Professional Documents
Culture Documents
Several types of devices and network connections can be used. For this lab, we will use End
Devices, Switches, Hubs, and Connections. Single click on each group of devices and connections,
to display the various choices.
Move the cursor into topology area. You will notice it turns into a plus “+” sign. Single click in the
topology area and it copies the device.
3
Step 4: Building the Topology – Connecting the Hosts to Hubs and Switches
Adding a Hub: Select a hub, by clicking once on Hubs and once on a Generic hub.
4
Repeat the steps above for PC1 connecting it to Port1 on Hub0. (The actual hub port you choose
does not matter.)
Adding a Switch
Select a switch, by clicking once on Switches and once on a 2950-24 switch. Add the switch
by moving the plus sign "+" below PC2 and PC3 and click once.
Repeat the steps above for PC3 connecting it to Port3 on switch0 on port FastEthernet0/2. (The
actual switch port you choose does not matter.)
Move the cursor over the link light to view the port. Fa means FastEthernet, 100 Mbps Ethernet.
Click on FastEthernet. Add the IP Address to 192.168.1.10. Click once in the Subnet Mask field to
enter the default Subnet Mask 255.255.255.0.
8
Also, notice this is where you can change the Bandwidth (speed) and Duplex of the Ethernet
NIC (Network Interface Card). The default is Auto (auto negotiation), which means the NIC will
negotiate with the hub or switch. The bandwidth and/or duplex can be manually set by removing the
check from the Auto box and choosing the specific option:
Bandwidth – Auto
If the host is connected to a hub or switch port which can do 100 Mbps, then the Ethernet
NIC on the host will choose 100 Mbps (Fast Ethernet). Otherwise, if the hub or switch port can only
do 10 Mbps, then the Ethernet NIC on the host will choose 10 Mbps (Ethernet).
Duplex – Auto
Hub: If the host is connected to a hub, then the Ethernet NIC on the host will choose Half Duplex.
Switch: If the host is connected to a switch, and the switch port is configured as Full Duplex (or
Autonegotiation), then the Ethernet NIC on the host will choose Full Duplex. If the switch port is
configured as Half Duplex, then the Ethernet NIC on the host will choose Half Duplex. (Full Duplex
is a much more efficient option.) The information is automatically saved when entered.
9
Repeat these steps for the other hosts. Use the information below for IP Addresses and Subnet
Masks.
Verify the information: To verify the information that you entered, move the Select tool (arrow)
over each host.
Deleting a Device or Link: To delete a device or link, choose the Delete tool and click on the item
you wish to delete.
Click once on Switch0 and choose FastEthernet0/3 (actual port does not matter).
The link light for switch port FastEthernet0/3 will begin as amber and eventually change to
green as the Spanning Tree Protocol transitions the port to forwarding.
11
Network Simulation
In this part, we are going to use the simulator to simulate traffic between hosts. For this
scenario, delete the switch and host PC3, then connect host PC2 to the hub.
Task 1 Observe the flow of data from PC0 to PC1 by creating network traffic.
a) Switch to Simulation Mode by selecting the tab that is partially hidden behind the Real Time
tab in the bottom right-hand corner. The tab has the icon of a stopwatch on it.
NOTE: When Simulation Mode is chosen, a Simulation Panel will appear on the right side of the
screen. This panel can be moved by moving the cursor at the top of the panel until it changes and
then double-clicking on it. The panel can be restored to the original location by double-clicking on
the Title bar. If the panel is closed, click on the Event List button.
b) Click on Edit Filters, and then select All/None to deselect every filter. Then choose ARP and
ICMP and click in the workspace to close the Edit Filters window.
c) Select a Simple PDU by clicking the closed envelope in the Common Tools Bar on the right.
Move to PC0 and click to establish the source. Move to PC1 and click to establish the
destination. Notice that two envelopes are now positioned beside PC0. This is referred to as a data
traffic scenario. One envelope is an ICMP packet, while the other is an ARP packet. The Event List
in the Simulation Panel will identify exactly which envelope represents ICMP and which represents
an ARP.
12
A scenario may be deleted by clicking on the Delete button in the Scenario panel.
Multiple scenarios can be created by clicking on the New button in the Scenario panel. The
scenarios can then be toggled between without deleting.
d) Select Auto Capture / Play from the Simulation Panel Play Controls. Below the Auto
Capture / Play button is a horizontal bar, with a vertical button that controls the speed of the
simulation. Dragging the button to the right will speed up the simulation, while dragging is to
the left will slow down the simulation.
e) Choose the Reset Simulation button in the Simulation window.
