Académique Documents
Professionnel Documents
Culture Documents
OPCION 1
OPCION 2
R3(config)#router rip
R3(config-router)#redistribute eigrp 100 metric 10
R3(config-router)#exit
R3(config)#router eigrp 100
R3(config-router)#redistribute rip metric 10000 1 255 1 1500
R3(config-router)#end
R3
R1(config-router)#metric weights 0 1 1 1 1 1
no ip address
ip authentication mode eigrp 10 md5
ip authentication key-chain eigrp 10 marcos
R0(config)#router ospf 1
R0(config-router)#router-id 1.1.1.1
R0(config-router)#network 192.168.1.0 0.0.0.255 area 0
R0(config-router)#network 10.0.0.0 0.0.0.3 area 0
R1(config)#router ospf 1
R1(config-router)#router-id 2.2.2.2
R1(config-router)#network 10.0.0.0 0.0.0.3 area 0
R1(config-router)#network 11.0.0.0 0.0.0.3 area 1
R1(config-router)#area 1 virtual-link 3.3.3.3
R2(config)#router ospf 1
R2(config-router)#router-id 3.3.3.3
R2(config-router)#network 11.0.0.0 0.0.0.3 area 1
R2(config-router)#network 12.0.0.0 0.0.0.3 area 2
R2(config-router)#area 1 virtual-link 2.2.2.2
R3(config)#router ospf 1
R3(config-router)#router-id 4.4.4.4
R3(config-router)#network 12.0.0.0 0.0.0.3 area 2
R3(config-router)#network 192.168.2.0 0.0.0.255 area 2
Router#terminal history size 256 (con este comando se pueden rescatar los ltimos
comandos hasta 256 lineas usadas)
Switch#vlan database
Switch(vlan)#vlan 99 name config
Switch(vlan)#exit
Switch#conf t
Switch(config)#interface vlan 99
Switch(config-if)#ip address 192.168.1.3 255.255.255.0
Switch(config-if)#no shutdown
Switch(config-if)#exit
Switch(config)#interface fastEthernet 0/1
Switch(config-if)#switchport mode access
Switch(config-if)#switchport access vlan 99
Switch(config-if)#no shutdown
Switch(config-if)#exit
Switch(config)#exit
Switch#show mac-address-table
X
Switch(config)#
line console 0
logging synchronous
exec-timeout 0 0 (sirve para q nunca salir de la sesin)
Switchins
PARA ADMINISTRAR EL SWITCH SE DEBE HACER POR LA VLAN
Switch1#conf t
Switch1(config)#interface vlan 1
Switch1(config-if)#ip address 192.168.7.11 255.255.255.128
Switch1(config-if)#no shutdown
Switch1(config-if)#exit
Switch1(config-vlan)#name VENTAS
Switch1(config-vlan)#vlan 3
Switch1(config-vlan)#name RH
Switch1(config-vlan)#vlan 4
Switch1(config-vlan)#name IT
Switch1(config-vlan)#END
ASIGNACION DE PUERTOS
Switch1#conf t
Switch1(config)#interface fastEthernet 0/8
Switch1(config-if)#switchport access vlan 4
Por ejemplo el siguente commando permite solamente a las VLAN 10-50
propagarce por un enlace troncal
Switch(config-if)#switchport trunk allowed vlan 10-50
CUANDO SE CONECTA A OTRO SWITCH SE DEBE CONFIGURAR ESA PUERTA
EN MODO trunk
y asi se logragra ver con las distintas vlan, solo es nesesario colocarlo en
una puerta
de cada switch
Switch1#conf t
Switch1(config)#interface fastEthernet 0/3
Switch1(config-if)#switchport mode trunk
Switch1(config-if)#
SI NO QUEREMOS DEJAR PASAR UNA VLAN X SE HACE DE ESTA MANERA (MENOS LA
QUE IDENTIFICAMOS QUE NO PASE)
Switch2#conf t
Switch2(config)#interface fastEthernet 0/1
Switch2(config-if)#switchport trunk allowed vlan remove 3(X)
Switch2(config-if)#end
Switch2#show interfaces trunk
SI QUEREMOS DEJAR PASAR SOLO UNA VLAN SE HACE DE ESTA MANERA
Switch2(config)#interface fastEthernet 0/1
Switch2(config-if)#switchport trunk allowed vlan 3
Switch2(config-if)#end
SI QUEREMOS DEJAR Q PASEN TODAS LAS VLAN ENTRE SWITCH
Switch2(config)#interface fastEthernet 0/1
Switch2(config-if)#switchport trunk allowed vlan all
Switch2(config-if)#end
PARA CAMBIAR LA VLAN NATIVA SE HACE DE ESTA MANERA
Switch2(config)#interface fastEthernet 0/1
Switch2(config-if)#switchport trunk native vlan 3
Switch2(config-if)#end
Para negociar con un router es nesesario dejar la puerta del switch en modo trunk
PARA CREAR UNA INTERFACE SE DEBE ELIMINAR LA IP CREADA EN LA
PUERTA Y
DESPUES COLOCAR ESTA LINEA DE COMANDOS Y DECIR Q ES LA VLAN
NATIVE
R1(config)#interface gigabitEthernet 0/1.1
R1(config-subif)#encapsulation dot1Q 1 native
R1(config-subif)#ip address 192.168.7.1 255.255.255.128
R1(config-subif)#
VTP
Switch1#show vtp status
Switch1#conf t
Switch1(config)#vtp
Switch1(config)#vtp
Switch1(config)#vtp
Switch1(config)#vtp
domain marcos
mode server
password cisco
version 2
on
on
auto
auto
802.1q
802.1q
n-802.1q
n-802.1q
trunking
trunking
trunking
trunking
1
1
1
1
Port
Fa0/1
Fa0/3
Fa0/23
Fa0/24
Port
Fa0/1
Fa0/3
Fa0/23
Fa0/24
Port
Fa0/1
Fa0/3
Fa0/23
Fa0/24
Switch1(config)#vlan 100
Switch1(config-vlan)#name VOICE
Switch1(config-vlan)#EXIT
Switch1(config)#mls qos
Switch1(config)#interface fastEthernet 0/10
Switch1(config-if)#mls qos trust cos
Switch1(config-if)#switchport voice vlan 100
Switch1(config-if)#end
Switch1#
Switching Etherchannel
PAGP
DESIREBLE - DESIREBLA SI SE PUEDE
DESIRABLE CON AUTO SI SE PUEDE
ETHERCHANEL
ON CON ON SI SE PUEDE
ACTIVE CON ACTIVE SI SE PUEDE
ACTIVE CON PASIVE SI SE PUEDE
NO SE PUEDE SI ESTAN AMBAS EN PASIVE
NO SE PUEDE SI ESTAN AMBAS EN AUTO
Switch1(config)#interface range fastEthernet 0/5 - 7
Switch1(config-if-range)#channel-group 1 mode on
Switch1(config-if-range)#
Switch1(config)#interface port-channel 1
Switch1(config-if)#no shutdown
Switch1(config-if)#switchport mode trunk
Switch1#show interfaces trunk
Port
Mode
Encapsulation Status
Native vlan
Fa0/1
on
802.1q
trunking
1
Fa0/3
on
802.1q
trunking
1
Fa0/23
auto
n-802.1q
trunking
1
Fa0/24
auto
n-802.1q
trunking
1
Po1
on
802.1q
trunking
1
EN DEFINITIVA SIRVE PARA TENER RESPALDO Y UNA MAYOR BANDA ANCHA permite
sumar la velocidad nominal de cada puerto fsico Ethernet usado y as obtener un
enlace troncal de alta velocidad.
