Sie sind auf Seite 1von 4

DRSEnt EIGRP/NAT/VLAN PT Practice SBA

A few things to keep in mind while completing this activity: 1. Do not use the browser Back button or close or reload any Exam windows during the exam. 2. Do not close Packet Tracer when you are done. It will close automatically. 3. Click the Submit Assessment button to submit your work.

Introduction
In this practice Packet Tracer Skills Assessment, you will: finish the configuration of a partially configured network establish connectivity within the enterprise and to the Internet implement a VLAN policy including inter-VLAN routing

Addressing Table

Device

Interface Fa0/0 S0/0/0

Address 10.10.10.129 10.10.10.249 10.10.10.253 209.165.201.2

Subnet Mask 255.255.255.248 255.255.255.252 255.255.255.252 255.255.255.252

Default Gateway n/a n/a n/a n/a

HQ S0/1/0 S0/0/1

Fa0/0 R1 Fa0/1 S0/0/0 Fa0/0.1 Fa0/0.10 R2 Fa0/0.20 Fa0/1 S0/0/0 S1 S2 H1 H2 H3 Inside Web Server VLAN 1 VLAN 1 NIC NIC NIC NIC

10.10.10.121 10.10.10.113 10.10.10.250 10.10.10.97 10.10.10.1 10.10.10.65 10.10.10.114 10.10.10.254 10.10.10.98 10.10.10.99 10.10.10.10 10.10.10.70 10.10.10.125 Inside: 10.10.10.132 Outside: 128.107.0.10

255.255.255.248 255.255.255.248 255.255.255.252 255.255.255.240 255.255.255.192 255.255.255.224 255.255.255.248 255.255.255.252 255.255.255.240 255.255.255.240 255.255.255.192 255.255.255.224 255.255.255.248 255.255.255.248

n/a n/a n/a n/a n/a n/a n/a n/a 10.10.10.97 10.10.10.97 10.10.10.1 10.10.10.65 10.10.10.121 10.10.10.129

NOTE: The password for user EXEC mode is cisco. The password for privileged EXEC mode is class.

Step 1: Configure PPP on HQ.


The link between HQ and ISP uses PPP with CHAP. The password is ciscochap. ISP is not accessible and is already configured.

Step 2: Configure Default Routing.


a. Configure HQ with a default route using the exit interface argument. b. Verify default routing.

Step 3: Configure EIGRP Routing.


a. b. c. Configure EIGRP routing on HQ, R1, and R2 using the following parameters: Use AS number 100. Do not use the wildcard mask argument. Do not advertise the network between HQ and ISP. On HQ, enter the command redistribute static to propagate the default route to R1 and R2. Configure the link between HQ and R2 so that the bandwidth of 128 is used in EIGRP calculations. Configure R1 and R2 to summarize the following subnets into one advertised route to be sent to HQ.

R1 and R2 Subnets 10.10.10.0/26 10.10.10.64/27 10.10.10.96/28 10.10.10.112/29 10.10.10.120/29

Step 4: Configure HQ with NAT.


a. Configure a static NAT mapping for the Inside Web Server so that the inside IP address is translated to the outside IP address when packets are routed to the Internet. Use the addresses in the Addressing Table. Configure dynamic NAT on HQ using the following guidelines: Only addresses in the 10.10.10.0/24 address space will be translated. Use the number 1 for the access list. Use PUBLIC as the NAT pool name and translate all inside addresses to the 128.107.0.4/30 address space. Configure PAT. Verify that NAT is working.

b. c.

Step 5: Configure Trunking.


Note: S2 is already configured with trunking. You only have user EXEC mode access to S2. On S1, manually configure the necessary links for trunking mode.

Step 6: Configure VTP and VLANs.


Note: S2 is already configured as a VTP client and will receive VLAN information from S1. You only have user EXEC mode access to S2. a. Configure S1 with the following VTP parameters: b. VTP server. VTP domain name: CCNA VTP password: ciscovtp

Create and name the following VLANs on S1: VLAN 10: Student VLAN 20: Faculty

c. Verify that S2 received VLAN information from S1.

Step 7: Configure the VLAN Interface and VLAN Access.


Note: The VLAN interface on S2 is already configured. a. b. Configure S1 for remote management access. Configure S1 interface Fa0/4 for access mode and assign it to VLAN 10.

Step 8: Configure Spanning Tree.


S2 is the current STP root bridge. Using a priority of 4096, configure S1 as the root bridge for all VLANs.

Step 9: Configure Port Security.


Note: Best practice requires port security on all access ports. However, for this practice exercise you will only configure one port with security. a. Configure S1 with port security on FastEthernet 0/4: b. No more than 2 MAC addresses are allowed. Once learned, MAC addresses should be automatically added to the running configuration. If this policy is violated, the port should automatically shutdown.

Verify that port security is implemented.

Step 10: Configure Inter-VLAN Routing.


a. b. Use the information in the Addressing Table to configure R2 for inter-VLAN routing. Verify inter-VLAN routing.

Step 11: Verify Connectivity.


Although these are not scored, the following connectivity tests should be successful.

H3 can ping H1 and H2. H3 can ping the Inside Web Server at both addresses. H1, H2, and H3 can ping the Outside Web Server. H1 can ping S1.