VLANs - Layer 3 Switches - HSRP - ASA 5505 - Router - Site to Site VPN

  Рет қаралды 30,440

Christian Augusto Romero Goyzueta

Christian Augusto Romero Goyzueta

Күн бұрын

Пікірлер: 111
@delta_eps8916
@delta_eps8916 4 жыл бұрын
Hello, 1) Why do you configure static route on core sw 2 at 11'45'' and not ospf route ? 2) At 19'40'' why do you use for FAI static route and not ospf ? 3) At 7'01'' you configure in core switch 1 in gig1/0/8 and gig1/0/9 => switchport mode access + switchport nonegotiate Why you don't configure in theses interfaces => switchport trunk native vlan 99 + switchport trunk encapsulation dot1q + switchport mode trunk ? Thanks a lot
@christianaugustoromerogoyz8177
@christianaugustoromerogoyz8177 4 жыл бұрын
Hello. These are the answers 1. and 2. ASA does not support OSPF, so that is why you need static routing 3. ASA can support trunks but in my case I'm using access ports on ASA and then neighbors like switches should use also access ports. Thank you
@rajan_
@rajan_ 3 жыл бұрын
On the left side the port-channel is 2, will there be same number on right side?
@christianaugustoromerogoyz8177
@christianaugustoromerogoyz8177 3 жыл бұрын
yes, should be the same number
@rajan_
@rajan_ 3 жыл бұрын
Very helpful tutorial, thanks. It will be very helpful if you can provide .pkt file or configurations in text file.
@christianaugustoromerogoyz8177
@christianaugustoromerogoyz8177 3 жыл бұрын
I don't have the packet tracer file and this video shows all the necessary configurations to complete the project
@m1rage92
@m1rage92 2 жыл бұрын
@Christian Augusto Romero Goyzueta II Hi bro sorry to bother I've been doing this practise and finish it but i still have an issue. If i try to ping from the LAN like PC1 (vlan 10 ==> to vlan interface 192.168.10.1 ) it works Each vlan can reach his interface , on the other part network is also working between routers BUT if i try from PC1 to reach the FAI ( 20.20.20.1 ) for example , the ping seems to not override the firewall Do you have maybe any ideas why ? Ty
@christianaugustoromerogoyz8177
@christianaugustoromerogoyz8177 2 жыл бұрын
you need to add a configuration on firewalls to pass ping (inspect icmp)
@stevezzorr
@stevezzorr 4 жыл бұрын
Thank you so much, very helpful material!
@christianaugustoromerogoyz8177
@christianaugustoromerogoyz8177 4 жыл бұрын
I appreciate, thank you
@rindu2909
@rindu2909 3 жыл бұрын
Hi chris, may i know where actually you configure the VLAN? through the access or at CORE 3 nor CORE 4? Thank you
@christianaugustoromerogoyz8177
@christianaugustoromerogoyz8177 3 жыл бұрын
Configure trunks, vlans and assign vlans to ports, all on Layer 2
@rindu2909
@rindu2909 3 жыл бұрын
@@christianaugustoromerogoyz8177 noted.thank U
@rindu2909
@rindu2909 3 жыл бұрын
Hi Chris. May i know if the gateway for syslog is 192.168.30.1? if yes, im not be able config the syslog and ping through the 192.168.30.1. could you advice? Thank you
@christianaugustoromerogoyz8177
@christianaugustoromerogoyz8177 3 жыл бұрын
@@rindu2909 please assign vlan 30 to the port connected from switch to server
@rindu2909
@rindu2909 3 жыл бұрын
@@christianaugustoromerogoyz8177 thank U chirs..im not assign the vlan at distribution layer...thank u so much..im able to ping now..may i know if you have lab related with vpn+wireless? TQ
@delta_eps8916
@delta_eps8916 4 жыл бұрын
Hello, If we had a link between ASA-1 and ASA-2. What zone would that be ? Thanks a lot
@christianaugustoromerogoyz8177
@christianaugustoromerogoyz8177 4 жыл бұрын
can be a new vlan, but you can use vlan 1 on that link
@jacka126
@jacka126 4 жыл бұрын
Hi, I have a question. I am doing almost identical topology like yours for my work security assignment and I have encountered a problem. On layer 3 switches cannot configure port-channel as I get this message "%EC-5-CANNOT_BUNDLE2: Fa0/24 is not compatible with Po3 and will be suspended (native VLAN of Fa0/24 is 99, Po3 id 1)" . First I have configured these ports as a native VLAN 99 and when I try to configure port-channel on fa0/21-24 it shows the above message. Please advice me. many thanks
@christianaugustoromerogoyz8177
@christianaugustoromerogoyz8177 4 жыл бұрын
when you configure a port channel or trunks, first shutdown the interfaces on all devices (two devices) then apply the configurations on the devices (two devices) finally enable the interfaces.
