Pages

Monday, October 18, 2010

Cisco Site to Site VPN-Part 2 of 2


Developing Site to Site VPNsImplementation Considerations for a Virtual Private Network (VPN) to Enable Broadband Secure Remote Access to the Naval Postgraduate School Intranet

Cisco site to site VPN Part 1 of 2


CCNA Official Exam Certification Library (Exam 640-802), Third Edition (Containing ICND1 and ICND2 Second Edition Exam Certification Guides)CCNA Official Exam Certification Library (Exam 640-802), Third Edition (Containing ICND1 and ICND2 Second Edition Exam Certification Guides)

Cisco PIX Remote Access VPN Configuration



How a Computer Network Works

CONFIGURING STATIC ROUTING RIP IGRP OSPF ON CISCO ROUTER

Wednesday, October 6, 2010

7 Steps to Recover Router or Switch Password

NAT Configuration

CHAP Configuration

PAP Configuration

ISDN Configuration

Frame Relay Configuration

Router on Stick Configuration

VTP Configuration 2900 Switches

VTP Configuration

Configuring 2 Switches to Communicate between vlans

Configuring Trunk Ports

TKRSCS1(config)#int fa0/24
TKRSCS1(config-if)#Switchport trunk allowed vlan all
TKRSCS1(config-if)#switchport mode trunk
TKRSCS1(config-if)exit


TKRSCS2(config)#int fa0/24
TKRSCS2(config-if)#Switchport trunk allowed vlan all
TKRSCS2(config-if)#switchport mode trunk
TKRSCS2(config-if)exit

Some switches support(switchport trunk encapsulation 2900 switch)
Configure on TKRSCS1 fa0/4 and TKRSCS2 fa0/24


TKRSCS1(config)#int fa0/24
TKRSCS1(config-if)#Switchport trunk encapsulation do1q
TKRSCS1(config-if)#switchport mode trunk
TKRSCS1(config-if)exit

Implementing VLAN's 3 Steps

TKRSCS>
TKRSCS>enable
TKRSCS#config t

TKRSCS(config)#vlan 10
TKRSCS(config-vlan)#name Sales
TKRSCS(config-vlan)#exit

TKRSCS(config)#vlan 20
TKRSCS(config-vlan)#name Accounts
TKRSCS(config-vlan)#exit

TKRSCS(config)#vlan 30
TKRSCS(config-vlan)#name Sales
TKRSCS(config-vlan)#exit

TKRSCS#show vlan

Some Switches support vlan databse (2900 Switch)

TKRSCS#vlan database
TKRSCS(vlan)#vlan 10 name Sales
TKRSCS(vlan)#vlan 20 name Accounts
TKRSCS(vlan)#vlan 30 name Marketing
TKRSCS(vlan)#end
TKRSCS#show vlan


Assiging IP Address to Vlan's

TKRSCS(config)#int vlan 10
TKRSCS(config-if)#ip add 192.168.10.100 255.255.255.0
TKRSCS(config-if)#no shutdown
TKRSCS(config-if)exit

TKRSCS(config)#int vlan 20
TKRSCS(config-if)#ip add 192.168.20.100 255.255.255.0
TKRSCS(config-if)#no shutdown
TKRSCS(config-if)exit

TKRSCS(config)#int vlan 30
TKRSCS(config-if)#ip add 192.168.30.100 255.255.255.0
TKRSCS(config-if)#no shutdown
TKRSCS(config-if)exit


Assigning Ports to Vlan


TKRSCS(config)#int range fa0/1-7
TKRSCS(config-if)#Switchport access vlan 10
TKRSCS(config-if)#switchport mode access
TKRSCS(config-if)exit

TKRSCS(config)#int range fa0/8-14
TKRSCS(config-if)#Switchport access vlan 20
TKRSCS(config-if)#switchport mode access
TKRSCS(config-if)exit

TKRSCS(config)#int range fa0/15-21
TKRSCS(config-if)#Switchport access vlan 30
TKRSCS(config-if)#switchport mode access
TKRSCS(config-if)exit

Switch Initial Configuration

Switch>
Switch>enable
Switch#config t

Switch(config)#Hostname TKRSCS

TKRSCS(config)#interface vlan 1
TKRSCS(config-if)#ip add 192.168.1.200 255.255.255.0
TKRSCS(config-if)#no shutdown
TKRSCS(config-if)#exit

TKRSCS(config)#line vty 0 15
TKRSCS(config-line)#password ccna
TKRSCS(config-line)#login
TKRSCS(config-line)#exit

TKRSCS(config)#line console 0
TKRSCS(config-line)#password ccna
TKRSCS(config-line)#login
TKRSCS(config-line)#exit

