<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-2076617431778629795</id><updated>2011-07-07T21:43:25.593+01:00</updated><category term='OSPF'/><category term='NAT'/><category term='VTP'/><category term='Frame-Relay'/><category term='RIP'/><category term='SSH'/><category term='DNS'/><category term='Static Routes'/><category term='Extended ACL'/><category term='CDP'/><category term='Clock'/><category term='NTP'/><category term='VLAN'/><category term='Standard ACL'/><category term='Terminal Emulation'/><category term='Switch'/><category term='EIGRP'/><category term='Port Security'/><category term='Time Based ACL'/><category term='EtherChannel'/><category term='Home Router Setup'/><category term='Router'/><category term='DHCP'/><category term='STP'/><title type='text'>Cisco Basics</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://ciscobasics.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://ciscobasics.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>SynJunkie</name><uri>http://www.blogger.com/profile/01249134797038027437</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_vZAp7b1QDw8/ScYc8FwNqTI/AAAAAAAABEw/ZFgShqSU9HI/S220/Photo+6.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>41</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-2076617431778629795.post-5946835051048513513</id><published>2010-05-13T23:41:00.004+01:00</published><updated>2010-05-13T23:52:39.806+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Router'/><category scheme='http://www.blogger.com/atom/ns#' term='Home Router Setup'/><title type='text'>Home Router Setup - Part 2: Interfaces &amp; Services</title><content type='html'>In this post I'll be setting up my network interfaces and some network services, DNS and DHCP.&lt;br /&gt;&lt;br /&gt;Below is a diagram of the lab I'll be using.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_vZAp7b1QDw8/S-yANMElcFI/AAAAAAAABmw/_ozMw1ckjog/s1600/HOME+LAB+.PNG"&gt;&lt;img style="cursor: pointer; width: 400px; height: 336px;" src="http://4.bp.blogspot.com/_vZAp7b1QDw8/S-yANMElcFI/AAAAAAAABmw/_ozMw1ckjog/s400/HOME+LAB+.PNG" alt="" id="BLOGGER_PHOTO_ID_5470888611415421010" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Part 2 - Interfaces and Services&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Here I will set up the 2 network interfaces and remove CDP from the Test Network interface.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Router1(config)#&lt;span style="font-weight: bold;"&gt;interface ethernet 0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Router1(config-if)#&lt;span style="font-weight: bold;"&gt;ip address 10.0.2.254 255.255.255.0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Router1(config-if)#&lt;span style="font-weight: bold;"&gt;no cdp enable&lt;/span&gt;      &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Router1(config-if)#&lt;span style="font-weight: bold;"&gt;exit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Router1(config)#&lt;span style="font-weight: bold;"&gt;interface ethernet 1&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Router1(config-if)#&lt;span style="font-weight: bold;"&gt;ip address 10.0.1.254 255.255.255.0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Router1(config-if)#&lt;span style="font-weight: bold;"&gt;no shut&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Router1(config-if)#&lt;span style="font-weight: bold;"&gt;exit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I configure the router to use the Extreme router as it's default gateway.  I will also configure it to use OpenDNS name servers and to resolve DNS queries for other network hosts.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Router1(config)#&lt;span style="font-weight: bold;"&gt;ip route 0.0.0.0 0.0.0.0 10.0.1.1&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Router1(config)#&lt;span style="font-weight: bold;"&gt;ip domain-lookup&lt;/span&gt;        &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Router1(config)#&lt;span style="font-weight: bold;"&gt;ip name-server 208.67.222.222&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Router1(config)#&lt;span style="font-weight: bold;"&gt;ip name-server 208.67.220.220&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Router1(config)#&lt;span style="font-weight: bold;"&gt;ip dns server&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Router1(config)#&lt;span style="font-weight: bold;"&gt;exit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Next I configure DHCP for the Test Network.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Router1(config)#&lt;span style="font-weight: bold;"&gt;service dhcp&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Router1(config)#&lt;span style="font-weight: bold;"&gt;ip dhcp pool TEST_NETWORK_DHCP_POOL&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Router1(dhcp-config)#&lt;span style="font-weight: bold;"&gt;network 10.0.2.0 /24&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Router1(dhcp-config)#&lt;span style="font-weight: bold;"&gt;domain-name walliford.local&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Router1(dhcp-config)#&lt;span style="font-weight: bold;"&gt;dns-server 10.0.2.254&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Router1(dhcp-config)#&lt;span style="font-weight: bold;"&gt;default-router 10.0.2.254&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Router1(dhcp-config)#&lt;span style="font-weight: bold;"&gt;lease 7&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Router1(dhcp-config)#&lt;span style="font-weight: bold;"&gt;exit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I include exclusions so only 10.0.2.10 - 10.0.2.20 are used for DHCP clients.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Router1(config)#&lt;span style="font-weight: bold;"&gt;ip dhcp excluded-address 10.0.2.1 10.0.2.9&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Router1(config)#&lt;span style="font-weight: bold;"&gt;ip dhcp excluded-address 10.0.2.21 10.0.2.255&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Router1(config)#&lt;span style="font-weight: bold;"&gt;end&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2076617431778629795-5946835051048513513?l=ciscobasics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/5946835051048513513'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/5946835051048513513'/><link rel='alternate' type='text/html' href='http://ciscobasics.blogspot.com/2010/05/home-router-setup-part-2-interfaces.html' title='Home Router Setup - Part 2: Interfaces &amp; Services'/><author><name>SynJunkie</name><uri>http://www.blogger.com/profile/01249134797038027437</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_vZAp7b1QDw8/ScYc8FwNqTI/AAAAAAAABEw/ZFgShqSU9HI/S220/Photo+6.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_vZAp7b1QDw8/S-yANMElcFI/AAAAAAAABmw/_ozMw1ckjog/s72-c/HOME+LAB+.PNG' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-2076617431778629795.post-3238810329378091373</id><published>2010-05-12T22:39:00.008+01:00</published><updated>2010-05-13T22:20:53.110+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Router'/><category scheme='http://www.blogger.com/atom/ns#' term='Home Router Setup'/><title type='text'>Home Router Setup - Part 1: Ports</title><content type='html'>The next few posts will be a series about the setup of a  Cisco 800  Series router as a home router.  I will detail everything from setting  up the interfaces, users, DNS, DHCP, SSH, NAT and more.&lt;br /&gt;&lt;br /&gt;Below is a diagram that illustrates the network layout for this series  of posts.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_vZAp7b1QDw8/S-sgO1FSn1I/AAAAAAAABmo/IX1bjWnwgQc/s1600/HOME+LAB+.PNG"&gt;&lt;img style="cursor: pointer; width: 400px; height: 336px;" src="http://3.bp.blogspot.com/_vZAp7b1QDw8/S-sgO1FSn1I/AAAAAAAABmo/IX1bjWnwgQc/s400/HOME+LAB+.PNG" alt="" id="BLOGGER_PHOTO_ID_5470501611511127890" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Lab Network - 10.0.1.0/24&lt;/li&gt;&lt;li&gt;Test Network - 10.0.2.0/24&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Part 1 - Initial Configuration&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;In this part I will configure my ports and apply some security to the router.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I name the router, apply an enable password and create a banner.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router#&lt;span style="font-weight: bold;"&gt;configure terminal&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router(config)#&lt;span style="font-weight: bold;"&gt;hostname Router1&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router1(config)#&lt;span style="font-weight: bold;"&gt;enable secret cisco123&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router1(config)#&lt;span style="font-weight: bold;"&gt;banner motd  % No Unauthorised Access %&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I create a local user.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router1(config)#&lt;span style="font-weight: bold;"&gt;username bob secret cisco123&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router1(config)#&lt;span style="font-weight: bold;"&gt;aaa new-model&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router1(config)#&lt;span style="font-weight: bold;"&gt;aaa authentication login local_auth local&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I set the domain, create SSH keys and apply some SSH settings.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router1(config)#&lt;span style="font-weight: bold;"&gt;ip domain-name walliford.local&lt;/span&gt;                  &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router1(config)#&lt;span style="font-weight: bold;"&gt;crypto key generate rsa general-keys modulus 1024&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;The name for the keys will be: Router1.walliford.local&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;% The key modulus size is 1024 bits&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;% Generating 1024 bit RSA keys, keys will be non-exportable...[OK]&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router1(config)#&lt;span style="font-weight: bold;"&gt;ip ssh time-out 120&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Router1(config)#&lt;span style="font-weight: bold;"&gt;ip ssh version 2&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router1(config)#&lt;span style="font-weight: bold;"&gt;ip ssh authentication-retries 2&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I create an ACL which I will be applying to my telnet ports&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router1(config)#&lt;span style="font-weight: bold;"&gt;ip access-list standard ADMIN_ACCESS&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router1(config-std-nacl)#&lt;span style="font-weight: bold;"&gt;permit 10.0.1.0 0.0.0.255 log&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router1(config-std-nacl)#&lt;span style="font-weight: bold;"&gt;deny any log&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router1(config-std-nacl)#&lt;span style="font-weight: bold;"&gt;exit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I configure the console port to use the local user account and apply some timeout values.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router1(config)#&lt;span style="font-weight: bold;"&gt;line console 0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router1(config-line)#&lt;span style="font-weight: bold;"&gt;logging synchronous&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router1(config-line)#&lt;span style="font-weight: bold;"&gt;login authentication local_auth&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router1(config-line)#&lt;span style="font-weight: bold;"&gt;exec-timeout 30 0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router1(config-line)#&lt;span style="font-weight: bold;"&gt;exit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I apply several settings to the Aux port so it cannot be used.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router1(config)#&lt;span style="font-weight: bold;"&gt;line aux 0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router1(config-line)#&lt;span style="font-weight: bold;"&gt;no password&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router1(config-line)#&lt;span style="font-weight: bold;"&gt;no exec&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router1(config-line)#&lt;span style="font-weight: bold;"&gt;exec-timeout 0 0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router1(config-line)#&lt;span style="font-weight: bold;"&gt;transport input none&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router1(config-line)#&lt;span style="font-weight: bold;"&gt;exit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I configure my telnet ports to use SSH and telnet only and the local user account.  I apply some timeout values and apply the ACL so only hosts from the Lab network can access the router.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router1(config)#&lt;span style="font-weight: bold;"&gt;line vty 0 4&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router1(config-line)#&lt;span style="font-weight: bold;"&gt;logging synchronous&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router1(config-line)#&lt;span style="font-weight: bold;"&gt;login authentication local_auth&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router1(config-line)#&lt;span style="font-weight: bold;"&gt;transport input ssh telnet &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router1(config-line)#&lt;span style="font-weight: bold;"&gt;exec-timeout 30 0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router1(config-line)#&lt;span style="font-weight: bold;"&gt;access-class ADMIN_ACCESS in&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router1(config-line)#&lt;span style="font-weight: bold;"&gt;end&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I prevent 3 of the 5 telnet ports from being used.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router1(config)#&lt;span style="font-weight: bold;"&gt;line vty 2 4&lt;/span&gt;             &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router1(config-line)#&lt;span style="font-weight: bold;"&gt;transport input none&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router1(config-line)#&lt;span style="font-weight: bold;"&gt;exit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I set the clock, timezone and daylight saving settings.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router1(config)#&lt;span style="font-weight: bold;"&gt;clock timezone GMT 0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router1(config)#&lt;span style="font-weight: bold;"&gt;clock summer-time BST recurring last Sun Mar 2:00 last Sun Oct 2:00&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router1(config)#&lt;span style="font-weight: bold;"&gt;end&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router1#&lt;span style="font-weight: bold;"&gt;clock set 21:24:00 12 May 2010&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I apply timeout values to login attempts to prevent brute-force attacks.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router1(config)#&lt;span style="font-weight: bold;"&gt;login block-for 20 attempts 3 within 20&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router1(config)#&lt;span style="font-weight: bold;"&gt;login delay 2&lt;/span&gt; &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2076617431778629795-3238810329378091373?l=ciscobasics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/3238810329378091373'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/3238810329378091373'/><link rel='alternate' type='text/html' href='http://ciscobasics.blogspot.com/2010/05/home-router-setup-part-1.html' title='Home Router Setup - Part 1: Ports'/><author><name>SynJunkie</name><uri>http://www.blogger.com/profile/01249134797038027437</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_vZAp7b1QDw8/ScYc8FwNqTI/AAAAAAAABEw/ZFgShqSU9HI/S220/Photo+6.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_vZAp7b1QDw8/S-sgO1FSn1I/AAAAAAAABmo/IX1bjWnwgQc/s72-c/HOME+LAB+.PNG' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-2076617431778629795.post-3323638848083102761</id><published>2010-05-09T22:48:00.005+01:00</published><updated>2010-05-09T23:03:15.221+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Frame-Relay'/><title type='text'>Frame Relay - Point to Point</title><content type='html'>In this post I will configure my lab to use frame relay in a point to point configuration. Below is a diagram of the lab I will be using.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_vZAp7b1QDw8/S-cuGrBYTAI/AAAAAAAABmg/2dTAZQRL63g/s1600/Screen+shot+2010-05-09+at+22.09.03.PNG"&gt;&lt;img style="cursor: pointer; width: 400px; height: 187px;" src="http://4.bp.blogspot.com/_vZAp7b1QDw8/S-cuGrBYTAI/AAAAAAAABmg/2dTAZQRL63g/s400/Screen+shot+2010-05-09+at+22.09.03.PNG" alt="" id="BLOGGER_PHOTO_ID_5469390964627360770" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;R0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0#&lt;span style="font-weight: bold;"&gt;configure terminal &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Enter configuration commands, one per line.  End with CNTL/Z.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0(config)#&lt;span style="font-weight: bold;"&gt;interface serial 0/0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0(config-if)#&lt;span style="font-weight: bold;"&gt;encapsulation frame-relay &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0(config-if)#&lt;span style="font-weight: bold;"&gt;exit &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0(config)#&lt;span style="font-weight: bold;"&gt;interface serial 0/0.100 point-to-point&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0(config-subif)#&lt;span style="font-weight: bold;"&gt;ip address 192.168.1.1 255.255.255.0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0(config-subif)#&lt;span style="font-weight: bold;"&gt;frame-relay interface-dlci 100 &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0(config-fr-dlci)#&lt;span style="font-weight: bold;"&gt;exit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0(config-subif)#&lt;span style="font-weight: bold;"&gt;exit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0(config)#&lt;span style="font-weight: bold;"&gt;interface serial 0/0.101 point-to-point&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0(config-subif)#&lt;span style="font-weight: bold;"&gt;ip address 192.168.2.1 255.255.255.0&lt;/span&gt;    &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0(config-subif)#&lt;span style="font-weight: bold;"&gt;frame-relay interface-dlci 101&lt;/span&gt;          &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0(config-fr-dlci)#&lt;span style="font-weight: bold;"&gt;exit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0(config-subif)#&lt;span style="font-weight: bold;"&gt;exit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0(config)#&lt;span style="font-weight: bold;"&gt;interface serial 0/0&lt;/span&gt;                    &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0(config-if)#&lt;span style="font-weight: bold;"&gt;no shut&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;R1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R1(config)#&lt;span style="font-weight: bold;"&gt;interface serial 0/0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R1(config-if)#&lt;span style="font-weight: bold;"&gt;encapsulation frame-relay&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R1(config-if)#&lt;span style="font-weight: bold;"&gt;exit&lt;/span&gt;  &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R1(config)#&lt;span style="font-weight: bold;"&gt;interface serial 0/0.200 point-to-point &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R1(config-subif)#&lt;span style="font-weight: bold;"&gt;ip address 192.168.1.2 255.255.255.0 &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R1(config-subif)#&lt;span style="font-weight: bold;"&gt;frame-relay interface-dlci 200&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R1(config-fr-dlci)#&lt;span style="font-weight: bold;"&gt;exit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R1(config-subif)#&lt;span style="font-weight: bold;"&gt;exit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R1(config)#&lt;span style="font-weight: bold;"&gt;interface serial 0/0&lt;/span&gt;                    &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R1(config-if)#&lt;span style="font-weight: bold;"&gt;no shutdown &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;R2&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R2(config)#&lt;span style="font-weight: bold;"&gt;interface serial 0/0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R2(config-if)#&lt;span style="font-weight: bold;"&gt;encapsulation frame-relay&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R2(config-if)#&lt;span style="font-weight: bold;"&gt;exit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R2(config)# &lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;span style="font-weight: bold;"&gt;interface  serial 0/0.300 point-to-point &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R2(config-subif)#&lt;span style="font-weight: bold;"&gt;ip address 192.168.2.2 255.255.255.0 &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R2(config-subif)#&lt;span style="font-weight: bold;"&gt;frame-relay interface-dlci 300&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R2(config-fr-dlci)#&lt;span style="font-weight: bold;"&gt;exit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R2(config-subif)#&lt;span style="font-weight: bold;"&gt;exit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R2(config)#&lt;span style="font-weight: bold;"&gt;interface serial 0/0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R2(config-if)#&lt;span style="font-weight: bold;"&gt;no shutdown&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Show Commands&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R2#&lt;span style="font-weight: bold;"&gt;show frame-relay pvc&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;PVC Statistics for interface Serial0/0 (Frame Relay DTE)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;              Active     Inactive      Deleted       Static&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Local          1            0            0            0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Switched       0            0            0            0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Unused         0            0            0            0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;DLCI = 300, DLCI USAGE = LOCAL, PVC STATUS = ACTIVE, INTERFACE = Serial0/0.300&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  input pkts 349           output pkts 358          in bytes 31010     &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  out bytes 30951          dropped pkts 0           in pkts dropped 0         &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  out pkts dropped 0                out bytes dropped 0         &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  in FECN pkts 0           in BECN pkts 0           out FECN pkts 0         &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  out BECN pkts 0          in DE pkts 0             out DE pkts 0         &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  out bcast pkts 344       out bcast bytes 29735     &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  5 minute input rate 0 bits/sec, 0 packets/sec&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  5 minute output rate 0 bits/sec, 0 packets/sec&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  pvc create time 00:32:46, last time pvc status changed 00:31:55&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R2#&lt;span style="font-weight: bold;"&gt;show frame-relay lmi&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;LMI Statistics for interface Serial0/0 (Frame Relay DTE) LMI TYPE = ANSI&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Invalid Unnumbered info 0        Invalid Prot Disc 0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Invalid dummy Call Ref 0        Invalid Msg Type 0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Invalid Status Message 0        Invalid Lock Shift 0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Invalid Information ID 0        Invalid Report IE Len 0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Invalid Report Request 0        Invalid Keep IE Len 0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Num Status Enq. Sent 25        Num Status msgs Rcvd 26&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Num Update Status Rcvd 0        Num Status Timeouts 0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Last Full Status Req 00:00:56        Last Full Status Rcvd 00:00:56&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R2# &lt;span style="font-weight: bold;"&gt;sh frame-relay map&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Serial0/0.300 (up): point-to-point dlci, dlci 300(0x12C,0x48C0), broadcast&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;          status defined, active&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;&lt;/span&gt;After configuring frame relay I am able to ping routers on the same network but not the other networks, so currently R2 cannot talk to R1.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R2#&lt;span style="font-weight: bold;"&gt;ping 192.168.1.1&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Type escape sequence to abort.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Sending 5, 100-byte ICMP Echos to 192.168.1.1, timeout is 2 seconds:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;.....&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Success rate is 0 percent (0/5)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;&lt;/span&gt;I have no route to the 192.168.1.0 network in my routing table.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R2#&lt;span style="font-weight: bold;"&gt;sh ip route&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Codes: C - connected, S - static, R - RIP, M - mobile, B - BGP&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       E1 - OSPF external type 1, E2 - OSPF external type 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       ia - IS-IS inter area, * - candidate default, U - per-user static route&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       o - ODR, P - periodic downloaded static route&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Gateway of last resort is not set&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;C    192.168.2.0/24 is directly connected, Serial0/0.300&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;&lt;/span&gt;To fix this problem I enable EIGRP on all my routers using the config below.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R2#&lt;span style="font-weight: bold;"&gt;conf t&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Enter configuration commands, one per line.  End with CNTL/Z.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R2(config)#&lt;span style="font-weight: bold;"&gt;router eigrp 10&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R2(config-router)#&lt;span style="font-weight: bold;"&gt;network 192.168.0.0 0.0.255.255 &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R2(config-router)#&lt;span style="font-weight: bold;"&gt;end&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Now I try again.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R2#ping &lt;span style="font-weight: bold;"&gt;192.168.1.1 &lt;/span&gt;  &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Type escape sequence to abort.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Sending 5, 100-byte ICMP Echos to 192.168.1.1, timeout is 2 seconds:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!!!!!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 4/7/12 ms&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;&lt;/span&gt;And my routing table shows the routes created by EIGRP.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R2#&lt;span style="font-weight: bold;"&gt;show ip route&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Codes: C - connected, S - static, R - RIP, M - mobile, B - BGP&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       E1 - OSPF external type 1, E2 - OSPF external type 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       ia - IS-IS inter area, * - candidate default, U - per-user static route&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       o - ODR, P - periodic downloaded static route&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Gateway of last resort is not set&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;D    192.168.1.0/24 [90/2681856] via 192.168.2.1, 00:01:20, Serial0/0.300&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;C    192.168.2.0/24 is directly connected, Serial0/0.300&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2076617431778629795-3323638848083102761?l=ciscobasics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/3323638848083102761'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/3323638848083102761'/><link rel='alternate' type='text/html' href='http://ciscobasics.blogspot.com/2010/05/frame-relay-point-to-point.html' title='Frame Relay - Point to Point'/><author><name>SynJunkie</name><uri>http://www.blogger.com/profile/01249134797038027437</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_vZAp7b1QDw8/ScYc8FwNqTI/AAAAAAAABEw/ZFgShqSU9HI/S220/Photo+6.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_vZAp7b1QDw8/S-cuGrBYTAI/AAAAAAAABmg/2dTAZQRL63g/s72-c/Screen+shot+2010-05-09+at+22.09.03.PNG' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-2076617431778629795.post-5013330880559213562</id><published>2010-05-07T20:36:00.003+01:00</published><updated>2010-05-07T20:47:52.897+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Frame-Relay'/><title type='text'>Frame-Relay - Multipoint</title><content type='html'>In this post I'll detail the configuration used to set up frame-relay in a multipoint configuration for the lab shown in the diagram below.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_vZAp7b1QDw8/S-RsUbYEPgI/AAAAAAAABmY/z2G1IvyzWlE/s1600/Screen+shot+2010-05-07+at+00.32.17.PNG"&gt;&lt;img style="cursor: pointer; width: 400px; height: 192px;" src="http://4.bp.blogspot.com/_vZAp7b1QDw8/S-RsUbYEPgI/AAAAAAAABmY/z2G1IvyzWlE/s400/Screen+shot+2010-05-07+at+00.32.17.PNG" alt="" id="BLOGGER_PHOTO_ID_5468614945736506882" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R0(config)#&lt;span style="font-weight: bold;"&gt;interface serial 0/0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R0(config-if)#&lt;span style="font-weight: bold;"&gt;ip address 192.168.1.1 255.255.255.0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R0(config-if)#&lt;span style="font-weight: bold;"&gt;encapsulation frame-relay&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R0(config-if)#&lt;span style="font-weight: bold;"&gt;no shut&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R0(config-if)#&lt;span style="font-weight: bold;"&gt;frame-relay map ip 192.168.1.2 100 broadcast&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R0(config-if)#&lt;span style="font-weight: bold;"&gt;frame-relay map ip 192.168.1.3 101 broadcast&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R0(config-if)#&lt;span style="font-weight: bold;"&gt;end&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1(config)#&lt;span style="font-weight: bold;"&gt;interface serial 0/0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1(config-if)#&lt;span style="font-weight: bold;"&gt;ip address 192.168.1.2 255.255.255.0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1(config-if)#&lt;span style="font-weight: bold;"&gt;encapsulation frame-relay&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1(config-if)#&lt;span style="font-weight: bold;"&gt;no shut&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1(config-if)#&lt;span style="font-weight: bold;"&gt;frame-relay map ip 192.168.1.1 200 broadcast&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1(config-if)#&lt;span style="font-weight: bold;"&gt;frame-relay map ip 192.168.1.3 200 broadcast&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1(config-if)#&lt;span style="font-weight: bold;"&gt;end&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R2&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R2(config)#&lt;span style="font-weight: bold;"&gt;interface serial 0/0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R2(config-if)#&lt;span style="font-weight: bold;"&gt;ip address 192.168.1.3 255.255.255.0&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R2(config-if)#&lt;span style="font-weight: bold;"&gt;encapsulation frame-relay&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R2(config-if)#&lt;span style="font-weight: bold;"&gt;no shut&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R2(config-if)#&lt;span style="font-weight: bold;"&gt;exit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R2(config)#&lt;span style="font-weight: bold;"&gt;interface serial 0/0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R2(config-if)#&lt;span style="font-weight: bold;"&gt;frame-relay map ip 192.168.1.1 300 broadcast&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R2(config-if)#&lt;span style="font-weight: bold;"&gt;frame-relay map ip 192.168.1.2 300 broadcast&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R2(config-if)#&lt;span style="font-weight: bold;"&gt;end&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Show Commands&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R2#&lt;span style="font-weight: bold;"&gt;show frame-relay lmi&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;LMI Statistics for interface Serial0/0 (Frame Relay DTE) LMI TYPE = ANSI&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Invalid Unnumbered info 0        Invalid Prot Disc 0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Invalid dummy Call Ref 0        Invalid Msg Type 0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Invalid Status Message 0        Invalid Lock Shift 0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Invalid Information ID 0        Invalid Report IE Len 0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Invalid Report Request 0        Invalid Keep IE Len 0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Num Status Enq. Sent 168        Num Status msgs Rcvd 80&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Num Update Status Rcvd 0        Num Status Timeouts 89&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Last Full Status Req 00:00:04        Last Full Status Rcvd 00:00:04&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R2#&lt;span style="font-weight: bold;"&gt;show frame-relay map&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Serial0/0 (up): ip 192.168.1.1 dlci 300(0x12C,0x48C0), static,&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;              broadcast,&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;              CISCO, status defined, active&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Serial0/0 (up): ip 192.168.1.2 dlci 300(0x12C,0x48C0), static,&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;              broadcast,&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;              CISCO, status defined, active&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Debug Commands&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R2#&lt;span style="font-weight: bold;"&gt;debug frame-relay lmi interface serial 0/0&lt;/span&gt;             &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Frame Relay LMI debugging is on&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Displaying lmi data from interface Serial0/0 only                                  &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;*Mar  1 00:58:02.583: Serial0/0(out): StEnq, myseq 100, yourseen 97, DTE up&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;*Mar  1 00:58:02.587: datagramstart = 0x7A019D4, datagramsize = 14&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;*Mar  1 00:58:02.587: FR encap = 0x00010308&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;*Mar  1 00:58:02.587: 00 75 95 01 01 01 03 02 64 61 &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;*Mar  1 00:58:02.595: &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;*Mar  1 00:58:02.607: Serial0/0(in): Status, myseq 100, pak size 14&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;*Mar  1 00:58:02.607: RT IE 1, length 1, type 1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;*Mar  1 00:58:02.607: KA IE 3, length 2, yourseq 98, myseq 100&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2076617431778629795-5013330880559213562?l=ciscobasics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/5013330880559213562'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/5013330880559213562'/><link rel='alternate' type='text/html' href='http://ciscobasics.blogspot.com/2010/05/frame-relay-multipoint.html' title='Frame-Relay - Multipoint'/><author><name>SynJunkie</name><uri>http://www.blogger.com/profile/01249134797038027437</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_vZAp7b1QDw8/ScYc8FwNqTI/AAAAAAAABEw/ZFgShqSU9HI/S220/Photo+6.