Thursday, March 21, 2013

Best Practice Access List Branch Office Router (Firewall)


At Branch office you will not always use ASA for security and VPN connectivity with Central office, best way is to use router that you already have at Branch office using Access control list.

 



This approach is best for this scenario, you can change, add or modify for your needs.

Monday, November 26, 2012

How To Configure VPN Site-to-Site using CiscoCP – GNS3

This is network lab I used to configure VPN in GNS3. I used my LAN to simulate the Internet and the network is 10.143.88.0 /24, and two LAN’s I want connect via VPN, 192.168.100.0/24 and 192.168.200.0/24.



Sunday, September 30, 2012

How to remove caps/num lock notifications




Every time when I press Caps Lock or Num Lock on keyboard notification balloon pop-up in right low corner of the screen that it’s been turned on/off. It is annoying and it’s disabled me from typing for a couple of seconds. So I decided to turned off, process responsible for notification is QLC Controller.

You can turn off from Task Manager, but every time you Log Off or Turn Off your computer it’s started again. The best way is to turner of from Startup. To do so, start MSCONFIG from Run and from Startup tab and uncheck HP Hotkey Support. 



This will solve problem permanently.

Sunday, September 9, 2012

How To Configure NTP on Cisco router - GNS3



Network Time Protocol (NTP) is a networking protocol for clock synchronization between computer systems over packet-switched, variable-latency data networks and it works on Application Layer. The protocol uses the User Datagram Protocol (UDP) on port number 123.
I will configure router R1 to use NTP clock synchronization from 2.rs.pool.ntp.org, the source of server from http://www.pool.ntp.org/ which is the largest virtual cluster of time servers.
So let's start.
First check time and date on R1...

R1#show clock
*00:14:33.191 UTC Fri Mar 1 2002

Before we configure R1 to use NTP first of all we need to configure name server and lookup for domain name.

R1(config)#ip domain-lookup
R1(config)#ip name-server 4.2.2.2

Thursday, August 23, 2012

Advertise default route under OSPF



In this example I will explain where and how to advertise default route under ospf process to send to other ospf routers.
From diagram you can see topology, it's not complex but is good for this purpose.
First I will list configuration of router R1 and R2 and configuration itself from both routers.

R1 is configured for:

- NAT overload
- Serial interface S1/0 as NAT inside with IP address 10.150.20.1/30, and interface on ISP direction with NAT outside with IP received from ISP DHCP server.
- OSPF routing protocol advertising on interface S1/0 or specific IP address 10.150.20.1/30

!
hostname R1
!
ip domain name lab.local
ip name-server 4.2.2.2
ip name-server 192.168.1.1
!
interface FastEthernet0/0
 ip address dhcp
 ip nat outside
 duplex auto
 speed auto
!
interface Serial1/0
 ip address 10.150.20.1 255.255.255.252
 ip nat inside
 clock rate 64000
!        
router ospf 1
 network 10.150.20.1 0.0.0.0 area 0
!
!        
ip nat inside source list NAT_ADDRESSES interface FastEthernet0/0 overload
!
ip access-list standard NAT_ADDRESSES
 permit 192.168.10.0 0.0.0.255
!
end

There is no command for static route because I received that route from my Linksys which I'm using for access the Internet. Addition: I read that if interface which have enabled ip address dhcp router will automatically learn default route, which is case in this example.
S*   0.0.0.0/0 [254/0] via 10.143.88.254 -- Linksys IP address

Saturday, June 16, 2012

Tips for the Cisco IOS alias commands

I read post on packetpushers.net  about IOS Alias command and I found them very helpful. I tried them my self. Read the post first and then experiment, the sky is the limit ;)

Thursday, March 29, 2012

RSTP and Port Fast

How much PortFast is actually fast? Well, let’s see.
For this purpose I will use debug for spanning-tree to see how much it is take to make interface in forwarding state.

SW_1#debug spanning-tree events

I choose interface FastEthernet 1/10 on my SW_1, and I shutdown interface.
That interface is in VLAN 1 and it is access port, because PortFast have to be configured on access port only, not trunk port.
So let’s make this interface UP/UP…

SW_1(config)#interface fastethernet 1/10
SW_1(config-if)#no shutdown
SW_1(config-if)#
*Mar  1 00:33:20.215: STP: VLAN1 Fa1/10 -> listening -- 15 sec forward delay
*Mar  1 00:33:35.231: STP: VLAN1 Fa1/10 -> learning -- 15 sec  forward delay
*Mar  1 00:33:50.255: STP: VLAN1 Fa1/10 -> forwarding
SW_1(config-if)#

Friday, February 10, 2012

Configure Basic NAT using CCP


It is very easy to configure NAT using CCP just with few clicks, if you know what you're doing.
Let's start configuring.
Firs off all start CCP and discover yours device (router), then click Configure ->Router -> NAT->Basic NAT  and click button "Launch the selected task".


Next