Switching and Routing Essentials for Enterprise Networks
Self-paced Packet Tracer labs from device basics to VLANs, OSPF, ACLs, NAT, wireless, and a capstone network.
This is the switching and routing course I wish I had when I started fixing office networks in Kampala. You will not read a slide deck. You will build one enterprise network, piece by piece, inside Cisco Packet Tracer. We start by plugging into a console port and setting a hostname. By the end you are running VLANs across trunks, bundling links with LACP, tuning spanning tree, routing with OSPF, filtering traffic with ACLs, translating addresses with PAT, standing up a wireless LAN, and handing a documented network over to a client. Every teaching lesson follows the same rhythm. First the concept in plain language, then the topology, then the exact Cisco IOS commands in order, then the show commands that prove it works, then the mistakes that will cost you an afternoon if nobody warns you. What you will be able to do when you finish: - Secure management access on a new switch or router before it ever carries traffic - Design a VLAN plan for a multi department office and route between the VLANs - Bundle uplinks with EtherChannel and keep spanning tree predictable - Choose between static routes and OSPF, and configure both correctly - Hand out addresses with DHCP across subnets using a relay - Write standard and extended ACLs that filter what you meant to filter - Configure NAT and PAT so a branch office can reach the internet on one public address - Stand up a WLAN with a WLC and secure it with WPA2 - Harden layer 2 against DHCP spoofing, ARP poisoning, and rogue switches - Troubleshoot a broken network using a repeatable layered method Bring a laptop, install Packet Tracer, and give yourself a few hours a week. The labs are where you actually learn this.
Curriculum Outline
Preliminary: Packet Tracer and Device Access
-
Welcome and how this course works (text)
Welcome
You are about to build a working enterprise network from an empty Packet Tracer canvas. Not a diagram of one, an actual running network with VLANs, trunks, redundant uplinks, a routing protocol, access control lists, address translation, and wireless. By the last section you will hand that network over with documentation, the way you would hand it to a paying client.
I teach this the way I learned it on the job. Concept first, in plain language. Then the topology, so you know what you are building. Then the commands in the order you actually type them. Then the verification output, because a config you have not verified is a guess. Then the mistakes, because somebody should warn you before you lose an afternoon to a native VLAN mismatch.
Learning objectives for this lesson
- Understand the structure of the course and why the order matters
- Know what a lesson, a lab brief, a quiz, and an assignment each expect from you
- Set up a study rhythm you can keep for six to eight weeks
- Know how to ask for help in a way that gets a fast answer
How the course is laid out
Thirteen sections, each one a layer on the same network:
- Preliminary, Packet Tracer and device access. You cannot configure what you cannot log into.
- VLANs and inter-VLAN routing, the heart of campus switching.
- EtherChannel, turning several physical links into one logical link.
- Spanning Tree Protocol, keeping redundancy from becoming a broadcast storm.
- Static routing, the manual way, and when manual is the right answer.
- Single-area OSPF, letting routers learn from each other.
- FHRP and HSRP, so one dead gateway does not stop the office.
- DHCP and relay, automatic addressing across subnets.
- Access control lists, filtering traffic on purpose.
- NAT and PAT, many private hosts behind one public address.
- Wireless LANs, access points, a controller, and WPA2.
- Layer 2 and layer 3 security, port security, DHCP snooping, dynamic ARP inspection.
- Capstone and troubleshooting, build it all, then fix a network you did not configure.
Work them in order. Section 4 assumes you understand trunks from section 2. Section 13 assumes everything.
The five lesson types
Video lessons
A demonstration you can watch once and then repeat yourself. Under every video there is a written article with the same commands, so you never have to scrub back through a video to find a syntax detail.
Text lessons
Written explanation and command walkthroughs. These are the pages you will come back to months from now.
Resource lessons
Downloadable lab briefs in Markdown. Each brief has an addressing table, numbered tasks, and verification checks. Do the labs. They are the course.
Quizzes
Four or five questions per section, pass mark 70 percent. They check understanding, not memory of trivia. You get three attempts.
