Upload
juel1904
View
242
Download
1
Embed Size (px)
Citation preview
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 1/128
Bringing a True-long Stand Vocation
CCNACCNAwww.saigonlab.vn
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 2/128
Bringing a True-long Stand Vocation 2
www.saigonlab.vn
Module 7: NAT and ACLs
The purpose and types of ACLs1
Configure and apply an ACLs2
The basic operation of NAT3
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 3/128
Bringing a True-long Stand Vocation 3
www.saigonlab.vn
Lesson 1: The purpose and types ofACLs
ACL Overview ACL Applications
Types of ACLs ACL Operations ACL Statement Processing
Wildcard Mas ing Process
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 4/128
Bringing a True-long Stand Vocation 4
www.saigonlab.vn
Lesson 1: The purpose and types ofACLs
W!y "se ACLs#
Manage $P traffic as networ access grows%ilter pac ets as t!ey pass t!ro&g! t!e ro&ter
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 5/128
Bringing a True-long Stand Vocation 5
www.saigonlab.vn
Lesson 1: The purpose and types ofACLs
ACL Applications
Permit or deny pac ets moving t!ro&g! t!e ro&ter Permit or deny vty access to or from t!e ro&ter Wit!o&t ACLs' all pac ets co&ld (e transmitted onto allparts of yo&r networ
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 6/128
Bringing a True-long Stand Vocation 6
www.saigonlab.vn
Lesson 1: The purpose and types ofACLs
Ot!er ACL "ses
pecial handling for traffic based on pac!et tests
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 7/128Bringing a True-long Stand Vocation 7
www.saigonlab.vn
Lesson 1: The purpose and types ofACLs
Types of ACLs
Standard ACL) C!ec s so&rce address) *enerally permits or denies entire protocol s&ite
"#tended ACL) C!ec s so&rce and destination address) *enerally permits or denies specific protocols
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 8/128Bringing a True-long Stand Vocation 8
www.saigonlab.vn
Lesson 1: The purpose and types ofACLs
+ow to $dentify ACLs
Standard $P lists ,1-../ test conditions of all $Ppac ets from so&rce addresses0 tended $P lists ,1 -1../ test conditions ofso&rce and destination addresses' specificTCP $P protocols' and destination ports
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 9/128Bringing a True-long Stand Vocation 9
www.saigonlab.vn
Lesson 1: The purpose and types ofACLs
+ow to $dentify ACLsStandard $P lists ,13 -1.../ ,e panded range/0 tended $P lists ,2 -24../ ,e panded range/Ot!er ACL n&m(er ranges test conditions forot!er networ ing protocols5amed ACLs identify $P standard and e tended
ACLs wit! an alp!an&meric string ,name/
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 10/128Bringing a True-long Stand Vocation 10
www.saigonlab.vn
Lesson 1: The purpose and types ofACLs
Testing Pac ets wit! Standard ACLs
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 11/128
Bringing a True-long Stand Vocation 11
www.saigonlab.vn
Lesson 1: The purpose and types ofACLs
Testing Pac ets wit! 0 tended ACLs
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 12/128
Bringing a True-long Stand Vocation 12
www.saigonlab.vn
Lesson 1: The purpose and types ofACLs
O&t(o&nd ACL Operation
$f no ACL state%ent %atches& discard the pac!et
'utbound$nterfaces
(ac!et
(ac!et
Notify ender (ac!et)iscard*uc!et
$nbound$nterface
(ac!et
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 13/128
Bringing a True-long Stand Vocation 13
www.saigonlab.vn
Lesson 1: The purpose and types ofACLs
A List of Tests6 7eny or Permit
(ac!et)iscard*uc!et
$nterface+s,
)estination
$f no Match deny All
(ac!et to $nterface+s, inthe Access -roup
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 14/128
Bringing a True-long Stand Vocation 14
www.saigonlab.vn
Lesson 1: The purpose and types ofACLs
Wildcard 8its6 +ow to C!ec t!eCorresponding Address 8its
means c!ec val&e of corresponding address (it1 means ignore val&e of corresponding address (it
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 15/128
Bringing a True-long Stand Vocation 15
www.saigonlab.vn
Lesson 1: The purpose and types ofACLs
Wildcard Bits to Match a Specific IPHost AddressChec! all of the address bits +%atch all,
erify an $( host address& for e#a%ple:
) 192:3 :14:2. : : : c!ec s all of t!e address (its) A((reviate t!is wildcard mas &sing t!e $P address
preceded (y t!e eyword !ost , !ost 192:3 :14:2. /
h d f
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 16/128
Bringing a True-long Stand Vocation 16
www.saigonlab.vn
Lesson 1: The purpose and types ofACLs
Wildcard 8its to Matc! Any $P AddressTest conditions: $gnore all the address bits+%atch any,An $( host address& for e#a%ple:
) Accept any address: any) Abbreviate e#pression with !eyword / any 0
h d f
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 17/128
Bringing a True-long Stand Vocation 17
www.saigonlab.vn
Lesson 1: The purpose and types ofACLs
Wildcard 8its to Matc! $P S&(netsChec! for $( subnets 17 .23. 14 .35 6 to17 .23. 21 .35 6
) Address and wildcard mas 6 192:3 :14:: :1;:2;;
L C fi d l
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 18/128
Bringing a True-long Stand Vocation 18
www.saigonlab.vn
Lesson : Configure and apply anACLs
$mplementing ACLs Config&ring Standard $P ACLs
Config&ring 0 tended $P ACLs "sing 5amed ACLs Config&ring vty ACLs
*&idelines for Placing ACLs <erifying t!e ACL Config&ration
L C fi d l
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 19/128
Bringing a True-long Stand Vocation 19
www.saigonlab.vn
Lesson : Configure and apply anACLs
ACL Config&ration *&idelines ACL n&m(ers indicate w!ic! protocol is filteredOne ACL per interface' per protocol' perdirection is allowedT!e order of ACL statements controls testingT!e most restrictive statements go at t!e top oft!e listT!e last ACL test is always an implicit deny anystatement' so every list needs at least onepermit statement
ACLs m&st (e created (efore applying t!em tointerfaces
ACLs filter traffic going t!ro&g! t!e ro&ter: ACLsdo not filter traffic originating from t!e ro&ter
L C fi d l
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 20/128
Bringing a True-long Stand Vocation 20
www.saigonlab.vn
Lesson : Configure and apply anACLs
ACL Commandtep 1: et para%eters for this ACL teststate%ent +which can be one of severalstate%ents,
tep : "nable an interface to use thespecified ACL
) Standard $P lists ,1-../) 0 tended $P lists ,1 -1../
outer+config,8access9list access-list-number
per%it ; deny< test conditions <
outer+config9if,8 protocol < access9groupaccess-list-number in ; out<
L C fi d l
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 21/128
Bringing a True-long Stand Vocation 21
www.saigonlab.vn
Lesson : Configure and apply anACLs
Standard $P ACL Config&ration
Sets parameters for t!is list entry$P standard ACLs &se 1 to ..
