All guided builds

Guided buildadvanced9 steps~35 min8 devices

Campus capstone

Put it all together: two wiring closets, two VLANs, DHCP for the desks, and one public address for the whole site.

What you'll be able to do: A desktop in the second-floor closet gets its address from the router, opens a file on a server in another VLAN, and reaches a site on the internet from behind a single public address — the four jobs every small campus network actually does.

Start this build in the lab 8 devices — needs any paid plan (the free canvas fits 5).

Topics: VLANs · Trunking · Inter-VLAN routing · DHCP · NAT/PAT · Default routes

What you'll build

Step by step

  1. 1. Cut the campus into two VLANs

    This site carries two kinds of traffic that have no business sharing a broadcast domain: staff desktops and the servers they open files on. You made this split in VLANs on one switch — here it is again as the foundation of a whole campus, so VLAN 10 for the desks and VLAN 20 for the servers go in before a single cable does.

    On SW-Core — Name the core switch and define the two campus VLANs

    enable
    configure terminal
    hostname SW-Core
    vlan 10
    name STAFF
    exit
    vlan 20
    name SERVERS
    exit
    end

    Check: run show vlan brief on SW-Core and look for 10 STAFF.

    Why: Segmenting by role puts a routed boundary between the desks and the servers, and a routed boundary is where policy can be applied later: an ACL on the router can control what staff reach, which no rule could do inside one VLAN. It also keeps the desks' broadcast chatter away from the servers.

  2. 2. Give both VLANs a gateway on one router port

    Two VLANs need two gateways, and the edge router has one Ethernet port to spare for the LAN. Router on a stick is the answer: leave the physical port without an address, hang a tagged subinterface on it for each VLAN, and one cable carries both. The .1 addresses you set here are what every host on this campus will point at for the rest of its working life.

    • Cable Edge Gi0/0 ↔ SW-Core Gi0/1

    On Edge — Name the router, open the physical uplink, and add a subinterface per VLAN

    enable
    configure terminal
    hostname Edge
    interface Gi0/0
    no ip address
    no shutdown
    exit
    interface Gi0/0.10
    encapsulation dot1Q 10
    ip address 192.168.10.1 255.255.255.0
    no shutdown
    exit
    interface Gi0/0.20
    encapsulation dot1Q 20
    ip address 192.168.20.1 255.255.255.0
    no shutdown
    exit
    end

    Check: run show ip route on Edge and look for C 192.168.10.0/24 is directly connected, Gi0/0.10.

    Why: Each subinterface is a separate layer-3 interface with its own address, its own connected route and, later in this build, its own NAT role — the router treats them exactly as it would two physical ports, which is why every later feature is configured per subinterface rather than on Gi0/0.

  3. 3. Address the file server by hand

    Servers are the one class of machine that does not take its address from DHCP — nobody can bookmark a file share that moves. The server VLAN gets no pool at all: every address in it is written down somewhere and typed in, starting with 192.168.20.5 for FILE1. Cable it to Fa0/2 and hand that port to VLAN 20.

    • Cable FILE1 Eth0 ↔ SW-Core Fa0/2

    On SW-Core — Put Fa0/2 in the server VLAN as an untagged access port

    enable
    configure terminal
    interface Fa0/2
    switchport mode access
    switchport access vlan 20
    no shutdown
    end

    On FILE1 — Name the server and give it a fixed address in the server subnet

    hostname FILE1
    ipconfig Eth0 192.168.20.5 255.255.255.0 192.168.20.1

    Check: run show vlan brief on SW-Core and look for 20 SERVERS active Fa0/2.

    Why: Clients reach a server by its address — typed in, bookmarked or stored in a DNS record — so that address must never change. A pool leases addresses for a limited time and may give a machine a different one later, while a hand-typed address stays exactly where it was put.

  4. 4. Trunk the uplink so the VLANs can meet

    One cable has to carry two VLANs up to the router, and only a trunk labels frames on the way. Turning Gi0/1 into an 802.1Q trunk that allows 10 and 20 is what makes the two subinterfaces real: the moment you press enter, FILE1 can reach its own gateway and the staff gateway on the far side of the same port.

