Switch
Switch
--------------------------------------------------------------------------------
*Configure el nombre de host del switch como se indica en la topolog�a.
Switch(config)#hostname S1
*Guardar configuracion
S1#copy running-config startup-config
Destination filename [startup-config]?
Building configuration...
[OK]
*CONFIGURACION LOOPBACK
R6(config)#interface loopback 0
R6(config-if)#
%LINEPROTO-5-UPDOWN: Line protocol on Interface Loopback0, changed state to
up
R6(config-if)#ip address 192.169.6.6 255.255.255.0
--------------------------------------------------------------------------------
CONFIGURACION VTP EN LOS 3 SWITCHES
--------------------------------------------------------------------------------
S1(config)#vtp mode server
S1(config)#vtp domain Lab5
S1(config)#vtp password cisco
S1(config)#end
--------------------------------------------------------------------------------
CONFIGURACION DE ENLACES TRONCALES Y LA VLAN NATIVA (VLAN 99 como VLAN nativa)
Aplicar a las interfaces Fa0/1 a la Fa0/4
--------------------------------------------------------------------------------
S1S2S3(config)#interface fa0/1
S1S2S3(config-if)#switchport mode trunk
S1S2S3(config-if)#switchport trunk native vlan 99
S1S2S3(config-if)#no shutdown
S1S2S3(config)#end
S1S2S3(config)#interface fa0/2
S1S2S3(config-if)#switchport mode trunk
S1S2S3(config-if)#switchport trunk native vlan 99
S1S2S3(config-if)#no shutdown
S1S2S3(config-if)#end
S1S2S3(config)#interface fa0/3
S1S2S3(config-if#switchport mode trunk
S1S2S3(config-if)#switchport trunk native vlan 99
S1S2S3(config-if)#no shutdown
S1S2S3(config-if-#end
S1S2S3(config)#interface fa0/4
S1S2S3(config-if#switchport mode trunk
S1S2S3(config-if)#switchport trunk native vlan 99
S1S2S3(config-if)#no shutdown
S1S2S3(config-if-#end
--------------------------------------------------------------------------------
2.Crear las VLAN.
--------------------------------------------------------------------------------
S1(config)#vlan 99
S1(config-vlan)#name management
S1(config)#vlan 10
S1(config-vlan)#name faculty-staff
S1(config)#vlan 20
S1(config-vlan)#name students
S1(config)#vlan 30
S1(config-vlan)#name guest
S1(config-vlan)#end
--------------------------------------------------------------------------------
3.Asignar puertos de switch a una VLAN.
--------------------------------------------------------------------------------
S2(config)#interface fa0/6
S2(config-if)#switchport mode access
S2(config-if)#switchport access vlan 10
S2(config-if)#no shutdown
S2(config-if)#interface fa0/11
S2(config-if)#switchport mode access
S2(config-if)#switchport access vlan 20
S2(config-if)#no shutdown
S2(config-if)#interface fa0/18
S2(config-if)#switchport mode access
S2(config-if)#switchport access vlan 30
S2(config-if)#no shutdown
--------------------------------------------------------------------------------
4. Comando Completo Port Security
--------------------------------------------------------------------------------
Switch01> enable
Switch01# config terminal
Switch01(config)# interface fa0/1
Switch01(config-if)# switchport mode access
Switch01(config-if)#switchport port-security
Switch01(config-if)#switchport port-security maximum 2
Switch01(config-if)# switchport port-security violation shutdown
Switch01(config-if)# switchport port-security mac-address sticky
Switch01(config-if)# end
--------------------------------------------------------------------------------
Configure las interfaces del router on a Sticke
--------------------------------------------------------------------------------
--------------------------------------------------------------------------------
4.Habilitar el enlace troncal en conexiones entre switches.
--------------------------------------------------------------------------------
Configure la VLAN troncal y nativa para los puertos troncales de todos los
switches.
--------------------------------------------------------------------------------
4.Asignar VLAN Administrativa.
