Tujuan Lab
- Seluruh client bisa saling berkomunikasi dan mengakses Core Server serta Backup server
- Seluruh IP-Phone bisa saling menelphone
- Server mempunyai link yang bagus dengan etherchannel
- Seluruh router mengaktifkan telnet dengan user dari AAA Server
- DNS, Web, dan AAA Server
- Etherchannel (PAGP & LACP)
- Frame Relay
- EIGRP Under Frame Relay
- IP Phone
- VLAN & Trunking
- Virtual Trunking Protocl (VTP)
- Per VLAN Spanning Tree (PVST)
Konfigurasi Lab
File superlab bisa didownload
disini
Pertama kita konfigurasi di bagian IDN-R1
|
Gambar 1 Topologi Bagian IDN-R1 |
Berikut konfigurasi etherchannel di IDN-MLS1 dan IDN-MLS2
IDN-MLS1(config)#vlan 100
IDN-MLS1(config-vlan)#exit
IDN-MLS1(config)#interface fa0/4
IDN-MLS1(config-if)#switchport trunk encapsulation dot1q
IDN-MLS1(config-if)#switchport mode trunk
IDN-MLS1(config-if)#exit
IDN-MLS1(config)#interface range fa0/1-3
IDN-MLS1(config-if-range)#switchport trunk encapsulation dot1q
IDN-MLS1(config-if-range)#switchport mode trunk
IDN-MLS1(config-if-range)#channel-group 1 mode desirable
IDN-MLS2(config)#interface range fa0/1-3
IDN-MLS2(config-if-range)#switchport trunk encapsulation dot1q
IDN-MLS2(config-if-range)#switchport mode trunk
IDN-MLS2(config-if-range)#channel-group 1 mode auto
IDN-MLS2(config-if-range)#exit
IDN-MLS2(config)#interface range fa0/4-6
IDN-MLS2(config-if-range)#switchport mode access
IDN-MLS2(config-if-range)#switchport access vlan 100
% Access VLAN does not exist. Creating vlan 100
Untuk verifikas kita coba lihat status etherchannel di IDN-MLS2
IDN-MLS2#show etherchannel summary
Flags: D - down P - in port-channel
I - stand-alone s - suspended
H - Hot-standby (LACP only)
R - Layer3 S - Layer2
U - in use f - failed to allocate aggregator
u - unsuitable for bundling
w - waiting to be aggregated
d - default port
Number of channel-groups in use: 1
Number of aggregators: 1
Group Port-channel Protocol Ports
------+-------------+-----------+----------------------------------------------
1 Po1(SU) PAgP Fa0/1(P) Fa0/2(P) Fa0/3(P)
Perhatikan bahwa status etherchannel di IDN-MLS2 sudah in use. Oke lanjut kita konfigurasi intervlan routing di IDN-R1
IDN-R1(config)#interface fa0/0
IDN-R1(config-if)#no shutdown
IDN-R1(config-if)#interface fa0/0.100
IDN-R1(config-subif)#encapsulation dot1q 100
IDN-R1(config-subif)#ip address 100.100.100.254 255.255.255.0
Sekarang kita konfigurasikan ip address di semua server kemudian lakukan pengujian ping ke IDN-R1
|
Gambar 2 Konfigurasi ip address IDN-SRV1 |
|
Gambar 3 Verifikasi ping dari server ke IDN-R1 |
Oke kita sudah berhasil konfigurasi di IDN-R1. Lanjut kita konfigurasi di bagian IDN-R2
|
Gambar 4 Topologi bagian IDN-R2 |
Berikut konfigurasi pada IDN-SW1
IDN-SW1(config)#vlan 101
IDN-SW1(config-vlan)#exit
IDN-SW1(config)#interface fa0/4
IDN-SW1(config-if)#switchport mode trunk
IDN-SW1(config-if)#interface range fa0/1-3
IDN-SW1(config-if-range)#switchport mode trunk
IDN-SW1(config-if-range)#channel-group 1 mode active
IDN-SW1(config-if-range)#interface range fa0/5-6
IDN-SW1(config-if-range)#switchport voice vlan 20
IDN-SW1(config-if-range)#switchport access vlan 21
% Access VLAN does not exist. Creating vlan 21
IDN-SW2(config)#interface range fa0/1-3
IDN-SW2(config-if-range)#switchport mode trunk
IDN-SW2(config-if-range)#channel-group 1 mode passive
IDN-SW2(config-if-range)#interface fa0/4
IDN-SW2(config-if)#switchport access vlan 101
