The way of the VLAN
Looking back over the previous config done on the switches you will remember that all switches were part of VLAN 1 (default vlan). If you don’t know this or know where I pulled this information from issue this command:
ASW1#show interfaces status
The output will show interface, the description of the interface, status, VLAN, duplex, speed and the type of connection (all connections by default unless told otherwise belong to the default VLAN iow VLAN 1)
To practice VLANs I am going to change some information from the initial config and add VLANs.
I am a glutton for punishment, I retype and redo all configurations when I am practising for an exam from scratch (I don’t run from saved, I redo). Try it, it’s a pain in the backside and takes longer but it means that you are forced to type the commands one at a time from memory (don’t take a shortcut and use notepad either, type each command, move between interfaces, keep track which interfaces you have completed and which you still have to do). It pays off at the end of the day and helps you logically organize how you configure IRL (In Real Life).
Distribution Switch 1
Step 1: Setup the basics all of the following is CCNA level stuff and should easy if not second nature. This is to get the security and host name down before going onto the interface configuration.
Enter Privileged Mode
switch>enable
Enter Global Configuration Mode
switch#configure terminal
Change the hostname of the switch
switch(config)#hostname DSW1
Enable secret and password
DSW1(config)#enable secret ciscosystems
DSW1(config)#enable password cisco
Setup a local user database
DSW1(config)#username admin@mydomain.com privilege 15 password cisco
Setup the console port password
DSW1(config)#line con 0
DSW1(config-line)#login local
DSW1(config-line)#exit
Setup the Virtual Teletype Terminal (VTY) Password
DSW1(config)#line vty 0 4
DSW1(config-line)#password cisco
DSW1(config-line)#login
DSW1(config-line)#exit
Setup the Auxiliary Password
DSW1(config)#line aux 0
DSW1(config-line)#no exec
DSW1(config-line)#exit
Step 2: Setup the management interface
Setup the default VLAN ip address from remote ip admin if there was a GUI and to Telnet to the switch
DSW1(config)#interface vlan 1
DSW1(config-if)#ip address 192.168.1.1 255.255.255.0
NB I am shutting the interface
DSW1(config-if)#shut
DSW1(config-if)#exit
Step 3: Setup other interfaces
Setup Fastethernet Interfaces
DSW1(config)#interface fastethernet 0/1
DSW1(config-if)#description DSW1 - ASW1
DSW1(config-if)#speed 100
DSW1(config-if)#duplex auto
DSW1(config-if)#no shut
DSW1(config-if)#exit
DSW1(config)#interface fastethernet 0/2
DSW1(config-if)#description DSW1 - ASW1
DSW1(config-if)#speed 100
DSW1(config-if)#duplex auto
DSW1(config-if)#no shut
DSW1(config-if)#exit
DSW1(config)#interface fastethernet 0/3
DSW1(config-if)#description DSW1 - ASW2
DSW1(config-if)#speed 100
DSW1(config-if)#duplex auto
DSW1(config-if)#no shut
DSW1(config-if)#exit
DSW1(config)#interface fastethernet 0/4
DSW1(config-if)#description DSW1 - ASW2
DSW1(config-if)#speed 100
DSW1(config-if)#duplex auto
DSW1(config-if)#no shut
DSW1(config-if)#exit
DSW1(config)#interface fastethernet 0/11
DSW1(config-if)#description DSW1 - DSW2
DSW1(config-if)#speed 100
DSW1(config-if)#duplex auto
DSW1(config-if)#no shut
DSW1(config-if)#exit
DSW1(config)#interface fastethernet 0/12
DSW1(config-if)#description DSW1 - DSW2
DSW1(config-if)#speed 100
DSW1(config-if)#duplex auto
DSW1(config-if)#no shut
DSW1(config-if)#exit
Alternatively use range command
Setup Fastethernet Interfaces
DSW1(config)#interface fastethernet 0/1
DSW1(config-if)#description DSW1 - ASW1
DSW1(config-if)#exit
DSW1(config)#interface fastethernet 0/2
DSW1(config-if)#description DSW1 - ASW1
DSW1(config-if)#exit
DSW1(config)#interface fastethernet 0/3