PORT SECURITY
Evita q se conecten usuarios no autorizados y tener el control de q esta conectado a
la red
Switch(config)#interface fastEthernet 0/1
Switch(config-if)#switchport mode access SIEMPRE DEBE ESATR EN ESTE MODO
Switch(config-if)#switchport port-security
Switch(config-if)#do sh port-security
Secure Port MaxSecureAddr CurrentAddr SecurityViolation Security Action
(Count)
(Count)
(Count)
-------------------------------------------------------------------Fa0/1
1
1
0
Shutdown
----------------------------------------------------------------------
Switch(config-if)#do sh arp
Protocol Address
Age (min) Hardware Addr Type Interface
Internet 192.168.7.1
5 000C.85BE.4401 ARPA Vlan1
Internet 192.168.7.13
- 0090.2118.13C5 ARPA Vlan1
ESTE COMANDO HARA Q NO SE TARDE AL CONECTAR LA INTERFAZ DE 50 SEGUNDOS
Switch(config-if)#spanning-tree portfast
portfast slo debe estar habilitado en los puertos conectados a un nico anfitrin.
Conexin de hubs, concentradores, conmutadores, puentes, etc ... a este interfaz
cuando se habilita portfast, puede provocar loops de puenteo temporales. Utilizar con
precaucin
% Portfast se ha configurado en FastEthernet0 / 1, pero slo se sin efecto cuando la
interfaz est en un modo de no-trunking.
CON ESTE COMANDO EL SWITCH MANDA MENSAJE
Switch(config)#interface fastEthernet 0/1
Switch(config-if)#switchport port-security violation restrict
CON ESTE COMANDO EL SWITCH NO MANDA MENSAJE
Switch(config-if)#switchport port-security violation protect
CON ESTE COMANDO SE PUEDEN ACPETAR EN EL PUERTO HASTA 4 DSTINTAS MAC
ADDRESS
Switch(config-if)#switchport port-security maximum 4
Switch#show port-security
Secure Port MaxSecureAddr CurrentAddr SecurityViolation Security Action
(Count)
(Count)
(Count)
-------------------------------------------------------------------Fa0/1
4
4
0
Restrict
---------------------------------------------------------------------witch#show port-security
Secure Port MaxSecureAddr CurrentAddr SecurityViolation Security Action
(Count)
(Count)
(Count)
-------------------------------------------------------------------Fa0/1
4
4
7
Restrict
---------------------------------------------------------------------Switch(config-if)#do sh arp
Protocol Address
Age (min) Hardware Addr Type Interface
Internet 192.168.7.1
0 001B.2BA1.4953 ARPA Vlan1
Internet 192.168.7.13
- 0090.2118.13C5 ARPA Vlan1
Switch(config-if)#
Switch(config-if)#do sh mac-add
Mac Address Table
------------------------------------------Vlan Mac Address
Type
---- ------------------ ----1
001b.2ba1.4953
STATIC
Ports
Fa0/1
Switch#show port-security
:
:
:
:
:
:
:
Enabled
Secure-up
Restrict
0 mins
Absolute
Disabled
1
:
:
:
:
1
0
001B.2BA1.4953:1
0
SPANNING TREE
CON ESTE COMANDO VERIFICAMOS COMO LA CPU ESTA TRABAJANDO
Switch1#show processes
el STP BLOQUEA PUERTOS PARA EVITAR LOOPS EN LA LAN, CREA UN SOLO CAMINO
ENTRE 2 PUNTOS
CO ESTE COMANDO VEMOS LA MAC Y QUIEN ES EL ROOT
Switch1#show spanning-tree vlan 1
VLAN0001
Spanning tree enabled protocol ieee
Root ID Priority 32769 INDICA PRIORIDAD
Address
0001.4381.120E INDICA LA MAC DEL ROOT
(CUANDO ES EL ROOT SALE ESTE MENSAJE,"This bridge is the
root")
Cost
19 INDICA COSTO
Port
2(FastEthernet0/2) INDICA POR Q PUERTO SE LLEGA
Hello Time
2 sec Max Age 20 sec Forward Delay 15 sec INDICA LOS
HELLO EN TIEMPO
Bridge ID Priority
Address
Hello Time
Aging Time
Interface
---------------Fa0/2
Fa0/8
Fa0/4
Fa0/3
PORFAST
ES RECOMENDABLE CONFIGURARLO A UN PUERTO DONDE SOLO HAYA UN SOLO
HOST
Switch1(config)#interface fastEthernet 0/8
Switch1(config-if)#spanning-tree portfast
BPDU GUARD
Switch1(config)#spanning-tree uplinkfast
debera ser habilitado en aquellos switches en donde existe algn puerto en estado
de bloqueo. En ese caso, si se detecta una cada en el puerto que est como FWD se
habilita rpidamente el puerto bloqueado, sin el delay habitual. Permite una reaccin
ms rpida ante un inconveniente en la red.
Switch1(config)#spanning-tree backbonefast
en este caso, se detecta el fallo en algn otro switch de la red y su objetivo es
acelerar la convergencia ante dicho fallo.
Switch1(config-if)#spanning-tree bpduguard enable
Para evitar esto tenemos BPDU Guard, una funcin de los puertos portfast que
controla la llegada de BPDUs, por donde no se las espera, bloqueando el puerto como
mecanismo de seguridad para evitar males mayores, como un cambio inesperado de
la topologa de STP.
RAPID STP
WIRELEESS
Como se ve hace la conectividad en ambos host sin importar el tercer octeto de direccion
Despues
CONFIGURACION wifi
Switch(config)#interface vlan 1
Switch(config-if)#ip address 192.168.7.1 255.255.255.0
Switch(config-if)#no shutdown
Switch(config)#ip dhcp excluded-address 192.168.7.1
Switch(config)#ip dhcp pool WIFI
Router(dhcp-config)#default-router 192.168.7.1
Switch#vlan database
Switch(vlan)#vlan 10 name profesores
VLAN 10 added:
Name: profesores
Switch(vlan)#vlan 20 name estudiantes
VLAN 20 added:
Name: estudiantes
Switch(vlan)#exit
Switch#
Switch#conf t
Switch(config)#interface fastEthernet 0/1
Switch(config-if)#switchport mode access
Switch(config-if)#switchport access vlan 10
Switch(config-if)#interface fastEthernet 0/2
Switc
h(config)#vlan 10
Switch(config-vlan)#exit
Switch(config)#vlan 20
Switch(config-vlan)#exit
Switch(config)#interface fastEthernet 0/2
Switch(config-if)#switchport mode access
Switch(config-if)#switchport access vlan 10
Switch(config-if)#interface fastEthernet 0/3
Switch(config-if)#switchport mode access
Switch(config-if)#switchport access vlan 20
Switch(config-if)#interface fastEthernet 0/1
Switch(config-if)#switchport mode trunk
Router(config)#interface fastEthernet 0/0
Router(config-if)#no shutdown
Router(config-if)#exit
Router(config)#interface fastEthernet 0/0.10
Router(config-subif)#encapsulation dot1Q 10
Router(config-subif)#ip address 192.168.1.1 255.255.255.192
Router(config-subif)#interface fastEthernet 0/0.20
Router(config-subif)#encapsulation dot1Q 20
Switch#vlan database
Switch(vlan)#vlan 10
VLAN 10 added:
Name: VLAN0010
Switch(vlan)#vlan 20
VLAN 20 added:
Name: VLAN0020
Switch(vlan)#exit
Switch#conf t
Switch(config)#interface fastEthernet 0/2
Switch(config-if)#switchport mode access
Switch(config-if)#switchport access vlan 10
Switch(config-if)#interface fastEthernet 0/3
Switch(config-if)#switchport mode access
Switch(config-if)#switchport access vlan 20
Switch(config-if)#interface fastEthernet 0/1
Switch(config-if)#switchport mode trunk
Switch_capa_3#vlan database
Switch_capa_3(vlan)#vlan 10
VLAN 10 added:
Name: VLAN0010
Switch_capa_3(vlan)#vlan 20
VLAN 20 added:
Name: VLAN0020
Switch_capa_3(vlan)#exit
Switch_capa_3(config)#ip routing
Switch_capa_3(config)#interface vlan 10
Switch_capa_3(config-if)#ip address 192.168.1.1 255.255.255.0
Switch_capa_3(config-if)#no shutdown
Switch_capa_3(config-if)#interface vlan 20
Switch _capa_3(config-if)#ip address 192.168.2.1 255.255.255.0
Switch_capa_3(config-if)#no shutdown
Switch_capa_3#show ip route
Router(config-if)#exit
Router(config)#interface serial 0/2/0
Router(config-if)#clock rate 56000
Router(config-if)#ip address 11.0.0.1 255.255.255.252
Router(config-if)#no shutdown
Router(config-if)#exit
Router(config)#ip route 192.168.2.0 255.255.255.0 11.0.0.2
Router(config)#ip route 192.168.1.0 255.255.255.0 10.0.0.1
Router(config)#interface serial 0/2/0
Router(config-if)#ip address 11.0.0.2 255.255.255.252
Router(config-if)#no shutdown
Router(config-if)#exit
Router(config)#interface fastEthernet 0/0
Router(config-if)#ip address 192.168.2.1 255.255.255.0
Router(config-if)#no shutdown
Router(config-if)#exit
Router(config)#ip route 192.168.1.0 255.255.255.0 11.0.0.1
HLDC
ES UN PROTOCOLO PUNTO A PUNTO, Proporciona recuperacin de errores en caso de
prdida de paquetes de datos, fallos de secuencia y otros, por lo que ofrece una
comunicacin confiable entre el transmisor y el receptor.
