1What a router decides
This is your copy to keep. The gold Going deeper boxes go past what the session covers, for anyone sitting the CompTIA Network+ exam or who wants the fuller picture.
A switch moves traffic between devices on one local network. A router moves traffic between networks, and it makes exactly one decision each time: given this destination address, which way do I send this next. Everything else a router does is in service of that.
It answers from a routing table, a list of destinations and where to send traffic for each. Every device has one, not just routers. Your workstation has a routing table and consults it before it sends anything.
Two terms are needed before the table is readable, and both were set up by the addressing work.
A subnet mask marks which part of an address names the network, and it is written as
a slash and a number of network bits, so 255.255.255.0 is /24 and names the
first three octets as the network. The default gateway is the router address a
device sends traffic to when the destination is not on its own network.
The addresses on this page are an example written for training. They are not a client network. The example site has three networks: staff 192.168.10.0/24, voice 192.168.20.0/24 and guest 192.168.30.0/24, with the gateway at .1 on each.
2The routing table on a workstation
Run route print on Windows, or ip route on Mac or Linux, and you get
this machine's own table. Here is the useful part of one, for a workstation at
192.168.10.15 with mask 255.255.255.0.
| Destination | Mask | Send it to | Out of | Meaning |
|---|---|---|---|---|
0.0.0.0 | 0.0.0.0 | 192.168.10.1 | 192.168.10.15 | Anything not matched below goes to the gateway |
192.168.10.0 | 255.255.255.0 | direct | 192.168.10.15 | My own network. Deliver these myself |
192.168.10.15 | 255.255.255.255 | direct | 192.168.10.15 | Me |
127.0.0.0 | 255.0.0.0 | direct | 127.0.0.1 | Traffic to myself, which never leaves the machine |
Read the second line first, because it is the one doing the ordinary work. Destination
192.168.10.0 with mask 255.255.255.0 means "any address whose first three
octets are 192.168.10". For those, the machine delivers directly: it finds the destination's hardware
address on the local network and sends the frame straight to it. No router involved.
Now the first line. Destination 0.0.0.0 with mask 0.0.0.0 is a mask with
no network bits at all, which matches every address in existence. This is the
default route, and it is the catch-all: anything that did not match a more specific
line goes to 192.168.10.1, the gateway. When a machine is described as "having a gateway", this line
is what that means.
3How the table picks a line
Two lines can both match the same destination. Send something to
192.168.10.200 and it matches the default route, because the default route matches
everything, and it matches the line for 192.168.10.0/24. The tie is broken by one rule.
The logic behind the tiebreaker can be worked out before the rule gets a name. The default route has
a mask of 0.0.0.0, which is zero network bits. The line for the local network has mask
255.255.255.0, which is 24 network bits. The local network line is more specific about
which addresses it is claiming, and it wins. So the traffic is delivered directly and never reaches
the router, which is what actually happens.
Stated as the rule: the line with the most network bits that still matches the destination wins. It is called longest prefix match, and it applies everywhere, on a workstation and on a router with four hundred lines in its table.
This rule is the reason a default route is safe to have. It matches everything, but it loses to every other line in the table, so it only ever catches what nothing else claimed.
4Routing between VLANs
A VLAN (virtual local area network) divides one switch into separate networks, and each VLAN carries its own subnet. Devices on different VLANs cannot reach each other directly, because they cannot hear each other's local broadcasts and therefore cannot find each other's hardware addresses.
What joins them is the gateway, and it joins them by holding an address on every VLAN. At the example site the gateway is 192.168.10.1 on staff, 192.168.20.1 on voice and 192.168.30.1 on guest. It is one device with three addresses, one foot in each network.
Follow a packet from a staff workstation at 192.168.10.15 to a phone system at
192.168.20.50.
- The workstation checks its own table. 192.168.20.50 does not match its local network line, because the first three octets differ. It matches the default route.
