Professional Documents
Culture Documents
A
Cisco Certified Network Associate
Before we talk about subneting we need know the decimal and Binary and Hexa .
Bin = 128 64 32 16 8 4 2 1
1 1 0 0 1 0 0 0
We calculate the subs which giving us 200 and write under it 1 for each value and 0 for others.
8 4 2 1 / 8 4 2 1
1 1 0 0 / 1 0 0 0
4 / F
Subneting Standards :
Subneting Ex:
255.255.255.0
0 0 0 0 0 0 0 0
1 1 1
1
Ayman Fouad shokry
Ex 2:
255.255.255.0
0 0 0 0 0 0 0 0
1 1 1 1
Ex 3 :
0.255.255.0
0 0 0 0 0 0 0 0
1 1
Host 2^6 – 2 = 64
Network ID:
255.255.255.0
N.ID : 32,64,96,128,160,192,224
8+ 8 + 8 + 3 =27
Ip: 192.168.0.0/27
2
Ayman Fouad shokry
Notes:
- Every network must have N.ID and B.C and ip add between these.
- Ip address can’t use 0 cause its network id.
- Also can’t use 255 cause its broadcast for all network
192.168.0.0 192.168.0.255
Ip which between 0 -> 255 are multicast, host or ip.
3
Ayman Fouad shokry
Switch and hub
Difference between switch and hub .
HUB SWITCH
Slow Fast
Broadcast Unicast
Has no O.S Has an O.S
Ex : 10.0.0.4 in port 4
Notes :
- Sort of Communications:
1- broadcast “ one to all “
- PC ID’s :
1 - Name
2 – Logical address
3 – physical address
4
Ayman Fouad shokry
- What is problems and disadvantages of broadcasting ?
No because as long as we increase B.C Domain’s the security also increase and the traffic be less .
- When hub make broadcast is broadcasting for all ports cause it has 1 B.C Domain.
- Collision happened in hub when 2 ports sent in the same time and that cause of Csma/CD is for
detection not for avoidance . and when happened the whole device stopping .
- When collision happened the whole ports get effected by collision .
In switch no way to happened collision like in hub but it may happened specific ports “ per port “
And it happened while port reciving and it sending in the same time and it effect only on the specific
port
Notes:
5
Ayman Fouad shokry
B.C Domain 2
B.C Collision
Hub 1 1
Switch 1 Per ports
Collision Domain 6
router Per ports Per ports
6
Ayman Fouad shokry
Vlan
Responsible to change the 1 B.C domain to many for less traffic and increase the security .
- Why we must divide the vlan and not just specific subnet and IP’S?
Because when the vlan be just 1 and any device make broadcast it moves to all vlan and gonna be very
easy to any other device see the data .
But even we sperate the vlan to many vlans they can connect to each other by unicast.
7
Ayman Fouad shokry
Basic vlan configuration
1) Create Vlans :
>enable
#Config t
#Vlan 2
#vlan 3
8
Ayman Fouad shokry
Basic Config
Because is the only way for connect devices with different subnets to each other .
- Ethernet types :
1- Ethernet E0 = 10
2- Fast Ethernet F0 = 100
3- Giga Ethernet G0 = 1000
9
Ayman Fouad shokry
- How to give IP to specific port ?
-
S0/0
S Module / Port
First you cant connet from Region A to B without have the right gateway of your connection and be the
same of the router
10
Ayman Fouad shokry
- How can add IP’s for router port ?
>enable
#config t
#int f 0/0
#No shut
#int f0/1
#no shut
#CTR Z
Notes :
11
Ayman Fouad shokry
Passwords
- Line passwords :
>enable
#config t
#line console 0
#password “ ****”
#login
#line aux 0
#password “ ****”
#login
#line vty 0 4
#password “ ****”
#login
#CTR Z
- Enable password :
>enable
#config t
Notes :
Must put password after user mode for secure it from any tries to hacking “ enable mode”
12
Ayman Fouad shokry
Vlan VTP
- When many switches are connected to each other in different floors in building and all have
1B.C domains
- We have 3 different management departments and need connect to each other . “ figure 2 “
T = Trunk : responsible for tag data before pass to other switch “ figure 2 “
13
Ayman Fouad shokry
- Switch configuration :
2 add trunk
Can recive all vlans but without share his data with others .
