All guided builds

Guided buildadvanced7 steps~28 min7 devices

OSPF across two areas

Split an OSPF network into a backbone and a branch area, and make one router the border between them.

What you'll be able to do: A headquarters in area 0 and a branch office in area 1 route to each other through a single border router, and a change on either side stops short of flooding the other.

Start this build in the lab 7 devices — needs any paid plan (the free canvas fits 5).

Topics: OSPF · Multi-area OSPF · ABR · Link-state routing

What you'll build

Step by step

  1. 1. Anchor the backbone at headquarters

    Drag a router and a switch onto the canvas, cable them, and give the router the HQ LAN address 10.10.0.1/24. Area 0 is the backbone every other area has to touch, so it is worth starting where the backbone lives rather than at the far end of the network.

    • Cable Core Gi0/0 ↔ SW-Core Gi0/1

    On Core — Name the HQ router and address its LAN port

    enable
    configure terminal
    hostname Core
    interface Gi0/0
    ip address 10.10.0.1 255.255.255.0
    no shutdown
    exit
    end

    On SW-Core — Name the HQ switch so its console prompt is unmistakable

    enable
    configure terminal
    hostname SW-Core
    end

    Check: run show ip interface brief on Core and look for Gi0/0 10.10.0.1 YES manual up.

    Why: OSPF's areas form a two-level hierarchy with area 0 at the centre, and routes between two areas only ever travel through it. Designing from the backbone outwards means every area you add later has a place to attach from the moment it is built.

  2. 2. Put a workstation on the HQ LAN

    Cable a PC to Fa0/1 and give it an address, a mask and the router as its gateway in one line. This host is the yardstick for the rest of the build: every later step is measured by what PC-HQ can and cannot reach.

    • Cable PC-HQ Eth0 ↔ SW-Core Fa0/1

    On PC-HQ — Name the workstation, address it, and prove it reaches its gateway

    hostname PC-HQ
    ipconfig Eth0 10.10.0.20 255.255.255.0 10.10.0.1
    ping 10.10.0.1

    Check: run ip -br a on PC-HQ and look for Eth0 UP 10.10.0.20/24.

    Why: A successful ping to the gateway is a compact proof of several layers at once: the cable and the switch port carried frames, ARP resolved the router's MAC, and both ends agree on the subnet. When a later ping fails, you already know which of those facts it is not.

  3. 3. Raise the backbone: area 0 between two routers

    Add the second router, join the two with a /30 — two usable addresses, which is all a point-to-point link ever needs — and start an OSPF process on each. Every `network` statement here says `area 0`, so both routers hold the same link-state database and both run SPF over the same map. That is exactly the property that stops scaling: in one flat area, a flapping link anywhere makes every router everywhere recompute.

    • Cable Core Gi0/1 ↔ Border Gi0/1

    On Core — Address the backbone link and advertise both HQ networks into area 0

    enable
    configure terminal
    interface Gi0/1
    ip address 10.0.0.1 255.255.255.252
    no shutdown
    exit
    router ospf 1
    router-id 1.1.1.1
    network 10.10.0.0 0.0.0.255 area 0
    network 10.0.0.0 0.0.0.3 area 0
    exit
    end

    On Border — Name the border router and bring its area 0 leg into the same process

    enable
    configure terminal
    hostname Border
    interface Gi0/1
    ip address 10.0.0.2 255.255.255.252
    no shutdown
    exit
    router ospf 1
    router-id 2.2.2.2
    network 10.0.0.0 0.0.0.3 area 0
    exit
    end

    Check: run show ip ospf neighbor on Core and look for 2.2.2.2 1 FULL.

    Why: A `network` statement does two jobs at once: it switches OSPF on for every interface whose address it matches, and it places that interface in an area. Area membership is therefore a property of each interface, not of the router — which is exactly what will let one router sit in two areas later in this build.

  4. 4. Cable the branch office

    Hang a third router off Border's serial port, give the branch its own /24, and put a workstation on it. Nothing here mentions OSPF yet: this step is only wire and addresses, so that the next one can isolate what the protocol adds.

