<0-15> First Line number
SW1(config)#
line vty 0 15
%LINK-5-CHANGED: Interface Vlan1, changed state to up
SW1(config-if)#
exit
%SYS-5-CONFIG_I: Configured from console by console
SW1#
copy run start
Destination filename [startup-config]?
ENTER
Building configuration...
[OK]
<0-15> First Line number
SW2(config)#
line vty 0 15
%LINK-5-CHANGED: Interface Vlan1, changed state to up
SW2(config-if)#
exit
%SYS-5-CONFIG_I: Configured from console by console
SW2#
copy run start
Destination filename [startup-config]?
ENTER
Building configuration...
[OK]
Destination filename [startup-config]?
ENTER
Building configuration...
[OK]
output
| Device | Book Port | PKT Port | |
|---|---|---|---|
| SW1 | f0/1 | f0/1 | 1st conn to Core |
| SW1 | f0/2 | f0/2 | 2nd conn to Core |
| SW1 | f0/3 | f0/3 | to HostA |
| SW1 | f0/4 | f0/4 | to PhoneA |
| SW1 | f0/8 | f0/8 | to IVR |
| ------------------------------------------- | |||
| SW2 | fa0/1 | f0/1 | 1st conn to Core |
| SW2 | fa0/2 | f0/2 | 2nd conn to Core |
| SW2 | fa0/3 | f0/3 | to HostB |
| SW2 | fa0/4 | f0/4 | to PhoneB |
| Device | Book Port | PKT Port | |
|---|---|---|---|
| Core | f0/5 | g1/0/1 | 1st conn to SW2 |
| Core | fa0/5 | g1/0/2 | 2nd conn to SW2 |
| Core | fa0/7 | g1/0/3 | 1st conn to SW1 |
| Core | fa0/8 | g1/0/4 | 2nd conn to SW1 |
Interface IP-Address OK? Method Status Protocol
GigabitEthernet1/0/1 unassigned YES unset down down
GigabitEthernet1/0/2 unassigned YES unset down down
GigabitEthernet1/0/3 unassigned YES unset down down
GigabitEthernet1/0/4 unassigned YES unset down down
Port Name Status Vlan Duplex Speed Type
Gig1/0/1 1st conn to SW2 notconnect 1 auto auto 10/100BaseTX
Gig1/0/2 2nd conn to SW2 notconnect 1 auto auto 10/100BaseTX
Gig1/0/3 1st connection to notconnect 1 auto auto 10/100BaseTX
Gig1/0/4 2nd connection to notconnect 1 auto auto 10/100BaseTX/span>
Port Name Status Vlan Duplex Speed Type
Fa0/1 1st connection to connected 1 auto auto 10/100BaseTX
Fa0/2 2nd connection to connected 1 auto auto 10/100BaseTX
Fa0/3 connection to Host connected 1 auto auto 10/100BaseTX
Fa0/4 connection to Phon connected 1 auto auto 10/100BaseTX
Fa0/5 notconnect 1 auto auto 10/100BaseTX
Fa0/6 notconnect 1 auto auto 10/100BaseTX
Fa0/7 notconnect 1 auto auto 10/100BaseTX
Fa0/8 connection to IVR notconnect 1 auto auto 10/100BaseTX
Gig1/0/1 1st conn to SW2 connected 1 auto auto 10/100BaseTX
Gig1/0/2 2nd conn to SW2 connected 1 auto auto 10/100BaseTX
Gig1/0/3 1st connection to connected 1 auto auto 10/100BaseTX
Gig1/0/4 2nd connection to connected 1 auto auto 10/100BaseTX
Fa0/1 1st connection to connected 1 auto auto 10/100BaseTX
Fa0/2 2nd connection to connected 1 auto auto 10/100BaseTX
Fa0/3 connection to Host connected 1 auto auto 10/100BaseTX
Fa0/4 connection to Phon connected 1 auto auto 10/100BaseTX
output
Sending 5, 100-byte ICMP Echos to 192.168.10.17, timeout is 2 seconds:
..!!!
Success rate is 60 percent (3/5), round-trip min/avg/max = 0/0/1 ms
Sending 5, 100-byte ICMP Echos to 192.168.10.17, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 0/0/2 ms
Sending 5, 100-byte ICMP Echos to 192.168.10.17, timeout is 2 seconds:
..!!!
Success rate is 60 percent (3/5), round-trip min/avg/max = 0/0/0 ms
Sending 5, 100-byte ICMP Echos to 192.168.10.18, timeout is 2 seconds:
.!!!!
Success rate is 80 percent (4/5), round-trip min/avg/max = 0/0/0 ms
Sending 5, 100-byte ICMP Echos to 192.168.10.17, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 0/0/2 ms
Sending 5, 100-byte ICMP Echos to 192.168.10.18, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 0/0/1 ms
<1-132> Maximum addresses
<1-132> protect Security violation protect mode
restrict Security violation restrict mode
shutdown Security violation shutdown mode
<1-132>
Secure Port MaxSecureAddr CurrentAddr SecurityViolation Security Action
(Count) (Count) (Count)
--------------------------------------------------------------------
Fa0/3 1 0 0 Shutdown
Fa0/4 1 0 0 Shutdown
----------------------------------------------------------------------
<1-132>
% Invalid input detected at '^' marker.
SW1#show port-security interface f0/3
Port Security : Enabled
Port Status : Secure-up
Violation Mode : Shutdown
Aging Time : 0 mins
Aging Type : Absolute
SecureStatic Address Aging : Disabled
Maximum MAC Addresses : 1
Total MAC Addresses : 0
Configured MAC Addresses : 0
Sticky MAC Addresses : 0
Last Source Address:Vlan : 0000.0000.0000:0
Security Violation Count : 0
disable Disable portfast for this interface
trunk Enable portfast on the interface even in trunk mode
SW1#(config-if-range)
spanning-tree portfast
%Warning: portfast should only be enabled on ports connected to a single
host. Connecting hubs, concentrators, switches, bridges, etc... to this
interface when portfast is enabled, can cause temporary bridging loops.
Use with CAUTION
%Portfast has been configured on FastEthernet0/3 but will only
have effect when the interface is in a non-trunking mode.
%Warning: portfast should only be enabled on ports connected to a single
host. Connecting hubs, concentrators, switches, bridges, etc... to this
interface when portfast is enabled, can cause temporary bridging loops.
