- Null route
-
In computer networking, a null route (blackhole route) is a network route (routing table entry) that goes nowhere. Matching packets are dropped (ignored) rather than forwarded, acting as a kind of very limited firewall. The act of using null routes is often called blackhole filtering. The rest of this article deals with null routing in the Internet Protocol (IP).
Null routes are typically configured with a special route flag, but can also be implemented by forwarding packets to an illegal IP address such as 0.0.0.0, or the loopback address.
Null routing has an advantage over classical firewalls since it is available on every potential network router (including all modern operating systems), and adds virtually no performance impact. Due to the nature of high-bandwidth routers, null routing can often sustain higher throughput than conventional firewalls. For this reason, null routes are often used on high-performance core routers to mitigate large-scale denial-of-service attacks before the packets reach a bottleneck, thus avoiding collateral damage from DDoS attacks — although the target of the attack will be inaccessible to anyone. Blackhole filtering can also be abused by malicious attackers on compromised routers to filter out traffic destined to a certain address.
However, routing typically only works on the Internet Protocol layer and is very limited in packet classification. It is bound to be stateless due to the nature of IP routers. Typically, classification is limited to the destination IP address prefix, source IP address and incoming network interface.
Specific examples
Nullrouting with iproute2 on Linux:
$ ip route add blackhole 192.168.32.128/32[1]
Nullrouting with 'route' on Solaris and BSD:
$ route add -host 10.10.0.1 127.0.0.1 -blackhole $ route add -net 10.10.64.0/18 127.0.0.1 -blackhole
Creating a discard route on Juniper Networks' Junos:
set routing-options static route 192.168.0.0/16 discard
Routing to the Null0 interface on Cisco IOS:
ip route 192.168.0.0 255.255.0.0 Null0[2]
Windows XP/Vista does not support reject or blackhole arguments via route, thus an unused IP address (e.g. 192.168.32.254) must be used as the target gateway:
route -p ADD 192.168.32.128 MASK 255.255.255.255 192.168.32.254
See also
References
- ^ Brown, Martin A. (2007-03-01). "Guide to IP Layer Network Administration with Linux". http://linux-ip.net/html/linux-ip.html#ex-list-route-blackhole. Retrieved 2008-03-15.
- ^ "Use a Static Route to the Null0 Interface for Loop Prevention". Cisco Document ID: 14956. http://www.cisco.com/en/US/tech/tk364/technologies_tech_note09186a00801c9a6e.shtml. Retrieved 2008-03-15.
Categories:
Wikimedia Foundation. 2010.