Developing Site to Site VPNs
Monday, October 18, 2010
Cisco Site to Site VPN-Part 2 of 2
Developing Site to Site VPNs
Cisco site to site VPN Part 1 of 2
CCNA Official Exam Certification Library (Exam 640-802), Third Edition (Containing ICND1 and ICND2 Second Edition Exam Certification Guides)
Thursday, October 7, 2010
Wednesday, October 6, 2010
Configuring Trunk Ports
TKRSCS1(config)#int fa0/24
TKRSCS1(config-if)#Switchport trunk allowed vlan all
TKRSCS1(config-if)#switchport mode trunk
TKRSCS1(config-if)exit
TKRSCS2(config)#int fa0/24
TKRSCS2(config-if)#Switchport trunk allowed vlan all
TKRSCS2(config-if)#switchport mode trunk
TKRSCS2(config-if)exit
Some switches support(switchport trunk encapsulation 2900 switch)
Configure on TKRSCS1 fa0/4 and TKRSCS2 fa0/24
TKRSCS1(config)#int fa0/24
TKRSCS1(config-if)#Switchport trunk encapsulation do1q
TKRSCS1(config-if)#switchport mode trunk
TKRSCS1(config-if)exit
TKRSCS1(config-if)#Switchport trunk allowed vlan all
TKRSCS1(config-if)#switchport mode trunk
TKRSCS1(config-if)exit
TKRSCS2(config)#int fa0/24
TKRSCS2(config-if)#Switchport trunk allowed vlan all
TKRSCS2(config-if)#switchport mode trunk
TKRSCS2(config-if)exit
Some switches support(switchport trunk encapsulation 2900 switch)
Configure on TKRSCS1 fa0/4 and TKRSCS2 fa0/24
TKRSCS1(config)#int fa0/24
TKRSCS1(config-if)#Switchport trunk encapsulation do1q
TKRSCS1(config-if)#switchport mode trunk
TKRSCS1(config-if)exit
Implementing VLAN's 3 Steps
TKRSCS>
TKRSCS>enable
TKRSCS#config t
TKRSCS(config)#vlan 10
TKRSCS(config-vlan)#name Sales
TKRSCS(config-vlan)#exit
TKRSCS(config)#vlan 20
TKRSCS(config-vlan)#name Accounts
TKRSCS(config-vlan)#exit
TKRSCS(config)#vlan 30
TKRSCS(config-vlan)#name Sales
TKRSCS(config-vlan)#exit
TKRSCS#show vlan
Some Switches support vlan databse (2900 Switch)
TKRSCS#vlan database
TKRSCS(vlan)#vlan 10 name Sales
TKRSCS(vlan)#vlan 20 name Accounts
TKRSCS(vlan)#vlan 30 name Marketing
TKRSCS(vlan)#end
TKRSCS#show vlan
Assiging IP Address to Vlan's
TKRSCS(config)#int vlan 10
TKRSCS(config-if)#ip add 192.168.10.100 255.255.255.0
TKRSCS(config-if)#no shutdown
TKRSCS(config-if)exit
TKRSCS(config)#int vlan 20
TKRSCS(config-if)#ip add 192.168.20.100 255.255.255.0
TKRSCS(config-if)#no shutdown
TKRSCS(config-if)exit
TKRSCS(config)#int vlan 30
TKRSCS(config-if)#ip add 192.168.30.100 255.255.255.0
TKRSCS(config-if)#no shutdown
TKRSCS(config-if)exit
Assigning Ports to Vlan
TKRSCS(config)#int range fa0/1-7
TKRSCS(config-if)#Switchport access vlan 10
TKRSCS(config-if)#switchport mode access
TKRSCS(config-if)exit
TKRSCS(config)#int range fa0/8-14
TKRSCS(config-if)#Switchport access vlan 20
TKRSCS(config-if)#switchport mode access
TKRSCS(config-if)exit
TKRSCS(config)#int range fa0/15-21
TKRSCS(config-if)#Switchport access vlan 30
TKRSCS(config-if)#switchport mode access
TKRSCS(config-if)exit
TKRSCS>enable
TKRSCS#config t
TKRSCS(config)#vlan 10
TKRSCS(config-vlan)#name Sales
TKRSCS(config-vlan)#exit
TKRSCS(config)#vlan 20
TKRSCS(config-vlan)#name Accounts
TKRSCS(config-vlan)#exit
