IP Addresses and Subnets — How Far Does Our Neighbourhood Go
In a nutshell
An IP address is divided into a network part and a host part, the subnet mask sets the boundary between them, and this boundary separates "peers you can send to directly" from "peers you must leave to the gateway".
Why this was needed
You cannot fit every host in the world in one table. A router cannot search through 4 billion entries. So a hierarchy was put into addresses. Addresses whose leading part is the same are bundled as one chunk so that "this chunk goes that way" can be written on one line.
How it works
In 192.168.10.37/24, /24 means the first 24 bits are the network part. That is, the network is 192.168.10.0 and the host part is the last 8 bits.
- The number of usable addresses is 2 to the 8th power minus the network address and the broadcast address, which is 254.
- If you split it into
/25, you get two halves, each with 126. /30has only 2 usable out of 4, so it is used for links connecting routers.
A host's decision when sending a packet is simple. It applies the mask to the destination address and to its own address, and if the network parts are the same, it is the same network, so it finds the peer's MAC address with ARP and sends directly. If they differ, it sends to the MAC address of the default gateway. The key point here is that the destination in the IP header remains the final destination and only the link layer destination is the gateway.
A router's decision is longest prefix match. If the routing table has both 10.0.0.0/8 and 10.1.2.0/24 and the destination is 10.1.2.5, it picks the more specific /24. The default route 0.0.0.0/0 has a prefix length of 0, so it is always the last candidate.
The private address ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) are not routed on the Internet. So when going out, NAT replaces the source address with a public address and remembers by port number which internal host's connection it is. Several consequences follow from the fact that NAT holds state. You cannot initiate a connection from the outside to the inside, and a connection that stays quiet for a long time is erased from the NAT table and cut off. This is a common cause of the phenomenon in which idle connections silently die after a few minutes.
What it looks like in the field
When you build a Kubernetes cluster, if the Pod CIDR, Service CIDR, and node network overlap, routing breaks silently. Traffic in the overlapping range goes to the wrong place, and the symptom appears sporadically, such as "only certain Pods can't communicate with each other". It is better to write out the range design on paper before creating the cluster. Changing it later often requires recreating the cluster.
What to check in the quiz that follows
Check whether you can calculate the network with the mask and follow the process of choosing the next hop by longest prefix match.