This exercise assumes nothing known in advance. We build a network from nothing: two computers, a switch, a router and an addressing plan. Every command is written out in full, alongside what should appear on the screen after it. At the end we slow the network down to the speed of thought and follow a single ping through each device.
1If you have never done this before
A computer network is made up of three kinds of thing. That is all. The whole rest of the course adds detail on top of this sketch.
| What | Its role, in one sentence | An everyday example |
|---|---|---|
| Hosts (PC, laptop, server, telephone) | They send and receive data. They are the reason the network exists. | The computer you are reading this page on. |
| Switch | Joins the hosts of the same network together and sends each message only to its recipient. | The clever multi-socket on the office wall. |
| Router | Joins different networks together. Without a router, one network cannot speak to another. | The box from your Internet provider at home. |
Two ways of working
You have a choice, and both variants are accepted for submission:
- The workbench in this page. Nothing to install. The equipment is simulated here, in the browser, with the same commands as on real hardware. Start straight from section 4.
- Cisco Packet Tracer, installed on your own computer. It is closer to reality, it has the visual simulation mode, and you will need it in the following laboratories. Installing it requires a free Cisco Networking Academy account.
.pkt file that is
submitted. The second time takes a quarter as long.2Equipment needed
The complete list for this exercise. In Packet Tracer the equipment is taken from the bottom bar: choose the category on the left first, then the model on the right, then click in the workspace.
| Qty | Equipment | Model | Packet Tracer category | What it is for here |
|---|---|---|---|---|
| 1 | Router | 4331 | Network Devices → Routers | joins the two networks |
| 2 | Switch | 2960 | Network Devices → Switches | joins the hosts of each network |
| 3 | Computer | PC-PT | End Devices → End Devices | the hosts PC0, PC1, PC2 |
| 1 | Server | Server-PT | End Devices → End Devices | the destination in the second network |
| 6 | Copper cable | Copper Straight-Through | Connections → Connections | every link in this exercise |
In addition, for yourselves: a notebook or a file in which to write the addressing plan and the answers, and about two hours.
Which cable, between which devices
The rule has a single idea: two devices of the same kind need a cable that swaps the wires; two devices of different kinds do not.
| Between | Cable | Why |
|---|---|---|
| PC ↔ switch | Copper Straight-Through | devices at different layers |
| switch ↔ router | Copper Straight-Through | different layers too |
| switch ↔ switch | Copper Cross-Over | the same layer |
| PC ↔ router, directly | Copper Cross-Over | the same layer |
FastEthernet0, for example) → click the second device → choose the port there too.
If no menu appears, you missed the device; press Esc and start again.3Five words, once and for all
The rest of the exercise uses these five notions at every step. Do not move on until they sound familiar.
192.168.1.10. It is like a postal address: whoever has none receives nothing.255.255.255.0, the first three groups are the street: 192.168.1.10 and
192.168.1.11 are neighbours, while 192.168.2.10 is on another
street.00D0.B0AB.0001. It does not change
and bears no relation to where the equipment is. Switches work with it alone.Reply from…,
communication works in both directions. It is the first thing any network engineer tries, for any
problem.4The first network: two computers
Before the complete topology, a network as small as it can be: two computers and a switch. Here you learn the mechanics - beyond this it is all repetition.
In the workbench below, click PC0, fill in the address 192.168.10.1 and the mask
255.255.255.0 in the right-hand panel, then press apply. Do the same for
PC1, with the address 192.168.10.2. Go back to PC0 and type in the terminal:
ping 192.168.10.2
enable, then
show mac address-table.Change PC1 address to 192.168.20.2, keeping the mask. Does the ping still work? Why?
See the answer
It no longer works. With the mask 255.255.255.0, the first three groups define the
network: 192.168.10.x and 192.168.20.x are two different networks. PC0 finds
that the destination is not on its street, looks for a gateway - and has none, so it gives up.
This is exactly why a router appears in the next section.
