Prerequisites: IP addresses and CIDR. Outcome: explain how name resolution, route selection, translation, and filtering affect the same connection. Allow: 25 minutes, including the exercise.

DNS finds addresses

The Domain Name System, or DNS, associates names with records. An A record contains an IPv4 address. An AAAA record contains an IPv6 address. A name can have several records, and a resolver can cache answers. The record’s time to live, or TTL, limits how long that cached answer remains valid. See RFC 1034. DNS does not establish a connection or prove that a service is healthy. Two clients can receive different answers because of resolver configuration, caching, or service routing policy. Record the actual address used when comparing their results.

Routes select a next hop

A routing table associates destination prefixes with an interface or next-hop router. Within an ordinary destination-based lookup, the most specific matching prefix wins. This is called longest-prefix matching. Policy routing and equal-prefix preferences add other decisions; they are outside this first example. Consider this simplified table: For 10.42.8.150, all three prefixes match. The /26 wins because it fixes the largest number of destination bits. For 10.42.8.20, the /24 wins. For 203.0.113.8, only the default route matches. 0.0.0.0/0 matches every IPv4 address in a routing table. It does not identify a particular server. An application binding to 0.0.0.0 uses a different convention: it usually listens on all local IPv4 interfaces. A default gateway is the next-hop router selected by the default route. It is not the final destination of every packet. See RFC 4632, section 5.1.

The first local hop

Suppose a laptop uses 192.168.10.77/26, with gateway 192.168.10.65. The laptop wants to contact a server outside that subnet.
  1. The application resolves the service name to an address.
  2. The operating system selects a route for that address.
  3. On Ethernet, the laptop uses ARP to find the next hop’s MAC address for IPv4.
  4. The laptop sends a frame to that next hop, carrying an IP packet for the server.
  5. The router repeats route selection for the next part of the journey.
IPv6 uses Neighbor Discovery instead of ARP. Neither mechanism resolves arbitrary Internet hostnames; that is a separate task for DNS.

NAT changes address information

Network Address Translation, or NAT, changes IP address information as packets cross a device. Home routers commonly also translate ports so several private devices can share one public IPv4 address. The device keeps a mapping to direct replies to the originating client. This example shows a fictional translation:
The documentation addresses above illustrate the mapping; they are not a deployed service. A translated source address is not the client’s application identity. Several clients can share that address. NAT also does not replace application authorization or a firewall policy. See RFC 3022.

Firewalls decide whether traffic is allowed

A firewall can evaluate source and destination addresses, transport protocols, ports, and connection state. The exact behavior depends on the firewall and its rules. A rule that allows TCP port 443 does not imply a rule that allows UDP port 443. Likewise, a route to a server does not prove that a firewall permits the traffic. Do not widen a CIDR range or disable a firewall just because a connection timed out. First identify the destination, protocol, direction, and policy that applies.

Trace the complete attempt

An error at one step can prevent every later step. A timeout alone rarely identifies which step failed. Use evidence from both endpoints when available.

Exercise

Use the routing table above.
  1. Which route handles 10.42.8.190?
  2. Which route handles 10.42.8.200?
  3. DNS returns an address, but the connection times out. Name two checks that remain necessary.
  4. A server sees one public address for three laptops. Does that prove they share one user account?
  1. The VPN route wins. .190 is within 10.42.8.128/26, whose range ends at .191.
  2. The lab route wins. .200 is outside that /26 but inside 10.42.8.0/24.
  3. Check the selected route and the firewall policy for the actual protocol and port. Also check whether the destination service is listening.
  4. No. NAT can produce that result. Application credentials establish user identity independently.
Completion check: explain why a successful DNS lookup, a matching route, and an allowed firewall rule prove different things. Next: latency, jitter, loss, and bandwidth.