Topology: Created by NRU Untuk Pelanggan Merapi Utama Pharma
Topology: Created by NRU Untuk Pelanggan Merapi Utama Pharma
Topology
Router Remote
Customer switch
Router Remote
Customer switch
Router Remote
Customer switch
Customer switch
interface GigabitEthernet9
description LINK_TO_WAN
ip address 202.152.xxx.xxx 255.255.255.252 => alokasi dari idola
ip nat outside
ip virtual-reassembly in
duplex auto
speed auto
end
!
interface GigabitEthernet8
description TO-FORTINET
ip address 1.1.2.1 255.255.255.252 => alokasi 1.1.34.1/30 (buat merapi jaya pura temporary )
ip nat inside
ip virtual-reassembly in
duplex auto
speed auto
end
!
2. Create Default route internet
exec-timeout 10
transport input all
!
service password-encryption
!
4. Create Timezone
interface Tunnel0
ip address 172.16.255.1 255.255.255.0
no ip redirects
ip mtu 1440
ip nhrp authentication cisco123
ip nhrp map multicast dynamic
no ip split-horizon eigrp 99
ip nhrp network-id 1
ip nhrp holdtime 600
tunnel source gi8
tunnel mode gre multipoint
tunnel key 0
tunnel protection ipsec profile MY-PROFILE
end
interface Tunnel0
ip address 172.16.255.x 255.255.255.0 => alokasi merapi jaya pura temporary 172.16.255.34
no ip redirects
Created By NRU untuk pelanggan Merapi Utama Pharma
ip mtu 1440
ip nhrp authentication cisco123
ip nhrp map multicast dynamic
ip nhrp map 172.16.255.1 182.23.95.98
ip nhrp map multicast 182.23.95.98
ip nhrp network-id 1
ip nhrp holdtime 600
ip nhrp nhs 172.16.255.1
tunnel source e 0/0
tunnel mode gre multipoint
tunnel key 0
tunnel protection ipsec profile MY-PROFILE
end
Router#ping 172.16.255.1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 172.16.255.1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 6/6/8 ms
Router#
Interface: Tunnel0
Session status: UP-ACTIVE
Peer: 10.0.0.1 port 500
Session ID: 0
IKEv1 SA: local 10.0.0.2/500 remote 10.0.0.1/500 Active
IPSEC FLOW: permit 47 host 10.0.0.2 host 10.0.0.1
Active SAs: 2, origin: crypto map
no auto-summary
!
10. Create NAT untuk LAN dan NAT STATIC untuk fortinet
12. Create BGP routing dan redistributing EIGRP dari Cisco 892FSP ke Fortinet di remote
edit wan1
set mode static
set ip 1.1.34.2 255.255.255.252
set allowaccess ping https ssh http telnet fgfm
next
edit lan
set ip 192.168.134.1 255.255.255.0
set allowaccess ping https ssh http fgfm capwap telnet
end
edit 1
set start-ip 192.168.134.10
set end-ip 192.168.134.250
next
end
set timezone-option default
set dns-service specify
set dns-server1 192.168.2.248
set dns-server2 202.152.5.36
set dns-server3 202.152.0.2
next
end
Pastikan routing di sisi Merapi Utama Pharma sudah di arahkan ke Internet DMVPN. Minta
tolong tim IT Pusat Merapi