Assignments
Graded submissions where you paste your configuration and your verification output. Marked out of 100, pass mark 60. This is where I can actually see whether your network works.
What you need before section 2
- Cisco Packet Tracer 8.2 or newer, installed and logged in with a free Networking Academy account
- A notebook, paper or digital, for your addressing tables. Every serious network engineer keeps one.
- About five hours a week. Two hours of watching and reading, three hours of labbing.
A study rhythm that works
- Watch the videos in a section once, at normal speed, without touching the keyboard.
- Read the article under each video and copy the commands into your notes by hand.
- Download the lab brief and build it from the addressing table without looking at the lesson.
- Break one thing on purpose. Shut an interface, remove a VLAN from a trunk, change a subnet mask. Then find it with show commands.
- Take the quiz, then write the assignment.
The students who finish this course are not the fastest ones. They are the ones who rebuild each lab a second time from a blank canvas.
Getting help
Use the course forum. Two threads are already open, one for introductions and one that is a dedicated VLAN help desk. When you post a problem, include your topology in one line, the show command output, and the exact thing that failed. That gets you an answer in hours instead of days.
A note on honesty
This is original Katusome content. The topologies, addressing plans, lab briefs, and assignments here were written for this course. The skills map onto entry level enterprise networking certifications, but nothing in here is exam material, and you should not treat it as such. Learn the network, and the exam takes care of itself.
Next up: install Packet Tracer and build your first two device topology.
- Installing Packet Tracer and building your first topology (video)
- CLI modes: user EXEC, privileged EXEC, global config (video)
- Out-of-the-box basics: hostname, passwords, banners, DNS (video)
- Console port and remote access with SSH (video)
- Lab download: Basic device security starter (resource)
- Quiz: Device access fundamentals (quiz)
- Assignment: Configure secure management access (assignment)
VLANs and Inter-VLAN Routing
- VLAN concepts: why we segment (video)
- Creating VLANs and access ports (video)
- 802.1Q trunking and the native VLAN (video)
- Router-on-a-stick inter-VLAN routing (video)
- Layer 3 switching with SVIs (video)
- Lab brief: SVI inter-VLAN routing (resource)
-
Voice VLANs overview (text)
Learning objectives
- Explain why voice traffic needs its own VLAN
- Describe how an IP phone and a PC share one access port
- Configure a voice VLAN with the right trust and quality of service settings
- Verify the voice VLAN and read the phone side of CDP
Why voice is different
Voice packets are small, constant, and completely intolerant of delay. A file transfer does not care about fifty milliseconds of jitter. A phone call turns into robot noise. The fix has two parts: separate voice into its own VLAN and subnet so that broadcast traffic and bulk transfers do not sit in the same queue, then mark voice traffic so switches prioritise it.
There is a practical problem. Offices have one network cable per desk, and the desk needs both a phone and a PC. The standard answer is to daisy chain: wall socket to phone, phone to PC. The phone has a small built in switch. Now one switch port must carry two VLANs from two devices, one of which knows nothing about tagging.
How the shared port works
[ KLA-SW-01 Fa0/5 ] | | VLAN 30 tagged from the phone | VLAN 10 untagged from the PC | [ IP Phone ] ---- [ PC ] 192.168.30.x 192.168.10.xFigure: one cable, two VLANs, one of them untagged. The phone tags its own traffic and passes the PC traffic through untouched.
The
switchport voice vlan 30command turns the access port into a special hybrid. The access VLAN, 10 here, remains untagged for the PC. The voice VLAN, 30, is carried tagged for the phone. The switch advertises the voice VLAN ID to the phone over CDP or LLDP-MED, so the phone learns which VLAN to tag with, automatically. No configuration on the phone at all, which is why this design survives in offices where nobody manages phones.Configuration
- Create the voice VLAN,
vlan 30thenname VOICE. - Give it a gateway, either a subinterface or an SVI at 192.168.30.1/24, and a DHCP scope.