Router_1(config)#interface serial 1/1
Router_1(config-if)#encapsulation hdlc
Router_1(config-if)#clock rate 56000
Router_1(config-if)#ip address 192.168.12.1 255.255.255.252
Router_1(config-if)#no shutdown
Router_1(config)#interface fastEthernet 0/0
Router_1(config-if)#ip address 10.0.0.1 255.255.255.0
Router_1(config-if)#no shutdown
Router_2(config)#interface serial 1/1
Router_2(config-if)#encapsulation hdlc
Router_2(config-if)#ip address 192.168.12.2 255.255.255.252
Router_2(config-if)#no shutdown
Router_2(config)#interface fastEthernet 0/0
Router_2(config-if)#ip address 10.0.0.2 255.255.255.0
Router_2(config-if)#no shutdown
PARA VER SI TENGO CLOCK RATE
R2#show running-config interface serial 1/1
PPP
Protocolo Punto-a-Punto (PPP), Point-to-Point Protocol, es un protocolo de nivel de
enlace de datos, estandarizado en el documento Request For Comments 1661 (RFC
1661). Comnmente usado para establecer una conexin directa entre dos nodos de
una red de computadoras.
Puede proveer:
autentificacin de conexin, cifrado de transmisin (usando Encryption Control
Protocol (ECP), RFC 1968), y compresin. PPP es usado en varios tipos de redes
fsicas, incluyendo: cable serial, lnea telefnica, lnea
troncal, telefona celular, especializado en enlace de radio y enlace de fibra ptica
como SONET (Synchronous Optical Network). Tambin es utilizado en las conexiones
de acceso a Internet (mercadeado como banda ancha o broadband). Los
proveedores de servicios de Internet (ISP) han usado PPP para que accedan a
Internet los usuarios de dial-up (lnea conmutada), ya que los paquetes de IP no
pueden ser transmitidos va mdem, sin tener un protocolo de enlace de datos.
Dos derivados del PPP son:
Point to Point Protocol over Ethernet (PPPoE),
Point to Point Protocol over ATM (PPPoA).
Son usados comnmente por los ISP para establecer una lnea de abonado digital
(Digital Subscriber Line, DSL) de servicios de Internet para clientes.
Router_2(config)#interface serial 1/1
Router_2(config-if)#encapsulation ppp
R1(config-if)#encapsulation frame-relay
R1(config-if)#ip address 10.0.0.1 255.255.255.252
R1(config-if)#frame-relay map ip 10.0.0.2 102 broadcast
R1(config-if)#no shutdown
R1(config)#ip route 192.168.2.0 255.255.255.0 10.0.0.2
R2(config)#interface serial 0/0/0
R2(config-if)#encapsulation frame-relay
R2(config-if)#ip address 10.0.0.2 255.255.255.252
R2(config-if)#frame-relay map ip 10.0.0.1 201 broadcast
R2(config-if)#no shutdown
R2(config)#ip route 192.168.1.0 255.255.255.0 10.0.0.1
valparaiso#ping 192.168.10.2
valparaiso#ping 192.168.30.5
FRAME RELAY
R1(config)#interface serial 0/0
R1(config-if)#ip address 10.0.0.1 255.255.255.252
R1(config-if)#no shutdown
R1(config-if)#encapsulation frame-relay
R1(config-if)#frame-relay lmi-type cisco
R1(config-if)#frame-relay interface-dlci 102
R2(config)#interface serial 0/0
R2(config-if)#ip address 10.0.0.2 255.255.255.252
R2(config-if)#no shutdown
R2(config-if)#encapsulation frame-relay
R2(config-if)#frame-relay lmi-type cisco
R2(config-if)#frame-relay interface-dlci 201
FRAME_RELAY(config)#frame-relay switching
FRAME_RELAY(config)#interface serial 0/0
FRAME_RELAY(config-if)#encapsulation frame-relay
FRAME_RELAY(config-if)#no shutdown
FRAME_RELAY(config-if)#frame-relay lmi-type cisco
FRAME_RELAY(config-if)#frame-relay intf-type dce
FRAME_RELAY(config-if)#clock rate 64000
FRAME_RELAY(config-if)#frame-relay route 102 interface serial 0/1 201
FRAME_RELAY(config-if)#int ser0/1
FRAME_RELAY(config-if)#encapsulation frame-relay
FRAME_RELAY(config-if)#frame-relay lmi-type cisco
FRAME_RELAY(config-if)#frame-relay intf-type dce
FRAME_RELAY(config-if)#clock rate 64000
FRAME_RELAY(config-if)#frame-relay route 201 interface serial 0/0 102
FRAME_RELAY(config-if)#no shutdown
FRAME_RELAY(config-if)#
Inactive
0
0
0
0
0
Deleted
0
0
0
Static
0
0
0
DLCI = 102, DLCI USAGE = LOCAL, PVC STATUS = ACTIVE, INTERFACE = Serial0/0
R1#show frame map
Serial0/0 (up): ip 10.0.0.2 dlci 102(0x66,0x1860), dynamic,
broadcast,
CISCO, status defined, active
R1#show frame lmi
LMI Statistics for interface Serial0/0 (Frame Relay DTE) LMI TYPE = CISCO
Invalid Unnumbered info 0
Invalid Prot Disc 0
Invalid dummy Call Ref 0
Invalid Msg Type 0
Invalid Status Message 0
Invalid Lock Shift 0
Invalid Information ID 0
Invalid Report IE Len 0
Invalid Report Request 0
Invalid Keep IE Len 0
Num Status Enq. Sent 165
Num Status msgs Rcvd 104
Num Update Status Rcvd 0
Num Status Timeouts 61
Last Full Status Req 00:00:45
Last Full Status Rcvd 00:00:45
RUTA ESTATICA
RIP
R6(config)#interface serial 0/0/0
R6(config-if)#ip address 160.15.50.1 255.255.255.0
R6(config-if)#no shutdown
R6(config-if)#EXIT
R6(config)#interface loopback 0
R6(config-if)#ip address 160.15.36.10 255.255.255.0
R4(config)#interface serial 0/0/0
R4(config-if)#ip address 160.15.50.2 255.255.255.0
R4(config-if)#no shutdown
R4(config-if)#exit
R4(config)#interface serial 0/0/1
R4(config-if)#ip address 160.15.51.1 255.255.255.0
R4(config-if)#no shutdown
R4(config-if)#exit
R4(config)#interface serial 0/1/0
R4(config-if)#ip address 160.15.54.1 255.255.255.0
R4(config-if)#no shutdown
OTRO EJEMPLO
Switch(config)#vlan 10
Switch(config-vlan)#name juan
Switch(config-vlan)#vlan 20
Switch(config-vlan)#name david
Switch(config-vlan)#exit
Switch(config)#interface fastEthernet 0/1
Switch(config-if)#switchport mode trunk
Switch(config-if)#exit
Switch(config)#interface fastEthernet 0/2
Switch(config-if)#switchport access vlan 10
Switch(config-if)#exit
Switch(config)#interface fastEthernet 0/3
Switch(config-if)#switchport access vlan 20
