All guided builds

Guided buildadvanced7 steps~20 min5 devices

Two routers that learn the network

Join two sites over a WAN link, then let OSPF fill in the routing tables that you would otherwise type by hand.

What you'll be able to do: Head office and the branch reach each other's LANs over a routing protocol, and adding a whole new subnet at one site puts a route for it on the other site's router without a single command being typed there.

Topics: OSPF · Dynamic routing · Wildcard masks · Routing tables · WAN links

What you'll build

Step by step

  1. 1. Stand up the head-office LAN

    Drag a router and a PC onto the canvas, wire the PC into Gi0/0, then name the router and give that port the address the LAN will use as its gateway. Keep `show ip route` in view from here on: every line that appears in it was put there by something, and knowing what put it there is the skill this build is about.

    • Cable PC-HQ Eth0 ↔ Edge-HQ Gi0/0

    On Edge-HQ — Name the router and address the head-office LAN port

    enable
    configure terminal
    hostname Edge-HQ
    interface Gi0/0
    ip address 192.168.10.1 255.255.255.0
    no shutdown
    exit
    end

    On PC-HQ — Name the workstation and point it at its gateway

    hostname PC-HQ
    ipconfig Eth0 192.168.10.10 255.255.255.0 192.168.10.1

    Check: run show ip route on Edge-HQ and look for C 192.168.10.0/24 is directly connected, Gi0/0.

    Why: Routing-table codes name each route's source — C connected, S static, O OSPF — and each source has its own lifetime: a C line lasts as long as its interface is up, an S line as long as its configuration line exists and its next hop is reachable, and an O line as long as a neighbour keeps advertising it.

  2. 2. Stand up the branch LAN

    Build the same thing at the other site: a second router, a second PC, a different subnet. Right now these are two islands. Each router's table holds exactly one network — the one plugged into it — and neither has any idea the other exists.

    • Cable PC-Branch Eth0 ↔ Edge-Branch Gi0/0

    On Edge-Branch — Name the branch router and address its LAN port

    enable
    configure terminal
    hostname Edge-Branch
    interface Gi0/0
    ip address 192.168.20.1 255.255.255.0
    no shutdown
    exit
    end

    On PC-Branch — Name the branch workstation and point it at its gateway

    hostname PC-Branch
    ipconfig Eth0 192.168.20.10 255.255.255.0 192.168.20.1

    Check: run show ip interface brief on Edge-Branch and look for Gi0/0 192.168.20.1 YES manual up.

    Why: Splitting a network into routed segments also splits its failures: a broadcast storm, a duplicate address or a looping cable on one LAN stays on that LAN, because routers do not forward broadcasts. Two sites with two subnets are two failure domains as well as two islands.

  3. 3. Join the sites with a /30 WAN link

    Run a serial cable between the two routers and address both ends out of 10.10.10.0/30 — four addresses, two of them usable, which is the exact size a point-to-point link needs. The routers can now reach each other, and each table grows a second connected route.

    • Cable Edge-HQ Se0/0/0 ↔ Edge-Branch Se0/0/0 (serial)

    On Edge-HQ — Address the head-office end of the WAN link

    enable
    configure terminal
    interface Se0/0/0
    ip address 10.10.10.1 255.255.255.252
    no shutdown
    exit
    end

    On Edge-Branch — Address the branch end of the same link

    enable
    configure terminal
    interface Se0/0/0
    ip address 10.10.10.2 255.255.255.252
    no shutdown
    exit
    end

    Check: run show ip route on Edge-HQ and look for C 10.10.10.0/30 is directly connected, Se0/0/0.

    Why: Joining the routers gives each one a single new fact — the transit subnet — and nothing about what lies behind the other. That gap is what every routing method exists to fill: a router has to be told, by a person or by a protocol, which remote networks sit behind which neighbour.

  4. 4. Close the gap by hand, and count the lines

    One static route on each router does it: each says 'anything for that subnet, hand it to the far end of the WAN'. It works, and for two routers it is honestly the simplest answer. Now picture a fourth site and a fifth subnet — every router needs a line for every network it cannot see, somebody has to type all of them, and each line keeps pointing down a path long after that path has gone.

    On Edge-HQ — Tell head office where the branch LAN lives

    enable
    configure terminal
    ip route 192.168.20.0 255.255.255.0 10.10.10.2
    end

    On Edge-Branch — Tell the branch where the head-office LAN lives

    enable
    configure terminal
    ip route 192.168.10.0 255.255.255.0 10.10.10.1
    end

    On PC-HQ — Prove the two LANs can now talk

    ping 192.168.20.10

    Check: run show ip route on Edge-HQ and look for S 192.168.20.0/24 via 10.10.10.2, Se0/0/0.

