Hermetic Networks Hermetic Networks

CompTIA Network+ (N10-009) - Session 04 - Instructor Guide

Routing and Gateways

How a router picks a path, what the routing table on a workstation is telling you, and where a packet actually stops.

1Session at a glance

Objectives

  1. Read a workstation's routing table and say what each line claims.
  2. Given two matching lines, say which one is used and why.
  3. Trace the path traffic takes between two VLANs at the same site.
  4. Say when a static route is needed and what happens without one.
  5. Read a trace and separate a silent hop from the point where traffic actually stops.

Before the session

  • A command prompt on the screen with route print already run, so the table is on the board before anyone is asked to read it.
  • A real site open in the UniFi console with its networks list, so the gateway address on each network can be pointed at.
  • A trace to a public site run in advance, ideally one with a silent hop in the middle, captured as text.
  • Everyone at a machine with a command prompt, and the Learner Guide open.
Run of show
TimeBlockWhat happens
0:00OpenTwo machines, same switch, two ports apart, and the traffic between them travels further than the internet does.
0:04ConceptThe routing table (5), how a line is chosen (4), routing between VLANs (6), static routes (4), following the path (3).
0:26ShowLive: route print read line by line, then the gateway addresses across the site's networks, then a trace out to the internet and a trace to another VLAN, meaning a virtual local area network.
0:36DoEveryone reads their own table, predicts which line handles two destinations, then runs both traces.
0:49CheckSix questions.
0:56CloseThe work before session 05, and what that session covers.
Pacing

Routing between VLANs gets six minutes because it is the block that changes how people work tickets, and because the five-step walk has to be done slowly enough to write down. If the room is behind, cut static routes to the one example and skip the return-path box, which the Learner Guide carries anyway. Do not shorten the table-reading block: every later block is read off that table.

Console paths

Menu names in the UniFi console move between versions. Confirm the paths in the version the site is running before the session rather than in front of the room.

2Open (0:00, 4 minutes)

Open with this

Two machines in the same room, plugged into the same switch, two ports apart. One is on the staff network and one is on the voice network. When one sends something to the other, that traffic leaves the switch, goes to the gateway, gets inspected against a rule list, and comes back to the same switch it started on. Two ports apart, and it makes a round trip through the firewall to get there. Meanwhile the same machine reaching a website goes out of the building and never comes back through anything internal. Today is why that is, and why it is the right design rather than a mistake.

  • Draw the two machines, the switch and the gateway on the board and leave it up. The concept block fills in the path.
  • Say what it buys on a ticket: knowing that path means knowing there are exactly four places traffic between networks can stop, and you can test them in an order.

3Concept (0:04, 22 minutes)

The routing table (5 min)

  • Restate the two terms before using them, because both get used in every line: the mask marks which part of an address names the network, and the default gateway is the router address used when the destination is not local.
  • Say the thing people do not expect: every device has a routing table, not just routers. The one on screen belongs to a workstation.
  • Read the local network line first, not the default route. Destination 192.168.10.0, mask 255.255.255.0, means any address whose first three octets are 192.168.10, and for those the machine delivers directly with no router involved.
  • Then the default route. Destination 0.0.0.0, mask 0.0.0.0. Ask the room how many network bits that mask has before you answer it. None, so it matches every address in existence.
  • Land it: when somebody says a machine "has a gateway", this line is what they mean.

How a line is chosen (4 min)

  • Set up the conflict with a real destination rather than in the abstract: send to 192.168.10.200 and two lines match, the default route and the local network line.
  • Work the logic out before naming it. Default route, zero network bits. Local network line, 24 network bits. The 24 is more specific about what it is claiming, so it wins, so the traffic is delivered directly and the router never sees it. Which is what actually happens.
  • Only now name it: longest prefix match. Most network bits, still matching, wins.
  • Then the consequence that makes it click: this is why a default route is safe. It matches everything and loses to everything, so it only catches what nothing else claimed.

Routing between VLANs (6 min)

  • Restate what a VLAN is before building on it: one switch divided into separate networks by configuration, each carrying its own subnet, and devices on different VLANs cannot find each other directly because they cannot hear each other's local broadcasts.
  • Then the join: the gateway holds an address on every VLAN. At the example site it is 192.168.10.1, 192.168.20.1 and 192.168.30.1. One device, three addresses, a foot in each network.
  • Walk the five steps in section 4 of the Learner Guide on the board, slowly. Workstation checks its table, no local match, default route. Sends to the gateway's hardware address with the destination address unchanged inside. Gateway consults its table, finds the voice network attached. Applies the rules. Sends it onto the voice VLAN.
  • Stop deliberately at step four and say what happens when the rules refuse: the packet stops there and the workstation is told nothing useful, which is why "it just times out" is not evidence of anything.
  • Pay off the open: this is the path those two machines two ports apart actually take, and it is why the gateway is in the path of internal traffic as well as internet traffic.

Static routes (4 min)

  • Say the normal case first, so this does not sound like routine work: most sites need no static routes at all, because the gateway knows its own networks and sends everything else to the internet.
  • Then the example that needs one: a second appliance at 192.168.10.9 reaching a remote network 10.50.0.0/24.
  • Walk the failure before the fix. Workstation asks for 10.50.0.4, matches its default route, sends to the gateway, gateway has no line for it, so it goes out to the internet and is discarded. The traffic does not fail in a way that names the cause, it disappears.
  • Then the route: for 10.50.0.0/24, send to 192.168.10.9. More specific than the gateway's own default route, so longest prefix match picks it. Point out that this is the rule from ten minutes ago doing real work.
  • Add the return-path warning in one line, because it is the fault they will actually meet: the far end needs the matching route back, or the connection opens and stalls instead of failing.

