A real-life situation
PC1 can reach the branch server now, but not a website at 198.51.100.80. R1 would need a route for every network on the internet: about a million of them. You can't type those in. Instead you add one route that means "everything else".
What a default route is
A default route is the route 0.0.0.0/0. Its prefix length is zero, so it matches every IPv4 address. Because it is the shortest possible prefix, longest prefix match (the “Longest prefix match” lesson) only uses it when no other route matches. It is a catch-all.
The next hop of the default route is called the gateway of last resort. It does the same job for a router as the default gateway does for a PC.
- 1. R1: no specific route matches, so the default route sends the packet to the ISP at 203.0.113.1.
- 2. R3 is a stub: it has only one way out, through R2. One default route via 10.0.23.1 replaces every other route it would need.
- 3. R2 passes it on: with its own default route via 10.0.12.1, internet traffic from the branches reaches R1 and then the ISP.
Why it works this way
A stub network is a network with only one way in and out, like a branch office with one link to head office. For a stub, every remote network is reached the same way. Listing them one by one adds work and gains nothing, so a single default route is the cleanest design.
| Router | Its position | Routes it needs |
|---|---|---|
| R1 | Edge, toward the internet | Specific routes to the company LANs + default to the ISP |
| R2 | Middle | Specific routes both ways + default toward R1 |
| R3 | Stub (one exit) | Only a default toward R2 |
PC1 uses a private address (192.168.1.10). The internet can't route back to private addresses, so R1 must also translate it to its public address, 203.0.113.2. That job is called NAT. The default route gets packets out; NAT makes sure replies can come back.
Configure it
⚠️ Based on Cisco IOS / IOS XE documentation, not run on a lab device.
ip route 0.0.0.0 0.0.0.0 203.0.113.1On R1: everything not listed elsewhere goes to the ISP.
ip route 0.0.0.0 0.0.0.0 10.0.12.1On R2: unknown destinations go toward R1.
ip route 0.0.0.0 0.0.0.0 10.0.23.1On R3: the only route this stub router needs besides its connected networks.
How to verify it
This output is based on Cisco documentation, not run on a lab device.
R3#show ip route Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP * - candidate default, U - per-user static route ... Gateway of last resort is 10.0.23.1 to network 0.0.0.0 S* 0.0.0.0/0 [1/0] via 10.0.23.1 10.0.0.0/8 is variably subnetted, 2 subnets, 2 masks C 10.0.23.0/30 is directly connected, GigabitEthernet0/0 L 10.0.23.2/32 is directly connected, GigabitEthernet0/0 192.168.3.0/24 is variably subnetted, 2 subnets, 2 masks C 192.168.3.0/24 is directly connected, GigabitEthernet0/1 L 192.168.3.1/32 is directly connected, GigabitEthernet0/1
S* marks the static default, and the "Gateway of last resort" line confirms it is in use. Without a default the line reads "Gateway of last resort is not set".Check yourself
R1 has 192.168.3.0/24 via R2 and 0.0.0.0/0 via the ISP. Which route does a packet to 192.168.3.10 use?
Why is a single default route enough on R3?