DSW1(config-if)#description DSW1 - ASW2
DSW1(config-if)#exit
DSW1(config)#interface fastethernet 0/4
DSW1(config-if)#description DSW1 - ASW2
DSW1(config-if)#exit
DSW1(config)#interface range fastethernet 0/1 - 4
DSW1(config-if-range)#speed 100
DSW1(config-if-range)#duplex auto
DSW1(config-if-range)#no shut
DSW1(config-if-range)#exit
DSW1(config)#interface fastethernet 0/11
DSW1(config-if)#description DSW1 - DSW2
DSW1(config-if)#exit
DSW1(config)#interface fastethernet 0/12
DSW1(config-if)#description DSW1 - DSW2
DSW1(config-if)#exit
DSW1(config)#interface range fastethernet 0/11 - 12
DSW1(config-if-range)#speed 100
DSW1(config-if-range)#duplex auto
DSW1(config-if-range)#no shut
DSW1(config-if-range)#exit
Step 4: Associate a VLAN with the Interfaces
Create and Associate VLAN 100 with Fe 1 to 4
DSW1(config)#interface range fastethernet 0/1 - 4
DSW1(config-if-range)#switchport
DSW1(config-if-range)#switchport mode access
DSW1(config-if-range)#switchport access vlan 100
%Access VLAN does not exist. Creating vlan 100
DSW1(config-if-range)#exit
Associate VLAN 100 with Fe 11 and 12
DSW1(config)#interface range fastethernet 0/11 - 12
DSW1(config-if-range)#switchport
DSW1(config-if-range)#switchport mode access
DSW1(config-if-range)#switchport access vlan 100
DSW1(config-if-range)#exit
Step 5: Assign an ip address to the new VLAN to ping
Setup the VLAN ip address
DSW1(config)#interface vlan 100
DSW1(config-if)#ip address 192.168.100.1 255.255.255.0
DSW1(config-if)#no shut
DSW1(config-if)#exit
Step 6: Shut down non-used interfaces
Administratively shut down all ports not connected
DSW1(config)#interface range fastethernet 0/5 - 10
DSW1(config-if-range)#shut
DSW1(config-if-range)#exit
Exit Global Configuration Mode
DSW1(config)#exit
Step 7: Check your work
Check that you named the interfaces correctly, havent missed out on a connected interface and that the duplex and speed setting are correct
DSW1#show interfaces status
show the vlans that are configured
DSW1#show vlan
show switchport you can change the fastethernet 0/4 for any active port for information
DSW1#show interface fasthethernet 0/4 switchport
show run the running configuration
DSW1#show run
Step 8: Save your work
Copy the running configuration to the startup configuration. I got in the bad habbit to do this the other way around for a while (did it in an exam)... oops copy start run
DSW1#copy run start
Distribution Switch 2
Step 1: Setup the basics all of the following is CCNA level stuff and should easy if not second nature. This is to get the security and host name down before going onto the interface configuration.
Enter Privileged Mode
switch>enable
Enter Global Configuration Mode
switch#configure terminal
Change the hostname of the switch
switch(config)#hostname DSW2
Enable secret and password
DSW2(config)#enable secret cisco
DSW2(config)#enable password cisco
Setup a local user database
DSW2(config)#username admin@mydomain.com privilege 15 password cisco
Setup the console port password
DSW2(config)#line con 0
DSW2(config-line)#login local
DSW2(config-line)#exit
Setup the Virtual Teletype Terminal (VTY) Password
DSW2(config)#line vty 0 4
DSW2(config-line)#password cisco
DSW2(config-line)#login
DSW2(config-line)#exit
Setup the Auxiliary Password
DSW2(config)#line aux 0
DSW2(config-line)#no exec
DSW2(config-line)#exit
Step 2: Setup the management interface
Setup the default VLAN ip address from remote ip admin if there was a GUI and to Telnet to the switch
DSW2(config)#interface vlan 1
DSW2(config-if)#ip address 192.168.1.50 255.255.255.0
NB I am shutting the interface
DSW2(config-if)#shut
DSW2(config-if)#exit
Step 3: Setup other interfaces
Setup Fastethernet Interfaces
DSW2(config)#interface fastethernet 0/1
DSW2(config-if)#description DSW2 - ASW2
DSW2(config-if)#speed 100
DSW2(config-if)#duplex auto
DSW2(config-if)#no shut