- We make sperate vlans for stop the 1 B.C domain and increase the security but vlans cant never
connect or ping to other
14
Ayman Fouad shokry
Configuration :
(A)>enable
#config t
#int f 0/1
(B)>enable
#config t
#int f 0/1
(C)>enable
#config t
#int f 0/1
15
Ayman Fouad shokry
(D)>enable
#config t
#int f 0/1
>enable
#config t
#int f 0/2
#int f 0/3
#etc….
16
Ayman Fouad shokry
Router Interface
>enable
#config t
Notes:
#int f0/0 We use router for make all vlans can connect to each
other by unicast and not B.C domain.
#no shut
#int f 0/0.1
#encapsulation Isl/1Q2
#int f0/0.2
#encapsulation isl/1Q 5
#int f 0/0.3
#encapsulation isl/1Q 8
17
Ayman Fouad shokry
Port Security
- Ports security with dynamic and static mac :
You can use port security to restrict a port increase traffic by limiting the mac address’s that are allowed
to send traffic into the port when you assigned secure mac mac address’s to secure port , the port
doesn’t forward increase traffic into the port that has source address’s outside the group of defined
address’s.
Ex :
>enable
#config t
#int f0/0
Can be learned dynamically port security with sticky mac address retain dynamically learned mac
address during a link down condition.
#int f0/0
Notes:
#int f0/0
18
Ayman Fouad shokry
Routing
- Routing :
1- Filling the routing table
2- Choose the best way for route
A- Static route
B- Dynamic route
Static route work only for next hub for more must use dynamic
EX: static
Ex: Dynamic
Notes:
#show ip route
Static is like blind after gives manual setting and happened changes it will never update itself
automatically
19
Ayman Fouad shokry
Routing serials
DTE : Data terminal equipment
DTE DCE
#int s0/0 #int s0/0
#ip add 70.0.0.10 2550.0.0 #ip add 70.0.0.20 2550.0.0
#no shut #no shut
#clock rate 1000000
Notes:
DCE : is responsible port for send rate for the DTE port and if forget or didn’t add clock rate the line
between port and DCE gonna be offline .
When make first serial port DCE the other port be auto DTE
20
Ayman Fouad shokry
Dynamic Routing
Dynamic Routing:
21
Ayman Fouad shokry
Distance vector
RIP IGRP
Notes:
Always IGRP appear first in router config if rip is already installed cause of admin distance is lower
B.W : bandwidth
22
Ayman Fouad shokry
OSPF protocol
Admin distance : 110
Metrics : 10^8/B.W
Update immediately
Notes:
OSPF requires router with strong hardware for can hold the load .
Building 3 tables
1- Neighbor table :
For knew which has ospf its sending hello messages 224.0.0.5 224.0.0.6
2- Topology table :
Is after get ospf of neighbor its join this table and share them networks .
3- Routing table:
23
Ayman Fouad shokry
Configuration :
(A)# router ospf 60
#network 10.0.0.0 0.255.255.255 area 1
#network 192.168.0.0 0 0.0.0.255 area 1
(ABR)#Router ospf 19
#network 172.16.0.0 0.0.255.255 area 0
# router ospf 47
#network 200.0.0.0 0.0.0.255 area 1
24
Ayman Fouad shokry
EIGRP
Cisco only .
Admin distance :90
Metrics:
B.W , load , reliability , delay , mtu
Config :
(A)#router egirp 11
#net 0.0.0.0 0.0.0.0
#net 0.0..0.0 0.0.0.0
#no auto summary
- How it works ?
1) Neighbor :
2) Topology “ database”
Dual choose best 2 path’s > successor route , leasable successor route
3) Routing table :
25
Ayman Fouad shokry
Protocols load balance
- Rip :
- IGRP , EIGRP :
For control the load balance and cause it never be equal … and it not near values .
So we must manage and configuration it set the load balance and choose the most close values to each
others.
Variance 2
Number prefer for time need multiply for the range it gonna chosen .
- Ospf :
Notes :
Admin distance :
Connected =0
Static = 1
EIGRP = 90
IGRP = 100
Ospf = 110
RIP = 120
26
Ayman Fouad shokry
Types of router
Router ID :
1- Router id 1.1.1.1
2- Highest loopback interface :
( )#int lo0
#int lo0
#int f0/0
#int f0/0.1
#int f0/0.2
27
Ayman Fouad shokry
Area Types
Areas:
We use it for decrease the load on routers and for spend less expenses in buy expenses strong routers
and it can exchange the whole data in the same time , if we have 1 area it doesn’t matter give any
number, but if have many areas must give number but after be sure that middle router has 0 number.
