Guided buildadvanced10 steps~50 min8 devices
Redundant campus
Double every link and box between a desk and HQ — bundled, spanning-tree protected, VRRP gateways, twin OSPF circuits — then break two of them and keep working.
What you'll be able to do: A desk that keeps reaching the application server at HQ while its active gateway is dead and its access uplink is cut at the same time — and a network that puts itself back exactly as designed once both are repaired.
Topics: Redundancy · Spanning Tree · EtherChannel · VRRP · OSPF · Trunking
What you'll build
- DIST-A — a switch, distribution switch A: the root bridge, beside the active gateway
- DIST-B — a switch, distribution switch B: the backup root, beside the backup gateway
- ACC-1 — a switch, the access switch, uplinked to both distribution switches
- PC-Lee — a pc, a desktop in the user VLAN
- GW-A — a router, the active gateway (VRRP master) and WAN circuit A
- GW-B — a router, the backup gateway and WAN circuit B
- HQ-Core — a router, the headquarters router at the far end of both circuits
- HQ-App — a server, the application server at headquarters
Step by step
1. Build the distribution pair
A redundant campus starts with two of everything in the middle. Drop in two switches as the distribution pair, name them DIST-A and DIST-B, and create the user VLAN on both — VLAN 10, USERS. Each switch keeps its own VLAN database, so a VLAN the pair will carry between them is created on each.
On DIST-A — Name distribution switch A and create the user VLAN
enable configure terminal hostname DIST-A vlan 10 name USERS exit endOn DIST-B — Name distribution switch B and create the same VLAN
enable configure terminal hostname DIST-B vlan 10 name USERS exit endCheck: run
show vlan briefon DIST-B and look for10 USERS.Why: The two distribution switches are meant to be interchangeable, so they are built identically from the first command. Everything later — the bundle between them, the uplinks from the access layer, a gateway on each — assumes either one can carry VLAN 10 on its own.
2. Bundle the pair with LACP
Run two cables between the distribution switches, Gi0/1 to Gi0/1 and Gi0/2 to Gi0/2, and bundle them into one logical link, Port-channel 1. Configure both members at once with `interface range`: a trunk allowing VLAN 10, and LACP — active on DIST-A, passive on DIST-B. Two cables, one link: twice the bandwidth, and losing either cable costs capacity, not connectivity.
- Cable DIST-A Gi0/1 ↔ DIST-B Gi0/1
- Cable DIST-A Gi0/2 ↔ DIST-B Gi0/2
On DIST-A — Trunk both members and start LACP negotiation
enable configure terminal interface range Gi0/1 - 2 switchport mode trunk switchport trunk allowed vlan 10 channel-group 1 mode active endOn DIST-B — Trunk both members and answer LACP
enable configure terminal interface range Gi0/1 - 2 switchport mode trunk switchport trunk allowed vlan 10 channel-group 1 mode passive endCheck: run
show etherchannel summaryon DIST-A and look for1 Po1(SU) LACP Gi0/1(P) Gi0/2(P).Why: Without a bundle, Spanning Tree sees two parallel links as a loop and blocks one, so half the bandwidth you cabled sits idle. LACP negotiates the pair into a single Port-channel that STP treats as ONE port, so both members forward. Active means 'start the negotiation'; passive means 'answer if asked'.
3. Hang the access switch off DIST-A
Add the access switch users plug into, with PC-Lee on Fa0/1 in VLAN 10, and uplink it from Fa0/23 to DIST-A's Fa0/1 as a trunk. Give PC-Lee 192.168.10.1 as its gateway — an address no device owns yet. It will be the virtual gateway the two routers share, and pointing hosts at it from day one is the whole trick.
- Cable ACC-1 Fa0/23 ↔ DIST-A Fa0/1
- Cable PC-Lee Eth0 ↔ ACC-1 Fa0/1
On ACC-1 — Name the access switch, add the user port and the uplink to DIST-A
enable configure terminal hostname ACC-1 vlan 10 name USERS exit interface Fa0/1 switchport mode access switchport access vlan 10 spanning-tree portfast exit interface Fa0/23 switchport mode trunk switchport trunk allowed vlan 10 endOn DIST-A — Trunk DIST-A's end of the uplink
enable configure terminal interface Fa0/1 switchport mode trunk switchport trunk allowed vlan 10 endOn PC-Lee — Name the desktop and point it at the virtual gateway
hostname PC-Lee ipconfig Eth0 192.168.10.101 255.255.255.0 192.168.10.1Check: run
show interfaces trunkon ACC-1 and look forFa0/23 on 802.1q trunking 1.Why: The access layer only needs VLANs and uplinks — the cleverness lives above it. Hosts are given the virtual gateway address because that address never moves: whichever router is in charge answers for it, so a failover needs no change on a single desk.
