128
Bringing a True-long Stand Vocation CCNA CCNA www.saigonlab.vn

SaigonLAB CCNA Module7 Va Module 8

Embed Size (px)

Citation preview

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 1/128

Bringing a True-long Stand Vocation

CCNACCNAwww.saigonlab.vn

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 2/128

Bringing a True-long Stand Vocation 2

www.saigonlab.vn

Module 7: NAT and ACLs

The purpose and types of ACLs1

Configure and apply an ACLs2

The basic operation of NAT3

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 3/128

Bringing a True-long Stand Vocation 3

www.saigonlab.vn

Lesson 1: The purpose and types ofACLs

ACL Overview ACL Applications

Types of ACLs ACL Operations ACL Statement Processing

Wildcard Mas ing Process

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 4/128

Bringing a True-long Stand Vocation 4

www.saigonlab.vn

Lesson 1: The purpose and types ofACLs

W!y "se ACLs#

Manage $P traffic as networ access grows%ilter pac ets as t!ey pass t!ro&g! t!e ro&ter

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 5/128

Bringing a True-long Stand Vocation 5

www.saigonlab.vn

Lesson 1: The purpose and types ofACLs

ACL Applications

Permit or deny pac ets moving t!ro&g! t!e ro&ter Permit or deny vty access to or from t!e ro&ter Wit!o&t ACLs' all pac ets co&ld (e transmitted onto allparts of yo&r networ

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 6/128

Bringing a True-long Stand Vocation 6

www.saigonlab.vn

Lesson 1: The purpose and types ofACLs

Ot!er ACL "ses

pecial handling for traffic based on pac!et tests

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 7/128Bringing a True-long Stand Vocation 7

www.saigonlab.vn

Lesson 1: The purpose and types ofACLs

Types of ACLs

Standard ACL) C!ec s so&rce address) *enerally permits or denies entire protocol s&ite

"#tended ACL) C!ec s so&rce and destination address) *enerally permits or denies specific protocols

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 8/128Bringing a True-long Stand Vocation 8

www.saigonlab.vn

Lesson 1: The purpose and types ofACLs

+ow to $dentify ACLs

Standard $P lists ,1-../ test conditions of all $Ppac ets from so&rce addresses0 tended $P lists ,1 -1../ test conditions ofso&rce and destination addresses' specificTCP $P protocols' and destination ports

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 9/128Bringing a True-long Stand Vocation 9

www.saigonlab.vn

Lesson 1: The purpose and types ofACLs

+ow to $dentify ACLsStandard $P lists ,13 -1.../ ,e panded range/0 tended $P lists ,2 -24../ ,e panded range/Ot!er ACL n&m(er ranges test conditions forot!er networ ing protocols5amed ACLs identify $P standard and e tended

ACLs wit! an alp!an&meric string ,name/

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 10/128Bringing a True-long Stand Vocation 10

www.saigonlab.vn

Lesson 1: The purpose and types ofACLs

Testing Pac ets wit! Standard ACLs

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 11/128

Bringing a True-long Stand Vocation 11

www.saigonlab.vn

Lesson 1: The purpose and types ofACLs

Testing Pac ets wit! 0 tended ACLs

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 12/128

Bringing a True-long Stand Vocation 12

www.saigonlab.vn

Lesson 1: The purpose and types ofACLs

O&t(o&nd ACL Operation

$f no ACL state%ent %atches& discard the pac!et

'utbound$nterfaces

(ac!et

(ac!et

Notify ender (ac!et)iscard*uc!et

$nbound$nterface

(ac!et

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 13/128

Bringing a True-long Stand Vocation 13

www.saigonlab.vn

Lesson 1: The purpose and types ofACLs

A List of Tests6 7eny or Permit

(ac!et)iscard*uc!et

$nterface+s,

)estination

$f no Match deny All

(ac!et to $nterface+s, inthe Access -roup

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 14/128

Bringing a True-long Stand Vocation 14

www.saigonlab.vn

Lesson 1: The purpose and types ofACLs

Wildcard 8its6 +ow to C!ec t!eCorresponding Address 8its

means c!ec val&e of corresponding address (it1 means ignore val&e of corresponding address (it

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 15/128

Bringing a True-long Stand Vocation 15

www.saigonlab.vn

Lesson 1: The purpose and types ofACLs

Wildcard Bits to Match a Specific IPHost AddressChec! all of the address bits +%atch all,

erify an $( host address& for e#a%ple:

) 192:3 :14:2. : : : c!ec s all of t!e address (its) A((reviate t!is wildcard mas &sing t!e $P address

preceded (y t!e eyword !ost , !ost 192:3 :14:2. /

h d f

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 16/128

Bringing a True-long Stand Vocation 16

www.saigonlab.vn

Lesson 1: The purpose and types ofACLs

Wildcard 8its to Matc! Any $P AddressTest conditions: $gnore all the address bits+%atch any,An $( host address& for e#a%ple:

) Accept any address: any) Abbreviate e#pression with !eyword / any 0

h d f

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 17/128

Bringing a True-long Stand Vocation 17

www.saigonlab.vn

Lesson 1: The purpose and types ofACLs

Wildcard 8its to Matc! $P S&(netsChec! for $( subnets 17 .23. 14 .35 6 to17 .23. 21 .35 6

) Address and wildcard mas 6 192:3 :14:: :1;:2;;

L C fi d l

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 18/128

Bringing a True-long Stand Vocation 18

www.saigonlab.vn

Lesson : Configure and apply anACLs

$mplementing ACLs Config&ring Standard $P ACLs

Config&ring 0 tended $P ACLs "sing 5amed ACLs Config&ring vty ACLs

*&idelines for Placing ACLs <erifying t!e ACL Config&ration

L C fi d l

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 19/128

Bringing a True-long Stand Vocation 19

www.saigonlab.vn

Lesson : Configure and apply anACLs

ACL Config&ration *&idelines ACL n&m(ers indicate w!ic! protocol is filteredOne ACL per interface' per protocol' perdirection is allowedT!e order of ACL statements controls testingT!e most restrictive statements go at t!e top oft!e listT!e last ACL test is always an implicit deny anystatement' so every list needs at least onepermit statement

ACLs m&st (e created (efore applying t!em tointerfaces

ACLs filter traffic going t!ro&g! t!e ro&ter: ACLsdo not filter traffic originating from t!e ro&ter

L C fi d l

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 20/128

Bringing a True-long Stand Vocation 20

www.saigonlab.vn

Lesson : Configure and apply anACLs

ACL Commandtep 1: et para%eters for this ACL teststate%ent +which can be one of severalstate%ents,

tep : "nable an interface to use thespecified ACL

) Standard $P lists ,1-../) 0 tended $P lists ,1 -1../

outer+config,8access9list access-list-number

per%it ; deny< test conditions <

outer+config9if,8 protocol < access9groupaccess-list-number in ; out<

L C fi d l

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 21/128

Bringing a True-long Stand Vocation 21

www.saigonlab.vn

Lesson : Configure and apply anACLs

Standard $P ACL Config&ration

Sets parameters for t!is list entry$P standard ACLs &se 1 to ..

