Difference between revisions of "Galaxy Network - Network Layout"

From Teknologisk videncenter
Jump to: navigation, search
(Predefined VLAN assocations)
m
 
(139 intermediate revisions by 2 users not shown)
Line 1: Line 1:
== Network Layout  ==
+
==IP Topology==
 +
===Amidala===
 +
<big>Interface</big>
 +
*'''Interface:''' Fast Ethernet 0/1
 +
**'''IP:''' None
 +
**'''Type:''' Etherchannel
 +
**'''Description:''' Part of Port-channel 1
 +
*'''Interface:''' Fast Ethernet 0/2
 +
**'''IP:''' None
 +
**'''Type:''' Etherchannel
 +
**'''Description:''' Part of Port-channel 1
 +
*'''Interface:''' Fast Ethernet 0/3
 +
**'''IP:''' 192.168.254.9 /30
 +
**'''Type:''' Routed
 +
**'''Description:''' Link to Leia
 +
*'''Interface:''' Fast Ethernet 0/4
 +
**'''IP:''' 192.168.254.37 /30
 +
**'''Type:''' Routed
 +
**'''Description:''' Link to Luck
 +
*'''Interface:''' Fast Ethernet 0/21
 +
**'''IP:''' 172.16.10.6 /30
 +
**'''Type:''' Routed
 +
**'''Description:''' Link to R7 (Cloud/ISP/MSPL)
 +
*'''Interface:''' Fast Ethernet 0/22
 +
**'''IP:''' 192.168.254.21 /30
 +
**'''Type:''' Routed
 +
**'''Description:''' Link to HanSolo
 +
*'''Interface:''' Fast Ethernet 0/23
 +
**'''IP:''' 192.168.254.17 /30
 +
**'''Type:''' Routed
 +
**'''Description:''' Link to MaceWindu
 +
*'''Interface:''' Fast Ethernet 0/24
 +
**'''IP:''' 192.168.254.29 /30
 +
**'''Type:''' Routed
 +
**'''Description:''' Link to QuiGon
 +
*'''Interface:''' Loopback 0
 +
**'''IP:''' 192.168.45.1 /30
 +
**'''Type:''' Routed
 +
**'''Description:''' Management interface
 +
*'''Interface:''' Port-channel 1
 +
**'''IP:''' None
 +
**'''Type:''' Switched
 +
**'''Description:''' Link to Anakin
 +
<br />
 +
<big>Routing</big>
 +
*'''Protocrol:''' EIGRP
 +
**'''AS:''' 1337
 +
**'''Networks'''
 +
***192.168.45.0 0.0.0.3
 +
***192.168.254.8 0.0.0.3
 +
***192.168.254.16 0.0.0.3
 +
***192.168.254.20 0.0.0.3
 +
***192.168.254.28 0.0.0.3
 +
***192.168.254.36 0.0.0.3
 +
<br />
 +
----
 +
<br />
  
=== IP Topology  ===
+
===Anakin===
 +
<big>Interface</big>
 +
*'''Interface:''' Fast Ethernet 0/1
 +
**'''IP:''' None
 +
**'''Type:''' Etherchannel
 +
**'''Description:''' Part of Port-channel 1
 +
*'''Interface:''' Fast Ethernet 0/2
 +
**'''IP:''' None
 +
**'''Type:''' Etherchannel
 +
**'''Description:''' Part of Port-channel 1
 +
*'''Interface:''' Fast Ethernet 0/3
 +
**'''IP:''' 192.168.254.5 /30
 +
**'''Type:''' Routed
 +
**'''Description:''' Link to Luke
 +
*'''Interface:''' Fast Ethernet 0/4
 +
**'''IP:''' 192.168.254.1 /30
 +
**'''Type:''' Routed
 +
**'''Description:''' Link to Leia
 +
*'''Interface:''' Fast Ethernet 0/21
 +
**'''IP:''' 172.16.10.2 /30
 +
**'''Type:''' Routed
 +
**'''Description:''' Link to R4 (Cloud/ISP/MSPL)
 +
*'''Interface:''' Fast Ethernet 0/22
 +
**'''IP:''' 192.168.254.25 /30
 +
**'''Type:''' Routed
 +
**'''Description:''' Link to Palpatine
 +
*'''Interface:''' Fast Ethernet 0/23
 +
**'''IP:''' 192.168.254.13 /30
 +
**'''Type:''' Routed
 +
**'''Description:''' Link to MaceWindu
 +
*'''Interface:''' Fast Ethernet 0/24
 +
**'''IP:''' 192.168.254.33 /30
 +
**'''Type:''' Routed
 +
**'''Description:''' Link to ObiWan
 +
*'''Interface:''' Loopback 0
 +
**'''IP:''' 192.168.45.5 /30
 +
**'''Type:''' Routed
 +
**'''Description:''' Management interface
 +
*'''Interface:''' Port-channel 1
 +
**'''IP:''' None
 +
**'''Type:''' Switched
 +
**'''Description:''' Link to Amidala
 +
<br />
  
Amidala
+
<big>Routing</big>
<pre>Interfaces
+
*'''Protocrol:''' EIGRP
{| summary="Interfaces"
+
**'''AS:''' 1337
|-
+
**'''Networks'''
!Interface
+
***192.168.45.4 0.0.0.3
!IP
+
***192.168.254.0 0.0.0.3
!Type
+
***192.168.254.4 0.0.0.3
!Description
+
***192.168.254.12 0.0.0.3
&gt; FA 0/1 + FA 0/2: Etherchannel (trunked) to Anakin
+
***192.168.254.24 0.0.0.3
&gt; FA 0/3: - Trunk link to Leia.
+
***192.168.254.32 0.0.0.3
&gt; FA 0/4: - Trunk link to Luke.
+
<br />
&gt; FA 0/21: 172.16.10.6    (172.16.10.4 /30) - Routed link to R7 (Cloud).
+
----
&gt; FA 0/22: 192.168.254.21  (192.168.254.20 /30) - Routed link to HanSolo.
+
<br />
&gt; FA 0/23: - Trunk link to MaceWindu
 
&gt; FA 0/24: 192.168.254.29  (192.168.254.28 /30) - Routed link to QuiGon.
 
