Guided buildstarter7 steps~12 min3 devices
Two LANs, one router
Put a PC on each of two different subnets and make them talk through a router.
What you'll be able to do: Two PCs on different networks ping each other through a router, and you can point at the two things that made it possible: the router's leg in each subnet, and each PC's default gateway.
Topics: IPv4 addressing · Subnets · Default gateway · Routing
What you'll build
- Edge — a router, the router with one leg in each LAN
- PC-A — a pc, a workstation on the 192.168.10.0/24 LAN
- PC-B — a pc, a workstation on the 192.168.20.0/24 LAN
Step by step
1. Place the router and name it
Drag a router onto the canvas. A router is the only device here that can move traffic between two different networks, so it goes down first and everything else hangs off it. Naming it now means every prompt you type at afterwards tells you which box you are on.
On Edge — Enter privileged mode, then configuration mode, and set the hostname
enable configure terminal hostname Edge endWhy: The CLI separates looking from changing with modes: `>` is user mode with a small set of harmless commands, `#` is privileged mode where the full set of show commands lives, and `(config)#` is the only place a change can be made. The hostname is written into the running configuration and shown in every prompt, so the prompt always tells you which box you are on and what you are allowed to do there.
2. Add the first PC and cable it to the router
Drop a PC on the canvas and run a copper cable from its Eth0 port to the router's Gi0/0 port. Everything plugged into Gi0/0 shares one network, so treat that port as the first LAN from here on.
- Cable PC-A Eth0 ↔ Edge Gi0/0
On PC-A — Name the workstation — a PC has no enable mode, so type straight into the shell
hostname PC-AWhy: Every router interface is the edge of its own network: a router does not pass broadcasts from one port to another, so each port bounds a separate broadcast domain. That is the physical reason each router port gets its own subnet, and why the two LANs on this router will need different address ranges.
3. Give the first LAN its gateway address
Address the router's Gi0/0 leg as 192.168.10.1/24. This address is the gateway every host on that LAN will point at, which is why it is conventional to take the first usable address in the subnet. Router ports start administratively down, so `no shutdown` is part of the job, not an afterthought.
On Edge — Address the Gi0/0 leg and bring it up
enable configure terminal interface GigabitEthernet0/0 description LAN-A ip address 192.168.10.1 255.255.255.0 no shutdown endCheck: run
show ip interface briefon Edge and look forGi0/0 192.168.10.1 YES manual up up.Why: A router only uses an interface that is up at both layers: the port must be enabled and see a signal, and the link above it must be working. Until Status and Protocol both read up, the router installs no connected route for the subnet on that port, so an address on a dead port is invisible to routing.
4. Address PC-A and point it at the gateway
Give PC-A an address inside the same /24 and tell it where to send anything that is not on its own wire. A host compares the destination with its own network address first: same network means speak directly, different network means hand the frame to the default gateway. Ping the gateway to prove the first LAN works.
On PC-A — Set the address, the default gateway, then test the local hop
ip address add 192.168.10.10/24 dev Eth0 ip route add default via 192.168.10.1 ping 192.168.10.1Check: run
ip address show dev Eth0on PC-A and look forinet 192.168.10.10/24.Why: A host keeps a routing table too, just a very short one: the address and prefix create a route for its own subnet, and the default gateway adds a line that matches everything else. The more specific entry always wins, so traffic for the host's own subnet goes straight onto the wire and only the rest is handed to the router.
5. Add a PC on a second network and watch the ping fail
Place the second PC, cable it to Gi0/1, and address it as 192.168.20.10/24 — a different network address, which is the whole exercise. Leave its default gateway off for now, and leave Gi0/1 unaddressed. The ping from PC-A fails because the router has no leg in 192.168.20.0/24 yet, so it has nowhere to forward the packet.
- Cable PC-B Eth0 ↔ Edge Gi0/1
On PC-B — Name the second workstation and address it on the other network
hostname PC-B ip address add 192.168.20.10/24 dev Eth0On PC-A — Try to reach the other subnet before any routing exists
ping 192.168.20.10Check: run
ip route showon PC-B and look for192.168.20.0/24 dev Eth0.Why: A router forwards by looking the destination up in its routing table, and its knowledge starts with connected routes — one per addressed interface that is up. With Gi0/1 unaddressed and shut, 192.168.20.0/24 appears nowhere in Edge's table, so a packet for PC-B matches nothing and Edge drops it.
6. Give the router its second leg
Address Gi0/1 as 192.168.20.1/24 and bring it up. The router now has an interface in each network, so both appear in its routing table as connected routes — and a device with a route to two networks can move traffic between them. Ping the new gateway from PC-B to confirm the second LAN is alive.
On Edge — Address the Gi0/1 leg and bring it up
enable configure terminal interface GigabitEthernet0/1 description LAN-B ip address 192.168.20.1 255.255.255.0 no shutdown endOn PC-B — Confirm PC-B can reach its own gateway
ping 192.168.20.1Check: run
show ip routeon Edge and look forC 192.168.20.0/24 is directly connected, Gi0/1.Why: Routing between two connected networks needs no route statements: both have C entries, so a packet arriving on one leg is matched against the table and sent out of the other. At each hop the router strips the incoming Ethernet frame and builds a new one for the outgoing link — the MAC addresses change hop by hop, while the IP source and destination travel end to end.
7. Give PC-B its default gateway
PC-A still cannot reach PC-B, and the router is no longer the reason. PC-B receives the echo request, but its reply is addressed to a network it holds no route to, so it is dropped before it leaves the host. Point PC-B at 192.168.20.1 and the round trip completes in both directions.
On PC-B — Give the host a way off its own wire, then test the full path
ip route add default via 192.168.20.1 ping 192.168.10.10On PC-A — Ping back across the router
ping 192.168.20.10 traceroute 192.168.20.10Check: run
ip route showon PC-B and look fordefault via 192.168.20.1 dev Eth0.Why: Reachability is two one-way trips, and each is decided by whichever host or router is sending at that moment. A host with no gateway can receive traffic from another network but cannot answer it, so the symptom appears at the far end — PC-A sees its ping time out — while the fault lives on PC-B.
The theory behind it
More in Foundations
- One router, one PC, one ping — Build the smallest network that works: address a router and a PC on the same subnet and get a reply back.
- Three hosts, one switch — Put three PCs on a single subnet through an unconfigured switch and watch it learn who lives where.
- ARP and MAC learning, side by side — Watch a host's ARP cache and a switch's MAC table fill from the very first frame — and see why a host never ARPs for anything beyond its gateway.
- VLSM for two sites — Carve one /24 into a /26, a /27 and a /30 sized to what each site needs, then route between them with masks that match the plan.
- A stub branch and one default route — Send everything a branch can't place to HQ with a single default route, and see why HQ still needs a specific route back for every branch network.
- Traceroute across three routers — Chain three routers with static routes and follow a packet hop by hop — then watch a trace stop at a missing route and circle in a routing loop.
Build it for real
The lab walks you through these steps and ticks each one off as your network starts working.
Open in the lab