0% found this document useful (0 votes)
9 views11 pages

Network Device Configuration Overview

The document contains configuration files for routers R1-R6 and switches SW1-SW2. The router configurations define interfaces, IP addresses, routing protocols (OSPF, RIP), VPN settings (crypto maps, ISAKMP policies), and other settings. The switch configurations define VLANs, interface descriptions and assignments to VLANs.

Uploaded by

AlexShear
Copyright
© Attribution Non-Commercial (BY-NC)
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
9 views11 pages

Network Device Configuration Overview

The document contains configuration files for routers R1-R6 and switches SW1-SW2. The router configurations define interfaces, IP addresses, routing protocols (OSPF, RIP), VPN settings (crypto maps, ISAKMP policies), and other settings. The switch configurations define VLANs, interface descriptions and assignments to VLANs.

Uploaded by

AlexShear
Copyright
© Attribution Non-Commercial (BY-NC)
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Configurations

Close Configs

Configurations
R1
! Last configuration change at 14:43:36 UTC Tue Aug 19 2008 ! version 12.4 service timestamps debug datetime msec service timestamps log datetime msec no service password-encryption !

R2

R3
version 12.4 service timestamps debug datetime msec service timestamps log datetime msec no service password-encryption ! hostname R3 ! boot-start-marker boot-end-marker ! no logging console ! no aaa new-model ip cef ! ! ! ! no ip domain lookup ! voice-card 0 no dspfarm ! ! ! ! ! ! ! ! ! !

R4
version 12.4 service timestamps debug datetime msec service timestamps log datetime msec no service password-encryption ! hostname R4 ! boot-start-marker boot-end-marker ! no logging console ! no aaa new-model ip cef ! ! ! ! no ip domain lookup ! voice-card 0 no dspfarm ! ! ! ! ! ! ! ! ! !

version 12.4 service timestamps debug datetime msec service timestamps log datetime msec no service password-encryption ! hostname R2 ! boot-start-marker boot-end-marker no ip bootp server ! no service dhcp no logging console aaa new-model ! username aset password 0 no aaa new-model cisco hostname R1 ip cef ! ! boot-start-marker ! boot-end-marker ! ! ! no logging console no ip domain lookup ! ! no aaa new-model voice-card 0 ip cef no dspfarm ! ! ! ! ! ! ! ! no ip domain lookup ! ! ip domain name [Link] ! ! ip accounting-list [Link] ! ! [Link] ! !

[Link] (1 of 11)8/19/2008 10:14:25 PM

Configurations

crypto map MYMAP 10 ipsecisakmp set peer [Link] set transform-set DES match address 100 ! crypto ipsec transform-set DES esp-des esp-sha-hmac ! crypto isakmp policy 10 ! ! crypto pki trustpoint CA enrollment url [Link] revocation-check none ! ip host CA [Link] voice-card 0 no dspfarm ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! ! !

! ! ! ! ! ! ! ! ! ! ! ! interface Loopback0 ip address [Link] [Link] ! interface GigabitEthernet0/0 no ip address shutdown duplex auto speed auto media-type rj45 ! interface GigabitEthernet0/1 description ASET-SEC-2101 ip address [Link] [Link] duplex auto speed auto media-type rj45 ! interface Serial0/0/0 ip address [Link] [Link] encapsulation frame-relay ip ospf network point-to-point frame-relay map ip [Link] 206 broadcast no frame-relay inverse-arp frame-relay lmi-type ansi

! ! ! ! ! ! ! ! ! ! ! ! interface Loopback0 ip address [Link] [Link] ! interface GigabitEthernet0/0 no ip address shutdown duplex auto speed auto media-type rj45 ! interface GigabitEthernet0/1 description ASET-SEC-2101 ip address [Link] [Link] duplex auto speed auto media-type rj45 ! interface Serial0/0/0 ip address [Link] [Link] encapsulation frame-relay ip ospf network point-to-point frame-relay map ip [Link] 306 broadcast no frame-relay inverse-arp frame-relay lmi-type ansi

! ! ! ! ! ! ! ! ! ! ! ! interface Loopback0 ip address [Link] [Link] ! interface GigabitEthernet0/0 description ASET-SEC-2101 ip address [Link] [Link] duplex auto speed auto media-type rj45 ! interface GigabitEthernet0/1 ip address [Link] [Link] duplex auto speed auto media-type rj45 ! interface Serial0/0/0 ip address [Link] [Link] encapsulation frame-relay ip ospf network point-to-point frame-relay map ip [Link] 406 broadcast no frame-relay inverse-arp frame-relay lmi-type ansi