% Access VLAN does not exist. Creating vlan 101
IDN-SW2(config-if)#interface range fa0/5-6
IDN-SW2(config-if-range)#switchport voice vlan 20
IDN-SW2(config-if-range)#switchport access vlan 21
% Access VLAN does not exist. Creating vlan 21
Lanjut kita konfigurasi di IDN-R2
IDN-R2(config)#interface fa0/0
IDN-R2(config-if)#no shutdown
IDN-R2(config-if)#interface fa0/0.20
IDN-R2(config-subif)#encapsulation dot1q 20
IDN-R2(config-subif)#ip address 20.20.20.254 255.255.255.0
IDN-R2(config-subif)#interface fa0/0.21
IDN-R2(config-subif)#encapsulation dot1q 21
IDN-R2(config-subif)#ip address 21.21.21.254 255.255.255.0
IDN-R2(config-subif)#interface fa0/0.101
IDN-R2(config-subif)#encapsulation dot1q 101
IDN-R2(config-subif)#ip address 101.101.101.254 255.255.255.0
IDN-R2(config-subif)#ip dhcp pool vlan20
IDN-R2(dhcp-config)#network 20.20.20.0 255.255.255.0
IDN-R2(dhcp-config)#default-router 20.20.20.254
IDN-R2(dhcp-config)#option 150 ip 20.20.20.254
IDN-R2(dhcp-config)#ip dhcp pool vlan21
IDN-R2(dhcp-config)#network 21.21.21.0 255.255.255.0
IDN-R2(dhcp-config)#default-router 21.21.21.254
IDN-R2(dhcp-config)#dns-server 100.100.100.1
IDN-R2(dhcp-config)#exit
IDN-R2(config)#telephony-service
IDN-R2(config-telephony)#max-dn 4
IDN-R2(config-telephony)#max-ephone 4
IDN-R2(config-telephony)#ip source-address 20.20.20.254 port 2000
IDN-R2(config-telephony)#auto assign 1 to 4
IDN-R2(config-telephony)#exit
IDN-R2(config)#ephone-dn 1
IDN-R2(config-ephone-dn)#number 1111
IDN-R2(config-ephone-dn)#ephone-dn 2
IDN-R2(config-ephone-dn)#number 1112
IDN-R2(config-ephone-dn)#ephone-dn 3
IDN-R2(config-ephone-dn)#number 1113
IDN-R2(config-ephone-dn)#ephone-dn 4
IDN-R2(config-ephone-dn)#number 1114
Untuk verifikasi kita coba konfigurasi ip address di IDN-SRV4 dan coba lakukan ping ke IDN-R2
|
Gambar 5 Konfigurasi ip address di IDN-SRV4 |
|
Gambar 6 Verifikasi ping dari IDN-SRV4 ke IDN-R2 |
Selanjutnya nyalakan seluruh IP Phone dan konfigurasikan dhcp client di seluruh PC
|
Gambar 7 Menyalakan IDN-Phone1 |
|
Gambar 8 Konfigurasi dhcp client |
Coba lakukan telphone dari IDN-Phone1 ke IDN-Phone2
|
Gambar 9 Verifikas telphone antar IP Phone |
Oke kita sudah selesai konfigurasi dibagian IDN-R2, lanjut konfigurasi di bagian IDN-R3
|
Gambar 10 Topologi bagiann IDN-R3 |
Pertama kita konfigurasi IDN-SW3 menjadi VTP Server
IDN-SW3(config)#vtp mode server
Device mode already VTP SERVER.
IDN-SW3(config)#vtp domain IDN
Changing VTP domain name from NULL to IDN
IDN-SW3(config)#vtp password 123
Setting device VLAN database password to 123
IDN-SW3(config)#vlan 10
IDN-SW3(config-vlan)#vlan 11
IDN-SW3(config-vlan)#exit
IDN-SW3(config)#interface range fa0/1-3
IDN-SW3(config-if-range)#switchport mode trunk
Lanjut konfigurasi di IDN-SW4
IDN-SW4(config)#vtp mode client
Setting device to VTP CLIENT mode.
IDN-SW4(config)#vtp domain IDN
Domain name already set to IDN.
IDN-SW4(config)#vtp password 123
Setting device VLAN database password to 123
IDN-SW4(config)#interface range fa0/1-2
IDN-SW4(config-if-range)#switchport mode trunk
IDN-SW4(config-if-range)#interface range fa0/3-4
IDN-SW4(config-if-range)#switchport mode access
IDN-SW4(config-if-range)#switchport voice vlan 10
IDN-SW4(config-if-range)#switchport access vlan 11
Lanjut konfigurasi di IDN-SW5
IDN-SW5(config)#vtp mode client
Setting device to VTP CLIENT mode.
IDN-SW5(config)#vtp domain IDN
Domain name already set to IDN.