DSW2(config-if)#exit
DSW2(config)#interface fastethernet 0/2
DSW2(config-if)#description DSW2 - ASW2
DSW2(config-if)#speed 100
DSW2(config-if)#duplex auto
DSW2(config-if)#no shut
DSW2(config-if)#exit
DSW2(config)#interface fastethernet 0/3
DSW2(config-if)#description DSW2 - ASW1
DSW2(config-if)#speed 100
DSW2(config-if)#duplex auto
DSW2(config-if)#no shut
DSW2(config-if)#exit
DSW2(config)#interface fastethernet 0/4
DSW2(config-if)#description DSW2 - ASW1
DSW2(config-if)#speed 100
DSW2(config-if)#duplex auto
DSW2(config-if)#no shut
DSW2(config-if)#exit
DSW2(config)#interface fastethernet 0/11
DSW2(config-if)#description DSW2 - DSW1
DSW2(config-if)#speed 100
DSW2(config-if)#duplex auto
DSW2(config-if)#no shut
DSW2(config-if)#exit
DSW2(config)#interface fastethernet 0/12
DSW2(config-if)#description DSW2 - DSW1
DSW2(config-if)#speed 100
DSW2(config-if)#duplex auto
DSW2(config-if)#no shut
DSW2(config-if)#exit
Alternatively use range command
Setup Fastethernet Interfaces
DSW2(config)#interface fastethernet 0/1
DSW2(config-if)#description DSW1 - ASW1
DSW2(config-if)#exit
DSW2(config)#interface fastethernet 0/2
DSW2(config-if)#description DSW1 - ASW1
DSW2(config-if)#exit
DSW2(config)#interface fastethernet 0/3
DSW2(config-if)#description DSW1 - ASW2
DSW2(config-if)#exit
DSW2(config)#interface fastethernet 0/4
DSW2(config-if)#description DSW1 - ASW2
DSW2(config-if)#exit
DSW2(config)#interface range fastethernet 0/1 - 4
DSW2(config-if-range)#speed 100
DSW2(config-if-range)#duplex auto
DSW2(config-if-range)#no shut
DSW2(config-if-range)#exit
DSW2(config)#interface fastethernet 0/11
DSW2(config-if)#description DSW1 - DSW2
DSW2(config-if)#exit
DSW2(config)#interface fastethernet 0/12
DSW2(config-if)#description DSW1 - DSW2
DSW2(config-if)#exit
DSW2(config)#interface range fastethernet 0/11 - 12
DSW2(config-if-range)#speed 100
DSW2(config-if-range)#duplex auto
DSW2(config-if-range)#no shut
DSW2(config-if-range)#exit
Step 4: Associate a VLAN with the Interfaces
Create and Associate VLAN 100 with Fe 1 to 4
DSW2(config)#interface range fastethernet 0/1 - 4
DSW2(config-if-range)#switchport
DSW2(config-if-range)#switchport mode access
DSW2(config-if-range)#switchport access vlan 100
%Access VLAN does not exist. Creating vlan 100
DSW2(config-if-range)#exit
Associate VLAN 100 with Fe 11 and 12
DSW2(config)#interface range fastethernet 0/11 - 12
DSW2(config-if-range)#switchport
DSW2(config-if-range)#switchport mode access
DSW2(config-if-range)#switchport access vlan 100
DSW2(config-if-range)#exit
Step 5: Assign an ip address to the new VLAN to ping
Setup the VLAN ip address
DSW2(config)#interface vlan 100
DSW2(config-if)#ip address 192.168.100.50 255.255.255.0
DSW2(config-if)#no shut
DSW2(config-if)#exit
Step 6: Shut down non-used interfaces
Aministratively shutdown all ports not connected
DSW2(config)#interface range fastethernet 0/5 - 10
DSW2(config-if-range)#shut
DSW2(config-if-range)#exit
Exit Global Configuration Mode
DSW2(config)#exit
Step 7: Check your work
Check that you named the interfaces correctly, havent missed out on a connected interface and that the duplex and speed setting are correct
DSW2#show interfaces status
show the vlans that are configured
DSW2#show vlan
show switchport you can change the fastethernet 0/4 for any active port for information
DSW2#show interface fasthethernet 0/4 switchport
show run the running configuration
DSW2#show run
Step 8: Save your work
Copy the running configuration to the startup configuration. I got in the bad habbit to do this the other way around for a while (did it in an exam)... oops copy start run
DSW2#copy run start
Access Switch 1
Step 1: Setup the basics all of the following is CCNA level stuff and should easy if not second nature. This is to get the security and host name down before going onto the interface configuration.