For solve problem of looping and echo updating broadcasting and for not break down the system must
make one router DR with highest priority 0-----255
For stop update sending from all routers and make 1 router manage the area.
28
Ayman Fouad shokry
NAT/PAT
NAT :Network address translation
Virtual ip Real ip
10.----------
192.168.------
PAT: port address translation 180.16.--------
172.32.--------
169.234.------- Any other ip
Apipa 169.254.---
Standard : no pc can get virtual ip to connect internet must real ip Auto private ip
add
Notes :
Corporation need buy real ip’s for can login to internet its very expensive per month so better they use
NAT and buy just 1 IP and NAT transit it from local ip to real ip and it can work up to 64000 without
conflicts corporation can buy more than 1 ip and manage NAT with router for close NAT for specific
users which use real ip.
P.S : real ip is not very good in security cause it make hacker work become very easy .
29
Ayman Fouad shokry
Nat ports :
EX: when pc want go yahoo it gonna use pat and nat for change virtual ip to real ip and change port for
don’t happened conflicts.
65535
64000 Free
PAT 80 80 ports
1625
1024
3389 RDT
110 Pops
80 http
69 DHCP
53 DNS
15 SMTP
23 telnet
21/20 PiP
17 VPN
30
Ayman Fouad shokry
CDP
CDP: Cisco discovery protocol.
EX:
10----2<- S0/1 <-- 13.4 <-- R <-- S0/0 f0/0 --> Sw --> 12.1 --> f0/1
31
Ayman Fouad shokry
IP v.4 /6
----.-----.-----.----
XVI Hexa 0---9 A----F
EX : 192.168.1.100
EX:
Ex:
A012:0000:0000:00CD:123C:0000:F280:C88F/112
A012: : CD:123C:0000:F280:C88F/112
Can when Colum start with 0 don’t mention it and start with letter or number after it direct
32
Ayman Fouad shokry
A.C.L
A.C.L: Access control list.
#int s0/0
Notes:
In pervious example was deny user 200.0.0.5 from access “A” and all network to access.
If want add other specific command must delete all access list.
Standard list for control permit / deny on port accessing only but not inside network.
33
Ayman Fouad shokry
2) Extended A.C.L : 100-199
(A) #access list 101 permit / deny protocol source net wildcard distention.
#int s0/0
Notes:
Extended A.C.L control what user or network or device can do inside the host network by add the “
eq”.
P.S : firewall auto deny the while network until you give it manual permit to access.
34
Ayman Fouad shokry
Class full/ classless
Network classes
- Class B : 128---191
172.16.0.0
255.255.0.0
92.168.0.0
255.255.255.0
255.255.255.0
255.0.0.0
Class full cant support with its protocols the classless IP’s because it gonna turn classless IP’s to class full.
35
Ayman Fouad shokry
High availability protocols
HSRP : Hot Standby routing protocol
Features :
1 cisco
Configuration:
Notes:
(1) Make 1 virtual ip to connect 2 lines with internet with the company.
(2) Making priority for lines which has higher value will be active and other standby.
(3) Sending hello message every 2 sec between 2 lines if other didn’t replay 3 sec’s its mean dead
and standby line start be active and take control.
(4) Incase #3 happened control will not back to main line until secondary line be down so we make
this command for keep eye on priority value.
(5) Is keep eye on port outside incase line is down from outside firm it make priority value decrease
to be less than standby line and it take control until back again.
36
Ayman Fouad shokry
- VRRP:
Public standard
No load balance
Config :
- GLBP:
Public standard
Load balance
Config :
37
Ayman Fouad shokry
OSI layers
OSI : open system inter connected .
Application
“app, presentation, session”
Transportation
Network
Physical
Encapsulation:
Application Data
Transportation Segment
Network Packet
Physical Frame
Notes:
DoD is the united states department of defense made this system and they combine 3 layer of
Application , presentation and session in 1 layer and named it application and its five stake protocol or
four stake and combine network and data link.
