Professional Documents
Culture Documents
CCNP
Developed by
ESP Team
ESP Press
-1-
LAB.
LABS DESCRIPTION
PAGE NO.
11
13
16
20
22
Configuring HSRP
25
10
27
11
29
12
31
13
Wireless
33
14
52
-2-
Lab # 1
Diagram
3560
2950
Console Port 0
Console
Port 0
Configuration
Step 1: After connecting your PC to the Console Port.
Switch con0 is now available
Press RETURN to get started.
Switch>
(User Mode)
-3-
Step 2: To Enter Into Privilege executive mode From User Mode & ViceVersa.
Switch>enable
Switch#
Switch#disable
Switch>
-4-
-5-
OR
3560#show flash:
-6-
-7-
Lab # 2
i. VLAN
Diagram
Switch
Con 0
Verifying Commands
Switch#show vlan
Switch#show mac address-table dynamic
-8-
Verifying Commands
Switch#show vtp status
Switch#show vlan
-9-
Lab # 3
Diagram
Non Root Switch
Priority: 32768
MAC: 0012.43a0.b840
2950-SWA
Con 0
Fa 0/23
Blocked Port
Fa 0/24
Root Port
Root Switch
Priority: 0
MAC: 0012.43a0.b940
Fa 0/23
Designated Port
Fa 0/24
Designated Port
2950-SWB
Con 0
Switch (2950-SWB)
Switch(config)#spanning-tree vlan 1 priority 0
Switch (2950-SWA)
Switch(config)#int fastethernet 0/24
Switch(config-if)#spanning-tree vlan 1 cost 18
Verifying Commands
Switch#show spanning-tree
Switch#show spanning-tree vlan 1
Etronics Solution Provider
- 10 -
Diagram
MAC: 0012.43a0.b840
2950-SWA
MAC: 0012.43a0.b940
Fa 0/23
Fa 0/24
Fa 0/23
2950-SWB
Fa 0/24
Con 0
Con 0
Switch (2950-SWA)
Switch(config)#vtp domain CISCO
Switch(config)#vlan 5
Switch(config-vlan)#name vlan-5
Switch (2950-SWB)
Switch(config)#spanning-tree vlan 5 priority 0
Verifying Commands
Switch# show spanning-tree vlan 1
Switch# show spanning-tree vlan 5
- 11 -
Lab # 4
i. Port Fast
Port Fast is used to bypass the STP Timers for connected PCs and Servers.
Diagram
3560
2950
Fa0/1
10.0.0.1
Fa0/1
10.0.0.2
Verifying Commands
Switch#show running-config interface fastEthernet 0/1
- 12 -
Diagram
Non Root Switch
Root Switch
Designated Port
Fa0/23
Root Port
Fa0/7
3560
2950
Con 0
Fa0/24
Designated Port
Fa0/8
Con 0
Blocked Port
Switch (3560)
3560(config)#spanning-tree uplinkfast
Verifying Commands
3560#show spanning-tree uplinkfast
3560#show spanning-tree vlan 1
- 13 -
Lab # 5
i. RSTP
Diagram
Fa0/23
Fa0/7
3560
2950
Con 0
Fa0/24
Fa0/8
Con 0
Switch (2950)
2950(config)#spanning-tree mode rapid-pvst
Switch (3560)
3560(config)#spanning-tree mode rapid-pvst
Verifying Commands
Switch# show spanning-tree vlan 1
- 14 -
ii. MST
Diagram
Fa0/23
Fa0/7
3560
2950
Con 0
Fa0/24
Fa0/8
Con 0
Switch (2950)
2950(config)#vlan 10
2950(config-vlan)#name vlan-10
2950(config)#vlan 20
2950(config-vlan)#name vlan-20
2950(config)#vlan 30
2950(config-vlan)#name vlan-30
2950(config)#vlan 40
2950(config-vlan)#name vlan-40
2950(config)#spanning-tree mode mst
2950(config)#spanning-tree mst configuration
2950(config-mst)#name MST-REGION
2950(config-mst)#revision 5
2950(config-mst)#instance 1 vlan 10,20
2950(config-mst)#instance 2 vlan 30,40
2950(config-mst)#show pending
Switch (3560)
3560(config)#vlan 10
3560(config-vlan)#name vlan-10
3560(config)#vlan 20
3560(config-vlan)#name vlan-20
3560(config)#vlan 30
Etronics Solution Provider
- 15 -
3560(config-vlan)#name vlan-30
3560(config)#vlan 40
3560(config-vlan)#name vlan-40
3560(config)#spanning-tree mode mst
3560(config)#spanning-tree mst configuration
3560(config-mst)#name MST-REGION
3560(config-mst)#revision 5
3560(config-mst)#instance 1 vlan 10,20
3560(config-mst)#instance 2 vlan 30,40
3560(config-mst)#show pending
3560(config)#spanning-tree mst 2 priority 0
Verifying Commands
Switch#show spanning-tree mst
- 16 -
Lab # 6
1.