- So the workstation sends the packet to 192.168.10.1, using the gateway's hardware address on the staff VLAN. The destination address inside the packet is still 192.168.20.50 and never changes.
- The gateway receives it and consults its own table. 192.168.20.0/24 is a network it is directly attached to, on the voice VLAN.
- Before it forwards anything, it applies the rules configured for traffic from the staff network to the voice network. If they permit it, the packet goes. If they do not, it stops here and the workstation is told nothing useful.
- The gateway sends the packet onto the voice VLAN, addressed to the phone system's hardware address, and the phone system receives it.
Two things follow that matter on tickets. Traffic between two VLANs always passes through the gateway even when both devices are plugged into the same switch two ports apart, so the gateway's load and its rules are in the path of internal traffic. And "can these two talk" is never answered by the switch alone: the VLAN decides whether they are neighbors, and the gateway and its rules decide everything after that.
5Static routes, and when one is needed
A static route is a line added to a routing table by hand, naming a destination network and the address to send it to. A site's gateway already knows about every network attached to it, and it sends everything else out to the internet, so most sites need no static routes at all.
One is needed when there is a network reachable through something that is not the default path. Take a site whose gateway is 192.168.10.1. A second appliance at that site, 192.168.10.9, has a permanent connection to another office and can reach that office's network, 10.50.0.0/24.
Without a static route, a workstation asking for 10.50.0.4 matches its default route, sends the packet to 192.168.10.1, and the gateway has no line for 10.50.0.0/24, so it sends it out to the internet, where it is discarded. The traffic does not fail in a way that names the cause. It just disappears.
The static route added on the gateway says: for 10.50.0.0/24, send to 192.168.10.9. Now the gateway has a line more specific than its own default route, longest prefix match picks it, and the packet goes to the appliance that can reach the far office.
A static route on the gateway fixes traffic leaving the site. The far end needs the matching route back, or the reply has the same problem in reverse and the connection still fails. A route that works in one direction only is the most common static routing fault, and the symptom is a connection that opens and never completes rather than one that fails outright.
6Following the path with tracert
tracert on Windows, traceroute on Mac and Linux, lists the routers a
packet passes through on the way to a destination. Each router along the way is called a
hop.
It works by sending packets with a deliberately short life. Every IP packet carries a time to live counter, and every router that forwards it subtracts one. A router that subtracts the last one discards the packet and reports back that it did. So a packet sent with a count of 1 dies at the first router and that router names itself. A count of 2 dies at the second, naming that one instead. Sending one packet at each increasing count, and collecting the name each router reports back, builds the full list of routers along the path.
| Hop | Address | What it is |
|---|---|---|
| 1 | 192.168.10.1 | The site gateway. If this fails, the fault is inside the building |
| 2 | a public address | The internet provider's equipment. If hop 1 answers and this does not, the fault is the circuit or the provider |
| 3 onward | public addresses | The provider's network and beyond. Not ours to fix, but useful to name in a ticket |
Reading it correctly matters more than running it. A hop showing a timeout in the middle of a trace, with later hops still answering, is not a fault: plenty of routers are configured not to reply to these packets while still forwarding traffic normally. What tells you something is the point where the trace stops answering and never resumes. That is the last device that was reachable, and the problem is at or just past it.
7Where a packet actually stops
When traffic between two networks does not arrive, there are four places it can be stopping, and they are worth testing in this order because each one rules out the ones below it.
| Where | What it looks like | How to tell |
|---|---|---|
| The sender's own table | The machine never sends it to the gateway at all | route print. A wrong mask can make the machine believe the destination is local, so it tries to deliver directly and gets no answer |
| The gateway has no route | Traffic leaves the machine and goes nowhere | A trace that reaches the gateway and stops. The gateway's own table, looking for a line covering that destination |
| A rule blocks it | The route exists and traffic is still refused | The rules between those two networks, and the gateway's log of what it blocked |
| The return path | The request arrives and the reply never comes back | The far end's route back to your network. Connections open and stall rather than failing immediately |
Notice what these four have in common: three of them look identical from the user's chair. In every case the application times out and says nothing useful. The order above is what separates them, and it is the same bottom-up habit as any other fault, applied to the path instead of the stack.
