Phase 1: Project Overview

<aside> 💡

Tool being used: Cisco Packet Tracer

Steps:

  1. Build a topology with one router, one switch and four PCs.
    1. Each PC will represent a department in the company
      1. Finance
      2. Human Resources(HR)
      3. IT
      4. Customer Support
  2. Configure a VLAN on the switch to separate traffic for each department
  3. Setup Routing so the different VLANs can communicate with each other
  4. Enable DHCP on the router so devices get an IP address when they connect.
  5. Secure the network by creating an Access Control List to block Customer Support from IT. </aside>

1. Network Topology Diagram (Phase 1)

                                                                    Router-on-a-stick Topology

                                                                Router-on-a-stick Topology 

2. VLANs (Traffic Segmentation)

VLAN ID Department Subnet Usable hosts
VLAN 10 Finance 192.168.10.0/24 254
VLAN 20 HR 192.168.20.0/24 254
VLAN 30 IT 192.168.30.0/24 254
VLAN 40 Customer Support 192.168.40.0/24 254
VLAN 99 Management 192.168.99.0/24 ————-

3. Network Addressing Table

Device Interface VLAN Department IP Address/Profile Default Gateway
R1 Gig0/0.10 10 Finance 192.168.10.1 —————
R1 Gig0/0.20 20 HR 192.168.20.1 —————
R1 Gig0/0.30 30 IT 192.168.30.1 —————
R1 Gig0/0.40 40 Customer Support 192.168.40.1 —————
R1 Gig0/0.99 99 Management 192.168.99.1 —————
SW1 Gig0/1 10 Finance ————— —————
SW1 Fa0/1 20 HR ————— —————
SW1 Gig0/2 30 IT ————— —————
SW1 Fa0/2 40 Customer Support ————— —————
PC-Finance Fa0/0 10 Finance DHCP Assigned 192.168.10.1
PC-HR Fa0/0 20 HR DHCP Assigned 192.168.20.1
PC-IT Fa0/0 30 IT DHCP Assigned 192.168.30.1
PC-Support Fa0/0 40 Customer Support DHCP Assigned 192.168.40.1

4. Switch Management

  1. Management Interface
Device Hostname Interface VLAN IP Address Subnet Mask Default Gateway
Switch SW1 VLAN 99 SVI 99 192.168.99.2 255.255.255.0 192.168.99.1
Router R1 Gig0/0.99 99 192.168.99.1 255.255.255.0 ———
  1. Remote Access Configuration

    Setting Value
    Protocol SSH v2
    VTY Lines 0 — 4
    Authentication Method Local username and password
    Session Timeout 5 minutes
    Encryption Key RSA 1024 bit
    Domain Name network.local
  2. Access Policy

    Rule Detail
    Permitted Access IT Department only (192.168.30.0/24)
    Access Method SSH from PC-IT via VLAN 30
    Blocked Departments Finance, HR, Customer Support
    Physical Access Console port only
    Password Storage Encrypted via service password-encryption

5. DHCP, Switch and Router Configuration