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_vZAp7b1QDw8/S-RsUbYEPgI/AAAAAAAABmY/z2G1IvyzWlE/s72-c/Screen+shot+2010-05-07+at+00.32.17.PNG' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-2076617431778629795.post-5985079047468699396</id><published>2010-04-18T23:30:00.003+01:00</published><updated>2010-04-18T23:38:49.067+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Router'/><category scheme='http://www.blogger.com/atom/ns#' term='Time Based ACL'/><title type='text'>Time Based Access Control Lists</title><content type='html'>This is just a quick post to show how to configure Time Based Access Control Lists.  My aim is to only allow telnet access to the Jet Direct in the Test network between 18:00 and 23:59 on a daily basis.&lt;br /&gt;&lt;br /&gt;So this post makes sense I should mention that I am using the network in the diagram below and I am NAT'ing 10.0.1.243 to the host in the Test network on 10.0.2.10.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_vZAp7b1QDw8/S8uIS6xOODI/AAAAAAAABmI/TARxeqpmRaA/s1600/Screen+shot+2010-04-18+at+23.12.39.PNG"&gt;&lt;img style="cursor: pointer; width: 400px; height: 126px;" src="http://3.bp.blogspot.com/_vZAp7b1QDw8/S8uIS6xOODI/AAAAAAAABmI/TARxeqpmRaA/s400/Screen+shot+2010-04-18+at+23.12.39.PNG" alt="" id="BLOGGER_PHOTO_ID_5461608831711590450" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Router1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Create a static NAT mapping to the Jet Direct Printer&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Router1(config)#ip nat inside source static 10.0.2.10 10.0.1.243&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I then check I can ping the Jet Direct and telnet to it.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;MacBook&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;MacBook:~ syn$ &lt;span style="font-weight: bold;"&gt;ping -c 2  10.0.1.243&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;PING 10.0.1.243 (10.0.1.243): 56 data bytes&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;64 bytes from 10.0.1.243: icmp_seq=0 ttl=59 time=9.490 ms&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;64 bytes from 10.0.1.243: icmp_seq=1 ttl=59 time=3.068 ms&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;MacBook:~ syn$ &lt;span style="font-weight: bold;"&gt;telnet 10.0.1.243&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Trying 10.0.1.243...&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Connected to 10.0.1.243.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Escape character is '^]'.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;HP JetDirect&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Please type "?" for HELP, or "/" for current settings&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;&gt; &lt;span style="font-weight: bold;"&gt;exit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt; EXITING WITHOUT SAVING ANY ENTRIES&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;&gt; Connection closed by foreign host.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Router1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Now I create the access list.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Router1(config)#&lt;span style="font-weight: bold;"&gt;ip access-list extended TELNET_TO_JETDIRECT&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Router1(config-ext-nacl)#&lt;span style="font-weight: bold;"&gt;permit tcp 10.0.1.0 0.0.0.255 10.0.1.243 0.0.0.0 eq 23 time-range EVENING log&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Router1(config-ext-nacl)#&lt;span style="font-weight: bold;"&gt;deny tcp 10.0.1.0 0.0.0.255 10.0.1.243 0.0.0.0 eq 23 log                  &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Router1(config-ext-nacl)#&lt;span style="font-weight: bold;"&gt;permit ip any any&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Router1(config-ext-nacl)#&lt;span style="font-weight: bold;"&gt;exit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="display: block;" id="formatbar_Buttons"&gt;&lt;span class=" on down" style="display: block;" id="formatbar_Bold" title="Bold" onmouseover="ButtonHoverOn(this);" onmouseout="ButtonHoverOff(this);" onmouseup="" onmousedown="CheckFormatting(event);FormatbarButton('richeditorframe', this, 3);ButtonMouseDown(this);"&gt;&lt;img src="img/blank.gif" alt="Bold" class="gl_bold" border="0" /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;I create a time range for the ACL&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Router1(config)#&lt;span style="font-weight: bold;"&gt;time-range EVENING&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Router1(config-time-range)#&lt;span style="font-weight: bold;"&gt;periodic daily 18:00 to 23:59&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I check the ACL&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Router1#&lt;span style="font-weight: bold;"&gt;sh ip access-lists&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Extended IP access list TELNET_TO_JETDIRECT&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;    10 permit tcp 10.0.1.0 0.0.0.255 host 10.0.2.10 eq telnet log time-range EVENING (active)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;    20 deny tcp 10.0.1.0 0.0.0.255 host 10.0.2.10 eq telnet log&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;    30 permit ip any any&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I apply the ACL to an interface&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Router1(config)#&lt;span style="font-weight: bold;"&gt;interface ethernet 1&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Router1(config-if)#&lt;span style="font-weight: bold;"&gt;ip access-group TELNET_TO_JETDIRECT in&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Router1(config-if)#&lt;span style="font-weight: bold;"&gt;end&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I check the ACL has applied&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Router1#&lt;span style="font-weight: bold;"&gt;sh ip interface ethernet 1 | include Inbound&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Inbound  access list is TELNET_TO_JETDIRECT&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Recheck the ACL after telneting to the JetDirect&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Router1#&lt;span style="font-weight: bold;"&gt;sh ip access-lists&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Extended IP access list TELNET_TO_JETDIRECT&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;    5 permit tcp 10.0.1.0 0.0.0.255 host 10.0.1.243 eq telnet log time-range EVENING (active) (9 matches)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;    20 deny tcp 10.0.1.0 0.0.0.255 host 10.0.1.243 eq telnet log&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;    30 permit ip any any (60 matches)&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: courier new;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2076617431778629795-5985079047468699396?l=ciscobasics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/5985079047468699396'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/5985079047468699396'/><link rel='alternate' type='text/html' href='http://ciscobasics.blogspot.com/2010/04/time-based-access-control-lists.html' title='Time Based Access Control Lists'/><author><name>SynJunkie</name><uri>http://www.blogger.com/profile/01249134797038027437</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_vZAp7b1QDw8/ScYc8FwNqTI/AAAAAAAABEw/ZFgShqSU9HI/S220/Photo+6.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_vZAp7b1QDw8/S8uIS6xOODI/AAAAAAAABmI/TARxeqpmRaA/s72-c/Screen+shot+2010-04-18+at+23.12.39.PNG' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-2076617431778629795.post-985028020602272484</id><published>2010-03-21T23:19:00.004Z</published><updated>2010-03-21T23:25:59.160Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Router'/><category scheme='http://www.blogger.com/atom/ns#' term='NTP'/><title type='text'>Configure NTP</title><content type='html'>In this post I will go through the steps to configure my router to use a NTP server as a time source.&lt;br /&gt;&lt;br /&gt;First I will check the current configuration. I  will then ping the public NTP server before setting up the router to use it.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1#&lt;span style="font-weight: bold;"&gt;sh clock detail&lt;/span&gt;   &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;23:18:28.123 GMT Sun Mar 21 2010&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Time source is user configuration&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1#&lt;span style="font-weight: bold;"&gt;ping 130.88.203.12&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Type escape sequence to abort.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Sending 5, 100-byte ICMP Echos to 130.88.203.12, timeout is 2 seconds:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!!!!!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 24/24/24 ms&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1#&lt;span style="font-weight: bold;"&gt;conf t&lt;/span&gt;            &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Enter configuration commands, one per line.  End with CNTL/Z.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(config)#&lt;span style="font-weight: bold;"&gt;ntp server 130.88.203.12&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Useful show commands to check the NTP settings are:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-family: courier new;"&gt;show ntp status&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-family: courier new;"&gt;show ntp associations&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2076617431778629795-985028020602272484?l=ciscobasics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/985028020602272484'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/985028020602272484'/><link rel='alternate' type='text/html' href='http://ciscobasics.blogspot.com/2010/03/configure-ntp.html' title='Configure NTP'/><author><name>SynJunkie</name><uri>http://www.blogger.com/profile/01249134797038027437</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_vZAp7b1QDw8/ScYc8FwNqTI/AAAAAAAABEw/ZFgShqSU9HI/S220/Photo+6.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-2076617431778629795.post-775467854918613204</id><published>2010-03-21T23:05:00.003Z</published><updated>2010-03-21T23:11:36.098Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Terminal Emulation'/><category scheme='http://www.blogger.com/atom/ns#' term='Router'/><category scheme='http://www.blogger.com/atom/ns#' term='Switch'/><title type='text'>Terminal Emulation Settings</title><content type='html'>This is just a very brief post to list the correct settings that are used to connect to the router or switch using a terminal program such as HyperTerminal and the console cable.&lt;br /&gt;&lt;br /&gt;&lt;span class="content"&gt;&lt;pre&gt;&lt;span style="font-family:courier new;"&gt;Bits per sec    :  9600 &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Data bits       :     8 &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Parity          :  none &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Stop bits       :     1 &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Flow control    :  none &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Rarely some routers may require different Bits per second settings.  Simply try 1200, 2400 or 4800.&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2076617431778629795-775467854918613204?l=ciscobasics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/775467854918613204'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/775467854918613204'/><link rel='alternate' type='text/html' href='http://ciscobasics.blogspot.com/2010/03/terminal-emulation-settings.html' title='Terminal Emulation Settings'/><author><name>SynJunkie</name><uri>http://www.blogger.com/profile/01249134797038027437</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_vZAp7b1QDw8/ScYc8FwNqTI/AAAAAAAABEw/ZFgShqSU9HI/S220/Photo+6.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-2076617431778629795.post-6316706803443680027</id><published>2010-03-20T14:12:00.001Z</published><updated>2010-03-20T14:18:09.757Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Router'/><category scheme='http://www.blogger.com/atom/ns#' term='Clock'/><title type='text'>Configure Time &amp; Date</title><content type='html'>In this short post I will configure my router with the correct timezone, time and date.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1#&lt;span style="font-weight: bold;"&gt;sh clock detai&lt;/span&gt;l &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;*01:56:43.478 UTC Mon Oct 19 2009&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;No time source&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1#&lt;span style="font-weight: bold;"&gt;conf t          &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Enter configuration commands, one per line.  End with CNTL/Z.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(config)#&lt;span style="font-weight: bold;"&gt;clock timezone GMT 0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(config)#&lt;span style="font-weight: bold;"&gt;end&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1#&lt;span style="font-weight: bold;"&gt;sh clock detail &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;*01:59:54.390 GMT Mon Oct 19 2009&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;No time source&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1#&lt;span style="font-weight: bold;"&gt;clock set 14:10:00 20 MARCH 2010&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1#&lt;span style="font-weight: bold;"&gt;sh clock detail &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;14:10:16.183 GMT Sat Mar 20 2010&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Time source is user configuration&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2076617431778629795-6316706803443680027?l=ciscobasics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/6316706803443680027'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/6316706803443680027'/><link rel='alternate' type='text/html' href='http://ciscobasics.blogspot.com/2010/03/configure-time-date.html' title='Configure Time &amp; Date'/><author><name>SynJunkie</name><uri>http://www.blogger.com/profile/01249134797038027437</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_vZAp7b1QDw8/ScYc8FwNqTI/AAAAAAAABEw/ZFgShqSU9HI/S220/Photo+6.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-2076617431778629795.post-244921080525412621</id><published>2010-03-18T23:17:00.003Z</published><updated>2010-03-19T00:08:07.669Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='NAT'/><category scheme='http://www.blogger.com/atom/ns#' term='Router'/><title type='text'>Static NAT &amp; Dynamic NAT with Overload</title><content type='html'>In this short post I will configure my router allow to NAT a single port only.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1#&lt;span style="font-weight: bold;"&gt;conf t&lt;/span&gt;                    &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Enter configuration commands, one per line.  End with CNTL/Z.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(config)#&lt;span style="font-weight: bold;"&gt;ip nat inside source static udp 10.0.2.2 514 10.0.1.245 514 extendable&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;This command will allow the router accept syslog messages sent to UDP port 514 on 10.0.1.245 and translate them to UDP 514 on 10.0.2.2 which is the syslog server.  Only port 514 will be available for translation.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2076617431778629795-244921080525412621?l=ciscobasics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/244921080525412621'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/244921080525412621'/><link rel='alternate' type='text/html' href='http://ciscobasics.blogspot.com/2010/03/static-nat_18.html' title='Static NAT &amp; Dynamic NAT with Overload'/><author><name>SynJunkie</name><uri>http://www.blogger.com/profile/01249134797038027437</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_vZAp7b1QDw8/ScYc8FwNqTI/AAAAAAAABEw/ZFgShqSU9HI/S220/Photo+6.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-2076617431778629795.post-5653343603501992250</id><published>2010-03-18T23:00:00.004Z</published><updated>2010-03-18T23:06:43.663Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='DNS'/><category scheme='http://www.blogger.com/atom/ns#' term='Router'/><title type='text'>Configure a DNS Server</title><content type='html'>In this short post I will configure my router to act as a DNS server for hosts on my network.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1#&lt;span style="font-weight: bold;"&gt;conf t&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Enter configuration commands, one per line.  End with CNTL/Z.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(config)#&lt;span style="font-weight: bold;"&gt;ip domain name lab.local&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(config)#&lt;span style="font-weight: bold;"&gt;ip domain-lookup &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(config)#&lt;span style="font-weight: bold;"&gt;ip name-server 8.8.8.8&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(config)#&lt;span style="font-weight: bold;"&gt;ip dns server&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The router will now pass and DNS requests to 8.8.8.8 (Google) to resolve.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2076617431778629795-5653343603501992250?l=ciscobasics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/5653343603501992250'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/5653343603501992250'/><link rel='alternate' type='text/html' href='http://ciscobasics.blogspot.com/2010/03/configure-dns-server.html' title='Configure a DNS Server'/><author><name>SynJunkie</name><uri>http://www.blogger.com/profile/01249134797038027437</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_vZAp7b1QDw8/ScYc8FwNqTI/AAAAAAAABEw/ZFgShqSU9HI/S220/Photo+6.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-2076617431778629795.post-7136221148357582116</id><published>2010-03-09T22:19:00.003Z</published><updated>2010-03-09T22:27:11.290Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='NAT'/><category scheme='http://www.blogger.com/atom/ns#' term='Router'/><title type='text'>Static NAT</title><content type='html'>In this post I will configure a Static NAT entry on Router1 for  the Win7 host.  I'll be using the network in the diagram below.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_vZAp7b1QDw8/S5bJ26131RI/AAAAAAAABmA/7T6xR4Hc2Sg/s1600-h/Screen+shot+2010-03-09+at+21.48.59.PNG"&gt;&lt;img style="cursor: pointer; width: 400px; height: 132px;" src="http://3.bp.blogspot.com/_vZAp7b1QDw8/S5bJ26131RI/AAAAAAAABmA/7T6xR4Hc2Sg/s400/Screen+shot+2010-03-09+at+21.48.59.PNG" alt="" id="BLOGGER_PHOTO_ID_5446762744696526098" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;First I remove the NAT configuration from my last post.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(config)#&lt;span style="font-weight: bold;"&gt;no ip nat inside source list NAT pool NAT_POOL overload &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Dynamic mapping in use, do you want to delete all entries? [no]: &lt;span style="font-weight: bold;"&gt;y&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Now I configure NAT to map Win7 (10.0.2.1) to 10.0.1.240&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(config)#&lt;span style="font-weight: bold;"&gt;ip nat inside source static 10.0.2.1 10.0.1.240&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I verify I can reach the internet from the NAT'd host and check the NAT translations&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(config)#&lt;span style="font-weight: bold;"&gt;do sh ip nat tran&lt;/span&gt;                                       &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Pro Inside global         Inside local          Outside local         Outside global&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;tcp 10.0.1.240:1328       10.0.2.1:1328         208.43.202.17:80      208.43.202.17:80&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2076617431778629795-7136221148357582116?l=ciscobasics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/7136221148357582116'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/7136221148357582116'/><link rel='alternate' type='text/html' href='http://ciscobasics.blogspot.com/2010/03/static-nat.html' title='Static NAT'/><author><name>SynJunkie</name><uri>http://www.blogger.com/profile/01249134797038027437</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_vZAp7b1QDw8/ScYc8FwNqTI/AAAAAAAABEw/ZFgShqSU9HI/S220/Photo+6.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_vZAp7b1QDw8/S5bJ26131RI/AAAAAAAABmA/7T6xR4Hc2Sg/s72-c/Screen+shot+2010-03-09+at+21.48.59.PNG' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-2076617431778629795.post-308179753887385378</id><published>2010-03-09T21:50:00.004Z</published><updated>2010-03-09T22:06:04.137Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='NAT'/><category scheme='http://www.blogger.com/atom/ns#' term='Router'/><title type='text'>Dynamic NAT Using Pools</title><content type='html'>In this post I will remove my previous NAT entry and create a pool of addresses to use for NAT.  I'll be using the network in the diagram below and configuring Router1.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_vZAp7b1QDw8/S5bDNVmhB6I/AAAAAAAABl4/qIMGmGRE9r8/s1600-h/Screen+shot+2010-03-09+at+21.48.59.PNG"&gt;&lt;img style="cursor: pointer; width: 400px; height: 132px;" src="http://3.bp.blogspot.com/_vZAp7b1QDw8/S5bDNVmhB6I/AAAAAAAABl4/qIMGmGRE9r8/s400/Screen+shot+2010-03-09+at+21.48.59.PNG" alt="" id="BLOGGER_PHOTO_ID_5446755433255602082" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;First I'll remove the previous NAT (from my last post) configuration.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;router1(config)#&lt;span style="font-weight: bold;"&gt;no ip nat inside source list NAT interface Ethernet0 overload&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Dynamic mapping in use, do you want to delete all entries? [no]: &lt;span style="font-weight: bold;"&gt;yes&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;After removing the config I verify that I cannot access the internet or ping the internet from the Win7 host.&lt;br /&gt;&lt;br /&gt;Now I create a NAT pool with three addresses.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;router1(config)#&lt;span style="font-weight: bold;"&gt;ip nat pool NAT_POOL 10.0.1.250 10.0.1.252 netmask 255.255.255.0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I already have the NAT access-list created from my previous post so I'll use that again.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;router1(config)#&lt;span style="font-weight: bold;"&gt;ip nat inside source list NAT pool NAT_POOL overload&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Now I access the internet from the Win7 host and verify that I am being NAT'd.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;router1#&lt;span style="font-weight: bold;"&gt;sh ip nat translations&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Pro Inside global         Inside local          Outside local         Outside global&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;tcp 10.0.1.251:1231       10.0.2.1:1231         208.43.202.17:80      208.43.202.17:80&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I can also check the NAT statistics.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;router1#&lt;span style="font-weight: bold;"&gt;sh ip nat statistics&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Total active translations: 41 (0 static, 41 dynamic; 41 extended)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Outside interfaces:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Ethernet0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Inside interfaces: &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Ethernet1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Hits: 24714  Misses: 1339&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;CEF Translated packets: 25094, CEF Punted packets: 1907&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Expired translations: 1666&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Dynamic mappings:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;-- Inside Source&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;[Id: 3] access-list NAT pool NAT_POOL refcount 41&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt; pool NAT_POOL: netmask 255.255.255.0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;    start 10.0.1.250 end 10.0.1.252&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;    type generic, total addresses 3, allocated 1 (33%), misses 0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Queued Packets: 0&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2076617431778629795-308179753887385378?l=ciscobasics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/308179753887385378'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/308179753887385378'/><link rel='alternate' type='text/html' href='http://ciscobasics.blogspot.com/2010/03/dynamic-nat-using-pools.html' title='Dynamic NAT Using Pools'/><author><name>SynJunkie</name><uri>http://www.blogger.com/profile/01249134797038027437</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_vZAp7b1QDw8/ScYc8FwNqTI/AAAAAAAABEw/ZFgShqSU9HI/S220/Photo+6.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_vZAp7b1QDw8/S5bDNVmhB6I/AAAAAAAABl4/qIMGmGRE9r8/s72-c/Screen+shot+2010-03-09+at+21.48.59.PNG' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-2076617431778629795.post-6728854826898107515</id><published>2010-03-08T21:01:00.004Z</published><updated>2010-03-08T21:11:23.539Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='NAT'/><category scheme='http://www.blogger.com/atom/ns#' term='Router'/><title type='text'>Basic NAT with Overload</title><content type='html'>In this post I will configure basic NAT with overload to NAT addresses from the 10.0.2.0/24 network (inside) to the outside interface Ethernet 0.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_vZAp7b1QDw8/S5VmclU6kQI/AAAAAAAABlw/1r5pLP9E0zg/s1600-h/ACL+Lab+-+Physical.PNG"&gt;&lt;img style="cursor: pointer; width: 400px; height: 237px;" src="http://4.bp.blogspot.com/_vZAp7b1QDw8/S5VmclU6kQI/AAAAAAAABlw/1r5pLP9E0zg/s400/ACL+Lab+-+Physical.PNG" alt="" id="BLOGGER_PHOTO_ID_5446371965616689410" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I have already configured DHCP to hand out addresses to computers on the 10.0.2.0/24 network.  I have also configured the router to be the DNS server for those computers.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I create a standard access-list defining the addresses I want to NAT.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(config)#&lt;span style="font-weight: bold;"&gt;ip access-list standard NAT&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(config-std-nacl)#&lt;span style="font-weight: bold;"&gt;permit 10.0.2.0 0.0.0.255&lt;/span&gt;   &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(config-std-nacl)#&lt;span style="font-weight: bold;"&gt;end&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I use a show command to view the access-list.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1#&lt;span style="font-weight: bold;"&gt;sh ip access-lists&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Standard IP access list NAT&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    10 permit 10.0.2.0, wildcard bits 0.0.0.255&lt;/span&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;I check my interfaces to make sure I know which I want to name as inside and outside.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(config)#&lt;span style="font-weight: bold;"&gt;do show ip interface brief&lt;/span&gt;   &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Interface                  IP-Address      OK? Method Status                Protocol&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;FastEthernet1              unassigned      YES unset  up                    up      &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;FastEthernet2              unassigned      YES unset  down                  down    &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;FastEthernet3              unassigned      YES unset  down                  down    &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;FastEthernet4              unassigned      YES unset  down                  down    &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Ethernet0                  10.0.1.254      YES NVRAM  up                    up      &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Ethernet1                  10.0.2.254      YES NVRAM  up                    up      &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I name the interfaces Inside and Outside&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(config)#&lt;span style="font-weight: bold;"&gt;interface ethernet 0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(config-if)#&lt;span style="font-weight: bold;"&gt;ip nat outside&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(config-if)#&lt;span style="font-weight: bold;"&gt;exit&lt;/span&gt;   &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(config)#&lt;span style="font-weight: bold;"&gt;interface ethernet 1&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(config-if)#&lt;span style="font-weight: bold;"&gt;ip nat inside&lt;/span&gt;       &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(config-if)#&lt;span style="font-weight: bold;"&gt;exit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I Configue NAT to translate any addresses in the source access-list to the outside interface with overload.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(config)#&lt;span style="font-weight: bold;"&gt;ip nat inside source list NAT interface ethernet 0 overload&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;To test the configuration I connect to a website with a client that is behind the inside interface. Then I check the NAT translations on my router.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1#&lt;span style="font-weight: bold;"&gt;sh ip nat translations&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Pro Inside global         Inside local          Outside local         Outside global&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;udp 10.0.1.254:123        10.0.2.1:123          207.46.232.182:123    207.46.232.182:123&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;tcp 10.0.1.254:1149       10.0.2.1:1149         174.36.30.70:443      174.36.30.70:443&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2076617431778629795-6728854826898107515?l=ciscobasics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/6728854826898107515'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/6728854826898107515'/><link rel='alternate' type='text/html' href='http://ciscobasics.blogspot.com/2010/03/basic-nat-with-overload.html' title='Basic NAT with Overload'/><author><name>SynJunkie</name><uri>http://www.blogger.com/profile/01249134797038027437</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_vZAp7b1QDw8/ScYc8FwNqTI/AAAAAAAABEw/ZFgShqSU9HI/S220/Photo+6.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_vZAp7b1QDw8/S5VmclU6kQI/AAAAAAAABlw/1r5pLP9E0zg/s72-c/ACL+Lab+-+Physical.PNG' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-2076617431778629795.post-1832577965511594921</id><published>2010-03-05T23:40:00.003Z</published><updated>2010-03-05T23:55:53.540Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Router'/><category scheme='http://www.blogger.com/atom/ns#' term='Extended ACL'/><title type='text'>Create a Named Extended ACL</title><content type='html'>In this post I'll be creating a named Access-List which will will block ICMP from R0 to R3. I'll also perform a little troubleshooting and I'll update the ACL.  I'll be using the network shown in the diagram below.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_vZAp7b1QDw8/S5GXWAqasdI/AAAAAAAABlo/PCuccY8jhxc/s1600-h/Screen+shot+2010-03-03+at+21.02.58.PNG"&gt;&lt;img style="cursor: pointer; width: 400px; height: 129px;" src="http://2.bp.blogspot.com/_vZAp7b1QDw8/S5GXWAqasdI/AAAAAAAABlo/PCuccY8jhxc/s400/Screen+shot+2010-03-03+at+21.02.58.PNG" alt="" id="BLOGGER_PHOTO_ID_5445299828858466770" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I start off by checking I can currently Ping R3 from R0.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R0#&lt;span style="font-weight: bold;"&gt;ping r3&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Type escape sequence to abort.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Sending 5, 100-byte ICMP Echos to 192.168.1.58, timeout is 2 seconds:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;!!!!!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 8/12/16 ms&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;On R1 I create the ACL and apply it to the interface nearest to the source.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1(config)#&lt;span style="font-weight: bold;"&gt;ip access-list extended ping_block&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1(config-ext-nacl)#&lt;span style="font-weight: bold;"&gt;deny icmp host 192.168.1.49 192.168.1.58 0.0.0.0 log&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1(config-ext-nacl)#&lt;span style="font-weight: bold;"&gt;permit ip any any log&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1(config-ext-nacl)#&lt;span style="font-weight: bold;"&gt;exit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1(config)#&lt;span style="font-weight: bold;"&gt;int ethernet 0/0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1(config-if)#&lt;span style="font-weight: bold;"&gt;ip access-group block_ping in&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1(config-if)#&lt;span style="font-weight: bold;"&gt;end&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1#&lt;span style="font-weight: bold;"&gt;sh ip access-lists&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Extended IP access list ping_block&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;    10 deny icmp host 192.168.1.49 host 192.168.1.58 log&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;    20 permit ip any any log&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Now I test ping again.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R0#&lt;span style="font-weight: bold;"&gt;ping r3&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Type escape sequence to abort.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Sending 5, 100-byte ICMP Echos to 192.168.1.58, timeout is 2 seconds:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;!!!!!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 4/9/16 ms&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;What went wrong? Lets look at the interface I applied the rule to.