EIGRP: 1337
 
&gt; 192.168.254.8  (0.0.0.3)
 
&gt; 192.168.254.16 (0.0.0.3)
 
&gt; 192.168.254.20 (0.0.0.3)
 
&gt; 192.168.254.28 (0.0.0.3)
 
&gt; 192.168.254.36 (0.0.0.3)
 
</pre>  
 
Anakin
 
  
- Interfaces
+
===QuiGon===
 +
<big>Interface</big>
 +
*'''Interface:''' Serial 0/3/0
 +
**'''IP:''' 192.168.50.1 /30
 +
**'''Type:''' Routed
 +
**'''Description:''' Link to ObiWan DTC (128.000)
 +
*'''Interface:''' Serial 0/3/1
 +
**'''IP:''' 192.168.50.5 /30
 +
**'''Type:''' Routed
 +
**'''Description:''' Link to ObiWan DTE
 +
*'''Interface:''' Fast Ethernet 0/0
 +
**'''IP:''' DHCP
 +
**'''Type:''' Routed
 +
**'''Description:''' Link to Mercantec (WAN NAT w/ ACL 1)
 +
*'''Interface:''' Fast Ethernet 0/1
 +
**'''IP:''' 192.168.254.30 /30
 +
**'''Type:''' Routed
 +
**'''Description:''' Link to Amidala
 +
*'''Interface:''' Loopback 0
 +
**'''IP:''' 192.168.45.9 /30
 +
**'''Type:''' Routed
 +
**'''Description:''' Management interface
 +
<br />
 +
<big>Routing</big>
 +
*'''Protocrol:''' EIGRP
 +
**'''AS:''' 1337
 +
**'''Networks'''
 +
***192.168.45.9 0.0.0.3
 +
***192.168.50.0 0.0.0.3
 +
***192.168.50.4 0.0.0.3
 +
***192.168.254.28 0.0.0.3
 +
<br />
 +
<big>Access List</big>
 +
*'''Access List'''
 +
**'''Number:''' 1
 +
***'''IP:''' 172.42.10.0
 +
***'''Wilcrad/Netmask:''' 0.0.0.255
 +
***'''Type:'''permit
 +
***'''IP:''' 172.42.20.0
 +
***'''Wilcrad/Netmask:''' 0.0.0.255
 +
***'''Type:'''permit
 +
<br />
 +
----
 +
<br />
  
&gt; FA 0/1 + FA 0/2: Etherchannel (trunked) to Amidala &gt; FA 0/3: 192.168.254.5 (192.168.254.4 /30) - Routed link to Luke. &gt; FA 0/4: 192.168.254.1 (192.168.254.0 /30) - Routed link to Leia. &gt; FA 0/21: 172.16.10.2 (192.168.10.0 /30) - Routed link to R4 (Cloud). &gt; FA 0/22: 192.168.254.25 (192.168.254.24 /30) - Routed link to Palpatine. &gt; FA 0/23: 192.168.254.13 (192.168.254.12 /30) - Routed link to MaceWindu. &gt; FA 0/24: 192.168.254.33 (192.168.254.32 /30) - Routed link to ObiWan.
+
===ObiWan===
 +
<big>Interface</big>
 +
*'''Interface:''' Serial 0/1/0
 +
**'''IP:''' 192.168.50.6 /30
 +
**'''Type:''' Routed
 +
**'''Description:''' Link to QuiGon DCE
 +
*'''Interface:''' Serial 0/1/1
 +
**'''IP:''' 192.168.50.2 /30
 +
**'''Type:''' Routed
 +
**'''Description:''' Link to QuiGon DTC (128.000)
 +
*'''Interface:''' Fast Ethernet 0/0
 +
**'''IP:''' DHCP
 +
**'''Type:''' Routed
 +
**'''Description:''' Link to Mercantec (WAN NAT w/ ACL 1)
 +
*'''Interface:''' Fast Ethernet 0/1
 +
**'''IP:''' 192.168.254.34 /30
 +
**'''Type:''' Routed
 +
**'''Description:''' Link to Anakin
 +
*'''Interface:''' Loopback 0
 +
**'''IP:''' 192.168.45.13 /30
 +
**'''Type:''' Routed
 +
**'''Description:''' Management interface
 +
<br />
 +
<big>Routing</big>
 +
*'''Protocrol:''' EIGRP
 +
**'''AS:''' 1337
 +
**'''Networks'''
 +
***192.168.45.12 0.0.0.3
 +
***192.168.50.0 0.0.0.3
 +
***192.168.50.4 0.0.0.3
 +
***192.168.254.32 0.0.0.3
 +
<br />
 +
<big>Access List</big>
 +
*'''Access List'''
 +
**'''Number:''' 1
 +
***'''IP:''' 172.42.10.0
 +
***'''Wilcrad/Netmask:''' 0.0.0.255
 +
***'''Type:'''permit
 +
***'''IP:''' 172.42.20.0
 +
***'''Wilcrad/Netmask:''' 0.0.0.255
 +
***'''Type:'''permit
 +
<br />
 +
----
 +
<br />
  