Use with CAUTION
%Portfast has been configured on FastEthernet0/4 but will only
have effect when the interface is in a non-trunking mode.
bpduguard Don't accept BPDUs on this interface
cost Change an interface's spanning tree port path cost
guard Change an interface's spanning tree guard mode
link-type Specify a link type for spanning tree protocol use
portfast Enable an interface to move directly to forwarding on link up
vlan VLAN Switch Spanning Tree
disable Disable portfast for this interface
trunk Enable portfast on the interface even in trunk mode
SW2#(config-if-range)
spanning-tree portfast
%Warning: portfast should only be enabled on ports connected to a single
host. Connecting hubs, concentrators, switches, bridges, etc... to this
interface when portfast is enabled, can cause temporary bridging loops.
Use with CAUTION
%Portfast has been configured on FastEthernet0/3 but will only
have effect when the interface is in a non-trunking mode.
%Warning: portfast should only be enabled on ports connected to a single
host. Connecting hubs, concentrators, switches, bridges, etc... to this
interface when portfast is enabled, can cause temporary bridging loops.
Use with CAUTION
%Portfast has been configured on FastEthernet0/4 but will only
have effect when the interface is in a non-trunking mode.
bpduguard Don't accept BPDUs on this interface
cost Change an interface's spanning tree port path cost
guard Change an interface's spanning tree guard mode
link-type Specify a link type for spanning tree protocol use
portfast Enable an interface to move directly to forwarding on link up
vlan VLAN Switch Spanning Tree
Reference
VLAN0001
Spanning tree enabled protocol ieee
Root ID Priority 32769
Address 0001.645B.5321
Cost 38
Port 1(FastEthernet0/1)
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
Bridge ID Priority 32769 (priority 32768 sys-id-ext 1)
Address 00E0.F7BC.472E
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
Aging Time 20
Interface Role Sts Cost Prio.Nbr Type
---------------- ---- --- --------- -------- --------------------------------
Fa0/1 Root FWD 19 128.1 P2p
Fa0/2 Altn BLK 19 128.2 P2p
Fa0/3 Desg FWD 19 128.3 P2p
Fa0/4 Desg FWD 19 128.4 P2p
VLAN0001
Spanning tree enabled protocol ieee
Root ID Priority 32769
Address 0001.645B.5321
This bridge is the root
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
Bridge ID Priority 32769 (priority 32768 sys-id-ext 1)
Address 0001.645B.5321
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
Aging Time 20
Interface Role Sts Cost Prio.Nbr Type
---------------- ---- --- --------- -------- --------------------------------
Fa0/1 Desg FWD 19 128.1 P2p
Fa0/3 Desg FWD 19 128.3 P2p
Fa0/2 Desg FWD 19 128.2 P2p
Fa0/4 Desg FWD 19 128.4 P2p
VLAN0001
Spanning tree enabled protocol ieee
Root ID Priority 32769
Address 0001.645B.5321
Cost 19
Port 1(GigabitEthernet1/0/1)
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
Bridge ID Priority 32769 (priority 32768 sys-id-ext 1)
Address 0001.96B3.31BC
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
Aging Time 20
Interface Role Sts Cost Prio.Nbr Type
---------------- ---- --- --------- -------- --------------------------------
Gi1/0/1 Root FWD 19 128.1 P2p
Gi1/0/2 Altn BLK 19 128.2 P2p
Gi1/0/4 Desg FWD 19 128.4 P2p
Gi1/0/3 Desg FWD 19 128.3 P2p
%LINEPROTO-5-UPDOWN: Line protocol on Interface
FastEthernet0/1, changed state to down
%LINEPROTO-5-UPDOWN: Line protocol on Interface
FastEthernet0/1, changed state to up
%LINEPROTO-5-UPDOWN: Line protocol on Interface
FastEthernet0/2, changed state to down
%LINEPROTO-5-UPDOWN: Line protocol on Interface
FastEthernet0/2, changed state to up
----
FastEthernet0/1:
Port state = 1
Channel group = 1 Mode = Desirable-S1 Gcchange = 0
Port-channel = Po1 GC = 0x00000000 Pseudo port-channel = Po1
Port index = 0 Load = 0x00 Protocol = PAgP
Flags: S - Device is sending Slow hello. C - Device is in Consistent state.
A - Device is in Auto mode. P - Device learns on physical port.
d - PAgP is down.
Timers: H - Hello timer is running. Q - Quit timer is running.
S - Switching timer is running. I - Interface timer is running.
Local information:
Hello Partner PAgP Learning Group
Port Flags State Timers Interval Count Priority Method Ifindex
Fa0/1 d U1/S1 H30s 1 0 128 Any 0
Age of the port in the current state: 00d:00h:00m:00s
----
FastEthernet0/2:
Port state = 1
Channel group = 1 Mode = Desirable-S1 Gcchange = 0
Port-channel = Po1 GC = 0x00000000 Pseudo port-channel = Po1
Port index = 0 Load = 0x00 Protocol = PAgP
Flags: S - Device is sending Slow hello. C - Device is in Consistent state.
A - Device is in Auto mode. P - Device learns on physical port.
d - PAgP is down.
Timers: H - Hello timer is running. Q - Quit timer is running.
S - Switching timer is running. I - Interface timer is running.
Local information:
Hello Partner PAgP Learning Group
Port Flags State Timers Interval Count Priority Method Ifindex
Fa0/2 d U1/S1 H30s 1 0 128 Any 0
Age of the port in the current state: 00d:00h:00m:00s
----
Port-channel1:Port-channel1
Age of the Port-channel = 00d:00h:27m:57s
Logical slot/port = 2/1 Number of ports = 0
GC = 0x00000000 HotStandBy port = null
Port state =
Protocol = 2
Port Security = Disabled
% Interface range command failed for GigabitEthernet1/0/3
% Command failed on interface GigabitEthernet1/0/3. Aborting
The interfaces are failing to join the etherchannel..
