Jumat, Agustus 31, 2012

Configuration VLAN and NAT

Asslamu`alaikum Wr.Wb.

Peace, now I'll try to post about the VLAN configuration of the router and NAT. Below is a picture of the topology that will be created.




The steps to configure a topology with NAT and OSPF:

STEP 1 : Provision
 
To facilitate please konfigurasian VLAN
use VTP (VLAN Trunking Protocol).
• Server is Switch1 and Switch2 as Client.
Configursai enabling NAT where you think it should be in NAT
Use the easiest Route table that you understand
Use BGP Route

SWITCH 1
Switch#enable
Switch#configure terminal
Enter configuration commands, one per line.  End with CNTL/Z.
Switch1 (config)#vtp mode server
Switch1 (config)#vtp domain ahri
Switch1 (config)#vtp password ahri
Switch1(config)#vlan 2
Switch1(config-vlan)#name hrd
Switch1(config-vlan)#vlan
Switch1(config-vlan)#vlan 3
Switch1(config-vlan)#name acc
Switch1(config-vlan)#vlan 4
Switch1(config-vlan)#name production
Switch1(config-vlan)#vlan 5
Switch1(config-vlan)#name direktur
Switch1(config-vlan)#vlan 6
Switch1(config-vlan)#name  IT server
Switch1(config-vlan)#exit 

Switch1#configure terminal
Enter configuration commands, one per line.  End with CNTL/Z.
Switch1(config)#interface fastEthernet 0/2
Switch1(config-if)#switchport mode access
Switch1(config-if)#switchport access vlan 2
Switch1(config-if)#interface fastEthernet 0/3
Switch1(config-if)#switchport mode access
Switch1(config-if)#switchport access vlan 3
Switch1(config-if)#interface fastEthernet 0/4
Switch1(config-if)#switchport mode access
Switch1(config-if)#switchport access vlan 4
Switch1(config-if)#interface fastEthernet 0/5
Switch1(config-if)#switchport mode access
Switch1(config-if)#switchport access vlan 5
Switch1(config-if)#interface fastEthernet 0/6
Switch1(config-if)#switchport mode access
Switch1(config-if)#switchport access vlan 6
Switch1(config-if)#^Z


STEP 2 : Create switch2 as a member VLAN 6
SWITCH2
Switch2>enable
Switch2#configure terminal
Enter configuration commands, one per line.  End with CNTL/Z.
Switch2(config)#interface fastEthernet 0/1
Switch2(config-if)#switchport mode trunk
Switch2(config-if)#switchport trunk native vlan 1
Switch2(config-if)#exit
Switch2(config)#vtp mode client
Setting device to VTP CLIENT mode.
Switch2(config)#vtp domain ahri
Switch2(config)#vtp password ahri
Setting device VLAN database password to ahri
Switch2(config)#interface fastEthernet 0/6
Switch2(config-if)#switchport mode access
Switch2(config-if)#switchport access vlan 6

STEP 3 : Encapsulation on router1
ROUTER 1
Route1r>enable
Router1#configure terminal
Enter configuration commands, one per line.  End with CNTL/Z.
Router1(config)#interface fastEthernet 0/0.2
Router1(config-subif)#encapsulation dot1Q 2
Router1(config-subif)#ip address 192.168.1.1 255.255.255.252
Router1(config-subif)#interface fastEthernet 0/0.3
Router1(config-subif)#encapsulation dot1Q 3
Router1(config-subif)#ip address 192.168.1.5 255.255.255.252
Router1(config-subif)#interface fastEthernet 0/0.4
Router1(config-subif)#encapsulation dot1Q 4
Router1(config-subif)#ip address 192.168.1.9 255.255.255.252
Router1(config-subif)#interface fastEthernet 0/0.5
Router1(config-subif)#encapsulation dot1Q 5
Router1(config-subif)#ip address 192.168.1.13 255.255.255.252
Router1(config-subif)#interface fastEthernet 0/0.6
Router1(config-subif)#encapsulation dot1Q 6
Router1(config-subif)#ip address 192.168.2.1 255.255.255.248
Router1(config-subif)#exit