- On the access port set
switchport mode accessandswitchport access vlan 10for the PC. - Add
switchport voice vlan 30. The port now serves both. - Trust the phone marking with
mls qos trust cos, or classify and mark on the switch if you do not trust the handsets. - Enable PortFast with
spanning-tree portfast, so the phone and PC come up quickly after a power cut. - Leave
switchport port-securityoff on these ports until you have read the layer 2 security section, because a phone plus a PC means two MAC addresses on one port and a default port security setting of one will shut the port.
Verification
show interfaces FastEthernet0/5 switchport, look for the Voice VLAN line reporting 30show vlan brief, VLAN 30 exists and the port appears under the access VLANshow cdp neighbors, a Cisco phone appears as a neighbour with its platform and the port it is onshow mac address-table interface FastEthernet0/5, two MAC addresses on one port, one in VLAN 10 and one in VLAN 30. That is the clearest single proof the design works.
Common mistakes
- No DHCP scope for the voice subnet. The phone boots, learns VLAN 30, and then has no address.
- Port security with a maximum of one MAC. Either the phone or the PC gets shut out. Set the maximum to at least two, three if the phone has its own management MAC.
- Trusting CoS on a port a user can reach. Anyone can mark their own traffic as high priority. Trust the phone, not the PC behind it.
- Putting voice on the same subnet as data to save effort. It works on a quiet day and falls apart during the monthly backup.
Practice beyond this lab
Voice VLANs are a small topic with real world value, so a single focused lab is enough. These three community lab repositories are free, and I have used all of them with students:
- Cisco Packet Tracer Labs for CCNA, broad topic coverage with ready .pkt files
- CCNA-Labs, compact labs that are good for a 30 minute session
- Packet Tracer Practice Labs, scenario style labs with written tasks
Tip: open a community lab, break something on purpose, then fix it. Deliberate breakage teaches faster than clean configuration.
- Lab pack: VLANs, trunks, and router-on-a-stick (resource)
- Quiz: VLANs and inter-VLAN routing (quiz)
- Assignment: Multi-VLAN Packet Tracer topology (assignment)
EtherChannel: Bundling Links
- EtherChannel concepts: one logical link from many (video)
- Configuring LACP step by step (video)
-
Verifying and troubleshooting EtherChannel (text)
Learning objectives
- Run a repeatable five command verification pass on any bundle
- Map each symptom to the flag that reveals it
- Confirm load distribution across members
- Document a bundle so the next engineer does not have to guess
The five command pass
When somebody hands you a switch and says the uplink is slow, run these five in this order and you will know where you stand within a minute.
show etherchannel summary. How many members, what flags, is the port channel SU.show interfaces port-channel1. Bandwidth, input and output rates, errors. This tells you whether the bundle is actually busy or whether the complaint is about something else entirely.show interfaces trunk. Is Po1 trunking, what is the native VLAN, what is allowed, what is forwarding.show spanning-tree vlan 10. One entry for Po1 and nothing for the members. If members appear individually, the bundle is broken and spanning tree has blocked something.show lacp neighbor. Does the far end agree, and is it the device you think it is.
Symptom to cause table
Symptom Look at Likely cause --------------------------------------- --------------------------- ----------------------------- Po1 shows SD, members show D show interfaces status Cables down or ports shut One member shows s show interfaces switchport Mode, native VLAN, or on both ends allowed list mismatch All members show I show lacp neighbor Far end not configured, or passive meets passive Po1 up but VLAN 20 will not cross show interfaces trunk VLAN 20 not in allowed list, or missing from VLAN database Members appear in spanning tree show etherchannel summary Bundle never formed Bundle up, throughput still one link show interfaces counters Single flow, hash sends it all down one memberFigure: print this and keep it. It has saved me more time than any other page of notes.