TKRSCS(config)#vlan 30
TKRSCS(config-vlan)#name Sales
TKRSCS(config-vlan)#exit
TKRSCS#show vlan
Some Switches support vlan databse (2900 Switch)
TKRSCS#vlan database
TKRSCS(vlan)#vlan 10 name Sales
TKRSCS(vlan)#vlan 20 name Accounts
TKRSCS(vlan)#vlan 30 name Marketing
TKRSCS(vlan)#end
TKRSCS#show vlan
Assiging IP Address to Vlan's
TKRSCS(config)#int vlan 10
TKRSCS(config-if)#ip add 192.168.10.100 255.255.255.0
TKRSCS(config-if)#no shutdown
TKRSCS(config-if)exit
TKRSCS(config)#int vlan 20
TKRSCS(config-if)#ip add 192.168.20.100 255.255.255.0
TKRSCS(config-if)#no shutdown
TKRSCS(config-if)exit
TKRSCS(config)#int vlan 30
TKRSCS(config-if)#ip add 192.168.30.100 255.255.255.0
TKRSCS(config-if)#no shutdown
TKRSCS(config-if)exit
Assigning Ports to Vlan
TKRSCS(config)#int range fa0/1-7
TKRSCS(config-if)#Switchport access vlan 10
TKRSCS(config-if)#switchport mode access
TKRSCS(config-if)exit
TKRSCS(config)#int range fa0/8-14
TKRSCS(config-if)#Switchport access vlan 20
TKRSCS(config-if)#switchport mode access
TKRSCS(config-if)exit
TKRSCS(config)#int range fa0/15-21
TKRSCS(config-if)#Switchport access vlan 30
TKRSCS(config-if)#switchport mode access
TKRSCS(config-if)exit
Switch Initial Configuration
Switch>
Switch>enable
Switch#config t
Switch(config)#Hostname TKRSCS
TKRSCS(config)#interface vlan 1
TKRSCS(config-if)#ip add 192.168.1.200 255.255.255.0
TKRSCS(config-if)#no shutdown
TKRSCS(config-if)#exit
TKRSCS(config)#line vty 0 15
TKRSCS(config-line)#password ccna
TKRSCS(config-line)#login
TKRSCS(config-line)#exit
TKRSCS(config)#line console 0
TKRSCS(config-line)#password ccna
TKRSCS(config-line)#login
TKRSCS(config-line)#exit
TKRSCS(config)#enable secret ccnp
TKRSCS(config)#exit
TKRSCS#copy run start
TKRSCS#show RUN
Switch>enable
Switch#config t
Switch(config)#Hostname TKRSCS
TKRSCS(config)#interface vlan 1
TKRSCS(config-if)#ip add 192.168.1.200 255.255.255.0
TKRSCS(config-if)#no shutdown
TKRSCS(config-if)#exit
TKRSCS(config)#line vty 0 15
TKRSCS(config-line)#password ccna
TKRSCS(config-line)#login
TKRSCS(config-line)#exit
TKRSCS(config)#line console 0
TKRSCS(config-line)#password ccna
TKRSCS(config-line)#login
TKRSCS(config-line)#exit
TKRSCS(config)#enable secret ccnp
TKRSCS(config)#exit
TKRSCS#copy run start
TKRSCS#show RUN
Standard ACL Configuration
image1
Note Routig protocol should be configured on router
CHE>enable
CHE#config t
CHE(config)#access-list 10 deny 192.168.1.1 0.0.0.0
CHE(config)#access-list 10 deny 192.168.1.2 0.0.0.0
CHE(config)#access-list 10 permit any
CHE(config)#interface 0/0 (or) int e0
CHE(config-if)#ip access-group 10 out
CHE(config-if)#exit
CHE(config)#exit
CHE#show access-list 10
CHE#show RUN
image2
CHE>enable
CHE#config t
CHE(config)#access-list 20 deny 192.168.1.1 0.0.0.0
CHE(config)#access-list 20 deny 192.168.1.2 0.0.0.0
CHE(config)#access-list 20 permit any
CHE(config)#interface 0/0 (or) int e0
CHE(config-if)#ip access-group 20 out
CHE(config-if)#exit
CHE(config)#exit
CHE#show access-list 20
CHE#ping 192.168.1.1
CHE#ping 192.168.3.1
image3
