Until now the addresses have been given to you. In this exercise you design them yourselves: you receive a single block of addresses and a list of real requirements, and at the end a scheme must come out in which nothing overlaps, nothing is wasted and room is left for growth. Then you let DHCP distribute it.
1What "designing the addresses" means
A provider gives you a block of addresses - a single block. Out of it must come every network of the company: production, the offices, the servers, the links between routers. Each piece must be large enough to hold the hosts, but no larger than necessary, because the rest is left for later.
/24 means 24 network
bits and 8 host bits. With 8 host bits you have 2⁸ = 256 addresses, of which 254 are usable - the network
address and the broadcast address are subtracted.2Equipment needed
| Qty | Equipment | Model | Packet Tracer category | What it is for here |
|---|---|---|---|---|
| 3 | Router | 4331 | Network Devices → Routers | R1 (headquarters), R2 (production), R3 (warehouse) |
| 6 | Switch | 2960 | Network Devices → Switches | one per user segment |
| 2 / segment | Computer | PC-PT | End Devices | one static, one through DHCP |
| 1 | Server | Server-PT | End Devices | in the Servers segment |
| 3 | Serial cable | Serial DCE | Connections | the point-to-point links between the routers |
| as needed | Straight cable | Copper Straight-Through | Connections | hosts → switches, switches → routers |
clock rate 128000 is issued. If
the interface stays up / down, you almost certainly forgot this command or put it on the wrong
end. On Ethernet links the command does not exist and is not needed.3The design brief
| Segment | Hosts now | Estimated growth | Remarks |
|---|---|---|---|
| Production | 420 | +15 % | the largest segment |
| Offices | 180 | +25 % | rapid growth |
| Warehouse | 90 | +10 % | mobile terminals |
| Guests | 50 | - | isolated from the rest |
| Servers | 25 | +50 % | static addresses |
| Management | 12 | +100 % | network equipment only |
| Links R1–R2, R2–R3, R1–R3 | 2 each | - | point-to-point |
4How it is computed, step by step
The method has four steps and none of them is skipped.
- Add the growth to each requirement and round up. Production: 420 × 1.15 = 483.
- Compute the host bits needed, from the inequality 2ⁿ − 2 ≥ the requirement. For 483 hosts, n = 9 (2⁹ − 2 = 510 usable), so the prefix is 32 − 9 = /23.
- Sort in decreasing order of size and allocate in that order, starting from the first address of the block.
- Verify that the total fits and note what has been left free.
A complete example, for the first two
| Step | Production (483) | Offices (225) |
|---|---|---|
| host bits | 2⁹ − 2 = 510 ≥ 483 → n = 9 | 2⁸ − 2 = 254 ≥ 225 → n = 8 |
| prefix | 32 − 9 = /23 | 32 − 8 = /24 |
| mask | 255.255.254.0 | 255.255.255.0 |
| subnet | 172.20.16.0/23 | 172.20.18.0/24 |
| usable range | 172.20.16.1 – 172.20.17.254 | 172.20.18.1 – 172.20.18.254 |
| broadcast | 172.20.17.255 | 172.20.18.255 |
| next free address | 172.20.18.0 | 172.20.19.0 |
Carry on by yourselves with Warehouse, Guests, Servers, Management and the three point-to-point links. Then check:
Do the computation on paper first, then compare with the widget. If the results differ, find where you went wrong - usually at the rounding or at the order of allocation. The widget is for checking, not for replacing the exercise: in the examination you will not have it.
Why does a segment with 30 hosts need a /26 and not a /27?
See the answer
A /27 offers 2⁵ = 32 addresses, from which the network address and the broadcast address are subtracted: 30 usable remain. So a /27 would be exactly enough - but only if you need no extra room at all, not even for the gateway.
Careful: the gateway consumes a usable address too. So for 30 hosts plus a gateway you need 31 usable addresses - and a /27 is no longer enough. This is the classic examination mistake.
Checking each subnet
Enter each subnet of your plan in turn and confirm the usable range and the broadcast address. Check in particular that the broadcast of one subnet is exactly 1 less than the network address of the next - if it is not, either you have left a hole, or the subnets overlap.
5The topology to implement
The addressing table - filled in before any command
| Segment | Subnet | Mask | Gateway | Usable range | Broadcast |
|---|---|---|---|---|---|
| Production | 172.20.16.0/23 | 255.255.254.0 | 172.20.16.1 | .16.1 – .17.254 | 172.20.17.255 |
| Offices | 172.20.18.0/24 | 255.255.255.0 | 172.20.18.1 | .18.1 – .18.254 | 172.20.18.255 |
| Warehouse | |||||
| Guests | |||||
| Servers | |||||
| Management | |||||
| R1–R2 | /30 | - | |||
| R2–R3 | /30 | - | |||
| R1–R3 | /30 | - |
The first two rows are filled in as a model. The convention: the gateway receives the first usable address of each subnet. It is a convention, not a rule - but if you follow it consistently, anybody can read your network without asking.