5The complete topology
The addressing plan
This is the table you fill in before touching any equipment. In practice, an addressing plan written in advance prevents more problems than any troubleshooting command.
| Device | Interface | IP address | Mask | Gateway |
|---|---|---|---|---|
| R1 | G0/0/0 | 192.168.1.1 | 255.255.255.0 | - |
| R1 | G0/0/1 | 192.168.2.1 | 255.255.255.0 | - |
| PC0 | Fa0 | 192.168.1.10 | 255.255.255.0 | 192.168.1.1 |
| PC1 | Fa0 | 192.168.1.11 | 255.255.255.0 | 192.168.1.1 |
| Server0 | Fa0 | 192.168.2.10 | 255.255.255.0 | 192.168.2.1 |
| PC2 | Fa0 | 192.168.2.11 | 255.255.255.0 | 192.168.2.1 |
| SW1, SW2 | - | - | - | - |
.1), and
the hosts receive addresses from .10 upwards. The first address of the block
(.0) is the network address, and the last (.255) is the broadcast address -
neither is given to a host.6The command line, in three minutes
Routers and switches have neither a screen nor a mouse. They are configured by typing commands into a console, in the Cisco IOS operating system. The console looks intimidating for two minutes, and then becomes the fastest tool you will ever use.
How to read the prompt
The text before the cursor always tells you which device you are on and in which mode. It is never typed by hand: the device displays it.
| Prompt | Mode | How you get there | What can be done |
|---|---|---|---|
Router> | user | on connecting | only a few display commands |
Router# | privileged | enable | every show command, saving, troubleshooting |
Router(config)# | global configuration | configure terminal | changes the device as a whole |
Router(config-if)# | interface configuration | interface G0/0/0 | changes a single interface |
You come back down with exit (one level) or end (straight to privileged mode).
conf t instead of configure terminal, int g0/0/0 instead of
interface gigabitEthernet 0/0/0, no shut instead of no shutdown.
All three work in the workbench in this page as well.% Invalid input detected at '^' marker. - the word under the ^ sign is wrong or
does not exist in the current mode.% Incomplete command. - the command is correct but unfinished; press ? to see what is
missing.% Ambiguous command - the abbreviation matches several commands; type one more letter.7Working steps
The workbench below holds the complete topology of figure 1, already cabled. Follow the steps in order; the list of objectives on the right ticks itself off as you progress.
- Build the topology Packet Tracer only
Place the two switches, the router, the three hosts and the server. Join them exactly as in figure 1, with
Copper Straight-Throughcable. Save the file aslab01_name.pktand get into the habit of saving often.Watch the colour of the cable ends: green means the link is up, red means the link has not come up, and amber, between two switches, means the port is going through the STP states and will turn green in about 30 seconds.
In the workbench in this page the topology is already cabled; go on to step 2.
- Configure the four hosts
In Packet Tracer: click PC0 → the Desktop tab → IP Configuration. In the workbench in this page: click PC0 → the Desktop → IP Configuration panel on the right. In both cases fill in the three fields from the addressing plan and repeat for PC1, PC2 and Server0.
Check, from Desktop → Command Prompt (or directly in the workbench terminal):
on PC0ipconfig ping 192.168.1.11
The second ping must work already: PC0 and PC1 are in the same network, and the switch joins them directly - the router plays no part here. The result looks like this:
what should appearPinging 192.168.1.11 with 32 bytes of data: Request timed out. Reply from 192.168.1.11: bytes=32 time<1ms TTL=128 Reply from 192.168.1.11: bytes=32 time<1ms TTL=128 Reply from 192.168.1.11: bytes=32 time<1ms TTL=128 Ping statistics for 192.168.1.11: Packets: Sent = 4, Received = 3, Lost = 1 (25% loss),The first packet is almost always lost. This is not a fault - it is ARP, and in step 8 you see exactly why.