7efa< wildcard mas = : : :no access9list access-list-number removes entire ACLremar lets yo& add a description for t!e ACL
Activates t!e list on an interfaceSets in(o&nd or o&t(o&nd testing7efa< = o&t(o&ndno ip access9group access-list-number removes ACLfrom t!e interface
Router(config)#access-list access-list-number{permit | deny | remark} source [ mask ]
Router(config-if)#ip access-groupaccess-list-number {in | out}
L C fi d l
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 22/128
Bringing a True-long Stand Vocation 22
www.saigonlab.vn
Lesson : Configure and apply anACLs
Standard $P ACL - 0 ample 1
Permit my networ only
outer+config,8 access9list 1 per%it 17 .14.3.3 3.3. ==. ==+$%plicit deny all > not visible in the List,+access9list 1 deny 3.3.3.3 ==. ==. ==. ==,
outer+config,8 interface ethernet 3outer+config,8 ip access9group 1 outouter+config,8 interface ethernet 1outer+config,8 ip access9group 1 out
L C fi d l
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 23/128
Bringing a True-long Stand Vocation 23
www.saigonlab.vn
Lesson : Configure and apply anACLs
Standard $P ACL - 0 ample 2
7eny a specific !ost
outer+config,8 access9list 1 deny 17 .14.6.12 3.3.3.3outer+config,8 access9list 1 per%it 3.3.3.3 ==. ==. ==. ==
+i%plicit e deny all,+access9list 1 deny 3.3.3.3 ==. ==. ==. ==,
outer+config,8 interface ethernet 3outer+config,8 ip access9group 1 out
L C fig d l
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 24/128
Bringing a True-long Stand Vocation 24
www.saigonlab.vn
Lesson : Configure and apply anACLs
Standard $P ACL - 0 ample 3
7eny a specific s&(net
outer+config,8 access9list 1 deny 17 .14.6.3 3.3.3. ==outer+config,8 access9list 1 per%it any
+i%plicit e deny all,+access9list 1 deny 3.3.3.3 ==. ==. ==. ==,
outer+config,8 interface ethernet 3outer+config,8 ip access9group 1 out
L C fig d l
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 25/128
Bringing a True-long Stand Vocation 25
www.saigonlab.vn
Lesson : Configure and apply anACLs
0 tended $P ACL Config&ration
Sets parameters for t!is list entry
Activates t!e e tended list on an interface
Router(config)#access-list access-list-number {permit | deny} protocol source source-wildcard[ operator port ] destination destination-wildcard
[ operator port ] [established] [log]
Router(config-if)#ip access-group access-list-number {in | out}
Lesson : Config re and appl an
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 26/128
Bringing a True-long Stand Vocation 26
www.saigonlab.vn
Lesson : Configure and apply anACLs
0 tended ACL - 0 ample 1
7eny %TP from s&(net 192:14:>: to s&(net 192:14:3: o&t 0Permit all ot!er traffic
outer+config,8 access9list 131 deny tcp 17 .14.6.3 3.3.3. == 17 .14.2.3 3.3.3. == e? 1outer+config,8 access9list 131 deny tcp 17 .14.6.3 3.3.3. == 17 .14.2.3 3.3.3. == e? 3outer+config,8 access9list 131 per%it ip any any
+i%plicit e deny all,
+access9list 1 deny 3.3.3.3 ==. ==. ==. == 3.3.3.3 ==. ==. ==. ==,
outer+config,8 interface ethernet 3outer+config,8 ip access9group 131 out
Lesson : Configure and apply an
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 27/128
Bringing a True-long Stand Vocation 27
www.saigonlab.vn
Lesson : Configure and apply anACLs
0 tended ACL - 0 ample 2
7eny only Telnet from s&(net 192:14:>: o&t 0Permit all ot!er traffic
outer+config,8 access9list 131 deny tcp 17 .14.6.3 3.3.3. == any e? 2outer+config,8 access9list 131 per%it ip any any
+i%plicit e deny all,
outer+config,8 interface ethernet 3outer+config,8 ip access9group 131 out
Lesson : Configure and apply an
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 28/128
Bringing a True-long Stand Vocation 28
www.saigonlab.vn
Lesson : Configure and apply anACLs
"sing 5amed $P ACL
Alp!an&meric name string m&st (e &ni?&e
Permit or deny statements !ave no prepended n&m(er @no removes t!e specific test from t!e named ACL
Activates t!e named $P ACL on an interface
Router(config)#ip access-list {standard | e tended} name
Router(config {std- | e t-}nacl)#{permit | deny}{ip access list test conditions}{permit | deny} {ip access list test conditions}no {permit | deny} {ip access list test conditions}
Router(config-if)#ip access-group name {in | out}
Lesson : Configure and apply an
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 29/128
Bringing a True-long Stand Vocation 29
www.saigonlab.vn
Lesson : Configure and apply anACLs
%iltering vty Access to a Bo&ter
%ive virt&al terminal lines , t!ro&g! >/%ilter addresses t!at can access t!e ro&ter vty ports%ilter vty access originating from t!e ro&ter
Lesson : Configure and apply an
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 30/128
Bringing a True-long Stand Vocation 30
www.saigonlab.vn
Lesson : Configure and apply anACLs
+ow to Control vty Access
Set &p an $P address filter wit! a standard ACL statement
"se line config&ration mode to filter access wit! t!e access-class commandSet identical restrictions on every vty
Lesson : Configure and apply an
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 31/128
Bringing a True-long Stand Vocation 31
www.saigonlab.vn
Lesson : Configure and apply anACLs
vty Commands
0nters config&ration mode for a vty or vty range
Bestricts incoming or o&tgoing vty connections foraddresses in t!e ACL
Router(config)#line !ty { vty# | vty-range }
Router(config-line)#access-class access-list-number {in | out}
Lesson : Configure and apply an
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 32/128
Bringing a True-long Stand Vocation 32
www.saigonlab.vn
Lesson : Configure and apply anACLs
vty Access 0 ampleControlling $n(o&nd Access
) Permits only !osts in networ 1.2:14 :1:: : :2;; to connect to t!e ro&ter vty
access-list " permit "$ %"&'%"% % % %
(implicit deny any) *line !ty + access-class " in
Lesson : Configure and apply an
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 33/128
Bringing a True-long Stand Vocation 33
www.saigonlab.vn
Lesson : Configure and apply anACLs
ACL Config&ration *&idelinesT!e order of ACL statements is cr&cial
) Becommended6 "se a te t editor on a PC to create t!e ACLstatements' t!en c&t and paste t!em into t!e ro&ter
) Top-down processing is important
) Place t!e more specific test statements firstStatements cannot (e rearranged or removed
