Breakout-Activity FINAL

Download as txt, pdf, or txt
Download as txt, pdf, or txt
You are on page 1of 8

SW1

enable
configure terminal
vlan 10
name Packaging_1
exit
vlan 20
name Packaging_2
exit

interface range fastethernet0/9-10


switchport access vlan 10
switchport mode access
exit

interface range fastethernet0/11-12


switchport access vlan 20
switchport mode access
exit

interface gigabitethernet 0/1


no shutdown
switchport mode trunk
switchport trunk allowed vlan 10,20
exit

SW2

enable
configure terminal
vlan 30
name Packaging_3
exit
vlan 40
name Packaging_4
exit

interface range fastethernet0/9-10


switchport access vlan 30
switchport mode access
exit

interface range fastethernet0/11-12


switchport access vlan 40
switchport mode access
exit

interface gigabitethernet 0/1


no shutdown
switchport mode trunk
switchport trunk allowed vlan 30,40
exit
Company 1 (Router)

enable
configure terminal
interface gigabitethernet0/0/0.10
ip address 192.168.20.1 255.255.255.0
encapsulation dot1q 10
no shutdown

interface gigabitethernet0/0/0.20
ip address 192.168.21.1 255.255.255.0
encapsulation dot1q 20
no shutdown

interface gigabitethernet0/0/1.30
ip address 192.168.22.1 255.255.255.0
encapsulation dot1q 30
no shutdown

interface gigabitethernet0/0/1.40
ip address 192.168.23.1 255.255.255.0
encapsulation dot1q 40
no shutdown

OSPF ROUTING CONFIGURATION

interface s0/2/0
ip address 192.168.6.2 255.255.255.0
no shutdown
exit

router ospf 10
router-id 1.1.1.1

passive-interface gigabitethernet0/0/0.10
passive-interface gigabitethernet0/0/0.20
passive-interface gigabitethernet0/0/1.30
passive-interface gigabitethernet0/0/1.40

network 192.168.20.0 0.0.0.255 area 0


network 192.168.21.0 0.0.0.255 area 0
network 192.168.22.0 0.0.0.255 area 0
network 192.168.23.0 0.0.0.255 area 0
network 192.168.6.0 0.0.0.255 area 0

IPSEC VPN configuration (we will make a tunnel between company 1 and 2)

access-list 100 permit 192.168.0.0 0.0.255.255


crypto isakmp policy 10
encryption aes 256
authentication pre-share
group 5
crypto isakmp key GROUP1 add 192.168.7.2
crypto ipsec transform-set C1TOC2 esp-aes 256 esp-sha-hmac
crypto map IPSEC- 5 ipsec-isakmp
set peer 192.168.7.2
set pfs group5
set security-association lifetime seconds 86400
set transform-set C1TOC2
match address 100
int S0/2/0
crypto map IPSEC-MAP

HQ_db (Router)

enable
configure terminal
interface s0/1/0
ip address 192.168.6.1 255.255.255.0
no shutdown
exit

interface s0/1/1
ip address 192.168.7.1 255.255.255.0
no shutdown
exit

interface s0/2/0
ip address 192.168.8.1 255.255.255.0
no shutdown
exit

enable
configure terminal
router ospf 10
router-id 4.4.4.4

network 192.168.6.0 0.0.0.255 area 0


network 192.168.7.0 0.0.0.255 area 0
network 192.168.8.0 0.0.0.255 area 0

default-information originate

Company 2 (Router)

enable
configure terminal

interface serial0/2/0
ip address 192.168.7.2 255.255.255.0
no shutdown

interface gigabitethernet0/0/0
no shutdown

interface gigabitethernet0/0/1
no shutdown
interface gigabitethernet0/0/0.10
ip address 192.168.24.1 255.255.255.0
encapsulation dot1q 10
no shutdown

interface gigabitethernet0/0/0.20
ip address 192.168.25.1 255.255.255.0
encapsulation dot1q 20
no shutdown

interface gigabitethernet0/0/1.30
ip address 192.168.26.1 255.255.255.0
encapsulation dot1q 30
no shutdown

interface gigabitethernet0/0/1.40
ip address 192.168.27.1 255.255.255.0
encapsulation dot1q 40
no shutdown

router ospf 10
router-id 2.2.2.2

passive-interface gigabitethernet0/0/0.10
passive-interface gigabitethernet0/0/0.20
passive-interface gigabitethernet0/0/1.30
passive-interface gigabitethernet0/0/1.40

network 192.168.24.0 0.0.0.255 area 0


network 192.168.25.0 0.0.0.255 area 0
network 192.168.26.0 0.0.0.255 area 0
network 192.168.27.0 0.0.0.255 area 0
network 192.168.7.0 0.0.0.255 area 0

