Sie sind auf Seite 1von 20

Jawaban Modul B Packet Tracer Challenge

- Konfigurasikan ip dan hostname pada semua perangkat sesuai tabel


- User yang masuk

RTR-SRV-FARM, RTR-HQ, RTR-BR1, RTR-BR2

username ROLks privilege 15 secret JkT2018


enable secret Jkt2018

line console 0

login local

Semua MLS

username MLSLks secret JkT2018


enable secret Jkt2018
line console 0

login local

SW-ACC1, SW-ACC2, SW1-BR1, SW2-BR1, SW-BR2

username SWLks secret JkT2018


enable secret Jkt2018

line console 0
login local

- Remote Management

Semua perangkat di SRV-FARM, HQ, Branch1, Branch2

ip domain-name jakarta.id
line vty 0

login local
transport input ssh

access-class 55 in

line vty 1 4
transport input none
access-list 55 permit 172.18.12.20 0.0.0.3

crypto key generate rsa


- BGP Peer

RTR-SRV-FARM

ip route 0.0.0.0 0.0.0.0 112.131.45.66


router bgp 64514
neighbor 1.1.1.1 remote-as 64513

R-EDGE-L

router bgp 64515

bgp router-id 2.2.2.2


neighbor 112.176.24.85 remote-as 64513

network 112.131.45.120 mask 255.255.255.252


network 112.131.45.80 mask 255.255.255.248

redistribute eigrp 100

redistribute ospf 99

- Konektifitas antar Router edge ISP A

R-EDGE-L

router eigrp 100


network 113.76.28.16 0.0.0.3

no auto-summary

R-CORE-2

router eigrp 100


network 113.76.28.16 0.0.0.3

network 118.12.55.100 0.0.0.3


no auto-summary

R-CORE-1

router eigrp 100

redistribute ospf 1 metric 1 1 1 1 1


network 118.12.55.100 0.0.0.3

no auto-summary
router ospf 1

router-id 1.1.1.1
redistribute eigrp 100 subnets

network 112.176.24.16 0.0.0.3 area 0


interface FastEthernet0/1

ip ospf authentication message-digest

ip ospf authentication-key JkT2018

R-CORE-3

interface FastEthernet0/0
ip ospf authentication message-digest

ip ospf authentication-key JkT2018

interface FastEthernet0/1
ip ospf authentication message-digest

ip ospf authentication-key JkT2018

router ospf 3

router-id 2.2.2.2
network 112.176.24.16 0.0.0.3 area 0

network 115.123.43.64 0.0.0.3 area 1

R-EDGE-R

interface FastEthernet0/0

ip ospf authentication message-digest


ip ospf authentication-key JkT2018

router ospf 1

router-id 3.3.3.3

network 115.123.43.64 0.0.0.3 area 1

- Tunnel Router Edge

R-EDGE-L

interface Tunnel101

tunnel source FastEthernet0/0


tunnel destination 115.123.43.66

router ospf 99
redistribute bgp 64515 subnets

network 192.168.123.100 0.0.0.3 area 99


network 112.131.45.120 0.0.0.3 area 99

network 112.131.45.80 0.0.0.7 area 99

R-EDGE-R

router ospf 99
network 192.168.123.100 0.0.0.3 area 99
network 112.131.46.96 0.0.0.3 area 99