%LINK-5-CHANGED: Interface Port-channel1, changed state to up
%LINEPROTO-5-UPDOWN: Line protocol on Interface Port-channel1, changed state to up
%PM-4-ERR_DISABLE: channel-misconfig error detected on Gig1/0/3, putting Gig1/0/3 in err-disable state
%LINK-3-UPDOWN: Interface GigabitEthernet1/0/3, changed state to down
%LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/3, changed state to down
%LINEPROTO-5-UPDOWN: Line protocol on Interface Port-channel1, changed state to down
Flags: D - down P - in port-channel
I - stand-alone s - suspended
H - Hot-standby (LACP only)
R - Layer3 S - Layer2
U - in use f - failed to allocate aggregator
u - unsuitable for bundling
w - waiting to be aggregated
d - default port
Number of channel-groups in use: 1
Number of aggregators: 1
Group Port-channel Protocol Ports
------+-------------+-----------+----------------------------------------------
1 Po1(SD) - Gig1/0/3(D) Gig1/0/4(D)
Number of channel-groups in use: 1
Number of aggregators: 1
Group Port-channel Protocol Ports
------+-------------+-----------+----------------------------------------------
1 Po1(SU) PAgP Fa0/1(P) Fa0/2(P)
Number of channel-groups in use: 1
Number of aggregators: 1
Group Port-channel Protocol Ports
------+-------------+-----------+----------------------------------------------
1 Po1(SU) PAgP Gig1/0/3(P) Gig1/0/4(P)
VLAN0001
Spanning tree enabled protocol ieee
Root ID Priority 32769
Address 0001.645B.5321
Cost 28
Port 27(Port-channel1)
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
Bridge ID Priority 32769 (priority 32768 sys-id-ext 1)
Address 00E0.F7BC.472E
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
Aging Time 20
Interface Role Sts Cost Prio.Nbr Type
---------------- ---- --- --------- -------- --------------------------------
Fa0/3 Desg FWD 19 128.3 P2p
Fa0/4 Desg FWD 19 128.4 P2p
Po1 Root FWD 9 128.27 Shr
VLAN0001
Spanning tree enabled protocol ieee
Root ID Priority 32769
Address 0001.645B.5321
Cost 19
Port 1(GigabitEthernet1/0/1)
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
Bridge ID Priority 32769 (priority 32768 sys-id-ext 1)
Address 0001.96B3.31BC
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
Aging Time 20
Interface Role Sts Cost Prio.Nbr Type
---------------- ---- --- --------- -------- --------------------------------
Gi1/0/1 Root FWD 19 128.1 P2p
Gi1/0/2 Altn BLK 19 128.2 P2p
Po1 Desg FWD 9 128.29 Shr
VLAN0001
Spanning tree enabled protocol ieee
Root ID Priority 32769
Address 0001.645B.5321
This bridge is the root
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
Bridge ID Priority 32769 (priority 32768 sys-id-ext 1)
Address 0001.645B.5321
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
Aging Time 20
Interface Role Sts Cost Prio.Nbr Type
---------------- ---- --- --------- -------- --------------------------------
Fa0/1 Desg FWD 19 128.1 P2p
Fa0/2 Desg FWD 19 128.2 P2p
Fa0/3 Desg FWD 19 128.3 P2p
Fa0/4 Desg FWD 19 128.4 P2p
pvst Per-Vlan spanning tree mode
rapid-pvst Per-Vlan rapid spanning tree mode
mode Spanning tree operating mode
portfast Spanning tree portfast options
vlan VLAN Switch Spanning Tree
Number of channel-groups in use: 1
Number of aggregators: 1
Group Port-channel Protocol Ports
------+-------------+-----------+----------------------------------------------
1 Po1(SU) PAgP Fa0/1(P) Fa0/2(P)
Ethernet IEEE 802.3
FastEthernet FastEthernet IEEE 802.3
GigabitEthernet GigabitEthernet IEEE 802.3z
Port-channel Ethernet channel port interface
Vlan Catalyst Vlans
etherchannel Show interface etherchannel information
status interface line status
switchport Show interface switchport information
trunk Show interface trunk information
| Output Modifiers
Port Mode Encapsulation Status Native vlan
Po1 on 802.1q trunking 1
Port Vlans allowed on trunk
Po1 1-1005
Port Vlans allowed and active in management domain
Po1 1,2,3,4
Port Vlans in spanning tree forwarding state and not pruned
Po1 1,2,3,4
VLAN Name Status Ports
---- -------------------------------- --------- -------------------------------
1 default active Fa0/3, Fa0/4, Fa0/5, Fa0/6
Fa0/7, Fa0/8, Fa0/9, Fa0/10
Fa0/11, Fa0/12, Fa0/13, Fa0/14
Fa0/15, Fa0/16, Fa0/17, Fa0/18
Fa0/19, Fa0/20, Fa0/21, Fa0/22
Fa0/23, Fa0/24, Gig0/1, Gig0/2
2 Sales active
3 Marketing active
4 Accounting active
1002 fddi-default active
1003 token-ring-default active
1004 fddinet-default active
1005 trnet-default active
VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Trans1 Trans2
---- ----- ---------- ----- ------ ------ -------- ---- -------- ------ ------
1 enet 100001 1500 - - - - - 0 0
2 enet 100002 1500 - - - - - 0 0
3 enet 100003 1500 - - - - - 0 0
4 enet 100004 1500 - - - - - 0 0
1002 fddi 101002 1500 - - - - - 0 0
1003 tr 101003 1500 - - - - - 0 0
1004 fdnet 101004 1500 - - - ieee - 0 0
1005 trnet 101005 1500 - - - ibm - 0 0
VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Trans1 Trans2
---- ----- ---------- ----- ------ ------ -------- ---- -------- ------ ------
Remote SPAN VLANs
------------------------------------------------------------------------------
Primary Secondary Type Ports
------- --------- ----------------- ------------------------------------------
output
Number of channel-groups in use: 1
Number of aggregators: 1
Group Port-channel Protocol Ports
------+-------------+-----------+----------------------------------------------
1 Po1(SU) PAgP Gig1/0/3(P) Gig1/0/4(P)
Port Mode Encapsulation Status Native vlan
Po1 on 802.1q trunking 1
Port Vlans allowed on trunk
Po1 1-1005
Port Vlans allowed and active in management domain
Po1 1
Port Vlans in spanning tree forwarding state and not pruned
Po1 1
VLAN Name Status Ports
---- -------------------------------- --------- -------------------------------