7efa&lt wildcard mas = : : :no access9list access-list-number removes entire ACLremar lets yo& add a description for t!e ACL

Activates t!e list on an interfaceSets in(o&nd or o&t(o&nd testing7efa&lt = o&t(o&ndno ip access9group access-list-number removes ACLfrom t!e interface

Router(config)#access-list access-list-number{permit | deny | remark} source [ mask ]

Router(config-if)#ip access-groupaccess-list-number {in | out}

L C fi d l

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 22/128

Bringing a True-long Stand Vocation 22

www.saigonlab.vn

Lesson : Configure and apply anACLs

Standard $P ACL - 0 ample 1

Permit my networ only

outer+config,8 access9list 1 per%it 17 .14.3.3 3.3. ==. ==+$%plicit deny all > not visible in the List,+access9list 1 deny 3.3.3.3 ==. ==. ==. ==,

outer+config,8 interface ethernet 3outer+config,8 ip access9group 1 outouter+config,8 interface ethernet 1outer+config,8 ip access9group 1 out

L C fi d l

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 23/128

Bringing a True-long Stand Vocation 23

www.saigonlab.vn

Lesson : Configure and apply anACLs

Standard $P ACL - 0 ample 2

7eny a specific !ost

outer+config,8 access9list 1 deny 17 .14.6.12 3.3.3.3outer+config,8 access9list 1 per%it 3.3.3.3 ==. ==. ==. ==

+i%plicit e deny all,+access9list 1 deny 3.3.3.3 ==. ==. ==. ==,

outer+config,8 interface ethernet 3outer+config,8 ip access9group 1 out

L C fig d l

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 24/128

Bringing a True-long Stand Vocation 24

www.saigonlab.vn

Lesson : Configure and apply anACLs

Standard $P ACL - 0 ample 3

7eny a specific s&(net

outer+config,8 access9list 1 deny 17 .14.6.3 3.3.3. ==outer+config,8 access9list 1 per%it any

+i%plicit e deny all,+access9list 1 deny 3.3.3.3 ==. ==. ==. ==,

outer+config,8 interface ethernet 3outer+config,8 ip access9group 1 out

L C fig d l

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 25/128

Bringing a True-long Stand Vocation 25

www.saigonlab.vn

Lesson : Configure and apply anACLs

0 tended $P ACL Config&ration

Sets parameters for t!is list entry

Activates t!e e tended list on an interface

Router(config)#access-list access-list-number {permit | deny} protocol source source-wildcard[ operator port ] destination destination-wildcard

[ operator port ] [established] [log]

Router(config-if)#ip access-group access-list-number {in | out}

Lesson : Config re and appl an

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 26/128

Bringing a True-long Stand Vocation 26

www.saigonlab.vn

Lesson : Configure and apply anACLs

0 tended ACL - 0 ample 1

7eny %TP from s&(net 192:14:>: to s&(net 192:14:3: o&t 0Permit all ot!er traffic

outer+config,8 access9list 131 deny tcp 17 .14.6.3 3.3.3. == 17 .14.2.3 3.3.3. == e? 1outer+config,8 access9list 131 deny tcp 17 .14.6.3 3.3.3. == 17 .14.2.3 3.3.3. == e? 3outer+config,8 access9list 131 per%it ip any any

+i%plicit e deny all,

+access9list 1 deny 3.3.3.3 ==. ==. ==. == 3.3.3.3 ==. ==. ==. ==,

outer+config,8 interface ethernet 3outer+config,8 ip access9group 131 out

Lesson : Configure and apply an

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 27/128

Bringing a True-long Stand Vocation 27

www.saigonlab.vn

Lesson : Configure and apply anACLs

0 tended ACL - 0 ample 2

7eny only Telnet from s&(net 192:14:>: o&t 0Permit all ot!er traffic

outer+config,8 access9list 131 deny tcp 17 .14.6.3 3.3.3. == any e? 2outer+config,8 access9list 131 per%it ip any any

+i%plicit e deny all,

outer+config,8 interface ethernet 3outer+config,8 ip access9group 131 out

Lesson : Configure and apply an

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 28/128

Bringing a True-long Stand Vocation 28

www.saigonlab.vn

Lesson : Configure and apply anACLs

"sing 5amed $P ACL

Alp!an&meric name string m&st (e &ni?&e

Permit or deny statements !ave no prepended n&m(er @no removes t!e specific test from t!e named ACL

Activates t!e named $P ACL on an interface

Router(config)#ip access-list {standard | e tended} name

Router(config {std- | e t-}nacl)#{permit | deny}{ip access list test conditions}{permit | deny} {ip access list test conditions}no {permit | deny} {ip access list test conditions}

Router(config-if)#ip access-group name {in | out}

Lesson : Configure and apply an

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 29/128

Bringing a True-long Stand Vocation 29

www.saigonlab.vn

Lesson : Configure and apply anACLs

%iltering vty Access to a Bo&ter

%ive virt&al terminal lines , t!ro&g! >/%ilter addresses t!at can access t!e ro&ter vty ports%ilter vty access originating from t!e ro&ter

Lesson : Configure and apply an

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 30/128

Bringing a True-long Stand Vocation 30

www.saigonlab.vn

Lesson : Configure and apply anACLs

+ow to Control vty Access

Set &p an $P address filter wit! a standard ACL statement

"se line config&ration mode to filter access wit! t!e access-class commandSet identical restrictions on every vty

Lesson : Configure and apply an

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 31/128

Bringing a True-long Stand Vocation 31

www.saigonlab.vn

Lesson : Configure and apply anACLs

vty Commands

0nters config&ration mode for a vty or vty range

Bestricts incoming or o&tgoing vty connections foraddresses in t!e ACL

Router(config)#line !ty { vty# | vty-range }

Router(config-line)#access-class access-list-number {in | out}

Lesson : Configure and apply an

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 32/128

Bringing a True-long Stand Vocation 32

www.saigonlab.vn

Lesson : Configure and apply anACLs

vty Access 0 ampleControlling $n(o&nd Access

) Permits only !osts in networ 1.2:14 :1:: : :2;; to connect to t!e ro&ter vty

access-list " permit "$ %"&'%"% % % %

(implicit deny any) *line !ty + access-class " in

Lesson : Configure and apply an

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 33/128

Bringing a True-long Stand Vocation 33

www.saigonlab.vn

Lesson : Configure and apply anACLs

ACL Config&ration *&idelinesT!e order of ACL statements is cr&cial

) Becommended6 "se a te t editor on a PC to create t!e ACLstatements' t!en c&t and paste t!em into t!e ro&ter

