You are on page 1of 2

CCNADiscovery:DesigningandSupportingComputerNetworks Chapter5CaseStudy CreatingtheNetworkDesign IntroductionandScenario Yourenterprisenetworknowappearstobestable,andyouaresatisfiedwiththeVLANsetup.However, althoughtheVLANstructureitselfgivesacertainlevelofsecuritytothenetwork,youfeelthatextra securitywouldprobablybejustified.Bettersafethansorryappearstobeyourmotto!

ThedefaultlevelsubnetinyourstructureisVLAN10,andyouwishtomakecertainthatusersonthis VLANdonothaveanyaccesstohostsonVLANs20or30.Inaddition,usersinVLAN30haveaccessto certainrestricteddocumentation,andyouwanttomakecertainthatthereisnoleakageofinformation tothepublicInternet.InternetaccessfromVLAN30hostsisnotrequired.However,itisessentialthat VLAN30hostshaveintranetaccess. Youarealsoconcernedaboutoutsideusersgettingaccesstotheinternalservers.Eventhoughyouusea privateaddressrangeinyourinternalnetwork,youwishtoincludefurtherrestrictionsonanyoutside hosttryingtomakeanHTTPconnectiontoyourinternalwebserver.


2009 Cisco Learning Institute

CCNADiscovery:DesigningandSupportingComputerNetworks Chapter5CaseStudy Tasks UsetheassociatedpacketTracerfileand: 1. CreatethenecessaryaccesslistsonthedistributionlayerrouterstorestrictIPtrafficbetween VLANs10,20and30.Totesttheaccesslists,youwillneedtomakesomechangestorouter configurations.UseTelnettoVLAN20orVLAN30portsontheinternalroutersfromVLAN10 hoststoensureIPtrafficisblocked.EnsurethatyouCANpingbetweenthehosts. 2. CreatethenecessaryaccessliststodenyVLAN30hostsaccesstotheexternalInternet. 3. CreatethenecessaryaccesslistontheGatewayroutertoensurethatHTTPsessionswith internalserverscanonlybeinitiatedfrominternaladdresses.TotestthenoexternalHTTP sessions,requirement,placeatemporaryPConportFA1/0oftheISProuter.Useanaddress of204.8.183.150forthePCand205.8.183.160fortherouterport.NamethePCExternalTest.

2009 Cisco Learning Institute

You might also like