[Link] (2 of 11)8/19/2008 10:14:25 PM

Configurations

! ! ! interface Serial0/1/0 router ospf 1 router ospf 1 interface Loopback0 ip address [Link] no ip address log-adjacency-changes log-adjacency-changes [Link] shutdown network [Link] [Link] area 2 area 2 virtual-link [Link] ! ! network [Link] [Link] area 2 network [Link] [Link] area 2 interface GigabitEthernet0/0 router ospf 1 ! network [Link] [Link] area 0 log-adjacency-changes ! network [Link] [Link] ip accounting accessnetwork [Link] [Link] area 3 ! area 0 violations ip http server ! ip accounting output-packets network [Link] [Link] area 3 no ip http secure-server router rip crypto map MYMAP ! ! passive-interface default description ASET-SEC-2101 ! ! network [Link] ip address [Link] ! ! distance 80 [Link] [Link] ip http server ! [Link] duplex auto no ip http secure-server ! ! speed auto ! control-plane ! media-type rj45 ! ! ! ! ! ! ip http server interface GigabitEthernet0/1 ! ! no ip http secure-server ip address [Link] ! ! ! [Link] control-plane ! ! duplex auto ! ! ! speed auto ! ! ! media-type rj45 ! ! ! ! ! ! control-plane interface Serial0/0/0 ! alias exec ipsec show crypto ! no ip address ! ipsec sa ! shutdown ! alias exec cipsec clear crypto sa ! ! ! alias exec ike show crypto ! interface Serial0/1/0 ! isakmp sa ! no ip address alias exec ipsec show crypto alias exec cike clear crypto ! shutdown ipsec sa isakmp ! clock rate 2000000 alias exec cipsec clear crypto sa ! ! ! alias exec ike show crypto line con 0 ! router ospf 1 isakmp sa exec-timeout 0 0 alias exec ipsec show crypto log-adjacency-changes stopbits 1 ipsec sa network [Link] [Link] area 0 alias exec cike clear crypto isakmp line aux 0 alias exec cipsec clear crypto sa network [Link] [Link] ! stopbits 1 alias exec ike show crypto area 0 line con 0 line vty 0 4 isakmp sa ! exec-timeout 0 0 login alias exec cike clear crypto !

[Link] (3 of 11)8/19/2008 10:14:25 PM

Configurations

! ip http server no ip http secure-server ! ! ! !

stopbits 1 line aux 0 stopbits 1 line vty 0 4 login ! scheduler allocate 20000 1000 ip access-list standard [name/ ! end num to match vty accessclass] permit [Link] ! control-plane ! ! ! ! ! ! ! ! ! alias exec ipsec show crypto ipsec sa alias exec cipsec clear crypto sa alias exec ike show crypto isakmp sa alias exec cike clear crypto isakmp ! access-list 100 permit ip host [Link] host [Link] ntp server [Link] source Loopback0 line con 0 exec-timeout 0 0 stopbits 1 line aux 0 stopbits 1 ! Only VTYs 0-4 should exist.

! scheduler allocate 20000 1000 ! end

isakmp ! line con 0 exec-timeout 0 0 stopbits 1 line aux 0 stopbits 1 line vty 0 4 login ! scheduler allocate 20000 1000 ! end

[Link] (4 of 11)8/19/2008 10:14:25 PM

Configurations

(0 points if true, -1 point if not true.) line vty 0 4 exec-timeout 3 30 telnet ssh access-class [name/ num to match ACL] in login ! scheduler allocate 20000 1000 ntp clock-period 17179876 ntp source Loopback0 ntp server [Link] ! exception core-file R1COREDUMP compress timestamp exception dump [Link] end

R5
! Last configuration change at 14:43:36 UTC Tue Aug 19 2008 ! version 12.4 service timestamps debug datetime msec service timestamps log datetime msec no service password-encryption ! hostname R5 ! boot-start-marker boot-end-marker ! no logging console ! no aaa new-model !

R6
! Last configuration change at 14:43:36 UTC Tue Aug 19 2008 ! version 12.4 service timestamps debug datetime msec service timestamps log datetime msec no service password-encryption ! hostname R6 ! boot-start-marker boot-end-marker ! no logging console ! no aaa new-model !

SW1
version 12.2 no service pad service timestamps debug uptime service timestamps log uptime no service password-encryption ! hostname SW1 ! no logging console ! no aaa new-model system mtu routing 1500 vtp domain ASET-SEC-2101 vtp mode transparent ip subnet-zero no ip domain-lookup ! !

