Guided buildadvanced9 steps~35 min8 devices
Campus capstone
Put it all together: two wiring closets, two VLANs, DHCP for the desks, and one public address for the whole site.
What you'll be able to do: A desktop in the second-floor closet gets its address from the router, opens a file on a server in another VLAN, and reaches a site on the internet from behind a single public address — the four jobs every small campus network actually does.
Topics: VLANs · Trunking · Inter-VLAN routing · DHCP · NAT/PAT · Default routes
What you'll build
- Edge — a router, the edge router: every VLAN's gateway and the only way out
- SW-Core — a switch, the core switch in the main comms room
- SW-Floor2 — a switch, the access switch in the second-floor closet
- PC-Ann — a pc, a staff desktop wired straight to the core
- PC-Ben — a pc, a staff desktop upstairs
- FILE1 — a server, the file server, alone on the server VLAN
- ISP — a router, the provider's router, standing in for the internet
- WEB1 — a server, a web server out on the internet
Step by step
1. Cut the campus into two VLANs
This site carries two kinds of traffic that have no business sharing a broadcast domain: staff desktops and the servers they open files on. You made this split in VLANs on one switch — here it is again as the foundation of a whole campus, so VLAN 10 for the desks and VLAN 20 for the servers go in before a single cable does.
On SW-Core — Name the core switch and define the two campus VLANs
enable configure terminal hostname SW-Core vlan 10 name STAFF exit vlan 20 name SERVERS exit endCheck: run
show vlan briefon SW-Core and look for10 STAFF.Why: Segmenting by role puts a routed boundary between the desks and the servers, and a routed boundary is where policy can be applied later: an ACL on the router can control what staff reach, which no rule could do inside one VLAN. It also keeps the desks' broadcast chatter away from the servers.
2. Give both VLANs a gateway on one router port
Two VLANs need two gateways, and the edge router has one Ethernet port to spare for the LAN. Router on a stick is the answer: leave the physical port without an address, hang a tagged subinterface on it for each VLAN, and one cable carries both. The .1 addresses you set here are what every host on this campus will point at for the rest of its working life.
- Cable Edge Gi0/0 ↔ SW-Core Gi0/1
On Edge — Name the router, open the physical uplink, and add a subinterface per VLAN
enable configure terminal hostname Edge interface Gi0/0 no ip address no shutdown exit interface Gi0/0.10 encapsulation dot1Q 10 ip address 192.168.10.1 255.255.255.0 no shutdown exit interface Gi0/0.20 encapsulation dot1Q 20 ip address 192.168.20.1 255.255.255.0 no shutdown exit endCheck: run
show ip routeon Edge and look forC 192.168.10.0/24 is directly connected, Gi0/0.10.Why: Each subinterface is a separate layer-3 interface with its own address, its own connected route and, later in this build, its own NAT role — the router treats them exactly as it would two physical ports, which is why every later feature is configured per subinterface rather than on Gi0/0.
3. Address the file server by hand
Servers are the one class of machine that does not take its address from DHCP — nobody can bookmark a file share that moves. The server VLAN gets no pool at all: every address in it is written down somewhere and typed in, starting with 192.168.20.5 for FILE1. Cable it to Fa0/2 and hand that port to VLAN 20.
- Cable FILE1 Eth0 ↔ SW-Core Fa0/2
On SW-Core — Put Fa0/2 in the server VLAN as an untagged access port
enable configure terminal interface Fa0/2 switchport mode access switchport access vlan 20 no shutdown endOn FILE1 — Name the server and give it a fixed address in the server subnet
hostname FILE1 ipconfig Eth0 192.168.20.5 255.255.255.0 192.168.20.1Check: run
show vlan briefon SW-Core and look for20 SERVERS active Fa0/2.Why: Clients reach a server by its address — typed in, bookmarked or stored in a DNS record — so that address must never change. A pool leases addresses for a limited time and may give a machine a different one later, while a hand-typed address stays exactly where it was put.
