Skip to content

Latest commit

History

22 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

TechCom banner

Tests Passed · CCNA-aligned · ⚑ Production-Ready

πŸš€ Quick Start Β· πŸ“ Architecture Β· βœ… Test Results

StatusCiscoTopologyVLANsRoutersSwitchesLicenseUniversity


Built by students, for students. A production-grade enterprise network β€” fully designed, configured, and verified in Cisco Packet Tracer, with full redundancy (HSRP + dual core), dynamic routing (OSPF), external edge (BGP + NAT/PAT), per-department segmentation (VLANs + ACLs), and hardened access (Port Security, BPDU Guard, SSH v2).


πŸ“‘ Table of Contents

  1. 🎯 About the Project
  2. πŸ—οΈ Architecture at a Glance
  3. 🌐 Topology Diagram
  4. 🧰 Tech Stack
  5. πŸ“ IP Addressing Plan
  6. πŸ—‚οΈ VLAN & Service Plan
  7. πŸ” Traffic Flow
  8. βš–οΈ HSRP Failover
  9. 🧩 Protocol Stack
  10. πŸ“ Repository Layout
  11. πŸš€ Quick Start
  12. βœ… Test Results
  13. 🧠 Challenges & Solutions
  14. πŸ›£οΈ Roadmap
  15. πŸ‘₯ Authors
  16. πŸ™ Acknowledgements
  17. πŸ“„ License

🎯 About the Project

TechCom is a fictional but realistic mid-sized telecom company whose network we β€” two IT undergraduates at the University of Ibb, Faculty of Applied Science, Department of Information Technology β€” designed from a blank canvas as our graduation project.

It is not a toy. Every decision in the design answers a real business question:

Business needNetwork answer
"Sales can't go down at 5 PM."Dual core + HSRP + dual uplinks
"Finance data must be isolated."Dedicated VLAN + trunk allow-list + ACL target
"We need phones, not just data."Separate Voice VLAN 150 with HSRP
"We must reach the Internet."BGP-style edge + NAT/PAT overload
"Plugging in a rogue switch must not break us."PortFast + BPDU Guard on every access port
"Configuration must be auditable."SSH v2, local user database, role-based exec

πŸ”¬ 100% of the test cases passed (see docs/TEST-RESULTS.md).


πŸ—οΈ Architecture at a Glance

 β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ ☁️ Internet / ISP β”‚
β”‚ ISP-Router (8.8.8.1) β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β”‚ Se0/0/0 200.100.50.0/30 β”‚ Se0/0/1 200.100.50.4/30
β”‚ β”‚
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β–Όβ”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β–Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ 🟦 CORE-R2 β”‚ β”‚ 🟦 CORE-R1 β”‚
β”‚ HSRP Standby │◄───────►│ HSRP Active β”‚
β”‚ NAT Β· BGP Β· OSPF β”‚ β”‚ NAT Β· BGP Β· OSPF β”‚
β””β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”˜ β””β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”˜
β”‚ Gi0/0 β”‚ Gi0/1 β”‚ Gi0/0 β”‚ Gi0/1
10.10.255.4/30 β”‚ 10.10.255.12/30 β”‚ 10.10.255.0/30 10.10.255.8/30
β”‚ β”‚ β”‚ β”‚
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β–Όβ”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β–Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β–Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β–Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ 🟩 DIST-SW1 β”‚ β”‚ 🟩 DIST-SW2 β”‚ β”‚ 🟩 DIST-SW1 β”‚ β”‚ 🟩 DIST-SW2 β”‚
β”‚ HSRP Active β”‚ β”‚ HSRP Standby β”‚ β”‚ HSRP Active β”‚ β”‚ HSRP Standbyβ”‚
β”‚ OSPF Β· SVIs β”‚ β”‚ OSPF Β· SVIs β”‚ β”‚ OSPF Β· SVIs β”‚ β”‚ OSPF Β· SVIs β”‚
β””β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”˜
β”‚ Trunk + EtherChannel Po1 β”‚ β”‚
β”‚ β”‚ β”‚
β”Œβ”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”
β”‚ β”‚
β”‚ 🟨 ACCESS LAYER β€” One access switch per department β”‚
β”‚ β”‚
β”‚ ACCESS-SW-IT (VLAN 20 + Voice 150) β”‚
β”‚ ACCESS-SW-SUPPORT (VLAN 30 + Voice 150) β”‚
β”‚ ACCESS-SW-FINANCE (VLAN 40 + Voice 150) β”‚
β”‚ ACCESS-SW-HR (VLAN 50 + Voice 150) β”‚
β”‚ ACCESS-SW-SALES (VLAN 60 + Voice 150) β”‚
β”‚ ACCESS-SW-MANAGEMENT (VLAN 10 only β€” isolated) β”‚
β”‚ β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

