Professional Documents
Culture Documents
En este ejercicio vamos a configurar la red de un campus universitario o un instituto con VLAN:
Vamos a tener tres Vlans:
PRESUPUESTO: 192.168.5.0/24
RRHH: 192.168.10.0/24
PLANIFICACION: 192.168.15.0/24
Configuremos:
Un Switch de acceso para cada planta
Un Switch troncal para comunicar los switch de acceso con el router
Un Router para intercomunicar las vlans y darles salida al exterior
SWITCH Nº 1
Switch>enable
Switch#conf ter
Enter configuration commands, one per line. End with CNTL/Z.
Switch(config)#vlan 5
Switch(config-vlan)#name PRESUPUESTO
Switch(config-vlan)#vlan 10
Switch(config-vlan)#name RRHH
Switch(config-vlan)#vlan 15
Switch(config-vlan)#name PLANIFICACION
Switch(config-vlan)#EXIT
Switch(config)#int rang fa0/1-4
Switch(config-if-range)#sw mode trunk
Switch(config-if-range)#exit
Switch(config)#exit
Switch#sh vlan brief
Switch#copy running-config startup-config
Destination filename [startup-config]?
Building configuration...
[OK]
SWITCH Nº 2 Y 3
Switch>enable
Switch#conf ter
Enter configuration commands, one per line. End with CNTL/Z.
Switch(config)#vlan 5
Switch(config-vlan)#name PRESUPUESTO
Switch(config-vlan)#vlan 10
Switch(config-vlan)#name RRHH
Switch(config-vlan)#vlan 15
Switch(config-vlan)#name PLANIFICACION
Switch(config-vlan)#exit
Switch(config)#int rang fa0/1-5
Switch(config-if-range)#sw mode access
Switch(config-if-range)#sw access vlan 10
Switch(config-if-range)#int rang fa0/6-10
Switch(config-if-range)#sw mode access
Switch(config-if-range)#sw access vlan 20
Switch(config-if-range)#int rang fa0/11-23
Switch(config-if-range)#sw mode access
Switch(config-if-range)#sw access vlan 30
Switch(config-if-range)#exit
Switch(config)#int fa0/24
Switch(config-if)#sw mode trunk
Switch(config-if)#exit
Switch(config)#exit
Switch#sh vlan brief
CONFIGURAR ROUTER
Router>
Router#enable
Router#config ter
Enter configuration commands, one per line. End with CNTL/Z.
Router(config)#int fa0/0.1
Router(config-subif)#encapsulation dot1q 5
Router(config-subif)#ip address 192.168.5.1 255.255.255.0
Router(config-subif)#exit
Router(config)#int fa0/0.2
Router(config-subif)#encapsulation dot1q 10
Router(config-subif)#ip address 192.168.10.1 255.255.255.0
Router(config-subif)#exit
Router(config)#int fa0/0.3
Router(config-subif)#encapsulation dot1q 15
Router(config-subif)#ip address 192.168.15.1 255.255.255.0
Router(config-subif)#exit
Router(config)#int fa0/0
Router(config-if)#no shutdown
Router(config-if)#exit
Router(config)#exit
Router# copy running-config startup-config
Destination filename [startup-config]?
Building configuration...
[OK]
Router#
Configurar las ACL (Access List Control), de tal modo, va
a denegar la comunicación con las vlans diferentes
Router#
Router#config ter
Enter configuration commands, one per line. End with CNTL/Z.
Router(config)#access-list 5 deny 192.168.10.0 0.0.0.255
Router(config)#access-list 5 deny 192.168.15.0 0.0.0.255
Router(config)#access-list 5 permit any
Router(config)#int fa0/0.1
Router(config-subif)#ip access-group 5 out
Router(config-subif)#exit
Router(config)#access-list 10 deny 192.168.5.0 0.0.0.255
Router(config)#access-list 10 deny 192.168.15.0 0.0.0.255
Router(config)#access-list 10 permit any
Router(config)#access-list 15 deny 192.168.5.0 0.0.0.255
Router(config)#access-list 15 deny 192.168.10.0 0.0.0.255
Router(config)#access-list 15 permit any
Router(config)#int fa0/0.2
Router(config-subif)#ip access-group 10 out
Router(config-subif)#exit
Router(config)#int fa0/0.3
Router(config-subif)#ip access-group 15 out
Router(config-subif)#exit
Router(config)#exit
Router#
Router#sh access-list (PARA VERIFICAR LOS ACCESS LIST)
Standard IP access list 5
deny 192.168.10.0 0.0.0.255
deny 192.168.15.0 0.0.0.255
permit any
Standard IP access list 10
deny 192.168.5.0 0.0.0.255
deny 192.168.15.0 0.0.0.255
permit any
Standard IP access list 15
deny 192.168.5.0 0.0.0.255
deny 192.168.10.0 0.0.0.255
permit any
Router#copy running-config startup-config
Destination filename [startup-config]?
Building configuration...
[OK]
Router#
Router(config-if)#
%LINK-5-CHANGED: Interface FastEthernet0/1, changed state to up
Router(config-if)#exit
Router(config)#ip dhcp pool PRESUPUESTO
Router(dhcp-config)#network 192.168.5.0 255.255.255.0
Router(dhcp-config)#default-router 192.168.5.1
Router(dhcp-config)#dns-server 192.168.100.254
Router(dhcp-config)#exit
Router(config)#ip dhcp pool RRHH
Router(dhcp-config)#network 192.168.10.0 255.255.255.0
Router(dhcp-config)#default-router 192.168.10.1
Router(dhcp-config)#dns-server 192.168.100.254
Router(dhcp-config)#exit
Router(config)#ip dhcp pool PLANIFICACION
Router(dhcp-config)#network 192.168.15.0 255.255.255.0
Router(dhcp-config)#default-router 192.168.15.1
Router(dhcp-config)#dns-server 192.168.100.254
Router(dhcp-config)#exit
Router(config)#exit
Router#copy running-config startup-config
Destination filename [startup-config]?
Building configuration...
[OK]
Router#