Design the campus subnets, build a router-on-a-stick, and hand out IP addresses automatically with DHCP
The NZSE campus is growing. The IT team needs to split the campus network into separate segments — one for the Library, one for the Computer Labs, one for Administration, one for Academic Staff, one for the Student Wi-Fi, and one for the Servers / Data Centre. Keeping every device on one flat network would flood it with broadcast traffic and let student Wi-Fi devices reach sensitive admin and server systems.
Subnetting divides one large Class B network into smaller department segments, each with its own broadcast domain — this reduces congestion, improves security, and makes faults easier to locate. But assigning a static IP to every laptop, PC and phone on campus by hand is impossible. That is where DHCP (Dynamic Host Configuration Protocol) comes in: the router hands out IP addresses, subnet masks, gateways and DNS servers automatically as devices connect.
In this practical you will subnet the Class B network 172.20.0.0/16, provision it for future growth, and map six subnets to six campus departments. Then you will build the network in Packet Tracer using VLANs and a router-on-a-stick, configure a DHCP pool for every department, and watch each PC receive its address automatically. Finally you will verify everything with ipconfig and ping.
The IT team has assigned NZSE the Class B network:
172.20.0.0255.255.0.0 (/16)We need 6 subnets now, but the design rule says provision for up to 16. How many host bits must you borrow to create at least 16 subnets?
11111111.11111111.11110000.00000000Work out the following from the /20 subnet mask:
| Question | Your Answer |
|---|---|
| Remaining host bits | |
| Total addresses per subnet (2?) | |
| Usable hosts per subnet (2? − 2) |
Fill in the details for the 6 subnets in use. Each row already shows which department the subnet belongs to.
| Subnet | Department | Network Address | First Usable Host | Last Usable Host | Broadcast Address |
|---|---|---|---|---|---|
| 1 | Library | ||||
| 2 | Computer Labs | ||||
| 3 | Administration | ||||
| 4 | Academic Staff | ||||
| 5 | Student Wi-Fi | ||||
| 6 | Servers |
172.20.0.1, Computer Labs 172.20.16.1, Administration 172.20.32.1, Academic Staff 172.20.48.1, Student Wi-Fi 172.20.64.1, Servers 172.20.80.1.
Create the following network in Packet Tracer. We will use a Router-on-a-Stick design: one physical cable carries traffic for all six departments using VLANs (Virtual LANs).
Click on the Switch, go to the CLI tab, and paste the following configuration. This creates 6 VLANs (one per department), assigns the device ports to the correct VLAN, and sets up a trunk link to the router.
enable
configure terminal
hostname CampusSwitch
enable — enters privileged EXEC mode (gives you full access to configuration commands).configure terminal — enters global configuration mode where you can change switch settings.hostname CampusSwitch — gives the switch a meaningful name so you can identify it in the CLI prompt.We create 6 VLANs — one for each department. A VLAN (Virtual LAN) logically separates ports on the same physical switch into isolated networks. Devices in the Student Wi-Fi VLAN cannot talk to devices in the Servers VLAN without going through the router, just as if they were on completely separate switches.
vlan 10
name Library
vlan 20
name Computer_Labs
vlan 30
name Administration
vlan 40
name Academic_Staff
vlan 50
name Student_WiFi
vlan 60
name Servers
vlan 10 — creates (or enters) VLAN number 10.name Library — assigns a human-readable name. This is optional but makes show vlan brief much easier to read.Each department's devices plug into specific switch ports. We put those ports in access mode and assign them to the correct VLAN. An access port belongs to exactly one VLAN and strips the VLAN tag before sending frames to the device (the PC never knows it is on a VLAN).
interface range FastEthernet0/1-2
switchport mode access
switchport access vlan 10
!
interface range FastEthernet0/3-4
switchport mode access
switchport access vlan 20
!
interface range FastEthernet0/5-6
switchport mode access
switchport access vlan 30
!
