LECTURE 06

Routing

Duration: 113 min of teaching Level: bachelor, year III - no prior knowledge assumed Course: Local Area Networks Related lab: Laboratory 05 PDF: download the notes RO versiunea română

A router does not know the Internet. It has no map of the world and asks nobody where the destination is. It has only a list of directions and a rule for choosing among them, which it applies again and again, for each individual packet. This lecture shows what that list looks like, how routes get into it, and why the order of the lines matters so much.

1Recap5 min

What to keep in mind
  • The IP address is hierarchical: the network part plus the host part, separated by the mask.
  • AND between the address and the mask gives the network address. This operation is the heart of today's lecture.
  • IP addresses stay constant from one end to the other; MAC addresses are rewritten at every hop.
  • The TTL is decremented by every router and stops loops.

Learning outcomes

  • Explain what a route is and what role the metric plays
  • State, for any route, which source it came from and what administrative distance it has
  • Read a routing table and predict exactly what happens to a given packet
  • Configure static routes, with a next hop or with an exit interface, and know when each works
  • Write a default route and a floating backup route
  • Compute a summary route and use the Null0 interface

2The role and functions of a router9 min

Architecturally, a router is a specialised computer: it has a processor, memory and input/output devices. The differences from an ordinary computer are considerable, however, and all of them serve the same purpose - to make forwarding decisions as fast as possible.

ComponentRole in a routerLost on reboot?
ROMthe bootstrap code and an emergency imageno - it is permanent
Flashthe operating system, that is, the IOS imageno
RAMthe running configuration, the routing table, the ARP table, the packet queuesyes - all of it
NVRAMthe startup configurationno
ASICsdedicated circuits that perform packet forwarding in hardware-
The distinction that saves a configuration running-config lives in RAM and is what is running right now. startup-config lives in NVRAM and is what will be loaded at the next boot.

A perfect configuration, not saved with copy running-config startup-config, vanishes at the first power cut - or at the first reboot performed by somebody else. It is mistake number one in laboratories and, sadly, in real networks too.
Why a router is slower than a switch

A switch reads the first 12 bytes of the frame - the two MAC addresses - and searches a table for an exact match. The operation is done in hardware, in a single cycle.

A router must decapsulate layer 2, read the IP header, decrement the TTL, recompute the checksum, search the routing table for a prefix match - not an exact one - and then re-encapsulate the frame with different MAC addresses, which may require an ARP resolution.

Modern routers do this in hardware too, but there is still more work. Hence the difference in price per port.

Besides the basic function, modern routers also do: traffic filtering with ACLs (lecture 7), address translation with NAT and PAT (lecture 9), setting up tunnels, handing out addresses as a DHCP server, and proxy ARP.

3The route and the metric9 min

The route
The triple (destination, direction, distance).

"To get to Brașov I can go via Ploiești; the total distance will be 120 km." - (Brașov, Ploiești, 120 km).

The triple is enough not merely to travel, but to choose between several possibilities.

In networks, "distance" in kilometres says nothing useful. The quantity attached to a route is called the metric and may be any of the following, or a combination:

MetricWhat it measuresWho uses it
Hop countthe number of routers to the destinationRIP
Costinversely proportional to bandwidthOSPF
Composite metricbandwidth, delay, load, reliabilityEIGRP
Policy attributesadministrative preference, not performanceBGP
Why hop count is a poor metric

Router S has two paths to the same destination: one through A, with 2 hops, but over two 64 kbps serial links; the other through B, with 3 hops, but over 10 Gbps fibre. What does RIP choose?

See the answer

RIP chooses the path through A, with 2 hops - because that is the only thing it measures.

The result: the traffic goes over 64 kbps links instead of 10 Gbps fibre. The difference is a factor of more than 150,000.

It was precisely this weakness that led to RIP being replaced by OSPF, which measures cost inversely to bandwidth. Details in lecture 10.

4Where routes come from8 min

When an unconfigured router starts up, it knows no routes at all. Routes appear from three directions:

SymbolSourceHow it appearsEffort
CConnectedautomatically, for every active interface with an IP address configurednone
LLocalautomatically, the /32 address of the interface itselfnone
SStaticwritten by hand by the administratorone line per network, per router
R, D, O, Bdynamiclearned automatically from neighbours through RIP, EIGRP, OSPF, BGPinitial configuration, then automatic
The difference between C and L

When you configure 192.168.1.1/24 on an interface, the router creates two entries:

  • C 192.168.1.0/24 - "this network is directly attached to me, on interface X"
  • L 192.168.1.1/32 - "this address is me"

The second exists so that the router knows at once, with no calculation, when a packet is destined for itself - a ping to its interface, say, or an SSH management connection.

Terminal: explore a router routing table

6The routing table and the decision process13 min

The routing table is the router's map of the network around it. It is organised from the most specific routes (long mask) to the most general, and the process of forwarding a packet has exactly two steps.

