A router does not know the Internet. It has no map of the world and asks nobody where the destination is. It has only a list of directions and a rule for choosing among them, which it applies again and again, for each individual packet. This lecture shows what that list looks like, how routes get into it, and why the order of the lines matters so much.
1Recap5 min
- The IP address is hierarchical: the network part plus the host part, separated by the mask.
- AND between the address and the mask gives the network address. This operation is the heart of today's lecture.
- IP addresses stay constant from one end to the other; MAC addresses are rewritten at every hop.
- The TTL is decremented by every router and stops loops.
Learning outcomes
- Explain what a route is and what role the metric plays
- State, for any route, which source it came from and what administrative distance it has
- Read a routing table and predict exactly what happens to a given packet
- Configure static routes, with a next hop or with an exit interface, and know when each works
- Write a default route and a floating backup route
- Compute a summary route and use the Null0 interface
2The role and functions of a router9 min
Architecturally, a router is a specialised computer: it has a processor, memory and input/output devices. The differences from an ordinary computer are considerable, however, and all of them serve the same purpose - to make forwarding decisions as fast as possible.
| Component | Role in a router | Lost on reboot? |
|---|---|---|
| ROM | the bootstrap code and an emergency image | no - it is permanent |
| Flash | the operating system, that is, the IOS image | no |
| RAM | the running configuration, the routing table, the ARP table, the packet queues | yes - all of it |
| NVRAM | the startup configuration | no |
| ASICs | dedicated circuits that perform packet forwarding in hardware | - |
running-config lives in RAM and is what is running right now.
startup-config lives in NVRAM and is what will be loaded at the next
boot.A perfect configuration, not saved with
copy running-config startup-config, vanishes at
the first power cut - or at the first reboot performed by somebody else. It is mistake number one in
laboratories and, sadly, in real networks too.A switch reads the first 12 bytes of the frame - the two MAC addresses - and searches a table for an exact match. The operation is done in hardware, in a single cycle.
A router must decapsulate layer 2, read the IP header, decrement the TTL, recompute the checksum, search the routing table for a prefix match - not an exact one - and then re-encapsulate the frame with different MAC addresses, which may require an ARP resolution.
Modern routers do this in hardware too, but there is still more work. Hence the difference in price per port.
Besides the basic function, modern routers also do: traffic filtering with ACLs (lecture 7), address translation with NAT and PAT (lecture 9), setting up tunnels, handing out addresses as a DHCP server, and proxy ARP.
3The route and the metric9 min
"To get to Brașov I can go via Ploiești; the total distance will be 120 km." - (Brașov, Ploiești, 120 km).
The triple is enough not merely to travel, but to choose between several possibilities.
In networks, "distance" in kilometres says nothing useful. The quantity attached to a route is called the metric and may be any of the following, or a combination:
| Metric | What it measures | Who uses it |
|---|---|---|
| Hop count | the number of routers to the destination | RIP |
| Cost | inversely proportional to bandwidth | OSPF |
| Composite metric | bandwidth, delay, load, reliability | EIGRP |
| Policy attributes | administrative preference, not performance | BGP |
Router S has two paths to the same destination: one through A, with 2 hops, but over two 64 kbps serial links; the other through B, with 3 hops, but over 10 Gbps fibre. What does RIP choose?
See the answer
RIP chooses the path through A, with 2 hops - because that is the only thing it measures.
The result: the traffic goes over 64 kbps links instead of 10 Gbps fibre. The difference is a factor of more than 150,000.
It was precisely this weakness that led to RIP being replaced by OSPF, which measures cost inversely to bandwidth. Details in lecture 10.
