MacBook-Pro-de-Carlos:~ carlosc$ whoami
carlosc
do shell script "/Applications/Wireshark.app/Contents/MacOS/Wireshark" user name "carlosc" password "password" with administrator privileges
freebsd, unix, openbsd, servidores, bsd, redes, linux, mikrotik, synology, zfs,
MacBook-Pro-de-Carlos:~ carlosc$ whoami
carlosc
do shell script "/Applications/Wireshark.app/Contents/MacOS/Wireshark" user name "carlosc" password "password" with administrator privileges
Optimizar el espacio de direcciones
No desperdiciar IPs
Comprobar ping y tracert entre PC-10,
MA-PC1 y ZA-PC1
Desde Hasta VLAN
67.83.0.1 - 67.83.0.254 10
67.83.1.1 - 67.83.1.254 20
67.83.2.1 - 67.83.2.254 30
67.83.3.1 - 67.83.3.126 40
67.83.3.129 - 67.83.3.190 --
67.83.3.193 - 67.83.3.254 --
67.83.4.1 - 67.83.4.6 --
Interface IP-Address OK? Method Status Protocol
GigabitEthernet1/0/1 unassigned YES unset up up
GigabitEthernet1/0/2 unassigned YES unset up up
GigabitEthernet1/0/3 unassigned YES unset down down
GigabitEthernet1/0/4 unassigned YES unset down down
GigabitEthernet1/0/5 unassigned YES unset down down
GigabitEthernet1/0/6 unassigned YES unset down down
GigabitEthernet1/0/7 unassigned YES unset down down
GigabitEthernet1/0/8 unassigned YES unset down down
GigabitEthernet1/0/9 unassigned YES unset down down
GigabitEthernet1/0/10 unassigned YES unset down down
GigabitEthernet1/0/11 unassigned YES unset down down
GigabitEthernet1/0/12 unassigned YES unset down down
GigabitEthernet1/0/13 unassigned YES unset down down
GigabitEthernet1/0/14 unassigned YES unset up up
GigabitEthernet1/0/15 unassigned YES unset up up
GigabitEthernet1/0/16 unassigned YES unset down down
GigabitEthernet1/0/17 unassigned YES unset down down
GigabitEthernet1/0/18 unassigned YES unset down down
GigabitEthernet1/0/19 unassigned YES unset down down
GigabitEthernet1/0/20 unassigned YES unset down down
GigabitEthernet1/0/21 unassigned YES unset down down
GigabitEthernet1/0/22 unassigned YES unset down down
GigabitEthernet1/0/23 unassigned YES unset down down
GigabitEthernet1/0/24 unassigned YES unset down down
GigabitEthernet1/1/1 unassigned YES unset down down
GigabitEthernet1/1/2 unassigned YES unset down down
GigabitEthernet1/1/3 unassigned YES unset down down
GigabitEthernet1/1/4 unassigned YES unset down down
Loopback0 11.11.11.11 YES manual up up
Vlan1 unassigned YES unset administratively down down
Vlan10 67.83.0.1 YES manual up up
Vlan20 67.83.1.1 YES manual up up
Vlan30 67.83.2.1 YES manual up up
Vlan40 67.83.3.1 YES manual up up
Core1#
Capability Codes: R - Router, T - Trans Bridge, B - Source Route Bridge
S - Switch, H - Host, I - IGMP, r - Repeater, P - Phone
Device ID Local Intrfce Holdtme Capability Platform Port ID
R1-NV Gig 1/0/1 157 R C2900 Gig 0/0
Core2 Gig 1/0/15 157 3650 Gig 1/0/15
Access Gig 1/0/2 120 S 2960 Fas 0/1
Core2 Gig 1/0/14 157 3650 Gig 1/0/14
Core1#
Core1#conf t
Enter configuration commands, one per line. End with CNTL/Z.
Core1(config)#interface g
Core1(config)#interface gigabitEthernet 1/0/1
Core1(config-if)#sw
Core1(config-if)#switchport mode
Core1(config-if)#switchport mode access
Core1(config-if)#switchport access
Core1(config-if)#switchport access vlan 40
Core1(config-if)#
Core1(config-if)#exit
Core1(config)#interface gigabitEthernet 1/0/2
Core1(config-if)#switchport trunk encapsulation dot1q
Core1(config-if)#switchport mode trunk
Core1(config-if)#switchport trunk allowed vlan 1,10,30,40
Core1(config-if)#exit
Core1(config)#interface gigabitEthernet 1/0/14
Core1(config-if)#switchport trunk encapsulation dot1q
Core1(config-if)#switchport mode trunk
Core1(config-if)#switchport trunk allowed vlan 1,10,30,40
Core1(config-if)#exit
Core1(config)#interface gigabitEthernet 1/0/15
Core1(config-if)#switchport trunk encapsulation dot1q
Core1(config-if)#switchport mode trunk
Core1(config-if)#switchport trunk allowed vlan 1,10,30,40
Core1(config-if)#
Core1#sh interfaces trunk
Port Mode Encapsulation Status Native vlan
Gig1/0/2 on 802.1q trunking 1
Gig1/0/14 on 802.1q trunking 1
Gig1/0/15 on 802.1q trunking 1
Port Vlans allowed on trunk
Gig1/0/2 1,10,20,30,40
Gig1/0/14 1,10,20,30,40
Gig1/0/15 1,10,20,30,40
Port Vlans allowed and active in management domain
Gig1/0/2 1,10,20,30,40
Gig1/0/14 1,10,20,30,40
Gig1/0/15 1,10,20,30,40
Port Vlans in spanning tree forwarding state and not pruned
Gig1/0/2 1,10,20,30,40
Gig1/0/14 1,10,20,30,40
Gig1/0/15 none
VLAN Name Status Ports
---- -------------------------------- --------- -------------------------------
1 default active Gig1/0/3, Gig1/0/4, Gig1/0/5, Gig1/0/6
Gig1/0/7, Gig1/0/8, Gig1/0/9, Gig1/0/10
Gig1/0/11, Gig1/0/12, Gig1/0/13, Gig1/0/16
Gig1/0/17, Gig1/0/18, Gig1/0/19, Gig1/0/20
Gig1/0/21, Gig1/0/22, Gig1/0/23, Gig1/0/24
Gig1/1/1, Gig1/1/2, Gig1/1/3, Gig1/1/4
10 VLAN10 active
20 VLAN20 active
30 VLAN30 active
40 VLAN40 active Gig1/0/1
1002 fddi-default act/unsup
