VLANs - Layer 3 Switches - HSRP - ASA 5505 - Router - Site to Site VPN

แชร์
ฝัง
  • เผยแพร่เมื่อ 21 ส.ค. 2024

ความคิดเห็น • 111

  • @rajan_
    @rajan_ 2 ปีที่แล้ว +4

    Very helpful tutorial, thanks. It will be very helpful if you can provide .pkt file or configurations in text file.

    • @christianaugustoromerogoyz8177
      @christianaugustoromerogoyz8177  2 ปีที่แล้ว +1

      I don't have the packet tracer file and this video shows all the necessary configurations to complete the project

  • @stevezzorr
    @stevezzorr 3 ปีที่แล้ว +1

    Thank you so much, very helpful material!

  • @GA-tl4iy
    @GA-tl4iy 4 ปีที่แล้ว +1

    WELL DONE BROTHER AUGUSTO, THANKS A LOT. GOD BLESS.

    • @christianaugustoromerogoyz8177
      @christianaugustoromerogoyz8177  4 ปีที่แล้ว

      Thank you for your comment, I appreciate

    • @GA-tl4iy
      @GA-tl4iy 4 ปีที่แล้ว +2

      @@christianaugustoromerogoyz8177 Just let you know, quality of video is very BAD, I can see and read text from packet tracer. if you can clear video to see better. Thanks anyway

    • @christianaugustoromerogoyz8177
      @christianaugustoromerogoyz8177  4 ปีที่แล้ว

      @@GA-tl4iy please go to options and set video to 720 or 1080 quality

    • @GA-tl4iy
      @GA-tl4iy 4 ปีที่แล้ว +1

      @@christianaugustoromerogoyz8177 I can not configure MAC-ADDRESS in VLANS, I have Cisco Packet Tracer 6.2 , Can you please advice? Appreciate

    • @christianaugustoromerogoyz8177
      @christianaugustoromerogoyz8177  4 ปีที่แล้ว

      @@GA-tl4iy why do you need that¡

  • @SquashMtb
    @SquashMtb 5 ปีที่แล้ว +1

    Hola Christian, ta bueno el Video, gracias.
    Saludos
    Christian

    • @christianaugustoromerogoyz8177
      @christianaugustoromerogoyz8177  5 ปีที่แล้ว

      Gracias por tu comentario, lo aprecio bastante

    • @SquashMtb
      @SquashMtb 5 ปีที่แล้ว +1

      @@christianaugustoromerogoyz8177 Hola, Te envie un email @ romeroc42@gmail.com echale una mirada,pls.

  • @hetalpanchal9433
    @hetalpanchal9433 5 ปีที่แล้ว +2

    Very good video, thanks for uploading, please could you provide the output of show vlan and show int trunk of the access and core switches.

  • @victorlin8098
    @victorlin8098 4 ปีที่แล้ว +1

    your videos are so good for me :-) THank you so much for your great efforts to share!!!!!

  • @delta_eps8916
    @delta_eps8916 4 ปีที่แล้ว +1

    Hello,
    1) Why do you configure static route on core sw 2 at 11'45'' and not ospf route ?
    2) At 19'40'' why do you use for FAI static route and not ospf ?
    3) At 7'01'' you configure in core switch 1 in gig1/0/8 and gig1/0/9 => switchport mode access + switchport nonegotiate
    Why you don't configure in theses interfaces => switchport trunk native vlan 99 + switchport trunk encapsulation dot1q + switchport mode trunk ?
    Thanks a lot

    • @christianaugustoromerogoyz8177
      @christianaugustoromerogoyz8177  4 ปีที่แล้ว

      Hello. These are the answers
      1. and 2. ASA does not support OSPF, so that is why you need static routing
      3. ASA can support trunks but in my case I'm using access ports on ASA and then neighbors like switches should use also access ports.
      Thank you

  • @rajan_
    @rajan_ 2 ปีที่แล้ว +2

    On the left side the port-channel is 2, will there be same number on right side?