4Where routes come from8 min
When an unconfigured router starts up, it knows no routes at all. Routes appear from three directions:
| Symbol | Source | How it appears | Effort |
|---|---|---|---|
C | Connected | automatically, for every active interface with an IP address configured | none |
L | Local | automatically, the /32 address of the interface itself | none |
S | Static | written by hand by the administrator | one line per network, per router |
R, D, O, B | dynamic | learned automatically from neighbours through RIP, EIGRP, OSPF, BGP | initial configuration, then automatic |
When you configure 192.168.1.1/24 on an interface, the router creates two
entries:
C 192.168.1.0/24- "this network is directly attached to me, on interface X"L 192.168.1.1/32- "this address is me"
The second exists so that the router knows at once, with no calculation, when a packet is destined for itself - a ping to its interface, say, or an SSH management connection.
5Administrative distance11 min
The metric allows two routes from the same source to be compared. But how do we compare an OSPF route with metric 20 against a RIP route with metric 3?
The RIP metric is a number of routers: 3 means "three hops".
The OSPF metric is a cost computed from bandwidth: 20 may mean "two 100 Mbps links" or "one slow serial link".
They are entirely different units, as though you were comparing 3 kilograms with 20 seconds. The numbers bear no relation to one another.
A second criterion is needed, applied before the metric: the administrative distance (AD), which expresses how much the router trusts the source of the route. The lower it is, the greater the trust.
| Symbol | Source | AD | The logic behind it |
|---|---|---|---|
C | Connected | 0 | the router sees the network itself - nothing is more certain |
S | Static | 1 | the administrator decided explicitly; presumably they know what they are doing |
D | EIGRP | 90 | proprietary protocol, rich metric |
O | OSPF | 110 | link-state, a complete view of the topology |
i | IS-IS | 115 | link-state as well |
R | RIP | 120 | distance-vector, simplistic metric |
- | unknown / untrusted | 255 | the route will never be used |
The complete selection rule
- The longest prefix always wins. A /26 route beats a /8 route, whatever the source, whatever the metric. This is the supreme criterion and it is not negotiable.
- At the same prefix, the lower administrative distance wins.
- From the same source, the lower metric wins.
- If the metric is equal too, the router keeps both paths and distributes traffic between them - a mechanism called equal-cost load balancing.
A router knows the following routes. Which of them end up in the routing table?
| # | Route |
|---|---|
| 1 | C (10.0.0.8/30, Fa0/0) |
| 2 | R (141.85.37.0/24, metric 3) |
| 3 | C (10.0.0.4/30, Fa0/1) |
| 4 | R (141.85.37.0/24, metric 2) |
| 5 | D (200.0.0.0/16, metric 31452) |
| 6 | R (200.0.0.0/16, metric 3) |
See the solution
Routes 1 and 3 go in: they are the only ones to their destinations, and in any case they have AD 0.
Route 4 goes in, route 2 does not: the same destination, the same source (RIP), so the metric decides - 2 < 3.
Route 5 goes in, route 6 does not - and here is the trap. Metric 3 looks far better than 31452, but the two numbers come from different protocols and are not comparable. The administrative distance applies: EIGRP has 90, RIP has 120, so the EIGRP route wins.
If you thought 6 ought to win, you applied the wrong criterion - which is exactly what happens in the examination.
The easiest way to remember this table is through the logic behind it: the more first-hand information the router has about a route, the lower the number. An interface of its own is absolute truth (0). A route written by a person is a verifiable statement (1). A link-state protocol, which has the map, is more credible (110) than one that repeats rumours (120).
6The routing table and the decision process13 min
The routing table is the router's map of the network around it. It is organised from the most specific routes (long mask) to the most general, and the process of forwarding a packet has exactly two steps.
- Receiving the packet. The layer 2 header is decapsulated, the destination IP address is read from the layer 3 header, the TTL is decremented and the checksum recomputed.
- Finding the route. The table is scanned; for each route, an AND is taken between its mask and the destination address, and the result is compared with the network address of the route. The first match wins. If nothing is found, the packet is discarded and an ICMP destination unreachable is sent.
That is why a /26 route beats a /8: it appears earlier in the table. And the default route, /0, is last - it applies only if nothing else matched.
