Diseño, subnetting e implementación de una red multi-sede con 4 locales interconectados mediante Router-on-a-Stick + HSRP LAN/WAN. Bloque raíz 10.25.0.0/22, segmentación VLSM por VLAN, 24 VLANs activas y 24 rutas estáticas en el Router Matriz. La Sede Central se conecta a la Matriz vía Fibra Óptica (Gig0/3/0); las demás sedes vía Ethernet estándar.
El bloque raíz 10.25.0.0/22 (~1022 hosts) se divide entre las 4 sedes usando VLSM: cada VLAN recibe la máscara mínima que cubre sus hosts requeridos + las 3 IPs reservadas (.1 VIP, .2 R1, .3 R2). El bloque 10.25.3.192/27 está reservado exclusivamente para los 4 enlaces WAN, cada uno con una subred /29 (6 hosts útiles).
| Sede | Red WAN /29 | VIP HSRP (.1) | R1 (.2) | R2 (.3) | Router Matriz (.4) |
|---|---|---|---|---|---|
| Sede Central | 10.25.3.192/29 | 10.25.3.193 | 10.25.3.194 | 10.25.3.195 | 10.25.3.196 |
| Local Santiago | 10.25.3.200/29 | 10.25.3.201 | 10.25.3.202 | 10.25.3.203 | 10.25.3.204 |
| Local Norte | 10.25.3.208/29 | 10.25.3.209 | 10.25.3.210 | 10.25.3.211 | 10.25.3.212 |
| Local Sur | 10.25.3.216/29 | 10.25.3.217 | 10.25.3.218 | 10.25.3.219 | 10.25.3.220 |
| VLAN | Nombre | Red / Máscara | VIP HSRP | R1 | R2 | Rango DHCP | Hosts req. |
|---|---|---|---|---|---|---|---|
| 20 | Contabilidad | 10.25.0.0/27 | 10.25.0.1 | 10.25.0.2 | 10.25.0.3 | 10.25.0.4–30 | 18 |
| 10 | Gerencia | 10.25.0.32/27 | 10.25.0.33 | 10.25.0.34 | 10.25.0.35 | 10.25.0.36–62 | 15 |
| 40 | Compras | 10.25.0.64/27 | 10.25.0.65 | 10.25.0.66 | 10.25.0.67 | 10.25.0.68–94 | 15 |
| 30 | Recursos Humanos | 10.25.0.96/28 | 10.25.0.97 | 10.25.0.98 | 10.25.0.99 | 10.25.0.100–110 | 12 |
| 50 | IT | 10.25.0.112/28 | 10.25.0.113 | 10.25.0.114 | 10.25.0.115 | 10.25.0.116–126 | 10 |
| 60 | Invitados | 10.25.0.128/28 | 10.25.0.129 | 10.25.0.130 | 10.25.0.131 | 10.25.0.132–142 | 10 |
| VLAN | Nombre | Red / Máscara | VIP HSRP | R1 | R2 | Rango DHCP | Hosts req. |
|---|---|---|---|---|---|---|---|
| 30 | Salón/Servicio | 10.25.1.0/27 | 10.25.1.1 | 10.25.1.2 | 10.25.1.3 | 10.25.1.4–30 | 25 |
| 60 | Clientes WiFi | 10.25.1.32/27 | 10.25.1.33 | 10.25.1.34 | 10.25.1.35 | 10.25.1.36–62 | 25 |
| 20 | Cocina | 10.25.1.64/27 | 10.25.1.65 | 10.25.1.66 | 10.25.1.67 | 10.25.1.68–94 | 20 |
| 40 | Caja/POS | 10.25.1.96/28 | 10.25.1.97 | 10.25.1.98 | 10.25.1.99 | 10.25.1.100–110 | 12 |
| 10 | Administración | 10.25.1.112/28 | 10.25.1.113 | 10.25.1.114 | 10.25.1.115 | 10.25.1.116–126 | 10 |
| 50 | IT | 10.25.1.128/28 | 10.25.1.129 | 10.25.1.130 | 10.25.1.131 | 10.25.1.132–142 | 6 |
| VLAN | Nombre | Red / Máscara | VIP HSRP | R1 | R2 | Rango DHCP | Hosts req. |
|---|---|---|---|---|---|---|---|
| 30 | Salón/Servicio | 10.25.2.0/27 | 10.25.2.1 | 10.25.2.2 | 10.25.2.3 | 10.25.2.4–30 | 22 |
| 60 | Clientes WiFi | 10.25.2.32/27 | 10.25.2.33 | 10.25.2.34 | 10.25.2.35 | 10.25.2.36–62 | 20 |
| 20 | Cocina | 10.25.2.64/27 | 10.25.2.65 | 10.25.2.66 | 10.25.2.67 | 10.25.2.68–94 | 18 |
| 40 | Caja/POS | 10.25.2.96/28 | 10.25.2.97 | 10.25.2.98 | 10.25.2.99 | 10.25.2.100–110 | 10 |
| 10 | Administración | 10.25.2.112/28 | 10.25.2.113 | 10.25.2.114 | 10.25.2.115 | 10.25.2.116–126 | 8 |
| 50 | IT | 10.25.2.128/28 | 10.25.2.129 | 10.25.2.130 | 10.25.2.131 | 10.25.2.132–142 | 6 |
| VLAN | Nombre | Red / Máscara | VIP HSRP | R1 | R2 | Rango DHCP | Hosts req. |
|---|---|---|---|---|---|---|---|
| 30 | Salón/Servicio | 10.25.3.0/27 | 10.25.3.1 | 10.25.3.2 | 10.25.3.3 | 10.25.3.4–30 | 20 |