- EIGRP 1337
+
===MaceWindu===
 +
<big>Interface</big>
 +
*'''Interface:''' Fast Ethernet 0/1
 +
**'''IP:''' 192.168.254.14 /30
 +
**'''Type:''' Routed
 +
**'''Description:''' Link to Anakin
 +
*'''Interface:''' Fast Ethernet 0/2
 +
**'''IP:''' 192.168.254.18 /30
 +
**'''Type:''' Routed
 +
**'''Description:''' Link to Amidala
 +
*'''Interface:''' Fast Ethernet 0/24
 +
**'''IP:''' None
 +
**'''Type:''' Switched
 +
**'''Description:''' Link to Cisco Call Manager
 +
*'''Interface:''' Loopback 0
 +
**'''IP:''' 192.168.45.33 /30
 +
**'''Type:''' Routed
 +
**'''Description:''' Management interface
 +
<br />
 +
<big>Routing</big>
 +
*'''Protocrol:''' EIGRP
 +
**'''AS:''' 1337
 +
**'''Networks'''
 +
***192.168.22.0 0.0.0.255
 +
***192.168.45.33 0.0.0.3
 +
***192.168.254.12 0.0.0.3
 +
***192.168.254.16 0.0.0.3
 +
<br />
 +
----
 +
<br />
  
&gt; 192.168.254.0 (0.0.0.3) &gt; 192.168.254.4 (0.0.0.3) &gt; 192.168.254.12 (0.0.0.3) &gt; 192.168.254.24 (0.0.0.3) &gt; 192.168.254.32 (0.0.0.3)
+
===HanSolo===
 +
<big>Interface</big>
 +
*'''Interface:''' Fast Ethernet 0/0
 +
**'''IP:''' 192.168.254.22 /30
 +
**'''Type:''' Routed
 +
**'''Description:''' Link to Amidala
 +
*'''Interface:''' Loopback 0
 +
**'''IP:''' 192.168.45.53 /30
 +
**'''Type:''' Routed
 +
**'''Description:''' Management interface
 +
<br />
 +
<big>Routing</big>
 +
*'''Protocrol:''' EIGRP
 +
**'''AS:''' 1337
 +
**'''Networks'''
 +
***192.168.45.53 0.0.0.3
 +
***192.168.254.20 0.0.0.3
 +
<br />
 +
----
 +
<br />
  
QuiGon
+
===Palpatine===
 +
<big>Interface</big>
 +
*'''Interface:''' Fast Ethernet 0/0.10
 +
**'''IP:''' 172.42.10.1 /24
 +
**'''Type:''' Routed
 +
**'''Description:''' Gateway for wireless clients
 +
*'''Interface:''' Fast Ethernet 0/0.100
 +
**'''IP:''' 172.42.100.1 /24
 +
**'''Type:''' Routed
 +
**'''Description:''' Gateway for Equipment
 +
*'''Interface:''' Fast Ethernet 0/1
 +
**'''IP:''' 192.168.254.26 /30
 +
**'''Type:''' Routed
 +
**'''Description:''' Link to Anakin
 +
*'''Interface:''' Loopback 0
 +
**'''IP:''' 192.168.45.17 /30
 +
**'''Type:''' Routed
 +
**'''Description:''' Management interface
 +
*'''Interface:''' Wlan-Controller
 +
**'''IP:''' 192.168.45.21 /30
 +
**'''Type:''' Routed
 +
**'''Description:''' Management interface
 +
*'''Interface:''' AP-Management
 +
**'''IP:''' 192.168.45.25 /30
 +
**'''Type:''' Routed
 +
**'''Description:''' AP Management interface
 +
<br />
 +
<big>Routing</big>
 +
*'''Protocrol:''' EIGRP
 +
**'''AS:''' 1337
 +
**'''Networks'''
 +
***172.42.10.0 0.0.0.255
 +
***172.42.100.0 0.0.0.255
 +
***192.168.45.16 0.0.0.3
 +
***192.168.45.20 0.0.0.3
 +
***192.168.45.24 0.0.0.3
 +
***192.168.254.24 0.0.0.3
 +
<br />
 +
----
 +
<br />
  
- Interfaces
+
===Luke===
 +
<big>Interface</big>
 +
*'''Interface:''' Fast Ethernet 0/1
 +
**'''IP:''' None
 +
**'''Type:''' Etherchannel
 +
**'''Description:''' Part of Port-channel ?
 +
*'''Interface:''' Fast Ethernet 0/2
 +
**'''IP:''' None
 +
**'''Type:''' Etherchannel
 +
**'''Description:''' Part of Port-channel ?
 +
*'''Interface:''' Fast Ethernet 0/3
 +
**'''IP:''' 192.168.254.6 /30
 +
**'''Type:''' Routed
 +
**'''Description:''' Link to Anakin
 +
*'''Interface:''' Fast Ethernet 0/4
 +
**'''IP:''' 192.168.254.38 /30
 +
**'''Type:''' Routed
 +
**'''Description:''' Link to Amadala
 +
*'''Interface:''' Fast Ethernet 0/23
 +
**'''IP:''' None
 +
**'''Type:''' Etherchannel
 +
**'''Description:''' Part of Port-channel ?
 +
*'''Interface:''' Fast Ethernet 0/24
 +
**'''IP:''' None
 +
**'''Type:''' Etherchannel
 +
**'''Description:''' Part of Port-channel ?
 +
*'''Interface:''' Port-channel 1
 +
**'''IP:''' None
 +
**'''Type:''' Switched
 +
**'''Description:''' Trunk link to ?
 +
*'''Interface:''' Port-channel
 +
**'''IP:''' None
 +
**'''Type:''' Switched
 +
**'''Description:''' Trunk link to ?
 +
*'''Interface:''' Loopback 0
 +
**'''IP:''' 192.168.45.37 /30
 +
**'''Type:''' Routed
 +
**'''Description:''' Management interface
 +
<br />
  