Notice that the ARP envelope is no longer present. This has reset the simulation but has not
cleared any configuration changes or MAC / ARP table entries.
13
Notice that the ICMP envelope moved forward one device and stopped. The Capture /
Forward button will allow you to move the simulation one step at a time.
g) Choose the Power Cycle Devices button on the bottom left, above the device icons.
h) Choose Yes
Notice that both the ICMP and ARP envelopes are now present. The Power Cycle Devices
will clear any configuration changes not saved and clear the MAC / ARP tables.
c) Select the Command Prompt and type the command arp -a.
d) Notice that the MAC address for PC2 is in the ARP table (to view the MAC address of PC2,
click on PC2 and select the Config tab).
e) To examine the ARP tables for PC1 and PC2 in another way, click on the Inspect Tool.
Then click on PC1 and the ARP table will appear in a new window.
14
Note that PC2 does not have an entry in the ARP table yet. Close the ARP Table window.
f) Click on PC2 to view the ARP table. Then close the ARP Table window.
A Cisco router is as a special-purpose computer. It has its own operating system, which is
called the Internetwork Operating System (IOS), as well as files and file systems. Cisco routers use
flash memory, rather than disks, for storing information. Flash storage media is significantly more
expensive and slower than disk storage, but the amount of storage needed to run a router is relatively
small compared to the amount needed to run a general-purpose computer.
Flash storage is similar to Random Access Memory (RAM), but it does not need power to
retain information, so it is called non-volatile RAM (NVRAM). There are other types of non-volatile
solid state storage, such as Erasable Programmable Read Only Memory (EPROM).On most Cisco
routers, the NVRAM area is somewhere between 16 and 256 KB, depending on the size and function
of the router.
There are two important configuration files on any router:
running-config – describes the current running state of the router.
startup-config – is used by router to boot.
c) Move the cursor to the Logical Workspace and click on the desired location.
NOTE: If multiple instances of the same device are needed press and hold the Ctrl button, click on
the desired device, and then release the Ctrl button. A copy of the device will be created and can
now be move to the desired location.
d) Click on the router to bring up the Configuration Window. This window has three modes:
Physical, Config, and CLI (Physical is the default mode).
17
The Physical mode is used to add modules to a device, such as a WAN Interface Card (WIC).
The Config mode is used for basic configuration. Commands are entered in a simple GUI format,
with actual equivalent IOS commands shown in the lower part of the window. The CLI mode allows
for advanced configuration of the device. This mode requires the user to enter the actual IOS
commands just as they would on a live device.
e) In the Physical mode, click on the router power switch to turn the device off.
f) Select the WIC-2T module and drag it to Slot 0 on the router. Then drag a WIC Cover to
Slot1.
NOTE: The Smart Connection can be used to automatically select the appropriate cable type.
However, the user will have no choice as to which interface the connection is assigned to; it will take
the first available appropriate interface.
i) Click on the hub and choose Port 3. Then click on the router and choose interface
FastEthernet 0/0.
NOTE: If the device hangs up in the booting process, save the activity. Then close the application
and reopen the file.
c) Click in the Hostname field and type CISCO_1, and then press the TAB key. Note the
equivalent IOS command is entered in the lower portion of the window.
d) Click on interface FastEthernet 0/0 and assign the IP address 192.168.1.1, then press the
TAB key. Enter the subnet mask 255.255.255.0.
e) Click the Port Status to On to enable the port (no shutdown).
19
3. To view and change system parameters of a Cisco router, you must enter the Privileged
EXEC mode by typing:
Router1> enable
Router1#
Router1# disable
or
Router1# exit
5. To modify system wide configuration parameters, you must enter the global configuration
mode. This mode is entered by typing:
Router1# configure terminal
Router1(config)#
6. To make changes to a network interface, enter the interface configuration mode, with the
command:
The name of the interface is provided as an argument. Here, the network interface that is
configured is FastEthernet0/0.
