Professional Documents
Culture Documents
RST 3
65469441 Page 1 / 17
Design the network using the diagra m and accompanying narrative. Simulate and test the network using the network simulator tool Packet Tracer. Correctly configure single-area OSPF Correctly configure VLANs and 802.1q trunking Correctly configure Frame Relay Correctly configure DHCP Correctly configure NATand PAT Create and apply access control lists on the appropriate routers and interfaces Verify that all configurations areoperational and functioning according to the scenario guidelines Provide documentation and configuration files as detailed in the following sections.
65469441 Page 2 / 17
Internet
200.1.1.1/24
OSPF Area 0
Engineering Server
The regional electrical utilitycompany, South West Electrical,needs a network to be designed and implemented. The company supplies electricity over a wide area . Its headquarters is in Exeter with a callcentre in Plymouth connected via leased line. The Engineering division operates out of Poole whilst the Sales team have a Sales Office in Bournemouth. The Bournemouth and Poole branches are connected to the companys headquarters in Exeterusing Frame Relay because of co st considerations. The companys networks communicate using the open standard routing protocol OSPF. The company wants to use private addresses throughout for security reasons and DHCP for the LANs. Access to the Internet is provided from Exeter using network address translation.The company also wishes to limit Internet access to Web traffic while allowingmultiple protocols within its own WAN. A set of servers are provided at the companys headquarters in Exeter although the Enginee ring division has it own server connectedto its own network. Due to the size and complexity, the company wants to create VLANs to control broadcasts, enhance security, and logically group users.
65469441 Page 3 / 17
Requirements The company has 6 departments / divisions Personnel, Accounts, Engineering, Sales, Customer Services and IT Support. The offsite sales team are provided with wireless laptops for access to the sales network via the Bournemouth branch. Your design must provide for 4 employees in the Personnel department. 5 employees in the Accounts department. 30 employees in the Engineering division at Poole 50 wired workstations for Customer Services at Plymouth. 50 laptops for external mobile Sales staff for access via Bournemouth office. 5 employees (maximum) in IT Support with direct access at Exeter. Lifetime max of two servers for Accounts and Personnel and two General Servers for all departments and divisions. Expect 100% growth of current IP requirements when determining size of subnets. All networking devices must have IP addresses. Use the private class B 172.20.0.0 network for internal addressing throughout the companys WAN and LAN networks. Use VLSM for IP addressing. Use subnet 200.1.1.0/24 for connection to the Internet via the HQ router in Exeter. There is a DNS server at address 198.198.1.2/24 connected to the HQ router. Security between the various networks is required to be controlled via firewalls (access control lists). One public address, 199.199.199.1, has been provided external access to the Internet for the company.
65469441 Page 4 / 17
172.21.0.0
255.255.255.128
172.20.0.1.28 255.255.255.128 172.20.0.0 172.20.1.64 172.20.1.80 172.20.1.96 255.255.255.192 255.255.255.224 255.255.255.224 255.255.255.224
65469441 Page 5 / 17
Below is a sample layout for routers. Reproduce this for each of the four routers and one for the ISP router. Router Name: HQ Network Description Name and Purpose Interface/Sub Interface Type/Number Serial0/0/0 Serial0/1/0 Serial0/3/0 FastEthernet0/0 FastEthernet0/1.1 FastEthernet0/1.10 FastEthernet0/1.20 FastEthernet0/1.30 FastEthernet0/1.99 Router Name: Call Center Network Description Name and Purpose Interface/Sub Interface Type/Number Serial0/0/0 FastEthernet0/0 Router Name: Engineering Network Description Name and Purpose Interface/Sub Interface Type/Number FastEthernet0/0 Serial0/0/0 Router Name: Sales frame-relay VLAN Encapsulation Network Number 1 2 Interface IP Address Subnet Mask VLAN Encapsulation Network Interface Number IP Address ppp 1 2 Subnet Mask dot1Q 1 dot1Q 10 dot1Q 20 dot1Q 30 dot1Q 99 native VLAN Encapsulation Network Number frame-relay ppp 1 2 3 4 5 6 7 8 9 Interface IP Address 172.20.0.4 172.20.0.9 200.1.1.1 198.198.1.1 Subnet Mask