) "se t!e no access9list nu%ber command to remove t!eentire ACL
) 0 ception6 5amed ACLs permit removal of individ&alstatements
$mplicit deny any will (e applied to all pac ets t!at donot matc! any ACL statement &nless t!e ACL endswit! an e plicit permit any statement
Lesson : Configure and apply an
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 34/128
Bringing a True-long Stand Vocation 34
www.saigonlab.vn
Lesson : Configure and apply anACLs
W!ere to Place $P ACLs
Place standard ACLs close to t!e destinationPlace e tended ACLs close to t!e so&rce
Lesson : Configure and apply an
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 35/128
Bringing a True-long Stand Vocation 35
www.saigonlab.vn
Lesson : Configure and apply anACLs
Monitoring ACL Statements, . $ #sho {protocol} access-list { access-list number }
, . $ #sho access-lists { access-list number }
g.ro.a# sho access-lists,tandard /0 access list " permit " % % %" permit " %1%1%" permit " %+%+%" permit " % % %"2 tended /0 access list " " permit tcp host " % % %" any e3 telnet permit tcp host " %11%11%" any e3 ftp permit tcp host " %++%++%" any e3 ftp-data"&
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 36/128
Bringing a True-long Stand Vocation 36
www.saigonlab.vn
Lesson 2: The basic operation of NAT
$ntrod&cing 5AT and PAT Translating $nside So&rce Addresses
Overloading an $nside *lo(al Address <erifying t!e 5AT and PAT Config&ration Tro&(les!ooting t!e 5AT and PAT Config&ration
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 37/128
Bringing a True-long Stand Vocation 37
www.saigonlab.vn
Lesson 2: The basic operation of NAT
5etwor Address Translation
An $P address is eit!er local or glo(alLocal $P addresses are seen in t!e inside networ
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 38/128
Bringing a True-long Stand Vocation 38
www.saigonlab.vn
Lesson 2: The basic operation of NAT
Port Address Translation
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 39/128
Bringing a True-long Stand Vocation 39
www.saigonlab.vn
Lesson 2: The basic operation of NAT
Translating $nside So&rce Addresses
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 40/128
Bringing a True-long Stand Vocation 40
www.saigonlab.vn
Lesson 2: The basic operation of NAT
Config&ring Static Translation
) 0sta(lis!es static translation (etween an insidelocal address and an inside glo(al address
) Mar s t!e interface as connected to t!e inside
) Mar s t!e interface as connected to t!e o&tside
Router(config)#ip nat inside source static local-ip global-ip
Router(config-if)#ip nat inside
Router(config-if)#ip nat outside
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 41/128
Bringing a True-long Stand Vocation 41
www.saigonlab.vn
Lesson 2: The basic operation of NAT
0na(ling Static 5AT Address Mapping 0 ample
$nterface s3ip address 1@ .14 .1.1 ==. ==. ==.3
ip nat outsideB$nterface e3ip address 13.1.1.1 ==. ==. ==.3ip nat insideB$p nat inside source static 13.1.1. 1@ .14 .1.
h b f
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 42/128
Bringing a True-long Stand Vocation 42
www.saigonlab.vn
Lesson 2: The basic operation of NAT
Config&ring 7ynamic Translation
7efines a pool of glo(al addresses to (e allocated as needed
7efines a standard $P ACL permitting t!ose inside localaddresses t!at are to (e translated
0sta(lis!es dynamic so&rce translation' specifying t!e ACL t!atwas defined in t!e prior step
Router(config)#ip nat pool name start-ip end-ip {netmask netmask | prefi -length prefix-length }
Router(config)#access-list access-list-number permitsource [ source-wildcard ]
Router(config)#ip nat inside source listaccess-list-number pool name
h b f
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 43/128
Bringing a True-long Stand Vocation 43
www.saigonlab.vn
Lesson 2: The basic operation of NAT
7ynamic Address Translation 0 ample$p nat pool net9 3 17 .4@. 22. 3@ 171.4@. 22. net%ar!
==. ==. ==. 63ip nat inside source list 1 pool net9 3B$nterfave serial 3 ip address 17 .4@. 2 .1 ==. ==. ==. 63 ip nat outsideB
$nterface ethernet 3 ip address 1@ .14 .1.@6 ==. ==. ==.3 ip nat insideBAccess9list 1 per%it 1@ .14 .1.3 3.3.3. ==
1@ .14 .1.@6 171.4@. 2 .1
"3 3
ost )17 .14 .1.1
ost C13.1.1.1
ost *1@ .14 .1.131
ost A1@ .14 .1.133
L 2 Th b i i f NAT
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 44/128
Bringing a True-long Stand Vocation 44
www.saigonlab.vn
Lesson 2: The basic operation of NAT
Overloading an $nside *lo(al Address
L 2 Th b i i f NAT
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 45/128
Bringing a True-long Stand Vocation 45
www.saigonlab.vn
Lesson 2: The basic operation of NAT
Config&ring Overloading
) 7efines a standard $P ACL t!at will permit t!e insidelocal addresses t!at are to (e translated
0sta(lis!es dynamic so&rce translation' specifyingt!e ACL t!at was defined in t!e prior step
Router(config)#ip nat inside source listaccess-list-number interface interface o!erload
Router(config)#access-list access-list-number permitsource source-wildcard
L 2 Th b i i f NAT
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 46/128
Bringing a True-long Stand Vocation 46
www.saigonlab.vn
Lesson 2: The basic operation of NAT
Overloading an $nside *lo(al Address 0 ample
1@ .14 .6.1
1@ .14 .6.11@ .14 .2.1
1@ .14 .6.1
"3
"1 317 .17.2 .1
L 2 Th b i i f NAT
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 47/128
Bringing a True-long Stand Vocation 47
www.saigonlab.vn
Lesson 2: The basic operation of NAT
7isplaying $nformation wit! s!ow Commands
7isplays active translations
7isplays translation statisticsRouter#sho ip nat statistics
Router#sho ip nat translations
Router#sho ip nat translation 0ro /nside global /nside local 4utside local 4utside global --- "5 %"&%"1"%" " %" %" %" --- ---
Router#sho ip nat statistics 6otal acti!e translations7 " (" static8 dynamic9 e tended) 4utside interfaces7 2thernet 8 ,erial %5 /nside interfaces7 2thernet" :its7 ;isses7 <
L 2 Th b i ti f NAT
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 48/128
Bringing a True-long Stand Vocation 48
www.saigonlab.vn
Lesson 2: The basic operation of NAT
Sample Pro(lem6 Cannot Ping Bemote +ost
ost A1@ .14 .1.