CHE>enable
CHE#config t
CHE(config)#access-list 102 deny tcp 192.168.2.0 0.0.0.255 192.168.1.100 0.0.0.0 eq 23
CHE(config)#access-list 102 deny tcp 192.168.2.0 0.0.0.255 10.0.0.1 0.0.0.0 eq 23
CHE(config)#access-list 102 permit ip any any
CHE(config)#interface 0/0 (or) int e0
CHE(config-if)#ip access-group 102 in
CHE(config-if)#exit
CHE(config)#exit
CHE#telnet 192.168.1.100
image4
CHE>enable
CHE#config t
CHE(config)#access-list 110 deny ip 192.168.2.0 0.0.0.255 192.168.1.0 0.0.0.255
CHE(config)#access-list 110 permit ip any any
CHE(config)#interface 0/0 (or) int e0
CHE(config-if)#ip access-group 110 in
CHE(config-if)#exit
CHE(config)#exit
CHE#ping 192.168.1.100
image5
CHE>enable
CHE#config t
CHE(config)#access-list 100 deny icmp 192.168.2.0 0.0.0.255 192.168.1.100 0.0.0.0 echo
CHE(config)#access-list 100 deny icmp 192.168.2.0 0.0.0.255 10.0.0.1 0.0.0.0 echo
CHE(config)#access-list 100 permit ip any any
CHE(config)#interface 0/0 (or) int e0
CHE(config-if)#ip access-group 100 in
CHE(config-if)#exit
CHE(config)#exit
CHE#ping 192.168.1.100
Note Routig protocol should be configured on router
CHE>enable
CHE#config t
CHE(config)#access-list 10 deny 192.168.1.1 0.0.0.0
CHE(config)#access-list 10 deny 192.168.1.2 0.0.0.0
CHE(config)#access-list 10 permit any
CHE(config)#interface 0/0 (or) int e0
CHE(config-if)#ip access-group 10 out
CHE(config-if)#exit
CHE(config)#exit
CHE#show access-list 10
CHE#show RUN
image2
CHE>enable
CHE#config t
CHE(config)#access-list 20 deny 192.168.1.1 0.0.0.0
CHE(config)#access-list 20 deny 192.168.1.2 0.0.0.0
CHE(config)#access-list 20 permit any
CHE(config)#interface 0/0 (or) int e0
CHE(config-if)#ip access-group 20 out
CHE(config-if)#exit
CHE(config)#exit
CHE#show access-list 20
CHE#ping 192.168.1.1
CHE#ping 192.168.3.1
image3
CHE>enable
CHE#config t
CHE(config)#access-list 102 deny tcp 192.168.2.0 0.0.0.255 192.168.1.100 0.0.0.0 eq 23
CHE(config)#access-list 102 deny tcp 192.168.2.0 0.0.0.255 10.0.0.1 0.0.0.0 eq 23
CHE(config)#access-list 102 permit ip any any
CHE(config)#interface 0/0 (or) int e0
CHE(config-if)#ip access-group 102 in
CHE(config-if)#exit
CHE(config)#exit
CHE#telnet 192.168.1.100
image4
CHE>enable
CHE#config t
CHE(config)#access-list 110 deny ip 192.168.2.0 0.0.0.255 192.168.1.0 0.0.0.255
CHE(config)#access-list 110 permit ip any any
CHE(config)#interface 0/0 (or) int e0
CHE(config-if)#ip access-group 110 in
CHE(config-if)#exit
CHE(config)#exit
CHE#ping 192.168.1.100
image5
CHE>enable
CHE#config t
CHE(config)#access-list 100 deny icmp 192.168.2.0 0.0.0.255 192.168.1.100 0.0.0.0 echo
CHE(config)#access-list 100 deny icmp 192.168.2.0 0.0.0.255 10.0.0.1 0.0.0.0 echo
CHE(config)#access-list 100 permit ip any any
CHE(config)#interface 0/0 (or) int e0
CHE(config-if)#ip access-group 100 in
CHE(config-if)#exit
CHE(config)#exit
CHE#ping 192.168.1.100
OSPF Configuration
HYD>enable
HYD#config t
HYD(config)#router ospf 1
HYD(config-router)#network 192.168.1.0 0.0.0.255 area 0
HYD(config-router)#network 10.0.0.0 0.255.255.255 area 0
HYD(config-router)#exit