4. Trunk the uplink so the VLANs can meet
One cable has to carry two VLANs up to the router, and only a trunk labels frames on the way. Turning Gi0/1 into an 802.1Q trunk that allows 10 and 20 is what makes the two subinterfaces real: the moment you press enter, FILE1 can reach its own gateway and the staff gateway on the far side of the same port.
On SW-Core — Turn the router-facing port into a tagged trunk carrying both VLANs
enable configure terminal interface Gi0/1 switchport mode trunk switchport trunk allowed vlan 10,20 no shutdown endCheck: run
show interfaces trunkon SW-Core and look forGi0/1 on 802.1q trunking 1.Why: FILE1's ping to 192.168.10.1 never enters VLAN 10: it goes up the trunk tagged 20, and the router answers for its own staff-side address on the spot. Reaching the far gateway proves the trunk and the VLAN 20 subinterface work, but nothing yet about VLAN 10's own ports — that is what the next step tests.
5. Let the desks address themselves with DHCP
Desks are the opposite of servers: there are a lot of them, they come and go, and nobody wants to walk round typing addresses. Put the pool on the router that already owns the VLAN 10 gateway, reserve .1 through .9 for infrastructure that must never move, and let PC-Ann ask for the rest.
- Cable PC-Ann Eth0 ↔ SW-Core Fa0/1
On SW-Core — Put the desk port in the staff VLAN
enable configure terminal interface Fa0/1 switchport mode access switchport access vlan 10 no shutdown endOn Edge — Reserve the low addresses, then serve the rest of the staff subnet
enable configure terminal ip dhcp excluded-address 192.168.10.1 192.168.10.9 ip dhcp pool STAFF network 192.168.10.0 255.255.255.0 default-router 192.168.10.1 dns-server 9.9.9.9 exit endOn PC-Ann — Name the desktop and ask the network for an address
hostname PC-Ann ipconfig /renewCheck: run
show ip dhcp bindingon Edge and look for192.168.10.10.Why: A client's Discover is a broadcast, and routers do not forward broadcasts, so a DHCP server has to sit in the client's broadcast domain or be reached through a relay. Edge qualifies because its Gi0/0.10 subinterface is a member of VLAN 10; a server anywhere else would need `ip helper-address` on the VLAN's gateway to forward the request.
6. Open the second-floor closet
A campus design proves itself the second time you use it. Trunk the two switches together, give the new switch the same VLAN database, and PC-Ben leases an address from a pool sitting on a router two hops away without you touching that router at all — which is the entire reason to centralise DHCP.
- Cable SW-Core Gi0/2 ↔ SW-Floor2 Gi0/1
- Cable PC-Ben Eth0 ↔ SW-Floor2 Fa0/1
On SW-Floor2 — Name the closet switch, mirror the VLAN database, trunk up and hand the desk to VLAN 10
enable configure terminal hostname SW-Floor2 vlan 10 name STAFF exit vlan 20 name SERVERS exit interface Gi0/1 switchport mode trunk switchport trunk allowed vlan 10,20 no shutdown exit interface Fa0/1 switchport mode access switchport access vlan 10 no shutdown exit endOn SW-Core — Make the core's side of the inter-switch link a trunk too
enable configure terminal interface Gi0/2 switchport mode trunk switchport trunk allowed vlan 10,20 no shutdown endOn PC-Ben — Name the upstairs desktop and lease an address
hostname PC-Ben ipconfig /renewCheck: run
show interfaces trunkon SW-Core and look forGi0/2 on 802.1q trunking 1.Why: A VLAN is a broadcast domain, not a box: once both inter-switch ports are trunks carrying VLAN 10, PC-Ben's Discover floods through SW-Floor2, across the trunk and through SW-Core to Edge exactly as PC-Ann's did. Adding a closet adds ports to existing VLANs; the addressing plan and the pool stay the same.
7. Wire the campus to the provider
The site works; now it needs a way out. A serial link to the provider, one public /30 across it, and a default route are the whole of it — anything that is not one of your own subnets leaves via 203.0.113.1. Ping 198.51.100.50 from PC-Ann and a reply comes back, which is worth looking at hard before you believe it.
