Determine whether the destination is on-link
Before investigating a router, confirm how the host classifies the destination. A 10.84.1.20 host incorrectly configured with /16 treats 10.84.2.30 as on-link even though the design uses /24 and separate VLANs. Without proxy ARP, looking directly for the destination on-link can fail. A host mask does not merge VLANs. Compare address, prefix, gateway, and intended configuration. A correction must respect IPAM and the actual network; changing only the gateway may not fix an on-link classification that prevents using it for that destination.
Size and aggregate without expanding scope
On a conventional LAN, /27 has 32 addresses and 30 hosts after network and broadcast. Thirty devices plus one gateway need 31, so /26 is the smallest sufficient option under the stated conditions. For aggregation, check alignment and the exact set. Four consecutive /24s from 10.96.20.0 through 10.96.23.0 fit an aligned /22. Networks 20, 21, 24, and 25 differ: two /23s cover those pairs exactly. A broader aggregate can include unauthorized sources. Address arithmetic helps reveal the effect of simplifying rules.
Inspect the table that actually forwards
The exercises use installed usable routes without policy routing, ECMP, or VRF ambiguity. Among matching default, /16, and /25 routes, the more-specific /25 wins. Choosing a protocol to install a route is a separate stage. After migrating a /16, a residual /24 can continue sending some traffic along the old path. Do not assume an aggregate removes existing prefixes. Capture the table and decision for an affected and a healthy destination, recording the observed device and time.
Read ACLs as ordered decisions
In this exercise’s first-match stateless ACLs, a broad permit before a specific deny can shadow the denial. A rule’s name or text does not establish that evaluation will reach it. Write the flow’s source, destination, protocol, ports, and direction, then follow the order. An old permit-any rule for S/443 can still authorize clients outside subnet A. Before removing it, check legitimate dependencies and approved scope. Do not turn a security change into an unanalyzed interruption for other consumers.
Follow return traffic and test denial
A received SYN and emitted SYN-ACK in the server capture do not prove the response reached the client. Compare return-path routes and filters between observation points. An isolated capture does not automatically identify the component losing the packet. To accept an access-restricting change, exercise a complete authorized connection and a source that should be denied. Confirm the matching rule and application rather than only ping. With stateless rules, outbound permission does not automatically create a session authorizing every return packet.
Convert counters into useful rates
An increase of 75 million octets over 30 seconds represents 20 million bits per second. On a nominal 100 Mbit/s interface, that is 20% under the simplified calculation. The model excludes uncounted overhead and depends on no reset or wrap. If a counter falls, investigate discontinuity before publishing a negative rate. A 30-second average can also hide shorter bursts. Record the interval and relate rate, drops, and latency; a low average does not prove the absence of transient congestion.
Separate calculated delay from actual performance
Sending 1500 bytes at 100 Mbit/s takes 120 microseconds in the model without overhead. That is one packet’s serialization rather than complete latency, RTT, or transfer duration. Propagation, queuing, processing, and other hops add components. During an incident, increasing speed does not necessarily fix an incorrect route or an ACL denying return traffic. Close the change with evidence of intended flows, denials, and business outcomes. This lesson’s models check arithmetic and decisions without claiming measured performance on actual equipment.
75,000,000 octets over 30 seconds give 20 Mbit/s. A residual /24 can divert traffic despite a new /16.
Common pitfalls
Counting network and broadcast as hosts, aggregating unrelated networks, ignoring earlier rules, or using averages as proof of no bursts.
Related topics: Addressing and routing · Security and observability
Validate the actual destination and source set covered as well as the complete path followed by each flow.
Reference: Requirements for IP version 4 routers · N10-009 V9