Addresses, Subnets and Gateways
Read and Compute the Routing Table
Goal
You read addresses, calculate subnets, and ask the kernel directly which way a packet will go out. Firewall rules and network policies all stand on top of this calculation.
Why it matters
Reports that "only some ranges fail" are almost always a routing or mask-calculation problem. But if you cannot read a routing table, you do not even know what to look at.
Step 4 is especially important. ip route get is a command that asks the kernel directly instead of reading the table by eye and reasoning about it. It is more accurate than human reasoning, and the answer comes back immediately.
Steps
- Why is my address a /32 →
/root/net/01-addr.txt - Subnet calculation for the three given ranges →
/root/net/02-subnet.txt - The routing table →
/root/net/03-route.txt - Two runs of
ip route get→/root/net/04-get.txt - Explain longest prefix match →
/root/net/05-longest.txt - Tell private from public →
/root/net/08-private.txt
Notes
- This Pod has no kernel privileges, so you cannot change routes with
ip route add. The goal is to read and calculate. - It is normal for the Pod's address to be a
/32. Cilium gives each Pod only one address and announces the way out separately as an on-link route. That is why a Pod has no "neighbors in the same subnet" and all traffic goes through the gateway. - The
python3standard library'sipaddressmodule is useful for checking your calculations. - The boundary of the 172 private range and
100.64.0.0/10are the traps.
My address has an odd prefix
Look at the address with ip -o addr show eth0. The prefix will be /32 — that is not a typo.
Write two lines in /root/net/01-addr.txt: (1) the address/prefix exactly as shown, and (2) one line on why it is /32. Hint: the CNI in this cluster is Cilium, and instead of giving the Pod a subnet it gives a single address and announces the way out separately as an on-link route. So the concept of "a neighbor in the same subnet" does not exist for a Pod.
Calculate the subnets
This Pod's address is a /32, so there is nothing to calculate; practice with the given ranges instead. Write three lines to /root/net/02-subnet.txt, each in the form <CIDR> <네트워크주소> <브로드캐스트> <호스트개수> (CIDR, network address, broadcast address, number of hosts).
The ranges to calculate: 192.168.219.0/26, 10.10.0.0/20, 172.16.5.128/25
Work them out by hand, then check with python3 -c "import ipaddress; n=ipaddress.ip_network('192.168.219.0/26'); print(n.network_address, n.broadcast_address, n.num_addresses-2)".
The routing table
Save the whole output of ip route to /root/net/03-route.txt. It must include the default line.
Ask the kernel directly
Ask twice. ip route get 8.8.8.8 (outside) and ip route get <게이트웨이 주소> (on-link; the gateway address). The gateway address is in the default via ... line you saved in step 3.
Save both results to /root/net/04-get.txt. One has via and the other does not — that difference is the distinction between "goes through the gateway" and "is sent directly."
Longest prefix match
Two lines in /root/net/05-longest.txt. (1) If both 10.0.0.0/8 and 10.244.0.0/16 exist, which one does 10.244.1.5 go to? (2) Why? Include the name of the rule in your answer.
Separate the name from the connection
This is practice in breaking "it doesn't work" into layers. Two lines in /root/net/06-dns.txt. (1) The result of getent hosts localhost. (2) A one-line explanation of what happens when you try getent hosts nowhere.invalid. A name that does not resolve and a connection that does not work are different problems, and to the user both look like the same "it doesn't work."
What is listening
Use ss -ltnp to look at the TCP ports in LISTEN. Save the result to /root/net/07-ports.txt. This Pod has no privileges, so process names may not show, and that is also normal — the list of ports is all you need.
Tell private ranges from public ones
Five lines in /root/net/08-private.txt. Each line has the form <주소> <private|public> (address, then private or public). The addresses to classify: 10.1.2.3 / 172.20.5.6 / 172.32.0.1 / 192.168.100.1 / 100.100.1.1. The boundary of the 172 range and the CGNAT range are the traps.