IP Connectivity
IP connectivity is the largest domain on the 200-301 exam. It is about how routers choose a path and forward packets: the structure of the routing table, how a router breaks ties with longest-prefix match and administrative distance, how to configure static and default routes, and how OSPFv2 dynamically discovers paths. Expect configuration and verification questions and OSPF cost calculations, all of which this chapter works through with concrete numbers.
The Routing Table and Longest Prefix Match
A router forwards each packet by consulting its routing table (the RIB) for the destination IP address. Entries are learned three ways and each is coded in "show ip route": C for directly connected, L for a local /32 host route to the interface itself, S for static, and O for OSPF (D for EIGRP, B for BGP). A directly connected route appears the moment an interface is configured with an IP and comes up. The single most important rule is longest-prefix match. When several routes could match a destination, the router always uses the most specific one — the entry with the longest prefix (largest mask) — regardless of administrative distance or metric. Administrative distance and metric only ever break ties between routes that have the same prefix length. Worked example: a packet is destined for 10.1.1.55 and the table holds 10.1.1.0/24 via R2, 10.1.0.0/16 via R3, and a default 0.0.0.0/0 via R4. All three technically "match," but /24 is longer than /16, which is longer than /0, so the router forwards to R2. The default route (0.0.0.0/0), shown as the "gateway of last resort," is used only when nothing more specific matches at all. This is why summarization and specific routes coexist safely: a specific /32 host route will always beat a broad summary. When you troubleshoot reachability, read the routing table the way the router does — find the longest match for the exact destination, note the next hop and exit interface, and confirm that route actually points where you expect. "show ip route 10.1.1.55" tells you precisely which entry the router will use, taking the guesswork out of path selection.
Administrative Distance and Metrics
When a router learns the same prefix from more than one routing source, it must decide which to trust. Administrative distance (AD) is that trust rating: a lower AD is more believable and its route is installed in the routing table. The values to memorize are: directly connected 0, static route 1, external BGP 20, EIGRP (internal) 90, OSPF 110, RIP 120, external EIGRP 170, and internal BGP 200. A route with AD 255 is considered unreachable and is never installed. So if a destination is learned by both OSPF (AD 110) and a static route (AD 1) with the same prefix length, the static route wins because 1 is less than 110. This is exactly how a floating static route works: you deliberately give a backup static route a high AD (say 130) so it stays out of the table while OSPF's route is present, and it only "floats" in when OSPF withdraws its route. Metric is a different, lower-level decision. Once AD has chosen a routing source, the metric compares multiple routes to the same prefix learned by that one protocol and picks the lowest. Each protocol computes metric differently: OSPF uses cost (derived from bandwidth), RIP uses hop count, and EIGRP uses a composite of bandwidth and delay. If a protocol finds two equal-metric paths, it can install both and load-balance (equal-cost multipath). Keep the two ideas separate on the exam: AD chooses between different protocols/sources, metric chooses between routes within the same protocol, and both only matter after longest-prefix match has narrowed the field to routes of the same prefix length. A quick sanity check for any "which route is installed" question is to ask, in order: longest prefix first, then lowest AD, then lowest metric.
Static and Default Routing
Static routes are manually configured entries, ideal for small or stub networks and for predictable, controlled paths. The command is: ip route <destination-network> <subnet-mask> <next-hop-IP | exit-interface>. For example, "ip route 192.168.2.0 255.255.255.0 10.0.0.2" tells the router to reach the 192.168.2.0/24 network via next hop 10.0.0.2. You may specify a next-hop IP, an exit interface, or both; on point-to-point links an exit interface alone is common, while on multi-access links (Ethernet) specifying the next-hop IP (or both) avoids recursive-lookup and ARP problems. A default route matches everything: "ip route 0.0.0.0 0.0.0.0 <next-hop>." It is the quad-zero route used when no more specific entry matches, typically pointing to the ISP or a core router. A default route is what makes a stub site reachable to the whole Internet with a single line. A host route is a /32 static (mask 255.255.255.255) that matches exactly one address — occasionally used for policy or a specific server. IPv6 uses the same idea with "ipv6 route 2001:db8:2::/64 2001:db8:1::2" and a default of "ipv6 route ::/0 <next-hop>." The floating static route deserves special mention: add an AD value at the end, e.g. "ip route 192.168.2.0 255.255.255.0 10.0.0.6 130." Because 130 is higher than OSPF's 110, this route is dormant until the primary route disappears, giving you a backup path without any dynamic protocol on the backup link. Verify static routing with "show ip route static" and test with ping and traceroute. Common mistakes: pointing to the wrong next hop, forgetting the return route (routing must work in both directions), or using only an exit interface on an Ethernet segment and causing repeated ARP for every destination.
