Configurações - Redes de Alto Débito
Configurações - Redes de Alto Débito
Configurações - Redes de Alto Débito
IPSEC.
Resoluo:
P001 192.X.2.0/23
P001 192.X.2.0/24
P001 192.X.3.224/27
P007 192.X.14.0/23
P007 192.X.14.0/24
P001 192.X.15.224/27
P113 192.X.86.0/23
P113 192.X.86.0/24
P001 192.X.87.224/27
P337 192.X.224.0/23
P337 192.X.224.0/24
P001 192.X.255.224/27
REDE CORPORATIVA
172.Y.X.0 mscara /24 = 255.255.255.0
Onde Y = 16 31 ( Escolha Pessoal)
SEDE : 172.Y.X.1/24
PC_1 : 172.Y.X.10/24
FILIAL_1 : 172.Y.X+1.1/24
PC_2 : 172.Y.X+1.10/24
FILIAL_2 : 172.Y.X+2.1/24
PC_3 : 172.Y.X+2.10/24
FILIAL_3 : 172.Y.X+3.1/24
PC_4 : 172.Y.X+3.10/24
CONFIGURAO DO TNEL
Para fazermos a configurao do Tnel, vamos pegar no ltimo endereo da nossa
FILIAL_3 e somamos +1 para obtermos os endereos para o Tnel.
SEDE : 172.Y.X+4.1/24
Para as FILIAIS somaremos +1 no ltimo octeto, ou seja, ltimo bit.
FILIAL_1 : 172.Y.X+4.1+1/24
FILIAL_2 : 172.Y.X+4.1+2/24
FILIAL_3 : 172.Y.X+4.1+3/24
Obs: O nmero Y utilizado na configurao da rede corporativa o mesmo que ser
utilizado na configurao do Tnel, no altera-se
DLCI
Nome
Serial0
202
SEDE-FILIAL_1
Serial0
203
SEDE-FILIAL_2
Serial0
204
SEDE-FILIAL_3
Serial1
201
FILIAL_1-SEDE
Serial1
203
FILIAL_1- FILIAL_2
Serial2
201
FILIAL_2-SEDE
Serial2
202
FILIAL_2- FILIAL_1
Serial3
201
FILIAL_3-SEDE
CONFIGURAO VLAN
Configurao das respectivas Vlans:
Portas
Atribuio
Rede
F0/1-6
172. Y+2.1.1
VLAN 1
Vlan 1 - Nativa
172.Y+2.1.11
VLAN 1
Vlan 2 - Dados
172. Y+2.2.12
VLAN 1
Vlan 3 - Voz
172. Y+2.3.13
VLAN 1
Vlan 4 - Wirelss
172. Y+2.4.14
CONFIGURAO DO TUNEL
Entramos Novamente Na SEDE
SEDE>en
SEDE#conf t
SEDE(config)#interface tunnel 0
SEDE(config-if)#ip address 172.Y.11.1 255.255.255.0
SEDE(config-if)#tunnel source serial 0/0/0
SEDE(config-if)#tunnel destination 192.X.255.226
SEDE(config-if)#tunnel mode gre ip
SEDE(config-if)#exit
SEDE(config)#router eigrp 100
SEDE(config-router)#network 172.Y.0.0
SEDE(config-router)#no auto-summary
CONFIGURAO FRAME-RELAY
Entramos Novamente Na SEDE
SEDE>en
SEDE#conf t
SEDE(config)#interface serial 0/0/1
SEDE(config-if)#encapsulation frame-relay
SEDE(config-if)#no shutdown
SEDE(config-if)#interface serial 0/0/1.1 multipoint
SEDE(config-subif)#ip address 10.X.7.1 255.255.255.0
SEDE(config-subif)#frame-relay interface-dlci 202
SEDE(config-subif)#frame-relay interface-dlci 203
SEDE(config-subif)#inteRface serial 0/0/1.2 point-to-point
SEDE(config-subif)#ip address 10.X.8.1 255.255.255.252
SEDE(config-subif)#frame-relay interface-dlci 204
SEDE(config-subif)#exit
SEDE(config)#router eigrp 100
SEDE(config-router)#network 10.0.0.0
SEDE(config-router)#no auto-summary
SEDE(config-router)#end
FILIAL-1(config-subif)#exit
FILIAL-1(config)#router eigrp 100
FILIAL-1(config-router)#network 10.0.0.0
FILIAL-1(config-router)#no auto-summary
FILIAL-1(config-router)#end
CONFIGURAO VLAN
Entramos Novamente Na DLS_1
DLS_1>en
DLS_1#conf t