) Top-down processing is important

) Place t!e more specific test statements firstStatements cannot (e rearranged or removed

) "se t!e no access9list nu%ber command to remove t!eentire ACL

) 0 ception6 5amed ACLs permit removal of individ&alstatements

$mplicit deny any will (e applied to all pac ets t!at donot matc! any ACL statement &nless t!e ACL endswit! an e plicit permit any statement

Lesson : Configure and apply an

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 34/128

Bringing a True-long Stand Vocation 34

www.saigonlab.vn

Lesson : Configure and apply anACLs

W!ere to Place $P ACLs

Place standard ACLs close to t!e destinationPlace e tended ACLs close to t!e so&rce

Lesson : Configure and apply an

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 35/128

Bringing a True-long Stand Vocation 35

www.saigonlab.vn

Lesson : Configure and apply anACLs

Monitoring ACL Statements, . $ #sho {protocol} access-list { access-list number }

, . $ #sho access-lists { access-list number }

g.ro.a# sho access-lists,tandard /0 access list " permit " % % %" permit " %1%1%" permit " %+%+%" permit " % % %"2 tended /0 access list " " permit tcp host " % % %" any e3 telnet permit tcp host " %11%11%" any e3 ftp permit tcp host " %++%++%" any e3 ftp-data"&

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 36/128

Bringing a True-long Stand Vocation 36

www.saigonlab.vn

Lesson 2: The basic operation of NAT

$ntrod&cing 5AT and PAT Translating $nside So&rce Addresses

Overloading an $nside *lo(al Address <erifying t!e 5AT and PAT Config&ration Tro&(les!ooting t!e 5AT and PAT Config&ration

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 37/128

Bringing a True-long Stand Vocation 37

www.saigonlab.vn

Lesson 2: The basic operation of NAT

5etwor Address Translation

An $P address is eit!er local or glo(alLocal $P addresses are seen in t!e inside networ

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 38/128

Bringing a True-long Stand Vocation 38

www.saigonlab.vn

Lesson 2: The basic operation of NAT

Port Address Translation

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 39/128

Bringing a True-long Stand Vocation 39

www.saigonlab.vn

Lesson 2: The basic operation of NAT

Translating $nside So&rce Addresses

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 40/128

Bringing a True-long Stand Vocation 40

www.saigonlab.vn

Lesson 2: The basic operation of NAT

Config&ring Static Translation

) 0sta(lis!es static translation (etween an insidelocal address and an inside glo(al address

) Mar s t!e interface as connected to t!e inside

) Mar s t!e interface as connected to t!e o&tside

Router(config)#ip nat inside source static local-ip global-ip

Router(config-if)#ip nat inside

Router(config-if)#ip nat outside

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 41/128

Bringing a True-long Stand Vocation 41

www.saigonlab.vn

Lesson 2: The basic operation of NAT

0na(ling Static 5AT Address Mapping 0 ample

$nterface s3ip address 1@ .14 .1.1 ==. ==. ==.3

ip nat outsideB$nterface e3ip address 13.1.1.1 ==. ==. ==.3ip nat insideB$p nat inside source static 13.1.1. 1@ .14 .1.

h b f

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 42/128

Bringing a True-long Stand Vocation 42

www.saigonlab.vn

Lesson 2: The basic operation of NAT

Config&ring 7ynamic Translation

7efines a pool of glo(al addresses to (e allocated as needed

7efines a standard $P ACL permitting t!ose inside localaddresses t!at are to (e translated

0sta(lis!es dynamic so&rce translation' specifying t!e ACL t!atwas defined in t!e prior step

Router(config)#ip nat pool name start-ip end-ip {netmask netmask | prefi -length prefix-length }

Router(config)#access-list access-list-number permitsource [ source-wildcard ]

Router(config)#ip nat inside source listaccess-list-number pool name

h b f

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 43/128

Bringing a True-long Stand Vocation 43

www.saigonlab.vn

Lesson 2: The basic operation of NAT

7ynamic Address Translation 0 ample$p nat pool net9 3 17 .4@. 22. 3@ 171.4@. 22. net%ar!

==. ==. ==. 63ip nat inside source list 1 pool net9 3B$nterfave serial 3 ip address 17 .4@. 2 .1 ==. ==. ==. 63 ip nat outsideB

$nterface ethernet 3 ip address 1@ .14 .1.@6 ==. ==. ==.3 ip nat insideBAccess9list 1 per%it 1@ .14 .1.3 3.3.3. ==

1@ .14 .1.@6 171.4@. 2 .1

"3 3

ost )17 .14 .1.1

ost C13.1.1.1

ost *1@ .14 .1.131

ost A1@ .14 .1.133

L 2 Th b i i f NAT

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 44/128

Bringing a True-long Stand Vocation 44

www.saigonlab.vn

Lesson 2: The basic operation of NAT

Overloading an $nside *lo(al Address

L 2 Th b i i f NAT

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 45/128

Bringing a True-long Stand Vocation 45

www.saigonlab.vn

Lesson 2: The basic operation of NAT

Config&ring Overloading

) 7efines a standard $P ACL t!at will permit t!e insidelocal addresses t!at are to (e translated

0sta(lis!es dynamic so&rce translation' specifyingt!e ACL t!at was defined in t!e prior step

Router(config)#ip nat inside source listaccess-list-number interface interface o!erload

Router(config)#access-list access-list-number permitsource source-wildcard

L 2 Th b i i f NAT

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 46/128

Bringing a True-long Stand Vocation 46

www.saigonlab.vn

Lesson 2: The basic operation of NAT

Overloading an $nside *lo(al Address 0 ample

1@ .14 .6.1

1@ .14 .6.11@ .14 .2.1

1@ .14 .6.1

"3

"1 317 .17.2 .1

L 2 Th b i i f NAT

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 47/128

Bringing a True-long Stand Vocation 47

www.saigonlab.vn

Lesson 2: The basic operation of NAT

7isplaying $nformation wit! s!ow Commands

7isplays active translations

7isplays translation statisticsRouter#sho ip nat statistics

Router#sho ip nat translations

Router#sho ip nat translation 0ro /nside global /nside local 4utside local 4utside global --- "5 %"&%"1"%" " %" %" %" --- ---

Router#sho ip nat statistics 6otal acti!e translations7 " (" static8 dynamic9 e tended) 4utside interfaces7 2thernet 8 ,erial %5 /nside interfaces7 2thernet" :its7 ;isses7 <

L 2 Th b i ti f NAT

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 48/128

Bringing a True-long Stand Vocation 48

www.saigonlab.vn

Lesson 2: The basic operation of NAT

Sample Pro(lem6 Cannot Ping Bemote +ost

ost A1@ .14 .1.

