Open the lab
[ YOUR LAB FILE ]
Download the starting topology, then work through the lesson in SwitchLab.
- Save the .swlab file without renaming its extension.
- Open SwitchLab. Import and export controls currently require a desktop-width window. On a smaller screen, Tools → Fit brings the topology into view.
- Select Import Sandbox (folder icon), choose the downloaded file, and confirm the device and cable counts below.
- Select a device, then choose Open device on desktop or its name in the bottom bar on smaller screens. Select CLI for switches/routers or Desktop → Terminal for PCs. Enter
enableonly when the prompt ends in >. - Follow this page beside the simulator. Use a free account to export your work. Reimport the original download to restart; export any work you want to keep first.
Prerequisites
- Complete the focused lessons for the features used in this scenario.
- For campus policy scenarios, complete VLANs, trunks, IPv4, OSPF and ACL lessons first.
Topology

4 devices · 3 links
Scenario
A maintenance script changed a static route and disabled the remote user interface. The transit is still up. Recover the branch without replacing the correct host settings or return route.
Objectives
- Implement or restore the approved network design without breaking required control paths.
- Verify configuration, end-to-end behavior and completed-network persistence.
- Produce an operational handoff with evidence and a deterministic reset path.
CCNA blueprint
200-301 v1.1 objectives — this lab covers the following specific skills, not every subtopic in the domain.
- 1.6 — Apply and verify the scenario’s IPv4 addressing.
- 3.3 — Repair an IPv4 static route and its forwarding path.
Starting information
- PC1 uses 10.10.10.0/24 through R1 g0/0=10.10.10.1; PC2 is 10.20.20.20/24 through R2 g0/0=10.20.20.1.
- The g0/1 transit is 10.0.12.1/30 on R1 and 10.0.12.2/30 on R2. Preserve all cables and router addresses.
| Host | IPv4 address | Mask | Gateway |
|---|---|---|---|
| PC1 | 10.10.10.10 | 255.255.255.0 | 10.10.10.1 |
| PC2 | 10.20.20.20 | 255.255.255.0 | 10.20.20.1 |
| Router | Interface | IPv4 address | Mask |
|---|---|---|---|
| R1 | g0/0 | 10.10.10.1 | 255.255.255.0 |
| R1 | g0/1 | 10.0.12.1 | 255.255.255.252 |
| R2 | g0/0 | 10.20.20.1 | 255.255.255.0 |
| R2 | g0/1 | 10.0.12.2 | 255.255.255.252 |
| Device / port | Device / port |
|---|---|
| PC1 / eth0 | R1 / g0/0 |
| R1 / g0/1 | R2 / g0/1 |
| PC2 / eth0 | R2 / g0/0 |
Tasks
- Compare both routers’ interface and route output with the cable/address plan.
- Identify the forwarding and destination-interface faults; explain why correcting only one cannot restore the service.
- Apply the smallest two repairs, then test each host’s local gateway and both intersite directions.
- Save/export/reload and document the fault-to-evidence mapping for the incident handoff.
Useful commands
show ip interface brief
show ip route
show running-config
copy running-config startup-configProgressive hints
Hint 1
Break the end-to-end path into host settings, local VLAN carriage, gateway reachability, route selection and any access policy.
Hint 2
Use a working control at each layer. Do not remove security controls or add broad routes just to make one ping succeed.
Hint 3
Compare each affected host, interface and route against the approved plan; use the earlier focused lessons for the exact command patterns.
Verification
- The final network matches every approved addressing, VLAN, routing and policy requirement above.
- Every required positive path succeeds and every forbidden path remains blocked.
- Completed export/reload retains the result; reimporting the starter restores the original exercise.
Solution / walkthrough
Show Solution
Use enable only from a > prompt; if already at #, begin with configure terminal.
R1
Use the actually connected peer as next hop.
enable
configure terminal
no ip route 10.20.20.0 255.255.255.0 10.0.12.99
ip route 10.20.20.0 255.255.255.0 10.0.12.2
end
copy running-config startup-configR2
Restore the destination LAN interface; a correct route cannot deliver to a disabled LAN.
enable
configure terminal
interface g0/0
no shutdown
end
copy running-config startup-configRun every verification check above after the changes. A saved configuration alone does not prove packet delivery.