skip to content

Choosing Between Route Sources

Connected beats static beats learned by administrative distance, floating statics wait as backup, and equal-cost paths share load. Interviewers ask you to explain why a given route lost.

on this pageshow

questions

6

On an IP router, what are connected, static and default routes, and how does each one get into the routing table?

level: juniorimportance: must knowfreq 62%

answer

  1. three ways a route arrives
  2. interface address plus prefix
  3. an operator types it in
  4. the prefix of length zero

basics

~20 s

A connected route appears when an interface with an address and prefix comes up; a static route is configured by hand; the default route (0.0.0.0/0, ::/0) matches everything and is used only when nothing more specific matches.

solid answer

~40 s

A router's table has three everyday sources. **Connected** routes come from its own interfaces: give an interface `192.0.2.1/24` and bring it up, and the router installs `192.0.2.0/24` as directly reachable, with no next-hop router, because it can deliver to hosts on that link itself. **Static** routes are typed in by an operator as a prefix plus a next hop (or an outgoing interface); RFC 1812 says a router SHOULD support them. **Dynamic** routes are learned from a routing protocol. The **default route** is the prefix of length zero, `0.0.0.0/0` in IPv4 and `::/0` in IPv6, which matches every destination and is therefore the route of last resort, used only when no more specific route matches. It is a prefix, not a source: it can be static or learned from an upstream router.

go deeper

for a junior

Name the three sources and what installs each: interface addresses, operators, routing protocols. Recognise 0.0.0.0/0 and ::/0 and know the default is the last resort.

for a middle

Explain that the default is a prefix any source can supply, that connected routes have no next-hop router, and why a static route keeps pointing at a dead path.

for a senior

Show when static routing is the right tool, such as single-exit stub sites, and when its silence about failures needs a backup path or failure detection beside it.

for a principal

Argue where a network should stop relying on static defaults and run a protocol instead, weighing operational simplicity against failover needs and how many people must reason about the table.

## What the routing table is for An IP router forwards each packet by looking up its destination address in a **routing table**: a list of entries, each pairing a **prefix** (a network address plus a prefix length, such as `198.51.100.0/24`) with a way to reach it. That way is either an outgoing interface on which the destination is directly reachable, or the IP address of a **next-hop** router. RFC 1812, the IPv4 router requirements, describes the per-packet lookup; this question is about the step before it: where the entries come from. Every entry has a **source**, and the three sources every engineer meets first are connected, static and dynamic. ## Connected routes: the router's own links When an interface is given an address and prefix, say `192.0.2.1/24`, and the interface is up, the router knows that every address in `192.0.2.0/24` sits on that link. It installs a **connected route** for the prefix automatically. Nobody configures the route and no protocol advertises it. - A connected route has **no next-hop router**: packets matching it are delivered straight to the destination host on the link, after the router resolves that host's link-layer address (ARP for IPv4 on Ethernet, Neighbor Discovery for IPv6). - It exists only while the interface is up and holds that address. Shut the interface down and the route disappears. - RFC 1812's local/remote decision is the rule behind it: if the destination's network bits equal the prefix of one of the router's interface addresses, the destination is directly reachable through that interface. ## Static routes: written by an operator A **static route** is an entry an operator types in: a prefix and a next-hop address, or a prefix and an outgoing interface. RFC 1812 section 7.4 says a router **SHOULD** provide a way to define one, and should let a metric be set on it. - Static routes never change on their own. If the network behind the next hop breaks, the static route keeps pointing at it; in most implementations only its outgoing interface going down, or an operator, removes it. - They suit places with exactly one way out (a branch site with one uplink, a stub network behind a single router) and become a liability where topology changes, because every change is manual. - The next hop of a static route must itself be reachable, normally through a connected route; otherwise the route cannot be used. ## Dynamic routes: learned from neighbours A routing protocol (RIP, OSPF or IS-IS inside an organisation, BGP between organisations) lets routers tell each other what they can reach. Routes learned this way are **dynamic**: they appear, change and vanish as neighbours update them. How each protocol computes its routes is a subject of its own; what matters here is that a learned route is one more source competing for a place in the table. ## The default route: prefix length zero The **default route** is the entry whose prefix length is zero: `0.0.0.0/0` in IPv4, `::/0` in IPv6. A zero-length prefix has no significant bits, so it matches every destination. RFC 1812 calls it the route to all networks for which there are no explicit routes, and ranks it last: any more specific matching route is preferred. RFC 4632, the current CIDR specification, says `0.0.0.0/0` MUST be accepted by every implementation, and should be advertised to another routing domain only when a router is explicitly configured to do so. A default route is not a fourth source. It is a prefix, and any source can supply it: 1. an operator configures it as a static route pointing at the upstream router; 2. a routing protocol advertises it from a border router; 3. a host, rather than a router, usually receives its equivalent from DHCP (IPv4) or from Router Advertisements (IPv6). If a router finds no matching route and has no default, it discards the packet and reports the failure with an ICMP Destination Unreachable message. ## One small router, one table A branch router with a LAN interface `192.0.2.1/24`, an uplink `198.51.100.1/30` to its provider at `198.51.100.2`, and a static route to a partner network might hold: | Prefix | Source | Reached via | |---|---|---| | `192.0.2.0/24` | connected | LAN interface, directly | | `198.51.100.0/30` | connected | uplink interface, directly | | `203.0.113.0/24` | static | next hop `198.51.100.2` | | `0.0.0.0/0` | static (default) | next hop `198.51.100.2` | A packet for `192.0.2.50` matches the connected LAN route; one for `203.0.113.9` matches the static route; one for any other address falls through to the default. The `/30` uplink holds exactly two usable addresses, `.1` and `.2`, one for each end of the link. ## Where candidates slip - Calling the default route the route used first. It is used last, only when nothing more specific matches. - Thinking a connected route needs configuring. The interface address creates it. - Believing a static route notices failures beyond its next hop. It does not. - Confusing the default route `0.0.0.0/0` with the reserved block `0.0.0.0/8` ('this host on this network' in RFC 6890) or with the limited broadcast address `255.255.255.255`, which RFC 1812 says routers must never forward.

