A real-life situation
The company adds a cheap backup link straight from R1 to R3. Normal traffic should still go through R2, which has the faster links. But if the link from R1 to R2 fails, traffic should move to the backup on its own, without anyone logging in at 3 a.m.
What a floating static route is
A floating static route is a static route with a higher administrative distance than the main route. Both are in the configuration, but only the one with the lower AD goes into the routing table. The backup "floats" above it, out of sight, until the main route disappears.
You set the AD by adding a number at the end of the ip route command. Any value from 2 to 254 is higher than a normal static route (AD 1).
- 1. Normal day: the AD 1 route via R2 is in the table. The AD 5 route via the backup link is configured but hidden.
- 2. The R1–R2 link fails. Its next hop, 10.0.12.2, is no longer reachable, so R1 removes the AD 1 route.
- 3. The backup floats down: the AD 5 route is now the best one left, so it enters the table. Traffic uses the R1–R3 link.
Why it works this way
AD only decides between routes for the same prefix. Both routes here are for 192.168.3.0/24, so the lower AD wins and the other is held back. When the winner leaves the table, the router looks again and installs the next best one.
| Primary route learned by | Its AD | Backup AD must be above | Typical choice |
|---|---|---|---|
| Static | 1 | 1 | 5 or 10 |
| EIGRP | 90 | 90 | 95 |
| OSPF | 110 | 110 | 115 or 120 |
A static route is only removed when the router itself can tell the path is broken: its exit interface goes down, or the next hop is no longer in a connected network. If the R2–R3 link fails instead, R1 still sees R2 as up and keeps sending traffic there. That is one reason backup routes often sit behind a dynamic protocol, or use a Cisco feature called IP SLA tracking that tests the path with pings.
Configure it
⚠️ Based on Cisco IOS / IOS XE documentation, not run on a lab device. Routes are needed on both ends, so the return traffic can fail over too.
ip route 192.168.3.0 255.255.255.0 10.0.12.2
ip route 192.168.3.0 255.255.255.0 10.0.13.2 5On R1: primary via R2 (AD 1), floating backup via R3's backup interface (AD 5).
ip route 0.0.0.0 0.0.0.0 10.0.23.1
ip route 0.0.0.0 0.0.0.0 10.0.13.1 5On R3: primary default via R2, floating default over the backup link.
How to verify it
These outputs are based on Cisco documentation, not run on a lab device.
R1#show ip route static Gateway of last resort is 203.0.113.1 to network 0.0.0.0 S* 0.0.0.0/0 [1/0] via 203.0.113.1 S 192.168.3.0/24 [1/0] via 10.0.12.2
show running-config | include ip route.Now simulate the failure by shutting R1's link to R2:
R1(config-if)#shutdown %LINK-5-CHANGED: Interface GigabitEthernet0/1, changed state to administratively down %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet0/1, changed state to down
R1#show ip route static Gateway of last resort is 203.0.113.1 to network 0.0.0.0 S* 0.0.0.0/0 [1/0] via 203.0.113.1 S 192.168.3.0/24 [5/0] via 10.0.13.2
[5/0] shows the floating route has taken over. Run no shutdown and the [1/0] route returns.Check yourself
A primary route is learned by OSPF. You add a static backup with AD 100. What happens?
With the routes above, the R2–R3 link fails but R1–R2 stays up. Does R1 fail over?