1003 token-ring-default act/unsup
1004 fddinet-default act/unsup
1005 trnet-default act/unsup
VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Trans1 Trans2
---- ----- ---------- ----- ------ ------ -------- ---- -------- ------ ------
1 enet 100001 1500 - - - - - 0 0
10 enet 100010 1500 - - - - - 0 0
20 enet 100020 1500 - - - - - 0 0
30 enet 100030 1500 - - - - - 0 0
40 enet 100040 1500 - - - - - 0 0
1002 fddi 101002 1500 - - - - - 0 0
1003 tr 101003 1500 - - - - - 0 0
1004 fdnet 101004 1500 - - - ieee - 0 0
1005 trnet 101005 1500 - - - ibm - 0 0
VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Trans1 Trans2
---- ----- ---------- ----- ------ ------ -------- ---- -------- ------ ------
Remote SPAN VLANs
------------------------------------------------------------------------------
Primary Secondary Type Ports
------- --------- ----------------- ------------------------------------------
Core1#
Capability Codes: R - Router, T - Trans Bridge, B - Source Route Bridge
S - Switch, H - Host, I - IGMP, r - Repeater, P - Phone
Device ID Local Intrfce Holdtme Capability Platform Port ID
Core1 Gig 1/0/15 174 3650 Gig 1/0/15
Core1 Gig 1/0/14 174 3650 Gig 1/0/14
Access Gig 1/0/1 174 S 2960 Fas 0/4
Core2#
Enter configuration commands, one per line. End with CNTL/Z.
Core2(config)#inter
Core2(config)#interface g
Core2(config)#interface gigabitEthernet 1/0/1
Core2(config-if)#switchport trunk encapsulation do
Core2(config-if)#switchport trunk encapsulation dot1q
Core2(config-if)#switchport mode trunk
Core2(config-if)#switchport trunk allowed vlan 1,10,20,30,40
Core2(config-if)#exit
Core2(config)#interface gigabitEthernet 1/0/14
Core2(config-if)#switchport trunk encapsulation dot1q
Core2(config-if)#switchport mode trunk
Core2(config-if)#switchport trunk allowed vlan 1,10,20,30,40
Core2(config-if)#exit
Core2(config)#interface gigabitEthernet 1/0/15
Core2(config-if)#switchport trunk encapsulation dot1q
Core2(config-if)#switchport mode trunk
Core2(config-if)#switchport trunk allowed vlan 1,10,20,30,40
Core2(config-if)#exit
Core2(config)#
Core2#sh interfaces trunk
Port Mode Encapsulation Status Native vlan
Gig1/0/1 on 802.1q trunking 1
Gig1/0/14 on 802.1q trunking 1
Gig1/0/15 on 802.1q trunking 1
Port Vlans allowed on trunk
Gig1/0/1 1,10,20,30,40
Gig1/0/14 1,10,20,30,40
Gig1/0/15 1,10,20,30,40
Port Vlans allowed and active in management domain
Gig1/0/1 1,10,20,30,40
Gig1/0/14 1,10,20,30,40
Gig1/0/15 1,10,20,30,40
Port Vlans in spanning tree forwarding state and not pruned
Gig1/0/1 1,10,20,30,40
Gig1/0/14 1,10,20,30,40
Gig1/0/15 10,20,30
Core2#
Enter configuration commands, one per line. End with CNTL/Z.
Core2(config)#interface loo
Core2(config)#interface loopback 0
Core2(config-if)#ip add
Core2(config-if)#ip address 22.22.22.22 255.255.255.255
Interface IP-Address OK? Method Status Protocol
GigabitEthernet1/0/1 unassigned YES unset up up
GigabitEthernet1/0/2 unassigned YES unset down down
GigabitEthernet1/0/3 unassigned YES unset down down
GigabitEthernet1/0/4 unassigned YES unset down down
GigabitEthernet1/0/5 unassigned YES unset down down
GigabitEthernet1/0/6 unassigned YES unset down down
GigabitEthernet1/0/7 unassigned YES unset down down
GigabitEthernet1/0/8 unassigned YES unset down down
GigabitEthernet1/0/9 unassigned YES unset down down
GigabitEthernet1/0/10 unassigned YES unset down down
GigabitEthernet1/0/11 unassigned YES unset down down
GigabitEthernet1/0/12 unassigned YES unset down down
GigabitEthernet1/0/13 unassigned YES unset down down
GigabitEthernet1/0/14 unassigned YES unset up up
GigabitEthernet1/0/15 unassigned YES unset up up
GigabitEthernet1/0/16 unassigned YES unset down down
GigabitEthernet1/0/17 unassigned YES unset down down
GigabitEthernet1/0/18 unassigned YES unset down down
GigabitEthernet1/0/19 unassigned YES unset down down
GigabitEthernet1/0/20 unassigned YES unset down down
GigabitEthernet1/0/21 unassigned YES unset down down
GigabitEthernet1/0/22 unassigned YES unset down down
GigabitEthernet1/0/23 unassigned YES unset down down
GigabitEthernet1/0/24 unassigned YES unset down down
GigabitEthernet1/1/1 unassigned YES unset down down
GigabitEthernet1/1/2 unassigned YES unset down down
GigabitEthernet1/1/3 unassigned YES unset down down
GigabitEthernet1/1/4 unassigned YES unset down down
Loopback0 22.22.22.22 YES manual up up
Vlan1 unassigned YES unset administratively down down
Vlan10 67.83.0.2 YES manual up up
Vlan20 67.83.1.2 YES manual up up
Vlan30 67.83.2.2 YES manual up up
Vlan40 67.83.3.2 YES manual up up
Core2#
Core2#sh vlan
VLAN Name Status Ports
---- -------------------------------- --------- -------------------------------
1 default active Gig1/0/2, Gig1/0/3, Gig1/0/4, Gig1/0/5
Gig1/0/6, Gig1/0/7, Gig1/0/8, Gig1/0/9
Gig1/0/10, Gig1/0/11, Gig1/0/12, Gig1/0/13
Gig1/0/16, Gig1/0/17, Gig1/0/18, Gig1/0/19
Gig1/0/20, Gig1/0/21, Gig1/0/22, Gig1/0/23