1@ .14 . .113.1.1. 5 61@ .14 .
int e3 ip address 1@ .14 . .1 ==. ==. ==.3Bint s3 ip address 13.1.1. ==. ==. ==.3B outer rip networ! 13.3.3.3 networ! 1@ .14 . .3
ost *1@ .14 . .
ip nat pool test 17 .14.17. 3 17 .14.17.23ip nat inside source list 1 pool testBint s3 ip address 13.1.1.1 ==. ==. ==.3 ip nat inside
Bint e3 ip address 1@ .14 .1.1 ==. ==. ==.3
ip nat outsideB
outer rip networ! 13.3.3.3 networ! 1@ .14 .1.3BAccess9list 1 per%it 1@ .14 .1.3 ==. ==. ==.3
L 2 Th b i ti f NAT
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 49/128
Bringing a True-long Stand Vocation 49
www.saigonlab.vn
Lesson 2: The basic operation of NAT
Sol&tion6 5ew Config&ration
ost A1@ .14 .1.
ost *1@ .14 . .
1@ .14 . .113.1.1. 5 61@ .14 .1
$nt e3 ip address 1@ .14 . .1 ==. ==. ==.3B$nt s3 ip address 13.1.1. ==. ==. ==.3B
outer rip networ! 13.3.3.1 networ! 1@ .1 . .3
L 2 Th b i ti f NAT
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 50/128
Bringing a True-long Stand Vocation 50
www.saigonlab.vn
Lesson 2: The basic operation of NAT
"sing t!e de(&g ip nat Command
Router# debug ip nat
=>67 s?"$ %"&'%"%$ -@"5 %1"% 11% $8 d?"5 %1"% %"1 [&' ] =>67 s?"5 %1"% %"1 8 d?"5 %1"% 11% $-@"$ %"&'%"%$ [ "' ] =>67 s?"$ %"&'%"%$ -@"5 %1"% 11% $8 d?"5 %1"%"%"&" [&' &] =>6A7 s?"5 %1"%"%"&"8 d?"5 %1"% 11% $-@"$ %"&'%"%$ [ 11""] =>6A7 s?"$ %"&'%"%$ -@"5 %1"% 11% $8 d?"5 %1"%"%"&" [&' 5] =>6A7 s?"$ %"&'%"%$ -@"5 %1"% 11% $8 d?"5 %1"%"%"&" [&' '] =>6A7 s?"5 %1"%"%"&"8 d?"5 %1"% 11% $-@"$ %"&'%"%$ [ 11"1] =>6A7 s?"5 %1"%"%"&"8 d?"5 %1"% 11% $-@"$ %"&'%"%$ [ 11 ]
L 2 Th b i ti f NAT
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 51/128
Bringing a True-long Stand Vocation 51
www.saigonlab.vn
Lesson 2: The basic operation of NAT
Translation 5ot $nstalled in t!eTranslation Ta(le#
<erify t!at6) T!e config&ration is correct
) T!ere are not any in(o&nd ACLs denying t!e pac ets entryto t!e 5AT ro&ter
) T!e ACL referenced (y t!e 5AT command is permitting allnecessary networ s
) T!ere are eno&g! addresses in t!e 5AT pool) T!e ro&ter interfaces are appropriately defined as 5AT
inside or 5AT o&tside
Module : $%ple%ent and verify DAN
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 52/128
Bringing a True-long Stand Vocation 52
www.saigonlab.vn
$ p ylin!s
Methods for connecting to aDAN
1
Connecting to e%ote Networ!s2
((( connection between Cisco routers3
Era%e elay on Cisco routers>
(N Technology;
Lesson 1: Methods for connecting to a
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 53/128
Bringing a True-long Stand Vocation 53
www.saigonlab.vn
gDAN
W!at $s a Wide Area 5etwor #W!y Are WA5s 5ecessary#+ow $s a WA5 7ifferent from a LA5#
WA5 Access and t!e OS$ Beference ModelWA5 7evicesT!e Bole of Bo&ters in WA5s
WA5 7ata Lin ProtocolsM<iple ingWA5 Comm&nication Lin Options
Lesson 1: Methods for connecting to a
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 54/128
Bringing a True-long Stand Vocation 54
www.saigonlab.vn
gDAN
Wide-Area 5etwor
Lesson 1: Methods for connecting to a
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 55/128
Bringing a True-long Stand Vocation 55
www.saigonlab.vn
gDAN
5eed for WA5s*ussiness (artners
ery e%ote 'ffice
Thousands ofe%ote Dor!ers
egional 'fficee%ote 'ffice
o%e 'ffices Mobile Dor!ers
Lesson 1: Methods for connecting to a
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 56/128
Bringing a True-long Stand Vocation 56
www.saigonlab.vn
gDAN
WA5s vs: LA5s
DANs LANs
Area
'wnership
Lesson 1: Methods for connecting to a
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 57/128
Bringing a True-long Stand Vocation 57
www.saigonlab.vn
gDAN
WA5 Access and t!e OS$ Model
Lesson 1: Methods for connecting to a
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 58/128
Bringing a True-long Stand Vocation 58
www.saigonlab.vn
gDAN
WA5 7evices
Lesson 1: Methods for connecting to a
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 59/128
Bringing a True-long Stand Vocation 59
www.saigonlab.vn
gDAN
WA5 Connection Types6 Layer 1
Lesson 1: Methods for connecting to a
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 60/128
Bringing a True-long Stand Vocation 60
www.saigonlab.vn
gDAN
WA5DM<iple LA5s
Lesson 1: Methods for connecting to a
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 61/128
Bringing a True-long Stand Vocation 61
www.saigonlab.vn
gDAN
$nterfacing 8etween WA5 Service Providers
Provider assigns connection parameters to s&(scri(er
Lesson 1: Methods for connecting to a
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 62/128
Bringing a True-long Stand Vocation 62
www.saigonlab.vn
gDAN
Serial Point-to-Point Connectionsouter Connections"nd9Fser )evice
)T"
)C"C F5) F
Networ! Connections at the C F5) F
Lesson 1: Methods for connecting to a
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 63/128
Bringing a True-long Stand Vocation 63
www.saigonlab.vn
gDAN
Typical WA5 0ncaps&lation Protocols6Layer 2
Lesson 1: Methods for connecting to a
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 64/128
Bringing a True-long Stand Vocation 64
www.saigonlab.vnDAN
M<iple ing Tec!nologies
Time-7ivision M<iple ing ,T7M/%re?&ency-7ivision M<iple ing ,%7M/Statistical M<iple ing
Multiple#er
Lesson 1: Methods for connecting to a
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 65/128
Bringing a True-long Stand Vocation 65
www.saigonlab.vnDAN
WA5 Lin OptionsDAN
witched)edicated
Lesson : Connecting to e%ote
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 66/128
Bringing a True-long Stand Vocation 66
www.saigonlab.vnNetwor!s
Circ&it-Switc!ed Comm&nication Lin sP&(lic Switc!ed Telep!one 5etwor$ntegrated 7igital Services 5etworPac et-Switc!ed Comm&nication Lin sE:2;%rame Belay
Async!rono&s Transfer Mode and Cell Switc!ing7SLCa(le*lo(al $nternetFt!e Largest WA5
Lesson : Connecting to e%ote
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 67/128
Bringing a True-long Stand Vocation 67
www.saigonlab.vnNetwor!s
Circ&it Switc!ing
Lesson : Connecting to e%ote
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 68/128
Bringing a True-long Stand Vocation 68
www.saigonlab.vnNetwor!s
PST5
Local "#change
Lesson : Connecting to e%ote
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 69/128
Bringing a True-long Stand Vocation 69
www.saigonlab.vnNetwor!s
PST5 ConsiderationsAdvantages
) Simplicity
) Availa(ility) Cost
)isadvantages) Low data rates
) Belatively long connection set&p time
Lesson : Connecting to e%oteN !
