COLEGIO HORIZONTE — LABORATORIO REPRESENTATIVO Estado: configuración propuesta, no ejecutada ni certificada en Packet Tracer. No existe todavía un archivo .pkt ni evidencia de ping obtenida. No aplicar estos comandos a equipos de producción. ALCANCE 1 router Cisco 2911 (R1), 1 switch 2960 (SW1), 7 terminales. Este laboratorio reduce los 33 dispositivos finales a representantes de cada área. El switch de producción propuesto es de 48 puertos; el 2960 del laboratorio usa solo los puertos necesarios para probar enrutamiento y ACLs. No prueba Internet, NAT, DHCP, radio Wi-Fi, límites de velocidad ni carga real. Un PC cableado representa Invitados. PC-CAM y PC-NVR representan CCTV. La prueba de ping no verifica un flujo de video ni la aplicación de impresión. CONEXIONES (COBRE DIRECTO) R1 GigabitEthernet0/0 -> SW1 GigabitEthernet0/1 (trunk) SW1 FastEthernet0/1 -> PC-ADMIN 192.168.10.100 /24 GW 192.168.10.1 SW1 FastEthernet0/2 -> PC-AULA 192.168.20.100 /24 GW 192.168.20.1 SW1 FastEthernet0/3 -> PC-GUEST 192.168.30.100 /24 GW 192.168.30.1 SW1 FastEthernet0/4 -> SERVER 192.168.40.10 /24 GW 192.168.40.1 SW1 FastEthernet0/5 -> PRINTER 192.168.40.20 /24 GW 192.168.40.1 SW1 FastEthernet0/6 -> PC-CAM 192.168.50.11 /24 GW 192.168.50.1 SW1 FastEthernet0/7 -> PC-NVR 192.168.50.10 /24 GW 192.168.50.1 SW1 SVI VLAN99: 192.168.99.2 /24 GW 192.168.99.1 Máscara en todos: 255.255.255.0. No se necesita DNS para estas pruebas por IP. En PC: Desktop > IP Configuration. En impresora, usar Config > interfaz. Si la impresora de esa versión no responde ICMP, usar un PC como representación y documentar esa sustitución; no afirmar que se verificó impresión real. SW1 — PEGAR EN CLI DESPUÉS DE ACCEDER AL EQUIPO enable configure terminal hostname SW1 vlan 10 name ADMIN vlan 20 name AULA vlan 30 name INVITADOS vlan 40 name SERVICIOS vlan 50 name CCTV vlan 99 name GESTION vlan 999 name NATIVA_SIN_USUARIOS interface gigabitEthernet0/1 switchport mode trunk switchport trunk native vlan 999 switchport trunk allowed vlan 10,20,30,40,50,99,999 no shutdown interface fastEthernet0/1 switchport mode access switchport access vlan 10 spanning-tree portfast no shutdown interface fastEthernet0/2 switchport mode access switchport access vlan 20 spanning-tree portfast no shutdown interface fastEthernet0/3 switchport mode access switchport access vlan 30 spanning-tree portfast no shutdown interface range fastEthernet0/4 - 5 switchport mode access switchport access vlan 40 spanning-tree portfast no shutdown interface range fastEthernet0/6 - 7 switchport mode access switchport access vlan 50 spanning-tree portfast no shutdown interface range fastEthernet0/8 - 24 switchport mode access switchport access vlan 999 shutdown interface gigabitEthernet0/2 shutdown interface vlan 99 ip address 192.168.99.2 255.255.255.0 no shutdown exit ip default-gateway 192.168.99.1 line vty 0 4 transport input none end copy running-config startup-config R1 — LAS ACL SON IPv4, SE APLICAN AL TRÁFICO DE ENTRADA DE CADA VLAN enable configure terminal hostname R1 ip access-list extended ADMIN_IN permit icmp 192.168.10.0 0.0.0.255 host 192.168.10.1 echo permit icmp 192.168.10.0 0.0.0.255 host 192.168.40.10 echo permit icmp 192.168.10.0 0.0.0.255 host 192.168.40.20 echo permit tcp 192.168.10.0 0.0.0.255 host 192.168.40.10 eq 443 permit tcp 192.168.10.0 0.0.0.255 host 192.168.40.20 eq 9100 permit tcp 192.168.10.0 0.0.0.255 host 192.168.50.10 eq 443 deny ip any any exit ip access-list extended AULA_IN permit icmp 192.168.20.0 0.0.0.255 host 192.168.20.1 echo permit icmp 192.168.20.0 0.0.0.255 host 192.168.40.10 echo permit icmp 192.168.20.0 0.0.0.255 host 192.168.40.20 echo permit tcp 192.168.20.0 0.0.0.255 host 192.168.40.10 eq 443 permit tcp 192.168.20.0 0.0.0.255 host 192.168.40.20 eq 9100 deny ip any any exit ip access-list extended GUEST_IN permit icmp 192.168.30.0 0.0.0.255 host 192.168.30.1 echo deny ip any any exit ip access-list extended SERVICES_IN permit icmp host 192.168.40.10 host 192.168.40.1 echo permit icmp host 192.168.40.20 host 192.168.40.1 echo permit icmp host 192.168.40.10 192.168.10.0 0.0.0.255 echo-reply permit icmp host 192.168.40.20 192.168.10.0 0.0.0.255 