CCNA:LAB No# 19 Configuration of Layer 2 Ether-Channel, STP & Port security

Опубликовано: 10 Август 2026
на канале: Faiz XP
2,224
5

Uploaded the Packet Tracer File here:
https://drive.google.com/file/d/0B3-H...

Made one minor change in the PT file , changed the Ether channel config, we have used the option ON instead of using PagP or LACP like we have used in the lab.

Made a minor change in the file , We just changed the Ether channel config, we use the option ÖN instead of using PagP or LACP like we have in the lab.

Assalam-o-Alaikum
In this topology , L2 switches S1 & S2 are configured with VLAN along with ports and DHCP is config on L3 switches and also configured VLAN 1 with an IP of 1.0.0.0/8 on all switches for testing purpose only.

Objective:
So in this lab,
1) First we will Create a layer-2 Ether-channel between L3 and L2 switches
All port channels have been created,

2) Now we will trunk all the port channels so that we can do our Routing between VLANs in the 3rd objective. Make sure trunk link are working by pinging the remote end.

3) Configure the inter-Vlans routing on both L3 (MS-A and MS-B) switches,
and make MS-A the Primary root bridge and MS-B the Secondary root bridge for VLAN 10 20 30 & 40
And now lets test by shutting down the trunk links.

And make sure no one else become the Root Bridge other then the L3 switches i.e MS-A and MS-B.

4) Change the Spanning mode to Rapid so that the STP convergence should be faster
and then test it either its converging fast from before or not.

5) Makes sure no one tries to connect another switch on Access layer i.e. with S1 & S2 switches and make the ports which are meant for Ed devices should skip the listening and learning transition and jump straight to forwarding state directly.

6) Port security, Only one End device is allowed on one port and bind the mac addresses to the L2 switch ports And If some one tries to connect a switch in place of a switch then that switch should not be allowed to take part in the root bridge election process.

7) Lastly , allow only necessary VLANs on the trunk ports and if we don't do it , this might cause bridging loops in the topology and if you are also configuring this particular lab then perform this task after the 3rd objective.

That's it for today,
I hope it was informative for you and i would like to Thank you for viewing
JAZAKALLAH KHAIR