All guided builds

Guided buildadvanced7 steps~22 min5 devices

Share one default route with OSPF

Give the edge router a default route to the provider, then let OSPF hand it to the rest of the campus instead of typing it on every router.

What you'll be able to do: The campus reaches the internet through its one edge router, and the only default route anyone typed is on that router: OSPF delivers it to the inside as O*E2 0.0.0.0/0, so the next router added inside gets it for free.

Topics: OSPF · Default routes · Dynamic routing · Routing tables

What you'll build

Step by step

  1. 1. Stand up the campus LAN

    Drag a router and a PC onto the canvas, cable the PC into Gi0/0, name the router Core and give Gi0/0 the campus gateway address. The campus owns 192.0.2.0/24, a public block its provider assigned, so nothing in this build needs NAT: the provider routes that block straight back to the campus.

    • Cable PC-A Eth0 ↔ Core Gi0/0

    On Core — Name the campus router and address the LAN port

    enable
    configure terminal
    hostname Core
    interface Gi0/0
    ip address 192.0.2.1 255.255.255.0
    no shutdown
    exit
    end

    On PC-A — Name the workstation and set address, mask and gateway

    hostname PC-A
    ipconfig Eth0 192.0.2.10 255.255.255.0 192.0.2.1

    Check: run show ip route on Core and look for C 192.0.2.0/24 is directly connected, Gi0/0.

    Why: PC-A hands anything outside 192.0.2.0/24 to its gateway, 192.0.2.1 — a host's default route, one line that means 'everything I don't know, give to Core'. By the end of this build Core has a default route of its own, and nobody will have typed it on Core.

  2. 2. Bring in the edge router and start OSPF

    Place a second router — the only one that will ever touch the provider — cable Core Gi0/1 to its Gi0/0, and number the link 10.0.0.0/30. Run OSPF on both: Core advertises the campus LAN and the link, Edge only the link. Edge learns the campus subnet from Core, which is OSPF doing its everyday job inside the campus.

    • Cable Core Gi0/1 ↔ Edge Gi0/0

    On Core — Address the link to Edge and advertise both campus networks

    enable
    configure terminal
    interface Gi0/1
    ip address 10.0.0.1 255.255.255.252
    no shutdown
    exit
    router ospf 1
    router-id 1.1.1.1
    network 192.0.2.0 0.0.0.255 area 0
    network 10.0.0.0 0.0.0.3 area 0
    end

    On Edge — Name the edge router and run OSPF on its campus-facing link

    enable
    configure terminal
    hostname Edge
    interface Gi0/0
    ip address 10.0.0.2 255.255.255.252
    no shutdown
    exit
    router ospf 1
    router-id 2.2.2.2
    network 10.0.0.0 0.0.0.3 area 0
    end

    Check: run show ip route on Edge and look for O 192.0.2.0/24 [110/2] via 10.0.0.1, Gi0/0.

    Why: Inside the campus OSPF tells every router about every campus subnet, so nobody types routes to internal networks. What it can't describe is the rest of the internet — a million or so prefixes that no router inside needs one by one, which is exactly what a default route stands in for.

  3. 3. Rent an uplink from the provider

    Drag in a third router to play the provider and cable a serial line from Edge Se0/0/0 to its Se0/0/0. The provider hands you 203.0.113.0/30: .1 is theirs, .2 is yours. Edge can reach the provider now — and has no idea what lies beyond it.

    • Cable Edge Se0/0/0 ↔ ISP Se0/0/0 (serial)

    On ISP — Name the provider router and address its end of the uplink

    enable
    configure terminal
    hostname ISP
    interface Se0/0/0
    ip address 203.0.113.1 255.255.255.252
    no shutdown
    exit
    end

    On Edge — Address the campus end of the uplink

    enable
    configure terminal
    interface Se0/0/0
    ip address 203.0.113.2 255.255.255.252
    no shutdown
    exit
    end

    Check: run show ip interface brief on Edge and look for Se0/0/0 203.0.113.2 YES manual up up.