Router(config-subif)#exit
Router(config)#interface fastEthernet 0/0.20
Router(config-subif)#encapsulation dot1Q 20
Router(config-subif)#ip address 20.20.20.1 255.255.255.0
Router(config-subif)#no shutdown
Router(config-subif)#exit
Router(config)#
Router(config)#ip dhcp pool lan-10
Router(dhcp-config)#default-router 10.10.10.1
Router(dhcp-config)#network 10.10.10.0 255.255.255.0
Router(dhcp-config)#exit
Router(config)#ip dhcp pool lan-20
Router(dhcp-config)#default-router 20.20.20.1
Router(dhcp-config)#network 20.20.20.0 255.255.255.0
Router(dhcp-config)#exit
Router(config)#interface fastEthernet 0/0
Router(config-if)#no shutdown
Router#show
IP address
address
10.10.10.2
20.20.20.2
ip dhcp binding
Client-ID/
0001.C718.411A
0060.5C06.0635
Lease expiration
---
Type
Automatic
Automatic
Hardware
VRF
OTRO EJEMPLO
R1(config)#interface fastEthernet 0/0
R1(config-if)#ip address dhcp
R1(config-if)#exit
R1(config)#interface fastEthernet 0/1
R1(config-if)#ip address 172.16.1.1 255.255.255.0
R1(config-if)#no shutdown
R1(config-if)#exit
R1(config)#ip dhcp pool LAN1
R1(dhcp-config)#network 172.16.1.0 255.255.255.0
R1(dhcp-config)#default-router 172.16.1.1
R1(dhcp-config)#ip dhcp excluded-address 172.16.1.1 172.16.1.11
R1(config)#exit
R1(config)#access-list 1 permit 172.16.1.0 0.0.0.255
R1(config)#ip nat inside source list 1 interface fastEthernet 0/0 overload
R1(config)#interface fastEthernet 0/0
R1(config-if)#ip nat outside
R1(config-if)#no shutdown
R1(config-if)#exit
R1(config)#interface fastEthernet 0/1
R1(config-if)#ip nat inside
R1(config-if)#no shutdown
R1(config-if)#
EIGRP
ip
ip
ip
ip
ip
ip
route
route eigrp
eigrp interfaces
eigrp neighbors
eigrp topology
protocols
OSPF POINT-TO-POINT
OSPF
BOSTON(config)#router ospf 1
BOSTON(config-router)#router-id 1.1.1.1
BOSTON(config-router)#network 192.168.10.0
BOSTON(config-router)#network 192.168.20.0
BOSTON(config-router)#network 192.168.81.0
BOSTON(config-router)#network 192.168.82.0
0.0.0.255
0.0.0.255
0.0.0.255
0.0.0.255
SANTO_DOMINGO(config)#router ospf 1
SANTO_DOMINGO(config-router)#router-id 3.3.3.3
SANTO_DOMINGO(config-router)#network 192.168.60.0
SANTO_DOMINGO(config-router)#network 192.168.50.0
SANTO_DOMINGO(config-router)#network 192.168.83.0
SANTO_DOMINGO(config-router)#network 192.168.81.0
MIAMI(config)#router ospf 1
MIAMI(config-router)#router-id 2.2.2.2
MIAMI(config-router)#network 192.168.30.0
MIAMI(config-router)#network 192.168.40.0
MIAMI(config-router)#network 192.168.82.0
MIAMI(config-router)#network 192.168.83.0
OTRO EJEMPLO
0.0.0.255
0.0.0.255
0.0.0.255
0.0.0.255
area
area
area
area
0
0
0
0
0.0.0.255
0.0.0.255
0.0.0.255
0.0.0.255
area
area
area
area
0
0
0
0
area
area
area
area
0
0
0
0
Router0(config)#router ospf 1
Router0(config-router)#router-id 1.1.1.1
Router0(config-router)#network 192.168.10.0 0.0.0.255 area 0
Router0(config-router)#network 10.10.10.0 0.0.0.3 area 0
Router1(config)#router ospf 1
Router1(config-router)#router-id 2.2.2.2
Router1(config-router)#network 10.10.10.0 0.0.0.3 area 0
Router1(config-router)#network 20.20.20.0 0.0.0.3 area 1
Router1(config-router)#area 1 virtual-link 3.3.3.3 (router de borde)
Router2(config)#router ospf 1
Router2(config-router)#router-id 3.3.3.3
Router2(config-router)#network 20.20.20.0 0.0.0.3 area 1
Router2(config-router)#network 30.30.30.0 0.0.0.3 area 2
Router2(config-router)#area 1 virtual-link 2.2.2.2 (router de borde)
Router3(config)#router ospf 1
Router3(config-router)#router-id 4.4.4.4
Router3(config-router)#network 30.30.30.0 0.0.0.3 area 2
Router3(config-router)#network 192.168.20.0 0.0.0.255 area 2
REDISTRIBUTE
R1/RIP(config)#router rip
R1/RIP(config-router)#version 2
R1/RIP(config-router)#network 10.0.0.4
R1/RIP(config-router)#network 192.168.2.0
R3/OSPF(config)#router ospf 1
R3/OSPF(config-router)#network 10.0.0.0 0.0.0.3 area 0
R3/OSPF(config-router)#network 192.168.1.0 0.0.0.255 area 0
R3/OSPF(config-router)#
R2/EIGRP(config)#router eigrp 1
R2/EIGRP(config-router)#network 10.0.0.8 0.0.0.3
R2/EIGRP(config-router)#network 192.168.3.0 0.0.0.255
BACKBONE(config)#router rip
BACKBONE(config-router)#version 2
BACKBONE(config-router)#network 10.0.0.4
BACKBONE(config-router)#exit
BACKBONE(config)#router ospf 1
BACKBONE(config-router)#network 10.0.0.0 0.0.0.3 area 0
BACKBONE(config-router)#exit
BACKBONE(config)#router eigrp 1
BACKBONE(config-router)#network 10.0.0.8 0.0.0.3
BACKBONE(config)#router rip
BACKBONE(config-router)#redistribute ospf 1 metric 1
BACKBONE(config-router)#redistribute eigrp 1 metric 1
BACKBONE(config-router)#exit
BACKBONE(config)#router ospf 1
BACKBONE(config-router)#redistribute
BACKBONE(config-router)#redistribute
BACKBONE(config-router)#exit
BACKBONE(config)#router eigrp 1
BACKBONE(config-router)#redistribute
BACKBONE(config-router)#redistribute
rip subnets
eigrp 1 subnets
SEGURIDAD
Router0(config)#interface fastEthernet 0/0
Router0(config-if)#ip address 192.168.1.1 255.255.255.0
Router0(config-if)#no shutdown
Router0(config-if)#exit
Router0(config)#interface fastEthernet 0/1
Router0(config-if)#ip address 192.168.3.1 255.255.255.0
Router0(config-if)#no shutdown
Router0(config)#router rip
Router0(config-router)#version 2
Router0(config-router)#network 192.168.1.0
Router0(config-router)#network 192.168.2.0
Router0(config-router)#network 192.168.3.0
Router0(config-router)#no auto-summary
DEPTO(config)#access-list 1 ?
deny Specify packets to reject
permit Specify packets to forward
remark Access list entry comment
DEPTO(config)#access-list 1 de
DEPTO(config)#access-list 1 deny ?