    Why: A static route is knowledge without feedback: it cannot learn that a path beyond its next hop has failed, and it cannot discover a better path when one appears. A routing protocol replaces that with a running conversation between routers, which is why its routes can change without anybody typing.

  5. 5. Retire the statics and start OSPF at head office

    A router trusts a static route more than anything a protocol tells it, so leaving those two lines in would let them quietly win and hide everything OSPF learns. Delete both, then start process 1 on Edge-HQ. A `network` statement creates nothing — it matches: every interface whose address falls inside 192.168.10.0 through 192.168.10.255 starts speaking OSPF and gets the subnet it sits in advertised into area 0. The 0.0.0.255 is a wildcard mask, the bit-for-bit inverse of the 255.255.255.0 on the interface, which is why the /30 link is written 0.0.0.3.

    On Edge-Branch — Remove the hand-written route so a learned one can replace it

    enable
    configure terminal
    no ip route 192.168.10.0 255.255.255.0
    end

    On Edge-HQ — Remove its static too, then advertise both of its networks into area 0

    enable
    configure terminal
    no ip route 192.168.20.0 255.255.255.0
    router ospf 1
    router-id 1.1.1.1
    network 192.168.10.0 0.0.0.255 area 0
    network 10.10.10.0 0.0.0.3 area 0
    exit
    end

    Check: run show ip ospf neighbor on Edge-HQ and look for (no OSPF neighbors yet).

    Why: Administrative distance is how a router ranks sources that disagree: connected routes are 0, static routes 1 and OSPF 110, and for the same prefix the lowest number is the one used for forwarding. A leftover static therefore does not conflict with OSPF — it simply wins, every time, without any error to point at it.

  6. 6. Start OSPF at the branch and watch routes arrive

    The same two `network` statements on Edge-Branch, with a router-id of its own. A protocol needs somebody to talk to, so nothing happened while only one side was configured — the moment the second process starts, the two routers find each other across the /30, exchange what they know, and each installs a route to the other's LAN. Look at the table on Edge-HQ: there is a route in it that nobody typed.

    On Edge-Branch — Advertise the branch networks into the same area

    enable
    configure terminal
    router ospf 1
    router-id 2.2.2.2
    network 192.168.20.0 0.0.0.255 area 0
    network 10.10.10.0 0.0.0.3 area 0
    exit
    end

    On PC-HQ — Cross the WAN again, this time on a route nobody wrote

    ping 192.168.20.10

    Check: run show ip route on Edge-HQ and look for O 192.168.20.0/24 [110/65] via 10.10.10.2, Se0/0/0.

    Why: OSPF routers first have to become neighbours: each sends Hellos out of every interface its `network` statements matched, and two routers that hear each other and agree on the details of the link they share, such as its area, exchange their link-state databases until both reach FULL. Each then runs SPF over the same map — what arrives is not a copy of the other router's table, but a conclusion each router reaches for itself.

  7. 7. Add a third subnet and touch only one router

    Cable a server into Edge-Branch's spare port, address it in a brand-new subnet, and add one `network` line for it. Head office gets no commands at all — and a route to 172.16.50.0/24 appears in its table anyway. That is the whole argument for a routing protocol: describe a network once, where it lives, and every other router finds out.

    • Cable WEB1 Eth0 ↔ Edge-Branch Gi0/1

    On Edge-Branch — Address the new server subnet and advertise it into area 0

    enable
    configure terminal
    interface Gi0/1
    ip address 172.16.50.1 255.255.255.0
    no shutdown
    exit
    router ospf 1
    network 172.16.50.0 0.0.0.255 area 0
    exit
    end

    On WEB1 — Name the server and give it an address and a gateway

    hostname WEB1
    ipconfig Eth0 172.16.50.10 255.255.255.0 172.16.50.1

    On PC-HQ — Reach a subnet that did not exist two minutes ago

    ping 172.16.50.10

    Check: run show ip route on Edge-HQ and look for O 172.16.50.0/24 [110/65] via 10.10.10.2, Se0/0/0.

    Why: When Edge-Branch starts advertising 172.16.50.0/24 it updates its own link-state advertisement and floods it to its neighbours; every router in the area receives the change, reruns SPF and installs the new route itself. That is the division of labour in a link-state protocol: each router describes only its own links, and every router builds the full picture from those descriptions.

The theory behind it

Build it for real

The lab walks you through these steps and ticks each one off as your network starts working.

Open in the lab
Two routers that learn the network — step-by-step network lab · NetForge-AI