1 default active Gig1/0/1, Gig1/0/2, Gig1/0/5, Gig1/0/6
Gig1/0/7, Gig1/0/8, Gig1/0/9, Gig1/0/10
Gig1/0/11, Gig1/0/12, Gig1/0/13, Gig1/0/14
Gig1/0/15, Gig1/0/16, Gig1/0/17, Gig1/0/18
Gig1/0/19, Gig1/0/20, Gig1/0/21, Gig1/0/22
Gig1/0/23, Gig1/0/24, Gig1/1/1, Gig1/1/2
Gig1/1/3, Gig1/1/4
1002 fddi-default active
1003 token-ring-default active
1004 fddinet-default active
1005 trnet-default active
VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Trans1 Trans2
---- ----- ---------- ----- ------ ------ -------- ---- -------- ------ ------
1 enet 100001 1500 - - - - - 0 0
1002 fddi 101002 1500 - - - - - 0 0
1003 tr 101003 1500 - - - - - 0 0
1004 fdnet 101004 1500 - - - ieee - 0 0
1005 trnet 101005 1500 - - - ibm - 0 0
VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Trans1 Trans2
---- ----- ---------- ----- ------ ------ -------- ---- -------- ------ ------
Remote SPAN VLANs
------------------------------------------------------------------------------
Primary Secondary Type Ports
------- --------- ----------------- ------------------------------------------
[cut]
interface FastEthernet0/1
description 1st connection to core switch
switchport trunk allowed vlan 1-3,5-1005
switchport mode trunk
switchport nonegotiate
channel-group 1 mode desirable
[cut]
VTP Version capable : 1 to 2
VTP version running : 1
VTP Domain Name :
VTP Pruning Mode : Disabled
VTP Traps Generation : Disabled
Device ID : 0000.0C44.7800
Configuration last modified by 192.168.10.17 at 3-1-93 00:24:14
Local updater ID is 192.168.10.17 on interface Vl1 (lowest numbered VLAN interface found)
Feature VLAN :
--------------
VTP Operating Mode : Server
Maximum VLANs supported locally : 255
Number of existing VLANs : 8
Configuration Revision : 6
MD5 digest : 0xC9 0xA8 0x18 0xDA 0x81 0xAB 0xB6 0x18
0x94 0xA8 0x20 0xAC 0x83 0x54 0x11 0x13
VTP Version capable : 1 to 2
VTP version running : 1
VTP Domain Name :
VTP Pruning Mode : Disabled
VTP Traps Generation : Disabled
Device ID : 0000.0C47.E300
Configuration last modified by 0.0.0.0 at 0-0-00 00:00:00
Local updater ID is 192.168.10.19 on interface Vl1 (lowest numbered VLAN interface found)
Feature VLAN :
--------------
VTP Operating Mode : Server
Maximum VLANs supported locally : 1005
Number of existing VLANs : 5
Configuration Revision : 0
MD5 digest : 0x7D 0x5A 0xA6 0x0E 0x9A 0x72 0xA0 0x3A
0xF0 0x58 0x10 0x6C 0x9C 0x0F 0xA0 0xF7
VTP Version capable : 1 to 2
VTP version running : 1
VTP Domain Name :
VTP Pruning Mode : Disabled
VTP Traps Generation : Disabled
Device ID : 000A.41A7.2600
Configuration last modified by 0.0.0.0 at 0-0-00 00:00:00
Local updater ID is 192.168.10.18 on interface Vl1 (lowest numbered VLAN interface found)
Feature VLAN :
--------------
VTP Operating Mode : Server
Maximum VLANs supported locally : 1005
Number of existing VLANs : 5
Configuration Revision : 0
MD5 digest : 0x7D 0x5A 0xA6 0x0E 0x9A 0x72 0xA0 0x3A
0xF0 0x58 0x10 0x6C 0x9C 0x0F 0xA0 0xF7
Device mode already VTP SERVER.
Changing VTP domain name from NULL to lammle
Setting device VLAN database password to todd
Setting device to VTP CLIENT mode.
Changing VTP domain name from NULL to lammle
Setting device VLAN database password to todd
Setting device to VTP CLIENT mode.
Changing VTP domain name from NULL to lammle
Setting device VLAN database password to todd
VTP Version capable : 1 to 2
VTP version running : 1
VTP Domain Name : lammle
VTP Pruning Mode : Disabled
VTP Traps Generation : Disabled
Device ID : 0000.0C44.7800
Configuration last modified by 192.168.10.17 at 3-1-93 00:24:14
Local updater ID is 192.168.10.17 on interface Vl1 (lowest numbered VLAN interface found)
Feature VLAN :
--------------
VTP Operating Mode : Server
Maximum VLANs supported locally : 255
Number of existing VLANs : 8
Configuration Revision : 0
MD5 digest : 0x41 0x79 0xCD 0x08 0x50 0x87 0x28 0x33
0xC9 0x04 0xFD 0xF8 0x0A 0xF5 0xD8 0x0B
VTP Version capable : 1 to 2
VTP version running : 1
VTP Domain Name : lammle
VTP Pruning Mode : Disabled
VTP Traps Generation : Disabled
Device ID : 0000.0C47.E300
Configuration last modified by 192.168.10.17 at 3-1-93 00:24:14
Feature VLAN :
--------------
VTP Operating Mode : Client
Maximum VLANs supported locally : 1005
Number of existing VLANs : 8
Configuration Revision : 0
MD5 digest : 0x41 0x79 0xCD 0x08 0x50 0x87 0x28 0x33
0xC9 0x04 0xFD 0xF8 0x0A 0xF5 0xD8 0x0B
VTP Version capable : 1 to 2
VTP version running : 1
VTP Domain Name : lammle
VTP Pruning Mode : Disabled
VTP Traps Generation : Disabled
Device ID : 0000.0C44.7800
Configuration last modified by 192.168.10.17 at 3-1-93 00:24:14
Feature VLAN :
--------------
VTP Operating Mode : Client
Maximum VLANs supported locally : 255
Number of existing VLANs : 8
Configuration Revision : 0
MD5 digest : 0x41 0x79 0xCD 0x08 0x50 0x87 0x28 0x33
0xC9 0x04 0xFD 0xF8 0x0A 0xF5 0xD8 0x0B
VLAN Name Status Ports
---- -------------------------------- --------- -------------------------------
1 default active Fa0/3, Fa0/4, Fa0/5, Fa0/6
Fa0/7, Fa0/8, Fa0/9, Fa0/10
Fa0/11, Fa0/12, Fa0/13, Fa0/14
Fa0/15, Fa0/16, Fa0/17, Fa0/18
Fa0/19, Fa0/20, Fa0/21, Fa0/22
Fa0/23, Fa0/24, Gig0/1, Gig0/2
2 Sales active
3 Marketing active
4 Accounting active
1002 fddi-default active
1003 token-ring-default active
1004 fddinet-default active
1005 trnet-default active
VLAN Name Status Ports
---- -------------------------------- --------- -------------------------------
1 default active Gig1/0/1, Gig1/0/2, Gig1/0/5, Gig1/0/6
Gig1/0/7, Gig1/0/8, Gig1/0/9, Gig1/0/10
Gig1/0/11, Gig1/0/12, Gig1/0/13, Gig1/0/14
Gig1/0/15, Gig1/0/16, Gig1/0/17, Gig1/0/18
Gig1/0/19, Gig1/0/20, Gig1/0/21, Gig1/0/22
Gig1/0/23, Gig1/0/24, Gig1/1/1, Gig1/1/2
Gig1/1/3, Gig1/1/4
2 Sales active
3 Marketing active
4 Accounting active
