Guided buildcore7 steps~25 min5 devices
Traceroute across three routers
Chain three routers with static routes and follow a packet hop by hop — then watch a trace stop at a missing route and circle in a routing loop.
What you'll be able to do: A three-router chain where a trace from one PC to the other names every router in order — and the habit of reading where a failing path stops, whether at a missing route or in a loop.
Topics: Traceroute · Static routing · Routing tables · Routing loops
What you'll build
- West — a router, the router at the west site, where every trace starts
- Core — a router, the transit router in the middle of the chain
- East — a router, the router at the east site
- PC-West — a pc, the workstation you run traceroute from
- PC-East — a pc, the workstation at the far end of the chain
Step by step
1. Stand up the west site
Drag in a router and a PC, cable the PC into Gi0/0, then name both and address the west LAN, 10.1.1.0/24. Every trace in this build starts at PC-West, so this is hop one.
- Cable West Gi0/0 ↔ PC-West Eth0
On West — Name the router and make Gi0/0 the west LAN's gateway
enable configure terminal hostname West interface Gi0/0 ip address 10.1.1.1 255.255.255.0 no shutdown exit endOn PC-West — Name the workstation, address it, and point it at its gateway
hostname PC-West ipconfig Eth0 10.1.1.10 255.255.255.0 10.1.1.1Check: run
show ip routeon West and look forC 10.1.1.0/24 is directly connected, Gi0/0.Why: A trace starts at the sender, and its first hop is always the sender's default gateway: a packet for another subnet goes nowhere until PC-West can hand it to West.
2. Add the transit router — and teach it the way home
Place a second router, draw a serial cable from West's Se0/0/0 to its Se0/0/0, and address the link as 10.0.12.0/30 — West .1, Core .2. Then give Core a route back to the west LAN and ping PC-West from Core to prove it.
- Cable West Se0/0/0 ↔ Core Se0/0/0 (serial)
On West — Take the west end of the first link, 10.0.12.1/30
enable configure terminal interface Se0/0/0 ip address 10.0.12.1 255.255.255.252 no shutdown exit endOn Core — Name the transit router, take the other end, and route home to the west LAN
enable configure terminal hostname Core interface Se0/0/0 ip address 10.0.12.2 255.255.255.252 no shutdown exit ip route 10.1.1.0 255.255.255.0 10.0.12.1 end ping 10.1.1.10Check: run
show ip routeon Core and look forS 10.1.1.0/24 via 10.0.12.1, Se0/0/0.Why: In a real traceroute every router along the path reports back to the SENDER, so each one needs a route to PC-West's network before it can appear in a trace at all. That is why every router in this chain gets its way home first, before anything points east.
3. Add the east site and the second link
Place the third router and PC-East. Cable Core's Se0/0/1 to East's Se0/0/0 (serial, 10.0.23.0/30 — Core .1, East .2) and PC-East into East's Gi0/0 on the east LAN, 10.3.3.0/24. East gets its route home to the west LAN too.
- Cable Core Se0/0/1 ↔ East Se0/0/0 (serial)
- Cable East Gi0/0 ↔ PC-East Eth0
On Core — Take Core's end of the second link, 10.0.23.1/30
enable configure terminal interface Se0/0/1 ip address 10.0.23.1 255.255.255.252 no shutdown exit endOn East — Name the far router, address its LAN and link, and route home to the west LAN
enable configure terminal hostname East interface Gi0/0 ip address 10.3.3.1 255.255.255.0 no shutdown exit interface Se0/0/0 ip address 10.0.23.2 255.255.255.252 no shutdown exit ip route 10.1.1.0 255.255.255.0 10.0.23.1 endOn PC-East — Name the far workstation, address it, and point it at East
hostname PC-East ipconfig Eth0 10.3.3.10 255.255.255.0 10.3.3.1Check: run
show ip routeon East and look forS 10.1.1.0/24 via 10.0.23.1, Se0/0/0.Why: The chain is three routers long, and every one of them knows the way back to the west LAN. Only East knows where 10.3.3.0/24 is — it is plugged into it — so a packet from PC-West toward the east still has nowhere to go: West holds no route for it.
