A real-life situation
A company has its office network, LAN A, behind router R1, and its servers, LAN B, behind R4. Two routers sit in between, R2 and R3, so there are two ways from the office to the servers: over the top through R2, or along the bottom through R3. The second path was bought for one reason: if something on the first path breaks, traffic should keep flowing.
An engineer set the network up with static routes, all pointing over the top. One evening the cable between R2 and R4 is cut. The bottom path is perfectly healthy, but the office can't reach a single server until someone logs in and changes the routes by hand. This lesson explains why, and what OSPF does differently.
The network in this module
The three lessons in this module use the same four routers. Each router-to-router link is its own small subnet (a /30), and every router has a router ID (RID), which the next lessons explain.
- 1. Over the top: LAN A → R1 → R2 → R4 → LAN B. All the static routes point this way.
- 2. Along the bottom: LAN A → R1 → R3 → R4 → LAN B. A spare path, only useful if the routers use it when path 1 fails.
Where a router's routes come from
A router forwards a packet only if its routing table has a route that matches the destination; otherwise it drops the packet. Routes get into the table in three ways:
- Connected routes are added automatically for every subnet the router has an interface in. R1 knows LAN A (192.168.1.0/24) this way, but nothing about LAN B.
- Static routes are typed in by an engineer, one line per destination.
- Dynamic routes are learned from other routers through a routing protocol. R4 tells its neighbours "I am connected to 192.168.4.0/24", they pass that on, and R1 ends up with a route to LAN B that nobody typed.
Because R1 hears about LAN B over two paths, a routing protocol also has to choose: each protocol has a metric, a number that says how good a path is, and the path with the best metric goes into the routing table.
What static routes can and can't see
A static route is a line of configuration: "to reach 192.168.4.0/24, send packets to 10.0.12.2". On R1 it looks like this:
ip route 192.168.4.0 255.255.255.0 10.0.12.2On R1, global configuration mode: send traffic for LAN B to R2 (10.0.12.2). R2 and R4 need their own routes too.
The router keeps that route in its routing table for as long as it can reach the next hop through one of its own interfaces. In simple terms, a static route only notices a failure on the router's own link. If R1's Gi0/1 goes down, the route to 10.0.12.2 disappears and the static route is removed. If the failure is one hop further away, between R2 and R4, R1's interface stays up, 10.0.12.2 still answers, and R1 keeps sending everything to R2.
- 1. Before the failure: Every router follows its static route over the top, and LAN B answers.
- 2. The R2–R4 cable is cut. R2's Gi0/1 goes down, so R2 removes its static route for LAN B. R1 knows nothing about it: its own link to R2 is still up.
- 3. Traffic still goes to R2: R1's static route still points at 10.0.12.2. R2 has no route to 192.168.4.0/24 any more, so it drops the packets and sends back ICMP 'destination unreachable'.
- 4. The healthy path sits idle: R1 → R3 → R4 works, but no router has a route that uses it. An engineer has to change the routes by hand.
A floating static route (a backup route with a higher administrative distance) doesn't help here either. It only takes over when the main route leaves the routing table, and R1's main route is still there.
Static routes at scale
Even without failures, static routes become a lot of typing. Every router needs a route to every network it is not directly connected to. The four-router network above has six networks: two LANs and four router-to-router links.
| Router | Directly connected | Static routes needed |
|---|---|---|
| R1 | LAN A, 10.0.12.0/30, 10.0.13.0/30 | 3 |
| R2 | 10.0.12.0/30, 10.0.24.0/30 | 4 |
| R3 | 10.0.13.0/30, 10.0.34.0/30 | 4 |
| R4 | LAN B, 10.0.24.0/30, 10.0.34.0/30 | 3 |
| Total | 14 | |
Fourteen routes for four routers is manageable. A network of 40 routers and 200 subnets needs thousands, and every new subnet means visiting every router. Each one is a chance for a typing mistake, and a mistake in a static route usually shows up as a routing loop or a black hole that is hard to trace.
What a dynamic routing protocol does instead
With a routing protocol such as OSPF, the routers do the work themselves. They:
- find their neighbours: other routers on the same links running the same protocol;
- share what they know: which networks they are connected to and how good each link is;
- pick the best path to every network using a metric (OSPF uses cost);
- notice failures anywhere in the network, not only on their own links;
- recalculate and switch to another path without anyone logging in;
- learn new networks as soon as they are added on any router.
The time from a change (a link failing, a router rebooting) until every router agrees again on the best paths is called convergence. Fast convergence is the main reason networks run a routing protocol at all.
- 1. Before the failure: OSPF has chosen the path over the top as the best one.
- 2. R2 and R4 report the failure: Both routers see their link go down and immediately send an update describing the change to their other neighbours, who pass it on.
- 3. Every router recalculates: Each router now has the same updated view of the network and works out new best paths. Typically this takes well under a second.
