Top Banner

of 22

EWAN Lab 8 5 2 Instructor

Jun 03, 2018

Download

Documents

Alex Ram
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
  • 8/12/2019 EWAN Lab 8 5 2 Instructor

    1/22

    Lab 8.5.2: Troubleshooting Enterprise Networks 2 (InstructorVersion)

    Topolog !iagra"

    #$$ressing Table

    !e%ice Inter&ace I' #$$ress ubnet ask !e&ault *atewa

    +,

    -a / 192.168.10.1 255.255.255.0 N/A-a /, 192.168.11.1 255.255.255.0 N/A/ / 10.1.1.1 255.255.255.252 N/A/ /, 10.3.3.1 255.255.255.252 N/A

    +2

    -a /, 192.168.20.1 255.255.255.0 N/A/ / 10.1.1.2 255.255.255.252 N/A/ /, 10.2.2.1 255.255.255.252 N/ALo 209.165.200.225 255.255.255.224 209.165.200.226

    +0

    -a /, N/A N/A N/A-a /,.,, 192.168.11.3 255.255.255.0 N/A-a /,.0 192.168.30.1 255.255.255.0 N/A

    / / 10.3.3.2 255.255.255.252 N/A/ /, 10.2.2.2 255.255.255.252 N/A

    , VL#N, DHCP N/A2 VL#N,, 192.168.11.2 255.255.255.0 N/A0 VL#N0 192.168.30.2 255.255.255.0 N/A

    '1, NI1 DHCP

    All contents are Copyrig t ! 1992"200# Cisco $yste%s& 'nc. All rig ts reser(e). * is )oc+%ent is Cisco P+,lic 'n-or%ation. Page 1 o- 22

  • 8/12/2019 EWAN Lab 8 5 2 Instructor

    2/22

    CCNA ploration Accessing t e AN Net or *ro+,les ooting a, 8.5.2 *ro+,les ooting nterprise Net or s 2

    '12 NI1 192.168.11.10 255.255.255.0 192.168.11.1'10 NI1 192.168.30.10 255.255.255.0 192.168.30.1

    T-T' er%er NI1 192.168.20.254 255.255.255.0 192.168.20.1

    Learning b3ecti%espon co%pletion o- t is la,& yo+ ill ,e a,le to

    Ca,le a net or accor)ing to t e topology )iagra% rase t e start+p con-ig+ration an) reloa) a ro+ter to t e )e-a+lt state oa) t e ro+ters an) s itc es it s+pplie) scripts in) an) correct all net or errors Doc+%ent t e correcte) net or

    cenarioor t is la,& )o not +se login or pass or) protection on any console lines to pre(ent acci)entalloc o+t. se ciscoccna -or all pass or)s in t is la,.Note 7eca+se t is la, is c+%+lati(e& yo+ ill ,e +sing all t e no le)ge an) tro+,les ootingtec ni +es t at yo+ a(e ac +ire) -ro% t e pre(io+s %aterial to s+ccess-+lly co%plete t is la,.

    +e4uire"ents $2 is t e spanning tree root -or : AN 11& an) $3 is t e spanning tree root -or : AN 30. $3 is a :*P ser(er it $2 as a client. * e serial lin ,et een ;1 an) ;2 is ra%e ;elay. * e serial lin ,et een ;2 an) ;3 +ses HD C encaps+lation. * e serial lin ,et een ;1 an) ;3 is a+t enticate) +sing CHAP. ;2 %+st a(e sec+re login proce)+res ,eca+se it is t e 'nternet e)ge ro+ter. All (ty lines& e cept t ose ,elonging to ;2& allo connections only -ro% t e s+,nets

    s o n in t e topology )iagra%& e cl+)ing t e p+,lic a))ress. $o+rce 'P a))ress spoo-ing s o+l) ,e pre(ente) on all lin s t at )o not connect to ot er

    ro+ters. ;o+ting protocols %+st ,e +se) sec+rely. '

  • 8/12/2019 EWAN Lab 8 5 2 Instructor

    3/22

    CCNA ploration Accessing t e AN Net or *ro+,les ooting a, 8.5.2 *ro+,les ooting nterprise Net or s 2

    hostname R1!boot-start-markerboot-end-marker!security passwords min-length 6enable secret ciscoccna!ip cef!ip dhcp pool Access1 network 192 16 1" " 2## 2## 2## " default-router 192 16 1" 1!no ip domain lookupframe-relay switching!username R2 password ciscoccnausername R$ password ciscoccna