Enter Privileged Mode
switch>enable
Enter Global Configuration Mode
switch#configure terminal
Change the hostname of the switch
switch(config)#hostname ASW1
Enable secret and password
ASW1(config)#enable secret cisco
ASW1(config)#enable password cisco
Setup a local user database
ASW1(config)#username admin@mydomain.com privilege 15 password cisco
Setup the console port password
ASW1(config)#line con 0
ASW1(config-line)#login local
ASW1(config-line)#exit
Setup the Virtual Teletype Terminal (VTY) Password
ASW1(config)#line vty 0 4
ASW1(config-line)#password cisco
ASW1(config-line)#login
ASW1(config-line)#exit
Setup the Auxiliary Password
ASW1(config)#line aux 0
ASW1(config-line)#no exec
ASW1(config-line)#exit
Step 2: Setup the management interface
Setup the default VLAN ip address from remote ip admin if there was a GUI and to Telnet to the switch
ASW1(config)#interface vlan 1
ASW1(config-if)#ip address 192.168.1.100 255.255.255.0
NB I am shutting the interface
ASW1(config-if)#shut
ASW1(config-if)#exit
Step 3: Assign an ip address to the new VLAN to ping
Create VLAN 100 and Configure Interface
ASW1(config)#vlan 100 name Marketing
ASW1(config)#interface vlan 100
ASW1(config-if)#ip address 192.168.100.100 255.255.255.0
ASW1(config-if)#no shut
ASW1(config-if)#exit
Step 4: Setup other interfaces
Setup Fastethernet Interfaces
ASW1(config)#interface fastethernet 0/1
ASW1(config-if)#description ASW1 - DSW1
ASW1(config-if)#speed 100
ASW1(config-if)#duplex auto
ASW1(config-if)#no shut
ASW1(config-if)#exit
ASW1(config)#interface fastethernet 0/2
ASW1(config-if)#description ASW1 - DSW1
ASW1(config-if)#speed 100
ASW1(config-if)#duplex auto
ASW1(config-if)#no shut
ASW1(config-if)#exit
ASW1(config)#interface fastethernet 0/3
ASW1(config-if)#description ASW1 - DSW2
ASW1(config-if)#speed 100
ASW1(config-if)#duplex auto
ASW1(config-if)#no shut
ASW1(config-if)#exit
ASW1(config)#interface fastethernet 0/4
ASW1(config-if)#description ASW1 - DSW2
ASW1(config-if)#speed 100
ASW1(config-if)#duplex auto
ASW1(config-if)#no shut
ASW1(config-if)#exit
Alternatively use the range command
Setup Fastethernet Interfaces
ASW1(config)#interface fastethernet 0/1
ASW1(config-if)#description DSW1 - ASW1
ASW1(config-if)#exit
ASW1(config)#interface fastethernet 0/2
ASW1(config-if)#description DSW1 - ASW1
ASW1(config-if)#exit
ASW1(config)#interface fastethernet 0/3
ASW1(config-if)#description DSW1 - ASW2
ASW1(config-if)#exit
ASW1(config)#interface fastethernet 0/4
ASW1(config-if)#description DSW1 - ASW2
ASW1(config-if)#exit
ASW1(config)#interface range fastethernet 0/1 - 4
ASW1(config-if-range)#speed 100
ASW1(config-if-range)#duplex auto
ASW1(config-if-range)#no shut
ASW1(config-if-range)#exit
Step 5: This is where the ASW and the DSW switches differ. This connects to the Workstation end-point where the DSW switches use port 11/12 to provide failover for the distribution
Setup Fastethernet 0/12 for 10mbs half duplex as an access level end-point interface
ASW1(config)#interface fastethernet 0/12
ASW1(config-if)#description ASW1 - PC1
ASW1(config-if)#speed 10
ASW1(config-if)#duplex half
ASW1(config-if)#switchport
Make the port as an access port
ASW1(config-if)#switchport mode access
Make the port an access port for VLAN 100
ASW1(config-if)#switchport access vlan 100
ASW1(config-if)#no shut
ASW1(config-if)#exit
Step 6: Associate a VLAN with the Interfaces
Associate VLAN 100 with Fe 1 to 4
ASW1(config)#interface range fastethernet 0/1 - 4
ASW1(config-if-range)#switchport
ASW1(config-if-range)#switchport mode access
ASW1(config-if-range)#switchport access vlan 100
ASW1(config-if-range)#exit
Step 7: Shut down non-used interfaces
Administratively shut down all ports not connected