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 70/128
Bringing a True-long Stand Vocation 70
www.saigonlab.vnNetwor!s
$S75
Lesson : Connecting to e%oteN !
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 71/128
Bringing a True-long Stand Vocation 71
www.saigonlab.vnNetwor!s
8B$ and PB$
Lesson : Connecting to e%oteN !
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 72/128
Bringing a True-long Stand Vocation 72
www.saigonlab.vnNetwor!s
$S75 ConsiderationsAdvantages
) Speed
) Always-on availa(ility)isadvantages) Limited geograp!ic availa(ility) Cost
Lesson : Connecting to e%oteN !
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 73/128
Bringing a True-long Stand Vocation 73
www.saigonlab.vnNetwor!s
Pac et Switc!ing
ynchronous
erial
ynchronouserial
Lesson : Connecting to e%oteN t !
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 74/128
Bringing a True-long Stand Vocation 74
www.saigonlab.vnNetwor!s
WA5 wit! E:2;
Lesson : Connecting to e%oteN t !
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 75/128
Bringing a True-long Stand Vocation 75
www.saigonlab.vnNetwor!s
%rame Belay)C" or Era%e
elay witch
Era%e elay wor!s here
Lesson : Connecting to e%oteN t !
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 76/128
Bringing a True-long Stand Vocation 76
www.saigonlab.vnNetwor!s
%rame Belay 7evices and <irt&al Circ&its
Lesson : Connecting to e%oteN t !
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 77/128
Bringing a True-long Stand Vocation 77
www.saigonlab.vnNetwor!s
ATM and Cell Switc!ing
ATM witch ATM witch
Cells
Lesson : Connecting to e%oteNet or!s
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 78/128
Bringing a True-long Stand Vocation 78
www.saigonlab.vnNetwor!s
7SL
Lesson : Connecting to e%oteNetwor!s
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 79/128
Bringing a True-long Stand Vocation 79
www.saigonlab.vnNetwor!s
7SL Service Types Overview
)own Fp )own Fp
Lesson : Connecting to e%oteNetwor!s
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 80/128
Bringing a True-long Stand Vocation 80
www.saigonlab.vnNetwor!s
7SL ConsiderationsAdvantages
) Speed) Sim<aneo&s voice and data transmission
) $ncremental additions) Always-on availa(ility) 8ac ward compati(ility wit! analog p!ones
)isadvantages) Limited availa(ility) Local p!one company re?&irements) Sec&rity ris s
Lesson : Connecting to e%oteNetwor!s
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 81/128
Bringing a True-long Stand Vocation 81
www.saigonlab.vnNetwor!s
Ca(le-8ased WA5s
Cable Mode% Cableeadend
Cable outer with 69port witch
Lesson : Connecting to e%oteNetwor!s
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 82/128
Bringing a True-long Stand Vocation 82
www.saigonlab.vnNetwor!s
+ow Ca(le Modems Wor(icasso "instein Leonard
osieCoa#ial Cable
Coa#
Gi%%y Mo%
-randpa
Gunior
(adA%plifier
plitter
Tap
Lesson : Connecting to e%oteNetwor!s
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 83/128
Bringing a True-long Stand Vocation 83
www.saigonlab.vnNetwor!s
T!e *lo(al $nternet
Lesson 2: ((( connection betweenCisco routers
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 84/128
Bringing a True-long Stand Vocation 84
www.saigonlab.vnCisco routers
+7LC 0ncaps&lation Config&rationPPP Layered Arc!itect&rePPP Config&ration
PPP Session 0sta(lis!mentPPP A&t!entication ProtocolsPPP A&t!entication Config&ration
Serial 0ncaps&lation Config&ration <erificationPPP A&t!entication Config&ration Tro&(les!ooting
Lesson 2: ((( connection betweenCisco routers
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 85/128
Bringing a True-long Stand Vocation 85
www.saigonlab.vnCisco routers
+7LC %rame %ormat
"ses a proprietary data field to s&pportm<iprotocol environments
S&pports only single-protocol environments
Lesson 2: ((( connection betweenCisco routers
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 86/128
Bringing a True-long Stand Vocation 86
www.saigonlab.vnCisco routers
Config&ring +7LC 0ncaps&lation
0na(les +7LC encaps&lation"ses t!e defa< encaps&lation on sync!rono&sserial interfaces
outer+config9if,8 encapsulation hdlc
Lesson 2: ((( connection betweenCisco routers
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 87/128
Bringing a True-long Stand Vocation 87
www.saigonlab.vnCisco routers
An Overview of PPP
PPP can carry pac ets from several protocol s&ites &sing 5CPPPP controls t!e set&p of several lin options &sing LCP
Multiple (rotocol"ncapsulations
Fsing NC(s in (((
Lesson 2: ((( connection betweenCisco routers
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 88/128
Bringing a True-long Stand Vocation 88
www.saigonlab.vnCisco routers
Layering PPP 0lements
PPP = 7ata lin wit! networ layer services
Lesson 2: ((( connection betweenCisco routers
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 89/128
Bringing a True-long Stand Vocation 89
www.saigonlab.vnCisco routers
PPP LCP Config&ration Options
Lesson 2: ((( connection betweenCisco routers
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 90/128
Bringing a True-long Stand Vocation 90
www.saigonlab.vnCisco routers
PPP Session 0sta(lis!ment
Two PPP a&t!entication protocols6 PAP and C+AP
Lesson 2: ((( connection betweenCisco routers
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 91/128
Bringing a True-long Stand Vocation 91
www.saigonlab.vnCisco routers
PPP A&t!entication Protocols
Passwords sent in clear te tPeer in control of attempts
(A(Two9Day andsha!e
/santacruH boardwal!0
e%ote outer+santacruH,
ost na%e : santacruH(assword: broadwal!
