6 ms·
While 3.2.1.0 is a valid IP address, some users might experience problems with IP address ending in 0. It would not be a good idea to use 3.2.1.0 if you want be
by Ocha 8y ago
While 3.2.1.0 is a valid IP address, some users might experience problems with IP address ending in 0. It would not be a good idea to use 3.2.1.0 if you want best compatibility with all available hardware/software on the market.
- TazeTSchnitzel 8y agor-really? What do people do with routers that use 192.168.1.0?
- eli 8y agoIt's probably less of an issue when you're on a local network with the device you're trying to connect to. That said, I think 192.168.0.1 (ending in a 1) is much more common.
- isostatic 8y agoA /23 with the router in the middle of it? Surely that can't be common. If someone actually chose that (to be annoying or security through obscurity or whatever) then they know what they're doing DHCP giving out a client address of 192.168.1.0 in the middle of a lagre block sure, but a router?
- dcow 8y agoRouters being the “bottom of the block” in a subnet is just convention. In fact I’d say someone with a router in the “middle” of a block probably knows exactly what they are doing.
- isostatic 8y agoAnd thus would be able to change it if they actually had a problem with ip stacks failing on valid .0 or .255 ips
- floatingatoll 8y agoTo potentially clarify here: Many home routers issue IPs using the follow netblock: Network: 192.168.1.0 Netmask: 255.255.255.0 (/24) Broadcast: 192.168.1.255 Gateway: 192.168.1.1 (the first valid IP in that block) or less often .254 (the last valid IP in that block) So for the past thirty years, nearly _every_ network block issued by _any_ network admin used /24, to the point that some things simply refuse .0 and .255 as valid IP addresses. The suggestion upstream is to set up the IP 3.2.1.0, within _any_ network block that can contain it legally. If you adhere to strict netmasking, that'd be (this is from memory, correct me if I'm wrong): Network: 3.2.0.0 Netmask: 255.255.254.0 (/23) Broadcast: 3.2.1.255 Which would provide a contiguous block of valid IPs from 3.2.0.1 through 3.2.1.254, _including_ the two perfectly valid IPs 3.2.0.255 and 3.2.1.0. Those valid IPs end in .255 and .0, which is completely legal since they're in the middle of a /23, and the default gateway wouldn't be anywhere near them. A lot of human-operated networks will blacklist issuing .0, .1, .254, .255 on the theory that it's simpler to just prohibit them and lose 4 IPs per /24 within a block, than deal with what's truly possible for a /23 or wider block. EDIT: Public BGP requires /24 or wider, and /24 cannot contain .0 or .255 as a valid IP, so the next widest is /23, which can contain even-numbered .x.255 and .x+1.0. If you're doing this on an internal network that permits narrower subnets, the narrowest available would be a /30, based (irregularly) on either .1.254 or .1.255: Network: 3.2.0.254 (or .255) Netmask: 255.255.255.252 (/30) Broadcast: 3.2.1.1 (or .2) With 3.2.1.0 as the live IP and either 3.2.0.255 or 3.2.1.1 as the in-network gateway for that device.
- zamadatix 8y ago> Public BGP requires /24 or wider, and /24 cannot contain .0 or .255 as a valid IP That requirement is about how you advertise your routes not how you subnetted the internal network. .0 and .255 of your advertised /24 can work fine as /32s on the server. Using the internet FW to NAT the network and broadcast addresses is another common trick to get more addresses, particularly when you only get an e.g. /29 from a carrier who is just routing that /29 to your specified next hop and 2 more addresses is a big bump.
- floatingatoll 8y agoYou can also use a fake IP for the default gateway on a wholly different segment with local segment ARP, or an IPv6 default router with 4-wrapping, or set up a router that uses promiscuous mode to capture all packets it receives from your “default route eth0” host. These are all irregular solutions, though, so I didn’t want to go too deep into the confusing weeds.
- ghshephard 8y agoI wouldn't bet my life on it, but I've never experienced a problem with an IP address ending in 0, and I've been using them for over 10 years. Our primary VPN end-point used to end in .0 - so we had lots of opportunity to find chance for breakage. :-)
- ryan-c 8y agoI have, actually. Most of our networks were /23s, and the syslog server was a .0 in the middle of one. An SMS sending appliance we bought would not accept IPs ending in .0. Fortunately, the check was client-side in javascript, and once overridden, everything worked.
- nathancahill 8y ago> in javascript Spotted your problem.
- duskwuff 8y agoIIRC, IPs ending in .0 or .255 were unreachable from some older Windows systems.
- oasisbob 8y agoThat's been my experience too. Even in 2003, the network I was involved in was handing out .0s out of larger CIDR blocks in DHCP leases with no issues.
- wpietri 8y agoDo you have an example? I could possibly imagine this being a problem on a local /24, in that after you apply the netmask the local part is all zero bits. But for a remote DNS server, I cannot fathom how this could be a problem.
- johnklos 8y agoAnything that cares about the zeroth IP of a destination not on the local subnet is broken. Anything that caters to broken is worrying about the wrong things.
- crunchlibrarian 8y agoCatering to the broken is like 90% of every developer and data scientist's day. I've spent the past two weeks just trying to fix some horribly wrong/invalid data that is absolutely positively guaranteed to always be correct due to certain standards and lots of money and one of the biggest best tech companies in the world stands behind it. Guess what it's still broken they just refuse to admit it.
- harryh 8y agoJon Postel (who wrote an early specification) of TCP would like to have a word with you: "be conservative in what you do, be liberal in what you accept from others"
- oxguy3 8y agoI like the spirit of this, but the problem is that it only works if everyone operates at least somewhat in line with it. If you're liberal in what you accept, then people are going to start being liberal in what they send, and soon we'll have a proper mess on our hands. And there's no takebacks -- once you start permitting something, you can't take it away later, or you'll break things. You're creating more legacy requirements that may cause you problems when you try to evolve in the future. As a web developer, I can only dream of how clean web standards might be today if the browsers of yore were a bit more conservative.
- floatingatoll 8y agoCloudflare's work with 1.1.1.1 has demonstrated not only that it's _possible_ to use a previously-unusable IP address, but that it's _valuable_ to do so because it compels reporting of – and repair of – broken hardware and software on the market.
- PhantomGremlin 8y agoThe cynic in me thinks that inbound traffic on 1.1.1.1 is "valuable" mostly to help balance Cloudflare's inbound vs outbound data flows. This balance is important in deciding whether their peering is settlement free. They're a CDN and send out a lot of bits, so every last bit of inbound traffic helps. Or am I totally off base on this?
- Something1234 8y agoI'm 95 percent sure that every dns response is bigger than the request, so it might not help much. Although if they're getting a lot of garbage in it might be helpful.
- mastazi 8y agoIt depends on what methodology is used to classify traffic as inbound/outbound. The large DNS response in your example counts as outbound packets, but it's part of an inbound TCP connection. I don't know how peering agreements work.
- Something1234 8y agoInteresting. I would have thought that they would go with the simplest measure possible, bytes in vs bytes out.
- oAlbe 8y agoPardon the ignorance, but I'm curious: why is it important for them (or anybody) to receive inbound traffic, given they offer 1.1.1.1 for free? And also what does it mean "This balance is important in deciding whether their peering is settlement free."?