Connect VLAN Branches with Static Routes
Secure two VLAN branches and connect them with IPv4 static routes.
Introduction
30 Second Summary
Each branch can work on its own while traffic between branches still fails. A simple test order helps you find the missing link quickly.
In this project, you will build two connected branches in Cisco Packet Tracer. You will use IPv4 static routes to make PC-A and PC-B communicate.
What You'll Build
You’ll open the saved lab and watch PC-A receive replies from PC-B across both branches.
By the end of this project, you'll have:
- Two working local branches where each PC reaches its gateway.
- A working router link between R1 and R2.
- End-to-end connectivity confirmed with pings in both directions.
- Secret Mission: Break PC-B’s VLAN assignment, find the fault, and repair it.
Are there any prerequisites?
You need Cisco Packet Tracer installed on Windows. Basic familiarity with Cisco IOS, IPv4 addresses, VLANs, and ping will help.
Before We Start
Before you begin, confirm what you are building and why the final connection test matters.
Set Up the Two-Branch Topology
A clear layout makes routing problems easier to spot. A wrong cable should never look like a routing failure.
In this step, you’ll build and save the two-branch layout in Cisco Packet Tracer.
In this step, get ready to:
- Place the six network devices.
- Label and connect the devices.
- Save the working topology.
Place and label the devices
- Select Network Devices in the bottom-left palette.
- Drag two Cisco 2911 routers into the workspace.
- Drag two Cisco Catalyst 2960 switches into the workspace.
- Select End Devices in the bottom-left palette.
- Drag two PC-PT devices into the workspace.
- Arrange them from left to right as PC, switch, router, router, switch, PC.
- Open each device’s Config tab and set the display names to PC-A, S1, R1, R2, S2, and PC-B from left to right.
You should see six clearly named devices in one line.
Connect the devices
Use these exact interfaces so the later Cisco IOS commands match your topology.
- Connect PC-A FastEthernet0 to S1 FastEthernet0/11 with a Copper Straight-Through cable.
- Connect an unused Gigabit Ethernet port on S1 to R1 GigabitEthernet0/0 with a Copper Straight-Through cable.
- Connect R1 GigabitEthernet0/1 to R2 GigabitEthernet0/1 with a Copper Cross-Over cable.
- Connect R2 GigabitEthernet0/0 to an unused Gigabit Ethernet port on S2 with a Copper Straight-Through cable.
- Connect S2 FastEthernet0/18 to PC-B FastEthernet0 with a Copper Straight-Through cable.
You should see five cable lines across the topology. Green indicators show active links, while amber indicators may take a few seconds to settle.
Is a cable wrong?
- Delete only the incorrect cable and reconnect the listed interfaces.
- Help me check my Packet Tracer cables.
Save and check the topology
- Click the save control in Packet Tracer’s top toolbar.
- Choose your Windows Desktop as the save location.
- Enter secure-two-branches.pkt as the filename.
- Keep Packet Tracer Activity File (*.pkt) as the file type.
- Confirm the save.
Before you check, do you expect to see six labels and five connected links?
- Read the six labels from left to right.
- Hover over each cable endpoint to confirm its interface.
- Check the title bar for secure-two-branches.pkt.
Your saved file should show PC-A, S1, R1, R2, S2, and PC-B joined by five links.
Your physical topology is ready. Next, you’ll secure the devices and bring both local branches online.
Secure the Devices and Bring VLANs Online
Your Cisco Packet Tracer topology is connected and saved. Now each branch needs a working local network.
You’ll apply a security baseline, create the correct VLANs, and test each PC against its local default gateway.
In this step, get ready to:
- Secure R1, R2, S1, and S2.
- Bring Branch A online through VLAN 10.
- Bring Branch B online through VLAN 20.
Secure the four devices
These passwords protect only this simulation. Never reuse class or cisco on a real device.
- Select R1 and open its CLI tab.
- Select No if the initial setup dialog appears.
- Enter privileged EXEC mode.
- Enter global configuration mode.
- Apply the R1 Cisco IOS security settings with this configuration:
hostname R1
enable secret class
service password-encryption
banner motd # Unauthorized access is strictly prohibited. #
line console 0
password cisco
login
What does this configure?
This gives R1 a clear hostname, protects privileged access, requires a console password, and displays a warning.
- Repeat the same configuration on R2 with hostname R2.
- Repeat the same configuration on S1 with hostname S1.
- Repeat the same configuration on S2 with hostname S2.
- Confirm that the four CLI prompts begin with R1, R2, S1, and S2.
Does a prompt still show the default name?
- Confirm that you entered global configuration mode before setting the hostname.
- Help me check the four device baselines.
Bring Branch A online
- Open S1’s CLI tab.
- Enter global configuration mode.
- Create VLAN 10 and assign PC-A’s port with this configuration:
vlan 10
name Faculty/Staff
interface f0/11
switchport mode access
switchport access vlan 10
What does this configure?
This creates VLAN 10 and places S1’s FastEthernet0/11 port inside it.
- Run this command from privileged EXEC mode to check S1:
show vlan brief
You should see Faculty/Staff as VLAN 10 with FastEthernet0/11 listed.