network 112.131.46.0 0.0.0.255 area 99

- Jaringan Frame Relay

R-EDGE-L

interface Serial0/0/0
encapsulation frame-relay
frame-relay interface-dlci 102

frame-relay interface-dlci 103

RTR-HQ

interface Serial0/0/0
encapsulation frame-relay

frame-relay interface-dlci 201


frame-relay interface-dlci 104

RTR-BR1

interface Serial0/0/0

encapsulation frame-relay
frame-relay interface-dlci 301

frame-relay interface-dlci 401

- Jaringan PPP

RTR-BR2

username R-EDGE-R secret Jkt2018


interface Serial0/0/0
encapsulation ppp

ppp authentication chap pap


ppp pap sent-username JKT2018 password 0 !!JKTPass

R-EDGE-R

username RTR-BR2 secret Jkt2018

interface Serial0/0/0
encapsulation ppp

ppp authentication chap pap


ppp pap sent-username JKT2018 password 0 !!JKTPass

- Default Route

RTR-BR2

ip route 0.0.0.0 0.0.0.0 112.131.46.97

RTR-HQ

ip route 0.0.0.0 0.0.0.0 112.131.45.81

ip route 0.0.0.0 0.0.0.0 112.131.45.121 7

RTR-BR1

ip route 0.0.0.0 0.0.0.0 112.131.45.81

- Spesial Route

RTR-HQ

ip route 112.131.45.64 255.255.255.252 112.131.45.121

- SRV FARM

MLS-SRV

vlan 10
name SRV-RADIUS

vlan 20
name SRV-DHCP

vlan 30

name SRV-WEB
vlan 40

name SRV-DNS
vlan 50

name TLP

vlan 60
name PC-Admin

interface FastEthernet0/1
switchport access vlan 10

spanning-tree portfast
interface FastEthernet0/2

switchport access vlan 20

spanning-tree portfast
interface FastEthernet0/3

switchport access vlan 30


spanning-tree portfast

interface FastEthernet0/4

switchport access vlan 40


spanning-tree portfast

interface FastEthernet0/6
switchport access vlan 60

switchport voice vlan 50

spanning-tree portfast
interface Vlan10

ip address 172.18.12.1 255.255.255.252


ip access-group PROTECT-RADIUS out

interface Vlan20
ip address 172.18.12.5 255.255.255.252

ip access-group PROTECT-DHCP out

interface Vlan30
ip address 172.18.12.9 255.255.255.252

ip access-group PROTECT-WEB out


interface Vlan40

ip address 172.18.12.13 255.255.255.252

ip access-group PROTECT-DNS out


interface Vlan50
ip address 172.18.12.17 255.255.255.252

interface Vlan60
ip address 172.18.12.21 255.255.255.252

ip helper-address 172.18.12.6

access-list 55 permit 172.18.12.20 0.0.0.3


ip access-list extended PROTECT-RADIUS

permit udp any host 172.18.12.2 eq 1645


ip access-list extended PROTECT-DHCP

permit udp any host 172.18.12.6 eq bootps


ip access-list extended PROTECT-WEB

permit tcp any host 172.18.12.10 eq 443

ip access-list extended PROTECT-DNS


permit udp any host 172.18.12.14 eq domain

- Tunnel antara RTR-HQ dan RTR-SRV-FARM

RTR-HQ

interface Tunnel201

ip address 192.168.55.62 255.255.255.252


tunnel source FastEthernet0/0

tunnel destination 112.131.45.65

RTR-SRV-FARM

interface Tunnel200
ip address 192.168.55.61 255.255.255.252
tunnel source FastEthernet0/0

tunnel destination 112.131.45.122

- Tunnel antara RTR-HQ dan RTR-BR1

RTR-HQ

interface Tunnel144
ip address 192.168.66.201 255.255.255.252
tunnel source Serial0/0/0