@hetalpanchal9433
@hetalpanchal9433 5 жыл бұрын
Very good video, thanks for uploading, please could you provide the output of show vlan and show int trunk of the access and core switches.
@christianaugustoromerogoyz8177
@christianaugustoromerogoyz8177 5 жыл бұрын
I sent you a message on google hangouts
@sylar5708
@sylar5708 3 жыл бұрын
Are the object network on ASA needed just to connect to ISP router? Do you have any other labs with 2 asa and 2 core switches?
@christianaugustoromerogoyz8177
@christianaugustoromerogoyz8177 3 жыл бұрын
yes, object network will use NAT to connect ASA to simulated Internet, I don't have more examples, but this playlist can have interesting projects kzbin.info/aero/PLdtRZtGMukf4GGF_jvBAuNQKZEnUi4TaQ
@sylar5708
@sylar5708 3 жыл бұрын
@@christianaugustoromerogoyz8177 What if i have only ISP router, without remote user and vpn. Will the NAT translation work with just 3 lines of "route inside etc" without object network?
@christianaugustoromerogoyz8177
@christianaugustoromerogoyz8177 3 жыл бұрын
@@sylar5708 for only one ISP you need NAT with object network, dynamic NAT
@sylar5708
@sylar5708 3 жыл бұрын
@@christianaugustoromerogoyz8177 Another question: Sometimes if i ping one of ISP ip from diffrent vlan pc's it doesnt work. What could be wrong? Is this because of one ASA being in standby mode? From core switches it is working fine.
@christianaugustoromerogoyz8177
@christianaugustoromerogoyz8177 3 жыл бұрын
@@sylar5708 ASA Firewalls are configured with static routing, and ISPs are configured with static routing, that is the problem, you can see the packet on simulation mode
@GA-tl4iy
@GA-tl4iy 4 жыл бұрын
WELL DONE BROTHER AUGUSTO, THANKS A LOT. GOD BLESS.
@christianaugustoromerogoyz8177
@christianaugustoromerogoyz8177 4 жыл бұрын
Thank you for your comment, I appreciate
@GA-tl4iy
@GA-tl4iy 4 жыл бұрын
@@christianaugustoromerogoyz8177 Just let you know, quality of video is very BAD, I can see and read text from packet tracer. if you can clear video to see better. Thanks anyway
@christianaugustoromerogoyz8177
@christianaugustoromerogoyz8177 4 жыл бұрын
@@GA-tl4iy please go to options and set video to 720 or 1080 quality
@GA-tl4iy
@GA-tl4iy 4 жыл бұрын
@@christianaugustoromerogoyz8177 I can not configure MAC-ADDRESS in VLANS, I have Cisco Packet Tracer 6.2 , Can you please advice? Appreciate
@christianaugustoromerogoyz8177
@christianaugustoromerogoyz8177 4 жыл бұрын
@@GA-tl4iy why do you need that¡
@delta_eps8916
@delta_eps8916 4 жыл бұрын
Hello, 1) Why do you use a vlan for network 172.160.0.0 /28 ? and why vlan 1 and not an other ? 2) If we don't use VLAN 1 for ASA it will there be a mistake ? 3) Why do you use VLAN 2 and 3 for the outside ? Can we just use adresse IP without VLAN for the ASA ? Thanks for the video bro
@christianaugustoromerogoyz8177
@christianaugustoromerogoyz8177 4 жыл бұрын
Hello, a lot of modifications are possible, and this is only an example thatmay vary
@walidharmel7619
@walidharmel7619 2 жыл бұрын
Hi, is it possible to use HSRP on vlan 1 (between coreSW1 and coreSW2)?
