Network Design Proposal Capstone Final Project

download Network Design Proposal Capstone Final Project

of 24

Transcript of Network Design Proposal Capstone Final Project

  • 8/9/2019 Network Design Proposal Capstone Final Project

    1/24

    NETWORK DESIGNPROPOSAL

    FOR CAPSTONE FINAL PROJECT

  • 8/9/2019 Network Design Proposal Capstone Final Project

    2/24

    1

    Table of Contents

    I. INTRODUCTION 2

    II. DESIGN CONSIDERATIONS 2

    WAN Services 2

    LAN Services 2

    Network Fundamentals 2

    Security Services 3

    III. NETWORK DIAGRAMS AND TOPOLOGIES 4

    WAN Topology 4

    IV. SYSTEM COMPONENTS 4

    V. CONFIGURATIONS 5

  • 8/9/2019 Network Design Proposal Capstone Final Project

    3/24

    2

    I. INTRODUCTION

    The implementation of a Service Ready Medium Branch Network enablesenterprises with branch offices of 50 to 100 users to deploy high-value networkservices such as unified communication and application optimization on top of a

    secure branch network infrastructure that is connected to a campus or data centercore (central site) over a variety of WAN technologies. The goal of the ServicesReady Medium Branch Network is to make deployment of these services fast,simple, and predictable.

    The design, test and deployment of this Services Ready Medium Branch Networkwill focus on the key elements to ensure the consistent connectivity and mandatorysecurity requirements for data, voice, and application optimization services.

    II. DESIGN CONSIDERATIONS

    WAN Services

    Layer 3 Multiprotocol Label Switching (MPLS) Virtual Private Network (VPN)for increased flexibility and reduced bandwidth cost

    Dedicated bandwidth ranging from 6 to 44 Mb/s to handle data, voice, andvideo traffic

    LAN Services

    Hierarchical network design to simplify deployment, troubleshooting, andmanagement

    Connectivity to branch devices at Fast Ethernet or Gigabit Ethernet speeds Near-wire-speed performance between all devices Provisions for accommodating future expansion Networking device redundancy without traffic loops Power-over-Ethernet (PoE)

    Network Fundamentals

    High availability, rapid recovery, and disaster recovery Rapid recovery in case of component failure Automatic switchover to backup WAN link that has a minimum one-quarter of

    the bandwidth of the primary WAN link Ability to restore service within 24 hours in the event of a disaster Quality of service (QoS)

  • 8/9/2019 Network Design Proposal Capstone Final Project

    4/24

    3

    Application-specific traffic prioritization both within the branch office andacross the enterprise

    Bandwidth management for WAN-based traffic Provisions for IP telephony, business video, critical and bulk data applications Provisions to mitigate denial of service (DoS) and worm attacks Identification and classification of critical application flows for QoS IP routing and addressing Routing within the enterprise and between the branch and the service

    provider network Direct Internet access from the branch Support for multicast applications Translation of private addresses and ports in order to access the Internet Dynamic allocation of IP addresses for end devices

    Security Services

    Infrastructure protection Physical securing of access to networking devices Disabling of unused services that may be used to exploit the network Authentication of routing protocol updates Access control Authentication and authorization services for controlling access to network

    resources Logging capabilities for auditing access to network devices and resources Integration with global access management system to enforce access

    privileges Secure connectivity Secure interoffice connectivity for full-mesh and hub-and-spoke WAN

    topologies Secure access into the branch network for remote or home office workers Voice, video, and data separation on the LAN Separation of network management traffic Access to the server in the branch by home office users

    Threat protection, detection, and mitigation Blocking of unauthorized traffic from entering or leaving the branch Access to servers in the branch by home office users Verification of source addresses for incoming traffic Identification and mitigation of common DoS attacks and worms Prevention of malicious attacks on the branch office network from outside Prevention of attacks and security breaches from within the branch office

