Routelearn.net
Course menu

Course 8: RoutingLesson 2.1 (4 of 12 in this course)53 of 91 in the CCNA series

Configuring static routes

Next-hop and exit-interface routes, how to add them, and how to check they work.

Beginner · 8 min read

A static route is a route an administrator configures by hand, telling the router to reach a destination network through a given next-hop address or exit interface. It stays in the routing table while its next hop or interface is usable and does not adapt to changes elsewhere in the network.

In simple terms: Instead of the router learning the way by itself, you type the directions in. They stay exactly as you wrote them until you change them.

A real-life situation

The three routers are cabled and every interface is up. Yet PC1 still can't reach the server. R1 only knows its own connected networks. Nobody has told it that 192.168.3.0/24 exists behind R2 and R3. The quickest fix in a small network is a static route.

What a static route is

A static route is a route you type in by hand. It tells the router: "to reach this network, send packets this way". It never changes by itself. The command is:

ip route <network> <mask> {<next-hop-ip> | <exit-interface>} [<AD>]

Entered in global configuration mode. The mask is written in dotted decimal, not as /24.

There are three ways to say "which way":

TypeExampleGood for
Next hopip route 192.168.3.0 255.255.255.0 10.0.12.2Ethernet links. The usual choice.
Exit interfaceip route 192.168.3.0 255.255.255.0 Serial0/1/0Point-to-point links, where there is only one device on the other end.
Fully specifiedip route 192.168.3.0 255.255.255.0 GigabitEthernet0/1 10.0.12.2Ethernet, when you want the route tied to one interface and one neighbour.

Why it works this way

With a next hop, the router does a second lookup: it finds which connected network 10.0.12.2 belongs to, and uses that interface. This is called a recursive lookup.

With only an exit interface on Ethernet, the router has no neighbour address. It treats every destination as if it were directly on that link and sends an ARP request for each one. That only works if the neighbour answers on their behalf (a feature called proxy ARP), and it fills the ARP table. On Ethernet, always give the next hop.

Routing also has to work in both directions. A route on R1 gets the request to the server. The reply needs routes on R3 and R2 that lead back to 192.168.1.0/24. Missing return routes are the most common reason a static setup "half works".

192.168.1.0/24203.0.113.0/3010.0.12.0/3010.0.23.0/30192.168.2.0/24192.168.3.0/24PC1192.168.1.10ISP203.0.113.1R1R2R3PC2192.168.2.10Server192.168.3.10
  1. 1. R1 needs: 192.168.3.0/24 via 10.0.12.2.
  2. 2. R2 needs: 192.168.3.0/24 via 10.0.23.2. The request arrives.
  3. 3. R3 needs: 192.168.1.0/24 via 10.0.23.1, or the reply is dropped right here.
  4. 4. R2 needs: 192.168.1.0/24 via 10.0.12.1. Now the round trip works.

Configure it

⚠️ Based on Cisco IOS / IOS XE documentation, not run on a lab device. These four routes give PC1 and the server a working round trip. The lab in the “Lab: static routing across three routers” lesson completes the rest.

ip route 192.168.3.0 255.255.255.0 10.0.12.2

On R1: the server LAN is through R2.

ip route 192.168.3.0 255.255.255.0 10.0.23.2 ip route 192.168.1.0 255.255.255.0 10.0.12.1

On R2: forward toward R3, and back toward R1.

ip route 192.168.1.0 255.255.255.0 10.0.23.1

On R3: the return route to PC1's LAN.

How to verify it

This output is based on Cisco documentation, not run on a lab device.

Example output · based on Cisco documentation; exact format varies by platform and software version
R1#show ip route static
Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP
       ...

Gateway of last resort is not set

S     192.168.3.0/24 [1/0] via 10.0.12.2
The route is there with AD 1. A static route is only installed while its next hop is reachable. If Gi0/1 goes down, it disappears from the table (it stays in the running configuration).
Example output · based on Cisco documentation; exact format varies by platform and software version
R1#ping 192.168.3.10 source GigabitEthernet0/0
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.3.10, timeout is 2 seconds:
Packet sent with a source address of 192.168.1.1
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/2 ms
Sourcing the ping from the LAN interface tests the same return path PC1 would use. A plain ping would come from 10.0.12.1, which the other routers may have no route back to.

Check yourself

Predict · scenario 1

R1 has a route to 192.168.3.0/24, but R3 has no route to 192.168.1.0/24. PC1 pings the server. What happens?

Predict · scenario 2

Which form is recommended for a static route out of an Ethernet interface?