@christianaugustoromerogoyz8177
@christianaugustoromerogoyz8177 2 жыл бұрын
Yes, ,you can use HSRP on interfaces on layer 3 switches (CORESW1 CORESW2)
@telecomnetworking6819
@telecomnetworking6819 4 жыл бұрын
I face the problem of STP during the simulation, do you have any clues?
@christianaugustoromerogoyz8177
@christianaugustoromerogoyz8177 4 жыл бұрын
there are no STP configurations here but you can do it if is necessary,
@abhishekshah11
@abhishekshah11 4 жыл бұрын
What kept bothering me throughout the video was that your etherchannels are in blocking state by spanning tree. What's the use of etherchannel if they are blocked
@christianaugustoromerogoyz8177
@christianaugustoromerogoyz8177 4 жыл бұрын
etherchannel will be used for add bandwidth and multiple paths will be used if main paths fail (redundancy)
@abhishekshah11
@abhishekshah11 4 жыл бұрын
@@christianaugustoromerogoyz8177 No, between core switches, I assume one core is root for one vlan and the other switch is root for another vlan? So for intervlan routing, if the etherchannel is configured as a trunk port, you achieve intervlan routing.
@christianaugustoromerogoyz8177
@christianaugustoromerogoyz8177 4 жыл бұрын
@@abhishekshah11 That will work fine
@thepuldarshana9056
@thepuldarshana9056 Жыл бұрын
are you just showing preconfigured configurations ?
@christianaugustoromerogoyz8177
@christianaugustoromerogoyz8177 Жыл бұрын
This is the updated video, you can see all the configs kzbin.info/www/bejne/Z3aTeZ-rrd2qd80
@thepuldarshana9056
@thepuldarshana9056 Жыл бұрын
@@christianaugustoromerogoyz8177 thank you so much, I am now watching it. I am looking for a great tutorial like site to site VPN using ASA . Such as vlan users can assess servers in a remote location via VPN . For my Network University project.
@thepuldarshana9056
@thepuldarshana9056 Жыл бұрын
@@christianaugustoromerogoyz8177 Hi , I went through your video and very good practical. can I know , is it possible to configure the 2 ASAs with HSRP like you did to Core SW ? One ASA fails other ASA will come up ?
@christianaugustoromerogoyz8177
@christianaugustoromerogoyz8177 Жыл бұрын
@@thepuldarshana9056 ASA's are not supporting HSRP on packet tracer, but we need to verify that on real devices
@thepuldarshana9056
@thepuldarshana9056 Жыл бұрын
@@christianaugustoromerogoyz8177 ok I understand. Thank you
@SquashMtb
@SquashMtb 5 жыл бұрын
Hola Christian, ta bueno el Video, gracias. Saludos Christian
@christianaugustoromerogoyz8177
@christianaugustoromerogoyz8177 5 жыл бұрын
Gracias por tu comentario, lo aprecio bastante
@SquashMtb
@SquashMtb 5 жыл бұрын
@@christianaugustoromerogoyz8177 Hola, Te envie un email @ romeroc42@gmail.com echale una mirada,pls.
@delta_eps8916
@delta_eps8916 4 жыл бұрын
What does mean FAI ? it's like a second ISP ?
@christianaugustoromerogoyz8177
@christianaugustoromerogoyz8177 4 жыл бұрын
FAI is noly name, is a second ISP
@delta_eps8916
@delta_eps8916 4 жыл бұрын
Hello, At 15'34'', Why do you write in ASA-1 "object network NET_LOCAL subnet 192.168.0.0 255.255.0.0" ? Thanks a lot
@christianaugustoromerogoyz8177
@christianaugustoromerogoyz8177 4 жыл бұрын
you create two objects NET LOCAL and NET REMOTE, on next lines you will see ACL that is configured to permit traffic using the objects
@johnangara7714
@johnangara7714 2 жыл бұрын
Great topology! can i have the PKT file sir?
@christianaugustoromerogoyz8177
@christianaugustoromerogoyz8177 2 жыл бұрын
I don't have the file, please if you can capture the running-config shown in the video
@victorlin8098
@victorlin8098 4 жыл бұрын
your videos are so good for me :-) THank you so much for your great efforts to share!!!!!
@christianaugustoromerogoyz8177
@christianaugustoromerogoyz8177 4 жыл бұрын
Thank you for all your support, I appreciate
@danmounter2287
@danmounter2287 4 жыл бұрын
hello could you also send me outputs vlan and trunk briefs of access and core switches. great vid thank you
@christianaugustoromerogoyz8177
@christianaugustoromerogoyz8177 4 жыл бұрын
Hello, I just showed all configurations and I don't have the files with configurations, so please try to implement your own file.
@0Rkvishwakarma
@0Rkvishwakarma Жыл бұрын
can you please share a topology file.
@christianaugustoromerogoyz8177
@christianaugustoromerogoyz8177 Жыл бұрын
use social media shown on 00:03 but anyway there is an update kzbin.info/www/bejne/Z3aTeZ-rrd2qd80
@agariskika3486
@agariskika3486 4 жыл бұрын
Why My vlan 10 20 30 40 on CoreSw can't up?
@christianaugustoromerogoyz8177
@christianaugustoromerogoyz8177 4 жыл бұрын
please enable trunk interface or access interface on the device, also configure the vlans to add on vlan table.
@agariskika3486
@agariskika3486 4 жыл бұрын
@@christianaugustoromerogoyz8177 i mean the gateway vlan on layer 3 switches
@christianaugustoromerogoyz8177
@christianaugustoromerogoyz8177 4 жыл бұрын
@@agariskika3486 don't forget no shutdown command and configure an access port and assign to that vlan or configure trunks correctly
@agariskika3486
@agariskika3486 4 жыл бұрын
@@christianaugustoromerogoyz8177now the vlan is up, but can't ping the user, all trunk and access is done
@christianaugustoromerogoyz8177
@christianaugustoromerogoyz8177 4 жыл бұрын
@@agariskika3486 you need to configure routes, static routes
@networkingandittechnologie4440
@networkingandittechnologie4440 3 жыл бұрын
can you share the lab output please
@christianaugustoromerogoyz8177
@christianaugustoromerogoyz8177 3 жыл бұрын
hello, I don't have the file
@sdayabaran
@sdayabaran 3 жыл бұрын
Thanks for the video, can you please share the configurations command file, Thank you
@christianaugustoromerogoyz8177
@christianaugustoromerogoyz8177 3 жыл бұрын
I don't have the commands on text but video shows all commands please try those commands, will work
@user-fz4uo9it4m
@user-fz4uo9it4m 3 жыл бұрын
@@christianaugustoromerogoyz8177 Noted with thanks
@christianaugustoromerogoyz8177
@christianaugustoromerogoyz8177 3 жыл бұрын
@@user-fz4uo9it4m thank you
@sdayabaran
@sdayabaran 3 жыл бұрын
@@christianaugustoromerogoyz8177 Noted and thank you,
@sdayabaran
@sdayabaran 3 жыл бұрын
@@christianaugustoromerogoyz8177 I have setup your topology and having some issues so could you please give me the packet tracer file?