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1#sh ip interface ethernet 0/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Ethernet0/0 is up, line protocol is up&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Internet address is 192.168.1.50/30&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Broadcast address is 255.255.255.255&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Address determined by non-volatile memory&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  MTU is 1500 bytes&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Helper address is not set&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Directed broadcast forwarding is disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Multicast reserved groups joined: 224.0.0.9&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Outgoing access list is not set&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  &lt;span style="font-style: italic;"&gt;Inbound  access list is block_ping&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Proxy ARP is enabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Local Proxy ARP is disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Security level is default&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Split horizon is enabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  ICMP redirects are always sent&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  ICMP unreachables are always sent&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  ICMP mask replies are never sent&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  IP fast switching is enabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  IP fast switching on the same interface is disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  IP Flow switching is disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  IP CEF switching is enabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  IP CEF Feature Fast switching turbo vector&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  IP multicast fast switching is enabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  IP multicast distributed fast switching is disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  IP route-cache flags are Fast, CEF&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Router Discovery is disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  IP output packet accounting is disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  IP access violation accounting is disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  TCP/IP header compression is disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  RTP/IP header compression is disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Policy routing is disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Network address translation is disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  BGP Policy Mapping is disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  WCCP Redirect outbound is disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  WCCP Redirect inbound is disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  WCCP Redirect exclude is disabled&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Ah, a typo.  I applied a named access-list to the interface but the name was block_ping not ping_block.  I'll remove it and enter the correct ACL name.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1(config)#&lt;span style="font-weight: bold;"&gt;interface ethernet 0/0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1(config-if)#&lt;span style="font-weight: bold;"&gt;no ip access-group block_ping in&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1(config-if)#&lt;span style="font-weight: bold;"&gt;ip access-group ping_block in&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1(config-if)#&lt;span style="font-weight: bold;"&gt;end&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Now I'll test the ping again.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R0#&lt;span style="font-weight: bold;"&gt;ping r3&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Type escape sequence to abort.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Sending 5, 100-byte ICMP Echos to 192.168.1.58, timeout is 2 seconds:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;U.U.U&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Success rate is 0 percent (0/5)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Great, no response. Can I ping R1 and R2?&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R0#&lt;span style="font-weight: bold;"&gt;ping r1&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Type escape sequence to abort.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Sending 5, 100-byte ICMP Echos to 192.168.1.50, timeout is 2 seconds:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;!!!!!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 4/12/36 ms&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R0#&lt;span style="font-weight: bold;"&gt;ping r2&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Type escape sequence to abort.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Sending 5, 100-byte ICMP Echos to 192.168.1.54, timeout is 2 seconds:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;!!!!!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 8/11/16 ms&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Brilliant.  And on R1 I see the packets hitting the statement and being logged to the screen.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;*Mar  1 00:29:49.719: %SEC-6-IPACCESSLOGDP: list ping_block denied icmp 192.168.1.49 -&gt; 192.168.1.58 (0/0), 1 packet&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1#&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;*Mar  1 00:31:07.123: %SEC-6-IPACCESSLOGDP: list ping_block permitted icmp 192.168.1.49 -&gt; 192.168.1.50 (0/0), 1 packet&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1#&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;*Mar  1 00:31:12.175: %SEC-6-IPACCESSLOGDP: list ping_block permitted icmp 192.168.1.49 -&gt; 192.168.1.54 (0/0), 1 packet&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The benefit of using a named ACL is I can modify the access-list on the fly.  Here I can see each statement is numbered.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R1#&lt;span style="font-weight: bold;"&gt;sh ip access-lists          &lt;/span&gt;&lt;/span&gt; &lt;span style="font-weight: bold;font-family:courier new;" &gt;Extended IP access list ping_block&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;   &lt;br /&gt;10 deny icmp host 192.168.1.49 host 192.168.1.58 log (5 matches)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    20 permit ip any any log (35 matches)&lt;/span&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;Now i'll update the ACL to include a statement to block R0 from pinging R2.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R1(config)#&lt;span style="font-weight: bold;"&gt;ip access-list extended ping_block&lt;/span&gt; &lt;/span&gt; &lt;span style="font-family:courier new;"&gt;&lt;br /&gt;R1(config-ext-nacl)#&lt;span style="font-weight: bold;"&gt;15 deny icmp host 192.168.1.49 host 192.168.1.54 log&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R1#&lt;span style="font-weight: bold;"&gt;sh ip access-lists&lt;/span&gt; &lt;/span&gt; &lt;span style="font-family:courier new;"&gt;&lt;br /&gt;Extended IP access list ping_block&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;   &lt;br /&gt;10 deny icmp host 192.168.1.49 host 192.168.1.58 log (5 matches)&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;   &lt;br /&gt;15 deny icmp host 192.168.1.49 host 192.168.1.54 log&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;   &lt;br /&gt;20 permit ip any any log (51 matches)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Now I test the updated ACL&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0#&lt;span style="font-weight: bold;"&gt;ping r2&lt;/span&gt;&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;&lt;br /&gt;Type escape sequence to abort.&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;&lt;br /&gt;Sending 5, 100-byte ICMP Echos to 192.168.1.54, timeout is 2 seconds:&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;U.U.U&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Success rate is 0 percent (0/5)&lt;/span&gt; &lt;br /&gt;&lt;br /&gt;Brilliant.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2076617431778629795-1832577965511594921?l=ciscobasics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/1832577965511594921'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/1832577965511594921'/><link rel='alternate' type='text/html' href='http://ciscobasics.blogspot.com/2010/03/create-named-extended-acl.html' title='Create a Named Extended ACL'/><author><name>SynJunkie</name><uri>http://www.blogger.com/profile/01249134797038027437</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_vZAp7b1QDw8/ScYc8FwNqTI/AAAAAAAABEw/ZFgShqSU9HI/S220/Photo+6.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_vZAp7b1QDw8/S5GXWAqasdI/AAAAAAAABlo/PCuccY8jhxc/s72-c/Screen+shot+2010-03-03+at+21.02.58.PNG' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-2076617431778629795.post-8468466806364045178</id><published>2010-03-03T21:21:00.005Z</published><updated>2010-03-03T21:36:23.632Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Router'/><category scheme='http://www.blogger.com/atom/ns#' term='Extended ACL'/><title type='text'>Extended ACLs</title><content type='html'>In this post I will create an Extended ACL to block Telnet traffic from the 192.168.1.48/30 network reaching the R3 router.  I'll be working with the network in the diagram below.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_vZAp7b1QDw8/S47Tu47EBcI/AAAAAAAABlg/asrld8ia1ns/s1600-h/Screen+shot+2010-03-03+at+21.02.58.PNG"&gt;&lt;img style="cursor: pointer; width: 400px; height: 129px;" src="http://4.bp.blogspot.com/_vZAp7b1QDw8/S47Tu47EBcI/AAAAAAAABlg/asrld8ia1ns/s400/Screen+shot+2010-03-03+at+21.02.58.PNG" alt="" id="BLOGGER_PHOTO_ID_5444521802045064642" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Unlike Standard ACL's which are placed as near to the destination as possible, Extended ACL's are placed as near to the source as possible, this is to reduce processing on the routers.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1#&lt;span style="font-weight: bold;"&gt;conf t&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Enter configuration commands, one per line.  End with CNTL/Z.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1(config)#&lt;span style="font-weight: bold;"&gt;ip access-list extended 100&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1(config-ext-nacl)#&lt;span style="font-weight: bold;"&gt;deny 192.168.1.48 0.0.0.3 192.168.1.58 0.0.0.0 eq 23 log&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1(config-ext-nacl)#&lt;span style="font-weight: bold;"&gt;permit ip any any log&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1(config-ext-nacl)#&lt;span style="font-weight: bold;"&gt;exit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I have created an access-list to block all the 192.168.1.48/30 subnet from access R3 with Telnet.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1(config-if)#&lt;span style="font-weight: bold;"&gt;ip access-group 100 in&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1(config-if)#&lt;span style="font-weight: bold;"&gt;end&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I have applied the list to interface ethernet 0/0 on R1&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1#&lt;span style="font-weight: bold;"&gt;sh ip inter ethernet 0/0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Ethernet0/0 is up, line protocol is up&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Internet address is 192.168.1.50/30&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Broadcast address is 255.255.255.255&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Address determined by non-volatile memory&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  MTU is 1500 bytes&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Helper address is not set&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Directed broadcast forwarding is disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Multicast reserved groups joined: 224.0.0.9&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Outgoing access list is not set&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Inbound  access list is 100&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Proxy ARP is enabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Local Proxy ARP is disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Security level is default&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Split horizon is enabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  ICMP redirects are always sent&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  ICMP unreachables are always sent&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  ICMP mask replies are never sent&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  IP fast switching is enabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  IP fast switching on the same interface is disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  IP Flow switching is disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  IP CEF switching is enabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  IP CEF Feature Fast switching turbo vector&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  IP multicast fast switching is enabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;I test that I can telnet to R3 from R1.&lt;span style="font-family: courier new;"&gt;          &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1#&lt;span style="font-weight: bold;"&gt;telnet 192.168.1.58&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Trying 192.168.1.58 ... Open&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;User Access Verification&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Password: &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Last login: Wed Mar  3 21:06:01 on ttys001&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Now on R0 I attempt to telnet  to R3&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new; font-weight: bold;"&gt;R0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R0#&lt;span style="font-weight: bold;"&gt;telnet 192.168.1.58&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Trying 192.168.1.58 ... &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;% Destination unreachable; gateway or host down&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R0#&lt;span style="font-weight: bold;"&gt;ping 192.168.1.58&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Type escape sequence to abort.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Sending 5, 100-byte ICMP Echos to 192.168.1.58, timeout is 2 seconds:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;!!!!!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 8/11/16 ms&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;My telnet fails but ping works just fine.  I check R1 to see the statement being hit.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new; font-weight: bold;"&gt;R1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;*Mar  1 00:10:52.315: %SEC-6-IPACCESSLOGP: list 100 denied tcp 192.168.1.49(22404) -&gt; 192.168.1.58(23), 1 packet &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1#&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;*Mar  1 00:11:02.615: %SEC-6-IPACCESSLOGDP: list 100 permitted icmp 192.168.1.49 -&gt; 192.168.1.58 (8/0), 1 packet &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1#&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2076617431778629795-8468466806364045178?l=ciscobasics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/8468466806364045178'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/8468466806364045178'/><link rel='alternate' type='text/html' href='http://ciscobasics.blogspot.com/2010/03/extended-acls.html' title='Extended ACLs'/><author><name>SynJunkie</name><uri>http://www.blogger.com/profile/01249134797038027437</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_vZAp7b1QDw8/ScYc8FwNqTI/AAAAAAAABEw/ZFgShqSU9HI/S220/Photo+6.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_vZAp7b1QDw8/S47Tu47EBcI/AAAAAAAABlg/asrld8ia1ns/s72-c/Screen+shot+2010-03-03+at+21.02.58.PNG' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-2076617431778629795.post-5172311928959116563</id><published>2010-03-02T23:18:00.006Z</published><updated>2010-03-02T23:41:16.719Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Standard ACL'/><category scheme='http://www.blogger.com/atom/ns#' term='Router'/><title type='text'>Standard ACL's</title><content type='html'>In this post I will be  creating a standard access-list to prevent traffic from R0 reaching from reaching the R3 router.&lt;br /&gt;&lt;br /&gt;I'll be using the diagram below for my network layout.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_vZAp7b1QDw8/S42c-YmSKHI/AAAAAAAABko/OSGN3RwZH8Y/s1600-h/Screen+shot+2010-03-02+at+22.37.25.PNG"&gt;&lt;img style="cursor: pointer; width: 400px; height: 144px;" src="http://3.bp.blogspot.com/_vZAp7b1QDw8/S42c-YmSKHI/AAAAAAAABko/OSGN3RwZH8Y/s400/Screen+shot+2010-03-02+at+22.37.25.PNG" alt="" id="BLOGGER_PHOTO_ID_5444180120129644658" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;As Standard ACL's can only filter based on the source address they should be placed as near to the destination as possible.  Standard access-lists can be numbered from 1-99 or 1300-1999 (expanded range). Standard access-lists can also be named.  In this post I'll be using a numbered Standard ACL.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I begin by verifying connectivity before the rule is created.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0#&lt;span style="font-weight: bold;"&gt;ping r3&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Type escape sequence to abort.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Sending 5, 100-byte ICMP Echos to 192.168.1.58, timeout is 2 seconds:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!!!!!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 4/8/16 ms&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Next I create the standard access-list&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R1#&lt;span style="font-weight: bold;"&gt;conf t&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Enter configuration commands, one per line.  End with CNTL/Z.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R1(config)#&lt;span style="font-weight: bold;"&gt;ip access-list standard 1&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R1(config-std-nacl)#&lt;span style="font-weight: bold;"&gt;deny host 192.168.1.49 log&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R1(config-std-nacl)#&lt;span style="font-weight: bold;"&gt;permit any log&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R1(config-std-nacl)#&lt;span style="font-weight: bold;"&gt;exit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;I have enabled logging so I can see as each statement is hit.  There is an implicit deny all statement so none is required in the access-list itself.&lt;br /&gt;&lt;br /&gt;I place the access-list as near to the destination as possible.  In  this case it will be on e0/2 on R1, and it will be outgoing.  Placing  the list any nearer to R0 would affect traffic to R2.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R1(config)#&lt;span style="font-weight: bold;"&gt;int&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R1(config)#&lt;span style="font-weight: bold;"&gt;interface ethernet 0/2&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R1(config-if)#&lt;span style="font-weight: bold;"&gt;ip access-group 1 out&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R1(config-if)#&lt;span style="font-weight: bold;"&gt;end&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I can check the ACL with a show command.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R1#&lt;span style="font-weight: bold;"&gt;sh ip access-lists 1&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Standard IP access list 1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    10 deny   192.168.1.49 log (0 matches)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    20 permit any log (0 matches)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I can also check which interface the rule is applied to.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R1#&lt;span style="font-weight: bold;"&gt;sh ip interface ethernet 0/2&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Ethernet0/2 is up, line protocol is up&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Internet address is 192.168.1.57/30&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Broadcast address is 255.255.255.255&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Address determined by non-volatile memory&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  MTU is 1500 bytes&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Helper address is not set&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Directed broadcast forwarding is disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Multicast reserved groups joined: 224.0.0.9&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  &lt;span style="font-style: italic;"&gt;Outgoing access list is 1&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Inbound  access list is not set&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Proxy ARP is enabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Local Proxy ARP is disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Security level is default&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Split horizon is enabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  ICMP redirects are always sent&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  ICMP unreachables are always sent&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  ICMP mask replies are never sent&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  IP fast switching is enabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  IP fast switching on the same interface is disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  IP Flow switching is disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  IP CEF switching is enabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  IP CEF Feature Fast switching turbo vector&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  IP multicast fast switching is enabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  IP multicast distributed fast switching is disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  IP route-cache flags are Fast, CEF&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Router Discovery is disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  IP output packet accounting is disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  IP access violation accounting is disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  TCP/IP header compression is disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  RTP/IP header compression is disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Policy routing is disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Network address translation is disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  BGP Policy Mapping is disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  WCCP Redirect outbound is disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  WCCP Redirect inbound is disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  WCCP Redirect exclude is disabled&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;From the output above I can see that the ACL is applied to the right interface in the right direction.  Only one access-list can be applied per interface per direction.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Now I check my pings fail to reach R3 from R0&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0#ping r3&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Type escape sequence to abort.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Sending 5, 100-byte ICMP Echos to 192.168.1.58, timeout is 2 seconds:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;U.U.U&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Success rate is 0 percent (0/5)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Back on R1 I can see the deny statement has been hit.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;*Mar  1 00:33:33.783: %SEC-6-IPACCESSLOGNP: list 1 denied 0 192.168.1.49 -&gt; 192.168.1.58, 1 packet&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;To verify that my traffic can still hit R2 I attempt to ping it from R0.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0#&lt;span style="font-weight: bold;"&gt;ping r2&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Type escape sequence to abort.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Sending 5, 100-byte ICMP Echos to 192.168.1.54, timeout is 2 seconds:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!!!!!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 4/12/24 ms&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R2&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;I can also check that traffic from R2 can reach R3.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R2#&lt;span style="font-weight: bold;"&gt;ping r3&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Type escape sequence to abort.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Sending 5, 100-byte ICMP Echos to 192.168.1.58, timeout is 2 seconds:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!!!!!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 8/8/12 ms&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;This can be seen hitting the permit statement in the access-list.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;*Mar  1 00:42:00.419: %SEC-6-IPACCESSLOGNP: list 1 permitted 0 192.168.1.54 -&gt; 192.168.1.58, 1 packet&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Checking the access-list again I can see a number of hits.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R1#&lt;span style="font-weight: bold;"&gt;sh ip access-lists 1&lt;/span&gt;       &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Standard IP access list 1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    10 deny   192.168.1.49 log (5 matches)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    20 permit any log (5 matches)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;As R3 is receiving its route updates from R1 it will still know about R0 and how to find it.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R3&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R3#&lt;span style="font-weight: bold;"&gt;sh ip route&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Codes: C - connected, S - static, R - RIP, M - mobile, B - BGP&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       E1 - OSPF external type 1, E2 - OSPF external type 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       ia - IS-IS inter area, * - candidate default, U - per-user static route&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       o - ODR, P - periodic downloaded static route&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Gateway of last resort is not set&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;     192.168.1.0/24 is variably subnetted, 6 subnets, 2 masks&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;C       192.168.1.32/28 is directly connected, Ethernet0/1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;C       192.168.1.56/30 is directly connected, Ethernet0/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R       192.168.1.48/30 [120/1] via 192.168.1.57, 00:00:15, Ethernet0/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R       192.168.1.52/30 [120/1] via 192.168.1.57, 00:00:15, Ethernet0/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R       192.168.1.0/28 [120/2] via 192.168.1.57, 00:00:15, Ethernet0/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R       192.168.1.16/28 [120/2] via 192.168.1.57, 00:00:15, Ethernet0/0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;However, R3 cannot recieving ping responses from R0 because the echo replies will be blocked by the access-list.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R3#&lt;span style="font-weight: bold;"&gt;ping r0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Type escape sequence to abort.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Sending 5, 100-byte ICMP Echos to 192.168.1.49, timeout is 2 seconds:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;.....&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Success rate is 0 percent (0/5)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Using a debug command on R0 I can see the pings hit the router but they cannot get back.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0#&lt;span style="font-weight: bold;"&gt;debug ip icmp&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;ICMP packet debugging is on&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0#&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;*Mar  1 00:56:11.823: ICMP: echo reply sent, src 192.168.1.49, dst 192.168.1.58&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;*Mar  1 00:56:11.835: ICMP: dst (192.168.1.49) administratively prohibited unreachable rcv from 192.168.1.50&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;I finish up by removing the ACL from the interface and the router.&lt;span style="font-family:courier new;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R1&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;br /&gt;&lt;br /&gt;R1(config)#&lt;span style="font-weight: bold;"&gt;interface ethernet 0/2&lt;/span&gt;&lt;br /&gt;R1(config-if)#&lt;span style="font-weight: bold;"&gt;no ip access-group 1 out &lt;/span&gt;&lt;br /&gt;R1(config-if)#&lt;span style="font-weight: bold;"&gt;exit&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;R1(config)#&lt;span style="font-weight: bold;"&gt;no access-list 1&lt;/span&gt;&lt;br /&gt;R1(config)#&lt;span style="font-weight: bold;"&gt;end&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2076617431778629795-5172311928959116563?l=ciscobasics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/5172311928959116563'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/5172311928959116563'/><link rel='alternate' type='text/html' href='http://ciscobasics.blogspot.com/2010/03/standard-acls.html' title='Standard ACL&apos;s'/><author><name>SynJunkie</name><uri>http://www.blogger.com/profile/01249134797038027437</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_vZAp7b1QDw8/ScYc8FwNqTI/AAAAAAAABEw/ZFgShqSU9HI/S220/Photo+6.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_vZAp7b1QDw8/S42c-YmSKHI/AAAAAAAABko/OSGN3RwZH8Y/s72-c/Screen+shot+2010-03-02+at+22.37.25.PNG' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-2076617431778629795.post-312231241655430068</id><published>2010-02-27T22:41:00.005Z</published><updated>2010-02-27T23:51:22.125Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Router'/><category scheme='http://www.blogger.com/atom/ns#' term='VLAN'/><category scheme='http://www.blogger.com/atom/ns#' term='Switch'/><title type='text'>Configure a Router on a Stick</title><content type='html'>In this post I will configure a router to route traffic between VLANs using just one router interface, this is commonly referred to as a Router on a Stick.&lt;br /&gt;&lt;br /&gt;Below is a diagram of the network I'll be working with in this post.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_vZAp7b1QDw8/S4mgVOkrQhI/AAAAAAAABkg/0AEz9rVK4So/s1600-h/Router+on+a+stick.png"&gt;&lt;img style="cursor: pointer; width: 400px; height: 304px;" src="http://3.bp.blogspot.com/_vZAp7b1QDw8/S4mgVOkrQhI/AAAAAAAABkg/0AEz9rVK4So/s400/Router+on+a+stick.png" alt="" id="BLOGGER_PHOTO_ID_5443057911203578386" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;My goal is for UserA in VLAN 64 to communicate with UserB in VLAN 128.  To do this my router and switch must use a fastethernet port running at 100Mb full duplex.&lt;br /&gt;&lt;br /&gt;To begin with I will configure the ports on Switch1 to be in the correct VLANs. These commands will also create the VLANs because the don't already exist.  I have named the VLANs to be the same as the networks to keep things simple.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Switch1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;conf t&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Enter configuration commands, one per line.  End with CNTL/Z.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;interface range fastEthernet 0/9 - 16&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config-if-range)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;switchport access vlan 64&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;% Access VLAN does not exist. Creating vlan 64&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config-if-range)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;exit&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;interface range fastEthernet 0/17 - 23&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config-if-range)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;switchport access vlan 128&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;% Access VLAN does not exist. Creating vlan 128&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config-if-range)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;end&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I have now created the VLANs and I check this with a show command.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1#&lt;span style="font-weight: bold;"&gt;sh vlan brief &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;VLAN Name                             Status    Ports&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;---- -------------------------------- --------- -------------------------------&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;1    default                          active    Fa0/2, Fa0/3, Fa0/4, Fa0/5, Fa0/6, Fa0/7, Fa0/8&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;2    dmz                              active    &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;64   VLAN0064                         active    Fa0/9, Fa0/10, Fa0/11, Fa0/12, Fa0/13, Fa0/14, Fa0/15, Fa0/16&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;128  VLAN0128                         active    Fa0/17, Fa0/18, Fa0/19, Fa0/20, Fa0/21, Fa0/22, Fa0/23&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;1002 fddi-default                     active    &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;1003 token-ring-default               active    &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;1004 fddinet-default                  active    &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;1005 trnet-default                    active&lt;/span&gt;  &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;On switch2 I configure the port that will be connected to the router as a trunk port.  I also configure the port to be fixed at 100Mb full duplex.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Switch2&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2#&lt;span style="font-weight: bold;"&gt;conf t&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Enter configuration commands, one per line.  End with CNTL/Z.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2(config)#&lt;span style="font-weight: bold;"&gt;interface fastEthernet 0/2&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2(config-if)#&lt;span style="font-weight: bold;"&gt;speed 100&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2(config-if)#&lt;span style="font-weight: bold;"&gt;duplex full&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2(config-if)#&lt;span style="font-weight: bold;"&gt;switchport mode trunk&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2(config-if)#&lt;span style="font-weight: bold;"&gt;end&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I check the configuration using a show command.  This tells me which interfaces are trunking and for which VLANs.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2#&lt;span style="font-weight: bold;"&gt;sh interfaces trunk&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Port        Mode         Encapsulation  Status        Native vlan&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Fa0/2       on           802.1q         trunking      1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Po5         desirable    802.1q         trunking      1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Port      Vlans allowed on trunk&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Fa0/2       1-4094&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Po5         1-4094&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Port        Vlans allowed and active in management domain&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Fa0/2       1-2,64,128&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Po5         1-2,64,128&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Port        Vlans in spanning tree forwarding state and not pruned&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Fa0/2       1-2,64,128&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Po5         1-2,64,128&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;On Router2 I create 2 sub-interfaces off the FastEthernet interface (fa0).  I name these the same as the VLANs, again to keep thing simple.  I also configure the sub-interfaces to support dot1q trunking.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Router2&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router2#&lt;span style="font-weight: bold;"&gt;conf t&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Enter configuration commands, one per line.  