<span> &gt; S 0/3/0: 192.168.50.1  (192.168.50.0 /30)  - DTC (128.000) link to ObiWan.
+
<big>Routing</big>
&gt; S 0/3/1: 192.168.50.5  (192.168.50.4 /30)  - DTE link to ObiWan.
+
*'''Protocrol:''' EIGRP
&gt; FA 0/0:  DHCP (NAT w/ ACL 1)                - Link to Mercantec <span onmouseover="TagToTip('WAN')" onmouseout="UnTip()" style="cursor:help">WAN</span>. &gt; FA 0/1: 192.168.254.30 (192.168.254.28 /30) - Routed link to Amidala.</span>
+
**'''AS:''' 1337
 +
**'''Networks'''
 +
***172.42.20.0 0.0.0.255
 +
***192.168.45.8 0.0.0.3
 +
***192.168.200.0 0.0.0.255
 +
***192.168.254.4 0.0.0.3
 +
***192.168.254.36 0.0.0.3
 +
<br />
 +
----
 +
<br />
  
- EIGRP 1337
+
===Leia===
 +
<big>Interface</big>
 +
*'''Interface:''' Fast Ethernet 0/1
 +
**'''IP:''' None
 +
**'''Type:''' Etherchannel
 +
**'''Description:''' Part of Port-channel 2
 +
*'''Interface:''' Fast Ethernet 0/2
 +
**'''IP:''' None
 +
**'''Type:''' Etherchannel
 +
**'''Description:''' Part of Port-channel 2
 +
*'''Interface:''' Fast Ethernet 0/3
 +
**'''IP:''' 192.168.45.10 /30
 +
**'''Type:''' Routed
 +
**'''Description:''' Link to Amadala
 +
*'''Interface:''' Fast Ethernet 0/4
 +
**'''IP:''' 192.168.45.2 /30
 +
**'''Type:''' Routed
 +
**'''Description:''' Link to Anakin
 +
*'''Interface:''' Fast Ethernet 0/23
 +
**'''IP:''' None
 +
**'''Type:''' Etherchannel
 +
**'''Description:''' Part of Port-channel 1
 +
*'''Interface:''' Fast Ethernet 0/24
 +
**'''IP:''' None
 +
**'''Type:''' Etherchannel
 +
**'''Description:''' Part of Port-channel 1
 +
*'''Interface:''' Port-channel 1
 +
**'''IP:''' None
 +
**'''Type:''' Switched
 +
**'''Description:''' Trunk link to Luke
 +
*'''Interface:''' Port-channel 2
 +
**'''IP:''' None
 +
**'''Type:''' Switched
 +
**'''Description:''' Trunk link to R2D2
 +
*'''Interface:''' Loopback 0
 +
**'''IP:''' 192.168.45.41 /30
 +
**'''Type:''' Routed
 +
**'''Description:''' Management interface
 +
<br />
  
&gt; 192.168.50.0 (0.0.0.3) &gt; 192.168.254.28 (0.0.0.3) &gt; 192.168.254.40 (0.0.0.3)
+
<big>Routing</big>
 +
*'''Protocrol:''' EIGRP
 +
**'''AS:''' 1337
 +
**'''Networks'''
 +
***172.42.20.0 0.0.0.255
 +
***192.168.200.0 0.0.0.255
 +
***192.168.254.0 0.0.0.3
 +
***192.168.254.8 0.0.0.3
 +
<br />
 +
----
 +
<br />
  
<span>- <span onmouseover="TagToTip('access')" onmouseout="UnTip()" style="cursor:help">Access</span>-List 1
+
===R2D2===
</span>
+
<big>Interface</big>
 +
*'''Interface:''' Fast Ethernet 0/1
 +
**'''IP:''' None
 +
**'''Type:''' Etherchannel
 +
**'''Description:''' Part of Port-channel ?
 +
*'''Interface:''' Fast Ethernet 0/2
 +
**'''IP:''' None
 +
**'''Type:''' Etherchannel
 +
**'''Description:''' Part of Port-channel ?
 +
*'''Interface:''' Gigabit Ethernet 0/1
 +
**'''IP:''' None
 +
**'''Type:''' Etherchannel
 +
**'''Description:''' Part of Port-channel ?
 +
*'''Interface:''' Gigabit Ethernet 0/2
 +
**'''IP:''' None
 +
**'''Type:''' Etherchannel
 +
**'''Description:''' Part of Port-channel ?
 +
*'''Interface:''' Port-channel 1
 +
**'''IP:''' None
 +
**'''Type:''' Switched
 +
**'''Description:''' Trunk link to ?
 +
*'''Interface:''' Port-channel 2
 +
**'''IP:''' None
 +
**'''Type:''' Etherchannel
 +
**'''Description:''' Trunk link to ?
 +
*'''Interface:''' Vlan 85
 +
**'''IP:''' 192.168.45.45 /30
 +
**'''Type:''' Routed
 +
**'''Description:''' Management interface
 +
<br />
 +
----
 +
<br />
  
