On one IPv4 Ethernet segment, how do hosts 192.0.2.40/24 and 192.0.2.140/25, both using gateway 192.0.2.254, reach each other, and what breaks?
answer
- each host uses its own mask
- AND the destination, compare networks
- one direction direct, one via router
- a Redirect that gets discarded
basics
~20 sThe /24 host finds 192.0.2.140 inside its own network and delivers directly; the /25 host ANDs 192.0.2.40 with 255.255.255.128, gets 192.0.2.0, not its 192.0.2.128, and sends via the router - an asymmetric path that stateful filtering breaks.
solid answer
~50 sCall 192.0.2.40/24 host A and 192.0.2.140/25 host B. Each host decides on-link versus remote by ANDing the destination with its *own* mask and comparing the result with its own network (RFC 1122, section 3.3.1.1). A: `192.0.2.140 AND 255.255.255.0 = 192.0.2.0`, its own network, so it resolves B's link-layer address and sends directly. B: `192.0.2.40 AND 255.255.255.128 = 192.0.2.0`, but B's network is `192.0.2.128`, so B sends everything for A to `192.0.2.254`. The router forwards it back out the same interface and may send B a Redirect naming A, but RFC 1122 says B SHOULD discard a Redirect whose new gateway is not on its own subnet. So A to B is direct and B to A hairpins through the router: it can work, but a stateful filter on the router sees half of each conversation and may drop it. Hosts in .129 to .253 are unaffected. The fix is B's mask.
go deeper
Remember that a host decides whether a destination is local by ANDing it with its own mask, so a wrong mask changes which traffic goes to the router.
Work the AND in both directions for any pair of hosts and say which side sends directly and which side uses the gateway.
Diagnose the asymmetric-path symptoms - one-sided failures, hairpinned traffic, ignored Redirects, stateful drops - back to a mask mismatch, and fix it at the configuration source.
Prevent the class of error: make the segment's prefix come from one authoritative source, so hosts are not hand-configured with masks that disagree with the link.
## The decision every IPv4 host makes Before sending, an IPv4 host decides whether the destination is on its own link or must go through a router. RFC 1122 (section 3.3.1.1) makes the algorithm mandatory: 1. Take the **address mask** configured with the sending interface's address. 2. AND the destination address with that mask, and compare the result with the host's own address ANDed with the same mask. 3. If they match, the destination is **on-link**: resolve its link-layer address (with ARP, on Ethernet) and send directly. 4. If not, the destination is **remote**: send the datagram to a gateway. The point that matters here: each host uses **its own mask**. Nothing on the wire tells a host what mask its neighbour was given, so two hosts on one segment can disagree about who is local. ## Working the scenario Call `192.0.2.40/24` **host A** and `192.0.2.140/25` **host B**; both use the router at `192.0.2.254`. B's mask, `255.255.255.128`, makes B believe its subnet is `192.0.2.128/25`, usable `.129` to `.254`. A believes the segment is `192.0.2.0/24`. | Direction | Sender's mask | Destination AND mask | Sender's own network | Decision | |---|---|---|---|---| | A to B | 255.255.255.0 | 192.0.2.140 gives 192.0.2.0 | 192.0.2.0 | on-link, direct | | B to A | 255.255.255.128 | 192.0.2.40 gives 192.0.2.0 | 192.0.2.128 | remote, via 192.0.2.254 | | B to 192.0.2.200 | 255.255.255.128 | 192.0.2.200 gives 192.0.2.128 | 192.0.2.128 | on-link, direct | ## What the asymmetric path does - **A to B works directly.** B accepts the datagrams: a datagram addressed to one of B's own addresses is B's, whatever subnet its source is in. - **B to A goes through the router.** The router sees a destination on its connected /24 and forwards the packet straight back out the interface it arrived on, so every B-to-A packet crosses the segment twice. - **The Redirect does not cure it.** RFC 1812 permits a router to send a host Redirect only when it forwards a packet out the interface it came in on and the source is on the same subnet as the next hop - exactly this case - so B may be told to use A itself as the next hop. RFC 1122 says a host SHOULD silently discard a Redirect whose new gateway is not on its own connected subnet, and by B's mask A is not. - **Stateful filtering breaks it.** A filter on the router that tracks connections sees only one direction of each conversation. For a TCP connection A opens, the router sees B's SYN-ACK but never A's SYN, and a strict filter drops it. The usual report is "it works from one side only" or "some connections hang". With no stateful filter in the path, the pair talks, and the main cost is the router carrying traffic that should never have reached it - which is why this mistake can survive for months. ## Who else is affected - Hosts numbered `192.0.2.1` to `192.0.2.127`: the same asymmetry as A. - Hosts numbered `192.0.2.129` to `192.0.2.253`: both sides agree they are on-link, so traffic with B is direct both ways. - Destinations off the segment: unaffected, because B's gateway, `192.0.2.254`, lies inside B's /25. ## The opposite mistake: a mask too wide Suppose the segment really is `192.0.2.0/25` with its router at `192.0.2.1`, and `192.0.2.128/25` is a different segment behind that router. A host misconfigured as `192.0.2.50/24` computes `192.0.2.200 AND 255.255.255.0 = 192.0.2.0`, its own network, so it tries to resolve 192.0.2.200 on the local link instead of sending to the router. Nobody on the link owns that address, so - unless the router answers on the far host's behalf with proxy ARP - that host cannot reach the other half while everything else works. ## Diagnosing it from the arithmetic 1. Collect both ends' addresses **and masks**, not only the one you suspect. 2. AND each destination with the **sender's** mask, in both directions. 3. If the two directions disagree, the path is asymmetric: look for traffic hairpinning through the router and for Redirects being sent and ignored. 4. Fix the mask so every host agrees with the segment's real prefix. A segment has one prefix, and every host on it must be configured with it.
- Why doesn't the router's ICMP Redirect fix the IPv4 mask mismatch between 192.0.2.40/24 and 192.0.2.140/25?The router may send B a host Redirect naming 192.0.2.40 as the better next hop, because it is forwarding the packet back out its arrival interface and B is on the same subnet as A from the router's view. But RFC 1122 says a host SHOULD silently discard a Redirect whose new gateway is not on its own connected subnet, and by B's /25 mask, 192.0.2.40 is not.
- What symptom does an IPv4 host see when its mask is wider than the segment's real prefix?It treats some remote addresses as on-link and tries to resolve them locally instead of sending them to the router. Nobody answers, so those destinations are unreachable from that host only, while the rest of the segment and the wider network work - unless the router covers the mistake by answering with proxy ARP.
Two neighbours disagree about where their street ends. A thinks B lives on the same street and walks letters over; B thinks A lives elsewhere and posts every reply through the sorting office, which drives it straight back to the same street.
saying these in an interview costs you the question
- Two hosts on the same switch can always reach each other directly, whatever their masks.
- A host learns its neighbour's subnet mask from the ARP reply.
- If one host's mask is wrong, traffic between the two fails in both directions.
- The router's Redirect will always teach the misconfigured host the direct path.
- Only the host with the wrong mask has trouble reaching the rest of the segment.