An IPv4 routing table holds 0.0.0.0/0, 10.0.0.0/8, 10.1.0.0/16 and 10.1.1.0/24; which entry forwards a packet to 10.1.1.7, and why?
answer
- more than one entry can match
- compare prefix lengths, not position
- count the matching leading bits
- the default route matches everything
basics
~10 s10.1.1.0/24 forwards it. All four entries match 10.1.1.7, and IPv4 forwarding picks the longest matching prefix, so the most specific route wins; the default route 0.0.0.0/0 is used only when nothing longer matches.
solid answer
~40 sA route matches a destination when the destination's first *N* bits equal the route's first *N* bits, where *N* is the prefix length. `10.1.1.7` matches `0.0.0.0/0` (zero bits to compare), `10.0.0.0/8` (first byte 10), `10.1.0.0/16` (10.1) and `10.1.1.0/24` (10.1.1). The router keeps only the matches with the largest prefix length, so `10.1.1.0/24` wins. RFC 1812 names these steps **Basic Match** and **Longest Match** and requires them, and RFC 4632 states that Internet forwarding is longest-match. Prefix length comes first: a better metric or a more preferred route source only breaks ties between routes for the **same** prefix. With the same table, `10.1.2.9` goes via the `/16`, `10.200.0.5` via the `/8` and `198.51.100.20` via the default route.
code
pseudocode · 15 linesfunction lookup(table, dst):
best = none
for route in table:
mask = leading_ones(route.length) # /0 -> all zeros
if (dst AND mask) == (route.prefix AND mask):
if best is none or route.length > best.length:
best = route
if best is none:
discard packet
send ICMP Destination Unreachable (Network Unreachable)
return none
return best # next hop + outgoing interface
# dst 10.1.1.7 against 0.0.0.0/0, 10.0.0.0/8,
# 10.1.0.0/16, 10.1.1.0/24 -> best = 10.1.1.0/24go deeper
Recall the rule in one line: of all routes that match, the one with the longest prefix wins, and the default route matches everything but loses to any other match.
Show the bit comparison on the overlapping entries, place each test address correctly, and state the order: prefix length first, then source preference, then metric.
Use longest match operationally: a more specific route deliberately pulls a slice of traffic, and an aggregate without a discard route can loop traffic for unused space.
Weigh aggregation against precision: shorter announcements keep tables small, while more specifics give control but grow every router's table across the network.
## What "matching" means A **route** is a **prefix** plus a **prefix length**: `10.1.0.0/16` means "every address whose first 16 bits equal those of 10.1.0.0", which is the range 10.1.0.0 to 10.1.255.255. A packet's **destination address** matches a route when its leading bits, as many as the prefix length says, are equal to the route's. The prefix length is also written as a **mask**: `/16` is 255.255.0.0. RFC 1812 section 5.2.4.3 describes the lookup as **pruning**. The router starts with every route in its forwarding table as a candidate and removes candidates rule by rule: 1. **Basic Match** discards every route whose significant bits differ from the destination's. 2. **Longest Match** keeps, from what remains, only the routes with the **largest** prefix length. 3. Later rules (type of service, best metric, vendor policy) only choose among routes that survived the first two. If the set ever becomes empty, the packet is discarded and an ICMP Destination Unreachable is generated. RFC 4632, the current CIDR specification (it obsoletes RFC 1519), states the same principle: "Forwarding in the Internet is done on a longest-match basis." ## The table, applied to several destinations The table under discussion, with illustrative next hops: | Prefix | Next hop | Outgoing interface | |---|---|---| | `0.0.0.0/0` (default) | `203.0.113.1` | uplink | | `10.0.0.0/8` | `172.16.0.2` | link A | | `10.1.0.0/16` | `172.16.1.2` | link B | | `10.1.1.0/24` | `172.16.2.2` | link C | | Destination | Routes that match | Winner | |---|---|---| | `10.1.1.7` | `/0`, `/8`, `/16`, `/24` | `10.1.1.0/24` via `172.16.2.2` | | `10.1.2.9` | `/0`, `/8`, `/16` | `10.1.0.0/16` via `172.16.1.2` | | `10.1.0.200` | `/0`, `/8`, `/16` | `10.1.0.0/16` via `172.16.1.2` | | `10.200.0.5` | `/0`, `/8` | `10.0.0.0/8` via `172.16.0.2` | | `198.51.100.20` | `/0` | default via `203.0.113.1` | Note `10.1.0.200`: it starts with "10.1" but its third byte is 0, so it is outside `10.1.1.0/24` (10.1.1.0 to 10.1.1.255) and falls to the `/16`. ## Why the most specific route wins A longer prefix describes a smaller set of addresses, so it carries more precise knowledge about where those addresses live. That is what makes **aggregation** work: a provider can announce one short prefix for a large block, and a more specific route for a part of that block that lives elsewhere (for example a multi-homed customer) still attracts the traffic for that part. RFC 1812 lists the resulting preference order: host routes first, then network prefixes in order of decreasing length, and the **default route**, "by definition the route whose prefix length is zero", last. RFC 4632 adds a rule for the router that announces an aggregate: packets matching the aggregate but none of its more specific routes must be **discarded** (the aggregate's next hop is a "null destination"), or they would follow a shorter route back upstream and loop. ## Where metric and route source fit - **Prefix length is decided first**, always. A `/24` learned from the least preferred source still beats a `/16` from the most preferred one for addresses inside the `/24`. - Among routes for the **same** prefix from different sources, implementations apply a source preference (often called administrative distance); that choice belongs to route selection, not to the per-packet lookup. - Within one routing protocol, the **metric** breaks ties for the same prefix. ## How routers make it fast The pruning description is conceptual. Real routers store routes in structures such as binary tries, where walking the destination's bits from the top visits every matching prefix and the deepest one reached is the answer, or in hardware that compares all prefixes at once. These are implementation choices; the result must equal the longest match. The same rule is a deliberate tool. Configuring or announcing a more specific route for one slice of an address block pulls that slice's traffic onto a different path without touching the rest of the block. ## Common mistakes - Treating the table as an ordered list where the first match wins. - Letting a lower metric or a "better" protocol override a longer prefix. - Reading `10.1.0.200` as inside `10.1.1.0/24` because both "start with 10.1". - Thinking the default route is checked first because it appears at the top of a printed table. - Forgetting that a `/32` host route is the most specific route possible and beats every network prefix for that one address.
- Can an IPv4 route with a better metric, or from a more preferred source, beat a route with a longer prefix?No. RFC 1812 applies Longest Match before Best Metric, and source preference (administrative distance, an implementation concept) only compares routes for the same prefix. For any address inside `10.1.1.0/24`, that `/24` wins over `10.1.0.0/16` whatever their metrics or sources. Metric and source preference decide which `/24` is installed when several sources offer one.
- What must an IPv4 router that announces an aggregate do with packets that match the aggregate but none of its more specific routes?RFC 4632 says it must discard them: the aggregate's next hop should be the null destination. Otherwise such a packet would match a shorter route, often the default, and be sent back upstream, where the upstream router's copy of the aggregate sends it straight back. The packet would bounce until its `TTL` ran out.
A sorting office has four rules on the wall: anything abroad goes to the airport, anything for this country to the national hub, anything for this city to the city depot, anything for one street to that street's carrier. A letter for a house on that street satisfies all four rules, and the clerk uses the street rule because it is the most specific, wherever on the wall it hangs.
saying these in an interview costs you the question
- The router uses the first route in the table that matches the destination.
- The default route wins because it is listed and checked first.
- A lower metric on 10.0.0.0/8 lets it beat the /24 for 10.1.1.7.
- A /8 is preferred because it covers more addresses than a /24.
- 10.1.0.200 is inside 10.1.1.0/24 because both start with 10.1.