All guided builds

Guided buildcore5 steps~18 min4 devices

VLSM for two sites

Carve one /24 into a /26, a /27 and a /30 sized to what each site needs, then route between them with masks that match the plan.

What you'll be able to do: Two sites cut from one /24 with masks sized to their needs — /26 for about 50 hosts, /27 for about 20, /30 for the link — with 156 addresses left free, and routes whose masks match the plan so every host reaches every other.

Topics: VLSM · Subnets · IPv4 addressing · Address planning · Static routing

What you'll build

Step by step

  1. 1. Plan first, then build the biggest site

    You have one block, 172.16.10.0/24, and two sites: the plant needs about 50 addresses, the office about 20. Start with the biggest. Place the Plant router and a PC, cable the PC into Gi0/0, and give the plant LAN 172.16.10.0/26 — the router takes the first usable address, .1, and the PC the last, .62.

    • Cable Plant Gi0/0 ↔ PC-Plant Eth0

    On Plant — Name the router and make Gi0/0 the plant gateway, 172.16.10.1/26

    enable
    configure terminal
    hostname Plant
    interface Gi0/0
    ip address 172.16.10.1 255.255.255.192
    no shutdown
    exit
    end

    On PC-Plant — Name the PC and give it the last usable address in the /26

    hostname PC-Plant
    ipconfig Eth0 172.16.10.62 255.255.255.192 172.16.10.1

    Check: run show ip route on Plant and look for C 172.16.10.0/26 is directly connected, Gi0/0.

    Why: Fifty hosts need 6 host bits: 64 addresses, minus the network and broadcast addresses, leaves 62 usable — five bits would give only 30. So the mask is /26 (255.255.255.192) and the block runs .0 to .63. Placing the biggest block first keeps every later block on its own natural boundary, with no gaps left behind.

  2. 2. Size the office block and start it where the plant's ended

    The office needs about 20 addresses, and the plant's block ended at .63, so the next one starts at .64. Place the Office router and its PC, and give the office LAN 172.16.10.64/27: gateway .65, PC on the last usable address, .94.

    • Cable Office Gi0/0 ↔ PC-Office Eth0

    On Office — Name the router and make Gi0/0 the office gateway, 172.16.10.65/27

    enable
    configure terminal
    hostname Office
    interface Gi0/0
    ip address 172.16.10.65 255.255.255.224
    no shutdown
    exit
    end

    On PC-Office — Name the PC and give it the last usable address in the /27

    hostname PC-Office
    ipconfig Eth0 172.16.10.94 255.255.255.224 172.16.10.65

    Check: run show ip route on Office and look for C 172.16.10.64/27 is directly connected, Gi0/0.

    Why: Twenty hosts need 5 host bits: 32 addresses, 30 usable, so /27 (255.255.255.224) fits with room to spare. A /26 would waste 32 addresses on a site that will never use them, and a /28 (14 usable) is too small. Choosing the mask per subnet, inside one block, is the whole idea of VLSM — variable-length subnet masking.

  3. 3. Carve a /30 for the link between the sites

    Two routers on a point-to-point link need exactly two addresses. The office block ended at .95, so take 172.16.10.96/30: draw a serial cable between the two Se0/0/0 ports, then give Plant .97 and Office .98.

    • Cable Plant Se0/0/0 ↔ Office Se0/0/0 (serial)

    On Plant — Take the plant end of the link, 172.16.10.97/30

    enable
    configure terminal
    interface Se0/0/0
    ip address 172.16.10.97 255.255.255.252
    no shutdown
    exit
    end

    On Office — Take the office end of the same link, 172.16.10.98/30

    enable
    configure terminal
    interface Se0/0/0
    ip address 172.16.10.98 255.255.255.252
    no shutdown
    exit
    end

    Check: run show ip route on Plant and look for C 172.16.10.96/30 is directly connected, Se0/0/0.

    Why: Two host bits give four addresses: .96 network, .97 and .98 usable, .99 broadcast — nothing wasted on a wire that can only ever hold two routers. The plan now spans .0 to .99 and leaves .100 to .255 free for the next site.

  4. 4. Route between the sites — with the slip VLSM invites

    Plant needs a route to the office's /27, and Office needs one to the plant's /26. Type Office's with the /27 mask you just used for its own LAN — the easiest VLSM mistake there is — then ping both ends of the plant LAN from PC-Office. The gateway at .1 answers; PC-Plant at .62 does not.

    On Plant — Route to the office LAN, 172.16.10.64/27, via Office's end of the link

    enable
    configure terminal
    ip route 172.16.10.64 255.255.255.224 172.16.10.98
    end

    On Office — Route to the plant LAN — with the wrong mask, on purpose

    enable
    configure terminal
    ip route 172.16.10.0 255.255.255.224 172.16.10.97
    end

    On PC-Office — Ping the bottom and the top of the plant LAN

    ping 172.16.10.1
    ping 172.16.10.62

    Check: run show ip route 172.16.10.62 on Office and look for % Network not in table.

    Why: A route's mask decides how many addresses it covers. 172.16.10.0/27 spans only .0 to .31, so the gateway at .1 is inside it and PC-Plant at .62 is not: Office has no route that matches .62 and drops the packet. With VLSM every route must carry the mask of the subnet it points at, not the mask you typed last.

  5. 5. Fix the mask and let the whole plant LAN in

    Delete Office's route and type it again with the plant's real mask, 255.255.255.192. The route now covers .0 to .63, PC-Plant at .62 falls inside it, and the two sites reach each other in both directions.

    On Office — Replace the /27 route with the /26 it should have been

    enable
    configure terminal
    no ip route 172.16.10.0 255.255.255.224 172.16.10.97
    ip route 172.16.10.0 255.255.255.192 172.16.10.97
    end

    On PC-Office — Repeat the ping that failed

    ping 172.16.10.62

    Check: run show ip route 172.16.10.62 on Office and look for Routing entry for 172.16.10.0/26.

    Why: A route is a promise about a range of addresses, and the mask is the size of that promise. With a /26 route on Office and a /27 route on Plant, each router's table now mirrors the other site's plan exactly.

The theory behind it

Build it for real

The lab walks you through these steps and ticks each one off as your network starts working.

Open in the lab
VLSM for two sites — step-by-step network lab · NetForge-AI