1002 fddi-default active
1003 token-ring-default active
1004 fddinet-default active
1005 trnet-default active
VLAN Name Status Ports
---- -------------------------------- --------- -------------------------------
1 default active Fa0/1, Fa0/2, Fa0/3, Fa0/4
Fa0/5, Fa0/6, Fa0/7, Fa0/8
Fa0/9, Fa0/10, Fa0/11, Fa0/12
Fa0/13, Fa0/14, Fa0/15, Fa0/16
Fa0/17, Fa0/18, Fa0/19, Fa0/20
Fa0/21, Fa0/22, Fa0/23, Fa0/24
Gig0/1, Gig0/2
1002 fddi-default active
1003 token-ring-default active
1004 fddinet-default active
1005 trnet-default active
Port Name Status Vlan Duplex Speed Type
Po1 connected trunk auto auto
Fa0/1 1st connection to connected trunk auto auto 10/100BaseTX
Fa0/2 2nd connection to connected trunk auto auto 10/100BaseTX
Fa0/3 connection to Host connected 1 auto auto 10/100BaseTX
Fa0/4 connection to Phon connected 1 auto auto 10/100BaseTX
Fa0/5 notconnect 1 auto auto 10/100BaseTX
Fa0/6 notconnect 1 auto auto 10/100BaseTX
Fa0/7 notconnect 1 auto auto 10/100BaseTX
Fa0/8 connection to IVR notconnect 1 auto auto 10/100BaseTX
Fa0/9 notconnect 1 auto auto 10/100BaseTX
Po1 connected trunk auto auto
Gig1/0/1 1st conn to SW2 connected 1 auto auto 10/100BaseTX
Gig1/0/2 2nd conn to SW2 connected 1 auto auto 10/100BaseTX
Gig1/0/3 1st connection to connected trunk auto auto 10/100BaseTX
Gig1/0/4 2nd connection to connected trunk auto auto 10/100BaseTX
Port Name Status Vlan Duplex Speed Type
Fa0/1 1st connection to connected 1 auto auto 10/100BaseTX
Fa0/2 2nd connection to connected 1 auto auto 10/100BaseTX
Fa0/3 connection to Host connected 1 auto auto 10/100BaseTX
Fa0/4 connection to Phon connected 1 auto auto 10/100BaseTX
Command rejected: An interface whose trunk encapsulation is "Auto" can not be configured to "trunk" mode.
%LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/1, changed state to down
%LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/1, changed state to up
Fa0/1 1st connection to connected trunk auto auto 10/100BaseTX
Fa0/2 2nd connection to connected 1 auto auto 10/100BaseTX
Fa0/3 connection to Host connected 1 auto auto 10/100BaseTX
Fa0/4 connection to Phon connected 1 auto auto 10/100BaseTX
VLAN Name Status Ports
---- -------------------------------- --------- -------------------------------
1 default active Fa0/2, Fa0/3, Fa0/4, Fa0/5
Fa0/6, Fa0/7, Fa0/8, Fa0/9
Fa0/10, Fa0/11, Fa0/12, Fa0/13
Fa0/14, Fa0/15, Fa0/16, Fa0/17
Fa0/18, Fa0/19, Fa0/20, Fa0/21
Fa0/22, Fa0/23, Fa0/24, Gig0/1
Gig0/2
2 Sales active
3 Marketing active
4 Accounting active
1002 fddi-default active
1003 token-ring-default active
1004 fddinet-default active
1005 trnet-default active
VLAN Name Status Ports
---- -------------------------------- --------- -------------------------------
1 default active Fa0/3, Fa0/4, Fa0/5, Fa0/6
Fa0/7, Fa0/8, Fa0/9, Fa0/10
Fa0/11, Fa0/12, Fa0/13, Fa0/14
Fa0/15, Fa0/16, Fa0/17, Fa0/18
Fa0/19, Fa0/20, Fa0/21, Fa0/22
Fa0/23, Fa0/24, Gig0/1, Gig0/2
2 Sales active
3 Marketing active
4 Accounting active
1002 fddi-default active
1003 token-ring-default active
1004 fddinet-default active
1005 trnet-default active
VLAN Name Status Ports
---- -------------------------------- --------- -------------------------------
1 default active Gig1/0/2, Gig1/0/5, Gig1/0/6, Gig1/0/7
Gig1/0/8, Gig1/0/9, Gig1/0/10, Gig1/0/11
Gig1/0/12, Gig1/0/13, Gig1/0/14, Gig1/0/15
Gig1/0/16, Gig1/0/17, Gig1/0/18, Gig1/0/19
Gig1/0/20, Gig1/0/21, Gig1/0/22, Gig1/0/23
Gig1/0/24, Gig1/1/1, Gig1/1/2, Gig1/1/3
Gig1/1/4
2 Sales active
3 Marketing active
4 Accounting active
1002 fddi-default active
1003 token-ring-default active
1004 fddinet-default active
1005 trnet-default active
VLAN Name Status Ports
---- -------------------------------- --------- -------------------------------
1 default active Fa0/2, Fa0/3, Fa0/4, Fa0/5
Fa0/6, Fa0/7, Fa0/8, Fa0/9
Fa0/10, Fa0/11, Fa0/12, Fa0/13
Fa0/14, Fa0/15, Fa0/16, Fa0/17
Fa0/18, Fa0/19, Fa0/20, Fa0/21
Fa0/22, Fa0/23, Fa0/24, Gig0/1
Gig0/2
2 Sales active
3 Marketing active
4 Accounting active
1002 fddi-default active
1003 token-ring-default active
1004 fddinet-default active
1005 trnet-default active
VTP Version capable : 1 to 2
VTP version running : 1
VTP Domain Name : lammle
VTP Pruning Mode : Disabled
VTP Traps Generation : Disabled
Device ID : 0000.0C44.7800
Configuration last modified by 192.168.10.17 at 3-1-93 00:24:14
Feature VLAN :
--------------
VTP Operating Mode : Client
Maximum VLANs supported locally : 255
Number of existing VLANs : 8
Configuration Revision : 0
MD5 digest : 0x41 0x79 0xCD 0x08 0x50 0x87 0x28 0x33
0xC9 0x04 0xFD 0xF8 0x0A 0xF5 0xD8 0x0B
VTP Version capable : 1 to 2
VTP version running : 1
VTP Domain Name : lammle
VTP Pruning Mode : Disabled
VTP Traps Generation : Disabled
Device ID : 0000.0C47.E300
Configuration last modified by 192.168.10.17 at 3-1-93 00:24:14
Feature VLAN :
--------------
VTP Operating Mode : Client
Maximum VLANs supported locally : 1005
Number of existing VLANs : 8
Configuration Revision : 0
MD5 digest : 0x41 0x79 0xCD 0x08 0x50 0x87 0x28 0x33
0xC9 0x04 0xFD 0xF8 0x0A 0xF5 0xD8 0x0B
VTP Version capable : 1 to 2
VTP version running : 1
VTP Domain Name : lammle
VTP Pruning Mode : Disabled
VTP Traps Generation : Disabled
Device ID : 000A.41A7.2600
Configuration last modified by 192.168.10.17 at 3-1-93 00:24:14
Feature VLAN :
--------------
VTP Operating Mode : Client
Maximum VLANs supported locally : 1005
Number of existing VLANs : 8
Configuration Revision : 0
MD5 digest : 0x41 0x79 0xCD 0x08 0x50 0x87 0x28 0x33
0xC9 0x04 0xFD 0xF8 0x0A 0xF5 0xD8 0x0B
--- AutoSecure Configuration ---
*** AutoSecure configuration enhances the security of
the router, but it will not make it absolutely resistant
to all security attacks ***
AutoSecure will modify the configuration of your device.