End with CNTL/Z.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router2(config)#&lt;span style="font-weight: bold;"&gt;interface fastEthernet 0.64&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router2(config-subif)#&lt;span style="font-weight: bold;"&gt;encapsulation dot1Q 64&lt;/span&gt;      &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router2(config-subif)#&lt;span style="font-weight: bold;"&gt;ip address 192.168.1.62 2 55.255.255.192&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router2(config-subif)#&lt;span style="font-weight: bold;"&gt;no shut&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router2(config-subif)#&lt;span style="font-weight: bold;"&gt;exit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router2(config)#&lt;span style="font-weight: bold;"&gt;interface fastEthernet 0.128&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router2(config-subif)#&lt;span style="font-weight: bold;"&gt;encapsulation dot1Q 128&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router2(config-subif)#&lt;span style="font-weight: bold;"&gt;ip address 192.168.1.190 2 55.255.255.192&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router2(config-subif)#&lt;span style="font-weight: bold;"&gt;no shut&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Router2(config-subif)#&lt;span style="font-weight: bold;"&gt;exit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Once the hosts are configured with valid IP addresses and subnet masks (as shown in the diagram) they are given the default gateway of the IP address that the sub-interface was configured with.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;UserA&lt;/span&gt;&lt;br /&gt;IP Address - 192.168.1.65&lt;br /&gt;Subnet Mask - 255.255.255.192&lt;br /&gt;Default Gateway - 192.168.1.126&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;UserB&lt;/span&gt;&lt;br /&gt;IP Address - 192.168.1.129&lt;br /&gt;Subnet Mask - 255.255.255.192&lt;br /&gt;Default Gateway - 192.168.1.190&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Now I will be able communicate between the hosts in the 2 VLANs.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2076617431778629795-312231241655430068?l=ciscobasics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/312231241655430068'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/312231241655430068'/><link rel='alternate' type='text/html' href='http://ciscobasics.blogspot.com/2010/02/configure-router-on-stick.html' title='Configure a Router on a Stick'/><author><name>SynJunkie</name><uri>http://www.blogger.com/profile/01249134797038027437</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_vZAp7b1QDw8/ScYc8FwNqTI/AAAAAAAABEw/ZFgShqSU9HI/S220/Photo+6.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_vZAp7b1QDw8/S4mgVOkrQhI/AAAAAAAABkg/0AEz9rVK4So/s72-c/Router+on+a+stick.png' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-2076617431778629795.post-3470675213197644631</id><published>2010-02-26T13:25:00.003Z</published><updated>2010-02-26T14:26:57.587Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='EIGRP'/><category scheme='http://www.blogger.com/atom/ns#' term='Router'/><title type='text'>Configuring EIGRP</title><content type='html'>In this post I will configure the network in the diagram below to use EIGRP as its routing protocol.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_vZAp7b1QDw8/S4fMvShfcfI/AAAAAAAABkY/jpEs5HHkfLs/s1600-h/VLSM+Lab+-+GNS3+Layout.PNG"&gt;&lt;img style="cursor: pointer; width: 400px; height: 286px;" src="http://2.bp.blogspot.com/_vZAp7b1QDw8/S4fMvShfcfI/AAAAAAAABkY/jpEs5HHkfLs/s400/VLSM+Lab+-+GNS3+Layout.PNG" alt="" id="BLOGGER_PHOTO_ID_5442543787498762738" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Before I get into the config I'll just mention that EIGRP is a Cisco proprietary hybrid routing protocol. It has all the features of OSPF but can be easily set up like RIP.  The downside is that it can only run on Cisco routers.  With that said, lets get on with the fun stuff.&lt;br /&gt;&lt;br /&gt;I have subnetted the 192.168.1.0 network using VLSM to cater or networks of the following sizes:&lt;br /&gt;&lt;br /&gt;192.168.1.0 - 60 Hosts&lt;br /&gt;192.168.1.64 - 40 Hosts&lt;br /&gt;192.168.1.128 - 30 Hosts&lt;br /&gt;192.168.1.160 - 25 Hosts&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;First I configure EIGRP on R1 on just one interface (linked to R2).&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1#&lt;span style="font-weight: bold;"&gt;conf t&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Enter configuration commands, one per line.  End with CNTL/Z.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1(config)#&lt;span style="font-weight: bold;"&gt;router eigrp 10 &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1(config-router)#&lt;span style="font-weight: bold;"&gt;network 192.168.1.193 0.0.0.0&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1(config-router)#&lt;span style="font-weight: bold;"&gt;no auto-summary &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1(config-router)#&lt;span style="font-weight: bold;"&gt;end&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I have used 10 as the AS for EIGRP, this must be the same for all the routers. I have turned off auto-summary so I can have better control of summarisation.  I use some show commands to check its running on just the specified interface.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1#&lt;span style="font-weight: bold;"&gt;sh ip eigrp interfaces &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;IP-EIGRP interfaces for process 10&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;                        Xmit Queue   Mean   Pacing Time   Multicast    Pending&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Interface        Peers  Un/Reliable  SRTT   Un/Reliable   Flow Timer   Routes&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Et0/0              0        0/0         0       0/1            0           0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt; &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;I can also see that there are currently no neighbors.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1#&lt;span style="font-weight: bold;"&gt;sh ip eigrp neighbors&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;IP-EIGRP neighbors for process 10&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I now enable EIGRP on R2 and I see the adjacency form.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R2&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R2#&lt;/span&gt;&lt;span style="font-weight: bold; font-family: courier new;"&gt;conf t&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Enter configuration commands, one per line.  End with CNTL/Z.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R2(config)#&lt;span style="font-weight: bold;"&gt;router eigrp 10 &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R2(config-router)#&lt;/span&gt;&lt;span style="font-weight: bold; font-family: courier new;"&gt;network 192.168.1.194 0.0.0.0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R2(config-router)#&lt;/span&gt;&lt;span style="font-weight: bold; font-family: courier new;"&gt;network  192.168.1.197 0.0.0.0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R2(config-router)#&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;*Mar  1 00:42:40.399: %DUAL-5-NBRCHANGE: IP-EIGRP(0) 10: Neighbor 192.168.1.193 (Ethernet0/3) is up: new adjacency&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Back on R1 i check the neighbor table.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1#&lt;/span&gt;&lt;span style="font-weight: bold; font-family: courier new;"&gt;sh ip eigrp neighbors&lt;/span&gt;&lt;span style="font-family: courier new;"&gt;        &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;IP-EIGRP neighbors for process 10&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;H   Address                 Interface       Hold Uptime   SRTT   RTO  Q  Seq&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;                                            (sec)         (ms)       Cnt Num&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;0   192.168.1.194           Et0/0             12 00:00:39   13   200  0  3&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Checking the route table on R1 i can also see the EIGRP route.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1#&lt;span style="font-weight: bold;"&gt;sh ip route&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Codes: C - connected, S - static, R - RIP, M - mobile, B - BGP&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;       D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;       N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;       E1 - OSPF external type 1, E2 - OSPF external type 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;       i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;       ia - IS-IS inter area, * - candidate default, U - per-user static route&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;       o - ODR, P - periodic downloaded static route&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Gateway of last resort is not set&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;     192.168.1.0/30 is subnetted, 3 subnets&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;C       192.168.1.204 is directly connected, Ethernet0/1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;C       192.168.1.192 is directly connected, Ethernet0/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;D       192.168.1.196 [90/307200] via 192.168.1.194, 00:04:36, Ethernet0/0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;On R4 I enable EIGRP.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R4&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R4#&lt;/span&gt;&lt;span style="font-weight: bold; font-family: courier new;"&gt;conf t&lt;/span&gt;&lt;br /&gt; &lt;span style="font-family: courier new;"&gt;Enter configuration commands,  one per line.  End with CNTL/Z.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R4(config)#&lt;span style="font-weight: bold;"&gt;router eigrp 10 &lt;/span&gt;&lt;/span&gt;&lt;br /&gt; &lt;span style="font-family: courier new;"&gt;R4(config-router)#&lt;/span&gt;&lt;span style="font-weight: bold; font-family: courier new;"&gt;network  192.168.1.198 0.0.0.0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R4(config-router)#&lt;/span&gt;&lt;span style="font-weight: bold; font-family: courier new;"&gt;network  192.168.1.202 0.0.0.0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;And on R3 I enable EIGRP.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R3#&lt;/span&gt;&lt;span style="font-weight: bold; font-family: courier new;"&gt;conf t&lt;/span&gt;&lt;br /&gt; &lt;span style="font-family: courier new;"&gt;Enter configuration commands,  one per line.  End with CNTL/Z.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R3(config)#&lt;span style="font-weight: bold;"&gt;router eigrp 10 &lt;/span&gt;&lt;/span&gt;&lt;br /&gt; &lt;span style="font-family: courier new;"&gt;R3(config-router)#&lt;/span&gt;&lt;span style="font-weight: bold; font-family: courier new;"&gt;network  192.168.1.201 0.0.0.0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R3(config-router)#&lt;/span&gt;&lt;span style="font-weight: bold; font-family: courier new;"&gt;network  192.168.1.206 0.0.0.0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R3(config-router)#&lt;/span&gt;&lt;span style="font-weight: bold; font-family: courier new;"&gt;network  192.168.1.161 0.0.0.0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;From R3 I check the routing table and I can see routes to the all the other networks I have configured so far.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R3#&lt;span style="font-weight: bold;"&gt;sh ip route&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Codes: C - connected, S - static, R - RIP, M - mobile, B - BGP&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;       D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;       N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;       E1 - OSPF external type 1, E2 - OSPF external type 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;       i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;       ia - IS-IS inter area, * - candidate default, U - per-user static route&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;       o - ODR, P - periodic downloaded static route&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Gateway of last resort is not set&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;     192.168.1.0/24 is variably subnetted, 5 subnets, 2 masks&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;C       192.168.1.200/30 is directly connected, Ethernet0/1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;C       192.168.1.204/30 is directly connected, Ethernet0/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;D       192.168.1.192/30 [90/332800] via 192.168.1.202, 00:00:09, Ethernet0/1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;D       192.168.1.196/30 [90/307200] via 192.168.1.202, 00:00:09, Ethernet0/1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;C       192.168.1.160/27 is directly connected, Ethernet0/2&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;What is missing from my routing table is routes for all the networks hanging off R2.  This is because I  used the wildcard mask of 0.0.0.0 to specify that EIGRP only ran on certain interfaces.  To enable EIGRP for all networks on R2 I will add a new network with no wildcard mask.  This is similar to commands used when setting up RIP.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R2&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R2#&lt;/span&gt;&lt;span style="font-weight: bold; font-family: courier new;"&gt;conf t&lt;/span&gt;&lt;br /&gt; &lt;span style="font-family: courier new;"&gt;Enter configuration commands,  one per line.  End with CNTL/Z.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R2(config)#&lt;span style="font-weight: bold;"&gt;router eigrp 10 &lt;/span&gt;&lt;/span&gt;&lt;br /&gt; &lt;span style="font-family: courier new;"&gt;R2(config-router)#&lt;/span&gt;&lt;span style="font-weight: bold; font-family: courier new;"&gt;network  192.168.1.0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Now when I check the routing table on R3 i can see all the new networks attached to R2.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R3&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R3#&lt;span style="font-weight: bold;"&gt;sh ip route&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Codes: C - connected, S - static, R - RIP, M - mobile, B - BGP&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;       D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;       N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;       E1 - OSPF external type 1, E2 - OSPF external type 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;       i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;       ia - IS-IS inter area, * - candidate default, U - per-user static route&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;       o - ODR, P - periodic downloaded static route&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Gateway of last resort is not set&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;     192.168.1.0/24 is variably subnetted, 8 subnets, 3 masks&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;D       192.168.1.64/26 [90/332800] via 192.168.1.202, 00:02:14, Ethernet0/1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;D       192.168.1.0/26 [90/332800] via 192.168.1.202, 00:02:14, Ethernet0/1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;C       192.168.1.200/30 is directly connected, Ethernet0/1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;C       192.168.1.204/30 is directly connected, Ethernet0/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;D       192.168.1.192/30 [90/332800] via 192.168.1.202, 00:04:25, Ethernet0/1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;D       192.168.1.196/30 [90/307200] via 192.168.1.202, 00:04:25, Ethernet0/1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;C       192.168.1.160/27 is directly connected, Ethernet0/2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;D       192.168.1.128/27 [90/332800] via 192.168.1.202, 00:02:14, Ethernet0/1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Now I can see all the networks.&lt;br /&gt;&lt;br /&gt;I want to test my reliance between R3 and R2.  To do this I will test connectivity and then shut down an interface on R4.  Hopefully routing will continue.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R3&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R3#&lt;span style="font-weight: bold;"&gt;ping r2&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Type escape sequence to abort.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Sending 5, 100-byte ICMP Echos to 192.168.1.197, timeout is 2 seconds:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;!!!!!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 4/9/16 ms&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;R3 can ping R2 successfully. Now I shutdown R4's interface.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R4&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R4(config)#&lt;span style="font-weight: bold;"&gt;int ethernet 0/0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R4(config-if)#&lt;span style="font-weight: bold;"&gt;shut&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R3&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R3#&lt;span style="font-weight: bold;"&gt;ping r2&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Type escape sequence to abort.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Sending 5, 100-byte ICMP Echos to 192.168.1.197, timeout is 2 seconds:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;..&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;*Mar  1 01:16:28.347: %DUAL-5-NBRCHANGE: IP-EIGRP(0) 10: Neighbor 192.168.1.202 (Ethernet0/1) is down: holding time expired...&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Success rate is 0 percent (0/5)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Pings fail!  I check R1 and find that it is only routing for network 192.168.1.192 (on interface 192.168.1.193).&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1#&lt;span style="font-weight: bold;"&gt;sh ip protocols &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Routing Protocol is "eigrp 10"&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Outgoing update filter list for all interfaces is not set&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Incoming update filter list for all interfaces is not set&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Default networks flagged in outgoing updates&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Default networks accepted from incoming updates&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  EIGRP metric weight K1=1, K2=0, K3=1, K4=0, K5=0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  EIGRP maximum hopcount 100&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  EIGRP maximum metric variance 1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Redistributing: eigrp 10&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  EIGRP NSF-aware route hold timer is 240s&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Automatic network summarization is not in effect&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Maximum path: 4&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Routing for Networks:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;    192.168.1.193/32&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Routing Information Sources:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;    Gateway         Distance      Last Update&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;    192.168.1.194         90      00:01:37&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;  Distance: internal 90 external 170&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I add the other interface into EIGRP for AS 10.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1#&lt;span style="font-weight: bold;"&gt;conf t&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Enter configuration commands, one per line.  End with CNTL/Z.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1(config)#&lt;span style="font-weight: bold;"&gt;router eigrp 10&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R1(config-router)#&lt;span style="font-weight: bold;"&gt;network 192.168.1.205 0.0.0.0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Back on R3 I attempt to contact R2 again.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;R3&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R3#&lt;span style="font-weight: bold;"&gt;ping r2&lt;/span&gt;    &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Type escape sequence to abort.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Sending 5, 100-byte ICMP Echos to 192.168.1.197, timeout is 2 seconds:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;!!!!!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 4/9/12 ms&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;And looking at my routing table I can see that the next hop to get to R2 is R1 whereas before it was R4&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;R3#&lt;span style="font-weight: bold;"&gt;sh ip route&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Codes: C - connected, S - static, R - RIP, M - mobile, B - BGP&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;       D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;       N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;       E1 - OSPF external type 1, E2 - OSPF external type 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;       i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;       ia - IS-IS inter area, * - candidate default, U - per-user static route&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;       o - ODR, P - periodic downloaded static route&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Gateway of last resort is not set&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;     192.168.1.0/24 is variably subnetted, 8 subnets, 3 masks&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;D       192.168.1.64/26 [90/332800] via 192.168.1.205, 00:01:22, Ethernet0/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;D       192.168.1.0/26 [90/332800] via 192.168.1.205, 00:01:22, Ethernet0/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;C       192.168.1.200/30 is directly connected, Ethernet0/1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;C       192.168.1.204/30 is directly connected, Ethernet0/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;D       192.168.1.192/30 [90/307200] via 192.168.1.205, 00:01:22, Ethernet0/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;D       192.168.1.196/30 [90/332800] via 192.168.1.205, 00:01:22, Ethernet0/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;C       192.168.1.160/27 is directly connected, Ethernet0/2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;D       192.168.1.128/27 [90/332800] via 192.168.1.205, 00:01:22, Ethernet0/0&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2076617431778629795-3470675213197644631?l=ciscobasics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/3470675213197644631'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/3470675213197644631'/><link rel='alternate' type='text/html' href='http://ciscobasics.blogspot.com/2010/02/configuring-eigrp.html' title='Configuring EIGRP'/><author><name>SynJunkie</name><uri>http://www.blogger.com/profile/01249134797038027437</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_vZAp7b1QDw8/ScYc8FwNqTI/AAAAAAAABEw/ZFgShqSU9HI/S220/Photo+6.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_vZAp7b1QDw8/S4fMvShfcfI/AAAAAAAABkY/jpEs5HHkfLs/s72-c/VLSM+Lab+-+GNS3+Layout.PNG' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-2076617431778629795.post-3718883124102502629</id><published>2010-02-22T22:07:00.006Z</published><updated>2010-02-24T22:16:07.433Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='OSPF'/><category scheme='http://www.blogger.com/atom/ns#' term='Router'/><title type='text'>Configure OSPF Routing</title><content type='html'>In this post I will configure the network below to use OSPF routing.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_vZAp7b1QDw8/S4MA3X7xS2I/AAAAAAAABiI/UAPPzBmKbQs/s1600-h/Screen+shot+2010-02-22+at+22.10.07.PNG"&gt;&lt;img style="cursor: pointer; width: 400px; height: 72px;" src="http://4.bp.blogspot.com/_vZAp7b1QDw8/S4MA3X7xS2I/AAAAAAAABiI/UAPPzBmKbQs/s400/Screen+shot+2010-02-22+at+22.10.07.PNG" alt="" id="BLOGGER_PHOTO_ID_5441193726111206242" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;OSPF uses areas to define it's structure, i'll be configuring a single area in this post so I will use area 0.  OSPF runs under a process on each router, this does not have to be the same but i'll keep thing simple and use process 10 on each router.&lt;br /&gt;&lt;br /&gt;Currently all routers can only see directly connected routers. Here is the routing table on R0.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;sh ip route&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Codes: C - connected, S - static, R - RIP, M - mobile, B - BGP&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       E1 - OSPF external type 1, E2 - OSPF external type 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       ia - IS-IS inter area, * - candidate default, U - per-user static route&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       o - ODR, P - periodic downloaded static route&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Gateway of last resort is 0.0.0.0 to network 0.0.0.0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;     195.211.64.0/30 is subnetted, 1 subnets&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;C       195.211.64.0 is directly connected, Serial1/1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;C    192.168.1.0/24 is directly connected, Serial1/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;S*   0.0.0.0/0 is directly connected, Serial1/1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I enable OSPF and configure it to advertise the 192.168.1.0 network.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0#&lt;span style="font-weight: bold;"&gt;conf t &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Enter configuration commands, one per line.  End with CNTL/Z.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0(config)#&lt;span style="font-weight: bold;"&gt;router ospf 10&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0(config-router)#&lt;span style="font-weight: bold;"&gt;network 192.168.1.1 0.0.0.0 area 0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0(config-router)#&lt;span style="font-weight: bold;"&gt;end &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;By specifying the interface with a  wilcard of 0.0.0.0 I am telling OSPF to only advertise out of that single interface.&lt;br /&gt;&lt;br /&gt;I configure OSPF on R1, R2 and R3 for the networks they are connected to.  After configuration I check routing tables.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;sh ip route&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Codes: C - connected, S - static, R - RIP, M - mobile, B - BGP&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       E1 - OSPF external type 1, E2 - OSPF external type 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       ia - IS-IS inter area, * - candidate default, U - per-user static route&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       o - ODR, P - periodic downloaded static route&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Gateway of last resort is 0.0.0.0 to network 0.0.0.0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;     192.168.4.0/32 is subnetted, 1 subnets&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;O       192.168.4.1 [110/85] via 192.168.1.2, 00:00:56, Serial1/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;     195.211.64.0/30 is subnetted, 1 subnets&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;C       195.211.64.0 is directly connected, Serial1/1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;C    192.168.1.0/24 is directly connected, Serial1/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;O    192.168.2.0/24 [110/74] via 192.168.1.2, 00:00:56, Serial1/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;O    192.168.3.0/24 [110/84] via 192.168.1.2, 00:00:56, Serial1/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;S*   0.0.0.0/0 is directly connected, Serial1/1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;So on each router I have advertised each interface into the OSPF area.  Now I would like to advertise the default route and check it on R3.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;I first configure a static route pointing towards the interface I want traffic to go and then I advertise that into OSPF.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0(config)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;ip route 0.0.0.0 0.0.0.0 serial 1/1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0(config)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;router ospf 10&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0(config-router)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;default-information originate&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0(config-router)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;end&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Now I check the routing tables across the routers finishing with R3.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R3&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R3#&lt;span style="font-weight: bold;"&gt;sh ip route&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Codes: C - connected, S - static, R - RIP, M - mobile, B - BGP&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       E1 - OSPF external type 1, E2 - OSPF external type 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       ia - IS-IS inter area, * - candidate default, U - per-user static route&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       o - ODR, P - periodic downloaded static route&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Gateway of last resort is 192.168.3.1 to network 0.0.0.0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;C    192.168.4.0/24 is directly connected, Loopback0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;O    192.168.1.0/24 [110/84] via 192.168.3.1, 00:05:49, Ethernet0/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;O    192.168.2.0/24 [110/20] via 192.168.3.1, 00:05:49, Ethernet0/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;C    192.168.3.0/24 is directly connected, Ethernet0/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;O*E2 0.0.0.0/0 [110/1] via 192.168.3.1, 00:05:49, Ethernet0/0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Below are some show commands which are useful when troubleshooting OSPF.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R3#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;sh ip ospf &lt;/span&gt;&lt;span style="font-family:courier new;"&gt;         &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; Routing Process "ospf 10" with ID 192.168.4.1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; Start time: 00:38:51.280, Time elapsed: 00:33:41.280&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; Supports only single TOS(TOS0) routes&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; Supports opaque LSA&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; Supports Link-local Signaling (LLS)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; Supports area transit capability&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; Router is not originating router-LSAs with maximum metric&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; Initial SPF schedule delay 5000 msecs&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; Minimum hold time between two consecutive SPFs 10000 msecs&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; Maximum wait time between two consecutive SPFs 10000 msecs&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; Incremental-SPF disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; Minimum LSA interval 5 secs&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; Minimum LSA arrival 1000 msecs&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; LSA group pacing timer 240 secs&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; Interface flood pacing timer 33 msecs&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; Retransmission pacing timer 66 msecs&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; Number of external LSA 1. Checksum Sum 0x008F40&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; Number of opaque AS LSA 0. Checksum Sum 0x000000&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; Number of DCbitless external and opaque AS LSA 0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; Number of DoNotAge external and opaque AS LSA 0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; Number of areas in this router is 1. 1 normal 0 stub 0 nssa&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; Number of areas transit capable is 0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; External flood list length 0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    Area BACKBONE(0)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    Number of interfaces in this area is 2 (1 loopback)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    Area has no authentication&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    SPF algorithm last executed 00:09:44.096 ago&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    SPF algorithm executed 3 times&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    Area ranges are&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    Number of LSA 6. Checksum Sum 0x03A79E&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    Number of opaque link LSA 0. Checksum Sum 0x000000&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    Number of DCbitless LSA 0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    Number of indication LSA 0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    Number of DoNotAge LSA 0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    Flood list length 0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R3#&lt;span style="font-weight: bold;"&gt;sh ip ospf interface&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Ethernet0/0 is up, line protocol is up &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Internet Address 192.168.3.2/24, Area 0 &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Process ID 10, Router ID 192.168.4.1, Network Type BROADCAST, Cost: 10&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Transmit Delay is 1 sec, State BDR, Priority 1 &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Designated Router (ID) 192.168.3.1, Interface address 192.168.3.1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Backup Designated router (ID) 192.168.4.1, Interface address 192.168.3.2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Timer intervals configured, Hello 10, Dead 40, Wait 40, Retransmit 5&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    oob-resync timeout 40&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    Hello due in 00:00:09&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Supports Link-local Signaling (LLS)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Index 2/2, flood queue length 0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Next 0x0(0)/0x0(0)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Last flood scan length is 1, maximum is 1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Last flood scan time is 0 msec, maximum is 0 msec&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Neighbor Count is 1, Adjacent neighbor count is 1 &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    Adjacent with neighbor 192.168.3.1  (Designated Router)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Suppress hello for 0 neighbor(s)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Loopback0 is up, line protocol is up &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Internet Address 192.168.4.1/24, Area 0 &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Process ID 10, Router ID 192.168.4.1, Network Type LOOPBACK, Cost: 1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Loopback interface is treated as a stub Host&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2076617431778629795-3718883124102502629?l=ciscobasics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/3718883124102502629'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/3718883124102502629'/><link rel='alternate' type='text/html' href='http://ciscobasics.blogspot.com/2010/02/configure-ospf-routing.html' title='Configure OSPF Routing'/><author><name>SynJunkie</name><uri>http://www.blogger.com/profile/01249134797038027437</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_vZAp7b1QDw8/ScYc8FwNqTI/AAAAAAAABEw/ZFgShqSU9HI/S220/Photo+6.