ASW1(config)#interface range fastethernet 0/5 - 11
ASW1(config-if-range)#shut
ASW1(config-if-range)#exit
Exit Global Configuration Mode
ASW1(config)#exit
Step 8: Check your work
Check that you named the interfaces correctly, havent missed out on a connected interface and that the duplex and speed setting are correct
ASW1#show interfaces status
show the vlans that are configured
ASW1#show vlan
show switchport you can change the fastethernet 0/4 for any active port for information
ASW1#show interface fasthethernet 0/4 switchport
show run the running configuration
ASW1#show run
Step 9: Save your work
Copy the running configuration to the startup configuration. I got in the bad habit to do this the other way around for a while (did it in an exam)... oops copy start run
ASW1#copy run start
Access Switch 2
Step 1: Setup the basics all of the following is CCNA level stuff and should easy if not second nature. This is to get the security and host name down before going onto the interface configuration.
Enter Privileged Mode
switch>enable
Enter Global Configuration Mode
switch#configure terminal
Change the hostname of the switch
switch(config)#hostname ASW2
Enable secret and password
ASW2(config)#enable secret cisco
ASW2(config)#enable password cisco
Setup a local user database
ASW2(config)#username admin@mydomain.com privilege 15 password cisco
Setup the console port password
Setup the console port password
ASW2(config)#line con 0
ASW2(config-line)#login local
ASW2(config-line)#exit
Setup the Auxiliary Password
ASW2(config)#line aux 0
ASW2(config-line)#no exec
ASW2(config-line)#exit
Setup the Virtual Teletype Terminal (VTY) Password
ASW2(config)#line vty 0 4
ASW2(config-line)#password cisco
ASW2(config-line)#login
ASW2(config-line)#exit
Step 2: Setup the management interface
Setup the default VLAN ip address from remote ip admin if there was a GUI and to Telnet to the switch
ASW2(config)#interface vlan 1
ASW2(config-if)#ip address 192.168.1.200 255.255.255.0
NB I am shutting the interface
ASW2(config-if)#shut
ASW2(config-if)#exit
Step 3: Assign an ip address to the new VLAN to ping
Create VLAN 100 and Configure Interface
ASW2(config)#vlan 100 name Marketing
ASW2(config)#interface vlan 100
ASW2(config-if)#ip address 192.168.100.200 255.255.255.0
ASW2(config-if)#no shut
ASW2(config-if)#exit
Step 4: Setup other interfaces
Setup Fastethernet Interfaces
ASW2(config)#interface fastethernet 0/1
ASW2(config-if)#description ASW2 - DSW2
ASW2(config-if)#speed 100
ASW2(config-if)#duplex auto
ASW2(config-if)#no shut
ASW2(config-if)#exit
ASW2(config)#interface fastethernet 0/2
ASW2(config-if)#description ASW2 - DSW2
ASW2(config-if)#speed 100
ASW2(config-if)#duplex auto
ASW2(config-if)#no shut
ASW2(config-if)#exit
ASW2(config)#interface fastethernet 0/3
ASW2(config-if)#description ASW2 - DSW1
ASW2(config-if)#speed 100
ASW2(config-if)#duplex auto
ASW2(config-if)#no shut
ASW2(config-if)#exit
ASW2(config)#interface fastethernet 0/4
ASW2(config-if)#description ASW2 - DSW1
ASW2(config-if)#speed 100
ASW2(config-if)#duplex auto
ASW2(config-if)#no shut
ASW2(config-if)#exit
Alternatively use the range command
Setup Fastethernet Interfaces
ASW2(config)#interface fastethernet 0/1
ASW2(config-if)#description DSW1 - ASW1
ASW2(config-if)#exit
ASW2(config)#interface fastethernet 0/2
ASW2(config-if)#description DSW1 - ASW1
ASW2(config-if)#exit
ASW2(config)#interface fastethernet 0/3
ASW2(config-if)#description DSW1 - ASW2
ASW2(config-if)#exit
ASW2(config)#interface fastethernet 0/4
ASW2(config-if)#description DSW1 - ASW2
ASW2(config-if)#exit
ASW2(config)#interface range fastethernet 0/1 - 4
ASW2(config-if-range)#speed 100
ASW2(config-if-range)#duplex auto
ASW2(config-if-range)#no shut
ASW2(config-if-range)#exit
