← TCP/IP: fundamentals and diagnosis
02 / 6 · 40 MIN

Routes and next-hop resolution

Connect more-specific prefixes, policy, and local neighbours.

Concept and mechanism

Within the eligible table, a longer-prefix route is preferred when it matches the destination. A /25 can therefore take precedence over a /24 that also includes it. However, policy routing can first choose another table according to source or other fields. On Linux, rules are processed by increasing numeric priority; the main table alone may not explain the real flow. Compare the application actual source with the manual test source. For a remote IPv4 destination over Ethernet, the host normally resolves the selected local gateway MAC while the IP destination still identifies the remote recipient.

Guided application

ARP does not cross routers to discover the final server MAC. IPv6 uses Neighbor Discovery over ICMPv6 for link-discovery functions. Interpret neighbour entries as states: STALE is not FAILED and does not establish that every request failed. In an exercise, a test from one source works while the application using a secondary address fails. Inspect rules and the selected route for that flow, then correlate forward and return traffic. A valid local route does not establish that the return path or filters are correct. Avoid copying every route from a healthy host: differences can reflect intentional isolation and design. Collect comparable evidence before proposing change.

IN PRACTICE

The /25 route for 198.51.100.128 includes 198.51.100.170; first establish that policy consults that table.

Common pitfalls

Main as a universal table; ARP to the remote destination; STALE as failure; assuming symmetric return.

Related topics: Addresses, prefixes, and scope · Transport, acknowledgement, and messages · States, queues, and flow control

Take this idea with you

Follow policy selection, the selected route, and next-hop resolution.

Create account

Reference: Linux routing policy rules · DR TCP/IP 2026-09; TCP RFC 9293; IPv6 RFC 8200 with RFC 9673 update; Linux socket and iproute2 guidance