&gt; permit 172.42.10.0 (0.0.0.255) &gt; permit 172.42.20.0 (0.0.0.255)
+
===C3PO===
 +
<big>Interface</big>
 +
*'''Interface:''' Fast Ethernet 0/1
 +
**'''IP:''' None
 +
**'''Type:''' Etherchannel
 +
**'''Description:''' Part of Port-channel ?
 +
*'''Interface:''' Fast Ethernet 0/2
 +
**'''IP:''' None
 +
**'''Type:''' Etherchannel
 +
**'''Description:''' Part of Port-channel ?
 +
*'''Interface:''' Gigabit Ethernet 0/1
 +
**'''IP:''' None
 +
**'''Type:''' Etherchannel
 +
**'''Description:''' Part of Port-channel ?
 +
*'''Interface:''' Gigabit Ethernet 0/2
 +
**'''IP:''' None
 +
**'''Type:''' Etherchannel
 +
**'''Description:''' Part of Port-channel ?
 +
*'''Interface:''' Port-channel 1
 +
**'''IP:''' None
 +
**'''Type:''' Switched
 +
**'''Description:''' Trunk link to ?
 +
*'''Interface:''' Port-channel 2
 +
**'''IP:''' None
 +
**'''Type:''' Etherchannel
 +
**'''Description:''' Trunk link to ?
 +
*'''Interface:''' Vlan 85
 +
**'''IP:''' 192.168.45.49 /30
 +
**'''Type:''' Routed
 +
**'''Description:''' Management interface
 +
<br />
 +
----
 +
<br />
  
ObiWan
+
== VLAN Topology  ==
  
- Interfaces
+
In order to allow our network to be scalable, we have allocated VLAN ranges to specific areas.
 +
Please note that even though we only use a range of 1000 VLANs.
  
<span> &gt; S 0/1/0: 192.168.50.6 (192.168.50.4 /30)    - DCE (128.000) link to QuiGon.
+
=== Predefined VLAN assocations ===
&gt; S 0/1/1: 192.168.50.2 (192.168.50.0 /30)    - DTE link to QuiGon.
+
<span>While only a few of these VLANs are actually in use,
&gt; FA 0/0:  DHCP (NAT w/ ACL 1)                - Link to Mercantec <span onmouseover="TagToTip('WAN')" onmouseout="UnTip()" style="cursor:help">WAN</span>. &gt; FA 0/1: 192.168.254.34 (192.168.254.32 /30) - Routed link to Anakin.</span>
+
the VLAN ranges will <span onmouseover="TagToTip('allow')" onmouseout="UnTip()" style="cursor:help">allow</span> our network to scale almost indefinitely.</span>
  
- EIGRP 1337
+
*'''1:''' Not in use; clear from all trunks. This is a Cisco best practice implementation (not required).
 +
*'''2-99:''' Management VLAN on all switches.
 +
*'''100–399:''' Access layer devices.
 +
*'''400–599:''' Data center devices.
 +
*'''600–699:''' Internet and partner connections.
 +
*'''700–899:''' Reserved for future use.
 +
*'''900–999:''' Point-to-point links between switches (Layer 3).
  
&gt; 192.168.50.0 (0.0.0.3) &gt; 192.168.254.32 (0.0.0.3)
+
=== VLANs currently in use ===
  
<span>- <span onmouseover="TagToTip('access')" onmouseout="UnTip()" style="cursor:help">Access</span>-List 1
+
* '''VLAN 45:''' Management VLAN used on all switches in the network.
</span>
+
* '''VLAN 100:''' Skywalker Enterprises.
 +
* '''VLAN 101:''' IP Phone.
 +
* '''VLAN 102:''' Wireless clients.
 +
* '''VLAN 400:''' Wireless.
 +
* '''VLAN 401:''' Wide-Area Network.
 +
* '''VLAN 402:''' ISDN/PSTN.
  
&gt; permit 172.42.10.0 (0.0.0.255) &gt; permit 172.42.20.0 (0.0.0.255)
+
=== Configuration of VLAN Layer-2 Security ===
 +
<pre>vlan access-map NAME 10
 +
match ip address <telnet access list>
 +
action drop
 +
vlan access-map 20
 +
match ip address <ssh access list>
 +
action forward
  
MaceWindu
+
switchport mode access (default)
 +
N/A (default)
 +
no cdp enable
 +
udld port disable
  
- Interfaces
+
interface vlan <management vlan>
  
&gt; FA 0/1: 192.168.254.14 (192.168.254.12 /30) - Routed link to Anakin. &gt; FA 0/2: 192.168.254.18 (192.168.254.16 /30) - Routed link to Amidala. &gt; FA 0/24: Switchport link to Cisco Call Manager.
+
switchport trunk allowed vlan remove 1
 +
</pre>
  
- EIGRP 1337
+
=== Configuration of Interface Security ===
 +
<pre>switchport mode access (default)
 +
N/A (default)
 +
no cdp enable
 +
udld port disable
 +
spanning-tree portfast
 +
spanning-tree portfast bpduguard default
  
&gt; 192.168.22.73 (0.0.0.3) &gt; 192.168.254.12 (0.0.0.3) &gt; 192.168.254.16 (0.0.0.3)
+
spanning-tree guard root
  
HanSolo
+
vtp mode transparent
  
- Interfaces
+
no mls qos trust {default}
 
 
&gt; FA 0/0: 192.168.254.22 (192.168.254.20 /30) - Routed link to Amidala.
 
 
 
- VTP Mode: Client
 
 
 
Palpatine
 
 
 
- Interfaces
 
 
 
&gt; FA 0/0: 172.42.10.1 (172.42.10.0 /24) - Gateway for wireless clients. &gt; FA 0/1: 192.168.254.26 (192.168.254.24 /30) - Routed link to Anakin.
 