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_vZAp7b1QDw8/S4MA3X7xS2I/AAAAAAAABiI/UAPPzBmKbQs/s72-c/Screen+shot+2010-02-22+at+22.10.07.PNG' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-2076617431778629795.post-1188243402951566684</id><published>2010-02-21T22:07:00.007Z</published><updated>2010-02-24T22:16:23.387Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Router'/><category scheme='http://www.blogger.com/atom/ns#' term='RIP'/><title type='text'>Configure Default Routing</title><content type='html'>In this post I will create a default route and distribute it using RIP.&lt;br /&gt;&lt;br /&gt;Below is a diagram of the network I'll be using in this post.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_vZAp7b1QDw8/S4GvXG-lyqI/AAAAAAAABiA/ZujbHsl2Ii0/s1600-h/Screen+shot+2010-02-21+at+21.37.46.PNG"&gt;&lt;img style="cursor: pointer; width: 400px; height: 62px;" src="http://1.bp.blogspot.com/_vZAp7b1QDw8/S4GvXG-lyqI/AAAAAAAABiA/ZujbHsl2Ii0/s400/Screen+shot+2010-02-21+at+21.37.46.PNG" alt="" id="BLOGGER_PHOTO_ID_5440822636385258146" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Currently on R0 I have no default route.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;sh ip route&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Gateway of last resort is not set&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R    192.168.4.0/24 [120/1] via 192.168.1.2, 00:00:08, Serial1/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;C    192.168.1.0/24 is directly connected, Serial1/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R    192.168.2.0/24 [120/1] via 192.168.1.2, 00:00:08, Serial1/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R    192.168.3.0/24 [120/1] via 192.168.1.2, 00:00:08, Serial1/0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I will configured interface S1/1 on R0 as being the interface that is connected to my ISP.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0(config)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;interface serial 1/1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0(config-if)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;ip address 195.211.64.2 255.255.255.252&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0(config-if)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;no keepalive &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0(config-if)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;no shut&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0(config-if)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;end&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I also check the default route on R3&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R3&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R3#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;sh ip route&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Gateway of last resort is not set&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;C    192.168.4.0/24 is directly connected, Loopback0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R    192.168.1.0/24 [120/1] via 192.168.3.1, 00:00:25, Ethernet0/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R    192.168.2.0/24 [120/1] via 192.168.3.1, 00:00:25, Ethernet0/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;C    192.168.3.0/24 is directly connected, Ethernet0/0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Back on R0 I create a default route pointing to Serial 1/1 and distribute it with RIP.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0(config)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;ip route 0.0.0.0 0.0.0.0 s1/1       &lt;/span&gt;&lt;span style="font-family:courier new;"&gt;      &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0(config)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;router rip&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0(config-router)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;default-information originate &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0(config-router)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;end&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Checking my route table I can see I have a gateway of last resort set and a default route is set.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;sh ip route&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Gateway of last resort is 0.0.0.0 to network 0.0.0.0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R    192.168.4.0/24 [120/1] via 192.168.1.2, 00:00:15, Serial1/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;     195.211.64.0/30 is subnetted, 1 subnets&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;C       195.211.64.0 is directly connected, Serial1/1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;C    192.168.1.0/24 is directly connected, Serial1/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R    192.168.2.0/24 [120/1] via 192.168.1.2, 00:00:16, Serial1/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R    192.168.3.0/24 [120/1] via 192.168.1.2, 00:00:16, Serial1/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;S*   0.0.0.0/0 is directly connected, Serial1/1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;On R3 I check the routing table to make sure it has a default route set and it is sending the packets out the right interface.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R3&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R3#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;sh ip route      &lt;/span&gt;&lt;span style="font-family:courier new;"&gt;   &lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Gateway of last resort is 192.168.3.1 to network 0.0.0.0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;C    192.168.4.0/24 is directly connected, Loopback0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R    192.168.1.0/24 [120/1] via 192.168.3.1, 00:00:26, Ethernet0/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R    192.168.2.0/24 [120/1] via 192.168.3.1, 00:00:26, Ethernet0/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;C    192.168.3.0/24 is directly connected, Ethernet0/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R*   0.0.0.0/0 [120/3] via 192.168.3.1, 00:00:26, Ethernet0/0&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2076617431778629795-1188243402951566684?l=ciscobasics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/1188243402951566684'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/1188243402951566684'/><link rel='alternate' type='text/html' href='http://ciscobasics.blogspot.com/2010/02/create-default-route.html' title='Configure Default Routing'/><author><name>SynJunkie</name><uri>http://www.blogger.com/profile/01249134797038027437</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_vZAp7b1QDw8/ScYc8FwNqTI/AAAAAAAABEw/ZFgShqSU9HI/S220/Photo+6.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_vZAp7b1QDw8/S4GvXG-lyqI/AAAAAAAABiA/ZujbHsl2Ii0/s72-c/Screen+shot+2010-02-21+at+21.37.46.PNG' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-2076617431778629795.post-1042083784206400618</id><published>2010-02-17T20:01:00.011Z</published><updated>2010-02-24T22:32:42.497Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Router'/><category scheme='http://www.blogger.com/atom/ns#' term='RIP'/><title type='text'>Configuring RIP</title><content type='html'>In this post I will configure a small network with RIP routing.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_vZAp7b1QDw8/S3xLbC7w6JI/AAAAAAAABhA/eXiq8hm-8Aw/s1600-h/Rip+Lab.PNG"&gt;&lt;img style="cursor: pointer; width: 400px; height: 103px;" src="http://3.bp.blogspot.com/_vZAp7b1QDw8/S3xLbC7w6JI/AAAAAAAABhA/eXiq8hm-8Aw/s400/Rip+Lab.PNG" alt="" id="BLOGGER_PHOTO_ID_5439305377972807826" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Currently all routers can only communicate with the routers they are directly connected to.  I will enable RIP v2 across all routers and perform some troubleshooting steps along the way.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;On R0 I enable RIP and turn on debugging to view the RIP updates when RIP is enabled on a  connected router.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;conf t&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Enter configuration commands, one per line.  End with CNTL/Z.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0(config)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;router rip&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0(config-router)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;version 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0(config-router)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;network 192.168.1.0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0(config-router)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;end&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;debug ip rip&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;On R1 I enable RIP.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R1#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;conf t&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Enter configuration commands, one per line.  End with CNTL/Z.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R1(config)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;router rip&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R1(config-router)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;version 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R1(config-router)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;network 192.168.1.0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R1(config-router)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;network 192.168.2.0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R1(config-router)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;end&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Back on R0 I can see the R0 sending updates to the multicast address and I can see it receive updates RIP updates from R1.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0#&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;*Mar  1 00:26:29.483: RIP: sending v2 update to 224.0.0.9 via Serial1/0 (192.168.1.1)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;*Mar  1 00:26:29.487: RIP: build update entries - suppressing null update&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0#&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;*Mar  1 00:26:35.091: RIP: received v2 request from 192.168.1.2 on Serial1/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;*Mar  1 00:26:35.095: RIP: sending update with long TTL&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;*Mar  1 00:26:35.099: RIP: sending v2 update to 192.168.1.2 via Serial1/0 (192.168.1.1)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;*Mar  1 00:26:35.099: RIP: build update entries - suppressing null update&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0#&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;*Mar  1 00:26:44.539: RIP: received v2 update from 192.168.1.2 on Serial1/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;*Mar  1 00:26:44.543:      192.168.2.0/24 via 0.0.0.0 in 1 hops&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0#&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;*Mar  1 00:26:46.543: RIP: sending v2 flash update to 224.0.0.9 via Serial1/0 (192.168.1.1)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;*Mar  1 00:26:46.547: RIP: build flash update entries - suppressing null update&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0#&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;*Mar  1 00:26:58.951: RIP: sending v2 update to 224.0.0.9 via Serial1/0 (192.168.1.1)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;*Mar  1 00:26:58.955: RIP: build update entries - suppressing null update&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I know check the routing table.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;sh ip route&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Codes: C - connected, S - static, R - RIP, M - mobile, B - BGP&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       E1 - OSPF external type 1, E2 - OSPF external type 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       ia - IS-IS inter area, * - candidate default, U - per-user static route&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       o - ODR, P - periodic downloaded static route&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Gateway of last resort is not set&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;C       192.168.1.0/24 is directly connected, Serial1/0&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R    192.168.2.0/24 [120/1] via 192.168.1.2, 00:00:07, Serial1/0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;I can see the RIP route to the 192.168.2.0 network listed.&lt;br /&gt;&lt;br /&gt;I can verify connectivity with ping.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;ping 192.168.2.1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Type escape sequence to abort.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Sending 5, 100-byte ICMP Echos to 192.168.2.1, timeout is 2 seconds:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!!!!!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 4/5/8 ms&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I can also check details of my routing protocols.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;sh ip protocols &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Routing Protocol is "rip"&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Outgoing update filter list for all interfaces is not set&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Incoming update filter list for all interfaces is not set&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Sending updates every 30 seconds, next due in 2 seconds&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Invalid after 180 seconds, hold down 180, flushed after 240&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Redistributing: rip&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Default version control: send version 2, receive version 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    Interface             Send  Recv  Triggered RIP  Key-chain&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    Serial1/0             2     2                                   &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Automatic network summarization is in effect&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Maximum path: 4&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Routing for Networks:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    192.168.1.0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Routing Information Sources:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    Gateway         Distance      Last Update&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    192.168.1.2          120      00:00:03&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Distance: (default is 120)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Here I can see information on the timers, the protocols and version and the interfaces RIP is enabled on.&lt;br /&gt;&lt;br /&gt;Now I configure RIP on the rest of the network and test connectivity.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R2&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R2#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;conf t&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Enter configuration commands, one per line.  End with CNTL/Z.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R2(config)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;router rip&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R2(config-router)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;version 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R2(config-router)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;network 192.168.2.0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R2(config-router)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;network 192.168.3.0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R2(config-router)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;end&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R2#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;ping 192.168.1.1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Type escape sequence to abort.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Sending 5, 100-byte ICMP Echos to 192.168.1.1, timeout is 2 seconds:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!!!!!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 8/11/16 ms&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R2#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;sh ip route&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;--cut--&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R    192.168.1.0/24 [120/1] via 192.168.2.1, 00:00:24, Ethernet0/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;C    192.168.2.0/24 is directly connected, Ethernet0/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;C    192.168.3.0/24 is directly connected, Ethernet0/1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;All good. R2 can communicate with R0 so RIP is working fine.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R3&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Finally I enable RIP and test connectivity.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R3#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;conf t&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Enter configuration commands, one per line.  End with CNTL/Z.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R3(config)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;router rip&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R3(config-router)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;network 192.168.3.0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R3(config-router)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;end&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R3#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;ping 192.168.1.1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Type escape sequence to abort.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Sending 5, 100-byte ICMP Echos to 192.168.1.1, timeout is 2 seconds:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!!!!!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 8/18/36 ms&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Great that all works.  But wait a minute.  Lets add another interface in a new network and see if R0 can see it. I'll just use a loopback interface to simulate a network.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R3#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;conf t&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Enter configuration commands, one per line.  End with CNTL/Z.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R3(config)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;int loopback 0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R3(config-if)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;ip address 192.168.4.1 255.255.255.0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R3(config-if)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;no keepalive&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R3(config-if)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;end &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R3#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;sh ip route&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;--cut--&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;C    192.168.4.0/24 is directly connected, Loopback0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R    192.168.1.0/24 [120/1] via 192.168.3.1, 00:00:11, Ethernet0/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R    192.168.2.0/24 [120/1] via 192.168.3.1, 00:00:11, Ethernet0/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;C    192.168.3.0/24 is directly connected, Ethernet0/0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R3#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;ping 192.168.4.1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Type escape sequence to abort.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Sending 5, 100-byte ICMP Echos to 192.168.4.1, timeout is 2 seconds:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!!!!!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 1/2/4 ms&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Now I add the new route in.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R3#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;conf t&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Enter configuration commands, one per line.  End with CNTL/Z.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R3(config)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;router rip&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R3(config-router)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;network 192.168.4.0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R3(config-router)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;end &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Great.  And back on R0....&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;ping 192.168.4.1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Type escape sequence to abort.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Sending 5, 100-byte ICMP Echos to 192.168.4.1, timeout is 2 seconds:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;.....&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Success rate is 0 percent (0/5)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Strange.  I'll try the other interface...&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;ping 192.168.3.2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Type escape sequence to abort.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Sending 5, 100-byte ICMP Echos to 192.168.3.2, timeout is 2 seconds:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!!!!!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 12/14/16 ms&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Well I can get to that one.  What does the routing table on R0 show?&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;sh ip route&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;--cut--&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;C    192.168.1.0/24 is directly connected, Serial1/0&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R    192.168.2.0/24 [120/1] via 192.168.1.2, 00:00:02, Serial1/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R    192.168.3.0/24 [120/1] via 192.168.1.2, 00:00:02, Serial1/0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Well there is no route for the 192.168.4.0 network.  Lets do some debugging.&lt;br /&gt;&lt;br /&gt;Ah here we are ...&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R2&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R2#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;debug ip rip&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;*Mar  1 02:34:39.755: RIP: ignored v1 packet from 192.168.3.2 (illegal version)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R2#&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;*Mar  1 02:34:48.511: RIP: sending v2 update to 224.0.0.9 via Ethernet0/1 (192.168.3.1)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;R3 is still configured to send RIP version 1 updates.  A closer look at the the output of show ip protocols tells us this.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R3&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R3#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;sh ip protocols &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Routing  Protocol is "rip"&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Outgoing update filter list for all interfaces is  not set&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Incoming update filter list for all interfaces is not set&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   Sending updates every 30 seconds, next due in 24 seconds&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Invalid  after 180 seconds, hold down 180, flushed after 240&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Redistributing:  rip&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;font-family:courier new;" &gt;Default version control: send version 1, receive any version&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;     Interface             Send  Recv  Triggered RIP  Key-chain&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;     Ethernet0/0           1     1 2                                 &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;     Loopback0             1     1 2                                 &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   Automatic network summarization is in effect&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Maximum path: 4&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   Routing for Networks:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    192.168.3.0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    192.168.4.0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Routing  Information Sources:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    Gateway         Distance      Last Update&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;     192.168.3.1          120      00:00:11&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Distance: (default is  120)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Line 7 of the output tells us that it will only send version 1 but will receive any version.  Unfortunately RIP version 2 will only send and receive RIP version 2 so the RIP v1 updates will not be added to the route table.&lt;br /&gt;&lt;br /&gt;I fix the problem on R3 by changing the version to RIP v2 and recheck connectivity from R0.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R3&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R3(config)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;router rip&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R3(config-router)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;version 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R3(config-router)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;end&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;R0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;sh ip route&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;--cut--&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R    192.168.4.0/24 [120/1] via 192.168.1.2, 00:00:09, Serial1/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;C    192.168.1.0/24 is directly connected, Serial1/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R    192.168.2.0/24 [120/1] via 192.168.1.2, 00:00:09, Serial1/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R    192.168.3.0/24 [120/1] via 192.168.1.2, 00:00:09, Serial1/0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;ping 192.168.4.1&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;         &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Type escape sequence to abort.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Sending 5, 100-byte ICMP Echos to 192.168.4.1, timeout is 2 seconds:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!!!!!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 8/14/20 ms&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;There we go.  Everything working just fine.&lt;br /&gt;&lt;br /&gt;Finally a few things about RIP for my exam:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;RIP v1&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Distance Vector Protocol&lt;/li&gt;&lt;li&gt;Classfull Routing Protocol&lt;/li&gt;&lt;li&gt;Uses Broadcast to send updates&lt;/li&gt;&lt;li&gt;Administrative Distance is 120&lt;/li&gt;&lt;li&gt;Max Hops 15&lt;/li&gt;&lt;li&gt;Sends Updates Every 30 Seconds&lt;/li&gt;&lt;li&gt;Holddown Timer is 180 Seconds&lt;/li&gt;&lt;li&gt;Invalid after 180 Seconds&lt;/li&gt;&lt;li&gt;Route Flushed after 240 Seconds&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;RIP v2&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Distance Vector Protocol&lt;/li&gt;&lt;li&gt;Classless Routing Protocol (supports VLSM)&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Uses Multicast to send updates (224.0.0.9)&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Administrative Distance is 120&lt;/li&gt;&lt;li&gt;Supports Authentication&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Max Hops 15&lt;/li&gt;&lt;li&gt;Sends Updates Every 30 Seconds&lt;/li&gt;&lt;li&gt;Holddown Timer is 180 Seconds&lt;/li&gt;&lt;li&gt;Invalid after 180 Seconds&lt;/li&gt;&lt;li&gt;Route Flushed after 240 Seconds&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Loop Prevention&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Rip uses the follow mechanisms to prevent routing loops:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Maximum Distance (15 hops)&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Poison Reverse&lt;/li&gt;&lt;li&gt;Holddown Timers&lt;/li&gt;&lt;li&gt;Split Horizen&lt;/li&gt;&lt;li&gt;Triggered Updates&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2076617431778629795-1042083784206400618?l=ciscobasics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/1042083784206400618'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/1042083784206400618'/><link rel='alternate' type='text/html' href='http://ciscobasics.blogspot.com/2010/02/configuring-rip.html' title='Configuring RIP'/><author><name>SynJunkie</name><uri>http://www.blogger.com/profile/01249134797038027437</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_vZAp7b1QDw8/ScYc8FwNqTI/AAAAAAAABEw/ZFgShqSU9HI/S220/Photo+6.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_vZAp7b1QDw8/S3xLbC7w6JI/AAAAAAAABhA/eXiq8hm-8Aw/s72-c/Rip+Lab.PNG' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-2076617431778629795.post-6364546793920724865</id><published>2010-02-15T22:31:00.006Z</published><updated>2010-02-24T22:17:10.199Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Static Routes'/><category scheme='http://www.blogger.com/atom/ns#' term='Router'/><title type='text'>Creating Static Routes</title><content type='html'>In this post I will create a static route to route traffic from  R0 (192.168.1.0/30 network) to R2 (192.168.1.4/30 network).&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_vZAp7b1QDw8/S3nLw0a44OI/AAAAAAAABgw/S0MrgN528NM/s1600-h/Screen+shot+2010-02-15+at+21.52.53.PNG"&gt;&lt;img style="cursor: pointer; width: 400px; height: 121px;" src="http://3.bp.blogspot.com/_vZAp7b1QDw8/S3nLw0a44OI/AAAAAAAABgw/S0MrgN528NM/s400/Screen+shot+2010-02-15+at+21.52.53.PNG" alt="" id="BLOGGER_PHOTO_ID_5438602064592167138" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;To begin with I check my routing table on R0.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0#&lt;span style="font-weight: bold;"&gt;sh ip route&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Codes: C - connected, S - static, R - RIP, M - mobile, B - BGP&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       E1 - OSPF external type 1, E2 - OSPF external type 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       ia - IS-IS inter area, * - candidate default, U - per-user static route&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       o - ODR, P - periodic downloaded static route&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Gateway of last resort is not set&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;     192.168.1.0/30 is subnetted, 1 subnets&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;C       192.168.1.0 is directly connected, Serial1/0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Currently I can only see directly connected interfaces.  Without any static routes or routing protocols traffic from one network cannot reach the other.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0#&lt;span style="font-weight: bold;"&gt;ping 192.168.1.2&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Type escape sequence to abort.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Sending 5, 100-byte ICMP Echos to 192.168.1.2, timeout is 2 seconds:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!!!!!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 4/11/24 ms&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;&lt;br /&gt;               &lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0#&lt;span style="font-weight: bold;"&gt;ping 192.168.1.5&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Type escape sequence to abort.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Sending 5, 100-byte ICMP Echos to 192.168.1.5, timeout is 2 seconds:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;.....&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Success rate is 0 percent (0/5)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I can ping the R1 interface on my network but not the interface on the other network.  This is because R0 does not know where 192.168.1.5 is.  By creating a static route I tell R0 which interface to send packets out of.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0(config)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;ip route 192.168.1.4 255.255.255.252 192.168.1.3 &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0(config)#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;end &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Now when I examine the route table I can see the static route I have created.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0#&lt;span style="font-weight: bold;"&gt;sh ip route&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Codes: C - connected, S - static, R - RIP, M - mobile, B - BGP&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       E1 - OSPF external type 1, E2 - OSPF external type 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       ia - IS-IS inter area, * - candidate default, U - per-user static route&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;       o - ODR, P - periodic downloaded static route&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Gateway of last resort is not set&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;     192.168.1.0/30 is subnetted, 2 subnets&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;C       192.168.1.0 is directly connected, Serial1/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;S       192.168.1.4 [1/0] via 192.168.1.3&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Now If I attempt to ping the ethernet interface on R1 I get a response.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0#&lt;span style="font-weight: bold;"&gt;ping 192.168.1.5&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Type escape sequence to abort.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Sending 5, 100-byte ICMP Echos to 192.168.1.5, timeout is 2 seconds:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!!!!!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 4/6/8 ms&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;So what about R2?&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0#&lt;span style="font-weight: bold;"&gt;ping 192.168.1.6&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Type escape sequence to abort.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Sending 5, 100-byte ICMP Echos to 192.168.1.6, timeout is 2 seconds:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;.....&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Success rate is 0 percent (0/5)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Well R2 is receiving the ICMP ping packets but it doesn't know how to get them back to me. By going to R2 and giving it a route to get back it will know which direction to send packets back.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R2#&lt;span style="font-weight: bold;"&gt;conf t&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Enter configuration commands, one per line.  End with CNTL/Z.