Beruflich Dokumente
Kultur Dokumente
PROPOSAL
FOR CAPSTONE FINAL PROJECT
Table of Contents
I. INTRODUCTION
WAN Services
LAN Services
Network Fundamentals
Security Services
WAN Topology
V. CONFIGURATIONS
I.
INTRODUCTION
II.
DESIGN CONSIDERATIONS
WAN Services
LAN Services
Network Fundamentals
Security Services
Infrastructure protection
Physical securing of access to networking devices
Disabling of unused services that may be used to exploit the network
Authentication of routing protocol updates
Access control
Authentication and authorization services for controlling access to network
resources
Logging capabilities for auditing access to network devices and resources
Integration with global access management system to enforce access
privileges
Secure connectivity
Secure interoffice connectivity for full-mesh and hub-and-spoke WAN
topologies
Secure access into the branch network for remote or home office workers
Voice, video, and data separation on the LAN
Separation of network management traffic
Access to the server in the branch by home office users
Threat protection, detection, and mitigation
Blocking of unauthorized traffic from entering or leaving the branch
Access to servers in the branch by home office users
Verification of source addresses for incoming traffic
Identification and mitigation of common DoS attacks and worms
Prevention of malicious attacks on the branch office network from outside
Prevention of attacks and security breaches from within the branch office
3
III.
WAN Topology
IV.
SYSTEM COMPONENTS
Device
Platform
Modules
P1
P2
PE1
PE2
PE3
PE4
VRF1 CE1
VRF1 CE2
V.
HQ GW
BR GW
HQ CORE
SW
BR CORE
SW
HQ
ACCESS
SW
BR
ACCESS
SW
N/A
N/A
N/A
N/A
CONFIGURATIONS
hostname P1
!
mpls traffic-eng tunnels
!
interface Loopback0
ip address 10.0.0.1 255.255.255.255
!
interface GigabitEthernet0/0
description Connected to P2 Fa0/0
ip address 10.1.0.1 255.255.255.252
ip ospf network point-to-point
duplex auto
speed auto
mpls traffic-eng tunnels
!
interface GigabitEthernet0/1
description Connected to P2 Fa2/0
ip address 10.1.0.5 255.255.255.252
ip ospf network point-to-point
duplex auto
speed auto
mpls traffic-eng tunnels
!
interface Serial0/0/0
description Connected to PE1 S1/0
ip address 10.1.1.1 255.255.255.252
ip ospf network point-to-point
mpls traffic-eng tunnels
no fair-queue
service-module t1 timeslots 1-24
!
interface Serial0/1/0
5
!
ip dhcp pool sdm-pool1
network 172.16.100.0 255.255.255.252
default-router 172.16.100.1
!
ip vrf vrf1
rd 64512:1
route-target export 64512:1
route-target import 64512:1
!
ip vrf vrf2
rd 64512:2
route-target export 64512:2
route-target import 64512:2
!
no ip domain lookup
!
multilink bundle-name authenticated
mpls traffic-eng tunnels
!
interface Loopback0
ip address 10.0.1.1 255.255.255.255
!
interface Tunnel2
ip unnumbered Loopback0
tunnel destination 10.0.1.2
tunnel mode mpls traffic-eng
tunnel mpls traffic-eng autoroute announce
tunnel mpls traffic-eng path-option 2 dynamic
no routing dynamic
!
interface Tunnel3
ip unnumbered Loopback0
tunnel destination 10.0.1.3
tunnel mode mpls traffic-eng
tunnel mpls traffic-eng autoroute announce
tunnel mpls traffic-eng path-option 3 dynamic
no routing dynamic
!
interface Tunnel4
ip unnumbered Loopback0
tunnel destination 10.0.1.4
tunnel mode mpls traffic-eng
tunnel mpls traffic-eng autoroute announce
tunnel mpls traffic-eng path-option 4 dynamic
no routing dynamic
9
!
interface FastEthernet0/0
ip address dhcp
ip nat outside
ip virtual-reassembly
duplex auto
speed auto
!
interface FastEthernet0/1
description $ETH-LAN$
ip address 172.16.100.1 255.255.255.252
ip nat inside
ip virtual-reassembly
duplex auto
speed auto
!
interface Serial0/0/0
description Connected to P1 S0/0/0
ip address 10.1.1.2 255.255.255.252
ip ospf network point-to-point
mpls traffic-eng tunnels
service-module t1 clock source internal
service-module t1 timeslots 1-24
!