tunnel destination 112.131.45.83


RTR-BR1

interface Tunnel145

ip address 192.168.66.202 255.255.255.252


tunnel source Serial0/0/0

tunnel destination 112.131.45.82

- Tunnel antara RTR-SRV-FARM dan RTR-BR2

RTR-SRV-FARM

interface Tunnel1001

ip address 192.168.101.1 255.255.255.252


tunnel source FastEthernet0/0

tunnel destination 112.131.46.98

RTR-BR2

interface Tunnel1002

ip address 192.168.101.2 255.255.255.252


tunnel source Serial0/0/0

tunnel destination 112.131.45.65

- Switching HQ

MLS1

vlan 99

name Remote
vlan 110

name LAN
vlan 120

name TLP

vlan 130
name Wireless

vtp mode server


vtp domain tKj2018.id

vtp password Jkt2018

interface Vlan1
ip address 172.16.148.61 255.255.255.252
no shutdown

interface Vlan99
ip address 172.16.99.1 255.255.255.248

interface Vlan110

ip address 172.16.110.254 255.255.255.128


interface Vlan120

ip address 172.16.120.126 255.255.255.192


interface Vlan130

ip address 172.16.130.126 255.255.255.224


spanning-tree mode rapid-pvst

spanning-tree vlan 1 root primary

ip routing
interface FastEthernet0/2

switchport trunk encapsulation dot1q


switchport mode trunk

interface FastEthernet0/3

switchport trunk encapsulation dot1q


switchport mode trunk

interface FastEthernet0/6
switchport trunk encapsulation dot1q

switchport mode trunk

MLS2

vtp mode client


vtp domain tKj2018.id
vtp password Jkt2018

spanning-tree mode rapid-pvst

spanning-tree vlan 110 root primary

interface FastEthernet0/1

switchport trunk encapsulation dot1q

switchport mode trunk


interface FastEthernet0/3
switchport trunk encapsulation dot1q

switchport mode trunk


interface FastEthernet0/4

switchport trunk encapsulation dot1q

switchport mode trunk

interface Vlan99
ip address 172.16.99.2 255.255.255.248

ip default-gateway 172.16.99.1

MLS3

vtp mode client


vtp domain tKj2018.id

vtp password Jkt2018

spanning-tree mode rapid-pvst

spanning-tree vlan 120 root primary

interface FastEthernet0/1

switchport trunk encapsulation dot1q


switchport mode trunk

interface FastEthernet0/3
switchport trunk encapsulation dot1q

switchport mode trunk


interface FastEthernet0/4

switchport trunk encapsulation dot1q


switchport mode trunk

interface FastEthernet0/5

switchport trunk encapsulation dot1q


switchport mode trunk

interface Vlan99

ip address 172.16.99.3 255.255.255.248


ip default-gateway 172.16.99.1

MLS4

vtp mode client

vtp domain tKj2018.id


vtp password Jkt2018

spanning-tree mode rapid-pvst

spanning-tree vlan 130 root primary

interface FastEthernet0/1

switchport trunk encapsulation dot1q


switchport mode trunk

interface FastEthernet0/3

switchport trunk encapsulation dot1q


switchport mode trunk

interface FastEthernet0/4
switchport trunk encapsulation dot1q

switchport mode trunk

interface FastEthernet0/5
switchport trunk encapsulation dot1q

switchport mode trunk

interface Vlan99
ip address 172.16.99.4 255.255.255.248

ip default-gateway 172.16.99.1

SW-ACC1

vtp mode client


vtp domain tKj2018.id
vtp password Jkt2018
spanning-tree mode rapid-pvst

interface FastEthernet0/1

switchport mode trunk

interface FastEthernet0/2
switchport mode trunk

interface FastEthernet0/3
switchport access vlan 110

switchport voice vlan 120


spanning-tree portfast

interface FastEthernet0/4

switchport access vlan 110


spanning-tree portfast

interface FastEthernet0/5
switchport access vlan 110

spanning-tree portfast

interface FastEthernet0/6
switchport access vlan 110

switchport voice vlan 120


spanning-tree portfast

interface FastEthernet0/7

switchport access vlan 130


spanning-tree portfast

interface Vlan99

ip address 172.16.99.5 255.255.255.248