  • Why would a branch router with a single uplink use a static default route instead of running a routing protocol to its provider?
    With one way out there is nothing to choose: every non-local destination goes to the same next hop. A static default says that in one entry, needs no protocol session, and cannot be fed wrong routes by a neighbour. Its weakness, never noticing failure, costs little when there is no alternative path to fail over to anyway.
  • Does a static route for 203.0.113.0/24 lose to a default route learned from a routing protocol?
    No. Prefix length is compared first, so the static `/24` serves every address in that block whichever source supplied the default. Preference between sources matters only when two sources offer exactly the same prefix. The learned default still carries every destination the static route does not cover.

saying these in an interview costs you the question

  • The default route is checked first and specific routes override it afterwards.
  • A connected route has to be configured just like a static route.
  • A static route is withdrawn automatically when the network beyond its next hop fails.
  • 0.0.0.0/8 is the IPv4 default route.
  • A router with no matching route sends the packet out of its first interface anyway.
open as a page

When an IPv4 router learns one prefix from a static route, OSPF and BGP, which wins, and how does administrative distance differ from a metric?

level: middleimportance: must knowfreq 55%

basics

~20 s

Only routes for the same prefix compete. Among them the router keeps the source with the best administrative distance, an implementation-defined trust ranking where lower wins; a metric ranks routes only within one protocol. With common defaults the static route wins.

open as a page

What distinguishes an interior gateway protocol from an exterior gateway protocol, and why is BGP used between autonomous systems instead of an IGP?

level: middleimportance: should knowfreq 48%

basics

~20 s

An interior gateway protocol finds best paths inside one autonomous system; an exterior gateway protocol exchanges reachability between autonomous systems. BGP-4 fills that role because it carries AS paths and applies each operator's policy, which a shared shortest-path metric cannot express.

open as a page

How does a floating static route back up a BGP-learned default route, and which failures will it fail to catch?

level: seniorimportance: should knowfreq 35%

basics

~20 s

A floating static route is given a worse administrative distance than the dynamic route, so it stays uninstalled until that route is withdrawn. It misses failures that never withdraw the primary, and dead backup paths behind an up interface.

open as a page

When an IP router holds several equal-cost next hops for one prefix, how should ECMP split traffic, and why per flow rather than per packet?

level: seniorimportance: nice to knowfreq 24%

basics

~20 s

ECMP should hash the header fields that identify a flow and map the result to one next hop, so each flow keeps a single path. Spraying per packet reorders segments, varies the path MTU and confuses diagnostics (RFC 2991).

open as a page