1@ .14 . .113.1.1. 5 61@ .14 .

int e3 ip address 1@ .14 . .1 ==. ==. ==.3Bint s3 ip address 13.1.1. ==. ==. ==.3B outer rip networ! 13.3.3.3 networ! 1@ .14 . .3

ost *1@ .14 . .

ip nat pool test 17 .14.17. 3 17 .14.17.23ip nat inside source list 1 pool testBint s3 ip address 13.1.1.1 ==. ==. ==.3 ip nat inside

Bint e3 ip address 1@ .14 .1.1 ==. ==. ==.3

ip nat outsideB

outer rip networ! 13.3.3.3 networ! 1@ .14 .1.3BAccess9list 1 per%it 1@ .14 .1.3 ==. ==. ==.3

L 2 Th b i ti f NAT

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 49/128

Bringing a True-long Stand Vocation 49

www.saigonlab.vn

Lesson 2: The basic operation of NAT

Sol&tion6 5ew Config&ration

ost A1@ .14 .1.

ost *1@ .14 . .

1@ .14 . .113.1.1. 5 61@ .14 .1

$nt e3 ip address 1@ .14 . .1 ==. ==. ==.3B$nt s3 ip address 13.1.1. ==. ==. ==.3B

outer rip networ! 13.3.3.1 networ! 1@ .1 . .3

L 2 Th b i ti f NAT

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 50/128

Bringing a True-long Stand Vocation 50

www.saigonlab.vn

Lesson 2: The basic operation of NAT

"sing t!e de(&g ip nat Command

Router# debug ip nat

=>67 s?"$ %"&'%"%$ -@"5 %1"% 11% $8 d?"5 %1"% %"1 [&' ] =>67 s?"5 %1"% %"1 8 d?"5 %1"% 11% $-@"$ %"&'%"%$ [ "' ] =>67 s?"$ %"&'%"%$ -@"5 %1"% 11% $8 d?"5 %1"%"%"&" [&' &] =>6A7 s?"5 %1"%"%"&"8 d?"5 %1"% 11% $-@"$ %"&'%"%$ [ 11""] =>6A7 s?"$ %"&'%"%$ -@"5 %1"% 11% $8 d?"5 %1"%"%"&" [&' 5] =>6A7 s?"$ %"&'%"%$ -@"5 %1"% 11% $8 d?"5 %1"%"%"&" [&' '] =>6A7 s?"5 %1"%"%"&"8 d?"5 %1"% 11% $-@"$ %"&'%"%$ [ 11"1] =>6A7 s?"5 %1"%"%"&"8 d?"5 %1"% 11% $-@"$ %"&'%"%$ [ 11 ]

L 2 Th b i ti f NAT

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 51/128

Bringing a True-long Stand Vocation 51

www.saigonlab.vn

Lesson 2: The basic operation of NAT

Translation 5ot $nstalled in t!eTranslation Ta(le#

<erify t!at6) T!e config&ration is correct

) T!ere are not any in(o&nd ACLs denying t!e pac ets entryto t!e 5AT ro&ter

) T!e ACL referenced (y t!e 5AT command is permitting allnecessary networ s

) T!ere are eno&g! addresses in t!e 5AT pool) T!e ro&ter interfaces are appropriately defined as 5AT

inside or 5AT o&tside

Module : $%ple%ent and verify DAN

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 52/128

Bringing a True-long Stand Vocation 52

www.saigonlab.vn

$ p ylin!s

Methods for connecting to aDAN

1

Connecting to e%ote Networ!s2

((( connection between Cisco routers3

Era%e elay on Cisco routers>

(N Technology;

Lesson 1: Methods for connecting to a

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 53/128

Bringing a True-long Stand Vocation 53

www.saigonlab.vn

gDAN

W!at $s a Wide Area 5etwor #W!y Are WA5s 5ecessary#+ow $s a WA5 7ifferent from a LA5#

WA5 Access and t!e OS$ Beference ModelWA5 7evicesT!e Bole of Bo&ters in WA5s

WA5 7ata Lin ProtocolsM&ltiple ingWA5 Comm&nication Lin Options

Lesson 1: Methods for connecting to a

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 54/128

Bringing a True-long Stand Vocation 54

www.saigonlab.vn

gDAN

Wide-Area 5etwor

Lesson 1: Methods for connecting to a

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 55/128

Bringing a True-long Stand Vocation 55

www.saigonlab.vn

gDAN

5eed for WA5s*ussiness (artners

ery e%ote 'ffice

Thousands ofe%ote Dor!ers

egional 'fficee%ote 'ffice

o%e 'ffices Mobile Dor!ers

Lesson 1: Methods for connecting to a

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 56/128

Bringing a True-long Stand Vocation 56

www.saigonlab.vn

gDAN

WA5s vs: LA5s

DANs LANs

Area

'wnership

Lesson 1: Methods for connecting to a

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 57/128

Bringing a True-long Stand Vocation 57

www.saigonlab.vn

gDAN

WA5 Access and t!e OS$ Model

Lesson 1: Methods for connecting to a

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 58/128

Bringing a True-long Stand Vocation 58

www.saigonlab.vn

gDAN

WA5 7evices

Lesson 1: Methods for connecting to a

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 59/128

Bringing a True-long Stand Vocation 59

www.saigonlab.vn

gDAN

WA5 Connection Types6 Layer 1

Lesson 1: Methods for connecting to a

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 60/128

Bringing a True-long Stand Vocation 60

www.saigonlab.vn

gDAN

WA5DM&ltiple LA5s

Lesson 1: Methods for connecting to a

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 61/128

Bringing a True-long Stand Vocation 61

www.saigonlab.vn

gDAN

$nterfacing 8etween WA5 Service Providers

Provider assigns connection parameters to s&(scri(er

Lesson 1: Methods for connecting to a

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 62/128

Bringing a True-long Stand Vocation 62

www.saigonlab.vn

gDAN

Serial Point-to-Point Connectionsouter Connections"nd9Fser )evice

)T"

)C"C F5) F

Networ! Connections at the C F5) F

Lesson 1: Methods for connecting to a

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 63/128

Bringing a True-long Stand Vocation 63

www.saigonlab.vn

gDAN

Typical WA5 0ncaps&lation Protocols6Layer 2

Lesson 1: Methods for connecting to a

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 64/128

Bringing a True-long Stand Vocation 64

www.saigonlab.vnDAN

M&ltiple ing Tec!nologies

Time-7ivision M&ltiple ing ,T7M/%re?&ency-7ivision M&ltiple ing ,%7M/Statistical M&ltiple ing