7. To return from the interface configuration to the global configuration mode, or from the
global configuration mode to the Privileged EXEC mode, use the exit command:
Router1(config-if) # exit
Router1(config)# exit
Router1#
The exit command takes you one step up in the command hierarchy. To directly return to
the Privileged EXEC mode from any configuration mode, use the end command:
Router1(config-if) # end
Router1#
8. To terminate the console session from the User EXEC mode, type logout or exit:
Router1> logout
Router1 con0 is now available
Press RETURN to get started.
Router1> exit
Router1 con0 is now available
Press RETURN to get started.
5. Login Configuration
5.1. Privileged Password
To assign the privileged level password, use enable password command
To enable strong, nonreversible encryption of the privileged password, use the enable secret
command.
You can remove privileged and secret passwords by the following commands:
5.3. Console
Without a console password, the connection can be made via the console connection without
password. To configure the console password,
Router1(config)#
Router1#sh run
!
line con 0
password ciscoconsole
login
line aux 0
line vty 0 4
!
end
Increase the console session timeout, so the connection will not be disconnected.
Router1#conf t
Router1(config)# line console 0
Router1(config-line)# exec-timeout 0 0
Router1(config-line)#exit
Router1(config)#
23
5.4. Telnet
To accept the telnet connection, configure enable secret (or enable password), and
the login must be configured on the VTY.
Router1#conf t
Router1(config)# line vty 0 4
Router1(config-line)# password ciscovty
Router1(config-line)#login
Router1(config-line)#exit
Router1(config)#
Router1(config-line)#exit
Router1(config)#
Router1#sh run
!
line vty 0 4
exec-timeout 0 0
password 7 070C285F4D060F110E
login
!
Now, test the telnet connection from router Router0 to Router1. Create the fastethernet link
between router Router0 and Router1
24
Router0#telnet 192.168.1.2
Trying 192.168.1.2 … Open
User Access Verfication
Password: ciscovty
Router1>
Password:admin
Router1#
6. Create a Copy of the Existing Router Complete with WIC Modules Already in Place
a) Make sure that the existing router is selected (it will be grayed out).
b) In the Main Tool Bar click on the Copy tool.
c) Click on the Paste tool and the copied device will appear in the work area.
f) Click on the RouterA router and connect to the Serial 0/0/0 interface.
25
g) Click on the new router (copy RouterA) and connect to the Serial 0/0/0 interface.
You can remove assigned ip address at interface fast Ethernet f0/0 of router 0 (R0), by the
following command:
Static Routing
The command “ip route” is used to configure static route information for a router to possibly
use in its routing table.
# ip route [destination_network] [mask] [next-hop_address or exitinterface]
Figure 3.1 – Simple Routed Network with one Host on Each Network
Router>en
Router#configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
Router(config)#hostname R0
R0(config)#enable secret router
R0config)#line console 0
R0(config-line)#password cisco
R0(config-line)#login
R0(config-line)#line vty 0 4
R0(config-line)#password cisco
R0(config-line)#login
R0(config-line)#exec-timeout 0 0
R0(config-line)#interface fastethernet 0/0
R0(config-if)#ip address 192.168.0.1 255.255.255.0
R0(config-if)#no shutdown
R0(config-if)#
%LINK-5-CHANGED: Interface FastEthernet0/0, changed state to up
28
R0(config-if)#
%LINK-5-CHANGED: Interface FastEthernet0/1, changed state to up
R0(config-if)#exit
R0(config)#exit
R0#
%SYS-5-CONFIG_I: Configured from console by console
R0#write memory
Building configuration...
[OK]
R0#
To view the IP routing table on a Cisco router, use the “show ip route” command, as shown below.
