Вы находитесь на странице: 1из 6

Router 1

Visitantes vlan70 fa0/0.70


Visitantes1 a internet:
access-list 101 permit ip 172.20.13.0 0.0.0.127 10.0.0.0 0.255.255.255
Visitantes1 a sw:
access-list 101 permit tcp 172.20.13.0 0.0.0.127 host 172.20.10.126 eq www
AdminsitracionRed Vlan10 fa 0/0.10
AdminRed1 a AdminRed2
access-list 102 permit ip 172.20.0.0 0.0.0.127 172.20.1.0 0.0.0.127
AdminRed1 a AdminRed3
access-list 102 permit ip 172.20.0.0 0.0.0.127 172.20.2.0 0.0.0.127
AdminRed1 a Internet
access-list 102 permit ip 172.20.0.0 0.0.0.127 10.0.0.0 0.255.255.255
AdminRed1 a SW
access-list 102 permit tcp 172.20.0.0 0.0.0.127 host 172.20.10.126 eq www
AdminRed1 a FTP
access-list 102 permit tcp 172.20.0.0 0.0.0.127 host 172.20.10.125 eq ftp
AdminRed1 a DNS
access-list 102 permit udp 172.20.0.0 0.0.0.127 host 172.20.10.125 eq domain
PAS VLAN40 FA0/0.40
PAS1 a PAS2
access-list 103 permit ip 172.20.6.0 0.0.0.127 172.20.7.0 0.0.0.127
PAS1 A INTERNET
access-list 103 permit ip 172.20.6.0 0.0.0.127 10.0.0.0 0.255.255.255
PAS1 A SW
access-list 103 permit tcp 172.20.6.0 0.0.0.127 host 172.20.10.126 eq www
PAS1 A FTP
access-list 103 permit tcp 172.20.6.0 0.0.0.127 host 172.20.10.125 eq ftp
PAS1 A DNS
access-list 103 permit udp 172.20.6.0 0.0.0.127 host 172.20.10.125 eq domain
RECURSOS
I3.adminred a adminRed1
Access-list 104 permit ip 172.20.10.124 0.0.0.127 172.20.0.0 0.0.0.127
I3.adminred a adminRed2
Access-list 104 permit ip 172.20.10.124 0.0.0.127 172.20.1.0 0.0.0.127
I3.adminred a adminRed3
Access-list 104 permit ip 172.20.10.124 0.0.0.127 172.20.2.0 0.0.0.127

Trafico dhcp en todas


access-list 120 permit udp any any eq 67
interface fastethernet 0/0.70
ip access-group 101 in
interface fastethernet 0/0.10
ip access-group 102 in
interface fastethernet 0/0.40
ip access-group 103 in
interface fastethernet 0/0.60
ip access-group 104 in

interface fastethernet 0/0.10


ip access-group 120 in
interface fastethernet 0/0.20
ip access-group 120 in
interface fastethernet 0/0.30
ip access-group 120 in
interface fastethernet 0/0.40
ip access-group 120 in
interface fastethernet 0/0.50
ip access-group 120 in
interface fastethernet 0/0.60
ip access-group 120 in
interface fastethernet 0/0.70
ip access-group 120 in
router2
vlan 70 fa0/0.70
visitantes 2 a internet
access-list 105 permit ip 172.20.14.0 0.0.0.127 10.0.0.0 0.255.255.255
visitantes 2 a sw
access-list 105 permit tcp 172.20.14.0 0.0.0.127 host 172.20.10.126 eq www
administracion2 vlan10 . fa0/0.10
ad2 a ad1
access-list 106 permit ip 172.20.1.0 0.0.0.127 172.20.0.0 0.0.0.127
ad2 a ad3
access-list 106 permit ip 172.20.1.0 0.0.0.127 172.20.2.0 0.0.0.127
ad2 a internet
access-list 106 permit ip 172.20.1.0 0.0.0.127 10.0.0.0 0.255.255.255
ad2 a sw
access-list 106 permit tcp 172.20.1.0 0.0.0.127 host 172.20.10.126 eq www