Inter-VLAN Routing
(Router on a Stick)
Objective
To transport packets between VLANs by a Router.
Diagram
2811
Fa 0/0
Fa 0 / 0.10
10.0.0.10 / 8
Fa 0 / 0.20
20.0.0.10 / 8
Fa 0/24
2950
Fa 0/1
Fa 0/11
Vlan 10
Vlan 20
Host A
10.0.0.1/8
10.0.0.10
Host B
20.0.0.1/8
20.0.0.10
Switch
Switch(config)#vlan 10
Switch(config-vlan)#name vlan-10
Switch(config)#vlan 20
Switch(config-vlan)#name vlan-10
- 17 -
Router
Router(config)#interface fastEthernet 0/0
Router(config-if)#no ip address
Router(config-if)#no shutdown
Router(config)#interface fastEthernet 0/0.10
Router(config-subif)#encapsulation dot1Q 10
Router(config-subif)#ip address 10.0.0.10 255.0.0.0
Router(config-subif)#exit
Router(config)#interface fastEthernet 0/0.20
Router(config-subif)#encapsulation dot1Q 20
Router(config-subif)#ip address 20.0.0.10 255.0.0.0
Router(config-subif)#exit
Verifying Commands
Switch#show vlan
Switch#show interface trunk
Router#show ip int brief
- 18 -
2. Inter-VLAN Routing
(By Multi-layer switch)
Objective
To transport packets between VLANs.
Diagram
3560
Fa 0/1
10.0.0.10
Vlan 10
Host A
10.0.0.1/8
10.0.0.10
Fa 0/2
20.0.0.10
Vlan 20
Host B
20.0.0.1/8
20.0.0.10
Switch
3560(config)#vlan 10
3560(config-vlan)#name vlan-10
3560(config)#vlan 20
3560(config-vlan)#name vlan-20
3560(config)#interface fastEthernet 0/1
3560(config-if)#switchport mode access
3560(config-if)#switchport access vlan 10
- 19 -
Verifying Command
Switch#show vlan
- 20 -
Lab # 7
i. BPDU-Guard (Port)
Diagram
Non Root Switch
Root Switch
Designated Port
Fa0/23
Root Port
Fa0/7
3560
2950
Con 0
Fa0/24
Designated Port
Fa0/8
BPDU-Guard
Enabled port
Con 0
Switch (3560)
3560(config)#interface fastEthernet 0/8
3560(config-if)#spanning-tree bpduguard enable
- 21 -
Verifying Commands
3560#show spanning-tree interface fastEthernet 0/8 detail
3560#show interfaces fastEthernet 0/8 status err-disabled
ii. Root-Guard
Diagram
3560
Root Switch
Fa0/8
Root-Guard
Enabled port
Fa0/24
Non Root
Switch
2950
Switch (3560)
3560(config)#spanning-tree vlan 1 priority 0
3560(config)#interface fastEthernet 0/8
3560(config-if)#spanning-tree guard root
Switch (2950)
2950(config)#spanning-tree vlan 1 priority 0
Verifying Commands
3560#show running-config interface fastEthernet 0/8
Switch#show spanning-tree vlan 1
- 22 -
Lab # 8
Ether Channel
Objective
Ether Channel allows to specify the multiple Ethernet ports of the same type as a single
virtual link.