πŸ“ Reading the diagram: every arrow is a physical link. Logical relationships (HSRP, OSPF adjacency, EtherChannel) are noted on the link.


🌐 Topology Diagram

flowchart TB
Internet(["☁️ Internet<br/>(ISP Cloud)"])
ISP["πŸ›°οΈ ISP-Router<br/>8.8.8.1/24"]
R1["🟦 CORE-R1<br/>(HSRP Active · NAT · BGP)"]
R2["🟦 CORE-R2<br/>(HSRP Standby · NAT · BGP)"]
D1["🟩 DIST-SW1<br/>(L3 · HSRP Active)"]
D2["🟩 DIST-SW2<br/>(L3 · HSRP Standby)"]
subgraph ACCESS["🟨 Access Layer β€” One switch per department"]
SW_IT["ACCESS-SW-IT<br/>VLAN 20 + Voice 150"]
SW_SUP["ACCESS-SW-SUPPORT<br/>VLAN 30"]
SW_FIN["ACCESS-SW-FINANCE<br/>VLAN 40"]
SW_HR["ACCESS-SW-HR<br/>VLAN 50"]
SW_SAL["ACCESS-SW-SALES<br/>VLAN 60"]
SW_MGT["ACCESS-SW-MGMT<br/>VLAN 10 only"]
end
Internet --- ISP
ISP ---|Se0/0/0 200.100.50.0/30| R2
ISP ---|Se0/0/1 200.100.50.4/30| R1
R1 ---|Gi0/0 10.10.255.0/30| D1
R1 ---|Gi0/1 10.10.255.8/30| D2
R2 ---|Gi0/0 10.10.255.4/30| D1
R2 ---|Gi0/1 10.10.255.12/30| D2
D1 ---|Trunk + EC Po1| SW_IT
D2 ---|Trunk + EC Po1| SW_IT
D1 --- SW_SUP
D2 --- SW_SUP
D1 --- SW_FIN
D2 --- SW_FIN
D1 --- SW_HR
D2 --- SW_HR
D1 --- SW_SAL
D2 --- SW_SAL
D1 ---|Trunk VLAN 10 only| SW_MGT
D2 ---|Trunk VLAN 10 only| SW_MGT
classDef core fill:#1f3a8a,stroke:#1e3a8a,color:#fff,stroke-width:2px;
classDef dist fill:#0e7490,stroke:#0e7490,color:#fff,stroke-width:2px;
classDef acc fill:#a16207,stroke:#a16207,color:#fff,stroke-width:2px;
classDef isp fill:#374151,stroke:#374151,color:#fff,stroke-width:2px;
classDef net fill:#16a34a,stroke:#16a34a,color:#fff,stroke-width:2px;
class R1,R2 core;
class D1,D2 dist;
class SW_IT,SW_SUP,SW_FIN,SW_HR,SW_SAL,SW_MGT acc;
class ISP isp;
class Internet net;
Loading

πŸ‘‰ See also:diagrams/02-traffic-flow.md Β· diagrams/03-vlan-broadcast-domains.md Β· diagrams/04-hsrp-failover-state.md Β· diagrams/05-protocol-stack.md


🧰 Tech Stack

LayerTechnologyWhere
SimulationCisco Packet Tracer 8.xpacket-tracer/
RoutingOSPF (single-area), static, simulated BGPCore + Distribution
First-hop redundancyHSRP v1 (priority + preempt)DIST-SW1/2
Switching802.1Q, EtherChannel (LACP active), PVST+All switches
Edge servicesNAT/PAT overload, ACL 1CORE-R1 / CORE-R2
VoiceVoice VLAN 150 + DHCP helperAccess + Distribution
SecuritySSH v2 (RSA-1024), enable secret, login localAll devices
HardeningPortFast, BPDU Guard, trunk allow-listsEvery access port
DocumentationMarkdown, Mermaid, PowerPoint, PDFdocs/

