A Guide: Non-Routable Protocols and Networks

Author: Colin Robbins

10 Mar 2015

cyber security

Non-Routable Protocols and Networks

Network segregation is a common security technique to prevent security issues in one network from affecting another. When examining how information can be moved or shared between such networks, the concepts of routable protocols and non-routable protocols are often employed. We also see the terms routable/non-routable networks. In fact, they are not the same thing. In this article, we’re going to explain the difference between non-routable protocols and networks.

Routable Protocols

The term "routable protocol" is used when the protocol contains the address of the target system, for example, UDP and TCP/IP. According to PC Magazine, a non-routable protocol is:

“A communications protocol that contains only a device address and not a network address. It does not incorporate an addressing scheme for sending data from one network to another.”

Non-routable protocols

An example of a non-routable protocol is NetBIOS. Put another way, the protocol does not make sense outside of the local area network. So this is fundamentally about the protocol and whether routing is an inherent capability of the protocol.

When considering routable protocols, we then have two classes of networks: routable and non-routable IP networks.

Routable Networks

Just because you have a routable protocol, it does not mean any address is routable. It all depends upon how the networks are connected. When using an IP address as a routable protocol, you are typically connecting to the internet. Internet IP addresses are global in nature, and your end-user device is able to access the Internet via the router. The router directs your traffic toward the relevant server.

Non-routable networks

The term non-routable just means exactly that: that IP packets cannot be directed from one network to another. This could be because your router is not configured with the information it needs to perform this operation, or because you are trying to access a private network.

Private Networks

Certain address spaces in IPv4 and IPv6 are reserved for internal networks. For example, the IP address range you most likely use at home starts 192.168... or 172.16… These are, by definition, non-routable IP networks, even in using routable protocols. An external router will not know how to find your network if these addresses are published.

From a security perspective, we can use these facts. We can hide our network in a private network space, preventing direct IP connections. If we wish these machines to have access to a wider network, we need to introduce routers, gateways, or proxies to our network – all of these are different ways we can interconnect networks, and exert some form of control over the traffic that passes over these networks.

Using a non-routable IP network alone is not great for security, as there are many ways to subvert the controls, but it is a small part of an overall system design.

Why is this important?

The article IoT / IoE: If It Has an IP Address, It Can Be Hacked observes the following when referring to the Internet of Things (IoT):

“While I agree that connectivity is great and adds a lot of value /interoperability/functionality features, there is an oftentimes underestimated risk in putting the whole world (well, the whole internet) directly in front of any system or device and even connect to it by giving it a routable IP address."

This is an important observation when designing an IoT system – if everything is routable then you need to take very careful security precautions.


Techniques like network segregation can help ensure your network is non-routable, and thus become a part of a defence-in-depth security strategy. A common network segregation approach is to use a Data Diode to ensure only a one-way flow of data. Data Diodes come in two forms – routable and non-routable.

How Nexor can help

The Nexor Data Diode is non-routable. In most common configurations, it is not possible to route IP packets directly to the Nexor Data Diode itself, and thus not possible to direct IP packets through the diode from a remote server – only the diode proxy can do that, only the diode proxy can route to the diode. This removes the possibility of IP-based attacks on the downstream side of the diode (Protocol break is a closely linked topic to this point). Some other diodes and pseudo-diodes are routable, thus enabling a channel of attack on the downstream servers.


These are very subtle points, but critical points when defending against the most determined adversaries. Is your diode solution routable? Get in touch with Nexor today and let us help you improve your cyber security.

Read more posts on

About the author

Colin Robbins is a Principal Security Consultant, leading customer-funded research activities in secure interoperability and information exchange. He has specific technical interests in the Single Information Environment and Data Centric Security, as well as the processes of security, such as Secure by Design and Information Security Management Systems (ISMS). He is a Fellow of CIISec, and a former NCSC certified Security and Information Risk Adviser (Lead CCP).

Colin Robbins on Linkedin

Read more posts by Colin Robbins