Multiple#er

Lesson 1: Methods for connecting to a

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 65/128

Bringing a True-long Stand Vocation 65

www.saigonlab.vnDAN

WA5 Lin OptionsDAN

witched)edicated

Lesson : Connecting to e%ote

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 66/128

Bringing a True-long Stand Vocation 66

www.saigonlab.vnNetwor!s

Circ&it-Switc!ed Comm&nication Lin sP&(lic Switc!ed Telep!one 5etwor$ntegrated 7igital Services 5etworPac et-Switc!ed Comm&nication Lin sE:2;%rame Belay

Async!rono&s Transfer Mode and Cell Switc!ing7SLCa(le*lo(al $nternetFt!e Largest WA5

Lesson : Connecting to e%ote

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 67/128

Bringing a True-long Stand Vocation 67

www.saigonlab.vnNetwor!s

Circ&it Switc!ing

Lesson : Connecting to e%ote

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 68/128

Bringing a True-long Stand Vocation 68

www.saigonlab.vnNetwor!s

PST5

Local "#change

Lesson : Connecting to e%ote

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 69/128

Bringing a True-long Stand Vocation 69

www.saigonlab.vnNetwor!s

PST5 ConsiderationsAdvantages

) Simplicity

) Availa(ility) Cost

)isadvantages) Low data rates

) Belatively long connection set&p time

Lesson : Connecting to e%oteN !

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 70/128

Bringing a True-long Stand Vocation 70

www.saigonlab.vnNetwor!s

$S75

Lesson : Connecting to e%oteN !

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 71/128

Bringing a True-long Stand Vocation 71

www.saigonlab.vnNetwor!s

8B$ and PB$

Lesson : Connecting to e%oteN !

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 72/128

Bringing a True-long Stand Vocation 72

www.saigonlab.vnNetwor!s

$S75 ConsiderationsAdvantages

) Speed

) Always-on availa(ility)isadvantages) Limited geograp!ic availa(ility) Cost

Lesson : Connecting to e%oteN !

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 73/128

Bringing a True-long Stand Vocation 73

www.saigonlab.vnNetwor!s

Pac et Switc!ing

ynchronous

erial

ynchronouserial

Lesson : Connecting to e%oteN t !

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 74/128

Bringing a True-long Stand Vocation 74

www.saigonlab.vnNetwor!s

WA5 wit! E:2;

Lesson : Connecting to e%oteN t !

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 75/128

Bringing a True-long Stand Vocation 75

www.saigonlab.vnNetwor!s

%rame Belay)C" or Era%e

elay witch

Era%e elay wor!s here

Lesson : Connecting to e%oteN t !

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 76/128

Bringing a True-long Stand Vocation 76

www.saigonlab.vnNetwor!s

%rame Belay 7evices and <irt&al Circ&its

Lesson : Connecting to e%oteN t !

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 77/128

Bringing a True-long Stand Vocation 77

www.saigonlab.vnNetwor!s

ATM and Cell Switc!ing

ATM witch ATM witch

Cells

Lesson : Connecting to e%oteNet or!s

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 78/128

Bringing a True-long Stand Vocation 78

www.saigonlab.vnNetwor!s

7SL

Lesson : Connecting to e%oteNetwor!s

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 79/128

Bringing a True-long Stand Vocation 79

www.saigonlab.vnNetwor!s

7SL Service Types Overview

)own Fp )own Fp

Lesson : Connecting to e%oteNetwor!s

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 80/128

Bringing a True-long Stand Vocation 80

www.saigonlab.vnNetwor!s

7SL ConsiderationsAdvantages

) Speed) Sim&ltaneo&s voice and data transmission

) $ncremental additions) Always-on availa(ility) 8ac ward compati(ility wit! analog p!ones

)isadvantages) Limited availa(ility) Local p!one company re?&irements) Sec&rity ris s

Lesson : Connecting to e%oteNetwor!s

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 81/128

Bringing a True-long Stand Vocation 81

www.saigonlab.vnNetwor!s

Ca(le-8ased WA5s

Cable Mode% Cableeadend

Cable outer with 69port witch

Lesson : Connecting to e%oteNetwor!s

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 82/128

Bringing a True-long Stand Vocation 82

www.saigonlab.vnNetwor!s

+ow Ca(le Modems Wor(icasso "instein Leonard

osieCoa#ial Cable

Coa#

Gi%%y Mo%

-randpa

Gunior

(adA%plifier

plitter

Tap

Lesson : Connecting to e%oteNetwor!s

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 83/128

Bringing a True-long Stand Vocation 83

www.saigonlab.vnNetwor!s

T!e *lo(al $nternet

Lesson 2: ((( connection betweenCisco routers

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 84/128

Bringing a True-long Stand Vocation 84

www.saigonlab.vnCisco routers

+7LC 0ncaps&lation Config&rationPPP Layered Arc!itect&rePPP Config&ration

PPP Session 0sta(lis!mentPPP A&t!entication ProtocolsPPP A&t!entication Config&ration

Serial 0ncaps&lation Config&ration <erificationPPP A&t!entication Config&ration Tro&(les!ooting

Lesson 2: ((( connection betweenCisco routers

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 85/128

Bringing a True-long Stand Vocation 85

www.saigonlab.vnCisco routers

+7LC %rame %ormat

"ses a proprietary data field to s&pportm&ltiprotocol environments

S&pports only single-protocol environments

Lesson 2: ((( connection betweenCisco routers

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 86/128

Bringing a True-long Stand Vocation 86

www.saigonlab.vnCisco routers

Config&ring +7LC 0ncaps&lation

0na(les +7LC encaps&lation"ses t!e defa&lt encaps&lation on sync!rono&sserial interfaces

outer+config9if,8 encapsulation hdlc

Lesson 2: ((( connection betweenCisco routers

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 87/128

Bringing a True-long Stand Vocation 87

www.saigonlab.vnCisco routers

An Overview of PPP

PPP can carry pac ets from several protocol s&ites &sing 5CPPPP controls t!e set&p of several lin options &sing LCP

Multiple (rotocol"ncapsulations

Fsing NC(s in (((

Lesson 2: ((( connection betweenCisco routers

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 88/128

Bringing a True-long Stand Vocation 88

www.saigonlab.vnCisco routers

Layering PPP 0lements

PPP = 7ata lin wit! networ layer services

Lesson 2: ((( connection betweenCisco routers

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 89/128

Bringing a True-long Stand Vocation 89

www.saigonlab.vnCisco routers

PPP LCP Config&ration Options

Lesson 2: ((( connection betweenCisco routers

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 90/128

Bringing a True-long Stand Vocation 90

www.saigonlab.vnCisco routers

PPP Session 0sta(lis!ment

Two PPP a&t!entication protocols6 PAP and C+AP

Lesson 2: ((( connection betweenCisco routers

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 91/128

Bringing a True-long Stand Vocation 91

www.saigonlab.vnCisco routers

PPP A&t!entication Protocols

Passwords sent in clear te tPeer in control of attempts

(A(Two9Day andsha!e

/santacruH boardwal!0

e%ote outer+santacruH,

ost na%e : santacruH(assword: broadwal!

