This project demonstrates a highly scalable, redundant, and secure network architecture suitable for medium to large enterprise environments. It combines Layer 2 and Layer 3 technologies to ensure high availability, load balancing, and optimized connectivity for both wired and wireless users.
Network Overview
The network is designed to support: Multiple VLANs for segmentation & Redundant gateways for fault tolerance & Dynamic routing QoS for IP telephony & Wireless access for mobile users & Scalable IP management and name resolution
Key Features
VLANs & Inter-VLAN Routing
Configured 10+ VLANs for user, server, voice, management, and guest segments
Router-on-a-Stick and SVIs (Switch Virtual Interfaces) used for inter-VLAN communication
Voice VLAN & QoS
Voice VLANs configured with Quality of Service (QoS) to prioritize VoIP traffic
Ensures low latency and jitter for IP phones
Spanning Tree Protocol
Rapid PVST+ implemented for loop prevention and fast convergence in Layer 2 domain
Port Security
Enabled port-level security with:
Sticky MAC addresses
MAC address limiting
Restricted violation mode for enhanced protection against unauthorized access
Dynamic Routing
Configured OSPF across routers for efficient, dynamic Layer 3 routing
Seamless integration between routing and switching components
Gateway Redundancy
Implemented HSRP (Hot Standby Router Protocol) to provide virtual default gateways
Ensures automatic failover between redundant routers
Wireless Infrastructure
WLC (Wireless LAN Controller) and Lightweight Access Points (CAPWAP) deployed
Wireless access provisioned for:
Employees (secure SSID)
Guests (isolated SSID)
Supports smartphones, laptops, and other wireless devices
Internal DNS
Internal DNS Server: 192.168.250.50 used for domain name resolution within the network
DHCP Services
Edge Routers act as DHCP servers
Large address pools configured to support scalable user growth
VoIP Support
IP Phones auto-register and receive extensions via DHCP and TFTP
Seamless peer-to-peer calling across the voice VLAN
Internet Access via NAT
Configured PAT (Port Address Translation) for secure internet access
Preserves internal IPs while enabling outbound connectivity
EtherChannel (Link Aggregation)
Core switches configured with EtherChannel for:
Link redundancy
Load balancing
Increased bandwidth between switches
? Technologies Used Cisco IOS
OSPF
HSRP
VLANs & SVIs
Rapid PVST+
DHCP, DNS
NAT (PAT)
QoS
EtherChannel
Wireless LAN Controller (WLC)