ATAU
# sh start
# sh run
# sh mac-address-table
# (privileged/enabled/EXEC mode)
#?
help mode
# s?
# show ?
# show version melihat info perangkat (platform, IOS, interfaces)
# sh ver
# sh<tab> ver<tab>
# sh flash
melihat isi dari storage device
# show running-config ATAU #sh run
melihat isi dari config di RAM
# show startup-config ATAU # sh start
melihat isi dari config di NVRAM
# sh clock
# clock set 7:00:00 5 dec 2011 set jam sesuai GMT/UTC (WIB 7 jam)
# configure terminal
ATAU #conf t
(config)# (global config)
(config)# clock timezone WIB 7
(config)# end
# show clock
# conf t
(config)# hostname ASW2-JKT
(config)# enable secret cisco123
utk set password utk masuk privileged mode
(config)# username netadmin password cisco123
(config)# banner motd %
Authorized users only
Please login with your own username & password
All activities are logged
% akan muncul pada saat sukses login
(config)# interface vlan 1
ATAU (config)# int vlan 1
(config-if)# (interface config)
(config-if)# description *** logical interface vlan 1 ***
(config-if)# ip address 10.1.1.20 255.255.255.0
(config-if)# no shutdown
utk mengaktifkan interface
(config-if)# exit
(config)# ip default-gateway 10.1.1.1
router
(config-line)# end
# copy (source) (destination)
# copy running-config startup-config
# write memory
ATAU # wr
ATAU
# sh start
# sh run
# sh mac-address-table
ATAU
# sh start
# sh run
# sh mac-address-table
# sh flash
melihat isi dari storage device
# show running-config ATAU #sh run
melihat isi dari config di RAM
# show startup-config ATAU # sh start
melihat isi dari config di NVRAM
# sh clock
# clock set 7:00:00 5 dec 2011 set jam sesuai GMT/UTC (WIB 7 jam)
# configure terminal
ATAU #conf t
(config)# (global config)
(config)# clock timezone WIB 7
(config)# end
# show clock
# conf t
(config)# hostname ASW-SBY
(config)# enable secret cisco123
utk set password utk masuk privileged mode
(config)# username netadmin password cisco123
(config)# banner motd %
Authorized users only
Please login with your own username & password
All activities are logged
% akan muncul pada saat sukses login
(config)# interface vlan 1
ATAU (config)# int vlan 1
(config-if)# (interface config)
(config-if)# description *** logical interface vlan 1 ***
(config-if)# ip address 10.1.4.10 255.255.255.0
(config-if)# no shutdown
utk mengaktifkan interface
(config-if)# exit
(config)# ip default-gateway 10.1.4.1
router
ATAU
# sh mac-address-table
ATAU
# sh start
# sh run
# sh mac-address-table
Verifikasi:
Dari semua PC ping ke subinterface Router-JKT:
C:> ping 10.1.1.1
C:> ping 10.1.2.1
C:> ping 10.1.3.1
Task 1: Portfast
Switch:
(config)# int range f0/1 - 3
(config-if)# spanning-tree portfast
Task 2: PVST
ASW1-JKT, ASW2-JKT, CSW-JKT:
# sh spanning-tree
[cari siapa yg menjadi Root Bridge]
CSW-JKT (dijadikan Root Bridge):
(config)# spanning-tree vlan 1 priority 0
(config)# spanning-tree vlan 2 priority 0
(config)# spanning-tree vlan 3 priority 0
ATAU
(config)# spanning-tree vlan 1 root primary
(config)# spanning-tree vlan 2 root primary
(config)# spanning-tree vlan 3 root primary
Task 3: PVRST
ASW1-JKT, ASW2-JKT, CSW-JKT:
# sh spanning-tree
# conf t
(config)# spanning-tree mode rapid-pvst
(config)# end
# sh spanning-tree
Router-JKT:
> enable
# clock set 7:00:00 5 dec 2011 jam GMT/UTC (WIB 7)
# conf t
(config)# clock timezone WIB 7
(config)# end
# sh clock
# conf t
(config)# hostname Router-JKT
(config)# enable secret cisco
(config)# username netadmin password cisco123
(config)# line vty 0 4
(config-line)# login local
(config-line)# exec-timeout 5 0
(config-line)# logging synchronous
(config-line)# line console 0
(config-line)# login local
(config-line)# exec-timeout 5 0
(config-line)# logging synchronous
(config-line)# exit
(config-if)# int s0/0/0
(config-if)# desc *** CONNECTED TO S0/0/0 ROUTER-SBY ***
(config-if)# ip address 10.1.0.1 255.255.255.252
(config-if)# clock rate 512000
(config-if)# bandwidth 512
(config-if)# no shutdown
(config-if)# int s0/0/1
(config-if)# desc *** CONNECTED TO S0/0/0 ROUTER-MDN ***
(config-if)# ip address 10.1.0.5 255.255.255.0
(config-if)# bandwidth 512
(config-if)# clock rate 512000
(config-if)# no shutdown