Central9 ite outer+ I,

ost na%e : santacruH(assword: broadwal!

Lesson 2: ((( connection betweenCisco routers

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 92/128

Bringing a True-long Stand Vocation 92

www.saigonlab.vnCisco routers

C!allenge +ands!a e A&t!entication Protocol

+as! val&es' not act&al passwords' are sent across t!e linT!e local ro&ter or e ternal server is in control of attempts

e%ote outer+santacruH,

ost na%e : santacruH(assword: broadwal!

Lesson 2: ((( connection betweenCisco routers

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 93/128

Bringing a True-long Stand Vocation 93

www.saigonlab.vnCisco routers

Config&ring PPP and A&t!entication Overview

Lesson 2: ((( connection betweenCisco routers

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 94/128

Bringing a True-long Stand Vocation 94

www.saigonlab.vnCisco routers

Config&ring PPP

"nables ((( encapsulation

Router(config-if)#encapsulation ppp

Lesson 2: ((( connection betweenCisco routers

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 95/128

Bringing a True-long Stand Vocation 95

www.saigonlab.vnCisco routers

Config&ring PPP A&t!entication

Assigns a host na%e to your router

$dentifies the userna%e and password ofre%ote router

0na(les PAP or C+AP a&t!entication

Router(config)#hostname name

Router(config)#username name pass ord password

Router(config-if)#ppp authentication{chap | chap pap | pap chap | pap}

Lesson 2: ((( connection betweenCisco routers

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 96/128

Bringing a True-long Stand Vocation 96

www.saigonlab.vnCisco routers

C+AP Config&ration 0 ample

Lesson 2: ((( connection betweenCisco routers

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 97/128

Bringing a True-long Stand Vocation 97

www.saigonlab.vnCisco routers

<erifying t!e +7LC and PPP0ncaps&lation Config&rationRouter# sho interface s,erial is up8 line protocol is up :ard are is :B&+ 5 /nternet address is " %"+ %"% C + ;6D " bytes8 EF " ++ Gbit8 BHI usec8 rely C 8 load "C 2ncapsulation 0008 loopback not set8 keepali!e set (" sec) HJ0 4pen <<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<< minute input rate bitsCsec8 packetsCsec minute output rate bitsCsec8 packetsCsec 1' " packets input8 & &"" bytes8 no buffer Recei!ed 1+'' broadcasts8 runts8 giants8 throttles

input errors8 JRJ8 frame8 o!errun8 ignored8 abort 1' $5 packets output8 "1 &$5 bytes8 underruns output errors8 collisions8 & + interface resets output buffer failures8 output buffers s apped out +' carrier transitions BJB?up B,R?up B6R?up R6,?up J6,?up

Lesson 2: ((( connection betweenCisco routers

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 98/128

Bringing a True-long Stand Vocation 98

www.saigonlab.vnCisco routers

<erifying PPP A&t!entication

) de(&g ppp a&t!entication s!ows s&ccessf&l C+AP o&tp&t:

outer8 debug ppp authentication6d 3h : J L$NK929F()'DN : $nterface erial3& changed state to up6d 3h : e3 ((( : Treating connection as a dedicated line6d 3h : e3 (((: (hase is AFT "NT$CAT$N-& by both6d 3h : e3 C A( : 3 C ALL"N-" id len fro% /left06d 3h : e3 C A( : $ C ALL"N-" id 2 len fro% /right06d 3h : e3 C A( : $ " ('N " id 2 len fro% /left06d 3h : e3 C A( : $ " ('N " id len fro% /right06d 3h : e3 C A( : 3 FCC" id len 6

6d 3h : e3 C A( : $ FCC" id 2 len 66d 3h : JL$N"( 'T'9=9F()'DN : Line (rotocol on $nterface erial3& changedstate to up

Lesson 2: ((( connection betweenCisco routers

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 99/128

Bringing a True-long Stand Vocation 99

www.saigonlab.vnC sco oute s

<erifying PPP 5egotiationRouter# debug ppp negotiation000 protocol negotiation debugging is onRouter#A;ar " 7 &71&%&+ 7 KH/=G-1-D0B4F=7 /nterface ER/ 7"8 changed state to upA;ar " 7 &71&%&&"7 ER 7" 0007 6reating connection as a callinA;ar " 7 &71&%&& 7 ER 7" 0007 0hase is 2,6>EH/,:/=L8 0assi!e 4penA;ar " 7 &71&%&&$7 ER 7" HJ07 ,tate is HistenA;ar " 7 &715% 1+7 ER 7" HJ07 / J4=MR2N [Histen] id 5 len "5A;ar " 7 &715% 1'7 ER 7" HJ07 >uth0roto 0>0 ( 1 +J 1)A;ar " 7 &715% + 7 ER 7" HJ07 ;agic=umber 5> "+B ( & 5> "+B)A;ar " 7 &715% +&7 ER 7" HJ07 Jallback ( B 1 )A;ar " 7 &715% +7 ER 7" HJ07 4 J4=MR2N [Histen] id + len "A;ar " 7 &715% '7 ER 7" HJ07 >uth0roto J:>0 ( 1 J 1 )A;ar " 7 &715% & 7 ER 7" HJ07 ;agic=umber " '"252" ( &" '"252")A;ar " 7 &715% &&7 ER 7" HJ07 4 J4=MR2O [Histen] id 5 len 5A;ar " 7 &715% 5 7 ER 7" HJ07 Jallback ( B 1 )A;ar " 7 &715% $'7 ER 7" HJ07 / J4=M>JG [R2Nsent] id + len "A;ar " 7 &715%" 7 ER 7" HJ07 >uth0roto J:>0 ( 1 J 1 )A;ar " 7 &715%" &7 ER 7" HJ07 ;agic=umber " '"252" ( &" '"252")A;ar " 7 &715%""+7 ER 7" HJ07 / J4=MR2N [>JGrc!d] id ' len "+A;ar " 7 &715%""57 ER 7" HJ07 >uth0roto 0>0 ( 1 +J 1)A;ar " 7 &715%" "7 ER 7" HJ07 ;agic=umber 5> "+B ( & 5> "+B)

Lesson 6: Era%e elay on Ciscorouters

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 100/128

Bringing a True-long Stand Vocation 100

www.saigonlab.vn

%rame Belay Overview%rame Belay Stac Layered S&pport%rame Belay Terminology%rame Belay Topologies

Beac!a(ility $ss&es in %rame BelayBeac!a(ility $ss&e Besol&tion%rame Belay Address Mapping

%rame Belay Signaling+ow Service Providers Map %rame Belay 7LC$sService Provider %rame Belay-to-ATM $nterwor ing

Lesson 6: Era%e elay on Ciscorouters

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 101/128

Bringing a True-long Stand Vocation 101

www.saigonlab.vn

%rame Belay Overview

Connections made (y virt&al circ&itsConnection-oriented service

Lesson 6: Era%e elay on Ciscorouters

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 102/128

Bringing a True-long Stand Vocation 102

www.saigonlab.vn

%rame Belay Stac' $ eference Model Era%e elay

(hysical

(resentation

ession

Transport

Networ!

