Posts

Showing posts with the label Routing

Autonomous Systems and BGP: How the Internet Routes Between Networks

An autonomous system is a network under one administrative authority with a single, consistent routing policy, identified by a globally unique AS number. The internet is roughly a hundred thousand of them exchanging reachability information, and BGP is the protocol they use to do it. Interior and exterior routing The distinction organizes the whole topic. Interior gateway protocols — OSPF, IS-IS, EIGRP, RIP — run inside one autonomous system. Their job is to find the best path by a technical metric such as cost or hop count, and they converge quickly because everyone inside the AS is cooperating. Exterior gateway protocols — BGP in practice — run between autonomous systems. Their job is to enforce policy , not to find the technically shortest path. A network may prefer a longer route because it is cheaper, or refuse to carry traffic between two neighbours because it has no contract to do so. That is why BGP is described as a path vector protocol rather th...

FHRP Explained: HSRP, VRRP and GLBP for Gateway Redundancy

A host knows exactly one default gateway. If that router fails, the host does not look for another — it simply cannot reach anything off its own subnet. First Hop Redundancy Protocols solve this by letting two or more routers share a single virtual gateway address, so the host's configuration never has to change and failover happens without the host knowing. The problem Redundant links, redundant switches, and redundant uplinks all count for nothing if every host on the segment points at one router's address. That address is a single point of failure sitting in the configuration of every device. Changing it on failure is not an option: hosts learn it from DHCP and hold it for the lease duration, and statically configured devices never change it at all. The gateway address has to stay constant while the router behind it changes. How the virtual gateway works Two or more routers share a virtual IP address and a virtual MAC address. Hosts are configured — usually via DH...

SVIs and Inter-VLAN Routing: From Router-on-a-Stick to Layer 3 Switching

VLANs separate broadcast domains, and traffic between them has to be routed. A switch virtual interface is a logical layer 3 interface on the switch itself, giving a VLAN a gateway address without any external router in the path. It is how nearly every campus network does inter-VLAN routing. The three ways to route between VLANs A router per VLAN — a physical router interface in each VLAN. Obviously correct, obviously unscalable: twenty VLANs needs twenty interfaces. Router-on-a-stick — one router interface carrying a trunk, divided into subinterfaces, one per VLAN, each with an address and a VLAN tag. It works, and every packet crossing between VLANs travels up the trunk to the router and back down, so the trunk carries the traffic twice and becomes the bottleneck. Fine for a small site, poor above that. Switch virtual interfaces — the switch itself holds a layer 3 interface per VLAN and routes between them in hardware, at line rate, with no packet leaving the...

NAT64 and DNS64: Letting IPv6-Only Clients Reach IPv4 Services

An IPv6-only client cannot talk to an IPv4-only server. The protocols are not interoperable, and a client with no IPv4 address has no way to form the packet. NAT64 and DNS64 solve this together, and they are the mechanism behind IPv6-only mobile networks that still reach the entire IPv4 internet. The two halves DNS64 handles the lookup. When an IPv6-only client asks for a name, the DNS64 resolver queries normally. If a AAAA record exists, it returns it and nothing special happens. If only an A record exists, the resolver synthesises an AAAA record by embedding the 32-bit IPv4 address inside a designated IPv6 prefix — commonly the well-known prefix reserved for this purpose — and returns that. The client now has an IPv6 address to connect to, and it has no idea the destination is actually IPv4. NAT64 handles the traffic. The synthesised address routes to the NAT64 gateway, which recognizes the prefix, extracts the embedded IPv4 address, and performs stateful translati...

