Skip to content

Route

Summary
  • Routing is the process of deciding, packet by packet, which interface (and which next hop) a device should use to actually reach a given destination.
  • Every routing decision comes down to consulting a routing table — an ordered list of known destinations and how to reach each one.
  • Routes get into that table one of two ways: static (a human or script typed them in) or dynamic (a routing protocol learned them automatically) — and almost every device also has a default route, the catch-all for anything not otherwise matched.

Think of routing as:

"Reading a series of increasingly general signs — 'this street,' 'this neighborhood,' and finally 'everything else, this way' — and taking the most specific sign that actually matches where you're going."

Routing Basics

Every time a device needs to send a packet, it has to answer one question: which interface, and via which next hop, gets this packet closer to its destination? That decision is made entirely by consulting the routing table, matching the packet's destination address against every entry, and picking the most specific match — this is called longest prefix match: a route to 192.168.1.0/24 beats a route to 192.168.0.0/16 for a destination of 192.168.1.50, because /24 is more specific than /16.

If nothing more specific matches, the default route catches everything else — covered in its own section below.

Routing Table

The routing table is the actual list of known destinations a device consults for every routing decision. Each entry (a "route") minimally answers three questions:

  • What destination does this entry apply to? (a specific host, or a network in CIDR notation)
  • Where does traffic to that destination go? (a next-hop gateway, or a directly-connected interface)
  • Which local interface does it go out?

A device typically builds its table from multiple sources at once: routes the kernel creates automatically for directly-connected networks, routes a human configured by hand, and routes learned from a routing protocol — all coexisting in the same table.

Static Routing

Static routing means a route was entered manually — by an administrator, a script, or a configuration file — rather than learned automatically. The device never questions it and never updates it on its own; if the network topology changes, someone has to update the static route themselves.

Pros Cons
Static Routing Predictable, no protocol overhead, no risk of being manipulated by a compromised neighbor Doesn't adapt to topology changes or failures; doesn't scale to large, changing networks

Table 1. Static Routing Tradeoffs

Static routing is a perfectly reasonable choice for small, stable networks — a home network, a lab, or a single edge device with exactly one way out — where the topology basically never changes.

Dynamic Routing

Dynamic routing means routes are learned and updated automatically, via a routing protocol that exchanges reachability information between routers. If a link goes down, routers using dynamic routing can detect it and automatically recalculate a working path — no human intervention required.

Protocol Type Common Use
RIP Distance-vector Small/legacy networks
OSPF Link-state Enterprise/campus networks
EIGRP Advanced distance-vector Cisco-centric enterprise networks
BGP Path-vector The internet itself — routing between autonomous systems (ISPs, large organizations)

Table 2. Common Dynamic Routing Protocols

Static and dynamic routes can coexist

A single device commonly has both — a handful of hand-configured static routes alongside routes learned dynamically. When routes to the same destination come from multiple sources, an administrative distance (a per-source trust ranking) decides which one actually gets used.

Default Route

The default route is the catch-all entry that matches any destination not covered by a more specific route — written as 0.0.0.0/0 (IPv4) or ::/0 (IPv6), the least specific possible prefix, so it only ever wins when nothing else matches.

This is exactly what makes a home router (or any default gateway) work the way it does: your laptop has specific routes only for its own local subnet, and a single default route pointing at the router for literally everything else on the internet.

Linux Route Output Explained

Here's a real ip route show output, and what every field actually means:

$ ip route show
default via 192.168.1.1 dev eth0 proto dhcp src 192.168.1.100 metric 100
10.0.0.0/8 via 192.168.1.254 dev eth0 proto static metric 200
192.168.1.0/24 dev eth0 proto kernel scope link src 192.168.1.100 metric 100
Reading the example output line by line
  • default via 192.168.1.1 dev eth0 proto dhcp src 192.168.1.100 metric 100 — the default route, learned via DHCP, pointing at gateway 192.168.1.1 out eth0
  • 10.0.0.0/8 via 192.168.1.254 dev eth0 proto static metric 200 — a manually-added static route to 10.0.0.0/8, via a different gateway (192.168.1.254) on the same interface, with a higher (less-preferred) metric than the default route
  • 192.168.1.0/24 dev eth0 proto kernel scope link src 192.168.1.100 metric 100 — the auto-generated route for the locally-connected subnet itself — no via gateway needed, since it's directly reachable
Field Meaning
default or <network>/<prefix> The destination this route applies to — default is shorthand for 0.0.0.0/0, matching everything
via <IP> The next-hop gateway to send packets through — absent on routes to a directly-connected network, since no gateway is needed
dev <interface> The local network interface this route sends traffic out of
proto <value> How this route was installed — see the table below
scope <value> How far this route's validity extends — see the table below
src <IP> The preferred source address to use when sending traffic via this route
metric <number> This route's priority/cost — lower wins when multiple routes could match

Table 3.ip route show Field Reference

proto values

Value Meaning
kernel Auto-installed by the kernel itself when an interface was configured and brought up
boot Installed during the boot sequence (this is also the silent default if no proto was ever specified)
static Manually installed by an administrator
dhcp Installed by the DHCP client after receiving a lease
ra Installed from an IPv6 Router Advertisement
redirect Installed because of an ICMP redirect message

Table 4.ip route proto Values

scope values

Value Meaning
global Valid everywhere — the default assumed for any route with a gateway (via)
link Valid only on this specific device/link — the default assumed for direct, gateway-less routes
host Valid only for addresses local to this host, not routable elsewhere

Table 5.ip route scope Values

ip route get 8.8.8.8      # show exactly which route would be used for a given destination
ip route show dev eth0    # show only routes going out a specific interface
ip route show proto static  # show only manually-added static routes

Useful Resources

  • ip-route(8) man page — the authoritative reference for every ip route field and option
  • IP — IP addressing, subnet masks, and CIDR notation referenced throughout this page