All guided builds

Guided buildadvanced10 steps~50 min8 devices

Redundant campus

Double every link and box between a desk and HQ — bundled, spanning-tree protected, VRRP gateways, twin OSPF circuits — then break two of them and keep working.

What you'll be able to do: A desk that keeps reaching the application server at HQ while its active gateway is dead and its access uplink is cut at the same time — and a network that puts itself back exactly as designed once both are repaired.

Start this build in the lab 8 devices — needs any paid plan (the free canvas fits 5).

Topics: Redundancy · Spanning Tree · EtherChannel · VRRP · OSPF · Trunking

What you'll build

Step by step

  1. 1. Build the distribution pair

    A redundant campus starts with two of everything in the middle. Drop in two switches as the distribution pair, name them DIST-A and DIST-B, and create the user VLAN on both — VLAN 10, USERS. Each switch keeps its own VLAN database, so a VLAN the pair will carry between them is created on each.

    On DIST-A — Name distribution switch A and create the user VLAN

    enable
    configure terminal
    hostname DIST-A
    vlan 10
    name USERS
    exit
    end

    On DIST-B — Name distribution switch B and create the same VLAN

    enable
    configure terminal
    hostname DIST-B
    vlan 10
    name USERS
    exit
    end

    Check: run show vlan brief on DIST-B and look for 10 USERS.

    Why: The two distribution switches are meant to be interchangeable, so they are built identically from the first command. Everything later — the bundle between them, the uplinks from the access layer, a gateway on each — assumes either one can carry VLAN 10 on its own.

  2. 2. Bundle the pair with LACP

    Run two cables between the distribution switches, Gi0/1 to Gi0/1 and Gi0/2 to Gi0/2, and bundle them into one logical link, Port-channel 1. Configure both members at once with `interface range`: a trunk allowing VLAN 10, and LACP — active on DIST-A, passive on DIST-B. Two cables, one link: twice the bandwidth, and losing either cable costs capacity, not connectivity.

    • Cable DIST-A Gi0/1 ↔ DIST-B Gi0/1
    • Cable DIST-A Gi0/2 ↔ DIST-B Gi0/2

    On DIST-A — Trunk both members and start LACP negotiation

    enable
    configure terminal
    interface range Gi0/1 - 2
    switchport mode trunk
    switchport trunk allowed vlan 10
    channel-group 1 mode active
    end

    On DIST-B — Trunk both members and answer LACP

    enable
    configure terminal
    interface range Gi0/1 - 2
    switchport mode trunk
    switchport trunk allowed vlan 10
    channel-group 1 mode passive
    end

    Check: run show etherchannel summary on DIST-A and look for 1 Po1(SU) LACP Gi0/1(P) Gi0/2(P).

    Why: Without a bundle, Spanning Tree sees two parallel links as a loop and blocks one, so half the bandwidth you cabled sits idle. LACP negotiates the pair into a single Port-channel that STP treats as ONE port, so both members forward. Active means 'start the negotiation'; passive means 'answer if asked'.

  3. 3. Hang the access switch off DIST-A

    Add the access switch users plug into, with PC-Lee on Fa0/1 in VLAN 10, and uplink it from Fa0/23 to DIST-A's Fa0/1 as a trunk. Give PC-Lee 192.168.10.1 as its gateway — an address no device owns yet. It will be the virtual gateway the two routers share, and pointing hosts at it from day one is the whole trick.

    • Cable ACC-1 Fa0/23 ↔ DIST-A Fa0/1
    • Cable PC-Lee Eth0 ↔ ACC-1 Fa0/1

    On ACC-1 — Name the access switch, add the user port and the uplink to DIST-A

    enable
    configure terminal
    hostname ACC-1
    vlan 10
    name USERS
    exit
    interface Fa0/1
    switchport mode access
    switchport access vlan 10
    spanning-tree portfast
    exit
    interface Fa0/23
    switchport mode trunk
    switchport trunk allowed vlan 10
    end

    On DIST-A — Trunk DIST-A's end of the uplink

    enable
    configure terminal
    interface Fa0/1
    switchport mode trunk
    switchport trunk allowed vlan 10
    end

    On PC-Lee — Name the desktop and point it at the virtual gateway

    hostname PC-Lee
    ipconfig Eth0 192.168.10.101 255.255.255.0 192.168.10.1

    Check: run show interfaces trunk on ACC-1 and look for Fa0/23 on 802.1q trunking 1.

    Why: The access layer only needs VLANs and uplinks — the cleverness lives above it. Hosts are given the virtual gateway address because that address never moves: whichever router is in charge answers for it, so a failover needs no change on a single desk.

  4. 4. Choose the root bridge, then close the loop

    A second uplink, ACC-1 Fa0/24 to DIST-B Fa0/1, turns the three switches into a triangle — a loop — and Spanning Tree will block one port to break it. Decide where BEFORE it happens: make DIST-A the root bridge for VLAN 10 and DIST-B the backup root. Then trunk the new uplink, and ACC-1's Fa0/24 settles into blocking: cabled, alive, and waiting.