| 60 | Clientes WiFi | 10.25.3.32/27 | 10.25.3.33 | 10.25.3.34 | 10.25.3.35 | 10.25.3.36–62 | 18 |
| 20 | Cocina | 10.25.3.64/27 | 10.25.3.65 | 10.25.3.66 | 10.25.3.67 | 10.25.3.68–94 | 15 |
| 10 | Administración | 10.25.3.96/28 | 10.25.3.97 | 10.25.3.98 | 10.25.3.99 | 10.25.3.100–110 | 8 |
| 40 | Caja/POS | 10.25.3.112/28 | 10.25.3.113 | 10.25.3.114 | 10.25.3.115 | 10.25.3.116–126 | 8 |
| 50 | IT | 10.25.3.128/28 | 10.25.3.129 | 10.25.3.130 | 10.25.3.131 | 10.25.3.132–142 | 6 |
/27
porque 2⁵ − 2 = 30 hosts útiles, suficientes para cubrir los 18 hosts requeridos
+ 3 IPs de infraestructura reservadas (.1 VIP HSRP, .2 R1, .3 R2), totalizando 21 direcciones
necesarias. Una máscara /28 solo ofrece 2⁴ − 2 = 14 IPs útiles,
resultado insuficiente para los 21 requeridos. El mismo criterio se aplicó a todas las VLANs:
/27 para VLANs con ≥15 hosts y /28 para VLANs con ≤12 hosts.
Cada sede implementa HSRP en dos niveles: en las subinterfaces LAN (una por VLAN, grupo = ID VLAN) y en la interfaz WAN hacia el Router Matriz (grupo 1). Convención: .1 = VIP, .2 = R1 (Active, priority 110, preempt ON), .3 = R2 (Standby, priority 90). R1 recupera el rol Active automáticamente al volver en línea gracias al preempt. Si R1 falla, R2 hereda ambas IPs virtuales sin downtime perceptible.
La encapsulación dot1Q se configura en cada subinterfaz para etiquetar el tráfico por VLAN sobre el enlace troncal.
! ── R1-Sur: subinterfaces dot1Q + HSRP LAN ─────────────────────
interface GigabitEthernet0/1.30
encapsulation dot1Q 30
ip address 10.25.3.2 255.255.255.224 ! R1 física — .2
standby 30 ip 10.25.3.1 ! VIP HSRP — gateway hosts
standby 30 priority 110 ! ACTIVE
standby 30 preempt
interface GigabitEthernet0/1.60
encapsulation dot1Q 60
ip address 10.25.3.34 255.255.255.224
standby 60 ip 10.25.3.33
standby 60 priority 110
standby 60 preempt
! ── R2-Sur: mismo VIP, prioridad 90, sin preempt ───────────────
interface GigabitEthernet0/1.30
encapsulation dot1Q 30
ip address 10.25.3.3 255.255.255.224 ! R2 física — .3
standby 30 ip 10.25.3.1 ! Mismo VIP
standby 30 priority 90 ! STANDBY
! ════════════════════════════════════════════════════════════════
! SEDE SUR — R1-Sur: 6 subinterfaces dot1Q + HSRP LAN
! ════════════════════════════════════════════════════════════════
interface GigabitEthernet0/1.30
encapsulation dot1Q 30
ip address 10.25.3.2 255.255.255.224 ! R1 — .2 | Red .0/27
standby 30 ip 10.25.3.1 ! VIP HSRP
standby 30 priority 110
standby 30 preempt
interface GigabitEthernet0/1.60
encapsulation dot1Q 60
ip address 10.25.3.34 255.255.255.224 ! R1 — .34 | Red .32/27
standby 60 ip 10.25.3.33
standby 60 priority 110
standby 60 preempt
interface GigabitEthernet0/1.20
encapsulation dot1Q 20
ip address 10.25.3.66 255.255.255.224 ! R1 — .66 | Red .64/27
standby 20 ip 10.25.3.65
standby 20 priority 110
standby 20 preempt
interface GigabitEthernet0/1.10
encapsulation dot1Q 10
ip address 10.25.3.98 255.255.255.240 ! R1 — .98 | Red .96/28
standby 10 ip 10.25.3.97
standby 10 priority 110
standby 10 preempt
interface GigabitEthernet0/1.40
encapsulation dot1Q 40
ip address 10.25.3.114 255.255.255.240 ! R1 — .114 | Red .112/28
standby 40 ip 10.25.3.113
standby 40 priority 110
standby 40 preempt
interface GigabitEthernet0/1.50
encapsulation dot1Q 50
ip address 10.25.3.130 255.255.255.240 ! R1 — .130 | Red .128/28
standby 50 ip 10.25.3.129
standby 50 priority 110
standby 50 preempt
