Is private IP's allowed on Public Networks?

speedfreak

Active Member
Joined
Apr 14, 2005
Messages
49
Reaction score
0
Location
Little Falls
I've been reading up on some very heated debates on the iBurst Forum regarding the appearence of Private IP's on the public network.

Some say jay, some say nay:

To my knowledge this is not allowed, even if it is used to 'hide' your identity. :cool:

What do you experts say? :confused:
 
iBurst is a private network, so technically its allowed. They can NAT to legal IP addresses on their firewall, so to people off their network it appears as if they are all legal. Incoming traffic can also be dropped at the firewall...
IP ranges are like hens teeth. I have about 25 class C addresses that I am not using but am loathe to give them up - they are impossible to get back...
 
But then surely if they use NAT we shouldn't be able to see these private ranges when we do a tracert? I refer to the 192.168.x.x addresses that appear when a Tracert is done from an iBurst connection to eg. www.microsoft.com.

Could this be a problem or is it because iBurst users are 'part' of the internal network (eg. behind an iBurst Firewall)? Hope I make sence...
 
Guys, any private ranges would not pass routers, that simple, so any address you are seening is bacuase you are on the same subnet as someone else, thats all, groups of addresses would be natted by them in class C format.

Routers and firewalls should always be set to drop private network packets its a RFC. as well as the would not get past the BGP table.
 
How on earth do you get 192.168.x.x bounced back on a trace to Microsoft? Is iBurst running a proxy on a private range? What does a typical IP look like for an iBurst user?

That is very strange!
 
WBS have finally registered their own IP range

antowan said:
...What does a typical IP look like for an iBurst user?...
Code:
connecting to whois.arin.net [69.25.34.144:43] ... 
connecting to whois.afrinic.net. [196.216.2.1:43] ... 
% This is the AfriNIC Whois server.

inetnum:      [B][COLOR=Blue]196.46.64.0 - 196.46.71.255[/COLOR][/B]
netname:      IBURST
descr:        Wireless Business Solutions (Proprietary) Limited
descr:        15 Floor Radiopark building
descr:        24 Henly Road
descr:        Johannesburg
descr:        Gauteng
descr:        2006
country:      ZA
org:          ORG-WBSL1-AFRINIC
admin-c:      SZA4-AFRINIC
tech-c:       SBN2-AFRINIC
status:       ALLOCATED PA
mnt-by:       AFRINIC-HM-MNT
mnt-lower:    TF-196-46-64-0-196-46-71-255-MNT
changed:      [email protected] 20041222
changed:      [email protected] 20041222
changed:      [email protected] 20050221
source:       AFRINIC

organisation: ORG-WBSL1-AFRINIC
org-name:     Wireless Business Solutions (Proprietary) Limited
org-type:     LIR
address:      Wireless Business Solutions (Proprietary) Limited
address:      15 Floor Radiopark building
address:      24 Henly Road
address:      Johannesburg
address:      Gauteng
address:      2006
country:      ZA
e-mail:       [email protected]
admin-c:      SZA4-AFRINIC
tech-c:       SBN2-AFRINIC
remarks:      Soth African wireless service provider
mnt-ref:      TF-196-46-64-0-196-46-71-255-MNT
mnt-by:       AFRINIC-HM-MNT
changed:      [email protected] 20040826
changed:      [email protected] 20040826
changed:      [email protected] 20050221
source:       AFRINIC

person:       Samkelo Zake
address:      15 Radiopark Building
address:      24 Henly Road
address:      Johannesburg
address:      Gauteng
address:      2006
address:      ZA
phone:        +27 8774700 4715
e-mail:       [email protected]
nic-hdl:      SZA4-AFRINIC
changed:      [email protected] 20040826
changed:      [email protected] 20040826
changed:      [email protected] 20050221
source:       AFRINIC

person:       Sibusiso Blessing Nzuza
address:      15 Floor Radiopark building
address:      24 Henly Road
address:      Johannesburg
address:      Gauteng
address:      2006
address:      ZA
phone:        +27861 927 6624 4714
e-mail:       [email protected]
nic-hdl:      SBN2-AFRINIC
changed:      [email protected] 20040826
changed:      [email protected] 20040831
changed:      [email protected] 20050221
source:       AFRINIC
 
Last edited:
WBS are already known for doing verrry odd things with private IP subnets, for example this thread:

[thread=17773]172.16.0.101[/thread]