IPSEC VPN configuration (we will make a tunnel between company 2 and 1)

access-list 100 permit 192.168.0.0 0.0.255.255


crypto isakmp policy 10
encryption aes 256
authentication pre-share
group 5
crypto isakmp key GROUP1 add 192.168.6.2
crypto ipsec transform-set C2TOC1 esp-aes 256 esp-sha-hmac
crypto map IPSEC- 5 ipsec-isakmp
set peer 192.168.6.2
set pfs group5
set security-association lifetime seconds 86400
set transform-set C2TOC1
match address 100
int S0/2/0
crypto map IPSEC-MAP

SW3
enable
configure terminal
vlan 10
name Packaging_5
exit
vlan 20
name Packaging_6
exit

interface range fastethernet0/9-10


switchport access vlan 10
switchport mode access
exit

interface range fastethernet0/11-12


switchport access vlan 20
switchport mode access
exit

interface gigabitethernet 0/1


no shutdown
switchport mode trunk
switchport trunk allowed vlan 10,20
exit

SW4

enable
configure terminal
vlan 30
name Packaging_7
exit
vlan 40
name Packaging_8
exit

interface range fastethernet0/9-10


switchport access vlan 30
switchport mode access
exit

interface range fastethernet0/11-12


switchport access vlan 40
switchport mode access
exit

interface gigabitethernet 0/1


no shutdown
switchport mode trunk
switchport trunk allowed vlan 30,40
exit

SW5

enable
configure terminal
vlan 10
name Packaging_9
exit
vlan 20
name Packaging_10
exit

interface range fastethernet0/9-10


switchport access vlan 10
switchport mode access
exit

interface range fastethernet0/11-12


switchport access vlan 20
switchport mode access
exit

interface gigabitethernet 0/1


no shutdown
switchport mode trunk
switchport trunk allowed vlan 10,20
exit

SW6

enable
configure terminal
vlan 30
name Packaging_11
exit
vlan 40
name Packaging_12
exit

interface range fastethernet0/9-10


switchport access vlan 30
switchport mode access
exit

interface range fastethernet0/11-12


switchport access vlan 40
switchport mode access
exit

interface gigabitethernet 0/1


no shutdown
switchport mode trunk
switchport trunk allowed vlan 30,40
exit

Company 3 (Router)

enable
configure terminal
interface serial0/2/0
ip address 192.168.8.2 255.255.255.0
no shutdown

interface gigabitethernet0/0/0
no shutdown

interface gigabitethernet0/0/1
no shutdown

interface gigabitethernet0/0/0.10
ip address 192.168.28.1 255.255.255.0
encapsulation dot1q 10
no shutdown

interface gigabitethernet0/0/0.20
ip address 192.168.29.1 255.255.255.0
encapsulation dot1q 20
no shutdown

interface gigabitethernet0/0/1.30
ip address 192.168.30.1 255.255.255.0
encapsulation dot1q 30
no shutdown

interface gigabitethernet0/0/1.40
ip address 192.168.31.1 255.255.255.0
encapsulation dot1q 40
no shutdown

router ospf 10
router-id 3.3.3.3

passive-interface gigabitethernet0/0/0.10
passive-interface gigabitethernet0/0/0.20
passive-interface gigabitethernet0/0/1.30
passive-interface gigabitethernet0/0/1.40

network 192.168.28.0 0.0.0.255 area 0


network 192.168.29.0 0.0.0.255 area 0
network 192.168.30.0 0.0.0.255 area 0
network 192.168.31.0 0.0.0.255 area 0
network 192.168.8.0 0.0.0.255 area 0

PAT on HQ_db

int s0/1/0
ip nat inside

int s0/1/1
ip nat inside

int s0/2/1
ip nat outside

ip nat pool HQ 200.165.1.100 200.165.1.101 netmask 255.255.255.128


ip nat inside source list 1 pool HQ overload
access-list 1 permit 192.0.0.0 0.255.255.255

You might also like