4. Point West east — and watch the trace stop at Core
Give West a route to the east LAN through Core, then run `traceroute 10.3.3.10` from PC-West and open the Console tab. The terminal only says whether the probe arrived; the Console lists every router it crossed: 'West → out Se0/0/0 via 10.0.12.2', then 'Core: no route to 10.3.3.10'. The trace stops at the first router with no route onward.
On West — Send traffic for the east LAN to Core
enable configure terminal ip route 10.3.3.0 255.255.255.0 10.0.12.2 endOn PC-West — Trace the path toward PC-East
traceroute 10.3.3.10Check: run
show ip route 10.3.3.10on Core and look for% Network not in table.Why: A real traceroute sends probes with a TTL of 1, then 2, then 3: every router lowers the TTL by one, and the router that takes it to zero discards the probe and sends an ICMP Time Exceeded back, so the routers reveal themselves in order. Here West and Core would answer and Core would then report the network unreachable — the last router to answer is where the path breaks. NetForge sends a single probe and logs each router it crosses in the Console tab instead, which traces the same path.
5. Teach Core the east LAN and trace the whole path
Add the missing route on Core and trace again. The Console now follows the probe all the way — West out Se0/0/0, Core out Se0/0/1, East out Gi0/0 — and ends with 'PC-West: reply from 10.3.3.10 (4 hops)': three routers and the destination, the four lines a real traceroute prints.
On Core — Send traffic for the east LAN on to East
enable configure terminal ip route 10.3.3.0 255.255.255.0 10.0.23.2 endOn PC-West — Trace the path again
traceroute 10.3.3.10Check: run
show ip route 10.3.3.10on Core and look for* 10.0.23.2.Why: No router knows the whole path. Each one looks the destination up in its own table and hands the packet to its next hop, and the path is simply what those independent decisions add up to — which is why `show ip route 10.3.3.10` on each router, in order, retraces it by hand.
6. Break it with one wrong next hop
One typo is enough to build a loop. Replace Core's route so its next hop is 10.0.12.1 — West — instead of East, and trace again: West hands the probe to Core, Core hands it straight back, and the Console reports 'West: routing loop detected'.
On Core — Retype the east route with the wrong next hop, pointing back at West
enable configure terminal no ip route 10.3.3.0 255.255.255.0 10.0.23.2 ip route 10.3.3.0 255.255.255.0 10.0.12.1 endOn PC-West — Trace into the loop
traceroute 10.3.3.10Check: run
show ip route 10.3.3.10on Core and look for* 10.0.12.1.Why: On real gear nothing referees a loop: the packet bounces between West and Core, losing one from its TTL at every hop, until the TTL reaches zero and a router discards it. That is exactly what TTL is for — and a traceroute through a loop prints the same two addresses over and over until it gives up. NetForge stops the probe the moment it arrives back at a router it has already crossed.
7. Fix the next hop and trace one last time
Delete the looping route and put back the one that points at East, then trace a final time: four hops, with every router between the two PCs named in order in the Console tab.
On Core — Replace the looping route with the one that points at East
enable configure terminal no ip route 10.3.3.0 255.255.255.0 10.0.12.1 ip route 10.3.3.0 255.255.255.0 10.0.23.2 endOn PC-West — Trace the repaired path
traceroute 10.3.3.10Check: run
show ip route staticon Core and look forS 10.3.3.0/24 via 10.0.23.2, Se0/0/1.Why: A failed ping only says the path is broken somewhere; traceroute says where. That turns 'the network is down' into the name of one router and one routing table to read.
The theory behind it
More in Foundations
- One router, one PC, one ping — Build the smallest network that works: address a router and a PC on the same subnet and get a reply back.
- Three hosts, one switch — Put three PCs on a single subnet through an unconfigured switch and watch it learn who lives where.
- ARP and MAC learning, side by side — Watch a host's ARP cache and a switch's MAC table fill from the very first frame — and see why a host never ARPs for anything beyond its gateway.
- Two LANs, one router — Put a PC on each of two different subnets and make them talk through a router.
- VLSM for two sites — Carve one /24 into a /26, a /27 and a /30 sized to what each site needs, then route between them with masks that match the plan.
- A stub branch and one default route — Send everything a branch can't place to HQ with a single default route, and see why HQ still needs a specific route back for every branch network.
Build it for real
The lab walks you through these steps and ticks each one off as your network starts working.
Open in the lab