Gig1/0/24, Gig1/1/1, Gig1/1/2, Gig1/1/3
Gig1/1/4
10 VLAN0010 active
20 VLAN0020 active
30 VLAN0030 active
40 VLAN0040 active
1002 fddi-default act/unsup
1003 token-ring-default act/unsup
1004 fddinet-default act/unsup
1005 trnet-default act/unsup
VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Trans1 Trans2
---- ----- ---------- ----- ------ ------ -------- ---- -------- ------ ------
1 enet 100001 1500 - - - - - 0 0
10 enet 100010 1500 - - - - - 0 0
20 enet 100020 1500 - - - - - 0 0
30 enet 100030 1500 - - - - - 0 0
40 enet 100040 1500 - - - - - 0 0
1002 fddi 101002 1500 - - - - - 0 0
1003 tr 101003 1500 - - - - - 0 0
1004 fdnet 101004 1500 - - - ieee - 0 0
1005 trnet 101005 1500 - - - ibm - 0 0
VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Trans1 Trans2
---- ----- ---------- ----- ------ ------ -------- ---- -------- ------ ------
Remote SPAN VLANs
------------------------------------------------------------------------------
Primary Secondary Type Ports
------- --------- ----------------- ------------------------------------------
Core2#
Capability Codes: R - Router, T - Trans Bridge, B - Source Route Bridge
S - Switch, H - Host, I - IGMP, r - Repeater, P - Phone
Device ID Local Intrfce Holdtme Capability Platform Port ID
MAN Gig 0/1 152 S 2960 Fas 0/1
Core1 Fas 0/0/0 152 3650 Gig 1/0/1
R1-NV#
Enter configuration commands, one per line. End with CNTL/Z.
R1-NV(config)#interface g
R1-NV(config)#interface gigabitEthernet 0/0
R1-NV(config-if)#ip add
R1-NV(config-if)#ip address 67.83.3.3 255.255.255.128
R1-NV(config-if)#no shut
R1-NV(config-if)#
Enter configuration commands, one per line. End with CNTL/Z.
R1-NV(config)#inte
R1-NV(config)#interface loo
R1-NV(config)#interface loopback 0
R1-NV(config-if)#ip addr
R1-NV(config-if)#ip address 1.1.1.1 255.255.255.255
Interface IP-Address OK? Method Status Protocol
GigabitEthernet0/0 67.83.3.3 YES manual up up
GigabitEthernet0/1 67.83.4.1 YES manual up up
GigabitEthernet0/2 unassigned YES unset administratively down down
FastEthernet0/0/0 unassigned YES unset up down
FastEthernet0/0/1 unassigned YES unset up down
FastEthernet0/0/2 unassigned YES unset up down
FastEthernet0/0/3 unassigned YES unset up down
Loopback0 1.1.1.1 YES manual up up
Vlan1 unassigned YES unset administratively down down
R1-NV#
Capability Codes: R - Router, T - Trans Bridge, B - Source Route Bridge
S - Switch, H - Host, I - IGMP, r - Repeater, P - Phone
Device ID Local Intrfce Holdtme Capability Platform Port ID
MAN Gig 0/0 169 S 2960 Fas 0/2
SW-MA
Enter configuration commands, one per line. End with CNTL/Z.
R2-MA(config)#inter
R2-MA(config)#interface loo
R2-MA(config)#interface loopback 0
R2-MA(config-if)#ip add
R2-MA(config-if)#ip address 2.2.2.2 255.255.255.255
R2-MA(config-if)#do sh ip inter b
Interface IP-Address OK? Method Status Protocol
GigabitEthernet0/0 67.83.4.2 YES manual up up
GigabitEthernet0/1 67.83.3.129 YES manual up up
GigabitEthernet0/2 unassigned YES unset administratively down down
FastEthernet0/0/0 unassigned YES unset up down
FastEthernet0/0/1 unassigned YES unset up down
FastEthernet0/0/2 unassigned YES unset up down
FastEthernet0/0/3 unassigned YES unset up down
Loopback0 2.2.2.2 YES manual up up
Vlan1 unassigned YES unset administratively down down
R2-MA(config-if)#
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 67.83.4.1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 0/0/2 ms
R2-MA#ping 67.83.4.3
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 67.83.4.3, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 0/0/2 ms
R2-MA#
Interface IP-Address OK? Method Status Protocol
GigabitEthernet0/0 67.83.4.2 YES manual up up
GigabitEthernet0/1 67.83.3.129 YES manual up up
GigabitEthernet0/2 unassigned YES unset administratively down down
FastEthernet0/0/0 unassigned YES unset up down
FastEthernet0/0/1 unassigned YES unset up down
FastEthernet0/0/2 unassigned YES unset up down
FastEthernet0/0/3 unassigned YES unset up down
Loopback0 2.2.2.2 YES manual up up
Vlan1 unassigned YES unset administratively down down
R2-MA#
R3-ZA#sh cdp neighbors
Capability Codes: R - Router, T - Trans Bridge, B - Source Route Bridge
S - Switch, H - Host, I - IGMP, r - Repeater, P - Phone
Device ID Local Intrfce Holdtme Capability Platform Port ID
SW-ZA Gig 0/1 147 S 2960 Fas 0/1
MAN Gig 0/0 120 S 2960 Fas 0/3
R3-ZA#
Enter configuration commands, one per line. End with CNTL/Z.
R3-ZA(config)#inter
R3-ZA(config)#interface g
R3-ZA(config)#interface gigabitEthernet 0/0
R3-ZA(config-if)#ip add
R3-ZA(config-if)#ip address 67.83.4.3 255.255.255.248
R3-ZA(config-if)#no shut
R3-ZA(config-if)#
%LINK-5-CHANGED: Interface GigabitEthernet0/0, changed state to up
%LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet0/0, changed state to up
R3-ZA#conf t
Enter configuration commands, one per line. End with CNTL/Z.