A.B.C.D Address to match
any
Any source host
host
A single host address
DEPTO(config)#access-list 1 deny 192.168.10.0 ?
A.B.C.D Wildcard bits
<cr>
DEPTO(config)#access-list 1 deny 192.168.10.0 0.0.0.255 ?
<cr>
DEPTO(config)#access-list 1 deny 192.168.10.0 0.0.0.255
DEPTO(config)#access-list 1 permit any
DEPTO(config)#interface fastEthernet 1/0
DEPTO(config-if)#ip access-group 1 ?
in inbound packets
out outbound packets
DEPTO(config-if)#ip access-group 1 out
DEPTO(config-if)#end
DEPTO#show access-lists
Standard IP access list 1
10 deny 192.168.10.0 0.0.0.255 (4 match(es))
20 permit any
DEPTO#show access-lists
Standard IP access list 1
10 deny 192.168.10.0 0.0.0.255 (4 match(es))
20 permit any (4 match(es))
ACL Estandar.
ACL Extendida
ASIR1(config)#access-list 100 ?
deny Specify packets to reject
permit Specify packets to forward
remark Access list entry comment
ASIR1(config)#access-list 100 deny ip 192.168.10.0 0.0.0.255 192.168.30.0
0.0.0.255
se deniega desde el origen de la red al destino de la red con la
red y wilcard
ASIR1(config)#interface fastEthernet 0/1
ASIR1(config-if)#ip access-group 100 in
ASIR1#show access-lists
Extended IP access list 100
10 deny ip 192.168.10.0 0.0.0.255 192.168.30.0 0.0.0.255 (4 match(es))
otro ejemplo
extendida
NAT
RED
RED
RED
RED
RED
RED
RED
estatico
NAT STATIC
Nat(config-if)#no shutdown
Nat(config)#interface fastEthernet 1/0
Nat(config-if)#ip address 192.168.23.2 255.255.255.0
Nat(config-if)#no shutdown
Server(config)#interface fastEthernet 0/0
Server(config-if)#ip address 192.168.23.3 255.255.255.0
Server(config-if)#no shutdown
Server(config)#ip route 192.168.12.0 255.255.255.0 192.168.23.2
COMANDO PARA VERIFICAR IP DE FUENTE Y DESTINO
Server#debug ip packet
IP packet debugging is on
DEL HOST SE ENVIA UN PING AL SERVER Y ESTO NOS MUESTRA
NAT DYNAMIC
Router#debug ip nat
IP NAT debugging is on
Router#
NAT OVERLOAD
Router0(config)#
Router0(config)#interface fastEthernet 0/0
Router0(config-if)#ip nat inside
Router0(config-if)#exit
Router0(config)#interface serial 2/0
Router0(config-if)#ip nat outside
Router0(config-if)#exit
Router0(config)#
Router0#conf t
Router0(config)#ip access-list standard marcos
Router0(config-std-nacl)#permit 192.168.0.0 0.0.0.255
Router0(config-std-nacl)#exit
Router0(config)#ip nat inside source list marcos interface serial 2/0 overload
Router0(config)#ip route 0.0.0.0 0.0.0.0 1.1.1.2
Router0(config)#
SE REALIZA UN PING AL SERVIDOR DESDE PC 1
Router0(config)#ipv6 unicast-routing
Router0(config)#ipv6 router rip marcos
Router0(config-rtr)#exit
Router0(config)#interface fastEthernet 0/0
Router0(config-if)#ipv6 enable
Router0(config-if)#ipv6 address 2001:db8:1:1::1/64
Router0(config-if)#ipv6 rip marcos enable
Router0(config-if)#no shutdown
Router0(config-if)#interface fastEthernet 0/1
Router0(config-if)#ipv6 enable
Router0(config-if)#ipv6 address 2001:db8:1:2::1/64
Router0(config-if)#ipv6 rip marcos enable
Router0(config-if)#no shutdown
Router0(config-if)#interface fastEthernet 0/0
Router0(config-if)#ipv6 address FE80::1 link-local
Router1(config)#ipv6 unicast-routing
Router1(config)#ipv6 router rip marcos
Router1(config-rtr)#exit
Router1(config)#interface fastEthernet 0/0
Router1(config-if)#ipv6 enable
Router1(config-if)#ipv6 address 2001:db8:1:2::2/64
Router1(config-if)#ipv6 rip marcos enable
Router1(config-if)#no shutdown
Router1(config-if)#interface fastEthernet 0/1
Router1(config-if)#ipv6 enable
Router1(config-if)#ipv6 address 2001:db8:1:3::1/64
Router1(config-if)#ipv6 rip marcos enable
Router1(config-if)#no shutdown
Router2(config)#ipv6 unicast-routing
Router1(config-rtr)#exit
Router1(config)#interface fastEthernet 0/0
Router1(config-if)#ipv6 eigrp 1
Router1(config-if)#no shutdown
Router1(config-if)#interface fastEthernet 0/1
Router1(config-if)#ipv6 eigrp 1
Router1(config-if)#no shutdown
Router0(config-rtr)#router-id 1.1.1.1
Router0(config-rtr)#exit
Router0(config)#interface fastEthernet 0/0
Router0(config-if)#ipv6 ospf 1 area 0
Router0(config-if)#interface fastEthernet 0/1
Router0(config-if)#ipv6 ospf 1 area 0
Switch#vlan database
Switch(vlan)#vlan 10
VLAN 10 added:
Name: VLAN0010
Switch(vlan)#vlan 20
VLAN 20 added:
Name: VLAN0020
Switch(vlan)#exit
Router0(config)#ipv6 unicast-routing
Router0(config)#ipv6 router ospf 1
Router0(config-rtr)#router-id 1.1.1.1
Router0(config-rtr)#exit
Router0(config)#interface fastEthernet 0/0
Router0(config-if)#ipv6 enable
Router0(config-if)#no shutdown
Router0(config-if)#exit
Router0(config)#interface fastEthernet 0/0.10
Router0(config-subif)#ipv6 address 2001:db8:1:1::1/64
Router0(config-subif)#ipv6 address fe80::1 link-local
Router0(config-subif)#encapsulation dot1Q 10
Router0(config-subif)#ipv6 ospf 1 area 0
Router0(config-subif)#interface fastEthernet 0/0.20
Router0(config-subif)#ipv6 address 2001:db8:1:2::1/64
Router0(config-subif)#ipv6 address fe80::1 link-local
Router0(config-subif)#encapsulation dot1Q 20
Router0(config-subif)#ipv6 ospf 1 area 0