@guildoquiroga3229
@guildoquiroga3229 5 жыл бұрын
buenas cristian, muy buen video sirvio de gran ayuda tengo algunas con la configuracion del asa me podes ayudar ? tenes algun numero para poder comunicarme ?
@christianaugustoromerogoyz8177
@christianaugustoromerogoyz8177 5 жыл бұрын
Gracias por seguir mi canal, mi whatsapp es +51 931033196
@moidukp
@moidukp 2 жыл бұрын
hi
@christianaugustoromerogoyz8177
@christianaugustoromerogoyz8177 2 жыл бұрын
hi
@stivencastro7925
@stivencastro7925 4 жыл бұрын
hi, very good video. Can you please send me the pkt file?
@christianaugustoromerogoyz8177
@christianaugustoromerogoyz8177 4 жыл бұрын
I don't have the file, but you can create the file using this video
@brahmam-vadla
@brahmam-vadla Жыл бұрын
Hi Plz send Pkt Lab file. Thank you
@christianaugustoromerogoyz8177
@christianaugustoromerogoyz8177 Жыл бұрын
Hello, I'm sorry I don't have the file. You can use the video to configure all the network
@EMTMZ
@EMTMZ 5 жыл бұрын
Please improve the sound of video
@christianaugustoromerogoyz8177
@christianaugustoromerogoyz8177 5 жыл бұрын
thank you, I will do it
@thavymony8053
@thavymony8053 5 жыл бұрын
Can you give me your Lab?
@christianaugustoromerogoyz8177
@christianaugustoromerogoyz8177 5 жыл бұрын
I don't have the file, but please follow steps on video
@sayuri-3623
@sayuri-3623 6 жыл бұрын
hi, you can give me file.pkt
@christianaugustoromerogoyz8177
@christianaugustoromerogoyz8177 6 жыл бұрын
I don't have the file but I can do it again, romeroc42@gmail.com
@santanumanna7266
@santanumanna7266 5 жыл бұрын
please send me file.pkt or CONFIGURATION FILE on santanumanna365@gmail.com
@rehanmistry114
@rehanmistry114 5 жыл бұрын
Can you send me the packet tracer file on rehanmistry38@gmail.com
Configure Layer 3 Switching and inter-VLAN Routing
16:32
Saleh Al-Moghrabi (Sal)
Рет қаралды 83 М.
Configuring ASA 5505 Security Policy, IPsec VPN, DHCP, NAT, SSH, NTP, Practice Lab
50:49
didn't manage to catch the ball #tiktok
00:19
Анастасия Тарасова
Рет қаралды 34 МЛН
إخفاء الطعام سرًا تحت الطاولة للتناول لاحقًا 😏🍽️
00:28
حرف إبداعية للمنزل في 5 دقائق
Рет қаралды 84 МЛН
Router on a Stick Inter-VLAN Routing | CISCO Certification
29:14
ASA 5506 Basics - Packet Tracer 8.2 - DHCP, route, NAT, inspect, SSH
38:07
Christian Augusto Romero Goyzueta
Рет қаралды 2,8 М.
DO NOT design your network like this!! // FREE CCNA // EP 6
19:36
NetworkChuck
Рет қаралды 3,3 МЛН
Layer 3 Hardware Offloading Mikrotik - Deep Dive
30:45
Wilmer Almazan / The Network Trip
Рет қаралды 16 М.
Network Virtual LANs (VLANs), Explained Simply (VLANs, Part 1)
28:38
Doug Johnson Productions
Рет қаралды 151 М.
L3 Switching: HSRP Configuration
15:27
CBT Nuggets
Рет қаралды 135 М.
CCNA Topics - Connect a Layer 3 Switch to the Internet
16:53
Moustapha Fall - Formation Reseau IP
Рет қаралды 116 М.
didn't manage to catch the ball #tiktok
00:19
Анастасия Тарасова
Рет қаралды 34 МЛН