- Cable Edge Se0/0/0 ↔ ISP Se0/0/0 (serial)
- Cable WEB1 Eth0 ↔ ISP Gi0/0
On ISP — Stand up the provider: your side of the /30 and the LAN the web server lives on
enable configure terminal hostname ISP interface Se0/0/0 ip address 203.0.113.1 255.255.255.252 no shutdown exit interface Gi0/0 ip address 198.51.100.1 255.255.255.0 no shutdown exit endOn WEB1 — Address the public web server
hostname WEB1 ipconfig Eth0 198.51.100.50 255.255.255.0 198.51.100.1On Edge — Take the public /30 and send everything unknown to the provider
enable configure terminal interface Se0/0/0 ip address 203.0.113.2 255.255.255.252 no shutdown exit ip route 0.0.0.0 0.0.0.0 203.0.113.1 endOn PC-Ann — Try the internet from a desk
ping 198.51.100.50Check: run
show ip routeon Edge and look forS* 0.0.0.0/0 via 203.0.113.1, Se0/0/0.Why: A default route keeps an edge router's table small: instead of a route for every network on the internet, Edge holds its own subnets plus one entry that matches everything else and points at the provider — enough to reach every prefix on the internet without knowing any of them.
8. Make the lab honest — the provider drops private addresses
That reply was a lab artefact. The packet that left the building carried the source address 192.168.10.10, which also exists inside a hundred thousand other networks, and no provider on earth will route it back to you. Put the filter a real provider already runs on its side of the link, and watch the whole campus fall off the internet — while Edge, whose serial port holds a public address, keeps getting answers.
On ISP — Deny RFC 1918 sources arriving from the customer link
enable configure terminal ip access-list extended NO-PRIVATE deny ip 192.168.0.0 0.0.255.255 any deny ip 10.0.0.0 0.255.255.255 any deny ip 172.16.0.0 0.15.255.255 any permit ip any any exit interface Se0/0/0 ip access-group NO-PRIVATE in endOn PC-Ann — Try the same ping again
ping 198.51.100.50Check: run
show access-listson ISP and look for10 deny ip 192.168.0.0 0.0.255.255 any.Why: Filtering is done where traffic enters a network because that is the only place it can be done reliably: at its customer-facing port the provider still knows which link a packet arrived on, and therefore which sources could legitimately be on it. One hop further in, the packet is mixed with everyone else's traffic and that knowledge is gone.
9. Translate the whole campus onto one public address
NAT overload — PAT — rewrites the source of everything leaving the site to the router's own public address and keeps the conversations apart by port number. Mark both inside subinterfaces, mark the serial as outside, list the subnets allowed to be translated, and 250 desks go out behind 203.0.113.2 as convincingly as one.
On Edge — Name the inside and outside of the NAT boundary, then overload the WAN address
enable configure terminal interface Gi0/0.10 ip nat inside exit interface Gi0/0.20 ip nat inside exit interface Se0/0/0 ip nat outside exit access-list 1 permit 192.168.10.0 0.0.0.255 access-list 1 permit 192.168.20.0 0.0.0.255 ip nat inside source list 1 interface Se0/0/0 overload endOn PC-Ann — The campus is back on the internet
ping 198.51.100.50On PC-Ben — And so is the upstairs desk
ping 198.51.100.50Check: run
show ip nat statisticson Edge and look foraccess-list 1 interface Se0/0/0 overload.Why: NAT roles belong to interfaces, not to VLANs or hosts: marking both subinterfaces inside and the serial outside tells Edge that anything routed from either VLAN out to the provider must be translated, while the access list decides which sources qualify.
The theory behind it
More in Capstones
- Branch office capstone — Staff and guests on one switch: guests lease an address the moment they plug in, reach the internet, and never see a staff file.
- Redundant campus — Double every link and box between a desk and HQ — bundled, spanning-tree protected, VRRP gateways, twin OSPF circuits — then break two of them and keep working.
Build it for real
The lab walks you through these steps and ticks each one off as your network starts working.
Open in the lab