Router0(config-subif)#exit
Router0(config)#interface fastEthernet 0/1
Router0(config-if)#ipv6 address 2001:db8:2:1::1/64
Router0(config-if)#ipv6 ospf 1 area 0
Router0(config-if)#no shutdown
Router1(config)#ipv6 unicast-routing
Router1(config)#ipv6 router ospf 1
Router1(config-rtr)#router-id 2.2.2.2
Router1(config-rtr)#exit
Router1(config)#interface fastEthernet 0/0
Router2(config)#ipv6 unicast-routing
Router2(config)#ipv6 router ospf 1
Router2(config-rtr)#router-id 3.3.3.3
Router2(config-rtr)#exit
Router2(config)#ipv6 dhcp pool CISCO
Router2(config-dhcpv6)#domain-name cisco.com
Router2(config-dhcpv6)#dns-server 2001:db8:3:1::1234
Router2(config-dhcpv6)#prefix-delegation pool CISCO lifetime 3600 3600
Router2(config-dhcpv6)#exit
Router2(config)#interface fastEthernet 0/1
Router2(config-if)#ipv6 address 2001:db8:2:2::2/64
Router2(config-if)#ipv6 ospf 1 area 0
Router2(config-if)#no shutdown
Router2(config-if)#interface fastEthernet 0/0
C:\>ipconfig
C:\>telnet 192.168.1.1
R1#show running-config
R1#show ip route
Router0(config)#ipv6 unicast-routing
Router0(config)#interface fastEthernet 0/0
Router0(config-if)#ipv6 enable
Router0(config-if)#ipv6 address autoconfig
Router0(config-if)#ipv6 address 2000::/64 eui-64
Router0(config-if)#no shutdown
Router(config)#ipv6 unicast-routing
Router(config)#interface fastEthernet 0/0
Router(config-if)#ipv6 enable
Router(config-if)#ipv6 address 2001:DB8:ACAD:A::1/64
Router(config-if)#ipv6 address 2001:DB8:C10:1::/64 eui-64
Router(config-if)#ipv6 address FE80::1 link-local
Router(config-if)#exit
Router(config)#interface fastEthernet 0/0
Router(config-if)#no shutdown
IPV6 Direccionamiento
R1(config)#ipv6 unicast-routing
R1(config)#interface fastEthernet 0/0
R1(config-if)#ipv6 enable
R1(config-if)#ipv6 address 2001:DB8:AAAA:1::1/64
R1(config-if)#ipv6 address FE80::1 link-local
R1(config-if)#no shutdown
R1(config-if)#interface fastEthernet 0/1
R1(config-if)#ipv6 enable
R1(config-if)#ipv6 address 2001:DB8:AAAA:2::1/64
R1(config-if)#no shutdown
R1(config-if)#exit
R1(config)#ipv6 route 2001:DB8:AAAA:3::/64 2001:DB8:AAAA:2::2
R2(config)#ipv6 unicast-routing
R2(config)#interface fastEthernet 0/0
R2(config-if)#ipv6 enable
R2(config-if)#ipv6 address 2001:DB8:AAAA:3::1/64
R2(config-if)#ipv6 address FE80::1 LINk-local
R2(config-if)#no shutdown
R2(config-if)#interface fastEthernet 0/1
R2(config-if)#ipv6 enable
R2(config-if)#ipv6 address 2001:DB8:AAAA:2::2/64
R2(config-if)#no shutdown
R2(config-if)#exit
Con el link local address solo se puede hacer ping ala red interna no hacia afuera o fuera del
segmento de red
Router0(config)#ipv6 unicast-routing
Router0(config)#interface fastEthernet 0/0
Router0(config-if)#ipv6 address 2000:DB8:1:1::1/64
Router0(config-if)#ipv6 address FE80::1 link-local
Router0(config-if)#ipv6 enable
Router0(config-if)#no shutdown
Router0(config)#interface fastEthernet 0/1
Router0(config)#interface tunnel 0
Router0(config-if)#ipv6 address 2001:DB8:1:1::1/64
Router0(config-if)#tunnel source fastEthernet 0/1
Router0(config-if)#tunnel destination 11.0.0.2
Router0(config-if)#tunnel mode ipv6ip
Router2(config)#ipv6 unicast-routing
Router2(config)#interface tunnel 0
Router2(config-if)#ipv6 address 2001:DB8:1:1::2/64
Router2(config-if)#tunnel source fastEthernet 0/1
Router2(config-if)#tunnel destination 10.0.0.1
Router2(config-if)#tunnel mode ipv6ip
Router2(config-if)#do ping 2001:DB8:1:1::1
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 0/0/3 ms
IPV6 DHCPv6
Sin Estado
Router0(config)#ipv6 unicast-routing
Router0(config)#ipv6 dhcp pool MARCOS
Router0(config-dhcpv6)#domain-name marcos.com
Router0(config-dhcpv6)#dns-server 2001:db8:1:1::1234
Router0(config-dhcpv6)#exit
Router0(config)#interface fastEthernet 0/0
Router0(config-if)#ipv6 address 2001:db8:1:1::1/64
Router0(config-if)#ipv6 address FE80::1 link-local
Router0(config-if)#ipv6 dhcp server MARCOS
Router0(config-if)#no shutdown
Sin Estado
Router1(config)#ipv6 unicast-routing
Router1(config)#ipv6 dhcp pool CISCO
Router1(config-dhcpv6)#domain-name cisco.com
Router1(config-dhcpv6)#dns-server 2001:db8:1:1::1234
Router1(config-dhcpv6)#prefix-delegation pool CISCO lifetime 3600 3600
Router1(config-dhcpv6)#exit
Router1(config)#interface fastEthernet 0/0
Router1(config-if)#ipv6 enable
Router1(config-if)#ipv6 address 2001:db8:1:1::1/64
Router1(config-if)#ipv6 address FE80::1 link-local
Router1(config-if)#no shutdown
Router1(config-if)#exit
Router1(config)#ipv6 local pool CISCO 2001:db8:1:1::/64 64
Router1(config)#interface fastEthernet 0/0
Router1(config-if)#ipv6 dhcp server CISCO
IPV6
R1(config)#ipv6 unicast-routing
R1(config)#interface serial 1/0
R1(config-if)#ipv6 enable
R1(config-if)#ipv6 address 2008:1313:0000:0000:0000:0000:0000:0001/64
R1(config-if)#no shutdown
R1(config-if)#exit
R1(config)#interface fastEthernet 0/1
R1(config-if)#no shutdown
R1(config-if)#ipv6 enable
ISP#conf t
Enter configuration commands, one per line. End with CNTL/Z.
