enable
configure terminal
hostname HQ-CORE
no ip domain-lookup
service password-encryption
enable secret REPLACE_WITH_ENABLE_SECRET
username netadmin privilege 15 secret REPLACE_WITH_ADMIN_SECRET
ip domain-name project03.lab
banner motd #Authorised lab administration only.#
access-list 10 permit 10.10.0.64 0.0.0.15
access-list 10 permit 10.10.0.96 0.0.0.15
access-list 10 permit 10.20.0.64 0.0.0.15
line console 0
 login local
 logging synchronous
 exec-timeout 10 0
 exit
line vty 0 4
 login local
 transport input ssh
 access-class 10 in
 exec-timeout 10 0
 exit
ip routing
vlan 10
 name ADMIN_PROPOSED
 exit
vlan 20
 name FINANCE_PROPOSED
 exit
vlan 30
 name IT_PROPOSED
 exit
vlan 40
 name OPERATIONS_PROPOSED
 exit
vlan 50
 name SERVERS_PROPOSED
 exit
vlan 99
 name MANAGEMENT
 exit
vlan 998
 name UNUSED_PORTS
 exit
vlan 999
 name NATIVE_UNUSED
 exit
interface Vlan10
 description HQ_ADMIN_PROPOSED
 ip address 10.10.0.1 255.255.255.224
 ip helper-address 10.10.0.82
 no shutdown
 exit
interface Vlan20
 description HQ_FINANCE_PROPOSED
 ip address 10.10.0.33 255.255.255.224
 ip helper-address 10.10.0.82
 no shutdown
 exit
interface Vlan30
 description HQ_IT_PROPOSED
 ip address 10.10.0.65 255.255.255.240
 ip helper-address 10.10.0.82
 no shutdown
 exit
interface Vlan40
 description HQ_OPERATIONS_PROPOSED
 ip address 10.10.0.129 255.255.255.192
 ip helper-address 10.10.0.82
 no shutdown
 exit
interface Vlan50
 description HQ_SERVERS_PROPOSED
 ip address 10.10.0.81 255.255.255.240
 no shutdown
 exit
interface Vlan99
 description HQ_MANAGEMENT
 ip address 10.10.0.97 255.255.255.240
 no shutdown
 exit
interface GigabitEthernet0/1
 description TRUNK_TO_HQ_SW1_Gi0_1
 switchport trunk encapsulation dot1q
 switchport mode trunk
 switchport trunk native vlan 999
 switchport trunk allowed vlan 10,20,99,999
 switchport nonegotiate
 no shutdown
 exit
interface GigabitEthernet0/2
 description TRUNK_TO_HQ_SW2_Gi0_1
 switchport trunk encapsulation dot1q
 switchport mode trunk
 switchport trunk native vlan 999
 switchport trunk allowed vlan 30,40,99,999
 switchport nonegotiate
 no shutdown
 exit
interface FastEthernet0/1
 description DHCP_DNS_SERVER_Fa0
 switchport mode access
 switchport access vlan 50
 spanning-tree portfast
 spanning-tree bpduguard enable
 switchport port-security
 switchport port-security maximum 1
 switchport port-security mac-address sticky
 switchport port-security violation restrict
 no shutdown
 exit
interface FastEthernet0/24
 description ROUTED_TO_HQ_R1_Gi0_0
 no switchport
 ip address 10.10.0.117 255.255.255.252
 no shutdown
 exit
interface range FastEthernet0/2 - 23
 description UNUSED_SHUTDOWN
 switchport mode access
 switchport access vlan 998
 shutdown
 exit
spanning-tree vlan 10,20,30,40,50,99 root primary
router ospf 1
 router-id 1.1.1.1
 passive-interface default
 no passive-interface FastEthernet0/24
 network 10.10.0.0 0.0.0.31 area 0
 network 10.10.0.32 0.0.0.31 area 0
 network 10.10.0.64 0.0.0.15 area 0
 network 10.10.0.128 0.0.0.63 area 0
 network 10.10.0.80 0.0.0.15 area 0
 network 10.10.0.96 0.0.0.15 area 0
 network 10.10.0.116 0.0.0.3 area 0
 exit
end