  • 8/9/2019 Network Design Proposal Capstone Final Project

    5/24

    4

    III. NETWORK DIAGRAMS AND TOPOLOGIES

    WAN Topology

    IV. SYSTEM COMPONENTS

    Device Platform Modules

    P1 Cisco 2851 IS Router 4 - WIC 1DSU-T1 V2 WAN Interface Card

    P2 Cisco 2851 IS Router 4 - WIC 1DSU-T1 V2 WAN Interface Card

    PE1 Cisco 2811 IS Router 3 - WIC 1DSU-T1 V2 WAN Interface Card

    PE2 Cisco 2811 IS Router 3 - WIC 1DSU-T1 V2 WAN Interface Card

    PE3 Cisco 2811 IS Router 3 - WIC 1DSU-T1 V2 WAN Interface Card

    PE4 Cisco 2811 IS Router 3 - WIC 1DSU-T1 V2 WAN Interface Card

    VRF1 CE1 Cisco 2610XM Router 2 - WIC 1DSU-T1 V2 WAN Interface CardCisco NM-1FE-TX 10/100 Fast Ethernet

    VRF1 CE2 Cisco 2610XM Router 2 - WIC 1DSU-T1 V2 WAN Interface CardCisco NM-1FE-TX 10/100 Fast Ethernet

  • 8/9/2019 Network Design Proposal Capstone Final Project

    6/24

    5

    HQ GW Cisco 2610XM Router Cisco NM-1FE-TX 10/100 Fast Ethernet

    BR GW Cisco 2610XM Router Cisco NM-1FE-TX 10/100 Fast Ethernet

    HQ CORESW

    Catalyst 3550-24 EMI N/A

    BR CORE

    SW

    Catalyst 3550-24 EMI N/A

    HQ ACCESSSW

    Catalyst 3524-24 EMI N/A

    BR ACCESSSW

    Catalyst 3524-24 EMI N/A

    V. CONFIGURATIONS

    hostname P1!mpls traffic-eng tunnels!interface Loopback0ip address 10.0.0.1 255.255.255.255!interface GigabitEthernet0/0description Connected to P2 Fa0/0ip address 10.1.0.1 255.255.255.252ip ospf network point-to-pointduplex autospeed autompls traffic-eng tunnels!interface GigabitEthernet0/1description Connected to P2 Fa2/0ip address 10.1.0.5 255.255.255.252ip ospf network point-to-pointduplex autospeed autompls traffic-eng tunnels!interface Serial0/0/0description Connected to PE1 S1/0ip address 10.1.1.1 255.255.255.252ip ospf network point-to-pointmpls traffic-eng tunnelsno fair-queueservice-module t1 timeslots 1-24!interface Serial0/1/0

  • 8/9/2019 Network Design Proposal Capstone Final Project

    7/24

    6

    description Connected to PE2 S1/0ip address 10.1.1.5 255.255.255.252ip ospf network point-to-pointmpls traffic-eng tunnelsservice-module t1 timeslots 1-24

    !interface Serial0/2/0description Connected to PE3 S1/0ip address 10.1.1.9 255.255.255.252ip ospf network point-to-pointmpls traffic-eng tunnelsservice-module t1 timeslots 1-24!interface Serial0/3/0description Connected to PE4 S1/0ip address 10.1.1.13 255.255.255.252

    ip ospf network point-to-pointmpls traffic-eng tunnelsservice-module t1 timeslots 1-24!router ospf 65000mpls traffic-eng router-id Loopback0mpls traffic-eng area 0router-id 10.0.0.1network 10.0.0.1 0.0.0.0 area 0network 10.1.0.0 0.0.0.7 area 0network 10.1.1.0 0.0.0.15 area 0

    !router bgp 65000bgp router-id 10.0.0.1bgp log-neighbor-changestimers bgp 12 36neighbor MPLS peer-groupneighbor MPLS remote-as 65000neighbor MPLS update-source Loopback0neighbor 10.0.0.2 remote-as 65000neighbor 10.0.0.2 update-source Loopback0neighbor 10.0.0.2 send-community extendedneighbor 10.0.1.1 peer-group MPLSneighbor 10.0.1.2 peer-group MPLSneighbor 10.0.1.3 peer-group MPLSneighbor 10.0.1.4 peer-group MPLS!address-family vpnv4neighbor MPLS send-community extendedneighbor MPLS route-reflector-client