6The workbench
Part of the topology - R1 with Offices and Servers, R2 with Production, joined by a serial link. It is enough for you to implement the plan, configure DHCP and the relay, and provoke all four problems of section 10. The remaining segments are added in Packet Tracer, following the same pattern.
7Implementing the plan
- Configure the routers
The addresses in the example below are those of the plan in section 5. If your plan differs, use your own values - but then the objectives in the workbench differ as well.
on R1Router> enable Router# configure terminal Router(config)# hostname R1 R1(config)# no ip domain-lookup R1(config)# interface gigabitEthernet 0/0/0 R1(config-if)# description LAN Offices R1(config-if)# ip address 172.20.18.1 255.255.255.0 R1(config-if)# no shutdown R1(config-if)# exit R1(config)# interface gigabitEthernet 0/0/1 R1(config-if)# description LAN Servers R1(config-if)# ip address 172.20.19.193 255.255.255.192 R1(config-if)# no shutdown R1(config-if)# exit R1(config)# interface serial 0/1/0 R1(config-if)# description Link towards R2 R1(config-if)# ip address 172.20.20.33 255.255.255.252 R1(config-if)# clock rate 128000 R1(config-if)# no shutdown R1(config-if)# end R1# show ip interface brief
on R2Router> enable Router# configure terminal Router(config)# hostname R2 R2(config)# interface gigabitEthernet 0/0/0 R2(config-if)# description LAN Production R2(config-if)# ip address 172.20.16.1 255.255.254.0 R2(config-if)# no shutdown R2(config-if)# exit R2(config)# interface serial 0/1/0 R2(config-if)# ip address 172.20.20.34 255.255.255.252 R2(config-if)# no shutdown R2(config-if)# end
A /23 mask is not 255.255.255.0 Production has 512 addresses, so the mask is255.255.254.0. It is the most frequent mistake of this exercise, and it has a treacherous symptom: half the hosts answer, the other half do not. Check withshow ip interface briefand with the subnet calculator above. - Add provisional static routing
The two routers do not yet know each other. Routing proper is the subject of laboratory 5; for now we write the routes by hand, just enough to test the plan.
on R1R1(config)# ip route 172.20.16.0 255.255.254.0 172.20.20.34
on R2R2(config)# ip route 172.20.18.0 255.255.255.0 172.20.20.33 R2(config)# ip route 172.20.19.192 255.255.255.192 172.20.20.33
Check with
show ip routeon each router, then ping from the server in the Servers segment towards the interface of R2. If it works, the addressing plan is consistent.
8DHCP on the router
A Cisco router can itself be a DHCP server. It is the usual solution in small and medium networks: you no longer need a dedicated server.
- Configure the pools
on R1
R1(config)# ip dhcp excluded-address 172.20.18.1 172.20.18.20 R1(config)# ip dhcp excluded-address 172.20.16.1 172.20.16.20 R1(config)# ip dhcp pool BIROURI R1(dhcp-config)# network 172.20.18.0 255.255.255.0 R1(dhcp-config)# default-router 172.20.18.1 R1(dhcp-config)# dns-server 172.20.19.194 R1(dhcp-config)# lease 0 8 0 R1(dhcp-config)# exit R1(config)# ip dhcp pool PRODUCTIE R1(dhcp-config)# network 172.20.16.0 255.255.254.0 R1(dhcp-config)# default-router 172.20.16.1 R1(dhcp-config)# dns-server 172.20.19.194 R1(dhcp-config)# end R1# show ip dhcp pool
The exclusions are always written first If you define the pool before the exclusions, the router may already have allocated the gateway address to a host. The result is an address conflict that is hard to diagnose, because it appears only when enough hosts connect.
lease 0 8 0means 0 days, 8 hours, 0 minutes. In an office network, 8 hours cover a working day; in a guest network, one hour is more suitable, so that the addresses are released quickly. - Test on a host
In the workbench in this page: pick PC-BIR and press the request through DHCP button, or type
ipconfig /renewin the terminal. In Packet Tracer: switch the IP configuration of the host to DHCP.on PC-BIRipconfig /release ipconfig /renew ipconfig /all
This must appear:
what should appearDHCP: address received from R1 IP address......................: 172.20.18.21 Subnet Mask.....................: 255.255.255.0 Default Gateway.................: 172.20.18.1 DNS Server......................: 172.20.19.194
Notice the .21: the first twenty addresses were excluded, so the first free one is the twenty-first. On the router, check the record:
on R1R1# show ip dhcp binding
The address appears together with the MAC address of the client. This is the binding that makes the same host receive the same address next time as well.