interface range FastEthernet0/7-8
switchport mode access
switchport access vlan 40
!
interface range FastEthernet0/9-10
switchport mode access
switchport access vlan 50
!
interface FastEthernet0/11
switchport mode access
switchport access vlan 60
interface range FastEthernet0/1-2 — selects ports Fa0/1 and Fa0/2 at the same time (saves typing).switchport mode access — tells the port it will connect to an end device and carry traffic for only one VLAN.switchport access vlan 10 — assigns these ports to VLAN 10 (Library). Any frame arriving on Fa0/1 or Fa0/2 is treated as Library traffic.The uplink from the switch to the router must carry traffic for all 6 VLANs over a single cable. We set this port to trunk mode. A trunk port tags every outgoing frame with its VLAN ID (using the 802.1Q standard) so the router knows which department the frame belongs to.
interface GigabitEthernet0/1
switchport mode trunk
interface GigabitEthernet0/1 — selects the Gigabit port connected to the router.switchport mode trunk — enables trunking. The switch will now add a 4-byte 802.1Q tag to every frame sent to the router, identifying which VLAN it came from.end
write memory
end — exits back to privileged EXEC mode.write memory — saves the running configuration to NVRAM so it persists after a reboot.Click on the Router, go to the CLI tab, and enter the following. This creates 6 sub-interfaces on a single physical port — one per department — each acting as the default gateway for its subnet.
enable
configure terminal
hostname CampusRouter
!
interface GigabitEthernet0/0
no shutdown
enable / configure terminal — same as on the switch: enters global configuration mode.hostname CampusRouter — names the router for easy identification.interface GigabitEthernet0/0 — selects the physical interface connected to the switch trunk.no shutdown — turns the interface on. By default, router interfaces are administratively shut down. Without this command, none of the sub-interfaces will work.A sub-interface is a logical division of a physical interface. The router uses sub-interfaces to handle traffic from different VLANs on the same physical cable — this is the “router-on-a-stick” design. Each sub-interface needs an 802.1Q encapsulation (which VLAN tag to match) and an IP address (the gateway for that department).
interface GigabitEthernet0/0.10
encapsulation dot1Q 10
ip address 172.20.0.1 255.255.240.0
!
interface GigabitEthernet0/0.20
encapsulation dot1Q 20
ip address 172.20.16.1 255.255.240.0
!
interface GigabitEthernet0/0.30
encapsulation dot1Q 30
ip address 172.20.32.1 255.255.240.0
!
interface GigabitEthernet0/0.40
encapsulation dot1Q 40
ip address 172.20.48.1 255.255.240.0
!
interface GigabitEthernet0/0.50
encapsulation dot1Q 50
ip address 172.20.64.1 255.255.240.0
!
interface GigabitEthernet0/0.60
encapsulation dot1Q 60
ip address 172.20.80.1 255.255.240.0
interface GigabitEthernet0/0.10 — creates sub-interface .10 on GigE0/0. We match the label to the VLAN number by convention to keep things clear.encapsulation dot1Q 10 — tells this sub-interface to handle frames tagged with VLAN 10 (the Library).ip address 172.20.0.1 255.255.240.0 — assigns the first usable IP in the Library subnet as the gateway. Every Library device will use 172.20.0.1 as its default gateway.255.255.240.0, because each department is a /20 subnet. Only the network portion (the 3rd octet: 0, 16, 32, 48, 64, 80) changes between departments.
Instead of typing a static IP into every PC on campus, we let the router hand out addresses automatically. When a PC set to DHCP powers on, it broadcasts a request; the router replies with an IP address, subnet mask, default gateway and DNS server for that department.