! ── R2-Sur: mismo VIP, prioridad 90, sin preempt ───────────────
interface GigabitEthernet0/1.30
encapsulation dot1Q 30
ip address 10.25.3.3 255.255.255.224 ! R2 — .3
standby 30 ip 10.25.3.1
standby 30 priority 90
interface GigabitEthernet0/1.60
encapsulation dot1Q 60
ip address 10.25.3.35 255.255.255.224 ! R2 — .35
standby 60 ip 10.25.3.33
standby 60 priority 90
interface GigabitEthernet0/1.20
encapsulation dot1Q 20
ip address 10.25.3.67 255.255.255.224 ! R2 — .67
standby 20 ip 10.25.3.65
standby 20 priority 90
interface GigabitEthernet0/1.10
encapsulation dot1Q 10
ip address 10.25.3.99 255.255.255.240 ! R2 — .99
standby 10 ip 10.25.3.97
standby 10 priority 90
interface GigabitEthernet0/1.40
encapsulation dot1Q 40
ip address 10.25.3.115 255.255.255.240 ! R2 — .115
standby 40 ip 10.25.3.113
standby 40 priority 90
interface GigabitEthernet0/1.50
encapsulation dot1Q 50
ip address 10.25.3.131 255.255.255.240 ! R2 — .131
standby 50 ip 10.25.3.129
standby 50 priority 90
! ── HSRP WAN Sur (10.25.3.216/29) ─────────────────────────────
! R1-Sur WAN
interface GigabitEthernet0/0
ip address 10.25.3.218 255.255.255.248 ! R1 — .218 (.2 del /29)
standby 1 ip 10.25.3.217 ! VIP WAN → next-hop Matriz
standby 1 priority 110
standby 1 preempt
no shutdown
! R2-Sur WAN
interface GigabitEthernet0/0
ip address 10.25.3.219 255.255.255.248 ! R2 — .219 (.3 del /29)
standby 1 ip 10.25.3.217
standby 1 priority 90
no shutdown
ip route 0.0.0.0 0.0.0.0 10.25.3.220 ! next-hop Router Matriz (.4)
! ════════════════════════════════════════════════════════════════
! SEDE NORTE — R1-Norte: 6 subinterfaces dot1Q + HSRP LAN
! ════════════════════════════════════════════════════════════════
interface GigabitEthernet0/1.30
encapsulation dot1Q 30
ip address 10.25.2.2 255.255.255.224 ! R1 — .2 | Red .0/27
standby 30 ip 10.25.2.1
standby 30 priority 110
standby 30 preempt
interface GigabitEthernet0/1.60
encapsulation dot1Q 60
ip address 10.25.2.34 255.255.255.224 ! R1 — .34 | Red .32/27
standby 60 ip 10.25.2.33
standby 60 priority 110
standby 60 preempt
interface GigabitEthernet0/1.20
encapsulation dot1Q 20
ip address 10.25.2.66 255.255.255.224 ! R1 — .66 | Red .64/27
standby 20 ip 10.25.2.65
standby 20 priority 110
standby 20 preempt
interface GigabitEthernet0/1.40
encapsulation dot1Q 40
ip address 10.25.2.98 255.255.255.240 ! R1 — .98 | Red .96/28
standby 40 ip 10.25.2.97
standby 40 priority 110
standby 40 preempt
interface GigabitEthernet0/1.10
encapsulation dot1Q 10
ip address 10.25.2.114 255.255.255.240 ! R1 — .114 | Red .112/28
standby 10 ip 10.25.2.113
standby 10 priority 110
standby 10 preempt
interface GigabitEthernet0/1.50
encapsulation dot1Q 50
ip address 10.25.2.130 255.255.255.240 ! R1 — .130 | Red .128/28
standby 50 ip 10.25.2.129
standby 50 priority 110
standby 50 preempt
! ── R2-Norte: mismo VIP, prioridad 90, sin preempt ─────────────
interface GigabitEthernet0/1.30
encapsulation dot1Q 30
ip address 10.25.2.3 255.255.255.224 ! R2 — .3
standby 30 ip 10.25.2.1
standby 30 priority 90
interface GigabitEthernet0/1.60
encapsulation dot1Q 60
ip address 10.25.2.35 255.255.255.224 ! R2 — .35
standby 60 ip 10.25.2.33
standby 60 priority 90
interface GigabitEthernet0/1.20
encapsulation dot1Q 20
ip address 10.25.2.67 255.255.255.224 ! R2 — .67
standby 20 ip 10.25.2.65
standby 20 priority 90
interface GigabitEthernet0/1.40
encapsulation dot1Q 40
ip address 10.25.2.99 255.255.255.240 ! R2 — .99
