Está en la página 1de 6

Configuración básica (Todos)

enable
configure terminal
no ip domain-lo
enable secret cisco
service password-encryption
line console 0
password cisco
login
exit
line vty 0 2
password cisco
login
exit

Configuración Vlans (Switch Principal)


vlan 2
name alumnos
exit
vlan 3
name docentes
exit
vlan 4
name administrativos
exit
vlan 99
name nativa
exit
Configuración de Troncales (Switch
Principal)
int range f0/2-f0/4
switch trunk encap dot1q
switch mode trunk
exit
int range f0/6-24, g0/1-2
shutdown
exit

Configurar VTP modo Servidor (Switch


Principal)
vtp mode server
vtp domain utng.edu.mx
vtp pass cisco

Configuración de Troncales(Switches)
enable
configure terminal
int f0/1
switch mode trunk
exit

Configurar VTP modo Cliente (Switches)


vtp mode client
vtp domain utng.edu.mx
vtp pass cisco

Configurar Interfaces para acceso VTP


(Switches)
en las Vlans correspondientes
int range f0/2-10
switch mode access
switch access vlan 2
exit
int range f0/11-16
switch mode access
switch access vlan 3
exit
int range f0/17-24
switch mode access
switch access vlan 4
exit

Apagar las interfaces que no se requieren


(Switches)
int range g0/1-2
shutdown
exit

Configuración del SSH (Switch Principal)


Todos
ip domain-name utng.edu.mx
crypto key generate rsa general-keys modulus 2048
username Admin secret cisco
ip ssh version 2
line vty 0 2
transport input ssh
login local

Definir la dirección IP a la Vlan Nativa


(Switch Principal) todos

int vlan 99
ip add 172.16.32.4 255.255.248.0
exit

Verificar que funciona


ssh -l Admin 172.16.32.2

Seguridad en los puertos (Switches)


int range f0/2-24
switchport mode access
switchport port-security
switchport port-security maximum 2
switchport port-security mac-address sticky
switchport port-security violation shutdown
int range f0/11-24
switchport mode access
switchport port-security
switchport port-security maximum 2
switchport port-security mac-address sticky
switchport port-security violation shutdown
int range f0/15-24
switchport mode access
switchport port-security
switchport port-security maximum 2
switchport port-security mac-address sticky
switchport port-security violation shutdown

por separado en cada interfaz


switchport port-security mac-address

Seguridad en las vlans


Switches
int f0/1
switchport nonegotiate
switchport trunk native vlan 99

Switch Principal
int range f0/1-4
switchport nonegotiate
switchport trunk native vlan 99

Seguridad en el ARP y DHCP (Switches)


DHCP
ip dhcp snooping
int f0/1
ip dhcp snooping trust
int range f0/2-24
ip dhcp snooping limit rate 6
exit
ip dhcp snooping vlan 2-4

ARP
ip arp inspection vlan 2-4
int f0/1
ip arp inspection trust
exit

Seguridad en el BPDU (Switches)


int range f0/2-24
spanning-tree portfast
spanning-tree bpduguard enable

apagar las interfaces que no usen....

También podría gustarte