SW2
version 12.2 no service pad service timestamps debug uptime service timestamps log uptime no service password-encryption ! hostname SW2 ! no logging console ! no aaa new-model system mtu routing 1500 vtp domain ASET-SEC-2101 vtp mode transparent ip subnet-zero no ip domain-lookup ! !

[Link] (5 of 11)8/19/2008 10:14:25 PM

Configurations

! ip cef ! ! no ip domain lookup ip domain name [Link] ! multilink bundle-name authenticated !

! ip cef ! ! no ip domain lookup

ip domain name [Link] ! multilink bundle-name authenticated ! voice-card 0 ! crypto map MYMAP 10 ipsec- no dspfarm ! isakmp ! set peer [Link] ! set transform-set DES ! match address 100 ! ! ! crypto ipsec transform-set ! DES esp-des esp-sha-hmac ! ! ! crypto isakmp policy 10 ! ! ! ! ! crypto pki trustpoint CA ! enrollment url [Link] ! revocation-check none ! ! ! ip host CA [Link] ! voice-card 0 ! no dspfarm ! crypto pki server CA ! grant auto ! lifetime certificate 4 ! auto-rollover ! ! ! crypto pki trustpoint CA ! revocation-check crl ! rsakeypair CA ! ! ! !

! ! ! ! no file verify auto spanning-tree mode pvst spanning-tree extend system-id ! vlan internal allocation policy ascending ! vlan 100,145,300 ! ! interface Loopback0 ip address [Link] [Link] ! interface FastEthernet0/1 description R1-Gi0/0 switchport access vlan 145 switchport mode access ! interface FastEthernet0/2 ! interface FastEthernet0/3 ! interface FastEthernet0/4 description R4-Gi0/0 switchport access vlan 145 switchport mode access ! interface FastEthernet0/5 description R5-Gi0/0 switchport access vlan 145 switchport mode access ! interface FastEthernet0/6 ! interface FastEthernet0/7

! ! ! ! no file verify auto spanning-tree mode pvst spanning-tree extend system-id ! vlan internal allocation policy ascending ! vlan 13,100,200,300 ! ! interface Loopback0 ip address [Link] [Link] ! interface FastEthernet0/1 description R1-Gi0/1 switchport access vlan 13 switchport mode access ! interface FastEthernet0/2 description R2-Gi0/1 switchport access vlan 200 switchport mode access ! interface FastEthernet0/3 description R3-Gi0/1 switchport access vlan 13 switchport mode access ! interface FastEthernet0/4 description R4-Gi0/1 switchport access vlan 100 switchport mode access ! interface FastEthernet0/5 description R5-Gi0/1

[Link] (6 of 11)8/19/2008 10:14:25 PM

Configurations

! ! ! ! ! ! ! ! ! ! ! ! ! archive log config hidekeys ! ! ! ! ! ! interface Loopback0 ip address [Link] [Link] ! interface GigabitEthernet0/0 crypto map MYMAP description ASET-SEC-2101 ip address [Link] [Link] duplex auto speed auto media-type rj45 ! interface GigabitEthernet0/1 ip address [Link] [Link] duplex auto speed auto

crypto pki certificate chain CA certificate ca 01 308201F3 3082015C A0030201 02020101 300D0609 2A864886 F70D0101 04050030 0D310B30 09060355 04031302 4341301E 170D3038 30383139 31333432 30395A17 0D313130 38313931 33343230 395A300D 310B3009 06035504 03130243 4130819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281 8100BE83 2113FB5D 0865E556 D2A70A98 B2A57246 BD9D58CA B107ADC0 B418CA57 4F51DDF6 8776CF1B 1EF928D7 E01D87DD C89FF130 61B6E9D3 2326FBBE 0881888E 2B22FC14 AD90183D 75B0959E A6644E79 0A543308 23FEF89B F7114811 BA941499 5ECAF7A7 1CF37B74 D61EC5D3 52A68CF6 54D0179F 46ABFC70 0106CFDD 15BA276C 4CF50203 010001A3 63306130 0F060355 1D130101 FF040530 030101FF 300E0603 551D0F01 01FF0404 03020186 301F0603 551D2304 18301680 145BAB1B 651D9371 EC4F8B4F F36DF1FD D0272503 C1301D06 03551D0E 04160414 5BAB1B65 1D9371EC