  • 8/9/2019 Network Design Proposal Capstone Final Project

    8/24

    7

    neighbor 10.0.1.1 activateneighbor 10.0.1.2 activateneighbor 10.0.1.3 activateneighbor 10.0.1.4 activateexit-address-family

    hostname P2!mpls traffic-eng tunnels!interface Loopback0ip address 10.0.0.2 255.255.255.255!interface GigabitEthernet0/0description Connected to P1 Fa0/0ip address 10.1.0.2 255.255.255.252ip ospf network point-to-point

    duplex autospeed autompls traffic-eng tunnels!interface GigabitEthernet0/1description Connected to P1 Fa2/0ip address 10.1.0.6 255.255.255.252ip ospf network point-to-pointduplex autospeed autompls traffic-eng tunnels

    !interface Serial0/0/0description Connected to PE1 S1/1ip address 10.1.2.1 255.255.255.252ip ospf network point-to-pointmpls traffic-eng tunnelsno fair-queueservice-module t1 timeslots 1-24!interface Serial0/1/0description Connected to PE2 S1/1ip address 10.1.2.5 255.255.255.252ip ospf network point-to-pointmpls traffic-eng tunnelsservice-module t1 timeslots 1-24!interface Serial0/2/0description Connected to PE3 S1/1ip address 10.1.2.9 255.255.255.252

  • 8/9/2019 Network Design Proposal Capstone Final Project

    9/24

    8

    ip ospf network point-to-pointmpls traffic-eng tunnelsservice-module t1 timeslots 1-24!interface Serial0/3/0

    description Connected to PE4 S1/1ip address 10.1.2.13 255.255.255.252ip ospf network point-to-pointmpls traffic-eng tunnelsservice-module t1 timeslots 1-24!router ospf 65000mpls traffic-eng router-id Loopback0mpls traffic-eng area 0router-id 10.0.0.2network 10.0.0.2 0.0.0.0 area 0

    network 10.1.0.0 0.0.0.7 area 0network 10.1.2.0 0.0.0.15 area 0!router bgp 65000bgp router-id 10.0.0.2bgp log-neighbor-changestimers bgp 12 36neighbor MPLS peer-groupneighbor MPLS remote-as 65000neighbor MPLS update-source Loopback0neighbor 10.0.0.1 remote-as 65000

    neighbor 10.0.0.1 update-source Loopback0neighbor 10.0.0.1 send-community extendedneighbor 10.0.1.1 peer-group MPLSneighbor 10.0.1.2 peer-group MPLSneighbor 10.0.1.3 peer-group MPLSneighbor 10.0.1.4 peer-group MPLS!address-family vpnv4neighbor MPLS send-community extendedneighbor MPLS route-reflector-clientneighbor 10.0.1.1 activateneighbor 10.0.1.2 activateneighbor 10.0.1.3 activateneighbor 10.0.1.4 activateexit-address-familyhostname PE1ip cefno ip dhcp use vrf connectedip dhcp excluded-address 172.16.100.1

  • 8/9/2019 Network Design Proposal Capstone Final Project

    10/24

    9

    !ip dhcp pool sdm-pool1network 172.16.100.0 255.255.255.252default-router 172.16.100.1!

    ip vrf vrf1rd 64512:1route-target export 64512:1route-target import 64512:1!ip vrf vrf2rd 64512:2route-target export 64512:2route-target import 64512:2!no ip domain lookup

    !multilink bundle-name authenticatedmpls traffic-eng tunnels!interface Loopback0ip address 10.0.1.1 255.255.255.255!interface Tunnel2ip unnumbered Loopback0tunnel destination 10.0.1.2tunnel mode mpls traffic-eng

    tunnel mpls traffic-eng autoroute announcetunnel mpls traffic-eng path-option 2 dynamicno routing dynamic!interface Tunnel3ip unnumbered Loopback0tunnel destination 10.0.1.3tunnel mode mpls traffic-engtunnel mpls traffic-eng autoroute announcetunnel mpls traffic-eng path-option 3 dynamicno routing dynamic!interface Tunnel4ip unnumbered Loopback0tunnel destination 10.0.1.4tunnel mode mpls traffic-engtunnel mpls traffic-eng autoroute announcetunnel mpls traffic-eng path-option 4 dynamicno routing dynamic

