All guided builds

Guided buildcore7 steps~25 min5 devices

Traceroute across three routers

Chain three routers with static routes and follow a packet hop by hop — then watch a trace stop at a missing route and circle in a routing loop.

What you'll be able to do: A three-router chain where a trace from one PC to the other names every router in order — and the habit of reading where a failing path stops, whether at a missing route or in a loop.

Topics: Traceroute · Static routing · Routing tables · Routing loops

What you'll build

Step by step

  1. 1. Stand up the west site

    Drag in a router and a PC, cable the PC into Gi0/0, then name both and address the west LAN, 10.1.1.0/24. Every trace in this build starts at PC-West, so this is hop one.

    • Cable West Gi0/0 ↔ PC-West Eth0

    On West — Name the router and make Gi0/0 the west LAN's gateway

    enable
    configure terminal
    hostname West
    interface Gi0/0
    ip address 10.1.1.1 255.255.255.0
    no shutdown
    exit
    end

    On PC-West — Name the workstation, address it, and point it at its gateway

    hostname PC-West
    ipconfig Eth0 10.1.1.10 255.255.255.0 10.1.1.1

    Check: run show ip route on West and look for C 10.1.1.0/24 is directly connected, Gi0/0.

    Why: A trace starts at the sender, and its first hop is always the sender's default gateway: a packet for another subnet goes nowhere until PC-West can hand it to West.

  2. 2. Add the transit router — and teach it the way home

    Place a second router, draw a serial cable from West's Se0/0/0 to its Se0/0/0, and address the link as 10.0.12.0/30 — West .1, Core .2. Then give Core a route back to the west LAN and ping PC-West from Core to prove it.

    • Cable West Se0/0/0 ↔ Core Se0/0/0 (serial)

    On West — Take the west end of the first link, 10.0.12.1/30

    enable
    configure terminal
    interface Se0/0/0
    ip address 10.0.12.1 255.255.255.252
    no shutdown
    exit
    end

    On Core — Name the transit router, take the other end, and route home to the west LAN

    enable
    configure terminal
    hostname Core
    interface Se0/0/0
    ip address 10.0.12.2 255.255.255.252
    no shutdown
    exit
    ip route 10.1.1.0 255.255.255.0 10.0.12.1
    end
    ping 10.1.1.10

    Check: run show ip route on Core and look for S 10.1.1.0/24 via 10.0.12.1, Se0/0/0.

    Why: In a real traceroute every router along the path reports back to the SENDER, so each one needs a route to PC-West's network before it can appear in a trace at all. That is why every router in this chain gets its way home first, before anything points east.

  3. 3. Add the east site and the second link

    Place the third router and PC-East. Cable Core's Se0/0/1 to East's Se0/0/0 (serial, 10.0.23.0/30 — Core .1, East .2) and PC-East into East's Gi0/0 on the east LAN, 10.3.3.0/24. East gets its route home to the west LAN too.

    • Cable Core Se0/0/1 ↔ East Se0/0/0 (serial)
    • Cable East Gi0/0 ↔ PC-East Eth0

    On Core — Take Core's end of the second link, 10.0.23.1/30

    enable
    configure terminal
    interface Se0/0/1
    ip address 10.0.23.1 255.255.255.252
    no shutdown
    exit
    end

    On East — Name the far router, address its LAN and link, and route home to the west LAN

    enable
    configure terminal
    hostname East
    interface Gi0/0
    ip address 10.3.3.1 255.255.255.0
    no shutdown
    exit
    interface Se0/0/0
    ip address 10.0.23.2 255.255.255.252
    no shutdown
    exit
    ip route 10.1.1.0 255.255.255.0 10.0.23.1
    end

    On PC-East — Name the far workstation, address it, and point it at East

    hostname PC-East
    ipconfig Eth0 10.3.3.10 255.255.255.0 10.3.3.1

    Check: run show ip route on East and look for S 10.1.1.0/24 via 10.0.23.1, Se0/0/0.