13.1.0.5- it matches both the /14 and the /8. The longer prefix wins. Follow the right-hand column to see why.13.128.0.1- it no longer fits in the /14, so it falls through to the /8. The same "13" network, a different route.192.168.3.7- it matches both the /24 (towards Null0) and the /20. The /24 wins, so the packet is deliberately discarded.8.8.8.8- it matches nothing specific and falls through to the default route.172.30.14.9- it matches neither of the two connected routes. Work out why, by computing the AND.
2. Every router decides solely on the basis of its own table. There is no coordination, no confirmation that the packet arrived and - very importantly - no guarantee whatever that the return path is the same.
You configure a route on router A towards the network behind C. You ping. It does not work. Why?
See the answer
Because the packet did arrive at the destination. But the destination answered, and the answer has no way back: router C does not know where A's network is.
Routing must be configured in both directions, always. It is the commonest beginner's mistake and it produces the most confusing symptom of all: "the packet leaves, but I get no answer".
How to check: ping from C to A. If that does not work either, you know exactly where the problem is.
7The default route7 min
The route 0.0.0.0/0, also called quad-zero, has a mask made up entirely of
zeros. An AND with it always gives 0.0.0.0, which always coincides with the network
address of the route - so it matches any destination.
Being the most general, it occupies the last position in the table and applies only if nothing else matched. It is the route every small network has towards its Internet provider.
The default route is that shelf. And the Internet provider's router is the sorting centre above.
The routers in the core of the Internet have none. They must know explicitly all of the more than 900,000 global prefixes, because there is no "above" to send what they do not know. That is the difference between being at the edge of the Internet and being in the middle of it.
8Static routes11 min
A static route is written by hand by the administrator. The direction can be expressed in two ways, and the choice between them is not a matter of indifference.
! via the next-hop address - always works R1(config)# ip route 192.168.10.0 255.255.255.0 10.0.0.3 ! via the exit interface - only on point-to-point links R1(config)# ip route 192.168.10.0 255.255.255.0 serial 0/0/0 ! both, the most explicit and the fastest form R1(config)# ip route 192.168.10.0 255.255.255.0 serial 0/0/0 10.0.0.3 ! the default route R1(config)# ip route 0.0.0.0 0.0.0.0 10.0.0.3
But to build a network on that basis is to build a network that breaks the moment somebody, entirely correctly, disables proxy ARP for security reasons. Write the next hop.
Three routers A, B, C joined in a triangle. A has the LAN 172.16.0.0/16, B has
144.13.248.0/21, C has 140.20.0.0/20. The A–C link is
10.0.0.4/30 (A has .5, C has .6). Configure static routes so that LAN A communicates with
LAN C over the optimal path.
See the solution
A(config)# ip route 140.20.0.0 255.255.240.0 10.0.0.6 C(config)# ip route 172.16.0.0 255.255.0.0 10.0.0.5
Both routes are needed - the second law of routing. The packet reaches the destination with the first, but the answer has no way back without the second.
Mind the masks too: /20 means 255.255.240.0, not
255.255.255.0. A wrong mask produces a bizarre symptom: some hosts answer, others do
not.
The floating route
Sometimes we want a backup path that activates only if the main one disappears. This is achieved by giving the backup route a higher administrative distance.
! the main one - default AD of 1 R1(config)# ip route 172.20.19.0 255.255.255.0 10.0.0.6 ! the backup - AD 200, so it does not enter the table while the first is valid R1(config)# ip route 172.20.19.0 255.255.255.0 10.0.0.2 200
Check with show ip route: the route with AD 200 does not appear in the table
as long as the one with AD 1 is valid. Shut down the main interface and look again - there it is.
Bring it back up and check that it withdraws.
9The complete journey of a packet11 min
Here we put together everything we have learnt: ARP from lecture 5, switching from lecture 3, and today's routing. It is the exercise that appears, in one form or another, in every examination.
10Route summarisation and the null interface11 min
A router with four routes to four consecutive subnets can replace them all with a single one, if they share a common prefix. The process is called summarisation (or aggregation).