- 4. Traffic takes the bottom path: R1 now sends traffic for LAN B to R3. Nobody touched the configuration.
Why it works this way
A static route is a fixed instruction about the next hop only. The router has no information about the rest of the path, so it can't know when a link two hops away has failed. A routing protocol exists to give routers that missing information: each router tells the others about its links, so a failure anywhere is reported everywhere.
That information costs something: CPU and memory to run the protocol, and a little bandwidth for the messages. That trade-off is why many networks use both. OSPF runs between the core routers, and a single static default route points out to the ISP, where there is only one way out anyway.
Static or dynamic?
| Question | Static routes | OSPF |
|---|---|---|
| Configuration effort | One line per network, on every router | A few lines per router, then automatic |
| Reacts to a remote failure | No | Yes, usually in under a second |
| Uses a second path | Only for local failures, with a floating static | Yes, automatically |
| New network added | Every router must be updated by hand | Learned automatically |
| Router resources | None | Some CPU, memory and bandwidth |
| Best for | Default route to an ISP, stub networks with one exit | Any network with several routers or paths |
Two ways to group routing protocols
By where they run. An autonomous system (AS) is a network under one organisation's control. An interior gateway protocol (IGP) such as OSPF, EIGRP, IS-IS or RIP shares routes inside one AS. An exterior gateway protocol (EGP) shares routes between different organisations; today that is only BGP. ("Gateway" is the old word for a router.)
By how they learn. This is the difference that explains how OSPF behaves:
| Distance-vector (RIP) | Link-state (OSPF, IS-IS) | |
|---|---|---|
| What a router shares | Its routes: "network X, this far, via me" | Its links: "I am R4, connected to these subnets and these neighbours, at this cost" |
| Who receives it | Direct neighbours only, who pass on their own version | Every router in the area, unchanged (flooding) |
| What each router knows | The next hop and distance for each network, not the path beyond | A full map of the area, from which it works out every path itself |
| When it sends updates | RIP: the whole table every 30 seconds | When something changes, plus a refresh every 30 minutes |
| Best-path calculation | Bellman-Ford | Dijkstra's shortest path first (SPF) |
| Convergence | Slow, with a risk of temporary loops ("counting to infinity") | Fast, because every router sees the change directly |
| Cost of running it | Little CPU and memory | More CPU and memory; large networks are split into areas |
A simple way to picture the difference: a distance-vector router follows signposts ("LAN B, 3 hops, that way"), while a link-state router carries a map and plans the route itself. EIGRP sits in between. It shares routes with neighbours like a distance-vector protocol but adds features such as backup routes kept ready in advance, so it is often called an advanced distance-vector or hybrid protocol.
Why OSPF and not another protocol?
The CCNA compares these protocols briefly; OSPF is the one you configure.
- RIP counts hops only, so a slow link with one hop beats a fast link with two. It allows at most 15 hops and converges slowly. It is mostly found in labs and very old networks.
- EIGRP converges fast and was developed by Cisco. Its basic form was published in 2016 (RFC 7868), but in practice it runs almost only on Cisco equipment.
- OSPF is an open standard (RFC 2328 for IPv4), so routers and firewalls from different vendors can share routes. It converges quickly, chooses paths by link speed, and scales to large networks by splitting them into areas.
- BGP connects separate organisations across the internet. It is covered in Where BGP fits.
💡 Exam tip: expect questions that ask what happens when a link beyond the next hop fails on a statically routed network. The answer is that the static route stays in the table and traffic is dropped further along. Also know that a floating static route needs a higher administrative distance than the route it backs up.
Common mistakes
- Assuming a static route is removed when any link on the path fails. Only a failure of the router's own exit stops it.
- Expecting a floating static route to cover a remote failure. It only replaces a route that has left the table.
- Thinking dynamic routing replaces static routes entirely. A static default route to the ISP is still normal.
- Calling OSPF a Cisco protocol. It is an open IETF standard; EIGRP is the one that came from Cisco.
Key takeaways
- A static route only knows its next hop, so it can't react to failures further along the path.
- Every router needs a static route to every network it is not connected to; that grows fast.
- A routing protocol finds neighbours, shares links, picks best paths and reroutes after failures.
- Convergence is the time until every router agrees on the best paths again.
- OSPF is an interior, link-state protocol: every router gets a full map and calculates its own paths.
- OSPF is the open-standard choice for enterprise networks and the protocol the CCNA has you configure.
Check yourself
R1 reaches LAN B with ip route 192.168.4.0 255.255.255.0 10.0.12.2 (R2). The link between R2 and R4 fails; R1's link to R2 stays up. What does R1 do with traffic for LAN B?
How many static routes does R2 need in the four-router network, if it must reach every network?
What does 'convergence' mean in routing?
A branch office has one router and a single link to head office. Which is the most sensible choice?
A router running a link-state protocol learns about a new subnet. What did it receive?
Which statement about OSPF is true?