enable
configure terminal
hostname HQ-SW1
no ip domain-lookup
service password-encryption
enable secret REPLACE_WITH_ENABLE_SECRET
username netadmin privilege 15 secret REPLACE_WITH_ADMIN_SECRET
ip domain-name project03.lab
banner motd #Authorised lab administration only.#
access-list 10 permit 10.10.0.64 0.0.0.15
access-list 10 permit 10.10.0.96 0.0.0.15
access-list 10 permit 10.20.0.64 0.0.0.15
line console 0
 login local
 logging synchronous
 exec-timeout 10 0
 exit
line vty 0 4
 login local
 transport input ssh
 access-class 10 in
 exec-timeout 10 0
 exit
vlan 10
 name ADMIN_PROPOSED
 exit
vlan 20
 name FINANCE_PROPOSED
 exit
vlan 99
 name MANAGEMENT
 exit
vlan 998
 name UNUSED_PORTS
 exit
vlan 999
 name NATIVE_UNUSED
 exit
interface Vlan99
 description STATIC_MANAGEMENT
 ip address 10.10.0.98 255.255.255.240
 no shutdown
 exit
ip default-gateway 10.10.0.97
interface GigabitEthernet0/1
 description TRUNK_TO_HQ_CORE_Gi0_1
 switchport mode trunk
 switchport trunk native vlan 999
 switchport trunk allowed vlan 10,20,99,999
 switchport nonegotiate
 no shutdown
 exit
interface FastEthernet0/1
 description HQ-SW1_PC1_VLAN10
 switchport mode access
 switchport access vlan 10
 spanning-tree portfast
 spanning-tree bpduguard enable
 switchport port-security
 switchport port-security maximum 1
 switchport port-security mac-address sticky
 switchport port-security violation restrict
 no shutdown
 exit
interface FastEthernet0/2
 description HQ-SW1_PC2_VLAN10
 switchport mode access
 switchport access vlan 10
 spanning-tree portfast
 spanning-tree bpduguard enable
 switchport port-security
 switchport port-security maximum 1
 switchport port-security mac-address sticky
 switchport port-security violation restrict
 no shutdown
 exit
interface FastEthernet0/3
 description HQ-SW1_PC3_VLAN20
 switchport mode access
 switchport access vlan 20
 spanning-tree portfast
 spanning-tree bpduguard enable
 switchport port-security
 switchport port-security maximum 1
 switchport port-security mac-address sticky
 switchport port-security violation restrict
 no shutdown
 exit
interface FastEthernet0/4
 description HQ-SW1_PC4_VLAN20
 switchport mode access
 switchport access vlan 20
 spanning-tree portfast
 spanning-tree bpduguard enable
 switchport port-security
 switchport port-security maximum 1
 switchport port-security mac-address sticky
 switchport port-security violation restrict
 no shutdown
 exit
interface range FastEthernet0/5 - 24
 description UNUSED_SHUTDOWN
 switchport mode access
 switchport access vlan 998
 shutdown
 exit
interface range GigabitEthernet0/2
 description UNUSED_SHUTDOWN
 switchport mode access
 switchport access vlan 998
 shutdown
 exit
end