  • 8/9/2019 Network Design Proposal Capstone Final Project

    11/24

    10

    !interface FastEthernet0/0ip address dhcpip nat outsideip virtual-reassembly

    duplex autospeed auto!interface FastEthernet0/1description $ETH-LAN$ip address 172.16.100.1 255.255.255.252ip nat insideip virtual-reassemblyduplex autospeed auto!

    interface Serial0/0/0description Connected to P1 S0/0/0ip address 10.1.1.2 255.255.255.252ip ospf network point-to-pointmpls traffic-eng tunnelsservice-module t1 clock source internalservice-module t1 timeslots 1-24!interface Serial0/1/0description Connected to P2 S0/0/0ip address 10.1.2.2 255.255.255.252

    ip ospf network point-to-pointmpls traffic-eng tunnelsservice-module t1 clock source internalservice-module t1 timeslots 1-24!interface Serial0/2/0description Connected to VRF1-CE1 S0/1ip vrf forwarding vrf1ip address 192.168.1.2 255.255.255.252ip ospf network point-to-pointmpls traffic-eng tunnelsservice-module t1 clock source internalservice-module t1 timeslots 1-24!interface Serial0/3/0description Connected to VRF2-CE1 S0/0ip vrf forwarding vrf2ip address 192.168.1.2 255.255.255.252ip ospf network point-to-point

  • 8/9/2019 Network Design Proposal Capstone Final Project

    12/24

    11

    mpls traffic-eng tunnelsservice-module t1 clock source internalservice-module t1 timeslots 1-24!router ospf 65000

    mpls traffic-eng router-id Loopback0mpls traffic-eng area 0router-id 10.0.1.1log-adjacency-changesnetwork 10.0.1.1 0.0.0.0 area 0network 10.1.1.2 0.0.0.0 area 0network 10.1.2.2 0.0.0.0 area 0!router bgp 65000bgp router-id 10.0.1.1bgp log-neighbor-changes

    timers bgp 12 36neighbor MPLS peer-groupneighbor MPLS remote-as 65000neighbor MPLS update-source Loopback0neighbor 10.0.0.1 peer-group MPLSneighbor 10.0.0.2 peer-group MPLS!address-family ipv4neighbor MPLS send-community extendedno neighbor 10.0.0.1 activateno neighbor 10.0.0.2 activate

    no auto-summaryno synchronizationexit-address-family!address-family vpnv4neighbor MPLS send-community extendedneighbor 10.0.0.1 activateneighbor 10.0.0.2 activateexit-address-family!address-family ipv4 vrf vrf2neighbor 192.168.1.1 remote-as 64512neighbor 192.168.1.1 activateneighbor 192.168.1.1 as-overridemaximum-paths 2no synchronizationexit-address-family!address-family ipv4 vrf vrf1

  • 8/9/2019 Network Design Proposal Capstone Final Project

    13/24

    12

    neighbor 192.168.1.1 remote-as 64512neighbor 192.168.1.1 activateneighbor 192.168.1.1 as-overridemaximum-paths 2no synchronization

    exit-address-family!ip nat inside source list 1 interface FastEthernet0/0 overload!access-list 1 remark SDM_ACL Category=2access-list 1 permit 172.16.100.0 0.0.0.3hostname PE2ip cefip vrf vrf1rd 64512:1route-target export 64512:1

    route-target import 64512:1!ip vrf vrf2rd 64512:2route-target export 64512:2route-target import 64512:2!mpls traffic-eng tunnels!interface Loopback0ip address 10.0.1.2 255.255.255.255

