skip to content

Why do IPv4 /31 and /32 prefixes break the 2^n - 2 host rule, and what does RFC 3021 change for a /31?

level: middleimportance: should knowfreq 32%

answer

  1. two endpoints, nothing to broadcast to
  2. the rule gives zero and minus one
  3. both /31 addresses become hosts
  4. limited broadcast on the link

basics

~20 s

The minus-two rule reserves network and broadcast addresses, which would leave a /31 with no hosts. RFC 3021 makes both /31 addresses hosts on a point-to-point link, which needs no broadcast; a /32 is one address, a host route.

solid answer

~40 s

Applied blindly, `2^(32 - n) - 2` gives zero hosts for a /31 and minus one for a /32, and both are wrong. A point-to-point link only ever has two endpoints and whatever one sends reaches the other, so reserving a network and a broadcast address there wastes half of a /30. RFC 3021 (Standards Track, December 2000) says that on a point-to-point link with a 31-bit mask both addresses MUST be interpreted as host addresses; a directed broadcast to the link becomes impossible, and broadcast traffic MUST use the limited broadcast, 255.255.255.255. Both ends have to implement it. A /32 has no host bits at all: it matches exactly one address, which RFC 4632's prefix table calls a host route, used to name one destination rather than to number a link.

go deeper

for a junior

Remember the two exceptions: a /31 can hold two hosts on a point-to-point link, and a /32 is exactly one address.

for a middle

Explain why the minus-two rule fails at /31 and /32, and what RFC 3021 says about host addresses and the limited broadcast on a /31 link.

for a senior

Know that both ends must implement RFC 3021, that the RFC scopes it to point-to-point links, and where a /32 host route is the right tool.

for a principal

Judge whether halving the address cost of every point-to-point link is worth the interoperability checks across an estate with older equipment.

## Where the minus two comes from The usual host count, **2^h - 2** for *h* host bits, removes two patterns of the host part: all zeros, the subnet's **network address**, and all ones, its **directed broadcast address**. RFC 1122 (section 3.2.1.3) made both patterns illegal as ordinary host addresses and noted that every field therefore needs at least two bits. At the bottom of the scale the formula stops describing anything real: | Prefix | Addresses | 2^h - 2 | What is really usable | |---|---|---|---| | /30 | 4 | 2 | 2 hosts | | /31 | 2 | 0 | 2 hosts on a point-to-point link (RFC 3021) | | /32 | 1 | -1 | 1 address - a single destination, not a subnet of hosts | ## /31 on point-to-point links: RFC 3021 A **point-to-point link** has exactly two endpoints, and anything one end sends is received by the other, so a network address and a broadcast address have no job there. Before RFC 3021 such links were usually numbered with a /30: four addresses for two interfaces. RFC 3021 (December 2000, Standards Track) changes the rules for this one case: - With a 31-bit mask on a point-to-point link, the two possible addresses - the all-zeros and all-ones host values - **MUST be interpreted as host addresses**. - A **directed broadcast** to the link becomes impossible, and **all broadcast traffic on the link MUST use the limited broadcast**, `255.255.255.255`. The RFC counts losing directed broadcast as a small benefit against a class of denial-of-service attacks. - It **updates RFC 1122 and RFC 1812** so that those two forms may appear as source addresses when the sender is an endpoint of such a link. - The RFC finds no impact on routing protocols; what changes is how the two endpoints treat the link's two addresses. The saving is a halving: two addresses per link instead of four. The RFC's own illustration is a network with 500 point-to-point links saving 1,000 addresses. | Numbering | First link | Second link | |---|---|---| | /30 | 192.0.2.0/30: hosts .1 and .2 (network .0, broadcast .3) | 192.0.2.4/30: hosts .5 and .6 | | /31 | 192.0.2.0/31: hosts .0 and .1 | 192.0.2.2/31: hosts .2 and .3 | The /31 plan numbers two links in the space the /30 plan spends on one. ## What has to be true for a /31 to work 1. **Both endpoints implement RFC 3021.** A stack that still follows only RFC 1122's rules treats the peer's address as its subnet's network or broadcast address; it may refuse the configuration, and RFC 1122 requires a host to silently discard datagrams whose source address is invalid by those rules. 2. **The link is point-to-point.** RFC 3021 does not consider other link types. Numbering an Ethernet link that joins exactly two routers with a /31 is common practice, and whether a given implementation accepts that is an implementation choice, not a protocol rule. 3. **Nothing on the link depends on a directed broadcast**, since there is none. ## /32: one address A /32 has no host bits: the prefix *is* the address. RFC 4632's prefix table labels it a **host route**. It appears wherever exactly one address must be named: - a route to a single destination, which wins over any covering prefix by longest match; - an address on a router's virtual interface that should stay reachable whichever physical link is up; - a filter entry or an allocation for exactly one host. It is not a way to number a shared link, because no other address falls inside it. ## Confusions to avoid - "A /31 has zero hosts" applies the classic rule to a link that has no use for broadcast. - RFC 3021 does not make a /31 a general LAN prefix; it is scoped to point-to-point links. - In a /31, neither address is the network address and neither is the broadcast address. - A /32 is not "a /31 with one host"; it is a single address with no subnet around it.

  • What goes wrong if only one end of an IPv4 /31 point-to-point link implements RFC 3021?
    The other end applies RFC 1122's older rules: one of the two addresses is its subnet's network address and the other its directed broadcast. It may refuse the configuration outright, or treat the peer's address as invalid; RFC 1122 requires a host to silently discard datagrams with an invalid source address. The link fails or works in one direction only.
  • Why not number a point-to-point link with a /32 on each end instead of a /31?
    RFC 3021 discusses that option: host addresses on both ends save the same space, but only work with PPP encapsulation, and they let each end carry an address from a different network, which makes link and network management awkward. A /31 keeps both ends in one prefix with ordinary routing.

saying these in an interview costs you the question

  • A /31 has zero usable hosts, so it can never be assigned to a link.
  • RFC 3021 lets a /31 be used on any LAN segment, however many hosts it has.
  • On a /31 link, the lower address is still the network address.
  • A directed broadcast to a /31 link still works through its higher address.
  • A /32 subnet holds one network address and one broadcast address.