--------------------------------------------------------------------------------
S1(config)#interface vlan 99
S1(config-if)#ip address 172.17.99.11 255.255.255.0
S1(config-if)#no shutdown
S2(config)#interface vlan 99
S2(config-if)#ip address 172.17.99.12 255.255.255.0
S2(config-if)#no shutdown
S3(config)#interface vlan 99
S3(config-if)#ip address 172.17.99.13 255.255.255.0
S3(config-if)#no shutdown
--------------------------------------------------------------------------------
Gateway
R1(config-subif)#encapsulation dot1Q 99
R1(config-subif)#ip address 172.17.99.1 255.255.255.0
--------------------------------------------------------------------------------
CONFIGURACION GATEWAY GATEWAY
switch(config)# ip default-gateway 192.168.1.1
--------------------------------------------------------------------------------
Configurar Port Security en Switches Cisco
Switch01# config terminal
Switch01(config)# interface GigabitEthernet 0/1
Switch01(config-if)#
Switch01(config-if)# switchport mode access
Switch01(config-if)#switchport port-security
Switch01(config-if)#switchport port-security maximum 1
--------------------------------------------------------
Switch01(config-if)# switchport port-security violation { protect | restrict |
shutdown }
Switch01(config-if)# switchport port-security violation shutdown
--------------------------------------------------------
Switch01(config-if)# switchport port-security mac-address 0a04.aaf8.13ad
--------------------------------------------------------
Switch01(config-if)# switchport port-security mac-address sticky (aprende la MAC)
--------------------------------------------------------
Comando Completo Port Security
Switch01> enable
Switch01# config terminal
Switch01(config)# interface GigabitEthernet 0/1
Switch01(config-if)# switchport mode access
Switch01(config-if)#switchport port-security
Switch01(config-if)#switchport port-security maximum 1
Switch01(config-if)# switchport port-security violation shutdown
Switch01(config-if)# switchport port-security mac-address sticky
Switch01(config-if)# end
--------------------------------------------------------------------------------
1)
CONFIGURACION BASICA DEL SWITCH
*Guardar configuracion
S1#copy running-config startup-config
Destination filename [startup-config]?
Building configuration...
[OK]
CONFIGURACION LOOPBACK
R6(config)#interface loopback 0
R6(config-if)#
%LINEPROTO-5-UPDOWN: Line protocol on Interface Loopback0, changed state to up
R6(config-if)#ip address 192.169.6.6 255.255.255.0
--------------------------------------------------------------------------------
S2(config)#interface fa0/6
S2(config-if)#switchport mode access
S2(config-if)#switchport access vlan 10
S2(config-if)#no shutdown
S2(config-if)#interface fa0/11
S2(config-if)#switchport mode access
S2(config-if)#switchport access vlan 20
S2(config-if)#no shutdown
S2(config-if)#interface fa0/18
S2(config-if)#switchport mode access
S2(config-if)#switchport access vlan 99
S2(config-if)#no shutdown
--------------------------------------------------------------------------------
S1S2S3(config)#interface fa0/1
S1S2S3(config-if)#switchport mode trunk
S1S2S3(config-if)#switchport trunk native vlan 99
S1S2S3(config-if)#no shutdown
S1S2S3(config)#end
S1S2S3(config)#interface fa0/2
S1S2S3(config-if)#switchport mode trunk
S1S2S3(config-if)#switchport trunk native vlan 99
S1S2S3(config-if)#no shutdown
S1S2S3(config-if)#end
S1S2S3(config)#interface fa0/3
S1S2S3(config-if#switchport mode trunk
S1S2S3(config-if)#switchport trunk native vlan 99
S1S2S3(config-if)#no shutdown
S1S2S3(config-if-#end
S1S2S3(config)#interface fa0/4
S1S2S3(config-if#switchport mode trunk
S1S2S3(config-if)#switchport trunk native vlan 99
S1S2S3(config-if)#no shutdown
S1S2S3(config-if-#end
--------------------------------------------------------------------------------
2)
CONFIGURACION DEL SERVIDOR VTP CON LAS VLAN
S1(config)#vlan 99
S1(config-vlan)#name management
S1(config)#vlan 10
S1(config-vlan)#name faculty-staff
S1(config)#vlan 20
S1(config-vlan)#name students
S1(config)#vlan 30
S1(config-vlan)#name guest
S1(config-vlan)#end
--------------------------------------------------------------------------------
S1(config)#interface vlan99
S1(config-if)#ip address 172.17.99.11 255.255.255.0
S2(config)#interface vlan99
S2(config-if)#ip address 172.17.99.12 255.255.255.0
S3(config)#interface vlan99
S3(config-if)#ip address 172.17.99.13 255.255.255.0
--------------------------------------------------------------------------------
S1#show spanning-tree
--------------------------------------------------------------------------------
OPTIMIZAR STP
Conexion SSH
hostname
mombre del dominio
crypto
nombre de usuario
conexion ssh
y autenticacion local
ip domain-name ucr.ac.cr
1024
line vty 0 4
transport input ssh
login local
username admin
password cisco
--------------------------------------------------------------------------------
Hosts/Net: 30