R0#sh ip route
Codes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP
i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area
C:\>ping 192.168.0.1
Pinging 192.168.0.1 with 32 bytes of data:
Reply from 192.168.0.1: bytes=32 time=1ms TTL=255
Reply from 192.168.0.1: bytes=32 time<1ms TTL=255
Reply from 192.168.0.1: bytes=32 time<1ms TTL=255
C:\>ping 10.0.0.1
Pinging 10.0.0.1 with 32 bytes of data:
Reply from 10.0.0.1: bytes=32 time=1ms TTL=255
Reply from 10.0.0.1: bytes=32 time<1ms TTL=255
Reply from 10.0.0.1: bytes=32 time<1ms TTL=255
C:\>ping 10.0.0.100
Pinging 10.0.0.100 with 32 bytes of data:
Reply from 10.0.0.100: bytes=32 time=1ms TTL=127
Reply from 10.0.0.100: bytes=32 time<1ms TTL=127
Reply from 10.0.0.100: bytes=32 time=1ms TTL=127
C:\>ping 10.0.0.1
C:\>ping 192.168.0.1
C:\>ping 192.168.0.99
Router>en
Router#configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
Router(config)#hostname RA
RA(config)#enable secret router
RA(config)#line console 0
RA(config-line)#password cisco
RA(config-line)#login
RA(config-line)#line vty 0 4
RA(config-line)#password cisco
RA(config-line)#login
RA(config-line)#exec-timeout 0 0
RA(config-line)#interface fastethernet 0/0
RA(config-if)#ip address 10.0.1.1 255.255.255.0
RA(config-if)#no shutdown
RA(config-if)#
%LINK-5-CHANGED: Interface FastEthernet0/0, changed state to up
RA(config-if)#interface fastethernet 0/1
RA(config-if)#ip address 10.0.2.1 255.255.255.0
RA(config-if)#no shutdown
33
RA(config-if)#
%LINK-5-CHANGED: Interface FastEthernet0/1, changed state to up
RA(config-if)#exit
RA(config)#exit
RA#
%SYS-5-CONFIG_I: Configured from console by console
RA#write memory
Building configuration...
[OK]
Router>en
Router#configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
Router(config)#hostname RB
RB(config)#enable secret router
RB(config)#line console 0
RB(config-line)#password cisco
RB(config-line)#login
RB(config-line)#line vty 0 4
RB(config-line)#password cisco
RB(config-line)#login
RB(config-line)#exec-timeout 0 0
RB(config-line)#int f0/0
RB(config-if)#ip address 10.0.2.2 255.255.255.0
RB(config-if)#no shutdown
RB(config-if)#
%LINK-5-CHANGED: Interface FastEthernet0/0, changed state to up
RB(config-if)#
%LINK-5-CHANGED: Interface FastEthernet0/1, changed state to up
RB(config-if)#exit
RB(config)#exit
RB#
%SYS-5-CONFIG_I: Configured from console by console
34
RB#write memory
Building configuration...
[OK]
RB#
Router>en
Router#conf ter
Enter configuration commands, one per line. End with CNTL/Z.
Router(config)#hostname RC
RC(config)#enable secret router
RC(config)#line console 0
RC(config-line)#password cisco
RC(config-line)#login
RC(config-line)#line vty 0 4
RC(config-line)#password cisco
RC(config-line)#login
RC(config-line)#exec-timeout 0 0
RC(config-line)#interface fastethernet 0/0
RC(config-if)#ip address 10.0.3.2 255.255.255.0
RC(config-if)#no shutdown
RC(config-if)#
%LINK-5-CHANGED: Interface FastEthernet0/0, changed state to up
RC(config-if)#
%LINK-5-CHANGED: Interface FastEthernet0/1, changed state to up
RC(config-if)#exit
RC(config)#exit
RC#
RC#write mem
RA#sh ip route
Codes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP
i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area
* - candidate default, U - per-user static route, o - ODR
P - periodic downloaded static route
Gateway of last resort is not set
10.0.0.0/24 is subnetted, 2 subnets
C 10.0.1.0 is directly connected, FastEthernet0/0
C 10.0.2.0 is directly connected, FastEthernet0/1
RB#sh ip route
Codes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP
i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area
* - candidate default, U - per-user static route, o - ODR
P - periodic downloaded static route
RC#sh ip route
Codes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP
i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area
* - candidate default, U - per-user static route, o - ODR
P - periodic downloaded static route
We’ll need to add a static route on RA, telling it that network 10.0.3.0/24 and 10.0.4.0/24 can
be reached via the next hop address of 10.0.2.2.
Again, We need to add a static route on RB, telling it that network 10.0.1.0/24 can be reached
via the next hop address of 10.0.2.1 and 10.0.4.0/24 can be reached via the next hop address of
10.0.3.2.
Again, we need to add a static route on RB, telling it that network 10.0.1.0/24 and 10.0.2.0/24
can be reached via the next hop address of 10.0.3.1.
RC#
Notice that a new entry has been added to the routing table, and is preceded by an “S”. This
designates the route as static.
