Guided buildstarter6 steps~12 min4 devices
Three hosts, one switch
Put three PCs on a single subnet through an unconfigured switch and watch it learn who lives where.
What you'll be able to do: Three PCs on 192.168.10.0/24 that can ping one another through a switch you never had to configure, plus a MAC address table you can read and explain.
Topics: Ethernet switching · MAC address table · ARP · IPv4 addressing
What you'll build
- SW-Floor1 — a switch, the access switch every host plugs into
- PC-A — a pc, the first host, on Fa0/1
- PC-B — a pc, the second host, on Fa0/2
- PC-C — a pc, the host that arrives late, on Fa0/3
Step by step
1. Start with the switch
Drag a switch onto the canvas and give it a name, so its console prompt tells you which box you are typing into. That name is the only thing you will configure on it for most of this build: a switch forwards Ethernet frames on every port out of the box, with no addresses and no commands.
On SW-Floor1 — Name the switch so the prompt is unambiguous
enable configure terminal hostname SW-Floor1 endCheck: run
show mac address-tableon SW-Floor1 and look for(empty).Why: A switch forwards on Ethernet MAC addresses and learns where each one lives for itself, from the traffic passing through, so it needs no IP address and no configuration to do its job. Its MAC address table starts empty, and every entry that ever appears there is learned — the rest of this build watches that happen.
2. Connect the first host
Place a PC, run a copper cable from its Eth0 port to Fa0/1 on the switch, then give it an address inside 192.168.10.0/24. No default gateway is needed: every address this host will talk to today sits on its own subnet, so nothing has to leave the LAN.
- Cable PC-A Eth0 ↔ SW-Floor1 Fa0/1
On PC-A — Name the host and give it a static address
hostname PC-A ipconfig Eth0 192.168.10.11 255.255.255.0Check: run
ip -br aon PC-A and look for192.168.10.11/24.Why: The switch never reads the PC's IP address; it carries the PC's frames whatever address it holds. Addresses and masks matter to the hosts, because each host uses its own to decide which destinations share its wire — 192.168.10.11/24 declares everything from .1 to .254 local.
3. Add a second host and ping across the switch
One host cannot prove anything, so cable a second PC to Fa0/2, address it in the same subnet, and ping it from PC-A. ARP has to run first: PC-A knows the IP but not the MAC behind it, so it broadcasts a request, the switch floods that frame out of every other port, and PC-B replies with its own address.
- Cable PC-B Eth0 ↔ SW-Floor1 Fa0/2
On PC-B — Name the second host and address it on the same subnet
hostname PC-B ipconfig Eth0 192.168.10.12 255.255.255.0On PC-A — Send the first traffic this LAN has ever carried
ping 192.168.10.12Check: run
arp -aon PC-A and look for(192.168.10.12) at.Why: A broadcast is flooded by definition, because it is addressed to everyone, but PC-B's reply is unicast to PC-A's MAC — and by then the switch has already learned from the request which port PC-A is on. Both hosts also cache what ARP taught them, which is why `arp -a` on PC-A now lists 192.168.10.12 and the next ping needs no ARP at all.
4. Plug in a third host, but say nothing yet
Place the last PC, cable it to Fa0/3 and name it, then stop before addressing it. Read the switch's MAC address table now: the cable is live and the port is up, yet the table still holds only the two hosts that have spoken, because a switch learns from the source address of arriving frames and not from ports coming up.
- Cable PC-C Eth0 ↔ SW-Floor1 Fa0/3
On PC-C — Name the third host and leave it silent for now
hostname PC-CCheck: run
show mac address-tableon SW-Floor1 and look forTotal Mac Addresses for this criterion: 2.Why: An unknown destination is not an error to a switch: a frame for a MAC it has never seen is flooded out of every port in the VLAN except the one it arrived on, and the reply, which carries the missing source address, fills the gap. Learning waits for traffic on purpose, because a frame from a host is the only reliable evidence of where that host really is.
5. Give the third host an address and let it speak
Address PC-C on the same subnet and ping PC-A from it. One exchange is enough: the switch sees a frame arrive on Fa0/3, files PC-C's MAC address against that port, and from then on sends traffic for PC-C down one cable instead of flooding it to everybody.
On PC-C — Address the third host and start a conversation
ipconfig Eth0 192.168.10.13 255.255.255.0 ping 192.168.10.11Check: run
show mac address-tableon SW-Floor1 and look forTotal Mac Addresses for this criterion: 3.Why: A MAC table entry is one fact — this address was last seen arriving on this port — and a single frame is enough to write it. From then on, frames for PC-C leave by Fa0/3 alone, which is what makes a switch both faster and more private than a hub, a device that repeats every frame out of every port.
6. Give the switch an address of its own
The switch has carried every frame so far without an IP address, which is exactly why nothing on the LAN can reach the switch itself. Putting a management address on the VLAN 1 interface makes it a host on this subnet as well, so you can reach its console remotely, and it changes nothing about how frames are forwarded.
On SW-Floor1 — Add a management address on the VLAN 1 interface
enable configure terminal interface vlan 1 ip address 192.168.10.2 255.255.255.0 no shutdown endOn PC-B — Prove the switch now answers for itself
ping 192.168.10.2Check: run
show ip interface briefon SW-Floor1 and look forVlan1 192.168.10.2.Why: `interface vlan 1` is a switch virtual interface: a logical port that connects the switch's own management plane to VLAN 1, as if a small host lived inside the chassis. It answers ARP and ping like any host but takes no part in moving frames between the physical ports, and reaching it from another subnet would also need `ip default-gateway`, just as a PC needs a gateway.
The theory behind it
More in Foundations
- One router, one PC, one ping — Build the smallest network that works: address a router and a PC on the same subnet and get a reply back.
- ARP and MAC learning, side by side — Watch a host's ARP cache and a switch's MAC table fill from the very first frame — and see why a host never ARPs for anything beyond its gateway.
- Two LANs, one router — Put a PC on each of two different subnets and make them talk through a router.
- VLSM for two sites — Carve one /24 into a /26, a /27 and a /30 sized to what each site needs, then route between them with masks that match the plan.
- A stub branch and one default route — Send everything a branch can't place to HQ with a single default route, and see why HQ still needs a specific route back for every branch network.
- Traceroute across three routers — Chain three routers with static routes and follow a packet hop by hop — then watch a trace stop at a missing route and circle in a routing loop.
Build it for real
The lab walks you through these steps and ticks each one off as your network starts working.
Open in the lab