  1. Receiving the packet. The layer 2 header is decapsulated, the destination IP address is read from the layer 3 header, the TTL is decremented and the checksum recomputed.
  2. Finding the route. The table is scanned; for each route, an AND is taken between its mask and the destination address, and the result is compared with the network address of the route. The first match wins. If nothing is found, the packet is discarded and an ICMP destination unreachable is sent.
Longest prefix match Ordering the table from specific to general is not an aesthetic convention - it is the algorithm itself. By scanning in this order and stopping at the first match, the router automatically finds the most specific route that matches.

That is why a /26 route beats a /8: it appears earlier in the table. And the default route, /0, is last - it applies only if nothing else matched.
Routing table lookup - test destinations
Experiments to try
  1. 13.1.0.5 - it matches both the /14 and the /8. The longer prefix wins. Follow the right-hand column to see why.
  2. 13.128.0.1 - it no longer fits in the /14, so it falls through to the /8. The same "13" network, a different route.
  3. 192.168.3.7 - it matches both the /24 (towards Null0) and the /20. The /24 wins, so the packet is deliberately discarded.
  4. 8.8.8.8 - it matches nothing specific and falls through to the default route.
  5. 172.30.14.9 - it matches neither of the two connected routes. Work out why, by computing the AND.
The two laws of routing 1. Routing is done individually, for each packet. Two packets of the same connection may take different paths, if something changed in between.

2. Every router decides solely on the basis of its own table. There is no coordination, no confirmation that the packet arrived and - very importantly - no guarantee whatever that the return path is the same.
Why the second law matters in practice

You configure a route on router A towards the network behind C. You ping. It does not work. Why?

See the answer

Because the packet did arrive at the destination. But the destination answered, and the answer has no way back: router C does not know where A's network is.

Routing must be configured in both directions, always. It is the commonest beginner's mistake and it produces the most confusing symptom of all: "the packet leaves, but I get no answer".

How to check: ping from C to A. If that does not work either, you know exactly where the problem is.

The routing decision, step by step

7The default route7 min

The route 0.0.0.0/0, also called quad-zero, has a mask made up entirely of zeros. An AND with it always gives 0.0.0.0, which always coincides with the network address of the route - so it matches any destination.

Being the most general, it occupies the last position in the table and applies only if nothing else matched. It is the route every small network has towards its Internet provider.

Analogy A mail sorting office has shelves for the destinations it knows: "Brașov", "Cluj", "Bucharest". And at the end it has one large shelf labelled "the rest of the world". Everything that fits no specific shelf goes there and leaves for the sorting centre above.

The default route is that shelf. And the Internet provider's router is the sorting centre above.
Who has a default route and who does not An enterprise network usually has a single default route - towards its provider.

The routers in the core of the Internet have none. They must know explicitly all of the more than 900,000 global prefixes, because there is no "above" to send what they do not know. That is the difference between being at the edge of the Internet and being in the middle of it.

8Static routes11 min

A static route is written by hand by the administrator. The direction can be expressed in two ways, and the choice between them is not a matter of indifference.

the three forms of a static route
! via the next-hop address - always works
R1(config)# ip route 192.168.10.0 255.255.255.0 10.0.0.3

! via the exit interface - only on point-to-point links
R1(config)# ip route 192.168.10.0 255.255.255.0 serial 0/0/0

! both, the most explicit and the fastest form
R1(config)# ip route 192.168.10.0 255.255.255.0 serial 0/0/0 10.0.0.3

! the default route
R1(config)# ip route 0.0.0.0 0.0.0.0 10.0.0.3
Why the next hop matters on Ethernet
There is a loophole - but do not rely on it The interface form can work on Ethernet if the neighbour has proxy ARP enabled: it will answer the ARP request on behalf of the destination, with its own MAC address.

But to build a network on that basis is to build a network that breaks the moment somebody, entirely correctly, disables proxy ARP for security reasons. Write the next hop.
Worked example

Three routers A, B, C joined in a triangle. A has the LAN 172.16.0.0/16, B has 144.13.248.0/21, C has 140.20.0.0/20. The A–C link is 10.0.0.4/30 (A has .5, C has .6). Configure static routes so that LAN A communicates with LAN C over the optimal path.

See the solution
configuration
A(config)# ip route 140.20.0.0 255.255.240.0 10.0.0.6
C(config)# ip route 172.16.0.0 255.255.0.0 10.0.0.5

Both routes are needed - the second law of routing. The packet reaches the destination with the first, but the answer has no way back without the second.

Mind the masks too: /20 means 255.255.240.0, not 255.255.255.0. A wrong mask produces a bizarre symptom: some hosts answer, others do not.

The floating route

Sometimes we want a backup path that activates only if the main one disappears. This is achieved by giving the backup route a higher administrative distance.

a main route and a floating route
! the main one - default AD of 1
R1(config)# ip route 172.20.19.0 255.255.255.0 10.0.0.6

! the backup - AD 200, so it does not enter the table while the first is valid
R1(config)# ip route 172.20.19.0 255.255.255.0 10.0.0.2 200

Check with show ip route: the route with AD 200 does not appear in the table as long as the one with AD 1 is valid. Shut down the main interface and look again - there it is. Bring it back up and check that it withdraws.