    ! A typo in the username will prevent R$ from authenticating with %&A'username ccna password ciscoccna!interface (ast)thernet"*" ip address 192 16 1" 1 2## 2## 2## " ip access-group Anti-spoofing out ip access-group Anti-spoofing in! +he access list was applied in the wrong direction +his common! mistake prevents all traffic from e,iting the interface duple, auto speed auto no shutdown!interface (ast)thernet"*1 ip address 192 16 11 1 2## 2## 2## " duple, auto speed auto no shutdown!interface erial"*"*" ip address 1" 1 1 1 2## 2## 2## 2#2 encapsulation frame-relay no keepalive clockrate 12 """ frame-relay map ip 1" 1 1 1 2"1 frame-relay map ip 1" 1 1 2 2"1 broadcast no frame-relay inverse-arp

    frame-relay intf-type dce no shutdown!interface erial"*"*1 ip address 1" $ $ 1 2## 2## 2## " ip address 1" $ $ 1 2## 2## 2## 2#2! +he subnet was misconfigured most likely due to wide use of the *2.! subnet encapsulation ppp ppp authentication chap

    All contents are Copyrig t ! 1992"200# Cisco $yste%s& 'nc. All rig ts reser(e). * is )oc+%ent is Cisco P+,lic 'n-or%ation. Page 3 o- 22

  • 8/12/2019 EWAN Lab 8 5 2 Instructor

    4/22

    CCNA ploration Accessing t e AN Net or *ro+,les ooting a, 8.5.2 *ro+,les ooting nterprise Net or s 2

    no shutdown!interface erial"*1*" no ip address shutdown clockrate 2""""""!interface erial"*1*1 no ip address shutdown!router eigrp 1" passive-interface default no passive-interface (ast)thernet"*" no passive-interface (ast)thernet"*1 no passive-interface erial"*"*" no passive-interface erial"*"*1 network 1" 1 1 " " " " 2## network 1" 1 1 " " " " $

    network 1" 2 2 " " " " 2## network 1" 2 2 " " " " $! Again it is easy to forget that not every subnet is a *2. subnet network 192 16 1" " " " " 2## network 192 16 11 " " " " 2## no auto-summary!ip route " " " " " " " " 1" 1 1 2!ip http server!ip access-list standard Anti-spoofing permit 192 16 1" " " " " 2## deny anyip access-list standard /+0 permit 1" " " " " 2## 2## 2## permit 192 16 1" " " " " 2## permit 192 16 11 " " " " 2## permit 192 16 2" " " " " 2## permit 192 16 $" " " " " 2##!line con " e,ec-timeout # " logging synchronousline au, "line vty " . access-class /+0 in

    login local!end!------------------------------------------! R2!------------------------------------------no service password-encryption!hostname R2!

    All contents are Copyrig t ! 1992"200# Cisco $yste%s& 'nc. All rig ts reser(e). * is )oc+%ent is Cisco P+,lic 'n-or%ation. Page 4 o- 22

  • 8/12/2019 EWAN Lab 8 5 2 Instructor

    5/22

    CCNA ploration Accessing t e AN Net or *ro+,les ooting a, 8.5.2 *ro+,les ooting nterprise Net or s 2

    security passwords min-length 6enable secret ciscoccna!aaa new-model!aaa authentication login local auth localaaa session-id common!ip cef!no ip domain lookup!username ccna password " ciscoccna!interface oopback" ip address 2"9 16# 2"" 22# 2## 2## 2## 22. ip access-group private in!interface (ast)thernet"*1

    ip address 192 16 2" 1 2## 2## 2## " ip access-group +(+' out ip access-group Anti-spoofing in ip nat outside no shutdown!!interface erial"*"*" ip address 1" 1 1 2 2## 2## 2## 2#2 ip nat inside encapsulation frame-relay no keepalive frame-relay map ip 1" 1 1 1 2"1 broadcast frame-relay map ip 1" 1 1 2 2"1 no frame-relay inverse-arp no shutdown!interface erial"*"*1 ip address 1" 2 2 1 2## 2## 2## 2#2 ip access-group R$-telnet in! 3t is common for an access list to be created but not applied to an! interface4 which is re5uired for the A% to function ip nat inside clockrate 12 """ no shutdown!!