Confirming load distribution
Run
show interfaces countersand compare the output packet counts of Gi0/1 and Gi0/2. Perfect balance is not the goal and you will never see it. What you want is both members carrying meaningful traffic. If one member shows millions of packets and the other shows a few hundred, your hash is a poor fit for the traffic. Switching from the MAC based default tosrc-dst-ipusually fixes it on a switch to switch uplink, because behind a router all traffic shares one or two MAC addresses but spreads across many IP pairs.On platforms that support it,
test etherchannel load-balance interface port-channel1 ip 192.168.10.10 192.168.20.10tells you exactly which member a given flow would take. Useful for explaining to somebody why their backup is not going faster.Documenting a bundle
Four things in your documentation, every time:
- Which physical ports are members, on both switches
- The channel group number on each side
- The protocol and mode, for example LACP active on both ends
- The trunk settings: native VLAN and allowed list
Put the same information in interface descriptions on the device.
description Po1 member, to KLA-SW-02 Gi0/1costs nothing and answers the question at 2am without a diagram.Common mistakes
- Diagnosing from the member ports. Start at the port channel and work down.
- Assuming a suspended port is a hardware fault. It is a configuration mismatch nearly every time.
- Not comparing both ends. Every EtherChannel fault needs output from both switches. One sided troubleshooting wastes hours.
- Clearing counters without noting the old values. You lose your only evidence of how the traffic was distributed.
Practice beyond this lab
Troubleshooting drills are the highest value use of a community lab repository. These three community lab repositories are free, and I have used all of them with students:
- Cisco Packet Tracer Labs for CCNA, broad topic coverage with ready .pkt files
- CCNA-Labs, compact labs that are good for a 30 minute session
- Packet Tracer Practice Labs, scenario style labs with written tasks
Tip: open a community lab, break something on purpose, then fix it. Deliberate breakage teaches faster than clean configuration.
- Lab download: LACP bundle and failover (resource)
- Quiz: EtherChannel (quiz)
- Assignment: Build and test an LACP bundle (assignment)
Spanning Tree Protocol
- Why spanning tree exists: loops and broadcast storms (video)
- Root bridge election, port costs, and PortFast with BPDU Guard (video)
-
Reading the spanning tree topology like an engineer (text)
Learning objectives
- Read every field of show spanning-tree vlan output
- Draw the logical tree from command output alone
- Identify which port is blocking and why
- Recognise a topology change storm and find its source
Dissecting the output
When you run
show spanning-tree vlan 10you get three blocks. Read them in order and the topology assembles itself in your head.VLAN0010 Spanning tree enabled protocol rstp <- mode, you want rstp Root ID Priority 4106 <- 4096 + VLAN 10 Address 00D0.BA12.3456 <- root switch MAC Cost 4 <- our cost to reach root Port 25 (GigabitEthernet0/1) Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Bridge ID Priority 32778 <- our own priority Address 00E0.F7AB.CDEF <- our MAC Interface Role Sts Cost Prio.Nbr Type -------------- ---- --- ------ -------- ---- Gi0/1 Root FWD 4 128.25 P2p Gi0/2 Altn BLK 4 128.26 P2p Fa0/1 Desg FWD 19 128.1 P2p EdgeFigure: annotated output. Three facts jump out: we are not root, our best path to root is Gi0/1, and Gi0/2 is our standby.
What each field tells you
- Root ID Priority and Address. If these match the Bridge ID block below, this switch is the root. If not, somebody else is, and the Address tells you exactly which switch.
- Root Cost. Accumulated cost to reach the root. Zero means you are root.
- Root Port. The single interface pointing toward the root. Every non root switch has exactly one.
- Role. Root, Desg for designated, Altn for alternate, Back for backup.
- Sts. FWD forwarding, BLK blocking or discarding, LRN learning.
- Type. P2p for a point to point link, Edge for a PortFast port, Shr for a shared segment through a hub.
Drawing the tree from output
- Run
show spanning-tree rooton any switch. Note the root bridge MAC and the VLAN. - On each switch run
show spanning-tree vlan 10and write down its root port and its cost. - Draw the root at the top. Draw each switch below it, connected by its root port.
- Mark every Altn BLK port with a cross. Those are the links that carry nothing today.
- Compare that picture with your cabling diagram. Anywhere the tree looks lopsided, your root placement or your costs need attention.
Do this once for a real network and you will understand your own topology better than the diagram on the wall, because the diagram shows what somebody intended and this shows what the switches actually decided.