    On SW-Core — Turn the router-facing port into a tagged trunk carrying both VLANs

    enable
    configure terminal
    interface Gi0/1
    switchport mode trunk
    switchport trunk allowed vlan 10,20
    no shutdown
    end

    Check: run show interfaces trunk on SW-Core and look for Gi0/1 on 802.1q trunking 1.

    Why: FILE1's ping to 192.168.10.1 never enters VLAN 10: it goes up the trunk tagged 20, and the router answers for its own staff-side address on the spot. Reaching the far gateway proves the trunk and the VLAN 20 subinterface work, but nothing yet about VLAN 10's own ports — that is what the next step tests.

  5. 5. Let the desks address themselves with DHCP

    Desks are the opposite of servers: there are a lot of them, they come and go, and nobody wants to walk round typing addresses. Put the pool on the router that already owns the VLAN 10 gateway, reserve .1 through .9 for infrastructure that must never move, and let PC-Ann ask for the rest.

    • Cable PC-Ann Eth0 ↔ SW-Core Fa0/1

    On SW-Core — Put the desk port in the staff VLAN

    enable
    configure terminal
    interface Fa0/1
    switchport mode access
    switchport access vlan 10
    no shutdown
    end

    On Edge — Reserve the low addresses, then serve the rest of the staff subnet

    enable
    configure terminal
    ip dhcp excluded-address 192.168.10.1 192.168.10.9
    ip dhcp pool STAFF
    network 192.168.10.0 255.255.255.0
    default-router 192.168.10.1
    dns-server 9.9.9.9
    exit
    end

    On PC-Ann — Name the desktop and ask the network for an address

    hostname PC-Ann
    ipconfig /renew

    Check: run show ip dhcp binding on Edge and look for 192.168.10.10.

    Why: A client's Discover is a broadcast, and routers do not forward broadcasts, so a DHCP server has to sit in the client's broadcast domain or be reached through a relay. Edge qualifies because its Gi0/0.10 subinterface is a member of VLAN 10; a server anywhere else would need `ip helper-address` on the VLAN's gateway to forward the request.

  6. 6. Open the second-floor closet

    A campus design proves itself the second time you use it. Trunk the two switches together, give the new switch the same VLAN database, and PC-Ben leases an address from a pool sitting on a router two hops away without you touching that router at all — which is the entire reason to centralise DHCP.

    • Cable SW-Core Gi0/2 ↔ SW-Floor2 Gi0/1
    • Cable PC-Ben Eth0 ↔ SW-Floor2 Fa0/1

    On SW-Floor2 — Name the closet switch, mirror the VLAN database, trunk up and hand the desk to VLAN 10

    enable
    configure terminal
    hostname SW-Floor2
    vlan 10
    name STAFF
    exit
    vlan 20
    name SERVERS
    exit
    interface Gi0/1
    switchport mode trunk
    switchport trunk allowed vlan 10,20
    no shutdown
    exit
    interface Fa0/1
    switchport mode access
    switchport access vlan 10
    no shutdown
    exit
    end

    On SW-Core — Make the core's side of the inter-switch link a trunk too

    enable
    configure terminal
    interface Gi0/2
    switchport mode trunk
    switchport trunk allowed vlan 10,20
    no shutdown
    end

    On PC-Ben — Name the upstairs desktop and lease an address

    hostname PC-Ben
    ipconfig /renew

    Check: run show interfaces trunk on SW-Core and look for Gi0/2 on 802.1q trunking 1.

    Why: A VLAN is a broadcast domain, not a box: once both inter-switch ports are trunks carrying VLAN 10, PC-Ben's Discover floods through SW-Floor2, across the trunk and through SW-Core to Edge exactly as PC-Ann's did. Adding a closet adds ports to existing VLANs; the addressing plan and the pool stay the same.

  7. 7. Wire the campus to the provider

    The site works; now it needs a way out. A serial link to the provider, one public /30 across it, and a default route are the whole of it — anything that is not one of your own subnets leaves via 203.0.113.1. Ping 198.51.100.50 from PC-Ann and a reply comes back, which is worth looking at hard before you believe it.

