← Network+: networking and production diagnosis
09 / 9 · 60 MIN

Prefixes, rules, and path validation

Connect subnets, routes, ACLs, and counters to verifiable production decisions.

Determine whether the destination is on-link

Before investigating a router, confirm how the host classifies the destination. A 10.84.1.20 host incorrectly configured with /16 treats 10.84.2.30 as on-link even though the design uses /24 and separate VLANs. Without proxy ARP, looking directly for the destination on-link can fail. A host mask does not merge VLANs. Compare address, prefix, gateway, and intended configuration. A correction must respect IPAM and the actual network; changing only the gateway may not fix an on-link classification that prevents using it for that destination.

Size and aggregate without expanding scope

On a conventional LAN, /27 has 32 addresses and 30 hosts after network and broadcast. Thirty devices plus one gateway need 31, so /26 is the smallest sufficient option under the stated conditions. For aggregation, check alignment and the exact set. Four consecutive /24s from 10.96.20.0 through 10.96.23.0 fit an aligned /22. Networks 20, 21, 24, and 25 differ: two /23s cover those pairs exactly. A broader aggregate can include unauthorized sources. Address arithmetic helps reveal the effect of simplifying rules.

Inspect the table that actually forwards

The exercises use installed usable routes without policy routing, ECMP, or VRF ambiguity. Among matching default, /16, and /25 routes, the more-specific /25 wins. Choosing a protocol to install a route is a separate stage. After migrating a /16, a residual /24 can continue sending some traffic along the old path. Do not assume an aggregate removes existing prefixes. Capture the table and decision for an affected and a healthy destination, recording the observed device and time.

Read ACLs as ordered decisions

In this exercise’s first-match stateless ACLs, a broad permit before a specific deny can shadow the denial. A rule’s name or text does not establish that evaluation will reach it. Write the flow’s source, destination, protocol, ports, and direction, then follow the order. An old permit-any rule for S/443 can still authorize clients outside subnet A. Before removing it, check legitimate dependencies and approved scope. Do not turn a security change into an unanalyzed interruption for other consumers.

Follow return traffic and test denial

A received SYN and emitted SYN-ACK in the server capture do not prove the response reached the client. Compare return-path routes and filters between observation points. An isolated capture does not automatically identify the component losing the packet. To accept an access-restricting change, exercise a complete authorized connection and a source that should be denied. Confirm the matching rule and application rather than only ping. With stateless rules, outbound permission does not automatically create a session authorizing every return packet.

Convert counters into useful rates

An increase of 75 million octets over 30 seconds represents 20 million bits per second. On a nominal 100 Mbit/s interface, that is 20% under the simplified calculation. The model excludes uncounted overhead and depends on no reset or wrap. If a counter falls, investigate discontinuity before publishing a negative rate. A 30-second average can also hide shorter bursts. Record the interval and relate rate, drops, and latency; a low average does not prove the absence of transient congestion.

Separate calculated delay from actual performance

Sending 1500 bytes at 100 Mbit/s takes 120 microseconds in the model without overhead. That is one packet’s serialization rather than complete latency, RTT, or transfer duration. Propagation, queuing, processing, and other hops add components. During an incident, increasing speed does not necessarily fix an incorrect route or an ACL denying return traffic. Close the change with evidence of intended flows, denials, and business outcomes. This lesson’s models check arithmetic and decisions without claiming measured performance on actual equipment.

IN PRACTICE

75,000,000 octets over 30 seconds give 20 Mbit/s. A residual /24 can divert traffic despite a new /16.

Common pitfalls

Counting network and broadcast as hosts, aggregating unrelated networks, ignoring earlier rules, or using averages as proof of no bursts.

Related topics: Addressing and routing · Security and observability

Take this idea with you

Validate the actual destination and source set covered as well as the complete path followed by each flow.

Create account

Reference: Requirements for IP version 4 routers · N10-009 V9

CompTIA® and Network+ are trademarks or registered trademarks of CompTIA, Inc. bigsavant.com is an independent preparation platform and is not affiliated with, associated with, sponsored, authorised or endorsed by CompTIA. Content and questions are original, are not official exam questions, and completing our tests does not award or guarantee any certification. Names are used only to identify the subject. All other trademarks belong to their respective owners.