TKRSCS(config)#enable secret ccnp

TKRSCS(config)#exit
TKRSCS#copy run start
TKRSCS#show RUN

Standard ACL Configuration

image1

Note Routig protocol should be configured on router
CHE>enable
CHE#config t
CHE(config)#access-list 10 deny 192.168.1.1 0.0.0.0
CHE(config)#access-list 10 deny 192.168.1.2 0.0.0.0
CHE(config)#access-list 10 permit any
CHE(config)#interface 0/0 (or) int e0
CHE(config-if)#ip access-group 10 out
CHE(config-if)#exit
CHE(config)#exit
CHE#show access-list 10
CHE#show RUN

image2

CHE>enable
CHE#config t
CHE(config)#access-list 20 deny 192.168.1.1 0.0.0.0
CHE(config)#access-list 20 deny 192.168.1.2 0.0.0.0
CHE(config)#access-list 20 permit any
CHE(config)#interface 0/0 (or) int e0
CHE(config-if)#ip access-group 20 out
CHE(config-if)#exit
CHE(config)#exit
CHE#show access-list 20
CHE#ping 192.168.1.1
CHE#ping 192.168.3.1

image3

CHE>enable
CHE#config t
CHE(config)#access-list 102 deny tcp 192.168.2.0 0.0.0.255 192.168.1.100 0.0.0.0 eq 23
CHE(config)#access-list 102 deny tcp 192.168.2.0 0.0.0.255 10.0.0.1 0.0.0.0 eq 23
CHE(config)#access-list 102 permit ip any any

CHE(config)#interface 0/0 (or) int e0
CHE(config-if)#ip access-group 102 in
CHE(config-if)#exit
CHE(config)#exit
CHE#telnet 192.168.1.100

image4

CHE>enable
CHE#config t
CHE(config)#access-list 110 deny ip 192.168.2.0 0.0.0.255 192.168.1.0 0.0.0.255
CHE(config)#access-list 110 permit ip any any

CHE(config)#interface 0/0 (or) int e0
CHE(config-if)#ip access-group 110 in
CHE(config-if)#exit
CHE(config)#exit
CHE#ping 192.168.1.100

image5

CHE>enable
CHE#config t
CHE(config)#access-list 100 deny icmp 192.168.2.0 0.0.0.255 192.168.1.100 0.0.0.0 echo
CHE(config)#access-list 100 deny icmp 192.168.2.0 0.0.0.255 10.0.0.1 0.0.0.0 echo
CHE(config)#access-list 100 permit ip any any

CHE(config)#interface 0/0 (or) int e0
CHE(config-if)#ip access-group 100 in
CHE(config-if)#exit
CHE(config)#exit
CHE#ping 192.168.1.100

OSPF Configuration

HYD>enable
HYD#config t
HYD(config)#router ospf 1
HYD(config-router)#network 192.168.1.0 0.0.0.255 area 0
HYD(config-router)#network 10.0.0.0 0.255.255.255 area 0
HYD(config-router)#exit
HYD(config)#exit
HYD#show ip route
HYD#show ip ospf databse
HYD#show ip ospf neighnors


CHE>enable
CHE#config t
CHE(config)#router ospf 2
CHE(config-router)#network 192.168.2.0 0.0.0.255 area 0
CHE(config-router)#network 10.0.0.0 0.255.255.255 area 0
CHE(config-router)#network 11.0.0.0 0.255.255.255 area 0
CHE(config-router)#exit
CHE(config)#exit
CHE#show ip route


BAN>enable
BAN#config t
BAN(config)#router ospf 1
BAN(config-router)#network 192.168.3.0 0.0.0.255 area 0
BAN(config-router)#network 11.0.0.0 0.255.255.255 area 0
BAN(config-router)#exit
BAN(config)#exit
BAN#show ip route

EIGRP Configuration

HYD>enable
HYD#config t
HYD(config)#router EIGRP 100
HYD(config-router)#network 192.168.1.0 0.0.0.255
HYD(config-router)#network 10.0.0.0 0.255.255.255
HYD(config-router)#exit
HYD(config)#exit
HYD#show ip route
HYD#show ip eigrp topology
HYD#show ip eigrp neighnors


CHE>enable
CHE#config t
CHE(config)#router EIGRP 100
CHE(config-router)#network 192.168.2.0
CHE(config-router)#network 10.0.0.0
CHE(config-router)#network 11.0.0.0
CHE(config-router)#exit
CHE(config)#exit
CHE#show ip route
CHE#show ip eigrp neighnors


