You are on page 1of 50

Kolej Kemahiran Tinggi MARA

Petaling Jaya, Selangor

JOB SHEET
PROGRAMME Diploma in Electronic Engineering (Internet of Things)
SESSION January 2023 – May 2023 SEMESTER 3
DFI 20453
CODE & COURSE SHEET NO
Communication Technologies
LECTURER Ts. Suhaimi Zakaria DURATION 4 Weeks

TOPIC Typical Campus Network Architectures and Practices

SUB-TOPIC Designing and implementing a network.

CLO 2 : Design small- and medium-sized campus networks.


TOPIC
LEARNING
CLO 3 : Organise in groups and present the application of communication
OUTCOME
technologies in related engineering fields.

1. Laptop
TOOLS /
2. Network Simulation Software, eNSP
EQUIPMENTS /
3. Network Protocol Analyzer, Wireshark
MATERIALS
4. Virtualization Tool, Virtual Box

DRAWING AND
DATA

KKTMPJ 1 DFI 20453


1. Use static and OSPF routing configurations.
2. The company uses a private Class C IP Addresses, and all users can
access the internet via the campus network.
3. All users can share resources on the network and access the
Web/FTP server.
4. Software Engineering, Hardware Engineering and Quality
Assurance are not permitted to access the HR Department and Top-
INSTRUCTION Level Management Office.
5. Server uses static IP Address and users use dynamic IP Address.
6. The network design must be based on maximum of 4 switches, 2
routers and 2 Access Points only.
7. Do you have any suggestion to provide a further robust and reliable
network architecture for DataStream Dynamics Technologies Sdn.
Bhd? If you have any suggestion, please add on configurations into the
network.

Lab Configuration
Configuration Roadmap

KKTMPJ 2 DFI 20453


WIRED PC Range of User’s IP Address

PC’s in HR Department 192.168.1.1 - 192.168.1.254

PC’s in Top-Level Management 192.168.2.1 - 192.168.2.254

PC’S in Software Engineering 192.168.3.1 - 192.168.3.254

PC’s in Hardware Engineering 192.168.4.1 - 192.168.4.254

PC’s in Quality Assurance 192.168.5.1 - 192.168.5.254

WIRELESS PC Range of Users’s IP Address

Laptop’s in HR Department 192.168.11.1 - 192.168.11.254

Laptop’s in Top-Level Management 192.168.12.1 - 192.168.12.254

Laptop’s in Software Engineering 192.168.13.1 - 192.168.13.254

Laptop’s in Hardware Engineering 192.168.14.1 - 192.168.14.254

Laptop’s in Quality Assurance 192.168.15.1 - 192.168.15.254

KKTMPJ 3 DFI 20453


Configuration Procedure
Step 1: Name all the devices.

KKTMPJ 4 DFI 20453


Step 2: Configure the VLAN for S2 and S3.
S2:

S3:

KKTMPJ 5 DFI 20453


Step 3: Configure VLAN on R1
Establish the VLAN100, allow the VLAN to pass through:

Step 4: Configure VLAN 10,20,30,40,50 and 100 on S1


Configure VLAN 10,20,30,40,50,100 to through the S1, configure the type of
interface that can pass through it:

KKTMPJ 6 DFI 20453


Step 5: Configure VLANIF 10,20,30,40,50,100
Configure the interface for S1, setup the IP address, create OSPF for VLAN
10,20,30,40,50,100:

KKTMPJ 7 DFI 20453


Step 6: Configure AC and AP
Configure VLAN:
S1:

AC:

S2:

S3:

KKTMPJ 8 DFI 20453


IP address on S1 and AC:

KKTMPJ 9 DFI 20453


Configure DHCP:

KKTMPJ 10 DFI 20453


Create AP group by rename it ap-group1:

Create regulatory domain profile set the country code:

Bind the regulatory domain profile to AP group:

Establish CAPWAP tunnels:

Import AP to the AC and add AP to AP group ap-group1:

MAC Address : 00:e0:fc:59:24:40

MAC Address : 00:e0:fc:6d:2b:60

KKTMPJ 11 DFI 20453


Display the AP:

VLAN11:

VLAN12:

VLAN13:

VLAN14:

VLAN15:

VLAN11:

KKTMPJ 12 DFI 20453


VLAN12:

VLAN13:

VLAN14:

VLAN15:

VLAN11:

VLAN12:

KKTMPJ 13 DFI 20453


VLAN13:

VLAN14:

VLAN15:

KKTMPJ 14 DFI 20453


Configure VAP profile HCIA-WLAN to radio 0 and 1 of AP in AP group:

Configure OSPF VLAN 10,20,30,40,50,100

KKTMPJ 15 DFI 20453


Step 7: Configure DHCP relay
Configure DHCP on VLANIF 10,20,30,40,50 and set relay Server IP address:

