What is a default gateway?
The default gateway is the IP address of the router that a device sends traffic to when the destination is not on its own subnet. It is the device's "way out" of the local network. On a home network it is usually the home router, often at an address like 192.168.1.1.
It is called "default" because the device uses it whenever it has no more specific route. Most PCs know only two things: their own subnet, and the gateway for everything else.
💡 In simple terms: picture an office building with internal mail. For a colleague on your floor, you carry the envelope over yourself. For anyone outside the building, you drop it at the mailroom and let the mailroom staff handle it. The mailroom is your default gateway. You don't need to know the route to every city; you only need to know where the mailroom is.
Why a gateway is required
On its own, a PC connected to a switch can only reach devices in its own broadcast domain: the devices that receive its broadcasts. That is its subnet. Two facts make a gateway necessary:
- Switches don't move traffic between subnets. A Layer 2 switch forwards frames by MAC address inside one network. It never looks at IP addresses.
- ARP can't cross a router. To send a frame, a PC must learn the receiver's MAC address with an ARP broadcast, and routers don't forward broadcasts. A PC can never learn the MAC address of a server in another network, let alone on the internet.
So the PC needs a device on its own subnet that is also connected to other networks and knows how to forward packets between them. That device is a router, and the address of its interface on your subnet is your default gateway. Without one, a PC can talk to its neighbours but not to anything else, including the internet.
Where the gateway sits
- 1. Local traffic skips the gateway. Traffic from PC-A to PC-B stays inside 192.168.10.0/24. The switch delivers it, and the router never sees it.
- 2. Remote traffic goes to the gateway. PC-A sends the packet for the web server to 192.168.10.1, the router's interface on its own subnet.
- 3. The router takes it from there. R1 looks up 203.0.113.20 in its routing table and forwards the packet towards the internet.
- 4. Replies come back the same way. The reply reaches R1, which delivers it directly to PC-A on the 192.168.10.0/24 subnet.
Several kinds of device can act as the gateway:
| Where | Typical gateway device | Typical address |
|---|---|---|
| Home | Home router (router + switch + Wi-Fi + NAT in one box) | 192.168.1.1 or 192.168.0.1 |
| Small office | A router or a firewall | Often .1 or .254 of the subnet |
| Larger office | A Layer 3 switch with one interface per VLAN | One gateway address in every VLAN |
| Cloud network | A virtual router provided by the cloud | Usually the first address of the subnet |
The parts that make it work
Gateway IP address
Typed in or learned from DHCP, for example 192.168.10.1. It must be inside the host's own subnet, or the host can't reach it.
Gateway MAC address
Learned with ARP the first time it is needed, then kept in the ARP cache. This is the address that goes into the frame.
Default route
Inside the host, the gateway setting becomes a route for 0.0.0.0/0: “send anything I have no better route for via 192.168.10.1”.
The router interface
The gateway is not a whole router; it is one router interface that sits in your subnet. Each subnet has its own gateway address.
A PC gets its gateway either from DHCP (the "router" option, which is how almost all laptops and phones get it) or from a static setting entered by an administrator.
How a PC decides: local or remote?
Before it sends a packet, the PC makes the same decision every time. It uses its own IP address and its subnet mask. In this example, PC-A has:
| IP address | 192.168.10.10 |
| Subnet mask | 255.255.255.0 (/24) |
| Default gateway | 192.168.10.1 |
Worked examples
| Destination | What it is | Compare (/24) | PC-A's decision |
|---|---|---|---|
192.168.10.20 | PC-B, same room | 192.168.10 = 192.168.10 | Local: send directly to PC-B |
192.168.10.1 | The gateway itself | 192.168.10 = 192.168.10 | Local: send directly to the router |
192.168.20.5 | File server, other floor | 192.168.10 ≠ 192.168.20 | Remote: send to the gateway |
203.0.113.20 | Web server on the internet | 192.168.10 ≠ 203.0.113 | Remote: send to the gateway |
Behind the scenes, the PC actually checks its routing table. It holds a route for its own subnet ("on-link") and a default route, 0.0.0.0/0, pointing at the gateway. The most specific matching route wins, so local addresses match the subnet route and everything else falls through to the default route. The result is the same as the comparison above.