All configuration changes will be shown. For a detailed
explanation of how the configuration changes enhance security
and any possible side effects, please refer to Cisco.com for
Autosecure documentation.
At any prompt you may enter '?' for help.
Use ctrl-c to abort this session at any prompt.
Gathering information about the router for AutoSecure
Is this router connected to internet? [no]: yes [enter]
Enter the number of interfaces facing the internet [1]: [enter]
Interface IP-Address OK? Method Status Protocol
GigabitEthernet0/0/0 10.10.1.1 YES manual up down
GigabitEthernet0/0/1 unassigned YES unset administratively down down
GigabitEthernet0/0/2 unassigned YES unset administratively down down
Vlan1 unassigned YES unset administratively down down
Enter the interface name that is facing the internet: gigabitethernet0/0/0
Securing Management plane services...
Disabling service finger
Disabling service pad
Disabling udp & tcp small servers
Enabling service password encryption
Enabling service tcp-keepalives-in
Enabling service tcp-keepalives-out
Disabling the cdp protocol
Disabling the bootp server
Disabling the http server
Disabling the finger service
Disabling source routing
Disabling gratuitous arp
Here is a sample Security Banner to be shown
at every access to device. Modify it to suit your
enterprise requirements.
Authorized Access only
This system is the property of So-&-So-Enterprise.
UNAUTHORIZED ACCESS TO THIS DEVICE IS PROHIBITED.
You must have explicit permission to access this
device. All activities performed on this device
are logged. Any violations of access policy will result
in disciplinary action.
Enter the security banner {Put the banner between
k and k, where k is any character}:# if you are not part of this domain, disconnect now! #
Enable secret is either not configured or
is the same as enable password
Enter the new enable secret: todd
Confirm the enable secret: todd
Enter the new enable password: 1234
Confirm the enable password: 1234
Configuring AAA local authentication
Configuring Console, Aux and VTY lines for
local authentication, exec-timeout, and transport
Securing device against Login Attacks
Configure the following parameters
Blocking Period when Login Attack detected:?
% A decimal number between 1 and 32767.
Blocking Period when Login Attack detected: 100
Maximum Login failures with the device: 5
Maximum time period for crossing the failed login attempts: 10
Configure SSH server? [yes]: [enter]
Enter the host name: lammle.com
Enter the domain-name: lammle.com
Disabling mop on Ethernet interfaces
Securing Forwarding plane services...
Enabling CEF (This might impact the memory requirements for your platform)
Enabling unicast rpf on all interfaces connected
to internet
Configure CBAC Firewall feature? [yes/no]: no
Tcp intercept feature is used prevent tcp syn attack
on the servers in the network. Create autosec_tcp_intercept_list
to form the list of servers to which the tcp traffic is to
be observed
Enable tcp intercept feature? [yes/no]: yes
This is the configuration generated:
!
service password-encryption
no cdp run
access-list 100 permit udp any any eq bootpc
banner motd #go away#
enable secret 5 $1$mERr$V5ujdIM9bTB/I.ipB0gkJ0
enable password 7 08701E1D5D
username todd password 7 0835434A0D
aaa new-model
aaa authentication login local_auth local
line con 0
login authentication local_auth
exec-timeout 5 0
transport output telnet
line vty 0 4
login authentication local_auth
transport input telnet
service timestamps debug datetime msec
service timestamps log datetime msec
logging trap debugging
logging console
logging buffered
line vty 0 4
transport input ssh
transport input telnet
hostname lammle.com
ip domain-name lammle.com
ip access-list extended 100
permit udp any any eq bootpc
Apply this configuration to running-config? [yes]: [enter]
Applying the config generated to running-config
The name for the keys will be: test.test
% The key modulus size is 1024 bits
% Generating 1024 bit RSA keys, keys will be non-exportable...
*Mar 1 22:56:41.001: %SYS-3-CPUHOG: Task is running for (2007)msecs, more than
(2000)msecs (0/0),process = crypto sw pk proc.
-Traceback= 0x824198E0 0x82419FC4 0x8283C238 0x82866AD8 0x828667A8 0x82865D34 0x
828660F4 0x82866510 0x802335D4 0x80236D80 [OK]
lammle.com#
extended Extended Access List
standard Standard Access List
<1-99> Standard IP access-list number
WORD Access-list name
<1-99> IP standard access list
<100-199> IP extended access list
<100-199> Extended IP access-list number
WORD name
Gateway of last resort is not set
172.16.0.0/16 is variably subnetted, 7 subnets, 2 masks
C 172.16.10.0/24 is directly connected, FastEthernet0/0
L 172.16.10.1/32 is directly connected, FastEthernet0/0
C 172.16.20.0/24 is directly connected, Serial0/0/0
L 172.16.20.1/32 is directly connected, Serial0/0/0
R 172.16.30.0/24 [120/1] via 172.16.20.2, 00:00:14, Serial0/0/0
R 172.16.40.0/24 [120/1] via 172.16.20.2, 00:00:14, Serial0/0/0
R 172.16.50.0/24 [120/2] via 172.16.20.2, 00:00:14, Serial0/0/0
Gateway of last resort is not set
172.16.0.0/16 is variably subnetted, 8 subnets, 2 masks
R 172.16.10.0/24 [120/1] via 172.16.20.1, 00:00:15, Serial0/0/0
C 172.16.20.0/24 is directly connected, Serial0/0/0
L 172.16.20.2/32 is directly connected, Serial0/0/0
C 172.16.30.0/24 is directly connected, FastEthernet0/0
L 172.16.30.1/32 is directly connected, FastEthernet0/0
C 172.16.40.0/24 is directly connected, Serial0/0/1
L 172.16.40.1/32 is directly connected, Serial0/0/1
R 172.16.50.0/24 [120/1] via 172.16.40.2, 00:00:24, Serial0/0/1
Gateway of last resort is not set
172.16.0.0/16 is variably subnetted, 7 subnets, 2 masks
R 172.16.10.0/24 [120/2] via 172.16.40.1, 00:00:03, Serial0/0/0
R 172.16.20.0/24 [120/1] via 172.16.40.1, 00:00:03, Serial0/0/0
R 172.16.30.0/24 [120/1] via 172.16.40.1, 00:00:03, Serial0/0/0
C 172.16.40.0/24 is directly connected, Serial0/0/0
L 172.16.40.2/32 is directly connected, Serial0/0/0
C 172.16.50.0/24 is directly connected, FastEthernet0/0
L 172.16.50.1/32 is directly connected, FastEthernet0/0
Pinging 172.16.10.3 with 32 bytes of data:
Request timed out.