Topology change storms
Every time a port transitions, the switch sends a topology change notification and switches flush MAC tables early. A flapping link therefore causes repeated MAC table flushes, which causes flooding, which looks like a performance problem rather than a link problem.
show spanning-tree detail | include changesgives you a per VLAN topology change counter. A healthy network changes a handful of times a day, not hundreds.show spanning-tree vlan 10 detailreports the last topology change and which port caused it. That port is your culprit.show interfaces Fa0/9 | include reset|erroron the suspect port usually reveals a dying cable or a failing NIC.
Common mistakes
- Assuming a BLK port is broken. A blocking alternate port is spanning tree working correctly.
- Reading only one switch. The tree is a network wide construct. Collect output from every switch.
- Ignoring the topology change counter. It is the earliest warning of a failing cable you will get.
- Confusing Root ID with Bridge ID. Read both blocks. They are different things and the difference is the whole answer.
Practice beyond this lab
Reading topology output is a skill, and the only way to build it is volume. These three community lab repositories are free, and I have used all of them with students:
- Cisco Packet Tracer Labs for CCNA, broad topic coverage with ready .pkt files
- CCNA-Labs, compact labs that are good for a 30 minute session
- Packet Tracer Practice Labs, scenario style labs with written tasks
Tip: open a community lab, break something on purpose, then fix it. Deliberate breakage teaches faster than clean configuration.
- Lab download: Spanning tree basics and root placement (resource)
- Quiz: Spanning Tree Protocol (quiz)
- Assignment: Design and verify a predictable spanning tree (assignment)
Static Routing
- Static routes: syntax, next hops, and the routing table (video)
- Static routing lab walkthrough and verification (video)
- Lab download: Static and default routes (resource)
- Quiz: Static routing (quiz)
- Assignment: Route a three site network with static routes (assignment)
Single-Area OSPF
- OSPF fundamentals: neighbours, LSAs, and the DR election (video)
- Configuring and verifying single-area OSPF (video)
- OSPF path selection and failover in practice (text)
- Lab download: Single-area OSPF (resource)
- Quiz: Single-area OSPF (quiz)
- Assignment: Deploy single-area OSPF with a redundant path (assignment)
First Hop Redundancy with HSRP
- Why the default gateway is a single point of failure (video)
- Configuring and verifying HSRP (video)
- Quiz: First hop redundancy (quiz)
- Assignment: Redundant gateways with HSRP load sharing (assignment)
DHCP and DHCP Relay
- How DHCP works and how to run it on a Cisco router (video)
- DHCP relay across subnets (video)
- Quiz: DHCP and relay (quiz)
- Assignment: Central DHCP with relay for three VLANs (assignment)
Access Control Lists
- ACL fundamentals: wildcard masks, order, and the implicit deny (video)
- Writing, applying, and verifying real ACLs (video)
- Quiz: Access control lists (quiz)
- Assignment: Filter an office network with ACLs (assignment)
NAT and PAT
- NAT concepts: inside, outside, local, and global (video)
- Configuring static NAT, dynamic NAT, and PAT (video)
- Quiz: NAT and PAT (quiz)
- Assignment: Give a branch office internet access with PAT (assignment)
Wireless LANs
- WLAN fundamentals: bands, channels, and coverage (video)
- Configuring a WLAN with a controller and WPA2 (video)
- Quiz: Wireless LANs (quiz)
- Assignment: Stand up a secure staff and guest WLAN (assignment)
Layer 2 and Layer 3 Security
- Layer 2 attacks and the features that stop them (video)
- Port security, DHCP snooping, and dynamic ARP inspection (text)
- Quiz: Layer 2 and layer 3 security (quiz)
- Assignment: Harden an access switch against layer 2 attacks (assignment)
Capstone and Troubleshooting
- A troubleshooting method you can repeat under pressure (text)
- Capstone network brief: build it all (text)
- Lab download: Capstone brief and verification matrix (resource)
- Quiz: Troubleshooting method (quiz)
- Capstone assignment: Build, document, and defend a full enterprise network (assignment)