# Apply the proposed draft in a working copy

The original /home/ed/pt/saves/3.pkt has not been inspected or modified. The draft department names, PC allocation, IP mappings and port map need comparison with that file. Confirm proposed department labels before treating them as final. The files are complete configuration templates for the specified port map, not safe merge scripts for arbitrary existing configurations. Old routing, helpers, ACLs or interface settings may conflict; inspect running configurations first. Do not paste blindly over the existing save.

## Working copy and inventory

Open 3.pkt and inspect the topology. Use File → Save As to create a working copy such as Project03_Swansea_Cardiff_Phase1_WORKING.pkt in this package's packet-tracer folder. Preserve 3.pkt. Compare actual models, links, VLANs and addressing with network-architecture.md and ip-addressing.md. If starting an empty workspace is explicitly approved, place the devices listed there and cable them exactly as shown. Do not create Phase 2 yet.

## Credentials and simulator support

Each device file contains `REPLACE_WITH_ENABLE_SECRET` and `REPLACE_WITH_ADMIN_SECRET`. Replace both in a private working copy with your chosen lab secrets BEFORE pasting. Never use personal or production passwords. Cisco IOS treats these placeholder strings as literal passwords if you leave them unchanged. The published templates contain no real credentials.

On HQ-CORE, confirm OSPF support before applying the full draft: at the global configuration prompt enter `router ?` and look for `ospf`. Check actual interfaces with `show ip interface brief`. If required syntax is rejected, capture the exact error so the draft can be adapted to the installed simulator.

## Configuration order

1. HQ-CORE: configs/HQ-CORE.txt.
2. HQ-SW1 and HQ-SW2: their matching files.
3. HQ-R1: configs/HQ-R1.txt.
4. BR-R1: configs/BR-R1.txt.
5. BR-SW1: configs/BR-SW1.txt.
6. Server-PT: follow dhcp-server-setup.md.
7. Set all twelve PCs to DHCP.

In each device CLI, press Enter and answer `no` if an initial setup dialog appears, then paste the matching file after checking existing settings. The templates enter privileged EXEC and configuration modes and finish with `end`. They deliberately leave saving until you verify the configuration.

## Complete SSH on every device

After its matching template is applied, enter:

```text
configure terminal
crypto key generate rsa
```

When prompted for modulus size, enter `1024` for this Packet Tracer educational lab. If the simulator accepts 2048, use 2048 instead. Then:

```text
ip ssh version 2
end
show ip ssh
```

RSA generation is separate because prompt/syntax support varies between simulator devices. If `show ip ssh`, VTY ACLs, port-security or any other feature is unsupported, record the error and the limitation. Do not assume success. Where a device has VTY 5–15, inspect `show running-config` and apply the same login, SSH, access-class and timeout settings to that range; templates use the commonly supported 0–4 range.

Test SSH from an HQ IT PC (HQ-SW2 Fa0/1 or Fa0/2): `ssh -l netadmin 10.10.0.98`. Other device targets are .99, .97, 10.10.0.118, 10.20.0.65 and 10.20.0.66. An HQ ADMIN VLAN 10 PC should be denied SSH by ACL 10. Console access is unaffected.

## Save only after checking

On all six Cisco devices: `copy running-config startup-config`, then accept the default destination filename. In Packet Tracer use File → Save, close/reopen the working copy, and retest. After the verification plan passes, use Save As for `Project03_Swansea_Cardiff_Phase1.pkt` to preserve the tested baseline. Keep later Phase 2 work in a separate file.
