Guided buildcore7 steps~22 min4 devices
A stub branch and one default route
Send everything a branch can't place to HQ with a single default route, and see why HQ still needs a specific route back for every branch network.
What you'll be able to do: A hub-and-spoke pair where the branch reaches every network at HQ — including ones added later — through one default route, and HQ reaches each branch network through a specific static route of its own.
Topics: Default routes · Static routing · Routing tables · Return paths
What you'll build
- HQ — a router, the headquarters router every branch hangs off
- Branch — a router, the stub branch router with a single way out
- PC-HQ — a pc, a workstation on the headquarters LAN
- PC-Branch — a pc, a workstation at the branch
Step by step
1. Stand up headquarters
Drag in a router and a PC, cable the PC into Gi0/0, then name both and address the HQ LAN, 172.20.0.0/24. This is the hub: the site every branch sends its traffic to.
- Cable HQ Gi0/0 ↔ PC-HQ Eth0
On HQ — Name the router and make Gi0/0 the HQ LAN's gateway
enable configure terminal hostname HQ interface Gi0/0 ip address 172.20.0.1 255.255.255.0 no shutdown exit endOn PC-HQ — Name the workstation, address it, and point it at its gateway
hostname PC-HQ ipconfig Eth0 172.20.0.10 255.255.255.0 172.20.0.1Check: run
show ip routeon HQ and look forC 172.20.0.0/24 is directly connected, Gi0/0.Why: A router knows the networks on its own live interfaces for free — those are the C lines. Everything else it has to be told, by you or by a routing protocol, and the rest of this build is about telling it as little as possible.
2. Stand up the branch
Same recipe for the branch: a router, a PC, one cable, and a subnet of its own — 192.168.40.0/24. Read the branch router's table afterwards: one connected network and nothing else.
- Cable Branch Gi0/0 ↔ PC-Branch Eth0
On Branch — Name the router and make Gi0/0 the branch LAN's gateway
enable configure terminal hostname Branch interface Gi0/0 ip address 192.168.40.1 255.255.255.0 no shutdown exit endOn PC-Branch — Name the workstation, address it, and point it at its gateway
hostname PC-Branch ipconfig Eth0 192.168.40.10 255.255.255.0 192.168.40.1Check: run
show ip routeon Branch and look forC 192.168.40.0/24 is directly connected, Gi0/0.Why: This branch will only ever have one link to the outside world. A network with a single exit is a stub, and a stub never has a routing decision to make: whatever is not local goes out the one link.
3. Run the WAN link
Draw a serial cable between the two Se0/0/0 ports and address both ends out of 10.255.0.0/30 — HQ takes .1, Branch .2. Each router can now reach the other's WAN address, and still neither LAN.
- Cable HQ Se0/0/0 ↔ Branch Se0/0/0 (serial)
On HQ — Take the HQ end of the link, 10.255.0.1/30
enable configure terminal interface Se0/0/0 ip address 10.255.0.1 255.255.255.252 no shutdown exit endOn Branch — Take the branch end, 10.255.0.2/30
enable configure terminal interface Se0/0/0 ip address 10.255.0.2 255.255.255.252 no shutdown exit endCheck: run
show ip routeon Branch and look forC 10.255.0.0/30 is directly connected, Se0/0/0.Why: A /30 holds exactly two usable addresses, one for each end of a point-to-point link. The link is now a connected network on both routers — but a router forwards only toward networks in its table, and neither LAN is in the other's.
4. Give the branch one way out: the default route
On Branch, one line: `ip route 0.0.0.0 0.0.0.0 10.255.0.1` — anything with no better route goes to HQ. The Branch router can now ping PC-HQ. Then ping the branch from PC-HQ: it dies at HQ, which still has no idea where 192.168.40.0/24 is.