    router eigrp 1""router eigrp 1"! +he A number was mistyped4 most likely because the " key was hitone ! too many times All the commands for this A must be re-enteredunder ! the correct A for )3 R' to function

    passive-interface default no passive-interface (ast)thernet"*1

    no passive-interface erial"*"*" no passive-interface erial"*"*1 no passive interface lo"

    All contents are Copyrig t ! 1992"200# Cisco $yste%s& 'nc. All rig ts reser(e). * is )oc+%ent is Cisco P+,lic 'n-or%ation. Page 5 o- 22

  • 8/12/2019 EWAN Lab 8 5 2 Instructor

    6/22

    CCNA ploration Accessing t e AN Net or *ro+,les ooting a, 8.5.2 *ro+,les ooting nterprise Net or s 2

    network 1" 1 1 " " " " $ network 1" 2 2 " " " " $ network 192 16 2" " " " " 2##network 2"9 16# 2"" " " " " 7 no auto-summary!ip route " " " " " " " " 2"9 16# 2"" 226!no ip http serverip nat inside source list 8A+ interface (ast)thernet"*" overload!ip access-list standard Anti-spoofing permit 192 16 2" " " " " 2## deny anyip access-list standard 8A+ permit 1" " " " " 2## 2## 2## permit 192 16 " " " " 2## 2##ip access-list standard private deny 127 " " 1

    deny 1" " " " " 2## 2## 2## deny 172 16 " " " 1# 2## 2## deny 192 16 " " " " 2## 2## permit any!ip access-list e,tended R$-telnet deny tcp host 1" 2 2 2 host 1" 2 2 1 e5 telnet deny tcp host 1" $ $ 2 host 1" 2 2 1 e5 telnet deny tcp host 192 16 11 $ host 1" 2 2 1 e5 telnet deny tcp host 192 16 $" 1 host 1" 2 2 1 e5 telnet permit ip any any! +he user forgot that all A% s end with an implicit deny4 so this! command is needed to permit all other traffic!ip access-list standard +(+'

    permit 192 16 2" " " " " 2##!control-plane!line con " e,ec-timeout # " logging synchronousline au, " e,ec-timeout 1# " logging synchronous login authentication local auth transport output telnet

    line vty " . e,ec-timeout 1# " logging synchronous login authentication local auth transport input telnet!end!------------------------------------------! R$!------------------------------------------

    All contents are Copyrig t ! 1992"200# Cisco $yste%s& 'nc. All rig ts reser(e). * is )oc+%ent is Cisco P+,lic 'n-or%ation. Page 6 o- 22

  • 8/12/2019 EWAN Lab 8 5 2 Instructor

    7/22

    CCNA ploration Accessing t e AN Net or *ro+,les ooting a, 8.5.2 *ro+,les ooting nterprise Net or s 2

    no service password-encryption!hostname R$!security passwords min-length 6enable secret ciscoccna! A user forgot to enter the enable secret4 which not only isinsecure4 ! but will prevent %&A' authentication over the ''' link from! working correctly!no aaa new-model!ip cef!no ip domain lookup!username R1 password ciscoccnausername ccna password ciscoccna!

    interface (ast)thernet"*1 no shutdown!interface (ast)thernet"*1 11 encapsulation dot1 11 ip address 192 16 11 $ 2## 2## 2## " no snmp trap link-status!interface (ast)thernet"*1 $" encapsulation dot1 $" ip address 192 16 $" 1 2## 2## 2## " ip access-group Anti- poofin in ip access-group Anti-spoofing in! +he access list was mistyped 3t now references a none,istent A% 4! so traffic is dropped because of the implicit deny all at the end of !every A%

    no shutdown!!interface erial"*"*" ip address 1" $ $ 2 2## 2## 2## 2#2 encapsulation ppp clockrate 12#"""! +he clock rate was forgotten on the :%) interface ppp authentication pap ppp authentication chap! 'A' was mistakenly misconfigured instead of %&A'

