3 ms·
> a bunch of other stuff which I don’t understand that well (metric 600, scope link, proto kernel, etc). Not understanding what those things mean hasn’t hurt me
by Hello71 8y ago
> a bunch of other stuff which I don’t understand that well (metric 600, scope link, proto kernel, etc). Not understanding what those things mean hasn’t hurt me yet.
These are pretty straightforward. metric 600 means that out of all the otherwise-identical routes, the kernel will prefer this one to one with a metric of 601 or greater. scope link means that this address is only valid on the local link (network interface). scope global means that (the kernel assumes) this address is valid on the wider Internet. proto kernel means that the kernel automatically installed this route for you because you used "ip address add x/y". Now, the "table x" part is actually really interesting, because Linux doesn't just support "a route table", it supports 256 routing tables. These are used in conjunction with policy routing in order to support source address routing, firewall mark based routing, and others. Firewall mark based routing is extremely powerful: for example: MARK all packets on port 53 whose (using BPF) first DNS query question is jvns.ca, and send those using eth1 instead of eth0. More mundanely, wg-quick from WireGuard uses this feature to bypass the VPN for the VPN packets, which allows the VPN to be used for the VPN gateway.
- eximius 8y agoRight, so you need to publish a networking textbook on this stuff, okay? If that sounds too dreary, I'd take a suggestion for one.