R3-ZA(config)#inter
R3-ZA(config)#interface lo
R3-ZA(config)#interface loopback 0
R3-ZA(config-if)#ip add
R3-ZA(config-if)#ip address 3.3.3.3 255.255.255.255
Interface IP-Address OK? Method Status Protocol
GigabitEthernet0/0 67.83.4.3 YES manual up up
GigabitEthernet0/1 67.83.3.193 YES manual up up
GigabitEthernet0/2 unassigned YES unset administratively down down
FastEthernet0/0/0 unassigned YES unset up down
FastEthernet0/0/1 unassigned YES unset up down
FastEthernet0/0/2 unassigned YES unset up down
FastEthernet0/0/3 unassigned YES unset up down
Loopback0 3.3.3.3 YES manual up up
Vlan1 unassigned YES unset administratively down down
R3-ZA#
Access#sh cdp neighbors
Capability Codes: R - Router, T - Trans Bridge, B - Source Route Bridge
S - Switch, H - Host, I - IGMP, r - Repeater, P - Phone
Device ID Local Intrfce Holdtme Capability Platform Port ID
Core1 Fas 0/1 122 3650 Gig 1/0/2
Core2 Fas 0/4 122 3650 Gig 1/0/1
Access#conf t
Enter configuration commands, one per line. End with CNTL/Z.
Access(config)#inter
Access(config)#interface fa
Access(config)#interface fastEthernet 0/1
Access(config-if)#sw
Access(config-if)#switchport mode
Access(config-if)#switchport mode tr
Access(config-if)#switchport mode trunk
Access(config-if)#sw
Access(config-if)#switchport tr
Access(config-if)#switchport trunk all
Access(config-if)#switchport trunk allowed vlan 1,10,20,30,40
Access(config-if)#exit
Access(config)#interface fastEthernet 0/4
Access(config-if)#switchport mode trunk
Access(config-if)#switchport trunk allowed vlan 1,10,20,30,40
Access(config-if)#sw
Access(config-if)#switchport none
Access(config-if)#switchport nonegotiate
Access(config-if)#exit
Access(config)#interface fastEthernet 0/1
Access(config-if)#sw
Access(config-if)#switchport none
Access(config-if)#switchport nonegotiate
Access(config-if)#exit
Access(config)#inter
Access(config)#interface fa
Access(config)#interface fastEthernet 0/2
Access(config-if)#sw
Access(config-if)#switchport mode acc
Access(config-if)#switchport mode access
Access(config-if)#sw
Access(config-if)#switchport acc
Access(config-if)#switchport access vlan 10
Access(config-if)#exit
Access(config)#interface fastEthernet 0/3
Access(config-if)#switchport mode access
Access(config-if)#switchport access vlan 20
Access(config-if)#
Port Mode Encapsulation Status Native vlan
Fa0/1 on 802.1q trunking 1
Fa0/4 on 802.1q trunking 1
Port Vlans allowed on trunk
Fa0/1 1,10,20,30,40
Fa0/4 1,10,20,30,40
Port Vlans allowed and active in management domain
Fa0/1 1,10,20,30,40
Fa0/4 1,10,20,30,40
Port Vlans in spanning tree forwarding state and not pruned
Fa0/1 1,40
Fa0/4 10,20,30
Access#sh vlan
VLAN Name Status Ports
---- -------------------------------- --------- -------------------------------
1 default active Fa0/5, Fa0/6, Fa0/7, Fa0/8
Fa0/9, Fa0/10, Fa0/11, Fa0/12
Fa0/13, Fa0/14, Fa0/15, Fa0/16
Fa0/17, Fa0/18, Fa0/19, Fa0/20
Fa0/21, Fa0/22, Fa0/23, Fa0/24
Gig0/1, Gig0/2
10 VLAN10 active Fa0/2
20 VLAN20 active Fa0/3
30 VLAN30 active
40 VLAN40 active
1002 fddi-default act/unsup
1003 token-ring-default act/unsup
1004 fddinet-default act/unsup
1005 trnet-default act/unsup
VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Trans1 Trans2
---- ----- ---------- ----- ------ ------ -------- ---- -------- ------ ------
1 enet 100001 1500 - - - - - 0 0
10 enet 100010 1500 - - - - - 0 0
20 enet 100020 1500 - - - - - 0 0
30 enet 100030 1500 - - - - - 0 0
40 enet 100040 1500 - - - - - 0 0
1002 fddi 101002 1500 - - - - - 0 0
1003 tr 101003 1500 - - - - - 0 0
1004 fdnet 101004 1500 - - - ieee - 0 0
1005 trnet 101005 1500 - - - ibm - 0 0
VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Trans1 Trans2
---- ----- ---------- ----- ------ ------ -------- ---- -------- ------ ------
Remote SPAN VLANs
------------------------------------------------------------------------------
Primary Secondary Type Ports
------- --------- ----------------- ------------------------------------------
Access#
Codes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP
i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area
* - candidate default, U - per-user static route, o - ODR
P - periodic downloaded static route
Gateway of last resort is not set
1.0.0.0/32 is subnetted, 1 subnets
O 1.1.1.1 [110/2] via 67.83.3.3, 01:58:21, Vlan40
2.0.0.0/32 is subnetted, 1 subnets
O 2.2.2.2 [110/3] via 67.83.3.3, 01:58:21, Vlan40
11.0.0.0/32 is subnetted, 1 subnets
C 11.11.11.11 is directly connected, Loopback0
22.0.0.0/32 is subnetted, 1 subnets
O 22.22.22.22 [110/2] via 67.83.0.2, 00:45:46, Vlan10