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R2(config)#&lt;span style="font-weight: bold;"&gt;ip route 192.168.1.0 255.255.255.252 192.168.1.4&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Because R1 know which networks it is directly connect to it happily passes the packets to the correct interface.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R1#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;sh ip route connected &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;     192.168.1.0/30 is subnetted, 2 subnets&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;C       192.168.1.0 is directly connected, Serial0/0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;C       192.168.1.4 is directly connected, Ethernet1/0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Attempting to ping R2 from R0 now produces the desired result.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;R0#&lt;span style="font-weight: bold;"&gt;ping 192.168.1.6&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Type escape sequence to abort.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Sending 5, 100-byte ICMP Echos to 192.168.1.6, timeout is 2 seconds:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;.!!!!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Success rate is 80 percent (4/5), round-trip min/avg/max = 4/12/24 ms&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2076617431778629795-6364546793920724865?l=ciscobasics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/6364546793920724865'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/6364546793920724865'/><link rel='alternate' type='text/html' href='http://ciscobasics.blogspot.com/2010/02/creating-static-routes.html' title='Creating Static Routes'/><author><name>SynJunkie</name><uri>http://www.blogger.com/profile/01249134797038027437</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_vZAp7b1QDw8/ScYc8FwNqTI/AAAAAAAABEw/ZFgShqSU9HI/S220/Photo+6.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_vZAp7b1QDw8/S3nLw0a44OI/AAAAAAAABgw/S0MrgN528NM/s72-c/Screen+shot+2010-02-15+at+21.52.53.PNG' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-2076617431778629795.post-172001145491250720</id><published>2010-02-13T19:34:00.013Z</published><updated>2010-02-24T22:17:27.884Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Router'/><category scheme='http://www.blogger.com/atom/ns#' term='CDP'/><category scheme='http://www.blogger.com/atom/ns#' term='Switch'/><title type='text'>Documenting a Network with CDP</title><content type='html'>In this post I will use the information available from CDP to help me create a logical network diagram.&lt;br /&gt;&lt;br /&gt;CDP is the Cisco Discovery Protocol and is enabled on all router and switch interfaces by default. The switch or router sends a CDP packet out of each interface every 60 seconds, any connected device records the delivery of these packets into a CDP table for a holdtime period of 180 seconds. If after 180 seconds the device has not received any more CDP packets on that interface it removes the entry from the table.   CDP can be disabled entirely or on any individual interface.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I begin by connecting to my switch and I check the CDP settings.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1#&lt;span style="font-weight: bold;"&gt;sh cdp&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Global CDP information:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   Sending CDP packets every 60 seconds&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   Sending a holdtime value of 180 seconds&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   Sending CDPv2 advertisements is  enabled&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;From the output I can see the CDP time settings and the version.  Next I look at the connected devices.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1#&lt;span style="font-weight: bold;"&gt;sh cdp neighbors&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Capability Codes: R - Router, T - Trans Bridge, B - Source Route Bridge&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;                 S - Switch, H - Host, I - IGMP, r - Repeater&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Device ID        Local Intrfce     Holdtme    Capability  Platform  Port ID&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2.lab.localFas 0/1            160         S I       WS-C2950-2Fas 0/1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2.lab.localFas 0/24           160         S I       WS-C2950-2Fas 0/24&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Here I can see that I have 2 ports (1 &amp;amp; 24) connected to switch2 (also using ports 1 &amp;amp; 24).  I can also see that switch2 is a Catalyst 2950.&lt;br /&gt;&lt;br /&gt;This is a great summary but for my diagram I could do with knowing the IP address of switch2.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1#&lt;span style="font-weight: bold;"&gt;sh cdp entry *&lt;/span&gt;                &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;-------------------------&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Device ID: switch2.lab.local&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Entry address(es):&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; IP address: 10.0.1.211&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Platform: cisco WS-C2950-24,  Capabilities: Switch IGMP&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Interface: FastEthernet0/1,  Port ID (outgoing port): FastEthernet0/1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Holdtime : 142 sec&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Version :&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Cisco Internetwork Operating System Software&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;IOS (tm) C2950 Software (C2950-I6Q4L2-M), Version 12.1(13)EA1, RELEASE SOFTWARE (fc1)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Copyright (c) 1986-2003 by cisco Systems, Inc.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Compiled Tue 04-Mar-03 02:14 by yenanh&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;advertisement version: 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Protocol Hello:  OUI=0x00000C, Protocol ID=0x0112; payload len=27, value=00000000FFFFFFFF01022505000000000000000CCE3E3EC0FF0000&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;VTP Management Domain: 'lab.local'&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Native VLAN: 1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Duplex: full&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;-------------------------&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Device ID: switch2.lab.local&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Entry address(es):&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; IP address: 10.0.1.211&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Platform: cisco WS-C2950-24,  Capabilities: Switch IGMP&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Interface: FastEthernet0/24,  Port ID (outgoing port): FastEthernet0/24&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Holdtime : 142 sec&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Version :&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Cisco Internetwork Operating System Software&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;IOS (tm) C2950 Software (C2950-I6Q4L2-M), Version 12.1(13)EA1, RELEASE SOFTWARE (fc1)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Copyright (c) 1986-2003 by cisco Systems, Inc.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Compiled Tue 04-Mar-03 02:14 by yenanh&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;advertisement version: 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Protocol Hello:  OUI=0x00000C, Protocol ID=0x0112; payload len=27, value=00000000FFFFFFFF01022505000000000000000CCE3E3EC0FF0000&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;VTP Management Domain: 'lab.local'&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Native VLAN: 1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Duplex: full&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;This detailed output gives me additional useful information such as the VLAN and the IOS version.&lt;br /&gt;&lt;br /&gt;Next I head over to switch2 and look at it's CDP information.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2#&lt;span style="font-weight: bold;"&gt;sh cdp neighbors&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Capability Codes: R - Router, T - Trans Bridge, B - Source Route Bridge&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;                 S - Switch, H - Host, I - IGMP, r - Repeater, P - Phone&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Device ID        Local Intrfce     Holdtme    Capability  Platform  Port ID&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1          Fas 0/24           168          S I      WS-C2950-2Fas 0/24&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1          Fas 0/1            168          S I      WS-C2950-2Fas 0/1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1.lab.localFas 0/2            175           R       Cisco C831Eth 0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1.lab.localFas 0/23           175           R       Cisco C831Eth 1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Here I can see the connections to switch1 and additional connections to router1.  Again I look at the detailed information to get the IP address of the router.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2#&lt;span style="font-weight: bold;"&gt;sh cdp entry *&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;-------------------------&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Device ID: switch1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Entry address(es):&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  IP address: 10.0.1.210&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Platform: cisco WS-C2950-24,  Capabilities: Switch IGMP&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Interface: FastEthernet0/24,  Port ID (outgoing port): FastEthernet0/24&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Holdtime : 152 sec&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Version :&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Cisco Internetwork Operating System Software&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;IOS (tm) C2950 Software (C2950-I6Q4L2-M), Version 12.1(12c)EA1, RELEASE SOFTWARE (fc1)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Copyright (c) 1986-2002 by cisco Systems, Inc.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Compiled Sun 24-Nov-02 23:31 by antonino&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;advertisement version: 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Protocol Hello:  OUI=0x00000C, Protocol ID=0x0112; payload len=27, value=00000000FFFFFFFF01022505000000000000000C8582C600FF0000&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;VTP Management Domain: 'lab.local'&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Native VLAN: 1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Duplex: full&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;-------------------------&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Device ID: switch1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Entry address(es):&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  IP address: 10.0.1.210&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Platform: cisco WS-C2950-24,  Capabilities: Switch IGMP&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Interface: FastEthernet0/1,  Port ID (outgoing port): FastEthernet0/1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Holdtime : 152 sec&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Version :&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Cisco Internetwork Operating System Software&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;IOS (tm) C2950 Software (C2950-I6Q4L2-M), Version 12.1(12c)EA1, RELEASE SOFTWARE (fc1)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Copyright (c) 1986-2002 by cisco Systems, Inc.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Compiled Sun 24-Nov-02 23:31 by antonino&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;advertisement version: 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Protocol Hello:  OUI=0x00000C, Protocol ID=0x0112; payload len=27, value=00000000FFFFFFFF01022505000000000000000C8582C600FF0000&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;VTP Management Domain: 'lab.local'&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Native VLAN: 1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Duplex: full&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;-------------------------&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Device ID: router1.lab.local&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Entry address(es):&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  IP address: 10.0.2.254&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Platform: Cisco C831,  Capabilities: Router&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Interface: FastEthernet0/23,  Port ID (outgoing port): Ethernet1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Holdtime : 176 sec&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Version :&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Cisco IOS Software, C831 Software (C831-K9O3Y6-M), Version 12.4(4)T1, RELEASE SOFTWARE (fc4)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Technical Support: http://www.cisco.com/techsupport&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Copyright (c) 1986-2005 by Cisco Systems, Inc.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Compiled Thu 22-Dec-05 01:39 by ccai&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;advertisement version: 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Duplex: half&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;-------------------------&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Device ID: router1.lab.local&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Entry address(es):&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  IP address: 10.0.1.254&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Platform: Cisco C831,  Capabilities: Router&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Interface: FastEthernet0/2,  Port ID (outgoing port): Ethernet0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Holdtime : 176 sec&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Version :&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Cisco IOS Software, C831 Software (C831-K9O3Y6-M), Version 12.4(4)T1, RELEASE SOFTWARE (fc4)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Technical Support: http://www.cisco.com/techsupport&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Copyright (c) 1986-2005 by Cisco Systems, Inc.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Compiled Thu 22-Dec-05 01:39 by ccai&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;advertisement version: 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Duplex: full&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;From the output I am able to determine the IP addresses of the connected router interfaces and I can also see that one interface is configured to half duplex.  Now I have some good information to begin populating my diagram with.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_vZAp7b1QDw8/S3f5z4YlOLI/AAAAAAAABgg/sj_a8NLc8W8/s1600-h/CDP+Drawing.png"&gt;&lt;img style="cursor: pointer; width: 320px; height: 292px;" src="http://2.bp.blogspot.com/_vZAp7b1QDw8/S3f5z4YlOLI/AAAAAAAABgg/sj_a8NLc8W8/s320/CDP+Drawing.png" alt="" id="BLOGGER_PHOTO_ID_5438089744777296050" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;From here I would probably move to the router and look at the CDP table.  But supposing I want to prevent CDP packets from leaving an interface?  After all, quite detailed information is included in CDP that you might not want everyone to view.&lt;br /&gt;&lt;br /&gt;I connect to the device that I want to stop sending CDP packets and turn CDP off on that particular interface.  In my case I would like to stop router1 from sending CDP packets on interface ethernet 1.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1#&lt;span style="font-weight: bold;"&gt;conf t&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Enter configuration commands, one per line.  End with CNTL/Z.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(config)#&lt;span style="font-weight: bold;"&gt;int ethernet 1&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(config-if)#&lt;span style="font-weight: bold;"&gt;no cdp enable&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(config-if)#&lt;span style="font-weight: bold;"&gt;end&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Now when I check the switch that router1 is connected to I see that the holdtime decreases as the switch receives no CDP packet on the interface until after 180 seconds it reaches 0 and the entry is removed from the table.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;sh cdp neighbors&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Capability Codes: R - Router, T - Trans Bridge, B - Source Route Bridge&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;                  S - Switch, H - Host, I - IGMP, r - Repeater, P - Phone&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Device ID        Local Intrfce     Holdtme    Capability  Platform  Port ID&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1          Fas 0/24           159          S I      WS-C2950-2Fas 0/24&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1          Fas 0/1            159          S I      WS-C2950-2Fas 0/1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1.lab.localFas 0/23           6             R       Cisco C831Eth 1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1.lab.localFas 0/2            126           R       Cisco C831Eth 0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;sh cdp neighbors&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Capability Codes: R - Router, T - Trans Bridge, B - Source Route Bridge&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;                  S - Switch, H - Host, I - IGMP, r - Repeater, P - Phone&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Device ID        Local Intrfce     Holdtme    Capability  Platform  Port ID&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1          Fas 0/24           153          S I      WS-C2950-2Fas 0/24&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1          Fas 0/1            152          S I      WS-C2950-2Fas 0/1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1.lab.localFas 0/23           0             R       Cisco C831Eth 1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1.lab.localFas 0/2            179           R       Cisco C831Eth 0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;sh cdp neighbors&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Capability Codes: R - Router, T - Trans Bridge, B - Source Route Bridge&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;                  S - Switch, H - Host, I - IGMP, r - Repeater, P - Phone&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Device ID        Local Intrfce     Holdtme    Capability  Platform  Port ID&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1          Fas 0/24           147          S I      WS-C2950-2Fas 0/24&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1          Fas 0/1            147          S I      WS-C2950-2Fas 0/1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1.lab.localFas 0/2            174           R       Cisco C831Eth 0&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2076617431778629795-172001145491250720?l=ciscobasics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/172001145491250720'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/172001145491250720'/><link rel='alternate' type='text/html' href='http://ciscobasics.blogspot.com/2010/02/documenting-network-with-cdp.html' title='Documenting a Network with CDP'/><author><name>SynJunkie</name><uri>http://www.blogger.com/profile/01249134797038027437</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_vZAp7b1QDw8/ScYc8FwNqTI/AAAAAAAABEw/ZFgShqSU9HI/S220/Photo+6.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_vZAp7b1QDw8/S3f5z4YlOLI/AAAAAAAABgg/sj_a8NLc8W8/s72-c/CDP+Drawing.png' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-2076617431778629795.post-6251717758867690934</id><published>2010-02-09T21:48:00.005Z</published><updated>2010-02-09T23:18:27.338Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Router'/><category scheme='http://www.blogger.com/atom/ns#' term='Switch'/><title type='text'>Duplex Configuration</title><content type='html'>Mismatched duplex settings can cause a network connection to perform poorly. Often a duplex mismatch is caused by a PC's network card or routers interface being configured to full or half duplex whilst the switch port being set to auto detect.  If there is a duplex mismatch the CDP will report it, and these can be seen on screen by enabling the terminal monitor.&lt;br /&gt;&lt;br /&gt;Below I have enabled terminal monitor and error messages are printed to the terminal.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1#&lt;span style="font-weight: bold;"&gt;terminal monitor &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1#&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;03:16:25: %CDP-4-DUPLEX_MISMATCH: duplex mismatch discovered on FastEthernet0/23 (not half duplex), with router1.lab.local Ethernet1 (half duplex).&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1#&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;03:17:25: %CDP-4-DUPLEX_MISMATCH: duplex mismatch discovered on FastEthernet0/23 (not half duplex), with router1.lab.local Ethernet1 (half duplex).&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1#&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;I can see that every 60 seconds as CDP packets are received I receive a warning that there is a duplex mismatch.&lt;br /&gt;&lt;br /&gt;To very quickly check all the ports on my switch I use the following show command:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1#&lt;span style="font-weight: bold;"&gt;show interfaces status&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Port    Name               Status       Vlan       Duplex  Speed Type&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Fa0/1                      connected    trunk      a-full  a-100 10/100BaseTX&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Fa0/2                      connected    1          a-full  a-100 10/100BaseTX&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Fa0/3                      connected    1          a-full  a-100 10/100BaseTX&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Fa0/4                      notconnect   1            auto   auto 10/100BaseTX&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Fa0/5                      notconnect   1            auto   auto 10/100BaseTX&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Fa0/6                      notconnect   1            auto   auto 10/100BaseTX&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Fa0/7                      notconnect   1            auto   auto 10/100BaseTX&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Fa0/8                      notconnect   1            auto   auto 10/100BaseTX&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Fa0/9                      notconnect   1            auto   auto 10/100BaseTX&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Fa0/10                     notconnect   1            auto   auto 10/100BaseTX&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Fa0/11                     notconnect   1            auto   auto 10/100BaseTX&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Fa0/12                     notconnect   1            auto   auto 10/100BaseTX&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Fa0/13                     notconnect   1            auto   auto 10/100BaseTX&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Fa0/14                     notconnect   1            auto   auto 10/100BaseTX&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Fa0/15                     notconnect   1            auto   auto 10/100BaseTX&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Fa0/16                     notconnect   1            full   auto 10/100BaseTX&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Fa0/17                     notconnect   2            auto   auto 10/100BaseTX&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Fa0/18                     notconnect   2            auto   auto 10/100BaseTX&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Fa0/19                     notconnect   2            auto   auto 10/100BaseTX&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Fa0/20                     notconnect   2            auto   auto 10/100BaseTX&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Fa0/21                     notconnect   2            auto   auto 10/100BaseTX&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Fa0/22                     notconnect   2            auto   auto 10/100BaseTX&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Fa0/23                     connected    2            full     10 10/100BaseTX&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Fa0/24                     connected    trunk      a-full  a-100 10/100BaseTX&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Po5                        connected    trunk      a-full  a-100 &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;From the output I can see that although most ports are set to auto, some are configured with specific speed and duplex settings.  Fa0/1,2,3 and fa0/24 are configured to auto for duplex and speed but have detected that the connect devices  are set to full duplex and 100Mb.&lt;br /&gt;&lt;br /&gt;Fa0/16 is configured as full duplex and the speed is set to auto. Fa0/23 which is the port which is shown in the error message is configured as full duplex and 10Mb.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;03:17:25:  %CDP-4-DUPLEX_MISMATCH: duplex mismatch discovered on &lt;span style="font-weight: bold;"&gt;FastEthernet0/23  (not half duplex&lt;/span&gt;), with &lt;span style="font-weight: bold;"&gt;router1.lab.local Ethernet1 (half duplex)&lt;/span&gt;.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Upon closer inspection of the error message I can see that the connected device (router1) is configured to half duplex on interface Ethernet 1.&lt;br /&gt;&lt;br /&gt;I can either change the router interface or the switch port so the duplex settings match but when I do the port will briefly shutdown.  I decide to make the change on the router so both  ports are configured to full duplex.&lt;br /&gt;&lt;br /&gt;After connecting to router1 I can use a show command to take a good look at the interface settings and the counters.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1#&lt;span style="font-weight: bold;"&gt;show interfaces ethernet 1 &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Ethernet1 is up, line protocol is up &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Hardware is PQUICC_FEC, address is 000e.3884.8540 (bia 000e.3884.8540)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Internet address is 10.0.2.254/24&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  MTU 1500 bytes, BW 10000 Kbit, DLY 1000 usec, &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;     reliability 255/255, txload 1/255, rxload 1/255&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Encapsulation ARPA, loopback not set&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Keepalive set (10 sec)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  &lt;span style="font-weight: bold;"&gt;Half-duplex, 10Mb/s&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  ARP type: ARPA, ARP Timeout 04:00:00&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Last input 00:00:06, output 00:00:06, output hang never&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Last clearing of "show interface" counters 23:42:46&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Queueing strategy: fifo&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  Output queue: 0/40 (size/max)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  5 minute input rate 0 bits/sec, 0 packets/sec&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;  5 minute output rate 0 bits/sec, 0 packets/sec&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;     3182 packets input, 362199 bytes, 0 no buffer&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;     Received 1581 broadcasts, 0 runts, 0 giants, 0 throttles&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;     0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;     0 input packets with dribble condition detected&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;     9407 packets output, 644928 bytes, 0 underruns&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;     35 output errors, 377 collisions, 0 interface resets&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;     0 babbles, 0 late collision, 0 deferred&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;     0 lost carrier, 0 no carrier&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;     0 output buffer failures, 0 output buffers swapped out&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;From the output above I can see that the interface is configured as half duplex and 10Mb.  I change the interface to full duplex to match the switch interface.  I can also see that there are some errors and collisions on the interface.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1#&lt;span style="font-weight: bold;"&gt;conf t&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Enter configuration commands, one per line.  End with CNTL/Z.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(config)#&lt;span style="font-weight: bold;"&gt;interface ethernet 1&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(config-if)#&lt;span style="font-weight: bold;"&gt;duplex full&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(config-if)#&lt;span style="font-weight: bold;"&gt;end&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I verify the configuration and reset the counters on both interfaces  so I can easily see if more issues occur.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1#&lt;span style="font-weight: bold;"&gt;clear counters ethernet 1&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Clear "show interface" counters on this interface [confirm]&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1#&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1#&lt;/span&gt;&lt;span style="font-weight: bold;font-family:courier new;" &gt;clear counters fastEthernet0/23&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Clear "show interface" counters on this interface [confirm]&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1#&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;04:00:19: %CLEAR-5-COUNTERS: Clear counter on interface FastEthernet0/23 by vty0 (10.0.1.4)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;It is always a good idea to configure interfaces on both servers and routers to match those of the switch rather than leave them at auto detect.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2076617431778629795-6251717758867690934?l=ciscobasics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/6251717758867690934'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/6251717758867690934'/><link rel='alternate' type='text/html' href='http://ciscobasics.blogspot.com/2010/02/duplex-configuration.html' title='Duplex Configuration'/><author><name>SynJunkie</name><uri>http://www.blogger.com/profile/01249134797038027437</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_vZAp7b1QDw8/ScYc8FwNqTI/AAAAAAAABEw/ZFgShqSU9HI/S220/Photo+6.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-2076617431778629795.post-4568961837274146456</id><published>2010-02-08T21:17:00.004Z</published><updated>2010-02-08T21:31:18.919Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Router'/><category scheme='http://www.blogger.com/atom/ns#' term='Switch'/><title type='text'>Schedule a Reload</title><content type='html'>Occasionally I might make changes to a switch or router that may lock me out.  If I am sat next to the device this isn't a problem, if I am not it is. By scheduling a reboot or reload I can be sure that the change I make is removed when the device reloads because it will reload the startup-config which I saved at the start of the session.&lt;br /&gt;&lt;br /&gt;First I save the running configuration to make sure the startup-config is current.  I then schedule my reload to allow me enough time to make my changes.  If the reload isn't required I simply cancel it.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1#&lt;span style="font-weight: bold;"&gt;copy run start&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Destination filename [startup-config]? &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Building configuration...&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;[OK]&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1#&lt;span style="font-weight: bold;"&gt;reload in 015&lt;/span&gt;  &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Reload scheduled in 15 minutes&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Proceed with reload? [confirm]&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1#&lt;span style="font-weight: bold;"&gt;reload cancel&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1#&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;***&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;*** --- SHUTDOWN ABORTED ---&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;***&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1#&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2076617431778629795-4568961837274146456?l=ciscobasics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/4568961837274146456'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/4568961837274146456'/><link rel='alternate' type='text/html' href='http://ciscobasics.blogspot.com/2010/02/schedule-reload.html' title='Schedule a Reload'/><author><name>SynJunkie</name><uri>http://www.blogger.com/profile/01249134797038027437</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_vZAp7b1QDw8/ScYc8FwNqTI/AAAAAAAABEw/ZFgShqSU9HI/S220/Photo+6.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-2076617431778629795.post-6067134922167106750</id><published>2010-02-07T15:46:00.006Z</published><updated>2010-02-24T22:18:00.762Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Port Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Switch'/><title type='text'>Configure Port Protection</title><content type='html'>Port Protection can be utilised to protect hosts from malware and abuse.  By placing ports into protected mode the connected hosts are unable to talk to other hosts connected to ports that are also in protected mode.&lt;br /&gt;&lt;br /&gt;Hosts connected to ports in protected mode can communicate with hosts on non-protected ports. Typically hosts offering services should not be connected to ports that have been placed in protected mode.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Below I configure ports 9 to 16 as protected ports. I use a show command to view the running config.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2#&lt;span style="font-weight: bold;"&gt;conf t&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Enter configuration commands, one per line.  End with CNTL/Z.