110byte 12byte 13byte 14byte 1510101100000100000000101001100011byte 16byte 17byte 18byte 1910101100000100000000101000001100version4ihl5dscp-ecn0x00total-length60identification0x1c46fragment-offset0ttl64protocol6->TCPheader-checksum0xb1e6source172.16.10.99destination172.16.10.12reserved: clear df: set mf: clearAfter header160 bits / 20 bytes0x4500003c1c4640003f06b2e6ac100a63ac100a0cbyte 0byte 1byte 2byte 301000101000000000000000000111100byte 4byte 5byte 6byte 700011100010001100100000000000000byte 8byte 9byte 10byte 1100111111000001101011001011100110byte 12byte 13byte 14byte 1510101100000100000000101001100011byte 16byte 17byte 18byte 1910101100000100000000101000001100version4ihl5dscp-ecn0x00total-length60identification0x1c46fragment-offset0ttl63protocol6->TCPheader-checksum0xb2e6source172.16.10.99destination172.16.10.12reserved: clear df: set mf: clear

Checksum changes too

Changing TTL changes a header byte, so the header checksum field also changes from 0xb1e6 to 0xb2e6.

0xb1e60xb2e60xb1e6\to0xb2e6
One hop changes TTLThe before and after IPv4 headers are shown as exact field strips.Before header160 bits / 20 bytes0x4500003c1c4640004006b1e6ac100a63ac100a0cbyte 0byte 1byte 2byte 301000101000000000000000000111100byte 4byte 5byte 6byte 700011100010001100100000000000000byte 8byte 9byte 10byte 1101000000000001101011000111100110byte 12byte 13byte 14byte 1510101100000100000000101001100011byte 16byte 17byte 18byte 1910101100000100000000101000001100version4ihl5dscp-ecn0x00total-length60identification0x1c46fragment-offset0ttl64protocol6->TCPheader-checksum0xb1e6source172.16.10.99destination172.16.10.12reserved: clear df: set mf: clearAfter header160 bits / 20 bytes0x4500003c1c4640003f06b2e6ac100a63ac100a0cbyte 0byte 1byte 2byte 301000101000000000000000000111100byte 4byte 5byte 6byte 700011100010001100100000000000000byte 8byte 9byte 10byte 1100111111000001101011001011100110byte 12byte 13byte 14byte 1510101100000100000000101001100011byte 16byte 17byte 18byte 1910101100000100000000101000001100version4ihl5dscp-ecn0x00total-length60identification0x1c46fragment-offset0ttl63protocol6->TCPheader-checksum0xb2e6source172.16.10.99destination172.16.10.12reserved: clear df: set mf: clear

Summary

One hop changes TTL by one and produces a new valid header checksum.

after checksum=0xb2e6\text{after checksum}=0xb2e6
One hop changes TTLThe before and after IPv4 headers are shown as exact field strips.Before header160 bits / 20 bytes0x4500003c1c4640004006b1e6ac100a63ac100a0cbyte 0byte 1byte 2byte 301000101000000000000000000111100byte 4byte 5byte 6byte 700011100010001100100000000000000byte 8byte 9byte 10byte 1101000000000001101011000111100110byte 12byte 13byte 14byte 1510101100000100000000101001100011byte 16byte 17byte 18byte 1910101100000100000000101000001100version4ihl5dscp-ecn0x00total-length60identification0x1c46fragment-offset0ttl64protocol6->TCPheader-checksum0xb1e6source172.16.10.99destination172.16.10.12reserved: clear df: set mf: clearAfter header160 bits / 20 bytes0x4500003c1c4640003f06b2e6ac100a63ac100a0cbyte 0byte 1byte 2byte 301000101000000000000000000111100byte 4byte 5byte 6byte 700011100010001100100000000000000byte 8byte 9byte 10byte 1100111111000001101011001011100110byte 12byte 13byte 14byte 1510101100000100000000101001100011byte 16byte 17byte 18byte 1910101100000100000000101000001100version4ihl5dscp-ecn0x00total-length60identification0x1c46fragment-offset0ttl63protocol6->TCPheader-checksum0xb2e6source172.16.10.99destination172.16.10.12reserved: clear df: set mf: clear