πŸ“ IP Addressing Plan

Full table lives in docs/IP-PLAN.md. TL;DR:

BlockPurpose
10.10.0.0/16All internal traffic
10.10.10.0/24 … 10.10.150.0/24One /24 per VLAN/department
10.10.255.0/30 … 10.10.255.12/30Point-to-point core ↔ distribution
200.100.50.0/30 … 200.100.50.4/30Public edge to ISP
8.8.8.0/24Simulated Internet on ISP router

Department gateways (HSRP virtual IPs):

VLANSubnetGateway (HSRP)
10 β€” Management10.10.10.0/2410.10.10.1
20 β€” IT10.10.20.0/2410.10.20.1
30 β€” Support10.10.30.0/2410.10.30.1
40 β€” Finance10.10.40.0/2410.10.40.1
50 β€” HR10.10.50.0/2410.10.50.1
60 β€” Sales10.10.60.0/2410.10.60.1
99 β€” Device-plane10.10.99.0/2410.10.99.1
150 β€” Voice10.10.150.0/2410.10.150.1

πŸ—‚οΈ VLAN & Service Plan

VLAN IDNameRole
10ManagementSVI / management plane (SSH, SNMP)
20ITIT department + Voice
30SupportTechnical support
40FinanceFinance (ACL target)
50HRHuman resources
60SalesSales (QoS-ready)
99Device-planeRouter ↔ switch protocol traffic
100NativeTrunk native (must match on every link)
150Voice (VoIP)IP phones

Full breakdown & rationale: docs/VLAN-PLAN.md


πŸ” Traffic Flow

Normal path β€” Sales PC β†’ Internet

sequenceDiagram
autonumber
participant PC as πŸ’» Sales PC<br/>(10.10.60.10)
participant ACC as 🟨 ACCESS-SW-SALES
participant D1 as 🟩 DIST-SW1 (HSRP Active)
participant R1 as 🟦 CORE-R1
participant ISP as πŸ›°οΈ ISP-Router
participant NET as ☁️ Internet
PC->>ACC: Ping 8.8.8.8
ACC->>D1: Trunk VLAN 60 (EtherChannel Po1)
D1->>R1: OSPF route via Gi0/0 (10.10.255.0/30)
R1->>R1: PAT overload β†’ 200.100.50.5:port
R1->>ISP: Serial0/0/1
ISP->>NET: Static route 0.0.0.0/0 β†’ Gi0/0
NET-->>PC: ICMP echo reply (no drops)
Loading

Failover path β€” CORE-R1 dies

sequenceDiagram
autonumber
participant PC as πŸ’» Sales PC
participant D2 as 🟩 DIST-SW2 (was Standby)
participant R2 as 🟦 CORE-R2 (BGP/NAT)
participant ISP as πŸ›°οΈ ISP-Router
Note over R1: ❌ CORE-R1 powered off
D2->>D2: HSRP preempt β†’ claim Active
PC->>D2: Ping 8.8.8.8
D2->>R2: OSPF via Gi0/1 (10.10.255.12/30)
R2->>ISP: Serial0/0/0
ISP-->>PC: Reply (zero packet loss observed)
Loading

πŸ” See diagrams/02-traffic-flow.md for the complete sequence diagrams including Finance β†’ Sales inter-VLAN traffic.


βš–οΈ HSRP Failover

stateDiagram-v2
[*] --> Normal
Normal: 🟒 DIST-SW1 = Active (prio 110)<br/>DIST-SW2 = Standby (prio 100)
Normal --> Detected: CORE-R1 dies<br/>HSRP hello missed Γ—3
Detected --> Switched: Gratuitous ARP
Switched: 🟠 DIST-SW2 = Active<br/>DIST-SW1 = Standby
Switched --> Recovered: CORE-R1 back
Recovered --> Normal: Preempt + higher priority
Loading

Priority table:

