Guided buildcore8 steps~20 min4 devices
A backup link that waits its turn
Run two sites over a fast primary link, park a floating static route on a slow standby line, then pull the primary and watch the backup carry the traffic.
What you'll be able to do: Two sites that keep talking when their main link dies: OSPF runs the fast primary, a static route with a distance of 200 waits on the serial standby, and pulling the primary moves the traffic across — and back again — without anyone touching a route.
Topics: Floating static routes · Administrative distance · Static routing · OSPF · WAN links · Routing tables
What you'll build
- HQ — a router, the head-office router
- PC-HQ — a pc, a workstation at head office
- Branch — a router, the branch router
- PC-Branch — a pc, a workstation at the branch
Step by step
1. Stand up the head-office site
Drag a router and a PC onto the canvas, cable the PC into the router's Gi0/0, then name the router and give that port the LAN's gateway address. Everything this build does is about how HQ reaches one network at the far end — first over one path, then over another.
- Cable HQ Gi0/0 ↔ PC-HQ Eth0
On HQ — Name the router and make Gi0/0 the head-office gateway
enable configure terminal hostname HQ interface Gi0/0 ip address 192.168.10.1 255.255.255.0 no shutdown exit endOn PC-HQ — Name the workstation, address it, and point it at its gateway
hostname PC-HQ ipconfig Eth0 192.168.10.10 255.255.255.0 192.168.10.1Check: run
show ip routeon HQ and look forC 192.168.10.0/24 is directly connected, Gi0/0.Why: A router learns exactly one kind of route for free: the networks on its own live interfaces, marked C. Every route beyond those has to come from somewhere else — a person typing it, or a protocol learning it — and this build uses both, for the same network, at the same time.
2. Stand up the branch site
Same recipe at the second site, in a different subnet: a router named Branch with 192.168.20.1 on Gi0/0, and a PC behind it. The two sites are still islands — there is no cable between them yet.
- Cable Branch Gi0/0 ↔ PC-Branch Eth0
On Branch — Name the router and make Gi0/0 the branch gateway
enable configure terminal hostname Branch interface Gi0/0 ip address 192.168.20.1 255.255.255.0 no shutdown exit endOn PC-Branch — Name the workstation, address it, and point it at its gateway
hostname PC-Branch ipconfig Eth0 192.168.20.10 255.255.255.0 192.168.20.1Check: run
show ip routeon Branch and look forC 192.168.20.0/24 is directly connected, Gi0/0.Why: Routing only exists between different subnets. If both sites used 192.168.10.0/24, every host would think the other site was local and never hand its traffic to a router at all.
3. Run the fast primary link
Cable HQ's Gi0/1 to Branch's Gi0/1 — this is the fast link, the one you want carrying traffic every day — and address both ends out of 10.0.0.0/30. HQ takes .1, Branch takes .2.
- Cable HQ Gi0/1 ↔ Branch Gi0/1
On HQ — Take the head-office end of the primary link, 10.0.0.1
enable configure terminal interface Gi0/1 ip address 10.0.0.1 255.255.255.252 no shutdown exit endOn Branch — Take the branch end of the same link, 10.0.0.2
enable configure terminal interface Gi0/1 ip address 10.0.0.2 255.255.255.252 no shutdown exit endCheck: run
show ip interface briefon HQ and look forGi0/1 10.0.0.1 YES manual up up.Why: A point-to-point link only ever holds two routers, so a /30 — exactly two usable addresses — wastes nothing. The routers can now reach each other, but neither has a route to the other's LAN yet.
4. Let OSPF run the primary path
Start OSPF on both routers with two `network` lines each: one for the router's own LAN, one for the primary /30. The routers find each other across Gi0/1, swap what they know, and each installs a route to the other site's LAN marked O. PC-HQ can now reach the branch.
On HQ — Advertise the head-office LAN and the primary link into OSPF
enable configure terminal router ospf 1 network 192.168.10.0 0.0.0.255 area 0 network 10.0.0.0 0.0.0.3 area 0 endOn Branch — Advertise the branch LAN and the same link
enable configure terminal router ospf 1 network 192.168.20.0 0.0.0.255 area 0 network 10.0.0.0 0.0.0.3 area 0 endOn PC-HQ — Cross to the branch over the primary link
ping 192.168.20.10Check: run
show ip routeon HQ and look forO 192.168.20.0/24 [110/2] via 10.0.0.2, Gi0/1.Why: The [110/2] reads as [administrative distance / metric]. 110 is how much a router trusts OSPF compared with other sources of routes; 2 is the path's cost, 1 for each gigabit interface on the way — HQ's Gi0/1 out, then the branch LAN's Gi0/0. The /30 line's wildcard, 0.0.0.3, matches the primary link and nothing else, so the serial line you add next stays outside OSPF — which is exactly what makes it a backup you control.