Why remote traffic goes to the gateway
The PC can't send a frame straight to 203.0.113.20, because it can't learn that server's MAC address: its ARP broadcast would never leave the local subnet. Even if it could, a MAC address is only useful on one local link. So the PC does the only thing it can: it hands the packet to a device on its own link that can move it further. The router accepts the frame (because it is addressed to the router's MAC address), removes the Ethernet header, reads the destination IP address and forwards the packet towards its destination in a new frame.
What the frame looks like
This is the most important idea in this lesson. Compare the frame that PC-A sends to a local neighbour with the frame it sends to a remote server. This lesson uses these addresses:
| Device | IP address | MAC address |
|---|---|---|
| PC-A | 192.168.10.10 | 02:00:00:00:00:aa |
| PC-B | 192.168.10.20 | 02:00:00:00:00:bb |
| Gateway (R1 G0/0) | 192.168.10.1 | 02:00:00:00:00:01 |
| Web server | 203.0.113.20 | Unknown to PC-A, and never needed |
Local: PC-A → PC-B
Destination is on 192.168.10.0/24
Remote: PC-A → web server
Destination is NOT on 192.168.10.0/24
In the remote frame, the two layers point at different devices. The destination MAC says "this frame is for the gateway"; the destination IP says "this packet is for the web server". The gateway's IP address 192.168.10.1 appears nowhere in the frame or the packet. The PC only uses it to look up the gateway's MAC address with ARP.
The full exchange, step by step
Later lessons follow this exact journey again, hop by hop.
Learn more: ARP for Local and Remote DestinationsDifferent-Subnet Communication
A real-world example: opening a website at home
- Your laptop (
192.168.1.10/24) got its settings from the home router by DHCP, including the gateway192.168.1.1. - You open a website. DNS returns its address,
203.0.113.20. - The laptop compares the network parts: 192.168.1 ≠ 203.0.113, so the site is remote.
- It already has the router's MAC address in its ARP cache, so it sends the frame straight to the router.
- The home router translates the source address with NAT and sends the packet to the internet provider.
- The reply comes back to the router, which reverses the NAT translation and delivers it to the laptop on the local subnet.
Even the DNS query in step 2 goes through the gateway if the DNS server is outside the local subnet. Almost everything a laptop does online passes through the default gateway.
What happens when the gateway is wrong or missing
A gateway problem has a very typical signature: local devices work, everything else fails. Here are the common cases for PC-A:
| Problem | Example setting | What happens |
|---|---|---|
| No gateway | (blank) | PC-A has no default route, so remote destinations fail immediately. Windows ping shows "transmit failed. General failure"; Linux shows "Network is unreachable". |
| Gateway address nobody uses | 192.168.10.99 | PC-A sends an ARP request for .99 and gets no reply. Remote pings report "Destination host unreachable" from PC-A's own address. |
| Gateway is another PC | 192.168.10.20 (PC-B) | ARP works, so frames go to PC-B. PC-B is not a router, so it normally drops them. Remote traffic simply times out. |
| Gateway in a different subnet | 192.168.20.1 | PC-A can't reach it directly. Most systems warn you or refuse the setting; if it is accepted, remote traffic fails. |
| Correct gateway, but the router is down | 192.168.10.1 | The same as an unused address: no ARP reply and no ping reply. Every PC on the subnet loses access to other networks at once. |
- 1. Local still works. PC-B is on the same subnet, so the gateway setting is not used.
- 2. PC-A asks for the wrong gateway. To reach the web server, PC-A sends an ARP request for 192.168.10.99. Every device receives it, but nobody has that address.
- 3. No MAC, no frame. With no ARP reply, PC-A can't build the frame. Ping reports “Destination host unreachable”, and the router never even receives the packet.