HYD(config)#exit
HYD#show ip route
HYD#show ip ospf databse
HYD#show ip ospf neighnors
CHE>enable
CHE#config t
CHE(config)#router ospf 2
CHE(config-router)#network 192.168.2.0 0.0.0.255 area 0
CHE(config-router)#network 10.0.0.0 0.255.255.255 area 0
CHE(config-router)#network 11.0.0.0 0.255.255.255 area 0
CHE(config-router)#exit
CHE(config)#exit
CHE#show ip route
BAN>enable
BAN#config t
BAN(config)#router ospf 1
BAN(config-router)#network 192.168.3.0 0.0.0.255 area 0
BAN(config-router)#network 11.0.0.0 0.255.255.255 area 0
BAN(config-router)#exit
BAN(config)#exit
BAN#show ip route
HYD#config t
HYD(config)#router ospf 1
HYD(config-router)#network 192.168.1.0 0.0.0.255 area 0
HYD(config-router)#network 10.0.0.0 0.255.255.255 area 0
HYD(config-router)#exit
HYD(config)#exit
HYD#show ip route
HYD#show ip ospf databse
HYD#show ip ospf neighnors
CHE>enable
CHE#config t
CHE(config)#router ospf 2
CHE(config-router)#network 192.168.2.0 0.0.0.255 area 0
CHE(config-router)#network 10.0.0.0 0.255.255.255 area 0
CHE(config-router)#network 11.0.0.0 0.255.255.255 area 0
CHE(config-router)#exit
CHE(config)#exit
CHE#show ip route
BAN>enable
BAN#config t
BAN(config)#router ospf 1
BAN(config-router)#network 192.168.3.0 0.0.0.255 area 0
BAN(config-router)#network 11.0.0.0 0.255.255.255 area 0
BAN(config-router)#exit
BAN(config)#exit
BAN#show ip route
EIGRP Configuration
HYD>enable
HYD#config t
HYD(config)#router EIGRP 100
HYD(config-router)#network 192.168.1.0 0.0.0.255
HYD(config-router)#network 10.0.0.0 0.255.255.255
HYD(config-router)#exit
HYD(config)#exit
HYD#show ip route
HYD#show ip eigrp topology
HYD#show ip eigrp neighnors
CHE>enable
CHE#config t
CHE(config)#router EIGRP 100
CHE(config-router)#network 192.168.2.0
CHE(config-router)#network 10.0.0.0
CHE(config-router)#network 11.0.0.0
CHE(config-router)#exit
CHE(config)#exit
CHE#show ip route
CHE#show ip eigrp neighnors
BAN>enable
BAN#config t
BAN(config)#router EIGRP 100
BAN(config-router)#network 192.168.3.0
BAN(config-router)#network 11.0.0.0
BAN(config-router)#exit
BAN(config)#exit
BAN#show ip route
BAN#show ip eigrp neighnors
Then ping 192.168.1.1
HYD#config t
HYD(config)#router EIGRP 100
HYD(config-router)#network 192.168.1.0 0.0.0.255
HYD(config-router)#network 10.0.0.0 0.255.255.255
HYD(config-router)#exit
HYD(config)#exit
HYD#show ip route
HYD#show ip eigrp topology
HYD#show ip eigrp neighnors
CHE>enable
CHE#config t
CHE(config)#router EIGRP 100
CHE(config-router)#network 192.168.2.0
CHE(config-router)#network 10.0.0.0
CHE(config-router)#network 11.0.0.0
CHE(config-router)#exit
CHE(config)#exit
CHE#show ip route
CHE#show ip eigrp neighnors
BAN>enable
BAN#config t
BAN(config)#router EIGRP 100
BAN(config-router)#network 192.168.3.0
BAN(config-router)#network 11.0.0.0
BAN(config-router)#exit
BAN(config)#exit
BAN#show ip route
BAN#show ip eigrp neighnors
Then ping 192.168.1.1
IGRP Configuration
HYD>enable
HYD#config t
HYD(config)#router igrp 10
HYD(config-router)#network 192.168.1.0
HYD(config-router)#network 10.0.0.0