- Configure the router
In Packet Tracer: click R1 → the CLI tab → press Enter. If it asks "Would you like to enter the initial configuration dialog?", answer
no. In the workbench in this page: click R1 and type straight into the terminal.Type the commands below line by line, pressing Enter after each. The prompt changes along the way - compare it with what you see at the left of each line:
the basic configuration of R1Router> enable Router# configure terminal Router(config)# hostname R1 R1(config)# no ip domain-lookup R1(config)# interface gigabitEthernet 0/0/0 R1(config-if)# description Link towards network A R1(config-if)# ip address 192.168.1.1 255.255.255.0 R1(config-if)# no shutdown R1(config-if)# exit R1(config)# interface gigabitEthernet 0/0/1 R1(config-if)# description Link towards network B R1(config-if)# ip address 192.168.2.1 255.255.255.0 R1(config-if)# no shutdown R1(config-if)# end R1# copy running-config startup-config
What each group of commands does:
Command Its effect enable+configure terminalopens the right to change the device hostname R1renames the router; from now on the prompt reads R1#interface …enters the configuration of a single physical interface ip address …gives the interface the gateway address of its network no shutdownbrings the interface up copy running-config startup-configsaves, so that the work survives a restart The two commands everybody forgetsno shutdown: the interfaces of a router are shut down by default, unlike those of a switch. Without this command, the interface has an address but is dead.
copy running-config startup-config: without it, all the work vanishes when the device restarts.running-configis the configuration in working memory;startup-configis the one read at boot.
no ip domain-lookupis not compulsory, but it spares you the 30-second wait that occurs whenever you mistype a command and IOS tries to resolve it through DNS. - Check the state of the interfaces
on R1
R1# show ip interface brief
You must see exactly this - both configured interfaces with
upin both columns:what should appearInterface IP-Address OK? Method Status Protocol GigabitEthernet0/0/0 192.168.1.1 YES manual up up GigabitEthernet0/0/1 192.168.2.1 YES manual up up GigabitEthernet0/0/2 unassigned YES unset administratively down down
The first status column refers to the physical layer (is there a signal on the wire?), the second to the line protocol (does the link actually work?). If you do not see this, the table below tells you what is missing:
What you see What it means What you do up / upall is well carry on administratively downno shutdownis missingre-enter the interface and issue no shutdowndown / downno signal missing cable, wrong end, or the device opposite is switched off up / downthere is a signal, but no protocol usually an encapsulation mismatch; rare in this exercise unassignedthe interface has no address you configured an interface other than the one that is cabled - Look at what the router knows about the world
on R1
R1# show ip route
Exactly two routes marked
C(directly connected networks) must appear, along with its own addresses markedL(local). The router knows only what is attached to it, and nobody has told it anything else. From laboratory 5 onwards we begin to tell it. - Test connectivity, in increasing order
on PC0
ping 192.168.1.1 ping 192.168.2.1 ping 192.168.2.10 tracert 192.168.2.10
The four commands rise in difficulty: one's own gateway, the far interface of the router, the server in the other network, then the complete path. If one of them fails, the problem is exactly between it and the previous one - it is the quickest way of locating a fault and you will use it all semester.
tracertmust show two hops: first192.168.1.1(the router), then192.168.2.10(the server). - Look at the ARP table of the host
on PC0
arp -a
You will see entries for
192.168.1.11(PC1, in the same network) and for192.168.1.1(the gateway). You will see nothing for192.168.2.10, although you have just pinged it successfully.Why the server does not appear in the ARP table Because PC0 never spoke to it directly. It sent the frames to the MAC address of the gateway, and from there the router took over. The destination IP address remained that of the server; the destination MAC address was, the whole time, that of R1. This is the rule of the two addresses, which you verify experimentally in the following section. - Look at the MAC table of the switch
on SW1
Switch> enable Switch# show mac address-table Switch# clear mac address-table dynamic Switch# show mac address-table
The first display shows a populated table, although nobody configured it: it filled itself from the traffic that passed through. After
clearit is empty. Issue a ping from PC0 and display it again - it fills up in less than a second.
8What a packet carries, segment by segment
This is the part for which the laboratory is worth doing. A ping from PC0 to Server0 crosses four links. On each of them, the packet carries a pair of IP addresses and a pair of MAC addresses. The question is: which of them change on the way?
In the workbench in this page
Issue the command ping 192.168.2.10 on PC0 and look at the Path of the last packet
table, which appears under the terminal. It has one row for each link crossed.
In Packet Tracer
- Switch from Realtime to Simulation, in the bottom right corner.
