NAT Overload Topology Diagram

CCNA Lab 7: IPv4 PAT (NAT Overload) Configuration

IPv4 address exhaustion makes public IP allocation scarce and expensive for enterprise networks. Port Address Translation (PAT), frequently referred to as NAT Overload, enables hundreds of internal hosts on private RFC 1918 subnets to share a single public IPv4 address for outbound internet access. PAT operates by tracking source port numbers on outbound Layer 4 (TCP/UDP) headers. When private traffic exits the WAN boundary interface, the router maps the private Inside Local IP and port number to the router’s public Outside Global IP and a uniquely assigned source port. ...

Floating Static Route Network Topology

CCNA Lab 6: Backup Path Redundancy with Floating Static Routes

Dynamic routing protocols like OSPF provide automated path calculation, but relying solely on dynamic neighbor adjacencies across secondary links isn’t always feasible, especially on metered backup connections (like 4G/5G or satellite), untrusted third-party WANs, or legacy links where running continuous Hello packets introduces unnecessary overhead and instability. Floating Static Routes solve this by serving as a low-overhead, deterministic backup mechanism. By assigning an Administrative Distance (AD) higher than the primary dynamic protocol, the static route remains completely dormant in the background, activating only when the primary dynamic route is withdrawn from the routing table. ...

FHRP HSRP Network Topology

CCNA Lab 5: First Hop Redundancy Protocols - High Availability Gateway with Cisco HSRP

A single default gateway represents a critical single point of failure in enterprise access layer networks. If a primary router loses power, suffers a link failure, or reboots, end hosts remain isolated from external subnets, even if a physical backup router is online and connected to the same switch. First Hop Redundancy Protocols (FHRP) solve this by allowing multiple physical routers to share a single Virtual IP (VIP) and Virtual MAC address. Hosts target the Virtual IP as their default gateway, ensuring transparent, automatic failover without requiring IP reconfiguration or ARP table flushes on client devices. ...

Single-Area OSPFv2 Network Topology

CCNA Lab 4: Single-Area OSPFv2 - Path Selection and Interface Cost Tuning

Dynamic routing protocols like OSPF dynamically calculate the shortest path through a network using link metrics. By default, OSPF calculates interface cost based on reference bandwidth (100 Mbps / bandwidth). However, in modern networks with disparate WAN links (such as high-speed fiber vs. low-bandwidth backup copper), default calculations may not accurately reflect desired traffic paths. To enforce traffic engineering, network administrators manually tune OSPF interface costs to prefer primary fiber paths over backup links. ...

Layer 2 Security Hardening Network Topology

CCNA Lab 3: Layer 2 Security Hardening - DHCP Snooping, DAI, and Port Security

Lab Objective: Prevent rogue endpoints from acting as DHCP servers or spoofing ARP responses, and enforce dynamic MAC address binding to automatically shut down ports when unauthorized cable moves occur. 📁 Lab File: Download the Layer 2 Security Hardening Packet Tracer Lab (.pkt). Topology The topology uses a single Catalyst 2960 switch connecting legitimate endpoints, an authorized DHCP server, and a rogue device acting as a fake DHCP server. Source Device Interface Destination Device Interface Port Security Role PC0 (Legitimate Host) Fa0 Switch0 Fa0/1 Untrusted (Sticky MAC) Server1 (Rogue DHCP/Host) Fa0 Switch0 Fa0/2 Untrusted (Sticky MAC) PC1 (Legitimate Host) Fa0 Switch0 Fa0/3 Untrusted (Sticky MAC) Server0 (Legitimate DHCP) Fa0 Switch0 Fa0/24 Trusted (Infrastructure) Global Configuration (Switch) Enable DHCP Snooping and DAI globally, then mark the DHCP server port (Fa0/24) as trusted. ...

Inter-VLAN Routing and Guest Isolation Network Topology

CCNA Lab 2: Inter-VLAN Routing and Guest Traffic Isolation with ACLs

Segmenting corporate networks into logical VLANs isolates broadcast domains, but without explicit access controls, inter-VLAN routing allows unrestricted traffic flow between subnets. To enforce security parameters at the network perimeter, engineers use Access Control Lists (ACLs) to filter traffic between guest networks and critical internal assets. Lab Objective: Build a Router-on-a-Stick (ROAS) architecture using 802.1Q trunks, configure router-based DHCP services, and apply an Extended ACL to block guest VLAN traffic from accessing the internal server. ...

Layer 2 EtherChannel and Spanning Tree Topology

CCNA Lab 1: Layer 2 Redundancy - EtherChannel and Spanning Tree Protocol

In enterprise campus networks, high availability requires redundant physical links between switches. However, redundant Layer 2 paths naturally introduce bridging loops and broadcast storms. To resolve this, network engineers combine two essential Layer 2 technologies: Spanning Tree Protocol (STP): Blocks redundant paths logically to maintain a loop-free topology. EtherChannel (Link Aggregation): Bundles multiple physical interfaces into a single logical link, increasing bandwidth without triggering STP blocks on parallel links. Lab Objective: Build a 3-switch topology where a single cable failure doesn’t disconnect users. ...