(config-if)# end
ROUTER-SBY:
> enable
# erase start
# reload
Tunggu sampai router selesai booting:
Would you like to enter initial configuration? n
> enable
# clock set 7:00:00 5 dec 2011 jam GMT/UTC (WIB 7)
# conf t
(config)# clock timezone WIB 7
(config)# end
# sh clock
# conf t
(config)# hostname Router-SBY
(config)# enable secret cisco
(config)# username netadmin password cisco123
(config)# line vty 0 4
(config-line)# login local
(config-line)# exec-timeout 5 0
(config-line)# logging synchronous
(config-line)# line console 0
(config-line)# login local
(config-line)# exec-timeout 5 0
(config-line)# logging synchronous
(config-line)# exit
(config)# int f0/0
(config-if)# description *** CONNECT TO LAN SBY ***
(config-if)# ip address 10.1.4.1 255.255.255.0
(config-if)# no shutdown
> enable
# clock set 7:00:00 5 dec 2011 jam GMT/UTC (WIB 7)
# conf t
(config)# clock timezone WIB 7
(config)# end
# sh clock
# conf t
(config)# hostname Router-MDN
(config)# enable secret cisco
(config)# username netadmin password cisco123
(config)# line vty 0 4
(config-line)# login local
(config-line)# exec-timeout 5 0
(config-line)# logging synchronous
(config-line)# line console 0
(config-line)# login local
(config-line)# exec-timeout 5 0
(config-line)# logging synchronous
(config-line)# exit
(config)# int f0/0
(config-if)# description *** CONNECT TO LAN MDN ***
(config-if)# ip address 10.1.5.1 255.255.255.0
(config-if)# no shutdown
s0/0/0
s0/0/1
Router-SBY:
(config)# int loopback 0
(config-if)# description *** as Router-ID for OSPF ***
(config-if)# ip address 10.100.100.2 255.255.255.255
(config-if)# router ospf 1
(config-router)# network 10.1.0.2 0.0.0.0 area 0
(config-router)# network 10.1.4.1 0.0.0.0 area 0
(config-router)# network 10.100.100.2 0.0.0.0 area 0
(config-router)# passive-interface f0/0
(config-router)# end
ALL ROUTERS (SBY, JKT, MDN):
# sh ip ospf
# sh ip ospf interface
# sh ip ospf neighbor melihat neighbor table
# sh ip ospf database melihat topology table
# sh ip route
melihat routing table
# sh ip protocols
melihat semua routing protocol di router
#debug ip ospf events
#debug ip ospf packet
#terminal monitor
#undebug all
# sh access-list
Task 2: Extended ACL utk mengeblok FTP & TFTP dari luar
Router-JKT:
(config)# access-list 100 deny udp any host 10.1.1.3 eq 69 log
(config)# access-list 100 deny tcp any host 10.1.1.3 range 20 21 log
(config)# access-list 100 permit ip any any log
(config)# int s0/0/0
(config-if)# ip access-group 100 in
(config)# int s0/0/1
(config-if)# ip access-group 100 in
(config-if)# end
# sh access-list
# sh ip int s0/0/0
# sh ip int s0/0/1
Menghapus konfigurasi extended ACL:
(config)# int s0/0/0
(config-if)# no ip access-group 100 in
(config-if)# int s0/0/1
(config-if)# no ip access-group 100 in
(config-if)# exit
(config)# no access-list 100
ATAU eq tftp
ATAU range ftp-data ftp
ATAU
ATAU
SBY:
(config)# ipv6 route ::/0 s0/0/0
ATAU
MDN:
(config)# ipv6 route ::/0 s0/0/0
ATAU
# conf t
(config)# hostname Router-SBY
(config)# user Router-JKT password ccna1
(config)# int s0/1
(config-if)# shut
(config-if)# encap ppp
(config-if)# ppp authentication chap
(config-if)# no shut
(config-if)# end
# sh int serial 0/0/0
# sh int serial 0/0/1
FRS configurations:
(config)# frame-relay switching
(config)# int serial 0/0/1
(config-if)# no ip address
(config-if)# description connect to Router-SBY
(config-if)# clock rate 2000000
(config-if)# encapsulation frame-relay
(config-if)# frame-relay intf-type dce
(config-if)# frame-relay route 100 int s0/0/0 101
(config-if)# int serial 0/0/0
(config-if)# no ip address
(config-if)# description connect to Router-JKT
(config-if)# clock rate 2000000
(config-if)# encapsulation frame-relay
(config-if)# frame-relay intf-type dce
(config-if)# frame-relay route 101 int s0/0/1 100
(config-if)# frame-relay route 102 int s0/1/0 200
(config-if)# int serial 0/1/0
(config-if)# no ip address
(config-if)# description connect to Router-MDN
(config-if)# clock rate 2000000
(config-if)# encapsulation frame-relay
(config-if)# frame-relay intf-type dce
(config-if)# frame-relay route 200 int s0/0/0 102
(config-if)# end
# copy run start