{"id":310,"date":"2018-05-04T09:53:43","date_gmt":"2018-05-04T08:53:43","guid":{"rendered":"http:\/\/darko-keric.from.hr\/?p=310"},"modified":"2018-05-04T09:53:43","modified_gmt":"2018-05-04T08:53:43","slug":"wifi","status":"publish","type":"post","link":"http:\/\/darko-keric.from.hr\/?p=310","title":{"rendered":"WiFi"},"content":{"rendered":"<p>SWITCH<\/p>\n<p>vlan 10<br \/>\nname nesto<br \/>\nvlan 20<br \/>\nname IT<br \/>\nvlan 30<br \/>\nname Guest<\/p>\n<p>interface FastEthernet1\/0\/1<br \/>\ndescription veza prema routeru \u2013 na svaki interface OBAVEZNO stavljati description !!!<br \/>\nswitchport trunk encapsulation dot1q<br \/>\nswitchport mode trunk allowed vlan 1,10,20,30 \u2013 potrebno je to\u010dno specificirati VALN-ove!!!<br \/>\nswitchport mode trunk<br \/>\n!<br \/>\ninterface FastEthernet1\/0\/2<br \/>\ndescription AP<br \/>\nswitchport trunk encapsulation dot1q<br \/>\nswitchport trunk allowed vlan 1,10,20,30<br \/>\nswitchport mode trunk<br \/>\n!<br \/>\ninterface FastEthernet1\/0\/3<br \/>\ndescription PC<br \/>\nswitchport access vlan 1 &#8211; ovo se ne pi\u0161e tj. ostaje u defaultnom vlan-u<br \/>\nswitchport mode access<br \/>\nspanning-tree portfast<br \/>\n!<br \/>\ninterface VLAN 1<br \/>\nip address 192.168.1.2 255.255.255.0 \u2013 mo\u017ee se staviti bilo koji ip iz range-a za management<br \/>\n!<br \/>\nLine vty 0 15 \u2013 omogu\u0107ujemo udaljeni pristup (telnet)<br \/>\nPassword xxxx \u2013 stavite po \u017eelji<br \/>\nno ip domain-lookup<\/p>\n<p>line con 0<br \/>\nlogging synchronous<br \/>\npass class<br \/>\nlogin<br \/>\nline vty 0 15<br \/>\npass class<br \/>\nlogin<br \/>\nenab sec class<\/p>\n<p>ROUTER<\/p>\n<p>ip dhcp pool IT-GrupaX \u2013 naziv pool-a stavljate po \u017eelji<br \/>\nnetwork 192.168.20.0 255.255.255.0<br \/>\ndns-server 8.8.8.8<br \/>\ndefault-router 192.168.20.1<br \/>\n!<br \/>\nip dhcp pool GUEST-GrupaX<br \/>\nnetwork 192.168.30.0 255.255.255.0<br \/>\ndns-server 8.8.8.8<br \/>\ndefault-router 192.168.30.1<br \/>\n!<br \/>\nip dhcp pool AP<br \/>\nnetwork 192.168.10.0 255.255.255.0<br \/>\ndefault-router 192.168.10.1<br \/>\ndns-server 8.8.8.8<br \/>\n!<br \/>\nip dhcp pool PC<br \/>\nnetwork 192.168.2.0 255.255.255.0<br \/>\ndns-server 8.8.8.8<br \/>\ndefault-router 192.168.2.254<br \/>\n!<br \/>\ninterface FastEthernet0\/0<br \/>\ntu samo no shu<br \/>\n!<br \/>\ninterface FastEthernet0\/0.1<br \/>\nencapsulation dot1Q 1 \u2013 enkapsulacija po vlanu kojem pripada<br \/>\nip address 192.168.1.1 255.255.255.0<br \/>\nip nat inside \u2013 naredba za NAT ide na svaki subinterface da bi vam radio pristup na Internet<br \/>\n!<br \/>\ninterface FastEthernet0\/0.10<br \/>\ndescription AP<br \/>\nencapsulation dot1Q 10<br \/>\nip address 192.168.10.1 255.255.255.0<br \/>\nip nat inside<br \/>\nip virtual-reassembly<br \/>\n!<br \/>\ninterface FastEthernet0\/0.20<br \/>\ndescription IT<br \/>\nencapsulation dot1Q 20<br \/>\nip address 192.168.20.1 255.255.255.0<br \/>\nip nat inside<br \/>\nip virtual-reassembly<br \/>\n!