    !interface erial"*"*1 ip address 1" 2 2 2 2## 2## 2## 2#2 no shutdown!router eigrp 1" passive-interface default

    no passive interface (a"*"no passive-interface erial"*"*"

    All contents are Copyrig t ! 1992"200# Cisco $yste%s& 'nc. All rig ts reser(e). * is )oc+%ent is Cisco P+,lic 'n-or%ation. Page # o- 22

  • 8/12/2019 EWAN Lab 8 5 2 Instructor

    8/22

    CCNA ploration Accessing t e AN Net or *ro+,les ooting a, 8.5.2 *ro+,les ooting nterprise Net or s 2

    no passive-interface erial"*"*1! +hese commands were forgotten4 so )3 R' is sent on all interfaces network 1" $ $ " " " " $ network 1" 2 2 " " " " $ network 192 16 11 " " " " 2## network 192 16 $" " " " " 2## no auto-summary!ip classlessip route " " " " " " " " 1" 2 2 1! +he default route to the 3nternet gateway was forgotten4 preventing! this device from reaching it!ip http server!ip access-list standard Anti-spoofing permit 192 16 $" " " " " 2## deny anyip access-list standard /+0

    permit 1" " " " " 2## 2## 2## permit 192 16 1" " " " " 2## permit 192 16 11 " " " " 2## permit 192 16 2" " " " " 2## permit 192 16 $" " " " " 2##!!line con " e,ec-timeout # " logging synchronousline au, " e,ec-timeout 1# " logging synchronousline vty " . access-class /+0 out access-class /+0 in! +his access list is applied in the wrong direction 3n this! case4 the result is not that all traffic is dropped Rather the! result is that all connections are accepted

    e,ec-timeout 1# " logging synchronous login local!end!-----------------------------------------! 1!-----------------------------------------

    no service password-encryption!hostname 1!security passwords min-length 6enable secret ciscoccna!no aaa new-modelvtp domain %%8A +roubleshootingvtp mode transparent

    All contents are Copyrig t ! 1992"200# Cisco $yste%s& 'nc. All rig ts reser(e). * is )oc+%ent is Cisco P+,lic 'n-or%ation. Page 8 o- 22

  • 8/12/2019 EWAN Lab 8 5 2 Instructor

    9/22

    CCNA ploration Accessing t e AN Net or *ro+,les ooting a, 8.5.2 *ro+,les ooting nterprise Net or s 2

    vtp password ciscoccnaip subnet-;ero!no ip domain-lookup!no file verify autospanning-tree mode pvstspanning-tree e,tend system-id!vlan internal allocation policy ascending!vlan 1"!interface (ast)thernet"*1 switchport access vlan 1" switchport mode access!interface (ast)thernet"*2 switchport access vlan 1"

    switchport mode access!interface range (ast)thernet"*$-2.!interface igabit)thernet"*1 shutdown!interface igabit)thernet"*2 shutdown!interface /lan1 no ip address no ip route-cache!interface /lan1" ip address dhcp no ip route-cache!ip default-gateway 192 16 1" 1ip http server!line con " e,ec-timeout # " logging synchronousline vty " . password ciscoccna login

    line vty # 1# no login!end!-----------------------------------------! 2!-----------------------------------------no service padservice timestamps debug uptimeservice timestamps log uptime

    All contents are Copyrig t ! 1992"200# Cisco $yste%s& 'nc. All rig ts reser(e). * is )oc+%ent is Cisco P+,lic 'n-or%ation. Page 9 o- 22

  • 8/12/2019 EWAN Lab 8 5 2 Instructor

    10/22

    CCNA ploration Accessing t e AN Net or *ro+,les ooting a, 8.5.2 *ro+,les ooting nterprise Net or s 2

    no service password-encryption!hostname 2!security passwords min-length 6enable secret ciscoccna!no aaa new-modelvtp domain %%8A +roubleshootingvtp mode %lientvtp password ciscoccnaip subnet-;ero!no ip domain-lookup!no file verify auto!spanning-tree mode mstspanning-tree mode rapid-pvst