172.20.1.161 255.255.255.224
65469441 Page 6 / 17
255.255.255.0 255.255.255.0
default
255.255.255.128
There are three switches with the distribution switch connected to the router. All switches are interconnected via two trunk links for robustness. Below is the sample layout for the tables for the switches. Distribution Switch Name: DSW0 Switch IP address: 172.20.1.163 VLAN: 99 Port/Number FastEthernet0/1 FastEthernet0/2 FastEthernet0/3 FastEthernet0/4 FastEthernet0/5 Descripti on and Purpose Speed 100 Mbps 100 Mbps 100 Mbps 100 Mbps 100 Mbps Duplex FullDuplex FullDuplex FullDuplex FullDuplex FullDuplex VLANs allowed Switchp ort Type trunk native trunk native trunk native trunk native trunk native Encapsulati on (if needed)
65469441 Page 7 / 17
VLAN:99
Duplex Network Number Subnet Mask V L A N Switchport Type
100M bps 100M bps 100M bps 100M bps 100M bps 100M bps 100M bps 100M bps 100M bps
99 99 99 99 20 99 20 30 10 30
trunk trunk trunk trunk access trunk access access access access
65469441 Page 8 / 17
65469441 Page 9 / 17
Subnet Mask 255.255.255.224 255.255.255.224 255.255.255.224 255.255.255.0 255.255.255.0 255.255.255.224 255.255.255.224 255.255.255.224 255.255.255.128 255.255.255.192
Gateway 172.20.1.129 172.20.1.97 172.20.1.65 198.198.1.1 210.1.1.1 172.20.1.97 172.20.1.129 172.20.1.65 172.21.0.1 172.20.1.1
The tables and supporting text will be part of the documentation delivered to the company. Before you commence with the implementation the logical diagram and tables need to be approved by the company. Instructors Signature: ______________________Date:_______________ MAYO 25 For this Case Study, implement your design in phases with Packet Tracer and check out any particular aspects not supported by Packet Tracer with the equipment.
65469441 Page 10 / 17
65469441 Page 11 / 17
1.
Configure Switches 1.1 Name the switches 1.2 On all switches, configure a login password as cisco, an encrypted privileged password as class, and provide secure telnet login capability. All passwords should be encrypted. 1.3 Assign single ports as access ports with port security for each VLAN on both access switches. 1.4 Create trunk ports assigning the management VLAN as the native VLAN. 1.5 Configure VTP on all switches with version 2, domain to SWElectrical and password cisco with the distribution switch in server mode and the access switches in client mode. 1.6 Create the VLANs as in your design for Personnel, Accounts and another for the General Server on the distribution switch and propagate with VTP. 1.7 Create a Management VLAN for the switches. 1.8 Connect the IT Management PC and assign a static IP address. Configure HQ Router for VLANs 1.1 Name the router and create the sub-interfaces 1.2 Configure the DHCP pools for the VLANs with excluded address ranges for the servers and gateways. 1.3 Connect the servers and PCs as in your design to the access switches. DO NOT connect the HQ router to any other routers.
Tests
1. Has the VLAN database propagated to the access switches? [Y/N] __Y__ 2. List the configurations received by the PCs from the DHCP pools?
ip dhcp pool HQ0/10.1 network 172.20.1.64 255.255.255.224 default-router 172.20.1.65 dns-server 198.198.1.2 ip dhcp pool HQ0/1.20 network 172.20.1.128 255.255.255.224 default-router 172.20.1.129 dns-server 198.198.1.2 ip dhcp pool HQ0/1.30 network 172.20.1.96 255.255.255.224 default-router 172.20.1.97 dns-server 198.198.1.2 _____________________________________________________________
3. Can the ITManagement PC ping all the switches, PCs and servers? [Y/N] _Y__ 4. List the routing table, vlan database and vtp settings.