standby 40 ip 10.25.2.97
standby 40 priority 90
interface GigabitEthernet0/1.10
encapsulation dot1Q 10
ip address 10.25.2.115 255.255.255.240 ! R2 — .115
standby 10 ip 10.25.2.113
standby 10 priority 90
interface GigabitEthernet0/1.50
encapsulation dot1Q 50
ip address 10.25.2.131 255.255.255.240 ! R2 — .131
standby 50 ip 10.25.2.129
standby 50 priority 90
! ── HSRP WAN Norte (10.25.3.208/29) ───────────────────────────
! R1-Norte WAN
interface GigabitEthernet0/0
ip address 10.25.3.210 255.255.255.248 ! R1 — .210 (.2 del /29)
standby 1 ip 10.25.3.209 ! VIP WAN → next-hop Matriz
standby 1 priority 110
standby 1 preempt
no shutdown
! R2-Norte WAN
interface GigabitEthernet0/0
ip address 10.25.3.211 255.255.255.248 ! R2 — .211 (.3 del /29)
standby 1 ip 10.25.3.209
standby 1 priority 90
no shutdown
ip route 0.0.0.0 0.0.0.0 10.25.3.212 ! next-hop Router Matriz (.4)
! ════════════════════════════════════════════════════════════════
! SEDE SANTIAGO — R1-Santiago: 6 subinterfaces dot1Q + HSRP LAN
! ════════════════════════════════════════════════════════════════
interface GigabitEthernet0/1.30
encapsulation dot1Q 30
ip address 10.25.1.2 255.255.255.224 ! R1 — .2 | Red .0/27
standby 30 ip 10.25.1.1
standby 30 priority 110
standby 30 preempt
interface GigabitEthernet0/1.60
encapsulation dot1Q 60
ip address 10.25.1.34 255.255.255.224 ! R1 — .34 | Red .32/27
standby 60 ip 10.25.1.33
standby 60 priority 110
standby 60 preempt
interface GigabitEthernet0/1.20
encapsulation dot1Q 20
ip address 10.25.1.66 255.255.255.224 ! R1 — .66 | Red .64/27
standby 20 ip 10.25.1.65
standby 20 priority 110
standby 20 preempt
interface GigabitEthernet0/1.40
encapsulation dot1Q 40
ip address 10.25.1.98 255.255.255.240 ! R1 — .98 | Red .96/28
standby 40 ip 10.25.1.97
standby 40 priority 110
standby 40 preempt
interface GigabitEthernet0/1.10
encapsulation dot1Q 10
ip address 10.25.1.114 255.255.255.240 ! R1 — .114 | Red .112/28
standby 10 ip 10.25.1.113
standby 10 priority 110
standby 10 preempt
interface GigabitEthernet0/1.50
encapsulation dot1Q 50
ip address 10.25.1.130 255.255.255.240 ! R1 — .130 | Red .128/28
standby 50 ip 10.25.1.129
standby 50 priority 110
standby 50 preempt
! ── R2-Santiago: mismo VIP, prioridad 90, sin preempt ──────────
interface GigabitEthernet0/1.30
encapsulation dot1Q 30
ip address 10.25.1.3 255.255.255.224 ! R2 — .3
standby 30 ip 10.25.1.1
standby 30 priority 90
interface GigabitEthernet0/1.60
encapsulation dot1Q 60
ip address 10.25.1.35 255.255.255.224 ! R2 — .35
standby 60 ip 10.25.1.33
standby 60 priority 90
interface GigabitEthernet0/1.20
encapsulation dot1Q 20
ip address 10.25.1.67 255.255.255.224 ! R2 — .67
standby 20 ip 10.25.1.65
standby 20 priority 90
interface GigabitEthernet0/1.40
encapsulation dot1Q 40
ip address 10.25.1.99 255.255.255.240 ! R2 — .99
standby 40 ip 10.25.1.97
standby 40 priority 90
interface GigabitEthernet0/1.10
encapsulation dot1Q 10
ip address 10.25.1.115 255.255.255.240 ! R2 — .115
standby 10 ip 10.25.1.113
standby 10 priority 90
interface GigabitEthernet0/1.50
encapsulation dot1Q 50
ip address 10.25.1.131 255.255.255.240 ! R2 — .131
standby 50 ip 10.25.1.129
standby 50 priority 90
! ── HSRP WAN Santiago (10.25.3.200/29) ────────────────────────
! R1-Santiago WAN
interface GigabitEthernet0/0
ip address 10.25.3.202 255.255.255.248 ! R1 — .202 (.2 del /29)
standby 1 ip 10.25.3.201 ! VIP WAN → next-hop Matriz
standby 1 priority 110