In order to remove a static route, use the “no” version of the ip route command, followed by
the network address and subnet mask of the route you wish to remove. For example, to remove the
static route to network 10.0.1.0/24 from router C, RC, you would enter:
In the figure, RouterA is connected to many different networks. RouterB, on the other hand,
is only connected to two networks. In order to allow RouterB to get to all of the other
networks shown, we would either need to configure a routing protocol (like RIP or IBRP) or
define static routes to each network.
In this scenario, it might be easier to use default routing to allow RouterB to reach those two
networks. In order to have RouterB forward all traffic destined for other networks to
RouterA, we should configure a gateway of last resort on RouterB. This involves a single
routing table entry, with a destination network of 0.0.0.0 which address literally means “all
networks”. In other words, we are saying that all other networks can be reached via RouterA.
You can only configure default routing on a router that is connected to a stub network, which
means that there is no another router on the connected networks. In other words, there is only
one way in and out.
39
Configuration of RouterA:
Router>en
Router#conf ter
Router(config)#hostname RouterA
RouterA(config)#enable secret router
RouterA(config)#line console 0
RouterA(config-line)#password cisco
RouterA(config-line)#login
RouterA(config-line)#line vty 0 4
RouterA(config-line)#password cisco
RouterA(config-line)#login
RouterA(config-line)#exec-timeout 0 0
RouterA(config-line)#interface fastethernet 0/0
RouterA(config-if)#ip address 10.0.10.1 255.255.255.0
RouterA(config-if)#no shutdown
RouterA(config-if)#interface serial 0/0/0
RouterA(config-if)#ip address 10.0.20.1 255.255.255.0
RouterA(config-if)#no shutdown
RouterA(config-if)#interface serial 0/0/1
RouterA(config-if)#ip address 10.0.30.1 255.255.255.0
RouterA(config-if)#clock rate 64000
RouterA(config-if)#no shutdown
RouterA(config-if)#exit
RouterA(config)#ip route 10.0.40.0 255.255.255.0 10.0.30.2
RouterA(config)#exit
RouterA#write memory
Building configuration...
[OK]
40
Configuration of RouterB:
Router>en
Router#conf ter
Router(config)#hostname RouterB
RouterB(config)#enable secret router
RouterB(config)#line console 0
RouterB(config-line)#password cisco
RouterB(config-line)#login
RouterB(config-line)#line vty 0 4
RouterB(config-line)#password cisco
RouterB(config-line)#login
RouterB(config-line)#exec-timeout 0 0
RouterB(config-line)#interface serial 0/0/0
RouterB(config-if)#ip address 10.0.30.2 255.255.255.0
RouterB(config-if)#no shutdown
RouterB(config)#interface fastethernet 0/0
RouterB(config-if)#ip address 10.0.40.1 255.255.255.0
RouterB(config-if)#no shutdown
RouterB(config-if)#exit
RouterB(config)#exit
RouterB#write memory
Building configuration...
[OK]
RouterB#
To configure the gateway of last resort on RouterB, use the “ip route” command, as shown below.
RouterB#conf ter
RouterB(config)#ip route 0.0.0.0 0.0.0.0 10.0.30.1
If you look at the routing table, you’ll see only the two directly connected networks plus and
*
S , which indicates this entry is a candidate for a default route.
41
RouterB(config)#do sh ip route
Codes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP
i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area
* - candidate default, U - per-user static route, o - ODR
P - periodic downloaded static route
Configuration of RouterC:
Router>en
Router#conf ter
Router(config)#hostname RouterC
RouterC(config)#enable secret router
RouterC(config)#line console 0
RouterC(config-line)#password cisco
RouterC(config-line)#login
RouterC(config-line)#line vty 0 4
RouterC(config-line)#password cisco
RouterC(config-line)#login
RouterC(config-line)#exec-timeout 0 0
RouterC(config-line)#interface serial 0/0/0
RouterC(config-if)#ip address 10.0.20.2 255.255.255.0
RouterC(config-if)#no shutdown
RouterC(config-if)#clock rate 64000
RouterC(config-if)#exit
RouterC(config)#ip route 0.0.0.0 0.0.0.0 10.0.20.1
RouterC(config)#exit
Click on HostA and select the Config tab. Enter the ip address 10.0.10.100, subnet mask
255.255.255.0 and the default gateway address 10.0.10.1.
42
Click on HostB and select the Config tab. Enter the ip address 10.0.40.100, subnet mask
255.255.255.0 and the default gateway address 10.0.40.1.