- Open R1’s CLI tab.
- Enter global configuration mode.
- Configure the Branch A router interface with these commands:
interface GigabitEthernet0/0
ip address 192.168.10.1 255.255.255.0
no shutdown
What does this configure?
R1 now uses 192.168.10.1 as Branch A’s gateway.
- Select PC-A and open Desktop.
- Open IP Configuration.
- Enter 192.168.10.10 in the IP Address field.
- Enter 255.255.255.0 in the Subnet Mask field.
- Enter 192.168.10.1 in the Default Gateway field.
- Open Command Prompt from PC-A’s Desktop.
Before you test, do you expect PC-A to reach its gateway?
- Test Branch A by running:
ping 192.168.10.1
You should receive replies from 192.168.10.1.
Can’t reach the Branch A gateway?
- Check PC-A’s address, mask, and gateway.
- Check that S1 lists FastEthernet0/11 under VLAN 10.
- Help me trace the Branch A failure.
Bring Branch B online
- Open S2’s CLI tab.
- Enter global configuration mode.
- Create VLAN 20 and assign PC-B’s port with this configuration:
vlan 20
name Students
interface FastEthernet0/18
switchport mode access
switchport access vlan 20
What does this configure?
This creates VLAN 20 and places S2’s FastEthernet0/18 port inside it.
- Run this command from privileged EXEC mode to check S2:
show vlan brief
You should see Students as VLAN 20 with FastEthernet0/18 listed.
- Open R2’s CLI tab.
- Enter global configuration mode.
- Configure the Branch B router interface with these commands:
interface GigabitEthernet0/0
ip address 192.168.20.1 255.255.255.0
no shutdown
What does this configure?
R2 now uses 192.168.20.1 as Branch B’s gateway.
- Select PC-B and open Desktop.
- Open IP Configuration.
- Enter 192.168.20.10 in the IP Address field.
- Enter 255.255.255.0 in the Subnet Mask field.
- Enter 192.168.20.1 in the Default Gateway field.
- Open Command Prompt from PC-B’s Desktop.
Before you test, do you expect PC-B to reach its gateway?
- Test Branch B by running:
ping 192.168.20.1
You should receive replies from 192.168.20.1. Both local branches are now working.
Can’t reach the Branch B gateway?
- Check PC-B’s address, mask, and gateway.
- Check that S2 lists FastEthernet0/18 under VLAN 20.
- Help me trace the Branch B failure.
Both PCs can reach their local routers. Next, you’ll connect R1 and R2 and expose the missing route between the branches.
Address the Transit Link and Expose the Routing Gap
Both local VLANs work in Cisco Packet Tracer. PC-A reaches R1, and PC-B reaches R2.
Now you’ll address the router-to-router link. Then you’ll test the full path and see why the branches still cannot communicate.
In this step, get ready to:
- Address the R1 and R2 transit interfaces.
- Test the router-to-router link.
- Expose the missing remote routes.
Address the transit interfaces
R1 and R2 need addresses in the same IPv4 subnet before they can exchange traffic.
- Open R1’s CLI tab.
- Reach the prompt ending in #.
- Configure R1’s transit interface with these commands:
configure terminal
interface GigabitEthernet0/1
ip address 10.0.0.1 255.255.255.248
no shutdown
end
show ip interface brief
What does this configure?
R1 uses 10.0.0.1 on GigabitEthernet0/1. The final command shows the address and interface state.
You should see 10.0.0.1 beside GigabitEthernet0/1.
- Open R2’s CLI tab.
- Reach the prompt ending in #.
- Configure R2’s transit interface with these commands:
configure terminal
interface GigabitEthernet0/1
ip address 10.0.0.5 255.255.255.248
no shutdown
end
show ip interface brief
How does R2 complete the link?
R2 uses 10.0.0.5 in the same 10.0.0.0/29 subnet as R1.
Packet Tracer may take a few seconds to turn the link green. You should then see 10.0.0.5 beside R2’s GigabitEthernet0/1.
Test the router link
The interface summaries show that the addresses exist. A ping proves that traffic crosses the cable.
- Return to R1’s privileged EXEC prompt.
- Test R2’s transit address by running:
ping 10.0.0.5
You should receive replies from 10.0.0.5.
- Return to R2’s privileged EXEC prompt.
- Test R1’s transit address by running:
ping 10.0.0.1
You should receive replies from 10.0.0.1.
Are the transit pings failing?
- Confirm that both transit interfaces use the mask 255.255.255.248.
- Confirm that both GigabitEthernet0/1 interfaces are enabled.
- Help me diagnose the transit link.
Expose the routing gap
The routers can now reach each other. The next test checks whether R1 knows how to forward traffic to Branch B.
- Select PC-A and open its Command Prompt.
Before you run the test, do you think PC-A can reach PC-B just because the routers can reach each other?
- Test PC-B’s address from PC-A by running:
ping 192.168.20.10
This failure is intentional
The ping should fail. This is the planned result because the routers do not yet know the remote branch networks.
- Open R1’s CLI tab.