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2(config)#&lt;span style="font-weight: bold;"&gt;interface range fastEthernet 0/9 - 16&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2(config-if-range)#&lt;span style="font-weight: bold;"&gt;switchport protected&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2(config-if-range)#&lt;span style="font-weight: bold;"&gt;end&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2#&lt;span style="font-weight: bold;"&gt;show run | begin interface FastEthernet0/9&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;interface FastEthernet0/9&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; switchport protected&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; no ip address&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; spanning-tree portfast&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;interface FastEthernet0/10&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; switchport protected&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; no ip address&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; spanning-tree portfast&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;interface FastEthernet0/11&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; switchport protected&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; no ip address&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; spanning-tree portfast&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;interface FastEthernet0/12&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; switchport protected&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; no ip address&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; spanning-tree portfast&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;interface FastEthernet0/13&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; switchport protected&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; no ip address&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; spanning-tree portfast&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;interface FastEthernet0/14&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; switchport protected&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; no ip address&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; spanning-tree portfast&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;interface FastEthernet0/15&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; switchport protected&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; no ip address&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; spanning-tree portfast&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;interface FastEthernet0/16&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; switchport protected&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; no ip address&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; spanning-tree portfast&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Using ping I verify that hosts on protected ports cannot communicate with each other but can still access services on non-protected ports.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2076617431778629795-6067134922167106750?l=ciscobasics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/6067134922167106750'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/6067134922167106750'/><link rel='alternate' type='text/html' href='http://ciscobasics.blogspot.com/2010/02/configuring-port-protection.html' title='Configure Port Protection'/><author><name>SynJunkie</name><uri>http://www.blogger.com/profile/01249134797038027437</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_vZAp7b1QDw8/ScYc8FwNqTI/AAAAAAAABEw/ZFgShqSU9HI/S220/Photo+6.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-2076617431778629795.post-8906745472882788746</id><published>2010-02-07T15:14:00.006Z</published><updated>2010-02-07T15:41:46.235Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Switch'/><title type='text'>Configure Logging</title><content type='html'>In this post I will configure my switch to log to a syslog server on my mac (10.0.1.4)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1#&lt;span style="font-weight: bold;"&gt;conf t&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Enter configuration commands, one per line.  End with CNTL/Z.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config)#&lt;span style="font-weight: bold;"&gt;logging trap debugging &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config)#&lt;span style="font-weight: bold;"&gt;logging 10.0.1.4&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config)#&lt;span style="font-weight: bold;"&gt;logging on&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Switch1 now logs to a remote syslog server.&lt;br /&gt;&lt;br /&gt;# &lt;span style="font-weight: bold;"&gt;tail -f /var/log/switch.log&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Feb  7 15:11:55 10.0.1.210 35: 00:09:48: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/16, changed state to down&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Feb  7 15:12:00 10.0.1.210 36: 00:09:53: %LINK-3-UPDOWN: Interface FastEthernet0/16, changed state to up&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Feb  7 15:12:03 10.0.1.210 37: 00:09:55: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/16, changed state to up&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;A switch can also be configured to log to the buffer. Below I will configure Switch2 to log notification messages to the buffer.  Finally I will use a show command to view the messages.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;switch2#&lt;span style="font-weight: bold;"&gt;conf t&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Enter configuration commands, one per line.  End with CNTL/Z.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;switch2(config)#&lt;span style="font-weight: bold;"&gt;logging buffered notifications&lt;/span&gt;       &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;switch2(config)#&lt;span style="font-weight: bold;"&gt;end&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;                               &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;switch2#&lt;span style="font-weight: bold;"&gt;show logging&lt;/span&gt;    &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Syslog logging: enabled (0 messages dropped, 0 messages rate-limited, 0 flushes, 0 overruns)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;    Console logging: level debugging, 23 messages logged&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;    Monitor logging: level debugging, 0 messages logged&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;    Buffer logging: level notifications, 1 messages logged&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;    Exception Logging: size (4096 bytes)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;    File logging: disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;    Trap logging: level informational, 27 message lines logged&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;          &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Log Buffer (4096 bytes):&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;00:37:19: %SYS-5-CONFIG_I: Configured from console by vty0 (10.0.1.4)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;To configure the mac as a syslog server follow the instructions below.&lt;br /&gt;&lt;br /&gt;1. Amend syslog.conf&lt;br /&gt;# &lt;span style="font-weight: bold;"&gt;echo "local7.debug /var/log/switch.log" &gt;&gt; /etc/syslog.conf&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;2. Create new log file&lt;br /&gt;# &lt;span style="font-weight: bold;"&gt;touch /var/log/switch.log&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;3. Change syslogd startup procedure by uncommenting the section (at the end) to accept remote logging in /System/Library/LaunchDaemons/com.apple.syslogd.plist&lt;br /&gt;&lt;br /&gt;4. Restart syslogd&lt;br /&gt;# &lt;span style="font-weight: bold;"&gt;launchctl unload /System/Library/LaunchDaemons/com.apple.syslogd.plist&lt;/span&gt;&lt;br /&gt;# &lt;span style="font-weight: bold;"&gt;launchctl load /System/Library/LaunchDaemons/com.apple.syslogd.plist&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;5. Allow syslog (/usr/bin/syslog) through the firewall.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2076617431778629795-8906745472882788746?l=ciscobasics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/8906745472882788746'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/8906745472882788746'/><link rel='alternate' type='text/html' href='http://ciscobasics.blogspot.com/2010/02/configure-logging.html' title='Configure Logging'/><author><name>SynJunkie</name><uri>http://www.blogger.com/profile/01249134797038027437</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_vZAp7b1QDw8/ScYc8FwNqTI/AAAAAAAABEw/ZFgShqSU9HI/S220/Photo+6.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-2076617431778629795.post-2215323413313600718</id><published>2010-02-06T22:47:00.003Z</published><updated>2010-02-06T22:55:37.754Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Switch'/><title type='text'>Configure a SPAN Port</title><content type='html'>In this post I will create a SPAN port on my switch to send a copy of all sent and received traffic from port 10 to port 13.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;switch1(config)#&lt;span style="font-weight: bold;"&gt;monitor session 1 source interface fastEthernet 0/10 both &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;switch1(config)#&lt;span style="font-weight: bold;"&gt;monitor session 1 destination interface fastEthernet 0/13&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;switch1(config)#&lt;span style="font-weight: bold;"&gt;end&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I verify the configuration with a show command.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;switch1#&lt;span style="font-weight: bold;"&gt;show monitor session 1&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Session 1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;---------&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt; Type       : Local Session&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Source Ports:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;    RX Only:       None&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;    TX Only:       None&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;    Both:          Fa0/10&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Source VLANs:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;    RX Only:       None&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;    TX Only:       None&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;    Both:          None&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Source RSPAN VLAN: None&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Destination Ports: Fa0/13&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;    Encapsulation: Native&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Reflector Port:    None&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Filter VLANs:      None&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Dest RSPAN VLAN:   None&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2076617431778629795-2215323413313600718?l=ciscobasics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/2215323413313600718'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/2215323413313600718'/><link rel='alternate' type='text/html' href='http://ciscobasics.blogspot.com/2010/02/configure-span-port.html' title='Configure a SPAN Port'/><author><name>SynJunkie</name><uri>http://www.blogger.com/profile/01249134797038027437</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_vZAp7b1QDw8/ScYc8FwNqTI/AAAAAAAABEw/ZFgShqSU9HI/S220/Photo+6.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-2076617431778629795.post-4600731351551980692</id><published>2010-02-05T22:52:00.008Z</published><updated>2010-02-24T22:18:33.428Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='EtherChannel'/><category scheme='http://www.blogger.com/atom/ns#' term='Switch'/><title type='text'>Configure EtherChannel</title><content type='html'>In this post I will configure 2 ports on 2 switches to be an EtherChannel.  This effectively bundles the lines to increase bandwidth and allows any link in the bundle to fail without affecting service.&lt;br /&gt;&lt;br /&gt;The diagram below shows the layout of the switches.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_vZAp7b1QDw8/S2yh_9MdW6I/AAAAAAAABgA/CDq7Btb-oco/s1600-h/Lab+Drawing.png"&gt;&lt;img style="cursor: pointer; width: 320px; height: 101px;" src="http://3.bp.blogspot.com/_vZAp7b1QDw8/S2yh_9MdW6I/AAAAAAAABgA/CDq7Btb-oco/s320/Lab+Drawing.png" alt="" id="BLOGGER_PHOTO_ID_5434896970459995042" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Before starting I make sure all interfaces that I will be configuring for EtherChannel have no configuration and are in the same VLAN.&lt;br /&gt;&lt;br /&gt;I use the following commands to configure EtherChannel on the switches.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1#&lt;span style="font-weight: bold;"&gt;conf t&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Enter configuration commands, one per line.  End with CNTL/Z.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config)#&lt;span style="font-weight: bold;"&gt;interface fastEthernet 0/1&lt;/span&gt;   &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config-if)&lt;span style="font-weight: bold;"&gt;#channel-group 5 mode desirable&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Creating a port-channel interface Port-channel 5 &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config-if)#&lt;span style="font-weight: bold;"&gt;exit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config)#&lt;span style="font-weight: bold;"&gt;interface fastEthernet 0/24&lt;/span&gt;   &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config-if)#&lt;span style="font-weight: bold;"&gt;channel-group 5 mode desirable &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Creating a port-channel interface Port-channel 5 &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config-if)#&lt;span style="font-weight: bold;"&gt;end&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2#&lt;span style="font-weight: bold;"&gt;conf t&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Enter configuration commands, one per line.  End with CNTL/Z.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2(config)#&lt;span style="font-weight: bold;"&gt;interface fastEthernet 0/1&lt;/span&gt;   &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2(config-if)#&lt;span style="font-weight: bold;"&gt;channel-group 5 mode desirable&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Creating a port-channel interface Port-channel 5 &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2(config-if)#&lt;span style="font-weight: bold;"&gt;exit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2(config)#&lt;span style="font-weight: bold;"&gt;interface fastEthernet 0/24&lt;/span&gt;   &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2(config-if)#&lt;span style="font-weight: bold;"&gt;channel-group 5 mode desirable &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Creating a port-channel interface Port-channel 5 &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2(config-if)#&lt;span style="font-weight: bold;"&gt;end&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_vZAp7b1QDw8/S2yibwiT9WI/AAAAAAAABgI/uDYJ-IG76_Y/s1600-h/Etherchannel+Drawing.png"&gt;&lt;img style="cursor: pointer; width: 320px; height: 101px;" src="http://1.bp.blogspot.com/_vZAp7b1QDw8/S2yibwiT9WI/AAAAAAAABgI/uDYJ-IG76_Y/s320/Etherchannel+Drawing.png" alt="" id="BLOGGER_PHOTO_ID_5434897448098329954" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I verify the configuration by checking the running config.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2#&lt;span style="font-weight: bold;"&gt;sh run&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Building configuration...&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Current configuration : 2447 bytes&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    ------cut------&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;interface Port-channel5&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; no ip address&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; flowcontrol send off&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;interface FastEthernet0/1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; no ip address&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; channel-group 5 mode desirable&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    -----cut--------&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;interface FastEthernet0/24&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; no ip address&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; channel-group 5 mode desirable&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;When I ping the remote switch and disconnect a cable I have no packet loss.&lt;br /&gt;&lt;br /&gt;I also use the following useful show command to view EtherChannel information.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1#&lt;span style="font-weight: bold;"&gt;sh etherchannel summary&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Flags:  D - down        P - in port-channel&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;        I - stand-alone s - suspended&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;        H - Hot-standby (LACP only)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;        R - Layer3      S - Layer2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;        u - unsuitable for bundling&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;        U - in use      f - failed to allocate aggregator&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;        d - default port&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Number of channel-groups in use: 1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Number of aggregators:           1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Group  Port-channel  Protocol    Ports&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;------+-------------+-----------+-----------------------------------------------&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;5      Po5(SU)         PAgP      Fa0/1(Pd)  Fa0/24(P)  &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2076617431778629795-4600731351551980692?l=ciscobasics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/4600731351551980692'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/4600731351551980692'/><link rel='alternate' type='text/html' href='http://ciscobasics.blogspot.com/2010/02/configure-etherchannel.html' title='Configure EtherChannel'/><author><name>SynJunkie</name><uri>http://www.blogger.com/profile/01249134797038027437</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_vZAp7b1QDw8/ScYc8FwNqTI/AAAAAAAABEw/ZFgShqSU9HI/S220/Photo+6.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_vZAp7b1QDw8/S2yh_9MdW6I/AAAAAAAABgA/CDq7Btb-oco/s72-c/Lab+Drawing.png' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-2076617431778629795.post-7163887155718372038</id><published>2010-02-05T20:30:00.011Z</published><updated>2010-02-24T22:18:48.224Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Switch'/><category scheme='http://www.blogger.com/atom/ns#' term='STP'/><title type='text'>Spanning Tree Protocol</title><content type='html'>In this post I'll be checking that Spanning Tree is working correctly between Switch1 and Switch2. Finally I will configure the non-Root Bridge as the Root and verify the configuration.&lt;br /&gt;&lt;br /&gt;The switches are connected as shown in the diagram below.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_vZAp7b1QDw8/S2yA9Ivlx5I/AAAAAAAABfw/V0ayHrfxQak/s1600-h/Lab+Drawing.png"&gt;&lt;img style="cursor: pointer; width: 320px; height: 101px;" src="http://4.bp.blogspot.com/_vZAp7b1QDw8/S2yA9Ivlx5I/AAAAAAAABfw/V0ayHrfxQak/s320/Lab+Drawing.png" alt="" id="BLOGGER_PHOTO_ID_5434860638136813458" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;I check the switches to determine which is the root switch.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1#&lt;span style="font-weight: bold;"&gt;show spanning-tree root&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;                                        Root    Hello Max Fwd&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Vlan                   Root ID          Cost    Time  Age Dly  Root Port&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;---------------- -------------------- --------- ----- --- ---  ------------&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;VLAN0001         32769 000c.8582.c600         0    2   20  15                  &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;VLAN0002         32770 000c.8582.c600         0    2   20  15                  &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1#&lt;span style="font-weight: bold;"&gt;show spanning-tree summary&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Root bridge for: VLAN0001, VLAN0002.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Extended system ID is enabled.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;PortFast BPDU Guard is disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;EtherChannel misconfiguration guard is enabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;UplinkFast is disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;BackboneFast is disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Default pathcost method used is short&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Name                   Blocking Listening Learning Forwarding STP Active&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;---------------------- -------- --------- -------- ---------- ----------&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;VLAN0001                  0        0         0        4          4      &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;VLAN0002                  0        0         0        2          2      &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;---------------------- -------- --------- -------- ---------- ----------&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;2 vlans                   0        0         0        6          6&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I can see this (Switch1) is the root bridge for both VLANs.  As this is the root bridge I check a non-root bridge (Switch2) to see which ports are in blocking mode.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2#&lt;span style="font-weight: bold;"&gt;sh spanning-tree blockedports&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Name                 Blocked Interfaces List&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;-------------------- ------------------------------------&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;VLAN0001             Fa0/24&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;VLAN0002             Fa0/24&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Number of blocked ports (segments) in the system : 2&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;From the output I can determine that port Fa0/24 on Switch2 is in blocking mode.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_vZAp7b1QDw8/S2yDXiAiyWI/AAAAAAAABf4/uaJ-VbLyeQ0/s1600-h/STP+Drawing.png"&gt;&lt;img style="cursor: pointer; width: 320px; height: 101px;" src="http://3.bp.blogspot.com/_vZAp7b1QDw8/S2yDXiAiyWI/AAAAAAAABf4/uaJ-VbLyeQ0/s320/STP+Drawing.png" alt="" id="BLOGGER_PHOTO_ID_5434863290618661218" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;To test Spanning Tree is working I ping Switch2 from a PC connected to Switch1 and disconnect the uplink on fa0/1&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;MacBook:~ syn$ &lt;span style="font-weight: bold;"&gt;ping 10.0.1.211&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;PING 10.0.1.211 (10.0.1.211): 56 data bytes&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;64 bytes from 10.0.1.211: icmp_seq=0 ttl=255 time=22.273 ms&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;64 bytes from 10.0.1.211: icmp_seq=1 ttl=255 time=4.341 ms&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Request timeout for icmp_seq 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Request timeout for icmp_seq 3&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Request timeout for icmp_seq 4&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Request timeout for icmp_seq 5&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Request timeout for icmp_seq 6&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;    --------cut----------&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Request timeout for icmp_seq 27&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Request timeout for icmp_seq 28&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Request timeout for icmp_seq 29&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Request timeout for icmp_seq 30&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Request timeout for icmp_seq 31&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Request timeout for icmp_seq 32&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;64 bytes from 10.0.1.211: icmp_seq=33 ttl=255 time=4.376 ms&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;64 bytes from 10.0.1.211: icmp_seq=34 ttl=255 time=4.117 ms&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;64 bytes from 10.0.1.211: icmp_seq=35 ttl=255 time=4.111 ms&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;^C&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;--- 10.0.1.211 ping statistics ---&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;36 packets transmitted, 5 packets received, 86.1% packet loss&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;round-trip min/avg/max/stddev = 4.111/7.844/22.273/7.216 ms&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;As can be seen from the ping results it takes 30 seconds for STP to converge and failover to port Fa0/24&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2#&lt;span style="font-weight: bold;"&gt;sh spanning-tree root&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;                                        Root Hello Max Fwd&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Vlan                   Root ID          Cost  Time Age Dly  Root Port&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;---------------- -------------------- ------ ----- --- ---  ----------------&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;VLAN0001         32769 000c.8582.c600     19    2   20  15  Fa0/24               &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;VLAN0002         32770 000c.8582.c600     19    2   20  15  Fa0/24    &lt;/span&gt;     &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Reconnecting the uplink cable causes STP to failover back to the Fa0/1 because Fa0/1 has the lowest priority.&lt;br /&gt;&lt;br /&gt;To view detailed information about Spanning Tree on a ports use the following show command.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2#&lt;span style="font-weight: bold;"&gt;show spanning-tree active detail&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;               ------cut---------&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; Port 24 (FastEthernet0/24) of VLAN0002 is blocking &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   Port path cost 19, Port priority 128, Port Identifier 128.24.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   Designated root has priority 32770, address 000c.8582.c600&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   Designated bridge has priority 32770, address 000c.8582.c600&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   Designated port id is 128.24, designated path cost 0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   Timers: message age 2, forward delay 0, hold 0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   Number of transitions to forwarding state: 4&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   Link type is point-to-point by default&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   BPDU: sent 8, received 8232&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Here I can see the ports priority details, timers and how many times the port has transitioned into a forwarding state.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;To configure Switch2 as the Root Bridge for both VLAN's I use the following command.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2(config)#&lt;span style="font-weight: bold;"&gt;spanning-tree vlan 1-2 root primary&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I verify this with the following show command.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2#&lt;span style="font-weight: bold;"&gt;show spanning-tree summary &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Switch is in pvst mode&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Root bridge for: VLAN0001-VLAN0002&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;EtherChannel misconfiguration guard is enabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Extended system ID   is enabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Portfast             is disabled by default&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;PortFast BPDU Guard  is disabled by default&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Portfast BPDU Filter is disabled by default&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Loopguard            is disabled by default&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;UplinkFast           is disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;BackboneFast         is disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Pathcost method used is short&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Name                   Blocking Listening Learning Forwarding STP Active&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;---------------------- -------- --------- -------- ---------- ----------&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;VLAN0001                     0         0        0          3          3&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;VLAN0002                     0         0        0          3          3&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;---------------------- -------- --------- -------- ---------- ----------&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;2 vlans                      0         0        0          6          6&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Switch1 being the non-Root Bridge now has interfaces in blocking state.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1#&lt;span style="font-weight: bold;"&gt;show spanning-tree blockedports&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Name                 Blocked Interfaces List&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;-------------------- ------------------------------------&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;VLAN0001             Fa0/24&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;VLAN0002             Fa0/24&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Number of blocked ports (segments) in the system : 2&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2076617431778629795-7163887155718372038?l=ciscobasics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/7163887155718372038'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/7163887155718372038'/><link rel='alternate' type='text/html' href='http://ciscobasics.blogspot.com/2010/02/spanning-tree-protocol.html' title='Spanning Tree Protocol'/><author><name>SynJunkie</name><uri>http://www.blogger.com/profile/01249134797038027437</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_vZAp7b1QDw8/ScYc8FwNqTI/AAAAAAAABEw/ZFgShqSU9HI/S220/Photo+6.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_vZAp7b1QDw8/S2yA9Ivlx5I/AAAAAAAABfw/V0ayHrfxQak/s72-c/Lab+Drawing.png' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-2076617431778629795.post-4034250537667794730</id><published>2010-02-04T23:35:00.004Z</published><updated>2010-02-24T22:19:03.077Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='VTP'/><category scheme='http://www.blogger.com/atom/ns#' term='Switch'/><title type='text'>Configure VTP</title><content type='html'>In this post I will configure VTP.  I will be working with Switch1 and Switch2.  I will configure port fa0/9 on each switch as a trunk port, configure VTP for the domain lab.local with a VTP password of cisco.  I will configure Switch2 to be a VTP Client.  Finally I will verify VTP is working with some useful show and  debugging commands.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Switch 1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1#&lt;span style="font-weight: bold;"&gt;conf t&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Enter configuration commands, one per line.  End with CNTL/Z.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config)#&lt;span style="font-weight: bold;"&gt;int fastEthernet 0/9&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config-if)#&lt;span style="font-weight: bold;"&gt;switchport mode trunk&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config-if)#&lt;span style="font-weight: bold;"&gt;exit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config)#&lt;span style="font-weight: bold;"&gt;vtp domain lab.local&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Changing VTP domain name from NULL to lab.local&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config)#&lt;span style="font-weight: bold;"&gt;vtp password cisco&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Setting device VLAN database password to cisco.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config)#&lt;span style="font-weight: bold;"&gt;end&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1#&lt;span style="font-weight: bold;"&gt;sh vtp status&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;VTP Version                     : 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Configuration Revision          : 0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Maximum VLANs supported locally : 64&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Number of existing VLANs        : 6&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;VTP Operating Mode              : Server&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;VTP Domain Name                 : lab.local&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;VTP Pruning Mode                : Disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;VTP V2 Mode                     : Disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;VTP Traps Generation            : Disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;MD5 digest                      : 0x12 0xBF 0xAA 0x37 0xDC 0x26 0xF2 0x03 &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Configuration last modified by 10.0.1.210 at 3-1-93 03:11:00&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Local updater ID is 10.0.1.210 on interface Vl1 (lowest numbered VLAN interface found)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Switch2&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2#&lt;span style="font-weight: bold;"&gt;conf t&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Enter configuration commands, one per line.  End with CNTL/Z.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2(config)#&lt;span style="font-weight: bold;"&gt;interface fastEthernet 0/9&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2(config-if)#&lt;span style="font-weight: bold;"&gt;switchport mode trunk&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2(config-if)#&lt;span style="font-weight: bold;"&gt;exit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2(config)#&lt;span style="font-weight: bold;"&gt;vtp domain lab.local&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Changing VTP domain name from NULL to lab.local&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2(config)#&lt;span style="font-weight: bold;"&gt;vtp password cisco&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Setting device VLAN database password to cisco&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2(config)#&lt;span style="font-weight: bold;"&gt;vtp mode client&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Setting device to VTP CLIENT mode.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2(config)#&lt;span style="font-weight: bold;"&gt;end&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2#&lt;span style="font-weight: bold;"&gt;sh vtp status &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;VTP Version                     : 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Configuration Revision          : 0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Maximum VLANs supported locally : 64&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Number of existing VLANs        : 6&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;VTP Operating Mode              : Client&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;VTP Domain Name                 : lab.local&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;VTP Pruning Mode                : Disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;VTP V2 Mode                     : Disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;VTP Traps Generation            : Disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;MD5 digest                      : 0x12 0xBF 0xAA 0x37 0xDC 0x26 0xF2 0x03 &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Configuration last modified by 10.0.1.210 at 3-1-93 03:11:00&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Turn on debugging for VTP events on Switch2&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2#&lt;span style="font-weight: bold;"&gt;terminal monitor&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2#&lt;span style="font-weight: bold;"&gt;debug sw-vlan vtp events&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;vtp events debugging is on&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Create a new VLAN on Switch1&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1#&lt;span style="font-weight: bold;"&gt;conf t&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Enter configuration commands, one per line.  