<br \/>\ninterface FastEthernet0\/0.30<br \/>\ndescription GUEST<br \/>\nencapsulation dot1Q 30<br \/>\nip address 192.168.30.1 255.255.255.0<br \/>\nip nat inside<br \/>\nip virtual-reassembly<br \/>\naccess-group GUEST in \u2013 primjenjujemo acc listu za goste<br \/>\n!<br \/>\ninterface FastEthernet0\/1<br \/>\ndescription WAN<br \/>\nip address 10.10.2.15X 255.255.255.0<br \/>\nip nat outside \u2013 na WAN su\u010delje obavezno se stavlja naredba nat outside!!!<br \/>\nip virtual-reassembly<br \/>\nduplex auto<\/p>\n<p>ip route 0.0.0.0 0.0.0.0 10.10.2.254 \u2013 ne zaboravite staviti defaultnu rutu s next hop adresom!!!<br \/>\n!<br \/>\nip nat inside source list WIFI interface FastEthernet0\/1 overload \u2013 sav promet se natira u wan int.<br \/>\n!<br \/>\nip access-list extended WIFI \u2013 access lista potrebna za nat mo\u017ee standardna ili extended !!!<br \/>\npermit ip 192.168.1.0 0.0.0.255 any<br \/>\npermit ip 192.168.10.0 0.0.0.255 any<br \/>\npermit ip 192.168.20.0 0.0.0.255 any<br \/>\npermit ip 192.168.30.0 0.0.0.255 any<br \/>\n!<br \/>\nip access-list extended GUEST \u2013 dopu\u0161tamo gostima samo izlaz na Internet, cijeli LAN zabranjujemo<br \/>\ndeny ip 192.168.30.0 0.0.0.255 192.168.1.0 0.0.0.255<br \/>\ndeny ip 192.168.30.0 0.0.0.255 192.168.10.0 0.0.0.255<br \/>\ndeny ip 192.168.30.0 0.0.0.255 192.168.20.0 0.0.0.255<br \/>\npermit ip any any \u2013 ne zaboravite na kraju dozvoliti svemu ostalom<\/p>\n<p>KONFIGURACIJA &#8211;&gt; AP<br \/>\nwelcome &#8211; next<br \/>\nip address -ostavi default DHCP<br \/>\nsingle point &#8211; Do not enable single point setup<br \/>\ntime settings next<br \/>\npassword stavi nesto, complexity ne, uzmi neki jedostavni<br \/>\nSSID &#8211; IT-grupaX&nbsp; &#8211;&gt; prvo ide configuration ITa onda gostiju<br \/>\ndalje no security ili ako pise u ispitu onda nesto stavim i upisem neki password<br \/>\nzatim kojem vlanu bude pripadao taj IT, to pise u ispitu. Sad je IT u 20, a na ispitu mozda bude nesto drugo<br \/>\nenable &#8211; yes<br \/>\nguest name &#8211; Guest-grupaX<br \/>\ndalje, no security, password nista<br \/>\nvlan ID sad je 30 jer su gosti u 30<br \/>\ndodatna mogucnost da redirecta, ne treba, next<br \/>\nfinish<br \/>\ni onda me izbaci van pa se prijavim s onim passwordom koji sam stavila<\/p>\n<p>captive portal<br \/>\ncreate<br \/>\nGosti<br \/>\nSave<\/p>\n<p>local users<br \/>\ngost1<br \/>\npostavi neki password<br \/>\nstavi da propada grupi Gosti<\/p>\n<p>instance configuration<br \/>\numjesto create wiz_cp_inst1<br \/>\njedino bitno je verification:<br \/>\nizaberi local<br \/>\nuser group name: Gosti<br \/>\nsave<\/p>\n<p>ACCESS POINT CISCO WAP 321<br \/>\nNa AP-u je potrebno konfigurirati 2 virtualna interface-a VAP0 i VAP1:<br \/>\nVAP0 \u2013 vlan id 20 \u2013 SSID IT-GrupaX<br \/>\nVAP1 \u2013 vlan id 30 \u2013 SSID GUEST-GrupaX<br \/>\nPod tabom LAN interface \u2013 potrebno postaviti management vlan id 10 \u2013 Vlan u kojem je na\u0161 AP<\/p>\n","protected":false},"excerpt":{"rendered":"<p>SWITCH vlan 10 name nesto vlan 20 name IT vlan 30 name Guest interface FastEthernet1\/0\/1 description veza prema routeru \u2013 na svaki interface OBAVEZNO stavljati description !!! switchport trunk encapsulation dot1q switchport mode trunk allowed vlan 1,10,20,30 \u2013 potrebno je &hellip; <a href=\"http:\/\/darko-keric.from.hr\/?p=310\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":348,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"ngg_post_thumbnail":0},"categories":[5],"tags":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v17.