Reply from 172.16.10.3: bytes=32 time=1ms TTL=126
Reply from 172.16.10.3: bytes=32 time=1ms TTL=126
Reply from 172.16.10.3: bytes=32 time=9ms TTL=126
Ping statistics for 172.16.10.3:
Packets: Sent = 4, Received = 3, Lost = 1 (25% loss),
Approximate round trip times in milli-seconds:
Minimum = 1ms, Maximum = 9ms, Average = 3ms
Pinging 172.16.10.3 with 32 bytes of data:
Reply from 172.16.20.1: Destination host unreachable.
Reply from 172.16.20.1: Destination host unreachable.
Reply from 172.16.20.1: Destination host unreachable.
Reply from 172.16.20.1: Destination host unreachable.s
Trying 172.16.20.2 ...
% Connection timed out; remote host not responding
User Access Verification
Password:
[cut]
Outgoing access list is not set
Inbound access list is 110
[cut]
deny Specify packets to reject
permit Specify packets to forward
remark Access list entry comment
A.B.C.D Address to match
any Any source host
host A single host address
Standard IP access list 10
10 permit host 172.16.1.1
Even though I did not use the HOST param.. the ACL processed the given address as a host
Standard IP access list 10
10 permit host 172.16.1.1
20 permit host 172.16.50.0
Again the rule automatically applied the HOST param. I am surprised the system didnt recoginze 50.0 as a network address...
% Incomplete command.
^ Here I tried to give a source and dest IP without the HOST param or supplying mask info. The command errored.
A.B.C.D Source address
any Any source host
host A single source host
Again let's try giving a network address with the HOST param
Standard IP access list 10
10 permit host 172.16.1.1
20 permit host 172.16.50.0
Extended IP access list 110
10 permit tcp host 172.16.50.0 host 172.16.50.2 eq telnet
Again it works.. would this cause problems later? The ACL shows 50.0 as a host, with no mask info provided.
ip nat pool todd-nat 170.168.10.10 170.168.10.20 netmask 255.255.255.0
dynamic
Gateway of last resort is not set
171.16.0.0/16 is variably subnetted, 3 subnets, 3 masks
S 171.16.0.0/16 [1/0] via 171.16.10.1
C 171.16.10.0/24 is directly connected, Serial0/0/1
L 171.16.10.2/32 is directly connected, Serial0/0/1
192.168.20.0/24 is variably subnetted, 2 subnets, 2 masks
C 192.168.20.0/24 is directly connected, Serial0/0/0
L 192.168.20.1/32 is directly connected, Serial0/0/0
Gateway of last resort is not set
192.168.20.0/24 is variably subnetted, 2 subnets, 2 masks
C 192.168.20.0/24 is directly connected, Serial0/0/0
L 192.168.20.2/32 is directly connected, Serial0/0/0
192.168.30.0/24 is variably subnetted, 2 subnets, 2 masks
C 192.168.30.0/24 is directly connected, FastEthernet0/0
L 192.168.30.1/32 is directly connected, FastEthernet0/0
Gateway of last resort is not set
R 192.168.20.0/24 [120/1] via 192.168.30.1, 00:00:10, FastEthernet0/0
192.168.30.0/24 is variably subnetted, 2 subnets, 2 masks
C 192.168.30.0/24 is directly connected, FastEthernet0/0
L 192.168.30.2/32 is directly connected, FastEthernet0/0
Interface IP-Address OK? Method Status Protocol
FastEthernet0/0 unassigned YES unset administratively down down
FastEthernet0/1 unassigned YES unset administratively down down
Serial0/0/0 192.168.20.1 YES manual up up
Serial0/0/1 171.16.10.2 YES manual up up
Vlan1 unassigned YES unset administratively down down
Capability Codes: R - Router, T - Trans Bridge, B - Source Route Bridge
S - Switch, H - Host, I - IGMP, r - Repeater, P - Phone
Device ID Local Intrfce Holdtme Capability Platform Port ID
B Ser 0/0/1 153 R C2800 Ser 0/0/0
ISP Ser 0/0/0 168 R C2800 Ser 0/0/0
Interface IP-Address OK? Method Status Protocol
FastEthernet0/0 unassigned YES unset administratively down down
FastEthernet0/1 unassigned YES unset administratively down down
Serial0/0/0 172.16.10.1 YES manual up up
Serial0/0/1 unassigned YES unset administratively down down
Vlan1 unassigned YES unset administratively down down
Capability Codes: R - Router, T - Trans Bridge, B - Source Route Bridge
S - Switch, H - Host, I - IGMP, r - Repeater, P - Phone
Device ID Local Intrfce Holdtme Capability Platform Port ID
A Ser 0/0/0 164 R C2800 Ser 0/0/0
Interface IP-Address OK? Method Status Protocol
FastEthernet0/0 unassigned YES unset administratively down down
FastEthernet0/1 unassigned YES unset administratively down down
Serial0/0/0 171.16.10.2 YES manual up up
Serial0/0/1 192.168.20.1 YES manual up up
Vlan1 unassigned YES unset administratively down down
Gateway of last resort is not set
171.16.0.0/16 is variably subnetted, 3 subnets, 3 masks
S 171.16.0.0/16 [1/0] via 171.16.10.1
C 171.16.10.0/24 is directly connected, Serial0/0/0
L 171.16.10.2/32 is directly connected, Serial0/0/0
192.168.20.0/24 is variably subnetted, 2 subnets, 2 masks
C 192.168.20.0/24 is directly connected, Serial0/0/1