[110/2] via 67.83.2.2, 00:45:46, Vlan30
[110/2] via 67.83.3.2, 00:45:46, Vlan40
67.0.0.0/8 is variably subnetted, 6 subnets, 4 masks
C 67.83.0.0/24 is directly connected, Vlan10
C 67.83.1.0/24 is directly connected, Vlan20
C 67.83.2.0/24 is directly connected, Vlan30
C 67.83.3.0/25 is directly connected, Vlan40
O 67.83.3.128/26 [110/3] via 67.83.3.3, 01:58:21, Vlan40
O 67.83.4.0/29 [110/2] via 67.83.3.3, 00:09:49, Vlan40
Core1#
Codes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP
i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area
* - candidate default, U - per-user static route, o - ODR
P - periodic downloaded static route
Gateway of last resort is not set
1.0.0.0/32 is subnetted, 1 subnets
O 1.1.1.1 [110/2] via 67.83.3.3, 00:00:21, Vlan40
2.0.0.0/32 is subnetted, 1 subnets
O 2.2.2.2 [110/3] via 67.83.3.3, 00:00:21, Vlan40
3.0.0.0/32 is subnetted, 1 subnets
O 3.3.3.3 [110/3] via 67.83.3.3, 00:00:21, Vlan40
11.0.0.0/32 is subnetted, 1 subnets
C 11.11.11.11 is directly connected, Loopback0
22.0.0.0/32 is subnetted, 1 subnets
O 22.22.22.22 [110/2] via 67.83.0.2, 01:01:09, Vlan10
[110/2] via 67.83.1.2, 01:01:09, Vlan20
[110/2] via 67.83.2.2, 01:01:09, Vlan30
[110/2] via 67.83.3.2, 01:01:09, Vlan40
67.0.0.0/8 is variably subnetted, 7 subnets, 4 masks
C 67.83.0.0/24 is directly connected, Vlan10
C 67.83.1.0/24 is directly connected, Vlan20
C 67.83.2.0/24 is directly connected, Vlan30
C 67.83.3.0/25 is directly connected, Vlan40
O 67.83.3.128/26 [110/3] via 67.83.3.3, 00:00:21, Vlan40
O 67.83.3.192/26 [110/3] via 67.83.3.3, 00:00:21, Vlan40
O 67.83.4.0/29 [110/2] via 67.83.3.3, 00:00:21, Vlan40
Core1#
Neighbor ID Pri State Dead Time Address Interface
22.22.22.22 1 FULL/DR 00:00:31 67.83.0.2 Vlan10
22.22.22.22 1 FULL/DR 00:00:31 67.83.1.2 Vlan20
22.22.22.22 1 FULL/DR 00:00:31 67.83.2.2 Vlan30
22.22.22.22 1 FULL/DR 00:00:31 67.83.3.2 Vlan40
1.1.1.1 1 FULL/DROTHER 00:00:31 67.83.3.3 Vlan40
Core1#
Routing Protocol is "ospf 1"
Outgoing update filter list for all interfaces is not set
Incoming update filter list for all interfaces is not set
Router ID 11.11.11.11
Number of areas in this router is 1. 1 normal 0 stub 0 nssa
Maximum path: 4
Routing for Networks:
11.11.11.11 0.0.0.0 area 0
67.83.0.0 0.0.0.255 area 0
67.83.1.0 0.0.0.255 area 0
67.83.2.0 0.0.0.255 area 0
67.83.3.0 0.0.0.127 area 0
Routing Information Sources:
Gateway Distance Last Update
1.1.1.1 110 00:04:38
2.2.2.2 110 00:04:49
3.3.3.3 110 00:04:49
11.11.11.11 110 00:04:48
22.22.22.22 110 00:04:48
Distance: (default is 110)
Core1#
Core2#sh ip route
Codes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP
i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area
* - candidate default, U - per-user static route, o - ODR
P - periodic downloaded static route
Gateway of last resort is not set
1.0.0.0/32 is subnetted, 1 subnets
O 1.1.1.1 [110/2] via 67.83.3.3, 00:01:39, Vlan40
2.0.0.0/32 is subnetted, 1 subnets
O 2.2.2.2 [110/3] via 67.83.3.3, 00:01:39, Vlan40
3.0.0.0/32 is subnetted, 1 subnets
O 3.3.3.3 [110/3] via 67.83.3.3, 00:01:39, Vlan40
11.0.0.0/32 is subnetted, 1 subnets
O 11.11.11.11 [110/2] via 67.83.0.1, 01:02:18, Vlan10
[110/2] via 67.83.1.1, 01:02:18, Vlan20
[110/2] via 67.83.2.1, 01:02:18, Vlan30
[110/2] via 67.83.3.1, 01:02:18, Vlan40
22.0.0.0/32 is subnetted, 1 subnets
C 22.22.22.22 is directly connected, Loopback0
67.0.0.0/8 is variably subnetted, 7 subnets, 4 masks
C 67.83.0.0/24 is directly connected, Vlan10
C 67.83.1.0/24 is directly connected, Vlan20
C 67.83.2.0/24 is directly connected, Vlan30
C 67.83.3.0/25 is directly connected, Vlan40
O 67.83.3.128/26 [110/3] via 67.83.3.3, 00:01:39, Vlan40
O 67.83.3.192/26 [110/3] via 67.83.3.3, 00:01:39, Vlan40
O 67.83.4.0/29 [110/2] via 67.83.3.3, 00:01:39, Vlan40
Core2#
Core2#sh ip ospf neighbor
Neighbor ID Pri State Dead Time Address Interface
11.11.11.11 1 FULL/BDR 00:00:38 67.83.0.1 Vlan10
11.11.11.11 1 FULL/BDR 00:00:39 67.83.2.1 Vlan30
11.11.11.11 1 FULL/BDR 00:00:39 67.83.3.1 Vlan40
1.1.1.1 1 FULL/DROTHER 00:00:39 67.83.3.3 Vlan40
Core2#
Core2#sh ip protocols
Routing Protocol is "ospf 1"
Outgoing update filter list for all interfaces is not set
Incoming update filter list for all interfaces is not set
Router ID 22.22.22.22
Number of areas in this router is 1. 1 normal 0 stub 0 nssa
Maximum path: 4
Routing for Networks:
22.22.22.22 0.0.0.0 area 0
67.83.0.0 0.0.0.255 area 0
67.83.1.0 0.0.0.255 area 0
67.83.2.0 0.0.0.255 area 0
67.83.3.0 0.0.0.127 area 0
Routing Information Sources:
Gateway Distance Last Update
