1
Wichita State University
Department of Electrical and Computer Engineering
CCIE Preparation Laboratory
WSU CCIE Lab #4
Advanced MultiprotocolSkillsLab
Version 0.02.2-324, 11-8-2000
• Configure the network using network 142.10.x.x
• Use an 8 bit subnet mask unless otherwise specified
• If a password is needed, use cisco for the password
• X is router number, Y is rack number
• Do not use any type of static routes
• At the end of each exercise, verify connectivity between all devices
• Use the Catalyst 3920, SW3, for all of the rings, do not use the MAUs.
ATM
R6
Ring 2
VLAN F
Frame Relay
S2
S0
S3
R2
ISDN /30
R3
VLAN D
VLAN A
VLAN B
ISL
R5
R7
R4
R1
Ring 1
VLAN C
Backbone 3
2
Frame Relay Setup
TERMINAL SERVER
Setup R5 as the terminal server, so that all routers can be accessed via reverse telnet. Set R5 ethernet address to
142.10.50.5/24 and use this interface as the source for all reverse telnets. Make sure that the router sees this
interfaces as always up, even if the physical link is down. R5’s asynchronous serial lines are connected as follows:
R1 – line 2001
R2 – line 2002
R3 – line 2003
R4 – line 2004
SW1 – line 2005
R6 – line 2006
R7 – line 2007
SW3 – line 2017
S3/0
S3/2
S3/3
R8
dlci 100
dlci 100
dlci 110
R6
Frame
R2
R3
dlci 120
3
4
NETWORK DIAGRAM
Make a network diagram that includes all addresses, frame relay DLCI’s and other pertinent information.
IP ADDRESSING
Use the class B network address 142.10.0.0 throughout the network, except on the backbone interfaces. Use the
subnet masks shown on page 1 and listed in the text. If a subnet mask is not given for an interface, use /24. For
Backbone 3 use the address 182.100.1.1 /24.
LOOPBACKS
Configure a loopback on each router with the IP address of 142.10.X.X.
REMOTE ACCESS
All routers and SW1 must be accessible by VTY session including enable mode.
FRAME RELAY
R8 is configured as the frame-relay switch. Configure frame relay between R2, R3, and R6. Refer to diagram on
page 2 for the DLCI routing setup on the frame switch. Use only the given PVCs.
• The PVC’s between R2, R3 and R6 should be on a single subnet.
• For all PCVs, CIR is 64kb, MinCIR is 32kb, BC is 32kb, and BE is 256kb.
VLANS
Configure 4 VLANs on SW1.
• Set the switch’s VTP domain to WSU.
• Set VLANs A, B, C, D, E, and F, (i.e. 30, 40, 80, 50, 70, 60) on ports 2/2, 2/3-4, 2/12, 2/7, 1/1, and 2/6.
• Configure VLAN B such that SW1 will always be the root bridge.
• Configure the SC0 interface, 142.10.80.1 in VLAN E. The switch must be able to ping any device in the
network.
• Configure port 2/1 as a trunking port with R6 for all VLANs except VLAN F.
• Set the forwarding delay on VLAN 50 to 10 seconds.
CATALYST
Configure SW1.
• Disable BPDU on VLAN F.
• R3’s MAC address is to be available to the switch at all times, even after a reboot.
DHCP
Configure R6 as a DHCP server for clients on VLAN B. Assume there is a DNS and WINS server 142.10.80.2 for
all clients to use.
ATM
5
Configure R6’s ATM interface. Create sub-interface 0.6 with the IP address 190.6.Y.6 /24, where Y is the rack #.
Use PVC 30Y, where Y is the rack #. R6 should contact the switch for its addressing needs, but no more the every
5 minutes. Set QoS parameters for this PVC: UBR maximum is 10000 and minimum is 1000.
RIP
Configure R2 to receive IP RIP routes from Backbone 1. Only advertise the 140.10.0.0 network out to Backbone1.
There are 3 networks being advertised for Backbone1; 199.172.1.0, 199.172.3.0, and 199.172.12.0.
Combine these routes into 2 routes and redistribute into OSPF.
OSPF
Configure OSPF for the frame relay links between R2, R3, R4, and R6, for VLAN 70 and for Rings 2 and 3.
• The frame relay network should be in area 1.
• VLAN 70 should be in area 0.
• Rings 2 and 3 should be in area 7, which is to be configured as a stub area.
• Configure MD5 authentication in area 1.
• Place VLAN D in area 6.
• Change the cost of all ethernet interfaces in VLAN D to 90 without using the cost command.
• Place the loopbacks of each router in any of the above areas on the router. Do not create any new areas.
IGRP
Configure IGRP on R1 and the serial link between R1 and R5.
EIGRP
Configure EIGRP on R6. Use the rack number for the AS number.
REDISTRIBUTION
Redistribute so that all routes, except Backbone 1, are visible on all routers. Do not redistribute directly between
EIGRP and IS-IS. Advertise a default route form R6 to R5 and then from R5 to R1. Redistribute form EIGRP into
OSPF but not vise-versa. Full connectivity must be maintained including across the ATM cloud.
ISDN
Configure the ISDN link between R2 and R3 as a backup for the frame relay network. Do not use floating static
routes, or the ‘backup interface’ command. R3 should never call R2. R2 should call R3 with authentication but
not be challenged by R3. R3 must then call R2 back with the userid userY, where Y is the rack number.
• Should the frame network connected to R2 go down all routes should still be visible on both R2 and R3.
• The link should come up for any network topology changes.
• Broadcast traffic should not bring the link up.
• Use CHAP authentication.
6
BGP
Configure BGP on R1.
• R1should be in AS 100.