interface Serial0/1/0
description Connected to P2 S0/0/0
ip address 10.1.2.2 255.255.255.252
ip ospf network point-to-point
mpls traffic-eng tunnels
service-module t1 clock source internal
service-module t1 timeslots 1-24
!
interface Serial0/2/0
description Connected to VRF1-CE1 S0/1
ip vrf forwarding vrf1
ip address 192.168.1.2 255.255.255.252
ip ospf network point-to-point
mpls traffic-eng tunnels
service-module t1 clock source internal
service-module t1 timeslots 1-24
!
interface Serial0/3/0
description Connected to VRF2-CE1 S0/0
ip vrf forwarding vrf2
ip address 192.168.1.2 255.255.255.252
ip ospf network point-to-point
10
no synchronization
exit-address-family
hostname PE3
!
ip cef
ip vrf vrf1
rd 64512:1
route-target export 64512:1
route-target import 64512:1
!
ip vrf vrf2
rd 64512:2
route-target export 64512:2
route-target import 64512:2
!
no ip dhcp use vrf connected
ip dhcp excluded-address 172.16.200.1
!
ip dhcp pool sdm-pool1
network 172.16.200.0 255.255.255.252
default-router 172.16.200.1
!
mpls traffic-eng tunnels
!
interface Loopback0
ip address 10.0.1.3 255.255.255.255
!
interface Tunnel1
ip unnumbered Loopback0
tunnel destination 10.0.1.1
tunnel mode mpls traffic-eng
tunnel mpls traffic-eng autoroute announce
tunnel mpls traffic-eng path-option 1 dynamic
no routing dynamic
!
interface Tunnel2
ip unnumbered Loopback0
tunnel destination 10.0.1.2
tunnel mode mpls traffic-eng
tunnel mpls traffic-eng autoroute announce
tunnel mpls traffic-eng path-option 2 dynamic
no routing dynamic
!
interface Tunnel4
ip unnumbered Loopback0
tunnel destination 10.0.1.4
15
interface Tunnel3
ip unnumbered Loopback0
tunnel destination 10.0.1.3
tunnel mode mpls traffic-eng
tunnel mpls traffic-eng autoroute announce
tunnel mpls traffic-eng path-option 3 dynamic
no routing dynamic
!
interface FastEthernet0/0
no ip address
shutdown
duplex auto
speed auto
!
interface FastEthernet0/1
no ip address
shutdown
duplex auto
speed auto
!
interface Serial0/0/0
description Connected to P1 S1/3
ip address 10.1.1.14 255.255.255.252
ip ospf network point-to-point
mpls traffic-eng tunnels
service-module t1 clock source internal
service-module t1 timeslots 1-24
!
interface Serial0/1/0
description Connected to P2 S1/3
ip address 10.1.2.14 255.255.255.252
ip ospf network point-to-point
mpls traffic-eng tunnels
service-module t1 clock source internal
service-module t1 timeslots 1-24
!
interface Serial0/2/0
description Connected to VRF1-CE2 S1/1
ip vrf forwarding vrf1
ip address 192.168.1.14 255.255.255.252
service-module t1 clock source internal
service-module t1 timeslots 1-24
!
interface Serial0/3/0
description Connected to VRF2-CE2 S1/1
ip vrf forwarding vrf2
19
interface FastEthernet0/0
ip address 10.10.200.1 255.255.255.0
ip nat inside
ip virtual-reassembly
duplex auto
speed auto
!
interface Serial0/0
description Connected to PE3 S1/2
ip address 192.168.1.9 255.255.255.252
no fair-queue
service-module t1 timeslots 1-24
!
interface Serial0/1
description Connected to PE4 S1/2
ip address 192.168.1.13 255.255.255.252
service-module t1 timeslots 1-24
!
interface FastEthernet1/0
ip address dhcp
ip nat outside
ip virtual-reassembly
duplex auto
speed auto
!
router bgp 64512
no synchronization
bgp log-neighbor-changes
timers bgp 12 36
redistribute connected
neighbor 192.168.1.10 remote-as 65000
neighbor 192.168.1.14 remote-as 65000
no auto-summary
!
ip forward-protocol nd
!
ip nat inside source list 1 interface FastEthernet1/0 overload
!
access-list 1 permit 10.10.200.0 0.0.0.255
23