! interface FastEthernet0/8 ! interface FastEthernet0/9 ! interface FastEthernet0/10 description Backbone 1 switchport access vlan 100 switchport mode access ! interface FastEthernet0/11 description Backbone 3 switchport access vlan 300 switchport mode access ! interface FastEthernet0/12 ! interface FastEthernet0/13 ! interface FastEthernet0/14 ! interface FastEthernet0/15 ! interface FastEthernet0/16 ! interface FastEthernet0/17 ! interface FastEthernet0/18 ! interface FastEthernet0/19 ! interface FastEthernet0/20 ! interface FastEthernet0/21 ! interface FastEthernet0/22 ! interface FastEthernet0/23 ! interface FastEthernet0/24

switchport access vlan 300 switchport mode access ! interface FastEthernet0/6 description R6-Gi0/1 switchport access vlan 100 switchport mode access ! interface FastEthernet0/7 ! interface FastEthernet0/8 ! interface FastEthernet0/9 ! interface FastEthernet0/10 description Backbone 2 switchport access vlan 200 switchport mode access ! interface FastEthernet0/11 ! interface FastEthernet0/12 ! interface FastEthernet0/13 ! interface FastEthernet0/14 ! interface FastEthernet0/15 ! interface FastEthernet0/16 ! interface FastEthernet0/17 ! interface FastEthernet0/18 ! interface FastEthernet0/19 ! interface FastEthernet0/20 ! interface FastEthernet0/21

[Link] (7 of 11)8/19/2008 10:14:25 PM

Configurations

4F8B4FF3 6DF1FDD0 ! 272503C1 300D0609 interface Serial0/0/0 2A864886 F70D0101 04050003 no ip address 8181005B CEE98E20 shutdown 7ADA7DE5 ! A2D1CA13 D30614FB router eigrp 100 68D8B382 24DEED0F network [Link] [Link] 91EF05AB 2D79B1A7 auto-summary CF9C1902 BDA23692 ! A76DDCB2 95532AB3 router ospf 1 3A14C6C2 F5F37B7F log-adjacency-changes 9EB11B3E 9799FBF8 redistribute eigrp 100 subnets 777051DC CCA065BA network [Link] [Link] area 0 A3AED34C 1A6C4B50 network [Link] [Link] 06FBE25A 955F074F area 0 B34D0002 4FD283E6 ! 1F37D8B0 A374E0FA ! 5EC37319 2491CFF3 ! 23891A7A D1B6C5C8 ip http server 50A07BEC A3440A no ip http secure-server quit ! ! ! ! ! ! ! ! ! archive ! log config ! hidekeys control-plane ! ! ! ! ! ! ! ! ! ! ! ! interface Loopback0 ! ip address [Link] ! [Link] ! ! alias exec ipsec show crypto interface GigabitEthernet0/0 ipsec sa no ip address

media-type rj45

! interface GigabitEthernet0/1 description Trunk to SW2-Gi0/1 switchport trunk encapsulation dot1q switchport mode trunk ! interface GigabitEthernet0/2 description Trunk to SW2-Gi0/2 switchport trunk encapsulation dot1q switchport mode trunk ! interface Vlan1 no ip address shutdown ! ip classless ip http server ip http secure-server ! ! ! control-plane ! ! line con 0 exec-timeout 0 0 line vty 0 4 login line vty 5 15 login ! end

! interface FastEthernet0/22 ! interface FastEthernet0/23 ! interface FastEthernet0/24 ! interface GigabitEthernet0/1 description Trunk to SW1-Gi0/1 switchport trunk encapsulation dot1q switchport mode trunk ! interface GigabitEthernet0/2 description Trunk to SW1-Gi0/2 switchport trunk encapsulation dot1q switchport mode trunk ! interface Vlan1 no ip address shutdown ! ip classless ip http server ip http secure-server ! ! ! control-plane ! ! line con 0 exec-timeout 0 0 line vty 0 4 login line vty 5 15 login ! end

[Link] (8 of 11)8/19/2008 10:14:25 PM

Configurations

alias exec cipsec clear crypto sa alias exec ike show crypto isakmp sa alias exec cike clear crypto isakmp !

shutdown duplex auto speed auto media-type rj45

! interface GigabitEthernet0/1 access-list 100 permit ip host description ASET-SEC-2101 ip address [Link] [Link] host [Link] [Link] ntp server [Link] source duplex auto Loopback0 speed auto line con 0 media-type rj45 exec-timeout 0 0 ! stopbits 1 interface Serial0/0/0 line aux 0 no ip address stopbits 1 encapsulation frame-relay line vty 0 4 no frame-relay inverse-arp login frame-relay lmi-type ansi ! scheduler allocate 20000 1000 ! ntp clock-period 17179980 interface Serial0/0/0.26 pointntp source Loopback0 to-point ip address [Link] ntp server [Link] [Link] ! frame-relay interface-dlci 602 webvpn cef ! ! interface Serial0/0/0.346 end multipoint ip address [Link] [Link] ip ospf network point-tomultipoint ip ospf hello-interval 10 frame-relay map ip [Link] 604 broadcast frame-relay map ip [Link] 603 broadcast ! router ospf 1 log-adjacency-changes area 2 virtual-link [Link]