echo-reply permit icmp host 192.168.40.10 192.168.20.0 0.0.0.255 echo-reply permit icmp host 192.168.40.20 192.168.20.0 0.0.0.255 echo-reply permit tcp host 192.168.40.10 eq 443 192.168.10.0 0.0.0.255 established permit tcp host 192.168.40.10 eq 443 192.168.20.0 0.0.0.255 established permit tcp host 192.168.40.20 eq 9100 192.168.10.0 0.0.0.255 established permit tcp host 192.168.40.20 eq 9100 192.168.20.0 0.0.0.255 established deny ip any any exit ip access-list extended CCTV_IN permit icmp 192.168.50.0 0.0.0.255 host 192.168.50.1 echo permit tcp host 192.168.50.10 eq 443 192.168.10.0 0.0.0.255 established deny ip any any exit ip access-list extended MGMT_IN permit icmp host 192.168.99.2 host 192.168.99.1 echo deny ip any any exit interface gigabitEthernet0/0 no ip address no shutdown interface gigabitEthernet0/0.10 encapsulation dot1Q 10 ip address 192.168.10.1 255.255.255.0 ip access-group ADMIN_IN in interface gigabitEthernet0/0.20 encapsulation dot1Q 20 ip address 192.168.20.1 255.255.255.0 ip access-group AULA_IN in interface gigabitEthernet0/0.30 encapsulation dot1Q 30 ip address 192.168.30.1 255.255.255.0 ip access-group GUEST_IN in interface gigabitEthernet0/0.40 encapsulation dot1Q 40 ip address 192.168.40.1 255.255.255.0 ip access-group SERVICES_IN in interface gigabitEthernet0/0.50 encapsulation dot1Q 50 ip address 192.168.50.1 255.255.255.0 ip access-group CCTV_IN in interface gigabitEthernet0/0.99 encapsulation dot1Q 99 ip address 192.168.99.1 255.255.255.0 ip access-group MGMT_IN in interface gigabitEthernet0/0.999 encapsulation dot1Q 999 native no ip address exit line vty 0 4 transport input none end copy running-config startup-config NOTAS DE SEGURIDAD Y ALCANCE - No hay Internet ni rutas por defecto en este laboratorio; el deny final también bloquea la salida pública. No confundir con la propuesta de producción. - La gestión remota queda deshabilitada en este laboratorio. El acceso SSH solo desde PC TI es una política de producción que requiere configurar claves, usuarios, VTY, ACL de gestión y reglas de retorno en el equipo definitivo. - La palabra established revisa bits ACK/RST, no mantiene una tabla de sesiones. No equivale a un firewall con inspección de estado. - Las reglas no cubren IPv6. No se ha probado resistencia a suplantación, salto de VLAN, filtrado de capa 2, aislamiento Wi-Fi ni seguridad de los dispositivos. - No se han configurado DHCP, NAT, QoS o rate limiting. Son tareas de producción. - El AP y la gestión Wi-Fi no están representados físicamente en este laboratorio. - No borrar la configuración de ningún equipo real para probar este archivo. VERIFICACIÓN PREVIA En SW1: show vlan brief / show interfaces trunk / show ip interface brief En R1: show ip interface brief / show ip route / show access-lists Cada host debe poder hacer ping a SU gateway. Si no responde, corregir primero dirección, máscara, gateway, conexión física, VLAN y trunk. CASOS A-D: RESULTADOS ESPERADOS, NO OBSERVADOS A) PC-AULA: ping 192.168.40.20 -> PERMITIDO por AULA_IN. Confirmar respuesta; repetir si el primer paquete se pierde durante ARP. B) PC-GUEST: ping 192.168.10.100 -> BLOQUEADO por GUEST_IN. C) PC-AULA: ping 192.168.10.100 -> BLOQUEADO por AULA_IN. D) PC-CAM: ping 192.168.50.10 -> PERMITIDO dentro de VLAN 50, sin router. CONTROL NEGATIVO PARA B Y C Antes del intento bloqueado, hacer ping al propio gateway. Después observar el descarte en el router en Simulation y el contador de la ACL cuando esté disponible. Un timeout aislado no prueba que la política de seguridad funcionó. PRUEBAS DE APLICACIÓN Si la versión de Server-PT ofrece HTTPS, activarlo y consultar 192.168.40.10 desde Aula y Admin. HTTPS a la impresora debe bloquearse según las ACLs. La funcionalidad TCP 9100 y NVR HTTPS depende del dispositivo simulado; no declararla validada solo porque su ACL exista o porque el ping responda. EVIDENCIAS Guardar el proyecto como colegio-horizonte.pkt después de las pruebas. Capturar origen, destino, comando y resultado; incluir topología y descarte. Insertar imágenes o un video de 1–2 minutos en la pestaña Demostración. Mantener las etiquetas de pendiente hasta contar con evidencia verificable.