DLS_1(config-if-range)#interface range fastEthernet 0/1-24
DLS_1(config-if-range)#shut
DLS_1(config-if-range)#interface range gi0/1-2
DLS_1(config-if-range)#shutdown
DLS_1(config)#interface range fastEthernet 0/1-6
DLS_1(config-if-range)#switchport trunk encapsulation dot1q
DLS_1(config-if-range)#switchport mode trunk
DLS_1(config-if-range)#switchport trunk native vlan 15
DLS_1(config-if-range)#no shutdown
DLS_1(config)#interface vlan 15
DLS_1(config)#vtp mode server
DLS_1(config)#vtp domain Lab6
DLS_1(config)#vlan 15
DLS_1(config-vlan)#name Administrador
DLS_1(config-vlan)#exit
DLS_1(config)#vlan 16
DLS_1(config-vlan)#name Dados
DLS_1(config-vlan)#vlan 17
DLS_1(config-vlan)#name Voz
DLS_1(config-vlan)#vlan 18
DLS_1(config-vlan)#name Wireless
DLS_1(config-vlan)#end
ASL_1(config)#interface vlan 15
ASL_1(config-if)#ip address 172.Y.15.13 255.255.255.0
ASL_1(config-if)#no shutdown
ASL_1(config-if)#exit
ASL_1(config)#vtp mode client
ASL_1(config)#vtp domain Lab6
ALS_1(config)#end
ALS_1(config)#interface range fastEthernet 0/1-24
ALS_1(config-if-range)#no shutdown
ALS_1(config-if-range)#switchport mode access
ALS_1(config-if-range)#end
ALS_1(config)#interface range fastEthernet 0/7-12
ALS_1(config-if-range)#switchport access vlan 16
ALS_1(config-if-range)#no shutdown
ALS_1(config-if-range)#interface range fastEthernet 0/13-18
ALS_1(config-if-range)#switchport access vlan 17
ALS_1(config-if-range)#no shutdown
ALS_1(config-if-range)#interface range fastEthernet 0/19-24
ALS_1(config-if-range)#switchport access vlan 18
ALS_1(config-if-range)#no shutdown
ALS_1(config-if-range)#end
ASL_2(config-if-range)#no shutdown
ASL_2(config)#interface vlan 15
ASL_2(config-if)#ip address 172.Y.15.14 255.255.255.0
ASL_2(config-if)#no shutdown
ASL_2(config-if)#exit
ASL_2(config)#vtp mode client
ASL_2(config)#vtp domain Lab6
ALS_2(config)#end
ALS_2(config)#interface range fastEthernet 0/1-24
ALS_2(config-if-range)#no shutdown
ALS_2(config-if-range)#switchport mode access
ALS_2(config-if-range)#end
ALS_2(config)#interface range fastEthernet 0/7-12
ALS_2(config-if-range)#switchport access vlan 16
ALS_2(config-if-range)#no shutdown
ALS_2(config-if-range)#interface range fastEthernet 0/13-18
ALS_2(config-if-range)#switchport access vlan 17
ALS_2(config-if-range)#no shutdown
ALS_2(config-if-range)#interface range fastEthernet 0/19-24
ALS_2(config-if-range)#switchport access vlan 18
ALS_2(config-if-range)#no shutdown
ALS_2(config-if-range)#end
==Configurao de DHCP==
EM DLS1
DLS1(config)#ip route 0.0.0.0 0.0.0.0 172.30.27.21\30
DLS1(config)#int gi 0/1
DLS1(config-if)#ip routing
DLS1(config-if)#no swithcport
DLS1(config-if)#ip address 172.30.27.22\30
NA SEDE
SEDE(config)# interface fa 0/1
SEDE(config-if)#ip address 172.30.27.21\30
SEDE(config-if)#description interface da SEDE
SEDE(config-if)#no shutdown
SEDE(config-if)#interface fa 0/1.1
SEDE(config-subif)#encapsulation dot1q 1