    ! < + was accidentally configured for spanning tree 3t should be the! same mode on all switchesspanning-tree e,tend system-idspanning-tree vlan 11 priority ."96spanning-tree vlan $" priority ."96spanning-tree vlan $" priority 192! +he roots were misplaced by incorrectly placing priorities!vlan internal allocation policy ascending!interface (ast)thernet"*1 switchport access vlan 11 switchport mode access!interface (ast)thernet"*2 switchport access vlan 11 switchport mode access!interface (ast)thernet"*$ switchport trunk allowed vlan 114$" switchport mode trunk!interface (ast)thernet"*. switchport trunk allowed vlan 114$" switchport mode trunk!interface range (ast)thernet"*#-2.

    shutdown!interface igabit)thernet"*1 shutdown!interface igabit)thernet"*2 shutdown!interface /lan1 no ip address

    All contents are Copyrig t ! 1992"200# Cisco $yste%s& 'nc. All rig ts reser(e). * is )oc+%ent is Cisco P+,lic 'n-or%ation. Page 10 o- 22

  • 8/12/2019 EWAN Lab 8 5 2 Instructor

    11/22

    CCNA ploration Accessing t e AN Net or *ro+,les ooting a, 8.5.2 *ro+,les ooting nterprise Net or s 2

    no ip route-cache!interface /lan11 ip address 192 16 11 2 2## 2## 2## " no ip route-cache!ip http server!control-plane!line con " e,ec-timeout # " logging synchronousline vty " . password ciscoccna loginline vty # 1# no login!

    end!-----------------------------------------! $!-----------------------------------------no service password-encryption!hostname $!security passwords min-length 6enable secret ciscoccna!no aaa new-modelvtp domain %%8A +roubleshootingvtp mode ervervtp password ciscoccnaip subnet-;ero!no ip domain-lookup!no file verify auto!spanning-tree mode rapid-pvstspanning-tree e,tend system-idspanning-tree vlan 11 priority ."96spanning-tree vlan 11 priority 192! +his switch should have a higher=worse> priority than switch2 for! this / A8 +his happens if the user forgets that lower priority is

    ! more desirable for root electionsspanning-tree vlan $" priority ."96! +he priority was left to the default for this / A8 3t should be set! to the lowest of the two switchesvlan internal allocation policy ascending!/lan 114$"!interface (ast)thernet"*1 switchport trunk allowed vlan 114$"

    All contents are Copyrig t ! 1992"200# Cisco $yste%s& 'nc. All rig ts reser(e). * is )oc+%ent is Cisco P+,lic 'n-or%ation. Page 11 o- 22

  • 8/12/2019 EWAN Lab 8 5 2 Instructor

    12/22

    CCNA ploration Accessing t e AN Net or *ro+,les ooting a, 8.5.2 *ro+,les ooting nterprise Net or s 2

    switchport mode trunk!interface (ast)thernet"*2 switchport access vlan $" switchport mode access!interface (ast)thernet"*$

    switchport trunk allowed vlan 114$" switchport mode trunk!interface (ast)thernet"*. switchport trunk allowed vlan 114$" switchport mode trunk!interface range (ast)thernet"*#-2. shutdown!interface igabit)thernet"*1

    shutdown!interface igabit)thernet"*2 shutdown!interface /lan1 no ip address no ip route-cache!interface /lan$" ip address 192 16 $" 2 2## 2## 2## " no ip route-cache!ip default-gateway 192 16 $" 1ip http server!line con " e,ec-timeout # " logging synchronousline vty " .

    password ciscoccna loginline vty # 1# no login!end

    Task 2: -in$ an$ 1orrect #ll Network Errors

    Task 0: Veri& that +e4uire"ents #re -ull et

    7eca+se ti%e constraints pre(ent tro+,les ooting a pro,le% on eac topic& only a select n+%,ero- topics a(e pro,le%s. Ho e(er& to rein-orce an) strengt en tro+,les ooting s ills& yo+ s o+l)(eri-y t at eac re +ire%ent is %et. *o )o t is& present an e a%ple o- eac re +ire%ent =-ore a%ple a show or $ebug co%%an)>.

    All contents are Copyrig t ! 1992"200# Cisco $yste%s& 'nc. All rig ts reser(e). * is )oc+%ent is Cisco P+,lic 'n-or%ation. Page 12 o- 22

  • 8/12/2019 EWAN Lab 8 5 2 Instructor

    13/22

    CCNA ploration Accessing t e AN Net or *ro+,les ooting a, 8.5.2 *ro+,les ooting nterprise Net or s 2

    * is is intentionally le-t (ag+e ,eca+se t ere are %any ays to (eri-y t e re +ire%ents. 7elo isan e a%ple -or re +ire%ent 1.