    Why: The uplink is a connected network on Edge, so Edge reaches 203.0.113.1 with no routing at all. Everything past the provider's router is still unknown: a router knows only the networks it is plugged into and the ones it has been told about.

  4. 4. Put a server out on the internet

    Give the provider a second network with a web server on it — 198.51.100.50 stands in for anything on the internet. The provider also routes your block to you: one static route for 192.0.2.0/24 pointing at Edge, the provider's half of the deal.

    • Cable WEB1 Eth0 ↔ ISP Gi0/0

    On ISP — Address the provider's server LAN and route the campus block to Edge

    enable
    configure terminal
    interface Gi0/0
    ip address 198.51.100.1 255.255.255.0
    no shutdown
    exit
    ip route 192.0.2.0 255.255.255.0 203.0.113.2
    end

    On WEB1 — Name the server and give it an address and a gateway

    hostname WEB1
    ipconfig Eth0 198.51.100.50 255.255.255.0 198.51.100.1

    Check: run show ip route on ISP and look for S 192.0.2.0/24 via 203.0.113.2, Se0/0/0.

    Why: A provider routes every customer block towards that customer's edge — here with a static route; in a real provider it is also announced onward to the rest of the internet with BGP. It is the return half of every conversation the campus will have: anything addressed to 192.0.2.0/24 reaches the provider and is handed to Edge.

  5. 5. Give the edge router its default route

    Edge knows the campus (through OSPF) and its own uplink, and nothing else in the world. One static default route hands every unknown destination to the provider. Ping the server from Edge: it answers.

    On Edge — Send everything Edge doesn't recognise to the provider, then try the server

    enable
    configure terminal
    ip route 0.0.0.0 0.0.0.0 203.0.113.1
    end
    ping 198.51.100.50

    Check: run show ip route on Edge and look for S* 0.0.0.0/0 via 203.0.113.1, Se0/0/0.

    Why: 0.0.0.0/0 has a zero-length prefix, so it matches every address and is the least specific route there is: longest-prefix match falls back to it only when nothing else fits. The edge router is the one place in the campus that can honestly say where 'everything else' is.

  6. 6. The campus still can't get out

    Change nothing — look. Ping the server from PC-A: it fails at Core. Core's table holds its two connected networks and nothing else, no route to 198.51.100.50 and no default. Edge knows the way out; Core doesn't, and OSPF hasn't been asked to tell it.

    On PC-A — Try the server from inside the campus

    ping 198.51.100.50

    On Core — Read the inside router's table

    enable
    show ip route

    Check: run show ip route 198.51.100.50 on Core and look for % Network not in table.

    Why: A default route lives in one router's table until a routing protocol is told to share it. The fix is not more static routes: it is getting the one router that owns the exit to advertise it.

  7. 7. Advertise the default into OSPF

    One line under Edge's OSPF process: `default-information originate`. Edge turns its own default route into an OSPF advertisement, Core installs it as O*E2 0.0.0.0/0, and PC-A's ping crosses the campus, the edge and the provider to the server. Core now has a default route that nobody typed on Core.

    On Edge — Advertise Edge's default route to the rest of the OSPF area

    enable
    configure terminal
    router ospf 1
    default-information originate
    end

    On PC-A — Reach the internet from inside the campus

    ping 198.51.100.50

    Check: run show ip route on Core and look for Gateway of last resort is 10.0.0.2 to network 0.0.0.0.

    Why: `default-information originate` re-announces a default the router already has — Edge's static — rather than inventing one, which is what keeps it safe: without a default of its own, Edge would advertise nothing. The `always` keyword advertises one regardless and belongs only in designs where the default really comes from elsewhere.

The theory behind it

Build it for real

The lab walks you through these steps and ticks each one off as your network starts working.

Open in the lab
Share one default route with OSPF — step-by-step network lab · NetForge-AI