    • Cable ACC-1 Fa0/24 ↔ DIST-B Fa0/1

    On DIST-A — Make DIST-A the root bridge for VLAN 10

    enable
    configure terminal
    spanning-tree vlan 10 root primary
    end

    On DIST-B — Make DIST-B the backup root, then trunk its end of the new uplink

    enable
    configure terminal
    spanning-tree vlan 10 root secondary
    interface Fa0/1
    switchport mode trunk
    switchport trunk allowed vlan 10
    end

    On ACC-1 — Trunk the second uplink

    enable
    configure terminal
    interface Fa0/24
    switchport mode trunk
    switchport trunk allowed vlan 10
    end

    Check: run show spanning-tree vlan 10 on ACC-1 and look for Fa0/24 Altn BLK 19 128.Fa0/24 P2p.

    Why: The switches elect the lowest bridge ID as root, and at the default priority that means the lowest MAC address — possibly the access switch in a closet. With DIST-A as root, ACC-1 reaches it through Fa0/23 at cost 19, while Fa0/24 would cost 4 + 19 = 23 through DIST-B, so Fa0/24 becomes the Alternate port and blocks. `root primary` and `root secondary` set the priorities to 24576 and 28672.

  5. 5. Put two gateway routers on the user VLAN

    Give each distribution switch a router: GW-A's Gi0/0 into DIST-A's Fa0/24, GW-B's into DIST-B's Fa0/24, so no single switch can take both gateways down. Address them 192.168.10.2 and 192.168.10.3, bring the ports up, and ping both from PC-Lee.

    • Cable GW-A Gi0/0 ↔ DIST-A Fa0/24
    • Cable GW-B Gi0/0 ↔ DIST-B Fa0/24

    On DIST-A — Put the port facing GW-A in the user VLAN

    enable
    configure terminal
    interface Fa0/24
    switchport mode access
    switchport access vlan 10
    end

    On DIST-B — Put the port facing GW-B in the user VLAN

    enable
    configure terminal
    interface Fa0/24
    switchport mode access
    switchport access vlan 10
    end

    On GW-A — Name the first gateway and give it its own address in VLAN 10

    enable
    configure terminal
    hostname GW-A
    interface Gi0/0
    ip address 192.168.10.2 255.255.255.0
    no shutdown
    end

    On GW-B — Name the second gateway and give it its own address in VLAN 10

    enable
    configure terminal
    hostname GW-B
    interface Gi0/0
    ip address 192.168.10.3 255.255.255.0
    no shutdown
    end

    On PC-Lee — Reach both routers from the desk

    ping 192.168.10.2
    ping 192.168.10.3

    Check: run show ip interface brief on GW-A and look for Gi0/0 192.168.10.2 YES manual up up.

    Why: Each router needs a real address of its own in the VLAN before it can share a virtual one: VRRP runs on top of the interface's own IP. To the switches a router is just another host, so the ports facing them are plain access ports in VLAN 10.

  6. 6. Share one virtual gateway with VRRP

    Configure VRRP group 10 with the virtual address 192.168.10.1 on both routers, and raise GW-A's priority to 110. GW-A becomes the master and answers for 192.168.10.1; GW-B stands by as backup. PC-Lee's gateway finally exists — and it does not belong to any one box.

    On GW-B — Join VRRP group 10 at the default priority

    enable
    configure terminal
    interface Gi0/0
    vrrp 10 ip 192.168.10.1
    end

    On GW-A — Join VRRP group 10 and outrank GW-B

    enable
    configure terminal
    interface Gi0/0
    vrrp 10 ip 192.168.10.1
    vrrp 10 priority 110
    end

    On PC-Lee — Reach the virtual gateway

    ping 192.168.10.1

    Check: run show vrrp brief on GW-A and look for Master local 192.168.10.1.

    Why: The master answers ARP for the virtual IP, so hosts hand it their off-subnet traffic; the backup takes the address over if the master goes silent. At equal priority the higher interface address wins — that would be GW-B, on the far side of the root bridge, so every frame from ACC-1 would cross the bundle between the distribution switches. Priority 110 puts the active gateway beside the root.

  7. 7. Reach HQ over two circuits with OSPF

    Give each gateway its own serial circuit to headquarters — GW-A's Se0/0/0 to HQ-Core's Se0/0/0, GW-B's to HQ-Core's Se0/0/1 — and hang the application server off HQ-Core's Gi0/0. Address the two /30s and the HQ LAN, then run OSPF area 0 on all three routers so each learns the others' networks. From PC-Lee, ping HQ-App.