However I have just run a tracert from my SmoothWall box (via the web interface ip tools > Traceroute www.microsoft.com) and here is the result that speedfreak is referring to:
Code:
[SIZE=3]207.46.244.188 (origin2.microsoft.com)

 1  196.30.31.100  112.048 ms  149.727 ms  160.017 ms
[B][COLOR=Red] 2  192.168.0.97  145.831 ms  305.321 ms  458.799 ms[/COLOR][/B]
 3  196.30.31.254  94.568 ms  159.781 ms  304.729 ms
 4  196.30.156.34  46.393 ms  133.474 ms  56.487 ms
 5  196.30.229.209  493.506 ms  544.990 ms  329.940 ms
 6  152.63.86.145  374.953 ms  284.977 ms  435.336 ms
 7  152.63.7.130  544.989 ms  384.490 ms  289.877 ms
 8  152.63.101.46  310.110 ms  340.285 ms  319.916 ms
 9  152.63.9.237  594.517 ms  570.023 ms  424.957 ms
10  152.63.144.98  519.957 ms  359.893 ms  359.950 ms
11  208.214.136.242  504.950 ms  645.015 ms  620.307 ms
12  207.46.41.129  474.956 ms  399.613 ms  465.306 ms
13  207.46.34.173  379.522 ms  575.392 ms  429.971 ms
14  207.46.36.146  604.929 ms  604.978 ms  374.570 ms
15  207.46.155.5  625.351 ms  379.551 ms  374.878 ms
16  * * *
17  * * *
18  * * *
19  * * *
20  * * *
21  * * *
22  * * *
23  * * *
24  * * *
25  * * *
26  * * *
27  * * *
28  * * *
29  * * *
30  * * *[/SIZE]
 
Last edited:
Uhm. Okay. So am I just confused or confused?

iBurst registered their own IP, but we still see 192.168.x.x? Bottom line, is this normal or not?
 
You can extend how far the private IP will travel until somebody well configured router say > route null This is a good eample of how big companies break the internet !
 
speedfreak said:
...but we still see 192.168.x.x? Bottom line, is this normal or not?
Normal? - maybe ;)

Totally a dumbass thing for WBS to be doing & exposing across subnets? - YES!!! :D
 
Please correct me if I am wrong,

A normal router cannot and will not route private ip along it unless it has been told to do this, they are running public ip addresses, so uunet will have a route 172.* 192.* etc to null on there serial to them, so how are there addresses getting out ?
 
They aren't getting out.
They're just using those IP addresses for an internal hop.
Those IP addresses needn't be reachable. The only thing that matters is that the 2 routers using those IP's know what they're doing.

Its possible to do this, it doesn't break anything, but its not professional at all!
As an ISP, they should use Public routable IPs everywhere in their network.
 
daffy said:
...
As an ISP, they should use Public routable IPs everywhere in their network.
Everywhere that's visible to customers at any rate - what they do internally that isn't visible to customers is their business :).
Code:
207.46.244.188 (origin2.microsoft.com)

 1  [B][COLOR=Red]196.30.31.100[/COLOR][/B]  112.048 ms  149.727 ms  160.017 ms
 2  192.168.0.97  145.831 ms  305.321 ms  458.799 ms
 3  [B][COLOR=Red]196.30.31.254[/COLOR][/B]  94.568 ms  159.781 ms  304.729 ms
...
Interesting thing to note, 196.30.31.100, 196.30.31.254 - they belong to UUNET, not WBS/iBurst:
Code:
Request: 196.30.31.100
connecting to whois.arin.net [192.149.252.44:43] ... 
connecting to whois.afrinic.net. [196.216.2.1:43] ... 
% This is the AfriNIC Whois server.

inetnum:      196.30.0.0 - 196.30.255.255
netname:      NET-196-30-0-0-1
descr:        UUNET SA
descr:        p.o. box 44633
descr:        claremont
descr:        cape town
descr:        western cape
descr:        7735
country:      ZA
org:          ORG-US4-AFRINIC
admin-c:      MAIN1-AFRINIC
tech-c:       MAIN1-AFRINIC
status:       ALLOCATED PA
remarks:      This organization uses RWhois. For reassignment information,
remarks:      Please see their RWhois server at:
remarks:      rwhois://server03.noc.uunet.co.za:4321.
mnt-by:       AFRINIC-HM-MNT
mnt-lower:    TF-196-30-MNT
changed:      [email protected] 19961028
changed:      [email protected] 20040210
changed:      [email protected] 20050221
source:       AFRINIC