ad2 a sftp
access-list 106 permit tcp 172.20.1.0 0.0.0.127 host 172.20.10.125 eq ftp
ad2 a sdns
access-list 106 permit udp 172.20.1.0 0.0.0.127 host 172.20.10.125 eq domain
Profesores2 VLAN 50
access-list 107 permit ip 172.20.8.0 0.0.0.127 172.20.9.0 0.0.0.127
access-list 107 permit ip 172.20.8.0 0.0.0.127 10.0.0.0 0.255.255.255
access-list 107 permit tcp 172.20.8.0 0.0.0.127 host 172.20.10.126 eq www
access-list 107 permit tcp 172.20.8.0 0.0.0.127 host 172.20.10.125 eq ftp
access-list 107 permit udp 172.20.8.0 0.0.0.127 host 172.20.10.125 eq domain
PAS2 VLAN 40
access-list 108 permit udp 172.20.7.0 0.0.0.127 host 172.20.10.125 eq domain
access-list 108 permit tcp 172.20.7.0 0.0.0.127 host 172.20.10.125 eq ftp
access-list 108 permit tcp 172.20.7.0 0.0.0.127 host 172.20.10.126 eq www
access-list 108 permit ip 172.20.7.0 0.0.0.127 10.0.0.0 0.255.255.255
access-list 108 permit ip 172.20.7.0 0.0.0.127 172.20.6.0 0.0.0.127
ESTUDIANTES2 30
access-list 109 permit udp 172.20.4.0 0.0.0.127 host 172.20.10.125 eq domain
access-list 109 permit tcp 172.20.4.0 0.0.0.127 host 172.20.10.125 eq ftp
access-list 109 permit tcp 172.20.4.0 0.0.0.127 host 172.20.10.126 eq www
access-list 109 permit ip 172.20.4.0 0.0.0.127 172.20.5.0 0.0.0.127
access-list 109 permit ip 172.20.4.0 0.0.0.127 10.0.0.0 0.255.255.255
recursos 60
i2.2 para todos
access-list 110 permit ip 172.20.11.123 0.0.0.127 any
access-list 110 permit ip 172.20.11.124 0.0.0.127 any
access-list 110 permit ip 172.20.11.125 0.0.0.127 any
access-list 110 permit udp host 172.20.10.125 any eq bootps
access-list 120 permit udp any any eq 67
interface fastehthernet 0/0.70
ip access-group 105 in
interface fastehthernet 0/0.10
ip access-group 106 in
interface fastehthernet 0/0.50
ip access-group 107 in
interface fastehthernet 0/0.40
ip access-group 108 in

interface fastehthernet 0/0.30


ip access-group 109 in
interface fastehthernet 0/0.60
ip access-group 104 in

interface fastethernet 0/0.10


ip access-group 120 in
interface fastethernet 0/0.20
ip access-group 120 in
interface fastethernet 0/0.30
ip access-group 120 in
interface fastethernet 0/0.40
ip access-group 120 in
interface fastethernet 0/0.50
ip access-group 120 in
interface fastethernet 0/0.60
ip access-group 120 in
interface fastethernet 0/0.70
ip access-group 120 in
ROUTER3
VISITANTES3 --> 70
access-list 111 permit ip 172.20.15.0 0.0.0.127 10.0.0.0 0.255.255.255
access-list 111 permit tcp 172.20.15.0 0.0.0.127 host 172.20.10.126 eq www
ADMINISTRACION3 --> 10
ad3 a ad1
access-list 112 permit ip 172.20.2.0 0.0.0.127 172.20.0.0 0.0.0.127
ad3 a ad2
access-list 112 permit ip 172.20.2.0 0.0.0.127 172.20.1.0 0.0.0.127
ad2 a internet
access-list 112 permit ip 172.20.2.0 0.0.0.127 10.0.0.0 0.255.255.255
ad2 a sw
access-list 112 permit tcp 172.20.2.0 0.0.0.127 host 172.20.10.126 eq www
ad2 a sftp
access-list 112 permit tcp 172.20.2.0 0.0.0.127 host 172.20.10.125 eq ftp
ad2 a sdns
access-list 112 permit udp 172.20.2.0 0.0.0.127 host 172.20.10.125 eq domain

PROFESORES 3 VLAN 50
access-list 113 permit ip 172.20.9.0 0.0.0.127 172.20.8.0 0.0.0.127

access-list 113 permit ip 172.20.9.0 0.0.0.127 10.0.0.0 0.255.255.255


access-list 113 permit tcp 172.20.9.0 0.0.0.127 host 172.20.10.126 eq www
access-list 113 permit tcp 172.20.9.0 0.0.0.127 host 172.20.10.125 eq ftp
access-list 113 permit udp 172.20.9.0 0.0.0.127 host 172.20.10.125 eq domain

ESTUDIANTES3 30
access-list 114 permit ip 172.20.5.0 0.0.0.127 10.0.0.0 0.255.255.255
access-list 114 permit ip 172.20.5.0 0.0.0.127 172.20.4.0 0.0.0.127
access-list 114 permit udp 172.20.5.0 0.0.0.127 host 172.20.10.125 eq domain
access-list 114 permit tcp 172.20.5.0 0.0.0.127 host 172.20.10.125 eq ftp
access-list 114 permit tcp 172.20.5.0 0.0.0.127 host 172.20.10.126 eq www
recursos 60
i2.2 para todos
access-list 115 permit ip 172.20.9.12 0.0.0.127 172.20.8.0 0.0.0.127
access-list 115 permit ip 172.20.9.12 0.0.0.127 172.20.9.0 0.0.0.127
access-list 115 permit ip 172.20.12.126 0.0.0.127 any

interface fastethernet 0/0.70


ip access-group 111 in
interface fastethernet 0/0.10
ip access-group 112 in
interface fastethernet 0/0.50
ip access-group 113 in
interface fastethernet 0/0.30
ip access-group 114 in
interface fastethernet 0/0.60
ip access-group 115 in

access-list 120 permit udp any any eq 67

interface fastethernet 0/0.10


ip access-group 120 in
interface fastethernet 0/0.20
ip access-group 120 in
interface fastethernet 0/0.30

ip access-group 120 in
interface fastethernet 0/0.40
ip access-group 120 in
interface fastethernet 0/0.50
ip access-group 120 in
interface fastethernet 0/0.60
ip access-group 120 in
interface fastethernet 0/0.70
ip access-group 120 in

Вам также может понравиться