Addresses, routes, and interfaces
How a host decides where to send a packet, and why one new route can steal traffic.
Addresses are prefixes plus hosts
An IPv4 address is 32 bits. CIDR notation, such as 10.20.0.0/16, says how many leading bits name the network. The rest identify hosts within it. Everything in operations that involves "is this address allowed / local / routed there?" is a prefix comparison. Practise doing it quickly. A /24 spans one value of the last octet, a /20 spans 16 values of the third octet, and a /16 spans the last two octets entirely.
A few ranges have fixed meanings worth memorising:
127.0.0.0/8and::1: loopback. Packets never leave the machine.10.0.0.0/8,172.16.0.0/12,192.168.0.0/16: private ranges, routed only inside organisations.169.254.0.0/16: link-local, often a sign that DHCP failed, and also where many cloud metadata services live.0.0.0.0/0: "everything", the default route.
The labs exploit loopback. Because all of 127.0.0.0/8 is local, 127.0.10.1 and 127.0.20.1 can act as two "hosts" on one machine, with real binds and refusals between them.
Interfaces carry addresses
ip addr lists interfaces and their addresses. A host typically has lo, one or more physical or virtual NICs, and perhaps tun0 for a VPN or docker0 and veth* pairs for containers. An address on an interface implies a connected route: the host can reach that prefix directly, without a gateway.
The forwarding decision
For every outgoing packet, the kernel looks up the destination in its routing table and picks the most specific matching route. This is longest-prefix match. Order of insertion does not matter, and neither does which route "looks" primary. ip route shows the table, and ip route get <addr> asks the kernel to make the decision and print it, including the chosen source address.
This explains a common post-change incident. A VPN client installs 10.20.14.0/24 dev tun0 to reach a partner network. A depot server also lives in 10.20.14.0/24 on the corporate network, previously reached via the broad 10.20.0.0/16 route. After the VPN connects, traffic to that depot silently goes into the tunnel. DNS works, the proxy is up, and only that subnet is dark. The routing table explains it, but only if you look.
Tools that observe rather than guess
ip -br addr,ip route, andip route getfor the host's view.pingtests reachability if ICMP is allowed. A failed ping is weak evidence on networks that filter it.traceroute,tracepath, ormtrto see the path's hops and where replies stop.tcpdump -ni <iface> host <addr>to see whether packets leave, and on which interface.
Compare a working host and a failing host side by side. The difference between their ip route get outputs is usually the entire diagnosis.
Key terms
- CIDR prefix
- An address block written as
address/length.10.20.0.0/16covers every address whose first 16 bits match. - Loopback
127.0.0.0/8(and::1). Traffic never leaves the host. A service bound only here is invisible to other machines.- Longest-prefix match
- When several routes contain the destination, the most specific one (largest prefix length) wins, whatever order the routes were added in.
- Default route
0.0.0.0/0, the route of last resort used when nothing more specific matches.
Read further
- TCP/IP Illustrated, Volume 1, 2nd edition, Ch. 2, "The Internet Address Architecture" (Purchase)
CIDR and prefixes, special-use addresses (loopback, private ranges), and how a host chooses a source address. Work the subnetting examples on paper. - TCP/IP Illustrated, Volume 1, 2nd edition, Ch. 5, "The Internet Protocol (IP)" (Purchase)
The IP forwarding section, especially the forwarding table and longest-prefix matching. Skip header field details on first read. - UNIX and Linux System Administration Handbook, 5th edition, Ch. 15, "IP Routing" (Purchase)
The routing table as shown by Linux tools, static routes, and how default routes are chosen.