- Inspect R1’s routing table by running:
show ip route
R1 should list Branch A and the transit subnet. It should not list 192.168.20.0/24.
- Open R2’s CLI tab.
- Run the same command on R2:
show ip route
R2 should list Branch B and the transit subnet. It should not list 192.168.10.0/24.
What did the tables prove?
Neither router has a path to the opposite branch. Reciprocal static routes will provide the missing destination and return paths.
- Save secure-two-branches.pkt with Packet Tracer’s save control.
The transit link works, and the failed PC ping now has a clear cause. Next, you’ll add the two missing static routes.
Add Static Routes and Prove Connectivity
Both local VLANs work, and R1 can reach R2. The failed PC test showed that each router is missing the remote branch.
You’ll add reciprocal static routes, confirm them in the routing tables, and test both directions.
In this step, get ready to:
- Add a remote route to each router.
- Check both routing tables.
- Prove and save end-to-end connectivity.
Add the two static routes
R1 needs a path to Branch B. R2 needs a return path to Branch A.
- Open R1’s CLI tab.
- Enter global configuration mode.
- Add R1’s route to Branch B by entering:
ip route 192.168.20.0 255.255.255.0 10.0.0.5 100
What does the R1 route do?
R1 sends traffic for 192.168.20.0/24 to R2 at 10.0.0.5. The route uses an administrative distance of 100.
- Return to privileged EXEC mode.
- Check R1’s installed static route by running:
show ip route static
You should see 192.168.20.0/24 through 10.0.0.5.
- Open R2’s CLI tab.
- Enter global configuration mode.
- Add R2’s route to Branch A by entering:
ip route 192.168.10.0 255.255.255.0 10.0.0.1
What does the R2 route do?
R2 sends traffic for 192.168.10.0/24 to R1 at 10.0.0.1. Cisco IOS uses the default static-route distance of 1.
- Return to privileged EXEC mode.
- Check R2’s installed static route by running:
show ip route static
You should see 192.168.10.0/24 through 10.0.0.1.
Is a static route missing?
- Confirm that you entered each route from global configuration mode.
- Confirm that R1 points to 10.0.0.5 and R2 points to 10.0.0.1.
- Help me check the two route commands.
Check both routing tables
- Display R1’s full routing table by running:
show ip route
Find the route marked S for 192.168.20.0/24 through 10.0.0.5.
- Display R2’s full routing table by running:
show ip route
Find the route marked S for 192.168.10.0/24 through 10.0.0.1.
What should the tables show?
The S marker confirms that each router installed its manually configured path.
Test and save the network
Before you test, do you expect the same failure or successful replies now that both routes exist?
- Open PC-A’s Command Prompt.
- Test PC-B by running:
ping 192.168.20.10
You should receive replies from 192.168.20.10.
- Open PC-B’s Command Prompt.
- Test PC-A by running:
ping 192.168.10.10
You should receive replies from 192.168.10.10. Both branches now communicate in either direction.
Is an end-to-end ping failing?
- Check each PC’s address and default gateway.
- Check that both routers still show their static routes.
- Check that the transit pings still succeed.
- Help me trace the failed end-to-end path.
- Return to R1’s privileged EXEC prompt.
- Save R1’s active configuration by running:
copy running-config startup-config
What does this save?
Press Enter if IOS asks for the destination filename. This copies the working settings into startup configuration.
- Run the same save command on R2.
- Run the same save command on S1.
- Run the same save command on S2.
- Save the Packet Tracer project as secure-two-branches.pkt.
Your saved network now carries traffic between both secured branches.
Secret mission
Break and Repair a VLAN Assignment
Break PC-B’s VLAN assignment, use local tests to find the fault, and restore connectivity.
Clean Up Your Resources
Clean Up Your Resources
This project uses one local Cisco Packet Tracer file, so there are no ongoing costs. Keep it, close it for later, or delete it.
Resources you used:
- Saved Packet Tracer project: secure-two-branches.pkt.
Keep everything running
No action is needed. Choose this if you want to practise with the network again.
- Keep secure-two-branches.pkt on your Desktop.
Pause - I'll come back to this later
Close Packet Tracer to free memory while keeping your saved work.
- Save secure-two-branches.pkt.
- Click the X in the upper-right corner of Packet Tracer.
- Confirm that the Packet Tracer window closes.
Delete - I don't want to use this again
This permanently removes the saved lab. Packet Tracer stays installed on your Windows computer.
- Close Packet Tracer.
- Press the Windows key.
- Type File Explorer.
- Press Enter.
- Open your Desktop folder.
- Select secure-two-branches.pkt.
- Press Shift+Delete.
- Confirm the permanent deletion.
You should no longer see secure-two-branches.pkt on your Desktop.
Nice Work!
Nice Work!
You did it! Your secure-two-branches.pkt project now connects two secured VLAN branches with reciprocal static routes in Cisco Packet Tracer.
You've learned how to:
- Build and cable a two-branch topology.
- Configure local VLAN connectivity for both PCs.
- Add and verify static routes between the branches.
- Secret Mission: Find and repair PC-B’s incorrect VLAN assignment.
Ready to quiz yourself?