- Follow DORA in detail in Packet Tracer
In Simulation, filtered on DHCP, run
ipconfig /renewon the host and follow the four messages. For each of them, open the envelope and note:Message Source IP Destination IP Unicast or broadcast? Discover Offer Request Ack QuestionWhat source IP address does the Discover message have, and why?
See the answer
0.0.0.0. The client does not yet have any address - that is precisely why it is asking. The destination is255.255.255.255, a limited broadcast, because it does not know the address of the server either.The important consequence: being a broadcast, the message passes through no router. That is why, for segments without a local server, a relay is compulsory - exactly what follows.
9DHCP relay
The Production segment has no local DHCP server. The server is on R1, beyond a serial link - and the request, being a broadcast, does not get through.
- Convince yourselves that it does not work
On PC-PROD, press request through DHCP. You must obtain:
what should appearDHCP: no server answered. The host assigned itself an APIPA address. IP address......................: 169.254.x.x Subnet Mask.....................: 255.255.0.0 Default Gateway.................: 0.0.0.0
The address that says everything A host with an address from169.254.0.0/16received no answer to its Discover. Do not look elsewhere: either there is no server, or the request does not reach it (missing relay, wrong VLAN, cable in the wrong port), or the pool is exhausted. It is one of the few symptoms in networking that points directly at the cause. - Configure the relay
on R2, the interface facing the hosts
R2(config)# interface gigabitEthernet 0/0/0 R2(config-if)# ip helper-address 172.20.18.1 R2(config-if)# end
The address is that of the interface of R1 on which the DHCP service runs. What the router does: it takes the broadcast request, turns it into a unicast towards the server and attaches the information about the network it came from. The server picks the right pool from that information - which is why a pool for the Production network must exist on R1.
Ask for an address on PC-PROD again. Now this must appear:
what should appearDHCP: address received from R1 (through the relay) IP address......................: 172.20.16.21 Subnet Mask.....................: 255.255.254.0 Default Gateway.................: 172.20.16.1
Notice the mask:
255.255.254.0, that is /23 - it comes from the PRODUCTIE pool, not from the Offices one. The server chose correctly.
10Four problems to diagnose
Provoke each situation and resolve it. Each time note which command showed you the problem.
| The situation provoked | How you produce it | Symptom | Where it shows |
|---|---|---|---|
| missing relay | on R2: no ip helper-address 172.20.18.1 | the hosts in Production receive 169.254.x.x | ipconfig on the host |
| gateway not excluded from the pool | delete the exclusions and ask for an address from several hosts | a host receives the gateway address itself | show ip dhcp binding |
| wrong mask | on R2: ip address 172.20.16.1 255.255.255.0 | half the hosts of Production become unreachable | computing the network address, on paper |
| overlapping subnets | on R2: ip route 172.20.16.0 255.255.252.0 172.20.20.33 | unpredictable routing, some destinations unreachable | show ip route - two routes to prefixes that cover each other |
172.20.16.0/22 and 172.20.16.0/23, the second wins for the addresses it covers,
and the first takes the rest. It is not an error - it is the rule. It becomes a problem only when you did
not intend it.11Assignments
- Work out the complete VLSM plan, on paper, and justify each prefix chosen
- Fill in the addressing table with all nine subnets
- Implement the plan on all three routers and check with
show ip route - Configure DHCP pools for Offices, Production, Warehouse and Guests
- Configure a relay on R2 and R3 and demonstrate that it works
- Document the four DORA messages, with source and destination addresses
- Provoke and resolve the four problems of section 10
- Compute and report: how many addresses you consumed, how many were left free, in which blocks
12Going further
Management announces a new branch, which will need: a segment with 100 hosts, one with 25 and two point-to-point links to head office.
- Do the new requirements fit in the block
172.20.16.0/21, with the plan you made? If so, where do you allocate them from? If not, what could you have done differently from the start? - Redo the plan so that all the subnets of one location are summarizable into a single route. How much extra space does this discipline cost?
- What is the summary route for each of the three locations, in the new plan?
See the hint
Point 2 is the essence of hierarchical address design. Strictly optimal, "packed" allocation minimizes waste but makes summarization impossible: the subnets of one location have no common prefix. Allocation in blocks - for example a /23 reserved entirely for each location, whatever fraction of it is used - wastes addresses, but reduces the routing table of each router from nine entries to three.
In an enterprise network, the compromise is almost always made in favour of summarization. Private addresses are free; large routing tables, useless routing updates and difficult troubleshooting are not.
13Self-check questions
14Deliverables
| Deliverable | Format | Weight |
|---|---|---|
| The complete VLSM plan, with the computations and the justification of each prefix | document | 30 % |
| The Packet Tracer file, implemented and working | .pkt | 30 % |
| The documentation of DORA, with the addresses of each message | document | 15 % |
| The four problems provoked, with symptom and diagnostic command | document | 10 % |
| Going further: the plan redone for summarization, with the three routes | document | 15 % |
Keep the file: laboratory 5 starts from exactly this topology.