    Why: The chain is three routers long, and every one of them knows the way back to the west LAN. Only East knows where 10.3.3.0/24 is — it is plugged into it — so a packet from PC-West toward the east still has nowhere to go: West holds no route for it.

  4. 4. Point West east — and watch the trace stop at Core

    Give West a route to the east LAN through Core, then run `traceroute 10.3.3.10` from PC-West and open the Console tab. The terminal only says whether the probe arrived; the Console lists every router it crossed: 'West → out Se0/0/0 via 10.0.12.2', then 'Core: no route to 10.3.3.10'. The trace stops at the first router with no route onward.

    On West — Send traffic for the east LAN to Core

    enable
    configure terminal
    ip route 10.3.3.0 255.255.255.0 10.0.12.2
    end

    On PC-West — Trace the path toward PC-East

    traceroute 10.3.3.10

    Check: run show ip route 10.3.3.10 on Core and look for % Network not in table.

    Why: A real traceroute sends probes with a TTL of 1, then 2, then 3: every router lowers the TTL by one, and the router that takes it to zero discards the probe and sends an ICMP Time Exceeded back, so the routers reveal themselves in order. Here West and Core would answer and Core would then report the network unreachable — the last router to answer is where the path breaks. NetForge sends a single probe and logs each router it crosses in the Console tab instead, which traces the same path.

  5. 5. Teach Core the east LAN and trace the whole path

    Add the missing route on Core and trace again. The Console now follows the probe all the way — West out Se0/0/0, Core out Se0/0/1, East out Gi0/0 — and ends with 'PC-West: reply from 10.3.3.10 (4 hops)': three routers and the destination, the four lines a real traceroute prints.

    On Core — Send traffic for the east LAN on to East

    enable
    configure terminal
    ip route 10.3.3.0 255.255.255.0 10.0.23.2
    end

    On PC-West — Trace the path again

    traceroute 10.3.3.10

    Check: run show ip route 10.3.3.10 on Core and look for * 10.0.23.2.

    Why: No router knows the whole path. Each one looks the destination up in its own table and hands the packet to its next hop, and the path is simply what those independent decisions add up to — which is why `show ip route 10.3.3.10` on each router, in order, retraces it by hand.

  6. 6. Break it with one wrong next hop

    One typo is enough to build a loop. Replace Core's route so its next hop is 10.0.12.1 — West — instead of East, and trace again: West hands the probe to Core, Core hands it straight back, and the Console reports 'West: routing loop detected'.

    On Core — Retype the east route with the wrong next hop, pointing back at West

    enable
    configure terminal
    no ip route 10.3.3.0 255.255.255.0 10.0.23.2
    ip route 10.3.3.0 255.255.255.0 10.0.12.1
    end

    On PC-West — Trace into the loop

    traceroute 10.3.3.10

    Check: run show ip route 10.3.3.10 on Core and look for * 10.0.12.1.

    Why: On real gear nothing referees a loop: the packet bounces between West and Core, losing one from its TTL at every hop, until the TTL reaches zero and a router discards it. That is exactly what TTL is for — and a traceroute through a loop prints the same two addresses over and over until it gives up. NetForge stops the probe the moment it arrives back at a router it has already crossed.

  7. 7. Fix the next hop and trace one last time

    Delete the looping route and put back the one that points at East, then trace a final time: four hops, with every router between the two PCs named in order in the Console tab.

    On Core — Replace the looping route with the one that points at East

    enable
    configure terminal
    no ip route 10.3.3.0 255.255.255.0 10.0.12.1
    ip route 10.3.3.0 255.255.255.0 10.0.23.2
    end

    On PC-West — Trace the repaired path

    traceroute 10.3.3.10

    Check: run show ip route static on Core and look for S 10.3.3.0/24 via 10.0.23.2, Se0/0/1.

    Why: A failed ping only says the path is broken somewhere; traceroute says where. That turns 'the network is down' into the name of one router and one routing table to read.

The theory behind it

Build it for real

The lab walks you through these steps and ticks each one off as your network starts working.

Open in the lab
Traceroute across three routers — step-by-step network lab · NetForge-AI