Central9 ite outer+ I,
ost na%e : santacruH(assword: broadwal!
Lesson 2: ((( connection betweenCisco routers
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 92/128
Bringing a True-long Stand Vocation 92
www.saigonlab.vnCisco routers
C!allenge +ands!a e A&t!entication Protocol
+as! val&es' not act&al passwords' are sent across t!e linT!e local ro&ter or e ternal server is in control of attempts
e%ote outer+santacruH,
ost na%e : santacruH(assword: broadwal!
Lesson 2: ((( connection betweenCisco routers
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 93/128
Bringing a True-long Stand Vocation 93
www.saigonlab.vnCisco routers
Config&ring PPP and A&t!entication Overview
Lesson 2: ((( connection betweenCisco routers
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 94/128
Bringing a True-long Stand Vocation 94
www.saigonlab.vnCisco routers
Config&ring PPP
"nables ((( encapsulation
Router(config-if)#encapsulation ppp
Lesson 2: ((( connection betweenCisco routers
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 95/128
Bringing a True-long Stand Vocation 95
www.saigonlab.vnCisco routers
Config&ring PPP A&t!entication
Assigns a host na%e to your router
$dentifies the userna%e and password ofre%ote router
0na(les PAP or C+AP a&t!entication
Router(config)#hostname name
Router(config)#username name pass ord password
Router(config-if)#ppp authentication{chap | chap pap | pap chap | pap}
Lesson 2: ((( connection betweenCisco routers
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 96/128
Bringing a True-long Stand Vocation 96
www.saigonlab.vnCisco routers
C+AP Config&ration 0 ample
Lesson 2: ((( connection betweenCisco routers
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 97/128
Bringing a True-long Stand Vocation 97
www.saigonlab.vnCisco routers
<erifying t!e +7LC and PPP0ncaps&lation Config&rationRouter# sho interface s,erial is up8 line protocol is up :ard are is :B&+ 5 /nternet address is " %"+ %"% C + ;6D " bytes8 EF " ++ Gbit8 BHI usec8 rely C 8 load "C 2ncapsulation 0008 loopback not set8 keepali!e set (" sec) HJ0 4pen <<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<< minute input rate bitsCsec8 packetsCsec minute output rate bitsCsec8 packetsCsec 1' " packets input8 & &"" bytes8 no buffer Recei!ed 1+'' broadcasts8 runts8 giants8 throttles
input errors8 JRJ8 frame8 o!errun8 ignored8 abort 1' $5 packets output8 "1 &$5 bytes8 underruns output errors8 collisions8 & + interface resets output buffer failures8 output buffers s apped out +' carrier transitions BJB?up B,R?up B6R?up R6,?up J6,?up
Lesson 2: ((( connection betweenCisco routers
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 98/128
Bringing a True-long Stand Vocation 98
www.saigonlab.vnCisco routers
<erifying PPP A&t!entication
) de(&g ppp a&t!entication s!ows s&ccessf&l C+AP o&tp&t:
outer8 debug ppp authentication6d 3h : J L$NK929F()'DN : $nterface erial3& changed state to up6d 3h : e3 ((( : Treating connection as a dedicated line6d 3h : e3 (((: (hase is AFT "NT$CAT$N-& by both6d 3h : e3 C A( : 3 C ALL"N-" id len fro% /left06d 3h : e3 C A( : $ C ALL"N-" id 2 len fro% /right06d 3h : e3 C A( : $ " ('N " id 2 len fro% /left06d 3h : e3 C A( : $ " ('N " id len fro% /right06d 3h : e3 C A( : 3 FCC" id len 6
6d 3h : e3 C A( : $ FCC" id 2 len 66d 3h : JL$N"( 'T'9=9F()'DN : Line (rotocol on $nterface erial3& changedstate to up
Lesson 2: ((( connection betweenCisco routers
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 99/128
Bringing a True-long Stand Vocation 99
www.saigonlab.vnC sco oute s
<erifying PPP 5egotiationRouter# debug ppp negotiation000 protocol negotiation debugging is onRouter#A;ar " 7 &71&%&+ 7 KH/=G-1-D0B4F=7 /nterface ER/ 7"8 changed state to upA;ar " 7 &71&%&&"7 ER 7" 0007 6reating connection as a callinA;ar " 7 &71&%&& 7 ER 7" 0007 0hase is 2,6>EH/,:/=L8 0assi!e 4penA;ar " 7 &71&%&&$7 ER 7" HJ07 ,tate is HistenA;ar " 7 &715% 1+7 ER 7" HJ07 / J4=MR2N [Histen] id 5 len "5A;ar " 7 &715% 1'7 ER 7" HJ07 >uth0roto 0>0 ( 1 +J 1)A;ar " 7 &715% + 7 ER 7" HJ07 ;agic=umber 5> "+B ( & 5> "+B)A;ar " 7 &715% +&7 ER 7" HJ07 Jallback ( B 1 )A;ar " 7 &715% +7 ER 7" HJ07 4 J4=MR2N [Histen] id + len "A;ar " 7 &715% '7 ER 7" HJ07 >uth0roto J:>0 ( 1 J 1 )A;ar " 7 &715% & 7 ER 7" HJ07 ;agic=umber " '"252" ( &" '"252")A;ar " 7 &715% &&7 ER 7" HJ07 4 J4=MR2O [Histen] id 5 len 5A;ar " 7 &715% 5 7 ER 7" HJ07 Jallback ( B 1 )A;ar " 7 &715% $'7 ER 7" HJ07 / J4=M>JG [R2Nsent] id + len "A;ar " 7 &715%" 7 ER 7" HJ07 >uth0roto J:>0 ( 1 J 1 )A;ar " 7 &715%" &7 ER 7" HJ07 ;agic=umber " '"252" ( &" '"252")A;ar " 7 &715%""+7 ER 7" HJ07 / J4=MR2N [>JGrc!d] id ' len "+A;ar " 7 &715%""57 ER 7" HJ07 >uth0roto 0>0 ( 1 +J 1)A;ar " 7 &715%" "7 ER 7" HJ07 ;agic=umber 5> "+B ( & 5> "+B)
Lesson 6: Era%e elay on Ciscorouters
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 100/128
Bringing a True-long Stand Vocation 100
www.saigonlab.vn
%rame Belay Overview%rame Belay Stac Layered S&pport%rame Belay Terminology%rame Belay Topologies
Beac!a(ility $ss&es in %rame BelayBeac!a(ility $ss&e Besol&tion%rame Belay Address Mapping
%rame Belay Signaling+ow Service Providers Map %rame Belay 7LC$sService Provider %rame Belay-to-ATM $nterwor ing
Lesson 6: Era%e elay on Ciscorouters
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 101/128
Bringing a True-long Stand Vocation 101
www.saigonlab.vn
%rame Belay Overview
Connections made (y virt&al circ&itsConnection-oriented service
Lesson 6: Era%e elay on Ciscorouters
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 102/128
Bringing a True-long Stand Vocation 102
www.saigonlab.vn
%rame Belay Stac' $ eference Model Era%e elay
(hysical
(resentation
ession
Transport
Networ!