9The complete journey of a packet11 min

Here we put together everything we have learnt: ARP from lecture 5, switching from lecture 3, and today's routing. It is the exercise that appears, in one form or another, in every examination.

One packet, from end to end

10Route summarisation and the null interface11 min

A router with four routes to four consecutive subnets can replace them all with a single one, if they share a common prefix. The process is called summarisation (or aggregation).

How it is calculated

You write the addresses in binary and see how many bits from the left are common to all of them. That number is the prefix of the summary route.

192.168.1.0/26    192.168.1.00000000
192.168.1.64/26   192.168.1.01000000
192.168.1.128/26  192.168.1.10000000
192.168.1.192/26  192.168.1.11000000
──────────────────────────────────
common: the first 24 bits  →  192.168.1.0/24
Exercise for you

What is the summary route for 10.4.0.0/16, 10.5.0.0/16, 10.6.0.0/16 and 10.7.0.0/16?

See the solution

Compare the second byte, in binary:

4 = 00000100
5 = 00000101
6 = 00000110
7 = 00000111

The first 6 bits are common: 000001. The first byte contributes 8 common bits, so the total is 8 + 6 = 14.

The summary route: 10.4.0.0/14.

Check: /14 covers 2(32−14) = 262,144 addresses, which is exactly four /16 blocks. Correct.

How much a summarisation saves

Choose /26 summarised to /24: four routes become one. Choose /30 summarised to /22 - the case of the point-to-point links in a large network - and you will see why summarisation is not a luxury: 256 lines replaced by a single one, in the table of every router in the network.

Why it matters, at scale The immediate benefit: smaller routing tables, faster lookups, fewer updates when a subnet appears or disappears.

At Internet scale, summarisation is the only reason the global routing table has hundreds of thousands of entries rather than hundreds of millions. Without it, the Internet would not work at its present size.

The side effect and the null interface

Summarisation has a price. If one of the four subnets - say 192.168.1.128/26 - no longer exists, the summary route 192.168.1.0/24 goes on attracting traffic for it and forwarding it onward, where it will be discarded only at the end of the chain. In the case of a loop, the traffic may even oscillate between routers until the TTL expires.

The solution is a static route to Null0, the null interface: a destination that immediately discards everything it receives. Being more specific than the summary route, it wins and stops the traffic at the source.

the "rubbish bin" route
R1(config)# ip route 192.168.1.128 255.255.255.192 null0

The equivalent in the Linux world is /dev/null; the idea is the same - a place where things disappear, on request and without error.

11Common mistakes4 min

  • "I configured the route, but the ping does not work" In nine cases out of ten, the return route is missing. The packet arrives; the answer has no way back. Routing is always configured in both directions.
  • "I compared the metrics of two different protocols" They are not comparable. The administrative distance applies first. Longer prefix → lower AD → lower metric. In that order.
  • "I wrote the route with the exit interface, on Ethernet" The router does not know which MAC address to put in the frame, because there are several candidates on the segment. On Ethernet, always write the next hop.
  • "I saved the configuration… I think" running-config is in RAM. Without copy running-config startup-config, it is lost on reboot. Save after each block of changes, not at the end.
  • "I summarised and now some destinations no longer answer" The summary route also covers subnets that do not exist or are not yours. Add routes to Null0 for the unused portions of the block.

12Summary and glossary5 min

  1. A route is the triple (destination, direction, distance). The distance is called the metric and depends on the protocol.
  2. Selection proceeds in order: longer prefix → lower AD → lower metric.
  3. The table is ordered from specific to general, and the first match wins. The default route is last.
  4. On Ethernet, a static route needs a next hop, because otherwise the destination MAC address is missing.
  5. IP addresses stay constant along the whole path; MAC addresses are rewritten at every hop; the TTL falls by 1 at every router.
  6. Summarisation shrinks the tables; Null0 stops traffic towards the unused portions.
routethe triple destination, direction, distance
metricthe quality of a route, measured by the protocol that produced it
administrative distancehow much the router trusts the source of the route
next hopthe IP address of the next router along the path
longest prefix matchthe rule by which the most specific route wins
default route0.0.0.0/0 - it matches anything and applies last
floating routea backup route, with a deliberately raised AD
summarisationreplacing several routes with a single, more general one
Null0the interface that discards everything it receives
running-configthe active configuration, in RAM; lost on reboot
startup-configthe configuration in NVRAM, loaded at boot

13Self-check questions7 min

14Further reading and bibliography2 min

Static routes are exact and predictable, but they react to no change and do not scale. Lecture 10 introduces the protocols that maintain the table by themselves. Until then, lectures 7 and 9 show what else a router can do with the packets passing through it: filter them and rewrite their addresses.

In laboratory 5 you configure exactly the topology from here, first with static routes and then with OSPF, then cut a cable and time which recovers faster.

  • RFC 1812 - requirements for IPv4 routers
  • RFC 4632 - CIDR and route aggregation
  • Cisco - IP Routing: Protocol-Independent Configuration Guide
  • Radia Perlman, Interconnections: Bridges, Routers, Switches and Internetworking Protocols