CNCO2000 - Data Communications and VLAN Computer Networks - Curtin University

Download Solution Order New Solution

Assignment Task

Objectives

1. Configure a complex network to enable communication between multiple departments.

2. Understand the importance of VLANs while configuring VLANs where necessary.

3. Configure GRE (General Routing Encapsulation)/VPN between networks that are geographically apart from each other.

4. Network access control via ACLs (Access Control List).

5. Network device maintenance and access authorization. 6. Validate and troubleshoot the network connectivity

Background

You, as a network engineer, are now required to configure a complex network to enable communication between multiple departments (b314 - Computing Department. IT Services, Human Resources, Curtin Library, Cisco Lab). Also, you are required to configure a network in Curtin Energy Research division located in Technology Park.

In Computing Department (Curtin University), unfortunately, a part of IT Services and Human Resources department is located, and they need to be on the respective VLANs as the IT Services Department and Human Resources Department. The Gateway Router of Curtin University and Curtin Energy Research Division is required to be configured with a public IP address. As a security measure, a set of ACLs (Access Control List) needs to be configured on Gateway Routers to restrict access to some parts of the network where necessary. Furthermore, Curtin Energy Research division which is geographically located away from the Curtin University has two branches for its HR and IT Services. Both branches must be connected to the Curtin HR and Curtin IT Services Departments respectively with a VPN (virtual private network)/GRE (General Routing Encapsulation) tunnel. These tunnels must be configured to carry on the relevant traffic for HR and IT Services. In addition to the tunnels designed for HR and IT services traffic, another tunnel must be configured to allow traffic to Curtin Library, and only to Curtin Library back and forth. The devices with the required connections are already in place. However, the network is yet to be configured, and all devices are offline.

You are only required to configure each device where necessary and set the network up and running according to the requirements stated below. Since this task is to deal with the configuration of devices, adding/removing/moving devices or arranging devices in the physical view of the network is not required. (please work only with the logical view of the network).

Configure VLANs

1. Configure the following VLANs in the devices where necessary:

2. Configure trunk ports on the links only if trunking is absolutely needed.

(if a link does not need to carry multiple VLAN data, it must be configured as an access link, but not as a trunk link). If you decide to configure a port as a trunk port, make sure to configure the trunk port with the absolute necessary traffic (for e.g. if a link is supposed to carry only the data belong to two VLANs (e.g. VLAN A, VLAN B) out of 5 VLANs, then only allow VLAN A, VLAN B traffic to be carried on the link but not others). Note that VLAN1 (default VLAN) traffic must be allowed on the trunk port in addition to the traffic of those VLANs which you will configure.

3. At this point, check the connectivity of the devices within a VLAN. The devices within the VLAN must be able to communicate within the same VLAN but not across VLANs. We are yet to configure inter VLAN communication.

4. Configure CUR_UNI.GW router for inter VLAN communication by defining a set of sub interfaces on Gig0/1 as shown below:

5. Configure the Default Gateway IP address on following PCs which are supposed be on a VLAN.

6. Test the connectivity of the devices across VLANs (inter VLAN). It must be successful.

Configuring IPv4 Tunnels

1. Following GRE/VPN Tunnels over IPv4 are required to be configured.

2. Complete the rest of the mandatory configuration to setup the tunnels up and running.

3. Add appropriate static routes to CUR_UNI.GW and CUR_ENGY.GW Routers (wherever necessary)

4. At this point,

a. HR Department of Curtin University should be able to communicate with the HR branch of Curtin Energy Research Division via tunnel 1.

b. IT Department of Curtin University should be able to communicate with the IT branch of Curtin Energy Research Division via tunnel 2.

c. Curtin Library must be accessible to all the PCs in Curtin Energy Research Division via tunnel 03. Furthermore,

d. IT Department of Curtin University should be able to communicate with all PCs in Curtin University and Curtin Energy Research Division.

e. Curtin Library must be accessible to all the PCs (Curtin University and Curtin Energy Research Division).

Configure Access Control Lists to restrict access

1. Network access needs to be restricted according to the following conditions:

a. HR Department of Curtin University must only be accessed by the IT Services and Library of Curtin University and HR branch of Curtin Energy Research Division.

b. HR branch of Curtin Energy Division must only be accessed by the IT Services, Library of Curtin University, and IT branch of Curtin Energy Research Division, HR department of Curtin University.

2. In order to satisfy the conditions above, define a standard access list (ACL) with the name “allow_CITS” on CUR_UNI.GW and CUR_ENGY.GW Routers

Network Device Security & Management

1. The following security measures must be in place to prevent unauthorized access to the Routers:

2. At this point, on CUR_UNI.GW and CUR_ENGY.GW Routers, if you inspect the “running-config” of the device, the password is stored on plain text. Avoid storing passwords on the devices in plain text by using password encryption service on those devices

3. Once the password encryption service is in place, inspect the “running-config” of CUR_UNI.GW and CUR_UNI.GW Routers. The password should not be displayed in plain text!

4. Since Curtin IT Services department has access to all the network devices (Routers, Switches, PCs) in Curtin University and Curtin Energy Research Division, the Switches must be configured with a Switch Virtual Interface (SVI) with an IP address, so that IT Services could ping them.

5. PCs in IT Department must be able to ping all the Switches and Routers (in Curtin University and Curtin Energy Research Division). To satisfy this requirement, set the default-gateways on the devices (Switches, Routers) where necessary. (Hint: figure out the correct default gateway IP address depending on the network in which the device resides in)

6. Once you complete step 4 and 5 above, you will notice that ONE (or more) of the switches cannot be ping-ed by the PCs outside the vlan it belongs to. Figure out the switch and fix the configuration error.

7. Now, try to ping each of the communication devices (Router, Switch). You should be successful.

8. Finally, save the running configurations of all communication devices (Routers, Switches) to its NVRAM (Hint: startup configuration).

9. Power Cycle all the devices and see whether the saved configuration of Routers and Switches is automatically loaded to the running configuration

Summary

1: Initial configuration of the devices

2: Configure VLANs 

3: Configuring IPv4 Tunnels

4: Configure Access Control Lists to restrict access

5: Network Device Security & Management 

6: Validate Network Connectivity

This CNCO2000IT and Computer Science has been solved by our PHD Experts at My Uni Paper.

Get It Done! Today

Country
Applicable Time Zone is AEST [Sydney, NSW] (GMT+11)
+

Every Assignment. Every Solution. Instantly. Deadline Ahead? Grab Your Sample Now.