Cheat Sheet (Referencia Técnica)
Direcciones privadas (RFC 1918)
Section titled “Direcciones privadas (RFC 1918)”| Clase | Rango |
|---|---|
| A | 10.0.0.0 – 10.255.255.255 |
| B | 172.16.0.0 – 172.31.255.255 |
| C | 192.168.0.0 – 192.168.255.255 |
NAT / PAT
Section titled “NAT / PAT”| Tipo | Relación | Uso |
|---|---|---|
| Estático | 1 privada ↔ 1 pública fija | Servidores accesibles desde fuera |
| Dinámico | Pool, primera libre | Sin sobrecarga |
| PAT (overload) | Muchas privadas → 1 pública + puertos | Salida a internet |
Terminología
Section titled “Terminología”Inside local = IP privada del host internoInside global = IP pública que representa al hostOutside local = IP del host externo vista desde dentroOutside global = IP real del host externoNAT estático
Section titled “NAT estático”ip nat inside source static 192.168.1.100 200.200.200.2
interface GigabitEthernet0/0 ip nat insideinterface GigabitEthernet0/1 ip nat outsidePAT (overload)
Section titled “PAT (overload)”access-list 1 permit 192.168.1.0 0.0.0.255ip nat pool PUBLICA 200.200.200.1 200.200.200.1 netmask 255.255.255.0ip nat inside source list 1 pool PUBLICA overload
interface GigabitEthernet0/0 ip nat insideinterface GigabitEthernet0/1 ip nat outside
overloadactiva el PAT. Verificación:show ip nat translations,show ip nat statistics. Debug:debug ip nat.
Conexión al ISP (Enlaces WAN)
Section titled “Conexión al ISP (Enlaces WAN)”| Tipo de enlace | Interfaz | Notas |
|---|---|---|
| Línea dedicada | Serial |
Encapsulación HDLC (Cisco) o PPP (estándar) |
| Fibra / Metro Ethernet | GigabitEthernet |
IP + no shutdown, como una LAN |
# Línea dedicada (serial)interface Serial0/0/0 ip address 10.0.0.1 255.255.255.252 encapsulation ppp no shutdown
# IP por DHCP del ISP (fibra/cable)interface GigabitEthernet0/1 ip address dhcp
# Ruta por defecto hacia el ISPip route 0.0.0.0 0.0.0.0 10.0.0.2- Enlace hacia el ISP: subred /30 (2 hosts).
- Salida a internet = ruta por defecto + NAT/PAT (ver arriba).
Puertos: 67 servidor / 68 clienteProceso: Discover → Offer → Request → Ack (DORA)ip dhcp excluded-address 192.168.1.1 192.168.1.10ip dhcp pool LAN-Oficina network 192.168.1.0 255.255.255.0 default-router 192.168.1.1 dns-server 8.8.8.8 lease 7
# Relay (servidor en otra subred)interface GigabitEthernet0/0 ip helper-address 10.0.0.5show ip dhcp bindingshow ip dhcp pool LAN-Oficinaip name-server 8.8.8.8ip domain lookup # no ip domain lookup desactiva la resoluciónip domain name empresa.local # dominio por defecto (para SSH)Puerto: 53 (UDP)Puerto: 123 (UDP)Stratum: distancia a la fuente atómica (menor = más preciso)ntp server 192.168.1.250ntp update-calendarshow ntp status # Clock is synchronized, stratum 3...show ntp associations # * = servidor de referencia| Tipo | Filtra | Números |
|---|---|---|
| Estándar | Solo IP origen | 1-99, 1300-1999 |
| Extendida | Origen, destino, protocolo, puerto | 100-199, 2000-2699 |
Reglas: orden secuencial, primera coincidencia decide, deny all implícito final, una ACL por protocolo por dirección por interfaz.
Estándar → cerca del destino. Extendida → cerca del origen.
Wildcards
Section titled “Wildcards”0 = debe coincidir | 1 = irrelevante255.255.255.0 -> 0.0.0.255255.255.255.128 -> 0.0.0.127255.255.0.0 -> 0.0.255.00.0.0.0 = host <ip>255.255.255.255 = anyACL estándar
Section titled “ACL estándar”access-list 10 permit 192.168.1.0 0.0.0.255access-list 10 deny anyinterface GigabitEthernet0/1 ip access-group 10 inACL extendida
Section titled “ACL extendida”access-list 100 permit tcp 192.168.1.0 0.0.0.255 host 10.0.0.10 eq 80access-list 100 deny ip any anyinterface GigabitEthernet0/0 ip access-group 100 outOperadores: eq, neq, gt, lt, range 1000 2000.
Named ACL
Section titled “Named ACL”ip access-list extended BLOQUEAR-WEB deny tcp any any eq 80 deny tcp any any eq 443 permit ip any anyinterface GigabitEthernet0/0 ip access-group BLOQUEAR-WEB inRestringir VTY (SSH/Telnet)
Section titled “Restringir VTY (SSH/Telnet)”access-list 15 permit 10.0.0.0 0.0.0.255line vty 0 4 access-class 15 inPara VTY se usa
access-class, noip access-group.
show ip access-listsshow ip interface GigabitEthernet0/0