ISP(config)#ip vr
ISP(config)#ip vrf RED
ISP(config-vrf)#exit
ISP(config)#ip vr
ISP(config)#ip vrf BLUE
ISP(config-vrf)#exit
ISP(config)#
ISP#
ISP#conf t
ISP(config)#interface fastEthernet 0/0
ISP(config-if)#ip vrf forwarding BLUE
% Interface FastEthernet0/0 IPv4 disabled and address(es) removed due to enabling
VRF BLUE
ISP(config-if)#ip address 192.168.1.254 255.255.255.0
ISP(config-if)#
ISP(config-if)#interface fastEthernet 1/0
BGP
R1#conf t
R1(config)#interface fastEthernet 0/0
R1(config-if)#ip address 192.168.1.1 255.255.255.252
R1(config-if)#no shutdown
R1(config-if)#end
R1#conf t
R1(config)#interface fastEthernet 0/1
R1(config-if)#ip address 192.168.2.254 255.255.255.0
R1(config-if)#no shutdown
R2#conf t
R2(config)#interface fastEthernet 0/0
R2(config-if)#ip address 192.168.1.2 255.255.255.252
R2(config-if)#no shutdown
R2(config-if)#end
R2#conf t
R2(config)#interface fastEthernet 0/1
R2(config-if)#ip address 192.168.3.254 255.255.255.0
R2(config-if)#no shutdown
R3#conf t
R3(config)#interface fastEthernet 0/0
R3(config-if)#ip address 192.168.2.1 255.255.255.0
R3(config-if)#no shutdown
R3(config-if)#
R4#conf t
R4(config)#interface fastEthernet 0/0
BGP REFLECTOR
R1(config)#
R1(config)#router bgp 123
R1(config-router)#neighbor 192.168.12.2 remote-as 123
R1(config-router)#exit
R1(config)#router bgp 123
R1(config-router)#network 1.1.1.1 mask 255.255.255.255
R1(config-router)#
R2(config)#
R2(config)#router bgp 123
R2(config-router)#neighbor 192.168.12.1 remote-as 123
R2(config-router)#neighbor 192.168.12.1 route-reflector-client
R2(config-router)#
R2(config-router)#neighbor 192.168.23.3 remote-as 123
EJEMPLO 2
Next Hop
192.168.12.1
R1#conf t
R1(config)#router bgp 65000
R1(config-router)#neighbor 10.0.0.6 remote-as 65000
R1(config-router)#neighbor 10.0.0.2 remote-as 65000
R1(config-router)#neighbor 10.0.0.10 remote-as 15000
R1(config-router)#no auto-summary
R1(config-router)#
R2(config)#
R2(config)#router bgp 65000
R2(config-router)#neighbor 10.0.0.14 remote-as 25000
R2(config-router)#neighbor 10.0.0.1 remote-as 65000
R2(config-router)#no auto-summary
R2(config-router)#
R3(config)#
R3(config)#router bgp 65000
R3(config-router)#neighbor 10.0.0.18 remote-as 35000
R3(config-router)#neighbor 10.0.0.5 remote-as 65000
R3(config-router)#no auto-summary
R3(config-router)#
R1#conf t
R1(config)#router bgp 65000
R1(config-router)#neighbor 10.0.0.2 route-reflector-client
R1(config-router)#neighbor 10.0.0.6 route-reflector-client
EJEMPLO 3
R1(config)#router bgp 1
R1(config-router)#neighbor RED peer-group
R1(config-router)#neighbor 2.2.2.2 remote-as 2
R1(config-router)#neighbor 3.3.3.3 remote-as 3
R1(config-router)#neighbor 4.4.4.4 remote-as 4
R1(config-router)#neighbor 2.2.2.2 peer-group RED
R1(config-router)#neighbor 3.3.3.3 peer-group RED
R1(config-router)#neighbor 4.4.4.4 peer-group RED
interface Loopback0
ip address 1.1.1.1 255.255.255.0
R1#show running-config | section router
router bgp 1
bgp log-neighbor-changes
neighbor RED peer-group
neighbor 2.2.2.2 remote-as 2
neighbor 2.2.2.2 peer-group RED
neighbor 3.3.3.3 remote-as 3
neighbor 3.3.3.3 peer-group RED
neighbor 4.4.4.4 remote-as 4
neighbor 4.4.4.4 peer-group RED
R1#conf t
R1(config)#router bgp 1
R1(config-router)#neighbor RED update-source loopback 0
R1(config-router)#neighbor RED route-map SET_MED out
R1(config-router)#exit
R1(config)#ip route 2.2.2.0 255.255.255.255 192.168.12.2
R1(config)#ip route 3.3.3.0 255.255.255.255 192.168.13.3
R1(config)#ip route 4.4.4.0 255.255.255.255 192.168.14.4
R2(config)#ip route 1.1.1.0 255.255.255.255 192.168.12.1
R2(config)#interface loopback 0
V
4
4
4
AS MsgRcvd MsgSent
1234
1234
1234
8
5
4
8
3
2
1
1
1
0
0
0
TblVer
0 00:04:00
0 00:01:46
0 00:00:41
Frame-Relay Point-to-point
Estos enlaces proveen operacin bidireccional full dplex y se asume que los paquetes sern
entregados en orden.Tiene tres componentes:
2. Un protocolo de control de enlace (LCP, Link Control Protocol) para establecer, configurar y
probar la conexin de datos.
3. Una familia de protocolos de control de red (NCPs, Network Control Protocols) para establecer
y configurar los distintos protocolos de nivel de red.
Tunnel GRE
Router0#ping 192.168.2.2
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 0/0/0 ms
Santiago(config-if)#exit
Santiago(config)#ip access-list extended LISTA_VPN
Santiago(config-ext-nacl)#permit ip 192.168.1.0 0.0.0.255 192.168.2.0 0.0.0.255
Santiago(config-ext-nacl)#exit
Santiago(config)#ip route 192.168.2.0 255.255.255.0 11.0.0.2
Santiago(config-isakmp)#hash sha
Santiago(config-isakmp)#authentication pre-share
Santiago(config-isakmp)#group 5
Santiago(config-isakmp)#crypto isakmp client configuration group GRUPO_VPN
Santiago(config-isakmp-group)#key cisco
Santiago(config-isakmp-group)#pool POOL_VPN
Santiago(config-isakmp-group)#crypto ipsec transform-set SET_VPN esp-aes esp-sha-hmac
Santiago(config)#crypto dynamic-map DINAMICOS_VPN 10
Santiago(config-crypto-map)#set transform-set SET_VPN
Santiago(config-crypto-map)#reverse-route
Santiago(config-crypto-map)#crypto map MAPA_ESTATICO client configuration address
respond
Santiago(config)#crypto map MAPA_ESTATICO client authentication list MARCOS_VPN
Santiago(config)#crypto map MAPA_ESTATICO isakmp authorization list GRUPO_VPN
Santiago(config)#crypto map MAPA_ESTATICO 20 IPSec-isakmp dynamic DINAMICOS_VPN
Santiago(config)#interface fastEthernet 0/1
Santiago(config-if)#crypto map MAPA_ESTATICO
*Jan 3 07:16:26.785: %CRYPTO-6-ISAKMP_ON_OFF: ISAKMP is ON
Santiago(config-if)#
ciscoasa>enable
Password:
ciscoasa(config)#interface vlan 2
ciscoasa(config-if)#ip address 192.168.2.1 255.255.255.0
ciscoasa(config-if)#exit
ciscoasa(config)#webvpn
ciscoasa(config-webvpn)#enable outside
INFO: WebVPN and DTLS are enabled on 'outside'.
ciscoasa(config-webvpn)#exit
ciscoasa(config)#username marcos password cisco
ciscoasa#show running-config
interface Ethernet0/0
switchport access vlan 2
interface Vlan1
nameif inside
security-level 100
ip address 192.168.1.1 255.255.255.0
!