 
 
- EIGRP 1337
 
 
 
&gt; 172.42.10.0 (0.0.0.255) &gt; 192.168.254.24 (0.0.0.3)
 
 
 
ip host Amidala 192.168.45.1 /30 ip host Anakin 192.168.45.5 /30 ip host QuiGon 192.168.45.9 /30 ip host ObiWan 192.168.45.13 /30 ip host Palpatine 192.168.45.17 192.168.45.21 192.168.45.25 /30 ip host Yoda 192.168.45.29 /30 ip host MaceWindu 192.168.45.33 /30 ip host Luke 192.168.45.37 /30 ip host Leia 192.168.45.41 /30 ip host R2D2 192.168.45.45 /30 ip host C3PO 192.168.45.49 /30 ip host HanSolo 192.168.45.53 /30 ip host Chewbacca 192.168.45.57 /30
 
 
 
=== VLAN Topology  ===
 
 
 
==== Predefined VLAN assocations ====
 
----
 
<span>While only a few of these VLANs are actually in use,
 
the VLAN ranges will <span onmouseover="TagToTip('allow')" onmouseout="UnTip()" style="cursor:help">allow</span> our network to scale almost indefinitely.</span>
 
 
 
*'''1:''' Not in use; clear from all trunks. This is a Cisco best practice implementation (not required).
 
*'''2–99:''' Management VLANs.
 
*'''100–399:''' Access layer devices.
 
*'''400–599:''' Data center devices
 
*'''600–699:''' Internet and partner connections.
 
*'''700–899:''' Reserved for future use.
 
*'''900–999:''' Point-to-point links between switches (Layer 3).
 
  
==== VLANs currently in use ====
+
shutdown
 +
</pre>
  
The following VLANs are in use.
+
==Network Topology==
 +
===Campus Model===
 +
<div>
 +
<p>
 +
[[Image:Star_Wars_-_Campus_Model.jpg]]<br />
 +
A compus model of the Galaxy network
 +
</p>
 +
</div>
 +
[[category:CCNP3]]

Latest revision as of 14:53, 5 August 2009

IP Topology

Amidala

Interface

  • Interface: Fast Ethernet 0/1
    • IP: None
    • Type: Etherchannel
    • Description: Part of Port-channel 1
  • Interface: Fast Ethernet 0/2
    • IP: None
    • Type: Etherchannel
    • Description: Part of Port-channel 1
  • Interface: Fast Ethernet 0/3
    • IP: 192.168.254.9 /30
    • Type: Routed
    • Description: Link to Leia
  • Interface: Fast Ethernet 0/4
    • IP: 192.168.254.37 /30
    • Type: Routed
    • Description: Link to Luck
  • Interface: Fast Ethernet 0/21
    • IP: 172.16.10.6 /30
    • Type: Routed
    • Description: Link to R7 (Cloud/ISP/MSPL)
  • Interface: Fast Ethernet 0/22
    • IP: 192.168.254.21 /30
    • Type: Routed
    • Description: Link to HanSolo
  • Interface: Fast Ethernet 0/23
    • IP: 192.168.254.17 /30
    • Type: Routed
    • Description: Link to MaceWindu
  • Interface: Fast Ethernet 0/24
    • IP: 192.168.254.29 /30
    • Type: Routed
    • Description: Link to QuiGon
  • Interface: Loopback 0
    • IP: 192.168.45.1 /30
    • Type: Routed
    • Description: Management interface
  • Interface: Port-channel 1
    • IP: None
    • Type: Switched
    • Description: Link to Anakin


Routing

  • Protocrol: EIGRP
    • AS: 1337
    • Networks
      • 192.168.45.0 0.0.0.3
      • 192.168.254.8 0.0.0.3
      • 192.168.254.16 0.0.0.3
      • 192.168.254.20 0.0.0.3
      • 192.168.254.28 0.0.0.3
      • 192.168.254.36 0.0.0.3




Anakin

Interface

  • Interface: Fast Ethernet 0/1
    • IP: None
    • Type: Etherchannel
    • Description: Part of Port-channel 1
  • Interface: Fast Ethernet 0/2
    • IP: None
    • Type: Etherchannel
    • Description: Part of Port-channel 1
  • Interface: Fast Ethernet 0/3
    • IP: 192.168.254.5 /30
    • Type: Routed
    • Description: Link to Luke
  • Interface: Fast Ethernet 0/4
    • IP: 192.168.254.1 /30
    • Type: Routed
    • Description: Link to Leia
  • Interface: Fast Ethernet 0/21
    • IP: 172.16.10.2 /30
    • Type: Routed
    • Description: Link to R4 (Cloud/ISP/MSPL)
  • Interface: Fast Ethernet 0/22
    • IP: 192.168.254.25 /30
    • Type: Routed
    • Description: Link to Palpatine
  • Interface: Fast Ethernet 0/23
    • IP: 192.168.254.13 /30
    • Type: Routed
    • Description: Link to MaceWindu
  • Interface: Fast Ethernet 0/24
    • IP: 192.168.254.33 /30
    • Type: Routed
    • Description: Link to ObiWan
  • Interface: Loopback 0
    • IP: 192.168.45.5 /30
    • Type: Routed
    • Description: Management interface
  • Interface: Port-channel 1
    • IP: None
    • Type: Switched
    • Description: Link to Amidala


Routing

  • Protocrol: EIGRP
    • AS: 1337
    • Networks
      • 192.168.45.4 0.0.0.3
      • 192.168.254.0 0.0.0.3
      • 192.168.254.4 0.0.0.3
      • 192.168.254.12 0.0.0.3
      • 192.168.254.24 0.0.0.3
      • 192.168.254.32 0.0.0.3




