Hello. Welcome back to ice. Indy one interconnecting Cisco Networking devices are one. This is Module six Lab.
I am trending Daryl and I will be your instructor for this lab. In this video. I'm gonna show you some things that you should have already configured.
And then I'm gonna show you what we need to configure it. I'm just gonna let you go at it in the lab and when you're ready on positive video and we will walk through the lab together.
So our lab diagram. If you don't take a screenshot of this, we have P c one of PC to over any 10 11 slash 24 network plugged into Roger one. We have a serial link between Roger wanted to on the 10 13 slash 29 network.
And PC three is over on the 10 12 slash 24 network.
So if you want to
Cetus just get these all plugged in, we'll get out. The i P addresses set in the last set up.
So the first thing I wanna do is always wanna put a base. Could figure in device username, password enable password, holster. Name, domain name. We want to set all the I P addresses. So you're synchronous your log in local.
But your normal based config on that you want to d'oh
from there, we're gonna enable a writ V two routing. We want no auto summary. We want a passive interface on the land ports.
So once we get to step two once to two is complete, We should be able to ping across the network
from there. We're gonna create a standard A c l 10 that will not allow PC one to reach the 10 12 slash 24 network. So think about where that he's replaced for a standard A CEO
from there, we're gonna create an extended A CEO won 20 that will not allow pc to two s s h two router to Onley.
What about that one for a second here, Think about the most specific for what you need. What is it for? What it s asking and from there gonna create a named a C l for the 10 110 slash 24 network on router one with the name router. One land are one land.
Don't do anything with that yet from there We will have Roger one. Use net overload for the public address of the serial interface. It's a notional public because there's 10 13 network.
It is technically RFC 1918
but for now it's a notional public address.
Um, if your lab network isn't actually hooked up to the Internet, you could use a normal public interest if you wanted to go.
Um, I have a habit of randomly plugging in my lab network into my normal network, so I try not to do that
anyway. So we're gonna have another one who's not overload for that public address on the serial interface using the name day. See how that we created a step five, and from there we're gonna verify that net overload is working. So remember, you have to send some traffic crossed it to enable are not really enabled, but to prove that it's working,
and from there we're gonna test all of the pains, so I'll give you a few seconds going to pause the video, take your screen shots. I think about what you need to dio what you go at it, and when you're ready on positive video, we will walk through this.
All right. So hopefully you got it. Every hope, everything set up. If not, don't worry about it. We're gonna walk through this. So I have my party session up. I removed the,
uh, the Nat Translations from the net overload. Of course. And I'm gonna go ahead, and we should have a base configure on this thing.
So we should be able to Ping because that we have everything set up here.
So it was gonna shoot that one. Okay, we can paint match
All right. So the next time, verify that you were I p addresses are correct. On your machines, I had 10 to 1 to 52.
That's why I was, like, managed. It could ping from the device. And I was like, What the heck?
Anyway, good troubleshooting experience. Uh, anyway, so you can pay across the network. We're going to go there,
So we're gonna go ahead and create that standard a c l 10. That is not going to a PC one to reach the 10 12 network. So from there, remember, it's a standard A C Also want a place near the destination to avoid, uh,
discarding any under or any necessary traffic.
So I'm gonna go ahead and plug in to router to real quick
way are in route or two.
So was going configure terminal. I weigh Just want to do a standard access list,
and we want to do access list. Huh?
We want to
America because it's a standard list. We don't need to do the host parameter,
so we just do 10 11 50.
And we want to too.
Yeah, we don't need a welcome bit, so
we just want to deny that.
And from there we marry. We want to set this on the we're gonna set us on the closest interface towards that device. Little to interface. A phaser zero I p
Ah, 10. And that would be outbound. Should be going out the fastest in the interface going onto the land.
So if I
really candy box now way. Bring up my show. You guys, what I'm doing here.
So do a ping to 10. 111 Okay, we compare outer one.
Do a ping.
This is the serial interface to writer, too.
And let's do a ping to the landside interface of water too.
It was working as well.
there we go. So now we are blocking the packets going into it
so I won't minimize visual box.
All right, so we have a stern access list we have done Step three. We have set up the
position. It is now blocking that.
So now we're gonna create extended A CEO won 20. That is not going to allow PC to two s s h two router to on Lee. So now I'm gonna plug into Roger one because we're the extended we're gonna want to set on the closest edge
to the source.
All right, so we should be in rather one.
I just figured terminal
prices do excess list
1 20 deny dcp. And we're gonna use that host. Prouder since we are just doing with one host
and our destination is going to going to set the router serial interface first.
And I'm actually gonna do the host command with this as well.
And we want this to equal before 22.
So I'm gonna just sit thea perro, and we're gonna d'oh
landside interface for router to
and from there, let's go ahead and put it on interface. If a 00 which is the closest
to the source,
I'd be access group 1 20
and that would be inward.
so now our PC two would not be able to get sssh access onto router to.
So now, honest, if I So now we're gonna create a name, Dae Seo, for the 10 11 slash 24 network on Rather one with the name Roger. One land.
All right, so he's going to get figure terminal
stew. I P access list
I didn't do was create standard list.
You know where we're gonna call it, rather one land,
and that brings us in here. So let's go ahead and permit
the 10 110 match. The 1st 3 activists.
And so now we have number six. Done.
All right, so, no, If sorry, excuse me. Haven't ever find out who's going to number six. We're gonna use Writer one for the net overload for that serial interface using that named a seal.
So let's go into my p nat inside or doing source and adding
and really is the list
for the broader one land list
we want to use the interface because merrily pools for dynamic
your serial series. There's zero
And from there, remember not to do we need to set. The interface is inside and outside, So the interface F A 00
Mrs I. P and Nats Inside
Missile Hang is always will give it a second.
All right, so now what's going to cereal,
which is the outside or inside global side?
Happy nights outside
and show I pee in that translations Nothing. So let me bring up Virgil. Box was Shoot a ping
to 10. 11 10 132
That's not good,
All right, Hopefully, you guys caught that mistake as well.
So let's add a other lines of that extended I p access list because I realized we're matching the 1st 2 packets and then we have that implied deny any statement at the end.
So it was going to excess list 1 20
And I was trying.
There we go.
A man. That's better.
All right. So we don't have translation. Jax were wasn't network, so no, If we do a ping on 32
we should have a translation now.
All right, So, weaken, I'm gonna go ahead and shoot a ping from the other device. Make sure that we are shooting off the same inside global address.
Make sure she's not paying my nights.
You should have to.
Oh, each each ping is a separate thing.
So my brain is out since I forgot about that. That, um
Anyway, so we have Let's go ahead and see what we have left here. So we have verified that net overload is properly working. So what's it gonna bring up the Cali box and we will ping across the network
goes Ping from the very start. 10 111
Theo was paying 10 13 That one.
And if you remember, we should get a packet filtered
for this one.
So should be working otherwise.
So I've been paying that site.
Certain things working. Probably as it is. Um, I will.
I'm gonna have these live commands in the proper four minute here. Essentially. So it should be the least live commands I'll be giving. You guys are gonna be in like, a copy paste for Matt. Um,
now, if you remember. Sometimes I I'm not good with keyboards. And I do fat finger stuff, miss type. So keep an eye out. If you do see said configuration, it's pride. Just a misspelled word. Hopefully, you guys caught those nat translation issues where you gotta have that permit. Any any statement? If you're only trying to deny stuff,
so go ahead and
pays up on the back if you got those.
I hope you guys enjoyed this lab. And if you have any questions, please shoot me. Message. Thank you.