Question

Create New Network with Cisco Packet Tracer 4.1

Asked by: chipmate

Can some one help me to create this in Packet Tracer Ver. 4.11 files and document?

1) Containing basic network (without ACLs) files.
2) Containing the network with ACLs applied files.
3) Document in working with an explanation for the subnet plan and the access control lists.

Network devices should be fully configured with a naming convention used to identify all devices in your network.

Please refer to the attached file for more detail.

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2008-03-25 at 19:51:56ID23269318
Tags

Networking

Topics

Network Design & Methodology

,

Network Analysis Software

,

Network Routers

Participating Experts
1
Points
125
Comments
33

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. Spoofed packets
    I have 5 lines for every second like this in the log: 19 11:10:55 3 IPG IPFIL FRAG Spoofed packet Fail 10.0.0.1>10.0.30.2 Prot=1 Int=eth0 The log is from a router with IP 10.0.01 - 10.0.30.x is a Lan on the other side of a router on the 10.0.0.x net. I know a spoofed ...
  2. Cisco Router can't process small packets
    Wasn't sure weather to ask this in security or hardware. :) I have a Cisco 7513 router. RSP4, 20MB Flash, 256Mb RAM. Under normal operations the router works very well. It's fast and can handle just about any load thrown at it it seems. The problem comes when we are att...
  3. cisco packet snif
    how can I snif the packets on a router that is on the other end of a T1. I have many packets coming in an interface of the router that are being stopped by an ACL. I want to use something like port mirroring to copy the packets to my laptop, or a server. any suggestions?
  4. Dropping Packets
    Topology: We have 3 Cisco ASA 5520's connected to an HP Procurve 2824, which is serving as our Internet switch. One of the ASA's is serving as the primary firewall, one is dedicated to hosting lan-2-lan tunnels, and the 3rd was installed simply for troubleshooting this parti...
  5. VPN Packet Loss
    I have a VPN setup between two site. I receive a maximum of 50% packet loss all the time. It will drop to 40% but never gets better than that. I never have more than one packet in a row drop, or more than 2 in a row not drop. I have turned off the DF bit and lowered the I...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: donmanrobbPosted on 2008-03-30 at 03:48:09ID: 21240215

If you post your Packet Tracer file, I'll look it over and give you some feedback as to if your working in the right direction and/or answer some questions to help get you started.

 

by: chipmatePosted on 2008-03-30 at 16:29:10ID: 21242373

Thanks, would you help me to create the ACL. I am looking for a program to do the ACL simulation. I know the Cisco ACL Editor And Simulation. Do you know where to download the full version.

Regards,

 

by: donmanrobbPosted on 2008-03-30 at 16:41:46ID: 21242407

Packet Tracer should be able to handle the ACLs just fine, of course the best free "simulator" around is GNS3 (www.gns3.net) if your able to get your hands on a real IOS image. As for ACL Editor it can be purchased here http://www.garethevans.info/products/acleditor for £20

What do you have done so far?

 

by: chipmatePosted on 2008-03-30 at 17:35:05ID: 21242532

I already done the network Ip allocation. I am now having the problem with the ACL. I can't make the router work. I try to create ACL but it doesn't work when I ping the Ip address. Can you help?

 

by: donmanrobbPosted on 2008-03-30 at 17:37:56ID: 21242542

Post your config or the packet tracer file and I'll have a look

 

by: chipmatePosted on 2008-03-30 at 19:11:59ID: 21242774

Thanks. Here is it.

Packet Tracer 4.1 program download.
ftp://satotech.serveftp.com/lim/packet_tracer_411.zip

Packet Tracer File
ftp://satotech.serveftp.com/lim/Part%20B%20-%20Wiithout%20ACL.pkt

I am sorry the forum won't allow me to upload. I put a link for you to download from my FTP server.

Many thanks.

 

by: chipmatePosted on 2008-03-30 at 21:28:30ID: 21243162

My due date is today. Do you have any chance to look at it yet? I need it by today before 9pm Australia time today.