How to check the gateway
Windows
C:\> ipconfig Ethernet adapter Ethernet: IPv4 Address. . . . . . . . . . . : 192.168.10.10 Subnet Mask . . . . . . . . . . . : 255.255.255.0 Default Gateway . . . . . . . . . : 192.168.10.1
255.255.255.0 mask), and it is not your own address.C:\> route print -4 IPv4 Route Table =========================================================================== Active Routes: Network Destination Netmask Gateway Interface Metric 0.0.0.0 0.0.0.0 192.168.10.1 192.168.10.10 25 127.0.0.0 255.0.0.0 On-link 127.0.0.1 331 192.168.10.0 255.255.255.0 On-link 192.168.10.10 281 192.168.10.10 255.255.255.255 On-link 192.168.10.10 281 192.168.10.255 255.255.255.255 On-link 192.168.10.10 281 ===========================================================================
0.0.0.0 and netmask 0.0.0.0 is the default route, created from the gateway setting; its Gateway column shows 192.168.10.1. On-link means "deliver directly", so 192.168.10.0 / 255.255.255.0 On-link is the local subnet.C:\> ping 192.168.10.1 Pinging 192.168.10.1 with 32 bytes of data: Reply from 192.168.10.1: bytes=32 time<1ms TTL=255 Reply from 192.168.10.1: bytes=32 time<1ms TTL=255 Reply from 192.168.10.1: bytes=32 time<1ms TTL=255 Reply from 192.168.10.1: bytes=32 time<1ms TTL=255 Ping statistics for 192.168.10.1: Packets: Sent = 4, Received = 4, Lost = 0 (0% loss)
C:\> ping 203.0.113.20 Pinging 203.0.113.20 with 32 bytes of data: Reply from 192.168.10.10: Destination host unreachable. Reply from 192.168.10.10: Destination host unreachable. Reply from 192.168.10.10: Destination host unreachable. Reply from 192.168.10.10: Destination host unreachable.
192.168.10.10. The PC is telling you it couldn't find the next hop's MAC address with ARP. That points to a wrong gateway setting or a gateway that is down.Linux and macOS
$ ip route default via 192.168.10.1 dev eth0 proto dhcp metric 100 192.168.10.0/24 dev eth0 proto kernel scope link src 192.168.10.10 metric 100
default via 192.168.10.1 line is the default route, so 192.168.10.1 is the gateway. proto dhcp shows it was learned from DHCP. The second line is the local subnet. On macOS, use netstat -rn or route -n get default.$ ip route get 203.0.113.20 203.0.113.20 via 192.168.10.1 dev eth0 src 192.168.10.10 uid 1000 cache
via 192.168.10.1 means "remote, through the gateway". For a local address such as 192.168.10.20, the answer has no via: 192.168.10.20 dev eth0 src 192.168.10.10.A quick troubleshooting order
The troubleshooting unit and the command guides give you more practice.
Learn more: IP and Gateway ProblemsEssential Windows Network CommandsEssential Linux Network Commands
Common mistakes
- Thinking the destination IP becomes the gateway's IP. It doesn't. Only the destination MAC address points at the gateway.
- Putting the gateway in a different subnet from the PC. The PC can't reach it with ARP. This often happens after copying settings from another office.
- Setting a server's gateway to its own address. A server is not a router, so remote traffic has nowhere to go.
- Blaming the gateway when local traffic also fails. If PC-B is unreachable too, check the cable, the switch or the IP address first.
- Setting default gateways on two adapters. The PC chooses one by metric, and traffic can leave through the wrong interface.
- Assuming the gateway is always .1. It is only a convention, so check the real setting.
- The default gateway is the router interface on your subnet that carries traffic to every other network.
- The PC uses its subnet mask to compare network parts: same → deliver directly; different → send to the gateway.
- For remote traffic: destination MAC = gateway, destination IP = the remote host.
- The PC uses ARP to find the gateway, never a remote host.
- Gateway trouble = local works, remote fails. Check the setting with ipconfig, route print or ip route, then ping the gateway.
Check yourself
PC-A (192.168.10.10/24, gateway 192.168.10.1) sends a packet to 203.0.113.20. What is the destination MAC address of the frame it sends?
PC-A sends a packet to 203.0.113.20 through the gateway. What is the destination IP address in the packet?
Users can print to a printer on their own subnet but can't open any website or reach other subnets. What is the most likely problem?
PC-A's gateway is set to 192.168.10.20, which is PC-B (an ordinary PC). What happens to traffic for the internet?
To see how a device turns the gateway's IP address into a MAC address, continue with ARP.
Learn more: ARP Fundamentals