interface Vlan2
nameif outside
security-level 0
ip address dhcp
West(config)#
West(config)#interface gigabitEthernet 0/1
West(config-if)#ip address 172.16.1.1 255.255.255.0
West(config-if)#no shutdown
West(config-if)#exit
West(config)#interface serial 0/0/0
West(config-if)#ip address 10.1.1.1 255.255.255.252
West(config-if)#no shutdown
ISP(config)#
ISP(config)#interface serial 0/0/0
ISP(config-if)#ip address 10.1.1.2 255.255.255.252
ISP(config-if)#no shutdown
ISP(config-if)#exit
ISP(config)#interface serial 0/0/1
ISP(config-if)#ip address 10.2.2.2 255.255.255.252
ISP(config-if)#no shutdown
East(config)#
East(config)#interface serial 0/0/1
East(config-if)#ip address 10.2.2.1 255.255.255.252
East(config-if)#no shutdown
East(config-if)#exit
East(config)#interface gigabitEthernet 0/1
East(config-if)#ip address 172.16.2.1 255.255.255.0
East(config-if)#no shutdown
West(config)#
West(config)#interface tunnel 0
West(config-if)#ip address 172.16.12.1 255.255.255.252
West(config-if)#tunnel source serial 0/0/0
West(config-if)#tunnel destination 10.2.2.1
East(config)#
East(config)#interface tunnel 0
East(config-if)#ip address 172.16.12.2 255.255.255.252
East(config-if)#tunnel source serial 0/0/1
East(config-if)#tunnel destination 10.1.1.1
West#conf t
West(config)#router ospf 1
West(config-router)#network 172.16.1.0 0.0.0.255 ar
West(config-router)#network 172.16.1.0 0.0.0.255 area 0
West(config-router)#network 172.16.12.0 0.0.0.3 area 0
West(config-router)#
East#conf t
East(config)#router ospf 1
East(config-router)#network 172.16.2.0 0.0.0.255 area 0
East(config-router)#network 172.16.12.0 0.0.0.3 area 0
East(config-router)#
R1#conf t
R1#conf t
R1(config)#interface gigabitEthernet 0/0
R1(config-if)#ip address 12.0.0.1 255.0.0.0
R1(config-if)#no shutdown
R1(config-if)#exit
R1(config)#interface fastEthernet 1/0
R1(config-if)#ip address 192.168.0.10 255.255.255.0
R1(config-if)#no shutdown
R1(config-if)#interface fastEthernet 1/1
R1(config-if)#ip address 172.16.0.10 255.255.0.0
R1(config-if)#no shutdown
R1(config-if)#exit
R1(config)#interface fastEthernet 1/0
R1(config-if)#ip ospf 1 area 0
R1(config-if)#exit
R1(config)#interface fastEthernet 1/1
R1(config-if)#ip ospf 1 area 0
R1(config-if)#exit
R1(config)#interface gigabitEthernet 0/0
R1#show policy-map
NUEVAMENTE
R1#show policy-map interface fastEthernet 0/0
R2(config)#class-map MATCHBOSSPREC5
R2(config-cmap)#match precedence 5
R2(config-cmap)#exit
R2(config)#policy-map BOSSPRIORITY20
R2(config-pmap)#class MATCHBOSSPREC5
R2(config-pmap-c)#priority percent 20
R2(config-pmap-c)#exit
R2(config-pmap)#exit
R2(config)#interface fastEthernet 0/0
R2(config-if)#service-policy input BOSSPRIORITY20
R2(config-if)#exit
R2(config)#interface fastEthernet 0/1
R2(config-if)#service-policy output BOSSPRIORITY20
R2(config-if)#end
Configuracion ip helper
Router7#
interface FastEthernet0/0
ip address 192.168.1.254 255.255.255.0
ip helper-address 172.16.1.1
interface FastEthernet0/1
ip address 172.16.1.2 255.255.255.252
Router8#
ip dhcp pool red1
network 192.168.1.0 255.255.255.0
default-router 192.168.1.254
interface FastEthernet0/0
ip address 172.16.1.1 255.255.255.0
ip route 192.168.1.0 255.255.255.0 FastEthernet0/0
ROUTER DHCP
ip dhcp pool red1
network 192.168.1.0 255.255.255.0
default-router 192.168.1.254
ip dhcp pool red2
network 192.168.2.0 255.255.255.0
default-router 192.168.2.254
ip dhcp pool red3
network 192.168.3.0 255.255.255.0
default-router 192.168.3.254
interface FastEthernet0/0
ip address 172.16.1.1 255.255.255.252
ip route 192.168.1.0 255.255.255.0 FastEthernet0/0
ip route 192.168.2.0 255.255.255.0 FastEthernet0/0
ip route 192.168.3.0 255.255.255.0 FastEthernet0/0
ROUTER
interface FastEthernet0/0
ip address 192.168.1.254 255.255.255.0
ip helper-address 172.16.1.1
interface FastEthernet0/0.2
encapsulation dot1Q 2
ip address 192.168.2.254 255.255.255.0
ip helper-address 172.16.1.1
!
interface FastEthernet0/0.3
encapsulation dot1Q 3
ip address 192.168.3.254 255.255.255.0
ip helper-address 172.16.1.1
!
interface FastEthernet0/1
ip address 172.16.1.2 255.255.255.0
SWITCH
interface FastEthernet0/2
switchport mode trunk
interface FastEthernet0/10
switchport access vlan 2
switchport mode Access
interface FastEthernet0/20
switchport access vlan 3
switchport mode Access
Ping extendido
R1(config-if)#mpls ip
R2(config)#interface fastEthernet 0/0
R2(config-if)#mpls ip
R2(config)#interface serial 1/0
R2(config-if)#mpls ip
R3(config)#interface serial 1/0
R3(config-if)#mpls ip
R2#
router rip
version 2
network 172.16.0.0
default-information originate
!
ip classless
ip route 0.0.0.0 0.0.0.0 Serial0/0/1
R3(config)#router rip
R3(config-router)#version 2
R3(config-router)#default-information originate
CON ESE COMANDO SE PUEDE LLEGAR PING A TODAS LAS LOOPBACK DESDE
CUALQUIER ROUTER DENTRO DE LA RED
Multicast LAB
Switch capa 3
Sw1#vlan database
Sw1(vlan)#vlan 10 name vlan10
Sw1(vlan)#vlan 20 name vlan20
Sw1(config)#interface fastEthernet 0/1
Sw1(config-if)#switchport mode access
Sw1(config-if)#switchport access vlan 10
Sw1(config-if)#interface fastEthernet 0/2
Sw1(config-if)#switchport mode access
Sw1(config-if)#switchport access vlan 20
Sw1(config)#interface fastEthernet 0/3
Sw1(config-if)#switchport mode trunk
Sw1(config-if)#switchport trunk allowed vlan all
Sw2#vlan database
Sw2(vlan)#vlan 10 name vlan10
Sw2(vlan)#vlan 20 name vlan20
Sw2(config)#interface fastEthernet 0/1
Sw2(config-if)#switchport mode access
Sw2(config-if)#switchport access vlan 10
Sw2(config-if)#interface fastEthernet 0/2
Sw2(config-if)#switchport mode access
Sw2(config-if)#switchport access vlan 20
Sw2(config)#interface fastEthernet 0/3
Sw2(config-if)#switchport mode trunk
Sw2(config-if)#switchport trunk allowed vlan all
Sw3_capa_3(config)#ip routing
Suponiendo que en el router2 tenemos un enlace de internet que ingresa en el, le decimos que toda
ruta que entre a ese router por esa interfast ingrese cualquier direccin y que se distribuya
perfectamente con los protocolos ya existentes
Router2(config)#route rip
Router2(config-router)#version 2
Router2(config-router)#default-information originate
Con esto en todos los routers aparecer la ruta por defecto
Router(config-if)#exit
Router(config)#ip dhcp pool POOL1
Router(dhcp-config)#dns-server 108.45.16.163
Router(dhcp-config)#exit
Router(config)#ip dhcp pool POOL2
Router(dhcp-config)#dns-server 176.65.13.2
Switch#vlan database
Switch(vlan)#vlan 10
VLAN 10 added:
Name: VLAN0010
Switch(vlan)#vlan 20
VLAN 10 added:
Name: VLAN0020
Switch(vlan)#exit
APPLY completed.
Exiting....
Switch(config)#interface fastEthernet 0/1
Switch(config-if)#switchport mode access
Switch(config-if)#switchport access vlan 10
Switch(config-if)#interface fastEthernet 0/2
Switch(config-if)#switchport mode access
Switch(config-if)#switchport access vlan 20
Switch(config-if)#interface fastEthernet 0/24
Switch(config-if)#switchport mode trunk
Router#vlan database
Router(vlan)#vlan 10
VLAN 10 added:
Name: VLAN0010
Router(vlan)#vlan 20
VLAN 20 added:
Name: VLAN0020
Router(vlan)#exit
APPLY completed.
Exiting....
Router(config)#interface fastEthernet 0/0
Router(config-if)#no shutdown
Router(config-if)#exit
Router(config)#interface fastEthernet 0/0.10
Router(config-subif)#ip address 192.168.1.1 255.255.255.0
Router(config-subif)#encapsulation dot1Q 10
Router(config-subif)#interface fastEthernet 0/0.20
Router(config-subif)#encapsulation dot1Q 20
Router(config-subif)#ip address 192.168.2.1 255.255.255.0
Router(config-subif)#exit
Router(config)#ip dhcp excluded-address 192.168.1.1 192.168.1.10
Router(config)#ip dhcp excluded-address 192.168.2.1 192.168.2.10
Router(config)#ip dhcp pool RED_A
Router(dhcp-config)#network 192.168.1.0 255.255.255.0
Router(dhcp-config)#ip dhcp pool RED_B
Router(dhcp-config)#network 192.168.2.0 255.255.255.0
El numero 35 es el puerto
Puerto 35:icmp
Puerto 1027:TCP