    • Cable Border Se0/0/0 ↔ Branch Se0/0/0 (serial)
    • Cable Branch Gi0/0 ↔ PC-Branch Eth0

    On Border — Address the serial link towards the branch

    enable
    configure terminal
    interface Se0/0/0
    ip address 10.0.0.5 255.255.255.252
    no shutdown
    exit
    end

    On Branch — Name the branch router and address both of its ports

    enable
    configure terminal
    hostname Branch
    interface Gi0/0
    ip address 10.20.0.1 255.255.255.0
    no shutdown
    exit
    interface Se0/0/0
    ip address 10.0.0.6 255.255.255.252
    no shutdown
    exit
    end

    On PC-Branch — Name and address the branch workstation

    hostname PC-Branch
    ipconfig Eth0 10.20.0.20 255.255.255.0 10.20.0.1

    Check: run show ip route on Branch and look for C 10.0.0.4/30 is directly connected, Se0/0/0.

    Why: Mixing prefix lengths is ordinary: LANs get a /24 because they hold hosts, and each point-to-point link gets a /30 because it holds exactly two routers. OSPF carries every prefix with its own mask, which is what makes a variable-length plan like this one work.

  5. 5. Start OSPF at the branch — and watch nothing happen

    Put both branch networks into area 1 and give the router an id. The serial link is up, the addresses are in the same /30, the process is running at this end — and the ping to HQ still fails. Read Branch's neighbour table before you read the next step: the router tells you exactly what it is waiting for.

    On Branch — Advertise the branch LAN and the serial link into area 1

    enable
    configure terminal
    router ospf 1
    router-id 3.3.3.3
    network 10.20.0.0 0.0.0.255 area 1
    network 10.0.0.4 0.0.0.3 area 1
    exit
    end

    On PC-Branch — Try HQ from the branch — this one is supposed to fail

    ping 10.10.0.20

    Check: run show ip ospf neighbor on Branch and look for Confirm the peer also runs OSPF with matching area..

    Why: An OSPF adjacency needs Hellos from both ends of a link, and Border's serial interface matches none of its `network` statements, so it sends none. Branch's Hellos go unanswered, no databases are exchanged, and area 1 stays cut off from the backbone.

  6. 6. Give Border a leg in both areas

    One line fixes it: Border claims the serial /30 for area 1 while it keeps Gi0/1 in area 0. A router with interfaces in two areas is an Area Border Router, and an ABR is the only thing that moves reachability between them — it keeps a separate link-state database per area and passes each one a summary of the other instead of the raw topology. Area 1 now has a way into the backbone, and every prefix that crosses arrives marked `O IA`, inter-area.

    On Border — Attach area 1 to the backbone through the existing OSPF process

    enable
    configure terminal
    router ospf 1
    network 10.0.0.4 0.0.0.3 area 1
    exit
    end

    Check: run show ip route on Core and look for O IA 10.20.0.0/24 [110/66] via 10.0.0.2, Gi0/1.

    Why: Between areas, OSPF behaves much like a distance-vector protocol: routers in area 1 know the HQ networks only as reachable through Border at a given cost, never as part of their own map. That is why every area must touch area 0 — with the backbone as the only transit between areas, those second-hand routes cannot form a loop.

  7. 7. Add a server to area 0 and read the branch's table

    Plug a server into the HQ switch, address it, and ping it from the branch. Nobody touched Branch, and `show ip route ospf` there looks identical to before — the single `O IA 10.10.0.0/24` entry already covered the new host. That is what buying an area gets you: work inside one area stops at the ABR instead of rippling out as a database change every router in the company has to process.

    • Cable WEB1 Eth0 ↔ SW-Core Fa0/2

    On WEB1 — Name and address the HQ server on the existing LAN

    hostname WEB1
    ipconfig Eth0 10.10.0.80 255.255.255.0 10.10.0.1
    ping 10.20.0.20

    Check: run show ip route ospf on Branch and look for O IA 10.10.0.0/24 [110/66] via 10.0.0.5, Se0/0/0.

    Why: Routing tables list networks, not hosts. WEB1 lives inside 10.10.0.0/24, a prefix Branch already reaches, so plugging it in changes no route anywhere — a new host is never an OSPF event, in any design. What an area boundary hides is topology: changes to links inside area 0 reach Branch only as updated summaries from Border, never as HQ's detailed map.

The theory behind it

Build it for real

The lab walks you through these steps and ticks each one off as your network starts working.

Open in the lab
OSPF across two areas — step-by-step network lab · NetForge-AI