38
Ayman Fouad shokry
- Sigma structure : S.Port D.Port
Data
S.port D.Port
UDP: user datagram protocol
Data
- Frame Structure :
Notes:
39
Ayman Fouad shokry
Spanning tree protocol “STP”
- Redundant topology :
1- Broadcast storm
2- Mac address table instability
3- Multi frame copies
40
Ayman Fouad shokry
2 non root :
3 Designed port:
Forward state
B.W Cost
10 100
4 root port :
100 19
One per non port bridge
1000 4
Forward state
10000 2
41
Ayman Fouad shokry
Network map
PS:
Switch protocol: token ring but no longer use it
42
Ayman Fouad shokry
WAN
- difference between LAN and WAN :
Every device we have as own personal or to our firm is LAN “switch, router, hub “
Notes:
In beginning before Adsl the only way for connect 2 firm to each other was by telephone but problem
was speed very low only 56k and very high cost cause was paying per minute as normal telephone rate,
And also not safe cause if someone called the telephone line the connection get cut.
1) Circuit switching :
Dial up 56k
2) Point to point
43
Ayman Fouad shokry
Notes :
in 2000 start take internet line from main source buy it and rent for people per month by use D Slam
and then it deliver to A slan and use telephone cable for transfer internet as telephone cable have about
1m free for use and then to splitter to be given 2 cables 1 for routers and other for telephone without
effect on connection or telephone line and it reduce the internet cost and it be more fast .
- Point to point :
ADSL SDSL
D U D U
1 2 1 1
1 4 2 2
1 6 3 3
1 8 4 4
Notes:
In Adsl company buy internet for example 100mb in 1 Internet Company they get customers for take
speed they get unlimited customers and then divided the speed on them no matter the usage or the
capacity on Dslam.
In Adsl they give you for example 1 mb then they give you 1/8 upload only.
Leased line is get speed stable not care about usage or capacity on Dslam and its more expensive cause
of that also it have special port in dslam and telephone cable be data only not voice .
SDSL is much better than Adsl but still shared tech but is given better uploading speed be the same of
downloading.
Radius is for have all information of users on d slam without be controlled from dslam .
44
Ayman Fouad shokry
DHCP is for give ip address.
1) PPP: 2) HDLC
Point to point protocols High data link connection
Config :
Config : (A)#int s0/1
(A)#int s0/1 #encapsulation HDLC
#encapsulation ppp
Doesn’t support authentication
Support authentication pap chap
#ppp authentication pap
Pap- chap
Chap – pap
Notes:
45
Ayman Fouad shokry
Pocket switching WAN:
9- Frame relay :
1 15 15 10---1
2 16 16 10---2
3 17 17 10---3
4 18 18 10---4
5 19 19 10---5
46
Ayman Fouad shokry
1) All in the same subnet :
#no shut
(A)#int s0/0
Etc….
Notes :
47
Ayman Fouad shokry
Wireless
We using wireless for connect devices which cant use cable and also for don’t use a lot of cables in the
firm.
Ex1:
1st we calculate the range of every floor which we want make it covered by internet.
For keep all floors with connection without get cut while moving from floor to other we need make 1
access point and 2 others be repeater from mode inside access point, and must make sure that every
range of A.P have overlap in ranges. For it repeat the same wave in its range. Figure 1
Must make sure that all ranges have the same SSID and PW.
48
Ayman Fouad shokry
Ex 2:
When we have company of 2 different floors or away from each other in the building,
We need make A.P connect to other by cable for they both continue the same range and internet
connection like in figure 2
Types of antennas:
49
Ayman Fouad shokry
Wireless Standards:
Password standards:
50
Ayman Fouad shokry
Cabling
1 Cross cable:
- Pc to pc “ IP “
- R to R “ IP “
- Sw to Sw “ Mac”
- PC to R “ IP “
2 Straight through :
3 Roll over :
Notes:
11 tel 4 bin
51
Ayman Fouad shokry
Cisco Devices Hardware
- RAM:
Is not for speed up the device is just for carry folders or configurations or program from HDD while we
using it and until we save our work it back again to HDD and if we lost power for the device we will lose
all data which are carrying upon ram, that why when we re upgrade the mount of rams device be more
fast cause there more mount of ram for carry.
- NVRAM:
- ROM:
Chiptec has BIOS inside it and mini operating system for it start when power start and check device and
then awake the main operating system for starts and it calls the firmware, and it has boot strap code
0x2102.
- Flash:
Power on:
Backup:
1- Install TFTP
2- #copy flash TFTP HTTP :// 10.0.0.1
3- #copy NVRAM TFTP HTTP :// 10.0.0.1
4- #copy TFTP flash
52
Ayman Fouad shokry
That’s the end of CCNA course .
Ayman Shokry.
53
Ayman Fouad shokry