L 192.168.20.1/32 is directly connected, Serial0/0/1
R 192.168.30.0/24 [120/1] via 192.168.20.2, 00:00:08, Serial0/0/1
Gateway of last resort is not set
192.168.20.0/24 is variably subnetted, 2 subnets, 2 masks
C 192.168.20.0/24 is directly connected, Serial0/0/0
L 192.168.20.2/32 is directly connected, Serial0/0/0
192.168.30.0/24 is variably subnetted, 2 subnets, 2 masks
C 192.168.30.0/24 is directly connected, FastEthernet0/0
L 192.168.30.1/32 is directly connected, FastEthernet0/0
Gateway of last resort is not set
R 192.168.20.0/24 [120/1] via 192.168.30.1, 00:00:08, FastEthernet0/0
192.168.30.0/24 is variably subnetted, 2 subnets, 2 masks
C 192.168.30.0/24 is directly connected, FastEthernet0/0
L 192.168.30.2/32 is directly connected, FastEthernet0/0
Gateway of last resort is not set
171.16.0.0/16 is variably subnetted, 2 subnets, 2 masks
C 171.16.10.0/24 is directly connected, Serial0/0/0
L 171.16.10.1/32 is directly connected, Serial0/0/0
Gateway of last resort is not set
171.16.0.0/16 is variably subnetted, 3 subnets, 3 masks
S 171.16.0.0/16 [1/0] via 171.16.10.1
C 171.16.10.0/24 is directly connected, Serial0/0/0
L 171.16.10.2/32 is directly connected, Serial0/0/0
192.168.20.0/24 is variably subnetted, 2 subnets, 2 masks
C 192.168.20.0/24 is directly connected, Serial0/0/1
L 192.168.20.1/32 is directly connected, Serial0/0/1
R 192.168.30.0/24 [120/1] via 192.168.20.2, 00:00:10, Serial0/0/1
Gateway of last resort is not set
R 171.16.0.0/16 [120/1] via 192.168.20.1, 00:00:18, Serial0/0/0
192.168.20.0/24 is variably subnetted, 2 subnets, 2 masks
C 192.168.20.0/24 is directly connected, Serial0/0/0
L 192.168.20.2/32 is directly connected, Serial0/0/0
192.168.30.0/24 is variably subnetted, 2 subnets, 2 masks
C 192.168.30.0/24 is directly connected, FastEthernet0/0
L 192.168.30.1/32 is directly connected, FastEthernet0/0
Gateway of last resort is not set
R 171.16.0.0/16 [120/2] via 192.168.30.1, 00:00:07, FastEthernet0/0
R 192.168.20.0/24 [120/1] via 192.168.30.1, 00:00:07, FastEthernet0/0
192.168.30.0/24 is variably subnetted, 2 subnets, 2 masks
C 192.168.30.0/24 is directly connected, FastEthernet0/0
L 192.168.30.2/32 is directly connected, FastEthernet0/0
Gateway of last resort is 0.0.0.0 to network 0.0.0.0
171.16.0.0/16 is variably subnetted, 2 subnets, 2 masks
C 171.16.10.0/24 is directly connected, Serial0/0/0
L 171.16.10.1/32 is directly connected, Serial0/0/0
S* 0.0.0.0/0 is directly connected, Serial0/0/0
Trying 171.16.10.1 ...Open
Trying 171.16.10.1 ...Open
Line User Host(s) Idle Location
0 con 0 idle 00:03:00
324 vty 0 idle 00:00:06 171.16.10.50
*325 vty 1 idle 00:00:00 171.16.10.51
Pro Inside global Inside local Outside local Outside global
tcp 171.16.10.50:1025 192.168.30.2:1025 171.16.10.1:23 171.16.10.1:23
tcp 171.16.10.50:1026 192.168.30.2:1026 171.16.10.1:23 171.16.10.1:23
tcp 171.16.10.50:1027 192.168.30.2:1027 171.16.10.1:23 171.16.10.1:23
tcp 171.16.10.51:1025 192.168.20.2:1025 171.16.10.1:23 171.16.10.1:23
This does not look like the results from the book- why are ports being used? I did not specify 'overload'
%Pool GlobalNet in use, cannot destroy
output
Trying 171.16.10.1 ...Open
ISP>
Trying 171.16.10.1 ...Open
ISP>
Line User Host(s) Idle Location
* 0 con 0 idle 00:00:00
324 vty 0 idle 00:01:44 171.16.10.100
325 vty 1 idle 00:01:42 171.16.10.100
Pro Inside global Inside local Outside local Outside global
tcp 171.16.10.100:1026 192.168.30.2:1026 171.16.10.1:23 171.16.10.1:23
tcp 171.16.10.100:1027 192.168.20.2:1027 171.16.10.1:23 171.16.10.1:23
NAT: s=192.168.30.2->171.16.10.100, d=171.16.10.1 [24]
NAT*: s=171.16.10.1, d=171.16.10.100->192.168.30.2 [105]
NAT: s=192.168.30.2->171.16.10.100, d=171.16.10.1 [25]
NAT*: s=171.16.10.1, d=171.16.10.100->192.168.30.2 [106]
NAT: s=192.168.30.2->171.16.10.100, d=171.16.10.1 [26]
NAT*: s=171.16.10.1, d=171.16.10.100->192.168.30.2 [107]
NAT: s=192.168.30.2->171.16.10.100, d=171.16.10.1 [27]
NAT*: s=171.16.10.1, d=171.16.10.100->192.168.30.2 [108]
NAT: s=192.168.30.2->171.16.10.100, d=171.16.10.1 [28]
NAT*: s=171.16.10.1, d=171.16.10.100->192.168.30.2 [109]
Pro Inside global Inside local Outside local Outside global
--- 1.1.128.1 10.1.1.1 --- ---
--- 1.1.130.178 10.1.1.2 --- ---
--- 1.1.129.174 10.1.1.10 --- ---
--- 1.1.130.101 10.1.1.89 --- ---
--- 1.1.134.169 10.1.1.100 --- ---
--- 1.1.135.174 10.1.1.200 --- ---
Need to cover 128 thru 135 in the 3rd octet for inside global addresses. Block size 8 will do it.
ip nat pool Corp 198.18.41.129 198.18.41.134 netmask 255.255.255.248
ip nat inside source list 100 int pool Corp overload
show access-list
NAT*: s=172.16.2.2, d=192.168.2.1->10.1.1.1 [1]
PROBLEM
output
output
output
output
output