Network Configuration: Router, Switch, and Server Setup

Router Configuration

ISP Router

Basic Configuration

Router(config)#hostname ISP
ISP(config)#ip domain-name santiago.cl
ISP(config)#enable secret cisco123
ISP(config)#crypto key generate rsa
ISP(config)#ip ssh version 2
ISP(config)#ip ssh time-out 30

Interface Configuration

ISP(config)#interface GigabitEthernet 0/0
ISP(config-if)#ip address 200.0.0.1 255.255.255.252
ISP(config-if)#no shutdown
ISP(config-if)#exit
ISP(config)#interface Serial 0/0/0
ISP(config-if)#ip address 200.0.0.5 255.255.255.252
ISP(config-if)#clock rate 128000
ISP(config-if)#no shutdown
ISP(config-if)#exit

IPv6 Configuration

ISP(config)#ipv6 unicast-routing
ISP(config)#interface Serial 0/0/0
ISP(config-if)#ipv6 address 2001:db8:cafe:1::1/64
ISP(config-if)#exit

Routing Configuration

ISP(config)#ip route 200.0.1.0 255.255.255.0 Serial 0/0/0

Line Configuration

ISP(config)#line vty 0 4
ISP(config-line)#transport input ssh
ISP(config-line)#login local
ISP(config-line)#exit
ISP(config)#do write memory

Santiago Router

Basic Configuration

santiago(config)#hostname santiago
santiago(config)#ip domain-name santiago.cl
santiago(config)#enable secret cisco123
santiago(config)#crypto key generate rsa
How many bits in the modulus [512]: 2048
santiago(config)#ip ssh version 2
santiago(config)#ip ssh time-out 30

Interface Configuration

santiago(config)#interface Serial 0/0/0
santiago(config-if)#ip address 200.0.0.6 255.255.255.252
santiago(config-if)#no shutdown
santiago(config-if)#exit
santiago(config)#interface Serial 0/1/0
santiago(config-if)#ip address 200.0.0.9 255.255.255.252
santiago(config-if)#clock rate 128000
santiago(config-if)#no shutdown
santiago(config-if)#exit
santiago(config)#interface GigabitEthernet 0/0
santiago(config-if)#ip address 200.0.1.1 255.255.255.0
santiago(config-if)#no shutdown
santiago(config-if)#exit

IPv6 Configuration

santiago(config)#ipv6 unicast-routing
santiago(config)#interface Serial 0/0/0
santiago(config-if)#ipv6 address 2001:db8:cafe:1::2/64
santiago(config-if)#exit
santiago(config)#interface Serial 0/1/0
santiago(config-if)#ipv6 address 2001:db8:cafe:2::1/64
santiago(config-if)#exit
santiago(config)#interface GigabitEthernet 0/0
santiago(config-if)#ipv6 address 2001:db8:cafe:3::1/64
santiago(config-if)#exit

OSPF Configuration

santiago(config)#router ospf 1
santiago(config-router)#network 200.0.0.4 0.0.0.3 area 0
santiago(config-router)#network 200.0.0.8 0.0.0.3 area 0
santiago(config-router)#network 200.0.1.0 0.0.0.255 area 0
santiago(config-router)#default-information originate
santiago(config-router)#exit
santiago(config)#ipv6 router ospf 1
santiago(config-rtr)#router-id 2.2.2.2
santiago(config-rtr)#exit
santiago(config)#interface Serial 0/1/0
santiago(config-if)#ipv6 ospf 1 area 0
santiago(config-if)#exit
santiago(config)#interface Serial 0/0/0
santiago(config-if)#ipv6 ospf 1 area 0
santiago(config-if)#exit
santiago(config)#interface GigabitEthernet 0/0
santiago(config-if)#ipv6 ospf 1 area 0
santiago(config-if)#exit

Static Routing

santiago(config)#ip route 0.0.0.0 0.0.0.0 Serial 0/0/0

Access List

santiago(config)#access-list 100 deny tcp 200.0.1.0 0.0.0.255 host 192.168.40.10 eq 80
santiago(config)#access-list 100 deny tcp 200.0.1.0 0.0.0.255 host 192.168.40.10 eq 443
santiago(config)#access-list 100 permit ip any any
santiago(config)#interface Serial 0/1/0
santiago(config-if)#ip access-group 100 out
santiago(config-if)#exit

Line Configuration

santiago(config)#line vty 0 4
santiago(config-line)#transport input ssh
santiago(config-line)#login local
santiago(config-line)#exit
santiago(config)#do write memory

Switch Configuration

Basic Configuration

Switch(config)#hostname switch0
switch0(config)#ip domain-name santiago.cl
switch0(config)#enable secret cisco123
switch0(config)#crypto key generate rsa
How many bits in the modulus [512]: 2048
switch0(config)#ip ssh version 2
switch0(config)#ip ssh time-out 30

VLAN Configuration

switch0(config)#vlan 10
switch0(config-vlan)#name VLAN10
switch0(config-vlan)#exit
switch0(config)#vlan 20
switch0(config-vlan)#name VLAN20
switch0(config-vlan)#exit
switch0(config)#vlan 30
switch0(config-vlan)#name VLAN30
switch0(config-vlan)#exit
switch0(config)#vlan 40
switch0(config-vlan)#name VLAN40
switch0(config-vlan)#exit