Lab Objective :
1. Enable Ether-Channel with no protocol on Cisco catalyst switches.
2. Enable Ether-Channel (PAgP) on Cisco catalyst switches.
3. Enable Ether-Channel (LACP) on Cisco catalyst switches.
i. Ether-Channel
Diagram
Ether Channel
2950
Fa0/23
Fa0/24
Root
Switch
3560
Fa0/7
Fa0/8
Non Root
Switch
Switch (2950)
2950(config)#interface range fastEthernet 0/23 - 24
2950(config-if-range)#channel-group 1 mode on
Switch (3560)
3560(config)#interface range fastEthernet 0/7 - 8
3560(config-if-range)#channel-group 1 mode on
- 23 -
Verifying Commands
Switch#show etherchannel
Switch#show etherchannel protocol
Switch#show etherchannel port
Switch#show etherchannel port-channel
Switch#show etherchannel summary
2950
Fa0/23
Fa0/24
Root
Switch
3560
Fa0/7
Fa0/8
Non Root
Switch
Switch (2950)
2950(config)#interface range fastEthernet 0/23 - 24
2950(config-if-range)#channel-group 1 mode desirable
Switch (3560)
3560(config)#interface range fastEthernet 0/7 - 8
3560(config-if-range)#channel-group 1 mode auto
Verifying Commands
Switch#show etherchannel
Switch#show etherchannel protocol
- 24 -
2950
Fa0/23
Fa0/24
Root
Switch
3560
Fa0/7
Fa0/8
Non Root
Switch
Switch (2950)
2950(config)#interface range fastEthernet 0/23 - 24
2950(config-if-range)#channel-group 1 mode active
Switch (3560)
3560(config)#interface range fastEthernet 0/7 - 8
3560(config-if-range)#channel-group 1 mode passive
Verifying Commands
Switch#show etherchannel
Switch#show etherchannel protocol
Switch#show etherchannel port
Switch#show etherchannel port-channel
Switch#show etherchannel summary
- 25 -
Lab#9
Diagram
Virtual
Router
10.0.0.20
E0 10.0.0.5
S0 13.0.0.1
RA
S0 13.0.0.2
L0 15.0.0.1
HSRP
GROUP
64
L0 15.0.0.1
S0 14.0.0.1
E0 10.0.0.10
RB
ISP-1
S0 14.0.0.2
ISP-2
Host A
10.0.0.1
- 26 -
Router A
RouterA(config)# interface ethernet0
RouterA(config-if)# ip address 10.0.0.5 255.0.0.0
RouterA(config-if)# standby 64 ip 10.0.0.20
RouterA(config-if)# standby 64 priority 150
RouterA(config-if)# standby 64 preempt
RouterA(config-if)# standby 64 track serial 0 100
Router B
RouterB(config)# interface ethernet0
RouterB(config-if)# ip address 10.0.0.10 255.0.0.0
RouterB(config-if)# standby 64 ip 10.0.0.20
RouterB(config-if)# standby 64 preempt
RouterB(config-if)# standby 64 track serial 0 50
Verifying Commands
Router# debug standby
Router# show standby
- 27 -
Lab # 10
VLAN ACL
Objective
The VLAN ACLs are filters that can directly affect how packets are handled within a
VLAN.
Diagram
3560
Fa/1
VLAN 2
Fa/2
VLAN 2
Host A
Ip Add: 10.0.0.1
Host B
Ip Add: 10.0.0.2
Switch (3560)
3560(config)#vlan 2
3560(config-vlan)#name vlan-2
3560(config)#interface range fastEthernet 0/1 - 2
3560(config-if-range)#switchport mode access
3560(config-if-range)#switchport access vlan 2
- 28 -
Verifying Commands
3560#show access-lists
3560#show vlan access-map VLAN-ACL
3560#show vlan filter vlan 2
3560#show vlan filter access-map VLAN-ACL
- 29 -
Lab # 11
Private Vlan
Objective
Understanding the Private VLAN operation.
