Septiembre 2017
Procedimiento de configuración de un Internet Dedicado para un Router TELDAT
Objetivo
El presente documento tiene como finalidad proporcionar una guía para realizar la configuración de
Internet dedicado en un router Teldat.
Contenido
Gerencia de Ingeniería
1.0 13-09-2017 Versión inicial
y Desarrollo Empresas
Configuración Principal
Datos necesarios
Diagrama de Red
INTERNET
WAN:
10.16.185.0/30
Encapsulamiento Dot1q
VLAN ID 1120
CLIENTE
LAN:
186.24.12.232/29
RADIO
CELDA MOVISTAR
RADIO .1 CORE IP/MPLS
.234 .233 CLIENTE
.2
CPE
Procedimiento de Configuración
P4
add device eth-subinterface ethernet0/0 10 Commented [AERI1]: VLAN Interna
network ethernet0/0.10 Commented [AERI2]: VLAN Interna
description "### CONEXION LAN ###"
description "1024 Kbps" Commented [AERI3]: AB Cliente
ip address 186.24.12.233 255.255.255.248 Commented [AERI4]: IP LAN
encapsulation dot1q 10 Commented [AERI5]: VLAN interna
exit
p4
protocol ip
route 0.0.0.0 0.0.0.0 10.16.185.1 Commented [AERI6]: IP WAN del PEC
exit
p4
feature vlan
enable
vlan 1120 ethernet0/0 port 1 Commented [AERI7]: VLAN WAN
vlan 1120 ethernet0/0 port internal Commented [AERI8]: Puerto WAN
vlan 10 ethernet0/0 port 2 Commented [AERI9]: VLAN WAN
vlan 10 ethernet0/0 port internal
Commented [AERI10]: VLAN Interna
tag-default ethernet0/0 port 1 1120
Commented [AERI11]: Puerto LAN
tag-default ethernet0/0 port 2 10
tag-removal ethernet0/0 port 2 Commented [AERI12]: VLAN Interna
exit Commented [AERI13]: Puerto WAN
Commented [AERI14]: Puerto LAN
Commented [AERI15]: Puerto LAN
5. Configurar el Hostname al router
p4
set hostname TRAKI_LIMPIA_3002
Ejemplo:
Usuario: traki
Password: Traki_0159.
p4
user traki password Traki_0159.
P4
network ethernet0/0
repeater-switch
port 1 no autonegotiation
port 1 speed 100Mbps Commented [AERI16]: 100Mbps <= AB cliente 100Mbps sino
port 1 duplex full 1000Mbps
port 2 autonegotiation
exit
exit
network ethernet0/0.1120 Commented [AERI17]: Sub-Interface WAN
description "### CONEXION WAN ###"
description "1024 Kbps" Commented [AERI18]: AB Cliente
exit
P4
banner login "inicio"
banner login
"++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++"
banner login "+ AVISO: ha accedido a un sistema propiedad de TELEFONICA. +"
banner login "+ Necesita tener autorizacin antes de usarlo, estando usted estrictamente +"
banner login "+ limitado al uso indicado en dicha autorizacin. +"
banner login "+ El acceso no autorizado a este sistema o el uso indebido del mismo esta +"
banner login "+ prohibido y es contrario a la Poltica Corporativa de Seguridad y a la +"
banner login "+ legislacin vigente. Si usted revela informacin interna de TELEFONICA o +"
banner login "+ de sus clientes sin previa autorizacin podr estar incurriendo en una +"
banner login "+ violacin de la Normativa Corporativa, que podra incluso suponer la +"
banner login "+ posible comisin de un delito o falta. +"
banner login
"++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++"
banner login " AUTENTICACION MEDIANTE AAA "
banner login " AUTHENTICATION FOR AAA "
banner login " TRAKI – LA LIMPIA " Commented [AERI19]: Según el nombre de ubicación de la
plantilla flotante SIP+
9. Configuración de AAA
p4
protocol snmp
no default-config
community G3sT10NmP15 default
host 200.35.72.227 trap version v2c G3sT10NmP15 all
trap sending-parameters reachability-checking ip-route
exit
feature radius
primary-address 200.35.72.227
primary-secret clientesfr
enable radius
source-interface ethernet0/0.1120 Commented [AERI20]: Sub-Interface WAN
telnet enabled
ssh enabled
p4
feature dns
server 200.35.65.3
server 200.35.65.4
exit
Configuraciones especiales
Configuración NAT
Datos Necesarios
Proceso de configuración
p4
network ethernet0/0.10 Commented [AERI21]: VLAN Interna
ip address 192.168.0.1 255.255.255.0
exit
p4
access-list 100
entry 1 default
entry 1 permit
entry 1 source address 192.168.0.0 255.255.255.0 Commented [AERI22]: Segmento LAN privado del cliente
exit
exit
3. Configurar NAT
protocol ip
nat dynamic
interface ethernet0/0.1120 outside Commented [AERI23]: Sub-Interface WAN
interface ethernet0/0.10 inside Commented [AERI24]: VLAN Interna
pool 1 186.24.12.233 186.24.12.235 Commented [AERI25]: Pool publico
rule 1 inside
rule 1 list 100
