Sie sind auf Seite 1von 9

##############################################################

#### A. Configuración Switching Básico #######################


##############################################################
###############
### MLS1 ######
###############
!
!
!
vlan 5
name CCNPR
!
vlan 10
name CCNPS
!
VLAN 15
name CCNPT
!
VLAN 20
name CCNAS
!
VLAN 1000
name NATIVA
!
!
inter range e0/0-1, e1/0-3
switchport trunk encapsulation dot1q
switchport mode trunk
switchport trunk allowed vlan 5,10,15,20
switchport trunk native vlan 1000
switchport nonegotiate
!
inter range e0/2-3
switchport mode access
switchport access vlan 1000
shutdown
!
inter range e0/0-1
channel-group 2 mode desirable
!
inter range e1/0-1
channel-group 1 mode on
!
inter range e1/2-3
channel-group 5 mode active
!
###############
### MLS2 ######
###############
!
!
!
vlan 5
name CCNPR
!
vlan 10
name CCNPS
!
VLAN 15
name CCNPT
!
VLAN 20
name CCNAS
!
VLAN 1000
name NATIVA
!
!
inter range e0/0-1, e1/0-3
switchport trunk encapsulation dot1q
switchport mode trunk
switchport trunk allowed vlan 5,10,15,20
switchport trunk native vlan 1000
switchport nonegotiate
!
inter e0/2
switchport mode access
switchport access vlan 1000
shutdown
!
inter range e0/0-1
channel-group 2 mode desirable
!
inter range e1/0-1
channel-group 4 mode on
!
inter range e1/2-3
channel-group 3 mode active
!
###############
### ALS1 ######
###############
!
!
!
vlan 5
name CCNPR
!
vlan 10
name CCNPS
!
VLAN 15
name CCNPT
!
VLAN 20
name CCNAS
!
VLAN 1000
name NATIVA
!
!
inter range e0/0-1, e1/0-3
switchport trunk encapsulation dot1q
switchport mode trunk
switchport trunk allowed vlan 5,10,15,20
switchport trunk native vlan 1000
switchport nonegotiate
!
inter e0/2
switchport mode access
switchport access vlan 5
switchport port-security
switchport port-security maximum 2
switchport port-security violation restrict
!
inter e0/3
switchport mode access
switchport access vlan 10
switchport port-security
switchport port-security maximum 2
switchport port-security violation restrict
!
inter range e0/0-1
channel-group 6 mode desirable
!
inter range e1/0-1
channel-group 1 mode on
!
inter range e1/2-3
channel-group 3 mode active
!
###############
### ALS2 ######
###############
!
!
!
vlan 5
name CCNPR
!
vlan 10
name CCNPS
!
VLAN 15
name CCNPT
!
VLAN 20
name CCNAS
!
VLAN 1000
name NATIVA
!
!
inter range e0/0-1, e1/0-3
switchport trunk encapsulation dot1q
switchport mode trunk
switchport trunk allowed vlan 5,10,15,20
switchport trunk native vlan 1000
switchport nonegotiate
!
inter e0/2
switchport mode access
switchport access vlan 15
switchport port-security
switchport port-security violation shutdown
!
inter e0/3
switchport mode access
switchport access vlan 20
switchport port-security
switchport port-security violation shutdown
!
inter range e0/0-1
channel-group 6 mode desirable
!
inter range e1/0-1
channel-group 4 mode on
!
inter range e1/2-3
channel-group 5 mode active
!
#######################################################################
#### B. Configuración de Switching Corporativo: #######################
#######################################################################
!
###############
### MLS1 ######
###############
!
spanning-tree mode rapid-pvst
!
!
spanning-tree vlan 5,10,15,20 hello-time 1
spanning-tree vlan 5,10,15,20 max-age 10
spanning-tree vlan 5,10,15,20 forward-time 8
!
###############
### MLS2 ######
###############
!
spanning-tree mode rapid-pvst
!
!
spanning-tree vlan 5,10,15,20 root primary
!
spanning-tree vlan 5,10,15,20 hello-time 1
spanning-tree vlan 5,10,15,20 max-age 10
spanning-tree vlan 5,10,15,20 forward-time 8
!
###############
### ALS1 ######
###############
!
spanning-tree mode rapid-pvst
!
!
!
spanning-tree vlan 5,10,15,20 hello-time 1
spanning-tree vlan 5,10,15,20 max-age 10
spanning-tree vlan 5,10,15,20 forward-time 8
!
interface range e0/2-3
spanning-tree portfast
spanning-tree bpduguard enable
!
errdisable recovery interval 45
errdisable recovery cause all
!
interface port-channel 1
spanning-tree guard loop
exit
!
ip dhcp snooping
ip dhcp snooping vlan 5,10,15,20
no ip dhcp snooping information option
!
interface range port-channel1, port-channel3, port-channel6
ip dhcp snooping trust
exit
!
###############
### ALS2 ######
###############
!
spanning-tree mode rapid-pvst
!
!
!
spanning-tree vlan 5,10,15,20 hello-time 1
spanning-tree vlan 5,10,15,20 max-age 10
spanning-tree vlan 5,10,15,20 forward-time 8
!
interface range e0/2-3
spanning-tree portfast
spanning-tree bpduguard enable
!
errdisable recovery interval 45
errdisable recovery cause all
