Skip to content
DnsLister Forum

Where domain hunters compare notes

built a coffee shop network project to help me learn networking!

sorry if this seems weird/unstructured. i had ai help me write it because my explaining skills sucks and i was too tiered/lazy to write it my self. this project took me 11 hours to finish.

  1. Network Segmentation Architecture

Instead of a single "flat" network, the business layout is carved into distinct software rooms (VLANs) to enforce isolation and data compliance.

VLAN ID VLAN Name Purpose / Devices Attached Switch Port Assignment IP Range & Subnet Default Gateway
VLAN 10 POS_System Cash registers and receipt printer Fa0/1 – Fa0/2 192.168.10.0/24 192.168.10.1
VLAN 20 Customers Public Wi-Fi Access Point (AP) Fa0/6 192.168.20.0/24 192.168.20.1
VLAN 30 Shop_Mgmt Store Manager's PC and office printer Fa0/11 – Fa0/12 192.168.30.0/24 192.168.30.1
VLAN 99 Net_Mgmt IT Infrastructure ONLY (Switch/Router & IT Laptop) Fa0/24 192.168.99.0/24 192.168.99.1
VLAN 666 Blackhole Quarantine trap for all unused open ports Fa0/3-5, Fa0/7-10, Fa0/13-23, Gi0/2 Unrouted / Dead None
VLAN 999 Native_Dead Untagged background trunk traffic Gi0/1 (Uplink only) Unrouted / Dead None
  1. Switch Hardening Configurations (coffeeshop-switch)

Global Protection

  • Domain Lookup Disabled: Avoids CLI lockups on typos by turning off DNS translation for mis-typed commands.
  • Local Database Authentication: Created a root-level account (username m3alim secret 5 ...) for access.

Port Security Policy (VLAN 10 – Payment Ports)

  • Static Access Mode: Dynamically negotiated connections are explicitly forbidden on user ports.
  • Sticky MAC Learning: The port dynamically binds to and memorizes the first 2 physical devices plugged into it.
  • Protect Violation Mode: If a 3rd unauthorized MAC address attempts to inject packets, the switch silently drops the traffic while keeping legitimate hardware active.
  • STP Portfast Enforced: Bypasses standard Spanning Tree listening loops to connect store devices immediately.

IT Management Port Hardening (Fa0/24)

  • Intense Security Layer: Locked to a strict maximum of 1 sticky MAC address with a Restrict violation mode (drops data and increments an error counter).
  • DTP Disabled (nonegotiate): Completely kills Dynamic Trunking Protocol negotiation to eliminate layer-2 sniffing vectors.

Exclusive Remote Access (The single VTY 0 Doorway)

  • Concurrency Lockdown: Restricted lines down to only line vty 0. If you are logged in from your IT laptop, the administrative pathway is physically full.
  • Protocol Banning: Enforced transport input ssh, disabling plaintext Telnet entirely.
  • Cryptographic Strength: Generated RSA crypto keys bound to ip domain-name using a modern, secure 2048-bit modulus.

Access Layer Defense-in-Depth (The Blackhole)

  • All unused active interfaces are assigned to VLAN 666 (Blackhole) and set to an administrative shutdown state. If a hacker awakens the hardware port via a software exploit, they are safely trapped in a void with no routing out.
  1. Router Highway & Automation (Router)

Router-on-a-Stick Backbone

The switch trunk link (Gi0/1) feeds directly into the router's physical port (Gi0/0/0). The physical interface remains unconfigured with an IP, instead split into 4 distinct virtual sub-interfaces acting as gateways:

The DHCP IP Automation Factory

Four completely independent DHCP server pools automate the storefront addressing.

  • Core IP Exclusions: Handing out .1 and .2 on the management network is banned via ip dhcp excluded-address to protect the router sub-interface and switch static SVI (192.168.99.2).
  • End-Device Automation: Flipping PCs, laptops, and registers to DHCP mode instantly fishes the correct IP variables based on their switchport home.1. Network Segmentation ArchitectureInstead of a single "flat" network, the business layout is carved into distinct software rooms (VLANs) to enforce isolation and data compliance.VLAN IDVLAN NamePurpose / Devices AttachedSwitch Port AssignmentIP Range & SubnetDefault Gateway VLAN 10POS_SystemCash registers and receipt printerFa0/1 – Fa0/2192.168.10.0/24192.168.10.1 VLAN 20CustomersPublic Wi-Fi Access Point (AP)Fa0/6192.168.20.0/24192.168.20.1 VLAN 30Shop_MgmtStore Manager's PC and office printerFa0/11 – Fa0/12192.168.30.0/24192.168.30.1 VLAN 99Net_MgmtIT Infrastructure ONLY (Switch/Router & IT Laptop)Fa0/24192.168.99.0/24192.168.99.1 VLAN 666BlackholeQuarantine trap for all unused open portsFa0/3-5, Fa0/7-10, Fa0/13-23, Gi0/2Unrouted / DeadNone VLAN 999Native_DeadUntagged background trunk trafficGi0/1 (Uplink only)Unrouted / DeadNone2. Switch Hardening Configurations (coffeeshop-switch)Global ProtectionDomain Lookup Disabled: Avoids CLI lockups on typos by turning off DNS translation for mis-typed commands. Local Database Authentication: Created a root-level account (username m3alim secret 5 …) for access.Port Security Policy (VLAN 10 – Payment Ports)Static Access Mode: Dynamically negotiated connections are explicitly forbidden on user ports. Sticky MAC Learning: The port dynamically binds to and memorizes the first 2 physical devices plugged into it. Protect Violation Mode: If a 3rd unauthorized MAC address attempts to inject packets, the switch silently drops the traffic while keeping legitimate hardware active. STP Portfast Enforced: Bypasses standard Spanning Tree listening loops to connect store devices immediately.IT Management Port Hardening (Fa0/24)Intense Security Layer: Locked to a strict maximum of 1 sticky MAC address with a Restrict violation mode (drops data and increments an error counter). DTP Disabled (nonegotiate): Completely kills Dynamic Trunking Protocol negotiation to eliminate layer-2 sniffing vectors.Exclusive Remote Access (The single VTY 0 Doorway)Concurrency Lockdown: Restricted lines down to only line vty 0. If you are logged in from your IT laptop, the administrative pathway is physically full. Protocol Banning: Enforced transport input ssh, disabling plaintext Telnet entirely. Cryptographic Strength: Generated RSA crypto keys bound to ip domain-name using a modern, secure 2048-bit modulus.Access Layer Defense-in-Depth (The Blackhole)All unused active interfaces are assigned to VLAN 666 (Blackhole) and set to an administrative shutdown state. If a hacker awakens the hardware port via a software exploit, they are safely trapped in a void with no routing out.3. Router Highway & Automation (Router)Router-on-a-Stick BackboneThe switch trunk link (Gi0/1) feeds directly into the router's physical port (Gi0/0/0). The physical interface remains unconfigured with an IP, instead split into 4 distinct virtual sub-interfaces acting as gateways:Gi0/0/0.10 → encapsulation dot1q 10 → 192.168.10.1 Gi0/0/0.20 → encapsulation dot1q 20 → 192.168.20.1 Gi0/0/0.30 → encapsulation dot1q 30 → 192.168.30.1 Gi0/0/0.99 → encapsulation dot1q 99 → 192.168.99.1The DHCP IP Automation FactoryFour completely independent DHCP server pools automate the storefront addressing.Core IP Exclusions: Handing out .1 and .2 on the management network is banned via ip dhcp excluded-address to protect the router sub-interface and switch static SVI (192.168.99.2). End-Device Automation: Flipping PCs, laptops, and registers to DHCP mode instantly fishes the correct IP variables based on their switchport home.

Source: r/ccna · by /u/Radiant-Ad-9731

Leave a Reply

Your email address will not be published. Required fields are marked *