1.1.1.1 110 00:05:25
2.2.2.2 110 00:05:34
3.3.3.3 110 00:05:34
11.11.11.11 110 00:05:35
22.22.22.22 110 00:05:34
Distance: (default is 110)
Core2#
Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP
i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area
* - candidate default, U - per-user static route, o - ODR
P - periodic downloaded static route
Gateway of last resort is not set
1.0.0.0/32 is subnetted, 1 subnets
C 1.1.1.1/32 is directly connected, Loopback0
2.0.0.0/32 is subnetted, 1 subnets
O 2.2.2.2/32 [110/2] via 67.83.4.2, 02:01:17, GigabitEthernet0/1
11.0.0.0/32 is subnetted, 1 subnets
O 11.11.11.11/32 [110/2] via 67.83.3.1, 02:01:17, Vlan40
22.0.0.0/32 is subnetted, 1 subnets
O 22.22.22.22/32 [110/2] via 67.83.3.2, 00:18:18, Vlan40
67.0.0.0/8 is variably subnetted, 8 subnets, 5 masks
O 67.83.0.0/24 [110/2] via 67.83.3.1, 00:18:18, Vlan40
[110/2] via 67.83.3.2, 00:18:18, Vlan40
O 67.83.1.0/24 [110/2] via 67.83.3.1, 00:18:18, Vlan40
[110/2] via 67.83.3.2, 00:18:18, Vlan40
O 67.83.2.0/24 [110/2] via 67.83.3.1, 00:18:18, Vlan40
[110/2] via 67.83.3.2, 00:18:18, Vlan40
C 67.83.3.0/25 is directly connected, Vlan40
L 67.83.3.3/32 is directly connected, Vlan40
O 67.83.3.128/26 [110/2] via 67.83.4.2, 02:01:17, GigabitEthernet0/1
C 67.83.4.0/29 is directly connected, GigabitEthernet0/1
L 67.83.4.1/32 is directly connected, GigabitEthernet0/1
R1-NV#sh ip ospf neighbor
Neighbor ID Pri State Dead Time Address Interface
11.11.11.11 1 FULL/BDR 00:00:38 67.83.3.1 GigabitEthernet0/0
22.22.22.22 1 FULL/DROTHER 00:00:38 67.83.3.2 GigabitEthernet0/0
3.3.3.3 1 FULL/DR 00:00:38 67.83.4.3 GigabitEthernet0/1
2.2.2.2 1 FULL/BDR 00:00:38 67.83.4.2 GigabitEthernet0/1
R1-NV#
R1-NV#sh ip protocols
Routing Protocol is "ospf 1"
Outgoing update filter list for all interfaces is not set
Incoming update filter list for all interfaces is not set
Router ID 1.1.1.1
Number of areas in this router is 1. 1 normal 0 stub 0 nssa
Maximum path: 4
Routing for Networks:
67.83.4.0 0.0.0.7 area 0
1.1.1.1 0.0.0.0 area 0
67.83.3.0 0.0.0.127 area 0
0.0.0.0 255.255.255.255 area 0
Routing Information Sources:
Gateway Distance Last Update
1.1.1.1 110 00:00:27
2.2.2.2 110 00:00:28
3.3.3.3 110 00:00:28
11.11.11.11 110 00:00:27
22.22.22.22 110 00:00:27
Distance: (default is 110)
R1-NV#
Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP
i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area
* - candidate default, U - per-user static route, o - ODR
P - periodic downloaded static route
Gateway of last resort is not set
1.0.0.0/32 is subnetted, 1 subnets
O 1.1.1.1/32 [110/2] via 67.83.4.1, 04:02:59, GigabitEthernet0/0
2.0.0.0/32 is subnetted, 1 subnets
C 2.2.2.2/32 is directly connected, Loopback0
3.0.0.0/32 is subnetted, 1 subnets
O 3.3.3.3/32 [110/2] via 67.83.4.3, 00:13:14, GigabitEthernet0/0
11.0.0.0/32 is subnetted, 1 subnets
O 11.11.11.11/32 [110/3] via 67.83.4.1, 01:54:58, GigabitEthernet0/0
22.0.0.0/32 is subnetted, 1 subnets
O 22.22.22.22/32 [110/3] via 67.83.4.1, 00:18:58, GigabitEthernet0/0
67.0.0.0/8 is variably subnetted, 9 subnets, 5 masks
O 67.83.0.0/24 [110/3] via 67.83.4.1, 01:54:58, GigabitEthernet0/0
O 67.83.1.0/24 [110/3] via 67.83.4.1, 01:32:17, GigabitEthernet0/0
O 67.83.2.0/24 [110/3] via 67.83.4.1, 01:54:58, GigabitEthernet0/0
O 67.83.3.0/25 [110/2] via 67.83.4.1, 01:54:58, GigabitEthernet0/0
C 67.83.3.128/26 is directly connected, GigabitEthernet0/1
L 67.83.3.129/32 is directly connected, GigabitEthernet0/1
O 67.83.3.192/26 [110/2] via 67.83.4.3, 00:13:14, GigabitEthernet0/0
C 67.83.4.0/29 is directly connected, GigabitEthernet0/0
L 67.83.4.2/32 is directly connected, GigabitEthernet0/0
Neighbor ID Pri State Dead Time Address Interface
1.1.1.1 1 FULL/DROTHER 00:00:32 67.83.4.1 GigabitEthernet0/0
3.3.3.3 1 FULL/DR 00:00:32 67.83.4.3 GigabitEthernet0/0
R2-MA#
R2-MA# sh ip protocols
Routing Protocol is "ospf 1"
Outgoing update filter list for all interfaces is not set
Incoming update filter list for all interfaces is not set
Router ID 2.2.2.2
Number of areas in this router is 2. 2 normal 0 stub 0 nssa
Maximum path: 4
Routing for Networks:
67.83.4.0 0.0.0.7 area 0
67.83.3.128 0.0.0.63 area 0
2.2.2.2 0.0.0.0 area 0
0.0.0.0 255.255.255.255 area 1
Routing Information Sources:
Gateway Distance Last Update
1.1.1.1 110 00:01:53
2.2.2.2 110 00:02:48
3.3.3.3 110 00:02:04
11.11.11.11 110 00:02:03
22.22.22.22 110 00:02:03
Distance: (default is 110)
R2-MA#
Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP
i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area
