Cisco home lab showcase

A three site enterprise home lab, built on real hardware

This is my home lab. I use it for proof of concept work, troubleshooting and certification study. Every Cisco router, switch, IP phone and access point, and every HP server, is physical kit in a 42U rack.

  • MPLS L3 VPN
  • DMVPN
  • Cisco ASA
  • Palo Alto
  • Check Point
  • Cisco UC
  • Cisco ISE
  • VMware ESXi
The top half of the 42U lab rack, full of Cisco routers and switches with labelled patch cables
42U rack · routers and switchesphysical kit
3enterprise sites
17Cisco routers
6Cisco switches
27virtual machines
9IP phones
9access points
01 · Purpose

Why I built it

I wanted a place where I can run a real enterprise network end to end, on the same kind of kit my clients use, without putting anything live at risk.

Proof of concept

I prove designs end to end before they go anywhere near a live network. Routing changes, firewall policy and failover all get tested here first.

Troubleshooting

When a fault is hard to pin down, I rebuild it here on the same class of kit. I can break things on purpose and work through the fix with no risk to anyone.

Learning and certification

The lab covers routing, switching, security, voice, wireless and virtualisation. It has been my study bench for Cisco and VMware certifications.

02 · Topology

How it all connects

The lab models a company called ITS Ltd with offices in London, New York and Dubai. A second company, GAP Ltd, shares the same carrier network from Perth and Sydney. Every ITS Ltd office has two ways out: a private MPLS (Multiprotocol Label Switching) link as the main path, and an internet link as the backup.

Connectivity at a glance

A simplified view I drew from the full diagram further down. The subnets match the real build.

Simplified lab connectivity An MPLS provider core with two P routers and five PE routers links three ITS Ltd sites in London, New York and Dubai, and two GAP Ltd sites in Perth and Sydney. Each ITS Ltd site also has an edge firewall and an internet router on a simulated internet run by the terminal server, with DMVPN tunnels as the backup path. The terminal server reaches the real internet through the home network. MPLS PROVIDER CORE ITS Ltd and GAP Ltd in separate VRFs 1.1.1.0/29 6.6.6.0/29 5.5.5.0/29 2.2.2.0/29 4.4.4.0/29 3.3.3.0/29 61.61.61.0/29 51.51.51.0/29 21.21.21.0/29 10.1.1.0/30 31.31.31.0/29 41.41.41.0/29 81.81.81.0/29 83.83.83.0/29 82.82.82.0/29 DMVPN backup DMVPN backup real internet P1 coreCisco 2811 P2 coreCisco 2811 PE PerthGAP Ltd PE SydneyGAP Ltd PE LondonITS Ltd PE New YorkITS Ltd PE DubaiITS Ltd CE Perth1603 · loopbacks CE Sydney1603 · loopbacks CE LondonCisco 2811 SITE 1 · ITS LTD London 10.1.x.x Core switch · Cisco 3750 Access switch (PoE) ESXi host · 11 VMs Voice GW · 3 phones Wireless · 3 APs Edge firewall SITE 2 · ITS LTD New York 10.2.x.x Core switch · Cisco 3750 Access switch (PoE) ESXi host · 11 VMs Voice GW · 3 phones Wireless · 3 APs Edge firewall SITE 3 · ITS LTD Dubai 10.3.x.x Core switch · Cisco 3560G Access switch (PoE) ESXi host · 5 VMs Voice GW · 3 phones Wireless · 3 APs Edge firewall Internet router Internet router Internet router Simulated internet, built with VRFs on the terminal server Terminal server2811 · 192.168.1.199 Home networkBT Infinity · iLO network
  • MPLS core and ITS Ltd
  • GAP Ltd
  • Internet
  • DMVPN backup
  • Site LAN
  • Home network

Swipe sideways to see the whole diagram.

Main path

MPLS from a carrier style core

Two P (provider core) routers and five PE (provider edge) routers act as the carrier. Each customer gets its own VRF (virtual routing and forwarding table), so ITS Ltd and GAP Ltd share the core but never see each other's routes.

Backup path

Internet with DMVPN tunnels

Each site has an edge firewall and its own internet router. If the MPLS path fails, traffic moves to DMVPN (Dynamic Multipoint VPN) tunnels built across the internet between the three sites.

Internet

Both real and simulated

The terminal server, a Cisco 2811, uses VRFs to act as a public internet between the sites. A default route to my BT Infinity line, through a DrayTek router, gives the lab real internet access too.

Management

Reachable even when the lab is down

The terminal server gives me console access to the kit. The iLO (Integrated Lights Out) ports on the HP servers sit on my home network, 192.168.1.0/24, so I can always reach every host.

The full topology

The detailed build diagram, with every interface and subnet. Open it full size and click to zoom in.

Lab topology brief
Detailed lab topology diagram showing the home network, terminal server, MPLS core with P and PE routers, customer edge routers, and three sites each with core and access switches, voice gateway, IP phones, access points, firewall, internet router and an ESXi host with its virtual machines
  1. 1

    Home network

    Top left. My BT Infinity broadband and home switches. It feeds real internet into the lab and carries the iLO network for all three servers.

  2. 2

    Terminal server

    Top centre. A Cisco 2811 on 192.168.1.199. It runs the simulated internet with VRFs and links to each site's internet router on its own /29.

  3. 3

    MPLS core

    Centre. Two P routers joined on 1.1.1.0/29, and five PE routers for Perth, London, New York, Dubai and Sydney. All are Cisco 2811s.

  4. 4

    Customer edge

    London connects through a CE (customer edge) router. In New York and Dubai the core switch connects straight to the PE. GAP Ltd uses Cisco 1603 CE routers with loopbacks.

  5. 5

    Site LAN

    Each site has a layer 3 core switch, a layer 2 PoE (Power over Ethernet) access switch on two uplinks, a voice gateway, three IP phones, three access points and a PC.

  6. 6

    Compute

    One VMware ESXi host per site. London and New York run HP DL160s with 11 VMs each, including the full Cisco voice suite. Dubai runs a smaller HP ML110 with 5 VMs.

03 · Capabilities

What the lab can do

Nine areas I can build, test and break on demand, all on the same network.

MPLS L3 VPN core

A carrier style core with P, PE and CE roles. Two customers share it in separate VRFs, so I can test VPN design, customer separation and convergence.

  • MPLS
  • VRF
  • PE and CE
  • Cisco 2811

Dual WAN with DMVPN backup

Every site has MPLS as the main path and DMVPN over the internet as the backup. I can pull a link and watch failover and failback happen for real.

  • DMVPN
  • Failover
  • Dual WAN

Real and simulated internet

VRFs on the terminal server act as a public internet between the sites. A default route to my BT line adds real internet access when I need it.

  • VRF
  • Internet edge
  • DrayTek

Firewalls from three vendors

The edge at each site can run a physical Cisco ASA 5510, a virtual Check Point or a virtual Palo Alto. Check Point management and Panorama give central policy control.

  • Cisco ASA
  • Check Point
  • Palo Alto
  • Panorama

Campus switching

Layer 3 core switches route between VLANs. Layer 2 PoE access switches power the phones and access points, with two uplinks back to the core.

  • Cisco 3750
  • Cisco 3560G
  • VLANs
  • PoE

Unified communications

A multi site voice build with call control, voicemail, presence and a contact centre. Every site has a voice gateway and three IP phones.

  • CUCM
  • Unity Connection
  • CUPS
  • UCCX

Wireless

Three access points per site on their own VLAN, managed by a virtual Cisco WLC (Wireless LAN Controller).

  • Cisco WLC
  • 9 APs
  • VLAN 14

Identity and access

Cisco ISE (Identity Services Engine) for network access control. Windows Server 2012 R2 runs Active Directory, DNS, DHCP and TACACS for device logins.

  • Cisco ISE
  • Active Directory
  • TACACS

Virtualisation

VMware ESXi on three HP servers, managed through vCenter, with vMotion to move running VMs between hosts. iLO gives remote console access.

  • ESXi
  • vCenter
  • vMotion
  • HP iLO
04 · Sites

Three sites, one standard build

Every ITS Ltd site uses the same port plan and VLAN numbers. Only the WAN handoff and the server size change. That keeps changes repeatable and makes faults easy to compare.

Site 1 · ITS Ltd

London

10.1.x.x
WAN
CE router to PE London on 21.21.21.0/29
Internet
Firewall and internet router on 81.81.81.0/29
Core
Cisco 3750, layer 3
Access
Cisco 3750 PoE, layer 2
Voice
2811 voice gateway, 3 IP phones
Wireless
3 access points
Server
HP DL160, 2 × hex core, 48 GB RAM, 900 GB RAID 5
iLO
192.168.1.254

11 virtual machines

Windows DC · DNS · DHCP · TACACSCisco ISECisco WLCPalo AltoPanoramaCheck PointCheck Point mgmtCUCMCUCCUPSUCCX
Site 2 · ITS Ltd

New York

10.2.x.x
WAN
Core switch straight to PE New York on 31.31.31.0/29
Internet
Firewall and internet router on 83.83.83.0/29
Core
Cisco 3750, layer 3
Access
Cisco 3750 PoE, layer 2
Voice
2811 voice gateway, 3 IP phones
Wireless
3 access points
Server
HP DL160, 2 × hex core, 48 GB RAM, 900 GB RAID 5
iLO
192.168.1.253

11 virtual machines

Windows DC · DNS · DHCP · TACACSCisco ISECisco WLCPalo AltoPanoramaCheck PointCheck Point mgmtCUCMCUCCUPSUCCX
Site 3 · ITS Ltd

Dubai

10.3.x.x
WAN
Core switch straight to PE Dubai on 41.41.41.0/29
Internet
Firewall and internet router on 82.82.82.0/29
Core
Cisco 3560G, layer 3
Access
Cisco 3750 PoE, layer 2
Voice
2811 voice gateway, 3 IP phones
Wireless
3 access points
Server
HP ML110, 1 × quad core, 16 GB RAM, 256 GB SSD
iLO
192.168.1.252

5 virtual machines

Windows DC · DNS · DHCP · TACACSPalo AltoPanoramaCheck PointCheck Point mgmt

A branch style site. It has no call servers of its own, so its phones rely on the call managers in London and New York.

The second customer: GAP Ltd

GAP Ltd has CE routers in Perth and Sydney, both Cisco 1603s, with loopback interfaces standing in for office networks. It shares the MPLS core with ITS Ltd but lives in its own VRF. That lets me prove the two customers stay apart while sharing the same carrier routers.

05 · Engineering detail

The numbers behind the diagram

For anyone who wants to check the design: VLANs, addressing, WAN links, the port plan and the compute behind each site.

VLANs (the same at every site)

VLANPurposeWhere it lives
11Servers and voice gatewayCore switch, ESXi host, voice gateway
12DataPCs on access ports Fa0/1 to 0/6
13VoiceIP phones on access ports Fa0/1 to 0/6
14Wireless access pointsAccess switch AP ports
17Second ESXi network (vMotion)Core switch to ESXi host, London and New York

Host addressing

SiteESXi on VLAN 11ESXi on VLAN 17iLO
London10.1.1.130/2510.1.7.130/25192.168.1.254/24
New York10.2.1.130/2510.2.7.130/25192.168.1.253/24
Dubai10.3.1.130/25Not used192.168.1.252/24

Each site has its own 10.x range: London 10.1.x.x, New York 10.2.x.x and Dubai 10.3.x.x. The London voice gateway sits on 10.1.1.250.

06 · Hardware

The 42U rack

Everything in the diagram is real hardware, racked and cabled in a single 42U cabinet. Select any photo to see it larger.

The lab rack seen from the front at an angle
Front
Top of the rack with Cisco routers and switches
Front top · routers and switches
Bottom of the rack with HP tower and rack servers
Front bottom · HP servers
Rear of the rack showing cabling and power distribution
Rear · cabling and power

What is in it

The main kit shown in the topology.

  • 15 ×
    Cisco 2811 routersMPLS core and edge, internet routers, voice gateways, terminal server
  • 2 ×
    Cisco 1603 routersGAP Ltd customer edge
  • 2 ×
    Cisco 3750 switchesLayer 3 core in London and New York
  • 1 ×
    Cisco 3560G switchLayer 3 core in Dubai
  • 3 ×
    Cisco 3750 PoE switchesLayer 2 access at each site
  • •
    Cisco ASA 5510Physical edge firewall
  • 9 ×
    Cisco IP phonesThree per site
  • 9 ×
    Cisco access pointsThree per site
  • 2 ×
    HP ProLiant DL160ESXi hosts in London and New York
  • 1 ×
    HP ProLiant ML110ESXi host in Dubai
07 · Workspace

Where the work happens

Kit gets built and configured on the bench before it goes in the rack, and spares are kept close by.

Prestaging area

Three desks with multiple screens, IP phones on the bench and room to stage new kit. I build and test configurations here before a device goes into the rack.

Prestaging desks with screens and IP phones
Test bench with monitors and Cisco IP phones
Network kit and boxed Cisco equipment staged on the bench
Shelving unit full of sorted cables, power leads and spare parts

Storage for spares

Cables, power leads, modules and spare parts, sorted by type. A rebuild never waits on a missing lead.

  • Patch and console cables by length and colour
  • Power leads and adapters
  • Spare modules, phones and parts
08 · Learning

Certifications and training

Most of these I studied for on this lab. Legacy certifications, written exams and training courses are labelled so it is clear what each one is.

Cisco

12 certifications
  • CCIE SecurityCiscoWritten exam
  • CCIE Routing and SwitchingCiscoWritten exam
  • CCNP EnterpriseCisco
  • CCNP Routing and SwitchingCisco
  • CCDP ARCHCisco network design
  • CCNA Routing and SwitchingCisco
  • CCVPVoice, later renamed CCNP VoiceLegacy
  • CCIPService providerLegacy
  • Cisco Certified Specialist 4 certifications

    • Enterprise Advanced Infrastructure Implementation
    • Enterprise Core
    • Enterprise Design
    • Security Core

Cloud, virtualisation and Microsoft

5 items
  • Solutions Architect ProfessionalAmazon Web Services
  • Google Cloud PlatformGCPTrained
  • Microsoft AzureCloud platformTrained
  • VMware Certified ProfessionalVCP5, Data Centre Virtualisation
  • MCITP and MCSEMicrosoftTrained

Audio visual and CCTV

10 certifications
  • Kramer Academy 9 certifications

    • AV Fundamentals
    • Audio Specialist
    • AV over IP Sales Associate
    • AV over IP Installer
    • Control System Designer (KCSDC 301)
    • Education Spaces and Solutions Designer
    • VIA Sales Installer
    • QuickLaunch Configuration 102
    • QuickLaunch Installer
  • Hikvision 1 certification

    • CCTV Expert