    !interface Tunnel1ip unnumbered Loopback0tunnel destination 10.0.1.1tunnel mode mpls traffic-engtunnel mpls traffic-eng autoroute announcetunnel mpls traffic-eng path-option 1 dynamicno routing dynamic!interface Tunnel3ip unnumbered Loopback0tunnel destination 10.0.1.3tunnel mode mpls traffic-engtunnel mpls traffic-eng autoroute announcetunnel mpls traffic-eng path-option 3 dynamicno routing dynamic!interface Tunnel4ip unnumbered Loopback0

  • 8/9/2019 Network Design Proposal Capstone Final Project

    14/24

    13

    tunnel destination 10.0.1.4tunnel mode mpls traffic-engtunnel mpls traffic-eng autoroute announcetunnel mpls traffic-eng path-option 4 dynamicno routing dynamic

    !interface FastEthernet0/0no ip addressshutdownduplex autospeed auto!interface FastEthernet0/1no ip addressshutdownduplex auto

    speed auto!interface Serial0/0/0description Connected to P1 S1/1ip address 10.1.1.6 255.255.255.252ip ospf network point-to-pointmpls traffic-eng tunnelsno fair-queueservice-module t1 clock source internalservice-module t1 timeslots 1-24!

    interface Serial0/1/0description Connected to P2 S1/1ip address 10.1.2.6 255.255.255.252ip ospf network point-to-pointmpls traffic-eng tunnelsservice-module t1 clock source internalservice-module t1 timeslots 1-24!interface Serial0/2/0description Connected to VRF1-CE1 S1/1ip vrf forwarding vrf1ip address 192.168.1.6 255.255.255.252service-module t1 clock source internalservice-module t1 timeslots 1-24!interface Serial0/3/0description Connected to VRF2-CE1 S1/1ip vrf forwarding vrf2ip address 192.168.1.6 255.255.255.252

  • 8/9/2019 Network Design Proposal Capstone Final Project

    15/24

    14

    service-module t1 clock source internalservice-module t1 timeslots 1-24!router ospf 65000mpls traffic-eng router-id Loopback0

    mpls traffic-eng area 0router-id 10.0.1.2log-adjacency-changesnetwork 10.0.1.2 0.0.0.0 area 0network 10.1.1.6 0.0.0.0 area 0network 10.1.2.6 0.0.0.0 area 0!router bgp 65000no synchronizationbgp router-id 10.0.1.2bgp log-neighbor-changes

    timers bgp 12 36neighbor MPLS peer-groupneighbor MPLS remote-as 65000neighbor MPLS update-source Loopback0neighbor MPLS send-community extendedneighbor 10.0.0.1 peer-group MPLSno neighbor 10.0.0.1 activateneighbor 10.0.0.2 peer-group MPLSno neighbor 10.0.0.2 activateno auto-summary!

    address-family vpnv4neighbor MPLS send-community extendedneighbor 10.0.0.1 activateneighbor 10.0.0.2 activateexit-address-family!address-family ipv4 vrf vrf2neighbor 192.168.1.5 remote-as 64512neighbor 192.168.1.5 activateneighbor 192.168.1.5 as-overridemaximum-paths 2no synchronizationexit-address-family!address-family ipv4 vrf vrf1neighbor 192.168.1.5 remote-as 64512neighbor 192.168.1.5 activateneighbor 192.168.1.5 as-overridemaximum-paths 2

  • 8/9/2019 Network Design Proposal Capstone Final Project

    16/24

    15

    no synchronizationexit-address-familyhostname PE3!ip cef

    ip vrf vrf1rd 64512:1route-target export 64512:1route-target import 64512:1!ip vrf vrf2rd 64512:2route-target export 64512:2route-target import 64512:2!no ip dhcp use vrf connected

    ip dhcp excluded-address 172.16.200.1!ip dhcp pool sdm-pool1network 172.16.200.0 255.255.255.252default-router 172.16.200.1!mpls traffic-eng tunnels!interface Loopback0ip address 10.0.1.3 255.255.255.255!