* - candidate default, U - per-user static route, o - ODR
P - periodic downloaded static route
Gateway of last resort is not set
1.0.0.0/32 is subnetted, 1 subnets
O 1.1.1.1/32 [110/2] via 67.83.4.1, 00:04:23, GigabitEthernet0/0
2.0.0.0/32 is subnetted, 1 subnets
O 2.2.2.2/32 [110/2] via 67.83.4.2, 00:04:23, GigabitEthernet0/0
3.0.0.0/32 is subnetted, 1 subnets
C 3.3.3.3/32 is directly connected, Loopback0
11.0.0.0/32 is subnetted, 1 subnets
O 11.11.11.11/32 [110/3] via 67.83.4.1, 00:04:23, GigabitEthernet0/0
22.0.0.0/32 is subnetted, 1 subnets
O 22.22.22.22/32 [110/3] via 67.83.4.1, 00:04:23, GigabitEthernet0/0
67.0.0.0/8 is variably subnetted, 9 subnets, 5 masks
O 67.83.0.0/24 [110/3] via 67.83.4.1, 00:04:23, GigabitEthernet0/0
O 67.83.1.0/24 [110/3] via 67.83.4.1, 00:04:23, GigabitEthernet0/0
O 67.83.2.0/24 [110/3] via 67.83.4.1, 00:04:23, GigabitEthernet0/0
O 67.83.3.0/25 [110/2] via 67.83.4.1, 00:04:23, GigabitEthernet0/0
O 67.83.3.128/26 [110/2] via 67.83.4.2, 00:04:23, GigabitEthernet0/0
C 67.83.3.192/26 is directly connected, GigabitEthernet0/1
L 67.83.3.193/32 is directly connected, GigabitEthernet0/1
C 67.83.4.0/29 is directly connected, GigabitEthernet0/0
L 67.83.4.3/32 is directly connected, GigabitEthernet0/0
R3-ZA#sh ip ospf neighbor
Neighbor ID Pri State Dead Time Address Interface
1.1.1.1 1 FULL/DROTHER 00:00:34 67.83.4.1 GigabitEthernet0/0
2.2.2.2 1 FULL/BDR 00:00:34 67.83.4.2 GigabitEthernet0/0
R3-ZA#
R3-ZA#sh ip protocols
Routing Protocol is "ospf 1"
Outgoing update filter list for all interfaces is not set
Incoming update filter list for all interfaces is not set
Router ID 3.3.3.3
Number of areas in this router is 1. 1 normal 0 stub 0 nssa
Maximum path: 4
Routing for Networks:
3.3.3.3 0.0.0.0 area 0
67.83.4.0 0.0.0.7 area 0
67.83.3.192 0.0.0.63 area 0
Routing Information Sources:
Gateway Distance Last Update
1.1.1.1 110 00:06:21
2.2.2.2 110 00:06:32
3.3.3.3 110 00:06:32
11.11.11.11 110 00:06:31
22.22.22.22 110 00:06:31
Distance: (default is 110)
R3-ZA#
Comprobando conectividad:
FastEthernet0 Connection:(default port)
Link-local IPv6 Address.........: FE80::260:3EFF:FE42:38D
IP Address......................: 67.83.0.10
Subnet Mask.....................: 255.255.255.0
Default Gateway.................: 67.83.0.1
C:\>ping 67.83.3.130
Pinging 67.83.3.130 with 32 bytes of data:
Reply from 67.83.3.130: bytes=32 time<1ms TTL=125
Reply from 67.83.3.130: bytes=32 time=1ms TTL=125
Reply from 67.83.3.130: bytes=32 time=12ms TTL=125
Reply from 67.83.3.130: bytes=32 time=12ms TTL=125
Ping statistics for 67.83.3.130:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 12ms, Average = 6ms
C:\>tracert 67.83.3.130
Tracing route to 67.83.3.130 over a maximum of 30 hops:
1 1 ms 0 ms 0 ms 67.83.0.2
2 0 ms 0 ms 1 ms 67.83.3.3
3 1 ms 0 ms 1 ms 67.83.4.2
4 10 ms 12 ms 11 ms 67.83.3.130
Trace complete.
C:\>ping 67.83.3.200
Pinging 67.83.3.200 with 32 bytes of data:
Reply from 67.83.3.200: bytes=32 time=11ms TTL=125
Reply from 67.83.3.200: bytes=32 time=12ms TTL=125
Reply from 67.83.3.200: bytes=32 time<1ms TTL=125
Reply from 67.83.3.200: bytes=32 time<1ms TTL=125
Ping statistics for 67.83.3.200:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 12ms, Average = 5ms
C:\>tracert 67.83.3.200
Tracing route to 67.83.3.200 over a maximum of 30 hops:
1 4 ms 0 ms 1 ms 67.83.0.2
2 0 ms 1 ms 1 ms 67.83.3.3
3 0 ms 1 ms 0 ms 67.83.4.3
4 0 ms 9 ms 1 ms 67.83.3.200
Trace complete.
C:\>
C:\>ipconfig
FastEthernet0 Connection:(default port)
Link-local IPv6 Address.........: FE80::2E0:F7FF:FE0C:B2C9
IP Address......................: 67.83.3.130
Subnet Mask.....................: 255.255.255.192
Default Gateway.................: 67.83.3.129
C:\>ping 67.83.0.10
Pinging 67.83.0.10 with 32 bytes of data:
Reply from 67.83.0.10: bytes=32 time=11ms TTL=125
Reply from 67.83.0.10: bytes=32 time=12ms TTL=125
Reply from 67.83.0.10: bytes=32 time=10ms TTL=125
Reply from 67.83.0.10: bytes=32 time=11ms TTL=125
Ping statistics for 67.83.0.10:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 10ms, Maximum = 12ms, Average = 11ms
C:\>
C:\>ipconfig
FastEthernet0 Connection:(default port)
Link-local IPv6 Address.........: FE80::2D0:BCFF:FE4B:A292
IP Address......................: 67.83.3.200
Subnet Mask.....................: 255.255.255.192
Default Gateway.................: 67.83.3.193
C:\>tracert 67.83.0.10
Tracing route to 67.83.0.10 over a maximum of 30 hops:
1 0 ms 0 ms 0 ms 67.83.3.193
2 0 ms 0 ms 0 ms 67.83.4.1
3 0 ms 1 ms 12 ms 67.83.3.2
4 12 ms 0 ms 11 ms 67.83.0.10
Trace complete.