standby 1 preempt
no shutdown
! R2-Santiago WAN
interface GigabitEthernet0/0
ip address 10.25.3.203 255.255.255.248 ! R2 — .203 (.3 del /29)
standby 1 ip 10.25.3.201
standby 1 priority 90
no shutdown
ip route 0.0.0.0 0.0.0.0 10.25.3.204 ! next-hop Router Matriz (.4)
! ════════════════════════════════════════════════════════════════
! SEDE CENTRAL — R1-Central: 6 subinterfaces dot1Q + HSRP LAN
! ════════════════════════════════════════════════════════════════
interface GigabitEthernet0/1.10
encapsulation dot1Q 10
ip address 10.25.0.34 255.255.255.224 ! R1 — .34 | Red .32/27
standby 10 ip 10.25.0.33
standby 10 priority 110
standby 10 preempt
interface GigabitEthernet0/1.20
encapsulation dot1Q 20
ip address 10.25.0.2 255.255.255.224 ! R1 — .2 | Red .0/27
standby 20 ip 10.25.0.1
standby 20 priority 110
standby 20 preempt
interface GigabitEthernet0/1.30
encapsulation dot1Q 30
ip address 10.25.0.98 255.255.255.240 ! R1 — .98 | Red .96/28
standby 30 ip 10.25.0.97
standby 30 priority 110
standby 30 preempt
interface GigabitEthernet0/1.40
encapsulation dot1Q 40
ip address 10.25.0.66 255.255.255.224 ! R1 — .66 | Red .64/27
standby 40 ip 10.25.0.65
standby 40 priority 110
standby 40 preempt
interface GigabitEthernet0/1.50
encapsulation dot1Q 50
ip address 10.25.0.114 255.255.255.240 ! R1 — .114 | Red .112/28
standby 50 ip 10.25.0.113
standby 50 priority 110
standby 50 preempt
interface GigabitEthernet0/1.60
encapsulation dot1Q 60
ip address 10.25.0.130 255.255.255.240 ! R1 — .130 | Red .128/28
standby 60 ip 10.25.0.129
standby 60 priority 110
standby 60 preempt
! ── R2-Central: mismo VIP, prioridad 90, sin preempt ───────────
interface GigabitEthernet0/1.10
encapsulation dot1Q 10
ip address 10.25.0.35 255.255.255.224 ! R2 — .35
standby 10 ip 10.25.0.33
standby 10 priority 90
interface GigabitEthernet0/1.20
encapsulation dot1Q 20
ip address 10.25.0.3 255.255.255.224 ! R2 — .3
standby 20 ip 10.25.0.1
standby 20 priority 90
interface GigabitEthernet0/1.30
encapsulation dot1Q 30
ip address 10.25.0.99 255.255.255.240 ! R2 — .99
standby 30 ip 10.25.0.97
standby 30 priority 90
interface GigabitEthernet0/1.40
encapsulation dot1Q 40
ip address 10.25.0.67 255.255.255.224 ! R2 — .67
standby 40 ip 10.25.0.65
standby 40 priority 90
interface GigabitEthernet0/1.50
encapsulation dot1Q 50
ip address 10.25.0.115 255.255.255.240 ! R2 — .115
standby 50 ip 10.25.0.113
standby 50 priority 90
interface GigabitEthernet0/1.60
encapsulation dot1Q 60
ip address 10.25.0.131 255.255.255.240 ! R2 — .131
standby 60 ip 10.25.0.129
standby 60 priority 90
! ── HSRP WAN Central — Fibra Óptica Gig0/3/0 (10.25.3.192/29) ─
! Puerto especial Gig0/3/0 — módulo HWIC / SFP óptico
! R1-Central WAN
interface GigabitEthernet0/3/0
ip address 10.25.3.194 255.255.255.248 ! R1 — .194 (.2 del /29)
standby 1 ip 10.25.3.193 ! VIP WAN HSRP
standby 1 priority 110
standby 1 preempt
no shutdown
! R2-Central WAN
interface GigabitEthernet0/3/0
ip address 10.25.3.195 255.255.255.248 ! R2 — .195 (.3 del /29)
standby 1 ip 10.25.3.193
standby 1 priority 90
no shutdown
ip route 0.0.0.0 0.0.0.0 10.25.3.196 ! next-hop Router Matriz (.4)
Para evitar conflictos de IP, se aplica ip dhcp excluded-address antes de definir cada pool.
Esto protege las 3 primeras IPs útiles de cada subred: .1 (VIP HSRP), .2 (R1) y .3 (R2),
garantizando que el servidor DHCP nunca las asigne a un host. Los hosts solo reciben IPs desde .4 en adelante.