65469441 Page 12 / 17
5. Can the router:ping the switches [Y/N]? __Y___ ping the servers [Y/N]? ___Y___ ping the PCs [Y/N]? ___Y____ Record the MAC addresses learned on each access port across all switches. Record the configurations of the switches, and the router.
65469441 Page 13 / 17
1.3 1.4
2
Configure Frame Relay between the HQ router and the routers at Poole and Bournemouth.
2.1 2.2
2.3
Configure a Frame Relay switch with connections between serial port 0 to serial ports 1 and 2. (Packet Tracer provides sublinks for this). Connect the serial WAN link between the HQ router and serial port 0 on the frame relay switch. Connect serial WAN links from the frame relay switch to the Poole and Bournemouth routers. Configure the WAN links and assign IP addresses as per the design.
2.4
3
Configure the Poole and Bournemouth LANs. Configure a wireless access point with SSID SWElectrical and WEP key 0123456789 on the Bournemouth LAN and a wireless PC. Add OSPF area 0 routing protocol to the HQ, Plymouth, Poole and Bournemouth routers. Provide a website over the Internet link for browsing from any PC. 6.1 Provide a default route from the HQ to the ISP and static route from the ISP to the company HQ. 6.2 6.3 6.4 Create a DNS server at 198.198.1.2 connected to the HQ router on an Ethernet port. Setup the appropriate services for browsing to the website example.com at the ISP. Propagate the default route within OSPF.
4 5 6
Tests
1. Can the HQ router ping the Poole and Bournemouth routers? [Y/N] ___ 2. Check the HQ routing table. Can the HQ router see the LANs of Plymouth, Poole and
Bournemouth? [Y/N] ____
3. Can the PCs on the LANs of Poole and Bournemouth reach the servers on the HQ LAN network?
[Y/N] ____
4. Can the IT Support PC reach the PCs at Plymouth, Poole and Bournemouth? [Y/N] ___ 65469441 Page 14 / 17
65469441 Page 15 / 17
2.2
2.3
2.4 2.5
Tests
1. Can the Sales, Engineering, Call-Centre PCs browse to the ISP website? [Y/N] ___ 2. Can Finance and Personnel and IT Support browse to the ISP website? [Y/N] ___ 3. Can Finance reach Personnels server but not vice versa? [Y/N] 4. Is access denied between subnetworks except for IT Support? [Y/N] ____ 5. Can the PCs on the LANs all reach their own servers via with FTP? [Y/N] ____
Record the ACL configurations of routers for (1) HQ, (2) Plymouth, (3) Poole and (4) Bournemouth. Record the routing tables of these routers. Record the Network Address Translations. Log all ACL activity.
65469441 Page 16 / 17
Phase 5: Verification and Testing (20 marks) Use the following instructions to co mplete Phase 5: Verify communication between variou s hosts in the network. Troubleshoot and fix any proble ms in the network until it works properly. Docu ment the results of the tests in the table below: Source Host on Sales Host on Engineering Host on Personnel Host on Finance Host on IT support Host on IT Support Destination example.com example.com example.com example.com example.com Host on Sales, Engineering, Personnel, Finance. All switches Host on IT Support To Internet Protocol HTTP HTTP HTTP HTTP HTTP ping Expected Result Success Success Success Success Success Success x 5 Signed Date
Host on Sales, Engineering, Finance and Personnel Host on Sales, Engineering, Finance and Personnel Host on Finance Host on Personnel Host on Engineering Host on Sales Host on Finance Host on Personnel Host on Engineering Host on Sales
Failure x 4 Failure x 4
Finance server, Personnel Server Personnel server General server Sales server Finance server Personnel server General server General server
FTP or HTTP FTP or HTTP FTP or HTTP FTP or HTTP ping ping ping ping
Record and log all ACL output and ping, browser and ping tests for future reference.
65469441 Page 17 / 17