    • Cable Edge Se0/0/0 ↔ ISP Se0/0/0 (serial)
    • Cable WEB1 Eth0 ↔ ISP Gi0/0

    On ISP — Stand up the provider: your side of the /30 and the LAN the web server lives on

    enable
    configure terminal
    hostname ISP
    interface Se0/0/0
    ip address 203.0.113.1 255.255.255.252
    no shutdown
    exit
    interface Gi0/0
    ip address 198.51.100.1 255.255.255.0
    no shutdown
    exit
    end

    On WEB1 — Address the public web server

    hostname WEB1
    ipconfig Eth0 198.51.100.50 255.255.255.0 198.51.100.1

    On Edge — Take the public /30 and send everything unknown to the provider

    enable
    configure terminal
    interface Se0/0/0
    ip address 203.0.113.2 255.255.255.252
    no shutdown
    exit
    ip route 0.0.0.0 0.0.0.0 203.0.113.1
    end

    On PC-Ann — Try the internet from a desk

    ping 198.51.100.50

    Check: run show ip route on Edge and look for S* 0.0.0.0/0 via 203.0.113.1, Se0/0/0.

    Why: A default route keeps an edge router's table small: instead of a route for every network on the internet, Edge holds its own subnets plus one entry that matches everything else and points at the provider — enough to reach every prefix on the internet without knowing any of them.

  8. 8. Make the lab honest — the provider drops private addresses

    That reply was a lab artefact. The packet that left the building carried the source address 192.168.10.10, which also exists inside a hundred thousand other networks, and no provider on earth will route it back to you. Put the filter a real provider already runs on its side of the link, and watch the whole campus fall off the internet — while Edge, whose serial port holds a public address, keeps getting answers.

    On ISP — Deny RFC 1918 sources arriving from the customer link

    enable
    configure terminal
    ip access-list extended NO-PRIVATE
    deny ip 192.168.0.0 0.0.255.255 any
    deny ip 10.0.0.0 0.255.255.255 any
    deny ip 172.16.0.0 0.15.255.255 any
    permit ip any any
    exit
    interface Se0/0/0
    ip access-group NO-PRIVATE in
    end

    On PC-Ann — Try the same ping again

    ping 198.51.100.50

    Check: run show access-lists on ISP and look for 10 deny ip 192.168.0.0 0.0.255.255 any.

    Why: Filtering is done where traffic enters a network because that is the only place it can be done reliably: at its customer-facing port the provider still knows which link a packet arrived on, and therefore which sources could legitimately be on it. One hop further in, the packet is mixed with everyone else's traffic and that knowledge is gone.

  9. 9. Translate the whole campus onto one public address

    NAT overload — PAT — rewrites the source of everything leaving the site to the router's own public address and keeps the conversations apart by port number. Mark both inside subinterfaces, mark the serial as outside, list the subnets allowed to be translated, and 250 desks go out behind 203.0.113.2 as convincingly as one.

    On Edge — Name the inside and outside of the NAT boundary, then overload the WAN address

    enable
    configure terminal
    interface Gi0/0.10
    ip nat inside
    exit
    interface Gi0/0.20
    ip nat inside
    exit
    interface Se0/0/0
    ip nat outside
    exit
    access-list 1 permit 192.168.10.0 0.0.0.255
    access-list 1 permit 192.168.20.0 0.0.0.255
    ip nat inside source list 1 interface Se0/0/0 overload
    end

    On PC-Ann — The campus is back on the internet

    ping 198.51.100.50

    On PC-Ben — And so is the upstairs desk

    ping 198.51.100.50

    Check: run show ip nat statistics on Edge and look for access-list 1 interface Se0/0/0 overload.

    Why: NAT roles belong to interfaces, not to VLANs or hosts: marking both subinterfaces inside and the serial outside tells Edge that anything routed from either VLAN out to the provider must be translated, while the access list decides which sources qualify.

The theory behind it

Build it for real

The lab walks you through these steps and ticks each one off as your network starts working.

Open in the lab
Campus capstone — step-by-step network lab · NetForge-AI