OSPFv2 Operation
OSPF (Open Shortest Path First) is a link-state interior gateway protocol, standards-based and used with IPv4 as OSPFv2. Every router floods link-state advertisements (LSAs) describing its links, so all routers in an area build an identical link-state database (LSDB). Each router then independently runs the SPF (Dijkstra) algorithm on that database to compute the shortest path to every network. OSPF has AD 110. Neighbors form adjacencies through hello packets (default hello 10s, dead 40s on broadcast/point-to-point links). To become neighbors, routers must agree on: the same area ID, matching hello and dead timers, the same subnet/mask on the link, matching authentication, and matching MTU; a mismatch on any of these stops the adjacency, a favorite exam troubleshooting theme. On broadcast (Ethernet) segments OSPF elects a DR and BDR to reduce flooding — highest OSPF priority wins, and the highest router ID breaks a tie (priority 0 means the router will never be DR/BDR). The router ID is chosen as the highest configured loopback IP, else the highest active interface IP, unless set manually with "router-id." OSPF metric is cost, and lower cost is better. Cost = reference-bandwidth ÷ interface-bandwidth, with the default reference bandwidth 100 Mbps (100,000,000 bps / 10^8). So a 100 Mbps link has cost 1, a 10 Mbps link cost 10, and a 1 Gbps link also computes to 1 with the default reference — which is why fast networks raise the reference bandwidth (e.g. "auto-cost reference-bandwidth 1000") so gigabit and faster links get distinct costs. The total cost of a path is the sum of the outbound interface costs along it, and SPF picks the lowest total. Configuration in single-area OSPF: "router ospf 1", then "network 10.0.0.0 0.0.0.255 area 0" (note the wildcard mask), or configure per-interface with "ip ospf 1 area 0." Verify with "show ip ospf neighbor," "show ip route ospf," and "show ip ospf interface brief." Area 0 is the backbone and all other areas must connect to it.
Next-Hop Resolution and IPv6 Routing
Knowing the next-hop IP is not enough to actually put a frame on the wire — the router must resolve that next hop to a Layer 2 address. For IPv4 this is ARP: the router broadcasts "who has 10.0.0.2?" and caches the reply's MAC in the ARP table. For IPv6, ARP is replaced by Neighbor Discovery Protocol (NDP), which uses ICMPv6 Neighbor Solicitation and Neighbor Advertisement messages to the solicited-node multicast address. This is why the destination MAC changes at every hop while the destination IP does not: each router rewrites the frame's Layer 2 header for the next link. Recursive lookup happens when a route's next hop is not directly connected. Suppose a static route says "reach 192.168.5.0/24 via 10.9.9.9," but 10.9.9.9 is itself only known through another route. The router must first resolve how to reach 10.9.9.9, then how to reach that next hop, and so on until it lands on a directly connected exit interface. This is normal and works, but specifying an exit interface (or both interface and next-hop) can avoid extra recursion; on Ethernet, always include the next-hop IP so ARP resolves correctly. IPv6 routing mirrors IPv4. Enable it globally with "ipv6 unicast-routing." Static IPv6 routes use "ipv6 route <prefix>/<length> <next-hop>," and the dynamic link-state option is OSPFv3, which runs per-interface ("ipv6 ospf 1 area 0") and, unlike OSPFv2, carries IPv6 prefixes while still requiring a 32-bit router ID that you should set manually. Note that IPv6 next hops are frequently the neighbor's link-local (FE80::) address. To confirm end-to-end reachability, verify layer by layer: "show ip route" (or "show ipv6 route") for the chosen path, "show ip arp" / "show ipv6 neighbors" for next-hop resolution, then ping and traceroute. If the route is present but pings fail, suspect an unresolved next hop, a missing return route, or an ACL dropping the traffic.
Keep going: the full Cisco CCNA 200-301 guide covers every section of the exam. Cisco CCNA 200-301 — Complete Study Guide (2026) — PDF + EPUB, $14.99 · 14-day refund →

Practice stays free. The full Cisco CCNA 200-301 study guide is the material itself, taught start to finish — a downloadable PDF + EPUB you keep.