End with CNTL/Z.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config)#&lt;span style="font-weight: bold;"&gt;vlan 3&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config-vlan)#&lt;span style="font-weight: bold;"&gt;name test-vlan&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config-vlan)#&lt;span style="font-weight: bold;"&gt;end&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Switch2 displays the VTP events.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;00:11:10: VTP LOG RUNTIME: Summary packet received, domain = lab.local, rev = 1, followers = 1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;00:11:10: VTP LOG RUNTIME: Summary packet rev 1 greater than domain lab.local rev 0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;00:11:10: VTP LOG RUNTIME: Domain lab.local currently not in updating state&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;00:11:10: VTP LOG RUNTIME: Subset packet received, domain = lab.local, rev = 1, seq = 1, length = 244&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;00:11:10: VTP LOG RUNTIME: Transmit vtp summary, domain lab.local, rev 1, followers 1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   MD5 digest calculated = C5 62 5F 4A 7B 07 69 C7 0E CD E9 42 0E 7C AF 5C&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;I verify that the VTP revision number has incremented on switch2&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2#&lt;span style="font-weight: bold;"&gt;sh vtp status&lt;/span&gt;           &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;VTP Version                     : 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Configuration Revision          : 1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Maximum VLANs supported locally : 64&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Number of existing VLANs        : 7&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;VTP Operating Mode              : Client&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;VTP Domain Name                 : lab.local&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;VTP Pruning Mode                : Disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;VTP V2 Mode                     : Disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;VTP Traps Generation            : Disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;MD5 digest                      : 0xC5 0x62 0x5F 0x4A 0x7B 0x07 0x69 0xC7 &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Configuration last modified by 10.0.1.210 at 3-1-93 00:20:13&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Attempts to create a VLAN on switch2 fails as it is in Client mode&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2#&lt;span style="font-weight: bold;"&gt;conf t&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Enter configuration commands, one per line.  End with CNTL/Z.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch2(config)#&lt;span style="font-weight: bold;"&gt;vlan 4&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;VTP VLAN configuration not allowed when device is in CLIENT mode.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2076617431778629795-4034250537667794730?l=ciscobasics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/4034250537667794730'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/4034250537667794730'/><link rel='alternate' type='text/html' href='http://ciscobasics.blogspot.com/2010/02/configure-vtp.html' title='Configure VTP'/><author><name>SynJunkie</name><uri>http://www.blogger.com/profile/01249134797038027437</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_vZAp7b1QDw8/ScYc8FwNqTI/AAAAAAAABEw/ZFgShqSU9HI/S220/Photo+6.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-2076617431778629795.post-5981113625505180589</id><published>2010-02-03T21:51:00.006Z</published><updated>2010-02-24T22:19:16.736Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Router'/><category scheme='http://www.blogger.com/atom/ns#' term='SSH'/><title type='text'>Configure SSH</title><content type='html'>In this post I will configure SSH version 2 on the router to have a 1024 bit key, allow 3 failed login attempt and set time-out to 30 mins.  I will then configure my vty ports to use either telnet or SSH and I will enable aaa new-model and create a user called syn with a password of cisco.  Lastly I will check my running config and use a show command to view the setup.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1#&lt;span style="font-weight: bold;"&gt;conf t&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Enter configuration commands, one per line.  End with CNTL/Z.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(config)#&lt;span style="font-weight: bold;"&gt;ip domain-name lab.local&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(config)#&lt;span style="font-weight: bold;"&gt;crypto key generate rsa general-keys modulus 1024 &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;The name for the keys will be: router1.lab.local&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;% The key modulus size is 1024 bits&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;% Generating 1024 bit RSA keys, keys will be non-exportable...[OK]&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(config)#&lt;span style="font-weight: bold;"&gt;ip ssh authentication-retries 3&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(config)#&lt;span style="font-weight: bold;"&gt;ip ssh time-out 30&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(config)#&lt;span style="font-weight: bold;"&gt;ip ssh version 2&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(config)#&lt;span style="font-weight: bold;"&gt;line vty 0 4 &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(config-line)#&lt;span style="font-weight: bold;"&gt;transport input ssh telnet &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(config-line)#&lt;span style="font-weight: bold;"&gt;end&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1#&lt;span style="font-weight: bold;"&gt;conf t&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Enter configuration commands, one per line.  End with CNTL/Z.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(config)#&lt;span style="font-weight: bold;"&gt;aaa new-model&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(config)#&lt;span style="font-weight: bold;"&gt;username syn secret cisco&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(config)#&lt;span style="font-weight: bold;"&gt;end&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1#&lt;span style="font-weight: bold;"&gt;show run&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Building configuration...&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Current configuration : 1564 bytes&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;version 12.4&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;aaa new-model&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;ip domain name lab.local&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;ip ssh time-out 30&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;ip ssh source-interface Ethernet0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;ip ssh version 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;username syn secret 5 $1$mU38$MPCu0GOeTzhKnQBNMKxe30&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;line vty 0 4&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; exec-timeout 0 0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; password 7 02050D480809&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; logging synchronous&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; transport input telnet ssh&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;end&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;&lt;br /&gt;&lt;br /&gt;router1#&lt;span style="font-weight: bold;"&gt;show ip ssh&lt;/span&gt;&lt;br /&gt;SSH Enabled - version 2.0&lt;br /&gt;Authentication timeout: 30 secs; Authentication retries: 3&lt;br /&gt;router1#&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2076617431778629795-5981113625505180589?l=ciscobasics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/5981113625505180589'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/5981113625505180589'/><link rel='alternate' type='text/html' href='http://ciscobasics.blogspot.com/2010/02/configure-ssh.html' title='Configure SSH'/><author><name>SynJunkie</name><uri>http://www.blogger.com/profile/01249134797038027437</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_vZAp7b1QDw8/ScYc8FwNqTI/AAAAAAAABEw/ZFgShqSU9HI/S220/Photo+6.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-2076617431778629795.post-5814402037415944484</id><published>2010-02-03T20:55:00.006Z</published><updated>2010-02-24T22:19:30.921Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Port Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Switch'/><title type='text'>Port Security</title><content type='html'>In this post I will configure a port with port security as sticky port (will learn the first mac address).  I then configure the switch to re-enable the port after 2 minutes of shutdown.&lt;br /&gt;&lt;br /&gt;Finally I will use some useful show commands to view the interface configuration, state of the port and verify that the correct settings are in the running config.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1#&lt;span style="font-weight: bold;"&gt;conf t&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Enter configuration commands, one per line.  End with CNTL/Z.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config)#&lt;span style="font-weight: bold;"&gt;interface fastEthernet 0/17&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config-if)#&lt;span style="font-weight: bold;"&gt;switchport port-security &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config-if)#&lt;span style="font-weight: bold;"&gt;switchport port-security mac-address sticky&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config-if)#&lt;span style="font-weight: bold;"&gt;end&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config)#&lt;span style="font-weight: bold;"&gt;errdisable recovery cause psecure-violation&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config)#&lt;span style="font-weight: bold;"&gt;errdisable recovery interval 120&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1#&lt;span style="font-weight: bold;"&gt;sh run interface fastEthernet 0/17&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Building configuration...&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Current configuration : 254 bytes&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;interface FastEthernet0/17&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; switchport access vlan 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; switchport mode access&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; switchport port-security&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; switchport port-security mac-address sticky&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; switchport port-security mac-address sticky 001e.68ff.d35f&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; no ip address&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; spanning-tree portfast&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;end&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1#&lt;span style="font-weight: bold;"&gt;show port-security interface fastEthernet 0/17&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Port Security : Enabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Port status : SecureUp&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Violation mode : Shutdown&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Maximum MAC Addresses : 1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Total MAC Addresses : 1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Configured MAC Addresses : 0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Sticky MAC Addresses : 1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Aging time : 0 mins&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Aging type : Absolute&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;SecureStatic address aging : Disabled&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Security Violation count : 0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1#&lt;span style="font-weight: bold;"&gt;show port-security address &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;          Secure Mac Address Table&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;-------------------------------------------------------------------&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Vlan    Mac Address       Type                Ports   Remaining Age&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;                                                         (mins)    &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;----    -----------       ----                -----   -------------&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   2    001e.68ff.d35f    SecureSticky        Fa0/17      -&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;-------------------------------------------------------------------&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Total Addresses in System : 1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Max Addresses limit in System : 1024&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;switch1#&lt;span style="font-weight: bold;"&gt;show running-config | include errdisable&lt;/span&gt;&lt;br /&gt;errdisable recovery cause psecure-violation&lt;br /&gt;errdisable recovery interval 120&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2076617431778629795-5814402037415944484?l=ciscobasics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/5814402037415944484'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/5814402037415944484'/><link rel='alternate' type='text/html' href='http://ciscobasics.blogspot.com/2010/02/port-security.html' title='Port Security'/><author><name>SynJunkie</name><uri>http://www.blogger.com/profile/01249134797038027437</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_vZAp7b1QDw8/ScYc8FwNqTI/AAAAAAAABEw/ZFgShqSU9HI/S220/Photo+6.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-2076617431778629795.post-4011141279139228473</id><published>2010-02-03T20:03:00.006Z</published><updated>2010-02-24T22:19:44.311Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Router'/><category scheme='http://www.blogger.com/atom/ns#' term='DHCP'/><title type='text'>Useful DHCP Show Commands</title><content type='html'>In this post I will demonstrate a few useful show commands that will help me see the state of the routers DHCP server which I set up in the previous post.&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;show ip dhcp binding&lt;/li&gt;&lt;li&gt;show ip dhcp pool&lt;/li&gt;&lt;li&gt;show ip dhcp server statistics&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;These commands were run after a computer was issued the IP 10.0.2.1 from the dmz pool.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1#&lt;span style="font-weight: bold;"&gt;show ip dhcp binding&lt;/span&gt;           &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Bindings from all pools not associated with VRF:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;IP address          Client-ID/             Lease expiration        Type&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;            Hardware address/&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;            User name&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;10.0.2.1            0100.1e68.ffd3.5f       Oct 13 2009 10:08 PM    Automatic&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1#&lt;span style="font-weight: bold;"&gt;show ip dhcp pool&lt;/span&gt;              &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Pool dmz :&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; Utilization mark (high/low)    : 100 / 0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; Subnet size (first/next)       : 0 / 0 &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; Total addresses                : 254&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; Leased addresses               : 1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; Pending event                  : none&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; 1 subnet is currently in the pool :&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; Current index        IP address range                    Leased addresses&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; 10.0.2.2             10.0.2.1         - 10.0.2.254        1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1#&lt;span style="font-weight: bold;"&gt;show ip dhcp server statistics&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Memory usage         23991&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Address pools        1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Database agents      0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Automatic bindings   1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Manual bindings      0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Expired bindings     0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Malformed messages   9&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Secure arp entries   0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Message              Received&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;BOOTREQUEST          0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;DHCPDISCOVER         8&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;DHCPREQUEST          12&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;DHCPDECLINE          0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;DHCPRELEASE          0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;DHCPINFORM           5&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Message              Sent&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;BOOTREPLY            0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;DHCPOFFER            1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;DHCPACK              4&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;DHCPNAK              0&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2076617431778629795-4011141279139228473?l=ciscobasics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/4011141279139228473'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/4011141279139228473'/><link rel='alternate' type='text/html' href='http://ciscobasics.blogspot.com/2010/02/useful-dhcp-show-commands.html' title='Useful DHCP Show Commands'/><author><name>SynJunkie</name><uri>http://www.blogger.com/profile/01249134797038027437</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_vZAp7b1QDw8/ScYc8FwNqTI/AAAAAAAABEw/ZFgShqSU9HI/S220/Photo+6.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-2076617431778629795.post-2161093846162074944</id><published>2010-02-02T23:04:00.006Z</published><updated>2010-02-24T22:20:03.017Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Router'/><category scheme='http://www.blogger.com/atom/ns#' term='DHCP'/><title type='text'>Confgure a DHCP Server</title><content type='html'>In this post I will configure DHCP Settings on my router.  I turn on the DHCP service, create a pool and configure it with an IP range, domain name, DNS server, default router and lease.  I add in exclusions for the addresses I do not want leased.  Finally I check the running config.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(config)#&lt;span style="font-weight: bold;"&gt;service dhcp&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(config)#&lt;span style="font-weight: bold;"&gt;ip dhcp pool dmz&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(dhcp-config)#&lt;span style="font-weight: bold;"&gt;network 10.0.2.0 /24&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(dhcp-config)#&lt;span style="font-weight: bold;"&gt;domain-name lab.local&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(dhcp-config)#&lt;span style="font-weight: bold;"&gt;dns-server 8.8.8.8&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(dhcp-config)#&lt;span style="font-weight: bold;"&gt;default-router 10.0.2.254&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(dhcp-config)#&lt;span style="font-weight: bold;"&gt;lease 7&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(dhcp-config)#&lt;span style="font-weight: bold;"&gt;exit&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(config)#&lt;span style="font-weight: bold;"&gt;ip dhcp excluded-address 10.0.2.10 10.0.2.255&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1(config)#&lt;span style="font-weight: bold;"&gt;end&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;router1#&lt;span style="font-weight: bold;"&gt;sh run&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;ip subnet-zero&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;no ip dhcp use vrf connected&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;ip dhcp excluded-address 10.0.2.10 10.0.2.255&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;ip dhcp pool dmz&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   network 10.0.2.0 255.255.255.0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   domain-name lab.local&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   dns-server 8.8.8.8 &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   default-router 10.0.2.254 &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;   lease 7&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2076617431778629795-2161093846162074944?l=ciscobasics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/2161093846162074944'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/2161093846162074944'/><link rel='alternate' type='text/html' href='http://ciscobasics.blogspot.com/2010/02/confgure-dhcp-server.html' title='Confgure a DHCP Server'/><author><name>SynJunkie</name><uri>http://www.blogger.com/profile/01249134797038027437</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_vZAp7b1QDw8/ScYc8FwNqTI/AAAAAAAABEw/ZFgShqSU9HI/S220/Photo+6.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-2076617431778629795.post-1108448210152859803</id><published>2010-02-02T22:33:00.004Z</published><updated>2010-02-06T19:37:55.752Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Router'/><category scheme='http://www.blogger.com/atom/ns#' term='Switch'/><title type='text'>Create a Static Host Mapping</title><content type='html'>In this post I will create a static host entry for router on the IP address 10.0.1.254.  I check the configuration with the show hosts command.  Finally I ping 10.0.1.254 using the host name.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1#&lt;span style="font-weight: bold;"&gt;ping router&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Translating "router"&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;% Unrecognized host or address, or protocol not running.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1#&lt;span style="font-weight: bold;"&gt;conf t&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Enter configuration commands, one per line.  End with CNTL/Z.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config)#&lt;span style="font-weight: bold;"&gt;ip host router 10.0.1.254&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config)#&lt;span style="font-weight: bold;"&gt;end&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;switch1#&lt;span style="font-weight: bold;"&gt;show hosts&lt;/span&gt;&lt;br /&gt;Default domain is not set&lt;br /&gt;Name/address lookup uses static mappings&lt;br /&gt;&lt;br /&gt;Host                      Port  Flags      Age Type   Address(es)&lt;br /&gt;router                    None  (perm, OK)  0   IP    10.0.1.254&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1#&lt;span style="font-weight: bold;"&gt;ping router&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Type escape sequence to abort.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Sending 5, 100-byte ICMP Echos to 10.0.1.254, timeout is 2 seconds:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!!!!!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 1/3/4 ms&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2076617431778629795-1108448210152859803?l=ciscobasics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/1108448210152859803'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/1108448210152859803'/><link rel='alternate' type='text/html' href='http://ciscobasics.blogspot.com/2010/02/create-static-host-mapping.html' title='Create a Static Host Mapping'/><author><name>SynJunkie</name><uri>http://www.blogger.com/profile/01249134797038027437</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_vZAp7b1QDw8/ScYc8FwNqTI/AAAAAAAABEw/ZFgShqSU9HI/S220/Photo+6.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-2076617431778629795.post-8248440299110743203</id><published>2010-02-02T22:13:00.005Z</published><updated>2010-02-06T19:38:33.721Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Router'/><category scheme='http://www.blogger.com/atom/ns#' term='Switch'/><title type='text'>Create a MOTD Banner</title><content type='html'>In this post I will create a MOTD banner for my switch and verify the configuration with a show command.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1#&lt;span style="font-weight: bold;"&gt;conf t&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config)#&lt;span style="font-weight: bold;"&gt;banner motd $ Authorised Access Only $&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config)#&lt;span style="font-weight: bold;"&gt;end&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1#&lt;span style="font-weight: bold;"&gt;sh run | include banner&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;banner motd ^C Authorised Access Only ^C&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1#&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2076617431778629795-8248440299110743203?l=ciscobasics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/8248440299110743203'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/8248440299110743203'/><link rel='alternate' type='text/html' href='http://ciscobasics.blogspot.com/2010/02/create-motd-banner.html' title='Create a MOTD Banner'/><author><name>SynJunkie</name><uri>http://www.blogger.com/profile/01249134797038027437</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_vZAp7b1QDw8/ScYc8FwNqTI/AAAAAAAABEw/ZFgShqSU9HI/S220/Photo+6.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-2076617431778629795.post-5571431798595229229</id><published>2010-02-02T22:00:00.006Z</published><updated>2010-02-06T19:39:26.594Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Router'/><category scheme='http://www.blogger.com/atom/ns#' term='Switch'/><title type='text'>Configure Switch VTY Ports</title><content type='html'>In this post I will configure all my VTY (Telnet ports) to have logging synchronous and a 30 minute exec timeout (max idle time). I give the ports a password of cisco, configure the switch to require a login on the VTY ports and display the motd banner.   Finally I use a show command to check the running config.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1#&lt;span style="font-weight: bold;"&gt;conf t&lt;/span&gt;        &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config)#&lt;span style="font-weight: bold;"&gt;line vty 0 15&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config-line)#&lt;span style="font-weight: bold;"&gt;logging synchronous &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config-line)#&lt;span style="font-weight: bold;"&gt;exec-timeout 30 0&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config-line)#&lt;span style="font-weight: bold;"&gt;password cisco&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config-line)#&lt;span style="font-weight: bold;"&gt;login&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config-line)#&lt;span style="font-weight: bold;"&gt;motd-banner &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config-line)#&lt;span style="font-weight: bold;"&gt;end&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1#&lt;span style="font-weight: bold;"&gt;sh run | begin line vty&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;line vty 0 4&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; exec-timeout 30 0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; password 7 01100F175804&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; logging synchronous&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; login&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;line vty 5 15&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; exec-timeout 30 0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; password 7 01100F175804&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; logging synchronous&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; login&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;end&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2076617431778629795-5571431798595229229?l=ciscobasics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/5571431798595229229'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/5571431798595229229'/><link rel='alternate' type='text/html' href='http://ciscobasics.blogspot.com/2010/02/configure-switch-vty-ports.html' title='Configure Switch VTY Ports'/><author><name>SynJunkie</name><uri>http://www.blogger.com/profile/01249134797038027437</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_vZAp7b1QDw8/ScYc8FwNqTI/AAAAAAAABEw/ZFgShqSU9HI/S220/Photo+6.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-2076617431778629795.post-2634713993202782922</id><published>2010-02-02T21:40:00.011Z</published><updated>2010-02-24T22:20:22.860Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='VLAN'/><category scheme='http://www.blogger.com/atom/ns#' term='Switch'/><title type='text'>Creating a VLAN</title><content type='html'>In this post I list the commands to create VLAN 2, name it to dmz and place a range of ports in the VLAN.  Finally I use a show command to look at the VLAN configuration.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1#&lt;span style="font-weight: bold;"&gt;conf t&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config)#&lt;span style="font-weight: bold;"&gt;vlan 2&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config-vlan)#&lt;span style="font-weight: bold;"&gt;name dmz&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config-vlan)#&lt;span style="font-weight: bold;"&gt;end&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1#&lt;span style="font-weight: bold;"&gt;conf t&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config)#&lt;span style="font-weight: bold;"&gt;interface range FastEthernet 0/17 - 24&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config-if-range)#&lt;span style="font-weight: bold;"&gt;switchport access vlan 2&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1(config-if-range)#&lt;span style="font-weight: bold;"&gt;end&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;switch1#&lt;span style="font-weight: bold;"&gt;sh vlan brief&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2076617431778629795-2634713993202782922?l=ciscobasics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/2634713993202782922'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/2634713993202782922'/><link rel='alternate' type='text/html' href='http://ciscobasics.blogspot.com/2010/02/creating-vlan.html' title='Creating a VLAN'/><author><name>SynJunkie</name><uri>http://www.blogger.com/profile/01249134797038027437</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_vZAp7b1QDw8/ScYc8FwNqTI/AAAAAAAABEw/ZFgShqSU9HI/S220/Photo+6.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-2076617431778629795.post-6204917406647386983</id><published>2010-01-30T20:32:00.003Z</published><updated>2010-02-06T19:40:40.570Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='Router'/><category scheme='http://www.blogger.com/atom/ns#' term='Switch'/><title type='text'>Show Version</title><content type='html'>The show version command is very useful.  From running the command I can see the following useful pieces of information about my router.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Model&lt;/li&gt;&lt;li&gt;Uptime&lt;/li&gt;&lt;li&gt;IOS Version &amp;amp; software release&lt;/li&gt;&lt;li&gt;CPU, RAM, NVRAM &amp;amp; Flash details&lt;/li&gt;&lt;li&gt;Configuration Register setting&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;Router&amp;gt;&lt;span style="font-weight: bold;"&gt;show version&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;Cisco IOS Software, 3600 Software (C3640-JK9S-M), Version 12.4(16), RELEASE SOFTWARE (fc1)&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;Technical Support: http://www.cisco.com/techsupport&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;Copyright (c) 1986-2007 by Cisco Systems, Inc.&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;Compiled Wed 20-Jun-07 11:43 by prod_rel_team&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;ROM: ROMMON Emulation Microcode&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;ROM: 3600 Software (C3640-JK9S-M), Version 12.4(16), RELEASE SOFTWARE (fc1)&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;Router uptime is 1 minute&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;System returned to ROM by unknown reload cause - suspect boot_data[BOOT_COUNT] 0x0, BOOT_COUNT 0, BOOTDATA 19&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;System image file is "tftp://255.255.255.255/unknown"&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;Cisco 3640 (R4700) processor (revision 0xFF) with 124928K/6144K bytes of memory.&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;Processor board ID 00000000&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;R4700 CPU at 100MHz, Implementation 33, Rev 1.2&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;DRAM configuration is 64 bits wide with parity enabled.&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;125K bytes of NVRAM.&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;8192K bytes of processor board System flash (Read/Write)&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;Configuration register is 0x2142&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;Router&amp;gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2076617431778629795-6204917406647386983?l=ciscobasics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/6204917406647386983'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/6204917406647386983'/><link rel='alternate' type='text/html' href='http://ciscobasics.blogspot.com/2010/01/show-version.html' title='Show Version'/><author><name>SynJunkie</name><uri>http://www.blogger.com/profile/01249134797038027437</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_vZAp7b1QDw8/ScYc8FwNqTI/AAAAAAAABEw/ZFgShqSU9HI/S220/Photo+6.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-2076617431778629795.post-1515751700102301394</id><published>2010-01-30T14:45:00.002Z</published><updated>2010-01-30T14:53:03.396Z</updated><title type='text'>Introduction</title><content type='html'>I will be using this blog to post notes of the commands used to configure firewalls, routers and switches in my lab. The posts are primarily created to help me as a study aid, if they help you too then that's great.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2076617431778629795-1515751700102301394?l=ciscobasics.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/1515751700102301394'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2076617431778629795/posts/default/1515751700102301394'/><link rel='alternate' type='text/html' href='http://ciscobasics.blogspot.com/2010/01/introduction.html' title='Introduction'/><author><name>SynJunkie</name><uri>http://www.blogger.com/profile/01249134797038027437</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://2.bp.blogspot.com/_vZAp7b1QDw8/ScYc8FwNqTI/AAAAAAAABEw/ZFgShqSU9HI/S220/Photo+6.jpg'/></author></entry></feed>