If you can help it will be very much appreciate.

Thanks.

 

by: donmanrobbPosted on 2008-03-30 at 22:31:53ID: 21243324

I didn't realise this was a priority, I'll look at it now

 

by: chipmatePosted on 2008-03-30 at 22:45:04ID: 21243354

You are good man. I love this experts exchange more and more now. It ready help people. I will highly recommend my IT friends this website from now on.

Thanks.

 

by: donmanrobbPosted on 2008-03-30 at 23:13:56ID: 21243429

I'll leave the rest and what interfaces to add the ACLs to in your capable hands.

WAN
--
ip access-list extended LAN->HTTP
 permit tcp 141.70.0.0 0.0.255.255 any eq www
ip access-list extended SERVERS
 permit ip 141.70.64.0 0.0.0.63 141.70.5.0 0.0.0.3
 permit ip 141.70.48.0 0.0.0.255 141.70.5.0 0.0.0.3
 permit ip 141.70.112.0 0.0.3.255 141.70.5.0 0.0.0.3
 permit tcp 141.70.0.0 0.0.255.255 host 141.70.5.1 eq www
 permit tcp 141.70.0.0 0.0.255.255 host 141.70.5.2 eq smtp
ip access-list extended WAN->Servers
 permit tcp any 141.70.5.0 0.0.0.3
--
IT MNT
ip access-list standard IT->Management
 permit 141.70.48.0 0.0.0.255

 

by: chipmatePosted on 2008-03-31 at 00:16:53ID: 21243654

Thanks for your help. I just try again to set the router connect the IT and Management as below:
      
Router>enable
Router#configure terminal
Enter configuration commands, one per line.  End with CNTL/Z.
Router(config)#access-list 1 permit 141.70.48.0 0.0.0.255
Router(config)#exit
Enter configuration commands, one per line.  End with CNTL/Z.
Router(config)#interface GigabitEthernet0/0
Router(config-if)#
Router(config-if)#exit
Router(config)#interface GigabitEthernet0/0
Router(config-if)#ip access-group 1 in
Router(config-if)#exit
Router(config)#
Router(config)#interface GigabitEthernet1/0
Router(config-if)#ip access-group 1 out
Router(config-if)#exit
Router(config)#

And I try to ping from IT host to Management host and it still give the result as below:
Packet Tracer PC Command Line 1.0
PC>ping 141.79.64.1

Pinging 141.79.64.1 with 32 bytes of data:

Request timed out.
Request timed out.
Request timed out.
Request timed out.

Ping statistics for 141.79.64.1:
    Packets: Sent = 4, Received = 0, Lost = 4 (100% loss),

I don't know where I did wrong and why it keep no reply. I has been try for few days and can't make it work until today my due date and I still try to work it out. Can you tell me why it doesn't work? Can you help me to configure some of ther router in the pkt file so I can try to understand from there.

Thanks.

 

by: chipmatePosted on 2008-03-31 at 00:45:01ID: 21243735

Here is the config I get from the router.

Router#show running-config
Building configuration...

Current configuration : 626 bytes
!
version 12.2
no service password-encryption
!
hostname Router
!
!
!
!
interface GigabitEthernet0/0
 ip address 141.70.63.254 255.255.240.0
 ip access-group 1 in
 duplex auto
 speed auto
!
interface GigabitEthernet1/0
 ip address 141.70.79.254 255.255.240.0
 ip access-group 1 out
 duplex auto
 speed auto
!
interface Serial2/0
 ip address 141.70.10.6 255.255.240.0
!
interface Serial3/0
 no ip address
 shutdown
!
interface FastEthernet4/0
 no ip address
 shutdown
!
interface FastEthernet5/0
 no ip address
 shutdown
!
ip classless
!
access-list 1 permit 141.70.48.0 0.0.0.250
!
!
!
line con 0
line vty 0 4
 login
!
!
end

 

by: donmanrobbPosted on 2008-03-31 at 01:51:17ID: 21243965

Check your IPs on the Mng IT router. The 48 network should be on the router's interface that connects IT and a 64 network should be on the interface that connects management.