!
interface port-channel 5
spanning-tree guard loop
exit
!
ip dhcp snooping
ip dhcp snooping vlan 5,10,15,20
no ip dhcp snooping information option
!
interface range port-channel4, port-channel5, port-channel6
ip dhcp snooping trust
exit
!
!
#######################################################################
#### C. Configuración de Enrutamiento: ################################
#######################################################################
###############
### MLS2 ######
###############
!
!
ipv6 unicast-routing
ip routing
!
interface e0/3
no switchport
ip address 192.168.31.1 255.255.255.252
ipv6 address 2018:acad:acad:31::1/112
no shutdown
!
!
interface vlan 5
ip address 192.168.5.1 255.255.255.0
ipv6 address 2018:acad:acad:5::1/64
no shutdown
!
interface vlan 10
ip address 192.168.10.1 255.255.255.0
ipv6 address 2018:acad:acad:10::1/64
no shutdown
!
interface vlan 15
ip address 192.168.15.1 255.255.255.0
ipv6 address 2018:acad:acad:15::1/64
no shutdown
!
interface vlan 20
ip address 192.168.20.1 255.255.255.0
ipv6 address 2018:acad:acad:20::1/64
no shutdown
!
router eigrp EVALUACION3
address-family ipv4 autonomous-system 1
!
af-interface vlan 5
passive-interface
!
af-interface vlan 10
passive-interface
!
af-interface vlan 15
passive-interface
!
af-interface vlan 20
passive-interface
exit
!
network 192.168.5.0 0.0.0.255
network 192.168.10.0 0.0.0.255
network 192.168.15.0 0.0.0.255
network 192.168.20.0 0.0.0.255
network 192.168.31.0 0.0.0.3
exit
!
address-family ipv6 autonomous-system 1
!
af-interface vlan 5
passive-interface
!
af-interface vlan 10
passive-interface
!
af-interface vlan 15
passive-interface
!
af-interface vlan 20
passive-interface
exit
!
exit
!
exit
!
ip dhcp excluded-address 192.168.5.1 192.168.5.5
ip dhcp excluded-address 192.168.10.1 192.168.10.5
ip dhcp excluded-address 192.168.15.1 192.168.15.5
!
ip dhcp pool VLAN5
network 192.168.5.0 /24
default-router 192.168.5.1
dns-server 8.8.8.8
!
ip dhcp pool VLAN10
network 192.168.10.0 /24
default-router 192.168.10.1
dns-server 8.8.8.8
!
ip dhcp pool VLAN15
network 192.168.15.0 /24
default-router 192.168.15.1
dns-server 8.8.8.8
!
ipv6 dhcp pool VLAN20
address prefix 2018:acad:acad:20::/64
dns-server 2018:acad:Acad:8::8
exit
!
interface vlan 20
ipv6 dhcp server VLAN20
ipv6 nd managed-config-flag
!
###############
### NUCLEO ####
###############
!
!
ipv6 unicast-routing
!
interface e0/1
ip address 192.168.25.2 255.255.255.0
ipv6 address 2018:acad:acad:25::2/64
no shutdown
!
ip route 0.0.0.0 0.0.0.0 205.0.0.1
ipv6 route ::/0 2018:acad:Acad:205::1
!
router eigrp EVALUACION3
address-family ipv4 autonomous-system 1
!
af-interface e0/0
passive-interface
!
af-interface e0/1
passive-interface
exit
!
network 192.168.25.0 0.0.0.255
network 192.168.31.0 0.0.0.3
!
topology base
redistribute static metric 10000 1000 255 1 1500
!
exit
!
exit
!
address-family ipv6 autonomous-system 1
!
af-interface e0/0
passive-interface
!
af-interface e0/1
passive-interface
exit
!
topology base
redistribute static metric 10000 1000 255 1 1500
!
exit
!
exit
!
exit
!
access-list 10 permit 192.168.0.0 0.0.31.255
!
ip nat inside source list 10 interface e0/0 overload
!
interface range e0/1, e0/3
ip nat inside
!
interface e0/0
ip nat outside
!
!
#############################################################################
#### D. Configuración de Seguridad de Campus: ################################
##############################################################################
###############
### SW ####
###############
!
!
vtp mode transparent
!
vlan 25
name SERVIDORES
private-vlan primary
private-vlan association 7,14
!
vlan 7
private-vlan isolated
!
vlan 14
private-vlan community
!
interface e0/2
switchport mode private-vlan host
switchport private-vlan host-association 25 7
!
interface e0/3
switchport mode private-vlan host
switchport private-vlan host-association 25 14
!
inter e0/1
switchport mode private-vlan promiscuous
switchport private-vlan mapping 25 add 7,14
!
!
###############
### ALS1 ####
###############
!
access-list 101 permit ip 192.168.10.0 0.0.0.255 192.168.20.0 0.0.0.255
mac access-list extended VLAN10
permit host aabb.cc00.0830 any
exit
!
!
interface e0/3
ip access-group 101 in
mac access-group VLAN10 in
!
###############
### ALS2 ####
###############
!
access-list 102 permit ip 192.168.15.0 0.0.0.255 192.168.5.0 0.0.0.255
mac access-list extended VLAN15
permit host aabb.cc00.0920 any
!
vlan access-map FILTRO_VL15
match ip address 102
match mac address VLAN15
action forward
!
vlan filter FILTRO_VL15 vlan-list 15

Das könnte Ihnen auch gefallen