    1 2? show spanning-tree / A8""11

    panning tree enabled protocol rstp

    Root 3: 'riority 2.# 7 Address ""1c #7ec 2. " +his bridge is the root &ello +ime 2 sec

  • 8/12/2019 EWAN Lab 8 5 2 Instructor

    14/22

    CCNA ploration Accessing t e AN Net or *ro+,les ooting a, 8.5.2 *ro+,les ooting nterprise Net or s 2

    !ip dhcp pool Access1 network 192 16 1" " 2## 2## 2## " default-router 192 16 1" 1!no ip domain lookupframe-relay switching!username R$ password " ciscoccnausername ccna password " ciscoccna!interface (ast)thernet"*" ip address 192 16 1" 1 2## 2## 2## "!interface (ast)thernet"*1 ip address 192 16 11 1 2## 2## 2## "!interface erial"*"*" ip address 1" 1 1 1 2## 2## 2## 2#2

    encapsulation frame-relay no keepalive clockrate 12 """ frame-relay map ip 1" 1 1 1 2"1 frame-relay map ip 1" 1 1 2 2"1 broadcast no frame-relay inverse-arp frame-relay intf-type dce!interface erial"*"*1 ip address 1" $ $ 1 2## 2## 2## 2#2 encapsulation ppp ppp authentication chap!!router eigrp 1" passive-interface default no passive-interface (ast)thernet"*" no passive-interface (ast)thernet"*1 no passive-interface erial"*"*" no passive-interface erial"*"*1 network 1" 1 1 " " " " $ network 1" $ $ " " " " $ network 192 16 1" " " " " 2## network 192 16 11 " " " " 2## no auto-summary!ip route " " " " " " " " 1" 1 1 2

    !ip http server!ip access-list standard Anti-spoofing permit 192 16 1" " " " " 2## deny anyip access-list standard /+0 permit 1" " " " " 2## 2## 2## permit 192 16 1" " " " " 2## permit 192 16 11 " " " " 2##

    All contents are Copyrig t ! 1992"200# Cisco $yste%s& 'nc. All rig ts reser(e). * is )oc+%ent is Cisco P+,lic 'n-or%ation. Page 14 o- 22

  • 8/12/2019 EWAN Lab 8 5 2 Instructor

    15/22

  • 8/12/2019 EWAN Lab 8 5 2 Instructor

    16/22

    CCNA ploration Accessing t e AN Net or *ro+,les ooting a, 8.5.2 *ro+,les ooting nterprise Net or s 2

    ip access-group R$-telnet in ip nat inside clockrate 12 """!interface erial"*1*" no ip address shutdown!interface erial"*1*1 no ip address shutdown clockrate 2""""""!router eigrp 1" passive-interface default no passive-interface erial"*"*" no passive-interface erial"*"*1 network 1" 1 1 " " " " $ network 1" 2 2 " " " " $

    network 192 16 2" " " " " 2## no auto-summary!ip classlessip route " " " " " " " " 2"9 16# 2"" 226!no ip http serverip nat inside source list 8A+ interface (ast)thernet"*" overload!ip access-list standard Anti-spoofing permit 192 16 2" " " " " 2## deny anyip access-list standard 8A+ permit 1" " " " " 2## 2## 2## permit 192 16 " " " " 2## 2##ip access-list standard private deny 127 " " 1 deny 1" " " " " 2## 2## 2## deny 172 " " " " $1 2## 2## deny 192 16 " " " " 2## 2## permit any!ip access-list e,tended R$-telnet deny tcp host 1" 2 2 2 host 1" 2 2 1 e5 telnet deny tcp host 1" $ $ 2 host 1" 2 2 1 e5 telnet deny tcp host 192 16 11 $ host 1" 2 2 1 e5 telnet deny tcp host 192 16 $" 1 host 1" 2 2 1 e5 telnet

    permit ip any any!ip access-list standard +(+'

    permit 192 16 2" " " " " 2##!control-plane!line con " e,ec-timeout # " logging synchronous