VLANDIST-SW1DIST-SW2
10, 20, 30, 40, 50, 60, 150110 (Active)100 (Standby)
99 (device-plane)11090 (intentionally lowest)

🎯 Full state machine: diagrams/04-hsrp-failover-state.md


🧩 Protocol Stack

flowchart TB
L7["πŸ“š App/Management β€” SSH v2 Β· SNMP Β· Syslog"]
L4["πŸ›‘οΈ Security β€” NAT/PAT Β· ACL Β· Port Security"]
L3["🌐 L3 β€” OSPF Β· BGP Β· HSRP Β· Static"]
L2["πŸ”Œ L2 β€” VLANs Β· 802.1Q Β· PVST+ Β· EtherChannel"]
L7 --> L4 --> L3 --> L2
Loading
ProtocolWhereWhy
OSPF (Area 0)Core + DistributionDynamic internal routing
BGP (sim.)Core ↔ ISPRealistic edge
HSRP v1DIST-SW1/2Gateway redundancy
NAT/PATCORE-R1/2Internet sharing
802.1QAll trunksVLAN tagging
EtherChannelAccess ↔ DistributionAggregated GigE
PortFast + BPDU GuardEvery access portEdge hardening
SSH v2All devicesEncrypted mgmt

πŸ“ Repository Layout

TechCom-Network/
β”œβ”€β”€ πŸ“„ README.md ← you are here
β”œβ”€β”€ πŸ“„ LICENSE
β”œβ”€β”€ πŸ“„ .gitignore
β”‚
β”œβ”€β”€ πŸ“ packet-tracer/
β”‚ └── Network Ayman & Alhareth.pkt ← the live lab
β”‚
β”œβ”€β”€ πŸ“ configs/
β”‚ β”œβ”€β”€ πŸ“ configs-Router/
β”‚ β”‚ β”œβ”€β”€ CORE-R1.conf
β”‚ β”‚ └── CORE-R2.conf
β”‚ β”œβ”€β”€ πŸ“ configs-Switch/
β”‚ β”‚ β”œβ”€β”€ DIST-SW1.conf
β”‚ β”‚ β”œβ”€β”€ DIST-SW2.conf
β”‚ β”‚ β”œβ”€β”€ ACCESS-SW-IT.conf
β”‚ β”‚ β”œβ”€β”€ ACCESS-SW-SUPPORT.conf
β”‚ β”‚ β”œβ”€β”€ ACCESS-SW-FINANCE.conf
β”‚ β”‚ β”œβ”€β”€ ACCESS-SW-HR.conf
β”‚ β”‚ β”œβ”€β”€ ACCESS-SW-SALES.conf
β”‚ β”‚ └── ACCESS-SW-MANAGEMENT.conf
β”‚ └── πŸ“ configs-ISP/
β”‚ └── ISP-Router.conf
β”‚
β”œβ”€β”€ πŸ“ diagrams/
β”‚ β”œβ”€β”€ 01-architecture-overview.md (3-tier Mermaid)
β”‚ β”œβ”€β”€ 02-traffic-flow.md (sequence diagrams)
β”‚ β”œβ”€β”€ 03-vlan-broadcast-domains.md (VLAN map)
β”‚ β”œβ”€β”€ 04-hsrp-failover-state.md (HSRP state machine)
β”‚ └── 05-protocol-stack.md (L2–L7 stack)
β”‚
└── πŸ“ docs/
β”œβ”€β”€ πŸ“ arabic/
β”‚ └── ΨͺΩ‚Ψ±ΩŠΨ± Ψ΄Ψ¨ΩƒΨ© - TechCom.pdf (original Arabic report)
β”œβ”€β”€ IP-PLAN.md
β”œβ”€β”€ VLAN-PLAN.md
β”œβ”€β”€ TEST-RESULTS.md
β”œβ”€β”€ CHALLENGES.md
└── network_topology.pptx (presentation slides)

πŸš€ Quick Start

▢️ Run the lab

  1. InstallCisco Packet Tracer 8.x.
  2. Clone this repository:
    git clone https://github.com/<your-username>/TechCom-Network.git
    cd TechCom-Network
  3. Open the lab file:
    # Windows
    start """packet-tracer/Network Ayman & Alhareth.pkt"# macOS
    open "packet-tracer/Network Ayman & Alhareth.pkt"# Linux
    pktui "packet-tracer/Network Ayman & Alhareth.pkt"
  4. Wait ~30 s for OSPF to converge, then run:
    PC-Sales> ping 8.8.8.8
    PC-IT> ping 10.10.60.10
    