    interface Tunnel1ip unnumbered Loopback0tunnel destination 10.0.1.1tunnel mode mpls traffic-engtunnel mpls traffic-eng autoroute announcetunnel mpls traffic-eng path-option 1 dynamicno routing dynamic!interface Tunnel2ip unnumbered Loopback0tunnel destination 10.0.1.2tunnel mode mpls traffic-engtunnel mpls traffic-eng autoroute announcetunnel mpls traffic-eng path-option 2 dynamicno routing dynamic!interface Tunnel4ip unnumbered Loopback0tunnel destination 10.0.1.4

  • 8/9/2019 Network Design Proposal Capstone Final Project

    17/24

    16

    tunnel mode mpls traffic-engtunnel mpls traffic-eng autoroute announcetunnel mpls traffic-eng path-option 4 dynamicno routing dynamic!

    interface FastEthernet0/0ip address dhcpip nat outsideip virtual-reassemblyduplex autospeed auto!interface FastEthernet0/1description $ETH-LAN$ip address 172.16.200.1 255.255.255.252ip nat inside

    ip virtual-reassemblyduplex autospeed auto!interface Serial0/0/0description Connected to P1 S1/2ip address 10.1.1.10 255.255.255.252ip ospf network point-to-pointmpls traffic-eng tunnelsno fair-queueservice-module t1 clock source internal

    service-module t1 timeslots 1-24!interface Serial0/1/0description Connected to P2 S1/2ip address 10.1.2.10 255.255.255.252ip ospf network point-to-pointmpls traffic-eng tunnelsservice-module t1 clock source internalservice-module t1 timeslots 1-24!interface Serial0/2/0description Connected to VRF1-CE2 S1/0ip vrf forwarding vrf1ip address 192.168.1.10 255.255.255.252service-module t1 clock source internalservice-module t1 timeslots 1-24!interface Serial0/3/0description Connected to VRF2-CE2 S1/0

  • 8/9/2019 Network Design Proposal Capstone Final Project

    18/24

  • 8/9/2019 Network Design Proposal Capstone Final Project

    19/24

    18

    address-family ipv4 vrf vrf1neighbor 192.168.1.9 remote-as 64512neighbor 192.168.1.9 activateneighbor 192.168.1.9 as-overridemaximum-paths 2

    no synchronizationexit-address-family!ip nat inside source list 1 interface FastEthernet0/0 overload!access-list 1 remark SDM_ACL Category=2access-list 1 permit 172.16.200.0 0.0.0.3hostname PE4!ip cefip vrf vrf1

    rd 64512:1route-target export 64512:1route-target import 64512:1!ip vrf vrf2rd 64512:2route-target export 64512:2route-target import 64512:2!mpls traffic-eng tunnels!

    interface Loopback0ip address 10.0.1.4 255.255.255.255!interface Tunnel1ip unnumbered Loopback0tunnel destination 10.0.1.1tunnel mode mpls traffic-engtunnel mpls traffic-eng autoroute announcetunnel mpls traffic-eng path-option 1 dynamicno routing dynamic!interface Tunnel2ip unnumbered Loopback0tunnel destination 10.0.1.2tunnel mode mpls traffic-engtunnel mpls traffic-eng autoroute announcetunnel mpls traffic-eng path-option 2 dynamicno routing dynamic!

  • 8/9/2019 Network Design Proposal Capstone Final Project

    20/24

    19

    interface Tunnel3ip unnumbered Loopback0tunnel destination 10.0.1.3tunnel mode mpls traffic-engtunnel mpls traffic-eng autoroute announce

    tunnel mpls traffic-eng path-option 3 dynamicno routing dynamic!interface FastEthernet0/0no ip addressshutdownduplex autospeed auto!interface FastEthernet0/1no ip address

    shutdownduplex autospeed auto!interface Serial0/0/0description Connected to P1 S1/3ip address 10.1.1.14 255.255.255.252ip ospf network point-to-pointmpls traffic-eng tunnelsservice-module t1 clock source internalservice-module t1 timeslots 1-24