)ata Lin!

Application

"$A5T$A9 2 &"$A5T$A966@& .2=&

. 1& "$A5T$A9=23

Era%e elay

$(5$( 5AppleTal!& etc.

Lesson 6: Era%e elay on Ciscorouters

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 103/128

Bringing a True-long Stand Vocation 103

www.saigonlab.vn

%rame Belay Terminology

)LC$ - 7ata-lin connection identifier LM$ - Local Management $nterface

outer A outer *

)LCL: 633

)LCL: 133

( C

LocalAccess

Loop T1

Local AccessLoop 46 !bps

Lesson 6: Era%e elay on Ciscorouters

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 104/128

Bringing a True-long Stand Vocation 104

www.saigonlab.vn

Selecting a %rame Belay Topology

%rame Belay defa&lt6 58MA

Lesson 6: Era%e elay on Ciscorouters

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 105/128

Bringing a True-long Stand Vocation 105

www.saigonlab.vn

Beac!a(ility $ss&es wit! Bo&ting "pdates

Pro(lem6

) 8roadcast traffic m&st (e replicated for eac! activeconnection) Split !oriGon r&le prevents ro&ting &pdates received on an

interface from (eing forwarded o&t t!e same interface

Lesson 6: Era%e elay on Ciscorouters

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 106/128

Bringing a True-long Stand Vocation 106

www.saigonlab.vn

Besolving Beac!a(ility $ss&es

Split !oriGon can ca&se pro(lems in 58MAenvironmentsS&(interfaces can resolve split-!oriGon iss&esSol&tion6 A single p!ysical interface sim&lates m&ltiplelogical interfaces

Lesson 6: Era%e elay on Ciscorouters

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 107/128

Bringing a True-long Stand Vocation 107

www.saigonlab.vn

%rame Belay Address Mapping

"se LM$ to get locally significant 7LC$ from t!e %rame Belay switc!"se $nverse ABP to map t!e local 7LC$ to t!e remote ro&ter networlayer address

Lesson 6: Era%e elay on Ciscorouters

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 108/128

Bringing a True-long Stand Vocation 108

www.saigonlab.vn

%rame Belay Signaling

Cisco s&pports t!ree LM$ standards6) Cisco) A5S$ T1:419 Anne 7) $T"-T H:.33 Anne A

Lesson 6: Era%e elay on Ciscorouters

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 109/128

Bringing a True-long Stand Vocation 109

www.saigonlab.vn

%rame Belay $nverse ABP and LM$ Signaling

Lesson 6: Era%e elay on Ciscorouters

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 110/128

Bringing a True-long Stand Vocation 110

www.saigonlab.vn

Stages of $nverse ABP and LM$ Operation

Lesson 6: Era%e elay on Ciscorouters

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 111/128

Bringing a True-long Stand Vocation 111

www.saigonlab.vn

Config&ring 8asic %rame Belay

Lesson 6: Era%e elay on Ciscorouters

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 112/128

Bringing a True-long Stand Vocation 112

www.saigonlab.vn

Config&ring a Static %rame Belay Map

Lesson 6: Era%e elay on Ciscorouters

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 113/128

Bringing a True-long Stand Vocation 113

www.saigonlab.vn

Config&ring S&(interfacesPoint-to-point) S&(interfaces act li e leased lines) 0ac! point-to-point s&(interface re?&ires its own s&(net

) Point-to-point is applica(le to !&(-and-spo e topologiesM&ltipoint) S&(interfaces act li e 58MA networ s' so t!ey do not

resolve t!e split !oriGon iss&es

) M&ltipoint can save address space (eca&se it &ses asingle s&(net

) M&ltipoint is applica(le to partial mes! and f&ll mes!topologies

i l b

Lesson 6: Era%e elay on Ciscorouters

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 114/128

Bringing a True-long Stand Vocation 114

www.saigonlab.vn

Config&ring Point-to-Point S&(interfaces

i l b

Lesson 6: Era%e elay on Ciscorouters

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 115/128

Bringing a True-long Stand Vocation 115

www.saigonlab.vn

M&ltipoint S&(interfaces Config&ration 0 ample

. 13.17.3.15 6 .1 13.17.3. 5 6

.1 13.17.3.25 6

.1 13.17.3.65 6

i l b

Lesson 6: Era%e elay on Ciscorouters

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 116/128

Bringing a True-long Stand Vocation 116

www.saigonlab.vn

Router# sho interfaces s,erial is up8 line protocol is up :ard are is :B&+ 5 /nternet address is " %"+ %"% C + ;6D " bytes8 EF " ++ Gbit8 BHI usec8 rely C 8 load "C 2ncapsulation MR>;2-R2H>I8 loopback not set8 keepali!e set (" sec) H;/ en3 sent "$8 H;/ stat rec!d 8 H;/ upd rec!d 8 B62 H;/ up H;/ en3 rec!d 8 H;/ stat sent 8 H;/ upd sent H;/ BHJ/ " 1 H;/ type is J/,J4 frame relay B62 MR ,PJ disabled8 H>0M state do n Eroadcast 3ueue C&+8 broadcasts sentCdropped 'C 8 interface broadcasts Hast input 7 7 8 output 7 7 8 output hang ne!er Hast clearing of Qsho interfaceQ counters ne!er Nueueing strategy7 fifo 4utput 3ueue C+ 8 drops9 input 3ueue C5 8 drops 4utput omitted@

<erifying %rame Belay Operation

7isplays information a(o&t %rame Belay 7LC$s and t!e LM$

outer8 show interfaces type number

ig l b

Lesson 6: Era%e elay on Ciscorouters

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 117/128

Bringing a True-long Stand Vocation 117

www.saigonlab.vn

Router# sho frame-relay lmi H;/ ,tatistics for interface ,erial (Mrame Relay B62)H;/ 6I02 ? J/,J4 /n!alid Dnnumbered info /n!alid 0rot Bisc /n!alid dummy Jall Ref /n!alid ;sg 6ype /n!alid ,tatus ;essage /n!alid Hock ,hift

