All guided builds

Guided buildcore9 steps~22 min6 devices

Static routes across a WAN

Join three sites with point-to-point WAN links and route between them by hand, one line at a time.

What you'll be able to do: Three sites in three subnets, chained by two serial links, where every router carries a hand-written route to every network it is not plugged into — and a ping that crosses the whole chain and comes back.

Start this build in the lab 6 devices — needs any paid plan (the free canvas fits 5).

Topics: Static routing · WAN links · Serial interfaces · /30 subnets · Return paths

What you'll build

Step by step

  1. 1. Stand up the branch site

    Drag a router and a PC onto the canvas, cable the PC into the router's Gi0/0, then name the router and put the LAN's first address on that port. A router learns exactly one thing for free: the networks wired to its own live interfaces. Everything beyond them is your job.

    • Cable Branch Gi0/0 ↔ PC-Branch Eth0

    On Branch — Name the router and make Gi0/0 the branch LAN's gateway

    enable
    configure terminal
    hostname Branch
    interface Gi0/0
    ip address 192.168.1.1 255.255.255.0
    no shutdown
    exit
    end

    On PC-Branch — Name the workstation, address it, and point it at its gateway

    hostname PC-Branch
    ipconfig Eth0 192.168.1.10 255.255.255.0 192.168.1.1

    Check: run show ip route on Branch and look for C 192.168.1.0/24 is directly connected, Gi0/0.

    Why: A router's first routes come from its own interfaces: every port that is up and addressed contributes a connected route for the subnet it sits on, with no configuration beyond the address. Every other kind of route is ultimately resolved through one of these, because a packet can only ever leave through a live interface toward a neighbour on a connected network.

  2. 2. Stand up the headquarters site

    Same recipe, second site: one router, one PC, one cable — and a different subnet. Two sites mean two subnets, because if both LANs were 192.168.1.0/24 there would be nothing for a router to route between and every host would think the others were local.

    • Cable HQ Gi0/0 ↔ PC-HQ Eth0

    On HQ — Name the router and make Gi0/0 the headquarters gateway

    enable
    configure terminal
    hostname HQ
    interface Gi0/0
    ip address 192.168.2.1 255.255.255.0
    no shutdown
    exit
    end

    On PC-HQ — Name the workstation, address it, and point it at its gateway

    hostname PC-HQ
    ipconfig Eth0 192.168.2.10 255.255.255.0 192.168.2.1

    Check: run show ip route on HQ and look for C 192.168.2.0/24 is directly connected, Gi0/0.

    Why: An address plan is the part of routing that happens before any router is involved. Giving each site its own /24 with the same internal pattern — .1 for the gateway, .10 for the first host — means any address tells you its site and its role at a glance, which pays off every time you read a routing table or chase a failed ping.

  3. 3. Run the WAN link between the two sites

    Draw a serial cable from Branch's Se0/0/0 to HQ's Se0/0/0 and address both ends out of 10.0.0.0/30. A /30 leaves exactly two usable addresses, which is all a point-to-point link will ever need: one per end, nothing wasted on a wire that can only ever hold two routers.

    • Cable Branch Se0/0/0 ↔ HQ Se0/0/0 (serial)

    On Branch — Take the branch end of the WAN link, 10.0.0.1

    enable
    configure terminal
    interface Se0/0/0
    ip address 10.0.0.1 255.255.255.252
    no shutdown
    exit
    end

    On HQ — Take the headquarters end of the same link, 10.0.0.2

    enable
    configure terminal
    interface Se0/0/0
    ip address 10.0.0.2 255.255.255.252
    no shutdown
    exit
    end

    Check: run show ip interface brief on Branch and look for Se0/0/0 10.0.0.1 YES manual up up.

    Why: A point-to-point link is a network in its own right, with its own subnet, even though only two devices will ever sit on it. Once both ends are up each router gains a connected route for 10.0.0.0/30 and can reach the other directly — but that is all it gains: a router learns about the link to its neighbour, not about anything behind the neighbour.

  4. 4. Tell Branch where the HQ LAN lives — and only Branch

    `ip route 192.168.2.0 255.255.255.0 10.0.0.2` reads as "for that network, hand the packet to 10.0.0.2". You are not describing a path, only the next router along. Now open PC-HQ and ping 192.168.1.10: it dies at HQ, which holds no entry for 192.168.1.0/24 and drops what it cannot place.

    On Branch — Point the branch at the headquarters LAN, via the far end of the WAN link

    enable
    configure terminal
    ip route 192.168.2.0 255.255.255.0 10.0.0.2
    end

    On PC-HQ — Try the trip in the other direction and watch it fail

    ping 192.168.1.10

    Check: run show ip route static on Branch and look for S 192.168.2.0/24 via 10.0.0.2, Se0/0/0.

    Why: A static route programs one router, for one destination, in one direction, and routers never share what they know unless a routing protocol makes them. Its next hop must also be an address the router can already reach — here the far end of a connected /30 — because the route only says who to hand the packet to, not how to get there.

  5. 5. Write the other half of the conversation

    Give HQ the mirror image, `ip route 192.168.1.0 255.255.255.0 10.0.0.1`, and each router now owns one direction of the same path. This is the rule that catches people out: traffic can arrive perfectly well and still have no way to answer, so a WAN is never finished until both ends have been told about each other.