KKTMPJ 16 DFI 20453


Step 8: Configure DHCP server
IP Pool HR=VLAN10, IP Pool TOPLEVEL=VLAN20, IP Pool SOFTWARE=VLAN30,
IP Pool HARDWARE=VLAN40, IP Pool QUALITY=VLAN50. Create OSPF VLAN
100, set DHCP as global, set IP address and interface VLAN100:

Configure VLANIF 100 AND OSPF:

KKTMPJ 17 DFI 20453


Step 9: Enable Access for user to Web / FTP
Interface VLAN200, VALNIF200:

Interface VLAN300:

Configure interface G0/0/1 on R1:

Configure interface G0/0/1 and VLANIF 300 on R2:

KKTMPJ 18 DFI 20453


Configure IP Static Route on R1:

Configure IP Static Route on R2:

Step 10: Configure network Address Translation


Configure IP static route on S1:

Configure NAT on R1:

Step 11: Restrict the access for VLAN 30,40,50,10,20


Set ACL for VLAN30,40,50, filter traffic using ACL VLAN100:

KKTMPJ 19 DFI 20453


Step 12: Enable DHCP as Global

Step 13: Server, Internet, Cloud and PC


Computer(HR):

KKTMPJ 20 DFI 20453


Laptop(HR):

Computer(TOPLEVEL):

KKTMPJ 21 DFI 20453


Laptop(TOPLEVEL):

Computer(SOFTWARE):

KKTMPJ 22 DFI 20453


Laptop(SOFTWARE):

Computer(HARDWARE):

KKTMPJ 23 DFI 20453


Laptop(HARDWARE):

Computer(QUALITY):

KKTMPJ 24 DFI 20453


Laptop(QUALITY):

SERVER:

KKTMPJ 25 DFI 20453


CLOUD:

----End

KKTMPJ 26 DFI 20453


VERIFICATION

1. S1 – display ip routing table

2. S2 – display ip routing table

No Display ip routing table S3

KKTMPJ 27 DFI 20453


VERIFICATION
3. R1 – display ip routing table

4. R2 – display ip routing table

KKTMPJ 28 DFI 20453


VERIFICATION
5. Ping all departments PC to internet.
i. HR Department

ii. TOP LEVEL Management

KKTMPJ 29 DFI 20453


VERIFICATION
iii. Software Engineering

iv. Hardware Engineering

KKTMPJ 30 DFI 20453


VERIFICATION
v. Quality Assurance

6. Ping all departments PC to WEB/FTP server


i. HR Department

KKTMPJ 31 DFI 20453


VERIFICATION
ii. TOP LEVEL Management

iii. Software Engineering

KKTMPJ 32 DFI 20453


VERIFICATION
iv. Hardware Engineering

v. Quality Assurance

KKTMPJ 33 DFI 20453


VERIFICATION
7. Every departments ping to each other in two layers
i. HR Department

KKTMPJ 34 DFI 20453


VERIFICATION
ii. TOP LEVEL Management

KKTMPJ 35 DFI 20453


VERIFICATION
iii. Software Engineering

KKTMPJ 36 DFI 20453


VERIFICATION
iv. Hardware Engineering

KKTMPJ 37 DFI 20453


VERIFICATION
v. Quality Assurance

KKTMPJ 38 DFI 20453


VERIFICATION
8. Every departments ping to each other in three layers
i. HR Department

KKTMPJ 39 DFI 20453


VERIFICATION
ii. TOP LEVEL Management

KKTMPJ 40 DFI 20453


VERIFICATION
iii. Software Engineering

KKTMPJ 41 DFI 20453


VERIFICATION

KKTMPJ 42 DFI 20453


VERIFICATION
iv. Hardware Engineering

KKTMPJ 43 DFI 20453


VERIFICATION

KKTMPJ 44 DFI 20453


VERIFICATION
v. Quality Assurance

KKTMPJ 45 DFI 20453


VERIFICATION

KKTMPJ 46 DFI 20453


VERIFICATION
Software Engineering cannot ping HR Department and TOP LEVEL Management

KKTMPJ 47 DFI 20453


VERIFICATION
Hardware Engineering cannot ping HR Department and TOP LEVEL Management

KKTMPJ 48 DFI 20453


VERIFICATION
Quality Assurance cannot ping HR Department and TOP LEVEL Management

KKTMPJ 49 DFI 20453


CONCLUSION

In conclusion, we have designed a VLSM address scheme for DataStream Dynamics


Technologies Sdn. Bhd. network that meets the company's requirements. We have divided
the private Class C IP address range into subnets using VLSM, based on the number of
hosts required in each department. We have also assigned IP addresses to each
department and device in the network, including the default gateway, DHCP range, and
switch and access point IPs. The network design includes static and OSPF routing
configurations, access to shared resources and the Web/FTP server, and restrictions on
access to certain departments. To provide further robust and reliable network architecture,
we could consider implementing redundancy through the use of redundant links, switches,
and routers, as well as implementing security measures such as firewalls, VPNs, and
network segmentation.

KKTMPJ 50 DFI 20453

You might also like