Step 5: This is where the ASW and the DSW switches differ. This connects to the Workstation end-point where the DSW switches use port 11/12 to provide failover for the distribution
Setup Fastethernet 0/12 for 10mbs half duplex as an access level end-point interface
ASW2(config)#interface fastethernet 0/12
ASW2(config-if)#description ASW2 - PC2
ASW2(config-if)#speed 10
ASW2(config-if)#duplex half
ASW1(config-if)#switchport
Make the port as an access port
ASW2(config-if)#switchport mode access
Make the port an access port for VLAN 100
ASW2(config-if)#switchport access vlan 100
ASW2(config-if)#no shut
ASW2(config-if)#exit
Step 6: Associate a VLAN with the Interfaces
Associate VLAN 100 with Fe 1 to 4
ASW2(config)#interface range fastethernet 0/1 - 4
ASW1(config-if-range)#switchport
ASW1(config-if-range)#switchport mode access
ASW2(config-if-range)#switchport access vlan 100
ASW2(config-if-range)#exit
Step 7: Shut down non-used interfaces
Administratively shut down all ports not connected
ASW2(config)#interface range fastethernet 0/5 - 11
ASW2(config-if-range)#shut
ASW2(config-if-range)#exit
Exit Global Configuration Mode
ASW2(config)#exit
Step 5: Check your work
Check that you named the interfaces correctly, havent missed out on a connected interface and that the duplex and speed setting are correct
ASW2#show interfaces status
show the vlans that are configured
ASW2#show vlan
show switchport you can change the fastethernet 0/4 for any active port for information
ASW2#show interface fasthethernet 0/4 switchport
show run the running configuration
ASW2#show run
Step 6: Save your work
Copy the running configuration to the startup configuration. I got in the bad habit to do this the other way around for a while (did it in an exam)... oops copy start run
ASW2#copy run start
This lab is pretty much exactly the same as the previous lab except for the small changes to VLAN 1 and the addition of VLAN 100. Other noteworthy changes would be the use of switchport access commands.
The object would be to be able to ping the various VLAN 100 interface ip addresses. There may be certain restrictions to what you can ping but as long as directly connected switches can ping the VLAN 100 interfaces you have VLAN 100 up and running.
Post Scriptum
I am going to assume* that if one telnets into a switch/router using the vlan 1 then go onto shut vlan 1 the session will be dropped (it will make sense if that were to happen). So I am going to assume you would have to use the Console connection to do this.
One can automate to an extent the speed and duplex commands with the interface range command for this lab, I just need to get into the habit of adding a description to my interfaces (don’t do that because I know what the interface are and do when setting it up, troubleshooting 6 months later I have found it to be another matter).
Also you can use the following to shorten what you have to type every time :-
ASW2(config)#define interface range OnetoFour fe 0/1, fe 0/2, fe 0/3, fe 0/4
ASW2(config)#interface range macro OnetoFour
*The say assumption is the mother of all f-ups. Until I have arranged lab time I am going to go on my assumptions because I want to test and see if this is the case.
Notes and Notices:
This is a part of my personal BCMSN notes and research to assist myself in learning and understanding the concepts and theory for the BCMSN exam. I learn by making notes reading and writing things down and wish to file them where I can’t lose them. These notes are not to be seen, judged or mistaken for replacements to Cisco recognized and authorized training which I personally support and attend and suggest you undertake if you are going for the BCMSN Certification.