QuiGon

Interface

  • Interface: Serial 0/3/0
    • IP: 192.168.50.1 /30
    • Type: Routed
    • Description: Link to ObiWan DTC (128.000)
  • Interface: Serial 0/3/1
    • IP: 192.168.50.5 /30
    • Type: Routed
    • Description: Link to ObiWan DTE
  • Interface: Fast Ethernet 0/0
    • IP: DHCP
    • Type: Routed
    • Description: Link to Mercantec (WAN NAT w/ ACL 1)
  • Interface: Fast Ethernet 0/1
    • IP: 192.168.254.30 /30
    • Type: Routed
    • Description: Link to Amidala
  • Interface: Loopback 0
    • IP: 192.168.45.9 /30
    • Type: Routed
    • Description: Management interface


Routing

  • Protocrol: EIGRP
    • AS: 1337
    • Networks
      • 192.168.45.9 0.0.0.3
      • 192.168.50.0 0.0.0.3
      • 192.168.50.4 0.0.0.3
      • 192.168.254.28 0.0.0.3


Access List

  • Access List
    • Number: 1
      • IP: 172.42.10.0
      • Wilcrad/Netmask: 0.0.0.255
      • Type:permit
      • IP: 172.42.20.0
      • Wilcrad/Netmask: 0.0.0.255
      • Type:permit




ObiWan

Interface

  • Interface: Serial 0/1/0
    • IP: 192.168.50.6 /30
    • Type: Routed
    • Description: Link to QuiGon DCE
  • Interface: Serial 0/1/1
    • IP: 192.168.50.2 /30
    • Type: Routed
    • Description: Link to QuiGon DTC (128.000)
  • Interface: Fast Ethernet 0/0
    • IP: DHCP
    • Type: Routed
    • Description: Link to Mercantec (WAN NAT w/ ACL 1)
  • Interface: Fast Ethernet 0/1
    • IP: 192.168.254.34 /30
    • Type: Routed
    • Description: Link to Anakin
  • Interface: Loopback 0
    • IP: 192.168.45.13 /30
    • Type: Routed
    • Description: Management interface


Routing

  • Protocrol: EIGRP
    • AS: 1337
    • Networks
      • 192.168.45.12 0.0.0.3
      • 192.168.50.0 0.0.0.3
      • 192.168.50.4 0.0.0.3
      • 192.168.254.32 0.0.0.3


Access List

  • Access List
    • Number: 1
      • IP: 172.42.10.0
      • Wilcrad/Netmask: 0.0.0.255
      • Type:permit
      • IP: 172.42.20.0
      • Wilcrad/Netmask: 0.0.0.255
      • Type:permit




MaceWindu

Interface

  • Interface: Fast Ethernet 0/1
    • IP: 192.168.254.14 /30
    • Type: Routed
    • Description: Link to Anakin
  • Interface: Fast Ethernet 0/2
    • IP: 192.168.254.18 /30
    • Type: Routed
    • Description: Link to Amidala
  • Interface: Fast Ethernet 0/24
    • IP: None
    • Type: Switched
    • Description: Link to Cisco Call Manager
  • Interface: Loopback 0
    • IP: 192.168.45.33 /30
    • Type: Routed
    • Description: Management interface


Routing

  • Protocrol: EIGRP
    • AS: 1337
    • Networks
      • 192.168.22.0 0.0.0.255
      • 192.168.45.33 0.0.0.3
      • 192.168.254.12 0.0.0.3
      • 192.168.254.16 0.0.0.3




HanSolo

Interface

  • Interface: Fast Ethernet 0/0
    • IP: 192.168.254.22 /30
    • Type: Routed
    • Description: Link to Amidala
  • Interface: Loopback 0
    • IP: 192.168.45.53 /30
    • Type: Routed
    • Description: Management interface


Routing

  • Protocrol: EIGRP
    • AS: 1337
    • Networks
      • 192.168.45.53 0.0.0.3
      • 192.168.254.20 0.0.0.3




Palpatine

Interface

  • Interface: Fast Ethernet 0/0.10
    • IP: 172.42.10.1 /24
    • Type: Routed
    • Description: Gateway for wireless clients
  • Interface: Fast Ethernet 0/0.100
    • IP: 172.42.100.1 /24
    • Type: Routed
    • Description: Gateway for Equipment
  • Interface: Fast Ethernet 0/1
    • IP: 192.168.254.26 /30
    • Type: Routed
    • Description: Link to Anakin
  • Interface: Loopback 0
    • IP: 192.168.45.17 /30
    • Type: Routed
    • Description: Management interface
  • Interface: Wlan-Controller
    • IP: 192.168.45.21 /30
    • Type: Routed
    • Description: Management interface
  • Interface: AP-Management
    • IP: 192.168.45.25 /30
    • Type: Routed
    • Description: AP Management interface


Routing

  • Protocrol: EIGRP
    • AS: 1337
    • Networks
      • 172.42.10.0 0.0.0.255
      • 172.42.100.0 0.0.0.255
      • 192.168.45.16 0.0.0.3
      • 192.168.45.20 0.0.0.3
      • 192.168.45.24 0.0.0.3
      • 192.168.254.24 0.0.0.3




Luke

Interface

  • Interface: Fast Ethernet 0/1
    • IP: None
    • Type: Etherchannel
    • Description: Part of Port-channel ?
  • Interface: Fast Ethernet 0/2
    • IP: None
    • Type: Etherchannel
    • Description: Part of Port-channel ?
  • Interface: Fast Ethernet 0/3
    • IP: 192.168.254.6 /30
    • Type: Routed
    • Description: Link to Anakin
  • Interface: Fast Ethernet 0/4
    • IP: 192.168.254.38 /30
    • Type: Routed
    • Description: Link to Amadala
  • Interface: Fast Ethernet 0/23
    • IP: None
    • Type: Etherchannel
    • Description: Part of Port-channel ?
  • Interface: Fast Ethernet 0/24
    • IP: None
    • Type: Etherchannel
    • Description: Part of Port-channel ?
  • Interface: Port-channel 1
    • IP: None
    • Type: Switched
    • Description: Trunk link to ?
  • Interface: Port-channel
    • IP: None
    • Type: Switched
    • Description: Trunk link to ?
  • Interface: Loopback 0
    • IP: 192.168.45.37 /30
    • Type: Routed
    • Description: Management interface