4. Choose the root bridge, then close the loop
A second uplink, ACC-1 Fa0/24 to DIST-B Fa0/1, turns the three switches into a triangle — a loop — and Spanning Tree will block one port to break it. Decide where BEFORE it happens: make DIST-A the root bridge for VLAN 10 and DIST-B the backup root. Then trunk the new uplink, and ACC-1's Fa0/24 settles into blocking: cabled, alive, and waiting.
- Cable ACC-1 Fa0/24 ↔ DIST-B Fa0/1
On DIST-A — Make DIST-A the root bridge for VLAN 10
enable configure terminal spanning-tree vlan 10 root primary endOn DIST-B — Make DIST-B the backup root, then trunk its end of the new uplink
enable configure terminal spanning-tree vlan 10 root secondary interface Fa0/1 switchport mode trunk switchport trunk allowed vlan 10 endOn ACC-1 — Trunk the second uplink
enable configure terminal interface Fa0/24 switchport mode trunk switchport trunk allowed vlan 10 endCheck: run
show spanning-tree vlan 10on ACC-1 and look forFa0/24 Altn BLK 19 128.Fa0/24 P2p.Why: The switches elect the lowest bridge ID as root, and at the default priority that means the lowest MAC address — possibly the access switch in a closet. With DIST-A as root, ACC-1 reaches it through Fa0/23 at cost 19, while Fa0/24 would cost 4 + 19 = 23 through DIST-B, so Fa0/24 becomes the Alternate port and blocks. `root primary` and `root secondary` set the priorities to 24576 and 28672.
5. Put two gateway routers on the user VLAN
Give each distribution switch a router: GW-A's Gi0/0 into DIST-A's Fa0/24, GW-B's into DIST-B's Fa0/24, so no single switch can take both gateways down. Address them 192.168.10.2 and 192.168.10.3, bring the ports up, and ping both from PC-Lee.
- Cable GW-A Gi0/0 ↔ DIST-A Fa0/24
- Cable GW-B Gi0/0 ↔ DIST-B Fa0/24
On DIST-A — Put the port facing GW-A in the user VLAN
enable configure terminal interface Fa0/24 switchport mode access switchport access vlan 10 endOn DIST-B — Put the port facing GW-B in the user VLAN
enable configure terminal interface Fa0/24 switchport mode access switchport access vlan 10 endOn GW-A — Name the first gateway and give it its own address in VLAN 10
enable configure terminal hostname GW-A interface Gi0/0 ip address 192.168.10.2 255.255.255.0 no shutdown endOn GW-B — Name the second gateway and give it its own address in VLAN 10
enable configure terminal hostname GW-B interface Gi0/0 ip address 192.168.10.3 255.255.255.0 no shutdown endOn PC-Lee — Reach both routers from the desk
ping 192.168.10.2 ping 192.168.10.3Check: run
show ip interface briefon GW-A and look forGi0/0 192.168.10.2 YES manual up up.Why: Each router needs a real address of its own in the VLAN before it can share a virtual one: VRRP runs on top of the interface's own IP. To the switches a router is just another host, so the ports facing them are plain access ports in VLAN 10.
6. Share one virtual gateway with VRRP
Configure VRRP group 10 with the virtual address 192.168.10.1 on both routers, and raise GW-A's priority to 110. GW-A becomes the master and answers for 192.168.10.1; GW-B stands by as backup. PC-Lee's gateway finally exists — and it does not belong to any one box.
On GW-B — Join VRRP group 10 at the default priority
enable configure terminal interface Gi0/0 vrrp 10 ip 192.168.10.1 endOn GW-A — Join VRRP group 10 and outrank GW-B
enable configure terminal interface Gi0/0 vrrp 10 ip 192.168.10.1 vrrp 10 priority 110 endOn PC-Lee — Reach the virtual gateway
ping 192.168.10.1Check: run
show vrrp briefon GW-A and look forMaster local 192.168.10.1.Why: The master answers ARP for the virtual IP, so hosts hand it their off-subnet traffic; the backup takes the address over if the master goes silent. At equal priority the higher interface address wins — that would be GW-B, on the far side of the root bridge, so every frame from ACC-1 would cross the bundle between the distribution switches. Priority 110 puts the active gateway beside the root.
7. Reach HQ over two circuits with OSPF
Give each gateway its own serial circuit to headquarters — GW-A's Se0/0/0 to HQ-Core's Se0/0/0, GW-B's to HQ-Core's Se0/0/1 — and hang the application server off HQ-Core's Gi0/0. Address the two /30s and the HQ LAN, then run OSPF area 0 on all three routers so each learns the others' networks. From PC-Lee, ping HQ-App.
