DNS finds addresses
The Domain Name System, or DNS, associates names with records. AnA record contains an IPv4 address. An AAAA record contains an IPv6 address.
A name can have several records, and a resolver can cache answers.
The record’s time to live, or TTL, limits how long that cached answer remains valid.
See RFC 1034.
DNS does not establish a connection or prove that a service is healthy.
Two clients can receive different answers because of resolver configuration, caching, or service routing policy.
Record the actual address used when comparing their results.
Routes select a next hop
A routing table associates destination prefixes with an interface or next-hop router. Within an ordinary destination-based lookup, the most specific matching prefix wins. This is called longest-prefix matching. Policy routing and equal-prefix preferences add other decisions; they are outside this first example. Consider this simplified table:
For
10.42.8.150, all three prefixes match.
The /26 wins because it fixes the largest number of destination bits.
For 10.42.8.20, the /24 wins.
For 203.0.113.8, only the default route matches.
0.0.0.0/0 matches every IPv4 address in a routing table.
It does not identify a particular server.
An application binding to 0.0.0.0 uses a different convention: it usually listens on all local IPv4 interfaces.
A default gateway is the next-hop router selected by the default route.
It is not the final destination of every packet.
See RFC 4632, section 5.1.
The first local hop
Suppose a laptop uses192.168.10.77/26, with gateway 192.168.10.65.
The laptop wants to contact a server outside that subnet.
- The application resolves the service name to an address.
- The operating system selects a route for that address.
- On Ethernet, the laptop uses ARP to find the next hop’s MAC address for IPv4.
- The laptop sends a frame to that next hop, carrying an IP packet for the server.
- The router repeats route selection for the next part of the journey.
NAT changes address information
Network Address Translation, or NAT, changes IP address information as packets cross a device. Home routers commonly also translate ports so several private devices can share one public IPv4 address. The device keeps a mapping to direct replies to the originating client. This example shows a fictional translation:Firewalls decide whether traffic is allowed
A firewall can evaluate source and destination addresses, transport protocols, ports, and connection state. The exact behavior depends on the firewall and its rules.
A rule that allows TCP port 443 does not imply a rule that allows UDP port 443.
Likewise, a route to a server does not prove that a firewall permits the traffic.
Do not widen a CIDR range or disable a firewall just because a connection timed out.
First identify the destination, protocol, direction, and policy that applies.
Trace the complete attempt
An error at one step can prevent every later step. A timeout alone rarely identifies which step failed. Use evidence from both endpoints when available.Exercise
Use the routing table above.- Which route handles
10.42.8.190? - Which route handles
10.42.8.200? - DNS returns an address, but the connection times out. Name two checks that remain necessary.
- A server sees one public address for three laptops. Does that prove they share one user account?
Worked answers
Worked answers
- The VPN route wins.
.190is within10.42.8.128/26, whose range ends at.191. - The lab route wins.
.200is outside that/26but inside10.42.8.0/24. - Check the selected route and the firewall policy for the actual protocol and port. Also check whether the destination service is listening.
- No. NAT can produce that result. Application credentials establish user identity independently.