- VLANs: Crear VLAN 100 (Departamentos) y VLAN 200 (Invitados)
- Switch: Asignar puertos a las VLANs
- Router: Subinterfaces para cada VLAN:
interface g0/0.100
encapsulation dot1Q 100
ip address 192.168.100.1 255.255.255.0
interface g0/0.200
encapsulation dot1Q 200
ip address 192.168.200.1 255.255.255.0
- NAT: Acceso a Internet para ambos:
ip nat inside source list 1 interface g0/1 overload
access-list 1 permit 192.168.0.0 0.0.255.255
- ACL: Restringir VLAN 200 del acceso a 192.168.100.100 (Servidor):
access-list 101 deny ip 192.168.200.0 0.0.0.255 host 192.168.100.100
access-list 101 permit ip any any
interface g0/0.200
ip access-group 101 in