Exercise No2
Exercise No2
2
Switch Security Configuration
-Create a Secure Trunk
-Secure Unused Switch ports
-Implement Port Security
-Enable DHCP Snooping
-Configure Rapid PVST Port Fast and BPDU Guard
TOPOLOGY
ADDRESSING TABLE
VLAN Table
S1(config-vlan)#interface vlan 15
S1(config-if)#ip address 192.168.15.254 255.255.255.0
S1(config-vlan)#interface g0/1
S1(config-if)#switchport mode trunk
S1(config-if)#switchport trunk native vlan 25
S1(config-if)#switchport trunk allowed vlan 5,10,15,25
S1(config-if)#switchport nonegotiate
S1(config-if-range)#spanning-tree portfast
S1(config-if-range)#spanning-tree bpduguard enable
S1(config-if-range)#exit
S1(config)#ip dhcp snooping
S1(config)#ip dhcp snooping vlan 5,10,15,25
S1(config)#exit
S1#copy run start
S2 Configuration
Switch>enable
Switch#configure terminal
Switch(config)#hostname S2
S2(config)#vlan 5
S2(config-vlan)#name HR
S2(config-vlan)#vlan 10
S2(config-vlan)#name Accounts
S2(config-vlan)#vlan 15
S2(config-vlan)#name Management
S2(config-vlan)#vlan 25
S2(config-vlan)#name Native
S2(config-vlan)#vlan 35
S2(config-vlan)#name Unused
S2(config-vlan)#interface vlan 15
S2(config-if)#ip address 192.168.15.253 255.255.255.0
S2(config-vlan)#interface g0/1
S2(config-if)#switchport mode trunk
S2(config-if)#switchport trunk native vlan 25
S2(config-if)#switchport trunk allowed vlan 5,10,15,25
S2(config-if)#switchport nonegotiate
S2(config-if-range)#exit
S2(config)#ip dhcp snooping
S2(config)#ip dhcp snooping vlan 5,10,15,25
S2(config)#exit
S2#copy run start
PC1 IP Configuration
IPv4 Address: 192.168.5.10
Subnet: 255.255.255.0
PC2 IP Configuration
IPv4 Address: 192.168.5.11
Subnet: 255.255.255.0
PC3 IP Configuration
IPv4 Address: 192.168.10.10
Subnet: 255.255.255.0
PC4 IP Configuration
IPv4 Address: 192.168.10.11
Subnet: 255.255.255.0
Successful
Ping From Ping To To IP Address
Yes/No
PC1 PC2 192.168.5.11 Yes
PC3 PC4 192.168.10.11 Yes
S1 S2 192.168.15.253 Yes