ip default-gateway 172.16.99.1

SW-ACC2

vtp mode client


vtp domain tKj2018.id

vtp password Jkt2018


spanning-tree mode rapid-pvst

interface FastEthernet0/1

switchport mode trunk

interface FastEthernet0/2
switchport mode trunk

interface FastEthernet0/3
channel-group 1 mode on

interface FastEthernet0/4
channel-group 1 mode on

interface Vlan99
ip address 172.16.99.6 255.255.255.248

ip default-gateway 172.16.99.1

TLP-GW-1

interface FastEthernet0/0
channel-group 48

interface FastEthernet0/1

channel-group 48

- Switching Branch 1

SW1-BR1

vlan 99
name Remote

vlan 110

name AP-Lantai-1-Marketing
vlan 210

name AP-Lantai-2-Manager
vlan 200

name LAN
vlan 250

name TLP
vlan 251

name TLP-GW
vtp mode server

vtp domain jakarta.id

vtp password Jkt2018

interface Port-channel1
switchport access vlan 251

interface FastEthernet0/1
switchport mode trunk

interface FastEthernet0/2

switchport mode trunk


switchport trunk native vlan 99

interface FastEthernet0/3
switchport access vlan 200

spanning-tree portfast

interface FastEthernet0/4
switchport access vlan 99

spanning-tree portfast
interface FastEthernet0/5

switchport access vlan 251

channel-group 1 mode on
interface FastEthernet0/6

switchport access vlan 251


channel-group 1 mode on

interface Vlan99

ip address 10.99.99.3 255.255.255.0

ip default-gateway 10.99.99.254

SW2-BR1

vtp mode client


vtp domain jakarta.id
vtp password Jkt2018

interface FastEthernet0/1

switchport trunk native vlan 99

switchport mode trunk


interface FastEthernet0/2

switchport access vlan 200


switchport voice vlan 250

spanning-tree portfast
interface FastEthernet0/3

switchport trunk native vlan 99

switchport mode trunk


spanning-tree portfast

interface Vlan99

ip address 10.99.99.4 255.255.255.0

ip default-gateway 10.99.99.254

- Switching Branch 2

SW-BR2

vlan 10

vlan 20

interface FastEthernet0/1
switchport mode trunk

interface FastEthernet0/2

switchport access vlan 10


spanning-tree portfast

interface FastEthernet0/3
switchport access vlan 10

spanning-tree portfast

interface FastEthernet0/4
switchport access vlan 20
spanning-tree portfast

- Routing dinamis jaringan lokal

MLS-SRV

router ospf 1

network 172.18.12.0 0.0.0.3 area 0


network 172.18.12.4 0.0.0.3 area 0

network 172.18.12.8 0.0.0.3 area 0


network 172.18.12.12 0.0.0.3 area 0

network 172.18.12.20 0.0.0.3 area 0

network 172.18.12.32 0.0.0.3 area 0

RTR-SRV-FARM

router ospf 1
network 192.168.101.0 0.0.0.3 area 0
network 192.168.55.60 0.0.0.3 area 0

network 172.18.12.32 0.0.0.3 area 0

RTR-HQ

router ospf 1
network 192.168.44.108 0.0.0.3 area 0

network 192.168.55.60 0.0.0.3 area 0


network 192.168.66.200 0.0.0.3 area 0

MLS1

router ospf 1

network 192.168.44.108 0.0.0.3 area 0


network 172.16.99.0 0.0.0.7 area 0

network 172.16.110.128 0.0.0.127 area 0


network 172.16.120.64 0.0.0.63 area 0

network 172.16.130.96 0.0.0.31 area 0

network 172.16.148.60 0.0.0.3 area 0

RTR-BR1
router ospf 1

network 10.99.99.0 0.0.0.255 area 0


network 192.168.66.200 0.0.0.3 area 0

network 172.20.20.0 0.0.0.255 area 0

network 172.20.50.0 0.0.0.3 area 0


network 172.20.51.0 0.0.0.3 area 0

network 172.24.110.0 0.0.0.255 area 0


network 172.24.120.0 0.0.0.255 area 0

network 172.24.210.0 0.0.0.255 area 0

RTR-BR2

router ospf 1
network 172.51.10.0 0.0.0.7 area 0
network 172.51.20.0 0.0.0.3 area 0

network 192.168.101.0 0.0.0.3 area 0

- Wireless Branch 1
Pada AP Branch 1, setting controller ke ip WLC, yaitu 10.99.99.100

Pada WLC-BRANCH1, buat wireless LAN dengan identitas sesuai di soal, dengan central
control : Local switching, central authentication.