- Press Edit Filters, deselect everything and leave only ICMP and ARP ticked.
- From PC0 issue
ping 192.168.2.10, then press Capture / Forward step by step. - Click the envelope and then the Inbound PDU Details tab to read the addresses.
The order of events is always the same:
- The first packet is an ARP request, in broadcast: PC0 is looking for the MAC address of the gateway. Notice that the switch sends it out of every port.
- R1 answers with an ARP reply, this time unicast, only towards PC0.
- Only now does the ICMP echo request leave - the real ping.
- Follow the same packet after it leaves R1 on G0/0/1. The IP addresses are the same. The MAC addresses are completely different.
- Follow the reply all the way back to PC0.
Fill in the table below for the ICMP echo request packet, on each segment. It is one of the deliverables of the exercise:
| Segment | Source MAC | Destination MAC | Source IP | Destination IP |
|---|---|---|---|---|
| PC0 → SW1 | ||||
| SW1 → R1 | ||||
| R1 → SW2 | ||||
| SW2 → Server0 |
9Three faults to diagnose
Introduce each of the faults below deliberately, one at a time - in the workbench or in Packet Tracer. Before repairing, observe exactly what symptom it produces. In the following laboratories you will work the other way round: you will be given the symptom and will have to find the cause.
| Fault | How you produce it | Expected symptom | The command that reveals it |
|---|---|---|---|
| missing gateway | delete the gateway on PC0 | a ping inside its own network works, a ping to the other network gives Destination host unreachable | ipconfig on the host |
| shut-down interface | shutdown on G0/0/1 of R1 | PC0 reaches 192.168.1.1, but no further | show ip interface brief |
| wrong mask | set the mask 255.255.0.0 on PC2 | the ping from PC2 leaves, but the reply never comes back | ipconfig plus computing the network address |
In the workbench, the second fault is produced like this:
R1# configure terminal R1(config)# interface g0/0/1 R1(config-if)# shutdown R1(config-if)# end
…and the repair is the same command with no in front. Notice that the objective "PC0 reaches
Server0" goes out and comes back on by itself.
In the third fault, what exactly breaks the communication? PC2 has the address 192.168.2.11
with the mask 255.255.0.0.
See the answer
With the /16 mask, PC2 considers its network to be 192.168.0.0/16 - which includes
192.168.1.0/24 as well. When it wants to reply to PC0, it believes that PC0 is in the same
network and attempts a direct ARP for it, instead of sending the frame to the gateway. Nobody answers,
because PC0 lies beyond the router.
This is the perfect illustration of why the mask must be identical on every host of a segment: a different mask produces no visible error at configuration time, but an asymmetric and confusing behaviour much later.
10Assignments
- Build the topology of figure 1 and configure it completely, according to the addressing plan
- Obtain a successful ping from every host to every other host (12 tests)
- Fill in the table of MAC and IP addresses on the four segments
- Reproduce the three faults and note the symptom of each, in your own words
- Add a third network,
192.168.3.0/24, on interface G0/0/2 of R1, with a switch and two hosts; verify complete connectivity - Save the configurations and check with
show startup-config
11Going further
Remove the router from the topology and join the two switches directly with a crossover cable. The hosts
keep their addresses: 192.168.1.x on the left, 192.168.2.x on the right.
In the workbench you can do this from the Cables panel: take out the two cables of R1 and join SW1 directly to SW2.
Questions:
- Does the ping between PC0 and Server0 still work? Why?
- What happens if you change the mask of every host to
255.255.0.0? Explain the result. - What happens to a broadcast sent by PC0 now, compared with the initial topology?
- Is the solution of point 2 acceptable in a real network? Argue using the notion of broadcast domain.
12Self-check questions
13Deliverables
| Deliverable | Format | Weight |
|---|---|---|
| The Packet Tracer file with the complete, working topology | .pkt | 40 % |
| The table of MAC and IP addresses on the four segments | document | 20 % |
| The description of the three faults and of the symptoms observed | document | 20 % |
| The answers to the challenge, with argument | document | 20 % |
The .pkt file must also contain the third network required in the assignments, and the
configurations must be saved in startup-config.