Interface Configuration

switch0(config)#interface FastEthernet 0/1
switch0(config-if)#switchport access vlan 10
switch0(config-if)#exit
switch0(config)#interface FastEthernet 0/2
switch0(config-if)#switchport mode access
switch0(config-if)#switchport access vlan 30
switch0(config-if)#exit
switch0(config)#interface FastEthernet 0/3
switch0(config-if)#switchport mode access
switch0(config-if)#switchport access vlan 40
switch0(config-if)#exit
switch0(config)#interface FastEthernet 0/4
switch0(config-if)#switchport mode access
switch0(config-if)#switchport access vlan 20
switch0(config-if)#exit

Line Configuration

switch0(config)#line vty 0 15
switch0(config-line)#transport input ssh
switch0(config-line)#login local
switch0(config-line)#exit
switch0(config)#do write memory

Server Configuration

Basic Configuration

servidores(config)#hostname servidores

Interface Configuration

servidores(config)#interface Serial 0/0/0
servidores(config-if)#ip address 200.0.0.10 255.255.255.252
servidores(config-if)#no shutdown
servidores(config-if)#exit
servidores(config)#interface GigabitEthernet 0/0
! Subinterfaces for VLANs
servidores(config)#interface GigabitEthernet 0/0.10
servidores(config-subif)#encapsulation dot1Q 10
servidores(config-subif)#ip address 192.168.10.1 255.255.255.0
servidores(config-subif)#exit
servidores(config)#interface GigabitEthernet 0/0.20
servidores(config-subif)#encapsulation dot1Q 20
servidores(config-subif)#ip address 192.168.20.1 255.255.255.0
servidores(config-subif)#exit
servidores(config)#interface GigabitEthernet 0/0.30
servidores(config-subif)#encapsulation dot1Q 30
servidores(config-subif)#ip address 192.168.30.1 255.255.255.0
servidores(config-subif)#exit
servidores(config)#interface GigabitEthernet 0/0.40
servidores(config-subif)#encapsulation dot1Q 40
servidores(config-subif)#ip address 192.168.40.1 255.255.255.0
servidores(config-subif)#exit

IPv6 Configuration

servidores(config)#interface Serial 0/0/0
servidores(config-if)#ipv6 address 2001:db8:cafe:2::2/64
servidores(config-if)#exit

OSPF Configuration

servidores(config)#router ospf 1
servidores(config-router)#network 192.168.10.0 0.0.0.255 area 0
servidores(config-router)#network 192.168.20.0 0.0.0.255 area 0
servidores(config-router)#network 192.168.30.0 0.0.0.255 area 0
servidores(config-router)#network 192.168.40.0 0.0.0.255 area 0
servidores(config-router)#network 200.0.0.8 0.0.0.3 area 0
servidores(config-router)#exit
servidores(config)#ipv6 router ospf 1
servidores(config-rtr)#router-id 1.1.1.1
servidores(config-rtr)#exit
servidores(config)#interface Serial 0/0/0
servidores(config-if)#ipv6 ospf 1 area 0
servidores(config-if)#exit

DHCP Configuration

servidores(config)#ip dhcp pool VLAN10
servidores(dhcp-config)#network 192.168.10.0 255.255.255.0
servidores(dhcp-config)#default-router 192.168.10.1
servidores(dhcp-config)#dns-server 200.0.0.2
servidores(dhcp-config)#exit
servidores(config)#ip dhcp pool VLAN20
servidores(dhcp-config)#network 192.168.20.0 255.255.255.0
servidores(dhcp-config)#default-router 192.168.20.1
servidores(dhcp-config)#dns-server 200.0.0.2
servidores(dhcp-config)#exit
servidores(config)#ip dhcp pool VLAN30
servidores(dhcp-config)#network 192.168.30.0 255.255.255.0
servidores(dhcp-config)#default-router 192.168.30.1
servidores(dhcp-config)#dns-server 200.0.0.2
servidores(dhcp-config)#exit
servidores(config)#ip dhcp pool VLAN40
servidores(dhcp-config)#network 192.168.40.0 255.255.255.0
servidores(dhcp-config)#default-router 192.168.40.1
servidores(dhcp-config)#dns-server 200.0.0.2
servidores(dhcp-config)#exit

DHCP Excluded Addresses

servidores(config)#ip dhcp excluded-address 192.168.10.1 192.168.10.100
servidores(config)#ip dhcp excluded-address 192.168.20.1 192.168.20.100
servidores(config)#ip dhcp excluded-address 192.168.30.1 192.168.30.100
servidores(config)#ip dhcp excluded-address 192.168.40.1 192.168.40.100

NAT Configuration

servidores(config)#ip nat inside source list 1 interface Serial 0/0/0 overload
servidores(config)#access-list 1 permit any
servidores(config)#interface Serial 0/0/0
servidores(config-if)#ip nat outside
servidores(config-if)#exit
servidores(config)#interface GigabitEthernet 0/0
servidores(config-if)#ip nat inside
servidores(config-if)#exit

Access List

servidores(config)#access-list 100 deny tcp host 192.168.20.10 host 200.0.0.2 eq 53
servidores(config)#access-list 100 deny udp host 192.168.20.10 host 200.0.0.2 eq 53
servidores(config)#access-list 100 permit ip any any
servidores(config)#interface Serial 0/0/0
servidores(config-if)#ip access-group 100 out
servidores(config-if)#exit
servidores(config)#do write memory