organisation: ORG-US4-AFRINIC
org-name:     UUNET SA
org-type:     LIR
address:      UUNET SA
address:      p.o. box 44633
address:      claremont
address:      cape town
address:      western cape
address:      7735
country:      ZA
e-mail:       [email protected]
admin-c:      MAIN1-AFRINIC
tech-c:       MAIN1-AFRINIC
remarks:      contact [email protected] to report abuse
remarks:      This organization uses RWhois. For reassignment information,
remarks:      Please see their RWhois server at:
remarks:      rwhois://server03.noc.uunet.co.za:4321.
remarks:      noc e-mail: , phone: +27 21 6588585
remarks:      abuse e-mail: , phone: +27 21 6588585
mnt-ref:      TF-196-30-MNT
mnt-by:       AFRINIC-HM-MNT
changed:      [email protected] 20031119
changed:      [email protected] 20040311
changed:      [email protected] 20050221
source:       AFRINIC

person:       MAINT MAINT
address:      p.o. box 44633
address:      claremont
address:      cape town
address:      western cape
address:      7735
address:      ZA
phone:        +27 21 6588585
e-mail:       [email protected]
nic-hdl:      MAIN1-AFRINIC
remarks:      please report abuse to [email protected]
changed:      [email protected] 20040202
changed:      [email protected] 20040202
changed:      [email protected] 20050221
source:       AFRINIC
So, the question is then, is it UUNET at fault or WBS? One thing that is certain, is that there is going to be a major clash with another 192.168.0.0 subnet out there (192.168.0.1 commonly used by Windoze ICS, not to mention everything up to 192.168.0.255).
 
Last edited:
oh my goodness. Let me clear this up :

Almost EVERY ISP/NETWORK/CARRIER use IP addresses from the Private ranges. If a host doesnt need to be contacted, or more specifically, you dont want it to be contacted, then its fine as long as all YOUR routers now how to route the IP.

When you configure a router, you have to configure all interfaces that you want to carry IP on with an IP address. Typically, this would be a Serial Interface and an Ethernet interface. Serial Interface = part of the router that the Telkom leased line or other WAN carrier plugs in to. You need to put an IP on here so that you can route over this line. What the carriers typically do is take a 192 or 10 address range, give it a /30 [255.255.255.252] bit mask (so that there are only 2 hosts permitted, 1 for each site, on that subnet), and set the deafult or other routes on the local router to the serial interface IP across the network.

Let me give an example :

192.168.1.0/30 configured on serial interface on each router.
Router a given IP address 192.168.1.1 and router b given IP adress 192.168.1.2.
192.168.1.0 will be the network address, and 192.168.1.3 will be the broadcast address.

assume site a is a branch site, and has network 196.30.1.1/24 configured on the ethernet interface. site b is the main central router (or carrier network hub etc).

Site a will then have a IP address from 196.30.1.1/24 configured on the actual ethernet interface, on a 24 bit network the IP is typically 196.30.1.1, and this will be the default gateway for all the clients on the local network. Once the traffic reaches the router, it needs to know how to pass it on. Here is where the routing on the serial interface comes into effect. Every router has a default route where it passes traffic onto that is not specifically destined for an IP range on the local routing table. In site a 's case, there will be a default route pointing to the serial interface of site b's router. when the traffic gets to site b, because it is a hub/core site, it will pass it onto another site or forward it on. So site a will have an entry in its routing table as follows:

0.0.0.0 mask 0.0.0.0 192.168.1.2 'all unspecified networks routed to router b

Now the same applies in reverse to site b - it needs to know how to get traffic to site a's subnet (196.30.1.1/24), so it will have a route as follows :

196.30.1.0 mask 255.255.255.0 192.168.1.1

Obviously, the default route on site b would be to its upstream provider and not to site a otherwise you would have a loop.

Now, typically ISPs dont want external internet users to attach to their routers, so they use private IPs so that their routers are not contactable directly from the internet. this is good for security, and because they device never really needs to be contacted from outside, doesnt waste legal IP addresses.

So, in summary, what WBS (and all the rest for that matter) are doing is perfectly normal and NOT cheapskate or bad practice. the only mistake they have seemingly made is that they havent hidden their serial interface routing. this is not a bid deal.