C:\>
VPN Túnel
Puertos que tenemos que abrir en el router Mikrotik 4500, 500, 1701 (udp) y el protocolo ipsec-esp (50).
Utilizar estos protocolos para conseguir conectividad en capa 2 con altos niveles de seguridad. Un túnel o VPN es una conexión entre dos equipos remotos como si los equipos estuviesen conectados directamente. Como este es un túnel de capa 2 vamos a extender nuestro dominio de broadcast de un router hacia el otro y crear un solo dominio de broadcast con independencia de su ubicación.
L2tp quiere decir Layer 2 Tunneling Protocol o protocolo de capa 2 y se utiliza con IPSec que proporciona encriptación y autenticación con el fin de para proporcionar mayores niveles de seguridad para la transmisión de datos. BCP (Bridge Control Protocol) sirve para agregar la interfaz virtual creada (el túnel) a un bridge. BCP es una parte independiente de PPP.
Laboratorio con GNS3. Con equipos físicos la configuración será la misma. Lo único que cambia es la IP pública que evidentemente debe ser alcanzable.
Configuración del equipo que va a servir de Servidor de las conexiones L2TP:
Tenemos una oficina remota con una IP pública 172.16.90.138 (es la IP con la que el equipo sale a Internet en este laboratorio) y una LAN con IP privada 10.1.101.0/24. Este equipo tiene un bridge llamado bridge_LAN al que pertenecen los puertos ether1 al ether5 y es el que vamos a utilizar con BCP en los túneles.
Queremos tener conexión total en capa 2 entre los dos routers. Comprobamos que tenemos conexión a Internet con un ping.
En el GNS3 desde la terminal, (botón derecho sobre el router clic en Console), cambiamos los nombres de los routers.
Abrimos el Winbox (los routers ya tienen IP asignadas por NAT desde mi red local:
nos conectamos al router L2TPServer y habilitamos desde PPP el L2TP Server haciendo clic en Enabled, elegimos default encryption, (es aquí donde habilitamos BCP o en su defecto en el perfil que nosotros generemos), como Default Profile, en Use IPsec elegimos required (esto obliga al cliente a utilizar IPSec). En Authentication solo dejamos habilitado mschap2. En IPsec Secret ponemos una contraseña fuerte para conseguir un buen nivel de seguridad (este Secret es para IPsec y puede ser diferente de la contraseña del usuario). También podemos habilitar una sesión por host habilitando One Session Per Host.
En la pestaña Profiles veremos los perfiles por defecto implementados en RouterOS. Abrimos Default Encryption. En bridge seleccionamos el bridge de la LAN. En estos momentos ya estamos utilizando BCP. Cuando se establezca el túnel, la interfaz del túnel se va a agregar a este bridge que se llama bridge_LAN guardamos los cambios.
Necesitamos crear un usuario y una clave, esto lo haremos en New PPP Secret. Este usuario es para establecer el túnel l2tp. Como usuario carles y una contraseña (, en Service l2tp y en Profile default encryption. El password anterior era para IPsec. En Local Address pondremos la IP 10.100.100.1 y en Remote Address la 172.16.254.1 (esta es la IP que tomará el equipo cliente). Estas son las direcciones IP que va a tomar en sus extremos el túnel.
Llegados a este punto nuestro router está listo para recibir conexión y nuestro dominio de broadcast sea extendido hacia el cliente.
Configuración del equipo Cliente:
Nos conectamos a través de Winbox
Equipo cliente desde el que vamos a conectarnos hacia la oficina. No es necesario que tenga una ip pública, algo imprescindible en el de la oficina, lo que si tiene que tener es conexión a Internet. Comprobamos conexión a Internet haciendo un ping.
Vamos a agregar un L2TP Client y agregar los parámetros de conexión que debe coincidir con lo configurado en el Servidor. Donde pone Dial Out en la entrada Connect To tenemos que introducir la IP pública de la oficina que dijimos que, (a efectos del laboratorio), es la 172.16.90.138. En el usuario y la contraseña que habéis puesto antes.
En Profile seleccionamos default encryption y tildar Use IPsec e introducir el password de IPsec. No necesitamos utilizar las opciones Dial on Demand ni Add Default Route. Clic en Aplicar y OK. Ahora en Profiles agregamos el bridge. En este caso el router tiene un bridge creado entre los puertos 2 al 5 y la wlan1 que se llama LAN_bridge.
En el momento de establecer el túnel todos los puertos perteneciente al bridge tendrán conectividad en capa 2 con el router de la oficina. Vamos a Interface y deshabitamos y habilitamos el túnel y vemos que el túnel se ha establecido. En status, Status connected. Las Local address (172.16.254.1) t Remote Address (10.100.100.1). Si hacemos un ping a la IP 10.100.100.1 veremos que hay respuesta. También podemos verificar que BCP está activo que entre los Ports del bridge LAN_bridge aparece el puerto l2tp dinámico que es el túnel L2TP.
Ping a la IP 10.100.100.1
Si abro una nueva ventana New Winbox veré en la pestaña Neighbors el equipo del otro extremo (172.16.254.1.1). Si configuro mi portátil con una IP del mismo rango de la que se utiliza en la oficina que es la tendría que poder hacer ping hacia el otro router.
Con un dhcp server habilitado mi portátil tomaría una IP automáticamente de esa LAN. Es como si estuviera conectado directamente al router de la oficina. Se pueden conectar clientes Mac, Windows, Linux, Android, etc.