Professional Documents
Culture Documents
Palo Alto
Palo Alto
Topology
Workflow
1. Create Eth1/1 as Layer 3 interface & assign the IP -Address 10.2.1.100/24
2. Create eth1/2 as Layer 2 interface & create layer 2 sub-interface (eth1/2.300)
3. Create vlan interface (vlan.300) and assigned Ip -address (10.5.1.100/24)
4. Create eth1/3 as layer 3 interface & create Layer 3 Sub-interface
Eth1/3.100 & eth1/3.200 and assigned them the IP-Address
ROUTER_1 Configuration
ROUTER_1#sh running-config interface gi0/0
interface GigabitEthernet0/0
ip address 10.2.1.10 255.255.255.0
duplex auto
speed auto
media-type rj45
end
ROUTER_1#sh ip route
Gateway of last resort is 10.2.1.100 to network 0.0.0.0
S* 0.0.0.0/0 [1/0] via 10.2.1.100
10.0.0.0/8 is variably subnetted, 2 subnets, 2 masks
C 10.2.1.0/24 is directly connected, GigabitEthernet0/0
L 10.2.1.10/32 is directly connected, GigabitEthernet0/0
ROUTER_2 Configuration
ROUTER_2#sh running-config interface gi0/0
interface GigabitEthernet0/0
ip address 10.3.1.10 255.255.255.0
duplex auto
speed auto
media-type rj45
end
ROUTER_2#sh ip route
Gateway of last resort is 10.3.1.100 to network 0.0.0.0
ROUTER_3 Configuration
ROUTER_3#sh running-config interface gi0/0
interface GigabitEthernet0/0
ip address 10.4.1.10 255.255.255.0
duplex auto
speed auto
media-type rj45
end
ROUTER_3#sh ip route
Gateway of last resort is 10.4.1.100 to network 0.0.0.0
S* 0.0.0.0/0 [1/0] via 10.4.1.100
10.0.0.0/8 is variably subnetted, 2 subnets, 2 masks
C 10.4.1.0/24 is directly connected, GigabitEthernet0/0
L 10.4.1.10/32 is directly connected, GigabitEthernet0/0
ROUTER_4 Configuration
ROUTER_4#sh running-config interface gi0/0
interface GigabitEthernet0/0
ip address 10.5.1.10 255.255.255.0
duplex auto
speed auto
media-type rj45
end
ROUTER_4#sh ip route
Gateway of last resort is 10.5.1.100 to network 0.0.0.0
L2_SWITCH_1 Configuration
L2_SWITCH_1#SH RUNning-config INterface GI0/0
interface GigabitEthernet0/0
switchport trunk encapsulation dot1q
switchport mode trunk
media-type rj45
negotiation auto
end
VIRTUAL ROUTER
CREATE VLAN
NAT POLICY
SECURITY POLICY
VERIFICATION
• First Verify are we getting arp for address 10.5.1.50 on ROUTER_4 Without ARP ROUTER_4
can’t connect to Router_3
ROUTER_4#sh ip arp
Protocol Address Age (min) Hardware Addr Type Interface
Internet 10.5.1.10 - 5000.0007.0000 ARPA GigabitEthernet0/0
Internet 10.5.1.50 0 badb.eefb.ad01 ARPA GigabitEthernet0/0
Internet 10.5.1.100 27 badb.eefb.ad01 ARPA GigabitEthernet0/0
• Ping
ROUTER_4#ping 10.5.1.50
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.5.1.50, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 11/15/19 ms
• Telnet