| Sede | Comando ip dhcp excluded-address | Razón |
|---|---|---|
| Sede Central | 10.25.0.97 10.25.0.99 | Protege VIP (.97), R1 (.98), R2 (.99) |
| Local Santiago | 10.25.1.1 10.25.1.3 | Protege VIP (.1), R1 (.2), R2 (.3) |
| Local Norte | 10.25.2.1 10.25.2.3 | Protege VIP (.1), R1 (.2), R2 (.3) |
| Local Sur | 10.25.3.1 10.25.3.3 | Protege VIP (.1), R1 (.2), R2 (.3) |
! ── SEDE CENTRAL — exclusiones + pools ─────────────────────────
ip dhcp excluded-address 10.25.0.33 10.25.0.35 ! VLAN 10 Gerencia
ip dhcp excluded-address 10.25.0.1 10.25.0.3 ! VLAN 20 Contabilidad
ip dhcp excluded-address 10.25.0.97 10.25.0.99 ! VLAN 30 RRHH
ip dhcp excluded-address 10.25.0.65 10.25.0.67 ! VLAN 40 Compras
ip dhcp excluded-address 10.25.0.113 10.25.0.115 ! VLAN 50 IT
ip dhcp excluded-address 10.25.0.129 10.25.0.131 ! VLAN 60 Invitados
ip dhcp pool GerenciaVLAN10
network 10.25.0.32 255.255.255.224
default-router 10.25.0.33
dns-server 8.8.8.8
ip dhcp pool ContabilidadVLAN20
network 10.25.0.0 255.255.255.224
default-router 10.25.0.1
dns-server 8.8.8.8
ip dhcp pool RRHHVLAN30
network 10.25.0.96 255.255.255.240
default-router 10.25.0.97
dns-server 8.8.8.8
ip dhcp pool ComprasVLAN40
network 10.25.0.64 255.255.255.224
default-router 10.25.0.65
dns-server 8.8.8.8
ip dhcp pool ITVLAN50
network 10.25.0.112 255.255.255.240
default-router 10.25.0.113
dns-server 8.8.8.8
ip dhcp pool InvitadosVLAN60
network 10.25.0.128 255.255.255.240
default-router 10.25.0.129
dns-server 8.8.8.8
! ── LOCAL SANTIAGO — exclusiones + pools ────────────────────────
ip dhcp excluded-address 10.25.1.113 10.25.1.115 ! VLAN 10 Administración
ip dhcp excluded-address 10.25.1.65 10.25.1.67 ! VLAN 20 Cocina
ip dhcp excluded-address 10.25.1.1 10.25.1.3 ! VLAN 30 Salón/Servicio
ip dhcp excluded-address 10.25.1.97 10.25.1.99 ! VLAN 40 Caja/POS
ip dhcp excluded-address 10.25.1.129 10.25.1.131 ! VLAN 50 IT
ip dhcp excluded-address 10.25.1.33 10.25.1.35 ! VLAN 60 Clientes WiFi
ip dhcp pool S_V10
network 10.25.1.112 255.255.255.240
default-router 10.25.1.113
dns-server 8.8.8.8
ip dhcp pool S_V20
network 10.25.1.64 255.255.255.224
default-router 10.25.1.65
dns-server 8.8.8.8
ip dhcp pool S_V30
network 10.25.1.0 255.255.255.224
default-router 10.25.1.1
dns-server 8.8.8.8
ip dhcp pool S_V40
network 10.25.1.96 255.255.255.240
default-router 10.25.1.97
dns-server 8.8.8.8
ip dhcp pool S_V50
network 10.25.1.128 255.255.255.240
default-router 10.25.1.129
dns-server 8.8.8.8
ip dhcp pool S_V60
network 10.25.1.32 255.255.255.224
default-router 10.25.1.33
dns-server 8.8.8.8
! ── LOCAL NORTE — exclusiones + pools ──────────────────────────
ip dhcp excluded-address 10.25.2.113 10.25.2.115 ! VLAN 10 Administración
ip dhcp excluded-address 10.25.2.65 10.25.2.67 ! VLAN 20 Cocina
ip dhcp excluded-address 10.25.2.1 10.25.2.3 ! VLAN 30 Salón/Servicio
ip dhcp excluded-address 10.25.2.97 10.25.2.99 ! VLAN 40 Caja/POS
ip dhcp excluded-address 10.25.2.129 10.25.2.131 ! VLAN 50 IT
ip dhcp excluded-address 10.25.2.33 10.25.2.35 ! VLAN 60 Clientes WiFi
ip dhcp pool AdminVLAN10
network 10.25.2.112 255.255.255.240
default-router 10.25.2.113
dns-server 8.8.8.8
ip dhcp pool CocinaVLAN20
network 10.25.2.64 255.255.255.224
default-router 10.25.2.65
dns-server 8.8.8.8
ip dhcp pool SalonVLAN30
network 10.25.2.0 255.255.255.224
default-router 10.25.2.1
dns-server 8.8.8.8
ip dhcp pool CajaVLAN40
network 10.25.2.96 255.255.255.240
default-router 10.25.2.97
dns-server 8.8.8.8
ip dhcp pool ITVLAN50
network 10.25.2.128 255.255.255.240
default-router 10.25.2.129
dns-server 8.8.8.8