HYD(config-router)#exit
HYD(Config)#exit
HYD#show ip roue
HYD#show ip protocol
CHE>enable
CHE#config t
CHE(config)#router igrp 10
CHE(config-router)#network 192.168.2.0
CHE(config-router)#network 10.0.0.0
CHE(config-router)#network 11.0.0.0
CHE(config-router)#exit
CHE(Config)#exit
BAN>enable
BAN#config t
BAN(config)#router igrp 10
BAN(config-router)#network 192.168.3.0
BAN(config-router)#network 11.0.0.0
BAN(config-router)#exit
BAN(Config)#exit
BAN#show ip roue
BAN#show ip protocol
HYD#config t
HYD(config)#router igrp 10
HYD(config-router)#network 192.168.1.0
HYD(config-router)#network 10.0.0.0
HYD(config-router)#exit
HYD(Config)#exit
HYD#show ip roue
HYD#show ip protocol
CHE>enable
CHE#config t
CHE(config)#router igrp 10
CHE(config-router)#network 192.168.2.0
CHE(config-router)#network 10.0.0.0
CHE(config-router)#network 11.0.0.0
CHE(config-router)#exit
CHE(Config)#exit
BAN>enable
BAN#config t
BAN(config)#router igrp 10
BAN(config-router)#network 192.168.3.0
BAN(config-router)#network 11.0.0.0
BAN(config-router)#exit
BAN(Config)#exit
BAN#show ip roue
BAN#show ip protocol
RIP Configuration
HYD>enable
HYD#config t
HYD(config)#router rip
HYD(config-router)#network 192.168.1.0
HYD(config-router)#network 10.0.0.0
HYD(config-router)#exit
HYD(Config)#exit
HYD#show ip roue
HYD#show ip protocol
CHE>enable
CHE#config t
CHE(config)#router rip
CHE(config-router)#network 192.168.2.0
CHE(config-router)#network 10.0.0.0
CHE(config-router)#network 11.0.0.0
CHE(config-router)#exit
CHE(Config)#exit
BAN>enable
BAN#config t
BAN(config)#router rip
BAN(config-router)#network 192.168.3.0
BAN(config-router)#network 11.0.0.0
BAN(config-router)#exit
BAN(Config)#exit
BAN#show ip roue
BAN#show ip protocol
Then ping Sys IP 192.168.1.100
HYD#config t
HYD(config)#router rip
HYD(config-router)#network 192.168.1.0
HYD(config-router)#network 10.0.0.0
HYD(config-router)#exit
HYD(Config)#exit
HYD#show ip roue
HYD#show ip protocol
CHE>enable
CHE#config t
CHE(config)#router rip
CHE(config-router)#network 192.168.2.0
CHE(config-router)#network 10.0.0.0
CHE(config-router)#network 11.0.0.0
CHE(config-router)#exit
CHE(Config)#exit
BAN>enable
BAN#config t
BAN(config)#router rip
BAN(config-router)#network 192.168.3.0
BAN(config-router)#network 11.0.0.0
BAN(config-router)#exit
BAN(Config)#exit
BAN#show ip roue
BAN#show ip protocol
Then ping Sys IP 192.168.1.100
Static Default Routing
HYD>enable
HYD#config t
HYD(config)#ip route 0.0.0.0 0.0.0.0 s0
HYD(config)#exit
HYD#show ip roue
HYD#config t
HYD(config)#ip route 0.0.0.0 0.0.0.0 s0
HYD(config)#exit
HYD#show ip roue
Static Routing
HYD>enable
HYD#config t
HYD(config)#ip route192.168.2.0 255.255.255.0 10.0.0.2
HYD(config)#exit
HYD#show ip roue
HYD#ping 192.168.2.100
HYD#ping 192.168.2.1
CHE>enabble
CHE#config t
CHE(config)#ip route 192.168.1.0 255.255.255.0 10.0.0.1
CHE(config)#Exit
CHE#show ip roue
CHE#ping 192.168.1.100
CHE#ping 192.168.1.1
HYD#config t
HYD(config)#ip route192.168.2.0 255.255.255.0 10.0.0.2
HYD(config)#exit
HYD#show ip roue
HYD#ping 192.168.2.100
HYD#ping 192.168.2.1