πŸ“₯ Apply a config to a real device

If you have a physical or virtual IOS device, push a single config:

# Example: copy a switch config to a TFTP server first, then merge# via the device console / VTY.# 1) From the device:
copy running-config tftp:
# 2) Replace the relevant section with the matching .conf file

Or use the lab as a config reference even on real gear β€” every command is copy-pasteable from the configs/ folder.

πŸ” Reproduce a failover test

  1. Open the lab.
  2. From a Sales PC, run ping -t 8.8.8.8.
  3. In Packet Tracer, delete the power connection to CORE-R1.
  4. Observe: HSRP reconverges in < 5 s, ping stays green.

βœ… Test Results

#TestExpectedResult
1Ping across VLANsInter-department replyβœ…
2Ping 8.8.8.1Internet via NATβœ…
3TraceroutePath: DIST β†’ CORE β†’ ISPβœ…
4HSRP failoverZero packet loss on CORE-R1 failβœ…
5BPDU GuardPort err-disabled on rogue BPDUβœ…
6OSPF neighborsFull adjacencyβœ…

πŸ“‹ Full breakdown with sample output: docs/TEST-RESULTS.md


🧠 Challenges & Solutions

#ChallengeFix
1Duplicate SVI IPs between DIST-SW1/2Split addresses + HSRP virtual IP
2HSRP Active/Standby flapSet priority 110 + preempt, verify failover
3Native VLAN mismatchStandardise on VLAN 100, audit every trunk
4Inter-VLAN silently brokenEnable ip routing, build SVIs, validate with ping
5NAT inside/outside reversedRe-tag interfaces, rebuild ACL 1
6VoIP one-wayUnify VLAN 150, HSRP, switchport voice vlan 150
7SPOF on distribution layerAdd DIST-SW2 + EtherChannel, validate failover

πŸ“š Full war stories: docs/CHALLENGES.md


πŸ›£οΈ Roadmap

  • Three-tier topology with full L2/L3 redundancy
  • OSPF + simulated BGP + HSRP
  • Per-department VLANs + Voice VLAN 150
  • Port Security + BPDU Guard
  • EtherChannel access uplinks
  • SSH v2 across the fabric
  • 100% test pass on failover / inter-VLAN / Internet
  • Add real ACL examples for Finance ↔ others
  • Add SNMPv3 + NetFlow collector config
  • Port to GNS3 / EVE-NG for hypervisor lab
  • Add QoS policy template for Voice VLAN 150
  • CI workflow: validate .conf syntax on every PR

πŸ‘₯ Authors


Alhareth Hayel Al-Dahiah
Network Design Β· Routing Β· Switching
πŸ“§ available on request

Ayman Bashi Al-Baidhani
Architecture Β· Security Β· Documentation
πŸ“§ https:/github/ayman-albaidahi

Supervisor: Dr. Salma Hammoud β€” University of Ibb, Faculty of Applied Science, Department of Information Technology


πŸ™ Acknowledgements

  • University of Ibb β€” for the lab time and the freedom to break things and rebuild them better.
  • Dr. Salma Hammoud β€” for the steady hand on the steering wheel.
  • Cisco Networking Academy β€” for Packet Tracer.
  • The open-source community β€” for Mermaid, Markdown, and the beautiful shields that make a README shine.

πŸ“„ License

Released under the MIT License. See LICENSE for the full text. You are free to use, modify, and distribute, provided attribution is kept.


⭐ Star this repo if it helped you design, study, or pass an exam ⭐


footer

⭐ If this helped you, give it a star!

Made with ❀️ in Yemen β€” University of Ibb

About

🏒 Three-tier enterprise network | ⚑ HSRP + dual core + EtherChannel | 🌐 OSPF Β· BGP Β· 9 VLANs Β· VoIP | πŸ“‘ Full L2/L3 redundancy | πŸŽ“ Cisco Packet Tracer lab

Topics

Resources

Stars

2 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors