sorry if this seems weird/unstructured. i had ai help me write it because my explaining skills sucks and i was too tiered/lazy to write it my self. this project took me 11 hours to finish.
- Network Segmentation Architecture
Instead of a single "flat" network, the business layout is carved into distinct software rooms (VLANs) to enforce isolation and data compliance.
| VLAN ID | VLAN Name | Purpose / Devices Attached | Switch Port Assignment | IP Range & Subnet | Default Gateway |
|---|---|---|---|---|---|
| VLAN 10 | POS_System |
Cash registers and receipt printer | Fa0/1 – Fa0/2 |
192.168.10.0/24 |
192.168.10.1 |
| VLAN 20 | Customers |
Public Wi-Fi Access Point (AP) | Fa0/6 |
192.168.20.0/24 |
192.168.20.1 |
| VLAN 30 | Shop_Mgmt |
Store Manager's PC and office printer | Fa0/11 – Fa0/12 |
192.168.30.0/24 |
192.168.30.1 |
| VLAN 99 | Net_Mgmt |
IT Infrastructure ONLY (Switch/Router & IT Laptop) | Fa0/24 |
192.168.99.0/24 |
192.168.99.1 |
| VLAN 666 | Blackhole |
Quarantine trap for all unused open ports | Fa0/3-5, Fa0/7-10, Fa0/13-23, Gi0/2 |
Unrouted / Dead | None |
| VLAN 999 | Native_Dead |
Untagged background trunk traffic | Gi0/1 (Uplink only) |
Unrouted / Dead | None |
- Switch Hardening Configurations (
coffeeshop-switch)
Global Protection
- Domain Lookup Disabled: Avoids CLI lockups on typos by turning off DNS translation for mis-typed commands.
- Local Database Authentication: Created a root-level account (
username m3alim secret 5 ...) for access.
Port Security Policy (VLAN 10 – Payment Ports)
- Static Access Mode: Dynamically negotiated connections are explicitly forbidden on user ports.
- Sticky MAC Learning: The port dynamically binds to and memorizes the first 2 physical devices plugged into it.
- Protect Violation Mode: If a 3rd unauthorized MAC address attempts to inject packets, the switch silently drops the traffic while keeping legitimate hardware active.
- STP Portfast Enforced: Bypasses standard Spanning Tree listening loops to connect store devices immediately.
IT Management Port Hardening (Fa0/24)
- Intense Security Layer: Locked to a strict maximum of 1 sticky MAC address with a Restrict violation mode (drops data and increments an error counter).
- DTP Disabled (
nonegotiate): Completely kills Dynamic Trunking Protocol negotiation to eliminate layer-2 sniffing vectors.
Exclusive Remote Access (The single VTY 0 Doorway)
- Concurrency Lockdown: Restricted lines down to only
line vty 0. If you are logged in from your IT laptop, the administrative pathway is physically full. - Protocol Banning: Enforced
transport input ssh, disabling plaintext Telnet entirely. - Cryptographic Strength: Generated RSA crypto keys bound to
ip domain-nameusing a modern, secure 2048-bit modulus.
Access Layer Defense-in-Depth (The Blackhole)
- All unused active interfaces are assigned to VLAN 666 (
Blackhole) and set to an administrativeshutdownstate. If a hacker awakens the hardware port via a software exploit, they are safely trapped in a void with no routing out.
- Router Highway & Automation (
Router)
Router-on-a-Stick Backbone
The switch trunk link (Gi0/1) feeds directly into the router's physical port (Gi0/0/0). The physical interface remains unconfigured with an IP, instead split into 4 distinct virtual sub-interfaces acting as gateways:
Gi0/0/0.10→encapsulation dot1q 10→192.168.10.1Gi0/0/0.20→encapsulation dot1q 20→192.168.20.1Gi0/0/0.30→encapsulation dot1q 30→192.168.30.1Gi0/0/0.99→encapsulation dot1q 99→192.168.99.1
The DHCP IP Automation Factory
Four completely independent DHCP server pools automate the storefront addressing.
- Core IP Exclusions: Handing out
.1and.2on the management network is banned viaip dhcp excluded-addressto protect the router sub-interface and switch static SVI (192.168.99.2). - End-Device Automation: Flipping PCs, laptops, and registers to DHCP mode instantly fishes the correct IP variables based on their switchport home.1. Network Segmentation ArchitectureInstead of a single "flat" network, the business layout is carved into distinct software rooms (VLANs) to enforce isolation and data compliance.VLAN IDVLAN NamePurpose / Devices AttachedSwitch Port AssignmentIP Range & SubnetDefault Gateway VLAN 10POS_SystemCash registers and receipt printerFa0/1 – Fa0/2192.168.10.0/24192.168.10.1 VLAN 20CustomersPublic Wi-Fi Access Point (AP)Fa0/6192.168.20.0/24192.168.20.1 VLAN 30Shop_MgmtStore Manager's PC and office printerFa0/11 – Fa0/12192.168.30.0/24192.168.30.1 VLAN 99Net_MgmtIT Infrastructure ONLY (Switch/Router & IT Laptop)Fa0/24192.168.99.0/24192.168.99.1 VLAN 666BlackholeQuarantine trap for all unused open portsFa0/3-5, Fa0/7-10, Fa0/13-23, Gi0/2Unrouted / DeadNone VLAN 999Native_DeadUntagged background trunk trafficGi0/1 (Uplink only)Unrouted / DeadNone2. Switch Hardening Configurations (coffeeshop-switch)Global ProtectionDomain Lookup Disabled: Avoids CLI lockups on typos by turning off DNS translation for mis-typed commands. Local Database Authentication: Created a root-level account (username m3alim secret 5 …) for access.Port Security Policy (VLAN 10 – Payment Ports)Static Access Mode: Dynamically negotiated connections are explicitly forbidden on user ports. Sticky MAC Learning: The port dynamically binds to and memorizes the first 2 physical devices plugged into it. Protect Violation Mode: If a 3rd unauthorized MAC address attempts to inject packets, the switch silently drops the traffic while keeping legitimate hardware active. STP Portfast Enforced: Bypasses standard Spanning Tree listening loops to connect store devices immediately.IT Management Port Hardening (Fa0/24)Intense Security Layer: Locked to a strict maximum of 1 sticky MAC address with a Restrict violation mode (drops data and increments an error counter). DTP Disabled (nonegotiate): Completely kills Dynamic Trunking Protocol negotiation to eliminate layer-2 sniffing vectors.Exclusive Remote Access (The single VTY 0 Doorway)Concurrency Lockdown: Restricted lines down to only line vty 0. If you are logged in from your IT laptop, the administrative pathway is physically full. Protocol Banning: Enforced transport input ssh, disabling plaintext Telnet entirely. Cryptographic Strength: Generated RSA crypto keys bound to ip domain-name using a modern, secure 2048-bit modulus.Access Layer Defense-in-Depth (The Blackhole)All unused active interfaces are assigned to VLAN 666 (Blackhole) and set to an administrative shutdown state. If a hacker awakens the hardware port via a software exploit, they are safely trapped in a void with no routing out.3. Router Highway & Automation (Router)Router-on-a-Stick BackboneThe switch trunk link (Gi0/1) feeds directly into the router's physical port (Gi0/0/0). The physical interface remains unconfigured with an IP, instead split into 4 distinct virtual sub-interfaces acting as gateways:Gi0/0/0.10 → encapsulation dot1q 10 → 192.168.10.1 Gi0/0/0.20 → encapsulation dot1q 20 → 192.168.20.1 Gi0/0/0.30 → encapsulation dot1q 30 → 192.168.30.1 Gi0/0/0.99 → encapsulation dot1q 99 → 192.168.99.1The DHCP IP Automation FactoryFour completely independent DHCP server pools automate the storefront addressing.Core IP Exclusions: Handing out .1 and .2 on the management network is banned via ip dhcp excluded-address to protect the router sub-interface and switch static SVI (192.168.99.2). End-Device Automation: Flipping PCs, laptops, and registers to DHCP mode instantly fishes the correct IP variables based on their switchport home.
Source: r/ccna · by /u/Radiant-Ad-9731