Trace and Change Linux Routes Safely with ip route

Traffic is leaving by the wrong interface and nobody knows why; ip route get asks the kernel directly which path it will take. You will read the routing tables, explain the interface and gateway Linux picks for an address, and add or remove a route without losing track of the change.

The examples use ip from iproute2 6.1.0, as installed on Ubuntu on the verification host. Allow about 10 minutes for the read-only checks, or 15 to 20 if you add and undo a test route.

Before you start

Record the interface and gateway that already work before changing anything:

ip -br address
ip route show table main

1. Ask the kernel for a route

A route lookup asks the kernel's forwarding logic for the path to one destination. It sends no packet and changes nothing.

ip route get 1.1.1.1

On the verification host, the result was:

1.1.1.1 via 136.243.171.1 dev enp0s31f6 src 136.243.171.23 uid 1004
    cache

Read that as: gateway 136.243.171.1, device enp0s31f6, preferred source 136.243.171.23. Yours will differ. The cache line is output from this installation, not a route to add by hand.

If the application uses a particular source address, include it. That can expose a policy or interface problem a destination-only test hides:

ip route get 1.1.1.1 from 192.0.2.10

Tip: Use a source address that is really assigned on your machine. One that is not may correctly return RTNETLINK answers: Network is unreachable; that is a failed lookup, not proof the destination is down.

2. Inspect the tables

Show the normal table by name or number:

ip route show table main
ip route show table 254
ip route show table local | sed -n '1,12p'

Warning: Do not flush or edit the local table as a first troubleshooting step. It is normally managed automatically.

For a narrower search, use selectors. All read-only:

ip route show table main default
ip route show table main match 10.20.0.0/16
ip route show table all

Know the difference: show lists entries matching a selector, while get evaluates a destination and can take source, interface, mark, protocol, ports or VRF details. When the question is "what will this connection use?", reach for get.

3. Add one specific route

Only do this when you know the destination network, next-hop address and outgoing device. This adds a route to a documentation network through a directly reachable gateway:

sudo ip route add 203.0.113.0/24 via 192.0.2.1 dev enp0s31f6

Warning: This changes the kernel's live routing state and may interrupt traffic. It usually disappears at reboot unless your distribution's network manager persists it.

The gateway must be reachable through the chosen device, or ip will normally reject the route.

Warning: Never add onlink just to silence that error. It tells the kernel to accept a gateway that does not appear to be on the link, and can black-hole traffic.

Verify the exact prefix and the decision it causes:

ip route show exact 203.0.113.0/24
ip route get 203.0.113.25

Checkpoint: The first command shows the route you added; the second names your gateway and device. If the lookup still picks another route, check prefix length, table, policy rules and address family before changing anything again.

4. Undo the test route

Remove it as soon as you have finished testing:

sudo ip route del 203.0.113.0/24 via 192.0.2.1 dev enp0s31f6
ip route show exact 203.0.113.0/24

Checkpoint: No matching route remains, although another may appear if a different configuration source recreates one.

To alter a route in place rather than delete it:

sudo ip route replace 203.0.113.0/24 via 192.0.2.1 dev enp0s31f6

Tip: Treat replace as a state change, not a harmless retry. Keep the original ip route show output so you can restore the previous gateway, device, metric or source address.

Warning: Avoid ip route flush unless you have a narrowly scoped selector and an outage plan. A broad flush can remove the default route and disconnect the machine.

5. Use route attributes and policy rules

A route can carry more than a destination and gateway:

sudo ip route add 203.0.113.0/24 via 192.0.2.1 dev enp0s31f6 metric 200
ip route show exact 203.0.113.0/24

These attributes help explain output and policy, but they do not replace a working interface, address or gateway.

For policy routing, inspect the rules as well as the tables:

ip rule list
ip route show table all

A route in main is not necessarily used first. Rules can send lookups to a custom table, and a VRF can imply its associated table.

Tip: Give ip route get the same source address, interface or VRF the application will use.

6. Save and restore cautiously

A catch: ip route save writes a binary stream for ip route restore, not a human-readable backup.

ip route save table main > /tmp/main.routes
sudo ip route restore < /tmp/main.routes

Warning: Restore replays route data and can disrupt connectivity. Never restore a file from another host without checking its interfaces, addresses, gateways and table assumptions.

Keep the file private if your environment treats network layout as sensitive, and remove it once it is no longer needed.

Done means