Inspect and Safely Change Linux Routes with route

One wrong route del and you can cut off the very SSH session you are using to fix things. This guide covers reading the kernel routing table with route, spotting the default path, and adding or removing a specific network route without losing your connection. The examples use the net-tools 2.10 command on Ubuntu. Inspection takes a couple of minutes; changing a live route takes seconds, but plan your rollback before you touch a production host.

Before you start

You need a shell on the Linux machine and the route command from the net-tools package. Reading routes needs no elevated privileges; adding or deleting one normally does, so keep sudo for those commands only. Have the intended interface name, the gateway if there is one, and the exact destination network and netmask ready before you start.

Never open with deleting the default route. It handles every destination that has no more specific route, so removing it can cut off your remote session outright. Also remember a route change is live kernel state, not durable configuration: it can vanish when the interface or system restarts.

1. Capture the current IPv4 table

Start with a numeric listing. The -n option skips reverse name lookups, so the output is faster and you avoid a confusing pause when DNS is part of the problem.

route -n

Expect a header followed by rows like this:

Kernel IP routing table
Destination     Gateway         Genmask         Flags Metric Ref    Use Iface
0.0.0.0         192.0.2.1       0.0.0.0         UG    0      0        0 enp1s0
192.0.2.0       0.0.0.0        255.255.255.0   U     0      0        0 enp1s0

That is a snapshot of this machine, so your interface names and addresses will differ. The row with destination 0.0.0.0 and genmask 0.0.0.0 is the default route. U means the route is up; G means traffic goes through a gateway. Iface names the interface that receives the packet.

Checkpoint: write down the default gateway and interface, plus the row you intend to keep. If you are on SSH, leave this terminal open and, ideally, have a second session ready. Run route -n again after any change to compare.

2. Read the IPv6 table when needed

Add -6 to select the IPv6 address family. Without it, this installation defaults to IPv4.

route -6 -n

IPv6 output uses columns such as Destination, Next Hop, Flag, Met and If. A default IPv6 route shows as ::/0. Keep IPv4 and IPv6 decisions separate: adding an IPv4 route never touches the IPv6 table.

3. Add a network route

For a directly connected network, pick a real interface and the correct network address and mask. Replace every uppercase placeholder before running this template:

sudo route add -net NETWORK_ADDRESS netmask NETMASK dev INTERFACE

For example, this adds the network 198.51.100.0/24 through enp1s0:

sudo route add -net 198.51.100.0 netmask 255.255.255.0 dev enp1s0

The destination and netmask must describe the same network. dev forces the route onto the chosen interface. The kernel can often infer it on its own, but stating it keeps the intended path visible instead of leaning on an ambiguous existing route.

To send the network through a gateway instead, use one that is already reachable from this host:

sudo route add -net 198.51.100.0 netmask 255.255.255.0 gw 192.0.2.1 dev enp1s0

The manpage is explicit that the gateway must be reachable before you add the route. If it is not, the add fails outright or creates a route that cannot deliver a single packet. Confirm the gateway in the existing table and with whoever runs the network; do not lift it from a diagram.

4. Verify the new route

Check the table straight away for the destination, mask, flags and interface you asked for:

route -n

A working added route normally shows U in its flags, and a gateway route adds G. Missing row: read the error from the add command and check the interface exists, the address family is right, and the gateway is reachable. Present but still failing: a route only picks a path. It does not open a firewall, enable forwarding, or prove the remote host is listening.

For an extended, netstat-style view:

route -n -e

Use it for the extra columns, not as a connectivity test. Compare the interface and gateway shown against your network design.

5. Remove the test route

Deleting a route is privileged and state-changing. Use the same destination and netmask that showed up in the listing:

sudo route del -net 198.51.100.0 netmask 255.255.255.0

Confirm it is gone:

route -n

Added a host route instead? Use -host with the host address. Added a default route? Stop and record the existing default row first: deleting it can sever access, and restoring it needs the exact gateway and interface, for example:

sudo route add default gw GATEWAY_ADDRESS dev INTERFACE

That is a template, not something to run unchanged. A botched recovery can leave a remote machine unreachable, so use the exact values from the original table and have an out-of-band console ready when the host matters.

Common traps

Done means