Guided buildadvanced7 steps~28 min7 devices
OSPF across two areas
Split an OSPF network into a backbone and a branch area, and make one router the border between them.
What you'll be able to do: A headquarters in area 0 and a branch office in area 1 route to each other through a single border router, and a change on either side stops short of flooding the other.
Topics: OSPF · Multi-area OSPF · ABR · Link-state routing
What you'll build
- Core — a router, the HQ router that anchors area 0
- Border — a router, the router with a leg in each area — the ABR
- Branch — a router, the branch-office router, alone in area 1
- SW-Core — a switch, the switch the HQ hosts plug into
- PC-HQ — a pc, a workstation at headquarters
- WEB1 — a server, the HQ server the branch has to reach
- PC-Branch — a pc, a workstation at the branch office
Step by step
1. Anchor the backbone at headquarters
Drag a router and a switch onto the canvas, cable them, and give the router the HQ LAN address 10.10.0.1/24. Area 0 is the backbone every other area has to touch, so it is worth starting where the backbone lives rather than at the far end of the network.
- Cable Core Gi0/0 ↔ SW-Core Gi0/1
On Core — Name the HQ router and address its LAN port
enable configure terminal hostname Core interface Gi0/0 ip address 10.10.0.1 255.255.255.0 no shutdown exit endOn SW-Core — Name the HQ switch so its console prompt is unmistakable
enable configure terminal hostname SW-Core endCheck: run
show ip interface briefon Core and look forGi0/0 10.10.0.1 YES manual up.Why: OSPF's areas form a two-level hierarchy with area 0 at the centre, and routes between two areas only ever travel through it. Designing from the backbone outwards means every area you add later has a place to attach from the moment it is built.
2. Put a workstation on the HQ LAN
Cable a PC to Fa0/1 and give it an address, a mask and the router as its gateway in one line. This host is the yardstick for the rest of the build: every later step is measured by what PC-HQ can and cannot reach.
- Cable PC-HQ Eth0 ↔ SW-Core Fa0/1
On PC-HQ — Name the workstation, address it, and prove it reaches its gateway
hostname PC-HQ ipconfig Eth0 10.10.0.20 255.255.255.0 10.10.0.1 ping 10.10.0.1Check: run
ip -br aon PC-HQ and look forEth0 UP 10.10.0.20/24.Why: A successful ping to the gateway is a compact proof of several layers at once: the cable and the switch port carried frames, ARP resolved the router's MAC, and both ends agree on the subnet. When a later ping fails, you already know which of those facts it is not.
3. Raise the backbone: area 0 between two routers
Add the second router, join the two with a /30 — two usable addresses, which is all a point-to-point link ever needs — and start an OSPF process on each. Every `network` statement here says `area 0`, so both routers hold the same link-state database and both run SPF over the same map. That is exactly the property that stops scaling: in one flat area, a flapping link anywhere makes every router everywhere recompute.
- Cable Core Gi0/1 ↔ Border Gi0/1
On Core — Address the backbone link and advertise both HQ networks into area 0
enable configure terminal interface Gi0/1 ip address 10.0.0.1 255.255.255.252 no shutdown exit router ospf 1 router-id 1.1.1.1 network 10.10.0.0 0.0.0.255 area 0 network 10.0.0.0 0.0.0.3 area 0 exit endOn Border — Name the border router and bring its area 0 leg into the same process
enable configure terminal hostname Border interface Gi0/1 ip address 10.0.0.2 255.255.255.252 no shutdown exit router ospf 1 router-id 2.2.2.2 network 10.0.0.0 0.0.0.3 area 0 exit endCheck: run
show ip ospf neighboron Core and look for2.2.2.2 1 FULL.Why: A `network` statement does two jobs at once: it switches OSPF on for every interface whose address it matches, and it places that interface in an area. Area membership is therefore a property of each interface, not of the router — which is exactly what will let one router sit in two areas later in this build.
4. Cable the branch office
Hang a third router off Border's serial port, give the branch its own /24, and put a workstation on it. Nothing here mentions OSPF yet: this step is only wire and addresses, so that the next one can isolate what the protocol adds.