Router1(config)#int fa0/0
Router1(config-if)#ip address 177.77.77.10 255.255.255.0
Router1(config-if)#no shutdown
Router1(config)#int fa0/1
Router1(config-if)#ip address 203.10.123.1 255.255.255.0
Router1(config-if)#no shutdown
Router1(config)#ip route 192.168.44.0 255.255.255.0 177.77.77.1
Router0 configuration:
Router0(config)#int fa0/1
Router0(config-if)#ip address 177.77.77.1 255.255.255.0
Router0(config-if)#no shut
Router0(config)#int fa0/0
Router0(config-if)#ip address 192.168.44.1 255.255.255.0
Router0(config-if)#no shut
Router0(config)#ip route 200.10.123.0 255.255.255.0 177.77.77.10
Router0(config)#exit
Here access list is used to identify which source IPs are going to be translated using NAT,
and this example allows any device from the 192.168.44.0 network.
Step 3: Create a dynamic NAT IP-address pool, this will hold a list of inside global addresses.
Name of Pool: NAT-POOL
Starting IP address 192.168.44.1
Ending IP address 192.168.44.14
Network mask 255.255.255.240
44
For network address translations, we require to identify at least two interfaces to be our inside
and outside.
Interface fa0/0 will be our inside interface
Interface fa0/1 our outside interface
You can use the following commands for configuring inside and outside interfaces.
Router0(config)#int fa0/0
Router0(config-if)#ip nat inside
Router0(config-if)#int fa0/1
Router0(config-if)#ip nat outside
Step4: Testing NAT translation: When we ping from PC1 to PC0 to R1 our original IP address will
be translated from a 192.168.44.x to 177.77.77.x
You can verify it after the successful ping from PC1 to PC0 and then use the command
“show IP nat translation”.
The command “show ip nat statistics” shows the total number of active translations, NAT
configuration parameters and how many addresses are in the pool, and how many have been
allocated.
45
PC Configuration:
Devices IP address VLAN Default Gateway
PC0 10.0.0.2 10 10.0.0.1
PC1 10.0.0.3 20 20.0.0.1
PC2 10.0.0.4 10 10.0.0.1
PC3 20.0.0.2 20 20.0.0.1
PC4 20.0.0.3 10 10.0.0.1
PC5 20.0.0.4 20 20.0.0.1
Switch0(config)#vlan 10
Switch0(config-vlan)#exit
Switch0(config)#vlan 20
Switch0(config-vlan)#exit
Switch0:
Switch1:
Switch2:
We have successfully assigned VLAN membership. It’s time to test our configuration. To test
this configuration, we will use ping command. ping command is used to test connectivity between
two devices. As per our configuration, devices from same VLAN can communicate. Devices from
different VLANs must not be able to communicate with each other without router.
48
In VLAN10, three PCs with IP addresses 10.0.0.2, 10.0.0.3, and 10.0.0.4 can communicate
with each other’s. At this point, PCs from VLAN10 should not be allowed to access PCs from
VLAN20.
Same as VLAN10, PCs from VLAN20 must be able to communicate with other PCs of same
VLAN while they should not be able to access VLAN10.
Typically routers are configured to receive data on one physical interface and forward that
data from another physical interface based on its configuration. Each VLAN has a layer 3 address
that should be configured as default gateway address on all its devices. In our scenario, we reserved
IP address 10.0.0.1 for VLAN10 and 20.0.0.1 for VLAN20.
With default configuration we need two physical interfaces on router to make this intra
VLAN communication. Due to price of router, it’s not a cost effective solution to use a physical
interface of router for each VLAN. To deal with situation, we use Router on Stick. Router on Stick is
router that supports trunk connection and has an ability to switch frames between the VLANs on this
trunk connection. On this router, single physical interface is sufficient to make connection between
both VLANs.
Configuration of Router0:
Router>en
Router#conf ter
Router(config)#int fa0/0
Router(config-if)#no ip address
Router(config-if)#no shut down
Router(config-if)#exit
Router(config)#interface fa0/0.10
Router(config-subif)#
Router(config-subif)#encapsulation dot1Q 10
Router(config-subif)#ip address 10.0.0.1 255.0.0.0
Router(config-subif)#exit
Router(config)#int fa 0/0.20
Router(config-subif)#encapsulation dot1Q 20
Router(config-subif)#ip address 20.0.0.1 255.0.0.0
Router(config-subif)#exit