Buat AP Groups sesuai di soal dengan memasukkan access point AP Branch 1 ke dalam group

ini dan 2 Wireless LAN yang sudah dibuat tadi.


Konekan Laptop ahmad ke SSID Lantai 1 Marketing dengan user “ahmad” dan password

“ahmad123”
Konekan Laptop Ani ke SSID Lantai 2 Manager dengan user “ani” dan password “ani123”

- Telephony Service
Cukup konfigurasikan Etherchannel pada masing masing Telephony gateway yang sudah

dilakukan sebelumnya pada bab switching.

- NAT SRV-FARM

MLS-SRV

ip route 0.0.0.0 0.0.0.0 172.18.12.34


RTR-SRV-FARM

interface FastEthernet0/0

ip nat outside
interface FastEthernet0/1

ip nat inside

ip nat inside source list 99 interface FastEthernet0/0 overload

ip nat inside source static tcp 172.18.12.10 443 112.131.45.65 443

access-list 99 permit 172.18.12.20 0.0.0.3

- NAT RTR-HQ dan RTR-BR1 dan RTR-BR2

MLS1

ip route 0.0.0.0 0.0.0.0 192.168.44.109

RTR-HQ

interface FastEthernet0/0
ip nat outside
interface FastEthernet0/1

ip nat inside

interface Serial0/0/0

ip nat outside

ip nat inside source list 88 interface Serial0/0/0 overload

ip nat inside source list 99 interface FastEthernet0/0 overload

access-list 88 permit 172.16.130.96 0.0.0.31

access-list 88 permit 172.16.110.128 0.0.0.127


access-list 99 permit 172.16.130.96 0.0.0.31

access-list 99 permit 172.16.110.128 0.0.0.127

RTR-BR1

interface FastEthernet0/0.110
ip nat inside
interface FastEthernet0/0.200

ip nat inside
interface FastEthernet0/0.210

ip nat inside

ip nat inside source list 99 interface Serial0/0/0 overload

access-list 55 permit 172.18.12.20 0.0.0.3

access-list 99 permit 172.24.110.0 0.0.0.255


access-list 99 permit 172.24.210.0 0.0.0.255

access-list 99 permit 172.20.20.0 0.0.0.255

RTR-BR2

interface FastEthernet0/0.10
ip nat inside

interface FastEthernet0/0.20
ip nat outside

interface Serial0/0/0

ip nat outside

ip nat inside source list 99 interface Serial0/0/0 overload

access-list 99 permit 172.51.10.0 0.0.0.7

access-list 99 permit 172.51.20.0 0.0.0.3

- Wireless HQ

Setting AP Karyawan dengan router ip 192.168.66.1 dan subnet mask 255.255.255.240, start ip
address 192.168.166.2, maximum number of users 5. dns server 172.18.12.14

Bagian menu wireless --> Basic wireless setting, SSID KarYawanHQ, Standard channel 7
Bagian menu wireless --> Wireless security, mode WPA enterprise, Encryption TKIP, Radius

server 172.18.12.2

Bagian administrator --> router password Jkt2018,


Bagian administrator --> remote management enable

Konekan kedua laptop sesuai petunjuk soal


- Wireless router test
Dial PPPoE dengan user PPPoE@LksJKT2018 dan password P123. konfigurasi kurang lebih

sama seperti Wireless HQ

- DHCP Service pada semua kantor

MLS1

interface Vlan110
ip helper-address 172.18.12.6

interface Vlan120

ip helper-address 172.18.12.6

RTR-BR1

interface FastEthernet0/0.110
ip helper-address 172.18.12.6
interface FastEthernet0/0.200

ip helper-address 172.18.12.6

interface FastEthernet0/0.210
ip helper-address 172.18.12.6

interface FastEthernet0/0.250
ip helper-address 172.18.12.6

- Default Route

Sudah di lalukan pada bab NAT

Das könnte Ihnen auch gefallen