Some addresses must never be handed out to random devices: the gateway (.1) and a small block reserved for printers, access points and other fixed infrastructure. We exclude the first 10 addresses of each user subnet.
ip dhcp excluded-address 172.20.0.1 172.20.0.10
ip dhcp excluded-address 172.20.16.1 172.20.16.10
ip dhcp excluded-address 172.20.32.1 172.20.32.10
ip dhcp excluded-address 172.20.48.1 172.20.48.10
ip dhcp excluded-address 172.20.64.1 172.20.64.10
ip dhcp excluded-address 172.20.0.1 172.20.0.10 — tells the router not to lease out 172.20.0.1 through 172.20.0.10 in the Library subnet. DHCP will therefore start handing out addresses from 172.20.0.11.Each pool defines the subnet to lease from, the gateway to advertise, and the DNS server. The DNS server lives in the Servers VLAN at 172.20.80.10.
ip dhcp pool LIBRARY
network 172.20.0.0 255.255.240.0
default-router 172.20.0.1
dns-server 172.20.80.10
!
ip dhcp pool COMPUTER_LABS
network 172.20.16.0 255.255.240.0
default-router 172.20.16.1
dns-server 172.20.80.10
!
ip dhcp pool ADMINISTRATION
network 172.20.32.0 255.255.240.0
default-router 172.20.32.1
dns-server 172.20.80.10
!
ip dhcp pool ACADEMIC_STAFF
network 172.20.48.0 255.255.240.0
default-router 172.20.48.1
dns-server 172.20.80.10
!
ip dhcp pool STUDENT_WIFI
network 172.20.64.0 255.255.240.0
default-router 172.20.64.1
dns-server 172.20.80.10
ip dhcp pool LIBRARY — creates a named pool for the Library department.network 172.20.0.0 255.255.240.0 — the range of addresses this pool leases from (the whole Library /20, minus the excluded block).default-router 172.20.0.1 — the gateway handed to clients. This must match the sub-interface IP you set in Task 4.dns-server 172.20.80.10 — the DNS server clients will use (the campus server in the Servers VLAN).network statement covers it — the ACADEMIC_STAFF pool. That is why the pool networks must line up exactly with your sub-interface subnets.
end
write memory
end — exits back to privileged EXEC mode.write memory — saves the running configuration (gateways and DHCP pools) to NVRAM.The campus server must keep a fixed address so clients (and the DHCP dns-server line) can always find it. Click DNS-Server → Desktop tab → IP Configuration → select Static and enter:
| Setting | Value |
|---|---|
| IPv4 Address | 172.20.80.10 |
| Subnet Mask | 255.255.240.0 |
| Default Gateway | 172.20.80.1 |
| DNS Server | 172.20.80.10 |
Every client PC gets its address automatically. For each of the 10 PCs:
172.20.0.11 and 172.20.0.12, each with mask 255.255.240.0 and gateway 172.20.0.1.
show vlan brief), the trunk is up, and the matching router sub-interface and DHCP pool exist.
Open the Command Prompt on PC-Lib-1 and run:
ipconfig /all
Confirm the PC received an address in the Library subnet (e.g. 172.20.0.11), mask 255.255.240.0, gateway 172.20.0.1, and DNS 172.20.80.10.
From PC-Lib-1, ping PC-Lib-2 (same VLAN):
ping 172.20.0.12
This should succeed immediately — both PCs are in the same VLAN and do not need the router.
ping 172.20.32.11ping 172.20.64.11ping 172.20.80.10This traffic goes: PC → Switch → Router (routes between VLANs) → Switch → destination. All pings should return successful replies.
On the router CLI, run:
show ip dhcp binding
show ip dhcp pool
show ip interface brief
show ip dhcp binding — lists every address the router has leased and to which device (MAC).show ip dhcp pool — shows each pool and how many addresses are in use.show ip interface brief — all six sub-interfaces should read up/up with the correct gateway IPs.ipconfig on the PC — confirm it holds a DHCP address, not 169.254.x.xshow vlan brief)show ip interface brief)default-router matches the sub-interface IP for that VLANip dhcp excluded-address the first 10 addresses of each subnet before creating the pool?default-router line was missing from a DHCP pool?In this practical you have:
ipconfig, ping, and show ip dhcp binding