College Network Scenario
College Network Scenario
College Network Scenario
On
CCNA Certification
SAYLANI MASS IT
TRAINNING PROGRAMME
1. Introduction ............................................................................................................................... 1
2. Objectives................................................................................................................................. 1
3. Network Requirements........................................................................................................... 1
9. Network Design....................................................................................................................... 9
Objectives
The main objective of the proposed network is to update the existing network and also enhance its
capabilities and increase the flexibility of the network which will eventually provide good security.
Network Requirements
1: The new system should be able to reduce internet downtime. Download and upload links should be
maintained above 5 Mbps speed requirement.
2: Network will be scalable.
3: The system should support remote access.
4: Should comprise of data centers with necessary security features and support.
1
Major Design Areas and Functional Areas
The new system planned comprises of IP based switches that remain as the access point to lan-based
(ethernet) as well as Wi-Fi-based connectivity.
These switches provide SNMP support as well so that traffic monitoring becomes
easy. Ip based switches are used mainly because:
The inter VLAN routing feature is supported on both IP base or SMI and IP services or EMI image
Layer 3 switches. For Layer 2-only switches, you require a Layer 3 routing device with any of the
previous images.
-
VLAN Config
The IP Base feature set includes advanced quality of service (QoS), rate limiting, access control lists
(ACLs), and basic static and Routing Information Protocol (RIP) functions. Dynamic IP routing
protocols (Open Shortest Path First (OSPF), BGPv4, Enhanced Interior Gateway Routing Protocol
(EIGRP)) are available only on the IP services image.
The IP Services image provides a richer set of enterprise-class features, which includes advanced
hardware-based IP unicast and IP Multicast routing. Support for IPv6 Layer 3 switching in hardware
is also available with the addition of the Advanced IP Services license to either the IP Base or the IP
Services images. Both the IP base Image and the IP services image allow for Layer 3 and Layer 4
lookups for QoS and security.
2
Existing Infrastructure
The existing system is a very basic system. College mainly comprises of three main sections as
1. TPO & Other
2. Exam Center
3. Office
All the hosts are assigned with static IPs and are assigned in the order in which it where set up.
No support for dynamic IP allocations. Even though the working is divided into three major sectors all the
host, multimedia devices are connected in a single network. Thus, network security and maintenance are
difficult. One more problem observed was the existing switches were outdated and hence could not prove to
be beneficial for the network administrator to observe monitor and handle the network traffic the system has
no remote access to the network. Absence of basic small-scale businesses firewall was also observed. Thus,
security is also compromised. Three server rooms were used for the purpose of independent networking
which further caused wastage of power and money.
The above design is the existing network traced on cisco packet tracer.
3
Network Devices
Developing the existing Lan system:
The basis of the LAN core is Cisco Catalyst 6509 switches equipped with Cisco 720 supervisors and
Virtual Switching System (VSS), as well as Cisco 4500 switches, combined in a stack with the data
transmission ports at 10 Gb/s bandwidth capacity. Switches create a platform for additional services,
such as content processing, firewall (the project uses the Cisco firewall), intrusion prevention system,
application of IPsec security tools, the arrangement of protected VPN channels, network analysis and
acceleration of Secure Sockets Layer (SSL) connections.
Mobility Services Engine (MSE) solution and 300 Cisco Aironet 1140 access points were used.
The Cisco Aironet 1140 Series is a component of the Cisco Unified Wireless Network, which
can scale up to 18,000 access points with full Layer 3 mobility across central or remote locations
on the enterprise campus, in branch offices, and at remote sites.
The Cisco Unified Wireless Network is the industry’s most flexible, resilient, and scalable
architecture, delivering secure access to mobility services and applications and offering the
lowest total cost of ownership and investment protection by integrating seamlessly with the
existing wired network.
4
Cisco Unified Computing System (UCS) solution allowed the integration of computer and network
resources as well as storage and virtualization systems as part of an energy efficiency system. Cisco
Unified Computing System platform notably simplifies traditional architecture and significantly reduces
the number of devices to be purchased, to connect by wires, to supply with electricity and cooling, to
protect and maintain. This solution is the foundation of complex optimization of the virtualized medium
while maintaining the ability to support traditional operating systems and applications stacks in physical
medium. This overall infrastructure developed allowed integration of several functionally different
physical networks into one, such as guest network, hotel management network, telephone network and
IP-Television network. The convergence within single network reduced hotel expenses for constructing
and managing several dedicated networks which traditionally remain separate in hotels.
The term unified computing system is often associated with Cisco. Cisco UCS products have the ability
to support traditional operating system (OS) and application stacks in physical environments, but are
optimized for virtualized environments. Everything is managed through Cisco UCS Manager, a
software application that allows administrators to provision the server, storage and network resources
all at once from a single pane of glass. Similar offerings to Cisco UCS include HP BladeSystem Matrix,
Liquid Computing's LiquidIQ, Sun Modular Datacenter and InteliCloud 360.
5
Request For Proposal
The Cisco
1 System Business 17,999 8 143,992
switches
Total 264,992
6
IPv4 Addressing Plan Using
DHCP
IT DEPARTMENT (192.168.1.0)
IT LAB 1 Dynamically
IT LAB 2 Dynamically
IT LAB 3 Dynamically
IT LAB 4 Dynamically
Printer 0 Dynamically
CS LAB 1 Dynamically
CS LAB 2 Dynamically
CS LAB 3 Dynamically
CS LAB 4 Dynamically
Printer 7 Dynamically
OTHERS (192.168.3.0)
OFFICE Dynamically
Printer 2 Dynamically
Printer 3 Dynamically
ENQUIRY Dynamically
TPO Dynamically
Printer 4 Dynamically
7
SERVER ROOM (1.0.0.0)
FTP SERVER 1.0.0.4 (Statically)
PC1 1.0.0.5 (Statically)
DNS SERVER 1.0.0.2 (Statically)
WEB SERVER 1.0.0.3 (Statically)
PC2 Dynamically
PC3 Dynamically
PC4 Dynamically
PC5 Dynamically
Printer 5 Dynamically
PC 0 Dynamically
LAPTOP 0 Dynamically
Other (192.168.3.0)
8
Routing Protocol Plan
Routing Information Protocol (RIP) is a dynamic routing protocol which uses hop count as
a routing metric to find the best path between the source and the destination network. It is a distance
vector routing protocol which has AD value 120 and works on the application layer of OSI model.
Routing Protocol Plan for Router1 Routing Protocol Plan for Router2
9
Network Design
10
Testing Web Hosting
11
DHCP Configured
Here I secure Server Room by blocking any type of traffic except Web and FTP that is coming from
any network using “Out bound Extended ACL” on Router2.
12
I secure IT depart and principle room from incoming traffic to any network by putting an “Out bound
Standard ACL” on Router0 and Router.
13
Summary
The outcome of the proposed system will be a fail-safe backbone network infrastructure which meets
the requirements for readily available access to information and security of the private network, and
also ensures optimized productivity when telecommunication services are accessed. The installed
equipment allowed to organize high-speed wired and wireless Internet access throughout the whole
complex of hospital buildings as well as providing transfer of all types of data throughout the single
optimized network.
14