[Link] (9 of 11)8/19/2008 10:14:25 PM

Configurations

redistribute rip subnets network [Link] [Link] area 2 network [Link] [Link] area 2 network [Link] [Link] area 3 ! router rip passive-interface default network [Link] distance 80 [Link] [Link] ! ! ! ip http server no ip http secure-server ! ! ! ! ! ! ! control-plane ! ! ! ! ! ! ! ! ! alias exec ipsec show crypto ipsec sa alias exec cipsec clear crypto sa alias exec ike show crypto isakmp sa alias exec cike clear crypto isakmp

[Link] (10 of 11)8/19/2008 10:14:25 PM

Configurations

! ntp source Loopback0 line con 0 exec-timeout 0 0 stopbits 1 line aux 0 stopbits 1 line vty 0 4 login ! scheduler allocate 20000 1000 ntp authenticate ntp master ! webvpn cef ! end

[Link] (11 of 11)8/19/2008 10:14:25 PM

Common questions

Powered by AI

VLANs are utilized within the network to segment traffic and organize devices into logical groups. Configurations show interfaces such as FastEthernet0/1 and FastEthernet0/10 accessing different VLANs like VLAN 145 and VLAN 100, allowing separation of data traffic for different network segments and enhancing security and performance .

Secure administrative access is managed through VTY lines limited to sessions 0-4 with login authentication, and the use of specific IPs in access control lists. However, potential vulnerabilities could arise from the lack of secure password encryption and the absence of SSH as a secure alternative to Telnet, which is not configured in the current setup .

OSPF areas are utilized to partition the network into different segments to optimize routing. The network addresses are assigned specific OSPF areas such as area 0, area 2, and area 3. For example, area 0 includes networks like 110.1.145.1 and 110.1.5.1, while area 2 includes network 110.1.0.3 and virtual-links to other network areas to facilitate communication between them. This structuring helps in reducing the size of routing tables and controlling the spread of routing update information .

Serial interfaces in the network are configured with point-to-point and multipoint setups. For instance, interface Serial0/0/0 has no IP address and uses Frame Relay encapsulation, while its sub-interfaces such as Serial0/0/0.26 and Serial0/0/0.346 have specific IP addresses with subnet masks like 110.1.100.6/255.255.255.224 and 110.1.0.6/255.255.255.0, respectively. The frame-relay maps and IP networks are used to route traffic correctly .

Loopback interfaces are regularly configured with IP addresses for use in routing protocols like OSPF for stability and management platform access points. They provide advantages in terms of consistent reachability as they remain 'up' regardless of physical interface status, facilitating network management and monitoring .

Challenges from the current IPsec configurations could include potential vulnerabilities due to the use of older encryption standards like DES. Addressing these requires updating transform sets to stronger algorithms such as AES, ensuring regular updates and audits of security protocols, and deploying appropriate cryptographic standards for all IPsec policies to enhance security .

Frame-relay configurations, especially as seen with interfaces like Serial0/0/0, play a role in linking different network sections using virtual circuits. The impact includes providing a cost-effective WAN link solution with capacity for dynamic network adjustments, but the potential downsides include slower response times compared to modern alternatives like MPLS or direct leased lines, which can impact real-time data applications .

Using both OSPF and EIGRP can be beneficial for leveraging OSPF's scalability and open standard compatibility alongside EIGRP's fast convergence and flexibility. However, drawbacks include increased network complexity, potential route redistribution challenges, and administrative overhead to manage and troubleshoot multiple protocols effectively .

The crypto map MYMAP is used to define the IPsec policies for securing the data exchanged between peers. It specifies the peer with which to establish the secure connection, the transform set defining the security protocols and algorithms (DES with ESP DES and SHA for integrity), and matches the address for which the traffic should be encrypted .

The spanning-tree protocol (STP) is set to run in PVST mode, with system ID extension enabled to prevent loops. While this setup ensures network stability by managing VLAN bridge priorities, improvements can include enabling Rapid PVST+ for faster convergence and ensuring that root bridge placement is optimal by manually setting bridge priorities for critical parts of the network .

You might also like