Diagram
Fa0/1
10.0.0.20
Fa0/0
20.0.0.10
Fa0/10
Promiscuous
Fa0/1
Fa0/2
Fa0/3
2811
Web Server
20.0.0.1
Isolated
Community
Vlan 20
Vlan 10
10.0.0.3
10.0.0.20
10.0.0.1
10.0.0.20
10.0.0.2
10.0.0.20
Switch (3560)
Switch(config)#vtp mode transparent
Switch(config)#vlan 10
Switch(config-vlan)#private-vlan community
Switch(config)#vlan 20
Switch(config-vlan)#private-vlan isolated
- 30 -
Switch(config)#vlan 100
Switch(config-vlan)#private-vlan primary
Switch(config-vlan)#private-vlan association 10,20
Switch(config)#int range fastEthernet 0/1 - 2
Switch(config-if-range)#switchport mode private-vlan host
Switch(config-if-range)#switchport private-vlan host-association 100 10
Switch(config)#int fa0/3
Switch(config-if)#switchport mode private-vlan host
Switch(config-if)#switchport private-vlan host-association 100 20
Switch(config)#int fa0/10
Switch(config-if)#switchport mode private-vlan promiscuous
Switch(config-if)#switchport private-vlan mapping 100 10,20
Verifying Commands
Switch#show vlan private-vlan
Switch# show vlan private-vlan type
- 31 -
Lab # 12
Port Security
Objective
To demonstrates the concept of port security mechanism on Switch.
Diagram
2950-SW
Fastethernet 0 / 9
Switch (2950)
Switch(config)#int fa0/9
Switch(config-if)#switchport mode access
Switch(config-if)#switchport port-security
Switch(config-if)#switchport port-security maximum 1
Switch(config-if)#switchport port-security mac-address sticky
Switch(config-if)#switchport port-security violation shutdown
- 32 -
Verifying Commands
Switch#show mac-address-table
Switch#show port-security
Switch#show port-security interface fa0/9
Switch#show interface status err-disabled
- 33 -
Lab # 13 (A)
Diagram
Cisco Aironet AP 1130
IP: 192.168.1.150 /24
PoE
Wireless Client 1
IP: 192.168.1.160 /24
SSID:
esp
- 34 -
Configuration
Step 1: Accessing the AP.
Enter;
o Username: ap
o Password: Cisco
- 35 -
- 36 -
Step 3: Go to the SETTINGS tab and select Enable in the Enable Radio
option & press Apply.
Step 4: Go to EXPRESS SECURITY and type an SSID ( esp ) and select the
check box Broad SSID in Beacons & press Apply.
- 37 -
- 38 -
Step 7: Verify the SSID (esp) appears as follow. Select it and press Activate.
- 39 -
Step 9a: Verify that a blue circle appears on antenna symbol under Network
Name (SSID).
- 40 -
- 41 -
Step 12: Go to Site Survey tab and see the SSID (esp) as shown below. Select it
and press Connect.
- 42 -
- 43 -
Lab # 13 (B)
Diagram
SSID: esp-adhoc
Wireless Client 2
IP: 10.0.0.44/ 8
Wireless Client 1
IP: 10.0.0.33/ 8
- 44 -
Configuration
Step 1: On wireless client 1, open wireless desktop utility. Go to Profile tab and
click New.
- 45 -
Step 3: Here you can see available networks. Click Manual Setup.
Step 4: Enter the ip address and subnet mask as shown below. Click Next.
- 46 -
Step 5: Select Wireless Mode as Ad-Hoc Mode. Enter SSID (esp-adhoc) and
click Next.
Step 6: Select Channel and Network Mode as shown below and click Next.
- 47 -
- 48 -
Step 10: Verify that wireless client 1 has successfully joined Ad-Hoc network.
- 49 -
- 50 -
Step 13: Verify the SSID (esp-adhoc) appears as follow. Select it and press
Activate.
- 51 -
- 52 -
Lab # 14
Client 1
Cisco 7940
IP Phone
Client 2
Cisco 7971
IP Phone