    All contents are Copyrig t ! 1992"200# Cisco $yste%s& 'nc. All rig ts reser(e). * is )oc+%ent is Cisco P+,lic 'n-or%ation. Page 16 o- 22

  • 8/12/2019 EWAN Lab 8 5 2 Instructor

    17/22

    CCNA ploration Accessing t e AN Net or *ro+,les ooting a, 8.5.2 *ro+,les ooting nterprise Net or s 2

    line au, " e,ec-timeout 1# " logging synchronous login authentication local auth transport output telnetline vty " . e,ec-timeout 1# " logging synchronous login authentication local auth transport input telnet!end!------------------------------------------! R$!------------------------------------------no service password-encryption!hostname R$!

    security passwords min-length 6enable secret ciscoccna!no aaa new-model!ip cef!no ip domain lookup!username R1 password " ciscoccnausername ccna password " ciscoccna!interface (ast)thernet"*1 no shutdown!interface (ast)thernet"*1 11 encapsulation dot1 11 ip address 192 16 11 $ 2## 2## 2## " no snmp trap link-status!interface (ast)thernet"*1 $" encapsulation dot1 $" ip address 192 16 $" 1 2## 2## 2## " ip access-group Anti-spoofing in no snmp trap link-status!!

    interface erial"*"*" ip address 1" $ $ 2 2## 2## 2## 2#2 encapsulation ppp clockrate 12#""" ppp authentication chap!interface erial"*"*1 ip address 1" 2 2 2 2## 2## 2## 2#2!router eigrp 1"

    All contents are Copyrig t ! 1992"200# Cisco $yste%s& 'nc. All rig ts reser(e). * is )oc+%ent is Cisco P+,lic 'n-or%ation. Page 1# o- 22

  • 8/12/2019 EWAN Lab 8 5 2 Instructor

    18/22

    CCNA ploration Accessing t e AN Net or *ro+,les ooting a, 8.5.2 *ro+,les ooting nterprise Net or s 2

    passive-interface default no passive-interface (ast)thernet"*" 11 no passive-interface (ast)thernet"*" $" no passive-interface erial"*"*" no passive-interface erial"*"*1 network 1" $ $ " " " " $ network 1" 2 2 " " " " $ network 192 16 11 " " " " 2## network 192 16 $" " " " " 2## no auto-summary!ip route " " " " " " " " 1" 2 2 1!ip http server!ip access-list standard Anti-spoofing permit 192 16 $" " " " " 2## deny anyip access-list standard /+0

    permit 1" " " " " 2## 2## 2## permit 192 16 1" " " " " 2## permit 192 16 11 " " " " 2## permit 192 16 2" " " " " 2## permit 192 16 $" " " " " 2##!!line con " e,ec-timeout # " logging synchronousline au, " e,ec-timeout 1# " logging synchronousline vty " . access-class /+0 in e,ec-timeout 1# " logging synchronous login local!end!-----------------------------------------! 1!-----------------------------------------no service password-encryption!hostname 1!

    security passwords min-length 6enable secret ciscoccna!no aaa new-modelvtp domain %%8A +roubleshootingvtp mode transparentvtp password ciscoccnaip subnet-;ero!no ip domain-lookup

    All contents are Copyrig t ! 1992"200# Cisco $yste%s& 'nc. All rig ts reser(e). * is )oc+%ent is Cisco P+,lic 'n-or%ation. Page 18 o- 22

  • 8/12/2019 EWAN Lab 8 5 2 Instructor

    19/22

    CCNA ploration Accessing t e AN Net or *ro+,les ooting a, 8.5.2 *ro+,les ooting nterprise Net or s 2

    !no file verify autospanning-tree mode pvstspanning-tree e,tend system-id!vlan internal allocation policy ascending!vlan 1"!interface (ast)thernet"*1 switchport access vlan 1" switchport mode access!interface (ast)thernet"*2 switchport access vlan 1" switchport mode access!interface range (ast)thernet"*$-2.!

    interface igabit)thernet"*1 shutdown!interface igabit)thernet"*2 shutdown!interface /lan1 no ip address no ip route-cache!interface /lan1" ip address dhcp no ip route-cache!ip default-gateway 192 16 1" 1ip http server!line con " e,ec-timeout # " logging synchronousline vty " . password ciscoccna loginline vty # 1# no login!end