ip dhcp pool Wifi-VLAN60
network 10.25.2.32 255.255.255.224
default-router 10.25.2.33
dns-server 8.8.8.8
! ── LOCAL SUR — exclusiones + pools ────────────────────────────
ip dhcp excluded-address 10.25.3.97 10.25.3.99 ! VLAN 10 Administración
ip dhcp excluded-address 10.25.3.65 10.25.3.67 ! VLAN 20 Cocina
ip dhcp excluded-address 10.25.3.1 10.25.3.3 ! VLAN 30 Salón/Servicio
ip dhcp excluded-address 10.25.3.113 10.25.3.115 ! VLAN 40 Caja/POS
ip dhcp excluded-address 10.25.3.129 10.25.3.131 ! VLAN 50 IT
ip dhcp excluded-address 10.25.3.33 10.25.3.35 ! VLAN 60 Clientes WiFi
ip dhcp pool AdminVLAN10
network 10.25.3.96 255.255.255.240
default-router 10.25.3.97
dns-server 8.8.8.8
ip dhcp pool CocinaaVLAN20
network 10.25.3.64 255.255.255.224
default-router 10.25.3.65
dns-server 8.8.8.8
ip dhcp pool SalonVLAN30
network 10.25.3.0 255.255.255.224
default-router 10.25.3.1
dns-server 8.8.8.8
ip dhcp pool CajaVALAN40
network 10.25.3.112 255.255.255.240
default-router 10.25.3.113
dns-server 8.8.8.8
ip dhcp pool ITVLAN50
network 10.25.3.128 255.255.255.240
default-router 10.25.3.129
dns-server 8.8.8.8
ip dhcp pool Wifi-VLAN60
network 10.25.3.32 255.255.255.224
default-router 10.25.3.33
dns-server 8.8.8.8
! ── VERIFICACIÓN ────────────────────────────────────────────────
show ip dhcp pool
show ip dhcp binding ! Confirmar VIP (.1) como gateway
El Router Matriz no tiene HSRP, VLANs ni DHCP. Su función exclusiva es el enrutamiento inter-sede con 24 rutas estáticas. El next-hop de cada ruta es la VIP HSRP WAN (.1) de la sede destino, haciendo el failover R1→R2 transparente para el Matriz.
| Puerto | Sede | IP Matriz | Medio |
|---|---|---|---|
| Gig0/0 | Local Santiago | 10.25.3.204 | Ethernet |
| Gig0/1 | Local Norte | 10.25.3.212 | Ethernet |
| Gig0/2 | Local Sur | 10.25.3.220 | Ethernet |
| Gig0/3/0 | Sede Central | 10.25.3.196 | ⬡ Fibra Óptica |
Gig0/1 (no Gig0/0).
La Sede Central es la única sede con enlace de Fibra Óptica usando el puerto Gig0/3/0
(módulo HWIC/SFP óptico), con IP de Matriz 10.25.3.196.
! ── SEDE CENTRAL (next-hop: 10.25.3.193) ───────────────────────
ip route 10.25.0.0 255.255.255.224 10.25.3.193 ! V20 Contabilidad
ip route 10.25.0.32 255.255.255.224 10.25.3.193 ! V10 Gerencia
ip route 10.25.0.64 255.255.255.224 10.25.3.193 ! V40 Compras
ip route 10.25.0.96 255.255.255.240 10.25.3.193 ! V30 RRHH
ip route 10.25.0.112 255.255.255.240 10.25.3.193 ! V50 IT
ip route 10.25.0.128 255.255.255.240 10.25.3.193 ! V60 Invitados
! ── LOCAL SANTIAGO (next-hop: 10.25.3.201) ─────────────────────
ip route 10.25.1.0 255.255.255.224 10.25.3.201 ! V30 Salón
ip route 10.25.1.32 255.255.255.224 10.25.3.201 ! V60 Clientes WiFi
ip route 10.25.1.64 255.255.255.224 10.25.3.201 ! V20 Cocina
ip route 10.25.1.96 255.255.255.240 10.25.3.201 ! V40 Caja/POS
ip route 10.25.1.112 255.255.255.240 10.25.3.201 ! V10 Administración
ip route 10.25.1.128 255.255.255.240 10.25.3.201 ! V50 IT
! ── LOCAL NORTE (next-hop: 10.25.3.209) ────────────────────────
ip route 10.25.2.0 255.255.255.224 10.25.3.209 ! V30 Salón
ip route 10.25.2.32 255.255.255.224 10.25.3.209 ! V60 Clientes WiFi
ip route 10.25.2.64 255.255.255.224 10.25.3.209 ! V20 Cocina
ip route 10.25.2.96 255.255.255.240 10.25.3.209 ! V40 Caja/POS
ip route 10.25.2.112 255.255.255.240 10.25.3.209 ! V10 Administración
ip route 10.25.2.128 255.255.255.240 10.25.3.209 ! V50 IT
! ── LOCAL SUR (next-hop: 10.25.3.217) ───────────────────────
ip route 10.25.3.0 255.255.255.224 10.25.3.217 ! V30 Salón
ip route 10.25.3.32 255.255.255.224 10.25.3.217 ! V60 Clientes WiFi
