Guided buildadvanced7 steps~25 min5 devices
Two routers, one gateway
Give a LAN a gateway that survives a router failure: two routers share one virtual address with VRRP, and the hosts never notice the handover.
What you'll be able to do: The hosts are configured once with 192.168.10.1 and never touched again: GW-A answers for it while healthy, GW-B takes it over the moment GW-A's port dies, and GW-A takes it back when it returns.
Topics: VRRP · First-hop redundancy · Default gateway
What you'll build
- SW-LAN — a switch, the LAN switch both gateways and both PCs plug into
- PC-Ops — a pc, an operations workstation on the LAN
- PC-Desk — a pc, a second workstation on the LAN
- GW-A — a router, the primary gateway router
- GW-B — a router, the standby gateway router
Step by step
1. Build the LAN around a gateway nobody owns yet
Drag a switch and two PCs onto the canvas and cable the PCs to Fa0/1 and Fa0/2. Address them .11 and .12 in 192.168.10.0/24, both with 192.168.10.1 as their gateway — an address that, for now, belongs to no device at all.
- Cable PC-Ops Eth0 ↔ SW-LAN Fa0/1
- Cable PC-Desk Eth0 ↔ SW-LAN Fa0/2
On SW-LAN — Name the LAN switch
enable configure terminal hostname SW-LAN endOn PC-Ops — Name the first PC and point it at the shared gateway
hostname PC-Ops ipconfig Eth0 192.168.10.11 255.255.255.0 192.168.10.1On PC-Desk — Name the second PC and point it at the same gateway
hostname PC-Desk ipconfig Eth0 192.168.10.12 255.255.255.0 192.168.10.1Check: run
route printon PC-Ops and look for0.0.0.0 0.0.0.0 192.168.10.1 Eth0.Why: A host holds exactly one default gateway and has no idea how many routers stand behind it. First-hop redundancy works by keeping that one address alive, never by reconfiguring the hosts.
2. Bring in the primary router
Drag a router on, name it GW-A, cable its Gi0/0 to the switch's Gi0/1, and give it 192.168.10.2. That is GW-A's own address — not the gateway. The hosts still cannot reach 192.168.10.1, because nothing claims it yet.
- Cable GW-A Gi0/0 ↔ SW-LAN Gi0/1
On GW-A — Name the primary router and give it its own LAN address
enable configure terminal hostname GW-A interface Gi0/0 ip address 192.168.10.2 255.255.255.0 no shutdown exit endCheck: run
show ip interface briefon GW-A and look forGi0/0 192.168.10.2 YES manual up up.Why: Each router in a redundancy group keeps a real address of its own, used to manage it and to exchange VRRP messages. The shared gateway address sits on top of those.
3. Claim the gateway address with VRRP
On GW-A's LAN port, create VRRP group 1 for the virtual address 192.168.10.1 and raise GW-A's priority to 110, above the default of 100. GW-A becomes the master: it answers for 192.168.10.1, and both PCs can reach their gateway for the first time.
On GW-A — Own the virtual gateway address as the preferred router
enable configure terminal interface Gi0/0 vrrp 1 ip 192.168.10.1 vrrp 1 priority 110 endOn PC-Ops — Reach the gateway
ping 192.168.10.1Check: run
show vrrpon GW-A and look forState is Master.Why: The master is the router with the highest priority. Setting it deliberately means you decide which router carries the traffic day to day — usually the one with the better uplink — instead of leaving it to chance.
4. Bring in the standby router
Drag a second router on, name it GW-B, cable its Gi0/0 to the switch's Gi0/2, and give it its own address, 192.168.10.3. It sits on the same LAN as GW-A, ready to be the second half of the pair.
- Cable GW-B Gi0/0 ↔ SW-LAN Gi0/2
On GW-B — Name the standby router and give it its own LAN address
enable configure terminal hostname GW-B interface Gi0/0 ip address 192.168.10.3 255.255.255.0 no shutdown exit endCheck: run
show ip interface briefon GW-B and look forGi0/0 192.168.10.3 YES manual up up.Why: Redundancy means two independent paths out of the LAN: two routers, on two separate switch ports, each able to carry every host's traffic alone.
5. Join GW-B to the group as the backup
Give GW-B the same group and the same virtual address, and leave its priority at the default 100. It hears GW-A's advertisements, sees a higher priority, and settles in as backup: show vrrp on GW-B names GW-A as the master at priority 110.
On GW-B — Join VRRP group 1 for the same virtual address
enable configure terminal interface Gi0/0 vrrp 1 ip 192.168.10.1 endCheck: run
show vrrpon GW-B and look forMaster Router is 192.168.10.2, priority is 110.Why: The master advertises itself about once a second. A backup does nothing but listen; as long as those advertisements keep arriving from a higher priority, it stays quiet and never answers for the virtual address.
6. Kill the master — the hosts keep their gateway
Shut GW-A's LAN port, as a failed cable or a dead router would. GW-B stops hearing advertisements, declares the master down, and takes over 192.168.10.1. Ping the gateway from PC-Ops: it answers. GW-A's own address, .2, does not — and the hosts never used it.
On GW-A — Take the master off the LAN
enable configure terminal interface Gi0/0 shutdown endOn PC-Ops — The gateway, after the failure
ping 192.168.10.1Check: run
show vrrpon GW-B and look forState is Master.Why: The backup declares the master dead after about three missed advertisements — a few seconds — then claims the virtual address itself. The hosts' configuration never changes, which is the whole point: a gateway failure costs seconds, not a visit to every desk.
7. Bring GW-A back — and watch it take over again
Open GW-A's port again. It comes back with priority 110, beats GW-B's 100, and takes the master role back — VRRP preempts by default. GW-B returns to backup, and both addresses answer again.
On GW-A — Restore the primary router's LAN port
enable configure terminal interface Gi0/0 no shutdown endCheck: run
show vrrpon GW-B and look forState is Backup.Why: Preemption returns the traffic to the router you chose as primary — the one with the better uplink, the one your monitoring expects. The price is a second, brief handover at the moment it comes back.
The theory behind it
More in Security & resilience
- One jack, one PC: port security — Lock the reception wall jack to one PC with sticky port security, watch a visitor's laptop err-disable it, recover the port, then switch to restrict so the next intruder is dropped without taking reception offline.
- Guard the server with an ACL — Let one workstation reach the server, stop the guest laptop, and learn what the implicit deny does to everyone else.
- A DMZ behind a firewall — Stand a firewall between three zones so the public reaches one server and nothing else.
Build it for real
The lab walks you through these steps and ticks each one off as your network starts working.
Open in the lab