IC - you should never get a clash because Routers almost never originate traffic, they just route it so the source IP will still be legal.
Now if they wanted to contact these private IPs from the net - on their Firewall they would assign a NAT rule (Network Address Translation) that would make this IP contactable, but via a legal IP address. Think of it as an alias... 196.25.1.45 natted to 192.168.1.1 on the firewall.

Hope this helps to clear things up a bit!
I will most probably edit this post to correct typos.... :D
Cheers -
 
Last edited:
ScrnScrm, thanks for clarifying that

Methinks I will re-read your post over the weekend, tiredness is obfuscating my ability to fully comprehend right now ;).

I agree that WBS can do what they want internally on their network, that it is a normal thing to use 192.168.a.0 or 10.x.y.0 ranges, and like you say the mistake is that 192.168.0.97 is not hidden, which is one of the reasons why I can ping it from my SWE2 box:
Code:
192.168.0.97 (Reverse lookup failed)

PING 192.168.0.97 (192.168.0.97) from 196.46.6x.y : 56(84) bytes of data.
64 bytes from 192.168.0.97: icmp_seq=1 ttl=254 time=371 ms
64 bytes from 192.168.0.97: icmp_seq=2 ttl=254 time=231 ms
64 bytes from 192.168.0.97: icmp_seq=3 ttl=254 time=276 ms
64 bytes from 192.168.0.97: icmp_seq=4 ttl=254 time=416 ms
64 bytes from 192.168.0.97: icmp_seq=5 ttl=254 time=207 ms

--- 192.168.0.97 ping statistics ---
5 packets transmitted, 5 received, 0% loss, time 4034ms
rtt min/avg/max/mdev = 207.360/300.978/416.896/80.716 ms
My question is this, if on my lan I had 2 subnets:
  • gateway with IP 192.168.1.1; and
    [*]gateway [t] with IP 192.168.0.1
Now lets assume that is the only route that PCs from both subnets can take to get to beyond my little lan. Further assume that one of my lan PCs has been assigned with the IP address 192.168.0.97. What happens when I ping 192.168.0.97 from a machine in the 192.168.1.0 subnet? Presumably this is where I would have to configure with routing info for [t]?

PS: I know I'm talking nonsense aren't I, I'm sure I am bcos I am just confusing myself here - need sleep...:D
 
Last edited:
ah, well if you ping 192.168.0.97 and you have the network 192.168.0.0/24 loaded on your local subet, it will have a route to it locally and you wouldnt be able to get to the WBS one. Not that it really matters though - you shouldnt need to attach to a WBS router anyway :D when the traffic leaves your local subnet, it will be natted with the IP assigned to you by WBS when you log in, so no external networks off your local subnet will be able to see that you are running private IPs anyway.
It would of course matter if WBS were hosting a service that you needed to attach to on 192.168.0.97 - but they dont do that. All services on their network have legal IPs.

Wrt talking nonsense - nevermind :D Private vs Public IP ranges confuses the hell out of most people - I am constantly argueing about it with my staff - all of whom are experienced, degreed professionals that spent years trying to understand IP at varsity. Wait until you start looking into things like route aggregation - then it all goes for a ball of s***. Thats the REAL reason why most companies settle on private IP ranges because it makes aggregation on the routers much much easier to maintain and configure. I could go into the details of designing WANs and telecommunications backbones, but I fear my boss will slaughter me for giving out free consulting hours :D
Only joking - if anyone here needs to know more about it for whatever reason, start a thread or PM me and I will gladly help!
Later -

/edit I made the assumption here that everyone knows what route aggregation is - sorry. Basically, manual or OSPF routes are created on a router for directing the traffic around. The less routes on the router, the better. With aggregation, you use class b for a hub, class c for a site hanging off it. on all your hubs, you manually or via OSPF specify the class b address to another hub, and it will automatically know how to route to any sites hanging off it. When you use OSPF - it doesnt need to learn all the routes hanging off a hub, only how to get to the hub, hence population of changes happens a LOT quicker. OSPF means Open Shortest Path First, and is basically a router technology that automatically propagates routes. So in a nutshell, the more routes are aggregated, the faster changes are populated across the network. the less routes on a router, the faster it can route traffic.
Hope this explanation is clear enough - if anyone finds it hard to understand, please let me know so that i can edit it again. I expect lots of edits :D
/endedit
 
Last edited:
Thanks ScrnScrm,

That makes perfect sence to me. Now my worries can be put to rest.

Regards,
Speadfreak.......
 
Top
Sign up to the MyBroadband newsletter
X