  • @delta_eps8916
    @delta_eps8916 4 ปีที่แล้ว +2

    Hello,
    If we had a link between ASA-1 and ASA-2.
    What zone would that be ?
    Thanks a lot

  • @jacka126
    @jacka126 4 ปีที่แล้ว +1

    Hi, I have a question. I am doing almost identical topology like yours for my work security assignment and I have encountered a problem. On layer 3 switches cannot configure port-channel as I get this message "%EC-5-CANNOT_BUNDLE2: Fa0/24 is not compatible with Po3 and will be suspended (native VLAN of Fa0/24 is 99, Po3 id 1)" . First I have configured these ports as a native VLAN 99 and when I try to configure port-channel on fa0/21-24 it shows the above message. Please advice me. many thanks

    • @christianaugustoromerogoyz8177
      @christianaugustoromerogoyz8177  4 ปีที่แล้ว +1

      when you configure a port channel or trunks, first shutdown the interfaces on all devices (two devices) then apply the configurations on the devices (two devices) finally enable the interfaces.

  • @delta_eps8916
    @delta_eps8916 4 ปีที่แล้ว +1

    Hello,
    1) Why do you use a vlan for network 172.160.0.0 /28 ? and why vlan 1 and not an other ?
    2) If we don't use VLAN 1 for ASA it will there be a mistake ?
    3) Why do you use VLAN 2 and 3 for the outside ? Can we just use adresse IP without VLAN for the ASA ?
    Thanks for the video bro

  • @abhishekshah11
    @abhishekshah11 4 ปีที่แล้ว +1

    What kept bothering me throughout the video was that your etherchannels are in blocking state by spanning tree. What's the use of etherchannel if they are blocked

    • @christianaugustoromerogoyz8177
      @christianaugustoromerogoyz8177  4 ปีที่แล้ว

      etherchannel will be used for add bandwidth and multiple paths will be used if main paths fail (redundancy)

    • @abhishekshah11
      @abhishekshah11 4 ปีที่แล้ว +1

      @@christianaugustoromerogoyz8177 No, between core switches, I assume one core is root for one vlan and the other switch is root for another vlan? So for intervlan routing, if the etherchannel is configured as a trunk port, you achieve intervlan routing.

    • @christianaugustoromerogoyz8177
      @christianaugustoromerogoyz8177  4 ปีที่แล้ว

      @@abhishekshah11 That will work fine

  • @walidharmel7619
    @walidharmel7619 2 ปีที่แล้ว +1

    Hi, is it possible to use HSRP on vlan 1 (between coreSW1 and coreSW2)?

  • @m1rage92
    @m1rage92 2 ปีที่แล้ว +1

    @Christian Augusto Romero Goyzueta II
    Hi bro sorry to bother
    I've been doing this practise and finish it but i still have an issue.
    If i try to ping from the LAN like PC1 (vlan 10 ==> to vlan interface 192.168.10.1 ) it works
    Each vlan can reach his interface , on the other part network is also working between routers
    BUT if i try from PC1 to reach the FAI ( 20.20.20.1 ) for example , the ping seems to not override the firewall
    Do you have maybe any ideas why ?
    Ty

  • @telecomnetworking6819
    @telecomnetworking6819 4 ปีที่แล้ว +1

    I face the problem of STP during the simulation, do you have any clues?

  • @delta_eps8916
    @delta_eps8916 4 ปีที่แล้ว +1

    Hello,
    At 15'34'',
    Why do you write in ASA-1 "object network NET_LOCAL
    subnet 192.168.0.0 255.255.0.0" ?
    Thanks a lot

    • @christianaugustoromerogoyz8177
      @christianaugustoromerogoyz8177  4 ปีที่แล้ว

      you create two objects NET LOCAL and NET REMOTE, on next lines you will see ACL that is configured to permit traffic using the objects

  • @rindu2909
    @rindu2909 3 ปีที่แล้ว +1

    Hi chris, may i know where actually you configure the VLAN? through the access or at CORE 3 nor CORE 4?
    Thank you

    • @christianaugustoromerogoyz8177
      @christianaugustoromerogoyz8177  3 ปีที่แล้ว +2

      Configure trunks, vlans and assign vlans to ports, all on Layer 2

    • @rindu2909
      @rindu2909 3 ปีที่แล้ว +1

      @@christianaugustoromerogoyz8177 noted.thank U

    • @rindu2909
      @rindu2909 3 ปีที่แล้ว +1

      Hi Chris. May i know if the gateway for syslog is 192.168.30.1? if yes, im not be able config the syslog and ping through the 192.168.30.1. could you advice? Thank you