 

by: chipmatePosted on 2008-03-31 at 02:39:51ID: 21244135

I am panic now. All the interface and IP is correct why is still not getting through. Below is the Ip I reconfigure. Even I try to go both way in and out still no respond from ping.

Router#show running-config
Building configuration...

Current configuration : 671 bytes
!
version 12.2
no service password-encryption
!
hostname Router
!
!
!
!
interface GigabitEthernet0/0
 ip address 141.70.48.254 255.255.240.0
 ip access-group 1 in
 ip access-group 1 out
 duplex auto
 speed auto
!
interface GigabitEthernet1/0
 ip address 141.70.64.254 255.255.240.0
 ip access-group 1 in
 ip access-group 1 out
 duplex auto
 speed auto
!
interface Serial2/0
 ip address 141.70.10.6 255.255.240.0
!
interface Serial3/0
 no ip address
 shutdown
!
interface FastEthernet4/0
 no ip address
 shutdown
!
interface FastEthernet5/0
 no ip address
 shutdown
!
ip classless
!
access-list 1 permit 141.70.48.0 0.0.0.250
!
!
!
line con 0
line vty 0 4
 login
!
!
end

 

by: donmanrobbPosted on 2008-03-31 at 03:01:05ID: 21244194

The access-list should be set on gig1/0 outbound

 

by: chipmatePosted on 2008-03-31 at 03:35:09ID: 21244295

Router#show running-config
Building configuration...

Current configuration : 626 bytes
!
version 12.2
no service password-encryption
!
hostname Router
!
!
!
!
interface GigabitEthernet0/0
 ip address 141.70.48.254 255.255.240.0
 ip access-group 1 in
 duplex auto
 speed auto
!
interface GigabitEthernet1/0
 ip address 141.70.64.254 255.255.240.0
 ip access-group 1 out
 duplex auto
 speed auto
!
interface Serial2/0
 ip address 141.70.10.6 255.255.240.0
!
interface Serial3/0
 no ip address
 shutdown
!
interface FastEthernet4/0
 no ip address
 shutdown
!
interface FastEthernet5/0
 no ip address
 shutdown
!
ip classless
!
access-list 1 permit 141.70.48.0 0.0.0.250
!
!
!
line con 0
line vty 0 4
 login
!
!
end

Still the same result
PC>ping 141.70.64.1

Pinging 141.70.64.1 with 32 bytes of data:

Request timed out.
Request timed out.
Request timed out.
Request timed out.

Ping statistics for 141.70.64.1:
    Packets: Sent = 4, Received = 0, Lost = 4 (100% loss),

I feel like I miss out some part of the setup in the router. Rounting setup?? Static & RIP ?? Can you help to make this router work in my packet tracer file and give it to me? I almost give up now.

 

by: donmanrobbPosted on 2008-03-31 at 04:31:53ID: 21244476

Your problem is a typo in the access-list you had, access-list 1 permit 141.70.48.0 0.0.0.250 instead of access-list 1 permit 141.70.48.0 0.0.0.255 which changes the logic drastically.
Pings work fine on my side of things.

 

by: chipmatePosted on 2008-03-31 at 09:39:22ID: 21246966

Now the IT -> Management is working. How do I implement your ACL to each router from the host to the server? Can you guide me in step by step? I get block by the Router Management IT to the WAN Router.

Thanks.

 

by: donmanrobbPosted on 2008-03-31 at 14:12:42ID: 21249248

I went to bed for the day :), Did you figure this out? I can still help you with this for knowledge purposes

 

by: chipmatePosted on 2008-03-31 at 15:49:02ID: 21249845

Sorry no. I still work on it. I can't make the ACL function. If I apply the gateway, it will allow to ping both way in Management and IT. Then I implement the ACL that you give to me at "interface GigabitEthernet1/0" as outbound. It make no different. When I try to insert and access-list deny from Management to IT "interface GigabitEthernet0/0 then block the ping both way in the LAN. I was try it until 4am in the morning and give up. It make me go crazy.