CHE>enabble
CHE#config t
CHE(config)#ip route 192.168.1.0 255.255.255.0 10.0.0.1
CHE(config)#Exit
CHE#show ip roue
CHE#ping 192.168.1.100
CHE#ping 192.168.1.1
WAN Interface Configuration
HYD>enable
HYD#config t
HYD(config)#interface s0/0/0 (or)intreface serial 0
HYD(config-if)#ip address 10.0.0.1 255.0.0.0
HYD(config-if)#no shutdown
HYD(config-if)#clock rate 64000
HYD(config-if)#encapsulate hdlc (or) ppp
HYD(config-if)#exit
HYD#show interface serial s0
HYD#show ip interface brief
HYD#show controllers serial 0/0/0
CHE>enabble
CHE#config t
CHE(config)#interface s0/0/1 (or) interface serial 1
CHE(config-if)#ip address 10.0.0.2 255.0.0.0
CHE(config-if)#no shutdown
CHE(config-if)#encapsulate hdlc (or) ppp
CHE(config-if)#exit
CHE#show interface s1
CHE#show ip interface brief
Then ping 10.0.0.1 from CHE.
HYD#config t
HYD(config)#interface s0/0/0 (or)intreface serial 0
HYD(config-if)#ip address 10.0.0.1 255.0.0.0
HYD(config-if)#no shutdown
HYD(config-if)#clock rate 64000
HYD(config-if)#encapsulate hdlc (or) ppp
HYD(config-if)#exit
HYD#show interface serial s0
HYD#show ip interface brief
HYD#show controllers serial 0/0/0
CHE>enabble
CHE#config t
CHE(config)#interface s0/0/1 (or) interface serial 1
CHE(config-if)#ip address 10.0.0.2 255.0.0.0
CHE(config-if)#no shutdown
CHE(config-if)#encapsulate hdlc (or) ppp
CHE(config-if)#exit
CHE#show interface s1
CHE#show ip interface brief
Then ping 10.0.0.1 from CHE.
NETWORK DIAGRAM
Physical connectivity for the Initial Configuration of the router should be as bellow Network diagram.
Router>
Router>enable
Router#Config t
Router(config)#Hostname TKRSCS
TKRSCS(config)#interface fa0/0 (or) interface e0
TKRSCS(config-if)#ip address 192.168.1.100 255.255.255.0
TKRSCS(config-if)#no shutdown
TKRSCS(config-if)#exit
TKRSCS(config)#line vty 0 4
TKRSCS(config-line)#password ccna
TKRSCS(config-line)#login
TKRSCS(config-line)#exit
TKRSCS(config)#line console 0
TKRSCS(config-line)#password ccna
TKRSCS(config-line)#login
TKRSCS(config-line)#exit
TKRSCS(config)#line aux 0
TKRSCS(config-line)#password ccna
TKRSCS(config-line)#login
TKRSCS(config-line)#exit
TKRSCS(config)#enable password cisco
TKRSCS(config)#enable secret ccnp
TKRSCS(config)#exit
TKRSCS#copy running-config startup-config
TKRSCS#show running-config
Router>
Router>enable
Router#Config t
Router(config)#Hostname TKRSCS
TKRSCS(config)#interface fa0/0 (or) interface e0
TKRSCS(config-if)#ip address 192.168.1.100 255.255.255.0
TKRSCS(config-if)#no shutdown
TKRSCS(config-if)#exit
TKRSCS(config)#line vty 0 4
TKRSCS(config-line)#password ccna
TKRSCS(config-line)#login
TKRSCS(config-line)#exit
TKRSCS(config)#line console 0
TKRSCS(config-line)#password ccna
TKRSCS(config-line)#login
TKRSCS(config-line)#exit
TKRSCS(config)#line aux 0
TKRSCS(config-line)#password ccna
TKRSCS(config-line)#login
TKRSCS(config-line)#exit
TKRSCS(config)#enable password cisco
TKRSCS(config)#enable secret ccnp
TKRSCS(config)#exit
TKRSCS#copy running-config startup-config
TKRSCS#show running-config
Subscribe to:
Posts (Atom)