SEDE(config-subif)#ip address 172.30.1.1 255.255.255.0
SEDE(config-if)#interface fa 0/1.2
SEDE(config-subif)#encapsulation dot1q 1 native
SEDE(config-subif)#ip address 172.Y.1.1 255.255.255.0
SEDE(config-if)#interface fa 0/1.3
SEDE(config-subif)#encapsulation dot1q 2
SEDE(config-subif)#ip address 172.Y.2.1 255.255.255.0
SEDE(config-if)#interface fa 0/1.4
SEDE(config-subif)#encapsulation dot1q 3
SEDE(config-subif)#ip address 172.Y.3.1 255.255.255.0
SEDE(config-if)#interface fa 0/1.5
SEDE(config-subif)#encapsulation dot1q 4
SEDE(config-subif)#ip address 172.Y.2.1 255.255.255.0
CONFIGURAO IPSEC
ROUTER DA SEDE
access-list 110 permit ahp host 172.Y.8.1 host 172.Y.7.1
access-list 110 permit esp host 172.Y.8.1 host 172.Y.7.1
access-list 110 permit udp host 172.Y.8.1 host 172.Y.7.1 eq isakmp
interface serial 0/0/0
ip access-group 110 in
crypto isakmp policy 110
authentication pre-shared
encryption des
group 1
hash md5
lifetime 86400
ENTRAMOS NA SEDE
SEDE(conf) # crypto isakmp enable
SEDE(conf) # crypto isakmp policy 110
SEDE(conf-isakmp) # authentication pre-shared
SEDE(conf-isakmp) # encryption 3des
SEDE(conf-isakmp) # group 2
SEDE(conf-isakmp) # hash sha
SEDE(conf-isakmp) # lifetime 43200
SEDE(conf-isakmp) # exit
SEDE(conf) # crypto isakmp key cisco123 address 192.X.15.226
SEDE(conf) # crypto ipsec transform-set MYSET esp-aes 128
SEDE(conf) # exit
SEDE(conf) # crypto map MYMAP 10 ipsec-isakmp
SEDE(conf-crypto-map) # match address 110
SEDE(conf-crypto-map) # set peer 192.X.15.226 default
SEDE(conf-crypto-map) # set peer 192.X.16.226
ENTRAMOS EM FILIAL_1
FILIAL_1(conf) # crypto isakmp enable
FILIAL_1(conf) # crypto isakmp policy 100
FILIAL_1(conf-isakmp) # authentication pre-shared
FILIAL_1(conf-isakmp) # encryption 3des
FILIAL_1(conf-isakmp) # group 2
FILIAL_1(conf-isakmp) # hash sha
FILIAL_1(conf-isakmp) # lifetime 43200
FILIAL_1(conf-isakmp) # exit
FILIAL_1(conf) # crypto isakmp key cisco123 address 192.X.3.226
FILIAL_1(conf) # crypto ipsec transform-set OTHERSET esp-aes 128
FILIAL_1(conf) # exit
FILIAL_1(conf) # crypto map MYMAP 10 ipsec-isakmp
FILIAL_1(conf-crypto-map) # match address 110
FILIAL_1(conf-crypto-map) # set peer 192.X.15.226 default
FILIAL_1(conf-crypto-map) # set peer 192.X.16.226
FILIAL_1(conf-crypto-map) # set pfs group1
FILIAL_1(conf-crypto-map) # set transform-set mine
FILIAL_1(conf-crypto-map) # set security-association lifetime seconds 86400
FILIAL_1(config)#access-list 110 permit ip 172.Y.7.1 0.0.0.255 172.Y.8.1 0.0
FILIAL_1(conf) # interface serial0/0/0
FILIAL_1(conf-if) # crypto map MYMAP
CONFIGURAO DE TELEFONE
ALS_2#conf t
ALS_2(config)#mls qos
ALS_2(config)#interface fastEthernet 0/14
ALS_2(config-if)#switchport mode access
ALS_2(config-if)#switchport access vlan 2
ALS_2(config-if)#mls qos trust cos
ALS_2(config-if)#switchport voice vlan 3
ALS_2(config-if)# mls qos trust device cisco-phone
ALS_2(config-if)#no shutdown