    • Cable GW-A Se0/0/0 ↔ HQ-Core Se0/0/0 (serial)
    • Cable GW-B Se0/0/0 ↔ HQ-Core Se0/0/1 (serial)
    • Cable HQ-App Eth0 ↔ HQ-Core Gi0/0

    On HQ-Core — Name HQ's router, address both circuits and the HQ LAN, and run OSPF

    enable
    configure terminal
    hostname HQ-Core
    interface Se0/0/0
    ip address 10.0.1.1 255.255.255.252
    no shutdown
    exit
    interface Se0/0/1
    ip address 10.0.2.1 255.255.255.252
    no shutdown
    exit
    interface Gi0/0
    ip address 172.16.0.1 255.255.255.0
    no shutdown
    exit
    router ospf 1
    network 10.0.1.0 0.0.0.3 area 0
    network 10.0.2.0 0.0.0.3 area 0
    network 172.16.0.0 0.0.0.255 area 0
    end

    On HQ-App — Name the application server and address it

    hostname HQ-App
    ipconfig Eth0 172.16.0.10 255.255.255.0 172.16.0.1

    On GW-A — Bring up circuit A and advertise the user VLAN over it

    enable
    configure terminal
    interface Se0/0/0
    ip address 10.0.1.2 255.255.255.252
    no shutdown
    exit
    router ospf 1
    network 192.168.10.0 0.0.0.255 area 0
    network 10.0.1.0 0.0.0.3 area 0
    end

    On GW-B — Bring up circuit B and advertise the user VLAN over it

    enable
    configure terminal
    interface Se0/0/0
    ip address 10.0.2.2 255.255.255.252
    no shutdown
    exit
    router ospf 1
    network 192.168.10.0 0.0.0.255 area 0
    network 10.0.2.0 0.0.0.3 area 0
    end

    On PC-Lee — Reach the application at HQ

    ping 172.16.0.10

    Check: run show ip route ospf on GW-A and look for O 172.16.0.0/24.

    Why: Two circuits only help if the routers know both exist. OSPF advertises every connected network a `network` statement covers, so HQ-Core learns 192.168.10.0/24 from both gateways and each gateway learns the HQ LAN over its own circuit. When a path disappears OSPF simply recalculates — no static route to edit at 3 a.m.

  8. 8. Kill the active gateway

    Time to earn the redundancy. Shut GW-A's Gi0/0 — as far as the user VLAN can tell, GW-A has just died. GW-B stops hearing the master, takes over 192.168.10.1, and PC-Lee's next ping reaches HQ-App through the backup gateway and the backup circuit, without the desk changing a single setting.

    On GW-A — Take the active gateway off the user VLAN

    enable
    configure terminal
    interface Gi0/0
    shutdown
    end

    On PC-Lee — The same application, from the same desk

    ping 172.16.0.10

    Check: run show vrrp brief on GW-B and look for Master local 192.168.10.1.

    Why: Hosts keep the same gateway address; what changes is which router answers for it. The new master announces itself with a gratuitous ARP, so every host's cache follows at once, and OSPF moves HQ-Core's route for 192.168.10.0/24 onto the circuit through GW-B so the replies find their way home.

  9. 9. Cut the uplink Spanning Tree chose

    Now break the layer below. Shut ACC-1's Fa0/23, the uplink to DIST-A that Spanning Tree picked as the root port. The blocked Fa0/24 becomes ACC-1's new root port and starts forwarding, and PC-Lee still reaches HQ-App: two failures at two different layers, and the desk noticed neither.

    On ACC-1 — Take down the uplink to the root bridge

    enable
    configure terminal
    interface Fa0/23
    shutdown
    end

    On PC-Lee — Try the application once more

    ping 172.16.0.10

    Check: run show spanning-tree vlan 10 on ACC-1 and look for Fa0/24 Root FWD 19 128.Fa0/24 P2p.

    Why: The Alternate port was blocking, not idle: it kept receiving BPDUs and already knew its cost to the root. With the root port gone it is the best path left, so Rapid PVST+ moves it straight to forwarding. PC-Lee's traffic now climbs Fa0/24 to DIST-B and on to GW-B — the backup of everything.

  10. 10. Repair both and watch it fall back

    Bring both back with `no shutdown` and type nothing else. GW-A's priority 110 beats GW-B's 100, so it takes the master role back by itself, and Fa0/23 is once again ACC-1's cheapest way to the root, so Fa0/24 returns to blocking. The network ends exactly as designed: root bridge and active gateway on the same side.

    On ACC-1 — Restore the uplink to the root bridge

    enable
    configure terminal
    interface Fa0/23
    no shutdown
    end

    On GW-A — Bring the active gateway back onto the user VLAN

    enable
    configure terminal
    interface Gi0/0
    no shutdown
    end

    On PC-Lee — Confirm the application is still there

    ping 172.16.0.10

    Check: run show spanning-tree vlan 10 on ACC-1 and look for Fa0/24 Altn BLK 19 128.Fa0/24 P2p.

    Why: VRRP pre-empts by default: a higher-priority router that comes back reclaims the master role. Spanning Tree keeps no memory either — it re-runs the election on the topology in front of it and lands where the costs say. Both converge on the design you chose, which is why it pays to choose it deliberately.

The theory behind it

Build it for real

The lab walks you through these steps and ticks each one off as your network starts working.

Open in the lab
Redundant campus — step-by-step network lab · NetForge-AI