Sei sulla pagina 1di 3

HQ se0/0/0

Se0/0/1
Se0/2/0
Fa0/0
ISP se0/0/0
Loopback1
B1 se0/0/0
Fa0/0
Tunnel0
B2 se0/0/0
Fa0/0
Fa0/1
Tunnel0
PC1 fa0
PC2 fa0
PC3 fa0
ServerPT fa0

10.0.0.1
10.0.0.5
204.0.0.1
192.168.50.31
204.0.0.2
1.1.1.1
10.0.0.2
192.168.10.31
172.16.0.1
10.0.0.6
192.168.20.31
192.168.30.31
172.16.0.2
DHCP
192.168.20.1
192.168.30.1
192.168.50.1

255.255.255.252
255.255.255.252
255.255.255.252
255.255.255.0
255.255.255.252
255.255.255.255
255.255.255.252
255.255.255.0
255.255.255.252
255.255.255.252
255.255.255.0
255.255.255.0
255.255.255.252
DHCP
255.255.255.0
255.255.255.0
255.255.255.0

192.168.10.31
192.168.20.31
192.168.10.31
192.168.50.31

Scenario:
You are the network engineer at Connect.Inc. You need to ensure that you have full
connectivity and can ping everywhere you are allowed.
Requirements.
Routing:
You can choose to use either EIGRP or OSPF for you internal routing protocol. You will
have to create a default route to the ISP and make sure you IGP learns about it.
You will also have to create a static route on ISp to allow traffic to return to Connect.Inc
IP Addressing
Use the subnets as shown on the diagram. Use the last ip in each subnet for LAN
interfaces. Use the 1st ip in each WAN link for HQ Router
The PC in B1 LAN must get an address via DHCP. Configure B1 as a DHCP router to
allow this.
The PC in B2 LAN must be statically configured with the 1st usable address
The Syslog/Web Server has an ip address of 192.168.50.1/24. It must also be reachable
via its public IP of 208.0.0.254/24
Create a loopback on ISP of 1.1.1.1/32 for testing purposes
Frame Relay
HQ and B1 are connected via F/R network. Use the shown DLCI numbers and IP Address
to create FR maps to ensure connectivity.
PPP
HQ and B2 are connected via a PPP connection. Use PPP CHAP for security with a
password of cisco1234
Tunnels
You have a GRE tunnel between B1 and B2. Ensure that traffic between B1 and B2
LANS goes via this tunnel
NAT
The web server (192.168.50.1) needs to be reachable via its public IP of 208.0.0.254/24.
Use static Nat to accomplish this.
We also have a pool of public addresses that can be used when any of the PCs need to
access the internet. This pool is from 208.0.0.1 through to 208.0.0.3. We will also need to
rather use PAT in order to conserve these addresses. Ensure that all the LANS on both B1
and B2 will be able to do NAT translations.

Security
Create ACLs to prevent the B1 LAN from pinging the 192.168.30.0 network. However,
they should still be able to ping the 192.168.20.0 LAN and all other networks.
Also prevent the B1 LAN from accessing any Web server
Logging
Use the syslog server on HQ router to record all router activity. Configure each router to
send the syslog updates to the server.
Connectivity Tests
All your PCs should successfully ping the loopback on ISP (1.1.1.1)

Potrebbero piacerti anche