)ata Lin!
Application
"$A5T$A9 2 &"$A5T$A966@& .2=&
. 1& "$A5T$A9=23
Era%e elay
$(5$( 5AppleTal!& etc.
Lesson 6: Era%e elay on Ciscorouters
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 103/128
Bringing a True-long Stand Vocation 103
www.saigonlab.vn
%rame Belay Terminology
)LC$ - 7ata-lin connection identifier LM$ - Local Management $nterface
outer A outer *
)LCL: 633
)LCL: 133
( C
LocalAccess
Loop T1
Local AccessLoop 46 !bps
Lesson 6: Era%e elay on Ciscorouters
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 104/128
Bringing a True-long Stand Vocation 104
www.saigonlab.vn
Selecting a %rame Belay Topology
%rame Belay defa<6 58MA
Lesson 6: Era%e elay on Ciscorouters
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 105/128
Bringing a True-long Stand Vocation 105
www.saigonlab.vn
Beac!a(ility $ss&es wit! Bo&ting "pdates
Pro(lem6
) 8roadcast traffic m&st (e replicated for eac! activeconnection) Split !oriGon r&le prevents ro&ting &pdates received on an
interface from (eing forwarded o&t t!e same interface
Lesson 6: Era%e elay on Ciscorouters
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 106/128
Bringing a True-long Stand Vocation 106
www.saigonlab.vn
Besolving Beac!a(ility $ss&es
Split !oriGon can ca&se pro(lems in 58MAenvironmentsS&(interfaces can resolve split-!oriGon iss&esSol&tion6 A single p!ysical interface sim&lates m<iplelogical interfaces
Lesson 6: Era%e elay on Ciscorouters
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 107/128
Bringing a True-long Stand Vocation 107
www.saigonlab.vn
%rame Belay Address Mapping
"se LM$ to get locally significant 7LC$ from t!e %rame Belay switc!"se $nverse ABP to map t!e local 7LC$ to t!e remote ro&ter networlayer address
Lesson 6: Era%e elay on Ciscorouters
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 108/128
Bringing a True-long Stand Vocation 108
www.saigonlab.vn
%rame Belay Signaling
Cisco s&pports t!ree LM$ standards6) Cisco) A5S$ T1:419 Anne 7) $T"-T H:.33 Anne A
Lesson 6: Era%e elay on Ciscorouters
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 109/128
Bringing a True-long Stand Vocation 109
www.saigonlab.vn
%rame Belay $nverse ABP and LM$ Signaling
Lesson 6: Era%e elay on Ciscorouters
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 110/128
Bringing a True-long Stand Vocation 110
www.saigonlab.vn
Stages of $nverse ABP and LM$ Operation
Lesson 6: Era%e elay on Ciscorouters
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 111/128
Bringing a True-long Stand Vocation 111
www.saigonlab.vn
Config&ring 8asic %rame Belay
Lesson 6: Era%e elay on Ciscorouters
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 112/128
Bringing a True-long Stand Vocation 112
www.saigonlab.vn
Config&ring a Static %rame Belay Map
Lesson 6: Era%e elay on Ciscorouters
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 113/128
Bringing a True-long Stand Vocation 113
www.saigonlab.vn
Config&ring S&(interfacesPoint-to-point) S&(interfaces act li e leased lines) 0ac! point-to-point s&(interface re?&ires its own s&(net
) Point-to-point is applica(le to !&(-and-spo e topologiesM<ipoint) S&(interfaces act li e 58MA networ s' so t!ey do not
resolve t!e split !oriGon iss&es
) M<ipoint can save address space (eca&se it &ses asingle s&(net
) M<ipoint is applica(le to partial mes! and f&ll mes!topologies
i l b
Lesson 6: Era%e elay on Ciscorouters
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 114/128
Bringing a True-long Stand Vocation 114
www.saigonlab.vn
Config&ring Point-to-Point S&(interfaces
i l b
Lesson 6: Era%e elay on Ciscorouters
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 115/128
Bringing a True-long Stand Vocation 115
www.saigonlab.vn
M<ipoint S&(interfaces Config&ration 0 ample
. 13.17.3.15 6 .1 13.17.3. 5 6
.1 13.17.3.25 6
.1 13.17.3.65 6
i l b
Lesson 6: Era%e elay on Ciscorouters
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 116/128
Bringing a True-long Stand Vocation 116
www.saigonlab.vn
Router# sho interfaces s,erial is up8 line protocol is up :ard are is :B&+ 5 /nternet address is " %"+ %"% C + ;6D " bytes8 EF " ++ Gbit8 BHI usec8 rely C 8 load "C 2ncapsulation MR>;2-R2H>I8 loopback not set8 keepali!e set (" sec) H;/ en3 sent "$8 H;/ stat rec!d 8 H;/ upd rec!d 8 B62 H;/ up H;/ en3 rec!d 8 H;/ stat sent 8 H;/ upd sent H;/ BHJ/ " 1 H;/ type is J/,J4 frame relay B62 MR ,PJ disabled8 H>0M state do n Eroadcast 3ueue C&+8 broadcasts sentCdropped 'C 8 interface broadcasts Hast input 7 7 8 output 7 7 8 output hang ne!er Hast clearing of Qsho interfaceQ counters ne!er Nueueing strategy7 fifo 4utput 3ueue C+ 8 drops9 input 3ueue C5 8 drops 4utput omitted@
<erifying %rame Belay Operation
7isplays information a(o&t %rame Belay 7LC$s and t!e LM$
outer8 show interfaces type number
ig l b
Lesson 6: Era%e elay on Ciscorouters
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 117/128
Bringing a True-long Stand Vocation 117
www.saigonlab.vn
Router# sho frame-relay lmi H;/ ,tatistics for interface ,erial (Mrame Relay B62)H;/ 6I02 ? J/,J4 /n!alid Dnnumbered info /n!alid 0rot Bisc /n!alid dummy Jall Ref /n!alid ;sg 6ype /n!alid ,tatus ;essage /n!alid Hock ,hift
/n!alid /nformation /B /n!alid Report /2 Hen /n!alid Report Re3uest /n!alid Geep /2 Hen =um ,tatus 2n3% ,ent ""1" =um ,tatus msgs Rc!d ""1" =um Dpdate ,tatus Rc!d =um ,tatus 6imeouts