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"http:\/\/darko-keric.from.hr\/?p=310\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"WiFi - Sistemski in\u017eenjer\" \/>\n<meta property=\"og:description\" content=\"SWITCH vlan 10 name nesto vlan 20 name IT vlan 30 name Guest interface FastEthernet1\/0\/1 description veza prema routeru \u2013 na svaki interface OBAVEZNO stavljati description !!! switchport trunk encapsulation dot1q switchport mode trunk allowed vlan 1,10,20,30 \u2013 potrebno je &hellip; Continue reading &rarr;\" \/>\n<meta property=\"og:url\" content=\"http:\/\/darko-keric.from.hr\/?p=310\" \/>\n<meta property=\"og:site_name\" content=\"Sistemski in\u017eenjer\" \/>\n<meta property=\"article:published_time\" content=\"2018-05-04T08:53:43+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"darko-keric\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebSite\",\"@id\":\"https:\/\/darko-keric.from.hr\/#website\",\"url\":\"https:\/\/darko-keric.from.hr\/\",\"name\":\"Sistemski in\\u017eenjer\",\"description\":\"System administrator\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/darko-keric.from.hr\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"http:\/\/darko-keric.from.hr\/?p=310#webpage\",\"url\":\"http:\/\/darko-keric.from.hr\/?p=310\",\"name\":\"WiFi - Sistemski in\\u017eenjer\",\"isPartOf\":{\"@id\":\"https:\/\/darko-keric.from.hr\/#website\"},\"datePublished\":\"2018-05-04T08:53:43+00:00\",\"dateModified\":\"2018-05-04T08:53:43+00:00\",\"author\":{\"@id\":\"https:\/\/darko-keric.from.hr\/#\/schema\/person\/5e2f76737b07a700e0e2a108d173e612\"},\"breadcrumb\":{\"@id\":\"http:\/\/darko-keric.from.hr\/?p=310#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"http:\/\/darko-keric.from.hr\/?p=310\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"http:\/\/darko-keric.from.hr\/?p=310#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/darko-keric.from.hr\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"WiFi\"}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/darko-keric.from.hr\/#\/schema\/person\/5e2f76737b07a700e0e2a108d173e612\",\"name\":\"darko-keric\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/darko-keric.from.hr\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"http:\/\/0.gravatar.com\/avatar\/0400800f6ebec266fcb39a1cb31b0b0e?s=96&d=mm&r=g\",\"contentUrl\":\"http:\/\/0.gravatar.com\/avatar\/0400800f6ebec266fcb39a1cb31b0b0e?s=96&d=mm&r=g\",\"caption\":\"darko-keric\"},\"url\":\"http:\/\/darko-keric.from.hr\/?author=348\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"http:\/\/darko-keric.from.hr\/?p=310","og_locale":"en_US","og_type":"article","og_title":"WiFi - Sistemski in\u017eenjer","og_description":"SWITCH vlan 10 name nesto vlan 20 name IT vlan 30 name Guest interface FastEthernet1\/0\/1 description veza prema routeru \u2013 na svaki interface OBAVEZNO stavljati description !!! switchport trunk encapsulation dot1q switchport mode trunk allowed vlan 1,10,20,30 \u2013 potrebno je &hellip; Continue reading &rarr;","og_url":"http:\/\/darko-keric.from.hr\/?p=310","og_site_name":"Sistemski in\u017eenjer","article_published_time":"2018-05-04T08:53:43+00:00","twitter_card":"summary","twitter_misc":{"Written by":"darko-keric","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebSite","@id":"https:\/\/darko-keric.from.hr\/#website","url":"https:\/\/darko-keric.from.hr\/","name":"Sistemski in\u017eenjer","description":"System administrator","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/darko-keric.from.hr\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"WebPage","@id":"http:\/\/darko-keric.from.hr\/?p=310#webpage","url":"http:\/\/darko-keric.from.hr\/?p=310","name":"WiFi - Sistemski in\u017eenjer","isPartOf":{"@id":"https:\/\/darko-keric.from.hr\/#website"},"datePublished":"2018-05-04T08:53:43+00:00","dateModified":"2018-05-04T08:53:43+00:00","author":{"@id":"https:\/\/darko-keric.from.hr\/#\/schema\/person\/5e2f76737b07a700e0e2a108d173e612"},"breadcrumb":{"@id":"http:\/\/darko-keric.from.hr\/?p=310#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["http:\/\/darko-keric.from.hr\/?p=310"]}]},{"@type":"BreadcrumbList","@id":"http:\/\/darko-keric.from.hr\/?p=310#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/darko-keric.from.hr\/"},{"@type":"ListItem","position":2,"name":"WiFi"}]},{"@type":"Person","@id":"https:\/\/darko-keric.from.hr\/#\/schema\/person\/5e2f76737b07a700e0e2a108d173e612","name":"darko-keric","image":{"@type":"ImageObject","@id":"https:\/\/darko-keric.from.hr\/#personlogo","inLanguage":"en-US","url":"http:\/\/0.gravatar.com\/avatar\/0400800f6ebec266fcb39a1cb31b0b0e?s=96&d=mm&r=g","contentUrl":"http:\/\/0.gravatar.com\/avatar\/0400800f6ebec266fcb39a1cb31b0b0e?s=96&d=mm&r=g","caption":"darko-keric"},"url":"http:\/\/darko-keric.from.hr\/?author=348"}]}},"_links":{"self":[{"href":"http:\/\/darko-keric.from.hr\/index.php?rest_route=\/wp\/v2\/posts\/310"}],"collection":[{"href":"http:\/\/darko-keric.from.hr\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/darko-keric.from.hr\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/darko-keric.from.hr\/index.php?rest_route=\/wp\/v2\/users\/348"}],"replies":[{"embeddable":true,"href":"http:\/\/darko-keric.from.hr\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=310"}],"version-history":[{"count":1,"href":"http:\/\/darko-keric.from.hr\/index.php?rest_route=\/wp\/v2\/posts\/310\/revisions"}],"predecessor-version":[{"id":311,"href":"http:\/\/darko-keric.from.hr\/index.php?rest_route=\/wp\/v2\/posts\/310\/revisions\/311"}],"wp:attachment":[{"href":"http:\/\/darko-keric.from.hr\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=310"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/darko-keric.from.hr\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=310"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/darko-keric.from.hr\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=310"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}