<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class="">
Hi Peter,
<div class="">Yes, the user has 1.1.1.1 defined as their resolver on their home network, but I don’t know why the Google resolver (8.8.8.8) ended up in the table.</div>
<div class=""><br class="">
</div>
<div class="">There are many more host entries in the routing table too, for multiple different Azure, Google, Akamai, etc., IP addresses. Each host entry has flags of either UHW3I or UHWIi.</div>
<div class=""><br class="">
</div>
<div class="">I’m assuming that the host entries are added because the default route is “ambiguous” (unlike in the older eduVPN client where the more specific catch-all routes of <font color="#000000" class="">0/1 and 128.0/1 are created and are matched before
the default), but that’s just a guess and I’d like to understand properly why the behaviour is so different between the two versions of eduVPN client.</font></div>
<div class=""><font color="#000000" class=""><span style="caret-color: rgb(0, 0, 0);" class=""><br class="">
</span></font></div>
<div class=""><font color="#000000" class=""><span style="caret-color: rgb(0, 0, 0);" class="">Regards,</span></font></div>
<div class=""><font color="#000000" class=""><span style="caret-color: rgb(0, 0, 0);" class="">Louis</span></font></div>
<div class="">
<div class="">
<div>-------<br class="">
Louis Twomey<br class="">
Technical Architect<br class="">
PGP key: C77D9256<br class="">
HEAnet CLG, Ireland’s National Education and Research Network<br class="">
1st Floor, 5 George’s Dock, IFSC, Dublin D01 X8N7, Ireland<br class="">
+353 (0)1 6609040 <a href="mailto:louis.twomey@heanet.ie" class="">louis.twomey@heanet.ie</a> <a href="http://www.heanet.ie" class="">www.heanet.ie</a><br class="">
Registered in Ireland, No. 275301. CRA No. 20036270</div>
<div class=""><br class="">
</div>
<br class="Apple-interchange-newline">
</div>
<div><br class="">
<blockquote type="cite" class="">
<div class="">On 8 Jul 2020, at 15:43, Peter Macfarlane <<a href="mailto:peter@ska.ac.za" class="">peter@ska.ac.za</a>> wrote:</div>
<br class="Apple-interchange-newline">
<div class="">
<div class="">CAUTION[External]: This email originated from outside of the organisation. Do not click on links or open the attachments unless you recognise the sender and know the content is safe.<br class="">
<br class="">
<br class="">
Hi Louis<br class="">
<br class="">
<blockquote type="cite" class="">Internet:<br class="">
Destination Gateway Flags Netif Expire<br class="">
default link#18 UCS utun2<br class="">
default 192.168.0.1 UGScI en0<br class="">
1.1.1.1 link#18 UHW3I utun2 2<br class="">
1.2.3.4 link#18 UHW3I utun2 1<br class="">
8.8.8.8 link#18 UHW3I utun2 3<br class="">
13.88.28.53 link#18 UHWIi utun2<br class="">
40.126.1.143 link#18 UHWIi utun2<br class="">
</blockquote>
<br class="">
Several of those if not all of those addresses look like Dns server<br class="">
addresses so perhaps there is some special rule which adds specific<br class="">
routes to those , it is a very interesting set of dns servers however<br class="">
;)<br class="">
<br class="">
Cheers Peter<br class="">
<br class="">
--<br class="">
Peter Macfarlane<br class="">
South African Radio Astronomy Observatory (SARAO)<br class="">
Tel Direct: +27 21 506 7370<br class="">
Tel Switchboard: +27 21 506 7300<br class="">
Mobile: +27 82 925-5353<br class="">
<a href="mailto:Peter@ska.ac.za" class="">Email: Peter@ska.ac.za</a><br class="">
</div>
</div>
</blockquote>
</div>
<br class="">
</div>
</body>
</html>