TT Lab
Get started
Learn Learning paths Courses

Addresses, Subnets and Gateways

Read and Compute the Routing Table

Continue in TT Lab

Goal

You read addresses, calculate subnets, and ask the kernel directly which way a packet will go out. Firewall rules and network policies all stand on top of this calculation.

Why it matters

Reports that "only some ranges fail" are almost always a routing or mask-calculation problem. But if you cannot read a routing table, you do not even know what to look at.

Step 4 is especially important. ip route get is a command that asks the kernel directly instead of reading the table by eye and reasoning about it. It is more accurate than human reasoning, and the answer comes back immediately.

Steps

  1. Why is my address a /32 → /root/net/01-addr.txt
  2. Subnet calculation for the three given ranges → /root/net/02-subnet.txt
  3. The routing table → /root/net/03-route.txt
  4. Two runs of ip route get → /root/net/04-get.txt
  5. Explain longest prefix match → /root/net/05-longest.txt
  6. Tell private from public → /root/net/08-private.txt

Notes

My address has an odd prefix

Look at the address with ip -o addr show eth0. The prefix will be /32 — that is not a typo.

Write two lines in /root/net/01-addr.txt: (1) the address/prefix exactly as shown, and (2) one line on why it is /32. Hint: the CNI in this cluster is Cilium, and instead of giving the Pod a subnet it gives a single address and announces the way out separately as an on-link route. So the concept of "a neighbor in the same subnet" does not exist for a Pod.

Calculate the subnets

This Pod's address is a /32, so there is nothing to calculate; practice with the given ranges instead. Write three lines to /root/net/02-subnet.txt, each in the form <CIDR> <네트워크주소> <브로드캐스트> <호스트개수> (CIDR, network address, broadcast address, number of hosts).

The ranges to calculate: 192.168.219.0/26, 10.10.0.0/20, 172.16.5.128/25

Work them out by hand, then check with python3 -c "import ipaddress; n=ipaddress.ip_network('192.168.219.0/26'); print(n.network_address, n.broadcast_address, n.num_addresses-2)".

The routing table

Save the whole output of ip route to /root/net/03-route.txt. It must include the default line.

Ask the kernel directly

Ask twice. ip route get 8.8.8.8 (outside) and ip route get <게이트웨이 주소> (on-link; the gateway address). The gateway address is in the default via ... line you saved in step 3.

Save both results to /root/net/04-get.txt. One has via and the other does not — that difference is the distinction between "goes through the gateway" and "is sent directly."

Longest prefix match

Two lines in /root/net/05-longest.txt. (1) If both 10.0.0.0/8 and 10.244.0.0/16 exist, which one does 10.244.1.5 go to? (2) Why? Include the name of the rule in your answer.

Separate the name from the connection

This is practice in breaking "it doesn't work" into layers. Two lines in /root/net/06-dns.txt. (1) The result of getent hosts localhost. (2) A one-line explanation of what happens when you try getent hosts nowhere.invalid. A name that does not resolve and a connection that does not work are different problems, and to the user both look like the same "it doesn't work."

What is listening

Use ss -ltnp to look at the TCP ports in LISTEN. Save the result to /root/net/07-ports.txt. This Pod has no privileges, so process names may not show, and that is also normal — the list of ports is all you need.

Tell private ranges from public ones

Five lines in /root/net/08-private.txt. Each line has the form <주소> <private|public> (address, then private or public). The addresses to classify: 10.1.2.3 / 172.20.5.6 / 172.32.0.1 / 192.168.100.1 / 100.100.1.1. The boundary of the 172 range and the CGNAT range are the traps.