    • @christianaugustoromerogoyz8177
      @christianaugustoromerogoyz8177  3 ปีที่แล้ว +1

      @@rindu2909 please assign vlan 30 to the port connected from switch to server

    • @rindu2909
      @rindu2909 3 ปีที่แล้ว +1

      @@christianaugustoromerogoyz8177 thank U chirs..im not assign the vlan at distribution layer...thank u so much..im able to ping now..may i know if you have lab related with vpn+wireless? TQ

  • @agariskika3486
    @agariskika3486 4 ปีที่แล้ว +2

    Why My vlan 10 20 30 40 on CoreSw can't up?

    • @christianaugustoromerogoyz8177
      @christianaugustoromerogoyz8177  4 ปีที่แล้ว +1

      please enable trunk interface or access interface on the device, also configure the vlans to add on vlan table.

    • @agariskika3486
      @agariskika3486 4 ปีที่แล้ว +2

      @@christianaugustoromerogoyz8177 i mean the gateway vlan on layer 3 switches

    • @christianaugustoromerogoyz8177
      @christianaugustoromerogoyz8177  4 ปีที่แล้ว

      @@agariskika3486 don't forget no shutdown command and configure an access port and assign to that vlan or configure trunks correctly

    • @agariskika3486
      @agariskika3486 4 ปีที่แล้ว +1

      @@christianaugustoromerogoyz8177now the vlan is up, but can't ping the user, all trunk and access is done

    • @christianaugustoromerogoyz8177
      @christianaugustoromerogoyz8177  4 ปีที่แล้ว

      @@agariskika3486 you need to configure routes, static routes

  • @delta_eps8916
    @delta_eps8916 4 ปีที่แล้ว +1

    What does mean FAI ? it's like a second ISP ?

  • @danmounter2287
    @danmounter2287 4 ปีที่แล้ว +1

    hello could you also send me outputs vlan and trunk briefs of access and core switches. great vid thank you

    • @christianaugustoromerogoyz8177
      @christianaugustoromerogoyz8177  4 ปีที่แล้ว +1

      Hello, I just showed all configurations and I don't have the files with configurations, so please try to implement your own file.

  • @thepuldarshana9056
    @thepuldarshana9056 ปีที่แล้ว +1

    are you just showing preconfigured configurations ?

    • @christianaugustoromerogoyz8177
      @christianaugustoromerogoyz8177  ปีที่แล้ว +1

      This is the updated video, you can see all the configs
      th-cam.com/video/1E0HluxxwAk/w-d-xo.html

    • @thepuldarshana9056
      @thepuldarshana9056 ปีที่แล้ว

      @@christianaugustoromerogoyz8177 thank you so much, I am now watching it. I am looking for a great tutorial like site to site VPN using ASA . Such as vlan users can assess servers in a remote location via VPN . For my Network University project.

    • @thepuldarshana9056
      @thepuldarshana9056 ปีที่แล้ว +1

      @@christianaugustoromerogoyz8177 Hi , I went through your video and very good practical. can I know , is it possible to configure the 2 ASAs with HSRP like you did to Core SW ? One ASA fails other ASA will come up ?

    • @christianaugustoromerogoyz8177
      @christianaugustoromerogoyz8177  ปีที่แล้ว +1

      @@thepuldarshana9056 ASA's are not supporting HSRP on packet tracer, but we need to verify that on real devices

    • @thepuldarshana9056
      @thepuldarshana9056 ปีที่แล้ว +1

      @@christianaugustoromerogoyz8177 ok I understand. Thank you

  • @johnangara7714
    @johnangara7714 ปีที่แล้ว +1

    Great topology! can i have the PKT file sir?

  • @sylar5708
    @sylar5708 3 ปีที่แล้ว +1

    Are the object network on ASA needed just to connect to ISP router?
    Do you have any other labs with 2 asa and 2 core switches?

