
Learn CCNP switch lab techniques using GNS3 to configure interfaces, port security, spanning tree protocol configurations, DHCP, and AAA with practical, hands-on exercises in a comprehensive lab manual.
Learn to define and use an interface range macro to select multiple switch interfaces, apply descriptions, enforce speed and duplex settings, and verify configurations with show commands.
configure port security on a switch interface, enable sticky mac learning, and specify the maximum authorized mac addresses with violation handling and automatic recovery.
Explore cdp and ldp discovery protocols, compare Cisco proprietary cdp with standard ldp, enable or disable them globally or per interface, adjust timers, and observe neighbors.
Define VLANs 100 and 200 for HR and R&D, assign interfaces and PCs with VLAN-aware IPs, compare static versus dynamic assignment via an MPS server, and test inter-VLAN routing.
configure vlan trunking between switches, create vlan 100 and 200, and assign pcs to access ports. use 802.1q or isl tagging, dynamic trunk negotiation, and verify with ping tests.
Explore how VTP operates across trunk links, domains, and server, client, and transparent roles, upgrading to version 3 for extended VLAN range, with config revision and password security.
Configure and validate VTP pruning to optimize network performance by limiting broadcast, multicast, and unknown unicast flooding across trunk ports in a three-switch VLAN topology.
Explore traditional spanning tree protocol concepts, including root bridge selection, root and designated ports, blocking redundant links, and BPDU driven topology changes in PVST networks.
Explore stp root election and how priority changes set the root bridge to prevent bottlenecks in campus networks, and verify with show spanning tree.
Speed up traditional spanning tree by reducing convergence time with indirect diameter-based timer adjustments, revealing root bridge roles and timer effects (hello time, max age, forward delay) for faster convergence.
Learn how to directly configure STP timers—hello time, max age, and forward delay—and see how changing them accelerates convergence across switches in a GNS3 lab scenario.
Explore Cisco proprietary port fast, uplink fast, and backbone fast features and their impact on spanning tree convergence in a three-switch lab, using show commands and configurations.
Learn how rapid spanning tree uses a proposal and agreement process to achieve sub-second convergence. See how port states shift to discarding and how rapid pvst compares with traditional stp.
Explore mstp and msde concepts, map vlans to instances, and load-balance traffic across two uplinks through practical configuration and verification with show spanning-tree.
Protect your network from rogue root switches by enabling root guard and bpdu guard on interfaces. Verify with spanning tree status and inconsistent ports to ensure blocked rogue devices.
Protect your stp infrastructure from rogue switches by configuring bpduguard on all ports or per interface, using spanning-tree portfast bpduguard default or enable, and verify with show commands.
Learn how to implement link aggregation (etherchannel) to create redundant, load-balanced connections between switches, using active or passive negotiation, port channels, and traffic hashing across mac, ip, and ports.
Explore inter-vlan routing with router on a stick and multi-layer switches, configure layer 3 interfaces or switch virtual interfaces, enable ip routing, and manage default and static routes for connectivity.
Configure a Cisco switch as an IPv4 dhcp server and a relay agent, creating two pools with exclusions and a reserved address, then verify bindings and connectivity.
Configure three DHCPv6 deployment models on Cisco devices—stateless, stateful, and lightweight—using pools, prefixes and default gateways, plus DNS and domain name options, with router solicitations/advertisements for client onboarding.
Explore first hop redundancy protocols, including HSRP, VRRP, and GLBP, to provide router failover, load balancing, and fast convergence with virtual IPs, preemption, and timers.
Configure VRRP by defining groups with distinct IPs to enable load balancing and assign master and backup roles. Disable preemption, adjust hello and advertisement timers, and enable authentication for VRRP.
Explore how GLBP on Cisco routers provides gateway load balancing through virtual MAC addresses, active virtual gateway and forwarder roles, with configurable timers and load balancing modes.
Configure object tracking to monitor an interface and adjust router priority, enabling preemption so a backup router becomes master when the primary link fails, then revert when restored.
Learn how to configure SNMP across versions 1, 2c, and 3, including manager and agent roles, polling vs traps, and the security enhancements of version 3 with authentication and encryption.
Configure internal buffer logging, set the buffer size to sixty five thousand five hundred thirty five, and enable remote syslog logging with chosen severity levels to a syslog server.
Configure local span on switches to copy traffic from a source to a destination interface for analysis with Wireshark, and review monitor sessions and VLAN-based options.
Configure IP SLA for performance monitoring between a source and responder, using ICMP echo and UDP options, and send logs to a syslog server.
Secure management access by moving to out-of-band networks, disabling telnet and http, and enabling ssh version 2 with rsa keys, while restricting access with access lists and banners.
Configure port-based authentication on Cisco switches using 802.1X, radius or tacacs+, and a local or external identity system; define device groups and users, enable aaa, and verify with client settings.
Configure Triple-A authentication on Cisco devices by using external tacacs+ or radius servers, with a local fallback, define server groups and method lists, and verify access via login attempts.
Configure centralized authorization on a switch using tacacs+ to enforce identity groups, command sets, and policies, limiting John to show commands only.
Configure aaa accounting to record user activities and send command logs to the accounting server; test with John and review level 0, 1, and 15 commands.
Clearly students should have associate level knowledge to understand professional materials.