How it is calculated
You write the addresses in binary and see how many bits from the left are common to all of them. That number is the prefix of the summary route.
192.168.1.64/26 192.168.1.01000000
192.168.1.128/26 192.168.1.10000000
192.168.1.192/26 192.168.1.11000000
──────────────────────────────────
common: the first 24 bits → 192.168.1.0/24
What is the summary route for 10.4.0.0/16, 10.5.0.0/16,
10.6.0.0/16 and 10.7.0.0/16?
See the solution
Compare the second byte, in binary:
4 = 00000100
5 = 00000101
6 = 00000110
7 = 00000111
The first 6 bits are common: 000001. The first byte contributes 8 common bits, so the
total is 8 + 6 = 14.
The summary route: 10.4.0.0/14.
Check: /14 covers 2(32−14) = 262,144 addresses, which is exactly four /16 blocks. Correct.
Choose /26 summarised to /24: four routes become one. Choose /30 summarised to /22 - the case of the point-to-point links in a large network - and you will see why summarisation is not a luxury: 256 lines replaced by a single one, in the table of every router in the network.
At Internet scale, summarisation is the only reason the global routing table has hundreds of thousands of entries rather than hundreds of millions. Without it, the Internet would not work at its present size.
The side effect and the null interface
Summarisation has a price. If one of the four subnets - say 192.168.1.128/26 - no
longer exists, the summary route 192.168.1.0/24 goes on attracting traffic for it and
forwarding it onward, where it will be discarded only at the end of the chain. In the case of a loop,
the traffic may even oscillate between routers until the TTL expires.
The solution is a static route to Null0, the null interface: a destination that immediately discards everything it receives. Being more specific than the summary route, it wins and stops the traffic at the source.
R1(config)# ip route 192.168.1.128 255.255.255.192 null0
The equivalent in the Linux world is /dev/null; the idea is the same - a place where
things disappear, on request and without error.
11Common mistakes4 min
- "I configured the route, but the ping does not work" In nine cases out of ten, the return route is missing. The packet arrives; the answer has no way back. Routing is always configured in both directions.
- "I compared the metrics of two different protocols" They are not comparable. The administrative distance applies first. Longer prefix → lower AD → lower metric. In that order.
- "I wrote the route with the exit interface, on Ethernet" The router does not know which MAC address to put in the frame, because there are several candidates on the segment. On Ethernet, always write the next hop.
- "I saved the configuration… I think"
running-configis in RAM. Withoutcopy running-config startup-config, it is lost on reboot. Save after each block of changes, not at the end. - "I summarised and now some destinations no longer answer" The summary route also covers subnets that do not exist or are not yours. Add routes to Null0 for the unused portions of the block.
12Summary and glossary5 min
- A route is the triple (destination, direction, distance). The distance is called the metric and depends on the protocol.
- Selection proceeds in order: longer prefix → lower AD → lower metric.
- The table is ordered from specific to general, and the first match wins. The default route is last.
- On Ethernet, a static route needs a next hop, because otherwise the destination MAC address is missing.
- IP addresses stay constant along the whole path; MAC addresses are rewritten at every hop; the TTL falls by 1 at every router.
- Summarisation shrinks the tables; Null0 stops traffic towards the unused portions.
13Self-check questions7 min
14Further reading and bibliography2 min
Static routes are exact and predictable, but they react to no change and do not scale. Lecture 10 introduces the protocols that maintain the table by themselves. Until then, lectures 7 and 9 show what else a router can do with the packets passing through it: filter them and rewrite their addresses.
In laboratory 5 you configure exactly the topology from here, first with static routes and then with OSPF, then cut a cable and time which recovers faster.
- RFC 1812 - requirements for IPv4 routers
- RFC 4632 - CIDR and route aggregation
- Cisco - IP Routing: Protocol-Independent Configuration Guide
- Radia Perlman, Interconnections: Bridges, Routers, Switches and Internetworking Protocols