• Add a loopback 192.81.y.y/32 on R1. Advertise this network into BGP.
Configure BGP on R5.
• R5 should be in AS 500.
• Add a loopback 192.85.y.y/32 on R5. Advertise this network into BGP.
• On R5 put a filter, without using any address statement, to not redistribute R3’s loopback 1 (192.83.y.y) to R1.
Configure BGP on R7.
• R7 should be in AS 700.
• R7 should receive BGP updates from both R4 and R6. The BGP routing table on R7 should show R6 as the
only path for AS100 and AS 500. The BGP routing table on R7 should show R6 as the preferred path for
AS 1000. Traffic destined for all other autonomous systems should be balanced between both R4 and R6.
Configure BGP on R3.
• R3 should be in AS 600.
• There is a BGP router on Backbone 2. Its AS is 20 and its IP address is 160.100.2.20. R3 should establish an
EBGP session with this router.
• Filter on R3 such that routes that pass through AS 40 and routes originating in AS 80 are not accepted into
AS 600.
• Advertise to the BGP router in AS 20 networks 192.84-85.y.y/32 and the 140.10.0.0/16 network.
Configure IBGP within AS 600 on R2, R3, R4, and R6, but don’t make it fully meshed.
• BGP should be synchronized.
• R4 should be peered with R3 and R6 within AS 600.
• All BGP routers in AS 600 should see all the routes, except those being filter on R3, from AS 20.
• R2 should be peered only with R7 and the external router.
• Add a loopback 192.82.y.y/32 on R2. Advertise this network into BGP.
• Add a loopback 192.83.y.y/32 on R3. Advertise this network into BGP.
• Add a loopback 192.84.y.y/32 on R4. Advertise this network into BGP.
• Add a loopback 192.86.y.y/32 on R6. Advertise this network into BGP.
• R6 is to peer with a BGP router, 100.1.1.1, in AS 1000.
7
DLSW+
Configure DLSW+ between VLAN A and Backbone 1. Configure DLSW+ between Ring 1 and Ring 4.
• R4 should not have a remote peer statement.
• R2 should use R6 as the primary path to VLAN A with R4 as a backup.
• Bridge VLAN A and Backbone 1, but not with Ring 1 or Ring 4. DLSW traffic from the VLAN A and
Backbone 1 should never cross with DLSW from Ring 1 or Ring 4.
• R1 should always show R6 as a connected TCP peer even if the path network is down.
IPX
Configure IPX on each of the routers.
• Use RIP/SAP routing on all of R1’s interfaces, on the serial link with R5, over the ISDN link, on Ring 2 and
Ring 3, ATM cloud, and on Backbone 1.
• Use EIGRP on all other interfaces.
• R7 and R4 must be in different network numbers, but full connectivity must be maintained.
• All routes should be visible on all routers.
• The ISDN link should only come up periodically for routing updates.
• Limit IPX SAP traffic on VLAN A to updates only.
• There are SAPs being advertised on Backbone 1, only allow IPXSERV1 to be seen by the rest of the network.
• There is a router advertising routes on Backbone 2, allow these networks to be seen by the rest of the network.
APPLETALK
Configure AppleTalk on R1, R2, R3, R5, R6, and R7. Do not configure AT on the Backbones, loopbacks, or over
the ISDN link.
• Use EIGRP as the routing protocol over the FR cloud but do not run AT directly on the FR links.
• Configure Ring 2 and Ring 3 in the same zone.
• Filter on R6, such that R2 sees the cable-range for Ring 1 but does not see the zone.
ISL
Configure ISL trunking on R6.
• Route IP across all interfaces and VLANs. Do not place IP address on the subinterfaces.
• Bridge IPX between VLAN B and VLAN C. Route IPX access all other VLANs and interfaces.
• Bridge AppleTalk across all VLANs and route it to the rest of the network.
MULTICAST
Configure the network for IP multicast support. Assume there is a multicast server on VLAN C. Configure the
network so that multicast traffic on all other VLANs is limited to a maximum of 50% of the VLAN’s bandwidth.
• Create a mbone between R1 and R6. Use PIM in sparse mode.
• Configure R4, R6, and R7 for PIM in dense mode.
Setup all VLANs for AppleTalk multicast support. R6 is to be the controlling source.
• Link the VLANs with R1 To0 to support AT multicast clients on Ring 1. Do not configure AppleTalk on the
HDLC link between R1 and R5.
• R4 should not be configured to support AT multicasting.
8
VOICE
Configure VoIP between R4 and R6 over the FR cloud. R4 should be able to make a clear call to R6, provide any
QoS needed. Use 4401 as the number for the 1
st
FXS port and 4402 for the 2
nd
FXS port on R4. Use 6601 as the
number for the 1
st
FXS port and 6602 for the 2
nd
FXS port on R6. Configure the 2
nd
FXS port on R4 to
automatically call the 1
st
FXS port on R6 when you bring the receiver up. All phone extensions in the 5000-5999
range are accessed via VoIP host180.200.1.10.
VPN
Configure a VPN between R3 E0 and R6 ATM 2/0. Use basic Cisco encryption with key maps.
NAT
Some of the clients on Ring 3 have been configured with ip addresses in the 10.10.10.0/24 range with 10.10.10.1
as the default gateway. Provide connectivity for these hosts with the rest of the network. Only R7 is to know about
the 10.0.0.0 network.
. Electrical and Computer Engineering
CCIE Preparation Laboratory
WSU CCIE Lab #4
Advanced Multiprotocol Skills Lab
Version 0.02.2-324, 11-8-2000
.
Configure SW1.
• Disable BPDU on VLAN F.
• R3’s MAC address is to be available to the switch at all times, even after a reboot.
DHCP
Configure