<erifying %rame Belay Operation
)isplays LM$ statistics
Router# sho frame-relay lmi [ type number ]
www saigonlab vn
Lesson 6: Era%e elay on Ciscorouters
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 118/128
Bringing a True-long Stand Vocation 118
www.saigonlab.vn
Router# sho frame-relay p!c "0PJ ,tatistics for interface ,erial (Mrame Relay B62)
BHJ/ ? " 8 BHJ/ D,>L2 ? H4J>H8 0PJ ,6>6D, ? >J6/P28 /=62RM>J2 ? ,erial
input pkts ' output pkts " in bytes '1$'
out bytes ""$' dropped pkts in M2J= pkts in E2J= pkts out M2J= pkts out E2J= pkts in B2 pkts out B2 pkts out bcast pkts " out bcast bytes ""$' p!c create time 7 17+&8 last time p!c status changed 7 17+5
<erifying %rame Belay Operation
7isplays P<C statistics
outer8 show fra%e9relay pvc type number dlci OO
www saigonlab vn
Lesson 6: Era%e elay on Ciscorouters
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 119/128
Bringing a True-long Stand Vocation 119
www.saigonlab.vn
Router# sho frame-relay map
,erial (up)7 ip " %"+ %"%" dlci " ( &+8 "'+ )8 dynamic8 broadcast88 status defined8 acti!eRouter# clear frame-relay-inarpRouter# sho frame mapRouter#
<erifying %rame Belay Operation
7isplays t!e c&rrent %rame Belay map entries
Clears dynamically created %rame Belay maps'created (y &sing $nverse ABP
outer8 show fra%e9relay %ap
outer8 clear fra%e9relay9inarp
www saigonlab vn
Lesson 6: Era%e elay on Ciscorouters
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 120/128
Bringing a True-long Stand Vocation 120
www.saigonlab.vn
Router# debug frame-relay lmiMrame Relay H;/ debugging is onBisplaying all Mrame Relay H;/ dataRouter#" d7 ,erial (out)7 ,t2n38 myse3 "+ 8 yourseen "1$8 B62 up" d7 datagramstart ? 2 '2J8 datagramsiSe ? "1" d7 MR encap ? MJM" 1 $
" d7 5 " " " 1 'J 'E" d7" d7 ,erial (in)7 ,tatus8 myse3 "+" d7 R6 /2 "8 length "8 type "" d7 G> /2 18 length 8 yourse3 "+ 8 myse3 "+" d7 ,erial (out)7 ,t2n38 myse3 "+"8 yourseen "+ 8 B62 up" d7 datagramstart ? 2 '2J8 datagramsiSe ? "1" d7 MR encap ? MJM" 1 $" d7 5 " " " 1 'B 'J" d7" d7 ,erial (in)7 ,tatus8 myse3 "+" d7 R6 /2 "8 length "8 type " d7 G> /2 18 length 8 yourse3 "+ 8 myse3 "+" d7 0PJ /2 5 8 length & 8 dlci " 8 status 8 b
Tro&(les!ooting 8asic %rame Belay
Operations
)isplays LM$ debug infor%ation
www saigonlab vn
Lesson =: (N Technology
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 121/128
Bringing a True-long Stand Vocation 121
www.saigonlab.vn
<P5 7efinitionBemote Access <P5sSite-to-Site <P5sT&nneling Protocols I *B0T&nneling Protocols I $PSecT&nneling Protocols I L2% and L2TP
www saigonlab vn
Lesson =: (N Technology
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 122/128
Bringing a True-long Stand Vocation 122
www.saigonlab.vn
<P5 7efinition
<irt&al private networ ,<P5/Dan encryptedconnection (etween private networ s over ap&(lic networ s&c! as t!e $nternet
www saigonlab vn
Lesson =: (N Technology
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 123/128
Bringing a True-long Stand Vocation 123
www.saigonlab.vn
Bemote Access <P5s
www saigonlab vn
Lesson =: (N Technology
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 124/128
Bringing a True-long Stand Vocation 124
www.saigonlab.vn
Site-to-Site <P5s
Site-to-Site <P5 I 0 tension of classic WA5
www.saigonlab.vn
Lesson =: (N Technology
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 125/128
Bringing a True-long Stand Vocation 125
www.saigonlab.vn
T&nneling Protocols I *B0 ,*eneric Bo&ting0ncaps&lation/
CiscoJs m<iprotocol carrier t!at can encaps&late $P' CL5P'$PE' AppleTal ' 70Cnet' and E5S inside $P t&nnels8est for site-to-site <P5sTypically &sed to t&nnel m<icast pac ets s&c! as ro&tingprotocols7oes not s&pport data encryption or pac et integrity0ncaps&lates all traffic regardless of so&rce destination
www.saigonlab.vn
Lesson =: (N Technology
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 126/128
Bringing a True-long Stand Vocation 126
www.saigonlab.vn
T&nneling Protocols I $PSec ,$P Sec&rity/Most commonly &sed t&nneling protocol wit! <P5sCan (e &sed in com(ination wit! *B0 or L2TP ,Layer 2T&nneling Protocol/ w!en t!ere is a need to s&pportt&nneling m<icast pac ets"ses $K0 to manage e c!ange of sec&rity eysBeplay protection I someone capt&ring pac ets andreplaying t!em later to gain access7ata origin a&t!entication ,Ma es&re t!e pac ets are a&t!entic/Confidentiality I 0ncryption is&sed to !ide t!e $P !eader of t!eoriginal pac et
www.saigonlab.vn
Lesson =: (N Technology
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 127/128
Bringing a True-long Stand Vocation 127
g
T&nneling Protocols I L2% ,Layer 2 %orwarding/ andL2TP ,Layer 2 T&nneling Protocol/
CiscoJs protocol t!at was &sed (efore L2TP ,Layer 2T&nneling Protocol/ was esta(lis!ed$t is not forward compati(le wit! L2TP
L2TP is a com(ination of CiscoJs L2% and MicrosoftJs PPTP,Point-to-Point T&nneling Protocol/L2TP is &sed to create a media-independent' m<iprotocol<P75 ,<irt&al Private 7ial 5etwor / w!ic! allows &sers toinvo e corporate sec&rity policies across a <P5 or <P75lin as an e tension of t!eir internal networ
L2TP is good for remote-access <P5s t!at re?&irem<iprotocol s&pport ,or *B0/
8/10/2019 SaigonLAB CCNA Module7 Va Module 8
http://slidepdf.com/reader/full/saigonlab-ccna-module7-va-module-8 128/128
www.saigonlab.vn