IDN-SW5(config)#vtp password 123
Setting device VLAN database password to 123
IDN-SW5(config)#interface range fa0/1-2
IDN-SW5(config-if-range)#switchport mode trunk
IDN-SW5(config-if-range)#interface range fa0/3-4
IDN-SW5(config-if-range)#switchport mode access
IDN-SW5(config-if-range)#switchport voice vlan 10
IDN-SW5(config-if-range)#switchport access vlan 11
Konfigurasi terahir pada bagian switch yang harus kita lakukan adalah PVSTP. Tujuan kita adalah agar paket yang berasal dari vlan 10 dilewatkan IDN-SW4, sedangkan paket yang berasal dari vlan 11 dilewatkan IDN-SW5. Untuk lebih jelasnya perhatikan ilustrasi berikut
|
Gambar 11 Ilustrasi konfigurasi PVSTP |
Oke untuk mewujudkan tujaun tersebut, kita harus konfigurasi IDN-SW4 menjadi root bridge vlan 10 dan IDN-SW5 menjadi root bridge vlan 11
IDN-SW4(config)#spanning-tree vlan 10 root primary
IDN-SW5(config)#spanning-tree vlan 11 root primary
Sekarang kita lanjut konfigurasi pada IDN-R3
IDN-R3(config)#interface fa0/0
IDN-R3(config-if)#no shutdown
IDN-R3(config-if)#interface fa0/0.10
IDN-R3(config-subif)#encapsulation dot1q 10
IDN-R3(config-subif)#ip address 10.10.10.254 255.255.255.0
IDN-R3(config-subif)#interface fa0/0.11
IDN-R3(config-subif)#encapsulation dot1q 11
IDN-R3(config-subif)#ip address 11.11.11.254 255.255.255.0
IDN-R3(config-subif)#ip dhcp pool vlan10
IDN-R3(dhcp-config)#network 10.10.10.0 255.255.255.0
IDN-R3(dhcp-config)#default-router 10.10.10.254
IDN-R3(dhcp-config)#option 150 ip 10.10.10.254
IDN-R3(dhcp-config)#ip dhcp pool vlan11
IDN-R3(dhcp-config)#network 11.11.11.0 255.255.255.0
IDN-R3(dhcp-config)#default-router 11.11.11.254
IDN-R3(dhcp-config)#dns-server 100.100.100.1
IDN-R3(dhcp-config)#exit
IDN-R3(config)#telephony-service
IDN-R3(config-telephony)#max-dn 4
IDN-R3(config-telephony)#max-ephone 4
IDN-R3(config-telephony)#ip source-address 10.10.10.254 port 2000
IDN-R3(config-telephony)#auto assign 1 to 4
IDN-R3(config-telephony)#exit
IDN-R3(config)#ephone-dn 1
IDN-R3(config-ephone-dn)#number 2221
IDN-R3(config-ephone-dn)#ephone-dn 2
IDN-R3(config-ephone-dn)#number 2222
IDN-R3(config-ephone-dn)#ephone-dn 3
IDN-R3(config-ephone-dn)#number 2223
IDN-R3(config-ephone-dn)#ephone-dn 4
IDN-R3(config-ephone-dn)#number 2224
Untuk pengujian kita nyalakan seluruh IP Phone kemudian konfigurasi dhcp client di seluruh PC
|
Gambar 12 Menyalakan IDN-Phone5 |
|
Gambar 13 Konfigurasi dhcp client di client |
Coba lakukan telphone dari IDN-Phone5 ke IDN-Phone6
|
Gambar 14 Verifikasi telphone dari IDN-Phone5 ke IDN-Phone6 |
Oke sampai saat ini kita sudah selesai konfigurasi di masing-masing bagian. Sekarang kita harus konfigurasi frame relay dan routing agar IDN-R1, IDN-R2, dan IDN-R3 bisa saling terhubung.
