Hermetic Networks Hermetic Networks

CompTIA Network+ (N10-009) - Session 04 - Learner Guide

Routing and Gateways

How a router picks a path, what the routing table on a workstation is telling you, and where a packet actually stops.

1What a router decides

This is your copy to keep. The gold Going deeper boxes go past what the session covers, for anyone sitting the CompTIA Network+ exam or who wants the fuller picture.

A switch moves traffic between devices on one local network. A router moves traffic between networks, and it makes exactly one decision each time: given this destination address, which way do I send this next. Everything else a router does is in service of that.

It answers from a routing table, a list of destinations and where to send traffic for each. Every device has one, not just routers. Your workstation has a routing table and consults it before it sends anything.

Two terms are needed before the table is readable, and both were set up by the addressing work. A subnet mask marks which part of an address names the network, and it is written as a slash and a number of network bits, so 255.255.255.0 is /24 and names the first three octets as the network. The default gateway is the router address a device sends traffic to when the destination is not on its own network.

The example network

The addresses on this page are an example written for training. They are not a client network. The example site has three networks: staff 192.168.10.0/24, voice 192.168.20.0/24 and guest 192.168.30.0/24, with the gateway at .1 on each.

2The routing table on a workstation

Run route print on Windows, or ip route on Mac or Linux, and you get this machine's own table. Here is the useful part of one, for a workstation at 192.168.10.15 with mask 255.255.255.0.

A workstation's routing table, trimmed to the lines that matter
DestinationMaskSend it toOut ofMeaning
0.0.0.00.0.0.0192.168.10.1192.168.10.15Anything not matched below goes to the gateway
192.168.10.0255.255.255.0direct192.168.10.15My own network. Deliver these myself
192.168.10.15255.255.255.255direct192.168.10.15Me
127.0.0.0255.0.0.0direct127.0.0.1Traffic to myself, which never leaves the machine

Read the second line first, because it is the one doing the ordinary work. Destination 192.168.10.0 with mask 255.255.255.0 means "any address whose first three octets are 192.168.10". For those, the machine delivers directly: it finds the destination's hardware address on the local network and sends the frame straight to it. No router involved.

Now the first line. Destination 0.0.0.0 with mask 0.0.0.0 is a mask with no network bits at all, which matches every address in existence. This is the default route, and it is the catch-all: anything that did not match a more specific line goes to 192.168.10.1, the gateway. When a machine is described as "having a gateway", this line is what that means.

3How the table picks a line

Two lines can both match the same destination. Send something to 192.168.10.200 and it matches the default route, because the default route matches everything, and it matches the line for 192.168.10.0/24. The tie is broken by one rule.

The logic behind the tiebreaker can be worked out before the rule gets a name. The default route has a mask of 0.0.0.0, which is zero network bits. The line for the local network has mask 255.255.255.0, which is 24 network bits. The local network line is more specific about which addresses it is claiming, and it wins. So the traffic is delivered directly and never reaches the router, which is what actually happens.

Stated as the rule: the line with the most network bits that still matches the destination wins. It is called longest prefix match, and it applies everywhere, on a workstation and on a router with four hundred lines in its table.

This rule is the reason a default route is safe to have. It matches everything, but it loses to every other line in the table, so it only ever catches what nothing else claimed.

4Routing between VLANs

A VLAN (virtual local area network) divides one switch into separate networks, and each VLAN carries its own subnet. Devices on different VLANs cannot reach each other directly, because they cannot hear each other's local broadcasts and therefore cannot find each other's hardware addresses.

What joins them is the gateway, and it joins them by holding an address on every VLAN. At the example site the gateway is 192.168.10.1 on staff, 192.168.20.1 on voice and 192.168.30.1 on guest. It is one device with three addresses, one foot in each network.

Follow a packet from a staff workstation at 192.168.10.15 to a phone system at 192.168.20.50.

  1. The workstation checks its own table. 192.168.20.50 does not match its local network line, because the first three octets differ. It matches the default route.
  2. So the workstation sends the packet to 192.168.10.1, using the gateway's hardware address on the staff VLAN. The destination address inside the packet is still 192.168.20.50 and never changes.
  3. The gateway receives it and consults its own table. 192.168.20.0/24 is a network it is directly attached to, on the voice VLAN.
  4. Before it forwards anything, it applies the rules configured for traffic from the staff network to the voice network. If they permit it, the packet goes. If they do not, it stops here and the workstation is told nothing useful.
  5. The gateway sends the packet onto the voice VLAN, addressed to the phone system's hardware address, and the phone system receives it.

Two things follow that matter on tickets. Traffic between two VLANs always passes through the gateway even when both devices are plugged into the same switch two ports apart, so the gateway's load and its rules are in the path of internal traffic. And "can these two talk" is never answered by the switch alone: the VLAN decides whether they are neighbors, and the gateway and its rules decide everything after that.

5Static routes, and when one is needed

A static route is a line added to a routing table by hand, naming a destination network and the address to send it to. A site's gateway already knows about every network attached to it, and it sends everything else out to the internet, so most sites need no static routes at all.

One is needed when there is a network reachable through something that is not the default path. Take a site whose gateway is 192.168.10.1. A second appliance at that site, 192.168.10.9, has a permanent connection to another office and can reach that office's network, 10.50.0.0/24.

Without a static route, a workstation asking for 10.50.0.4 matches its default route, sends the packet to 192.168.10.1, and the gateway has no line for 10.50.0.0/24, so it sends it out to the internet, where it is discarded. The traffic does not fail in a way that names the cause. It just disappears.