STEP 4 : Configure OSPF on router1
ROUTER 1
Router1(config)#router ospf 1
Router1(config-router)#network 192.168.1.0 0.0.0.3 area 0
Router1(config-router)#network 192.168.4.0 0.0.0.3 area 0
Router1(config-router)#network 192.168.8.0 0.0.0.3 area 0
Router1(config-router)#network 192.168.12.0 0.0.0.3 area 0
Router1(config-router)#network 192.168.2.0 0.0.0.7 area 0
Router1(config-router)#exit

STEP 5 : Giving IP address on each router that has been used as a VLAN member.
ROUTER3
Router3>enable
Router3#configure terminal
Enter configuration commands, one per line.  End with CNTL/Z.
Router3(config)#interface fastEthernet 0/1
Router3(config-if)#ip address 172.16.0.1 255.255.255.0
Router3(config-if)#no shutdown

ROUTER4
Router4>enable
Router4#configure terminal
Router4(config)#interface fastEthernet 0/1
Router4(config-if)#ip address 172.16.1.1 255.255.255.0
Router4(config-if)#no shutdown

ROUTER5
Router5>enable
Router5#configure terminal
Router5(config)#interface fastEthernet 0/1
Router5(config-if)#ip address 172.16.2.1 255.255.255.0
Router5(config-if)#no shutdown
ROUTER6
Router6>enable
Router6#configure terminal
Router6(config)#interface fastEthernet 0/1
Router6(config-if)#ip address 172.16.3.1 255.255.255.0
Router6(config-if)#no shutdown

STEP 6 : Configure OSPF routing on each router that has been used as a VLAN member.
ROUTER3
Router3(config)#router ospf 1
Router3(config-router)#network 192.168.1.0 0.0.0.3 area 0
Router3(config-router)#network 172.16.0.0 0.0.0.255 area 0

ROUTER4
Router4(config)#router ospf 1
Router4(config-router)#network 192.168.1.4 0.0.0.3 area 0
Router4(config-router)#network 172.16.1.0 0.0.0.255 area 0

ROUTER5
Router5(config)#router ospf 1
Router5(config-router)#network 192.168.1.8 0.0.0.3 area 0
Router5(config-router)#network 172.16.2.0 0.0.0.255 area 0

ROUTER6
Router6(config)#router ospf 1
Router6(config-router)#network 192.168.1.12 0.0.0.3 area 0
Router6(config-router)#network 172.16.3.0 0.0.0.255 area 0

 
STEP 7 : Giving IP Address that will be the IP NAT outside.
ROUTER1
Router1(config)#interface fastEthernet 0/1
Router1(config-if)#ip address 222.124.194.2 255.255.255.252
Router1(config-if)#no shutdown

:: Provide default routing
Router1(config)#ip route 0.0.0.0 0.0.0.0 222.124.194.1
Router1(config)#exit

STEP 8 : Configuration NAT
ROUTER1
Router1(config)#interface fastEthernet 0/1
Router1(config-if)#ip nat outside
Router1(config-if)#exit

Router1(config)#interface fastEthernet 0/0.2
Router1(config-subif)#ip nat inside
Router1(config-subif)#interface fastEthernet 0/0.3
Router1(config-subif)#ip nat inside
Router1(config-subif)#interface fastEthernet 0/0.4
Router1(config-subif)#ip nat inside
Router1(config-subif)#interface fastEthernet 0/0.5
Router1(config-subif)#ip nat inside
Router1(config-subif)#exit
Router1(config)#ip nat inside source list 1 interface fastEthernet 0/1 overload
Router1(config)#access-list 1 permit any
Router1(config)#router ospf 1
Router1(config-router)#default-information originate

STEP 9 : Configuration NAT Static
:: Static NAT is designed to map the mapping (pemetaan) one-to-one between local and global addresses.
 
ROUTER1
Router1(config)#ip nat inside source static 192.168.2.2 222.124.194.2
Router1(config)#ip nat inside source static tcp 192.168.2.3 88 222.124.194.2 88

Nah......tuch diatas adalah konfigurasinya.
semoga bermanfaat.