|
Gambar 15 Topologi Frame Relay |
Berikut konfigurasi yang perlu kita lakukan
IDN-R1(config)#interface se1/0
IDN-R1(config-if)#no shutdown
IDN-R1(config-if)#ip address 123.123.123.1 255.255.255.0
IDN-R1(config-if)#encapsulation frame-relay
IDN-R1(config-if)#frame-relay map ip 123.123.123.2 102 broadcast
IDN-R1(config-if)#frame-relay map ip 123.123.123.3 103 broadcast
IDN-R2(config)#interface se1/0
IDN-R2(config-if)#no shutdown
IDN-R2(config-if)#ip address 123.123.123.2 255.255.255.0
IDN-R2(config-if)#encapsulation frame-relay
IDN-R2(config-if)#frame-relay map ip 123.123.123.1 201 broadcast
IDN-R2(config-if)#frame-relay map ip 123.123.123.3 203 broadcast
IDN-R3(config)#interface se1/0
IDN-R3(config-if)#no shutdown
IDN-R3(config-if)#ip address 123.123.123.3 255.255.255.0
IDN-R3(config-if)#encapsulation frame-relay
IDN-R3(config-if)#frame-relay map ip 123.123.123.1 301 broadcast
IDN-R3(config-if)#frame-relay map ip 123.123.123.2 302 broadcast
Untuk verifikasi coba lakukan ping dari IDN-R1 ke IDN-R2 dan IDN-R3
IDN-R1(config)#do ping 123.123.123.2
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 123.123.123.2, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 2/114/378 ms
IDN-R1(config)#do ping 123.123.123.3
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 123.123.123.3, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 2/129/375 ms
Sekarang lakukan konfigurasi EIGRP di seluruh router
IDN-R1(config)#interface se1/0
IDN-R1(config)#no ip split-horizon
IDN-R1(config)#router eigrp 1
IDN-R1(config)#no auto-summary
IDN-R1(config-router)#network 123.123.123.0
IDN-R1(config-router)#network 100.100.100.0
IDN-R2(config)#interface se1/0
IDN-R2(config)#no ip split-horizon
IDN-R2(config)#router eigrp 1
IDN-R2(config)#no auto-summary
IDN-R2(config-router)#network 123.123.123.0
IDN-R2(config-router)#network 101.101.101.1
IDN-R2(config-router)#network 20.20.20.0
IDN-R2(config-router)#network 21.21.21.0
IDN-R3(config)#interface se1/0
IDN-R3(config)#no ip split-horizon
IDN-R3(config)#router eigrp 1
IDN-R3(config)#no auto-summary
IDN-R3(config-router)#network 123.123.123.0
IDN-R3(config-router)#network 10.10.10.0
IDN-R3(config-router)#network 11.11.11.0
Untuk verifikasi kita coba lihat tabel routing di IDN-R3
IDN-R3(config-if)#do show ip route eigrp
20.0.0.0/24 is subnetted, 1 subnets
D 20.20.20.0 [90/20514560] via 123.123.123.2, 00:00:12, Serial1/0
21.0.0.0/24 is subnetted, 1 subnets
D 21.21.21.0 [90/20514560] via 123.123.123.2, 00:00:12, Serial1/0
100.0.0.0/24 is subnetted, 1 subnets
D 100.100.100.0 [90/20514560] via 123.123.123.1, 00:01:09, Serial1/0
101.0.0.0/24 is subnetted, 1 subnets
D 101.101.101.0 [90/20514560] via 123.123.123.2, 00:00:12, Serial1/0
Perhatikan bahwa IDN-R3 sudah mengetahui tentang seluruh network yang ada. Sekarang kita coba akses ke web server dari client
|
Gambar 16 Verifikasi Core Server |
|
Gambar 17 Verifikasi Backup Server |
Oke terlihat bahwa client sudah bisa mengakses web server utama dan web server backup. Lanjut kita coba telphone dari IP Phone yang ada di IDN-R3 ke IP Phone yang ada di IDN-R2
|
Gambar 18 Verifikasi telephone |
Perhatikan bahwa masih gagal, kita harus menambahkan beberapa konfigurasi seperti berikut
IDN-R2(config)#dial-peer voice 1 voip
IDN-R2(config-dial-peer)#destination-pattern 222.
IDN-R2(config-dial-peer)#session target ipv4:123.123.123.3
IDN-R3(config)#dial-peer voice 1 voip
IDN-R3(config-dial-peer)#destination-pattern 111.
IDN-R3(config-dial-peer)#session target ipv4:123.123.123.2
Sekarang kita coba lagi telephone dari IP Phone yang ada di IDN-R3 ke IP Phone yang ada di IDN-R2
|
Gambar 19 Verifikasi telephone |
Oke kita sudah berhasil. Terahir kita konfigurasi AAA Server di IDN-SRV3 dan AAA Client di seluruh router.
|
Gambar 20 Konfigurasi AAA Server |
Lanjut enable telnet di seluruh router dengan memanfaatkan user yang kita buat di AAA Server
IDN-R1(config)#aaa new-model
IDN-R1(config)#aaa authentication login AAA group tacacs+ local
IDN-R1(config)#tacacs-server host 100.100.100.3
IDN-R1(config)#tacacs-server key IDN
IDN-R1(config)#line vty 0 4
IDN-R1(config-line)#login authentication AAA
Kita lakukan pengujian dari client
|
Gambar 21 Verifikasi telnet dari client |
Lakukan langkah seperti di IDN-R1 untuk IDN-R2 dan IDN-R3.
Oke sampai saat ini kita sudah selesai dan berhasil konfigurasi superlab 39. Semoga bermanfaat dan jangan lupa share ya biar lebih bermanfaat....
Tidak ada komentar:
Posting Komentar
Komentar