5. Add the slow standby line
Now the insurance policy: a serial cable between the two routers' Se0/0/0 ports, addressed from the next /30 along, 10.0.0.4/30. The line comes up, but nothing crosses it — no route anywhere points at it, and OSPF was never told about it.
- Cable HQ Se0/0/0 ↔ Branch Se0/0/0 (serial)
On HQ — Take the head-office end of the standby line, 10.0.0.5
enable configure terminal interface Se0/0/0 ip address 10.0.0.5 255.255.255.252 no shutdown exit endOn Branch — Take the branch end, 10.0.0.6
enable configure terminal interface Se0/0/0 ip address 10.0.0.6 255.255.255.252 no shutdown exit endCheck: run
show ip interface briefon HQ and look forSe0/0/0 10.0.0.5 YES manual up up.Why: A backup path is a link like any other and needs its own subnet. It is deliberately left out of OSPF: which traffic crosses it, and when, is about to be decided by a single static route.
6. Park a floating static on the standby line
Give each router a static route to the other site's LAN through the serial line — with 200 on the end. That number is the route's administrative distance. A plain static carries 1 and would beat OSPF's 110; at 200 it loses instead, so it waits, configured but carrying nothing, until OSPF has no answer for that network. Ask HQ which route it would use for the branch: it still names OSPF.
On HQ — Point HQ at the branch LAN through the standby line, at distance 200
enable configure terminal ip route 192.168.20.0 255.255.255.0 10.0.0.6 200 endOn Branch — Point Branch back at the head-office LAN the same way
enable configure terminal ip route 192.168.10.0 255.255.255.0 10.0.0.5 200 endCheck: run
show ip route 192.168.20.10on HQ and look forKnown via "ospf 1", distance 110, metric 2.Why: When two sources offer the exact same prefix, a router believes the one with the lower administrative distance: connected 0, static 1, EIGRP 90, OSPF 110, RIP 120. A floating static is an ordinary static route with its distance raised above the route it protects, so it only takes over once that route is gone. It is configured on both routers because traffic has to be able to come back, too.
7. Pull the primary link
Shut HQ's Gi0/1 — the same thing a cut cable or a dead provider circuit does to a router. OSPF loses its neighbour and withdraws the route it learned over that link, and the static route at distance 200 is suddenly the best answer left. Ping the branch again from PC-HQ: it still works, now across the serial line.
On HQ — Take the primary link down
enable configure terminal interface Gi0/1 shutdown endOn PC-HQ — Reach the branch with the primary link gone
ping 192.168.20.10Check: run
show ip route 192.168.20.10on HQ and look forKnown via "static", distance 200, metric 0.Why: Nothing about the static route changed; the route that was beating it disappeared. Distance only chooses between routes that exist, so removing the winner promotes the runner-up without anyone typing a command. Branch fails over the same way, which is why the return traffic finds its way home too.
8. Restore the primary and watch OSPF take it back
Bring Gi0/1 back with `no shutdown`. OSPF re-forms its adjacency and re-learns the branch LAN at distance 110, the floating static drops back to waiting, and traffic returns to the fast link — again without a single route being edited.
On HQ — Bring the primary link back up
enable configure terminal interface Gi0/1 no shutdown endCheck: run
show ip routeon HQ and look forO 192.168.20.0/24 [110/2] via 10.0.0.2, Gi0/1.Why: Failback is as automatic as failover, and for the same reason: whenever both routes exist, the lower distance wins. Nobody has to remember to undo the backup — which is the whole point of floating it instead of switching routes by hand.
The theory behind it
More in Routing
- Static routes across a WAN — Join three sites with point-to-point WAN links and route between them by hand, one line at a time.
- RIP: routing by counting hops — Chain three routers over two serial links and let RIP version 2 teach every router the way to every network, counting the hops as it goes.
- Two routers that learn the network — Join two sites over a WAN link, then let OSPF fill in the routing tables that you would otherwise type by hand.
- Steer OSPF with link cost — Give OSPF two paths between two sites, watch it choose the cheaper one over the shorter one, then re-rate a link and watch the route move.
- Share one default route with OSPF — Give the edge router a default route to the provider, then let OSPF hand it to the rest of the campus instead of typing it on every router.
- EIGRP across three routers — Join two sites through a hub with EIGRP, find why one router learns nothing, then add a direct link and watch EIGRP choose speed over hop count.
Build it for real
The lab walks you through these steps and ticks each one off as your network starts working.
Open in the lab