 

by: chipmatePosted on 2008-03-31 at 19:54:23ID: 21250884

I am sorry this is my first time of touching Cisco. Do you know anything wrong or anything that I should take note to implement the ACL? Any concept or guide line for me to follow?

Thanks.

 

by: donmanrobbPosted on 2008-03-31 at 20:09:26ID: 21250943

Can you repost the updated packet tracer file? I'll look it over and let you know.

 

by: chipmatePosted on 2008-03-31 at 20:25:24ID: 21251017

Thanks. Here is it.

Packet Tracer 4.1 program download.
ftp://satotech.serveftp.com/lim/packet_tracer_411.zip

Packet Tracer File
ftp://satotech.serveftp.com/lim/Part%20B%20-%20With%20ACL.pkt

Please tell me is there any problem on physical connectivity. Router setting RIP/Static and so on.

 

by: chipmatePosted on 2008-03-31 at 23:47:23ID: 21251703

Thanks for looking over again. I am finish work soon. I will be continue to working on Pakect Traser again in another 1 hr. Have you got the chance to look at it yet?

 

by: donmanrobbPosted on 2008-03-31 at 23:53:06ID: 21251722

Some of the problems I found with your network.
No connectivity. All serial links were up/down because no clock rate was configured on the DCE, done with clock rate 64000

Incorrect IP address was used, everything used a mask of 255.255.240.0 when you were asked to use variable subnetting for each segment.

RIP was also incorrectly configured. Version 2 should have been used because of the variable subnet requirements. Also split horizon needed to be disabled on all the WAN router's serial interfaces since RIP  by default will not send updates out to the spoke routers otherwise.

Lastly your ACL placement was incorrect, you tend to use both in/out directions on the same interface, careful planning is needed to know what kind of affect this would cause.

If I have time tonight 'll fix up the pkt file so you can see how it looks.

 

by: chipmatePosted on 2008-04-01 at 00:02:54ID: 21251760

Thanks a lot. I will look into the problems you just mention when you fix up my pkt file.

Many thanks.

 

by: donmanrobbPosted on 2008-04-01 at 01:47:16ID: 21252213

Here you go, you'll have to rename the file from Changes.pkt.txt to Changes.pkt

Let me know if you have any questions with what I done

 

by: donmanrobbPosted on 2008-04-01 at 01:58:34ID: 21252258

While double checking I found a couple changes didn't save.
All the servers should have a mask of 255.255.255.248
And the research computer should have a mask of 255.255.255.128

 

by: donmanrobbPosted on 2008-04-01 at 02:44:18ID: 21252431

I also have a couple recommendations for when you post another question on the site to improve your success.

If you need assistance in another assignment, please clearly state in the question that it is homework and what exactly you need a hand with as well as what you have tried rather then just posting the question requirements. Experts will be more likely to assist you if you make it clear that your trying to understand a problem rather then get some experts to do your homework. Also if the deadline is add the date to the question and possibly raise the point value of the question so we can better gauge the urgency.

Lastly, you have rated yourself a guru on the subject, but have said you don't have much experience with Cisco. This can mislead the experts and effect the level of help you receive. Since to us it looks like you have a firm understanding of the topic and requires minimal explaination to get you going.

 

by: chipmatePosted on 2008-04-01 at 07:56:03ID: 31442918

Thanks. Good help but take a some time to work it out.

 

by: chipmatePosted on 2008-04-01 at 07:59:38ID: 21254596

Thanks for your advice. I still not understand on the certain part of the Subnet and ACL. Would I be able to get your help later? I still can't granted the ACL but I will study it and work it out later.

 

by: donmanrobbPosted on 2008-04-01 at 15:03:53ID: 21258554

What did you need a hand with understanding?

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...