For IPv4 point-to-point links in a VLSM plan, when would you use a /30 and when a /31, and what did RFC 3021 change?
answer
- two endpoints, no one to broadcast to
- four addresses, two usable
- RFC 3021: both addresses are hosts
- limited broadcast only on /31
basics
~20 sA /30 has four IPv4 addresses: network, two hosts and broadcast. RFC 3021 lets both addresses of a /31 be hosts on a point-to-point link, halving the cost. Use /31 where both ends support it, /30 where one does not.
solid answer
~50 sA point-to-point link only ever has two endpoints, so a `/30` spends half its four addresses on the network and broadcast addresses. RFC 3021 (Standards Track, December 2000) says that on a point-to-point link with a 31-bit mask, both addresses - host bit 0 and host bit 1 - MUST be interpreted as host addresses, so `10.40.6.224/31` numbers both routers. Broadcast traffic on such a link MUST use the limited broadcast `255.255.255.255`, and a directed broadcast to the link becomes impossible, which RFC 3021 counts as a small security gain. Three links cost 6 addresses instead of 12; across hundreds of links that is real space. I still use a `/30` where an endpoint's implementation does not support `/31`, and RFC 3021 covers point-to-point links only - a segment that may gain a third device needs a `/29`.
go deeper
Recall the counts: a /30 has four addresses with two usable, and a /31 has two addresses that are both usable on a point-to-point link.
Explain what RFC 3021 changed: both /31 addresses are hosts, broadcast uses 255.255.255.255, directed broadcast to the link disappears, and routing protocols are unaffected.
Judge when /30 is still right: an endpoint without /31 support, a link that may gain a third device, or a two-device LAN that is not truly point-to-point.
Weigh the saving against uniformity: /31 halves link addressing at scale, but mixed support across an estate can make a single convention cheaper to operate.
## Why a point-to-point link is a special case A **point-to-point link** joins exactly two interfaces, typically two routers. Nothing else can ever sit on it, and every packet one end transmits is received by the other, so the link has no use for a broadcast address. Yet ordinary IPv4 subnetting spends two addresses in every subnet on the **network address** (host bits all zero) and the **broadcast address** (host bits all one). On a two-device link that overhead is half the subnet. ## The /30: the classic choice A `/30` has four addresses. On the link `10.40.6.224/30`: | Address | Role | |---|---| | `10.40.6.224` | network address | | `10.40.6.225` | router 1 | | `10.40.6.226` | router 2 | | `10.40.6.227` | directed broadcast | Two usable addresses out of four, on every link. RFC 3021 notes that numbered links of its day did not, in most cases, use masks longer than 30 bits, and calls the four-addresses-per-link cost unfortunate for exactly this reason. ## The /31 under RFC 3021 RFC 3021, "Using 31-Bit Prefixes on IPv4 Point-to-Point Links" (Standards Track, December 2000), changes the interpretation for this one case: 1. A `/31` leaves a single host bit, so only two addresses exist. On a point-to-point link with a 31-bit mask, both **MUST be interpreted as host addresses** (section 2.1). `10.40.6.224/31` gives the routers `10.40.6.224` and `10.40.6.225`. 2. **Broadcast traffic uses the limited broadcast**, `255.255.255.255`, which MUST be used for all broadcast traffic on such a link (section 2.2). 3. A **directed broadcast** to the link becomes impossible, since no address is left to mean "every host on this subnet" (section 2.2.1). RFC 3021 treats the loss as a small gain against directed-broadcast attacks, citing RFC 2644. 4. It updates RFC 1122 so that an endpoint of a `/31` link may use either address as its source, even though those bit patterns mean the subnet number or the directed broadcast on other links (section 3.1). 5. Routing protocols are unaffected: their peers talk using multicast, limited broadcast or unicast, none of which needs a directed broadcast (section 2.3). RFC 3021 scopes itself to point-to-point links and states that effects on other interface types are not considered. ## Side by side | | `/30` | `/31` (RFC 3021) | |---|---|---| | Addresses per link | 4 | 2 | | Usable by the two ends | 2 | 2 | | Network and broadcast addresses | reserved | none | | Directed broadcast to the link | possible | impossible | | Three links in one plan | 12 addresses | 6 addresses | | Defined for | any subnet | point-to-point links only | Apart from directed broadcast, both columns give the two routers the same service: two unicast addresses, a shared prefix that routing advertises like any other, and broadcast delivery through the limited broadcast if anything needs it. The difference is purely how much address space each link consumes. At scale the saving is large: RFC 3021's own example is a network of 500 point-to-point links, where `/31` numbering saves 1,000 addresses. In a single `/22` plan, three `/31` links free six addresses - small, but it can be the difference between a remaining `/29` and a remaining `/30`. ## When /30 is still the right call - **An endpoint does not support 31-bit masks.** Support is a property of each implementation; a device that treats the two addresses as network and broadcast will refuse the configuration or misbehave. Both ends must agree. - **The link may stop being point-to-point.** If a third device may join - a second router sharing a virtual gateway address, for example - even a `/30` is too small; that segment needs a `/29`, with six usable addresses. - **A two-host LAN is not a point-to-point link.** RFC 3021 does not cover multi-access segments, even ones that happen to hold two devices today. - **Uniform conventions.** Some operators keep `/30` everywhere so addressing conventions and tooling assumptions stay uniform; that is an operational choice, not a protocol requirement. ## The IPv6 parallel IPv6 has no scarcity reason for the trick, but the same shape exists: RFC 6164 says routers MUST support `/127` prefixes on point-to-point inter-router links, partly because a `/64` on such a link exposes the routers to neighbor-cache exhaustion attacks. Like `/31` in IPv4, it is a link-numbering choice, not a LAN design.
- On an IPv4 /31 link, how does a router send broadcast traffic such as a routing protocol message?RFC 3021 says the limited broadcast, `255.255.255.255`, MUST be used for all broadcast traffic on a point-to-point link with a 31-bit mask, because neither of the link's two addresses is a broadcast address any more. In practice most routing protocols talk to peers by multicast or unicast anyway, which RFC 3021 section 2.3 notes are unaffected.
- What alternative to a /31 does RFC 3021 mention for saving addresses on point-to-point links, and why is it less attractive?Using host addresses on both ends of the link. RFC 3021 notes it saves the same space but works only on links using PPP encapsulation, and because each end may carry an address from a different network, link and network management stop being straightforward. The `/31` keeps one shared prefix per link with the same saving.
saying these in an interview costs you the question
- A /31 has no usable addresses because both are network and broadcast.
- A /31 works on any segment, including a LAN with three devices.
- RFC 3021 is a vendor extension rather than a standards-track RFC.
- On a /31 link, broadcasts go to the link's directed broadcast address.
- Routing protocols cannot run over a /31 link.