The static route added on the gateway says: for 10.50.0.0/24, send to 192.168.10.9. Now the gateway has a line more specific than its own default route, longest prefix match picks it, and the packet goes to the appliance that can reach the far office.

Going deeper

A static route on the gateway fixes traffic leaving the site. The far end needs the matching route back, or the reply has the same problem in reverse and the connection still fails. A route that works in one direction only is the most common static routing fault, and the symptom is a connection that opens and never completes rather than one that fails outright.

6Following the path with tracert

tracert on Windows, traceroute on Mac and Linux, lists the routers a packet passes through on the way to a destination. Each router along the way is called a hop.

It works by sending packets with a deliberately short life. Every IP packet carries a time to live counter, and every router that forwards it subtracts one. A router that subtracts the last one discards the packet and reports back that it did. So a packet sent with a count of 1 dies at the first router and that router names itself. A count of 2 dies at the second, naming that one instead. Sending one packet at each increasing count, and collecting the name each router reports back, builds the full list of routers along the path.

A trace from the example staff network out to the internet
HopAddressWhat it is
1192.168.10.1The site gateway. If this fails, the fault is inside the building
2a public addressThe internet provider's equipment. If hop 1 answers and this does not, the fault is the circuit or the provider
3 onwardpublic addressesThe provider's network and beyond. Not ours to fix, but useful to name in a ticket

Reading it correctly matters more than running it. A hop showing a timeout in the middle of a trace, with later hops still answering, is not a fault: plenty of routers are configured not to reply to these packets while still forwarding traffic normally. What tells you something is the point where the trace stops answering and never resumes. That is the last device that was reachable, and the problem is at or just past it.

7Where a packet actually stops

When traffic between two networks does not arrive, there are four places it can be stopping, and they are worth testing in this order because each one rules out the ones below it.

The four candidates, in the order to test them
WhereWhat it looks likeHow to tell
The sender's own tableThe machine never sends it to the gateway at allroute print. A wrong mask can make the machine believe the destination is local, so it tries to deliver directly and gets no answer
The gateway has no routeTraffic leaves the machine and goes nowhereA trace that reaches the gateway and stops. The gateway's own table, looking for a line covering that destination
A rule blocks itThe route exists and traffic is still refusedThe rules between those two networks, and the gateway's log of what it blocked
The return pathThe request arrives and the reply never comes backThe far end's route back to your network. Connections open and stall rather than failing immediately

Notice what these four have in common: three of them look identical from the user's chair. In every case the application times out and says nothing useful. The order above is what separates them, and it is the same bottom-up habit as any other fault, applied to the path instead of the stack.

8Practice on your own machine

  1. Run route print, or ip route. Find your default route and your own network's line. Write down what each one claims and what it does with matching traffic.
  2. Pick an address on your own network and an address on the internet. For each, say which line of your table matches, and why that line beats the other one.
  3. Run tracert to a public site. Write down hop 1 and confirm it is your gateway. Note any hop that times out while later hops still answer, and say why that is not a fault.
  4. Run tracert to an address on another VLAN at the same site. Count the hops and say what the count tells you about how internal traffic reaches it.
  5. In the UniFi console, open the site's networks and list the gateway address on each one. Confirm they are the same device holding one address per network.

9Check for understanding

  1. A workstation's table has a line for 192.168.10.0/24 and a default route. It sends to 192.168.10.200. Which line is used, and why?

  2. What does a default route of 0.0.0.0 with mask 0.0.0.0 match, and why does having it not break everything else in the table?

  3. Two machines are on different VLANs, plugged into the same switch, two ports apart. Describe the path traffic between them actually takes.

  4. A trace to a public site shows hop 4 timing out, while hops 5, 6 and 7 answer normally and the site loads. What is happening, and what would you tell a user who sent you that screenshot as evidence of a problem?

  5. A site can reach a remote office's servers, but the remote office cannot reach anything at this site. Traffic is permitted in both directions by the rules. What do you check, and why does this fault appear as connections that stall rather than connections that fail?

  6. A trace from a workstation stops at hop 1, the site gateway, and goes no further, while other machines at the site are browsing normally. Name the two most likely causes and how you would tell them apart.

10Before the next session

  • Do the practice steps in section 8 and bring your own routing table written out, with the matching line identified for each of the two destinations.
  • Be able to state longest prefix match in one sentence and give an example of two lines competing.
  • Read the Network+ companion, chapter 6, the command-line tools section.

Next session. 05 - DHCP and DNS. The Dynamic Host Configuration Protocol, which hands a device its addressing, and the Domain Name System, which turns names into addresses, and the faults each one produces.

11Glossary

Router
The device that moves traffic between networks, choosing where to send each packet next.
Routing table
The list of destinations and where to send traffic for each. Every device has one.
Default gateway
The router address a device sends traffic to when the destination is not on its own network.
Default route
The table line with destination 0.0.0.0 and mask 0.0.0.0, matching every address and used when nothing more specific does.
Longest prefix match
The rule that the matching line with the most network bits wins.
Static route
A routing table line added by hand, naming a destination network and where to send it.
Hop
One router along the path between two machines.
Time to live
A counter in every IP packet that each router reduces by one. At zero the packet is discarded, which is what stops a packet circulating forever and what makes a trace possible.
tracert
The Windows command that lists the routers along a path. Called traceroute on Mac and Linux.
VLAN
Virtual local area network. One switch divided into separate networks by configuration, each carrying its own subnet.
Subnet mask
The marker saying which part of an address names the network and which names the device.
Loopback
The 127.0.0.0 range, used for a machine to reach itself. Traffic to it never leaves the machine.

12Sources