8Practice on your own machine
- Run
route print, orip route. Find your default route and your own network's line. Write down what each one claims and what it does with matching traffic. - Pick an address on your own network and an address on the internet. For each, say which line of your table matches, and why that line beats the other one.
- Run
tracertto a public site. Write down hop 1 and confirm it is your gateway. Note any hop that times out while later hops still answer, and say why that is not a fault. - Run
tracertto an address on another VLAN at the same site. Count the hops and say what the count tells you about how internal traffic reaches it. - In the UniFi console, open the site's networks and list the gateway address on each one. Confirm they are the same device holding one address per network.
9Check for understanding
A workstation's table has a line for
192.168.10.0/24and a default route. It sends to192.168.10.200. Which line is used, and why?What does a default route of
0.0.0.0with mask0.0.0.0match, and why does having it not break everything else in the table?Two machines are on different VLANs, plugged into the same switch, two ports apart. Describe the path traffic between them actually takes.
A trace to a public site shows hop 4 timing out, while hops 5, 6 and 7 answer normally and the site loads. What is happening, and what would you tell a user who sent you that screenshot as evidence of a problem?
A site can reach a remote office's servers, but the remote office cannot reach anything at this site. Traffic is permitted in both directions by the rules. What do you check, and why does this fault appear as connections that stall rather than connections that fail?
A trace from a workstation stops at hop 1, the site gateway, and goes no further, while other machines at the site are browsing normally. Name the two most likely causes and how you would tell them apart.
10Before the next session
- Do the practice steps in section 8 and bring your own routing table written out, with the matching line identified for each of the two destinations.
- Be able to state longest prefix match in one sentence and give an example of two lines competing.
- Read the Network+ companion, chapter 6, the command-line tools section.
Next session. 05 - DHCP and DNS. The Dynamic Host Configuration Protocol, which hands a device its addressing, and the Domain Name System, which turns names into addresses, and the faults each one produces.
11Glossary
- Router
- The device that moves traffic between networks, choosing where to send each packet next.
- Routing table
- The list of destinations and where to send traffic for each. Every device has one.
- Default gateway
- The router address a device sends traffic to when the destination is not on its own network.
- Default route
- The table line with destination 0.0.0.0 and mask 0.0.0.0, matching every address and used when nothing more specific does.
- Longest prefix match
- The rule that the matching line with the most network bits wins.
- Static route
- A routing table line added by hand, naming a destination network and where to send it.
- Hop
- One router along the path between two machines.
- Time to live
- A counter in every IP packet that each router reduces by one. At zero the packet is discarded, which is what stops a packet circulating forever and what makes a trace possible.
- tracert
- The Windows command that lists the routers along a path. Called traceroute on Mac and Linux.
- VLAN
- Virtual local area network. One switch divided into separate networks by configuration, each carrying its own subnet.
- Subnet mask
- The marker saying which part of an address names the network and which names the device.
- Loopback
- The 127.0.0.0 range, used for a machine to reach itself. Traffic to it never leaves the machine.
12Sources
- Internet Engineering Task Force, RFC 791, Internet Protocol, for the time to live field and packet forwarding.
- Internet Engineering Task Force, RFC 1812, Requirements for IP Version 4 Routers, for forwarding behavior and route selection.
- Internet Engineering Task Force, RFC 4632, Classless Inter-domain Routing (CIDR), for longest prefix match.
- Internet Engineering Task Force, RFC 792, Internet Control Message Protocol, for the time-exceeded messages that make a trace work.
- Ubiquiti, Creating Virtual Networks (VLANs), for where each network's gateway address is set.
- Kodi A. Cochran, CompTIA Network+ (N10-009) Certification Companion (Apress, 2026), chapter 6, command-line tools.