You are on page 1of 4

Guía de Laboratorio: Redes Vlan

Configuración de una Red institucional con VLAN

En este ejercicio vamos a configurar la red de un campus universitario o un instituto con VLAN:
 Vamos a tener tres Vlans:
 PRESUPUESTO: 192.168.5.0/24
 RRHH: 192.168.10.0/24
 PLANIFICACION: 192.168.15.0/24
 Configuremos:
 Un Switch de acceso para cada planta
 Un Switch troncal para comunicar los switch de acceso con el router
 Un Router para intercomunicar las vlans y darles salida al exterior

CONFIGURAR RED VLANS

SWITCH Nº 1
Switch>enable
Switch#conf ter
Enter configuration commands, one per line. End with CNTL/Z.
Switch(config)#vlan 5
Switch(config-vlan)#name PRESUPUESTO
Switch(config-vlan)#vlan 10
Switch(config-vlan)#name RRHH
Switch(config-vlan)#vlan 15
Switch(config-vlan)#name PLANIFICACION
Switch(config-vlan)#EXIT
Switch(config)#int rang fa0/1-4
Switch(config-if-range)#sw mode trunk
Switch(config-if-range)#exit
Switch(config)#exit
Switch#sh vlan brief
Switch#copy running-config startup-config
Destination filename [startup-config]?
Building configuration...
[OK]

SWITCH Nº 2 Y 3
Switch>enable
Switch#conf ter
Enter configuration commands, one per line. End with CNTL/Z.
Switch(config)#vlan 5
Switch(config-vlan)#name PRESUPUESTO
Switch(config-vlan)#vlan 10
Switch(config-vlan)#name RRHH
Switch(config-vlan)#vlan 15
Switch(config-vlan)#name PLANIFICACION
Switch(config-vlan)#exit
Switch(config)#int rang fa0/1-5
Switch(config-if-range)#sw mode access
Switch(config-if-range)#sw access vlan 10
Switch(config-if-range)#int rang fa0/6-10
Switch(config-if-range)#sw mode access
Switch(config-if-range)#sw access vlan 20
Switch(config-if-range)#int rang fa0/11-23
Switch(config-if-range)#sw mode access
Switch(config-if-range)#sw access vlan 30
Switch(config-if-range)#exit
Switch(config)#int fa0/24
Switch(config-if)#sw mode trunk
Switch(config-if)#exit
Switch(config)#exit
Switch#sh vlan brief

Switch#copy running-config startup-config


Destination filename [startup-config]?
Building configuration...
[OK]
Switch#

CONFIGURAR ROUTER
Router>
Router#enable
Router#config ter
Enter configuration commands, one per line. End with CNTL/Z.
Router(config)#int fa0/0.1
Router(config-subif)#encapsulation dot1q 5
Router(config-subif)#ip address 192.168.5.1 255.255.255.0
Router(config-subif)#exit
Router(config)#int fa0/0.2
Router(config-subif)#encapsulation dot1q 10
Router(config-subif)#ip address 192.168.10.1 255.255.255.0
Router(config-subif)#exit
Router(config)#int fa0/0.3
Router(config-subif)#encapsulation dot1q 15
Router(config-subif)#ip address 192.168.15.1 255.255.255.0
Router(config-subif)#exit
Router(config)#int fa0/0
Router(config-if)#no shutdown
Router(config-if)#exit
Router(config)#exit
Router# copy running-config startup-config
Destination filename [startup-config]?
Building configuration...
[OK]
Router#
Configurar las ACL (Access List Control), de tal modo, va
a denegar la comunicación con las vlans diferentes

Router#
Router#config ter
Enter configuration commands, one per line. End with CNTL/Z.
Router(config)#access-list 5 deny 192.168.10.0 0.0.0.255
Router(config)#access-list 5 deny 192.168.15.0 0.0.0.255
Router(config)#access-list 5 permit any
Router(config)#int fa0/0.1
Router(config-subif)#ip access-group 5 out
Router(config-subif)#exit
Router(config)#access-list 10 deny 192.168.5.0 0.0.0.255
Router(config)#access-list 10 deny 192.168.15.0 0.0.0.255
Router(config)#access-list 10 permit any
Router(config)#access-list 15 deny 192.168.5.0 0.0.0.255
Router(config)#access-list 15 deny 192.168.10.0 0.0.0.255
Router(config)#access-list 15 permit any
Router(config)#int fa0/0.2
Router(config-subif)#ip access-group 10 out
Router(config-subif)#exit
Router(config)#int fa0/0.3
Router(config-subif)#ip access-group 15 out
Router(config-subif)#exit
Router(config)#exit
Router#
Router#sh access-list (PARA VERIFICAR LOS ACCESS LIST)
Standard IP access list 5
deny 192.168.10.0 0.0.0.255
deny 192.168.15.0 0.0.0.255
permit any
Standard IP access list 10
deny 192.168.5.0 0.0.0.255
deny 192.168.15.0 0.0.0.255
permit any
Standard IP access list 15
deny 192.168.5.0 0.0.0.255
deny 192.168.10.0 0.0.0.255
permit any
Router#copy running-config startup-config
Destination filename [startup-config]?
Building configuration...
[OK]
Router#

CONFIGURAR PARA SERVIDOR


Router#
Router#config ter
Enter configuration commands, one per line. End with CNTL/Z.
Router(config)#int fa0/1
Router(config-if)#ip address 192.168.100.1 255.255.255.0
Router(config-if)#no shutdown

Router(config-if)#
%LINK-5-CHANGED: Interface FastEthernet0/1, changed state to up

Router(config-if)#exit
Router(config)#ip dhcp pool PRESUPUESTO
Router(dhcp-config)#network 192.168.5.0 255.255.255.0
Router(dhcp-config)#default-router 192.168.5.1
Router(dhcp-config)#dns-server 192.168.100.254
Router(dhcp-config)#exit
Router(config)#ip dhcp pool RRHH
Router(dhcp-config)#network 192.168.10.0 255.255.255.0
Router(dhcp-config)#default-router 192.168.10.1
Router(dhcp-config)#dns-server 192.168.100.254
Router(dhcp-config)#exit
Router(config)#ip dhcp pool PLANIFICACION
Router(dhcp-config)#network 192.168.15.0 255.255.255.0
Router(dhcp-config)#default-router 192.168.15.1
Router(dhcp-config)#dns-server 192.168.100.254
Router(dhcp-config)#exit
Router(config)#exit
Router#copy running-config startup-config
Destination filename [startup-config]?
Building configuration...
[OK]
Router#

You might also like