Following the path (3 min)

  • Explain the mechanism rather than just the command, because reading the output depends on it. Every packet carries a counter, every router subtracts one, and the router that subtracts the last one reports back that it discarded it. Send one with a count of 1 and the first router names itself. Count of 2, the second. The replies list the path.
  • Walk the three-hop table in section 6 of the Learner Guide: hop 1 is the site gateway, so a failure there is inside the building; hop 2 is the provider.
  • Then the reading that matters most, and say it twice: a silent hop in the middle with later hops answering is not a fault. Plenty of routers are set not to reply while forwarding normally. What tells you something is where the trace stops and never resumes.

4Show (0:26, 10 minutes)

  1. Read the table on screen, line by line. Local network line first, then the default route, then the line for the machine's own address, then loopback. Say what each one claims and what it does with matching traffic.
  2. Make the table decide something. Name a destination on the local network and a destination on the internet, and have the room say which line handles each before you confirm it.
  3. The gateway across the site. In the console, open the networks list and read the gateway address on each network out loud. One device, one address per network. This is the picture from the concept block, in the real site.
  4. Trace to the internet. Run it live. Point at hop 1 and confirm it is the gateway. If a hop goes silent, stop and say why that is not a fault, and note that the later hops answering is the proof.
  5. Trace to another VLAN at the same site. Count the hops out loud. The gateway is in the path, which is the open, demonstrated rather than asserted.

5Do (0:36, 13 minutes)

  1. Their own table. route print, or ip route. Write down the default route and the local network line, and what each claims.
  2. Predict, then test. Pick one address on their own network and one on the internet. Write down which line will handle each and why, before running anything.
  3. Trace out. tracert to a public site. Confirm hop 1 is their gateway. Mark any silent hop and write one sentence saying why it is not the fault.
  4. Trace across. tracert to an address on another VLAN at the site. Count the hops and say what the count proves about the path.
What to correct

The one to watch for is people reading a silent hop as the answer. Somebody will point at a row of asterisks in the middle of a trace and call it the problem. Ask them what the hops after it are doing, and let them say it out loud: still answering, so traffic passed through it.

6Check (0:49, 7 minutes)

  1. A workstation's table has a line for 192.168.10.0/24 and a default route. It sends to 192.168.10.200. Which line is used, and why?

    Answer

    The 192.168.10.0/24 line. Both match, but it has 24 network bits against the default route's zero, so longest prefix match picks it. The workstation delivers directly on the local network and the router is never involved.

  2. What does a default route of 0.0.0.0 with mask 0.0.0.0 match, and why does having it not break everything else in the table?

    Answer

    A mask with no network bits matches every address in existence. It does not break anything because it loses to every more specific line in the table, so it only ever catches destinations that nothing else claimed.

  3. Two machines are on different VLANs, plugged into the same switch, two ports apart. Describe the path traffic between them actually takes.

    Answer

    Out of the first machine to the switch, up to the gateway on the first VLAN, through the gateway's routing table and its rules for traffic between those two networks, back down to the same switch on the second VLAN, and to the second machine. The gateway is in the path of that traffic even though both machines are on the same piece of hardware.

  4. A trace to a public site shows hop 4 timing out, while hops 5, 6 and 7 answer normally and the site loads. What is happening, and what would you tell a user who sent you that screenshot as evidence of a problem?

    Answer

    The router at hop 4 is configured not to reply to the expiring packets a trace uses, while forwarding traffic normally. The hops after it answering is the proof that traffic passed through it. Nothing is wrong at hop 4, and the site loading settles it.

    The obvious answer is that hop 4 is the fault, because a row of asterisks reads as a failure. The only meaningful signal in a trace is the point where it stops answering and never resumes.

  5. A site can reach a remote office's servers, but the remote office cannot reach anything at this site. Traffic is permitted in both directions by the rules. What do you check, and why does this fault appear as connections that stall rather than connections that fail?

    Answer

    The route back, at the far end. Their gateway needs a line for this site's network pointing at the connection between the two offices, and without it their traffic matches their default route and goes out to the internet, where it is discarded. It stalls rather than failing because the request that started at this end arrives fine and the reply has nowhere to go, so the connection opens and never completes.

  6. A trace from a workstation stops at hop 1, the site gateway, and goes no further, while other machines at the site are browsing normally. Name the two most likely causes and how you would tell them apart.

    Answer

    Either a rule on the gateway blocking that source, or the machine is on a different network than it should be, such as a guest or restricted VLAN whose traffic is deliberately limited. Tell them apart by reading the machine's own address and mask and checking which network that puts it in against the site documentation, then by looking at the gateway's log of blocked traffic for that source address.

    Other machines browsing normally is the part that does the work here: it rules out the circuit, the provider and the gateway's own route, and leaves only something specific to this machine.

7Close (0:56, 4 minutes)

Work before the next session

  • The practice steps in section 8 of the Learner Guide, with their own routing table written out and the matching line identified for both destinations.
  • Longest prefix match, stated in one sentence with an example of two lines competing.
  • The Network+ companion, chapter 6, command-line tools.

Next session

05 - DHCP and DNS. The Dynamic Host Configuration Protocol, which hands a device its address, mask, gateway and resolver, and the Domain Name System, which turns names into addresses. Both are the cause behind a large share of faults that look like something else.

Open items to settle

  • Whether any site has a static route in place that is not in its documentation, which the console demo may surface.
  • Which sites have a permanent connection to another office, so the return-route case can be shown on a real one rather than an example.

8Sources

9After the session

Delivered on
Attendance
What landed
What did not
Changes for next time
Backlog items created