    !-----------------------------------------! 2!-----------------------------------------!hostname 2!enable secret ciscoccna!vtp domain %%8A +roubleshootingvtp mode client

    All contents are Copyrig t ! 1992"200# Cisco $yste%s& 'nc. All rig ts reser(e). * is )oc+%ent is Cisco P+,lic 'n-or%ation. Page 19 o- 22

  • 8/12/2019 EWAN Lab 8 5 2 Instructor

    20/22

    CCNA ploration Accessing t e AN Net or *ro+,les ooting a, 8.5.2 *ro+,les ooting nterprise Net or s 2

    vtp password ciscoccna!no ip domain-lookup!!spanning-tree mode rapid-pvstspanning-tree e,tend system-idspanning-tree vlan 11 priority 2.#76spanning-tree vlan $" priority 2 672!vlan internal allocation policy ascending!interface (ast)thernet"*1 switchport access vlan 11 switchport mode access!interface (ast)thernet"*2 switchport access vlan 11 switchport mode access

    !interface (ast)thernet"*$ switchport trunk native vlan 99 switchport trunk allowed vlan 114$" switchport mode trunk!interface (ast)thernet"*. switchport trunk native vlan 99 switchport trunk allowed vlan 114$" switchport mode trunk!interface range (ast)thernet"*#-2. shutdown!interface igabit)thernet"*1 shutdown!interface igabit)thernet"*2 shutdown!interface /lan1 no ip address no ip route-cache!interface /lan11 ip address 192 16 11 2 2## 2## 2## " no shutdown

    !ip http server!control-plane!line con " e,ec-timeout # " logging synchronousline vty " . password ciscoccna

    All contents are Copyrig t ! 1992"200# Cisco $yste%s& 'nc. All rig ts reser(e). * is )oc+%ent is Cisco P+,lic 'n-or%ation. Page 20 o- 22

  • 8/12/2019 EWAN Lab 8 5 2 Instructor

    21/22

    CCNA ploration Accessing t e AN Net or *ro+,les ooting a, 8.5.2 *ro+,les ooting nterprise Net or s 2

    loginline vty # 1# no login!end!-----------------------------------------! $!-----------------------------------------no service password-encryption!hostname $!security passwords min-length 6enable secret ciscoccna!no aaa new-modelvtp domain %%8A +roubleshootingvtp mode ervervtp password ciscoccna

    ip subnet-;ero!no ip domain-lookup!no file verify auto!spanning-tree mode rapid-pvstspanning-tree e,tend system-idspanning-tree vlan 11 priority 2 672spanning-tree vlan $" priority 2.#76!vlan internal allocation policy ascending!/lan 114$"!interface (ast)thernet"*1 switchport trunk allowed vlan 114$" switchport mode trunk!interface (ast)thernet"*2 switchport access vlan $" switchport mode access!interface (ast)thernet"*$ switchport trunk native vlan 99 switchport trunk allowed vlan 114$" switchport mode trunk

    !interface (ast)thernet"*. switchport trunk native vlan 99 switchport trunk allowed vlan 114$" switchport mode trunk!interface range (ast)thernet"*#-2. shutdown!interface igabit)thernet"*1

    All contents are Copyrig t ! 1992"200# Cisco $yste%s& 'nc. All rig ts reser(e). * is )oc+%ent is Cisco P+,lic 'n-or%ation. Page 21 o- 22

  • 8/12/2019 EWAN Lab 8 5 2 Instructor

    22/22

    CCNA ploration Accessing t e AN Net or *ro+,les ooting a, 8.5.2 *ro+,les ooting nterprise Net or s 2

    shutdown!interface igabit)thernet"*2 shutdown!interface /lan1 no ip address no ip route-cache!interface /lan$" ip address 192 16 $" 2 2## 2## 2## " no shutdown!ip default-gateway 192 16 $" 1ip http server!line con " e,ec-timeout # " logging synchronous

    line vty " .password ciscoccna loginline vty # 1# no login!end

    Task 5: 1lean 6p

    rase t e con-ig+rations an) reloa) t e ro+ters. Disconnect an) store t e ca,ling. or PC ostst at are nor%ally connecte) to ot er net or s =s+c as t e sc ool AN or to t e 'nternet>&reconnect t e appropriate ca,ling an) restore t e *CP/'P settings.