rule 1 pool 1
exit
2. Configuración
p4
protocol dhcp
server
enable
shared 1
subnet LAN 1 network 192.168.0.0 255.255.255.0 Commented [AERI26]: Segmento LAN privado del cliente
subnet LAN 1 range 192.168.0.2 192.168.0.254 Commented [AERI27]: Rango de IPs para asignar
subnet LAN 1 dns-server 200.35.65.3
subnet LAN 1 router 192.168.0.1 Commented [AERI28]: Segmento LAN privado del cliente
exit
exit
Plantilla
P4
add device eth-subinterface ethernet0/0 10 Commented [AERI29]: VLAN Interna
network ethernet0/0.10 Commented [AERI30]: VLAN Interna
description "### CONEXION LAN ###"
description "1024 Kbps" Commented [AERI31]: AB Cliente
ip address 186.24.12.233 255.255.255.248 Commented [AERI32]: IP LAN
encapsulation dot1q 10 Commented [AERI33]: VLAN interna
exit
p4
protocol ip
route 0.0.0.0 0.0.0.0 10.16.185.1 Commented [AERI34]: IP WAN del PEC
exit
p4
feature vlan
enable
vlan 1120 ethernet0/0 port 1 Commented [AERI35]: VLAN WAN
vlan 1120 ethernet0/0 port internal Commented [AERI36]: Puerto WAN
vlan 10 ethernet0/0 port 2 Commented [AERI37]: VLAN WAN
vlan 10 ethernet0/0 port internal
Commented [AERI38]: VLAN Interna
tag-default ethernet0/0 port 1 1120
Commented [AERI39]: Puerto LAN
tag-default ethernet0/0 port 2 10
tag-removal ethernet0/0 port 2 Commented [AERI40]: VLAN Interna
exit Commented [AERI41]: Puerto WAN
Commented [AERI42]: Puerto LAN
p4 Commented [AERI43]: Puerto LAN
set hostname TRAKI_LIMPIA_3002
p4
user traki password Traki_0159.
P4
network ethernet0/0
repeater-switch
port 1 no autonegotiation
port 1 speed 100Mbps Commented [AERI44]: 100Mbps <= AB cliente 100Mbps sino
port 1 duplex full 1000Mbps
port 2 autonegotiation
exit
exit
network ethernet0/0.1120 Commented [AERI45]: Sub-Interface WAN
description "### CONEXION WAN ###"
description "1024 Kbps" Commented [AERI46]: AB Cliente
exit
P4
banner login "inicio"
banner login
"++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++"
banner login "+ AVISO: ha accedido a un sistema propiedad de TELEFONICA. +"
banner login "+ Necesita tener autorizacin antes de usarlo, estando usted estrictamente +"
banner login "+ limitado al uso indicado en dicha autorizacin. +"
banner login "+ El acceso no autorizado a este sistema o el uso indebido del mismo esta +"
banner login "+ prohibido y es contrario a la Poltica Corporativa de Seguridad y a la +"
banner login "+ legislacin vigente. Si usted revela informacin interna de TELEFONICA o +"
banner login "+ de sus clientes sin previa autorizacin podr estar incurriendo en una +"
banner login "+ violacin de la Normativa Corporativa, que podra incluso suponer la +"
banner login "+ posible comisin de un delito o falta. +"
banner login
"++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++"
banner login " AUTENTICACION MEDIANTE AAA "
banner login " AUTHENTICATION FOR AAA "
banner login " TRAKI – LA LIMPIA " Commented [AERI47]: Según el nombre de ubicación de la
plantilla flotante SIP+
p4
protocol snmp
no default-config
community G3sT10NmP15 default
host 200.35.72.227 trap version v2c G3sT10NmP15 all
trap sending-parameters reachability-checking ip-route
exit
feature radius
primary-address 200.35.72.227
primary-secret clientesfr
enable radius
source-interface ethernet0/0.1120 Commented [AERI48]: Sub-Interface WAN
telnet enabled
ssh enabled
p4
feature dns
server 200.35.65.3
server 200.35.65.4
exit
p4
network ethernet0/0.10 Commented [AERI49]: VLAN Interna
ip address 192.168.0.1 255.255.255.0
exit
p4
access-list 100
entry 1 default
entry 1 permit
entry 1 source address 192.168.0.0 255.255.255.0 Commented [AERI50]: Segmento LAN privado del cliente
exit
exit
protocol ip
nat dynamic
interface ethernet0/0.1120 outside Commented [AERI51]: Sub-Interface WAN
interface ethernet0/0.10 inside Commented [AERI52]: VLAN Interna
pool 1 186.24.12.233 186.24.12.235 Commented [AERI53]: Pool publico
rule 1 inside
rule 1 list 100
rule 1 pool 1
exit
p4
protocol dhcp
server
enable
shared 1
subnet LAN 1 network 192.168.0.0 255.255.255.0 Commented [AERI54]: Segmento LAN privado del cliente
subnet LAN 1 range 192.168.0.2 192.168.0.254 Commented [AERI55]: Rango de IPs para asignar
subnet LAN 1 dns-server 200.35.65.3
subnet LAN 1 router 192.168.0.1 Commented [AERI56]: Segmento LAN privado del cliente
exit
exit