Split Horizon, Route Poisoning and Hold-Down Timers: Loop Prevention

Distance vector routing protocols learn routes from their neighbours and pass them on. That works until a network goes down and a router learns about the dead destination from a neighbour it originally told — at which point two routers can point at each other indefinitely, incrementing the hop count and forwarding packets in a circle. Split horizon and its companions exist to stop exactly that. Counting to infinity The failure works like this. Router A is connected to network X. A tells B about X at one hop; B tells C at two hops. Network X fails and A removes the route. Before A can inform B, B advertises its own route to X back toward A. A now believes it can reach X through B at three hops, and tells B so. B updates to four, A to five, and the count climbs while packets for X loop between them. The base defence is a maximum metric — sixteen hops is unreachable in RIP — which caps the damage but does not prevent it. The loop still forms and still wastes time con...

BGP Security: Prefix Filtering, RPKI and Route Origin Validation

BGP was designed among a small number of cooperating operators who knew each other, and it kept that trust model as the internet grew to a hundred thousand autonomous systems. A network announcing a prefix is generally believed, and everything below is the retrofitted machinery for deciding when not to believe it. The protocol itself is covered under autonomous systems and BGP . The two failure modes Prefix hijacking is announcing address space you do not hold. Traffic destined for that space arrives at you instead, which allows interception, redirection or simply a blackhole. Announcing a more specific prefix wins over a less specific one regardless of path length or policy, which is what makes the attack reliable — a /24 beats the legitimate holder's /16 everywhere. Route leaks are a policy failure rather than a forgery. A network advertises routes it should not — typically announcing one peer's routes to a provider — and briefly becomes transit for traffic fa...

Administrative Distance: How a Router Picks Between Two Sources for One Route

A router may learn the same destination from several places at once — a static route, OSPF, and BGP all offering a path to the same network. Their metrics are not comparable, since a hop count and an OSPF cost measure different things. Administrative distance is the tiebreaker: a number expressing how much the router trusts each source , with lower being more trusted . The values to know Directly connected interface: 0 . Static route: 1 . External BGP: 20 . Internal EIGRP: 90 . OSPF: 110 . IS-IS: 115 . RIP: 120 . External EIGRP: 170 . Internal BGP: 200 . Unknown or untrusted: 255 , which means the route is never installed. The ordering encodes a judgement about reliability. A directly connected interface is fact. A static route was configured deliberately by an administrator, so it is trusted next. Among dynamic protocols, those carrying richer information rank above simpler ones, which is why OSPF beats RIP. Two values reward attention. External BGP at 20 is more trusted tha...

NHRP and DMVPN: How Spoke-to-Spoke Tunnels Build Themselves

Next Hop Resolution Protocol solves one problem: on a network where every site has a dynamic or unknown public address, how does one spoke learn how to reach another directly instead of routing everything through headquarters? NHRP is the lookup service that answers that, and DMVPN is the architecture built on top of it. The problem with hub-and-spoke A traditional site-to-site VPN builds a tunnel between two known endpoints. With twenty branch sites, connecting every site to every other requires 190 tunnels, each configured by hand, and every new site multiplies the work. So most deployments settle for hub-and-spoke: every branch tunnels to headquarters, and traffic between two branches goes branch to hub to branch. That is simple to configure and wasteful in practice — it doubles latency for site-to-site traffic, consumes hub bandwidth twice for every flow, and makes the hub a bottleneck for voice and video between offices that may be physically close together. What NHRP d...

NAT vs PAT: How Address Translation Works and Why Networks Need It

Network Address Translation rewrites IP addresses in packet headers as they cross a router boundary. Port Address Translation extends that by rewriting port numbers too, so many internal hosts can share one public address. On the Network+ exam the distinction between the two is a reliable question, and the reasoning behind it explains most of how home and office internet access actually works. Why translation exists IPv4 has roughly 4.3 billion addresses and far more than that many connected devices. The reserved RFC 1918 private ranges — 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16 — can be reused by every organization simultaneously because they are never routed on the public internet. That reuse is only useful if private hosts can still reach the internet, and that is the job of translation. The router swaps the private source address for a public one on the way out and reverses the swap on the way back. The three flavors Static NAT maps one private address to o...