    On HQ — Point headquarters back at the branch LAN

    enable
    configure terminal
    ip route 192.168.1.0 255.255.255.0 10.0.0.1
    end

    On PC-HQ — Repeat the ping that failed a moment ago

    ping 192.168.1.10

    Check: run show ip route on HQ and look for S 192.168.1.0/24 via 10.0.0.1, Se0/0/0.

    Why: Routers do not consult each other when forwarding; each decides from its own table alone. That makes each direction of a path a separate fact stored on a separate router — Branch's route cannot help a packet that starts at HQ. Static routing leaves every one of those facts to you, where a routing protocol would have had Branch advertise its own LAN to HQ.

  6. 6. Add the third site and a second WAN leg

    The remote site is the same recipe once more — a LAN gateway on Gi0/0, a PC behind it — plus a second serial link into HQ's spare Se0/0/1, addressed out of a fresh 10.0.0.4/30. HQ now sits between two WAN neighbours, which is what makes it the transit site for everything that follows.

    • Cable HQ Se0/0/1 ↔ Remote Se0/0/0 (serial)
    • Cable Remote Gi0/0 ↔ PC-Remote Eth0

    On HQ — Address the headquarters end of the second WAN link

    enable
    configure terminal
    interface Se0/0/1
    ip address 10.0.0.5 255.255.255.252
    no shutdown
    exit
    end

    On Remote — Name the far router, give it a LAN gateway and the other end of the link

    enable
    configure terminal
    hostname Remote
    interface Gi0/0
    ip address 192.168.3.1 255.255.255.0
    no shutdown
    exit
    interface Se0/0/0
    ip address 10.0.0.6 255.255.255.252
    no shutdown
    exit
    end

    On PC-Remote — Name the workstation, address it, and point it at its gateway

    hostname PC-Remote
    ipconfig Eth0 192.168.3.10 255.255.255.0 192.168.3.1

    Check: run show ip interface brief on Remote and look for Se0/0/0 10.0.0.6 YES manual up up.

    Why: Transit links are carved as consecutive /30 blocks — 10.0.0.0, 10.0.0.4, 10.0.0.8 — because a block always starts on a multiple of its own size. Keeping them together in one range makes them easy to recognise in a routing table and possible to summarise later as a single route.

  7. 7. Route between headquarters and the remote site

    Two more routes, one on each router, and the middle site can talk to the far one. It is the same pair you wrote for the first WAN link, pointed at the new next hops — and that arithmetic is the honest cost of static routing: one line per router, per remote network, every time the network grows.

    On HQ — Point headquarters at the remote LAN, via 10.0.0.6

    enable
    configure terminal
    ip route 192.168.3.0 255.255.255.0 10.0.0.6
    end

    On Remote — Point the remote site back at the headquarters LAN, via 10.0.0.5

    enable
    configure terminal
    ip route 192.168.2.0 255.255.255.0 10.0.0.5
    end

    Check: run show ip route on Remote and look for S 192.168.2.0/24 via 10.0.0.5, Se0/0/0.

    Why: A static route never changes on its own: it keeps pointing at its next hop until someone edits it, and it only leaves the table if that next hop becomes unreachable. That predictability is why statics are still used for small and stub networks — and why every new network means another line on every router that needs to reach it.

  8. 8. Join the two ends that share no cable

    Branch and Remote have never been wired together, so each needs a route to the other's LAN pointing at the only neighbour it has. Branch sends 192.168.3.0/24 to 10.0.0.2 even though that address belongs to HQ: a next hop is always the next router along, never the destination you are aiming at.

    On Branch — Point the branch at the remote LAN, through HQ

    enable
    configure terminal
    ip route 192.168.3.0 255.255.255.0 10.0.0.2
    end

    On Remote — Point the remote site at the branch LAN, through HQ

    enable
    configure terminal
    ip route 192.168.1.0 255.255.255.0 10.0.0.5
    end

    On PC-Branch — Cross the whole chain: two routers, two WAN links, one reply

    ping 192.168.3.10

    Check: run show ip route on Branch and look for S 192.168.3.0/24 via 10.0.0.2, Se0/0/0.

    Why: Routing is hop by hop: Branch only has to get the packet one router closer, and HQ then makes its own decision from its own table. No router ever holds the whole path — each knows only the next step — which is why a path is only as good as the weakest table along it.

  9. 9. Route the WAN links themselves

    Ping 10.0.0.6 from PC-Branch and it fails, even though the LAN-to-LAN path already works. The transit /30s are networks like any other and nobody outside them has been told where they are. Two last routes make every address in the topology answer, which is exactly what you want on the day a link goes quiet and you need to ping the far end of it.

    On Branch — Teach the branch about the far WAN link, 10.0.0.4/30

    enable
    configure terminal
    ip route 10.0.0.4 255.255.255.252 10.0.0.2
    end

    On Remote — Teach the remote site about the near WAN link, 10.0.0.0/30

    enable
    configure terminal
    ip route 10.0.0.0 255.255.255.252 10.0.0.5
    end

    Check: run show ip route static on Branch and look for S 10.0.0.4/30 via 10.0.0.2, Se0/0/0.

    Why: Transit subnets are networks like any other, and a router only forwards to networks in its table. User traffic never targets them, which is why everything worked without these routes, but management does: engineers reach, monitor and log routers at their interface addresses, and many of those live in the transit /30s.

The theory behind it

Build it for real

The lab walks you through these steps and ticks each one off as your network starts working.

Open in the lab
Static routes across a WAN — step-by-step network lab · NetForge-AI