Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Eliminating a default route can stop a device from sending traffic to destinations that have no more specific route—but it can also cut off internet or other remote-network access. It is not a universal security hardening step or a substitute for firewall rules. Before changing anything, identify the device, IPv4 or IPv6 routing table, and service or profile that installed the route.

What a default route does

A default route is the fallback route used when a destination does not match a more specific entry in the routing table. On Linux, the route(8) manual describes the default route as appearing in the destination field as default or 0.0.0.0. Removing it can prevent otherwise-unmatched traffic from being routed; it does not remove more-specific routes.

Whether that is useful depends on the intended policy. If a host should communicate only with explicitly routed networks, removing its fallback may help enforce that reachability design. If the goal is to filter inbound connections, control which applications can send traffic, or block selected destinations, route deletion alone does not provide those controls.

Check what will change before deleting a route

Do not assume that a route shown in one table represents all traffic. Confirm the operating system and routing mechanism in use, the address family, and the route’s interface and gateway. Also determine whether the entry comes from a network profile, DHCP, a VPN, a router protocol, or a managed cloud configuration.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Scope: Identify the device and routing table you intend to change.
  • Address family: Check IPv4 and IPv6 independently. A change to one family does not establish that the other family has changed.
  • Route source: Find the service or profile that installs the route, especially if you need the change to survive a reconnect or reboot.
  • Required reachability: List the networks and services that must remain reachable after the fallback is gone.

Delete a default route with Linux route(8)

The following is the Linux route utility’s documented command for deleting the current default route:

route del default

This is a live routing-table operation; the command does not by itself configure a persistent change. The utility documents separate address-family options, -4 and -6, but its deletion example is not a complete paired procedure for removing IPv4 and IPv6 defaults. Verify the installed platform’s current tools and documentation before changing either table.

  1. Inspect the active routing table with the tools appropriate to your Linux system. Confirm that the default entry is the one you intend to remove, and note its interface and gateway.
  2. Run route del default only when the Linux route utility and the identified route are in scope.
  3. Inspect the routing table again. Check which destinations still have routes, then test only the connectivity that is supposed to remain.
  4. If the default returns after reconnect or reboot, change the configuration that supplies it. The persistent method depends on the operating system, network manager, VPN, DHCP service, or cloud networking product; there is no single procedure established for every platform.

Route removal is not firewalling

Removing a fallback route changes where unmatched traffic can go; it does not create a complete security boundary. It does not, by itself, define inbound filtering, application-level egress policy, or protection against traffic covered by other routes. Use firewall rules or the platform’s supported network controls when those are the requirements. The Linux manual makes the distinction explicit for its reject-route option: “This is NOT for firewalling.” See the route(8) manual.

Choose the control that matches the problem

Situation What to consider
Testing a temporary route-table change A live deletion can test reachability, but it does not establish persistence across reconnects or reboots.
Keeping a route absent after reconnect or reboot Change the authoritative network profile or service that adds it. The method is platform-specific.
Changing only DNS behavior over a VPN Use the VPN and DNS-routing controls intended for that purpose; DNS route selection is not the same as deleting an IP default route.
Controlling router-learned or advertised routes Review which route sources and prefixes are trusted, accepted, and advertised. Host-side deletion is not a replacement for routing policy.
Blocking traffic or limiting application access Use firewall policy or supported network controls rather than treating the missing fallback route as a firewall.

VPNs: separate IP routing from DNS routing

A VPN can affect IP routes and DNS selection through distinct settings. systemd’s VPN DNS documentation describes a corporate VPN example that assigns a specific DNS routing domain and sets resolvectl default-route <iface> false. Its privacy VPN example instead routes the DNS domain ~. over that link. These are per-link DNS decisions, not general procedures for deleting a kernel IP default route. If the concern is that a VPN becomes the default IP gateway, identify the VPN client’s route configuration and follow the documentation for that client and operating system.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Routers and managed cloud networks need their own route policy

For routers, the question may be less about deleting one local fallback and more about which neighbors and routing sources are trusted, what prefixes are accepted, and what is advertised onward. RFC 1812, section 7.1.1, says a router should be able to rank routing information sources by trustworthiness and accept destination information from the most trustworthy sources first. It also advises against redistributing routing data that the router does not use, trust, or consider valid.

Managed cloud routing is product-specific. In its forced-tunnel guidance, Azure Virtual WAN documentation describes outcomes after default-route advertisements and static routes are withdrawn: depending on the security solution and configuration, internet traffic may be dropped or blackholed, or a firewall with a public IP may route it using that address. Those outcomes are specific to the documented Azure configurations. Inspect effective routes and follow the cloud product’s design guidance before changing route advertisements.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.