All guided builds

Guided buildcore7 steps~22 min4 devices

A stub branch and one default route

Send everything a branch can't place to HQ with a single default route, and see why HQ still needs a specific route back for every branch network.

What you'll be able to do: A hub-and-spoke pair where the branch reaches every network at HQ — including ones added later — through one default route, and HQ reaches each branch network through a specific static route of its own.

Topics: Default routes · Static routing · Routing tables · Return paths

What you'll build

Step by step

  1. 1. Stand up headquarters

    Drag in a router and a PC, cable the PC into Gi0/0, then name both and address the HQ LAN, 172.20.0.0/24. This is the hub: the site every branch sends its traffic to.

    • Cable HQ Gi0/0 ↔ PC-HQ Eth0

    On HQ — Name the router and make Gi0/0 the HQ LAN's gateway

    enable
    configure terminal
    hostname HQ
    interface Gi0/0
    ip address 172.20.0.1 255.255.255.0
    no shutdown
    exit
    end

    On PC-HQ — Name the workstation, address it, and point it at its gateway

    hostname PC-HQ
    ipconfig Eth0 172.20.0.10 255.255.255.0 172.20.0.1

    Check: run show ip route on HQ and look for C 172.20.0.0/24 is directly connected, Gi0/0.

    Why: A router knows the networks on its own live interfaces for free — those are the C lines. Everything else it has to be told, by you or by a routing protocol, and the rest of this build is about telling it as little as possible.

  2. 2. Stand up the branch

    Same recipe for the branch: a router, a PC, one cable, and a subnet of its own — 192.168.40.0/24. Read the branch router's table afterwards: one connected network and nothing else.

    • Cable Branch Gi0/0 ↔ PC-Branch Eth0

    On Branch — Name the router and make Gi0/0 the branch LAN's gateway

    enable
    configure terminal
    hostname Branch
    interface Gi0/0
    ip address 192.168.40.1 255.255.255.0
    no shutdown
    exit
    end

    On PC-Branch — Name the workstation, address it, and point it at its gateway

    hostname PC-Branch
    ipconfig Eth0 192.168.40.10 255.255.255.0 192.168.40.1

    Check: run show ip route on Branch and look for C 192.168.40.0/24 is directly connected, Gi0/0.

    Why: This branch will only ever have one link to the outside world. A network with a single exit is a stub, and a stub never has a routing decision to make: whatever is not local goes out the one link.

  3. 3. Run the WAN link

    Draw a serial cable between the two Se0/0/0 ports and address both ends out of 10.255.0.0/30 — HQ takes .1, Branch .2. Each router can now reach the other's WAN address, and still neither LAN.

    • Cable HQ Se0/0/0 ↔ Branch Se0/0/0 (serial)

    On HQ — Take the HQ end of the link, 10.255.0.1/30

    enable
    configure terminal
    interface Se0/0/0
    ip address 10.255.0.1 255.255.255.252
    no shutdown
    exit
    end

    On Branch — Take the branch end, 10.255.0.2/30

    enable
    configure terminal
    interface Se0/0/0
    ip address 10.255.0.2 255.255.255.252
    no shutdown
    exit
    end

    Check: run show ip route on Branch and look for C 10.255.0.0/30 is directly connected, Se0/0/0.

    Why: A /30 holds exactly two usable addresses, one for each end of a point-to-point link. The link is now a connected network on both routers — but a router forwards only toward networks in its table, and neither LAN is in the other's.

  4. 4. Give the branch one way out: the default route

    On Branch, one line: `ip route 0.0.0.0 0.0.0.0 10.255.0.1` — anything with no better route goes to HQ. The Branch router can now ping PC-HQ. Then ping the branch from PC-HQ: it dies at HQ, which still has no idea where 192.168.40.0/24 is.

    On Branch — Send everything that is not local to HQ, then test it from the router

    enable
    configure terminal
    ip route 0.0.0.0 0.0.0.0 10.255.0.1
    end
    ping 172.20.0.10

    On PC-HQ — Try the trip toward the branch and watch it fail

    ping 192.168.40.10

    Check: run show ip route on Branch and look for S* 0.0.0.0/0 via 10.255.0.1, Se0/0/0.

    Why: 0.0.0.0/0 matches every address with the shortest possible prefix, so longest-prefix matching uses it only when nothing more specific fits — the last resort, which is exactly what `show ip route` calls it. Branch's own ping comes back because it leaves from 10.255.0.2, an address on a link HQ is plugged into; a packet addressed to the branch LAN has no such luck.

  5. 5. Write HQ's route back — a specific one

    HQ is where the branch's traffic goes by default, so a default route back would only point the problem at the branch. HQ needs a specific route per branch network: `ip route 192.168.40.0 255.255.255.0 10.255.0.2`. Repeat PC-HQ's ping and the two LANs talk in both directions.

    On HQ — Point HQ at the branch LAN, via the branch end of the link

    enable
    configure terminal
    ip route 192.168.40.0 255.255.255.0 10.255.0.2
    end

    On PC-HQ — Repeat the ping that failed

    ping 192.168.40.10

    Check: run show ip route static on HQ and look for S 192.168.40.0/24 via 10.255.0.2, Se0/0/0.

    Why: Every reply needs a route home. The branch's default route carries packets to HQ; HQ's specific route carries the answers — and anything HQ starts — back. Routing is always two one-way decisions, made on two different routers.

  6. 6. HQ grows — and the branch doesn't notice

    Add a new network at HQ: a loopback interface, 172.20.50.1/24, standing in for a new server subnet. Then ping it from PC-Branch without touching Branch at all — its default route already covers it, as it will cover every network HQ ever adds.

    On HQ — Add a new network at HQ on a loopback interface

    enable
    configure terminal
    interface Loopback1
    ip address 172.20.50.1 255.255.255.0
    exit
    end

    On PC-Branch — Reach the new network with no change at the branch

    ping 172.20.50.1

    Check: run show ip route on HQ and look for C 172.20.50.0/24 is directly connected, Loopback1.

    Why: A default route is a promise that someone upstream knows more. The branch never needs to — which is why a stub site can be configured once and left alone while everything behind its hub keeps changing.

  7. 7. The branch grows — and HQ has to be told

    Now the reverse: give Branch a second network on a loopback, 192.168.41.1/24, and ping it from PC-HQ. The first ping fails — HQ holds a route for 192.168.40.0/24 only. Add the matching route on HQ, and the second ping comes back.

    On Branch — Add a second network at the branch

    enable
    configure terminal
    interface Loopback0
    ip address 192.168.41.1 255.255.255.0
    exit
    end

    On PC-HQ — Try to reach it before HQ knows about it

    ping 192.168.41.1

    On HQ — Tell HQ where the new branch network lives

    enable
    configure terminal
    ip route 192.168.41.0 255.255.255.0 10.255.0.2
    end

    On PC-HQ — Try again once HQ has the route

    ping 192.168.41.1

    Check: run show ip route static on HQ and look for S 192.168.41.0/24 via 10.255.0.2, Se0/0/0.

    Why: That is the asymmetry of hub-and-spoke routing: the stub needs one line forever, the hub needs one line per network behind every spoke. It is also exactly the bookkeeping a dynamic routing protocol exists to take off your hands.

The theory behind it

Build it for real

The lab walks you through these steps and ticks each one off as your network starts working.

Open in the lab
A stub branch and one default route — step-by-step network lab · NetForge-AI