ip route 10.25.3.64 255.255.255.224 10.25.3.217 ! V20 Cocina
ip route 10.25.3.96 255.255.255.240 10.25.3.217 ! V10 Administración
ip route 10.25.3.112 255.255.255.240 10.25.3.217 ! V40 Caja/POS
ip route 10.25.3.128 255.255.255.240 10.25.3.217 ! V50 IT
! ── VERIFICACIÓN ────────────────────────────────────────────────
show ip route static
show ip route summary
| # | Destino | Máscara | Next-Hop (VIP WAN) | VLAN | Sede |
|---|---|---|---|---|---|
| // SEDE CENTRAL — next-hop 10.25.3.193 | |||||
| 1 | 10.25.0.0 | /27 | 10.25.3.193 | V20 | Central |
| 2 | 10.25.0.32 | /27 | 10.25.3.193 | V10 | Central |
| 3 | 10.25.0.64 | /27 | 10.25.3.193 | V40 | Central |
| 4 | 10.25.0.96 | /28 | 10.25.3.193 | V30 | Central |
| 5 | 10.25.0.112 | /28 | 10.25.3.193 | V50 | Central |
| 6 | 10.25.0.128 | /28 | 10.25.3.193 | V60 | Central |
| // LOCAL SANTIAGO — next-hop 10.25.3.201 | |||||
| 7 | 10.25.1.0 | /27 | 10.25.3.201 | V30 | Santiago |
| 8 | 10.25.1.32 | /27 | 10.25.3.201 | V60 | Santiago |
| 9 | 10.25.1.64 | /27 | 10.25.3.201 | V20 | Santiago |
| 10 | 10.25.1.96 | /28 | 10.25.3.201 | V40 | Santiago |
| 11 | 10.25.1.112 | /28 | 10.25.3.201 | V10 | Santiago |
| 12 | 10.25.1.128 | /28 | 10.25.3.201 | V50 | Santiago |
| // LOCAL NORTE — next-hop 10.25.3.209 | |||||
| 13 | 10.25.2.0 | /27 | 10.25.3.209 | V30 | Norte |
| 14 | 10.25.2.32 | /27 | 10.25.3.209 | V60 | Norte |
| 15 | 10.25.2.64 | /27 | 10.25.3.209 | V20 | Norte |
| 16 | 10.25.2.96 | /28 | 10.25.3.209 | V40 | Norte |
| 17 | 10.25.2.112 | /28 | 10.25.3.209 | V10 | Norte |
| 18 | 10.25.2.128 | /28 | 10.25.3.209 | V50 | Norte |
| // LOCAL SUR — next-hop 10.25.3.217 | |||||
| 19 | 10.25.3.0 | /27 | 10.25.3.217 | V30 | Sur |
| 20 | 10.25.3.32 | /27 | 10.25.3.217 | V60 | Sur |
| 21 | 10.25.3.64 | /27 | 10.25.3.217 | V20 | Sur |
| 22 | 10.25.3.96 | /28 | 10.25.3.217 | V10 | Sur |
| 23 | 10.25.3.112 | /28 | 10.25.3.217 | V40 | Sur |
| 24 | 10.25.3.128 | /28 | 10.25.3.217 | V50 | Sur |
Validación end-to-end con pings entre todas las sedes. Verificaciones con show standby brief, show ip route y prueba de failover apagando R1 con ping continuo activo.
| Comando | Propósito |
|---|---|
| show standby brief | Confirma roles Active/Standby y VIP activa por VLAN |
| show ip route | Verifica las 24 rutas estáticas en el Router-Matriz |
| show ip dhcp binding | Valida que los hosts reciben la VIP (.1) como gateway |
| show ip dhcp pool | Confirma los rangos y exclusiones de cada pool |
| ping <IP_sede_remota> | Conectividad extremo a extremo entre sedes (0% loss) |
Referencia rápida de conectividad WAN, rangos de hosts por VLAN y comandos de verificación para el proyecto HJS Network. Cada sede enlaza al Router Matriz vía su subred /29 usando HSRP WAN (grupo 1). Los DHCP Pools asignan IPs desde la .4 debido a las exclusiones de VIP, R1 y R2.
| Sede | Red WAN /29 | VIP HSRP (.1) | R1 (.2) | R2 (.3) | Router Matriz (.4) |
|---|---|---|---|---|---|
| Sede Central | 10.25.3.192/29 | 10.25.3.193 | 10.25.3.194 | 10.25.3.195 | 10.25.3.196 |
| Local Santiago | 10.25.3.200/29 | 10.25.3.201 | 10.25.3.202 | 10.25.3.203 | 10.25.3.204 |
| Local Norte | 10.25.3.208/29 | 10.25.3.209 | 10.25.3.210 | 10.25.3.211 | 10.25.3.212 |
| Local Sur | 10.25.3.216/29 | 10.25.3.217 | 10.25.3.218 | 10.25.3.219 | 10.25.3.220 |
.4 porque las primeras 3 IPs útiles de cada subred
están excluidas del DHCP Pool:
.1 → VIP HSRP (gateway de hosts),
.2 → R1 (Active), .3 → R2 (Standby). Esta exclusión garantiza que ningún
host reciba por DHCP una
dirección reservada para infraestructura.