bobbyforhire
Technical User
So most of you in here know my ccent is coming up this Wednesday.. Today was my hands on day....I took what seems to be all day to draw up my network and implement it but i think i'm getting closer to being ready for the test.
here is my new network setup. I tossed in more than what was needed but i wanted to use all of my hardware and also use RIPv2.
PIX 501
2611 (2 ETH, 2 DSU/CSU)
2610 (1 ETH, 1 DSU/CSU)
1720 (1 FE , 1 DSU/CSU)
2924 (24 FE)
2924 - This was an older version so i had to use VLAN Database. I setup two VLans (well the first one came free). Ports 1-12 for VLan1 and 13-24 for VLan2.
2611 - I'm using this guy as my backbone. It's not the best but it's what I have.
ETH0/0 - 10.3.0.1/255.255.240.0
ETH0/1 - 10.4.0.1/255.255.240.0
SERIAL0 - 10.1.0.1/255.255.240.0
SERIAL1 - 10.2.0.1/255.255.240.0
My Pix is going out to ETH0/0 on the 2611. this is how i get my Internet. i setup ip nat ouside on this interface.
Eth0/1 - This is my personal network. I setup DHCP on the 2611 for this network. Also this is running ip nat inside.
Serial0 - (yes i know i's only 1.5mb but hey how many people going for there ccent get to play with t1 cross overs?) This is for my Production (web servers exc) i also put nat inside on this interface.
Serial1 - I need to make another T1 crossover cable so im not fully done with this one but it will be for my wireless.
On here i created an access-list 1 and included 10.4.0.0 0.0.0.255 and i included 10.2.0.0 for a permit.
After that i setup the overload to allow for PAT on the ETH0/0 interface. Tested from 10.4.0.0 and it worked!!!
2610:
Next was to play with the 2610 in this network. ETH0/0 is connected back to the 2611's 10.2.0.1. Then to make things fun i put the production on 192.168.2.1/24 and enabled DHCP, and connected this back to VLAN2 on the 2924. This is where i used my RIPv2. I enabled rip on all networks waited a few minutes and......YUP. the 2611 router could see the 192.168.2.X network with a nice shiney R next to it.
1720:
This is what's next, Right now i have my wireless in "bridge" mode and just tapped into the 2.x network to make sure that my VLANS were working and also my DHCP. I am going to setup the 1720 to do pretty much what the 2610 is doing.. just rouing and adding more IP address and DHCP server....before i do this i'm going to make sure that I have 3 vlans on the 2924 (one for me, one for wireless, and one for production). Oh and on the wireless i'm going to enable WEP on the linksys AP and then switchport security on the 2924 so only my MAC's can jump on the net and if anyone gets past my WEP...bam!!!! down goes the wireless and ill know about it.
I know that someone out there has read all of this and is like "Yeah, so whats your poin". Well i really wanted to beable to explain myself and to use this post as a ref back incase i decided to blow up my network and bring it back to this.
this is really starting to become fun!!!!
here is my new network setup. I tossed in more than what was needed but i wanted to use all of my hardware and also use RIPv2.
PIX 501
2611 (2 ETH, 2 DSU/CSU)
2610 (1 ETH, 1 DSU/CSU)
1720 (1 FE , 1 DSU/CSU)
2924 (24 FE)
2924 - This was an older version so i had to use VLAN Database. I setup two VLans (well the first one came free). Ports 1-12 for VLan1 and 13-24 for VLan2.
2611 - I'm using this guy as my backbone. It's not the best but it's what I have.
ETH0/0 - 10.3.0.1/255.255.240.0
ETH0/1 - 10.4.0.1/255.255.240.0
SERIAL0 - 10.1.0.1/255.255.240.0
SERIAL1 - 10.2.0.1/255.255.240.0
My Pix is going out to ETH0/0 on the 2611. this is how i get my Internet. i setup ip nat ouside on this interface.
Eth0/1 - This is my personal network. I setup DHCP on the 2611 for this network. Also this is running ip nat inside.
Serial0 - (yes i know i's only 1.5mb but hey how many people going for there ccent get to play with t1 cross overs?) This is for my Production (web servers exc) i also put nat inside on this interface.
Serial1 - I need to make another T1 crossover cable so im not fully done with this one but it will be for my wireless.
On here i created an access-list 1 and included 10.4.0.0 0.0.0.255 and i included 10.2.0.0 for a permit.
After that i setup the overload to allow for PAT on the ETH0/0 interface. Tested from 10.4.0.0 and it worked!!!
2610:
Next was to play with the 2610 in this network. ETH0/0 is connected back to the 2611's 10.2.0.1. Then to make things fun i put the production on 192.168.2.1/24 and enabled DHCP, and connected this back to VLAN2 on the 2924. This is where i used my RIPv2. I enabled rip on all networks waited a few minutes and......YUP. the 2611 router could see the 192.168.2.X network with a nice shiney R next to it.
1720:
This is what's next, Right now i have my wireless in "bridge" mode and just tapped into the 2.x network to make sure that my VLANS were working and also my DHCP. I am going to setup the 1720 to do pretty much what the 2610 is doing.. just rouing and adding more IP address and DHCP server....before i do this i'm going to make sure that I have 3 vlans on the 2924 (one for me, one for wireless, and one for production). Oh and on the wireless i'm going to enable WEP on the linksys AP and then switchport security on the 2924 so only my MAC's can jump on the net and if anyone gets past my WEP...bam!!!! down goes the wireless and ill know about it.
I know that someone out there has read all of this and is like "Yeah, so whats your poin". Well i really wanted to beable to explain myself and to use this post as a ref back incase i decided to blow up my network and bring it back to this.
this is really starting to become fun!!!!