BAN>enable
BAN#config t
BAN(config)#router EIGRP 100
BAN(config-router)#network 192.168.3.0
BAN(config-router)#network 11.0.0.0
BAN(config-router)#exit
BAN(config)#exit
BAN#show ip route
BAN#show ip eigrp neighnors

Then ping 192.168.1.1

IGRP Configuration

HYD>enable
HYD#config t
HYD(config)#router igrp 10
HYD(config-router)#network 192.168.1.0
HYD(config-router)#network 10.0.0.0
HYD(config-router)#exit
HYD(Config)#exit
HYD#show ip roue
HYD#show ip protocol


CHE>enable
CHE#config t
CHE(config)#router igrp 10
CHE(config-router)#network 192.168.2.0
CHE(config-router)#network 10.0.0.0
CHE(config-router)#network 11.0.0.0
CHE(config-router)#exit
CHE(Config)#exit


BAN>enable
BAN#config t
BAN(config)#router igrp 10
BAN(config-router)#network 192.168.3.0
BAN(config-router)#network 11.0.0.0
BAN(config-router)#exit
BAN(Config)#exit
BAN#show ip roue
BAN#show ip protocol

RIP Configuration

HYD>enable
HYD#config t
HYD(config)#router rip
HYD(config-router)#network 192.168.1.0
HYD(config-router)#network 10.0.0.0
HYD(config-router)#exit
HYD(Config)#exit
HYD#show ip roue
HYD#show ip protocol


CHE>enable
CHE#config t
CHE(config)#router rip
CHE(config-router)#network 192.168.2.0
CHE(config-router)#network 10.0.0.0
CHE(config-router)#network 11.0.0.0
CHE(config-router)#exit
CHE(Config)#exit


BAN>enable
BAN#config t
BAN(config)#router rip
BAN(config-router)#network 192.168.3.0
BAN(config-router)#network 11.0.0.0
BAN(config-router)#exit
BAN(Config)#exit
BAN#show ip roue
BAN#show ip protocol

Then ping Sys IP 192.168.1.100

Static Default Routing

HYD>enable
HYD#config t
HYD(config)#ip route 0.0.0.0 0.0.0.0 s0
HYD(config)#exit
HYD#show ip roue

Static Routing

HYD>enable
HYD#config t

HYD(config)#ip route192.168.2.0 255.255.255.0 10.0.0.2
HYD(config)#exit
HYD#show ip roue
HYD#ping 192.168.2.100
HYD#ping 192.168.2.1


CHE>enabble
CHE#config t
CHE(config)#ip route 192.168.1.0 255.255.255.0 10.0.0.1
CHE(config)#Exit
CHE#show ip roue
CHE#ping 192.168.1.100
CHE#ping 192.168.1.1

WAN Interface Configuration

HYD>enable
HYD#config t

HYD(config)#interface s0/0/0 (or)intreface serial 0
HYD(config-if)#ip address 10.0.0.1 255.0.0.0
HYD(config-if)#no shutdown
HYD(config-if)#clock rate 64000
HYD(config-if)#encapsulate hdlc (or) ppp
HYD(config-if)#exit
HYD#show interface serial s0
HYD#show ip interface brief
HYD#show controllers serial 0/0/0

CHE>enabble
CHE#config t
CHE(config)#interface s0/0/1 (or) interface serial 1
CHE(config-if)#ip address 10.0.0.2 255.0.0.0
CHE(config-if)#no shutdown
CHE(config-if)#encapsulate hdlc (or) ppp
CHE(config-if)#exit
CHE#show interface s1
CHE#show ip interface brief

Then ping 10.0.0.1 from CHE.

NETWORK DIAGRAM

Physical connectivity for the Initial Configuration of the router should be as bellow Network diagram.

Router>
Router>enable
Router#Config t
Router(config)#Hostname TKRSCS

TKRSCS(config)#interface fa0/0 (or)  interface e0
TKRSCS(config-if)#ip address 192.168.1.100 255.255.255.0
TKRSCS(config-if)#no shutdown
TKRSCS(config-if)#exit

TKRSCS(config)#line vty 0 4
TKRSCS(config-line)#password ccna
TKRSCS(config-line)#login
TKRSCS(config-line)#exit

TKRSCS(config)#line console 0
TKRSCS(config-line)#password ccna
TKRSCS(config-line)#login
TKRSCS(config-line)#exit


TKRSCS(config)#line aux 0
TKRSCS(config-line)#password ccna
TKRSCS(config-line)#login
TKRSCS(config-line)#exit

TKRSCS(config)#enable password cisco
TKRSCS(config)#enable secret ccnp

TKRSCS(config)#exit
TKRSCS#copy running-config startup-config
TKRSCS#show running-config
Spice Up Your Blog Gadgets