    !interface Serial0/1/0description Connected to P2 S1/3ip address 10.1.2.14 255.255.255.252ip ospf network point-to-pointmpls traffic-eng tunnelsservice-module t1 clock source internalservice-module t1 timeslots 1-24!interface Serial0/2/0description Connected to VRF1-CE2 S1/1ip vrf forwarding vrf1ip address 192.168.1.14 255.255.255.252service-module t1 clock source internalservice-module t1 timeslots 1-24!interface Serial0/3/0description Connected to VRF2-CE2 S1/1ip vrf forwarding vrf2

  • 8/9/2019 Network Design Proposal Capstone Final Project

    21/24

  • 8/9/2019 Network Design Proposal Capstone Final Project

    22/24

    21

    neighbor 192.168.1.13 remote-as 64512neighbor 192.168.1.13 activateneighbor 192.168.1.13 as-overridemaximum-paths 2no synchronization

    exit-address-familyhostname VRF1-CE1!ip cef!no ip dhcp use vrf connectedip dhcp excluded-address 10.10.100.1 10.10.100.100ip dhcp excluded-address 10.10.100.200 10.10.100.254!ip dhcp pool sdm-pool1import all

    network 10.10.100.0 255.255.255.0default-router 10.10.100.1dns-server 10.10.100.21 4.2.2.2domain-name CAPSTONE.LOCAL!no ip domain lookupip name-server 10.10.100.1ip name-server 4.2.2.2ip auth-proxy max-nodata-conns 3ip admission max-nodata-conns 3!

    interface Loopback0ip address 10.255.0.1 255.255.255.255!interface FastEthernet0/0ip address 10.10.100.1 255.255.255.0ip nat insideip virtual-reassemblyduplex autospeed auto!interface Serial0/0description Connected to PE1 S1/2ip address 192.168.1.1 255.255.255.252no fair-queueservice-module t1 timeslots 1-24!interface Serial0/1description Connected to PE2 S1/2ip address 192.168.1.5 255.255.255.252

  • 8/9/2019 Network Design Proposal Capstone Final Project

    23/24

    22

    service-module t1 timeslots 1-24!interface FastEthernet1/0ip address dhcpip nat outside

    ip virtual-reassemblyduplex autospeed auto!router bgp 64512no synchronizationbgp log-neighbor-changestimers bgp 12 36redistribute connectedneighbor 192.168.1.2 remote-as 65000neighbor 192.168.1.6 remote-as 65000

    no auto-summary!ip forward-protocol nd!ip nat inside source list 1 interface FastEthernet1/0 overload!access-list 1 permit 10.10.100.0 0.0.0.255hostname VRF1-CE2ip cef!no ip dhcp use vrf connected

    ip dhcp excluded-address 10.10.200.1 10.10.200.100ip dhcp excluded-address 10.10.200.200 10.10.200.254!ip dhcp pool sdm-pool2import allnetwork 10.10.200.0 255.255.255.0domain-name CAPSTONE.LOCALdns-server 10.10.200.21 4.2.2.2default-router 10.10.200.1!no ip domain lookupip name-server 10.10.200.2ip name-server 4.2.2.2ip auth-proxy max-nodata-conns 3ip admission max-nodata-conns 3!interface Loopback0ip address 10.255.0.2 255.255.255.255!

  • 8/9/2019 Network Design Proposal Capstone Final Project

    24/24

    23

    interface FastEthernet0/0ip address 10.10.200.1 255.255.255.0ip nat insideip virtual-reassemblyduplex auto

    speed auto!interface Serial0/0description Connected to PE3 S1/2ip address 192.168.1.9 255.255.255.252no fair-queueservice-module t1 timeslots 1-24!interface Serial0/1description Connected to PE4 S1/2ip address 192.168.1.13 255.255.255.252

    service-module t1 timeslots 1-24!interface FastEthernet1/0ip address dhcpip nat outsideip virtual-reassemblyduplex autospeed auto!router bgp 64512no synchronization

    bgp log-neighbor-changestimers bgp 12 36redistribute connectedneighbor 192.168.1.10 remote-as 65000neighbor 192.168.1.14 remote-as 65000no auto-summary!ip forward-protocol nd!ip nat inside source list 1 interface FastEthernet1/0 overload!access-list 1 permit 10.10.200.0 0.0.0.255