TP1 16 02 2024 Resolv
TP1 16 02 2024 Resolv
TP1 16 02 2024 Resolv
1) Plan d’adressage
Device Interface IP Address Subnet Mask Default Gateway
G0/0.10 192.168.1.126 255.255.255.128
G0/0.20 192.168.1.158 255.255.255.224
R-LAN G0/1 10.0.0.1 255.255.255.252 N/A
R-ASA G1/1(inside) 10.0.0.2 255.255.255.252
G1/2 (dmz) 10.0.0.6 255.255.255.252
G1/3 (outside) 10.0.0.10 255.255.255.252 N/A
R-DMZ G0/0 192.168.2.14 255.255.255.240
G0/1 10.0.0.5 255.255.255.252 N/A
R-ISP G0/0 172.16.1.254 255.255.255.0
G1/0 10.0.0.9 255.255.255.252 NA
SrvDNS NIC 192.168.2.12 255.255.255.248 192.168.2.14
SrvRadius NIC 192.168.2.10 255.255.255.248 192.168.2.14
SrvWEB NIC 172.16.1.100 255.255.255.0 172.16.1.254
SrvFTP NIC 172.16.1.110 255.255.255.0 172.16.1.254
VLAN10 NIC DHCP
VLAN10-1 NIC DHCP
VLAN20-1 NIC DHCP
VLAN20-2 NIC DHCP
2) Gestion des Vlans (VTP)
Enable
Conf t
Hostname S3
Vtp domain ita.lan
Vtp version 2
Vtp mode server
Vtp password Azerty2024
Vlan 10
Name CISCO
Exit
Vlan 20
Name DBA
Enable
Conf t
Hostname S1
Vtp domain ita.lan
Vtp version 2
Vtp mode client
Vtp password Azerty2024
Enable
Conf t
Hostname S2
Vtp domain ita.lan
Vtp version 2
Vtp mode client
Vtp password Azerty2024
a- Router R-LAN
Enable
Conf t
Hostname R-LAN
Interface g0/0
No ip address
No shutdown
Exit
Interface g0/0.10
Encapsulation dot1q 10
Ip address 192.168.1.126 255.255.255.128
Exit
Interface g0/0.20
Encapsulation dot1q 20
Ip address 192.168.1.158 255.255.255.224
Exit
Interface g0/1
No shutdown
Ip address 10.0.0.1 255.255.255.252
End
Copy running-config startup-config
b- Router R-DMZ
Enable
Conf t
Hostname R-DMZ
Interface g0/0
No shutdown
Ip address 192.168.2.14 255.255.255.240
Exit
Interface g0/1
No shutdown
Ip address 10.0.0.5 255.255.255.252
End
Copy running-config startup-config
c- Router R-ISP
Enable
Conf t
Hostname R-ISP
Interface g0/0
No shutdown
Ip address 172.16.1.254 255.255.255.0
Exit
Interface g0/1
No shutdown
Ip address 10.0.0.9 255.255.255.252
End
Copy running-config startup-config
d- R-ASA
Enable
Conf t
Hostname R-ASA
Interface g1/1
Nameif inside
No shutdown
Ip address 10.0.0.2 255.255.255.252
Exit
Interface g1/2
Nameif dmz
Security-level 75
No shutdown
Ip address 10.0.0.6 255.255.255.252
Exit
Interface g1/3
Nameif outside
No shutdown
Ip address 10.0.0.10 255.255.255.252
End
Copy running-config startup-config
Enable
Conf t
Ip dhcp pool VLAN10
Network 192.168.1.0 255.255.255.128
Default-router 192.168.1.126
Dns-server 192.168.2.12
option 150 ip 192.168.1.126
exit
ip dhcp excluded-address 192.168.1.126
4) Routage statique
a- Router R-LAN
Enable
Conf t
Ip route 172.16.1.0 255.255.255.0 10.0.0.2
Ip route 192.168.2.0 255.255.255.240 10.0.0.2
End
Copy running-config startup-config
b- Router R-DMZ
Enable
Conf t
Ip route 172.16.1.0 255.255.255.0 10.0.0.6
Ip route 192.168.1.0 255.255.255.0 10.0.0.6
End
Copy running-config startup-config
c- Router R-ISP
Enable
Conf t
Ip route 172.16.1.0 255.255.255.0 10.0.0.10
Ip route 192.16.1.0 255.255.255.0 10.0.0.10
End
Copy running-config startup-config
Enable
Conf t
route outside 172.16.1.0 255.255.255.0 10.0.0.9
route dmz 192.168.2.0 255.255.255.240 10.0.0.5
route inside 192.16.1.0 255.255.255.0 10.0.0.1
End
Copy running-config startup-config