- Cable GW-A Se0/0/0 ↔ HQ-Core Se0/0/0 (serial)
- Cable GW-B Se0/0/0 ↔ HQ-Core Se0/0/1 (serial)
- Cable HQ-App Eth0 ↔ HQ-Core Gi0/0
On HQ-Core — Name HQ's router, address both circuits and the HQ LAN, and run OSPF
enable configure terminal hostname HQ-Core interface Se0/0/0 ip address 10.0.1.1 255.255.255.252 no shutdown exit interface Se0/0/1 ip address 10.0.2.1 255.255.255.252 no shutdown exit interface Gi0/0 ip address 172.16.0.1 255.255.255.0 no shutdown exit router ospf 1 network 10.0.1.0 0.0.0.3 area 0 network 10.0.2.0 0.0.0.3 area 0 network 172.16.0.0 0.0.0.255 area 0 endOn HQ-App — Name the application server and address it
hostname HQ-App ipconfig Eth0 172.16.0.10 255.255.255.0 172.16.0.1On GW-A — Bring up circuit A and advertise the user VLAN over it
enable configure terminal interface Se0/0/0 ip address 10.0.1.2 255.255.255.252 no shutdown exit router ospf 1 network 192.168.10.0 0.0.0.255 area 0 network 10.0.1.0 0.0.0.3 area 0 endOn GW-B — Bring up circuit B and advertise the user VLAN over it
enable configure terminal interface Se0/0/0 ip address 10.0.2.2 255.255.255.252 no shutdown exit router ospf 1 network 192.168.10.0 0.0.0.255 area 0 network 10.0.2.0 0.0.0.3 area 0 endOn PC-Lee — Reach the application at HQ
ping 172.16.0.10Check: run
show ip route ospfon GW-A and look forO 172.16.0.0/24.Why: Two circuits only help if the routers know both exist. OSPF advertises every connected network a `network` statement covers, so HQ-Core learns 192.168.10.0/24 from both gateways and each gateway learns the HQ LAN over its own circuit. When a path disappears OSPF simply recalculates — no static route to edit at 3 a.m.
8. Kill the active gateway
Time to earn the redundancy. Shut GW-A's Gi0/0 — as far as the user VLAN can tell, GW-A has just died. GW-B stops hearing the master, takes over 192.168.10.1, and PC-Lee's next ping reaches HQ-App through the backup gateway and the backup circuit, without the desk changing a single setting.
On GW-A — Take the active gateway off the user VLAN
enable configure terminal interface Gi0/0 shutdown endOn PC-Lee — The same application, from the same desk
ping 172.16.0.10Check: run
show vrrp briefon GW-B and look forMaster local 192.168.10.1.Why: Hosts keep the same gateway address; what changes is which router answers for it. The new master announces itself with a gratuitous ARP, so every host's cache follows at once, and OSPF moves HQ-Core's route for 192.168.10.0/24 onto the circuit through GW-B so the replies find their way home.
9. Cut the uplink Spanning Tree chose
Now break the layer below. Shut ACC-1's Fa0/23, the uplink to DIST-A that Spanning Tree picked as the root port. The blocked Fa0/24 becomes ACC-1's new root port and starts forwarding, and PC-Lee still reaches HQ-App: two failures at two different layers, and the desk noticed neither.
On ACC-1 — Take down the uplink to the root bridge
enable configure terminal interface Fa0/23 shutdown endOn PC-Lee — Try the application once more
ping 172.16.0.10Check: run
show spanning-tree vlan 10on ACC-1 and look forFa0/24 Root FWD 19 128.Fa0/24 P2p.Why: The Alternate port was blocking, not idle: it kept receiving BPDUs and already knew its cost to the root. With the root port gone it is the best path left, so Rapid PVST+ moves it straight to forwarding. PC-Lee's traffic now climbs Fa0/24 to DIST-B and on to GW-B — the backup of everything.
10. Repair both and watch it fall back
Bring both back with `no shutdown` and type nothing else. GW-A's priority 110 beats GW-B's 100, so it takes the master role back by itself, and Fa0/23 is once again ACC-1's cheapest way to the root, so Fa0/24 returns to blocking. The network ends exactly as designed: root bridge and active gateway on the same side.
On ACC-1 — Restore the uplink to the root bridge
enable configure terminal interface Fa0/23 no shutdown endOn GW-A — Bring the active gateway back onto the user VLAN
enable configure terminal interface Gi0/0 no shutdown endOn PC-Lee — Confirm the application is still there
ping 172.16.0.10Check: run
show spanning-tree vlan 10on ACC-1 and look forFa0/24 Altn BLK 19 128.Fa0/24 P2p.Why: VRRP pre-empts by default: a higher-priority router that comes back reclaims the master role. Spanning Tree keeps no memory either — it re-runs the election on the topology in front of it and lands where the costs say. Both converge on the design you chose, which is why it pays to choose it deliberately.
The theory behind it
More in Capstones
- Campus capstone — Put it all together: two wiring closets, two VLANs, DHCP for the desks, and one public address for the whole site.
- Branch office capstone — Staff and guests on one switch: guests lease an address the moment they plug in, reach the internet, and never see a staff file.
Build it for real
The lab walks you through these steps and ticks each one off as your network starts working.
Open in the lab