/n!alid /nformation /B /n!alid Report /2 Hen /n!alid Report Re3uest /n!alid Geep /2 Hen =um ,tatus 2n3% ,ent ""1" =um ,tatus msgs Rc!d ""1" =um Dpdate ,tatus Rc!d =um ,tatus 6imeouts

<erifying %rame Belay Operation

)isplays LM$ statistics

Router# sho frame-relay lmi [ type number ]

www saigonlab vn

Lesson 6: Era%e elay on Ciscorouters

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 118/128

Bringing a True-long Stand Vocation 118

www.saigonlab.vn

Router# sho frame-relay p!c "0PJ ,tatistics for interface ,erial (Mrame Relay B62)

BHJ/ ? " 8 BHJ/ D,>L2 ? H4J>H8 0PJ ,6>6D, ? >J6/P28 /=62RM>J2 ? ,erial

input pkts ' output pkts " in bytes '1$'

out bytes ""$' dropped pkts in M2J= pkts in E2J= pkts out M2J= pkts out E2J= pkts in B2 pkts out B2 pkts out bcast pkts " out bcast bytes ""$' p!c create time 7 17+&8 last time p!c status changed 7 17+5

<erifying %rame Belay Operation

7isplays P<C statistics

outer8 show fra%e9relay pvc type number dlci OO

www saigonlab vn

Lesson 6: Era%e elay on Ciscorouters

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 119/128

Bringing a True-long Stand Vocation 119

www.saigonlab.vn

Router# sho frame-relay map

,erial (up)7 ip " %"+ %"%" dlci " ( &+8 "'+ )8 dynamic8 broadcast88 status defined8 acti!eRouter# clear frame-relay-inarpRouter# sho frame mapRouter#

<erifying %rame Belay Operation

7isplays t!e c&rrent %rame Belay map entries

Clears dynamically created %rame Belay maps'created (y &sing $nverse ABP

outer8 show fra%e9relay %ap

outer8 clear fra%e9relay9inarp

www saigonlab vn

Lesson 6: Era%e elay on Ciscorouters

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 120/128

Bringing a True-long Stand Vocation 120

www.saigonlab.vn

Router# debug frame-relay lmiMrame Relay H;/ debugging is onBisplaying all Mrame Relay H;/ dataRouter#" d7 ,erial (out)7 ,t2n38 myse3 "+ 8 yourseen "1$8 B62 up" d7 datagramstart ? 2 '2J8 datagramsiSe ? "1" d7 MR encap ? MJM" 1 $

" d7 5 " " " 1 'J 'E" d7" d7 ,erial (in)7 ,tatus8 myse3 "+" d7 R6 /2 "8 length "8 type "" d7 G> /2 18 length 8 yourse3 "+ 8 myse3 "+" d7 ,erial (out)7 ,t2n38 myse3 "+"8 yourseen "+ 8 B62 up" d7 datagramstart ? 2 '2J8 datagramsiSe ? "1" d7 MR encap ? MJM" 1 $" d7 5 " " " 1 'B 'J" d7" d7 ,erial (in)7 ,tatus8 myse3 "+" d7 R6 /2 "8 length "8 type " d7 G> /2 18 length 8 yourse3 "+ 8 myse3 "+" d7 0PJ /2 5 8 length & 8 dlci " 8 status 8 b

Tro&(les!ooting 8asic %rame Belay

Operations

)isplays LM$ debug infor%ation

www saigonlab vn

Lesson =: (N Technology

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 121/128

Bringing a True-long Stand Vocation 121

www.saigonlab.vn

<P5 7efinitionBemote Access <P5sSite-to-Site <P5sT&nneling Protocols I *B0T&nneling Protocols I $PSecT&nneling Protocols I L2% and L2TP

www saigonlab vn

Lesson =: (N Technology

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 122/128

Bringing a True-long Stand Vocation 122

www.saigonlab.vn

<P5 7efinition

<irt&al private networ ,<P5/Dan encryptedconnection (etween private networ s over ap&(lic networ s&c! as t!e $nternet

www saigonlab vn

Lesson =: (N Technology

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 123/128

Bringing a True-long Stand Vocation 123

www.saigonlab.vn

Bemote Access <P5s

www saigonlab vn

Lesson =: (N Technology

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 124/128

Bringing a True-long Stand Vocation 124

www.saigonlab.vn

Site-to-Site <P5s

Site-to-Site <P5 I 0 tension of classic WA5

www.saigonlab.vn

Lesson =: (N Technology

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 125/128

Bringing a True-long Stand Vocation 125

www.saigonlab.vn

T&nneling Protocols I *B0 ,*eneric Bo&ting0ncaps&lation/

CiscoJs m&ltiprotocol carrier t!at can encaps&late $P' CL5P'$PE' AppleTal ' 70Cnet' and E5S inside $P t&nnels8est for site-to-site <P5sTypically &sed to t&nnel m&lticast pac ets s&c! as ro&tingprotocols7oes not s&pport data encryption or pac et integrity0ncaps&lates all traffic regardless of so&rce destination

www.saigonlab.vn

Lesson =: (N Technology

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 126/128

Bringing a True-long Stand Vocation 126

www.saigonlab.vn

T&nneling Protocols I $PSec ,$P Sec&rity/Most commonly &sed t&nneling protocol wit! <P5sCan (e &sed in com(ination wit! *B0 or L2TP ,Layer 2T&nneling Protocol/ w!en t!ere is a need to s&pportt&nneling m&lticast pac ets"ses $K0 to manage e c!ange of sec&rity eysBeplay protection I someone capt&ring pac ets andreplaying t!em later to gain access7ata origin a&t!entication ,Ma es&re t!e pac ets are a&t!entic/Confidentiality I 0ncryption is&sed to !ide t!e $P !eader of t!eoriginal pac et

www.saigonlab.vn

Lesson =: (N Technology

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 127/128

Bringing a True-long Stand Vocation 127

g

T&nneling Protocols I L2% ,Layer 2 %orwarding/ andL2TP ,Layer 2 T&nneling Protocol/

CiscoJs protocol t!at was &sed (efore L2TP ,Layer 2T&nneling Protocol/ was esta(lis!ed$t is not forward compati(le wit! L2TP

L2TP is a com(ination of CiscoJs L2% and MicrosoftJs PPTP,Point-to-Point T&nneling Protocol/L2TP is &sed to create a media-independent' m&ltiprotocol<P75 ,<irt&al Private 7ial 5etwor / w!ic! allows &sers toinvo e corporate sec&rity policies across a <P5 or <P75lin as an e tension of t!eir internal networ

L2TP is good for remote-access <P5s t!at re?&irem&ltiprotocol s&pport ,or *B0/

8/10/2019 SaigonLAB CCNA Module7 Va Module 8

http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 128/128

www.saigonlab.vn