    • @christianaugustoromerogoyz8177
      @christianaugustoromerogoyz8177  3 ปีที่แล้ว +1

      yes, object network will use NAT to connect ASA to simulated Internet, I don't have more examples, but this playlist can have interesting projects th-cam.com/play/PLdtRZtGMukf4GGF_jvBAuNQKZEnUi4TaQ.html

    • @sylar5708
      @sylar5708 3 ปีที่แล้ว +1

      @@christianaugustoromerogoyz8177 What if i have only ISP router, without remote user and vpn. Will the NAT translation work with just 3 lines of "route inside etc" without object network?

    • @christianaugustoromerogoyz8177
      @christianaugustoromerogoyz8177  3 ปีที่แล้ว

      @@sylar5708 for only one ISP you need NAT with object network, dynamic NAT

    • @sylar5708
      @sylar5708 3 ปีที่แล้ว +1

      @@christianaugustoromerogoyz8177
      Another question: Sometimes if i ping one of ISP ip from diffrent vlan pc's it doesnt work. What could be wrong? Is this because of one ASA being in standby mode? From core switches it is working fine.

    • @christianaugustoromerogoyz8177
      @christianaugustoromerogoyz8177  3 ปีที่แล้ว +1

      @@sylar5708 ASA Firewalls are configured with static routing, and ISPs are configured with static routing, that is the problem, you can see the packet on simulation mode

  • @networkingandittechnologie4440
    @networkingandittechnologie4440 3 ปีที่แล้ว +1

    can you share the lab output please

  • @guildoquiroga3229
    @guildoquiroga3229 5 ปีที่แล้ว +1

    buenas cristian, muy buen video
    sirvio de gran ayuda
    tengo algunas con la configuracion del asa
    me podes ayudar ?
    tenes algun numero para poder comunicarme ?

  • @sdayabaran
    @sdayabaran 3 ปีที่แล้ว +1

    Thanks for the video, can you please share the configurations command file, Thank you

    • @christianaugustoromerogoyz8177
      @christianaugustoromerogoyz8177  3 ปีที่แล้ว +2

      I don't have the commands on text but video shows all commands please try those commands, will work

    • @user-fz4uo9it4m
      @user-fz4uo9it4m 3 ปีที่แล้ว +1

      @@christianaugustoromerogoyz8177 Noted with thanks

    • @christianaugustoromerogoyz8177
      @christianaugustoromerogoyz8177  3 ปีที่แล้ว

      @@user-fz4uo9it4m thank you

    • @sdayabaran
      @sdayabaran 3 ปีที่แล้ว +1

      @@christianaugustoromerogoyz8177 Noted and thank you,

    • @sdayabaran
      @sdayabaran 3 ปีที่แล้ว

      @@christianaugustoromerogoyz8177 I have setup your topology and having some issues so could you please give me the packet tracer file?

  • @0Rkvishwakarma
    @0Rkvishwakarma 10 หลายเดือนก่อน +1

    can you please share a topology file.

    • @christianaugustoromerogoyz8177
      @christianaugustoromerogoyz8177  10 หลายเดือนก่อน

      use social media shown on 00:03 but anyway there is an update th-cam.com/video/1E0HluxxwAk/w-d-xo.html

  • @EMTMZ
    @EMTMZ 4 ปีที่แล้ว +1

    Please improve the sound of video

  • @stivencastro7925
    @stivencastro7925 4 ปีที่แล้ว +1

    hi, very good video. Can you please send me the pkt file?

  • @moidukp
    @moidukp 2 ปีที่แล้ว +1

    hi

  • @brahmam-vadla
    @brahmam-vadla ปีที่แล้ว +1

    Hi Plz send Pkt Lab file. Thank you

  • @thavymony8053
    @thavymony8053 5 ปีที่แล้ว +1

    Can you give me your Lab?

  • @sayuri-3623
    @sayuri-3623 6 ปีที่แล้ว +2

    hi, you can give me file.pkt

    • @christianaugustoromerogoyz8177
      @christianaugustoromerogoyz8177  6 ปีที่แล้ว

      I don't have the file but I can do it again, romeroc42@gmail.com

    • @santanumanna7266
      @santanumanna7266 5 ปีที่แล้ว

      please send me file.pkt or CONFIGURATION FILE on santanumanna365@gmail.com

    • @rehanmistry114
      @rehanmistry114 5 ปีที่แล้ว

      Can you send me the packet tracer file on rehanmistry38@gmail.com