# Proposed Phase 1 topology

Status: design and configuration draft; not inspected, applied or tested in Packet Tracer.
Models: 2 × 2911; 1 × 3560-24PS; 3 × 2960-24TT; 1 × Server-PT; 12 × PC-PT.
Interface names assume those Packet Tracer models. Check existing device models and interfaces before applying.

```mermaid
flowchart TB
  subgraph Swansea["Swansea HQ"]
    HQR["HQ-R1 · 2911"]
    CORE["HQ-CORE · 3560 · SVI gateways"]
    SW1["HQ-SW1 · 2960"]
    SW2["HQ-SW2 · 2960"]
    SERVER["Server-PT · DHCP + lab DNS · 10.10.0.82"]
    P1["4 PCs · VLANs 10 and 20"]
    P2["4 PCs · VLANs 30 and 40"]
    HQR ---|"10.10.0.116/30"| CORE
    CORE ---|"802.1Q: 10,20,99,999"| SW1
    CORE ---|"802.1Q: 30,40,99,999"| SW2
    CORE ---|"access VLAN 50"| SERVER
    SW1 --- P1
    SW2 --- P2
  end
  subgraph Cardiff["Cardiff branch"]
    BRR["BR-R1 · 2911 · subinterface gateways"]
    BRS["BR-SW1 · 2960"]
    BP["4 PCs · VLANs 10 and 40"]
    BRR ---|"802.1Q: 10,40,99,999"| BRS
    BRS --- BP
  end
  HQR ---|"Ethernet WAN · 10.10.0.112/30 · OSPF Area 0"| BRR
```

## Physical cable map

| Endpoint A | Endpoint B | Cable | Purpose |
|---|---|---|---|
| HQ-R1 Gi0/0 | HQ-CORE Fa0/24 | Copper straight-through | Routed core/router transit |
| HQ-R1 Gi0/1 | BR-R1 Gi0/1 | Copper crossover | Direct Ethernet WAN |
| HQ-CORE Gi0/1 | HQ-SW1 Gi0/1 | Copper crossover | Trunk |
| HQ-CORE Gi0/2 | HQ-SW2 Gi0/1 | Copper crossover | Trunk |
| HQ-CORE Fa0/1 | Server-PT Fa0 | Copper straight-through | Server access, VLAN 50 |
| HQ-SW1 Fa0/1–4 | HQ-PC01–04 Fa0 | Copper straight-through | PCs: VLAN 10,10,20,20 |
| HQ-SW2 Fa0/1–4 | HQ-PC05–08 Fa0 | Copper straight-through | PCs: VLAN 30,30,40,40 |
| BR-R1 Gi0/0 | BR-SW1 Gi0/1 | Copper straight-through | Router-on-a-stick trunk |
| BR-SW1 Fa0/1–4 | BR-PC01–04 Fa0 | Copper straight-through | PCs: VLAN 10,10,40,40 |

Packet Tracer automatic cable selection is also suitable. The core/router link uses a FastEthernet core port because both core GigabitEthernet ports serve access-switch trunks. This is an educational baseline without a throughput claim.

## Routing

HQ-CORE owns all HQ VLAN gateways; BR-R1 owns Cardiff VLAN gateways. HQ-R1 has only routed transit interfaces. All three participate in OSPF process 1, Area 0. Only the two transit links send OSPF hello packets; client and management interfaces are passive. No internet connection, default route, NAT or external DNS reachability is assumed.

Expected neighbours: HQ-CORE has 1; HQ-R1 has 2; BR-R1 has 1. Expected remote VLAN routes appear as OSPF routes. Verify 3560 support with `router ?` from global configuration mode and `show ip protocols` after configuration. Cisco hardware IOS support does not establish simulator support. If `router ospf 1` or a required command is rejected, record the error and stop before changing the architecture.

## Lab security

SSH login uses a local administrator, with VTY ACL 10 allowing HQ IT VLAN 30 and both management VLANs. Other client VLANs cannot administer devices through VTY. VLAN 998 parks disabled ports; VLAN 999 is the unused native VLAN. Only required VLANs traverse each trunk. Sticky port security, PortFast and BPDU Guard apply to endpoint ports. These drafts do not add traffic ACLs between departments; routing permits ordinary inter-VLAN connectivity.

The 2960 management SVI also requires a live link carrying VLAN 99. Physical console access remains available for recovery. Port-security restrict mode drops frames from unexpected MAC addresses; if moving a PC, inspect and update the sticky entry deliberately. `service password-encryption` is only weak obfuscation for eligible plaintext settings, not strong credential protection. Keep real secrets and configuration exports containing secrets out of public repositories.

Reference: [Cisco 3560 IP routing guide](https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst3560/software/release/15-0_1_se/configuration/guide/scg3560/swiprout.html).