- Cable Border Se0/0/0 ↔ Branch Se0/0/0 (serial)
- Cable Branch Gi0/0 ↔ PC-Branch Eth0
On Border — Address the serial link towards the branch
enable configure terminal interface Se0/0/0 ip address 10.0.0.5 255.255.255.252 no shutdown exit endOn Branch — Name the branch router and address both of its ports
enable configure terminal hostname Branch interface Gi0/0 ip address 10.20.0.1 255.255.255.0 no shutdown exit interface Se0/0/0 ip address 10.0.0.6 255.255.255.252 no shutdown exit endOn PC-Branch — Name and address the branch workstation
hostname PC-Branch ipconfig Eth0 10.20.0.20 255.255.255.0 10.20.0.1Check: run
show ip routeon Branch and look forC 10.0.0.4/30 is directly connected, Se0/0/0.Why: Mixing prefix lengths is ordinary: LANs get a /24 because they hold hosts, and each point-to-point link gets a /30 because it holds exactly two routers. OSPF carries every prefix with its own mask, which is what makes a variable-length plan like this one work.
5. Start OSPF at the branch — and watch nothing happen
Put both branch networks into area 1 and give the router an id. The serial link is up, the addresses are in the same /30, the process is running at this end — and the ping to HQ still fails. Read Branch's neighbour table before you read the next step: the router tells you exactly what it is waiting for.
On Branch — Advertise the branch LAN and the serial link into area 1
enable configure terminal router ospf 1 router-id 3.3.3.3 network 10.20.0.0 0.0.0.255 area 1 network 10.0.0.4 0.0.0.3 area 1 exit endOn PC-Branch — Try HQ from the branch — this one is supposed to fail
ping 10.10.0.20Check: run
show ip ospf neighboron Branch and look forConfirm the peer also runs OSPF with matching area..Why: An OSPF adjacency needs Hellos from both ends of a link, and Border's serial interface matches none of its `network` statements, so it sends none. Branch's Hellos go unanswered, no databases are exchanged, and area 1 stays cut off from the backbone.
6. Give Border a leg in both areas
One line fixes it: Border claims the serial /30 for area 1 while it keeps Gi0/1 in area 0. A router with interfaces in two areas is an Area Border Router, and an ABR is the only thing that moves reachability between them — it keeps a separate link-state database per area and passes each one a summary of the other instead of the raw topology. Area 1 now has a way into the backbone, and every prefix that crosses arrives marked `O IA`, inter-area.
On Border — Attach area 1 to the backbone through the existing OSPF process
enable configure terminal router ospf 1 network 10.0.0.4 0.0.0.3 area 1 exit endCheck: run
show ip routeon Core and look forO IA 10.20.0.0/24 [110/66] via 10.0.0.2, Gi0/1.Why: Between areas, OSPF behaves much like a distance-vector protocol: routers in area 1 know the HQ networks only as reachable through Border at a given cost, never as part of their own map. That is why every area must touch area 0 — with the backbone as the only transit between areas, those second-hand routes cannot form a loop.
7. Add a server to area 0 and read the branch's table
Plug a server into the HQ switch, address it, and ping it from the branch. Nobody touched Branch, and `show ip route ospf` there looks identical to before — the single `O IA 10.10.0.0/24` entry already covered the new host. That is what buying an area gets you: work inside one area stops at the ABR instead of rippling out as a database change every router in the company has to process.
- Cable WEB1 Eth0 ↔ SW-Core Fa0/2
On WEB1 — Name and address the HQ server on the existing LAN
hostname WEB1 ipconfig Eth0 10.10.0.80 255.255.255.0 10.10.0.1 ping 10.20.0.20Check: run
show ip route ospfon Branch and look forO IA 10.10.0.0/24 [110/66] via 10.0.0.5, Se0/0/0.Why: Routing tables list networks, not hosts. WEB1 lives inside 10.10.0.0/24, a prefix Branch already reaches, so plugging it in changes no route anywhere — a new host is never an OSPF event, in any design. What an area boundary hides is topology: changes to links inside area 0 reach Branch only as updated summaries from Border, never as HQ's detailed map.
The theory behind it
More in Routing
- Static routes across a WAN — Join three sites with point-to-point WAN links and route between them by hand, one line at a time.
- RIP: routing by counting hops — Chain three routers over two serial links and let RIP version 2 teach every router the way to every network, counting the hops as it goes.
- Two routers that learn the network — Join two sites over a WAN link, then let OSPF fill in the routing tables that you would otherwise type by hand.
- A backup link that waits its turn — Run two sites over a fast primary link, park a floating static route on a slow standby line, then pull the primary and watch the backup carry the traffic.
- Steer OSPF with link cost — Give OSPF two paths between two sites, watch it choose the cheaper one over the shorter one, then re-rate a link and watch the route move.
- Share one default route with OSPF — Give the edge router a default route to the provider, then let OSPF hand it to the rest of the campus instead of typing it on every router.
Build it for real
The lab walks you through these steps and ticks each one off as your network starts working.
Open in the lab