Routing

  • Protocrol: EIGRP
    • AS: 1337
    • Networks
      • 172.42.20.0 0.0.0.255
      • 192.168.45.8 0.0.0.3
      • 192.168.200.0 0.0.0.255
      • 192.168.254.4 0.0.0.3
      • 192.168.254.36 0.0.0.3




Leia

Interface

  • Interface: Fast Ethernet 0/1
    • IP: None
    • Type: Etherchannel
    • Description: Part of Port-channel 2
  • Interface: Fast Ethernet 0/2
    • IP: None
    • Type: Etherchannel
    • Description: Part of Port-channel 2
  • Interface: Fast Ethernet 0/3
    • IP: 192.168.45.10 /30
    • Type: Routed
    • Description: Link to Amadala
  • Interface: Fast Ethernet 0/4
    • IP: 192.168.45.2 /30
    • Type: Routed
    • Description: Link to Anakin
  • Interface: Fast Ethernet 0/23
    • IP: None
    • Type: Etherchannel
    • Description: Part of Port-channel 1
  • Interface: Fast Ethernet 0/24
    • IP: None
    • Type: Etherchannel
    • Description: Part of Port-channel 1
  • Interface: Port-channel 1
    • IP: None
    • Type: Switched
    • Description: Trunk link to Luke
  • Interface: Port-channel 2
    • IP: None
    • Type: Switched
    • Description: Trunk link to R2D2
  • Interface: Loopback 0
    • IP: 192.168.45.41 /30
    • Type: Routed
    • Description: Management interface


Routing

  • Protocrol: EIGRP
    • AS: 1337
    • Networks
      • 172.42.20.0 0.0.0.255
      • 192.168.200.0 0.0.0.255
      • 192.168.254.0 0.0.0.3
      • 192.168.254.8 0.0.0.3




R2D2

Interface

  • Interface: Fast Ethernet 0/1
    • IP: None
    • Type: Etherchannel
    • Description: Part of Port-channel ?
  • Interface: Fast Ethernet 0/2
    • IP: None
    • Type: Etherchannel
    • Description: Part of Port-channel ?
  • Interface: Gigabit Ethernet 0/1
    • IP: None
    • Type: Etherchannel
    • Description: Part of Port-channel ?
  • Interface: Gigabit Ethernet 0/2
    • IP: None
    • Type: Etherchannel
    • Description: Part of Port-channel ?
  • Interface: Port-channel 1
    • IP: None
    • Type: Switched
    • Description: Trunk link to ?
  • Interface: Port-channel 2
    • IP: None
    • Type: Etherchannel
    • Description: Trunk link to ?
  • Interface: Vlan 85
    • IP: 192.168.45.45 /30
    • Type: Routed
    • Description: Management interface




C3PO

Interface

  • Interface: Fast Ethernet 0/1
    • IP: None
    • Type: Etherchannel
    • Description: Part of Port-channel ?
  • Interface: Fast Ethernet 0/2
    • IP: None
    • Type: Etherchannel
    • Description: Part of Port-channel ?
  • Interface: Gigabit Ethernet 0/1
    • IP: None
    • Type: Etherchannel
    • Description: Part of Port-channel ?
  • Interface: Gigabit Ethernet 0/2
    • IP: None
    • Type: Etherchannel
    • Description: Part of Port-channel ?
  • Interface: Port-channel 1
    • IP: None
    • Type: Switched
    • Description: Trunk link to ?
  • Interface: Port-channel 2
    • IP: None
    • Type: Etherchannel
    • Description: Trunk link to ?
  • Interface: Vlan 85
    • IP: 192.168.45.49 /30
    • Type: Routed
    • Description: Management interface




VLAN Topology

In order to allow our network to be scalable, we have allocated VLAN ranges to specific areas. Please note that even though we only use a range of 1000 VLANs.

Predefined VLAN assocations

While only a few of these VLANs are actually in use, the VLAN ranges will allow our network to scale almost indefinitely.

  • 1: Not in use; clear from all trunks. This is a Cisco best practice implementation (not required).
  • 2-99: Management VLAN on all switches.
  • 100–399: Access layer devices.
  • 400–599: Data center devices.
  • 600–699: Internet and partner connections.
  • 700–899: Reserved for future use.
  • 900–999: Point-to-point links between switches (Layer 3).

VLANs currently in use

  • VLAN 45: Management VLAN used on all switches in the network.
  • VLAN 100: Skywalker Enterprises.
  • VLAN 101: IP Phone.
  • VLAN 102: Wireless clients.
  • VLAN 400: Wireless.
  • VLAN 401: Wide-Area Network.
  • VLAN 402: ISDN/PSTN.

Configuration of VLAN Layer-2 Security

vlan access-map NAME 10
match ip address <telnet access list>
action drop
vlan access-map 20
match ip address <ssh access list>
action forward

switchport mode access (default)
N/A (default)
no cdp enable
udld port disable

interface vlan <management vlan>

switchport trunk allowed vlan remove 1

Configuration of Interface Security

switchport mode access (default)
N/A (default)
no cdp enable
udld port disable
spanning-tree portfast
spanning-tree portfast bpduguard default

spanning-tree guard root

vtp mode transparent

no mls qos trust {default}

shutdown

Network Topology

Campus Model

Star Wars - Campus Model.jpg
A compus model of the Galaxy network