On Branch — Send everything that is not local to HQ, then test it from the router
enable configure terminal ip route 0.0.0.0 0.0.0.0 10.255.0.1 end ping 172.20.0.10On PC-HQ — Try the trip toward the branch and watch it fail
ping 192.168.40.10Check: run
show ip routeon Branch and look forS* 0.0.0.0/0 via 10.255.0.1, Se0/0/0.Why: 0.0.0.0/0 matches every address with the shortest possible prefix, so longest-prefix matching uses it only when nothing more specific fits — the last resort, which is exactly what `show ip route` calls it. Branch's own ping comes back because it leaves from 10.255.0.2, an address on a link HQ is plugged into; a packet addressed to the branch LAN has no such luck.
5. Write HQ's route back — a specific one
HQ is where the branch's traffic goes by default, so a default route back would only point the problem at the branch. HQ needs a specific route per branch network: `ip route 192.168.40.0 255.255.255.0 10.255.0.2`. Repeat PC-HQ's ping and the two LANs talk in both directions.
On HQ — Point HQ at the branch LAN, via the branch end of the link
enable configure terminal ip route 192.168.40.0 255.255.255.0 10.255.0.2 endOn PC-HQ — Repeat the ping that failed
ping 192.168.40.10Check: run
show ip route staticon HQ and look forS 192.168.40.0/24 via 10.255.0.2, Se0/0/0.Why: Every reply needs a route home. The branch's default route carries packets to HQ; HQ's specific route carries the answers — and anything HQ starts — back. Routing is always two one-way decisions, made on two different routers.
6. HQ grows — and the branch doesn't notice
Add a new network at HQ: a loopback interface, 172.20.50.1/24, standing in for a new server subnet. Then ping it from PC-Branch without touching Branch at all — its default route already covers it, as it will cover every network HQ ever adds.
On HQ — Add a new network at HQ on a loopback interface
enable configure terminal interface Loopback1 ip address 172.20.50.1 255.255.255.0 exit endOn PC-Branch — Reach the new network with no change at the branch
ping 172.20.50.1Check: run
show ip routeon HQ and look forC 172.20.50.0/24 is directly connected, Loopback1.Why: A default route is a promise that someone upstream knows more. The branch never needs to — which is why a stub site can be configured once and left alone while everything behind its hub keeps changing.
7. The branch grows — and HQ has to be told
Now the reverse: give Branch a second network on a loopback, 192.168.41.1/24, and ping it from PC-HQ. The first ping fails — HQ holds a route for 192.168.40.0/24 only. Add the matching route on HQ, and the second ping comes back.
On Branch — Add a second network at the branch
enable configure terminal interface Loopback0 ip address 192.168.41.1 255.255.255.0 exit endOn PC-HQ — Try to reach it before HQ knows about it
ping 192.168.41.1On HQ — Tell HQ where the new branch network lives
enable configure terminal ip route 192.168.41.0 255.255.255.0 10.255.0.2 endOn PC-HQ — Try again once HQ has the route
ping 192.168.41.1Check: run
show ip route staticon HQ and look forS 192.168.41.0/24 via 10.255.0.2, Se0/0/0.Why: That is the asymmetry of hub-and-spoke routing: the stub needs one line forever, the hub needs one line per network behind every spoke. It is also exactly the bookkeeping a dynamic routing protocol exists to take off your hands.
The theory behind it
More in Foundations
- One router, one PC, one ping — Build the smallest network that works: address a router and a PC on the same subnet and get a reply back.
- Three hosts, one switch — Put three PCs on a single subnet through an unconfigured switch and watch it learn who lives where.
- ARP and MAC learning, side by side — Watch a host's ARP cache and a switch's MAC table fill from the very first frame — and see why a host never ARPs for anything beyond its gateway.
- Two LANs, one router — Put a PC on each of two different subnets and make them talk through a router.
- VLSM for two sites — Carve one /24 into a /26, a /27 and a /30 sized to what each site needs, then route between them with masks that match the plan.
- Traceroute across three routers — Chain three routers with static routes and follow a packet hop by hop — then watch a trace stop at a missing route and circle in a routing loop.
Build it for real
The lab walks you through these steps and ticks each one off as your network starts working.
Open in the lab